Static | ZeroBOX

PE Compile Time

2020-05-25 17:20:41

PDB Path

C:\gicecatovalo\jivumokudu\jesuyuraji\38\fayagecoca_sodirowogi.pdb

PE Imphash

9e6cdfd867cec1c30d2ae8894f290a78

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00076870 0x00076a00 7.97672728093
.rdata 0x00078000 0x00004d6c 0x00004e00 5.63603304335
.data 0x0007d000 0x0288f6a4 0x00003e00 1.29301058403
.rsrc 0x0290d000 0x0000cb96 0x0000cc00 6.7567139494

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_STRING 0x029190e4 0x000001f2 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_STRING 0x029190e4 0x000001f2 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x02919318 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x02919318 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x0291939c 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x0291939c 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_VERSION 0x02919404 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x029195b8 0x000005ad LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x478008 WriteConsoleOutputW
0x478010 GetConsoleAliasA
0x478020 GetUserDefaultLCID
0x478024 SetEvent
0x47802c GetConsoleTitleA
0x478030 CreateActCtxW
0x478038 GetConsoleCP
0x47803c GlobalAlloc
0x478040 GetSystemDirectoryW
0x478044 GetFileAttributesA
0x478048 lstrcpynW
0x478058 IsBadWritePtr
0x47805c GetModuleFileNameW
0x478064 CreateFileW
0x478068 lstrcatA
0x47806c GetACP
0x478070 lstrlenW
0x478074 EnumDateFormatsExW
0x478078 VerifyVersionInfoW
0x47807c InterlockedExchange
0x478080 GetCPInfoExW
0x478088 GetLastError
0x47808c GetProcAddress
0x478090 PeekConsoleInputW
0x478098 LocalLock
0x4780a4 SetTimerQueueTimer
0x4780a8 GetLocalTime
0x4780ac WriteConsoleA
0x4780b0 DeleteTimerQueue
0x4780bc GlobalGetAtomNameW
0x4780c8 GetModuleFileNameA
0x4780cc GetModuleHandleA
0x4780d0 EraseTape
0x4780d4 EndUpdateResourceA
0x4780d8 ReadConsoleInputW
0x4780dc FindFirstVolumeW
0x4780e0 GetCurrentProcessId
0x4780e4 AreFileApisANSI
0x4780e8 LCMapStringW
0x4780ec FlushFileBuffers
0x4780f0 LCMapStringA
0x4780f4 GetStringTypeW
0x478100 HeapAlloc
0x478104 GetModuleHandleW
0x478108 Sleep
0x47810c ExitProcess
0x478110 GetStartupInfoW
0x478114 WriteFile
0x478118 GetStdHandle
0x478124 HeapFree
0x478128 VirtualFree
0x47812c VirtualAlloc
0x478130 HeapReAlloc
0x478134 HeapCreate
0x478138 TlsGetValue
0x47813c TlsAlloc
0x478140 TlsSetValue
0x478144 TlsFree
0x478148 SetLastError
0x47814c GetCurrentThreadId
0x478150 TerminateProcess
0x478154 GetCurrentProcess
0x478158 IsDebuggerPresent
0x47815c LoadLibraryA
0x478168 GetCommandLineW
0x47816c SetHandleCount
0x478170 GetFileType
0x478174 GetStartupInfoA
0x47817c GetTickCount
0x478184 RaiseException
0x478188 RtlUnwind
0x47818c GetCPInfo
0x478190 GetOEMCP
0x478194 IsValidCodePage
0x478198 HeapSize
0x47819c GetLocaleInfoA
0x4781a0 WideCharToMultiByte
0x4781a4 GetStringTypeA
0x4781a8 MultiByteToWideChar
Library USER32.dll:
0x4781b0 RealGetWindowClassA
Library ADVAPI32.dll:
0x478000 AdjustTokenGroups

Exports

Ordinal Address Name
1 0x401003 @GetAnotherVice@12
2 0x401000 @SetFirstEverVice@4
!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVVht
"uzVVV
VVVVVV
eu`VVVVVV
D$8PVV
tNIt?It0It
>=Yt1j
QQSVWh
j@j ^V
0SSSSS
0SSSSS
0SSSSS
URPQQh
0A@@Ju
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
:ngN=&
6iL RP0
9+"N23$|
vN*]/#|
{\T$3+
[)9'@OA
5cY~&MT
vnU61f
AY&lo},
6Rv=Gu
E7wd[u
iWX\GzA
6rVH(h/
'-KUhS
jMdWWK
k1F+Cr
?Y2|cDF
!O3UbD
ZF6|Qb
:on}.`
xygJjG
"/8_- 6
f1)6t
]M%'m:
x`M4laZ
(:1:Y1l5
H9Ghz!
|gDR`Zr
v^+sxg9
D?F0dL
B[5w62
Iaq0HF9
QKQo-E7
Lu-m:i2
5fT?qS%
x|bm)q
fEW@Lvo
h)Ae4c
($qCl{
wdf/e`$_u
+X?{'A
;{=;D<
!UJ$B8
wVF3k
7le;9W
iNU>>uni
;=M,r
sA@X~
M%3WVI
tXtFeZ
FKaA/-
%s~}JH
XY!9a1
5VYj0B
VfbU~f
ve*'\i)t
P1;02&
ks3CDt
hV;ga
L(K C
=wdY;Q
bzR6YLO
aS)5,O
B}+WD5
9^<'^9
=eojP4L
K##">[
m6<+:QD
Qc`<Yn
O#+!X#[
kgMr<|lw
.sBJ&)
7@jc_V
=v`@^J
O=TtX<
,zInePQ
OmW+O5l
!h}t(O
>lf(Y]
2^paMH
r:y{Jn
$v5'2z
W$3rl$
%n)?>rU
=CuI#o
,XH$Tq
_0"8<z
hDRp<,
c%Cr}t
+|(,gt[U
}hx F|
AW/.%d
MkLv):
Gld*&?
fN$pWN
Z0e#7Y
x~(6[wM2Of
>D?2G
YeGKuXMu
S:T|O3
9x#J;|
(DpEC*
&~}xKI
.Hs:V5
|s`r'G
~Wr~RJ
T^*3p>
Cp}~!k
HO1+TMfI
Qga8L\
Z{}pr|V
<\b"?_
7%k2{H
"$=MI{
XZqDM}
+,aq\=
Q19jdb~
VN/!=c
hjm/&0Y
_9R%S3
58Gr,Z
j@Ue6,
jB/<kI
}iK.^pgJ{
A5yocj
X)We@>
V9QHDK)0
UBzE!rwE
C0OTVJ
".`&e~N-=
zR.bp(`yP
9A Ajn
N]q1PrG
,-mdVj
iOz\xp
imsq[m-
5rZ}#.
g.s<)Yo
}EiolO
W&q<[\
NuV'e|
~\5AQ&
h\TGn7
{<|mP[
S[oM1iT
5bxkN
V](x/3"
gKGa"O
tw6B=Lc
B4*<P\s^P-
JPIY{t^
(qTn($
RX%Pn~s"9Ju
)JXoi
pvx2\#
U2KQ,s
Bc!.N)B
\{12cE
# |k<sS
TOqNOJK
|L[A-[d
6yl:,{z
TsYj:h
/ooAB<u
k0(wlDe'
nuB;XE
@}y3GN
`5S&2s
3`~iFs
<Jtt;(
|wGQ;{
,~-Lt92
Y0[{%0
MtX=C"
Q-2[OVd
=#f"(xD
hM8Q$U
~eku3j
^r>b;S
n=4WK8S
r(+v|5
Rp[en|
=^sm@9
+\1z}&s]
x? IqIi
x3TK$#
&{kb:Kn"F^
wVfqQ/
'2+B\H
S;Sqyc
qWHbG,
qWgAlx
S?i9CA
x,K{%$K
<,L_C.6
&'=hps
nh7:Qj
c|_}N$w
./8E1j
$?LL$CD
*Qykc]k
nVByX
G"TOx1
%RgkNI
""STFK
'wIQr~([W
kQDAIZ
[ID2$~
Mlu?~aQG
}F[IuH[nq
[U\(%t
wynTNSZ
5Gx$a1
[r)4O>qzsr
ezgx:c
Hw!/&x
i`G)8K k
jSD3S3
`qtMic
)X;}t5:y
jQ->rq
CXum*c
h\3d.Q3
DM90Zv/
l79+3}
%{~pbq
>+^Rbj
s IsM
\rzs~-
!x:;n,4D
!kUQ7Q
ik<v-s
~,PC|_;
?n1Ng`
?_3gH/
%DLa>p"
kb-< v
MD_I[
;-0b+b
de-\A#A\
kMLFt}Q
$W{!=R
W{PF["
?zJo<$Oh
v`Ze8]g
>#T\HT\J
UhZ-r?8
7-TNMsf
U-bD1c
UEd2fG
H&h,CqG[{ d0*2
k$;+1Ro
0Soerh[
5['`/#
>qju.`
A8h|*
E!Z5@u
@ 0bv<
w=:r<."
WO7Z*S]
QiO(J;
b:+xELs
Y*kV^E{u
{IU"dY
L0"XzV
=r`BPx^
,IVWN^
x_Fi`\/
}v+s&
;e6/B*
LEK[F|
;|4+^g
Q\]g^^v
3 ./,?
99u,*L
gs>2ao^A
=Zg Edy
,qz }nJ#
aQE86-
LQeZJ(
CvmR:
\"Qb|o
]bKQiG
iL.m`U
nOHSZj
6BHZo.
ekHJ6}
z 2V$f`)
|)<cNWx
'BQ2O"
?srRt
Sc^{mt
(V45Gt
Q5Oit=
E1|A L
B0Jo{q
Y^%kyR
[o=Dnl4
Wzb.DU
9n3&q.
ue(PZ%
^^BpEZg
s|C?k|
$&FfcD
/E_[6H
>UrMBt
$ny9Fo#d
Q{eLnO5
X0S}bAb
!#w*bVc
oa'VC,ci
!=%GPw
=48WD3
UwGM<
=\HT\O
(.'tTZS
l;_Sv$
U[W2&E
qU('+y
D0HfG#
xC;'D)n
Cs,Ew4
C|7ZMU3
jKw@:f
(V[G>6
w <?TD
f3.1rr
TkO(m}B1
rStF,o
b7+(%-X
KquyB|
od{7~^!Q
oY{c#N
lvSyGo)nV
p2)EA2r5
6tiPKit
\+_tX7
<&hr.%8q81
,<JktJ
ItjzrP
v+qR"*
5J[Ni,
$:~dD.Lu
uz}w{p
$2tFc7
g$bam.
nWJ6s4
4MPGS[x
XD~Z]G
b.&U{o
O-:V/\
m8iehm
Bdvy
~o4-p>
8BH._A&gU
Dz^Tmv
Gg~8<
8)8Z]3^
gF*_G/y
D;p/YZ8{~
'#@EAV'RZ
UulWU/Cd
Crud=U
0"_Amv
EdL&IWg
0<r-x
%w!+Z_j
DgcT]eG5
l$jky[
a:6/dp
`Z3a26x
*egO1r0
`yvOy#
b\UU^@
/qKbRDl
^D<NVwt
M{o8h
@?XaI3
Z!1luU
Q],#XS
;dbHl8
(/:= J5
,6E!$~
O9J(*E\Ad
g)@a-V
@OyZPC1
hFJ:8R
'9d7XE
D[C"Ph
;gT"E$
IOUB/j
1JzSgR
HY7;=\
m5szUEu
xyr2,k
qooaP"
}bm(@e
2r84],
@YcNEv0
+SI15#
H=~0ee
,vToUu
iR~4QI3
2~_(Ntw
w9uq#2.
"-o->'
/XHD[+n
B;yVN]
J~b;"{
cF=d/L
]M7DG?
1c6M_j
M-Ts!_
:" 5qeZ
uR(y-
U:Zqga?
h^lTYx
cO56g%
o$._!'
?K00Z;
k;h}4J
C<~bU8
eEBW]b
ssUhI+@0p)
+\bkr&
)b1a|}
;>z:].
^m^3O<
VBGI<H
`NPF:%
rzX=Jt
!8<h'
A-3f#S0
g3X:XS|
rMbe7=
(t`!Q|
HkCl4R
*g=9I#_w
FrNN%5zj
u.xP7[
|oP5gN
4qBv{,"
+N@:~3K8
o4^-c`O
0ST~NH
aGRf7J
&?'dH4
(rjg)\{
zOkyg&!
x.HKR:
WeVE(X
Q^kgPr
B[Hzm8l
Ian|(e
d4wg.d
B}.v-Z
.9Qy^!
8+ig@2
7TP{t
U@#$9d
%HEplgd
q@Z^>y
IM^kcK)`
w;t0~i
w?!'wg*
tc"-2#3$
NLCL1IJ
6M}{-h
')Ummr
v!ygg4
m~L&(s
4#juAp
JEU;B/
J(AWg`
E!F+`!y
2oIAi]
KBJ?z2
n<MFA/
rHZhma
<LB)xkCm
nz;lT
Y%":~
$BnNax|sE
u"nl q{
<]6:#E
$z^NV./\
Bu5sGu
qW0rZ#G
HI7rah
%$m)+*
.,6r<A
zaEF|R
&Fw2+-K}
X]~:@~
*p3M+&
g5GJ"<Y
JL1O5a
a8)04*
dY0mV&Ljf
L0o@?5
Xz/_OC
F#'F}tLe
VKm4e(W6_
rZ4Wz5
c/~43W
`{B%hE7
478wqf
kxy9frD
o*qm'a
&'oA{Q
OIr`ut
HI44Rk
lU0'|;
y#6;Xf
d("t_
;.vx$#
E V`Vb
$Cl:K>
>%;G#P
b@wacc'
r!JS6|
KM@7{tU
ai9$<6
;D'&k3
9'+'22
}v!K4zM+
&R}R;`>JN
;Gwcg+
m=)d!F
[Kj'r@
|qrFRn
sL$rw'$
U&w1)U%
qKtg6J
OfwITqU
Fi#irL
IJwtAb
!W[2r.7
(\N%jxh
*/~2*c|&2
`,/!sa/a
>v~|sZQI
#!/!HhQ
0>Ge_k
w$81mn
zAv"Qp
j<@0zIu
p@%~[iog
((d')e:
:4R>U#
*cCfN#
r5qDVC
QY-0/c
!0jCoq
k1C([4
i x5IE
9$A$
yI9&04W`
Kj\EpCb33
e!d+$W
)E_>rO
,"`j&,(&q*
-kJ]wL
Ciu4B"iudVwi
daIF`S
=N~l@c
m\|&a(
/opc*Z
E4xlZP
af1d;q
HDr0~~
7qSG5u
WR8#S1
Ai|#RmpE
4IptQk$M
@:W#^)
@R;G9b"
kF>H$bx
Y0WA[a
U1;;$%
GMi!/9
AIoo1uK
8?*>ol
=fH{8L
S;-off5
p#D{xu
Az?Dey
] <gE7
dz_#yx
}OxH<'
Sclj| [
5"rq}~C
[#N(ir1
JP@_}T.
Bd*)=!60Yu
(E=~Z4c
r%6?%0
~{1~IU
5.PG:H
h2N'6l
8)4H*
'/x:Y6
dp3_ejG
XC{><;}QmX*
ZLzb`m
gkz>]r
}Om7q
<H*W6}W[b
4NHf<rU]
zJ=g|i!
l\6*3+$
Mz"+i
'^V8^g2
hyR'k]B
Vxz\'Pwp?
WEmh+HZ
(`)gZ.R
D,w;t7
>nhDGmt
m9:0jE
u6"-+l(Yw
:)F`dn
;t-,|B
o6A5H,
[Y3[d /
|>IQ!'
[b~)1T@
0:UW1I
gUfuN?7\$
oc`.+r
>!>yUw
mGZSuJ
5E\RIr
KiY][KrN
y|Oc"9#
7V9,hZ
#c|@<%2
h/pqc=
e1MP..4
^krOXn
yQ.a4]
:pdjz>
d;MY p
S*w%#$
inlJx
UCN:.=
1qyLK!
b[&,P9jZ
fk|Q$i6
-N39:[
3q@}cH
`{xyV7
`zUwghS4
0WA\w'
Q2x%#<4
[cvX`j?:l
Bf%L.Y
7ieX7,$X0|
zc2Wf#j
,KdJ)^
*BYiY_
|XC+dL
F=.5bk
P3\[s+
0c}Y6H
uY%5=fY
{ZJM@:
JGFMu(p5
(_J\rC
/r;-\}
ztK>1MI7
w$xe-|*.
6Tf>!l
]liZ+C
/1u2.0
8XLA9f
,pqryKm)
?mkdp!
Rc'tCo
NQbj66
cR&.LM
\BAkVb
CM.s9w
,_B) r
iz^I`&
_(8/A?
J+e DW
GAxlX
B`20"#
Zr6[P)
=QjrKWc
4n]k9.
)]k iZ
ES8Nb*
C"bz+h
md<F)D
:l.^va
n~8Se6
dHs?;K
5gW:Ny
y:0SS3
\?(iDc
P"fTv,
5=*E?0
E:?==7
clNcz{
IY0Vo/
ayt`Y
q@L'(y2Xj
qq&I;
$d1R'
L+B*!=
^U!%{P
t$^bC6
tD++^G|[h
2[5a|;
V<^D!40
n]vGjD&3%
gGRU%5g;
J}1!U'
I?("l H
YsYL<W
v2-0l4"
D#Cb27(>SYAp
:1+vMP
O48q6pB
$Mh[4*m]!
8RxxF2E
E\#AtK
bj'ha`
2&ZyAE<
YS6-!j
47eamDYQ
yiRKDY[
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
tonelotali
kernel32.dll
LocalAlloc
VirtualProtect
divugezenowuxeg fowavaxafarilojihulinemeyoha nalowexukosugulomebemogudoxezi
C:\gicecatovalo\jivumokudu\jesuyuraji\38\fayagecoca_sodirowogi.pdb
EnumDateFormatsExW
WriteConsoleOutputW
InterlockedIncrement
GetConsoleAliasA
InterlockedDecrement
GetSystemWindowsDirectoryW
GetEnvironmentStringsW
GetUserDefaultLCID
SetEvent
GetConsoleAliasesLengthA
GetConsoleTitleA
CreateActCtxW
InitializeCriticalSection
GetConsoleCP
GlobalAlloc
GetSystemDirectoryW
GetFileAttributesA
lstrcpynW
SetConsoleCursorPosition
HeapQueryInformation
WritePrivateProfileSectionW
IsBadWritePtr
GetModuleFileNameW
GetCompressedFileSizeA
CreateFileW
lstrcatA
GetACP
lstrlenW
FlushFileBuffers
VerifyVersionInfoW
InterlockedExchange
GetCPInfoExW
FillConsoleOutputCharacterW
GetLastError
GetProcAddress
PeekConsoleInputW
CreateTimerQueueTimer
LocalLock
GetConsoleDisplayMode
EnterCriticalSection
SetTimerQueueTimer
GetLocalTime
WriteConsoleA
DeleteTimerQueue
DnsHostnameToComputerNameA
BeginUpdateResourceA
GlobalGetAtomNameW
WaitForMultipleObjects
SetEnvironmentVariableA
GetModuleFileNameA
GetModuleHandleA
EraseTape
EndUpdateResourceA
ReadConsoleInputW
FindFirstVolumeW
GetCurrentProcessId
AreFileApisANSI
KERNEL32.dll
RealGetWindowClassA
USER32.dll
AdjustTokenGroups
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapAlloc
GetModuleHandleW
ExitProcess
GetStartupInfoW
WriteFile
GetStdHandle
DeleteCriticalSection
LeaveCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
RaiseException
RtlUnwind
GetCPInfo
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
WideCharToMultiByte
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
cone.exe
@GetAnotherVice@12
@SetFirstEverVice@4
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
9999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999c
.t.99999999999999999999999999999999999999
999999999999999999999999999999999999
Q999999999999999999999999999999999
9999999999999999999999999999999
$999999999999999999999999999999
99999999999999999999999999999h
99999999999999999999999999999/I
99999999999999999999999999999t5
RRy]'{
4999999999999999999999999999999+8
j=V999999999999999999999999999999
9999999999999999999999999999999Q$+?__
999999999999999999999999999999999
T99999999999999999999999999999999999999999
T99999999999999999999999999999999999999999F
X$99999999999999999999999999999999999999999
$99999999999999999999999999999999999999999
9999999999c5Q9999999999999999999999999999
9999999999C
9999999999999999999999999999
-999999999
9999999999999999999999999999
-9999999
9999999999999999999999999999
9999999999999999999999999999
9999999999999999999999999999
DPN.9999999999999999999999999999
99999999999999999999999999999
999999999999999999999999999991
>999999999999999999999999999999-
999999999999999999999999999999
9999999999999999999999999999999-
999999999999999999999999999999999
mu/199999999999999999999999999999999999999
9999999999999999999999999999999999999999
9999999999999999999999999999999999999999
999999999999999999999999999999999999999999F
99999999999999999999999999999999999999999999F
9999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwO|
wwwwwwwwwwwwwwwwwwwwwwwwwm
wwwwwwwwwwwwwwwwwwwwwwww?B
wwwwwwwwwwwwwwwwwwwww
Trilwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwwww
Kwwwwwwwwwwwwwwwwww
\swwwwwwwwwwwwwwwwwww
)wwwwwwwwwwwwwwwwwww
.wwwwwwwwwwwwwwwwwwwww5
wwwwwwwwwwwwwwwwwwwwwwwwwwww
Dwwwwwwwwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwwwwwwwwwwwww
L6wwwwwwww
wwwwwwwwwwwwwwwwwwk
wwwwwww
wwwwwwwwwwwwwwwwwwo
Xwwwwww
wwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwww
,wwwwwwwwwwwwwwwwww
`Ywwwwwwwwwwwwwwwwwww1
wwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwwwww9
wwwwwwwwwwwwwwwwwwwww
dwwwwwwwwwwwwwwwwwwwwww(
&wwwwwwwwwwwwwwwwwwwwwwwww
-Fwwwwwwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwww
CDzd(-{
&CY{u2A|
HNz{IU
13L}s-$
Haa{y4/
1L^~s1#{
&76}d'&
9^fuG94~
Teb}yo
)OVs?/FzV
IMR{}_
KgP{|Zo
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
00Drrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Crrrrrrrrrrrrrrrrr
rrrrrrrrr
rrrrrrrrrrrrrrUU2
$Urrrr
rrrrrrrrrrrrr4
rrrrrrrrrr
vUrrrrrrrrrd>%P
rrrrrrC
rrrrrr
rrrrrrqe
frrrrrrr
mrrrrrrr
RWR~~=
Llrrrrrrr
rrrrrrr
{y0rrrrrrr
rrrrrrrrr4
rrrrrrrrr
rrrrrrrrrr
rrrrrrrrrrrrr0
Drrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
WT*UrrrrrrrrrrrrrrrrCbb
rrrrrrrrrrrrrrrrrr
Urrrrrrrrrrrrrrrrrrr=R
>$UrrrrrrrrrrrrrrrrrrrrrrB=
Urrrrrrrrrrrrrrrrrrrrrr
Urrrrrrrrrrrrrrrrrrrrr
lUrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
0rrrrrrrrrrrrrrrrrrrrrrcI
rrrrrrrrrrrrrrrrrrrrrrrC
e0rrrrrrrrrrrrrrrrrrrrrrrrr
b0rrrrrrrrrrrrrrrrrrrrrrrrrrrK
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
^^^^^^^^^^^^^^^^^^
KeF^^{w
^^X|-6
.`v^^^^A
&^^^^^^
^^^^^^^
^^^^^^^
^^^^^^^^4
k^^^^^^^^^^qS
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
*Qp; j
kFKj18R
4YkC(v
U{{'7MuQ
4k~\0c
1Lc;"v
/<kA,|
{6d~~Bl~Z
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:v3="urn:schemas-microsoft-com:asm.v3"><assemblyIdentity version="1.1.00.00" name="AutoHotkey" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility><v3:application><v3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns:ws2="
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
kadezidanoyefadurumuhafugogemako
kuloxosigolixilaf
wukacuno
ribaxodekuhewem
Zaj sozapubujobih%Nocisi wito bud yaronuba rajometavokeADepavisapuju ravexemacehazas buvozekurutahe joju harahugepaga nov#Wamexuyacekoz dafecitis hucuhejudelLRapuhapuwokeni pilenisovedo leh viruwecuyej gifariza bimemecofocedor nukawocTBavenebihixa tusayezejifiz tetasodedowaf rizovukuyami xaromupo kasizelox razicomemox?Xibusejaxutuhix cupanigaloxul sufetugijeyod vukuwuneveki yatuvo
Xeposo,Zabe zuciy gexevezuxusaz sowa yen zerodesiru
Keyixubuto
Zozacux gopimicuhojah wotani#Dapavabasuto bedufab dolu fihusujer$Busavuy nuloketapig dicagad sem tovoJHadupuherino nozuhunetob way cufehuvejo hegizulexege yoricitag gaheceyezoc
VS_VERSION_INFO
StringFileInform
080564c6
InternalName
sagzmeoleke.iwi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.21.22.123
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMDM
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
FireEye Generic.mg.8592015a4beab9f1
Sophos ML/PE-A + Troj/Krypt-W
Ikarus Trojan-Downloader.Win32.Zurgop
GData Win32.Trojan.Ilgergop.CLSXAU
Jiangmin Clean
eGambit Unsafe.AI_Score_69%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPe.R426948
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 BScope.Trojan.Glupteba
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HMDM!tr
Webroot W32.Trojan.Gen
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_80% (D)
Qihoo-360 Clean
No IRMA results available.