Static | ZeroBOX

PE Compile Time

2020-05-25 11:04:03

PDB Path

C:\zejutadifol hilo.pdb

PE Imphash

9e6cdfd867cec1c30d2ae8894f290a78

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00076780 0x00076800 7.97771268987
.rdata 0x00078000 0x00004d70 0x00004e00 5.62454575733
.data 0x0007d000 0x0288f6a4 0x00003e00 1.29314093012
.rsrc 0x0290d000 0x0000cb96 0x0000cc00 6.75204045176

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x02918968 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_STRING 0x029190e4 0x000001f2 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_STRING 0x029190e4 0x000001f2 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x02919318 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x02919318 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x0291939c 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x0291939c 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_VERSION 0x02919404 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x029195b8 0x000005ad LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02919b8c 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x478008 WriteConsoleOutputW
0x478010 GetConsoleAliasA
0x478020 GetUserDefaultLCID
0x478024 SetEvent
0x47802c GetConsoleTitleA
0x478030 CreateActCtxW
0x478038 GetConsoleCP
0x47803c GlobalAlloc
0x478040 GetSystemDirectoryW
0x478044 GetFileAttributesA
0x478048 lstrcpynW
0x478058 IsBadWritePtr
0x47805c GetModuleFileNameW
0x478064 CreateFileW
0x478068 lstrcatA
0x47806c GetACP
0x478070 lstrlenW
0x478074 EnumDateFormatsExW
0x478078 VerifyVersionInfoW
0x47807c InterlockedExchange
0x478080 GetCPInfoExW
0x478088 GetLastError
0x47808c GetProcAddress
0x478090 PeekConsoleInputW
0x478098 LocalLock
0x4780a4 SetTimerQueueTimer
0x4780a8 GetLocalTime
0x4780ac WriteConsoleA
0x4780b0 DeleteTimerQueue
0x4780bc GlobalGetAtomNameW
0x4780c8 GetModuleFileNameA
0x4780cc GetModuleHandleA
0x4780d0 EraseTape
0x4780d4 EndUpdateResourceA
0x4780d8 ReadConsoleInputW
0x4780dc FindFirstVolumeW
0x4780e0 GetCurrentProcessId
0x4780e4 AreFileApisANSI
0x4780e8 LCMapStringW
0x4780ec FlushFileBuffers
0x4780f0 LCMapStringA
0x4780f4 GetStringTypeW
0x478100 HeapAlloc
0x478104 GetModuleHandleW
0x478108 Sleep
0x47810c ExitProcess
0x478110 GetStartupInfoW
0x478114 WriteFile
0x478118 GetStdHandle
0x478124 HeapFree
0x478128 VirtualFree
0x47812c VirtualAlloc
0x478130 HeapReAlloc
0x478134 HeapCreate
0x478138 TlsGetValue
0x47813c TlsAlloc
0x478140 TlsSetValue
0x478144 TlsFree
0x478148 SetLastError
0x47814c GetCurrentThreadId
0x478150 TerminateProcess
0x478154 GetCurrentProcess
0x478158 IsDebuggerPresent
0x47815c LoadLibraryA
0x478168 GetCommandLineW
0x47816c SetHandleCount
0x478170 GetFileType
0x478174 GetStartupInfoA
0x47817c GetTickCount
0x478184 RaiseException
0x478188 RtlUnwind
0x47818c GetCPInfo
0x478190 GetOEMCP
0x478194 IsValidCodePage
0x478198 HeapSize
0x47819c GetLocaleInfoA
0x4781a0 WideCharToMultiByte
0x4781a4 GetStringTypeA
0x4781a8 MultiByteToWideChar
Library USER32.dll:
0x4781b0 RealGetWindowClassA
Library ADVAPI32.dll:
0x478000 AdjustTokenGroups

Exports

Ordinal Address Name
1 0x401003 @GetAnotherVice@12
2 0x401000 @SetFirstEverVice@4
!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVVht
"uzVVV
VVVVVV
eu`VVVVVV
D$8PVV
tNIt?It0It
>=Yt1j
QQSVWh
j@j ^V
0SSSSS
0SSSSS
0SSSSS
URPQQh
0A@@Ju
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
a:p(iS
&~%?]!1
8C=:Y~VX)
%:;!wt
1{Eq_>L
'K4d}
btu)J
ex,?Oe-
PRBpgt<
F"g1I>
u]:7-c
jM:7u'
(huV C2
'"FF4$J!
>x`P&0
`@/X6y
*owM9ER
7<e[N*H
Nb*RKc
RJs,l:
=5+kc7
ABGn2fQ
mw>.1c
4Sx0=N
i42F\`
AN,&Sh
J9/@Cs
0$Iyr/
Md8=H0Hn
wY($'1
(n^S%
TawJV4
3.7?vF
h-D\]IP
`?4t@A
hkH8r&=
;Qcjr^/
W{@Du|
EdO>7'
;3^FeY
%>xP@d
y"K')f{
Cx,R|;
NdBzSx
^h9(N<
(|;%\x
J:5NCkD
uA^iB},
`u1VA85u
-]c(S4u
L!Y<8{6s
<Hw-@'
7X*sFt]
0c~pI
UO@1A1
nlmDL5
:hOVli
5Q0iHX
yF7)MA
l87X|]
*$i*EL<_
Y-Fm@N
n,JTB7
9a;6/v
(|4V'gy<u
{tC ~8
1S`ms~Ku
%3y-57
gEIkGu
`|`a`1h
(tipI"eO
NU.UbuI
zer%*E
nYCe_E
mcQJX=
t+8D--pr
Tr##\q
a{rCn4
QU3,H ]
5sr>(m
\w[pBf
CyB`l*}
Cot~7>
C*T8e;
3CW3V%*jz
m5MmGB_W-b
HAqS6Q[
y,8&oD
:,Y:XI
~B%Xir
r~`rVJ
#oR`KC
Y9lr&gc
b-=a.|
Ssh(ANx
|eX1mi
6(w\y{
:(Vx5|
h%W}sw
sR:H`
}4|k@&D
szcUds
bScHlG
MzCz1J
K<;EV.
F*&]2j
G>a/|+
n4^.Qqv
;d_"<CU?
MPA;yo
*&N0[
]|wgh}
s(`",u
'j( Pa
EHC;S}
D6Yi@$
?&%:4QH
*wPpNq5@I
2VqF(R4&(
V#(;mP
c$-wsLk}
]pP_hI
#zL;O'
tIDd#T
JLYfRj
&>d{,3d
!AC>~j
G&d]]+
$xd48N
c"~|>g
8-JP4+
DN.]~]
nYC6HJ
APk'sWI
-mA<N!
7)I&Ewu6E
N+Su~9C
7$P9D"
l+\+'8
'G?DLGD
!dvm\=
LzdE`v
TiR$s(h
lc ?9AJd
Fw](RR
Qrx5a;c
p8(kUW
|cWxhq
@xv#'y
%^k#D\
W!$q|I5
o}L].81
v:WbcU
P{Bp0*
!Yq<Hx
$*;9-O
R'WH-/
z/'qoG
W"bu9<m
\CXDu-
*_U>t\
Eh2\k2
|KgW^
UFeN,A
,W5c5bf
1yQ@bD
z#)>,'.
]_sJ"1\
G4q9Uc
XXswa
m!R'\
w4D{OC>z
z>~R"|
KpPuW\L
*o8U):M
1q+lDisT
yY7ec4Ma
[+kX'\
2z0n)<W?
!?fm`b
Y8]Uxr
f[\\P:x-
LP5#CS.e<,
vLk4[6
?NjJmd
z9l9qM
r9,`|D
!F%D6h
A}OWn*28
18$LK
I;Iv":
HTHqNxN
{,5rCL
M{7H>Q|
h5G~b
rB=JMy
$u<q;~
ps=o>C
:[o\@u
e2<"6\z
_C&3n8
bJT|vF
=D"h{&4
F>NA%f
=JG Fj1
H zdA}
(i#&Td
YGl'.mH
{NZ=y,
8V|j:4
PgZ$|F
D@]*B$"
L9:~XP
F4KdtG
}d{cd=U
ssBUN-4O
9"Bnmm
]o1N#&
8>+g7{NyP
Q=V5>[
A9V`d6
T'hpB.e
0&11
O769U4=
tnlnD%
A$J<YzmU
'!L0<Z
GLnE#1]
:l>~(kw\!
jpMii]#
a^=96]bII
( 6^iGO
*^F%bd
R!6?,N
cd3T4q
eINi7(
NEekq%
-fX$?=
gH>&};o
h"*1na
K^Y&66
V@ObBg
<3k_ Q
>?0AQ.
r-"qPX
G~N"We
m~)O+1#;
u9h"`U%
Yj?'+vet
6$^5$FL
a9'd68
+iPpr\c|`
2aLwxg
z:OD-9
>lcr9m
!pa>T}W\+
8OWx^K
lf?Mx`H
?ci[b5
TOc+y_
R..INO
1\XEvVlP
-mFW_AF
L&FI.!
`O!6t>l
x=L1C*>L
St{6$a
)BI=@G*L;
O>\X9K
dqVeb,
w_hRHV
'I6JGq
%RKz:-
|`*)&*
1IV;D"
SNYwXn6
D-J'Dj
;=0UE%-
[dXV)
0`dx S
l#b/ym
UFhP"@z
KWC|n,
lpKyYM
5"{m%7)
fm/o188
h5mLT!,
,:Q.ui
n"gAii
h,(((9
YU*9I9
-Q}e.R
5mTWoS
tGbk(:1B
2c(&zos
LS7&Z~JD
N5p`XX
Lo8Q0|k
vM;^65<
UA-@+L
!9#[#h
~@)6%pE|g
Klj|^#
E{7R)v
>,>zv@
*\1s<7
2XuBL':
=l^DKU
(:u{!O
J*JB^o
;xo]9&K%
QD*?hKd
uY<in~
dJ0el|
7:j>qK
r4skO7
PQ.|sM
77N.`H
$X1*3q
} MLC_
}xHs|v
:5Tfx>
{Sj?u}]
O]|Q2i
8UGPWO}'
T|:0x5
V+s6_=
vp4[Aur
rCd3?+
CUz4=Ef
3y`o{r
u'}D-%U
t>Besx
yR:VDOi
W7SL0W7
j:0K'+
Yp]metl
a|vLg5
xDCeU3#
7!j)L[
JD.MH\
Mayg*H
6W<eu-b
C$gfd?
JKm$:_u
IsuzBx
]S?s,k
>L*hpQ{
CY(J;'}s
TRuHu-
Cvx`a|
:'M@-X
0]sEJ)
:Lzqw9J
nj3gT]:
S!Gf\q
5]U4iF<TJ
Pa/wB3
]^zq;xp
B7JK(=
cuNrM?
9<2$;(
X z1gX
A3$PQ<
i6m?iU
npwU^A
4#jh;q
vKmvl<
AH7@X]
;fs2r*
s+[0"?1
lgwq+A;\
K nQ_%
{WVEy:
.l1;eu$pwY
Z/CH,Y
B_)EbT3
XEnbOX
^m3j`=
bI9I1^
@Oef-/4
v*OF{w
c][L F
_/{rIW
h>Yly.
v13{UZ
]VEtAv
x7P&E@
[zKjX*
b"n:Mg
^pES~8;
{3gcSM
SlL30t
uFmAmh]r
!g6*)o
pW(Ym[E
h={giY
>~7Sl(
`D6C-4P
#fzj?W36
w%A"U}
\bgBB
f{&eV]
F-xqI
#&/;b"
Oqv[p2=
2LB(Fc
X]5`K_
dKw4NZ
?cAV3*wG
6Rno^`tSG
2%n\\C
!\tCTALl
'_9Wgw
iO&m S
@oldKi_;L
O:aW_B
CM,;VGP
5(E!^Q
G0t8<xX
M!?Nb
F"d)/
c6UP\QsE
uow"yg
U#)'>D
},dMr<
[pl<vj]A
f>Mk60~oQ
%x5sr8u.
t/LE}8
q GAh&h
M+W--m
dA.1|?V
23ZW-;
&8F|Q#
uh]+d0
Ax76Cm
r3:q&o
H"^sqU
<w7{kC
<^6#\dR
UE-x7s>
M1)"3&D]
K*N8Ip
YjmpO[\]
:\%,A9z
:69}-6
gOIjfd"0
vT~@$J
oiY/^0
Zc7\a]
A~>BC?Dp
HfAdF9
eX5acp
u_W?n
&2@rn`g\;
U+&h%3E
,ft`}O
6WoF<J,
FnifEP
tposoL
8>wo&9
pVdaT)X
3U.k>f
0I+-Dk
wi_i4"
G'r*]58
AO 8pKi`
0LcwxhQ
ClQN0+`
=3JE`AL
*_HX/Y
Zl4W,_
rdVZ[c
RN2{)5S6
&ta%c!
#sDG?lZF
F0*((&
fXXs~iQV
Q1YyE4
|DS#Mss
vXsHDk
}5r# v
'*?|b
p5h0\0
F8x%w*
jttOMP%
pcJvZ)!a
w>%x'^
:kAqD6Q
]ZtC8r4
t6P{1o
Z4K5gp
on-Kx]I
&|?n?e
fT?XWn
@:GmXswh
{Z#<9@am
FW4jE~
"]D1XG
Bqj$l;
+sc:"-
0CwZC?
(Ubdx8
o>@f"u
'HDj}M
O=)N:
(qZK(+
:!#C:^*
DIfln)
lo_I\.
6Zq0=NH
,i%UOC
i+ 53s1-
N,gG6xe
)fGdZu
WacZ2E
8&EoI56*/
uO7+dtoh
+ne8y^
c8=X1@
KkB0pMD
8LSiGU
3W+s0c,
H(U<VA`
NC<@ `
5eCC$M
xjk}L./V
SL.]J#
iPl|Q=
0fGl:Y
>chjXrn+
C@U%n9(
KM6M#
7K>*4X
}}:}v\m:
.<>{CZc
riU%5w
Mmk`YY
z]>Q\ v8dW3
4^c2cr
b~mn)agA
.a*YT3c
\VccS@ti
wtu~1S
Cml.-n=4
A:K`8LBD
lsQjC`
6-\=V#
Rdzbc$DK]>
Dn';Y|2
l&:Vz
q<&5.qeS
L|U~at
Z5oj}N
0dkR[^T
-z\/P 4
3BiR%Pt
(9v*'A3
98t<Qx;
=yB6n~
bOl'r;z
|HOG=OL
sRYpCb
1-eG2VZ<
Yto~?d
E+Qz;N
aYYR/
ZW*_t^
J\-z"1
Mm+J1
g|H68w
+9)/=[
7|C9A%Z
Y_A1+G
C-5Zt^y
S{>'&L
.1K2I
@h~HAJ
c/=xGZ)2
+0=,ig_P
b90SlR
y{e]Euh
GL[<7l
TrO9EV
)oAJE1
,QnN=Zts
3c_(:{5
gUyOms
\e_J4TG})kV5@
|>b'xg
Tn'[W=V
@[lLj
(EPo7q
(EXx3^m}
4TmdORG
..Ed9@n=
T'Yfm>:l
ANgxVZf
BjTL!0D
jhb6^/
<K'bBr
Zge}jN
v,zn/l
O_JFPA
e{[UTK%
o*f!$D
Q#R{vQR
t"!(I-Z=
|tLG;y
6nBfF4)I!
u$k5H0
DZIL=)
%M~q71z
r8$jp)h
eT#lmn
uP&vi"R
i+iD2q;.%
(_di[I
y#XKS2\
>Mjjn/i
bthrdm
,SLn>m
stSi h
pK$JJ@
s[LZrW
|>qf{W
icGZ<w
6Zq>1IYM
\w` ZE
#kTXk`
7%;n2)
*aMg20~S
xL|.[j
KnW9$y
=X'E%
HW[3{4
j0AS]i
{@`|yI
}j:U4
F1fcz_
;t?h':
's"g:b$
4>\DkA
7_eV/F
{p'x6fm
r,3'?7
0wi}=[zZQ
W~;VR*
l}\]F)
JF_:*f1
}s!sAZfr
"b?o:[
% 8{ls
@7&iTW<>
?^V]7S
GB&t-;
8WA[/2q
f6Edh5
Rn2OIC
W6p?s[6
/!3GUQ
n_=pux
PhG8I<%
;!eTy>{
Nm0+=jei
mcx@"IM78
0Jy:UR
K&h'Jv
$.]jff
[13qdh
;bUDkH@
\zuJSk6
J&s!es%Z
M'`niN
;?VJ34
j@A5 .
\/>sWJ
=g!$QV$
yK>'$NEg:
\Tbvr1mZ
\a;;P7
+C^Ps
c"1`pdm
3+<KrJBrv:
J70t&7
d^of~1
.Z}-Kg-f
8<d{Mx
Ck<?0'
#/z)x/0<l&u
*UQjHu
b ,q/o
}n6g"*
BD3/g\
c+1r(l
GdhP{x=
%V%g?!
=uMG3:
&m"=u*
$K07.+
6pG!&P
NLZZNO
z6^%}Qyu
g}7@nwB
p@G{U-
zgvP6*
?*NAf<
&yZ>c}
)Ky/TS
^K/LY;
R9$9.A
fe7!vn
_4af,
nOs]l%
0C7*?pxp
fQ]Ko-c{
eZm:+`@
R?3vH+ZX0
bvlCcu
;CvAKw
!+!.xxV
j:S=&M
s?n0m[,
{hM>?q!
[.s<c#
\|=Z[x
)`^PJP
boo!0 1Q`
[22b$MX
'?G@|0rp)
)w=6O-?
=PzoM:
p"pFhn
jAt<;K
hB/m9:\
jLa3c%
U{"m,@
,70vWJ9iZ-
}?=V-Q
haPu'f
9c}KNv;
/t+/PftK
E$.Suo
[:j!UFHoB
@#r?Z_
[UZV~&KP>#A8k
5WCrB#x
l,IE:*
PYqxrWW
c0~(vor
x.pM$b
_w#HNM
7$PFnM
uStG
<Y+!+Y
l GM4)y
Fo6:-C?H
'RC_w/
#m#Yld8+>
-.[l?H
"]5s{Q
Ju xN$
wt2V4S
R5D%D`F
0`L=$
)!`ZOy
`WRn*-
~y{y0
xQ<9;W
r>9-cK
V>tMPpVt
&)|dj4l
`2m(%[
STW5y,
jsly|9
mm17!o0
#^@@/'{
}bkb24
M"j9OQv
GD6p;O[
&#S[;u
b ]?9Fo
-!z4Je
`Q@]sA:
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
tonelotali
kernel32.dll
LocalAlloc
VirtualProtect
divugezenowuxeg fowavaxafarilojihulinemeyoha nalowexukosugulomebemogudoxezi
C:\zejutadifol hilo.pdb
EnumDateFormatsExW
WriteConsoleOutputW
InterlockedIncrement
GetConsoleAliasA
InterlockedDecrement
GetSystemWindowsDirectoryW
GetEnvironmentStringsW
GetUserDefaultLCID
SetEvent
GetConsoleAliasesLengthA
GetConsoleTitleA
CreateActCtxW
InitializeCriticalSection
GetConsoleCP
GlobalAlloc
GetSystemDirectoryW
GetFileAttributesA
lstrcpynW
SetConsoleCursorPosition
HeapQueryInformation
WritePrivateProfileSectionW
IsBadWritePtr
GetModuleFileNameW
GetCompressedFileSizeA
CreateFileW
lstrcatA
GetACP
lstrlenW
FlushFileBuffers
VerifyVersionInfoW
InterlockedExchange
GetCPInfoExW
FillConsoleOutputCharacterW
GetLastError
GetProcAddress
PeekConsoleInputW
CreateTimerQueueTimer
LocalLock
GetConsoleDisplayMode
EnterCriticalSection
SetTimerQueueTimer
GetLocalTime
WriteConsoleA
DeleteTimerQueue
DnsHostnameToComputerNameA
BeginUpdateResourceA
GlobalGetAtomNameW
WaitForMultipleObjects
SetEnvironmentVariableA
GetModuleFileNameA
GetModuleHandleA
EraseTape
EndUpdateResourceA
ReadConsoleInputW
FindFirstVolumeW
GetCurrentProcessId
AreFileApisANSI
KERNEL32.dll
RealGetWindowClassA
USER32.dll
AdjustTokenGroups
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapAlloc
GetModuleHandleW
ExitProcess
GetStartupInfoW
WriteFile
GetStdHandle
DeleteCriticalSection
LeaveCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
RaiseException
RtlUnwind
GetCPInfo
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
WideCharToMultiByte
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
pasafagi.exe
@GetAnotherVice@12
@SetFirstEverVice@4
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
::m^r^
N86}|55
@J~c(6
@?}7/+
.LT}p.4z
?Ua|w+&
?ajz|20
%?9{l##
\h}sz}
<VauK15
'MOq?1H}W
%WY|E-8
X[yzN>
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
00Drrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Crrrrrrrrrrrrrrrrr
rrrrrrrrr
rrrrrrrrrrrrrrUU2
$Urrrr
rrrrrrrrrrrrr4
rrrrrrrrrr
vUrrrrrrrrrd>%P
rrrrrrC
rrrrrr
rrrrrrqe
frrrrrrr
mrrrrrrr
RWR~~=
Llrrrrrrr
rrrrrrr
{y0rrrrrrr
rrrrrrrrr4
rrrrrrrrr
rrrrrrrrrr
rrrrrrrrrrrrr0
Drrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
WT*UrrrrrrrrrrrrrrrrCbb
rrrrrrrrrrrrrrrrrr
Urrrrrrrrrrrrrrrrrrr=R
>$UrrrrrrrrrrrrrrrrrrrrrrB=
Urrrrrrrrrrrrrrrrrrrrrr
Urrrrrrrrrrrrrrrrrrrrr
lUrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
0rrrrrrrrrrrrrrrrrrrrrrcI
rrrrrrrrrrrrrrrrrrrrrrrC
e0rrrrrrrrrrrrrrrrrrrrrrrrr
b0rrrrrrrrrrrrrrrrrrrrrrrrrrrK
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
^^^^^^^^^^^^^^^^^^
KeF^^{w
^^X|-6
.`v^^^^A
&^^^^^^
^^^^^^^
^^^^^^^
^^^^^^^^4
k^^^^^^^^^^qS
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
*Qp; j
kFKj18R
4YkC(v
U{{'7MuQ
4k~\0c
1Lc;"v
/<kA,|
{6d~~Bl~Z
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:v3="urn:schemas-microsoft-com:asm.v3"><assemblyIdentity version="1.1.00.00" name="AutoHotkey" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility><v3:application><v3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns:ws2="
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
kadezidanoyefadurumuhafugogemako
kuloxosigolixilaf
wukacuno
ribaxodekuhewem
Zaj sozapubujobih%Nocisi wito bud yaronuba rajometavokeADepavisapuju ravexemacehazas buvozekurutahe joju harahugepaga nov#Wamexuyacekoz dafecitis hucuhejudelLRapuhapuwokeni pilenisovedo leh viruwecuyej gifariza bimemecofocedor nukawocTBavenebihixa tusayezejifiz tetasodedowaf rizovukuyami xaromupo kasizelox razicomemox?Xibusejaxutuhix cupanigaloxul sufetugijeyod vukuwuneveki yatuvo
Xeposo,Zabe zuciy gexevezuxusaz sowa yen zerodesiru
Keyixubuto
Zozacux gopimicuhojah wotani#Dapavabasuto bedufab dolu fihusujer$Busavuy nuloketapig dicagad sem tovoJHadupuherino nozuhunetob way cufehuvejo hegizulexege yoricitag gaheceyezoc
VS_VERSION_INFO
StringFileInform
080564c6
InternalName
sagzmeoleke.iwi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.21.22.123
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.b6b054b0a63ed8e8
CAT-QuickHeal Clean
McAfee Artemis!B6B054B0A63E
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
CrowdStrike win/malicious_confidence_80% (D)
BitDefenderTheta Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMDM
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Zenpak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A + Troj/Krypt-W
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Emsisoft Trojan.Agent (A)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.Ilgergop.UNI2RA
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPe.R426948
Acronis suspicious
VBA32 BScope.Trojan.Glupteba
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Downloader.Win32.Zurgop
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.FJEX!tr
AVG Win32:DropperX-gen [Drp]
Cybereason Clean
Avast Win32:DropperX-gen [Drp]
No IRMA results available.