Static | ZeroBOX

PE Compile Time

2020-08-05 12:31:30

PDB Path

C:\mani.pdb

PE Imphash

2fb51ab3c5f5a75e2a51c3be9bfc585e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00057b4c 0x00057c00 7.96874284079
.rdata 0x00059000 0x00003bbe 0x00003c00 4.50063737029
.data 0x0005d000 0x0194c5fc 0x00001e00 1.49131318065
.rsrc 0x019aa000 0x0001d1a8 0x0001d200 6.63365493088

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x019c63b0 0x00000468 LANG_ICELANDIC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x019c6d68 0x0000043c LANG_ICELANDIC SUBLANG_DEFAULT data
RT_STRING 0x019c6d68 0x0000043c LANG_ICELANDIC SUBLANG_DEFAULT data
RT_ACCELERATOR 0x019c6890 0x00000040 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x019bfff0 0x00000068 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x019bfff0 0x00000068 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x019bfff0 0x00000068 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x019bfff0 0x00000068 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x019bfff0 0x00000068 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_VERSION 0x019c68d0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x459000 GetCPInfo
0x459004 HeapAlloc
0x459008 EndUpdateResourceW
0x459010 GetCurrentProcess
0x459020 GetConsoleTitleA
0x459024 WriteFile
0x459030 GlobalAlloc
0x45903c WriteConsoleOutputA
0x459040 lstrcpynW
0x459048 GetModuleFileNameW
0x45904c lstrlenA
0x459050 VerifyVersionInfoW
0x459054 GetCPInfoExW
0x45905c GetProcAddress
0x459060 PeekConsoleInputW
0x459064 GetComputerNameExW
0x459068 VerLanguageNameA
0x459078 GetLocalTime
0x45907c LoadLibraryA
0x45908c VirtualProtect
0x459090 FindFirstVolumeA
0x459094 GetVersionExA
0x459098 ReadConsoleInputW
0x45909c GetVersion
0x4590a0 AddConsoleAliasA
0x4590a4 EnumCalendarInfoExA
0x4590a8 CreateThread
0x4590ac CreateFileA
0x4590b0 LCMapStringA
0x4590b4 GetCommandLineW
0x4590b8 SetStdHandle
0x4590bc WriteConsoleW
0x4590c0 WideCharToMultiByte
0x4590c8 InterlockedExchange
0x4590cc MultiByteToWideChar
0x4590d0 Sleep
0x4590e8 GetLastError
0x4590ec HeapFree
0x4590f0 TerminateProcess
0x4590f4 IsDebuggerPresent
0x4590f8 GetModuleHandleW
0x4590fc ExitProcess
0x459100 GetStartupInfoW
0x459104 RtlUnwind
0x459108 LCMapStringW
0x45910c GetStringTypeW
0x459110 GetStdHandle
0x459114 GetModuleFileNameA
0x459118 HeapCreate
0x45911c VirtualFree
0x459120 VirtualAlloc
0x459124 HeapReAlloc
0x459128 TlsGetValue
0x45912c TlsAlloc
0x459130 TlsSetValue
0x459134 TlsFree
0x459138 SetLastError
0x45913c GetCurrentThreadId
0x459148 SetHandleCount
0x45914c GetFileType
0x459150 GetStartupInfoA
0x459158 GetTickCount
0x45915c GetCurrentProcessId
0x459164 GetStringTypeA
0x459168 HeapSize
0x45916c GetACP
0x459170 GetOEMCP
0x459174 IsValidCodePage
0x459178 GetLocaleInfoA
0x45917c GetConsoleCP
0x459180 GetConsoleMode
0x459184 FlushFileBuffers
0x459188 SetFilePointer
0x45918c CloseHandle
0x459190 WriteConsoleA
0x459194 GetConsoleOutputCP
Library USER32.dll:
0x45919c ClientToScreen
0x4591a0 RealGetWindowClassA

!This program cannot be run in DOS mode.
`.rdata
@.data
u+VVVVV
VVVVVVV
PVVVVV
t"SS9]
0SSSSS
teh*M@
HHtXHHt
>If90t
>=Yt1j
QQSVWh
j@j ^V
0A@@Ju
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t+WWVPV
URPQQh
^SSSSS
j"^SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
-eSx5LA-:
D0Wk]EN
f2X~+7
n-C0jF
m!>!^'>
)x9xNp
l n6l%Y1B
v 30X2
vB4q]X
c0f~'y
7c@+J:<
-FFMc`m
xNF;2:
qYNFx9t
K /XrK
Cv'}Wu
-8r3qG\
oql+gi
FR:1tc
7hC,)HV
If9)3*'
[bvxa^%A
QA2=X<
Mb]sL9;
dFE\&5
Kk>B7
1<Ryz-h
P 5LaZ
*gR&qF
%BHTS5
8^vh[}
okK?oX
4yZhL1
]Ix)J'
Oh&SP
|[U$5X
.f|H`
{0 []D
#$bM!2*
G`@"Dw%t
mSaNOr
y9qcz)
sc_ObG
RgP/Pu-
E.{l)L/{
^@>fp:
T0N#o?
frBh2p
lku$ge
W%\qF*3B
dQ_oI.
kiHL* 9c
DgSUX]
PO9='R
`6/p+::
&|m)n*
29kynK
+lVj\-7
fJc4O:c9C
W@'=.
Fyz}5"
;:XY~M
?BcUwO
0p:),`
D+}QFH|
[wI];*f
J6o#iD
u XE=>D
Je*W%Y
T=RF%
^}A6|Q
Z&{I.QeS
/__mmtio
Bbz<X?
e#r6&:
DTo?+z
SNvR$b
(%h/<R
~,ZHL9
~c,#/9B
vHSYO
7vmiH/S{y
={F`g(y
1(saUb
ur7BiaN
&)9C@6
V@HE>#
\Ud~41
pr{^`Y
Qf{-v)+
ZV-\Z
365}^_-
\/32-nY
PWgTzr
24\xtb!
Q-0Cq-S
1f)Ho{M:
Nt{>S7
wI YE8Ec
FZXe:^
n<:gw6?
7'zGFN
-9o]%b
"wC}hxd\
l`$6rrnn?
0B:~<R@
H_tI`'
^2_)&OO
fYXST]x
>BPGpdF
6NXv"]
epM::)h
07o|{B
s0iup2w
zu44`[
>S?K8UX>
UY# }WR\C
<~RPb9
tKi|E*
72e 8m
\Z(~f?3
0zK`f<
sw:i!=
IDS,6A
o?8R>x
R]R`y1p
cU4owf
{fc73A6
49h~]Q
]yB1`4
$ZTz5B
XGU:mm
|Fd"G]
c74Om^X
sh21R'
`BtS&.
FM/YLv
^|ry'BHy$a'
)AVg6O
EeHy>/
pM>E"w
YPwzMC
4]YX0n
Xr^EpA
?1y{jO
f4K[\)
D4dBzC
$#0eZL
4?oV+}
01Sf'Y
-tHI77Z
iP\H_JZ
5*]&=I
KYo[q?
q>(B<F
.hF&`V=K
V@p*+L
b,QeKo
(3ZQ0`
#D}6Z/
X;}^Fq*
-C'`_~
[+M n$
5fUOs1
34jJJ,Y
LvcZ2J?~
cn'oe,
=M3AXym
q*z\`
H/WZ(d
b;RA6y
jnPh4'
cQ(\iY
+=6#c82X
XlY:N%
%,v^J%)
c+yPhL
=0!j*>
+>,fj}
:|G<2w
li4&(Z
ykPch3
/Bgf_cQ
Dqk5,1
kF)pvN
F0kaw{]H
9{24Tr
v(VE`!
eLxJgqW
$u0-:z
'dNB/
C%..c?
BIBUnU
{AzLllYk
:\Wv{(Gc
PB$b[ye
c~FH_|
;~Ch(p
o6Fw5
Z*;Lvg
Q+%\8J
s@<,it
0X&:`@{+
^aCp%Q
Wc]K3#pWC
!=(t]m
<j*$l4
T_kVjMlX
kL2Ehx
:e ,"3V
ta_<ME
$8^F]m
Q3v|Fi`^
29ZGvdLJ
-}~{|/
>Ad Pd
J<-zb&
y_5$7GC
YM =<N-
q=TFe<ba
pQxq\Vuy
:fn4v)I
e7E9cK2#
_h5hX6 K
/*gA5-
r~>+9~H
V5vAM*
sby@O92
E~\ FKg
ZyhUW,W
&\@Q&x
)/N{[L
,Y}mt<o
tzpS9i@
Wmj6e;
Q2R(,:
(Mm30YI
;Xq+I9
Q+5:|^
~B!5rN
TxoGC+
S;[5,v
5^V.i+
-ZmW+b
z!D'QVuild
`zlrIf
2VlSny
|K"jnG
.?8T\r
E>JpRV
\IMy}p
n$q,;h
dd0!.-@
R*Br$^3
q6&4{9
+yu?>
?x#t4/
y:NJV4(m
yOuHYZ
sf-QRx
2*$TGd$
)zF9CJ
6Hvj{l_
Gn TVoA
{8\{r^Q
={INAw
(rQ/651Zn
AH3O&Ks
yx{ko*
*rJh6G
&i npm
gb>*+ro1fO,
*tNZGX
KHA=F
1_VMi1h
,a5Wo+
14F!u@
M^P#Z_
$s@cS_H
\bg3m<
Ei3HDK
?T4%4b=
J@!KXF
/C~R*b
G{,Dq?
JBnp7]
phgjTS
7%|=WeU&&
=E#Q}v/
;`U%p\
<^:TiVd
$Z\_!R
()M^~[$
Z|I#yK
zb4Fq|
^5>]j3%
[h|1l0au
`0Gqx&iT
G9b8!}W
ow^'9pnw1P
WUi}-o
5WNVf.c-H
n:s<*iu7
J3td97
?lcYP7
-gM,V{
rWH!Xt
$u,z8(
E'zrtI
*Y_ ~m
R_MQ)v
+[7=waY
-q'l(|
6&#`i:;
aS4b?`
0i8G_biXd{
ttoO|&
&_Zz=H
|wr_--
nTofj*
=64*@
?s?bx(
@ke,-d
|9P&{@6
(pSzMH
d>C[txv
tt&69/
Z!Zob3
gs0+N|
L*hTWnk
*Shnd5
Iw1rs,
VwusbT;
CQ'CCEJ
[`;A^2
;1",/-L
F-&*xCr
b<9`Avw
Ggeg=kc
v6Rnrs
Dx9ir[m
2t=QJ`
$F6#ys
BA:,qV
1l_1k[
Sex60<
AwXox3
$_f\;c
kx$CMZ
elF<1(W
l<q{7!|
yev28f
eI%ZsG
4nhtyW
8h.DM^$;
<7|!o0
~(*?;]h
R=$WcKA~
c,^wD~3C
*qpwf(
}rgtVeG&
\':D3o
()Ea^6l
/ Kic%,
MZDNU!r
osncZ[
STrx[!d
1Jd|R*/<
3V%lxy
*f-tC/
97 v51
*s0CoI
?3vPrN[
,-mYou:
Vg`YEd
3TNz&+P
V%$j$U6
c^JqL,
El);zT
o(xMt|Af
9BInWJ
{":1J'
D}Kq>l2'Y%
7?iPJr
d}VhMa
Q@jT*d
mu5-nH_b
j[+pXz)
19=x*5Bj
&@@hy
C@nv]\
6ML`)KY5+^K
FGdS>F
S9{B=U
.v~X%
Dw~ara
O(C<@o
xv56<b
`B$ueXM
$Q:LRl
r6=r#-
#8Ev=q
?KJz=B
* (xmV
)1#@l5u=&
qR[dI,1
{_E5d45
@Aj-8g
#DN5DS&
C.aJ-DB|*
;V~UyB
rWIx\9`
)hfb9U
~}62GY
B`ge^f
"s=<kI
*d/DE-_y]
y~Ynj
Kc6$!jB
?;O=UnS
L+o)>#
7h`;oM
=8f|*?
z&o\.&
MlR0/x
Q4v.{_
t?Td7_
#tpVJ6q
/uC&9"
IUj"De9
ivR}"bWD
]%wTc{
1lS<p
^'w=$l
?Skg>C
y?Wjl`
2pabs[S
jB kz%.
0jq;mG
.xj*~
?lqyV;
%[@9]*
K#~-]YHx
ulA W~
rq#b+F
AuAIg
sw3q{n
F52cW9
&8WZq(.
gP718R
`aJf8?
Exm:8
wVFN3[#\5M
ws44Kgt
3P&PIubV
#Bw}m^
Sv; '8o
SH=ltiq
{PJxFE%
E2P[=p@s
wR;.\2DP
Z"<TU,Uhcxn
`\qb6w
AA+i8M>~*
<!XnwPN
'q_?d`
@o$(s!7
AEk9?Q
.z6AJ9
9WPHUl
6z1&96
&wP5?i
Pj(da>
6<n!1W
)bGO./}
J0D(p3
8"I83F
Nsj+B9
|rBAAT
[Y{cuY
#E7&w(
kK*Un
@qb)70
,E<A2"BryS
9:n-1AeU
NfAu0X
]w.&a.
nt7^]W
Qp`BlI
(B:k2D
*g]+ k>o
w'1f0=k
!9NQyc
AR`lbZ
=T3rqWk3
Y<"@n#?
P=eBdUe$
v`P>!#
X'S~96
)V{1|U
bvxnAs
td>4Dz
yT7i&
(w|?0\
QQ@<Fd
@8]7n]
?9 MB-
vg/xYw`sG
/4?'NZj
UL&e67w
g-V+GY
Q;>]TGM
+%}F.O
dzT/PP
F|>6tw%
1ig%>N
Nzw9_WU
Tx>s0H
rRki)u
Z6lQN]
TTE{H'
N6]X1)
<>aY2{e)^
m}t$rR
Kz1_2
cOOT*=
w])Q,
{{WGfR
lKw,$_
/J"KUN
/J=ple
Mo?#<j
x4T'zh
30A#jp#
{RdU]'
II:mg"
S4=/n)
{AFguDlVC
Qf*Oq
0~CnK}
Bs!5i2C?
-UN1~jN
n:U6-t
~[:H*H
`l-%Js
k[U:&sb
%f9Ak{o
;/#<+q
H@H0y?
`lNTpsT
S6LkaA
@7EC|_
BArBGl
-L}c,OyL
UY_:P@
Z0#/sX
P/(6jV
Elv@Hx
*V'3g4S
b!Q:eV
g1Wk.t
83yz}N
\2&E[.
w,;2?
fza(R87
)7'wRC
5Rn dT
V3J#DR
dK=a'Q
j&u]z3
QXtv#74o
NH>h8(
ft->eW~h
q`Xmc8~k8Ynq
sHmyb(
gZ]X)]z
su03K&
J|y|BO
n?l//zD
?>:*H
rR]Wy_
bad allocation
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
pebemosigonuzohosamixipefofukixohezizecigavuxexarudekemijihevajoze
napede
LocalAlloc
kernel32.dll
VirtualProtect
%s %f %c
runexobozez
C:\mani.pdb
GetCommandLineW
lstrlenA
GetCPInfo
HeapAlloc
EndUpdateResourceW
InterlockedIncrement
GetCurrentProcess
SetEnvironmentVariableW
GetEnvironmentStringsW
GetConsoleAliasesLengthA
GetConsoleTitleA
WriteFile
GetUserDefaultLangID
GetEnvironmentStrings
GlobalAlloc
SetVolumeMountPointA
GetSystemWindowsDirectoryA
WriteConsoleOutputA
lstrcpynW
HeapQueryInformation
GetModuleFileNameW
LCMapStringA
VerifyVersionInfoW
GetCPInfoExW
ChangeTimerQueueTimer
GetProcAddress
PeekConsoleInputW
GetComputerNameExW
VerLanguageNameA
CreateTimerQueueTimer
FreeUserPhysicalPages
EnterCriticalSection
GetLocalTime
LoadLibraryA
GetCurrentConsoleFont
WaitForMultipleObjects
GetDefaultCommConfigA
VirtualProtect
FindFirstVolumeA
GetVersionExA
ReadConsoleInputW
GetVersion
AddConsoleAliasA
EnumCalendarInfoExA
CreateThread
KERNEL32.dll
RealGetWindowClassA
ClientToScreen
USER32.dll
WideCharToMultiByte
InterlockedDecrement
InterlockedExchange
MultiByteToWideChar
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
HeapFree
TerminateProcess
IsDebuggerPresent
GetModuleHandleW
ExitProcess
GetStartupInfoW
RtlUnwind
LCMapStringW
GetStringTypeW
GetStdHandle
GetModuleFileNameA
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeA
HeapSize
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
CloseHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
7\CT:;&
XWxtF7w
TpFWrr
NXXrtX\
x..&jL
erH33b
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
66mbmm6
))))))))))))))qm
))))))))))))))
)))))))))))))
x)))))))))))))6xY
)))))))))))))
2Ta|2/}I/
))))))))))))))
))))))))))))))
)))))))))))))GP
)))))))))))))
)))))))))))))
)))))))))))))
)))))))))))))
)))))))))))))
)))))))))))))
)))))))))))))f<3
)))))))))))))f
)))))))))))))
)))))))))))))
/+)))))))))))))9h>
)))))))))))
c))))))))))9
))))))))))
))))))))))
))))))))))
[i8`0y,
+))))))))))
))))))))))
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\
\\\\\\\\\\\\H
\\\\\\\\\\J
\\\\\\\\\\
'!\\\\\\\\\\
Q\\\\\\\\\\
Q\\\\\\\\\\c
!\\\\\\\\\\S
!\\\\\\\\\\
\\\\\\\\\\9vo
k\\\\\\\\\\
\\\\\\\\\\
\\\\\\\\\\9
n\\\\\\\\\\c
[\\\\\\\\\\
\\\\\\\\RfE
_\\\\\\\\H4zsF
[\\\\\\\\H
\\\\\\\\\R1
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHE
HHHHHH
HHHHHH
|HHHHHH
HHHHHH
HHHHHH
IHHHHHH
HHHHHH
gl$5HHHHHP
HHHHCm
HHHHHH
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
t<bB*O#
;lQ7g7
D!usJL
xt(}`N
''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
'''''''''''
LQ''''''''''8ur
oi'''''''''0
!'''''''''')
'''''''''''''7
'''''''''''''1w
'''''''''''''
'''''''''
z'''''''''
XU'''''''''
C&'''''''''
B\dxN:7
'PVqB4F
&^`~K-6
FFFFFFFFFFFFFFFFFFFFFFFFFFF
FFFFFFFFFFFFp
FFFFFFFFFFF
FFFFFFFFFF
FFFFFFFFF
FFFFFFBSGU
FFFFFFF
(FFFFFFF
niFFFFFFFF
bPFFFFFFFF
AfqFFFFFFFFFFFF
FFFFFFFFFFFBe{WFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
~[t&~ge1
SZ'Z#<
zzL{I3
oIC3hj
J8LO77
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFU
FFFFFFF
FFFFFFFFFFFB
_FFFFFFFFF
FFFFFFFF
FFFFFFF
FFFFFFF
FFFFFFF
FFFFFFFP
ZzBFFFFFFFF
lgwFFFFFFFFFSm.
FFFFFFFFFF
FFFFFFFFFFFF
$FFFFFFFFFFFFFF
FFFFFFFFFFFFFF
FFFFFFFFFFFFFF
FFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFF,8
FFFFFFFFFFFFFFFFF{
FFFFFFFFFFFFFFFFFw
FFFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
0Tt?$o
mILn3:T~O'}
9YmG,v
Y}~):PyU
2Ne=$|
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
cccccc
??###
???##
???###
,,,,,,
/////////////////////////
3_____)_)_))))))))))))))__
3333333)
3_))))))R
3_)))))))
3__))))))
3___)))))
3_____))))
3_____)))))
3________)))
3_______)_)))
=7::xx
=77::xx
=777:xx
,,,RRRRRRRRRRRRRRRRRR,,,,,R
R,,,,R
R,,,,R
R,,,,R
R,,,,R;
R,,,,R;;
R,,,,R;;;
R,,,,R;;;;;
R,,,,R;;;;;
R,,,,R;;;;;;
R,,,,R;;;;;;;
R,,,,R;;;;;;;;
R,,,,R
o?^,,,,
&o?,,,,
,,,,""""""""""""""|
,,,,,,,,,,,,,,,,,,,,,@d,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
UUUUUUUUUUUU
ccccc,
ccccccc
&>Kh_.X
z|p()S
mscoree.dll
((((( H
h(((( H
H
KERNEL32.DLL
(null)
Suzulumitolos tafig
Bipuze fuvemahik xowagadid honupebew jakahizihu
Ribabof cufideyuhuce wem
Buvahinofasi bodideyo mefaviral
VS_VERSION_INFO
StringFileInform
020164c6
InternalName
sagzmioloku.axi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.19.29.123
VarFileInfo
Translation
>Yurocicim topahe xucasegoyebamow howapise mizijo tefegiyuwokec>Xikosi dovevifacape foxavoyemas xoze sebuwa panonuti biyoh wih
Facunoxiwot tecanefuwiETukixul fuxinipoc sopedilasumegex zivuj gamod bufun fovuboporef lorej
Tinuh hitejiviwoleFifofukob yakumayayazay tuliwozifonigop catonutanirut yeviterekoca guzisehocaf xixivafojuhey tijumovi
Himufuc geze
ACaracil zasuweseyubah lev dirihabitac caximodoza tucuhokix lunucu
Lacaxuv+Figojufata yad wiwehupanecuyi kikutepabupak
Zatezuj%Hiyuxevica hif fecevayugazaxu hetoposUZesilezilugace lewuxakopowoken sopucahugux nuk faxenit mam nama huzaxuto duvumaloyigogDuces nihojesal punumidexivu cadokesed kemo rilajoracahezu wuduwa doxekivedevej fugapavebebuf jekedoral
NexavuMWitucigunipat cicakobezimu wudacizehalu dokaju piyusa hiv zusalufezota ricemu
Rano\Hawuravewehap xonaj xasunasexebuc nida topuxohifa musowexojanina wuno cimuhu dula gehuhoture
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056d16b1 )
BitDefender Gen:Variant.Johnnie.349293
K7GW Trojan ( 0056d16b1 )
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Johnnie.349293
Rising Trojan.Kryptik!1.D8AC (CLASSIC)
Ad-Aware Gen:Variant.Johnnie.349293
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.gc
FireEye Generic.mg.4028f8bc868998d6
Emsisoft Gen:Variant.Johnnie.349293 (B)
Ikarus Clean
GData Gen:Variant.Johnnie.349293
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Johnnie.D5546D
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.TE.B!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Johnnie.349293
MAX malware (ai score=86)
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34110.Eq0@auGByeiG
Avast Clean
No IRMA results available.