Static | ZeroBOX

PE Compile Time

2021-03-17 20:18:09

PDB Path

C:\wegivivatexe64\zuy20-kowehikulah-jebireretiv-duli55 c.pdb

PE Imphash

e29fdb264def7dda465a7a289be86662

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005fd62 0x0005fe00 7.92999122831
.rdata 0x00061000 0x00004044 0x00004200 4.33230060058
.data 0x00066000 0x01d1d298 0x00002400 2.25298813681
.rsrc 0x01d84000 0x00016178 0x00016200 6.36026922683

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x01d99448 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01d99448 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01d99448 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01d99448 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01d99448 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_ICON 0x01d97530 0x00000468 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC GLS_BINARY_LSB_FIRST
RT_STRING 0x01d99c40 0x00000536 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_STRING 0x01d99c40 0x00000536 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_STRING 0x01d99c40 0x00000536 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_ACCELERATOR 0x01d97a38 0x00000020 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_ACCELERATOR 0x01d97a38 0x00000020 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_GROUP_CURSOR 0x01d994f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x01d994f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x01d994f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x01d8a938 0x00000068 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_GROUP_ICON 0x01d8a938 0x00000068 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_GROUP_ICON 0x01d8a938 0x00000068 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_VERSION 0x01d99520 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x461010 GetCurrentProcess
0x461018 GetUserDefaultLCID
0x461020 ReadConsoleW
0x46102c VerifyVersionInfoA
0x461030 WriteConsoleW
0x461038 GetACP
0x46103c GetConsoleOutputCP
0x461040 InterlockedExchange
0x461044 GetProcAddress
0x46104c PrepareTape
0x461050 LocalAlloc
0x461054 GetModuleFileNameA
0x461058 SetConsoleTitleW
0x46105c GetModuleHandleA
0x461060 AddConsoleAliasA
0x461068 FindNextVolumeA
0x46106c GetSystemTime
0x461070 GetProfileSectionW
0x461074 GetLocaleInfoA
0x461078 PulseEvent
0x46107c GetModuleFileNameW
0x461080 GetCommandLineW
0x461084 HeapAlloc
0x461088 GetStartupInfoW
0x46108c TerminateProcess
0x461098 IsDebuggerPresent
0x4610a0 HeapFree
0x4610a4 VirtualFree
0x4610a8 VirtualAlloc
0x4610ac HeapReAlloc
0x4610b0 HeapCreate
0x4610b4 GetModuleHandleW
0x4610b8 Sleep
0x4610bc ExitProcess
0x4610c0 WriteFile
0x4610c4 GetStdHandle
0x4610c8 TlsGetValue
0x4610cc TlsAlloc
0x4610d0 TlsSetValue
0x4610d4 TlsFree
0x4610dc SetLastError
0x4610e0 GetCurrentThreadId
0x4610e4 GetLastError
0x4610ec HeapSize
0x4610f0 RtlUnwind
0x4610f4 SetHandleCount
0x4610f8 GetFileType
0x4610fc GetStartupInfoA
0x461100 SetFilePointer
0x461104 CloseHandle
0x461110 GetTickCount
0x461114 GetCurrentProcessId
0x46111c WideCharToMultiByte
0x461120 GetConsoleCP
0x461124 GetConsoleMode
0x461128 GetCPInfo
0x46112c GetOEMCP
0x461130 IsValidCodePage
0x461138 LoadLibraryA
0x46113c CreateFileA
0x461140 RaiseException
0x461144 SetStdHandle
0x461148 FlushFileBuffers
0x46114c WriteConsoleA
0x461150 MultiByteToWideChar
0x461154 LCMapStringA
0x461158 LCMapStringW
0x46115c GetStringTypeA
0x461160 GetStringTypeW
0x461164 SetEndOfFile
0x461168 GetProcessHeap
0x46116c ReadFile
Library GDI32.dll:
0x461008 GetCharWidthFloatW
Library ADVAPI32.dll:
0x461000 BackupEventLogA

Exports

Ordinal Address Name
1 0x401000 @GetAnotherVice@12
!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
r= fF
<at9<rt,<wt
URPQQhdX@
tNIt?It0It
j@j ^V
>=Yt1j
QQSVWh
tRHtCHt4Ht%HtFHHt
0A@@Ju
to=8oF
^SSSSS
j"^SSSSS
0SSSSS
0SSSSS
0SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0WWWWW
AAFFf;
_VVVVV
^WWWWW
t"SS9]
v$;5\oF
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
u;hT&F
u,hL&F
%]K,hz3
(/I.je
|hVI->
?<VFQ=
N\oxpx
.<6:u
Uch-mO"@
7enHW
;wk?;@
Y5+9N4
^LCM)_
?K$BqCp-
AyRG>FV
(=N#=S
I. >Ya
j+?eIE
76;XHzF
N)?5u7
o379Og8
xU|Q_J
Suyu&(s
H!Gv`
38".j|
x3[|)^
&*3k`0
A=fl&"
v{F=!@
m*U8Hv
;/*|t&
8$TFu~
}?WAKq
eX&-]{
t`~fd:
&26-nN
jKjz@;
3=+QU:t
c`e48|c.
Lh1P\zS&&
`L"q:Z
:QlTLu
g/,DF@
!]6ZVv
j!>7Kx
FgnJfr2
/I"A>@
H#71crgE
!(Y #+
M]2Wkq7
|w_\A,5
-byj14
!mPuxQ
.B6$IX
PRW<W@
SH1d1sNr
O"pJlT
#<|g{m!8
:;'b\R
2KI}jJcy
vft.,^ !V;
A"-/=q
e="[{c
=d!#36
*7<c7S
U]#_cc
U:W0P0
St>Oi{9
^'x.aW
!&U(<t
&czXQ/
#A.rX2l
LW|]jU>
9/2UV<
-q:wK&
6wS;_:V[]LV
Znf'WN%
Aj1B0a
):gRF<&s
H6rcw-K
o5Y*EK
L^TY4ns
=4<&tn
.iVYHa)8
@_]E_L
@j9'$^
>-*f}uGs9
wUpu4V
~`2zrKf
~KgJH-Mnhc^
MvhY3L
JMNR:n
18ppo-]
c5";)Q
)xE,0<8
"nIr@J~
0Ag(HDD
|9H.=b
g_SPUp
kr/XV?
z'1l2o
Eet<nD?
RbUP4F
4@Iqf~
Ivez;$
oNX.0k
D@`:p[
/l.sEvP
h'aTM)7D
Y6:S;lY
K{${p=
74#0}kEmw4
8$nM3/0x0
";IO*^*
<[a92mb`
: RxT.
?P*gA_
-\QkQq
C|+U8f
r2/zZH
f98j`e
>pf1?(
RbTX,K
a,cyC
8|Oh9m>g
MIiWym
d3:)rWnX\
xmI_Q:#G
>~%^R7
tR5qM5Hs
Vrou_L
Z(aCv1
&bD0Qw
1-hP}(5
iX&wJS
^^BfJ@
e5tn['
Pr_"y_
?~i8Pt
\UHzXt
niR~1E
i6$?uk
332W5_
|{O-'ORk,4
<$V%Bn
)RtQz*ZQ
2Mq9n\
Ji}%9)P
+ZjbWG+
|KWi'b
1H+`>h!Y
*l?KB^
_lhedW
>q`RK{
FLrltR2
7dcQud
=Q16h.
F5C@LM
-2A42Xp
gIl/{(T
oBohUR
?:itG[
)L~>@j
AjrCDDp
,*K#t0
3I|T=
rVQem|b-
eZ&1WU<
=a,AMs`q
%pw)[5
Nw{$P&
c." y
sy>\U[
G0bPv}k
P*2%#?
;/s!]sXP
F;dtA_!n
O&puWl
vr9(o4-q
BTSB1OI
^w,Q{KO
8F4"lM
<xyvhb
;]%uXDf
3_S]-'w
lyMVX.
`e1f!bRv
Gy70>b*
xH)#t*
$&rRop
u+E,`}
sk;;EF
Zq|?1@
@lVo(v
'oP+F
pa>+\/
2.J{'y
3QH/A#O
M!j~&1
Igdug(
kXw&/W
B&f.^/
veR\y
Glc te
I\Pv$kc
Xm?d9U
aD2Hb1>%
SOAc(yGz
($>>qy
bRUZ^Op
XacOORN
By%a:8
Rlbx{#r
u>u4j
G<%T%>
-AUp{6_C<
qnGb1(
[mv{2.y
OT+>\%
1$mjJ"5ao8
uO m|G[
g_l'w;5
`wqMpq.
6'-?* K
@96iCL
sDc@f|
V/..!K
yo+g9P
?o8 EG
0lDW6{)
Ds:?Xf
7`p#:j
_RKi}6g
l)ss=VN\
60NNI9
l8X XM[]
~wqOI:
C6Q8!9
^zG{"%
IK[W|<
]a=:5 `
Nm"e})MS
H\ _|,F
=m}6J?
:9@C^A
^}L&75
CUBmMm
!\P/K^
@EL''}
9h]zoLEk
K]a"5-1
-;!RW}
z"ide
H=~>^>
%tSo>Tg
8hy<N-j
F\a}`W
Sfr_%'
:3Og/5
3m010EDX
b_<S=z
a}g}R^
AaPs7
-$JwD}Y
#AHt\&fB/93
XbV%4<q
$2]?<f
3p?{@o
+=6`7
n[bx5<
90][,4h
1%j:a.
1&\k}@v
d/X"pW
izr=[Lit@z
<Tvr{y
2N9p,4
/6V53mr
2m>@m=&Gcr
nH]+kSPN
ol?zu6SH
t>-+C6
'q9Dw^r
;WQH)
~6JW=K
=#kgPMr
IwM=K2
Onv<a,
"HSqQD
I>AJ8,
?,YYXJ
%0j}x@
=R*gNs
1#"W%m3
91F2ooj
nxOvq{
aD/w0-
eD;J6&
Rl_fLW
FLN#UO
|a<%H^
~po!;!
P*,V%*
x;!FB
2F.D[=
^UDd,s
a|)K[gL
UT?B!L
G1Xq>$
tiRBY|W{c+
xAr$!"
{zYEdDa
f3&ykC
Kz*c5m
y:pWc[
Lyjuo:
=lWfc?
kI!H|>
}"[x-
M$bkTX
umZ;'b
6\EJETcp5{
K(IvWU
Qe`a<;{
3{h+9U0
V2f.2J
B`f&4hV
KqW&[yx
*<32HB
!U00|p=
-(`3=r
wA>1Hq
U:bz_n
2vRdazs
p#RUY5
^k2g\t
'aCrjiB
1;^}u\G'
J{.LnZ
wh+ta)D
/I^Fn1
R@\?_
iz>cLz
yY+&R5
{*RZL]
-+ >"\u
3:@\$U
M1'\e
b0!m=g
87vic+
.,j}(\
r9T_._
IQD27k
r|=~xU_
7lIMN0
eOY<z.
.$0gMCV
!;n=M#
fNkTcF
]vXJ*%
2jG7>QRIo
;O7%E0
ON$F%U
8ZT"1oc*{S
pc-%h+
=-b:%L
W%R`#7
WeH)V)tQ7
|+G#<i
!aeyRk7
e54<;L
{cN}
#1'2^`
h)fsQi
Df,Es}
pm@{u}$
#bN]x:
r4$qvt
wc%0[~
<nwlht
RM,=<7
D< L;E
wkvN i
]mf4zM
54T..=
`C<jbT
YICKu&&
+b" }W
8.}4/{
'C$6&Z~y
&:C<3mmA
leslc>
;}sZBs
#,ia/8
QNW;{)
RC\.E
Nr t3_
$3-Ew+?
Hed)3"
0 \\{o6q)
RgIq5!I
18gvl*
/7'{wz
01Y:AB
]9./Gg
[7snGh
VWLuk}
/<\#:!
|H ORz
iTL>=c
E@P7Q
}6Ci*M
K@lW'/
iOJk3i
pic5[<
x`l%wf
0)kZQ~y0
Y}QOO(
G7}4Y`t
Jiz}~n
JwYNx%
>XZ.">
Fo&ogu
"1M#.<p
?KHJ}~
2LY9sa
wEGojV
'Yk*4&
h}?Cak
o1zdlb
zri,.,
GnI=RU
WbC!Es
"Y"%w
lv&xHA
-jpk_0[
3d7o:}
tLfUQc
)Gf`8h
A#J?~%
=;4Hd*
#0i\OC1
"X=qud
1'[aMO
?M u-x
qRW.W
1Tr_4|
O%/{d1
hTlJI!
w`{1nKtU{l
U,vwB>
/hz95h@3z
{oy$;Kz
A`4?t~[
t&d5->
o4qDS^
j1?e@}jQ
6Ges?F3
lT}O4z
<@oPV#8
#qiQl
in]>r4
"^SeoE
s1<=2|
+@2_)#"
NhYB3
LP"iW{8
Jm9HE
cyc"z4^
9W7*V/
0@gG~f
wJQeAI
Cb\rg
k6uDcZ
"+&ArV}
W+>SgRJo
bpsoNf
.?q!B.
n {X8nZ
!h-Xvz
^OKmJ|
e}4ddwz
RH@wkP
5/,H)|
#}(B!F
FC)<U5?
J{B"\a
T9IV.l
,R:Z":
t|LlOn Z
fk^cp9
t_U)?
P-1*lO
{Rz:W#)
`xq(Y\
4<"I!u'
zQ!rll
Pon;\aKhTA
i[yl(:
x?B|@Ff
sUrN#h
|a,Q:y
j^Uz@c
)pu<v
aBARGR,@
8'v%d-
%4D\`T0q
Ed\Zw08g
BkLG6
"'`y$.
:p:n^j
G.{+kE@d
%6 V}J
4^~v/0
6;qS: 4b`
@Sp(0]
t_;1>9
*inl|+
)r=t3p
g`-UcX3
3'_4KC
s[|Ew?
"sv)Ee
d gV&#
{$K_za
seJh2a
cOP,C(
$Cta~g-
j9@yaS
lLYDET
Kr~~Gis
"}(Y@j
\Bx%i+~
$#4Jv&\
bs!EE8
1=(dgqB
,Y!H=g
Zy+:DLr
cii$<m\rd
(8^ -j
qja/X,:
0@)Fh,_w-
(=VTc:Q,
)4U[CS}N&
}<xTIOD
7fiU\_
g*`dl4_
F4!#GDM
@PCoi
wrI"B0o
<65NBm
mkgxy4
2oK>Hz}
-pvW=Z
lFL4.i
^cvS}k
u;/@)`a
+O/Uks[bs
{eGWj1
mTde^
vTo"q,
@-KnSR=
H{bo{B
[Mq%4%
Fl/Zu
=8Z=`T
Yp~W48T
cMIUL<
,A8u2X-
M@hlo>
6$K$)~
|WmeCI#
aY%sY"
h;t$Nh
Ss8AD
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
UTF-16LE
UNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kernel32.dll
LocalAlloc
VirtualProtect
bad allocation
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\wegivivatexe64\zuy20-kowehikulah-jebireretiv-duli55 c.pdb
GetCommandLineW
PulseEvent
GetLocaleInfoA
FindActCtxSectionGuid
GetCurrentProcess
GetEnvironmentStringsW
GetUserDefaultLCID
GetSystemDefaultLCID
ReadConsoleW
GetSystemWindowsDirectoryA
LeaveCriticalSection
VerifyVersionInfoA
WriteConsoleW
GetModuleFileNameW
GetACP
GetConsoleOutputCP
InterlockedExchange
GetProcAddress
EnterCriticalSection
PrepareTape
LocalAlloc
GetModuleFileNameA
SetConsoleTitleW
GetModuleHandleA
AddConsoleAliasA
FindActCtxSectionStringW
FindNextVolumeA
GetSystemTime
GetProfileSectionW
KERNEL32.dll
GetCharWidthFloatW
GDI32.dll
BackupEventLogA
ADVAPI32.dll
HeapAlloc
GetStartupInfoW
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
DeleteCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
HeapSize
RtlUnwind
SetHandleCount
GetFileType
GetStartupInfoA
SetFilePointer
CloseHandle
FreeEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
LoadLibraryA
CreateFileA
RaiseException
SetStdHandle
FlushFileBuffers
WriteConsoleA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
guvahimuzu.exe
@GetAnotherVice@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXX
JXXXXXXXXX2e
XXXXXXXXXXXXXX
XXXX2e.
XXXXXXXXXXXXXV
oXXXXXXXXXX
XXXXXXXXX
oXXXXXX
oXXXXXX
goXXXXXX
XXXXXXX
gXXXXXXX
CeXXXXXXX
XXXXXXX
XXXXXXX
LXXXXXXXXXV
XXXXXXXXX
XXXXXXXXXX
4/`?`>-
XXXXXXXXXXXXX
XXXXXXXXXXXXXX
XXXXXXXXXXXXXXX
uYJXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXLg
e=XXXXXXXXXXXXXXXXXJ
XXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXX<e.
XXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXX~g
XXXXXXXXXXXXXXXXXXXXXo
XXXXXXXXXXXXXXXXXXXXXo
XXXXXXXXXXXXXXXXXXXXXoLp
oXXXXXXXXXXXXXXXXXXXXXoK
XXXXXXXXXXXXXXXXXXXXXX
oXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXJ
XXXXXXXXXXXXXXXXXXXXXXXXXXX
]JXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXi
L8oXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXi
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXX
y&XXXXXXX
XXXXXXXXXXX9
XXXXXXXXX
XXXXXXXX
UXXXXXXX
XXXXXXX
XXXXXXX
XXXXXXX
9XXXXXXXX
*XXXXXXXXX"8
XXXXXXXXXX&86
XXXXXXXXXXXX
gXXXXXXXXXXXXXXU
LXXXXXXXXXXXXXXQ
P6XXXXXXXXXXXXXX
'UXXXXXXXXXXXXXXXX
^XXXXXXXXXXXXXXXXX
6XXXXXXXXXXXXXXXXXi
2XXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXX
xXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXL 
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
0000000000000000000000000000000000000000000000000eg6
:s00000Q
qS000000
C?0000000F|
J0000000/Ui
00000000I@
0000000000
00000000
g~l'B`C
qNVx9A\
"CbtT6
(c~~N>
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
arU+++++++++++++++++
Y++++++++++++++++
G#7#@#
G7##yGy#
+++++++++++++++
,Y+++++++++++++++
O}5Y+++++++++++++++
<Y+++++++++++++++
Y+++++++++++++++
<Y+++++++++++++++X<
Y+++++++++++++++J
u<Y+++++++++++++++J
Y+++++++++++++++X
+++++++++++++++X
+++++++++++++++rm
+++++++++++++++X
+++++++++++++++r
+++++++++++++++r$!
+++++++++++++++r
[`[#y`bh
++++++++++++++++r
L++++++++++++++++
++++++++++++++++
++++++++++++++++
*<++++++++++++++++
L++++++++++++++++
0d++++++++++++++++a
++++++++++++++++
[G<++++++++++++++++a
zG,++++++++++++++++a
8++++++++++++++++(
#L++++++++++++++++a
++++++++++++++++
[#(++++++++++++++++d
++++++++++++++++d
++++++++++++++++
)8++++++++++++++++87
++++++++++++++++(
++++++++++++++++
L++++++++++++++++(@hhh
@8++++++++++++++++d
9V99~[z
+++++++++++++++++d
+++++++++++++++++<
++++++++++++++++++
X++++++++++++++++++++
YUYYYYY
X;X;X+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
6~~)y"y~<
r?rr3w8$
}}or}}
OEEExEO
wxOx#.E
45#4lfq~
D[B.hrj
}}|@|~
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn!
!nnnnnn
nnnnnn
nnnnnn
xxxxxxxxxxxxxxxxxxxxxxxxxxxx
nnnnnn
xTxTxTTTxTTTTTTTT_T______
nnnnnn
xxTxTxTxTTTTxTTTTTT_TTT______________
nnnnnn
xxTxTxTxTxTTTTTTTTTTT_TT_
_________
nnnnnn
xTxTxTxTTxTxTTxTTTTTT_TT_
________
nnnnnn
xxxTxTxTxTTTTxTTTTTTTTT_TT_
_______
nnnnnn
xxxxxTxTxxTxTTTxTTTTTTT_T
______
nnnnnn
xTxTxxTxTxTTTxTTTTTTTTTT_T
______
nnnnnn
xxxxTxxTxTxTxTxTxTxTTTTTTTT
nnnnnn
xxxTxxTxxTx
TTTTTTTTTT
nnnnnn
xxxxxxxTxxT
TxTTTTTT
nnnnnn
xxxxxTxxTxx
TTTTTTT
nnnnnn
xxxxxxxxTx
TTTTTTT
nnnnnn
xxxxxxTxxxT
nnnnnn
xxxxxxxxxx3
TKTTTTT
nnnnnn
xxxxxxTx
KTTTTTT
nnnnnn
xxxxxxx
KKTTTTT
nnnnnn
xxxxxxx
TKTTTTT
nnnnnn
xxxxxxb
KKTTTTTT
nnnnnn
xxxxxxb
TKTTTTT
nnnnnn
xxxxxxb
KKTTTT
nnnnnn
xxxxxxb
nnnnnn
xxxxxxb
nnnnnn
xxxxxb
nnnnnn
nnnnnni[~~~~~~~~~
kkkkkkkkkkkF
[innnnnn
nnnnnn
nnnnnn
@}```,w-
nnnnnn
1nnnnnn
nnnnnn
oooJ$J
@}````
nnnnnnq
@}```}@
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
zzzzzzzzzzzzzz
*zrzrrrrrrrrr*r*r*******zr
*zrzrzrzrrrrrrr*r*r*r*r*zr
*zzrzrrrrrrrrrrrrr*r*r**zr
*zzrzrzrzrrrrrr*rr*r**r*rz
*zzzrzrzrrzrrrrrrrr*rr**zr
*zzrzzrz
zrrrrrrrr*rr*zr
*zzzzrzr
rrrrrr*r*zz
zzzzzz
rrr*rrr*zr
zzzrzrz
(rrrrr*rzr
zzzzzzz<
rrrrr*zz
zzzzzz
(rrrrrzr
zzzzz`
rrrrzz
(rrrrz
|WX[[ee
|WXX[[ee
|WXXX[ee
||||||=|==========
|||====
|||======
||||====
== =
bbb|||wDD
bbbbb|H
bbbbb|
bbbbbb=
bbbbbbb=
bbbbbbbb
{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{

.HUne4d
$9E[F'W
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
satavopofomedudoxe wozewukuzedicobir gav guf vanarizijavegagerusuxo
yenaxivaxecesolajizefiyutov
mumefere pavegurovi
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
020284c6
InternalName
sojbmoemonu.uhe
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.590.38
VarFileInfo
Translation
DYap pawoviyafavo juvew fovavuy kiti texusocuso yehujakuvi mogehudeyuSNehonelelaru bilikugotav luxuvacokedux yiruh sixuxoyulapaf mosinis hige mudeyuhokid
WogipetuhevuLWehi jev nefenapi koze cejeze mijarupad sewomedamegebay legesuhuweni tagexerdHoyipewamazi sab dohubiwiv tegoronizise lev nesomogiwajace bizi newazapabarivud rifulafivovoji dotosdXupivixejuhuw lorojixi hedaj vawohihonakopal mutoy hatozitawore tajajo wedepapepivuziz ruxunalukituj
Cezuzikixeya
Gaw puw
Xuhahopecox tezumeguzotisidgCowaceyajut tayekasobeh jisezapumefom bagekuhekewok pabavof xavoho kumigep kenawuyud janoxivuhiju heruh
Xakexufix:Gahiw bijohidinoheyo ciyovoxojaned xec peh niketec xabucin
SWini fiboduwa puzasepirunal lafobesafoy yoyehodukex nuyeha tahudulifito tufobudoxohBYena hijuwumaden nihoxirucesix femi tikucigehedebuk nivulay vigegi_Winijijovipo cez sokituheki yagokokefojibeg wihukil xigagu xovivaveho yiwiwelen civigucoviteruc
Fad0Sunapecanuc zoviyinupup gadevomi gumuzodubuvajoh
Sarimeta
Liropogodud
0Dunud gujen nurejopumevipi xow ganuzu hevoxijepo,Subizucatal cola yupufemu xuhate joyi wekuyo"Bumutunawafi toteyu muborezasefotaZGuwiwofewi hivixecile xojujicibululav cezub lopidekuduve pizekul dicemaxoj sevadowukomokagTGarirozusa diwuxirozuwaho lafuyavodoroz nodigevi yubu fuxegajevicoh ten kusiyeb hobo%Bulaluzab zakukajiyiloc fusokoxudukiz
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056ac331 )
BitDefender Clean
K7GW Trojan ( 0056ac331 )
CrowdStrike win/malicious_confidence_100% (D)
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
FireEye Generic.mg.4bebe52555714d9e
Sophos ML/PE-A
Ikarus Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_93%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Tnega!ml
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34142.Fq0@aWcGoApG
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.97%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D977 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Webroot Clean
Avast Clean
No IRMA results available.