Static | ZeroBOX

PE Compile Time

2021-10-15 20:56:06

PE Imphash

8596a0b998af48f029f2f9b41336794e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00053dd0 0x00054000 6.7478849259
.data 0x00055000 0x00004810 0x00001000 0.0
.rsrc 0x0005a000 0x0004195c 0x00042000 7.99338991335

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0005a8b0 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0005a8b0 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0005a8b0 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0005a8b0 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
SHADO 0x0005a998 0x00040854 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009b604 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b604 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b604 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0009b72c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0009b75c 0x00000200 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarTstGt
0x401004 __vbaVarSub
0x401008 None
0x40100c __vbaStrI2
0x401010 None
0x401014 None
0x401018 _CIcos
0x40101c _adj_fptan
0x401020 __vbaHresultCheck
0x401024 __vbaVarMove
0x401028 __vbaStrI4
0x40102c __vbaVarVargNofree
0x401030 __vbaAryMove
0x401034 __vbaFreeVar
0x401038 __vbaLineInputStr
0x40103c __vbaStrVarMove
0x401040 __vbaLenBstr
0x401044 __vbaLateIdCall
0x401048 None
0x40104c None
0x401050 None
0x401054 __vbaPut3
0x401058 __vbaFreeVarList
0x40105c __vbaEnd
0x401060 _adj_fdiv_m64
0x401064 None
0x401068 __vbaNextEachVar
0x40106c __vbaFreeObjList
0x401070 None
0x401078 __vbaStrErrVarCopy
0x40107c _adj_fprem1
0x401080 None
0x401084 None
0x401088 None
0x40108c __vbaForEachCollAd
0x401090 __vbaVarCmpNe
0x401094 __vbaStrCat
0x401098 __vbaSetSystemError
0x40109c __vbaLenBstrB
0x4010a4 __vbaLenVar
0x4010a8 _adj_fdiv_m32
0x4010ac __vbaAryVar
0x4010b0 None
0x4010b4 __vbaAryDestruct
0x4010b8 None
0x4010c0 __vbaExitProc
0x4010c4 __vbaVarForInit
0x4010c8 __vbaVarPow
0x4010cc None
0x4010d0 None
0x4010d4 None
0x4010d8 __vbaOnError
0x4010dc __vbaObjSet
0x4010e0 None
0x4010e4 _adj_fdiv_m16i
0x4010e8 __vbaObjSetAddref
0x4010ec _adj_fdivr_m16i
0x4010f0 __vbaVarIndexLoad
0x4010f4 None
0x4010f8 __vbaFpR4
0x4010fc __vbaForEachCollVar
0x401100 None
0x401104 __vbaRefVarAry
0x401108 __vbaFpR8
0x40110c __vbaBoolVarNull
0x401110 _CIsin
0x401114 __vbaErase
0x401118 None
0x40111c None
0x401120 None
0x401124 __vbaVarCmpGt
0x401128 __vbaVargVarMove
0x40112c __vbaChkstk
0x401130 None
0x401134 __vbaFileClose
0x401138 EVENT_SINK_AddRef
0x40113c None
0x401144 __vbaStrCmp
0x401148 None
0x40114c __vbaGet3
0x401150 __vbaAryConstruct2
0x401154 __vbaVarTstEq
0x401158 __vbaPutOwner4
0x401160 None
0x401164 __vbaI2I4
0x401168 __vbaPrintObj
0x40116c __vbaObjVar
0x401170 DllFunctionCall
0x401174 None
0x401178 None
0x40117c __vbaVarOr
0x401180 None
0x401184 __vbaLbound
0x401188 _adj_fpatan
0x40118c __vbaLateIdCallLd
0x401190 __vbaR8Cy
0x401194 __vbaRedim
0x401198 __vbaStrR8
0x40119c EVENT_SINK_Release
0x4011a0 __vbaNew
0x4011a4 None
0x4011a8 None
0x4011ac __vbaUI1I2
0x4011b0 _CIsqrt
0x4011b4 __vbaObjIs
0x4011b8 __vbaVarAnd
0x4011c0 __vbaStr2Vec
0x4011c4 __vbaUI1I4
0x4011c8 __vbaVarMul
0x4011cc __vbaExceptHandler
0x4011d0 None
0x4011d4 None
0x4011d8 __vbaStrToUnicode
0x4011dc __vbaPrintFile
0x4011e0 None
0x4011e4 None
0x4011e8 _adj_fprem
0x4011ec _adj_fdivr_m64
0x4011f0 None
0x4011f4 None
0x4011f8 __vbaVarDiv
0x4011fc None
0x401200 None
0x401204 __vbaFPException
0x401208 __vbaInStrVar
0x40120c None
0x401210 __vbaUbound
0x401214 __vbaStrVarVal
0x401218 __vbaVarCat
0x40121c None
0x401220 None
0x401224 __vbaI2Var
0x401228 None
0x40122c None
0x401230 None
0x401234 _CIlog
0x401238 __vbaErrorOverflow
0x40123c __vbaFileOpen
0x401244 __vbaVar2Vec
0x401248 __vbaInStr
0x40124c __vbaNew2
0x401250 None
0x401254 None
0x401258 __vbaR8Str
0x40125c None
0x401260 _adj_fdiv_m32i
0x401264 _adj_fdivr_m32i
0x401268 __vbaVarSetObj
0x40126c None
0x401270 __vbaStrCopy
0x401274 __vbaI4Str
0x401278 None
0x40127c __vbaVarCmpLt
0x401280 __vbaFreeStrList
0x401284 None
0x401288 _adj_fdivr_m32
0x40128c __vbaR8Var
0x401290 __vbaPowerR8
0x401294 _adj_fdiv_r
0x401298 None
0x40129c None
0x4012a0 __vbaVarTstNe
0x4012a4 __vbaVarSetVar
0x4012a8 __vbaI4Var
0x4012ac None
0x4012b0 __vbaFpCy
0x4012b4 __vbaAryLock
0x4012b8 __vbaVarAdd
0x4012bc __vbaLateMemCall
0x4012c0 __vbaStrComp
0x4012c4 __vbaStrToAnsi
0x4012c8 __vbaVarDup
0x4012cc None
0x4012d0 None
0x4012d8 __vbaFpI4
0x4012dc __vbaVarTstGe
0x4012e0 __vbaLateMemCallLd
0x4012e4 None
0x4012e8 __vbaR8IntI2
0x4012ec _CIatan
0x4012f0 __vbaCastObj
0x4012f4 None
0x4012f8 __vbaAryCopy
0x4012fc __vbaStrMove
0x401300 __vbaForEachVar
0x401304 None
0x401308 __vbaStrVarCopy
0x40130c __vbaR8IntI4
0x401310 None
0x401314 _allmul
0x401318 _CItan
0x40131c __vbaNextEachCollAd
0x401320 __vbaAryUnlock
0x401324 __vbaUI1Var
0x401328 __vbaFPInt
0x40132c __vbaVarForNext
0x401330 _CIexp
0x401334 __vbaFreeStr
0x401338 __vbaFreeObj
0x40133c None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
-C000-Project1
046}#2.
MDIddddForm1
MDIForm1
MDIForm1
Project1
ReadyState
ieframe.dll
SHDocVwCtl.WebBrowser
WebBrowser
Nevoar
chainahi
modPlaySound
Module1dd
Module4
stringbroda
jsombeta
buildstr
frmSplashc
laptopwah
MDIddddForm1
frmAbout
frmTip
frmSplash
Project1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
BitBlt
Buffer
BackGround
Timer1
Texture
SetPixel
GetPixel
LineTo
gdi32.dll
MoveToEx
StretchBlt
kernel32
DrawMap
GetDist
MoveWithHID
RayCastingEngine
DrawTextureSlither
SetupDataSystems
LineDraw
ShadeColor
VBA6.DLL
__vbaI2Var
__vbaVargVarMove
Label4
__vbaFreeStrList
__vbaStrI4
__vbaStrCat
__vbaStrMove
__vbaEnd
__vbaPowerR8
__vbaVarSetVar
__vbaErrorOverflow
__vbaFreeObj
__vbaVarMul
__vbaObjSet
Label13x
__vbaVarCmpGt
__vbaVarCmpLt
__vbaVarTstGe
__vbaVarDiv
__vbaFPInt
__vbaFreeObjList
__vbaVarCmpNe
__vbaVarOr
__vbaR8IntI2
__vbaFpR4
__vbaVarTstNe
Commandb
__vbaFpI4
__vbaVarLateMemCallLd
__vbaBoolVarNull
__vbaVarMove
__vbaObjVar
__vbaLateMemCall
__vbaVarVargNofree
__vbaVarPow
__vbaVarAdd
__vbaR8Var
__vbaFreeVarList
__vbaFreeVar
__vbaPrintObj
__vbaVarForNext
__vbaSetSystemError
__vbaHresultCheckObj
__vbaGenerateBoundsError
__vbaVarSub
__vbaI4Var
__vbaVarForInit
Label12x
nowtime
Command2
Label3
send_st
altafbhai
waittmr
Label14
Label11x
shell32.dll
ShellExecuteA
V5CI0YgD
$XCommand1
Command3
Command4
Command5
Command6
Command8
Command9
Command7
Label2
Label5
lblshell
cunbhai
Label1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\vbc14028.oca
SHDocVwCtl
dikhao
sheller
Frame1
visibl
upback
altbool
alturl
debugmode
backup
herlicopter
killerman
rastabro
frommn
centerbroda
txtshell
poratime
konarw
Label12
Label13
Label11
Label16
Label15
raaste
eyeshere
Logger
shelled
mufuckr
__vbaFpR8
__vbaR8Str
__vbaStrR8
__vbaLateIdCall
__vbaPrintFile
__vbaVarDup
__vbaStrVarVal
RegCreateKeyA
__vbaLenBstr
__vbaStrToUnicode
__vbaStrToAnsi
__vbaAryDestruct
__vbaPut3
__vbaFreeStr
__vbaVarCat
__vbaAryVar
__vbaAryCopy
winmm.dll
PlaySoundA
__vbaFileClose
__vbaGet3
__vbaStrVarMove
__vbaFileOpen
__vbaStrCopy
__vbaObjSetAddref
__vbaNew2
__vbaOnError
GetComputerNameA
user32
GetKeyState
GetForegroundWindow
GetWindowTextA
GetWindowTextLengthA
advapi32.dll
RegCloseKey
RegDeleteValueA
RegOpenKeyA
RegQueryValueExA
RegSetValueExA
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
RegOpenKeyExA
GetAsyncKeyState
GetVersionExA
__vbaInStr
__vbaStrCmp
__vbaPutOwner4
__vbaR8IntI4
__vbaUbound
__vbaVar2Vec
__vbaAryMove
__vbaLbound
__vbaStrVarCopy
__vbaVarTstGt
__vbaVarTstEq
__vbaStrComp
__vbaRedim
__vbaUI1I4
__vbaStr2Vec
__vbaUI1Var
__vbaUI1I2
__vbaErase
C:\Windows\SysWow64\MSVBVM60.DLL\3
RtlMoveMemory
Length
Capacity
ChunkSize
toString
TheString
AppendNL
Append
AppendByVal
Insert
InsertByVal
Remove
HeapMinimize
__vbaVarIndexLoadRefLock
__vbaAryUnlock
__vbaRefVarAry
__vbaVarAnd
__vbaLenVar
__vbaNextEachVar
__vbaForEachVar
__vbaVarLateMemCallLdRf
__vbaVarIndexLoad
__vbaStrErrVarCopy
__vbaHresultCheck
__vbaCastObj
__vbaVarSetObj
__vbaNew
__vbaI2I4
__vbaAryConstruct2
X+Eval
ExecCommand
__vbaVarIndexLoadRef
__vbaLateMemCallLd
__vbaObjIs
__vbaI4Str
__vbaLenBstrB
CreateToolhelp32Snapshot
Module32First
Module32Next
CloseHandle
GetCurrentProcessId
advapi32
GlobalMemoryStatusEx
__vbaR8Cy
__vbaFpCy
ZBlblLicenseTo
lblCompanyProduct
lblProductName
__vbaAryLock
__vbaLateIdCallLd
LoadTips
__vbaNextEachCollVar
__vbaForEachCollVar
__vbaStrI2
__vbaInStrVar
__vbaNextEachCollAd
__vbaForEachCollAd
MDIForm
7&1A5
%picIcon
lblTitle
lblDescription
lblVersion
cmdSysInfo
lblDisclaimer
StartSysInfo
GetKeyValue
__vbaExitProc
#SchkLoadTipsAtStartup
Picture1
cmdNextTip
lblTipText
DisplayCurrentTip
__vbaLineInputStr
imgLogo
lblPlatform
lblWarning
lblCompany
lblCopyright
frmSplashc
Timer1
Frame1
Label1
lblProductName
Welcome
Arial'
lblLicenseTo
LicenseTo
lblCompanyProduct
Loading...
Arial'
Commandb
Down()
send_st
SUB MIT!
Command2
STE ALTH!
Arial0
Arial0
Arial0
Arial0
Fetch FF()
altafbhai
waittmr
Label13x
Sub ject :
Palatino Linotype
Label12x
FR OM :
Palatino Linotype
Label11x
Palatino Linotype
Label14
Palatino Linotype
nowtime
Label3
Label4
M i n
frmTip
Tip of the Day
chkLoadTipsAtStartup
&Show Tips at Startup
cmdNextTip
&Next Tip
Picture1
Label1
Did you know...
lblTipText
frmAbout
About MyApp
picIcon
cmdSysInfo
&System Info...
lblDescription
App Description
lblTitle
Application Title
lblVersion
Version
lblDisclaimer
Warning: ...
frmSplash
Frame1
imgLogo
lblCopyright
Copyright
lblCompany
Company
lblWarning
Warning
lblVersion
Version
lblPlatform
Platform
lblProductName
Product
lblLicenseTo
LicenseTo
lblCompanyProduct
CompanyProduct
laptopwah
Command9
Command8
Command7
Command7
MS Sans Serif0
alturl
Arial0
altbool
Arial0
killerman
Frame1
Settings
backup
Arial0
Command6
debugmode
SHDocVwCtl.WebBrowser
txtshell
sheller
centerbroda
MS Sans Serif0
Command3
Command4
Command5
visibl
Visible?
Arial0
upback
Arial0
SHDocVwCtl.WebBrowser
dikhao
mere ko dikhao
raaste
AltOpen()
rastabro
Arial0
Arial0
frommn
Arial0
Arial0
Arial0
konarw
Timer1
poratime
Arial0
Command2
ST EALTH!
SUBMIT!
Command1
RESET TIMER!
CLEAR()
herlicopter
SHDocVwCtl.WebBrowser
cunbhai
SHDocVwCtl.WebBrowser
Label1
lblshell
Label16
Label15
Country:
Label14
Palatino Linotype
Label13
Subject:
Palatino Linotype
Label12
Palatino Linotype
Label11
Palatino Linotype
Label5
M i n
Label2
Full Time:
Label3
Label4
Texture
$" &0P40,,0bFJ:Ptfzxrfpn
"$$0*0^44^
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
F0Wq<g
KHdT(
nbV?"F8
/#89=;t
['?_\b
:H4&kKm
QH%Y#>G
]"DYff
iVeVv
#zyc!B
]q#:cy
Ee3)bI
h`/&c&5
;c).y
*FK$>r
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
e"Kf|d
$ROjeF
0@8.q
rco^N+a
+e/K\M
gFtVv]
`KtWl1P
VKpQmxP2
,Kiiqu#O
bWo1OP
/-AflJ
HYbTT',H
"(.Ye`
}~ /M4
5&[ILWJ
<{fAcd
ci.dc+
xPF:}(
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
SDVF7e
DT[1f8
)'(B -
c95\^.
G5yo&B
^:TOuq
EibW6n
i;4?u-S
#2_J,
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
clXlZY
`$uK|#
vc;jy,
NrOSV|
6YZMP&
n9BTd~__
b{FxlD{F
wCOHr,Ic
h0J#8
F>Belg=q
FB72HN8
k-1$1.
T2FV&>c
Texture
$" &0P40,,0bFJ:Ptfzxrfpn
"$$0*0^44^
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
7{S3Z;
Y'#'q
}(*2i^
`0bCp9
Sy!UKO
P-WP{[Q O$1
%X$%LC
Texture
(B+(%%(Q:=0B`Ued_U][jx
(#(N++N
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
=WBI"i
E,xFcxq
ibrrp3
A3(p9
QN%$8FU
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
OFvKF;@
.js;j[
;I#j(q
j)la*Y
kde1np
+m+$M 1
M#,D|
[6R}n6
>};g$}}i
[\,qY3*
TH$hR%Q
o&B7dt
pIr&g'
v)Z#K:D
>Y%kuf
c<TVpy
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Y$V;KK
T5]VH4
o7XO/~9
WKy.nl
\$'YEb
:{UX5)
Goqt5'y
!?",V{s
8:hY8(
w[oY&Fb
=!XHA-
jA)|&w
k>'s"&
M2km.v2
IQ&A,es
o;M>}?H
(23\HI
Texture
(B+(%%(Q:=0B`Ued_U][jx
(#(N++N
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
o.f[6c
n&@:O
no0qS]^F'h
I@Cq(R
Texture
(B+(%%(Q:=0B`Ued_U][jx
(#(N++N
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
`.XJV=
ehVWgq
p"RO?"
i34c#
^=i/P&k;D
~b'66Q6
Kmzc`mG'
\1t;W
dG<+60
v@1c;$o1
+`%[viL?h
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
!T}P&@23
^4{b@\E
w[%BZLd
!HPGoN
a,|Z*nr
1M{+y#
^AelL?
Z%{~CLv
]00~oRO
n+-G9["
o0;wnI'
U)mo!Y
}:Uj?z
mHH#/'
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
o<&d8^
+mPUJ(
Rq,j2;
QMk;6Q
4#ld67
XeO1\0
i`1b6/#pK
e0%m6d
3g31k\3
[a`$uP
{gTlc2.[
f%>b)-
v[_/#r
e?{=qM$)6
$#!flg
$WB]f}
zzQE4L
,[b|;s
Texture
=,.$2I@LKG@FEPZsbPUmVEFd
;!!;|SFS||||||||||||||||||||||||||||||||||||||||||||||||||
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
m/7oKY72
m2o8p@
&($U^2
b0ZA+u<
zS%-tE
5p0Oo
(xu)bd
_M$b;Y
rey%-<
I8n7r}q
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
SD7f)T
bQkxW"
)&6smQi
*,JKrg
M$N!W1F
R TpIq
Buffer
BackGround
Timer1
Texture
(:3=<9387@H\N@DWE78PmQW_bghg>Mqypdx\egc
/cB8Bcccccccccccccccccccccccccccccccccccccccccccccccccc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
)|)'ic
B?1,i
73gy`=8
:R,(Ws
Ei}@NI
Heighty
Length
Colour
iChunkSize
iIndex
sToFind
lStartIndex
compare
KeyRoot
KeyName
SubKeyRef
KeyVal
O|PQWhH
f94At
f94At
}#j8ht
}#j\hT
}#j8ht
}#j\hT
}#j8ht
}#j8ht
}#j8ht
}#j8ht
}#j8ht
}#j8ht
} j(h4
} j hp
}#j0h4
}#j h4
}#j(h4
}#j$h4
~<hK\D
N<h#bD
G<hQeD
~@h$gD
}#j\hT
}#j8ht
}#j\hT
}#j8ht
}#j\hT
} j hl
}#j8hl
}#j\hT
}#j\hT
MSVBVM60.DLL
__vbaVarTstGt
__vbaVarSub
__vbaStrI2
_CIcos
_adj_fptan
__vbaHresultCheck
__vbaVarMove
__vbaStrI4
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaLineInputStr
__vbaStrVarMove
__vbaLenBstr
__vbaLateIdCall
__vbaPut3
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaNextEachVar
__vbaFreeObjList
__vbaVarIndexLoadRef
__vbaStrErrVarCopy
_adj_fprem1
__vbaForEachCollAd
__vbaVarCmpNe
__vbaStrCat
__vbaSetSystemError
__vbaLenBstrB
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaExitProc
__vbaVarForInit
__vbaVarPow
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaFpR4
__vbaForEachCollVar
__vbaRefVarAry
__vbaFpR8
__vbaBoolVarNull
_CIsin
__vbaErase
__vbaVarCmpGt
__vbaVargVarMove
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaGet3
__vbaAryConstruct2
__vbaVarTstEq
__vbaPutOwner4
__vbaNextEachCollVar
__vbaI2I4
__vbaPrintObj
__vbaObjVar
DllFunctionCall
__vbaVarOr
__vbaLbound
_adj_fpatan
__vbaLateIdCallLd
__vbaR8Cy
__vbaRedim
__vbaStrR8
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
__vbaObjIs
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStr2Vec
__vbaUI1I4
__vbaVarMul
__vbaExceptHandler
__vbaStrToUnicode
__vbaPrintFile
_adj_fprem
_adj_fdivr_m64
__vbaVarDiv
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaVarCat
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVarLateMemCallLdRf
__vbaVar2Vec
__vbaInStr
__vbaNew2
__vbaR8Str
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaVarSetObj
__vbaStrCopy
__vbaI4Str
__vbaVarCmpLt
__vbaFreeStrList
_adj_fdivr_m32
__vbaR8Var
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaFpCy
__vbaAryLock
__vbaVarAdd
__vbaLateMemCall
__vbaStrComp
__vbaStrToAnsi
__vbaVarDup
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarTstGe
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaCastObj
__vbaAryCopy
__vbaStrMove
__vbaForEachVar
__vbaStrVarCopy
__vbaR8IntI4
_allmul
_CItan
__vbaNextEachCollAd
__vbaAryUnlock
__vbaUI1Var
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
vbvbvbvbvb|6
vbvbvbvbvb|
%-4%N=
vbvbvbvbvb|YTYD&AASEaHR0cDovL25ld2xvc2hyZWUueHl6L3dvcmsva2VubnkzLnBocA==YTYD&AASE
vbvbvbvbvb|
vbvbvbvbvb|hofjband
vbvbvbvbvb|3
alt|aHR0cDovL3RlcmViaW5uYWhpY2MuY2x1Yi9zZWMva29vbC50eHQ=
Pwqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwe[XXXXXXX]
*aw>&|XI.
iT<{?b;
jn>ND|?
R[XXXXXXX]
bvnbvnbvnfgfhfghfghfgbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbLOL
}i/wX1"I&
}?<&LI
wTlU0-5S
2Ek~!
fE-m?g
3wqCnj
$8<_b~
UN"|H*
VEV9g[8
{zF6D\
4`dz6e
n@0.4X
Ntg2K'
_W"J?B
}_E0D.
@fSY`WJ
rp><G?
-VbKz1V
LbDOUf
<C~GBF
dlO$&Bw
pi_XeE
s!r!^n
)~*X Z
Ew9}8<
TXujoD
VI3:b4
~e0oNs
t$FXKX
QL=5!61
SAlVqkT
%vkQK0S;
yV1j@mj
/<I;(H
{ m-ta
fpXp:#$
[S9[C[
+X{eB(
EpDVrJ
9);}b\
OO}^$X{
([zVpj
-{EMyB
MKy^4V
#r6|#f%
yN*mw<A{
zYBJCT
z6rezd
:@l[3w
Xf&`w=
l}Z?{*
@1cY,a
D[cUT)V
J21QG$q
eI3Z]]c
vfaEx5M
:~t}1o=NI
)ADGXA
EbonH11aO
{"/JN4
Q2E,*1Y
`.T_g$|
>pDE"*
;::*X0
nd_&ib
!gz>S=
EUrz|
kV)M:]
y $wr@Hc
&1k|VY,
8qF&%O
Ky4l|#7
NFW'P0C
(9}.|8
6oxQ,c
,*U[OH|>S
nhBQp*
vP%W 8
yOKJ>~
r)DGRK
{5G?)k
I36:s/
+'e$5x
pDeu(J
OY~"hwl
&?zd&,
.*!\`O
~IU RY
DMp\p>
,GRLqP
~Y*t( ?
vr;r1tr
hg}H0j
2m5H#
]j9?=R7
Z96/K6
1o+/.h
a0D^'V
l]O#J~I
14'U;C
.WE|oCY
E+HGu1(
Tr4sg%J
ia*W]3
<EK$2~\
"SU]d!
^Z5icN
]/LYG
GxW5)$o
L5Je)q|
'U=-<*
T;gqvU`
ux1.WyB$
z.xJO7FYN
XNfWXqH=O
_8zNX=:n
RaHF?N
8_=p4;
4"TGh2D"
=0YK\aR
?o>4)o
pK8bm[Q>Ss|p
[N30v1
7"fdp5m
&M}*d
6\0+9p
PI;Ut@
Q c."~
5910e1_
9leB!
5$vnDn
Y6?:=d
qi[# du
`oWFZe"
.jl'ow%
Mf%gWe
{XOA?
8H<A+4
RIbv1D
7|+e7-
>e^2(u
"B1@%uO1
:Ki%m[R
Vj>`{\
L\b>;B5
b:1'Hqa
sY+I|<!S
NXt<kb9
E3}^!+
0qW]}U
C6/5-lI
r5|'/<
@ovt!V
=aL*4i4
"AKe;2
j{D?(mur
GB]2z\
/]'h3/
a\Vsi*S
@PxApU
LSkLzm
r89^7OD
k+p7qUU
oF\b;Z
ur"|} o
.ym> n
am2[&|?
}Hvtj4
^&c1<?
"+n}Z|a
C}m6[J
9""rLZ
}N4%e8
b#dyAXD
N%[8YL
evfV{%
^lvb4h
Dhms#
bh3Yvz
1Ub)Vq
)oTVXP
W^*?F3
[?|KnP
-m~rxn
8UyHNT
a#*0SoI
<5!52K/
`FQC9v
V_iQ~H
>pc$,e
,75pW,
4pd-RV
K*.<Ku3V
yc01&%
oUnHAD
/`6j~
lEx^tK
o`eQ.q>
VHtxQM}
+\s,A)
Nkb"aB
orW fL
lC#p1(
8*jB"v
c*Zd?N
w}jzNf
W4r;.-
>;{98l
N612U
t233m+
J:0%G&
&ThCA"
.w:`fzX[*
:5*4d2
bGV<=j;
fXp}Sx1
{9j'Oui
ps\|0i
e~@JZ.
KAL~]
{OkF`bFv
Fkt=`/
mw_aH1.+
7;}Z8-
YG.1,w
b1H3\ U:
r=.ut
v8C'X]g
x:us$
KS1P{&
g8:[0q
cZ9RB>9
^jlgBme
,w)n<_h
SCp1H-!
,:0EZe
&x~c[
>Dl/S>
g~gt#[
~lVkt|
$4Rx.[
d3xLLZZ|
'rB6\kZ
u<{rig
Ci4O65
t\X0}2/Z'
0;U*I3
00{!p=
K)(T)*
AwXe:;
Ev_;'0U
WX1pO%P
[Vu$)#
OKccEz
#).Sk[
-J1Stu
!(Omw\
3'W?hA(e}
>ZQ>8cgX[
}mv;'@
ILW~x9
E@4vp%
\"kGxU\z
D:0MqsD1
m%jT^h
mVQYl!
m+:l&k
-m4<4.
Ik=(E^
F{e24[
]7BQ.kV
D#zoU;
S&zj_{J U
x^Ir`b
6V@\\/y
!{,%CSb
7I@ 1[|}
*F!FiYr
Lne&X7
1\iP2?
j RL|ll
>H9|U\
NYQ88z
;-I;n?
xw?u."
>8~"&z
^p;r#~
zKZHQkd
s5tA~gpw
8Hlnp).
H$_SG@_r
s-j<y
A|^MMt
,u'QX:HN
LCV8<*
\ikPZn<
TB/lg#k\
;M9_eQ
yP~DRV
'=q;'7kMv<
]^D|hS
jns0Rf
^^uZ"p
qaG$V4
*aAPv^
]\oq',
])yk)39j
0zzScP}
we%\/R:R
=\n-C
GRdYCT
LdGG\zJ
]pj>yR
W\og)5
ueG$bX6
zSKMUH
|5|~S=8<
M#-NxZ
-zW"TV
yvSs*&*
yKd4<?t
;$peS+
h`eaGp
lm%&ez
=UW%d]
c@o]7+
}D~l{A
O2w<d
|<tB'h
,4T&Am\
DVaD9
b<O3e9
Fc})&v
e-#?bA
U[{EOk
SpIATm
-'-ID\
k;}O"l
bn=[-C
&.<P_z
;y}$bG
_3G|}v
#C=k%`9#
uWLEEyC
et.ljul
59|C.tx=
_<)w2
J4X|=Z
[n*)bJ
OqgSkrV
of8tMQ
^o]b8U
_l5G`M$'
{EYLx"k
-Skojrh7,
x61A!J
tr}$op3=
ua-~Ut
j9J7[{
MPx:U
(XptG'
hpaV~8
?l$:a@
<kR._k
?.m%:m
'Ppzs!
wM3Ou`
i<!/c$b
gn/$u\
yez.@:
0v+[3v
n#'ODu
p|r9o5
h*Hr ;
VxZ9K?JCb
-\5qu*Nt
y0R,TgC
&X^3C?
FK#^~Y
\-6<w@K
<md0yIV}
~W9?tm>?`h
vB:>|5
|R/cg)/
[hqZK&
]iSdu!
H}~xG({
roP<<{
dVo^Qi
.Ral^r
hsi le
3&?3Fe
:k~xQA
*s*'I9
hi0W_x
:\QVwC
f?C>+dg!1m
t$F]y/
KDV:7%L
MV4C6OX
f~jWxRU
lpqw3he@
G(gY9z
U@"i.t
{(+DtdA
j]zi"3dV
k'&xX9
@RsYt3
./IY[o
ydLTi1)
cd%YWu
H4n4t4
Y@kvQztK
^]ju!H+
dlP,:1V
.ga!fL
4\U s g
:U|JO%
>-0_},
p,-b34
60qsd[\
aISe'-I-
ab "Fa0
qh}w0[
QP`V;L7
G^f=M(
(Co,Z[
%Cb$_;
YR2GY?
W(">~1
xRu|i>
w{{O3CR
$p3_0\S
_(c{vw
"CReOVZV
AX'L%V
T<wGE7
z^YLBYi_#7&
O_!$w;
Thjaji
N!m*Q\@
P#GY,vV
fR@:OGjx
b|375u
dvv7GJ
PIq{*P
\wj%F&
,\VO9
$MCXE
|!NzAo
lU'olm
)erLb>
V@m]$!
m9O3WwM
Io|44}f
^\^e55
<;%$i'B
O?s:HO
r~f`\
~W"JpXE
_Z#F I
Z7;2Sm
[?*U"4
}8zGPp
U%Ya|^
u^^^^wqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwewqeuuiwe(
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
\Users\hp\Ap
@ell Dlg
Look &in:
E*\AC:\porana\NewKLL\6-TRayCstr\Ray.vbp
SOFTWARE\Microsoft\Windows NT\CurrentVersion
SOFTWARE\Microsoft\Shared Tools Location
MSINFO
SOFTWARE\Microsoft\Shared Tools\MSINFO
TIPOFDAY.TXT
GetDeviceStateKeyboard
DirectInputCreate
GUID_SysKeyboard
CreateDevice
SetCommonDataFormat
SetCooperativeLevel
Acquire
Unacquire
Ni-Star Enterprises RayCaster - FPS =
\st.htm
yutyutyutyutyutyutr
234234234234234234234
sdsdsd
sdfsdsd
sdsfdsd
achibat
[Passwords]
[[$%]]
CUSTOM
[XXXXXXX]
achibat321Xz
YTYD&AASE
============================
[ALTUP]
[ ALTDOWN ]
[ ALTUP ]
[Escape]
SpecialFolders
Invalid Object at position
Missing '}':
namebro
achibat1
WScript.Shell
Startup
vbnbnbv,bnnbnvvn,tyrggg,qwwwweeee,iouyutr
altmeml
Alturl
abdefgijklmnopqrstuvwxyz
ch.exe
taskkill /im
cmd.exe /c
<Error>
Length of Base64 encoded input string is not a multiple of 4.
Illegal character in Base64 encoded data.
Invalid JSON
Invalid Array at position
Missing ']':
+-0123456789.eE
Invalid Boolean at position
Invalid null value at position
Invalid Key at position
Dictionary
Collection
( {"Records": [
"RecordCount":"
[PageUp]
]pUegaP[
]nwoDegaP[
]emoH[
]tresnI[
]eteleD[
Parser Error
ERROR: Nesting level exceeded.
message
prompt
default
switch
return
value1
value2
[[PASTE]]
ExecQuery
Caption
Timer Val:
uparkx
\log.txt
\h2.htm
Log Submitted!
Are You Sure You Want To Re-set Timer???
S u r e
saverbro
werewrwwwwww
\c.exe
\c.exe -o
^(1|3)[1-9A-HJ-NP-Za-km-z]{26,34}$
a9ew64jszjh70gt909c0ji9ln2bm1um27i00a3hepj144emtht
Win32_NetworkAdapterConfiguration
winmgmts:
InstancesOf
IPEnabled
IPAddress
oy7oel014pgx3rnmgo1floytt4o8eghapzuon70fhru0lnlsvl
control
innerText
WantToCle Log?
Target
Uninstall
/apap/
php.bp
Reported
About
Version
\MSINFO32.EXE
System Information Is Unavailable At This Time
Options
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
http:///
http:///
http:///
http:///
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
CompanyName
Ni-Star Enterprises
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.733398
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_80% (D)
BitDefender Gen:Variant.Bulz.733398
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren W32/Kryptik.BZN.gen!Eldorado
ESET-NOD32 a variant of Win32/Spy.KeyLogger.NJK
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Spy.Win32.KeyLogger.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Bulz.733398
TACHYON Clean
Emsisoft Gen:Variant.Bulz.733398 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Swisyn.jc
FireEye Generic.mg.9c3259f246b2cd75
Sophos ML/PE-A
Ikarus Trojan-Spy.Agent
GData Gen:Variant.Bulz.733398
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1135698
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Bulz.DB30D6
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Bulz.733398
MAX malware (ai score=85)
Malwarebytes Malware.AI.11071512
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Spyware.KeyLogger!1.D278 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_63%
Fortinet W32/Bingoml.BSER!tr
BitDefenderTheta Gen:NN.ZevbaF.34218.Mm0@a0!jDrdi
Avast Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.