Static | ZeroBOX

PE Compile Time

2021-02-21 07:04:57

PDB Path

C:\rewi\mac30.pdb

PE Imphash

f937f2af706dbcbf43ed87b459c473ae

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c150 0x0001c200 7.62137812446
.rdata 0x0001e000 0x00004468 0x00004600 4.05207468622
.data 0x00023000 0x02ac72e0 0x00002200 2.24726780999
.doye 0x02aeb000 0x00000270 0x00000400 0.0
.veyi 0x02aec000 0x00000017 0x00000200 0.0
.rsrc 0x02aed000 0x000250e0 0x00025200 6.34474723569

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x02b0ff38 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02b0ff38 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02b0ff38 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02b0ff38 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02b0ff38 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x02b10f30 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x02b10f30 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x02b10f30 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02b0fa20 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x02b11d78 0x00000362 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x02b11d78 0x00000362 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x02b11d78 0x00000362 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02b117d8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x02b117d8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02b02e28 0x00000068 None SUBLANG_DEFAULT data
RT_VERSION 0x02b11800 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x41e008 HeapAlloc
0x41e00c GetCurrentProcess
0x41e014 SetEvent
0x41e018 FlushViewOfFile
0x41e01c SleepEx
0x41e020 ReadConsoleW
0x41e024 CreateActCtxW
0x41e028 FreeConsole
0x41e02c HeapDestroy
0x41e030 FindNextVolumeW
0x41e034 WriteConsoleW
0x41e038 GetModuleFileNameW
0x41e03c GetOverlappedResult
0x41e040 GetACP
0x41e044 ReleaseSemaphore
0x41e048 DeactivateActCtx
0x41e04c Module32First
0x41e050 SetLastError
0x41e054 GetProcAddress
0x41e05c GetAtomNameA
0x41e060 LocalAlloc
0x41e068 GetModuleHandleA
0x41e070 EraseTape
0x41e074 VirtualProtect
0x41e078 GetCPInfoExA
0x41e07c EndUpdateResourceA
0x41e080 GetVersionExA
0x41e084 DeleteAtom
0x41e088 FindNextVolumeA
0x41e08c lstrcpyW
0x41e090 LCMapStringW
0x41e09c HeapReAlloc
0x41e0a0 EncodePointer
0x41e0a4 DecodePointer
0x41e0a8 GetModuleHandleW
0x41e0ac ExitProcess
0x41e0b0 GetCommandLineW
0x41e0b4 HeapSetInformation
0x41e0b8 GetStartupInfoW
0x41e0bc TlsAlloc
0x41e0c0 TlsGetValue
0x41e0c4 TlsSetValue
0x41e0c8 TlsFree
0x41e0d0 GetCurrentThreadId
0x41e0d4 GetLastError
0x41e0dc ReadFile
0x41e0e8 IsDebuggerPresent
0x41e0ec TerminateProcess
0x41e0f8 HeapFree
0x41e0fc SetHandleCount
0x41e100 GetStdHandle
0x41e108 GetFileType
0x41e110 SetFilePointer
0x41e114 GetCPInfo
0x41e118 GetOEMCP
0x41e11c IsValidCodePage
0x41e120 CloseHandle
0x41e124 LoadLibraryW
0x41e128 WriteFile
0x41e130 HeapCreate
0x41e138 GetTickCount
0x41e13c GetCurrentProcessId
0x41e144 Sleep
0x41e148 MultiByteToWideChar
0x41e14c WideCharToMultiByte
0x41e150 RtlUnwind
0x41e154 SetStdHandle
0x41e158 GetConsoleCP
0x41e15c GetConsoleMode
0x41e160 FlushFileBuffers
0x41e164 GetStringTypeW
0x41e168 HeapSize
0x41e16c RaiseException
0x41e170 CreateFileW
Library USER32.dll:
0x41e178 ScreenToClient
Library GDI32.dll:
0x41e000 GetBitmapBits
Library WINHTTP.dll:
0x41e180 WinHttpSetOption

!This program cannot be run in DOS mode.
`.rdata
@.data
`.veyi
`.rsrc
HHtXHHt
?If90t
j@j ^V
Fh=X4B
to=H>B
<+t"<-t
+t HHt
^SSSSS
QQSVWh
tRHtCHt4Ht%HtFHHt
URPQQh
t"SS9] u
v4;5|>B
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
ENEY2i
ENEY2i
ENEY2i
ENEY2i
1(}.C(A
H">HwJ
s>UKj%]e
^\C_*:{
"5QNt6
&Z_Ecf>=}
S&|@Mgw
pv{eLJ
jsg6Na
]Hso2/
5raOb}
>!Pxq[
6"Zl`Yas
V3`2AI!
[5NDyF
l:]Yfw_O$g
vsICgx
Ukp{=:!
}Xnn_L)
!gYxz[1
UqJjLM
.rhkl~
qj?zU\E&^
3_2ZEO.h@
.<")X:
=^wUR&
}3^FA
OvFqaD
.iF=ut\9&,
Sc(D[h
\0n@sww
52x.&l3
%QL^ip
+<g<,0V<
/a9A~$"
P#QpWB
M+6@Gj
`tEW+[t
o\I7N
;QRN<#y
}"XY^N
L|jNP0f>[
gedB"Y
KG}yr#
2Hlz+gC
A(=I>:g
ueU_8G
v`Q3[~3Nu>
AD8wFE
@xO=5Q
t:(AQiq`
8KQnZ&
8VUz^-Y"QlP
KNBd4Sk
~]z|B=
(<F~ _
>g6[/ j
*0b&tM
Z>hd9.
q>XDr (
1z:'q,0
m't"zLFP.]Ff
Wqv<X-
96GX03N
D@9BJV
bC&~<7
<VD15g
.QR.n7d
i0NGld
8U=_c*
r/d52\[
n:I..Z
i2*|wI
IE&ql{
B:Mw)
x6O|wF
A!\7=H
qyXlp
kN+[%w
a.nzfS
YfI+{Ns
Nu$`B_
N5}F}x
.r6%u~
nG%7dY
r8nc0>
W{(~P
MWrhLQ,
|>{7N7
l[Jcer)c
5L>Y2>im}f\G
bV[HT
FmN:e!p
.@yH.K
HgQ:M2
*e/w7[
4QAFCR^
9K^s;wI4
qc."}YlH:
}]}$KC
H; t}n^
-FdU[#2
X&H3E/
"$FUS_
4@gA5f
5vlQZ(
l@0UkQ
:udQZ
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
1#QNAN
1#SNAN
cehiwah manamuxezexemuwetesaxuzaduzawor
darujuwihunuyun zabebedidez zizofokajitaxipogejipubowexo gifitutatopumiduc deguvofagebifut
VirtualProtect
kernel32.dll
LocalAlloc
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\rewi\mac30.pdb
SetProcessAffinityMask
HeapAlloc
GetCurrentProcess
GetEnvironmentStringsW
SetEvent
FlushViewOfFile
SleepEx
ReadConsoleW
CreateActCtxW
FreeConsole
HeapDestroy
FindNextVolumeW
WriteConsoleW
GetModuleFileNameW
GetOverlappedResult
GetACP
ReleaseSemaphore
DeactivateActCtx
Module32First
SetLastError
GetProcAddress
BeginUpdateResourceW
GetAtomNameA
LocalAlloc
SetEnvironmentVariableA
GetModuleHandleA
GetProcessShutdownParameters
EraseTape
VirtualProtect
GetCPInfoExA
EndUpdateResourceA
GetVersionExA
DeleteAtom
FindNextVolumeA
lstrcpyW
LCMapStringW
KERNEL32.dll
ScreenToClient
USER32.dll
GetBitmapBits
GDI32.dll
WinHttpSetOption
WINHTTP.dll
EncodePointer
DecodePointer
GetModuleHandleW
ExitProcess
GetCommandLineW
HeapSetInformation
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
GetLastError
InterlockedDecrement
ReadFile
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
EnterCriticalSection
LeaveCriticalSection
HeapFree
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
SetFilePointer
GetCPInfo
GetOEMCP
IsValidCodePage
CloseHandle
LoadLibraryW
WriteFile
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
MultiByteToWideChar
WideCharToMultiByte
RtlUnwind
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetStringTypeW
HeapSize
RaiseException
HeapReAlloc
IsProcessorFeaturePresent
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
q9_iiiiiiiiiiiiiiii
Viiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiid
diiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiioV
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
88JJ\q
iiiiiiiiiiiiiiii
JT8yR3
iiiiiiiiiiiiiiii<x
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii$
iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
<iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiii
;iiiiiiiiiiiiiiii~~
iiiiiiiiiiiiiii
iiiiiiiiiiiiiii1<
iiiiiiiiiiiiiiix
iiiiiiiiiiiiiii1
iiiiiiiiiiiiiii1Vm
iiiiiiiiiiiiiii1
iiiiiiiiiiiiiiiY
iiiiiiiiiiiiiiiY
iiiiiiiiiiiiiii
iiiiiiiiiiiii
;Yiiiiiiiiiiii
v-BWv00
Yiiiiiiiiiiii
<:iiiiiiiiiiiio
V:iiiiiiiiiiii
R*C*eCC
iiiiiiiiiiii
iiiiiiiiiiii
iiiiiiiiiiii
&R&6R6*
CCeemI
mZ m
iiiiiiiiiiii
iiiiiiiiiiiix;3
~iiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
u]00]"
TTK7TDK
YYY 9K
<{~~N{|}
H9r&[8d4
0rps@|}
A~d>dIm
$yeA~>AI
Q^~~OU
=cs~iK;
4lx~mLS
Osv~YJJ
=kt~_ED
}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}o
p}}}}}}}}}}}}}}}}}}}}
}}}}}}}}}}}}}}}}}})[
}}}}}}}}}}}}}}}}
5}}}}}}}}}}}}}}}&f
m}}}}}}}}}}}}}}
Mz}}}}}}}}}}}}}}}
}}}}}}}}}}}}}}}
}}}}}}}}}}}\
}}}}}}}}}}?$D
}}}}}}}}}}@
h7jN]j
}}}}}}}}}}}}
}}}}}}}}}}}}
xb.}}}}}}}}}}}}}C
}}}}}}}}}}}}:
1}}}A/
BKq}}}}}}}}}}}}@
}}}}}?%b
A}}}}}}}}}}}}}}}}}}T
}}}}}}}}}}}}}}}}}}
q}}}}}}}}}}}}}}}}}}
}}}}}}}}}}}}}}}}}}q
Y}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
ffpsIq
0N.5+
4+-``Dg`>
XQE=\^jK
ccccccccccccccccccccccccccccccccccccccccccccccccc_
ccccc8
cccccc}
ccccccc
$ccccccc
cccccccc
zcccccccccc
cccccccc
Cg~P8}
+Lmx`B
'm~~<S_
+2ROac
jjZjiA
dl:fdBz`
///$1s
$$sssp
MMGGGMMMGGMG
PDhGha
cc:@^z@@@B
(t%##=t
VjBjBBBj
<C2;ruz~~
Zd~$Fd
P`M<y|{
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzz
zzzzzz
zzzzzz
hhhhhhhhhhhhhhhhhhhhhhhhhhhh
zzzzzz
heheheeeheeeeeeeeDeDDDDDD<D<D<D<D<D<
zzzzzz
hheheheheeeeheeeeeeDeeeDDDDDDDDDDDDDD
zzzzzz
hheheheheheeeeeeeeeeeDeeD
DDDDDDDDD
zzzzzz
heheheheeheheeheeeeeeDeeD
DDDDDDDD
zzzzzz
hhheheheheeeeheeeeeeeeeDeeD
DDDDDDD
zzzzzz
hhhhhehehheheeeheeeeeeeDe
DDDDDD
zzzzzz
hehehheheheeeheeeeeeeeeeDe
DDDDDD
zzzzzz
hhhhehheheheheheheheeeeeeee
zzzzzz
hhhehhehhehNH!
eeeeeeeeee
zzzzzz
hhhhhhhehheH
eheeeeee
zzzzzz
hhhhhehhehh!
eeeeeee
zzzzzz
hhhhhhhheh
eeeeeee
zzzzzz
hhhhhhehhheN
zzzzzz
hhhhhhhhhh
zzzzzz
hhhhhheh
eeeeee
zzzzzz
hhhhhhh
zzzzzz
hhhhhhh
zzzzzz
hhhhhh
eeeeee
zzzzzz
hhhhhh
zzzzzz
hhhhhh
zzzzzz
hhhhhh
zzzzzz
hhhhhh
zzzzzz
zzzzzz
zzzzzzx{
{xzzzzzz
zzzzzz
zzzzzz
zzzzzz
zzzzzz
zzzzzz
zzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
3333333
!!!!!!!!!!!!!!!!!!
!^^^^^^o^oooooooooo!
!^^^oooo0o0o000
!^^^oooooo00
!^^^^oooo0oo
^^^U''
!LLLLLL
JJJJJz
rrrrrrrrrrrrrr
******
XXXXXXX
(Mr~~;g
/EPeQ3a
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

mscoree.dll
KERNEL32.DLL
(null)
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
@runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
pCONOUT$
nohacekadavinanaruze
xa xogegewe xejaxegexakeboxa nuworewurekihevab
BhBLB<B8B0B B
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
080824a0
InternalName
natgpiamizu.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
91.40.21.87
VarFileInfo
Translation
9Wedopabase guze mahucugawo gep wofi nujuvo jujanarocavifa1Xujenuxiwihudi meyi xigokamileyo lak guyomini gumCCujepogotujoded povafegubim royarudora fatic danihusu taravisoyijes
Vuzotuzul vujelu
Masepucec rajetofojeyezuw+Gawus mogojijorozar kedoha dirob kemaduyihoAWisirucayozo modutezehivuje lirud popimebakido gamum hidiharikozo
JijerepotuvNHetudu jebigimefixiful vodaxehaxoxuluv katayorazaj hibe renudixu lugujijeyovob
Jexapize lajemuzuhoj xexadur zuy
KujoxijodemWehawe datubu wolaloziz lohumaruxebac legagokif kuduhoyatoluz letutih tahebamuwomajug bokobesoxac menavijowem#Soxusefejig jujerosigetobe yute suy
Cofucub
Hegikugakehikaj
3Niworezilob zoxajahi fet lozaxu feneye hibocabobopoWTupebenetituk xeciva cucoloyo doxigo boxebozofilifom herukav dijavepiveyacet giwoja bopETujecivaxig lewekerutefa jor nozax keruwehowageg ruruyab gaped zehama
Neruvosodoxe toxe texazadimut
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.47212647
FireEye Generic.mg.a6cf11855cd106ea
CAT-QuickHeal Clean
McAfee Packed-GDV!A6CF11855CD1
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005890361 )
BitDefender Clean
K7GW Trojan ( 005890361 )
Cybereason malicious.8aec2f
BitDefenderTheta Gen:NN.ZexaF.34218.sy0@aa7b2rcG
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMYZ
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Androm.gen
Alibaba Backdoor:Win32/Androm.4fd05b3a
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.DA21 (CLASSIC)
Ad-Aware Clean
Emsisoft Trojan.GenericKD.47212647 (B)
Comodo TrojWare.Win32.UMal.ywycz@0
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
CMC Clean
Sophos Mal/Generic-R + Troj/Krypt-BO
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.LokiBot.4LQ5DU
Jiangmin Clean
eGambit Unsafe.AI_Score_73%
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/StopCrypt.PH!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.CRYPTINJECT.USMANJJ21
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HMYZ!tr
Webroot W32.Malware.Gen
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.