Static | ZeroBOX

PE Compile Time

2020-09-05 19:55:23

PDB Path

C:\bihigolezu\59\zoteyudagaxitu_9 xiwo.pdb

PE Imphash

399419c867e1b29b8b53fcd0cc79fbe7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0007af23 0x0007b000 7.95660334479
.rdata 0x0007c000 0x00005f34 0x00006000 5.28005939165
.data 0x00082000 0x0000912c 0x00001a00 2.93750076787
.cut 0x0008c000 0x00000272 0x00000400 0.0
.rsrc 0x0008d000 0x00047191 0x0000d200 6.41837936226

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0008d638 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0008d638 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00098c48 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00099514 0x00000432 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00099514 0x00000432 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00099514 0x00000432 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00099948 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000999e4 0x0000004c LANG_DIVEHI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000999e4 0x0000004c LANG_DIVEHI SUBLANG_DEFAULT data
RT_VERSION 0x00099a30 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00099be4 0x000005ad LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x47c000 FindVolumeClose
0x47c004 HeapAlloc
0x47c008 EndUpdateResourceW
0x47c00c HeapFree
0x47c018 AddConsoleAliasW
0x47c01c SetEvent
0x47c020 GetTickCount
0x47c024 GetProcessHeap
0x47c02c Sleep
0x47c030 InitAtomTable
0x47c034 GetTapePosition
0x47c038 GetAtomNameW
0x47c03c GetMailslotInfo
0x47c040 GetModuleFileNameW
0x47c044 CreateActCtxA
0x47c048 GetConsoleOutputCP
0x47c04c GetCPInfoExW
0x47c050 GetProcAddress
0x47c054 VirtualAlloc
0x47c058 LoadLibraryA
0x47c05c WriteConsoleA
0x47c060 LocalAlloc
0x47c06c GetModuleFileNameA
0x47c074 Module32Next
0x47c078 FindNextVolumeA
0x47c07c TlsFree
0x47c080 lstrcpyA
0x47c084 EncodePointer
0x47c088 DecodePointer
0x47c08c GetCommandLineA
0x47c090 HeapSetInformation
0x47c094 GetStartupInfoW
0x47c098 RaiseException
0x47c0a4 IsDebuggerPresent
0x47c0a8 TerminateProcess
0x47c0ac GetCurrentProcess
0x47c0b0 GetLastError
0x47c0b8 TlsAlloc
0x47c0bc TlsGetValue
0x47c0c0 TlsSetValue
0x47c0c8 GetModuleHandleW
0x47c0cc SetLastError
0x47c0d0 GetCurrentThreadId
0x47c0d8 WideCharToMultiByte
0x47c0dc SetHandleCount
0x47c0e0 GetStdHandle
0x47c0e8 GetFileType
0x47c0f8 ReadFile
0x47c0fc RtlUnwind
0x47c100 SetFilePointer
0x47c104 CloseHandle
0x47c108 ExitProcess
0x47c10c WriteFile
0x47c114 HeapCreate
0x47c11c GetCurrentProcessId
0x47c124 GetConsoleCP
0x47c128 GetConsoleMode
0x47c12c GetCPInfo
0x47c130 GetACP
0x47c134 GetOEMCP
0x47c138 IsValidCodePage
0x47c13c MultiByteToWideChar
0x47c140 CreateFileA
0x47c144 SetStdHandle
0x47c148 FlushFileBuffers
0x47c14c HeapSize
0x47c150 LoadLibraryW
0x47c154 WriteConsoleW
0x47c158 LCMapStringW
0x47c15c GetStringTypeW
0x47c160 HeapReAlloc
0x47c164 SetEndOfFile
0x47c168 CreateFileW

!This program cannot be run in DOS mode.
`.rdata
@.data
@.rsrc
HHtXHHt
?If90t
Y;=X,H
j@j ^V
<at,<rt"<wt
URPQQh
^SSSSS
tCHt(Ht
;t$,v-
UQPXY]Y[
tWItHIt9It
tRHtCHt4Ht%HtFHHt
t"SS9] u
vL;5$/H
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
6((Tvfu
hX4".+
s8LLf)p
<4LrlU
h:<B12w
4Xb=GL
E14 eD
ATIOj
668r$`@
m~MPID-
*8<(fA
lzSA=5a&6
Y*s#$x
EK[m!=
r=cvz,
,:iYS!Z~{
<%fXn-
"ZI,:#
Ebz6jz
CyqJpA
6*cQF6[YT3
nVp$x_
M:&~mw
}`?4Q1
N>b8uj
Cg@b"x
U&{.E~
+%v2zKaB?T"
Upz9]l
qEW'{:
O<\SPzL
LfE94P%^
4:sn4~
KKk0F#
')#EY!
t;txjB9
M-P=}g
5J.fQ
qV^YD#
3v~]L7
@Iff{*
eR!!!2
EfPH)
GRnO!S$
d{idW
/V~^;.
V{&n0
)GC:&8?%
gW-x:G
>Bs@Inc
d Yn4'
U<P{gtzY
b^ukLh
(cv`MD.]~
O4u.^@
t#`LzsS
'Ml!,w
$NdGwQ
1NVEwT
WvI7H
~ee9"*
#"9~ox
2dQv7KD
eMhMj=7AV
P,hgo|
kz5KAK
U:^wZFW4
ATj!O;
V4S$N
v9<0K6
@vlQAX
sy^ex%
y<</)iN
3-y!EL
c" U'~
%6\XW=
m&-xN
rV$Oe(u0#
jf@N\Ww
zu$'>*Ur
EH=zTN
>#;K,:
F[Oe$^?o
.{|)~7Y
qQ1Jb}DD
W/8knuY
.u9x#J
|6}NN"
35BI9g1=s
2>d^|>m.S
717}&i
>guqR!
BGbBQN
CYD#1S
>2pTcg
[8~B62
ZOBkm[
w=Md2P
\lcO.~!\
K&/a}}
C5=fSl
?1r_im
b~`Eex
)j%@82
}pik&w
L\~>C4
OOIU]8
t&t\HH%
C8Cd$V
;pj7c
ykln0\K
ki?`Xo
a61RRR
H6?C$?/
qf;n+y
B4t^u'l
6 X\l*
-z]m;A
d)VD9V
5,} Do
/$SPK>+
b$$yp1n
s!5^0jO
i7wPmFg9R^
S_;:{Qq
Ph&ytWC
;&[\Wm
wQ<O*p
}h[Dp
g^1T3v.
[^&Ob~
9P>,K{HW
fRN_V&K
s-`bXa
]xxt(/
bzHX/i
`ch+E-
Tw<"%8
ZXd5xu
8Jh|tQ
o!Oqhu\
,3Zf oJ4F
~Q >[S
8-HXO]4`[k
$.6MrY
y;<`BUCi
r)]%zU
,s|NLR
1gC )`
wc/aY]
#oC5c_rNFmsFE'f
z53S{Be
d?iB[P
%=h>
v$'7(eI
E`pkki
6&8F(3
F%O;y2N
>Rp#$=
%BbiJ%qtI5?
kx~g"H
(\tk)%7LeX
`9ib7^
~P}Du_Ou
<&Y$jy
w[_nQjB
TsbY JM
O2#{2CA]}
+?#GZl;
0kWMlao
wdrD'C-
5kR|$l
K'o1Tg
<Uo{Fw
2p|!B\aX"O
cprKAL
vNcZ%y
}i}wvFW
~SK}n:6
AJ Pi
0&JUwn~
D:e;Z?
_[\$2~
X%e,MA^{
*k5Dd+Dw
Pf=mf;
'Dx"]&
esuxn2
{ygL"
6F9@~\}
,fK|!*
#bIQ068i
s~<FI/B,@
}Sit3W96
(%7S=U2
b22%"|
-!;]Z
E:4DOY6
~Uv"2\
m|2i=zd
KD'KO7
yWQ|2}
] p}88
m!qh^}
Xm/*/fQY
42iD^S
^QHLb@
DA:k{=kW
hupy 4
!]~FlW["S
F=pj(N+
",P*IW
zm9Bwq)jy
rjM\r[Z
>4}-3%
C(9n0cY
}I5t/(
_"bvg1
b0h+mc
I<|_vs
.X~JgBk
(TsWr0
zAUa:a}
Lwf|XW
]GQ:nC
p_|3^;
V]Oo*I
F20e^}{a
8\(.7w0
MkL>a=&e
WLMSU@
-cIQ,+
lo.{v}
|QWWd>V
DtM.q'
/|33X{
y%>IDw
wW%93@51A
x",Y*u
`CZtV8
#],s-c
1#LW"^
W0SgC1
b8jMb>
~tzXMg
4PEd:
nfkrmv
DT<8S0
R8[`Aw
M30~x+
H!pDa?_p
A%nDH\
n"\(YJ(
*t]/r:
}:Gy-o
q5NBb=;WTD
#S?9=]
W0c6kz
Gr:x1fr)
'mhT96
#!Z}1A
F)}o"L
sqB!J8
}py]Nw[
hus\r0
EFnr7
=j@V$k`
6}6b0W
2[M9y.
1PxqnQ
O&tLY~Ph;a
TNstIQs-B
F+0*|8QNk
|A-(Q=i:
YPptqK
/\:yb7
.Bwk[iXb
`z1yMd
yG7e=|
9h%l9GU{5{
suI0VL
X3y[nbX
GTj33F
iW_<y[
NgNqNU
3$L,ou
(Q-Ftaw&,v
N\(RYh^
&p=$~P{
EPss@AV{
j7hiqNb
,C=}<(
g^)ky!
M#S-?dXN
^?Pv'(i
/:5S@g
W\'k'?
jme5xH
]a`+Yn
=capx*F
DP7!IL
llLt((f
v'Ei-$#
v9~\Xb
zk+s-^
(XCtt'cs
{pN.|s
xOX~)W'a
?cb.TE
@k(Y!8
{%[krl
3'wK}g`}
/TFbK.
{YFk9fm
i}K}:0
k,Y2vG
([US6.:
Vjo/,k
ahzbDWR
_d3;n,
Su:QJ[
bB8#T4N]
aY^_Wr
X|v@t
&sk}-.EH]c
da{\Tl]
8I{SET<[<
D:~/VRF
Mwnrgs
`+kw?\gU
- 6knwP
F[n0n7\|
</mD|@HG
c6]&6
tlelr+
77S"IC
99m;~s
yqHc9H
ti_V6A
N*mtJ1
703"t[
1y&W/5
t.wYWxd
FZ"4&
.\]>k(
7/5-*YU
A)f?WuO{bd?
dm@*tq8
Z,z5|+5dp
s<N$v3
o>OUs$y
e2Qm#W
#NE{Yv2)
LF!WV}
bQ}df#T
6`8Icl#
N_-.9c
GnHU0#<
a 0MKG
k?9hx0
5N%E+=
%6w6!wA
)&v)-W
;%(Z:9
D83Ank
]^8`,WN
]]fjC9
y|c(b1
4to1.pR
'xp(k${
2r}f'@
vBU?N|
Z87K!+
!s'N`
2o.xD8
_u:!>|
fdx$d1
G^|]<.`w
;0Xne8
J=};p]
D3V+Jm
/@]cQo
-E6M3$U
hFQFdo
b#o6%O:I
5FN]CU
]@{0j6&|
i1iPfr
X_/(i!
HVKs1%'
nT},q#J
epL$J4f
436^^d
>-C"m\
aPJxt5
-cuu9\=
Z/<Z7FxI
K3G9K,Y
l[bRX7
P)^Pj{
u.)~i'
5;eGI*
+UB\qg
4Fu8Y#
/G{>(44
#Aj4=D,
6m:{9g
-wGY-V
xJGbWIrM
?F5%-Yu!
::X;_.
sha8zx+5
+,Q;e|
?wdF6=
2S38}@
*.mtKX
Z@Kr>%
#,[R.T5
A4~[MV
/=SR2y
.f7JX~
ti 1]i
wi;IG
iFTHFli
hB3S;
rsCNMw
eSZ8ST
Wiy*)7
r`dEK(
2'ik6{y
X:=<b>
`3gv7.)
YiLhcP
dQ/#XGl
(jw#T19L
ns<TH\'
M_hY#y
mL0WP-
ve~Nlf
E@i&L<#N'
lI~2=Y
BYDH%^
e/rUJt
Sr^[B:[T
Oo|p{i
@#bGox
+-)!zte
)u=JF(6
Lf6mJr
)~bWY{
ek)2>Z
crHM%K
?'M?5I
#mOVY9}x-
Iu~I'%5
r,#.G[d
jA|}<N
&n N!o>
2,<$5
mnDkE'k
+;4b&(^W
AsK*
MwR~ $8
/%u0!,y
l}b&_DB
#U}iNE
!cZ3+T
a=i}CS`
eC*oO1
;T5tfc
X4}{AL
0Zn>8H
RzkZN-+
twbQEJ@
Z]iKT
5:VMjE
e;)m&a
_ys<wA
8l._s([$
|%X=Vt
2@07%U
Q!o/Gb
CXn#kH
g,v{n<
mjG:ku!I
/WQ}cd
yCb|g
zic `,?
=UG_t>5B
bnAMK?
0j<urH5
4$&#w
HTN@-}@
a@*#ih
6;vECx
O?9|Jxs
K{(vG.
^D<N!8p{
@(jf{QK4
I218hA!
F,E7m6H
|/:0M
M/x<c,
:FEiLf
aCVf/h
j%n7]SG
MJ<5ED
>=4*@m
g;Ej042
fP]7[BO
S6WXhs!
Tb7%r
inHnz-
+Ium#4B
TD;HB
UQCDYu\*
^21+ [
W9-Ef_SCWe|0Z
Dpxw'+
cl`=EB8
*13:<\
wY)^K#
yVvKxp
D]ngB,
%gv8uq
)w):\7
s0D6U3
ci`G:
(1??qb
[K>8Yck
E1j'\ Bq
)\_ )JCt
yNr;h^
*jM<?@mV\6
$7YCY.SC
uhh{`)
SVGT>t
dr.Q(5^
E]]de9
b)vJIe,4
tR(: \
O,kdkh
baC}{`#
;W_pM)
Ay{z#/g
T%dH%e
w75>)-
/Ymga
@^u^%k`rZsn
)m>y;/
%zz"x(
HC}+\Q
CR`=3s
~M<Nm`
1> !1+#
wG9!kp
Qfx:-5
5;!qJ'd{ov
SQ+ZYh|
1}8`X(
"sHG))n)
sg1<!D
@Z,g%,J
}Y#iYr
/2Y;B8
**({V
j_,CmE
%>[-Rp/
'Eoe67rJ
?T*ZuX
hI~)IkeM
!cG"[p
jh#kN*
XD9~of
G}B7+y
0X\*ht{
6so8l<
X{?{!3
BO23AQ
8D{n!U
{2K_}B
)%'e,%,?
\*Z$e"
r7gk_kB%
z2v0^o
!Ww+2;g#
0(d8WFDzqU
iEkB|i[M
%W$m"=
}z1Bk=
GAw"w$X[:
9zpQ<.
jPH7&l
H!(x{?j
6s@PYf
8Nax">
6+|v]D
cxaj7i
f4$PK[R
LZM,C{Q
vC]v1(
GlghJ
XAzG6@
@AvLJ8/
~h|{H?as+4
gzv)z.
ni9B,.
\P~sJ`
['9uVu
wZZz|>Ix
M'/nxl
iBi2Zp
m&f"ft
h>`~VxC>o
O?a80#si
nWeUQz
Yh<l~m13
L/CNfVc
V}U&/h
2LG-a<(~
ejira;j67
g&>tm`
Y6[9f\~
P?sy}qk
8y4:qM
i/jm>%Y
a3=fN)R
3W^@#1I)-
Q{-S@f
co#moG
uId/o4
yVic*
Rzm|Q7
,L:VY-
U)"+Ds.j
KUHUL*
f7-3vx_
&ffn;;+
ZZ;lO*
z{XqQl&
bU+~2H
Y^S!-PZN
QX>/Swg
=H$h$ Rc
7xe~Ood
U`+i4)
v)4$2^
aUYrs_
xGN%R{
aNdP[l
`{9R[2
SmAQ8j
+%C7AB
%We*?
5zbk79G
vE8'gEP
g+p5ZO3;Y
q&=msA
W>cDS
VT1rcI
h&:1KP
Q3I~b8
_D)i+:
XI!_=URq
p6&Ii#
Q=oE~g
I({]mxI
[;`kVa}
f]uwx<Fd
W?}$6sQC
Pir2_>@
f!<&-m
[/#)L}
"(ph(?
N-]I]$
OxDomAS
U7jI:V
N.]}0^
%J{OIG
rgz{5B
0'W_UE#
kdCxrE
V^G<QD
w89:H)
T_Ep:
E;L$hDg
+j0IrB
}e%leo#:K
dD0e)0
@}3wB02
+t:eKY
Xc0K2/7s,
bHNbi
w2TNtqH3W%
~I~K1
Ozh%43S
Q=bNr=
M"t4_sS
[%Q>"kC*n
"PCsHk
+&UWKS
~<]}Hr
otAeKBb
qyH%y
:yA0KP
OGfsshR
f![19<
:a;S7L
DX^~#_
+9-m=Lx>
(RpEZ.!.
V,_8rZ
Y`E#7W
Bt`d6S
2~4'wL
6By;Q^gAx
m<a*/+H
2KxJ@Z
Zrm)T8
e-f{S9j
9,N1~Z
gGI"~au
Vd&3"
=TpQueP
&?fzg37q
o:l8]GI
A<|!qp
.QN[S1Z
b?MEl
CHKTP)
Qc/;J
.]I}*?
xu<~#A
@{4NJ-<
XLnM,r
R!c$i3
v5{)iD;
sK*l[|
gtEhw91-
8@s3Es8/
:U^$.~
NmN':(
7DtVPw2
KK0ylG
@~;"a+3
{Tgk@]w,
:eHmU
m7mI7?
_ZWgF!
l@_TO_
\l" !k@
:)TCa?g
Bz{?3
>(`:nX-N*
BRt/01nKg
4>:tU"
,!Izg3|
$G7{6R}X
fe+wF^}
QFi{i+0#
_Thn!5
U%4E .
gs_?>Z%
Z[WXb5~,
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
Unknown exception
bad allocation
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
UTF-16LE
UNICODE
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
bivucimihupibifonevenabilowosuwuxocuremucebisenomur
lixuhurejofakamamemoteku
gunuhoboyibaxuzagasawa
VirtualProtect
kernel32.dll
LocalAlloc
invalid string position
string too long
bad exception
C:\bihigolezu\59\zoteyudagaxitu_9 xiwo.pdb
FindVolumeClose
HeapAlloc
EndUpdateResourceW
HeapFree
GetEnvironmentStringsW
SetConsoleScreenBufferSize
AddConsoleAliasW
SetEvent
GetTickCount
GetProcessHeap
FindActCtxSectionStringA
InitAtomTable
GetTapePosition
GetAtomNameW
GetMailslotInfo
GetModuleFileNameW
CreateActCtxA
GetConsoleOutputCP
GetCPInfoExW
GetProcAddress
VirtualAlloc
LoadLibraryA
WriteConsoleA
LocalAlloc
BeginUpdateResourceA
SetEnvironmentVariableA
GetModuleFileNameA
GetProcessAffinityMask
Module32Next
FindNextVolumeA
TlsFree
lstrcpyA
KERNEL32.dll
EncodePointer
DecodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
RaiseException
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
GetLastError
IsProcessorFeaturePresent
TlsAlloc
TlsGetValue
TlsSetValue
InterlockedIncrement
GetModuleHandleW
SetLastError
GetCurrentThreadId
InterlockedDecrement
WideCharToMultiByte
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
ReadFile
RtlUnwind
SetFilePointer
CloseHandle
ExitProcess
WriteFile
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
MultiByteToWideChar
CreateFileA
SetStdHandle
FlushFileBuffers
HeapSize
LoadLibraryW
WriteConsoleW
LCMapStringW
GetStringTypeW
HeapReAlloc
SetEndOfFile
CreateFileW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOAF
'OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO/
OOOOOOOOOOOOOOOOU
UOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
VOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO&/SS
VOOOOOOOOOOOOOOOO/
OOOOOOOOOOOOOOOO
VOOOOOOOOOOOOOOOO
VOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO//
OOOOOOOOOOOOOOOO/
OOOOOOOOOOOOOOOO
/AOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOY
AOOOOOOOOOOOOOOO
yOOOOOOOOOOOOOOOYVtS
AOOOOOOOOOOOOOOOY
/AOOOOOOOOOOOOOOOY
AOOOOOOOOOOOOOOO
AOOOOOOOOOOOOOOO
/AOOOOOOOOOOOOOOO
AOOOOOOOOOOOOO
OOOOOOOOOOOO
OOOOOOOOOOOO/E
"OOOOOOOOOOOO
"OOOOOOOOOOOO
OOOOOOOOOOOO
OOOOOOOOOOOOV8
OOOOOOOOOOOOV
=te=ee@
VHOOOOOOOOOOOOq
OOOOOOOOOOOO
OOOOOOOOOOOOOA
yOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
11111111111111111111111111111111111111111111111111111111111111111111111
11111111111111
11111111111111
1111111111111
\1111111111111
1111111111111
Fx11111111111111
11111111111111x
1111111111111
;UUz;0
1111111111111xF
K26e;`0
1111111111111#F&
1111111111111
1111111111111#
P1111111111111
1111111111111
P1111111111111
1111111111111
1111111111111TF7
eH1111111111111@{
1111111111111
8=11111111111
+1111111111
1111111111
1111111111=
1111111111=
11111111113;
1111111111
111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{*'
{{{{{{{{{{{{{*
{{{{{{{{{{{{
{{{{{{{{{{S
{{{{{{{{{{
{{{{{{{{{{
(8{{{{{{{{{{
8{{{{{{{{{{
{{{{{{{{{{
{{{{{{{{{{
{{{{{{{{{{K
{{{{{{{{{{
{{{{{{{{{{
{{{{{{{{{{K
%M]${{{{{{{{{{
{{{{{{{{{{*aVV
{{{{{{{{'
o{{{{{{{{
{{{{{{{{
{{{{{{{{{'
y{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
F?s(\;f=
1yssD{
||||~~
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:v3="urn:schemas-microsoft-com:asm.v3"><assemblyIdentity version="1.1.00.00" name="AutoHotkey" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility><v3:application><v3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns:ws2="
(null)
KERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
GMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
vemetahupofutadiki
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa
*Vezuzoladec mehumusutonobaw vefadusococavu1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
VS_VERSION_INFO
StringFileInform
080805a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
75.54.32.5
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Zbot.m6l9
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.37910886
FireEye Generic.mg.f066b1dcc3c84091
CAT-QuickHeal Clean
McAfee Artemis!F066B1DCC3C8
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37910886
K7GW Hacktool ( 700007861 )
Cybereason malicious.5fc1f3
BitDefenderTheta Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Trojan.Gen.9
ESET-NOD32 a variant of Win32/Kryptik.HNDM
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.DA22 (CLASSIC)
Ad-Aware Trojan.GenericKD.37910886
Emsisoft Trojan.GenericKD.37910886 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Sophos Mal/Generic-R + Troj/Krypt-BO
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.Ilgergop.PGLDWC
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Packed.vb
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/StopCrypt!ml
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.Generic.R373480
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.MalPack
Panda Trj/Genetic.gen
APEX Malicious
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
eGambit Unsafe.AI_Score_99%
Fortinet W32/Kryptik.HNDM!tr
Webroot Clean
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_80% (W)
No IRMA results available.