Static | ZeroBOX

PE Compile Time

2021-01-06 15:21:11

PDB Path

C:\wafatasu76 zecawuroyunuw\hayokesurey\kidocoza.pdb

PE Imphash

6ddd2d9f36cd353ba9a4fd8b55b9d3cc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00089880 0x00089a00 7.97110853307
.rdata 0x0008b000 0x00005c5a 0x00005e00 4.74006405574
.data 0x00091000 0x00009104 0x00001800 2.91512088809
.xobolaw 0x0009b000 0x00000272 0x00000400 0.0
.rsrc 0x0009c000 0x0003c998 0x00006a00 6.01011990673

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x000a1708 0x0000000e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x000a1718 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000a11e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000a11e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000a11e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000a11e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000a11e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000a2358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x000a2358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x000a2358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x000a2358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000a16e0 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000a16e0 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000a1848 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a1648 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x000a1860 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x000a16f8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x48b000 LoadResource
0x48b004 HeapAlloc
0x48b008 SetMailslotInfo
0x48b014 SetEvent
0x48b01c GetTickCount
0x48b020 TlsSetValue
0x48b024 FindResourceExA
0x48b028 GlobalAlloc
0x48b02c FindNextVolumeW
0x48b034 WriteConsoleW
0x48b038 GetModuleFileNameW
0x48b03c CreateActCtxA
0x48b044 GetProcAddress
0x48b048 VirtualAlloc
0x48b050 PrepareTape
0x48b054 GetAtomNameA
0x48b058 LoadLibraryA
0x48b05c WriteConsoleA
0x48b068 AddConsoleAliasA
0x48b06c CreateFileW
0x48b070 GetProcessHeap
0x48b074 DecodePointer
0x48b078 EncodePointer
0x48b07c GetModuleHandleW
0x48b080 ExitProcess
0x48b084 GetCommandLineW
0x48b088 HeapSetInformation
0x48b08c GetStartupInfoW
0x48b09c IsDebuggerPresent
0x48b0a0 TerminateProcess
0x48b0a4 GetCurrentProcess
0x48b0b4 RtlUnwind
0x48b0b8 SetHandleCount
0x48b0bc GetStdHandle
0x48b0c0 GetFileType
0x48b0c8 GetLastError
0x48b0cc SetFilePointer
0x48b0d0 TlsAlloc
0x48b0d4 TlsGetValue
0x48b0d8 TlsFree
0x48b0e0 SetLastError
0x48b0e4 GetCurrentThreadId
0x48b0ec HeapFree
0x48b0f0 CloseHandle
0x48b0f4 LoadLibraryW
0x48b0f8 WriteFile
0x48b100 HeapCreate
0x48b108 GetCurrentProcessId
0x48b110 ReadFile
0x48b114 Sleep
0x48b118 GetCPInfo
0x48b11c GetACP
0x48b120 GetOEMCP
0x48b124 IsValidCodePage
0x48b128 WideCharToMultiByte
0x48b12c CreateFileA
0x48b130 SetStdHandle
0x48b134 GetConsoleCP
0x48b138 GetConsoleMode
0x48b13c FlushFileBuffers
0x48b140 HeapSize
0x48b144 RaiseException
0x48b148 MultiByteToWideChar
0x48b14c HeapReAlloc
0x48b150 LCMapStringW
0x48b154 GetStringTypeW
0x48b158 SetEndOfFile
Library USER32.dll:
0x48b160 SetCursorPos

!This program cannot be run in DOS mode.
`.rdata
@.data
.xobolawr
@.rsrc
uTVWh<V@
f-00f=
HHtXHHt
?If90t
<at,<rt"<wt
URPQQh`A@
j@j ^V
^SSSSS
QQSVWh
tRHtCHt4Ht%HtFHHt
to=xI
tCHt(Ht
;t$,v-
UQPXY]Y[
tWItHIt9It
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
66U"ua
JV~QfUWa
5`cI<~Z)
3^"rq1)2
SczBXg
@mcdqWl1
>6)Lr'zi
ZeHPgQ
4P`-"6J
7-*oDC
"X601!
ezuiT9
giF{}$
0Co%
&f,G0{
E$Rwk^
^Fmc~
C[eKoc7
RH/axS
"|}ef29[
vGZSDG
v)FCQ
|?a /d
RVd/GhIi
#]XE|Zo
<Tt+6'_
4Qs:#8|"
1q_ohh
f[!:H?
0H0K<jw
@U57zd
H{xIq~
VsI4Tc
@AIF1B=$
=V(wY2H4WZ-
:k5"pO
8+hSCh
Y=RW(r$
f$5?==-|Lsr
~Bx}:e
:d"1@\
-/87?:
Z"8emS
0HkX}
|Y(tXd
)3rG\V
""^c1I
*7w~Dj
<EGcK8
Mp^LK
9#=k5o
8)=eaL
h2j1:)
{p}>t2
lW7#U>
g7SQm%
31-m" ,
as#;N)hy
)gtE\Ux*_[,HD_
"U';(
4VG>2S
_{ 839
w}Ho{(
|#*qz}
Xngy)ALJ
%K9Y*7"C
CTB2KrHo
&La~^4
[]k9|l
z<AB&g
7)ovr/a
6u\e=X
/M1e$l*)
=eKKup
Z)4p,w
']%WH{z
b6MW]l
pcw:R2
1MOPg"
F"Qjp_
:;xaaZ
Mc}5#U
iY(yL8v
uP?)i*&
^td7PTO
~Fc<ID
;Epe2]
:.Hy<8
D7wRvvq
HgICb
]V9x-?
]WW%6l
)rdd}"d
wgF%\N
+x}o%
HD3kY;n
|8aChyd
5;o5X\
s~AkF%$9
q 6<+7
n\+%_
e4Zla^
1 z/T
Dh6np'
PWwxl
jSpIC1
$fS^64
El2eh3?
R; n'W
#KE]D?
9PWT`
d}`xX;D
gd.,_!
P=NX(G
@C7T>W
bgk.qH0
+`#KJd
Kh=CH1
"N_Sw=
s@VY)a
Uj9R3=I
~?lA$F
B{yUO\
"'5;ZJgC
<*s&ioR
V{MoH0
'#|H(
}'%q|d
(eCkGVVU
1~H^YC
9,oF{QL
ph;@[t
t,q0sk
tZ&3y9
4Xk~3%
t]|~m
.eUhF#
JtNk z
yv~}p%
u3o ^MK
2*yHnl
jqK~7l]
EHXBM]
N7!3mt
L|j~}C
i<j>t>
lL)qF|
dK(mM e
hZS5\f
*OqWX|
*r5q{E)
JBbU)y
;N\0"bHH
hCI}3IX
yd{B:Z
^FW_vuUN
C]Qn"'{[
)"DEa|
y|M'T^
&f<Oa&
'H`(\V
_e6z]9
2ZUoet_
"6X+Yx
)QV|>k<
dRIIBH
0>Cu!<
r}}'<:
]tk#tVm
q]+L<E
$84,aA
zQ~-R-
}y7NF6
.S.&*{Rg2
0V"mbr
;[zGjhyD
&B5Zn?
% y/3xrP;u
QfDe<I
4a4up),
!/'$2R
[T[`P\
_%,Lh:@
gp_BMr
zZ%Pz$
x$(*?.
pdraT_~
r;fu 3C$
(yuei
UMAMU$
1z3o U
Vp4YN>
bjVkY.)
H06P\I
(=08JC2
S1XP\b
YshByl
7e/,]A:Wd
8"(N0EVM
oPDJ%}
}'WixQ
*xF7$1}
0>@ \D
-WU&JW
!,Yn4?9
nE+?Xt
@}m|S<
~l)^"9
!O|P+@$1
Dw9HVba
^/U%ba
-Y0pV:
1ddz;h,`
Z|tm\A
Nz#w#7
HPskuFx{
R`VYYv
o@- jk8
4^h6`UOGt
hDc9{T
/mZ.7f9{
j#_Gi,
mJDH8x
^Yz|,|
8_4XzA
h.},tyv
EloQDW#
i)]k*(
P"2BN\
ec6f`++1
y?i1#C
j9;!w/
JB**@+
"%~qr1K<8
A_\i1t
)eud<p
i%6e$$
_0~R8sS
;Lj` ;
~{XkUs{B
Xr({Xb
80Mrb*
3d{xP3i
$p\0bA|
>_aA:V
aIVu(b(C
.FoJ j/
`uPekR
nj!+Yc`
#7E7JO5
TWkezv/
Vi\o+B
!yt:3c
CXa2"+."
0C=s:$A
TP0SW*
{/%kz\
dT3^Q1
>vxkut
yp"J70Z+
YaK9+Cc
[-d]:m
cS:$:5#_X[
m4oy$U
w/ZZ~5
e)sqZ
{}rmHp
A[yoLLh
\j5ef7
G?`S$wS
jfA,6
-/82iP
( fB#d
dmI!?w
Gq`+~;
+<Uj-G
'~'wY>
Pp6K:,Y5O
OKOAQ:
6wK:$!V[^
~ph*LJu
|g0g}@N\
o#O'$c
/3:^6Da
Wh`GPt
:"RUME
;6N" $
Av&}y&
=:]dPq
F|>t[]
kPBZnH
$pd* *
`KOhzRU
^,/zq1h
;Aul}7
;t b8]v
^,ouYAL
z1,2L0
0l>+eL
clVKv[
%Yi\QXx
j)8xC*
1t^!6B
^fB".c
j;"Lk6fj
yO8`QY
?sj=7#
Iyd)^@xe
?+,0h|<
u#|_4N
+VR<^?RY
}J{3uM
{W-&Zw
r}w7(;Rz
7}9;a.
qZK{10
P4M|TA
+'UDUE
ui1B6^
C;2yJ;;
6@v4P(
xz$UUt
p[5!"*
@&[5{W
]F@oco=
2wMQyv
bul0=|
5`VW\7
9 :.i-H
1^kUE
RB8Gs.
W$xM)
Gdev-,2
NU=\R&+~'
v8W1{
ggyCel{x
k1_Md*
D\9jU"
.=J;Q^
."p5MY
d C`bR
rv9Xmy
Q3>5ad
CG^<M|?*I
Fq,]Xqr
f?rB:)3
(*Q?.X
w@y/z1WN
p}"I:*
H ^cG8
=/t|m)
1.h7k]
L};X\
HsCuEy
j_FO<G
;#7*X`
XdA]sx]
wFbhJL
iA?G^:
+Y.0s|)
"]aDN]MK
z;YzNo
Yt5A%L
)cY6H-X
^G920q
><xzJg=
YmqX*u
FfWIWR
am<";L&O
0WDUrM
eKlkFG
&E"$^L
^_,yHx
5|we17J
h<K}*R
o""}^:
79UT3O{
^5Eu9U
qGHW~
@4=SYQ
!?~Y5$
U-IIA?^7d(
ZXSt?x
.g+zeB
dV`jZ1
9|Vxtl
JF,qBB
'7@be
=}CaZP
-*Kr5?
F$5+u
S=I$/P
F_#oP_|A<
Me[*'<
!dKWua\F
ol;ft
V~i73Bz=
)K^<?Bl
9WpLlz.
WeD0yA
05C bO
D%iHwm,
`J)^,i
xE(S=P|
rbE"]h
~x?NoK
W?Oc V
oYp F$L
~xD+yg
LqPH_VR
I2Qe)
)(>hFj
*{.d(V
 BeSq6SD
oJ^RRQ
Zrcm:vt
6;RXN3
|sk:ex
5W46<T
GVbGNuE
aw(8/$
dEByX0
|zr4LE
h0c4-nS
A!8^7"Z
?K?4^"
2u[zr}^
Q^rmG:7
oN`pI.?
/*M7sC7QZ
z]?4z*
UYU+>Q?
(+"{9Dc
*jv*EE
Q~3Y;[
e+[bI;
vM8u_7_
cY;Cn
Sb5L@U&
>PL4.:
0ed}c4
igvb"@
=5J8=z
6Nq.~)U
)q(v1c/
E^/_kB
}rQ'vv
nFfDEk
nJ{Un}
>DQIg
@4;yrf
6(N cU
t5(mGH
2$=0vW
5;N"Vs(
*-!_:X
,(@\'>
.oOrk
rRQ,fR
V!CcFb
q!q(VoWc:W
sq/~LP
OcT4:Z
&OnDsV
xF{CU_
|pqMBs
<Nan<Q
MgKCe?|
(} 16&
IdaTed
S5zDd`
kneI9rqd
@`@k($
mL?/1VeV
@&H'7&L
l{}R&!#
-bQ`Pr
1Z`wF.=
`*F|MP
^$RsWS
VS0(jv
)cwg|ax
cgmx`83
531dys
v)"uE#
T|DK.3L
XHVCu+
1eIzd:`
Hf"4&,
7ArfPCduf
fcC8oS0!k
ex2O=E
PX|UH!
R'rk5"3
N7YA$^
L>Bq7L
ibO>;<
|nW~=N
2$meym
D|F0t]
qC^+Mq
*LLdYBi
5;KC}m:
}:$>&%n
|0 'B;c
v~{4IM|
=qX9dY
[XQu,`
Fh[V`K
BN:m,Y
W,XRM!
wsShQKWB
r3kKuQ
z,l%#i
:1p'G
s(o3nP
-G(y8_2
:|56Qk
#<0v$?
uMNI5
kYfo.n&
E>zI(k
AoOnL;S
WDd],Q
S)1ySXDec
(szK0T
XF^UCq
kc,)8CS
r5W`K'|$
bIp'&a
G~Zn[:Q
5GzKdG
n*E;TO{
$!O7v$
k<}Q\m
_'<M68#
H\c}}n
]V{"`,
6Hd~,>Y
<(zjeP
~0xU# IN
jv=OlHUI~
IHwbPi
b+Zz;*
yFVKax$
8$:coN
ak5W@*
GU+m7B
,k]f&jc
]*%#2K
`27Re5fK
lUnGK:
,?1GiY
Py5YJzF8
Cm_#eO6
T\^rVl
-`U('BH1
Uh|AHn
46*Y$k$^
w?ICBX!
$fY1pf;
,[@}'B\Zw
aYb9?=
_xV{10
vptQD=U
5b91>%
7OmA>|
ppk/WbR
uS!viFP
Jx<(xo
lgQ\fW
:Bj(zV!M|
KzV7/S=
Z'Owt\n&Z
_mw;d2
2XtG)B
'@2E9D
y;Rx,n
z:Pgw4
]P3>AO
q}DDk&
C.>co7
OJ52RZ~2
60pGGP
y{E@|M
uYu+'T
TCyfv
p3%LAg
t}>5p
N$x`6q36X
`vn~"0
ZUCB\B
;;$y+Q
]\U34X
fOh7Du
aPFZ!6$3
2k,Oe.
bGZO}G
{0m6&Hv2y'
\1hp>@2
r+$)kf
2+!+wk
Jo2Njz
fl-XR[{
VM".;l
WjcZkWf
8*%}y6{"H
rB_e"s
I^U|l<
=Jj=m0F
WQm]<0'
la/LHs
>v|vx+
40~=/2l
6??hLyRh
B|$jkV
+7!`>,GWkQd@
/!z_Oo
XQ:op)ou
.B0A(S
<1"]tt
Y@{\[DH
E1P0S/3
l^:0o,
!}/*9h
]Z:zQX
KY$R_d6
Dr*t'>
Mb{+a6^
A@jlxeK@l
Cr(6>8:I0
YGw\Z?
1}dOz^O
R&@;G5
Pl *,v
CR.=R0
W9IY{\-
f8.N|Ud
icw[<)
z[[p-4
FL3sIr$P
MGnmM@
u5^zK=?
SqMT~4
?4S~^Q
B4Z_5f
8:.B4QA
|fCbIp
PuYbu>
?&_|:{
^I23t
a=T\+E
c?mTg[
( Grpy
|=NX=f
f,K2}.
H[ethA
m$}*.dz
CL&NEd
4hZ<4q
ZolP1x
GA~.-A
t,F9534
]uq \\
s8]VfC
`i^P<
HQ,u{<i
]?j9v)\
%F)SQP
XDvr.=
wdlF`-0:x
UDj@Y:
v8XV[Z
_vS0N4
'!C!*K90
0aa2>~y
>4C)A{
/.=:Dk
6x=H]F
q7j*8#
$&GNC=-
3=a!YJp
Ex{Pw@
Rz(6C(
`H4TA
.=Xa>EL
N#&803
2idQft
*A~w%'
b3RIk=n
~([Mga
[ L%G25
|,Hx0xUc
^FKTd2=%
okn3XO7
c`N&U]
m|=Dp:I
P@9#sb
}fI;6=
w0++(D2XI
wEDKG9*4
a;x{mj
R^@94@
-HFc+i(`Di
6I?<z_A
bE'H~s
SoH)TX
w6{,'-
YBL-cH+
FAhDOe
[ n%,w
E|WOp(r
Be&Jp4
"_fK,C
%P7>2f
XI*ixO
sQVJ@2
Cw#&=R
>A(oBD:
9znX8\
}XE:St
M{qJu
6gH#@%kx
gWwdnt$
1e3?jM
\A \2tC
H!URE6 c
_pBKi=!
vdU#t/
(pKo%?G
Dsw%"8
H3JN.w
0TtOM!
M[[0rR
]]61 %4B
U""F1CU
Ht LJ6
i8b\bl
}Pzwa>
U :$*
*vpyOr7T,
K%(vas
&FGi$"
0(zbU$
EY#O>{
~6<<KC
*}/1ia
8.t}
CU Y[a^
(]pe"{}
ctC8'v
Kllt7,
3Rj\h5k|(
)!"zS!
_r*t:7,
C=LB5|
MvT+s9
&@\~J*
O@B\mG
xpa]/c
vGKrLL
oh/rH"n
BMhW]_
r+k]T$
}=a[.NP
qOQS!i
3fQMN
p+tgQ'9
[*/`gC
6Oklb.n
n|f9b=
E9(+Et
S5ox/`bG
+5wAjo2
*:NW^x
1,d0Z'
,YM-(g
ZAAn[S
^./L@y
p{s,lQ
q>s;IWo
[zvUJoR
:TLX7.
YQoNN.
&4^{J[
c`~4G@Sm
v8^uE9
2fDj;
!CQBXw
@:RlcWR
T'!LBU
~o$ojd}
S|9w(<-
h23^%M
r>Iy~$
h3Pw3g
!Sy .6!
dYJq#0
5?dr=A
='-orn
s=B8>k
W^33zu
{XZI>'u
'Z6ZH
a6w:S$
cn*6La
P5!elKv?
TI/2^#
vg-|A,
;oqQjm
Obl=suv
RN-g*g
BWPkD
J-KFA.
:ctZMC-
*h_d@?
<D+'Xd
C9CendW
,j2CrF9
6z7'6v
Y0K=5d=
1YX]V4
uX>.q;
myW&yl
JI/8g|
7g7a}ml
Kjs^G03
ue{v"f
GrFbI:Rv
!~[9B"
yUPl}y
80OV!ZgL
q>6si**
cedkfRI
RaH%<{
6(J~(i
Os~P/[
fWu"*<
X.M%}V_
^ha`t"i;
qmZ3#=S
]@vX:!
Dvs:1gWGLj
]dx8|M9
1I34<)+-
4GX3=4
O%HiN^
%(gik[
C_)]iJ(%_~
Aon#U,2
F`j~0)
QyQC{"
^@pGH
pOBa@\
[4JT#L
\yC[9b
(B;L/&c
Zm~&<4Q}
?_0B{(X
a'LRL>
OSd0:+bO
wj/+1n
LO/ +^
~-qxNP
**2:?\[
[g$v@9
d/+Wt;
de#AT!
q#~SI(
0<'b-lu
q[?;4-
Al*~\L
",)#!p
5#y)wd
m>O<6/U\fG5
S@IGd
CorExitProcess
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
RUUUUU
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
i^^?(>
Y:/(A6>
<GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
VirtualProtect
Dad zupabozusojay
Zepakubagorore zeper ton
kernel32.dll
LocalAlloc
Yulun xakay boz makige
C:\wafatasu76 zecawuroyunuw\hayokesurey\kidocoza.pdb
LoadResource
HeapAlloc
SetMailslotInfo
SetEnvironmentVariableW
GetEnvironmentStringsW
SetEvent
FlushConsoleInputBuffer
GetTickCount
TlsSetValue
FindResourceExA
GlobalAlloc
FindNextVolumeW
SetConsoleCursorPosition
WriteConsoleW
GetModuleFileNameW
CreateActCtxA
BindIoCompletionCallback
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
PrepareTape
GetAtomNameA
LoadLibraryA
WriteConsoleA
FindFirstChangeNotificationA
GetProcessAffinityMask
AddConsoleAliasA
KERNEL32.dll
SetCursorPos
USER32.dll
DecodePointer
EncodePointer
GetModuleHandleW
ExitProcess
GetCommandLineW
HeapSetInformation
GetStartupInfoW
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
GetLastError
SetFilePointer
TlsAlloc
TlsGetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapFree
CloseHandle
LoadLibraryW
WriteFile
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
ReadFile
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
CreateFileA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
RaiseException
MultiByteToWideChar
HeapReAlloc
LCMapStringW
GetStringTypeW
SetEndOfFile
GetProcessHeap
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
g=a=SR
wGGPPnyrv
Ajp|kHR
*80}^JD{
AJ{|GL
Ibi|}Vcz~PX|
2RQ~LLK
bg{|hk
h"[{m(;
pR}p&;
_Zz|SX~
j^|{v|
CrWz~C\
Yea{|~
Dpz~bGC
ts{~_W
}Q_~zHH{
ZYe{z}
tqo~|k{
mscoree.dll
(null)
KERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
HMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
teyawuyozahamigusimuhobusokuveragen
ladubokomumajopovugavatezuko
AFX_DIALOG_LAYOUT
VS_VERSION_INFO
StringFileInform
080905a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.32.31
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Jaik.49038
FireEye Generic.mg.faa81ed90ab9f9d0
CAT-QuickHeal Clean
McAfee Artemis!FAA81ED90AB9
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Jaik.49038
K7GW Hacktool ( 700007861 )
Cybereason malicious.98b372
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34236.Mu0@aWA6TFiI
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Win32/Kryptik.HNEC
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Chapak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Jaik.49038
TACHYON Clean
Sophos Mal/Generic-R + Troj/Krypt-BO
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Drixed.jc
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Racealer.HA!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan-Stealer.PSWSteal.UDJOUL
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
MAX malware (ai score=85)
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Heuristic!ET#98% (RDMK:cmRtazqAsyg6+Eesyu+638mtAZJI)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat.PALLASNET.H
Webroot Clean
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.