Static | ZeroBOX

PE Compile Time

2020-08-17 11:29:13

PDB Path

C:\gadaboke62\dikitidala81\bajakusamovoc_hividali-rerakuro\dis.pdb

PE Imphash

959e3f7a6ddd7b4ec96854ed6fe13765

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005bcf0 0x0005be00 7.94583068128
.rdata 0x0005d000 0x00003b30 0x00003c00 3.86790067672
.data 0x00061000 0x00008ee4 0x00001800 2.85445493293
.rsrc 0x0006a000 0x00026a50 0x0001ac00 6.37265122185

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00083420 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00082ef0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000845a8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000845a8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000845a8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000845a8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000845a8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00083410 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00083410 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00083550 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00076310 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00076310 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00076310 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00076310 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x00083568 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x45d008 CommConfigDialogA
0x45d020 BackupSeek
0x45d024 GetTickCount
0x45d028 GetProcessHeap
0x45d030 ReadConsoleW
0x45d034 SizeofResource
0x45d03c InitAtomTable
0x45d040 HeapValidate
0x45d044 GetModuleFileNameW
0x45d048 DeactivateActCtx
0x45d04c GetLastError
0x45d050 GetProcAddress
0x45d054 VirtualAlloc
0x45d058 HeapSize
0x45d064 GetAtomNameA
0x45d068 LoadLibraryA
0x45d06c WriteConsoleA
0x45d070 LocalAlloc
0x45d07c DeleteAtom
0x45d080 AddConsoleAliasA
0x45d084 FindNextVolumeA
0x45d088 LCMapStringW
0x45d08c lstrcpyA
0x45d090 WriteConsoleW
0x45d094 CreateFileW
0x45d098 EncodePointer
0x45d09c DecodePointer
0x45d0a0 HeapReAlloc
0x45d0a4 GetCommandLineA
0x45d0a8 HeapSetInformation
0x45d0ac GetStartupInfoW
0x45d0b8 IsDebuggerPresent
0x45d0bc TerminateProcess
0x45d0c0 GetCurrentProcess
0x45d0c4 HeapAlloc
0x45d0c8 Sleep
0x45d0cc GetModuleHandleW
0x45d0d0 ExitProcess
0x45d0e0 SetHandleCount
0x45d0e4 GetStdHandle
0x45d0ec GetFileType
0x45d0f4 SetFilePointer
0x45d0f8 HeapCreate
0x45d0fc HeapFree
0x45d100 CloseHandle
0x45d104 WriteFile
0x45d108 GetModuleFileNameA
0x45d110 WideCharToMultiByte
0x45d114 TlsAlloc
0x45d118 TlsGetValue
0x45d11c TlsSetValue
0x45d120 TlsFree
0x45d128 SetLastError
0x45d12c GetCurrentThreadId
0x45d134 GetCurrentProcessId
0x45d138 LoadLibraryW
0x45d13c RtlUnwind
0x45d140 GetCPInfo
0x45d144 GetACP
0x45d148 GetOEMCP
0x45d14c IsValidCodePage
0x45d150 RaiseException
0x45d154 SetStdHandle
0x45d158 GetConsoleCP
0x45d15c GetConsoleMode
0x45d160 FlushFileBuffers
0x45d164 MultiByteToWideChar
0x45d168 GetStringTypeW
Library USER32.dll:
0x45d170 MessageBeep
Library ADVAPI32.dll:
0x45d000 AdjustTokenGroups

!This program cannot be run in DOS mode.
`.rdata
@.data
^uKVVV
uTVWhTi@
HHtXHHt
?If90t
tWItHIt9It
j@j ^V
^SSSSS
tRHtCHt4Ht%HtFHHt
URPQQh
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
<+t"<-t
+t HHt
A5_xh/
*JwI}&
Ud: b2
C$2q%!
}#HmP'
e+ihV(I!
lB.8ua
!zA8E:T
(?ZTZ|2
IdVKJf
bs$?us
DDQY\((9L'
L{wEi+
_Lzrlg
9WKQ`^
9p)yjk
&t(GM
I nQ"
ubt_jF[
(0RL Z=z6
Hf8Pkx
*&5T$
R`a2Y'
|c9-W&sy
(m2~Q'
;hVA6B[!g
d3fO7#
.ghl ?
F*_P>B
{CpGs*@
L>Jt{47
?eZwW0
(prM[
Ra"B)Y
1ziVu#@bnO~
\1g>7w
'+?)De
Qy!pnD
&%aKy)!M
+luRPlLL
.jP1Mu
qM~I|ZI
h:,m1E
*D6$s^
7?ivNl
v~-AV)
Lqv{ai
K"a]_q
~ctom\
IIgkMX
3u0'1QO
.-9B=V
iRN+9`O.
blDA$V
+"I539_k
hq<P}P
|p*V!
<%X:+[
f(,T19
<klQ}
Ej*(RL
VnS*Jj|b
.W5DQG
de[ez)a
Vd4V0zK
}~.0)>
WP/AsW9C
/z%n#`
`\T)hN
pqq+Bn<
Mgj'{^*
s^r$/m#
VIui["I
<O!w*10
#$<#/
.BMQwytT
RF_eZ$:
2rEsU&
.\;LGp
;ip%{B-
BlWnI* ?@
u8'{/M
gom}5v
K4#97E
/H@~@4
HP!d9_(
R 0~UKX
YN59CICc2
A',1uP
wh{%t3
PEJ]a4
Oa?@i>
7{2zM
xi=T]v
drZ47"P
y*N\$=
<8;Xy5
i!oa)5
^R2 +O
LatdSrhT
z>}aAe
S@4PB;
X*u[G%^
)qp|QE
2V?XD:
ZrOFT
lK^`H[
h!s^@@N|q!
j8?oW_
V+&}ha
Hf vkq
LY-g8R
?_2["r6
#; wB.
wd$M+'{
SQtl+)
~wbO?V
2dJ&Io
v0p*sBh)}0
1F#I1ObT;
N)/]N!P
b{#]NX
<p!h-/
w}1pIN1p
u:i8Cq
bSF4*
8+uy(a
.=3YGeo?
_;!miz
]lm'nf
engh.]
QQd+hq
LZ$OCcu
E1J.Sc
\)RT:K
~I:h?n
:@w@+a9
^)\I7vo8
SY38:q
v5pE<`
QV8dzO
|nnn3x
23CDy<
@}',O1~
K{<YpM
^K<@0kD
Qw'CZ'
fspPf[
b]ipjG4
5g+FwKX
r*x@j&Wl
B5DP&!
LpZ"+VK%
\}x39)
p:xRMfm
E$>$=G
`L4ov_
)y+uf@
CqN#r5
Ji.o)N
@LF<Y5N
Kr[EPw
eR*<$27
SRxpk=
FQ|-^w
Vh0+y`_
]*-dI@
i>}ob*
Ae+u1A
ES)~2!)
/eezq=
ahO+YN
h:F8`!&
L_)|c#
[iSy.n
AyyYa:
4[;#c@<
,q/c=p
}xnseS
[!Uttw
b`& hE
Q<njD:
Db{`e0}
M)s1-t
L:dNo
&]C,KQ
1Fq5%0
\3\-,.X}
uoMTvo
u2Q,&v
CUiRC@@
Y.o;X'
Pp y_x
42^y,~l
+BtvJzy
_2Q'N;
v-;.UN
&#9lg]:>
:"EiHe!
k3L^;u
d?\yS
k@"W09
')ic$Qj
0%Na>l
IJC!oz
@A?Hi:
g2rE86ZN
ht,]I\
uwV1E|2
)4[E
m:hm@l@)
~T}q[Y
=XM!T4
kM0&n;
Lvv!@
(%=@2%
ewI?{
OM\N/O
=7p!8C
>~ZcsR
_d[y?-
px[;0r
C@L 9Q
.u\& %
UIJ|s>j<}k
lM0y4E
|ZF` 
\r5w[|
1MAX.L.
V1tjfo'
ixtEu<\
x3q+,r
%Sz6J/
i6YiIoX(
6*Fj^$
+*ZG3-r)
B?#a5}|s
-xAEh
P@$d*A
Kxdu11O
TDiW;3
af=%'"
h$aG%%
Yc#|,/
g Ptp
%U-9-J%
U[&9sp
TwRqQ,wr7c
80>Z>
2`NCY
"KK'//
Ob|)|4,Q
<prthT
YuDw]qH
5f;n<q~
+,zY%z
-jJ.`&
V9]?rW
/s (0f_
!5EWcDjN
`cnWQiZ
Wz\}w
bNuD-,
x:3P
J(T8F0%
=Y>aD7
(De1Il
@7%a-'}
N*~:A
bZ8k'@[?
iGJs;;
Zqj8i9
8L6WY[
>FIckq
7JD)lt
#BHdn\
-Ngy"L
{\$E'+
|<j\#
ozB_2'
0p|E\^]/"'
3;B%FF
b?B=L]
|G1&xLIh
8tPa>
=H]1$>
_1|8]!#
N,R};>
WV?rlD
w{uec
';0fQ(
d?Y9<bO
JdW^z^
G6#0.7
0h9SgzB
, 7p!P
7kh>sU1
4#4KS\
iW2@)
/&#oeC
0>:y*L
\`>}Z
~O|!4[i
u{I=NH
C})[tK
_axlVL
bQZ/KD
z;|~[[kV
f4tMbC
K,MaX]
mJLzs*
4 /A?N
vJfJZ5l
R,!dAE
t(vC6QC
qso0st
zYSep9
^ um'UQ9
8#7uWo
XJB BcCN$
b(Kt@x
>T&k:+
"%M\d!T
0?Q[63
.>HqDmx&
km0N*:q
iet\&x
n~S@{7
aO%0 |r:n
Du_>:p
iP\Ii0_
GeDhu{
GrPSIz
w|)^)4
Cn?CT%
:#QQsotS{J
Q%IU=;
vbW|<!=6E
n:*>n4
;E/p6!.gTD
3 iV#@
?v&q%@/
UOQ1+{
_urA,@
n79C)y
(cA)+q
#Kb5ch5
FA1KYT
7X,J9%
xh?F0Z*
kMZiOi
dP;/P
m?|<'y
qWYs~'
Qu|=pU
1Y#P!Cl
yeFqEkCc
?)IT*=
y0*xn|
$l'nPe
JbztVL
c]sY9
YZjvK
Vishg:
(+iL@M!q
XqXMB7
*jq=akf%P
]~y%,=
25>1vt/
v)Og9e
7GE#(\
dDbfWm
(~d`_`
O[=!7T
oq7#aD
;vq988`{
h,Xy n~^
Sss80P
D9`55n
1syt.M@
28%BKx
GA49Z&
S,+oZL
b451#(
eD{U&
5,bz,6
ML%.Q'
VA(}T>
:MtR}wMj
;Z{&t\
s{;w/G
XCSdUO(m/
!}jcB#))
L"@Gy%
IipiPM
>abv10
yAGW=b
Gb' 3]Bg
Xr@wR5
n"J7;o
\g:ezJE
cNJ2"5')
3gg|}lQ*VM
[H4@X-6^
;%@v\`
>ei}-g
I^z{g@EaJL6
!#M/}e|E
_p(QOK
(K<wCp
W(1;HpE
#i;QK@
+%y;\
`a''/t
F!JFXP
D!F *IV"
`3F,XsY
&f{"Xi:/o]
;ycxU'
EJes'}
FRbq]2
k }+{=U
C.1p[@t
G#z[h)
NNA5Ha
<JTf]EE
Cr-8d!
q>Y[,-?F1ck
r<g@C~^e
y}a4,W
QZlT &F
,r@pM+4
L")(k_S
6c;o=k#I!
y-T\W\]
39#OfI,S}
_lt]^%M=
~$.)};
>|GI^a
f":Zr%|
r;,:hS
Z=!388
c\?@Y7
!1:;:P
tU""(e
Y0<YYz
)zT'&6><
RatdBS
hf5]FR
MGWD7s
yvin\N
/U1-^h
Y+w-=pJo
#@2RXI
*<ruKE:&
'HI%^v
Dx\'>'
:ew;Rn
KCLU(X
8bA'y\?
#^l'\j
C1zDVW
G@j<C7
U$OuX-
-{t|er
t:u0"Xo
MjwV~ig
UX Z1o
k}:${"w9OR
Z5xRXG
j<58'*
>Vcf-u8
Zcl`S}
h)pDzT1
5wYuaab
_tMnrL
nDI[!]
&g<:z$
kg5"Qm
#"`'Qv
8g_ Zf
~pp!Ru
?p(/UB
zSx9G3
a?~6<G
yyK? $
.~rgB'G
`b"CqBp
xFH2:_
p@OzyY
R*2PX?{AQ
xsLM3I
iQy+z>]
3xGma
Ld}]\O
@WQ/"O|A
PH*faT';
saG/&s
xb(hg%
]|-[{r
*bLlBv
;,y~mA
E9![78P
CB=4zT
UaC5,@
Al60&5
zN=P,"
uYv"[\5!
?/7vFH
FdF6Lp
R JUe-
Jot1B_f
Hu$kU/
[45wY|
c)t|a9=^
X)>R<O
vbb7c*9^s
-b%f!:
/6Xapi
`),Sgv
n*\9Au
Rq;ysNk^
Xur%^6
^CCp5"
[S>9#Z
O7>MNF
MhgP2@
=pk^u$+
|#q\R
(|UX.9D)(
hhd,mH9
B#GOT&
6c\(WD
|?hjv%
6Ym5a(
XYC.7]
pU[C0E
"&gZ8U
Yh5lq@y
:zmV.b6
K8W+Q'^
rE~W&)
8oA$\I
|x{asn
@8S:\O
?|>Ql9
D0oW"L|3S
siR|9u
z@"y?|
nh=FU
kiK+IGR7
"6x%%7
!hSzw8
4U=b9;}DT
B_]-Nu
dR<pOCG
1/n41#
x61cNwO
JFuG*8
|7?ojg
yd;@RCUQ'
TIweIn
![YB[9
QFzNmT
[V'(O,7
8Qa=Re
2OlnL8
|VD\Q?
I`|iqB
6e@n%k
zINu`%
y"/wNy
jj.\Yt
R2n]`C
}6O=vw#k
*a$(0{:
fEj0L0
kOj_xu
G4@+X\I
P89tj7Y
={`fDy
\7||Z
m)ezFW
{sX`w-
!s+xXgd%f\}G
~O$bBWdOC
o<gI)
@j3RP'`
(k#kk*
]fsDB6*
CorExitProcess
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
Lazexohex xewiset gepes
Zohiboluvitepem
Damilasosasalep
Cizizikini
VirtualProtect
kernel32.dll
LocalAlloc
C:\gadaboke62\dikitidala81\bajakusamovoc_hividali-rerakuro\dis.pdb
CommConfigDialogA
GetDefaultCommConfigW
GetSystemWindowsDirectoryW
QueryPerformanceCounter
GetEnvironmentStringsW
SetConsoleScreenBufferSize
BackupSeek
GetTickCount
GetProcessHeap
GetSystemTimeAsFileTime
ReadConsoleW
SizeofResource
GetProcessHandleCount
InitAtomTable
HeapValidate
GetModuleFileNameW
DeactivateActCtx
GetLastError
GetProcAddress
VirtualAlloc
HeapSize
BeginUpdateResourceW
GetFirmwareEnvironmentVariableW
GetAtomNameA
LoadLibraryA
WriteConsoleA
LocalAlloc
GetProcessAffinityMask
GetConsoleCursorInfo
DeleteAtom
AddConsoleAliasA
FindNextVolumeA
LCMapStringW
lstrcpyA
KERNEL32.dll
MessageBeep
USER32.dll
AdjustTokenGroups
ADVAPI32.dll
EncodePointer
DecodePointer
HeapReAlloc
GetCommandLineA
HeapSetInformation
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
HeapAlloc
GetModuleHandleW
ExitProcess
EnterCriticalSection
LeaveCriticalSection
IsProcessorFeaturePresent
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
SetFilePointer
HeapCreate
HeapFree
CloseHandle
WriteFile
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentProcessId
LoadLibraryW
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RaiseException
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
MultiByteToWideChar
GetStringTypeW
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
g
e
|e
@
-/ |e}
(Lc&c%
Z
Z
cWEzzL
&z;z;n&JIc
}]Z
Z
/
]/ ~
:/ X|ob
[
~
d
d
y22
[yx[/[
:/[d y
d
u6v6?v
Z
}PuPvuu
`uHu?o
/
/
uHuuvv
/S
g1~
ygg3]y
&6ii(?
?/gffj
####PP
(G:e#e
gggggggggggggggggggggggggggggggggggg
gggggg#
ggggggIzR
ggggggI
6+dgggggg
Kgggggg
gggggg#
Igggggg
gggggg
Agggggggggggggggggggggggggggggggggg
J=v*U5e<
-sqnH~
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
______-
_____-
{{{{{{{{{{{
G00000000000000000000000000
LLLLLLLLLLLLLL
LLLLLL`
LLLLLLL2
LLLLLL
H--------
--------------------
%%%%%%%%%%%%%%%%%%
YYYYYYYYYY%
YYYYYY
%qqqqq
%qqqqq
%qqqqqqY8
%qqqqqqqY8
%qqqqqqqqH
gggggggggK
ggggggggggg?K
3HShT7e~
k>#4ik
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
210525000000Z
281231235959Z0V1
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
H/(@Bp 6
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
210322000000Z
360321235959Z0T1
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
FFlCx@
H/(@Bp 6
:http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0{
:http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
http://ocsp.sectigo.com0
ts7!:o
n0PPd}
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
210901000000Z
220901235959Z0g1
Hovedstaden1 0
Fjordland Bike Wear ApS1 0
Fjordland Bike Wear ApS0
cl:A"X
Nf+CB/
https://sectigo.com/CPS0
8http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
8http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://ocsp.sectigo.com0
larsenn@mail.ee0
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R36
{l9zU1
mscoree.dll
(null)
wruntime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
EMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
@HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
peraleyuwawusogeyodotu
tilibevigonisesayetecacimofizojokepabovobaciki
saxaxo
sirucilecukucolecesokedizevatarokayemufepusuxujeposar
VS_VERSION_INFO
StringFileInform
090101a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.12.11
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug
bFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibikKRexiyosununuti rihoxorowopal vemerey fawunujokog foco xacovuku luhohefaneru3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.1629965aff3a7f0a
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
BitDefenderTheta Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 a variant of Win32/GenCBL.BCO
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.82 (RDML:rO2mz8mj3q+AZVEArNdn8A)
Ad-Aware Clean
Emsisoft MalCert-S.ML (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Stealer.31421
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos ML/PE-A
APEX Malicious
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SentinelOne Static AI - Malicious PE
AhnLab-V3 Trojan/Win.MalPe.R449286
Acronis Clean
McAfee Artemis!1629965AFF3A
TACHYON Clean
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Ransom.StopCrypt
Fortinet Clean
AVG Win32:DangerousSig [Trj]
Avast Win32:DangerousSig [Trj]
No IRMA results available.