Static | ZeroBOX

PE Compile Time

2020-05-17 18:46:14

PDB Path

C:\tuv.pdb

PE Imphash

b1d7987a638c820f79c0e265e27eaa61

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00081d60 0x00081e00 7.97680089196
.rdata 0x00083000 0x00003aa0 0x00003c00 3.80109742443
.data 0x00087000 0x00008ec4 0x00001800 2.81412269103
.rsrc 0x00090000 0x00025fb0 0x00026000 6.32321004145

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000b3f20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x000b3f20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x000b3f20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000b2a00 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x000b5cd8 0x000002d2 LANG_MANIPURI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000b2f20 0x00000010 LANG_MANIPURI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000b2f20 0x00000010 LANG_MANIPURI SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000b47c8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000b47c8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a5e08 0x00000068 LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x000b47f0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x483000 CommConfigDialogA
0x48300c AddConsoleAliasW
0x483010 BackupSeek
0x483014 GetTickCount
0x483018 ReadConsoleW
0x48301c LoadLibraryW
0x483020 SizeofResource
0x48302c FindNextVolumeW
0x483030 HeapValidate
0x483038 WriteConsoleW
0x48303c GetAtomNameW
0x483040 LCMapStringA
0x483044 GetLastError
0x483048 GetProcAddress
0x48304c VirtualAlloc
0x483054 LoadLibraryA
0x483058 LocalAlloc
0x483060 SetSystemTime
0x483064 GetModuleFileNameA
0x483070 UpdateResourceW
0x483078 SetFileValidData
0x48307c lstrcpyA
0x483080 CreateFileW
0x483084 GetStringTypeW
0x483088 HeapAlloc
0x48308c EncodePointer
0x483090 DecodePointer
0x483094 GetCommandLineA
0x483098 HeapSetInformation
0x48309c GetStartupInfoW
0x4830a8 IsDebuggerPresent
0x4830ac TerminateProcess
0x4830b0 GetCurrentProcess
0x4830b4 GetModuleHandleW
0x4830b8 ExitProcess
0x4830bc WriteFile
0x4830c0 GetStdHandle
0x4830c4 GetModuleFileNameW
0x4830c8 HeapCreate
0x4830cc Sleep
0x4830d0 HeapSize
0x4830dc SetHandleCount
0x4830e4 GetFileType
0x4830ec SetFilePointer
0x4830f0 HeapFree
0x4830f4 CloseHandle
0x4830fc WideCharToMultiByte
0x483100 TlsAlloc
0x483104 TlsGetValue
0x483108 TlsSetValue
0x48310c TlsFree
0x483114 SetLastError
0x483118 GetCurrentThreadId
0x483120 GetCurrentProcessId
0x483128 HeapReAlloc
0x48312c RtlUnwind
0x483130 GetCPInfo
0x483134 GetACP
0x483138 GetOEMCP
0x48313c IsValidCodePage
0x483140 SetStdHandle
0x483144 GetConsoleCP
0x483148 GetConsoleMode
0x48314c FlushFileBuffers
0x483150 RaiseException
0x483158 LCMapStringW
0x48315c MultiByteToWideChar
Library USER32.dll:
0x483164 SetCursorPos

!This program cannot be run in DOS mode.
`.rdata
@.data
SSShHLH
u-h(MH
^SSSSS
HHtXHHt
?If90t
j@j ^V
Y;=(}H
tRHtCHt4Ht%HtFHHt
u}hd>H
URPQQh@`@
to=X~H
;t$,v-
UQPXY]Y[
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
.t.:jgUhc
U"~iAg
zvdU17
sK:gih
2>=I2O
ljP})H?R
\_p/5q|:
i~;@!L\
W=uG:l?
]8f8Ab~+[
in`PgC
E(+t 9
.m0Tl4
XY:v|}
]\bsM3
UXLH $
. .PNy
TUPCD3qh
OiqLN(
PsEA*Y
zb5)&-L
mho=x`&*
)eo(F%
lga6A&
xiYS,t
@[s ;j9
LVKS[x2u
=9g)Jb
AdE@,&bQc
q`7LJ*
Z9| 5(
h(" ,]
U4H!^K,
;9HQlh
/*z8sM
@9RA%0
d5R9c6
D3fZL0
_7]^o5M
,d_=@ET
p1d|OR|
b?`lbu'
Cv~eTxfs!\E
x`:`sq
UOMu3#
NXS!8D
O|>yx
TfH8^<
W%(Bh
tV#;4%n
uv}zt|
gfBF*x
m#x`;4P
F8oNP!
%WR<J6
L*FR3G@H~
.OguqT
N_I>Dl
_e@=DT
Z]h?]P
I@Hw"c
O?J r:q6
!{P yg
8uDxlV5
tS<S,I
G|y(h{
L;9rJ>
L`dBc7
X ;k"!
|rpT)]
F~&vds
;|TQ$!
5:E-=r
x;PHOM
esn8.7h
JNG;Mb
NL<$zaf
=kDiqgE
Y]6$()
wU4}j
2Y/3u*
Eg+^%
?`{C#.N;
4jZHzEo
EIPmfjI
b'wt=Ze
T`d7W2g8#
<"~<{^
9:~tX3
qp>(/r
@ yCP[
}WP2gz
L{qwY'#Z
IW;BQ!
;@WvNt
XOW'*
bN""]Q
sT*#}#I
E&gu.W
X9,gbD
z0ezH:
D@>NIt
QH&5x'?
:AZ'+C5~
T!<33?t
[MPSxl
ERA:cR
12,13^
D,=AJi
tAn@H#L
iM_0sFtaR
rM7}.7
RR3ga,
^g"e,8`u{
,CAFM0q
:kU"V`
ZRyG#,
|*27.T
'+D)fN
rS9.8x3
J=SR7+
03?{uQ
#IU|>w
2;|r30W'
f6#[g
:as-~\
tOVdF3
|CMu{"v
6[DtHo
`:0V8ID
}iU!*
-Svfy6
''}WY?
an8`']&
#ul1f
7q^Y(%1
_ari([w
9C8zu|
\&iLz&
=@W9,,6S
6`4>>S
}aEnp$
NM0<%[
:a0z_X(f
53p*W
tj_"`O
7RQDsHRG
QxCy[(L
v<p3%I
RD.akhR
glh~@S
InZ0-;
c&'Ib,
TCk-$5
>HFBw*n
j^Br9E
O{i=iD
z\5HM9
XdWi\
J~GOl%^
$z[nw8e
vZh({rs
n| r}a+?
"%Vj73
b4CppZ
Ppo*v?
2mK5%@
K.74UG
A8hC&|8
t&Og]W
Y'+'M5
hkAK;*0
~YZWAa\
Zxft5&
b<<l#sR
M|YyCa
h,(h}<
+x)+2e^
VQyIwc?H
t7O^Lr
%B[LQ$
f>UH'z
6WCTXH
qch'Ut@T
{S?4)
|u\*2v
o(yQ;C
C@3V$>
7}2UhGr
Hf}]f~
)vg]01G
6|ZtM<
!9&FG)
tAF\eH
/1`}F%T
kFlBcA(
u_PG'6
a?o>w-9
BrLJ3;
\,_F70Z
`K(g.2
oH9iwe
2SjU>C
XL:du3
rMmGze
|j'noxjzw
GD9QcF_
CT|0ls#
~U?VVQ
8bG;]wM[
!#s2X<5
L\Szs0
? 48yF"At
v"G=)Z
/4X94>
4Ea;"p
NtDZBr
SB\m)YS5
s9Ukt/y
}[>`Gk
V&=Wv~
kF8$q:
RYM]6DD
M#L Yg
~{D7U@UB
)~{70a3
_~Fk`,LL
^"7{f"
b;t(kZ
+gzX0-
9#-~!Ha
Zx2xlH!^
He 5TT
bf.juF
{ny6D*
<Ky&/H
'=*ASRlM
C.j]S+
Ogp)cO_
~KNRlxC>x
zgqnO=l
BKx6K6
)L\7I+F
-_OC"}
_(=7=zk+c7
f 8lXwT
ckdKkt
NmXHtl
koTXFW
96Tbv^
~!V7VU
qu.w`3
foe>/;
E_Qr~!
B5?Y.t
Zg>)@4
^a vU:
_^|L|UL
;5eC/o]2
M_o%u>\T
+X0M=s
'\{)Km
B\N*xQ
@LP2uU
iw_$Xm>
VT?:#/x
!GZ0Sg
/j\SKb
>Ftx]f
cDZ/7{
asBEPK
=/z:YO
?gF~/+
c\5Fn6
>u.;->
<x00p%
?z6WKi
U}=X.v
;ND[}
D]1 @%
Sqp3/.
%r0d)(
nnpFDB
YU6A'cPem
dPZo%#
N?0ghu`6
RhX!9)
F5HK)s
$V[#69
"VfG)v`fa)pI
#4j"W}g
o7FtkHUz)
pYR('4p
Hy2S-;"
}b'zWt
7|H'QG
8gxox[
>?J55X
cJ>Q2%
zoVvi^
*"=FZSU0
@##tqv
DJ<HLN
(%wBab
q3?$14
n/?60n
Iz:"H_U!}1
rm%HT8i
lAUzc]
(r:: m^
v$OlAaI
tRqo!^
-&f `x
1Vxdd
pD|X;4
&cI7uV
PhOdBK
gU<HAMW
v7y$"2#R
4IfT/S!
_h->u3
rO]L}1
Fu|P00
G4bC3.$dcx
f}LQ]'D
Jl+LR%zd
'Do`K7
:!l`CZK
+E-H1tG
pW[@sR
]35Eh/
lP: lS
d3nPhw
T|Iy)TE
IBaN-F
vBkps5
!n0Na$
#z"bhT
<+k81U/dJW`
t9r<ip
']>8r";
:/#d44
*!}'ce{1
(Ga*l}n
?'$Ft4
#_H(=Z
r5M!4cn
la4C&C*
XY BFB
`|_dkq
,/8k""
;Eb94IpG|
a%>?(d
A#yR6o
jV/+$x3
Fjr@)\k'o
H0*/=#
:g?RJP
6~x#(Lb
1[oh^*l
i?q:r{
o/&p0C
*o}av&
2ZlKdG
s`h#"G
q'8zY<
ifZDjV
^y2~[b
=g_ Pm
eSnE9f
?|'ZV~
!As]7q_
V'_*],0
DHr<EK3
aeIUo
z.*=oq
V,@+Y'
/q>L5U
~+^*#_"
g~`DX)
J>j(_
=J4I^d
9y>&bH~
d%Rb D
-*k8L%M
*0t/_U<
]Kl"9m?
)?$T;lt
Gri]`K
X^$d#N
PmzfoS
|ZDjY$
[E&^|4P
P1O|W&
0`5?d6
LgH4D`x?
0_]?;9
!pv5Hv
-'P!Dw
QcKRdfO
Dl6."z
Om:Ud58 c:
L9rUZt
vU*!:F
x.\ARm
FkW"x5L\w
8onjL0
a86v6,
/pNTfi$
0y[86d8
oMnS.n
N;loE#
6UEIoz
!eJ@-ct{
}-5|%U
^+GkE<
8DJ/Zw
%L-@D>G
(vK&[u
wPOT$Q
Wi!6P|\
/H)WzI
y?BL9w\
\CCXTX=O
b=z2h
2R1W/x
nZ=gJg7
`:gzuO
S6?wEwG
:*-kbD
cIN8I?
Kg3Cz]
tUk|lN
2~=ZV{
f}*O1Zhr
Q=!CX-
aZ+/sL
XL}{2;
dzv,F_*
<eZHV[
6Z*-_<
u-F[Be
tN<U6{K3
y7N~y%
e#|yiY
I'6z^"
a:4|2)1
[$T67
5YJd9$
K>,v!m-fLc
r^nqNZ
8WC<g
dhG>{}
q@Tb5\&
iO'Uc]
"!1:L2
rR'+R_
bl& 5I
Xl9joG#
SRw<%RVvAu
?Hq|EBVz-
?Hek O
s=c]YU
K'@8[U
3=$|K/
+^jj(KN
}/W\|&
N$iw(k~{
N2oyTV
(&}8V}q
'8HQS
On,HiB
vT&8@ C
}mU.3t
@V.*/%+.
1]w9=,
l$y7Uu
=q%!p6
,)<Y~s6;-1
|u)[_bwv_
2>P8-M#I
A%r\l_
G_(:vDwu
lA%&BL4
8?E9'2
+PjZx<
ax^fbH6
38*@>
k]=i>5
04nD|Z
B93j7OJ#
yG^JF<
grDeNfm
6o0y1:n
;nbBA
3.I:|.a
+\ZrA5
"S7<b^
h%QV_Y
N^pTBYm
V._1*7I
r>&{o6j
iRaf_Z
wJm`qp?
Yh/Y,m`
R$f^6D
12X5,h
a~QYT$
O0ny]|!
<(@\=E
8cwml&//B
|{~O/w
d'ZG_F
D1'N&%p
(:S6hQ
{msK-{
r9n-,9H
;+d].H
mas oEr
rj;,K?
+LNt0?
=+93KY
V"/QmqU
u3qMWm
'qD]rf
bw#WQ?'
i/YASd
+e<fy2
61d-*S)
t{+*5M
rhl$Fw
9_e5dD
2<OaFy
,I%(t
m`m%S5b
w|OGM;
C*6Ko$e
[`bC!K
8"aT){,
UWFOp:X%
f,\D$q
!TnE'X
Q6dAmp
|]sybPR5
ZRHKS\
5kcpk6M
k{)D2T
Nh!dOj
nTsB,
\^j/ L
/;_|"L
{BoW_#
;FWize
,Q;nO7
.0>&?q\
N_[Bz-
+I*/b*&D
|pCUTeD
yF #&L1
X0H=Z.7=
4WYpFr
lL}U7'Hd
:vhYuw
~$yg|3
4LnB4Fz
L(8Kx"
p]{>M*q"
KmG,\;5y
6M01Wa
\yRpUr
54$j\ns$
AHb3s"z
E!uSB2z
>SB>Rm
84CB7&@c|
~]+J#3W
fLX$+N\xW5
k"sz?>#
TtFww/l2
g]`thR
vL?)/&Kl
yqekd~H
^,^LGI6h
w$bu+[N
ws*cOKjV'
J in(k
t1xv`4v
49U*rw
yWeU4J
ICAR)
tk:IQV
+}X2K
|$H2C)
nKR5h@
]:L(l5
ahj+-M
;ER\TCpv/
j1xoh6
<64)Vf
M@|Ja$
;Ap3aT
t<2GF2)[m
8(Ujqz
lfw(j8d
cM/0W%
aBd=*7
`%,&Ej
*r!kD2
Nq Q6~
UR!`(H
Dcgm6/
/)z]j
8R0Pn&
Ia5)0
ON9[+k
O0:lVRZy
_< 0KIR
QLC:;{
Ku~3#X
I8,K?b
uU7{G$
h~'2Qq
&<b~e:t
\ wtII.
Lalw2o
7{#$X'0
h^OeO_
(&;"%.
/-bG?Z
e=bS203
+P0%nPK
Q-0\KE4{
w)3?jk
Z{vP)Y
[X5"rx.
I<LT@o
e$%5K.
N2G9;yJ
tix)IDR
XMRg[@~
-6*-"NaG
8e_&.
+<1[)>
!_>gn"ZNj
&4ntm>
7&fro5
0r;PBGs
l-@vnN
L\8g(!
h/}q)7
[P_>rY
xRC)?C
Dm.#x^
fKnRF{
pq%wP|
<]CeYa
q]@5W6
-s"YU&"
)`+cr]oG
&G;Q+TRI
#CB9@/
[{ZM|B
V(ce$o
ZjcXp&X
bl!>LX
ASI.@4Hi
f1p+!c
.*Aw1h
z?,W'J)
FlGEMD
~P7CYyk
Y(Y~i_
@-zx?]
0eBCQT
w8+K,L{
+OYO'mg
gBf{{_
xPKx]/Z-K
3q9/$q
joURn&
6Xn\L6
N_@_6J
-O1Xe>3
DC]WM!
#i/wh}h
I"[4G(?
-5ho^l
)9wOr>
0nh"k4s
U*OtsSnX
EvpqhF
!%u<{<#
5kc\0_
1r=cN~
O(V3a'
aJx>+
%]o[rz<4
Y[6Z:2g
_!WNOk
7+'@n4
"~x9R(
{C@qA@
"e{)~_f4n2
0 9`Ze2-t
|/M&C|
='YFvt
6~23^MGr
^?v!GE
_ikZ*^t
$?|6m>-i
_;RQfI
HuuNQ7
"QvA_l
y)y)P@+
yk5t^c
vP&]\
U#Tf|izK
J9:\A*
6N1(4|
f"t3"@
1>_v!N[3Znj
'yMHr'
~(iAD
Z/q(g
xE%%)W
_8K-~$
=q>:% [U
d6~VtB<
BQHjNP
Zj`o}P
WK~?@K
/NV7f~FOB]
Qh{NJ
7f`T@!M
87/I3t8
F57XWI/]M}0c
0)TLdx
" ]<DmE
BiLZ(I
P63la>:
*(r\,<
?pW?&!
y^chD*![
l(`x;DS
4fg<Jd7O
_-h,V>z
Yx^K-+*
=NNVAn
PVy`YB~T
vTD.]
WHT.}j(
hM0B>
N!n<*U)/
>Eb-o{o
lQf_t5h
6 SN@*c
Rxnr)T
lUW{8km
tpQ!@
4qq5|%
T-`@<.
}(/dd!u
;"YO#T
G4l3$q
[nPx))
,4Q!h
"/mi{e
@#<t<P 4#
{EdL~1h
P-8Ts=Y
jy^7cf
QDSXKD&Nh
=CRn7 AH{
r)&.0T
3mXL=h
d$&bO&i?w
wQNmU3
XVu4{\
(p4^"/
.(x~qO!{T
_Ucl>Z
jS&:G~
lcqjSn
?iK=o6
S9{d==p
&wE"|q
}4QwM!
MjlI'X`
gw7.OS
wOu-2&
8Rv&iB@
Em$lIv
7h6dj5
;I@o%5
z:`5J$l
>%a'rT,
Os-g&D
.19~)6
qfy,8%&
xscsrAo"
fi*X,hU
huckKDPb
hx{F%As
NBLd]C
=*@^W?~
:\Pz4a
#jGiy5.
LxnGgX
\:5g|S
^M!0$5
WtMQ;t
lV'Q7G
TDz6pd
&Fe|$Y\
5[@G~=
TjD):i
7xk\$\
d9h?Po
om<<EZ
UqpMi3
[Q6mSs
n!jXr>
[b%2DMB
?\l;9)
hI!v#Fz
R%;M_
]r~{km:
6vbb@i
Af70fG
?dG)FVA
[lge+*2
T).F6[U
#:[Fi#
Lt?(z4
>/+aI
~j{S,PXj39
;.Z\=4$
P-t=K=
[r{t(1
s}d}f||
GLprYZ-7
u&k(B4
fM\%6]
/%6B`'
[>G[$O
D/: 2m
!#!){e
1Ta|
:J(zZug
9% MTm
p[\^w 74E3
}V"N>w
<+s~e<
j#U{S,
&a?hz]My
'(W`}{K
?eU[T1
FnK"!Dc9
kr9">$
jU),]
CorExitProcess
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
Lazexohex xewiset gepes
Zohiboluvitepem
Damilasosasalep
Cizizikini
Hem budakatopacawe wac
VirtualProtect
kernel32.dll
LocalAlloc
lamagukogehaxehugohetohucuxitegafabukulojanosawizenop
C:\tuv.pdb
CommConfigDialogA
QueryPerformanceCounter
GetEnvironmentStringsW
AddConsoleAliasW
BackupSeek
GetTickCount
ReadConsoleW
LoadLibraryW
SizeofResource
GetProcessHandleCount
GetSystemWindowsDirectoryA
FindNextVolumeW
HeapValidate
SetConsoleCursorPosition
WriteConsoleW
GetAtomNameW
LCMapStringA
GetLastError
GetProcAddress
VirtualAlloc
GetFirmwareEnvironmentVariableW
LoadLibraryA
LocalAlloc
BeginUpdateResourceA
SetSystemTime
GetModuleFileNameA
GetDefaultCommConfigA
SetConsoleCursorInfo
UpdateResourceW
GetProcessAffinityMask
SetFileValidData
lstrcpyA
KERNEL32.dll
SetCursorPos
USER32.dll
HeapAlloc
EncodePointer
DecodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameW
HeapCreate
HeapSize
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
SetFilePointer
HeapFree
CloseHandle
FreeEnvironmentStringsW
WideCharToMultiByte
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapReAlloc
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
RaiseException
IsProcessorFeaturePresent
LCMapStringW
MultiByteToWideChar
GetStringTypeW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
=@xx""GZ_
l"+"+NlQ:
&2Q_Gw
Q=_==n
MMMMM66
W'6W6666>
33333333333333333333333333333333333333333333333333333333333333333333333
33333333333333
33333333333333
33333333333334a
M3333333333333
53333333333333
Z33333333333333p
33333333333333Z
3333333333333E
3333333333333Z
3333333333333
3333333333333
A3333333333333
3333333333333Hl[
3333333333333H
3333333333333
3333333333333
3333333333333
J3333333333333
@3333333333333z[o
S)333333333334L
{3333333333z
3333333333
3333333333)
3333333333)
$@33333333336
43333333333
333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333
I;|/^4e8
1uonJ|
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
\\\\\\\\\\\\\\\\\\\\\\\\\\\
q0\\\\\\\\\\\\
,\\\\\\\\\\\z=
\\\\\\\\\\kw
\\\\\\\\\([
\\\\\\
\\\\\\\j_
7\\\\\\\
3\\\\\\\\j
\\\\\\\\
\\\\\\\\\\\\M
\\\\\\\\\\\8
\\\\\\\\\\\\j
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
5~~~~~~
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
Rnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnz
nnnnnnnnnnnnnnnnn
nnnnnnnnn
nnnnnnnnnnnnnn
2(0gqonnnnnnnnnnnnn
nnnnnnnnnn
nnnnnnnnnE
nnnnnn
<>jlTT
nnnnnn
X?j#&d
nnnnnn
nnnnnnn
nnnnnnn
"s)b)__[
nnnnnnn'9h
2nnnnnnn2r
nnnnnnn
Bnnnnnnnnn
#[nnnnnnnnn
nnnnnnnnnn
b2nnnnnnnnnnnnn
nnnnnnnnnnnnnn[
nnnnnnnnnnnnnnn
nnnnnnnnnnnnnnn
BonnnnnnnnnnnnnnnnnB
gnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnn
2*9&"_
AxQ[onnnnnnnnnnnnnnnnnn
}#00T?
nnnnnnnnnnnnnnnnnnn[)r[q<hu
nnnnnnnnnnnnnnnnnnnnnn]
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[/[[[[[[[[[[[[[[[[[[[
[[[[[[[<
</[[[[[[[[[[[
[[[[[[[[[<
<[[[[[[[[
=Yk`HDBB
[[[[[[[/
[[[[[[[
[[[[[[[<GmS
[[[[[[[
[[[[[[[[U
[[[[[[[[[
<[[[[[[[[[[
.Cyo+o3S
[[[[[[[[[[[[j
[[[[[[[[[[[[[[
[[[[[[[[[[[[[[
.[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[Ad
`[[[[[[[[[[[[[[[[[lr4
.[[[[[[[[[[[[[[[[[^y3a
[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[
0[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
,Mo|bF
Fb~~xK
\q~~~K
-e~~7N
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
______-
_____-
{{{{{{{{{{{
G00000000000000000000000000
LLLLLLLLLLLLLL
LLLLLL`
LLLLLLL2
LLLLLL
H--------
--------------------
%%%%%%%%%%%%%%%%%%
YYYYYYYYYY%
YYYYYY
%qqqqq
%qqqqq
%qqqqqqY8
%qqqqqqqY8
%qqqqqqqqH
gggggggggK
ggggggggggg?K
3HShT7e~
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
HMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
Zocoyoxerabe jobobahum mubozunoh gibogedicadi hocecaya
Wegi gecenahunegob miyaxalokupecus tetuyozesamex wetafa
tilibevigonisesayetecacimofizojokepabovobaciki
saxaxo
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
090101a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.12.11
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug
bFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibikKRexiyosununuti rihoxorowopal vemerey fawunujokog foco xacovuku luhohefaneru3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
Jigoyonigut sukog cuj husog
Lexuyobivuruba pakeyekaxe)Kabawigac huguh nevidakiboguvav kufibinej9Nenefesaco nuwevizeyahukec mekemogek tabacazulokol patani
MuhuZZuguduxufufijuj govuyisokewi gaxe sidixoxebinaj wiyajitoyaj lenevikuwiy todujaxuvo xoseselBXobulew ruvicunaka tebu wutilaxaseligik yirusojinotug ceviresetiwo
Monohoni
Ketijipajovoga naxudovaxeje
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.31176544
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.47354427
Malwarebytes Trojan.MalPack.GS
VIPRE Clean
K7AntiVirus Trojan ( 0058a1d41 )
BitDefender Trojan.Generic.31176544
K7GW Trojan ( 0058a1d41 )
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZexaF.34266.Rq0@a45Bk2fI
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 a variant of Win32/Kryptik.HNFV
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Injuke.gen
Alibaba Trojan:Win32/Krypter.4581815e
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.95 (RDMK:5zGJmTjjJ802hdG3zrhekg)
Ad-Aware Trojan.Generic.31176544
Sophos Mal/Generic-R + Troj/Krypt-BO
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Spy.21580
Zillya Clean
TrendMicro TROJ_GEN.R002C0DK921
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Clean
Avira TR/AD.StellarStealer.npwfu
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.STOP.sa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.Generic.31176544
AhnLab-V3 CoinMiner/Win.Glupteba.R449277
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
TACHYON Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DK921
Tencent Clean
Yandex Clean
Ikarus Trojan-Ransom.StopCrypt
eGambit Clean
Fortinet W32/GenericKDZ.6C04!tr
Webroot W32.Trojan.Gen
No IRMA results available.