Static | ZeroBOX

PE Compile Time

2020-12-16 00:05:31

PDB Path

C:\jigusisowapi\gapuvaxa.pdb

PE Imphash

52f3cbaa89ec222f54fb6ad33fd12ebf

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00088a20 0x00088c00 7.97230110011
.rdata 0x0008a000 0x00003a5a 0x00003c00 3.82998429382
.data 0x0008e000 0x00008ec0 0x00001800 2.84786709921
.rsrc 0x00097000 0x000406d0 0x00015800 6.28515890415

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000ab208 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ab208 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aaba8 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000ac228 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000ac228 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000ac228 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000ac228 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x000ac228 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000ab0c8 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000ab0c8 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000ab2b8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a47d8 0x00000076 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a47d8 0x00000076 LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000a47d8 0x00000076 LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x000ab2e0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x48a00c LoadResource
0x48a020 BackupSeek
0x48a024 GetTickCount
0x48a028 GetProcessHeap
0x48a030 ReadConsoleW
0x48a03c InitAtomTable
0x48a040 HeapValidate
0x48a044 HeapCompact
0x48a048 WriteConsoleW
0x48a04c DeactivateActCtx
0x48a050 LCMapStringA
0x48a054 GetConsoleOutputCP
0x48a058 SetLastError
0x48a05c GetProcAddress
0x48a060 VirtualAlloc
0x48a068 GetAtomNameA
0x48a06c LoadLibraryA
0x48a070 LocalAlloc
0x48a074 GetModuleFileNameA
0x48a07c DeleteAtom
0x48a080 AddConsoleAliasA
0x48a084 FindNextVolumeA
0x48a088 lstrcpyW
0x48a08c CommConfigDialogW
0x48a094 CreateFileW
0x48a098 GetLastError
0x48a09c HeapReAlloc
0x48a0a0 GetModuleHandleW
0x48a0a4 ExitProcess
0x48a0a8 DecodePointer
0x48a0ac GetCommandLineA
0x48a0b0 HeapSetInformation
0x48a0b4 GetStartupInfoW
0x48a0c0 IsDebuggerPresent
0x48a0c4 EncodePointer
0x48a0c8 TerminateProcess
0x48a0cc GetCurrentProcess
0x48a0d0 HeapAlloc
0x48a0e0 SetHandleCount
0x48a0e4 GetStdHandle
0x48a0ec GetFileType
0x48a0f4 SetFilePointer
0x48a0f8 HeapCreate
0x48a0fc HeapFree
0x48a100 CloseHandle
0x48a104 LoadLibraryW
0x48a108 TlsAlloc
0x48a10c TlsGetValue
0x48a110 TlsSetValue
0x48a114 TlsFree
0x48a11c GetCurrentThreadId
0x48a124 WriteFile
0x48a128 GetModuleFileNameW
0x48a130 WideCharToMultiByte
0x48a134 GetCurrentProcessId
0x48a138 Sleep
0x48a13c GetCPInfo
0x48a140 GetACP
0x48a144 GetOEMCP
0x48a148 IsValidCodePage
0x48a14c RtlUnwind
0x48a150 RaiseException
0x48a154 SetStdHandle
0x48a158 GetConsoleCP
0x48a15c GetConsoleMode
0x48a160 FlushFileBuffers
0x48a164 HeapSize
0x48a168 LCMapStringW
0x48a16c MultiByteToWideChar
0x48a170 GetStringTypeW
Library USER32.dll:
0x48a178 ShowCursor
Library ADVAPI32.dll:
0x48a000 AdjustTokenGroups

!This program cannot be run in DOS mode.
`.rdata
@.data
G;=lII
HHtXHHt
?If90t
tWItHIt9It
j@j ^V
^SSSSS
URPQQh
t"SS9] u
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
<+t"<-t
+t HHt
btryWv
I$1DBQ'f
h<2F~Q7
G'3-9H9
Y4t:wY
^+&Y,U
g)WA2i
aj@T)\
euC(qm
Gv5.yj
#b-fG5\
\n:eq7
$2y[~8
~7O/'!<
wI7=gdY
,I_tR`
=HW_2Q
23HaGh
`)<DxMZ
v5ZB/C
8B!+x
r7 nmf
8j:nCB"
3I7K[&
?Bdit$
@>(a2(t
tU0h[=.'
/f%#aTe
]?k<^Z
]$}_D'
kjvN4D
:YyK7Pz
u>$,Q;
Wyh/l=
m+K|{W
FiD..ORP\
7JW&;}
q`#>";
3^B"W7/
J`3{w2
@:Y@|R
t}set5>
o|uxK=
\ tdH6S
=v7{mj
j%(I=s
f87sNX0qD
rneL![
@+]zh:
4Yg2;mj>
?#lSM7w
8e],]
'<5.IQ
TAe^f&
A)9g'>
~6Y>B&[
.]vr@u
~b5@lo
1gszvE"
]uT57]
t3tY(
5>tt&g}]
of#nxj
U2s%zh
wKK8]v
tA,er)
#}`U".
`eS~rog
6oV)\Y
W$~PNm
|&Met+
f[~.)b
8u7Z[A
ow}\6[$i_Q
}=mRoS
2.V{Z5"_
7N2>b3*
|P_]p^
(f#46k
?IMm<]
`ToAJ}
VLyebW
<k6f2'C
#*R$w{t
rw{\V_
X~8>n0
{u~(MZ
jRa9B2
p|dw}s+
GX}B4F
}.->,#
%V>[$.[;
DXB.3y
ECGux\
:V48*`
C4b@PB
}2klbL
vE=:@zH
q:+niH
o(H5_:
<!ZSEB
aO#x3]R
=(87mn
e#n .n
eRMwF7
~t&i^s
HIO,~E"Z
Ns*>2i
ctAK&5
zQmS[`
N*uo:M
ehv;;F
9oDV@aE
irbm]
P#Y+cK
opO)2C
2~dkzx
GE&=C]
sIvsep
vrrq;=t+
]1zp'~}
}\eBH
tb5]__
RT@HNbm
Y3UcG];
51o *|
~O;,Va
*8F5lr=W
\$3c+`
'1_PhB
J<P#&Q
f-.tOU<
+ J_t' a1
.e*Gkh
'l;\T0&Y
b"M)<\%
=c*A9&
;qtLo47
x^']*>
QiDh&'@
t2+9{L
v#pfNs
(@9=*J
%2p{UN
vE6]Cz
5sM;O^
.*t3*j
=XRJqIh
VzMS96
U|+R3Q
JPoozq
Nkv$~g
Jo1l_p
rF}g"3
|:{0i7
25d?DDbG
Kp|hjK>
]lzWDT
:d'yAgu
/yh Y
DFbJSb#
pzk@fn
a&UQ'
^3<vUV
b[Z>2b
:XY'8v
a>weiE
SY)Ca\H
==nV]>h
>2+pIi
x|~}{[
j36-zT
Wm0GT=|
m:7W1Dq
jqv%XB
-w!^-}\
Z^9F<Z
b;:9=h
7|NSw *bN<D
d*l4)$
?r1zsc
u3h.ZE[
*RhE#Y
#*t8w,
sl@:G8c
gge~0$
c8t}5Y
wZmp*%
F5t,eb
<U?=TYg
eIrCUh
6Q,vz(
g7Ttb*
xBxf0a=
QDV7E'
9r@'oK
#->m"y
7`voeoy0U
YC_HI;
f}+[=b
5m|2WW
}7Pt2l
:ct7V`
?nV27r_i
_dUfRuS
kPnV0D
.n/A}HUJ
Y@v>UW)
U+LZn}^
*^l>c]
lc\:e1
NEvp.mE
L| ;W
vV^}!/
jZ&Yp]vr@}
5e}.%4E
JDw+JVYk
d]aN,3
ur02g}
~v{Zo0
0'){rRO
AqgMoA
Z(Jbnc2
V14BOZjH&
Dh4 WZ
f pT52
/dY#?p
\p6[!W
PM)D{;
_W*CSC
hq$\x?
tZ/!Vcz
D 9_3;m"
]VA<xw1T$
pU!7i8c
UlN?:"
R^v>\wS
)D2xo{
!}|/Wk:]
]t./+^
b)c9x(
I1i;#[
!8-iu]8{p
K_sOGr
TqTj=cY
YLV"&[
:n;B5Z
nZ]9(6
S4UEF
`O*"I_=
;MrE7+
K~gas"
n1pRr.
9K.)?eG
2W<)yD
qb*'mI
Daiu%lg
ooNR#H
Lk#B!-
#b%%&Zo
qTI(+Yc
!TkQ:z
@$l`"
v~m]~
fD%jDMVwd
S~O0 h
S!Aa*2
(ZqE$-
|+!j"<
09%M&F{
}4P_'W
NPk*O{L
0}'1"s
D3hg,w
6wmlx$IP
(&Fh,E
i-Hc-s
)aJXh
65g}pM d
3va8vi
SOX{;z
@R.'"c
}"@IQS
zgdiGUv
q~9iKnr
=8G1^e
^%j8W|
X6JHAX
B+'n*,
l'R<)-8
)pr`qj8
z77E R
rmhQ{aw\6R
akI<3-[
ns)Ya9
/2y5bx
&)lJ:
."PVc
s/o+Ho
(H-G\C9R`
Z:r?C.RP
.peERQ
(*DQTb
PSc)oI
V'ouP
pE`2Ym
bK$n8T
bhI"MO
2L88[L
sJs3c}6
(1p:nD
@w'$'o
\OXqvPOV
gD"[Y
y'd16=
1xeD.Vz
_S'wgz
X43<'OT=6x_u
;zQ-Xd
cev<Ek
\Ln<?F&A
ooKnf<
(wP=*93
JO>xOd
4s1n>V
?C6W/o{
j!vv=Ua^
qW@5ax|
Vz:5AO1
]],IC`"
3#?|h/=
f'U}kw
2m7!$,W
;l2%if
h\G^&
yq34Vp
e'8$2,
lfGoY~
yixsa1
<MZ/Hi
g\0`%f
h|?g@^
q~" oE
8(-4eV
$#mp0%
i<H;Y!
s.m8Pa
AQ/H1
,m>5/F
_<BVVP
R#=wUT
PGhz8K
u[E}5g
PE_eBO
["~ c$
|0bM2wh
F1#R |
oWcY;j
K1dz64
aLSa=Y
3Fn{^
t;"o<]/,
4M\fSx
PeG|maG
6p:bTG
B}WB1M
$\:|]=
WvrZ3z
_~HW9A
>qIojz!
D'Fq_O
ve69Va_
/Ny*%<
.b?"8'
0d)iZ
1s$4zM
aA>gFX
RnLG0y
r@t+u5q
o5/":l:>4!v
t-Oyn?
K},hfi
B?sV|a^|
8~5s%N
e,U-}
PRxG#(
y Fz D
*WD2X`j@
aX/+)v
Z5z\IIY
"^TU50
h\"(6V
H4qn-*
JnTnF
>x'_Ix
9G%K_u6
V-1mJO
+A|8bb\w
L%I,pd
,DWSwR
/DS6l8&b
&S+k~&
dmh1:72
@?Jn^(
c[Cv|>
}Fbf%qm
I+\aI
-?fb_v
9Wv^pN
0zx7BYl
{-.u=p
8<.3a8
mJ,#[%D^
D0(=zu
M5/9%Nt
9,[Lp=
s=Q%7h
NN/F',q
*QsyI?O
WQ"@=]
.!(395N
-a)?NW
b9U Ct(%
f$uyFB
Ehq+\m
=1Nl=l{
0R/qFvn
r6s&g*
#)1l3=>
5lAoXp
4C[$m+
TCC`Kv
p'L8%W\
!#|{Z5
rRz'vs
62F)}S
KDe2i&
y/{V~\F
bx'=e3
ud)$l1
%qv)o..V
;~$R<A
t?ZztE
X~vI<M
Gf{)/.8
_r'C"/
6](4d}
=Y^,yX
3Y%IUk
O89THh.
EcuxSl
::* pC
!UQR=>t
t]J-,i
C0IP!9
??LM;M
(>9|,
*PWl=yI
.aTk#^
v{PioG
h`~kFVI
1NpOFzB
/s2w5
6iKe9L\=
gJ@`pR;VO(
##/Mb`%
|y=GIC
Y3ISv}
>4m%<Y
|NFzkQx
KIi&AM
]mm$;
U|s%@^]b
$0*'Ha
SFNryd
%t2n6-&t
&yB!V
sV5v&.
@TdRWk
fH;^#r
7{0RDi
I1#EjX
.akz++|U
G!wE*$
zvG+-b)
jd|nfifU
,X@ti\
HA@9LW
BW"XR^)O#
K]'BD2
$l<cD`
^(Aun}
h$6rY-
e{/h\xWA
#l(,oX
P_E9#{
Yqi?FF
34.emz
xkmyJ(V
q*_\rU
u3f8t&
{h}#1w|6
~=ugy~X
hi Q1*
.-G- 0mf
<Ce+Wwo
QF%,1}
^*ID-/
o$G$S0
ND<s 8
P;&e.
,_`?iq1
>,m}&%
xCq6NI
'iXMS(
TcG{_Q
B[8#N$m
&"b?_r!
)c@3]u
ozjqCm%
h!Z)a)
r;EDKt
+`> QH
|s>g):
m!%p~`5
~+ 2&)b
w)`]O3
-QQQ_
<Meb/\'"F
AZd0#]&n)
i/$*"V
qjz0?\
k/Ay Z#
pk-v=,yoh
^-`#LQ
YAVkF@
4Gd>5u
Js1wSN
aC?F_) Tu
OCO `$
w%}us(#u`
aU]{eu{
?_* D:(
]=W*)1
AJc` :#W"|
n{l|3D
d9^Aqes5Q{
Y9&~bv
'*S5KI
Nu5_9-
%5x0nhN@N
675e'0
{iKtiZ
~ngqf[
h3>95?
^E{|zQ[
9x3yX
BEWMd\
hJ/hHs
$BHu?*]18
f/w`hO
hZP?v"
h1+o">G
5VFQ >8
u<Jby)
lG8SwD
5>$ed)m
iWBP;U
$Rif_0-
xRkk~w
j'vlk;
' SK6I
6`$e~
:py/-sx
{U`j38
H6DA/S.
h$A.Iq
u<5g`V
~NJeQ>[
f5<xh-C^
;[g>$hsc
inhslY
pqC~Uz
-d`Nnd^
WFyxrf
=|b&~~B%
g\rF>Y
#qr"J3
<j6<7f
D$v6L-
?3[%N"
.i*t+C
oxLuxcPZ
4m{pe?
Qu_DU6w
$}gk:R
sr9OdO
0Pdh/
~mW/LP
<Ve7Os
#75k1c
Q77y5k-
9DjT_(
3!/*vN>
'4SYrZ
&Gd5[s
Mv=sz$
a{7?J@
^U6cpv
(hq@"mK,q5\
B<g6^r
GduEAm4
kYsDzm
7I.Z$=+
^#dc>h6
ynIT>7/
F:>LmP
=OsD6I
vw4xm#^
z-h9z
zY,-!/i
22m<Cw:{
NK[{7BuZ
dnvK4T
3#M5~GP
?m*LPe]
tpHl1J
Xz#H5?n
4]az?^
b]<}trPT
g'.CHja
3'v@]NjQ9%FPt
Y%ez{>U
}Hw4\Zi
yvPI-N
>6v4`n
+4Hy*w
?y75pa
*N[];8Po
_,fH<ldBb#
W#H4g]
Cf;9;_
vK!*8nW&
}7(?C_+h
c@Sd.c
( luVd
tjKDDM
Wh;")v(
;t&#dB
8Qqwht
EY#9zG6
!h}r38
;KYeG4
$kNm]-
7\u(15h5
T1+&S7%
c`bcZ<
pN>^Cj
U>J*=N
Y:y4*yG
5GD7=O
WMO$iG-
++^Y#
dwq6-s
CK&6Z[,
~q:.F(?
j^-Vq1
SU(f#+{
_;Yk-X
nqRe/GBe
Amz`$r
??2FWL
Iw<#V
>M&{I>]
SOhzJ{
=ruNp0
1mBa)^_t+)
|{LY\T
Xt;9<!
=oA4k4o
"7o4/h
lApDR<
JN;#)w
cPZo[s
_XfoTI
K.p3OS
/:G=9Q
JR%Ef)a
&,GY2^
7ZGwY>P
cY/h!2M
K.:ae*}
?l-]!#
WL5b~D_
~TW2p?D?
W22UoeO
/@#x89
FN}_9F
Z(mJz,b
IX1y]
4+^t(1
=9CQ-C
j$CX{Nx
6[.0E
*j1y+po5
EiEe$'
=k.~,d
&<c}
Qg,>GU
PlZPR&I
7~'fHg
u5;Yo-'b
;NVsK33
GoV&rr
!vp!>0A'OI
I48<jf_
CV&r"
PdhAK_
|H%qv%
}(d)~H
`-6LCN
ICwt|a
R0`$RK
6Kp'k}
-Iio(KMn\Z
_n}BL<
i/90^O/V
|]k*Y!
-U.K8]
N/}qpQ
Iq9] ,0
j*r/i5
g!3Zui
qwTLwt,
fhuQ1
^R' G{
]zV8T`
Wa~j$\
w89 @y
aXj)y1Xj
irC]?I
Ra{on%
m4#=Co
e{[w#7
fg`'A"
rnB,|X
[LD:'&L#4
7_nu{C5
@`7ztw
k;MV\*
:E.T41
tf0P&c&
U&|G0<
|hldc[
-'[P1tf
=}9\NH
-FO-~t
2=0l}!
N a}@B
^&V'Z`
q~)6\M
R[w~<nd
-p:ZA(w
o7W8!&
4*s'i$R
AH+1%8%
[lQ~[ vBD
6.&x#T
pVe ]^
(?LEp+
_O]pY
o;5\]d
@gxV]yC
yuY#F[
o[+<P)
uMA>shP
Mf>m,T
cHW}AO
D'.En<
QKZ'!q
#B{r2H:
-7rqb.
N>8M$|
LF"1+mU
M&"nMr
gN3JtWT
"0/9^Q
,WC*Ajx
RB5S=v
oneX/!l
9XyiYI
?1\RS]zj"
|R6`;}
](#'`[q
^`0$Po
~pt]pK
?TMhg)Lg
1cfxGmO
n{h~y\
ID^eW<
MP|q(t
Vzv0ib
NvX2kA
rN7\0[r%C
Y3K*/3
)nLVbcu{
%BVL]f\
FXn.5_=*
GFxc.i
0.2b9{
=omRyNZ\
`/8%0l
[qwS&q
"c0:WBR
U>//:W
FJ"G,J
ZI/'L4
~HKh!,J
!w7<pZ
[~Ek0iN
{I^c~+
;oTJ,&#
9rXIKcViVD4
AM"(Z""c^
(-42"$
;).MC=
55Gdtf
jB^5UY
f)ti;+
4{`8I;
'?BxfA
}H"#?]/
PE{hQN<
jzr_@*?
5D5 DY7
_H'4A#
drcDjXWxq
3sX~5/
2 YMiM,
"o88.0
=`w/+X
Uxs,,H!Bm)
'7aUfH]
rDZG1&
f7kW}V
e7(i12
PTYcWr<1.
on.ds:
J_c:(`7wz7
Oo+Ys>-A
@t\fs#
P_yFEZ
6\<}g`
Q o7^h
TG!nr$
pKd+7
$O8V4x
4njIN_
>Nz$Ki
.=52.CO@I
:4"sQu
6ZT#cl
E>MJ0[
\H9H`fm
/\9G0h
CorExitProcess
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
Lazexohex xewiset gepes
Zohiboluvitepem
Damilasosasalep
tilibevonisesayetecacimofizojokepabovobaciki
saxaxos
VirtualProtect
kernel32.dll
LocalAlloc
bawatizebitotinoxenepekederajecofepofewudoyajemihexiz
C:\jigusisowapi\gapuvaxa.pdb
SetProcessAffinityMask
HeapCompact
GetDefaultCommConfigW
LoadResource
GetSystemWindowsDirectoryW
QueryPerformanceCounter
GetEnvironmentStringsW
SetConsoleScreenBufferSize
BackupSeek
GetTickCount
GetProcessHeap
GetSystemTimeAsFileTime
ReadConsoleW
GetFirmwareEnvironmentVariableA
GetProcessHandleCount
InitAtomTable
HeapValidate
WriteConsoleW
DeactivateActCtx
LCMapStringA
GetConsoleOutputCP
SetLastError
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
GetAtomNameA
LoadLibraryA
LocalAlloc
GetModuleFileNameA
GetConsoleCursorInfo
DeleteAtom
AddConsoleAliasA
FindNextVolumeA
lstrcpyW
CommConfigDialogW
KERNEL32.dll
ShowCursor
USER32.dll
AdjustTokenGroups
ADVAPI32.dll
GetLastError
HeapReAlloc
GetModuleHandleW
ExitProcess
DecodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetCurrentProcess
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
IsProcessorFeaturePresent
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
SetFilePointer
HeapCreate
HeapFree
CloseHandle
LoadLibraryW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
WriteFile
GetModuleFileNameW
FreeEnvironmentStringsW
WideCharToMultiByte
GetCurrentProcessId
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
RaiseException
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
LCMapStringW
MultiByteToWideChar
GetStringTypeW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
&FEEEE/:EE:E/E/E/E//>//E/EE:
d\)w+{\g
JJvig&
vUsLpSg
.O?u~?
uEiF0Fm00b0
L:{'X:h3
4}}{k}
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
______-
_____-
{{{{{{{{{{{
G00000000000000000000000000
LLLLLLLLLLLLLL
LLLLLL`
LLLLLLL2
LLLLLL
H--------
--------------------
%%%%%%%%%%%%%%%%%%
YYYYYYYYYY%
YYYYYY
%qqqqq
%qqqqq
%qqqqqqY8
%qqqqqqqY8
%qqqqqqqqH
gggggggggK
ggggggggggg?K
3HShT7e~
mscoree.dll
(null)
wKERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
HMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
pCizizikin
peraleyuwawusogeyodotu
VS_VERSION_INFO
StringFileInform
090104a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.12.21
VarFileInfo
Translation
)Judisigidu rizuxuxoci yanor cuk yijanilug
bFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibikKRexiyosununuti rihoxorowopal vemerey fawunujokog foco xacovuku luhohefaneru3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.80001
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0058a41f1 )
BitDefender Trojan.GenericKDZ.80001
K7GW Trojan ( 0058a41f1 )
Cybereason malicious.38ec6d
Baidu Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 a variant of Win32/Kryptik.HNGW
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Fragtor-9907126-0
Kaspersky HEUR:Trojan-Spy.Win32.Zbot.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKDZ.80001
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.jc
FireEye Generic.mg.9be7ba9afcb345e5
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Fragtor.40092
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Jaik.DC051
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Raccrypt.GF!MTB
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R449620
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34266.Oq0@aSDPj1gc
ALYac Clean
MAX malware (ai score=87)
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Heuristic!ET#96% (RDMK:cmRtazrXfmKdzUl7qhEjXpkuYJNn)
Yandex Clean
Ikarus Trojan-Ransom.StopCrypt
eGambit Unsafe.AI_Score_99%
Fortinet W32/Kryptik.FOQ!tr
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.