Static | ZeroBOX

PE Compile Time

2022-07-16 22:18:05

PE Imphash

8513d38276d3bae5f771a5f33a9b91c2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00020ffc 0x00021000 6.67162461629
.rdata 0x00022000 0x00007de4 0x00008000 4.98872165589
.data 0x0002a000 0x00006278 0x00003000 2.81510533442
.rsrc 0x00031000 0x00009340 0x0000a000 5.54797565919

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x00032de4 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00032fd0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00032fd0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00038194 0x00000368 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_DIALOG 0x000386ec 0x00000034 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000386ec 0x00000034 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000386ec 0x00000034 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00039dac 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00039f18 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00039f2c 0x00000084 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x00039fb0 0x00000338 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x0003a2e8 0x00000056 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x42208c HeapFree
0x422090 HeapAlloc
0x422094 GetProcessHeap
0x422098 GetStartupInfoW
0x42209c ExitProcess
0x4220a0 RtlUnwind
0x4220a4 RaiseException
0x4220a8 HeapReAlloc
0x4220ac HeapSize
0x4220b0 GetStdHandle
0x4220b4 GetModuleFileNameA
0x4220cc GetCommandLineA
0x4220d0 GetCommandLineW
0x4220d4 SetHandleCount
0x4220d8 GetFileType
0x4220dc GetStartupInfoA
0x4220e0 HeapDestroy
0x4220e4 HeapCreate
0x4220e8 VirtualFree
0x4220f0 GetTickCount
0x4220fc IsDebuggerPresent
0x422100 VirtualAlloc
0x422104 Sleep
0x422108 GetCPInfo
0x42210c GetACP
0x422110 GetOEMCP
0x422114 GetLocaleInfoA
0x422118 GetConsoleCP
0x42211c GetConsoleMode
0x422120 GetStringTypeA
0x422124 GetStringTypeW
0x422128 LCMapStringA
0x42212c LCMapStringW
0x422130 SetStdHandle
0x422134 WriteConsoleA
0x422138 GetConsoleOutputCP
0x42213c WriteConsoleW
0x422140 CreateFileA
0x422144 SetErrorMode
0x422148 lstrlenA
0x42214c GetCurrentProcess
0x422150 FlushFileBuffers
0x422154 SetFilePointer
0x422158 WriteFile
0x42215c ReadFile
0x422160 GetThreadLocale
0x422164 GlobalFlags
0x422168 TlsFree
0x422170 LocalReAlloc
0x422174 TlsSetValue
0x422178 TlsAlloc
0x422180 GlobalHandle
0x422184 GlobalReAlloc
0x42218c TlsGetValue
0x422194 LocalAlloc
0x42219c GlobalFindAtomW
0x4221a0 CompareStringW
0x4221a4 LoadLibraryA
0x4221a8 GetVersionExA
0x4221b0 GetCurrentProcessId
0x4221b4 GlobalAddAtomW
0x4221b8 CloseHandle
0x4221bc FreeResource
0x4221c4 GetCurrentThread
0x4221c8 GetCurrentThreadId
0x4221d0 GetModuleFileNameW
0x4221d4 GetVersion
0x4221dc lstrcmpA
0x4221e0 GetLocaleInfoW
0x4221e4 LoadLibraryW
0x4221e8 WideCharToMultiByte
0x4221ec InterlockedExchange
0x4221f0 lstrcmpW
0x4221f4 FreeLibrary
0x4221f8 GlobalDeleteAtom
0x4221fc GetModuleHandleW
0x422200 GetLastError
0x422204 SetLastError
0x422208 GlobalFree
0x42220c GlobalAlloc
0x422210 GlobalLock
0x422214 GlobalUnlock
0x422218 FormatMessageW
0x42221c LocalFree
0x422220 FindResourceW
0x422224 LoadResource
0x422228 LockResource
0x42222c SizeofResource
0x422230 lstrlenW
0x422234 MulDiv
0x422238 GetModuleHandleA
0x42223c GetProcAddress
0x422240 TerminateProcess
0x422244 MultiByteToWideChar
Library USER32.dll:
0x42229c UnregisterClassW
0x4222a0 LoadCursorW
0x4222a4 GetSysColorBrush
0x4222a8 ShowWindow
0x4222ac SetWindowTextW
0x4222b0 IsDialogMessageW
0x4222b8 SendDlgItemMessageW
0x4222bc SendDlgItemMessageA
0x4222c0 WinHelpW
0x4222c4 GetCapture
0x4222c8 GetClassLongW
0x4222cc GetClassNameW
0x4222d0 SetPropW
0x4222d4 GetPropW
0x4222d8 RemovePropW
0x4222dc SetFocus
0x4222e0 GetWindowTextW
0x4222e4 GetForegroundWindow
0x4222e8 GetTopWindow
0x4222ec GetMessageTime
0x4222f0 GetMessagePos
0x4222f4 MapWindowPoints
0x4222f8 SetForegroundWindow
0x4222fc UpdateWindow
0x422300 GetMenu
0x422304 CreateWindowExW
0x422308 GetClassInfoExW
0x42230c GetClassInfoW
0x422310 RegisterClassW
0x422314 AdjustWindowRectEx
0x422318 CopyRect
0x42231c PtInRect
0x422320 GetDlgCtrlID
0x422324 DefWindowProcW
0x422328 CallWindowProcW
0x42232c SetWindowLongW
0x422330 SetWindowPos
0x422338 GetWindowPlacement
0x42233c GetWindowRect
0x422340 GetWindow
0x422344 GetSysColor
0x422348 EndPaint
0x42234c BeginPaint
0x422350 ReleaseDC
0x422354 GetDC
0x422358 ClientToScreen
0x42235c GrayStringW
0x422360 DrawTextExW
0x422364 DrawTextW
0x422368 TabbedTextOutW
0x42236c wsprintfW
0x422370 LoadIconW
0x422374 UnregisterClassA
0x422378 IsIconic
0x42237c SendMessageW
0x422380 GetSystemMetrics
0x422384 UnhookWindowsHookEx
0x42238c GetLastActivePopup
0x422390 MessageBoxW
0x422394 SetCursor
0x422398 SetWindowsHookExW
0x42239c CallNextHookEx
0x4223a0 GetMessageW
0x4223a4 TranslateMessage
0x4223a8 DispatchMessageW
0x4223ac IsWindowVisible
0x4223b0 DestroyMenu
0x4223b4 GetClientRect
0x4223b8 DrawIcon
0x4223bc EnableWindow
0x4223c0 GetSubMenu
0x4223c4 GetMenuItemCount
0x4223c8 GetMenuItemID
0x4223cc GetMenuState
0x4223d0 PostMessageW
0x4223d4 PostQuitMessage
0x4223d8 EndDialog
0x4223dc GetNextDlgTabItem
0x4223e0 GetParent
0x4223e4 IsWindowEnabled
0x4223e8 GetDlgItem
0x4223ec GetWindowLongW
0x4223f0 GetKeyState
0x4223f4 PeekMessageW
0x4223f8 GetCursorPos
0x4223fc ValidateRect
0x422400 SetMenuItemBitmaps
0x422408 LoadBitmapW
0x42240c GetFocus
0x422410 ModifyMenuW
0x422414 EnableMenuItem
0x422418 CheckMenuItem
0x42241c GetDesktopWindow
0x422420 GetActiveWindow
0x422424 SetActiveWindow
0x42242c DestroyWindow
0x422430 IsWindow
Library GDI32.dll:
0x422028 DeleteDC
0x42202c GetStockObject
0x422030 ScaleWindowExtEx
0x422034 SetWindowExtEx
0x422038 ScaleViewportExtEx
0x42203c ExtTextOutW
0x422040 SetViewportExtEx
0x422044 OffsetViewportOrgEx
0x422048 SetViewportOrgEx
0x42204c SelectObject
0x422050 GetDeviceCaps
0x422054 TextOutW
0x422058 RectVisible
0x42205c PtVisible
0x422060 GetObjectW
0x422064 DeleteObject
0x422068 GetClipBox
0x42206c SetMapMode
0x422070 SetTextColor
0x422074 SetBkColor
0x422078 RestoreDC
0x42207c SaveDC
0x422080 CreateBitmap
0x422084 Escape
Library WINSPOOL.DRV:
0x422438 ClosePrinter
0x42243c DocumentPropertiesW
0x422440 OpenPrinterW
Library ADVAPI32.dll:
0x422000 RegQueryValueW
0x422004 RegEnumKeyW
0x422008 RegDeleteKeyW
0x42200c RegSetValueExW
0x422010 RegCreateKeyExW
0x422014 RegOpenKeyExW
0x422018 RegQueryValueExW
0x42201c RegOpenKeyW
0x422020 RegCloseKey
Library SHELL32.dll:
0x422288 ShellExecuteExW
Library SHLWAPI.dll:
0x422290 PathFindFileNameW
0x422294 PathFindExtensionW
Library ole32.dll:
Library OLEAUT32.dll:
0x42224c SysAllocString
0x422254 SysStringByteLen
0x422258 SysFreeString
0x42225c VariantInit
0x422260 VariantClear
0x422264 SysAllocStringLen
0x422268 SafeArrayGetDim
0x42226c SafeArrayGetLBound
0x422270 SafeArrayGetUBound
0x422274 SafeArrayAccessData
0x42227c VariantChangeType
0x422280 GetErrorInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
VWh@[B
D$Proot
D$T\cim
L$HQhPYB
RSSSSS
T$(RSUP
T$ RSP
T$(RSSUVP
t$$u!h
D$xPhH
D$ +D$
L$|_^[3
VWh`+B
PWVWWW
QQSUVW
0UUUUW
WtrHHt
tA9wht<
9p t-S
whh2)@
g9n t_;
udhL'B
tShp3B
tBh\3B
S\_^[]
S\_^[]
FD_^][
j h c@
t39w u&
_ 9w$u
uMh2)@
O 9Htu
u0j0^VP
WWWWhd
SVWj(3
+F(_;E
F(@@;F,v
F(;^ r
F(;F0u
^(_^[]
tj9~8u@j
k9~8uDj
F4_]^[
0WWWWW
YYuTVWh
0WWWWW
BBFFf;
0WWWWW
@@BBf;
@@BBf;
0WWWWW
QQSVWd
8VVVVV
AAGGf;
>=Yt/j
4~f9.u
QQSVWh
@@f98u
@@f98u
j(j ^V
YYu-9D$
HtHu4j
s[S;7|G;w
tR99u2
URPQQh
_VVVVV
^WWWWW
u,hhFB
0SSSSS
0SSSSS
0SSSSS
t^9(uZ
tD9(u@
0A@@Ju
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
^SSSSS
0SSSSS
_VVVVV
PPPPPPPP
PPPPPPPP
tb9} u
<+t(<-t$:
+t HHt
u&f!;f;
t+WWVPV
9~$~!S
COleException
CInvalidArgException
CNotSupportedException
CMemoryException
CException
CWinApp
DeactivateActCtx
ActivateActCtx
ReleaseActCtx
CreateActCtxW
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
CDialog
CCmdTarget
CWinThread
CGdiObject
CPaintDC
CUserException
CResourceException
GetMonitorInfoA
GetMonitorInfoW
EnumDisplayDevicesW
EnumDisplayMonitors
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
GetSystemMetrics
DISPLAY
InitCommonControls
InitCommonControlsEx
HtmlHelpW
hhctrl.ocx
Exception thrown in destructor
f:\rtm\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
CObject
CMapPtrToPtr
CArchiveException
NotifyWinEvent
CByteArray
CObArray
CPtrArray
CorExitProcess
mscoree.dll
bad allocation
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
KERNEL32.DLL
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
InitializeCriticalSectionAndSpinCount
kernel32.dll
bad exception
GAIsProcessorFeaturePresent
KERNEL32
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
Unknown exception
(null)
`h````
xpxxxx
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
CONOUT$
OLEACC.dll
kernel32
LoadLibraryA
SHELL32
USER32
OLEAUT32
GetEnvironmentVariableW
wsprintfW
lstrcatW
CloseHandle
CoSetProxyBlanket
CoCreateInstance
WriteFile
CreateFileW
CreateStdAccessibleObject
LresultFromObject
MultiByteToWideChar
GetProcAddress
GetModuleHandleA
MulDiv
lstrlenW
SizeofResource
LockResource
LoadResource
FindResourceW
LocalFree
FormatMessageW
GlobalUnlock
GlobalLock
GlobalAlloc
GlobalFree
SetLastError
GetLastError
GetModuleHandleW
GlobalDeleteAtom
FreeLibrary
lstrcmpW
InterlockedExchange
WideCharToMultiByte
LoadLibraryW
GetLocaleInfoW
lstrcmpA
EnumResourceLanguagesW
GetVersion
GetModuleFileNameW
ConvertDefaultLocale
GetCurrentThreadId
GetCurrentThread
WritePrivateProfileStringW
FreeResource
CloseHandle
GlobalAddAtomW
GetCurrentProcessId
InterlockedDecrement
GetVersionExA
LoadLibraryA
CompareStringW
GlobalFindAtomW
InterlockedIncrement
LocalAlloc
LeaveCriticalSection
TlsGetValue
EnterCriticalSection
GlobalReAlloc
GlobalHandle
InitializeCriticalSection
TlsAlloc
TlsSetValue
LocalReAlloc
DeleteCriticalSection
TlsFree
GlobalFlags
GetThreadLocale
ReadFile
WriteFile
SetFilePointer
FlushFileBuffers
GetCurrentProcess
lstrlenA
SetErrorMode
HeapFree
HeapAlloc
GetProcessHeap
GetStartupInfoW
ExitProcess
RtlUnwind
RaiseException
HeapReAlloc
HeapSize
GetStdHandle
GetModuleFileNameA
UnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapDestroy
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
TerminateProcess
SetUnhandledExceptionFilter
IsDebuggerPresent
VirtualAlloc
GetCPInfo
GetACP
GetOEMCP
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
GetStringTypeA
GetStringTypeW
LCMapStringA
LCMapStringW
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
KERNEL32.dll
wsprintfW
LoadIconW
IsIconic
SendMessageW
GetSystemMetrics
GetClientRect
DrawIcon
EnableWindow
GetSubMenu
GetMenuItemCount
GetMenuItemID
GetMenuState
PostMessageW
PostQuitMessage
EndDialog
GetNextDlgTabItem
GetParent
IsWindowEnabled
GetDlgItem
GetWindowLongW
IsWindow
DestroyWindow
CreateDialogIndirectParamW
SetActiveWindow
GetActiveWindow
GetDesktopWindow
CheckMenuItem
EnableMenuItem
ModifyMenuW
GetFocus
LoadBitmapW
GetMenuCheckMarkDimensions
SetMenuItemBitmaps
ValidateRect
GetCursorPos
PeekMessageW
GetKeyState
IsWindowVisible
DispatchMessageW
TranslateMessage
GetMessageW
CallNextHookEx
SetWindowsHookExW
SetCursor
MessageBoxW
GetLastActivePopup
GetWindowThreadProcessId
UnhookWindowsHookEx
TabbedTextOutW
DrawTextW
DrawTextExW
GrayStringW
ClientToScreen
ReleaseDC
BeginPaint
EndPaint
GetSysColor
GetWindow
GetWindowRect
GetWindowPlacement
SystemParametersInfoA
SetWindowPos
SetWindowLongW
CallWindowProcW
DefWindowProcW
GetDlgCtrlID
PtInRect
CopyRect
AdjustWindowRectEx
RegisterClassW
GetClassInfoW
GetClassInfoExW
CreateWindowExW
GetMenu
UpdateWindow
SetForegroundWindow
MapWindowPoints
GetMessagePos
GetMessageTime
GetTopWindow
GetForegroundWindow
GetWindowTextW
SetFocus
RemovePropW
GetPropW
SetPropW
GetClassNameW
GetClassLongW
GetCapture
WinHelpW
SendDlgItemMessageA
SendDlgItemMessageW
RegisterWindowMessageW
IsDialogMessageW
SetWindowTextW
ShowWindow
GetSysColorBrush
LoadCursorW
UnregisterClassW
DestroyMenu
USER32.dll
GetDeviceCaps
CreateBitmap
SaveDC
RestoreDC
SetBkColor
SetTextColor
SetMapMode
GetClipBox
DeleteObject
GetObjectW
PtVisible
RectVisible
TextOutW
ExtTextOutW
Escape
SelectObject
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
SetWindowExtEx
ScaleWindowExtEx
DeleteDC
GetStockObject
GDI32.dll
ClosePrinter
DocumentPropertiesW
OpenPrinterW
WINSPOOL.DRV
RegCloseKey
RegOpenKeyW
RegQueryValueExW
RegOpenKeyExW
RegCreateKeyExW
RegSetValueExW
RegDeleteKeyW
RegEnumKeyW
RegQueryValueW
ADVAPI32.dll
ShellExecuteExW
SHELL32.dll
PathFindExtensionW
PathFindFileNameW
SHLWAPI.dll
CoInitializeSecurity
ole32.dll
OLEAUT32.dll
UnregisterClassA
.?AVCOleException@@
.?AVCException@@
.PAVCOleException@@
.PAVCException@@
.PAVCObject@@
.PAVCMemoryException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCMemoryException@@
.?AVCSimpleException@@
.?AVCNotSupportedException@@
.?AVCInvalidArgException@@
.?AVCCmdUI@@
.?AV_AFX_THREAD_STATE@@
.?AVCNoTrackObject@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AVAFX_MODULE_STATE@@
.?AVCDllIsolationWrapperBase@@
.?AVCComCtlWrapper@@
.?AVCCommDlgWrapper@@
.?AV_AFX_BASE_MODULE_STATE@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCResourceException@@
.?AVCUserException@@
.?AVCGdiObject@@
.?AVCDC@@
.?AVCPaintDC@@
.?AVXAccessible@CWnd@@
.?AVXAccessibleServer@CWnd@@
.?AVCTestCmdUI@@
.?AV_AFX_HTMLHELP_STATE@@
.?AV?$IAccessibleProxyImpl@VCAccessibleProxy@ATL@@@ATL@@
.?AUIAccessible@@
.?AUIDispatch@@
.?AUIUnknown@@
.?AUIAccessibleProxy@@
.?AV?$CMFCComObject@VCAccessibleProxy@ATL@@@@
.?AVCAccessibleProxy@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AUIOleWindow@@
.?AVCAfxStringMgr@@
.?AUIAtlStringMgr@ATL@@
.?AUCThreadData@@
.?AVCHandleMap@@
.?AVCMapPtrToPtr@@
.?AVCMenu@@
.PAVCArchiveException@@
.?AVCArchiveException@@
.?AVCObArray@@
.?AVCByteArray@@
.?AVCPtrArray@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_com_error@@
ShellExecuteExW
SafeArrayUnaccessData
GetModuleFileNameW
.?AVCObject@@
.?AVCCmdTarget@@
.?AVCWinThread@@
.?AVCWinApp@@
.?AVCUserLoginApp@@
.?AVCWnd@@
.?AVCDialog@@
.?AVCUserLoginDlg@@
wwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwww}
wwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwww}
wwwwwww}x
}wwwwwww}
_`__``_``a`_`_aaaa`
! !
i\\\\\\\\[\\\\\\\[\\a///2/////////2/22///
da2/BB<<<<777111,,,*/
RFGHJCDKLL=>>88+/
[`//"QRT$
1=>>8+2
\`2/"OQ
$%=>>*2
\a//"NO
\a//"WN
FTHI*++LL=(/
\`//'VW
RFTHJCDKLL)2
j\]x|~
\_//'VV
QRFTHJCDKL(/
i\^wx|~pcccccb
\`//'UV
OQRFGHJCDK(/
i\]wwx|pcckrss
\a//0UU
NOQRSGHIJD(2
i\^vwwxpccr
\`///YU
WNOQRFTHIJ)/
j\]uvwwmccp
\`//9YY
VWNO5;*THI)2
j\]uuvwmccp
\a//9XY
i\]ouuvmccbbbbbs
\a//@XX0
RST)/
i\]oouulefffggkt
\`/2@ZXX:
;NPRF(/
h\]loouuvwwx|~
\_2/@ZZXXYYUUUVWNOPQ(/
i\]ffggkkqqqzzz{{{
\_//?MMMMEEEAAAA33452
i\\\\\\\\\\\\\\\\\\\`//&&&&&--&&&&-&&&&./
illlllllll
]ZZZZZZZZZZZWV-1---------1-
mV2.AHBC5D;<<(-
kV2.P:#
!!+=>(-
OGJKD;*1
]d}~wca``
OOGJKD*1
\dy}rch{
MNOGIK/1
\buyrcj
RR.#:I/-
[btuncfssv
]_ptqhhhjj
kV?LTE
]_mptuy}~
lV6SUTTQQQRRN91
[WXXXYXXYXYYWV-)))))))))),,
F5><<==.
ECK2LPV.
E@J3MOU.
D?H31IT.
B;G1JKS.(
E9A011R.&#
E/4678:."&'
NQWhX^XXXe
djklnoc
sgba`_f|
ux||||
# # # # # # # #! # #! #! # # # # # # # #gdc # # #! # # # # # # # # # # # # # # # # #
t5! #! #
b;wi=ua=ua=ua=ua<u`=ua=ua<u`9d[qikunntnntnnunntnnunnunntpwyr
4@egdc
5@fgdc
5@fgdc
4@egdc
5Afgdc
4@egdc
5@fgdc
5@fgdc
4@egdc
4@egdc
5@fgdc
5Afgdc
5@egdc
5@fgdc
# # # # # # # # # # # # #
# # # # # # # # # # # # #
BL@BM@BM@BL@BL@BL@BL@BM@CMABM@BL@BL@ #w\Rv\Rw]Sw\Rw\Rw\Sv\Rv\Rw\Rw]Sw]Sw]StYQ1-/ #
t6REE #
t6RDD #
t5REE #
t5RDE #
u6RDD #
=REE #
=REE #
=SEE #
=REE #
=REE #
=SEE #
=SEE #
;tcc #
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPAD
pSettings
PreviewPages
KERNEL32
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
RestrictRun
NoNetConnectDisconnect
NoRecentDocsHistory
NoClose
Software\Microsoft\Windows\CurrentVersion\Policies\Network
NoEntireNetwork
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
NoPlacesBar
NoBackButton
NoFileMru
ntdll.dll
Control Panel\Desktop\ResourceLocale
kernel32.dll
%s.dll
software
MS Shell Dlg
@Software\
@comctl32.dll
@comdlg32.dll
AfxWnd80su
AfxControlBar80su
AfxMDIFrame80su
AfxFrameOrView80su
AfxOleControl80su
AfxOldWndProc423
USER32
YaccParent
accChildCount
accChild
accName
accValue
accDescription
accRole
accState
accHelp
accHelpTopic
accKeyboardShortcut
accFocus
accSelection
accDefaultAction
accSelect
accLocation
accNavigate
accHitTest
accDoDefaultAction
#32768
%s (%s:%d)
%s (%s:%d)
commctrl_DragListMsg
@System
@MSWHEEL_ROLLMSG
user32.dll
(null)
((((( H
h(((( H
H
Delete
NoRemove
ForceRemove
Local AppWizard-Generated Applications
UserLogin
MS Shell Dlg
Cancel
TODO: Place dialog controls here.
MS Shell Dlg
Cancel
MS Shell Dlg
Save As
All Files (*.*)
Untitled
an unnamed file
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Out of memory.
An unknown error has occurred.$An invalid argument was encountered.
Invalid filename.
Failed to open document.
Failed to save document.
Save changes to %1? Failed to create empty document.
The file is too large to open.
Could not start print job.
Failed to launch help.
Internal application error.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Please enter an integer.
Please enter a number.*Please enter an integer between %1 and %2.(Please enter a number between %1 and %2.(Please enter no more than %1 characters.
Please select a button.*Please enter an integer between 0 and 255. Please enter a positive integer. Please enter a date and/or time.
Please enter a currency.
Please enter a GUID.
Please enter a time.
Please enter a date.
Unexpected file format.V%1
Cannot find this file.
Please verify that the correct path and file name are given.Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
%1: %2
Continue running script?
Dispatch exception: %1
#Unable to read write-only property.#Unable to write read-only property.
#Unable to load mail system support.
Mail system DLL is invalid.!Send Mail failed to send message.
No error occurred.-An unknown error occurred while accessing %1.
%1 was not found.
%1 contains an invalid path.=%1 could not be opened because there are too many open files.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on %15A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
%1 has a bad format."%1 contained an unexpected object. %1 contains an incorrect schema.
pixels
Uncheck
VS_VERSION_INFO
StringFileInfo
040904e4
CompanyName
TODO: <Company name>
FileDescription
TODO: <File description>
FileVersion
1.0.0.1
InternalName
UserLogin.exe
LegalCopyright
TODO: (c) <Company name>. All rights reserved.
OriginalFilename
UserLogin.exe
ProductName
TODO: <Product name>
ProductVersion
1.0.0.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (moderate confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Zusy.432628
FireEye Gen:Variant.Zusy.432628
CAT-QuickHeal Clean
ALYac Gen:Variant.Zusy.432628
Cylance Unsafe
VIPRE Gen:Variant.Zusy.432628
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.432628
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Trojan.Gen.2
tehtris Clean
ESET-NOD32 Clean
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Backdoor.Manuscrypt!8.110D5 (C64:YzY0OgX6ew17JcXcfQ)
Ad-Aware Gen:Variant.Zusy.432628
Emsisoft Gen:Variant.Zusy.432628 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Trojan:Win32/Emotet!ml
Gridinsoft Clean
Arcabit Trojan.Zusy.D699F4
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Zusy.432628
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!72DCEACC4CA9
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG DropperX-gen [Drp]
Avast DropperX-gen [Drp]
CrowdStrike Clean
No IRMA results available.