Static | ZeroBOX

PE Compile Time

2022-12-10 07:03:50

PDB Path

C:\fehoxexe sopakiv key\Xejawa_leviw\patin dir.pdb

PE Imphash

2ea0d8985489fac9d703f2d23c1ba077

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001225c6 0x00122600 7.92485619711
.rdata 0x00124000 0x000058dc 0x00005a00 5.0494806665
.data 0x0012a000 0x001c68e0 0x00001600 3.33937534752
.rsrc 0x002f1000 0x000287a8 0x00028800 7.57328353284
.reloc 0x0031a000 0x00006312 0x00006400 4.99522597036

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x003181c8 0x00000128 LANG_ROMANIAN SUBLANG_ROMANIAN GLS_BINARY_LSB_FIRST
RT_DIALOG 0x00318830 0x0000012c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_DIALOG 0x00318830 0x0000012c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_DIALOG 0x00318830 0x0000012c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_DIALOG 0x00318830 0x0000012c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_DIALOG 0x00318830 0x0000012c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_STRING 0x003194f4 0x0000008c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_STRING 0x003194f4 0x0000008c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_STRING 0x003194f4 0x0000008c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_STRING 0x003194f4 0x0000008c LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_GROUP_ICON 0x00319580 0x000000ca LANG_ROMANIAN SUBLANG_ROMANIAN data
RT_MANIFEST 0x0031964c 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x524004 GetFileSize
0x524008 GlobalDeleteAtom
0x52400c TlsGetValue
0x524018 HeapAlloc
0x52401c HeapFree
0x524024 SleepEx
0x524028 GetTickCount
0x52402c GetCurrentThread
0x524030 GetProcessHeap
0x524034 IsBadReadPtr
0x52403c GetCurrencyFormatW
0x524040 GetConsoleCP
0x524044 LoadLibraryW
0x524048 Sleep
0x52404c HeapCreate
0x524050 GetFileAttributesW
0x524054 ReadFile
0x524058 CreateFileW
0x52405c GetACP
0x524060 lstrlenW
0x524064 RaiseException
0x524068 GetLastError
0x52406c SetLastError
0x524070 GetProcAddress
0x524074 IsValidCodePage
0x524078 GetLargePageMinimum
0x52407c FoldStringW
0x524080 SetConsoleTitleW
0x524084 GetModuleHandleA
0x524088 GetThreadId
0x52408c GetConsoleTitleW
0x524090 GetCurrentThreadId
0x524094 CloseHandle
0x524098 GetCurrentProcessId
0x52409c GlobalAddAtomW
0x5240a0 GetThreadUILanguage
0x5240a4 WriteConsoleW
0x5240a8 GetStringTypeW
0x5240ac LCMapStringW
0x5240b4 MultiByteToWideChar
0x5240b8 SetEndOfFile
0x5240bc SetFilePointer
0x5240c0 FlushFileBuffers
0x5240c4 GetConsoleMode
0x5240c8 SetStdHandle
0x5240cc HeapReAlloc
0x5240d0 HeapSize
0x5240d4 WideCharToMultiByte
0x5240d8 GetOEMCP
0x5240dc GetCPInfo
0x5240e0 CreateFileA
0x5240e8 GetCommandLineW
0x5240ec HeapSetInformation
0x5240f0 GetStartupInfoW
0x5240f4 TerminateProcess
0x5240f8 GetCurrentProcess
0x524104 IsDebuggerPresent
0x524108 GetModuleHandleW
0x52410c ExitProcess
0x524110 DecodePointer
0x524114 WriteFile
0x524118 GetStdHandle
0x52411c GetModuleFileNameW
0x524120 EncodePointer
0x524130 RtlUnwind
0x524138 SetHandleCount
0x52413c GetFileType
0x524140 TlsAlloc
0x524144 TlsSetValue
0x524148 TlsFree
Library USER32.dll:
0x524160 IsMenu
0x524164 IsZoomed
0x524168 GetLastActivePopup
0x52416c GetParent
0x524174 AnyPopup
0x524178 wsprintfW
0x52417c GetDoubleClickTime
0x524180 GetDesktopWindow
0x524184 LoadBitmapW
0x524188 IsWindow
0x52418c IsWow64Message
0x524190 GetSystemMetrics
0x524194 IsWindowVisible
0x524198 GetDlgCtrlID
0x52419c GetDialogBaseUnits
0x5241a0 GetMessagePos
0x5241a4 GetShellWindow
0x5241a8 GetTopWindow

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
T$$hax
T$T_^[
t7Ht(Hui
;T$$|O
D$,o(k
_^[)D$ f
D$l_^[
h.1#jRQ
hXmz1QP
u28*rm@
hEaX}RP
%^]C+=
Mk1a G~(M_
Mk1a G~(4
a G~(_
jXh`}R
^SSSSS
<at,<rt"<wt
URPQQh
QQSVWh
j@j ^V
F\=PLR
tCHt(Ht
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
X;M6o7d>
Ji0fAi
Rm5ZBP
(bV.MI
h~F;B(-
V!RDxY
"KgCmt
UuZ(c%
Y0@9W.Z
#3MevP
NsUeU
xt83$)f
XBLJh
'6-T\{1H"k
P`pTaq
1S($t2
6;=S[k
J|R[d<J
D/?V\
C#XI;+W
)dA|z?
<YQkWp
adPTyR
6Q;CMc
F1<#uEc
[-r]X>
K4?am<'
?sPSal
IRv\W8
*o+fz-
T@C]A~
'.4FG,8
/QJ)*t
AUP |Iy]
ZSnN^-
,]{4\J9:-
&W=dL/51
RtmPT'
3r97aD>
9iVRSe
Vd*180
':HhK>
K$A73e
+#kr^M
5ecH*.HY
3.&F1&>8
I8LT\F
.$&-qm
I?j|3
xcoW\V
vCd!E]z[a
LHLoRc
x%AAQk
EIlwZd
Ed~tJS
N8]8}k
MY02XQ\pr
/"eR'f
] 9gq,
qeb.!)
8rt=@q
5 s9V\
('EGc|
Cz|YV%m
kR%DS@#
L#}'*}|
Cmag`@
Vtav}e
yjykdF
nXy.4*
KRg{'\
nzaZ[|
O,=l>>
")9e08
gU:hu
Bs.L1&
MS,;Q5
Sy|N{91?
7^z/r
z:"pGU
$}3W.H
8NDU@i>
0p]4"$
e>@VzBdN
U#8jl'
3!9+.C
;kivI;
1kOdQ3Q
X`~]w,
D]5F5
S7,Qf_
c+b*:}x
P i&N?)`4
Ld"80j
gl>z]R5
%)!(Wwv\
p]!aqD|d
CqfMFl4
Q9Dz;:
-m*XdL
:N=-:~\
b:$]H::HY$S
o5&a8O
Bty3xw
j2|dDN
Yp!AZ^:
yf>w5N:
Z,bx}c
X"N(?b
J2Z+"V
x90+8A
ZTT)}Lx
F~DpOj`a/
Z526q*
WK5O8#
%0/B\$
\C#xq3Z%h
PHurD{
Cy{1'@
}+k.y=
F.*hK{
\q+M,
,~(lGR
T^y%mw
mNpVe\&
Nfj_9d
"j_8+:m
n*g7d+o;7!
v#p+'@
Sn(R|:
/4F6+9
%r$,Co
{MHyId
q's;lU
T#~b/K
ltAEGi
co=4dr
"U*"=}
`j~~i&^
=F)6qo~
|%^h/-O
7xqc7
.ian,p0
K=T{;X
{QhLb_
+j6~[2
(Z0VH2
9D .}ofv
="JJ=>
<7`9MqJ
I20ClyyH=
Nc =
):9nCx3
NZ}LI.
'ntTr;qB
6`7K:xO
J5I_3E
iN R
d-!|iF
G_4ljA
Js_d&;
dFqBkV
zX3f&m
wUXo2r
MDw6Zu7
rc^Jix
h<76nA
NfB!JN
KqG(?@!
!l,Sg~
Mo,TMb`-
H?x.k!BG5
4E+o_#n
DcMR.
"Gd~ N
7{K?w"
nv$~P@F
?p#=
g8@P].G"
`j} g:
k/^~vI
O.2857
"*zb%z
Ce\#@&
i%@wTi=EQ
n *Kg
`CM~Pu
jbso5-
j3@ge
P&HIV
h0;HaL
_]HZfT
UG<-'V
|uD?&!
M9;[{!:Fg
\(9cMi&}
{9er5u
/~ZB!n
ytG>"~
dRSF"~
FR_/@#
)AnE[MT
CMK/{)qL
bz!.Gso
|s&T4s
+0rhu{1v
-r\;3>
vh0U*?
nW'IUVs
]S|e<]
~HYGM3TgdS
]|kyG3
5.m's;
z7J]qV2X
SN-[6w
QE#+`v
IKp\$)
mH@Ms.
R;JXg&
8%P{,z
c?6+?
8<h-E*
ZRkB}
fyx^UI
MNrxfG[p
D1&o14@
/L&@>G[
yjZ!@K
-c;2]R
G{m#qu
0v.7!C
ME>PFw
{cJqhC
_j*brJ
Z9(H8q
Efi)dW
lqr_
v-kkxX
7:<er#
3f$ G"1
/b|03G
IQAMBf
*g#]f@
d?GHk@
<C+ pa'
cs6uKs`
<hqIM0
h:mE)[
u:jRP;[h
(l'"bx
)s'#L"
VWGAJg-
oaL"X<
}c\a2bB
^'GI78
VPIxV:
,_=]xh
u%mOuq
cv -j#~8
d7=';U
XAH#v+
cB>*J
4.w`B-
#)w9D_/
Q'R5P
RRTQ1S
<O-$*^}
S1sm_,HF(
O%wa)Kp
hahm!/R
EP}&;h1
LZ#ZR'
YyBp
H#3WRF
Z<2q\s
.pW{F9
B0n}kii
?v#J)!
D]U+A
mlI1[g
jdf#TXC
Gw-SN-
y@nVl(
UwpX)-
Nn*p&h
{`~`(}
hCJ7(jG_
p#YV[8
ST[=`Z?
^(57[!
\T@%g'
;"MU47
J>E|U(WY
iv?/rA
iz"d9$
Z4Ql#i
jreMS7
SJVztZN
^)w)Uc
66AB |!
#n5m#mGm0
FNG[jS{
cH;TOLD
"?}=c@z
:Z1s.NJ/
0_twYE
[RgRqq
}4)8~u
O6$SEY3*-j
Lp-\-p
*2_LjZ"
Z\xL]XK
}qMKQm
TskqoT0}K0|
2fJ1f5i
Ge8Y,.rR
9zcP1g
8$elhi
qH>QJp
BsSz_066
nd[o9?
&>|4bC
8Bp8%
%Q3kEO
9&o>{{
>_o#r5
}:8k~7
dsCS8'
1%BW q6V
osa`P-
$s2^H0
WJNlwS
T>(i;UgpJ
EegS4`!
\.36*b
R/>Wppv
RM>ir"Z
],AqL:J
&6Jq-E
ngA4!{
Cg!\83
;n,uUzV
BluIAfH
*VoK}D
CJ?I3)CQ
wsp9"r
#mg~pG
rDZ=|^
n.[o
6yr9:@
X6Kd8UC
#eoWco0
5;?lqv
rfo'C>
O8w7et
'!'Pw?
e]NYp=<
<Dv[Yv
|&=z-u
Dm}[8\
[V/Hg
( }xud
8!$8`:
6@jyb|
l+2Ap?
hl1go8 #
#-`ot0o
[.F7|OO
pY0fm3
Cux2^_
}N,!md
##pd*]
t4!iVR
n:{S{c
H,C6~I
U:+7&L
3=9[fL
/jbn_Z
oxy=q_
jlGd/j
p,> W
b!ZEP&
O\h/m"
1rufM~[
b;sOF|H
-s/I^g
@cZ)_
0>Psh
#}-Vn\z
Bl^X+
tn?\s_v
d&V88@
w C"NV4
f0X137=
>sPV34
Y?taS>
lcYw,I
(O6"Vl
[Dd_Rb
l? N3i
>')S$^
T\I_zZ
Ue9^eK
d6MsdeCf
N#2uGU:
5!$C<'
ZGd|3!
)s?hDo
BFwdY0
50pG3q
O+DtB)b
+YD$2]
?J(YQS
cHRHadU
_,?-y9J
+Ts'gp
{j7[_'
)5iy.{2
e@ArG}
O+p*Dg
co!AnP
CyT^MC
&BGQH20<
|/5bkl2w4
'L:=7)at
8~%Csu
xA[c.L%
ntPEC0
40i)y%eT
LJ88"`4
<+4ZyK
NaMHB9
kvGC0^
<z7eCEP
hSPBB%
tU:zT"
a'*j.'6
]h,0;.
r~YU\M,@v
fn%epk
1r4A)C
ZQJ)vv
wW;"Vs
bl&8s\RXl
Ag{sN7A
>9Cir~
!T&3T8
!V!Y-]
6Y^IFL
9Z!HE?
"| r}i
14LejD5.Q
OhN3fWu
=rt*VTwaU
e}q}~i
r?FJAm
IDZL0,
F8M|e4h
+owglF
a1<k$@
h(&}8B
w$%+WG
!Aq>[M
BD6mmy.i
$gKC@l
mxsNIh]
zKHZ/'!
~%iRUG
I- CLHl
`#{F?
qQ]2=e
(X=g.~
5,<u)y
BF_&<
);kS{>
LKFOXRM_
^2^9w?p
\]3b`o
:[O"U&
o^[AP<
BVc]nD
{Ozv.d
@0NOy9,
$+AYf%
_dh6scL:
%(^t+|c@
)!K-_|
inAk,a
]c]<q]
!VJ(iH
4Q4Lg.
ES*rXA
+]Ucrt
t>v"fb
:1fl~3;
FIKU!z
%hZ"xmf
9,S*rx`
es=xx.
-Fcy!M
xd(M`L
>{*>4gp
)UktXn
Ews%>^
aX0TON
8CUE3iZ,X$
-S4k-o
#!jX~fq
JU<vHG
Gf2"7mO!
-}cU+X!
eQr+$
%Gk I#1
tS+E7 J
>'74=x
R{$Mk~K
,;PVvTu
?>wcj<
^'{qWr>
<d2Mu
"^#03K
&NNA{
J:%v!wl
Xhf+oZ
db=:?c
:#2Gw+
HVP8;g
yJ"iuUU
4,<j;X
NBbes'
5Sn+8{L
^?H2d
IbP&oG
;(8$ X,{
W=;/?B?
(([FJpg
kIxo4g
@lzA'k
0Zu:\V
?8Z-F
9@:f L
M<(WJ(
&[Bf_C1
{.am:
Lk~U8:8k
:slkOx
hf7#3'ETE
X.q6Gk
7:>>Ig
LD*WPSa
/wR,_eh95
;&0mb
a[mMfm
-\|/1P
Uryhy8we
F,c(-2
S9X4aC
T"4d|X
TJ:mcVwP&
96_nxITdIJS"8K
?m.xDge
7+xBaJ
OhD:Ti
N([k,D
urk-p
{z_KLpy
'2Oy\6
2(i:2~Qi<
@It0h
Xac9oQ
iGrhwc
hlN5;>
q~7kd1
P[Lh;<
0+H"@{U
vjlucy&Wa
m=cAY8
U/JRS[a
k'_(4C
&<f"l|i
\&Ev-Hk
,z<!Jop
p<Rj0}
z/x=X=B
;E5.bu
tbz XW
,e/gf6h
52U^)_
KAAPU)
'9"o'ns
<M@):b"
]/\+`U
jX2K<
9KBD^O
LG-,`=ru0
RK]V/&
D}v}WJ
-$vp<eRt
Nnv{3Qw
t&;)P=Y(}
n;!xE!A
b$UDU%k
KOtC5(`
R@]QXX
!C7%$Q
# f94"
LHDo0A
#d:1Zra)B
S-10`O
:G*t<?E
%-aV/]
}-S1\z
Z,VYZ
y>}VB5
r#zx`x
p!UvA(
RZ'RUH
F%C)hZ
+:V$Zb
;&|KWr&
z29u?*
e$.zyr~
C7![ay
tLo4xW
uE"sW)
~^>cyt
?_5d}q:F
@]D0}0y>
$9:?_8JY
'UD] 5Xf^
bC\_Fr>>
#!1t_I
0uh D
dsW|'w
BLc{1B
L+YiRA
.3o<F!^k
WnLV*P;
AH/u!-y
GMEHwN
|+_W2i
Q\gS2Q!
I`0WR~
P&Uzxwc
|xl]K}
AYKU&x
lJP6>'
AL.o+%
6]P/%u
PL8S^|\w
IB&'"d3
f@.RyN
t:vQ '
_1W#|&
LBoXYd,
sr0&lPdi?
-3gMuz
_Q>JUU
^ $to
IZQn"EWp
fOweH6
?8)U]z
=:Q4tG
9YOa\xn
e>M^ 8
PWcAn2/
XC109V
ab,H~#6X
.FmuRR
FotO8?#
rGRY%|E
<s[!wT
@ ?='I
L{Zbs{#
nR!G*m
Q,0mBq
:fti@)u.
s$1(2x
g0u<co&
OL&u'O
!NwD'LL
K'e~6
\^0U7
0PTPb3cO
pK^[8B?1g
`:8CpCq?
LY5o"O
$z(9G G
muWf0gvj
M8\Wn9
PFT:CwY
!kY2j|w
maaK8w
z8-/dj
b=O(oQH
,OYI!r
n/CF'hk
~8#oFr
G SRgB
Uv~zj$
>?&xco.
u'b,Iy#
Rh<([.
+:i$R4
e( of'P
?$]rfAP
]+E}P{
c'l|V%
?Lf#I^$
nhe=HM
^$2kQS
i.\I&[
XBJ1Lv
)"$D:u
oA_@>dD
RAiT#D.
gCY+Z1
.h #P@
-Gjw*8
D;|q(8N
B,j`6o]
HxgK<v
s7tj|-
"v+!;L
ufvJF!
0w4:9-~
ijBlyh
(a).`b@
;9nFay*
=ViX!
Y{k_}0
DtnI/M
5H7YA^q
-,m;4
X'<Z]n"
K2X+B&
?s?wU<
Evb="=
Xr'lA^
\yM.X5+
vzo-3_&
NqMpBz
A^Rkd\~
A-$9!^
<3NUm@
]s8W$e
290IJ[
Xb*#aX
7+}MN/3
yCqvz@
/kHsJ>
|[Ts(>e
8y/wsP%y
_FBR(b0
.;of;X
Kt lyPL
sO5oI_6
q^mCp@f
9:%Qu6X<O
Ikcr,(
8}9;lS
{3O#d<32V'v,
M i"Qm
}9a7 zpEj
H}R\;C
f:He#;
xCJjXW
lB~2#q
SuXG#wg
`{TW=i
^e3Us)
Kv~ (Z
8f$^QcZm
aKz3?u`
4-4;y{
~eAV'@{
piV&opsB
#HCrb`}Z
LV^eL"
oLg9=4g
|>8'?f
{2@ZA"
uqAsu|!
i/x${JQ
^\X7MJ
'>cY3u
xjj}eYCy
rG6}gN
A%2K\W
3LKHi&#%{I*
J3^Bu:m+
G"-up.
2I(`#U
"Ld9GS!
Kk4jtt
{%"sGh
^?om;d
V>J]HE
R<IMV=.Iy
#x[\U@b
6Mx;l<0
.R=bM`Uxu[bE
#v3?\~
nyECKnG
oTlnF)
^XFku*x
Lvb<Wp
9XBtK#
7x,](
%0uc:C
k}%2KU
Cdx(cB
_<gpZ8F
uV,2&3
yB?V5
^_RB~'
Tc%EBa.
nvFRv
By|M%^&
]Ft+GR
LFa_8+
kthj&|
JsZgXkU
{\H~,&
A8m*f-
|F)Wmu
ALmmjh#
A(d.30Vs|
_-$+rF
zh{dN\
9)-3UT
,=4mCv
nAD'm?r
%&='x}
Q(=f|
M@3*l@
b@lNSc
l~KteY
FSQn8dk+j!
r]o1&&
stae*#Q.P
C+ymgJ$
nfM[pF
MVhB@'
"%&Q2~
UZzCw
4pm,Xd
^Xf0<g
t`~/q=?
Q(XRh2]
2q"~Cw
3O8j2+
56dZ2L
5oM6"To
pLS>zp
WHnZ)0
?GmX,f
;w`DQu
#*OFda
Y3W/=?
m5^/cy
gJ9U<|
bN} uI
i~GN<@
=W@L/
'JuwY?T
)JG<'^
RZejjWYf
Bai,7J
Y!p_'L
V`Ps a
O|~|os
I({( Wl
89q}>
z0HB:R\
?=4B_%
%=wj7c
7I;yTC
9W45lb
S9nwkx
F#]T.9g
~z-cg{
BZ"JFA
K#2I^8
04XK!j
-Yz.;\
/jfO{M.
c\-9(X)]_Y
`,hpa*
}AxOuz-
j(P=L)
CgU9h9:
n9pK>fC
"Pnk} k
?$kNVa
sKC^52
$0l:~U
+wI-Xce
b)-Hb8
7|n@l=\
o{Y2LE
'r["|{#z
<(v?>o
PE77|XG
{5`U+$
Uwhy+/
O;GV!,@
r^YNF/
7h}B+>
Xn]&XZ
{QmCw[v
j20F@2
IU+?bG
y-gwR*S
;`gVqxz
6$UvW#
h99&qH
m=vZ#p
/d;2HY
_z?&H*
c1?:4y
}X(KJ8-
,,jB#t
=;tck{Y
@j6y?Lv
2<+N.
AZX/70
H IIIT/Te
4xyUdro^
\bB4QB
%PJBcK
T<KD$_
T[B$,gaUr
1Fx4dM
eJEWA<
$_K~9y
9Me%6q0
njy{eQ*0~
+!W>]"
n^Ir}y=
D!HHBord2
9\=[EM
{JNn$AG
3x7X.(
Mt6Tr4f_
`1L zB
mXm> &o
ap w]7
q ~ E}0
G3qN^I
!JWgu2j8
%O%i'}X
A[vxiO
D+&[EC
uU/0p"
$R|l&
Cm[5=|
H="-`;9sv
.nwjO$
<j0~E{=
@:y*8Z
-@L|6h
Wa-pn8wd
QJW0W]
jp@X~IF{
H!S:'a
7y>!a}
Dwicw5
1](N-c
uK:jIq)K
tQ;cmV
60_g?B
wpU#-V
m:Lz5&t
EWnDow%
Wh=*Q\
&\av45$HY
^|2:DNU4XH
D"SmSf
czP1wD
q%7'Rc)
7E5U'CG
:X+>/s
mlZ1E]r
d+93B
9jJ@F
B_Q"^R)
\74Z-?,+]
5mO?|j
gep$sqax
,u 4-t
!]N]wi~FV
jic#cAL
k^ 9,n
Dg~~R>
mdDFSY
?N`~e#
bDx=S*
7fP{um
NqvMd*r
vC]RP1
/Srs#!
1/MgEOe
_-nUhq
]1sbU#
i6!M//
^k;uI3
ANsf4j
{_ttF*
W|PNo
NMm]>
p~SDO>
%>P'8*m
t2x^@0
M.(c#_
mHN]`S
c75,'
f_#MvP
}60u',
k5qhA?
@To8t =)
X9Vn.$
BIcGh
=E>i>\
KAH,Pg
^I5k#P
ULAL~U
AIDd%d
vtQDr5%c
B]cX-.+
1#KR&
zaL6t^t
ZvCc(o
"D/CDk
c5 ea[eX
eOY58F
ybF(xB
Ppf#5-
`$?q]i
t`P"A!=yR
j&I3_-
x6``Mq
"75:5S
#kBVa=
H'+`=67
<|m[fg
lAw6VL
9_;hH'3
&aQX5I
ZE_#{z#
!hn&8s
K4.`=CJ
=bL.pVj
Bu8q7!
4d.G5=
(I(5D0
|N}18u1%
R&pYxk
VO/k%z
v#';9|
_$`H^7a
VoDDEd(q
Bwjtd>*
KMb6!I^
]wUVW:
FlMrhPp?m
\G>F"\)
g^.Cqa
'9O)Bh
,*=^DI
>)'-!!%
>SoQP
BTx a;!N
&9sGW
fcqK`;
%O$u|]
C$dHW,
-^T5|{f
m,idzUU=
ojr&z[,~
fsU)b,
Va"E'<
F|4 8/
m^--'q
F2Ju\
.Ygg07
x+a*bL
!#:WZG
S> ~x=
}7wpE
g'LAL!
VZ`~4p
gnL]s6Y
i+RS!c
~O[yP+w
vEJ}?Y
rDOgk0>q
+:k7I$QX(
E`{ukiDc
;c[.6!xQ
a.*DMJ
R[GjWY
]b!`,F
hA[>_R
^eCO7I,-j2
`41qZVri
5zKKY9
hpdQS2A
~>lF3oX
Bo]z|Il
X59`O!
Y<P ))
5j1nbr@
mTEA^#
|*Fj/#
\=evB=
CdK&8M
rsx~cW-
STyEqZ
fKb`#wT
wMMI{dU
<=wQ[N
=N&\d+
$z.\QW
_PqvR>
/L!Th<e>
t<';{.
{y)h)7
4z# /6
di"y\.
BF$KSr
.@{r}XW
s>Mo3g
G_2XJg
?^}^G_
OB;N\Q
xfDV@6
{Ti^,O
7etqmW
xE|pVb
aS(B@V
cZ<^%V
k>(%C]N
4n?O,h
yfsZT1
a'>]>\
.>nq)3>
M.eHZ
dG^~M}
3O+S1&
Vs*71t
+(MFu5u
`XE/v
-~;'`Vn}
3nQ86M
(#|dX1i
q\INr*~j
kn4vZe&
B?=?3g
"0hpcK
\8U6 ++
vrw,`:+8
671,=0
WhR*au&
]mDPIW
;U>2V;
TaV4}r
[&QAh8(
It`n+s
%M,OB8
tiE2Mgw
&iJso^
/_5)u<
B68\f1md*
qG!Ru|
w,p$3B
mcEO4jV
l)_~#b
MBSr3/
i8h,~"N
iR==g(
hCf9%0
B7/=8b
>3My6
"q}Z?F>
1x(\%<g
0$)YRS
K81@1c
.yFkPM
3R:\yQ
^4M6]~2
]w"<QS
u/D+61;
+F"7IkOb
B3/ox;G
!mMQkhs
7Dx!vjU
2%N>;2
zDz79=
'FFx4S
9dzO%
cxg+{a
<~b9Eo
*HB&sE
_F*~K14h
0H)vdZ
A4"crt(
[E<30W
|2f?/u
)}fQR
jg\A/Bz
\sc-{W,
JzqN;- |'?
*jb.<S
~Zf>DR
]{~=*8
Lv{t8E=
lS:5TP2
`z)$R#
q(Y`<RI
R<PFvz
dR} )oq0aDf14
KX[RkT
4!57>fyW
ANexKP
o,I<Reo
,8 [xch
J+*:lw]m\
cIxzrn
;:WUKp
io+Z:G
9yF,ymx
xu2TJ
tbE9GX
T.Qx@&<
0[5FN(
B2 mjtC(_
-qPhBh:
5q/Jf
yoWm#n7
)`$az
S`Mlk>G
Mu9SUq
JU0h8
e[&Y 2
'cdgA!n
6e](t
qVo>JK%
B,R-YM
){5Wl_
34xZy{
0m&naC
-G5m5ik
N=:X*
ia8fL6
x9%-0N;a1
tX~b4
{6UM_4g
-9""k^zM@
=%C}/U
jA<V*A
$L@E1$
XL[p9ZRC
A5TTeO
} t?',i
PdX#O].
w7hX|R
Ayd|j T
FtW0uWF 4
5p++{&*
wQx>7#a
4-^=lV
&P($Rw(C~.X
Su$[PkrY
&B&45:
8psdrU
?764ZbT
m{2?6:
(KqpQ
+509vq
:15zG"BM
+[\6W[)
J:Ts/3DS
CuTG94v
g~wnjO
y%r6E`E
^T3dB.Z
8'?e@U
L>_c?g~
p:&0-/
s=3Z>o
F%v8D@3
Rq5GcU
$j5ahVZNP'
'EEb65
YE`pyt
PEKj[x
DD|$}T
iSyZl5F
]c/f\.
|W&)4A
'^W|l7
+w)r2+I
O<#@d,
:h!ZW9
"ig"~E
aU+[]/
+@2>h%!8
`I:B+V
+{[<v(B
&tn+V3
h'0$Ta
GOLGpK
l{`kP'
VHVcI=a
0aSXZ'd
(rDC6CpY!
HJG(-xqqHv
Ck/+yA
4At6"B
OJMqAlE
4,6|R}
ibI'mG
hS_c;X
VI2gm3+
|9i0`;
&W4c@G%Y
du=sCUZYjP
05+3v#!
.}i]~`_A
Rz2e4M
$dis{P
sfK6~cdB8
]'C/M[
6;gDVi
fr~$b+4
2lW7qq
d3vV'U
7"4'Vl1
Y<yvyr
XAl;Ej7<XY
9A`@ax[
gX 8`.
=ky)kw
AG&t'j
[ay1`>pf
%Sy6>U8H
!H+/PT
nBN-4V
Nge;FX
;^>cL*
h VUDC>
c=/'sV
f^oE!QDW
!=Nz*>cCZ
H5VxgG
nSnDJh
qmzZ,F
uGs<Z9c
Vj@jx5
^vHDpK
97X4ygP
t({oa3
~sY}qt
';KH]z
wGy}$BJO<$
xB,v/f
bYmtVy
'Id"7u
hcO{70#
n2_0#g
!8YU<{
*7f?Jr
N?o?n/_}
O\N6'3
o!rS=A
BT33D)
c4m{LH
%?cF\@Z
\V:u'@
AmK?1_s
fS[qJ&
}i+8y
eW"z0|
v^U2`k
y|&-9*f
-6Mhk)q
&7x/\a
zF;a)I
@oT=MK
F&B2Ejt
>$B<p.o
qdKt<w*
=hQv^m
3jM"Sm
yc_AVB6a
l+<\;X
UL{F|
E[NZUF\
g>gWJy1}
_h9V9H
6^&i@Z
xn}\2S
_?'Xrf
_Gp([M<;
I~*c@7o
Q7XYb84
<P6O/2
*~2*v
L`[kNF
O_t}p(O
'BW"%j
v/3?hC
tS3-U(
Sk}-^j`
gJ4C_Z
D;!a*yBb
Uh0D
iWJOCd
689o2wsTH
KcSE5|
R0pTbY3
'ABZfl
up7?og
DA@[M~
*R"M+erK
)E5K&vB&'
IJgi|z
JJ9m{w
,2[-{3u
Y$RP2f(
^-Syu(y4I
A]<es"
7z(7qi*g
;Ous~p
y3_ElW
jw 'w?Sh
s%";~!
bytGRG
wSDM:kN
w$>[Hm]
9$SU\t?
)0jC."9c
)/`="zr
!'3eP_2>j
gbkqAUh
?kV_Y|w
WeZtp
)r"-%F
65CNx1
$_Q_7.U
?0W}vP
J#TgPlA8
ajUWW(
af4CG<9
SMwk>r
8'DiCs6
0O4Gss
r2P<IMT
{vO ,3@
j=#XlVd'`e
QN,@z&
2Z2E]$
i;jAip
{V-(\'
`{'\2y
C]fF+gjn
4'xi^S
*Vxqs:
d;C~8~U.
|5r-"*P
p*6,24
.4_]-x
\V BP]Zzp
hn'x)S$gP
v"f}Aa
G3uA+=o
ay?ea)
jUfS-0~yY
O9o^h6:O
:&|t`S
@08d_g
Bf|H&+
zu[`kJ
#`VsLn
ag-1hL
'9YSR8
~9B>gr
2C60~N
Yx],Z%
29<+0zm*
%FEX``
kv+dm%
FomL\ftk
N)k@~1
]-[&r *sb=:y{
kAoPo_
_%+0lL
P5t1c
q+O%%|
:hDCk1
p.T]$(
4e&/'/
~/WGOU
:\vNGzLq
Zbjv<V
3Pyxav*
8Wa4k&
tWakq\Y
o*dc\,p
\\TOYmB
~4X8+z
$i.TX8
s*Y#/[
Rg_]EdLP
1tR;xLI
}6%}2$N
f3R*8$
WaB"c~Q
($1y C
(NM 02
i'4d5Y
(R<ZB~
0t9}rp
gCT\;'
MnLYcDk
fq48ia
HrA3aS)
g"=/&HH
{j0hqx
"zhv*K
D$Iy|@
){w!yr
$T0[K0
W(!+>?/A
%E{b,z
h"cbrv
D:uP(7
,<?{5V07`
z,mm\W
dlmKRH
LWDKBf
)Fu?@K
NDDZ~;
^EJqF%&
_9k[m_
3p~$R*
Hzn{,^
CXjpb@Sy
Nd/_32
4X34N;0
Ew:{FB
]Ni}5j
aL#@Sa
%%sh]0
FaTZ"
Y>OiGZ`
=+/V$nB
*&BtYg
uBY{2{
c" #~^a
9qv6Il
C])d-T3
^p{si:zK3|+Nq
YU'?c~j
>oCmr"
u+S.%o
o!(~q{1
V_!_'W
7lDY7#
]L#izM?M
'G_%M(
Q.Z#HL
VzfwKx
dL!"ywm8k
TteH@jK
GuiL'
SW(lSF
E{zf"|F
5<iJ7N
&u?Z6
M50i7^
quE6"!#
qH:&" V0p
iFKU@F
C^c$u_
qB>MK]5
gtm"C{..
:Gi] \
b{'XJc
*aR8<]
t)80,P
wh`;+G
@BZWcN
TP`^78
U|C-.E
LFIgfq
?+z<IT
b{@OL`f",U
R E-,u
3Ky"xy
#>qt?DW
1h/CO%$
Nx9z&u
ZvN:0r&
nMek)I
|(0:$)$
>-x2[m
Bc-tE%@
2<[~w#
pmT9n$
NA(?]*p
Ec\{d#g/
o'L3;Z
lFcdsG
6]NWTR,7
r|6jbXq
i&ab6.
FH_"yMk
b]0eqem
Xb&5i#l
a$OjXOQ
>O/xdp
V46L9\
$xfHM+
#i|vh$\
C"5noz
o|/D9;
M/.W@04
p`LOCd
Dypo%,
4-.Iz?
LJf)`c!
HSR>t<
WHcPa*
:*T4f_
HcxUP}
~+&&zKr
=`6ic[
sw`g2i
rQ V.W
r?"\5,q:
.iW4Yi
<@hsFll
|S[y2
!|:EH%
jg%?6sXJv
RIr4#s
%TP@~c
Oh;\3g
W0ZM,b
jR=X+{
:`e*@U
IN`Xe>
e3:6/L
E!2\x;F
]c(&2_1*
lWT_.-
2uy%m:<
tx|e/A
L/Yx(s
.N551C
LDB O!
/*Y!c[
dFFDAB
Qt[O1:*
@I>p2k
x>=8%SK
lp<%pN`<
y+@a0K
?~+W1cOU
%ByMiC
V&V4q6
K7oA^n"
Az&Cm
:5V:}"
l*F@W3M
x'5EUf
jjU&_5X~
0~_p~vN
*)}[\%
iKYg:'
YR{;|\L3
c8Lb'6i
>3;C7~
FSYPn3
qR{MO8m(H
1olP'P
V8EsY*0
!8=g&8}
F]<MRq
t)!;o0
Bl>9Eo
I"Cub 64h
0UD[R8
H)[r{=jZ
[Tx=;\p
SkN5d[Bl
yvz8I<
v<?FlC
RP;&BF
'7D=kJ[l
";.u;
B#T?Mh
qR?)s2=e
IRO2YvrF
n{6k9G
y*;Qa
#6,w-1
-WJrv=
d5&0dH
JeJaqB
#x(iM|I
bssu;C
|,!!e_
^1<v`T
j5=[>7
8-n2*:
FD{{7`
*Oqz[&V7
XU#X#SOki
&?hXP0
8T(S|$
4z9"tm83}
ewsM3q
YM{_h|
(:j0ME+{
&|Lh+2L
qh.bs1
l^?qA8
%?|oBq
9_3pY@
JVRojKpO
HbiK(1z
YCnQwo
ibG;6#
iUP~I7L>
}UU$bF
SHZYih
]xJ,!
.DVkz>`
^fzfgk
;dMl_a7cpA
sLJpl3
ezzd9{/
g!QHI8"7
A1bRRvK@
:M*ickR
Du7N"R
m28*C"nv'b
Oj1vUU
~dm#]$
:c7.w/
wQz%p9
>Q]]/z
ut"6Pv C
q*hnpCfp
XPRR1H
3l1Wf>
nGi4_"]
fqyL;4
X|~,,u
?0wyv@
[b5RSV
CsP^"1
p',X&\|M
gbJ|xQ
!%,dU`
1K@e3Hw
I`0~_&
2Q?nl]
q#sW1y
'rOhS8
ySu&^<
_1/:zP
RX}L_o
C2(Ajf
n()eAW
}g4F!b
9n<Tl-
<kJ,~p
POh/R>U-Q.
#dmzz%
8@mR@au
!AVNPc
FA/TzFB
=\,+T!
#hk$1wVL
g>Q=,1
NPmU2E,
b}8ymX-8/
\Em<DA`
M<fi32
W)~`)Iu
R-/oDY
MwbI%!Nb
.IR t>
_Sm;9Y
!x :C'od
1?6R~M
_Mp*LF
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
f-00f=
f-00f=
tRHtCHt4Ht%HtFHHt
<+t"<-t
+t HHt
u-hxsR
CorExitProcess
UTF-16LE
UNICODE
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EventData
GetLastError
unsupported_respon
IsBoxDomainJoined
Cannot access user
An extended error
ResolveDelayLoaded
The connection was
.?AVCertificate@@
The server has ful
.?AU?$ImplementsHe
GetCommandLineW
Another thread has
ErrorMessage
GetTickCount
token_endpoint
?GetIBoxArrayVtabl
No responses accep
_initterm
prt_refresh_timeou
vsprintf_s
WebRequest needs c
owner dead
DsrGetJoinInfo
DecodingProtectedC
HTTP request state
PointType
.?AVbad_function_c
An asynchronous re
shift_jis
Signing by cloud A
RetryNumber
Windows.Foundation
Could not create a
SendWebRequest
CloudAPPluginIniti
GDI32.dll
SetUnhandledExcept
dsreg.dll
GetCommandLineA
bad exception
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
Unknown exception
1#QNAN
1#SNAN
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
RSDSyE6
C:\fehoxexe sopakiv key\Xejawa_leviw\patin dir.pdb
GetSystemDefaultLangID
GetFileSize
GlobalDeleteAtom
TlsGetValue
GetSystemDefaultUILanguage
GetDefaultCommConfigW
HeapAlloc
HeapFree
GetEnvironmentStringsW
SleepEx
GetTickCount
GetCurrentThread
GetProcessHeap
IsBadReadPtr
GetUserDefaultLangID
GetCurrencyFormatW
GetConsoleCP
LoadLibraryW
HeapCreate
GetFileAttributesW
ReadFile
CreateFileW
GetACP
lstrlenW
RaiseException
GetLastError
SetLastError
GetProcAddress
IsValidCodePage
GetLargePageMinimum
FoldStringW
SetConsoleTitleW
GetModuleHandleA
GetThreadId
GetConsoleTitleW
GetCurrentThreadId
CloseHandle
GetCurrentProcessId
GlobalAddAtomW
GetThreadUILanguage
KERNEL32.dll
GetShellWindow
GetMessagePos
GetDialogBaseUnits
GetDlgCtrlID
IsWindowVisible
GetSystemMetrics
IsWow64Message
IsWindow
LoadBitmapW
GetDesktopWindow
GetDoubleClickTime
wsprintfW
AnyPopup
EnumClipboardFormats
GetParent
GetLastActivePopup
IsZoomed
GetTopWindow
IsMenu
USER32.dll
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
Cynet Clean
FireEye Generic.mg.1f00638214824577
CAT-QuickHeal Clean
McAfee Artemis!1F0063821482
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Generik.JABKJZ
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.Win32.Reline.gen
BitDefender Trojan.GenericKD.64151888
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.64151888
Avast Win32:PWSX-gen [Trj]
Tencent Win32.Trojan.FalseSign.Qqil
Ad-Aware Trojan.GenericKD.64151888
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.64151888 (B)
SentinelOne Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Trojan/Win32.Wacatac
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win32.Wacatac.sa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.64151888
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=83)
Malwarebytes MachineLearning/Anomalous.97%
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!8.8 (TFE:5:pYfVodzM5IU)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36106.wvX@amLwy!oO
AVG Win32:PWSX-gen [Trj]
Panda Clean
No IRMA results available.