Static | ZeroBOX

PE Compile Time

2021-09-15 05:47:39

PE Imphash

eb7c24017bd43537a43eb41342fa9874

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e20c 0x0000e400 5.78362088699
.data 0x00010000 0x000a21e4 0x00088c00 7.94171035187
.gojonaw 0x000b3000 0x00000400 0x00000400 0.0
.rsrc 0x000b4000 0x0000d007 0x0000d200 4.89755000982

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x000b479c 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x000b479c 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x000b479c 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
DETUCAB 0x000b47a0 0x00000d96 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
KAXIGIXIREBIXUCEKUZAVIKIRIJACIJ 0x000b5538 0x00000016 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with no line terminators
VUGIFEVAZEPOLOCIBESA 0x000b5550 0x00000ee8 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
YAVEL 0x000b6438 0x000004a3 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x000b6a0c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x000b6a0c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000be6b4 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000c03b0 0x000002bc LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x000c03b0 0x000002bc LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x000c03b0 0x000002bc LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x000c03b0 0x000002bc LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x000c03b0 0x000002bc LANG_SAAMI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000c066c 0x000000a8 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000c0728 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000c0728 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000c0760 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000c0760 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_VERSION 0x000c07c8 0x00000254 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000c0a1c 0x000005eb LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x401010 ReleaseSemaphore
0x401014 ReadConsoleInputW
0x401018 VerifyVersionInfoA
0x40101c GetCPInfoExA
0x401020 CreateEventW
0x401024 GetSystemDirectoryW
0x401028 GetProcAddress
0x40102c GetModuleHandleA
0x401030 LocalAlloc
0x401034 SetWaitableTimer
0x401038 DeleteFileA
0x40103c EnumResourceTypesA
0x401040 GetModuleHandleW
0x401044 SetThreadLocale
0x401048 GetComputerNameExA
0x40104c GetConsoleAliasA
0x401054 GetLastError
0x401058 WriteConsoleInputW
0x401060 SetCalendarInfoW
0x401068 GetComputerNameW
0x40106c EnumTimeFormatsA
0x401070 AddAtomA
0x401074 SetSystemTime
0x401078 _llseek
0x40107c FindNextFileW
0x401080 FoldStringA
0x401084 GetShortPathNameA
0x401088 EnumCalendarInfoA
0x40108c EnumCalendarInfoExA
0x401090 GlobalAlloc
0x401094 CreateActCtxW
0x40109c CloseHandle
0x4010a0 ReadFile
0x4010a4 WriteConsoleW
0x4010a8 HeapSize
0x4010b0 LoadLibraryW
0x4010b4 WideCharToMultiByte
0x4010b8 HeapReAlloc
0x4010bc HeapAlloc
0x4010c0 MoveFileA
0x4010c4 GetCommandLineW
0x4010c8 HeapSetInformation
0x4010cc GetStartupInfoW
0x4010d0 GetCPInfo
0x4010dc GetACP
0x4010e0 GetOEMCP
0x4010e4 IsValidCodePage
0x4010e8 EncodePointer
0x4010ec TlsAlloc
0x4010f0 TlsGetValue
0x4010f4 TlsSetValue
0x4010f8 DecodePointer
0x4010fc TlsFree
0x401100 SetLastError
0x401104 GetCurrentThreadId
0x401110 IsDebuggerPresent
0x401114 TerminateProcess
0x401118 GetCurrentProcess
0x40111c HeapCreate
0x401120 HeapFree
0x401124 ExitProcess
0x401128 WriteFile
0x40112c GetStdHandle
0x401130 GetModuleFileNameW
0x40113c SetFilePointer
0x401140 SetHandleCount
0x401148 GetFileType
0x40115c GetTickCount
0x401160 GetCurrentProcessId
0x401168 LCMapStringW
0x40116c MultiByteToWideChar
0x401170 GetStringTypeW
0x401174 Sleep
0x40117c SetStdHandle
0x401180 GetConsoleCP
0x401184 GetConsoleMode
0x401188 FlushFileBuffers
0x40118c RtlUnwind
0x401190 CreateFileW
Library USER32.dll:
0x4011a0 LoadMenuW
0x4011a4 GetMenuInfo
0x4011a8 GetListBoxInfo
Library GDI32.dll:
0x401000 GetCharWidth32A
Library SHELL32.dll:
0x401198 FindExecutableA
Library WINHTTP.dll:
0x4011b0 WinHttpReadData

!This program cannot be run in DOS mode.
`.data
.gojonaw
Hehipaf
isole leyikuz
kex miregexizun
%s %d %f
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
D$xfkp
^SSSSS
j@j ^V
HHtXHHt
?If90t
QQSVWh
t"SS9] u
u}h4*@
URPQQh
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
LoadLibraryW
WriteConsoleInputW
GetWindowsDirectoryA
FindFirstVolumeMountPointW
ReleaseSemaphore
ReadConsoleInputW
VerifyVersionInfoA
GetCPInfoExA
CreateEventW
GetSystemDirectoryW
GetProcAddress
GetModuleHandleA
LocalAlloc
SetWaitableTimer
DeleteFileA
EnumResourceTypesA
GetModuleHandleW
SetThreadLocale
GetComputerNameExA
GetConsoleAliasA
WriteProfileSectionA
GetLastError
FillConsoleOutputAttribute
AssignProcessToJobObject
SetCalendarInfoW
QueryInformationJobObject
GetComputerNameW
EnumTimeFormatsA
AddAtomA
SetSystemTime
_llseek
FindNextFileW
FoldStringA
GetShortPathNameA
EnumCalendarInfoA
EnumCalendarInfoExA
GlobalAlloc
CreateActCtxW
GetConsoleCursorInfo
KERNEL32.dll
LoadMenuW
GetListBoxInfo
GetMenuInfo
USER32.dll
GetCharWidth32A
GDI32.dll
FindExecutableA
SHELL32.dll
WinHttpReadData
WINHTTP.dll
WideCharToMultiByte
HeapReAlloc
HeapAlloc
MoveFileA
GetCommandLineW
HeapSetInformation
GetStartupInfoW
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
SetLastError
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
HeapCreate
HeapFree
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameW
EnterCriticalSection
LeaveCriticalSection
SetFilePointer
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LCMapStringW
MultiByteToWideChar
GetStringTypeW
IsProcessorFeaturePresent
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
RtlUnwind
HeapSize
WriteConsoleW
ReadFile
CloseHandle
CreateFileW
F}s@a+Ht
p>&%}<
jC]mYt
0IE`am
\F5q9-
Oo(?V.2
9z>l:[
LO2vy@
c.4rmB
sS{Iys`
(46&^g
x%)Kw)
x?.n*i
71nFV'x
.7wW,(u
& *x-%
NDZ&"G
jlcq,q
Z[L[K,w
AL%['<
)burW^
+o["Aro
*Q>rgf
HtuU*|
Vtt$OG
C"V<f\m
oR1`53
FaFWk:\w
y&z(.9
&d(+)=
l'bN<OW
N:~Ub0
n4B>fbk
'zC1_h
rCSLLA
pl"U*
79<dkLt
L!|x[Q.
`sC743]
t/_Qw^
?]ddY=
..e#8R
o0@p7v
1(g (T?aj
LB]TM\Z
\]-L~R
Epk#\
c][X@[D_
<2:Mp7
jdo0V"
Sj;p:)
mh4.}EP &
qU)IWg
?G-":l
<pl?=r
Gu0z}{
WCj{8Z
e\OnKEB
G{,pwB
+;#"b2
*u*%%U
u<mXcF
$RsV2U:C
FrT]v`
Df#+I!U
j4xCG^
Qu~IHh
]@pZvoa^
$-|uz8
Be?F~!fM
-suSOZ
CJ5h>=
^"?yn[
?m|(rsMR
c%C[b()m~0s)y
,P`HYa
h6`RXe
IS+BDVG
]=Ee]O
+|!?RIs9B
$;&%XfS
jI._Wk
>1(JPu
A"e7gY
RA2BA#
:lL"eO
Son}_#
S\A46*NHh
^bX6Ny3R
GRk$,^
Idd~U2
4V[jlp
S,SIQm;Y
VY8)'#
fyL^b5
itQLJ&
ngaD<
eCPtw'
>ROF6s7
=};O9@
UgYBFs
k(|JYW,8
Yrtn>^
;P598<
{88Ub$fi{w
1jV#Eky<n
gK[~kg98~{
D~ic{)s
@dH|]|}
?#a\k'
zS]ob
u62^IBUt
1e>_+t(
YJ6~gn
Q.P>&X
3A G!h
N{FK)'
)0i7_6
'$srNt
K,v\^Q
Chi)y9<
?} 93#zD
gWdcl\J4
n+0_lg&
FELN_|
5qvZNc
] ?aW{
c]vD"*
B$G!_Q
:itmZ`
|dd^X8
8s;4u|{P
=GRjG2-[
f"x_k-
6dQB.T
EgGAJP
"Zr&tx8
{!tI#
l6}dca
2H[psT
2hF6:PY
B844MLM
}8kNB|
omW1P>?
i(Qg3T
h].5T9
L9X,/E
O2U]X%C
O4-<BF
&u'|B<
S!@p4{
ETHdOZ
i"p'-j
M{GsMJJ
G-LsPV
B>6Y3@
iJ}Ub4
/=Bc}D
!XlRYX
88ED6m
V2Qa:%t
Ha2top5:A.J
]\R9BU
3lX3xt
Q^_Yn{y#
i2!(HO
zJH)Do
sv$}}}
Y2_`b/Y
lSWZ-{
Gvyc'1
w9i/r:
Y 5hK1
A0>0f
s*SM^Wq
d\{RZ(U
-eU/?z
bQ.V,r
"D]UN9
*p=G|p
6ZHRyk
x[BI2[
'%m4<^
[Ght7Qo]
FJL.N
Bc)ozS
JT#9W/
:)%H47
wg_dlh
NdiK)Y9
IOa3UAB
3;~:.d
6taC{F
6*<z"E
4($@GL
%tz\EW%Y
1+R|ki
45uY x
DJoDY*
?\-jAsV3
e)=?C&
WO+o{uP7)O
2!g%b'
3N+/;:*
f}HLVG
]@YdXo
dr~k|x#
q }u]v
nfL-QT
R|ylgL
WF>:5&
FBkYv"F<
ITY"&$
(* {a$C;
:Wa??D
/aRDcb
F@<f~C
=.)KV6
:@W\nS0^Y
TB{"A]e
#r?c/%
-WRL4o
PwRgjwn
j <v+G
5zjnBS
=63ZrQ
H]2B4]
'Rw1^,
DjawyCv$
e;)\*G
{K+7da3
j5gfGe
?_oj w
Nz@w]]p
t.Lg-A_
j)}A}HQw
\-0RPe
ti16gNq
s_5sYn
+^-(H/+-
$OJrV#
YAu!*-;*q
ztuVF(
j-(nw0
0+S,=/
@l8B0}R
>sm'IN
R)_;Lj
`B$N[0
SK=>& Qi
h2s[)"Hi
['1=5G
Lqs0|(
#Ju-H;K
i<i.-q
E%_iyk_
6%\AKY
qHmz7}
|eA<%;
J,x>1z
:]8^'z
f|#_=UA
fC:%lX
">?SH$NWZ.
MuNOQs'
=b3re8
$\V0(
(Nd]"9
Qdd~tV
^:e?-q}
AP:L#XZ
<1j}M]
*"< 6%
kYmQ|pu
)*pltP
~?W0}/
Ad9+x?
'2Dm6V
5CGA3+
nky\VS
%p.U6%
*T<GT0
fxJ"0
K07"G^
{qcNY;
yamAjR
6&bKpz
@2q!Nt
;$NAl!
"bR]NM
+T2/QdW
o5PFFU
'XzaVLIy
[1S|nRz
NwDhC2
1uPy%A
iALmU.
.ak- {p
&IV[?rR
c\-~/YKKb
tOl>/a
!]B@uZ
fOM~x{
OC_.G;
@&v/\'
(zR.e!
vovn2E
G]\|_z
i?#"68u
6x)vErZ
W.\{gU
\*?g`T
ecg" 1
|"=_FlHn
(cKIm
QH5|v2
iU%I|c
dj/_?r[
_-'+z
NwEtBMA
LC7QiT5
^t&5(m0
'h9+tx
w=iv2U
#|:;R0
3yP~Wx[
KFM[$w
O\O`PUo#5;
p\u$"v+v
/*ObMB
;A"hYU
q2B4e3
y]%M>w
@U-W%+
#B>eZj.
g{StEb
C~`68G
g3%FXE
8l;b,*~
bCYv:H
xV=Lon=
3#*]UH
o*T*Yy
l[yiinr
*hl1Mw
bQb0XR
s'n#r
}Ok}Ww
k+FA0:D
Y8C,=~
"yk z[
f7rt_*
Ob ik}^C
Pf)7!~
>|3P*W?
]/0-&v`FO
dN/V4L
lK!b}`]
I<P'?n
b#9d+q
OVg;_5
D\>$:~
H7aQoV
U*4l"!
Q82tY7o
&*ZCT9e
%~\^sR
_4UqyA.0
Td)}lO
4ZO_x~
`k%;|;
g_lTz$
Qmq3Q%b
i#ystyR
M!Tj:Kns+
c4ye3H./
fqkXcW
<`MmSE5
o aZvQ
=E3{Bl
Id{WdO
I[vLQ?
zy9?xHJ
R$d.3U
1%1SH*
M8h Fa
%]Z#RF
EQyyAn
<z=I\b
HTxVQ:
dka]pR
x!x,ma
~3#!eFg
<*:/x?D
bcSm'3
g p?;a
dW'pX(
ag 1Xq
Rw~y1Y
U/#BO;
\x({[#d
Z*SQl%
]Eg>dm
VIJol
*y7y({
I}kG)W
Os+&su
be8X@
7By6xex
W]h##T)
s0odNG
^Aq&?(
UGe"eNfe
!+7]ER
vI+^M+p~]
cg^_4W
ap9Zav
&HEE:-r
1B+$2N
lP5Xv(
\4=!"@}
pQ$<5"h
OY'[lnV
B<Yx)X
nV59K]
HI#!TqM
A('kCn
TGhUZp{S
"6Pp6A
zn{?zU
x4&^N7?
f>5kA8]e
Tf2%yj
H)W=gU
p]jJeJ
}OS*F9
yLMuAXg
jq@zTc
:JyFUYo
uL5Q7O=q~C
cUB606
HM,ZWx
W;^VKT
>_ XYu
pf1_.[
pK3FUV
xWGzTJ:
[]/Ofbu
F[\N]JF;C
R_Wee&
7vh'ni
J`qd\4
>yC,]
z(Ds6Ad
+C =vO
],g[15t
i9Qqp|
r\Y'wJ
NPb^]3
1VN/y9*
]3SGn}%
w57LDapW
r_#-mpy
m{W}cH
Bp\oMf2N
K>B+g~
wri^_,p a
mvl|Ba
i}n<P`
WwOHFD
[lmPe}
v>W]`w
oCuU.5
;qUjH;
+ae|sD[H=V/X
!IK.a#D
XSkz?tvE3C
O$9N[d
T/YQ\"K&?
c4qet`
cMKE@X
o?<r9}$?
U^Hd5)
;i}N:5<S\(e
bCNR,@
wtWe)AG
r}6ZjbQ.'
M &*0M,
q5~1Al
yN|jh =
l&X7kD
${<&q_Rz?
xu'7v^7x
+tSzH_
lSHK:1
A{RM~B
<l\>"4A
nJ"X{zc0'
E$Y`:b
W^wi]M
Nq.#s&
-Sc6D5
ZjYqFf
gDEyA~
9y9o2\
?&yeKfk
XO-2Tk
;fIe?r
7QBag)
wZsc24
^%X[g/
5h)wy.
@#VZA;
}r?PJa
Fy>{T
Eisyj$~a
O*d#oJ
:^P3S~
tJ5:xG>
xJm=Mm`
s\t#x&.
xAgB7j,b
!%V~Yj
"j+A(E
u=T5H|S
cdRxOd$
=RLp9g
Fzeoi3
0POAtAjR
S,aQv4
#;Ay)C
K#nJO;k
+9~M!|
@mqY2.
k.$\Gs/n
Fe'0Gv
]o1e mY
P4,d~2`:
hIrL.GR
&|8'm;
#QD#/`
.J;Am{
{^7_,LXZ
R.;+,y
ED-Lxcq
c9d(FQ
@H`EC
k`}LW">Cmpz
qE&!vMIsD
%-`D\1
`Zw*ki
hcT0er
nk{Me5*
)M?&,7|9
K=CX=O
I(Q<[n%
e23l*S
zZL)%_;?
CeBBsM
5.NLwF
[sah0.
[X?"nCe
Mg)0|6
{/f>>|
4dyYvr
{[Hn'3
yf7S/-
UgodD}
sz~"Pm
ia(_"3
!$nTk:
9Dq\hv
(i|cb$S>
W%qX j
5P}qi,
Y6"r_\
:1`~yZP
{+dXi&1
^bnFE{K
w;W]k(
9GQ=a6$0
qnR%5
k/{F~r
Gvp6U&
?$nKqv
^bGjz0
yiJk,qk
-^M{z,~#
Bv8Y`F
d\9$eO
U-i-O,O
nFKq6p
Q>xt0\>k
;gedxI
jUaf8/Z
E{<XHn
w] &{7[
om Wt4
&yArO$
Y^>~GrF
t%ql]AI
gW'@Mq|
{6fd?}5y
H7|fp`
@"r7YEN
D|9 BpU,E
rlR,|A
KC)mv{
oi8ho'Hpy
r-?>js
kLM9p}
+85CCgo
yPvCkW
dJP3fP
:Dh$#f
G e;k~-z#
H:D:}OJXa
A3u&!/
{0zJi'l
u6+Ga,t
m^Nq0m
w0FZ![
obG1s\?v
bB4`"b
0Ivp:p
3?p?'$
K_6Gr-
agFYvk
IS8Ze]J
RQ/?
)iBmRW
n}:~ix
M<sk
#Yn5 nc
_X((V3
J[ntxJ
7<k;a-
: |}OX
Gt|!Wd
FxtavwV
;$;I'+
o*PjL&
W<O+EV
B'1Wl>o
!?[wVS"
Zcz)]w
i|;piP
kpqgFx`)7
d-Mi5Dy:
{pRv$!
O9rN=[_
#=Z>NGv
U7WQqb
XF}9*7
NWSBZm
'Q-M0eJ$
t&'nUfOL
N3sgp_
|P:v[|p
xW/ZXqaU9
WXrr#Bk_
0,NZU}sSD
`M"2(4
ir{kDo
l!`(z[
622ya9
')=v>k
i(Ow4n
z)&4<"
1y;in^
,AxsG
idWugN
X9TkoH?
l@z<aV
vL]Rf6
gNfAy5
9c'!s0M
bKpD|@
j.+'HJ
zU_?&]
rf>lt/_D
z<]J")K
k,kKHT
7J5phK
slplhs
_SU#qv4
;~;sO
t-1l*3
W!\xhm
t^?VfLn
pc1`1E#
.Y<[4P
N4-Tkh
WUtP~9
2P@lEJ
$AGo&M
'~:8we;
$k0:N4E
_M~+:ZVX
:Wi"5a
b4X`V*
TJAS9U
{Z2kjT
PcU|Yg1
y*W^L"9
X%Ve\WT
]mI,:L
1L{cD1
q[ad7
}g/D>?#
su|@c&
]|'$um?`
nVqe16
Y HG-%
ibBB6d
B^o*Dp
;*&{LVd
_?Z||2
%{o &e7
i~Xufk-
3i5gH?
Ik(4Qr<,
K,-"9
5I!o`8d
NcNdoSC
ne)ro^
OVaSH!
;W|eb/
u8:~~hM
lM6mgz
B>R@=S
_u3@?C
KzXt|R_A
]Z!V$mp4@
T*4wvi
TO`W@
)>Na[K
)nCaL>
4`]_pZO
5Jg( ^-
;]? p4
PjhLv2q
_'{9LB
.CV>D70g
:p%4ve
n!)T+;=
*%lskK
'%^.`
HctINYf
1;b[CR
F([Nv[
wWeX>r(
?;?dG
gA\lb
pJcdMc
5/jU8B{y
;)O\62
|bD\5=
P\3N/G
}??~~:
e/ugE]
kb%U%s$
{W5`5!$Q
*kigZ_
yk!q^C5
&E_,!'
|DUsLK
KG/x;YO#
y;uk
D$pno0T
*CNYtS
N$oUv(
wH=J:J
4p*\kF
z^yK%4
wV/#\c
b%Zrh-Qq_
r=9Gbi
2}d`hO+
7j%v<d
~:}{<]1
MiW9ZU
+RY58:H
/h'/r1X
+eixN\
e^{]\LcEzG~u[
u3w]AX
*2'"*d
};.=T\
av|u-C#
qrry$Gm
;4mx$y
dV,1=P
\AOyUg
32_2X@
8IC/?0
.O3H{\
N,)d5l
{-Sp_
I7(%<.
(L% I[
^,a$;a~
X32+`0o
QH,PR;
2.<H'y
e|85.w
1IDo;ds
>FlFv@
-JiFf~
*6:_![8
FvgPs}_)
tUIZ^^
{?!<#[
H6%K 8
fstiPoE
mq;NN"B
F+,dvx
=6S< S
(r!ko.W
TaY"]U
ykR5*~
.`&pDfP
I=o8l;Q
T4fR'n
_&(4QiTCyrv
P}WdK(
V3:7Mh
1u+dcQ
$p\R+I
_E}++!
Zfq6+P
tOV#x5
UF_+sxY
mO'Lcr
L xH()
2-7'o'h+
QdCFq/
ABbb L;
pV[V$>
7S_gHY3<
iz_>l:
RdDvx'
l[Y:/k
_}7!lw
`JV l2
1azd|&8x
>vGwgBW
.!{5IZ
d@+hc7>
jO@uj7
{OmU[
Qk?77\6H
sm@Ja_
@gyTu{3r
N~vH[w
Oxh9R
QW@':u
`w&d~p
NnoAvNb
S()(>R]
iyb*O~Z
9 n! 4
%+o\Xo
)\=w' !
raMQDGv
*S283r&f
8#*I0d
-LA#HY
5)Vyy;
.Vwm,e']
'l+yhX
GTb4n
`EYSVgv
EfQ3Cn
`C)@|
O8i6|Z
^%1bu
k#4Su
r)v4zr
pCuJY1
}z|ZmU.XV
=,a}]~
,aaajW
DtX@.UL
}-vv<Y
b@1w]G:p@
(r"@6f
,vp@L*
Uboms
V}u3-\
wsWtSRmS
Dr`Qg$
+2BE*|Q
bV mWX
?,u#J@/
#"]5gxS
i!X*C
TlYxMX
#2':=MI
dSG,tG
n8nOoVT
DBJW 1
|e[MI&
st0%Tk
&=lJ/X#
INGzR(t
B3(j1&
a3eTZ+{L
k7~I}JO
sZBrDK
$I/"nI;
06#9 L
8$HR<`
sn(_B8N
fr%v!
guGBF2W
20|Itwr
b3>-WC
"]49AM
1iZl"[C
:d[d7Q/
/v|#u|
rLUO8T
}7G`q$rq
9:i,q;^
{0JwQT
EhMnf|
7=AjO\
{rL!LVS
7#2z2k
x~ENmgD
*Og<al
2!!J^Jx
>h?FXg
y9Ox*(
bjA3}J
JBW1T^
8jcKES
Kmlvxmg
{N~'9N
<8q./m5
xH8Onu
R{K.pB
dQ&tPJTP
1KL*vL
DGW#<8
MtmgU=1O
HKTHFf#
Hk>Isd
!iG"W0
BU['.i%M{
p#Y({7q
2(ezL9I
s<?)xnA"
|p}Q)-
*C&B.d
QmQr~Uj6
<4YDv%
rBV4T4K
%VPq]D_
W_1xvO
nx$`WLe;Ad
5n(bk]
t0\``J
5?&(0C
q !xR2
\r+(+`
&n3Lm%L
qG|:AK
EHR*9\
ErX3bLJd
H!TIHo
]`Eq_-;
(3K9"u
qv3k1I
X-qukn,]&
:`5+8@
r(v*.u:
w2IGBA
GhMK6Z
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Gacu sixuvizi. Bus zavuradiri hikuwasoc. Wuvidohoreyi wuvubuj xifekaxitu sesax yonisoneposap. Pam wur vij lotakapig ripixorunoco. Xovolihizopuj hovobaguyujom. Jamediyofixufa cune. Tizecurajuduk liguzuliheg vaperimam. Miyixunof cenekogaberosa semezedoc. Paxo tayayavi tozubuxiwoj. Huditehigozepam mijibumek tohiwivu zosibalupufek rejadovehodav. Johawisikanaxo. Mihovodoyomop ribiwuwesax. Gadihilahizowol mupisisi. Mobiyujelanufi fanazecir. Toritagetamicis xut seyitic yakupuj zumak. Mazahizuz. Nepi. Vupevi. Hunecikize cahixurogi yelemim gopovet. Hosufacuge miputixirahim xumu. Cahox ridoyesihorijes witik xiwiwub. Dudokivuhocekes zamaloze yec foha monasejafinago. Xogar wusamujut xowayay kixewoluweme. Basageyakilu vagukafog juna yiyarohajedipa wikabiruhuh. Bajagikilig siyo towunefiwela wer. Lohali. Hitico. Yuteyice winaracay lupixacurapodex. Ribapuf jarup rorev. Vohog sebohajiri taye bijeficoxofe jewofopotavo. Yozujegin yoyew xawexosebe nipe kesuduya. Bexojuvo jewa tujipedijeru bofe. Pay. Bocabe fuh. Baradilefebu zena
Boke saresupujoyolex m
Cekepagojoze ziyovaragijen gedozutusekave ric wohegabo. Punetijeh firocozudubatux fotani. Hisejuxebik piko doyanetaxe guyuvafi. Voduyowe pivezafos. Faraji biw xizecayeb tecocorinepob. Hol mohumumagacey sugepom larogiy. Bajemuna darawedecu rezazipaki guvome boci. Yahe zidog cowimes. Dimuco hulirixizeviz kaxadaco wanejo xujuhuzepabupi. Ric debiziviwir pok xugawil. Tufadaxolohu tugisijomalib. Gifufa. Mujoboyenehupey noji. Hoboh jarisicux. Xedubus. Temi xefef numiyuhivavalo fekocapojey takucif. Hobezokix sahizap vilaneh. Dohikivuyano gugatiyazu. Rafiwunuzuy wudakibu filatozeweze supecegadeser lulofecoye. Giduxufecodep mov fejocake canopagag kerepevedosexi. Yiyowaharuxupe hafimocakujawa motoxot dititejare. Cejupi bimusipola ruwevehari mihunalew cizarasujeme. Mujate. Vijo vovutegocamoze vufug kodayiponew zeyomurihipe. Mubifozeh. Gafu fobogowu jubipejoxosote. Datalibeburaru jah rayid hubayumoz. Jarogeticemata yefejuno. Cehahabiguxe. Lirogaziloruhi wixe yopodem fomaxemugadiw. Havihobo. Godivuyoro tuyilebejegoyak wipa
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~
CCCCb~~~~~~~~~~
CCb~~~~~~~~~~
55555555555555d
b~~~~~~~~~~
|5555555555555dVV
~~~~~~~~~~
55555555555555
c~~~~~~~~~~
|5555555555555d
c~~~~~~~~~~
55555555555555
~~~~~~~~~~
55555555555555
~~~~~~~~~~
||55555555555
~~~~~~~~~~
|||5555555
~~~~~~~~~~
%%%%||555
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
AA"""vv
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
777777
s7777777777v7777777777s
&&&&&&&&&&&
&CCCCCCCCCCCCCCCCCv
SSSSSSSSSSSSSSSSSC
}}S}}S}}}}}}}}}}}
l3}FFFFFF
FFFFFFFF
FcccccccccccccccccccccF
Fc22c22c22c22222222
l[\2LLLLLLLLL2\[l
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJAJJJJJJJJJJJ
JJJJJJJJJJJ2
JJJJJJJ!
JJJJJJJJJJJ!
:2JJJ8
JJJJJJJJJJJ
JJJJJJJJJJJJ:
2JJJJJJJJJJJJW
\JJJJJJJJJJJJ
JJJJJJJJJJJJJ
JJJJJJJJJJJ
@@@@@777%
KJJJJJJJJJ
KJJJJJJJ
KJJJJJ
JJJJJJJKq2f
LJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJJJJJ4
JJJJJJJJJJJJJJJJJJJJJJAJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
QQQQQQ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="5.1.0.0" processorArchitecture="x86" name="wextract" type="win32"></assemblyIdentity>
<description>IExpress extraction tool</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
</application>
</compatibility>
</assembly>
cihafinahafe
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
((((( H
h(((( H
H
WUSER32.DLL
KCONOUT$
@jjjjjj
AFX_DIALOG_LAYOUT
DETUCABKAXIGIXIREBIXUCEKUZAVIKIRIJACIJ
VUGIFEVAZEPOLOCIBESA
/ P6pL
,/KPip
/-P?pR
Jolimatu yudum pag)Hixedicuh moyuculuhor biheselucojur hahiz
Kariz mag lanuko"Netegawiwotoz bugozozitub juverapupWecuvik parumopa xegaj cedadivedu pokapucacutikag sixulaluyecad yoyizeleyunuzo pinanijiwonar xadore nubiruzisuraRXiwerofuvuyug waxifux zok niwebupoh hibepuge paceze pajohepaw mopix fuh teyiyohage
Zejasi bixenus malewinuberekiGCadurarubupiguy takozalimadel sizor mihinuxal gevo duca xigunabojuyasanXNanigekorevone gitenuveruyibu wuw tesaguv tiriz gekuxakodenu nilat nidow toye gajalawimi
Kevuwiki hoxox borososok
-Nij hoja mihetobifuperut daxudosow reloyigela,Nowizew mubodemogukugut popohagawinuwo suyec'Yofudofi vofahitopiy lumopegepog vejuso:Dicecono fabivuledadi petepajegini kopolad muyabihaminuzer
Wupav vapumoguhozebat voyoki
ZotomolajLuxizofe ducexoba deruwigef zobenizabawes gugiyo kevumuvoyoyukeb jobicavuhomaz jivejuxisi zofegudovuja wol,Geje vivohuwonatuwec bifukivadufi bibiyuyije
Xelew<Powehogu liviginuray liwawiwemid jusudiyuvu noyo geka fuvipaKKawacegu royiz sowigahup tukizaris som tonohomipedibu diw vijaceb budeyojigRGiko dexuxa rapevaxoxo tofedadazas pali maxid sovuturejobo wegifabixituju vososiyiQNihihageguyidon bera hixovizuseme yuyawecac vun zocopo cis cewuz xakuvuroni miwuy
Gubuvivoxubac sip nedokeg
Vul bideyu behug buvodako6Nuka cifuresikokal zehulilac legicowefik jatoluco yiwe
HMugupetum fahosujo kalikitavam tawigahe facabeten gihofu socimibojujurorLJehonihecucaju verepihowigu jojoxobahor fihokowo yitusibobir bifojazihubexesEHagi zugicinezam jahikufehovatin sifopefoxuye yevagix bedek yexoderorOLozahisivec xok hax mesitige kodapatinavu cejokev worovu hiluwuy ciyizowenufiwu
Kilepomere#Meboli pelezobe roc vefuhalemufekat*Yojuramup dodawu reyucu gufakuta kuvakayor
Pam sanecuWLegocezebugo sojevuciciduda madepuyefero rutarewa gimuceze vuxawoxa pojoxeto leyunaxazi
Tuzibo kaxerpZelemipuhejecun fekapehubusinu jodewupa zadodubux jonuzocijugu giredak gafeneworeheh nabidavexajaki hetitepimeki
eZefijadube giribeleha wibisixolidedo volexugabo pedezanasunofu gawevilefumusen pegufuzomimicit lihoni]Henovorucoyo guwujizowaxe rozacihehemafep jorikadeyiloke zepepaxumiso gajucavucagil nayifocun
Neraguweyebucu civin?Yohucaneg vef gufuvawegoyil mijigijafixod wikiju zogujiyutaluni
VBozor xigubonu bal wawuligan xikiwelijacig zoruj wakuc bur somisaxomekax demuzacasurerRSohokagotal mojosakepewebun zitutacoyezi wodateg josu celagej kotisusah hakogerabo
Hoboled bojekego pivoloro(Ponekutokojof rewu mososu dolucu sivixikcMugejozibe zolasururowajuy gijawegejakesug vokuvid kidiyamusi cigedezat sepayuca wurapenuyizito xalNJodug kaki luwekiv zetop rakiyegeho hube ziwutuviw sabiyakased nexegozovo kota=Firafejovumedoc kasi bozimuvorayibi xesudeviyaxi tirusaluweta0Kuwu bazup jeladal hesacimewepugit zulujofiluhep,Dafudosuded vubike gapexeyosaduke ruzexogoki-Givif vufeyizunohol roya tipefovapujor lexijo7Zomibalujakos levuxedu salodanud vofufexuyedapo torurijLNazew cibupavigalod joyadoribu tahozagoteda puvocizema pad mik munadutowuwew;Jobiriwe nevuto yekonavavuhome pikawebuwo bon mevipibuvabezHRudenoraju lozitayocizuk cokubabezoh sofuj xuwasukezi cuvaz rujepitewake
"Rofihohawur xidesewuzobejar wojeha:Gig xalalezi xekabe zaju pipokacun tok dimaxodopo sul jabe9Gapoluvev hetixurubu pewele lunojadojimuz socekofina feyaQJovomaloyaxi sapomebilokaku diw cubevatab ceg tenopifamilu luba vivopeb rihewahicOXowub ximone tuzuciruf wuwokofocedu retugi tuvevefaporuye likujazi rukomeyebuseTevulipexor jupodat diliwadiyeg
Wihofohizihit tonazagukocuci
VS_VERSION_INFO
StringFileInfo
046805E6
CompanyName
Furious
FileDescription
WholeSheet
FileVersion
170.43
InternalName
FloriousCourse.exe
LegalTrademarks1
Coordinator inc.
OriginalFilename
roulette.exe
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Win32.Trojan.Kryptik.jm
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Generic@AI.100 (RDML:pa9RcgP2vSA83ROBqq4fXQ)
TACHYON Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
Trapmine malicious.high.ml.score
FireEye Generic.mg.9cb2c1a445f74bde
Sophos Troj/Krypt-VE
Ikarus Trojan-Banker.UrSnif
GData Clean
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1224196
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
No IRMA results available.