Static | ZeroBOX

PE Compile Time

2023-05-08 18:45:23

PE Imphash

ae64f100c0f22c43c95a1d2055ef681a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001b919 0x0001ba00 6.63089012155
.rdata 0x0001d000 0x00004a46 0x00004c00 5.07971647903
.data 0x00022000 0x00024508 0x00022600 7.2004510408
.rsrc 0x00047000 0x00000630 0x00000800 3.4731886814

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000470a0 0x000003cc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0004746c 0x000001b5 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x41d034 GetLocaleInfoW
0x41d038 WriteConsoleA
0x41d03c LoadLibraryA
0x41d040 GetConsoleOutputCP
0x41d044 WriteConsoleW
0x41d048 SetStdHandle
0x41d04c CreateFileA
0x41d050 GetCurrentProcess
0x41d054 GetVersion
0x41d058 GetModuleHandleA
0x41d05c MultiByteToWideChar
0x41d064 GetProcAddress
0x41d068 WideCharToMultiByte
0x41d074 InterlockedExchange
0x41d078 Sleep
0x41d08c RtlUnwind
0x41d090 RaiseException
0x41d094 TerminateProcess
0x41d0a0 IsDebuggerPresent
0x41d0a4 GetCommandLineA
0x41d0a8 GetCPInfo
0x41d0ac GetLastError
0x41d0b0 HeapFree
0x41d0b4 LCMapStringA
0x41d0b8 LCMapStringW
0x41d0bc HeapAlloc
0x41d0c0 GetModuleHandleW
0x41d0c4 TlsGetValue
0x41d0c8 TlsAlloc
0x41d0cc TlsSetValue
0x41d0d0 TlsFree
0x41d0d4 SetLastError
0x41d0d8 GetCurrentThreadId
0x41d0dc ExitProcess
0x41d0e0 WriteFile
0x41d0e4 GetStdHandle
0x41d0e8 GetModuleFileNameA
0x41d0fc SetHandleCount
0x41d100 GetFileType
0x41d104 GetStartupInfoA
0x41d108 HeapCreate
0x41d10c VirtualFree
0x41d114 GetTickCount
0x41d118 GetCurrentProcessId
0x41d120 GetStringTypeA
0x41d124 GetStringTypeW
0x41d128 HeapSize
0x41d12c VirtualAlloc
0x41d130 HeapReAlloc
0x41d134 GetACP
0x41d138 GetOEMCP
0x41d13c IsValidCodePage
0x41d140 GetUserDefaultLCID
0x41d144 GetLocaleInfoA
0x41d148 EnumSystemLocalesA
0x41d14c IsValidLocale
0x41d150 GetConsoleCP
0x41d154 GetConsoleMode
0x41d158 FlushFileBuffers
0x41d15c ReadFile
0x41d160 SetFilePointer
0x41d164 CloseHandle
Library USER32.dll:
0x41d16c GetClassInfoA
0x41d170 CallWindowProcA
0x41d174 SetWindowLongA
0x41d178 IsDlgButtonChecked
0x41d17c SetWindowTextA
0x41d180 CheckDlgButton
0x41d184 GetActiveWindow
0x41d188 LoadCursorA
0x41d18c MessageBoxA
0x41d190 wsprintfA
0x41d194 GetDlgItemTextA
Library GDI32.dll:
0x41d014 GetStockObject
0x41d018 DeleteObject
0x41d01c SetBkMode
0x41d020 SetTextColor
0x41d024 CreateFontIndirectA
0x41d028 SelectObject
0x41d02c GetObjectA
Library COMDLG32.dll:
0x41d008 GetSaveFileNameA
0x41d00c GetOpenFileNameA
Library ADVAPI32.dll:
0x41d000 RegDeleteKeyA

!This program cannot be run in DOS mode.
`.rdata
@.data
^\9nTr
^@9n8r
T$\SQRV
L$XVUPQ
H$SUVW
D$09\$Ds
|$09\$Ds
L$tRPQ
D$tQRP
D$pQSWRP
L9t$Dr
<+t'<-t#<0u
L$\WQRP
D$`PSUQR
T$|RPQWV
L$hQPhd
|$tPQWV
L$hQPhh
|$tPQWV
L$dQRPhl
|$pQRWV
L$dQRPhp
|$pQRWV
T$,jlR
T$DPQVR
T$,jlR
T$DPQVR
D$lQRPWV
t}9>uyj
tz9uvj
F09^(u
0WWWWW
0WWWWW
QQSVWd
PPPPPPPP
to=d2D
HtHu4j
s[S;7|G;w
tR99u2
^SSSSS
^SSSSS
t"SS9]
0SSSSS
_VVVVV
^WWWWW
>=Yt1j
j@j ^V
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0A@@Ju
Fh= ;D
0SSSSS
0SSSSS
PPPPPPPP
t+WWVPV
URPQQh$sA
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
HHtYHHt
u,VVWV
t VV9u
<+t(<-t$:
+t HHt
kernel32.dll
bad allocation
VirtualProtect
ynbjivuscffuvpwlaqcajxznlyrzeogpykxnkbknobatuqinhnkfwebfqvcbqwxjl
ios_base::eofbit set
ios_base::failbit set
ios_base::badbit set
bad cast
Your lucky number is:
Welcome to my program!
string too long
invalid string position
Unknown exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GAIsProcessorFeaturePresent
KERNEL32
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
CONOUT$
GetProcAddress
GetModuleHandleA
MultiByteToWideChar
GetVersion
GetCurrentProcess
KERNEL32.dll
GetDlgItemTextA
wsprintfA
MessageBoxA
LoadCursorA
GetActiveWindow
CheckDlgButton
SetWindowTextA
IsDlgButtonChecked
SetWindowLongA
CallWindowProcA
GetClassInfoA
USER32.dll
SelectObject
CreateFontIndirectA
SetTextColor
SetBkMode
DeleteObject
GetStockObject
GetObjectA
GDI32.dll
GetSaveFileNameA
GetOpenFileNameA
COMDLG32.dll
RegDeleteKeyA
ADVAPI32.dll
WideCharToMultiByte
InterlockedIncrement
InterlockedDecrement
InterlockedExchange
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
RaiseException
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetCommandLineA
GetCPInfo
GetLastError
HeapFree
LCMapStringA
LCMapStringW
HeapAlloc
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeA
GetStringTypeW
HeapSize
VirtualAlloc
HeapReAlloc
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetConsoleCP
GetConsoleMode
FlushFileBuffers
ReadFile
SetFilePointer
CloseHandle
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetLocaleInfoW
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CreateFileA
)*`+ws
m#v+7kftnN
Bv%-asoro\Xv0.4.wtw1y\XAttLa1.'hjaxeIZ
l)wd4vog2a-$#!jj+4$fe vuj mn$D
dm/da.
DDD@B
.paxtD@D$E
@dn2wv'@
@D.re(/'
wQDP*
3O(&ny
8MS%!o
qMQ% E
*{jA$`
mAzA,[h
G?$]b
(~v6\8
J#aVSpx
Y-Qfc
aMX$f<
lxK9V!
V(QqxWZ]
\IUVe
@|jc?(
zF_:N<
u*wy/[rGg
[C}5J$
xV7Qq`#m3
6|=:w`
,*bjnS
j}:_O>
Fu7|[o
hPyR1c
qMM67S
M#7hM,
a;vVa$
(6x1ox
-Y"fb)?
aaWLJ^A
&ZE"D@D
`^ "Z_a%8
Z W 9f%8
UHd;r_
?Z Vo
jvH$Zh
.Xn7L`&
UH`Gd/
DDB!W\TD
FjWnwL$
Gso!"8
n.Ld,8
$kH~=a&|
!/B`3,
_Pfd:A
$JIzZ$#
D@F%WX
DDF%S\
b`~E@D
ma%WH_
YS e"QH$d
$G}}4Z`
T>:a8g
Bj]j3L`
%$6!fx
dOj4Oax~
OUL d{
No D@J
f`~E@D
bd~EDD
Z-a+B$
Z$grs]!|
Ay%+B`-
(%D@N
G*S4H@h
DDB!W\TD
FnVnnH$
@QH$o
T&$~A
e{X!kF$
D@@Y_`X}C
H_FZ`/
`N|G2Zax
_bjvHd
W\JG$x
zD@@^@
XE^Z`!Y
bDDD|@
v!oB$re
$DDDB@
rZdRYg
Y`HQA$
Y S@
s2D@B}U
rDDD+0
RJC }_),
jvHdE0
Bo+D@F
e%I[R^
^&CXL
%oF`K\
7~R0!<
KADDqA
$:sDRZ
dczVh<P
NZ]kW@
dN4%Xe"x~
xVe"xj
UZ k~'
h%bQK$!
Ua!b|c
Oe"UK$
Z[&\I ]
3%oFd?o
[I%_Y
oQB.F$}
XD@@j@
!&CdZ!
X[_fJ
dee/F`
__[#\nD
F{!D@D
OXeaKZE
f%+B`P
%+F gfE
D@BdN
!kF$w{h
sWL!oB$Al.6e"xT
^EA@D
kBFRy)
8e&F$;
|a/B t
jNkZ%xh
D7H$GAX.ak
+QBl.D
D+:BB;.@
DDY]=/DD
Nb<n^
DDXY9/
!kF$?e
e!OYZA
$7gxc X
L(GD@F
6L`lQ;1!+
>ZSab|Z
D@A!Y$
D@E!_ 
$&:K;V
,_DDB&Q
>WVw>D@
%Y 3'b
#\d^
Rs:D@J
D@E!S U1
D(bD@F
Udp%oFd
Rs:D@J
D$hhYg
z/DD@~|
^ ,ld|e8:
s:D@N$
@F,ZD@
Na!(e@
\D@E%R$
E,>k@,
({D@B(L d
jWE:8D
AeMRd~
a]$Qhx!`
DDE%V
Rs:D@J
6`i9FF
C9:RR7:@
X`%vCt$3
DAaN$
(<D@Nkln
u$TSRsz
EeY -/y
`{Zq?
@= bqWh
J$?ZdV
D@A!\$O
D@E!Z Y
,;DDNlh`
? `*Ce
DDE%Z
eL$[@
D@E%^$
`DRV3>@
A!Yd/2
EaZ !N
-%M0$
+k$ Q)
a%WL]^
n/9$'d`
@F,}D@
BD@DUD
D@oWL(
D@F(H$
DQdM<!
a_K$Ku3
%W`Ii8
SD</E@
aaW_J^A
3D@@x@
(@@D/U
!_~<D@D
^ 3aV8e8
D+NUIQ
Z$s'"Rak
(A@D/l
!]~DD@D
F"U_$7
QQ,zD@
{>o^ HJ
@@zED@
@^q^$k
e[z@D@
{UJ,z
(vD@B(
!X$~0
k.`e|O
e%W_]^
,dDDB(
FW,WD@
(E@D/l
p++@(C
e%W_]^
8a%WG]^
!~DD@@
"~FD@@
j@4B@
^o=a%S
@F"zy@
BUA R&nv^$
p$@^k9!!SE
@~4D@D!m
z9DD@%m
%iFbvE
%iFbrE
"rEDDph
Zo9aaSE
$D^+=a!
|D@D5D
,uDDB&Q
~<D@D$
(G@D/ld
B&~x@@
o(dD@F,
$X;Z"e8s
/}a%WE_
A`c5E8^
(uD@B"U
~=D@D$
(F@D/ld
@F"zy@
@k,`D@
Q7[e<D
D+( @@
UKds2F
@@n_NQ
@@n4L`.l
-_N5L :
-vL E0s
uc,!oB$N}
be"QK$
d0uD@hf@
6W*@^
KKvJk
(A@D+l`
$v2tuZdZ
U(lD@J.@
D@N*W4
D@J.S4@D
"B@D\D
CL@@B@
F"QJ$Q
DDE%X 5O
$[dGCZ
aZdwXD
XIQN$s
D@A![$i
D@E!Y 5
,<DDNkh
_*LZ m
D+@,C@
3>WRw~
DAb'\-D
g"*^%|R
DBL1k
@@</D@
2H@DHZ
OX@DtS
\1P!&8
DDE%X
n8ia|F
D@A!X$k
D@E!^
=h1a8b
D@E%_$K7:
A%\$gk
^$Jl8*%8i
UDY/L$
$b%+B`
$E1!fx
DDE%] C
BYd-`
Omd9Fh
D@A!^$
U<&a|S
5SV7:D
dxM[y%/
IJ%+B`_
US\2L$
`yGDo`
I|WRw~
svRRw:
Q# 5K0
D@A!^$
LQ\ NY
WVw>D@
lST 1r
D@A!X$
D@E!^ +
7f!oF$
%+F QZ
">aoB
'cW!b8
Rs:D@J
Ee^$7e
A[M2H
w%+B`<E
$|#@Zd
GAkD,G
bQX$d/-^
HRR7:@
DBb#)W
Rs:D@J
JRV7>D
Zdf/9Xe|
sfM%f8v
dg_j`d>
D@A!\$
D@E!Z kj(e$
,;DDNlh
Rs:D@J
$yQ]e >
DEaM A
`N1%"8
;j%+F
Rs:D@J$
@@/,B@
\D@E!R
X/@,ED
a_$FpY
-Ocvo
e+@,D@
PdQc&@W
)6LdYYH%%k
D@E%^$
SK7SV7>D
EaZ {j
_a afx
D@A!X$
D@E!^
D@A!X$
D@E!^ 5
DDE%W U
VVw>D@
DEaI _
^T%"8(
D@E%\$
_RV3>@
r3)OSR7:@
<GSVw>
!]`O5T
W+/@,GD
eK$;+!
-g-^ }
JRR7:@
D@E%R$gT
JSV3>@
WVw>D@
QZ]$]l
*D@DAX
cx@@9@
!!N]ZE
}7te)n
a3k16gesnR%w/5vg!
aedev,$mwckr(-&,`Varwmonytj0j4.0l$Cul056ayne142e,(d
ko!.9f77e5g521=3p!t8y#Wywpemj
!s+qrc%w.Ru*4-i!Re7/5v#a
D@TEDPEDT
}st%i.Re7/1v'esj
%w/q6'aRe!d%vl`iw'/vhib( Revsmo*yp.p.4.4( C1,0u6a=n%qtra(ldT1bl-#
a9P+/an="7weu#12uy70e0<9'S}spe)j
e3oqrgas.
5*t-ieR%wour'%
D@FWJB
64*0*703uyD
p2)jc7@
D@gF(obD@@
'Sprmn#7D
D@gB(kb
D#S'(%i!
RIFDL_V
_=VE@(D
DeSm@'
1DA@x)
A@@jD@
@-)O@A
@@FoEE
@PW)DM
Ma|FND
l5XGJD
q@d\uA9
I@*ZGI
KDIF~J
3DZA.@;
CDsA.DO
TAn@g@7Aj
0DDD#@
BlC1C3
"DD]@(b
8"@D_Ddf
oy@JyJ4}
kB.EKJ
-D30v-ng
"q4@2wr55EpC
5=57A4554D<D
035E<D2
6088vys6|CAu
111x7r5vr74u
2166A9@D7DB0}
Bq4F154BB
qq9rADEx3BC7}s
4@@u}G25s0p4
yF@|w3FD671105EB8||
70C30FC
|6|79pv
637u0w0v
x7F63@5197127q
0=0<@D3
B}GADx4AF5r
4@8z}[_3s_p
34vm*'[f0
wtvijg[buuD6
C160F5E|w
@4AC5BG0<EE7}uDl"_5
wpri*'
1Dhnu-[1
.1i!ra&,%dq
jum%r!p/2d5D
wtvijg
3tvijc_burDM-gro3kft.
+Mnts2@0
w<=50BEE50B@4|qp3w5@3AB26purDwGB3
t0wFF}
Bt|B83
2@w42mj#6
Fujcd2
spr-*#_"2
spvin#&1w
Ev93}r
4spF85qD
u@F|p64D5761444G5
u|0r4@0F@9Aqu
ECqBE54r
BpuFBEt4q6
=3B2BB41B1=CwrwB
2A0F5D1wr
E8u7F90tusA
=DDy2yA
r<3rxB05D=7@7<0GC||v4s14A3GCD
32w<7A4rt
u05973CB42C3Es
F7C76BAp
7BuF414tqp2}2B
Fw4urB1Cq2
F77E5A5AG678
9<7A794
st2mng_w@7p6in#"7@w06mngbq0@r40
w5FFBA742A064
w|Fs5F4<3A6pq}A
687t@1D0
kM*420
sprmnc_0
706i.g[b0
G31q<CE7p
B17y0x6x
v4728@15A=5EEw|u3p8B11
FEEu6D6C}
|3wF9u
@tr108
s<EC6ADE0G522p
w6q2=21
CuG54q=4F7wy
Ar8Drrs5tB
379054B92D75u
7t1331
71A0}p
Fy0wq404v4x3vtB1tv=1343804FC<1
wuDp3=31
rv7tBC6
tB65uCsBst24py51A5=6GD5DEC
Au9141
Au<A1tA6B7
}G}FDstv6
u53Aw2q@yt12u
15B8AF244DAFp
u|Av=F7t6924
t}GqDA
t<508<5F75729r}
CxEEE1
st6)*g
s4ving
@5qp4G6DGC56@A<8r
sEw4EE7596vs
A4A5usr
F}v472
BAtsGAF97E7415=2t
tCp5E8742FvptE}EB3
rp<v@sw4F7
Ct3qqG=
uE749GA61<F34wqrE
5AB=023r
|6t737
80tuv3w1p
77qq7<73510DE0GC
ws2u8@22<18
6u528wE41Ew
7tr-.'[v
70vin'_"2@yA7u
0E3C67G674FC
rBw464<2A7
trB|GADp65F8
vrBq3B
6BFt6r3@w1Bs
3561=84C7D3C
52336C0
@3Fq3EB0px
=tu300x7u3@KVru~kcpsSOQpEEC
9NK7N7
L-Hep.^0Yq!7)E
PsDwtr)n'[w@wp6)jc_b3
wtvijg
D@9BB42
222t3E69
v6xFptE95
5490741FE0B6q
vF270G63wxr6uBAE
pABEw1w2puE2
wFA1E1753B4@Bq
'ep_QPF8D30r-jg_x
str-.#[&8
R77GGS2H]C=
t}|1s0EDGGE1
7u=F6y4309puu0
s186x0
y13BEB42A<D=
706i.g[b=
<M+$1l!:
2C17qp
r77FD=DF110G7r
8386698
B2vsx6qAp
=EEp1q=
A6E1A2EF5DF5qpp7tE17AF96
Ey6055|p
FvA7swq@
6s|=A4
E7stE0F5@E1C35=C}ps6
F71<@CAr
Fs30BE
u72ArCy5
p5@B4183E2712p
2<C156Bu
_vlONo>
@*<|%S9Eqk
$UsKl}auMTyQb|
D3JESRl9BD5rpCmM6APlE2)
6=5962@A<3GDs
p0p23C0437sv
CuB80vFDDD}svG
53uxqAp4r
v<<56E6=A3BGEptwFs1<8679F
2ECp357A
28uur3
F2705F=2@BG5
D54F61Cv
@73yEB56wy}0u14vv
1uxG3v
@2E5347F10<F}r}7x663AA29
ys3u@C8x<F36wtv2}7B|
1p2v2q
r027007264728pwtA
D<033DAwyw7v7D2
<720|v
r0@uvEFB7375B160B}}rBq6B40E1Bv
6F9vB58B
7@996EF838A0s
5<CB<4Fsrq4
270rAB4Ap
v3u4Cv
<wEtsA
vpapPIGd^ohP
[c`B6P):(B
uZkR#p)V2Nbw
BABw0sE
x@1C0A0722A39
114EB04
520q@D29wwp@s9C
b<t)lOVNFI~jAzol
[FF&r q
S3K17!1\
N92&35
@O(1moVZ<K4s03Q7
m7AiPOrr
_=%3l!Bv iCr%E
19+h<7(]]P7SL
_vCpEt
pHaf=Ng
+P<fw-
FuI.+Q8M/BpI
@W}stam*IK
40a9BprlPUS)9sJ
21-78T#b-
rGb*0vL:
_C8i7Wrsb"
58*v@qNoFq
v/i4QV
5q5Xp
q3#b91+k5@
LEEMEqAELAae
O2VAKlZD
QpmZR56Pxz5)
o%A53yqW31w
m3c/v,)f
7%p[Vevb
5i6hUL4&x
tFV66c
S=30a).C+,,a#p-+js.
e.a2)g
/sjloedBiheEs=*'
panVaadD
S=.'l6on-:%`@G(%wsI4e-B)%h`D
vmmEjd
RkujdD(+d@MekaWpa'%DC6aat%Mnst%.'aDse0
cep_Qnmc+ !
nqmavab(%DI
msp/wabl!@
k1bl!@
q.p-)aFi%l$L!.`h!@VqntmmaT}paH%* l%
CepPyp!
6o)Lan$he
9wp!-EgcewsVuhe
R!#-s4r}Agges7
se4[For)
7!p_W)n$k7
TrogewsSijd+3
3at_E<
C!4BmleJaie
cep[Us!2
#!p_P2o#a33Je)%
VeedHi*!DW2ipeHmneD
+m&mne@Hoca(
%g,in!@
}pe@S%g52mp=
vktogohT}pa
''e3sGojpro(
co.prol
94aDGe0
,a-a*0Pyp%
j)4me()~aHavdsave
ywtaiHa6$3a6a
S9wtemj
A40,m#e0-knS%t4m.'wF%3a
@iwp+7!
r}PevseD
6u*gat%
Cre%4!
di0/2F2k37ebl%S4e4%
@!,ape
,r%a`Appri&50eDGom0mler
%*a6at!$
p4v-&qte@G5m$
pp6)fqte
Ganaret!
o$eEtpvib14!
abu'cerN+.
w!rC+$%E4p6-fut%
a"5cc%"haAtprmbqta
-t/rFrkssa&,!A0pri"qte
/)R-si&,%E4p6-fut%
w3%if(9PmtlaAptvifu0!DA3samfhyT6! e)erk
ptri&50aDTa6'%p
v%)awo2k
p42mf14a
AsweibhyBi(!
e2smojEtt6)&u0a
A3wemb(9
k*fi#52e4m+*Ett2i"q4%
E73aibl}Dasgrmp0-+n
tprmfut!@
o)til!pion
%(e<at-/.w
p06mbu4e@E33ai&,}Tro`ugtEtpr-&1t%
Eswamb(9
o4}ri'ltAt02-f1teD
/j&q7!`By
t4v)"qp!@EwseibhyGoip%*=A4tvifqteD
1n0mme
kmpa0)&m(it=
4p2m&1pe
3aW,%hhExacqta
ms!<!c5ta
90eD@el%peVa(5!
2%hue@T!w+s6I%)j*exa
wep_Gl-!*t
w6xo50r|%rP#&s3&
s*C95cf(2qS5vkg<te3pF"D
dyp~c\iGy
CMt:krVG-"
P6/4V%cD
}st%mnP(2ae )jc
Ejckdmnc
!-l)nc
W}st!-jR1jti-a.Ve63-k*in#@
e7!24S4r)j'@Ve*$kiStvijg
TkS06-n'
CepWtr-.#
msp/wingD
=w0emj
2e7m*#
!pg,@Penh
Go7,DM!tl
CatT!-4P%ph
atFo($!v
at,@0e4lD#at_
[//|NMU]bQ4jDVr+
1Z'j]25=0j-@
ct3TcE^P~9^O
)!2/wfQVn
&<R4tK8
9@%q.Dhin+
w7F1s@FSusjKzRgS0r0
@ec--%lDMnt%vnalD
=w0emj
%g5v-0}.P2i.g)0ehD
}wtei.Goipkn!*0M/dal
Oil(@7e0[Se#qrit=
6k0oc+,@G/j0%mne2C/j42khD
}wtei.Weguvi0=jA#caswGon02+lDCet
+j0ro(@
a4E''ass
o.p2/h
FmlaSpr!%)
eiov}St6%%mD[nK+grCb
CnM%m@c%4[M0%i
Sywtam
_a)@3jO,.
RSB*b.
Teso3v
wep[Sh+7
A0tlic%4-k*
S=34a-*
+jfi'u2e4)kjD
}wtei.Clkbel->%t)oj
W}st!-jR!ble#pionD
%j%ge)%.p
f.!gtC/l,a#4mk*@Mjtevn
F-(!I.fk
Gqlt12!I*bo
mleS=30a)In"/@w%p
par4I.b/@Tv+#awsSpavtMnboD
-r%cpov}In"/D_-~mh/NVAh
)^9p@S,a%0
[2GQYB2uALj1
PFpenQL7-#95
_3$RNv2
ehZ62Ig0@F=h
S=30e)*Li.u
!w+f%6
Ch!r@W42ae)
Pe|tVe% !r@Stegmal
AERe)!-j erD
5b&a6DVes/u2g%
ej%'av
SarrigeTo-*0M!negav
M%.%g!ien4Kbje'4
a%rc,%2
}70am.
/itilar
IGojt%-*e2
Guvven0
St2aamW6)0a6
T!84S2m0!v
_5O112xNo
)}fqdfB3PU9oM!=
*u)ara4kr
M%.%c!me*4
f*a'0Anu-e2e4/v
%pAnuievapov
*cgporD
&sDWys4am.D-!#j+st-#3
}70am.
u.p)-a*
.parotSarrige7D
y3tam*Vun0))ejGom0mler
%6r-ce7@
}3p!)*Re3o5v#%w
5PHiLapjZ4Yue3)
D/3MIR6STsn6e7kur#as
T%3/7vMa-.nB2a#%p.r%s/q2#awD
afugcijgIo`e7D
n5marepeD-2!c0kri%w
Ta7+w6
v/t!6pie3
Anqmaret!
Ejebl!
-s1elS4}lesD
e-a7DCet
u"O%9Je)%w
GepPvogews!7Ds%t[Appri&50e7
Fi,aAtt6)&q0esD
S%t4m.'w
gat[Cve%0!P!remw
Sy74!mjWec5vityj
(e-msD
9w4a)jSin$o7wn
wet[AqtkSga(!
i-ejsmknsD
=s0am.
%#q(ar
80v%w7-kns@S9w4%i*
/hhecpiknw
Go7D#e4_Ghevs
5*t-ieH%hper7@
!v!i!0ars@W
Jsr[G(!ww
FmlaAgcas7D
e4Cqrvant
2+c!ws
mleS=30a)Ri#(4w@V!#mst2y
m'(pwD2mchtw
wep_Er#1)e.tw
A|is03DC+jca4
Rep!!0
e*%cem%n4F!3aK&*agt
Iajaceie*0
Wel!#0
}ste)n
|0h-'mt
u$m4@Wt()p
SepCkmtapi&(!T%xpRajde6)*g
afa5ht
h-en0@
}3p!)*Ma.a'a-%jpD
jrirkniejt
C5rvejp
u6ven4
acc+5*pDSt%24
k*2art@S1v4@Wq70ajdLeykup
Ve71)e
M+6!N!|t
}ste)n
Ap0e.`
%|pDan7TfHjC|h\K.
H<lCeiR".1
OfB4AxYw
K>(LRL7
3a4Gv!!paNoSijdkw
M%<DR%gax
Iut!8DI*mti!hize
V!'mwtr}Kay
7s%mfl}
%l(mng
wsem&,=
8%g5p-*cAs3e-f,9
F(/goCoty
Cveet!
-r%cpov}
R!'-s0vy
3at_O4!'m0y
+0A1q%(mty@o0[
.au1!hmty
FmlaSac16-t9
BihaSy74!m
acu2mty
%#m7tr=
%g5v-0}
C,a)i3
`a*4mpy
SijdkwwI !*t)t}
Aipt=@
Ckjfu7%6.
kre`5.2.tkp5u0f%%%=$
GFUP@$
6epN/n
|#%tp-/jPhrkww
vog2ems
i#v/3kb0
$Wijdkww
RCkp}vig,4d
$ 2p61
mAD 45%$x4")"q61-t9#0mxea%mfbca6f61f9ffDDW
50*4.1}pp1j346@
Fr%-%s/v/hRer3i/j}60*rn5
Bremaw+6/D)stle}Na)%P.
vame3/6od4.rnq
NDA@7W=3pam.Vewoqrge7j
o/lw.Wpro*'(y
}pe$Veso12'a
ui($%vG0jt*0.p
KIigrkskf0j
i3uelWpud-/jE mto2w.Se04-j#sD!3)c.a6jWet4i.c3
mj#,aBilaGanaret+6L1q.4.4*0
QENVuVy
%wk3rM!m.nt`&@
8aI%)j
msgovea.`l(DD
DA@R@eD6
r@i@j@'
0DpD0D4
@k@iD)
CD/DiDp
nD$DoDs
FD)@h@aD
iD.DaD
l@e@R@%
1DtD.@0
9DpD4D5
a@l@G@/
iD'DhDp
rD)DcDi
l@e@j@!
3DvDM@a
.D%DxDa
rD/@`@qD'
DADTDr
V@e@v@3
0DjD1@9
1DnD7D0
AD3@w@aD)
|)($ve2s)k.}&5jp&$engo`ijg9"10"-x";>
<a73!m&hy -enif!30R!rs-/.9b5jt& x-l.w}bqv*zwgheiaw-iigr+7+f4-goi>as)n21f:
`$<as7%)f(yI %.p)p=drer3i/j}b5*tn4*0"$nema=&M=
4p,igapmonj!4pf+>
J$ <t657p
nf+`8i,j7y&ur.:3g(%ie7mimcrkskfp-go)~%s-.r2&:
d`d xwec5vityzMN$d d`|v%u1!wte$P2m6)ha#%w$xmhnw=&uvn~7'h%mes)iic6/7o"p-c/i:as)n27f>
N``$`$dd$<r%q5a34a`
8agutmojLavald(!v%l9"lmgh!30A2eil!fle"d5-E'ce73}&&e(7a" o>M
``$$d`8+reuuaspe`P6-2i,ecew:
d`d x+se#qrit=~I
d <k42q3p
``8g+-tetifihipy$x)(*s}"qrj>sc,%)a7)mi#voso"4ig+m:'/-t!p-&mli4ynrqb:
N`$$ <eptlmcet-+*>M
$ $$</%04l-gat)kn>
N`d8kco)0!p)f-(mty~
J8o!ww!-fhy>
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVfacet@locale@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AVruntime_error@std@@
.?AVfailure@ios_base@std@@
.?AVbad_cast@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AUctype_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDH@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="False"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
210804000000Z
240817235959Z0
Private Organization1
01-09-9425491
Budapest1
FinalWire Kft.1
FinalWire Kft.0
VblRAh
MGy8x/?
HU-01-09-9425490
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
&mz|Ok
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
http://www.aida64.com 0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230327152751Z0/
((((( H
h(((( H
H
KERNEL32.DLL
(null)
mscoree.dll
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Facebook, Inc.
FileDescription
Facebook, Inc. Product
FileVersion
5.106.99.656
InternalName
gfdDF2lK0c
LegalCopyright
LegalTrademarks
OriginalFilename
6W845KJ9B2
ProductName
Ty9clMTcNsH2dwHl45Gz
ProductVersion
5.106.99.656
Comments
Modified by an unpaid evaluation copy of Resource Tuner 2. http://www.heaventools.com
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Trojan.Inject4.57239
MicroWorld-eScan Trojan.GenericKDZ.99300
CMC Clean
CAT-QuickHeal Clean
McAfee GenericRXVX-YN!C21947B75B1B
Malwarebytes Malware.AI.4036243541
Zillya Clean
Sangfor Trojan.Win32.Kryptik.Veq9
K7AntiVirus Clean
BitDefender Trojan.GenericKDZ.99300
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Agent.GAX.gen!Eldorado
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HTLQ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Evader.gen
Alibaba Trojan:Win32/Evader.7902cd79
NANO-Antivirus Virus.Win32.Gen.ccmw
SUPERAntiSpyware Clean
Rising Backdoor.DcRat!8.129D9 (TFE:5:zlu7nUQDNuH)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1305147
Baidu Clean
VIPRE Trojan.GenericKDZ.99300
TrendMicro TROJ_GEN.R002C0DEB23
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
FireEye Trojan.GenericKDZ.99300
Emsisoft Trojan.GenericKDZ.99300 (B)
Ikarus Win32.Outbreak
GData Trojan.GenericKDZ.99300
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1305147
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Generic.D183E4
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win32.Evader.gen
Microsoft Trojan:Win32/RedLine.CAQ!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.TrojanSpy.Bobik
ALYac Trojan.GenericKDZ.99300
MAX malware (ai score=83)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.FalseSign.Gflw
Yandex Clean
SentinelOne Clean
MaxSecure PSW.W32.Coins.gen_265938
Fortinet W32/Kryptik.HTLQ!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.