Static | ZeroBOX

PE Compile Time

2022-05-02 20:50:34

PDB Path

C:\Users\谷堕\Desktop\2022远程管理gfi\cangku\WinOsClientProject\Release\上线模块.pdb

PE Imphash

3cc284cd2dd655170243627a984cee7b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00029586 0x00029600 6.64374827266
.rdata 0x0002b000 0x0000b0dc 0x0000b200 5.86299865944
.data 0x00037000 0x00009f94 0x00005200 2.80338159632
.rsrc 0x00041000 0x000001b4 0x00000200 5.11205617833
.reloc 0x00042000 0x000057ee 0x00005800 3.74287901364

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00041058 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x1002b050 Process32FirstW
0x1002b054 Process32NextW
0x1002b058 CloseHandle
0x1002b05c LoadLibraryW
0x1002b060 GetProcAddress
0x1002b064 CreateFileW
0x1002b068 GetCurrentProcess
0x1002b06c lstrcpyW
0x1002b070 GetLastError
0x1002b074 HeapAlloc
0x1002b078 GetProcessHeap
0x1002b07c HeapFree
0x1002b080 OpenProcess
0x1002b084 GetDriveTypeW
0x1002b088 GetDiskFreeSpaceExW
0x1002b08c GlobalMemoryStatusEx
0x1002b090 GetSystemInfo
0x1002b094 FreeLibrary
0x1002b098 GetModuleFileNameW
0x1002b09c GetCommandLineW
0x1002b0a0 GetStartupInfoW
0x1002b0a4 CreateProcessW
0x1002b0a8 ExitProcess
0x1002b0ac WideCharToMultiByte
0x1002b0b0 CreateFileA
0x1002b0b4 DeviceIoControl
0x1002b0bc CreateEventW
0x1002b0c0 SetEvent
0x1002b0c4 ResetEvent
0x1002b0cc WaitForSingleObject
0x1002b0d0 InterlockedExchange
0x1002b0d4 WriteFile
0x1002b0dc CopyFileW
0x1002b0e0 GetFileAttributesW
0x1002b0e4 GetConsoleWindow
0x1002b0e8 FormatMessageW
0x1002b0ec SetLastError
0x1002b0f0 VirtualProtect
0x1002b0f4 IsBadReadPtr
0x1002b0f8 LoadLibraryA
0x1002b0fc GetNativeSystemInfo
0x1002b100 SetErrorMode
0x1002b108 CreateThread
0x1002b10c CreateMutexW
0x1002b110 GetFileSize
0x1002b114 DeleteFileW
0x1002b118 ReleaseMutex
0x1002b11c SetFilePointer
0x1002b120 RaiseException
0x1002b12c GetCurrentThreadId
0x1002b130 LocalFree
0x1002b134 ReadFile
0x1002b138 LCMapStringW
0x1002b13c FlushFileBuffers
0x1002b140 SetStdHandle
0x1002b144 WriteConsoleW
0x1002b148 GetModuleHandleW
0x1002b14c lstrcmpW
0x1002b150 GetTickCount
0x1002b154 Sleep
0x1002b158 lstrcatW
0x1002b15c GetSystemDirectoryW
0x1002b160 GetLocaleInfoW
0x1002b164 GetLocalTime
0x1002b168 GetCurrentProcessId
0x1002b16c MultiByteToWideChar
0x1002b170 lstrlenW
0x1002b174 InterlockedDecrement
0x1002b178 VirtualAlloc
0x1002b17c LeaveCriticalSection
0x1002b180 EnterCriticalSection
0x1002b184 DeleteCriticalSection
0x1002b188 VirtualFree
0x1002b190 GetEnvironmentStringsW
0x1002b198 GetModuleFileNameA
0x1002b19c HeapCreate
0x1002b1a0 HeapDestroy
0x1002b1a4 CreateEventA
0x1002b1ac CreateWaitableTimerW
0x1002b1b0 GetFileType
0x1002b1b4 SetHandleCount
0x1002b1b8 IsValidCodePage
0x1002b1bc GetOEMCP
0x1002b1c0 GetACP
0x1002b1c4 GetCPInfo
0x1002b1c8 GetStringTypeW
0x1002b1cc TlsFree
0x1002b1d0 TlsSetValue
0x1002b1d4 TlsGetValue
0x1002b1d8 TlsAlloc
0x1002b1dc HeapSize
0x1002b1e0 GetStdHandle
0x1002b1e4 GetConsoleMode
0x1002b1e8 GetConsoleCP
0x1002b1f0 IsDebuggerPresent
0x1002b1f8 TerminateProcess
0x1002b1fc RtlUnwind
0x1002b200 GetCommandLineA
0x1002b204 HeapReAlloc
0x1002b208 ExitThread
0x1002b20c EncodePointer
0x1002b210 DecodePointer
0x1002b218 CancelWaitableTimer
0x1002b21c SetWaitableTimer
0x1002b220 lstrlenA
0x1002b224 UnmapViewOfFile
0x1002b228 SwitchToThread
0x1002b22c CreateFileMappingW
0x1002b230 MapViewOfFileEx
0x1002b234 InterlockedIncrement
Library USER32.dll:
0x1002b26c GetForegroundWindow
0x1002b270 GetMonitorInfoW
0x1002b274 GetWindowTextW
0x1002b27c PeekMessageW
0x1002b280 TranslateMessage
0x1002b284 DispatchMessageW
0x1002b288 GetLastInputInfo
0x1002b28c SendMessageW
0x1002b290 FindWindowA
0x1002b294 GetWindowTextA
0x1002b298 GetWindow
0x1002b29c GetClassNameA
0x1002b2a0 OpenWindowStationW
0x1002b2a8 IsWindow
0x1002b2ac EnumDisplayMonitors
0x1002b2b0 wsprintfW
Library ADVAPI32.dll:
0x1002b000 OpenProcessToken
0x1002b004 RegSetValueExW
0x1002b008 RegCreateKeyW
0x1002b00c RegDeleteValueW
0x1002b010 RegQueryValueExW
0x1002b014 RegOpenKeyExW
0x1002b018 LookupAccountSidW
0x1002b01c GetTokenInformation
0x1002b020 GetCurrentHwProfileW
0x1002b024 FreeSid
0x1002b028 CheckTokenMembership
0x1002b030 RegCloseKey
0x1002b034 RegEnumKeyExA
0x1002b038 RegQueryInfoKeyW
0x1002b03c RegOpenKeyExA
Library SHELL32.dll:
0x1002b254 SHGetFolderPathW
Library ole32.dll:
0x1002b344 CoUninitialize
0x1002b348 CoCreateInstance
0x1002b34c CoInitialize
Library OLEAUT32.dll:
0x1002b244 SysFreeString
0x1002b248 SysStringLen
0x1002b24c SysAllocString
Library WS2_32.dll:
0x1002b2cc getsockname
0x1002b2d0 WSAAddressToStringW
0x1002b2d4 WSASetLastError
0x1002b2d8 WSAStringToAddressW
0x1002b2dc closesocket
0x1002b2e0 send
0x1002b2e4 setsockopt
0x1002b2e8 WSAIoctl
0x1002b2ec htons
0x1002b2f0 ntohs
0x1002b2f4 WSAGetLastError
0x1002b2f8 inet_ntoa
0x1002b2fc gethostbyname
0x1002b300 gethostname
0x1002b304 freeaddrinfo
0x1002b308 getaddrinfo
0x1002b30c WSAStartup
0x1002b310 WSAResetEvent
0x1002b314 WSAEventSelect
0x1002b318 WSACleanup
0x1002b31c bind
0x1002b320 connect
0x1002b324 recv
0x1002b328 WSACloseEvent
0x1002b32c WSACreateEvent
0x1002b330 socket
0x1002b334 WSAEnumNetworkEvents
0x1002b33c shutdown
Library SHLWAPI.dll:
0x1002b25c StrChrW
0x1002b260 StrPBrkW
0x1002b264 PathIsDirectoryA
Library NETAPI32.dll:
0x1002b23c NetWkstaGetInfo
Library DINPUT8.dll:
0x1002b044 DirectInput8Create
Library WINMM.dll:
0x1002b2b8 timeGetDevCaps
0x1002b2bc timeEndPeriod
0x1002b2c0 timeBeginPeriod
0x1002b2c4 timeGetTime

Exports

Ordinal Address Name
1 0x10009080 GetInstallDetailsPayload
2 0x100090e0 SignalChromeElf
3 0x100090d0 Version
4 0x10009020 load
5 0x10009080 run
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
L$t_^3
RPQhp(
Rjdh,,
SSPh0V
QSFVhpm
SVWh2u
tkHt@H
D$ QRP
D$ QRP
)_p)_l)_\
^l+^\+
Nlf+Np
Vlf+Vd
O(9O$u
^(9^$u
~49F4u
w@;N(w;
ND;H s
ND;H(s
Nl;N`sN
Fl9Flr
@PAQBR
t!VFVS
Nd;N<sH
C@9CDv
+^tx<=X
+S(xM@
S4;V|r
+xT_^x
Nd;N<r
Vd;V<sM
Fd;F<s
~<WRQP
9^$uh
9^$u/h
u<;~ u0
u)jAXf;
QQSVWd
tWItHIt9It
^SSSSS
uTVWhK
j@j ^V
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
tUjXXf;
ou-j8Xf;
UVVVVV
HHtXHHt
?If90t
URPQQh
t"SS9] u
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
Q1.2.11
deflate 1.2.11 Copyright 1995-2017 Jean-loup Gailly and Mark Adler
1.2.11
incorrect length check
incorrect data check
invalid distance too far back
invalid distance code
invalid literal/length code
invalid distances set
invalid literal/lengths set
invalid bit length repeat
invalid code -- missing end-of-block
too many length or distance symbols
invalid code lengths set
invalid stored block lengths
invalid block type
header crc mismatch
unknown header flags set
incorrect header check
invalid window size
unknown compression method
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
need dictionary
inflate 1.2.11 Copyright 1995-2017 Mark Adler
bad allocation
CTcpPackClientT<class CTcpClient>::CheckParams
CreateFileTransactedW
[RO] %ld bytes
input wins: %lu
input probe
input psh: sn=%lu ts=%lu
input ack: sn=%lu rtt=%ld rto=%ld
[RI] %d bytes
recv sn=%lu
%s --> Error: %d, EC: %d
<C-CNNID: %Iu> OnReceive() event return 'HR_ERROR', connection will be closed !
<C-CNNID: %Iu> OnSend() event should not return 'HR_ERROR' !!
---------------> Client Worker Thread 0x%08X stoped <---------------
---------------> Client Worker Thread 0x%08X started <---------------
<C-CNNID: %Iu> send 0 bytes (detect package)
<C-CNNID: %Iu> recv 0 bytes (detect package)
Unknown exception
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
(null)
`h````
xpxxxx
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
`h`hhh
xppwpp
1#QNAN
1#SNAN
generic
iostream
system
iostream stream error
Visual C++ CRT: Not enough memory to complete call to strerror.
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
>f:yhV:
>f:yhV:
SHGetSpecialFolderPathW
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
CTXOPConntion_Class
Software\Tencent\Plugin\VAS
GetNativeSystemInfo
RtlGetNtVersionNumbers
RtlGetVersion
C:\Program Files\VMware\VMware Tools\
\\.\PhysicalDrive0
invalid string position
string too long
0123456789abcdef
RegCreateKeyExW
RegSetValueExW
RegDeleteKeyW
RegDeleteValueW
RegEnumValueW
RegEnumKeyExW
g>N1Y%
InternetOpenW
InternetOpenUrlW
InternetReadFile
InternetCloseHandle
vector<T> too long
C:\Users\
\Desktop\2022
gfi\cangku\WinOsClientProject\Release\
InitializeCriticalSection
VirtualFree
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
VirtualAlloc
InterlockedDecrement
lstrlenW
MultiByteToWideChar
GetCurrentProcessId
GetLocalTime
GetLocaleInfoW
GetSystemDirectoryW
lstrcatW
GetTickCount
lstrcmpW
GetModuleHandleW
GetConsoleWindow
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
CloseHandle
LoadLibraryW
GetProcAddress
CreateFileW
GetCurrentProcess
lstrcpyW
GetLastError
HeapAlloc
GetProcessHeap
HeapFree
OpenProcess
GetDriveTypeW
GetDiskFreeSpaceExW
GlobalMemoryStatusEx
GetSystemInfo
FreeLibrary
GetModuleFileNameW
GetCommandLineW
GetStartupInfoW
CreateProcessW
ExitProcess
WideCharToMultiByte
CreateFileA
DeviceIoControl
QueryPerformanceFrequency
CreateEventW
SetEvent
ResetEvent
QueryPerformanceCounter
WaitForSingleObject
InterlockedExchange
WriteFile
ExpandEnvironmentStringsW
CopyFileW
GetFileAttributesW
CreateEventA
FormatMessageW
SetLastError
VirtualProtect
IsBadReadPtr
LoadLibraryA
GetNativeSystemInfo
SetErrorMode
SetUnhandledExceptionFilter
CreateThread
CreateMutexW
GetFileSize
DeleteFileW
ReleaseMutex
SetFilePointer
KERNEL32.dll
wsprintfW
GetForegroundWindow
GetWindowTextW
GetMonitorInfoW
EnumDisplayMonitors
GetLastInputInfo
SendMessageW
FindWindowA
GetWindowTextA
GetWindow
GetClassNameA
OpenWindowStationW
SetProcessWindowStation
IsWindow
USER32.dll
GetCurrentHwProfileW
RegOpenKeyExA
RegQueryInfoKeyW
RegEnumKeyExA
RegCloseKey
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
OpenProcessToken
GetTokenInformation
LookupAccountSidW
RegOpenKeyExW
RegQueryValueExW
RegDeleteValueW
RegCreateKeyW
RegSetValueExW
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
OLEAUT32.dll
WS2_32.dll
WSAIoctl
WSAStringToAddressW
WSAAddressToStringW
freeaddrinfo
getaddrinfo
WSAResetEvent
WSAEventSelect
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAWaitForMultipleEvents
PathIsDirectoryA
StrChrW
StrPBrkW
SHLWAPI.dll
NetWkstaGetInfo
NETAPI32.dll
DirectInput8Create
DINPUT8.dll
timeGetTime
timeBeginPeriod
timeGetDevCaps
timeEndPeriod
WINMM.dll
InterlockedCompareExchange
RaiseException
InitializeCriticalSectionAndSpinCount
GetCurrentThreadId
HeapCreate
HeapDestroy
CreateWaitableTimerW
InterlockedIncrement
MapViewOfFileEx
CreateFileMappingW
SwitchToThread
UnmapViewOfFile
lstrlenA
SetWaitableTimer
CancelWaitableTimer
TryEnterCriticalSection
DecodePointer
EncodePointer
ExitThread
HeapReAlloc
GetCommandLineA
RtlUnwind
TerminateProcess
UnhandledExceptionFilter
IsDebuggerPresent
IsProcessorFeaturePresent
GetConsoleCP
GetConsoleMode
GetStdHandle
HeapSize
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStringTypeW
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
SetHandleCount
GetFileType
GetModuleFileNameA
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetSystemTimeAsFileTime
WriteConsoleW
SetStdHandle
FlushFileBuffers
LCMapStringW
ReadFile
LocalFree
DispatchMessageW
TranslateMessage
PeekMessageW
MsgWaitForMultipleObjects
GetInstallDetailsPayload
SignalChromeElf
Version
ngyixiugaidaochuhanshu
.?AVIClient@@
.?AVIArqClient@@
.?AVIPackClient@@
.?AVCAtlException@ATL@@
.?AVIUdpClient@@
.?AV?$CArqSessionT@VCUdpArqClient@@V1@@@
.?AVITcpClient@@
.?AVCTcpClient@@
.?AVCUdpClient@@
.?AVCUdpArqClient@@
.?AV?$CTcpPackClientT@VCTcpClient@@@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AV_com_error@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVCBuffer@@
.?AVexception@std@@
xiugaishiyong
mainsetting
.?AVbad_alloc@std@@
.?AV?$CHPObjectPtr@V?$DualInterface@VIPackClient@@VITcpClient@@@@VITcpClientListener@@UTcpPackClient_Creator@@@@
.?AVCTcpSocket@@
.?AVCTcpClientListener@@
.?AV?$ISocketListenerT@VITcpClient@@@@
.?AV?$IClientListenerT@VITcpClient@@@@
.?AVITcpClientListener@@
.?AVISocketBase@@
.?AVCManager@@
.?AVCKernelManager@@
.?AV?$CHPObjectPtr@V?$DualInterface@VIArqClient@@VIUdpClient@@@@VIUdpClientListener@@UUdpArqClient_Creator@@@@
.?AVCUdpSocket@@
.?AVCUdpClientListener@@
.?AV?$ISocketListenerT@VIUdpClient@@@@
.?AV?$IClientListenerT@VIUdpClient@@@@
.?AVIUdpClientListener@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0:1n1t1
363D3~3
324H4~4
5 5:5m5
7)7.7R7i7r7y7
83888t8{8
8"9B9O9k9r9
9;:L:h:
1,161{1
3&3+3=3B3H3R3j3
494B4J4T4
9$:2:\:
;#;;;B;
<6<H<Z<i<
0"0/0E0
10191J1[1b1
2"3?3T3m3
3&444B4L4p4z4
5%505a5
6H6a6g6q6
7C7p7v7
8'8+81858;8A8%9
:;;F;o;H<S<q<
:U;`;v;
='=;=N=l=
=->=>`>
667Z7`7
8D8J8O8V8j8o8
939?9X9r9
::3:M:[:o:
;&;0;6;];g;l;x;};
> ?%?*?~?
0 0$0(0,0
141?1I1[1d1j1p1
2*222h2|2
3*353<3
3#4.4;4X4_4x4
5)646L6_6d6
899r9y9
:(:.:4:9:S:a:u:
<<$<+<d<i<{<
=%=3=F=
0d0n0}0
7%868[8
9$9A9r9
: :3:;:[:b:i:p:w:
>-?I?l?
1L1R1_122I2Z3
696H6l6{6
687i7{7
8J8Q8Y8_8e8|8
879<9B9J9T9a9h9u9
:+:2:?:I:S:[:a:}:
;(;/;>;D;R;W;h;
<2<I<T<a<g<~<
=,=B=w=}=
>#>V>[>n>|>
>%?Q?r?
0/090C0K0Y0j0q0
1%171F1W1\1a1g1l1v1~1
2'212=2V2
3:3M3[3e3k3q3
4/454Z4g4t4
55P5V5f5w5~5
6G6@7Y;h;u;
$3M3\3
2 2$2(2,202
1,464F4
7'797`;e;F>{>
?,?>?J?W?q?~?
0.0@0L0Y0
==+=\=
>%>R>d>
>&?5?L?^?
;/;=;I;
1Q1202W2
5f6v667E7\7c7
= >+>S>X>c>
?"?)?0?7?>?E?L?S?Z?`?d?h?l?p?t?x?|?
0"0+020
6#727S7
;;;J<N=
> ?;?W?
616A6h6
9S:f:s:{:
>>)>V>f>
>*?4?V?e?
3+4V4e4
;';6;C;`;
;-<8<h<
>(>?>J>_>
40\0{0
0&161T1m1
4-474f4v4
5=5G5j566H6u6
:!;W;z;
3 404A4H4c4v4
3%3.3z3
4/4M4T4X4\4`4d4h4l4p4
425=5X5_5d5h5l5
6V6\6`6d6h6K7
9.9\90<6<H<
<;=A=m=t=|=
>,>1>6>M>
>,?3?9?
52;2G2~2
:K:c:k:t:
;4;P;h;
=/=M=T=X=\=`=d=h=l=p=
=2>=>X>_>d>h>l>
?V?\?`?d?h?
6"6(6,61676;6A6E6K6O6U6Y6
:#:*:1:8:?:F:N:V:^:j:s:x:~:
<'<3<?<K<s<|<
=$=0=9=B=
4(454s4z4
8)9I99:b:
2)2M2_2m2
2!3P3a3~3
7Y7q7{7
9 9,9c9l9x9
:U:[:g:m:v:}:
;/;:;?;Q;[;`;|;
;4<><d<k<
<+=2=C=I=T=^=d=p=v=
>&>;>a>
0d0t0z0
1 1'1,141=1I1N1S1Y1]1c1h1n1s1
8#8-8;8D8N8
8(9]9p9
:I;U;h;z;
<D<m<~<
>2?L?]?
0*0o0v0
11=1a1
2/2T2_2n2
6)6.6O6T6
8P8c819R:K;
2#2:4.5z5
1"121a1g1o1
=&=,=5=H=l=
> >E>Q>\?
354\5>6R6v6
181Y1l1
1282T2
2(3H3~3
4(454:4H4
55=5Q5W5
66'6-676=6G6M6W6`6k6p6y6
?/?U?g?y?
4/5=7H9w9
@0Q2X2
2}3q4y4*5
6J7P7^7
0?4C4G4K4O4S4W4[4_4c4g4k4x4:5b5r5
>-?G?x?
0B0J0T0d0p0v0
3+3;3K3T3[3a3h3t3
5!6'626N6
1121E1`1e1j1
252P2U2Z2
2%3@3E3J3s3}3
4%414D4N4X4q4|4
55)535>5B5I5M5T5X5^5h5r5}5
X3\3`3d3h3l3p3t3x3|3
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
7T7X7\7
1$1,141<1D1L1T1\1
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?
\8`8d8h8l8p8t8x8|8
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
=`?d?h?|?
242D2H2X2\2d2|2
343D3H3X3\3`3d3l3
4,404H4L4d4h4
5$54585H5L5\5`5h5
6,6<6@6P6T6X6\6d6|6
7$7(787<7@7H7`7p7t7
8 8$8,8D8T8X8h8l8p8x8
9 90949D9H9X9\9`9d9h9l9p9x9
:$:(:,:0:4:<:T:d:h:l:p:x:
; ;$;,;D;T;X;h;l;p;x;
< <0<4<D<H<X<\<l<p<t<x<|<
=$=(=8=<=@=D=H=P=h=x=|=
?$?D?L?X?x?
0<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
282D2d2l2t2
3,383X3d3
4$4D4P4p4x4
5@5`5|5
6 6,6H6h6
787@7D7\7`7p7
8 8(80888<8D8X8t8x8
989X9x9
:(:0:8:@:D:H:P:d:l:t:|:
; ;@;`;h;t;
;4<D<X<l<x<
=$=,=4=@=`=t=
>(>0>8>\>
040P0p0
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<
=4=@=D=H=L=P=T=
>$>,>4><>D>L>T>\>d>l>t>|>
P0T0`0d0h0l0p0t0x0|0
505T5x5
7 707@7P7`7p7
8 808@8P8`8p8
9 909@9P9`9p9
: :0:@:P:`:p:
; ;0;@;P;`;p;
< <0<@<P<`<p<
= =0=@=P=`=p=
> >0>@>P>`>p>
? ?0?@?P?`?p?
0 000@0P0`0p0
1 101@1P1`1p1
2 202@2P2`2p2
3 303@3P3`3p3
4 404@4P4`4p4
5 505@5P5`5p5
6 606@6P6`6p6
7 7$7(7,7074787<7@7D7H7L7T7l7
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
jjjjjj
jjjjjj
jjjjjj
#+3;CScs
%d.%d.%d.%d%c
UNKNOWN ERROR
SSL environment not ready
Send Data Fail
Process Data Error
Network Error
Connect to Server Fail
Attach SOCKET to IOCP Fail
Create Detector Thread Fail
Create Worker Thread Fail
Create IOCP Fail
Listen SOCKET Fail
Prepare SOCKET Fail
Bind SOCKET Fail
Create SOCKET Fail
Invalid Parameter
Illegal State
SUCCESS
wruntime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
mscoree.dll
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
(null)
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
UnThreat
UnThreat.exe
K7TSecurity.exe
Ad-watch
ad-watch.exe
PSafeSysTray.exe
BitDefender
vsserv.exe
remupd.exe
rtvscan.exe
ashDisp.exe
avcenter.exe
TMBMSRV.exe
knsdtray.exe
egui.exe
Mcshield.exe
avp.exe
F-Secure
f-secure.exe
avgwdsvc.exe
AYAgent.aye
V3Svc.exe
Outpost
acs.exe
DR.WEB
SPIDer.exe
Comodo
cfp.exe
mssecess.exe
QuickHeal
QUHLPSVC.EXE
RavMonD.exe
KvMonXP.exe
baiduSafeTray.exe
BaiduSd.exe
HipsTray.exe
QQPCRTP.exe
KSafeTray.exe
kxetray.exe
360sd.exe
ZhuDongFangYu.exe
360tray.exe
360Tray.exe
360Safe.exe
ProcessorNameString
HARDWARE\DESCRIPTION\System\CentralProcessor\0
BEIZHU
%4d.%2d.%2d-%2d:%2d:%2d
%s %d %d %d %d
%s %d %d %d %d
%4d.%2d.%2d-%2d:%2d:%2d
GFIRestart32.exe
Shell32.dll
W%s\%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ADVAPI32.dll
FriendlyName
NONE_MAPPED
%d Gb
%d Gb
%d Gb
%d Gb
DriverDesc
SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
okernel32.dll
ntdll.dll
%d.%d.%d
XP-sp1
XP-sp2
XP-sp3
Vista-sp1
Vista-sp2
Win7-sp1
2008R2
Win8R1
2012R2
%s %d.%d.%d.%d.%d
VMwareService.exe
VMwareTray.exe
VMwareUser.exe
localhost
WORKGROUP
%s--%s
%s\shell\open\command
WinSta0\Default
wininet.dll
MSIE 6.0
winsta0
www.baidu.com
127.0.0.1
\sys.key
:]%d-%d-%d %d:%d:%d
@[esc]
[enter]
[lctrl]
[lshift]
[rshift]
[lalt]
[numlock]
[scrolllock]
[enter]
[rctrl]
[ralt]
[home]
[pagup]
[pagdn]
[lwin]
[rwin]
712.802.431.391
654321
712.802.431.391
654321
712.802.431.391
654321
2023. 6
127.0.0.1
No antivirus signatures available.
No IRMA results available.