Static | ZeroBOX

PE Compile Time

2005-08-28 10:29:11

PDB Path

cmd.pdb

PE Imphash

d73e39dab3c8b57aa408073d01254964

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003463d 0x00035000 6.31433113947
.rdata 0x00036000 0x00009602 0x0000a000 4.76669497736
.data 0x00040000 0x0001bde8 0x00001000 0.522172462209
.pdata 0x0005c000 0x00002568 0x00003000 4.64991745546
.didat 0x0005f000 0x000000a8 0x00001000 0.214483481123
.rsrc 0x00060000 0x000084f8 0x00009000 4.12100853208
.reloc 0x00069000 0x000001d0 0x00001000 0.993465635179

Resources

Name Offset Size Language Sub-language File type
MUI 0x00068420 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00067b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00068000 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00068098 0x00000388 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00060350 0x00000428 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library api-ms-win-crt-string-l1-1-0.dll:
0x1400373a0 wcscmp
0x1400373a8 wcsncmp
0x1400373b0 memset
0x1400373b8 wcsspn
Library api-ms-win-crt-time-l1-1-0.dll:
0x1400373c8 _time32
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140037378 _initterm
0x140037380 _initterm_e
0x140037390 _c_exit
Library api-ms-win-crt-private-l1-1-0.dll:
0x1400370f8 _o__get_osfhandle
0x140037100 _o__getch
0x140037120 _o__open_osfhandle
0x140037128 _o__pclose
0x140037130 _o__pipe
0x140037138 _o__purecall
0x140037148 _o__seh_filter_exe
0x140037150 _o__set_app_type
0x140037158 _o__set_fmode
0x140037160 _o__set_new_mode
0x140037168 _o__setmode
0x140037170 _o__tell
0x140037178 _o__ultoa
0x140037180 _o__ultoa_s
0x140037188 __intrinsic_setjmp
0x140037190 _o__wcsicmp
0x140037198 _o__wcslwr
0x1400371a0 _o__wcsnicmp
0x1400371a8 _o__wcsupr
0x1400371b0 _o__wpopen
0x1400371b8 _o__wtol
0x1400371c0 _o_calloc
0x1400371c8 _o_exit
0x1400371d0 _o_feof
0x1400371d8 _o_ferror
0x1400371e0 _o_fflush
0x1400371e8 _o_fgets
0x1400371f0 _o_free
0x1400371f8 _o_iswalpha
0x140037200 _o_iswdigit
0x140037208 _o_iswspace
0x140037210 _o_iswxdigit
0x140037218 _o_malloc
0x140037220 _o_qsort
0x140037228 _o_rand
0x140037230 _o_realloc
0x140037238 _o_setlocale
0x140037240 _o_srand
0x140037248 _o_terminate
0x140037250 _o_towlower
0x140037258 _o_towupper
0x140037260 _o_wcstol
0x140037268 _o_wcstoul
0x140037270 __CxxFrameHandler3
0x140037278 __current_exception
0x140037288 _CxxThrowException
0x140037290 _o__exit
0x140037298 _o__errno
0x1400372a0 _o__dup2
0x1400372a8 _o__dup
0x1400372b0 _o__crt_atexit
0x1400372c0 _o__configthreadlocale
0x1400372c8 _o__close
0x1400372d0 _o__cexit
0x1400372d8 _o__callnewh
0x140037300 _o___std_exception_copy
0x140037308 _o___p__commode
0x140037310 _o___p___argv
0x140037318 _o___p___argc
0x140037320 _o___acrt_iob_func
0x140037328 wcsstr
0x140037330 wcsrchr
0x140037338 wcschr
0x140037340 longjmp
0x140037348 __C_specific_handler
0x140037350 _local_unwind
0x140037358 memcmp
0x140037360 memcpy
0x140037368 memmove
Library ntdll.dll:
0x140037408 NtOpenProcessToken
0x140037410 NtQueryInformationToken
0x140037420 NtOpenThreadToken
0x140037428 RtlNtStatusToDosError
0x140037438 NtFsControlFile
0x140037440 NtSetInformationProcess
0x140037448 RtlFreeHeap
0x140037458 NtSetInformationFile
0x140037468 RtlCaptureContext
0x140037470 RtlLookupFunctionEntry
0x140037478 RtlVirtualUnwind
0x140037480 NtOpenFile
0x140037488 RtlReleaseRelativeName
0x140037490 RtlFreeUnicodeString
0x140037498 NtClose
Library api-ms-win-core-libraryloader-l1-2-0.dll:
0x140036da8 LoadLibraryExW
0x140036db0 GetModuleFileNameA
0x140036db8 GetModuleHandleW
0x140036dc0 GetModuleHandleExW
0x140036dc8 GetModuleFileNameW
0x140036dd0 GetProcAddress
Library api-ms-win-core-synch-l1-1-0.dll:
0x140036fd0 ReleaseSRWLockShared
0x140036fd8 CreateSemaphoreExW
0x140036fe0 EnterCriticalSection
0x140036fe8 ReleaseSemaphore
0x140036ff0 LeaveCriticalSection
0x140037010 WaitForSingleObject
0x140037018 ReleaseMutex
0x140037020 ReleaseSRWLockExclusive
0x140037028 AcquireSRWLockExclusive
0x140037030 DeleteCriticalSection
0x140037038 AcquireSRWLockShared
0x140037040 CreateMutexExW
0x140037048 WaitForSingleObjectEx
0x140037050 OpenSemaphoreW
Library api-ms-win-core-heap-l1-1-0.dll:
0x140036d30 HeapSize
0x140036d38 HeapReAlloc
0x140036d40 HeapSetInformation
0x140036d48 HeapAlloc
0x140036d50 HeapFree
0x140036d58 GetProcessHeap
Library api-ms-win-core-errorhandling-l1-1-0.dll:
0x140036bd0 UnhandledExceptionFilter
0x140036bd8 SetErrorMode
0x140036be0 SetLastError
0x140036be8 GetLastError
Library api-ms-win-core-threadpool-l1-2-0.dll:
0x1400370b0 CreateThreadpoolTimer
0x1400370b8 CloseThreadpoolTimer
0x1400370c8 SetThreadpoolTimer
Library api-ms-win-core-processthreads-l1-1-0.dll:
0x140036ed8 GetCurrentProcessId
0x140036ee0 GetStartupInfoW
0x140036ee8 CreateProcessAsUserW
0x140036ef0 CreateProcessW
0x140036f00 GetCurrentProcess
0x140036f08 ResumeThread
0x140036f10 GetCurrentThreadId
0x140036f18 GetExitCodeProcess
0x140036f20 TerminateProcess
0x140036f30 OpenThread
Library api-ms-win-core-localization-l1-2-0.dll:
0x140036de0 SetThreadLocale
0x140036de8 FormatMessageW
0x140036df0 GetCPInfo
0x140036df8 GetThreadLocale
0x140036e00 GetLocaleInfoW
0x140036e08 GetACP
0x140036e10 GetUserDefaultLCID
Library api-ms-win-core-debug-l1-1-0.dll:
0x140036b88 DebugBreak
0x140036b90 OutputDebugStringW
0x140036b98 IsDebuggerPresent
Library api-ms-win-core-handle-l1-1-0.dll:
0x140036d18 CloseHandle
0x140036d20 DuplicateHandle
Library api-ms-win-core-memory-l1-1-0.dll:
0x140036e20 VirtualAlloc
0x140036e28 ReadProcessMemory
0x140036e30 VirtualQuery
0x140036e38 VirtualFree
Library api-ms-win-core-console-l1-1-0.dll:
0x140036ad0 GetConsoleOutputCP
0x140036ad8 GetConsoleMode
0x140036ae0 SetConsoleCtrlHandler
0x140036ae8 ReadConsoleW
0x140036af0 WriteConsoleW
0x140036af8 SetConsoleMode
Library api-ms-win-core-file-l1-1-0.dll:
0x140036bf8 FindNextFileW
0x140036c00 SetFileTime
0x140036c08 DeleteFileW
0x140036c10 CreateFileW
0x140036c18 SetFileAttributesW
0x140036c20 GetFileSize
0x140036c28 CreateDirectoryW
0x140036c30 FindClose
0x140036c38 FindFirstFileW
0x140036c40 GetFullPathNameW
0x140036c48 ReadFile
0x140036c50 FlushFileBuffers
0x140036c58 SetFilePointer
0x140036c60 RemoveDirectoryW
0x140036c68 CompareFileTime
0x140036c70 FindFirstFileExW
0x140036c78 GetVolumePathNameW
0x140036c80 SetEndOfFile
0x140036c88 GetFileAttributesW
0x140036c90 GetFileAttributesExW
0x140036c98 GetDriveTypeW
0x140036ca0 GetFileType
0x140036ca8 GetDiskFreeSpaceExW
0x140036cb0 FileTimeToLocalFileTime
0x140036cb8 GetVolumeInformationW
0x140036cc0 WriteFile
0x140036cc8 SetFilePointerEx
Library api-ms-win-core-string-l1-1-0.dll:
0x140036fb8 WideCharToMultiByte
0x140036fc0 MultiByteToWideChar
Library api-ms-win-core-processenvironment-l1-1-0.dll:
0x140036e60 SearchPathW
0x140036e68 GetEnvironmentVariableW
0x140036e70 SetCurrentDirectoryW
0x140036e78 GetEnvironmentStringsW
0x140036e88 FreeEnvironmentStringsW
0x140036e90 GetStdHandle
0x140036e98 SetEnvironmentVariableW
0x140036ea0 GetCommandLineW
0x140036ea8 SetEnvironmentStringsW
0x140036eb0 GetCurrentDirectoryW
Library api-ms-win-core-console-l2-1-0.dll:
0x140036b08 FlushConsoleInputBuffer
0x140036b10 SetConsoleCursorPosition
0x140036b28 SetConsoleTextAttribute
Library api-ms-win-security-base-l1-1-0.dll:
0x1400373d8 RevertToSelf
0x1400373e0 GetFileSecurityW
Library api-ms-win-core-sysinfo-l1-1-0.dll:
0x140037060 GetSystemTimeAsFileTime
0x140037068 GetVersion
0x140037070 SetLocalTime
0x140037078 GetLocalTime
0x140037080 GetSystemTime
0x140037088 GetWindowsDirectoryW
Library api-ms-win-core-timezone-l1-1-0.dll:
0x1400370d8 FileTimeToSystemTime
0x1400370e0 SystemTimeToFileTime
Library api-ms-win-core-datetime-l1-1-0.dll:
0x140036b70 GetTimeFormatW
0x140036b78 GetDateFormatW
Library api-ms-win-core-systemtopology-l1-1-0.dll:
0x1400370a0 GetNumaHighestNodeNumber
Library api-ms-win-core-console-l2-2-0.dll:
0x140036b48 SetConsoleTitleW
0x140036b50 GetConsoleTitleW
Library api-ms-win-core-processenvironment-l1-2-0.dll:
Library api-ms-win-core-registry-l1-1-0.dll:
0x140036f70 RegCloseKey
0x140036f78 RegQueryValueExW
0x140036f80 RegDeleteValueW
0x140036f88 RegCreateKeyExW
0x140036f90 RegDeleteKeyExW
0x140036f98 RegOpenKeyExW
0x140036fa0 RegSetValueExW
0x140036fa8 RegEnumKeyExW
Library api-ms-win-core-file-l2-1-0.dll:
0x140036cd8 CreateHardLinkW
0x140036ce8 CreateSymbolicLinkW
0x140036cf0 MoveFileExW
0x140036cf8 MoveFileWithProgressW
Library api-ms-win-core-heap-l2-1-0.dll:
0x140036d68 GlobalFree
0x140036d70 GlobalAlloc
0x140036d78 LocalFree
Library api-ms-win-core-file-l2-1-2.dll:
0x140036d08 CopyFileW
Library api-ms-win-core-io-l1-1-0.dll:
0x140036d98 DeviceIoControl
Library api-ms-win-core-console-l3-2-0.dll:
0x140036b60 GetConsoleWindow
Library api-ms-win-core-processtopology-l1-1-0.dll:
0x140036f50 GetThreadGroupAffinity
Library api-ms-win-core-processthreads-l1-1-1.dll:
Library api-ms-win-core-profile-l1-1-0.dll:
0x140036f60 QueryPerformanceCounter
Library api-ms-win-core-interlocked-l1-1-0.dll:
0x140036d88 InitializeSListHead
Library api-ms-win-core-misc-l1-1-0.dll:
0x140036e48 lstrcmpW
0x140036e50 lstrcmpiW
Library api-ms-win-core-apiquery-l1-1-0.dll:
Library api-ms-win-core-delayload-l1-1-1.dll:
0x140036bb8 ResolveDelayLoadedAPI
Library api-ms-win-core-delayload-l1-1-0.dll:
0x140036ba8 DelayLoadFailureHook

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.didat
@.reloc
\$ UVWATAUAVAWH
fG94lu
fD94~u
fD94~u
tGD95)6
fD94{u
fD94Su
A_A^A]A\_^]
\$ UVWATAUAVAWH
`A_A^A]A\_^]
UAVAWH
@A_A^]
@USVWATAUAVAWH
fC94fu
fD9,^u
fD9,Vu
^fD9+uYH
fD9,Cu
fD9,Cu
fD9,Su
fD9,Ju
fD9,Cu
fE9,Gu
fE9,Wu
fE9,xu
A_A^A]A\_^[]
x ATAVAWH
A_A^A\
@USVWATAUAVAWH
fD9,Ku
A_A^A]A\_^[]
tZ9t$H
D$89t$P
9t$Pt!H
@USVWATAVAWH
A_A^A\_^[]
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
fF9$Iu
fD9$yu
A_A^A]A\_^]
fD9$Cu
fD9$Hu
fD9$Au
UVWATAUAVAWH
D$lt$E
H9K@t89
D9L$|t#D
D$PuNI
\$dD9L$Lu
D9L$hu
A_A^A]A\_^]
t$ UWAVH
D$ H;D$0u
D$(H;D$8t
@USVWATAUAVAWH
fD9TH,u
A_A^A]A\_^[]
@USVWATAUAVAWH
fD9$Fu
A_A^A]A\_^[]
x ATAUAVH
*tvfA;
fD9#tSH
A^A]A\
fA9,Hu
f9lQ,u
WAVAWH
A_A^_
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
fD9$Fu
@A_A^A]A\_^]
x UATAUAVAWH
|$XM9/u
E8n t|
A_A^A]A\]
fD9,Au
fD9,Au
UVWATAUAVAWH
0A_A^A]A\_^]
WATAUAVAWH
fE9'tdA
fE9$wu
A_A^A]A\_
UVWATAUAVAWH
,.u$fD9o.t
fD9o0u
A_A^A]A\_^]
t$ UWAVH
qbYTg'
@USVWATAUAVAWH
|$z:t0A
A_A^A]A\_^[]
x ATAVAWH
fF9<Au
A_A^A\
x UATAUAVAWH
fA94Fu
fA94Lu
D8|$Tt
f9t$Xt3H
D8l$Tt
D8l$\t
fD9,Gu
D8l$^u
D8l$UL
t D8l$Vt
A_A^A]A\]
UAVAWH
WAVAWH
A_A^_
UVWATAUAVAWH
A_A^A]A\_^]
UWATAVAWH
fE9$@u
u(D9d$ t,
A_A^A\_]
UVWATAUAVAWH
fF9,cu
fD9,su
@A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWAVAWH
LcL$ A
0A_A^_^]
WAVAWH
A_A^_
x UAVAWH
fD9<Wu
fD9<_u
WAUAVH
x ATAVAWH
A_A^A\
x UATAUAVAWH
t$49\$Ht&9
uH9\$<uH
M9\$<t
u1H9D$`~*D
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
UWAUAVAWH
A_A^A]_]
tGf9+t
UVWATAUAVAWH
fD9,Gu
@A_A^A]A\_^]
ATAVAWH
fD9$Zu
fD9 tuH
fD9$Cu
A_A^A\
v8f98
l$ VWAVH
\$ UVWAVAWH
pA_A^_^]
WATAUAVAWH
fB9<iu
A_A^A]A\_
|$ AVH
|$ AVH
UWATAVAWH
;:tufD93u/H;
A_A^A\_]
UATAVH
UVWATAUAVAWH
fE9<^u
A_A^A]A\_^]
H!\$ L
x AUAVAWH
t,9u(D
@A_A^A]
fE9<nu
fD9<{u
t$HD9=9i
fD9<Cu
9:uGH9-
t$ WATAUAVAWH
fD94qu
fF94`u
A_A^A]A\_
f90t13
WATAUAVAWH
A_A^A]A\_
|$ UATAUAVAWH
A_A^A]A\]
t$HD9-
D9l$Dt
fD9l$p
UVWATAUAVAWH
A_A^A]A\_^]
t[I9?t!I
4FHcD$`H
HcD$`H
4FHcD$`H
HcD$`H
t$ WATAUAVAWH
A_A^A]A\_
4FHcD$PH
HcD$PH
SUWATAUAVAWH
A_A^A]A\_][
WATAUAVAWH
A_A^A]A\_
@SVAUH
x ATAVAWH
A_A^A\
UVWATAUAVAWH
A_A^A]A\_^]
f90t/3
t$ WATAVH
A^A\_
SVWATAUAVAWH
D$ fA;
A_A^A]A\_^[
WAVAWH
A_A^_
UVATAVAWH
fD99t~D9=t
A_A^A\^]
WAVAWH
fD9<Cu
A_A^_
UVWATAUAVAWH
"uB95G
0A_A^A]A\_^]
@USWATAUAVAWH
D9u@u5M
fE94Du
fE94Lu
fE94\u
A_A^A]A\_[]
CHcD$pH
HcD$pH
UVWATAUAVAWH
0A_A^A]A\_^]
\$ UVWATAUAVAWH
t$4fD93
;.u#fD9s
HcD$@M
9D$4t$
tkHcT$@I
t'HcT$@I+
A_A^A]A\_^]
L$ AUH
fE9<Hu
@USVWATAUAVAWH
D$@fD9&t
HcT$0M
0H+t$@H
A_A^A]A\_^[]
SVWATAUAVAWH
HcT$@L
A_A^A]A\_^[
8@8=!`
fA9<Vu
f98tDA
fA9<@u
x UATAUAVAWH
fD9,Qu
fD9,Au
A_A^A]A\]
SUVWATAVAWH
`A_A^A\_^][
`A_A^A\_^][
D$@H9t$@
UVWATAUAVAWH
fD9<qu
A_A^A]A\_^]
USVWATAUAVAWH
A_A^A]A\_^[]
\$ UVWATAUAVAWH
L+D$ H+
fD9,Gu
fD9,Ou
A_A^A]A\_^]
fA9<Vu
fA9<Fu
t$ UWATAVAWH
A_A^A\_]
|$ ATAVAWH
fD9$Cu
fD9$yu
A_A^A\
WATAUAVAWH
H!|$`I
A_A^A]A\_
@SUVWAVH
0A^_^][
t$ WAVAWH
fB9<su
\uc@8=s$
WAUAVH
t!fD9l$
fD9t$"
fD9l$
UWAUAVAWH
"D9t$0u
"D9t$0u
"D9t$0u
D9t$0u
/D9t$0u!E3
/D9t$0u!E3
fD9|$pt
A_A^A]_]
UVWATAUAVAWH
t 8\$ t
A_A^A]A\_^]
@USVWATAUAVAWH
C:fD9/
Nf9t f9G
A_A^A]A\_^[]
t|fD90tvH
\u;fD9s
@SUVWATAUAVAWH
t$0fA9)
d$@@8-'
4FfA9.
A_A^A]A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
n(D9-?
A_A^A]A\_^]
UVWATAUAVAWH
|$XD9w
f9TF0u
pbYTg'
|$XD;w
G09W$v
A_A^A]A\_^]
qbYTg'
UVWATAUAVAWH
A_A^A]A\_^]
fA9,Pu
fA9,Au
WATAUAVAWH
D$@fD9
u0fD9o
A_A^A]A\_
WAVAWH
0A_A^_
f99ujH
L$8f99u`+
x ATAVAWH
fD9 tK
A_A^A\
f9*u%H
t$ WATAUAVAWH
fD9,pu
fD9,pu
A_A^A]A\_
` AUAVAWH
fA9<$u
@fA9|M
t$09|$8t1
f9|$<tPH;
fB9<ku
A_A^A]
fA94Ru
q0R^G'
q0R^G'
q0R^G'
q0R^G'
H3E H3E
u/HcH<H
H SVWH
H SVWH
\$ UVWATAUAVAWH
D9l$(|
D$,D8-`
@USVWATAVAWH
A_A^A\_^[]
|$ UATAUAVAWH
A_A^A]A\]
F8@88t
UWATAVAWH
A_A^A\_]
UVWATAUAVAWH
ty@8=5
@A_A^A]A\_^]
s WAVAWH
@A_A^_
UVWAVAWH
L$`H+~(H
0A_A^_^]
t$ WAVAWH
@u;L9;u$E3
0A_A^_
p WAVAWH
A_A^_
WAVAWH
|$ UATAUAVAWH
A_A^A]A\]
UVWAVAWH
H!t$PM
A_A^_^]
rHfD97w
C9fD97u,
D$0D9r
{ ATAVAWH
A_A^A\
h UAVAWH
fE9,Gu
f;0u>H
fB9<{u
L$ht'A
fD9<Xu
fE9<^u
fA9,Pu
CxfD90
fD94xu
fE9$Ou
fF9$su
fD9<Hu
fD9<Au
t|D9t$xuuH
fE9$Fu
fE9$Fu
tBD9t$pu;H
fE9,Gt
t5fA9(t/I
VWATAVAWH
D$0fD9 t
A_A^A\_^
WAVAWH
A_A^_
\$ UVWAVAWH
A_A^_^]
@SUVWH
K SVWH
WATAUAVAWH
H9/sDH
A_A^A]A\_
x UAVAWH
D$@fD98t
D$@fD98t
HcD$$HcL$ H
@SUVWATAUAVAWH
fD94Ku
fD94Bu
A_A^A]A\_^][
@USVWATAUAVAWH
fD9$Fu
fD9$Fu
fD9$Fu
A_A^A]A\_^[]
x UAUAWH
tvf93tqH
D$Xf90t
\$ UVWATAUAVAWH
@A_A^A]A\_^]
\$ UVWATAUAVAWH
fD9,_u
fD9,Gu
@A_A^A]A\_^]
Gxf9(u)3
Gxf9(u(3
WATAUAVAWH
fD9$nu
fD9$_u
tUD9%}w
fD9$_u
A_A^A]A\_
x UATAUAVAWH
u"f90uH
f90uH
A_A^A]A\]
{ ATAVAWH
fE9$Fu
AfD9!u
fD9$Au
@A_A^A\
UWATAVAWH
|$P.uEH
fD9$Gu
fD9$hu
A_A^A\_]
UVWATAUAVAWH
A_A^A]A\_^]
{ ATAVAWH
fE9$Fu
AfD9!u
fD9$Au
@A_A^A\
t$0uKE3
H9L$@r
tsHcL$8L
HcT$8H
f9|$Xvx
t,fD92t&I
M0H9M`t
WAVAWH
fD9<Gu
\$ UVWATAUAVAWH
fD9<Bu
D$`fD98t
tlfD9>tfI
fF9<fu
A_A^A]A\_^]
x UATAUAVAWH
fD9$Cu
<GfD9#
fD9$Gu
fD9$Su
fD9$Wu
fF9$yu
fD9$Ku
A_A^A]A\]
f9|$Vt"
WATAUAVAWH
fD9$hu
A_A^A]A\_
fD94Qu
L$ USWH
VAVAWH
0A_A^^
D9t$Pu
UVWATAUAVAWH
d$Ht*D
D;d$@D
A_A^A]A\_^]
x ATAVAWH
@A_A^A\
H!|$ L
\$ UVWATAUAVAWH
fD94Hu
fD94xu
`A_A^A]A\_^]
WAVAWH
fD94Cu
fD94wu
A_A^_H
WATAUAVAWH
A_A^A]A\_
@SUVWAVH
A^_^][
@USVWATAVAWH
fD98t&f
:ufD9x
A_A^A\_^[]
\$ UVWH
l$ VWATAVAWH
u fE9`
fD9$Cu
A_A^A\_^
t$ UWATAVAWH
fD94Au
D9t$Dt>D
A_A^A\_]
t$ UWAVH
WATAUAVAWH
A_A^A]A\_
D9q$vrH
fD9tA0u
fD9tY0u
UVWATAUAVAWH
D9f$t
l$PLcv$I
fF9Dj0u
A_A^A]A\_^]
SVWATAUAVAWH
@A_A^A]A\_^[
WATAUAVAWH
H9|$Xt eH
A_A^A]A\_
UVWAVAWH
@A_A^_^]
SetThreadUILanguage
Unknown exception
bad allocation
bad array new length
api-ms-win-core-winrt-l1-1-0.dll
ext-ms-win-branding-winbrand-l1-1-0.dll
ext-ms-win-cmd-util-l1-1-0.dll
ext-ms-win-appmodel-shellexecute-l1-1-0.dll
Exception
ReturnNt
ReturnHr
FailFast
onecore\internal\sdk\inc\wil\opensource\wil\resource.h
WilError_03
WilFailureNotifyWatchers
RtlRegisterFeatureConfigurationChangeNotification
RtlUnregisterFeatureConfigurationChangeNotification
RtlNotifyFeatureUsage
NtQueryWnfStateData
NtUpdateWnfStateData
onecore\internal\sdk\inc\wil/Staging.h
WilStaging_02
CMD Internal Error %s
Null environment
APerformUnaryOperation: '%c'
APerformArithmeticOperation: '%c'
CopyFileExW
IsDebuggerPresent
SetConsoleInputExeNameW
RaiseFailFastException
RtlNtStatusToDosErrorNoTeb
RtlDllShutdownInProgress
RtlDisownModuleHeapAllocation
NtQueryInformationProcess
Copyright (c) Microsoft Corporation. All rights reserved.
onecore\base\cmd\StartShellExecServiceProvider.h
onecore\base\cmd\maxpathawarestring.cpp
cmd.pdb
.text$di
.text$lp00cmd.exe!20_pri7
.text$lp01cmd.exe!20_pri7
.text$lp03cmd.exe!35_hybridboot
.text$mn
.text$mn$00
.text$np
.text$x
.text$yd
.text$zy
.text$zz
.rdata$brc
.rdata$00$brc
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gehcont
.gfids
.giats
.gljmp
.rdata
.rdata$00
.rdata$03
.rdata$r
.rdata$voltmd
.rdata$zz
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.idata$2
.idata$3
.idata$4
.idata$6
.data$dk00$brc
.data$r$brc
.data$rs$brc
.data$00
.data$dk00
.data$pr00
.data$zz
.bss$00
.bss$01
.bss$03
.bss$dk00
.bss$dk01
.bss$dk03
.bss$pr00
.bss$zz
.pdata
.didat$5
.rsrc$01
.rsrc$02
RoInitialize
RoUninitialize
BrandingFormatString
CmdBatNotificationStub
SaferWorker
MessageBeepStub
GetVDMCurrentDirectoriesStub
ShellExecuteWorker
DoSHChangeNotify
QueryFullProcessImageNameWStub
WNetGetConnectionWStub
WNetCancelConnection2WStub
WNetAddConnection2WStub
LookupAccountSidWStub
FindFirstStreamWStub
FindNextStreamWStub
ShellExecuteExW
wcsspn
_time32
wcsncmp
_initterm
_initterm_e
_c_exit
_register_thread_local_exe_atexit_callback
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
__C_specific_handler
longjmp
wcschr
wcsrchr
wcsstr
_o___acrt_iob_func
_o___p___argc
_o___p___argv
_o___p__commode
_o___std_exception_copy
_o___std_exception_destroy
_o___stdio_common_vfprintf
_o___stdio_common_vswprintf
_o___stdio_common_vswscanf
_o__callnewh
_o__cexit
_o__close
_o__configthreadlocale
_o__configure_narrow_argv
_o__crt_atexit
_o__dup
_o__dup2
_o__errno
_o__exit
_o__get_initial_narrow_environment
_o__get_osfhandle
_o__getch
_o__initialize_narrow_environment
_o__initialize_onexit_table
_o__invalid_parameter_noinfo
_o__open_osfhandle
_o__pclose
_o__pipe
_o__purecall
_o__register_onexit_function
_o__seh_filter_exe
_o__set_app_type
_o__set_fmode
_o__set_new_mode
_o__setmode
_o__tell
_o__ultoa
_o__ultoa_s
_o__wcsicmp
_o__wcslwr
_o__wcsnicmp
_o__wcsupr
_o__wpopen
_o__wtol
_o_calloc
_o_exit
_o_feof
_o_ferror
_o_fflush
_o_fgets
_o_free
_o_iswalpha
_o_iswdigit
_o_iswspace
_o_iswxdigit
_o_malloc
_o_qsort
_o_rand
_o_realloc
_o_setlocale
_o_srand
_o_terminate
_o_towlower
_o_towupper
_o_wcstol
_o_wcstoul
__CxxFrameHandler3
__current_exception
__current_exception_context
memset
_CxxThrowException
api-ms-win-crt-private-l1-1-0.dll
RtlCreateUnicodeStringFromAsciiz
NtCancelSynchronousIoFile
RtlNtStatusToDosError
NtQueryInformationProcess
NtSetInformationProcess
NtQueryVolumeInformationFile
NtSetInformationFile
RtlDosPathNameToRelativeNtPathName_U_WithStatus
NtOpenFile
RtlReleaseRelativeName
RtlFreeUnicodeString
RtlFindLeastSignificantBit
RtlDosPathNameToNtPathName_U
NtFsControlFile
RtlFreeHeap
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
GetModuleFileNameA
CreateSemaphoreExW
HeapFree
SetLastError
EnterCriticalSection
ReleaseSemaphore
GetModuleHandleExW
LeaveCriticalSection
InitializeCriticalSectionEx
WaitForThreadpoolTimerCallbacks
WaitForSingleObject
GetCurrentThreadId
ReleaseMutex
FormatMessageW
GetLastError
ReleaseSRWLockExclusive
OutputDebugStringW
CloseThreadpoolTimer
AcquireSRWLockExclusive
WaitForSingleObjectEx
OpenSemaphoreW
CloseHandle
SetThreadpoolTimer
ReleaseSRWLockShared
CreateThreadpoolTimer
HeapAlloc
GetProcAddress
CreateMutexExW
AcquireSRWLockShared
DeleteCriticalSection
GetCurrentProcessId
GetProcessHeap
GetModuleHandleW
DebugBreak
IsDebuggerPresent
VirtualQuery
GetCPInfo
GetConsoleOutputCP
SetThreadLocale
SetFilePointer
GetFullPathNameW
FindFirstFileW
FindNextFileW
FindClose
CreateFileW
ReadFile
MultiByteToWideChar
GetFileSize
WideCharToMultiByte
GetStdHandle
FlushConsoleInputBuffer
RevertToSelf
GetConsoleScreenBufferInfo
ReadConsoleW
SetConsoleCursorPosition
FillConsoleOutputCharacterW
WriteConsoleW
GetFileType
GetUserDefaultLCID
GetLocaleInfoW
SetLocalTime
GetSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
FileTimeToSystemTime
GetDateFormatW
GetTimeFormatW
GetLocalTime
GetConsoleMode
SetConsoleMode
GetEnvironmentVariableW
GetCommandLineW
GetNumaHighestNodeNumber
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetEnvironmentStringsW
GetConsoleTitleW
SetErrorMode
InitializeProcThreadAttributeList
UpdateProcThreadAttribute
DeleteProcThreadAttributeList
GetStartupInfoW
CreateProcessAsUserW
CreateProcessW
GetFileAttributesW
NeedCurrentDirectoryForExePathW
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
RegEnumKeyExW
RegDeleteKeyExW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
LoadLibraryExW
ReadProcessMemory
MoveFileWithProgressW
MoveFileExW
SetConsoleTitleW
LocalFree
SearchPathW
WriteFile
SetFilePointerEx
GlobalAlloc
GlobalFree
GetVolumeInformationW
TryAcquireSRWLockExclusive
ExpandEnvironmentStringsW
InitializeCriticalSection
SetConsoleCtrlHandler
GetWindowsDirectoryW
GetModuleFileNameW
GetVersion
GetDriveTypeW
GetFileAttributesExW
OpenThread
HeapSetInformation
VirtualFree
VirtualAlloc
HeapReAlloc
HeapSize
DuplicateHandle
FlushFileBuffers
GetACP
ScrollConsoleScreenBufferW
FillConsoleOutputAttribute
SetConsoleTextAttribute
CreateDirectoryW
CopyFileW
SetFileAttributesW
SetEndOfFile
DeleteFileW
SetFileTime
GetFileInformationByHandleEx
SetCurrentDirectoryW
TerminateProcess
GetExitCodeProcess
GetCurrentDirectoryW
RemoveDirectoryW
CompareFileTime
GetFileSecurityW
GetSecurityDescriptorOwner
DeviceIoControl
GetDiskFreeSpaceExW
FindFirstFileExW
GetConsoleWindow
GetThreadGroupAffinity
GetNumaNodeProcessorMaskEx
ResumeThread
GetThreadLocale
GetVolumePathNameW
CreateSymbolicLinkW
CreateHardLinkW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-synch-l1-1-0.dll
api-ms-win-core-heap-l1-1-0.dll
api-ms-win-core-errorhandling-l1-1-0.dll
api-ms-win-core-threadpool-l1-2-0.dll
api-ms-win-core-processthreads-l1-1-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-debug-l1-1-0.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-memory-l1-1-0.dll
api-ms-win-core-console-l1-1-0.dll
api-ms-win-core-file-l1-1-0.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-processenvironment-l1-1-0.dll
api-ms-win-core-console-l2-1-0.dll
api-ms-win-security-base-l1-1-0.dll
api-ms-win-core-sysinfo-l1-1-0.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-core-datetime-l1-1-0.dll
api-ms-win-core-systemtopology-l1-1-0.dll
api-ms-win-core-console-l2-2-0.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-file-l2-1-0.dll
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-core-file-l2-1-2.dll
api-ms-win-core-io-l1-1-0.dll
api-ms-win-core-console-l3-2-0.dll
api-ms-win-core-processtopology-l1-1-0.dll
api-ms-win-core-processthreads-l1-1-1.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-interlocked-l1-1-0.dll
lstrcmpiW
lstrcmpW
api-ms-win-core-misc-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-apiquery-l1-1-0.dll
NtOpenProcessToken
NtQueryInformationToken
NtClose
NtOpenThreadToken
ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-delayload-l1-1-1.dll
api-ms-win-core-delayload-l1-1-0.dll
wcscmp
_local_unwind
memcmp
memcpy
memmove
__intrinsic_setjmp
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="amd64"
name="Microsoft.Windows.FileSystem.CMD"
type="win32"
<description>Windows Command Processor</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
<windowsSettings xmlns:ws2="http://schemas.microsoft.com/SMI/2016/WindowsSettings">
<ws2:longPathAware>true</ws2:longPathAware>
</windowsSettings>
</application>
</assembly>
wwwwwwwwwwwwwwwwwwwww
Se%ae`
cCBR_p
RRRRP%
CCCC@40`P@
cG?CCRRRRP`R
4qaCCRCCCB
pqacG%%apppppppaB
prRRRPa
wwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwww
se%%%%% R
u%6RRRRRPp
wwwwwwwwwwwwwww
wwwwwwwwp
wwwwwwww
!

((((&&(&&&(&(&&&&&&(((#&&###
*)))))))))))))))))))))
eIDATx
""""""""""""""""""""""""""""""""""""""""
'Px0&D
XXX8Pvh8v
],//cuu
n<DSbb
!KD4)#
NDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
ENABLEDELAYEDEXPANSION
DISABLEEXTENSIONS
ENABLEEXTENSIONS
<>+-*/%()|^&=,
Software\Policies\Microsoft\Windows\System
%2d%s%02d%s%02d%s%02d
CMD.EXE
0123456789
ERRORLEVEL
CMDCMDLINE
CMDEXTVERSION
DEFINED
COPYCMD
MM/dd/yy
\XCOPY.EXE
=ExitCode
=ExitCodeAscii
????????.???
%d.%d.%05d.%d
Software\Microsoft\Windows NT\CurrentVersion
HIGHESTNUMANODENUMBER
RANDOM
KERNEL32.DLL
/D /c"
COMSPEC
ext-ms-win-branding-winbrand-l1-1-0
ext-ms-win-branding-winbrand-l1-1-1
ext-ms-win-branding-winbrand-l1-1-2
lext-ms-win-cmd-util-l1-1-0
ext-ms-win-appmodel-shellexecute-l1-1-0
%hs(%u)\%hs!%p:
%hs!%p:
(caller: %p)
%hs(%d) tid(%x) %08X %ws
Msg:[%ws]
CallContext:[%hs]
[%hs(%hs)]
kernelbase.dll
ntdll.dll
Local\SM0:%lu:%lu:%hs
usebackq
useback
delims=
tokens=
%s %s
%s %s%s
(%s) %s
PROMPT
.COM;.EXE;.BAT;.CMD;.VBS;.JS;.WS;.MSC
PATHEXT
=,;+/[]
Software\Microsoft\Command Processor
System\Software\Microsoft\Command Processor
DisableUNCCheck
EnableExtensions
DelayedExpansion
DefaultColor
CompletionChar
PathCompletionChar
AutoRun
()|&=,;"
fdpnxsatz
FOR /?
REM /?
%s (%s) %s
Cmd: %s Type: %x
Args: `%s'
*** Unknown type: %x
GeToken: (%x) '%s'
<noalias>
DIRCMD
AFFINITY
ABOVENORMAL
BELOWNORMAL
NEWWINDOW
NORMAL
REALTIME
SEPARATE
SHARED
MACHINE
/K %s
RENAME
PROMPT
VERIFY
MKLINK
SETLOCAL
ENDLOCAL
cmd.exe
DISABLEDELAYEDEXPANSION
chdir
rmdir
mkdir
pushd
dd/MM/yy
yy/MM/dd
HH:mm:ss t
%02d%s%02d%s
%02d%s%02d%s%02d
\CMD.EXE
%04X-%04X
Software\Classes
NTDLL.DLL
\Shell\Open\Command
%WINDOWS_COPYRIGHT%
Ungetting: '%s'
Unknown
DisableCMD
Application
System
Redir:
%x %c
[...]
&()[]{}^=;!%'+,`~
IDI_APPICON
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Windows Command Processor
FileVersion
10.0.22621.608 (WinBuild.160101.0800)
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
Cmd.Exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.22621.608
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.