Static | ZeroBOX

PE Compile Time

2019-06-11 09:49:55

PE Imphash

9308ae5a32f3325746ec67b81842246c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00024bf0 0x00024c00 6.63108779238
.rdata 0x00026000 0x00008480 0x00008a00 5.02680039478
.data 0x0002f000 0x00005c3c 0x00002200 4.06930044614
.rsrc 0x00035000 0x00006404 0x00006600 3.88624915922

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00036d9c 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00036f88 0x00000144 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00036f88 0x00000144 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037e54 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_DIALOG 0x00038c6c 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00038c6c 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00038c6c 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0003a264 0x00000042 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x0003a3d0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x0003a42c 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0003a42c 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0003ab7c 0x0000072c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0003ab7c 0x0000072c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0003b2a8 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library USER32.dll:
0x426258 EndPaint
0x42625c BeginPaint
0x426260 ReleaseDC
0x426264 GetDC
0x426268 ClientToScreen
0x42626c GrayStringA
0x426270 DrawTextExA
0x426274 DrawTextA
0x426278 TabbedTextOutA
0x42627c ShowWindow
0x426280 SetWindowTextA
0x426284 IsDialogMessageA
0x426288 SetDlgItemTextA
0x426290 SendDlgItemMessageA
0x426294 WinHelpA
0x426298 GetCapture
0x42629c GetClassLongA
0x4262a0 GetClassNameA
0x4262a4 SetPropA
0x4262a8 GetPropA
0x4262ac RemovePropA
0x4262b0 SetFocus
0x4262b8 GetWindowTextA
0x4262bc GetForegroundWindow
0x4262c0 GetTopWindow
0x4262c4 GetMessageTime
0x4262c8 GetMessagePos
0x4262cc MapWindowPoints
0x4262d0 SetMenu
0x4262d4 SetForegroundWindow
0x4262d8 UpdateWindow
0x4262dc GetSubMenu
0x4262e0 GetMenuItemCount
0x4262e4 CreateWindowExA
0x4262e8 GetClassInfoExA
0x4262ec GetClassInfoA
0x4262f0 RegisterClassA
0x4262f4 GetSysColor
0x4262f8 AdjustWindowRectEx
0x4262fc CopyRect
0x426300 PtInRect
0x426304 GetDlgCtrlID
0x426308 DefWindowProcA
0x42630c CallWindowProcA
0x426310 GetMenu
0x426314 SetWindowLongA
0x426318 SetWindowPos
0x426320 GetWindowPlacement
0x426324 GetWindowRect
0x426328 GetWindow
0x42632c UnhookWindowsHookEx
0x426330 GetDesktopWindow
0x426334 SetActiveWindow
0x42633c DestroyWindow
0x426340 IsWindow
0x426344 GetDlgItem
0x426348 GetNextDlgTabItem
0x42634c EndDialog
0x426354 GetWindowLongA
0x426358 GetLastActivePopup
0x42635c IsWindowEnabled
0x426360 MessageBoxA
0x426364 SetCursor
0x426368 SetWindowsHookExA
0x42636c DestroyMenu
0x426370 UnregisterClassA
0x426374 CallNextHookEx
0x426378 GetMessageA
0x42637c TranslateMessage
0x426380 DispatchMessageA
0x426384 GetActiveWindow
0x426388 IsWindowVisible
0x42638c GetKeyState
0x426390 PeekMessageA
0x426394 GetCursorPos
0x426398 ValidateRect
0x42639c SetMenuItemBitmaps
0x4263a4 LoadBitmapA
0x4263a8 GetFocus
0x4263ac GetParent
0x4263b0 ModifyMenuA
0x4263b4 GetMenuState
0x4263b8 EnableMenuItem
0x4263bc CheckMenuItem
0x4263c0 PostMessageA
0x4263c4 PostQuitMessage
0x4263c8 GetSysColorBrush
0x4263cc LoadCursorA
0x4263d0 EnableWindow
0x4263d4 IsIconic
0x4263d8 GetSystemMetrics
0x4263dc GetClientRect
0x4263e0 DrawIcon
0x4263e4 SendMessageA
0x4263e8 GetMenuItemID
0x4263ec LoadIconA
Library SHLWAPI.dll:
0x42624c PathFindFileNameA
0x426250 PathFindExtensionA
Library OLEACC.dll:
0x426234 LresultFromObject
Library KERNEL32.dll:
0x42608c CreateFileA
0x426090 GetCPInfo
0x426094 GetOEMCP
0x426098 GetModuleHandleW
0x42609c SetErrorMode
0x4260a0 RtlUnwind
0x4260a4 GetCommandLineA
0x4260a8 GetStartupInfoA
0x4260ac HeapAlloc
0x4260b0 HeapFree
0x4260b4 Sleep
0x4260b8 ExitProcess
0x4260bc RaiseException
0x4260c0 HeapReAlloc
0x4260c4 VirtualAlloc
0x4260c8 HeapSize
0x4260cc TerminateProcess
0x4260d8 IsDebuggerPresent
0x4260dc GetACP
0x4260e0 IsValidCodePage
0x4260e4 GetStdHandle
0x4260f8 SetHandleCount
0x4260fc GetFileType
0x426100 HeapCreate
0x426104 VirtualFree
0x42610c GetTickCount
0x426118 LCMapStringA
0x42611c LCMapStringW
0x426120 GetStringTypeA
0x426124 GetStringTypeW
0x426128 GetConsoleCP
0x42612c GetConsoleMode
0x426130 SetStdHandle
0x426134 WriteConsoleA
0x426138 GetConsoleOutputCP
0x42613c WriteConsoleW
0x426140 GetCurrentProcess
0x426144 FlushFileBuffers
0x426148 SetFilePointer
0x42614c WriteFile
0x426154 TlsFree
0x42615c LocalReAlloc
0x426160 TlsSetValue
0x426164 TlsAlloc
0x42616c GlobalHandle
0x426170 GlobalReAlloc
0x426178 TlsGetValue
0x426180 LocalAlloc
0x426184 GlobalFlags
0x42618c FormatMessageA
0x426190 LocalFree
0x426194 MulDiv
0x426198 lstrlenA
0x42619c GlobalGetAtomNameA
0x4261a0 GlobalFindAtomA
0x4261a4 MultiByteToWideChar
0x4261a8 lstrcmpW
0x4261ac GetVersionExA
0x4261b4 GetModuleFileNameW
0x4261b8 GlobalUnlock
0x4261bc GlobalFree
0x4261c0 FreeResource
0x4261c4 GetCurrentProcessId
0x4261c8 GetLastError
0x4261cc SetLastError
0x4261d0 GlobalAddAtomA
0x4261d4 CloseHandle
0x4261d8 GlobalDeleteAtom
0x4261dc GetCurrentThread
0x4261e0 GetCurrentThreadId
0x4261ec GetModuleFileNameA
0x4261f0 GetLocaleInfoA
0x4261f4 LoadLibraryA
0x4261f8 WideCharToMultiByte
0x4261fc CompareStringA
0x426200 FindResourceA
0x426204 LoadResource
0x426208 LockResource
0x42620c SizeofResource
0x426210 InterlockedExchange
0x426214 GlobalLock
0x426218 lstrcmpA
0x42621c GlobalAlloc
0x426220 FreeLibrary
0x426224 GetModuleHandleA
0x426228 GetProcAddress
Library GDI32.dll:
0x426028 SetMapMode
0x42602c ScaleViewportExtEx
0x426030 SetWindowExtEx
0x426034 ScaleWindowExtEx
0x426038 DeleteDC
0x42603c GetStockObject
0x426040 OffsetViewportOrgEx
0x426044 GetDeviceCaps
0x426048 SetViewportOrgEx
0x42604c SelectObject
0x426050 Escape
0x426054 ExtTextOutA
0x426058 RestoreDC
0x42605c SaveDC
0x426060 GetObjectA
0x426064 SetBkColor
0x426068 SetTextColor
0x42606c GetClipBox
0x426070 CreateBitmap
0x426074 TextOutA
0x426078 RectVisible
0x42607c PtVisible
0x426080 DeleteObject
0x426084 SetViewportExtEx
Library WINSPOOL.DRV:
0x4263f4 DocumentPropertiesA
0x4263f8 OpenPrinterA
0x4263fc ClosePrinter
Library ADVAPI32.dll:
0x426000 RegSetValueExA
0x426004 RegCreateKeyExA
0x426008 RegQueryValueA
0x42600c RegOpenKeyA
0x426010 RegEnumKeyA
0x426014 RegDeleteKeyA
0x426018 RegOpenKeyExA
0x42601c RegQueryValueExA
0x426020 RegCloseKey
Library OLEAUT32.dll:
0x42623c VariantClear
0x426240 VariantChangeType
0x426244 VariantInit
Library kernel32.dll:
0x42e6f8 GetProcessHeap
0x42e6fc ReadFile
0x42e700 GetLocalTime
0x42e704 lstrcmpiA
0x42e708 CreateMutexA
0x42e710 GetAtomNameA

!This program cannot be run in DOS mode.
`.rdata
t'hziF?h
.hrTd|
chyh2z
}3h@V
7ah"1+8
4h;3(Ch
hc;_;hF
}3h-gm,h.t
t6hU[0Ch3
MlYhVu
GhJ8#(
h@}^[h3}
h~*]^hN//w
hX@</hV
t!h DN
HtQhxkB
qh.&{&h
VWh|lB
0WWWWS
WtrHHt
tA9wht<
9p t-S
udh|lB
jh8uB
PQQQQQ
S\_^[]
S\_^[]
t39w u&
_ 9w$u
Ht;O u
u8h\yB
u:j0^V
QQQQhd
SVWj(3
PWVWWW
SSOWVQ
<A|0<Z
<A|S<Z
+F(_^[;E
F(@@;F,v
F(;^ r
F(;F0u
^(_^[]
tj9~8u@j
9~8ucj
F4_^[]
QQSVWd
HYYtJHt9H
0WWWWW
0WWWWW
0SSSSS
0SSSSS
0SSSSS
HtHu4j
s[S;7|G;w
tR99u2
_VVVVV
^WWWWW
0A@@Ju
<+t(<-t$:
+t HHt
HHtXHHt
>If90t
HHtYHHt
>=Yt1j
j@j ^V
URPQQh
^SSSSS
^SSSSS
j"^SSSSS
PPPPPPPP
PPPPPPPP
uL9=89C
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t"SS9]
PPPPPPPP
^SSSSS
j"^SSSSS
t+WWVPV
>%%.%df
%%.%de
CWinApp
Settings
PreviewPages
DeactivateActCtx
ActivateActCtx
ReleaseActCtx
CreateActCtxA
KERNEL32
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
RestrictRun
NoNetConnectDisconnect
NoRecentDocsHistory
NoClose
Software\Microsoft\Windows\CurrentVersion\Policies\Network
NoEntireNetwork
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
NoPlacesBar
NoBackButton
NoFileMru
ntdll.dll
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
kernel32.dll
%s%s.dll
%s (%s:%d)
%s (%s:%d)
Exception thrown in destructor
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
CCmdTarget
CWinThread
Software\Classes\
Software\
CDialog
CreateActCtxW
comctl32.dll
comdlg32.dll
shell32.dll
AfxWnd90s
AfxControlBar90s
AfxMDIFrame90s
AfxFrameOrView90s
AfxOleControl90s
AfxOldWndProc423
EnumDisplayDevicesA
GetMonitorInfoA
EnumDisplayMonitors
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
GetSystemMetrics
USER32
DISPLAY
InitCommonControls
InitCommonControlsEx
HtmlHelpA
hhctrl.ocx
F#32768
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
commctrl_DragListMsg
CGdiObject
CPaintDC
CUserException
CResourceException
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin1.inl
COleException
CInvalidArgException
CNotSupportedException
CMemoryException
CSimpleException
CException
CSpinButtonCtrl
msctls_updown32
CObject
Delete
NoRemove
ForceRemove
software
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
System
CMapPtrToPtr
CArchiveException
NotifyWinEvent
user32.dll
CByteArray
%2\CLSID
%2\Insertable
%2\protocol\StdFileEditing\verb\0
%2\protocol\StdFileEditing\server
CLSID\%1
CLSID\%1\ProgID
CLSID\%1\InprocHandler32
ole32.dll
CLSID\%1\LocalServer32
CLSID\%1\Verb\0
&Edit,0,2
CLSID\%1\Verb\1
&Open,0,2
CLSID\%1\Insertable
CLSID\%1\AuxUserType\2
CLSID\%1\AuxUserType\3
CLSID\%1\DefaultIcon
CLSID\%1\MiscStatus
CLSID\%1\InProcServer32
CLSID\%1\DocObject
%2\DocObject
CLSID\%1\Printable
CLSID\%1\DefaultExtension
%9, %8
CObArray
CPtrArray
bad allocation
CorExitProcess
HeapQueryInformation
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GAIsProcessorFeaturePresent
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
_nextafter
_hypot
(null)
`h````
xpxxxx
`h`hhh
xppwpp
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
Unknown exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
1#QNAN
1#SNAN
CONOUT$
LoadIconA
SendMessageA
DrawIcon
GetClientRect
GetSystemMetrics
IsIconic
EnableWindow
USER32.dll
PathFindExtensionA
PathFindFileNameA
SHLWAPI.dll
CreateStdAccessibleObject
LresultFromObject
OLEACC.dll
GetProcAddress
GetModuleHandleA
FreeLibrary
GlobalAlloc
lstrcmpA
GlobalLock
InterlockedExchange
SizeofResource
LockResource
LoadResource
FindResourceA
CompareStringA
WideCharToMultiByte
LoadLibraryA
GetLocaleInfoA
GetModuleFileNameA
EnumResourceLanguagesA
ConvertDefaultLocale
GetCurrentThreadId
GetCurrentThread
GlobalDeleteAtom
CloseHandle
GlobalAddAtomA
SetLastError
GetLastError
GetCurrentProcessId
FreeResource
GlobalFree
GlobalUnlock
GetModuleFileNameW
InterlockedDecrement
GetVersionExA
lstrcmpW
MultiByteToWideChar
GlobalFindAtomA
GlobalGetAtomNameA
lstrlenA
MulDiv
LocalFree
FormatMessageA
WritePrivateProfileStringA
GlobalFlags
LocalAlloc
LeaveCriticalSection
TlsGetValue
EnterCriticalSection
GlobalReAlloc
GlobalHandle
InitializeCriticalSection
TlsAlloc
TlsSetValue
LocalReAlloc
DeleteCriticalSection
TlsFree
InterlockedIncrement
WriteFile
SetFilePointer
FlushFileBuffers
GetCurrentProcess
CreateFileA
GetCPInfo
GetOEMCP
GetModuleHandleW
SetErrorMode
RtlUnwind
GetCommandLineA
GetStartupInfoA
HeapAlloc
HeapFree
ExitProcess
RaiseException
HeapReAlloc
VirtualAlloc
HeapSize
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetACP
IsValidCodePage
GetStdHandle
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetConsoleCP
GetConsoleMode
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
KERNEL32.dll
PostQuitMessage
PostMessageA
CheckMenuItem
EnableMenuItem
GetMenuState
ModifyMenuA
GetParent
GetFocus
LoadBitmapA
GetMenuCheckMarkDimensions
SetMenuItemBitmaps
ValidateRect
GetCursorPos
PeekMessageA
GetKeyState
IsWindowVisible
GetActiveWindow
DispatchMessageA
TranslateMessage
GetMessageA
CallNextHookEx
SetWindowsHookExA
SetCursor
MessageBoxA
IsWindowEnabled
GetLastActivePopup
GetWindowLongA
GetWindowThreadProcessId
EndDialog
GetNextDlgTabItem
GetDlgItem
IsWindow
DestroyWindow
CreateDialogIndirectParamA
SetActiveWindow
GetDesktopWindow
UnhookWindowsHookEx
GetWindow
GetWindowRect
GetWindowPlacement
SystemParametersInfoA
SetWindowPos
SetWindowLongA
GetMenu
CallWindowProcA
DefWindowProcA
GetDlgCtrlID
PtInRect
CopyRect
AdjustWindowRectEx
GetSysColor
RegisterClassA
GetClassInfoA
GetClassInfoExA
CreateWindowExA
GetMenuItemCount
GetMenuItemID
GetSubMenu
UpdateWindow
SetForegroundWindow
SetMenu
MapWindowPoints
GetMessagePos
GetMessageTime
GetTopWindow
GetForegroundWindow
GetWindowTextA
GetWindowTextLengthA
SetFocus
RemovePropA
GetPropA
SetPropA
GetClassNameA
GetClassLongA
GetCapture
WinHelpA
SendDlgItemMessageA
RegisterWindowMessageA
SetDlgItemTextA
IsDialogMessageA
SetWindowTextA
ShowWindow
TabbedTextOutA
DrawTextA
DrawTextExA
GrayStringA
ClientToScreen
ReleaseDC
BeginPaint
EndPaint
LoadCursorA
GetSysColorBrush
UnregisterClassA
DestroyMenu
CreateBitmap
GetClipBox
SetTextColor
SetBkColor
GetObjectA
SaveDC
RestoreDC
SetMapMode
DeleteObject
PtVisible
RectVisible
TextOutA
ExtTextOutA
Escape
SelectObject
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
SetWindowExtEx
ScaleWindowExtEx
DeleteDC
GetStockObject
GetDeviceCaps
GDI32.dll
ClosePrinter
DocumentPropertiesA
OpenPrinterA
WINSPOOL.DRV
RegCloseKey
RegQueryValueExA
RegOpenKeyExA
RegDeleteKeyA
RegEnumKeyA
RegOpenKeyA
RegQueryValueA
RegCreateKeyExA
RegSetValueExA
ADVAPI32.dll
OLEAUT32.dll
kernel32.dll
GetProcessHeap
ReadFile
GetLocalTime
lstrcmpiA
CreateMutexA
GetSystemDefaultLangID
GetAtomNameA
ExpandEnvironmentStringsA
GetUserDefaultUILanguage
.?AVCCNumSpinCtrlDemoApp@@
.?AVCWinApp@@
.?AVCWinThread@@
.?AVCCmdTarget@@
.?AVCObject@@
.?AVCCNumSpinCtrlDemoDlg@@
.?AVCDialog@@
.?AVCWnd@@
.?AVCSpinButtonCtrl@@
.?AVCNumSpinCtrl@@
.PAVCException@@
.?AVCCmdUI@@
.PAVCMemoryException@@
.?AV_AFX_THREAD_STATE@@
.?AVCNoTrackObject@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AVAFX_MODULE_STATE@@
.?AVCDllIsolationWrapperBase@@
.?AVCComCtlWrapper@@
.?AVCCommDlgWrapper@@
.?AVCShellWrapper@@
.?AV_AFX_BASE_MODULE_STATE@@
.?AVXAccessible@CWnd@@
.?AVXAccessibleServer@CWnd@@
.?AVCTestCmdUI@@
.?AV_AFX_HTMLHELP_STATE@@
.PAVCUserException@@
.?AV?$IAccessibleProxyImpl@VCAccessibleProxy@ATL@@@ATL@@
.?AUIAccessible@@
.?AUIDispatch@@
.?AUIUnknown@@
.?AUIAccessibleProxy@@
.?AV?$CMFCComObject@VCAccessibleProxy@ATL@@@@
.?AVCAccessibleProxy@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AUIOleWindow@@
.PAVCResourceException@@
.PAVCSimpleException@@
.PAVCObject@@
.?AVCSimpleException@@
.?AVCException@@
.?AVCResourceException@@
.?AVCUserException@@
.?AVCGdiObject@@
.?AVCDC@@
.?AVCPaintDC@@
.?AVCAfxStringMgr@@
.?AUIAtlStringMgr@ATL@@
.?AVCOleException@@
.PAVCOleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCMemoryException@@
.?AVCNotSupportedException@@
.?AVCInvalidArgException@@
.?AUCThreadData@@
.?AVCHandleMap@@
.?AVCMapPtrToPtr@@
.?AVCMenu@@
.PAVCArchiveException@@
.?AVCArchiveException@@
.?AVCObArray@@
.?AVCByteArray@@
Apartment
.?AV?$CArray@W4LoadArrayObjType@CArchive@@ABW412@@@
.?AVCPtrArray@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
wxr""/p
wr""/p
DDLLDDDL
LLDDLD
DDLDLD
LDDDDDDD
DDDDDDDDD
DDDDDDDDDDD
DDDDDDDDDDDDD
DDDDDDD
ozR1ML
oLLLLL
DDDDD@
wwwwwwwxp
"""""/
"""""/
wwwwwwww
zz1111MMM
^zz1111MM
^zz1111M
^zz1111
^zz111
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD=P
|y0iv}E?p
Roo6~~Ft
\jlV)v@
d$t=UcG
}b~c/{
[3d`s9
e>MIL'Z
D&0Q n
%{>M{r
(R#CUG
T_-{;.
;g]]Nu9
}z)K-;
iU}KUNV
;RytqV0
&1}JMk
RcavZF
*62ee$
6z#cfJ'X
gXujh$
pxmwB~'Q
M'e:iI
z+USIm
2-i]y`
n1MIQP
GrbCi!
^l U54
mq+TSz
,pV@|T
+1fJ&
-Rfb/NB
(t_vB&
TR1#=M9
WK{0G]
fT1?4JRP
36tK%M/
G$YWE*3
}..sko
ybvUdW
hP-rT]]2
96GRR5
Kr?&yb[h
[9?mNa
'f/=-v'B o
])pv'
kb*mD{
Y+;MtN
Ly;oz:
|~PVF5@
vE$%?W6
1~2md1>
UCanfs
|u,X{U[F
T},\nq^
~y+:,z
%D.h3[)
bOg19F
hl2_93
^l2_93
tMl2_93
tMl2_93
tMl2_93
FzW[MU
Qg.gID
uylh0O
sGt%d5Rg
:@v?@uBa='.(
'C~C9j
s+Y!#/QE
C*W>ey1
bMH}AI
e#O$F!J
l$gJ/Zk1|
/})}Jq
hC1?W
4`F537I
xAr%6@
w2KH$#
^R[{#Z=
RUleGo
-Hf[/V
jn\i:E4N
0tG+#i
Y$[K{)"
{:\t\c
:A#/6z
D:Ld -d
9!d(p;
dCsiO\
yDBi4/
rqZ@JaA
r0@8JY
Xx;XL-
Jxb$}{
:@v?@uBa
yj|r>
?Au.EH
%.]"@,6
M^]#UA+
\z%e?y
]\hey(Z
v^EcW!
<>yk#Q
(p0h:rq
*u2UX:
9kza4mo}d
E tv}^
PK-AAZM%Taq
t~rdc[/f
c?tt`T
:@v?@uBa;
j2'}0K
hUTs;|
8jfDy
m/=gWK
r)0m5W
{+o& lx
;mUNrmR
O(XRfr
>W<rii2
1_ToJp
;U-e.?
`.,rOE
nLzC\k
s>bTnoY_
nI/ss^
:?u|3<
uN5?4Z[^
f% YBTNS{U
GF;GTv
jXGrju
#0aW{W
8848"h
r7Cq(w
sW}'#)
,4|cG2 HqYl
cA&JIJ
tMl2_93
tMl2_93
phdW7J
BznXw{g
tM]$W
!WL5xG
Z#xF2B
)[L$$)a
~V8'<l
&l54D7S
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
w( +Y,7
v"i-?k
QQfqD%
~i\m+O
l2_93
[_vD/q
tMl2_93
tMl2_93
tMl2_93
tMl2_93
`|sA9C
)Kv3U#
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
sl2_93
WNf29$
tMl2_93
tMl2_93
G;?Kbcr]
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
ml2_93
>RU8ZOU
tMl2_93
C)'PmV4
tMl2_93
M'(;iG`
tMl2_93
tMl2_93
jl*-u6
nKwPg#4
MRw+l5
U]g#dV
|Ab-(i
lDU=US
-z'6>+=
_QG!dt
tMl2_93
tMl2_93
tMl2_93
k^a@UX
<J(QAg
iSq!X$
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
_=N{\CA
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
Akk?Rgwk
J}# >{,
:r~ItF
c,$m@9*
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
X>noLg
tMl2_93
7xSAl`ONZ
tMl2_93
tMl2_93
ap~1Bpu?,$G
nD)'Dd
tMl2_93
tMl2_93
&Va C~
*_lqI`t3 S
Z:XPoK
yQ(&evDZ
tMl2_93
tMl2_93
k^a@UX
wR1|FK+
k^a@UX
k^a@UX
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
3~rkl4
,VZCG$
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
7[zSCz
%ot#[s_
[kLc?A
*#_$:
(VUHt
Kmd#.uMS1
K9]%tD
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
Hl2_93
tMl2_93
tMl2_93
GEaYO8
7[zS0n$
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
nglR"!/
^W>^k4
^W>^k4
Y%p^[o
YEVb.'H
:OTkPm
[j*\'~
j#JB G'@^
891wT7
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
tMl2_93
YaccParent
accChildCount
accChild
accName
accValue
accDescription
accRole
accState
accHelp
accHelpTopic
accKeyboardShortcut
accFocus
accSelection
accDefaultAction
accSelect
accLocation
accNavigate
accHitTest
accDoDefaultAction
mscoree.dll
kernel32.dll
KERNEL32.DLL
p(null)
((((( H
h(((( H
H
phqghumeaylnlfdx
MS Sans Serif
ircvscxggb
kfnqdu
msctls_updown32
vsrtkjprepggxrpnrv
stmwcysy
cqpevike
fmznimkka
vwsrenzkycxfxtlsgy
sfadpooefxzbcoejuv
vaboygpoeylfpbnpljvrvipyamyehwqnqrqpmxu
jloovaowuxwhmsncbxc
zkvatx
knlyjyhfix
MS Shell Dlg
Cancel
MS Shell Dlg
lyhnkoaugzqrcddiuteiojwayy
Save As
All Files (*.*)
Untitled
an unnamed file
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Out of memory.
An unknown error has occurred.!Encountered an improper argument.
Incorrect filename.
Failed to open document.
Failed to save document.
Save changes to %1? Failed to create empty document.
The file is too large to open.
Could not start print job.
Failed to launch help.
Internal application error.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Enter an integer.
Enter a number.#Enter an integer between %1 and %2.!Enter a number between %1 and %2.!Enter no more than %1 characters.
Select a button.#Enter an integer between 0 and 255.
Enter a positive integer.
Enter a date and/or time.
Enter a currency.
Enter a GUID.
Enter a time.
Enter a date.
Unexpected file format.O%1
Cannot find this file.
Verify that the correct path and file name are given.Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
%1: %2
Continue running script?
Dispatch exception: %1
#Unable to read write-only property.#Unable to write read-only property.
#Unable to load mail system support.
Mail system DLL is invalid.!Send Mail failed to send message.
No error occurred.-An unknown error occurred while accessing %1.
%1 was not found.
%1 contains an incorrect path.8Could not open %1 because there are too many open files.
Access to %1 was denied.0An incorrect file handle was associated with %1.8Could not remove %1 because it is the current directory.2Could not create %1 because the directory is full.
Seek failed on %14Encountered a hardware I/O error while accessing %1.3Encountered a sharing violation while accessing %1.3Encountered a locking violation while accessing %1.
Disk full while accessing %1.$Attempted to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1.%Attempted to write to the reading %1.$Attempted to access %1 past its end.&Attempted to read from the writing %1.
%1 has a bad format."%1 contained an unexpected object. %1 contains an incorrect schema.
pixels
Uncheck
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
CTF Loader
FileVersion
10.0.17134.1 (WinBuild.160101.0800)
InternalName
CTFMON
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
CTFMON.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17134.1
OleSelfRegister
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
CTF Loader
FileVersion
10.0.17134.1 (WinBuild.160101.0800)
InternalName
CTFMON
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
CTFMON.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17134.1
OleSelfRegister
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.842b0d0eb01716a9
CAT-QuickHeal Clean
ALYac Backdoor.Agent.status
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.36318.wq3@amu@YVbi
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.GenericML.xnet
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen-Crypt.ccnc
ViRobot Clean
Avast Clean
Rising Trojan.Generic@AI.96 (RDML:j60fWFoEihUF5Rsl06HbAA)
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Trojan/Win32.Sonbokli
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan.Win32.GenericML.xnet
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!842B0D0EB017
TACHYON Clean
VBA32 suspected of Trojan.Downloader.gen
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Virus.Win32.CeeInject
MaxSecure Virus.Patched.OF
Fortinet W32/PossibleThreat
AVG Clean
DeepInstinct MALICIOUS
No IRMA results available.