Static | ZeroBOX

PE Compile Time

2023-07-28 01:33:47

PDB Path

D:\source work\ExeSmall\Release\arithmetic.pdb

PE Imphash

c89bd32d7beced586fcbabe7e651db83

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002b875 0x0002ba00 6.40119992053
.rdata 0x0002d000 0x00002958 0x00002a00 4.97292111396
.data 0x00030000 0x00001ac0 0x00000c00 2.70106761463
.rsrc 0x00032000 0x000004e0 0x00000600 4.59983322431
.reloc 0x00033000 0x00001156 0x00001200 3.45361106543

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000320a0 0x000002e4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00032384 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x42d000 ExitProcess
0x42d004 GetProcAddress
0x42d008 VirtualAlloc
0x42d00c LoadLibraryA
0x42d010 VirtualProtect
0x42d014 HeapAlloc
0x42d018 GetCommandLineW
0x42d01c HeapSetInformation
0x42d020 GetStartupInfoW
0x42d024 GetModuleHandleW
0x42d028 DecodePointer
0x42d02c WriteFile
0x42d030 GetStdHandle
0x42d034 GetModuleFileNameW
0x42d038 HeapCreate
0x42d03c EncodePointer
0x42d040 RaiseException
0x42d050 SetHandleCount
0x42d058 GetFileType
0x42d060 TlsAlloc
0x42d064 TlsGetValue
0x42d068 TlsSetValue
0x42d06c TlsFree
0x42d074 SetLastError
0x42d078 GetCurrentThreadId
0x42d07c GetLastError
0x42d088 GetTickCount
0x42d08c GetCurrentProcessId
0x42d09c LoadLibraryW
0x42d0a4 IsDebuggerPresent
0x42d0a8 TerminateProcess
0x42d0ac GetCurrentProcess
0x42d0b0 HeapFree
0x42d0b4 Sleep
0x42d0b8 HeapSize
0x42d0bc GetCPInfo
0x42d0c0 GetACP
0x42d0c4 GetOEMCP
0x42d0c8 IsValidCodePage
0x42d0cc RtlUnwind
0x42d0d0 WideCharToMultiByte
0x42d0d4 HeapReAlloc
0x42d0dc LCMapStringW
0x42d0e0 MultiByteToWideChar
0x42d0e4 GetStringTypeW

!This program cannot be run in DOS mode.
.rdata
@.data
@.reloc
^SSSSS
QQSVWh
j@j ^V
URPQQhpL@
t"SS9] u
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
'.IDATx
%o~eG}A
PZ9||
PZ9||
aPo=@[
,yv)Vf
DD~EIa
%=??S0-0
+S7hq(
Px7>!7yn
GdK>\-
K}>y+
.Rb'W\i
0miKze
w06>O{
,Ibekd
II(k'5
X1)K$j
V<;d]>
E^tZ()
>gKHY;
5AMoNR]
:{]U$af
!|uJ$J
7 8Lc?
kkp'-!
bTv^6O#
V:-%6@
S-+%[~
F9=cOS
irjj7?7
WIz`jI
y`YE<+X@Va
]D9|_<
RN`N'5L
J~crVB
969cV7
jKbY:!
c.Nr'2!
<Y'< *R
O?3~Ue
sK1;Id
4W$m6FL{
"QCUDFO
z)Z:gn
$+n8x F
-zsa2M\c
]cemk!
Tf\(H<<
w(z-fJ
*ztrM\
E3Oyat
#HWUJQpEt
c5384u
9yQF(H
~ SN<<
6ivz7e#5
c+%<\'
hJUj1I
85.:x`!o
OD6|'5
iS[yEA"{
yPaEb-
vHn6a=
e> }pq
n_e&R%
Fy73Uy
'FVD:`[
'x#KBW
`fz[ od-F
V'Z2qt};!
w4IdfD
v2yrVw
6dhu<<
kPA`P,
ZiC`}~
^SSr{3
:xT${_tG
Gr0vU/F
EhVKrR
o#DJ]
2mS=-;
M`;I$#
e@Y#LJ
1T7Paqz3
M?8~@*
!si }~<j=
2F*jC.
`#8LB*
FQ;4>wqNH
V"G>fPGk
R_[tE3
["b~"SM
AP~a>X
pwbSi8
z(NQ',o
6$SV\=
<oTM)\CfF
QF&M<'
gYK^%~
?1q,nt
xq?i'wWo
hqUh#4
{7:C_q
=iW"{i
sXujTS
v_JP}U
5+R~n1o
*Je/'D$
"j3M#X8
{BDGZWl=P
:.eK7NB
O6"XCwJ
'qura!JYW
K*Kv'B
galR0%
b#p.$.S
EY?ZG~z
eXIGT.
f@RQ?.>
?_>R,$^DH;
AxbpzZ
UgrJ]
|pJ4Ns
dO3pHs"9
'[<q1T
D4_V,1jn
$T~Yn}F
e"9{A5
.sS+/go
KTZa>/
H%Ydk
3^C#JVP
ci}D*%p
nBfPPD<P
*pv6j=
v5g[c*
i`nCOz5%
wnVuIY
DjJp_
Qb3t0v
If<m$
;3Zz&f
tK!"Ki{I
@ip#b
vTs<[bH
}hP`u*
oXfZv
{{UE'T}
j5Kpq5H
&qJlQ
j.&2$|V
\:"e0)2
&#8^q$w
oR8Ay5
"ajYgnmS
]s |^
`7jR8|L=9X
0^m@H*
mJQ|w
fGI $Z
7(9sgA
A*kU:
kUn:n{
O#,RC9d]t
>])8f7
of2J)]
l:tVVS
bad allocation
CorExitProcess
Unknown exception
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
D:\source work\ExeSmall\Release\arithmetic.pdb
ExitProcess
GetProcAddress
VirtualAlloc
LoadLibraryA
VirtualProtect
KERNEL32.dll
HeapAlloc
GetCommandLineW
HeapSetInformation
GetStartupInfoW
GetModuleHandleW
DecodePointer
WriteFile
GetStdHandle
GetModuleFileNameW
HeapCreate
EncodePointer
RaiseException
SetUnhandledExceptionFilter
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
EnterCriticalSection
LoadLibraryW
UnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
HeapFree
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
WideCharToMultiByte
HeapReAlloc
IsProcessorFeaturePresent
LCMapStringW
MultiByteToWideChar
GetStringTypeW
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
7(7M7\7d7q7}7
:!:,:4:D:J:[:
;%<=<G<b<j<p<~<
>$>6>C>I>p>
>#?6?d?}?
=0B0K0Z0}0
23\3k3
3\5h5n5s5y5
9!9*969<9D9J9V9\9i9s9y9
9 :&:P:V:\:r:
:*;M;W;
<#<)<1<8<=<E<N<Z<_<d<j<n<t<y<
= =&=>=a=~=
>>?X?{?
0+090?0b0i0
282>2F2
2X3a3g3
5T5[5h5n5
8&8,868<8F8O8Z8_8h8r8}8
='=3=l=u=
=,>D>K>S>X>\>`>
>:?@?D?H?L?
070i0p0t0x0|0
2q243b3
7[7c7x7
;!;=;F;L;U;Z;i;
=>%>+>1>7>=>D>K>R>Y>`>g>n>v>~>
?X?^?h?
070O1T1
5+5Q5c5u5
*818<8Q8\8c8g8l8
1\1`1d1$:,:4:<:D:L:T:\:d:l:t:|:
0@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
1 1(1@1D1\1l1p1
2 242<2P2l2p2
3 3<3@3`3|3
1034383<3@3D3H3L3P3T3x3|3
4 4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
485H5X5h5x5
;(;,;0;4;8;<;@;D;H;P;T;p;
Codemasters
Horizon is at wrong depth, but only by a little.
2000-12-14 00:00:00
Codemasters
SIMULATIONS/RACING
Colin McRae Rally 2.0(CMR2Demo.exe)
2012-07-31 00:00:00
Planetside 2
Sims 3: World Adventures Expansion Pack
Zhong Jie Zhe 2
Monsterx
InnovMetric PolyWorks
HUD Items at various depths
2001-07-17 00:00:00
Mightygames
SIMULATION
Jumpgate Evolution
Conan Exiles
Obduction
Go to: Main menu: Options: Set graphics to low. Some objects render at the wrong depth. Some cutscenes render out of screen.
Jagged Alliance
Dungeon Defenders 2
Planet Moon Studios
Crosshair is 2D
2000-11-27 00:00:00
Interplay
ACTION/SHOOTER
Giants Citizen Kabuto(Giants.exe)
Go to - options: graphics tab Set Grass quality to Low Set Shadow Map Size to off
2009-04-23 00:00:00
ElvenLegacy
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
alpha-blend LLC
FileVersion
10.0.22621.1635 # Private BuildEdition
InternalName
arithmetic.dll
LegalCopyright
Copyright (C) 1997-2023 Cermane Baplit. Portions Copyright (C) 2000-2023 Addi Matter.
OriginalFilename
arithmetic.dll
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.68397371
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Spyware.Stealer
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.68397371
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.FMAG-4512
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Win32/PSW.Agent.ONW
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.98 (RDML:AELJH4wlJUs4KQeE3+HAeA)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.68397371
TrendMicro TrojanSpy.Win32.STEALC.YXDG2Z
McAfee-GW-Edition BehavesLike.Win32.Infected.ch
Trapmine Clean
FireEye Generic.mg.d6067ce0e193dd31
Emsisoft Trojan.GenericKD.68397371 (B)
Ikarus Clean
GData Trojan.GenericKD.68397371
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Trojan/Win32.Sabsik
Gridinsoft Ransom.Win32.Sabsik.cl
Xcitium Clean
Arcabit Trojan.Generic.D413A93B
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Vidar.RAN!MTB
Google Detected
AhnLab-V3 Malware/Win.Generic.C5462103
Acronis Clean
McAfee Artemis!D6067CE0E193
MAX malware (ai score=81)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.STEALC.YXDG2Z
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.