Static | ZeroBOX

PE Compile Time

2023-03-17 06:18:49

PE Imphash

8e4ac255f5ef2adac99344450f27e6ce

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00048f2f 0x00049000 6.4576582113
.rdata 0x0004a000 0x000126f0 0x00012800 5.37773228198
.data 0x0005d000 0x00002764 0x00000c00 2.45032511605
.pdata 0x00060000 0x00004308 0x00004400 5.70105620459
.rsrc 0x00065000 0x0002b060 0x0002b200 7.77224067439
.reloc 0x00091000 0x000007c0 0x00000800 5.32535725426

Resources

Name Offset Size Language Sub-language File type
TZU 0x00065ba0 0x00029e00 LANG_ENGLISH SUBLANG_ENGLISH_US data
TZU 0x00065ba0 0x00029e00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0008fe98 0x00000048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0008f9a0 0x000004f4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0008fee0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x18004a038 OutputDebugStringA
0x18004a040 SetFilePointerEx
0x18004a048 GetConsoleMode
0x18004a050 GetConsoleCP
0x18004a058 FlushFileBuffers
0x18004a060 WriteFile
0x18004a068 SetStdHandle
0x18004a070 OutputDebugStringW
0x18004a078 HeapSize
0x18004a080 GetStringTypeW
0x18004a088 SetConsoleCtrlHandler
0x18004a090 GetFileType
0x18004a098 GetStdHandle
0x18004a0a0 GetProcessHeap
0x18004a0a8 SetEnvironmentVariableW
0x18004a0b0 SetEnvironmentVariableA
0x18004a0b8 CloseHandle
0x18004a0c0 WaitForSingleObjectEx
0x18004a0c8 CreateThread
0x18004a0d0 WriteConsoleW
0x18004a0d8 CreateFileW
0x18004a0e0 HeapReAlloc
0x18004a0e8 ExitProcess
0x18004a0f0 FreeEnvironmentStringsW
0x18004a0f8 GetEnvironmentStringsW
0x18004a100 GetCommandLineW
0x18004a108 GetCommandLineA
0x18004a110 GetCPInfo
0x18004a118 GetOEMCP
0x18004a120 GetACP
0x18004a128 IsValidCodePage
0x18004a130 FindNextFileW
0x18004a138 FindNextFileA
0x18004a140 FindFirstFileExW
0x18004a148 FindFirstFileExA
0x18004a150 FindClose
0x18004a158 UnhandledExceptionFilter
0x18004a168 GetCurrentProcess
0x18004a170 TerminateProcess
0x18004a180 IsDebuggerPresent
0x18004a188 GetStartupInfoW
0x18004a190 GetModuleHandleW
0x18004a198 QueryPerformanceCounter
0x18004a1a0 GetCurrentProcessId
0x18004a1a8 GetCurrentThreadId
0x18004a1b0 GetSystemTimeAsFileTime
0x18004a1b8 InitializeSListHead
0x18004a1c0 RtlUnwindEx
0x18004a1d0 InterlockedFlushSList
0x18004a1d8 GetLastError
0x18004a1e0 SetLastError
0x18004a1e8 EncodePointer
0x18004a1f0 RaiseException
0x18004a1f8 EnterCriticalSection
0x18004a200 LeaveCriticalSection
0x18004a208 DeleteCriticalSection
0x18004a218 TlsAlloc
0x18004a220 TlsGetValue
0x18004a228 TlsSetValue
0x18004a230 TlsFree
0x18004a238 FreeLibrary
0x18004a240 GetProcAddress
0x18004a248 LoadLibraryExW
0x18004a250 RtlPcToFileHeader
0x18004a258 GetModuleHandleExW
0x18004a260 GetModuleFileNameA
0x18004a268 GetModuleFileNameW
0x18004a270 MultiByteToWideChar
0x18004a278 WideCharToMultiByte
0x18004a280 GetCurrentThread
0x18004a288 GetDateFormatW
0x18004a290 GetTimeFormatW
0x18004a298 CompareStringW
0x18004a2a0 LCMapStringW
0x18004a2a8 GetLocaleInfoW
0x18004a2b0 IsValidLocale
0x18004a2b8 GetUserDefaultLCID
0x18004a2c0 EnumSystemLocalesW
0x18004a2c8 HeapAlloc
0x18004a2d0 HeapFree
Library USER32.dll:
0x18004a2e0 GetGestureInfo
0x18004a2e8 InvalidateRect
0x18004a2f0 ScreenToClient
0x18004a2f8 CloseGestureInfoHandle
0x18004a300 EndPaint
0x18004a308 BeginPaint
0x18004a310 UpdateWindow
0x18004a318 PostQuitMessage
0x18004a320 LoadCursorW
0x18004a328 TranslateMessage
0x18004a330 TranslateAcceleratorW
0x18004a338 SetGestureConfig
0x18004a340 ShowWindow
0x18004a348 GetMessageW
0x18004a350 DefWindowProcW
0x18004a358 DestroyWindow
0x18004a360 CreateWindowExW
0x18004a368 RegisterClassExW
0x18004a370 LoadStringW
0x18004a378 DispatchMessageW
Library GDI32.dll:
0x18004a000 Polyline
0x18004a008 LineTo
0x18004a010 CreatePen
0x18004a018 MoveToEx
0x18004a020 DeleteObject
0x18004a028 SelectObject
Library ntdll.dll:
0x18004a388 NtQueueApcThread
0x18004a390 ZwOpenSymbolicLinkObject
0x18004a398 LdrFindResource_U
0x18004a3a0 NtAllocateVirtualMemory
0x18004a3a8 atoi
0x18004a3b0 sin
0x18004a3b8 LdrAccessResource
0x18004a3c0 __C_specific_handler
0x18004a3c8 RtlCaptureContext
0x18004a3d0 RtlLookupFunctionEntry
0x18004a3d8 RtlVirtualUnwind
0x18004a3e0 memset
0x18004a3e8 NtTestAlert
0x18004a3f0 strchr
0x18004a3f8 wcschr
0x18004a400 strrchr
0x18004a408 _local_unwind
0x18004a410 memcmp
0x18004a418 cos
0x18004a420 floor

Exports

Ordinal Address Name
1 0x180047d00 AFxNCNDhpJUjLGSUBdyJAlirW
2 0x180047cd0 APgLpQbnGOFg
3 0x180048270 AaVQghYMoDvlcIkoDhwOzm
4 0x180048380 AbGiqsZapYXQEJBQNrWj
5 0x180047d70 AcIMOdUMWKfNaHjlQaJhaKDTvv
6 0x180047d10 AjmdNJiPaRsRtAqadcjQnlCAvv
7 0x180047620 AmhroJJBvgsvk
8 0x180047d40 BdxxRGs
9 0x1800481b0 BgAFcJi
10 0x180047710 BlIVCeEMUhTYUniUkHlJscB
11 0x1800475f0 BleGyOkIaepldUi
12 0x1800474e0 BoepXZDDjhOrSbcuQncJB
13 0x180047f00 BpzeaEnGa
14 0x180047f70 BwCjRp
15 0x1800478f0 CFIstcx
16 0x180047e80 CJsqCnAMpj
17 0x180047f20 CNPpdSVcuSzviIZhvCWSTfhZ
18 0x180047bc0 COOXnQoQSaTGSpWIAaSzo
19 0x1800483f0 CSUruSgGDFRVUvVHcTu
20 0x180047d50 CTCQAClHYzuiPWfwqyQYV
21 0x180047dd0 CeHgsCxOuoDTDrP
22 0x180048170 CpbkGyHjPVYKKbevwuabtfos
23 0x180047e10 DIczDdVVlD
24 0x180048290 DXtcAMkZFB
25 0x180048460 DahoeOjCy
26 0x180048420 DdmfNyLzGBEZdhjuVaLnGLAC
27 0x180048a60 DllRegisterServer
28 0x1800475e0 EDirxlezljynQMb
29 0x1800481a0 EJrkYuGqWKJxcbkEWFxWuj
30 0x180048210 EOCBExEDvmpuiTSdISaFTJpbnD
31 0x1800483b0 ERdHSxbrluXBmlg
32 0x180047c50 EWqRXzEYZJPwDvIiOC
33 0x180048080 EbquiojgkxAH
34 0x180047f90 EjCrzK
35 0x1800476b0 FSJZHjqXtVCcouB
36 0x180047be0 FmgnZSs
37 0x180047da0 FwGMzFvmlRhqfdgYj
38 0x180047e20 GEakZdngEgkQEMUw
39 0x180048440 GIucseXHMrRrXPFeKw
40 0x180047680 GNoduqRICMxxYLScjzRR
41 0x1800481f0 GTdkEFQtZIyifVPtMw
42 0x180047b40 GUUIOYFVBkCRKKGPM
43 0x180047690 GabGyY
44 0x180047790 GlmIPNFEUxGfzccoGbGvt
45 0x180048090 GqxGeRkjCFW
46 0x180047600 GrnXAG
47 0x180047ba0 GsRUyGCvRhXYbBNdoXgMoD
48 0x1800483a0 GyQSbTrVGUQXgOfZOvlwGGJOZ
49 0x180047a90 HCaLEQxCPhokiggZc
50 0x180047c90 HETlXz
51 0x180047c30 HRQNzHLCNHYjXY
52 0x1800481d0 HbOXELXYC
53 0x180047ff0 ISKZiApGwwqfPxyvDE
54 0x180047840 IcSKMpKalYoTBtNC
55 0x1800481e0 IprhqRmUjfLjdAvaVSyh
56 0x180047920 IsZFDjJYWWGraQqQsCIojuoPI
57 0x180047500 ItCdjvWTgdRQjqKEojXISZB
58 0x180047800 JEVIhwFBZItxqXVhyUDXDtvW
59 0x1800475b0 JEhcfsFJLI
60 0x180047b10 JhsVgkWwuNGjkVJBv
61 0x180047a50 JiXLWADK
62 0x180048110 JkvQVFXLk
63 0x180047df0 JqTVuEmdOv
64 0x180048310 JuvMSMMEvEF
65 0x180047aa0 KDwYBJCicCZzRoOZ
66 0x1800477e0 KLAfQsdsaKGHSrQOYTMpVzgK
67 0x180047570 KSnZqpvzTNl
68 0x180048340 KWfbJvRFrOV
69 0x180047b80 KcugiBMUcgjkCqc
70 0x180047ac0 KidKIFrYdPHAre
71 0x180047e70 KlkHRlyspyEbCqaAF
72 0x1800481c0 KtJgAGRGyADIhGc
73 0x180047e40 LGWXmeQgMABu
74 0x180048330 LGyzhOBlGMKKEiSyBNOA
75 0x180047f50 LUjVXvmpjLkwIEYtcKcCx
76 0x180047830 LebFCnlzbXtrrLdB
77 0x180047740 LsyMBhredZBvk
78 0x180047ca0 LtFyFAsWliacGsTGXqjeeLvK
79 0x1800476c0 MBYEluvEyDzsC
80 0x1800478e0 MHJytDnaUPMzueb
81 0x180047d60 MRAAdjwmnMsgXIeyxsstimL
82 0x180047b60 MTyYvXrFDEVJRoIKFwFl
83 0x180048160 MXvGmOYJBUNcUhrUCfuEpj
84 0x1800478d0 MZrxiTTzjWhcxLrlJk
85 0x1800477d0 MdAKHWoLiTGZE
86 0x180048200 MoEtlGhIUoAqzlzsWDD
87 0x180047730 MxxORRnm
88 0x180048060 NDUAXvzsdeydywwRNMHWRJGK
89 0x180047b20 NTSxfMIpNzhwDaIYTg
90 0x180047a60 NUIiQUpkB
91 0x180047670 NdojhsEWJXelkYgY
92 0x180047bf0 NqNktJurxEPsSVvLgoiCKI
93 0x180047ce0 OBviaeAmDhEKB
94 0x180047760 OPTztDwnXmUalz
95 0x180047af0 OarYXdaVMs
96 0x1800482f0 OuaaSMDdKAHJBSI
97 0x180047fb0 OxtFZQuvLvXO
98 0x180047990 PJPUWySrtcFnoU
99 0x1800479d0 PkrxWwd
100 0x180047630 QBzgDamuPMHnmBmxqsemB
101 0x180048130 QIPgSlrJ
102 0x180047b00 QdXiEwjVRvwsA
103 0x180047fd0 QkJCVvrpO
104 0x1800483d0 QlKOChPtGkCgueNfMfmE
105 0x180047de0 RgpZIjoS
106 0x180048190 RyWPRDWAZokSpgjdX
107 0x1800477b0 RzInNvLFbXSrZs
108 0x180048020 SBVACGqdL
109 0x180047ea0 SEXaxJE
110 0x180048320 SRIMcYcgmQzv
111 0x180047fc0 SVExPilkWeEdOmPKxmE
112 0x180047590 SshJfgldnoPmDiuzthDwd
113 0x180047ab0 SvDHpIXg
114 0x1800477f0 THleRyMKuvcwAptfFoQK
115 0x180047f10 TTMslvZRPDHsOsrU
116 0x180047580 TYDISaLzbh
117 0x180047780 UCcbUfpvn
118 0x180047860 USnHmXWDgJkTuRXnXRjn
119 0x180047850 UUHotoQypbMRPBbQhwXJ
120 0x180047750 UViPeuVtuJLKc
121 0x180048470 VBkQTrbKGhVfQhRTgXMjbrfiaA
122 0x180047980 VFhGvlPGsQhxHtTvhSxKcY
123 0x1800482e0 VMzeZLRonjcnd
124 0x180047c00 VvcxTjnHmbhTuwSu
125 0x180048450 WNjGlSlYPJjasDjMnceJuoqnOl
126 0x180047c10 WOmHhVXU
127 0x180047820 WWcFKCS
128 0x180047520 WghExnDSDsHbsIsQUpcOxNq
129 0x180047b50 WxdatBbzivhjgPXiraHxWOM
130 0x180047e30 XAcTVarCmGzF
131 0x180047950 XAqsrMHoZFRaFCiaysvzy
132 0x180047d20 XIXyiQCQ
133 0x1800476a0 XQVwoczNAXAPbeZcjruIA
134 0x180047dc0 XatHkgeISNp
135 0x180048000 XpoUhKqoThkn
136 0x180047b90 YDFhjgerDlMLHVuXkSGEv
137 0x180047f60 YDKNGzOAPZlebFJpomRMxWNWg
138 0x180048050 YFhZJoLhPOxEKBaBTzdVAs
139 0x180048040 YMAJlulpbXVSpmjWQoONYi
140 0x180048070 YQhjFQTZKDC
141 0x1800482b0 YVgAZYazoRsKAdHqUTqkgZq
142 0x1800483e0 YkervHFfkUmQ
143 0x180048220 ZlZscmMrWi
144 0x180048350 ZmdBIuhvLHIhsHYfrVvyNMOd
145 0x1800480a0 aWbGhfFeswwmRPshquqsl
146 0x180047650 aloTparayLO
147 0x1800479e0 amdrEpsU
148 0x1800478a0 bQQBvUQww
149 0x180047db0 bVWsKcmDpbKTsnGSXiKxM
150 0x1800475d0 beHDhlBgUZsmJPexvSQKWCSKnW
151 0x1800477a0 brphqpZlLTLruTZptc
152 0x180047a00 bwgKjSDuHKhDy
153 0x1800476e0 cEmuUSbtGzsPAWGLdEauFU
154 0x1800475c0 cZCtvLKOxGXeuQWS
155 0x180047bd0 ccdfvrWFVeOtkqurRNVLro
156 0x180047b70 ceebsfNkbprRYc
157 0x180048010 cjGWSR
158 0x180047e50 cnuLgsUOwrPiw
159 0x180047930 dKIpmirT
160 0x180047540 dWSStgetesFZgKWUlQPKU
161 0x180048140 dnXDSBiTBWy
162 0x180047ef0 doAVSHUlJOFKbCQnzEW
163 0x180048390 dsZUCLcbYUzqmmD
164 0x180047c80 eGrZsXv
165 0x180047a10 fFODoRkFUnPhPoFzbafui
166 0x180048180 fZITkvmvMdUvysq
167 0x1800479f0 fnQaoYOUVI
168 0x180048150 fobQqObMbQikgyImDguWIsSqjW
169 0x1800480d0 fvnKblUjOPABvhy
170 0x180047940 gHaJYcXzizzOUSXyHhzXij
171 0x180047c20 gVVLvY
172 0x180047720 gYsqbdDRcVuEYq
173 0x180048410 gkKTzQjnWeBVBmdNP
174 0x180047a30 hYVSsGvvkQKPjqcuHGhHnYbA
175 0x1800480b0 hdCnmtITRRiwGbqpRVNVj
176 0x180048030 hgmXlQGHxqVCPqrOlJgdTzKjmy
177 0x180047a70 hmUYZEkqsD
178 0x180047cf0 hnPgQMKxfZHj
179 0x180047c70 hrxRKGrcsUQAxyvDxBdrVDpeiV
180 0x1800475a0 hyuMoli
181 0x180047c60 hzuYAENAOWXcCMPPwupdAT
182 0x180047660 iDKwhD
183 0x180047910 iLpIoCoOGqSLknWShpOrXAuKw
184 0x180047d90 iYwAhnXpbSUzlmHnmKQLjmmXK
185 0x180047900 idYAJoIIJgaqEeHFdg
186 0x180047870 ifPZCTSHPzCTdOekgUaxrQHYuc
187 0x180047c40 ixhaskjGAZPmibXdKZvYtk
188 0x180047fe0 ixlbCgxrYjUWwQkziPixAHKEBS
189 0x1800478c0 jKcyyPRaYIKARbKLutjxMJNS
190 0x180048370 jNWPvYbBEhWjWSkVPtU
191 0x180047770 jfNeLGJbrBNgcJglu
192 0x180047a80 jlLkWHkPXzdlBWKxH
193 0x180048260 kOjPaBJwhKOkyyEkfyJDAZvEgX
194 0x1800478b0 kSACSUJ
195 0x180047ec0 keQAVKXtmULHuOImJnBpdef
196 0x180048360 lErkuJeOFVOTsm
197 0x1800480c0 lhaXGZqTpNIGy
198 0x180048100 meuEhwBKCbfkejUqzTJjdKD
199 0x180047e90 mfNRni
200 0x180048240 mhUamrXpNTQoqAXBAOdni
201 0x180047cb0 mnIEDKk
202 0x180047890 mrDsuVk
203 0x180047510 nEGgbfNwyEuu
204 0x180047610 nGvRmUygfURBUP
205 0x180047fa0 oqvDWjwIAJzWpnG
206 0x180048300 osgOmxsPqdsdPKyVAAI
207 0x1800479c0 oxavVlwWCBrupyASASSutRHKF
208 0x1800480f0 pEJxpRWmhWgptnfFGEVk
209 0x180047970 pUkHWIGVsMnGAg
210 0x180048250 pfTZxt
211 0x180047d80 qDYXLQXI
212 0x180047ae0 qNjfExouMwyiEVRAxF
213 0x180047a20 qWDwMV
214 0x180047bb0 qapxTEwK
215 0x180047ad0 qhNODbIuKwAidWpM
216 0x180047cc0 qndJteadmvKtwtX
217 0x180047a40 rBfJGBNajQh
218 0x1800474f0 rSkbfbenMNaD
219 0x180048430 rZemjjNLjMchLkQfeDUbbzpm
220 0x1800477c0 rcIMrQ
221 0x1800482d0 rlylMbEyTzmhBhMnsDWGjHrGZm
222 0x180047f40 skxWqECeFacKy
223 0x180048280 tEUCHIYiCUXq
224 0x1800479a0 tGglDMKXeMQhJtvQKRDRYth
225 0x180047530 tiZBMlcH
226 0x180047560 tuTdavYyrkmrqttj
227 0x1800482c0 tusJWJatGAjHQ
228 0x180047960 uAYOOXzsVtedIEB
229 0x180048400 uITvpyYWxWdxFIyrNcapZqG
230 0x1800483c0 uNuWYXNzTxyYiYCxISZFREssT
231 0x180047b30 uYqFfsiZigpJTLvHeRJSzRJ
232 0x180047810 uisBqJhQtDhrUvJXqoNzC
233 0x180047e60 ulGorqIa
234 0x1800482a0 ulLWzRKIaihpUWldzULuQvs
235 0x180047ed0 uxWnjhMRdalMeIJVVXvepyLQST
236 0x180047550 uzhPwfneAafRTwZNOMlbtoLv
237 0x180047640 vzJKCHMTTJNRLftltdRzpgG
238 0x180047700 wXfbObReo
239 0x1800476f0 wdgRqjrlxLcZ
240 0x180047d30 woilPxqxjb
241 0x1800476d0 xFhlmQwlqWlunaXSAGTJZgm
242 0x180047e00 xpkNqPyEjlUhxYeMh
243 0x180047f30 yMJBOjjpGcaArcbwYVksQ
244 0x180047880 yQMmxxuzvesyFjnQWZeF
245 0x180047eb0 ySqQLXYBVIeML
246 0x1800480e0 ybQKUWgVxypfnYzfV
247 0x180048120 yjlEMfeHtJJufvAhijuftNF
248 0x180047ee0 ymFmaPktGszCn
249 0x180048230 yshKYdVQRI
250 0x180047f80 zJRSMdlcrlWvknxiExxY
251 0x1800479b0 zOroUYHqtGnEfcUvuhlrsOvr
!This program cannot be run in DOS mode.
Richu%L
`.rdata
@.data
.pdata
@.rsrc
@.reloc
|$ AVH
D$H9D$ s"
u0HcH<H
H3E H3E
H3E H3E
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
@A_A^A]A\_^]
UAVAWH
L$XA9H
H;xXu5
WATAUAVAWH
(D$0fA
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
AUAVAWH
;I9}(tiH
0A_A^A]
AUAVAWH
;I9}(tiH
0A_A^A]
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
D;l$du
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
ri9O vdH
WAVAWH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAWH
L!|$(L!|$0D
A_A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
SVWATAUAVAWH
HcD$|L
LcD$|L
A_A^A]A\_^[
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
t`H91u
UVWATAUAVAWH
A_A^A]A\_^]
d$ UAVAWH
D8 t_3
M9&toA
<0t/<2t
|$ UAVAWH
WtHv:A
D$X$$h
UVWATAUAVAWH
|$(D88
D88t'H
D88tEH
\$8D8|$@t$L
\$8D8|$ t$L
D8|$(t
uuL9:tf
uDM99t?H
A_A^A]A\_^]
UAVAWH
<1~1<3~$<4t9<5t
x UATAUAVAWH
D8)u#L
)u!D8)t
D8(tXH
M9/tJE
A_A^A]A\]
UWATAVAWH
A_A^A\_]
<Kt!<L
UAVAWH
@A_A^]
L97tzH
\$ D8t$(uhH
x UAVAWH
L9|$ t7@
UATAUAVAWH
A_A^A]A\]
L$ SUVWH
fffffff
u3HcH<H
UVWAVAWH
0A_A^_^]
UVWAVAWH
0A_A^_^]
x ATAVAWH
A_A^A\
fD9!u7A
UVWAVAWH
0A_A^_^]
UVWAVAWH
0A_A^_^]
WAVAWH
A86taH
0A_A^_
WAVAWH
fA96tdH
fA94nu
0A_A^_
L$ WATAUAVAWH
@A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
ATAVAWH
0A_A^A\
UVWAVAWH
A_A^_^]
t$ UWATAVAWH
D8d$pt
A_A^A\_]
UVWAVAWH
A_A^_^]
t$ UWATAVAWH
D8d$pt
A_A^A\_]
UVWAVAWH
A_A^_^]
t$ UWATAVAWH
D8d$pt
A_A^A\_]
D$@H;G
D$@H;G
D$@H;G
D$@H;G
D$@H;G
D$@H;G
D$0H;G
D$0H;G
D$0H;G
D$0H;G
D$0H;G
D$0H;G
S,, <Zw
CA< t(<#t
WAVAWH
S,, <Zw
CA< t(<#t
A_A^_
S,, <Zw
CA< t(<#t
S,, <Zw
CA< t(<#t
WAVAWH
S,, <Zw
CA< t(<#t
A_A^_
S,, <Zw
CA< t(<#t
x ATAUAVH
A^A]A\
x ATAUAVH
A^A]A\
AA< t(<#t
AA< t(<#t
AA< t(<#t
AA< t(<#t
AA< t(<#t
AA< t(<#t
<htr<jtb<lt6<tt&<wt
!,X< w
<htr<jtb<lt6<tt&<wt
!,X< w
<htr<jtb<lt6<tt&<wt
!,X< w
<htr<jtb<lt6<tt&<wt
!,X< w
<htr<jtb<lt6<tt&<wt
!,X< w
<htr<jtb<lt6<tt&<wt
!,X< w
t$ WAVAWH
s4+sP+
0A_A^_
t$ WAVAWH
s4+sP+
0A_A^_
t$ WAVAWH
s4+sP+
0A_A^_
t$ WAVAWH
s4+sP+
0A_A^_
t$ WAVAWH
s4+sP+
0A_A^_
t$ WAVAWH
s4+sP+
0A_A^_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
|$ AWH
|$ AWH
t$ WATAVH
A^A\_
t$ WATAVH
A^A\_
t$ WATAVH
A^A\_
t$ WATAVH
A^A\_
D$8HcO(H
D$8HcO(H
D$8HcO(H
D$8HcO(H
WAVAWH
A_A^_
t$ WAVAWH
A_A^_
x ATAVAWH
A_A^A\
WATAUAVAWH
A_A^A]A\_
WATAWH
0A_A\_
x ATAUAWH
0A_A]A\
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
'D8l$@
t)D8l$@t
WD8l$@t
D8l$@t
A_A^A]A\_
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
f;\$ts
rsf;\$
r_f;\$,
rKf;\$<
r7f;\$L
r#f;\$\s
f;\$ds
f;\$(r
f;\$0r
rvf;\$
rbf;\$,
rNf;\$<
r:f;\$L
r&f;\$\s
f;\$ds
A_A^A]A\_
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
fA9<Bu
fC9<hu
A_A^A]A\_^]
x ATAVAWH
0A_A^A\
WATAUAVAWH
fD9,yu
0A_A^A]A\_
\$ UVWAVAWH
A_A^_^]
@8|$^t
\$ UVWAVAWH
A_A^_^]
f9|$^t&f
f9|$`t
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
UVWATAUAVAWH
tPH95Y
0A_A^A]A\_^]
I96t4H
xWI96tRI
@8t$p@
WATAUAVAWH
0A_A^A]A\_
I96t:H
fB94`t
xWI96tRI
fC94wu
t{H9/tQL
L97t5H
fD94pt
fD9t$b
SVWATAUAWH
HA_A]A\_^[
L98u&H
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
I9\$ ~@H
WAVAWH
fE98t'
0A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
?Cu0f9w
fD9<Xu
fD9?t&
fA9<\u
x ATAVAWH
A_A^A\
L$ SUVWH
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
^fD9+t
A_A^A]A\_^]
\$ UVWATAUAVAWH
A_A^A]A\_^]
f9\$bu
H9L$Ht?H
l$ WAVAWH
A_A^_
@UATAVH
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@8l$Ht
ATAVAWH
0A_A^A\
|$ AVH
WAVAWH
@A_A^_
s WATAUAVAWH
9t$P~58
A_A^A]A\_
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
l$ VATAUAVAWH
A_A^A]A\^
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
|$ UATAUAVAWH
A_A^A]A\]
fB9<Hu
fB9<@u
fB9<Bu
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
f9)uTH
f9)u H
fB94Ou
tVf91tQH
x ATAVAWH
A_A^A\
x ATAVAWH
fD9 tMH
fG9$Ou
0A_A^A\
fB9<Hu
fB9<@u
fB9<Bu
WAVAWH
fD9<Au
fF9<qu
tSf91tNH
S;\$0tH
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
@USVWATAUAVAWH
e8A_A^A]A\_^[]
WAVAWH
fA94Nu
0A_A^_
H!D$ I
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
@UAVAWH
e0A_A^]
@SUVWATAVAWH
A_A^A\_^][
ffffff
fffffff
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
@8|$Pt
@8|$Pt
@8l$8t
D8t$8t
|$ ATAVAWH
\$@@8=
A_A^A\
USVWAVH
A^_^[]
USVWAVH
A^_^[]
u1!D$0H
UVWATAUAVAWH
0A_A^A]A\_^]
x UAVAWH
H9\$0v<
H;D$0r
|$ AVHcA<E3
u"HcMHH
Unknown exception
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
template-parameter-
generic-type-
`anonymous namespace'
`non-type-template-parameter
`template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char16_t
char32_t
wchar_t
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
volatile
const
cli::array<
cli::pin_ptr<
{flat}
CorExitProcess
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetActiveWindow
GetCurrentPackageId
GetDateFormatEx
GetEnabledXStateFeatures
GetFileInformationByHandleEx
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
SetThreadStackGuarantee
SystemFunction036
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
log10f
_hypot
_nextafter
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
MTGestures.dll
AFxNCNDhpJUjLGSUBdyJAlirW
APgLpQbnGOFg
AaVQghYMoDvlcIkoDhwOzm
AbGiqsZapYXQEJBQNrWj
AcIMOdUMWKfNaHjlQaJhaKDTvv
AjmdNJiPaRsRtAqadcjQnlCAvv
AmhroJJBvgsvk
BdxxRGs
BgAFcJi
BlIVCeEMUhTYUniUkHlJscB
BleGyOkIaepldUi
BoepXZDDjhOrSbcuQncJB
BpzeaEnGa
BwCjRp
CFIstcx
CJsqCnAMpj
CNPpdSVcuSzviIZhvCWSTfhZ
COOXnQoQSaTGSpWIAaSzo
CSUruSgGDFRVUvVHcTu
CTCQAClHYzuiPWfwqyQYV
CeHgsCxOuoDTDrP
CpbkGyHjPVYKKbevwuabtfos
DIczDdVVlD
DXtcAMkZFB
DahoeOjCy
DdmfNyLzGBEZdhjuVaLnGLAC
DllRegisterServer
EDirxlezljynQMb
EJrkYuGqWKJxcbkEWFxWuj
EOCBExEDvmpuiTSdISaFTJpbnD
ERdHSxbrluXBmlg
EWqRXzEYZJPwDvIiOC
EbquiojgkxAH
EjCrzK
FSJZHjqXtVCcouB
FmgnZSs
FwGMzFvmlRhqfdgYj
GEakZdngEgkQEMUw
GIucseXHMrRrXPFeKw
GNoduqRICMxxYLScjzRR
GTdkEFQtZIyifVPtMw
GUUIOYFVBkCRKKGPM
GabGyY
GlmIPNFEUxGfzccoGbGvt
GqxGeRkjCFW
GrnXAG
GsRUyGCvRhXYbBNdoXgMoD
GyQSbTrVGUQXgOfZOvlwGGJOZ
HCaLEQxCPhokiggZc
HETlXz
HRQNzHLCNHYjXY
HbOXELXYC
ISKZiApGwwqfPxyvDE
IcSKMpKalYoTBtNC
IprhqRmUjfLjdAvaVSyh
IsZFDjJYWWGraQqQsCIojuoPI
ItCdjvWTgdRQjqKEojXISZB
JEVIhwFBZItxqXVhyUDXDtvW
JEhcfsFJLI
JhsVgkWwuNGjkVJBv
JiXLWADK
JkvQVFXLk
JqTVuEmdOv
JuvMSMMEvEF
KDwYBJCicCZzRoOZ
KLAfQsdsaKGHSrQOYTMpVzgK
KSnZqpvzTNl
KWfbJvRFrOV
KcugiBMUcgjkCqc
KidKIFrYdPHAre
KlkHRlyspyEbCqaAF
KtJgAGRGyADIhGc
LGWXmeQgMABu
LGyzhOBlGMKKEiSyBNOA
LUjVXvmpjLkwIEYtcKcCx
LebFCnlzbXtrrLdB
LsyMBhredZBvk
LtFyFAsWliacGsTGXqjeeLvK
MBYEluvEyDzsC
MHJytDnaUPMzueb
MRAAdjwmnMsgXIeyxsstimL
MTyYvXrFDEVJRoIKFwFl
MXvGmOYJBUNcUhrUCfuEpj
MZrxiTTzjWhcxLrlJk
MdAKHWoLiTGZE
MoEtlGhIUoAqzlzsWDD
MxxORRnm
NDUAXvzsdeydywwRNMHWRJGK
NTSxfMIpNzhwDaIYTg
NUIiQUpkB
NdojhsEWJXelkYgY
NqNktJurxEPsSVvLgoiCKI
OBviaeAmDhEKB
OPTztDwnXmUalz
OarYXdaVMs
OuaaSMDdKAHJBSI
OxtFZQuvLvXO
PJPUWySrtcFnoU
PkrxWwd
QBzgDamuPMHnmBmxqsemB
QIPgSlrJ
QdXiEwjVRvwsA
QkJCVvrpO
QlKOChPtGkCgueNfMfmE
RgpZIjoS
RyWPRDWAZokSpgjdX
RzInNvLFbXSrZs
SBVACGqdL
SEXaxJE
SRIMcYcgmQzv
SVExPilkWeEdOmPKxmE
SshJfgldnoPmDiuzthDwd
SvDHpIXg
THleRyMKuvcwAptfFoQK
TTMslvZRPDHsOsrU
TYDISaLzbh
UCcbUfpvn
USnHmXWDgJkTuRXnXRjn
UUHotoQypbMRPBbQhwXJ
UViPeuVtuJLKc
VBkQTrbKGhVfQhRTgXMjbrfiaA
VFhGvlPGsQhxHtTvhSxKcY
VMzeZLRonjcnd
VvcxTjnHmbhTuwSu
WNjGlSlYPJjasDjMnceJuoqnOl
WOmHhVXU
WWcFKCS
WghExnDSDsHbsIsQUpcOxNq
WxdatBbzivhjgPXiraHxWOM
XAcTVarCmGzF
XAqsrMHoZFRaFCiaysvzy
XIXyiQCQ
XQVwoczNAXAPbeZcjruIA
XatHkgeISNp
XpoUhKqoThkn
YDFhjgerDlMLHVuXkSGEv
YDKNGzOAPZlebFJpomRMxWNWg
YFhZJoLhPOxEKBaBTzdVAs
YMAJlulpbXVSpmjWQoONYi
YQhjFQTZKDC
YVgAZYazoRsKAdHqUTqkgZq
YkervHFfkUmQ
ZlZscmMrWi
ZmdBIuhvLHIhsHYfrVvyNMOd
aWbGhfFeswwmRPshquqsl
aloTparayLO
amdrEpsU
bQQBvUQww
bVWsKcmDpbKTsnGSXiKxM
beHDhlBgUZsmJPexvSQKWCSKnW
brphqpZlLTLruTZptc
bwgKjSDuHKhDy
cEmuUSbtGzsPAWGLdEauFU
cZCtvLKOxGXeuQWS
ccdfvrWFVeOtkqurRNVLro
ceebsfNkbprRYc
cjGWSR
cnuLgsUOwrPiw
dKIpmirT
dWSStgetesFZgKWUlQPKU
dnXDSBiTBWy
doAVSHUlJOFKbCQnzEW
dsZUCLcbYUzqmmD
eGrZsXv
fFODoRkFUnPhPoFzbafui
fZITkvmvMdUvysq
fnQaoYOUVI
fobQqObMbQikgyImDguWIsSqjW
fvnKblUjOPABvhy
gHaJYcXzizzOUSXyHhzXij
gVVLvY
gYsqbdDRcVuEYq
gkKTzQjnWeBVBmdNP
hYVSsGvvkQKPjqcuHGhHnYbA
hdCnmtITRRiwGbqpRVNVj
hgmXlQGHxqVCPqrOlJgdTzKjmy
hmUYZEkqsD
hnPgQMKxfZHj
hrxRKGrcsUQAxyvDxBdrVDpeiV
hyuMoli
hzuYAENAOWXcCMPPwupdAT
iDKwhD
iLpIoCoOGqSLknWShpOrXAuKw
iYwAhnXpbSUzlmHnmKQLjmmXK
idYAJoIIJgaqEeHFdg
ifPZCTSHPzCTdOekgUaxrQHYuc
ixhaskjGAZPmibXdKZvYtk
ixlbCgxrYjUWwQkziPixAHKEBS
jKcyyPRaYIKARbKLutjxMJNS
jNWPvYbBEhWjWSkVPtU
jfNeLGJbrBNgcJglu
jlLkWHkPXzdlBWKxH
kOjPaBJwhKOkyyEkfyJDAZvEgX
kSACSUJ
keQAVKXtmULHuOImJnBpdef
lErkuJeOFVOTsm
lhaXGZqTpNIGy
meuEhwBKCbfkejUqzTJjdKD
mfNRni
mhUamrXpNTQoqAXBAOdni
mnIEDKk
mrDsuVk
nEGgbfNwyEuu
nGvRmUygfURBUP
oqvDWjwIAJzWpnG
osgOmxsPqdsdPKyVAAI
oxavVlwWCBrupyASASSutRHKF
pEJxpRWmhWgptnfFGEVk
pUkHWIGVsMnGAg
pfTZxt
qDYXLQXI
qNjfExouMwyiEVRAxF
qWDwMV
qapxTEwK
qhNODbIuKwAidWpM
qndJteadmvKtwtX
rBfJGBNajQh
rSkbfbenMNaD
rZemjjNLjMchLkQfeDUbbzpm
rcIMrQ
rlylMbEyTzmhBhMnsDWGjHrGZm
skxWqECeFacKy
tEUCHIYiCUXq
tGglDMKXeMQhJtvQKRDRYth
tiZBMlcH
tuTdavYyrkmrqttj
tusJWJatGAjHQ
uAYOOXzsVtedIEB
uITvpyYWxWdxFIyrNcapZqG
uNuWYXNzTxyYiYCxISZFREssT
uYqFfsiZigpJTLvHeRJSzRJ
uisBqJhQtDhrUvJXqoNzC
ulGorqIa
ulLWzRKIaihpUWldzULuQvs
uxWnjhMRdalMeIJVVXvepyLQST
uzhPwfneAafRTwZNOMlbtoLv
vzJKCHMTTJNRLftltdRzpgG
wXfbObReo
wdgRqjrlxLcZ
woilPxqxjb
xFhlmQwlqWlunaXSAGTJZgm
xpkNqPyEjlUhxYeMh
yMJBOjjpGcaArcbwYVksQ
yQMmxxuzvesyFjnQWZeF
ySqQLXYBVIeML
ybQKUWgVxypfnYzfV
yjlEMfeHtJJufvAhijuftNF
ymFmaPktGszCn
yshKYdVQRI
zJRSMdlcrlWvknxiExxY
zOroUYHqtGnEfcUvuhlrsOvr
ExitProcess
KERNEL32.dll
GetGestureInfo
InvalidateRect
ScreenToClient
CloseGestureInfoHandle
EndPaint
BeginPaint
UpdateWindow
PostQuitMessage
LoadCursorW
TranslateMessage
TranslateAcceleratorW
SetGestureConfig
DispatchMessageW
ShowWindow
LoadStringW
RegisterClassExW
CreateWindowExW
DestroyWindow
DefWindowProcW
GetMessageW
USER32.dll
DeleteObject
MoveToEx
CreatePen
LineTo
Polyline
SelectObject
GDI32.dll
NtQueueApcThread
ZwOpenSymbolicLinkObject
LdrFindResource_U
NtAllocateVirtualMemory
NtTestAlert
LdrAccessResource
__C_specific_handler
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
memset
ntdll.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
InterlockedPushEntrySList
InterlockedFlushSList
GetLastError
SetLastError
EncodePointer
RaiseException
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RtlPcToFileHeader
GetModuleHandleExW
GetModuleFileNameA
GetModuleFileNameW
MultiByteToWideChar
WideCharToMultiByte
GetCurrentThread
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapAlloc
HeapFree
FindClose
FindFirstFileExA
FindFirstFileExW
FindNextFileA
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
SetEnvironmentVariableW
GetProcessHeap
GetStdHandle
GetFileType
SetConsoleCtrlHandler
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
WriteFile
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
OutputDebugStringA
OutputDebugStringW
CloseHandle
WaitForSingleObjectEx
CreateThread
WriteConsoleW
CreateFileW
strchr
wcschr
strrchr
_local_unwind
memcmp
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
.?AVCGestureEngine@@
.?AVCMyGestureEngine@@
-HsV0B
u6Dx8Z
5$!=XH&
Qf%Y-~
)UE^1N
2wt!1s9
1U xq$*
d'T3j?
s6DgmZ
i9w+UD
3W5iJ\#c
5m#Wf}
u(oo2$
f/m%#>v
u6Do[v
oguIsR
sU?j63
1x*&0~w((
wP)sVu
l!)2zY1
*W#Vu2D+T
o9wgl!)3uIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIs
QSOtQ#
-Et{%$L?
Ia,#WuIsVuq
d-H<L9r
Ro9wgl!)suIsVuq
"0?jwlRo9w
mQ1*T#Vu
*T?zwlRo9
fl!)seIsVwq
kq1*T#Vu0D+T?jwlR
;wgh!)suIsTu
mq!*T#Vu6T+T?jwlRo)wgl!)seIsVuq
mq1*D#Vu
)TujwlRo9wgl!)suIsVuq
-Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu
0N,Kjwl
;wg|!)s
mq1*T#Vu6D+Tjw
!)Y|IsV
Tu6D+T?jwlRo9w'l!i]
Tu6D+T?jwlRo9wgl!)suIs
UK BVuzJ+T?
#)suIsVuq
#V56D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
3CL/tsu
(vO7sgl
(s<*;j7
< )Skj
3C\lnsu
Wu~'|h
Is=1U`U
^PvkkV
]WU1K^
mEvZo|<
otzcu6
|+B6eg
6m"6N1
gr5SX+T
1*TsHt6
?jw_no9;d
o9wglM
wlR#%wg
),?fN#
muwZoLm
EM/.*T
=T#=8.
3Hj_KG
!rVutpmq
flRRCDgl.
tIskv
plq1WI8$
"n9wE[
`lq1$?
So9]Tl!
[U?j_<f
!)N}'sVz
&aW,'p}
su"7rE
KNGZm_9
}S?~C)s
op[U4lR'
mW%%Vu
Ysu"7r%5
bcW+s9
1mWKfq
1mSu q
DI9bOk
!d^(2h@
4GHP1*
eo93h(
dn@mIs
\4^qHV
vg8wg%
H1(suM
ntsqwl
PouL/|S!;
HbbR3C\y
9.T#kb
dNA>Is
~uqk)U
|:?fF~
4)K #V
l!B6e4
(vW^4q
mWU""Vu
oDn@u6
@wl9"!b
r`cLl@
"to3twgc
0Q(zuq
o9J+`!)|
>Nc;8W
Zeq)sz
!=wgQg
mW!vmVu
B`{/rmw
KaUll!
opkLalR
UeD+?{N/u
MS3WM+s
4/opgI
nps+s6D
Hrh9w/
.t6DjF?j
So9N~l!
NE+TTY
Avglu-xu
mWp*Tk
[U?jZa
vlRqe{
yugl`w,+
'G-nel
WrMj`8T
U0LcKW
r'/#);
u6y"\?jx
4)/b#V
0&H T?
$JmWE(
"|Jlc-
1m3eXq
t:QzVu
MT#=0&5
0I}uT?
uqk(zZ
/x&&o9
^#5bvl
:eDnR&
%Ja:&+
zJd}Ro
b#Feli
pRt)Tw
6U4PVu
u6/n|.
0Q{Uq1
Q]%qqD
!0U,'p}
u6/n4j
o<3&u6
n</uwl9*QT
n<w1wl
JTlR`}
o<]eu6
s,m&?j?
!_}JoR
1UxN+1*
DJ8?Pu
o4"~u6
zvlR.f69-|h/*
vFlRRsRgl.
uIski@
+TK&JE
vwl &:i
)~y]uI
{NWaWo9
(v_GUgl
5$! :*Tk
glJmW=(2
{=1U@?
hJ'(Tk
C|t~2#
4 n21*?fv>
E}!<*T
2wF>)s
Vu6(NT?
oigPoq
DIQ&VT#
.S\XQ9w
grEd<+T
S\Cm:w
! &:`~;
$kT?j>
#HQvSuI
o+C}u6
glJmW-1
otyeu6
so3Q?j
!DYN6D
zVuLs4q1%
#7D+iz
!XV9XA
PNwTYC
)F>uI
|lt|!)
(stIsV
*&;|l!
d]?f!&
tIqVuq
8INr;l
^.quI7
D+?zrJ
uqk(iw
6mVVVu
u}ME+T
1mSW{q
tI!6&9+
glJmW5
Q1k)Uq
3CH!Nsu
rUuk)U
}SW/&)s
oD=Pu6
RB?fFj
<o &9`~;
)IsVH*]mq>
!s)&>D
\;(GzV
!oTDbR
\3tIl
48t+1*?fn
#M];iq
|7$]!)
5q%s:u
0x*82zt
]WUL8}
{N7gfU}
+RoR3C\@
WrEUQ+T
7D+@Dbm
Avgl1^
So98yl!e
*)vXl!
3Hj?7wg_
{N48o9
fF4]D+
rm'W,'y
Kysdl!
&'W,'y
su"61)9
VROTsm
0QU<T?
)2buI
__U= i
n#%Xwl
09%kT?
!(T?WSkRo6
r )sH=NVu~
su"61I
t69hT?
KsVH8omq>
sC)w?j
o3kfu6
*F4;l!
+TXfu6
n+E[wl
*F&Vl!
n9S`l!
0A yT?
4FBQ#V
V'?f1V
n3S5wl
TV^;Os
f1[@D+
0Q@7T?
VN^\U+
f~c<D+
pglX[uu
kRou$gl
S#V`"D+
^ps"pRD
rIsxUD
su"7r!L
"Q5LGF
wgl`v2+
OkwlrN9w
AvglV_
ruITykq
)sx)sV
{QlRR(Qgl.
R|Cgl.
2D^-9w
LWg`/)
'wmcfl
u6/nL#
zz6cRo
;ewk(ar
"|%)su
E}d *TH
fF rD+
;U;/ntV
USGcJmWU
Oh3sV=
3C\JmWEv
Qv^tT?"
(aW T#
*|bH`3
#HAvSuI2
)s4|sV
SU?jx;Ro
wlo~Ewgc
[U?jgFRo
{V?j(7
CVuqk)U
QEswq1
1mg}_q
RoR3C\O
"QAbD&1
4%A80gk
[Su6y>M?jx
";wgQ(
l!)my>v
9wg(Y)s
wlRf1wg
lRosWgl
6D+-wjw
IsV% a
#VuJ*+T
T?j(JRoq
uIsF=b6
l!)*=Is
)suM}Vu
+T?alR
Is=1Ud(
jwlW2B2
wgljFsu
^pGFAi
lRo\hglJ
(0\2/l
b;R(s=
Iq0*Tk
T?j/Ro
3C\!N21
Is1*iW
S(sutf
(l!B6e
/gVto9
QA90gk
&3`w2)
.SL_N9w
GQ#!)?
9k)Uu'
1*?grMA
zzyFRo
XT/nL
}SGh!)s=
p3.Wu9
2ti:)s
+TT/xE
oC&vu6
2lGZ)s
mWU( Vu
8QKJ&#
+TT/_M
0&D(uq
)^}uuI
W^ 'W,%p
f!riD+
HTnlR'
*N"fl!
*FnRl!
s3|Y?j
z<T#=0IJ
0AX$T?
f)`|D+
!\#eVE
9wg-~h-4
lRRhfgl.
nk&cwl
4VUm#V
O3'=0Q
f1^]D+
Q1ATqD
4 %'1*?fv
0a;wuq
n!)ruIs
,twlo|'wgc
.S\}e9w
-y<r2N
"QQf~z1
.S\o-9w
)B*>wg
oL`mu6
C\9P8j
(Q:~T#
2GdE)s
lk/)sV
fN&LD+
Eu .*T
lS9*sV
KsVHx
m6+TT/oa
lSvGsV
6U"6v9
h*/+Tk
npko|6D
Q^#vT?
Qu=0i6
"t`Csu
RoR3C\
:MomR+
3Hrrfwg
0v3=T?
An9vgl!
Nv[rV=
"\Tzsu
0YXoq1
2DCQ9w
"\nosu"6fb
Is=1U0
U#Vo{A+
(sufaB
9)$II7
4)k;#V
9wg|!)s8
u6/op(
(vOR3CLN
Swm!)?
Ro9ASl!
$ep1*S
SOm!)g
mWEsDVu9
T?S4d'c
2?w~2#
]0D+\xjw
ZqlR*9
RqlRu/
DTo9t
L')s`^sV
auVu]>mq
LTo9c3
Uw1*m3
R?jw%Ro
mq)HT#
]OsVK{
/su;?Vu
Ew1*w@A
t9jw=~
Uw1*5:
d%Vu.j-T
WjRorggl
lwl-F](
SlSo9;
mWUMsVu9
QiNSOF
4(521*
7rIKmq
{NC.-o9?
}S[`Z)s
^T.STo
}S##Z)s=
!0U,'p}
m[WuqL
WMHsV<
QirVui
n9ws;!)
m;Wuqa
(v?fWgl
rExk)U
3Hf9)wg
Ge"7rA4
.SL{P9w
.S`e9wT
fjZD+?{NG
dI)Znp{;
Qnb@T?"
-$e$g}
V~6Ynv
zZn%Ro
/G(Ro9
mWEt1Vu
PZl!B7Qi
vi5D+?{NWp
mWU]7Vu
CLRksu
3C,~csu
(v?fWgl
opY(lR
Q!k)Ua
.Sd`!9w
%ipIse
"V:0gb
r`{_|jw
6*TR&y6
tuIb-uq
S?ju^Ro
Qu6LrT?
$VuS*+T
1D+jljw
tVu%Sjqu
&S8x-x
S#V~PD+
tuI%c"
mqW4n
Qu6LA4N
+TT.S<
!"&8`|2#
Quq=:h1*[
3C8@wsu
Kib"l!
}Up<v=1UTc
su"7r-
_l!B7Q
}S3/Q)s
_pkl(>
5$5bT*T
sVuqLb6
4.A30lk
JsVHl9mq>
BrVuL#
L)B6Uh
~2~d5
)1X<uI
rdZoDd
mqZoLN
Q9+sq1
5$)1C*T
$Yt\-T
gre>~+TZ"
>yV:0gb
lRoC6gli
WrE"u-T
sVuGOmq
2*T1/u6
Uuqxeq1
iwldw9w
v6Dm8?j;
v6DZZ?j
2*TD=u6
v6Dz2?j
nDB wl
zzz+Ro
l[aKsV
di wl9+
3HbV{wg
irxwl]
opoQylR
5D+:Ljw
k9w87|
oRo[Cgl
vIswsq
")snisV
Qo9[Zl!
W?jA'D
G+Tp$wl
0QN8uq
4)1x#V
\k|:MQ
nG.!wl
\k-"RE
6e4lVu
t=8>Vu
DIQ= T#
4G;y1*
v8?f9H
wl9*V)
dF=?Is=8
0Y${T?
f1yiD+
?rE{e4
9m;XV[3
%+a^z&
grEA(+T
EuVs*T
7rE&3mq
LJ-uqH
.SdVd9w
7QyX#uq
S\/?zr,
0.zkT?
Cl{bDy
re'W,'y
gl!.SuI
rEr]gs
USWhJmWEc
mWEAgVu
7r5QMmq
UqZr.V
?r}$V:0ek
!)N(]sVz
77R2?#
(! RT#
1{9rP<
7?_+s1
#VH@]+T0
HsVH:
KU?j<a
QvglAZsu"
<"Vu8/
WkwlXX
I(suB[
BU#V^5D+
,*T?b<lR
<"VuRD
<>jwe9
8wg%})s
m!)NvIs
I(suTdg
:yWlR'
:n9w.y
:n9w2,:)
!rVuzr&
!rVusk
CU?jdbRo
tIs2tq
KWu6ZQT?
<>jw[-
!rVuosmq
p1*=RVu
AruIz?
KWu6:"F
fl!JhuI
>t6D(?
m!)y6Is=
?nRob*
1U k/1*
1U@Im1*
_pwLx3*
}S'& )s
')|$4;
(k,13h.b!
(i;oT#
3m1/nLr
2|Ih9w
Wluwg$
re'W,'y
^Y+TT.S
lRo9wgl
{NW{uo9
78L!)2
}SOv;)s
}SG':)s
K!vgli
/$fVu~
0Bn}uq
oS$}u6
05`iT?
DIU*4T#
z`C?sNP
! &:`~;
r`Y|jw
7Qarhh
]WUdtRu
dF&Is
u6/n;a
l!B7Q9O
;wgQR2suF
P>h*T,
X7D+i36wl]
mqEi"
wlRrIwg
fl!h,4
W^ 'W%
:jwv?w
hq1L4#V
Ua%R#V
hq1WI#V
LsVS;}9
A+TN}wl
rglG~su
Q#V6TD+
vVu $mqZ
.T?^OlR
iRol>o{e
Iuqk(i:
6UWvVu
UIs=1U0#
1U0!p1*
[W?joq-
<(T?CXP
*l9wYb))
I)T#SL6D
UuqFBq1
&v6D`H
pVuA*mq
.=#jw-
DIAn|T#
W\ wg$
ruINU q
T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
lw3*RQTE7@*T;HwlSb=wjX1)~
1*U'Wu2
0)hAYsM
ePl{3*^QPE7N/T5^
4zU)Ru<p!T5
1)g!FsBA
!ZU<Zu) 8T >elM[(wx
bpla3*D
_%7P(T+k=lW?9wfs*)l
rE'*K"Du.
wlS`?wh
,)|AEsY
zplb5*G
$$>s}lK
3)j!XsOAa
jlu[%w@m7)o
y!1*U?]u*02T#
olN;.w{X7)ot]sC
S%7S#T(
(wpX1)d
?*@w[u"p'T+
+T>ful^
<'f~')a
:zU*Tu?6)
>uplM[
ll6*I"
}\[?9wf|#)c
e31*U3Ru&p9T/
q<Sf;wn
rsKsP's0lx3*]
T%7Z T!
llL[#wym5)a
}pf!1*U+Wu>f+T>{tlC
3Gn<!)riBsJA[
T?9wf{&)d
zp/*_sVu7^"T%
ilH[$w}m9)}
ln8*KW}u)
T ^_lMnws<!)r|Ks_
t0lb5*G
$$>bvlZ
9wfv()i
lH;,w}X5)i
a`lS8*vW
^-lpnaws<!)rsKsPGs0lj;*OG@u-
>T$^clI
1Yrn@sM
Bu-E9T/:wlSc;wk
$yrm@sNAh
>4,49:wlSc;wk
$yrqHsR
q\W?9wf|#)c
|p}*VsVu7I)T2X~\S}1wu81)aAGsD
:JU9Qu,E=T1
3Gn<!)reLsFtc
VsVu7R,T)kamU
q%IsWkv
u(EgT/:wlSK2wCX
)WtQsO
slGnrwa\$yrxJs[
w0h!1*U)Ru<p'T5
5)k!ZsNAc
zlB[5ww
-YroLsLt;
]sVu7` T
}`f!1*U9^u,0>T%
dlH[+w}
1yroAsL
7)S!\svAe
wlSs3w{
:)lASsIti
y!1*U6Uu#E9T6:wlSs2w{X
)otWsF
+T>dtl\n-we<!)rdJsG
{0d!1*U,Pu9 %T0^{l]
{<S{:wsmy)v%IsWj{
&*Kw@u)p>T
rE)*K"Du.
B9wff%)yANs\Gwplh6*M"
q\W?9wfc%)|ACsY
zplk6*NW
lY?9wf
>ZU<[u) 5T >jlM[%wxm7)k
1*U4Pu! !T(^
f{))d!ZsAAc
7K-T0^yl]
'yrmAsN
?$>Izlq
)PAosutQ
83)kAXsN
epld7*AWEu#p9T*
.)cAGsF
}pld4*A
u#EyT9:wlS
bE;*[Q]
7_#T$>blI[*w|
7]-T&^alK
1yrbOsAt
S%7R.T)k
lU?Gb<!)rxMs[A{
7zU8\u-
(w|X1)h
**wWLu
^olqn-w
g%IsWjz
(*KWNu) <T ^alMn-ws<!)r`JsCtk
d!1*U:\u/0:T&
glK;6w~X/)j
xp%*]sVu7V#T->fl@[)wu
2'fu%)jt
s\ExPlk9*NGBu,p8T%
C)'fv))i
F%7V#T->zl@[5wu
1*U8_u- <T$>alI[-w|m3)g
*KWtu)
T ^WlMn'ws<!)rgKsD
0li8*L
a<!)rbNsAA
+T>|slD[3wq
.yraJsBt
h!1*U1Ru$
$5Z~<S`;wh^*
suIsVuq
ulSo9wfl!)ruIs^
ulRo|Y
DD+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
mq1*T#Vu6D+T?jwlRo9wgl!)suIsVuq
dIs~fq
3*|0Vu|W+T#
uljs9w8p!)o
)T/Hwl
VuWa+T[
ul6J9w+D!)
F!)?^Is
Fwl;B9w
#)XIs3[q
Vuak+T
@9wTV!)w
+T5Twl
;wkR!)
]01*daVu
(wlW,9w;
#){6Is
&9w1'!)
!!)1:Is
)Tk:wl
'IsI,q
3*tzVu
ulR39wE0!)o
;w'2!)
@Vum!+T
Tuj#+TK
#)7|Hs^yp
3*\/WulK*T'
`8w&~ )3
TuZW*T ~vl
;wGx )
4Wu0]*T
ulZv8w
;w'q )okHs
qo0*d<Wu
uvlV_8w
#)wEHs
Wumq*T
50*deWu
ulZ!8w
;w'< )<$Hs^
= 0*6qWu>
)T[8vl
!Hs."p
3*,tWu
Tu:.*T
0*)LWu
TuB2*T
0*sYWu6
;w'h#)
lul-g;w_
}KsBys
3*@/Tu
TujS)T
N;wZN#)'
Tuzg)T
)T?Cul
\Ksp_s
ulzD;w
T;w2<#)
Antivirus Signature
Bkav W32.AIDetectMalware.64
Lionic Trojan.Win32.Emotet.L!c
Elastic malicious (high confidence)
DrWeb Trojan.Emotet.1310
MicroWorld-eScan Gen:Variant.Ulise.405919
ClamAV Clean
FireEye Gen:Variant.Ulise.405919
CAT-QuickHeal Clean
McAfee Emotet-FUD!C901C8089C5E
Cylance unsafe
VIPRE Gen:Variant.Ulise.405919
Sangfor Spyware.Win64.Emotet.Vjsd
K7AntiVirus Trojan ( 0059b58d1 )
BitDefender Gen:Variant.Ulise.405919
K7GW Trojan ( 0059b58d1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
VirIT Trojan.Win64.Emotet.DPQ
Cyren W64/Emotet.BGN.gen!Eldorado
Symantec Trojan Horse
tehtris Clean
ESET-NOD32 Win64/Emotet.AL
APEX Clean
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky Trojan-Banker.Win64.Emotet.cmvs
Alibaba TrojanBanker:Win64/Emotet.f53d6a7c
NANO-Antivirus Trojan.Win64.Emotet.jvobvn
SUPERAntiSpyware Clean
Rising Trojan.Kryptik!8.8 (TFE:5:F5gXdyKd7lN)
Sophos Troj/Emotet-DCT
F-Secure Trojan.TR/Agent.aogi
Baidu Clean
Zillya Trojan.Emotet.Win64.712
TrendMicro TrojanSpy.Win64.EMOTET.YXDCQZ
McAfee-GW-Edition Emotet-FUD!C901C8089C5E
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Ulise.405919 (B)
Ikarus Trojan-Spy.Emotet
GData Gen:Variant.Ulise.405919
Jiangmin Trojan.Banker.Emotet.scv
Webroot W32.Trojan.Emotet
Avira TR/Agent.aogi
MAX malware (ai score=100)
Antiy-AVL Trojan/Win64.GenKryptik
Gridinsoft Malware.Win64.Emotet.bot
Xcitium Malware@#1f2osespawys
Arcabit Trojan.Ulise.D6319F
ViRobot Clean
ZoneAlarm Trojan-Banker.Win64.Emotet.cmvs
Microsoft Trojan:Win32/Emotet!ic
Google Detected
AhnLab-V3 Trojan/Win.Emotet.R564334
Acronis Clean
VBA32 TrojanBanker.Emotet
ALYac Trojan.Agent.Emotet
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win64.EMOTET.YXDCQZ
Tencent Malware.Win32.Gencirc.118bf89d
Yandex Trojan.Emotet!NeE/T5E6Ku8
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Win64:BankerX-gen [Trj]
Avast Win64:BankerX-gen [Trj]
No IRMA results available.