Static | ZeroBOX

PE Compile Time

2017-05-24 21:17:21

PE Imphash

fe586131a824714774b47ac27da9e046

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000545a6 0x00054600 5.61070960833
.rdata 0x00056000 0x0000247c 0x00002600 5.48806811353
.data 0x00059000 0x0000cedc 0x0000d000 4.98156002764
.rsrc 0x00066000 0x00017070 0x00017200 5.8595263094

Resources

Name Offset Size Language Sub-language File type
MAD 0x000668c8 0x0000514c LANG_NEUTRAL SUBLANG_NEUTRAL data
MAD 0x000668c8 0x0000514c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_BITMAP 0x000707a8 0x00000428 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0007b320 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0007b320 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0007b320 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0007cd50 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_RCDATA 0x0007b988 0x0000061c LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators
RT_GROUP_ICON 0x0007b888 0x00000030 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x0007b8b8 0x000000ca LANG_DUTCH SUBLANG_DUTCH data

Imports

Library KERNEL32.dll:
0x45618c CloseHandle
0x45619c ExitProcess
0x4561a0 FindClose
0x4561a4 FindFirstFileA
0x4561a8 FindNextFileA
0x4561ac FormatMessageA
0x4561b8 GetACP
0x4561bc GetCPInfo
0x4561c0 GetCommMask
0x4561c4 GetCommandLineA
0x4561c8 GetCurrentProcess
0x4561cc GetCurrentProcessId
0x4561d0 GetCurrentThreadId
0x4561dc GetFileType
0x4561e0 GetLastError
0x4561e4 WriteFile
0x4561e8 WideCharToMultiByte
0x4561ec WaitForSingleObject
0x4561f0 VirtualFree
0x4561f4 VirtualAlloc
0x4561f8 VerifyVersionInfoW
0x456200 TlsSetValue
0x456204 TlsGetValue
0x456208 TlsFree
0x45620c TlsAlloc
0x456210 Thread32Next
0x456214 TerminateProcess
0x456218 Sleep
0x456220 SetLocalTime
0x456224 SetLastError
0x456228 SetHandleCount
0x456230 RtlUnwind
0x456234 RaiseException
0x45623c MultiByteToWideChar
0x456240 LocalFree
0x456244 LoadLibraryA
0x45624c LCMapStringW
0x456250 LCMapStringA
0x456254 IsValidCodePage
0x456258 IsDebuggerPresent
0x456268 HeapSize
0x45626c HeapReAlloc
0x456274 HeapFree
0x456278 HeapCreate
0x45627c HeapAlloc
0x456280 GetVersionExA
0x456284 GetTickCount
0x456288 GetTempPathA
0x456290 GetStringTypeW
0x456294 GetStringTypeA
0x456298 GetStdHandle
0x45629c GetStartupInfoA
0x4562a0 GetProcAddress
0x4562a4 GetOEMCP
0x4562a8 GetModuleHandleW
0x4562ac GetModuleHandleA
0x4562b0 GetModuleFileNameA
0x4562b4 GetLocaleInfoA
Library USER32.dll:
0x4562d8 LoadCursorFromFileA
0x4562dc CloseClipboard
0x4562e0 GetLastActivePopup
0x4562e8 IsMenu
0x4562ec GetInputState
0x4562f0 GetKeyboardLayout
0x4562f4 CloseDesktop
0x4562f8 IsCharAlphaNumericA
0x4562fc GetWindowDC
0x456300 PaintDesktop
0x456304 GetActiveWindow
0x456308 CharUpperA
0x45630c IsWindow
0x456310 GetCaretBlinkTime
0x456318 GetThreadDesktop
0x45631c CopyIcon
0x456320 GetCursor
0x456324 WindowFromDC
0x456328 LoadCursorFromFileW
0x45632c GetMenu
0x456334 EndMenu
0x456340 IsGUIThread
0x456344 CharLowerA
0x456348 GetDialogBaseUnits
0x45634c IsCharLowerA
0x456350 ShowCaret
0x456354 GetKeyState
0x456358 GetMessageExtraInfo
0x45635c GetTopWindow
0x456360 CharNextA
0x456364 IsCharAlphaA
0x456368 DestroyIcon
0x456370 TranslateMessage
0x456378 ToAscii
0x456380 SetWindowTextW
0x456384 SetWindowRgn
0x456388 SetWindowPos
0x45638c SetWindowLongW
0x456390 SetTimer
0x456394 SetScrollInfo
0x45639c SetForegroundWindow
0x4563a0 SetDlgItemTextW
0x4563a4 SetClipboardViewer
0x4563a8 SendMessageW
0x4563ac SendMessageTimeoutA
0x4563b0 SendInput
0x4563b4 SendDlgItemMessageW
0x4563b8 ReplyMessage
0x4563bc ReleaseDC
0x4563c0 ReleaseCapture
0x4563c8 CharLowerW
0x4563cc RegisterClassExA
0x4563d0 PostThreadMessageW
0x4563d4 PostQuitMessage
0x4563d8 PostMessageW
0x4563dc OpenIcon
0x4563e0 OffsetRect
0x4563e4 MonitorFromRect
0x4563e8 MessageBoxW
0x4563ec MessageBoxA
0x4563f0 LoadStringW
0x4563f4 LoadKeyboardLayoutW
0x4563f8 LoadImageW
0x4563fc LoadBitmapW
0x456400 KillTimer
0x456404 IsWindowVisible
0x456408 IsWindowEnabled
0x45640c IsRectEmpty
0x456410 IsIconic
0x456414 IsCharUpperW
0x456418 InflateRect
0x45641c HiliteMenuItem
0x456424 GetWindowTextW
0x456428 GetWindowRect
0x45642c GetWindowLongW
0x456430 GetSystemMetrics
0x456434 GetSysColorBrush
0x456438 GetScrollPos
0x45643c GetMonitorInfoW
0x456440 GetMessageW
0x456444 GetMenuItemRect
0x456448 GetInputDesktop
0x45644c GetDlgItem
0x456450 GetDlgCtrlID
0x456454 GetDesktopWindow
0x456458 GetDC
0x45645c GetCursorPos
0x456460 GetClientRect
0x456464 GetClassNameW
0x456468 GetClassLongW
0x45646c FindWindowW
0x456470 FillRect
0x456474 EnumWindows
0x456478 EnumWindowStationsA
0x45647c EnumThreadWindows
0x456484 EnumDisplayDevicesW
0x456488 EndDialog
0x45648c DispatchMessageW
0x456490 DestroyWindow
0x456494 DefWindowProcW
0x456498 CreateWindowExW
0x45649c CreateMenu
0x4564a0 CreateIconIndirect
0x4564a8 CreateIcon
0x4564b0 IsCharAlphaNumericW
0x4564b4 DestroyCursor
0x4564b8 VkKeyScanA
0x4564bc VkKeyScanW
0x4564c0 CopyRect
0x4564c4 CloseWindow
0x4564c8 CharNextW
0x4564d0 GetQueueStatus
0x4564d8 GetSysColor
0x4564dc CallWindowProcW
0x4564e0 ShowWindow
Library GDI32.dll:
0x45605c CreateMetaFileA
0x456060 AddFontResourceExW
0x456064 AngleArc
0x456068 CloseEnhMetaFile
0x45606c CopyEnhMetaFileA
0x456070 CreateColorSpaceW
0x456074 CreateCompatibleDC
0x456078 CreateFontA
0x45607c CreateFontIndirectW
0x456080 CreateSolidBrush
0x456084 DeleteObject
0x45608c EngCreatePalette
0x456090 EngDeleteSurface
0x456094 EngFillPath
0x456098 EngPaint
0x45609c EngTextOut
0x4560a0 FillRgn
0x4560a4 FlattenPath
0x4560a8 FloodFill
0x4560ac FontIsLinked
0x4560b0 GdiAlphaBlend
0x4560b4 GdiConvertBrush
0x4560bc GdiEntry8
0x4560c0 GdiPlayJournal
0x4560c8 GdiSetBatchLimit
0x4560d0 GetCharABCWidthsW
0x4560d8 GetDeviceCaps
0x4560dc GetEnhMetaFileW
0x4560e0 GetFontData
0x4560e4 GetGlyphIndicesA
0x4560e8 GetObjectW
0x4560f0 GetWinMetaFileBits
0x4560f8 NamedEscape
0x4560fc PathToRegion
0x456100 PolyDraw
0x456104 ScaleViewportExtEx
0x456108 SetDIBColorTable
0x45610c SetMetaRgn
0x456110 SetPolyFillMode
0x456114 SetROP2
0x456118 SetTextAlign
0x45611c UpdateColors
0x456120 GetSystemPaletteUse
0x456124 CreateMetaFileW
0x456128 EndDoc
0x45612c DeleteEnhMetaFile
0x456130 BeginPath
0x456134 CreatePatternBrush
0x45613c CancelDC
0x456140 GdiGetBatchLimit
0x456144 GetColorSpace
0x456148 EndPath
0x45614c EndPage
0x456150 SaveDC
0x456154 SwapBuffers
0x456158 CloseMetaFile
0x45615c GetDCPenColor
0x456160 AbortDoc
0x456164 GetTextCharset
0x456168 GdiFlush
0x45616c FillPath
0x456170 CloseFigure
0x456174 GetTextAlign
0x456178 GetMapMode
0x45617c GetBkMode
0x456180 GetStretchBltMode
0x456184 AbortPath
Library ADVAPI32.dll:
0x456000 RegOpenKeyExA
0x456008 CryptCreateHash
0x45600c CryptDestroyHash
0x456010 CryptGetHashParam
0x456014 CryptHashData
0x456018 CryptReleaseContext
0x45601c RegCloseKey
0x456020 RegCreateKeyExW
0x456024 RegDeleteKeyW
0x456028 RegDeleteValueA
0x45602c RegOpenKeyW
0x456030 RegQueryValueExA
0x456034 RegSetValueExA
0x456038 RegSetValueExW
0x45603c RegQueryValueExW
Library SHELL32.dll:
0x4562bc SHGetFolderPathW
0x4562c0 CommandLineToArgvW
0x4562c4 ShellExecuteExA
Library ole32.dll:
0x456550 CoInitialize
0x456554 CoUninitialize
0x456558 CoCreateInstance
Library SHLWAPI.dll:
0x4562cc StrCmpNA
0x4562d0 StrStrA
Library COMCTL32.dll:
0x456044 ImageList_AddMasked
0x45604c ImageList_Destroy
0x456050 ImageList_Create
0x456054 CreateStatusWindowW
Library msvcrt.dll:
0x4564e8 _except_handler3
0x4564ec wcslen
0x4564f0 wcscpy
0x4564f4 wcscmp
0x4564f8 _XcptFilter
0x4564fc __dllonexit
0x456500 __p__commode
0x456504 __p__fmode
0x456508 __set_app_type
0x45650c __setusermatherr
0x456510 __wgetmainargs
0x456514 _adjust_fdiv
0x456518 _c_exit
0x45651c _cexit
0x456520 _controlfp
0x456524 _exit
0x456528 _initterm
0x45652c _onexit
0x456530 _purecall
0x456534 _snwprintf
0x456538 _wcmdln
0x45653c _wcsicmp
0x456540 _wcsnicmp
0x456544 exit
0x456548 wcscat

!This program cannot be run in DOS mode.
`.rdata
@.data
5Gs:3r
@K8>CL
fAC$nE
jzGC$"
n#,!n#,!
u?C&E
K:AVE
{9Af.r
>=nAke
!:WhdkMe
I/s$^b
M^QF ~
o^Xy:j
QW%;O9
(;s$:E
Ve<1uz
&j&/|$v!z<V
-;PZAxp
|2]Dt;
UZ3oa^
yoSh3pj
3_:B=
)x@&EM
D:rwuO
L:n0Lz}z
f]OEfoR
$u")$Y8
/+Zf?
C7F=s3I
3OV+ -
N34Js$
tyU36~
+XQ9KL
{/AfF
A&w]j'w
wZSEwZ
Xu:Bs7
Wh |F^
WhO)|`
btZjZuZjWuZSEwZS9+
OFSsE?
OJ$6QR$
+?6#Gj
?f(C$F
T]%$K$
T!(PYc
^hx']+<
[T[m%T
$$n0Agt
G"V6;v
)SL#Vs
6W}0;,
x}%@3`
>,knPY
^zSEPz_<
Dxn;>92pDbl&
92@&bl
bm1<$d
krUU$d
(%xs/;d.J>b
Va+/bd(
kr? _r
?gl3/co
LPGZqA
H9D]{A
kBw]aC&H-
8XU5O",7
euR3ng
nxjz-^
feQOh?
RU&zl%
@,)n6mX]F
EX!be{
q9G@%19
Zt O89f
}uQfl-
>NK;h-d
{0C+t:t
>[t|p
dhzM9
1U*TrqVoT'
^N]iVj
#OkY2(J
lZzmMP
EYiz%*+
a( e+
uEm:z\eU\
3%PCF'cQ
Ib$b)li(
hY~iAN
~2G^]!
Unm!0l0:3
:Jw@iZ
k.6)]{K&
TA)O%>'Y
SrBb>X
UMr;9v
]F+aFA
ae{lFKY
J-/#;
=P 0WA
*hq,:S
U}Yi.4#
=JtsPjs5
BztV\Fn
/3J\DH
TwpA6fo
>qY6d?
4wLIFr
|ARup/
h|L>$&
Hj}Kg[.
IC}8AeMy
[Mxf.'
[1]#WGn
<9>~=O
adSj'>%
BrB[JXT
b;Y|LM
RIB%q?
l7d9+w
sH1jRM
YvLi~7
gY7NlQu
DPtrhF
f=Fe?{
6^,@D:
9&9gF:S
*fMx)c
@@m&R`T
2?zhP?
g]YK/
^bn|`)
RI]eSX*1
sGL9;3
)0'3r@
w-=C:LP9
<Ws%Iu
z/9)?&
2044 s
NusQg"c;
#IAs$|
nm5-v%8
B2*C}+K
Ypm8y2
}%b&f|
&`k{f
eG2L?,
gor7@]
vYsSH]bJ#K
E>xy2YMsp
D]jqE
Ko=|%@
MkuL}M}$:
go8n0(l
FC(xDQ
c|c:<UF
Ax>K%c8=
fQ2iIF
[\`B`z
'y_ia}
!k1XSM
}`F9Y7
=}xxI\
`nD_is
f|x7ur
.tDo#X"O\
x66'n?
_%[<t.
X? +"
yy.{xH
gt#uKt
wIq {FZ}
z}_tKD
Y'w"o>
[41GOx+
Nyx~n(
?QK;,;
Z?,vz'
K6*ae5
~`dTu;\/{:
i@Vq9E
L!nBLO
4G.5c|/~
>7}-'Rl
y/pas9C
<8IDQ
ZFE+0J
_/{xU]v1h
&eRV%}
LQBw6-
TRuE!6a~
*gV/uPTk
;5K0~)
Z(5X*V
=h&\9E
'YXLsb!
N7m~iw
Ya9^S5
l$h@\o=
T/EhHS6)
9bVHc0D
V%q6%g
<$1q)G
'xr<8P
4gN4/,
U-*{Dz
hs7Y/u
S]f>y(
5t@teO
{1K8)n
S`uRe9~
_wbc'yV
!~7!Mau
sQ^TbC
ncRo-`
Mx?<QW
az6l~>
u*&vUI;F
'VzIfF='
/(rQ(G
I*j{y.
oPGAd}
)_}+%jZFa
+z1`0R
F&Mot
J Lz[[
feXnI
wgC_l\
G-X<*+"
v>'sXi
0J#F$v
$Zu!m`
7JzI8vz
<zz-<~y
gG=YgB=Bg
ue0 r}0
06u61-uY1
21w!2\tZ2<t
p#4H~K4
r/6LpO6
7Fs$7cqJ
{38czo8 |
}&:}}1:
<coH<"
~D=)~p=
3Rz03*{
6iw46pxf6|x
|z2"|r2
{%<Lnc<
og9;q_9Sqw9+ro9
:!p_:yp
>'|3>#|X>
{f?3{|?
u[2&u|2
x&3[w93Rw
V5Rm~5
=4u1=1uj=!u
=gtD>Xx
n?67pw6
7Do#7Oo@7
;uy";"{
yF<rvQ<Hv
13xQ2-q
4wn$5Am
5dq/6'tY68t
sH7.sh7
y/<Ev|<
0}rF1Fu
:e~W:A|
o04ZvL4Bv
5|u86,t\6
tq6nt&7gtU70s{7
1~EWJD
~UG?E4
$`~U7AL
~EGA?<0
i?G0a??
1~H;=D
i=G0a=?
z2~H;?D
~Ec<?T
"~Bk9K
QEPoQD
3yIKxpK
vAak4
/Mo*K9
=s]q(i
6ZD/uO
BeginUpdateResourceA
CloseHandle
DeleteCriticalSection
EnterCriticalSection
EnumLanguageGroupLocalesA
ExitProcess
FindClose
FindFirstFileA
FindNextFileA
FormatMessageA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetACP
GetCPInfo
GetCommMask
GetCommandLineA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStrings
GetEnvironmentStringsW
GetFileType
GetLastError
GetLocaleInfoA
GetModuleFileNameA
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetStartupInfoA
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemTimeAsFileTime
GetTempPathA
GetTickCount
GetVersionExA
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InterlockedDecrement
InterlockedIncrement
IsDebuggerPresent
IsValidCodePage
LCMapStringA
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LocalFree
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
RtlUnwind
SetConsoleScreenBufferSize
SetHandleCount
SetLastError
SetLocalTime
SetUnhandledExceptionFilter
TerminateProcess
Thread32Next
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
VerifyVersionInfoW
VirtualAlloc
VirtualFree
WaitForSingleObject
WideCharToMultiByte
WriteFile
KERNEL32.dll
CallWindowProcW
ChangeDisplaySettingsExW
CharNextW
CloseWindow
CopyRect
CreateDialogIndirectParamW
CreateIcon
CreateIconFromResourceEx
CreateIconIndirect
CreateMenu
CreateWindowExW
DefWindowProcW
DestroyWindow
DispatchMessageW
EndDialog
EnumDisplayDevicesW
EnumDisplaySettingsW
EnumThreadWindows
EnumWindowStationsA
EnumWindows
FillRect
FindWindowW
GetClassLongW
GetClassNameW
GetClientRect
GetCursorPos
GetDesktopWindow
GetDlgCtrlID
GetDlgItem
GetInputDesktop
GetMenuItemRect
GetMessageW
GetMonitorInfoW
GetScrollPos
GetSysColorBrush
GetSystemMetrics
GetWindowLongW
GetWindowRect
GetWindowTextW
GetWindowThreadProcessId
HiliteMenuItem
InflateRect
IsCharUpperW
IsIconic
IsRectEmpty
IsWindowEnabled
IsWindowVisible
KillTimer
LoadBitmapW
LoadImageW
LoadKeyboardLayoutW
LoadStringW
MessageBoxA
MessageBoxW
MonitorFromRect
OffsetRect
OpenIcon
PostMessageW
PostQuitMessage
PostThreadMessageW
RegisterClassExA
RegisterClipboardFormatA
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
ReplyMessage
SendDlgItemMessageW
SendInput
SendMessageTimeoutA
SendMessageW
SetClipboardViewer
SetDlgItemTextW
SetForegroundWindow
SetMenuContextHelpId
SetScrollInfo
SetTimer
SetWindowLongW
SetWindowPos
SetWindowRgn
SetWindowTextW
ShowWindow
SystemParametersInfoW
ToAscii
TranslateMDISysAccel
TranslateMessage
UserHandleGrantAccess
DestroyIcon
IsCharAlphaA
CharNextA
GetTopWindow
GetMessageExtraInfo
GetKeyState
ShowCaret
IsCharLowerA
GetDialogBaseUnits
CharLowerA
IsGUIThread
GetWindowTextLengthW
GetSysColor
GetQueueStatus
VkKeyScanW
VkKeyScanA
DestroyCursor
IsCharAlphaNumericW
CharLowerW
LoadCursorFromFileA
CloseClipboard
GetLastActivePopup
GetMenuContextHelpId
IsMenu
GetInputState
GetKeyboardLayout
CloseDesktop
IsCharAlphaNumericA
GetWindowDC
PaintDesktop
GetActiveWindow
CharUpperA
IsWindow
GetCaretBlinkTime
GetClipboardSequenceNumber
GetThreadDesktop
CopyIcon
GetCursor
WindowFromDC
LoadCursorFromFileW
GetMenu
GetProcessWindowStation
EndMenu
GetOpenClipboardWindow
USER32.dll
AbortPath
AddFontResourceExW
AngleArc
CloseEnhMetaFile
CopyEnhMetaFileA
CreateColorSpaceW
CreateCompatibleDC
CreateFontA
CreateFontIndirectW
CreateSolidBrush
DeleteObject
EngCreateDeviceSurface
EngCreatePalette
EngDeleteSurface
EngFillPath
EngPaint
EngTextOut
FillRgn
FlattenPath
FloodFill
FontIsLinked
GdiAlphaBlend
GdiConvertBrush
GdiDeleteSpoolFileHandle
GdiEntry8
GdiPlayJournal
GdiPlayPrivatePageEMF
GdiSetBatchLimit
GetCharABCWidthsFloatW
GetCharABCWidthsW
GetCurrentPositionEx
GetDeviceCaps
GetEnhMetaFileW
GetFontData
GetGlyphIndicesA
GetObjectW
GetTextExtentExPointWPri
GetWinMetaFileBits
ModifyWorldTransform
NamedEscape
PathToRegion
PolyDraw
ScaleViewportExtEx
SetDIBColorTable
SetMetaRgn
SetPolyFillMode
SetROP2
SetTextAlign
UpdateColors
GetSystemPaletteUse
CreateMetaFileW
EndDoc
DeleteEnhMetaFile
BeginPath
CreatePatternBrush
GetTextCharacterExtra
CancelDC
GdiGetBatchLimit
GetColorSpace
EndPath
EndPage
SaveDC
SwapBuffers
CloseMetaFile
GetDCPenColor
AbortDoc
GetTextCharset
GdiFlush
FillPath
CloseFigure
GetTextAlign
GetMapMode
GetBkMode
GetStretchBltMode
CreateMetaFileA
GDI32.dll
CryptAcquireContextW
CryptCreateHash
CryptDestroyHash
CryptGetHashParam
CryptHashData
CryptReleaseContext
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RegSetValueExW
RegQueryValueExW
RegOpenKeyW
ADVAPI32.dll
ShellExecuteExA
SHGetFolderPathW
CommandLineToArgvW
SHELL32.dll
CoCreateInstance
CoInitialize
CoUninitialize
ole32.dll
StrCmpNA
StrStrA
SHLWAPI.dll
CreateStatusWindowW
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
InitCommonControlsEx
COMCTL32.dll
_XcptFilter
__dllonexit
__p__commode
__p__fmode
__set_app_type
__setusermatherr
__wgetmainargs
_adjust_fdiv
_c_exit
_cexit
_controlfp
_except_handler3
_initterm
_onexit
_purecall
_snwprintf
_wcmdln
_wcsicmp
_wcsnicmp
wcscat
wcscmp
wcscpy
wcslen
msvcrt.dll
2[T}t.TT
%Zj!zcu
RI45W,
NY&fb'
*F|(jC
j~M.Uo
$XP^Hx
L'p9^"-4
h(Le};`
BL=)\U_L
D&/v-X
+DvYx7X
4|ztW+d
KOm?4D
3M,>lg
)0bk#mjS
7C%#--A
}'iOHP
U6AJ$_D
^\f)ko
c5Rn,l/
~E*=ru
jlaDGj
IaEf5
4;a0/\
!:%obG
3b@SCm
:.\&{P
N>Xy;3
2xU\_>\
vF$K}&
?CZ_f9y@FPM
eJuRwCespd
WHxB lpoBh
GBpJCsYwqU
mJvVvfylwh
hJoyMDCfSQ
EfpCuGzkSr
www.madshi.net'Q
O\QT&k
GoS|Tk
Ur[\$l
M?Pk~(
>~/lfs;
4P~<&
1iq$)V
3o0q2KC
`E%u<
P<=*i7{x!
u#;<}TBq
O_;w|B
dg[WeZW
wXYj%0<
9yV)WxlX
N@N<.b9
I rAAM")9_`x
RpQ)Va
cr/Bjd
n^gjXC
M,LELJ
Ph;UnZ{
sey>V1
$840"
8sZJz%
W#Fu"S
!WNX\]
UUHs?c
-?-B2EW`V
n|{_+k
7Yb+O//
+bqQV#1
yE$a#%i
UYTBAu
'BBH_f
E&sJM(
]d8Qx}
fMe]Kx
33:8@R
33:6y
33D/''6f
)).b22K
33A?q
33D_Si
33@O33O
H%%xa11
)*+^vvv
677~CK
?333333
?tE)!XU
?tE)!XU
AUpdate
^Classes
UTypes
SysInit
System
SysConst
"RTLConsts
eCharacter
KWindows
SysUtils
YStrUtils
ImageHlp
sActiveX
3Messages
QTypInfo
CVariants
$VarUtils
NmadStackTrace
madZip
madStrings
KmadTypes
madTools
amadDisAsm
HmadMapFile
madCrypt
madNVPrgrAlert
^ActCommon
(ShlObj
UrlMon
?WinInet
RegStr
*ShellAPI
CommCtrl
xHttpGetThread
Logger
PSafeIniFile
IniFiles
_DateUtils
madListModules
madExcept
WinSock
3CommDlg
EmadNVBitmap
madNVAssistant
2madListProcesses
SmadListHardware
madLinkDisAsm
TMadExcept
madExcept
Enabled
NoSettings
CheckFileCrc
CheckFreeze
FreezeTimeout
AutoSave
AutoSaveIfNotSent
AutoSend
AutoSendBox
AutoClip
PauseThreads
PlWaitBox
AutoContinue
AutoRestart
AutoClose
SendBtnVis
SaveBtnVis
PrintBtnVis
ShowBtnVis
ContinueBtnVis
RestartBtnVis
CloseBtnVis
FocusedBtn
SendAssis
SendAssistant
SaveAssis
SaveAssistant
PrintAssis
PrintAssistant
AutoShowBugRep
UglyBtns
MailAddr
support10@iobit.com
SendInBackgr
MailAsSmtpServer
MailAsSmtpClient
UploadViaHttp
MailViaMapi
MailViaMailto
SmtpServer
SmtpPort
SmtpAccount
SmtpPassword
HttpServer
HttpPort
HttpAccount
HttpPassword
AttachBugRep
AttachBugRepFile
DelBugRepFile
BugRepSendAs
bugreport.txt
BugRepZip
ScrShotDepth
ScrShotAppOnly
ScrShotSendAs
screenshot.png
ScrShotZip
AddAttachs
BugRepFile
bugreport.txt
AppendBugReps
BugRepFileSize
NoDupExcepts
NoDupFreezes
DupExceptDef
DupFreezeDef
ListThreads
CpuRegs
StackDump
ShowDisAsm
HideUglyItems
ShowRelAddrs
ShowRelLines
FormatDisAsm
LimitDisAsm
Plugins
modules|processes|hardware
F1Classes
EDBEditError
F1NoBugRep
F1NoScrShot
F1NoHandlers
F1NoSuspend
F1ShowCfg
F1Assis
F2Classes
F2NoBugRep
F2NoScrShot
F2NoHandlers
F2NoSuspend
F2ShowCfg
F2Assis
GnNoBugRep
GnNoScrShot
GnNoHandlers
GnNoSuspend
GnShowCfg
GnAssis
Assistant1
SendAssistant|Send Assistant|ContactForm|DetailsForm|ScrShotForm
Assistant2
SaveAssistant|Save Assistant|ContactForm|DetailsForm
Assistant3
PrintAssistant|Print Assistant|ContactForm|DetailsForm
TitleBar
%appname%
ExceptMsg
An error occurred in the application.
FrozenMsg
The application seems to be frozen.
BitFaultMsg
The file "%modname%" seems to be corrupt!
SendBtnTxt
send bug report
SaveBtnTxt
save bug report
PrintBtnTxt
print bug report
ShowBtnTxt
show bug report
ContinueBtnTxt
continue application
RestartBtnTxt
restart application
CloseBtnTxt
close application
OkBtnTxt
DetailsBtnTxt
&Details
PlWaitTitle
Information
PlWaitText
Please wait a moment...
MailSubj
[Bug Report] - %appname%
MailBody
please find the bug report attached
SendBoxTitle
Sending bug report...
PrepAttMsg
Preparing attachments...
MxLookMsg
Searching for mail server...
ConnMsg
Connecting to server...
AuthMsg
Authentication...
SendMailMsg
Sending mail...
FieldMsg
Setting fields...
SendAttMsg
Sending attachments...
SendFinalMsg
Finalizing...
SendFailMsg
Sorry, sending the bug report didn't work.
TMEContactForm
ContactForm
Message
Contact Information
MinWidth
OnAction
madExcept.HandleContactForm
INVButton
ContinueBtn
Caption
Continue
Enabled
NoOwnerDraw
Visible
INVButton
SkipBtn
Caption
Enabled
NoOwnerDraw
Visible
INVButton
CancelBtn
Caption
Cancel
Enabled
NoOwnerDraw
Visible
INVLabel
Label1
Caption
your name:
Enabled
Spacing
INVEdit
NameEdit
Colored
Enabled
Optional
OutputName
contact name
OutputType
nvoHeader
Spacing
INVLabel
Label2
Caption
your email:
Enabled
Spacing
INVEdit
EmailEdit
Colored
Enabled
Optional
OutputName
contact email
OutputType
nvoHeader
Spacing
INVCheckBox
MemCheck
Caption
remember me
Checked
Enabled
OutputName
Spacing
TMEDetailsForm
DetailsForm
Message
Error Details
MinWidth
OnAction
INVButton
ContinueBtn
Caption
Continue
Enabled
NoOwnerDraw
Visible
INVButton
SkipBtn
Caption
Enabled
NoOwnerDraw
Visible
INVButton
CancelBtn
Caption
Cancel
Enabled
NoOwnerDraw
Visible
INVLabel
Label1
Caption
in which situation did the error occur?
Enabled
Spacing
INVEdit
DetailsMemo
Colored
Enabled
Optional
OutputName
error details
OutputType
nvoOwnSection
Spacing
TMEScrShotForm
ScrShotForm
ActiveControl
ContinueBtn
Message
Screenshot Configuration
MinWidth
OnAction
madExcept.HandleScreenshotForm
INVButton
ContinueBtn
Caption
Continue
Enabled
NoOwnerDraw
Visible
INVButton
SkipBtn
Caption
Enabled
NoOwnerDraw
Visible
INVButton
CancelBtn
Caption
Cancel
Enabled
NoOwnerDraw
Visible
INVCheckBox
AttachCheck
Caption
attach a screenshot to the bug report
Checked
Enabled
OutputName
Spacing
INVImage
ScrShotImg
Border
Clickable
Enabled
Height
Spacing
INVLabel
Label1
Caption
(click to edit image)
Enabled
Spacing
{zzzzzzzzzzzz
zzzzzzzzzzzz{(
[slnlllllllllllllllllnmmmmkks\-
>)++**++***+*+++++++++%%+%+$$G-
>9000<00<<<0000000<;=<A?;A:
FWZVY@S@@Y@YVTSSOOMOMMDCV\B
\WZURRNQNLQRPUUURQLNLJHJJHKII[
,,,,,,,/,E
/,/,,,,/8
m@@@@<4
lm::m}_
R,:::8
]::m^Q
4m@m^Q
2,:.nopsr?tuvwxyz
2,=.n`abcd
fghijk9.:m^Q
2,=..STUVdJKLYZ[\n==m^Q
2,=.=8FGHdJKLMNOE:.=m^1
2,=...:>?@
D<...3<^1
+,=...nnn456W
n..=.3m;1
+----------n--------,01
$$$$$$$$
]mnopqrstuvwxyz{|^_`abcdefghijklMNOPQRSTUVWXYZ[\]?@ABCDEFGHIJK<LM/0123456789:;<=> !"#$%&'()**+,-.
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="*"
name="IObit"
type="win32"
<description>IObit</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
i111111c76p3050F55D-98B5111CF1BB82500AA00BDCE0Bf
yKGSTkpqex
yAaEcpFKoa
smBORKYZTz
mtDjxGAxfp
CALIBRATE
EXCEPT
MEIBIG
MEICANTCONTINUE
MEICLOSE
MEICONTINUE
MEIPLWAIT
MEIPRINT
MEIRESTART
MEISAVE
MEISEND
MEISEND32
MEISHOW
CHARTABLE
DVCLAL
PACKAGEINFO
TMADEXCEPT
TMECONTACTFORM
TMEDETAILSFORM
TMESCRSHOTFORM
MAINICON
0@P`p
111QQQ
VS_VERSION_INFO
StringFileInfo
040904E5
CompanyName
IObit
+Out of memory while expanding memory stream
Stream read error
%s.Seek not implemented$Operation not allowed on sorted list
Stream write error
\'\'%s\'\' is not a valid date'\'\'%s\'\' is not a valid date and time'\'\'%s\'\' is not a valid integer value
\'\'%s\'\' is not a valid time
Invalid destination array"Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Cannot assign a %s to a %s%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid property value List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Unable to create directory
Invalid source array
January
February
August
September
October
November
December
Exception in safecall method
Object lock not owned(Monitor support function not initialized
%s (%s, line %d)
Abstract ErrorAAccess violation at address %p in module \'%s\'. %s of address %p
System Error. Code: %d.
%sA call to an OS function failed
$Error creating variant or safe array)Variant or safe array index out of boundsVariant or safe array is lockedInvalid variant type conversion
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
Application Error3Format \'%s\' invalid or incompatible with argument
No argument for format \'%s\'"Variant method calls not supported
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Ransom.359
FireEye Generic.mg.8b3d0bc69064a015
CAT-QuickHeal Ransom.Cerber.A4
McAfee Ransomware-CBER!8B3D0BC69064
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005224381 )
BitDefender Gen:Variant.Ransom.359
K7GW Trojan ( 0050e5e41 )
Cybereason malicious.69064a
BitDefenderTheta Gen:NN.ZexaF.34114.Eq0@aymjM4dP
VirIT Trojan.Win32.Genus.CBE
Cyren W32/S-502d1467!Eldorado
Symantec Ransom.Cerber
ESET-NOD32 Win32/Filecoder.Cerber.G
Baidu Clean
TrendMicro-HouseCall Ransom_HPCERBER.SMALY5A
Paloalto generic.ml
ClamAV Win.Ransomware.Cerber-9828953-0
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Ransom:Win32/generic.ali2000010
NANO-Antivirus Trojan.Win32.Zerber.epfvib
ViRobot Trojan.Win32.Cerber.504320
Rising Trojan.Generic@ML.100 (RDML:74HmFHENQ/+dFqwKEK17+Q)
Ad-Aware Gen:Variant.Ransom.359
Emsisoft Gen:Variant.Ransom.359 (B)
Comodo TrojWare.Win32.Ransom.Cerber.EW@73u1y1
F-Secure Clean
DrWeb Trojan.Siggen7.22225
Zillya Trojan.Zerber.Win32.2459
TrendMicro Ransom_HPCERBER.SMALY5A
McAfee-GW-Edition BehavesLike.Win32.Ransomware.gm
CMC Clean
Sophos Mal/Generic-R + Mal/Cerber-B
Ikarus Trojan.Krypt
GData Gen:Variant.Ransom.359
Jiangmin Trojan.Zerber.cdw
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1111273
MAX malware (ai score=100)
Antiy-AVL Trojan/Generic.ASMalwS.204E04B
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
APEX Malicious
Microsoft Ransom:Win32/Cerber.K
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/Cerber.Exp
Acronis suspicious
VBA32 BScope.Trojan.Encoder
ALYac Gen:Variant.Ransom.359
TACHYON Ransom/W32.Cerber.504320
Malwarebytes Malware.AI.3892641679
Zoner Clean
Tencent Malware.Win32.Gencirc.10b20a6a
Yandex Trojan.GenAsa!hwUIeNdKBl8
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet W32/Kryptik.HGZD!tr
Webroot Clean
Panda Trj/Genetic.gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.