Static | ZeroBOX

PE Compile Time

2090-01-16 18:26:43

PDB Path

cmd.pdb

PE Imphash

272245e2988e1e430500b852c4fb5e18

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00030ef9 0x00031000 6.30957865075
.rdata 0x00032000 0x0000a53c 0x0000a600 4.92262455461
.data 0x0003d000 0x0001bc50 0x00000200 3.17983043542
.pdata 0x00059000 0x00002334 0x00002400 5.48929985504
.didat 0x0005c000 0x00000090 0x00000200 1.03466026585
.rsrc 0x0005d000 0x000084f8 0x00008600 4.35939148345
.reloc 0x00066000 0x0000030c 0x00000400 4.67734346646

Resources

Name Offset Size Language Sub-language File type
MUI 0x00065420 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00064b98 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00065000 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00065098 0x00000388 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0005d350 0x00000428 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x140033af8 _setmode
0x140033b00 exit
0x140033b08 iswxdigit
0x140033b10 time
0x140033b18 srand
0x140033b20 _wtol
0x140033b28 fflush
0x140033b30 wcsstr
0x140033b38 iswalpha
0x140033b40 wcstoul
0x140033b48 _errno
0x140033b50 printf
0x140033b58 rand
0x140033b60 fprintf
0x140033b68 wcsncmp
0x140033b70 _pipe
0x140033b78 _commode
0x140033b80 _lock
0x140033b88 wcsrchr
0x140033b90 realloc
0x140033b98 towlower
0x140033ba0 _initterm
0x140033ba8 __setusermatherr
0x140033bb0 setlocale
0x140033bb8 _wcsupr
0x140033bc0 iswdigit
0x140033bc8 _ultoa
0x140033bd0 _cexit
0x140033bd8 _unlock
0x140033be0 _exit
0x140033be8 __dllonexit
0x140033bf0 _wcsicmp
0x140033bf8 iswspace
0x140033c00 wcschr
0x140033c08 fgets
0x140033c10 ??_V@YAXPEAX@Z
0x140033c18 _pclose
0x140033c20 ferror
0x140033c28 _onexit
0x140033c30 __CxxFrameHandler3
0x140033c38 _open_osfhandle
0x140033c40 _close
0x140033c48 feof
0x140033c50 _dup
0x140033c58 _wpopen
0x140033c60 _wcsnicmp
0x140033c68 ?terminate@@YAXXZ
0x140033c70 memset
0x140033c78 wcstol
0x140033c80 _get_osfhandle
0x140033c88 _dup2
0x140033c90 _getch
0x140033c98 towupper
0x140033ca0 memcmp
0x140033ca8 _setjmp
0x140033cb0 wcsspn
0x140033cb8 _fmode
0x140033cc0 qsort
0x140033cc8 __set_app_type
0x140033cd0 _tell
0x140033cd8 _wcslwr
0x140033ce0 longjmp
0x140033ce8 _local_unwind
0x140033cf0 _purecall
0x140033cf8 __C_specific_handler
0x140033d00 ??3@YAXPEAX@Z
0x140033d08 memcpy_s
0x140033d10 free
0x140033d18 calloc
0x140033d20 __getmainargs
0x140033d28 _XcptFilter
0x140033d30 _amsg_exit
0x140033d38 ??1type_info@@UEAA@XZ
0x140033d40 memmove
0x140033d48 memcpy
0x140033d50 _CxxThrowException
0x140033d58 _vsnwprintf
0x140033d60 swscanf
0x140033d68 __iob_func
0x140033d70 malloc
0x140033d78 _callnewh
0x140033d98 ??1exception@@UEAA@XZ
0x140033da8 wcscmp
Library ntdll.dll:
0x140033db8 RtlLookupFunctionEntry
0x140033dc0 RtlCaptureContext
0x140033dc8 NtOpenProcessToken
0x140033dd0 NtQueryInformationToken
0x140033dd8 NtClose
0x140033de0 NtOpenThreadToken
0x140033de8 RtlFreeHeap
0x140033df0 NtFsControlFile
0x140033e00 RtlVirtualUnwind
0x140033e08 RtlFreeUnicodeString
0x140033e10 RtlReleaseRelativeName
0x140033e18 NtOpenFile
0x140033e28 NtSetInformationFile
0x140033e38 NtSetInformationProcess
0x140033e48 RtlNtStatusToDosError
Library api-ms-win-core-kernel32-legacy-l1-1-0.dll:
0x140033788 CopyFileW
0x140033790 GetConsoleWindow
Library api-ms-win-core-libraryloader-l1-2-0.dll:
0x1400337a0 GetModuleHandleW
0x1400337a8 GetModuleFileNameA
0x1400337b0 LoadLibraryExW
0x1400337b8 GetProcAddress
0x1400337c0 GetModuleFileNameW
0x1400337c8 GetModuleHandleExW
Library api-ms-win-core-synch-l1-1-0.dll:
0x1400339c8 CreateSemaphoreExW
0x1400339d8 WaitForSingleObject
0x1400339e0 ReleaseSemaphore
0x1400339f0 WaitForSingleObjectEx
0x1400339f8 ReleaseMutex
0x140033a00 ReleaseSRWLockShared
0x140033a08 AcquireSRWLockShared
0x140033a10 LeaveCriticalSection
0x140033a18 CreateMutexExW
0x140033a20 EnterCriticalSection
0x140033a28 ReleaseSRWLockExclusive
0x140033a30 OpenSemaphoreW
Library api-ms-win-core-heap-l1-1-0.dll:
0x140033720 HeapFree
0x140033728 HeapAlloc
0x140033730 GetProcessHeap
0x140033738 HeapSetInformation
0x140033740 HeapReAlloc
0x140033748 HeapSize
Library api-ms-win-core-errorhandling-l1-1-0.dll:
0x1400335c8 SetLastError
0x1400335d0 UnhandledExceptionFilter
0x1400335d8 GetLastError
0x1400335e0 SetErrorMode
Library api-ms-win-core-processthreads-l1-1-0.dll:
0x1400338b8 GetCurrentThreadId
0x1400338d0 GetStartupInfoW
0x1400338d8 CreateProcessAsUserW
0x1400338e0 OpenThread
0x1400338e8 CreateProcessW
0x1400338f0 ResumeThread
0x1400338f8 TerminateProcess
0x140033900 GetExitCodeProcess
0x140033908 GetCurrentProcess
0x140033910 GetCurrentProcessId
Library api-ms-win-core-localization-l1-2-0.dll:
0x1400337d8 GetThreadLocale
0x1400337e0 SetThreadLocale
0x1400337e8 FormatMessageW
0x1400337f0 GetLocaleInfoW
0x1400337f8 GetCPInfo
0x140033800 GetACP
0x140033808 GetUserDefaultLCID
Library api-ms-win-core-debug-l1-1-0.dll:
0x140033588 OutputDebugStringW
0x140033590 DebugBreak
0x140033598 IsDebuggerPresent
Library api-ms-win-core-handle-l1-1-0.dll:
0x140033708 DuplicateHandle
0x140033710 CloseHandle
Library api-ms-win-core-memory-l1-1-0.dll:
0x140033818 VirtualAlloc
0x140033820 VirtualQuery
0x140033828 VirtualFree
0x140033830 ReadProcessMemory
Library api-ms-win-core-console-l1-1-0.dll:
0x1400334e0 ReadConsoleW
0x1400334e8 SetConsoleCtrlHandler
0x1400334f0 SetConsoleMode
0x1400334f8 WriteConsoleW
0x140033500 GetConsoleMode
0x140033508 GetConsoleOutputCP
Library api-ms-win-core-file-l1-1-0.dll:
0x1400335f8 CreateFileW
0x140033600 FlushFileBuffers
0x140033608 GetFileAttributesExW
0x140033610 GetDriveTypeW
0x140033618 FindClose
0x140033620 FindNextFileW
0x140033628 CreateDirectoryW
0x140033630 GetVolumeInformationW
0x140033638 SetFileAttributesW
0x140033640 SetEndOfFile
0x140033648 SetFilePointerEx
0x140033650 WriteFile
0x140033658 DeleteFileW
0x140033660 SetFileTime
0x140033668 GetVolumePathNameW
0x140033670 SetFilePointer
0x140033678 ReadFile
0x140033680 GetFileAttributesW
0x140033688 GetFileType
0x140033690 RemoveDirectoryW
0x140033698 FindFirstFileExW
0x1400336a0 CompareFileTime
0x1400336a8 GetFullPathNameW
0x1400336b0 GetDiskFreeSpaceExW
0x1400336b8 FileTimeToLocalFileTime
0x1400336c0 GetFileSize
0x1400336c8 FindFirstFileW
Library api-ms-win-core-string-l1-1-0.dll:
0x140033998 WideCharToMultiByte
0x1400339a0 MultiByteToWideChar
Library api-ms-win-core-processenvironment-l1-1-0.dll:
0x140033840 GetCommandLineW
0x140033848 GetEnvironmentStringsW
0x140033858 FreeEnvironmentStringsW
0x140033860 SetEnvironmentVariableW
0x140033868 SearchPathW
0x140033870 SetCurrentDirectoryW
0x140033878 GetCurrentDirectoryW
0x140033880 GetEnvironmentVariableW
0x140033888 SetEnvironmentStringsW
0x140033890 GetStdHandle
Library api-ms-win-core-console-l2-1-0.dll:
0x140033518 SetConsoleCursorPosition
0x140033540 FlushConsoleInputBuffer
0x140033548 SetConsoleTextAttribute
Library api-ms-win-security-base-l1-1-0.dll:
0x140033ad8 GetFileSecurityW
0x140033ae0 RevertToSelf
Library api-ms-win-core-sysinfo-l1-1-0.dll:
0x140033a50 GetSystemTime
0x140033a58 SetLocalTime
0x140033a60 GetSystemTimeAsFileTime
0x140033a68 GetTickCount
0x140033a70 GetWindowsDirectoryW
0x140033a78 GetLocalTime
0x140033a80 GetVersion
Library api-ms-win-core-timezone-l1-1-0.dll:
0x140033aa8 SystemTimeToFileTime
0x140033ab0 FileTimeToSystemTime
Library api-ms-win-core-datetime-l1-1-0.dll:
0x140033570 GetDateFormatW
0x140033578 GetTimeFormatW
Library api-ms-win-core-systemtopology-l1-1-0.dll:
0x140033a98 GetNumaHighestNodeNumber
Library api-ms-win-core-console-l2-2-0.dll:
0x140033558 SetConsoleTitleW
0x140033560 GetConsoleTitleW
Library api-ms-win-core-processenvironment-l1-2-0.dll:
Library api-ms-win-core-registry-l1-1-0.dll:
0x140033950 RegCloseKey
0x140033958 RegSetValueExW
0x140033960 RegOpenKeyExW
0x140033968 RegCreateKeyExW
0x140033970 RegEnumKeyExW
0x140033978 RegDeleteKeyExW
0x140033980 RegDeleteValueW
0x140033988 RegQueryValueExW
Library api-ms-win-core-file-l2-1-0.dll:
0x1400336d8 MoveFileExW
0x1400336e0 CreateSymbolicLinkW
0x1400336e8 CreateHardLinkW
0x1400336f0 MoveFileWithProgressW
Library api-ms-win-core-heap-l2-1-0.dll:
0x140033758 GlobalAlloc
0x140033760 GlobalFree
0x140033768 LocalFree
Library api-ms-win-core-io-l1-1-0.dll:
0x140033778 DeviceIoControl
Library api-ms-win-core-winrt-l1-1-0.dll:
0x140033ac0 RoInitialize
0x140033ac8 RoUninitialize
Library api-ms-win-core-processtopology-l1-1-0.dll:
0x140033920 GetThreadGroupAffinity
Library api-ms-win-core-synch-l1-2-0.dll:
0x140033a40 Sleep
Library api-ms-win-core-profile-l1-1-0.dll:
0x140033940 QueryPerformanceCounter
Library api-ms-win-core-string-obsolete-l1-1-0.dll:
0x1400339b0 lstrcmpW
0x1400339b8 lstrcmpiW
Library api-ms-win-core-processtopology-obsolete-l1-1-0.dll:
0x140033930 SetProcessAffinityMask
Library api-ms-win-core-apiquery-l1-1-0.dll:
Library api-ms-win-core-delayload-l1-1-1.dll:
0x1400335b8 ResolveDelayLoadedAPI
Library api-ms-win-core-delayload-l1-1-0.dll:
0x1400335a8 DelayLoadFailureHook

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.didat
@.reloc
UVWATAUAVAWH
fF9,gu
fD9,ou
@A_A^A]A\_^]
UWATAVAWH
fE9$@u
A_A^A\_]
UVWATAUAVAWH
fD9,_u
fD9,Au
fD9,Au
A_A^A]A\_^]
\$ UVWATAUAVAWH
fG94lu
fD94~u
fD94~u
fD94{u
fD94Su
A_A^A]A\_^]
UWATAVAWH
fD9$Wu
A_A^A\_]
x UAVAWH
x UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
fD9,Fu
@A_A^A]A\_^]
\$ UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
fD9,Ku
D$89|$P
A_A^A]A\_^[]
@USVWATAVAWH
A_A^A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
fF9$Iu
fD9$yu
A_A^A]A\_^]
@USVWATAUAVAWH
fD9,^u
fD9,Vu
fD9,Cu
fD9,Cu
fD9,Su
A_A^A]A\_^[]
fE9,Wu
fE9,xu
x ATAVAWH
A_A^A\
WATAUAVAWH
fE9&tdA
fE9$vu
A_A^A]A\_
UAVAWH
@A_A^]
UVWATAUAVAWH
A_A^A]A\_^]
SUVWATAUAVAWH
A_A^A]A\_^][
@USVWATAUAVAWH
fD9$Fu
A_A^A]A\_^[]
x ATAUAVH
*t|fA;
A^A]A\
fA94Hu
f9tQ,u
WAVAWH
A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
x UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
A_A^A]A\_
x UAVAWH
UVWATAUAVAWH
0A_A^A]A\_^]
WAVAWH
fF9<Au
A_A^_
x UATAUAVAWH
A_A^A]A\]
D8L$iL
x ATAVAWH
fD9 tK
A_A^A\
UAVAWH
UVWATAUAVAWH
fA9<wu
A_A^A]A\_^]
HcT$ L
WAVAWH
A_A^_
WAUAVH
x ATAVAWH
A_A^A\
x UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UWAUAVAWH
A_A^A]_]
@SUVWATAUAVAWH
|$4fE99
t$@D8=
A_A^A]A\_^][
fD94Au
fD94yu
UVWATAUAVAWH
fD94Gu
@A_A^A]A\_^]
ATAVAWH
fD9$Zu
fD9 tuH
fD9$Cu
A_A^A\
WATAUAVAWH
fB9<iu
A_A^A]A\_
UVWATAUAVAWH
D8L$ t
A_A^A]A\_^]
UWATAVAWH
fD93u6H;
A_A^A\_]
t$ UWATAVAWH
A_A^A\_]
\$ UVWATAUAVAWH
A_A^A]A\_^]
fD9,Gu
fD9,Ou
9:uGH9-n
t$ WATAUAVAWH
fD9$yu
fF9$xu
A_A^A]A\_
USVWATAUAVAWH
A_A^A]A\_^[]
WATAUAVAWH
A_A^A]A\_
x UATAUAVAWH
A_A^A]A\]
f90t13
UVWATAUAVAWH
A_A^A]A\_^]
4FHcD$`H
HcD$`H
H+L$xH
$DHcD$`H
t$ WATAUAVAWH
A_A^A]A\_
$DHcD$PM
HcD$PM
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
UVWATAUAVAWH
A_A^A]A\_^]
@SVAUH
SVWATAUAVAWH
D$ fA;
A_A^A]A\_^[
WAVAWH
A_A^_
t$ WATAVH
A^A\_
UVATAVAWH
fD99t~D9=<u
A_A^A\^]
|$ UATAUAVAWH
A_A^A]A\]
WAVAWH
fD9<Cu
A_A^_
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
fE9$Ou
fE9$Gu
A_A^A]A\_^]
CHcD$pH
HcD$pH
SUWATAUAVAWH
@A_A^A]A\_][
\$ UVWATAUAVAWH
fD9,xu
fD9,Wu
fE94Wu
fD94~u
A_A^A]A\_^]
9T$0u0
L$ UVWATAUAVAWH
0A_A^A]A\_^]
tRHcL$xI
@USVWATAUAVAWH
A_A^A]A\_^[]
D$@fD9'
H+|$@H
SVWATAUAVAWH
d$x@8=
f98tDA
fA9<@u
A_A^A]A\_^[
SUVWATAVAWH
`A_A^A\_^][
`A_A^A\_^][
D$@H9t$@
UVWATAUAVAWH
fD9<qu
A_A^A]A\_^]
fA9<Vu
fA9<Fu
UVWATAUAVAWH
fE9<^u
A_A^A]A\_^]
H!\$ L
x AUAVAWH
t,9u(D
@A_A^A]
UATAVH
fE9<nu
fD9<{u
t$HD9=
fD9<Cu
|$ ATAVAWH
fD9$Cu
fD9$pu
A_A^A\
@SUVWAVH
0A^_^][
WATAUAVAWH
H!|$`I
A_A^A]A\_
t$ WAVAWH
fB9<su
\uc@8=
WAUAVH
t!fD9l$
fD9t$"
fD9l$
UWATAVAWH
A_A^A\_]
|$ AVH
|$ AVH
@USVWATAUAVAWH
A_A^A]A\_^[]
\$ UVWAVAWH
pA_A^_^]
l$ VWAVH
v;f98
UVWATAUAVAWH
u#D8g!u
A_A^A]A\_^]
UVWATAUAVAWH
|$8D9{
fD9|F0u
T$XD;{
A_A^A]A\_^]
UVWATAUAVAWH
n(D9-c
A_A^A]A\_^]
WATAUAVAWH
|$[fD9?
u+fD9o
A_A^A]A\_
f99ujH
L$8f99u`+
f9(u%H
t$ WATAUAVAWH
fD9$xu
A_A^A]A\_
u*9Q<|%
LcA<E3
u HcA<H
H3E H3E
SVWAVH
8A^_^[
u0D9d$
fD9,Au
fD9,Au
fB9<{u
L+D$ H+
fA9,Pu
fA94Du
KxfD91
fD94yu
HcD$`H
fD9$su
fD9<Hu
D9|$Pt
u4D95N
fE9$wu
tGHcT$0M
fA9<Vu
L$ht'A
fD9<Xu
fE9<^u
D9|$0u$E3
D9|$0u$E3
fD9d$P
fD9,Cu
f;0u>H
C0D9s$
fD9$_u
fD9$Au
fD9$Au
fE9,Fu
fE9,Fu
9|$Pt!H
fD9$Cu
fD9$Hu
fD9$Au
fD9,Ju
fD9,Cu
fE9,Gu
fE9,Ft
\$dD9L$T
fD9TH,u
|$z:t0A
t|D9t$xuuH
tBD9t$pu;H
D$xH#E
L$4uFA
t$49\$Ht&9
uE9\$<uE
K9\$<t
fD9$xu
t<fA9(t6I
UVWAVAWH
D$8H!t$8H
A_A^_^]
UVWAVAWH
D$0fD98t
A_A^_^]
\$ UVWAVAWH
L9{0t#H
A_A^_^]
@SUVWH
WATAUAVAWH
A_A^A]A\_
L$ SWH
t$ WAVAWH
0A_A^_
x ATAVAWH
H9{Hs>H
A_A^A\
x UAVAWH
D$0fD98t
D$0fD98t
HcL$ HcD$$H
ATAVAWH
fA94Ru
A_A^A\
@SUVWATAUAVAWH
fD94Ou
fD94Bu
A_A^A]A\_^][
@USVWATAUAVAWH
FtFfD9
fD9$Fu
fD9$Fu
fD9$Fu
A_A^A]A\_^[]
t4f93t/H
L$Xf91t
\$ UVWATAUAVAWH
@A_A^A]A\_^]
\$ UVWATAUAVAWH
@A_A^A]A\_^]
Fxf9(u-3
Gxf9(u,3
WATAUAVAWH
fD9$nu
fD9$_u
fD9$_u
A_A^A]A\_
x UATAUAVAWH
u"f90u&H
f90u&H
A_A^A]A\]
{ ATAVAWH
fE9$Fu
AfD9!u
fD9$Au
@A_A^A\
UWATAVAWH
|$P.uEH
fD9$Gu
fD9$hu
A_A^A\_]
UVWATAUAVAWH
A_A^A]A\_^]
{ ATAVAWH
fE9$Fu
AfD9!u
fD9$Au
@A_A^A\
t$0uKE3
H9L$@r
tsHcL$8L
HcT$8H
f9|$Xvx
t,fD92t&I
M0H9M`t
WAVAWH
fD9<Gu
\$ UVWATAUAVAWH
fD9<Bu
D$`fD98t
tlfD9>tfI
fF9<fu
A_A^A]A\_^]
x UATAUAVAWH
fD9$Cu
<GfD9#
fD9$Gu
fD9$Su
fD9$Wu
fF9$pu
fD9$Ku
A_A^A]A\]
f9|$Vt"
` AUAVAWH
t$(9|$8t1
f9|$<tMI;
fA9<Du
fA9<\u
A_A^A]
WATAUAVAWH
fD9$hu
A_A^A]A\_
fD94Wu
L$ USWH
WAVAWH
A_A^_
VAVAWH
tbD9t$Pu[H
0A_A^^
UVWATAUAVAWH
d$Ht*E
D;d$@D
A_A^A]A\_^]
x ATAVAWH
@A_A^A\
H!|$ L
\$ UVWATAUAVAWH
fD94Hu
fD94xu
`A_A^A]A\_^]
WAVAWH
fD94Cu
fD94wu
A_A^_H
WATAUAVAWH
A_A^A]A\_
@SUVWAVH
A^_^][
UVWATAUAVAWH
fD9 t&f
:ufD9`
A_A^A]A\_^]
\$ UVWH
l$ VWATAVAWH
fF9$Cu
A_A^A\_^
UWATAVAWH
fD94Au
D9t$DtND
A_A^A\_]
x UAVAWH
WATAUAVAWH
A_A^A]A\_
WAVAWH
D9y$vb
fD9|G0u
fD9|G0u
A_A^_
UVWATAUAVAWH
D9f$t
l$PLcv$I
fF9Dj0u
A_A^A]A\_^]
SVWATAUAVAWH
@A_A^A]A\_^[
WATAUAVAWH
H9t$Xt eH
A_A^A]A\_
x UATAVH
UVWAVAWH
@A_A^_^]
SetThreadUILanguage
bad allocation
ext-ms-win-branding-winbrand-l1-1-0.dll
ext-ms-win-cmd-util-l1-1-0.dll
ext-ms-win-shell-shell32-l1-2-0.dll
generic
unknown error
iostream
iostream stream error
system
invalid string position
string too long
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
Exception
ReturnHr
FailFast
onecore\internal\sdk\inc\wil\opensource\wil\resource.h
WilError_03
CopyFileExW
IsDebuggerPresent
SetConsoleInputExeNameW
RaiseFailFastException
RtlDllShutdownInProgress
RtlDisownModuleHeapAllocation
CMD Internal Error %s
Null environment
APerformUnaryOperation: '%c'
APerformArithmeticOperation: '%c'
NtQueryInformationProcess
Copyright (c) Microsoft Corporation. All rights reserved.
onecore\base\cmd\StartShellExecServiceProvider.h
onecore\base\cmd\maxpathawarestring.cpp
cmd.pdb
.text$di
.text$lp00cmd.exe!20_pri7
.text$lp01cmd.exe!20_pri7
.text$mn
.text$mn$00
.text$np
.text$x
.text$yd
.text$zy
.text$zz
.rdata$brc
.rdata$00$brc
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIY
.CRT$XIZ
.gehcont
.gfids
.giats
.gljmp
.rdata
.rdata$00
.rdata$zz
.rdata$zzzdbg
.xdata
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.idata$2
.idata$3
.idata$4
.idata$6
.data$brc
.data$dk00$brc
.data$r$brc
.data$00
.data$pr00
.data$zz
.bss$00
.bss$dk00
.bss$pr00
.bss$zz
.pdata
.didat$5
.rsrc$01
.rsrc$02
BrandingFormatString
CmdBatNotificationStub
SaferWorker
MessageBeepStub
GetVDMCurrentDirectoriesStub
ShellExecuteWorker
DoSHChangeNotify
QueryFullProcessImageNameWStub
WNetGetConnectionWStub
WNetCancelConnection2WStub
WNetAddConnection2WStub
LookupAccountSidWStub
FindFirstStreamWStub
FindNextStreamWStub
ShellExecuteExW
??_V@YAXPEAX@Z
_vsnwprintf
memcpy_s
??3@YAXPEAX@Z
__C_specific_handler
longjmp
wcsspn
towupper
_getch
_get_osfhandle
wcstol
_wcsnicmp
_wpopen
ferror
_pclose
wcschr
iswspace
_wcsicmp
iswdigit
_wcsupr
setlocale
towlower
realloc
wcsrchr
fprintf
printf
_errno
wcstoul
iswalpha
wcsstr
fflush
iswxdigit
_setmode
wcsncmp
_ultoa
swscanf
_open_osfhandle
_close
_wcslwr
_purecall
calloc
_XcptFilter
_amsg_exit
__getmainargs
__set_app_type
_cexit
__setusermatherr
_initterm
_fmode
_commode
msvcrt.dll
_unlock
__dllonexit
_onexit
__CxxFrameHandler3
?terminate@@YAXXZ
RtlCreateUnicodeStringFromAsciiz
NtCancelSynchronousIoFile
RtlNtStatusToDosError
NtQueryInformationProcess
NtSetInformationProcess
NtQueryVolumeInformationFile
NtSetInformationFile
RtlDosPathNameToRelativeNtPathName_U_WithStatus
NtOpenFile
RtlReleaseRelativeName
RtlFreeUnicodeString
RtlFindLeastSignificantBit
RtlDosPathNameToNtPathName_U
NtFsControlFile
RtlFreeHeap
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
CopyFileW
GetConsoleWindow
api-ms-win-core-kernel32-legacy-l1-1-0.dll
GetModuleFileNameA
CreateSemaphoreExW
HeapFree
SetLastError
ReleaseSemaphore
GetModuleHandleExW
WaitForSingleObject
GetCurrentThreadId
ReleaseMutex
FormatMessageW
GetLastError
OutputDebugStringW
WaitForSingleObjectEx
OpenSemaphoreW
CloseHandle
HeapAlloc
GetProcAddress
CreateMutexExW
GetCurrentProcessId
GetProcessHeap
GetModuleHandleW
DebugBreak
IsDebuggerPresent
VirtualQuery
GetCPInfo
GetConsoleOutputCP
SetThreadLocale
SetFilePointer
GetFullPathNameW
FindFirstFileW
FindNextFileW
FindClose
CreateFileW
ReadFile
MultiByteToWideChar
GetFileSize
WideCharToMultiByte
GetStdHandle
FlushConsoleInputBuffer
RevertToSelf
AcquireSRWLockShared
ReleaseSRWLockShared
GetConsoleScreenBufferInfo
ReadConsoleW
SetConsoleCursorPosition
FillConsoleOutputCharacterW
WriteConsoleW
GetFileType
GetUserDefaultLCID
GetLocaleInfoW
SetLocalTime
GetSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
FileTimeToSystemTime
GetDateFormatW
GetTimeFormatW
GetLocalTime
GetConsoleMode
SetConsoleMode
GetEnvironmentVariableW
GetCommandLineW
GetNumaHighestNodeNumber
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetEnvironmentStringsW
GetConsoleTitleW
SetErrorMode
InitializeProcThreadAttributeList
UpdateProcThreadAttribute
DeleteProcThreadAttributeList
GetStartupInfoW
CreateProcessAsUserW
CreateProcessW
GetFileAttributesW
NeedCurrentDirectoryForExePathW
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
RegEnumKeyExW
RegDeleteKeyExW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
LoadLibraryExW
ReadProcessMemory
MoveFileWithProgressW
MoveFileExW
SetConsoleTitleW
LocalFree
SearchPathW
WriteFile
SetFilePointerEx
GlobalAlloc
GlobalFree
GetVolumeInformationW
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
ExpandEnvironmentStringsW
InitializeCriticalSection
SetConsoleCtrlHandler
GetWindowsDirectoryW
GetModuleFileNameW
EnterCriticalSection
LeaveCriticalSection
GetVersion
GetDriveTypeW
GetFileAttributesExW
OpenThread
HeapSetInformation
VirtualFree
VirtualAlloc
HeapReAlloc
HeapSize
DuplicateHandle
FlushFileBuffers
GetACP
ScrollConsoleScreenBufferW
FillConsoleOutputAttribute
SetConsoleTextAttribute
CreateDirectoryW
SetFileAttributesW
SetEndOfFile
DeleteFileW
SetFileTime
SetCurrentDirectoryW
TerminateProcess
GetExitCodeProcess
GetCurrentDirectoryW
GetFileInformationByHandleEx
RemoveDirectoryW
CompareFileTime
GetFileSecurityW
GetSecurityDescriptorOwner
DeviceIoControl
GetDiskFreeSpaceExW
FindFirstFileExW
RoInitialize
RoUninitialize
GetThreadGroupAffinity
GetNumaNodeProcessorMaskEx
ResumeThread
GetThreadLocale
GetVolumePathNameW
CreateSymbolicLinkW
CreateHardLinkW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-synch-l1-1-0.dll
api-ms-win-core-heap-l1-1-0.dll
api-ms-win-core-errorhandling-l1-1-0.dll
api-ms-win-core-processthreads-l1-1-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-debug-l1-1-0.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-memory-l1-1-0.dll
api-ms-win-core-console-l1-1-0.dll
api-ms-win-core-file-l1-1-0.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-processenvironment-l1-1-0.dll
api-ms-win-core-console-l2-1-0.dll
api-ms-win-security-base-l1-1-0.dll
api-ms-win-core-sysinfo-l1-1-0.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-core-datetime-l1-1-0.dll
api-ms-win-core-systemtopology-l1-1-0.dll
api-ms-win-core-console-l2-2-0.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-file-l2-1-0.dll
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-core-io-l1-1-0.dll
api-ms-win-core-winrt-l1-1-0.dll
api-ms-win-core-processtopology-l1-1-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-profile-l1-1-0.dll
lstrcmpiW
lstrcmpW
api-ms-win-core-string-obsolete-l1-1-0.dll
SetProcessAffinityMask
api-ms-win-core-processtopology-obsolete-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-apiquery-l1-1-0.dll
__iob_func
malloc
_callnewh
??0exception@@QEAA@AEBQEBD@Z
??0exception@@QEAA@AEBQEBDH@Z
??0exception@@QEAA@AEBV0@@Z
??1exception@@UEAA@XZ
?what@exception@@UEBAPEBDXZ
_CxxThrowException
memcpy
memmove
??1type_info@@UEAA@XZ
NtOpenProcessToken
NtQueryInformationToken
NtClose
NtOpenThreadToken
ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-delayload-l1-1-1.dll
api-ms-win-core-delayload-l1-1-0.dll
_local_unwind
_setjmp
memcmp
memset
wcscmp
.?AVbad_alloc@std@@
.?AVexception@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="amd64"
name="Microsoft.Windows.FileSystem.CMD"
type="win32"
<description>Windows Command Processor</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
<windowsSettings xmlns:ws2="http://schemas.microsoft.com/SMI/2016/WindowsSettings">
<ws2:longPathAware>true</ws2:longPathAware>
</windowsSettings>
</application>
</assembly>
wwwwwwwwwwwwwwwwwwwww
Se%ae`
cCBR_p
RRRRP%
CCCC@40`P@
cG?CCRRRRP`R
4qaCCRCCCB
pqacG%%apppppppaB
prRRRPa
wwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwww
se%%%%% R
u%6RRRRRPp
wwwwwwwwwwwwwww
wwwwwwwwp
wwwwwwww
!

((((&&(&&&(&(&&&&&&(((#&&###
*)))))))))))))))))))))
eIDATx
""""""""""""""""""""""""""""""""""""""""
'Px0&D
XXX8Pvh8v
],//cuu
n<DSbb
!KD4)#
NDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
DISABLEEXTENSIONS
ENABLEDELAYEDEXPANSION
ENABLEEXTENSIONS
tokens=
delims=
useback
usebackq
=,;+/[]
()|&=,;"
CMD.EXE
0123456789
ERRORLEVEL
CMDCMDLINE
CMDEXTVERSION
DEFINED
HIGHESTNUMANODENUMBER
RANDOM
%2d%s%02d%s%02d%s%02d
PATHEXT
fdpnxsatz
COPYCMD
PROMPT
COMSPEC
MM/dd/yy
Software\Microsoft\Command Processor
AutoRun
PathCompletionChar
CompletionChar
DefaultColor
DelayedExpansion
EnableExtensions
DisableUNCCheck
Software\Policies\Microsoft\Windows\System
\XCOPY.EXE
=ExitCodeAscii
=ExitCode
<>+-*/%()|^&=,
????????.???
DIRCMD
%d.%d.%05d.%d
Software\Microsoft\Windows NT\CurrentVersion
NEWWINDOW
BELOWNORMAL
ABOVENORMAL
AFFINITY
KERNEL32.DLL
/D /c"
ext-ms-win-branding-winbrand-l1-1-0
ext-ms-win-branding-winbrand-l1-1-1
ext-ms-win-branding-winbrand-l1-1-2
ext-ms-win-branding-winbrand-l1-2-0
lext-ms-win-cmd-util-l1-1-0
ext-ms-win-shell-shell32-l1-2-0
ext-ms-win-shell-shell32-l1-2-1
ext-ms-win-shell-shell32-l1-2-2
ext-ms-win-shell-shell32-l1-2-3
ext-ms-win-shell-shell32-l1-3-0
%hs(%u)\%hs!%p:
%hs!%p:
(caller: %p)
%hs(%d) tid(%x) %08X %ws
Msg:[%ws]
CallContext:[%hs]
[%hs(%hs)]
%WINDOWS_COPYRIGHT%
WGeToken: (%x) '%s'
cmd.exe
MKLINK
ENDLOCAL
SETLOCAL
VERIFY
PROMPT
RENAME
kernelbase.dll
ntdll.dll
Local\SM0:%d:%d:%hs
DISABLEDELAYEDEXPANSION
chdir
rmdir
mkdir
pushd
dd/MM/yy
yy/MM/dd
HH:mm:ss t
%s %s
%s %s%s
(%s) %s
%02d%s%02d%s
%02d%s%02d%s%02d
.COM;.EXE;.BAT;.CMD;.VBS;.JS;.WS;.MSC
\CMD.EXE
%04X-%04X
Software\Classes
NTDLL.DLL
\Shell\Open\Command
Ungetting: '%s'
Unknown
FOR /?
REM /?
DisableCMD
Application
System
%s (%s) %s
Cmd: %s Type: %x
Args: `%s'
*** Unknown type: %x
Redir:
%x %c
<noalias>
[...]
NORMAL
REALTIME
SEPARATE
SHARED
/K %s
&()[]{}^=;!%'+,`~
IDI_APPICON
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Windows Command Processor
FileVersion
10.0.19041.746 (WinBuild.160101.0800)
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
Cmd.Exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.746
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
No IRMA results available.