Static | ZeroBOX

PE Compile Time

2023-07-29 13:46:38

PDB Path

C:\Users\Clive\source\repos\x86_driver\Release\x86.pdb

PE Imphash

20afef352a96b089338fdac7aa310ca8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004259e 0x00042600 6.63251161859
.rdata 0x00044000 0x00011a68 0x00011c00 5.40603949666
.data 0x00056000 0x0001afcc 0x00001a00 3.83086036597
.rsrc 0x00071000 0x000288f0 0x00028a00 6.14768308097
.reloc 0x0009a000 0x000033c4 0x00003400 6.62105879082

Resources

Name Offset Size Language Sub-language File type
SYS 0x000710b0 0x00028618 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL PE32+ executable (native) x86-64, for MS Windows
RT_MANIFEST 0x000996c8 0x00000224 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library SHLWAPI.dll:
0x4441f4 PathFileExistsA
Library ADVAPI32.dll:
0x444000 RegSetValueExW
0x444004 OpenProcessToken
0x444010 RegSetValueExA
0x444014 RegFlushKey
0x444018 RegCreateKeyExW
Library USER32.dll:
0x4441fc SendMessageA
0x444200 GetSystemMetrics
0x444204 wsprintfA
0x444208 SetWindowPos
0x44420c GetWindowRect
0x444210 MessageBoxA
0x444214 FindWindowA
0x444218 FindWindowExA
0x44421c GetWindow
0x444224 GetTopWindow
Library ntdll.dll:
0x44424c RtlUnwind
0x444250 NtLoadDriver
Library KERNEL32.dll:
0x444020 EncodePointer
0x444024 SetStdHandle
0x444034 GetOEMCP
0x444038 GetACP
0x44403c IsValidCodePage
0x444040 FindNextFileW
0x444044 FindFirstFileExW
0x444048 FindClose
0x444050 ReadConsoleW
0x444054 SetFilePointerEx
0x444058 GetFileSizeEx
0x44405c GetConsoleMode
0x444060 GetConsoleCP
0x444064 FlushFileBuffers
0x44406c DeleteFileW
0x444070 GetFileType
0x444074 EnumSystemLocalesW
0x44407c CreateFileA
0x444080 CreateFileW
0x444084 GetFileSize
0x444088 ReadFile
0x44408c WriteFile
0x444090 DecodePointer
0x444094 CloseHandle
0x444098 RaiseException
0x44409c GetLastError
0x4440a0 HeapDestroy
0x4440a4 HeapAlloc
0x4440a8 HeapReAlloc
0x4440ac HeapFree
0x4440b0 HeapSize
0x4440b4 GetProcessHeap
0x4440c0 Sleep
0x4440c4 GetCurrentProcess
0x4440c8 GetCurrentProcessId
0x4440cc TerminateProcess
0x4440d0 CreateProcessA
0x4440d4 OpenProcess
0x4440d8 GetModuleHandleA
0x4440dc GetProcAddress
0x4440e0 LoadResource
0x4440e4 LockResource
0x4440e8 SizeofResource
0x4440ec LoadLibraryA
0x4440f0 lstrcmpiA
0x4440f4 lstrcpyA
0x4440f8 lstrcatA
0x4440fc lstrlenA
0x444104 FindResourceA
0x444110 QueryDosDeviceA
0x444114 IsBadReadPtr
0x444118 MultiByteToWideChar
0x44411c WideCharToMultiByte
0x444124 Process32First
0x444128 Process32Next
0x444138 WriteConsoleW
0x44413c LCMapStringEx
0x444140 GetLocaleInfoEx
0x444144 GetStringTypeW
0x444148 CompareStringEx
0x44414c GetCPInfo
0x444150 IsDebuggerPresent
0x444154 OutputDebugStringW
0x444158 GetUserDefaultLCID
0x44415c IsValidLocale
0x444160 GetLocaleInfoW
0x444164 LCMapStringW
0x444168 CompareStringW
0x44416c GetTimeFormatW
0x444170 GetDateFormatW
0x444174 GetCommandLineW
0x444178 GetCommandLineA
0x44417c GetStdHandle
0x444180 GetModuleFileNameW
0x444188 SetEvent
0x44418c ResetEvent
0x444194 CreateEventW
0x444198 GetModuleHandleW
0x4441a4 GetStartupInfoW
0x4441b0 GetCurrentThreadId
0x4441b8 InitializeSListHead
0x4441bc SetLastError
0x4441c0 TlsAlloc
0x4441c4 TlsGetValue
0x4441c8 TlsSetValue
0x4441cc TlsFree
0x4441d0 FreeLibrary
0x4441d4 LoadLibraryExW
0x4441d8 ExitProcess
0x4441dc GetModuleHandleExW
0x4441e0 GetDriveTypeW
0x4441e4 GetFullPathNameW
Library SHELL32.dll:
0x4441ec ShellExecuteA
Library WININET.dll:
0x44422c HttpQueryInfoA
0x444230 InternetReadFile
0x444234 InternetOpenUrlA
0x444238 InternetCloseHandle
0x44423c InternetOpenA
Library urlmon.dll:
0x44425c URLDownloadToFileA

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
uhSPPj
SWhlGD
PRQhx`E
tchtID
tG9uCj
tG9uCj
tG9uCj
tZ9uVj
W9^Lt"
GL9_8u
tC97u?j4
t{9uwj
t{9uwj
tO9uKjD
tO9uKjD
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tc9u_jX
td9u`jX
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tZ9uVj
tZ9uVj
tI97uEjD
tI97uEjD
tS9uOj
tS9uOj
YPhsaD
M$+E4@Pj
M$+E4@Pj
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
t{9uwj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tI97uEjD
tS9uOj
M$+E4@Pj
<xt><Xu=
<xt <Xt
<xt"<Xu!
QQQPSVW
QQSVWd
URPQQh
UQPXY]Y[
YYh<CD
t#VhLrD
u9jAXf;
u-jAXf;
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
zSSSSj
7ARPRQh
PPPPPPPP
j,hpGE
SWt@jU
@s1PVj@W
>Cu2f9V
Wj0XPV
SPjdVQ
PPPPPWS
PP9E u<PPVWP
j$hXKE
SSVWh
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@hX
9C`u99C\t4
u29K\t-
PPPPPPPP
Unknown exception
bad array new length
string too long
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
--BaseAddress--%llX
--AllocationBase--%llX
--AllocationProtect--%d
--RegionSize--%d
--State--%d
--Protect--%d
--Type--%d
RtlImageDirectoryEntryToData
ntdll.dll
SeLoadDriverPrivilege
C:\Driver2030.sys
EvilDriver
LinLauncherWnd
Lineage
#32770
0729_1
C:\Config.ini
x86.exe
TWClient.bin
partial
error
noconv
unknown
, please check out_cvt_state.
._cache_
Chinese_Taiwan.950
http://149.129.37.78:22556/ck?m=
InternetOpen fail
error open url
error query info
error to read file
x86_dll_ver
%s\x86.dll
x86_exe_ver
%s\AP.exe
invalid string position
vector too long
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
%b %d %H : %M : %S %Y
%m / %d / %y
:AM:am:PM:pm
%I : %M : %S %p
%H : %M
%H : %M : %S
%d / %m / %y
0123456789-
0123456789-
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
0123456789ABCDEFabcdef-+XxPp
+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
0123456789-
0123456789-
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
SleepConditionVariableCS
WakeAllConditionVariable
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
C:\Users\Clive\source\repos\x86_driver\Release\x86.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
PathFileExistsA
SHLWAPI.dll
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueA
RegCreateKeyExW
RegFlushKey
RegSetValueExA
RegSetValueExW
ADVAPI32.dll
wsprintfA
SendMessageA
SetWindowPos
GetSystemMetrics
GetWindowRect
MessageBoxA
FindWindowA
FindWindowExA
GetTopWindow
GetWindowThreadProcessId
GetWindow
USER32.dll
NtQuerySystemInformation
RtlInitUnicodeString
RtlDosPathNameToNtPathName_U
NtLoadDriver
ntdll.dll
GetCurrentDirectoryA
CreateFileA
CreateFileW
GetFileSize
ReadFile
WriteFile
DecodePointer
CloseHandle
RaiseException
GetLastError
HeapDestroy
HeapAlloc
HeapReAlloc
HeapFree
HeapSize
GetProcessHeap
InitializeCriticalSectionEx
DeleteCriticalSection
GetCurrentProcess
GetCurrentProcessId
TerminateProcess
CreateProcessA
OpenProcess
GetModuleHandleA
GetProcAddress
LoadResource
LockResource
SizeofResource
LoadLibraryA
lstrcmpiA
lstrcpyA
lstrcatA
lstrlenA
GetLogicalDriveStringsA
FindResourceA
GetPrivateProfileStringA
WritePrivateProfileStringA
QueryDosDeviceA
IsBadReadPtr
MultiByteToWideChar
WideCharToMultiByte
CreateToolhelp32Snapshot
Process32First
Process32Next
K32GetProcessImageFileNameA
EnterCriticalSection
LeaveCriticalSection
EncodePointer
LCMapStringEx
GetLocaleInfoEx
GetStringTypeW
CompareStringEx
GetCPInfo
IsDebuggerPresent
OutputDebugStringW
KERNEL32.dll
ShellExecuteA
SHELL32.dll
InternetOpenA
InternetCloseHandle
InternetOpenUrlA
InternetReadFile
HttpQueryInfoA
WININET.dll
URLDownloadToFileA
urlmon.dll
RtlUnwind
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetModuleHandleW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
SetLastError
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetDriveTypeW
GetFullPathNameW
GetModuleFileNameW
GetStdHandle
GetCommandLineA
GetCommandLineW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
DeleteFileW
GetCurrentDirectoryW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
GetTimeZoneInformation
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVCAtlException@ATL@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVCWin32Heap@ATL@@
.?AUIAtlMemMgr@ATL@@
.?AUIAtlStringMgr@ATL@@
.?AVCAtlStringMgr@ATL@@
.?AVerror_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@GDU_Mbstatet@@@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV_Locimp@locale@std@@
.?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AV?$ctype@_W@std@@
.?AV?$ctype@G@std@@
.?AUmessages_base@std@@
.?AUmoney_base@std@@
.?AUtime_base@std@@
.?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AV?$collate@_W@std@@
.?AV?$messages@_W@std@@
.?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$moneypunct@_W$0A@@std@@
.?AV?$_Mpunct@_W@std@@
.?AV?$moneypunct@_W$00@std@@
.?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$numpunct@G@std@@
.?AV?$collate@G@std@@
.?AV?$messages@G@std@@
.?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$moneypunct@G$0A@@std@@
.?AV?$_Mpunct@G@std@@
.?AV?$moneypunct@G$00@std@@
.?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$collate@D@std@@
.?AV?$messages@D@std@@
.?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$moneypunct@D$0A@@std@@
.?AV?$_Mpunct@D@std@@
.?AV?$moneypunct@D$00@std@@
.?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVtype_info@@
!This program cannot be run in DOS mode.
h.rdata
H.data
.pdata
b.reloc
H9D$8t2H
H9D$Ht/H
L$@H9HPu
D$@H9D$
D$ FileE3
H9D$@sM
D$HHc@<H
D$HHc@<H
9D$$s-
D$(H9D$@r%
H9D$@w
H9D$(tlH
@0H9D$HrH
A0H9D$Hs
D$0H9D$ t^H
@0H9D$8uBH
L$ H9A
D$XBSBS
L$PH9HPu
D$@H9D$
H9D$@sM
9D$Tst
8PAGEttH
L$(H;A
ffffff
fffffff
ffffff
ffffff
fffffff
ffffff
fffffff
BBLookupProcessThread
BlackBone: %s: Failed to allocate memory for process list
BlackBone: %s: Failed to locate process
LeiLeiGetKernelBase
LoadDriver: %s: Invalid SystemModuleInformation size
LeiLeiInitLdrData
LoadDriver: %s: Failed to retrieve Kernel base address. Aborting
LoadDriver: %s: Failed to retrieve PsLoadedModuleList address. Aborting
LeiLeiResolveImageRefs
LoadDriver: %s: Failed to load import '%wZ'. Status code: 0x%X
LoadDriver: %s: Failed to resolve import '%wZ' : '%s'
LoadDriver: %s: Failed to resolve import '%wZ' : '%d'
LeiLeiMapWorker
LoadDriver: %s: Failed to open %wZ. Status: 0x%X
LoadDriver: %s: Failed to get '%wZ' size. Status: 0x%X
LoadDriver: %s: Failed to obtaint NT Header for '%wZ'
LoadDriver: %s: Failed to read '%wZ'. Status: 0x%X
DYN_PTE_BASE-2222--%X
Lonad--Drvier win10
Lonad--Drvier win7
Lonad--Drvier 11111111
LoadDriver: %s: Failed to relocate image '%wZ'. Status: 0x%X
LoadDriver: %s: Failed to allocate memory for image '%wZ'
LoadDriver: %s: Successfully mapped '%wZ' at 0x%p
GetPML4
GetPPE
GetPDE
GetPTE
111111
2222222
NtCreateThreadEx
333333
444444
[2030]33---%d-%p-%p
[2030]Thread-%p
Context.Rip-%p
OKOKOKOK
C:\Users\Administrator\Desktop\
\x64\Release\Driver11111.pdb
.text$mn
.text$mn$00
.text$mn$21
.text$s
.text$x
.idata$5
.00cfg
.gfids
.rdata
.rdata$zzzdbg
.xdata
.pdata
.idata$2
.idata$3
.idata$4
.idata$6
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
L$ SVWH
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
t<ffff
WATAUAVAWH
A_A^A]A\_
fffffff
D8t$8t
D$@H;G
CA< t(<#t
<htl<jt\<lt4<tt$<wt
!,X< w
t$ WAVAWH
<Ct-<D
<StW@:
<g~{<itd<ntY<ot7<pt
<utT@:
D<P0@:
k4+kP+
0A_A^_
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
L$ VWAVH
u3HcH<H
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
WAVAWH
A_A^_
` UAVAWH
@A_A^]
WATAUAVAWH
A_A^A]A\_
L$ VWAVH
fD9t$b
8\$8t(H
@8l$Ht
L$ UVWH
WATAUAVAWH
gfffffffH
D8l$ht
A_A^A]A\_
<at <rt
u"8Z(t
uF8Z(t
vC8_(t
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
u"8Z(t
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
x AVAWE3
|$0A_A^
UVWATAUAVAWH
D8T8>t
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
ATAVAWH
0A_A^A\
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
SUVWATAVAWH
A_A^A\_^][
@USVWATAUAVAWH
D+d$8H
#D8d$`t
A_A^A]A\_^[]
D$0H9D$8
@UATAUAVAWH
e0A_A^A]A\]
s WAVAWH
0A_A^_
u~9t$Xt
UATAUAVAWH
A_A^A]A\]
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
0A_A^A]A\_^]
@SUVWATAUAVAWH
8A_A^A]A\_^][
x ATAVAWH
0A_A^A\
UVWATAUAVAWH
@8t$HtsL
`A_A^A]A\_^]
UVWAVAWH
@A_A^_^]
ffffff
fffffff
x ATAVAWH
A_A^A\
USVWAVH
A^_^[]
LcA<E3
u HcA<H
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
`h````
xpxxxx
(null)
CorExitProcess
AreFileApisANSI
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UTF-16LEUNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
xxxxxxxxxxxxxxxx
C:\Users\Administrator\Desktop\TLS
11-19\x64\Release\Dll.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.rsrc$01
.rsrc$02
AllocConsole
SetConsoleTitleW
AttachConsole
GetCurrentProcessId
CreateThread
KERNEL32.dll
MessageBoxW
USER32.dll
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
InterlockedFlushSList
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
LCMapStringW
GetStdHandle
GetFileType
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
SetStdHandle
GetFileSizeEx
SetFilePointerEx
GetStringTypeW
CloseHandle
CreateFileW
HeapSize
HeapReAlloc
ReadFile
ReadConsoleW
SetEndOfFile
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
wcsstr
DbgPrintEx
RtlGetVersion
KeDelayExecutionThread
ExAllocatePoolWithTag
ExFreePoolWithTag
PsWrapApcWow64Thread
ObfDereferenceObject
PsGetCurrentThreadId
PsGetProcessId
KeStackAttachProcess
KeUnstackDetachProcess
PsIsThreadTerminating
PsLookupProcessByProcessId
PsLookupThreadByThreadId
ZwQueryVirtualMemory
PsGetThreadTeb
PsGetProcessPeb
PsGetProcessWow64Process
ZwQuerySystemInformation
KeInitializeApc
KeInsertQueueApc
KeTestAlertThread
PsGetCurrentProcessWow64Process
__C_specific_handler
strcmp
RtlInitAnsiString
RtlAnsiStringToUnicodeString
RtlCompareUnicodeString
RtlFreeUnicodeString
ExAllocatePool
MmGetSystemRoutineAddress
MmMapLockedPagesSpecifyCache
MmAllocatePagesForMdl
MmFreePagesFromMdl
ObReferenceObjectByHandleWithTag
ObCloseHandle
ZwCreateFile
ZwQueryInformationFile
ZwReadFile
ZwClose
RtlCompareString
IoCreateFileEx
RtlRandomEx
MmFlushImageSection
ZwDeleteFile
RtlImageNtHeader
RtlImageDirectoryEntryToData
IoFileObjectType
RtlInitUnicodeString
MmBuildMdlForNonPagedPool
MmAllocateContiguousMemory
IoAllocateMdl
IoGetCurrentProcess
MmGetPhysicalAddress
MmIsAddressValid
RtlCaptureContext
ObOpenObjectByPointer
ZwAllocateVirtualMemory
ObReferenceObjectByName
MmCopyVirtualMemory
KeCapturePersistentThreadState
ZwSetSystemInformation
MmMarkPhysicalMemoryAsBad
MmUserProbeAddress
IoDriverObjectType
_stricmp
ZwOpenFile
ZwCreateSection
ZwMapViewOfSection
ZwUnmapViewOfSection
ntoskrnl.exe
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
121206000000Z
131206235959Z0
Guangdong1
Shenzhen1$0"
Blueone Technology Co., Ltd1>0<
5Digital ID Class 3 - Microsoft Software Validation v21$0"
Blueone Technology Co., Ltd0
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
https://www.verisign.com/rpa0
http://ocsp.verisign.com0;
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
v>;tE
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Code Verification Root0
110222192517Z
210222193517Z0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
,N<jPl
3BH8Q:|8
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
100208000000Z
200207235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0
[0Y0W0U
image/gif0!00
#http://logo.verisign.com/vslogo.gif04
#http://crl.verisign.com/pca3-g5.crl04
http://ocsp.verisign.com0
VeriSignMPKI-2-80
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></windowsSettings></application></assembly>
010A0Q0a0q0
1!111A1Q1]1g1s1
2-2A2E2O2]2g2q2}2
213M3l3|3
6&7/747T7&8886<F<
=5=<=B=G=U=
5585_5
8F:S:&;2;u;
;&=+=:=c=j=x=
>+>1>7>A>G>P>U>_>e>
11&171J1l1r1
1h2q2~2
3$3.383A3G3K3U3z3*4
5-525K5X5
6(6.6C6n6
8$8)848>8E8X8o8w8
;";1;6;?;
<?<Q<a<q<
%1/141T1
9$:6:E:m:
; ;*;/;
<,<9<N<l<
="='=1=A=M=Y=t=
>d?j?p?w?}?
2#2.242;2R2X2_2v2|2
3#3,31373M3R3X3`3|3
4$4)444:4E4w4|4
4&585P5a5f5k5p5
7&7,747B7G7]7
8(8n8v8
9*9/949Y9d9j9q9w9
:;1;m;
;A<N<Y<`<
=1=A=J=R=w=
>&>8>O>`>e>j>p>
0#0)0/060;0A0J0Q0m0v0
1"1/151=1C1I1N1T1_1m1
33&3+313:3@3
414H4M4i4
5+5F5_5e5
6#6B6X6
7.7A7p7
8-848<8R8n8
:3:>:h<t=
5 5t5~5
606E6J6
637=7Z7
9;:E:;
5=6B6M6
5&5L5g5
6h7v7~8
:@:n;2<
<K=e=x=
?&?^?j?
0Q0^0w0
;3;H;x;
??%?*?3?C?X?f?t?
2(2=2B2
2+353R3g3l3
4U4_4|4
6;6P6U6
6>7H7e7z7
9$999>9
9':1:N:c:h:
:Q;[;x;
<"<'<{<
=7=L=Q=
=:>D>a>v>{>
1 1,1;1U1d1~1
183G3f3u3
3?4N4m4|4
172E2h2
2@3N3q3
9f9k9v9
0_0d0o0
6&7+767
;<Z<a<l<5>
3#4H4}4
4 5.5H5{5
:Q:_:y:
;`<+=&>N?
5x6 7;7E7P7
;;<@<H<
9d:W;n;
<&=6=M>c>
7I8S8p8
99s9}9
:/:D:I:
:2;<;Y;n;s;
;0J0m0
6[7v92:
1&242N2
>W?r?|?
6%7*727
878H8u8
0/0U0[0
7M8W8]8j8
979=9C9I9O9e9
:$:*:4:C:K:W:h:o:
;$;*;1;D;^;|;
>0>6><>B>H>N>T>i>~>
4O5a5~5
787A7J7X7a7
8"8)80878?8G8O8[8d8i8o8y8
9!9(9/969=9E9M9U9`9e9k9u9
9+:4:A:G:n:
:,;A;P;
j<n<r<v<z<~<
>(>.>?>P>Z>h>
9<:@<E<s<
<=3=D=P=_=w=
>(>1>6>;>V>`>l>q>v>
? ?8?{?
1N1q1x1
1!242@2
3 3,313E3
4%494A4K4T4e4w4
0#080N0[0i0w0
2K3T8u9
6/63676;6?6
0+151k1
:B:I:T:b:i:o:
<9<N<j<=&>
$1.181$2i2.3l4
=(>W?[?_?c?g?k?o?s?w?{?
1i6j8r8
M1Q4Y4
2p2u2|2
; =$=(=,=0=4=8=<=|>
3,3Q3o3
6?6J6<8F8_8i8
</=:=y=
=@>D>L>X>r>
?#?<?A?Z?k?p?~?
1X1q1v1
<%=j=z=O?
848I8[8h8
9:9A9b9
:&:k:q:
=!='=.=3=g=o=
>+>0>5>E>J>O>_>d>i>y>~>
171A1Q1V1[1v1
3(3-323S3c3
585?5V5l5y5~5
7U8i8s8
`0"3a3h3s3~3
:@<L>r?
>B?T?f?
0#1+1\1e1p1
232<2E2
5/5_5g5
6!6,6o6
=G=d=x=
F0f0v0+1,2<2M2U2e2v2
5/6D6U6
:P:q:|:
;J;i;{;
<"=H=q=
0+1e2o2
4;4]4!5b6
223I3r3
5I6S6}6
8Z9c9{9
9b9i9p9w9
7(707Y7`7|7
9*9<9N9`9r9
<L=^=p=
7A7X7x7
91:P:2;d=
3a7h7o7
0O0^0j0y0
0:1C1L1U1
4%4.4T4
5)5A5G5S5r5x5
9 :J:R:o:
;F<K<]<{<
>?>\>y>
?$?/?B?F?L?b?l?
0"0,0W0a0k0
1!1+1B1r1|1
222<2g2q2{2
2'313;3R3\3
4G4Q4[4r4|4
5'515;5E5O5Y5c5m5w5
d2l2p2t2x2|2
3(3,303@3D3H3L3P3T3\3`3d3h3l3p3t3x3|3
4D4H4L4\4`4d4h4
4l;p;t;x;|;
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :$:(:,:0:4:8:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
:P>T>X>\>`>d>h>l>p>t>x>|>
6$6,646<6D6L6T6\6j8n8r8v8
9 9X9d9p9|9
:$:0:<:H:T:`:l:x:
; ;,;8;D;P;\;h;t;
<(<4<@<L<X<h<t<
=(=4=@=L=X=d=p=
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
0888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?
;$;(;8;<;@;H;`;d;|;
<$<(<8<<<D<\<l<p<
= =$=,=D=T=X=`=x=
>,>0>@>D>H>P>h>x>|>
?(?,?0?4?<?T?d?h?p?
0 0004080<0@0H0`0p0t0
1 1$14181<1D1\1l1p1
2 2$2(2,20282P2`2d2t2x2|2
3 3$3(3,343L3\3`3p3t3x3|3
4 4(4@4P4T4d4h4l4p4x4
5,5<5@5P5T5X5\5`5h5
6$64686H6L6P6T6X6\6d6|6
7$7(7,70747<7T7d7h7l7p7t7|7
8$8<8L8P8`8d8h8l8p8x8
9$9<9L9P9`9d9h9l9p9x9
: :(:@:D:\:l:p:t:x:|:
; ;8;H;L;\;`;d;h;l;t;
< <$<(<0<H<X<\<l<p<t<x<|<
= =$=(=0=H=X=\=l=p=t=x=|=
> >$>(>,>4>L>P>h>x>|>
? ?$?,?D?T?X?h?l?p?t?x?
0$0(0,0004080@0X0h0l0|0
1$1(1,1014181<1D1\1`1x1
2 2$2(2,20242<2T2d2h2x2|2
3(3,30383P3
:<:\:d:l:t:|:
; ;@;L;l;t;|;
<(<0<8<D<d<l<t<|<
=4=X=d=l=
>8>L>X>`>x>
?$?0?P?\?|?
0 0(0<0D0L0T0X0`0t0|0
1$1,141<1@1D1L1`1h1p1x1|1
2,2L2X2|2
3<3D3L3T3\3d3l3x3
4(4H4P4X4`4h4t4
5,545@5`5h5p5x5
6,686X6`6h6t6
848@8`8l8
9 9(90989@9H9T9x9
:(:H:P:X:`:l:
;8;@;L;l;x;
< <(<0<8<@<H<P<X<`<h<p<|<
=$=,=4=@=`=h=p=x=
>8>D>d>p>
? ?,?L?T?\?d?p?
0,040<0D0L0T0\0d0l0t0|0
181@1H1P1X1`1h1p1x1
2@2H2h2x2
3(30383@3H3P3X3`3h3p3x3
444<4D4L4T4\4d4l4t4
5$5(5D5H5d5h5
6$6L6P6l6p6x6
7(7H7h7
8(8H8h8
9(9H9h9
:(:H:P:\:
;0;P;p;
<0<P<l<p<
3H3X3h3x3
;4;P;p;
<0<P<p<
>0>L>p>
2 2@2`2
System\CurrentControlSet\Services\EvilDriver
ImagePath
\Registry\Machine\System\CurrentControlSet\Services\EvilDriver
x86.dll
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
:AM:am:PM:pm
ERROR : Unable to initialize critical section in CAtlBaseModule
api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
Dapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
(null)
((((( H
((((( H
(
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
CLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Dapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
Dja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
NtOpenFile
\Driver\ACPI
\SystemRoot\SysWOW64\ntdll.dll
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
(null)
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
111111
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.hh
McAfee Artemis!5FD66BA54FDD
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Trojan:Win32/MalwareX.0144f00b
K7GW Clean
Cybereason malicious.54fdd5
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Clean
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Trojan.Heur.RP.GuW@b44bHIcj
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Trojan.Heur.RP.GuW@b44bHIcj
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.XPACK.Gen7
DrWeb Clean
VIPRE Gen:Trojan.Heur.RP.GuW@b44bHIcj
TrendMicro TROJ_GEN.R002C0XFE24
McAfeeD Real Protect-LS!5FD66BA54FDD
Trapmine Clean
FireEye Generic.mg.5fd66ba54fdd5400
Emsisoft Gen:Trojan.Heur.RP.GuW@b44bHIcj (B)
SentinelOne Static AI - Malicious PE
GData Gen:Trojan.Heur.RP.GuW@b44bHIcj
Jiangmin TrojanSpy.Stealer.cga
Webroot Clean
Varist W32/ABRisk.HCTI-6432
Avira TR/Crypt.XPACK.Gen7
Antiy-AVL Trojan/Win32.Sabsik
Kingsoft malware.kb.a.716
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Heur.RP.E3A58E
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5641369
Acronis Clean
BitDefenderTheta AI:Packer.944428AF1F
MAX malware (ai score=86)
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes Malware.AI.2420482668
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XFE24
Rising Trojan.Generic@AI.87 (RDMK:cmRtazoZDhJ39uPQZ/D2osunxCE5)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.218110627.susgen
Fortinet W32/PossibleThreat
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
alibabacloud Suspicious
No IRMA results available.