Static | ZeroBOX

PE Compile Time

2023-07-07 17:46:22

PE Imphash

49403c7fa5940d83b3c1972c644d5f4b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001bcc40 0x001bce00 6.19275111245
.rdata 0x001be000 0x0000a6de 0x0000a800 4.8152897225
.data 0x001c9000 0x000053c8 0x00001200 3.72433672617
.pdata 0x001cf000 0x00001008 0x00001200 4.91150211303
.rsrc 0x001d1000 0x00000650 0x00000800 3.39499779329
.reloc 0x001d2000 0x00000668 0x00000800 4.89714145736

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x001d10a0 0x00000430 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x001d14d0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x1401be070 GetProcessHeap
0x1401be078 LCMapStringW
0x1401be080 FlsFree
0x1401be088 FlsSetValue
0x1401be090 FlsGetValue
0x1401be098 FlsAlloc
0x1401be0a0 GetStringTypeW
0x1401be0a8 GetFileType
0x1401be0b0 SetStdHandle
0x1401be0b8 FreeEnvironmentStringsW
0x1401be0c0 GetEnvironmentStringsW
0x1401be0c8 WideCharToMultiByte
0x1401be0d0 MultiByteToWideChar
0x1401be0d8 GetCommandLineW
0x1401be0e0 GetCommandLineA
0x1401be0e8 GetCPInfo
0x1401be0f0 GetOEMCP
0x1401be0f8 GetACP
0x1401be100 IsValidCodePage
0x1401be108 FindNextFileW
0x1401be110 FindFirstFileExW
0x1401be118 FindClose
0x1401be120 HeapFree
0x1401be128 HeapAlloc
0x1401be130 GetModuleHandleExW
0x1401be138 TerminateProcess
0x1401be140 HeapSize
0x1401be148 GetCurrentProcess
0x1401be150 GetModuleFileNameW
0x1401be158 WriteFile
0x1401be160 GetStdHandle
0x1401be168 RtlPcToFileHeader
0x1401be170 RaiseException
0x1401be178 EncodePointer
0x1401be180 LoadLibraryExW
0x1401be188 GetProcAddress
0x1401be190 FreeLibrary
0x1401be198 TlsFree
0x1401be1a0 TlsSetValue
0x1401be1a8 TlsGetValue
0x1401be1b0 TlsAlloc
0x1401be1c0 DeleteCriticalSection
0x1401be1c8 LeaveCriticalSection
0x1401be1d0 EnterCriticalSection
0x1401be1d8 SetLastError
0x1401be1e0 GetLastError
0x1401be1e8 RtlUnwindEx
0x1401be1f0 GetModuleHandleW
0x1401be200 GetStartupInfoW
0x1401be210 UnhandledExceptionFilter
0x1401be218 IsDebuggerPresent
0x1401be220 RtlVirtualUnwind
0x1401be228 RtlLookupFunctionEntry
0x1401be230 RtlCaptureContext
0x1401be238 InitializeSListHead
0x1401be240 GetSystemTimeAsFileTime
0x1401be248 GetCurrentThreadId
0x1401be250 GetCurrentProcessId
0x1401be258 QueryPerformanceCounter
0x1401be260 HeapReAlloc
0x1401be268 FlushFileBuffers
0x1401be270 GetConsoleOutputCP
0x1401be278 GetConsoleMode
0x1401be280 SetFilePointerEx
0x1401be288 CreateFileW
0x1401be290 CloseHandle
0x1401be298 WriteConsoleW
0x1401be2a0 ExitProcess
0x1401be2a8 GetModuleHandleA
Library USER32.dll:
0x1401be408 UpdateLayeredWindow
0x1401be410 AnimateWindow
0x1401be418 ShowWindow
0x1401be420 GetClassInfoExA
0x1401be428 CallWindowProcA
0x1401be430 DefWindowProcA
0x1401be438 DrawCaption
0x1401be440 GetMouseMovePointsEx
0x1401be448 ToUnicodeEx
0x1401be458 ShowWindowAsync
0x1401be460 GetWindowPlacement
0x1401be468 DeferWindowPos
0x1401be478 GetClipboardViewer
0x1401be480 EmptyClipboard
0x1401be498 GetOpenClipboardWindow
0x1401be4a0 CharToOemBuffA
0x1401be4a8 CharNextExA
0x1401be4b0 CharPrevExA
0x1401be4b8 IsCharAlphaNumericA
0x1401be4c0 GetAltTabInfoA
0x1401be4c8 RealGetWindowClassA
0x1401be4d0 GetComboBoxInfo
0x1401be4d8 GetWindowModuleFileNameA
0x1401be4e0 ChangeDisplaySettingsExA
0x1401be4e8 TileWindows
0x1401be4f0 DlgDirSelectExA
0x1401be4f8 GetIconInfo
0x1401be500 DrawIconEx
0x1401be508 CheckMenuRadioItem
0x1401be510 IsGUIThread
0x1401be518 GetParent
0x1401be520 GetClassLongA
0x1401be528 SetClassWord
0x1401be530 SetWindowLongA
0x1401be538 PtInRect
0x1401be540 SubtractRect
0x1401be548 SetRect
0x1401be550 SetSysColors
0x1401be558 MapWindowPoints
0x1401be560 ScreenToClient
0x1401be568 SetCaretBlinkTime
0x1401be570 SetCursorPos
0x1401be578 MessageBoxIndirectA
0x1401be580 AdjustWindowRect
0x1401be588 EnumPropsExA
0x1401be590 ShowScrollBar
0x1401be598 ScrollWindow
0x1401be5a0 LockWindowUpdate
0x1401be5a8 ValidateRgn
0x1401be5b0 InvalidateRgn
0x1401be5b8 GetWindowRgnBox
0x1401be5c0 GetWindowDC
0x1401be5c8 GetDC
0x1401be5d0 WindowFromDC
0x1401be5d8 PaintDesktop
0x1401be5e0 MenuItemFromPoint
0x1401be5e8 SetMenuDefaultItem
0x1401be5f0 SetMenuItemInfoA
0x1401be5f8 TrackPopupMenu
0x1401be600 ModifyMenuA
0x1401be608 GetMenuItemID
0x1401be610 GetSubMenu
0x1401be618 GetMenuStringA
0x1401be620 IsWindowEnabled
0x1401be628 EnableWindow
0x1401be630 IsWindowUnicode
0x1401be638 GetCapture
0x1401be640 VkKeyScanA
0x1401be648 ToAscii
0x1401be650 GetKeyboardState
0x1401be658 GetKeyState
0x1401be660 GetActiveWindow
Library WINSPOOL.DRV:
0x1401be670 ResetPrinterA
0x1401be678 SetJobA
0x1401be680 EnumJobsA
0x1401be688 SetPrinterA
0x1401be690 GetPrinterA
0x1401be698 WritePrinter
0x1401be6a0 FlushPrinter
0x1401be6a8 AbortPrinter
0x1401be6b0 ReadPrinter
0x1401be6b8 GetPrinterDataA
0x1401be6c0 ConnectToPrinterDlg
0x1401be6c8 ConfigurePortA
0x1401be6d0 GetPrinterDataExA
0x1401be6d8 EnumPrinterDataA
0x1401be6e0 EnumPrinterDataExA
0x1401be6e8 EnumPrinterKeyA
0x1401be6f0 SetPrinterDataA
0x1401be708 GetFormA
0x1401be710 SetPortA
Library COMDLG32.dll:
0x1401be010 ChooseColorA
0x1401be018 FindTextA
0x1401be020 ReplaceTextA
0x1401be028 GetOpenFileNameA
0x1401be030 PrintDlgA
0x1401be038 PrintDlgExA
0x1401be040 CommDlgExtendedError
0x1401be048 PageSetupDlgA
0x1401be050 ChooseFontA
0x1401be058 GetFileTitleA
0x1401be060 GetSaveFileNameA
Library ADVAPI32.dll:
0x1401be000 DecryptFileA
Library SHELL32.dll:
0x1401be2b8 ShellExecuteExA
0x1401be2c0 None
0x1401be2c8 SHPathPrepareForWriteA
0x1401be2d0 SHBindToParent
0x1401be2d8 None
0x1401be2e0 None
0x1401be2e8 SHGetDataFromIDListA
0x1401be2f0 SHGetInstanceExplorer
0x1401be2f8 None
0x1401be300 None
0x1401be308 DragQueryFileA
0x1401be310 DragQueryPoint
0x1401be318 DragFinish
0x1401be320 DragAcceptFiles
0x1401be328 ShellExecuteA
0x1401be330 ShellAboutA
0x1401be338 DuplicateIcon
0x1401be340 ExtractIconExA
0x1401be348 SHFileOperationA
0x1401be350 None
0x1401be358 SHGetFileInfoA
0x1401be360 SHGetDiskFreeSpaceExA
0x1401be368 None
0x1401be370 SHSetLocalizedName
0x1401be378 None
0x1401be380 SHGetIconOverlayIndexA
0x1401be388 None
0x1401be390 None
0x1401be398 None
0x1401be3a0 None
0x1401be3a8 None
0x1401be3b0 None
0x1401be3b8 None
0x1401be3c0 None
0x1401be3c8 None
0x1401be3d0 None
0x1401be3d8 SHBrowseForFolderA
0x1401be3e0 SHGetDesktopFolder
0x1401be3e8 SHChangeNotify
0x1401be3f0 None
0x1401be3f8 None
Library dxgi.dll:
0x1401be720 CreateDXGIFactory

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
D$$bS6
D$8HcD$ H
s;HcD$ H
+D$$HcL$ H
D$@Hc@<H
4gW%6
s-P89@
Hn9)`-
t$s`c(uscX
xxS9iD
wTNASt
\!}Lm[
`9NKc[
{"[1i7^[
/.YV!6
_~%Hsc
;>)U`VA
k/dt&`
BtiSpS
8V{yCpa0
@wwcH!]L
v,=(A*
'I7J]
9D$o*d
W'bI!B
GPvV6{
>.634K
ftH?tB
A#R&lNw
lxC/?`
J]nXrE
*]2y<a(
VU,U;^
sUN+{2U
!Cc7Z
dgw?^6s
iFTNc=;s
5"%uUz
FHt~`u
IHWy>LV
M^\*it
FdoMHV
gqBJ|u
>g}Q/?
<AWbJ
|ZM/ag
4D+){8
I+ &^;r
G`s9`e
:inbYv
=K}Z)_1
rE72?:
6*LQA8
d;Z*VA
GwC%2[
-/|hW)
q-WOUYDq9
#K|y A
#(##IL
hXQ)R
YE\{a~
(0R@v%
:T7R`>
hj&cnP
o;/@L`
.Z qpx[
a\|fi
PAAL(#
zHr^~)'F
:vS:C
z{Zeb~
qC~[(2#
XY1o=!
9SNa3<
.RXc}A
"*6R.G
V(Q/tz
XYu7M]V
@H\lI=
2IL[t&i
>qm5{&;
o1Uo2I
l,{Bsne,
uXwizf9N=D
UIFQ'L
P9zW$m5
K40v9Gd
_r]b/'
O%nz:%
AE'2P9
byaRT`
|/LZ4*
~8;@1I
xcY.3+
s!=,zS
lw'"f7
O3|4?$
X]wN8+
n=@f.q
#4`U~1Lh
`I)j*O
.Pyp8r
0wOOCk
Gbi9j}
!dNTef
I\IZ`!`L
ZppzZj
zCBjZ-7
>',>%+
*+F^Ipwe
,/XI~
0UTT&*
ln97-YE{@L6y
t*Ya'(.
Z2SgCn
6`lm6,
ssRe.Q
!RvrKz
V:mS~t
UxWzh*
3@nuI:u%xJ?
R`_f9G
l"Q ]P
r,P(8jC
\S3U;KH
9O(Xe7c0i&
1{_@J;
Z`32T2
"c>F&NY
ML9N^`
7yT^H4
UON5<4
]@=@eU
eXOVzM
(J(@'\<
=)>g1+
:-g=(H
gmMKgH9
jW'Nn7H
b"."th
|$x8Jp
oH9D$H
|$tD-(
OFo-XxvH
D$DrqT
D$D5-G
CH9D$8t
H9D$0|0H
y\L?Dt
)Nr M!\
2e=H\O
"U_C9-
w?/RDD
#}YUWS)
y;vS=I
P4^zMP
tA+tl"h
,J,e3_
%g;|v#@@
,_?&{M
{pubq5
%y?>M136
-:&)B.0
)VZ:saD
9>4.6i
'?*{u
Vi^)X8
RT.$u'
z'?_/L
=57VU/
gDY/(.
zlmZcs8
fJC9^!
2i4G?Y
?v- R
y^}9TAu;
'Z@jcxx
YbNz.^
=u.ANW
)s^ g
'N6XhqLz
0#d^##Q
?W.m/T
D(O=w[
4q</Bb
DKq=jC
#<5[_NA
ec&8/F
OsxZ}Fi
'@AjUhO
}s1M6C
2DHkQa
;m_Fxe
"\B/dj
|NO;rfh
C~Z\,k
%7?8U$
us+Z'K
Meh^-]
<@^";
X=|C|~
EEd'ra
g?b\{y
Oy6x"\
wQVa[c
*?$gCO
lBWku%kG
kNvNw\
c7[Dog`
_T2_1>
9~5c<V
q~t+~Dp
z8 tFsI
Da`QJl
%^t0p,
4uEk8a
*)1Z{O_`
sW[zU]
W)O{8y'
Z:m+Lz#
+,7$'~i
NcNCt!
OR7km
4/I BC
a[>yK9
jC~k9j
%LnG7}8
hVPgO
vxz:F3
Qbs{DWl
MO:9L{
{#Q{,i
Uv>g@x
11l0\|Z
%N2&Lu
FTE ?.
IED`U2
6)t$r[
L=H8;z
08,QR0
8wGW@M
ED=EZ8e
l)bWQ!
bvUl7V
"#(0wpJC
#Qn#]f
k,~Su7.
Sm|gm}
S[r*|R
^#xe`5
]wbKDiD>
h3'4Br
Uj=;68re
|m0Q)]
uQH`zW
}(uOy8
R6[4pa
9UHnKu
z N/c[
B1;Eb8n!QWF
]FXwQy
)74|_!
8hq$:Y:
WI&dU'
E\c Mg
xS--[O
,{/YT(
k"N^86mP\
[lgF~9V-
c$`_>L
sN\.L)4
@sA&[.
:4c+*Z
jpDjON
)L.3."
11vF-c
CaYzO|A
xv[s*
'jz*'&
Mu>/mn
JxF;05
W`hMS{R
g$Q"rz
="")<)
(66;UJS;
y+a9U$
`t>r~8?
tq}C[X
5L~$K=
U .hR/
iD$]f7
;!JbX2
~2@BR^%
Kl'>^R
^u<%=^
}q1X5G
}(gWr0
]Vb_T6wGE
GnBjGD
Za:(u$5
91XU]C
WWmWb1
H<.I-\
NQ-@sW
w _O)W\f 6
`sEO{i
$g>\gcU
2e}4^gh
s%f+E2
9l{]uR
h.9`eD)
KEwY}3
iP4%ns`r
;P+w;|;
+IwH7MIQ
I_jZ>l
Bk;V"e
&zS&5~
}U)n:'~U
C5Ra.5*
,b<%8v
~eTzkt?
l p#)Rs
|(wDI+6
(&$Ori
GhlfuN u7
xWyqMX
o|o+5P
GT'?H$
ByucC`
W0:f*$
x&MW}u
D6(sde
NFt"~w
N!>*h;
e(."<?
u{X2MP
z :HmRr-
n;`jn
=s"G"B
]u;tU:
ccFEFf=
\uC/Z4
5cS+P{N
,Oo'XcwDYB
Yf+9yP
CEwFf|
IW_LnN
0>q-Zd
yXV:~8
!+=eUU
LOBMl^
Hd*Nbx
A@jM~*
9-M'MB_
Dose^;
Y[-S0t
FbMEq?
tS{32w
@6]C?<-
NFJ{GE
#>$h=1
V`wSBi
lk>mWY)
kxT#o$
Q-Z}{"
;O6yHA
+f3j*7
5B.X |
/V!w\ZB
F/8.Okji
g]+\~N
)=p#m{Y
k03"i|m
;FSZ'h
BaUv)y
2AMm=o
y/F|b1
*j_vJG
,/S3(I
W<fD%n
F}&#h7
(rwV2m
R%"d-n>#
JC`P7F
YHSl,!m
dbF]fbw
s$%efl
;M7 w
dUC]Km!
{hJ}f$
~d:*9`
gUb9cY
/'z1-]
~@Z5Lc
@hvKo7
;/I&O]{
e3|oNZ-
hH"B,
_>9(cf
"2^=!-z
}s$YU/
`q;zf
*_tg!S
)#D4thGR
AMK1R%u9
r%}X:
)$n!a6RI8Nw
2uYADfg
b&7joC
falAM?+c`
79Tqo-b
sPb(I|"
c_"?w)
)]yA<G1
t'VVAU
]{G*$K
d +%q!ej
[OU#;AQ^(
E@qK`-`
g-Y~_K
#JC(-7
MV5+*
| {w.#
M6M14/v
'J$\"<
89X9w*
u6|@}y
raB<n-
||"EPHj<
,0<6 t8
[Xu7#i
Oundpa
"*-7ycM
/?&teH46
+jT{d?=
*EEwS}"
VCh[VY
+&T3&.79
v4J]Ik=
w+W@x?iZ
cN)^3@
F%idzh
{A1gK)
\w->;m
*6I*i<z
)e[sok
,5Z<wh
8-L9D/09
-6BCS F>h
S9dc_Q
=v3{0k\
#*NUe1
Pdw,G\
1<zs,P,?Iw
laa@CQf
=96D>0M
PHGqy[
;,<0^'
%>j9XQK
.QuKSbS
?zni%:;
/bP6;O74
_Y* I~#
k-v>V4
b|&=?^
k>a;Hv
{9>Z_6z5w$
Z^:]#i
z#-"POB
@!e}yy
pjw(jH{h
;zhw(!
m;Ih{
O's.UD0_
A+;# +
\H.p"KZh
/f&+qV
Z5gW/d
}EFK#1
}<9TM!
jNRAdL
?TlpdMR5x
S,rp1k
j[%>Vj
L,F#"f
:rB+Gg
DP$#&
&'Qx"b
-z_+ k<
O/Y4_n
J)+3ZPUN#
JpbI\a>
<D5|$r
{cGtQF
N"0fnS
/(?p{n
$Aa_HtW
NKt=P3%w@
i<mw/4
HpXa HS7
V4)kFh
((ZJC
Y0 XMf
2):s?7ohP
}fz\;*
[`\,AK_
t=( SS
ZH/cFA
CHsN"e
|B5sYd
&d=3x>Q@
u/HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
p0R^G'
u3HcH<H
WAVAWH
A_A^_
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
p0R^G'
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
USVWAVH
A^_^[]
LcA<E3
fffffff
ffffff
vKfffff
fffffff
fffffff
Vengeful weathers hymn Dethrone
steal derates Scored
Aunties uncovering considerately
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
GetModuleHandleA
KERNEL32.dll
ToUnicodeEx
GetMouseMovePointsEx
DrawCaption
DefWindowProcA
CallWindowProcA
GetClassInfoExA
ShowWindow
AnimateWindow
UpdateLayeredWindow
SetLayeredWindowAttributes
ShowWindowAsync
GetWindowPlacement
DeferWindowPos
GetClipboardSequenceNumber
GetClipboardViewer
EmptyClipboard
IsClipboardFormatAvailable
GetPriorityClipboardFormat
GetOpenClipboardWindow
CharToOemBuffA
CharNextExA
CharPrevExA
IsCharAlphaNumericA
GetActiveWindow
GetKeyState
GetKeyboardState
ToAscii
VkKeyScanA
GetCapture
IsWindowUnicode
EnableWindow
IsWindowEnabled
GetMenuStringA
GetSubMenu
GetMenuItemID
ModifyMenuA
TrackPopupMenu
SetMenuItemInfoA
SetMenuDefaultItem
MenuItemFromPoint
PaintDesktop
WindowFromDC
GetWindowDC
GetWindowRgnBox
InvalidateRgn
ValidateRgn
LockWindowUpdate
ScrollWindow
ShowScrollBar
EnumPropsExA
AdjustWindowRect
MessageBoxIndirectA
SetCursorPos
SetCaretBlinkTime
ScreenToClient
MapWindowPoints
SetSysColors
SetRect
SubtractRect
PtInRect
SetWindowLongA
SetClassWord
GetClassLongA
GetParent
IsGUIThread
CheckMenuRadioItem
DrawIconEx
GetIconInfo
DlgDirSelectExA
TileWindows
ChangeDisplaySettingsExA
GetWindowModuleFileNameA
GetComboBoxInfo
RealGetWindowClassA
GetAltTabInfoA
USER32.dll
ResetPrinterA
SetJobA
EnumJobsA
SetPrinterA
GetPrinterA
WritePrinter
FlushPrinter
AbortPrinter
ReadPrinter
GetPrinterDataA
GetPrinterDataExA
EnumPrinterDataA
EnumPrinterDataExA
EnumPrinterKeyA
SetPrinterDataA
FindNextPrinterChangeNotification
FindClosePrinterChangeNotification
GetFormA
ConfigurePortA
SetPortA
ConnectToPrinterDlg
WINSPOOL.DRV
GetOpenFileNameA
GetSaveFileNameA
GetFileTitleA
ChooseColorA
FindTextA
ReplaceTextA
ChooseFontA
PrintDlgA
PrintDlgExA
CommDlgExtendedError
PageSetupDlgA
COMDLG32.dll
DecryptFileA
ADVAPI32.dll
DragQueryFileA
DragQueryPoint
DragFinish
DragAcceptFiles
ShellExecuteA
ShellAboutA
DuplicateIcon
ExtractIconExA
SHFileOperationA
ShellExecuteExA
SHGetFileInfoA
SHGetDiskFreeSpaceExA
SHSetLocalizedName
SHGetIconOverlayIndexA
SHBrowseForFolderA
SHGetDesktopFolder
SHChangeNotify
SHGetInstanceExplorer
SHGetDataFromIDListA
SHBindToParent
SHPathPrepareForWriteA
SHELL32.dll
CreateDXGIFactory
dxgi.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
?qLt;B
fSUv1_
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040B04E3
Comments
Swindles reinstalling motel monumentally
CompanyName
Magnesium
FileDescription
Investment hook tensing egalitarians
FileVersion
7.69.188.8
InternalName
Grandparents bind
LegalCopyright
Copyright
Battening cram indulgent
LegalTrademarks
Renders hovercraft traces tussocks locus halters
OriginalFilename
Syphilitic
ProductName
Colonel evolutionists
ProductVersion
7.69.188.8
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
Cynet Clean
CMC Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Paloalto generic.ml
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Generic.mg.54d967f9eb61177b
Emsisoft Clean
huorong Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.708
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Win64.Agent
MaxSecure Clean
Fortinet Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (D)
alibabacloud Clean
No IRMA results available.