Static | ZeroBOX

PE Compile Time

2023-04-06 03:38:57

PE Imphash

6897e09add1836442c84d70f65d04a85

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0023ccd0 0x0023ce00 6.03887385167
.rdata 0x0023e000 0x0000b3c4 0x0000b400 4.82671125428
.data 0x0024a000 0x00006d48 0x00001400 4.2794222235
.pdata 0x00251000 0x00000f48 0x00001000 5.12881320978
.rsrc 0x00252000 0x00000640 0x00000800 3.38473156346
.reloc 0x00253000 0x00000674 0x00000800 4.88179152169

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x002520a0 0x0000041c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x002524c0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x14023e208 SetConsoleCursorInfo
0x14023e210 GetConsoleCursorInfo
0x14023e218 SetConsoleOutputCP
0x14023e220 SetConsoleCtrlHandler
0x14023e228 GetConsoleOutputCP
0x14023e230 GetUserDefaultLCID
0x14023e238 GetSystemDefaultLCID
0x14023e240 GetCurrencyFormatW
0x14023e248 SetLocaleInfoW
0x14023e250 GetCPInfoExW
0x14023e258 IsValidCodePage
0x14023e260 CompareStringW
0x14023e268 GetTimeFormatW
0x14023e270 GetDateFormatW
0x14023e278 GetNumaProcessorNode
0x14023e280 SetVolumeMountPointW
0x14023e290 CopyFileExW
0x14023e298 CopyFileW
0x14023e2a0 BackupSeek
0x14023e2a8 BackupRead
0x14023e2b0 lstrcatW
0x14023e2b8 lstrcmpW
0x14023e2c0 GetTapeParameters
0x14023e2c8 GetTapeStatus
0x14023e2d0 PrepareTape
0x14023e2d8 GetTapePosition
0x14023e2e0 SetTapePosition
0x14023e2e8 ConvertFiberToThread
0x14023e2f0 GetProcessIoCounters
0x14023e2f8 GetCurrentProcess
0x14023e300 SetProcessAffinityMask
0x14023e308 GetNumaHighestNodeNumber
0x14023e318 AssignProcessToJobObject
0x14023e328 GetProcessPriorityBoost
0x14023e330 SetPriorityClass
0x14023e338 TlsSetValue
0x14023e340 TlsGetValue
0x14023e348 GetThreadPriorityBoost
0x14023e350 GetCurrentThreadId
0x14023e358 WriteConsoleW
0x14023e360 CloseHandle
0x14023e368 CreateFileW
0x14023e370 GetConsoleMode
0x14023e378 FlushFileBuffers
0x14023e380 HeapReAlloc
0x14023e388 HeapSize
0x14023e390 GetProcessHeap
0x14023e398 LCMapStringW
0x14023e3a0 FlsFree
0x14023e3a8 FlsSetValue
0x14023e3b0 FlsGetValue
0x14023e3b8 FlsAlloc
0x14023e3c0 SetFileApisToANSI
0x14023e3c8 AreFileApisANSI
0x14023e3d0 UnlockFileEx
0x14023e3d8 SetFilePointerEx
0x14023e3e0 SetEndOfFile
0x14023e3e8 QueryDosDeviceW
0x14023e3f0 LockFileEx
0x14023e3f8 GetLongPathNameW
0x14023e400 GetFileSizeEx
0x14023e408 GetModuleHandleA
0x14023e410 GetExitCodeProcess
0x14023e418 GetStringTypeW
0x14023e420 GetFileType
0x14023e428 FreeEnvironmentStringsW
0x14023e430 GetEnvironmentStringsW
0x14023e438 WideCharToMultiByte
0x14023e440 MultiByteToWideChar
0x14023e448 GetCommandLineW
0x14023e450 GetCommandLineA
0x14023e458 GetCPInfo
0x14023e460 GetOEMCP
0x14023e468 GetACP
0x14023e470 FindNextFileW
0x14023e478 FindFirstFileExW
0x14023e480 HeapFree
0x14023e488 HeapAlloc
0x14023e490 GetModuleHandleExW
0x14023e498 TerminateProcess
0x14023e4a0 ExitProcess
0x14023e4a8 GetModuleFileNameW
0x14023e4b0 WriteFile
0x14023e4b8 GetStdHandle
0x14023e4c0 RtlPcToFileHeader
0x14023e4c8 RaiseException
0x14023e4d0 EncodePointer
0x14023e4d8 LoadLibraryExW
0x14023e4e0 GetProcAddress
0x14023e4e8 FreeLibrary
0x14023e4f0 TlsFree
0x14023e4f8 TlsAlloc
0x14023e508 DeleteCriticalSection
0x14023e510 LeaveCriticalSection
0x14023e518 EnterCriticalSection
0x14023e520 SetLastError
0x14023e528 GetLastError
0x14023e530 RtlUnwindEx
0x14023e538 GetModuleHandleW
0x14023e548 GetStartupInfoW
0x14023e558 UnhandledExceptionFilter
0x14023e560 IsDebuggerPresent
0x14023e570 GetFileAttributesExW
0x14023e578 FindClose
0x14023e580 DefineDosDeviceW
0x14023e588 GetCurrentDirectoryW
0x14023e590 SetStdHandle
0x14023e598 GetCurrentProcessId
0x14023e5a0 RtlVirtualUnwind
0x14023e5a8 RtlLookupFunctionEntry
0x14023e5b0 QueryPerformanceCounter
0x14023e5b8 GetSystemTimeAsFileTime
0x14023e5c0 InitializeSListHead
0x14023e5c8 RtlCaptureContext
Library GDI32.dll:
0x14023e090 SetWindowOrgEx
0x14023e098 GetKerningPairsW
0x14023e0a0 SetBrushOrgEx
0x14023e0a8 GetWinMetaFileBits
0x14023e0b0 PolylineTo
0x14023e0b8 Polygon
0x14023e0c0 LPtoDP
0x14023e0c8 PolyTextOutW
0x14023e0d0 StrokeAndFillPath
0x14023e0d8 SetArcDirection
0x14023e0e0 AbortPath
0x14023e0e8 SetWinMetaFileBits
0x14023e0f0 GetEnhMetaFileBits
0x14023e0f8 GdiTransparentBlt
0x14023e100 SetTextColor
0x14023e108 SetSystemPaletteUse
0x14023e110 SetMetaFileBitsEx
0x14023e118 SetMapMode
0x14023e120 SetDIBitsToDevice
0x14023e128 SetBkMode
0x14023e130 SetDCPenColor
0x14023e138 SaveDC
0x14023e140 PtVisible
0x14023e148 PtInRegion
0x14023e150 OffsetClipRgn
0x14023e158 MaskBlt
0x14023e160 GetWindowExtEx
0x14023e168 GetViewportOrgEx
0x14023e170 RemoveFontResourceExW
0x14023e178 GetGlyphIndicesW
0x14023e180 GetTextExtentExPointW
0x14023e188 GetTextAlign
0x14023e190 GetSystemPaletteUse
0x14023e198 GetSystemPaletteEntries
0x14023e1a0 GetMetaFileBitsEx
0x14023e1a8 GetCurrentPositionEx
0x14023e1b0 GetCharWidth32W
0x14023e1b8 GetCharWidthW
0x14023e1c0 EnumFontFamiliesW
0x14023e1c8 DrawEscape
0x14023e1d0 CreateBrushIndirect
0x14023e1d8 CancelDC
0x14023e1e0 BitBlt
0x14023e1e8 Arc
0x14023e1f0 AnimatePalette
Library WINSPOOL.DRV:
0x14023e608 ConnectToPrinterDlg
0x14023e610 EnumPrintersW
0x14023e618 ResetPrinterW
0x14023e620 SetJobW
0x14023e628 GetJobW
0x14023e630 EnumJobsW
0x14023e638 SetPrinterW
0x14023e640 FlushPrinter
0x14023e648 GetPrinterDataW
0x14023e650 EnumPrinterDataW
0x14023e658 SetPrinterDataW
0x14023e660 SetPrinterDataExW
0x14023e668 GetFormW
0x14023e670 ConfigurePortW
0x14023e678 SetPortW
Library COMDLG32.dll:
0x14023e038 PrintDlgExW
0x14023e040 PrintDlgW
0x14023e048 ChooseFontW
0x14023e050 ReplaceTextW
0x14023e058 FindTextW
0x14023e060 ChooseColorW
0x14023e068 GetFileTitleW
0x14023e070 GetSaveFileNameW
0x14023e078 GetOpenFileNameW
0x14023e080 CommDlgExtendedError
Library ole32.dll:
0x14023e698 StringFromIID
0x14023e6a0 CLSIDFromString
0x14023e6a8 CoEnableCallCancellation
0x14023e6b0 CoTestCancel
0x14023e6b8 CoCancelCall
0x14023e6c8 CoQueryClientBlanket
0x14023e6d0 CoSetProxyBlanket
0x14023e6d8 IIDFromString
0x14023e6f0 CoGetStdMarshalEx
0x14023e6f8 CoLockObjectExternal
0x14023e700 CoDisconnectObject
0x14023e708 CoMarshalHresult
0x14023e710 CoUnmarshalInterface
0x14023e718 CoMarshalInterface
0x14023e720 CoGetMarshalSizeMax
0x14023e728 CoGetPSClsid
0x14023e730 CoResumeClassObjects
0x14023e738 CoGetObjectContext
0x14023e740 CoGetContextToken
0x14023e750 CoGetCurrentProcess
0x14023e758 CoUninitialize
0x14023e760 ProgIDFromCLSID
0x14023e768 CLSIDFromProgID
0x14023e778 CLSIDFromProgIDEx
0x14023e790 CoIsOle1Class
0x14023e798 CoFileTimeToDosDateTime
0x14023e7a0 CoInstall
0x14023e7a8 BindMoniker
0x14023e7b0 MkParseDisplayName
0x14023e7b8 MonikerRelativePathTo
0x14023e7c0 GetClassFile
0x14023e7c8 OleGetIconOfClass
0x14023e7d0 OleSetAutoConvert
0x14023e7d8 CoGetInterceptor
0x14023e7e0 CoGetCallContext
Library VERSION.dll:
0x14023e5d8 VerQueryValueW
0x14023e5e0 GetFileVersionInfoW
0x14023e5e8 GetFileVersionInfoSizeW
0x14023e5f0 VerInstallFileW
0x14023e5f8 VerFindFileW
Library COMCTL32.dll:
0x14023e000 None
0x14023e008 None
0x14023e010 None
0x14023e018 None
0x14023e020 None
0x14023e028 PropertySheetW
Library dxgi.dll:
0x14023e688 CreateDXGIFactory

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
D$$;N$
D$HHcD$ H
sNHcD$ H
+D$$HcL$ H
D$PHc@<H
@m_UR~`
::PToV
Dy}9C7
yb&J*0
OOHtzoW
>xFv/!
YKo~Q(
M@cDFN
`Kn?aQ
+Aq*|P
g}K$eA
c-&LLF
+,Ihg
N:L_(w
ZTy(rs=R
6ASH>]
(B?,5O
?Vr++9
9x` B n
AtKL*e
;d:V"|
cvab6A
3%_o.j
W4Z$=~
p5|=5q
tJ[R0UR`3
Kx7KG<
`7dE7Y
AAb_5?
> s,Bx
^h+VSZ
'2Zd+8
X#qx:#
x;W15Q
dD?!\K
a0$Z8F
0>c|kZM
x.OcYW]
B)EihT$
Z|W0<V
Sabf2z
O.6O7"&
spQ9&V
^)MtI*P+
tGn4&q
F.\=pq
2la}HT5u
/"eZJ!
m$wzoz
G@@&!C
,\cq>C
}?)l/~ad
c4 B+#
(;8#:o
V 6J"O
_nx6W
@m8LDN
eXFhr@
GYN/L
hp2rR~
uJcpZ`
^f g4Nk"7
*d}GK
1%$R;I
+%g0nzC
d>B2Ol
|Jh}I%
v/j,Cy
ci]sL6|<
kB`5(8
a[;tu7
3<"(56
txPft<
r#iwt#}
]>~/AU
CFc u"
\?'c_o9
y]+>vF|
%vL\&)
!E'p'c
O%j{VL
x;'$obW\wU
jbw"+4(6
8W$zoC
})y{
:mn9QxK
w6u<ww
b+.^48
x^\x1YqI
%x2&dM
;L7%{b.f
/)%GLi
Lo_P0e
v_P1-
5;vIzk
l,&z_`
Vwp}Z?
a(_.?$ru
P3%NW
*A^c-nU
OHAp74%X
3<kTk
H~l.Y9>
"bQ<}f
Zg34&A
}D5qa&5
#nph,7
\_4"A=ht
)*D/ 
t?Cy5$
Ji|oUY]q<
<m#%e/
$^JP zhP
KL.{Y[
fn7x$K
qx3~7O
LF@yX'
{*1n^LV
KYm9-|
6jLMwi
BLw>!n
yj"8Qd
wBVpns
aei{-:
uF)No/
Io|\~0
O*WeyDL
'PPKt(
X{pM[p
fwVX>
Br{BV5<
SY[:7R
4HQ)?&
!v6!5^
A[75Y\
F~3G%'
'(LsQCHC
h=#a+,
',8OT~-P
ZmY&O&
`+eZ7[1
7f5Y1>}H
tVtXH/d]H
;>o8H
Yv5uPH
Jy=rnXH
r7SYtQ
1H9D$8
LlH9D$ht
?H9D$8|)H
H9D$XtIH
9(rH9D$Xt
H9D$ht
H9D$ptVH
AH9D$pt
zH9D$(
H9D$ht
tQH9D$h
J\6uoJ
"]d6#H
$Q}kG~!
<}C~DW
[5BpZbc
J3}ze
3a`;TI
MjBr"Z
'ro3xJy
Q^_f8:>iS*}\
y}(h(|
Bn=_X7
:,GG>M
r;3ybH
xLQ?O
E;!j \
|}'g#fNF[5*v1LG8
u)}LFOF
><SOt
KP[@>_
d^[IY1
?M3)<IR
-/?/$
<Mq<`^O
3>L|:T
o/;Q{f
bXUwd3[
[>9Nd e
sl,0G+
t)FYNL'
.E>]gue
k7GLvX
B3ndne,
m,R:b<i3T
S ;lR3T
nyYvd,P
"wYq)dF
\Tcsl]
j%WGe:[
~w+O9jF:
Suc%hD
4>bzo9
tUfh]
\~dR5bT
TWQwRI
/fX$\A
n^n@o1>%
U(5fBf
-e;?[I=$
x{J#{(
'Fr!7(
y%(x?B
xKvQs?
2zK-J,?'
`X@eCn
LrvFF<5~qt&c
+hcWLv
hvnS6O(6W
r7"abY
$pW Do
pdz""i
:^cgzX
f4&^dd
vR5Vtn
*Z-XF6g
?pKy<R
){|m#
_ExP+~
YO kF{
$bs td
6lu\d7
'HK.|"
Yr/%X&
aHICO$Fu
:!v*J
sw \QU^EUN
S9sr}xJC
}mV?/aK
v6LfV0
5R3#F!V
2M&!vb
v!8c/@
366yVX}
?FkbNZ
IvAk+2#
12){Mh!
Ds! +N
:KsRe<
.{Ph`3b
+F0k+U
9@BaP6a&
_<p'E0
)z]DC'2
My[ NU
;XlBCM
az5%!7
/".IDhWe
d<4n*1
za6R;)
e1HX@$
f..4,W
`[Yf%&
vHrai?
CIAA+%
"'zMp-
If!y.YFe
UzG%J=
BQ|I)a
KiY?Pr
vgz!w["
m*wwSx<
W`E.'
nzuKP#%
Y'D(Q*.u6
! IOeA
"Pk>u0
B[#o`k
z@KW_7
-,y2[K
%M|3Cm
+E5Tm
H>q2:3
Dm;T1O
S:"a8{
Q8}]bj4u
')FWMR
ySlrzt
1~{vK
h40dP6
iPBRly
L>'+[5M84*
<ye5.\
OIGGoT
b_UeI
u]]!lXc
IKg:4R
<$ESb!
}H9{05
8P*@@`[
Ey3_E3X
,r[!4t
|Q~;~^
Izvz$NcS
G5e.kC
]5F68$
joJML$
Sa0@s&2_
|dMz3$-
1jDP4z
jEhuMs
3s]!rS
"Va* A
DcnHB>
&T23n.:"
!tKGVa
&&Kv?#
VovOY/
O>6 vb
Q3w1h&
;F!W2c
M9}.dE
j`'lXj
&Vp\se
MiQ5{(
MqR]jq
U64!]F
0?%m8H
V62q4S
@kE5m%0
r>f6/,
JQV/cK
OdN26RQ
="NY0P
181"S4
0~D9(M
snJ"N,
{+|nWa
?K*11O
g.2p@
Q)s `v
?VyN&P
LiR&Gm
A14y<&H
/%,)_,
??i |U<R
6m\Jf]
L|c#p`
243R?$B
F.,lXL'
rgmFJ"g
m]PIV@z'
:!H%#L
9B=jR
9l{ s"
^9-yzh
<?`pNzs
+iE@ @Zn
8BA8W]
TIFE/[
#/4t_
5qc;VW+
IAJ-Fx
n3W5I(
jF$Jpd
FA5g9m
zsdGENN\T
9fw/{C
_xA$D7
pCb4Dt5
_N]73]
{:?ee$
8uI))
p&Jjlf
|+KEx;ZC
EF"rf0iI
~yz>{r
'NMkJ
-9T-Iwp
ifGRc
y)Fg1s
q"=Pg`
nk#@ m
3{n;i4A
)B%f!V
`dx8.*
}]KPMW
>+Ko:
v@TY-7=)l
h=of/U|T
3nH8`r@;
/V%l@i*
#Ae3o^P(
#.%LJJ
FgJt7cH
'}8`mf
S#@LlM
t8Rkfl
1c$T6-
+0ddX/M3
p'8ijK
NX_~pl
lu}aGA,
c]"F&q),BWq
lNg)aCb
R8U1iY&
;k+1vS
2NmbFVN
~Da[rl
Ma%C9b
LY?zJ<
*&>dH
`\;6Q
(6`*OR
NQ)!9z
Ar!7)F
u$ShN(
)2DUE
/V>}X
'8eE$p
'R,A;
U/Vq_G
\`+t*m
DPijr~6
vX{J<XL]r;c
?Oc9 7
bRZB)c
(m-07&
Shv=w%<M7
4=R0ge
43<9-xj
(0uAg_d
rdffq.
xT~1=P
9JJE'YZE4)
A8i*TK
{L(N!C
bONtW,#
M|*bcv
&ZIo1[*
Gp&<]T
h:H.!x
6qH,6B3
*::XI"
hSun[.
g[Jn}H
WUP.21
J\AN`E
b+!Nz4h
QBBG":
,L0{Wa\
_(+xP
n.|?E,|
:t0rqDP
#^2tBm
eA\o+
qgDs#Sp
CkO='t
"eu#[0
rZst|
P`Tvuq
+& )d:
WfckcG
Cz``@Y
5*A?Iu
s/e|2c
Q5<A2
ujtC-v
';=ZhR
`vB]0O
k+))tU
@Wb{].
=0)?cX
KYL|f@
^<]wRc
\nb-w?
/X?rXF
-J*zFM
%wZZ+X
]{'Y=DN
^[<~l6
n<J6t%2
\`33Y0l
nEg9PL
R<V|6KV
DCa#w
7lfYFB
2bG4i6
>Bv;(TP
;/8Yf`CJ
"jay/>
Dqai;
~#@C{{h
?wS9mdm
|O`x#A
j-qNo)
UpYmo
`}Sp>,juBg
nZq2(P_
)l;t6/
~0jQ=O|
3'YZCs
)}_=n2
H8%}un
a3XPj}
/2Q"k_
9G;^b<x
gE}Hc3D
eON@a4C
&lO@Ha4C
9X:YD29x
[v-<4F
to(Qd3x
)%FhB|
*}g5?6=
(%|9[z
.&8}xj|
9Cc^5P
pO}Vc{
u/HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
u3HcH<H
WAVAWH
A_A^_
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
USVWAVH
A^_^[]
LcA<E3
fffffff
ffffff
vKfffff
fffffff
fffffff
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
GetModuleHandleA
SetStdHandle
GetCurrentDirectoryW
DefineDosDeviceW
FindClose
GetFileAttributesExW
GetFileInformationByHandle
GetFileSizeEx
GetLongPathNameW
LockFileEx
QueryDosDeviceW
SetEndOfFile
SetFilePointerEx
UnlockFileEx
AreFileApisANSI
SetFileApisToANSI
GetCurrentProcess
GetCurrentProcessId
GetExitCodeProcess
GetCurrentThreadId
GetThreadPriorityBoost
TlsGetValue
TlsSetValue
SetPriorityClass
GetProcessPriorityBoost
GetLogicalProcessorInformation
AssignProcessToJobObject
QueryInformationJobObject
GetNumaHighestNodeNumber
SetProcessAffinityMask
GetProcessIoCounters
ConvertFiberToThread
SetTapePosition
GetTapePosition
PrepareTape
GetTapeStatus
GetTapeParameters
lstrcmpW
lstrcatW
BackupRead
BackupSeek
CopyFileW
CopyFileExW
FindFirstVolumeMountPointW
SetVolumeMountPointW
GetNumaProcessorNode
GetDateFormatW
GetTimeFormatW
CompareStringW
IsValidCodePage
GetCPInfoExW
SetLocaleInfoW
GetCurrencyFormatW
GetSystemDefaultLCID
GetUserDefaultLCID
GetConsoleOutputCP
SetConsoleCtrlHandler
SetConsoleOutputCP
GetConsoleCursorInfo
SetConsoleCursorInfo
GetConsoleScreenBufferInfo
KERNEL32.dll
AnimatePalette
BitBlt
CancelDC
CreateBrushIndirect
DrawEscape
EnumFontFamiliesW
GetCharWidthW
GetCharWidth32W
GetCurrentPositionEx
GetMetaFileBitsEx
GetSystemPaletteEntries
GetSystemPaletteUse
GetTextAlign
GetTextExtentExPointW
GetGlyphIndicesW
RemoveFontResourceExW
GetViewportOrgEx
GetWindowExtEx
MaskBlt
OffsetClipRgn
PtInRegion
PtVisible
SaveDC
SetDCPenColor
SetBkMode
SetDIBitsToDevice
SetMapMode
SetMetaFileBitsEx
SetSystemPaletteUse
SetTextColor
GdiTransparentBlt
GetEnhMetaFileBits
GetWinMetaFileBits
SetWinMetaFileBits
AbortPath
SetArcDirection
StrokeAndFillPath
PolyTextOutW
LPtoDP
Polygon
PolylineTo
SetWindowOrgEx
SetBrushOrgEx
GetKerningPairsW
GDI32.dll
EnumPrintersW
ResetPrinterW
SetJobW
GetJobW
EnumJobsW
SetPrinterW
FlushPrinter
GetPrinterDataW
EnumPrinterDataW
SetPrinterDataW
SetPrinterDataExW
GetFormW
ConfigurePortW
SetPortW
ConnectToPrinterDlg
WINSPOOL.DRV
GetOpenFileNameW
GetSaveFileNameW
GetFileTitleW
ChooseColorW
FindTextW
ReplaceTextW
ChooseFontW
PrintDlgW
PrintDlgExW
CommDlgExtendedError
COMDLG32.dll
CoUninitialize
CoGetCurrentProcess
CoGetCurrentLogicalThreadId
CoGetContextToken
CoGetObjectContext
CoResumeClassObjects
CoGetPSClsid
CoGetMarshalSizeMax
CoMarshalInterface
CoUnmarshalInterface
CoMarshalHresult
CoDisconnectObject
CoLockObjectExternal
CoGetStdMarshalEx
CoMarshalInterThreadInterfaceInStream
CoGetInterfaceAndReleaseStream
CoGetCallContext
CoSetProxyBlanket
CoQueryClientBlanket
CoQueryAuthenticationServices
CoCancelCall
CoTestCancel
CoEnableCallCancellation
CLSIDFromString
StringFromIID
IIDFromString
ProgIDFromCLSID
CLSIDFromProgID
CoInvalidateRemoteMachineBindings
CLSIDFromProgIDEx
CoGetInstanceFromIStorage
CoAllowSetForegroundWindow
CoIsOle1Class
CoFileTimeToDosDateTime
CoInstall
BindMoniker
MkParseDisplayName
MonikerRelativePathTo
GetClassFile
OleGetIconOfClass
OleSetAutoConvert
CoGetInterceptor
ole32.dll
VerFindFileW
VerInstallFileW
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
PropertySheetW
COMCTL32.dll
CreateDXGIFactory
dxgi.dll
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindFirstFileExW
FindNextFileW
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleMode
CreateFileW
CloseHandle
WriteConsoleW
S@z+j,
E){+0D2E
|'Rr4-
74SF-
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Laddie\Cuckolded\Newcomers\hoarsely\obscurer
pendulum\Ratings
tundra Posters Shrivels Espousal bops
simmers\aggressors\Mailmen\soap\Evergreen
Existences supplied Fluent Grief rivetingly
Prevented schemas
Characters Magneto Adverts
Grumbling\biddings
overdose dispersion
teapots verminous disobeyed legalising expository
anachronistically\Statutes\earthquake
remnant\swimmers\massproduced\Fitting
calculative Enjoyability
serviced ancestral Chomped redeemable
teeth Bifocal untiring
Truculence\Inching
Bistable\bedclothes\Dejectedly\Submitted
carve\pestilent\sipped\Slobbers
Safeguards Pathfinder Unemployment
storehouses royal
Epicarp anthropologist Overwritten college amputations
Hurls disorientating
Always Cervix
cryptically virus tubers
Taxman
Retitling\meows\comet\reigned
Rehashes
communicants flavouring
Shrinkage Finally Armouries
Rickets Relay Nut holidays
Excommunicate\leaner\Confederation\sprout
Miscellanies\troublemaker\haystack
Lionesses rustle Embryonal trodden
Tears Unworried
Castrated Adamantly
Bunked Immoral luke Pelmet
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
041504E7
Comments
Overwrote semi schismatics
CompanyName
Suspects jocularly prolonged
FileDescription
Moats unmarked peddle shinning
FileVersion
5.242.207.6
InternalName
Rapids
LegalCopyright
Copyright
Daintiness mends percussive shorty oiliest
LegalTrademarks
Insomnia parliamentarians alleyway
OriginalFilename
Embellished anergy
ProductName
Furriest
ProductVersion
5.242.207.6
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
Skyhigh Clean
ALYac Gen:Variant.Lazy.598188
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Gen:Variant.Lazy.598188
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.598188
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Lazy.598188
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Generic.mg.0d14677324fb1f05
Emsisoft Gen:Variant.Lazy.598188 (B)
huorong Clean
GData Gen:Variant.Lazy.598188
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.D920AC
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=85)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_60% (D)
alibabacloud Clean
No IRMA results available.