Static | ZeroBOX

PE Compile Time

2019-04-21 08:23:35

PE Imphash

8d947d8266d1e96ff10ab0c505eb32cf

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003d60c 0x0003d800 6.40598155627
.rdata 0x0003f000 0x0001511a 0x00015200 4.88366342031
.data 0x00055000 0x00006d00 0x00003e00 3.33068802013
.pdata 0x0005c000 0x00003cfc 0x00003e00 5.63801054312
.reloc 0x00060000 0x00000c44 0x00000e00 5.16490241108

Imports

Library WS2_32.dll:
0x18003f648 recv
0x18003f650 bind
0x18003f658 closesocket
0x18003f660 htons
0x18003f668 WSASocketA
0x18003f670 WSAGetLastError
0x18003f678 setsockopt
0x18003f680 send
0x18003f688 select
0x18003f690 accept
0x18003f698 __WSAFDIsSet
0x18003f6a0 WSADuplicateSocketA
0x18003f6a8 WSAStartup
0x18003f6b0 socket
0x18003f6b8 listen
0x18003f6c0 inet_addr
Library KERNEL32.dll:
0x18003f100 LeaveCriticalSection
0x18003f108 DeleteCriticalSection
0x18003f110 ReleaseSemaphore
0x18003f118 Sleep
0x18003f120 CloseHandle
0x18003f128 DuplicateHandle
0x18003f130 GetSystemTime
0x18003f138 TlsAlloc
0x18003f140 TlsGetValue
0x18003f148 TlsSetValue
0x18003f150 CreateSemaphoreA
0x18003f158 UnmapViewOfFile
0x18003f160 SetErrorMode
0x18003f168 WriteFile
0x18003f170 FindClose
0x18003f178 SetFileTime
0x18003f180 GetLogicalDriveStringsA
0x18003f188 CreateDirectoryA
0x18003f190 CreateFileA
0x18003f198 DeleteFileA
0x18003f1a0 FindFirstFileA
0x18003f1a8 FindNextFileA
0x18003f1b0 GetComputerNameA
0x18003f1b8 GlobalAlloc
0x18003f1c0 GlobalLock
0x18003f1c8 GlobalUnlock
0x18003f1d0 GlobalDeleteAtom
0x18003f1d8 SystemTimeToFileTime
0x18003f1e0 GlobalAddAtomA
0x18003f1e8 GetVersionExA
0x18003f1f0 SetEvent
0x18003f1f8 GetConsoleCP
0x18003f200 FlushFileBuffers
0x18003f208 HeapSize
0x18003f210 GetProcessHeap
0x18003f218 GetFileType
0x18003f220 GetCPInfo
0x18003f228 GetOEMCP
0x18003f230 EnterCriticalSection
0x18003f238 IsValidCodePage
0x18003f240 GetModuleFileNameW
0x18003f248 GetStdHandle
0x18003f250 GetModuleHandleW
0x18003f258 GetStartupInfoW
0x18003f260 TlsFree
0x18003f268 TerminateProcess
0x18003f280 UnhandledExceptionFilter
0x18003f288 RtlVirtualUnwind
0x18003f290 RtlCaptureContext
0x18003f2a0 IsDebuggerPresent
0x18003f2a8 SetLastError
0x18003f2b0 GetCommandLineA
0x18003f2b8 RaiseException
0x18003f2c0 RtlPcToFileHeader
0x18003f2c8 LoadLibraryExW
0x18003f2d0 CreateThread
0x18003f2d8 HeapAlloc
0x18003f2e0 HeapFree
0x18003f2e8 GetSystemTimeAsFileTime
0x18003f2f0 WideCharToMultiByte
0x18003f2f8 MultiByteToWideChar
0x18003f300 GetModuleHandleExW
0x18003f308 ExitProcess
0x18003f310 DecodePointer
0x18003f318 GetConsoleMode
0x18003f320 EncodePointer
0x18003f328 RtlUnwindEx
0x18003f330 RtlLookupFunctionEntry
0x18003f338 ReadFile
0x18003f340 ReadConsoleW
0x18003f348 GetModuleFileNameA
0x18003f350 QueryPerformanceCounter
0x18003f360 ResumeThread
0x18003f368 GetLastError
0x18003f370 SetThreadPriority
0x18003f378 GetCurrentThreadId
0x18003f380 GetCurrentThread
0x18003f388 GetCurrentProcess
0x18003f390 LoadLibraryA
0x18003f398 CreateEventA
0x18003f3a0 WaitForSingleObject
0x18003f3a8 ExitThread
0x18003f3b0 GetCurrentProcessId
0x18003f3b8 GetProcAddress
0x18003f3c0 FreeLibrary
0x18003f3c8 GetEnvironmentStringsW
0x18003f3d0 FreeEnvironmentStringsW
0x18003f3d8 OutputDebugStringW
0x18003f3e0 HeapReAlloc
0x18003f3e8 CompareStringW
0x18003f3f0 LCMapStringW
0x18003f3f8 GetStringTypeW
0x18003f400 SetStdHandle
0x18003f408 SetFilePointerEx
0x18003f410 WriteConsoleW
0x18003f418 SetEnvironmentVariableA
0x18003f420 GetACP
0x18003f428 CreateFileW
Library USER32.dll:
0x18003f440 MessageBeep
0x18003f448 ExitWindowsEx
0x18003f450 MapVirtualKeyA
0x18003f458 VkKeyScanA
0x18003f460 GetAsyncKeyState
0x18003f468 SystemParametersInfoA
0x18003f470 ChangeDisplaySettingsA
0x18003f478 DrawIconEx
0x18003f480 LoadCursorA
0x18003f488 GetClassNameA
0x18003f490 EnumWindows
0x18003f498 FindWindowA
0x18003f4a0 SetWindowLongPtrA
0x18003f4a8 GetWindowLongPtrA
0x18003f4b0 GetWindowLongA
0x18003f4b8 EqualRect
0x18003f4c0 WindowFromPoint
0x18003f4c8 RemovePropA
0x18003f4d0 GetPropA
0x18003f4d8 SetPropA
0x18003f4e0 GetForegroundWindow
0x18003f4e8 SetTimer
0x18003f4f0 EmptyClipboard
0x18003f4f8 GetClipboardData
0x18003f500 SetClipboardData
0x18003f508 ChangeClipboardChain
0x18003f510 SetClipboardViewer
0x18003f518 GetClipboardOwner
0x18003f520 CloseClipboard
0x18003f528 OpenClipboard
0x18003f530 IsWindowVisible
0x18003f538 DestroyWindow
0x18003f540 CreateWindowExA
0x18003f548 RegisterClassExA
0x18003f550 PostQuitMessage
0x18003f558 DefWindowProcA
0x18003f560 WaitMessage
0x18003f568 PostMessageA
0x18003f570 SendMessageA
0x18003f578 PeekMessageA
0x18003f580 DispatchMessageA
0x18003f588 RegisterWindowMessageA
0x18003f590 EnumDesktopWindows
0x18003f598 OpenDesktopA
0x18003f5a0 GetDesktopWindow
0x18003f5a8 IsRectEmpty
0x18003f5b0 IntersectRect
0x18003f5b8 GetCursorPos
0x18003f5c0 GetWindowRect
0x18003f5c8 GetSystemMetrics
0x18003f5d0 mouse_event
0x18003f5d8 keybd_event
0x18003f5e0 GetKeyboardState
0x18003f5e8 EnumDisplaySettingsA
0x18003f5f0 GetThreadDesktop
0x18003f5f8 CloseDesktop
0x18003f600 SetThreadDesktop
0x18003f608 ReleaseDC
0x18003f610 GetDC
0x18003f618 SetRect
0x18003f620 GetIconInfo
0x18003f628 GetProcessWindowStation
0x18003f630 OpenInputDesktop
0x18003f638 KillTimer
Library GDI32.dll:
0x18003f040 GetObjectA
0x18003f048 GetBitmapBits
0x18003f050 DeleteObject
0x18003f058 GetStockObject
0x18003f060 RealizePalette
0x18003f068 SelectObject
0x18003f070 GetSystemPaletteEntries
0x18003f078 CreateDIBSection
0x18003f080 GdiFlush
0x18003f088 CombineRgn
0x18003f090 CreateRectRgn
0x18003f098 CreateRectRgnIndirect
0x18003f0a0 GetRegionData
0x18003f0a8 CreateDCA
0x18003f0b0 DeleteDC
0x18003f0b8 ExtEscape
0x18003f0c0 BitBlt
0x18003f0c8 CreateCompatibleBitmap
0x18003f0d0 CreateCompatibleDC
0x18003f0d8 CreatePalette
0x18003f0e0 SelectPalette
0x18003f0e8 GetDIBits
0x18003f0f0 GetDeviceCaps
Library ADVAPI32.dll:
0x18003f000 GetUserNameA
0x18003f008 RevertToSelf
0x18003f010 RegSetValueExA
0x18003f018 RegDeleteValueA
0x18003f020 RegCreateKeyA
0x18003f028 RegCloseKey
0x18003f030 ImpersonateLoggedOnUser

Exports

Ordinal Address Name
1 0x180001320 ?ReflectiveLoader@@YA_KPEAX@Z
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.reloc
SAVAWH
V IcB<B
l$hLc}<3
t$HcF<
@A_A^[
|$ AUAVAWH
A+1A+i
0A_A^A]
|$ AVH
SUVWATAUAVAWH
T$,fff
HA_A^A]A\_^][
SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAVAWH
HA_A^A]A\_^][
SUWAVH
u;Hc\$dH
u;Hc\$TH
SUWAVH
u8Hc\$`H
|$ AVH
A+9A+q
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
D;L$x|
A_A^A]A\_^]
A+1A+Y
fD+T$PH
f+L$XfA
SUVWATAUH
Lc\$p3
~MLcL$x
A]A\_^][
A]A\_^][
l$ AVH
l$HD9~p
L$ WATAUAVAWH
A_A^A]A\_
B!8BAuvD
B"8BBt
B$f9BDuN
B&f9BFuD
B(f9BHu:
B*8BJu1
B+8BKu(
B,8BLuH
WAVAWH
@A_A^_
WATAUAVAWH
A+1A+i
0A_A^A]A\_
SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAVAWH
\$$fff
L$6D;L$,
HA_A^A]A\_^][
~*HcT$(
~)HcT$(3
~*HcT$(
@VWATH
SAUAVH
|$XL;t$`
|$8HcyhH
HcAdHk
D;D24H
D;D1$H
t$ AVD
t$ AVD
t$ AVD
USVWAUAVAWH
;EwtN=
A_A^A]_^[]
SVWATAUAVH
hA^A]A\_^[
L$Pfff
hA^A]A\_^[
WATAUAVAWH
P0HcFdA
`~?Hc^h
t)HcFh
@A_A^A]A\_
WATAUAVAWH
@A_A^A]A\_
@UVWATAVH
fE9$Fu
A^A\_^]
A^A\_^]
A^A\_^]
@UVWATAVH
A^A\_^]
A^A\_^]
A^A\_^]
SUVWATH
A\_^][
SWAUAVAWH
pA_A^A]_[
SVWATAVH
A^A\_^[
UWAUAVAWH
`A_A^A]_]
`A_A^A]_]
HcAdHk
\$ UVW
\$8_^]
|$ ATAVAWD
|$8A_A^A\
|$ AVH
p WAVAWH
UVWATAVH
l$pfA#
@A^A\_^]
WATAUAVAWH
0A_A^A]A\_
USVWAUAVAWI
L$@fE;
P0Lcl$PM
Lcl$PI
"~h+D$hH
D$TD;d$`
A_A^A]_^[]
USVWATAUAVH
;T$@tJ
P0Lcl$DM
Lcl$DI
"~h+D$dH
D$PD;|$X
A^A]A\_^[]
SUVWATAVH
P0Lcd$HM
Hc\$HA
"~s+D$XHc|$HH
A^A\_^][
WATAUAVAWH
@A_A^A]A\_
@VWAVH
\$0tL
SUVWATAUAVAWH
T$HD9s8
;CH|LHc
;k4}+H
hA_A^A]A\_^][
d$H9YL
T$Pfff
D$`9>s
D$DE;|$
d$H;YL
@SVWAVAWH
A9Z8~bL
`A_A^_^[
\$ UWAWH
uXD9}L~wH
v`D;}L|
@SUATH
y0Hci8A
t5;S<u
C89CLt
Y0LcQL
|$ AVAWH
|$0A_A^
ATAUAVAWH
A_A^A]A\
)D$pfD
)L$`fD
)\$@fD
)d$0fD
)l$ fD
WAVAWH
UWATAUAWI
A_A]A\_]
t89n0u0
@SUVWAUH
A]_^][
A]_^][
@SVAWH
|$ ATAVAWH
A_A^A\
UATAUAVAWH
L$PD91u
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
@SWAUAVH
(A^A]_[
9sL~GL
l$ VAVAWH
@A_A^^
\$ VWAVH
9iL~#H
9kL~^H
{X9kL~vH
|$ AVH
9KL~VD
|$ AVH
UVWATAUAVAWH
A_A^A]A\_^]
|$ AVH
@SUATAWH
(A_A\][
@SUWATAUH
A]A\_][
@SUVWATAVAWH
A_A^A\_^][
|$ AVH
{X9sL~OL
SVWAUAVH
C49G`uhE3
D9{L~_
gdD)g`
Gl9Gd}C3
9kL~6H
Gl9Gdu_A
Gh9wh|
PA^A]_^[
D9{L~-H
9Edu%A
E9&rH
{XD9{L~<H
`D;{L|
UVWATAUAVAWH
D$pE;e
A_A^A]A\_^]
VAVAWH
A_A^^
SUVWAUAVH
HA^A]_^][
SUVWATAUAVH
@A^A]A\_^][
@SUVWAVH
9nL~gL
A^_^][
|$ ATAVAWA
|$8A_A^A\
|$ ATAUAVAWA
|$@A_A^A]A\
WAVAWH
A_A^_
WAVAWH
A_A^_
|$ ATAVAWH
A_A^A\
|$ AVH
|$ ATAVAWH
A_A^A\
|$ ATAVAWH
A_A^A\
|$ ATAVAWH
0A_A^A\
|$ ATAVAWH
0A_A^A\
|$ AVH
|$ AVH
|$ ATAVAWH
A_A^A\
WATAUAVAWH
A_A^A]A\_
uX9o,t
@SUVAVH
(A^^][
|$ L9s0u
C0L9s8u
(A^^][
(A^^][
C D9C,}
C,D9C,
\$0)p(H
|$ ATAUAVAW
A_A^A]A\
A(LcA(H
~NIcR(A
B(IcR(I
~OIcR(A
B(IcR(I
~YIcR(
B(IcR(I
~_McB(I
B(McB(A
~mHcS(D
C(HcS(H
~\HcS(D
C(HcS(H
~_IcR(A
B(IcR(I
A(HcQ(A
|/HcQ(A
~LcA(
|$ ATAVAWH
A_A^A\
~ZLc@(A
;Lc@(A
~ZLc@(A
@(LcH(
tRIcJ(I
B(IcJ(I
B(IcJ(I
B(IcJ(I
@SUVWATH
tdLc\$HIc
A\_^][
C(HcS(H
~[HcS(A
C(HcS(H
~\HcS(E
C(HcS(H
C(HcS(H
~aLc@(E
~aLc@(E
~^Lc@(E
%3333D3
WAVAWH
|$ AVH
\$ WATAVAWLcD$X
HcT$PL
\$@A_A^A\_
@SHcD$8D
HcL$@+
\$ WATAVAWLcD$X
HcT$PL
\$@A_A^A\_
WAVAWH
A_A^_
|$ AVH
t$ AVH
@SHcD$@
\$ UWAVAWLcD$X
\$@A_A^_]
@SHcD$@
HcL$8H
\$ WATAVAWLcD$X
HcT$PM
\$@A_A^A\_
@SHcD$@
HcL$8H
\$ WATAVAWLcD$X
HcT$PM
\$@A_A^A\_
WAVAWH
A_A^_
|$ AVH
t$ AVH
@SHcD$@
\$ UWAVAWLcD$X
\$@A_A^_]
@SHcD$@
HcL$8H
\$ WATAVAWLcD$X
HcT$PM
\$@A_A^A\_
@SHcD$@
HcL$8H
\$ WATAVAWLcD$X
HcT$PM
\$@A_A^A\_
|$ AVH
|$ AVH
HcL$@+
\$ UWAVAWLcD$X
\$@A_A^_]
@SHcD$8D
HcL$@+
t$@Lct$XHc
DISPLAY
@USVWATH
A\_^[]
A\_^[]
t$ ATAVAWH
@A_A^A\
t$ ATAVAWH
@A_A^A\
@SVAUAVAWH
0A_A^A]^[
0A_A^A]^[
|$ AVH
t'H;Kpt!H
t)H;Kpt#H
t)H;Kpt#H
9C(tHH
tP@8{xt
@USVWATAVAWH
`A_A^A\_^[]
VNCAUTH_D
D$$STDVH
t$ WAVAWH
@A_A^_
@WAVAWH
0A_A^_
@WAVAWH
0A_A^_
FTS_LSDT
D$$TGHTH
FTS_DNDT
FTS_UPCN
D$4TGHTH
FTS_DNFL
D$DTGHTA
D$TTGHT
FTC_LSRQ
D$dTGHTH
FTC_DNRQ
FTC_UPRQ
D$tTGHTH
FTC_UPDT
FTC_DNCN
FTC_UPFL
COPYRECT
RRE_____H
CORRE___H
HEXTILE_A
ZLIB____
ZLIBHEX_
TIGHT___
COMPRLVL
JPEGQLVL
X11CURSR
RCHCURSR
POINTPOS
LASTRECT
NEWFBSIZ
E$TGHTf
E4TGHTf#
EDTGHT
ETTGHT
EdTGHT
EtTGHT
@UVWATAUAVAWH
0A_A^A]A\_^]
@SVWAVH
XA^_^[
9Gpt89
@VWAVH
UVWATAUAVAWH
A_A^A]A\_^]
L$0)D$P
D$()D$TH
WAVAWH
SVWAVAWH
L$H+L$@
D$h+D$`;
L$L+L$D
D$l+D$d;
D$H;D$@u
D$L;D$Du
A_A^_^[
UAVAWH
A_A^]
A+0E+p
WATAUAVAWH
A_A^A]A\_
@VAVAWH
@A_A^^
WAVAWH
A_A^_
|$ AVH
VWATAVAWH
0A_A^A\_^
WATAUAVAWH
A_A^A]A\_
@SVWATAUAWH
D$8D+D$LA
xA_A]A\_^[
t]A8BItW
{$9{(t
UVWATAUAVAWH
D$(+D$ H
;\$,}2Hc
0A_A^A]A\_^]
SVWAVH
8A^_^[
@UVAVH
effffff
ATAVAWH
0A_A^A\
D$@L;D$Hu
UWATAVAWH
A_A^A\_]
I;>t&L
@SUVWAVH
@A^_^][
@SUVWAUAVAWH
PA_A^A]_^][
SUVWATAVAWH
0A_A^A\_^][
@VWAVH
WAVAWH
A_A^_
WAVAWH
G0+G(A
G4+G,A
VAVAWH
A_A^^
;QltEH
D;Apt0H
;Qtt6H
D9A$tFH
@SUAWH
SUVWATAUAVAWH
HA_A^A]A\_^][
@UVWAVAWH
0A_A^_^]
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
fffffff
WATAUAVAWH
@A_A^A]A\_
H SVWAVH
(A^_^[
ATAVAWH
A_A^A\
t$ WAVAWH
0A_A^_
AUAVAWH
0A_A^A]
L$ USWH
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
D8eoupH
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
0A_A^A]
@SVWATAUAVAWH
L!|$@L!
D$HHcH
A_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAVH
@A^A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
gfffffffH
D8L$Ht
A_A^A]A\_
x AUAVAWH
A_A^A]
@SUVWH
@SUVWH
@SUVWAVH
A^_^][
t$ WAVAWH
LcA<E3
WAVAWH
A_A^_
t$ WATAUAVAWH
D!l$h3
0A_A^A]A\_
l$ VWATAVAWH
T$&@8t$&t9@8r
A81t@@8r
A_A^A\_^
UVWATAUAVAWH
D$DD9T$X
|$h+t$D+
A_A^A]A\_^]
WAVAWH
A_A^_
` AUAVAWH
t$8Hc0I
\$0D9=fd
A_A^A]
VWATAVAWH
A_A^A\_^
\$ UVWATAUAVAWH
D9l$dtXH
HcD$PH;
HcD$PH;
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
USVWATAUAVAWH
8UXt$@
XA_A^A]A\_^[]
UVWATAUAVAWH
D)\$4A;
t$\9D$`t
D8|$0u
D9|$pt
t$PD8|$8t
A_A^A]A\_^]
@UATAUAVAWH
!t$(H!t$ I
A_A^A]A\]
Hct$@H
sYHcL$HH
x ATAVAWH
A_A^A\
H3E H3E
@USVWH
@SUVWATAVAWH
PA_A^A\_^][
@UATAUAVAWH
A_A^A]A\]
VWATAVAWH
A_A^A\_^
D82u&H
D8t$Ht
WATAUAVAWH
0A_A^A]A\_
D9t$htrH
@USVWATAUAVAWH
eHA_A^A]A\_^[]
|$ UATAUAVAWH
A_A^A]A\]
|$ UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@8t$8t
WATAVH
H(H9J(u
user32.dll
UnlockWindowStation
127.0.0.1
getBgColour: bpp %d?
getBgColour
%s: unusual colour = %d
Hextile
ZlibHex
BKbhTb~XBK!;
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
BKbhTb~XBK!;
Bogus message code %d
Sorry, there are legal restrictions on arithmetic coding
ALIGN_TYPE is wrong, please fix
MAX_ALLOC_CHUNK is wrong, please fix
Bogus buffer control mode
Invalid component ID %d in SOS
DCT coefficient out of range
IDCT output block size %d not supported
Bogus Huffman table definition
Bogus input colorspace
Bogus JPEG colorspace
Bogus marker length
Wrong JPEG library version: library is %d, caller expects %d
Sampling factors too large for interleaved scan
Invalid memory pool code %d
Unsupported JPEG data precision %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Invalid progressive parameters at scan script entry %d
Bogus sampling factors
Invalid scan script at entry %d
Improper call to JPEG library in state %d
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Bogus virtual array access
Buffer passed to JPEG library is too small
Suspension not allowed here
CCIR601 sampling not implemented yet
Too many color components: %d, max %d
Unsupported color conversion request
Bogus DAC index %d
Bogus DAC value 0x%x
Bogus DHT index %d
Bogus DQT index %d
Empty JPEG image (DNL not supported)
Read from EMS failed
Write to EMS failed
Didn't expect more than one scan
Input file read error
Output file write error --- out of disk space?
Fractional sampling not implemented yet
Huffman code size table overflow
Missing Huffman code table entry
Maximum supported image dimension is %u pixels
Empty input file
Premature end of input file
Cannot transcode due to multiple use of quantization table %d
Scan script does not transmit all data
Invalid color quantization mode change
Not implemented yet
Requested feature was omitted at compile time
Backing store not supported
Huffman table 0x%02x was not defined
JPEG datastream contains no image
Quantization table 0x%02x was not defined
Not a JPEG file: starts with 0x%02x 0x%02x
Insufficient memory (case %d)
Cannot quantize more than %d color components
Cannot quantize to fewer than %d colors
Cannot quantize to more than %d colors
Invalid JPEG file structure: two SOF markers
Invalid JPEG file structure: missing SOS marker
Unsupported JPEG process: SOF type 0x%02x
Invalid JPEG file structure: two SOI markers
Invalid JPEG file structure: SOS before SOF
Failed to create temporary file %s
Read failed on temporary file
Seek failed on temporary file
Write failed on temporary file --- out of disk space?
Application transferred too few scanlines
Unsupported marker type 0x%02x
Virtual array controller messed up
Image too wide for this implementation
Read from XMS failed
Write to XMS failed
Copyright (C) 1998, Thomas G. Lane
6b 27-Mar-1998
Caution: quantization tables are too coarse for baseline JPEG
Adobe APP14 marker: version %d, flags 0x%04x 0x%04x, transform %d
Unknown APP0 marker (not JFIF), length %u
Unknown APP14 marker (not Adobe), length %u
Define Arithmetic Table 0x%02x: 0x%02x
Define Huffman Table 0x%02x
Define Quantization Table %d precision %d
Define Restart Interval %u
Freed EMS handle %u
Obtained EMS handle %u
End Of Image
%3d %3d %3d %3d %3d %3d %3d %3d
JFIF APP0 marker: version %d.%02d, density %dx%d %d
Warning: thumbnail image size does not match data length %u
JFIF extension marker: type 0x%02x, length %u
with %d x %d thumbnail image
Miscellaneous marker 0x%02x, length %u
Unexpected marker 0x%02x
%4u %4u %4u %4u %4u %4u %4u %4u
Quantizing to %d = %d*%d*%d colors
Quantizing to %d colors
Selected %d colors for quantization
At marker 0x%02x, recovery action %d
Smoothing not supported with nonstandard sampling ratios
Start Of Frame 0x%02x: width=%u, height=%u, components=%d
Component %d: %dhx%dv q=%d
Start of Image
Start Of Scan: %d components
Component %d: dc=%d ac=%d
Ss=%d, Se=%d, Ah=%d, Al=%d
Closed temporary file %s
Opened temporary file %s
JFIF extension marker: JPEG-compressed thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: RGB thumbnail image, length %u
Unrecognized component IDs %d %d %d, assuming YCbCr
Freed XMS handle %u
Obtained XMS handle %u
Unknown Adobe color transform code %d
Inconsistent progression sequence for component %d coefficient %d
Corrupt JPEG data: %u extraneous bytes before marker 0x%02x
Corrupt JPEG data: premature end of data segment
Corrupt JPEG data: bad Huffman code
Warning: unknown JFIF revision number %d.%02d
Premature end of JPEG file
Corrupt JPEG data: found marker 0x%02x instead of RST%d
Invalid SOS parameters for sequential JPEG
Application transferred too many scanlines
JPEGMEM
Qkkbal
- deflate 1.1.4 Copyright 1995-2002 Jean-loup Gailly
need dictionary
inflate 1.1.4 Copyright 1995-2002 Mark Adler
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
WinStationConnectW
winsta.dll
WTSGetActiveConsoleSessionId
kernel32.dll
ProcessIdToSessionId
LockWorkStation
DISPLAY
EnumDisplayDevicesA
User32.DLL
SYSTEM\CurrentControlSet\Hardware Profiles\Current\System\CurrentControlSet\Services
DEVICE0
Screen.ForcedBpp
Pointer.Enabled
Cap.DfbBackingMode
Order.BltCopyBits.Enabled
Attach.ToDesktop
ChangeDisplaySettingsExA
RFB %03d.%03d
Authentication failed
Cannot impersonate logged on user
Path length exceeds 255 bytes
Cannot open file, perhaps it is absent or is a directory
Path length exceeds MAX_PATH value
Could not create file
Server does not support data compression on upload
Error writing file data
<unknown>
[unknown]
VNCHooks.CopyRect.WindowPos
WinVNC desktop sink
generic
unknown error
iostream
iostream stream error
system
WinVNC.Update.DrawRect
WinVNC.Update.CopyRect
WinVNC.Update.Mouse
WinVNC.Local.Keyboard
WinVNC.Local.Mouse
WindowsScreenSaverClass
Screen-saver
WinVNC
ConsoleWindowClass
string too long
invalid string position
WinVNC_Win32_Instance_Mutex
map/set<T> too long
list<T> too long
localhost
MonitorFromPoint
GetMonitorInfoA
Default
Winlogon
SAS window
SAS window class
<unavailable>
bad allocation
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
_hypot
CorExitProcess
RoInitialize
RoUninitialize
Unknown exception
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
(null)
`h````
xpxxxx
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
_nextafter
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
`h`hhh
xppwpp
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#SNAN
1#QNAN
winvnc.x64.dll
?ReflectiveLoader@@YA_KPEAX@Z
WSADuplicateSocketA
WSASocketA
WS2_32.dll
FreeLibrary
GetProcAddress
GetCurrentProcessId
ExitThread
WaitForSingleObject
CreateEventA
LoadLibraryA
GetCurrentProcess
GetCurrentThread
GetCurrentThreadId
SetThreadPriority
GetLastError
ResumeThread
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
ReleaseSemaphore
CloseHandle
DuplicateHandle
GetSystemTime
TlsAlloc
TlsGetValue
TlsSetValue
CreateSemaphoreA
UnmapViewOfFile
SetErrorMode
WriteFile
FindClose
SetFileTime
GetLogicalDriveStringsA
CreateDirectoryA
CreateFileA
DeleteFileA
FindFirstFileA
FindNextFileA
GetComputerNameA
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalDeleteAtom
SystemTimeToFileTime
GlobalAddAtomA
GetVersionExA
SetEvent
KERNEL32.dll
OpenInputDesktop
GetProcessWindowStation
GetIconInfo
SetRect
ReleaseDC
SetThreadDesktop
CloseDesktop
GetThreadDesktop
EnumDisplaySettingsA
GetKeyboardState
keybd_event
mouse_event
GetSystemMetrics
GetWindowRect
GetCursorPos
IntersectRect
IsRectEmpty
GetDesktopWindow
OpenDesktopA
EnumDesktopWindows
RegisterWindowMessageA
DispatchMessageA
PeekMessageA
SendMessageA
PostMessageA
WaitMessage
DefWindowProcA
PostQuitMessage
RegisterClassExA
CreateWindowExA
DestroyWindow
IsWindowVisible
OpenClipboard
CloseClipboard
GetClipboardOwner
SetClipboardViewer
ChangeClipboardChain
SetClipboardData
GetClipboardData
EmptyClipboard
SetTimer
KillTimer
GetForegroundWindow
SetPropA
GetPropA
RemovePropA
WindowFromPoint
EqualRect
GetWindowLongA
GetWindowLongPtrA
SetWindowLongPtrA
FindWindowA
EnumWindows
GetClassNameA
LoadCursorA
DrawIconEx
ChangeDisplaySettingsA
SystemParametersInfoA
GetAsyncKeyState
VkKeyScanA
MapVirtualKeyA
ExitWindowsEx
MessageBeep
GetUserObjectInformationA
USER32.dll
DeleteObject
GetBitmapBits
GetObjectA
GetSystemPaletteEntries
CreateDCA
DeleteDC
ExtEscape
BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
CreatePalette
GetDeviceCaps
GetDIBits
GetStockObject
RealizePalette
SelectObject
SelectPalette
CreateDIBSection
GdiFlush
CombineRgn
CreateRectRgn
CreateRectRgnIndirect
GetRegionData
GDI32.dll
RegCloseKey
RegCreateKeyA
RegDeleteValueA
RegSetValueExA
RevertToSelf
GetUserNameA
ImpersonateLoggedOnUser
ADVAPI32.dll
RtlLookupFunctionEntry
RtlUnwindEx
EncodePointer
DecodePointer
ExitProcess
GetModuleHandleExW
MultiByteToWideChar
WideCharToMultiByte
GetSystemTimeAsFileTime
HeapFree
HeapAlloc
CreateThread
LoadLibraryExW
RtlPcToFileHeader
RaiseException
GetCommandLineA
SetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
TerminateProcess
TlsFree
GetStartupInfoW
GetModuleHandleW
GetStdHandle
GetModuleFileNameW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetFileType
GetProcessHeap
HeapSize
FlushFileBuffers
GetConsoleCP
GetConsoleMode
ReadFile
ReadConsoleW
GetModuleFileNameA
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
OutputDebugStringW
HeapReAlloc
CompareStringW
LCMapStringW
GetStringTypeW
SetStdHandle
SetFilePointerEx
WriteConsoleW
SetEnvironmentVariableA
CreateFileW
VNC AAAABBBBCCCC
;3+#>6.&
'2, /+0&7!4-)1#
Mirage Driver
DemoForge Mirage Driver
dfmirage
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVvncEncodeCoRRE@@
.?AVvncEncoder@@
.?AVvncEncodeHexT@@
.?AVvncEncodeRRE@@
.?AVvncEncodeTight@@
.?AVvncEncodeZlib@@
.?AVvncEncodeZlibHex@@
.?AVomni_thread_fatal@@
.?AVomni_thread_invalid@@
.?AVomni_thread@@
.?AV_internal_omni_thread_dummy@@
.?AVFileTransferItemInfo@@
.?AVvncClient@@
.?AVvncClientThread@@
.?AVvncDesktopThread@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVvncServer@@
.?AVvncCorbaConnect@@
.?AVvncSockConnect@@
.?AVvncSockConnectThread@@
.?AVVSocket@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
@@@@@@@@
mscoree.dll
combase.dll
kernel32.dll
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
(null)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
USER32.DLL
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
((((( H
((((( H
CONOUT$
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Hacktool.Win32.Meterpreter.3!c
Elastic Windows.Generic.Threat
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.NetLoader.fh
ALYac Misc.HackTool.Meterpreter
Cylance Unsafe
Zillya Tool.Meterpreter.Win64.462
Sangfor Riskware.Win32.Inject.Vijo
CrowdStrike win/grayware_confidence_100% (W)
Alibaba HackTool:Win32/Inject.e59970a2
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
huorong HackTool/VNCDll.b
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Trojan Horse
tehtris Clean
ESET-NOD32 a variant of Win64/Riskware.Meterpreter.H
APEX Clean
Avast Win64:Malware-gen
Cynet Malicious (score: 99)
Kaspersky HEUR:HackTool.Win32.Inject.heur
BitDefender Gen:Variant.Tedy.394289
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Tedy.394289
Tencent Malware.Win32.Gencirc.11b10f1b
Sophos Harmony Loader (PUA)
F-Secure PrivacyRisk.SPR/Injector.agw
DrWeb Tool.Inject.79
VIPRE Gen:Variant.Tedy.394289
TrendMicro PUA.Win64.WINVNC.A
McAfeeD ti!13FEAA32E4B0
Trapmine Clean
CTX dll.hacktool.inject
Emsisoft Gen:Variant.Tedy.394289 (B)
Ikarus PUA.RiskWare.Meterpreter
FireEye Gen:Variant.Tedy.394289
Jiangmin HackTool.Inject.ciu
Webroot W32.Malware.Gen
Varist W64/ABApplication.QKNU-2496
Avira SPR/Injector.agw
Fortinet Riskware/Inject
Antiy-AVL HackTool/Win32.Inject
Kingsoft Win32.HackTool.Inject.heur
Gridinsoft Trojan.Win64.Agent.dg
Xcitium Malware@#262v94zt9ji48
Arcabit Trojan.Tedy.D60431
SUPERAntiSpyware Clean
ZoneAlarm HEUR:HackTool.Win32.Inject.heur
Microsoft Trojan:Win32/CobaltStrike!MTB
Google Detected
AhnLab-V3 Malware/Win.Inject.R635405
Acronis Clean
McAfee RDN/Generic PUP.z
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2936209353
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall PUA.Win64.WINVNC.A
Rising Trojan.CobaltStrike!8.EDF2 (TFE:5:iw1lVS3f5fU)
Yandex Trojan.Igent.bUAavR.18
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.10455307.susgen
GData Gen:Variant.Tedy.394289
AVG Win64:Malware-gen
DeepInstinct MALICIOUS
alibabacloud RiskWare:Win/Meterpreter
No IRMA results available.