Static | ZeroBOX

PE Compile Time

2024-12-11 15:12:20

PE Imphash

ef010df142cc83b7965c91c2e1814b80

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003c096 0x0003c200 6.68142547051
.rdata 0x0003e000 0x00013bf0 0x00013c00 5.65032542088
.data 0x00052000 0x00002428 0x00001200 3.5272537048
.rsrc 0x00055000 0x00000420 0x00000600 2.56114641951
.reloc 0x00056000 0x00002c94 0x00002e00 6.49673923547

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00055060 0x000003c0 LANG_KOREAN SUBLANG_KOREAN data

Imports

Library KERNEL32.dll:
0x1003e048 GetProcessHeap
0x1003e04c FreeLibrary
0x1003e050 CreateProcessA
0x1003e054 MultiByteToWideChar
0x1003e058 GetModuleHandleA
0x1003e05c WideCharToMultiByte
0x1003e064 GetLastError
0x1003e068 RaiseException
0x1003e06c DecodePointer
0x1003e070 DeleteCriticalSection
0x1003e074 ReadFile
0x1003e078 WriteFile
0x1003e07c SetFilePointer
0x1003e080 UnmapViewOfFile
0x1003e084 CreateFileA
0x1003e088 FileTimeToSystemTime
0x1003e08c CloseHandle
0x1003e090 GetLocalTime
0x1003e094 CreateFileMappingA
0x1003e098 SystemTimeToFileTime
0x1003e09c MapViewOfFile
0x1003e0a0 FindNextFileA
0x1003e0a4 FindClose
0x1003e0a8 DeleteFileA
0x1003e0ac FindFirstFileW
0x1003e0b0 FindNextFileW
0x1003e0b4 CreateMutexA
0x1003e0b8 WaitForSingleObject
0x1003e0bc GetFileAttributesW
0x1003e0c0 GetCurrentThreadId
0x1003e0c4 SuspendThread
0x1003e0c8 Sleep
0x1003e0cc GetTempPathA
0x1003e0d0 GetFileAttributesA
0x1003e0d4 CreateThread
0x1003e0d8 SetFileAttributesA
0x1003e0dc ExitProcess
0x1003e0e0 IsWow64Process
0x1003e0e4 GetDriveTypeW
0x1003e0e8 OpenThread
0x1003e0f4 GetEnvironmentStringsW
0x1003e0f8 GetCommandLineW
0x1003e0fc GetCommandLineA
0x1003e100 GetProcAddress
0x1003e104 HeapAlloc
0x1003e108 LoadLibraryA
0x1003e10c SetLastError
0x1003e110 HeapFree
0x1003e114 GetModuleFileNameA
0x1003e118 GetVolumeInformationA
0x1003e11c GetTickCount
0x1003e120 GetLogicalDrives
0x1003e124 GetOEMCP
0x1003e128 IsValidCodePage
0x1003e12c FindFirstFileExA
0x1003e130 HeapSize
0x1003e134 EnumSystemLocalesW
0x1003e138 GetUserDefaultLCID
0x1003e13c IsValidLocale
0x1003e140 WriteConsoleW
0x1003e144 FlushFileBuffers
0x1003e148 GetTimeZoneInformation
0x1003e14c GetConsoleCP
0x1003e150 SetStdHandle
0x1003e154 ReadConsoleW
0x1003e158 GetConsoleMode
0x1003e15c SetFilePointerEx
0x1003e160 GetStdHandle
0x1003e164 HeapReAlloc
0x1003e168 GetACP
0x1003e16c GetModuleHandleExW
0x1003e174 SetFileTime
0x1003e178 EnterCriticalSection
0x1003e17c LeaveCriticalSection
0x1003e184 SetEvent
0x1003e188 ResetEvent
0x1003e18c WaitForSingleObjectEx
0x1003e190 CreateEventW
0x1003e194 GetModuleHandleW
0x1003e198 IsDebuggerPresent
0x1003e1a4 GetStartupInfoW
0x1003e1b0 GetCurrentProcessId
0x1003e1b8 InitializeSListHead
0x1003e1bc GetCurrentProcess
0x1003e1c0 TerminateProcess
0x1003e1c4 GetStringTypeW
0x1003e1c8 EncodePointer
0x1003e1cc TlsAlloc
0x1003e1d0 TlsGetValue
0x1003e1d4 TlsSetValue
0x1003e1d8 TlsFree
0x1003e1dc CompareStringW
0x1003e1e0 LCMapStringW
0x1003e1e4 GetLocaleInfoW
0x1003e1e8 GetCPInfo
0x1003e1ec OutputDebugStringW
0x1003e1f0 RtlUnwind
0x1003e1f4 InterlockedFlushSList
0x1003e1f8 LoadLibraryExW
0x1003e1fc SetEndOfFile
0x1003e200 CreateDirectoryW
0x1003e204 CreateFileW
0x1003e208 GetFileType
Library USER32.dll:
0x1003e21c GetMonitorInfoA
0x1003e220 GetDesktopWindow
0x1003e224 EnumDisplayMonitors
0x1003e228 GetDC
Library GDI32.dll:
0x1003e01c BitBlt
0x1003e020 SaveDC
0x1003e024 SelectObject
0x1003e028 CreateDIBSection
0x1003e02c CreateCompatibleDC
0x1003e030 GetDeviceCaps
0x1003e034 DeleteDC
0x1003e038 RestoreDC
0x1003e03c DeleteObject
0x1003e040 CreateDCA
Library ADVAPI32.dll:
0x1003e000 RegCloseKey
0x1003e004 RegOpenKeyA
0x1003e008 RegQueryValueExA
0x1003e00c RegSetValueExA
0x1003e010 RegOpenKeyExA
0x1003e014 RegCreateKeyA
Library SHELL32.dll:
0x1003e210 SHCreateDirectoryExA
0x1003e214 SHGetFolderPathA
Library ole32.dll:
0x1003e298 CreateStreamOnHGlobal
Library WINHTTP.dll:
0x1003e238 WinHttpReceiveResponse
0x1003e23c WinHttpOpen
0x1003e240 WinHttpQueryHeaders
0x1003e244 WinHttpReadData
0x1003e248 WinHttpOpenRequest
0x1003e24c WinHttpSetOption
0x1003e250 WinHttpCloseHandle
0x1003e254 WinHttpSendRequest
0x1003e258 WinHttpSetCredentials
0x1003e25c WinHttpConnect
Library ntdll.dll:
0x1003e290 RtlGetVersion
Library gdiplus.dll:
0x1003e264 GdiplusStartup
0x1003e268 GdiplusShutdown
0x1003e26c GdipGetImageEncoders
0x1003e270 GdipCloneImage
0x1003e274 GdipSaveImageToStream
0x1003e27c GdipFree
0x1003e280 GdipDisposeImage
0x1003e288 GdipAlloc

Exports

Ordinal Address Name
1 0x100133e0 GetFileVersionInfoA
2 0x100133f0 GetFileVersionInfoByHandle
3 0x10013400 GetFileVersionInfoExA
4 0x10013410 GetFileVersionInfoExW
5 0x10013420 GetFileVersionInfoSizeA
6 0x10013430 GetFileVersionInfoSizeExA
7 0x10013440 GetFileVersionInfoSizeExW
8 0x10013450 GetFileVersionInfoSizeW
9 0x10013460 GetFileVersionInfoW
10 0x10013470 VerFindFileA
11 0x10013480 VerFindFileW
12 0x10013490 VerInstallFileA
13 0x100134a0 VerInstallFileW
14 0x100134b0 VerLanguageNameA
15 0x100134c0 VerLanguageNameW
16 0x100134d0 VerQueryValueA
17 0x100134e0 VerQueryValueW
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
<-t6,0<
M0j9hd
u)j*h\
^$_^[]
p 9X$|
QQSVWd
URPQQh=
;t$,v-
UQPXY]Y[
F4_^[]
^$+^8+
PVSQSWV
u0jAXf;
u0jAXf;
PPPPPPPP
v!j"X_^[
QSSSSj
jYjf
tyPVj@W
_tcPVj@
u#j,Xf;
Wj0XPS
(HXt9f
<at<rt
>=upF8
QQSWj0j@
SSPQSS
u kE$<
SSSPSW
u-PSSW
SSVWh
f9:t!V
PPPPPWS
PP9E u:PPVWP
u^9^\t/
VX9^`tT
;N\u\W
u2Vj@h
9C`u99C\t4
9C`u5Wj
PPPPPPPP
SleepConditionVariableCS
WakeAllConditionVariable
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
UTF-16LEUNICODE
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetDateFormatEx
GetLocaleInfoEx
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
456789:;<=
 !"#$%&'()*+,-./0123
Qkkbal
Unknown exception
bad array new length
string too long
invalid string position
file too large
unknown error
Qkkbal
WinHttpOpen fails!
WinHttpConnect fails!
Error in WinHttpQueryOption WINHTTP_OPTION_SECURITY_FLAGS
WinHttpSetCredentials fails!
WinHttpSendRequest fails!
WinHttpReceiveResponse fails!
WinHttpQueryHeaders fails!
Error in WinHttpQueryDataAvailable:
Error in WinHttpReadData:
WinHttpQueryAuthSchemes in case 401 fails!
WinHttpSetCredentials in case 401 fails!
WinHttpQueryAuthSchemes in case 407 fails!
http://
https://
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
version.dll
GetFileVersionInfoA
GetFileVersionInfoByHandle
GetFileVersionInfoExA
GetFileVersionInfoExW
GetFileVersionInfoSizeA
GetFileVersionInfoSizeExA
GetFileVersionInfoSizeExW
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerFindFileA
VerFindFileW
VerInstallFileA
VerInstallFileW
VerLanguageNameA
VerLanguageNameW
VerQueryValueA
VerQueryValueW
vector too long
iostream stream error
doYeLlLawlw_\
)+ !&-h&)%-rh
Urvere7$#PAT%C9'i|iC(viumE*nqtm*
:;<=>?@ABC5
xe~mvc~xy-7
n:wlrq=#irup0gdwd>\Fd~dH|`t^`tLnfA{pvuA'mvyt4kh{hB!rBSDDORINU
KQDF'T.PQC:/F.#A"':Gyl6-obxcil
t0b]H({GN\_IZMtnG]_ARR//qRGSMkukGso{Ul?
V#00rSHTNlvlHtp|VjKLMNOPQRSTUVWXYH55wXMYSq{qMyu
Nbcyhcy Yt}h7-`o{CemNkdVjCcCn|cp|DfnOleWkDdDo}du
IksTqj\pIiIt
ixw{q|qwvB(nwzu5lxayd}l
Frqwhqw0Glvsrvl}c`t\MSa];~m
;ymZ[\]^_`abcdklmno
Jvu{lu{4Kpzwvzp~Xr~FhpQngYmFfFqa&t]c{vqebufs]Vq
22tUJVPnxnJvro{y;mp~t|n~z>E;uw\zlyPup{TwySvnv'uhtlD)th
Kv~usv#qdph@%dxwrGhohw4Mrjsvqexmsr2x|x!Tpguxbsf]Gpvxj{
Kwv|mv|5Lq{pqrstuvwxyz{|}~
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
DllProxy.dll
GetFileVersionInfoA
GetFileVersionInfoByHandle
GetFileVersionInfoExA
GetFileVersionInfoExW
GetFileVersionInfoSizeA
GetFileVersionInfoSizeExA
GetFileVersionInfoSizeExW
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerFindFileA
VerFindFileW
VerInstallFileA
VerInstallFileW
VerLanguageNameA
VerLanguageNameW
VerQueryValueA
VerQueryValueW
GetLogicalDrives
GetVolumeInformationA
GetModuleFileNameA
HeapFree
SetLastError
LoadLibraryA
HeapAlloc
GetProcAddress
GetProcessHeap
FreeLibrary
CreateProcessA
MultiByteToWideChar
GetModuleHandleA
WideCharToMultiByte
InitializeCriticalSectionEx
GetLastError
RaiseException
DecodePointer
DeleteCriticalSection
ReadFile
WriteFile
SetFilePointer
UnmapViewOfFile
CreateFileA
FileTimeToSystemTime
CloseHandle
GetLocalTime
CreateFileMappingA
SystemTimeToFileTime
MapViewOfFile
GetTickCount
FindNextFileA
FindClose
DeleteFileA
FindFirstFileW
FindNextFileW
CreateMutexA
WaitForSingleObject
GetFileAttributesW
GetCurrentThreadId
SuspendThread
GetTempPathA
GetFileAttributesA
CreateThread
SetFileAttributesA
ExitProcess
IsWow64Process
GetDriveTypeW
OpenThread
KERNEL32.dll
GetDesktopWindow
GetMonitorInfoA
EnumDisplayMonitors
USER32.dll
CreateDCA
DeleteObject
RestoreDC
DeleteDC
GetDeviceCaps
CreateCompatibleDC
CreateDIBSection
SelectObject
SaveDC
BitBlt
GDI32.dll
RegOpenKeyExA
RegSetValueExA
RegQueryValueExA
RegOpenKeyA
RegCloseKey
RegCreateKeyA
ADVAPI32.dll
SHGetFolderPathA
SHCreateDirectoryExA
SHELL32.dll
CreateStreamOnHGlobal
ole32.dll
WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSetCredentials
WinHttpSendRequest
WinHttpQueryAuthSchemes
WinHttpCloseHandle
WinHttpSetOption
WinHttpOpenRequest
WinHttpReadData
WinHttpQueryHeaders
WinHttpOpen
WinHttpReceiveResponse
WINHTTP.dll
RtlGetVersion
ntdll.dll
GdipSaveImageToStream
GdipGetImageEncodersSize
GdipFree
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipAlloc
GdipCloneImage
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetModuleHandleW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
TerminateProcess
GetStringTypeW
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CompareStringW
LCMapStringW
GetLocaleInfoW
GetCPInfo
OutputDebugStringW
RtlUnwind
InterlockedFlushSList
LoadLibraryExW
SetEndOfFile
CreateDirectoryW
CreateFileW
GetFileType
SetFileTime
TzSpecificLocalTimeToSystemTime
GetModuleHandleExW
GetACP
HeapReAlloc
GetStdHandle
SetFilePointerEx
GetConsoleMode
ReadConsoleW
SetStdHandle
GetConsoleCP
GetTimeZoneInformation
FlushFileBuffers
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapSize
FindFirstFileExA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AV_Locimp@locale@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVCAtlException@ATL@@
.?AV_Iostream_error_category2@std@@
.?AV?$numpunct@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVbad_cast@std@@
.?AV?$numpunct@_W@std@@
.?AUctype_base@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AVBitmapC@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV_System_error@std@@
.?AV?$ctype@_W@std@@
.?AVImageC@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$basic_ostringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AVsystem_error@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
0#1-1A1V1w1
2.2I2S2_2k2w2
2U3b3o3}3
8#8?8_8x8
9&959G<
0L1g1q14&4
8<8@8D8V?
6(6;6Q6q6
; ;$;(;,;0;4;8;<;@;D;H;L;P;
;i<n<{<
=<=P=\=i=w=
G0V0`0o0{0
1+2>2V2
8#888N8g8
162X2o=
!646G6Z6m6
3!4/484@4
=(=-=7===D=J=S=d=}=
>>>S>n>
112;2E2I2X2y2
4S4f4}4
6L6B7;9g9
1&161[1a1s1
5"5H5P5V5#696L6n6
;:;H;N;X;^;v;
909B9Q9e:y:
: ;4;F;
=C=N=Y=d=o=
;S<Z<0===
:r<9=l=
9.;*<<<N<%?
2 2'2-22292?2D2K2Q2V2]2c2h2o2u2z2
3#3)3.353;3@3J3O3Y3^3j3
4!4&41464A4F4Q4V4a4f4q4v4
:0;F>k>s>
:4:9:O:V:\:a:o:
6A6G6]6d6j6o6}6
697g7l7
:f:q;O=
,1q1{1f5
;6;k;q;
292V2\2a2g2r2x2
3"3,3;3C3O3`3g3
4)5I5z5
626G6N6T6f6p6
9"9;9@9M9
=!=,=6=
=1>;>D>M>b>k>
060>0C0V0j0o0
1 1'1.151=1E1M1Y1b1g1m1w1
2%2,232:2B2J2R2]2b2h2r2|2
3#3B3X3
6'6V6n6
6V7g7n7v7
9:9R9m9x9
?4?B?N?[?p?x?~?
2"2)2.242:2?2E2K2P2V2\2a2g2m2r2x2~2
3"3(3-33393>3D3J3O3U3[3`3e3l3q3w3}3
4!4'4,42484=4C4I4N4T4Z4_4e4k4p4v4|4
5>6[6j6s6y6
=3>g>o>
0D1W1u1
113h3o3t3x3|3
4 4$4(4,4
:[:`:d:h:l:
0P;T;X;\;`;d;h;l;p;t;x;|;
<2<@<F<a<
=-=>=J=
5*6B6H6o638
;<;X;x;
<$=8=I=U=d=|=
> >->6>;>@>[>e>q>v>{>
353N3<4F4S4
485[5b5
>&>Z>b>
>\?`?d?h?l?p?t?x?|?
>5=7E7|7
3P3W3c6
8"8M8T8
030S0e0
1L2P2T2X2\2`2d2h2
2h3l3p3t3x3|3
1f2)3V3
8 9:9?9
4C4V4.5^5x5
<?=$>=?J?f?
051K1o1
2272<2H2M2a2(3/3A3J3
3)4r4|4
5;5F537=7Y7`7
879O9|9
>C>Z>e>m>x>~>
?=?Z?~?
050b0i0t0
0$2g4g5
3"4<4S4Z4w4
5 5G5\5l5y5
6!6.6H6O6Y6{6
0!030>0
9"949r9x9
3"4,464
6!6-696G6W6l6
7/777B7~7
0>0J0g0
182\2e3
5\6d6-7
3M3\3j3
3&4-4o4v4
5)5X5d5
=!=T=q=
d0%222\2f2
6&686C6K6S6[6d6m6u6
878<8B8M8W8n8v8
;";3;:;h;p;
1 181=1B1R1W1\1l1q1v1
2"2'2,2<2A2F2k2
2*323j3
5 5%5*5E5O5k5v5{5
6"6'6,6J6T6p6
7;7M7o7z7
8 8E8v8
6!606:6G6Q6a6
9):2:6:<:@:F:J:T:g:p:
> >Q>_>k>|>
0+121<1K1o1
5"5:5G5S5[5s5
;3<;<l<u<
=!=-=C=L=U=
.0?0o0w0
1(111<1
8H8e8y8
1-2X2j2|2
303o3W6
707B7T7
7T9[9c9k9s9-=A?
=@>i>~>
1;40585o5v5v8
;"<C<J<`<v<
4"4+4m4
:#:0:B:
:';<;E;N;
<)</<;<Z<`<~<
=1>=>Q>]>i>
??/?;?J?
1V2[2m2
+0P0a0t0
0(1Z1s1
2#232|2
>,>I>b>m>
?"?-?\?f?p?
0&000A0Q0[0e0o0y0
4 4$4(4,4044484<4@4D4H4L4
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9\?`?d?h?l?p?t?x?|?
84<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:
t0x0|0
0 0$0(0,0
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>
7$7,747<7D7L7T7\7d7`8d8h8l8
4 4,484D4P4\4h4t4
5(545@5L5X5d5p5|5
6$606<6H6T6`6l6x6
7$707<7H7T7`7l7x7
748<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?
P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484p7t7x7|7
<p<t<x<|<
=(=,=<=@=D=H=P=h=x=|=
> >0>4>8>@>X>h>l>p>t>x>
? ?$?<?@?D?X?\?`?x?
0(0,040L0P0h0l0p0t0|0
10141L1P1T1\1t1x1
2 2$2,2024282@2X2h2x2
343D3T3d3h3l3p3x3
4(4,4<4@4X4\4t4x4
5$5(5@5D5\5l5p5x5|5
6 6$6(6,60646H6L6\6`6x6
7 7$74787H7L7\7`7d7h7l7p7x7
8(8,808H8L8d8h8
=0=8=@=H=d=t=
>,>4><>D>L>X>x>
?,?8?@?X?|?
,0<0H0h0p0
1$1D1L1T1\1d1p1x1
2 2,2L2T2\2d2l2x2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4X4|4
5,545<5D5L5T5\5d5l5t5|5
6$6,6D6P6p6
7$7<7D7L7d7l7
8(8H8P8X8`8l8
8(989H9l9t9|9
:$:<:D:X:h:t:
;8;@;L;l;t;
<$<,<4<<<D<L<T<\<d<l<t<
=(=0=8=D=L=d=l=
> >(>4>T>\>d>l>x>
?4?<?T?\?p?
04080X0t0x0
1 1(1014181@1T1\1d1l1p1t1|1
2 2$2@2H2L2\2
383X3x3
484X4x4
54585X5x5
686X6x6
787X7x7
888X8x8
9 9(90989L9T9x9
: :4:<:P:
h0l0p0t0x0|0
1 101@1P1h1t1x1|1
4p9t9x9
:(:H:l:
0(0D0d0
jjjjjjj
api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
ERROR : Unable to initialize critical section in CAtlBaseModule
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
(null)
mscoree.dll
((((( H
(
((((( H
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UTF-16LEUNICODE
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
#+3;CScs
Windows
System Volume Information
Recovery
Drive:
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Microsoft Corporation
FileDescription
Version Checking and File Installation Libraries
FileVersion
6.2.19041.3636 (WinBuild.160101.0800)
InternalName
version
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
VERSION.DLL
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.3636
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Dropper.fh
ALYac Trojan.Agent.177346A
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.V4em
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Trojan:Win32/DllHijack.ce653ea2
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.DllHijack.sjl
BitDefender Clean
NANO-Antivirus Clean
ViRobot Trojan.Win.S.Agent.346112
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Trojan.TR/AVI.PredThief.xurmv
DrWeb Trojan.Siggen30.26889
VIPRE Clean
TrendMicro Clean
McAfeeD ti!C43507B6F2C2
Trapmine Clean
CTX Clean
Emsisoft Clean
Ikarus Trojan-Spy.PredThief
FireEye Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/AVI.PredThief.xurmv
Fortinet Malicious_Behavior.SB
Antiy-AVL Trojan/Win32.Agent
Kingsoft Win32.Trojan.DllHijack.sjl
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Clean
Google Detected
AhnLab-V3 Downloader/Win.Agent.R684503
Acronis Clean
McAfee Artemis!66E8096B9B06
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Win32.Trojan.Agent.XEGT42
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.