Static | ZeroBOX

PE Compile Time

2020-02-19 01:11:23

PDB Path

c:\Colorabout\ForLarge\Forwardnext\past.pdb

PE Imphash

65a443b7932fd9eb2ea467f5b70b9704

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00042664 0x00042800 6.7484722091
.rdata 0x00044000 0x00016e82 0x00017000 5.87277796854
.data 0x0005b000 0x0005d5dc 0x00002c00 5.14409014452
.rsrc 0x000b9000 0x00000640 0x00000800 2.79675531602
.reloc 0x000ba000 0x0000269c 0x00002800 6.57410170309

Resources

Name Offset Size Language Sub-language File type
RT_STRING 0x000b94b0 0x0000018a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b94b0 0x0000018a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000b90d0 0x000002a8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x1044000 VirtualProtect
0x1044004 VirtualFree
0x1044008 VirtualAlloc
0x104400c Sleep
0x1044010 DeleteFileA
0x1044014 CloseHandle
0x1044018 ResetEvent
0x104401c GetWindowsDirectoryA
0x1044020 GetStartupInfoA
0x1044024 CreateProcessA
0x1044028 CreateDirectoryA
0x104402c CreateSemaphoreA
0x1044030 GetTickCount
0x1044034 HeapSize
0x1044038 SetStdHandle
0x104403c GetProcessHeap
0x1044048 GetCommandLineW
0x104404c GetCommandLineA
0x1044050 GetOEMCP
0x1044054 GetACP
0x1044058 IsValidCodePage
0x104405c FindNextFileW
0x1044060 FindFirstFileExW
0x1044064 FindClose
0x1044068 HeapReAlloc
0x104406c ReadConsoleW
0x1044070 SetFilePointerEx
0x1044074 GetFileSizeEx
0x1044078 ReadFile
0x104407c GetConsoleMode
0x1044080 GetConsoleCP
0x1044084 FlushFileBuffers
0x1044088 EnumSystemLocalesW
0x104408c GetUserDefaultLCID
0x1044090 IsValidLocale
0x1044094 OutputDebugStringW
0x1044098 WriteFile
0x104409c HeapFree
0x10440a0 HeapAlloc
0x10440a4 ExitProcess
0x10440a8 WriteConsoleW
0x10440ac GetModuleHandleExW
0x10440b0 GetModuleFileNameW
0x10440b4 GetFileType
0x10440b8 WideCharToMultiByte
0x10440bc EnterCriticalSection
0x10440c0 LeaveCriticalSection
0x10440c4 DeleteCriticalSection
0x10440c8 EncodePointer
0x10440cc DecodePointer
0x10440d0 MultiByteToWideChar
0x10440d4 SetLastError
0x10440dc TlsAlloc
0x10440e0 TlsGetValue
0x10440e4 TlsSetValue
0x10440e8 TlsFree
0x10440f0 GetModuleHandleW
0x10440f4 GetProcAddress
0x10440f8 LCMapStringW
0x10440fc GetLocaleInfoW
0x1044100 GetStringTypeW
0x1044104 GetCPInfo
0x1044110 GetCurrentProcess
0x1044114 TerminateProcess
0x1044120 GetCurrentProcessId
0x1044124 GetCurrentThreadId
0x1044128 InitializeSListHead
0x104412c IsDebuggerPresent
0x1044130 GetStartupInfoW
0x1044134 RtlUnwind
0x1044138 RaiseException
0x104413c InterlockedFlushSList
0x1044140 GetLastError
0x1044144 FreeLibrary
0x1044148 LoadLibraryExW
0x104414c GetStdHandle
0x1044150 CreateFileW
Library SETUPAPI.dll:
0x1044168 SetupGetStringFieldA
0x1044170 SetupGetSourceInfoA
0x1044174 SetupAddToSourceListA
0x1044178 SetupIterateCabinetA
0x104417c SetupGetTargetPathA
0x1044184 SetupGetIntField
0x1044188 SetupCopyOEMInfA
0x104418c SetupQueueRenameA
0x1044194 SetupCloseLog
0x1044198 SetupFreeSourceListA
0x10441a0 SetupGetFieldCount
0x10441a4 SetupTerminateFileLog
0x10441ac SetupQueueCopyA
0x10441b0 SetupGetLineCountA
0x10441b8 SetupOpenLog
0x10441bc SetupPromptReboot
0x10441cc SetupSetDirectoryIdA
0x10441d0 SetupGetLineByIndexA
0x10441d4 SetupOpenMasterInf
0x10441d8 SetupGetLineTextA
0x10441dc SetupLogErrorA
0x10441e0 SetupQuerySourceListA
0x10441e8 SetupSetSourceListA
Library RASAPI32.dll:
0x1044158 RasHangUpA
0x104415c RasEnumConnectionsA
0x1044160 RasGetConnectStatusA

Exports

Ordinal Address Name
1 0x10220d0 Thisview
!This program cannot be run in DOS mode.
[KnM4Jo
[KnM4Oo
[KnM4Ho
[KnM4No
[Jn1[KnM4Ko
[KnM4Bo
[KnM4Io
[KnRich
`.rdata
@.data
@.reloc
;_^][Y
l$$_^[
tG9uCj
GL9_8u
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
PPPPPPPP
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
V2jx_f;
V2jx_f;
F2jgYf;
sAj5X+
yj#RWV
ARPRQh
Wj0XPV
SPjdVQ
SWt@jU
_tqPVj@
zSSSSj
D8(Ht'
PPPPPWS
PP9E u:PPVWP
f9:t!V
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
QQSVj8j@
PPPPPPPP
r#f)=j
r&f)=j
D$(+D$
L$ PVQ
T$$PVR
T$(PWQR
Y}T%wL
{G7T:r
RQ7Ns;
H,@UJB-
kDRDLk
mHQDDHT
%u<,@
l>`"~Y
MIW{%{
%Qhhqe
GF1RITT+{&
9NUT}(
>|[lm.
HHH"\O
!64_KO2
R[s >h
C7f?Ik
.U?W:d!
(CW9Flu
(x7ZzF
7.<C;p
%WnY_w
W|G;TL~
z>OLQ`
WL$ u\
IBHRPsH
RJoH}u
ibfx]
0DHWUZn
(+*K%n<
:B +b<
8M0$#T
NjO&!|R
pbSf;
@WNc8/
;^F-`a
HHHDP;c(DX
lM._WH
-<h,4R
ELjLWW
Es3jc
(O$HIH
^[L%JM
.Z3V{>b
|!~bk&A
]IK"-
HHOtt^
H\$DP$
mXLng:
3lL$HH
XCDLLM
4XA3&L
Z=P[AO
0c7#e#
HMk{3<
JDHHH}
G$b0c*
Ms}bhA
AaVu.e
D$eq$W
HQp-\P
8-jl/kZ2
U$tc`LH
FI@V4K
N^v-~w
,:m!7q
r$;Hu HW
<#5L4Mt
nC;QHU
U>uCFj
gjW-YK4v
5J?vpa
(8'pwQC
qP$o!qj[h
rs"_tJ
$+$s$[L
5]$jLrD
fER(SI
mAr2xR
HH dGA
BWHW$6
/}8@~
LEHA+}
HQ$HQL
\iA$=L
$CPHe+P
hav$S=8
RH+C_A>d
p$HV}C
PJHT$Q
@LHH`S
%PfVPH
HI#GNt
H^TM@8
"VHLSTHE
D=IhIDH
$PpTVjWH
t8fCAs$
4WOd$@
$HhtHQ
IMp8d$$
^$H5HA
|[jIQx
$t$jLW,
uO3Abt,
@H@HN$j
(jL[Pb
$\CE8H
XM:h W
$BJ$W+
LVffHD5
P(HT(P
@HEL%;$
L$H@HDH
3D\tW$
OGHK1j
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
`h````
xpxxxx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
AreFileApisANSI
EnumSystemLocalesEx
GetActiveWindow
GetDateFormatEx
GetLastActivePopup
GetProcessWindowStation
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
MessageBoxA
MessageBoxW
AppPolicyGetProcessTerminationMethod
AppPolicyGetShowDeveloperDiagnostic
AppPolicyGetWindowingModel
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
map/set too long
lift t
Self ag
Crowd da
grow So
type must be boolean, but is
type must be number, but is
type must be number, but is
type must be number, but is
Hk/Ojc
0j110y
hWVUT6Z74
3ch;c?Q
@kAe5z7
3JMToi
2vwh"m
pvfNdQ~N
$:2OW`
VVVV1111
1*;Em9
Xh]tj{
vector too long
iostream stream error
c:\Colorabout\ForLarge\Forwardnext\past.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
past.dll
Thisview
VirtualProtect
VirtualFree
VirtualAlloc
DeleteFileA
CloseHandle
ResetEvent
GetWindowsDirectoryA
GetStartupInfoA
CreateProcessA
CreateDirectoryA
CreateSemaphoreA
GetTickCount
KERNEL32.dll
SetupCancelTemporarySourceList
SetupQuerySourceListA
SetupLogErrorA
SetupGetLineTextA
SetupOpenMasterInf
SetupGetLineByIndexA
SetupSetDirectoryIdA
SetupDefaultQueueCallbackA
SetupGetInfInformationA
SetupSetPlatformPathOverrideA
SetupPromptReboot
SetupOpenLog
SetupInitializeFileLogA
SetupGetLineCountA
SetupQueueCopyA
SetupQuerySpaceRequiredOnDriveA
SetupTerminateFileLog
SetupSetSourceListA
SetupRemoveFromSourceListA
SetupFreeSourceListA
SetupCloseLog
SetupRemoveFileLogEntryA
SetupQueueRenameA
SetupCopyOEMInfA
SetupGetIntField
SetupTermDefaultQueueCallback
SetupGetTargetPathA
SetupIterateCabinetA
SetupAddToSourceListA
SetupGetSourceInfoA
SetupQueryInfVersionInformationA
SetupGetStringFieldA
SetupGetFieldCount
SETUPAPI.dll
RasHangUpA
RasEnumConnectionsA
RasGetConnectStatusA
RASAPI32.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwind
RaiseException
InterlockedFlushSList
GetLastError
FreeLibrary
LoadLibraryExW
GetStdHandle
GetFileType
GetModuleFileNameW
GetModuleHandleExW
WriteConsoleW
ExitProcess
HeapAlloc
HeapFree
WriteFile
OutputDebugStringW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
>1@[PZ;
Z=Br=!
GxA~X2H
jC7O 6:P
-(q%"'
Qy?Lm/
7&hg=Za
2hSZ~
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Iostream_error_category2@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
0#03080B0X0l0p0z0
1,1T1h1
6+6Q6g6
6]7c7|7
=)=Q=d={=
0%0>0O0`0
1c1j1y1
2!2V2h2"3'3
55$5B5G5e5j5
:\;`;d;h;l;p;t;x;
:;$;B;G;e;j;
333L3R3g3
4&494h4
7 7/7L7d7
9'9.9K9t9
:':?:w:
<1<><W<
:/=T=b=n={=
>:>A>n>
0;1A1H1O1T1Z1`1e1k1q1v1|1
2 2&2,21272=2B2H2N2S2Y2_2d2j2p2u2{2
33%3+30363<3A3G3M3R3X3^3c3i3o3t3z3
6:7f7s7
8A8K8Y8t8
<"<(<.<4<I<^<e<k<}<
?#?*?J?P?V?\?b?h?o?v?}?
0O0U0[0a0g0m0t0{0
141Q1m1
112:2A2G2M2Y2|2Z3z3
5!565?5n5w5
87:L:[:
D2W2u2
214h4o4t4x4|4
5 5$5(5,5
)8-8185898=8A8E8I8M8Q8U8Y8]8a8e8i8m8q8u8y8}8
;!;;;c;q;w;
<'<8<D<
4$5<5B5i5-7
:E:P:j;q;
<#<4<@<O<g<
=!=&=+=F=P=\=a=f=
>(>l>u>
0O1f1~1
3#353J3
777d7k7v7
;*;?;U;b;p;~;
=J?f?{?
5`5h5r5{5
5#616:6
9!9L:m:
>L>P>X>d>~>
?-?F?K?w?
>D>^>v>}>
?-?K?r?
030E0R0k0|0
;#<.<g<y<
7C8s809
97:G: <j>
5!5U5x5
7@;H<Y<
L0S0Y0=2
5S6\6t6
627\7c7i7p7u7
8)8.838C8H8M8]8b8g8w8|8
9B9^9l9x9
:A:Y:i:}:
;$;H;y;
<#<.<3<8<S<b<m<r<w<
=*=/=4=U=e=
?5?B?G?L?i?w?|?
0M0_0k0F1
262S2r2K3
3E3R3a3
3(4i4x4
9,9M9a9
1*404e4
5%505k5
7I7U7m7u7
;A<p<==Q=i=q=
?8?@?M?
1$181C1
6%666u6
8M9{9w:
;-<s<>?
1)1_1Z2
2J3Q3X3_3y3
4G4o4_6
94:9:?:D:
<(<0<H<V<^<v<
31;9;p;w;
2)60676T6
7-7?7Q7c7u7
8909A9
:9;d;5<}<
021!2W2
70777S7Z7q7
161A1G1P1
2,2u2~2
3>3t4,5
0D1J1O1V1f1t1
10293A3I3Q3Y3w3
7-7K7_7e7
;N<b<s<
32373I3N3`3i3s3z3
3#4?4D4m4
5)7?7R7h7{7
9>9O9Y9g9}9
9*:1:I:^:i:v:
;#;8;>;M;X;s;
;d<p<x<
=K=R=Y={=
>3><>E>Q>d>k>
?#???c?z?
0A0N0X0o0
1"131J1U1a1m1
2%2,2D2X2b2m2{2
3=3Z3f3n3
4)4>4N4
959g9u9
;$;5;D;b;s;
=H=T=`=i=s=
>+>2>L>f>n>v>
?4?A?M?b?j?r?|?
0$0+01080F0P0W0]0h0t0~0
1#1-12171E1K1U1e1|1
2!2?2H2]2i2
2'3M3h3~3
384B4L4T4_4e4j4
5(5I5P5^5o5}5
6"6,646:6G6U6`6h6n6u6
7#7.7:7D7I7N7V7\7l7r7z7
81878A8K8Y8k8x8
9)90979C9N9[9b9p9
::&:/:5:V:h:v:
;&;;;A;F;L;q;{;
<'<6<=<D<P<[<h<o<}<
='=-=2=;=N=^=}=
>3>H>S>h>
??(?7?M?T?\?c?h?r?
030R0d0j0p0}0
1(1G1U1[1f1w1
222;2E2o2
3G3L3[3t3y3
4#4)4/454;4@4E4K4Q4W4]4b4g4m4s4y4
5#5)5.53595?5E5K5P5U5[5a5g5m5r5w5}5
66)636=6G6Q6[6
2$2(2,20242@2D2H2`2d2h2l2p2t2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
H5L5T5X5\5`5d5h5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
7 7$7(7,7074787<7@7D7H7L7P7T7 8(8,8084888<8@8D8H8L8P8T8X8\8`8d8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:
>$>,>4><>D>L>T>\>d>l>t>|>
Z7^7b7f7
9$909<9H9T9`9l9x9
: :,:8:D:P:\:h:t:
;(;4;@;L;X;d;p;|;
<(<4<@<L<X<d<p<|<
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
788L8P8`8d8h8p8
9,9<9@9P9T9X9`9x9|9
:(:,:<:@:H:`:p:t:
;,;0;4;<;T;d;h;l;p;t;|;
<4<D<H<X<\<`<h<
= =8=<=@=T=X=p=t=x=|=
>$>8><>L>P>T>\>t>x>
? ?8?H?X?h?l?|?
0 0$0,040L0P0h0x0|0
5$5,545<5D5L5|5
6 6@6H6P6X6`6h6p6|6
70787\7l7t7|7
808<8\8h8
9 9@9L9
:$:(:D:H:h:p:t:
;,;0;8;@;H;L;T;h;
<(<H<h<
=(=D=H=d=h=
>(>H>h>
?(?0?<?p?
000P0p0
1$1,1@1H1P1X1l1t1|1
P0T0X0\0`0d0h0l0p0t0
2 2$2@2D2
949L9l9
:(:D:p:
kernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
Assertion failed: %Ts, file %Ts, line %d
Microsoft Visual C++ Runtime Library
Assertion failed!
Program:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts
(Press Retry to debug the application - JIT must be enabled)
<program name unknown>
((((( H
((((( H
(
mscoree.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
C:\Cryptor\CryptorDLL\bin\json.h
oC:\Cryptor\CryptorDLL\bin\json.h
m_type != value_t::object || m_value.object != nullptr
m_type != value_t::array || m_value.array != nullptr
m_type != value_t::string || m_value.string != nullptr
m_type != value_t::binary || m_value.binary != nullptr
gobject != nullptr
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Gone on
ProductName
Law paper
FileVersion
5.4.7.686
FileDescription
Law paper
ProductVersion
5.4.7.686
Process
LegalCopyright
Copyright
Gone on 1997-2019
OriginalFilename
past.dll
VarFileInfo
Translation
Throughtoward
Example raise poem
example
whosequotient
tie game
shoe block Bone
Written boat represent joy
Control chord mark talk
life claim
bird steam
Clean separate
Tell mountain rope win
should
him deep
think enough
opposite motherBuild
Hard third before horse
Rock east past clean
hurry flower
spring steel
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Trojan.Gozi.793
MicroWorld-eScan Trojan.GenericKD.45781189
FireEye Trojan.GenericKD.45781189
CAT-QuickHeal Trojan.Agent
McAfee RDN/Generic.com
Cylance Clean
VIPRE Trojan.Win32.Generic!BT
Sangfor Spyware.Win32.Ursnif.KLHKV8
CrowdStrike win/malicious_confidence_60% (W)
BitDefender Trojan.GenericKD.45781189
K7GW Trojan ( 00578d3b1 )
K7AntiVirus Trojan ( 00578d3b1 )
BitDefenderTheta Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Trojan:Win32/Ursnif.c54f49f2
NANO-Antivirus Trojan.Win32.Gozi.inksdu
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.45781189
Sophos Mal/Generic-S
Comodo Clean
F-Secure Trojan.TR/Gozi.wxqlr
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0PBS21
McAfee-GW-Edition RDN/Generic.com
CMC Clean
Emsisoft Trojan.GenericKD.45781189 (B)
GData Trojan.GenericKD.45781189
eGambit Clean
Avira TR/Gozi.wxqlr
MAX malware (ai score=85)
Antiy-AVL Trojan/Win32.Generic
Kingsoft Clean
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Trojan.Generic.D2BA90C5
SUPERAntiSpyware Clean
AhnLab-V3 Malware/Win32.Generic.C4362827
ZoneAlarm Clean
Microsoft Trojan:Win32/Ymacco.AB7E
ESET-NOD32 a variant of Win32/Kryptik.HJTY
Acronis Clean
ALYac Trojan.GenericKD.45781189
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PBS21
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Trojan.Agent!SmbOeIeMjts
SentinelOne Clean
MaxSecure Trojan.Malware.115371239.susgen
Fortinet PossibleThreat.MU
Webroot Clean
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
Qihoo-360 Win32/TrojanPSW.Gozi.HgkASQMA
No IRMA results available.