a6630b31230a00dddb66097a38266a496fbea2bfe6379c8f9e84ac2b43ee1924

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jul-24 04:22:46
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to RC5 or RC6
Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • system
Can create temporary files:
  • GetTempPathA
  • CreateFileW
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • URLDownloadToFileA
Interacts with services:
  • OpenSCManagerW
  • DeleteService
  • OpenServiceA
  • CreateServiceA
Manipulates other processes:
  • ReadProcessMemory
  • WriteProcessMemory
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The file contains overlay data. 525 bytes of data starting at offset 0x146c00.
The overlay data has an entropy of 7.62445 and is possibly compressed or encrypted.
Malicious VirusTotal score: 34/58 (Scanned on 2026-08-08 11:01:38) ALYac: Gen:Variant.Yogi.36801
APEX: Malicious
AhnLab-V3: Malware/Win.Generic.R786999
Antiy-AVL: Trojan/Win32.GenericML
Arcabit: Trojan.Yogi.D8FC1
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Yogi.36801
Bkav: W32.Malware.628CB255
CTX: exe.trojan.genericml
CrowdStrike: win/malicious_confidence_70% (D)
Cynet: Malicious (score: 100)
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.36801 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: W32/PossibleThreat
GData: Gen:Variant.Yogi.36801
Kaspersky: UDS:Trojan.Win32.GenericML.xnet
Kingsoft: Win32.Troj.Unknown.a
Lionic: Trojan.Win32.GenericML.4!c
Malwarebytes: Malware.AI.59383222
McAfeeD: ti!A6630B31230A
MicroWorld-eScan: Gen:Variant.Yogi.36801
Microsoft: Trojan:Win32/Wacatac.B!ml
Paloalto: generic.ml
Rising: Trojan.Generic!8.C3 (TFE:5:rHJvkphGCAS)
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Trapmine: malicious.high.ml.score
TrendMicro: Trojan.Win32.GENERICML.USBLGQ26
TrendMicro-HouseCall: Trojan.Win32.GENERICML.USBLGQ26
VIPRE: Gen:Variant.Yogi.36801
alibabacloud: Trojan:Win/Wacatac.B9nj

Hashes

MD5 e88c300778f6b7f68b51ff3b55db4b7c
SHA1 c7ae8e8e0d2e091173afdb5b213a19754dfaf4f8
SHA256 a6630b31230a00dddb66097a38266a496fbea2bfe6379c8f9e84ac2b43ee1924
SHA3 c046b449102ee6dc5c81dc00f22b72d9d9a472cdb3a1e848f26e33a7ce5fe703
SSDeep 24576:pjESGCw4wTKMycEAszzwumicTZTnhgcel/ZSTsqOdrsX06Ai:5N3m1lczwumic1nhMEoqiP6V
Imports Hash f8eef7ef5fb87cbc7086f3c844f7308d

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jul-24 04:22:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xbe400
SizeOfInitializedData 0x89600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000BB040 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x14c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x800000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a547c7851e72343363228d21df071f4a
SHA1 ea2d0bf4105ea7dfbeef03eb08dc2c1f500ea17f
SHA256 e90b7b24fa463eee7597bec51e0f4d43e78be905dd85ab6224d6b01f871988af
SHA3 d292447b97b9b448e79ed23b192e0b94559ce1d5b24d68a38cfe8e76bdae82f3
VirtualSize 0xbe3df
VirtualAddress 0x1000
SizeOfRawData 0xbe400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.43356

.rdata

MD5 10d816f4ffafb21c526a8ea7c32bbf3f
SHA1 37acd1eb7891005c819bab4f2ff5b295135b13f7
SHA256 86a2dbcbd9dfe5dc5d341285f589dcd3fa29161efec3d999ffca3f204bef3438
SHA3 cd350ce2252cc05cf70d20b06fc3eafd0e6c569ab486364937189ad8aa50e5a6
VirtualSize 0x20eb4
VirtualAddress 0xc0000
SizeOfRawData 0x21000
PointerToRawData 0xbe800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.08871

.data

MD5 0f05f218be8cf69dc85c08514fd07ccb
SHA1 9b57eb6d7a174aa25f17fb5c6856fa108ade02d3
SHA256 9a14c49270ed476f2273da282cc10eb192635c1bf5f4f155436a7a7cfa12dda4
SHA3 f851ffd4703165c5714a88db7a166855efdf5872c37dda9c29cbc63704ef2117
VirtualSize 0x61390
VirtualAddress 0xe1000
SizeOfRawData 0x60200
PointerToRawData 0xdf800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.97028

.pdata

MD5 c5d57be5edc4c491dca6dbf76e760136
SHA1 95c237c50a5128149ac2c78cd2892346c342b5f6
SHA256 beeb876b87a115483d6e1426b2ef1d81c50951997269000618400a943d01f82a
SHA3 d4afaf2805dfa24f00a11c04e64cbef11af07f83629aa3df31341919663e985d
VirtualSize 0x6a8c
VirtualAddress 0x143000
SizeOfRawData 0x6c00
PointerToRawData 0x13fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.96883

.rsrc

MD5 b7da501c00a75401bdf3cac8a1b823b8
SHA1 03697a6838cc147a293d0b097aedee80ec3d460c
SHA256 a309779b5e70b9025866502f389cb4b01aeac03052a059b58e6719857b939bf2
SHA3 9a29bd9ea19080f0b53cbfdfc2f1f09a99eb00e9afde46c70999a22024a618bb
VirtualSize 0x1e8
VirtualAddress 0x14a000
SizeOfRawData 0x200
PointerToRawData 0x146600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 4a073323aa0eb22daa1c88fb793b9c45
SHA1 09247c5cd35b2c6070524969470c903b23b5a2de
SHA256 a7b6d1294b8bfebb5fd39a838f11e9a29e7665e41fcbed1f4f9f7cf43f7c0639
SHA3 c26e228261e2452a7c45a5f2874f430bd67d87b3ca606e5cef2662aef971653f
VirtualSize 0x234
VirtualAddress 0x14b000
SizeOfRawData 0x400
PointerToRawData 0x146800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.61326

Imports

d3d9.dll Direct3DCreate9Ex
KERNEL32.dll GetTempPathA
GetTickCount64
GetLastError
GetCurrentThread
CreateThread
SetFileAttributesA
Module32FirstW
VirtualProtectEx
GetThreadContext
GetProcAddress
ExitProcess
ReadProcessMemory
GetCurrentProcessId
GetModuleHandleW
Module32NextW
SetThreadContext
GetTickCount
VirtualQueryEx
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
LoadLibraryA
QueryPerformanceFrequency
QueryPerformanceCounter
WriteProcessMemory
CreateDirectoryW
FindClose
FindFirstFileExW
GetModuleFileNameA
Sleep
GetStdHandle
GetFileAttributesExW
GetFileInformationByHandle
SetFileInformationByHandle
AreFileApisANSI
CopyFileW
MoveFileExW
GetFileInformationByHandleEx
LocalFree
FormatMessageA
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
IsDebuggerPresent
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetConsoleMode
OpenProcess
TerminateProcess
SetConsoleMode
CloseHandle
Process32FirstW
GetCurrentProcess
SetConsoleTitleA
Process32NextW
CreateToolhelp32Snapshot
CreateFileW
DeviceIoControl
FindNextFileW
USER32.dll GetKeyState
ShowWindow
RegisterClassExW
SendInput
GetCursorPos
ShowCursor
UpdateWindow
ScreenToClient
ClientToScreen
GetClientRect
mouse_event
LoadCursorW
TranslateMessage
GetSystemMetrics
CreateWindowExW
SetWindowPos
DefWindowProcW
SetClipboardData
GetClipboardData
EmptyClipboard
CloseClipboard
OpenClipboard
SetLayeredWindowAttributes
MessageBoxA
SetWindowDisplayAffinity
PeekMessageW
DispatchMessageW
SetCursorPos
SetCursor
GetForegroundWindow
GetAsyncKeyState
ADVAPI32.dll OpenSCManagerW
GetUserNameA
DeleteService
StartServiceA
RegOpenKeyExA
OpenServiceA
RegQueryValueExA
CloseServiceHandle
RegCloseKey
CreateServiceA
MSVCP140.dll ??Bid@locale@std@@QEAA_KXZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_N@Z
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPEBD@Z
_Thrd_yield
_Query_perf_frequency
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Throw_Cpp_error@std@@YAXH@Z
?uncaught_exceptions@std@@YAHXZ
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A
?_Xinvalid_argument@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
?_Winerror_map@std@@YAHH@Z
?_Throw_C_error@std@@YAXH@Z
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z
?id@?$ctype@D@std@@2V0locale@2@A
?_Random_device@std@@YAIXZ
?_Syserror_map@std@@YAPEBDH@Z
_Mtx_destroy_in_situ
_Mtx_lock
_Mtx_init_in_situ
_Cnd_do_broadcast_at_thread_exit
_Thrd_sleep
_Thrd_id
_Query_perf_counter
_Thrd_detach
_Xtime_get_ticks
_Thrd_join
_Mtx_unlock
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEA_N@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z
??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAM@Z
?get@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAHXZ
?ignore@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
urlmon.dll URLDownloadToFileA
ntdll.dll RtlCaptureContext
RtlVirtualUnwind
RtlLookupFunctionEntry
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
dwmapi.dll DwmExtendFrameIntoClientArea
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll __std_exception_destroy
memcmp
__std_exception_copy
memcpy
memmove
__std_terminate
__C_specific_handler
wcsstr
strstr
__current_exception
memset
_CxxThrowException
__current_exception_context
memchr
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
free
realloc
malloc
_callnewh
api-ms-win-crt-runtime-l1-1-0.dll _register_thread_local_exe_atexit_callback
system
_invalid_parameter_noinfo_noreturn
exit
_errno
_c_exit
__p___argv
__p___argc
_beginthreadex
_exit
_initterm_e
_initterm
_get_initial_narrow_environment
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
_initialize_narrow_environment
_configure_narrow_argv
terminate
api-ms-win-crt-stdio-l1-1-0.dll fflush
__stdio_common_vsscanf
_wfopen
fclose
_set_fmode
fseek
ftell
_get_stream_buffer_pointers
_fseeki64
fread
__stdio_common_vsprintf_s
fsetpos
fgetc
ungetc
setvbuf
fgetpos
__stdio_common_vsprintf
fputc
fwrite
__p__commode
api-ms-win-crt-string-l1-1-0.dll isdigit
strnlen
strcpy_s
tolower
strncpy
strncmp
_wcsicmp
strcmp
api-ms-win-crt-utility-l1-1-0.dll rand
qsort
api-ms-win-crt-filesystem-l1-1-0.dll _lock_file
_unlock_file
api-ms-win-crt-convert-l1-1-0.dll atof
strtol
api-ms-win-crt-math-l1-1-0.dll acosf
asin
asinf
atan2f
atanf
ceilf
cos
cosf
_dclass
__setusermatherr
pow
powf
sin
sqrtf
_fdclass
sinf
sqrt
fmodf
ldexp
tanf
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
_configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jul-24 04:22:46
Version 0.0
SizeofData 1012
AddressOfRawData 0xd1c00
PointerToRawData 0xd0400

TLS Callbacks

StartAddressOfRawData 0x1400d2020
EndAddressOfRawData 0x1400d2190
AddressOfIndex 0x140141630
AddressOfCallbacks 0x1400c0c10
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001400BA498
0x00000001400BACA4

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400e1010

RICH Header

XOR Key 0x88d0837c
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
C objects (30034) 10
ASM objects (30034) 4
C++ objects (30034) 38
Imports (30034) 6
Imports (35222) 19
Total imports 394
C++ objects (30159) 1
C++ objects (LTCG) (30159) 10
Resource objects (30159) 1
Linker (30159) 1

Errors

Leave a comment

No comments yet.