Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
glib-2.0.dll

Overview

General Information

Sample name:glib-2.0.dll
Analysis ID:1544942
MD5:34f4b186c725c3948820c0ad65c42c27
SHA1:a5422d027adc059ef5c78e635af2d43795710925
SHA256:5cfa104a083d2b1d223f306b86829e5ae40cd0909c8d46828149296388d542a7
Tags:dlluser-likeastar20
Infos:

Detection

Score:23
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

AI detected suspicious sample
Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)
PE / OLE file has an invalid certificate
PE file contains an invalid checksum
Program does not show much activity (idle)
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

  • System is w10x64
  • loaddll32.exe (PID: 6568 cmdline: loaddll32.exe "C:\Users\user\Desktop\glib-2.0.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 6592 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 6708 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 6784 cmdline: rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 6732 cmdline: rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_flags MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 6972 cmdline: rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_initialized MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7076 cmdline: rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,g_access MD5: 889B99C52A60DD49227C5E485A016679)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Submited SampleIntegrated Neural Analysis Model: Matched 86.0% probability
Source: glib-2.0.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: C:\Windows\System32\loaddll32.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9625_none_508ef7e4bcbbe589\MSVCR90.dllJump to behavior
Source: glib-2.0.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: Binary string: c:\toolchain\src\glib-2.22.4-3\glib-2.22.4\build\win32\vs8\Release\bin\glib-2.0.pdb source: glib-2.0.dll
Source: glib-2.0.dllString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: glib-2.0.dllString found in binary or memory: http://freedesktop.org
Source: glib-2.0.dllString found in binary or memory: http://freedesktop.orgmetadataUnexpected
Source: glib-2.0.dllString found in binary or memory: http://ocsp.thawte.com0
Source: glib-2.0.dllString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: glib-2.0.dllString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: glib-2.0.dllString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarks
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksapplicationUnexpected
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksgroupUnexpected
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksgrouphttp://www.freedesktop.org/standards/desk
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksgroupshttp://www.freedesktop.org/standards/des
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksmetadataUnexpected
Source: glib-2.0.dllString found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: glib-2.0.dllString found in binary or memory: http://www.vmware.com/0
Source: glib-2.0.dllStatic PE information: invalid certificate
Source: glib-2.0.dllBinary or memory string: OriginalFilenamelibglib-2.0-0.dll* vs glib-2.0.dll
Source: glib-2.0.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: classification engineClassification label: sus23.winDLL@12/0@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6592:120:WilError_03
Source: glib-2.0.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_flags
Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\glib-2.0.dll"
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_flags
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_initialized
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,g_access
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_flagsJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_initializedJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,g_accessJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: intl.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: glib-2.0.dllStatic PE information: More than 1235 > 100 exports found
Source: glib-2.0.dllStatic file information: File size 1074880 > 1048576
Source: C:\Windows\System32\loaddll32.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9625_none_508ef7e4bcbbe589\MSVCR90.dllJump to behavior
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: glib-2.0.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: glib-2.0.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: c:\toolchain\src\glib-2.22.4-3\glib-2.22.4\build\win32\vs8\Release\bin\glib-2.0.pdb source: glib-2.0.dll
Source: glib-2.0.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: glib-2.0.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: glib-2.0.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: glib-2.0.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: glib-2.0.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: glib-2.0.dllStatic PE information: real checksum: 0x1108d6 should be: 0x10d0b0
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: glib-2.0.dllBinary or memory string: VMware, Inc.1>0<
Source: glib-2.0.dllBinary or memory string: http://www.vmware.com/0
Source: glib-2.0.dllBinary or memory string: VMware, Inc.0
Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
11
Process Injection
1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Rundll32
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
Process Injection
Security Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1544942 Sample: glib-2.0.dll Startdate: 29/10/2024 Architecture: WINDOWS Score: 23 19 AI detected suspicious sample 2->19 7 loaddll32.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 conhost.exe 7->11         started        13 rundll32.exe 7->13         started        15 2 other processes 7->15 process5 17 rundll32.exe 9->17         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
glib-2.0.dll11%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://crl.thawte.com/ThawteTimestampingCA.crl00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.freedesktop.org/standards/desktop-bookmarksglib-2.0.dllfalse
    unknown
    http://www.freedesktop.org/standards/desktop-bookmarksgrouphttp://www.freedesktop.org/standards/deskglib-2.0.dllfalse
      unknown
      http://www.vmware.com/0glib-2.0.dllfalse
        unknown
        http://crl.thawte.com/ThawteTimestampingCA.crl0glib-2.0.dllfalse
        • URL Reputation: safe
        unknown
        http://www.freedesktop.org/standards/desktop-bookmarksgroupshttp://www.freedesktop.org/standards/desglib-2.0.dllfalse
          unknown
          http://www.freedesktop.org/standards/shared-mime-infoglib-2.0.dllfalse
            unknown
            http://freedesktop.orgglib-2.0.dllfalse
              unknown
              http://ocsp.thawte.com0glib-2.0.dllfalse
              • URL Reputation: safe
              unknown
              No contacted IP infos
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1544942
              Start date and time:2024-10-29 21:50:05 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 1s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:glib-2.0.dll
              Detection:SUS
              Classification:sus23.winDLL@12/0@0/0
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .dll
              • Stop behavior analysis, all processes terminated
              • Exclude process from analysis (whitelisted): SIHClient.exe
              • Not all processes where analyzed, report is missing behavior information
              • VT rate limit hit for: glib-2.0.dll
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Entropy (8bit):6.573248721973091
              TrID:
              • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
              • Generic Win/DOS Executable (2004/3) 0.20%
              • DOS Executable Generic (2002/1) 0.20%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:glib-2.0.dll
              File size:1'074'880 bytes
              MD5:34f4b186c725c3948820c0ad65c42c27
              SHA1:a5422d027adc059ef5c78e635af2d43795710925
              SHA256:5cfa104a083d2b1d223f306b86829e5ae40cd0909c8d46828149296388d542a7
              SHA512:bf1baf5be92dccdfe446505a8d26269c0d7fd65839b2ac15e84ca834cf36cc06844ad336f0b6c9e302f342aa4320685ed93f88a562cfbf742c801457d269520c
              SSDEEP:24576:NekMj5RU/KFHOTHRMQHa6dcS/KODIj5d0Hl/QrVmPQN:NekMjoKsRMQUS//DIj5d0FSVmYN
              TLSH:2D350712F501F067FB8398BA63A5936A79745B212F5710C37A9CE6D4E71C6E22032F87
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........S..............@.......C.......U.......R.......E.........K....._.......D.......B.......G.....Rich...........................
              Icon Hash:7ae282899bbab082
              Entrypoint:0x10001481
              Entrypoint Section:.text
              Digitally signed:true
              Imagebase:0x10000000
              Subsystem:windows gui
              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
              Time Stamp:0x50BCEACF [Mon Dec 3 18:09:19 2012 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:5
              OS Version Minor:0
              File Version Major:5
              File Version Minor:0
              Subsystem Version Major:5
              Subsystem Version Minor:0
              Import Hash:9bc40fa39ece484543c8e07744cdc3ca
              Signature Valid:false
              Signature Issuer:CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
              Signature Validation Error:The digital signature of the object did not verify
              Error Number:-2146869232
              Not Before, Not After
              • 16/10/2013 20:00:00 15/11/2016 18:59:59
              Subject Chain
              • CN="VMware, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="VMware, Inc.", L=Palo Alto, S=California, C=US
              Version:3
              Thumbprint MD5:31E7FB307B9796C0A2B1963C4441488B
              Thumbprint SHA-1:968970C359F148B1F3670A41C48B4DC47B1478A9
              Thumbprint SHA-256:E0EE6CB3E8F109F9196F74619C60831E68CC516D8B56BD50CB3DE83C994FEFD8
              Serial:4451AD3717CFA22371FFBC07DF13E65D
              Instruction
              mov edi, edi
              push ebp
              mov ebp, esp
              cmp dword ptr [ebp+0Ch], 01h
              jne 00007F66E0CB8EF7h
              call 00007F66E0CB926Ah
              push dword ptr [ebp+08h]
              mov ecx, dword ptr [ebp+10h]
              mov edx, dword ptr [ebp+0Ch]
              call 00007F66E0CB8DC1h
              pop ecx
              pop ebp
              retn 000Ch
              mov edi, edi
              push ebp
              mov ebp, esp
              sub esp, 00000328h
              mov dword ptr [100FE3E0h], eax
              mov dword ptr [100FE3DCh], ecx
              mov dword ptr [100FE3D8h], edx
              mov dword ptr [100FE3D4h], ebx
              mov dword ptr [100FE3D0h], esi
              mov dword ptr [100FE3CCh], edi
              mov word ptr [100FE3F8h], ss
              mov word ptr [100FE3ECh], cs
              mov word ptr [100FE3C8h], ds
              mov word ptr [100FE3C4h], es
              mov word ptr [100FE3C0h], fs
              mov word ptr [100FE3BCh], gs
              pushfd
              pop dword ptr [100FE3F0h]
              mov eax, dword ptr [ebp+00h]
              mov dword ptr [100FE3E4h], eax
              mov eax, dword ptr [ebp+04h]
              mov dword ptr [100FE3E8h], eax
              lea eax, dword ptr [ebp+08h]
              mov dword ptr [100FE3F4h], eax
              mov eax, dword ptr [ebp-00000320h]
              mov dword ptr [100FE330h], 00010001h
              mov eax, dword ptr [100FE3E8h]
              mov dword ptr [100FE2E4h], eax
              mov dword ptr [100FE2D8h], C0000409h
              mov dword ptr [100FE2DCh], 00000001h
              Programming Language:
              • [ASM] VS2008 SP1 build 30729
              • [ C ] VS2008 SP1 build 30729
              • [C++] VS2008 SP1 build 30729
              • [IMP] VS2008 SP1 build 30729
              • [EXP] VS2008 SP1 build 30729
              • [LNK] VS2008 SP1 build 30729
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0xc99300x92ac.rdata
              IMAGE_DIRECTORY_ENTRY_IMPORT0xc87ac0xb4.rdata
              IMAGE_DIRECTORY_ENTRY_RESOURCE0xff0000x698.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x1048000x1ec0.reloc
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x1000000x6cde.reloc
              IMAGE_DIRECTORY_ENTRY_DEBUG0x943b00x1c.rdata
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xc86500x40.rdata
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x940000x38c.rdata
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x926790x928008a514ce59898df6f254a4b43cb29a4bfFalse0.41519737894624575data6.300539378421434IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rdata0x940000x3ebdc0x3ec00354de873ddfec807ec4394b1a3ddc8dfFalse0.26878812873505975data5.385878719544283IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .data0xd30000x2b9b80x2b400c160d8b3022f8e9801d76e07272f9c11False0.12650718027456648data5.047363038871125IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .rsrc0xff0000x6980x800d0114d8302fd977243570810cfcb8eb5False0.396484375data4.777209148765724IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .reloc0x1000000x72d60x74009cf6cf85f0b0abcab94d41696c10e28dFalse0.7156519396551724data6.636934563660123IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_VERSION0xff0a00x39cdataEnglishUnited States0.47835497835497837
              RT_MANIFEST0xff43c0x259ASCII text, with CRLF line terminatorsEnglishUnited States0.5158069883527454
              DLLImport
              intl.dlllibintl_gettext, libintl_sprintf, libintl_bindtextdomain, libintl_bind_textdomain_codeset, libintl_fprintf, libintl_textdomain, libintl_dgettext, libintl_dngettext
              WS2_32.dllWSAEnumNetworkEvents, send, WSACloseEvent, WSASetEvent, ioctlsocket, WSAGetLastError, closesocket, WSAEventSelect, recv, WSACreateEvent, getsockopt
              KERNEL32.dllLocalFree, GetVersion, GetShortPathNameW, FormatMessageW, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, InterlockedExchange, GetModuleHandleW, GetLocaleInfoA, ExpandEnvironmentStringsW, GetWindowsDirectoryW, FreeEnvironmentStringsW, GetModuleHandleA, InterlockedCompareExchange, InterlockedExchangeAdd, IsDebuggerPresent, WideCharToMultiByte, GetACP, MultiByteToWideChar, GetLastError, IsDBCSLeadByteEx, GetProcAddress, IsValidCodePage, LoadLibraryA, GetCPInfoExA, GetDateFormatW, GetLocaleInfoW, GetTimeFormatW, GetTimeZoneInformation, GetThreadLocale, GetFileAttributesW, PeekNamedPipe, WaitForSingleObject, SetEvent, WriteFile, InitializeCriticalSection, ReadConsoleInputA, CreateEventA, LeaveCriticalSection, ReadFile, EnterCriticalSection, ResetEvent, PeekConsoleInputA, DeleteCriticalSection, CloseHandle, GetSystemTimeAsFileTime, GetExitCodeProcess, CreateSemaphoreA, ReleaseSemaphore, MapViewOfFile, UnmapViewOfFile, CreateFileMappingA, SleepEx, WaitForMultipleObjectsEx, GetSystemInfo, GetCurrentProcess, GetStdHandle, GetConsoleCursorInfo, DuplicateHandle, MoveFileExW, Sleep, GetComputerNameA, GetEnvironmentVariableW, VirtualQuery, SetEnvironmentVariableW, GetEnvironmentStringsW, GetSystemDirectoryW, GetModuleFileNameW, GetCurrentDirectoryW
              USER32.dllPostMessageA, MessageBoxA, MsgWaitForMultipleObjectsEx, PeekMessageA, IsWindow
              ADVAPI32.dllGetUserNameW
              SHELL32.dllSHGetPathFromIDListW, SHGetSpecialFolderLocation
              ole32.dllCoTaskMemFree
              MSVCR90.dll_adjust_fdiv, __CppXcptFilter, _crt_debugger_hook, _except_handler4_common, __clean_type_info_names_internal, _close, _open, _fdopen, _read, _lseek, _amsg_exit, _initterm_e, _initterm, _encoded_null, _malloc_crt, _decode_pointer, _write, free, _onexit, _lock, _encode_pointer, __dllonexit, _unlock, memcpy, memmove, qsort, memset, abort, _exit, strlen, strchr, atoi, strcmp, atol, _time64, strncmp, strncpy, _stricmp, _strnicmp, _getpid, calloc, strcpy, _errno, strstr, wcslen, setlocale, _localtime64, wcscat, malloc, _wfindfirst64i32, _findclose, _wfindnext64i32, _wfullpath, wcscmp, wcscpy, feof, memcmp, fflush, fread, ferror, fwrite, strrchr, fclose, strcspn, _fstat64i32, _beginthreadex, _get_osfhandle, getenv, _kbhit, strtol, strtoul, realloc, fputs, __iob_func, strcat, exit, strerror, fprintf, vfprintf, _wspawnvp, _pipe, _wspawnve, _wspawnv, _open_osfhandle, _wspawnvpe, _wopen, _wchmod, _wmkdir, _wrmdir, _wfopen, _wstat64i32, _wremove, _wcreat, _wchdir, _waccess, _wunlink, _wutime64, _wfreopen, strtod, localeconv, tolower, isdigit, isupper, toupper, islower, strpbrk, printf, _mktime64, _gmtime64, strcoll, strxfrm, bsearch, wcschr, _wputenv, _chsize, sprintf, ___mb_cur_max_func
              NameOrdinalAddress
              _g_debug_flags10x100fe7c8
              _g_debug_initialized20x100fe7c4
              g_access30x100252d0
              g_allocator_free40x1003b890
              g_allocator_new50x1003b8a0
              g_array_append_vals60x10075080
              g_array_free70x10075f60
              g_array_get_element_size80x10074c60
              g_array_insert_vals90x10074ee0
              g_array_new100x100751f0
              g_array_prepend_vals110x10074fb0
              g_array_ref120x10076090
              g_array_remove_index130x10075e10
              g_array_remove_index_fast140x10075cd0
              g_array_remove_range150x10075b40
              g_array_set_size160x10074df0
              g_array_sized_new170x10075110
              g_array_sort180x10075ae0
              g_array_sort_with_data190x10076400
              g_array_unref200x10076020
              g_ascii_digit_value210x10021470
              g_ascii_dtostr220x100242a0
              g_ascii_formatd230x10023f90
              g_ascii_strcasecmp240x10021340
              g_ascii_strdown250x10023920
              g_ascii_strncasecmp260x10023570
              g_ascii_strtod270x100242d0
              g_ascii_strtoll280x100249b0
              g_ascii_strtoull290x10024a60
              g_ascii_strup300x10023880
              g_ascii_table310x100c8240
              g_ascii_tolower320x100214e0
              g_ascii_toupper330x100214a0
              g_ascii_xdigit_value340x100215d0
              g_assert_warning350x1003b5b0
              g_assertion_message360x1001d3c0
              g_assertion_message_cmpnum370x1001d6c0
              g_assertion_message_cmpstr380x1001dd90
              g_assertion_message_error390x1001d5e0
              g_assertion_message_expr400x1001d7a0
              g_async_queue_length410x10073e20
              g_async_queue_length_unlocked420x10073da0
              g_async_queue_lock430x10073f70
              g_async_queue_new440x10073ca0
              g_async_queue_new_full450x10073d00
              g_async_queue_pop460x10074a40
              g_async_queue_pop_unlocked470x100749c0
              g_async_queue_push480x10074490
              g_async_queue_push_sorted490x10074b90
              g_async_queue_push_sorted_unlocked500x10074b00
              g_async_queue_push_unlocked510x100743b0
              g_async_queue_ref520x10074080
              g_async_queue_ref_unlocked530x10074000
              g_async_queue_sort540x10074190
              g_async_queue_sort_unlocked550x10074100
              g_async_queue_timed_pop560x100747c0
              g_async_queue_timed_pop_unlocked570x10074740
              g_async_queue_try_pop580x10074900
              g_async_queue_try_pop_unlocked590x10074880
              g_async_queue_unlock600x10073ee0
              g_async_queue_unref610x10074570
              g_async_queue_unref_and_unlock620x100746b0
              g_atexit630x1000ed90
              g_atomic_int_add640x10073c40
              g_atomic_int_compare_and_exchange650x10073c10
              g_atomic_int_exchange_and_add660x10073c60
              g_atomic_int_get670x10073bc0
              g_atomic_int_set680x10073bb0
              g_atomic_pointer_compare_and_exchange690x10073be0
              g_atomic_pointer_get700x10073ba0
              g_atomic_pointer_set710x10073b90
              g_base64_decode720x10091440
              g_base64_decode_inplace730x10091350
              g_base64_decode_step740x10090ce0
              g_base64_encode750x10091550
              g_base64_encode_close760x10090ed0
              g_base64_encode_step770x10091070
              g_basename780x1000ecd0
              g_bit_nth_lsf790x1000cce0
              g_bit_nth_msf800x1000cca0
              g_bit_storage810x1000cc70
              g_blow_chunks820x1003b8b0
              g_bookmark_file_add_application830x10070960
              g_bookmark_file_add_group840x10070c70
              g_bookmark_file_error_quark850x1006e9a0
              g_bookmark_file_free860x10072bc0
              g_bookmark_file_get_added870x1006fd10
              g_bookmark_file_get_app_info880x100719c0
              g_bookmark_file_get_applications890x1006f450
              g_bookmark_file_get_description900x1006ffe0
              g_bookmark_file_get_groups910x1006f730
              g_bookmark_file_get_icon920x1006f2f0
              g_bookmark_file_get_is_private930x1006fde0
              g_bookmark_file_get_mime_type940x1006fee0
              g_bookmark_file_get_modified950x1006fc40
              g_bookmark_file_get_size960x1006f400
              g_bookmark_file_get_title970x10070090
              g_bookmark_file_get_uris980x10070140
              g_bookmark_file_get_visited990x1006fb70
              g_bookmark_file_has_application1000x1006f630
              g_bookmark_file_has_group1010x1006fa60
              g_bookmark_file_has_item1020x10070250
              g_bookmark_file_load_from_data1030x10073700
              g_bookmark_file_load_from_data_dirs1040x10073930
              g_bookmark_file_load_from_file1050x10073820
              g_bookmark_file_move_item1060x100729f0
              g_bookmark_file_new1070x1006e810
              g_bookmark_file_remove_application1080x10070860
              g_bookmark_file_remove_group1090x1006f8e0
              g_bookmark_file_remove_item1100x10072170
              g_bookmark_file_set_added1110x10070f70
              g_bookmark_file_set_app_info1120x10070560
              g_bookmark_file_set_description1130x10071280
              g_bookmark_file_set_groups1140x10070ac0
              g_bookmark_file_set_icon1150x10070410
              g_bookmark_file_set_is_private1160x10071050
              g_bookmark_file_set_mime_type1170x10071150
              g_bookmark_file_set_modified1180x10070ea0
              g_bookmark_file_set_title1190x10071360
              g_bookmark_file_set_visited1200x10070dd0
              g_bookmark_file_to_data1210x10073460
              g_bookmark_file_to_file1220x100735f0
              g_build_filename1230x10057c60
              g_build_filenamev1240x10057c90
              g_build_path1250x100580e0
              g_build_pathv1260x10057cb0
              g_byte_array_append1270x10075250
              g_byte_array_free1280x10076260
              g_byte_array_new1290x10075290
              g_byte_array_prepend1300x10075230
              g_byte_array_ref1310x10076240
              g_byte_array_remove_index1320x10076200
              g_byte_array_remove_index_fast1330x100761e0
              g_byte_array_remove_range1340x10076110
              g_byte_array_set_size1350x10075210
              g_byte_array_sized_new1360x10075270
              g_byte_array_sort1370x100760f0
              g_byte_array_sort_with_data1380x10076470
              g_byte_array_unref1390x10076220
              g_cache_destroy1400x1008f2d0
              g_cache_insert1410x1008f020
              g_cache_key_foreach1420x1008ee90
              g_cache_new1430x1008f100
              g_cache_remove1440x1008ef10
              g_cache_value_foreach1450x1008ee10
              g_chdir1460x10024e40
              g_checksum_copy1470x1006e450
              g_checksum_free1480x1006dff0
              g_checksum_get_digest1490x1006e030
              g_checksum_get_string1500x1006e1f0
              g_checksum_new1510x1006e5a0
              g_checksum_reset1520x1006e4d0
              g_checksum_type_get_length1530x10064d10
              g_checksum_update1540x1006e310
              g_child_watch_add1550x10045180
              g_child_watch_add_full1560x10044a10
              g_child_watch_funcs1570x100e6be4
              g_child_watch_source_new1580x10042160
              g_chmod1590x10025250
              g_clear_error1600x100595f0
              g_completion_add_items1610x10064c10
              g_completion_clear_items1620x10064ae0
              g_completion_complete1630x100647d0
              g_completion_complete_utf81640x10064a50
              g_completion_free1650x10064cc0
              g_completion_new1660x10064780
              g_completion_remove_items1670x10064b60
              g_completion_set_compare1680x10064600
              g_compute_checksum_for_data1690x1006e5e0
              g_compute_checksum_for_string1700x1006e6b0
              g_convert1710x10063d70
              g_convert_error_quark1720x10062cb0
              g_convert_with_fallback1730x100631e0
              g_convert_with_iconv1740x10063ae0
              g_creat1750x10025150
              g_datalist_clear1760x100600e0
              g_datalist_foreach1770x1005f680
              g_datalist_get_flags1780x1005f4d0
              g_datalist_id_get_data1790x1005f8b0
              g_datalist_id_remove_no_notify1800x1005fb00
              g_datalist_id_set_data_full1810x1005fcf0
              g_datalist_init1820x1005f640
              g_datalist_set_flags1830x1005f5b0
              g_datalist_unset_flags1840x1005f510
              g_dataset_destroy1850x10060000
              g_dataset_foreach1860x1005f730
              g_dataset_id_get_data1870x1005f9b0
              g_dataset_id_remove_no_notify1880x1005fbf0
              g_dataset_id_set_data_full1890x1005fe50
              g_date_add_days1900x1005c190
              g_date_add_months1910x1005ae80
              g_date_add_years1920x1005aac0
              g_date_clamp1930x1005c820
              g_date_clear1940x1005a2f0
              g_date_compare1950x1005bd80
              g_date_days_between1960x1005cd40
              g_date_free1970x1005a690
              g_date_get_day1980x1005b900
              g_date_get_day_of_year1990x1005b810
              g_date_get_days_in_month2000x1005a8a0
              g_date_get_iso8601_week_of_year2010x1005c4f0
              g_date_get_julian2020x1005c610
              g_date_get_monday_week_of_year2030x1005cf00
              g_date_get_monday_weeks_in_year2040x1005cc20
              g_date_get_month2050x1005ba60
              g_date_get_sunday_week_of_year2060x1005cde0
              g_date_get_sunday_weeks_in_year2070x1005cb00
              g_date_get_weekday2080x1005c6b0
              g_date_get_year2090x1005b9b0
              g_date_is_first_of_month2100x1005b160
              g_date_is_last_of_month2110x1005b070
              g_date_is_leap_year2120x1005a1b0
              g_date_new2130x1005a190
              g_date_new_dmy2140x1005a790
              g_date_new_julian2150x1005a6d0
              g_date_order2160x1005c760
              g_date_set_day2170x1005b450
              g_date_set_dmy2180x1005b220
              g_date_set_julian2190x1005a240
              g_date_set_month2200x1005b570
              g_date_set_parse2210x1005e5f0
              g_date_set_time2220x1005c270
              g_date_set_time_t2230x1005b690
              g_date_set_time_val2240x1005c250
              g_date_set_year2250x1005b320
              g_date_strftime2260x1005e170
              g_date_subtract_days2270x1005c0a0
              g_date_subtract_months2280x1005abf0
              g_date_subtract_years2290x1005a950
              g_date_to_struct_tm2300x1005c990
              g_date_valid2310x1005a620
              g_date_valid_day2320x1005a0f0
              g_date_valid_dmy2330x1005a5b0
              g_date_valid_julian2340x1005a0b0
              g_date_valid_month2350x1005a140
              g_date_valid_weekday2360x1005a0c0
              g_date_valid_year2370x1005a120
              g_dgettext2380x10021d10
              g_dir_close2390x10059d10
              g_dir_open2400x1005a040
              g_dir_open_utf82410x10059ec0
              g_dir_read_name2420x10059fc0
              g_dir_read_name_utf82430x10059db0
              g_dir_rewind2440x10059d60
              g_direct_equal2450x1000c920
              g_direct_hash2460x1000c940
              g_dngettext2470x10021cc0
              g_double_equal2480x1000c860
              g_double_hash2490x1000c830
              g_dpgettext2500x10021e20
              g_dpgettext22510x10021d40
              g_error_copy2520x100597a0
              g_error_free2530x10059590
              g_error_matches2540x100593b0
              g_error_new2550x10059820
              g_error_new_literal2560x100593f0
              g_error_new_valist2570x100596f0
              g_file_error_from_errno2580x10057600
              g_file_error_quark2590x10057ce0
              g_file_get_contents2600x100590b0
              g_file_get_contents_utf82610x10059010
              g_file_open_tmp2620x10059330
              g_file_open_tmp_utf82630x10059110
              g_file_read_link2640x10057d00
              g_file_set_contents2650x10058da0
              g_file_test2660x10058d50
              g_file_test_utf82670x10058980
              g_filename_display_basename2680x10064320
              g_filename_display_name2690x10064260
              g_filename_from_uri2700x10064070
              g_filename_from_uri_utf82710x100637f0
              g_filename_from_utf82720x10063e90
              g_filename_from_utf8_utf82730x10063ef0
              g_filename_to_uri2740x100645a0
              g_filename_to_uri_utf82750x10064490
              g_filename_to_utf82760x10063f50
              g_filename_to_utf8_utf82770x10063fb0
              g_find_program_in_path2780x1000fcf0
              g_find_program_in_path_utf82790x1000fb90
              g_fopen2800x10024c10
              g_format_size_for_display2810x10057d30
              g_fprintf2820x1008ed50
              g_free2830x1003bcd0
              g_freopen2840x10024b50
              g_get_application_name2850x1000ddd0
              g_get_charset2860x10011900
              g_get_codeset2870x1000d7f0
              g_get_current_dir2880x1000df00
              g_get_current_dir_utf82890x1000d6c0
              g_get_current_time2900x100403a0
              g_get_filename_charsets2910x100602c0
              g_get_home_dir2920x100101d0
              g_get_home_dir_utf82930x100102b0
              g_get_host_name2940x10010290
              g_get_language_names2950x1000eea0
              g_get_prgname2960x1000dc80
              g_get_real_name2970x100101e0
              g_get_real_name_utf82980x100102c0
              g_get_system_config_dirs2990x1000f0a0
              g_get_system_data_dirs3000x1000f190
              g_get_tmp_dir3010x100101c0
              g_get_tmp_dir_utf83020x100102a0
              g_get_user_cache_dir3030x1000fe90
              g_get_user_config_dir3040x10010200
              g_get_user_data_dir3050x10010020
              g_get_user_name3060x100101f0
              g_get_user_name_utf83070x100102d0
              g_get_user_special_dir3080x1000fd80
              g_getenv3090x1000de70
              g_getenv_utf83100x1000d4c0
              g_hash_table_destroy3110x10057530
              g_hash_table_find3120x10056c70
              g_hash_table_foreach3130x10056d40
              g_hash_table_foreach_remove3140x10056e90
              g_hash_table_foreach_steal3150x10056e00
              g_hash_table_get_keys3160x10056b90
              g_hash_table_get_values3170x10056af0
              g_hash_table_insert3180x10056ad0
              g_hash_table_iter_get_hash_table3190x10057320
              g_hash_table_iter_init3200x100574a0
              g_hash_table_iter_next3210x10057360
              g_hash_table_iter_remove3220x100575e0
              g_hash_table_iter_steal3230x100575c0
              g_hash_table_lookup3240x100564c0
              g_hash_table_lookup_extended3250x10057000
              g_hash_table_new3260x100565e0
              g_hash_table_new_full3270x10056540
              g_hash_table_ref3280x10057160
              g_hash_table_remove3290x10056a90
              g_hash_table_remove_all3300x10056f90
              g_hash_table_replace3310x10056ab0
              g_hash_table_size3320x10056c30
              g_hash_table_steal3330x10056a70
              g_hash_table_steal_all3340x10056f20
              g_hash_table_unref3350x100570a0
              g_hook_alloc3360x10055220
              g_hook_compare_ids3370x10054aa0
              g_hook_destroy3380x10056060
              g_hook_destroy_link3390x100555b0
              g_hook_find3400x10055920
              g_hook_find_data3410x10054ca0
              g_hook_find_func3420x10054be0
              g_hook_find_func_data3430x10054b10
              g_hook_first_valid3440x10055b10
              g_hook_free3450x100550c0
              g_hook_get3460x10054d20
              g_hook_insert_before3470x10054dc0
              g_hook_insert_sorted3480x10055700
              g_hook_list_clear3490x10055650
              g_hook_list_init3500x10055300
              g_hook_list_invoke3510x10055f60
              g_hook_list_invoke_check3520x10055e40
              g_hook_list_marshal3530x10055bc0
              g_hook_list_marshal_check3540x10055cf0
              g_hook_next_valid3550x10055a40
              g_hook_prepend3560x10054fb0
              g_hook_ref3570x10055000
              g_hook_unref3580x100553d0
              g_hostname_is_ascii_encoded3590x10054220
              g_hostname_is_ip_address3600x100539e0
              g_hostname_is_non_ascii3610x10053ed0
              g_hostname_to_ascii3620x10054920
              g_hostname_to_unicode3630x10054810
              g_iconv3640x10061a00
              g_iconv_close3650x100619e0
              g_iconv_open3660x10062cd0
              g_idle_add3670x10045160
              g_idle_add_full3680x10044970
              g_idle_funcs3690x100e6bfc
              g_idle_remove_by_data3700x10045140
              g_idle_source_new3710x10042130
              g_int64_equal3720x1000c8a0
              g_int64_hash3730x1000c890
              g_int_equal3740x1000c900
              g_int_hash3750x1000c8f0
              g_intern_static_string3760x1005edb0
              g_intern_string3770x1005ee60
              g_io_add_watch3780x100539b0
              g_io_add_watch_full3790x10053910
              g_io_channel_close3800x10051440
              g_io_channel_error_from_errno3810x100500e0
              g_io_channel_error_quark3820x1004fa40
              g_io_channel_flush3830x1004fbf0
              g_io_channel_get_buffer_condition3840x1004f910
              g_io_channel_get_buffer_size3850x10050040
              g_io_channel_get_buffered3860x1004faa0
              g_io_channel_get_close_on_unref3870x1004fd40
              g_io_channel_get_encoding3880x1004fa60
              g_io_channel_get_flags3890x1004fde0
              g_io_channel_get_line_term3900x1004ff10
              g_io_channel_init3910x1004f990
              g_io_channel_new_file3920x1004e7a0
              g_io_channel_new_file_utf83930x1004e1f0
              g_io_channel_read3940x100516f0
              g_io_channel_read_chars3950x10052630
              g_io_channel_read_line3960x10053590
              g_io_channel_read_line_string3970x100533b0
              g_io_channel_read_to_end3980x10052bc0
              g_io_channel_read_unichar3990x10052390
              g_io_channel_ref4000x10050330
              g_io_channel_seek4010x10051510
              g_io_channel_seek_position4020x10050e20
              g_io_channel_set_buffer_size4030x10050080
              g_io_channel_set_buffered4040x1004faf0
              g_io_channel_set_close_on_unref4050x1004fd90
              g_io_channel_set_encoding4060x100509f0
              g_io_channel_set_flags4070x1004fe80
              g_io_channel_set_line_term4080x1004ff60
              g_io_channel_shutdown4090x10051280
              g_io_channel_unix_get_fd4100x1004bd90
              g_io_channel_unix_new4110x1004dfa0
              g_io_channel_unref4120x10051820
              g_io_channel_win32_get_fd4130x1004bb00
              g_io_channel_win32_make_pollfd4140x1004f6e0
              g_io_channel_win32_new_fd4150x1004e060
              g_io_channel_win32_new_messages4160x1004c670
              g_io_channel_win32_new_socket4170x1004c500
              g_io_channel_win32_new_stream_socket4180x1004d5f0
              g_io_channel_win32_poll4190x1004ed50
              g_io_channel_win32_set_debug4200x1004bae0
              g_io_channel_write4210x10051620
              g_io_channel_write_chars4220x10051960
              g_io_channel_write_unichar4230x10053770
              g_io_create_watch4240x10050210
              g_io_watch_funcs4250x100ec9a8
              g_key_file_error_quark4260x10046b10
              g_key_file_free4270x1004b2b0
              g_key_file_get_boolean4280x10049050
              g_key_file_get_boolean_list4290x1004a6f0
              g_key_file_get_comment4300x1004aea0
              g_key_file_get_double4310x10048a20
              g_key_file_get_double_list4320x1004a390
              g_key_file_get_groups4330x100478e0
              g_key_file_get_integer4340x10048d40
              g_key_file_get_integer_list4350x1004a540
              g_key_file_get_keys4360x10047ac0
              g_key_file_get_locale_string4370x1004a8a0
              g_key_file_get_locale_string_list4380x1004af30
              g_key_file_get_start_group4390x10047a60
              g_key_file_get_string4400x10049930
              g_key_file_get_string_list4410x100495f0
              g_key_file_get_value4420x10047770
              g_key_file_has_group4430x10047540
              g_key_file_has_key4440x10047410
              g_key_file_load_from_data4450x1004b310
              g_key_file_load_from_data_dirs4460x1004b980
              g_key_file_load_from_dirs4470x1004b6c0
              g_key_file_load_from_file4480x1004b860
              g_key_file_new4490x1004b690
              g_key_file_remove_comment4500x1004a0b0
              g_key_file_remove_group4510x1004add0
              g_key_file_remove_key4520x10047100
              g_key_file_set_boolean4530x10048fe0
              g_key_file_set_boolean_list4540x10048ec0
              g_key_file_set_comment4550x1004a2b0
              g_key_file_set_double4560x100489a0
              g_key_file_set_double_list4570x10048880
              g_key_file_set_integer4580x10048cd0
              g_key_file_set_integer_list4590x10048bb0
              g_key_file_set_list_separator4600x10047e90
              g_key_file_set_locale_string4610x10049380
              g_key_file_set_locale_string_list4620x100491d0
              g_key_file_set_string4630x10049880
              g_key_file_set_string_list4640x100494c0
              g_key_file_set_value4650x100475d0
              g_key_file_to_data4660x10047c60
              g_list_alloc4670x10045f80
              g_list_append4680x10045e40
              g_list_concat4690x10045a10
              g_list_copy4700x10045da0
              g_list_delete_link4710x10045bf0
              g_list_find4720x10045880
              g_list_find_custom4730x100460d0
              g_list_first4740x100457a0
              g_list_foreach4750x10045740
              g_list_free4760x10045d70
              g_list_free_14770x10045d50
              g_list_index4780x10045800
              g_list_insert4790x10045eb0
              g_list_insert_before4800x10046140
              g_list_insert_sorted4810x100462b0
              g_list_insert_sorted_with_data4820x10046290
              g_list_last4830x100457d0
              g_list_length4840x10045770
              g_list_nth4850x10045930
              g_list_nth_data4860x100458b0
              g_list_nth_prev4870x10045900
              g_list_pop_allocator4880x10045ac0
              g_list_position4890x10045840
              g_list_prepend4900x10045a50
              g_list_push_allocator4910x10045ad0
              g_list_remove4920x10045cc0
              g_list_remove_all4930x10045c30
              g_list_remove_link4940x10045b90
              g_list_reverse4950x10045960
              g_list_sort4960x10045bd0
              g_list_sort_with_data4970x10045bb0
              g_listenv4980x1000d380
              g_locale_from_utf84990x10064010
              g_locale_to_utf85000x10063180
              g_log5010x1003b160
              g_log_default_handler5020x1003b660
              g_log_remove_handler5030x1003b190
              g_log_set_always_fatal5040x10039f50
              g_log_set_default_handler5050x10039ef0
              g_log_set_fatal_mask5060x1003a660
              g_log_set_handler5070x1003b2d0
              g_logv5080x1003ad00
              g_lstat5090x10025440
              g_main_context_acquire5100x100442a0
              g_main_context_add_poll5110x100439a0
              g_main_context_check5120x10042fe0
              g_main_context_default5130x100434b0
              g_main_context_dispatch5140x10042f50
              g_main_context_find_source_by_funcs_user_data5150x10044490
              g_main_context_find_source_by_id5160x100445c0
              g_main_context_find_source_by_user_data5170x100443a0
              g_main_context_get_poll_func5180x100436e0
              g_main_context_get_thread_default5190x10042c40
              g_main_context_is_owner5200x10043570
              g_main_context_iteration5210x10045530
              g_main_context_new5220x10043310
              g_main_context_pending5230x100455e0
              g_main_context_pop_thread_default5240x10044850
              g_main_context_prepare5250x10043b10
              g_main_context_push_thread_default5260x10045080
              g_main_context_query5270x100408b0
              g_main_context_ref5280x100420a0
              g_main_context_release5290x10044130
              g_main_context_remove_poll5300x10043890
              g_main_context_set_poll_func5310x100437b0
              g_main_context_unref5320x10042cc0
              g_main_context_wait5330x10043f00
              g_main_context_wakeup5340x10043610
              g_main_current_source5350x10040ad0
              g_main_depth5360x10040b10
              g_main_loop_get_context5370x10040d30
              g_main_loop_is_running5380x10040db0
              g_main_loop_new5390x10043ab0
              g_main_loop_quit5400x10040e30
              g_main_loop_ref5410x10040f60
              g_main_loop_run5420x10045210
              g_main_loop_unref5430x10042eb0
              g_malloc5440x1003bdd0
              g_malloc05450x1003bd70
              g_mapped_file_free5460x10090920
              g_mapped_file_get_contents5470x10090940
              g_mapped_file_get_length5480x10090980
              g_mapped_file_new5490x100909c0
              g_mapped_file_ref5500x10090890
              g_mapped_file_unref5510x100907d0
              g_markup_collect_attributes5520x1003d460
              g_markup_error_quark5530x1003d0a0
              g_markup_escape_text5540x1003dbb0
              g_markup_parse_context_end_parse5550x1003e460
              g_markup_parse_context_free5560x1003dd80
              g_markup_parse_context_get_element5570x1003dce0
              g_markup_parse_context_get_element_stack5580x1003dca0
              g_markup_parse_context_get_position5590x1003dc40
              g_markup_parse_context_get_user_data5600x1003cad0
              g_markup_parse_context_new5610x1003df40
              g_markup_parse_context_parse5620x1003f200
              g_markup_parse_context_pop5630x1003d360
              g_markup_parse_context_push5640x1003d3e0
              g_markup_printf_escaped5650x1003e430
              g_markup_vprintf_escaped5660x1003e0b0
              g_match_info_expand_references5670x100335d0
              g_match_info_fetch5680x100319b0
              g_match_info_fetch_all5690x10032d70
              g_match_info_fetch_named5700x10032ed0
              g_match_info_fetch_named_pos5710x10032e20
              g_match_info_fetch_pos5720x100318f0
              g_match_info_free5730x10031b90
              g_match_info_get_match_count5740x10031ae0
              g_match_info_get_regex5750x10031c20
              g_match_info_get_string5760x10031be0
              g_match_info_is_partial_match5770x10031a90
              g_match_info_matches5780x10031b40
              g_match_info_next5790x10032f70
              g_mem_chunk_alloc5800x1003c360
              g_mem_chunk_alloc05810x1003c310
              g_mem_chunk_clean5820x1003b8f0
              g_mem_chunk_destroy5830x1003c3b0
              g_mem_chunk_free5840x1003c2c0
              g_mem_chunk_info5850x1003b8c0
              g_mem_chunk_new5860x1003c410
              g_mem_chunk_print5870x1003b8d0
              g_mem_chunk_reset5880x1003b8e0
              g_mem_gc_friendly5890x100fe78c
              g_mem_is_system_malloc5900x1003b900
              g_mem_profile5910x1003c070
              g_mem_set_vtable5920x1003c5f0
              g_memdup5930x10021810
              g_mkdir5940x10024eb0
              g_mkdir_with_parents5950x10058bc0
              g_mkstemp5960x10058150
              g_mkstemp_full5970x100582f0
              g_mkstemp_utf85980x100584f0
              g_node_child_index5990x10038dd0
              g_node_child_position6000x10038e50
              g_node_children_foreach6010x10038c10
              g_node_copy6020x10039bd0
              g_node_copy_deep6030x10039c40
              g_node_depth6040x10038ae0
              g_node_destroy6050x10039910
              g_node_find6060x10039980
              g_node_find_child6070x10038f40
              g_node_first_sibling6080x10038d60
              g_node_get_root6090x10039500
              g_node_insert6100x10039ab0
              g_node_insert_after6110x10039550
              g_node_insert_before6120x100396c0
              g_node_is_ancestor6130x10039470
              g_node_last_child6140x100390e0
              g_node_last_sibling6150x10038d10
              g_node_max_height6160x10038a80
              g_node_n_children6170x10039000
              g_node_n_nodes6180x10039140
              g_node_new6190x10038bf0
              g_node_nth_child6200x10039070
              g_node_pop_allocator6210x10038b10
              g_node_prepend6220x10039a60
              g_node_push_allocator6230x10038b20
              g_node_reverse_children6240x100393f0
              g_node_traverse6250x100391d0
              g_node_unlink6260x10039870
              g_nullify_pointer6270x1000df40
              g_on_error_query6280x10073b40
              g_on_error_stack_trace6290x10073b20
              g_once_impl6300x1001a5b0
              g_once_init_enter6310x1001a750
              g_once_init_enter_impl6320x1001a690
              g_once_init_leave6330x1001ab00
              g_open6340x100251d0
              g_option_context_add_group6350x10035870
              g_option_context_add_main_entries6360x10036170
              g_option_context_free6370x10035b60
              g_option_context_get_description6380x10035230
              g_option_context_get_help6390x10036790
              g_option_context_get_help_enabled6400x10035ac0
              g_option_context_get_ignore_unknown_options6410x10035a20
              g_option_context_get_main_group6420x100357a0
              g_option_context_get_summary6430x100352d0
              g_option_context_new6440x10034ee0
              g_option_context_parse6450x10037ae0
              g_option_context_set_description6460x10035270
              g_option_context_set_help_enabled6470x10035b10
              g_option_context_set_ignore_unknown_options6480x10035a70
              g_option_context_set_main_group6490x100357e0
              g_option_context_set_summary6500x10035310
              g_option_context_set_translate_func6510x10035370
              g_option_context_set_translation_domain6520x10035d80
              g_option_error_quark6530x10034fe0
              g_option_group_add_entries6540x100354e0
              g_option_group_free6550x10035620
              g_option_group_new6560x10034dc0
              g_option_group_set_error_hook6570x10035450
              g_option_group_set_parse_hooks6580x10035490
              g_option_group_set_translate_func6590x100353e0
              g_option_group_set_translation_domain6600x10035de0
              g_parse_debug_string6610x1000cd20
              g_path_get_basename6620x1000d030
              g_path_get_dirname6630x1000e760
              g_path_is_absolute6640x1000ec30
              g_path_skip_root6650x1000ea50
              g_pattern_match6660x10034830
              g_pattern_match_simple6670x10034a80
              g_pattern_match_string6680x10034b30
              g_pattern_spec_equal6690x10034330
              g_pattern_spec_free6700x100343f0
              g_pattern_spec_new6710x10034450
              g_poll6720x10092f60
              g_prefix_error6730x10059550
              g_print6740x1003abd0
              g_printerr6750x1003aaa0
              g_printf6760x1008ed90
              g_printf_string_upper_bound6770x1003a520
              g_propagate_error6780x10059620
              g_propagate_prefixed_error6790x100596a0
              g_ptr_array_add6800x10075420
              g_ptr_array_foreach6810x10075350
              g_ptr_array_free6820x10075930
              g_ptr_array_new6830x10075310
              g_ptr_array_new_with_free_func6840x10075320
              g_ptr_array_ref6850x10075a80
              g_ptr_array_remove6860x10076370
              g_ptr_array_remove_fast6870x100762e0
              g_ptr_array_remove_index6880x10075730
              g_ptr_array_remove_index_fast6890x10075620
              g_ptr_array_remove_range6900x10075490
              g_ptr_array_set_free_func6910x10074c10
              g_ptr_array_set_size6920x10075860
              g_ptr_array_sized_new6930x100752b0
              g_ptr_array_sort6940x100753c0
              g_ptr_array_sort_with_data6950x10076280
              g_ptr_array_unref6960x10075a10
              g_qsort_with_data6970x100923e0
              g_quark_from_static_string6980x1005ec70
              g_quark_from_string6990x1005ed10
              g_quark_to_string7000x1005ea20
              g_quark_try_string7010x1005f390
              g_queue_clear7020x10090690
              g_queue_copy7030x10090040
              g_queue_delete_link7040x10090400
              g_queue_find7050x1008ff50
              g_queue_find_custom7060x1008fec0
              g_queue_foreach7070x1008ffa0
              g_queue_free7080x10090200
              g_queue_get_length7090x10090120
              g_queue_index7100x1008f3f0
              g_queue_init7110x100901b0
              g_queue_insert_after7120x10090300
              g_queue_insert_before7130x1008f350
              g_queue_insert_sorted7140x10090260
              g_queue_is_empty7150x10090160
              g_queue_link_index7160x1008f5b0
              g_queue_new7170x1008f340
              g_queue_peek_head7180x1008f4a0
              g_queue_peek_head_link7190x1008f8d0
              g_queue_peek_nth7200x100903a0
              g_queue_peek_nth_link7210x1008f600
              g_queue_peek_tail7220x1008f440
              g_queue_peek_tail_link7230x1008f890
              g_queue_pop_head7240x1008f9b0
              g_queue_pop_head_link7250x1008f910
              g_queue_pop_nth7260x10090490
              g_queue_pop_nth_link7270x1008f6d0
              g_queue_pop_tail7280x1008f7e0
              g_queue_pop_tail_link7290x1008f740
              g_queue_push_head7300x1008fdb0
              g_queue_push_head_link7310x1008fc10
              g_queue_push_nth7320x1008fd30
              g_queue_push_nth_link7330x10090510
              g_queue_push_tail7340x1008fb80
              g_queue_push_tail_link7350x1008fa60
              g_queue_remove7360x10090760
              g_queue_remove_all7370x100906e0
              g_queue_reverse7380x100900c0
              g_queue_sort7390x1008fe20
              g_queue_unlink7400x1008f500
              g_rand_copy7410x10091880
              g_rand_double7420x100919f0
              g_rand_double_range7430x10091cc0
              g_rand_free7440x100918f0
              g_rand_int7450x100916a0
              g_rand_int_range7460x10091ce0
              g_rand_new7470x100920c0
              g_rand_new_with_seed7480x10091bd0
              g_rand_new_with_seed_array7490x10092090
              g_rand_set_seed7500x10091a60
              g_rand_set_seed_array7510x10091ea0
              g_random_double7520x100921d0
              g_random_double_range7530x10092110
              g_random_int7540x10092330
              g_random_int_range7550x10092280
              g_random_set_seed7560x10091c10
              g_realloc7570x1003bd00
              g_regex_check_replacement7580x100331e0
              g_regex_error_quark7590x10030d20
              g_regex_escape_string7600x10030d50
              g_regex_get_capture_count7610x10030b60
              g_regex_get_max_backref7620x10030b90
              g_regex_get_pattern7630x100317c0
              g_regex_get_string_number7640x10031720
              g_regex_match7650x10033540
              g_regex_match_all7660x10032970
              g_regex_match_all_full7670x100326b0
              g_regex_match_full7680x100333c0
              g_regex_match_simple7690x10033570
              g_regex_new7700x100329a0
              g_regex_ref7710x100318a0
              g_regex_replace7720x100339f0
              g_regex_replace_eval7730x10033710
              g_regex_replace_literal7740x10033950
              g_regex_split7750x100340b0
              g_regex_split_full7760x10033bf0
              g_regex_split_simple7770x100340e0
              g_regex_unref7780x10031800
              g_relation_count7790x100303b0
              g_relation_delete7800x10030710
              g_relation_destroy7810x10030a60
              g_relation_exists7820x100301c0
              g_relation_index7830x100305a0
              g_relation_insert7840x10030800
              g_relation_new7850x10030960
              g_relation_print7860x100309c0
              g_relation_select7870x10030460
              g_reload_user_special_dirs_cache7880x1000dab0
              g_remove7890x10024d40
              g_rename7900x10024f20
              g_return_if_fail_warning7910x1003b620
              g_rmdir7920x10024cd0
              g_scanner_cur_line7930x1002d200
              g_scanner_cur_position7940x1002d1c0
              g_scanner_cur_token7950x1002d2b0
              g_scanner_cur_value7960x1002d240
              g_scanner_destroy7970x1002eae0
              g_scanner_eof7980x1002d150
              g_scanner_error7990x1002d810
              g_scanner_get_next_token8000x1002fe00
              g_scanner_input_file8010x1002d050
              g_scanner_input_text8020x1002cf40
              g_scanner_lookup_symbol8030x1002d420
              g_scanner_new8040x1002d990
              g_scanner_peek_next_token8050x1002fed0
              g_scanner_scope_add_symbol8060x1002d590
              g_scanner_scope_foreach_symbol8070x1002d2f0
              g_scanner_scope_lookup_symbol8080x1002d3b0
              g_scanner_scope_remove_symbol8090x1002d4d0
              g_scanner_set_scope8100x1002d360
              g_scanner_sync_file_offset8110x1002cea0
              g_scanner_unexp_token8120x1002deb0
              g_scanner_warn8130x1002d750
              g_sequence_append8140x1002bd70
              g_sequence_foreach8150x1002bde0
              g_sequence_foreach_range8160x1002bac0
              g_sequence_free8170x1002be30
              g_sequence_get8180x1002b8b0
              g_sequence_get_begin_iter8190x1002b770
              g_sequence_get_end_iter8200x1002b7c0
              g_sequence_get_iter_at_pos8210x1002b710
              g_sequence_get_length8220x1002ac70
              g_sequence_insert_before8230x1002c480
              g_sequence_insert_sorted8240x1002c320
              g_sequence_insert_sorted_iter8250x1002bf70
              g_sequence_iter_compare8260x1002c4f0
              g_sequence_iter_get_position8270x1002b550
              g_sequence_iter_get_sequence8280x1002b930
              g_sequence_iter_is_begin8290x1002b5a0
              g_sequence_iter_is_end8300x1002b5f0
              g_sequence_iter_move8310x1002b430
              g_sequence_iter_next8320x1002b500
              g_sequence_iter_prev8330x1002b4b0
              g_sequence_move8340x1002b640
              g_sequence_move_range8350x1002c610
              g_sequence_new8360x1002b360
              g_sequence_prepend8370x1002bcf0
              g_sequence_range_get_midpoint8380x1002b980
              g_sequence_remove8390x1002c3d0
              g_sequence_remove_range8400x1002c820
              g_sequence_search8410x1002c210
              g_sequence_search_iter8420x1002beb0
              g_sequence_set8430x1002b800
              g_sequence_sort8440x1002c9f0
              g_sequence_sort_changed8450x1002c290
              g_sequence_sort_changed_iter8460x1002c060
              g_sequence_sort_iter8470x1002c8a0
              g_sequence_swap8480x1002bbf0
              g_set_application_name8490x1000e360
              g_set_error8500x10059730
              g_set_error_literal8510x10059490
              g_set_prgname8520x1000dbe0
              g_set_print_handler8530x10039d30
              g_set_printerr_handler8540x10039ce0
              g_setenv8550x1000ee30
              g_setenv_utf88560x1000e570
              g_shell_error_quark8570x1008df50
              g_shell_parse_argv8580x1008e8e0
              g_shell_quote8590x1008e2d0
              g_shell_unquote8600x1008e730
              g_slice_alloc8610x1002a430
              g_slice_alloc08620x1002a580
              g_slice_copy8630x1002a540
              g_slice_free18640x100299b0
              g_slice_free_chain_with_offset8650x100297a0
              g_slice_get_config8660x10028720
              g_slice_get_config_state8670x1002a5c0
              g_slice_set_config8680x1002a6f0
              g_slist_alloc8690x10028020
              g_slist_append8700x10027ef0
              g_slist_concat8710x10027b70
              g_slist_copy8720x10027e70
              g_slist_delete_link8730x10027d00
              g_slist_find8740x10027a10
              g_slist_find_custom8750x10028160
              g_slist_foreach8760x10027900
              g_slist_free8770x10027d60
              g_slist_free_18780x10027d40
              g_slist_index8790x10027990
              g_slist_insert8800x10027f50
              g_slist_insert_before8810x100281d0
              g_slist_insert_sorted8820x100282f0
              g_slist_insert_sorted_with_data8830x100282d0
              g_slist_last8840x10027960
              g_slist_length8850x10027930
              g_slist_nth8860x10027a90
              g_slist_nth_data8870x10027a40
              g_slist_pop_allocator8880x10027bd0
              g_slist_position8890x100279d0
              g_slist_prepend8900x10027ba0
              g_slist_push_allocator8910x10027be0
              g_slist_remove8920x10027e00
              g_slist_remove_all8930x10027d90
              g_slist_remove_link8940x10027ca0
              g_slist_reverse8950x10027ac0
              g_slist_sort8960x10027ce0
              g_slist_sort_with_data8970x10027cc0
              g_snprintf8980x1008eba0
              g_source_add_poll8990x10041ac0
              g_source_attach9000x100446c0
              g_source_destroy9010x10042bd0
              g_source_get_can_recurse9020x10041450
              g_source_get_context9030x10041c40
              g_source_get_current_time9040x10040c40
              g_source_get_id9050x10041c90
              g_source_get_priority9060x10041590
              g_source_is_destroyed9070x10040380
              g_source_new9080x10041f40
              g_source_ref9090x10041370
              g_source_remove9100x10045010
              g_source_remove_by_funcs_user_data9110x10044f60
              g_source_remove_by_user_data9120x10044fd0
              g_source_remove_poll9130x10041950
              g_source_set_callback9140x10042b50
              g_source_set_callback_indirect9150x10041810
              g_source_set_can_recurse9160x100414a0
              g_source_set_funcs9170x10041730
              g_source_set_priority9180x100415d0
              g_source_unref9190x10042b00
              g_spaced_primes_closest9200x10034140
              g_spawn_async9210x10026f50
              g_spawn_async_utf89220x10026d80
              g_spawn_async_with_pipes9230x10026df0
              g_spawn_async_with_pipes_utf89240x10026c50
              g_spawn_close_pid9250x10025460
              g_spawn_command_line_async9260x10027620
              g_spawn_command_line_async_utf89270x10026f90
              g_spawn_command_line_sync9280x100277d0
              g_spawn_command_line_sync_utf89290x10027730
              g_spawn_error_quark9300x10025890
              g_spawn_sync9310x100276b0
              g_spawn_sync_utf89320x10027020
              g_sprintf9330x1008ed10
              g_stat9340x10025350
              g_static_mutex_free9350x1001c310
              g_static_mutex_get_mutex_impl9360x1001ac10
              g_static_mutex_init9370x1001c380
              g_static_private_free9380x1001ae00
              g_static_private_get9390x1001a8f0
              g_static_private_init9400x1001a5a0
              g_static_private_set9410x1001a950
              g_static_rec_mutex_free9420x1001c470
              g_static_rec_mutex_init9430x1001c2b0
              g_static_rec_mutex_lock9440x1001c1a0
              g_static_rec_mutex_lock_full9450x1001bec0
              g_static_rec_mutex_trylock9460x1001c070
              g_static_rec_mutex_unlock9470x1001bfd0
              g_static_rec_mutex_unlock_full9480x1001be10
              g_static_rw_lock_free9490x1001c3d0
              g_static_rw_lock_init9500x1001b730
              g_static_rw_lock_reader_lock9510x1001b620
              g_static_rw_lock_reader_trylock9520x1001b520
              g_static_rw_lock_reader_unlock9530x1001b440
              g_static_rw_lock_writer_lock9540x1001b330
              g_static_rw_lock_writer_trylock9550x1001b240
              g_static_rw_lock_writer_unlock9560x1001b170
              g_stpcpy9570x10021520
              g_str_equal9580x1001fa90
              g_str_has_prefix9590x10022050
              g_str_has_suffix9600x10022110
              g_str_hash9610x1001fa30
              g_strcanon9620x10023190
              g_strcasecmp9630x10023430
              g_strchomp9640x10022a00
              g_strchug9650x10022a90
              g_strcmp09660x1001c730
              g_strcompress9670x10022f60
              g_strconcat9680x10021690
              g_strdelimit9690x10023240
              g_strdown9700x100237f0
              g_strdup9710x10021850
              g_strdup_printf9720x10021ad0
              g_strdup_vprintf9730x10021aa0
              g_strdupv9740x10021a00
              g_strerror9750x10021ef0
              g_strescape9760x10022b30
              g_strfreev9770x10021640
              g_string_append9780x10020260
              g_string_append_c9790x10020b90
              g_string_append_len9800x100201d0
              g_string_append_printf9810x10020350
              g_string_append_unichar9820x10020b40
              g_string_append_uri_escaped9830x10020be0
              g_string_append_vprintf9840x100200f0
              g_string_ascii_down9850x10020610
              g_string_ascii_up9860x10020590
              g_string_assign9870x10020e70
              g_string_chunk_clear9880x10021070
              g_string_chunk_free9890x10021250
              g_string_chunk_insert9900x10021020
              g_string_chunk_insert_const9910x100211a0
              g_string_chunk_insert_len9920x10020f10
              g_string_chunk_new9930x1001fb10
              g_string_down9940x100204f0
              g_string_equal9950x1001f970
              g_string_erase9960x1001f710
              g_string_free9970x100203d0
              g_string_hash9980x1001f910
              g_string_insert9990x100208c0
              g_string_insert_c10000x1001fcb0
              g_string_insert_len10010x1001fdb0
              g_string_insert_unichar10020x100206f0
              g_string_new10030x100202e0
              g_string_new_len10040x10020380
              g_string_overwrite10050x10020690
              g_string_overwrite_len10060x1001fb70
              g_string_prepend10070x10020ac0
              g_string_prepend_c10080x100209e0
              g_string_prepend_len10090x10020a30
              g_string_prepend_unichar10100x10020990
              g_string_printf10110x10021130
              g_string_set_size10120x10020d70
              g_string_sized_new10130x10020020
              g_string_truncate10140x10020df0
              g_string_up10150x10020450
              g_string_vprintf10160x10021170
              g_strip_context10170x10021300
              g_strjoin10180x100218b0
              g_strjoinv10190x10022410
              g_strlcat10200x100239c0
              g_strlcpy10210x10023ae0
              g_strncasecmp10220x100232d0
              g_strndup10230x100217c0
              g_strnfill10240x10021780
              g_strreverse10250x100236c0
              g_strrstr10260x100221d0
              g_strrstr_len10270x10024870
              g_strsignal10280x10021b00
              g_strsplit10290x10022800
              g_strsplit_set10300x10022560
              g_strstr_len10310x100222e0
              g_strtod10320x100247a0
              g_strup10330x10023760
              g_strv_length10340x10021ff0
              g_test_add_data_func10350x1001e250
              g_test_add_func10360x1001e310
              g_test_add_vtable10370x1001dec0
              g_test_bug10380x1001dc10
              g_test_bug_base10390x1001ca90
              g_test_config_vars10400x100bf5f4
              g_test_create_case10410x1001da80
              g_test_create_suite10420x1001d9a0
              g_test_get_root10430x1001dbc0
              g_test_init10440x1001f290
              g_test_log_buffer_free10450x1001cdd0
              g_test_log_buffer_new10460x1001cac0
              g_test_log_buffer_pop10470x1001cd40
              g_test_log_buffer_push10480x1001cb50
              g_test_log_msg_free10490x1001c870
              g_test_log_set_fatal_handler10500x10039ea0
              g_test_log_type_name10510x1001c780
              g_test_maximized_result10520x1001d520
              g_test_message10530x1001d4d0
              g_test_minimized_result10540x1001d580
              g_test_queue_destroy10550x1001d810
              g_test_queue_free10560x1001d880
              g_test_rand_double10570x1001e3d0
              g_test_rand_double_range10580x1001ead0
              g_test_rand_int10590x1001e080
              g_test_rand_int_range10600x1001eb00
              g_test_run10610x1001f6f0
              g_test_run_suite10620x1001f500
              g_test_suite_add10630x1001d920
              g_test_suite_add_suite10640x1001d8a0
              g_test_timer_elapsed10650x1001dd20
              g_test_timer_last10660x1001c770
              g_test_timer_start10670x1001dd60
              g_test_trap_assertions10680x1001c6e0
              g_test_trap_fork10690x1001d7f0
              g_test_trap_has_passed10700x1001c710
              g_test_trap_reached_timeout10710x1001c6f0
              g_thread_create_full10720x1001bab0
              g_thread_error_quark10730x1001aae0
              g_thread_exit10740x1001a8c0
              g_thread_foreach10750x1001afb0
              g_thread_functions_for_glib_use10760x100d5de0
              g_thread_get_initialized10770x1001a4e0
              g_thread_gettime10780x100d5dbc
              g_thread_init_glib10790x1001c4c0
              g_thread_join10800x1001b8c0
              g_thread_pool_free10810x10019c10
              g_thread_pool_get_max_idle_time10820x100193b0
              g_thread_pool_get_max_threads10830x10019530
              g_thread_pool_get_max_unused_threads10840x100193d0
              g_thread_pool_get_num_threads10850x10019480
              g_thread_pool_get_num_unused_threads10860x100193c0
              g_thread_pool_new10870x1001a280
              g_thread_pool_push10880x1001a1b0
              g_thread_pool_set_max_idle_time10890x100195e0
              g_thread_pool_set_max_threads10900x1001a020
              g_thread_pool_set_max_unused_threads10910x10019720
              g_thread_pool_set_sort_function10920x10019650
              g_thread_pool_stop_unused_threads10930x100198b0
              g_thread_pool_unprocessed10940x100193e0
              g_thread_self10950x1001a770
              g_thread_set_priority10960x1001b780
              g_thread_use_default_impl10970x100d5dc0
              g_threads_got_initialized10980x100fe8c0
              g_time_val_add10990x10018ff0
              g_time_val_from_iso860111000x10018bd0
              g_time_val_to_iso860111010x10018ac0
              g_timeout_add11020x100451f0
              g_timeout_add_full11030x10044b50
              g_timeout_add_seconds11040x100451a0
              g_timeout_add_seconds_full11050x10044ab0
              g_timeout_funcs11060x100e6bcc
              g_timeout_source_new11070x10042220
              g_timeout_source_new_seconds11080x100421c0
              g_timer_continue11090x100191b0
              g_timer_destroy11100x10019370
              g_timer_elapsed11110x10019100
              g_timer_new11120x10018a80
              g_timer_reset11130x10019270
              g_timer_start11140x10019320
              g_timer_stop11150x100192c0
              g_trash_stack_height11160x1000cbc0
              g_trash_stack_peek11170x1000cc00
              g_trash_stack_pop11180x1000cc20
              g_trash_stack_push11190x1000cc50
              g_tree_destroy11200x100188b0
              g_tree_foreach11210x10017760
              g_tree_height11220x10017580
              g_tree_insert11230x10018590
              g_tree_lookup11240x10017870
              g_tree_lookup_extended11250x100177f0
              g_tree_new11260x100187e0
              g_tree_new_full11270x10018700
              g_tree_new_with_data11280x10018790
              g_tree_nnodes11290x10017540
              g_tree_ref11300x100185e0
              g_tree_remove11310x10018080
              g_tree_replace11320x10018540
              g_tree_search11330x10017630
              g_tree_steal11340x10018020
              g_tree_traverse11350x10017690
              g_tree_unref11360x10018830
              g_try_malloc11370x1003bca0
              g_try_malloc011380x1003beb0
              g_try_realloc11390x1003bc50
              g_tuples_destroy11400x1002ffd0
              g_tuples_index11410x10030320
              g_ucs4_to_utf1611420x100119e0
              g_ucs4_to_utf811430x10011bc0
              g_unichar_break_type11440x10016e30
              g_unichar_combining_class11450x10015bb0
              g_unichar_digit_value11460x10012ca0
              g_unichar_get_mirror_char11470x10012720
              g_unichar_get_script11480x100142b0
              g_unichar_isalnum11490x100141a0
              g_unichar_isalpha11500x10014090
              g_unichar_iscntrl11510x10013f80
              g_unichar_isdefined11520x10013420
              g_unichar_isdigit11530x10013e70
              g_unichar_isgraph11540x10013d60
              g_unichar_islower11550x10013c50
              g_unichar_ismark11560x100137c0
              g_unichar_isprint11570x10013b40
              g_unichar_ispunct11580x10013a30
              g_unichar_isspace11590x100138d0
              g_unichar_istitle11600x10013670
              g_unichar_isupper11610x100136b0
              g_unichar_iswide11620x100144d0
              g_unichar_iswide_cjk11630x10014c50
              g_unichar_isxdigit11640x10013530
              g_unichar_iszerowidth11650x100132d0
              g_unichar_to_utf811660x100109e0
              g_unichar_tolower11670x10012e40
              g_unichar_totitle11680x10014350
              g_unichar_toupper11690x10013070
              g_unichar_type11700x100129d0
              g_unichar_validate11710x100102e0
              g_unichar_xdigit_value11720x10012ad0
              g_unicode_canonical_decomposition11730x10016640
              g_unicode_canonical_ordering11740x10015730
              g_unlink11750x10024dd0
              g_unsetenv11760x1000edf0
              g_unsetenv_utf811770x1000e420
              g_uri_escape_string11780x1008bed0
              g_uri_list_extract_uris11790x10062900
              g_uri_parse_scheme11800x1008be00
              g_uri_unescape_segment11810x1008bcd0
              g_uri_unescape_string11820x1008bde0
              g_usleep11830x10018a20
              g_utf16_to_ucs411840x10012040
              g_utf16_to_utf811850x100115f0
              g_utf8_casefold11860x10014dc0
              g_utf8_collate11870x10016a00
              g_utf8_collate_key11880x10016840
              g_utf8_collate_key_for_filename11890x10016b90
              g_utf8_find_next_char11900x10010dd0
              g_utf8_find_prev_char11910x10010e50
              g_utf8_get_char11920x10010c40
              g_utf8_get_char_validated11930x10010f00
              g_utf8_normalize11940x10016750
              g_utf8_offset_to_pointer11950x10010bb0
              g_utf8_pointer_to_offset11960x10010b40
              g_utf8_prev_char11970x10010da0
              g_utf8_skip11980x10095b3c
              g_utf8_strchr11990x100125e0
              g_utf8_strdown12000x10014d20
              g_utf8_strlen12010x100124e0
              g_utf8_strncpy12020x10010ad0
              g_utf8_strrchr12030x10012630
              g_utf8_strreverse12040x100110c0
              g_utf8_strup12050x10015420
              g_utf8_to_ucs412060x10011d60
              g_utf8_to_ucs4_fast12070x100122d0
              g_utf8_to_utf1612080x10011330
              g_utf8_validate12090x10010e90
              g_utime12100x10024ae0
              g_vasprintf12110x1008eaa0
              g_vfprintf12120x1008ec70
              g_vprintf12130x1008ecc0
              g_vsnprintf12140x1008eb10
              g_vsprintf12150x1008ebe0
              g_warn_message12160x1003a550
              g_win32_error_message12170x1000c320
              g_win32_ftruncate12180x1000bfb0
              g_win32_get_package_installation_directory12190x1000c730
              g_win32_get_package_installation_directory_of_module12200x1000c240
              g_win32_get_package_installation_directory_utf812210x1000c660
              g_win32_get_package_installation_subdirectory12220x1000c7e0
              g_win32_get_package_installation_subdirectory_utf812230x1000c6e0
              g_win32_get_system_data_dirs_for_module12240x1000e0f0
              g_win32_get_windows_version12250x1000c6c0
              g_win32_getlocale12260x1000bfd0
              g_win32_locale_filename_from_utf812270x1000c170
              glib_binary_age12280x10095b18
              glib_check_version12290x1000cb40
              glib_gettext12300x1000da40
              glib_interface_age12310x10095b14
              glib_major_version12320x10095b08
              glib_mem_profiler_table12330x100e4f98
              glib_micro_version12340x10095b10
              glib_minor_version12350x10095b0c
              glib_on_error_halt12360x100fc650
              Language of compilation systemCountry where language is spokenMap
              EnglishUnited States
              No network behavior found

              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:16:50:55
              Start date:29/10/2024
              Path:C:\Windows\System32\loaddll32.exe
              Wow64 process (32bit):true
              Commandline:loaddll32.exe "C:\Users\user\Desktop\glib-2.0.dll"
              Imagebase:0xe30000
              File size:126'464 bytes
              MD5 hash:51E6071F9CBA48E79F10C84515AAE618
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:1
              Start time:16:50:55
              Start date:29/10/2024
              Path:C:\Windows\System32\conhost.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Imagebase:0x7ff7699e0000
              File size:862'208 bytes
              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:2
              Start time:16:50:55
              Start date:29/10/2024
              Path:C:\Windows\SysWOW64\cmd.exe
              Wow64 process (32bit):true
              Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1
              Imagebase:0x240000
              File size:236'544 bytes
              MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:3
              Start time:16:50:55
              Start date:29/10/2024
              Path:C:\Windows\SysWOW64\rundll32.exe
              Wow64 process (32bit):true
              Commandline:rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_flags
              Imagebase:0x690000
              File size:61'440 bytes
              MD5 hash:889B99C52A60DD49227C5E485A016679
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:4
              Start time:16:50:55
              Start date:29/10/2024
              Path:C:\Windows\SysWOW64\rundll32.exe
              Wow64 process (32bit):true
              Commandline:rundll32.exe "C:\Users\user\Desktop\glib-2.0.dll",#1
              Imagebase:0x690000
              File size:61'440 bytes
              MD5 hash:889B99C52A60DD49227C5E485A016679
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:5
              Start time:16:50:58
              Start date:29/10/2024
              Path:C:\Windows\SysWOW64\rundll32.exe
              Wow64 process (32bit):true
              Commandline:rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,_g_debug_initialized
              Imagebase:0x690000
              File size:61'440 bytes
              MD5 hash:889B99C52A60DD49227C5E485A016679
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:6
              Start time:16:51:01
              Start date:29/10/2024
              Path:C:\Windows\SysWOW64\rundll32.exe
              Wow64 process (32bit):true
              Commandline:rundll32.exe C:\Users\user\Desktop\glib-2.0.dll,g_access
              Imagebase:0x690000
              File size:61'440 bytes
              MD5 hash:889B99C52A60DD49227C5E485A016679
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              No disassembly