Static | ZeroBOX

PE Compile Time

2009-02-15 09:17:38

PDB Path

c:\anyview\Thicknight\inrise\offer.pdb

PE Imphash

aea7cd92e8d54732bbabf352b513d261

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000c7c8e 0x000c7e00 6.10393555501
.data 0x000c9000 0x00060f1c 0x00000e00 2.65105789774
.rsrc 0x0012a000 0x00000388 0x00000400 2.98399514547
.reloc 0x0012b000 0x00001f24 0x00002000 3.99301850563

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0012a060 0x00000328 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library USER32.dll:
0x1001134 SetParent
0x1001138 EndDeferWindowPos
0x100113c ExitWindowsEx
0x1001140 IntersectRect
0x1001144 InflateRect
Library ole32.dll:
0x1001168 CoTaskMemAlloc
0x100116c CoTaskMemFree
0x1001170 CoInitialize
0x1001174 CoUninitialize
Library VERSION.dll:
0x1001158 VerQueryValueA
0x100115c GetFileVersionInfoA
Library UxTheme.dll:
0x100114c DrawThemeBackground
0x1001150 CloseThemeData
Library MPR.dll:
0x1001124 WNetGetUniversalNameA
0x1001128 WNetGetUserA
0x100112c WNetAddConnection2A
Library GPEDIT.DLL:
0x1001000 CreateGPOLink
0x1001004 DeleteGPOLink
0x1001008 ExportRSoPData
0x100100c BrowseForGPO
Library KERNEL32.dll:
0x1001014 HeapSize
0x1001018 LCMapStringW
0x100101c LCMapStringA
0x1001020 GetStringTypeW
0x1001024 MultiByteToWideChar
0x1001028 GetStringTypeA
0x100102c RtlUnwind
0x1001034 LoadLibraryA
0x1001038 GetLocaleInfoA
0x100103c GetStdHandle
0x1001040 CreateEventA
0x1001048 GetVersion
0x100104c GetModuleHandleA
0x1001054 EnterCriticalSection
0x1001058 VirtualProtectEx
0x100105c Sleep
0x1001060 GetTempPathA
0x1001064 OpenMutexA
0x100106c GetCurrentThreadId
0x1001070 GetCommandLineA
0x1001074 GetModuleHandleW
0x1001078 GetProcAddress
0x100107c TlsGetValue
0x1001080 TlsAlloc
0x1001084 TlsSetValue
0x1001088 TlsFree
0x100108c InterlockedIncrement
0x1001090 SetLastError
0x1001094 GetLastError
0x1001098 InterlockedDecrement
0x100109c HeapFree
0x10010a0 ExitProcess
0x10010a4 SetHandleCount
0x10010a8 GetFileType
0x10010ac GetStartupInfoA
0x10010b0 DeleteCriticalSection
0x10010b4 GetModuleFileNameA
0x10010bc GetEnvironmentStrings
0x10010c4 WideCharToMultiByte
0x10010cc HeapCreate
0x10010d0 HeapDestroy
0x10010d4 VirtualFree
0x10010dc GetTickCount
0x10010e0 GetCurrentProcessId
0x10010e8 LeaveCriticalSection
0x10010ec GetCPInfo
0x10010f0 GetACP
0x10010f4 GetOEMCP
0x10010f8 IsValidCodePage
0x10010fc HeapAlloc
0x1001100 VirtualAlloc
0x1001104 HeapReAlloc
0x1001108 WriteFile
0x100110c TerminateProcess
0x1001110 GetCurrentProcess
0x100111c IsDebuggerPresent

Exports

Ordinal Address Name
1 0x10c1000 Dangerbeauty
2 0x10c1820 Settlehear
!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
r(xq_63
6l1:lk
<8;;;;
9999{{{{
8888;;;;
9999{{{{
'Ru}+wIT
tcM|V{k
SyQ9K{{*
CBB>y)XQ9
4<;Ru}
19kn*+
@VWATH
?4V9kf
<i*,yy
^2X-Ak
DmU"iq
x{^|nDg
@VWATH
|$`HcG
@VWATH
|$`HcG
~@clji
m$if]O
UATAUAVAWH
1TA)`<
>yS-,J
!ZtD]-7
2lmEy?
l>uA)Up,
$ HLJH +0$
L$[HsGH
0I\\I$
%HUGH$
^[$HHH$
:`bO<|
t4^e(
A\DyH
lHoLa&
{}G&fV
QH0HftH
0$HDXH
yO/'sW
AWt@T$
VScorq
U'(DHE
MWHHPG
z45Ul2Y
~jT[f?tH
LL`h`3
IH((H0I$
HXdHA($t
s;I_T\
kAHM-H
H xuHD%
Hh33D$
HPtHHu
MXH8H$
I.;H$0I
tLHUH$
$0HAHW
U$H\H@
%H$EzH
sJ`;'{]<x
5J)kh@
!@e5]:
H$$T0H
HQH*wk
}]V4N
t8HIuX
sXM@(t
]HHkHH
HHHH3(;
uHLC[H
WXXh9X
g,H6cC
T$$D3H
$eHDHE
%EHHZ$
vHvHH0
mV,81
KWurQ|(
E30$LH
H[\\H1HU
t$H:$D~
^|T4__
HHD#HL0
$HtPHUJM=
$Vl:N}
|3!:y?>
H$D tH
$H @H@
#RT_/T
=99Fix|9
$X$HfH
%$u]3H$
$H$|HH
>i+=(>
@HtUHA0SI0
`C'|(l
qLSH0H
M_i@>N2
;[\6UH
HH`\0|
H'8HL0
H$Pb8H
MHHm@H
Lt#HHp
M^ZtOr
Otvd*qu
,tH` L
$HH$D$
dC_PAL
7iV^:"
@m*SRx
*uKd;
H\7E0H$
I}LJlH
T`0AH\g
Q#^P=S5
{\;U\m
HH=3_M
HlIH^H
$H\:kZ
H$~HH;H
*{U{h^
mmF(~3
zwfR!V
fJ}y0v
+q,xv&
4r~7Sv
TA6Gvw
I\|LH|
\AHE^$
7vAtK(
x$$[3H
H;H]HHP
HH$LOI
tEs_H
wO8$H\
H HHt|
Wv_avx
UmmNTu9
mz2?]H
H$UI$A
AHSHWf$
MHHLHH
#{kLT$uq
aShvrv
HHH.HF
H>WnHW
'Hpx~#}v
HVA%`w
i1u%1Eq
HA xHs
(n5J:$;
pUAH|*
_HAHIA
c]OL@$
ztYU7*Z
H$tKON
HH(U$t
<+` HHA
@:tLPD3
6lKe54
/JmxJw
M$K;ML
HH>`[u
H2jDLAD@cH
`HyHA
M <HO
{B1X!L5_
$HC0L@H
^'HA$ $
$HH%0H
HIHH3L
BHH$$X
y)Sko*
t^EnHIH
$U` HD
yGE?Mv
LXLE}SH
H $HPDS
PHFfHM
AdOHL
-:k"k6
CI-E'$
;MAL#3
C$@LCLHH
t7H S{M!H
H0LHDH
DE$+Cc
^h8HK((
&lDLu!
3IHLHg
HTt@S1
HH0H`H
LH>H p
HHE IHSH
PHH$#V
t$H;HH
UL]_HH
|tLIHH
H@HHHHPH
D\HHHH
CHLHcMt
t H.HB
S@HMHx
I*LpEHL
$%|HLH
HPE "K
$HHAH0(`W
HHHPb!
`IS0S3
H~tLtL
HH3HU3T
HHC08p
Hp;LTHP
HLtH3E
Hc)T@LAI%
SH%,D"
$$V@ L
$HLLP]
|H8`tL
H$rt@O
HvH$2H
L8HXA
HL/H(Hm
D{Qx t\H
$$H$$p$
H$H$LMHI
HIHHHA
DWDT3H
HH8HGIH
HHtH_HW
HPHH$C
H2[0SL
HHHS$H
H-HcHt
LHKCTH
8HX/3H]
H$LLE
D<Hx(TH
:HkHpH
HLeLSE
V$H(HHMg
;@5+H
HH$LE37
IwVHt3
U-&fH}
HWMIdX
S HHL.@
H\u;334;]
MOH $MH
&t<H\B
`UHDH]H/
=I}*Hu
~\GH;f
t=LtH8
tH(D0D
3H!HD
.$LU$H
H(PH(H$
@UH$1HH"\
RtHHHl
HH\fzH
LVbHL$AH0HMM
$H0E[7
X$HHPO
%\tHHt
H];&hL%
$H HtIHg
HMH%HK
LUtZ$M
XHHH]HLM<
8HHM+\
yC\HL@
I+$.oH@
8@pyMH
H$HK$c
SpH_H;t
AH2uuQ
AHvIHJ
HH H]`
Ht9f_
H$$HH%
p$0fHHG
H$HL=y\
(A\0HL
fMK$H#
HH%LIH
D;$_H"
H$h P
D3HUHL
AZAxxt(
$H0H%X
M$ L$L
\MJ8HH[
HHAXM.
IH$?HH
HDPLL$`
DA[|AH
H0LMA$
@<V$7H
"$u-]%HH
EU3H^T
TL'LCH
DHDH$=
8CHDDH$
p %H{H
$-SC E
A0H@H _
HH:DL^
$3Ht HZ
J0HHH7
'*tXTAt
L(EHtH
HH^([H
0I%q t
L@$H(8
MHXLTH
L$d%/
HH@W]H{
HsW $O
H_(H!IW
UHV%DHM
$HWHhH
$$HtH^$
HGQH@H
^MHuH;H
IHZHAHH
`tHH[QWHHt'
H$;$`I$@
x/HI t\
xPAD4J
H@&%EH
3pHHL"
AtLuHH
`LAAHHS
D[s_3MS
t$HAHH\
hHtH$NPI
HH$E;&
?HHHSHW
HH P_L
(0HH@:
{KtHHH
HT8HHC
$HI$H\
HH%HM@
hXHM 8L
DtHH:H
Ht#H^HUH
$EHc H
8Hf@LY
HO JCH
tn}0 A
DHHHF$$
H0C]IH
HI$AHH
HAH`C
4H $_
M$LHHH$G7
HP\xHjJ
rxA)H$A
H@H $]c
HtH+$t
N0L@HH
@AH}lHH
LH hI$H
z0% \LX
V3HEHHH H)
9IHS2$u0
GMIDHH
LHHp8cH
_L`H=t
tH`\E%L
xHH\LoK
{t;$HP
3HHS0$
XLHxHH
t*H*H H
$0TH%$0
HxLDAHH
IHtHLH
9$HH(0
`M;N#A
EcHXF%H
H$@LH_\H
OPHT$DH0
zHHH,_
H_HPLH
xDOiHP
K,]_D|
H+PS*HtH
H((<@S
rH`H[W)+
@ @nnSOH
tC *W$Ht
Mxf@H`
a8H$HH
Lz0 u'
yHHLt+
$UHg[E
HSHVLH
[$$$,T
HXt D~
It8$tAH
HHHF_U
PHH@H]
HtX`HH@
HXHH^}
] StN=
$7HDH`
Lt HH
@1HHHKL
0\HH$H
MHM I
H2HH$U
HHH=;9
H%HHAL
`3HHSH
HSLs$$P
tuLH$$00
DK0HHH
$HHhC
SHtM@HULH
H ACP$
$[HHHH
'CHHLD
SE0=Ht
EHGH`E
$;_txH$0
O0MH{t
\H$HOS
!HHHHC M
.1%HHE$
HHLHHH
H.0HG-
$^MHHt
5HHP1-2P
XAS$Lt
\3hDHH$$
A@@HHH
Hx*]HH
HHT%C7x
HDHt 3H
\zDhH$
0 1K`KF
pXHtHq
HH HDH;
0_^tA HHD$
H D^Ec
0%&`~H
H*8* t
Green e
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
c:\anyview\Thicknight\inrise\offer.pdb
$tKM=3
pA>8~"
%%%0$#&
L32h~\
akeo*o
###w)))
y(^bh_?
E~C7d/
-3,,/+-
4#-&4(
"-3/%&&
%!*+!'+
,-1&3"*
,)%.,,
%+10)#-
"+502"
[(wRYn<n
1.!.,
)'/%((
&)(*1.
0.1-+
4.2$.D)$2
sGVlnS
Mr[!z`F
21>4t
1%2.2'
-+/2'$
,$33()%
?n.hlO
6 +1(!/
/))/2
g6Ox)K
#2-,!%
/2 .-
/$'$!"
Z@;YDi
#.+#).
33,*+/
/$)*,-
* 1.113&
3'!0!,
B0}_V7
!*oS?b
RBgZ^l
!#00).
,$)&/.
&.%,'"2$
$3'"$04211
v~#=;!/
20(&1&&)14
J>YjyD
\y#SntYJ
qaJezvv ]
/!(+(
l/i\#ki
]dnl"(
+1'((
)5"!81
441!$@
0$/*%"
CkfgX<{k
@^H%Ab
"0+#+0*
1.)1 -
00(2$ 0/
*+$"#+
.*-*/-+
.*!,'0
!,T.4F.,,0
{>}VcD
71v5w,
~A,WF
6P/w?~
41".23
%+1)."/
$-%-!
-m"nJ?A:q
@%n`1+k
"1")4-
#0-2.,
-2X{i
U`"o2
=yp:P1
(0%)Z0
wQ_~4y
0*3"$)0-$
1/34022
/&330,2
2,%0.(%
(,$..,
*#$,-!+"1)! !)$
2/,))'&(
"31#A4
2",.20
0hg3N\/`Y
]xraz4
1y IQ6hA
11.'2-,(
M-.3%/
1**&000 -
#.#*Vk
*kPJ%x
*($+30%3,0)
$-"x21
02&,%/
)%-!("
9ZT_k}
y8:" q
!%*+&.2
&,(%#&
10+w$3
%%3!%1
bT%>PA
')"!!.(*-2
+!2,/2
oBI}*=
^JSM:
"--")4
&+"(22
")+0'3
%#-)#3(..
%..*/#(
7=1.I`
(3-C |
bMzyi2
*1 .B
0 1423
/%2'.0
0'&!'"D
`VO^>Y
@_|>M#o5+
33'0,)
,(1'C# 5
*/23)(
'33".'2
mLylY2-
,)3 -!/
;1=);;
.F6<^p
m/1+-$1
.1%&2",
6(.5.2
ryv\uG
\F&U\[
5<~!aT!
3)!%'*
32-&6)
&4(0"*
*!4)0
'5I ])
12/!'%
.,2433
(-/%)(!)
q,<eBP_(X
#"-)$/
,2%#$)-
3($-"/
*2%(2
%R-'-2$/
!32!!,2
!-$!44
xmYQn5
2!!$/
$2+'3
'*"#-!
/32*4.
!2D*s+
../$-1"
')3T-5"
*+& !2
HY}2r<
!3$1+"1&'
3"#)14
Gx2gHuv;
#46~M[h
>_MU<x
'(4.-
!4/3,3
s&TdfA
"'(#%!
2.2'5)4
3-#,,*
6+kQ;4
m<b8o[
&$14).10
$+'+'4
A;lW/z
IK#j7*.f
2 *')5
$ "(
1'0&(+3
1&113
||V'_{
Z2*1'-;
1&/22&
,)2 ))
j=e-b_ZL
%-43*"!
v]qb$8]UUB
[*Qol`cR;&
'**)2$
!$0+&$
"$-!1/
!!-11"
&#1)+/
E*$-&'
(*-&(*
1&0!+'
..,($&
0,03+)
2"3($&
5!5$!#
&12"#'
*%2 * !1
#&)//24*
2-'24*
2#+!%,
"+&-!00
0& ,%%
*$"1)!
!.2',2
-$11/"
&$,%*!
!(&1#.3
/*"*(*0#2
10''!
4!/ -3
4&&8$1/
X'"&,$
&221)3
-3&.'*0
,& -/1$
!*-0!(
$"'02$"
$1).#Z
4+.5*.
&!(2#%3$4+
' +2!%
,-/2!0
#35!2
)*'*&-%
3,4$.)
,-.)/.
-%04,
12*(#*$4
(-/*15"(
12!1+,
0&$s-)3
'"2!2*
0)22).
"0*%(*
T41*$"'.
-11'/-'"
$3-120-
3/'-0%
-2/%2
.,-0,'-
%"/0 /(
+-5+")
)4.'+2
)%!41.
1'"0,"&$
*3#/!'
!,)21-
/.2,%0
*!,#&4*
2*/#156(
3-42-5,
,21",
/"$)2*4
-4&1)*
&#*3$0-!D"/
,3$3"4
!'1*/2
.),"%2
03# 064
!""!63
+-0"D12
13@2-
&0(0,#
0'%-(0&
"2/!1*#
30#$"*%
'+*+&/^
*%*1))
2(34"3
-%'4%*0'
%30" %
%&%&'&
4!4#$!
31.-$
$!&/%!
/%$&!!
0%*$(%
,0!+."
D"3,4%
,530$"
[)))+0
)0((2,
2.,E*'#
&/10#%
!*$'",
--//%
43(#
)$(?'+-
%3) -1
#,$0%#
(.!1)3
)+3*%5
1%3,!'
(3-12&)
%(1-!+
*2++*(
)-%$%"
&1.-2)
!$,',*
--$02(
!*.!34
24/02'&
.(3!+-,
1--11&/4-
,&0,'(
/1),*,)%*
%"5+3s
%*%2%$
$2 "%"*
#&.2 -2
-1'4 (
1$12,2
) %"$%%
2/+25/$*
0A 3.)
0 %*3%
*(,./-
$.$')'+
!+*(,21/
/0,R!2
(&'*13
)2& &2
%3+(('
&(-(*#
'0* %+0')
0)#"(&
-"23.-
4"3(*'
#!),)#/0,
!!3(-'
2 &+0#
,5&(/;
2&0+!+
.-,$ 3$0
!)-/$2
4/%1$0
'"&#3/'
*24.+&,2
!1"'+0)
1-11$20*
.)2-+$
%*0!) !.'+-
0"%/-4
2,$+!3
2)!410
"$ /.%,
1323"0&)
3,/20+
.-134)
,&.*+
*!1)$0
-3*%'3
)! *22%
2)!+#.
#!#$3*
,43"3'
%(/%$*
+*.-(4
13!-42*2
-.43+)0&1
)013"/
"'*430.
$(02.!
"2"+,%
"$22 +
/3',04
,!W/
/2#
",$!0
+#0%+1
#*2..
-/&*)2#
'*))#43
+#*-.110
2&3+ 
"&16,
#.!'4)
$ &'3"
/&&,.
&%%(-1
%+,$0!
))&-!1
#(0,-+($
(,$2.$-
"'-&".
40(%$#/
0!$.4,
%(-'5$
) 0(( ".
/"&(4&22
&3"+23$
4F.304
*11 3+
'*1&%5#
(,/12/
,.&2+(#+
12!34
(.4!),
$1($+<%
+$+,/*
.-%)-#
.$.,$.0
".",+
-314&0
1.0.,+1
"3'1,2
/#%,$)
2/+')&!!
/3"&!+0
/$21*,
-3-/,2
/"+#!.
",*025%
$1+"2W
#+%$0+
*'(1+(/1
#3. ,.
30,.(#
!3$"#(
. "T1,4
'/*0%!1!,2"
,)(*$/-
(-0+%'
,,)3%'
-1!-!3$
12[2.)
,&%1#!2
,.!)"2
$0* !30
!1)1'
F###4(
/+,/1'*(0,
4/%.3"
."-$.
#402/*"
*')%2/+
1$03p24
")/*!"
01! 20
-*#23+,
0$$ '#/
(1,#(&
2.#,!#%
12X&(0
+-(2"","
&"4/"Q,
(%.!%4
!3&3&(
20)1(
5%-*-/3
$/",(/
.%$4+(1-04 %2
* 0&/0(
##25.3$)
25+$0-
!0((%+0
&51( $
"-0(-/
2"!)$/
,)"2!
$,!&&'
+-.' 23
#-$+4,1(
)0$/*('
$/#-,
%#!+(
2$(".+0'/"
'0#%%1
!%0+'&0
12.!*
3"')-)%
&-/,)*
.+"'($
0 ,+/-
!(1,*1
&.32"%"
+"#" !
. ?+2
(.'#2,!
(!4/*2
3"%"12
+3 !/-
w%)( [
(#)1"#
52"#)"1*
?,),"(+0
&3.$%0
1-/.'+
3$-/#&
*'')53!
1P4(/%
$'0%&)'
210 %!
-1 2/#
%1((21
$2134'
2,$+&.1
,'!-1(
'-3+4.$
42#)-"
$'%#3/
$3.12+
+**!24*
3.")2/
+1"&/.
31(+++
(+ v1-
..+(2,
'1,..1#
1,*+'
"2!/?*3
'%* -,
(!1).,
50!&-
$2!$&/
!5!-#1-
+)-02*
'#"&-,
41$$'-
6'*#
3)-3."
D$ 9=(
t$ +t$
j@j ^V
>=Yt1j
0A@@Ju
0SSSSS
URPQQh
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t"SS9]
;t$,v-
UQPXY]Y[
t+WWVPV
InflateRect
SetParent
EndDeferWindowPos
ExitWindowsEx
IntersectRect
USER32.dll
CoUninitialize
CoTaskMemAlloc
CoTaskMemFree
CoInitialize
ole32.dll
GetFileVersionInfoA
VerQueryValueA
GetFileVersionInfoSizeA
VERSION.dll
CloseThemeData
DrawThemeBackground
UxTheme.dll
WNetAddConnection2A
WNetGetUserA
WNetGetUniversalNameA
MPR.dll
ExportRSoPData
DeleteGPOLink
CreateGPOLink
BrowseForGPO
GPEDIT.DLL
CreateEventA
FileTimeToLocalFileTime
GetVersion
GetModuleHandleA
InitializeCriticalSection
EnterCriticalSection
VirtualProtectEx
GetTempPathA
OpenMutexA
GetEnvironmentVariableA
KERNEL32.dll
GetCurrentThreadId
GetCommandLineA
GetModuleHandleW
GetProcAddress
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetLastError
InterlockedDecrement
HeapFree
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapAlloc
VirtualAlloc
HeapReAlloc
WriteFile
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
LoadLibraryA
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
HeapSize
offer.dll
Dangerbeauty
Settlehear
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
$;);/;5;;;A;F;K;Q;U;[;_;e;i;o;u;{;
<<#<)</<5<;<@<E<K<Q<W<]<
>*>0>5>:>Z>n>~>
?/?5?D?b?h?p?v?
0%0-030E0J0Y0b0j0s0
1%151;1M1S1Y1d1y1
2,272Q2c2j2}2
3+3:3?3Q3_3e3m3u3
4(4/494Q4W4a4g4y4
5/545B5G5T5_5h5n5}5
6$656F6V6b6s6y6
7)7/757<7V7c7n7t7y7
8%8;8C8J8_8n8x8
892989>9G9L9f9n9x9
::':-:::@:F:L:R:X:^:f:l:t:z:
;@;F;U;l;s;{;
<-<N<W<b<k<|<
=/=B=R=d=o=|=
>#>7>H>X>i>t>z>
?!?&?1?C?I?O?U?o?u?
0"0.0B0I0U0
1$1;1`1f1
202?2N2V2v2|2
3#3(3;3E3_3
40474>4U4`4f4~4
5'52595?5J5V5a5g5y5
6!6?6W6f6k6q6w6
7$72787A7P7U7[7c7j7o7u7
8$8*858=8H8M8U8\8a8y8
919S9d9j9t9
: :&:D:Q:]:f:u:
;;>;E;V;[;a;
<%<:<@<F<P<g<v<~<
= =4=:=U=[=j=r=z=
>>%>?>D>J>O>U>_>m>v>
?"?(?-?7?<?D?L?U?]?c?m?
0#0-080>0E0W0]0i0r0
1!1'181A1G1O1^1c1t1|1
2%2/2>2D2\2o2}2
3"353B3J3[3a3g3r3
4,4;4E4\4
5*5J5Y5h5{5
676W6w6
7+717A7L7W7_7o7y7
8!82888B8H8W8]8c8i8x8
9+919@9L9\9z9
::=:[:z:
;1;V;{;
<*<7<G<M<W<n<|<
?[?a?|?
1E1K1V1b1w1~1
22,262=2U2d2k2x2
3F3L3h3
3 4C4M4
5,5:5E5L5g5l5t5z5
66$6/646?6D6Q6_6e6r6
61777H7u7~7
8$8H8Q8~8
80989K9V9[9k9u9|9
:D:Q:{:
::;G;P;d;
1(131J1V1c1j1
252N2]2b2
3%3-373=3C3e3
6$6<6T6
7A7I7Y7`7j7
?"?7?B?
30h0{0
1P2\2o2
3$3K3t3
346B6H6b6g6v6
7"7,737G7N7T7b7i7n7w7
?4?k?|?
!060|0
3I3a3l3
4;4`4s4
788=8O8m8
8'929@9E9J9O9_9
9-:2:9:>:E:J:
:R;a;p;y;
=?=X=_=g=l=p=t=
>N>T>X>\>`>
?!?K?}?
G0i0u0
1M3_3q3
9(949>9F9Q9
=O=h=o=w=|=
>^>d>h>l>p>
1"12171O1U1d1j1y1
22<2{2
6!6'6.656<6C6J6Q6X6`6h6p6|6
93:@:;.;
181D1`1
2 2@2`2
3 3@3\3`3
3$3034383<3@3H3L3x7
:$:,:4:<:D:L:T:\:d:l:t:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Surprise
FileDescription
Necessary point
FileVersion
6.6.8.426
InternalName
offer.dll
LegalCopyright
2017 Surprise Corporation. All rights reserved
OriginalFilename
offer.dll
ProductName
Surprise Necessary point
ProductVersion
6.6.8.426
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic Clean
DrWeb Trojan.Dridex.735
MicroWorld-eScan Trojan.GenericKD.36522017
FireEye Generic.mg.9da3ac5eeb02e9e4
CAT-QuickHeal Clean
McAfee RDN/Dridex
Cylance Clean
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Dridex.4!c
Sangfor Trojan.Win32.Dridex.PQ
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.36522017
K7GW Trojan ( 005669021 )
K7AntiVirus Trojan ( 005669021 )
BitDefenderTheta Clean
Cyren W32/Dridex.CK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
APEX Clean
Avast Win32:TrojanX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Dridex.a0e3c453
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Dridex.832512.A
Tencent Clean
Ad-Aware Trojan.GenericKD.36522017
Emsisoft Trojan.Dridex (A)
Comodo Malware@#1gfpdu46j67by
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R057C0DCJ21
McAfee-GW-Edition RDN/Dridex
CMC Clean
Sophos Mal/Generic-R + Troj/Dridex-AFL
Ikarus Trojan.Win32.Dridex
GData Trojan.GenericKD.36522017
Jiangmin Clean
eGambit Clean
Avira TR/AD.Dridex.wmn
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Banker.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Dridex.PQ!MTB
Cynet Malicious (score: 85)
AhnLab-V3 Trojan/Win32.Dridex.R372644
Acronis Clean
VBA32 BScope.TrojanSpy.Zbot
ALYac Spyware.Banker.Dridex
TACHYON Clean
Malwarebytes Trojan.Dridex
Panda Trj/GdSda.A
Zoner Clean
ESET-NOD32 Win32/Dridex.DD
TrendMicro-HouseCall TROJ_GEN.R057C0DCJ21
Rising Trojan.Dridex!8.33B (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.1728101.susgen
Fortinet W32/Dridex.DD!tr
Webroot W32.Trojan.Gen
AVG Win32:TrojanX-gen [Trj]
Paloalto Clean
Qihoo-360 Win32/Trojan.Dridex.HgkASQ4A
No IRMA results available.