Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

9f4693fc0c511135129493f2161d1e86

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000722c 0x00007400 6.51167217489
DATA 0x00009000 0x00000218 0x00000400 3.15169834056
BSS 0x0000a000 0x0000a899 0x00000000 0.0
.idata 0x00015000 0x00000864 0x00000a00 4.17385976895
.tls 0x00016000 0x00000008 0x00000000 0.0
.rdata 0x00017000 0x00000018 0x00000200 0.206920017787
.reloc 0x00018000 0x000005cc 0x00000600 6.44309346589
.rsrc 0x00019000 0x00001400 0x00001400 5.9269634536

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00019150 0x000010a8 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0001a2b4 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN data

Imports

Library kernel32.dll:
0x4150ec VirtualFree
0x4150f0 VirtualAlloc
0x4150f4 LocalFree
0x4150f8 LocalAlloc
0x4150fc GetVersion
0x415100 GetCurrentThreadId
0x415104 GetThreadLocale
0x415108 GetStartupInfoA
0x41510c GetLocaleInfoA
0x415110 GetCommandLineA
0x415114 FreeLibrary
0x415118 ExitProcess
0x41511c WriteFile
0x415124 RtlUnwind
0x415128 RaiseException
0x41512c GetStdHandle
Library user32.dll:
0x415134 GetKeyboardType
0x415138 MessageBoxA
Library advapi32.dll:
0x415140 RegQueryValueExA
0x415144 RegOpenKeyExA
0x415148 RegCloseKey
Library oleaut32.dll:
0x415150 SysFreeString
0x415154 SysReAllocStringLen
Library kernel32.dll:
0x41515c TlsSetValue
0x415160 TlsGetValue
0x415164 LocalAlloc
0x415168 GetModuleHandleA
Library advapi32.dll:
0x415170 RegSetValueExA
0x415174 RegOpenKeyExA
0x415178 RegCloseKey
Library kernel32.dll:
0x415180 WriteFile
0x415184 WinExec
0x415188 SetFilePointer
0x41518c SetFileAttributesA
0x415190 SetEndOfFile
0x415198 ReleaseMutex
0x41519c ReadFile
0x4151a4 GetTempPathA
0x4151a8 GetShortPathNameA
0x4151ac GetModuleFileNameA
0x4151b4 GetLocalTime
0x4151b8 GetLastError
0x4151bc GetFileSize
0x4151c0 GetFileAttributesA
0x4151c4 GetDriveTypeA
0x4151c8 GetCommandLineA
0x4151cc FreeLibrary
0x4151d0 FindNextFileA
0x4151d4 FindFirstFileA
0x4151d8 FindClose
0x4151dc DeleteFileA
0x4151e0 CreateMutexA
0x4151e4 CreateFileA
0x4151e8 CreateDirectoryA
0x4151ec CloseHandle
Library gdi32.dll:
0x4151f4 StretchDIBits
0x4151f8 SetDIBits
0x4151fc SelectObject
0x415200 GetObjectA
0x415204 GetDIBits
0x415208 DeleteObject
0x41520c DeleteDC
0x415210 CreateSolidBrush
0x415214 CreateDIBSection
0x415218 CreateCompatibleDC
0x415220 BitBlt
Library user32.dll:
0x415228 ReleaseDC
0x41522c GetSysColor
0x415230 GetIconInfo
0x415234 GetDC
0x415238 FillRect
0x41523c DestroyIcon
0x415240 CopyImage
0x415244 CharLowerBuffA
Library shell32.dll:
0x41524c ShellExecuteA
0x415250 ExtractIconA

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
_^[YY]
HBITMAP
YXZQRPR
R;P P|
IVXLCDMT
_^[YY]
_^[YY]
XH;XH~
9PD}-RP
PH9PL~
KH+KLQ
;CHRQ~
RP;P ~
tSPRQj
_^[YY]
QQQQQS
\PROGRA~1\
QQQQQQSVW
_^[YY]
QQQQQQS3
QQQQQQ
QQQQQQSV
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetVersion
GetCurrentThreadId
GetThreadLocale
GetStartupInfoA
GetLocaleInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
user32.dll
GetKeyboardType
MessageBoxA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysReAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegSetValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WriteFile
WinExec
SetFilePointer
SetFileAttributesA
SetEndOfFile
SetCurrentDirectoryA
ReleaseMutex
ReadFile
GetWindowsDirectoryA
GetTempPathA
GetShortPathNameA
GetModuleFileNameA
GetLogicalDriveStringsA
GetLocalTime
GetLastError
GetFileSize
GetFileAttributesA
GetDriveTypeA
GetCommandLineA
FreeLibrary
FindNextFileA
FindFirstFileA
FindClose
DeleteFileA
CreateMutexA
CreateFileA
CreateDirectoryA
CloseHandle
gdi32.dll
StretchDIBits
SetDIBits
SelectObject
GetObjectA
GetDIBits
DeleteObject
DeleteDC
CreateSolidBrush
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
BitBlt
user32.dll
ReleaseDC
GetSysColor
GetIconInfo
FillRect
DestroyIcon
CopyImage
CharLowerBuffA
shell32.dll
ShellExecuteA
ExtractIconA
0"0*020:0B0J0R0Z0b0j0r0z0
4-595T5
8&8,848F8R8a8m8u8
9/9:9[9s9
<'<0<;<D<K<Z<a<
?2?\?e?u?}?
0(0@0L0T0k0z0
0,1P1n1~1
2$2u2|2
4#4+4O4o4
8A8Q8g8
9*929H9`9n9
9+:X:a:
< =T=\=g=
>N>R>X>\>a>h>n>v>
?%?/?7?=?K?f?{?
N0W0}0
466?6:7C7
<)<2<><E<
=/=;=B=L=V=m=~=
>/>@>J>R>Z>b>j>
?&?+?0?7?>?H?_?k?x?
0:0B0J0R0Z0b0j0r0z0
1"1*121:1B1J1R1Z1b1j1r1z1
2#202B2J2R2_2k2x2
3 323?3K3X3j3w3
4$4(4,484<4@4L4P4T4`4d4h4t4x4|4
9,;:;A;H;c;o;
:(;=;c;
=*=:=Z=
9_9d9w9
:.:E:c:z:
030F0X0\0`0d0h0l0p0t0x0|0
1%191M1a1
004080
1 1$1(1
777WXXXb...
JJJmNNND]]]~
NNNh]]]<XXXy=:6
QQQd^^^6MMM}
NNNa[[[2___{
KKK_UUU0HHHm|yx
FFF^III-???lwus
BBB\<<<*555i...
>>>Z333(,,,h
---d"""%###f
rppp4###d
;555hL</
BNNNnXF3
FaaasWI4
Immmw\P;
Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus.
! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas]
X+cd(
X+Wx(
X+Rq(
X+Zv(
_ _b``
X+Qq(
X+W](
X+`^(
X+Pt(
X+`](
X+Y^(
X+Y`(
X+^`(
mHsH
(sH
#KsH
X+M`(
aefe* ;
cfe* =
6 ;)a
Yefe* 7
ce* z<+
Y@[Z(d
Y@[Z(d
aefe*
cefe*
"HsH
jfsH
jEsH
X+Lx(
X+U{(
X+U{(
X+Uc(
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADT
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
8i*Z9i1h*8
1==qC?
\31>7<
}}#xG(Y
fB]EIi
#'7hnM
n^a)G,
[r:^5z
x50yL$
mKnbYd
6zM6WX
_xBw8.
?tug(FIdv
H/;V( %b
Tt_*w*
Xg;odT
k*')53z
2-)9"-F
w?!5`|
}aN<xK
G0$2~M
rWX/?do
Vgv=[~
CfP/O~
K}%{d9OUS
,H_EZ3
BZ`lae
JSfV.?F
zlYO|H
`zFNj6#
{5D\?=w7
'O$b"j
M^p~Nd`
U&U:nn
}wy$EZ
_ObMi"\
qU&|r
$!'*zK8-
wJ-<MWOvm
7@cKF=y9v
?P}HCka
149i^vY
2M4<*r
nWpp<0N
XNxy8c
_3in6[
l7v3Hi
nMfvT
,CebBt4n
S~n1=YvR}
R@0xhO
?\?~-l
Pen'yvb
hr'd[ab
Uy0jjh
K>)@*v
Sj0$`00
;r|1PZ
MR%e+zG^
UDs=px%
#1a!9{
2.Q|zw
]2Z1V1
S5yJ[
ccT3-[_p
Ch&yw]
~>Hy$Oh
8L0dC3i^{
D;G{@o
7tfn>o
&2"zH:0
Ej7H_#
fM!{9
'?3~Dn}
?.^bxm
}/7h{p
iT!G%<
<Zk]IY{I
YB@i'T
Le(%}|U
rs!EiD
_2!4XO
5=F^Jx$h
N[qygB_)
K'q5X
/cf"P#
/Xu5J,tQ
%Fec<V
8Lr,%j
Al} >5
:\b`Nh
Cm_"QY
GF]OE/
RRcAM'
@p\Z>4
D,&* n
4cuE6O
ZkgYEl
#*RLzv]
.N{+"L
>X^mv"
o1L>Y7
:%"e|,
M9N%|;{
CX V}nDX_K
#@h)44
#G"E+)
Ya/*F$
.}(`_
jW(ijK
msuUZ
ljFbTh
!Tn"*y
25Q$vV?
IDATuDG
6cpO~#gU0(
:H#Oep|
1g?@WV
@hNJ*q^
#kBf}{
U\PiI@\yd
bLb&4*t
$kR{juAR
%}o_sv
<?9Iv@
C{H8@/
oujZ.Q
4f+/Db\
{'8]{9
%K<LAa
}ql9[)
tmS\|1~
~n[8XS
[/R~^}c
n}izy!
s_'TBE
'j&yx=
QQx\!V
\sw~@E;
zg/D,0>m
blVbBe
W!c"odkv
yIq\Y6
n]vN(\(
w7A ZhM
01d'g@T8
ETZx7E
j|V>YTu
3{8e&+S+-
<.SfB
SWO<}^38
kyo~Is
z]|U1eQ
g>_@Seb1
T;]3x "
L=?^*p
7)Q~{p
h\w_5j
3La@qp
4htd}k
uD#T!~Bjd"
Y>Gq1-
&'q@7
e9_#o)
:uhq`Ak
]C+5bb\o
A>#Gm=-
#X"}j%
G+>v)y4
FTBxT0
6f>g_W
8<c@46
N\'[PRz
8UF:h
O M8Te\J>
$c2G>>
c`>p$Tv
.* (8V
<1}xa;
:fV``TFB
iTxdr2
+7;wW
C0P[d~,:
=?Y=}?
VS|3"\
SlKugN
0hq`uJ
'&-^7xO
i#sjJ4
/o^}v,
mUObek
D8QQ3D
(]V~SlQ
VD#w!L
i626t;
x.E$~8
E}l`@;
=5asIFk
6d8]+y
2\*$mo
=\5[nNg
kA'Z~e
T~g~Sk&
s!]UqI
lK`"QN)
#T!tQ/
4XLZw3
TA~+xq,
fJ?#Zv
MF9Uz&-
NNu~=Zu
KdJs0i=
n,tL0b
pu_Mh4
Z}Y^aN
#Svb0X$0$
vL$-e8
4P\{pA/
H>Bg_%
=!osv A
,'EmCvJ6G
Ef%WtikoO
vF-Ng8xy
o5/n<zSx
h>3w/N[L
m(s8_R}1u?s
Bv5fe
_=@m6>
Rz"\O
/<qp&(
mi#y%;
QEg{=ky#
H^jtL$Pq+
lgm7oov'
aVSa`X
s{x&9e
&m%0/G{v
XhZ5DLN
f,M^T%lTm
1th.p:p'
vf:X!
Xq5aOA/
5ArKK(
P"|LGZ_
w}fVL!
S~5G+.
'7'vE27[
7+/z$O?
SY/,9P
8BX'?Om
"`.r+%
5~2jC@
C!aUpP6B
_/:l4T(
G)5EGP
]{XkCc
.:Z7c8l
/}:WB.
ehd1k-(27=
)| g/"
HL19Km
UdAWYI
ELuZB,
EV5fm%
9dc$lR
BeYB>w
4Q7%I3P
;eRkw_
yiv!:4O`
+'CN)q#(
|6F~V%S6
GxUkT
{%"k/0f
?|]tu9v
"1>]ED
Vz/:~x1c
aQ6M_*
n-Vf0+
MMo7,H
wDsf{U
{4`T`.
fS\O=Tq
DDAT9j
x2``\q
iiLlq<
Qb2o?-U
/f!&b`
4g46(X
4M\k<
}g;@Q[W
o\!)3-
YP"`$=
0[*1!Ua
j#nA#m
S&=cn~
#I#U/f1
1w:vr7
n0X2k)
\GM<4c]
tg~R{w
7YO([hN]
0c8wx"j
_^k]qp
\^MwX}
!Ff9b
6n=>_ib
~U@y>.
's2m\r
KBG{PTi{
[FbD--
"A('9g
WjL!.n
DO3;F<
7'8y]$;
~S;'uw0'
d%e'0+
/f""@?Ih
"M?9X
'_)g?*
8=`-JL e
fft@waSqUm
'QhhGv
:{`7MM#e
CtQTfD
,no=-m
Ou&oVM
T|-]cx
6Wi*bV
>FR7y'ys
H](Ci&
]jsMD1H9
.[aa1S
4voLZy
y)2J%A
Y"^gY`^
"4VVs\
f?Tm1w
z<fiT
M3Ry/8
,\?yv~
_PQ?AJ4XJ
d[Mlg,62=
S>j9}^
6PpgO,)2
s6#Qc<1
bF9,X[[
_lvS?v&{p
%'-LT9N
DH*J8@
t`UAI?r<
gC[epyEc
+o:\<S
e)e-i6
P9b'0`
IDATkq
#o}3u=
jV!5>hd)
urs4ra
J??GC{;
23Y"6"!8
cZaOciK
XQvo)%
<o[ayQ
\:/f"&c
{&srf?
kS/(0_
t1<6s]
\j@_Ah
DbK0%o
!0+Gb<
y`u6oyX
lp#VdB
E\/aY.,-
i]e\~Q.t
lP?}j@p
(>o4/;L{Fm
k l\(W
q0c8C$b
r7~KK"O
]JA?6
&*_Rh}
D%C^WH
7J^P)Jg
QhX71<
%p^+4j
YGDcp#
o*og<\/
fyuzgA
W<fk'B
0X2I\e
9{S#9N
Rnh'IV
8GvwA/
B}U^y^
rf1"ucrG
!t=.|~
mA#Pqx
w#Wzd0
.y~sS#
t^p8.!
9W\>Ny
EcB` d
SG??5h
a`M\b<h
VVPbVU
>Oj5SG
e>cabU}
??.%bS
3w'6<\
caEO^M
70,ufI
N?8hj+[p
|+I#\1j
"JzCr3f
qhr8+8
)LJ6a3S}
gD)(t
zZS)?="h
bM9ds*m!
|x`$A}
4Qx`Y^
bZyhaX
+ZQY_V
T&N+"g
F+j^L|
Sj60x0
<0K`VU
JJwByy
4yHdpC
N3`M&7x
,#g=5O$
L''pm
5~=9#Zm
0B \Tq
sM`G4v
8x[D:Hy|
ZKx5N2
_GzyyW
sY'0h
/iEt8}B
[uXmj(
Tpn&OI
w}G:~0|
9~V?Vx
Y?=*RjN
I8_@8q
NZgX*:
>m}&Y*
J<2=\
<?.#w]
oO@*T2G
gha).R
l?1D&TRr
_3^L_=Qw!h
W${`2bQ'$
ej]Hus
+@B~9dY
Vf=}_sy
J+!bpa!
(TMJ ?
znSTW06CIj
Y<yg~Db
?g'.qp
?::NzN
e[?Fn2
yFTDE?M
Xr,<_W
^BVA1ZuS=W
]_G^HVxsQ
O_bit4
ig\F}]
f?qbPqX
w=,iz8
_en*<R
>!Gz61
qLrVZO
EqG+^TO
E~V-efP
3/L%wE~
}q7,N/7+
AEq{b
|9ZJVw
uiTECO
` KF-n:Fy
.4>,h`
kP.E#u
HL|wB8
kYZdp}
qWB?O9
c L@cP`
SP1.;H
x60Qj
):Vc"7
1"&> M
]MPahv
;GpIv`$
ft'k~{
G:kY*3AO
=?=W$%
5(+%[M
,vGo_G
J0;Q4`
-r<L_'
<#DfX
K:H1%W"z
PpEz[B
&U/8@?
tlm.2y
U$mUaT
We"FqY
m\NrKf)
UEAsA}
\J#<;>tA
+B.lwq
XcQ,*A*
kv$!TQ?
!LUfb'
.NaO6M5
z%1&y%zbJJ
xDUfT[
e\0]yi
0ErwXJ
q}eh:k
ck.mv<
f4BBh#
ucE'Wj
S=Vg9y
9}@!:G
a,rz=k
D`xW?4
eC&-nzP
hF &x
4F%\h{
<8fcD
le|bd4PE
qa@/~u)
]S>*_AQ?s
isMt\3Kv
l8bCkH
sYDNb~A
|;^HWd
x+)6^H
TSs'<=
Zc+|Kr
{Q3ir9S
?*.Ao(
{U~c3:
Q=^%ff[J
L;O0+C
gqX4R,+f?
8yr-Q6
(C(<&N
=6yqXx
r0J+Rw@
9cj|9E
8E3+,?
L:Y>T(
Jc]5Aai
3e%qEgF
s1(5zl+
DT~"&J
3[$`v`
{kd&gq
Up6S!F
!?\69O
x,pnJ<
+FT'" l
h:}8Fx}
wy~4h
|9WD2>
0Hb(YRc!C
9G1kBb
y-M{?*
n'rMS0
Nvs1k
rTq9QY:
j~L;W^Lm~U
Lmp-e;
Zx?0sR8
GAbvp1
)>DtQ\%
VA&b,7
~g2<O
Hh:^Usi
j-Wioo
5(}{O(
<3S^e>+
C88v L
y\~y<D
<#` }e,
aNDY$c$
?56(BY
RZ0bUvE^#
Ejw;Gc
w MCy~
ORc1'w+
iN6{~t/
x9\5[bW
L\NT sMN
pEI"9mI
nb{\Y>v
H,DL9?
5|<MDe
x`\043
]jO?sP
}zz,!1F
aK#Bm8&
[1d{-I
IO/V*0}
{p9Ro{
i>n=w(Q[QM
9jpILa
1UZtLsJ
.$^R[ZCz
1/_@[3
2#]0,X
08sdqV
E~GlQ3_
>jeir%"s$r
pVfP*t
[sT[Q)
_LGd/
26!>/w
3O[zS$
Gq1f=-
Rt)|D\O
?M-bvt
`t}!q<
VTpsAI'
tLBG)5
q5Z>FM%
E;!/C,I
3gxZj2
.'~fra
sF<tb>&<
kb^TkV
lgyi&u
I>]N*=
, f4
Gk+.|0
+`C;BJK
c:b/5P4
6&b/5F
~*o48}
`+O^y
tfODv5.b
Xq *J.
*{"TZW
* yPNn
>nJkG8
oIcCeq
k`<AhG
|HUYy2
gaIp}f
@k()7c(
b*_^8C
9G]3g8
zQRL(N%A
6)"C$Y(
~=/RaY
=?a]r[rx
rL"AC{q
y^qm\(.1
C,j$Ez
C\MnC`
6Cdug]g
?502ri
6UA-+4#v
!(JHI
\JlN]9
[b1M\f
@*&Ki+AV/
-`MP"l
Hl(]+4q
$Co:.1
bh1>8ELl
-Iid:Z
"FWRb^
f2"1_1
\s{?@y
{o'[Q8
PaBbA#
?(ijN]
Jt'm' gb~[
bbkZJ5
; "z%.
00`Bp_
7I@p}
w*O+>ss
G)i'_)
R<]N"T
W;EKg[
>lg!_MJ
5L =oF
Ra@xo_
aon~kX
mv_<@o|u3
DW6MIbC
92Z.[_
mIhl|`
Zx=uPP
8BVQ3Jr
w}SLfc(
b])%:a
n_7R$2*-
|Y^}Sf
@&e+BYe
Ck?9Mbj
t6|`Gc
A:HIAu
vxe)rB
Z5MQvqm4S
+;-DU_
l"a0Fp
[$~1rZ
u9/9jB
f_>c_
>G?Tt4
^j-hd?
#%0!/+
|_?,vF
~!Y &U
>&k)_9
w$cJ>|
h'U{rK
^>tO4l$
Kds[sl<F
nqEUM?]U
"_vL[]
]mvv:\
[L,=>rR
KYd{I9a
9v+ov%
so}o#T
!dl!j7
_}[T=I
Gbr"},
!vO++U
(!LXzR{$2
9%$>2S3
{~3/9hWH
v|fH!a
MN#|_7
xu.m<PR
,N4HDZ7
l4<"w2
`TAh2[
[D{!z+
F_rP\TB
6mq{mL
PS]}1G/"
D@ALH_3
54ZbHU
] W<y<
7QhmPUt
z2B-1+
ajR!"[
2d AjX
il-6c=
]D{8ha<
3+>QaC
Ca+rp
Xu"e?&
3Zi?/94
|[[;!{
n_8pK\
==w^P"C
P3QEq'
G9.*[Cw2
9M<.)
)5x=`H?hO
1sm(tD?
h`{CN[u,
BfjNrGA
c*qbQQ
Sj<,*%
ipEj(Er
qXa;}A
}lj&D
z\.ch/]
*zo,.O
aydGC?G
"|t5"E|
}<4='rY
Kmh^07J
5p +JW
p9Pea`
9EA8ug
Jws#uCS
W#"6b(
opequ|
G= aK`
K_H?">_[ym7
>9Y5k_
K+V4-P
f~+"i|
{sum.F
Dv: 36
d>5/ai
]<KrKN
A6L+@i
sRf5vZ2
/-t2tymv"
}!}!l!)
_/HT5m
>MiRk=
,s+<Cf
+\No:sV
]QC?RP
gl:Kw~f
yEXS|F!?
@"oY-P
[jKC?;gu
4<#{iX3
8f!yZi
tfs"$}g
Q>g'Tw
5o+p<i
Uw?%v
Q#F0@Kc
~'F]v#
Z`F-D|
|<Sp&7
+8-b{=66
wQRt>-F
cgXi'e
$?A}WP
$IPI"ID
ky/^tSnb
Tq2a:%e10
*4OD.=
G5r{<&
&_@c'1
:zYy:r
7f2s3=
gUdx{W
S!L[zy?
9!.gzM
GJl(I-8
45F7u
,dTJwa
WqfJI(e?
n-OV'bX
5md,70e$
~p{5)o'
=epYQ1
ZItf8uU
7Gl`['
c8#>hj
FxVL2A
EWN3cU
5;][e;
Tlt1vZ
ySzM.:
2yEKd@
59Qk"w
Mx}~97<
eoq[*3
9D%h^3
?Yb}3i
kx0J`!4
Z'qCWA
LF8\B?W@
-4T/>4
&"d/I>5
YkH{QfyFc
#d;hcS
<bAh=f
"c{xx*
}=?;z8
qe0e::
|#c|wS8$
/%z3|u
}~{$1Wu:
4Te9>:
aUY0[:
\Ebm9g
UeKzOQ
G:c2t
:\|L'O[
#;""1)
whM8m9
<W/3ud
Z[%hE<$
N7u[$hK
Xy:?nL
06D\%{
8[#X'u
nQzYe*
/kK$R&!}
m*:sv]
hhc>3|
k\VVV9X
0>eUUL
F,<|EF
D,OP<@&
aF&W}f
5V]gdY},d+
c=,EE)
QLQcgv
WwJ=V6(H
ijBhh(
C?Bc1(>
'\>< =t
re^k8m
oJ-&S^
u.Q\y*o7)g
DUFbnH`
~.3m%s
50a7Fi
;iK6GA
h""/al
5<Rr$3
{CMCVyO
Qhw^PR
t2~fT)
$gud"
rT}[*Q
EkExD04
3z-J(0p
@Ohy:h
5az0POp
yE]}|u{
Xym1,?v
';MpA^k,G
5a{;S7
\N+4Fb
2Z}zeIB
?f3r40+2
^SbktU
v-MP).
?X$OsJ
;5ukl]
@ci|h8
p,:8f?
:*.05Q
|ru~~x
?q]P5H
4(.w/*
L0+bR=O'
xbPF0G
]iLh1_
W|"Tjq
si+6&l_
)59Z .8
:%MQK*
!|fjx:
:\n|*,
lTgh\2
'3.kTf$
*^GA,8
Uj08mf
&~8gg&
IJ-'7L5
(&<z3]
3`=`9Si
9WzK*U
]L87{R#
6*=!mO
a-~=WB
}j>?c#-
l8NcIc
1`H?bP
"+!4j<4
LqNLPX
}B\m~o
0*x=`3
@}-$(W
fgZWLV
S$n?&<
c@QU,(~
}J:l!E
8<hjfNt/
CeeiP?
;p@LFCi
0)cq9)
g2i.-?*
NB\IwW
<z%Nz
(h*j %
o| {u&
7Ys&#H?
*UFyx$
,Hy!K>
uYFCzr
fS6_,J
e$Y'A$d
0U-8xMK
}xxz=!
NC]S\V
(ae?=e
(aj_gm
Qe5&}E
3!qugi
Kf]__r5
L'7nt?\
I|Oqf"u
k\XYY0;
AvM!rz
:m?"yG
hg`_~B~
dc)^>s
U_!|h;
P*i*4X+
\]2\]B
.(0r"~
^vc.C_
&~??hvAK
+Cf0x<
St_ouO
=:5jdV
.Ar='+
l)ET5h
/ODrD%
<&B+d7_{<
EsVp6lQ
^O;|BdT
q\GE.Qm
Qc{P>T
G~VF!w
xV=51&a
=>e"MZbyi
N]h49`
j<3bOqB
f0lSgp
Ty/T@2<
ku}FS>
~eV`i#p
lX[2{m/
f=||wy
c9MjxdTQ
141gw]P.
bop~efh
RfViyz
Q8>lW$uI"
@x}"h
B4Im2jQ
bTm GI
dM!0P*DlGV({
%M)i)?
jaA+5%
S,.jTg
HEF^E)
t2!uug`;&'
Ccu1(G
<F'>f?
l}jxd~r
[H^hI$
ojXXrL+4
F)ACo'
BIw:l'
k`{:C
otTz>KYF
"`{CKV
'&`bR#
o%Ck7EFre
d/56A0:
}y(lD5
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
<jO{%0
]P?(vs
O^8<@>
Ou-^{/.
Y0Ypdo
8?U+>+
sR{[|l
euNc~r&
GscMs]
Ffy'Gm
{Dk"|:
/:;WAg
gNAG>|
>|x@cP
|iLW+'
0^4l$K
\[v2vM
4spuDO
G\0cZ<
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
#&$9$e$
get_Scan0
IEnumerable`1
IEquatable`1
IEnumerator`1
List`1
get_Label1
set_Label1
get_ToolStripSeparator1
set_ToolStripSeparator1
ToWin32
UInt32
ReadInt32
WriteInt32
ToInt32
KeyValuePair`2
Dictionary`2
get_Label2
set_Label2
mPages2
CCITT3
get_Label3
set_Label3
UInt64
CCITT4
get_Label5
set_Label5
75A2A13326B2A4A0B2265DBC2D0A91BFC7B540F0B10B5B9ABD2A3FC9D7B83016
UInt16
<Module>
16F0216D360C0DEAD0B03675C96F1D8E0016236744FE69EAE493FDB447D66B9A
BI_RGB
ConvertToRGB
CreateCompatibleDC
ReleaseDC
DeleteDC
CCITT3_1D
CCITT3_2D
System.Drawing.Drawing2D
EA50985D8479DA131A150350CB5FC7A94F80A33DF6EE4FD53E368624FDFF64DD
UNDEFINED
GetIFD
mNextIFD
SRCAND
DOUBLE
NOTSRCERASE
SRATIONAL
System.IO
DIB_RGB_COLORS
WHITENESS
BLACKNESS
CAPTUREBLT
SRCPAINT
MERGEPAINT
PATPAINT
SRCINVERT
PATINVERT
DSTINVERT
SSHORT
SetPixelV
NOTSRCCOPY
MERGECOPY
PATCOPY
value__
mPageData
get_RawPageData
AssembleImageData
BitmapData
ProjectData
get_RawData
FromArgb
ToArgb
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CanRead
add_Load
SaveAdd
add_CheckedChanged
remove_CheckedChanged
add_ContentsChanged
remove_ContentsChanged
changed
applied
get_Checked
set_Checked
Interlocked
preScaled
DrawImageUnscaled
set_Handled
get_Canceled
set_Canceled
TypeIsSigned
ClrUsed
get_IsDisposed
m_FormBeingCreated
cropStarted
NotSupported
add_ImageSaved
remove_ImageSaved
Synchronized
GetPageIfd
get_NextIfd
nextIfd
get_PrevIfd
get_IsValid
mIsValid
NewGuid
TrimEnd
Append
TargetMethod
set_IsSingleInstance
CreateInstance
defaultInstance
get_PreserveReference
set_PreserveReference
mPreserveReference
get_Stride
GetHashCode
set_AutoScaleMode
FileMode
set_SizeMode
PictureBoxSizeMode
ImageLockMode
AuthenticationMode
set_InterpolationMode
interpolationMode
ShutdownMode
TiffPage
GetPage
get_Image
set_Image
GetScaledImage
ReplaceImage
AppendPageImage
ReplacePageImage
DeletePageImage
MovePageImage
GetPageImage
InsertPageImage
DeleteImage
MoveImage
SizeImage
originalImage
GetScaledThumbnailImage
GetThumbnailImage
FromImage
MergeToImage
ObjectToImage
ByteArrayToImage
SplitImage
InsertImage
DrawImage
get_Message
percentage
AddRange
get_PatternRange
set_PatternRange
get_NotifyOnChange
set_NotifyOnChange
mNotifyOnChange
CompareExchange
EndInvoke
BeginInvoke
ConvertToGrayscale
IDisposable
Hashtable
set_Visible
Double
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
FillRectangle
DrawRectangle
Single
isFromFile
openFile
SaveToFile
lookIntoFile
ReadProfile
MimeTypesProfile
Multiple
BitsPerSample
set_Title
set_DashStyle
DockStyle
EndianStyle
set_ShutdownStyle
FontStyle
get_Name
set_Name
get_FileName
set_FileName
mFileName
fileName
get_FullName
get_Filename
mFilename
filename
SelectActiveFrame
SelectFrame
get_NewLine
Combine
Rotate180FlipNone
RotateNoneFlipNone
IFDType
get_Type
GetIfdType
get_MimeType
TryGetImageMimeType
GetMimeType
VerifyMimeType
mimeType
CheckForSyncLockOnValueType
GetSizeOfType
CompressionType
compressionType
OrientationType
get_PatternType
set_PatternType
RotateFlipType
GetType
GetDotNetType
mimetype
fliptype
FileShare
set_Picture
TiffPageStructure
resourceCulture
WindowsFormsApplicationBase
ButtonBase
ApplicationSettingsBase
TextBoxBase
Dispose
TryParse
Reverse
add_ProgressUpdate
remove_ProgressUpdate
Create
MulticastDelegate
DelegateAsyncState
DebuggerBrowsableState
EditorBrowsableState
set_CheckState
Rotate
Delete
overwrite
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
ObsoleteAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
AccessedThroughPropertyAttribute
ByteToSByte
WriteByte
SByteToByte
IntegerToByte
get_Value
m_ThreadStaticValue
disposedValue
ValidateEnumValue
CompressionValue
EncoderValue
WithEventsValue
GetObjectValue
AutoPropertyValue
imageToSave
add_MouseMove
remove_MouseMove
Remove
jM0x97rkz0c41Xu.exe
get_Size
set_Size
get_ImageSize
set_MinimumSize
set_MaximumSize
set_AutoSize
set_ClientSize
newSize
ISupportInitialize
SuppressFinalize
LastIndexOf
get_Tiff
RecompressExistingTiff
get_Gif
get_Exif
get_Emf
get_Wmf
IFDTag
get_Tag
GetIfdTag
SaveFlag
get_Jpeg
get_Png
System.Threading
NewLateBinding
GetEncoding
System.Drawing.Imaging
IsNothing
System.Runtime.Versioning
get_UseCompatibleTextRendering
GetResourceString
CompareString
ByteToString
GetString
set_ShortcutKeyDisplayString
Substring
add_FormClosing
disposing
System.Drawing
ByteToLong
get_imageWindowSaveFileDialog
set_imageWindowSaveFileDialog
get_mdiMainOpenFileDialog
set_mdiMainOpenFileDialog
CommonDialog
ColorDialog
colorDialog
ShowDialog
Refresh
SolidBrush
get_Width
set_Width
get_ImageWidth
initialWidth
cropWidth
get_Length
ImageLength
SetLength
get_TextLength
length
StartsWith
get_BitDepth
LayoutMdi
AsyncCallback
DelegateCallback
get_Black
add_Click
remove_Click
PerformClick
set_CheckOnClick
set_Dock
get_CanSeek
UpdateImageOnDisk
WriteImageToDisk
Marshal
original
ConvertToBitonal
set_Cancel
System.ComponentModel
GetPixel
SetPixel
get_Thumbnail
gdi32.dll
user32.dll
ContainerControl
ObjectFlowControl
AppendPageStream
ReplacePageStream
DeletePageStream
MovePageStream
GetPageStream
InsertPageStream
FileStream
FromStream
ImageToStream
MergeToStream
WriteBitmapsToStream
get_ToMemoryStream
memoryStream
stream
get_Param
get_Item
ToolStripDropDownItem
ToolStripItem
set_MdiWindowListItem
get_Level1ToolStripMenuItem
set_Level1ToolStripMenuItem
get_Level2ToolStripMenuItem
set_Level2ToolStripMenuItem
get_Level3ToolStripMenuItem
set_Level3ToolStripMenuItem
get_CascadeToolStripMenuItem
set_CascadeToolStripMenuItem
get_GrayscaleToolStripMenuItem
set_GrayscaleToolStripMenuItem
get_FileToolStripMenuItem
set_FileToolStripMenuItem
get_CloseToolStripMenuItem
set_CloseToolStripMenuItem
get_SaveToolStripMenuItem
set_SaveToolStripMenuItem
get_ResizeToolStripMenuItem
set_ResizeToolStripMenuItem
get_TileVerticalToolStripMenuItem
set_TileVerticalToolStripMenuItem
get_TileHorizontalToolStripMenuItem
set_TileHorizontalToolStripMenuItem
get_openToolStripMenuItem
set_openToolStripMenuItem
get_CropToolStripMenuItem
set_CropToolStripMenuItem
get_BlurToolStripMenuItem
set_BlurToolStripMenuItem
get_SaveAsToolStripMenuItem
set_SaveAsToolStripMenuItem
get_EffectsToolStripMenuItem
set_EffectsToolStripMenuItem
get_exitToolStripMenuItem
set_exitToolStripMenuItem
get_InvertToolStripMenuItem
set_InvertToolStripMenuItem
get_newToolStripMenuItem
set_newToolStripMenuItem
get_WindowToolStripMenuItem
set_WindowToolStripMenuItem
System
moveFrom
set_MainForm
OnCreateMainForm
get_ParentForm
resourceMan
Boolean
get_Endian
set_Endian
LittleEndian
BigEndian
mEndian
SetEndian
endian
cropPen
set_FullOpen
System.ComponentModel.Design
m_MDIMain
SeekOrigin
get_Icon
MessageBoxIcon
FrameDimension
get_Extension
GetMimeTypeInfoByFileExtension
extension
Conversion
get_Compression
SelectCompression
compression
Application
set_Location
location
Information
System.Configuration
get_PhotometricInterpretation
UpdateOrientation
CustomRotation
rotation
System.Globalization
set_MergeAction
Interaction
CreateDIBSection
System.Reflection
ControlCollection
ToolStripItemCollection
set_StartPosition
FormStartPosition
NotImplementedException
NotSupportedException
FileNotFoundException
NullReferenceException
ArgumentOutOfRangeException
IndexOutOfRangeException
ArgumentNullException
TargetInvocationException
InvalidOperationException
get_InnerException
FormatException
ArgumentException
get_VerticalResolution
get_HorizontalResolution
SetResolution
get_okButton
set_okButton
get_aCancelButton
set_aCancelButton
get_pixelsRadioButton
set_pixelsRadioButton
get_percentRadioButton
set_percentRadioButton
get_selectColorButton
set_selectColorButton
get_Pattern
set_Pattern
add_MouseDown
remove_MouseDown
add_Shutdown
Unknown
WriteTo
moveTo
CopyTo
ImageCodecInfo
FileInfo
MimeTypeInfo
CultureInfo
mTiffInfo
FileSystemInfo
MimeTypePatternInfo
GetEncoderInfo
DirectoryInfo
add_MouseUp
remove_MouseUp
CreateCompatibleBitmap
CreateBitmap
copyOfBitmap
ResizingBitmap
m_PropertiesForBitmap
InvertBitmap
FromHbitmap
GetHbitmap
RotateFlip
ToolStrip
set_MainMenuStrip
get_mdiMainMenuStrip
set_mdiMainMenuStrip
get_ImageWindowMenuStrip
set_ImageWindowMenuStrip
get_Bmp
get_MemoryBmp
set_TabStop
MimeTypePatternGroup
get_KeyChar
GetPageNumber
pageNumber
mHeader
LittleEndianHeader
BigEndianHeader
MimeTypesProfileReader
m_AppObjectProvider
m_UserObjectProvider
m_ComputerObjectProvider
m_MyWebServicesObjectProvider
m_MyFormsObjectProvider
sender
compressionEncoder
MimeSniffer
ResourceManager
ImageManager
TiffManager
ByteToUInteger
ByteToInteger
addedHandler
ContentsChangedEventHandler
ImageSavedEventHandler
MouseEventHandler
ProgressUpdateEventHandler
FormClosingEventHandler
ShutdownEventHandler
KeyPressEventHandler
System.CodeDom.Compiler
IContainer
set_IsMdiContainer
ImageHelper
XPelsPerMeter
YPelsPerMeter
EncoderParameter
set_Filter
ImageConverter
Computer
get_Color
ignoredColor
NotReplaceColor
SetBkColor
set_UseVisualStyleBackColor
backColor
targetColor
replacementColor
ClearProjectError
SetProjectError
set_Cursor
get_WaitCursor
ColorTranslator
ToolStripSeparator
IEnumerator
GetEnumerator
Activator
.cctor
Image_Editor.Image_Editor
Monitor
IntPtr
SaveAs
CreateGraphics
System.Diagnostics
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
Image_Editor.My.Resources
Image_Editor.MDIMain.resources
Image_Editor.ResizingBitmap.resources
Image_Editor.PropertiesForBitmap.resources
Image_Editor.Resources.resources
Image_Editor.ImageWindow.resources
DebuggingModes
get_Pages
RotateOddPages
maxNumberOfPages
mPages
RotateEvenPages
MergeImages
mImages
images
changes
get_Entries
mEntries
TiffUtilities
set_EnableVisualStyles
Planes
Strings
MySettings
MouseEventArgs
FormClosingEventArgs
CancelEventArgs
KeyPressEventArgs
ReferenceEquals
get_Controls
get_Items
get_DropDownItems
System.Windows.Forms
getImageForms
imageForms
Image_Editor.Image_Editor.Enums
Contains
set_AutoScaleDimensions
Conversions
omissions
TernaryRasterOperations
rotations
System.Collections
MessageBoxButtons
get_Patterns
set_Patterns
mPatterns
get_PageInfos
get_MimeTypeInfos
set_MimeTypeInfos
mStrips
get_PatternGroups
set_PatternGroups
GetImageEncoders
RuntimeHelpers
EncoderParameters
Cursors
Operators
FileAccess
add_KeyPress
remove_KeyPress
get_Cross
mOffsets
get_StripOffsets
PackBits
UnpackBits
LockBits
UnlockBits
results
components
get_StripByteCounts
get_Exists
add_LostFocus
remove_LostFocus
set_ShortcutKeys
RemoveAt
Concat
GetImageFormat
imageFormat
get_PixelFormat
get_RawFormat
InvalidateRect
AddObject
ConcatenateObject
DeleteObject
addedHandlerLockObject
SelectObject
GetObject
TargetObject
LateGet
get_IfdOffset
mIfdOffset
get_ValueOffset
mValueOffset
mOffset
get_PatternOffset
set_PatternOffset
get_ValueIsOffset
mValueIsOffset
mParentOffset
parentOffset
mEntryOffset
offset
set_RightToLeft
get_Height
set_Height
get_ImageHeight
initialHeight
cropHeight
height
op_Explicit
EndInit
BeginInit
GraphicsUnit
get_SaveMySettingsOnExit
set_SaveMySettingsOnExit
BitBlt
get_Default
SetCompatibleTextRenderingDefault
Antivirus Signature
Bkav W32.NeshtaB.PE
Elastic malicious (high confidence)
MicroWorld-eScan Win32.Neshta.A
FireEye Generic.mg.ab893264f84383e4
CAT-QuickHeal W32.Neshta.C8
Qihoo-360 Virus.Win32.Neshta.B
McAfee W32/HLLP.41472.e
Cylance Unsafe
VIPRE Virus.Win32.Neshta.a (v)
Sangfor Win.Trojan.Neshuta-1
K7AntiVirus Virus ( 00556e571 )
BitDefender Win32.Neshta.A
K7GW Virus ( 00556e571 )
Cybereason malicious.4f8438
BitDefenderTheta AI:FileInfector.D5C3B0640E
Cyren W32/Neshta.OBIX-2981
Symantec W32.Neshuta
ESET-NOD32 Win32/Neshta.A
Baidu Win32.Virus.Neshta.a
APEX Malicious
Paloalto Clean
ClamAV Win.Trojan.Neshuta-1
Kaspersky Virus.Win32.Neshta.a
Alibaba Clean
NANO-Antivirus Trojan.Win32.Winlock.fmobyw
ViRobot Win32.Neshta.Gen.A
Rising Trojan.VBRunner!1.9F6D (RDMK:cmRtazq8Hm8t6E6NnjsvbmBqwIZe)
Ad-Aware Win32.Neshta.A
TACHYON Virus/W32.Neshta
Emsisoft Win32.Neshta.A (B)
Comodo Win32.Neshta.A@3ypg
F-Secure Clean
DrWeb Win32.HLLP.Neshta
Zillya Virus.Neshta.Win32.1
TrendMicro PE_NESHTA.A
McAfee-GW-Edition BehavesLike.Win32.HLLP.dc
CMC Clean
Sophos ML/PE-A + W32/Neshta-D
Ikarus Virus.Win32.Neshta
GData Win32.Virus.Neshta.D
Jiangmin Virus.Neshta.a
Webroot Clean
Avira W32/Neshta.A
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Virus.Neshta.A.sd!yf
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Virus:Win32/Neshta.A
Cynet Malicious (score: 100)
AhnLab-V3 Win32/Neshta
Acronis suspicious
VBA32 Virus.Win32.Neshta.a
ALYac Win32.Neshta.A
MAX malware (ai score=87)
Malwarebytes Neshta.Virus.FileInfector.DDS
Panda W32/Neshta.A
Zoner Virus.Win32.19514
TrendMicro-HouseCall PE_NESHTA.A
Tencent Virus.Win32.Neshta.a
Yandex Trojan.GenAsa!Mo0tdcmmg3o
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet W32/Generic.AC.171!tr
AVG Win32:Apanas [Trj]
Avast Win32:Apanas [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Virus.Infector.Gen9
No IRMA results available.