Static | ZeroBOX

PE Compile Time

2089-05-08 04:47:06

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00073df4 0x00073e00 7.97438920866
.rsrc 0x00076000 0x000216c4 0x00021800 4.66728330864
.reloc 0x00098000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00096ccc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00097134 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000971e4 0x000002f2 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000974d8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
j@Dee
]u{'a
Y D7dra
s<_Xe
j@Dee
CiFX -
~_{'
S\X NU
b L"9YX
s<_Xe Q
+J&ae
P[Xe o
S\X NU
~_{'
~_{'
v4.0.30319
#Strings
NVA.exe
<Module>
VisitorPolicyItem
NVA.Items
ValueType
System
mscorlib
IdentifierDispatcherFilter
Gfqdflpmskahsi.Filter
Issuer
NVA.Adapter
Descriptor
WriterStructStruct
NVA.Structs
Object
Factory
NVA.Bridges
MapperInterpreterBridge
System.Windows.Forms
ConfigurationTaskWriter
NVA.Writers
AttrRuleProducer
MulticastDelegate
<>c__DisplayClass19_0
<>c__DisplayClass20_0
CodePool
Gfqdflpmskahsi.Pools
ProducerInterpreterBridge
Exporter
MessagePrototypeMapping
Gfqdflpmskahsi.Maps
Resources
Gfqdflpmskahsi.Properties
Settings
ApplicationSettingsBase
System.Configuration
<PrivateImplementationDetails>
<Module>{3e82bf4e-3431-4634-969f-2973230d9e32}
m_Process
Double
prototype
SortAdapter
DeleteProcess
PostProcess
ToString
String
Format
AddAdapter
Boolean
PushAdapter
dispatcher
m_Rule
MapAdapter
PrepareProcess
CalcProcess
PopAdapter
ListAdapter
iterator
struct
FillAdapter
ViewProcess
ResolveProcess
DisableAdapter
RunAdapter
SearchAdapter
TestProcess
VisitProcess
InvokeProcess
WriteProcess
NewProcess
ConcatProcess
DefineProcess
ChangeProcess
SetProcess
m_Error
IContainer
System.ComponentModel
attribute
ListView
m_Task
NotifyIcon
_Policy
RadioButton
m_Container
m_Interpreter
DateTimePicker
_Manager
CheckBox
_State
Button
m_Annotation
m_Info
m_Stub
FlushAdapter
EnableProcess
EventArgs
result
Dispose
isinit
IDisposable
CallProcess
ContainerControl
set_AutoScaleMode
AutoScaleMode
Control
get_Controls
ControlCollection
set_Text
ButtonBase
set_UseVisualStyleBackColor
System.Drawing
set_Location
set_TabIndex
set_Size
set_HideSelection
set_Name
Single
set_UseCompatibleStateImageBehavior
set_Visible
ResumeLayout
SuspendLayout
set_AutoSize
set_TabStop
PerformLayout
EventHandler
IntPtr
add_Load
set_ClientSize
Container
InsertAdapter
MoveAdapter
RemoveAdapter
ReflectAdapter
AssetAdapter
IncludeAdapter
InstantiateAdapter
set_AutoScaleDimensions
InvokeAdapter
DestroyAdapter
m_Property
_Utils
_Worker
repository
TaskCompletionSource`1
System.Threading.Tasks
producer
m_Observer
UpdateAdapter
CreateProcess
Interlocked
System.Threading
CompareExchange
Delegate
Combine
ReflectProcess
Remove
ExcludeProcess
DisableProcess
set_ShowInTaskbar
set_Width
MoveProcess
AppDomain
get_CurrentDomain
ResolveEventHandler
Thread
Console
WriteLine
ListProcess
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
get_Length
ToArray
GetTypeFromHandle
RuntimeTypeHandle
InvokeMember
BindingFlags
Binder
GetExecutingAssembly
GetManifestResourceStream
QueryProcess
Task`1
ClassLibrary
Wcupmrcwxjlcmgwuoretvl
ThreadStart
SetApartmentState
ApartmentState
set_IsBackground
get_Task
RegisterProcess
ReadProcess
caller
RijndaelManaged
System.Security.Cryptography
CryptoStream
Rfc2898DeriveBytes
SymmetricAlgorithm
set_KeySize
CreateDecryptor
ICryptoTransform
CryptoStreamMode
get_KeySize
DeriveBytes
GetBytes
set_Key
get_BlockSize
set_IV
OnLoad
SetResult
AssetProcess
InvalidOperationException
MethodInvoker
Invoke
RunProcess
get_Disposing
get_IsDisposed
Exception
ConnectProcess
InstantiateProcess
Application
FlushProcess
WndProc
Message
instance
get_Msg
.cctor
Encoding
System.Text
get_UTF8
CallAdapter
VerifyAdapter
CalcAdapter
set_Height
VisitAdapter
CustomizeAdapter
add_AssemblyResolve
ViewAdapter
RegisterAdapter
CopyTo
PrepareAdapter
set_BlockSize
CalculateAdapter
FindAdapter
CipherMode
set_Mode
DefineAdapter
CollectAdapter
DeleteAdapter
RuntimeFieldHandle
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
RateAdapter
RateProcess
Concat
CountAdapter
AwakeAdapter
_Database
RevertAdapter
ManageProcess
get_Handle
LoginWrapper
CreateWrapper
server
WriteWrapper
ComputeProcess
get_Visible
SortWrapper
AddWrapper
LogoutAdapter
PublishProcess
maxord
SendMessage
user32.dll
SelectProcess
RegisterWindowMessage
user32
OrderProcess
Marshal
System.Runtime.InteropServices
SizeOf
AllocHGlobal
StructureToPtr
FillProcess
op_Equality
AwakeProcess
PtrToStructure
DestroyProcess
config
StringToHGlobalAnsi
InitProcess
PtrToStringAnsi
OrderAdapter
FreeHGlobal
ExcludeAdapter
CloneAdapter
_Identifier
_Watcher
ReadAdapter
CustomizeProcess
endtoken
res_Ptr
connection2
Win32Exception
SystemDefaultCharSize
Environment
get_NewLine
ToInt32
GetLastWin32Error
StopProcess
tokenhigh
RestartProcess
CalculateProcess
GetLParam
set_Result
GetProcess
ResolveAdapter
get_Message
ResetAdapter
PrintAdapter
m_Parameter
m_Helper
SelectAdapter
SetupProcess
EnableVisualStyles
SetCompatibleTextRenderingDefault
InitAdapter
PatchAdapter
m_Customer
ResourceManager
System.Resources
m_Status
CultureInfo
System.Globalization
ChangeAdapter
get_ResourceManager
get_Assembly
get_Culture
set_Culture
get__00_Blanco
Bitmap
GetObject
get__01_Smile
get__02_Laugh
get__03_Silly
get__04_Wink
get__05_Blush
get__06_Sad
CheckAdapter
QueryAdapter
CompareAdapter
ConcatAdapter
Culture
_00_Blanco
_01_Smile
_02_Laugh
_03_Silly
_04_Wink
_05_Blush
_06_Sad
defaultInstance
StartAdapter
get_Default
SettingsBase
Synchronized
ConnectAdapter
EnableAdapter
Default
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_766eecd03ad74752bdb3307a3fa7189b
m_084d064040974c13972460e02cbed21d
m_4b5f0285f9694181ade7f7450a095d6b
m_1dd996c4281442b1937884af92b5476a
m_04ada7e02a3f4d44b66b3d565246f384
m_b419441d4cf44ca089c5728e9043c4e9
m_aef88356bc8942339a73ddd37aa436c8
m_495b3197d0f9441db3c8802e7e73dbfe
m_90ab4e82f1a04c84bebd732f0b07232a
m_37d178e7993c49539737ef38a8858d0e
m_586f6f8affd94d6b9d773a1907bcd171
m_d205eec5295a46e78b8c67d0ed73a68c
m_319bfcbc0eb74683936dc96fa882eb64
m_49bcdf1b1bc0442090ca3a71b7515072
m_cace728d98eb4635a64bc58749c3f5ed
m_de89fdcc50ff4701a0907f6bc6eda56d
m_0cc6fdbedb9e41faa0c21de06e84c636
m_2bb9b120a2924e6ca794df10b231d736
m_b7b0200a16b745f8b4097826c2d6a971
m_cc547e44700444659780a119b70b2213
m_40bb881489494449a86d762d98747157
m_22dd0d8ebc394718923cc8c167f2dce0
m_5d10f70938bf4e4a83c59db293225e04
m_b24d7fa275c8439d8b54800240e24f57
m_a80b4d76c5104635b1350d05a718fa58
m_cde0eaed963f4c6ca42a349ae75dfa52
m_63180435ab274537a52448d7499f585d
m_fa96cd4495094ba08c5e85d54aab9d47
m_7f757b17cc0b46e89b1c3aac2b86f889
m_7a734995b50b47b787997fcfc7564242
m_bae364087cff45a6844861093046492b
m_c5eeb97a7a6e4011a663b60b17c3526c
m_528ddb2334ed4ae196152e08543460da
m_43ed7793377446dbbf5fd0e4fb59398e
m_e37013eafbae48fd9a867b5238e75302
m_fdb0ef2834f14fd9a8b6266e21288609
m_104a24222d5d40fb82ed53c2996e41d9
m_ad6f51fefa3d4fe2ae9f8d4885704632
m_0c9b34c5469b4e85abed3e518546c063
m_4c570fec3e0348328514ac4e0c69a18c
m_c3c804785f844b48ad155be065d51561
m_59c8454f019b4bd2b382b4b0046a099e
m_66e96fb7e43c403a86385a370198ebf3
m_8421dcf3e6434bd09343fdbd7639979a
m_8eeafea36de945f38d0178f38e51cce4
m_71923eb9764d46ffa1285e5d3601a9ab
m_5d17c0e157ed4af8bda028cd039302a8
m_88963d52bd8c4b528c3034ac6d81e8ac
m_b10e0cb09404491fb388c779cb341d8d
m_07c582eba90e424eb35c37c113872dfc
m_11fc61b2808d46a1bfbc286969068207
m_b2c13bd8cec54e33846e6d6451cb3708
m_16903ea406b14d6586318f1ec179584a
m_ea9941e685434600bc043a8ffacbe19e
m_e7163ddced404cc08f17fc10e23e9f3f
m_5c333619a2b0494c94adde883c62ef4d
m_55ec690465a24a5b9682086e1e32543a
m_26dffca5719440a6a9c8f5c43bde85fc
m_6d1700fc0b5f454c920b2e7395954062
m_0e0979772e744581b841697820cc4d8d
m_e4358fc2bfa54aeeb9c65e010ca67d24
m_55fb7997b99d453897bb2beb028eb204
m_ca0de6a8d7a7487dbb9a3c10af3102f0
m_c4da3c06c68f4e8db2a8d3741a7e6a9b
m_1c2f5181690e4c359a75ce66cc4312ff
m_8a5839639eb748da8eca8e332f21e297
m_c406d80cb06c41399093ead1ba5f26ad
m_ee980e1fe0614695b3e8084bbd51d208
m_257e83a6029c4d7bbd2b6ae656fa849a
m_0940e8b6dc8f4b888a33fa6c5e1e7b61
m_01ca76d5fedd4fe9aae272a495381b62
m_b731592740754dc3b6cc0304d109ac51
m_df491eed539c4713851593a123142a57
m_aa8622e7bfd74159bf20a06775d85cec
m_61b4981dd95046c3bb3f7d102dd695d8
m_35b2f518568c45bba80e05df29801c73
m_cd62d66506a94ac5a938cb7765509bba
m_00257c9373f140b48164151005705b85
m_6e0566730ae44e3cba1d792f2857073d
m_b1532b6c6f9f40b882af948f134b3ab7
m_a9937a814f8f4ae89501365eb75eec58
m_852d327677824f71a64a2e50cdbf0d87
m_4de9dd74a87e424e981ea19efe7bfb98
m_3534f6dbfe6f45108a7842dfa3372a12
m_f52aa4f611104a8ca3fdf7b46c19df9a
m_3ddfa81d3d1547febb6aff660f4d612e
m_9c7ac35a31284166a0d026167f47078f
m_bd2270b39a7043c5b1bec9421b8b826b
m_96f3bdcefb4343238e0a476f99bf14a3
m_217e297eb76b4ee5b0e7556a58dfcc22
m_e22b0738f9444b5093557dd2bb64d397
m_e17dceff73ac48d1952612e9a941330d
m_2d65f5a74bd546f3ad8fab7b270384b5
m_7270dac7b41744339a20c2fe997406cf
m_d134332ee1c149e6a2f71a3d8f42a547
m_908de084ba284c5185306ae878697e0a
m_b3448b26b9f444f085dc5751be6290e6
m_dd1a5fc78b2c460488e531b7a435f65e
m_280d0daaebd14446ba7734024c91c669
m_391a1f70d7d24d88a9f8c475fecb0eff
PushWrapper
h8ef1f3c5658c4253a052ec2d4b87fccb
MapWrapper
PopWrapper
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
NVA.Bridges.MapperInterpreterBridge.resources
Gfqdflpmskahsi.Properties.Resources.resources
Gfqdflpmskahsi.Wcupmrcwxjlcmgwuoretvl.dll
WrapNonExceptionThrows
$6f2eee00-b9e8-443c-8c07-bceb11826ae2
1.28.2851.9944
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
4IDAT8O
X-]]ur
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
nIDAT8O
(}kM3!
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
HIDAT8O
Yyu-eU-
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
8IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
XIDAT8O
&$feUq
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
<IDAT8O
O #@RmeY
/2R:|
xm7v@1
,)}O,J
tb=qiL$
Ek#~=l
~_Xh1#
o6.+E;.
gV2Qm=
{tz3.U
9+wz:Cy
}q0X8s
,w{v3:Y
V&${VW
dWl;42
3:QQ1
6K<v'8m
/dB3b]
$2U-S!n
O\f?x7Ab
D$[PH45Gr
:S8B!uPE}
?FE5+$
<kG.aR
874b]k
s2Mjlop
Q \0lt
@599T-
HjY3PE
R(6V,4
jhI9jn
RqFb'^J
Yp0)>&
98|%=|
/+ENYg
BGCSuM
J+#G/ZA
w(r9d@b-
$<O)Bv
Z|ne55
JBb7bA
U)AZ%a<C
@f$&75
F6{{J,
_;?#:`
@nZ6d)e
7Z/)k{5
U-LEw
W(V,\
aX|Lw9&
M8`%y4@ H5
Vkj:d?O|
6B."4=
tfF?&:
%n*'Y)
wA8ec8,
2TJm7`
R6oa2=C
!u56-U
r7}f=O
n)^z?aC
4lV4ei
UX.9q:
=ZXBe1
"72&}9
ndksOw
{,JzML
~EoSIi-
[_.5|A
A?UrLa
]by=[v
*Z=iX(h}
^aW.J
g1ZNlO
*r~)=)#R
I!v]G(
Ss[U?V
|Nok=4
sod1VF
_OF7@
"X[]/?n
b/hbYF.2
SZeui2p-_
966\d6
O&F3dp
K-)?<C
m=!-rp
5`;d0z
\^?%#O
uh29T^
$Tp93p0
Na!(7QW%
: hZ`o
1FiHeBwt
umG&!CQ
1?;V]z
**b-gH1T
'p<t[>S
z>$,8n+LTk
hmWkl]
l</X$nU
.!\$?y
P`|3X4M
hC$oSXb
TQZ1h^)
>|FfG2Ua
*kp3-3V
\3/nr'
6upf$L
97nq<zh&|
6mb<rK
z6O]9d
,:YA_s
dLK+\K
x.4x2x
D2=n|m
x~:i%V
a7t:g|
%,[vZ`
Au74,8
iX,sKN
,%XO$)w\}Id1
4>M/\"
WuN&E@bb
3I@3`Hc
00?'l&\
`VKIbo
X[j(>x
#8a7F @[
yM6M*P
}Wub<7
#;EA*l
;Q42(*
E/~vu;!6
?c]sMO
|3[}a8
5<5g3WmB
-uQ;K?
r.8:O;C
DrSry"
<z#3zp+
hgZO]G6
Qj5_vQ
VOCAWH
TM&S`z1
9,ct8AJC
Hgr\6A
&NVBv
)>@&DV
,;Mf.s
>J}ll%9b>
$m\Vpr0
acf#3+
5F_RLO
?cpA!/
L@wYD!5q
%g#j9_
&^gr8G
i-`?f0
_AwU5~u
"e5]Wlr
1UXOsz
~A8w,9|
$/ )?#*GW
mbkV1)
=-6[1h
jY^8S)R
7s(%P
(w&i.U
fqHVH`
C;YsYi
s$NLP]"
I`z!T
>K>XlI
o|#(K[
|@Gb2@b
!p@S.|
fc(=|i
fcJv'e
P!z?bE
w;9ZDs
Clt,pT;
)&eUJH
/Tvbw?E
I'h0.M
PT97mpG
M?<Oy!
ws{e|xg
L8KEV<hCO
5XR-jH
|(JXHo
aW8zsX
O\:q<j
Ba9dBa
#i<Z@{x(
\95Cw!
3T:U}U
;dz*]Q
lKbw9^s
FMF&/x
]-I>>%^i
^+PBQw
&Rv/8u
NlN(A
(Zy2Hl'-
/#o^OP=
P6t`z3
>J2xk
fR3I&%
`Q sX9
j=5@XO
/<l,Cw
Jyp8lt
$+Rw\Nbi:9
Tid9zIV
gwc{G$
s{N%5f
_^qhY4
a}D\t`
?i;U1%
@FsMVk
y`CQKo
E|\[8V0(
%Ccg0(K
@1y;qB
(9EGj%
[*SGLzx
%0"Vx|
Ao?3-]
yLo&y=
yw`%Hy
yYS[];
Lf_c*U%l
l*XL;m
zJ21]l~
^8B%]*
`;43'\|
?gq/:Ny
SW%<yX
.dRd}
l3=lI"c%
gVn+H6vS5
P|1I;U
PEJ{\x
GTd~1l
WmH*NcN
;iWYq_19W
{LX<y)
GLFI3j%}
O1[EV&
)4Ng}lj
]lnA<"
]Est'xI
[;~"w_c
E6!T;(
Yu5JR|
|0~=16V<%
5H<e8w
(1$oFj
PpR5"z
p%*ReL"ht{
(XdTt}L.
o=J6"|
l#;HzK
Mwjxk(
C+Z7sI
n_he/
x$:O?b
L'Puy
>.0ck~
N`gdU
mVnJZ5q
B=uHq7
=fKd;^
49F|/w
D0:')r"
N=e$DF*
rp|)J}
r?I8?N
[g@QT(
N}La"V
,w6-an
[.HX%L
_XiCMW
3JY/]OW
fR#O;~to
0byY.d
BNSo,J]
DT,sn$
2=cP7 c
G{*Pt,
FZs5@ j]
aD.QxM{
^fuU]Q2|
.m9@Pc
}26N7U
yRuQuL
n709$}
ql[Bd6
Jv'|qB9
sGj&x0
l=HG}z
M H49M
C=8s-J
plwEx,
@,IzJp
Ep7M$l
{RWQ&H:
_`/,_a
l3|xkZ
sZFvFM
ZDQ0;0$
bm6^n'
8CUDFC
&0_vVGO
p^Q`xg
bw3#x&
=SF+ldlUuU
B2`m~45
j{,Ji!
'61e,l
% xPm,
dT5K,
v[35iXw7
3=M7*$
p\m~S'
6n/i2qE
D_{Ufc
:h;yRnk
_ylGqL
W/:+\{xk
]xk,G/
[{74Ma
q%*g(F8
k{6LRr
AYzOzy
'p[M$&
YN\CnM
C6\t.A
'A{ym8
A@nD;t
B|'=sG
s#cJ9e
T5nrKz
\%vAt
a'e2k?
^zLY0~
gvel\PD
)(p|!b
)c{h.F
Fu]4<M
5K4v!F
`H Q%4
M5gB0Hf
HL5S4
!=K8vd
stKK5P
H.?[//
'gMm/1!
:?:Chd
s-wwbx(
D&De[ rh
7#A3:(
w(;;7)>
h<HQ!H
i/8y]
6(0"y9vG
"g1 =bD
1C6( Yz
40sX@e
2>S YA
vPp&t(
pHah?'b
>kg.[c
e%@3<|P
L+~AOb
Vy"Y|G
y!S2{dg
-/:|3Q
i@I1nA
M@ ufc
P&Igi5
9[A@O3UX8
O{hq3i
1IFG3(G
<8]A&.
\H[]c4
o?#&S{
~VpJ3@cD
W"PT72
s;!aI\
"J}d$R
~q%R!,5
"Qax`mP
C_8euM
k23)$N
0hQ8 w
l5Yl_!bq
x/A|I9<"!
lf.L|k|,
yEJVak*
us377:
<@eP*b]
tm#rYF9
JB4Lqd
ZKx/ds
S"E`wp
X(' -r
:Fiy#n
=M\W'w
!.>E^m
1;>)II8E
T9WL4y
|H|[_Bf
I81HJ^
7]<ca*
b84 J
pq)m<}L
dVF(y.
"<+Z*q
g_eS,WD
<oX%`H
W~<U(
SAsn'<T
"P.|*p
,+]f^6/
n0=oTlN
*sT"o4C
6hMoB}
PM2*&_
U=^"r
rS&N R
WlRaF
c#1/kP
5^12XP;VX
~c.3xH
[Qm}Rxm
{}RCND
y+=P1k
Ezb=XeI:
CYGIu
q>'k)}
ZGEykMyv
2&M=c*H
Dq'M\ '
Qt]e`1
;&?4SJ
OP0^a]
JvU1g`
X2fP:Z
6y\q-&
!V{Jl#
6z*N z
"AGkyr
A"O*NM
w(WpQ
HZDgUu
NA@1a#
0q@)0I9
R3J9F.
lu(R&b
=U$#_c
j[Cf[|
SAMO#V+g
rhYiZRT
gt<'+#
skb_ds
>U1q^\o7
r",-ru
*#>3[Bh
[`.Qdk
udz_O7N
ePq(~{
d!K(~.
.P/vpp
Ut|br58
ZA~bmh
UhbQ/`rk#
xO@7H1
D}oTwT
|h9AM
)p(";
T{GK~J@
Ad'}cS
WxS*1Nh
n,V\y7
;d.*?
}>JU%D
srv2%Z
xB!tC
X'2n'V
Rh;%DQ
&L)*^b
I6@tev
C})3e<Z
^$:Hn9
\t+s%T
-C.&B3~
Y/+/8Yq
8~x?jc
M|8vhI
1:82tz
N>zKWsp
gt{%k0
..jX3An~
]rTi4.-@%
;M?`844F?Pe
Jcg#iI
r0 {Ol
q8n)+c;
?jn1_J
$Uh%o(
k5c6T|
9~~7}f
+cTm`xL
-#|UY%R
N?R/QS
XwQO>rM]
Tqe{E(
e( e]P
!AH$dXS
)HAN6K
zQWT}>2
K"\Q*)
Q!c+ D
t8JcsQ
ln'/ok#
{5?q0p
rZc|=
[jkx4Z+
#pWJq_
fUb>dT
y3QUD[
gj&EM(&I
XLq.sA
rPSSA>K
=l:gM?
^xeAiQS4h
BIdsCQ
I@t,?B
.62IOm
}3uSH}
n_M N4$
]u4Fi:
]Bz9%B%iM
*41%-|
PgarO*!
AxAMoBR
vC.lL)8C
U8{!"\YiQd
d0^\,w6h&
]%fXFV
o<d;J2:
"m|e|l
eCzI=i
Pq'JJ.
5Z}soIJ[Y
/l~V{d:
PP5dL+
^u_94Q)*
XH`@D>
D=2:&e
/.8^@VC'
Ii!GU;4!
?<uv5J
?m3-%F
c$hx@
k(\w:\ws
wugM#`
Aa'ZM4
0$.=j~
p*yMblO+
k%TvNX
ZQf-#(
O}tpy6Fz
Y5D$p6=Oh_/
c"F]u^
+cq#<
b<a$u
ORq.y@
=O:{T8
VXAJs1
^K9U[a
#61&!S}*
f$zQ<Be@g
: 0?Le
3SLS+"
Ky"fB[
,:fR}4Pu
ljId}uy
vA4|`*
A2sWgxA
J\^e!Q
GEd`?>
fgVODok
QpRij|(a,(HzU[
x`_lICCD85
>&jP!
O^n/% <
J0g,'^
.hf~XCPF
^|5w!|
eJGXw\
_J.G!L[
tnlp&0[4u
t<%V.^,
7m$yAU
beI|sz
'c``#[
#X('%b
zm8u.0F
C`4e[&
|`re2fF1q{
>!d'bZc
ymZn%J,
G\!a}b
FO,>I~
SuT@0a8
*W5~3n
GdOnN[&/
P;w6@B
1~D^^(g
a${KV1>5(r
~-l\hP,5
N[>wahe
nv8N4>l{F
jon+Zx
ZBYTi_`
Ulg+5;
sXOd9)
2TMp]:x
2`E%bV
fK+rc`
erMnP$
'LkF;@i
|Mw^/:1
>M/rf1
vB{$4h
Yft-u`2v
!Ttn/j
KSkNr#L
p6YZ@n*
Tu{(_H
%FIbqm
IuIc #
4jQdK[+I(
XdLVM2
mJMQO,.
\[En9
m.jB0!
hQON;w
-9K|"Uj1WrS+LE
V/SHFCmm
u|GM?="
GYTofYkk
b@S%EX
\=hP#
M8gj44
XBqm{]
lqMO#
"?W3w
pPSJ>2ZtOA
!}5pB,
]:ga19
Tya[ZBS
{-sRc`
OI0!-kR
^+yMew
drbz0J
k~4p]y
\>=?#ol
IW0g"&
U7;H7<6G
%5V=`
)_Rq.Qa
L>P_tf
7P|2HP
khP*>^W
},S}FL
sD)3}Z
dM3%mMu
1uLn1<
2}iI>X
0aKK$4 =
[x"H+h
J+&R[?
2w?)M)
0u}!&6C
vvb36P
-YT<&W|
0\NI.m
/=ve-T7
]DGpCU
9:JyJn
fS}E3=
)QiW&QQ
x*6n4s0]
N,<Vv>
ge*zg-
;'h;2;!d
'z;3}L
PV1;DkH&v2
J$4(QY
rOSt4A
w.x>+J
HBKGl[w
.1->y4T[
y5Tr!$
o"yP>5
ILPJL/
M.9=IB
R"n^lrXrZ
$zykZv
xX5/sC
h']I"
wcW<v[
ktG|(N!FQ`
9n:JR-k
0'<k7>)
R6<16
;9UFi`c}
>;,E){,
yJSZr]D
Kb+\sV`C
F~<\:>1
bzdz_j
P4zHS 6L
>zQb9l
2;}aN6-
7}X>
MnLN9-+
Xs0r"u
AW=hh,
kX}+I[
/Im; L
zAAXAK
k%4BMX
u/riqw
aU;=CZ
w>Ihk%
TIEqyY
x^&5
0nC_0{zv
r+g"q(
"FzAU\J
*q%msB
Fl&5y(Irn4
{h<g5%
E9P(|%
;,U3$<
u$@wnS
mLhiC7
)QF@;Hh
UeHpX~
B]jE._
``kpi\
i^N1ky
bds~8
5hYEQs
#j%JY&D
K6<&du
w"&Ai2
6YVgNh
%X1Ume
vD9do6
".<c+E
B9}s#F<BF+~!
<Dl-/w
}EDSc
/TgP<T
f(5NN@F
mzGx,T)
dq{a<A
mM7#'>
1XPE 9B(q
AW5<uP
B[F{Wl
s>&K5
B(=D||
_@)wgat
"/Cf.c
;YN/ -]
1BpdT+
PWG*D8
CO,FIa
G4S:X=
|IEQ+V
{4r0.
dmL]`'
#Z^cy]xU
wsY4a!G7
>pT6Zb
vbprc/z
wh{f\f
p!,R[}:
@ ?x0o
a\F|Ax
]z>8wKI
@MRpBX
k \$Xf
=WFw X
8yiB|V
UO/yD~
_CorExeMain
mscoree.dll
%<JOJx
M tabP
{NVejZ
5p^2P)
y5$4rv
~U~mQ&^]I#
L/}{^E3?
MV\\#|
q<@!@M
1td>6=p
>V=UXh
Fc@FSd
---------------------------------------------------------$
9998998998998998998998998998998998998998998998998998998990
9889889889889889889889889889889889889889889889889889889880
8988898898898898898898898898898898898898898898898898898890
9988988988988988988988988988988988988988988988988988988980
9988898889889889889889889889889889889889889889889889889880
9989889888988898898898898898898898898898898898898898898890
$-8888988988988988988988988988988988988988988980
&5998-
"-9889889889889889889889889889889889889880
099898890
-888898898898898898898898898898898890
&8898898898-
-89888988988988988988988988988980
&9898889889880
&88889889889889889889889889880
!98988988898-
88899980-!
'98898898898898898898898890
4988988989*
88898899899890!
*98889888988988988988980
"989889889"
99898898889889988"
!498898889889889889880
098988988*
98898898988988898884
0988988988988988980
889889888
9980488888988988889998
-9889889889889890
88898898-
-9889898898898
-98898898898880
98898898&
-988988988890
4988988988980
98898898!
!889880
"989889889:8*
88898898890
88898898!
4888898-
"88988889998
-898898890
88889889$
!99889898(!-88994&
*9899888889-
88898890
08898898-
(8889889"
9989898998*
88888988898
8988980
&98988980
-9889884
988988988999-
"8988988889!
88898880
88988989
(9889880
99889888988898"
9898899889-
-988988980
88898898
9889880
9889889889888895
-9888988985
$98898898890
*98898880
9889884
98898898898989898
$9898898989
8989898898890
98988989
4898898
998898898889889889&
9889888989!
589888988988980
88898898&
!989889!
9889889889898889889-
8889889889*
09888889889889880
!89889889
8889888
9889889889
589889889-
8889888989988988988988988980
98988988"
"898898
998898898"
0998988980
0:9889888898898988988988980
&98898898
9898898
988988988
*98898899-
49889889889889889889889890
98898898&
988988"
99889888
!98898889*
4988988988988988988988890
&98898898
0:98898
9889889*
98898989"
498898898898898898898980
988988984
88988985
9988985
88889889
88898898898898898898880
988988985
59889898
988988
59889898
8889889889889889889890
888988989-
09898889!
88898890
8889889889889889889880
0:9889889&
!98898898
88889884
49889889889889889888980
-98889889$
0:8988988-!
88889888
0:9889889889889889898890
&98988989&
88988888990
!88889884
0:98898898898898898889880
88898889*
88998889-
499889884
09988988988988988988988980
098898894
'98889-
*98898898*
099889889889889889889889890
"98988989
0:98988988!
8989889889889889889889889880
49889889-
-&"$(0999989889884
98898898898898898898898898890
!98898998!
8999998898889889!
&989889889889889889889889888980
098888888
98888989889898'
49999889889889889889889889889880
498898998&
998898898898"
999898898898898898898898898898890
8888888890$
988898898$
0:988988988988988988988988988988980
8899898:9980&
----&!
)9:9898898898898898898898898898898890
-988998899999-
)99998988988988988988988988988988988980
!5889898888-
-:998898898898898898898898898898898898880
!0:98899-
"99:9898988988988988988988988988988988988990
!-8999989889889889889889889889889889889889889880
*&"&&-0989898898898898898898898898898898898898898898898880
99999:9898888988988988988988988988988988988988988988988990
8888888988988898898898898898898898898898898898898898889880
8988988898898988988988988988988988988988988988988988988880
:898898988988988988988988988988988988988988988988988988990
8988988988988988988988988988988988988988988988988988988880
:898898898898898898898898898898898898898898898898898898990
9898898898898898898898898898898898898898899898898898898880
!!!!!!!!!!!!!!!!!!!!!
'444444444444444444444
'444444444444444444444
#,34444444444444
#03444444444
'4440&
#33444444
#')/3343#
034444
03,#))!
'4444&
'444440
'443#443
4443434444
443444444
44444444
#44444444
!444444444
%4444444444
'4443&
,44444444444
#3444444444444
%334444444444444
!#',344444444444444444
'433444444444444444444
'444444444444444444444
#############
(1111111111111#
"+1111111#
+1111#
-1#111&
-1111#
+1111#
(11111&
*111111#
!11111111&
(1111111111#
(1111111111111&
! !
##########
'.......
*-.....
'---......
######
!!!!!#
jA;?mxn
l;+na
~M1yf^
RG6iLH
l(oIoAj
b|1S$:M
(.lJFVR#&G
\Jj[N-R
;41Gt+
qIDAT=
v{0<LY
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
({0}, {1})
button4
radioButton1
button3
button2
listView2
label1
dateTimePicker1
listView1
checkBox1
notifyIcon1
button1
other test
Gfqdflpmskahsi.Wcupmrcwxjlcmgwuoretvl.dll
Catcher not started
Qpvpzavehswfbdle
Received
IntPtr is already 0
Last Error isn't success:
Message isn't WM_COPYDATA
Gfqdflpmskahsi.Properties.Resources
_00_Blanco
_01_Smile
_02_Laugh
_03_Silly
_04_Wink
_05_Blush
_06_Sad
_00_Blanco
_01_Smile
_02_Laugh
_03_Silly
_04_Wink
_05_Blush
_06_Sad
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.28.2851.9944
InternalName
NVA.exe
LegalCopyright
LegalTrademarks
OriginalFilename
NVA.exe
ProductName
ProductVersion
1.28.2851.9944
Assembly Version
1.28.2851.9944
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Quasar.4!c
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.9486fe80718f69b1
CAT-QuickHeal Clean
Qihoo-360 Win32/Backdoor.Quasar.HgIASXwA
McAfee RDN/Generic.grp
Cylance Unsafe
Zillya Trojan.Quasar.Win32.5235
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057eea61 )
BitDefender Trojan.GenericKD.46569617
K7GW Trojan ( 0057eea61 )
Cybereason Clean
Baidu Clean
Cyren W32/Trojan.CION-4018
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABUK
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.MSIL.Quasar.gen
Alibaba Trojan:MSIL/Kryptik.b45f235e
NANO-Antivirus Trojan.Win32.Quasar.ixhcsx
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.46569617
Rising Clean
Ad-Aware Trojan.GenericKD.46569617
Sophos Mal/Generic-S
Comodo Malware@#1caxji34vkrhu
F-Secure Clean
DrWeb Trojan.Inject4.13548
VIPRE Trojan.Win32.Generic!BT
TrendMicro TROJ_GEN.R011C0PG521
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Emsisoft Trojan.GenericKD.46569617 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.46569617
Jiangmin Trojan.MSIL.aesie
Webroot Clean
Avira TR/Kryptik.qvofh
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
AhnLab-V3 Trojan/Win.Generic.C4542132
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34050.Lm0@aCuHmP
ALYac Trojan.GenericKD.46569617
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Backdoor.Quasar
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R011C0PG521
Tencent Msil.Trojan.Quasar.Htby
Yandex Trojan.Quasar!T5sEaD+qGKI
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ABRS!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.73405263.susgen
No IRMA results available.