Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

9f4693fc0c511135129493f2161d1e86

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000722c 0x00007400 6.51167217489
DATA 0x00009000 0x00000218 0x00000400 3.15169834056
BSS 0x0000a000 0x0000a899 0x00000000 0.0
.idata 0x00015000 0x00000864 0x00000a00 4.17385976895
.tls 0x00016000 0x00000008 0x00000000 0.0
.rdata 0x00017000 0x00000018 0x00000200 0.206920017787
.reloc 0x00018000 0x000005cc 0x00000600 6.44309346589
.rsrc 0x00019000 0x00001400 0x00001400 1.29674401743

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00019150 0x000010a8 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x0001a208 0x000000ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0001a2b4 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN data

Imports

Library kernel32.dll:
0x4150ec VirtualFree
0x4150f0 VirtualAlloc
0x4150f4 LocalFree
0x4150f8 LocalAlloc
0x4150fc GetVersion
0x415100 GetCurrentThreadId
0x415104 GetThreadLocale
0x415108 GetStartupInfoA
0x41510c GetLocaleInfoA
0x415110 GetCommandLineA
0x415114 FreeLibrary
0x415118 ExitProcess
0x41511c WriteFile
0x415124 RtlUnwind
0x415128 RaiseException
0x41512c GetStdHandle
Library user32.dll:
0x415134 GetKeyboardType
0x415138 MessageBoxA
Library advapi32.dll:
0x415140 RegQueryValueExA
0x415144 RegOpenKeyExA
0x415148 RegCloseKey
Library oleaut32.dll:
0x415150 SysFreeString
0x415154 SysReAllocStringLen
Library kernel32.dll:
0x41515c TlsSetValue
0x415160 TlsGetValue
0x415164 LocalAlloc
0x415168 GetModuleHandleA
Library advapi32.dll:
0x415170 RegSetValueExA
0x415174 RegOpenKeyExA
0x415178 RegCloseKey
Library kernel32.dll:
0x415180 WriteFile
0x415184 WinExec
0x415188 SetFilePointer
0x41518c SetFileAttributesA
0x415190 SetEndOfFile
0x415198 ReleaseMutex
0x41519c ReadFile
0x4151a4 GetTempPathA
0x4151a8 GetShortPathNameA
0x4151ac GetModuleFileNameA
0x4151b4 GetLocalTime
0x4151b8 GetLastError
0x4151bc GetFileSize
0x4151c0 GetFileAttributesA
0x4151c4 GetDriveTypeA
0x4151c8 GetCommandLineA
0x4151cc FreeLibrary
0x4151d0 FindNextFileA
0x4151d4 FindFirstFileA
0x4151d8 FindClose
0x4151dc DeleteFileA
0x4151e0 CreateMutexA
0x4151e4 CreateFileA
0x4151e8 CreateDirectoryA
0x4151ec CloseHandle
Library gdi32.dll:
0x4151f4 StretchDIBits
0x4151f8 SetDIBits
0x4151fc SelectObject
0x415200 GetObjectA
0x415204 GetDIBits
0x415208 DeleteObject
0x41520c DeleteDC
0x415210 CreateSolidBrush
0x415214 CreateDIBSection
0x415218 CreateCompatibleDC
0x415220 BitBlt
Library user32.dll:
0x415228 ReleaseDC
0x41522c GetSysColor
0x415230 GetIconInfo
0x415234 GetDC
0x415238 FillRect
0x41523c DestroyIcon
0x415240 CopyImage
0x415244 CharLowerBuffA
Library shell32.dll:
0x41524c ShellExecuteA
0x415250 ExtractIconA

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
_^[YY]
HBITMAP
YXZQRPR
R;P P|
IVXLCDMT
_^[YY]
_^[YY]
XH;XH~
9PD}-RP
PH9PL~
KH+KLQ
;CHRQ~
RP;P ~
tSPRQj
_^[YY]
QQQQQS
\PROGRA~1\
QQQQQQSVW
_^[YY]
QQQQQQS3
QQQQQQ
QQQQQQSV
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetVersion
GetCurrentThreadId
GetThreadLocale
GetStartupInfoA
GetLocaleInfoA
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
user32.dll
GetKeyboardType
MessageBoxA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysReAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegSetValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WriteFile
WinExec
SetFilePointer
SetFileAttributesA
SetEndOfFile
SetCurrentDirectoryA
ReleaseMutex
ReadFile
GetWindowsDirectoryA
GetTempPathA
GetShortPathNameA
GetModuleFileNameA
GetLogicalDriveStringsA
GetLocalTime
GetLastError
GetFileSize
GetFileAttributesA
GetDriveTypeA
GetCommandLineA
FreeLibrary
FindNextFileA
FindFirstFileA
FindClose
DeleteFileA
CreateMutexA
CreateFileA
CreateDirectoryA
CloseHandle
gdi32.dll
StretchDIBits
SetDIBits
SelectObject
GetObjectA
GetDIBits
DeleteObject
DeleteDC
CreateSolidBrush
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
BitBlt
user32.dll
ReleaseDC
GetSysColor
GetIconInfo
FillRect
DestroyIcon
CopyImage
CharLowerBuffA
shell32.dll
ShellExecuteA
ExtractIconA
0"0*020:0B0J0R0Z0b0j0r0z0
4-595T5
8&8,848F8R8a8m8u8
9/9:9[9s9
<'<0<;<D<K<Z<a<
?2?\?e?u?}?
0(0@0L0T0k0z0
0,1P1n1~1
2$2u2|2
4#4+4O4o4
8A8Q8g8
9*929H9`9n9
9+:X:a:
< =T=\=g=
>N>R>X>\>a>h>n>v>
?%?/?7?=?K?f?{?
N0W0}0
466?6:7C7
<)<2<><E<
=/=;=B=L=V=m=~=
>/>@>J>R>Z>b>j>
?&?+?0?7?>?H?_?k?x?
0:0B0J0R0Z0b0j0r0z0
1"1*121:1B1J1R1Z1b1j1r1z1
2#202B2J2R2_2k2x2
3 323?3K3X3j3w3
4$4(4,484<4@4L4P4T4`4d4h4t4x4|4
9,;:;A;H;c;o;
:(;=;c;
=*=:=Z=
9_9d9w9
:.:E:c:z:
030F0X0\0`0d0h0l0p0t0x0|0
1%191M1a1
004080
1 1$1(1
Delphi-the best. Fuck off all the rest. Neshta 1.0 Made in Belarus.
! Best regards 2 Tommy Salo. [Nov-2005] yours [Dziadulja Apanas]
VolumeDown
OnMouseDown
ToolStripDropDown
add_Shutdown
get_mnuChooseVideo
set_mnuChooseVideo
get_Info
dwExtraInfo
CultureInfo
set_StartInfo
ProcessStartInfo
HitTestInfo
AssemblyInfo
get_Audio
VolumeUp
add_MouseUp
remove_MouseUp
grdPlaylist_MouseUp
Bitmap
ToolStrip
set_MainMenuStrip
ContextMenuStrip
get_mnuMenuStrip
set_mnuMenuStrip
ShowHelp
OnDragDrop
DoDragDrop
clsDragDrop
DataGridViewDragDrop
set_AllowDrop
EndApp
set_ShowInTaskbar
Linear
Agregar
Limpiar
HelpProvider
m_AppObjectProvider
m_UserObjectProvider
m_ComputerObjectProvider
m_MyWebServicesObjectProvider
m_MyFormsObjectProvider
sender
Buffer
buffer
get_ResourceManager
ComponentResourceManager
ToInteger
addedHandler
SerialDataReceivedEventHandler
MouseEventHandler
DataGridViewCellValidatingEventHandler
ShutdownEventHandler
System.CodeDom.Compiler
IContainer
get_User
TextFieldParser
StreamWriter
TextWriter
set_Filter
OleDbDataAdapter
SqlDataAdapter
get_Computer
ServerComputer
MyComputer
OnDragOver
Player
set_Anchor
get_Major
set_BackgroundColor
set_ForeColor
set_SelectionForeColor
set_BackColor
set_UseVisualStyleBackColor
set_SelectionBackColor
get_Minor
ClearProjectError
SetProjectError
Cursor
HelpNavigator
IEnumerator
GetEnumerator
get_playlistSeperator
Activator
.cctor
m_frmEditor
get_frmEditor
set_frmEditor
Monitor
IntPtr
get_mnuFileSaveAs
set_mnuFileSaveAs
get_Tablas
System.Diagnostics
ReadFields
dwMilliseconds
Microsoft.VisualBasic.Devices
get_WebServices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
get_mnuSettingsPreferences
set_mnuSettingsPreferences
System.Resources
StarPlayerPC.My.Resources
StarPlayerPC.Form1.resources
StarPlayerPC.frmSplash.resources
StarPlayerPC.frmEditor.resources
StarPlayerPC.Resources.resources
DebuggingModes
get_Tables
set_EnableVisualStyles
get_ColumnStyles
AnchorStyles
get_RowStyles
get_SerialPortNames
GetSerialPortNames
GetTypes
dwFlags
Strings
get_Settings
AutoSaveSettings
MySettings
get_CommandLineArgs
SerialDataReceivedEventArgs
MouseEventArgs
DragEventArgs
DataGridViewCellValidatingEventArgs
ReferenceEquals
get_Cells
get_Controls
get_Items
get_DropDownItems
playlistItems
System.Windows.Forms
get_Forms
MyForms
Contains
get_Columns
set_AutoScaleDimensions
Conversions
System.Text.RegularExpressions
System.Collections
MouseButtons
I_Campos
get_campos
set_campos
nRegistros
I_Datos
get_datos
set_datos
RuntimeHelpers
SetDelimiters
SystemColors
Operators
ConsultaDBAccess
GrabarDBAccess
InsertarDBAccess
Process
DragDropEffects
set_DataBits
set_StopBits
components
get_mnuHelpContents
set_mnuHelpContents
System.IO.Ports
get_Ports
get_lstPorts
set_lstPorts
FileExists
checkSongStatus
get_lblStatus
set_lblStatus
get_Rows
EnumChildWindows
SendKeys
RemoveAt
Concat
get_Repeat
set_Repeat
get_TrackRepeat
set_TrackRepeat
Format
get_Effect
set_Effect
IDataObject
addedHandlerLockObject
GetObject
TargetObject
MyProject
get_btnConnect
set_btnConnect
LateGet
DataSet
get_ControlLightLight
set_ItemHeight
get_Copyright
set_Copyright
SendWait
op_Explicit
EndEdit
EndInit
BeginInit
GraphicsUnit
get_mnuFileExit
set_mnuFileExit
get_SaveMySettingsOnExit
set_SaveMySettingsOnExit
get_Default
SetCompatibleTextRenderingDefault
IAsyncResult
DelegateAsyncResult
DialogResult
MsgBoxResult
System.Data.SqlClient
PointToClient
ContentAlignment
Environment
InitializeComponent
hWndParent
get_Transparent
get_Current
keybd_event
set_Font
get_Count
set_ColumnCount
get_RowCount
get_TrackStart
set_TrackStart
Insert
get_SerialPort
set_SerialPort
HitTest
get_grdPlaylist
set_grdPlaylist
SavePlaylist
OpenPlaylist
AddItemToPlaylist
ClearPlaylist
set_TopMost
get_mnuHelpAbout
set_mnuHelpAbout
SuspendLayout
set_BackgroundImageLayout
ResumeLayout
PerformLayout
set_DefaultExt
MoveNext
PlayNext
System.Text
get_Text
set_Text
AppendText
ReadAllText
set_ToolTipText
set_HeaderText
get_inputText
set_inputText
GetWindowText
SetWindowText
get_mnuCellContext
set_mnuCellContext
DebuggerVisualizerAttribu
PlayPrev
get_mnuFileNew
set_mnuFileNew
DataGridView
get_Now
get_mnuRemoveRow
set_mnuRemoveRow
CanDragDropRow
get_mnuInsertNewRow
set_mnuInsertNewRow
DataGridViewRow
FindWindow
SetForegroundWindow
get_mnuInsertRowBelow
set_mnuInsertRowBelow
set_TabIndex
get_SelectedIndex
get_ColumnIndex
set_FilterIndex
get_RowIndex
GetRowIndex
get_ContextMenuRowIndex
set_ContextMenuRowIndex
get_NewRowIndex
rowIndex
STRconex
set_MinimizeBox
set_MaximizeBox
MsgBox
set_ControlBox
ComboBox
ListBox
TextBox
StarPlayerPC.My
AndPlay
_latency
ContainsKey
spotify
get_Assembly
set_ReadOnly
BlockCopy
ExecuteNonQuery
set_RestoreDirectory
set_Parity
MySettingsProperty
NotifyCurrentCellDirty
FileSystemProxy
WrapNonExceptionThrows
StarPlayerPC
StarPlayerPC
Copyright
2018
$6cdf1603-5a4c-4bcf-acf4-14ad523f5605
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
Timer1
lstConsole
btnConnect
lstPorts
Label1
lblStatus
inputText
Timer2
SerialPort
mnuMenuStrip
FileToolStripMenuItem
mnuFileOpen
mnuFileSaveAs
mnuFileExit
mnuFileNew
HelpToolStripMenuItem
mnuHelpAbout
SettingsToolStripMenuItem
mnuSettingsPreferences
mnuHelpContents
grdPlaylist
HelpProvider1
VideoToolStripMenuItem
SaveAndPlaybackToolStripMenuItem
mnuCellContext
ToolStripMenuItem1
RemoveRowToolStripMenuItem
InsertRowToolStripMenuItem
DuplicateRowToolStripMenuItem
ToolStripMenuItem2
InsertRowAboveToolStripMenuItem
mnuChooseVideo
mnuRemoveRow
mnuInsertNewRow
mnuInsertRowBelow
mnuInsertRowAbove
TrackFilename
TrackStart
TrackEnd
TrackRepeat
ApplicationTitle
Version
Copyright
MainLayoutPanel
DetailsLayoutPanel
MyTemplate
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.7.0.0
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
My.Computer
My.Application
My.User
My.Forms
My.WebServices
StarPlayerPC
playlist
QC:\Program Files (x86)\VideoLAN\VLC\vlc.exe|C:\Program Files\VideoLAN\VLC\vlc.exe
My.Settings
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
v(hU$x{@
VW;G-v
(Y-;@!
|w7[{I)
kOjUJ*
gxL$$
&>rB"
h,?hXD
SZ[$-Z
TH%!j^
zvgaInJ
`Rlgb23
h@WC5J)t
r:32Y
VeH#e\
l>\Sq9
M9hRvic
EQr6O5
cp4>t
nL>+_;o
P$2[p
2Gv.Uo
'gSN(;
DhMu?z
9HC<qY
vvB*A#
pKjP@X6HQ
(TYpH)pt
q'#P$'
qL9Qn:
Gusf E*6:
?uOO0?z
`vaHhT
D7z#T
ka.`-8<
bsDXtZ
Rft#n):
"Q1Mym
"G!:`$!D
<B%@po~
`$z-@"Of$:
ki"Jik
`SJQG
Cx={m0
ChYV?r2
6/9?e7
H<!,M%
XRH|i9&
c=h)%fz
C6;h~J
!,5'7O
a(uGqPX
<:go(n
95K1"
b@J<M-
)&vK[Go
;rKl yX
#{$F33
0uX,C)B
^Q`!z$
/@UQDQ
[[C$v5
Z5?pz&
cDt%ed
9g)FH)
N;N<!dZ
@8iXka=E
rdME(Tk
$a9khW
J5(j[N9
0jfX?H
XO%`.I
<P^bfH
n=$C X\\
BR}?x.
k6#/PN
m! Y5g
EWkBRJ-
\3t4Yk9sY
EQ"Tov}
44{Qwj
R46o4b
Nm*0KE
$!`lbH
LQ^_]
e-Tt}Oi67
a~+})x
:_=G~j
}$;P+g
'O t,gD
Q{]`Hh1BT
HUo\^^
X]Y%~
,AqBJq%
w!"xN+j!
U]+WEm
3}(R!A
.`>,&`
k3vU50
a4Z:Im
2f}OBM
CoQqd#.
QpJ#j.H
Z+rbYN
a1`1,0_,
W-,#cG
7,(:qp
zxN @DZ
1%45c+
,k%hU+
L"X*;Xkw
ZI$j,L
GBN4fa
s"!s#! s$#!s%#!s%$"s%$"s%$#s%%#s&%$s&%#s&%"s%$"s%$"s%$"s$#!s#" s"!s"!s!
764cRPN{VUS{ZYW{]\Z{_^]{a`^{aa_{aa_{a`^{_^\{]\Z{ZXW{VUS{QPN{864e
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
gSystem.Drawing.Point, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADP
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
AV{,eR
5vj[E
5rv]E
5rvQE
5vgAE
5t1SE
?z!gE
#t1}E
~}}5vi
5p9CE
5vIGS?
7^PIE&
5pvqE
?^RIE&
5t9iF
?^[IE*
3^\IE*
5vi&z
IEh\dV
5tvpE
5tvrE
E^&IE*
5|9GE
5vW[S
I}C]dV
5tvrE
5vP6j
5|1E
#tbFE
"^QIE&
5v9HE
4^GIE&
?|9OE
5NnIE
5rg[E
7v1sE
5^~IE*
#v1 E
3N/IE
5P9IE
<gXM(
5v!8E
:v13E
'w12E
5p9LE
5|1sE
5va7
5v9JE
1v11E
5tb^E
|'g5vIo
5|9NE
1t9KM
7`dPE
*Uj5E
5pk:D
5|9YE
*cj5E
.^#IE*
5pk>D
5|9BE
.^#IE*
#i:VN?
&z9NE
*G1sE
?i::9
.i`t5v
.^#IE*
,i3Vo?
IE ,`V9
IE (fV9
5v1sE
.i'j5vIm
5^#IE*
*Uj5E
~'c5v:
#^fIE&
5NKIE
?VIE
5p9IE0
?tbSE
5|dQE
5|9LE
5r!cE
5p#tE
5r!cE
5N'IE
5r!cE
5NzIE
5|dTE
5p SE
5P9KE
5v\OE
5N3IE
5v1sE
t'O5v:
.i`w5v
3v!IE
5NQIE
,^~IE&
5NcIE
5v! E
IEE\dV
*[1sE
j'S5v:
)i)Vu?
L'S5v:
4vikE
I}b\dV
5NQIE
5p# E
5P9JE
5|9LE
~',5vs
i',5vs
IE cdV9
5v!BE
3qYCE
5NrIE
9teoE
IE 2dV9sa
5v?iG
.i`t5v
5v!:F
?l1.E
.i`w5v
}S4vikE
IE 3`V9
7v1sE
5N?IE
5v?i@
5P9ME
5tb`E
5N:IE
5v0IE cdV9
5v IE
1t1ID
1t1ID
5N=IE
5NLIE
5v!mE
5v9JE
5v_m'
3t1OD
5N!IE
5v\@E
4vIT$
!^#IE*
,i7Vk?
3NJIE
4vIE
5P9LE
5N.IE
5N9IE
1|9LE
5p E
5tbxE
4vIo
*D1sE
#t1jD
3O(IE
$r1#E
5|1nD
4vI`7
5|9@E
-^~IE&
5NIIE
4va{!
5v?iA
"^'HE&
5` RE
5v\OE
3^$HE&
5NVIE
4vq}
7z!gE
=q1ME
5N1IE
&r9LE
@|O\dV
5tb~E
5v*IE
5vOIE
5^'HE&
4vZB1
?v<^ml
5w<_CO
5p ;E
5v9ME
5v!IG
3tbpE
1^yHE&
7^gIE*
4vIAOX
?r1*D
't13E
't12E
?^EHE&
3svMD
5|vOD
IEH\dV
IEe\dV
5v\AE
4vIG7
5p#;G
'r1GD
5v!+D
,^~IE&
7i%Vy?
2i4Vh?
5|vXD
5v9KE
5|9ME
7v1sE
:w13E
4^cIE*u
4^cIE*u
<:w12E
4va>!
4vqk
'w12E
4^bIE*u
4^cIE*
4^bIE*u
4^cIE*
4^bIE*u
3^eHE&
5NoIE
4viG
-^MIE*
*^1sE
5v12D
a-x'e4vB7[
*D1sE
7^;HE*
;^>HE*
"i1Vm?
I}S^dV
2t1`D
t'i4vAe
2t1`D
t'i4vAe
&^cIE*
&^gIE*
.i't4vI`7
*b1sE
~'u4vqo
IE DeV9
5v!BE
v'r4v[M
=^bIE*
=^fIE*
'~1lD
'~1lD
'~1}D
{'n4vZK2
0^?HE*
$s1oD
7v1sE
7v1 E
5P9JE
5N[IE
5N+IE
5tbrE
~'J4vp
3}9ME
5|![G
3OvHE
&s9@E
7v1sE
t?_E"/
5vjWE
5S1hE
$rvkE
5^2IE*
5v1SE
5t1bE
t?_E"/
5tbeE
%v)IC
3vhI!
v}IC ^
?v|K+"
2uI`#
#vmN['
*~}IW
QvI0*
|PKC B
{}IW
}f}IC
'v0ZB#
'v#_B#
3vySu
3v.R!
5vPIB
=v?IE!
5v}JE
LueJ
Pv+In!
3n@Ir
lv.ID
=vAjE
=vymE
TuNJT
vmdE
#v%fE
Fp*I=q
wvI!E
su&Xc(
~vU E
3~Q[V
hvy<E
m~cg5v
lv.I+
d~gl5v
6v_Jz1
s~'i5v
=vAw6
3~/_E#!
=vIq7,
=vAT9
3n@Ir 9
4v<LE
7v<LE
7v<LE
0v<LE
4v<LE
7v<LE
4v<LE
4v<LE
7vtXE
4v<LE
4v<LE
4v<LE
4v<LE
7v<LE
4v<LE
3v<LE
7v<LE
4v<LE
4v<LE
6vgXE
<v@IV
lvGI$
lv.II
)v@Ir
u2HQ j
uxHq)$
lv.I$!
Lt@Ir "
v.Er j
uNQj+B
lr@Ir
4v7Iv
}pIF*d
}zHN*>
Wt{HE ,
5v)J<"
4v1IJ
4v%I\
5v$PE
5vI@
5Xz=*R
5$l'1I
Gw.Ea
PvX:6E
L7m=7I
G~!1a
Q7m=7I
Yz(1I
5;p*7O
Y4x:,C
cj<$L
X'yxEJ
Aw.6
Xv\.EC
Z4v1Ei
\vs0Eu
P>x'!L
57z=,V
P?w:1A
A2x=$
Gw.Ek
A x%0E
L%|;3I
j x%0E
TvK,6O
GvJ06T
57j: M
|5v'1A
PvJ<6P
Bw.EG
50k&(a
^v]&&K
j%p3
fc,ES
^5v%*R
Qw.ES
5%p3 f
A)X%,G
Y~'(E
X%p3
C$HI=r
C$*I0r
Ev[01E
ZvW,=T
Qv^,1t
55q(7
FvH%Ea
[z&!E
ea,)
A3o,+T
G1k(!I
5$|*1A
Rv_ )L
GvP'1E
SvZ&+V
XvZ%*S
[;v<6E
j;v<6E
E)\15L
ww-,N
A)J$*O
F3JI2e
P3a*-A
5&v +T
R'l()I
AvM,=T
[vj*p
VvM,=T
P5v%*R
A)_&7E
54v;!E
5&o+ER
5.\{Ej
YvS?$
A3w<(E
X3o,+T
j2x:-s
B0v*0S
XXZ&)L
`v];$W
Pvx?6
Vvnx3
rvJxr
Q?w- X
5?t("E
j0v'1f
5#(>Eq
58(zEb
5.(1EA
5?(Eo
5#X?EX
P7m=7I
XXZ&!E
52|+0G
Q;v-0L
5>p- m
G4k&2S
52|+0G
svvI7
VvlI7
ZvkI(
[v|I7
AvpI*
PvxI!
gv|I6
Tv}I
]vMI-
avxI'
5gMI$
AvmI*
RvqI1
avxI'
ZvuIt
ZvlI7
wv/Ip
Tv~I
TvqI*
d9HW,
d9HW8
Pp9HD1#B
p9HD2#&
q9KD1"
7~iD!
'=p9HD2"R
p9HD2"
Qd}AA*
LXX95L
5EJ06T
L"`9 D
Aw.6s
;5q,&K
,%`:1E
jdT0km
5BJ06T
Y%`:1E
FXK,6O
5VYIE
svpI)
[vjI)
AvkI,
PvPI+
4v)Iu
Xv|I+
bvpI+
PvjI&
ZvwIE
Ev|IE
\vuI
ZvwIE
[vmI
TvtI
Ev|Ik
vvvI5
4vUI
Tv}I
GvpI"
\vuI
vvvI+
YvuIE
GvvI!
Xv|IE
Ev|IE
GvvI!
GvjI,
4vXI6
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^T
~By~Lg
M8{|Kg
rqGk<<;
s,bDlf
7y;.{]
'b>/S(*F
r3N!?W;
d~k8Un
"F <#:
!3PLi4
;[]u-;
&q= L2
5:*CEx
eci7Og6
vfy+yHg0
~>P`J.
MK?2{
\g{s7,
L#f/]^
FGji<=
H9$I8j8
z)O6#4(
|vJ{\9=
_ }P?|
;W[Ltd
\-7q[Ii
R2u7k8
'd_ap>
.#8$AYC
=,"~V-~uBy
eT~C3[O
-.0|6
h{\*YUr
#Nn<Ts
S@{fZl
rz_}:/
UtE98N
`voS#t
.IJ[*,3
~(>xMn
?m^|VcS
m@8V3x
s@rg3i
p-:3-!
8W/<<Q
DkP[K7
ZgE@vX
R_SQv*
dogy.
jUW:=&
<VDwxb
*x(*h#
4`Hn)Y
xK"8d_
DWaVmw
_t<_da6
T>jMT*
Spzog7s
S9Y`.[
N;kZ{[
&"muRY
'6Nf-?
O-I%{4
I+ne8
)9ifF:
VnETaP
8@dH R
sUlPT
R3W}d.
\-_RI`b
W 0Z5H
w=iRV/
}-7+?n
hi,7o5
A}#U+:
ay=ej"
l/)~=A
U_f[}}
oGsdb@
aIwgWKTF
sn4q>X6>
{sFpLr
Q@jYXOd
f4NQ"R^
7?QHzve$
o{x3_s
EJ36~z|Q)
&g,9~i
u`)K"
F}xP}
u~x-Wq
/.evN-
7|'s86)
W{twV*
^G=h7adq
K?x_|~
Sp$3`w
0dl 2(@
q5;D[9
~$!'k
49%\}~)
}!s]k'
cB{# |
0I3sAxT
Rep,Hy
!h874~T
;VY.PV
D1>:_V
>HE+J2a
MaRoL|
6QH F~4e
Mfi_Y>wl
=}\W#apO
n[=[0o
|?HI1
OchkwT
ML_xz
5_*1o%
VO^9w!SO
y+:v>|
pz/LZ5/
C0,k-ZV
WLf8.<
h,l+x'x
bS/WK7O|l8
(\;DhsWlX
~MqmHE6
lQbwW$
3p,zc=
]mt&k*_
WpRYhtO
>G4 ]l
#kJQVo
r]Tt1r3
sKk.?2Vl38vH
h_]sZJA\
}%YPE&
5|u.%|b
wcS~_0*
szM<6^
u_*NLR
-*i~)s
&ByX:
wPW+`j
)?fm|h
l35g*
Sh'wd5\
sw>6FF
PP?=Lq
'&3)@jpH-
-THV=Y
{L}Msoz
~8q@}X
Z|l8>~
9.?fTL
mnbL4
;_8,)s
m[?H6^
+xa1(4
]#6w`:
oPv&~_
I,bGdG
z|KfJ;t
9ir6OUW
elGso3@u
|0o5J;
3D1]Vsv
8r}XLL
V/Y9>R
~uwoV<
Th6bI&G_
I0j7
J@~ ca
p(bR}f
IHBV}~cC
_j-u^(p
d=6^\Cu
|5*QJ
5pwG>j
RYG9O.k
ZYA,*)k
[@E,^ Cc
mN qKLJ
;/-mI'
Xbj$_WBr
>F^G[E
zek$%Aq
7C!I6qk
{w}W?gc
)v^OzI
=Wm;kr
8AGN`s
KF^>_v
Qx]5S
SQK:26
+q5 *5
E<@Qo<*
N=t0gP)
=ayW99
rBE-Z74o
!adx(CS@=}
YFm=(&]
~>[|W+
=~C%]P
)xUv|hL4
]:Q>'#|p
cbv%%
sieIH~%
"mqaF_
ea{))p
3J[%m!&5
UzkJvm
'.HLlx,
T">U_Uh
$oOrdEm
6/,M{wy
`hi#!_
jVg99R
:4f4'T
Q]4a}
,f0029
"\e7pS
CEx\mG'
/$qYka
Y[M~=6y
Cf$#jY
<Roj^+E
^v}ZJ4
J.m;"?
%~1]n5
8#4,4!
On Z;Kx
Dn`@Qn`jz
Y<A~}zF
.~vdr~
D!n|xz
;~EmL;c
b&zR#U-
`-'(OpkA
B<7Gkms
=mw_U'~
<`a0Ri
g,MiiZ+W
O/qt9q
N<T{fY$5h
ENEs#p
Ha'@_4z
Ne_LVX
)F-|GV
rEJYtvG
E'SGX&
.)%_(z
G4GS"Cl'
fgm)N|
e`<#A\
VE?#\)'
53AXT^
"RGw7v
)1BUmqR
_3W{nI
#V"7~?~<<e
0Upau@
csM >|9
Abpy5(j
Yt9+% sjy
00w8>4
fNK-J<)
+i:67]
<3jTr
|}iiAW9
(Nr^=;
mV29i*2,
yyuS^Pz@l"H
Lf2'm=
yb[i[g
d<~buL
,2)0vA
Mp*yA_
iB'.//
:"l*<9
^hY1VDxhWH!
d4danP
R9rtFE
Ac]"8,#,H
6,X" \
*}~N]J
gD%3~
h(@8Er
-u87hd
QyXNsn
zM)4"w6
Y"Wwp*,
IIXwXXl#|G
RJ@mJT
I<mk"-h#
i8O4c{
h[.:.*L
e#BGXa
v1Jw/|
_RV:^B
pT*HXK
8^s?pw
:al.:/
Ur}rG9
aJ|6Q
LKl/Af
4q@XbOsD"
vYvqD]xoC
pXDF*Q
SVlb<K
J6VeY,
hnY1RV
s'r07#
Fo8^dj
{;n</%A
.v?(@{
',f$0F1
Ne<*x
Z\/t|6
Ws6wG$9
Wsn)-OWS
?%o>}-6:
1G83gV
Nk-3H>
8?1k<T
5BJYMu
xp+Q8l
cS\2 "
QahfXU
U,~_cU}S<N8
x"^pUd
EZ8gS+
[QWb^
S:w|??
~fBU-a`
`{s878
"{bxxx
6GM=cS
~~:K]
Q6]Zu\
C%-l#D
4u?YI;
xH4E8VRjY
mU{4XD
eg~9@f
o!mruD
@(R9fi
]Vn$S
k&!fm\
rB[oEy
G>4w-+
xVc_dy(
$%o@tJ
x\&<pxQ,
HXnN}+4U0
oH^D}OG
W0LQyY\
'Uk8r}w
q\Q&_~DI3w
V[9TB9j
8V[v%G
Dg[!^nsp
Pg"VamA
]qN^8r
:3apV9{
wk/2+2Z
m0' F
'Wu}P5
v/ 5BU
~Zu]qW
^@nBjP*
57UN'W
!X[^sqc
6@_!uI
B'H)?
o[d~dT%
0v AGY
K$h(@|!
ZoEC}!
vL+yG'
0f"S@*
TLujE7
lG8hjz
2"ML}K
`lN^X,/h
}FSqmU
Rx)=f{|
\X|9aL
KW6,<0
aW7!b
!TR`{,+[
n|z 9
k?zomH
3sE&>g
]k/ows
TyE>Fu
7O-oa@
LoW{dI
@'cxk+
rBd*4Y
CiAC<Jx
Gu%}sc
|(!p z}
R&mN0,
6\Lc%nz?<
Z`/VK6
m1xVY{~
>yvdzy
qJlaG_
r-Cuz
]J}O;`
Q{hC}F
l+qNo^/{W
RNEWrv
nqT2N8l
<H\nRzK
= wt8
q]ercU
:|0Qf^U
J;"s:
v"9eV.
H9mnA0
M{jol{
=`r6\
"P=i!Z
NpiRW{K
-`"f`m
.l\afXeZ
y/S@z]
/{:x.|
(viMzew
rOkS}w
s<pDhl
nf90xN
_*]dkkF
LEn=Ye
,w!*|K
?^9Gl-
kl'-og<s
=GJUa_a
toUQ4o
3x)!X@
3hT&Mv0
>QmVnoTV
;[WLU/Y\w
YH+V1w
=mf<^a
5X5(2=
8b}pT{
(w6x3^
zG6<Q}n[q
8:=Z}n5
>#%/!2
jT;)iTNX
;P9|T&0
W}{LKk
8p\4FvgL
h."E-|
]w^z~HZ
!bL~B%R
N@)Pd/
gt(NVej
WVPn{
"PgZqek?
]c'YEw
*T:U|i
?[Q_"c
i[pv_^
HeKp8C
gmL39*r
2~Uy%8_
U[bU>n
J+|<N!
cI)e3H
0_n)99
{vR|J
(Ka,pC
67pN T
aT^B965
}jjz~c
u;ayNF
RgVyueM
o:6QTP@
gb5qcG`1(N
)l>;vZ
)?6{y7
)>o-).
/=oJ_YG
xDT5y?i/v
k|{e<mp
ko=;Pg
{4?G[v
!I&S~
<=zC#0474
+zO5`
*&a;Gmn
w^"$ua
\]oWuK
zwR.V&
~4gP-R
82{'O`;=abY
&A##yv
JAx/']
VE*]4w
3i6"yOm?=w
Kr^*E~
\k.5Xx
Tqs%[r
^w>V?'
}s(7NP
aZtn<,
$)^tE
S:om?>
K{~Df@
l,)I4?
?cy4)Iy
<~\\;}
7}Y+iv
(%|@*'
&Ec$e~
9sfbrr~
oy(9'Y
hry.<s
Z6.K H
MExVKX
aOug'Q
F5?oXY
u'Qh3J
~d+neae
-8%9BC:
aQ$~ :
{F'"]b7Z
2e*omI
vGe19X
KmIO:\
1,Bw_?
M)8HU@[
lk\ba<
K^H]v:
dAm16>
nx=MRP
toFfior
]1rs3Tv$1
{|9Ux0G1
9I3O]")
<#N3:h
6ko=yQ
TY/}-.
\:0OU:9y
E{?[W>
0#SCx
mU6]m*
!O';c3
5&?FfP
$..,JDz
1KaUv(
|Q~Klg
`zhBIyk
#&L8EX
mE~Fwb
g;I5(k
WMv\O2
OFAz1{
<mE81
tx$s>(
E,hg>K
B[rHDP
" SyAdn8
foO}8~~
,:=me2
z xx"^<
~t72?[kp
d8\1#x{
83\8AN
YRV[\e
DVHI-Qc
)0^iyl
;RFqh
!1QJh-
XI!}l,
L)umXk
+GkW9-
$W0PBV:
eb/=y'
at^>;@
?<_s$3
ROU?N"
y"M{wmg/
4GKtO[
UYFm!@
X,Vwt*
D^7~.D
G,RW9l:v
7d$QAs
smp;K|
jMwNg~5
glzQpaYUCr
%UyLb`
=_y]jp
_fxw_>
~qGv;U
MSCfOc)q6
zIKH,(j%
BqRy%>
>`J$OZ\}y
6xGP93
jp-cD4
,|yT]`
\{xOVgm
;(`vbu
yu>!dy
7j}sWN
]nC0;d
v:2Xx:
)[o~~)
,r6!P)
?E:k!
toW-]i)
e=z\{]Q
gRiIzg
pfg{B&
kp~'>{
eO/l>:
XP;|v
3"\f)9
,P<t=R
NS1*E&
9"L+V%
BH?g\_
bj"s Rn
Jv@^
"7`Sq:
RSpGd4y
f;w9%wX
c9%sXH:
Wi<|L4
(Koy&o Q
GL DJSO
"4b Y$
{3t]Gx~
Q,8NK4
78Oa`x\
(|q4c`
Zw3t|J
p3|"@K
)%jRz{*
D9Y(*<:
Yf<]6q
zcffazT
JV5U}?X
}hQI 8
c`r79,
lUz:Qu
LLQlqL8
aLwCweh
i/hKjL
^&Y0L
24pvE
j4')83
Vm:Sp
xR~yUE
&EIi0^
/2q@cwE
\OOnnD
V;ky7]
SI><.6
)ka6_k
,/uIm
Ogm2$~
m~jZc>
gdt}H6
w|p4]/-
Laajn)
Mb<^}G
U*P(u8/i
O[\F5F
?-Mf9]@
!?8A_}
$D}y|;
.}Ti3m
vb<6 V2
R=84
8<Fykg
;DB=>,
G9ni4@
f`$@~A
S/V2"h
joce7N
'2-@*U
c4YNV@
J3W~~f
f=ec//
JN[nTA?k
^0'hi1xB
ygMRg
da/6K&
>3/* U-
<'gX=n
s1&w{2#G
qrL0wN
GwfvFn
6p13Wq
$s<n||
mCSa+C
fcwxmTK
Q[0YvqAk
xrLg@8
_o!_~JH
j%iO?u
~%,v)9
m"G`jmWk
\\PtCe
BBsCi^7
w-[SYx
R#+Om-On'
R0!42Ex3p"6
JVrjl[
^!pl~0
V8OQZk
;+w\Ub
o):3{~
e]qL["
}8/b`;
kt&)Qf
U8~."F
v=aRk/E)
_~=iQS
Z0;UU1
mhZ^3Mp
qI1G|<
ttJK1F
\dJ\0|>`i
%{0iuD
!'Ee?
6V>]5Z
:N%RZ.}
Fd8o|-
E}/bMCS
OoCt)]
P6K1hP
6_~x<m]n
X8\<2l
q+xt}e
:b|?Wm{
b%G96j\
uZo$Du
G/t[(?c
==+;^4dj
x.UP1D
NH>\Qx
,k}reS
Su<NLr
&P"e-B
uAgm&#
ic,4VE
1d!+j@@
CJve9eON0E
V>qL?
H]YHFY
j|t"F
Ml,6*?^
]6i'KT
($,e']
~M'=c:
V4n=!1y
U-`2ie
,<a{8.
We}{~l
lN@CBY
[1)ZoE$
*Sj\
x/5_)\*
Xm~~,AQ,
$akEkL
!cTOd: 2mPS
o^=XD<
g:iC~W
%/jS<_\
L<F.<2U
Mz7v-.
6z1@/W
@p"#E-
!Lel9ftZ
&m:0Q2
e54_4GTP
9?7%[g
Tzz4{v7F/
5L8-Dmg
D*2@P`
g<F%VYeE
E<].!,R[
<V,83<8
w-j?Sx0
4u|sv:
AL9-k/
~&*l'^o
V:z|xx/
+03#sW-
|E*_w_a09
+a2!.a
FMX)_=,DuQQA
1iL 9'
U2s\^[
u97LRj
+7s"d|
|F-\[v
>K{fo[
85<texs
GUe^Q
T+!juCxw
+[Xvaa
WO0unL
lus>qY
5^}RaY
Y~U\jZ
~"rCXuE
:bp6ay|
Z OY3sn|H
.^^X|t0
_-X_]$i
bd9/!rE*X
>$d3.>
_tY;dM
,zY=ri
[=ps'kIX
aQ/Ww3!
hN(@} U,<
WO(R3>T
Antivirus Signature
Bkav W32.NeshtaB.PE
Lionic Virus.Win32.Neshta.tn9H
Elastic malicious (high confidence)
MicroWorld-eScan Win32.Neshta.A
FireEye Generic.mg.febb47ebfc843b81
CAT-QuickHeal W32.Neshta.C8
ALYac Win32.Neshta.A
Malwarebytes Virus.Neshta
VIPRE Virus.Win32.Neshta.a (v)
K7AntiVirus Virus ( 00556e571 )
BitDefender Win32.Neshta.A
K7GW Virus ( 00556e571 )
Cybereason malicious.bfc843
Baidu Win32.Virus.Neshta.a
Cyren W32/Neshta.OBIX-2981
Symantec W32.Neshuta
ESET-NOD32 Win32/Neshta.A
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Neshuta-1
Alibaba Virus:Win32/Neshta.3bb
NANO-Antivirus Trojan.Win32.Winlock.fmobyw
ViRobot Win32.Neshta.Gen.A
Tencent Virus.Win32.Neshta.a
Ad-Aware Win32.Neshta.A
Comodo Win32.Neshta.A@3ypg
F-Secure Clean
DrWeb Win32.HLLP.Neshta
Zillya Virus.Neshta.Win32.1
TrendMicro PE_NESHTA.A
CMC Clean
Sophos ML/PE-A + W32/Neshta-D
Ikarus Virus.Win32.Neshta
Jiangmin Clean
eGambit Clean
Avira W32/Neshta.A
MAX malware (ai score=88)
Antiy-AVL Trojan/Generic.ASVirus.20D
Kingsoft Clean
Gridinsoft Virus.Win32.Neshta.ka!s8
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Virus.Win32.Neshta.a
GData Win32.Virus.Neshta.D
Cynet Malicious (score: 100)
AhnLab-V3 Win32/Neshta
Acronis suspicious
BitDefenderTheta AI:FileInfector.D5C3B0640E
TACHYON Virus/W32.Neshta
VBA32 Virus.Win32.Neshta.a
Panda W32/Neshta.A
Zoner Virus.Win32.19514
TrendMicro-HouseCall PE_NESHTA.A
Rising Win32.Neshta.a (CLASSIC)
Yandex Trojan.GenAsa!Mo0tdcmmg3o
SentinelOne Static AI - Malicious PE
MaxSecure Virus.Infector.Gen9
Fortinet W32/Generic.AC.171!tr
Webroot Clean
AVG Win32:Apanas [Trj]
Avast Win32:Apanas [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Virus.Win32.Neshta.B
No IRMA results available.