Static | ZeroBOX

PE Compile Time

2016-05-05 15:59:40

PE Imphash

7ca35f2e334ab384d940a0b3696ed721

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004392 0x00004400 6.2295502935
.rdata 0x00006000 0x00001e8c 0x00002000 4.60599593585
.data 0x00008000 0x000007c4 0x00000600 4.3457404588
.rsrc 0x00009000 0x0000a000 0x00009400 4.52393952644

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000099b8 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US AmigaOS bitmap font
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x0000a560 0x000002c8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00010ff8 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_MENU 0x00011460 0x00000012 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000119f8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00011e7c 0x0000008c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00011f08 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00011fc8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x00011fdc 0x00000300 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MFC42.DLL:
0x406078 None
0x40607c None
0x406080 None
0x406084 None
0x406088 None
0x40608c None
0x406090 None
0x406094 None
0x406098 None
0x40609c None
0x4060a0 None
0x4060a4 None
0x4060a8 None
0x4060ac None
0x4060b0 None
0x4060b4 None
0x4060b8 None
0x4060bc None
0x4060c0 None
0x4060c4 None
0x4060c8 None
0x4060cc None
0x4060d0 None
0x4060d4 None
0x4060d8 None
0x4060dc None
0x4060e0 None
0x4060e4 None
0x4060e8 None
0x4060ec None
0x4060f0 None
0x4060f4 None
0x4060f8 None
0x4060fc None
0x406100 None
0x406104 None
0x406108 None
0x40610c None
0x406110 None
0x406114 None
0x406118 None
0x40611c None
0x406120 None
0x406124 None
0x406128 None
0x40612c None
0x406130 None
0x406134 None
0x406138 None
0x40613c None
0x406140 None
0x406144 None
0x406148 None
0x40614c None
0x406150 None
0x406154 None
0x406158 None
0x40615c None
0x406160 None
0x406164 None
0x406168 None
0x40616c None
0x406170 None
0x406174 None
0x406178 None
0x40617c None
0x406180 None
0x406184 None
0x406188 None
0x40618c None
0x406190 None
0x406194 None
0x406198 None
0x40619c None
0x4061a0 None
0x4061a4 None
0x4061a8 None
0x4061ac None
0x4061b0 None
0x4061b4 None
0x4061b8 None
0x4061bc None
0x4061c0 None
0x4061c4 None
0x4061c8 None
0x4061cc None
0x4061d0 None
0x4061d4 None
0x4061d8 None
0x4061dc None
0x4061e0 None
0x4061e4 None
0x4061e8 None
0x4061ec None
0x4061f0 None
0x4061f4 None
0x4061f8 None
0x4061fc None
0x406200 None
0x406204 None
0x406208 None
0x40620c None
0x406210 None
0x406214 None
0x406218 None
0x40621c None
0x406220 None
0x406224 None
0x406228 None
0x40622c None
0x406230 None
0x406234 None
0x406238 None
0x40623c None
0x406240 None
0x406244 None
0x406248 None
0x40624c None
0x406250 None
0x406254 None
0x406258 None
0x40625c None
0x406260 None
0x406264 None
0x406268 None
0x40626c None
0x406270 None
0x406274 None
0x406278 None
0x40627c None
0x406280 None
0x406284 None
0x406288 None
0x40628c None
0x406290 None
0x406294 None
Library MSVCRT.dll:
0x40629c _controlfp
0x4062a0 _except_handler3
0x4062a4 __set_app_type
0x4062a8 __p__fmode
0x4062ac __p__commode
0x4062b0 _adjust_fdiv
0x4062b4 __setusermatherr
0x4062b8 _initterm
0x4062bc __CxxFrameHandler
0x4062c0 malloc
0x4062c4 _CxxThrowException
0x4062c8 free
0x4062cc realloc
0x4062d0 __dllonexit
0x4062d4 _onexit
0x4062dc _exit
0x4062e0 _XcptFilter
0x4062e4 exit
0x4062e8 _acmdln
0x4062ec __getmainargs
0x4062f0 _stricmp
Library KERNEL32.dll:
0x406030 FreeLibrary
0x406034 HeapFree
0x406038 GetStartupInfoA
0x40603c IsBadReadPtr
0x406040 VirtualFree
0x406044 VirtualProtect
0x406048 VirtualAlloc
0x40604c CloseHandle
0x406050 CreateFileA
0x406054 GetProcAddress
0x406058 Sleep
0x40605c LoadLibraryA
0x406060 ReadFile
0x406064 GetFileSize
0x406068 GetModuleHandleA
0x40606c GetProcessHeap
0x406070 HeapAlloc
Library USER32.dll:
0x406308 DrawIconEx
0x40630c IsIconic
0x406310 GetWindowRect
0x406314 IsZoomed
0x406318 PtInRect
0x40631c DrawIcon
0x406320 OffsetRect
0x406324 AppendMenuA
0x406328 LoadIconA
0x40632c InvalidateRect
0x406330 CopyRect
0x406334 GetSystemMetrics
0x406338 GetParent
0x40633c IsWindow
0x406340 GetWindowDC
0x406344 GetSystemMenu
0x406348 ReleaseDC
0x40634c SendMessageA
0x406350 EnableWindow
0x406354 GetClientRect
0x406358 FillRect
0x40635c LoadBitmapA
Library GDI32.dll:
0x406010 BitBlt
0x406014 GetTextColor
0x406018 CreateFontA
0x40601c GetObjectA
0x406024 CreateSolidBrush
0x406028 CreateCompatibleDC
Library SHELL32.dll:
0x4062f8 SHBrowseForFolderA
0x406300 SHGetMalloc
Library COMCTL32.dll:
0x406004 ImageList_Draw
Library imagehlp.dll:
Library WININET.dll:
0x406364 InternetCloseHandle
0x406368 InternetReadFile
0x40636c InternetOpenUrlA

!This program cannot be run in DOS mode.
D04'Km4
D04gX>4
D14=D04
D04#B64
D04Rich
`.rdata
@.data
u,_^][
u,_^][
u,_^][
T$`RPQ
D$ DPV
L$$_^]
D$0RPQ
T$@QRU
D$ <k@
L$d_^][d
MFC42.DLL
__CxxFrameHandler
malloc
_CxxThrowException
realloc
MSVCRT.dll
__dllonexit
_onexit
??1type_info@@UAE@XZ
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
CloseHandle
CreateFileA
GetProcAddress
LoadLibraryA
ReadFile
GetFileSize
HeapAlloc
GetProcessHeap
VirtualAlloc
VirtualProtect
VirtualFree
IsBadReadPtr
HeapFree
FreeLibrary
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
FillRect
GetClientRect
EnableWindow
SendMessageA
GetParent
GetSystemMetrics
CopyRect
InvalidateRect
LoadIconA
AppendMenuA
GetSystemMenu
DrawIcon
IsIconic
ReleaseDC
GetWindowDC
IsWindow
OffsetRect
DrawIconEx
LoadBitmapA
GetWindowRect
IsZoomed
PtInRect
USER32.dll
CreateSolidBrush
GetTextExtentPoint32A
GetObjectA
CreateFontA
GetTextColor
BitBlt
CreateCompatibleDC
GDI32.dll
SHGetPathFromIDListA
SHBrowseForFolderA
SHGetMalloc
SHELL32.dll
ImageList_Draw
ImageList_GetImageInfo
ImageList_ReplaceIcon
COMCTL32.dll
MakeSureDirectoryPathExists
imagehlp.dll
InternetCloseHandle
InternetReadFile
InternetOpenUrlA
WININET.dll
_stricmp
Select a directory...
4jNnIiz7AYwRrV0iD5UUadEvQZUBhnWPv6/zEf6tEToOJMYNFoB5Vt6K
xe5ey0Yzvls0ggAPPRajrFET1PJYkgEb6mgG03wYhzdpPn+2CaiRy5Nm8dPmmAUMnhUNUb85FzUOpYIduP+3BSAxcD8D62EP2cY9BdX9gNbTWQkKAMCMG55pZJyRZL7GKUvUtMhh8eWWz6aLgXmC1qBC3vtBuxbr9MXE0lQyKdmvg6oRqIiiH7qM8bY4jg8JKeLuXriTU/qH3Cyf9tItZjO2BNPJZdbzsUATqBzX4fQYUotnWepDTUPilZ+RpitorQQBtCIXDU3vgKIxbq/9PJR4M78qDFfBXA6bfHpBWbAjXIDuh3AZ9jMVk96ZLeg4KApoiOX7GsSV4ylWzbD76Y1c0OCEEODjleLNuF+irR2hHuSCIPCI787DODn0APHbwgIccVbFs8eG9A7rayNw+ZRGuraUoLSOM+7sRpPbEfhhcwoOtluKS6Vl7j9yH0TEsJk25yVQpf8fNjr8M4IrQvfCMFDMexGexink6tfk8+ahaPwQpi6APiq9k4XK+ld7
EMail:Song_0962@sina.com
.?AVtype_info@@
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
0-WBome
wwwwww|
wwwwwww
wwwwww|
wwwwwww
wwwwwww
wwwwwww
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwp
wwwwwww
wwwwwww
wwwwwww
wwwwwww
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwp
wwwwww|
wwwwww|
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwp
wwwwww|
wwwwwww
wwwwww|
wwwwwww
wwwwwww
wwwwwww
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwp
wwwwwwwwwwwwwwp
wwwwwwwwwwwwwwp
wwwwwwwwwwwwwwp
wwwwwwwwwwwwwwp
wwwwwwwwwwwwwwp
cccnnccccnncccccccccnncccncccccccccccnncncccccccccccccncncccccccccccccnnnccccccccccccccnnncccccccccccnn
nncccccccccnc
cnccccccnnnncccccnnnccccnnn
nnccccnnn
nnccccnnnncccccnnncccccccncccccncccccccccnncccnncccccccccccnnncccccccccccccccccccccc
-9999*
)9999999999)
(4991(
HrCg@b
_%fNS
HrCg@b
W>W{|+R
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
150930000000Z
180928235959Z0k1
Beijing1
Beijing1
Sogou.com1
Desktop1
Sogou.com0
'f tJ"
7kT ;J
http://sv.symcb.com/sv.crl0f
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
@Up 9
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
160414100439Z0#
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
070615000000Z
120614235959Z0\1
VeriSign, Inc.1402
+VeriSign Time Stamping Services Signer - G20
6^bMRQ4q
JcEG.k
http://ocsp.verisign.com0
"http://crl.verisign.com/tss-ca.crl0
TSA1-20
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
031204000000Z
131203235959Z0S1
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
http://ocsp.verisign.com0
0http://crl.verisign.com/ThawteTimestampingCA.crl0
TSA2048-1-530
?7!Op1
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority0
040716000000Z
140715235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
https://www.verisign.com/rpa01
http://crl.verisign.com/pca3.crl0
Class3CA2048-1-430
==d6|h
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
070514000000Z
100712235959Z0
Beijing100.
'Beijing Jiangmin New Sci.&Tec. Co. Ltd.1>0<
5Digital ID Class 3 - Microsoft Software Validation v2100.
'Beijing Jiangmin New Sci.&Tec. Co. Ltd.0
/http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
https://www.verisign.com/rpa0
http://ocsp.verisign.com0?
3http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0
==d6|h
Z!Etb
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA
,^jGR=
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA
090114031250Z0#
i.r2{kFU
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
070615000000Z
120614235959Z0\1
VeriSign, Inc.1402
+VeriSign Time Stamping Services Signer - G20
6^bMRQ4q
JcEG.k
http://ocsp.verisign.com0
"http://crl.verisign.com/tss-ca.crl0
TSA1-20
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
031204000000Z
131203235959Z0S1
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
http://ocsp.verisign.com0
0http://crl.verisign.com/ThawteTimestampingCA.crl0
TSA2048-1-530
?7!Op1
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority0
040716000000Z
140715235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
https://www.verisign.com/rpa01
http://crl.verisign.com/pca3.crl0
Class3CA2048-1-430
==d6|h
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
080703000000Z
090703235959Z0
GUANGDONG1
ZHUHAI1*0(
!Zhuhai Kingsoft Software Co.,Ltd1>0<
5Digital ID Class 3 - Microsoft Software Validation v21
Kingsoft Research1*0(
!Zhuhai Kingsoft Software Co.,Ltd0
_,5Ic>
/http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
https://www.verisign.com/rpa0
http://ocsp.verisign.com0?
3http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0
==d6|h
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA
bzxJD
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA
090210134607Z0#
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
070615000000Z
120614235959Z0\1
VeriSign, Inc.1402
+VeriSign Time Stamping Services Signer - G20
6^bMRQ4q
JcEG.k
http://ocsp.verisign.com0
"http://crl.verisign.com/tss-ca.crl0
TSA1-20
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
031204000000Z
131203235959Z0S1
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA0
http://ocsp.verisign.com0
0http://crl.verisign.com/ThawteTimestampingCA.crl0
TSA2048-1-530
?7!Op1
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority0
040716000000Z
140715235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
https://www.verisign.com/rpa01
http://crl.verisign.com/pca3.crl0
Class3CA2048-1-430
==d6|h
VeriSign, Inc.1705
.Class 3 Public Primary Certification Authority
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA0
070509000000Z
100608235959Z0
Slovakia1
Bratislava1
ESET, spol. s r.o.1>0<
5Digital ID Class 3 - Microsoft Software Validation v21
ESET, spol. s r.o.0
/http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
https://www.verisign.com/rpa0
http://ocsp.verisign.com0?
3http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0
==d6|h
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)041.0,
%VeriSign Class 3 Code Signing 2004 CA
EmEo!Oj
VeriSign, Inc.1+0)
"VeriSign Time Stamping Services CA
081024185022Z0#
;kfJ?<pG9
uO/y7Q
jjjjjjj
TabTest
TabTest 1.0
(C) 2010
V1.0----
SysTabControl32
System
System
System
Email: z.ch163@163.com
603854038
1998-2012
System
SysListView32
MS Shell Dlg
MS Shell Dlg
SysTreeView32
MS Shell Dlg
SysListView32
QQMaster
%d%%...
%d%%...
VS_VERSION_INFO
StringFileInfo
040904e4
FileVersion
11.6.17627.218
CompanyName
Tencent
LegalCopyright
Copyright
2016 Tencent. All Rights Reserved.
ProductName
ProductVersion
11,6,17627,218
FileDescription
OriginalFilename
QQPCMgr.exe
InternalName
QQ PCMgr Main Program
VarFileInfo
Translation
<<<Obsolete>>
$Jiangmin AntiViru
<<<Obsolete>>
4Kingsoft Internet Securit
<<<Obsolete>>
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46752096
FireEye Generic.mg.efc0f46f3fa314f2
CAT-QuickHeal Trojan.MauvaiseRI.S5244871
Qihoo-360 Win32/Backdoor.Farfli.HwcB3JYA
McAfee Trojan-FJYJ!EFC0F46F3FA3
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 004eeb581 )
BitDefender Trojan.GenericKD.46752096
K7GW Trojan-Downloader ( 004eeb581 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Win32.Trojan-Downloader.Agent.bh
Cyren W32/Agent.ZZJG-1868
Symantec SMG.Heur!gen
ESET-NOD32 Win32/TrojanDownloader.Agent.CJI
APEX Malicious
Paloalto generic.ml
ClamAV Win.Downloader.Zegost-6484584-1
Kaspersky Backdoor.Win32.Farfli.akdq
Alibaba Backdoor:Win32/Zlob.180910
NANO-Antivirus Trojan.Win32.BesysAd.eljjnl
ViRobot Clean
Tencent Malware.Win32.Gencirc.10b3bd37
Ad-Aware Trojan.GenericKD.46752096
Sophos Mal/Generic-S
Comodo TrojWare.Win32.TrojanDownloader.Redosdru.FG@6j5x7c
F-Secure Clean
DrWeb Trojan.BesysAd.18
Zillya Backdoor.Farfli.Win32.5448
TrendMicro BKDR_ZEGOST.SM17
McAfee-GW-Edition Trojan-FJYJ!EFC0F46F3FA3
CMC Clean
Emsisoft Trojan.GenericKD.46752096 (B)
Ikarus Trojan.Win32.Redosdru
GData Win32.Trojan.PSE.1NT5ZA2
Jiangmin Backdoor/Hupigon.ayjb
Webroot Clean
Avira TR/Crypt.XPACK.Gen3
MAX malware (ai score=83)
Antiy-AVL Trojan/Generic.ASCommon.1F4
Kingsoft Clean
Gridinsoft PUP.Win32.Tencent.zv!s1
Arcabit Trojan.Generic.D2C96160
SUPERAntiSpyware Clean
ZoneAlarm Backdoor.Win32.Farfli.akdq
Microsoft TrojanDownloader:Win32/Farfli.F!bit
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Farfli.R187699
Acronis Clean
BitDefenderTheta Clean
TACHYON Backdoor/W32.Farfli.88420
VBA32 Backdoor.Farfli
Malwarebytes Backdoor.Farfli
Panda Trj/Genetic.gen
Zoner Trojan.Win32.80374
TrendMicro-HouseCall BKDR_ZEGOST.SM17
Rising Trojan.Generic@ML.100 (RDML:B/qpGP2/p3Blnakb5J5isA)
Yandex Trojan.GenAsa!rUmyptG9Mc4
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Agent.CGT!tr
AVG Win32:Malware-gen
Cybereason malicious.f3fa31
Avast Win32:Malware-gen
MaxSecure Clean
No IRMA results available.