Static | ZeroBOX

PE Compile Time

2021-08-19 23:39:22

PDB Path

C:\ldesi\iljubv\lpkq\54bc27a3d09443b6a1fd403c62ec2562\gyyqvx\swhltjbc\Release\swhltjbc.pdb

PE Imphash

4f489b335db6d5ec89d1f80710469941

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00041a49 0x00041c00 6.60583296578
.rdata 0x00043000 0x000091ca 0x00009200 4.96405677983
.data 0x0004d000 0x0000254c 0x00001400 3.73516169443
.rsrc 0x00050000 0x00000708 0x00000800 2.8130485611

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000500a0 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00050588 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x443030 CreateThread
0x443034 GetSystemDirectoryW
0x443038 VirtualAlloc
0x44303c FreeLibrary
0x443040 GetModuleFileNameW
0x443044 GetModuleHandleA
0x443048 GetProcAddress
0x44304c LoadLibraryExW
0x443050 LoadLibraryA
0x443054 lstrcpynW
0x443058 ExitProcess
0x44305c lstrlenW
0x443060 CompareStringW
0x443064 MultiByteToWideChar
0x443068 EnumTimeFormatsA
0x44306c GetThreadLocale
0x443074 WriteConsoleW
0x443078 ReadConsoleW
0x44307c CloseHandle
0x443080 HeapReAlloc
0x443084 CreateEventW
0x443088 WaitForSingleObject
0x44308c SetEvent
0x443090 GetProcessHeap
0x443094 HeapFree
0x443098 HeapAlloc
0x44309c GetLastError
0x4430a0 WriteFile
0x4430a4 ReadFile
0x4430a8 CreateFileW
0x4430ac lstrcpyW
0x4430b0 GetCommandLineW
0x4430b4 HeapSize
0x4430b8 SetFilePointerEx
0x4430bc GetFileSizeEx
0x4430c0 GetConsoleMode
0x4430c8 GetCurrentProcessId
0x4430cc GetCurrentThreadId
0x4430d4 InitializeSListHead
0x4430d8 IsDebuggerPresent
0x4430e4 GetStartupInfoW
0x4430ec GetModuleHandleW
0x4430f0 GetCurrentProcess
0x4430f4 TerminateProcess
0x443100 RtlUnwind
0x443104 SetLastError
0x443118 TlsAlloc
0x44311c TlsGetValue
0x443120 TlsSetValue
0x443124 TlsFree
0x443128 EncodePointer
0x44312c RaiseException
0x443130 GetStdHandle
0x443134 GetModuleHandleExW
0x443138 GetCurrentThread
0x44313c GetDateFormatW
0x443140 GetTimeFormatW
0x443144 LCMapStringW
0x443148 GetLocaleInfoW
0x44314c IsValidLocale
0x443150 GetUserDefaultLCID
0x443154 EnumSystemLocalesW
0x443158 GetFileType
0x44315c OutputDebugStringW
0x443160 FindClose
0x443164 FindFirstFileExW
0x443168 FindNextFileW
0x44316c IsValidCodePage
0x443170 GetACP
0x443174 GetOEMCP
0x443178 GetCPInfo
0x44317c GetCommandLineA
0x443180 WideCharToMultiByte
0x443190 SetStdHandle
0x443194 GetStringTypeW
0x44319c FlushFileBuffers
0x4431a0 GetConsoleOutputCP
0x4431a4 DecodePointer
Library USER32.dll:
0x4431ac MessageBoxA
0x4431b0 LoadStringW
Library ADVAPI32.dll:
0x443004 SetServiceStatus
0x44300c OpenServiceW
0x443010 OpenSCManagerW
0x443014 DeleteService
0x443018 CreateServiceW
0x44301c CloseServiceHandle
0x443020 RegQueryValueExW
0x443024 RegOpenKeyW
0x443028 RegCloseKey
Library ole32.dll:
0x4431b8 CoInitializeEx
0x4431bc CLSIDFromString
0x4431c0 CoUninitialize

!This program cannot be run in DOS mode.
Richd3]
`.rdata
@.data
URPQQh`
tJ<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
t h8>D
t h@>D
<0|O<9
<A|2<P
9t2j(
t4<A|)<P
<0|*<9
<0|]<8
;t$,v-
UQPXY]Y[
QQSVWd
tH9] uC
u PWQR
<xt<Xt
F4_^[]
F4_^[]
F4_^[]
F4_^[]
F4_^[]
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
Tt)jhZf;
Jjl^f;
V2jx_f;
V2jx_f;
V2jx_f;
V2jx_f;
V2jx_f;
V2jx_f;
F2jgYf;
jg[BjG_
F2jgYf;
F2jgYf;
F2jgYf;
jg[BjG_
F2jgYf;
F2jgYf;
x!j$Xf9
x!j$Xf9
j"_f9y
SWt@jU
_tqPVj@
SVh@_D
u,PQRS
Wj0XPV
SPjdVQ
tlj*Yf
zSSSSj
f9:t!V
QQSVj8j@
ARPRQh
NX9^`t1
;V\uYW
tjh(pD
u2Vj@h
9C`u99C\t4
u29K\t-
7;1u"3
CY<u
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
D8(Ht'
tHSVWP
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
template-parameter-
generic-type-
`anonymous namespace'
`non-type-template-parameter
`template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char16_t
char32_t
wchar_t
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
volatile
const
cli::array<
cli::pin_ptr<
{flat}
Unknown exception
bad exception
(null)
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetActiveWindow
GetDateFormatEx
GetEnabledXStateFeatures
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
AppPolicyGetShowDeveloperDiagnostic
AppPolicyGetWindowingModel
SetThreadStackGuarantee
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
C:\ldesi\iljubv\lpkq\54bc27a3d09443b6a1fd403c62ec2562\gyyqvx\swhltjbc\Release\swhltjbc.pdb
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
GetCommandLineW
CreateFileW
ReadFile
WriteFile
GetLastError
HeapAlloc
HeapFree
GetProcessHeap
SetEvent
WaitForSingleObject
CreateEventW
ExitProcess
CreateThread
GetSystemDirectoryW
VirtualAlloc
FreeLibrary
GetModuleFileNameW
GetModuleHandleA
GetProcAddress
LoadLibraryExW
LoadLibraryA
lstrcpynW
lstrcpyW
lstrlenW
CompareStringW
MultiByteToWideChar
EnumTimeFormatsA
GetThreadLocale
GetUserDefaultLangID
KERNEL32.dll
LoadStringW
MessageBoxA
USER32.dll
RegCloseKey
RegOpenKeyW
RegQueryValueExW
CloseServiceHandle
CreateServiceW
DeleteService
OpenSCManagerW
OpenServiceW
RegisterServiceCtrlHandlerA
SetServiceStatus
StartServiceCtrlDispatcherA
ADVAPI32.dll
CoUninitialize
CoInitializeEx
CLSIDFromString
ole32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
InterlockedPushEntrySList
InterlockedFlushSList
RtlUnwind
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
RaiseException
GetStdHandle
GetModuleHandleExW
GetCurrentThread
GetDateFormatW
GetTimeFormatW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
OutputDebugStringW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetStringTypeW
SetConsoleCtrlHandler
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
HeapSize
HeapReAlloc
CloseHandle
ReadConsoleW
WriteConsoleW
DecodePointer
Killing service
Failed to set service status
Unhandled service control code: %d
Failed to create thread
MSIServer
Failed to register service ctrl handler
Failed to create event
MSIServer
Starting MSIServer service
Failed to start MSIServer service
msi.dll
GetModuleFileName failed: %d
MsiGetFileVersion failed with %d
Out of memory!
properties -> %s
Unable to load dll %s
Dll %s does not implement function %s
DllRegisterServer
Failed to register dll %s
Successfully registered dll %s
DllUnregisterServer
Failed to unregister dll %s
Successfully unregistered dll %s
Failed to open the service control manager.
Failed to create MSI service
Failed to open service control manager
Failed to delete MSI service
Failed to open MSI service
Invalid parameter %s
Failed to create custom action server pipe: %u
Failed to write to custom action server pipe: %u
Failed to read from custom action server pipe: %u
VirtualProtect
kernel32.dll
Embedding
argvW[%d] = %s
regserver
unregserver
unregister
package
argvW[%d] = %s
argvW[%d] = %s
Administrative installs are not currently supported
Unknown option "%c" in Repair mode
argvW[%d] = %s
uninstall
PackageName = %s
Unknown option "%c" in Advertise mode
argvW[%d] = %s
argvW[%d] = %s
argvW[%d] = %s
argvW[%d] = %s
argvW[%d] = %s
argvW[%d] = %s
Logging in %s (0x%08x, %u) failed
update
argvW[%d] = %s
Unhandled modifier: !
Unknown option "%s" for UI level
passive
argvW[%d] = %s
argvW[%d] = %s
Unknown parameter /m
Unknown parameter /D
Product code treatment not implemented yet
Unknown function, ignoring
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
p7,-kV
u^Ho }8
S}c14K
%aUl1m)
m|3ke}
!L4n5;
B6rG58
!L4n5;
;F;W(779
ggyqF:
VI"A\&
+D@d)WA
ag,A/ID%
ag,A/ID%
ag,A/ID%
JGvXoC%
:dBNg,
4dBNg,YE=
A8nCiX
d\h=W~
6P;p4{>X
+#@nz!
A]ID(d
@GJV$y}
(:z}+V
]fLzb%
a-lA^gE
i}ty&X1
0l3T0d
\*svk,
y$VZMKW
p*)gp
'$|qr!y
F.GL"G\
B_gul1
=C.R~:
yY:d-#
,7&H r
Y7pJi+F
4F`!aQ
H]}Rzb
5?]'$2
G7|F6K
Lt$}TZ
]hF:M-
.<%VHQ(
Ia=E!}
Mz;f0!
}3,}&L
&TWelC
qU|V~m\
2eF@p\
@Ll25"
*fz$V&
g+4aZ]
(2qS1b
5<-VH =
rNA886j
^%}7CR
a!VMQ|d
MJ9Y9o
`S~(SZc
k[iY^~
x0HOW<
^N!~po9
X%l8^n
s9Qw*!c
u7Nj=
_zlz''
R-Ly8i
@QtSEh kV
vlN'=x
~I3D7&
$<e,I3
g,J;8C
cJ>BN4
O]GZ}}8R,
QmlNfqx
qm](S^-
$Ki,I-h
1yzbG:
]Ds*`j
YiVj!
Jgjy}`
mD?MK5>A
Y:Mr1W}
:q71B2
!/N&O)nD
#'+p\l
-$/In"
9)oWp
?M'I|@U
XK6^'DC
UT1O#^`
0?;q&4
\iPJ6@
b^Y9(uQ+
^nmU|%
Y9(u&*y
/C^={)
D2QT&N*w
eUI~.K
Fu(kN>
Yp{2 :
`_xdJm
95>@py
+Bx3S\i\
M\yrNi
YrTW7
66kYZ|
_2lNj&x
cPh ri
3U-$zjO
5SdVEr
j:R|F6K
U=!5]pQ8
t1KxqK$A
;J`/=o
YY":&Pd
-pLo<N!
=#~VZ!Rk@8
~q] '+
V**@w>A
&>lBe/Y]D
2W#~fz
mO16E:>
_gul1_
A5+W86
_gul1_
I/=W%}
Os!41mn
Cqk7SV
:rMEy^
5"yIOw
c|9^fx|
-_)=67
$oi,IE4
.w;fd<N
Ix-'9E
(1yZT
.Qx8RP
0fqiy=
%y3H+;
M[%]Q4
XpQ%I#8
ag,A/ID%
[D~87|^
ftr`~:g
KaD,x/
,A/ID~
X_Y85"
PXXYX5
1X_YX5T
Gu$LYb
,A/ID~
aao,(/
XfY85c
,q/*D%
aaT,'/lD
aF,A/ID
ag,'/:D>
aao,&/
aao,8/lD)
a@,&/ED%
X.Y95@
:d<)4_
ag,u/:D
aao,&/*D~
?a_,A/ID
^5E-l2TH&
&IUTv4
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
6):@Pgq
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
ag,A/ID%
Cf)S|V
WiclH.
XrBqFx
Rr)k)%
UueM[q
z]+Yik
p98'3c"
[c@UJ*
3#NJ9f
z0J*.msT
O>huu$$b
CeXZP8.1
G Qoj4
<8@jS
[OYuPMDcA8^
(noKYg_
zT)W6%
:a/Lb6gX
bmmy>B.
uk8PXB
RyCod+
k{}K\'E
Di.56e
02msWUT
Jv{S/u^f
(CdZ<N
$oh5'M
@_E|x`
bTt7Ye
|OA66"
CZF5"A
I!(Vlh
qg?Vt.
+(&~^
& tU35
sBUWnp
E\yr[6-2}^
r+<{MJ
[9d0Bo
F2\LyCAq
b0Pz?
t22<abmY
,N*"m|?
`ezLln}
M]M0x\
3DL{iQ
`}!T(`
MS#O/
Mk(:IG K=[6
7Kbaba
7s %yS(
.8@[!7
5Dve'N
i1kkb\Chy
[fq-2n
miv*f<
;]<pct
[1;SrG
QkNv9'
KWG,w%i
QRL0xs
+e=9\y];
RVK,?`
c7zAfDPt
m+K^Y6
-%qUPXy=
YgE,Pt
|+S~sbHSN
U:d+rX
^92hhy
fgQ=<E
E0fj=E
s%=yI%~
zj>fiH fw
|e& LJ6IX
K\ZwLI
\R;@w0
r2vXu"
tUEX0,7
gmZl>7Y7dX
vQ"Z0U
NX'8Ng
ddtdAG+
1(F)EG
{s|J\g
)gsPY~mW
9j<S(M
t=PG(S
Oe]SC/
zR6Y.q
<,~{C,
i{{n\$^
Y7bv~!xQ{Z
VU`{x^0V
N0l\cb
:+DrCwD
pp0cYt3Kj"
x&)';:
+3&`c#^
p'=#A,
]B"^dJ
G<-8S^
8>Dw.
Mta0zi
VY&1CqA(
6TRB5u
vr7vop
8r-pw
b5"&pq
$ZtCxJ
I +5vJ
z@Hs*}u
b(L`Qo
,T0@|]
?}s'Be
E3,Q4.&J
h#,Bs}
>/3bk
AaD(wE
jSiHty
"-HWm(
3LN(]n
| +Hoi6/j
!-8CcT
d,E>D
#!qHVS
MyH;7=Z
Mz-%!G
i8Al#:"+
JEx6W2
L+(_{D
P8[~i^6
%Yy GC
5=uz07
ARdn,i
IdbQ<!
9CNrVm
\]-)vw
)GD)|KF
F|.sy0
(t;r5T"q
$M?Piwew
Wb0RnF
$U:|Pw
[;DnWJ
gP?z7+*
j1< /z
jIpYx
lkeTu
GXgCvt
EZE.'
"E^|Iw#
mHA<%*
k3 'Q
t4$b"{
rR0Fc#p([NK
J{U!3w
BQt;u@
uWgc8BS
3T1:{C
5^4L?'
mudI|u
)o@|W+t
i{P#g{
fi(%7q
AjS#M3
jeneS[n
^N`!&#
1rC?&&s
FU]p!\
dY<l%F
nUmB=-
vx7Ic\
?Dv8g76
\4OhFV
oHf)yk
B*IN#z
q/*}b6
o]PN1!j
.PUHdS,w
Gh1"c{
r~&*,c
<}>)~J
0 {0NB\[
Ukr^?|
&#WZS=
9h0zEn
C-(cP&ppqvn!
nf5+.G
Xw+*1,
8&T[AO
<]3fQyV
OA_&w"4
7^Zd09\
C/r>3+
Djjjjj
Dapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
(null)
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
mscoree.dll
CLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
((((( H
((((( H
(
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Dapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
Dja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ServicesActive
\msiexec /V
MSIServer
MSIServer
ServicesActive
MSIServer
\\.\pipe\msica_%x_%d
Software\Microsoft\Windows\CurrentVersion\Installer\RunOnceEntries
ACTION=ADMIN
REMOVE=ALL
eREBOOTPROMPT="S"
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
DrWeb BackDoor.SpyBotNET.25
MicroWorld-eScan Gen:Variant.Fragtor.9833
FireEye Generic.mg.2b5346dcfa4f86d3
CAT-QuickHeal Clean
McAfee Artemis!2B5346DCFA4F
Cylance Unsafe
Zillya Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Fragtor.9833
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaCO.34088.GqZ@aqJbnomi
Cyren W32/Kryptik.FAW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMEA
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Fragtor.9833
Emsisoft Clean
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/Tnega!ml
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.AgentTesla
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/GenKryptik.FJFZ!tr
AVG Win32:MalwareX-gen [Trj]
Cybereason Clean
Avast Win32:MalwareX-gen [Trj]
Qihoo-360 HEUR/QVM20.1.6384.Malware.Gen
No IRMA results available.