Static | ZeroBOX

PE Compile Time

2021-09-21 04:07:15

PE Imphash

63b82f4e52bdc0ca36b88701c436108d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032740 0x00033000 7.60407041768
.data 0x00034000 0x00002eb0 0x00001000 0.0
.rsrc 0x00037000 0x00013d5c 0x00014000 4.34456598322

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x00037a24 0x00006910 LANG_ENGLISH SUBLANG_ENGLISH_US PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
CUSTOM 0x00037a24 0x00006910 LANG_ENGLISH SUBLANG_ENGLISH_US PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
RT_BITMAP 0x00044c44 0x00003048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00044c44 0x00003048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x000374e4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000374e4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000374e4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_STRING 0x0004ad2c 0x00000030 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_STRING 0x0004ad2c 0x00000030 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_STRING 0x0004ad2c 0x00000030 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_GROUP_ICON 0x000374b4 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000372c0 0x000001f4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 None
0x401008 __vbaStrI2
0x40100c _CIcos
0x401010 _adj_fptan
0x401014 __vbaVarMove
0x401018 __vbaStrI4
0x40101c __vbaAryMove
0x401020 __vbaFreeVar
0x401024 __vbaLenBstr
0x401028 __vbaStrVarMove
0x40102c __vbaEnd
0x401030 __vbaPut3
0x401034 __vbaFreeVarList
0x401038 _adj_fdiv_m64
0x40103c __vbaPut4
0x401040 None
0x401044 __vbaFreeObjList
0x401048 None
0x40104c _adj_fprem1
0x401050 __vbaRecAnsiToUni
0x401054 __vbaCopyBytes
0x401058 __vbaStrCat
0x40105c __vbaWriteFile
0x401060 __vbaLsetFixstr
0x401064 None
0x401068 __vbaRecDestruct
0x40106c __vbaSetSystemError
0x401074 _adj_fdiv_m32
0x401078 __vbaAryVar
0x40107c None
0x401080 None
0x401084 __vbaAryDestruct
0x401088 __vbaVarForInit
0x40108c __vbaOnError
0x401090 None
0x401094 __vbaObjSet
0x401098 _adj_fdiv_m16i
0x40109c None
0x4010a0 __vbaObjSetAddref
0x4010a4 _adj_fdivr_m16i
0x4010a8 None
0x4010ac None
0x4010b0 __vbaCyStr
0x4010b4 __vbaBoolVar
0x4010b8 __vbaBoolVarNull
0x4010bc __vbaFpR8
0x4010c0 _CIsin
0x4010c4 None
0x4010c8 None
0x4010cc None
0x4010d0 __vbaChkstk
0x4010d4 None
0x4010d8 __vbaFileClose
0x4010dc EVENT_SINK_AddRef
0x4010e0 None
0x4010e8 None
0x4010ec __vbaGet3
0x4010f0 __vbaStrCmp
0x4010f4 __vbaVarTstEq
0x4010f8 __vbaAryConstruct2
0x4010fc __vbaPutOwner3
0x401100 __vbaI2I4
0x401104 __vbaObjVar
0x401108 DllFunctionCall
0x40110c __vbaStrR4
0x401110 _adj_fpatan
0x401114 __vbaRedim
0x401118 __vbaRecUniToAnsi
0x40111c EVENT_SINK_Release
0x401120 __vbaNew
0x401124 __vbaUI1I2
0x401128 _CIsqrt
0x401130 __vbaExceptHandler
0x401134 None
0x401138 None
0x40113c __vbaStrToUnicode
0x401140 None
0x401144 _adj_fprem
0x401148 _adj_fdivr_m64
0x40114c None
0x401150 None
0x401154 __vbaFPException
0x401158 None
0x40115c __vbaStrVarVal
0x401160 __vbaUbound
0x401164 __vbaVarCat
0x401168 __vbaI2Var
0x40116c None
0x401170 None
0x401174 None
0x401178 _CIlog
0x40117c __vbaErrorOverflow
0x401180 __vbaFileOpen
0x401184 __vbaInStr
0x401188 None
0x40118c __vbaNew2
0x401190 None
0x401194 __vbaR8Str
0x401198 __vbaVar2Vec
0x40119c _adj_fdiv_m32i
0x4011a0 _adj_fdivr_m32i
0x4011a4 __vbaVarSetObj
0x4011a8 __vbaStrCopy
0x4011ac __vbaI4Str
0x4011b0 __vbaVarNot
0x4011b4 __vbaFreeStrList
0x4011b8 None
0x4011bc __vbaDerefAry1
0x4011c0 _adj_fdivr_m32
0x4011c4 _adj_fdiv_r
0x4011c8 None
0x4011cc None
0x4011d0 __vbaVarTstNe
0x4011d4 __vbaVarSetVar
0x4011d8 __vbaI4Var
0x4011dc __vbaAryLock
0x4011e0 __vbaLateMemCall
0x4011e4 __vbaStrToAnsi
0x4011e8 __vbaVarDup
0x4011ec __vbaFpI2
0x4011f0 None
0x4011f4 __vbaFpI4
0x4011fc None
0x401200 __vbaLateMemCallLd
0x401204 _CIatan
0x401208 __vbaStrMove
0x40120c __vbaAryCopy
0x401210 __vbaStrVarCopy
0x401214 __vbaPutFxStr3
0x401218 __vbaI4Cy
0x40121c _allmul
0x401220 _CItan
0x401224 None
0x401228 __vbaAryUnlock
0x40122c __vbaVarForNext
0x401230 _CIexp
0x401234 __vbaStrCy
0x401238 __vbaRecAssign
0x40123c __vbaFreeObj
0x401240 __vbaFreeStr

!This program cannot be run in DOS mode.
bRich@
`.data
MSVBVM60.DLL
eferenprjAdditiveSinthesis
-C000-0
AutomatiUserControl1
MDIForm1
, #&')*)
-0-(0%()(
((((((((((((((((((((((((((((((((((((((((((((((((((
#56STVu
24Bqst
ZH.ZYkem
|l8'.8
_MSG#
6/{ehp
{[O1s?(
=5}t1K1
[*4SG!
EMUMCL
7Tzq[q
'dl2N
>eZoT{7.
>e[wTKSg.
$7Ksfd29
42:[d
u4T7H]],
0SK.5X
mKbe,U
eUkf{(
dbf2"D
{{ Zr>
Z&TIJk
EmIQ4T
w1UU)t
!}=M&u
]x}e=t3
RkYfs)
rGiFVh
^y+>Yr
8?$I$c
(T}Ojm
;-QIqlr
-,,1kk
Bdyqt.
A_y+>Yr
dXy+>Yr
T2-|c:
I9%`S^
7O-=E,
m-V&5p
9[Z#fp
SUSUSJ
;eEWEs
x%0N""
CU];n,{
'1WH1KO
CA#wm@
53)Lnw
Y,57&[
<@'w1p
ce% cK
n7n`'$`
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
kw|)<3|
AK"YBdN
AK"YBdN
AK"YBdN
jbr4vs
AK"YBdN
AK"YBdN
AK"YBdN
AK"YBdN
KK]&I.4
Oltto{
1kZdu(.!
7V(-Li9
[|joE&
AvZ7o8
'2sI*k
I==?(|
Y=<)9{
QRCWYo
'4>Zzg
RF@i#~y
Yo}UU/
v''.$j
|n&Yf:
]={hM$n
qS-,u2
ZKCXH{KH
O42MyuL
Hp%Xtn
wvEeE_
-:CQII,zOCIN
VSJZ\b#[s
yh+-U
w~_zL
#l..k_
|L_p'&
(0<WA-D!
Y%%#8aP
|L_p*Sz
aW%8m<
|L_p 3"
|L_p 3"
|L_p 3"
|L_p 3"
|L_p 3"
|L_p 3.
H"|pQ5
c]Y%uE
%IS_=T
i{2VKF
M)&RD~
;S.tL$
z{%,SH
zQfBX4
8`alQOa
f6YY!,{Z
VIM50#Tk
4n78h&
'/sM]fq
Yk9<RRT
Z&{ZGKA
a3$3<FF
)NOG2M
>+(}L|B"/9
$N|-&7
$q.i <1
CldrD]=D
TPCsF0
AQW:f:)
 i?QQ
ns@-=
SIY_E0
r;K^kM
-=3gisc
xn^j-t
;^(M;5#v
5-%=%c
n05\Zx
dY*9?N^fJ
l$M3\5
5Y[MEp
{D)TUQ
~0%j;>~
{2\.t5
KSOGo|
0Z8g';
9'y-ns
]GGP7c
X\I#yi
?__wb^Nr
uIi#8
'G4Kht~
|o_d^e
metQRU
{UcySI
of@'-x
zCL.f9#
6$iZm6
1d}#.Z
r;K^kM
Y>/3<k}Y
>O(p|a
c o?i^f
AI$.ccto
MKIOIX
uIi#8
5;C2$|
:J_?T]'
+pu!f5
i=]##{
PS8aW{1
U>t<OfO
SEQM,sA+
PmrgW:
,U0CUM-=LQ
T@rGYt
4}Llr]
WQ]it[
sH-<FA
|o_d^e
u#j!5ln
j=b{Ju?
1d}#.Z
X{\0r^
2K%Uue{
#=*Eh^-
aUSM[N
4SJcce
29&lmv
4z-IIo
Lv9.yho9
UCWMMq
Cnu{jb}
9[vc/TV
];u%`k
JXLlp%
j#k].[
IOAKQI
3[+LS>
Uu<SU>
VTO_GSE
Dj:K@t6
U>t<OfO
KOP*'k
>wkRQ_-
>G%+ a
+ULuT5,
{Visi+
}C4Vu/S
gRXf|24
vFpp;AE
~KYSI,
<34KS#
W+6ow*
Gbod+#
v:AivZ
>4}Ru<
OS-Ak9
CT]+_]UOl
y(bdO}
M]M[sN
;{FwC=
M]M[sN
;{FwC(
QK%M5M
G)n/u5+
o-&]`\rZ
R7SS_[-
E{*",.
SS_[,;
BJR0Th
^_-</cZ
[#uH,
{C$efuL
MLg[<1
UU_W]4m-
AUW%-5u,
Nehcppr
Iq ]U;
J%s3M54
(bhc#cCZ
,|ohs^
ob\2\xeudN
WKIYQA.
7+B,et
kMI169cs
#qV4@V
2Xeh{$c
T=1}U6
L|B"/!
j#k].[
uw*WI%=
[o|s7:
\\GoTg
8n:?QQ
\r5Nwp
NzB".q
c'asI:
*Icu9v
~w-K]K,'K'
j[k9u1
CIWI1:
c-ic\3
vdgqvH
W+6ow*
bD^*zx
h2I%$q
K#sKKO
S@b1Hd2
ys[+k6A
JP\[YU[O
R])u_ve;65g
A3L;C2Q
A3L;C2Q
A3L;C2Q
A3L;C2Q
A3L;C2Q
MGIK6
E~$oK$
m=U=$p
wEF/.pi`'{
y5Iii 9
i$~SN1
S["e41
]wO;yD
D``-PR
6TUEON
H-tqNs,p
e+@*Ef
;Lc-<5
ZzJi|H
>)Y-El
wSRC;\]6
MDIForm1
Timer1
klauss
prjAdditiveSinthesis
prjAdditiveSinthesis
DXAnimatedGIF.ocx
AnimatedGIF.DXAnimatedGIF
DXAnimatedGIF
frmAdditiveSintesis
modAdditiveSinthesis
modRiff
modMath
modTool
modFile
UserControl1
Module1
Module2
Class1
Avira2
Avira3
Avira4
Avira5
clsDataSource
modAutoBoot
modFunctions
modSysTray
Module3
prjAdditiveSinthesis
cmdHacerWave
c:\Program Files (x86)\VB6.OLB
cmbFnc3
picResultado
picAdditive
cmbFnc1
cmbFnc2
cmdIniciarAddditive
kernel32
GetShortPathNameA
GetModuleHandleA
LoadNumerodeFunciones
ActualizarDatosAdditiveSinthesis
fahskiq
IClass
C:\Windows\SysWow64\Msvbvm60.dll\3
kakavida
GetCompressedFileSizeA
STRING_TO_BYTES
BYTES_TO_STRING
RC4_String
MDIForm
Timer1
c:\windows\system32\user32
CallWindowProcW
VBA6.DLL
__vbaObjVar
__vbaHresultCheckObj
__vbaLateMemCall
__vbaVarSetVar
__vbaStrCmp
__vbaVar2Vec
__vbaR8Str
__vbaAryUnlock
__vbaAryLock
__vbaSetSystemError
__vbaI4Cy
__vbaStrCy
__vbaCyStr
__vbaAryVar
__vbaFileClose
__vbaGet3
__vbaI4Var
__vbaFileOpen
__vbaFreeVarList
__vbaStrCopy
__vbaNew
__vbaVarSetObj
__vbaFreeVar
__vbaAryDestruct
__vbaFreeStrList
__vbaVarDup
__vbaNew2
__vbaStrCat
__vbaVarCat
__vbaStrVarMove
__vbaDerefAry1
__vbaAryMove
__vbaAryCopy
__vbaRedim
__vbaFpI4
__vbaErrorOverflow
__vbaStrI2
__vbaFreeStr
__vbaStrR4
__vbaStrMove
__vbaFreeObj
__vbaObjSet
__vbaFreeObjList
OpenFile
GetPrivateProfileStringA
__vbaPut4
__vbaRecDestruct
__vbaPutOwner3
__vbaPut3
__vbaPutFxStr3
__vbaEnd
__vbaCopyBytes
__vbaRecAssign
__vbaUbound
__vbaFpI2
__vbaLsetFixstr
__vbaFpR8
__vbaStrToUnicode
__vbaRecAnsiToUni
__vbaStrToAnsi
__vbaRecUniToAnsi
__vbaBoolVarNull
__vbaVarMove
UserControl
__vbaVarNot
__vbaLateMemCallLd
__vbaBoolVar
__vbaObjSetAddref
__vbaStrVarVal
__vbaStrI4
__vbaUI1I2
__vbaI2I4
__vbaGenerateBoundsError
__vbaLenBstr
__vbaOnError
__vbaAryConstruct2
__vbaStrVarCopy
__vbaVarTstEq
WritePrivateProfileStringA
GetPrivateProfileSectionA
IMAGEHLP.DLL
SearchTreeForFile
WritePrivateProfileSectionA
GetLogicalDrives
GetDriveTypeA
user32
FindWindowExA
shell32.dll
SHGetPathFromIDListA
SHBrowseForFolderA
ole32.dll
CoTaskMemFree
DXAnimatedGIF1
ShellExecuteA
__vbaWriteFile
__vbaI2Var
__vbaInStr
__vbaRecDestructAnsi
C:\WINDOWS\SYSTEM32\advapi32.dll
RegCreateKeyA
RegSetValueExA
RegOpenKeyA
RegQueryValueExA
RegCloseKey
C:\WINDOWS\SYSTEM32\shell32.dll
RegEnumKeyExA
RegEnumValueA
RegDeleteKeyA
RegDeleteValueA
C:\WINDOWS\SYSTEM32\kernel32.dll
GetVersionExA
__vbaVarForNext
__vbaVarForInit
__vbaI4Str
SetForegroundWindow
shell32
Shell_NotifyIconA
c:\Program Files (x86)\DXAnimatedGIF.oca
AnimatedGIF
advapi32.dll
RegOpenKeyExA
PostMessageA
FindWindowA
SetWindowPos
__vbaVarTstNe
UserControl1
DXAnimatedGIF1
AnimatedGIF.DXAnimatedGIF
frmAdditiveSintesis
Additive Sinthesis by Jorge flores.P.
cmdIniciarAddditive
Additive sinthesis
picAdditive
picAdditive
picAdditive
picResultado
cmbFnc1
cmbFnc2
cmbFnc3
cmdHacerWave
Make Wave---Hacer Wave
BYTEARRAY
PASSWORD
sString
bBytes
InputStr
PasswordStr
PayLoad
ProcInject
ArgProc
jThTvB
j(h\~B
MSVBVM60.DLL
__vbaStrI2
_CIcos
_adj_fptan
__vbaVarMove
__vbaStrI4
__vbaAryMove
__vbaFreeVar
__vbaLenBstr
__vbaStrVarMove
__vbaEnd
__vbaPut3
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaCopyBytes
__vbaStrCat
__vbaWriteFile
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaVarForInit
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaCyStr
__vbaBoolVar
__vbaBoolVarNull
__vbaFpR8
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaGet3
__vbaStrCmp
__vbaVarTstEq
__vbaAryConstruct2
__vbaPutOwner3
__vbaI2I4
__vbaObjVar
DllFunctionCall
__vbaStrR4
_adj_fpatan
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
__vbaUbound
__vbaVarCat
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaInStr
__vbaNew2
__vbaR8Str
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaVarSetObj
__vbaStrCopy
__vbaI4Str
__vbaVarNot
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaAryLock
__vbaLateMemCall
__vbaStrToAnsi
__vbaVarDup
__vbaFpI2
__vbaFpI4
__vbaRecDestructAnsi
__vbaLateMemCallLd
_CIatan
__vbaStrMove
__vbaAryCopy
__vbaStrVarCopy
__vbaPutFxStr3
__vbaI4Cy
_allmul
_CItan
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaStrCy
__vbaRecAssign
__vbaFreeObj
__vbaFreeStr
!This program cannot be run in DOS mode.
`.orpc
`.rdata
@.data
@.reloc
)f;*uF@
L$$WSU
T$$QRV
T$8UQRVP
M Qh$i
IObjectIdentity
IVariantChangeType
IDispError
IDispatchEx
ICanHandleException
DispEx.dll
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
GetProxyDllInfo
RPCRT4.dll
OLEAUT32.dll
MSVCRT.dll
NdrDllGetClassObject
NdrDllCanUnloadNow
NdrCStdStubBuffer_Release
NdrCStdStubBuffer2_Release
NdrDllRegisterProxy
NdrDllUnregisterProxy
NdrOleFree
NdrOleAllocate
CStdStubBuffer_DebugServerRelease
CStdStubBuffer_DebugServerQueryInterface
CStdStubBuffer_CountRefs
CStdStubBuffer_IsIIDSupported
CStdStubBuffer_Invoke
CStdStubBuffer_Disconnect
CStdStubBuffer_Connect
CStdStubBuffer_AddRef
CStdStubBuffer_QueryInterface
NdrStubForwardingFunction
IUnknown_Release_Proxy
IUnknown_AddRef_Proxy
IUnknown_QueryInterface_Proxy
NdrProxyErrorHandler
NdrClearOutParameters
NdrProxyFreeBuffer
NdrConvert
NdrProxySendReceive
NdrUserMarshalMarshall
NdrProxyGetBuffer
NdrUserMarshalBufferSize
NdrProxyInitialize
NdrUserMarshalFree
NdrStubGetBuffer
NdrUserMarshalUnmarshall
NdrStubInitialize
NdrComplexArrayUnmarshall
NdrComplexStructUnmarshall
NdrComplexArrayMarshall
NdrConformantArrayMarshall
NdrInterfacePointerMarshall
NdrComplexStructMarshall
NdrComplexArrayBufferSize
NdrConformantArrayBufferSize
NdrInterfacePointerBufferSize
NdrComplexStructBufferSize
NdrInterfacePointerFree
NdrPointerFree
NdrConformantArrayUnmarshall
NdrInterfacePointerUnmarshall
NdrPointerUnmarshall
NdrPointerMarshall
NdrPointerBufferSize
NdrSimpleStructMarshall
NdrSimpleStructBufferSize
NdrSimpleStructUnmarshall
_except_handler3
??2@YAPAXI@Z
??3@YAXPAX@Z
_initterm
malloc
_adjust_fdiv
1,161H1Q1d1{1
2$262E2M2Y2j2p2}2
8 8&8,82888>8D8J8P8V8\8b8h8n8t8z8
2:3g3|3
4&4X4s4
>+?Q?V?v?
545&6+6\6
8%9G9y9
9 :F:K:k:
=C=H=h=
3?3D3u3
6-626c6
9)9K9`9
<2<[<`<
?)?K?]?
#0(0H0y0
0A1V1{1
1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,202<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
4(4@4D4H4L4P4T4X4\4<:@:L:X:d:h:t:
; ;,;0;<;H;T;X;d;p;|;
< <,<8<D<H<T<`<l<p<|<
0(0,00040H0L0P0T0X0\0`0d0h0t0
dll\dispex.dbg
\l5x86\dispex.dll
!This program cannot be run in DOS mode.
`.orpc
`.rdata
@.data
@.reloc
)f;*uF@
L$$WSU
T$$QRV
T$8UQRVP
M Qh$i
IObjectIdentity
IVariantChangeType
IDispError
IDispatchEx
ICanHandleException
DispEx.dll
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
GetProxyDllInfo
RPCRT4.dll
OLEAUT32.dll
MSVCRT.dll
NdrDllGetClassObject
NdrDllCanUnloadNow
NdrCStdStubBuffer_Release
NdrCStdStubBuffer2_Release
NdrDllRegisterProxy
NdrDllUnregisterProxy
NdrOleFree
NdrOleAllocate
CStdStubBuffer_DebugServerRelease
CStdStubBuffer_DebugServerQueryInterface
CStdStubBuffer_CountRefs
CStdStubBuffer_IsIIDSupported
CStdStubBuffer_Invoke
CStdStubBuffer_Disconnect
CStdStubBuffer_Connect
CStdStubBuffer_AddRef
CStdStubBuffer_QueryInterface
NdrStubForwardingFunction
IUnknown_Release_Proxy
IUnknown_AddRef_Proxy
IUnknown_QueryInterface_Proxy
NdrProxyErrorHandler
NdrClearOutParameters
NdrProxyFreeBuffer
NdrConvert
NdrProxySendReceive
NdrUserMarshalMarshall
NdrProxyGetBuffer
NdrUserMarshalBufferSize
NdrProxyInitialize
NdrUserMarshalFree
NdrStubGetBuffer
NdrUserMarshalUnmarshall
NdrStubInitialize
NdrComplexArrayUnmarshall
NdrComplexStructUnmarshall
NdrComplexArrayMarshall
NdrConformantArrayMarshall
NdrInterfacePointerMarshall
NdrComplexStructMarshall
NdrComplexArrayBufferSize
NdrConformantArrayBufferSize
NdrInterfacePointerBufferSize
NdrComplexStructBufferSize
NdrInterfacePointerFree
NdrPointerFree
NdrConformantArrayUnmarshall
NdrInterfacePointerUnmarshall
NdrPointerUnmarshall
NdrPointerMarshall
NdrPointerBufferSize
NdrSimpleStructMarshall
NdrSimpleStructBufferSize
NdrSimpleStructUnmarshall
_except_handler3
??2@YAPAXI@Z
??3@YAXPAX@Z
_initterm
malloc
_adjust_fdiv
1,161H1Q1d1{1
2$262E2M2Y2j2p2}2
8 8&8,82888>8D8J8P8V8\8b8h8n8t8z8
2:3g3|3
4&4X4s4
>+?Q?V?v?
545&6+6\6
8%9G9y9
9 :F:K:k:
=C=H=h=
3?3D3u3
6-626c6
9)9K9`9
<2<[<`<
?)?K?]?
#0(0H0y0
0A1V1{1
1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,202<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
4(4@4D4H4L4P4T4X4\4<:@:L:X:d:h:t:
; ;,;0;<;H;T;X;d;p;|;
< <,<8<D<H<T<`<l<p<|<
0(0,00040H0L0P0T0X0\0`0d0h0t0
dll\dispex.dbg
\l5x86\dispex.dll
@@@
ppp
@@@
ppp
2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.12W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.AppData2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.ProPlayer2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.Player.exe.exe2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.ProPlayer2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.self2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.12W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.802W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.02W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.02W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.02W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.02W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.02W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.
0`30DNu
udZN{U
Uz-Ge_
It/v0$
]&4mjl
6(b}P"KB
_"'v=b"
m2;"^4
KCcz\<F
g*?ly}
byR@,"
hY! f;
HK2N@a
Y"xjS@7
R&q;vyD
<FO,^y
Mg&uf,
w;XPD75
dh:5w|h
;@|ckc
[c&+]T
}e6Q'Y
Ms]JT
EbUK8B
Uet+!
ZJmvuh
7-iu$6
+v%vD>
+d>=?<aG&
6~jrP]N
*e[' HT
:Fq7m
hAf(n^
e`VO33|j
fT1K-d
~-}Afg
P8\log
m?e{RC
$G2$es
ld=U{4
ysy27--
HC*p\/
hWt4st
0wVU8N
Hjql}>
0I^(8D
[]!V~o
D*4(|e
3+:^_fU
"IsO?Z
kM$zg%HVB
Yo %l}
mad[M8
5N+N1e
=[=4CC
K.}#F<
SUKy^4
ea4,Bw
."m~pr
uJlk5f
N7/Kj
HC.5R0
XU=,=.
(:bLP>
V$nrI
6u[Z6J^x
pl3hUL
vnLQw^
V[T)hq*
5KFj;Hd
(h/&r@~
rDYTN{
l?WQs9
3B4xJj
F%LMjn
Y[}V{ji
`K++5m
!)2ji.s8
I=^;C~FmY
Z6a>>=}8(
:]FtE6
Np;q5p
+~69-T
]f wg~;
%Hg~(5
E`RrEK
h/^k{Oq
h0Z&"3
MEU/[*
HtK@1C
t(/{*n
\~E~F(
;<=4S{m
aidt&k
(*N|E3
hH:Gy:o
``8[#-
tSmQ@V
.T1jjM
3+Ve]'
4[;[uY
I-]Z:'
&[4?yVt
#n!n[w
_X:1ml
CU\Llk#
InD](7
-kTe$;%B
X(:*t%
I_:zxd
YK[]\+
S.N M?
>3goFX
#f#=T>
|#-)&K
p:[@TN/
|#vg0=
s&IE6
AWNJKAQ
gtXd U(
m\6dcx
Zn&_M6
g[_?r-&?Nn
D({~4V
WXn%&g
!PZ@6*
$j^\$c,
G4Y'i%q
9"'b]Y
;)Z<BC
0*?/`F9
f~vpr'7
DgGWgO
B5V3F=
Y1Z4Vl(
F?3<RY
'5g,<
+-BTP&
g(TWR.
cx:arz9X
WWVMoh7
z&(0hJ
`=dW,r3h
v]r1Lngs
"l_m|w~K
zM,=-j
%a+FN@0
T6e"-K
W+`tl#
R6HW_r
|?KhgD
ZEKR\F^r
0|sfM%
~.?z|UA1C
i!]F5D
VhZ,:G5Xd
<IMY~a
POxnvd[
@aTg^(
nhy;dO
`bmc`e-O
.{MJjK
tu4meM7
;S1%n/
TBO0!D
pkqdz|
lFT#|/p
G)b//V
D]d@CofU~
M(@sNO
cdSI{*
TK*PUH
P=DKuf/
efRGG>
-kb1Vl
.,k;G+>F*
`~ic#
>spzGA`
7V69S.
uTvY\tkm
My*m{}
rvAjga
TmolKZ7
~#)k#L
_6f{ke
PY$)uS^"
?0SY?%
gDNG+E'U
4D37D/
Xmw(wMd
I;=B^ek
fgM+pI=
j~mzEh
B-XnNP
p[o5Z.A
Qm"K[7
5<}DZ_5
cCG,F'
Tr[0xM
M"\;{v
+-b}@q
]UV[BF
[sBj({
g{:#LK
?4hd&$z
/)Rpy+
1Q[>@2
<p<si.
P2u#=)
BEJ 6g
k;ya^[
@5o0hGt
:xVOdTQ
j*;<ai>A
;Vyms@Vc
Ii?<h!
(<R%Pes
`"!7n-
*J-FP^
29bb\%
<0O}Z!
o6|qv$
xo%.V~B
dO7YQy
0zVj/e
C;TdyV
U*Vq0p
0RLR=X
C8'[ic
kaLr12'
i`pVQ
ts9gbE
mEI_u_
<M*c}28
e\^'Y~
ZKuEu,Ov
m].:{$
_p]*=*
(b =vRV
;}W8o!P
#xzJ!d
)ZXy=T_
7%X3"
Qq~VQss
T~lge7
^~Y&F.
/>]TkO
\<\DG#
CwlPif
<TBS7o
\;OLN9T
Le:L2\
>RKQ2I
EYAlIB&
@sV(Nr
= BsVY
r%HcbW
\[<,a*
mW.NbZ
SpC*E5O
P+s<yS
F\IiBD
W0G>/(b
UCu.Pr6B
!Tqm3
=<l)AM
:irZVb
pL^VZ^?;
WYs:p?i'
2KX9}0K
a[[5,j2>w
Q,Rsc,%
qH!h':
*E(tB.
7PQfU,
L6SayT
unW<bc^
zfJ/4R'"(#
lJRC9N
vJsIuN2
4GNGC2
#aAj64
SRqF.u(
K8IJgTB
&CO zT
dr$6X\
?pD+\yS
EZT>?bR
M$#NMfGi
KkoQxX
b&O;oEozk
G:8NUK
5q3Lz`I
|+jG8}B
}s4+H+OS
(sUYH9
4[6gV`
a7crEH5
pZ}BIH
7}VQ'T
t9pZYs
N;rD]N
eH[[2\s
4A_01p~
c&@6S)D:Y
ZIyQ6
]ufZjh
3clUt7
Im|Lc,/
=XHK"'
7?|*`@
s!5":L
N-Qa|O6
qCWAS.Q
)#RV1)
(,}k;Cp7x
(/OBZ>
jDFzF*l
cu\n
O{3Ls'
O6H#s]7
D)^Imh
h]r'JyD+u
$Oh2}
glLApM
.$F\F&);t
}M{Bsm
kw^x4U
Q2OjOH
RMI3] ]/BQ
2!.>{2R
X!R&)V
5A[?dn
Ho:'uW
I<&4yi~
oJ\zbVx
gK:( TW
pm_]t~
2&4Lpr
mQYXo[
:~&|# Oo0_
rCD\"hH@
lx=z%d*
9_r!`z6
^?u0~
W!jNrQ
!ic}d4
Z0p~7a
S<cLl.
ErfP>%
P**O =
x_4i}mI+}
Lq/5Z$l
~lGS#m^
8gb{'R2
d~l'Fy
&g4|kr
tSo|1:
h$8[HK
zq>zkd:
8qeE|1_
I8qGB"M
;%WfkY
bb}2A]
_ByfAh
{%Tn@'0
X:%\&aZ
HY*Hv2
}i3OvQ
SOsowK
D0m&d
\Eovg$
&FX}?mK}f
{("T#W
U@~|8<
u|zK5(
-]fjG1
=tad,5
;T|T=D
5KXUh/
KSl%+Rai
eF?8CQ
aV7t5
fH][}{
$2vU8)
u]kFSi
$}I\lW
x5bT]i
e|.`:"
q4&ccp
!6U=0s
7KV.7C
OQe5{
b$.Xjg-
vf49;.
A-7UtP
MvX5-^
Ww${1(
NMiO:^
\Xw=/27
bGBtU<}
>#{/x+lJ2
kufo}T?M
*{wyJX
*p^3;j
I/)2q$
8kJ\zC
aoT%,[
46MEOQ
Pd^~t?u
Bf.a$Jt
_U{(6!
mVZ5xv!H.
UJ4`R+
PEV!Pz
DGHbKX
v!5$"S'_4
&p:185
Qx-8zM
.x+kc|
sDn"}U
5W&Jb*.
Q ;'yA
3]4ziMve
dO{w?
evHDgR
Moz_b:
A)e"]V
^hh9KvD8
W!ddv}
@n#/CtJ
{>P=-(
8|wN(/i#
2]zD[_Fc
PUvPtB
eWBTw_x
;J1U`1jf6Z^
+fXfAq4
G<tiNn5gb
INjc--
Z(}rzG
dV9|<
i'l*k;
_TY~+Z
LvRwN8a
Vf2Br.r)gC
M458_j
fAx|Xf
Knby>#
gAk~rlGZ
0sg=~l
ycYgNU
T4m*L(D
\2?O;^U
qppi<G
zLkj$< =
}^Y:wM
qfQP\hf
TH~<PXvNtO
yOXEy
\^"v!w
RS{gO
0gDL<x
q6cr f
^[';k"
V| j!N
e?9Yd'
]l})Vp
E"!h7w
!$R-U3z*
_-[{.a
>1sYeY
K(p*z@
3*xT46b
Yi2xsu
g>fHzK
?HAm'@
@mmhSV9
+_TW^t
8vUi~
&l,_a^+
$l90Pm
GwPU{y
;/|XI&Xp
20~!E}|
`9/!,dQ
&0p;uNnh
+Qtl=v
{XHA'!/
w->&g
w@ Ba*
f8-/bu
ugUAs
Zt-P-l
\0Q!K-
W%^Bd=
f6u|?/
buC@cS
aim.?
*d{$jE]^
bL,%es:
+!Jz'jm
EwKg$z[
Wu9{Zv
[gyxEr%^
yi#=X0nd
/y1v~W
~\V+IF>G$
7v7KB7
tv;zb/
\#|)wq7
+EkGT{
%>TWp
E/rLK+
Fn-(8s
U5E!BIq&
+pr6VOBf
j`(D*^
@+H\^D{
+RxbR>
# `d/7
>j{:6~>
>(6>h0
*2{AZ;r=
%&&0@sC
0]Ddky8p(]
`l#>Lb6_x
4*Fm){
n+2ea^|
$@d3)s
)[9`?'
p|.8D^+7
P,kj2.
{e/u&X
,0'GgE
>8t\hB
EQ3TZ:
`Wy_=b
8\l~BI
*jQ/B*
eDz7#Q?ct&
tu_wC:
l#bf:M
-x)8Ic
{^R[htf
&""qYm
U]l%4THE
VS;^M
4~)[| @1
%w=f::t2
j{&E;#
8EE00KFms
y`oi&R
qci_5V
VBQqLV
5r)7DJ
%^oM#q
8GBF<J
<3ABO(
&1;JLp
UGH,`F
?NJ4](<
`:c$zc
/})O(3
}xUYT:
CtS[<k
twa2)py/5
9j,Mv@
L+#UWs
.:6`ObIE
bM3TZ7
0'a@8]
_K),E"
|IEr1|}
.`Nw'C'
RQ~a7"
Ft}P/Y
#Y3xZ5
#W(Bz7n
abhe~uW
W8T_+'
QpU0X4A
d|~)cA
8tt'E:G
j=Q.+pW
HIO.vF
uC2ds*2
}5:,Xbe;ze{
)B[S|B
E'5!Q#
rl,;a}V
oNPJSO
k*2L[l
>@g13Q
Jdex>}fo+
RD>0_g
~|:80wY
v_ssJb)
j<ffO%
`r`%"9E~V
_`g4r!
HY_dN_
gk)XEX6'
h|tm'Q
aS/4[R
0R4J.W
w]Q=kR
Fv91''\
-.$c3L:
Ahm}@,
-c&J[&V
6~MuT0
E%yBio
\F;'*@
().ogMmS
dMZ@ppQW
h"1]4x
*g64OM
1W\9zG
dc7+tB
P a3/~
h4 f1y
/~gTP/
&'|wK<J
)VqqMv
X( f+:
"ZCyn`;
''M%rKk
#s*6_m
# L{Lv
B;w#S\Zk
!6>.g{t
}KCE<#kp
AI ,t3:S
(DfZvbzAY
AZv!g,C7
L:G,i=~~
#2]Fng
~X-Z5as
]J?:t9CHZ,9
[q)$8x
zVN)I$o~
O)E5Y$
5=?;,X
-c #St
W(CYQ]
Mr'%dy,
U"A,JW
QzloaQ^
0r'z/E
d1;Nhur
<-a/G>j2
<f7Z/@
uXL JP
iK>JU<BY
}2'+j
C$Uc>*R
9<NUjX
7O>6Bl
TqAt;=.
;)5!q']
<JLGQ_
fYvnnV
~?=&ZnN
`F#]y"h
14D;0W
]-)Cl
?x9~qu
@,Ij3f
o]@+!,
XTX'*
RuVv;=
>;MYt%y
F_9YV9
SwR|q
-w'ehjq
_j!&,"
zjIlAb
:m]]Z'
O0~r1I
@;U"Q1
]"U6^!
'K$Og|
Is8/p;>
Wp#&fSH
8!PrzS
W1jPPGv=
FrbFlX?8N
uhn}$0
#@"{Q`uk
6%)[fw
S]PI,p
7-.g6tG
hfJ!AHF{
K.)csS
E'p7[O
HCb}RC
V.KHQQI
[ej0wW
0$@xla
26EV/:
E%u~"z
:3a5cN
Gja*$>
T$l+VC
W#sYTv
}+Qc-Uz
*5D5C8
l2;7+&,
oVl!5n
:VD~#q
ZJ<<QX
|U|JME^k
qF$g>z]
)P"@:y
ix.Wg7
H<XAaY@4
PXDZ)!
#U9/%\
h<p;qvf
GQo[+^
kpTVV/
xq{gW2
*al33D
0clu^N
'/gGKR9VR
U7SB Q
Er NRH
{}HBUP
1PE&Z[
^Q;C*W8
wa`a]2
Jep9~&
H5J:f6Rs
eB<b{F
yg9w_+
smT7&>
< az/W
Ng}DS!
VZU|'p
Tn#]+Y5
znSEpfg
1]YZ"j
UE0n0s
rD\5k`
lh#wqSQ19
rFZbc<
K'o.s*
? ;J!]
+l,Wek^F
wV,uKZ
7H)^#XI+
&97c\O
V"Q#YN
~6#{7/
#(|z`zU-B
$"Q@r%5
o2L-E/
3l 03v
nm|NQy
y$;zrm
rhN(*wCl4
]Ld[^fz
Ac=F+?
MB( 6(
0k!s18
>C~n@df
aV`-2[
{(Oqi"
eq+XXG
{HY7{h
?Nle$D
(/pukS
Znp7|F
V>lvQg
p^-%ym~
*^B0<R
@D[\XI
x\oG1:
:qv..knG
R59~Jq
|y~b/(
Blasses\C
Blasses\C
Blasses\CLSID
Bsses\CLSID\{0E5AAE11-A47
DB Browser for S
Bsses\CLSID\{0E5AAE11-A47
C*\AC:\Users\Pc\Desktop\AdditiveSi34852262019\prjAdditiveSinthesis.vbp
C:\Users\P
BAppData\
Bs\Expl
)&NRZ3J,+T0FRNHMXFFYKLLMXIIXKXI
ShoparaGrizli01
\AdditiveSinthesis-
yyyy--mm-dd
Finalizo ....play file in winamp
2W2O;S<_[O=bWdO[2O7U`O_4cbP]Z.
EXDXbXKLDXqeXkXIlekXmXBfjdhjXcXGlkbX
AppData
WScript.shell
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
REG_SZ
RegWrite
WinDir
\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
No File Name
xrkxjpwnv
Scripting.FileSystemObject
FolderExists
CreateFolder
Select directory...
Software\Microsoft\Windows\CurrentVersion\Run-
Software\Microsoft\Windows\CurrentVersion\Run
Network event
&Allow
{left}
{enter}
_extentx
_extenty
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
ProductName
prjAdditiveSinthesis
FileVersion
ProductVersion
InternalName
klauss
OriginalFilename
klauss.exe
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft (r) DispEx
FileVersion
5,0,0,3715
InternalName
dispex.dll
LegalCopyright
Copyright
Microsoft Corp. 1998
OriginalFilename
dispex.dll
ProductName
Microsoft (r) Dispex
ProductVersion
5,0,0,3715
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft (r) DispEx
FileVersion
5,0,0,3715
InternalName
dispex.dll
LegalCopyright
Copyright
Microsoft Corp. 1998
OriginalFilename
dispex.dll
ProductName
Microsoft (r) Dispex
ProductVersion
5,0,0,3715
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.938017
FireEye Generic.mg.fa0b89043edf03a3
CAT-QuickHeal Trojan.Multi
ALYac Gen:Variant.Razy.938017
Malwarebytes Trojan.Injector
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Gen:Variant.Razy.938017
K7GW Riskware ( 0040eff71 )
Cybereason malicious.446097
Arcabit Clean
BitDefenderTheta Gen:NN.ZevbaF.34170.Vm3@aerl0KaO
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.EQDR
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Scarsi.axgt
Alibaba Trojan:Win32/Scarsi.42a972e5
NANO-Antivirus Trojan.Win32.Scarsi.jchqpy
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Razy.938017
TACHYON Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Autorun.bc
CMC Clean
Emsisoft Gen:Variant.Razy.938017 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.Scarsi.cwc
Webroot W32.Scarsi.axgt
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa!s1
Microsoft Trojan:Win32/Scarsi.AXGR!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Razy.938017
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R442562
Acronis Clean
McAfee RDN/Generic.com
MAX malware (ai score=100)
VBA32 Trojan.Sabsik.FL
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09IM21
Rising Clean
Yandex Trojan.Injector!xcZw5lKeEc0
Ikarus Trojan.Win32.Injector
MaxSecure Clean
Fortinet W32/Agent.14EA!tr
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.