Static | ZeroBOX

PE Compile Time

2090-11-24 14:42:35

PDB Path

VolumeConverter.pdb

PE Imphash

dae02f32a21e03ce65412f6e56942daa

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000d9d4 0x0000da00 5.88553278046
.sdata 0x00010000 0x000001e8 0x00000200 6.61773120421
.rsrc 0x00012000 0x000003a4 0x00000400 2.9247083034
.reloc 0x00014000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00012058 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorDllMain

!This program cannot be run in DOS mode.
`.sdata
@.reloc
Z?_d
_b`*
v4.0.30319
#Strings
VolumeConverter
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
mscorlib
System
Boolean
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
String
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
SuppressIldasmAttribute
AssemblyKeyNameAttribute
AssemblyDelaySignAttribute
fadf0556-5b3c-4b0e-bef4-59a15b824a6e
VolumeConverter.dll
<Module>
fRPUjC41Rj7TPdtWo9
jIs3Psvoeo2Na6gfe7
Object
volumeConverter
System.Windows.Forms
BajdFry2a9ID1NfoRF
S1o8ge9XT2s9Ar9AOE
Resources
VolumeConverter.Properties
Settings
ApplicationSettingsBase
System.Configuration
tbx064LtyJETnUo1T9
MulticastDelegate
xdg2aeVH7hnGP22BCN
mubNxp7qlol8fnNomI
toFj6tYDLVdINcNQWr
f6VLFMnPNJ97pxIpUm
VjyDnXxx55Lr55Q9Zg
wPgnlrmv4ZLCraGyAf
Q3Ukbb5oko0AiXny9s
icwtfMNdv4eUrHCiqO
Ib42pCTYPIZpcqXWgG
ePhtabSs8hlxBcIarh
ValueType
WubEwDob7S1NSxAie6
<Module>{BC039B27-FD6D-4050-B5D5-56C1EE7EF74E}
cGvRxJeymT2EVUwnBi
k4YOdbrIT6euvwT0Pg
SFU4mbT3GMret7THonf
FufmmOjfqBMhsFZBIN
UyYuAtIRQWAJPkvDuT
pQ5rRKDpaeG9Pe6v97
Attribute
HKOh8kUIuQwnjyypT5`1
aFhU2KPtMUAMUArJnT
JdcGtctGhtGrdVbX56
Rmjb23b74ySqZgCOmC
yyhtvruvHQreIBA89H
ULe3sshwyTIiF8PrlZ
WWKiMu8pWcyrlgQ04q
tM5WXI1uxg8bSHJay3
lJSssvO4Bva6lOLT8Q
GhVcGLAmI96TP3eZ81
<PrivateImplementationDetails>{9B4172CF-493A-4EF3-883E-B456815C2425}
__StaticArrayInitTypeSize=256
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=16
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=18
Uj7yTPdtW
IContainer
System.ComponentModel
p9n9Is3Ps
Button
peo02Na6g
Je7LOajdF
TextBox
r2aV9ID1N
JoR7FZ1o8
DeXYT2s9A
r9AnOEe8R
HvNJVTSIf
EventArgs
Single
MessageBox
DialogResult
Control
get_Text
op_Equality
ToString
set_Text
zSZ4Odeln
Dispose
disposing
IDisposable
QLRvPUjC1
System.Drawing
set_Size
set_Location
FontStyle
GraphicsUnit
set_Name
set_TabIndex
ButtonBase
set_UseVisualStyleBackColor
EventHandler
IntPtr
add_Click
TextBoxBase
set_Multiline
set_MaximizeBox
get_DarkTurquoise
set_Font
set_StartPosition
FormStartPosition
ResumeLayout
SystemColors
get_Highlight
set_ClientSize
get_Controls
ControlCollection
set_AutoSize
get_Black
set_ForeColor
set_TextAlign
HorizontalAlignment
ContainerControl
set_AutoScaleMode
AutoScaleMode
g8N7k6PVPZscc8xn6k
gX6EmcZJUjQFlks9cF
nMm0ETqL131gGHwf38
set_Enabled
TcrFfqspiWR1dIdcHd
aPQv2Bw4MYLAtN3TMb
o21cFlpnuAttD9jhlN
Convert
ToInt32
PilLA6hwbCMK4vlahF
fm5EUIkcMdlCqMWcrg
SuspendLayout
HH8HTmbFZy7MhYRSo0
set_BackColor
qXOdyXJoSOTSJcW6Hd
get_Cornsilk
WYp7W1VC39khXwxnQu
BdiZEavupPJwMiEhJd
iYhkTRdiKb3gAYntB4
oKRw2vYn1DQ6mEH2wF
u1LD7Oy2ecVr96DuWV
NTyHBll7nnjchTNs6P
SIKKeOcgHctdHQ5K3F
WnhG40iqeObvtUJYiK
XYOY4rSAIWxD0jVImj
WgAQ50Al4bdIaTPTjB
set_AutoScaleDimensions
IbADqrmyFhh2HMPQZJ
get_MediumPurple
Eu6NA27cwwykbmxs1A
TWXXkw8Rtgsjx08ByP
f2eXdr1P79wwTlvcey
PerformLayout
sa1xfIt1b
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
aQtQDdKDc3BitvMh3O
XFLmjDfrdWQi7iVdqa
muboNxpql
ResourceManager
System.Resources
pl8efnNom
CultureInfo
System.Globalization
iDkmET1Ib
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
nnUNo1T9b
Eg2TaeH7h
DByWSerm4GuLoL2QXN
LkUuFd5CssPW5349HU
PFl8DGB4FBwRUDQHT0
k0654tyJE
jGPS22BCN
defaultInstance
get_Default
.cctor
SettingsBase
Synchronized
QrvCUKOhZUIinhW2MR
bFVopIgAbdCDNh9Tyb
Ej4XHDxYPRvP0Ke9pa
Default
wNJD97pxI
SUmUCjyDn
Ex5W5Lr55
K9ZPgtPgn
Mrvt4ZLCr
XGybAfH3U
Lbbuoko0A
HXnhy9sYc
Otf8Mdv4e
urH1CiqOF
tIorFj6tD
LoadLibraryA
kernel32
gVdjINcNQ
GetProcAddress
vr0I6VLFM
q8Rja10fIt1bYDkET1
Marshal
GetDelegateForFunctionPointer
Delegate
payload
SizeOf
ToUInt32
UInt32
Exception
Buffer
BlockCopy
BitConverter
get_Size
ToInt16
Process
RMWchDXxxUZSmyN6ug
get_ExecutablePath
Gr4MufHA1NoZ7FuyRH
BuneWGTh51JfvPm2ci
iGZ2Zttd9SIKxE4qlG
I2eNcn0uqlUSJImKfc
GetBytes
rioNqVoVm4Uosuimf1
GetProcessById
a2cDFvRcyaq4DotSAK
y78WH7IbSw3AuCtICW
PImd1HNfppZ9Arlv2J
Invoke
handle
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
thread
context
address
length
protect
process
baseAddress
buffer
bufferSize
bytesWritten
bytesRead
applicationName
commandLine
processAttributes
threadAttributes
inheritHandles
creationFlags
environment
currentDirectory
startupInfo
processInformation
x42OpCYPI
SpcAqXWgG
ePhgtabs8
zlxdBcIar
zBuXbEwDb
iS1cNSxAi
q64iGvRxJ
dmTs2EVUw
jBiFm4YOd
xITf6euvw
n0PQgXufm
lOfKqBMhs
IZBkINRyY
yAtlRQWAJ
Module
ITfyHNuuXbHAX
typemdt
FieldInfo
MethodInfo
ResolveType
GetFields
MemberInfo
get_MetadataToken
ResolveMethod
MethodBase
CreateDelegate
get_ManifestModule
YyFAhf3CvZcwGSX8sa
SetValue
xhH40uayQjYyUJbmMN
pw39S0uUM7k8Z4HHfB
zMaDOvevSF3RnPg7ub
method
G1FJocs7AH
lfcJrpY5a2
SIwJjJNRrA
QbsJIlZItM
OnSJ1EjHNw
mftJOrSmOj
r2FJAxBTY8
VSHJXsEGco
jSoJcNJyT5
RwbJTtdwAN
TrhJW0Iyns
QfHJdeMEHV
vDWJSNHD4e
hmoJiIl9Iy
BGIJPCVWwH
iCnJsOLmGQ
TeaJUOFpcm
D3FJFQpneH
y8EJujpTrE
iGWJes9Mmo
LBFJtFmmmP
SAJJfWIxaj
nvfJDn66HE
IwMJhSFtc8
iXMJbtPQcV
XJUJ8YYcjk
SortedList
System.Collections
qWsJQ5AtpP
Hashtable
fKRJgPn8Wo
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
RSACryptoServiceProvider
System.Security.Cryptography
set_UseMachineKeyStore
yj0yHNuMrdpao
vkvqDuToQ
UInt64
mrRwKpaeG
UInt16
ePe66v97i
LOhH8kIuQ
OnjGyypT5
z0qpR2EH5
NKWZeaNup
AJF3hU2Kt
SymmetricAlgorithm
AesCryptoServiceProvider
System.Core
RijndaelManaged
Activator
CreateInstance
ObjectHandle
System.Runtime.Remoting
Unwrap
aUARMUArJ
CryptoConfig
get_AllowOnlyFipsAlgorithms
jTfCdcGtc
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
Rht2GrdVb
BinaryReader
System.IO
ICryptoTransform
MemoryStream
CryptoStream
GetManifestResourceStream
Stream
get_BaseStream
set_Position
get_Length
ReadBytes
GetName
AssemblyName
GetPublicKeyToken
set_Mode
CipherMode
CreateDecryptor
CryptoStreamMode
FlushFinalBlock
ToArray
T74aySqZg
UOmECbyht
crvzHQreI
FromBase64String
Encoding
System.Text
get_Unicode
GetString
WA8JM9HRLe
TssJJwyTIi
I8PJ4rlZ2W
GetMethod
LiMJvupWcy
get_Location
Exists
get_CodeBase
Replace
GetType
GetProperty
PropertyInfo
GetValue
qlgJyQ04qD
FileStream
FileMode
FileAccess
FileShare
a5WJ9XIuxg
set_Key
set_IV
AbSJ0HJay3
lJSJLssv4B
ca6JVlOLT8
KchJ7VcGLm
s96JYTP3eZ
A1XJnDBL8s
EQpJxaF3yA
NFGJmSZNgx
rGNJ5xGYUR
zmNJN6vm8e
rWwvrRl5KOYKaEB9b5
nxfUjDQLfsrb16EpQd
XWP4ANdxXeQ7A8Rjxr
RT6IZAopDWhPt3bmXj
U1fD2FAs3MUHqnKGEN
zZNGY4xaMHs0XtebRR
BZdhhHOq6PYwj4WDLN
Reverse
WFLnRMqXm8cntHWpKn
CV345MyPyCJx9UObMC
UpLogycD0msC12bpMn
JUwrKQ82YSd0HCnZAi
vFWCEyioGYhy3boKU9
Hh8L94uHx6sTWfH5ff
Uwcx39RgvbSnmxSOTB
Ypp8MqbfWh7pSxSjjE
XxtC4pMnkZ8e2HbPKu
vqk8etLGsbWgnkBmXJ
PUB0F73YQy5LQmD320
YsrIFbJExE4bG9NTZk
NZlvjOHdmfY6RPxrN6
YqW9qISpuZOG2crDYJ
gmMM2QDHcH9kOOjI4H
tmgbrpFT0ykDJCAD99
z0qR2EWH5lKWeaNup1
ce4DmfsmSrOT856tDgfrkMb
ToBase64String
op_Inequality
vSyJKraAfH
hnlwlZWQ6fHpb0IraNW
R1bLZoWWxyKe2yyAUJw
SK8rx8WCru2QDwVc6Nu
YTyrhDW6DEfq3YcrF1B
u8jVJFW4eOKffbcrWXf
SyNrhJWs9NZZ26mltCH
CreateEncryptor
mpLvNgWwmc6FmFsj2AH
tHtihqWPBOJZl2IbsdB
classthis
nativeEntry
nativeSizeOfCode
r2yJkAuKD5
NIHJlBqg5H
value__
sSiJqHxShv
KfAyHNuz8I0US
aakJwvocp6
ModuleHandle
nBYyHNMhlqnxM
GetRuntimeTypeHandleFromMetadataToken
d7pyHNMdPL6af
GetRuntimeFieldHandleFromMetadataToken
get_ModuleHandle
FvKomEWJo0Sa5ThiuV3
PD1OfFWVxmotco016JM
wYjBsrWv7VffM3Y3ngI
GetModules
$$method0x6000007-1
$$method0x6000020-1
$$method0x6000020-2
$$method0x600002a-1
$$method0x600002a-2
$$method0x6000039-1
$$method0x600005f-1
$$method0x600027b-1
VolumeConverter.volumeConverter.resources
VolumeConverter.g.resources
cEJHxttwRuwq355UlZ.6cstawgk4fyome7vuv
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
VolumeConverter.Properties.Resources.resources
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
EditorBrowsableState
UnmanagedFunctionPointerAttribute
CallingConvention
FlagsAttribute
WrapNonExceptionThrows
VolumeConverter
Copyright
2021
$848b10ba-02a7-4507-9d4a-a63f18737be9
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
UyYuAtIRQWAJPkvDuT.FufmmOjfqBMhsFZBIN+pQ5rRKDpaeG9Pe6v97+HKOh8kUIuQwnjyypT5`1[[System.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]][]
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.CodeDom.MemberAttributes
value__
System.Globalization.CultureInfo
m_isReadOnly
compareInfo
textInfo
numInfo
dateTimeInfo
calendar
m_dataItem
cultureID
m_name
m_useUserOverride
System.Globalization.CompareInfo
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo
System.Globalization.Calendar
System.Globalization.CompareInfo
m_name
win32LCID
culture
m_SortVersion
System.Globalization.SortVersion
System.Globalization.TextInfo
m_listSeparator
m_isReadOnly
m_cultureName
customCultureName
m_nDataItem
m_useUserOverride
m_win32LangID
%System.Globalization.NumberFormatInfo"
numberGroupSizes
currencyGroupSizes
percentGroupSizes
positiveSign
negativeSign
numberDecimalSeparator
numberGroupSeparator
currencyGroupSeparator
currencyDecimalSeparator
currencySymbol
ansiCurrencySymbol
nanSymbol
positiveInfinitySymbol
negativeInfinitySymbol
percentDecimalSeparator
percentGroupSeparator
percentSymbol
perMilleSymbol
nativeDigits
m_dataItem
numberDecimalDigits
currencyDecimalDigits
currencyPositivePattern
currencyNegativePattern
numberNegativePattern
percentPositivePattern
percentNegativePattern
percentDecimalDigits
digitSubstitution
isReadOnly
m_useUserOverride
m_isInvariant
validForParseAsNumber
validForParseAsCurrency
Infinity
-Infinity
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Size
height
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
RSDSZ_
VolumeConverter.pdb
_CorDllMain
mscoree.dll
,dRfhn M
)Z71ZDAZ_QZ_YZ_aZ_iZ_qZ_yZ_
.Sd.[d.
.+d.CJ.Kj.3d.;dI
"!#!$!%!&!'!(!
VolumeConverter.Properties.Resources
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.Security.Cryptography.AesCryptoServiceProvider
{11111-22222-20001-00000}
{11111-22222-10009-11112}
cEJHxttwRuwq355UlZ.6cstawgk4fyome7vuv
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
file:///
Location
{11111-22222-20001-00001}
{11111-22222-20001-00002}
{11111-22222-30001-00001}
{11111-22222-30001-00002}
{11111-22222-40001-00001}
{11111-22222-40001-00002}
{11111-22222-50001-00001}
{11111-22222-50001-00002}
$this.SnapToGrid
$this.TrayLargeIcon
$this.Icon
$this.Locked
$this.DrawGrid
progressBar1.Modifiers
$this.Localizable
$this.Language
$this.GridSize
$this.TrayHeight
progressBar1.Locked
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
VolumeConverter
FileVersion
1.0.0.0
InternalName
VolumeConverter.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
VolumeConverter.dll
ProductName
VolumeConverter
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.37778045
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37778045
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Trojan.GenericKD.37778045
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
ESET-NOD32 a variant of MSIL/Injector.LOS
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Trojan:MSIL/Injector.9c37cc21
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37778045
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.dx
FireEye Trojan.GenericKD.37778045
Emsisoft Gen:Variant.Bulz.816933 (B)
Ikarus Trojan.MSIL.Injector
GData Trojan.GenericKD.37778045
Jiangmin Clean
eGambit Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D240727D
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Trojan/Win.Generic.C4409000
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet MSIL/LOS!tr
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
No IRMA results available.