Static | ZeroBOX

PE Compile Time

2071-03-19 01:11:56

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0007a7f8 0x0007a800 7.09724624733
.rsrc 0x0007e000 0x000010d0 0x00001200 4.8906809251
.reloc 0x00080000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0007e090 0x00000304 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0007e3a4 0x00000d25 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF, LF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
$%sJ
8&sJ
8&sJ
8&sJ
(3sE
v4.0.30319
#Strings
IEnumerable`1
List`1
fontDialog1
get__2008
<Module>
DeserializeFromXML
SerializeToXML
System.IO
get_Data
set_Data
mscorlib
System.Collections.Generic
add_Load
NoteForm_Load
FormNoteList_Load
NoteItemLoad
add_ControlAdded
flowLayoutPanelNoteList_ControlAdded
add_ValueChanged
remove_ValueChanged
Item_ValueChanged
labelDateModified
get_Checked
set_Checked
Interlocked
get_Enabled
set_Enabled
add_SaveBeforeClosed
remove_SaveBeforeClosed
NoteForm_SaveBeforeClosed
add_FormClosed
NoteForm_FormClosed
FormNoteList_FormClosed
labelDateCreated
add_ControlRemoved
flowLayoutPanelNoteList_ControlRemoved
Synchronized
get_Gold
get_Hand
get_PaleGoldenrod
defaultInstance
get_NoteListInstance
set_NoteListInstance
noteListInstance
set_AutoScaleMode
FileMode
CompareExchange
get_WhiteSmoke
Invoke
SetButtonEnable
isEnable
Enumerable
IDisposable
set_Visible
SetButtonEnableAndVisible
isEnableAndVisible
RuntimeTypeHandle
GetTypeFromHandle
get_Title
set_Title
labelTitle
get_FontTitle
set_FontTitle
textBoxTitle
set_BorderStyle
set_FlatStyle
FontStyle
set_Name
DateTime
Combine
set_Multiline
buttonDone
GetType
System.Core
get_Culture
set_Culture
resourceCulture
ButtonBase
ApplicationSettingsBase
TextBoxBase
Dispose
get_Date
set_Date
get_LastModifiedDate
set_LastModifiedDate
lastModifiedDate
labelDate
Create
Delegate
DebuggerBrowsableState
EditorBrowsableState
SetCheckBoxDelete
checkBoxDelete
buttonAddNote
buttonDeleteNote
SetDefaultNote
ShowNote
buttonModifyNote
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_IsContinue
set_IsContinue
isContinue
Remove
Zo.exe
get_Size
set_Size
set_AutoSize
set_ClientSize
Serialize
Deserialize
IndexOf
System.Threading
Padding
System.Runtime.Versioning
ToString
add_FormClosing
NoteForm_FormClosing
FormNoteList_FormClosing
disposing
LoadSetting
SaveSetting
System.Drawing
CommonDialog
FontDialog
ShowDialog
filePath
labelBack
buttonBack
Callback
IsCheckBoxDeleteCheck
SetCheckBoxDeleteCheck
isCheck
add_Click
labelTitle_Click
buttonDone_Click
labelDate_Click
buttonAddNote_Click
buttonDeleteNote_Click
buttonModifyNote_Click
buttonBack_Click
NoteItem_Click
buttonFormat_Click
flowLayoutPanelNoteList_Click
buttonModify_Click
add_DoubleClick
labelTitle_DoubleClick
labelDate_DoubleClick
NoteItem_DoubleClick
add_NoteItemDoubleClick
remove_NoteItemDoubleClick
NoteItem_NoteItemDoubleClick
add_NoteItemClick
remove_NoteItemClick
NoteItem_NoteItemClick
PerformClick
set_Cancel
System.ComponentModel
FlowLayoutPanel
GetPixel
set_AutoScroll
System.Xml
ScrollableControl
ContainerControl
UserControl
BotFactoryImpl
FileStream
Program
get_Item
set_Item
AddNoteItem
focusingNoteItem
ChangeBackColorNoteItem
System
ShowNoteForm
add_BackToFirstForm
remove_BackToFirstForm
NoteForm_BackToFirstForm
resourceMan
set_TextAlign
set_Margin
set_Icon
MessageBoxIcon
Application
set_Location
System.Configuration
System.Globalization
System.Xml.Serialization
System.Reflection
ControlCollection
ArrangedElementCollection
set_StartPosition
FormStartPosition
Disposition
Exception
Button
button
CultureInfo
Bitmap
MyNoteApp
System.Linq
InvokeMember
labelNumber
sender
Binder
get_ResourceManager
ComponentResourceManager
noteManager
NoteListManager
FormClosedEventHandler
FormClosingEventHandler
ControlEventHandler
System.CodeDom.Compiler
IContainer
get_KeyProper
XmlWriter
XmlSerializer
set_BackColor
set_UseVisualStyleBackColor
set_Cursor
ColorTranslator
IEnumerator
GetEnumerator
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
MyNoteApp.NoteItem.resources
MyNoteApp.NoteForm.resources
MyNoteApp.Properties.Resources.resources
MyNoteApp.FormNoteList.resources
DebuggingModes
MyNoteApp.Properties
EnableVisualStyles
GetTypes
BindingFlags
Settings
FormClosedEventArgs
FormClosingEventArgs
CancelEventArgs
ControlEventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
System.Collections
MessageBoxButtons
Cursors
FileAccess
MutexRights
X509Constants
components
RemoveAt
ElementAt
Concat
buttonFormat
GetObject
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
ParallelLoopResult
ContentAlignment
InitializeComponent
get_Current
get_Content
set_Content
get_FontContent
set_FontContent
textBoxContent
content
get_Font
set_Font
get_Count
TrimStart
get_DataList
set_DataList
dataList
labelNoteList
flowLayoutPanelNoteList
FormNoteList
System.Windows.Forms.Layout
SuspendLayout
set_BackgroundImageLayout
ResumeLayout
PerformLayout
MoveNext
get_Text
set_Text
get_Now
set_TabIndex
MessageBox
CheckBox
TextBox
buttonModify
get_Assembly
set_ReadOnly
isReadOnly
SetTextBoxReadOnly
op_Inequality
WrapNonExceptionThrows
MyNoteApp
Copyright
2020
$939b6d4f-6a2f-43ef-82f6-56e424585645
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.7.0.0
640, 670
#Times New Roman, 13.8pt, style=Bold
Times New Roman, 12pt
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
~n !YR
+++,//
JxnNW
^gf_Zo
,!}R&*
UUU)gggAgggCgggCgggCgggCgggCgggCgggB\\\1"""
^^^5===
qqqF<<<
lllG>>>
qqqG===
kkkG>>>
qqqG>>>
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD0~
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^t
0I0`ba
NGx2!@5
]V};hR}(k
kv.TmG
?!g.E{x
xp\?Eg
&A;_`ry
ia|c y
J04%yK
7)T#i5
rlnQw
2ttDQZ
gRE'-}
\Nk5B1
Izhg-[
3v)M#n
QJCi <
W=Q+Q7F7
r'!c<O
:"S:_3
R87oqxa
+dq&wH
gIGQZ<
r&yHA29
\}DJt5h
nY$.<G
*{2^;kt
Br/J"y
CH(~u|
VqsZw"
_C{cJ-
K-K~K:
SOTOTMP'
(S|vhKX
N[":>L
{s3/vm
yrF:ip
#Tvu$z
`J$EyN
^K$N&6t
L5G_O<sM
c+ QG2
Yt)%YY
:t,t4Y
t"c+a6
)so6l7
eNE_+s
|@\l($
(;)]t/:
76pD(|?
$[xbx'
TDATPC
YFq)P~
VYH*J
^tl3J25
{xv9IC
ZtvNko_
=rVdy
rib#_Y
K\^HS%+
YPs"|G
J^-Wew
$67FojtI
K&{QMg
$%"J$~
sz5pfq
~^-\<W5
>\_;On
Y`-QSE
?;T(?=
}/H}Xh
Ds`ExC
\~V_sk
M]*16`
sa>a8s
{X=2{R
7u2mQY
_?u6=2s,
Z.7j}:
Cr/MOsD
Q:IcX&a
d5Q~H.NCT
g'|Vkw^
M.YGbZ
t}v#ct.P
h\aRL=NR
`DI E)P
iICfAL
e;U-n&X_
cK> U1
"@Q!fV
L(>S1Y
A.>B??
1Qz:ob
yQ_Gu]
^*&R1N
t8\wy-
dGfXxb(
V$r+ Q
:3}Wm:|
5k{l&]@C
|PZ9MAI
sp0a E
a,D-Y)I4
l-S`oGL
4J;c1P
(],; 5|
B @($*m
nS?sL/
$G572$3?l
zY:rx
}|R}Bn
3zVzYm
iNnp{Lr
_#G.[q
I{SPvA5
Fs26ft
xW!'%[
-L: U~
$%X)m'
o1RW5f@
yt[F =
_W<m$$
Y`r.vo[AZ
(5;]Z?
\;,(v
;h"j6xo
9Fyc/+
E]k\9W
uybTl,
S!)}S)
FWYi'O
"/[^>Ov
,F9C$b,?
QCl J,
AA]7JP
$iT4_(E
`[r36
/ME*%c
"jwE8{]
[#>|]f
0,0,DB
w,tq|y
h6\m{]
o]*}"\F
e>{RL.
Um6i_a
s`vGc]
G]%fyvJt
'~ZNw^M
}m9S4C
o*n^Bgq
.E}BOQ
O_@q'_
a)}vwMx
pARC?>V
^lt~1rb
?96-tv
u2>3&Ok
g}ujr8
f~[5wr
Q0m!J<55j<}
i8w5Gl
VaLOCb
U-_>T(I
7we<yi*
?fu}0:
0-*P,Q
8q"(D/
A$iSI%
r>r^(tSC
o(,:"[
|+^/nd
=_s8?r
|/mk<i=
4mLcmW
H/2t\7*
oYnj#/]X
q!)3jq
r;Zo>lY|,
nc[)N.
Lz.oC_
/&GJZ/
oQ=y$i
9Cq{u7
D}Kyd_p
4C:>E&R
x>,9=Z
E]aoj6
{s.%Hl
8s5iF@
#X 0J`
`_$mr#
9ChdO.
*V%K+!&
VHRtuV|
>0<yJ,Ak
tER3%w
@cW#n<E2A1G
(l[SHO
w'Tvm9
s40qTP
Zf5tUC
8P<p~V
10~M2b
"D!nv>
$T@o<J
/?G2#/
*X'LSe
x%XJ^>
nUFcV
:&R^ai
Hs9hpg{_^
?~:FL9p
vk!Y^vM
/Uz=5`
(|d,Y0_
zTW7Sy
$cGc5x
PM=;uw
ObE\5>
$bXY&@oE
<Xv/61
y `)jM]
h(U%i;
|[#H_7h
t0p;rl
wNoO0:
A&[3ueL
6{`'$`
mdgjIp
$]RD2:
/+pQngX
#`&/B0?
j=gx$
+?U$vxl
UR*7'2
:'[Fk>
g}~}-g
Aic?*(
>^[r
6X4a>
enF__
;-j-|$
LCMcTB
\VKm_U[
:&uG=9
D\Cti]
E?X?";
e~nm'^N
;`=O!t@
Wa%35G
aj(0:`X
0rTGL!@
W+pe<A`
".'] Z
ubMVz{
}%!/}Q
'xWWB]t
)rqJe/
{B3?^s
yb@Edx
*qIyrD
7Z"+n2
dqW~oS
?V&K6{
~f^*DL
9T.ad^
ddca_
ZB0:is
VtIvlW
l8!$rb
2k?EZ
eE2g-=
qK$^Tk
&A6K~3
+)A1'c
E~nrXj
;)DrMZ
\If/*wQ
993}l
*B78"x
xzjK&g
y,9A@7T
*'UWSO
7NejoJB
C$zm29
+Ai7X+
W+oHOm
gsyC[1
=Lx6~;
].(R6s
=\mv$A
B.Ae*v
=@/4pt*
Pf}@M
|9)QK/
q1lj-tn
P[Z8{1
/wZvs5]N
KX^L:|
TZBR@X
u%O2wD
u@$P%@
BH~ksY
F.nj`S
FW?#x$
OeJk?|
ad7FE5)
r`lF:m
qW[WcJ H
{,Vf\)R@(
6Uy=TLcc
Okzylzz
rpzF.p
^gU`7F
Q+S'zo<
E61F%Ba%/
5+`q_g
1p~2jOc
h^5i@A
8Q^[<Q*
L'<?X3
o*[voi
&pFysd
\znd),
6>[|o\
fz{]k
JNZ7o
yeYk&=
fsQH0A\
AA)T1D
V!Vbc
h{dsT4!
z<.L|>{"d
6IZAt|
rz#TA+!
{Vv`".
o2?2VA
lxmg*NI
Ehh9/R
9:A(w(
,Y0l\/
Tde#^_O?[
=9I9h*
rJlF!*H
Uh6Vh9
0-GeD,
[x-rz}
>vI\9,p
dK.M?v
>KdGBwa'
p(ZKE#
>~[/P~
D:q$lM
H7v]H)
<rKEL7
7j(!C7
Eb495zD
2]Yk;]
Q=)t7
("*b/(""( X
kO {s-p
Pw#_)X-\
E/E5"YO
{~78~G
7[MmDr!
_Uo%_Y
##$G%@%
7GDOf/F
z{fOL\
PHo0B:
->T#];
?X4i_3
C!$C6q@~
]ZkQX4
W:XZXy
fn0B0hP
V%;X#Z+
!9X]v_$
09clCkbE
^Y@u2+`
_\5W[WY
%hcoETa
i-|z>;g
vdLf]/
V&P#G#
{ (R C
3V+|\j
tQoNe2
Jypd=|
]HsJ[T
kRBlIM
/l"~.et
&ny%n;
uT}9y2.
ek}km,7
LT@2kkPz
S_YINgZL
3eJd3/.F_
TK_o?y
0!UV}9
n}3S9_
gX$kip
(8[esy
(je~}grw
@9H&V,S
?z(9gQ
Mj.(a
C|ie.%u
5("^e#
bp!<Q,
?-h|<H
394Z;A
y*2!!6a
j0,Oru
{Z;k'Mh
C!+Arl
>&.%,f
qQ+<qT8fb
>(un2Z-
p:'rmM
|+g^+U;
mA(VyD;
5N~8x4
eKtFu
-y2Jc:K
QtHD}{
Z,C@Mgg
.~`c7=
9DNuT)S
PoP{op
+SqWpe
}f{iI4
@M`}EP
c<fbBO1
%6J$B9
HxsMvT
t08S!m/IX
1[K/a?
!FZ9o'`
];d;.I
5N6aww
q,<L4=
(:'NHz5
2lu5.9
[A@D
J1&g>d
1d[s9s
V>j|:O
DY'[d5
Ruw43T
l#eqf&
SQtAN,J.5L
?x)T4f
JR~UjL2
I7E.|sD
cH;qnC
7zSN)O0
0QT1X/
Gf5O9<
qdcOSrt
G\EA?_
Xyk34S
M)-/,sx
:1ak}m
0l`NER>
IJd![!
v_$59AK
47_[3wK
?c9KJB
3Wf%Ue
_8tRM4,
Va/9svs
4\:xfG#
,YLPTuY
7]u'l#,wXv
\vojCR
W(X5hM0g
s.7Qgj
c1\\D
1n3gVq
xayvWHKW
^T_3iSrF
]'zd_%F
2"S#Z-]-R3Z+a
6E/r25
;F#87R
z7g8t4V:
4]y&J,
]_ovP&
5n([5R
Qs;!_6V5
,RNJ}?
P0d5o5
PzDK_M
4;,D!A
i,rtht
>f5;@w
u,L1TF
e^u\6a
:<8+K
zG2AT&Q
L^%9?n
j"3H4=
QLsDqS
l(l9t}
Bo8&d{
pp3_ua
u"sCtKr
i~mZM9W
3c[INgVF
{CO#aNO5
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
K,IDATx^
sVWUWWUW
otA~q
Z%9d+'n
tTGGyr
g9ub+>
r*]\G3u
1aNr->
i#qrgx
C9eO
<7x6?
=#d/q8
9+;:+d_
O!On#O
';_D?m
~'D\uf
k} ff{|
}kS}0v
=~ve{>|
OcO)7(
7NOx~<
5{Vo>9
V6>7}q
+|=SN
>'<}Nx
~cM)O(
SGO}}Uw
}vz&Onb}r
O/sq1
AyY=>6
kpkjk`8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app" />
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
<applicationRequestMinimum>
<PermissionSet class="System.Security.PermissionSet" version="1" Unrestricted="true" ID="Custom" SameSite="site" />
<defaultAssemblyRequest permissionSetReference="Custom" />
</applicationRequestMinimum>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
4B657950726F706572
6D6156537847526A
data.xml
Untitled
ghi ch
Times New Roman
labelNoteList
Danh s
ch ghi ch
buttonAddNote
buttonModifyNote
flowLayoutPanelNoteList
labelNumber
0 ghi ch
buttonDeleteNote
buttonDone
SelectorX
#WinHostsManager
FormNoteList
MyNoteApp
ToWin32
u ghi ch
buttonBack
labelBack
textBoxTitle
textBoxContent
buttonFormat
Format
buttonModify
labelDateCreated
labelDateModified
$this.Icon
NoteForm
labelTitle
label1
labelDate
label2
checkBoxDelete
NoteItem
MyNoteApp.Properties.Resources
KeyProper
FontTitle
FontContent
$this.Icon
KeyProper
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
MyNoteApp
FileVersion
1.0.0.0
InternalName
Zo.exe
LegalCopyright
Copyright
2020
LegalTrademarks
OriginalFilename
Zo.exe
ProductName
MyNoteApp
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.47334528
CMC Clean
CAT-QuickHeal Clean
McAfee PWS-FCUF!225D57C6CFE5
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.MSIL.Injuke.gen
K7AntiVirus Trojan ( 00589fe71 )
BitDefender Trojan.GenericKD.47334528
K7GW Trojan ( 00589fe71 )
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Kryptik.GAZ.gen!Eldorado
Symantec Trojan.Gen.9
ESET-NOD32 a variant of MSIL/Kryptik.ADJT
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Injuke.ezvr
Alibaba Trojan:MSIL/Injuke.fad9393d
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Undef.507392
Rising Clean
Ad-Aware Trojan.GenericKD.47334528
TACHYON Clean
Emsisoft Trojan.GenericKD.47334528 (B)
Comodo .UnclassifiedMalware@0
F-Secure Clean
DrWeb BackDoor.SpyBotNET.25
Zillya Clean
TrendMicro TrojanSpy.MSIL.NEGASTEAL.DYSHQAI
McAfee-GW-Edition PWS-FCUF!225D57C6CFE5
FireEye Generic.mg.225d57c6cfe5370d
Sophos Mal/Generic-S
Ikarus Trojan-Ransom.FileCrypter
GData Trojan.GenericKD.47334528
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Trojan.Generic.D2D24480
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.KA!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.FCUF.C4756449
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.47334528
MAX malware (ai score=100)
Malwarebytes Trojan.MalPack.PNG.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.MSIL.NEGASTEAL.DYSHQAI
Tencent Clean
Yandex Trojan.AvsArher.bToZAi
SentinelOne Clean
eGambit Clean
Fortinet MSIL/GenKryptik.FNAJ!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.