Static | ZeroBOX

PE Compile Time

2022-01-26 22:00:45

PE Imphash

32c5de998b5f069b26c94c8143b13c06

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001c000 0x00006400 7.98747953275
.sedata 0x0001e000 0x000bc000 0x000bb000 7.82583782109
.idata 0x000da000 0x00002000 0x00000200 4.2645920894
.rsrc 0x000dc000 0x0000e000 0x0000d600 4.24139932531
.sedata 0x000ea000 0x00002000 0x00002000 7.99336228802

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000e823c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000e86a4 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000e871c 0x000003c8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000e8ae4 0x00000a41 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

Imports

Library mscoree.dll:
0x4da197 _CorExeMain
Library MSVCRT.dll:
0x4da1a3 strncpy
Library IPHLPAPI.DLL:
0x4da1af GetInterfaceInfo
Library PSAPI.DLL:
0x4da1bb GetMappedFileNameW
Library KERNEL32.dll:
0x4da1c7 GetModuleFileNameW
Library USER32.dll:
0x4da1d3 GetWindow
Library ADVAPI32.dll:
0x4da1df RegDeleteKeyA
Library SHELL32.dll:
0x4da1eb SHGetFolderPathW

!This program cannot be run in DOS mode.
.sedata
.idata
.sedata
j,8HLA0
8oN|yL
YxkM=R`
eEpyNa
o5le2An
Lu)%;5
P+<#1e
'ny!7>
cqyd?"
b1WDvT
W8cGb/t
93%M!CX
$]z*W\K
3QVQ-`Z
P<?V(_O
s`v!]?
K#8y$?T
tws/o;
G}c3SC
g}/X*J
}%f|wbA
>UF#6vc\
,BBX1S
XRlqd$1}E&
|h2nvl
~a(z2 $D
*;0?Yd
md,$J\
2;bk`WP
<fh%aL
>\[rICg
9<cY2y
1!,5zV2
/`h."XIR
32"DD<
coC(A@pg
.-bA k|
y|((Zb
2faT"P
-FtAm
",g]om
@c/Qc`x$
HPIGxCb
K?MerZRc@
Vz\\}K
d8*!;%D
`6+vz
:/~]`d
K^q}O>Z
s\.0bg
@rLW<zW
]a<G7c
0EU`z@.0
szEewep
-*tGyb
psjP<+
ogoLSE_
EF#*)c
6I&-K`
aTur55yb
:/,f5yb
;L$,wv)L$,
Yy!I}:J
J9T?F\
7H|k>^
4$v\wD
Zb?F/h
er\div
/6}Mc
ck-~0
103*`f
?g(28c
#iFMK
/h(vS
nh:&}
m1%~^u
)<(jU%
,dxbHzU
++B{y:o
TEBLXyb
rhLsS
?XN b[
?ep4C/0I
rm|OhwrS
3"chK~
LhsVh:
j =}q3
pbdqps
pVI\$s
w^$%&-
Nls=]g*
FObGZ+
M5@)*1
8?F4d*
r'I&-+
#]E))/L
Ecrm|O
V{J/0;
GetModuleHandleA
GetProcessHeap
HeapCreate
ntdll.dll
RtlAllocateHeap
LoadLibraryExA
CreateFileW
GetFileSize
ReadFile
CloseHandle
VirtualProtect
GetTickCount
GetProcAddress
RtlFreeHeap
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DbgBreakPoint
DbgUserBreakPoint
DbgUiRemoteBreakin
kernel32.dll
NtQueryInformationThread
NtSetInformationThread
user32.dll
advapi32.dll
hid.dll
iphlpapi.dll
VirtualAlloc
VirtualFree
SetThreadAffinityMask
GetCurrentThread
ExitProcess
GetSystemDefaultLangID
GetSystemTime
SystemTimeToFileTime
WriteFile
GlobalAlloc
GlobalLock
GlobalUnlock
GetCurrentThreadId
GetExitCodeThread
OpenThread
TerminateThread
SuspendThread
MultiByteToWideChar
WideCharToMultiByte
IsWow64Process
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CheckRemoteDebuggerPresent
CreateThread
ResumeThread
GetThreadContext
SetThreadContext
mscoree.dll
mscorwks.dll
mscorsvr.dll
KernelBase.dll
mscoreei.dll
clr.dll
diasymreader.dll
SECheckProtection
SEGetAppStatus
SESetAppStatus
SEGetLicenseUserInfoW
SEGetLicenseTrialInfo
SEGetNumExecUsed
SEGetNumExecLeft
SESetNumExecUsed
SEGetExecTimeUsed
SEGetExecTimeLeft
SESetExecTime
SEGetTotalExecTimeUsed
SEGetTotalExecTimeLeft
SESetTotalExecTime
SEGetNumDaysUsed
SEGetNumDaysLeft
SECheckHardwareID
SECheckExpDate
SECheckExecTime
SECheckTotalExecTime
SECheckCountryID
SEGetHardwareIDW
SECheckLicenseFileW
SEGetLicenseHash
SENotifyLicenseBanned
SEResetTrial
SEGetProtectionDate
SEAddMemoryGuard
SEDelMemoryGuard
CreateFileMappingW
MapViewOfFile
MapViewOfFileEx
UnmapViewOfFile
LoadLibraryExW
LoadLibraryA
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
6bad allocation
_except_handler3
MSVCRT.dll
GetInterfaceInfo
IPHLPAPI.DLL
??3@YAXPAX@Z
strncpy
wcsrchr
??2@YAPAXI@Z
strncat
_wcsicmp
_wcsnicmp
__dllonexit
_onexit
_initterm
malloc
_adjust_fdiv
GetMappedFileNameW
PSAPI.DLL
DeviceIoControl
DeleteCriticalSection
GetModuleFileNameW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleHandleExA
LoadLibraryExW
MapViewOfFileEx
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
wsprintfW
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
MessageBoxW
FindWindowA
GetDesktopWindow
GetClassNameA
GetWindow
USER32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegDeleteKeyA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
~IqSpQf
\$ fRf
103*Ef
strncpy
_onexit
wcsrchr
MSVCRT.dll
??2@YAPAXI@Z
GetInterfaceInfo
IPHLPAPI.DLL
_except_handler3
MSVCRT.dll
??3@YAXPAX@Z
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
__dllonexit
MSVCRT.dll
MSVCRT.dll
_adjust_fdiv
MSVCRT.dll
_initterm
strncat
MSVCRT.dll
malloc
MSVCRT.dll
??2@YAPAXI@Z
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
_wcsicmp
MSVCRT.dll
_wcsnicmp
MSVCRT.dll
_initterm
MSVCRT.dll
__dllonexit
PSAPI.DLL
GetMappedFileNameW
PSAPI.DLL
GetMappedFileNameW
_wcsnicmp
kWX-z7N
GetWindow
KERNEL32.dll
KERNEL32.dll
QueryDosDeviceW
MSVCRT.dll
KERNEL32.dll
GetModuleFileNameW
KERNEL32.dll
UnmapViewOfFile
USER32.dll
USER32.dll
GetClassNameA
MSVCRT.dll
USER32.dll
OpenClipboard
GetLogicalDriveStringsW
MSVCRT.dll
X-3x>
USER32.dll
EmptyClipboard
USER32.dll
SetClipboardData
USER32.dll
MapViewOfFileEx
KERNEL32.dll
CloseClipboard
KERNEL32.dll
MapViewOfFile
KERNEL32.dll
CreateFileMappingW
wsprintfW
USER32.dll
USER32.dll
MessageBoxW
strncat
wcsrchr
DeleteCriticalSection
KERNEL32.dll
GetModuleHandleExA
MSVCRT.dll
KERNEL32.dll
strncpy
MSVCRT.dll
KERNEL32.dll
LoadLibraryExW
_wcsicmp
ADVAPI32.dll
RegDeleteKeyA
wsprintfW
RegCreateKeyExA
ADVAPI32.dll
ADVAPI32.dll
RegSetValueExA
ADVAPI32.dll
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
RegOpenKeyExA
RegQueryValueExA
KERNEL32.dll
DeviceIoControl
MSVCRT.dll
USER32.dll
USER32.dll
MessageBoxW
SHELL32.dll
SHGetFolderPathW
MSVCRT.dll
USER32.dll
GetDesktopWindow
USER32.dll
FindWindowA
USER32.dll
FindWindowA
FindWindowA
USER32.dll
FindWindowA
USER32.dll
d$ aRf
3?2MzGl00JnyX
DRt\{/}
<o`.AO
8#z,8!
]fHuDf
&fCz(f
Om|OWQ
![O.SZP
/6!`Pf
w6!`WQ
K9N2-<
4'NWGc
`\(OCA,0
|$..4Q
DR4kpL
dR1$|\
d$$VSf
FC8`Stq*q
;F#z_a
_a0;;$
c>)-0%
r:v,,4
}76ZF%>@-0
%;&QIQ
vL,mZCU
Cf@p$A
01FlvA
9hS/|[)
Z`h,f(
n%ov\3:
?w2XA
.K{4yxaq
=97FzZ
-~+m|O
l\Tw+C
5A&@rd
B[_!%{
7Coy&Z
_pzibD
qR8-jz9
@jMx@)
p^/{n(
hSfCJB
qpsjo
IL/mF#r
zY8+$
vCw_yX
s"f!b#
_9;%fo
pD,lF
#9nPj}GYl6
!?w(PH
]a"ova
i,^`hEY
Fjq!k;
/;|:`|:
5Q~Cg4
q(1U#c
>Fj9A,
#tW_HP
h'TFsR
2s:BT/U
5ova%ks5
JY2>wc
UgiU!
IG`xnT1
D"C>PK
?u}?G2
^!Ne@
TBcFq
c&{'$#
%rm|O`#
dIvZMC
@b%|+aS
z :23i
1>7_~!{
d1A/04
xJjt&5$WP
~o5y1pN1
?vb}~~o+N
fz?~x
|o"r<g[~Qi
|oZ>Bx-
Nt-_m{
i{8/us
!:>~B
LCQ1Bi
4_wk5|
$>8B8a
HW_Sbj<
\q~&>j
\J4Dv5
,!/6!`
8K7yva
-!q#*_
UgTM|:
qWv\1p
,kUVrC
kV`j2s|
pZ0Ci4'
\IWwbEK
t{<2b
QGwb[U
$}^qsM
ys{S1
d$$afUf
d(4\Gqpsj
M}:3\7
,&P-4I3b
cZ}EP"
&L7<Ii
s;:Yji$L
rxtlHp
0*L8CF
D%L%g}.
_%L5(
=*Lt6_
-L)-tF
|^Q+LV&
e8*LT2,
&Ls,`#5#
y+`%LX
du/c.L
mpB*LN
I*L6N|
v+L#.M
_$L"r]}
4E*Lx!
DOjO'L
*LQf2c
R.]k&L
$TYM'LCs
d&LU1y
X nN*L
\.%'LG
G+Lw@h
-Lh'TFb
9s%Li5
;cEQD*L
/6!|Xzb
;eCb5F
#RY64b
;"M7{g4f
qWv\Kl
M{;M-9
^u090P
=~0)xhY
>8/1j
$:Q?TM
<Vpj"-
"f*6Py
,$SE.^V
~@$+>c%>cL
5O];5`
Ztn&1;r
4j :4
}-9SMxj^x
.HBse6v
B6PJupR
~DG9SJ
byJwh=
@`cKegS
;q@L5_
FNai+bi
>k9jud
.5K=p~
T\h`hQY
cf'.2q
BuBKR#w
z!{4<st
(Se?$W
MT4F4D
|GZ&xO
enevb2
_a`qpsj
iHqW]a
#s^!u|
>j<q7L
fCs/r-<
z_") 9
kr4u&Z7'
QV,,LfV
frm|Of
=J}$|u
;^]<5>;n
U;"R"~"
M~}7AW"
S"X,0^
BfP"/I*
p~LtU"
2Dre[R"R
t1/R"6
Q"=~0)
~fR"0Q
\d`vR"E0
T"[~
iIfS"H@1
4nR"W_c
Q"cHh'
U"S.{~
P"@>Yr
U"xfw-
shfR"?
>U"#M?N
d(X%<&
CH~)LHc#
hT6d#j0MU
Ed#@WN
(T@d#g
k ) :Gc#
b#1D][q
c^mfd#/,
od#$9|
e#_-g]
Wy<d#r
0cOCc#
8"L/c#gB
ZETd#(
HP[d#A
k#$c#KN
dUpwc#
+wi#5N
XoWTc#
-"XJG<
=2+!la:
[H)UV:
#jZpsU@
>z'J"A
l%@R:co
:Hr*Cn
gK; Vi
4^#k>/
O`xDkT
u!vnV
&U\:3b
GtM,up
Cf|@.J
?_Vay*H!
GG f32
_Z"dRbo
vLM'1k
`?XjF(;
^vC$<3
}SckgI
)RYe!m
ej`oxbCH
#at_.)*
h&Uma^[z
H2(#Cl
-c^Acd
rm|O^s
"sK()}j
x!yVp3
a:&-Au
gMJ":.
h*6m<C5
W&.e4z
D?G08#
pf8x, 7
Xr.Dox
`*r5Ai
}CJN04
T+}P B
yHOt3b
)}x[}u
0CO=#Z
;5dbH
9Q0zqe
ms&?8
?@#TixF
%Jp.)x
o3*Ex$
[sdaSk
+gzFNJ
x1)e&^
HX[vekq
zHd;Sml
ntRsaZE
{RT;<q
ho`ZQEn
w^Jquf
Gf.)!>
{RT$-{
-V]K%5(|i
6IUC}L
Gh4xa:
103*!V
~p_*MT
VA@o8=
.l^|w:
<s.hppP
)Hh7pP
s!|urWevbc
rCf6Tb
zb(6)3
U@lEh).
5$WVWW
*rm|OV
IP"j`*
a2{IWi
>kS"aA
z8;V(V
n3~a;
O; a3x0
/R>2I^
a=~0)K
?0B( a
3I&By$#
6LS%$a
j|)bGT
0t; a[
a5y1pKj@
jova*S
8c[*~yz
0gJR= fn
;rj9@.
}Lh1:a:
`Xz{^-
5$hh5a:
szDJ`*
I&-47b
`<k+Xd
(GWbmJ
fRfJyWx;c
;%_fxY
a>?i|ph"
RPU7Y6
W^SPU*
;)f6+k
!D2]5~
LbM,qn(7~bE
e03*E]
<n*VKJ
}x;N]U8KW
"U\):Y*
[%[}~y
Al?JK(RtW!u
/6!`h%
`*")C
(|?*RY
+Y*k.l6
4j-9X5<
d,rzW^
;+d2-f1Xx
+6F8ea""
* wl.(
UZj=ea
d$ ;XPfRf
;HPfVfQ
!lw]aG
:SQ0=*=
9'"''=
/x\_][
}LhQ|Y
(xI7|!f
K$9h?b
UZO<yb;
i]wq5Q
^IcNs$
`:8?9R:%
_*[8?<
rm|OoZ
c%4;Mz2
k~DE"L
4'NhRgY
n<.Qh6
fYy<A}%
#B:ACy:%
!9ark"
Jw=)'.
*"M*TUU$+<
_17918R
{O-8RhL
[z`ix>R
Gp7RS#
d)-&9R
3*u8R|
`O%)8R
reI{=R
8RA_ _r
C8Rj0MUm
:RX,0^)
8Rph@8~
?Lv}[7R
n/8R/%Rk
4-9RuI$Ci
e(yqNO2\
(2v=b{
w~\T:%
`#tlIJ-
F>0>i,j
rm|Oh:3Y
c&w~ L`*t7
tQ{EXLP5
rOVq3b
b18\3b
.5;*X*
F:%|.:
+`V6)1
UuO# +
rIJ5be_5
,hS{|Y
B#<1m0
K1Dpd_
"M*TUA
FN2-<G
vM[=G=
\qideHr
ih{v`:
10eW}Za
Lo$$*G
}xb{zU
'~07W^
}P_Ja+
J],3B]
wxbp[u1
bcj,rz
r:Aj\2%
N7>i)2
SV^Ru)
)Hh+c_
Y`:3:$
/6!p s
|I-7g
pBbfZ}
34zW^
rmtB|O
.>5aLI
N%$Y~d
qxrN_*OV
Ch28`:
,103*hA
&lt6!go
2/?*glTc
5kr,;`:
nM|%+
L~9dwc
03*EdV
ipj{W*G$+b@
}xEgJl
J,`:l/BNI
ADU%}Z
2$O,3|c
PBs{Ida
&J]:23
}Lh,!`:
u8!aIeW
`g12_*
rm|l9%
g)#z<0S
Y`B(_*&K
%Cp$:-
/fCJE3b
'lIPxd
IAJ~6X
cL:>[L
bT~|xBg
6i_j`e8
<7Jkhe
qm3$&g;
ii,j9@1c
^*^!r8
e8fppv
4.bv+f
L_Qsk.R
stoLS[d
+BKL)S
NfZWTs
Uwb7$W
.]d73b
aLf"zM
|KF)KC '_b
$b?F\d
S<'~0<%
2%$E){
X6!`YIs
u7)4"?
|Yl=e{f
Hdzp'h
$=\`rE
R d {,
X%wL>+
7hv_X
103*cN
0%c&]O
7HIk>M
J4*%l|
!Z$'\b#
&_%0r^
(K6|>|
aFi1<0t^
vpV*EL
EfqXGD`i
.nu5qV*
?\`EXf
];}RyA
@'7%|%ny
qpsji1Ds
Bem<C
_aqnyX
=D:VV*
4_<Cl*
Ih];X
FhCsS
4'Nh6b
08#RZEM
ZC '5@
AV*KR
)ow9d'xc
rm|OhN
;V*wT[#~
vb0103
VB2m"'
cxm3mn
^U{/V~
J_#A((
Kffdet
EyGrGn
.^D0#T
SH:$v,3
t _q;t
|?RS0Z
MU$+#k
aW)i#5ii
"\_~~I
_aS6!S
{L)0f3b
(H^#fZ
r[!upSuv
WM_Ug
RhZa_:
crTlT~L
E>< g7
1Za#)9,
8F"ZDC
u:?)J#
fcx@#
(Nuw/8
Tv~[b<b
*V9>wHwb
EF03*E
ryCk^*
t&2iFMXd
rh\U_:
&U(nyX
e.Ly-H
%/beYz
'z+6Wh;
e-W&zuXzD!(
3Q~2]&
nW{f!C
aL_f~;_:v9
V t7"F
nbXLB2
03*E9@
Fi]W<7(-t
T[K6,2
V>mt}\
)`=D'"
q,' }E0
Y9%\V
K&(/Sq
m/6#Z-
<I,]|Q
|UwHT&39
-oQc[P
<Ddygle)
yX1d2d
U<4%C7
<r*)L2
_wg)ow9d'
K(U*u8
q4GZaGf95
LEMi+gZ
qpF[yT
/6!`h
k=]as]
f8x,>[r
SF{m|!
<T]>zu
w4G(%+R
k/id:n
[g*hApw1B
\~AM\
~f*xtq
%\o>`[8
uh/%m0
Bf8%&yO
wd^Li+
YGDEHc
;;U3_xY"
Vu 3B[
K'/IC@v
Bm) C$
F.Y+fPf
_zybs^x4
zu#sk?
/MC\Q<2
^*@G\6
.9cxQ,
103heb[
KBhSr:
$)[[ fQf
4'Nq@O
GD7Yog
_h)Q[
/6!`D3
snQsPW
<CF|T*#*
3wT*] 3
)TUwF>!W!KR
BlOzr
Xk_hl)]
QI,b,V]
/{rm|Op
`TyBApl
o&]6Xz
*% (4z
(y+bMqZ
BUd\3l
;<^V9o9c
^i]o]fg
gcf\ve
l>~th<
qpsjS"
LCf.9{l-
5GT*_"
3pi$Ym
Za:ET*
(wCj";
w)^[c5UYKWC
cL)0{3b
oj7hlL]
w^AqpC
ck^:@GC
|5nq2
q7p5%T
D$ 0v^:
HIkf^AwA
b>`.*-#=
No*c }
~k!a4y
2hBj^:
p?FW3b
ipWcT*&
fCmh2T
FTf;Xm
Gh"g^:
NF)_)SZ(R
]er58}
hckT\G
^*b%8!(
7%n1Dls
PW]`^:O
Rrzz6z
;hI\^:
e,03*ED
qn]*NU
J[`BGybT
[*1)3b
rm|O|k
D^m}w72
K\jLV7
Fp?"vn
COV4g]*
5,cryb
&w~|N^:K
@{Wn`;w
PWIc]*
_2?zf;
wjL{xH
+P23=,
}tI%ybu
gnL\]*
wo2>)TF
;dHq-)
.&>9TM
S*s6IP:"-
khU>^:
4m,E~Ip|
4krL:^:D
tmY55"
U]ia07&3b
,103*@
GGWy5)C
3X@\;v
<ww]$BlM
@`md5`
CP'ch
NN;`+f
Bw_C]
~v#Q6N
/6!)\r
BU}@S$
,0$ilK
AHORS*y<
CUnO_Z%
mM$V,n
; f%~
1146XB
@+3'IR
'dA=|20
{u(0!>
R+)k>3
N#h"XN
s2J]EH
9_Iyw|
bqVYu?
Cwe6s1`v
.X(uj+
$mscoree.dll
_CorExeMain
=PSAPI.DLL
MSVCRT.dll
USER32.dll
4IPHLPAPI.DLL
KERNEL32.dll
=ADVAPI32.dll
SHELL32.dll
Z103*f
Safengine Shielden v2.3.7.0
D$$f[f
103*f]
:mscoree.dll
MSVCRT.dll
IPHLPAPI.DLL
PSAPI.DLL
KERNEL32.dll
USER32.dll
ADVAPI32.dll
SHELL32.dll
_CorExeMain
strncpy
GetInterfaceInfo
GetMappedFileNameW
GetModuleFileNameW
GetWindow
RegDeleteKeyA
SHGetFolderPathW
cIDATx
"]|NLb
Fqb ygt
'k-7=s
&4/&ro
#vn,ua
E,6]r)F
Cb#Fz}c
hEdGXX
{voGve
\cY"'
^,~)I
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.7.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Microsoft Corporation
FileDescription
FileVersion
6.2.17763.1697
InternalName
REGEDIT
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
REGEDIT
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.2.17763.1697
Assembly Version
6.2.17763.1697
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Hacktool.Win32.Generic.mzvW
tehtris Clean
ClamAV Clean
FireEye Generic.mg.3578aaa113d7683b
CAT-QuickHeal Clean
McAfee RDN/Generic.grp
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.48302227
K7GW Trojan ( 00481e081 )
K7AntiVirus Trojan ( 00481e081 )
Baidu Clean
VirIT Clean
Cyren W32/Patched.J.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.NoobyProtect.C
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Droma.aedp
Alibaba Trojan:Win32/Droma.6e463cd2
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.48302227
Rising Trojan.Generic@AI.99 (RDMK:HnWZroXS9+dGMXI9TuDqoA)
Ad-Aware Trojan.GenericKD.48302227
Emsisoft Trojan.GenericKD.48302227 (B)
Comodo TrojWare.Win32.Amtar.KNB@4wlm66
F-Secure Clean
DrWeb BackDoor.AsyncRATNET.1
Zillya Trojan.Droma.Win32.1651
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.cc
Trapmine malicious.high.ml.score
Sophos Mal/Generic-S
Ikarus PUA.NoobyProtect
GData Win32.Packed.NoobyProtect.B
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1248973
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Heur!.030100A1
Arcabit Trojan.Generic.D2E10893
ViRobot Clean
ZoneAlarm Trojan.Win32.Droma.aedp
Microsoft Trojan:Win32/Sabsik.TE.B!ml
TACHYON Clean
AhnLab-V3 Trojan/Win.Generic.R480150
Acronis Clean
ALYac Trojan.GenericKD.48302227
MAX malware (ai score=82)
VBA32 TScope.Malware-Cryptor.SB
Malwarebytes Malware.Heuristic.1003
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Droma.Ljki
Yandex Trojan.GenAsa!ZU9DiP7n6KA
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.140129947.susgen
Fortinet Riskware/Application
BitDefenderTheta Gen:NN.ZexaF.34742.0u0@amhLiRp
AVG Win32:Malware-gen
Cybereason malicious.0a1d80
Avast Win32:Malware-gen
No IRMA results available.