Static | ZeroBOX

PE Compile Time

2089-08-31 08:20:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00045c14 0x00045e00 6.99285918934
.rsrc 0x00048000 0x00049f80 0x0004a000 6.06468883006
.reloc 0x00092000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00090e10 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00090eb0 0x000003ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009125c 0x00000d21 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
|~&<nM
no@F-$
peQkEn
mv _eQ
RQf|ja
Bu(/KP9o"
D$:>w\
p&R:VBo
0vtW9W
kETK-6
>:.q3\I
RMpWke
}*)nvS
RPRGt<
u4v#sF
NKbxA\
L(m_DRam\
X"BPHr
\v#R2X
:Lc.1j
\z|mln
]<KW3x
{bhXk6
}N%[?=
}-5"/'
HF_*q$
woPIrH
t1mw#PV[
ghHib`
AN5,|N<
wTYMnv
yht7Ev[
-wNH*B
XAN&Y<
e8E/DW
um:*o
,t(t9x
Q~Q^s%
sNxsS?
+93=(_
3*K`j2
DNvsA^
*<P8*p
!J+Ncy
j>x4xy
;,HTIK
H/zKR@s
%fI@@YN
v6L.2i
>}t(f1
.P]DN0>
qJ["zM
,L<t_N4
LOo*$
_"<\Jrv
SO4-!j
/7C8,*
LMLfoz
rU7|,O
Yaceos
j$?N4}|y
J*cb~t5N
)TCt'N
W9Jlk-
5F{G+x
r?,'klkt
QT9`yl
>3Vwx}
U$! f<
vUrxHd
H@:(8H
t3e<Zh
&Fo,(Jw^
gx"MGU
^V?;@X
5b3o(G8
u=Ntr[
@3{sQ`
wwJps]
VgcbEb
qzGT-J
.k u}h
C%k:Vn
{ap$tL
8+?LE'I
K#a}b4h
_Mc>JCN
Pb:jwm
=I||"0
Vd]oaQ
?Gcvgu
%k`T8J
i~&`$w
&B.*Qc'?
J)GV\94/
1k()y^
N"(mE\
1ls;Re
/Aj%B^
qLt@^_O!_
t"E!&!^q
=d|)G#
tDc7\s
C{s;}-
4JH&1+
oY<A|hI
X+X?X8Mq
.Rb!,y
h-U<]kD#}
#H?SEU
o[?^Ds
58Gzz:
:Fsm<40w
H%oyrW
v&bv2)b
C]Ol`%
#lj~bq
f:Sz
W'}rFi.5
=^dY4po$
59aMyYP
Y=dzma\
+ZE..G;
AEIp]5
>m6mZM
Idzs[b$
eY?4cp
d\c3mV
(x^~:}
t(lG;l
$.Wr5&
i2+^4C
l$Q{SY
_0itFg
,%g`h.
fvCH[.
*ijZ/E&
FYUTZB%u
|7 V)D%t
>,PX+t
_J3\ #
t|>T]*
E|( PO
$i6WF.
eTc )Q
CZ[v)c
|z~W&a
_gM07,{
X8$SrEoU?M
(v'/i
$CH.Vf
Dsql+
NboI'f
lohB S.
p)PX*\`
;mF;ePtGy
>`+49wH
|AevaQ
`e*>>v"
MDaY b
a68VWK*R
(5-"8(
DG9Ie`Z
eox2gKP
C`>hqzH
LT+3J9
V`TF0d
c5A<yE
=n.Q|R
95$~+
@V[-vX7w|
($t8H(
q\:{3Ub
L'k0vLq
~;[c(K#
yY`W2x
nH[<+
OT)zW;#
WWx7(
z%d<:X"
'3;]"o0
)+6`)\
} 84l$
`Z/61E
KjgIn&
N%0`z:
t*Iiv&
{"*TkY
~qH[S}
SMUAt6'
rC+P4D
lDbNhAjSk
Q3]h7f
/V" 8n
\;!V{L
%Sn]~7u
7z;l6r9
d*Lq[Gm
05C\;W
5!Tqf/
'6}75[
o4svhX
8DoFvwI
KCV9.U
K=Du]rutIL
9hI%&}
4jRC/l
^8i4*n
=h+c~/u_f#
z0QTgf@
:0?,K
Z&+$!p
2#zZ &
Z?_b`
XdP)Z p~\Qa8
V#=Z e
%TeeZ
?Z ck"
1Bja8C
KZ !Fl.a8t
um\a8U
;COj%&80
%vpZa8
-0P;%+
h,f%&8
ri'Z /fPga8?
:'Z *!
Tlia8~
O`5wZ
J/7Z 8D{
_bj2
_bY*
@sZ L1b
03)a8R
*8Z *Q
p3Z wF4
$TZ Dnq
Z j.XIa+
KW}Z !
WZ ;MI
,QmZ u
oFZa8@
|FZ 3o
rsZ FUC
Z 'H@na+
Z_bX
.&9p8R
)Z ;vB{a+
Aj &/EUa%
{*}Z 2
HoH_%&+
Y_cX*
] QU`Ja%
yZ I9P
:%sK
.(Sa89
^qZ iV
_Z SlF
'zBa8a
99sK
Q}YZ =
Z q=I,a8j
CZJa8y
6V3Za8R
j(Z 8aG
N\Za8z
^-F%&8
Z d*Qwa8y
nY"GZ k
fIva8y
~KZa8c
Z DZW0a8F
[Z !9O
Z lpjua+
t@n,Z P
4G<4Z a
WqeZ "]
8 pTQ,a%
R_i[%&
KY)-%+
I;4-%&
r2%&8F
AXu%&8<
ke4a8A
L[Za8w
o!q(
oNF%&8
6& SS+&
*Mw,Z QA
5-^*(
x$%&8u
z`j&(
Z ~|^ca8
@P@X(D
2JgF%+
% 3_AZ(
\p^;(
~#cO%&
)E%&8(
"q'9%&8k
*LuZa8D
J<.%%+
6EZa8L
V/8ya%
/Ffa8F
vgIZa8h
uv "%+
[ak%&8D
VMwTZ
%_u[Za8+
-=uk(
h'}~8
wae%&8k
FV0Za8:
~-?,%+
v4.0.30319
#Strings
poweroff.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
uh,2<ULpr(x)QQ#YcAg"~H(]
System.Windows.Forms
IContainer
System.ComponentModel
TextBox
EventArgs
Dispose
IDisposable
ComponentResourceManager
Control
<$i`kx5cw$Jf7PP%a]s5_E)g!
UserControl
ContainerControl
AppDomain
ResolveEventHandler
<>9__0_0
AssemblyName
List`1
System.Collections.Generic
RegistryKey
Microsoft.Win32
Environment
SpecialFolder
WebClient
System.Net
RemoteCertificateValidationCallback
System.Net.Security
SecurityProtocolType
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
ProcessStartInfo
System.Diagnostics
Process
ThreadStart
DirectoryInfo
<>9__8_0
X509Certificate
System.Security.Cryptography.X509Certificates
X509Chain
SslPolicyErrors
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
PaddingMode
CipherMode
ICryptoTransform
MemoryStream
CryptoStream
CryptoStreamMode
Encoding
System.Text
HttpResponseHeader
Delegate
WebRequest
WebResponse
Random
<>9__2_0
GetProcAddress
kernel32.dll
GetModuleHandle
GetCurrentProcess
IsWow64Process
StringBuilder
SearchOption
FileSystemInfo
BindingFlags
Binder
HttpWebRequest
DecompressionMethods
StreamReader
TextReader
715G<=oN23%wc0=ZObcO*Our"
RegexOptions
System.Text.RegularExpressions
hR:P!Pv,M{PWqIW! c"v-Sn]
ResourceManager
System.Resources
CultureInfo
System.Globalization
Settings
pwroff_B6LeYs4LznWeYW2E.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
poweroff
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
NeutralResourcesLanguageAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
SecurityCriticalAttribute
System.Security
SecuritySafeCriticalAttribute
TypeLibTypeAttribute
DispIdAttribute
TypeLibFuncAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
Newtonsoft.Json
JsonPropertyAttribute
NewtonsoftJson.Json
uh\,2<ULpr(x)QQ#YcAg"~H(\].resources
aJIwmMbLMvaaUGJDTSVWiAZzjVsXA
hR:P!Pv\,M{PWqIW! c"v-Sn\].resources
<$i`kx5cw$Jf7PP%a\]s5_E)g!.resources
715G<=oN23%wc0=ZObcO\*Our".resources
pwroff_B6LeYs4LznWeYW2E.Resources.Newtonsoft.Json.dll
String
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
ReadByte
get_Length
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetElementType
CreateInstance
Buffer
BlockCopy
get_UTF8
GetString
Intern
get_CurrentDomain
add_AssemblyResolve
get_FullName
get_Name
op_Equality
set_Name
System.Drawing
set_Size
set_TabIndex
set_Text
set_Location
set_ClientSize
Padding
set_Margin
EventHandler
add_TextChanged
get_Controls
ControlCollection
TextBoxBase
set_Multiline
SystemColors
get_ActiveCaption
set_BackColor
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_FormBorderStyle
FormBorderStyle
ResumeLayout
get_AliceBlue
set_ForeColor
PerformLayout
SuspendLayout
get_MediumTurquoise
Contains
GetExecutingAssembly
GetManifestResourceNames
GetManifestResourceStream
Registry
CurrentConfig
IEnumerable`1
ToArray
Exception
Enumerator
GetEnumerator
MoveNext
get_Current
Boolean
ThreadAbortException
CurrentUser
ToUpper
ToString
Substring
CreateSubKey
SetValue
NewGuid
OpenSubKey
GetValue
IsNullOrEmpty
Replace
GetFolderPath
Combine
WriteAllText
Remove
ToLower
DownloadString
ServicePointManager
set_ServerCertificateValidationCallback
set_SecurityProtocol
get_Headers
DownloadData
Console
WriteLine
set_CreateNoWindow
ResetAbort
get_Chars
Directory
CreateDirectory
set_Padding
set_Mode
set_KeySize
set_BlockSize
Convert
FromBase64String
CreateEncryptor
get_ASCII
GetBytes
FlushFinalBlock
ToBase64String
CreateDecryptor
get_ExitCode
LocalMachine
Win32Exception
GetTempPath
Exists
Insert
IntPtr
get_Size
set_UseShellExecute
set_Verb
set_Expect100Continue
get_ResponseHeaders
get_Item
WriteAllBytes
Collect
get_ServerCertificateValidationCallback
DownloadFile
Create
set_Method
GetResponse
GetResponseStream
GetEnvironmentVariable
GetDirectories
op_Inequality
DateTime
get_Now
get_Ticks
NextDouble
ToInt32
ToChar
Append
InvokeMember
GetTypeFromProgID
Activator
set_AutomaticDecompression
set_ContentType
set_ContentLength
GetRequestStream
ReadToEnd
TimeSpan
get_UtcNow
Subtract
get_TotalSeconds
set_AutoSize
ClassesRoot
GetSubKeyNames
IsMatch
StartsWith
get_Assembly
Synchronized
JsonConvert
DeserializeObject
ConfuserEx v1.0.0
WrapNonExceptionThrows
pwroff_B6LeYs4LznWeYW2E
Copyright
2022
$d2cb6955-985b-4d62-8fee-2e65abe10ee7
2.0.3.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$F935DC23-1CF0-11D0-ADB9-00C04FD58A0B
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
ExecParams
country
partnerName
productName
excutionWidget
buyingChannel
discrepancy
PostBackUrl
userId
prices
salesChannel
active
ipLoggerCode
modeUpdater
modePublisher
paramsProduct
ListProductInstall
UrlTrack
trackPostVar
dailycheck
TrackDecrPrmKey
TrackDecrPrmIv
_CorExeMain
mscoree.dll
8nVDNR
#Rp!rAFV
;t-D_b
`] DDD
v X%?""2
&Ti7@N
}EDD&[
/""2=|
nMDDD.Q
Ge?"""
Rr'"""
EDDD&E
DDNpp|
yVW<>:d
9W{=>[X
$@DFy,
p#o3,Vs
mk-TUJ%2
__`?,;XoY%
<IC[{XlWcU`
#"2]bIPSU
{O?d,g
<g-/X/rV
cu^iP
!b" U
W.OSU6+
92<!xVb2
%kyN?t
&K qPn
a1qDZK
;=%F8-
=F)F6#
8wK2c8-K2
5VkV]G$=
q_d= L)Jcy<
8-K&YNi-
S~3!v-
t!0o[^,
3D:8.V\
BkJm(M
uF)Jc8
%F+Jk)m
Z2c8*$`
D+Ea,Gy
KTdM+E
};PI|^
P#0oZ^,
2%M@7E
IDAT?./x
-S(Rc(
4V)i{)
M(lBn-
i--A7(
2JQ&)O
:fYFn-VkB
<-K^L&
5{VFM|
~^0MSRc$
LVgbkzO
,!>;J)
ohn,{y
udZShC!
I]s\U,
%ZS&)e
052 l+6
7{s&IJb
3~:;#5
gdgng.
cTCPjhOiIT,PM
&ir^,9MS
fs^L&</'<
hLEK6Z
rBfmLM
z{C#>Q
UzO/M9
BcEeIV
{FyNw<
CP?-(g#@
jQ7,K>n
"xFYN7M
y?nr-nr=
IBg<&-
ex2_2(
Q5@,rV
$#NF#N
TDvqrO
>@c?C4
&)Z\j6
%IQ0.r
(HZE5Xlv
lvHVZL
s_2}2`
1+,C[|
y "_Um>
x}xfq c
KDvqrO
HPT]68
"r&"Oq
RDO VO
Uo_0f
!G$Ei(
KUzq*Q
d%i"#+o
%r+tGQ
@dImno
&cz_YQ
Fh[]Dn
2:iB+M
fDyF'Mi%
8XC\d=
CzYF;Iy
.;QD=I
Z/V~E0g
A@FN+M
z]Z:)p
"NSziB
IL/IhF
{m`fmc}
0$pNfI
v;<m5i
E9 &.r3
Ek8[%
104A@5"-
LVkx)r
s|)qW`
IDATVJ
,&VGon
nosmm
sJ3`FYT
B5+`7M
ro<1#~
sg<f?4#~
so2ag65w
!w&cvgS
M{r~G9#
!ou{\[[g#
!n/{Q'
")r&Iy
_~[1KS
\Bw|Z@
,"rZD>C
;.NN r
U~92R)
?/N. r
?::4|!
){=o"K
[DdBD
<_}+vz
iUk4fg
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app" />
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
<applicationRequestMinimum>
<defaultAssemblyRequest permissionSetReference="Custom" />
<PermissionSet Unrestricted="true" ID="Custom" SameSite="site" />
</applicationRequestMinimum>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! " )(-,
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
pwroff_B6LeYs4LznWeYW2E
CompanyName
pwroff_B6LeYs4LznWeYW2E
FileDescription
pwroff_B6LeYs4LznWeYW2E
FileVersion
2.0.3.0
InternalName
poweroff.exe
LegalCopyright
Copyright
2022
LegalTrademarks
OriginalFilename
poweroff.exe
ProductName
pwroff_B6LeYs4LznWeYW2E
ProductVersion
2.0.3.0
Assembly Version
2.0.3.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Strictor.266661
ClamAV Clean
FireEye Generic.mg.cfa7c46797e6d113
CAT-QuickHeal Clean
McAfee Clean
Cylance Clean
VIPRE Gen:Variant.Strictor.266661
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Strictor.266661
K7GW Clean
Cybereason malicious.c44b6a
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Adware.CsdiMonetize.BC
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Csdi.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic/MSIL@AI.97 (RDM.MSIL:7w0Fx+M1PlJHMg8a7fdWNA)
Ad-Aware Gen:Variant.Strictor.266661
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Strictor.266661 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Strictor.266661
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Strictor.D411A5
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Trojan/Win.MSILZilla.C5289426
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Strictor.266661
TACHYON Clean
Malwarebytes Adware.Csdimonetize
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34796.Km0@aCzbYz
AVG Win32:AdwareX-gen [Adw]
Avast Win32:AdwareX-gen [Adw]
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.