Static | ZeroBOX

PE Compile Time

2022-12-15 12:41:17

PDB Path

I:\Crypts\Kover (vouch)\Project03\installer.pdb

PE Imphash

d39206ee3735ee3b2bba27dfb83f5afd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000d7940 0x000d7a00 6.09493544054
.rdata 0x000d9000 0x000121b8 0x00012200 5.18119300602
.data 0x000ec000 0x00002658 0x00000c00 2.4859943483
.pdata 0x000ef000 0x00004638 0x00004800 5.83966264643
_RDATA 0x000f4000 0x0000015c 0x00000200 3.34538403786
.rsrc 0x000f5000 0x004651d0 0x00465200 7.97295880966
.reloc 0x0055b000 0x00000808 0x00000a00 4.88404288963

Resources

Name Offset Size Language Sub-language File type
RES 0x00489dd8 0x000cfedf LANG_ENGLISH SUBLANG_ENGLISH_US JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 5242x3499, frames 3
RES 0x00489dd8 0x000cfedf LANG_ENGLISH SUBLANG_ENGLISH_US JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 5242x3499, frames 3
RES 0x00489dd8 0x000cfedf LANG_ENGLISH SUBLANG_ENGLISH_US JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 5242x3499, frames 3
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00104e90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001052f8 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00559cb8 0x00000398 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0055a050 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x1400d9030 GetProcAddress
0x1400d9038 ReadProcessMemory
0x1400d9040 GetWindowsDirectoryW
0x1400d9048 GetModuleHandleW
0x1400d9050 WriteConsoleW
0x1400d9058 CloseHandle
0x1400d9060 GetLastError
0x1400d9068 Sleep
0x1400d9070 OpenProcess
0x1400d9078 GetCurrentProcessId
0x1400d9080 GetModuleFileNameW
0x1400d9088 CreateFileW
0x1400d9090 ReadConsoleW
0x1400d9098 ReadFile
0x1400d90a0 SetFilePointerEx
0x1400d90a8 QueryPerformanceCounter
0x1400d90b0 GetCurrentThreadId
0x1400d90b8 GetSystemTimeAsFileTime
0x1400d90c0 InitializeSListHead
0x1400d90c8 RtlCaptureContext
0x1400d90d0 RtlLookupFunctionEntry
0x1400d90d8 RtlVirtualUnwind
0x1400d90e0 IsDebuggerPresent
0x1400d90e8 UnhandledExceptionFilter
0x1400d90f8 GetStartupInfoW
0x1400d9108 GetCurrentProcess
0x1400d9110 TerminateProcess
0x1400d9118 RtlUnwindEx
0x1400d9128 InterlockedFlushSList
0x1400d9130 RtlPcToFileHeader
0x1400d9138 RaiseException
0x1400d9140 SetLastError
0x1400d9148 EnterCriticalSection
0x1400d9150 LeaveCriticalSection
0x1400d9158 DeleteCriticalSection
0x1400d9168 TlsAlloc
0x1400d9170 TlsGetValue
0x1400d9178 TlsSetValue
0x1400d9180 TlsFree
0x1400d9188 FreeLibrary
0x1400d9190 LoadLibraryExW
0x1400d9198 EncodePointer
0x1400d91a0 GetStdHandle
0x1400d91a8 WriteFile
0x1400d91b0 ExitProcess
0x1400d91b8 GetModuleHandleExW
0x1400d91c0 GetCommandLineA
0x1400d91c8 GetCommandLineW
0x1400d91d0 GetCurrentThread
0x1400d91d8 HeapAlloc
0x1400d91e0 OutputDebugStringW
0x1400d91e8 HeapFree
0x1400d91f0 FindClose
0x1400d91f8 FindFirstFileExW
0x1400d9200 FindNextFileW
0x1400d9208 IsValidCodePage
0x1400d9210 GetACP
0x1400d9218 GetOEMCP
0x1400d9220 GetCPInfo
0x1400d9228 MultiByteToWideChar
0x1400d9230 WideCharToMultiByte
0x1400d9238 GetEnvironmentStringsW
0x1400d9240 FreeEnvironmentStringsW
0x1400d9248 SetEnvironmentVariableW
0x1400d9250 SetStdHandle
0x1400d9258 GetFileType
0x1400d9260 GetStringTypeW
0x1400d9268 GetLocaleInfoW
0x1400d9270 IsValidLocale
0x1400d9278 GetUserDefaultLCID
0x1400d9280 EnumSystemLocalesW
0x1400d9288 FlsAlloc
0x1400d9290 FlsGetValue
0x1400d9298 FlsSetValue
0x1400d92a0 FlsFree
0x1400d92a8 GetDateFormatW
0x1400d92b0 GetTimeFormatW
0x1400d92b8 CompareStringW
0x1400d92c0 LCMapStringW
0x1400d92c8 GetProcessHeap
0x1400d92d0 SetConsoleCtrlHandler
0x1400d92d8 HeapSize
0x1400d92e0 HeapReAlloc
0x1400d92e8 FlushFileBuffers
0x1400d92f0 GetConsoleOutputCP
0x1400d92f8 GetConsoleMode
0x1400d9300 GetFileSizeEx
0x1400d9308 RtlUnwind
Library ADVAPI32.dll:
0x1400d9000 RegCloseKey
0x1400d9008 RegSetValueExA
0x1400d9010 RegOpenKeyExA
0x1400d9018 RegDeleteValueA
0x1400d9020 RegCreateKeyA
Library ole32.dll:
0x1400d9318 CoUninitialize
0x1400d9320 CoInitializeEx
0x1400d9328 CoGetObject

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
UATAUAVAWH
A_A^A]A\]
D$8H;D$`sC
D$H-T9
D$H5NV
D$X5DF
H3E H3E
H3E H3E
u/HcH<H
D$H9D$ s"
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
t^H91u
UVWATAUAVAWH
]h9]xtX3
A_A^A]A\_^]
UAVAWH
D88tS3
L9:tgH
<0t0<2t
D$X$$h
UATAUAVAWH
L9d$Xt2A
D8 t(H
D8 t'H
|$HD8d$PtB
|$HD8d$ tB
uSM9&tN
D8d$!t
A_A^A]A\]
UAVAWH
UATAUAVAWH
D8)u#L
)u"D8)t
D8(tLH
A_A^A]A\]
` UAVAWH
<>u98]
UAVAWH
H9tfI9
UAUAVH
L97t{L
t$ D8t$(uZH
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
H!|$ H
L$ !|$(
<>u:D8t$(
|$ D8t$(
H!|$ H
L$ !|$(
A_A^A]A\]
|$ UAVAWH
8@t?E3
L$ SUVWH
L$ SUVWH
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
D8L$0uP
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
ffffff
fffffff
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$ltY
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
WAVAWH
@A_A^_
WAVAWH
fA94Ou
0A_A^_
UVWAVAWH
0A_A^_^]
UVWAVAWH
0A_A^_^]
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
UVWAVAWH
0A_A^_^]
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
u3HcH<H
u0HcH<H
ATAVAWH
A_A^A\
WAVAWH
fE98t'
0A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
9Cu,fD9y
fB9<{u
fD9,pu
t$`fD9+t$I
x ATAVAWH
A_A^A\
L$ SUVWH
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
A_A^A]A\_^]
\$ UVWATAUAVAWH
f9t$bu
A_A^A]A\_^]
H9L$Ht?H
UVWATAUAVAWH
fE9,Fu
A_A^A]A\_^]
|$ AVH
|$ AVH
t$ WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
0A_A^_
@USVWATAVAWH
A_A^A\_^[]
@USVWATAVAWH
A_A^A\_^[]
@USVWATAUAWH
A_A]A\_^[]
@USVWATAUAWH
A_A]A\_^[]
@USVWATAVAWH
A_A^A\_^[]
@USVWATAVAWH
A_A^A\_^[]
x AUAVAWH
0A_A^A]
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
f;\$Dr
f;\$Lr
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
|$ UAVAWH
0A_A^]
UWATAVAWH
A_A^A\_]
x UAVAWH
x UAVAWH
x UAVAWH
x UAVAWH
UWATAVAWH
A_A^A\_]
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
D$@H;F
kL@8o(u
VWATAVAWH
0A_A^A\_^
A9.}NA
C9< t8<#t+<+t
kL@8o(u
kL@8o(u
kL@8o(u
VWATAVAWH
A9.}NA
C9< t8<#t+<+t
kL@8o(u
0A_A^A\_^
kL@8o(u
x ATAVAWH
0A_A^A\
x ATAVAWH
0A_A^A\
A9< t(<#t
A9< t(<#t
A9< t(<#t
A9< t(<#t
A9< t(<#t
A9< t(<#t
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
|$ UATAUAVAWH
<Ct-<D
<St[A:
u<g~l<it[<ntP<ot,<pt
<utK@:
{,D+{HD+
A_A^A]A\]
|$ UATAUAVAWH
<Ct-<D
<St[A:
u<g~l<it[<ntP<ot,<pt
<utK@:
{,D+{HD+
A_A^A]A\]
|$ UATAUAVAWH
<Ct-<D
<St[A:
u<g~l<it[<ntP<ot,<pt
<utK@:
{,D+{HD+
A_A^A]A\]
|$ UATAUAVAWH
<Ct-<D
<St[@:
u<g~l<it[<ntP<ot,<pt
<utK@:
A_A^A]A\]
|$ UATAUAVAWH
<Ct-<D
<St[@:
u<g~l<it[<ntP<ot,<pt
<utK@:
A_A^A]A\]
|$ UATAUAVAWH
<Ct-<D
<St[@:
u<g~l<it[<ntP<ot,<pt
<utK@:
A_A^A]A\]
t$ WATAUAVAWH
D+{HD+
L$0Lc@
A_A^A]A\_
t$ WATAUAVAWH
D+{HD+
L$0Lc@
A_A^A]A\_
t$ WATAUAVAWH
D+{HD+
L$0Lc@
A_A^A]A\_
t$ WATAUAVAWH
|T4fD;
A_A^A]A\_
t$ WATAUAVAWH
|T4fD;
A_A^A]A\_
t$ WATAUAVAWH
|T4fD;
A_A^A]A\_
D$18F(u
l$1@8n(u
D$18F(u
D$18F(u
l$1@8n(u
D$18F(u
D$HHcK H
D$HHcK H
D$HHcK H
D$HHcK H
H!L$ E3
t$ WAVAWH
|$PLc@
0A_A^_
t$ WAVAWH
|$PLc@
0A_A^_
t$ WAVAWH
|$PLc@
0A_A^_
t$PLc@
t$PLc@
t$PLc@
WAVAWH
A_A^_
WAVAWH
~,*u<I
A_A^_
WAVAWH
~,*uEI
A_A^_
` UAVAWH
` UAVAWH
@USVWATAVAWH
A_A^A\_^[]
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
f;\$Dr
f;\$Lr
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
f;\$Dr
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
D$0@8{
p*W4H
p*W4H
T$`fA;
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
WATAUAVAWH
0A_A^A]A\_
H97u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
@SUVWATAVAWH
fD9d$`t
A_A^A\_^][
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
UVWATAUAVAWH
tUH95i
xWI96tRI
0A_A^A]A\_^]
WATAUAVAWH
fB94ht
xXI96tSI
fC94wu
0A_A^A]A\_
fD94pt
u9!\$0
ATAVAWH
0A_A^A\
fD9t$b
s WATAUAVAWH
D$h9t$P
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
@UATAUAVAWH
e0A_A^A]A\]
fB9<Hu
fB9<@u
fB9<Bu
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
f9)u:H
fB94Ou
x ATAVAWH
A_A^A\
x ATAVAWH
fG9$Ou
0A_A^A\
fB9<Hu
fB9<@u
fB9<Bu
fD94Au
fD94iu
tSf91tNH
tU;\$0tH
WAVAWH
A_A^_
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
p0R^G'
H!L$ D
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
L$ VWAVH
WATAUAVAWH
gfffffffH
A_A^A]A\_
{ AUAVAWH
0A_A^A]
t$xt*3
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
L$ VWAVH
fD94H}aD
UVWAVAWH
A8^8}SD
u,9\$0~LL
PA_A^_^]
l$ WAVAWH
A_A^_
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
H!T$0D
u,!T$(H!T$
A_A^A]A\]
x UAVAWH
@UATAUAVAWH
e0A_A^A]A\]
@SUVWATAVAWH
A_A^A\_^][
WAVAWH
D8|$`t
A_A^_
WAVAWH
D8|$`t
A_A^_
x ATAVAWH
@A_A^A\
WAVAWH
A_A^_
WAVAWH
A_A^_
H!D$ H
UVWATAUAVAWH
fB9<A}1L
A_A^A]A\_^]
|$ AVH
VWATAVAW
A_A^A\_^
AUAVAWH
@A_A^A]
@USVWATAUAVAWH
H!D$ I
hA_A^A]A\_^[]
x ATAVAWH
0A_A^A\
UVWATAUAVAWH
D9t$Du
A_A^A]A\_^]
SUVWATAVAWH
A_A^A\_^][
@USVWATH
A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@UVATAVAWH
A_A^A\^]
A_A^A\^]
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
A9tgA
A_A^A]A\_
VWATAVAWH
A_A^A\_^
A8^0t
@USVWH
D$0H9D$8
WATAVH
0A^A\_
E80t"A
fD94Q}
@USVWATAUAVAWH
eHA_A^A]A\_^[]
AUAVAWH
@A_A^A]
AUAVAWH
@A_A^A]
UVWATAUH
0A]A\_^]
@SUVWATAUAVH
s5fE9!
fE9!fA
D$pfA;
NfD9d$pu
fD9d$pt+fD
0A^A]A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
AUAVAWH
A_A^A]
SUWATAUAVAWH
`A_A^A]A\_][
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
USVWAVH
A^_^[]
u1!D$0H
UVWATAUAVAWH
PA_A^A]A\_^]
LcA<E3
u"HcMHH
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
template-parameter-
`template-parameter-
generic-type-
`generic-type-
`non-type-template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
nullptr
lambda
`template-parameter
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char8_t
char16_t
char32_t
wchar_t
decltype(auto)
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
const
cli::array<
cli::pin_ptr<
{flat}
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetActiveWindow
GetDateFormatEx
GetEnabledXStateFeatures
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
AppPolicyGetShowDeveloperDiagnostic
AppPolicyGetWindowingModel
SetThreadStackGuarantee
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
log10f
_hypot
_nextafter
NtQueryInformationProcess
RtlEnterCriticalSection
RtlLeaveCriticalSection
RtlInitUnicodeString
Software
Logic Media Explorer
Software\Logic Media Explorer
I:\Crypts\Kover (vouch)\Project03\installer.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$CastGuardVftablesA
.rdata$CastGuardVftablesC
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
GetModuleFileNameW
OpenProcess
GetLastError
CloseHandle
GetWindowsDirectoryW
GetProcAddress
ReadProcessMemory
GetCurrentProcessId
GetModuleHandleW
KERNEL32.dll
RegDeleteValueA
RegOpenKeyExA
RegSetValueExA
RegCloseKey
RegCreateKeyA
ADVAPI32.dll
CoUninitialize
CoInitializeEx
CoGetObject
ole32.dll
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetCurrentProcess
TerminateProcess
RtlUnwindEx
InterlockedPushEntrySList
InterlockedFlushSList
RtlPcToFileHeader
RaiseException
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
GetCurrentThread
HeapAlloc
OutputDebugStringW
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetProcessHeap
SetConsoleCtrlHandler
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadFile
ReadConsoleW
CreateFileW
WriteConsoleW
RtlUnwind
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
8Za8[g
g0l1`:
L`ge3a
wBW^~`
g/\YFs}
@4*#WT
&93QPRF
g^~)u%
3^@8"@
IDATv8Ey"
2M(idjv
-M]9|`
8dXEX2e
8@Mkn
g,<A-
}2=;}W
z|yi=]y
cmm-3Y
n,.`yu
/n9VgG
0Q82`(
kf^`\VM
YSJ@YSJ
a[S0YSJ0
XICC_PROFILE
mntrRGB XYZ
acspMSFT
IEC sRGB
Copyright (c) 1998 Hewlett-Packard Company
sRGB IEC61966-2.1
sRGB IEC61966-2.1
IEC http://www.iec.ch
IEC http://www.iec.ch
.IEC 61966-2.1 Default RGB colour space - sRGB
.IEC 61966-2.1 Default RGB colour space - sRGB
,Reference Viewing Condition in IEC61966-2.1
,Reference Viewing Condition in IEC61966-2.1
CRT curv
$$M$|$
#*%%*525EE\
#*%%*525EE\
FDZ$FH
0HbR"4
l.o?G}8L
qMHHqi
j80,*Q
A4J,H}
0#!<rn!
<hj9nW
,hD@m9Bx
vk:Xqc
LCH@4&
h5Zz5gM
{Ky+UU
hfLy#
_.<z>#
6FBCJq
fv.Yp,D
%&EHCP
rlC"G&<
LfLfLa
E<nddc
PCR"FI
#,fB2#
,Uhky]
-fXqk*
>s[]GU
yw)CW
bhJJ2K&&4
4&FD@jD\G(
LJII)A
&3&2Q2
Bq`)DhN2CP
J-22Dd
rchhM4
bjHMJ$
M)FDI&
z:-mm&
FQhqR@
Ru}n_0
X!4"IJ 8
Qm"Bi9
)FHJ9"
8M2$rAJ#
EM!9E1#
N-J2JI
)J FR1
LHRM$0
LM9DhjQL
FIFUx-
60LbNPqLN9
C FQm'(
mFHrJ*N
Ba"(Y1
iJ-I1!
H9%$!7
ynq99~
rF9#"2
0N2L#"2
pR"J,A
}#kf9*l
JH`DK&0
hd$FHqa
&3$dFTy
#(IC$
2"J:mV
%}}mu]F
#"!"2"
C$[Bp`
7K_*x0V
-lw5pi*
EJ9 1"I
)EHLLI
-]:Q2JX
h!5(85$HOE
C@41"IM@
#iI)E)
\ZbmFBn$
iGOVUlv
JBI&Acq
5$%$4D'
BDFI9)6L
_Vq,{
E12-HI
0M14J.
#&9',nde
J@Dbm)E
F9# #()K
n"N#Br
qY1IH"
oYOg./
0! LBjpn*1
q?Noni
m*h.m7
jhy;fnkq
K{q=ULx
&}nxjs
C#"$e,fH
hCwqiu
)F#dC&0
ov8+z~
.ym3Ko
[wgny1X
0[[IJY%:
JQqRlD$
J G$BQ
6v2l>n
A_]G[+8h
?(qlz
WlgX.P
g41S0P
jpjy,\_
-4,WXy=V
u#N1jQc
qbLb"y
wOW_-W
ql@&&",&
!<chCLM%
eN9"%(
Qz]E~sI
Xz}>/?
m=VmnbD@
0t_}kqs
!)"I86
Vv?+}M
(LiI)!&
4 bRhM
N,"8Hh\
K\g[J\'
u]Ge{yc
R|gByW
C"HhN2
4<'?Wg
|g9[Ir
3QjQqn"r
%,61K=
"HN-J,"
,m0C@)FQcM8
FH%$I!40JL
<xql3d
NcSouO
@1%%,rHd
'"9KVlg
#u_.]_I_
M2! "d
AJ 123
"))c$G!
Z5)a0b
+KJ:z:
$;]D+j9
HCM44)
pzsdd
:y']OaR
M}wB:+
T1kuz<z}6
@=v J$F
><8tt>
10N,M0
h<N%|2
~QjI6%"2
N#pqjQ
2Jm<W3f
FJ.Qbi
hMnJ5j
RB`% "
rCK&&8
&$0hjQ
hdXFD@
=]<z=V
xo#S[_
v)kqvv
MC$Zm0M
R8k`T|
X1kt:z]OQ
NQj. &6
_*:M?WC
lcCSZT
NhCn,
I0,l-d
qn,RJDb
dBN2n#
xgN40dUc
m$6-nl
JVs8IO.y
]UZx0P
h@) R"
%8 LCL
DBC@81#
zm{(i4
{HJ*N-98
7<y"J$
F}fDZqm
ddc%,`d
bbRM jDX
f~~zn_
I19FQqq
'(IIF@
.k6UQb2
)f9N_w
Ve\y1V
pvrB8qd
v55|G'
6YcQ\yi]
=~(Juqt
qR@4FI
nV=U|Z
6{-6,:
6$64D!&
,VY,eY65
u[+;\u
qk*,7'O
"FqiI&
0MBLJq`
v[()C=
y2,HrRN
HlN.,%
}UjZNoy
IFDX8N-
2,iJ FLD
QN2LL#(
W:utV6k
I%$!I8
42-5!2!(14
% hLRM
JDXFQjI
i9(M&$
eS__Q=e(G
j3QiHD
0@J*P%
,[LWmK
savw3Vt*
zNwAg
o_^z}/;
#&9FDF
Yg_YG[[S
5=%~sWwi
bJJBCR
v4WicT
1"HR"0q
iI)15":
Bn,R@E
Oms51g
&"qu9/
"*II q`
".HLLH
9"FhJp
FqB`%$
"2HRiFHR
HLhMIA
s5*,xl
d\XFBiH
Dh"HcM
FM&4#$
bA!2.!(
^-ckkm
j@FHq$
LB`&!
[7sKag
0N#MI8
bj-"jJ
& SbLA(
J2h`)EN3@
[#!4&48
K]e=O
:MT)/b
UpKQQ,
kobM!9c
jQ$$J &
,8i~'|
gsWWnd
7IqVy%R
F&<sqbSQx
dSY""P
/]kQW}
BjQdF&
5$4)BBhBm
mJ,Bn2D
ymGQjI
5(M8I2"
jN#IHb
!2=y()
6D$BQ}d
n(j.I b
M0MFdy-
Zr%=t1
gc4^<y
,]~ZV0
5.sgs_
Fn^'fv2_
()!6))
)BJPlM4
:x/?WOS
JHn J2
cHM2I
i422Iu
LJBbba
ZxuY3|
Y540owCCM
sveK?Y%
#iHN"M
#5*x58
3q_OCU
FHbhq`
RHcHbMJ-
n}%$I
89DNQM
lTkjKQ
HChqb)
@J,N,h
IFA(HM
`$5K&}
MI~w|w
)FB`4J
)& `F@
8J.2@N-
hhbqm19E
AM dX&
-%=v<U
M4&J-44
J@F@FDa
0OcC6\5!
1HN-19F3@
F`BPlM8
2RbiN,
)"qbIHM
Dd6%"
O.xq~m
'/K{_U
q?*q}g
m1"Dd$
__S&<t
I[ESi<
HC"I''
2U-m,a
N2NDQ(
LCbLR
8N3!2,
RJJ->w?
'"+$E.^
Qn#@&4I&
)C$Ra(7
2,c" M
OuW-L;/
<ht{.oU
nvV2;:=
9!6)F.Qb$
J2RDd
x=Kg<y*
FBCRI6
$6 JQm8
"blDIDQbjC
._AomO
v3Nu5Q
jI&)AN
e0C"J$
PmJ(N3
LM8J2Cb
N21m-U
$2)IHR@
!8IN(d
LLJQrQi
lz+Wr,
a())"2h
49<{7E
=}-um^
xrw?/y
ubWpk3
O_w%|*
n,q`BbMJ,
MQO\xwo
cHhdd&
HCMEIc
3y<Tu\
Qm@m)EM!8
9':XaN
.pRBSI
]=|1rz-
DQ".Pb@6D
N#qcHi
&:WndJ
)brQb`
w#CM&J"
Jqdc41
jJJ#qdd
J2@"I7
|22X3N9
Bi4HCM
$&!FhA
;lt!KS
$%".!<S
Mk3m/Zz
!&&)!1
LqRQfLl%
KX69,K
N )(JR
{6lZ[9
Oa`&&F@
22@2-0
RBcC@)
29"FM8
N2# qx
~u6|Go
FQ2c$!
FQcM1J
9BBK,#(
8HdDJ2
D"2#!5
_Oa["'Z
Bi2Q#!HHa
@L$F#`
m<8y>o{e|
QO*SbI2#i(
jDdc#"Q!
IHqiw["
)DJQhb2c
?LYB`E
"-11J(Ni
'",N-;Z
(IIFI$
"#!48J#
"qRN.QD
QRI46)
,M15"-y
fM]+J+"D
dd&E1JP
|W+S_R
lDgq&
IJIFj!
XDjp`)(
8)FQRQbh
z]}=o1
dd80mFJQ`=~
Oe^Vjt
C6:zM7=CY
qlA"91
lv_rzJ
Li5)c%
69qOev
"@) jDv
*X1<f(
>LU5Z^c
"3N.2hh
I0MIDjDd
Z`J FLi
@)!8J56
PLJN.2
Hwl;;l
n?EKWn
2,hRQrD[
b J-I88
WcW_[[
qdf"*DZ
<lj2#$
0qcJH@
BrJHB`
& hBj3
qI<c2c
",p$4(
HLJiF@
CBpRi1
"#$!C"
9,E|5u
BJ+.2Qj-
QlB"BDD
}NJVu5
FQn-I&
*h@62*q
EJ2Qk$
FJqM2De
!FII)@
f n..x
411J.,h
~MNxph
`"J2"0@
&$I)&E
JBpmJ2K$R$D
G*DQ5<c
$FPhl
FM n-E
XFJ,Mc
8FII8'
FPdI)D
z=l>e]
dIHNPd
DCNQN#CQ
J*pCn)
wi=W99_
LiIFiE8
E)<jK$
HPYA10
Kw6W;N
w?aw+{~
W@LM2V
SIp(MV
]Wnenj
a10Jb`
}>^5[^
,Bf%ITD
DLLLLH
M&,UV5
1]11UT
^FVMyWoUb
[\7?Ug
3JQ%`}
K_sw:
=FnN/9
v8Yui9
b`UP='
VV'ys33
~3lbnc
^z@UJj
U5LSqWM
sP$ L$
&.DSU7
f*S]5B
FMUW5k
3mlzOf
wWoeem
bbbbbEt*t
7IgQ{;
tl}kiw2n
a111$LJ&%^
"bbH&&.[
,-fEUb
Jf*S)D
1(&$"D
.Uw#g~
@M31(&
J&&*&$
t{L|{x
c3#+:z
|;Z\+Z
bk10puw6
o]:]~6
o/3goI
m=Ex;O
^/_{/'
Ec*r#"
LLI5=We
EqEUS|
"=scqv
Vw=O#j
lM`2}+
'7#''"
b`LLUQ
"A1TM31;;
;:x^?.
nS^ET[
SR&&b@
;c{/"/
&AU5"A$
TLIU1R&"
khdgefq
TIMIBn
@BDI%I
cIew'wF
&&f"Sv
G+EV'.
y\LJ&&b
H"a0LL+
%P"EAu_q
a3MtLT
%"bjUDWK
%R!T*DL
>+Cs33
10tUw~
`J$"Q0
L$BQ"$D
10EQ15U
SE@E}wOs6
n=/_ki
Q "D$"
?7AU34
LLLLI3
j"E3{;
;+znOM
saNv5Ywpp
Er"bbI
Ec+3e]
bBHMA(
2u;N{?s
%QTI1$$&
oM;~kV
31(&$&
Q"AQ1$LH"
l2p8}O
n\QTAR
bQ11Z@
vywrmiy~7
dJQ"DWL
$LJa33
I%3$LI0&$
TLL"f*P
jLSTED
A3Mq2EJfULL
33'c]x
MYy{o[
a11U314
LLLI5P
Q1!]5Q
WEtEe5&&
&*&&*%
aTy_a_a
VnWTsN
hW+kr\
_-Sq_<
#';N(CF
#|ao\Sl
G#>y6N
~LFN:E
y?g68W>
tC<4[]
=f+4y9uL
>duYZR9
7_9G>\
&'NzcN
3{,c+9s
S^_ZX1S
^uUU\c
3[LeMOC~
>~_Keq
N]_'e6v
V\Vzz5`
N}:eVz
UUL!Ta(
fZg+&O
L=|:~wWtk
F~!W,B
UT!_UC
`'.VJ3
E.A)X
{wHF'`
m(JNAee
%uuI8U
N<z=?f
gxY_cj
VxG$uzzv0G.|
>x9=(xz/
fmO?=Us
G5{<<v
SGyUvN
%'#4dE>
8tFHqd$u
TSLcBv
;$eX3S
FB1G5Q
uF_Ry1v
L~n{tk
l:!_6U
z8sWEU
&xsV?B
G9VZcT
"Qa2q0BP`
c^&5aK+
$X[!n$$$X
)pNq+6
\c.7vC
pE:J"Y/
R|%vc1
Y""Yn$Y
y_6u..
{_-/Se
"R%"O&
Nv?<Wk
BWkgfN#
R%xZJ^
~d%q!/
rr#V/{
JMl5tQ
&6\rys
%&2Llr5?
jcwli.=nv
JNV4iOk
7fwnE83
Z\lapT
eIt+N0
i)$Jwe
qW6(ajV
^_"26cF
CIRnLl
7,$XQ,i,S
%-)lAb
#%"S%1
%"R'"U#
[Hrry]
pR]x52
JVGydT
~r,ZR!
TuGTuGP
r.9t.\
wknaj^:_1
b4g."R
kS!R]H^
N8x;rV
:7ZL%%
;^~l<?f
8V+~MM|
vRn5_{
.2bvv'N.J}R
|0_dWv
S;64*M
i,i,i,i4
$(nbi]
)E.8*V
-*%Ev|;
M[Tda?*q
_+x[Hb
j*pr|"
BY3VRe
.666;5fZ
(RWS#
xZT1:)q
W%24jO
)pE_r29
Ccg$c=r
QN7"@O>
k9$K&8
t}Ii(S
&GUIFr
ObBf)E
SS*WIm
wd0{^o~
?RUnJE
tXK&1r>F
'#VUeN
|g45rH
DYXq)KK
vy5..+<
57+.Ha
jjz5-V
sToqi}Eq
+b!/TR"
Ux1p05f
ggvU\F
g>$2YId
9l;IlR
w_zjK{
(C+'+Z
9vn*Q}6;+UGy^n
vuE(Xt
7V0\i~
R2WY667
td\mcM
>QKd_L[f
Szt;lJ
wIp[%6
d0TeOTx
{n)em1
\hLLYX
[r5blD
J^mDZ'R/
:XhGG;
LO{ATqq
SGh~MJ_
\e-)Nr{G
RzmfA$2*
&`ez?/
WiA;j)
Jp089W
%$Xq,[%6
KcQYnFWVdji
LR_xwr
;_vTU%
a)wtcA2
cN1\%d\\
SUGy24}
R `?YS
C[rn)'k;
vt/Ru
erf"~{
GEOfFB
SSPvkk
KEIBnVz}
ZdB\nI
O:x<UG
yWViA/
by4u)T
{Yt,FBy#
pFSs{X
LO)G*u5|
v-5R4q=
yG~<,{
ve-U%>
}/bJ;]^
5)~cR<
;>{J>7
v<,aAa
R<!Ds%2S
?oOwaXd
r%Rni(
rYXQ,,
$=WVGcYO
mJ%9wu-
1FszRm
+)8=;>
#iIKa=
9{!;ul
m\ll6Nq
rO$!g7
V%N2Vj
5tN"zX
LLO&1OZ
JdaR|-
r9Or{C~
.jWHNnm[o\
\=(AJs
-/J[[|
\-<=;.z
X*MJQs
YZkdap40
$1pTEH
zuuvCw
f4FN"i
9pa*}_
JClHm"uI
*V'WsP
D}.![%
67q_b7
hLyrBF"
'd&GqE
YCCRn[.Y
Fu5nu6
_V[J;4F
T'9Z1m
<C%Xrc
C$U^_q
E"u-QD
pt5-YX
*biSi6)
+amk/4
eF9"$K
<<!Z-\
L>%bg9Kfp
[U>8dt
lakFxx%
K4t7;F
{\Lllc+J
ey|1^
=q(a4M
dVK,eZ
2r\"uU:
I$IlCWWrsK
*\KLm}^
c=Z7!|
UULeKq"
a/2\n=1
K'$\llc
)n\loc
N" @LDHp,
Du=rc{
,Elt'Z0i22
JZ*&'u
wcQr|r_
&rTz`T
N~^Eg?
c-%iF[
zxn6%R
{!e66`a
bge{piv~
"*M-YYg
sDy"DDH
R{t*?<
Kapvt?D
//B/M*
vt!9J\
>BDbF%8
?tBu]d
YSE4QG
FKw#}o
R.UL3t
R.j5=L
V!!e%rH
HB1Kn8
G+[+l!"$
R|Kr3W
W%/:rv
Vr{>H-
"En@Dw
'9$Jv'"M
[V)AqM[
B,lB$ $B
,[>rcy1
%fFE6C5l
u#}+k{
bkwTe#
v'bet`
m,ObR*T%/
.\r)a\
4Mn|3)
HY$$$-
^^LWhh
5ijV!BQ
%)NNRwo%
+\O&Td
r&L{M?qq
\r%Wb8y
9t'Sbu.9
rew+lATorEB
jb$PoN
*U%/rJ
2F#iF^
Yr+rl/
;(9m8E
_$2Ls5
goTH{[
2(HBDb$(
MmnLE6
'2S.r3ke|
dIHuQq
ZNBY2=
t9#d]"cd
WY\y_+
&_'.MYXq
wrf"mN
^k$$B$P
8'"ObR!
e+"(Y!F
)2r%#w$
):t(7)_G>
')Yu0XUB
pzWy.z}
;c_w-)
.[+e"
'"R%/r
5gYCJoOR
HwbB^+
ObObo+
_6TY!}
jov(+?r
F+;x.JK
o&Hc:f
B+%agqpz
-+{l`e
F"u%y3L
6C.j.\
r/b,LL\
zNbAg">;
F7+M$b'
!"2#",l{
NF\y[&
bj/q3tE
u|Di/qUs
d6666_Q'
FU,G,F
~ZKi?y
o/"_V#
w DOq1
T%2s5_+
4aMl8'
mZVKvb
.9e)$W
UnNcllu
JiKvrnlK
w,i,$(
buR*VEl@
V_b2jukMIyH
JeO24/NI
%)t#%$]q|
lluy]p[
+ok_$S
I>v%Rp
cvVu4y#}
-Ck>rr
g$[ctG
|DkSSH
s{g'dw
gArEpH
*p^X%a
g-[6R^T!/
U4Sr0X
."\nvZK
_'q&G+
W5$j.;
3B"DDJd
YDB"t".
S]l\RGA
x$rWv%
XK(BS{
y\lbY6j.
HSW'U'b
[)DK6m
0T*;nR
~9.sDH
g9KWA"4
zm~M1Oh
!x;23#!?
$#V]rob
(G\#)%
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Variant.Lazy.272934
FireEye Gen:Variant.Lazy.272934
CAT-QuickHeal Clean
ALYac Gen:Variant.Lazy.272934
Cylance Clean
VIPRE Gen:Variant.Lazy.272934
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Lazy.272934
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win64/GenKryptik.GDIW
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky Trojan.Win32.BypassUAC.aby
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:CBR6z2xCXtJ)
Ad-Aware Gen:Variant.Lazy.272934
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.tc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Lazy.272934 (B)
Ikarus Trojan.Win64.Krypt
GData Gen:Variant.Lazy.272934
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Lazy.D42A26
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.BypassUAC.aby
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5326569
Acronis Clean
McAfee Artemis!62843EC5A756
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Malware.Win32.Gencirc.1168df41
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG CrypterX-gen [Trj]
Avast CrypterX-gen [Trj]
No IRMA results available.