Static | ZeroBOX

PE Compile Time

2022-10-28 12:15:53

PE Imphash

8f54c7f89ab7fb80e3cbd057af48cb19

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00062000 0x00029000 7.97823235922
.sedata 0x00063000 0x000ec000 0x000ec000 7.58089688837
.idata 0x0014f000 0x00001000 0x00001000 1.30779531436
.rsrc 0x00150000 0x00011000 0x00011000 3.4396357541
.sedata 0x00161000 0x00001000 0x00001000 7.98225752685

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001500e8 0x00010828 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00160910 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x00160924 0x00000418 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x54f2ae HeapSize
Library USER32.dll:
Library GDI32.dll:
0x54f2c6 SetMapMode
Library comdlg32.dll:
0x54f2d2 GetOpenFileNameA
Library WINSPOOL.DRV:
0x54f2de OpenPrinterA
Library ADVAPI32.dll:
0x54f2ea RegCloseKey
Library SHELL32.dll:
0x54f2f6 SHGetMalloc
Library COMCTL32.dll:
0x54f302 None
Library oledlg.dll:
0x54f30e None
Library ole32.dll:
Library OLEPRO32.DLL:
0x54f326 None
Library OLEAUT32.dll:
0x54f332 SysFreeString
Library MSVCRT.dll:
0x54f33e strncpy
Library IPHLPAPI.DLL:
0x54f34a GetInterfaceInfo
Library PSAPI.DLL:
0x54f356 GetMappedFileNameW

!This program cannot be run in DOS mode.
.sedata
.idata
.sedata
N/(?O]=
bRUE,#
:#Rto$$
6EB0y8
?lpA)T
e%adyW
Zs9P<"z
U%0?t0
v-@Cn,
+*/bqD
DZz%`XP
*ckD$Z
S|}q(H
wg.o.N
}8MQ0p
*;9|S-
fvF)<.
ux-/[!$
4m(!J,
[cEVh#
azJ-.}
aBJuBKC
s].*o1
4hyt09I
<T|HbT
zwe<rt
T0}9m*
)x#^Cd|
0q9Yfo6?>5v
nn&/&G
QC#<PW
LMx7QC3
FwE]/2
Na5h}r
d67mSgo
6~fl<r
\22VvTj
Ze%AnoU$?
~Q&+<.I
>4uI;|
6rbfI
FQ@)1|
tP~gbv
~ao2M2C
?z6Zb:
T1gtY]gR
Yk% Re
Tttly{
@=5+a*2d
KIv?I}I-
rKRb3K
shE(?]?-
`v0&.K
8$M8At)
HyyGfS,
\!{oJSvG
4g2_DUz6R
dZFzF,?
Ezb5fE
+EGaS0
B7cx*~/
l#zL^`lv
4BNuhR
3=rf[Q
x_2RXT
bV3(OZ
Dm\lFl
!#nz"T
5{"UT;*
X=Yo8MZ
&?.5As
I}J9}cB_ng,
Zb}]X[>
E}K{>&
vMyv\1
?yU8`"
p:`e^'
z@+Hac
ET=7J6
ed>+5|
CvCY~aw7
U;_,'x
W9$6w:
2>,4)KLw
HE8OT#5
QSV&3?/
hXW+aGn
8?*a4
G,&p8gZ
4H%uPE
Y2lO<gv
&d;".(W
h{*3RY}
l*NxA1
4DdWrB
87?NH_["V
'}zu?/
LgwnV
FF^.^.}
a_ukqv
Vv*lhFT
Ut,N)+a
Nb:[!y]
T/um%E#
hg}[aJ
9:X4+@q* {
+-y /5
}!2s5>;
tS;GRs
,R&1Pi
MDQo$[
v'Nox5W
y)&{zm
qiYx06
K-?:bk8
!LI!!Y
w;B<R25i
o!@(zS
e`5x#
aO<zE?
5:ECl>
6){fnvD"
LlY770CY
#$yjGg
S7yPw
j0GL+/[
^k?(/cv
<DY1UN
B?hM05
fUMJcO
|@Jz&a
*K~.")C
7qd;(I
g$6sWnt
#H{!`b
>T[,XK
/G9r\4
]4^3bY]
/hezy
Y>CbC
<R#fa0
N;5$~
ppBU;g7
a-zBsX-
.Dn[1PF
T.4@1M
2UbMel
hdcm(y
9aK'%/
P"7$`yZ$B
!_lCa`
F1PQjL
RLG9!C&{?
ZrQ et
&A$K G
q2^A[H
Ed]'70
FVi?^,
q%Ge~j@
U*'~2G
K6oh3
]ZD6u0
~.Z-hm
!Y_B~zF
jnIfdF
BcgMq$
c]4/^T
u^'(P\L
I 0wo:
qg.V5?
!ShJ($;
0x5?lV
:MfZA$
O7<K)Z
JQL0sQ
t$Wwq,b+
F E\nk
|*[#%$
bHt((uZ
n~Rn".
5>Dxn;
]0=@Wm
jZ]Re9
Ens>"S
-a[vU{
F^0x9s^
%B,_n[
/(wbn:7
"2W jS
)cnV$X
2z6x~i
\lP7X(
+<f4*>-P8
X;D=[f
`^Nx8Fb
kvrH];fg
Wty5|w
m;3dKrg
nu\^%
bnV5E'9`
JL*c17
ZgJ7Xo)p
gHC3J0
S(siU`
Bs2,76
b_{S;[
zUR,}.
a#U~C6
FtOUA<
rU.({{
~DZchb%
wfo_o\6n6X
P:$V*|7:fOQ
\*K\bh9VL
'$A;9\
bO+BvzkL
X^]iy!
x9S#FJ
m`[2aeb
UIB]nv
[9xf*+
tdbRD+
bE?U~F
t8ozrA
"HdhFz
HrZc/N
,x,@{O
CW_+yj`
Z\ReM9
Uw+wo'
uZOX_m
rUCJ-x
vj)u93
h `rU>
%MWjG]
qs?%^k
WmB\q`
V|@Mr;
ndiw1ca
V=Tn'#7F
o( $TJ
:9F{#]
|4Q72P
KjlU}syZ
G'"_iP
(RCy_z
>P#?%<
,k`*&
IS%3iY
hUiNo`4
eHmfr&
YA39CE
^}lv>
6}Gk#B
}Zvo{Q
B'\G-u\8
NSHqNdpu\lv
Nod5B}@
_b{!BB
i%K?:i
@I,A>?|
z`;E{.
b 7;7APx
:GJ^kx
[mJ@y?
w"k(]k
moME!Fzs&
8w0`G!
=C|v>?
3FUuGk
>4"TlP
/dV}jSD
Nz/o/D
KPs^>s
zvCw+w^
3lCfQ1f
Q,G6k-=hl
)|^U6AMY
<uoO"J
Ycm|Ol
*4dR#_
;L$,wv)L$,
i)|h_\
Z~o#2hL
+BheHm/
5$WYfU
Gfaq^n
~RS9];Q/
"`<lZ+
{o)|JAh
};UJ)|
03*E3z
e.MH1/
|ulwK2
103*{M
I)|SJU
{RW5iH
JI1xxm
0.>a_o
nI)|?6
Yp\c{O
/yFp5'
n/hx#P
('DHsj
d{_~|BY"
'Dipsj
Ws9xA|(
sK/6!`
vx>0zF
3dSh/G$g
'D_5$W
=WA-m0x
Gpl`Ma?!
hUB&EC
ZXoS<}j
GetModuleHandleA
GetProcessHeap
HeapCreate
ntdll.dll
RtlAllocateHeap
LoadLibraryExA
CreateFileW
GetFileSize
ReadFile
CloseHandle
VirtualProtect
GetTickCount
GetProcAddress
RtlFreeHeap
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DbgBreakPoint
DbgUserBreakPoint
DbgUiRemoteBreakin
kernel32.dll
NtQueryInformationThread
NtSetInformationThread
user32.dll
advapi32.dll
hid.dll
iphlpapi.dll
VirtualAlloc
VirtualFree
SetThreadAffinityMask
GetCurrentThread
ExitProcess
GetSystemDefaultLangID
GetSystemTime
SystemTimeToFileTime
WriteFile
GlobalAlloc
GlobalLock
GlobalUnlock
GetCurrentThreadId
GetExitCodeThread
OpenThread
TerminateThread
SuspendThread
MultiByteToWideChar
WideCharToMultiByte
IsWow64Process
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CheckRemoteDebuggerPresent
CreateThread
ResumeThread
GetThreadContext
SetThreadContext
mscoree.dll
mscorwks.dll
mscorsvr.dll
KernelBase.dll
mscoreei.dll
clr.dll
diasymreader.dll
SECheckProtection
SEGetAppStatus
SESetAppStatus
SEGetLicenseUserInfoW
SEGetLicenseTrialInfo
SEGetNumExecUsed
SEGetNumExecLeft
SESetNumExecUsed
SEGetExecTimeUsed
SEGetExecTimeLeft
SESetExecTime
SEGetTotalExecTimeUsed
SEGetTotalExecTimeLeft
SESetTotalExecTime
SEGetNumDaysUsed
SEGetNumDaysLeft
SECheckHardwareID
SECheckExpDate
SECheckExecTime
SECheckTotalExecTime
SECheckCountryID
SEGetHardwareIDW
SECheckLicenseFileW
SEGetLicenseHash
SENotifyLicenseBanned
SEResetTrial
SEGetProtectionDate
SEAddMemoryGuard
SEDelMemoryGuard
CreateFileMappingW
MapViewOfFile
MapViewOfFileEx
UnmapViewOfFile
LoadLibraryExW
LoadLibraryA
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
6bad allocation
_except_handler3
MSVCRT.dll
GetInterfaceInfo
IPHLPAPI.DLL
??3@YAXPAX@Z
strncpy
wcsrchr
??2@YAPAXI@Z
strncat
_wcsicmp
_wcsnicmp
__dllonexit
_onexit
_initterm
malloc
_adjust_fdiv
GetMappedFileNameW
PSAPI.DLL
DeviceIoControl
DeleteCriticalSection
GetModuleFileNameW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleHandleExA
LoadLibraryExW
MapViewOfFileEx
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
wsprintfW
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
MessageBoxW
FindWindowA
GetDesktopWindow
GetClassNameA
GetWindow
USER32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegDeleteKeyA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
yex(C
003*Ef
strncpy
_onexit
E9"fV;
Lf@v`w2
??2@YAPAXI@Z
MSVCRT.dll
MSVCRT.dll
_except_handler3
IPHLPAPI.DLL
GetInterfaceInfo
MSVCRT.dll
??3@YAXPAX@Z
MSVCRT.dll
9z}&t\
MSVCRT.dll
MSVCRT.dll
wcsrchr
__dllonexit
MSVCRT.dll
malloc
_adjust_fdiv
MSVCRT.dll
MSVCRT.dll
strncat
_initterm
MSVCRT.dll
_wcsicmp
MSVCRT.dll
MSVCRT.dll
??2@YAPAXI@Z
103*Eh
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
_wcsnicmp
_initterm
MSVCRT.dll
MSVCRT.dll
__dllonexit
MSVCRT.dll
PSAPI.DLL
PSAPI.DLL
GetMappedFileNameW
GetMappedFileNameW
_wcsnicmp
KERNEL32.dll
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
MSVCRT.dll
GetWindow
KERNEL32.dll
GetModuleFileNameW
KERNEL32.dll
UnmapViewOfFile
USER32.dll
USER32.dll
GetClassNameA
MSVCRT.dll
USER32.dll
OpenClipboard
USER32.dll
EmptyClipboard
SetClipboardData
USER32.dll
USER32.dll
CloseClipboard
KERNEL32.dll
MapViewOfFileEx
KERNEL32.dll
MapViewOfFile
wsprintfW
strncat
KERNEL32.dll
wcsrchr
CreateFileMappingW
USER32.dll
USER32.dll
MessageBoxW
GetModuleHandleExA
KERNEL32.dll
strncpy
MSVCRT.dll
wsprintfW
_wcsicmp
KERNEL32.dll
LoadLibraryExW
MSVCRT.dll
RegDeleteKeyA
ADVAPI32.dll
DeleteCriticalSection
ADVAPI32.dll
RegCreateKeyExA
utIX-jmV
ADVAPI32.dll
RegSetValueExA
KERNEL32.dll
ADVAPI32.dll
RegCloseKey
RegQueryValueExA
ADVAPI32.dll
ADVAPI32.dll
RegOpenKeyExA
KERNEL32.dll
MSVCRT.dll
DeviceIoControl
USER32.dll
USER32.dll
MessageBoxW
SHELL32.dll
MSVCRT.dll
USER32.dll
GetDesktopWindow
SHGetFolderPathW
USER32.dll
FindWindowA
FindWindowA
USER32.dll
USER32.dll
FindWindowA
USER32.dll
FindWindowA
=vrm|O
103*fU
#mo=Yg
fr ~x|
XM,7FD
|qP[jh
jYgI+B
&Q_.C]
v'|g^M
5$|K`z
Zrm|Oj
Zgsrm|O
zO{M:
$$f%kA
$$f%kA
B^t(rR
*|yps'r
+ByExC
qhpffA
103*Ef
*D2m|O
jli*D
qpsj`f
kMwc3$k
cLi1m
Dv+Zgd
3103*Ef
5Z/GTf
s1103*
co0'fOS
q~pPTFJ
k/md~x
YB\Jrh
#hg3l/
64NItzxu%T
)|SJC~Nf
a@l)zU
L<!@hY
Yd103*
K{jzh>
/6!D4o"
}="AiZzh{-^
rm|OuK
b</uNt
%'9)Dr
sW103*
d$<S`f
d$$PfV
rm|~^B
gyxI2-<
&%Lz~q
)EL{hd
'RLrrS
2_Z&ooZ>
aZYu$kpo=
g$?uo$
*wom?^
gz-fto
KzV$lxo
f0xo;`'
sE\sqo=
'so?mk8
etxoRog
Z+woDG
@`chiJX
4LJU\3
*6Tgvo
Xqo|`}
_qo\`$<
_`&zSs
wAuI(|Z
AJ+_&\
N@B}1{
1R Z~k
+'1;
bE[sd]
?b 1[!
h_BFpM
kI1-5
SvO1ss
;1tJ8
[kM5pif
{pu"u
m3kdEk
(cD48^
u>@\r&p5
KHp"Om
JIvDhm
vKE,8m
tA1,:#l
pl/^-m
uq{ZT-l
,fDal%
fAw+v)fV
Ne@dP~
<)SYS{5;]
5:]H;Jw
D;lZCZ,9
eZbOZv
EbP"iZ
6$jZCc8
??B:iZ
d+80ccZZ
Orh\gZ
"EBiZ[
H)kZ[A
f5b,$A
vL55fi
Sf6fw"
h"x_RH<
h+MM)|;
!i@9'h
Hj{n#6
!vIfW$
!DJu,N
%^(-=+AH?
0TV!Tp
vOy!5>
?+@ovRi
B@c(:U
KyK6RZ
2m3$j=S
S6;/Qe
[d1?-2
a%uXCw^
tOa~uR^
>V8lDa
RIWB\[
w.xs&R
Y}|xNI
Coh(m|
$^o+C#
/6!`FW-q
Y!%hl
kq.s1B
W7bu1'
?@4:|1C
Rlmmu1~
s1*VBN[
z1CZ,9b
u19xk!
Ft:o|1
X<%8zx?
St1k >\qHt[
=%t1|J
z>u0Gs1
)E9^s1
Xw1]\\
D/Yz jt1n
w1[[c^TI
V67.1f
qpsj{-
km6vx>~
<_m!/?
8~DT>+
10h8Im/
[kb*a#
q$ayGA
9=s!'8
K\e5\
{u@_SdA
(^smXZ
zajL,5A
`V8(Mw
l0c[@?;
YJo=|7
g'Isw`
CZytD[G
pe1.&peM
p^,$?ce
K:|vT0
$#KuSI
uxW4'N
Rgc/6!``
B5yc3'
@`cb@|
`@&phC
<,H27~
j}@]n+
f5cw#b
XiYXq9
Ez>$5F6
;._'^g?
;T[d}>
>XM*`r
K^%A4;
atR@?E
RQTH;V
@dzGuxp
|2}0nyX
ZlUetg
Fm|4'Nf
)PE_BY
~$rcRS
7]&q{T
@`ct.VU
``f@y3x
J<[[B
.~_qos
|zMD)w^
qpsj`f
-r{B
103fS`
Sc#|e^A
31{-z+
n\(p<
-.4JZ=
Y@qgHh)
fD)~]3
~@h%&(
cXRRY,
cco*v~
;<NgQfja
:@rmN*
iNZ\O@
7{g*|<
\TXfMR
QJ.@e)
cV>D1d
OHZDN
<U "4a
>zQ`$TY
#R8=ZY
vcSO/4nD
|w94KY
#[z~2(Y
H~:1hl
|`$;K{
2+l|eu
Z,ovhw
b'qOtK
[-(?O
g-wUUL
v'Vgg_
r%\{0?
nEP0<<
Rgz<x=
)XW3U)
i-]/A`pGS
Q03*ES
1oK{i:+
='2YBblE
.3h/i
>[K)SE
^9x{gQ8
4'Nh*J
O\T+7$l
/6!`9c
SC!A}w
kLw{)|
|]!nRb
/YK-&P
n@|euL
% a'5"
\nh*5b
uKrx[va
5*A0?=
B/?p.;,vj
mg/j0d
CrxD,?
ze^:od
{.z7xh
&j?sj0
X|,c8 j
]kavZ<
]4S4Dt
nECKcS
q5LG^n
eq@,3c
rxDova
\^$WE
j?f5C1J
@\b=Yu:RZ
~S8!*m3
V~;d({
AQ'&cZ
X*\VJe
-;M/!8
72niy:hpr
dyzSD
d; ]>$
dCWXts
dVKX?0bbh
`+\H<Q
<~01Qx
/!Z h1j
.I0iJUn
9,]%/]/
K8J+;^$j
X/OG<3$
.i.LL
@oePfT
,G"|sN
;z&psO/'d
;103*^
j*Lvz)
.h1Am/
zijA0q
8qmF9:
pY=\Z ova
=)7qxs
5_QiGqG%
jl@Hhl
Ws9O*tV
03*EXX
Z#OKws
uC6g/f
|!$yS}
vEI unwT2\
`A%5"]
}103*\
!X;&rE
1N4b4T
Fb(\tb
%VdbC>wdMd
0^103
|;OL2-<
|geNe.
D$ IfN
}l4GQp8u
03*EB"
Wm$'hLDg/
rLo#BR
/6!`T4m{
p6MK"o
103*Ef
OxkH&Xb(
_HQ(~{
L9"rV(#2f
f,Kbp]X*h
qpshS&c
QhG)g/
^}fta\.h
[zCQ>9
Aq]}3O
sR+L!;
N3}g/J
w:z&.WH
KpxR+B
VdQh:3
L1{e+J
103*Ek
\r)h-w
>R1o{L
JLh-/E
^Hi-'`
xA]s*x
$nXV-'p
qpsh :
ovah[@
DRMdM.
2[WKK9
p3 -''
&(g*m$&
`v;,vi
6!`h5Q
h5E_^W
i[x=E^
9E"c=Y
(Ky<Ef?
{d2{7E
tx7)5E;
&6EMZiq9
_F"&;E
6EZQ=uR
M*7k>E
qLf;E0
M5ED-N
SO89E^
9EqConOq
+4Pa9E
_en@'$;El
L=r6E"cy>
A~F,6E
Y6E9mn
0{>`8E#
-g^69E
Nj,irc
P{VI@J
M[*=0#Y
DJP2Nk
R`[r[<
{tHR|
'b+3}+
C3103*
{RCJMr
oxxk7h7&'
d$ PfS
C]03*E
nfA[m}?
VSDmT?
0K4'3D
5'c/wC
#0xV4Yt3
/6!`fR
s;03*Ehi
?{:_'8
+U[[C
MJGdhx
_zRYc#
[^Csal
7)I#M+
(Yd5'G
)S03*E
v9M*h7
*p1?P4D
"h)jhx
4'N.m!(
?03*EU
|x<7sn~
xX*%^l
rlK5'Z&n:
;'/i3S)
#:cY`l
='^*r>
|:}3O*N
8a]Q>R0
Fe.<)$
|Cl.Z
Lb+j0!k
ovaaB~
Md,e^2
U/re?
JgR03*Edx
oq:<o8@1{|
a!VuEp
8~gw"D
W/6!`f
~b(GES@;
t=Yo&e}
|w2IYD;
E4h<ghl
$MI==+
4'NJR=
/6fIf6
q"poHL
%`)1t+
'b^b^b
zhscb{C
#*lzl@l
g6O4'Z
\hR2f/
'k?Csnx]
5fd{iZ
XkzLAh
udh@(f/
!0?sGhll
Zhn7m/
5<QPi10
Hzd!)%
CV?0US(uk&a=i
Z.zAb*L
4#$TW
$&RPOk1
yHxM_?
fIav#cm
/6!h7%
8FA`wdM.
?uu[+,s>
axJ3t:
\ PK)H
Cc"nuX
#h*7m/
A|= |a
Zm2|3hl
&IlPa\l
103*{l4\
#174'
Jg4qpsj
DyPDRr
g4b]z
\[^?o"
5C>]+uW
qpsjM>
4'Nh8Q
rm|OhO
JgC/6!`
Tb]|eRh
rJj+4'N
Jg&m|O
R{wksQ/
Y"aw.|
S-&3rm|h?
%faJ[Vfa
#1T&B&
R^`rF*
E_6sXr|
/+}Q5K
aq0^tOd+
+2^ax_"
)-pY+r
0!cq@x
@,3ZCcsT=W
O#s.H$L
P*< 0a
ova]=2
Gpl``N,
z jOXk
iW<<C+
"UtP]t
&g0d]b
8X5nkE
fX,krl
.SCJo&
IZc:}P;oC
Ih&3*E
JgL4'N
tgq"jn
8ZI<UOG
$mxNva
baDE)8
{?-I?[Q"
]>(qKL
ThQle/
>(;|Eyr"
RAmAphl
lx(5$W
0"OZqz
0jIsr{
0[^CsK
RKJc+*
*c,t:s
rm|O'G
$jTF]A
g~yfOn`
nyXi#
$to\Ed
xR)vtr
mhLZ;t
%ylx1f
dpp_~zU
c,tQa
9q`lx#)H
~\}yG2
Y,FCij{k
*c`hB5
U9GBa3J7
JEdEu
oM! W^
/All6!`
t^h:SG
K$8YU#
@!(zVY+7
2P77lx
K=GF_'
3lxP99
6wr_Hg
&Q['o;
0.o5tr
)H+m@b
c?dlx*:7
+{A4e-d[
^YF/N/
~r_sW6
:"3;dk
bp64S%<u^?3
Mv"b%I
a^TF<.<
fF]A*k
@Q_om}
1'j4'N
}HS/_6
niM[<u
69h+]e
v:QpY"
)8 ova
`)l"li
8qpsj4
R`r;K"
103c(*x
$>UB+
"]hLoe
(@D'Sc
LP$Eo/
rm|O`-
z|P[hl
}CVTfP
x_1'{H
rm|}E h
u1dZNO
*-BAk
I`[H1P
Vl1{f01'i
D-idt5
ilk[^U
t=|`pT
Mr#,\?
Bkx?03*E
g-;t-<
C_.NqX
,.m!#V
5;'kxQf
8q(p'`
HvHZ>N
rm|tCgm
[*&nZ u
qpsjz:
b|M<=s
nmUrcT
'{suSp
YX@]j#
103*EB
:uc/wC
ED,IB#
iyaNE6l
J=n6)k)
nd{yX
Y;p@g7
Vy8'(^
&\Zjhx
u103*-
[<L^K[
F9DS{f:
s5KL}J~
Hl?!o=
mU}M1#
$>Y_`!pj6D(
rZ[WLD%
JeBg^V
2{G,,|"
}s&/'1
fGi~3@
h,g1vV
79jos`
sv&Puq
Xck2F1
F[C`,MG
K]pwIU
M7]<~'7
k=f_O{
!Ebe3eJV
}<>$;w
<,r>(D
zq\!F]
;z nh/
8[Qp*%C
N$C^9z
`F3Qvs
|V5arj
}tv5L[
mA~,*`
4GbRO4d
)j#P!U
#;USVd
~os=es=
8378D8
lA]ee#T
CN{=+Cteqi
@i6x~Z
Md/.bs
"C?-D+
M$&05"X=
!z}Us[
fo263o
ZH:Pmi
l!AU-~
d3[$B5
#3Fmvd
3BZ53Y
|<8*ga
aT fRj$
!)ku0.^;T
~ieB:!
dnxj"(
l\JB3&
D-$MJtS%
4yY=~FX
WfE-(IU
b/;?9!
UoVG<U
*\}Mfu
I>afcHw
c7?"<
]z` uP
h`b`My
&@<a`NY
8C"fLu|Ag
5^DH6_
yi){7!Uh"t
EKfa?^
E=:u}P
4<:z (
,~[Xu}|Ca
CZ4l'}
t/P|GIe
PO699d
y[0/K~
eTrZQ29z
2;umZj
:3#/SD0Z
gbG+CZ
\~hwrZ
CL!}w]
FjV>rHK
[pOX_R
O-YYWnZ
Xa/?p>
RMBC]&
O<'e>\
86Sq#~
TksqXK
8@X8jF
fZQ/X!
>Vv5f_
,%A_-5
Rds;Xfp
6)P\_n
/[sOq^
v3Lk6SgT
rL8pGa<,
fsK_B'
8jg.I#*
m)Vk&n5s8
8b;~;_@
0~d5B7
]q~AtY
ia"-:T
}X/XghY
7zC0p^Q9
)-Vv0O1.
acr@ik
=}D4V1
,|+.'XVV
!(X}oA
YTHsA{6
@e5Da1
j1!lo{
Fl~-\'*
o<4Q8O@<S?
9W,`k(dF&dt
.PpyVC
+,"1N"
QKE?@*
E"szCp^
K:Ua6o
"='}v
2\CnB-
\&`Tm[
d%(%Tm
z>@U]a
ekj%LR;
n@mDL
"6cunS-
$iMS4)huc(P
R&Y?%:
nxd4WB
bV#{9FZ
u[t4I{
CVJvND
dxkhqV
w3}<"6I
MgQ#=F5
fs#n&]
2lbBz6
|c(x\V
Ni,q>N
1wn4gOg
B=}Ov4!6
n38hF<m
6z,1#}
PlCK({
0^B6.^;K
uVS=3U
":l3R^!
dKx-n
IwKwB2
!.7wsH
I@JoZf#
L+^$T[N
[Ktt~\%
.vv{,gB
}O7\cU
^eHdd>
hqb@)d
!clgq(
MFQ[Wj
:,Hl(F;
hNKDylh
:=L\=I,
Nv3I~.
q--c0c
u_EJzV
O;aQ6w
iGo@yE
NxJbmu
kFj7O#
%m7(XjcH
umBXP)
)c'"/J
.:wnCB
1j[{k@
/Hch8M
0ti$9BU
Ci~t\CSbM
HkDM,}[
k$Z'by
;}d+@#
(-Zg^5m
s2UwqZV
*ysaNe
D;)BOW
=Bcz|5
&UL7XH
![Wi[2
gHH4E/o
u0qL;5n
nm0pyI
tXU1{.
\HLdkv
U~@O:+8
BtAB*~
+n:HT~
-_Vz*n
D!HLzT
Ypu6RB`7
O2-aCR
4^?g|[
&0$xCQy
;oBM*\
?e/FXy
u[pk[5
+0.X/],
?'\|8BW
/QO[o$
s(j+|U
J5Xx0K
#V2\ h+
3="\JvrN
|><. .;
_x/RO3v
"`[1Y/
)L\K+h
A;$yY@
KERNEL32.dll
HeapSize
GetACP
MulDiv
$SetHandleCount
;PatBlt
]GetStdHandle
GetFileType
hGetVersionExA
IsChild
HeapFree
DPtoLP
HeapDestroy
IsBadWritePtr
LCMapStringA
LPtoDP
~LCMapStringW
RtlUnwind
.GetStringTypeA
GetStringTypeW
GetMenu
*GetOEMCP
GetCPInfo
iIsBadCodePtr
SetStdHandle
SetRect
GetTickCount
CompareStringA
GetFileTime
GetTimeZoneInformation
CompareStringW
GetEnvironmentStrings
SetUnhandledExceptionFilter
TerminateProcess
UnhandledExceptionFilter
GetCommandLineA
GetProfileStringA
tFreeEnvironmentStringsW
gFreeEnvironmentStringsA
GetStartupInfoA
GetEnvironmentStringsW
RaiseException
FileTimeToSystemTime
FileTimeToLocalFileTime
SetEnvironmentVariableA
TlsGetValue
TlsAlloc
GetFileAttributesA
LocalAlloc
GetFileSize
LocalReAlloc
lstrcatA
WritePrivateProfileStringA
GlobalReAlloc
TlsSetValue
lstrcpynA
GetEnvironmentVariableA
GetProcessVersion
GlobalHandle
LeaveCriticalSection
EnterCriticalSection
FindClose
SizeofResource
DeleteCriticalSection
GlobalFlags
GetVersion
SetEndOfFile
LInitializeCriticalSection
GetThreadLocale
GlobalFindAtomA
GetVolumeInformationA
GetFullPathNameA
UnlockFile
GlobalAddAtomA
LockFile
ReadFile
FindFirstFileA
FlushFileBuffers
MGlobalGetAtomNameA
DuplicateHandle
GetCurrentProcess
GetLastError
GlobalAlloc
SetFilePointer
lstrcmpiA
lstrcpyA
5$lstrcmpA
(KGlobalDeleteAtom
GetCurrentThreadId
GlobalFree
lGetCurrentThread
LoadResource
lstrlenA
FindResourceA
LockResource
WideCharToMultiByte
LocalFree
FormatMessageA
InterlockedDecrement
GlobalLock
GetModuleFileNameA
VirtualAlloc
CopyRect
IsBadReadPtr
FreeLibrary
VirtualFree
ExitProcess
HeapReAlloc
HeapAlloc
WriteFile
SetLastError
LoadLibraryA
WinHelpA
GetModuleHandleA
CreateFileA
SetPropA
GetProcessHeap
HeapCreate
USER32.dll
CloseHandle
PostThreadMessageA
MultiByteToWideChar
GetCapture
GetProcAddress
GetClassInfoA
GetTopWindow
RegisterClassA
RegisterClipboardFormatA
GetMenuItemCount
GetSubMenu
GlobalUnlock
GetWindowTextA
GetDlgCtrlID
GetWindowTextLengthA
UnhookWindowsHookEx
fGetClassLongA
CallWindowProcA
GetPropA
RemovePropA
CreateWindowExA
DefWindowProcA
GetWindow
GetMenuItemID
GetMessagePos
SetWindowLongA
GetMessageTime
GetForegroundWindow
InterlockedIncrement
OffsetRect
CharUpperA
RegisterWindowMessageA
wsprintfA
oSetForegroundWindow
InvalidateRect
aSetWindowContextHelpId
SetWindowPos
SetMenuItemBitmaps
ModifyMenuA
GetNextDlgGroupItem
GetFocus
GetMenuState
EnableMenuItem
GetMessageA
MapDialogRect
TranslateMessage
GetWindowRect
DispatchMessageA
GetKeyState
IsWindow
GetWindowPlacement
CallNextHookEx
SystemParametersInfoA
IsWindowVisible
ValidateRect
IntersectRect
GetLastActivePopup
SetWindowsHookExA
PostQuitMessage
SetCursor
MessageBoxA
PostMessageA
EndDialog
GetCursorPos
SetActiveWindow
iGetActiveWindow
GetNextDlgTabItem
CreateDialogIndirectParamA
PeekMessageA
GetParent
GetDlgItem
DestroyWindow
HideCaret
b4rho0
I.u_4r
I.*[4r(n0
Y4rhn0
I.5X4r
E,77.G@FrU>
zB@D@y
Exf7.GEFr
SDrawFocusRect
EndPaint
ExcludeUpdateRgn
DefDlgProcA
LoadIconA
ShowCaret
CopyAcceleratorTableA
IsWindowUnicode
.SendMessageA
GetWindowDC
ReleaseDC
BeginPaint
DrawTextA
9IsWindowEnabled
GetMenuCheckMarkDimensions
{RInflateRect
MessageBeep
FillRect
GetSysColor
TabbedTextOutA
IsIconic
DrawIcon
UpdateWindow
GetSystemMetrics
GetClientRect
EnableWindow
AppendMenuA
CharNextA
GetSystemMenu
LoadCursorA
#GrayStringA
GetSysColorBrush
GetDesktopWindow
ZLoadBitmapA
GetClassNameA
PtInRect
LoadStringA
SetFocus
>DestroyMenu
ShowWindow
ScreenToClient
SetWindowTextA
GDI32.dll
MoveWindow
MapWindowPoints
qpsSendDlgItemMessageA
SetBkMode
IsDialogMessageA
AdjustWindowRectEx
4CheckMenuItem
rClientToScreen
OffsetViewportOrgEx
m|SetViewportOrgEx
ScaleViewportExtEx
ASetViewportExtEx
SetWindowOrgEx
GetClipBox
SetMapMode
ScaleWindowExtEx
wSetWindowExtEx
GetDeviceCaps
IntersectClipRect
GetViewportExtEx
GetWindowLongA
GetTextColor
GetWindowExtEx
GetMapMode
SetBkColor
GetBkColor
CreateBitmap
Escape
DeleteDC
ExtTextOutA
TextOutA
StretchBlt
PtVisible
PSaveDC
CreateSolidBrush
BitBlt
GetObjectA
oledlg.dll
SetTextColor
ole32.dll
CreateCompatibleDC
GetTextExtentPointA
.9CreateDIBitmap
CreateFontIndirectA
DeleteObject
comdlg32.dll
GetFileTitleA
CreateCompatibleBitmap
GetSaveFileNameA
GetOpenFileNameA
WINSPOOL.DRV
RectVisible
ClosePrinter
#OpenPrinterA
MSVCRT.dll
RestoreDC
SHELL32.dll
SHGetMalloc
PSAPI.DLL
RegSetValueExA
SHGetDesktopFolder
RegOpenKeyExA
SHBrowseForFolderA
bRegCreateKeyExA
SHGetPathFromIDListA
RegCloseKey
CoTaskMemFree
CoTaskMemAlloc
OLEPRO32.DLL
OleUninitialize
CoGetClassObject
4CreateILockBytesOnHGlobal
CLSIDFromString
rStgCreateDocfileOnILockBytes
CLSIDFromProgID
StgOpenStorageOnILockBytes
CoRevokeClassObject
zUCoRegisterMessageFilter
OleFlushClipboard
CoFreeUnusedLibraries
OleIsCurrentClipboard
OleInitialize
COMCTL32.dll
IPHLPAPI.DLL
\TOLEAUT32.dll
Safengine Shielden v2.4.0.0
nADVAPI32.dll
DocumentPropertiesA
SelectObject
P103*E
eAV;fX
tGetStockObject
KERNEL32.dll
USER32.dll
GDI32.dll
comdlg32.dll
WINSPOOL.DRV
ADVAPI32.dll
SHELL32.dll
COMCTL32.dll
oledlg.dll
ole32.dll
OLEPRO32.DLL
OLEAUT32.dll
MSVCRT.dll
IPHLPAPI.DLL
PSAPI.DLL
HeapSize
RegisterClipboardFormatA
SetMapMode
GetOpenFileNameA
OpenPrinterA
RegCloseKey
SHGetMalloc
CoFreeUnusedLibraries
strncpy
GetInterfaceInfo
GetMappedFileNameW
HrCg@b
VS_VERSION_INFO
StringFileInfo
080404b0
Comments
CompanyName
(Future Studio)
FileDescription
FileVersion
1, 0, 0, 1
InternalName
FileSplt
LegalCopyright
(C) 2001
(Future Studio)
LegalTrademarks
OriginalFilename
FileSplt.EXE
PrivateBuild
ProductName
ProductVersion
1, 0, 0, 1
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Generic.Malware
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.6bb3828d5bd61e4b
CAT-QuickHeal Clean
McAfee GenericRXAA-FA!6BB3828D5BD6
Malwarebytes Malware.Heuristic.1003
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005239691 )
BitDefender Clean
K7GW Adware ( 005693e61 )
CrowdStrike win/malicious_confidence_100% (D)
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.36308.kv0@aakdxxkb
VirIT Clean
Cyren W32/Trojan.HPC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.NoobyProtect.M suspicious
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Dropper.Win32.Injector.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.98 (RDML:MeA6SSOgtrMzjEDLxLyRJw)
Emsisoft Clean
F-Secure Heuristic.HEUR/AGEN.1237427
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Injector.tc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus PUA.NoobyProtect
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1237427
MAX Clean
Antiy-AVL GrayWare/Win32.Safeguard.a
Gridinsoft Trojan.Heur!.03010021
Xcitium TrojWare.Win32.Amtar.KNB@4wlm66
Microsoft Program:Win32/Wacapew.C!ml
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-Dropper.Win32.Injector.gen
GData Win32.Packed.NoobyProtect.B
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Leonem.C5391929
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG RATX-gen [Trj]
Avast RATX-gen [Trj]
No IRMA results available.