Static | ZeroBOX

PE Compile Time

2023-03-06 18:52:41

PE Imphash

f37a61d96b690f7b944e7449374d4371

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000228be 0x00022a00 6.46792969349
.rdata 0x00024000 0x00009058 0x00009200 5.7432492827
.data 0x0002e000 0x000c20e0 0x00000e00 1.92730940344
.pdata 0x000f1000 0x000013ec 0x00001400 5.31776472978
.rsrc 0x000f3000 0x000001e0 0x00000200 4.7113407226
.reloc 0x000f4000 0x00000168 0x00000200 4.20197030007

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x000f3060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x140024128 WaitForMultipleObjects
0x140024130 LeaveCriticalSection
0x140024140 DeleteCriticalSection
0x140024148 LoadLibraryW
0x140024150 GetProcAddress
0x140024160 CreateProcessW
0x140024168 FindFirstFileW
0x140024170 FindNextFileW
0x140024178 FindClose
0x140024180 GetDiskFreeSpaceExW
0x140024188 GetDriveTypeW
0x140024190 GetModuleHandleA
0x140024198 SetFileAttributesW
0x1400241a0 GetCurrentProcessId
0x1400241a8 SetFilePointer
0x1400241b0 LocalAlloc
0x1400241b8 GlobalSize
0x1400241c0 GetLocalTime
0x1400241c8 GlobalLock
0x1400241d0 ExitProcess
0x1400241d8 LocalReAlloc
0x1400241e0 GlobalUnlock
0x1400241e8 DeleteFileW
0x1400241f0 GetSystemInfo
0x1400241f8 GetComputerNameW
0x140024200 IsWow64Process
0x140024208 TerminateProcess
0x140024210 K32GetProcessMemoryInfo
0x140024218 GetPriorityClass
0x140024220 GetModuleHandleW
0x140024228 LocalFree
0x140024230 GetStartupInfoW
0x140024238 CreatePipe
0x140024240 PeekNamedPipe
0x140024248 DisconnectNamedPipe
0x140024250 TerminateThread
0x140024258 WideCharToMultiByte
0x140024260 lstrcmpiW
0x140024268 GetModuleHandleExW
0x140024270 EncodePointer
0x140024278 RtlUnwindEx
0x140024280 RaiseException
0x140024288 OutputDebugStringW
0x140024290 InitializeSListHead
0x140024298 GetSystemTimeAsFileTime
0x1400242a0 QueryPerformanceCounter
0x1400242a8 IsDebuggerPresent
0x1400242c0 UnhandledExceptionFilter
0x1400242c8 RtlVirtualUnwind
0x1400242d0 RtlLookupFunctionEntry
0x1400242d8 RtlCaptureContext
0x1400242e0 WaitForSingleObjectEx
0x1400242e8 ResetEvent
0x1400242f0 EnterCriticalSection
0x1400242f8 GlobalFree
0x140024300 MoveFileW
0x140024308 K32EnumProcessModules
0x140024310 Process32FirstW
0x140024318 lstrcpyA
0x140024320 GlobalAlloc
0x140024328 lstrcatW
0x140024330 Process32NextW
0x140024338 GetTickCount64
0x140024340 CreateToolhelp32Snapshot
0x140024348 GetLogicalDriveStringsW
0x140024350 OpenProcess
0x140024358 lstrcatA
0x140024360 GetSystemDirectoryW
0x140024370 GetCurrentThreadId
0x140024378 CreateFileW
0x140024380 lstrlenA
0x140024388 QueryDosDeviceA
0x140024398 WriteFile
0x1400243a0 lstrlenW
0x1400243a8 GetCurrentProcess
0x1400243b0 GetVolumeInformationW
0x1400243b8 VirtualFree
0x1400243c0 QueryDosDeviceW
0x1400243c8 lstrcmpiA
0x1400243d0 lstrcpyW
0x1400243d8 FreeLibrary
0x1400243e0 GetFileSize
0x1400243e8 MoveFileExW
0x1400243f0 GetWindowsDirectoryW
0x1400243f8 GetLogicalDriveStringsA
0x140024400 VirtualProtect
0x140024408 CloseHandle
0x140024410 ReadFile
0x140024418 SetEvent
0x140024420 GetLastError
0x140024428 Sleep
0x140024430 CreateEventW
0x140024438 WaitForSingleObject
0x140024440 CancelIo
0x140024448 VirtualAlloc
0x140024450 GlobalMemoryStatusEx
Library USER32.dll:
0x140024490 SetWindowLongPtrW
0x140024498 CreateWindowExW
0x1400244a0 CallNextHookEx
0x1400244a8 GetAsyncKeyState
0x1400244b0 OpenClipboard
0x1400244b8 GetKeyState
0x1400244c0 CloseClipboard
0x1400244c8 ExitWindowsEx
0x1400244d0 GetWindowTextA
0x1400244d8 GetRawInputData
0x1400244e0 GetForegroundWindow
0x1400244e8 UnhookWindowsHookEx
0x1400244f0 DefWindowProcW
0x1400244f8 GetMessageW
0x140024500 DispatchMessageW
0x140024508 GetCursorPos
0x140024510 wsprintfW
0x140024518 SystemParametersInfoW
0x140024520 OpenInputDesktop
0x140024528 GetDesktopWindow
0x140024530 LoadCursorW
0x140024538 GetCursorInfo
0x140024540 DestroyCursor
0x140024548 GetSystemMetrics
0x140024550 SendMessageW
0x140024558 GetWindowThreadProcessId
0x140024560 CloseDesktop
0x140024568 wsprintfA
0x140024570 GetThreadDesktop
0x140024578 SetThreadDesktop
0x140024580 SetRect
0x140024588 IntersectRect
0x140024590 CopyRect
0x140024598 GetMonitorInfoW
0x1400245a0 OffsetRect
0x1400245a8 UnionRect
0x1400245b0 EqualRect
0x1400245b8 ReleaseDC
0x1400245c0 GetDC
0x1400245c8 mouse_event
0x1400245d0 BlockInput
0x1400245d8 keybd_event
0x1400245e0 MapVirtualKeyW
0x1400245e8 SetWindowsHookExW
0x1400245f8 TranslateMessage
0x140024600 GetClipboardData
0x140024608 RegisterRawInputDevices
Library GDI32.dll:
0x1400240c0 CreateCompatibleBitmap
0x1400240c8 SelectObject
0x1400240d0 CreateDIBSection
0x1400240d8 CreateCompatibleDC
0x1400240e0 GetDIBits
0x1400240e8 DeleteObject
0x1400240f0 GetDeviceCaps
0x1400240f8 DeleteDC
0x140024100 BitBlt
Library ADVAPI32.dll:
0x140024000 OpenSCManagerW
0x140024008 OpenProcessToken
0x140024010 StartServiceW
0x140024018 RegOpenKeyExW
0x140024020 OpenServiceW
0x140024028 LookupAccountSidW
0x140024030 RegQueryValueExW
0x140024038 GetTokenInformation
0x140024040 CloseServiceHandle
0x140024048 RegCloseKey
0x140024050 AdjustTokenPrivileges
0x140024058 LookupPrivilegeValueW
0x140024060 DeleteService
0x140024068 RegEnumValueW
0x140024070 RegEnumKeyExW
0x140024078 EnumServicesStatusW
0x140024080 QueryServiceConfig2W
0x140024088 ChangeServiceConfigW
0x140024090 QueryServiceConfigW
0x140024098 ControlService
0x1400240a0 LockServiceDatabase
0x1400240a8 UnlockServiceDatabase
0x1400240b0 QueryServiceStatus
Library SHELL32.dll:
0x140024478 ShellExecuteW
0x140024480 SHFileOperationW
Library ole32.dll:
0x140024840 CoInitializeEx
0x140024848 CoUninitialize
0x140024850 CoInitialize
0x140024858 CoCreateInstance
Library OLEAUT32.dll:
0x140024460 VariantClear
0x140024468 VariantInit
Library WTSAPI32.dll:
0x1400246d0 WTSFreeMemory
0x1400246e0 WTSEnumerateSessionsW
Library WS2_32.dll:
0x140024628 WSACleanup
0x140024630 gethostname
0x140024638 inet_ntoa
0x140024640 WSAStartup
0x140024648 WSAEventSelect
0x140024650 send
0x140024658 socket
0x140024660 select
0x140024668 WSAWaitForMultipleEvents
0x140024670 recv
0x140024678 closesocket
0x140024680 WSAEnumNetworkEvents
0x140024688 htons
0x140024690 WSACreateEvent
0x140024698 setsockopt
0x1400246a0 getaddrinfo
0x1400246a8 WSAGetLastError
0x1400246b0 WSASend
0x1400246b8 connect
0x1400246c0 gethostbyname
Library IPHLPAPI.DLL:
0x140024110 GetExtendedUdpTable
0x140024118 GetExtendedTcpTable
Library WINMM.dll:
0x140024618 timeGetTime
Library gdiplus.dll:
0x1400246f0 GdipCloneImage
0x1400246f8 GdiplusShutdown
0x140024700 GdipFree
0x140024710 GdipDeleteGraphics
0x140024720 GdipDrawImageI
0x140024728 GdiplusStartup
0x140024730 GdipDisposeImage
0x140024738 GdipAlloc
Library msvcrt.dll:
0x140024748 _msize
0x140024750 _XcptFilter
0x140024758 __set_app_type
0x140024760 _acmdln
0x140024768 _fmode
0x140024770 ?_set_new_mode@@YAHH@Z
0x140024778 _commode
0x140024780 ?terminate@@YAXXZ
0x140024788 realloc
0x140024790 _initterm
0x140024798 _callnewh
0x1400247a0 _errno
0x1400247a8 wcsncmp
0x1400247b0 strncmp
0x1400247b8 _beginthreadex
0x1400247c0 malloc
0x1400247c8 free
0x1400247d0 abort
0x1400247e0 _amsg_exit
0x1400247e8 memmove
0x1400247f0 memset
0x1400247f8 memcpy
0x140024800 _CxxThrowException
0x140024808 __C_specific_handler
0x140024810 wcsstr
0x140024818 __getmainargs
0x140024820 __CxxFrameHandler
0x140024828 _ismbblead
0x140024830 ceil

!This program cannot be run in DOS mode.
Rich37
`.rdata
@.data
.pdata
@.rsrc
@.reloc
x ATAVAWH
A_A^A\
WATAUAVAWH
A_A^A]A\_
@SUVWATAUAVAWH
xSA;/yN
HcL$ H
HA_A^A]A\_^][
@USVWATAUAVAWH
D9[@uQ
CLD;Ctx3
s@D9s8D
UwD9[lu
D;v0xU
CXD9[lu
Uw9F<r
D9]ot$
A_A^A]A\_^[]
x AVAWeH
|$0A_A^
D$hu)H
\$ UVWATAUAVAWH
A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
x UAVAWH
UVWATAUAVAWH
A_A^A]A\_^]
p UWAUAVAWH
A_A^A]_]
|$ UATAUAVAWH
A_A^A]A\]
|$ UATAUAVAWH
A_A^A]A\]
@USVWAUAVAWH
A_A^A]_^[]
\$ UVWATAUAVAWH
`A_A^A]A\_^]
@SUVWAVH
A^_^][
UWATAVAWH
A_A^A\_]
\$ UVWATAUAVAWH
A_A^A]A\_^]
WAVAWH
A_A^_
u\;_Ht%
\$ UVWATAUAVAWH
A9@$uWA;N<sQI
w A;N<s
D$,9D$0r
`A_A^A]A\_^]
VWATAVAWH
0A_A^A\_^
AL9Ypu
\$ UVWAVAWH
A_A^_^]
\$ UVWATAUAVAWH
`A_A^A]A\_^]
\$ UVWATAUAVAWH
A_A^A]A\_^]
\$ UVWAVAWH
`A_A^_^]
\$ UVWAVAWH
A_A^_^]
\$ UVWH
\$ UVWATAUAVAWH
A_A^A]A\_^]
x UATAUAVAWH
U H;U(t
A_A^A]A\]
\$ UVWATAUAVAWH
\$XD9}
A_A^A]A\_^]
@USVWATAUAVAWH
`HD+;D+c
A_A^A]A\_^[]
gfffffffH
t$ WATAUAVAWH
0A_A^A]A\_
` AUAVAWH
gfffffffL
fffffff
A_A^A]
x ATAVAWH
gfffffffI
fffffff
A_A^A\
|$ AVH
gfffffffH
x UATAUAVAWH
~HD9<
A_A^A]A\]
UVWAVAWH
A_A^_^]
p AWE3
D;T$0s0
9D;\$0r
9{Xt7L
79{\t?L
UAVAWH
9sXt L
9s\tUL
WAVAWH
0A_A^_
x UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
A_A^A]A\_^[]
UAVAWH
9T$pu*D
` UAVAWH
UVWAVAWH
A_A^_^]
UWATAUAVH
A^A]A\_]
UATAUAVAWH
@SVWAVH
xA^_^[
x UAVAWH
x AVeH
UWATAVAWH
A_A^A\_]
UWATAVAWH
A_A^A\_]
\$ UVWAUAWH
A_A]_^]
UWATAVAWH
A_A^A\_]
UWATAVAWH
0.0.0.0
A_A^A\_]
UWATAUAVH
A^A]A\_]
\$ UVWATAUAVAWH
A_A^A]A\_^]
|$ AVH
UVWATAUAVAWH
A_A^A]A\_^]
x UAVAWH
UATAUAVAWH
\$8L9l$0u
L9l$0u
\$HE8.u
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
l$ VWAVH
D$09P }
UUUUUUU
\$ UVWATAUAVAWH
D9d$@v
A_A^A]A\_^]
|$ UATAUAVAWH
A_A^A]A\]
t$ WAVAWH
0A_A^_
UVWATAUAVAWH
A_A^A]A\_^]
x UATAUAVAWH
A_A^A]A\]
l$ VWAUAVAWH
A_A^A]_^
x UATAVH
@UWAVH
fD94Bu
t$ UWAVH
@USVWAVH
A^_^[]
UATAUAVAWH
A_A^A]A\]
` UAVAWH
UVWATAUAVAWH
uVD9o0u
OP;H(s
OP;H8s
wL9w4u)A;_
tY;w$tTH
PA_A^A]A\_^]
WAVAWH
K<;C4s
A_A^_
t$ WATAUAVAWH
t$PD+p
A_A^A]A\_
x ATAVAWH
A_A^A\
WATAUAVAWH
{@9{(t
C09x<t
C(9x<t
C(9x<t
C,9{(@
A_A^A]A\_
WATAUAVAWH
K H9K0u
C0H9K8u
L9~PtAL9~`t;L9~ht5H
A_A^A]A\_
x ATAVAWH
A_A^A\
t$ WATAUAVAWD
d$8D8$
A_A^A]A\_
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAUAVAWH
(A_A^A]A\_^][
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
SUVWATAUAVAWH
A_A^A]A\_^][
l$ VWATAUAVAW
Hc\$@E
l$PA_A^A]A\_^
x ATAVAWH
A_A^A\
x ATAUAVAWD
|$@A_A^A]A\
u/HcH<H
H3E H3E
h VAVAWH
AUAVAWH
0A_A^A]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVAUAVAWH
A_A^A]^]
|$ AVH
|$ AVH
|$ AVH
@SVWATAUAVAWH
D$@L9wXt~
A_A^A]A\_^[
@SVWATAUAVAWH
A_A^A]A\_^[
|$ AVHcA
u3HcP<H
u3HcH<H
SVWATAUAVAWH
PA_A^A]A\_^[
PA_A^A]A\_^[
l$ WATAVH
A^A\_
A^_^H
}1$_=C
bad allocation
1.2.13
incorrect header check
unknown compression method
invalid window size
unknown header flags set
header crc mismatch
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid code lengths set
invalid bit length repeat
invalid code -- missing end-of-block
invalid literal/lengths set
invalid distances set
invalid literal/length code
invalid distance code
invalid distance too far back
incorrect data check
incorrect length check
deflate 1.2.13 Copyright 1995-2022 Jean-loup Gailly and Mark Adler
Qkkbal
v$F}%g
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
inflate 1.2.13 Copyright 1995-2022 Mark Adler
SleepConditionVariableCS
WakeAllConditionVariable
bad exception
CorExitProcess
__setusermatherr
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AddDllDirectory
Unknown exception
bad array new length
vector too long
map/set too long
\Pbk-N
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
.rsrc$01
.rsrc$02
08@P^B0
VirtualFree
VirtualAlloc
CancelIo
WaitForSingleObject
CreateEventW
GetLastError
SetEvent
ReadFile
QueryDosDeviceW
GetVolumeInformationW
GetCurrentProcess
lstrlenW
WriteFile
K32GetProcessImageFileNameA
QueryDosDeviceA
lstrlenA
CreateFileW
GetCurrentThreadId
K32GetProcessImageFileNameW
GetSystemDirectoryW
lstrcatA
OpenProcess
GetLogicalDriveStringsW
CreateToolhelp32Snapshot
GetTickCount64
Process32NextW
lstrcatW
GlobalAlloc
lstrcpyA
Process32FirstW
GlobalFree
CloseHandle
GetLogicalDriveStringsA
GetWindowsDirectoryW
MoveFileExW
GetFileSize
FreeLibrary
lstrcpyW
lstrcmpiA
K32EnumProcessModules
lstrcmpiW
MoveFileW
IsWow64Process
EnterCriticalSection
WaitForMultipleObjects
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
LoadLibraryW
GetProcAddress
InitializeCriticalSectionAndSpinCount
CreateProcessW
FindFirstFileW
FindNextFileW
FindClose
GetDiskFreeSpaceExW
GetDriveTypeW
GetModuleHandleA
SetFileAttributesW
GetCurrentProcessId
SetFilePointer
LocalAlloc
GlobalSize
GetLocalTime
GlobalLock
ExitProcess
LocalReAlloc
GlobalUnlock
DeleteFileW
GetSystemInfo
GetComputerNameW
GlobalMemoryStatusEx
TerminateProcess
K32GetProcessMemoryInfo
GetPriorityClass
GetModuleHandleW
LocalFree
GetStartupInfoW
CreatePipe
PeekNamedPipe
DisconnectNamedPipe
TerminateThread
WideCharToMultiByte
KERNEL32.dll
wsprintfW
GetUserObjectInformationW
OpenInputDesktop
CloseDesktop
wsprintfA
GetThreadDesktop
SetThreadDesktop
SetRect
IntersectRect
CopyRect
GetMonitorInfoW
OffsetRect
UnionRect
EqualRect
ReleaseDC
mouse_event
BlockInput
keybd_event
MapVirtualKeyW
SetWindowsHookExW
GetClipboardData
TranslateMessage
RegisterRawInputDevices
UnhookWindowsHookEx
GetForegroundWindow
GetRawInputData
GetWindowTextA
ExitWindowsEx
CloseClipboard
DispatchMessageW
OpenClipboard
GetAsyncKeyState
CallNextHookEx
CreateWindowExW
SetWindowLongPtrW
GetKeyState
DefWindowProcW
GetMessageW
GetWindowThreadProcessId
GetCursorPos
SystemParametersInfoW
GetDesktopWindow
LoadCursorW
GetCursorInfo
DestroyCursor
GetSystemMetrics
SendMessageW
USER32.dll
DeleteDC
GetDeviceCaps
DeleteObject
GetDIBits
CreateCompatibleDC
CreateDIBSection
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
GetTokenInformation
RegQueryValueExW
LookupAccountSidW
OpenServiceW
RegOpenKeyExW
StartServiceW
OpenProcessToken
OpenSCManagerW
CloseServiceHandle
RegCloseKey
AdjustTokenPrivileges
LookupPrivilegeValueW
DeleteService
RegEnumValueW
RegEnumKeyExW
EnumServicesStatusW
QueryServiceConfig2W
ChangeServiceConfigW
QueryServiceConfigW
ControlService
LockServiceDatabase
UnlockServiceDatabase
QueryServiceStatus
ADVAPI32.dll
ShellExecuteW
SHFileOperationW
SHELL32.dll
CoCreateInstance
CoInitialize
CoUninitialize
CoInitializeEx
ole32.dll
OLEAUT32.dll
WTSQuerySessionInformationW
WTSEnumerateSessionsW
WTSFreeMemory
WTSAPI32.dll
WSAEnumNetworkEvents
WSAWaitForMultipleEvents
WSAEventSelect
getaddrinfo
WSACreateEvent
WSASend
WS2_32.dll
GetExtendedUdpTable
GetExtendedTcpTable
IPHLPAPI.DLL
timeGetTime
WINMM.dll
GdipDrawImageI
GdipCreateBitmapFromScan0
GdipDeleteGraphics
GdipGetImageGraphicsContext
GdipFree
GdipDisposeImage
GdipAlloc
GdipCloneImage
GdiplusShutdown
GdiplusStartup
gdiplus.dll
wcsstr
__C_specific_handler
_CxxThrowException
memcpy
memset
memmove
_amsg_exit
msvcrt.dll
__DestructExceptionObject
malloc
_beginthreadex
strncmp
wcsncmp
_errno
_callnewh
_initterm
__getmainargs
_msize
_XcptFilter
__set_app_type
_ismbblead
_acmdln
_fmode
?_set_new_mode@@YAHH@Z
_commode
?terminate@@YAXXZ
realloc
ResetEvent
WaitForSingleObjectEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
IsDebuggerPresent
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
RaiseException
RtlUnwindEx
EncodePointer
GetModuleHandleExW
__CxxFrameHandler
VirtualProtect
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::j:o:~:j:::::
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::j:o:~:j:::::
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::j:o:~:j:::::
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::j:o:~:j:::::HdAQo:
:{:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
D::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::y:
:f:m:S:T:^:U:M:I:f:N:_:W:J:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
k_:B:_:
t7n::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AV_com_error@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
.?AUCClinet@@
.?AUCXTcp@@
.?AUCXUdp@@
.?AVGdiplusBase@Gdiplus@@
.?AVImage@Gdiplus@@
.?AVBitmap@Gdiplus@@
.?AVCScreenSpy@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
#+3;CScs
api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
ERROR : Unable to initialize critical section in CAtlBaseModule
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
ymsvcrt.dll
ImageQuality
WinSta0\Winlogon
\cmd.exe
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Trojan.ClipSpy.83
MicroWorld-eScan Trojan.GenericKD.65888220
FireEye Generic.mg.ef57f8d8a632b8cf
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Generic.Malware/Suspicious
Zillya Clean
Sangfor Trojan.Win32.Agent.Vhcy
K7AntiVirus Clean
BitDefender Trojan.GenericKD.65888220
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Trojan.Generic.D3ED5FDC
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Generik.ECRJPKD
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.NetLoader.ch
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.65888220 (B)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Script/Wacatac.H!ml
ViRobot Clean
ZoneAlarm Clean
GData Trojan.GenericKD.65888220
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!EF57F8D8A632
MAX malware (ai score=82)
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Undefined!8.1327C (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Win64:DropperX-gen [Drp]
Avast Win64:DropperX-gen [Drp]
No IRMA results available.