Static | ZeroBOX

PE Compile Time

2023-03-12 23:20:46

PE Imphash

f0e8db307701582115b12426e04e3928

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002b2d8 0x00000000 0.0
.rdata 0x0002d000 0x0000eed0 0x00000000 0.0
.data 0x0003c000 0x00001f34 0x00001200 3.33677971121
.PB 0x0003e000 0x003f2273 0x00000000 0.0
.o)= 0x00431000 0x00000514 0x00000600 4.06812622104
.$w^ 0x00432000 0x00700c30 0x00700e00 7.97454578672
.reloc 0x00b33000 0x000006cc 0x00000800 4.15574843158
.rsrc 0x00b34000 0x00076d95 0x00076e00 5.61456699924

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b8f16c 0x0001b641 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00baa7b0 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00baa828 0x000003f0 LANG_ENGLISH SUBLANG_ENGLISH_US SysEx File - OctavePlateau
RT_MANIFEST 0x00baac18 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x831000 DeviceIoControl
0x831008 GetTickCount64
0x83100c Process32NextW
0x831010 CreateFileA
0x831014 Process32FirstW
0x831018 CloseHandle
0x83101c GetSystemInfo
0x831020 GetProcAddress
0x831028 GetModuleFileNameA
0x83102c IsDebuggerPresent
0x831030 GetComputerNameA
0x831034 Sleep
0x831038 CreateDirectoryA
0x83103c WriteConsoleW
0x831040 HeapSize
0x831044 CreateFileW
0x831048 GetProcessHeap
0x83104c SetStdHandle
0x831058 GlobalUnlock
0x83105c GlobalLock
0x831060 GlobalFree
0x831064 GetModuleHandleW
0x831068 GlobalAlloc
0x831070 GetOEMCP
0x831074 GetACP
0x831078 IsValidCodePage
0x83107c FindNextFileW
0x831080 FindFirstFileExW
0x831084 FindClose
0x831088 MultiByteToWideChar
0x83108c WideCharToMultiByte
0x831090 LCMapStringEx
0x8310a4 EncodePointer
0x8310a8 DecodePointer
0x8310ac CompareStringEx
0x8310b0 GetCPInfo
0x8310b4 GetStringTypeW
0x8310c0 GetCurrentProcessId
0x8310c4 GetCurrentThreadId
0x8310cc InitializeSListHead
0x8310d8 GetStartupInfoW
0x8310dc GetCurrentProcess
0x8310e0 TerminateProcess
0x8310e4 RtlUnwind
0x8310e8 RaiseException
0x8310ec GetLastError
0x8310f0 SetLastError
0x8310f8 TlsAlloc
0x8310fc TlsGetValue
0x831100 TlsSetValue
0x831104 TlsFree
0x831108 FreeLibrary
0x83110c LoadLibraryExW
0x831110 GetStdHandle
0x831114 WriteFile
0x831118 GetModuleFileNameW
0x83111c ExitProcess
0x831120 GetModuleHandleExW
0x831124 GetCommandLineA
0x831128 GetCommandLineW
0x83112c HeapReAlloc
0x831130 CompareStringW
0x831134 LCMapStringW
0x831138 GetLocaleInfoW
0x83113c IsValidLocale
0x831140 GetUserDefaultLCID
0x831144 EnumSystemLocalesW
0x831148 HeapFree
0x83114c GetFileSizeEx
0x831150 SetFilePointerEx
0x831154 GetFileType
0x831158 FlushFileBuffers
0x83115c GetConsoleOutputCP
0x831160 GetConsoleMode
0x831164 HeapAlloc
0x831168 ReadFile
0x83116c ReadConsoleW
0x831170 SetEndOfFile
Library USER32.dll:
0x831178 EmptyClipboard
0x83117c GetClipboardData
0x831180 OpenClipboard
0x831184 CloseClipboard
0x831188 SetClipboardData
Library ADVAPI32.dll:
0x831190 RegSetValueExA
0x831194 RegOpenKeyExW
0x831198 GetUserNameA
0x83119c RegCloseKey
Library SHELL32.dll:
0x8311a4 ShellExecuteA
0x8311a8 SHGetFolderPathA
Library WININET.dll:
0x8311b0 InternetCloseHandle
0x8311b4 HttpOpenRequestA
0x8311b8 InternetOpenA
0x8311bc HttpSendRequestW
0x8311c0 InternetConnectA
0x8311c4 InternetReadFile
Library KERNEL32.dll:
0x8311d0 GetModuleHandleA
0x8311d4 CreateEventA
0x8311d8 GetModuleFileNameW
0x8311dc TerminateProcess
0x8311e0 GetCurrentProcess
0x8311e8 Thread32First
0x8311ec GetCurrentProcessId
0x8311f0 GetCurrentThreadId
0x8311f4 OpenThread
0x8311f8 Thread32Next
0x8311fc CloseHandle
0x831200 SuspendThread
0x831204 ResumeThread
0x831208 WriteProcessMemory
0x83120c GetSystemInfo
0x831210 VirtualAlloc
0x831214 VirtualProtect
0x831218 VirtualFree
0x831224 GetCurrentThread
0x83122c Sleep
0x831230 LoadLibraryA
0x831234 FreeLibrary
0x831238 GetTickCount
0x831244 GlobalFree
0x831248 LocalAlloc
0x83124c LocalFree
0x831250 GetProcAddress
0x831254 ExitProcess
0x831268 GetModuleHandleW
0x83126c LoadResource
0x831270 MultiByteToWideChar
0x831274 FindResourceExW
0x831278 FindResourceExA
0x83127c WideCharToMultiByte
0x831280 GetThreadLocale
0x831284 GetUserDefaultLCID
0x83128c EnumResourceNamesA
0x831290 EnumResourceNamesW
0x83129c EnumResourceTypesA
0x8312a0 EnumResourceTypesW
0x8312a4 CreateFileW
0x8312a8 LoadLibraryW
0x8312ac GetLastError
0x8312b0 FlushFileBuffers
0x8312b4 WriteConsoleW
0x8312b8 SetStdHandle
0x8312c0 DecodePointer
0x8312c4 GetCommandLineA
0x8312c8 RaiseException
0x8312cc HeapFree
0x8312d0 GetCPInfo
0x8312dc GetACP
0x8312e0 GetOEMCP
0x8312e4 IsValidCodePage
0x8312e8 EncodePointer
0x8312ec TlsAlloc
0x8312f0 TlsGetValue
0x8312f4 TlsSetValue
0x8312f8 TlsFree
0x8312fc SetLastError
0x831308 IsDebuggerPresent
0x83130c HeapAlloc
0x831310 LCMapStringW
0x831314 GetStringTypeW
0x831318 SetHandleCount
0x83131c GetStdHandle
0x831324 GetFileType
0x831328 GetStartupInfoW
0x83132c GetModuleFileNameA
0x831338 HeapCreate
0x83133c HeapDestroy
0x831344 HeapSize
0x831348 WriteFile
0x83134c RtlUnwind
0x831350 SetFilePointer
0x831354 GetConsoleCP
0x831358 GetConsoleMode
0x83135c HeapReAlloc
0x831360 VirtualQuery
Library USER32.dll:
0x831368 CharUpperBuffW
Library KERNEL32.dll:
0x831370 LocalAlloc
0x831374 LocalFree
0x831378 GetModuleFileNameW
0x83137c ExitProcess
0x831380 LoadLibraryA
0x831384 GetModuleHandleA
0x831388 GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.reloc
@.rsrc
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVregex_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AV_Node_if@std@@
.?AV?$collate@D@std@@
.?AV?$_Node_str@D@std@@
.?AV?$ctype@D@std@@
.?AV_Node_end_rep@std@@
.?AV_Node_end_group@std@@
.?AV_Node_back@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Node_base@std@@
.?AUctype_base@std@@
.?AV_Root_node@std@@
.?AVfacet@locale@std@@
.?AV_Node_assert@std@@
.?AV_Node_rep@std@@
.?AV?$_Node_class@DV?$regex_traits@D@std@@@std@@
.?AV_Node_capture@std@@
.?AV_Node_endif@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AVcodecvt_base@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
l\>^0W4
P8cMf;^TC:
kHH|F}
~Xs{D\
GetOEMCP
C=y2-N
Z8^J3R
~"`l8~
>S^_n+=g
:FjhAr
5G`H)0
jmP+)|G
D1<$A^
f?7)3FG
jZ<gso
{*RR?<
m`:19qh
fNv=eZ
fNd"sP
^[^=b}
QA*y2O
TzOjd=
+F18iZ
OjV,X e
4t #`{u
45%vXV
*C#//_
d\g9LK`_
fxi!xv
*-V]Ey-*
+imNj~
^.Ny&Q
"dDC?u8
:(q1KZ4
6WOkDEj^
,@FqHJ
N;1:[MI]
VL##q#GQIq
[}JF'f
uOEQ@ur
ls`,iUBCb
,P3b#T
DClPz%
Riif'o
|(=fRm
%C]$nqaO
hgaJK+r
t9"Wy;
FzNw-F
K+LDAf
ce) &.0
qfn!+k|
sB}#w
S=ri-W
rGqsbj
C9 >ZzYG
n4{Q%a>f;
mY@_iPg
!` @$J
2f6we5Z
;\:h(D8
)WRO/f
F+PztmE
2iCV"*
WqV1@-'
'B<YMN
SPrt]N
$'30@
p('@~73
8(_m!t
#d@`Ow
J}(97V
_h`j=Ts
1t1dHl
"d|v0:
6m23z<
EM%"]+
]`A{gX&
;,Nw6t
)>H.4'
mqLOUe;d
c<#:dGKh
U _Kpf
_+kb|8
@PZD!X
|Q/1|F
3+E@Xk
;TtDdr@(
40|I;R
=|S4b#
h{mq6|
]8=4,^@:
08-z2Q}
lEhaLQ
YWzgKW
};^=po
awj-YF
6|>eOa
"aj0OE+
*.$2`b
2zmkgn
aa~OL^
sr{yYc
&Jfb'8_
bo4g k
+enW,L
[vd3|#"
f:o.m$
c/PFw0
o 4/8{
@?R"Ha|
hXU?UWO
t|[cbS
wn)W^
543"m8
*cm5Z"
]?+<l;
obR?#0
g#dvfx
J6{*I#
Wd1LY0
70o'RZ
qBi=<
$NHYV]
J{9{4D!
r=hiyVU
pm<$[;a
Q#{[~h
YKiXmt#
o^1jNg
!b <f
P/zEg Gm
~d-.'DBz
r f4ok
uQFX+h7f
,pK0F-7_
2&;* M
]4dfF
(M67e@a#
{G"GPI
OzByvv
sq[/?&
1t=bc6
&)oPD"7&
HGYs}s
VYwpwC
UQkvSF
rZs?2b
2K;rRY
gK3nzM-H
XR'(sw{
[[j81j"
<dN^-[!
\({Fjjw6
KC}-l^
5(Dlo/
`:BDYJ
m-G#'+
jI;8xe
V'i>4U1
SMY9zf
cB\ !3
*rF+21
t?cU5k
Lm(pi>
o(d@4~VD
gs"(G-}
~rL4,5
HttpOpenRequestA
4V>2L:
NF{K M
&NDAhy"
`gKn<7
:1:m|0
jS~EWqx
u[x[TZu
.^KrH)Z%
)yb>xp
uxvq$q
S}#rczT
|7=?{@
ei';w:bv
`ZJ-O}J
1z%52NdG
1Gyz.N
jBI+uOO[G{'
w/2'SCdk$
wf;/UCmb,
:xnH"%_n
ID{$&$
1/"NjS
/.z<O[S
n`^Pc3
n%'o`M5
-XSOE$j
M&wtTC
HP'?xWP
Q3p$VD
eTcLUS
u=/>$4
)<;qx5
~<>NN;I
S8z=c?
y_JF9Fdj>
f?B"-6o
{b}zs^
Hc-&XS
78KHOS
Os!]tk~tV
#@^`2g
!va<S%
#*.o2g
6"Z#r~
"Y]K}hH
Ls4d#o
$%tb#r
CL<0iN
|~IF-w
1~9%(Nh
:Ge3Y0
1<S<6N
1cMv*N
b)OZ2N
vlr#}b;
*9^D0N
oje~$xH
TbV0C_
N/*N$
Gzt#w}
j~0PZyG
)Zh16oyXW
cj1Vm1c`>
i]26Tk
D)B{<Q
5gXBlP
tn|Jd2
`YUSXa
XT0gJl
Fo=o#!
?s#c!Y
qMI% ]
HU?BE?g
\e8wGO
}7\%HFS
|d\E[7f
64Lb|4
D1<$A^Mc
~/428
<pYl')
A_l!R$
O->K,F7)
N}GTn_
R1S`"X
GetSystemTimeAsFileTime
`{G\FTk
fN+ R'
;]<E&>
@BxDG[
{<}eKN
!4%Yg]+
K>+r](
`2wJ(P
UG5dD8
81e<kz
GetCurrentThreadId
GetFileType
3Wc4xN
k<|>J,
z_$WBFJ
A)"k;5p
`@O{rl
?aZ_1P4=
-OM%/,
[)?>.$Vu{
"7;klz
CloseHandle
/rR'yhZ%
o;;!+~
\o)3!"I
=W_uw=
o/ [qs
O8xlPb
dG45O
b$=O0!
)LC3>~x
$Z9BT>~
2+sw/G
:1'AK9
vBrEQ$
tx66.z
'n[dFL
dt6QVJ
#k{fkv
)V},D'ju
<xZ+4aH
h,t4:
$FQ4[b2
IsProcessorFeaturePresent
m?iRV>i
Kck!YN&N
0H^VZ!a]
r}G=*|
0?pc IG
N/r<I]&
dDSWpUZ
oRC@Xq
w~KfRC
rU#X|x*
|j9?l@
b2EUU|W
[J4ZX,
t.e9y>Z
LJLQq9E >
z6mk?7?
m9)N<'
6VYUyA
1^q4+N
1*=7+N
==nUl4
qU6hARA
j=kjZ:
8;V+?L
Thread32First
92Y3:fM
(y}K~p
vO{]:gD!
MJUJ@es
sT<Q"Q
RQ<X_y-
wN['IC
!((7H;
CharUpperBuffW
SetThreadAffinityMask
8x-d"N
&%FrQ
?N@>M$R
,WLvm8
;a%#@Ah
Uu^c5:
0c2?-)
C|O7Ecr
oh~|A3
v=_A&\x
wtI&a\]:
P{]b5Lt
0)%*4O
hosm;H$
kAq"3
WYy@^$
>ThUQ`
vb4^Nb
=h\`$(
.G-8tj-x
po:^o
y1X8I6/
B 8;L
+ufKB
z_PhnQ
9Kr\(D
=M_d4
*eLQF\Y;
oIeSf?
uJ?)/8
&+XlW&
g4:fE;
Aa(NI/[
aIclf_R
(="!JT
CreateEventA
TlsGetValue
tyZR%p
1F/;PV6
1gkX[B
l{Iz\|>
oO*/h8
Cn[esi,
1,$A^@:
Hx{*&HLG
,e}oe9
%D EDJ
GetSystemInfo
qF5il_
1r-E.N
&>v`?x
D1<$A^
yG'6Z.D
eli)Ye
HttpSendRequestW
1)6$2Nwd
-pnG-6SG
0tL~AV1,$D
cmw(Cl
\TXzrA
:breEW
Eg%z)0
{ezFhx>
4[K8n`
7d=m.2
kX?y=5)
Y9qFi>
dTyG5]
t=55D:B
oUh7_R
BQ,DrV[
pNg3iX
mOuSJ
5s+b'3
klHyRud
#~t>0s
l7Qb9l
1OhV3N)*
GetCommandLineA
fB3j/&L'3F
.BW5U-.m
*9~Z"K
3AZ82b
cQOL[[
}oon\(
1Pzcd&
e<YuF
&DJ$wu
c,D!r;rz<9
&}>cE7
Qh7(.N
X3UcbL
{"p,mr\:]u
0@M!if
1j=e*N
Po5YIoT]
1?0}4Na
1yG34N
BzkN_%2
I6`v4*
OzhnrXP3
hh5YqGS]
Process32NextW
4a*%|4
R9xXm{y
caiQj)&
51$;(u
Vpq&<%
|M+?f
A$#E"y
/6Y?f]
Qfw"%]
1DcH(N
"[h$JL:
D1<$A^Mc
AVD1,$M
&V2M16
%f42l(
qH(trt
Dr~Wa{7
Dt[vBX
"MwGJX
ud>BMPc=A
zl+#+\*
k)_g8*
}|CTzo
A;)IpR
@TV)qu
Sl9(#'0
.:Yl+Gj
^$~|(\
Gcqc1H
L+uWe1G
||1N&/
qM.(GVi
gk|xN2k#
)w4G.*"<
dDKX{z
09&OP>
m3LrN=
1_vea6
{T1I0c
iUM~vm
\x]|s'
FreeEnvironmentStringsW
Od"]h7BT
v~vkso
~%DI9Ft
{FU-s'
#{HuZ|
D1<$fA
14$A^Hc
aPtl`Np
1z-(3Nlo
H\0t>'
nix.?`
2hlaca
m9b$jN
Hl--xkZ
ehi^Uo
d]-{Z|b
6O:AVD1<$A
q?qA_A]Y]fE
P;/m$H
!D<NP[
vy?1zb6)
1D#&%N
gw 9]L
_:tnY[
N#<}PsI
K`f *[
ShellExecuteA
-QlC2p
d{tv{$
@>V+ {8}s5
6?.vpn
gGk)Zy
!"bElo5k_7-j
fb3EGMV
EC}WO
$Cz,?&
POa8:=
].rmAo
? cp+c
^ !`:(
gXcL16O
sf}=XA
/^p\p;
ZuuwPl
}+X"+#
]P&U#`
7vR#Xccf
2vm!_%
2WUHFmh
IsDebuggerPresent
\#&l[:
1U(}zt
1MJ!'N
7 WAf)
M_@:J(
` R~P'%
QSi_eZ
8FQADG
Hlo)OTC
>aAb y
.dawv+
>aSpLn
L.8;Q:2
idAVLc
Id*5x]
!dD*@0
m?N78f
gQG SR`3
GetConsoleMode
qv<~AqK
Wz+<3D
uo1E$f
SjdFcm
~n 5NiW
WqU!6
xoqS)f
^j$PnmS
k02lG
sn`#Ci
/otlh
!epS=tu
f:KXg+|
p7eO&N
,x|c!0
?%"eQL
xd* U
UA]Y]^A
1[tL'N
*NPV
J[VS\m
ll8,Pb
z(s/rB
v>%noW
S_%'9yD
ZJ1z^R*
N;2oA\fE
]^AXfD
k9_,fp!
?}SF\D
FKKlwX
{pPA!s
LocalFree
8q(aYxv3
bF~YB
Uie%?u
+;2*DW}
c{NM?9
lu181A
9_x(V6
GetLastError
|I}~yP
fS4WBJ
JD1,$A^f
62~c 8
lnFObi
'nV`F_
:GcJ2So
d(~'/Y
=2?Bzm4
W(ai4K
8tNPQg
(nwmFY
UHr=RZ
+xNu]+J
cU9d<&
{o$nNv
C]sLCR
~nH?4/
F4RNnN
G^8y;Ib
_,<w:_9e
=s`*eq
1UzM&N;
;4UGVD
~*Ls?r
'SlYXoa
IDG'A=
]dV8#zt
oC^xOCm
g#2CJ0
QO/!,u
GK>xaX>j[
"ovrMP
Tc$N%.
z2* 0C;
othgf[R
W~qo`T
hgf[F_
AV1,$A
1Bu|&N4
ShG=4>
Zs@)jt7
rTf6u#
zD1<$fE
52aHq-
H0N.`C
Te{gV)
TW)Z]b
ZDziAE
1=BG$N
1,$A^Hc
5$Mv":
CreateFileA
sCmL_|&m
KPW"L'
/&XV~/
x&]iH!*
L60&+_
=|_,4kXwyrs
Xpb"?N
/<lhilS
2Od!@h{B
e8'^<q
y#5Iv
e Rwg'H
RY9[Qp
csXC5:p
v\#yq{-
{Ov(r*
,5yY#+
%S+>m
TerminateProcess
~+/@'(
ni$cdi
rP.Yq
<C\E#iC\
E=uW9~U
UO`f:l
q/7B(1
'N=og
4bg 5$
c}31<t
rZ1Jb"5
~S]S5q
1D+(&NzA
|VZT28
/04jr9
+NDtc
3J-yf;
2U')(G$
f,>qA{,3
e3G\dp
6co(:&
YZJKF'
BXW K];d
n#luL
8C29Qy
x.z\<Fn
1Y.+=N
FileTimeToSystemTime
"YX*+4zH
1t"-!N
g#CZL5DC
2uFeav
('Q/Co
Y-hOz~
Sra&y
|m:Wne
AXAYAZf
^'2nI;
},q!D\
ScAz"[
~dP'ZmF
YPKWFW
F6`6=U
}mJJr)9
AJ;?0?L
c}o`v4{R
,=Eu}T
N6d5\]
Gw`JfV$P
Cc^_*7[
uAAs:`
1KTm>N
}LvLbOd
h5}r0l
00fE6yh
eE+er vW
!={7u,)m
52aHq-
~uHgNr?
oQkSPK
:*FW/
TlsFree
1r-J'N
9o#.`"O[
(SQTm]
x[n@t/
z_D74<
'tdHNQVi
AV14$L
7uGE{WT
1[<B>Nmv
"(Fp[}g
Tidpsf
dO#]C{ ^
"Z=y4
_611%@
G_#ts\
(m wA)
\NC'(U
iYahl\
8%u$usU
"rh3d,
JPdaB
*F?2s1l
pFD#$(
}~<k.`
,iMC~ O'
Me_>&
FrfJQt
LeaveCriticalSection
u*/l50
AqpieJ
nGDFh{m"
#9VL^
&RyzI!$Vc+c
an~,)}
jnX|{V
6SgyqJuO
S9~w{g
7S-R_M
oT9|<E
vg].9~8F
"u3laZ
Xj(HAj
0-QBVE
f)V+'i
$DnauV
1Z-2>Nl
dTg&$o,
~aIrBi
hbTn?i
$)V Uf
O1vFc$j^
I=gBAA
F(>x3f
.BoRNV
>GA^Hc
uh_5"w]f
Tg.[)vW
Ya9f`_d
.afKZ-iPk+
76'K*:d
P[7{ />m
G"">ypU@
b{f=DG
GetCurrentProcess
SNNp
ko;<S+
NN(~!
?-P'=g
Nvw^2$
'i%*dp
E>H)j5b"
VT,<C0
N)XBRk
`w@fvA
g2{2AW
WfH^e.
*PT{e"
w\6+9w
GetProcessHeap
soPq0K.
?Om{fn
y=7|ET
1fx>:N
Sj&LJE
&JqYVaE
(&[?8LA
TWe:"_
3D/![l
XWy{"Q
KAb]J
?2@uO`
1(/K&Nn
3vb, ]{
8K2*
kNR%uU{
(f;||)2
OQIt^4
G'].w *
&Ia+!>
zJU/+C
&KA`wB
qKD_AL3
%D1<$A
BG6^+
Q#&q A
@_* =F
n"?^J$*
fvY1~
:'L[~G
Df8p>P
0Y1H|0
i'@gY 7
JMY3M:
T4/_=[
=zq"YP
cE!x?A
3Sany<
MVWjld
jn*),8
;eQcfA
K9mmII+
{ieapgh
JgC/[Y12
"1j2fR
SuspendThread
sECV!PU
6TCB/3
tUORT\T*dE
H,s+ Us
=hfg'w
LqfA:
QueryPerformanceCounter
InitializeCriticalSection
`.MXuL
~\.RR}JtX
p)2]ih
uzv'Ks|;
J_.&D-
1[U+?N
KJ 9K"
hd5|q0
ouxn+
K+mv*-]a
/?!6Td
X5Wj|F
Cr^]rRV=
%)\Tx6c1
,V?v)BW#
~WMomwP{
q& )@
1a66!N
=dPFj};K
WaQzf9<h
1]j9!N
o-08"N
@zu04v
{O&hc0J
x6u0&2
HeapDestroy
Np3]2M |.
]7Z_E8
K:S&Os;
`1$d@H&
xYqj=J
@:R?0i
t/>$WS
6I9Q?k
QZPow$'
D1,$A^Mc
p}~k~t`
~`FA!G
PHjQiS
u,F;7JA
.(kX}v
9r](a~[d
wP&O8@
+v{Ak)dNx
f88x9m
LPt.|W
q=|/ 4
-<h`|5
aT0]QSG
z<m_J;
9=c;>J
W8),g?^
]f3hK;
\g9.@S
6wk uY
9b!3|s
f=?+f;
AVD1<$A
Vjs&Cu
0N^hYq
y{GHxTp
?AVD1,$fA
V1,$fA
A^<!Hc
[NKgpE
&tprot
@o9E3
{a*]kz
#N(zQN
hGM?R+
g6m~6?
;7y1j>
2,2-5[
A38}q4O
GetCurrentProcessId
!H[^]f
d`c(.d
W{3gN;C
uT5xtT{"
<3-6SG
w5kfa}
rWJVbNB
aLZ`;uC
WININET.dll
[bYETQ
Bj9jWi!I
QON0C:
jOC@~g
S:E~ks
\B]k){
e-)Rx&3
6O:AVD1<$A^Mc
SyInf&
X;.Vms=
rf6^j
D(k)uA 4V
1j=-$N|
BGBY~aW
l%cKB)
[q&NIS
|AU8]K
m;t2<2
1:`}`3
}R8@MUO
PV|3`Q
Wh|<P
?5~'8B
K>!1{9V
f:eBV=
q#3vS\
8FD7*U
0VpLf;
1D~W\J=
=59FRgyl
p3DizL
1)VW:N'
^'2nE:
AV1,$A
~H$@9x
LgCGH+r
Lmu^p4
^HD-f
i0@de%
1j-p:N
+WW*T0
qVADAQ6
G:X5w=/
;Lz+<;
5[O9Qf
Rd-L~8o
`)]JMCO
uKzHj\
(g6>13C
Fq@iyg
z"|~>,L(
1=*T9Nk
Ob|IN
p&t-R~
l<N`$D
759[0^
5<IPl__'
SbJvce=
c^9?d)
'Udv\
k=GY[:0
PJg1W=
]Q^(mV)
1nas9N
(yOEp T
p/v$ob
1$"C"N
YpEqbi_~
5kxg.7`J
P]MDV+h
vWAuEbX
+ukZHygh
?^_:wi>
bti:c2
;#H[7y
4n|g"wL
qMDzAJ3
ID+'>
eubwXFe
Thread32Next
?r:[?kE
JM)A*0
Bq6dhC
*[\c~+
|t&_,wk@}
)P3Jp\
1A>D>NO
'OXA.*
\kQzzA`
[a u,/
A)uVpC(
A;vs1}
GQ%NUO
a%1sZ`
`{j('K
a%wg3
1yI\@Fe=
L8xt2c
NLZ5<j
?,~,C9
fsS-u4#
x6fHAv
lP)[kILM
a';N #
l;JeMwrR
1;tk9N
,zvo%z
8jxFLGcv
c3X"'jH
+J`pcSU{
PG&N:$
>=%)W
dJS4>N
sY q k
*;',.x
1Y6Q;Ng
q}5#2u
MFs8O;
[nf77UR.
3k`j`5
[e33r_
1DzW%N
:<-}3I
1jw0 !
1af$9N
Hg5"f;
g-~s/%
~,Ib'ns6
Bc}k$Vd#H4
=[^4:
1|B='N
b4I8oN
fS%mS}
1L#n%N
8=Xrl+
hKUBq=
0=?NrS\H
T,se?>
Un`Pc+-
rMAd>B
A!frXj
4Ou4)M
4\PpZc:
zoUb?P
Q3|#&:
Q>_`eN`
{_6du=
winl#d
EG--scQE-
@QOKLR
\Om>:>~
Vk^&o!
L#.Eq>D
FreeEnvironmentStringsW
t^*EfE
#e|\{m<
%Nf(t$
iRJ)Nw'
g(zv~/
1sU8&N7
]oe4fX
+UDk)=
mU9[N-
|y?;N/
5$Mv"3
ResumeThread
v#5ytb,
}6F*`(
~gN+1!
c$(699U
Q@AN9-
ptDNypr
vg>RoU
\(WvBm
bY7mh@?
JImRj[
P7)E3;
51[c.PjR
r94)3x^W
1'XJ#N)"
=o@J$&
1POH#N
TYSzdgq
1T;N#N
vagqnbnqR~
1>iY!N8#
'i##3pw
Z{qi<b
hq:|a7
KF\+Uh^%
'O8^c',
2zBJis7@:{
aMCc1LE$
1cU\=N7
GetSystemDefaultLCID
OTQM~+
!hLKh
+eec%+
gj'_Q:
AVD1<$Mc
{n<rK7U
e!>}b8
1tZF:N
>X7JTgmq
m*s~gs
y)}NC9
jLRlq$
1-M II
54en2>N
$m|Lq|J
:^E 66
\-*y2-
TYwOZ5
GetUserNameA
'SM0lM
~!tA3>u3
z&u;Wq
2N3zm&kv
0$0u(C
zm`C.0
xdv uC
M5 KpW
b#lDz0+"
~7?]gAB
rz,va2
.JMK9vT
-)Rx&f
e3pI`k
z57N{"
*yl<S[#
Bikd+F
v+}Ss%kL
A]4Tmt
0_h=ZU
(U]4d(
?y%La
D1,$fA
%h(Ezf
{OHusnw
tO+Pie9
BQ)w>*
rL?hkz~
A)Poo/
BAV14$A^fD
1@_?"N
Blj~\p
BQeKh|P
:@CD[9
Fp:ORC:
w_;AVI
|kZ4i[!
1N#.uo
Xy,b5_9
Gj/X/e
#<<}m@
hjYP,#
"h6[qP
h{tXa4
varGy
'lW=2-f
2l.0?lV>
w_;AVD1<$A^D:
AVD1<$A^D:
!$AVfA
1%Jt"N
\ 4Bl'C
q$p1A#
aM<C0D
jL-3ZKZ
GHi@wO
|@Sbf;
1M"|"NS
fOT;"v
<>@&Vhf
;$@t`=
q)p%}2
FlushFileBuffers
&I}VK*
1?PW"N
_a!v01
S"&QN[W+
Q#ErHi
P[2c^)a
wZcV2Mb
%LKUr;
EncodePointer
C&hEuW
[VJ`A"gj2J
(raF\8
<ZUg9!Z
>[^i'+
cSc>j[
>r;;[t
-~vm**Wd
HUa(aRWO
>17PQm
Y _~%4D
d.yc;"sxnv
[[I|GP
9.!i$
7]!lTs81
fhCX`:
`XsyS\&
+C?k&0i
@rTn,r
c{_m[g
4_U\>q
I2L>}
jQ{wveX_
nK0i`Z
fgU5@:4
mQ}su9
X|GPb~
AVD1<$D"
kB);_y
K}w]og`
AVD1<$A^Mc
AVD1,$
=;@NO;
._q5A
)0JLdY
8Q~6/{
d:6i/>
NuIs~@
1WY5;N;
E@@AQd2
.7OnE:5
?nD=MA
-d|2,A
p\e9I<
>^!,W'
qqQg8i
v?L!48
D1<$A^
`0Gr-k
8i=},
1P?H$N
qDLKCJ
5[O9Qf
;>xz"
x<UMZ,
BXqS-L
-.T#v2~Z
WIk43`\j
ozE?fN
ooII@(
_B:HFZ
~6skec
6N'YE
&o'kMM
d7~G&8
yiF q<
Zbn[URxI
@F}zK
PeGCAWE
RNOr;+6
D1<$A^fA
($=-B;4
1a~p=N
Y[DGAB
?lQpT1
)"*"3q
=i* !x1
!+j(Du
&m4q!
mu<;k{
A %X{f@D+
MaWL54
.IWA|:
MbRTId
zk[WJl,
Wo$ghh
(b1ee(
|U!7XN\$
zrO;$;p
:!cS=
1x'I#N
gE5v2"Wv
@wxcrC
.?A0?/;
"Ygh"e
aQI$5'[
%f7|,]9H
1|;J$Nzy
\D1<$A^Mc
1)'M8Nu
2]uB:D
-/]!Hxk
"|_!Z}3
>'N\Lo
*iF.,Y
l-[g5x
55Y$C!9
fLx|eJSY
KMX\23
K.`+?6E~l
tj`;;l"
1.9S?N
1>I~$N
qf=caU
:%i,%u)
t(Od0?9
o(PZ!5(
7,}Vr
C9}je"
U)7<>
,a3v=o
?OK/wM
55VvwBs
%$HUU.#|
FSA S`r
^3ad4'
k!7Nm^
eb)| db
0SeqDJ
TlsFree
F<&149
5rR|FG
c[1>t'
1,C2>N
14$A^Hc
::t)ac
) Z#R
gI^o6`,
vKd!j(
lw8?dj
@"-P7[u
DsX>5S
9_8ioc
>EmVSk
5$Mv"f;
|adp>_
1uqNTa)
ugvYk?MGD
5mk[:`o\
Fh#=MH[
E9=SYeA
1|zM>N(
VaRo2C
p1gA%
*g"])"
GetEnvironmentStringsW
IBl^V,
j\X%kI
j),")f
}YmhW,M
? SFIU#
jDtwaV
cc=Y*}
;2uqj;
t!]'|&
JpxuiQ,
x|V H{!
A8A&^
tK<'y)
zL.VR6h
Tze36s
x~kZ}2
reTJ]Q
=|mt)G31
RtlUnwind
!H(CH`
1DL/TA
-5ZN6(k
S~?]@s
{JL'KM;
M&UV}!"
IuC9`AZ
K:5\LF
R&=m[*DM
5'jV]Z
uY{fic
Yq~GG%
hy^<jk
SetEndOfFile
NLZ5<j
D1,$fA
;b2gNsg
s{;1#,
d2}`K.
wg@^@.
^zuVW},
kb~ 2d
Mw4iS91p
+*!GUZ`
[J1wB0
b_{\J+
H>P7Q7t
L-0Sx+S
wi\X@C
2bx\LC
O9mE,;
1hiGWk
gn#zT0
A=vtX
fv5SPm*
Lj+nlA
/=-_E`
;1B%Th
osB95
>Oi<&:
*OCOfh
4\(O{j
AbLE1UE
!z,Uf&
.J"Q#M
hkEDcY
,dy?+]rM
ADVAPI32.dll
{2A_K56
M^X.}Y/
_La!X;
1:u@&N4
`^TTPY#
V2M%f5:
3Yj:4.
5q/85e
1V) !N
?orc<'3
_Ybh<Y
@|w?q
=&@Or
XTO=w
G](`{\
g:*l~+b
#eNig
w?*Kb|
1e5$yd
ubC3>rA
!5@~ck
D%$QyQ
BN(0KE
GetTickCount64
*2,=y^(3
*A_seg
72:T>|
.1X&Fe
%Uk,-uT|{
GlobalMemoryStatusEx
7Ilt~Aj|
7'J5^z
v1wRzb
l0i`:/
d#jPsIc
VirtualQuery
AVD1,$A^fA
O]CL[L
QL&'LB
B'gz<XP
S[!O,W[
HeapSize
P`yTD?
(Qrlnh
>>$Y5}
I[?em8
q?n'*&
,8XUik
Uv9Z~}
kb7=qS
ss.{_\
0\9P6]~
J4pBCW
riB?iN"
(98EAVA
<Rp4AVD
GetStartupInfoW
hqf'G"
eiFN,s
'jb{m>
[XXI&$
Y,S~p%\q
kn[vfiHfO
fAVAE_a
'C@RbRaal
&LR/uo{|r
(NU.:_v
7<@Nf="
@2#qs?
d08bNY
v>}3,
g3}Y&,
eJO_b$
76[?;y6
D1,$A^Mc
-nn|O[
f=:-Mw
Y&$tQH
$R#khh
D2=Vd@
,y):cP
'h1stF
:ggv@`5dI
ZmRkqn
&+1L[)^a
_[0)A.
4x?+r$
.PW1, -b
OkuJ $i
a/#.b
y:)D0p
dZiVre
T3>TMNo
u,p:r[
Vt8?fsO
{p|LKw
vrtofb}
7?zY\z
fhaR2}
<Go\#4315
PhdRG,
&IxJq
kg.SvC 0k
VirtualFree
CdD1<$fA
\52aHqf;
D{eCQP|;`A
ToN9K+
MrP1m
o9[TZN
ph%#]@z
<m<1=nl
&=Tm:(
v]{9{br
rtt>=5
6e YMe
dd;96"
E~T4N[
1)/@ N]
rl@>vC
GetProcAddress
b4a|ka
BOa|(Oi/
c?/5lc%
0A\A_A
t*}#D-
dC1Q5J
Y.9Pi)N
/-5(Z
BFdRrA
oB !_EW
]}b5pubBF
e=,GMPX
AV14$A
/A^fA;
?>?7|X
kJ2O>o
r<%w"Q
/X({Wo;
njVDE
|F8.>@S/
AFjDvF
LFof$j
w[k?[tS
1z06n!
aLO\1}"z
GlobalFree
GetCPInfo
|&Y=(H
pH_)e2
T;yJm~
UB+0S
38<GTIFgFY?
,Mev{8
{,D_tC
#A_).i
%afZl%=H
i=/j9N
_+r"Iv
etg-#%K,
!Vilu!{\
}-Zdl/s
v mGR4
Y9Z;Cw
FgnZO/UA
ZiTRjn#
MultiByteToWideChar
AV14$I
$A^f=c
Av3M;
GlobalUnlock
5[O9Q3
r1,$fE
;/t^N6
}D<YtJ
m H>E:
AV1,$A^Hc
f~9b?P
zuL6{+
cyo=W:l\f
Q_gi5Q
"8>M.6
`46#TC$
Ce}RJ;:
@" PY0}_
4XWNf_
1;="9N
GetModuleFileNameW
\3sy Fc
OpenClipboard
P{]b5Lt
!xK'JB
Qh^v-`
`6~:#j
?j+BPg=
YkYIf4
ht*sNmDu
VV5(-S
bSTd5?
x {Ua`
xJ-&(M-i
LCMapStringEx
0=Z l!
1Z&~>wm
BN]-/
B!00Fo
'A^fA;
DlUI'D
5&*y~6G
zU#7n1
:['VeT
w^S^[C
h9Gsa[
*6;NkX
Gh[&[;V
L,P<3'
$n.eNr
<]H2B_
~=X6`g
5s+b'f;
AVD1,$A^Mc
|&c 'ly
c$jrBH@u
hAVfE#
DeleteCriticalSection
,kG}j-vrcI
HREm,J
h#c%i
X]1UmR
xS%YTu
Q0\'>)
D1<$A^f
]n-i/f
yuX#gc
<=j#.$2q
1o r;Na
5)lwfb
LeaveCriticalSection
03 7YG(
D|B,Tf
c-+>BZ
.h-FLyGH
"rZthQ
[l&Q9.
;iBAdX}(/;H
Zw&\Bn"
~@5wC\
"ro]:8.)
1zU1=0
j#AA{J
@gWK7 y
R9G+UN
jWi{ZP
&?1Fw6
q?4yA8C
l5lX/P
f=jqf;
Q^u_H_}e
ys]]#b
cfd2}j
:ydQ*iv
14$A^Hc
1VOyx"v7
aA!S5G
~m9iB[
z0H]*
"p.[H'
=?)a3>
j:fQ(E
HeapReAlloc
1fI}"N
h\5G+$<
Ccq=A:
F=W{_i
gcb}q"
1/028NqR
vku&gbl+
*.W*=7
GetStdHandle
Ia?K[e
}D-b-]5
MoHjSC
9HP:nQ
|7rLo5EY
xl|+(o
!f(;,;ac
i9zap
B[jIc&
LoadResource
>14$A^
b;C!IX
V`Z!HthG
f;g^K)
X6&}bR
I-Om/j
%6d0 -
R(5$Mv"3
17x`:N
1z|/&N
1%;!:N
1CT{8N
0$NEDF
3g.lG
<>g=@
,b$hb1
D1/>iL
}wRg{5v
^_;HnXL
N6w:?
c23I2;
/Zkt]
h3"9X4U
E7fJu0
;VGOh\
q>kIjQ
^Te)C$
14$A^@
f=k2f;
"A^fE;
*u!L'A
dEQIhg%
-L'y;w
H`63<SD
rjlm'^
aDoa:qIO
11gV!N
3bGz7{
ouo2t$H
CN.dX
1RlN=N~
UU)h@<
Gf`)0p<
@X6m2`
]>/0|V
1AVb!N
g(F2 s
.BQbG-*oB6
bMIAYL
Dn`$6NQ
}O]Fvv3
(-08"N
/~;h~w
Uzz$e}
x~>WHyI
X%=<'t
lG>N&(
"*u<$^
u+i?L2
Y]#]:4
^T~/WFC
FB(=M,
?L#G_
2&k1xT
x>Os#k
88@'@(M~
OFUYa|
LhXL,q
Process32FirstW
DecodePointer
O1fL6;^O
YA-~[/
)LTUn
?(O/Dc
sn#Su7/%'
^#p#rSt
c*s+c0
TckSlc}S~c
s,cESFsj
3s5sUc
<cCSDsIsL
Ychsl#q
c# c%3&#(
)c.#/c:3;sJsWcd
#"s#s$c&s/
GcK3PsR
wC|s}S
cCdSecf
jckSpCqC
]c_caCb
osp3r#sss
v#wsw#y
NSO3P3Q
f3jsm#n
PcPsRsS
0s2c4#@#C3H
-S.C1C3
C%3'c)
kCmcnsr3w
536S7s8
>3?S@CD
d3esgsj
;CFSMsSc[
s"C#C&
Ss!3-
-3.S5#9
8s9C:#>
s"s&3)S+SH
$3%S&s'
JsLCVcY
1LEn}se
?1u+h.
^O!mpl
j4haH2
8LkOsg
t+Jqy4
CreateToolhelp32Snapshot
}n@#ki
1k,t9Nmn
1FX;%N
[AkpnO
>.Bq66
0Je2+
ZA[[A\A
]^AXfD
D1,$Mc
`2j%UG
EyRyN`
'[q34_
GetUserDefaultLCID
^;m<MZ
".a#9VUd
qY/yge6aZw
a%T8/0
*oH'$vF
~vOhN(
|CMpe\
Vf~4#.w40
TmfVT]_
jbt7~0
XNv#SB
n*\CD<
_s/1M.
R8muSi
6c9R}<l
YtR>:I
=xL4Yh
InitializeCriticalSectionEx
EnterCriticalSection
AV14$A^Hc
x[8Vfx
4mWzN_
Gbr4/V
5_FoD":
f[]zDc
9)6Y@h
'wW#.V
rbEY@+
IcCBz-
U-`"6-
#Q1jj^
/2g_ZM
rlV*wE?H
5b"NtW
<mdQ6d]|
~t@+Nfu
Ry{(l)
FlushFileBuffers
52aHqf
-QIHX<Hc&
+q$LoJ
2DI=N.0
2zJhxP
mKp&Ru
mu9h-M
G+bjaX
T &T+)
N-uh;y
IUp4Hj
c;t4*&9
bnuqO\
VnJ=3"8/o
L$6adlm6
HH+T6(
VAfx$`|
;k{k?3*
:l3u41
hg5h`y
Jm{O@y
X;-=)5
=z{rltuS
)~bwV$,
-^9yq#
Q@O_9#
AV1,$I
,;m9:
FJHV|?OO
*bI)\-/
b\"o4G
Y#c',g
O,7X(v,{
;K7I"n
kB2+ [
F&_[n)
*txFV1l
p;pY $
9Odv.\
1MZ$:N
1hFk&NT
v95G8`t
jv*P<
uC2!V?g@]
KQOq;d
wU;e{wt
p5;IpW/
:?8?gw9Q
n8!d!
oqo@>x
It:CysM
dp~0Tw
+-ky p
,&e8DS
fpR,-_
A0N;c,
1iG[$N
D1<$fA
n-pEWj{
\wXWUT
VwP1-
m`uwP1u[
rVa`O,+
suwP1E
Dy3W-c
5|Mm~"N
InterlockedDecrement
o'N(A/
'[-H<3tCk,
CG5Pz)0
'wr[[
1rm:N
x|X3H{/
I?2oBB
S=f1,^tu
_Q-`_(g
ak9WY ~E
f.uo7IK
$itzlv{w
%KZF;=
/XJx_=
sY^7C^)
N4V6=
E5GFu20
1Wx#N
.d5A/d
xdJ+d9
Antivirus Signature
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.fb0deff37fe12bbc
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Malware.AI.2943530042
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZexaF.36344.@J0@aagvjPpi
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.AHG
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:El+nAknUmndjOz85+GZe6A)
TACHYON Clean
Emsisoft Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.wc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1254260
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Caynamer.A!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX Clean
Cylance unsafe
Panda Trj/Agent.MK
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.