Static | ZeroBOX

PE Compile Time

2015-06-20 21:05:39

PDB Path

F:\Projects\7妹子\20150606\Server\Release\Server.pdb

PE Imphash

3eef63a9074cade023a62e2ebdf31860

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00013d95 0x00013e00 6.66371165818
.rdata 0x00015000 0x00007174 0x00007200 4.90093363447
.data 0x0001d000 0x00009760 0x00007600 3.35559342261
.rsrc 0x00027000 0x00000290 0x00000400 3.88002172532
.reloc 0x00028000 0x00001630 0x00001800 6.39638327442

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00027060 0x0000022f LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library WS2_32.dll:
0x4151b0 WSAIoctl
0x4151b4 select
0x4151b8 recv
0x4151bc __WSAFDIsSet
0x4151c0 gethostname
0x4151c4 connect
0x4151c8 WSAStartup
0x4151cc inet_addr
0x4151d0 htonl
0x4151d4 htons
0x4151d8 setsockopt
0x4151dc sendto
0x4151e0 socket
0x4151e4 closesocket
0x4151e8 gethostbyname
0x4151ec send
0x4151f0 WSASocketA
Library IPHLPAPI.DLL:
0x415038 GetNetworkParams
Library DNSAPI.dll:
0x41502c DnsFree
0x415030 DnsQuery_A
Library KERNEL32.dll:
0x415040 ReadConsoleW
0x415044 LCMapStringW
0x415048 FlushFileBuffers
0x41504c SetStdHandle
0x415050 WriteConsoleW
0x415054 CreateFileW
0x415058 IsDebuggerPresent
0x41505c CreateFileA
0x415060 GetTickCount
0x415064 WriteFile
0x415068 GlobalAlloc
0x415070 Sleep
0x415074 TerminateProcess
0x415078 RaiseException
0x41507c GetLastError
0x415080 GlobalFree
0x415084 DecodePointer
0x41508c CloseHandle
0x415090 DeleteFileA
0x415094 CreateThread
0x415098 GetCurrentProcess
0x41509c WaitForSingleObject
0x4150a0 CopyFileA
0x4150a4 GetModuleFileNameA
0x4150a8 GetCurrentThreadId
0x4150ac GetCurrentProcessId
0x4150b0 ExitProcess
0x4150b4 GlobalMemoryStatus
0x4150b8 SetErrorMode
0x4150bc FreeLibrary
0x4150c4 ReadFile
0x4150cc GetProcAddress
0x4150d0 LoadLibraryA
0x4150d4 GetSystemInfo
0x4150d8 CreateMutexA
0x4150dc GetVersionExA
0x4150e0 WinExec
0x4150e4 HeapFree
0x4150e8 HeapAlloc
0x4150ec EncodePointer
0x4150f8 GetCommandLineA
0x4150fc GetProcessHeap
0x415100 GetModuleHandleExW
0x415104 AreFileApisANSI
0x415108 MultiByteToWideChar
0x41510c WideCharToMultiByte
0x415110 GetStdHandle
0x415114 GetModuleFileNameW
0x415118 HeapSize
0x41511c SetLastError
0x415124 TlsAlloc
0x415128 TlsGetValue
0x41512c TlsSetValue
0x415130 TlsFree
0x415134 GetStartupInfoW
0x415138 GetModuleHandleW
0x41513c IsValidCodePage
0x415140 GetACP
0x415144 GetOEMCP
0x415148 GetCPInfo
0x415154 RtlUnwind
0x415158 CreateDirectoryW
0x41515c GetFileType
0x41516c LoadLibraryExW
0x415170 OutputDebugStringW
0x415174 HeapReAlloc
0x415178 GetConsoleCP
0x41517c GetConsoleMode
0x415180 SetFilePointerEx
0x415184 GetStringTypeW
0x415188 SetEndOfFile
Library USER32.dll:
0x4151a8 wsprintfA
Library ADVAPI32.dll:
0x415004 FreeSid
0x41500c OpenProcessToken
0x415010 RegSetValueExA
0x415014 RegQueryValueExA
0x415018 RegCloseKey
0x415020 RegOpenKeyA
Library SHELL32.dll:
0x415190 ShellExecuteExA
Library SHLWAPI.dll:
0x41519c PathFindFileNameA
0x4151a0 PathRemoveFileSpecA

!This program cannot be run in DOS mode.
$>Rich
`.rdata
@.data
@.reloc
c|w{VW
D$,{}Q
D$,{}Q
D$,{}Q
u#h`SB
YYhDRA
HHtVHHt
~pjCXf
<at-<rt"<wt
URPQQh
j@j _W
VVh<nA
PP9E u
jA[jZZ+
;t$,v-
UQPXY]Y[
,SVWj0X
Wj0XPV
~';_t|%3
tHHt*Ht#
Ht+Ht$Ht
HtHHt
PWWWWV
PSSSSV
+tHHt
+t"HHt
HAO8t
QQSVWd
HtHu4j
bad allocation
CorExitProcess
(null)
`h````
xpxxxx
`h`hhh
xppwpp
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
Unknown exception
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LE
UNICODE
_hypot
_nextafter
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CreateFile2
1#SNAN
1#QNAN
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad exception
GET %s HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.4; en-US; rv:1.9b5) Gecko/2008032619 Firefox/3.0b5
Host: %s
Connection: Keep-Alive
GET %s HTTP/1.1
Host: %s
Range:bytes=0-%s
Accept-Encoding: gzip
Connection: close
POST /?%d HTTP/1.1
Host: %s
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.4; en-US; rv:1.9b5) Gecko/2008032619 Firefox/3.0b5
Content-Length: %d
X-%c: %c
[By:GameOver]:Fuck your ass!
http://
www.%s
Unknown
Windows 8
Windows 7
Windows Vista
Windows 2003
Windows XP
Windows 2000
Windows NT
Windows 2008
HARDWARE\DESCRIPTION\System\CentralProcessor\0
%d * %dMHz
FuckShieldRefreshMutex
dnsapi.dll
DnsFlushResolverCache
CreateFileA
KERNEL32.dll
SetFilePointer
lstrlenA
Software\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Security Center
UACDisableNotify
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
EnableLUA
PromptOnSecureDesktop
.temp.fortest
generic
unknown error
iostream
iostream stream error
system
SeBackupPrivilege
systemroot
appdata
\WindowsUpdate
string too long
invalid string position
F:\Projects\7
\20150606\Server\Release\Server.pdb
WSASocketA
WSAIoctl
WS2_32.dll
GetNetworkParams
IPHLPAPI.DLL
DnsQuery_A
DnsFree
DNSAPI.dll
CreateFileA
GetTickCount
WriteFile
GlobalAlloc
InitializeCriticalSectionAndSpinCount
TerminateProcess
RaiseException
GetLastError
GlobalFree
DecodePointer
DeleteCriticalSection
CloseHandle
DeleteFileA
CreateThread
GetCurrentProcess
WaitForSingleObject
CopyFileA
GetModuleFileNameA
GetCurrentThreadId
GetCurrentProcessId
ExitProcess
GlobalMemoryStatus
SetErrorMode
FreeLibrary
SetUnhandledExceptionFilter
ReadFile
GetEnvironmentVariableA
GetProcAddress
LoadLibraryA
GetSystemInfo
CreateMutexA
GetVersionExA
WinExec
HeapFree
HeapAlloc
EncodePointer
IsDebuggerPresent
IsProcessorFeaturePresent
GetSystemTimeAsFileTime
GetCommandLineA
GetProcessHeap
GetModuleHandleExW
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
GetStdHandle
GetModuleFileNameW
HeapSize
SetLastError
UnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetModuleHandleW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
CreateDirectoryW
GetFileType
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
LoadLibraryExW
OutputDebugStringW
HeapReAlloc
GetConsoleCP
GetConsoleMode
SetFilePointerEx
GetStringTypeW
LCMapStringW
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
SetEndOfFile
ReadConsoleW
KERNEL32.dll
wsprintfA
USER32.dll
OpenProcessToken
RegSetValueExA
RegQueryValueExA
LookupPrivilegeValueA
AllocateAndInitializeSid
FreeSid
CheckTokenMembership
RegOpenKeyA
AdjustTokenPrivileges
RegCloseKey
ADVAPI32.dll
SHGetSpecialFolderPathA
ShellExecuteExA
SHELL32.dll
PathRemoveFileSpecA
PathFindFileNameA
SHLWAPI.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
!This program cannot be run in DOS mode.
`.rdata
@.data
D$ RPh(6@
@tPhH@@
Q hL@@
L$,^]d
MFC42.DLL
__CxxFrameHandler
_except_handler3
__dllonexit
_onexit
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
CloseHandle
CreateThread
GetLastError
CreateMutexA
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
LoadIconA
EnableWindow
SendMessageA
DrawIcon
GetClientRect
GetSystemMetrics
IsIconic
USER32.dll
CoUninitialize
CoInitialize
ole32.dll
OLEAUT32.dll
_CxxThrowException
_setmbcp
??1type_info@@UAE@XZ
LocalFree
LLLLLK
FuckShieldRefreshMutex
JavaScript
function confirm(str){return true;}function alert(str){return true;}window.history.back(-1);
Click to continue
CWebBrowser2
.?AV_com_error@@
.?AVtype_info@@
DDLLDDDL
LLDDLD
DDLDLD
LDDDDDDD
DDDDDDDDD
DDDDDDDDDDD
DDDDDDDDDDDDD
DDDDDDD
DDDDD@
HrCg@b
81.68.216.37
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVAES@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></windowsSettings></application></assembly>
0!0-070t0\5
:$;>;F;O;W;p;
;&<I<v<
>)>V>y>
? ?$?(?,?0?4?8?<?@?D?]?
0$030C0h0o0|0
1!282J2v2
2)3I3Y3h3
4-4[4r4
5 60686M6Y6_6y6
7*7d7w7
8/9O9c9v9
:&:6:F:v:
<;<[<k<z<
0:1F1k1
4=5C5R5v5
7X8p8z8
9#919m9
9B;i;|;
<-<=<E<^<
>1?G?N?^?p?
1.1@1u1
192@2m2
3363q3v3|3
4"4-4<4P4^4
5:5g5r5
6#626\6
9>9]9i9y9
:%:0:=:F:L:`:f:p:u:
;%;1;L;R;];e;j;t;|;
2p2u2~2
3F4M4`4
55)535C5S5c5l5
6&606C6H6
7&7]7k7u7
7<:C:Y:c:
>1>W>u>|>
0 0$0(0,00040~0
4E5J5T5
6'7[7o7
7"8<8I8u8
8(909C9N9S9c9o9t9
;*;/;;;@;_;
<F<^<h<
>>;>\>
;';-;L;R;
<'?+?/?3?7?;???C?
3*373A3G3W3_3e3t3~3
4$4<4O4U4[4b4k4p4v4~4
5!5)5.545<5A5G5O5T5Z5b5g5m5u5z5
6 6%6+63686>6F6K6Q6Y6^6d6l6q6w6
9+9B9M9|9
:+:@:J:c:m:z:
: <v<0=c=
?'?8?b?i?p?w?
"0T0o0
1.2C2Q2Z2
353O3W3b3y3
8)888?8P8^8i8q8~8
9F9O9q9|9
<2<Q<p<
>N>X>z>
51P1f1|1
7 7&7*70747:7>7D7H7t7
?'?1?7?=?C?
2"2>2F2K2w2
3'3,3K3
515:5F5Q5x5
7 8&8+82888D8I8N8S8\8
<3<D<J<V<f<l<{<
==(=.=8=C=
>>+>b>z>
.0H0n0
1#2,2J2
7E8N8v8
:J;U;5<Q<I=[=m=
>!>@>R>d>v>
959<9@9D9H9L9P9T9X9
:%:@:G:L:P:T:u:
:>;D;H;L;P;
<"=0=6=r=
>8>E>J>X>
5k6l7|7
494?4G4
6A6J6S6
9<:A:G:N:
:I<b=m=
;.;B;H;M;
<J=j=0>E>r>
?)?2?<?c?v?
30<0F0Z0{0
0191I1p1
2<3E3O3k3
4(5D5e5
4M8Q8U8Y8]8a8e8i8m8q8u8y8
8E9^9m9
9?9l9r9{9
:M:[:e:
;J<b<g<
496G6Q6
:2=M=b=f=r=v=
2 2$2024282
3$3,343<3D3L3T3\3d3l3t3|3
1<1@1D1H1@6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
= =8=<=T=d=h=|=
>(>,><>@>D>H>P>h>x>|>
?$?<?L?\?`?x?
000@0P0T0X0\0p0t0x0|0
1(181H1h1p1x1
282X2x2
3(3H3d3h3
4,404L4P4p4
585X5`5t5|5
60686<6T6X6t6x6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7|7
8 8$8(8,8T8d8t8
<$<,<4<<<D<L<T<\<d<l<t<|<
< >$>(>,>0>4>8><>@>D>P>X>\>`>d>h>l>p>t>x>|>
444T4t4
jjjjjj
mscoree.dll
AR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
(null)
kernel32.dll
Aja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
USER32.DLL
((((( H
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
2CONOUT$
ERROR : Unable to initialize critical section in CAtlBaseModule
@jjjjj
BrowserServer
{8856F961-340A-11D0-A96B-00C04FD705A2}
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
BrowserServer Microsoft
FileVersion
1, 0, 0, 1
InternalName
BrowserServer
LegalCopyright
(C) 2015
LegalTrademarks
OriginalFilename
BrowserServer.EXE
ProductName
BrowserServer
ProductVersion
1, 0, 0, 1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.VariantPalevoB.Trojan
Lionic Worm.Win32.Palevo.tnDr
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.47077691
FireEye Generic.mg.faf3c47c4d784d20
CAT-QuickHeal Trojan.Mauvaise.SL1
McAfee GenericRXFQ-JP!FAF3C47C4D78
Malwarebytes Agent.Trojan.DDOS.DDS
VIPRE Trojan.GenericKD.47077691
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus DoS-Trojan ( 004c87db1 )
BitDefender Trojan.GenericKD.47077691
K7GW DoS-Trojan ( 004c87db1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.36344.juW@a01N9bei
VirIT Trojan.Win32.Generic.FPU
Cyren W32/Palevo.AA.gen!Eldorado
Symantec SMG.Heur!gen
Elastic malicious (high confidence)
ESET-NOD32 Win32/DDoS.Agent.NBL
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky P2P-Worm.Win32.Palevo.hsfb
Alibaba Malware:Win32/km_2c960.None
NANO-Antivirus Trojan.Win32.Palevo.eedpnj
ViRobot Trojan.Win32.Agent.148992.V
Rising Trojan.DDOS!1.AAB0 (CLASSIC)
TACHYON Worm/W32.Palevo.148992.CT
Emsisoft Trojan.GenericKD.47077691 (B)
F-Secure Clean
DrWeb Trojan.DownLoader24.60205
Zillya Clean
TrendMicro TROJ_FUSHIELD.SM
McAfee-GW-Edition BehavesLike.Win32.NetLoader.ch
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Troj/Mdrop-IIF
Ikarus P2P-Worm.Win32.Palevo
Jiangmin Trojan/Generic.bgtwn
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1317457
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Agent.sd!s1
Xcitium TrojWare.Win32.Palevo.AA@5szlv3
Arcabit Trojan.Generic.D2CE593B
SUPERAntiSpyware Trojan.Agent/Gen-Malagent
ZoneAlarm P2P-Worm.Win32.Palevo.hsfb
GData Trojan.GenericKD.47077691
Google Detected
AhnLab-V3 Trojan/Win32.Dynamer.R159816
Acronis suspicious
VBA32 BScope.Trojan.Pynamer
ALYac Trojan.GenericKD.47077691
MAX malware (ai score=84)
Cylance unsafe
Zoner Clean
TrendMicro-HouseCall TROJ_FUSHIELD.SM
Tencent Malware.Win32.Gencirc.10b0d343
Yandex Trojan.GenAsa!HmnMauVhttw
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.8559262.susgen
Fortinet W32/Agent.NBI!tr
Panda Trj/Genetic.gen
No IRMA results available.