Static | ZeroBOX

PE Compile Time

2009-07-14 09:07:47

PDB Path

napstat.pdb

PE Imphash

070e553ddabe88527fa952a08fb09ea6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001f428 0x0001f600 6.25915476649
.rdata 0x00021000 0x000092fc 0x00009400 4.55585801128
.data 0x0002b000 0x00002454 0x00002400 2.30015720176
.pdata 0x0002e000 0x00002298 0x00002400 4.98118535402
.rsrc 0x00031000 0x00022cc0 0x00022e00 6.43429199896
.reloc 0x00054000 0x00000278 0x00000400 4.01850679849

Resources

Name Offset Size Language Sub-language File type
MUI 0x00053bf0 0x000000d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00053700 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00053b68 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00053b68 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00053b68 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00053b68 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00031840 0x000003ac LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00031bf0 0x000004b5 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library GDI32.dll:
0x100021000 DPtoLP
0x100021008 CreateFontIndirectW
0x100021010 SelectObject
0x100021018 DeleteObject
0x100021020 RestoreDC
0x100021028 CreateCompatibleDC
0x100021030 CreateCompatibleBitmap
0x100021038 CreateSolidBrush
0x100021040 SetWindowOrgEx
0x100021048 SetBkMode
0x100021050 SetTextColor
0x100021058 GetStockObject
0x100021060 GetObjectA
0x100021068 GetObjectW
0x100021070 DeleteDC
0x100021078 CreateBitmap
0x100021080 SetLayout
0x100021088 SetViewportOrgEx
0x100021090 ModifyWorldTransform
0x100021098 SetGraphicsMode
0x1000210a0 SaveDC
0x1000210a8 BitBlt
0x1000210b0 GetDeviceCaps
Library USER32.dll:
0x1000210c0 SetWindowLongPtrW
0x1000210c8 DefWindowProcW
0x1000210d0 GetWindowLongPtrW
0x1000210d8 PostMessageW
0x1000210e0 PostQuitMessage
0x1000210e8 SendMessageW
0x1000210f0 SetWindowTextW
0x1000210f8 ShowWindow
0x100021100 UpdateWindow
0x100021108 GetMessageW
0x100021110 TranslateMessage
0x100021118 DispatchMessageW
0x100021120 FindWindowExW
0x100021128 IsWindow
0x100021130 CallWindowProcW
0x100021138 RegisterClassExW
0x100021140 GetClassInfoExW
0x100021148 LoadCursorW
0x100021150 CreateWindowExW
0x100021158 CharNextW
0x100021160 RegisterWindowMessageW
0x100021168 LoadIconW
0x100021170 LoadImageW
0x100021178 GetSystemMetrics
0x100021180 PeekMessageW
0x100021190 DestroyIcon
0x100021198 KillTimer
0x1000211a0 LoadStringW
0x1000211a8 GetDC
0x1000211b0 ReleaseDC
0x1000211b8 SetForegroundWindow
0x1000211c0 UnregisterClassA
0x1000211c8 SetTimer
0x1000211d0 GetCursorPos
0x1000211d8 CreatePopupMenu
0x1000211e0 AppendMenuW
0x1000211e8 SetMenuItemInfoW
0x1000211f0 SetMenuDefaultItem
0x1000211f8 TrackPopupMenu
0x100021200 DestroyMenu
0x100021208 BringWindowToTop
0x100021210 GetSysColor
0x100021218 SystemParametersInfoW
0x100021220 GetWindowRect
0x100021228 MapWindowPoints
0x100021230 FillRect
0x100021238 GetAncestor
0x100021240 IsIconic
0x100021248 GetLastActivePopup
0x100021250 BeginPaint
0x100021258 EndPaint
0x100021260 MoveWindow
0x100021268 InvalidateRect
0x100021270 GetWindowLongW
0x100021278 GetWindowTextW
0x100021280 GetWindowTextLengthW
0x100021288 DrawTextW
0x100021290 IsWindowEnabled
0x100021298 GetParent
0x1000212a0 TrackMouseEvent
0x1000212a8 SetRect
0x1000212b0 ScreenToClient
0x1000212b8 GetDlgItem
0x1000212c0 SetFocus
0x1000212c8 DestroyWindow
0x1000212d0 GetScrollInfo
0x1000212d8 SetScrollInfo
0x1000212e0 ScrollWindowEx
0x1000212e8 GetScrollPos
0x1000212f0 SetScrollPos
0x1000212f8 ScrollWindow
0x100021300 GetFocus
0x100021308 DrawIcon
0x100021310 EnableWindow
0x100021318 IsWindowVisible
0x100021320 SendNotifyMessageW
0x100021328 GetKeyState
0x100021330 GetClientRect
Library msvcrt.dll:
0x100021340 free
0x100021348 swprintf_s
0x100021350 memcpy_s
0x100021358 memmove_s
0x100021360 malloc
0x100021368 _vscwprintf
0x100021370 wcsncpy_s
0x100021378 vswprintf_s
0x100021380 _wtof
0x100021388 wcstol
0x100021390 towupper
0x100021398 wcsstr
0x1000213a0 wcschr
0x1000213a8 iswspace
0x1000213b0 _resetstkoflw
0x1000213b8 wcscat_s
0x1000213c0 _vsnwprintf
0x1000213c8 memcmp
0x1000213d0 __CxxFrameHandler3
0x1000213d8 _onexit
0x1000213e0 _lock
0x1000213e8 __dllonexit
0x1000213f0 memset
0x1000213f8 _errno
0x100021400 realloc
0x100021408 ??1type_info@@UEAA@XZ
0x100021410 ?terminate@@YAXXZ
0x100021418 __set_app_type
0x100021420 _fmode
0x100021428 _commode
0x100021430 __setusermatherr
0x100021438 _amsg_exit
0x100021440 _initterm
0x100021448 _wcmdln
0x100021450 exit
0x100021458 _cexit
0x100021460 _exit
0x100021468 _XcptFilter
0x100021470 __wgetmainargs
0x100021478 _callnewh
0x100021480 _CxxThrowException
0x100021490 ??1exception@@UEAA@XZ
0x1000214a8 wcscpy_s
0x1000214b0 __C_specific_handler
0x1000214b8 _unlock
0x1000214c0 memcpy
Library ntdll.dll:
0x1000214d0 RtlCaptureContext
0x1000214d8 RtlLookupFunctionEntry
0x1000214e0 RtlVirtualUnwind
0x1000214e8 EtwUnregisterTraceGuids
0x1000214f0 EtwRegisterTraceGuidsW
0x1000214f8 EtwGetTraceEnableFlags
0x100021500 EtwGetTraceEnableLevel
0x100021508 EtwGetTraceLoggerHandle
0x100021510 EtwTraceMessage
Library gdiplus.dll:
0x100021540 GdiplusShutdown
0x100021548 GdipAddPathArcI
0x100021550 GdipClosePathFigure
0x100021558 GdipCreateFromHDC
0x100021560 GdipDeleteGraphics
0x100021568 GdipSetSmoothingMode
0x100021578 GdipDeleteBrush
0x100021580 GdipFree
0x100021588 GdipDrawPath
0x100021590 GdipDrawImageRectI
0x1000215a0 GdipFillPath
0x1000215a8 GdipDeletePath
0x1000215b0 GdipCreatePath
0x1000215b8 GdipDeletePen
0x1000215c0 GdipCreatePen1
0x1000215c8 GdipCreateSolidFill
0x1000215d8 GdipMeasureString
0x1000215e0 GdipDeleteStringFormat
0x1000215e8 GdipCreateStringFormat
0x1000215f0 GdipDeleteFont
0x100021600 GdipCreateFontFromDC
0x100021608 GdipDrawImageRectRectI
0x100021610 GdipGetImageHeight
0x100021618 GdipGetImageWidth
0x100021620 GdipDisposeImage
0x100021628 GdipCloneImage
0x100021630 GdipLoadImageFromFile
0x100021638 GdipFillRectangleI
0x100021640 GdipAlloc
0x100021648 GdiplusStartup
Library COMCTL32.dll:
0x100021658 None
Library KERNEL32.dll:
0x100021668 VirtualAlloc
0x100021670 InterlockedPopEntrySList
0x100021678 VirtualFree
0x100021680 HeapSize
0x100021688 HeapReAlloc
0x100021690 HeapDestroy
0x100021698 GetVersionExA
0x1000216a0 DelayLoadFailureHook
0x1000216a8 LoadLibraryExA
0x1000216b0 GetSystemTimeAsFileTime
0x1000216b8 LocalFree
0x1000216c0 MoveFileExW
0x1000216c8 WriteFile
0x1000216d0 CreateFileW
0x1000216d8 GetTempFileNameW
0x1000216e0 GetTempPathW
0x1000216e8 GetSystemDefaultLangID
0x1000216f0 DeleteFileW
0x1000216f8 GetTimeFormatW
0x100021708 FileTimeToSystemTime
0x100021710 FileTimeToLocalFileTime
0x100021718 CheckElevationEnabled
0x100021728 SetProcessWorkingSetSize
0x100021730 GetLocaleInfoW
0x100021738 RegQueryValueExW
0x100021740 FindResourceExW
0x100021748 WaitForSingleObject
0x100021750 CreateThread
0x100021758 GlobalFree
0x100021760 GetCommandLineW
0x100021768 CreateProcessW
0x100021770 FormatMessageW
0x100021778 SetEvent
0x100021780 CreateMutexW
0x100021788 CreateEventW
0x100021790 CloseHandle
0x100021798 LoadLibraryExW
0x1000217a0 MultiByteToWideChar
0x1000217a8 RegDeleteValueW
0x1000217b0 RegCreateKeyExW
0x1000217b8 RegSetValueExW
0x1000217c0 lstrcmpiW
0x1000217c8 RegOpenKeyExW
0x1000217d0 RegEnumKeyExW
0x1000217d8 RegQueryInfoKeyW
0x1000217e0 RegCloseKey
0x1000217e8 GetModuleHandleW
0x1000217f0 LoadLibraryW
0x1000217f8 GetProcAddress
0x100021800 FreeLibrary
0x100021808 DeleteCriticalSection
0x100021818 GetLastError
0x100021820 HeapSetInformation
0x100021828 FindResourceW
0x100021830 LoadResource
0x100021838 LockResource
0x100021840 SizeofResource
0x100021848 GetUserDefaultUILanguage
0x100021850 HeapFree
0x100021858 GetProcessHeap
0x100021860 HeapAlloc
0x100021868 RaiseException
0x100021870 SetLastError
0x100021878 lstrlenW
0x100021880 GetModuleFileNameW
0x100021888 LeaveCriticalSection
0x100021890 EnterCriticalSection
0x100021898 GetCurrentThreadId
0x1000218a0 FlushInstructionCache
0x1000218a8 GetCurrentProcess
0x1000218b0 Sleep
0x1000218b8 GetStartupInfoW
0x1000218c8 QueryPerformanceCounter
0x1000218d0 GetTickCount
0x1000218d8 GetDateFormatW
0x1000218e0 TerminateProcess
0x1000218e8 UnhandledExceptionFilter
0x1000218f0 OutputDebugStringA
0x1000218f8 GetCurrentProcessId

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
GDI32.dll
USER32.dll
NTDLL.DLL
msvcrt.dll
API-MS-Win-Security-Base-L1-1-0.dll
gdiplus.dll
COMCTL32.dll
KERNEL32.dll
D!d$(D
A_A^A]A\_
WATAUAVAWH
WATAUH
A]A\_
UVWATAUAVAWH
PA_A^A]A\_^]
ATAUAVH
0A^A]A\
WATAUAVAWH
fD;d$@
fD;d$H
fD9d$@
L$DfD;
A_A^A]A\_
ATAUAVH
fD;'sCI
t$ WATAUH
@A]A\_
WATAUH
A]A\_
H SUVWATH
A\_^][
VATAUAVAWH
A_A^A]A\^
t$ WATAUH
UVWATAUAVAWH
u*9Q<|%
A_A^A]A\_^]
kXL9)t
E9k,tHI
0A^A]A\
x6;{@}1H
WATAUH
9\$0uL
x ATAUAVH
A^A]A\
WATAUH
89:u*9z
A]A\_
H9K@t'H
H!{0H!{
;{Du99kDu
C8HcK@H
H9w@uH
VWATAUAVH
@A^A]A\_^
H!T$@D
B 9A ukH
B8H9A8uaL
H9Y8u0H
H;H8s"H
i(f;k(u7I
D$ u^D
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
pA_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
x ATAUAVH
A^A]A\
WATAUH
t$`+t$X
x ATAUAVH
A^A]A\
WATAUH
L9i(u0
H9;u%L
UVWATH
A\_^][
SVWATAUAVAWH
`A_A^A]A\_^[
UVWATAUAVAWH
tjH9>t'H
A_A^A]A\_^]
VWATAUAVAW
D$xH9D$ptFH
A_A^A]A\_^[
WATAUH
fD; tqH
fD;(u\H
fD; t{fD
A]A\_
9T$ttIH
up9T$ptjH
9T$ptD;
\$ UVWATAUAVAW
'fE;4$
A_A^A]A\_^]
D$xH9D$pt
D$xH9D$pt
UVWATH
A\_^][
SUVWATH
\$0HcK
D9d$$t
A\_^][
WATAUH
D+D$T+T$P
l$ VWATAUAVH
A^A]A\_^
SUVWATH
D9d$Pv@3
D;d$Pr
A\_^][
UVWATAUAVAWH
H;l$@sI
PA_A^A]A\_^]
x ATAUAVH
Lcd$`A
A^A]A\
UVWATH
A\_^][
WAUAWH
SUVWATAUAVH
A^A]A\_^][
VWATAUAVH
+T$XD+L$P
+T$XD+L$P
A^A]A\_^
SUVWATAUAVAWH
A_A^A]A\_^][
VWATAUAVH
t%fE;0sH
t%fD;3sH
A^A]A\_^[
{ ATAUAVH
A^A]A\
UVWATH
D9d$0H
A\_^][
HcCPH;G8
D$L;CPtD
UVWATAUAVH
A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
VWATAUAWH
A_A]A\_^
UVWATAUAVAWH
A_A^A]A\_^]
SUVWAUH
`A]_^][
H9KHt'H
H!{8H!{
UVWATAUAVAWH
A_A^A]A\_^][
uVH9yXv-H
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
9\$@v5
pA_A^A]A\_^]
WAUAVH
UVWATAUAVAWH
|$XD9g
D$PD9`
D$HD9`
D$(D9`
D$8D9`
ttD9f8@
A_A^A]A\_^]
x ATAUAVH
A^A]A\
H;KXs_H
UVWATAUH
A]A\_^]
VWATAUAVH
A^A]A\_^
UVWATAUAVAWH
A_A^A]A\_^]
AUWVSH
AVAUWVSH
[^_A]A^
L$8;L$H~
L$<;L$L~
UVWATAUAVH
$9t$0t
A^A]A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
t$ WATAUAVAWH
t$X+t$P
t$P+t$XD
T$`D+|$T
l$lD+d$`D+l$du
A_A^A]A\_
WATAUAVAWH
D9d$Hu
D!d$(A+
D!d$(+
A_A^A]A\_
ATAUAVH
A^A]A\
x ATAUAVH
0A^A]A\H
ATAUAVH
A^A]A\
{ ATAUAVH
A^A]A\
H9O0tH
L$ SUVWH
x ATAUAVH
A^A]A\
x:;^Xu
SVWATH
8A\_^[
WATAUH
0A]A\_
LcA<E3
napstat.pdb
bad allocation
Invalid parameter passed to C runtime function.
305.1i
RegDeleteKeyExW
RegDeleteKeyW
API-MS-WIN-Service-winsvc-L1-1-0.dll
API-MS-WIN-Service-Management-L1-1-0.dll
SHELL32.dll
OLEAUT32.dll
SHLWAPI.dll
ole32.dll
QueryServiceStatus
OpenServiceW
OpenSCManagerW
CloseServiceHandle
CommandLineToArgvW
SHGetFolderPathW
Shell_NotifyIconW
ShellExecuteW
StrCmpW
CoCreateInstance
CoTaskMemFree
CoTaskMemRealloc
CoTaskMemAlloc
CoInitializeEx
CoUninitialize
CoInitialize
StringFromGUID2
CoGetObject
KERNEL32.dll
COMCTL32.dll
gdiplus.dll
API-MS-Win-Security-Base-L1-1-0.dll
ntdll.dll
msvcrt.dll
USER32.dll
GDI32.dll
DPtoLP
CreateFontIndirectW
SelectObject
DeleteObject
RestoreDC
CreateCompatibleDC
CreateCompatibleBitmap
CreateSolidBrush
SetWindowOrgEx
SetBkMode
SetTextColor
GetStockObject
GetObjectA
GetObjectW
DeleteDC
CreateBitmap
SetLayout
SetViewportOrgEx
ModifyWorldTransform
SetGraphicsMode
SaveDC
BitBlt
GetDeviceCaps
SetWindowLongPtrW
DefWindowProcW
GetWindowLongPtrW
PostMessageW
PostQuitMessage
SendMessageW
SetWindowTextW
ShowWindow
UpdateWindow
GetMessageW
TranslateMessage
DispatchMessageW
FindWindowExW
IsWindow
CallWindowProcW
RegisterClassExW
GetClassInfoExW
LoadCursorW
CreateWindowExW
CharNextW
RegisterWindowMessageW
LoadIconW
LoadImageW
GetSystemMetrics
PeekMessageW
MsgWaitForMultipleObjectsEx
DestroyIcon
KillTimer
LoadStringW
ReleaseDC
SetForegroundWindow
UnregisterClassA
SetTimer
GetCursorPos
CreatePopupMenu
AppendMenuW
SetMenuItemInfoW
SetMenuDefaultItem
TrackPopupMenu
DestroyMenu
BringWindowToTop
GetSysColor
SystemParametersInfoW
GetWindowRect
MapWindowPoints
FillRect
GetAncestor
IsIconic
GetLastActivePopup
BeginPaint
EndPaint
MoveWindow
InvalidateRect
GetWindowLongW
GetWindowTextW
GetWindowTextLengthW
DrawTextW
IsWindowEnabled
GetParent
TrackMouseEvent
SetRect
ScreenToClient
GetDlgItem
SetFocus
DestroyWindow
GetScrollInfo
SetScrollInfo
ScrollWindowEx
GetScrollPos
SetScrollPos
ScrollWindow
GetFocus
DrawIcon
EnableWindow
IsWindowVisible
SendNotifyMessageW
GetKeyState
GetClientRect
swprintf_s
memcpy_s
memmove_s
malloc
_vscwprintf
wcsncpy_s
vswprintf_s
wcstol
towupper
wcsstr
wcschr
iswspace
_resetstkoflw
wcscat_s
_vsnwprintf
memcmp
__CxxFrameHandler3
_onexit
__dllonexit
memset
_errno
realloc
??1type_info@@UEAA@XZ
?terminate@@YAXXZ
__set_app_type
_fmode
_commode
__setusermatherr
_amsg_exit
_initterm
_wcmdln
_cexit
_XcptFilter
__wgetmainargs
_callnewh
_CxxThrowException
??0exception@@QEAA@AEBV0@@Z
??1exception@@UEAA@XZ
?what@exception@@UEBAPEBDXZ
??0exception@@QEAA@AEBQEBDH@Z
wcscpy_s
__C_specific_handler
_unlock
memcpy
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
EtwUnregisterTraceGuids
EtwRegisterTraceGuidsW
EtwGetTraceEnableFlags
EtwGetTraceEnableLevel
EtwGetTraceLoggerHandle
EtwTraceMessage
CheckTokenMembership
FreeSid
AllocateAndInitializeSid
GdiplusShutdown
GdipAddPathArcI
GdipClosePathFigure
GdipCreateFromHDC
GdipDeleteGraphics
GdipSetSmoothingMode
GdipCreateLineBrushFromRectI
GdipDeleteBrush
GdipFree
GdipDrawPath
GdipDrawImageRectI
GdipCreateBitmapFromHICON
GdipFillPath
GdipDeletePath
GdipCreatePath
GdipDeletePen
GdipCreatePen1
GdipCreateSolidFill
GdipCreateLineBrushFromRectWithAngleI
GdipMeasureString
GdipDeleteStringFormat
GdipCreateStringFormat
GdipDeleteFont
GdipCreateFontFromLogfontA
GdipCreateFontFromDC
GdipDrawImageRectRectI
GdipGetImageHeight
GdipGetImageWidth
GdipDisposeImage
GdipCloneImage
GdipLoadImageFromFile
GdipFillRectangleI
GdipAlloc
GdiplusStartup
VirtualAlloc
InterlockedPopEntrySList
VirtualFree
HeapSize
HeapReAlloc
HeapDestroy
GetVersionExA
DelayLoadFailureHook
LoadLibraryExA
GetSystemTimeAsFileTime
LocalFree
MoveFileExW
WriteFile
CreateFileW
GetTempFileNameW
GetTempPathW
GetSystemDefaultLangID
DeleteFileW
GetTimeFormatW
InterlockedPushEntrySList
FileTimeToSystemTime
FileTimeToLocalFileTime
CheckElevationEnabled
GetUserPreferredUILanguages
SetProcessWorkingSetSize
GetLocaleInfoW
RegQueryValueExW
FindResourceExW
WaitForSingleObject
CreateThread
GlobalFree
GetCommandLineW
CreateProcessW
FormatMessageW
SetEvent
CreateMutexW
CreateEventW
CloseHandle
LoadLibraryExW
MultiByteToWideChar
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
lstrcmpiW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
GetModuleHandleW
LoadLibraryW
GetProcAddress
FreeLibrary
DeleteCriticalSection
InitializeCriticalSection
GetLastError
HeapSetInformation
FindResourceW
LoadResource
LockResource
SizeofResource
GetUserDefaultUILanguage
HeapFree
GetProcessHeap
HeapAlloc
RaiseException
SetLastError
lstrlenW
GetModuleFileNameW
LeaveCriticalSection
EnterCriticalSection
GetCurrentThreadId
FlushInstructionCache
GetCurrentProcess
GetStartupInfoW
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetDateFormatW
TerminateProcess
UnhandledExceptionFilter
OutputDebugStringA
GetCurrentProcessId
.?AVCMessageMap@ATL@@
.?AVCWindow@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AU_ATL_MODULE70@ATL@@
.?AVCAtlModule@ATL@@
.?AV?$CAtlModuleT@VCComModule@ATL@@@ATL@@
.?AVCComModule@ATL@@
.?AV?$CWindowImpl@VCBannerPanel@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AVCBannerPanel@@
.?AV?$CWindowImpl@VCSHAItemList@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AVCSHAItemList@@
.?AV?$CWindowImpl@VCScrollPanel@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AVCScrollPanel@@
.?AV?$CWindowImpl@VCDetailsWindow@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AVCDetailsWindow@@
.?AV?$CComObject@VCSafeWebBrowser@@@ATL@@
.?AUIDocHostShowUI@@
.?AUIDocHostUIHandler@@
.?AUIOleWindow@@
.?AUIOleInPlaceSite@@
.?AUIOleClientSite@@
.?AUIUnknown@@
.?AUIDispatch@@
.?AV?$IDispatchImpl@UIDispatch@@$1?_GUID_00020400_0000_0000_c000_000000000046@@3U__s_GUID@@B$1?m_libid@CAtlModule@ATL@@2U_GUID@@A$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$CWindowImpl@VCWebBrowseHost@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AV?$CComCoClass@VCWebBrowseHost@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AVCWebBrowseHost@@
.?AVCSafeWebBrowser@@
.?AUIRegistrarBase@@
.?AVCRegObject@ATL@@
.?AVbad_alloc@std@@
.?AVexception@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0A@$0A@@2@@ATL@@
.?AV?$CWindowImpl@VCMyWindow@@VCWindow@ATL@@V?$CWinTraits@$0A@$0A@@3@@ATL@@
.?AVCMyWindow@@
.?AVCAtlException@ATL@@
.?AVImage@Gdiplus@@
.?AVGdiplusBase@Gdiplus@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0FEAAAAAA@$0CA@@2@@ATL@@
.?AV?$CWindowImpl@VCSHAItem@@VCWindow@ATL@@V?$CWinTraits@$0FEAAAAAA@$0CA@@3@@ATL@@
.?AVCSHAItem@@
.?AV?$CSysLinkT@VCWindow@ATL@@@@
.?AV?$CWindowImplRoot@V?$CSysLinkT@VCWindow@ATL@@@@@ATL@@
.?AV?$CWindowImplBaseT@V?$CSysLinkT@VCWindow@ATL@@@@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@
.?AV?$CWindowImpl@VCShellStandardSysLink@@V?$CSysLinkT@VCWindow@ATL@@@@V?$CWinTraits@$0FGAAAAAA@$0A@@ATL@@@ATL@@
.?AVCShellStandardSysLink@@
.?AUIAccPropServer@@
.?AVCScrollPanelPropertyServer@@
<?xml version='1.0' encoding='utf-8' standalone='yes'?>
<assembly
xmlns="urn:schemas-microsoft-com:asm.v1"
xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"
manifestVersion="1.0"
<assemblyIdentity
name="napstat.exe"
processorArchitecture="*"
type="win32"
version="1.0.0.0"
/>
<description>Isolation Notify</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity
language="*"
name="Microsoft.Windows.Common-Controls"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
type="win32"
version="6.0.0.0"
/>
</dependentAssembly>
</dependency>
<asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
wvzbf"cf
siSTLH
CGGKKKMl
FFFHGDDMUUVXZZS
gCLNNUX
p]\\]]X
EZZ\]p
q`\[_bRI
^Y\]`ecRSaWNC
xRdXMGC
/&'')()
5*9;;:*
6:????:
BAA}~>
l:2.-*
S*14>XQHEGA5
e@FGILMFC0
PJNcTU9?>3,
yslily
1))((%$
wGoRs>
Z_Viz^)uUk
5&S5DI
,@]k}ngg
PJyFk}&I
ox@S)ulwg
]}}{;y
fwwWw:
!{{=^x
Yk7Y_k
w!"[;D
1Kty;M&
! l90HH)VD
)`040PB
ZkXpt90
UqXt"_b]
;p-ehk
!D?#)U5`)8R
qU5 6:
2FU_Vm
xr&3`
cfffg$
P#6~>B
i7Te`B
xYK@``
B\2lhp
vS*Fa-}
kR*X.!l
g]dbI!
{nJ(".
<Y,Ol3
Sjy"xI
+(OLbz
o}+IN8
*S$_,#W(
cqLsQJI
B:u^?8"
HH[HiG\
RPJI$8
CJiHHC(
[XXd'N
#<x"D(9
TJI)cP
DdddddE
w%j11^
y/G&)&g&
K3b"2E
S47okH
%#AGP2q
fXfafo
.m,c}s
NkGP,E
%*QaKE
(Bl"$&B
Ad"$6Blb
/0j!1J
ftvrB'
n#ES{X
b^ @@}&
IDAT<}
1x]oZ{
"Dd Pt4
Qt}x{?0
);=}1my
h9(Fv1
43T3F4n
+`T#+a
Le]Fk#bc
$6:4=V
C"$pah
"D$"DD
897sh|
Jrdarf
P8c8%Pj
-?Toa{G
'aTR)B
~gZ:[
Pqd*](F
rn:U-
MJ?FRMBt
-)/6MSGwRt:
4@&j-')Dli^
#&!AP^G{
+5'LK[:
&1"MG_2
mtph:MKG
G;8/r|xh
;8*zmfT
ywmfgd^9
%.-,%B?>'tqpP
%{}}Auvv
HGG:Ji3h
9E44?Q5s
Lc;JXsB
Dz#-=}
.,,!hebX~zw
wwwwwp
}}}}way
xtmaaadddeeeeK
xmh`OOOOWWbbddeaE
Oxmm`OIIAEEJJUWbbbd`A
{aah_KAAAA<DFFFTWbWdOI^
KO`OKA?:3@
ADFTTTWWOIE
KOLKK?<33I
<===TTUOFIA
JJLK?;30:
k.<<==TFFIIA
JJLLE?404
/7<9=FFEAAA
KJLLE;..
/66<<<E;;;
LUXLLC.4
//67<;;3
JXX[L85
+////;2223
UX]]LK
*+...3
Xqsp]X
C))()((((
fC6)))()((
fYVP-))((((
sYVVSP6)(((
sqfYYVC9,((
~~sqYYSCC81+
sqYVCCC8E
qYSCFD;h
qYSGFB;
s]XSEC>3
s]LEA?>
s]LGE?>
s]LE?>?D
p[EC>?
v{ljimmmmS
clbRGGSSUVVG
ThREA<<BLLUUSE
[RHA91113>>>QSA_
>DA7)*
@05>>LE2
BBA7((
045>B9F
]$-4539)
rId~:
e.! ! #
gNI.!
WQNJ/%"
qgWNJ;/&
gQJ=0D
oNM>,k
reM=:*Y^
J`dd`J
JdaD1adJ
Md8%le:lf
MdFC?)!
JdFZZC)!
MddU[Z@(#
RMaa^C07daMR
aN`dd`N`
;;;4ddd
PPPOiii
WWWYnnn
PPP:ppp
aaa?{{{
===`BBB
222M+++
j3cb#xp
#c"$#xp
zssr6xp
w:rscxp
ORRRRT
sqpbaWXYZ[4578862,
yvmhffgj`#'))*)&
vkd^dg_##))))"
{tld^^]"##)%$
{wuolg]""##$"
{yvon/+%$"
yrDB<<0-
|GDD><33..
ED><:..
GC>;.:=
HfjjTH
Hjf&dfjH
Hj%##ceAjH
cFF?jL
bDF@iL
bGFB>TP
`=<;:fL
HjU/*)+1
HjW8-''
HjVV7.,
HjY]]Z93
Kjj^lk]452
fLKfgm_N5ifKLf
ROTjjTLR
===`BBB
222M+++
IGGGG_
~tt}wz
tqqE0.1X
~}tEp6
w}tmpp-
ayw}xqEDpB
v}xxxmDDFp/
tlEDDFpB:`}z
xtEFDFD=5568u
xmFDDF3
xmFDFF,
tllDDF,
tlDFlF,
{olFDDF
tFllDD
,pooosq}wwtm8
tlDlDF
Flpmomtmmmm?
FlFlDElEmEE8
DDDDEDEEEEEBP
DDDDDDCCECCBP
DDDCDCDECEC@P
CDDCCCCCCC@@L
ADDCCDCCE@<<L
UFFDDDECCC<<L
UnllllEECC<CL
UnnllllDEC<@L
UnnnlllDAC<@P
rrnlllDDDA77
rrnnllUU77X
rrnlnU?G
fyw`A8
tyqw]?A.
ef|c??A846U
Xz}u`?g3
_blxffw=
g]]`aaa=
?_?Z@@@;G
:??>?@@7F
:???>>>2F
:??>>@22F
Lg_?]@>2F
Lk_[Z:>2F
dd_]?:73I
[immi[
[mjI8jm[
/?;%ij
^mOLB!
[mNLQ=
^mRRYe
[mTUfh
47m[
^mmGWgXC<-#mm^
`^jjHK:'mj^`
j_immi_i
;;;4ddd
PPPOiii
WWWYnnn
PPP:ppp
aaa?{{{
===`BBB
222M+++
quarui_details_window_class
Probation
Not-Quarantined
quarui_hidden_window
Quarantined
QUI_APP_EVENT
TaskbarCreated
Local\quar_qclintfy_mtx
Delete
NoRemove
ForceRemove
TypeLib
Software
SYSTEM
SECURITY
Hardware
Interface
FileType
Component Categories
ATL:%p
<NULL>
SmallText
LargeText
"%1\control.exe" ncpa.cpl%2
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
Wadvapi32.dll
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
Module
Module_Raw
REGISTRY
0x%08lx
EnableBranding
Software\Microsoft\NetworkAccessProtection\UI
Software\Microsoft\NetworkAccessProtection\UI\Branding\%d
DefaultBrandingLanguage
Software\Microsoft\NetworkAccessProtection\UI\Branding\%s
Picture
STATIC
SysLink
Elevation:Administrator!new:%s
ShieldIcon
napagent
BUTTON
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Network Access Protection Client UI
FileVersion
6.1.7600.16385 (win7_rtm.090713-1255)
InternalName
napstat.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
napstat.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7600.16385
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
FireEye Trojan.GenericKD.66210371
CAT-QuickHeal Clean
McAfee Artemis!AB28D926012B
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.66210371
K7GW Clean
Baidu Clean
VirIT Clean
Cyren W64/Downuk.A.gen!Eldorado
Symantec Trojan.Gen.2
Elastic Clean
ESET-NOD32 a variant of Generik.FKHLKGS
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Trojan-Downloader.Win32.Agent.xyaoiu
Alibaba TrojanDownloader:Win32/Generic.b4a6ac3e
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.66210371
Rising Downloader.Agent!8.B23 (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.66210371
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.66210371 (B)
SentinelOne Clean
GData Trojan.GenericKD.66210371
Jiangmin Clean
Webroot Clean
Avira TR/Dldr.Agent.pmmpz
MAX malware (ai score=85)
Antiy-AVL Clean
Gridinsoft Ransom.Win64.Sabsik.sa
Xcitium Clean
Arcabit Trojan.Generic.D3F24A43
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Downloader.Win32.Agent.xyaoiu
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan-Downloader.Agent.Cplw
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.