Static | ZeroBOX

PE Compile Time

2071-08-11 23:36:48

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00045084 0x00045200 6.97739532648
.rsrc 0x00048000 0x00049f90 0x0004a000 6.06491521709
.reloc 0x00092000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00090e10 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00090eb0 0x000003b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS
RT_MANIFEST 0x00091268 0x00000d21 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
(Q_HKx
}QMw?j
YP*0.a
l2|orE^
v5WK,t
t_7yLQ
F@qU1?
D[>x|(
B ,x-51
'~br:>
t. b#o+
{UCGhC3
akWUt%iJ
ak<iiX
X'Qt=!
XczKvQ
T{o:xSv
Bnv$T'
K.#VVc
\856h
y JVJ_#O
;t'KrlQ
>q<j>X
Z#QMr:
,sE/N)%U
PUGIjC
"f4cx(+6
$f>g\ >
dxt!N$p
(OcB]I
:)'AiKKCz4a
pnhW1-
>C\|>tZ
uL}`K,F
3dr'Ok
/<!f 7;
L'/uAU
JD5Fg5:
>`~4cH
/Yo/iv
B:u;t&
EO.[|#
brou=e
Xhy,(:
(b[se.oP
!]!{G>
h'r'S#
b}I*xF
ii7w&(
Z0lY=T
%2[2a8
0>VE4J
YZ`uXu
4W%z0d
9OOw9;/{x
Gb"HM?
xE(,AFL
a\;j/X
=MiqU5
ip%@!P
qaaq34
0,YgH+
v2EuNgKK`+
$`X`Pg
@dZX}#Y
}>sR]o
8r'd@8)
ntyQ>q
YJ-C2K
fIzD7|
qFU|/L
[-eR
}MP%<R_
7m=l(B
OyE,v$
.8z[K
-+slC.i
,S \x
lH~|XLn
hj,"Es
Yb{x~;
!RD/cm
Cqum8@#
%GD62[RD
y=1Jz<)
S@TMT_
[+"KlO
f@wyv;
U@>QRs
m'GT&`
b&f^U[ioW
+mK}<th
**f<>1q]
=f>6t|V
y-_Q~}
CjiXaC
hed^=`y2
N$#x29h+G
>j kH0
wL"^FH,
/@fPk,Nu
/f-+@V
qLTQoc"Osih
[}7Z^\
DdA(rr3A
+J]e&rk}j
uX?0Iq
d&pWjw
.]7~Rh
gc$;||i
9D@X,/
p]8@2j
VBnXVEy
a\rWh=U
.rW6/CI
yfO)`h.
|w$$ZL
9kNz"q
HG*^c-OVh
B(vW]O8
[ru-9|I
]_!qRI
95t.-
s`y;i^
rQPrZG
O:"CYy
}WZW|n#[
Dzzzf
B%N:(N
$fec1
`8-eZDv
-qyO+2
K[Jv'S <q
u9^8C
?}@HY"
1%MULA
Rx[^"<0
Zk.q"Z
mTSy?X
PhmeoXp
`7fMK',~;
&vV2)+O`
(\.~bm
_*Bn@o
[8ti_8
dYLD@R
x%/)l
{5\ec3*
y}`d mK
T3^>%b~
j!s)rs
N,=HLmz
\rB[.A
27%yxy
KCo2D+
M9"@KG6
B> _P2
8MZUDW
2=oz&.
=TMlMH
O;@l@M
D8=PM;
Nm>lOq
*x-)}
.co>_k
6~B"+%
m}#/XR
$P2#d"
)^Hpx'<V
/#{C->y
pY :qo
NN\S^
*i8BiIQ^
eZdw[1]
#rt\Muj
l8WG%R
No_5x
%1lYLL
\Li*;}
2uore$
Gev1y)y&`
<"\%`7
V3)GV-
{^5w)I#
}R:oGQ
GwHU"4
/A/U>}
5cX4L~
B5Q1}%r
|i*x[&ki
f_NVi8
;p=3.,
GZ2i^!
"4N"|z
L4gc}9
S*{D$JNF/
!y`oKH!X
{+2Wd!
$(Um1,
n^ -h7
r0w"SU$p
D}n!A'
IP#&}Z
A5~yIg
nb|~uE
X[]PX[A
[l5s~q5Q
#kvf3fJ
\b&($=
-ceG8B
D_o](
yZ (w@aa8)
Z?_b`
]T.a83
i:#a8F
1 ez(va%
gWZ o*zOa8
2LZ u^}
Z OXO2a8
: `jZ r0
3/hZ c
Q<7Za80
bZ DtG
Z =r|+a8,
xZ $`|
zZ JKq
Z j;;6a8B
_bj/
)`S@%&+
_bY*
.:%&8t
r Z ;M
f:%&8b
Z_bX
rqZ f{
!aZiZ
*=Z aOs
JRDa+
Y_cX*
s H_h?a%
%Z l{D^a+
3"Z t1
tPTp%&
5%sT
IbXa8|
vrNZ T
99sT
97m[Z mJ
^SbW(
7utZ `p" a8
Ko%&8i
@hqZ @
jUHa8M
t=Z bo
+ ^SbW(
;2|o%+
^R6Za8
Z ]WHa84
O_Za8.
6& PiQ
_6s%Za8
.~tZa8
Q>%&8S
\DZZ w
=]%&8g
ft=%&8
*8lJ%+
|XZa8b
0Tk?%&8A
|wpZa8
x>dZ [
Z c :Ua8
IZ !#5
r!Z }-
L;Z SF
Z $F6Fa8
^0<EZ
2\s\%+
uklh(
--)N
7RQAZa+
(~a8s
@P@X(D
4?Za8N
jUm:Za8
p'Za8h
3}$Z ]
sKfl(
5'fV%+
cOZa8b
/2a%+
3owT%&8r
mLq.%+
RSZa8L
g`e2%&8
B4gj%&8
:bZa8n
ulZa89
i<Z%&8&
TzZa8F
d,q%&8
* Aael8
u 1!Z q/
1CTh(
,DDW(
v4.0.30319
#Strings
poweroff.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
bt]]]A:^VL7AoGi7T=eVG!jl*
System.Windows.Forms
IContainer
System.ComponentModel
TextBox
EventArgs
Dispose
IDisposable
ComponentResourceManager
Control
{EYA-=Xq7!/V"jy-SrEH#/uj!
UserControl
ContainerControl
AppDomain
ResolveEventHandler
<>9__0_0
AssemblyName
List`1
System.Collections.Generic
RegistryKey
Microsoft.Win32
Environment
SpecialFolder
WebClient
System.Net
RemoteCertificateValidationCallback
System.Net.Security
SecurityProtocolType
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
ProcessStartInfo
System.Diagnostics
Process
ThreadStart
DirectoryInfo
<>9__8_0
X509Certificate
System.Security.Cryptography.X509Certificates
X509Chain
SslPolicyErrors
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
PaddingMode
CipherMode
ICryptoTransform
MemoryStream
CryptoStream
CryptoStreamMode
Encoding
System.Text
HttpResponseHeader
Delegate
WebRequest
WebResponse
Random
<>9__2_0
GetProcAddress
kernel32.dll
GetModuleHandle
GetCurrentProcess
IsWow64Process
StringBuilder
SearchOption
FileSystemInfo
BindingFlags
Binder
HttpWebRequest
DecompressionMethods
StreamReader
TextReader
})d i4oO;~EHZbA"^S4MI!7 /
RegexOptions
System.Text.RegularExpressions
2Ot<IfO\}:s{,:dOpZl[kmC7!
ResourceManager
System.Resources
CultureInfo
System.Globalization
Settings
pwroff_zKvqvyrRWxK3zZPr.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
poweroff
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
NeutralResourcesLanguageAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
SecurityCriticalAttribute
System.Security
SecuritySafeCriticalAttribute
TypeLibTypeAttribute
DispIdAttribute
TypeLibFuncAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
Newtonsoft.Json
JsonPropertyAttribute
NewtonsoftJson.Json
bt\]\]\]A:^VL7AoGi7T=eVG!jl\*.resources
CdrCxXjxwwROGXBxoNwbItOoawnd
2Ot<IfO\\}:s{\,:dOpZl\[kmC7!.resources
{EYA-=Xq7!/V"jy-SrEH#/uj!.resources
})d i4oO;~EHZbA"^S4MI!7 /.resources
pwroff_zKvqvyrRWxK3zZPr.Resources.Newtonsoft.Json.dll
String
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Length
ReadByte
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Buffer
BlockCopy
GetElementType
CreateInstance
get_UTF8
GetString
Intern
get_CurrentDomain
add_AssemblyResolve
get_FullName
get_Name
op_Equality
TextBoxBase
set_Multiline
set_TabIndex
set_AutoScaleMode
AutoScaleMode
set_Name
Padding
set_Margin
System.Drawing
set_Size
get_AliceBlue
set_ForeColor
set_ClientSize
set_Text
EventHandler
add_TextChanged
set_Location
ResumeLayout
PerformLayout
get_Controls
ControlCollection
SystemColors
get_ActiveCaption
set_BackColor
set_FormBorderStyle
FormBorderStyle
set_AutoScaleDimensions
SuspendLayout
get_Yellow
get_MediumTurquoise
Contains
GetExecutingAssembly
GetManifestResourceNames
GetManifestResourceStream
Registry
CurrentConfig
IEnumerable`1
ToArray
Exception
Enumerator
GetEnumerator
get_Current
MoveNext
Boolean
ThreadAbortException
CurrentUser
ToUpper
ToString
Substring
CreateSubKey
SetValue
NewGuid
OpenSubKey
GetValue
IsNullOrEmpty
Replace
GetFolderPath
Combine
WriteAllText
Remove
ToLower
DownloadString
Console
WriteLine
ServicePointManager
set_ServerCertificateValidationCallback
set_SecurityProtocol
get_Headers
DownloadData
set_CreateNoWindow
ResetAbort
get_Chars
Directory
CreateDirectory
set_Padding
set_Mode
set_KeySize
set_BlockSize
Convert
FromBase64String
CreateEncryptor
get_ASCII
GetBytes
FlushFinalBlock
ToBase64String
CreateDecryptor
get_ExitCode
LocalMachine
Win32Exception
GetTempPath
Insert
Exists
IntPtr
get_Size
set_UseShellExecute
set_Verb
set_Expect100Continue
get_ResponseHeaders
get_Item
WriteAllBytes
Collect
get_ServerCertificateValidationCallback
DownloadFile
Create
set_Method
GetResponse
GetResponseStream
GetEnvironmentVariable
GetDirectories
op_Inequality
DateTime
get_Now
get_Ticks
NextDouble
ToInt32
ToChar
Append
InvokeMember
GetTypeFromProgID
Activator
set_AutomaticDecompression
set_ContentType
set_ContentLength
GetRequestStream
ReadToEnd
TimeSpan
get_UtcNow
Subtract
get_TotalSeconds
set_AutoSize
ClassesRoot
GetSubKeyNames
IsMatch
StartsWith
get_Assembly
Synchronized
JsonConvert
DeserializeObject
ConfuserEx v1.0.0
WrapNonExceptionThrows
pwroff_zKvqvyrRWxK3zZPr
$1bf2ba48-62ac-4d8d-9a1c-a5f3e3ed704d
2.2.1.2
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$F935DC23-1CF0-11D0-ADB9-00C04FD58A0B
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
ExecParams
country
partnerName
productName
excutionWidget
buyingChannel
discrepancy
PostBackUrl
userId
prices
salesChannel
active
ipLoggerCode
modeUpdater
modePublisher
paramsProduct
ListProductInstall
UrlTrack
trackPostVar
dailycheck
TrackDecrPrmKey
TrackDecrPrmIv
_CorExeMain
mscoree.dll
8nVDNR
#Rp!rAFV
;t-D_b
`] DDD
v X%?""2
&Ti7@N
}EDD&[
/""2=|
nMDDD.Q
Ge?"""
Rr'"""
EDDD&E
DDNpp|
yVW<>:d
9W{=>[X
$@DFy,
p#o3,Vs
mk-TUJ%2
__`?,;XoY%
<IC[{XlWcU`
#"2]bIPSU
{O?d,g
<g-/X/rV
cu^iP
!b" U
W.OSU6+
92<!xVb2
%kyN?t
&K qPn
a1qDZK
;=%F8-
=F)F6#
8wK2c8-K2
5VkV]G$=
q_d= L)Jcy<
8-K&YNi-
S~3!v-
t!0o[^,
3D:8.V\
BkJm(M
uF)Jc8
%F+Jk)m
Z2c8*$`
D+Ea,Gy
KTdM+E
};PI|^
P#0oZ^,
2%M@7E
IDAT?./x
-S(Rc(
4V)i{)
M(lBn-
i--A7(
2JQ&)O
:fYFn-VkB
<-K^L&
5{VFM|
~^0MSRc$
LVgbkzO
,!>;J)
ohn,{y
udZShC!
I]s\U,
%ZS&)e
052 l+6
7{s&IJb
3~:;#5
gdgng.
cTCPjhOiIT,PM
&ir^,9MS
fs^L&</'<
hLEK6Z
rBfmLM
z{C#>Q
UzO/M9
BcEeIV
{FyNw<
CP?-(g#@
jQ7,K>n
"xFYN7M
y?nr-nr=
IBg<&-
ex2_2(
Q5@,rV
$#NF#N
TDvqrO
>@c?C4
&)Z\j6
%IQ0.r
(HZE5Xlv
lvHVZL
s_2}2`
1+,C[|
y "_Um>
x}xfq c
KDvqrO
HPT]68
"r&"Oq
RDO VO
Uo_0f
!G$Ei(
KUzq*Q
d%i"#+o
%r+tGQ
@dImno
&cz_YQ
Fh[]Dn
2:iB+M
fDyF'Mi%
8XC\d=
CzYF;Iy
.;QD=I
Z/V~E0g
A@FN+M
z]Z:)p
"NSziB
IL/IhF
{m`fmc}
0$pNfI
v;<m5i
E9 &.r3
Ek8[%
104A@5"-
LVkx)r
s|)qW`
IDATVJ
,&VGon
nosmm
sJ3`FYT
B5+`7M
ro<1#~
sg<f?4#~
so2ag65w
!w&cvgS
M{r~G9#
!ou{\[[g#
!n/{Q'
")r&Iy
_~[1KS
\Bw|Z@
,"rZD>C
;.NN r
U~92R)
?/N. r
?::4|!
){=o"K
[DdBD
<_}+vz
iUk4fg
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app" />
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
<applicationRequestMinimum>
<defaultAssemblyRequest permissionSetReference="Custom" />
<PermissionSet Unrestricted="true" ID="Custom" SameSite="site" />
</applicationRequestMinimum>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! " )(-,
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
pwroff_zKvqvyrRWxK3zZPr
CompanyName
pwroff_zKvqvyrRWxK3zZPr
FileDescription
pwroff_zKvqvyrRWxK3zZPr
FileVersion
2.2.1.2
InternalName
poweroff.exe
LegalCopyright
pwroff_zKvqvyrRWxK3zZPr
LegalTrademarks
OriginalFilename
poweroff.exe
ProductName
pwroff_zKvqvyrRWxK3zZPr
ProductVersion
2.2.1.2
Assembly Version
2.2.2.2
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Csdi.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Strictor.266661
ClamAV Clean
FireEye Generic.mg.4de7538747bf36f8
CAT-QuickHeal Clean
ALYac Gen:Variant.Strictor.266661
Malwarebytes Adware.Csdimonetize
VIPRE Gen:Variant.Strictor.266661
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
BitDefender Gen:Variant.Strictor.266661
K7GW Adware ( 005685b11 )
K7AntiVirus Adware ( 005685b11 )
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.ISJR-5626
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Adware.CsdiMonetize.BC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Csdi.gen
Alibaba TrojanDownloader:MSIL/CsdiMonetize.2622e156
NANO-Antivirus Trojan.Win32.Csdi.jvkygw
ViRobot Clean
Rising Adware.CsdiMonetize!8.1C9D (CLOUD)
TACHYON Clean
Sophos Generic Reputation PUA (PUA)
F-Secure Heuristic.HEUR/AGEN.1312230
DrWeb Adware.WizzMonetize.1
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Strictor.266661 (B)
Ikarus Clean
GData Gen:Variant.Strictor.266661
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1312230
Antiy-AVL GrayWare[AdWare]/MSIL.CsdiMonetize
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Trojan.Strictor.D411A5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Csdi.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!4DE7538747BF
MAX malware (ai score=81)
DeepInstinct MALICIOUS
VBA32 TScope.Trojan.MSIL
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CD823
Tencent Msil.AdWare.Csdi.Eajl
Yandex PUA.Csdi!qT4yaucbJNg
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Adware/CsdiMonetize
BitDefenderTheta Gen:NN.ZemsilF.36132.Jm0@aSjfrtp
AVG Win32:AdwareX-gen [Adw]
Avast Win32:AdwareX-gen [Adw]
No IRMA results available.