Static | ZeroBOX

PE Compile Time

2023-02-07 08:11:33

PE Imphash

379ac571aeb3154c809e333b6e5cbb5a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000fd0a 0x0000fe00 6.5432109328
.rdata 0x00011000 0x00008542 0x00008600 5.85936597
.data 0x0001a000 0x00000f2c 0x00000600 3.86574487703
.rsrc 0x0001b000 0x0000047d 0x00000600 3.42801678759
.reloc 0x0001c000 0x00000ee4 0x00001000 6.35195344761
fre832s 0x0001d000 0x0005d000 0x0005c400 7.99920372949

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001b0a0 0x00000260 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0001b300 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x411000 GetProcAddress
0x411004 LoadLibraryA
0x411008 VirtualAlloc
0x41100c HeapAlloc
0x411010 WideCharToMultiByte
0x411014 lstrlenA
0x411018 GetModuleFileNameW
0x41101c CreateFileW
0x411020 GetFileSize
0x411024 ReadFile
0x411028 CloseHandle
0x41102c GetModuleHandleW
0x411030 GetModuleHandleExW
0x411034 FreeLibrary
0x411038 ExitProcess
0x41103c Sleep
0x411040 LCIDToLocaleName
0x411044 GetStartupInfoW
0x411048 IsDebuggerPresent
0x41104c InitializeSListHead
0x411054 GetCurrentThreadId
0x411058 GetCurrentProcessId
0x411060 TerminateProcess
0x411064 GetCurrentProcess
0x411074 LCMapStringEx
0x411078 MultiByteToWideChar
0x41107c DecodePointer
0x411080 EncodePointer
0x411084 GetLocaleInfoEx
Library msvcrt.dll:
0x41109c setvbuf
0x4110a0 ungetc
0x4110a4 realloc
0x4110a8 abort
0x4110ac __strncnt
0x4110b0 tolower
0x4110b4 wcsnlen
0x4110b8 _callnewh
0x4110bc _initterm
0x4110c0 _initterm_e
0x4110c4 fgetpos
0x4110c8 __p__commode
0x4110cc _controlfp_s
0x4110d0 _stricmp
0x4110d4 strcpy_s
0x4110d8 strnlen
0x4110dc strtol
0x4110e0 wctomb_s
0x4110e4 _lock
0x4110e8 _unlock
0x4110ec _iob
0x4110f0 ___lc_handle_func
0x4110f4 _XcptFilter
0x4110f8 __set_app_type
0x4110fc fsetpos
0x411100 _wcmdln
0x411108 _msize
0x41110c ?terminate@@YAXXZ
0x411110 _isatty
0x411114 _fileno
0x411118 _CIlog10
0x41111c ceil
0x411120 _clearfp
0x411124 fgetc
0x411128 fflush
0x41112c fclose
0x411130 islower
0x411134 ___mb_cur_max_func
0x411138 _errno
0x41113c _wcsdup
0x411140 ___lc_codepage_func
0x411144 isupper
0x411148 __pctype_func
0x41114c malloc
0x411150 strcspn
0x411154 puts
0x411158 calloc
0x41115c localeconv
0x411160 free
0x411164 frexp
0x411168 strrchr
0x41116c _amsg_exit
0x411178 memmove
0x41117c memset
0x411180 memcpy
0x411184 _CxxThrowException
0x411188 __CxxFrameHandler3
0x41118c _fseeki64
0x411190 __wgetmainargs
0x411194 fread
0x411198 _set_fmode
0x41119c strchr
0x4111a0 wcsrchr
0x4111a4 pow

!This program cannot be run in DOS mode.
.W Tj6N
Richj6N
`.rdata
@.data
@.reloc
Bfre832s
SWh(3A
tahd3A
t,ht3A
WPhd4A
D$,j@P
D$,j@P
D$(j@P
D$(j@P
tG9uCj
W9^Lt"
PPPPPWS
G1^[<gt
~[Sj0W
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
setlocale
fwrite
[aOni*{
~ $s%r
@b;zO]
v2!L.2
;__setusermatherr
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
1#QNAN
1#SNAN
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
[+] Fix Import Address Table
[+] Import DLL: %s
[V] API %x at %x
[V] API %s at %x
GetCommandLineA
GetCommandLineW
__wgetmainargs
__getmainargs
[!] Not supported relocations format at %d: %d
[-] Out of Bound Field: %lx
[V] Apply Reloc Field at %x
ntdll.dll
NtUnmapViewOfSection
[+] Relocation Fixed.
NtDelayExecution
invalid string position
iostream stream error
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
GetProcAddress
LoadLibraryA
VirtualAlloc
HeapAlloc
WideCharToMultiByte
lstrlenA
GetModuleFileNameW
CreateFileW
GetFileSize
ReadFile
CloseHandle
GetModuleHandleW
KERNEL32.dll
__CxxFrameHandler3
_CxxThrowException
memcpy
memset
memmove
__uncaught_exception
msvcrt.dll
_except_handler4_common
_amsg_exit
localeconv
calloc
strcspn
malloc
__pctype_func
isupper
___lc_codepage_func
_wcsdup
_errno
___mb_cur_max_func
islower
fclose
fflush
fgetpos
fsetpos
_fseeki64
setvbuf
ungetc
realloc
__strncnt
tolower
wcsnlen
_callnewh
_initterm
_initterm_e
_set_fmode
__p__commode
_controlfp_s
_stricmp
strcpy_s
strnlen
strtol
wctomb_s
_unlock
___lc_handle_func
_XcptFilter
__set_app_type
__wgetmainargs
_wcmdln
?_set_new_mode@@YAHH@Z
_msize
?terminate@@YAXXZ
_isatty
_fileno
_CIlog10
_clearfp
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
GetLocaleInfoEx
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
LCIDToLocaleName
ExitProcess
FreeLibrary
GetModuleHandleExW
strchr
wcsrchr
strrchr
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVfailure@ios_base@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVsystem_error@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_array_new_length@std@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AV_Facet_base@std@@
.?AV_Iostream_error_category2@std@@
.?AVerror_category@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0(040@0P0U0_0u0
1282_2x2
6#797a7
8#8?8_8x8
9G:i:p:
=K>X>p>y>
0&0=0Q0a0w0
2%2D2R2Z2y2
6%606E6Y6`6
7V8[8m8
869;9J9
1Z2J3:4*5
6%6&848
717F7U7
9%9T9Y9o9v9|9
:5;?;6<E<t<z<
3M3U3t3{3
3@4f4x4r5
828K8S8c8~8
9&9E9[9
:,:?:n:
= =&=5=R=j=
1)232P2j2}2
3/353Q3^3v3
4 4<4S4
4I5f5s5
0R2+4~4
5"52585?5F5l5
6O7l7s7
<0<6<<<B<H<N<T<i<~<
=C>M>V>
?L?V?_?h?}?
1#1)10171>1E1L1S1Z1b1j1r1~1
2#2)2/262=2D2K2R2Y2`2h2p2x2
3S3\3i3o3
5%5d5j5
616N6y6
7(8?8U8p8
:9:@:U:[:6;;;M;
5 5$5(5,5D5H5L5P5T5X5\5`5d5h5+6=6\6[7b7
>0?4?8?<?@?W?
1 4$4(4,4044484<4@4D4H4L4
=8=B=T=d=l=
0"0(0.040:0@0F0L0U0^0j0y0
1#1/1A1
2E2]2f2r2
3$3*30363<3B3H3N3T3Z3h3p3
4J4a4l4
686=6J6O6e6
77'70797P7w7
9V:[:m:
>">R>]>c>u>
8!9-9;9
:!:(:.:4:
=6>;>Y>w>
:0<8<P<Z<
F0P>T>X>\>
4p5v5|5R7
7 8(8Y8b8m8
90999B9
0)1E2r2z2
2:3E3K3T3
<1<N<}<
1 2$2(2,20242H2L2P2T2X2\2`2d2h2l2p2t2
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0
<$<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<
>@?D?H?L?d?h?x?|?
0 0(0@0P0T0d0h0l0p0t0|0
101@1D1T1X1\1`1h1
2,202@2D2H2L2P2X2p2
3 3$3(3,30343<3T3d3h3x3|3
4$4,40484<4D4H4L4P4X4\4`4h4p4t4|4
5(5,5D5H5`5d5|5
6$6(6@6D6\6`6x6|6
7$747D7T7d7t7
8,808@8D8T8X8h8l8|8
2(202<2\2d2l2t2|2
3$303P3\3
444<4D4\4d4x4
5 5@5L5l5t5|5
6(686D6L6
7$7,747<7D7L7T7\7d7l7t7
8$8,848<8H8P8h8p8
9 9(9094989@9T9\9d9l9p9t9|9
:8:@:L:l:x:
;,;0;P;l;p;
< <(<<<D<L<T<h<p<
D0P0p0
101P1l1
404T4t4
c@5Lh9
}?yT{Z7
3qhX4#[
G^C"af
e`TR:'
HKHF1r
LbC1q
o*$+5!0
!,5Lu*qs
v?\}f>"
Dd-LOB
AuEYOO,9J/hiq
pHR%~dR
L##`&62
r2q{)i
UR*N@i1
]gN!XW
6+gVX^
8#Vu>0>
GRa;sG=
;5M8b1Y
]p5V{;
@n'YD4-
Den!Tq
vY6w ^
#`+8&
hEXe2)fi
[ec0o3
AGpTu5
S)oY4m
Y9w&5uN
,W(\*?
wr{@U\
4WGu/_${
v8JOO!
KSP?<!sM
hxHF,d
uO?f-)cO
UBPCQgS
IBC6P
YZAG./*
}7>C_3.
#08Vu3kP]
vv@q(B
S|fws&
iGd(sC
j#/PF|
H*!N,J
G6@l.f)
ib:o'w
?.sa<z
FJJF\~
8Q`d[6
=5{$"H
l#T[K1
\2I6XPa
C~u0Q'd
($$(1x0d
B6LysJ
~:e0/V
UvjssY/
pl7c[7`
oVL#+{
5n_IFD
:J3bIw8A
GDKs9X.m
L0Th#8
b"bpB)o#C
r8ytqK
rcSbJV
k=j(;q
*Go`5x
&l un-
kcP pwh
aNP{]F
NG J~2
hpt:Ge
`h,Z3m
2bxNj}c
A|/'ky
h7HU,xQ
Zq,tN
-?'ZrF
&M$1U\
}3~\*J9T
q3zq|jT$
Bp54l(+V
cC/(A
kT<zNf
)vf]55H
3L6)rx
~v\w@1
{qXMg(#
uXo`N|
(HE!2yI]
oHeQA{
*1/V&\
Sp#n xr
<u:L"~#N
uvTI3]
,WDm_}
}#v4}:
@}2$MNQ@
n(od<+]
C|Dh^K
H9R(V#-
LfYBI4
T#1ywK
93i#*
k}`Ayg
9+bHe{W
ST1Y| D
e$"XznO
%A6R8r
s[RXj!m
Hrz6Du
39hYgG@*_]
a 6L|{G
M%&>e$8
33s@fG
hI-{Jo
;7hRM_
f=(mH*U
<g^_>;
ni;Sol/
\yS{)-'
68#@kG
#<+2%eotV
uy-:ra
Vo33__
fhH_I4
f6i"VU}!i
p:m8_B_
[ 9|1)
x+GJJ/
w;4CDF1O
lR@UmI
VKv8-|yt'9
k?tNTT
ZG6qHw
7{oSxLc
}g-KxC
+ |Z>?E
3AH~W
y&qKkt
G#Ox0c
WI_}.w
MSLCm-L!Xk
v)o:l(
sp;jso<
%T]h-<
TVPu*(
)wCVnp
%^y)_x
pXmI?.]
UuyoyB
t"FA\mO
q|2'kH
\:)qP
w'+_&?
!,-$ehS!
WB~Jumi
5L9QN-
!wpAf8
Jy!W9[
d{m%$q
c2~2O}
AzxK*ou
zQ_Rc+S
=9i\AJ(
O<Iv;8
"*ec4n
jD4s47
iI|qA7x
;My)@<
aOd@)B(}
m\rtN|>Y
4Do~c{_
OuRdD*b
P@b.,r
zy#5}.
op({% |s
@:%J]X
4^BYk6
e3mf*)
>xq@,:
lE<]6*]\#B
7$q4eS
"3ukd(O*
EHN?#-fL
qch]}AF
dI*uya#
TPhRR!PC
H0jA>1n
&mz97~
`v,i!S
9$_T6{
]D3Ks!
md2eg|
!qu$2a
UOQ4>`f
-Uj4PyK
[8wXu=
yF(z4p
b:!E.m
>J+~D2+
#CZ54c
Li<Kdz
"SFAw[
KT$fR5
e}:mexL
a1NW2U
3aWifN{
Bx_f:4
6r['HC
q-n8ii
#3`~)
/[I)H!)|
[NsXn
J^Jf)'
#e#1pU
}2&Ro'gg
y(/!e3
I4Twn`G
[;D],1
wy_NL%
^@560
\RkK-y
i2v_:r
s03BQ?y
|OXc|N
l0qUfJ7
aVA-As
$#+!T\
gX+QT
#<,a%;4(
'~b2f?
~t}m4@
o$"7Khh0{
PhnPg:k
3jJADZ
sYH/ur
=4gMOQ4
>J(G/U
]Td*wH
41>Fq[
C]}8q)7
"=*Xnp
wKs#p87
{4^*m[*
%nd2^(
j9Q^o
/,^&$s
V:m/=X
At-Qzh
MoP!xjI
4CyyTk9
p]r!wb
[c-ZE$
UbA|}w
!XBwu_G
&a5}*(m
i~7$B.1
q(Za-a
b B]&s
r@O4ngm
LjP@6\
?o-?9~
wbm8cN3
, jiV8;
,4U8Ke
A0p6"b
F`N^Q
Aa+Ka:
M}/f6j.(
Wqq;Cn
7PlO2
0c[(q:
P)Mb(&{O
@3IYQ&
'M=~c(5
y}{WdYcs
#^/W{S
0uD-<?
v#XRnO
#=X7_8
},M;uU
E0X}0u
YhN$f
Y+QrPD
[-pGLJ
:E |.f
t>$+lB
bnGk!%6QP
ppIH[\,S
^s3tQy
j)@sbo
~lLR|r
Mi%{]yC
|j0< @
YHM#?#
:eMYC;
kk`xRMu
IZjI[7
V`&9{&
9M7>|V
o]}f7.
J'f)S-i
IfvjqR
yQ=#My
'(;74w
8V;p5|
am-MWa
AT.i7`]$P5`
p.|j%P
$W^IN?
+scQtd
V_}U\I
+&RR}p
(\JCd-H
LT51Pc8
uXj<'s}
{^7_X3Y
|x&-cz/
_")aH..vNZ)
nW6Z A"
!p`q}2
-9X#~s
cDPTV
)*odc6
<p2;)c
sx(CpQ
n-nU~(14
7:sgw6{
s[xLd K
)vH2Ln|y
uW:4Q0m
N$3"}^5
G595x,+Fa/
/xUjP/\A
]f.(.B
tX(*OWk
Djs=@.
?3fDze
U~3 ua
NoW/Va
(fG68%
z8u]9i
/l+dD{
E+U7[og
sv4CCy3njto
=x(;)U
7k%hMKD
jzFD*ft
8+0!e'b
o|Lh`b
Y{)--19
}adrw]
7,iYv9v3
5(,e)?g
DvU[(0
!dBb;@cf
RGv~4g
+?LL~N
Ft"=tm'
P=W2Xo
</zf'q
4^2vsI
f;u'x$
Wkpb1eKm
}*a>{}
OR8E_b
|A~+~%saW
==f\u%U
.bV]r0
+>P/{Z
}&#R$Lj
^2GWP<
+k.W!n
zt^)<JJG
|.b(Z1
:w>>j<
HRQ'z_07v]y
}X`K-(_
IQUxFW
zRa;HT
};w-#y
VoVn 3
"I3RJh
|qt>gPG
\5,%FS
ur~1Wq
6A`.}x
|A\c`v
nQDdZf
^*l\M\8e
.,@X<:`
= 4[<Y
Y'X@#<
&8TZO
J9>A<C
[_RAxz
}6}hM@
t[/!-Y
6ChQOq
Poy#|L
2$_y'fq
`Ma.-O6
;'.pO-
< kH#5
>[&U2L/Pq
?'"yKF
y:!%`i
a+?(:r
1im{Np
z-$og,
s]0;A\Y
yrDLXz
$R&HsF
CFe"lVp|6
q/69E_s
)&W8x+
>u3%ki^
5e+K*61
-`HV75x{3ie
@L%G=Q
n)a$~}g
!qH:N(
JCNNU?T
V^iq9R8
F_`zmT}
6yO(pY
3e)'k7
frRDGv
Z|;6xN
<5rbd
yP=( "9u
u@3hS(
7Tp%wk
)sHy;+H
/'0>k[
q~bJ|d
TZWf7T
o9Hu~v
< (1|l
\#7IL]
KFsg\U
2wVGLv
Sv="W]
f'-gkJ
@sD~,`!
SpJO`
J4WRF*2
n!qF#l
5k#(\P_[
P*>1&>
I,o.NQ<)
kX`Xum
XN<t3}
o9P5,5
(7y<}UF%_
^:uVH!0
T@pQ{xB
`xY6S=!m
+dtLC]
1VD{-S<
]3r_#_7h
\[E}%oLJ
}7\A#h
s3y_-3P{
P}1B=tW
9\}<wHI
zkPwU-
7;Dx"i
b(eeMa
Ab<l$
,3VBW"aX8<t}{p
7,b;-v
,MFae4
s\5>DE8
;gk@$%
;f7mwVTe
XkwA':
hi|/apO
P1<zvw%\3
RO xKBT
K 2+0?U
pDj5cnJ
a#I&Qk5t|C
Z;-$pjn$
n#0f}M}<
p1UV1J
/~6^p0<
WTx!~JYj
k-mVMV
Z?.NDc
Zo7lh~
D6_{1E
R]mLeB
a;p6-\
LB4KCir
<9CLb=8I
HDl^GH
Mz?} +
CrOMKT
<0sVb$
t0-gYjR
qL*KPD
rmXLlDt
y#e00}N-
L21LAN#
%#;ql
)CT^
_Z~uBxTG[
u||b-;
\U s\X
KFW+5B
Omal;A
.#!:]@
*$8^B{q
S;/ZK*
6N|Q`g
Pac}lS
<)jTkD
6aSqFu#5H
FvEC]j[BGt
7g._4
hDbT0uyH
y(z#&G
q")dQ]y
mz\y}n
bs2,QZ7
U3y n60
Gl`p!MY:
d^Gi2~
%1. ]2
Zvh.:x
dSgP'K
]%q(ug~.
)EZKeL
whG[=W
7j\O7&
[d#&M&
qzC4IP
i:09$`
CTF`*,
Au,q`K
L`N`w
F{frp"
n"7'O0SW
}i-?E,
b,Ox7^
\PcL^j2
wsTKlf
(b>)`kE
guCo6RJ>
C|N4`5t
%*7Q,)
e4^).^
n><B9
B9/kA\(
M#"FF
J)VN*`R
Eu&4JoRm
<RyOy!$
-un>h[6
gf`IwN;
m)vD-d6
~`[S/p$
eZH"de
+!da1I:!
9Bci&G
&?OF^#
e$AL$
,_Z>hwV
Zk#,<>
^D6t:XX
)kKCu,
k7D9C1fr
-a&Dij
A@\Q@P/E
IHQS\9
|8*>C~C'
kLfYuGq
SX{om1
wgs{Lt
"/Ay~e
}Mf%+IC
z#/h2d
;4G^{&A
*GSlK$||
H=N`A:
FkEzT5
$gpbb<
xu}Z$D
Q`<Fcc
<29!R8
&~fM6ba
"Y/hG
-8J5Lt
3}8`H04
]\3dAiNj)i
0&hvAv+-
,Fb=MW
?{L*'q
V3D$b.\g
_^sPQF
AsHfZ~
+&.1}kL
%6ED/y&-4
(null)
mscoree.dll
msvcrt.dll
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
ntdll.dll
VS_VERSION_INFO
StringFileInfo
040904B0
FileDescription
AdGuard Web Installer
LegalCopyright
(C) 2009-2018 Adguard Software Ltd
ProductName
AdGuard Web Installer
ProductVersion
CompanyName
Adguard Software Ltd
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Vidar.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.66549324
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee GenericRXVL-CM!2252417DD70E
Malwarebytes Trojan.Crypt.Generic
VIPRE Gen:Variant.Zusy.449076
Sangfor Infostealer.Win32.Vidar.Vrhz
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.66549324
K7GW Trojan ( 005a16541 )
K7AntiVirus Trojan ( 005a16541 )
BitDefenderTheta Gen:NN.ZexaF.36164.Dy0@auv0R9ei
VirIT Trojan.Win32.GenusT.DGBW
Cyren W32/ABRisk.QSFW-4458
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HSTO
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Vidar.gen
Alibaba TrojanPSW:Win32/Vidar.be493b26
NANO-Antivirus Trojan.Win32.Vidar.juvrsl
ViRobot Trojan.Win.Z.Vidar.485376.B
Rising Stealer.Vidar!8.11173 (TFE:5:kRjQ8iIk7J)
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Trojan.TR/Crypt.Agent.lwryu
DrWeb Trojan.PWS.Steam.34705
Zillya Trojan.Vidar.Win32.474
TrendMicro TrojanSpy.Win32.VIDAR.YXDDTZ
McAfee-GW-Edition GenericRXVL-CM!2252417DD70E
Trapmine Clean
FireEye Generic.mg.2252417dd70ee414
Emsisoft Trojan.GenericKD.66549324 (B)
Ikarus Trojan.Win32.Crypt
GData Win32.Trojan-Stealer.Arkei.7WNFK8
Jiangmin Trojan.PSW.Vidar.qf
Webroot W32.Trojan.Gen
Avira TR/Crypt.Agent.lwryu
Antiy-AVL Trojan/Win32.GenKryptik
Gridinsoft Spy.Win32.Vidar.bot
Xcitium Malware@#3ghgyspkmb8a
Arcabit Trojan.Generic.D3F7764C
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Vidar.gen
Microsoft Trojan:Win32/Vidar.MAN!MTB
Google Detected
AhnLab-V3 Trojan/Win.PWS.C5379969
Acronis suspicious
VBA32 TrojanPSW.Vidar
ALYac Gen:Variant.Zusy.449076
MAX malware (ai score=86)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.VIDAR.YXDDTZ
Tencent Malware.Win32.Gencirc.10bea0e9
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Kryptik.HSTO!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.