Static | ZeroBOX

PE Compile Time

2023-05-16 09:11:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005a001 0x0005a200 7.96880807042
.rsrc 0x0005e000 0x0002fa93 0x0002fc00 6.08888563687
.reloc 0x0008e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008ce98 0x00000468 LANG_INDONESIAN SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0008d33c 0x00000084 LANG_INDONESIAN SUBLANG_NEUTRAL data
RT_VERSION 0x0008d3fc 0x00000274 LANG_INDONESIAN SUBLANG_NEUTRAL data
RT_MANIFEST 0x0008d6ac 0x000003e7 LANG_INDONESIAN SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+`+e
+1+6(B
#ffffff
#333333
918(!
v4.0.30319
#Strings
djjc.exe
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
PoweredByAttribute
SmartAssembly.Attributes
Dictionary`2
System.Collections.Generic
.cctor
ParameterInfo
System.Reflection
object
method
Invoke
nhffskdgsfkdfffddadfrfffdfdhffscfdf
hkgfffgsddfffdhhddrfdafddsshcf
chfdgffdkffdafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hfsdkffddgfgfhseffdfaffdchd
fghhfgsfffrfddfffdfffddshfdasdfh
cffhdfffdfadfdfrsfsshdkfffgh
hjfdfffhgfadsffgdfdcdffffskhj
ffghrgfdffdffdfdfffkhsjd
fsfddffffddshdffgfefdfkfghj
sddddfffhedfgddjffgffffgjfsfkdgsacsafp
sgfhjffkfffgdhjsrfhddfhfffaddsfsfssfcfgdb
ddfdjffffsffhgdffafcfdssfkfhgj
ffchkfffgdafhfdsfrdsfsfj
jffgadffcffdgfgfsdehfsgkffj
jcfsfdgddhffrfdfdsdgkfff
fdfcfffhrffdgfdfdfgsfssffj
jffafffgfffdrfdfhfcsdsgkffj
jcfdhfffsffgfdsadfsdgkffff
gdddffdsdhfssfdgh
fhfsdsdfsffhfddfhhs
hsfffffd
ffffsh
shsdsfffasd
sdfffsfsfh
sdhffffssf
sfsafdsfgfs
fffdsffdshs
gsffdsd
gssdfadss
gfsfhafsfs
gffdffsdg
gsdfdffshsg
gdsdafag
hsffddafs
adsfsfdds
jdddfssf
ggffsssdfh
jfsdaffdffhg
jffdffdfsgfdgs
jsfsfffdfdf
jdffffaf
gdfddsffdfdj
kfdssfsgfh
fsffffdfg
sjffffaf
fdfssfsfs
sffffdssd
jdfffffssk
wssffssdv
gsffffssds
gffssffddsx
startupInfo
AdnailobaohncrlkpdjkhhAaSFiakebfoFdjnoIkhpomkkimSFSdemSpenaldopdmbAenbFbj
jdfhfdffdfssdkfj
hdffdfhffassdkfsh
hdffhdfasfdfdfkdf
affdsdfhfhh
sdffdsdshfdhf
hffdsffdfsshdhs
hhhgfffffdfsfh
ffdfsfhfffdhs
fddfffss
ffhdfff
hfhfdsdffsf
jhffsdfdfdh
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
djjc.resources
{049403f6-cf59-4e34-894e-a7ce91993e50}
String
System.Windows.Forms
Application
get_ExecutablePath
AssemblyName
AppDomain
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
IEnumerable`1
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
System.Runtime.InteropServices
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_CurrentDomain
get_ParameterType
TryGetValue
Encoding
System.Text
get_UTF8
GetString
Convert
FromBase64String
Intern
Assembly
GetExecutingAssembly
GetManifestResourceStream
Stream
System.IO
get_Length
ToInt32
IDisposable
Dispose
op_Equality
System.Management
ManagementClass
GetInstances
ManagementObjectCollection
GetEnumerator
ManagementObjectEnumerator
get_Current
ManagementBaseObject
ManagementObject
get_Item
ToString
MoveNext
TimeSpan
Subtract
Concat
Console
WriteLine
MD5CryptoServiceProvider
System.Security.Cryptography
get_ASCII
GetBytes
HashAlgorithm
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
RijndaelManaged
System.Collections
Double
IEnumerator
ProcessStartInfo
System.Diagnostics
set_CreateNoWindow
Process
set_StartInfo
ReadLine
ArrayList
Remove
Marshal
SizeOf
ToUInt32
IsNullOrEmpty
IntPtr
Exception
BitConverter
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
TripleDESCryptoServiceProvider
Replace
get_Message
ResourceManager
System.Resources
GetObject
get_Assembly
Directory
get_Chars
get_Location
GetDirectoryName
Exists
EnumerateDirectories
WrapNonExceptionThrows
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
2Qz{`i3
ZQ-Ciuq
<'q!
toEU&9
iBlQBI
LTR9L|
jK8gwD
xw.`b*
6"&=Q>8
BZX}5:
gf)y?~
vEq.W7P
9^!Jip-
_u9M -
,AZB#c
!*FW:V
gl@/0QL
su`<&r
&^9rPLEQ
EL?Hxy
]Cj= ~A
`,[]wu
cg ?#Q
)wN?O1
Xok4jS
ImZ&Qf
NWNAJ#*
hT|avK
aFr.3y
-|R$S
Xl\"D'N
dEU:u_;s
+"7v'W
/s_s+BJ
}wQuT|k
0')'c
$TypMU
GGUMK0
@8|j}M]~/z
q(b`#1
Nd2m_9
T%0Q'l_
gnq@[B/w
;GB,[y
uK(U1*Eg"
W%jnAf$!P
eOgP1<
m\):R
HaG 6Y
760?FW7
qT7xVl
)tIs"UFD
8o~<LCU
AD$X&x
q'L$Q1
g3\./:
:(^1+/m
3<e=(}R
zD_H`{+%~
%H/o/d+
sTH.&7
jIO2E~
SH4{-5
Z6EY66X
N]L;7*
Kb=<#7
k&P@B=/
Ex{oDq
C]ceuP
6.f7ug
7g!"6V
:"s`v+
ZqIV!U)
AM0Z(u
24Yp@C
x'EZ9X
:UZzcj
zx/wNl
Hbf9T1
>c<UPW
W5(I~^e
W[Is})
tY/4wP
06%hw"
WCR>4,T+
tjtNn
5Vo!PtC
!+WGhn
zWR N
&`(k9L%
/bw.,o
[M{#zV
~a1Q669M
w{-B\Y
WH`5 >
U\<B;-hM
.dAlF*
tA;^Ro
{e>G@n
*k:dW'
rN'68O
rX~_;Pp
8YvHa<
`5TtU2
g%QitdgF
'>S2T.
|P$G{J
a| 5AwC
_Sgg-6
gt5/Z/
n{|=e2
/9SG1g
VK*)9S
7O@c+t
@7| SH
d@3nJm
dyUSD~
YWXs|a
&p:YM{$;W
~$]%1O
.yML"H>
b6E[gq
7S&pi;
oqq-M]bp
fH?GCD
*#O84I
(GbEu*M
u/l=yA:/
c'k1o
t:qudd
~qe5/!
Loh&C
$'u`/\r
1HMNjh}
nkSF<M`r
R7BCWV
5+@}P
&vd}zu
h3Rp3_
*l=VqW
9],$}4>;
Zj%]:
oSYK:4
e+d%-|
.I1 \S
DwZJg#
1DjBsGV
$H;2)1G
%[0El@r
-gDi7(
8um=GN
~2ELzD
6WRF!^
la42"a
It`y%=
{k*qWm
]Y ;F9Q
et-#?,
6xFd55
!YFw.9"
fCs|Q
-foPbU
D!W#1)m`
O{[fO~\
Q@o^h{
K1h~!*V
j,N&84s
g[oUBc
!ipi$B8
Z_L}%C5
Ts9"?T4
s4sRlJ
YaHuju
#nTy~i
"v5.X\
,|Yr,P
ET DNo
QZ1rx.
W3ii%r
e|LCcgP
KI"<{B
0nPlJI
~t`t\G
aw2r0w
.r(3pU
q7`TN8
)QR2]q#<2
SL$9<53Jy
&XfX}c
WQW{Y+
&XfX}c
5@p+u0
p<#)5(
{G?CxA
71<(C{R
gXcO_m+!
ioyEm{
EkGR{k
{uV-Q~
{HLUe-
.=Odw
.0=:OU
Q~o"L<
NWNAJ#*
2r^qe_e
H.23P4
Dy5,w4
F/av4<_
=SaoJQ]
1`q3[-c
H7K8O3
,porXCz
E<kENp
zt@Yu.
+mAM76
:*3z."
B&%.n
4o~ooQ
P/+fm?
6?E[J@
5ACSZ!
K.,\"%8
2j(pus
gA69BP<
K.Cq?(
_`ZR#YZ
QtEzMw
,f:XXL
+PB7(=~
%J\XlN
YaHuju
fZ::aR4IA(
U_L]u/{
Y[\ud15
n $s6V
P+]?y*
9P[#+]
0qZo~d@
ODICe(
y[V@3MU
>Llm~w
BBG]gusP
H*mfF!
=(Ea9
oF>\^S
uXpUQr
krF4v}
?3x=<G/
(q=T\"
8P[27~Pmj
=D$kX![
AWI5n|
&v1k&NG
{H-=gb
m\):R
,mRRL}
BVGGU$
0aO9yLoaQ|
_:~bIJ
">XjiOT
DnH?:\
Xg!GC+
'mrY|Gcl
b5J<pa
orrb($
-,)*lN
"UWk)8
#X`G\u
9P%,yop$1
Wc>\%)
C4b(}N}^
]jR>RP
I(c$I`
_XbtTX
_XbtTX
1GkQ*P}
pB/;y8
V}X=>D
b.L`/
V.$9>c
49+!
!f_]8g
*FjiMi
C6@!]=
DSc_e)>8
QZy#bu6LmS
vMs@/t
*FjiMi
C6@!]=
K?:8LO
4g&)RN
7dAB*{
Cou4dR
l 85sqB_H
Q<HXcQ
E_TNp
i+ I'g
Z:jT/
g|jwVQ
*WM><e3
"*7Z^~
wV,H*!Y
N'a}]M1
8|uF$vd
%)KJA^
-p>!54
"?qp[.f
VignA%
~n[m(S
K0%$[!
(_.GhE2
s~cNrG|
9 *OG
;CE!n7E
|#1E0Q8
.NG(sI
m4rGK6
l9:dX%
=20!*P
k0Z|59e
s5Suj*
Bla:w(H
yN9]b7
n$6&^&
d:y/\O
_OZ]p)]v
FK9#hm
DK<%YZ
IfzEc3_m
[:TH.Ao
hJNzBtB
Ky(gt1
gkiaS|{
]*jUhC
Yzm`w|]
<J+f>.
I^MEDU%
\z7b#uBL
ji<Z!B+_
*3p`U= Q
p`eoZ
;^pGs$
(/C9W;
4okf[+
"-W(q3G
KpcV..
:E@`4?
v~RdAU
lk `gC
s2r\3m
kT&?V#&9
`_J'%
4Rqm]Ky
,dG%$'Y^k-
2(mX]BCL
6x9B+5
Ko7EKw
]zHNC;U
FbEJR%
71ipa^.
9FXhk
Mp~UH$aZ
ANPB9q
"t-izi
Nq*Fj+
H7]osC
<bEw?^
e04bcW*%
[7;&ED
R~.,}U
wI2'
wYxf9<
y"Md8!
.?Q+/m
B]#@Kq=C1B
^\0S>P
twZ~>>
D-S"hN
<nIov,
kxi`_F9
sgq7KV
W"h/~p
{n2y"H
EA>,8Ir
J9Ay`
_r*S*|
7r6KaO
M:B<6S
GD6^^&
Jhon,U?'
w{NlnQ
}{cWkUH
3hs=-r
c.nB6
E).9/(
N\!@DwG
@ly9*F
;^wY+&
g/:TRJ
MLys:h
v@5GI?
IIR(lNE
g<\ At
7d/8[eo6
O2)~M8
N-aq[bS
_q,.kb
sh|iYX
[6vh}-A=
QOxj:0
Dzbvp*
8v@n-B
[0o/8D
PMrV{x
,e^9h6
VP%}9
ThSix$
v'Amjvt;@
sc4yd\EFN(
U~Pkz[{.h~
8@?Hhf}
se4,&i2I
$H-Y'|
wAdG+!
aL-p?*
w)7p}O>
]\\cyl
p|I>%
<TxH>s
Q,Qe-.
0c]6!9
;Qu+kZ
>r;-Ko
hE+;m|y
tua<4aP
Cu#]wi
5,}QTN
#<'nZu
xEZ:!K
=[3U\6
~RUS5/
<*3P5_E
NT/0^8)yb
yOZL8R
ka}VGe
9%B"Vn
=U>bYAx
TN2lc\
;<:EaF
B|i>>{
\Gqwg'J
v:;|=;
=LOe\'J
MBt[3:
Ii1uf"
/NLShK
p'\~h\
@>7B->
hU}eVs
@>7B->
&~u["3#
Z e9tBw
5=J:N5
bt5b_$
bt5b_$
V?EN|!
j@Y`//
W[/Xczd
3lCtze[
=BVCzQQ
0fge4OM
n, J{
)|R0l3
;)E&s3
;=H3-
gi.3~w$
gi.3~w$
7`>!r@
pPnNq~
E:(q7<
%NkH%tI}
!xq!LG
H`o(kn
.&2luS
XY#3^A
ek-:+R
Kq[ +^du
:5[4"m
Q`=u6^
j2~qhNI1
8TO%VA
Jy~S(GH
&h7QS
n{Z 2#
j%sE4"lh$hU
aN}0\b1
pfQ3LD
Tu>687
(zErS@G
>m'>q@
|rX[z^
a>p-#
bGzbPa
Jz~f[]
>mx/Oj
5cIC?gj
PJJX}1K
Peqj,Kuq
P{_tTg
0C4HiB
'CQ%#k#x
4 R~Uj
Wz7=3m3
VNt}TV
~L>O?X
uRCqwR
0P=4p0bb
OPWmEK#(
k?Od/g
p+PWWi-
g@F!!K
0bT?ek
<>|Z>g
z "ga<*d
~-c;?(
#T=I}-slM
gA;yU6k
.}TYRale
~cn2_]
2dRRhE
d]*Ies
j|X|Ua
\_JH?
]r,QIY
6e{R J>
^_AD-]
a\)[H6
!;em<C
#NL%=i
-;y.~w
}!9iVyTW
nA?(TEK,
j@")yb
4!\"1=
Kb!w6sz
}*Zzc?
Gwife]
wK aQ,
K^NjYzg
.\X{yw
pKU<qo
[Px(4X
d_ja[%
R]D'2K
tSVY(+R
*gN@@&
,b3Fva1JMa2FRT2RjTEZ2NlRRbm9lUDdXUXZpcy9aMkk=
ZGpqYw==,b3Fva1JMa2FRT2NvcWs2NWRhd2ZZLzdXUXZpcy9aMkk=
RHluYW1pY0RsbEludm9rZVR5cGU=
RkwyV3dQNDlhZjA9 OTVBVUVZSy8vb1o3bFBWUmhuUmFtQT09,Z3hDYS9xdW0vanlxam1zNXZtU2VmTTBXS0RmSzdZRys=,cWlwVm85SkQvMlhkM2l6dWRnNXZWUDdXUXZpcy9aMkk=,M1VpY1ZUVXJ3OElNZ1BzdlFxNGkwOG56OXczV2tCdnA= aEdyVFVxcUJ4Mm1VSmpLQzIyNUhPUT09,NERUdHMxSnBtVXVpR1hoeXVUQUlTV0ZCQmpjdHMyUXg=,ck9VaFplNHkrUkdxam1zNXZtU2VmTTBXS0RmSzdZRys=,UVFzTU5nZnhRamJkM2l6dWRnNXZWUDdXUXZpcy9aMkk= UE9ZWG5XVlRXcWt4VTBNZEpqQ3Z6QT09 b01JKzlMc1paRUo3bFBWUmhuUmFtQT09,QUlIZy9ZMENXWDBtYnlqYk42dWRoSVdKU1JlajhhanI=
8U3VidHJhY3Rpb24gb2YgdGltZXNwYW4xIGZyb20gdGltZXNwYW4yIDog$VmFsdWVzIGFmdGVyIHN3YXBwaW5nIGFyZTo=
V2luMzJfUHJvY2Vzc29y
VW5pcXVlSWQ=
UHJvY2Vzc29ySWQ=
TmFtZQ==
TWFudWZhY3R1cmVy
TWF4Q2xvY2tTcGVlZA==
R2Vla3M=
Z2Vla3Nmb3JnZWVrcw==
c2RmZmQ=
L2NzZnNmIA==
RW50ZXIgVmFsdWUgb2YgTiA6IA==
UFFS0VmFsdWVzIGluIGFycmF5IGxpc3QgYmVmb3JlIFJlbW92ZQ==0CgpWYWx1ZXMgaW4gYXJyYXkgbGlzdCBhZnRlciByZW1vdmU=
ZGFkYWg=
ZGRkZGRkZGRkZA==
_CorExeMain
mscoree.dll
RR)%SJQ
QRJM)U
:::d0D
|6L#X~9X
ISJu0]
P TR$pC
>9v*r~
Ay7P'|
,J)i<
+,#xJ)
mx_ap6
EZ#J)b
ON0\Oo
RJQFC"O
+R+H%
c:8@AC
'}H%KYvo
T&}2!\
T$;}9|
sR+xSg"
Hww7->
bffFF"
ytuuadddA?
?mS1>S
8v+xTy
C"3aX
D$\{IP
(QJ%Zkm
V/@H)ec
@G/`N^
Y*$"R!M
n`jtpf
fk"cS*
;^Q!tI
A@Zkji
xP}]Ji
J4??/k
Ra)%|y0
`vvVT*
R:"bk-7*
7022"|X
CZk122"
(((((()))
'''!''''(((,&&&/&&&2&&&2&&&/(((,'''''''!***
)))%'''-'''4&&&9(((>)))A'''D'''D)))A(((>&&&9'''4'''-)))%)))
)))%(((.(((6(((>(((C',(N'>*
(-(J(((>(((6(((.)))%+++
'''"''',(((5(((>(((E'+(N'C+
(+(J(((>'''5''','''"(((
'''((((2(((<(((D(((J'<*~&W.
(<+|(((D(((<(((3'''()))
'''#(((.'''8'''A(((H'0)]&O.
(2)\'''A'''8(((.)))#***
'''((((3(((=)))E()(L&D,
)*)G(((='''3)))((((
(((!'''-'''8***A(((I(2*b&T/
(4*a***A'''8'''-'''"+++
(((&)))1'''<'''E'('K&D-
'((F'''=)))1(((&)))
((()%%%5)))@'''H'0)Z%T0
'0)W)))@%%%5'''****
&&&!'''-(((9(((C(((J&;,z%]3
'=-w(((C(((9'''-&&&!+++
+++#'''0(((<'''E')(M&K0
')(G(((<'''0'''#)))
(((%(((2'''>(((G'/*W$V2
'/*S'''>(((2(((&***
&&&'&&&4(((@'''I'6,i$^5
&5+g)))@&&&4(((')))
((()(((6(((B(((I&@.
'A/~(((B(((6((()(((
))))'''7)))C(((J%F0
)))C'''7''')'''
'''*(((7(((C(((K%N2
(((C(((7'''*)))
'''*)))7(((C()(K%S4
()(D)))7'''*'''
'''))))7(((C()(L%T5
()(D)))7''')(((
(((('''7(((C()(K%U6
(*)E'''7((())))
'''''''5)))B()(K#U6
)))C(((6''''***
(((%'''4)))A(((J#R5
(((A'''4(((%+++
(((")))2(((@'''I$L4
(((@)))2(((",,,
''' '''/(((='''H%D1
(((='''/''' '''
(((,)));(((G&8.i!j?
&9.e)));(((,***
'''((((7)))D'0+U!g>
(1+O(((7'''('''
'''$'''4***A()(K"];
*+*B'''4'''$,,,
((('''/(((>'''I$Q6
(((>'''/((((((
(((*''':(((G%:/mnB
&;/h''':(((*(((
)))%&&&5(((C(-*Q iA
(.*H&&&5)))%+++
(((&&&/(((?'''J"V:
(((?&&&/(((***
))))''':(((F%=0o qD
%>1k''':))))***
)))#'''4)))C'*(N kC
(,*E'''4)))#&&&
(((-(((=(((I#R9
'''=(((-)))
'''&(((7'''E&5.^sG
&5.W(((7'''&+++
(((&&&0)))?(((J!_?
)))?&&&0)))+++
***(&&&9(((F$@2q
$@3l&&&9***((((
(((!(((2'''A'''KlE
'''B(((2(((!***
)))*(((;(((G#G5
#I6|(((;))))+++
'''"(((3)))B'*(M
)+*C(((3'''"***
(((*(((;(((H#L8
(((;)))****
'''!(((3)))C(*)M
)+*D(((3'''!***
))))''';(((H#L9
''';))))+++
))) (((2(((B'''L
(((B(((2))) (((
(((((((:(((G#G6|
#G7v(((:***()))
)))&&&0(((A'''K
)))A&&&0)))(((
(((&'''8(((F%?3i
%@4b'''8(((&+++
(((-(((?'''JdE
)))?(((.***
(((#'''5(((D'1-T
&2,M(((5(((#,,,
(((*(((<(((H"S=
(((<(((+***
***&&&2(((B'''K
(((B(((2))) '''
(((&'''8(((F#B5k
$C5e'''8(((&+++
)))-(((>'''JeG
)))>'''-***
'''"'''4(((C'-*O
'-+F'''4'''"+++
)))(''':(((H"M:
"L:z''':)))((((
'''.)))?(((J
)))?'''.***
&&&"'''4(((D'/,Q
'/,I'''4&&&"+++
)))(''':(((H!O=
''':)))((((
(((.)))?(((J
)))?(((.)))
'''!'''3(((D'-*O
'-*G'''3'''!)))
'''''''9(((G"M<y
"L<t'''8''''(((
''','''>'''J
'''>(((,+++
(((&&&1(((B(((K
(((B&&&1((((((
&&&$)))6(((F$B7e
$C7^(((6&&&$,,,
((()(((;(((I YC
''';((()(((
(((.)))@'''K
)))@(((.)))
''' (((3'''C(**M
'*)D(((2''' &&&
&&&$(((7(((F#I;n
#I;h(((7&&&$+++
((()''';(((I]E
''';((()(((
'''-)))?'''K
(((?'''-***
&&&1(((B()(L
()(B&&&1)))
&&&"(((4(((E#C7c
$D8[(((4'''",,,
'''%'''8(((G VC
'''8'''%+++
)))(&&&;(((I
''':***(&&&
(((*(((='''J
)))=(((*+++
'''-(((?'''K
(((?'''-+++
'''/(((A%60T
%50I&&&.(((
'''0(((B!N?p
!P?f'''0***
(((&&&2'''DZF
&&&2((()))
&&& (((3(((D
'''3&&& ***
)))!)))5(((E
)))4)))!(((
)))")))5(((F
)))5)))",,,
'''#'''6(((F
'''6'''#...
&&&$'''7(,*H
'*)8&&&$---
&&&$)))7$E:Z
#F:J&&&$,,,
'''%(((8!QBk
RB\&&&$,,,
)))%(((8YGz
YFm)))%***
(((&'''9
^I}(((%***
)))&'''9
(((&***
+++&'''9
(((&***
+++&'''9
(((&***
+++&'''9
(((&***
***&'''9
(((%***
)))%(((8
'''%***
%%%%(((8
%%%%+++
&&&$)))7
&&&$,,,
&&&$)))7
&&&$,,,
&&&$'''7
&&&$...
'''#'''7
'''#...
(((#(((6
(((",,,
)))")))5
)))"(((
&&&!)))4
cOr&&&!***
(((1#@8T
"B9B)))
(((,)))?
(((,)))
***$'''5%<6Q
#<5C***$)))
&&&''''3(((<"C:R
aN{!C:N'''3&&&')))
&&&")))(''',%%%.&&&/(((0'''0'''0'''1&&&2&&&2(((3)))5(((6'''7(((9''':(((<)))>(((?)))A(((D(((E(((H'''J'''K!G<`
!G<_'''J(((H(((E(((D)))A(((?)))=(((<''':(((9'''7(((6)))5(((3&&&2&&&2'''1'''0'''0(((0&&&/%%%.''',)))(&&&"***
(((''' &&& )))!(((#&&&$(((&***'((())))+'''-(((/'''2(((5(((9'''=(((@'''E(((H'''K#A8^
$;5W(((H'''E(((@'''=(((9(((5'''2(((/'''-)))+((()***'(((&&&&$(((#)))!&&& ''' ((()))
''' (((#(((&(((*'''/&&&5&&&;(((@(((E'''I&/,O
[Jy'((J(((E(((@&&&;&&&5'''/(((*(((&(((#''' )))
&&&#)))(&&&/(((6(((=(((D(((H'**M
PCm'''I(((D(((>)))6&&&/)))(&&&#(((
)))$''',&&&4'''=(((C(((I',+N
SEq'''I(((D'''=&&&5''',)))%(((
'''#''',&&&5(((=(((D'''J&3/R
UFs'''J'''E'''=&&&5&&&,'''#)))
)))#(((,%%%6)))>(((F'''J#>7[
'((K)))F)))?)))6'''-)))$+++
)))%'''.(((7(((@(((G'''KQCn
&-+N(((G(((@'''8'''.)))%***
''''%%%0''':)))B(((H())L
$94V'''H)))B(((:***0'''''''
))) ))))(((3(((<(((D'''J%72T
"E<b'''I(((D'''<'''3))))((( ***
'''"(((,'''5)))>(((E(((J"D;`
TFr(((J(((E)))>'''5(((,&&&"***
***$(((.(((7(((?)))F'''JWHs
_M}(((J(((F(((?(((7(((.)))%)))
(((&'''.(((7)))>(((D(((H
ZIv(((H(((D)))>(((7'''.(((&)))
(((%(((-)))4''';)))@(((C(((D(((D(((C)))@&&&;'''4(((-(((%(((
(((")))(&&&-'''1'''2'''2'''1&&&-)))(&&&"***
&&& &&& )))
'''%'''*(((-(((-'''*'''%)))
)))!(((,'''5'''=(,)I'2(g'3(p(2)^')'@'''5(((,)))!(((
)))(((+(((8(((A'/(Y&E+
(,(K(((8(((+)))'''
'''''''4(((@(*(M&B+
';+}'''@'''4''''(((
(((!(((.(((<(((G'7*t&T/
'2)_'''<(((/)))!+++
(((''''5(((B(-)V&I-
(*(F(((5(((')))
))),''';'('F'8+s%W0
'1)\''';))),'''
)))#'''2(((@'+(P&I.
()(A'''2)))#'''
'''&'''6'('D'2*b%U2
'-)P'''6'''&)))
))))'''9(((F&;,{$]4
'3+^'''9((()***
&&&,(((<')(J%G0
&;,x(((=''',)))
(((-(((>(,)P%O2
()(@(((-(((
(((.'''?',)R$T4
'''?'''.)))
(((/(((?'.)V$\7
(+)D(((/(((
'''-(((?'/*Y$[7
(+)D'''-)))
&&&+(((>'.*V#[8
(((>''',+++
(((*'''=(,)O"\8
')(?(((****
(((&(((:'*(M#V7
()(;(((&(((
)))"(((5(((F#M5
&?0w(((5)))"&&&
'''2(((C%C1
'5-Z'''2'''
''',(((?&5,c!j@
'.*I''',)))
(((%''';'+)O!`=
''';(((%'''
)))'''4(((F#Q8
&A1v'''4)))$$$
(((,'''@%;/o nC
'.*I(((,+++
((($(((9')(J f@
()(:((($&&&
(((2(((D#M7
%<0i(((2)))
'''((((>&3,^oF
(+)B'''('''
)))'''4(((G!Z=
'''4)))'''
(((+'''@%<0m
',)E(((+***
((( (((6(((H cB
(((6((( &&&
(((,(((A%=1n
(0,M(((+)))
))) (((7(*)KfD
(((7))) &&&
(((*'''A%>2p
&/+L(((*)))
)))5'''HcC
)))5***
''')'''?%:0f
(+)A'''))))
(((2(((F \A
$G7x(((3***
(((%'''<'-*O
'*)>(((%'''
(((/(((C"N;
&91\'''/)))
))) '''8'*)K
(((8))) $$$
)))('''@%<2h
(.+E'''()))
'''1(((F]B
#F7u'''1)))
((("(((9',*N
(((9((("'''
'''*(((@$A5q
'+*C(((*)))
'''2(((F
#J:w(((2)))
((("(((9()(J
(((9'''"%%%
''')(((@$?4f
'/,H''')'''
'''1'''E\D
#C6j'''0***
(((7'*)K
'''7(((
'''%(((=&4.\
'((='''$&&&
'''+(((B O>
%:2W(((+)))
(((1'''G
"M=|(((1(((
''''''7()(J
'''7'''###
((($)))<$:2`
(((<((($(((
''')(((@"K<}
&1,G'''))))
'''.(((D
"H;j'''.+++
'''2'''F
'''1(((
(((5'''H
(((5***
((('''7&0,N
&)(9'''()(
)))"''':"F:i
%1-D)))!%%%
'''#'''; Q@
$60O'''#'''
)))%)))=
"L=b)))%%%%
)))&(((>
YFz(((&'''
'''''''?
''''(((
&&&((/,C
&&&(+++
'''('3/J
'''(+++
((()&50O
((()***
(((*%61T
''')***
****#A7\
%.,-***
****!M?e
$723***
))))TDl
$=58***
''')ZHs
">6=***
!@6@,,,
!@7?,,,
"?6;(((
((('SCh
$<53(((
)))%#?7W
(.,'$$$
'''$&61J
'''$&&&
))) '*):
))) $%$
(((.#C:[
&408)))
'''.')):!J>[
VGyUFwUFx
UFyVG}
XH|ZI
VGs"A8M'''.(((
((( '''$'''%(((&***')))'(((('''))))+''',&&&.(((0(((3(((5(((8(((<(((?'''C')(G%40USEw
!F<h&1.N'''C(((?(((<(((8(((5(((3(((0&&&.''',)))+''')(((()))'***'(((&'''%'''$((( )))
))) (((#'''((((-&&&3''':'''A(((H#<5]
&1.N'''A''':&&&3(((-'''((((#))) )))
((("'''+(((4'''=(((E&2/R
PBp'''F'''>(((4'''+((("(((
'''(&&&3'''>(((F$73Y
RDv',*I'''>&&&3'''()))
(((('''4(((?(((H"C:e
',+K(((@(((4(((()))
((()'''6'''A'''ISEs
'+*J(((A'''6((())))
''' '''-(((9(((D&/-P
$83Y(((D(((9)))-))) (((
'''#'''0(((<(((F$93Z
"D;d(((F(((<'''0'''$***
)))&(((2(((=(((F"B9a
!F=f(((F(((=(((2)))&)))
((('(((2(((;'))D"C:_
"D;`'*)D''';(((2(((')))
)))$(((-'''3'''6'''6'''3'''-'''$***
(((!(((!)))
)))&'''3(((='/(W'0(`',(G'''3)))&)))
((($(((5()(E':*
(1)Z(((5((($)))
'''/(((@'3)h&P.
(+(G'''/)))
(((&(((8(+)M&E-
'8+r(((9(((&(((
(((-'''@'5*k%U0
'+(G(((-(((
((('''4()(G&C-
'4*b'''4'''&&&
)))#(((8',)R%Q1
'''8(((#+++
(((''''<'3*e$[5
'*(A((('(((
(((((((>&8,r#`7
'+)E'''('''
(((((((?&=.~#e:
(-*J(((('''
((('(((?&=.
(.*K((('***
'''%(((=&=.z"h=
',)D(((%$%$
))) (((:&8-l"h>
(+)?))) %%%
(((5'1+Z!e=
(((5)))
'''/(*)I"^;
'''/(((
(((''''A#O6
&4,Y(((&&&&
'''9%<0s qE
')(<)))
(((/'+)L gA
(((/(((
((($(((@#P8
&3,U((($%%%
'''5&5-arG
'((5(((
(((('''C!_?
$=1l((((&'&
(((8%<1pyN
(*):)))
(((*())F eC
%C4t(((*&&&
(((8%>2q
()):)))
(((((((DeD
$@3o)))(&&&
'''6%:0f
'('6)))
)))$'''A ]B
&80Y)))$%&%
'''1'.+P
'''1(((
'''<"M:
'-+C)))
((()'((E
#H9{''')&''
(((4%80a
(((4(((
((( (((> V@
'/,E))) %%%
(((*(((E
'''*&''
'''3&5/Y
'''3'''
'''<!R?
&.+D)))
(((&(((C
#D7l(((&$$$
'''.&/,P
'''.'''
(((6#A6n
(((6(((
'''=\E
&1-F(((
(((%(((B
"F9n(((%%%%
(((*(((F
(((*(((
(((/$91Z
(((/%%%
'''3"G:u
&('4)))
&0,?(((
%:2M)))
"L>d***
SB{***
`Lx(((
((((!I>e
'.,-%&&
(((%')(0&+)6&1.:%72>$40>'-+;(-+<&+*>&+*@',+C',*F'-+K#>7ZPCw
!J>i%82Q',+F',+C&+*@&+*>(-+<',+;%2/=%;4@%72=%.,9'+*2(((%)))
))) ((($(((('''.'''6'''?'+*I M@r
%72T'''?'''6'''.((((((($))) )))
((( (((+'''8(((D"C:f
'*)F'''9(((,((( (((
''')'''9'((E NAs
'.,K'''9'''*)))
(((+(((;'))H
&1.O(((;(((+)))
((((((/(((?%3/S
#<6\(((?(((/)))&&&
(((#(((3(((A#@9a
!G=h(((A(((3(((#'''
(((%(((4())@"F<d
!G=f')(@(((4(((%)))
)))"''',(((1(((1''',(((")))
)))!'''''''')))!)))
))))'''8'.(T'>*
'7)r')':))))***
'''%'''8(-)S&H,
'9*z'''8'''%(((
(((0(((C'>+
'/)U(((0***
)))$'''9(/)Z&P/
''':)))$%%%
(((+(((@&<,
'-)L(((+'''
(((1')(H%K0
'5+h'''1)))
'''5'.)U$V4
'''5)))
(((7'1+^#]6
'''7(((
(((7'3+d#b9
(((7(((
(((6'4+d#d;
(((6***
(((2'1+Z"d;
(((2)))
(((-',)M"a;
(((-&&&
'''&()(B#X9
'8.d'''&$%%
'''<$H3
',)D(((
'''2&5-b qF
'''2'''
)))&(((D!c?
%?1q)))&$$$
(((9$H5
'+)>)))
''','.+PpG
(((,'''
(((="T;
'0+J)))
(((.'2,X
(((.&&&
(((>!Y>
&1,M)))
(((-&/+T
)))-&&&
'''<!U=
'-*C)))
(((('*)H
((((&&&
(((6#F7
(((7(((
)))!'''B
%>3b)))!$%%
'''.&2-V
'''.&&&
(((9!R>
()):)))
)))"(((C
#D7m((("%&&
'''-&2-U
'''-$$$
'''7!O=
'''7(((
$:2Y(((
(((''((G
((('%&&
'''0$=4f
'''0&&&
(((8WC
'''8)))
%:2R)))
))) '''B
!P?z))) ###
((($'+)H
((($&''
'''($>5`
((((%&&
(((*!N?{'
(((*$&&
(((,%)'
&/,3(-+
#>6E(*)
"D9U'''
OAe'''
ZHm'''
^Jt(+*
`Lv)52
_Kp$0-
RC`#-*
$=6<$,*
))) "G<a
))) ",)
'''&&.,9!E;[ NAiTElM@j"J?g!H=d!F<b"F<d"F<g!J?r
UF{!H=l!G<g!G<d!H=d"J?gL?jUFmTEl K?e#=6G'''&')(
)))!(((%'''*(((1''':'''C#A9c
',+F''':(((1'''*(((%)))!)))
(((#(((1'''?%72X
MAq'''@(((1(((#(((
)))(((0'''@#?7`
QDv(((A'''0))) &&&
(((!'''3(((DQCu
())D(((4)))"(((
(((&(((8',*H
&/-L'''8(((&'''
(((*(((:%40P
%61R(((:(((*(((
)))((((4''':''':'''4(((()))
'''-'+(B'-(I'('.)))
(((/(/)X&J,
'9*w(((/'''
((($()(A'A,
'/)Q)))%$$$
(((/'1)^%V3
(((/&&&
'''7&=,
'*(=(((
'((>%I0
'/*N(((
()(@$Q4
'2+W(((
(*(@$S5
'3,X)))
'((;$R6
'1+M'('
(((3$I3
(+)9&&&
((()&:.p%}U
((()$%$
',)J"mG
%@1u(((
(((5"T:
'-*>&&&
((($&7.e&
((($%&&
(((:!dC
'3-N'''
(((&%=2p(
)))&%%%
(((: fE
&4-N'''
(((#%90e(
(((#$%%
(((5 ^B
',*<&&&
(((*"J:
(((*&&&
&1-E&''
(((("I:
((('$%%
',*9&&&
#A6d&&&
((($!K<|6
((($%%%
())*%&&
&.+6%&&
%=5J%'&
!H;b'+*
WEu'+*
SDc$-*
(+* #.+
((()))"(((&(((+(((2'(';%51R
"B9a'*)<(((2(((+(((&)))"((('''
(((.'*)B
%1.J(((.(((
(((.&.,I
%61Q(((/(((
(((4$:4X
#A9`'''4(((
)))"(((7!G=f
I>i(((7)))"%%%
(((((((('''
'''!'1)Z&N3
'8*p'''!%&%
(*(8&H0
(.)D%%%
'1*X%dB
&9,r'''
&9,r&yU
'0*N'~Z
%</l%&%
(((,%fH
'-*7$%%
&6.P%&&
'3.E%%%
(((##iM
'(($%%%
$=3Z%%%
'-+/%%%
$@6W%%%
SBx%&&
%0-/$=6@$:4A%83@%72D#>6U
"B9[%83F%83@$93@$?7A$515%*(
(((("A8^!
L@l((()&&&
(((,QDt+
XI}(((-&'&
'+*4&&&
&'&"&(&$&&&
'''!'?/
')'%$$$
',(?%_C
&1)M&&&
'3+U&xW
';/j&&&
'=0j%&%
',)7)}\
&3,H$$$
$L;|%%%
%4.>
YHpVFoUFr]K
UFsVFp
ZIqOA^$,*
$<6M&&&
"H>_&&&
&3*L&6+U$$$
&(&!&ZC
&,)/'vY
%-+&.ze
%0-*"""
$401$501###
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
{049403f6-cf59-4e34-894e-a7ce91993e50}
https://subf.domfagdffa6fafiffn.comd/objecsts.json?api_key=123
{"objeact":{"ffffffudgfndaf":"Naddfme"}}
https:/f/susb.doffmfyffagffdin.com/obadjdects.json?api_key=123
{"obfject":{"nfffuaffffgmef":"dNaafme"}}
https:/f/sub.dofmuffffgfain.com/objecadts.json?api_key=123
{"obfject":{"nffufgfafcme":"Naafme"}}
VS_VERSION_INFO
StringFileInfo
000004b0
CompanyName
Bernd Schuster
FileDescription
W10Privacy Setup
FileVersion
4.1.2.3
LegalCopyright
Copyright (C) 2023 Bernd Schuster
ProductName
W10Privacy.exe
ProductVersion
4.1.2.3
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.de27e688202b4fc3
CAT-QuickHeal Clean
McAfee Artemis!DE27E688202B
Cylance unsafe
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.MSIL.Stealerc.gen
Alibaba Trojan:MSIL/Kryptik.6a2fa59d
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Trojan.Win32.SMOKELOADER.YXDEQZ
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-PSW.MSIL.Stealerc.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.36196.Im0@auttqigG
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.SMOKELOADER.YXDEQZ
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:4qNwGYgUsRpFNF2ayHKCfA)
Yandex Clean
Ikarus Trojan-Spy.AgentTesla
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.9e5c3b
Avast Win32:PWSX-gen [Trj]
No IRMA results available.