Static | ZeroBOX

PE Compile Time

2023-03-12 20:55:03

PE Imphash

7e60c38086d25d57354ecdf04c4b17ba

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
0x00001000 0x00002d9e 0x00001400 7.84121138465
0x00004000 0x00000a55 0x00000200 7.47475031189
0x00005000 0x00000253 0x00000200 7.14930317482
0x00006000 0x000001b0 0x00000200 5.30711684948
0x00007000 0x00001c80 0x00000800 7.07555443384
.edata 0x00009000 0x00001000 0x00000200 0.665912752318
.idata 0x0000a000 0x00001000 0x00000200 2.71895458386
.themida 0x0000b000 0x003b6000 0x003b6000 6.3058578134

Imports

Library kernel32.dll:
0x18000a138 GetModuleHandleA
Library user32.dll:
0x18000a148 wsprintfA
Library ws2_32.dll:
0x18000a158 getaddrinfo
Library advapi32.dll:
0x18000a168 GetTokenInformation
Library secur32.dll:
0x18000a178 GetUserNameExA
Library ole32.dll:
0x18000a188 CoUninitialize

Exports

Ordinal Address Name
1 0x180001020 rundll
!This program cannot be run in DOS mode.
` U
@ S
@
@.edata
@.idata
.themida
iQ!N=acL
kS{MEwq
1p(sm|
B*nPp|'5
socks64.dll
rundll
kernel32.dll
GetModuleHandleA
user32.dll
wsprintfA
ws2_32.dll
getaddrinfo
advapi32.dll
GetTokenInformation
secur32.dll
GetUserNameExA
ole32.dll
CoUninitialize
#"fggI
AXAYAZA[A\A]A^A__^][ZYX
E37A3U
$JnkH
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
3H5rHzLL)
Mc,$H!
"[<hIM
0M39I)
,$O8ME9
-4LC-I
SOFTWARE\WinLicense
['Pqy
Ho}{M6
&i(T$dh
gjaD4S
G!_:+2
5fNNSI
3Rq)jH
E1<$M!
rHzLM!
E#'M9e
lQ:6_mg
rHzLM!
4%sPQRSUVWAWAVAUATASARAQAPH
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
xvaDM!
H5.g/GI
rA)?M!
H5.g/GH
.g/GL)
AXAYAZA[A\A]A^A__^][ZYX
k{f!(S
OLyV!J
/xXcX~
4=oDZh
!'VX)Y1
j8D2ZO
H5rHzLI
rHzLI1
H5B$0:I
E+)M9*H
3I94$I
E3<$M9;M!
*i}NDI
A32H97I
E#9L9:H
AXAYAZA[A\A]A^A__^][ZYX
ExpInfo
CheckIN
D3 L9'I
rHzLI1
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
#0H97I
+8H99H
D3)M9)I
#0H92I1
rHzLM)
'9kd:I
JahM9'I
72 7&H
H5rHzLI
0z%%mH
-~+$~
E3M9]
/DW-HH
rHzLM1
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZ
A[A\A]A^A__^][
Ic<$L1
SplashClassName
'+5zXH
AXAYAZA[A\A]A^A__^][ZYX
AYAZA[A\A]A^
A__^][ZYX
L+6E)]
rHzLH)
H5rHzLH
Please, contact the software developers with the following codes. Thank you. (version %d.%d.%d)
(press CTRL+C on this window to copy to clipboard)
CheckIN = %d
CheckOUT = %d
ProcIN = %d
ProcOUT = %d
ExitIN = %d
ExitOUT = %d
TPin = %d
HWIn = %d
IntV = %x, %x, %x, %x
/AUYQH
AXAYAZA[A\A]A^A__^][ZYX
-EJe#I
H5rHzLH5)
E1<$M)
H5rHzLI
>H5u)V
E1<$I)
A^A__^][ZYX
AXAYAZA[
rHzLL)
AXAYAZA[A\A]A^A__^][ZYX
6:Z`yI
E#3M97H
E#&L9"H
E+ M9!I
++kGbH
AXAYAZA[A\A]A^A__^][ZYX
5pA-aI
05k_E|H
AXAYAZA[A\A]A^A__^][ZYX
"Jw]1M1
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
TP_IN = %d
D3.L9*H
2Z'FdH
],6_H!
E+'L9&H
{NluI1
AXAYAZA[A\A]A^A__^][ZYX
D+:L9?H
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AYAZA[A\
2AVYQH
AXAYAZA[A\A]A^A__^][ZYX
4$AYUH
/ATz.I
AXAYAZA[A\A]A^A__^][ZYX
/`H'LH
AXAYAZA[A\A]A^A__^][ZYX
rHzLI!
Exception Information
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
rHzLM!
AXAYAZA[A\A]A^A__^][ZYX
UBn6bJ
6/checkprotection
.S^F9%
D+2M97H
E++L9+H
1AXAYH
AXAYAZA[A\A]A^A__^][ZYX
x/showcode2
rH5O.k;I
rHzLM)
O.k;I)
/skipactivexreg
E3#M9&I
rHzLM)
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
.Oo%qH
E'S;gp
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZ
A\A]A^A_
AXAYAZA[A\A]A^A__^][ZYX
/getwlstatus
7VMc)I
W4#-Gg
AXAYAZA[A\A]A^A__^][ZYX
:&R:fx
WLProtectionDateTime
A#;I9<$H
D+:M9>H
|XBH_FNT
AXAYAZA[A\A]A^A__^]
$?>4+
A^A__^][
AYAZA[A\A]
3;H98M)
J,X@l~
VHt#OX
=)U=in
Activation1679467762
VHt#OX
AXAYAZA[A\A]A^A__^][ZYX
PROC_IN = %d, Process = %x
H5rHzLI
A]A^A__^
AZA[A\
VHt#OX
=)U=in
U<hP||
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
<#O7ce
/bugcheckfull
/showinstance
Software\WLkt
(A[H-DS
AXAYAZA[A\A]A^A__^][ZYX
A32I9u
AXAYAZA[A\A]A^A__^][ZYX
rHzLI)
7tRZI!
)Z|}4H
&8MQH)
D#*M9,$H
<$A!2L9?I
QAPAQA
AYD)D$
A32H97H
3Z@U/M
fE1,$I
rHzLH1
*I+;L)
#7I92I
rHzLI1
#QExitOk
AXAYAZA[A\A]A^A__^][ZYX
?Q{Y%&
#T*&;I
/ee8'I
A3>I9<$H
3>H99L3:M1
E+,$M9+L)
AXAYAZA[A\A]
+:H9>H
VHt#OX
=)U=in
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
XprotExit
/showcode
AXAYAZA[A\A]A^A__^][ZYX
/nosplash
/bugcheck
AXAYAZA[A\
A]A^A__
^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
&6MT[I
rHzLM1
AXAYAZA[A\A]A^A__^][ZYX
rHzLM!
3TDeTH
AXAYAZA[A\A]A^A__^][ZYX
<$M9;H
p5<.H
D#?M9;H
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
E+7M94$A
A!4$M!
6AVYQH
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__^][ZYX
n#I+1I
N+W?ky
nAWAQH
hTf.3H
,$\AQh
@K}YATA
A\AYAWAUh*
4$YAWI
L3<$L1<$L3<$\QAQA
,$-vsZ
%|kAPA
,$r1~wY
r1~wA^H
_ASPSH
mPAPXH
D$pUATM
P]y[H9
H34$H14$H34$H
4$XAUI
$ASTA[I
4$AXAVI
L34$L14$L34$H
4$YARTAZI
$\ATAQA
ARQASA
RH-go7[H-e
$AWAVI
zhcj}^h
$AVTA^I
OAYAUA
>?QAPP
T{w=1D$
T{w=AX
AVTA^I
4$[API
ASARA[AS
MH-#'{
;el[p/)P&)
~Zk44I
({Xn;S
0#4+$
5'IN97(
lbf;"8U
bU@v2o
td4oYt
Iq1ztydh
b?3*OM
Ma@Z"z
O-'X2(
1Eab62
^][ZYX
AZA[A\A]
h1OZNyW
&$<u0I
@@HOn
wH=yA+
$ATTA\I
A[_ATAUWH
$\AVhz<
AVAVAVH
XARAQA
_PAPAUI
ATTA\I
D$pAPAQA
vzVxAQ
+AXATA
4$\AWI
L3<$L1<$L3<$H
4$[AWI
xYu-R|4o-
}aAYI
$$\RAPH
-{~UQH
$0XvrA_ATA
+AWASA
Q>mH-4
}H-Bgr~ARI
H34$H14$H34$\h
m*_[H9
?XATAQA
L3$$L1$$L3$$\
Mc,$L!
Ag[3mo
A^A__^][Z
AXAYAZA[A\A]
?UV{V?
L34$L14$L34$\H
L3<$L1<$L3<$\AR
H3<$H1<$H3<$\H
$PSAUA
uW:A_A
+YA]AQA
[A^ARA
wg[AQA
hkvu}H
}A\H-O
APATA
4$XASI
4$YAVI
-H-m0{kUH
4$V~.{
1)D|/H
w$0|w+
zzB`.J
$hA^moH
$h&u!|H
ATTA\I
>*o:AUS
|}_ARWh
AUUARA
Aw\H-3
$APAYAQ
ATTA\I
zwAPh0
H-L-WkH-x<
L-WkAUA
zhbrowUH
H3,$H1,$H3,$\
4$[AWH
<$\h+
L34$L14$L34$H
YATTA\I
<$AUTA]I
$ASAWM
4$YAUI
$A]ASM
A[A]ASA
D$pAWA
"O?,A1
4$XAUI
4$[h=pf]H
4$\PATWH
$$\hQ!n_AW
APAUAXh
+APAQM
4?7A[A
$A[ATM
$ATTA\I
H3,$H1,$H3,$H
A\A]A^A_
_^][ZY
u3clC5
&Ih(_/
H3,$H1,$H3,$\L
4$AYAQI
4$YARI
7ASARM
{ZAPA
o8!7D1
APTAXI
$;fH-k?
$t(~{[
~RAQAQAYH
4+AQSRH
4$XASI
#2+9|M)
AXAYAZA[A\A]
H2$-)G!
sV.lU*9j
*T#Y7cr_Q
ak-W"c
]~UWrY
>hiPu
^][ZYX
AXAYAZ
A[A\A]A^A__
!O]Z=b
3LOvp>
NYBpJ~
@uUi ;h
FFn5]t
Wn2WG~
]zR@3v
Y~k0}X
D/V`}v
>HC0e1
@fB#!9C
fE)<$H
oBVs>A
E!4$M1
H3<$H1<$H3<$H
PAPAVA
4$[AVI
4$ZATI
ARWARA
q/_Vm{/L]
?|,Rj2/
%L7swa
0DMQ-@
OXlO#^
cUdk}E
cg0},/r
XkFtxJpW9N
ISkT<E
}ZZ4tWs
o]rRV(
?Y:@>=yJ}8*
PROC_OUT = %d, Process = %x
R)]V)O
,0LeQh
KK7uF0
&rHVRI
J$&,c2
*Lg q,
3\vE"
A^A__^
AZA[A\A]
$$APhz
$sugD1
5`M AT
4$XAQI
KQFQR7
2p&#&G
6~_$n>
js/l^7
hH9g}H
b9&WxTi
~YkUpm
eY,%M9
1}3!I
k \a]q
g<.\."
wmz>J5
{|^#`w
g>L|Px
K[8VaUVv
5EQL^1
qAY=!<,5p
oG^fKlS
t,,di:
= _UpL{8b
-?*=(}
tk`m9J
p>L!Iq
CQ1R-`?
/6i2BI
fA)<$I
-3YS*H
fE)4$H
A__^][ZYX
AZA[A\
e,Bwg*
/Grsva
ik i?5j
==@_qk
gWm@ib
b0Aq]@E
?um*g<k;
AYAZA[A\
/AUYQH
A]A^A_
_^][ZYX
WinLicenseDriverVersion
WlM9;I
le1`1,E
L[30oJ
7R-vNH
-\1P+K
Ey.c&,
%pD.@c
kRuHa5
MGmSpf:
R0tNx>
/gYfW8
v&oCjM
z(m[~R
*<w%w"
tw&> v :
ag(XMu
\T1F1!
XAPAPH
4$XST[H
4$[AQI
CheckOUT
#PD>S3
o3O(SeE
&SA#&e
<+9!_cO
-_pPm+|
7G%i#,_
f]o19R
Ro],~:a
lZWDG|
fc=pMdf
cxB<5c
U,vcD_
e0,*0>
+Iw^><
$u8mlH
AXAYAZA[A\A]A^A__^][ZYX
AXAYAZA[A\A]A^A__
6fD16H
))55P]
sG'8$x
@hR]+)
M[<H~on
gFAy<K
xz$zzc
xNZ"W+
4$D;{{H
$ARTAZI
4$XQTYH
N1]i`C
.ZVWbK
)Hba4/
DBG'/g5
D4{3cQ%
*s"[fI
AXAYAZA[A\A]A^A__^][ZY
rS6$)c
>9=(Fv
A^A__^][ZYX
AXAYAZA[
Uv*nW-
D):H%v
G`Pyb
fE),$I
HOOK_IN = %d
?vXAUA
SSVARh
WLSoftwareVersion
AXAYAZ
A[A\A]A^A__^
jrs</rR
eEY#`E
Rv%J8wo
sga_kGW
Zf2F)H
]\yfGrR
6/;;zH1
AYAZA[A\A]A^A_
'kI92I
=PbQFl
SS[AQI
$AWTA_I
oIATI
4$XRTZH
AV_A^H
33nYTb>
CP6lcI
3|G5%x
AXAYAZA[A\
A]A^A__^]
69?zNH
-._JI9
AZA[A\A]A^A__^][
wBIu@qg
ixa~,!
fE14$H
fE)4$I
j^dPfA
fA)4$H
Eyb#72
7+Boe~
RjCSb(
x\mr9W
AXAYAZ
A[A\A]A^A__^][ZY
q6.86$
3>nH=~x/
4KJ5_:
:T9.fsVV
}eLkiV
,a)pg%
)DMF-H
gSAPAXI
'=(bEH
<$VA\I
&pb>II
'7zXAQh!
UXU#jf6
Tr<:AG
A\A]A^A__^][Z
AXAYAZA[
WmVR|s;
fq20Thp
E1z9%g
&bEhvI
0UBsnH
AXAYAZA[A\A]A^A__^][ZYX
2O5H7D
[A%`*J+
oYcPV7
nZV/|^o
,f_y,?'
&hp]6P
Vkibx(h
_=6uu_J
aNl,O>
bo^0y<abE4
|tlFu`5
:'\WP~K
cQN`<&
^}dqO7
j4]=Av
rXdihs
AXAYAZA[A\A]A^A__^][ZYX
n^`-L0v
B-8_0#
9/forcerun
2M)4$I
A^A__^][ZY
AYAZA[A\
2M)4$I
jF(eOaa
A8A6(QR
7Qw!-e
]G" ?@
yA'+,Q
x1j@Q}
k=!:w58
7Hagx^
<D1+F'
/QcA1o
%-M+F1A?9
Tz)AAfP
9eQ<AV
c]jL!Em
W1Ou-
AXAYAZA[A\A]A^A__^][ZYX
WinLicenseVersion
n4H"nb
]n4d!c
A/ubdW
1kAgxN.
/c4QXV
*E"B_u
7 a/ze
>doW>"
"{`T;R
kfZPS4L
g~*m{+u
xTy]9X:
p/a@>4b
BC@.?]hn
e2U`TN
C&H4q3pH
Msb~N<
jbA<;j
g]d,Ox
K&_.H#CP
oA@es"
[;Z1n&
VC8?j'
^rI9;I
"]>LH!
"7^~qI
?fA18I
9Rsncig
iTNGB<
~!3!d2
W.$m4aZ
g|G#o$VF
:8tJbQ
h^\:jQ
|F!WMh$
NfmTMAS
]FOr}
7"N)3\
5O=^nb
M,_Gw;
9MWD(9V
AXAYAZA[A\A]A^A__
ON9jiK'x
nf=U,
WIW9"c
.^KfmK
4$\AQM
4$XST[H
4$[ASI
;3HthK
$$fD1'
d([GIYF%
hU%m":=^
WE3B'&,
e .$wF
;eQH:.
AXAYAZA[
A\A]A^A__
GL(-s}1
_Su3Zre
ziY+@;
7AXAYH
_ASASA[WH
AZA[A\
A]A^A_
AXAYAZA[A\A]A^A__^][ZYX
PROC_IN = %d
4$YRTZH
A\A]A^A_
AYAZA[
0[.A.
$hpLs=h
$APTAXI
?ATTA\I
$h8$cL
\4YUAPA
L34$L14$L34$\H
AQWVUh
D$pARh
::D)d$
$AQAVA
A^D1L$
Lu_\Mu
$A[AVI
$ARAZWH
APTAXI
4$[AQTAYI
,$TA]I
L3,$L1,$L3,$\H
A\A]A^A__^]
L3<$L1<$L3<$\V
<$ARTAZI
$APAWA
}V[AVA
,$TA]I
<AXAQA
j~xUAQA
A\ASAWVH
4$L[^A_I
L[^^M
D$pAPAVA
4$[AUTA]I
,$\h*9
R??=T@
55M9e2
A^Y!v'
yX:){^
gKg}Kz
~m856U
m8ihLf
$AQTAYI
H3,$H1,$H3,$\h
AWUAQASA
V&7lA1
4$YAPI
qE+SD)
*AVTA^I
L34$L14$L34$\L
D$pATA
Ww~H-%
+AQUh6
AYH-gv[
j/rA\
h|CoWH
-H- YW
0T}-.H
A[ATSAQM
4$[AUTA]I
,$\AUI
4$[AVH
WLProjectName
A__^][ZYX
AZA[A\
fA)4$H
d2A!3I
$'.jqH
,$&^'j
mvnC#0JM
g*qZmM
1L'0,2
AZA[A\A]
$P^V(3
GCbV]~
Lq,}vP
R#Yd`#
WEIz~O
Dcwl-S
Bp8P@#nTh
0EIXU;
uzo6lg
szE<J6.'?=
nKy|wi
ExitOUT
VY8yI9
3yb~@{
(Q_nXI
$$E!'I
A\A]A^A_
AYAZA[
fE1,$I
Op+RO{
7)=5YW"
){4yQH
AXAYAZA[
A\A]A^A__^]
E)4$L1
E34$M1
h3L9)I
8P]&[5%
N'**(~V
7zUQ:I
AXAYAZA[A\A]A^
A__^][ZY
,$Cn,\I
kLct`d
FxADh";e
A\A]A^A__^][ZY
A<)3BF
(}kXhn
VJ~=D)d$
C<MD;
/Q[B8I
"8v/ZI
4$AVA^SH
6fE14$A
8I`~H%
++|L9I
4$\ARAWI
i~Nulk_
TL[#m)
A\A]A^A__^][ZYX
AXAYAZ
1(\LnH
a@9 6a
fA14$H
#+IW8H
h`3zjx
q8[=ig
DIbZ\2-zb
+DZ8({
7j<:7
A__^][ZYX
AXAYAZA[A\A]A^
19JAUI
$$fD9&A
A__^][ZYX
AXAYAZA[A\A]
ATTA\I
$$ARUH
AZhWq_
L3<$ATM
A\L3<$H
y=ASATH
$hAdngh
$ARhh.
D$pARAVhp
A^APh8
W~A]ATA
[H-I`{uH
I`{uH-
fQARfA
fE14$I
'OQJ;I
06a;3I
=c4/k#cr
L/logstatus
/bugcheck2
%FjT**
kCWWEfw
SkCHECK_OUT = %d
WLSoftwareName
fE1<$I
i W{.|
:?D)D$
AX[AVA
a'hgUw
=J?k(*%
%b&"q8>1
Re?"H*
t&Ike~
fE1,$I
.Poq I
&.6>defg
AXAYAZA[A\A]A^A__^][Z
(nlp'I
UvProcIN
ExitIN
(aQ\OI
$AUARA
D9Y]=A
'qukF\B|
&/deactivate
$AQTAYI
ARTAZI
A]X-M|
?H-UZz
D$pARAWh
h,w{MH
4$\AWI
4$[ARI
A[H1D$
$$TA\I
$AWTA_I
hqD}{L
4$AXAVI
H3,$H1,$H3,$\H
:AYATh
wAVAUA
_3S~D)
4$_AVI
,$SS[H
Yo^hAQAUA
}OD1t$
A^XATA
o;PARI
4$A]VH
4$\UAPASM
<$\AUA
4$XAPI
{A^ARAPM
}-^tk\A
h\t~mH
4$XARTAZI
4$[ATI
H5!%0^
H5!%0^I
!%0^H)
!%0^L1
H5!%0^
!%0^L1
L+/H%K
- YURH9
!%0^H5
$<.?=M
A__^][ZYX
A[A\A]A^
"k$xuI
AXAYAZA[A\A]A^A__^][ZYX
I+<$M!
AXAYAZA[A\A]A^A__^][ZYX
7('+zH
Software\WinLicense
Software\WinLicense
=PbQFl
4$[API
$\VT^H
E34$M)
ATTA\I
AXAYAZA[A\A]A^A__^][ZYX
WinLicenseInstance
$\WAWI
yARATI
4$AU^I
$AUTA]I
$ASTA[I
4$AYAVI
L34$L14$L34$\h
$3@Z~A]A
yYXAQA
+?AUh,
,*A]hH
Uv_H-&$
]wEASA
A^H->i
4$XAWTA_I
AXAYAZ
A[A\A]A^A_
/dumpstatus
M3+H%v
L9'AXI
5mzsD)
-AQAPI
APWATM
M|wASA
$$\5$x
<$P_ARI
+AZ_ASh
[X-)[[OA^D1
zH-0W}}H-
/C#*GI
U^Z>EW
uAZ1L$
A]A^A__^][ZY
AZA[A\
^][ZYX
A[A\A]A^A__
AXAYAZ
/Mw7IH)
M1)-<?
4$YAPI
K{?H-k
}}[AVA
4$XAPTAXI
To{H-?
+A]hx!
:tAQTL
(N*w?hg
ATTA\I
4$[AUI
$ARTAZI
<$AUWL
$ARAZPH
hVnnsASI
$>W8BEp
mis[/=
4$AUWH
>5?ASQL
APTAXI
$AQWh+o
4$YATI
$$\AQS
$AQTAYI
wARATI
zoXA\L
D$pAWARA
+YWAVM
$AThS,
$\PASI
4$YAPTAXI
$ATAUM
$\RAVAQA
AYAQATA
iF}+AT
ZhI8wvL
qt?{AQQW
AZ^SARA
PAUAPA
AXD1l$
:Bb..7
A[A\A]
AXAYAZ
A^A__^
H3<$H1<$H3<$\H
59Kws-A1
,$\API
$AWTA_I
,M+hOp
f{XAUARA
)wH-l\
H34$H14$H34$\h
4+RAVI
$APUAWA
AUTA]I
APUAXAP
$\h,W?}H
$AQTAYI
H3<$H1<$H3<$\
H3,$ATI
A\H3,$\hxT
4$A_VH
A]_SAQA
$$PA\ATH
D$pAQh
$AVAUA
$AVTA^I
H3<$H1<$H3<$\AR
4$XARI
H3<$H1<$H3<$\hV
;AUPA]AU
4$XARTAZI
$AWASA_M
UU]AWUH
4$[ASI
$\h;0n
$SA_AW
A[AZAPhR8
L3$$L1$$L3$$H
t~ATSL
4$XRTZH
AUTA]I
L3,$L1,$L3,$\R
$$\ARI
4$YAUTA]I
,$\ASI
6wA_VAQA
AQAWAPA
$A_APM
D$pAVA
$APATI
ATTA\I
ASPA[ASAVI
$$\5:>
-xA>y
YY& 8H{I}
R;i8Ux;
)A$PyLu4
Qkkbal
;?ic#Ec
1aM`oy
TF-'jE1
4$XST[H
4$[ATI
UAVAUI
A^AVSH
$AQTAYI
.\A4P*
vg7kJkX
Ntzs[=[
cw{D)l$
A]Zh>{U
$AWARA
fE)4$I
ARD(;H
AUAUA]ARI
4$[AWI
h+2v{H
AXXAPA
"Z8L1T$
$AWATA
H34$H14$H34$\H
APAPARI
4$[ASI
DDDDDDDD
&.6>defg
%.8X %i %i %i %i %i
X86IL <16|32|64> <FileName>
c:\miniprojects\x86il\il86\x64\release\IL86.pdb
L34$L14$L34$\
k>D1\$
R3(8xF
5:c-H\h
]4Jl<wF
|xGZ1E
,$TA]I
4$XAUI
APWAPH
AVTA^I
L34$L14$L34$\QH
,$\hr?
A\Ph,V
$AQAWA
4$\APA
A^XAWA
A_[UAPh
_VV^AQI
4$[AUI
$AUTA]I
PROC_OUT = %d
CHECK_IN = %d
=PbQFl
1AZARAPA
A[XASA
4$XARTAZI
L3$$L1$$L3$$\H
4$XASI
AYXAVA
4$AYRH
NXATAWh
Ph.d|_H
APTAXI
B~nPQH
,$\PUh
_H-5#?}H
$APTAXI
hu'_OH
4$XAVI
4$\ARA
AZX5%X
lLpVZ9>
<$\API
whR^zQ
^NAZARAVH
AX-K@<
,$\h 
4$YVT^H
X?lA_A
$APTAXI
PARAPI
4+RAPI
AXH)T$
ASATA
oWWT_H
$hzw^vh<
L34$L14$L34$H
>APAVAXL
$ARTAZI
?^APAUA
AUQH
$ARh\_
H>QxA1
4$YAQI
4$XAPI
$\PATI
AYL1d$
gATATM
$AQTAYI
4$Yhr<klL
<$\ASI
A]AVQH
AQTAYI
)-_AXAU
RSZRPH
ZAZUATA
}A^X-T4
q5;nAQA
H-G?nwH
G?nwAQUH
}APAWA
h=b?RH
(P^}=H
^XAQVU
_-2-_)
h215OL
4$[AUI
L3,$L1,$L3,$\
AZ[VAPA
vkD1\$
wXSARA
]QWQhKw
uaY)|$
k<SASA
4$WhnV
3vo~D1L$
QAVAWh
A_D1t$
ARATARA\M
%W/X6Q$
hWG)|$
fE)<$I
ProcOUT
fE1<$H
.{OMVI
APAPAXAQI
4$XARI
;>mA\I
h4n2OH
4$[ASI
tAUA]I
2}hR<I
+]mA_I
+]m]SH
<$_AVI
3qI\E(
t?\A_H
4$XARTAZI
L3<$L1<$L3<$\H
H34$H14$H34$\
X2@O\5
AVAVAWI
ARPAZL
$ATTA\I
4$XASI
VvE91l$
5VvE9PhuU
=[}91L$
ARfAUfA
4$[APTAXI
$hS}o=API
4$XASI
ATATA\QAQI
AQTAYI
4$[AVTA^I
4$XVT^H
H34$H14$H34$\H
ZAPATM
Zh,,;KH
$APTAXI
4$[ATI
A\SAQA
A]AShG
4$[WT_H
<$\ST[H
ASA_A[H
A][AWA
4$_ATI
4$[ARTAZI
$AVTA^I
<$AQTAYI
E#KG1|$
4$\5E#KGh{W
tdgAZA
G:;y<3
,$TA]I
h6={H
L34$L14$L34$\
ARTAZI
AUXA]H
o{'D1l$
$RZAQI
L3<$L1<$L3<$H
4$AUAVH
$?ZJr|
Yh/lu^H
4$XARI
A]ASTA[I
4$XAPI
AUAUPH
AXASTL
4$XAQI
6~zAYI
eyD1D$
U)X7)=
ARAWARA_M
<$W_hAQ
$hXul/H
4$[ATI
l$(A]H
$QYAVI
$\h"m3VH
4$[ARH
_{&s[8f
$RZATI
$AVTA^I
4$XAVTA^I
u}{D1|$
,$6WwnH
4$\AQA
^O[ATA
AQAQAYVH
AQTAYI
hw9}zh9zjzS
$\Rh!^NvH
_oD1l$
A]XWAUA
hx{8{H
ZMWD1T$
_~D1T$
h0(tpH
~XQATA
A][APA
4$I0un
I0unD1
SASAPhC
AXD1\$
]PARAWA
A_D)T$
4$_WT_H
_XAUAWA
h.X?-H
H3,$H1,$H3,$H
$AUTA]I
L3,$L1,$L3,$\
4$[AVTA^I
4$A_VH
<$AWPH
H3,$H1,$H3,$\H
H34$H14$H34$\hGj
[APAVA
hl7vgH
$ARAZH
h-W[_h
AUSA]PAUH
4$XARI
,$sdoq_H
APTAXI
4$[ST[H
4$h?S=SL
Xhcl+kh/
4$XRTZH
4$[AQI
$AVA^H
AYARVH
AWTA_I
4$E}{;_H
$ASTA[I
4$XASTA[I
hJc{_H
AYXAQA
xAZXAUA
ATTA\I
$AUTA]I
L3,$L1,$L3,$\AU
L34$SL
[L34$H
4$YATI
c:XD1D$
hN]{wH
$AQAVA
AXL)|$
L3<$L1<$L3<$\H
-H-:b|zH-9
$ARAPAZM
H-z9ndH
z9ndH-s`
$ATh|7
=ATPPH
sH-J|-zH-L
J|-zH-K
0wg;-u
4$4P[rH
UoD)L$
$$\hg7
hv|K}L
L3$$L1$$L3$$\L
$ARAZH
AU]A]U
4$[AUI
{SXhK]
]XhAh?{U
ATATA\H
4$\AWI
L34$L14$L34$\H
$RZAQI
pw[AQI
4$[AQI
4$[AWI
L3$$L1$$L3$$H
4$Xhg6
$_u[D)l$
kXhd?>>L
PAWAQh,6
AYD)|$
LG]1\$
APAPAXH
AP[AXPH
$\hvs5~H
,$o(v)ZARA
4$_ASI
A_[VAVA
4$ATTA\I
APTAXI
$AV^A^
$__A^A
4$PAPA
_D1|$
Cj|D)D$
AXXATA
L3<$L1<$L3<$\
NCtASTA[I
>_SQASh
<$\APA
h$2qzH
AUVA]L
A]D)T$
fXfXf5
<$PTXH
ATAUI
$\ST[H
4$[RTZH
4$[AVI
$ARTAZI
?QXASA
T{XAPP
X-T>x}D
T>x}AX
=kZA[h
E=vAWI
A_QARI
4$AYWH
WAPARh3V
ARTAZI
AR^AZH
oATAPh
L3<$AQM
AYL3<$H
QATAUA
A]D)d$
qcD1d$
A^D1T$
C_+D)D$
AXXARA
AXXAQA
_GD1\$
_GQUPht
$AUAVI
APASAWM
A[APUH
H34$H14$H34$\
4$[AWI
T[<"%Y
AQAShSI
AYARAWA
4$[ATI
$\VATI
YXARAUhB
ON[D)\$
fZAQfA
$PXAPI
L3<$L1<$L3<$\
H34$PH
YATATA\ATUH
H3,$ATI
A\H3,$\hP
4$_UT]H
;Ou4wK
A\$ax0
4$_AVI
$AVTA^I
[ASAVI
4$XASI
sVXSAVA
RRZQAUI
AUYA]H
$Guo_ZATASA
$APAXAUI
AQTAYI
4$XATTA\I
N*om1|$
$\X5N*omH
,$\AVI
$ASTA[I
L14$L34$H
1o[)L$
$$AShDh
AWAWQH
ATTA\I
L34$L14$L34$\
|!Ko-/
4$XAUI
A[APTAXI
4$[AVI
$ARTAZI
q~o)L$
|A]ZAWA
,$ATTA\I
4$[API
4$XAPI
$$Vhvm{=H
4$XAUI
$$Ph?-
AUASA
QAWASA
4$[AWI
4$XAUI
4$XARI
_>8)|$
QARASht
AVVAVAPI
,$+Ku$H
\0WED1T$
X5\0WE
h|Wm?h
ARTAZI
4$XAQI
SARAPA
4$AVVH
owXASR
4$XAPI
<$\ATATA\SH
<$AWA_AUI
4$AVSH
4$[ASI
f[QARh
p\}AZA
$ARAUA
A]D)T$
AYXAUAVA
$APWh~
AXXARA
A]APAPAXAUWH
4$XAUTA]I
4$XAVI
$ATTA\I
RzHQD)
,$AUA]AVI
4$\h:S
4$XARI
$ATA\H
4$ZAQI
$S[WRH
4$XAWI
SAPASA
A[D1D$
4$XRTZH
AVTA^I
L34$L14$L34$\S
RAWPA_AWZA_H
H34$H14$H34$\H
H3,$H1,$H3,$\H
h-UnGH
$A]AZH
YPAXXH
H34$H14$H34$H
,$APASAVM
$APTAXI
$$\hun
AUAUA]ATSH
4$[ST[H
@w}AWI
$AUARI
_ASTA[I
$[q1\$
$AWTA_I
4$XAWI
$APTAXI
mARATSH
H3<$H1<$H3<$\H
$AVTA^I
4$YAWI
(|ST[H
$Rhz(;~Z
4$XAVI
L34$L14$L34$\
$$TA\I
A^WATI
QAVARRH
A\ARTAZI
4$XPTXH
][ARPh
h3K??L
$AUARA]M
H3<$H1<$H3<$\H
4$XASI
QFQRiC0
G7)Q;P
4$XVT^H
$ATTA\I
$\ATSA\L
4$[AVI
H3<$H1<$H3<$\APM
$h.C_]ATI
D$([A_AXh*
$ARASI
dsoAQPAYAQ
NASARI
4$XASTA[I
AVA_A^VH
4z5SAVA
A^ZAQA
yjgG5@
ATAUA\L
AXAWTA_I
4$\AUI
4$XARTAZI
cby"w9C{
ngQ~C3
6 Opwj
C+W+6]
X8`^`AV
rWa=k~
%VdGRzR
!72tE/
Gvz2>|
LaDzi^
U`o{Y.w
_N}M,X}M,X
_W}M,X}M,X}M,X
D,X}M,X}M,X}M,X
L,X}M,X}M,X
"X}M,X
tM,X}M,X}M,X}M,X
"X}M,X}M,X
"X}M,X
"X}M,X}M,X}M,X
}M,X}M,X}M,X
"X}M,X
"X}M,X}M,X}M,X
"X}M,X}M,X
"X}M,X}M,X}M,X
D,X}M,X}M,X
tM,X}M,X
tM,X}M,X}M,X}M,X
tM,X}M,X
tM,X}M,X
L,X}M,X}M,X
D,X}M,X}M,X}M,X
C,X}M,X
+X}M,X}M,X
"X}M,X
_W}M,X
}M,X}M,X}M,X}M,X
+X}M,X}M,X}M,X
+X}M,X}M,X
_W}M,X}M,X
+X}M,X
L,X}M,X}M,X
+X}M,X
L,X}M,X
_W}M,X
D,X}M,X
tM,X}M,X}M,X}M,X
_W}M,X}M,X}M,X
tM,X}M,X}M,X
L,X}M,X}M,X}M,X
tM,X}M,X
D,X}M,X}M,X
"X}M,X}M,X}M,Xi
tM,X}M,X}M,X}M,X
C,X}M,X}M,X}M
D,X}M,X}M
<V_\6A
D,X}M,X}M,X}M,X}M
_W}M,X}M,X}M,X}M
tM,X}M,X}M
_N}M,X}M
}M,X}M
tM,X}M,
|tM,X5J
Y{K4a]
5no tBC
Vq<C!t
"X}M,X}M,X
<S3l<R3o
^LtM,X
c%IoBz
a<NH)6
<P__6A
Jo"qD,X
tM,X<R
v~7M6A
C,X}M,X
CK<LHY
D,X}M,X}M,X}M,X}M
LtM,X<
vb4UubY
<LW]2J
O}M,X}M,X}M,X
nqD,X
M,X}M,X}M,X}M
4Ep}tM,X}M,X}M,X}M,X}M,X}M
"X}M,X}M,X}M,X}M
a,X}M,X}M,X}M,X
,X}M,X}M,X}M,X
N}M,X}M,X
N}M,X}M,X
,X}M,X
D,X}M,X}M,X
"X}M,X}M,X
O<&G;5
#S[S5d'H
cGv{6S
$\ioMo
`]qbe[
W0%HYOHh|
KqB"OuF&SyJ*W}N.[
KqB"OuF&SyJ*W}N.[
KqB"OuF&SyJ*W}N.[
KqB"OuF&SyJ*W}N.[
QSRZ<R
0i% 0y%00
6i+ 6y+06
;i0 ;y00;
AWPA_L
4$[ATTA\I
L3<$L1<$L3<$\S
ZA\hm w]UH
H3,$H1,$H3,$\H
AYPUASI
Q};hK!
kAUSA]L
\$ A[_hp5
4$[AVI
$\APAPASI
A_AUASA
hi#?WQ
<$_AWI
4$[API
4$XASI
hLL=}H
ATAVASA
4$XASI
AUTA]I
,$\ASAS
$AQAYH
t$(A^H
L3$$L1$$L3$$\
r"J c
$APAXPH
4$[AVI
a([?AWA
AVYA^API
4$UA^AV_L
4$[API
7AQPAYL
$\QQASI
SAWhu6
_ok6A_
AQA[AYQH
4$[AVTA^I
^7ASRH
4$[VT^H
,$\QQYH
4$XASTA[I
$AWA_AWI
$AUA]AWI
4$[UT]H
$AYATI
$AQAWAYM
$ATTA\I
4$[ARI
A\ASSL
4$XVT^H
AUTA]I
,$\AVAQM
_AUAUH
$$\AQM
4$A^PH
:v}AXI
:v}AQWH
ASASAPI
$APAXH
$ASA[ATI
gAPPSH
$$SA\L
<$\AQAQL
ARSAZAR
$APTAXI
ASASPQH
{AVSA^AV
,$A]WH
GhUDgvH
,$UA]L
$$TA\I
$ATTA\I
ARTAZI
ASQARM
AQSAQI
,$TA]I
,$\APH
RRZAPWH
,$\WASI
$$ATA\UH
4$[AUI
$$UT]H
A_ATTL
L3$$L1$$L3$$\H
4$XAPTAXI
AVSATI
4$[ASI
4$XAPI
QFY{Rm
ZAPTAXI
vj[A^H
QQYAVI
L34$L14$L34$H
$$WAWM
WA]_QH
4$XWT_H
$\ASASH
$hb&{<H
,$TA]I
4$XAVI
L3$$SASM
A[H1\$
[L3$$\H
h't{oH
4$AVAWI
4$XAPI
$h/?}^H
$APTAXI
<$AWAPI
4$[APTAXI
$S[ARI
AXASTA[I
\$ [^hlO
4$[ATI
h#Jz?AR
AYQQYWH
4$XAVI
4$XAUI
`>3ldL
$$RRRH
AZAPARI
AXQAPI
L34$L14$L34$\P
4$[AVI
$AVTA^I
,$PA]L
H3<$UH
]H3<$\
$-{uoA_I
-{uoAVI
Z>Az>7
AZ_AWI
iU5AYI
<$AWA_RH
4$XST[H
$\AUAUH
$QAPAWI
D$0A^A]
$\QAWI
4$[ARTAZI
4$[ATI
f}[h8r
pr`7#B
A]AQAUWL
XA]AQI
4$XQTYH
AWPA_AW
$ARTAZI
h*,e[L
,$AUAQI
4$XAUI
4$XAPI
$$AWAPM
$A^A[H
4$[ASTA[I
4$XST[H
VASVA[L
AYAUATAUH
A^[A[I
,$ATUH
[APAPH
ARSAZhf
4$XARTAZI
$$ATATAWI
$ARAZVASI
$AQAPI
4$[AUTA]I
4$XAPI
AQA\AYH
4$[AQI
4$[UT]H
4$XAUTA]I
L3,$L1,$L3,$\UUPH
~h_J]~S
4$[API
U)X7)P/
<D2=s[>
\K{hw/
A\ASTA[I
H3<$AQI
AYH3<$H
^|AUI
AUTA]I
~h(FG?H
H3,$H1,$H3,$\h;7
hq3_sL
$AYATI
4$XWT_H
$$VV^H
Xh~EG[(wb
AUQAUUH
4$[AWTA_I
>;)A4b
$AWTA_I
L3,$L1,$L3,$\
4$\SWARI
AZPASI
$$ASUL
]AWAVI
l$0A]^
,$A]VH
4$\ATI
4$XARI
<$AWA_AWAPI
,$\h`5}
!woAPI
$AXASI
hj7N~AT
AQAQVH
4$\ATM
uh]c_oH
4$XAUI
4$XAWTA_I
<$\AWI
L34$L14$L34$\H
4$A^APTAXI
$\UAVI
4$[ARI
4$[AUTA]I
L3,$L1,$L3,$\
Vh0cq>L
AQAQAYH
H3,$VH
^H3,$\
,$U]AQI
AVAVA^API
$\SS[H
4$[AQI
?h/]{fH
-ywcAWI
4$[APTAXI
hZuS?L
APTAXI
4$XAQI
,$\AVTA^I
ASTA[I
AVTA^I
[SS[QAVI
L3<$L1<$L3<$\hS8
4$XAUTA]I
$APAXH
4$TA^I
4$XASI
APTAXI
AYA^RH
L}cmYo
4$APA^L
4$XASI
AQTAYI
D$(AZH
D|h*T]Gm
,$A]QPH
H3<$H1<$H3<$\
$AVTA^I
G7)Q;PX
4$[ASTA[I
4$[AQTAYI
4$[ATI
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
FireEye Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!0168CA4A89A1
TACHYON Clean
DeepInstinct Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG FileRepMalware [Trj]
Avast FileRepMalware [Trj]
No IRMA results available.