Static | ZeroBOX

PE Compile Time

2013-12-20 21:35:38

PE Imphash

65624f92376796124f44332f088e6bfd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e6ea 0x0000e800 6.42615467186
.rdata 0x00010000 0x00006094 0x00006200 5.21071840309
.data 0x00017000 0x0000327c 0x00001400 2.57163577529
.rsrc 0x0001b000 0x00000480 0x00000600 2.86834583179
.reloc 0x0001c000 0x00001390 0x00001400 6.71853819076

Resources

Name Offset Size Language Sub-language File type
RT_DIALOG 0x0001b3c0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0001b0c0 0x000002fc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x410074 GlobalUnlock
0x410078 lstrcmpiA
0x41007c CreateDirectoryW
0x41008c CreateJobObjectW
0x410090 SetFilePointer
0x410098 ResumeThread
0x4100a0 Sleep
0x4100a4 lstrcpyA
0x4100a8 GetCurrentProcessId
0x4100ac CreateProcessA
0x4100b0 TerminateJobObject
0x4100b4 lstrcmpiW
0x4100b8 GetCommandLineW
0x4100bc GetCurrentProcess
0x4100c0 TerminateProcess
0x4100c4 lstrcmpA
0x4100c8 SetFileAttributesW
0x4100cc ExitProcess
0x4100d0 lstrcmpW
0x4100d4 SetErrorMode
0x4100d8 ExitThread
0x4100e0 FindFirstFileW
0x4100e4 FindNextFileW
0x4100e8 MapViewOfFile
0x4100ec FindClose
0x4100f0 TerminateThread
0x4100f4 CreateFileMappingW
0x4100f8 MoveFileW
0x4100fc GetVersionExW
0x410104 FreeLibrary
0x410108 LoadLibraryExW
0x41011c GetModuleFileNameW
0x410124 OpenProcess
0x41012c Process32NextW
0x410130 Process32FirstW
0x410134 CreateFileMappingA
0x410140 GetCurrentThreadId
0x410148 GetTickCount64
0x410150 GetTempFileNameW
0x410154 lstrcpyW
0x410158 CopyFileW
0x41015c CreateProcessW
0x410160 GetFileSize
0x410164 MoveFileExW
0x410168 LocalFree
0x41016c GlobalLock
0x410170 GetProcAddress
0x410174 CreateThread
0x410178 CloseHandle
0x41017c DeleteFileW
0x410180 GlobalAlloc
0x410184 lstrcatW
0x410188 LoadLibraryA
0x41018c FlushViewOfFile
0x410190 GetLastError
0x410194 FormatMessageW
0x410198 GetModuleHandleA
0x41019c lstrcatA
0x4101a0 UnmapViewOfFile
0x4101a4 GetFileAttributesW
0x4101a8 CreateFileW
0x4101ac LocalAlloc
0x4101b0 WaitForSingleObject
0x4101b4 lstrlenA
0x4101b8 VirtualAlloc
0x4101bc GetTickCount
0x4101c0 lstrcpynW
0x4101c4 WriteFile
0x4101c8 lstrlenW
0x4101cc VirtualFree
0x4101d0 ReadFile
Library USER32.dll:
0x4101f0 GetDesktopWindow
0x4101f8 GetThreadDesktop
0x4101fc MonitorFromWindow
0x410200 ToAscii
0x410204 SetForegroundWindow
0x410208 PtInRect
0x41020c OpenDesktopW
0x410210 MenuItemFromPoint
0x410214 HiliteMenuItem
0x41021c PrintWindow
0x410220 BringWindowToTop
0x410224 GetTopWindow
0x410228 CreateDesktopW
0x41022c SetWindowLongA
0x410230 VkKeyScanExA
0x410234 GetKeyboardState
0x410238 GetMenuItemCount
0x41023c SetActiveWindow
0x410240 SetWindowPos
0x410244 GetDC
0x410248 GetMenu
0x41024c GetWindow
0x410254 CloseWindow
0x410258 PostMessageW
0x41025c GetWindowRect
0x410260 SendMessageTimeoutW
0x410264 SendMessageTimeoutA
0x410268 ScreenToClient
0x41026c WindowFromPoint
0x410270 GetWindowPlacement
0x410274 IsWindow
0x410278 CloseDesktop
0x41027c GetKeyboardLayout
0x410280 MoveWindow
0x410284 SetFocus
0x410288 LoadKeyboardLayoutA
0x410290 GetParent
0x410294 IsWindowVisible
0x410298 SetThreadDesktop
0x41029c GetWindowLongA
0x4102a0 GetWindowTextW
0x4102a4 OemToCharA
0x4102a8 GetClassNameW
0x4102ac CharLowerA
0x4102b4 FindWindowExW
0x4102b8 PostMessageA
0x4102bc wsprintfA
0x4102c0 FindWindowW
0x4102c4 EnumDesktopWindows
0x4102c8 OpenClipboard
0x4102cc wvsprintfW
0x4102d0 CloseClipboard
0x4102d4 wvsprintfA
0x4102d8 GetClipboardData
0x4102dc SetClipboardData
0x4102e4 EmptyClipboard
Library GDI32.dll:
0x410040 BitBlt
0x410048 SelectObject
0x41004c CreateCompatibleDC
0x410050 CreateDCA
0x410054 GetDIBits
0x410058 DeleteObject
0x41005c CreateSolidBrush
0x410060 GetDeviceCaps
0x410064 CreatePen
0x410068 Rectangle
0x41006c DeleteDC
Library ADVAPI32.dll:
0x410000 RegQueryValueA
0x410008 GetSidSubAuthority
0x41000c OpenProcessToken
0x410010 RegQueryValueExW
0x410014 RegDeleteValueA
0x410018 RegDeleteValueW
0x41001c RegOpenKeyExW
0x410020 RegOpenKeyExA
0x410024 RegSetValueExA
0x410028 RegQueryValueExA
0x41002c RegCloseKey
0x410030 RegSetValueA
0x410034 RegEnumKeyA
0x410038 GetTokenInformation
Library SHELL32.dll:
0x4101e0 ShellExecuteW
0x4101e4 SHGetFolderPathW

!This program cannot be run in DOS mode.
GRich_
`.rdata
@.data
@.reloc
t/WWWj
D$$GPW
D$XQRV
D$lWP3
D$pPWWh
D$ ionI
D$$nfor
D$(mati
D$,onW
WTSQPW
D$ Toke
LocaPW
GetCPW
D$ ameA
)))))))))
)))))))))))))))))))))))))))))))))))))
))))))))))))))
))))))))))))))
))))))))))))))) !)"#$))))))))))))))%&)')(
t9UVPW
t%UVPW
SUVWj"
D$`tW
+T$(+|$$
t$$+T$(
t$$+L$(
+t$$+T$(
+t$$+L$(
t$8QWRV
D$0PQSW
D$,PUUUUUU
SUVWhy2
|$ iuQf
|$"duIf
|$$guAf9T$&u:f
|$(tu2f
|$*Wu*f
|$,iu"f
L$@+L$8QS
9^0tA9^8t<9^<t7
9Y tT9Y$tO
Wj*Xjq
F<)^h)^d)^TY
Gdf+Gh
Gl;OxwY
td;Wxs_
Gd+Gh[=
Gdf+G\fH
VWhxrA
S0;S(t
w(;G,u
W0;W(t
W0;W(t
Unknown command.
kgibkgldkakgpcialhlplnkglhpcjblnlmkgkalnlopcpkjkiejmjbplpclblolllhlmkgpckglnpckblhkakelhkapc
pekalp
gofcemfefjdkeihphhhfgohpdkfjhfhegogihfhg
iikdnjmmmejaiekdnjjikd
jhmgndnlipjl
injcjmiljhjmjfmkmlnhjnjfjf
fcgbedfcgaepekedhcepeled
cmbodbdednamdbdfdnamdhalcbclcmdndfamdbdfdn
gaflgehbhkfchnhihbfjhfgegehnhkhdff
niobmnnmpkmfmjnlodmkokmfmamj
joknipjokgifijiligloidihip
idloiekajiiambmdkhifjijejcieie
kgjflhkgiflllmlglnkfkbjgllkalhlbkglnkaklif
lbialnlfkeklkbiaklldkmlhkkklkikakllbjglblhkmklkclgjc
cebdccdfdbcedfaaccdpdddfcdcdah
pnmkplomoipnommdogolmgolodomokpnno
jgkdjbjbilifimlcjainibihjbjblginkiiniakniaiiihibjg
oimopjopojpbpjmipeoopjpnpi
hiepgagdhpgjeegngcgigagj
ijlcinjijdknipjcjojiioio
kcjbldkcjfljllkgkdkcldkejilhllldib
bldmadakakbp
cdaedpdedicfdchjdddldl
clbidkclblcpdgbjdacnbcdadbdgcldacn
oknjplokmnpnpppcplnipppnokpbomnipbomndpbpaphokpbom
kniklmknijkllglklmkkkkjnkjlajikolikllmlhlmkkkk
mambmhnbmgihigjknanini
hdebgogjgdfagogjgdgihaeg
nfohmimpmfpgmimpmfmongpg
hhefgkgnghfegkgnghgmheeghlec
mdpancmdoanonjndnimaofncnemd
lfickjkiknkfjgkikpkfkolgihldkokmjbkokikplf
ijkojiijknipjcjojiioioljknlelmikjmipji
hefdgfhefegihcgfgbgeeehagjebhhgbhcgfgogfhdhdedgpgohegfhihe
niolmjnipjnpmjnoocmnmbmjpl
ghgegacbemcacbdnhhhphp
lljijmiojmllkolnlllklp
eeghgdhbhdfmfffbfoefea
apaibebibaboap
phoaomononogoaph
dpdicocfcp
idifjcjeib
ebegfafjfafgeb
ldkpldkikjle
dfcicpcedfbocacfcfdd
ompbpgpnommhpgomphpj
hkgjglhkgggbhnhkgmhhgagpgdgl
gdhehlhigehcgehihehmhcgd
dnbobkaiaocmdnafcidkdnamdldlcgdl
hgfffbedfbghhgeogdhbhgehhahagnha
lklnkllklnkbknkfkblolk
amcpcldjdbbhblambe
khkallkgkhlhlmkeln
gbhchagbgfhahaghhlhehiha
poonoppopjofojoboeolohop
gphkhihihoglgp
mdnfnonjnd
abbjbmagabbabl
kplklpknlkkllcoiojpflplhlh
jblgjmjgjbiaiikdjailigjbimikilnfngnd
chabdgdebmcddgdnbidgckbgclbc
oimopjplmppjoimkpnpaojpjnn
njmkmjmejojpidmjmbmb
iokjjpiokjioiijpiojjjclijgiolhjfjojp
aickbfapajbnbadjbkbkbjbpaiap
geedhphggeghhbgchfemfnhjhdgchpgdhphggeemehhjhohehpghgdemfdgfgcgchfhogeeghfgcgdhjhphoemffgigahmhpgchfgcemfbhegghbhohdhfhe
abcbbeagbobhbeahdcbjbkbidjbaadbabj
bgdbepfdepfdfeepfkfdflfa
phpbpgonohopoplalbknogplogkdpaologopoplalbknohopopkpkalflc
mgobnnnemgmfndmanhooppnlnbmannmbnnnemgooofnlnmngnnmfmboopbmhmamanhnmmgoenhmambnlnnnmooplnmmgnhmanmnhmgjcobnhmgmgnlnmnfmboooinnnmnhmboojhng
hbcadfdbgjfn
mjooncnlmjmknmmpniobpanenompncmoncnlmjobpendmjnimpndnimjjnpimfmnnbncmpnimpobpanmnend
pmmlpnpkpkonogpmmeonpoonoe
pomeofnkpiofpoopojpoopoomhofooopmioloeoeoppi
eggbfnfeegeffdeafhgohpflfbeafnebfnfeeggohlfmegfheafmfhegbchhekecfofneafheagogbfhfbeheaflegel
mcpcnpmfnhnenkndofndnfmdmenpmcmpofndmcmcnpninbmfpfnondnfnn
ncocmpnfmhmemkmdoampnopfmdmfndnempncnppfmdncncmpmimbnf
fmhleheofmfpejfkenhegfebelfkehfleheofmhehpebegemehfpflheglfnfkfkenegfmhoenfkflebeheghegbegfmenfkegenfmaihlenfmfmebegepfl
mhoencmbnnpmnnpknnmhmbncnnngmh
ljjoiciljjjkimjpiijbiakekolpkclokcklljjbiolplelnljkckklpkmlnkfle
fmgfejeleaebegengpfnebem
obngpnohpkpipamknipaogogpepcpamcpmplpbpkoc
nkmimhmcmlnnioidioilmkkdke
jnmjmemjkgkcoeod
lcogologiakhkpkkkdkcmlmm
kkpmndnelklllcpopbjipopbippoploondne
flabeneofl
niopmenomdmbmjpdppnfnpnimjmbobmjnpnpmnmlmjplmfmcmimdnl
miimimimimimiiimif
ckclcndlcmabcocmdldihghmdcdpchdlcmcnhadpdndndldcdlcmdpckdhdbdahadkdhcndpdmdcdldk
mkmlmnnlmmobmommnlnijgjmncnpmhnlmmmnjanpnnnnnlncnlmmnpmknhnbnajanknhmnnpnmncnlnkjmjcjomkmmmlnljojhif
jakfjejekbjcibikjajhlilhihimibijibjh
bmcjbibicnboanagbmbldedlalaaanafanbldecjbibibldeegcmanaoajbnaebm
baekckalakab
nhppinoangnbnbmgmnnh
gkecdafkhlhihpglhcgk
ohpnohphpppplnphpppp
lpjjlpkhimkolpjnkoljlikckekf
mdoejkigjkicjkigip
gjddhigfhi
bodjcfcmdodncldicpdgchadajbiafbjafambodgdnadaeaoafbnbjekcedodgcjbpbibiapaebodmapbibjadafaedgdnadaeagafanafae
hneihmhnggflgmhkhngihlhnfkgbgmgfgf
ickfidjfjfjdififniplpmlfjkjpjdjiicngifjdicngndjcngjfjojhieifngjfjkjpigjejjjhiejcngicjdioicni
nippmdmkninlmnnomjpaobmfmpnomdnpmdmknipaplmfmcmimdnlnpimocpipaopnjnonomjmcnipkmjnonpmfmdmcpaoimjnkmfmpmjnp
hfefgihchbgngahi
pinkofoiojod
imlmjnjojjinjeimninikiikjbjgimjnik
polklilplpollmoolp
mpppnhnhojnonmncmimpnomjoinomjmnnomj
jhkclanjmdlbigieikjajhjbjk
gdfgeecndhfjhihjhc
njompojhinolmmmembmimj
cbbidkdbcadjdacggpfifp
nfpnpnippnofoipcpbonoapijb
gkfbffdodlcocghcggdodlcocghcggdodlhk
engkfmenbjbjfkfffaejflfgfielfnbjenfmebenbjfpfifafffmfnbhbjdeddbjhmelelfgelbjbkbjbmfnbjbebjbmajabffeb
cdgogghjgfgegchjgggegbhjgggcgc
dahahahh
iflcjjidjojmjeko
jmknimipinlh
omnonomh
jhkbjbicjfiglm
hdfogihfgigo
mcocmenjninknpninn
pmmgoboopmpb
oanjpboapfpjpfohpp
kdjklgkdlp
hgebgnglgmgagdhbgh
ocnepppiphpipfpdnfpophpppi
fmgkfkejfoen
kcjbkdlhkelclh
becfbbbfabam
ephbfkedededhhfcfjfoejepec
pimoofpimnpmpm
adbocabgblblbcad
pknjobodomoppk
mjpmmjncnaneno
heengfhhedhi
hgefhhglgogg
dlbmcodldkdncb
jelcipioijio
peneofpcpcob
fpgdekfjegeeeffc
jikpidificnfne
bidiadaccpbobfbpbianaa
pkmfoppmokohopmnogopohoa
igkcjkjdjmigjnjp
hmehhahbgpgngg
olmppopdpg
jokiifigjolc
nnofmaninmmimfmannna
nmpammmnmomb
pnmhoioeoa
naojmfmnmfngoambocmn
fohjefegeleeel
heeceeemfe
dlaicdcadi
pbmkoloamooapm
bpcgaobpak
hoengfgfgngggpdiemel
jjmilnlpkckklpkmkakjkmljkmmilb
mjpjninlnmminbmj
gbghgahlhbhjhjcgchdlhagnhadfdh
boeiegejfl
gnheeggkgphk
mnjjjgmkmamk
oimlpfpcopoipnkmmanipjpkpnojpaoi
ngmnncmhmm
pjpppiodompo
ipiljeimjoijiijdjojhjhnfjoidjonl
jjmalkmnkfieijijiiidmnmakijfiiiomnkpjejnimjojomnkmijijmakajnlnjpiiiliijpiiidioiimnmakijfioibjijoieicidlnimjjifmnmp
nmmnnanimemhnkmnnkigmnnamnii
gmdnfefhflfjfefjeieifmfjemfjdn
cobgdfdjdldgbgdfcnag
pnmkobplogoeomngnlomohonomplnooaonooompnmbogpkpnmbnomhmn
obnbpmohpapgobmanmnnmcnlnb
bocjagadapaeboekcjalbkboadafae
dcbfapaeaechdeaocjdfdc
cfbfdeccdkcfdocbabcddodgcddadmccbmbhae
jbkiikjhialfjhikicjhieiijglfieilia
bacaabbhapbaalbeeecjalbgabeedebgaladbgafajbheedeafakab
oincpnpbpjopompnpppjmioopjpjnppdpcoioopdpa
bnekfkflfofpfb
cobedpcoapbdbcanbebo
gdeegogeedgfhchcebhohcgacecf
mjoomemopbnemomjolnenimkioip
kkjmklkkkklbla
djgohohphkhkhn
pfmeofoipf
gifphdhbhohdfohdge
akdnbbbdbmbbdmbbagdlagenem
hpepfoecfngcgohmfmgfgpeighgkhihiefgkgggo
aidkbabdbnaidcbdaibfbkafcpbfbcbh
bcdgbeajabalahai
dbbfdhckccdhcecigfaiceclcecccadh
bfdccjcecncncfcncndocfaeahdhaiaebg
nmoomhmemmmnnkpombmnnp
pcnfooodokoknjncpeohppnboioc
mnolnmplnimloonanhnnngmoikil
hbeifgfbgehggofghcfceggjgehghg
mnpeokonnimkncpfnamkmnoopknfnimkmk
dcbfapaeamddcldgbacpcddb
oanamckgnhplpkoaogplpinmplohoa
djajcidocgdjccdnajcidodjcecdcmdjcecccdabcedodj
pjnboipfpnobocppoippkdoipfoi
kijejhjjifidjajdjpjnjaidjbjnjpjejfjcjj
phmlmimgnknmmangnbnbmgmnnhnmngnamgnb
amfnalfifhblfifaambbbfbnbhanamfifhamfieoeifbfifofifaakbnbpfgbnaabnfibjbmbmfifnalcefnalfifhbofifhakbnbpeceoemfifhaofifnalfifhbmfifkfnalfkfb
goejfffmeoenfleifpegfhhdhjgihfgjhfhmgoegenhdhehohfgngjegfjgpgigihphegoemhpgigjhdhfheegeigphe
gdhihlecehhjhihahefcefgofbfagohogehmgg
mejcjajpndjaji
cmhbhigghihk
fjapanbpbdalbm
gjdicncfhbgf
aihbhghbhgfjaphbhghbhgdjaoaobdaofmfpfmfjbihbhghbhgfjemeebaaehf
pfkepckbkoockbpdpeopofononlcldkpoepjoekbkdkepckdknkclakbojomooof
lpkdkgljjeobofkpkklp
ojpopfoppcpapildpiofpi
gcdedgdldlhihjdlgfhhhihchehjgodgdldlhhhkhkhjgbdlhihjdlgfhhhihchehjgodlhmhjhedgdldlhchpgfhhhehkhddlhbgggddgdldlgdgfhddlhbhkclhchpgfhhhehkhdhcdgdldlhchpgfhhhehkhddlhhgdhchphjdgdldlhhgdgehhdlhihjdlgfhohhhchjgbgfdgdldlgdgfhdgedlhchhgchhdlhchpgeclde
ojmbmioopioplnnjpmojpm
kdilihkflilblolllcphoh
bjdbckacacakabaidbcoafbpacaaai
fhhpgeememeeepeg
cgaobbdkcadndpdh
inkflnjmjpjiimjfin
mkocpanlmkmjnbmmnf
nlpdodmammmomdippmnlmannmomimk
cpahbcdfdpdocddodpbpbj
fchkhfedffffepejeiaghffcejfeehebed
mhopoangmamanknmnnma
abcjcgabbkahbebcba
pjnbnopeodooknmjompjom
pbnjmapnpboaolpgomokolpgnj
cobjdldjdcdp
fngkegenemajgkeiekebem
cgbfacahbbdddbdkdh
adcebgbbbcfhdfafbiaaaebobjbafhdjbcadaabiafbm
fagdfghhemefeaebfgghefehemeb
aoficjblbmbpfkdiaibfanajbdbebn
lcoejfkokhkckdleifkhkfkokd
lfodjclgjdkelbkoldlfkeld
odlfnfofpioaoepcofnkpcodofpopeoe
hfcdecgngigegphffcgigfgefbgjgihcgjgigpgg
pomjocpiofohopkkoeofpokkomofppoeookkofoekkojogodopoepoke
jgiajaidjeihmmihjkih
eigahoeofnekfjgpfdfkeielfneofjgahoeofnekfjbbhoeofdelepfjeo
lhjpiblbkclfkgjakmkflhlekclbkg
caaibgcgdfccdbhjbgcgdlcdchdbcg
oonioiplompplkpepfoolkpmpfoppepolkpfpelkpjpgpdpppeoole
djcpdpccdkdocidpgdcidfci
fohghdeleeeoepfc
lojgjdklkekokplciilikflnljkpli
acckcpbhbibcbdaockcpbhbibcbdaodeaebjabafbdae
pondoloeoooppckkoipiofpnpjoppikkoeofpokkomofppoeookkofoekkojogodopoepoke
kjlakoliljlklipdlikfli
badicjanahbgalbhalacbadicbaaadab
mlodpcngnmmnnammnanjml
dbbjaacbccca
liooomobobkckdoblpknkckikokdleomobobknkakakdllobkckdoblpknkckikokdleobkgkdkoomobobkikflpknkokakjobkllmljomobobljlpkjobklkapbkikflpknkokakjkiomobobkikflpknkokakjobknljkikfkdomobobknljloknobkckdoblpkeknkikdlllpomobobljlpkjloobkiknliknobkikflopboo
kjjiljlklipnldlckjpnlllckildljpnlcldpnlolblelildkjpd
bccaapbeadaaajboegaiajbcegaaajbdaiacegajaiegafakapadaibcei
lpjhigkelbkckhkhkkjhinkcljkoknkeldjh
bjbnbpacalaeabaiboedaeadae
ndphnfmimbmomlmcneii
fngafkhlemefeifneafpem
gceghhgcho
ffadabamepeoamfdeeemeoffeeabamfbfdeoeheieneeabad
lokmkdlikpkmkflcoekplckp
dhaocmdjckcpcpccaacmcoddcmdackdhcmdbbeckcnchcmdeaacpccdada
gmeeglgmhhgkhjhphn
eigafjeeeifjfcepfffdfcep
emflfjflfafnak
kjlolmlolfli
hegegbhegbhcgfhagphchegjgogh
cidbdfdcdfdicjdbcmcp
imiljajjjmjniknfjljjjljajn
dnafcgckcccmcn
nlpdnpnnmkmjnmibmfnm
opljlllgpfpepnojpkpgpopgpoojpmpcpfpmlllgpfpepdpkpfpmojpopipeonpoojoclllgpfpepgpoojpmpollljpkpjpeooopkbpjphpkpfpa
fiefejfefmeaedfoejacejfeej
mmolphpoomoppjokpnoepfnbnlmknhmlnhnommoeopnbngnmnhmpmljipgomoeplmnmkmknnngmmoonnmkmlnbnhng
ncodmcmpncmpmjmiopoc
echfhjhlgfgghdhf
pgkcknobkcpbpgodpapgkckakakcknmpmdnkkcka
nliniknminiknmiknmiknmiknmin
bebcbfaoaeamamfdfceoafbiafeaecefbdecemedfbeaecefbdefbdefbdec
jhifikjlmnihicjh
edbjbcahapflep
elhjfofgfdfkflbb
abddbmbjbafffhfaagfhffbgahbabeabbaffagaabgbgbaagagfl
kgnpninpniibkhlblblhkbkbpm
pdkcnhnfmimanfmgmkmdmgndmgkcnlpeocpfpboooeockjodof
plkknpnnmaminnmomcmlmonlmokkndnlpnnnmfmdojocnponnppgpfmemmolnhkbokphok
mimomjncninanaipiojcnjmenjjmjo
epbjbhbiak
gphihghpdfhogdhodldehidlddgphchghohegogpdldegpdlckcldcdldndlddhphohhdldefndldeekdldj
hmckcbcicocicahlhmgjhkhmcickckcick
phkbkk
hicocfcmckcmcehohjgcgigagadpdoccgjhegjcmco
cehchmhdgbhj
cddbdbdjdfdcdldbdddidcdodidpdcdjdmdndodfdjdkdgdddndodcdpdndpdgdndf
nemjmcmomfmkmemgmkmnmnmlnamdmommnamfmcmlmmmnmomlmpmfmpmjmimpmgmfmd
kfllldlflalolclplelilililplmllldlllnlglalnljlclelnlgldlelllmlplilf
ibjljojhjmjnjdjhjajkjcjejajejkjajnjjjajdjljojkjbjhjajdjcifjcjojljl
gdhghbhfhehfhnghhfghhbhghdhlhmhkhphkhehlhphmhchchihdhkhghkhehbhlhe
apbdbfbnbkbfbabfbebibnbobebnbjbpbpbmbibcbbbfbgbdbfbnbfbabpbfbkbkbp
epfnfdfjfefdfcfgfkfofhfjfefdelfbfjfjfhfpfifffmfifffkelfffpfefpfbel
oipdpipopkompjpjpfpepiphpopfpepbpdomphpopgpbpdpdpcpkpnpcpapopkpppa
plohppoiodojohoiojobohonoippofolokobofoiocoloioaokogooppppooojodob
ccdedkdidpdddpdpdadadedjdpdkdkdndidmdiddcgdjdbdmdodndbdidjdhcgdhdf
cadhdodbdidccedicedidbdgdadododbdkdidicedodhdgdidjdodpdcdhdcdcdkdb
ngmemlmkmjmdmjmemnmamjmpmjmimnmincmbmkncmemfmbmpmkmemimmmpmmmencml
faepekehehemeaenedelegedemebekegegefeaeaeleoeoekekefeledecfefeeceo
kflalmlklmlllllmlmlhlnlflflolglmljkblllnlolilmlikbldlolhlplhlllilj
cbdddndmdjdedndadmdidcdjdmdcdldbdbdodpdcdkdddodgdhdcdadodndadldhdn
nkmamcmmmdmamamhmemnmamcmlmjmfmemenomnmimemnmcmdmnmimjmjmimlmimkmd
kplflklflblglplalfldlalclflclnlflalmlplilmlmlilnlfldlplklklglglglb
docecbcococncecjcocacncacmcjcococlchcmcncjchcmcecgcccjcjcecdchcdcn
ddcbcjcncpckcmcpcpckcmcfcncmcmcgcfcjcdcecjcjcicacgcacicacfcjccccce
mcnhnpnpnaneninenanjnemgnlndndnnnpmgnondndnpnmnpnlncmgninkmgnbmgmg
kdlbljljlclakhlplllilflnldkhlmlplclelgkhlmlolnlnldlmlalelnlplmlolf
ddcgcccgcecpcmcjckcccbdhcpccdhcececocicjcfcicicpcecmcicjciccccckca
bhaaaeagagamahbdafacaeajaaagagafakagafapaoahafbdalbdapaiaganapafai
eoekfoflfofafbfmfbfnfjflfmfnfifjfpfdfhfjekfifbflfgfefmfefpekfifefb
eifofkfcfnfjfafbfdfbfjfffbfefaemfbflfgfcfgfdemfefeemfhfhfdfafgemfn
lnkpkbkakfkikbkmkakekokfkakokhknknkckdkokgkpkckkklkokmkckbkmkhklkb
bdakaaababamabafaoadaoapanbhaiagaiakaganalafaaaeapadadalaoaeaabhaj
lekbkpkeklklkbkhkokbkekdkckpkckglakhkhkgkokkkfkpkokhkfknkkkckkkdkb
cfdkcbdhdocbdkdedndmdacbdcdodicbdedmdhdedpdfdmdfdcdgdjdpdedgdidmdp
egfkfpfhfnfafmfefmfefbfpfgfjfgfbfpfofafofffdfffpfeecfefafnflfhfdfe
bdalbhabaeafanamajaoanbhacacaoalalaoabajamaoamaaajaeaoamaaabapadai
baaaakadajaiagaiahalaaacalagbeaabeabahafafaaadacagahadadacaoacakaj
kmlklalplalhljlfljkilllmkilklhlakilalblplhlhlhljlmlmlblgkildlkljlb
ffeaekeoeieaeiedepeefbeceeefecfbeneielemeieaemepeaeiegedeefbemeced
jbiaipihieijihieioikjfijiginijiciniaigibieijiiiaiaiaieipilimiiinii
bkakaialananapakacahacboaaakaeaeabagamaeakamacalboadaealapagacadad
fpeaebegeeeeedehemeeeaeieieeepeceiebebeneoejeneeegehejehebemenedea
dhcccjciclcmcgckckcmcickceclcpcochcncpccciddcjcfcmcmcbcncjckcnckcg
bdabbhalabaobhakagakaeanagamajbhaaajaobhanacagacacaoadajanaiaiagai
fhenekekelefemeiehepekeoebehehelefeoeneeenfdepeeefeaeefdeoepekehem
nhmmmbmfmfmimimcmendmommmlmgmnmnmkndmjmmmimondmpmpmmmamnmpmnmhmcma
effkfhfofcfpfnfffffhfafjfifjfofafnfifpfpfhfdfpfhfmfoebflfofkfmfjfn
anbgbkbobfbcbmajblbablbhbibfblbobeblbibkbbbcbhbobfajbnbaajbmbgbabg
fnfcbmbkbjepboekbpekaebpbjboboaebnbobjbkaebbepbobiaeekelbkbpbbekbpbpbkembkbmfeahfbfjea
ibihjkjljmjlniicjejjjjjaiblfjeinjmjajmjljdjmjljmibimnljgjkjinlinifjm
fffgeeedeefjffeeepfceieoepgbemeeffeaemeafcekapeieoapfjfbei
jjjgninkneneijneipnlmanfnonjnomanjionpnlmaneimipnlmaniijnpimijnonenfnfnjioiijamdjfjnie
jejlibibninbncicififmnnjifnjncmnneniicibmnnjnfnhnamnnfigibignaidigifncnfnhnijnmojijaij
ohoikgkkpgpckgpfkbkklokfpgpckklokhkdpbkgloklkapaphlokkkakekbkhkkpbkdkdkcpgkcoolnolodpk
hfhkgfdjgfgfghgcddgacmdidggfdicmdfgcdhdbcmdjgddedccmdegegfgfdddidigddhdhdgdfhmcphjhbgi
lflkpgkcpfpdkekekapaomkdpckepfompfkdkepfomkapephkhompjpdkapepjpepdkdpapdkfkclmopljlbki
babpagfhabfnfcagfbacejagfbagacejfmagfafmejfmfafcagejfbfgacfafhfefhfcfbabfmfebjekbmbean
cnccdmdlgidpdlgmgodlhedkdigkdnhegngpglgnhedigbgngihegoglgbdpdndlglgbgngmgmdpcehhcbcjda
ejegakalaiaealfiaoanbafifofjfpbaajakakfmbaaeamflfjbafoanafflapanamaffjflamfmeabdefenfe
namfnbnammmbmknamnmhmfnamlngoemjnnmjmnmkmanhnamlngmjiknmnemn
ReadFile
VirtualFree
lstrlenW
WriteFile
lstrcpynW
VirtualAlloc
lstrlenA
WaitForSingleObject
LocalAlloc
CreateFileW
GetFileAttributesW
UnmapViewOfFile
lstrcatA
GetModuleHandleA
FormatMessageW
GetLastError
FlushViewOfFile
LoadLibraryA
lstrcatW
GlobalAlloc
DeleteFileW
CloseHandle
CreateThread
GetProcAddress
GlobalLock
LocalFree
MoveFileExW
GetFileSize
CreateProcessW
CopyFileW
lstrcpyW
GetTempFileNameW
CreateFileMappingW
MapViewOfFile
GetTickCount
GlobalUnlock
lstrcmpiA
CreateDirectoryW
WritePrivateProfileStringW
GetPrivateProfileIntW
AssignProcessToJobObject
CreateJobObjectW
SetFilePointer
GetPrivateProfileSectionNamesW
ResumeThread
GetPrivateProfileStringW
lstrcpyA
GetCurrentProcessId
CreateProcessA
TerminateJobObject
lstrcmpiW
GetCommandLineW
GetCurrentProcess
TerminateProcess
lstrcmpA
SetFileAttributesW
ExitProcess
lstrcmpW
SetErrorMode
ExitThread
SetUnhandledExceptionFilter
FindFirstFileW
FindNextFileW
ExpandEnvironmentStringsW
FindClose
TerminateThread
GetWindowsDirectoryW
MoveFileW
GetVersionExW
WaitForMultipleObjects
FreeLibrary
LoadLibraryExW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
GetModuleFileNameW
GetEnvironmentVariableA
OpenProcess
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
CreateFileMappingA
SetEnvironmentVariableA
GetEnvironmentVariableW
GetCurrentThreadId
ProcessIdToSessionId
GetTickCount64
WTSGetActiveConsoleSessionId
KERNEL32.dll
IsClipboardFormatAvailable
SetClipboardData
GetClipboardData
wvsprintfA
EmptyClipboard
CloseClipboard
wvsprintfW
OpenClipboard
EnumDesktopWindows
FindWindowW
wsprintfA
PostMessageA
FindWindowExW
GetWindowThreadProcessId
CharLowerA
GetClassNameW
OemToCharA
GetWindowTextW
GetWindowLongA
SetThreadDesktop
IsWindowVisible
GetParent
SystemParametersInfoA
LoadKeyboardLayoutA
SetFocus
MoveWindow
GetKeyboardLayout
CloseDesktop
IsWindow
GetWindowPlacement
WindowFromPoint
ScreenToClient
SendMessageTimeoutA
SendMessageTimeoutW
GetWindowRect
PostMessageW
CloseWindow
GetKeyboardLayoutList
GetProcessWindowStation
GetDesktopWindow
GetUserObjectInformationW
GetThreadDesktop
MonitorFromWindow
ToAscii
SetForegroundWindow
PtInRect
OpenDesktopW
MenuItemFromPoint
HiliteMenuItem
ActivateKeyboardLayout
PrintWindow
BringWindowToTop
GetTopWindow
CreateDesktopW
SetWindowLongA
VkKeyScanExA
GetKeyboardState
GetMenuItemCount
SetActiveWindow
SetWindowPos
GetMenu
GetWindow
USER32.dll
CreateDCA
GetDeviceCaps
CreateSolidBrush
DeleteObject
Rectangle
CreatePen
DeleteDC
GetDIBits
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
RegQueryValueExW
RegDeleteValueA
RegDeleteValueW
RegOpenKeyExW
RegOpenKeyExA
RegSetValueExA
RegQueryValueExA
RegCloseKey
RegQueryValueA
RegSetValueA
RegEnumKeyA
GetTokenInformation
OpenProcessToken
GetSidSubAuthority
GetSidSubAuthorityCount
ADVAPI32.dll
SHGetFolderPathW
ShellExecuteW
SHELL32.dll
3S4_4e4
425I5U5|5
6#6P6c6q6
7727E7X7k7~7
8(878K8U8
:K:V:i:x:
;4;?;X;b;i;o;u;
<1<D<J<O<k<r<
=$=/=E=Q=Y={=
>D>O>^>~>
000@0N0]0
1%161=1h1o1~1
3&3,31373>3D3J3T3
5 5&525U5o5w5~5
6'676W6e6
7"7+747=7F7O7
9*:N:T:Y:_:f:l:r:|:
;#;);I;S;^;r;x;~;
= =.=?=Y=f=
=&>4>:>D>[>i>u>
?&?J?a?
C0L0U0^0g0z0
1!1)1o1
2#2-2R2X2]2c2j2p2v2
3#3.3J3T3s3
484C4Z4t4~4
5#5:5T5^5
646F6Q6`6n6y6
8%838Z8`8m8v8
8+969A9V9\9
:1:8:>:D:g:
<0<6<u<
>?1?D?p?~?
0'0-0E0N0Y0h0r0|0
1 1.1=1P1V1
2 2/2B2k2y2
7:7[7l7
768l8~8
9#9/9o9
=#=+=9=K=S=a=i=w=
>#>+>9>A>O>W>e>m>{>
?!?'?-?3?9???E?K?Q?W?
0 0+0=0h0n0s0y0
1&1J1P1U1[1b1h1n1x1
293P3c3
5"5,5;5N5T5
636<6B6
7+737@7Z7q7w7
8 8&808J8\8
9'949\9h9z9
:$:*:C:K:U:
;K;h;p;
<!<'<;<O<c<r<
=9=?=E=m={=
>#>)>0>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
0E0S0]0c0
0!1*1X1
172S2e2p2
364J4Q4i4z4
545]5c5y5
7737G7Q7[7p7
8+818^8h8q8w8}8
9+9I9m9w9
;6;X;s;
<><C<b<u<
<)=3=v=
?'?=?O?U?[?
0-0>0L0V0p0
0=1L1d1s1
2 2$2(2,2024282B2M2R2^2h2m2
3+353@3G3R3o3w3
4 4+42494?4F4P4Z4d4o4z4
525=5R5w5
6@6G6M6R6\6c6l6}6
797`7h7n7
8&8-8:8A8N8U8[8a8g8m8w8
9'989?9L9S9X9^9d9{9
:#:):0:::D:N:X:]:c:i:q:x:~:
;';1;K;R;
;$<9<B<K<Y<
<$=>=K=T=_=j=r=
>!>Y>i>
?"?8?U?g?u?
0"0,0>0K0S0v0}0
061<1R1X1^1
4#494?4s4
5/595@5L5S5Y5
6"6)646>6z6
7$8H8T8
0*1G1`1}1
2-2F2c2
3$4(4,4044484<4@4D4H4L4P4T4X4
515=5L5\5c5u5|5
737K7[7
8!8R8g8
:+:::A:X:^:
; ;&;E;i;o;u;{;
<F<N<T<]<c<i<o<u<
=Y=g=u=
>%>*>0>6>@>
0J0R0Z0s0}0
2"212;2k2q2w2~2
3 3$3(3,3034383<3@3D3H3L3P3T3X3v3
3"4B4H4\4o4}4
5K6b6o6
7&7,71777A7G7M7S7Y7_7e7q7
8(8.848=8F8
90:m:t:z:
?0?E?R?y?
0"0-030;0F0L0T0_0i0z0
2&2E2Q2Y2i2w2
3 3+3>3C3_3
44%4-4V4c4j4q4w4|4
5/585?5G5N5V5b5h5{5
6"6=6C6c6n6|6
7#707E7
7*8J8j8
:c;o;K<U<b<o<
4?7o7y7
==X=]=D>U?
0=1Q3U3Y3]3a3e3i3m3q3u3
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2(242@2L2X2d2p2|2
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
jjjjjj
VS_VERSION_INFO
VS_VERSION_INFO
StringFileInfo
040004B0
CompanyName
OohtYhqVclAjP
FileDescription
BNRKVsYVxtYsDaFZ
FileVersion
69.5.85
InternalName
qcoNRIpoNHV.exe
LegalCopyright
Copyright MdYzrbVIBKRg (C) 2011
OriginalFilename
OhVhjyLpPAbrBHr.exe
ProductName
recWqPcrlIIWC
ProductVersion
11.81.77
VarFileInfo
Translation
ojWFQkNSpCMYctS
sIDNwybPlbvxJI
TgfJSRJSNmbqbAKxf
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic Windows.Trojan.Lobshot
MicroWorld-eScan Gen:Variant.Lazy.271868
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee GenericRXVX-DB!7104F635A418
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Agent.As5t
K7AntiVirus Clean
BitDefender Gen:Variant.Lazy.271868
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Agent.ADYK
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky HEUR:Backdoor.Win32.DarkVNC.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Agent!8.B1E (TFE:3:lVmKEGZ4QoP)
Sophos Clean
F-Secure Trojan.TR/Crypt.XPACK.Gen3
DrWeb BackDoor.Siggen2.4466
VIPRE Gen:Variant.Lazy.271868
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.nh
Trapmine suspicious.low.ml.score
FireEye Gen:Variant.Lazy.271868
Emsisoft Gen:Variant.Lazy.271868 (B)
Ikarus Clean
GData Gen:Variant.Lazy.271868
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen3
MAX malware (ai score=85)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.D425FC
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.DarkVNC.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Trojan/Win.Generic.C5396646
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Lazy.271868
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36270.fu0@ai5jF9mi
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.