Static | ZeroBOX

PE Compile Time

2022-07-19 14:55:49

PE Imphash

f2d625db1ca3c7b0cefab187e9edcce3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000326bc 0x00032800 6.55227599333
.rdata 0x00034000 0x0000f464 0x0000f600 5.61171074752
.data 0x00044000 0x00028f88 0x00001200 3.17248258643
.rsrc 0x0006d000 0x00000508 0x00000600 3.76105177837
.reloc 0x0006e000 0x00002184 0x00002200 6.58666802806

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006d0a0 0x000002e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0006d388 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library RPCRT4.dll:
0x100341c8 RpcStringFreeA
Library KERNEL32.dll:
0x10034018 ReadFile
0x1003401c WriteFile
0x10034020 CloseHandle
0x10034024 Sleep
0x10034028 OpenProcess
0x1003402c GetModuleFileNameA
0x10034030 GetModuleFileNameW
0x10034034 GetProcAddress
0x10034038 WinExec
0x10034040 Process32First
0x10034044 Process32Next
0x10034048 GetSystemInfo
0x1003404c DeleteFileA
0x10034050 GetVersionExW
0x10034054 GetModuleHandleA
0x10034058 GlobalMemoryStatus
0x10034060 GetComputerNameW
0x10034064 GetTimeZoneInformation
0x10034068 GetDateFormatW
0x1003406c GetTimeFormatW
0x10034070 GetLocaleInfoW
0x10034074 GetNumberFormatW
0x10034078 FindFirstFileExW
0x1003407c SetEndOfFile
0x10034080 WriteConsoleW
0x10034084 CreateFileA
0x10034088 FindNextFileW
0x1003408c IsValidCodePage
0x10034090 GetACP
0x10034094 GetSystemDirectoryW
0x10034098 GetCPInfo
0x1003409c HeapSize
0x100340a0 CreateFileW
0x100340a4 SetStdHandle
0x100340a8 GetProcessHeap
0x100340b0 FindClose
0x100340b4 HeapReAlloc
0x100340b8 DeleteFileW
0x100340c0 ReadConsoleW
0x100340c4 SetFilePointerEx
0x100340c8 GetFileSizeEx
0x100340cc GetEnvironmentStringsW
0x100340d0 GetCommandLineW
0x100340d4 GetCommandLineA
0x100340d8 WideCharToMultiByte
0x100340dc EnterCriticalSection
0x100340e0 LeaveCriticalSection
0x100340e8 DeleteCriticalSection
0x100340ec LocalFree
0x100340f0 EncodePointer
0x100340f4 DecodePointer
0x100340f8 MultiByteToWideChar
0x100340fc LCMapStringEx
0x10034100 GetStringTypeW
0x10034104 GetConsoleMode
0x10034108 GetLastError
0x10034114 GetCurrentProcess
0x10034118 TerminateProcess
0x10034124 GetCurrentProcessId
0x10034128 GetCurrentThreadId
0x10034130 InitializeSListHead
0x10034134 IsDebuggerPresent
0x10034138 GetStartupInfoW
0x1003413c GetModuleHandleW
0x10034140 RaiseException
0x10034144 RtlUnwind
0x10034148 InterlockedFlushSList
0x1003414c SetLastError
0x10034154 TlsAlloc
0x10034158 TlsGetValue
0x1003415c TlsSetValue
0x10034160 TlsFree
0x10034164 FreeLibrary
0x10034168 LoadLibraryExW
0x1003416c ExitProcess
0x10034170 GetModuleHandleExW
0x10034174 HeapAlloc
0x10034178 HeapFree
0x1003417c CompareStringW
0x10034180 LCMapStringW
0x10034184 IsValidLocale
0x10034188 GetUserDefaultLCID
0x1003418c EnumSystemLocalesW
0x10034190 GetStdHandle
0x10034194 GetFileType
0x10034198 FlushFileBuffers
0x1003419c GetConsoleOutputCP
0x100341a0 GetOEMCP
Library USER32.dll:
0x100341e4 wsprintfA
0x100341e8 LoadStringW
Library ADVAPI32.dll:
0x10034000 RegOpenKeyExW
0x10034004 RegEnumKeyExW
0x10034008 RegCloseKey
0x1003400c GetUserNameA
0x10034010 RegQueryValueExW
Library ole32.dll:
0x100341f0 CoInitializeSecurity
0x100341f4 CoCreateInstance
0x100341f8 CoUninitialize
0x100341fc CoInitializeEx
Library OLEAUT32.dll:
0x100341b4 SysFreeString
0x100341b8 SysAllocString
0x100341bc VariantClear
0x100341c0 VariantInit
Library NETAPI32.dll:
0x100341a8 NetApiBufferFree
0x100341ac NetGetJoinInformation
Library SHLWAPI.dll:
0x100341d8 PathFileExistsA
0x100341dc None

Exports

Ordinal Address Name
16 0x10007e8d ?GetFileVersionInfoByHandleEx@@YGHXZ
1 0x10004ec8 GetFileVersionInfoA
2 0x10004ece GetFileVersionInfoByHandle
3 0x10004ed4 GetFileVersionInfoExW
4 0x10004eda GetFileVersionInfoSizeA
5 0x10004ee0 GetFileVersionInfoSizeExW
6 0x10004ee6 GetFileVersionInfoSizeW
7 0x10004eec GetFileVersionInfoW
8 0x10004ef2 VerFindFileA
9 0x10004ef8 VerFindFileW
10 0x10004efe VerInstallFileA
11 0x10004f04 VerInstallFileW
12 0x10004f0a VerLanguageNameA
13 0x10004f10 VerLanguageNameW
14 0x10004f16 VerQueryValueA
15 0x10004f1c VerQueryValueW
!This program cannot be run in DOS mode.
4Y<SC\=
C\=Rich
`.rdata
@.data
@.reloc
@@;E$w4
@@;E$w4
PQQSVW
PPPPPWS
QQSVWd
URPQQhPb
UQPXY]Y[
PVVVVV
PVVVVV
j0Z9~4t
j0Z9~4t
j0Z9~4t
uj*Xf;
<j*Xf;
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
JjlZf;
V +V4+
tb9^4~]
V.jx_f;
~ +~4+
F.jgYf;
PRRRRR
PPPPPPPP
ARPRQh
jYjf
uSSSSj
SWt@jU
_tqPVj@
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
u kE$<
j-Xf9E
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
<at.<rt!<wt
<=upG8
f9:t!V
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
QQSVj8j@
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
MICROSOFT
64914429082040625334531630171992528649754997484940
433A5C5C50726F6772616D446174615C5C
74732E646174
53595354454D20494E464F524D4154494F4E205C6E
5C6E5C6E205B50524F43455353204C4953545D205C6E
---------
24746D702E747874
2463616368652E646174
7C2A3F2928257D5E267B
633A5C5C50726F6772616D446174615C5C24746D702E747874
494E46
44574E
53495A45
48415348
4E4554455252
4552524F52
5645524946494544
4552524F525245504C414345
52554E
444C59
434D44
636D642E657865202F6320
633A5C55736572735C5075626C69635C63722E646174
msdata.ddns.net
Runtime reported exception
GetFileVersionInfoA
GetFileVersionInfoByHandle
GetFileVersionInfoExW
GetFileVersionInfoSizeA
GetFileVersionInfoSizeExW
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerFindFileA
VerFindFileW
VerInstallFileA
VerInstallFileW
VerLanguageNameA
VerLanguageNameW
VerQueryValueA
VerQueryValueW
Unknown exception
bad array new length
string too long
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid stoi argument
stoi argument out of range
invalid stoul argument
stoul argument out of range
invalid string position
vector too long
Error! GetSystemDirectory failed.
Error! GetComputerName failed.
Host Name:
Error! RegOpenKeyEx failed.
OS Name:
OS Version :
OS Build Type :
Registered Owner:
RegisteredOrganization:
Product ID:
Install Date:
System Manufacturer:
System Model:
System type:
Processor(s):
BiosVersion:
BIOSVENDOR:
BIOS Date:
Boot Device:
System Locale:
Input Locale:
Time zone:
Total Physical Memory:
Available Physical Memory:
Virtual Memory: Max Size:
Virtual Memory: Available:
Virtual Memory: In Use:
Page File Location(s):
Domain:
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
UTF-16LEUNICODE
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
version.dll
GetFileVersionInfoA
GetFileVersionInfoByHandle
?GetFileVersionInfoByHandleEx@@YGHXZ
GetFileVersionInfoExW
GetFileVersionInfoSizeA
GetFileVersionInfoSizeExW
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerFindFileA
VerFindFileW
VerInstallFileA
VerInstallFileW
VerLanguageNameA
VerLanguageNameW
VerQueryValueA
VerQueryValueW
RpcBindingFromStringBindingA
RpcStringBindingComposeA
RpcStringFreeA
RPCRT4.dll
CreateFileA
DeleteFileA
ReadFile
WriteFile
CloseHandle
OpenProcess
GetModuleFileNameA
GetModuleFileNameW
GetProcAddress
WinExec
CreateToolhelp32Snapshot
Process32First
Process32Next
GetSystemInfo
GetSystemDirectoryW
GetVersionExW
GetModuleHandleA
GlobalMemoryStatus
GetPrivateProfileStringW
GetComputerNameW
GetTimeZoneInformation
GetDateFormatW
GetTimeFormatW
GetLocaleInfoW
GetNumberFormatW
KERNEL32.dll
LoadStringW
wsprintfA
USER32.dll
GetUserNameA
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegQueryValueExW
ADVAPI32.dll
CoUninitialize
CoInitializeEx
CoInitializeSecurity
CoCreateInstance
ole32.dll
OLEAUT32.dll
NetApiBufferFree
NetGetJoinInformation
NETAPI32.dll
PathFileExistsA
SHLWAPI.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
LocalFree
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
GetStringTypeW
GetCPInfo
GetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RaiseException
RtlUnwind
InterlockedFlushSList
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetStdHandle
GetFileType
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
DeleteFileW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
lientC
RPCRT4.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AV_com_error@@
.?AVbad_exception@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVerror_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AVcodecvt_base@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV_Locimp@locale@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0(040>0J0V0f0k0u0
)0B1g2
7":6:>:
9(:Y:=;s;
<2<C<c<
393S3m3
?(?-?E?b?x?
1 1.1^1
4_6s8F:
>1?X?d?
!3J3W4
9M:%<3<
?!?=?_?
0(1-1|1
2 212?2Q2d2x2
3'343Q3Z3
k1{12
<:<C<I<^<y=
55$5*50555:5@5F5K5P5V5\5a5f5l5r5w5|5
<*=@=G=Z=d=l=
>?A?]?
01A1X1d1
262;2@2F2
;+;Y;l;w;
4"4C4X4
6.6R6k6
9&9C9v9
:-:5:E:`:y:
;#;B;a;q;
<9<S<_<f<~<
>'>4>=>B>U>
?j?r?x?
3#3*3W3}3
3M4a4m4
5$5@5g5m5q5y5
5+6@6N6\6h6u6
9&9+9:9
9&:1:i:
:$;H;[;m;
;H<Q<\<c<v<
==/=?=O=X=|=
>.>3>@>
> ?-?N?S?l?q?~?
44%474A4
4G5z56F6U6^6k6
8(81868I8]8b8u8
:L:U:^:l:u:
4+5054585<5
313E3a3l3z3
3A4P405]7
363V3d3k3q3
4(4Q4l4q4v4
5"5'5E5O5[5`5e5
6J6Q6W6
7?7-878D8u8
<-<B<O<e<l<x<
=.><>U>]>f>o>
;,;B;O;];k;v;
0V1[1b1
313T3l3
283 =9=f=m=x=
23D6N6X6
E0c0{0
6&6Z6a6
859P9g9u9
< =+=3=>=D=O=U=c=p=t=|=
>>K>\>a>
363E3W3j3
434:4Y4
5,5A5Q5^5
6_6x6}6
7)8]8h8r8
<*>E>[>q>y>
3a5l5|5
5+6=6O6
979A9h9r9
:!:5:A:F:K:[:`:e:u:z:
;+;0;5;E;J;O;w;
<!<6<?<w<
>'>6>A>F>K>f>u>
?'?=?B?G?h?x?
(0L0p0
161=1T1j1w1|1
<(=:=D=g=
0*050t0
1(1f1|1
6"6,6h6
6&7\7|7
:;3;=;X;
;9=A=M=Z=a=j=s=
0!0.0B0G0M0i0k1
4$434>4D4J4^4f4
5!5.5:5
5"6[7m7U8B:
5"8(8C8H8s8{8
9'909;9C9a9m9
=D=h=q=|=
:-;L;b;
<]<b<g<l<u<6=?=
5-7H7R7
7(8G8j8
<G=P=T=Z=^=d=h=r=
6*626J6X6`6x6
:2:D:V:h:z:
===D=[=q=
>,>?>I>b>
>#?9?t?{?
?-?L?w?
!0C0g0
< <&<R=
>8>C>P>b>
>G?\?e?n?
:0;Z;b;
=f=k=}=
616N6a6k6u6
2 2$2(2,2024282<2@2L2P2T2X2\2h2l2p2@7D7H7`7d7h7l7p7t7
8(8,80848X8\8`8d8h8l8p8t8x8|8
: :$:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
5 5$5(5,50545
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
T0X0\0`0x0|0
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
4(4044484<4@4D4H4L4T4X4\4`4d4h4l4p4|4
4 5(5,5054585<5@5D5H5L5P5T5X5\5`5d5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7
;$;,;4;<;D;L;T;\;d;l;t;|;
4@5D5H5L5
6(646@6L6X6d6p6|6
7$707<7H7T7`7l7x7
8 8,888D8P8\8h8t8
9 9,989D9P9\9h9t9
T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
8(8,8<8@8D8H8P8h8x8|8
9 9$9<9@9X9h9l9|9
: :$:,:D:T:X:h:l:p:x:
;,;<;@;H;`;p;t;
<(<,<0<8<P<`<d<t<x<|<
=$=<=L=P=X=p=
>,><>@>P>T>X>\>`>d>l>
?4?D?H?X?\?`?d?h?p?
0(080<0L0P0T0X0`0x0
1(1,1<1@1D1H1L1T1l1|1
2,20242<2T2
909T9`9h9
:8:\:h:p:
; ;8;@;H;L;P;X;l;t;
<0<8<@<H<L<P<T<X<`<t<|<
=$=,=4=<=@=D=L=`=h=p=x=|=
><>@>H>P>X>`>t>
?8?@?D?`?h?l?|?
0$080T0X0x0
181X1x1
282@2H2T2t2
383X3x3
484X4x4
585X5x5
686X6x6
2H2X2h2x2
;(;D;`;
<$<D<d<
= >D>p>
Microsoft Update
Trigger1
2018-01-01T00:00:00
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
CurrentType
RegisteredOwner
RegisteredOrganization
ProductId
InstallDate
%s\oeminfo.ini
To Be Filled By O.E.M.
Manufacturer
General
To Be Filled By O.E.M.
General
X86-based PC
IA64-based PC
AMD64-based PC
Unknown
[%02u]:
HARDWARE\DESCRIPTION\System\CentralProcessor\%u
Identifier
VendorIdentifier
SystemBiosVersion
HARDWARE\DESCRIPTION\System
BIOSVENDOR
HARDWARE\DESCRIPTION\System\BIOS
SystemBiosDate
HARDWARE\DESCRIPTION\System
SystemPartition
SYSTEM\Setup
MIME\Database\Rfc1766
Keyboard Layout\Preload
MIME\Database\Rfc1766
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
Display
PagingFiles
SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
(null)
((((( H
((((( H
(
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Microsoft Outlook Suite
FileDescription
Service
FileVersion
8.54.120.34
InternalName
OLMAPI32.dll
LegalCopyright
Copyright (C) 2010
OriginalFilename
OLMAPI32.dll
ProductName
Microsoft Outlook
ProductVersion
8.54.120.34
VarFileInfo
Translation
Antivirus Signature
Bkav W32.Common.B0019620
Lionic Trojan.Win32.Jaik.4!c
tehtris Clean
ClamAV Clean
FireEye Gen:Variant.Babar.99231
CAT-QuickHeal Clean
McAfee Artemis!09A9E1B03F7D
Cylance unsafe
VIPRE Gen:Variant.Babar.99231
Sangfor Trojan.Win32.Agent.Vf79
K7AntiVirus Trojan ( 00487a5c1 )
BitDefender Gen:Variant.Babar.99231
K7GW Trojan ( 00487a5c1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.HUAD-3913
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Agent.UWL
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Agentb.lbqi
Alibaba Trojan:Win32/Generic.063e6adf
NANO-Antivirus Clean
ViRobot Trojan.Win.S.Agent.285696
MicroWorld-eScan Gen:Variant.Babar.99231
Rising Backdoor.[Bitter]Agent!1.E3FD (CLASSIC)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Agent.nxsqm
DrWeb Clean
Zillya Trojan.Agent.Win32.3147319
TrendMicro TROJ_FRS.0NA103DD23
McAfee-GW-Edition BehavesLike.Win32.BadFile.dh
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Babar.99231 (B)
SentinelOne Clean
GData Gen:Variant.Babar.99231
Jiangmin Backdoor.Bitter.d
Webroot Clean
Avira TR/Agent.nxsqm
MAX malware (ai score=84)
Antiy-AVL Trojan/Win32.Wacatac
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Babar.D1839F
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Agentb.lbqi
Microsoft Trojan:Win32/Emotet!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R560734
Acronis Clean
BitDefenderTheta Gen:NN.ZedlaF.36348.ru8@a0w1afci
ALYac Trojan.Agent.Wacatac
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Malware.AI.105397623
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103DD23
Tencent Malware.Win32.Gencirc.11850d07
Yandex Clean
Ikarus Trojan.Win32.Agent
MaxSecure Trojan.Malware.193418222.susgen
Fortinet W32/Agent.UWL!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.