Static | ZeroBOX

PE Compile Time

2010-11-19 01:27:35

PE Imphash

3786a4cf8bfee8b4821db03449141df4

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000199ea 0x00019a00 6.60849441752
.rdata 0x0001b000 0x00004494 0x00004600 4.3680164362
.data 0x00020000 0x00005a48 0x00003200 1.37053943287
.sxdata 0x00026000 0x00000004 0x00000200 0.0203931352361
.rsrc 0x00027000 0x00000a60 0x00000c00 3.30196469484

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00027788 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00027788 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_DIALOG 0x000278d8 0x000000b8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00027a28 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00027a28 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000278b0 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000271e0 0x000002bc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library OLEAUT32.dll:
0x41b190 VariantClear
0x41b194 SysAllocString
Library USER32.dll:
0x41b1a4 SendMessageA
0x41b1a8 SetTimer
0x41b1ac DialogBoxParamW
0x41b1b0 DialogBoxParamA
0x41b1b4 SetWindowLongA
0x41b1b8 GetWindowLongA
0x41b1bc SetWindowTextW
0x41b1c0 LoadIconA
0x41b1c4 LoadStringW
0x41b1c8 LoadStringA
0x41b1cc CharUpperW
0x41b1d0 CharUpperA
0x41b1d4 DestroyWindow
0x41b1d8 EndDialog
0x41b1dc PostMessageA
0x41b1e0 ShowWindow
0x41b1e4 MessageBoxW
0x41b1e8 GetDlgItem
0x41b1ec KillTimer
0x41b1f0 SetWindowTextA
Library SHELL32.dll:
0x41b19c ShellExecuteExA
Library KERNEL32.dll:
0x41b000 GetStringTypeW
0x41b004 GetStringTypeA
0x41b008 LCMapStringW
0x41b00c LCMapStringA
0x41b018 GetProcAddress
0x41b01c GetOEMCP
0x41b020 GetACP
0x41b024 GetCPInfo
0x41b028 IsBadCodePtr
0x41b02c IsBadReadPtr
0x41b030 GetFileType
0x41b034 SetHandleCount
0x41b04c HeapSize
0x41b050 GetCurrentProcess
0x41b054 TerminateProcess
0x41b058 IsBadWritePtr
0x41b05c HeapCreate
0x41b060 HeapDestroy
0x41b06c TlsAlloc
0x41b070 ExitProcess
0x41b074 GetVersion
0x41b078 GetCommandLineA
0x41b07c GetStartupInfoA
0x41b080 GetModuleHandleA
0x41b084 WaitForSingleObject
0x41b088 CloseHandle
0x41b08c CreateProcessA
0x41b094 GetCommandLineW
0x41b098 GetVersionExA
0x41b0a8 MultiByteToWideChar
0x41b0ac WideCharToMultiByte
0x41b0b0 GetLastError
0x41b0b4 LoadLibraryA
0x41b0b8 AreFileApisANSI
0x41b0bc GetModuleFileNameA
0x41b0c0 GetModuleFileNameW
0x41b0c4 LocalFree
0x41b0c8 FormatMessageA
0x41b0cc FormatMessageW
0x41b0d4 SetFileTime
0x41b0d8 CreateFileW
0x41b0dc SetLastError
0x41b0e0 SetFileAttributesA
0x41b0e4 RemoveDirectoryA
0x41b0e8 SetFileAttributesW
0x41b0ec RemoveDirectoryW
0x41b0f0 CreateDirectoryA
0x41b0f4 CreateDirectoryW
0x41b0f8 DeleteFileA
0x41b0fc DeleteFileW
0x41b100 lstrlenA
0x41b104 GetFullPathNameA
0x41b108 GetFullPathNameW
0x41b110 GetTempPathA
0x41b114 GetTempFileNameA
0x41b118 FindClose
0x41b11c FindFirstFileA
0x41b120 FindFirstFileW
0x41b124 FindNextFileA
0x41b128 CreateFileA
0x41b12c GetFileSize
0x41b130 SetFilePointer
0x41b134 ReadFile
0x41b138 WriteFile
0x41b13c SetEndOfFile
0x41b140 GetStdHandle
0x41b148 Sleep
0x41b14c VirtualAlloc
0x41b150 VirtualFree
0x41b154 CreateEventA
0x41b158 SetEvent
0x41b15c ResetEvent
0x41b164 RtlUnwind
0x41b168 RaiseException
0x41b16c HeapAlloc
0x41b170 HeapFree
0x41b174 HeapReAlloc
0x41b178 CreateThread
0x41b17c GetCurrentThreadId
0x41b180 TlsSetValue
0x41b184 TlsGetValue
0x41b188 ExitThread

!This program cannot be run in DOS mode.
`.rdata
@.data
.sxdata
PSSSSSS
^L8^4t
2AABBf;
CCEEf;
t'<\t<nt
PPRPQPh
SPSVSh
B@@f98u
9t6j`
F$;F,r
t\IItEIt2IIt!It
9^pY~0
CY;^p|
w$_^[]
9~|~!;~pt
G490tvB
V4u$9]
tpNtfNt*Nt
tSNNt*
t4Ht"Ht
x0C;^D|
_^][YY
u ;~D|
FD;FHu
t)It"It
t7Ht#Hu
D$ )Ft
D$,_^]
L$,_^]
T$,_^]
|$D;T$
AG;L$$u
;L$ds3
;T$hs)
D$(;D$
D$(;D$
L$(;L$
9F _^]
9NLtp;
T$0_^]
D$0_^]
D$0_^]
L$0_^]
T$0_^]
uRFGHt
QQSVWd
t.;t$$t(
FLVh)IA
VC20XC00U
sO;>|C;~
6;58(B
uA;5<(B
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
HSVHWtgHHtF
PPPPPPPP
PPPPPPPP
tFGQPS
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
OLEAUT32.dll
MessageBoxW
ShowWindow
PostMessageA
EndDialog
DestroyWindow
CharUpperA
CharUpperW
LoadStringA
LoadStringW
SetWindowTextA
SetWindowTextW
GetWindowLongA
SetWindowLongA
DialogBoxParamA
DialogBoxParamW
SetTimer
SendMessageA
LoadIconA
GetDlgItem
KillTimer
USER32.dll
ShellExecuteExA
SHELL32.dll
WaitForSingleObject
CloseHandle
CreateProcessA
SetCurrentDirectoryA
GetCommandLineW
GetVersionExA
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
MultiByteToWideChar
WideCharToMultiByte
GetLastError
LoadLibraryA
AreFileApisANSI
GetModuleFileNameA
GetModuleFileNameW
LocalFree
FormatMessageA
FormatMessageW
GetWindowsDirectoryA
SetFileTime
CreateFileW
SetLastError
SetFileAttributesA
RemoveDirectoryA
SetFileAttributesW
RemoveDirectoryW
CreateDirectoryA
CreateDirectoryW
DeleteFileA
DeleteFileW
lstrlenA
GetFullPathNameA
GetFullPathNameW
GetCurrentDirectoryA
GetTempPathA
GetTempFileNameA
FindClose
FindFirstFileA
FindFirstFileW
FindNextFileA
CreateFileA
GetFileSize
SetFilePointer
ReadFile
WriteFile
SetEndOfFile
GetStdHandle
WaitForMultipleObjects
VirtualAlloc
VirtualFree
CreateEventA
SetEvent
ResetEvent
InitializeCriticalSection
RtlUnwind
RaiseException
HeapAlloc
HeapFree
HeapReAlloc
CreateThread
GetCurrentThreadId
TlsSetValue
TlsGetValue
ExitThread
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
TlsAlloc
SetUnhandledExceptionFilter
GetEnvironmentVariableA
HeapDestroy
HeapCreate
IsBadWritePtr
TerminateProcess
GetCurrentProcess
HeapSize
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetFileType
IsBadReadPtr
IsBadCodePtr
GetCPInfo
GetACP
GetOEMCP
GetProcAddress
InterlockedDecrement
InterlockedIncrement
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
KERNEL32.dll
,!@Install@!UTF-8!
,!@InstallEnd@!
.?AVCNewException@@
out of memory
.?AUCSystemException@@
.?AUCInBufferException@@
.?AUCOutBufferException@@
.?AVCInArchiveException@N7z@NArchive@@
GenuineIntelAuthenticAMDCentaurHauls
.?AVtype_info@@
33333330
{{{{{{{3
{{{{{{{33
{{{{{{{330
{{{{{{{330
{{{{{{{330
3333333
33333333
wwwwwwwwwww
DDDDDD@
DDDDDDGpw
DDDDDDGpw
DDDDDDDDDDD
wwwwwwwwwww
;!@Install@!UTF-8!
Title="Install"
Progress="no"
RunProgram="Install.exe"
MiscFlags="4"
;!@InstallEnd@!
F</}h<
0~,acJ
CQ_Xr%
Vs,JD2
4O%Lfr[
2cxQ`{
a`$c[r
%Lui ,
S29 i.
2&8-9d
G#hm'V
GC\$<|
dS3tAMAJ
sFN}!IVu
}_'Va<
;PJzu+Mi
0O]3ns
r0$SVX
.y*;1p)
*.M`l?
?@h@YlK
i[ua@c[b
zj&q]l
f)"w{Jj
W=euZ6
o=+cBO
6MB^l5
Oot"v%
_d*$.n
y&<%F
}o'+QfHQ
|_Cj A
& Dhyg
Re@WI]
X'[Afw
s:Ii-(
i>Z=qRI
aXt6TjZ\$
cw.$Un
(1S<8'j
N,q/- 3
s&&+Gxt
S6Gi2:a
fq}I)s"
5,M{km
m'<S-m^
zCh!/u
*@Vh!3
3AS5;`X
#O2c[$
%bDM\r
0d`'v-
LD3_:@/
6wxDuY
a*G%&]
l"^Uly
uq<8-7dd
k b>Rm
FFe9@?T
Hd]kI)Dk
#4<)B5
PIv^'`
p8rsrx
Gk,5ZL
=}^1`#
`"rGoi
>86yI"<
@qX8v
qY@87)e<
X7lWfv-
SqMwr*L
V<\G|2
&YPx<m
q2_Ig[+
qsFlRq
bkICY5oU
*uhKnE
Fsc;-Q!
89VF7N*
d,M5]N
<&?\w
)m4=DW#R
@)8j7u
1ww=Sb$=
Sn:ef
{>pi5,
Nh/!2lN
0YhD+]
FD;(n
$PTM^>s.
h3aU4yB
%+w<R(
l<g[IMy
qH^2ve^
HlNFuj
N20~R{
VMh/B}
lq2#/H(Y
jHmQP|ly
g9t2'_
"Ffy.T
c+fCq9
@J6h <z;
i {.CS
illX\E
UGw80L
PzHDVJ
}0)Q)4
=1X=7.@
B==D+"
rUC(p)
O^rjP{
3Xonn}
.B5{^?O
FWE&M.QI
%\B%pgN
W3R~lS
8+{BbT
wKhC6%N=t
|$(T'|-z
c4I{7lj
"vEX[,
l.j|D$
0>=D5=
RZP*@l
?2JCMu`kUs1
)ijcy]
;]>)Oa
^x]z3n
MK*G.'{E
UVpCx )6
Aw}=Sw
6k(EHh
{1'\+
WnfHx^
zS|T[~
Lh_nQ%
Nb/OYA
'LDt.)n
XHR*NW
KjO?So
;AYG @
i4;]Ft
"E}&dR
fT|kfn
>{$}eX
Fl>hvd
)J!bmE,
K)["#j
PEC`Sig
UfN4>,
i MOyU
6Kr)"(
:p}gvD
``<H;J
&> uo-
|bo3^S
a|ck:e
R7AbRb
jsB2od
d!<N)u
I,f>f`
{,RV66
=v0~Wg
,J9wm?
3RTw_V
v[yfN*
n'fP&2
k;KHp!
*K>>WI
mCz\V}
+l'fN~N)
r^8B:G^
kgdv=*
]Y=igl1
sQlH:a
|~V:*
dPv(T"5
oB"5Ur.
qfG$:2
vc|[I+
P#1ck(
$Ncx%$
3~IG;}
>b}!y!
TAG@k1
xxTl?
Xr]6!kE<g
yg {[
7Z@fG;7
@M:6Ed
PF_qt
Hl0kU<h
0{[nar
dUf+[H
g']j>2n!
21ep)&
>atbH'
&x7G1w
kSs7zX
k^0aex
TgN6K-
542w~m)
beA7Ho
qS\8<!}
cmBB0785
F0)utx
<k}h,d
Xy9c6)T
]K0Y%Iw'
5S1"}@$
4NlI@3!
Im:iDC
,l:3gc
-az7Xy
sM\BT*
"/ TGK
eahmPlr1J
umKd!
I+Yj.7`0
P9q*92
pZ=2r`;Cz
";90Vm
H)=/V&GC
|4*Em@
p9aj38
P{v"-p
\vV9^^T
+S^KE_
I<$h4
?L lSJ
JmuS6!
;@4wob
i^XFrNXe02J
}M\QrV
VK){Y/BQ
+WEEO=[B
;+-L%9c
Hp|EW\
fUiFi)
Ht[1W>
bhtdKF
TE\Ds0R
=-@AFU5
'Z dZ:
!8~et
giyj1]
Bpx#8\
g>"QA
{BjT/f
.G5w t
AX0-GY
7l"Ldp{5
n56q)$
7@Zh2xA
[2~$\{
gLdJ{}I
!:8FoI&
dhQhG}
8y{b{a5
z(utLN
H+s$,F
kVU_XJ
7d^Jey
70Nyo={
YUdY5M
z^)h:DB
!Y.ZN|
%dy1@C
A,Ob3sM
JwFRsp*>V
;?:tTy+F
*{!?Q2b
6F@.YgI
FR.A\$J
D)Y|~f
Iz@-:)rp
OofQT=#lfo
/Z@\[
`>D#I6
WG@s7r
C>vxtP
(~[0kr
%[w ]veOQ)
QbURI'=mD
oC~!e
[O5Uv
,O|k~^
El,w s
6SKq)l
uo>BD,
=K`IW609
*.78Z
aTPuV@,
}'{kU<
1IK]am
*mHl,rY
W+CwPo
5| 0/)
zx~Rz`
CMVTXi
H/60TOS
8y?^K~M
:/qOVt
jC'\Q
ts"Lc>
m4a7P6
rt.dy%
|6d_<!j
g%;Kc-
bPdE"E
qzo7*C
D5;WB"
07^w7I
k/boF<
kXLn4z
w:\HeH
e-XeN3
F)u'v/
0}y2]/
Pj^VD7
8m'C|y
EjXjJf
7k]/,
)_?AU/
[[rSO2-
YP`%m5
]o^/:s
Jw.Y:.
B=ix_9
D:Hj(OMw
^!fC,=
4"i&,.V
{k'3n7O/Nb
~2[#K)
z`HRY
Zz:rx4)
FedT1@
,{#]^g
H7t_y!
31WHxnA?
"N'k:"
'$|J&s
dOZP"8
]R"J#Z
!XZ1>u
"Ry|j5/1
!GqFzv
3\SP#Q
|r^psp
{C0@.R
L6(an#O
T>)K@j
i&Wa-)
JRu*S};8j
;q{uQ!
P$T1#B
a o%K-
yF$4z=
&+< 3]8i
~&eMx)r
bdIcx2
6.'[x0@N
~LwiJ]
lR[UWd
0{S=%&
2NF?ZW
K_0{(8
/uT2(t (i
iB6,zY
C@hq0_
vu@j 2x`
IR\RC{
(FXZ}l
Wp22P/Ci?7=
,oL\I5
3>/aA4x
"l,[1F
7I;"zX
/)n*u>bA|
C@#rtn
$(z0eRDM
9CfO+H
9{\gz_E
p&x{Y,
p_X{Thf
uzs/}-
"YxG`G
b-|rC8
s&&Kn'
"_~[O$A
6["w,
ZU&Ypx
:w_;ky
BtfX<U
JgPh.O
sT]Ir!
,/2Fy"Y
z7*cZr=
*{28k<p
_T@X9u
~G('C`
\"m&T\
88C>Tu
5F9H"3
g(*$>G
,[wA(M
ViI>QunR
su!CjHA
G-J+#F
U0Cj6
Huv`"V
/!'JD<
2a,?#W
l-&q9,
(Zg2b>
UsLn/i
($"m^-n|^
b7uSKm
(%e9:HN
=B8N%0l
Z~u=nIr
o6T0!W
0m6\@"s)
,C}I)$
#z:`")9
;,']".$
@2sRCT
>2r5&
(UeRiJ
F@%]SJ\
>C19}v
O{s7I$
;HqXKc
><dl%$
+c$P/7P
hCmW9}ZB
rC5$bUB
"%NK|PL
r9|J7
nXU[>
Le1\"{*
r~nahq
i[QGD.
h0ufan
g{NO$4Z
L][RnI
dG=cY|j
Xn(-C'
C$ (Wo
.O,8/
P}90iL
Mn(#h&
r{{%,m
j?1|1
=>t|U7@
B1B0I*
T]VVq
0y5ak#
[y{[A.v
ld_.TK$
h)jIA
|C=^9k3
>0-wTNx
BPX'Q/
9+%`PnV
{Et(dX
3}! +.
*72kv<u
/5FPvy
|BD@oJ
QZ{KYR
wf^ y(
8SRG;a{
yg75HM)aIC
MukWc8
-)Pt!ox
2 ]BZ%%F
nCA]RB"
O|kJ[z+
o]r%I"N
$C!#+B
1^z'NQ
1ef2<r
+U|k,-X+
JajSIn
p,TX4\
J`~o;`
jJ#MnJZ
hnVK79
esV-5[
B`1}fD
L&>L-F
it+^eu
qJtl\_
^q@Ujv
iGW>t0]
atWg`[
KmFo"#YTj4
@Mk#7= J9
hw[J~C
CNT]%*
q;J|Z\
)42h_>|
l[5P+
'01XtE}
^SwPPQ
Os+D<:i
QkDPZY
I7J)]3
%3 X4l
qqZ:w0
:gOh"fO
>_0ZUL
UepLN [d%@2
5]RsC?
OH>goPW
GG]p)Dn
'6ch(c,
kwdWQ'C6
OlGEWirvV
)Ue75l!
sWYZ\I
hr8]Sp
X+aH}*
\!46JC
sJA54JG1P
5|:^Nm
[oQ?rO
%-kXK}
W5C7i+
Eau"2=
$:iP?^
.]L05u
O,OFPS
YbV#K(
TL]9`Q
>j1Vc)
$^B%})
AZ<B{R
-BlOtlc
%aMo-w
GHF2GP
1N9djC>
`xR@HM
4{$&)9I
T{0Wg(h
5N8{k!t
_!Z 2a;
~3H'TQ
nWLi^I
*mX|I1>Jh
ImB9M
:00+8V
2P>#^G
NHODk/U
WM.!.{
'k>FK]NZ
`rCAS
V8nAVr
c_A{ lvc
@l(9d$)
kn<H3Kvg
Zj&"ao`
lV47n%
xzdgYX
/N2,},
#$0'`#b
N*pV[4
avex1?
8Q#u?HZ
j_6QPN
nqN[G/3K
\M2%{]U
"4`*5
7c175f.
?*]DxdS
Z.`^P>
f*dP+a]
=gVie>
{1=Tc@
M:Kb%|
/Mm0|H
TCaLW.+b
y6.N;C
5Fyz@
uZE0mN
+}6oP=
T]u[Gp
>_5_0J
"_g.aOO{
RhLM+c
'$0_\Wu8
5AH XR
)q1C=#t
M&DQ>}
V12)h7
gL5BYEV
L a78>
w94Gol
+*z'8BmM
T"hx!)
qBN\SGM
}A"nq^o
/(Yl@<8
?!7]ap7
E>]I-r
v1^$PE
w/yY6Y
A@dyX|.&
G'\oJy
E$c5WsF
34>?|[
-=~}3R
8jd.gR%
bsLQ^"A
IS:yP8X3
6J6Nc
-,59g\`
=ANp_.Y
g7%c}=sI
a3MA_7"
-mcF-
(@|\:SP
O,d&T
5vY<G+'
T6*q f<q
,cZ-hm
L![;IDC
8AGKTzg7
teUf!a=o
za|bk"2
{2&869
hU]1pbut
tt%/,S
B~|/&9
CY2vU@
+;.[JS
Y.Gvfo
I|\~rsU
6?Q0#)
$PN9-t
o;~%y$J1
JiA?hf
bJjmV>
c)a'N
U)Pe~
Nk<eo&Hd
yD>V6<
wf6qTX
T%aw|B
_)6/[]
pM-"CX
q,S"i]
9U[g-x
T-}W'O
sePRyn
(%g9:x
Zah#XB
a\6Y^U
%QMyA+7
}b|hK_[GU
8P{. +
"mY&#
#>63?=Y
2d#/w
TF_83J
>19c(5D
-u0_znE
,C"[\Uc
;^q?5Qv
+-adDP
uIIR?f
MQ`!nw
IN1^,U
:Bx3-Y
O*UUwXyN
c>'E+<(
7l2Tj#
T??%Hp
|P(:Z%U[
/+Lm~UA
22[8K{L
K 4IXQ"*
P6o*mx
an"E<?
@NR%d@
F+0@q8g
s?n|gj{
tJm_!-
sJvuwb
x:] VRA,
=@9gh7d
}N%?T)
{XW5CM
V^:alWh(}
y S^B:
:"Itz\
VeXeN_
E-; on
a!_GxXrKh
=w$)Sm
}dWGsx
4f0q[Y
EgCkX`
x&g)i[
OF~]-W
ValYEZ
O_>KY0
\SH +esD
6V"1>(
q4N{[W
(-GZ>yl
o10eVqD
=yI'=/
Yb{!-W
{,RQ@h
"uz{ yu
:}oS[qH\
9jzXqL
(@#0TW
^I5{jt
Z0eVd9
H0f*L}
)a5s5p
i/u:TJ
b{sF<-
y{~te81
l3;W`
tuQY*A.
$8>2DX
:-s)4?#
]~Og/7
5Gq%T#
hO8sPL
L}'Dt,T
N?:FZO@
E=t;,87\
`L-/3;P
[,o.=lZ
TvMam6
4CQctWh
@]AtWn
n`EVyX+2
N<|%pU
Wi2RXe
EE's'C
,0HwBx
+2i4EL
d92(U__
EFeFud
F4Rl5K
{>&kae
+M`]N[M5
r_YINk
^]V,t%
X UyL
l_NQHl
QnQm/>)E
"])sSl
ROS)-M
oQ'TV#/
ajv H
jFj9["
b\XNsK:
AD:,U(
hY|#Gu
.=.dMD
Fb| ).F
=g]z-7
m9yc3:*
S~I_I5gH)Bs
xy}qy3
k{@$a-`
d|fJC$
av7plh
ZAb7#d
MS51f:
`4KoD!
`S3 @2xu6
hk0]m[
p~_P65
1Q.O{2R
MrH}KUC
&DRD (
st|P?hzF]
f;L4bI$
5eyvM
NNmtvr
sNEcji
W\#10]j(/
<w`r-0
jYx9bQ
Q=u{i'X
.K;7%cz
em)$x+
[gkl=yb
[^N*l
3P?:e#
Vk\;!c
!vc\01
j4KN<4_
Xs:|rX
073Rt$
w'135G
l$LuA5
<~p!i+`
HZ<I<x
t5'Fy`
s4p~\^.
C@'lk{
;.L:m#
x3NPX^w
SWW"H:
wn3kVsd
oqpsZnG
3!!O.:
|M7HPfc
bOjFOpVJ60
;y}N/`X
kL3f$#
o(`S7H
Rb]Btb
4_&j5k
bcb{Z>9lX
;Wheic
$`B['H
CE\rr"
dpbvC{
% 4+BQ
dA\#K>
/4`lo8BnbVai
I"vMGhs
eUj3}i0_
v|"NmOu
GkSvQ3
F'Ol9|
_b9'Ov
Z\YxAe
TI7n=mJ\7k
M1g04j
Kx/LI(P3
g01 N8
^F7i#`
l4n>q'
`!^[*H
WLaxF+$
tCx Khx
)b6'lr
!8ZiJB
jAs9G$a{g
`HY.Cd
/y#iT\
WKU)Fd
ruXA.b
|k"HJ'x
2K\.mb
qirq<?
h`$swm
EOw+$cP
K*[`X<
U*}S,rN
gb?<T4
ug6[|
DI;l"$
_)O6W{
drV2lp
JX8w=!
y ;!W
'*(IKQ%
8zjokJ
7n`i2xl
D!m70!Z
$e%Md(
:^L1D*#
G~aB?F
\U/la
SWz}%+
{'KPR)
OJ)0w{
U]Ho0^[
@H:LnUA
Y(n!'
5\[vm|_vm
1vw={S
*:'1fN5
Np^962
W:>XfP
muSyp_
ioZIS\
-y$"vW
R96Q'#"
!jz~Ln
EDh0p*
g2lC]%
;rx(Mm9
u=Y:Q
83:Pcz
v*vZ7q
,M HH!
Q|& u
*CdHFEs
>B~.Yk
,Q:fME
##(/aL
_Qw4g)
%-n~4l
9c'Is]
;rqEsI
qWzFi$T
D|Gr2:
~f0*JG
J{6Pw~
v)T5laW
4;sUnM":
(r_1_s@
rg.XpS
uv(R4L/
MhLr#*
%yEP~ez[,$
+j|(:SzY
Ag0Fj>
j[|IVu
MxuLKy
Go7C}
5K5ceE
pFW}!A_
e-GG&!
ND!To>S
69$-R#.Di
ol`}:+N@
5t.S&~
RAgMZY
mg5^H2
hZ }_
0o&6FN
*/S';EJ
QsV[o22
S{8?5O
{7<5h
@b(huh
Z5;?YMS
E-8vOV
u`zmsA
:!sSejL
vj\#x.I
Bj9uBiC
@Up{B=
"yfjro
&T_%uw=
s8F[%+/
m>&T-L
w,5ttj`G
ZXhOjz
r.6j8L
Sf{k43
v5vHd0
cn[Il
1 i+]U
&likmIFi
"1_zf>;
TzvIS6
-/^{j3
>&458H
)oz,9p
j7L?12
\r:zsD
vd*%0]Q
(,gKkE
M1~)"\
9k/\k
Zn+]V^
`bEqQ3
%>b!<T@:%M
YAJ|UP
\@IyM9
q]jne)C
D>s)eH5
Ax(&e1
,dAzm$
uij4oEk
INU,%E
1(|m>i
2C=ymcV
B+g#v#
M JxPlkO
B"*Vq#
MLxL\/
YrW]fM
(UmQ*q
cf/ygwb
U;HkI&
qS\"2nVE
Yc>p;wQ
[pkJ<m
4E}FlS
!`/!,#7E
+fM|[U
[\E&bL
<lYcWG
VRB@7`
OFXII+
+`y R$JI
epPssW
$MY*X[-,
%~b }f+
jZWv9gG
]v}qnSI
}/b6<[
Jq6qR
\KDm9L
BfQdc*x
FDB6f2
WK$S%>
i'/E;VQs
lJF,ja^
.!'xkRi
S_[>m~
la|2s_u
sl!pV
BS@TD
!_fP)pO;
6\t$,
UEyY:e>
b.e2(8S
?'={='
E$!Z5Ml
O?"9$)-
7@A.'{
z;klkJS
~\+mS=,s
E&z.OT
Jm'/t}\
?R`7v6^l
#S)}TkG+
9C}An2
y&KSh5
ltjW#F
d[Iz3
RJ)|fu
Wy:FMGz
Nc7vgi
_3Bd'm
N2O[gl
kS}J%8
:yxo-D
ipc7pJ
5px%da
{2yr"iL
HyExWKc
/2}+qi
;o4oV`
600O$s
Rc>VkMA
T5%`Go
?O6=NQ
feP:;'
nJwgw|s
RBo,fs
FZ7Wla
d0egkg
[-=kzv
G0&`33G
-I~O '
YugHo9
p@CXw>
I<;kJv
Ei=8}?
,>;."s
,)7g9z
%$.EJi
ZXtKM'
Q9YV484
Lb7R$9
2KB(V|
.TbI`"
2>B,Z=
N>zcZ$
cm_r)9
sJ_Tp#r
Q7=fzB
@I@v`/
j#<2V<
8easD>
?M]0WM
bq G;'
Y6J]-\
p31Lt|
YWi4IM-6SZ+
kn}H-]nV
RzG,YR
|S3 ,{
&FYV4'
0 dkf}F@Y
~)hL[w;
>.p(fX
T@+v;)S
"4IYVt
+RCSB
i!D:Ca
cO+%'m
xOg&k`
JyX.>**w
N=c\b\B:\
xPv2Z`
utlbpB
[,#aM_
q}0m]i
c[<7~e
}A%5e@
^II,CHX
&7e-~eq6
4KK=!
0FkEqr
l*+BLHd
`7wbop
(pyOGKe
KR'TlZ[
tn6Fia
_m:jBY
eMTCw0'
LTAstR
zMi~~h
D-HV@B
U!>&{f
nXt^,D
"V&N+4
tI1Ac7_
=rkFy/
:,s<3
[q.nk;
'>7!z:
/^)/mp-]h
dS42}U
q|@4h&
G);y_q
[Sft5u
X|5ZI]j
dP`Eyc
*mp3ho
:_7a.uD
j&Zm%Y
@Or/U(
`"za)`
}/|!uN
O,w?pgG
q\J7x
^}oHkN
]ut.`W4a
_]NT_h3
63y\%0
MebhC=
D9qXs9
Pps7Xqx
jkzr|m
$e#?ch
$qVwOd`=p
E$(uLUA
L-5:pjt
B0xp7?
1vGPQ
w<7MOd
.qn'Q2Y
~L)RAEM
Gl*!QJ}
?jCs7-
Gr^+T[p
Eq|/96
k'ZsT056
zc~s[sU
E Z#*?
fA8`[U
:m/0}(0C
FMAb!J
6\eU[T
|9*Q.:
3Se\4;1
/?$*\q
Q>$kS73q
.oEOk5
%IxUU'
bLf]hu
~jtxxaJ
|`u[/F
`FT.|_
04pxt|
#K[E\
Zt0[QP
ST9]|w
h<F(MH
HA.nu!
pPR=3p
a *OlM
1vv#V\
.C0JLr
f#d}Px
gP&ph\cqv
,NbZA"s
'pYR2s
d/<d"Jm
vw=&kg
!Jo%U#
aWVh#6
)!70Go'7
04_@AM
TKUy.1
9p@$*(k
HlKctB
(-Z?;i%
9$s]8#
By(=8m
uhHyLG
d-|%)
f7?D(-M\.
@rlQ:&
a&4X$U
(n8|%u'#i
ajoaQ3
ck=QKy
E07L&+
/+q-<$c
DYE6$G
n5P8_|
'Xt`Ca
Wao(Y
[7dcgS
ceG.0Y
ZgP gLD.UXN
(B6$T!u
N"l*l7e
SNGjO%
EsOq(9|
J>>L@4
u,{~h3z
~Wgg&B2
$hA3p,>;_
SmB7(_
P&E2H6
RJju5q
&1Fj3C
}+AaCT=2a
;2}CQH
G@8yO
"PRg]Dbp
K8?/lT
!G~.C}
oX])P1
d`|Y$7h
uXXw58d
zu=xXF
gGsFpg
+t`En"
0Q<okFe
L3q*#$
cdwTy`
UJl7j3
'}~'<)
p(crh7
s/zNg[
S5h} L
tKmvGT
x-?!>
zw vyUVZN$
gKUb/~a
0+"WeZ!
gr?!r+DQ
t:bZKP
gV97=$8
%u5h!c
Vu@*c
&7ugkN
c`*$7$
=.|qNge
m_g%dJ
5JnE)8
gKL8MC
nEknFX
~SY%tj^
|]%K'p
3S~wUs
~b9l:}
9KiLw_
=xC)D1jG
~"cS0z
phw '~
k"TMm<.
1/|Mic
7j^T"
lmv TC!
?:Uu5#
Jsn@U"
j:fx{C:
f>4UT4
4mW3E"
iD-=,L(
>;G]6s(aO+^x-
7PJm7>
Sp#Mt~
t)a5`0
D<t(UFo9
Jt%(-Z
`%t{@r
g.%HVl
Oj(OmK
^WWY63
Sx.PH4E
LqbPD/
mHP7,v
3Q'np*
=\juF281a
iU],EzX#D}x
TN%-IO
:|?L{Z
Mi)}}Z
'aHr^
h6xs<w
U&s8-5V
]B7F;p
0o|-s!I6Z
r0[c!^|}Y
T--P/2
:GkJK=
8xA(8c
O*oM}
exAE@7
;oXoog<
c9)]>v=l
bD+J!O&z\1P
;RNJ+m/
Ikvmkl!t
?Jo:|e
ds{K=O]
@CQMm
dl$B{}
6bhf'JS`OH
eU*1jq
Q:%1MG
@5F1d,
XO_P?np
^/=w|z5J?
0<p<3A
auIb\.
'M]W72
Z>'#-"
kJM:qm'
\hviO;
}';"gaK
e&]hY=E
P`+[fv
6nVkBO
Y4Q{Hcgl
6zBD=--
7u:h.h^
HVEiE:
+a+#P |
pJlY46
(IO|[P
ec-M,)
lAd\(IE
#>,gw+
84U!j@
")kU:
s8PArp
+G{+z[
YTM,Y_J
hrJ-[cw;c
_fk|g4
ZI~H=Q
Z=ud"5
4M/jaU
r-}e!P
WO>yB<
6SaSDK
&&P8Z(
TPPRBH
kl}lD+t
TVoZaKm'
}YU[ h
I4n8~%k[
jn@_%B
)fpaZ@
Fb1kNB
^>$_!&+
}azix?
VqBE^S:
Oh[!u8
$sD[#C
{RAApL\&_]%
knw>A9]
Wwk9v{
0^PYXj]+
e1v VL
"5S3 
8%'vv!J
(EECtT-
8L^iXH
c=1Nxy<*
oJ%,Ch
1W <Oj
U{`'!;_
0*\VW>
6K])]9
0$\GcG9
Nfu&qq
:^bxpn
6I% Y]grdU
d :QWNrk"
_S81a+@
V[{7_u
EFRMWiN
6c'S:t
EcPEKV
Q8PVJ_
.r?,4
zA_V4e
Kw0+f[
gLg)%4
)1L:TD'
]EN2n(
`0&+|k
djouZ
22uSe/
\txL9&
\.ke2l
,kJ:`k
qUD<,a
995dLn~
]V9z2C
bYOE`yjP2`
K2Rk_oW
hk\ES}
up}|&956
&Y3y|)
)mcf&W
,g(XO.
QCIu2j
NDs\^6
bnOu;O
Q1 h]ff
CWO2[&]
e)2c&JU-
6BHp<o
*vwfi1
y};]6zS
D6f2v$
p;{a]l6
%2&IZh
!9u6XR1
P;{384#
seIN c
"Ctm$a
0}s@@}5S
MqSU"\#
"mY[m3
A~`@c,
q>K +$7P"
"2~F4|
|_Hc;W`v
bT{jP~T
H[>U@{
KaTmzII
/tbu5{
=^1m~h
DR1&oc-
eyVh;<
NS[jbB3
uO_M;[
G-]%J$
VT22IR
A+r#l0w
LbK/>!
7ub5L}g
'n04a~
!7_v
kC>I(R\
(KR*.E
@Vm4im
bNX2Jb
B06{%x
2"(YgW.
1e.GV
--GXxQ
NC&^I44
JanN?%6
*nq|]~@J
;e8of,
kb(wHv'X
"G[\v.
~60qRX
[WHS i
$%8sP<
,LVdj|n
"BX#]<
$dU}kcH
sQNDt
M17Ue@q:
y5LEc'
!jv:Pf
8QM8kf<
&,I*M7
E=( _g
*(y!k=|
xLVK\ a
2|8CeL
ckpDFt,
X7sqG^w
35@6kH
!q8a%h
4+x)!T7
Xy|kU(
!&;I(
/n/D;s>o
LdUX\b^
C'r+Vd
Ouox!"
-a@$b}
AFW`#`
kCGs|y
/|_Gn`
dcw)x)
ItNIXM
jJx1xgf
p#[1Lm
zM-[o|
?UIV5|
X{euy9]|
5Zv Q
/~x/1{>
(m&>js
&'aq8k$
Des;.O
TJ"tT`S
T:@%"A
>&GUmrl[Oo
7&__93Iw
fXzuTtu
ES8O@p
rCZOZ
'Xs "*|&`
Nh]%#f
r@@Jd/
{{yU_]4
kYe"x~
gk!eO|
<V?{LF
bz&"78
Le3+}-
Nh_Xd|
1Hcs|Vw
$ClUz$
k'7,M8
bgw 6iaV
2"CcsM`
u)=a1.
GfA#hnDZf
:ODEE:&M
cDeLXZ
79pH!M
>p7rm4
KWi.8uaK
%9_%M)
Zh+|#
km|ziZ
6>||n^
Ou]Ux5
Q8Z=O}0m\y
3g&ps;
KE[=*w
@%S;9^H
,4c,qU
oiO7cx
F$'TxI
o|Nf:D41s
`/!zVP
zdV\]B
TCKvCa
5X7?G6
5n^5+L
ZIq>A:
4AWm(A
&$8[NG
|WnV`x
(Qa{tL
J#}Yh#n
>ugx]p6n
U%8{>h}
1T2(7h%
zZ;Y3G
d,>;xe"
Evmrw/
nA1i9
{f-v/n
:oFoO8
4-(8/#(5
5u,@Cu
wvqz1?Q
Me.+~P
~;@{dg
3YOWmX>gfG
eQFl7h
s=GP<Q<
D,cZvZ
Mi!E7}
A$t(r0&
QYE0p?
:=<ouV
Dod7s
y8*Qw;I
4}ZbKv
t,U*P@
@.Gm1=
5xCK!~,
PZNV!Md
3D/nf(
158.S2
4(iK
fN&]SL
zs)#EZl
c)th2HLA
@4=lU q
bLl.Oi
;IcY%mI
<xktHl2
>8I'W.{
WvFW*23j]+.
/K sL2
$NY__$;
(Jk7:#y
LhyME-
y@WX=J
e+_*i/
,>.O!tII
Z63I!Q
, +g?o
\<9@5S]
R6(Qa
ihb>qPP>
N >^fM
fFLU2Qo~
X6PM2W
$}-`NM
}*h6f0ab
kkqx{m
~aT$I=
vV?z-D
s!qKW!
'AwDjp
SE.`o
9:UT3gr
[2^(tEr
tR`u7y
<u#;O!
%#veJjm-
0Uhn}^u
q"=aY1c
u^mx9$
l\*bnV
k3s$?A
!AxeU
kQ&!TKE
`a)'+z
L>myL{
3yo$Vc
,jov*(`%bw
ZM)'F
(nC;NC
N' O>IL
-(!'Cp
r=?,{F
Wa F-^CYVL
fSeH$,/;(
N@CLCr
EJ6SM2
)sB!CgF
o{tDQh
U+fB|a
olX5PbO
\]m]8{2
Je}c'Xea
e:5K]g
V;b\-7
}[$<+
#LCyj&D
)nkXEg
8S`,{Ed:
r;iVw=
x8PrCiu
mGYw$9
xpPrWpZ
Gd7?Z:
(>c5p
LPY`SK
D=8.)v
{%bYBo
|Pfx!Is
4\so',<9
]xOQXb4[
t4_UHN
v-(Z{e
dDXRZX
05]jUS
AO"4^v
?GFu\m
.3:kT\a
i?H_&lM
k&#)@u
7Jjsgl(
/C|a2O
Aa~pP8
g?-zBtfg0W
_R`-2&
X'$&gS
]bRtM`
:wO}_o
+'eq2T
^h<Z<K
G1i>O-
`lXT-.l_
x~OnAv
3#H+u<
@JONkOO
XncDp'
??}(Z~
%ay`B?
B+*d&V
:s-\Zb
#bNfAg
l+sgZ9
bDU'7(
Yhp((b'
@gc6(G4C"
4ik{NI
;~9z`U
{MoeMFp
{:T;{,
H"vn\n
NhR@^o`
sox:Ti``
F2U?cJN
6n"JX9
ulP=G-
8v?PTB
)LKtr%
e&{bm\
R4m|Q:=
bsSLK2
Q/e94i
!?W!k@
e&j6dh1
V<Pi8pj
KQ]o2p6O
$}2C;_
Sg#B<;
GMiP1rM
g.&QXUZ>
3Qig|F8ub
h$F3_r
oj'4u4X
)oNG'\
D:1~kg
|q?&.Y
""?3@n6
"1/}.q
,Zdpc':
,G<KvTF
?I)&iG
R<$O7/
D9mAm@,Q
vGn`57
XMY1;@
>(~j[
Xm$xW"J
K/^^N^N
W]]2sz0q
1ls&;H
gpu,yz=
URYCUY
#A&4k65
SYqj!t5L
H^=:jn
z=#4[&
0:A7rB
:/y9+9c}
lChMV(
Antivirus Signature
Bkav W32.Common.C74CE111
Lionic Trojan.Win32.Fragtor.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.380111
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.PUP.wc
ALYac Gen:Variant.Fragtor.380111
Malwarebytes Generic.Malware.AI.DDS
VIPRE Gen:Variant.Fragtor.380111
Sangfor Adware.Win32.Neoreklami.Vzju
K7AntiVirus Clean
Alibaba AdWare:Win32/Neoreklami.95f3da13
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Adware.Neoreklami.NK
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan-Dropper.Win32.Agent.tfjkgu
BitDefender Gen:Variant.Fragtor.380111
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Win32:Evo-gen [Trj]
Tencent Clean
Emsisoft Gen:Variant.Fragtor.380111 (B)
F-Secure Adware.ADWARE/Neoreklami.ladef
DrWeb Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.moderate.ml.score
FireEye Gen:Variant.Fragtor.380111
Sophos Generic Reputation PUA (PUA)
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/AD.Nekark.zflss
MAX malware (ai score=81)
Antiy-AVL GrayWare[AdWare]/Win32.Neoreklami
Kingsoft Clean
Microsoft Program:Win32/Wacapew.C!ml
Gridinsoft Trojan.Win32.Generic.sa
Xcitium Clean
Arcabit Trojan.Fragtor.D5CCCF
ViRobot Clean
ZoneAlarm Trojan-Dropper.Win32.Agent.tfjkgu
GData Win32.Trojan.PSE.1QY8TTW
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!3111F8D446EF
TACHYON Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07JD23
Rising Trojan.Sdum!8.1155F (TFE:2:grN22HR5FJE)
Yandex Clean
Ikarus PUA.Neoreklami
MaxSecure Trojan.Malware.121218.susgen
Fortinet Adware/Neoreklami
BitDefenderTheta Gen:NN.ZexaF.36738.@Z0@a8yfG3di
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/grayware_confidence_100% (D)
No IRMA results available.