Static | ZeroBOX

PE Compile Time

2014-05-12 05:03:33

PE Imphash

7ed0d71376e55d58ab36dc7d3ffda898

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005cf6 0x00005e00 6.44106605244
.rdata 0x00007000 0x00001354 0x00001400 5.03750274937
.data 0x00009000 0x00020298 0x00000600 3.65634232522
.ndata 0x0002a000 0x00020000 0x00000000 0.0
.rsrc 0x0004a000 0x000046d8 0x00004800 5.43534044373

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004d8b8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004d8b8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004d8b8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_DIALOG 0x0004e008 0x00000060 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004e008 0x00000060 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004e008 0x00000060 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004e008 0x00000060 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0004e068 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0004e098 0x00000338 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0004e3d0 0x00000305 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.dll:
0x407060 CompareFileTime
0x407064 SearchPathW
0x407068 SetFileTime
0x40706c CloseHandle
0x407070 GetShortPathNameW
0x407074 MoveFileW
0x40707c GetFileAttributesW
0x407080 GetLastError
0x407084 GetFullPathNameW
0x407088 CreateDirectoryW
0x40708c Sleep
0x407090 GetTickCount
0x407094 GetFileSize
0x407098 GetModuleFileNameW
0x40709c GetCurrentProcess
0x4070a0 CopyFileW
0x4070a4 ExitProcess
0x4070b0 GetTempPathW
0x4070b4 SetFileAttributesW
0x4070bc LoadLibraryW
0x4070c0 lstrlenW
0x4070c4 lstrcpynW
0x4070c8 GetDiskFreeSpaceW
0x4070cc GlobalUnlock
0x4070d0 GlobalLock
0x4070d4 CreateThread
0x4070d8 CreateProcessW
0x4070dc RemoveDirectoryW
0x4070e0 lstrcmpiA
0x4070e4 CreateFileW
0x4070e8 GetTempFileNameW
0x4070ec lstrcpyA
0x4070f0 lstrcpyW
0x4070f4 lstrcatW
0x4070f8 GetSystemDirectoryW
0x4070fc GetVersion
0x407100 GetProcAddress
0x407104 LoadLibraryA
0x407108 GetModuleHandleA
0x40710c GetModuleHandleW
0x407110 lstrcmpiW
0x407114 lstrcmpW
0x407118 WaitForSingleObject
0x40711c GlobalFree
0x407120 GlobalAlloc
0x407124 LoadLibraryExW
0x407128 GetExitCodeProcess
0x40712c FreeLibrary
0x407134 SetErrorMode
0x407138 GetCommandLineW
0x407140 FindFirstFileW
0x407144 FindNextFileW
0x407148 DeleteFileW
0x40714c SetFilePointer
0x407150 ReadFile
0x407154 FindClose
0x407158 MulDiv
0x40715c MultiByteToWideChar
0x407160 WriteFile
0x407164 lstrlenA
0x407168 WideCharToMultiByte
Library USER32.dll:
0x40718c EndDialog
0x407190 ScreenToClient
0x407194 GetWindowRect
0x407198 RegisterClassW
0x40719c EnableMenuItem
0x4071a0 GetSystemMenu
0x4071a4 SetClassLongW
0x4071a8 IsWindowEnabled
0x4071ac SetWindowPos
0x4071b0 GetSysColor
0x4071b4 GetWindowLongW
0x4071b8 SetCursor
0x4071bc LoadCursorW
0x4071c0 CheckDlgButton
0x4071c4 GetMessagePos
0x4071c8 LoadBitmapW
0x4071cc CallWindowProcW
0x4071d0 IsWindowVisible
0x4071d4 CloseClipboard
0x4071d8 SetClipboardData
0x4071dc wsprintfW
0x4071e0 CreateWindowExW
0x4071e8 AppendMenuW
0x4071ec CreatePopupMenu
0x4071f0 GetSystemMetrics
0x4071f4 SetDlgItemTextW
0x4071f8 GetDlgItemTextW
0x4071fc MessageBoxIndirectW
0x407200 CharPrevW
0x407204 CharNextA
0x407208 wsprintfA
0x40720c DispatchMessageW
0x407210 PeekMessageW
0x407214 ReleaseDC
0x407218 EnableWindow
0x40721c InvalidateRect
0x407220 SendMessageW
0x407224 DefWindowProcW
0x407228 BeginPaint
0x40722c GetClientRect
0x407230 FillRect
0x407234 DrawTextW
0x407238 GetClassInfoW
0x40723c DialogBoxParamW
0x407240 CharNextW
0x407244 ExitWindowsEx
0x407248 DestroyWindow
0x40724c CreateDialogParamW
0x407250 SetTimer
0x407254 SetWindowTextW
0x407258 PostQuitMessage
0x40725c GetDC
0x407260 SetWindowLongW
0x407264 LoadImageW
0x407268 SendMessageTimeoutW
0x40726c FindWindowExW
0x407270 EmptyClipboard
0x407274 OpenClipboard
0x407278 TrackPopupMenu
0x40727c EndPaint
0x407280 ShowWindow
0x407284 GetDlgItem
0x407288 IsWindow
0x40728c SetForegroundWindow
Library GDI32.dll:
0x40703c SelectObject
0x407040 SetBkMode
0x407044 CreateFontIndirectW
0x407048 SetTextColor
0x40704c DeleteObject
0x407050 GetDeviceCaps
0x407054 CreateBrushIndirect
0x407058 SetBkColor
Library SHELL32.dll:
0x407178 SHBrowseForFolderW
0x40717c SHGetFileInfoW
0x407180 ShellExecuteW
0x407184 SHFileOperationW
Library ADVAPI32.dll:
0x407000 RegCloseKey
0x407004 RegOpenKeyExW
0x407008 RegDeleteKeyW
0x40700c RegDeleteValueW
0x407010 RegEnumValueW
0x407014 RegCreateKeyExW
0x407018 RegSetValueExW
0x40701c RegQueryValueExW
0x407020 RegEnumKeyW
Library COMCTL32.dll:
0x407028 ImageList_Create
0x40702c ImageList_AddMasked
0x407030 ImageList_Destroy
0x407034 None
Library ole32.dll:
0x4072a4 CoCreateInstance
0x4072a8 CoTaskMemFree
0x4072ac OleInitialize
0x4072b0 OleUninitialize
Library VERSION.dll:
0x407298 GetFileVersionInfoW
0x40729c VerQueryValueW

!This program cannot be run in DOS mode.
*jRichu
`.rdata
@.data
.ndata
SQSSSPW
Instu`
softuW
NulluN
SUVWj 3
@j"@^f
D$$Ph0
D$(UPU
WSWh`s@
D$$+D$
D$,+D$$P
PPPPPP
\u f9O
90u'AAf
MulDiv
DeleteFileW
FindFirstFileW
FindNextFileW
FindClose
SetFilePointer
ReadFile
MultiByteToWideChar
WriteFile
lstrlenA
WideCharToMultiByte
GetPrivateProfileStringW
WritePrivateProfileStringW
FreeLibrary
LoadLibraryExW
GetModuleHandleW
GetExitCodeProcess
WaitForSingleObject
GlobalAlloc
GlobalFree
ExpandEnvironmentStringsW
lstrcmpW
lstrcmpiW
CloseHandle
SetFileTime
CompareFileTime
SearchPathW
GetShortPathNameW
GetFullPathNameW
MoveFileW
SetCurrentDirectoryW
GetFileAttributesW
GetLastError
CreateDirectoryW
SetFileAttributesW
GetTickCount
GetFileSize
GetModuleFileNameW
GetCurrentProcess
CopyFileW
ExitProcess
SetEnvironmentVariableW
GetWindowsDirectoryW
GetTempPathW
GetCommandLineW
SetErrorMode
LoadLibraryW
lstrlenW
lstrcpynW
GetDiskFreeSpaceW
GlobalUnlock
GlobalLock
CreateThread
CreateProcessW
RemoveDirectoryW
lstrcmpiA
CreateFileW
GetTempFileNameW
lstrcpyA
lstrcpyW
lstrcatW
GetSystemDirectoryW
GetVersion
GetProcAddress
LoadLibraryA
GetModuleHandleA
KERNEL32.dll
EndPaint
DrawTextW
FillRect
GetClientRect
BeginPaint
DefWindowProcW
SendMessageW
InvalidateRect
EnableWindow
ReleaseDC
LoadImageW
SetWindowLongW
GetDlgItem
IsWindow
FindWindowExW
SendMessageTimeoutW
wsprintfW
ShowWindow
SetForegroundWindow
PostQuitMessage
SetWindowTextW
SetTimer
CreateDialogParamW
DestroyWindow
ExitWindowsEx
CharNextW
DialogBoxParamW
GetClassInfoW
CreateWindowExW
SystemParametersInfoW
RegisterClassW
EndDialog
ScreenToClient
GetWindowRect
EnableMenuItem
GetSystemMenu
SetClassLongW
IsWindowEnabled
SetWindowPos
GetSysColor
GetWindowLongW
SetCursor
LoadCursorW
CheckDlgButton
GetMessagePos
LoadBitmapW
CallWindowProcW
IsWindowVisible
CloseClipboard
SetClipboardData
EmptyClipboard
OpenClipboard
TrackPopupMenu
AppendMenuW
CreatePopupMenu
GetSystemMetrics
SetDlgItemTextW
GetDlgItemTextW
MessageBoxIndirectW
CharPrevW
CharNextA
wsprintfA
DispatchMessageW
PeekMessageW
USER32.dll
SelectObject
SetTextColor
SetBkMode
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
GetDeviceCaps
SetBkColor
GDI32.dll
SHFileOperationW
ShellExecuteW
SHGetFileInfoW
SHBrowseForFolderW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
SHELL32.dll
RegEnumValueW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCreateKeyExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
RegOpenKeyExW
ADVAPI32.dll
ImageList_Destroy
ImageList_AddMasked
ImageList_Create
COMCTL32.dll
CoCreateInstance
OleUninitialize
OleInitialize
CoTaskMemFree
ole32.dll
VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
VERSION.dll
SHGetFolderPathW
SHFOLDER
SHAutoComplete
SHLWAPI
GetUserDefaultUILanguage
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegDeleteKeyExW
ADVAPI32
MoveFileExW
GetDiskFreeSpaceExW
KERNEL32
[Rename]
%ls=%ls
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v3.0b0</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/></application></compatibility></assembly>
NullsoftInst
C6(+V?
Jza@yu
"0#?,n
Re[+;Zz
_VC82W
[J61ng<5
[$W)#()
lXx?bO
h$A0il0
"^f]m2
~$Jx;cG
wRq4j6
Upr!V1
vov,HWl
PqP6Y
L(k}7Z
#iUSxV
S;[|uh
=l!=7"
c&!HSn
GU)Z@S
"@hew,U
8kQ0pU
{^:=lS
XW0,}Z
\Z/ab<
t,~<dP
%OF#n"!
n2~O_Y1
+^CR{F
^z.YVU`
vk#H*4
,/`3"U
a:0Y(T
o{J4]N
a?T~/ei
*\T'K~
P.S9z94
A5:DF4=R
'taYQm
"pOQY:P
y|AhUq
c6dL++A
n_N&9o
XlAwyw
PUvCVB
l-G=l%
{1rONQ
}p#*n%]
<5\kG` 4n
x4UdY^
_dnwjd?
'tAT/};
?A~]hy
A+[tKh
W1U)+S
W5&u/\k0
{7X3oP|
,BUq7'
K~frp2|
E9d?ze^y
V{Xr|
wQu"4[
-IWUM6
~N+uj
bFHQMX
pi8k7V
Yi !O:xj"^
02a,19y
,7<6H5
y@x@+n
<=CvAQ
gt2+0p
C({]_/
Y<Q0w-
W+t4gS
-ElL@5
&2G{m=
_'2P8f
{=\6Vg
xrC#v2
m|;zCe~
e>L+^xEe
nyAFCTD7
`%L>UR
fZn,NI(
|M=3[~
`I`fzf
k1JQo1
-JNAL)
GHK7D
pqh5-w}
+MT<E^~
:}sBag]
K~Ts^
u\)_@CG
;\*jo(#
D!S3;EV
upy8n
0E.d9j5
U,^#<~?
-}Ne*R
A-6*F!;u
~~_GG
?[>T%
/Q#si>;B
NZ~Tnq
Ne3;OL
$<k5&?f
oOzut<
]Iq;?
`9P}bE
d.!v \C&=cd
g/?/I[N
p0Q;Oy
vQ<g&yqG
#7{u?Q
@\-sgo
}G)[9k0
J%@c-z
~T4SqS
5@_]o*@Q>
!FThqB
It-:AK
_xHS7W
c4_*@[
n)E%~A:
V(Gw1L
&["g+Fq|#
Aa>JWGbt{
HdOX+`
?8)~]lL"
>e FDFI
^ys7hv
:e$667
GXgc.=
q2rE!zUgm
*g K"
2qRvtr
pG)KIJ
D4&r06
3Mh;1oV$
v<M1E/
@Bck(iYI
L$&A`cs
7C\!n9
Pbb3h?
B'ZM]H
:i_b %:
i'B/,WdN
"{c3eh
eR9a7@
hB6@UI
JS&KF[
n'lR/g[
pY:t]9
`B=KY-F
<8:};=
D\Ey+K
#*RCTA
WT,9qx
@Y=YKH
J)r.w:&Q
ee`K'/
LWn5;*@
`*7[TQ
uv$[]0
0wa7M^
=}\<Ici7
9&!YeFi
}tbPQt
%UH0gP?t
|TDJj"\FJ
XVeJWL
G?|@[],
Lv`m/n<
3Rk[N=
:8G}A(
}s4;Z[
6L=.lPwo
N;SSz[
Ir7O!eG
;"G\:w"g
!ldKoc1.O
,=HFn8
a8V1#d
F~W`05
{)+*&<
A]#VxoxR
Xk"tY-
w;qZ%<
APF,EH1
X~JpI`g
&.9Be
GoSJUGg
+!H6f*
Kc\i?+
bqN|k;
H|r'}9
{{nzFC%6e
32":Xz
u]@|$[
3HNG(B
b}\V4b
#|t36:
yxjD$Q
Ye8o='
r7+BY]b?X
2=)%7v
Xz[DbN
Um3X{na=
bqbr8zQ
?F]pqTW
_D,KG[
EUt 9CK
B<}MUI
.X9kA
X<P$ua
7sU'FZ
N;8flWGC
1;yYTg
pUY#f$
_Bb)t$
|Bj,J<
\BW}c~w
!e_R"#
S0uqX&?
E1$k8_
,y//fl
HL|kAwy
Od=k11M
T50%g+Blw
ixpxs%
j<'$M`
HTAxc"
8Hl]RH
-+H,0
+KN(]
NE33_}
&78OS7
:G86C|
Wn@s4'
#hw.g8b
n:cveX
2sIR:P
Jma!iQhk
p.yl&@
hgp[4K
@q4Y$3
R|GoJ?h
e0oUEvFI
NKDvw
Uagr$~
TN9K../
BMo8R (c
"tTs- V
H2)p[wFa
uGAmg-I
~s4\<?(
z9`-yO
FV|t=\zx
_btwK3^
>=*UUZ0
-5Y:pQ
<iHBM
Tm9~.%F
1N]&v2\NB
d9rgO?
*6*z+G
4'dYd}
%7NR'\k
P""`6_7
lWDn|*K#
"=[bu63
~f&;h+Xw=
]DXHs{i
_-MccTpS
ZB8[;RB
hH67-l
ctM#c
!KP:30&
;>%E(Q
hW>}+t
Ji_XAJRA
EZVr[C
=_c_}R$
(Vi}+;"
5W{anlG
.L`l|R
9i*Uv4
j3>z,2
(Hj4fxg
q!wl0n
g|L|<h,
)tWO`}
X -igNO
c,i11i
X^p@Lz,
0A!1#V
+f]x,
%{P2:_Vm
PMN-%&
ZFK-)J
JX~<Er
|&.oTt
b|9:2r
Dqq$MU
*fi*ftO^
c>``oX/
.olcXoR]
~W"_%V
bcHgJnw>?
1KT{<E
49`6}Vc
uM9i:v
OOAVBa
%fu~6\
"aBud@
&<i)8K*
`@s\bb|8y1
3S=m:['jIG
anORb`a
nkIHOAOJ5
]ujgsV
q\-&,2(j
1GV3 >
*S7-P#
n5Qq7;#?
"h9VaH
E%fJ5@
~((16*
/\_v4/
.yC]g
1<#hQfv
?$,lR2
IH-I!HQ
7(@a|YP
_)rH6PM
oq7jO^
7'2RSQu
0SpP`f
@K-.#.
(y3(%_
N~uT"K
?dKPd8([
if~[j*
H^gLr
9is!e,
O+H$f2
PiQdQ(Q
+-`$V)
vtO! i
7bgEo"
fzyMD'<c
zdV{2z
1`pL3:
b>r^qM
;mRK=r
_K~Krc\
,7)tE
r"m60@
'cU-X(
~SZsiB
a*ql>x
C|]Hh%`IO"
1W9vw}m
fr48Z7
,:YU4
\9WcEAK
`]_|F^
*J%c%{"=;_U
~h-R&L
{1gMw!
i!GSMC+
&#2]Rs}
Mxpi%,
n}1^ct
$l{m8.*'
HalbK1
?Gpm}
-;P$Fy
%Lw4$)*I
m3)/Y!
P~I)H}
?bC{l|x~6]5
P<|#z11s
rsCE=
/dnP&]'
'd]}o(
YK?Nlh
6FSH~z
?")5ShR
TO?x0D+
;Wta~f
pk_1Bhd
k|Sq':
a?!C3\
1|%EFMn
t*a&#
bv7*X%
A2-a:m
u'?SXoi5-
vHT\Jf
=ThF %
(_'TQD
tlj,ON
'bK@vm
q"%?~z
b}}HI+
wY+W]S
=zj}a
ZG\2if
=(iTIA`
D;>|Iq
`^p23Bx>\s
x"]1Yo
U[-)MC
d[oF,S
b 8o^5
"be\+C
sjZhu=
!O-j@P
V,l &3NrV\
f}C#a>
8X^.Z#)ju
I?]ILGj
!Ca?C
xgXm~w
I<PKMDj
":Sxt;
So[.%2;9
zC@/'|
0j(86!
3cz.~*
gY4}ey
q2xp%S
WP44gzHr
lT/qz^
OE}%UF
Wnow8V.
o^0^pL
lX9]Y)"
1RH8>lg
o*g Im
&k4qP=G
!&A8a>
t@]r#24ddG
~ [X_`Y
f&8W3
\7g.X/PJ;O
25Ja"fMW
mY.P`?X
5+D8J"SZR
_7NjH[G
vbR}'=AJ
',FO*K
*b,36W
Xp9Hvc
~pB"zL
lAlmLK\
(QZ&n
ZX{$zY
f;RCa<
s1a{zf
DM)cWI
{.G>z{l
;[eZ7(cl
+V\VHL
Fd|LJY
x]ZH&H
a?Huq8Y-
D[5i/337
n;` J:
lRmwz#
Gy^7E(
K>_9X(
8xK"|'Zc
:|YUln
}0m{b(
&_:n36P<
(,AdN0
a!>1I9B
88DaQm
,k_e>zm
P%v43X
*"Bve
>`/cPab
-W[0*U
B,vsGD
&6v1L-
P#@t{MHJ
H-N9Rf`
zPm|GMc
/Twg{%
:hw|8R
x3iQ1Z
9nhF~e
ZNO?z!
MJZKDy)h
9Lr^_u
(_z+80
\)SuY|
6ke`#=
+p?XjO
$d!r<n_
`UHYI#
{e=Z7t
^5l#Q
e:iXj{
I-&}{R)_Z
F:c=hS
7:1$m.
`NdcSC
H6|(Qj
.(@cxN
twXw(x
+fNqn?
=uuK`Rl
]y_Y|^
,jh|qW
VJ=Ws!
E.v'hLC
7}Y/l&
93kv7+
[EP-1
rfigt&@.
G}SP<N3
=iq6'A
@q:a"Qg
>;!KtbX
m3>Y$QA
1s)j^V
8wame40
H:LTq;
6v&DeOb
boY'<D
p$]z[n
<Fs*+f
\:^G&^(
i1t=^&@
f^vASL
scqzbzVp@
j$)%n:=
LlSRU^tX
7i(yzQ
p{}nZ}
o,gNf{=EY%
5Oz5 c
UY!LB*
;IYF'S
eS4;t=GO
P^]mUo6:pT
u?Hz7s
:hXp*O
gl;#m3
m1zZ-~&
L8<Fd
{%e{eJ
Wk%Bse
rFA!U?(Z
0q9ufo)
HINH`r
5nSJC.
9Q'8Di
Z7A;Tk
-fKq?|
Mp2&Plj^M
#^>H.$
5~T2QE
*Sm;2@
D^HqK
'fk_JU
+3a*VNr
2.U["U-
5re7A_
R-&<I4
)~5M'k
>d@t;P
#;.$e*
U*~~7G
<\nPcW
(*RdCo7
e;"K@;;
DDu]Lh1
JFG /V
9,|A6]
:"xG2n
Kv}Be|_
4zo5f?4As
gu@jJG
$J2#Guk
_mY$nN
*p=J>4
di<3`"
`uOS7
cXxSz-V-
SZNLj%
9q15j"8
q'5obz
1y!^2n;
&JNZp<K
t.w3^c
IYjMc
g&WY44
~6b_zkv
i)mdM7
^F2O6{'
`'E$aO
?Ipbp{
|y)mO0
D0az6
fU<W?s
*OgO*f
`)6<'-m3
/ka=(.
#]3,y_
IOz<J+U
Piypx=']
eifhgi
Xx'Q) Yzy
x7C/u%
)CQ?Vg
rDycfo
mU?i7\
/r9l(W&
U*6X]S_
]ik_F8''
im8a0Rtc
][IzV\M
!7kIs~
wqW#hw
NFeP=3!5
`2X]!W
4]8iHt
y6+_$o
Isy-t}
'YjhLg
4VJrii_
5v{.|6
X[hK{!
#);Q7w
>'=2'e
ah&*sBkU
)dScuD
)4bws>
DgxFcnD
*S7^`<d@
`0w?.?
;5+OdY
"NFF7bg
a%Zh\7m
oUPDg|
Sgk!T0
e?6Mg[
~4EG<[
8c;if)Z
Y>66T+)"
#VG[8z
rY$a}&
{H}ewc
=zTe7G
)OgI"%q
uX*6i@
Bym['I
J>>hzo
kze|GO
,ws^!^e
"!bXb+~
l^L9Z}
vNc4la
B(Y_$
(Cuj]ep%d=
pmw%;^\5
S=uTs^
[<<;Pi7
X`[LJJ
f0Z#8}oW
Q6Awe8
DeR\p8t
^l}.n8{
DId%{C
(?St,1
*q;!(2z
/\kSR
M'.nMn
R<Yo\!
HN4"bp
4z=ab*
'TT1Kot
!:=o1w
;zw4C-a
V}_A8<sNf
~dLJJ4
$%P][Q
{!q{<g
G~#y$"
gcwHV>
.9io[@(
\\JfE=
GDw-i'
yXU7Y*BF
B{U,XN{
I1hLm<
gnQ~<^\
06|}(Q
8kd.7c;
q+x"Ge<
If8l"~
%xS7Ft$
VEDN"iocf#
W8!U'y
F-ef!9
1`~\zz
}cYF}2h
E%CME"
RJI;vv
ql7A=t
`n=`3N
FV"mp,
Fq0@A\
F43SD5
0 o@l1
cr6}p1
|`lkPz
(@i<F3
`kK/&e
PM8Fwm
7X8}LM
3V/#ue13
QO"~1^
VJ{kSCw
<Rjl1'
"W<xf~
:h'DT7
d3!o>8
8g37y1
Wm)WAO
s!SMUX
2BS[z3
_!#K3<f
3E/2Ho
^4[O&Y?
G^8yM4
PpJ v't
k* <?&j
! \3v`
{pT$e
4Qf%*:
@*/<AR
vvFQRW
VfQx.N
%NgyVf
et#%])
/`l5Sn
6S'\\hR+
*:64~Q
S2qgH"c\oZ
Z?v~^$
}N~y9t:
<nO#^%
F@hGdH/
TWJ;'/Rvd
"!4g|~
N\2~FZ
LM0Oc<<
[ez Re
X49iJU
uJUIT7
cni>Lf
.:h![=L/X
8?JGmy!
X&^ 9UQ
;tSb}\
qTL>$"
C4i$"j
r{H{q^oL
\49PQ.
hCoGo4
E$*]&n
E(%DCGl`
RJ@4Di*
)H%b@u
E5P?@-
~1k4r4
mAvj"#
MSreXe_
)%0c#]I
pFZq2kph
FneKCx
6"y,&j
S7!'S}/
6'Qv'V
rCbJ=/
32cH6!
s<q8oQ
B9]eE.
jE2w#
A+K4l!
08Vmrz
%-D&:1
.1p5.\
S6.YVB}
[iA>z/F
0ns;Ib
-|KL]h
X=0*En
@5Ud]h
&z-IjZ
Y?)3v[k
`L.yS8
VfHaxR"
@t8zdoIQ
$1}>Jki
'dU*{D
k@ 4JU
c<qC(A
=+-d3C
Llqx)e
eI5O9D
/NXaK
fh\8s=
M/c:!S@
E?V`s#
"Dn!$*
u1Fnmm
)cXef&8c
^gw&H7J
?2p]/S
5]Nv#]7
c]F@3~
e'RJ{1C
>\Go{HDm
}%>(ip
,MmD{v
aW)-*VP
'|>7AGq
mECbyZ
c*m:~ufL
4*E( R#r@
_s=gfMC
NBoDPg1
yTqJJ<O
h5Gc"f
nzn?)m
wWz/+{u
C_Zis0
OA;+9|
'TV*eF
eG)3oT
y&M|RnD
L\v3+x
V7 b3yb
NU{IIog
<W0M^aw@
!gjd@N
|b^aE@o1
x_2DJ[
kb0Ra>k
3F{ow%
I,(5Gq
cc>p8j%
:W6;N~
#imDry
v.!>7OT
?Y5Q-<
'T)[-*x
xX,B5+`q
?D$5T1
XfmW9v
3maJoh
Tj=n-(h
R-3W6@mc.
2*Kvr:
q3K4=#
V'iFv@g&>f
v'\fK0
EL,D6=2
YV*DB"
;-)2%)\
cK_8Wl!
I*$e3b
Wv?O{F
,H(lC+
!dp/8]
-LN;X=
w[.Cke
>n~Y_D
zZ9D6x
YU3L[<
y*I=.r
p2)R/+
8ZzwYl
", %:B,
EtzB<P
HLY"]
D\n qj
z_?AB}
N(>OPH
A/EFF9
$Ok}jNg
+9wXWMpT(
vApGaA
R[pU)D
%jSlf{s9Y
Q9~s0f
B[5]U{
TrCkq07
=o*3;O
&4h&6k
t(dM<c
PJOY,
nD!4^1
Vo83Bt\\
KO[&lu
+93TW)
IcN,h@Gj
(v|)Wl"
_29+Mx
G#hHjT
qY"Q3Kf
SZ5-:)
ls'+l}
-K/'vf
$f~\`
sKgvMbF
FAey9~c8
z>\!(z
[/@cf]
ebOSvC
IEHK/4
$Bq`a(
vJTNL74
{%6c|h
|4.Co6
n;g{#^
lo@FQ&,
W9Fv_A
JF=m#lO
uU\${Q^
*35v^+
L=i7az
CfOrf.4
NO0SeC&
>8LO)e+
*#D8>G
s#7[Q8
B(J>&;
=z$+GB!
2iaHJ]
J7C%[U
:LOypW
Z%=/|2!
KE$j"n
f(6Ip5W
'[/aH-
H1%"dF0i
t/F<0:
?\PDMd\1
1WnM:e
wHva7O
w"IeYX
a5mYbJ68
yIE?^-*
+!IBl)
cq0~*)
t]p.9#
&SdMXfe
+TFCpK
H(pqW
l~S73n7r?
$D$z.IC
tE/RLb<ta_
FrNsy6
';Jxk4
=''X];
uAt8WJ
ScU&=[
I"6jg1frR
M8` P3#
PXP'z22W
;%X%&piWND
_nb'_f
1~hJI_
7'6+,kxn
<Tg6$h
tf/E45
DkU'j?
p'H\lQ
Y2v''2
ln F]J
6jz'n?
S,qd[Rg
-}jtGD]
wKN]b"q
N&3AID
((bn(PjP-d
?xl2a|
6QTNSB
y+.yEv
[[?k$-
[_4@aPio
U+$kYf
BOb @A
dj*DS#
nX.gwcc
0p-gE
\r&! 3dkXW
l;DpZ<n(2
3K<BWh
#:e)|
:U_O;>c$B
FjPmB\
\5(9`)
V>uEtZ
J%!eut
9E|-vP
+)UkBn
tc`|[,HF
%|u^jj
p!uspH
#BHwA
v0"bp
y uf-WJnI
i;4G^=
XEW2$]I
dDP!9_
7:cNaW
qm2l);
+iZr+v
{d-!56
$Mv*!e
Y+gQ@~4J
zIO(:w
Yt/}B,
l@U(hy
\:-V2,
Lmb..a&
Iqwm>6
=vtoi#
RdzGZU
L_QH=)@FF]
a}$YR
4%b6+E=
K4E{po
{u"Ot*)
RVb$r/
hetES_oj
Ogg-lX
32#DH-
h9gm;J
dNLl91
VauaL-*
+]6I_N
vo4N3>o
7QlyPO}~9
T\csy>
+/OO3a
(kNz.%
RVZ^12
tQR}WOJ
:m`2X0
7Tl8%*
yoJ2^w
r9Fmae
p{i$c"
Gh8R,:
s$-3o\
ZDIedC
foiP!]`
6e?/x'
b_8^{d_
^l!p%A
uYg;&F
!rr$~d
DeNk:&
fzO75Cu=
Nno-\u1
MXel]~1
R9pUhN
v0dMsGB
5Vjs\So
F(l2hj
]v@\4|
su:_i
"gJ_Yj]
MEL`P+e
\:xRIG
uQ%}G&
#$0Crk
unBLT6
{O,l3H
j>q;AU
w!Bun7y^};d
@3abxA
~6]i<R
L"@?KP!
~sG#_}m
kU!reN
x9Cp4=
t` aC[hd
)ClVQr
|UvS^c
XCXvvz
MNf.X_
k!--)+
!v HkL
<PmMLHZ
_&@rj+L@
GosR*&HA
EWr"^%
Pdo=1x/
Z2bE6 z
+v_+g+
KTn=D{`
1QrVBh1
CIxDC2
T?b:"OR
+$E7no
Z/%t&G/
[tqM7+
ll>H"8
!>5%D_
rx:TOCe:B
3f%M@i
VEXT!\*f
!R}5tM
uB>2@vH
NQqcB
'EC*lJ
y4~jj>#
i1&*))
26#su'e#'
gD[-@(G
U#x6bZ"
M3en ~
p,u.>[l
":FauNdb
bH_!d$p
}kAcM|
U2Lg>j
"harE}
txz"_e
(9jQY
zTQ0@i
`y:a`h
=pJ."{
$cL~w@
3*{gK:F
s"L-q{^
iYbmO%
UH;hXe
sMhGeI!
O&&%dC
YO~&:+
B5J*#3j
9cU06IW
N.4oD+
'@dYB\
~FlPZqS
|tHKQ\
MP: "_
o9a]S}P
(|yYqpO
a5|/K{
u0x))t
Po2ZN9
gX:#}.V
/`|=+Yl$
:h&63X
nsI&{[
sy{GyE
(T4K!u+p
.W"P`r
clv]H~J{
TC3fS`
K #O`(
II)c:R
z=o;T_A
vn`H{|
Na2 mk
J6MCcv
OGg(j}r
FIRQan
Em4/1JL?
U^kHW.
_opXV~
#wo&uU0
k*:bD~1i
i5YQ1)
P!.?owa
%i5h-N
WR6Gch
1kbme9OuZ
#NjtiJTa
E-szpp5
smHOtb@
2<S9vELO
yg>fKOW
_{BAH`
NTeh%_s
z(m&q>
"rz1D.
nLZpn
'fw#J]
x4=$uP>
:cO{:YrXZSi
36}&yE
f<pA3]%
Qus~KO
OxGU8GQk
5+A\b[G]k-
imw9-H
"dpMy-
nL+e9X
l(IUh[Hf
p9;.(,
<Xa`/T
t^=h:
4hzP#'
I$4@Xjy
AD0`Rn
P"BnkcD
30aU0{
7.0'Iv0
L{E:1r
(3FQkz;
ruM p
(&3SE
~S@d`
thQUm].
B&P{{J
;3/4eo
W7F;/G
CaV3/7^
wZtfw5!
bZ2cfwv
`XZ&m>\Uz
ubfN*K
\4;)GBe
K$4\1
|oye~_4P
La|CCN
3,L<LfG
cS(9qj
Tm Vtq
q>e+.
zWHUw^`}}zJ
ki;+,3
w'_{:7
7jR3.7
x:@#YU
cQ#YYM
YaQ.M
Q"/[p
g3L,$
^#"!IeoM
]P{>j(
/$p"74-
I^7D\:]
|3<pp<
|Nf<F+
e?PBvy
%8KLy;
UP++ou
VwT<X;B3
n9`DIbT
im*{cn
Wn=tv<
mi+oE&
Y%,<yV
;}p*`'
-7;sG#
75=I2f
\&c8/}
jTkBFf
`g<Oz,_
R9<H{@
%WvI{K
DPOl8e
25qnEl
PV3]U(
V^bu&Yf4
_H(-zj/
aC1.f.
T^LEEft
$bJq*2
fh&\oc
GoC3RLh
JdbW*w
PR(pcq
Q8poLd
nK7n;w
XWd$yhyy
DpX+|(B?
ZWN,B!
$R.hp>8
ON))?H
xRQmB M
KwhsMe
wIADcz
Zk@uta
\N={^{
m$9<j:z
S;=/0n
~%T)9N
p7=5Wz
rZWz*Aq
p,DMA.
`PkQ{[D m
c>[Eg
v7-#1q%
GgQV\#[F
aS${%Q
2>['Qh?
Eqx<[z
/L}Yr-
&oCoU4
)TO CO
hsxH~g
9E/C)`
`WVb3D
44p^Jh
*D6^"q 1
jciw"4
q3?o/ k
V[E&Iuu
0"}Qk&J
>pDJ[l
#SgGLe
af7`X-6
de}I{R
KmTY:t9U
D)\`0<
,=)'<=
T@@nf\
-t/e,J
,N7\vG
mc k#'
;wO|#P
]yHR5Z
8qBb&t]_+
\,g)8?
*_I#&WW
R0S0TF1
Poh-@T
l<Iwoiv
$K *gR
`,o_5Q
sBOW+U
ch> fxer
z@qznMk
.`iz*a
XasbkS!
?W{PLY)
Fm"yl9
^</M2e
!VGSym
nv/~v1
9Y{pb[8;8
cbB.sP
H @1xq+|
*/S?TwD
$6$lx%
gDS#JT
*s`q.C
m; U+SBt
nQ"z30
}A4E!t
Gq@0H12
lhjOnEd
N8g(4ZoW
p]=f+<c
u7)FoA
ka(#"K
/wV->(
Uj/]a"<
R+g[Sr
u7}M8Ij
n[x~H*nTJ
5<SDh7
)RqB$%
n05Tb@?
G>Xx1T
A5?]3I
G*b67P
(mKTsI
`+ZN!6k
xSD<a*
NcGb}
xE,2"i;
}sw(RG
D.zuRN
I6"0]#X
oS*eH0,
sVXX[?
.m ?V@*
zB+kYY
tlW'cF
r;b%h
v Z<eXTB
cX73dyhC
YwPVI's
'k=ad8
5B@H- ;
sc0z}[
WI)&?a
kS#{\[
~T<A'h
c~drx|*
%tPz!v
s-^A(^
<&eV5Z
%r1Z^Z
/gH&f0
`J4Dh7
LAs1_m
,Q?DQJSy5
VI{nud
!>mtJUC
a>[-pOw
'xv} 4
U fB~u
egL9:N
$fe1_|)
k:}I?Wf
FRN-=W
%eOkrf
V_7W^E
#?AS ewfX
+t|H5B"
N\!<rw
QGXH~0
'^Q" a5H
M4@nYU
2ptjI<
ISN)gV
Ni,B=H
V >RE7=
<hYd[F
USwav'`
RTh8{~V
,GY"\'
0i9O<l1KGuKSd
DG}\<.
mSB-,1$
5( ( U
1(*GCY^T
yLOnjy
;uCMP8
=iNL+1
s,cypl(a
qo;igJ
t6':7&
b[v/U:
u.G?3jT*
5T^rDh
L/S4AP
H/[~u~%
qdeTSx
qFD#?Y
Bc47W`
`s 2D
g1Rh"*
26QA*.[;
RL$XIYXq
"PMu7
>b@L|CJ
]KXh `
kn>G_^7
_jGIUf
w/z}bwS
=4cf`tf
i3g"Uw
i%XKu{
yT<%<f
&|/nLz
qQ?NJ
7hJv5.
H-$Ch)
k^|;t6S
mn,L&8
j~=Po7
?Q9+s]"#*
VhG7 "
tV\sT{
q~-tT9WxL
WPNpg0
I7jI!e
Il( yMQ
,+AU|^
9A.KuMs9
wb]6d F
45?j!BF
X$i`<?
()O7(P
4jt{v_
V}%a%JhR
\!V^fa^
0FUJy'u
-Jlq~^Q
7(B\V7
<?!?CHz
}}VX?+
:U6WKM'u_qM
e3:T.Z
U'<rKO
6dl/}5
ugdU@*9w
=It'&7
SY59%G
n]/J98)
*.0zH!c
(k!|$o22
Jjh1M`(
W>},|-U
Qo\E('
I$3Sq
}&UVo^
lSw,1e
@.:j.ub
FC'$jF3
P))(+G
fh'-l
Tzeh'5i
!-sFT9j|
a4~\gs
DMK%fC?vi
sxmCZ"
avGDa?
Yh6_R7
t0yPDS*
Clinton1
Sanser1
Sanser1503
,Restprodukts Pedestaling tilstaaelsessagens 1&0$
Toreadorernes@Emends.Ho0
231030111226Z
261029111226Z0
Clinton1
Sanser1
Sanser1503
,Restprodukts Pedestaling tilstaaelsessagens 1&0$
Toreadorernes@Emends.Ho0
HY:e?p
Clinton1
Sanser1
Sanser1503
,Restprodukts Pedestaling tilstaaelsessagens 1&0$
Toreadorernes@Emends.Ho
20231206202746Z0
PL1!0
Asseco Data Systems S.A.1
Certum Timestamp 2023
PL1!0
Asseco Data Systems S.A.1$0"
Certum Timestamping 2021 CA0
231102083223Z
341030083223Z0P1
PL1!0
Asseco Data Systems S.A.1
Certum Timestamp 20230
"http://crl.certum.pl/ctsca2021.crl0o
http://subca.ocsp-certum.com05
)http://repository.certum.pl/ctsca2021.cer0A
https://www.certum.pl/CPS0
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1$0"
Certum Trusted Network CA 20
210519053207Z
360518053207Z0V1
PL1!0
Asseco Data Systems S.A.1$0"
Certum Timestamping 2021 CA0
http://crl.certum.pl/ctnca2.crl0l
http://subca.ocsp-certum.com02
&http://repository.certum.pl/ctnca2.cer09
http://www.certum.pl/CPS0
iMi=}B
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1"0
Certum Trusted Network CA0
210531064306Z
290917064306Z0
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1$0"
Certum Trusted Network CA 20
cyD~Kc$
.4?)LR
http://crl.certum.pl/ctnca.crl0k
http://subca.ocsp-certum.com01
%http://repository.certum.pl/ctnca.cer09
http://www.certum.pl/CPS0
[.&iB<
PL1!0
Asseco Data Systems S.A.1$0"
Certum Timestamping 2021 CA
231206202746Z07
/1(0&0$0"
PL1!0
Asseco Data Systems S.A.1$0"
Certum Timestamping 2021 CA
RichEdit
RichEdit20W
RichEd32
RichEd20
.DEFAULT\Control Panel\International
Control Panel\Desktop\ResourceLocale
Software\Microsoft\Windows\CurrentVersion
\Microsoft\Internet Explorer\Quick Launch
verifying installer: %d%%
Installer integrity check has failed. Common causes include
incomplete download and damaged media. Contact the
installer's author to obtain a new copy.
More information at:
http://nsis.sf.net/NSIS_Error
Error launching installer
... %d%%
SeShutdownPrivilege
~nsu.tmp
NSIS Error
Error writing temporary file. Make sure your temp folder is valid.
%u.%u%s%s
*?|<>/":
MS Shell Dlg
MS Shell Dlg
msctls_progress32
SysListView32
MS Shell Dlg
MS Shell Dlg
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
arachnidium estus
FileDescription
konformitets semiromantic
InternalName
pemmican.exe
LegalCopyright
univac opiumvalmuernes prrierne
LegalTrademarks
skkens gananciales outwaiting
OriginalFilename
pemmican.exe
ProductName
mellemgangens pilgrimwise virksomhedsledelsen
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.GuLoader.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.70716086
FireEye Trojan.GenericKD.70716086
CAT-QuickHeal Clean
Skyhigh RDN/genericv
ALYac Trojan.GenericKD.70716086
Malwarebytes Trojan.GuLoader
Zillya Clean
Sangfor Trojan.Win32.Injector.Vao2
K7AntiVirus Clean
BitDefender Trojan.GenericKD.70716086
K7GW Clean
Cybereason Clean
Arcabit Trojan.Generic.D4370AB6
Baidu Clean
VirIT Clean
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 NSIS/Injector.ASH
Cynet Malicious (score: 99)
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Makoob.gen
Alibaba Trojan:Win32/Makoob.bc15459c
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.FalseSign.Ywhl
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Injector.ubpnj
DrWeb Clean
VIPRE Trojan.GenericKD.70716086
TrendMicro Trojan.Win32.GULOADER.YXDLIZ
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.70716086 (B)
Ikarus Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/ABRisk.OBQB-3952
Avira TR/Injector.ubpnj
Antiy-AVL Trojan/NSIS.Injector
Kingsoft Win32.Troj.Generic.v
Gridinsoft Clean
Xcitium Malware@#3k2ruk0vd7drb
Microsoft Trojan:Win32/GuLoader.KTTQ!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Makoob.gen
GData Trojan.GenericKD.70716086
Google Detected
AhnLab-V3 Trojan/Win.GuLoader.C5560244
Acronis Clean
McAfee RDN/genericv
MAX malware (ai score=83)
DeepInstinct MALICIOUS
VBA32 Trojan.Makoob
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.GULOADER.YXDLIZ
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet NSIS/Injector.C8D5!tr
BitDefenderTheta Clean
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.