Static | ZeroBOX

PE Compile Time

2023-12-14 13:50:39

PDB Path

D:\东方 Visual Studio 2022\Mpclient\Release\Mpclient.pdb

PE Imphash

dcfee58a3d5f8da2a88f4ee7b3dcb6a3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00020a39 0x00020c00 6.62743189373
.rdata 0x00022000 0x0000c0e6 0x0000c200 5.21466288478
.data 0x0002f000 0x00001d04 0x00001000 3.34320549573
.rsrc 0x00031000 0x000000f8 0x00000200 2.53129810048
.reloc 0x00032000 0x00001b24 0x00001c00 6.42564759044

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00031060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x10022000 VirtualFree
0x10022004 VirtualAlloc
0x10022008 GetCurrentDirectoryA
0x1002200c Sleep
0x10022010 CopyFileA
0x10022014 FreeConsole
0x10022018 CreateThread
0x1002201c CreateFileW
0x10022020 CloseHandle
0x10022024 GetConsoleMode
0x10022028 WideCharToMultiByte
0x1002202c EnterCriticalSection
0x10022030 LeaveCriticalSection
0x10022038 DeleteCriticalSection
0x1002203c EncodePointer
0x10022040 DecodePointer
0x10022044 MultiByteToWideChar
0x10022048 LCMapStringEx
0x1002204c GetStringTypeW
0x10022050 GetCPInfo
0x10022060 GetCurrentProcess
0x10022064 TerminateProcess
0x1002206c GetCurrentProcessId
0x10022070 GetCurrentThreadId
0x10022078 InitializeSListHead
0x1002207c IsDebuggerPresent
0x10022080 GetStartupInfoW
0x10022084 GetModuleHandleW
0x10022088 RtlUnwind
0x1002208c RaiseException
0x10022090 InterlockedFlushSList
0x10022094 GetLastError
0x10022098 SetLastError
0x100220a0 TlsAlloc
0x100220a4 TlsGetValue
0x100220a8 TlsSetValue
0x100220ac TlsFree
0x100220b0 FreeLibrary
0x100220b4 GetProcAddress
0x100220b8 LoadLibraryExW
0x100220c0 ExitProcess
0x100220c4 GetModuleHandleExW
0x100220c8 GetModuleFileNameW
0x100220cc HeapAlloc
0x100220d0 HeapFree
0x100220d4 GetStdHandle
0x100220d8 GetFileType
0x100220dc CompareStringW
0x100220e0 LCMapStringW
0x100220e4 GetLocaleInfoW
0x100220e8 IsValidLocale
0x100220ec GetUserDefaultLCID
0x100220f0 EnumSystemLocalesW
0x100220f4 HeapReAlloc
0x100220f8 FindClose
0x100220fc FindFirstFileExW
0x10022100 FindNextFileW
0x10022104 IsValidCodePage
0x10022108 GetACP
0x1002210c GetOEMCP
0x10022110 GetCommandLineA
0x10022114 GetCommandLineW
0x10022118 GetEnvironmentStringsW
0x10022124 GetProcessHeap
0x10022128 SetFilePointerEx
0x1002212c SetStdHandle
0x10022130 HeapSize
0x10022134 FlushFileBuffers
0x10022138 WriteFile
0x1002213c GetConsoleOutputCP
0x10022140 WriteConsoleW
Library WININET.dll:
0x10022148 InternetOpenW
0x1002214c InternetOpenUrlA
0x10022150 InternetCloseHandle
0x10022154 InternetReadFile

Exports

Ordinal Address Name
1 0x10002d40 MpAddDynamicSignatureFile
2 0x10002d40 MpAllocMemory
3 0x10002d40 MpAmsiCloseSession
4 0x10002d40 MpAmsiNotify
5 0x10002d40 MpAmsiScan
6 0x10002d40 MpAsrSetHipsUserExclusion
7 0x10002d40 MpChangeCapability
8 0x10002d40 MpCheckAccessForClipboardOperation
9 0x10002d40 MpCheckAccessForClipboardOperationEx
10 0x10002d40 MpCheckAccessForClipboardOperationEx2
11 0x10002d40 MpCheckAccessForDragDropOperation
12 0x10002d40 MpCheckAccessForDragDropOperation2
13 0x10002d40 MpCheckAccessForPrintOperation
14 0x10002d40 MpCheckAccessForPrintOperation2
15 0x10002d40 MpCleanControl
16 0x10002d40 MpCleanOpen
17 0x10002d40 MpCleanPrecheckStart
18 0x10002d40 MpCleanStart
19 0x10002d40 MpClientUtilExportFunctions
20 0x10002d40 MpClose
21 0x10002d40 MpConfigClose
22 0x10002d40 MpConfigDelValue
23 0x10002d40 MpConfigGetValue
24 0x10002d40 MpConfigGetValueAlloc
25 0x10002d40 MpConfigInitialize
26 0x10002d40 MpConfigIteratorClose
27 0x10002d40 MpConfigIteratorEnum
28 0x10002d40 MpConfigIteratorEnumV2
29 0x10002d40 MpConfigIteratorOpen
30 0x10002d40 MpConfigOpen
31 0x10002d40 MpConfigQueryProtection
32 0x10002d40 MpConfigRefresh
33 0x10002d40 MpConfigRegisterForNotifications
34 0x10002d40 MpConfigSetValue
35 0x10002d40 MpConfigUninitialize
36 0x10002d40 MpConfigUnregisterNotifications
37 0x10002d40 MpConveyDlpBypass
38 0x10002d40 MpConveySampleSubmissionResult
39 0x10002d40 MpConveyUserChoiceForDlpNotification
40 0x10002d40 MpConveyUserChoiceForDlpNotificationEx
41 0x10002d40 MpConveyUserChoiceForSampleList
42 0x10002d40 MpCreateComInstance
43 0x10002d40 MpDbgAllocMemory
44 0x10002d40 MpDebugExportFunctions
45 0x10002d40 MpDefenderIsPrintAccessCheckNeeded
46 0x10002d40 MpDefenderPrintAccessCheck
47 0x10002d40 MpDefenderPrintDataProvide
48 0x10002d40 MpDelegateCopyFile
49 0x10002d40 MpDeleteAsrHistory
50 0x10002d40 MpDetectionEnumerate
51 0x10002d40 MpDetectionQuery
52 0x10002d40 MpDeviceControlAuthenticateNetworkShare
53 0x10002d40 MpDeviceControlValidateDataDuplicationRemoteLocationConfiguration
54 0x10002d40 MpDlpCheckAccessForBuffer
55 0x10002d40 MpDlpDelegateEnforcement
56 0x10002d40 MpDlpGetEvidenceFileUrl
57 0x10002d40 MpDlpGetOperationEnforcmentMode
58 0x10002d40 MpDlpInitializeEnforcementMode
59 0x10002d40 MpDlpNotifyCloseDocumentFile
60 0x10002d40 MpDlpNotifyPostOpenDocumentFile
61 0x10002d40 MpDlpNotifyPostSaveAsDocument
62 0x10002d40 MpDlpNotifyPostStartPrint
63 0x10002d40 MpDlpNotifyPreOpenDocumentFile
64 0x10002d40 MpDlpNotifyPrePrint
65 0x10002d40 MpDlpNotifyPreSaveAsDocument
66 0x10002d40 MpDynamicSignatureEnumerate
67 0x10002d40 MpDynamicSignatureOpen
68 0x10002d40 MpElevateCleanHandle
69 0x10002d40 MpElevationHandleAcquire
70 0x10002d40 MpElevationHandleActivate
71 0x10002d40 MpElevationHandleAttach
72 0x10002d40 MpElevationHandleOpen
73 0x10002d40 MpErrorMessageFormat
74 0x10002d40 MpFastMemoryScan
75 0x10002d40 MpFastMemoryScanOpen
76 0x10002d40 MpFlushLowfiCache
77 0x10002d40 MpForcedReboot
78 0x10002d40 MpFreeFileTrustExtraInfo
79 0x10002d40 MpFreeMemory
80 0x10002d40 MpFreeTSModeInfo
81 0x10002d40 MpGenerateSignature
82 0x10002d40 MpGenerateSignatureEx
83 0x10002d40 MpGenerateThreatReport
84 0x10002d40 MpGetASRPerRuleExclusions
85 0x10002d40 MpGetAsrBlockedActionInfos
86 0x10002d40 MpGetAsrBlockedActions
87 0x10002d40 MpGetAsrBlockedProcesses
88 0x10002d40 MpGetCallistoDetections
89 0x10002d40 MpGetCopyAcceleratorProcessStatus
90 0x10002d40 MpGetDevMode
91 0x10002d40 MpGetDeviceControlSecurityPolicies
92 0x10002d40 MpGetDeviceControlStatus
93 0x10002d40 MpGetDlpEvents
94 0x10002d40 MpGetEngineVersion
95 0x10002d40 MpGetFCValue
96 0x10002d40 MpGetHIPSRuleInfo
97 0x10002d40 MpGetMAPSConnectivityStatusInfo
98 0x10002d40 MpGetNpSupportFile
99 0x10002d40 MpGetRunningMode
100 0x10002d40 MpGetSACInfo
101 0x10002d40 MpGetSampleChunk
102 0x10002d40 MpGetSampleListRequiringConsent
103 0x10002d40 MpGetTDTFeatureStatus
104 0x10002d40 MpGetTDTFeatureStatusEx
105 0x10002d40 MpGetTPStateInfo
106 0x10002d40 MpGetTSModeInfo
107 0x10002d40 MpGetTaskSchedulerStrings
108 0x10002d40 MpGetThreatExecutionInfo
109 0x10002d40 MpHandleClose
110 0x10002d40 MpIsDeviceControlAvailable
111 0x10002d40 MpIsGivenRunningModeSupported
112 0x10002d40 MpIsRtpAutoEnable
113 0x10002d40 MpManagerDisable
114 0x10002d40 MpManagerEnable
115 0x10002d40 MpManagerOpen
116 0x10002d40 MpManagerStatusQuery
117 0x10002d40 MpManagerStatusQueryEx
118 0x10002d40 MpManagerVersionQuery
119 0x10002d40 MpManagerXBGMDisable
120 0x10002d40 MpManagerXBGMEnable
121 0x10002d40 MpMemoryScanStart
122 0x10002d40 MpNetworkCapture
123 0x10002d40 MpNotificationRegister
124 0x10002d40 MpOfflineScanInstall
125 0x10002d40 MpOfflineScanStatusQuery
126 0x10002d40 MpOpen
127 0x10002d40 MpProductGenuineCheck
128 0x10002d40 MpQuarantineRequest
129 0x10002d40 MpQueryDefaultFolderGuardList
130 0x10002d40 MpQueryEngineConfigDword
131 0x10002d40 MpQueryFileTrustByHandle
132 0x10002d40 MpQueryFileTrustByHandle2
133 0x10002d40 MpRemapCallistoDetections
134 0x10002d40 MpRemoveDynamicSignatureFile
135 0x10002d40 MpReportClipboardOwner
136 0x10002d40 MpRequestSnooze
137 0x10002d40 MpRollbackPlatform
138 0x10002d40 MpSampleQuery
139 0x10002d40 MpSampleSubmit
140 0x10002d40 MpScanControl
141 0x10002d40 MpScanResult
142 0x10002d40 MpScanStart
143 0x10002d40 MpScanStartEx
144 0x10002d40 MpSendBrowserHeartbeat
145 0x10002d40 MpServiceLogMessage
146 0x10002d40 MpSetBreakTheGlassStatus
147 0x10002d40 MpSetTPState
148 0x10002d40 MpSetUacElevationDefaultWindowHandle
149 0x10002d40 MpShowDlpDetailsDialog
150 0x10002d40 MpShutdownCopyAcceleratorProcess
151 0x10002d40 MpSmartLockerEnable
152 0x10002d40 MpTelemetryAddToAverageDWORD
153 0x10002d40 MpTelemetryAddToStreamDWORD
154 0x10002d40 MpTelemetryAddToStreamDWORD64
155 0x10002d40 MpTelemetryAddToStreamString
156 0x10002d40 MpTelemetryIncrementDWORD
157 0x10002d40 MpTelemetryInitialize
158 0x10002d40 MpTelemetryIsOptIn
159 0x10002d40 MpTelemetryLiteralAddToAverageDWORD
160 0x10002d40 MpTelemetryLiteralAddToStreamDWORD
161 0x10002d40 MpTelemetryLiteralAddToStreamDWORD64
162 0x10002d40 MpTelemetryLiteralAddToStreamString
163 0x10002d40 MpTelemetryLiteralIncrementDWORD
164 0x10002d40 MpTelemetryLiteralSetDWORD
165 0x10002d40 MpTelemetryLiteralSetDWORD64
166 0x10002d40 MpTelemetryLiteralSetIfMaxDWORD
167 0x10002d40 MpTelemetryLiteralSetIfMinDWORD
168 0x10002d40 MpTelemetryLiteralSetString
169 0x10002d40 MpTelemetrySetConsent
170 0x10002d40 MpTelemetrySetDWORD
171 0x10002d40 MpTelemetrySetDWORD64
172 0x10002d40 MpTelemetrySetIfMaxDWORD
173 0x10002d40 MpTelemetrySetIfMinDWORD
174 0x10002d40 MpTelemetrySetString
175 0x10002d40 MpTelemetryUninitialize
176 0x10002d40 MpTelemetryUpdateUserConsent
177 0x10002d40 MpTelemetryUpload
178 0x10002d40 MpThreatAction
179 0x10002d40 MpThreatEnumerate
180 0x10002d40 MpThreatHistoryRequest
181 0x10002d40 MpThreatLocalizedInfoQuery
182 0x10002d40 MpThreatOpen
183 0x10002d40 MpThreatQuery
184 0x10002d40 MpThreatRollup
185 0x10002d40 MpTriggerErrorHeartbeatReport
186 0x10002d40 MpTriggerHeartbeatOnUninstall
187 0x10002d40 MpTriggerStatusRefreshNotification
188 0x10002d40 MpUnblockEngine
189 0x10002d40 MpUnblockPlatform
190 0x10002d40 MpUnblockSignatures
191 0x10002d40 MpUpdateBrowserActiveTab
192 0x10002d40 MpUpdateControl
193 0x10002d40 MpUpdateDevMode
194 0x10002d40 MpUpdateEngine
195 0x10002d40 MpUpdatePlatform
196 0x10002d40 MpUpdateStart
197 0x10002d40 MpUpdateStartEx
198 0x10002d40 MpUpdateTSMode
199 0x10002d40 MpUpdateTSModeEx
200 0x10002d50 MpUtilsExportFunctions
201 0x10002d40 MpWDEnable
202 0x10002d40 MpXBGMEnable
203 0x10002d40 MpXBGMFreeEvent
204 0x10002d40 MpXBGMGetData
205 0x10002d40 MpXBGMPutData
206 0x10002d40 MpXBGMUpdateIV
207 0x10002d40 MputAddToAverageDWORD64Rpc
208 0x10002d40 MputAddToAverageDWORDRpc
209 0x10002d40 MputIncrementDWORD64Rpc
210 0x10002d40 MputIncrementDWORDRpc
211 0x10002d40 MputSetBoolRpc
212 0x10002d40 MputSetDWORD64Rpc
213 0x10002d40 MputSetDWORDRpc
214 0x10002d40 MputSetIfMaxDWORD64Rpc
215 0x10002d40 MputSetIfMaxDWORDRpc
216 0x10002d40 MputSetIfMinDWORD64Rpc
217 0x10002d40 MputSetIfMinDWORDRpc
218 0x10002d40 MputSetStringRpc
219 0x10002d40 WDEnable
220 0x10002d40 WDStatus
!This program cannot be run in DOS mode.
M8;Rich
`.rdata
@.data
@.reloc
T$$+T$
O8_^][Y
D$$j@P
D$$j@P
PPPPPWS
QQSVWd
URPQQh
UQPXY]Y[
PPPPPPPP
<ItC<Lt3<Tt#<h
A<lt'<tt
tb9^4~]
PRRRRR
ARPRQh
jYjf
uSSSSj
SWt@jU
_t^PVj@
u/j,Xf;
M,j"^QRRRRR
Vj0XPW
M$j"^QRRRRR
j"[VWWWW
[PVVVVV
j"[WVVVV
PVVVVV
_PSSSSS
j"_VSSSS
WVVVVV
PVSRSQV
PPPPPWV
PP9E uPPSWP
f9:t!V
C PjPW
C$PjQW
C*PjTW
C+PjUW
C,PjVW
C-PjWW
C.PjRW
C/PjSW
CHPjPW
CLPjQW
u{9^\t/
NX9^`t1
u2Vj@h0`
9C`u99C\t4
u29K\t-
WHPh@c
^PQQQQQ
E ^PQQQQ
CY<u
QQSVj8j@
PPPPPPPP
PVVVVV
bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
invalid stoul argument
stoul argument out of range
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
\mpclient.dll
invalid string position
vector too long
iostream stream error
RSDSoT
Visual Studio 2022\Mpclient\Release\Mpclient.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
Mpclient.dll
MpAddDynamicSignatureFile
MpAllocMemory
MpAmsiCloseSession
MpAmsiNotify
MpAmsiScan
MpAsrSetHipsUserExclusion
MpChangeCapability
MpCheckAccessForClipboardOperation
MpCheckAccessForClipboardOperationEx
MpCheckAccessForClipboardOperationEx2
MpCheckAccessForDragDropOperation
MpCheckAccessForDragDropOperation2
MpCheckAccessForPrintOperation
MpCheckAccessForPrintOperation2
MpCleanControl
MpCleanOpen
MpCleanPrecheckStart
MpCleanStart
MpClientUtilExportFunctions
MpClose
MpConfigClose
MpConfigDelValue
MpConfigGetValue
MpConfigGetValueAlloc
MpConfigInitialize
MpConfigIteratorClose
MpConfigIteratorEnum
MpConfigIteratorEnumV2
MpConfigIteratorOpen
MpConfigOpen
MpConfigQueryProtection
MpConfigRefresh
MpConfigRegisterForNotifications
MpConfigSetValue
MpConfigUninitialize
MpConfigUnregisterNotifications
MpConveyDlpBypass
MpConveySampleSubmissionResult
MpConveyUserChoiceForDlpNotification
MpConveyUserChoiceForDlpNotificationEx
MpConveyUserChoiceForSampleList
MpCreateComInstance
MpDbgAllocMemory
MpDebugExportFunctions
MpDefenderIsPrintAccessCheckNeeded
MpDefenderPrintAccessCheck
MpDefenderPrintDataProvide
MpDelegateCopyFile
MpDeleteAsrHistory
MpDetectionEnumerate
MpDetectionQuery
MpDeviceControlAuthenticateNetworkShare
MpDeviceControlValidateDataDuplicationRemoteLocationConfiguration
MpDlpCheckAccessForBuffer
MpDlpDelegateEnforcement
MpDlpGetEvidenceFileUrl
MpDlpGetOperationEnforcmentMode
MpDlpInitializeEnforcementMode
MpDlpNotifyCloseDocumentFile
MpDlpNotifyPostOpenDocumentFile
MpDlpNotifyPostSaveAsDocument
MpDlpNotifyPostStartPrint
MpDlpNotifyPreOpenDocumentFile
MpDlpNotifyPrePrint
MpDlpNotifyPreSaveAsDocument
MpDynamicSignatureEnumerate
MpDynamicSignatureOpen
MpElevateCleanHandle
MpElevationHandleAcquire
MpElevationHandleActivate
MpElevationHandleAttach
MpElevationHandleOpen
MpErrorMessageFormat
MpFastMemoryScan
MpFastMemoryScanOpen
MpFlushLowfiCache
MpForcedReboot
MpFreeFileTrustExtraInfo
MpFreeMemory
MpFreeTSModeInfo
MpGenerateSignature
MpGenerateSignatureEx
MpGenerateThreatReport
MpGetASRPerRuleExclusions
MpGetAsrBlockedActionInfos
MpGetAsrBlockedActions
MpGetAsrBlockedProcesses
MpGetCallistoDetections
MpGetCopyAcceleratorProcessStatus
MpGetDevMode
MpGetDeviceControlSecurityPolicies
MpGetDeviceControlStatus
MpGetDlpEvents
MpGetEngineVersion
MpGetFCValue
MpGetHIPSRuleInfo
MpGetMAPSConnectivityStatusInfo
MpGetNpSupportFile
MpGetRunningMode
MpGetSACInfo
MpGetSampleChunk
MpGetSampleListRequiringConsent
MpGetTDTFeatureStatus
MpGetTDTFeatureStatusEx
MpGetTPStateInfo
MpGetTSModeInfo
MpGetTaskSchedulerStrings
MpGetThreatExecutionInfo
MpHandleClose
MpIsDeviceControlAvailable
MpIsGivenRunningModeSupported
MpIsRtpAutoEnable
MpManagerDisable
MpManagerEnable
MpManagerOpen
MpManagerStatusQuery
MpManagerStatusQueryEx
MpManagerVersionQuery
MpManagerXBGMDisable
MpManagerXBGMEnable
MpMemoryScanStart
MpNetworkCapture
MpNotificationRegister
MpOfflineScanInstall
MpOfflineScanStatusQuery
MpOpen
MpProductGenuineCheck
MpQuarantineRequest
MpQueryDefaultFolderGuardList
MpQueryEngineConfigDword
MpQueryFileTrustByHandle
MpQueryFileTrustByHandle2
MpRemapCallistoDetections
MpRemoveDynamicSignatureFile
MpReportClipboardOwner
MpRequestSnooze
MpRollbackPlatform
MpSampleQuery
MpSampleSubmit
MpScanControl
MpScanResult
MpScanStart
MpScanStartEx
MpSendBrowserHeartbeat
MpServiceLogMessage
MpSetBreakTheGlassStatus
MpSetTPState
MpSetUacElevationDefaultWindowHandle
MpShowDlpDetailsDialog
MpShutdownCopyAcceleratorProcess
MpSmartLockerEnable
MpTelemetryAddToAverageDWORD
MpTelemetryAddToStreamDWORD
MpTelemetryAddToStreamDWORD64
MpTelemetryAddToStreamString
MpTelemetryIncrementDWORD
MpTelemetryInitialize
MpTelemetryIsOptIn
MpTelemetryLiteralAddToAverageDWORD
MpTelemetryLiteralAddToStreamDWORD
MpTelemetryLiteralAddToStreamDWORD64
MpTelemetryLiteralAddToStreamString
MpTelemetryLiteralIncrementDWORD
MpTelemetryLiteralSetDWORD
MpTelemetryLiteralSetDWORD64
MpTelemetryLiteralSetIfMaxDWORD
MpTelemetryLiteralSetIfMinDWORD
MpTelemetryLiteralSetString
MpTelemetrySetConsent
MpTelemetrySetDWORD
MpTelemetrySetDWORD64
MpTelemetrySetIfMaxDWORD
MpTelemetrySetIfMinDWORD
MpTelemetrySetString
MpTelemetryUninitialize
MpTelemetryUpdateUserConsent
MpTelemetryUpload
MpThreatAction
MpThreatEnumerate
MpThreatHistoryRequest
MpThreatLocalizedInfoQuery
MpThreatOpen
MpThreatQuery
MpThreatRollup
MpTriggerErrorHeartbeatReport
MpTriggerHeartbeatOnUninstall
MpTriggerStatusRefreshNotification
MpUnblockEngine
MpUnblockPlatform
MpUnblockSignatures
MpUpdateBrowserActiveTab
MpUpdateControl
MpUpdateDevMode
MpUpdateEngine
MpUpdatePlatform
MpUpdateStart
MpUpdateStartEx
MpUpdateTSMode
MpUpdateTSModeEx
MpUtilsExportFunctions
MpWDEnable
MpXBGMEnable
MpXBGMFreeEvent
MpXBGMGetData
MpXBGMPutData
MpXBGMUpdateIV
MputAddToAverageDWORD64Rpc
MputAddToAverageDWORDRpc
MputIncrementDWORD64Rpc
MputIncrementDWORDRpc
MputSetBoolRpc
MputSetDWORD64Rpc
MputSetDWORDRpc
MputSetIfMaxDWORD64Rpc
MputSetIfMaxDWORDRpc
MputSetIfMinDWORD64Rpc
MputSetIfMinDWORDRpc
MputSetStringRpc
WDEnable
WDStatus
VirtualFree
VirtualAlloc
GetCurrentDirectoryA
CopyFileA
FreeConsole
CreateThread
KERNEL32.dll
InternetOpenUrlA
InternetOpenW
InternetCloseHandle
InternetReadFile
WININET.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
GetStringTypeW
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwind
RaiseException
InterlockedFlushSList
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
QueryPerformanceFrequency
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
GetStdHandle
GetFileType
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetFilePointerEx
SetStdHandle
HeapSize
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
CloseHandle
CreateFileW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$numpunct@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AUctype_base@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
0#0/090E0Q0
262A2\2v2
5(6a6t6
868C8B9
9T:(;h<
>1>D>[>v>
5!5V5h5
808D8U8
=$=.=S=Y=
>6?C?b?|?
80878=8B8P8
9D9I9_9f9l9q9
:r:1;;;6<E<
1|1f7z7
<<8<><S<r<
= =6=g=
>D>\>o>
>D?U?\?d?z?
#0=0r0
1&1>1Y1d1
6.6>6D6K6R6x6
8%9Q9^9
9,:6:D:_:w:
<+=K=|=
>>4>I>P>V>h>r>
1&1;1D1s1|1
3"3.373<3B3L3V3f3v3
4 4(43484>4H4R4e4j4
4 5)50565<5H5k5~5J6c6m6
8X8p8u8|9
=$>7>U>c>
0H0O0T0X0\0`0
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;
>4>\>p>
>!>J>f>
?7?A?a?k?w?
0"0=0G0S0X0]0{0
0#131f1m1
2 20262E2R2[2k;s;y;
A0E0I0M0Q0U0Y0]0
1)505M5Q5U5Y5]5
=<>_>f>o>h?
8A9I9O9!?,?
9#:m:|:
:@;I;5=?=X=b=
1&212p2
2B3F3N3Z3w3
4&4?4D4p4
8.888_8i8
<C<R<d<w<
=@=G=f=
>9>N>^>k>
031g1r1|1
4c9i9{9
4?4Y4h4v4
5#515?5J5`5t5|5
9(9>9T9\9U=X>
M0X0h0
3S3Z3c3t3
4!4&464;4@4P4U4Z4j4o4t4
5525S5`5u5~5
7)737C7H7M7h7w7
828V8h8~8
:*:<:H:7;I;.<
7)80878>8K8
9 :N:_;X<
4.5I5S5
5)6H6k6
:A;J;N;T;X;^;b;l;
;&;8;J;\;
9D:_:H<
=B=I=P=s=
N4o4v4
4V5j5%6?6
232V2j2
3H3Z3d3
4#5J5i5%6U6o6
>%>.>|>
9!9)9G9O9
1-151E1V1
2 2,2;2N2m2
8&9C9`9}9
\1h1l1p1t1x1
2 2$2(2,2024282<2@2
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7
> >$>(>,>0>4>8><>@>D>H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0040<0@0D0H0L0P0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
X0`0h0l0p0t0x0|0
0X1`1d1h1l1p1t1x1|1
1H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
7 7$7(7,7074787<7@7D7
8$8,848<8D8L8T8\8d8l8t8p9t9x9|9
00<0H0T0`0l0x0
1 1,181D1P1\1h1t1
2(242@2L2X2d2p2|2
3$303@3L3X3d3p3|3
4$404<4H4,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6
J0N0R0V0
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;l;p;\<`<h<
>(>,><>@>D>H>P>h>x>|>
? ?0?4?<?T?d?h?x?|?
0$0(080<0T0X0\0`0d0x0|0
1,101H1L1d1h1
2 20242D2H2X2\2`2h2|2
3 3$3(3,30343<3T3X3p3
4,404H4L4P4T4X4\4`4d4h4l4
5 5$54585H5X5\5l5|5
64686P6T6l6p6t6|6
7 787H7L7T7X7\7d7|7
=(>L>T>\>d>l>t>|>
?$?D?L?T?\?d?l?x?
0$040<0H0P0h0p0x0
1 1@1L1l1t1|1
242D2P2p2x2
3(30383@3L3l3t3
4 4(40484<4@4H4\4d4x4
5 5X5x5
6(60646D6h6t6|6
7 7@7`7h7t7
9(9H9h9
:(:H:h:
;(;H;h;
<$<,<4<<<P<X<\<`<d<h<p<x<
1$1(14181h1x1
1044484<4p:x:
;@;`;|;
; <D<`<
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
140526000000Z
170624235959Z0`1
TAIWAN1
HSINCHU1
MEDIATEK INC.1
MEDIATEK INC.0
http://sf.symcb.com/sf.crl0f
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sf.symcd.com0&
http://sf.symcb.com/sf.crt0
R;cLE6
x;?+7U
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Code Verification Root0
110222192517Z
210222193517Z0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
,N<jPl
3BH8Q:|8
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
100208000000Z
200207235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0
[0Y0W0U
image/gif0!00
#http://logo.verisign.com/vslogo.gif04
#http://crl.verisign.com/pca3-g5.crl04
http://ocsp.verisign.com0
VeriSignMPKI-2-80
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
230714000000Z
341013235959Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20230
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
l2|X/gGe
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
231214045142Z0/
9<\wx5
Q6UOvy
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
mscoree.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Jaik.101379
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Rozena.Vdxq
K7AntiVirus Clean
BitDefender Gen:Variant.Jaik.101379
K7GW Clean
CrowdStrike Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 Win32/Rozena.BUF
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Rozena!8.6D (TFE:5:H0Bz8OO6O3T)
Sophos Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
FireEye Clean
Emsisoft Gen:Variant.Jaik.101379 (B)
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX malware (ai score=83)
Antiy-AVL Trojan/Win32.Rozena
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Malgent!MSR
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Gen:Variant.Jaik.101379
Varist Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 SigCompromised.MEDIATEKINC
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014H0DLE23
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.