Static | ZeroBOX

PE Compile Time

2012-02-05 07:43:24

PE Imphash

6058ac660564f64af764bdf1e4fe5d2b

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0007c000 0x00000000 0.0
UPX1 0x0007d000 0x0004b000 0x0004aa00 7.94096585609
.rsrc 0x000c8000 0x00008000 0x00007400 5.91181513522

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000c1b28 0x0000004e LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_DIALOG 0x000c1b78 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000cec2c 0x0000019c LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000cedcc 0x0000026c LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x4cf18c LoadLibraryA
0x4cf190 GetProcAddress
0x4cf194 VirtualProtect
0x4cf198 VirtualAlloc
0x4cf19c VirtualFree
0x4cf1a0 ExitProcess
Library ADVAPI32.dll:
0x4cf1a8 GetAce
Library COMCTL32.dll:
0x4cf1b0 ImageList_Remove
Library COMDLG32.dll:
0x4cf1b8 GetSaveFileNameW
Library GDI32.dll:
0x4cf1c0 LineTo
Library MPR.dll:
0x4cf1c8 WNetUseConnectionW
Library ole32.dll:
0x4cf1d0 CoInitialize
Library OLEAUT32.dll:
0x4cf1d8 SysFreeString
Library PSAPI.DLL:
0x4cf1e0 EnumProcesses
Library SHELL32.dll:
0x4cf1e8 DragFinish
Library USER32.dll:
0x4cf1f0 GetDC
Library USERENV.dll:
0x4cf1f8 LoadUserProfileW
Library VERSION.dll:
0x4cf200 VerQueryValueW
Library WININET.dll:
0x4cf208 FtpOpenFileW
Library WINMM.dll:
0x4cf210 timeGetTime
Library WSOCK32.dll:
0x4cf218 recv

!This program cannot be run in DOS mode.
Tdev+S
cdS?t>b
-HxV4
\f4x`N
{f@bjd
'ph[`i<
zx|YdCq
RZv!r!>
C0-!Zc
tPCWPMk
{r5o+",
j_!RP*
vxiUDpb
U50)83T*
TN(:HL
2$EDFDHVn?*
.(),02
Z.GH@m
,pgD5.
?P*Phl
<*(0D48w9y
15CGTX\c*
0d88&<<
5`+h \
x|8h8s
PTjptrRY
49=83@p[X
PZlptr
rRDHL;
4ZTX`&
<<PT\r
\N*@DH
l2t;x1
\*PXLp
=r<1@D
$(0AZc
RyX|lpx&d<
648rRY
r\%x|\N.
B((1,0
LPplp9
ri,04<
D$(DoIe
F&+<@.'
^N.8<@G
>HHH0Ws
H(8><
I$0p<@
]X1\d
MW M$.'
5TX`H
c@1DH2r
K,4dLP.
sXXpt|
81<@\n
{$',PD
e0P@xh.
TFZ)QQQ
\n1\`)
5h;p&t
[jRRRcl*#
/7104S?8
<`Rd;l&
5R8/H/R2p
[HS1|r9y
TTT!R)
TUXU`2
W1 W$*
Z,V0V[
fWT*OyW&
Xl$(0
TX\z!H7
<\\`\R
|3DHXh
T3X\d.
L@PT5\s
(p)t3x
` `(,IN*+
Ddhewr
`t$4T
S.(`5|
5 a$(0
r8b<b\%`
r\`dlC.
t748<D
K0Tt_jp
T4@4PS
4@(WEQ
"p6L.nCVP
pDjX|/
70HHHp#G
mFoyNT
JJ+J.
il2*@,W
Q*Q1Qxe8
tS^ujy
T$,4`}
6bPb]ba
'6.Vatg
[#$(,0
C^W,"0-h
r9lptx
HLP]/\
+]:SZG
[@`Zj_{
u*V|#3
yY;j$&
u4wA}6
W.#^d)
$ldQ$P7
b,,P((t~
q7&b?0
jc`Kb
Txtplu
PONKJcB
J!``.J
]Sj Z~
8_WJba
/^0Ma_
=,g|.i
*T] h(
A<[_<X:
O9!<Uv
SWEB!
h^f9-b
^Gjz-uJ
zhtN!u
woVW@9
uV tO
9u(vEVS
F)71J@]
8&g8lS
9H*Wt!
)9MY"tQ
>"!SS";
{@*?_ kX
AZ6"dec
fv`Mo$V
jBFZejb
jHhpr!
"jAua<
tv:# y
" R\]gnMi
@K`B#
|tld\/
w<x-B^
h}xxQ0
}>v`~p0g&
EYS[(T7
jo8u1.
F-?Ht-?
]~W$\7C
@~20Fv
'X. vCX939u
VEY!V!Q
W\)jAo74
oxx]xv
lh\6Xa>
i.Ksi.o%u
=w|Jt~(At
{.R7C
>8d0Xf
<;f99t6C;]D
t-SDR4
#<9w"L
.i/C%V
j@j ^V?
kE~<0L0
qGF`Z&
dH0;oa
an_ItU
i*Mx&X
"N?tu\q
fbAi+M
- 9} 7}
_/9>t
[[DSW1
w|k?8t
r9B[U(LT
(I\$IK
q_SAp=H
Qhda 
l.2S'"+
AVWPAuI[@
@Sj"\YTD)
zpRB.\t
Jaj\YFI
$(rrrr,04
\9999`dhl9999ptx|
`@eDH$
v4;5\V
f$L8`fB
ipLt$\
_ESvP{
;er 8^
YTX%a!*Fv
F67Dat
@R8]>s
tj.<N)
UQPXY]Y[l
h)a.KC4
WAq8!k
&*-K&@YpY
^g,YY
v!}#O+
R&=llg
P H,}&
*A-|3\
]FNc'i|
y$c~@#
)y.BiU
V@P8RZ
wAk0V[
ac2Mu7
TNP/)w
2>`0V-
!K{s$R
Y'J Pl
Y$"@>GJ
ABatk1
Fa'z2c
TPQR;O
pduf@,{
/Y8|Zi
PHQ!n~:
SRWn0u,
M&Sb7u
tKq]=r
H40`!h
bn` PK
^j pH)
{bwlt=
*zI^r8
`a+eLMq
D<Bn[DQH
rRDP/GX<
$,(|Qx
H*9MsA8
0PKt>@
U:`5GD
UfVF1
(JB5$D
/HY2@^^
zd}I2;
XnWyD@
o767ni-
Io&a(o^
;W;4T-
t5q|-i
!!,\Fp
(yyN1:1
:$z&<$
KPR\SQ
dwhV5Bb}9p
)^dFA;
1|<\uEF
Pj5C%SpeSQu#gA
{jq!7`
vCCR0r
RZ~D
qLeH#4
d<`+M\
!9B"eHk
xlF%52zO
@jXC~}
w<@0;xr
%kFeW#p
T;VLuq
&8mN PX&
l`51P"C
x=it [
p>ccO
dthWp]k
&{j\7.
j*P3.3
O(B>=)&
F&V(RW
_PYp:P')b
Vx>4>u.
lpd1t"/
+9*" ;t
CiG.pt
Dx(fX03![H$LQ*
#SDv0%
DGHuANJ`]
8crtsgtM
H6E$8VD~)
VZB@ba6
7T=c!M
.Mf=+A
dW8[_I
eW:F2[
0SR/P@p;
gL8=`&
Z8PBqe
WFeKIA
RSjIDEGW
xC4Ji)
0C/mV3
@p2<.2
=ERCPt
E(: .h
Dl+Ghp
9Z(MOPhH
Y92v/*
~9&NHQ
U`tm*lFT
F%OJ-0y
4{9NHc
,G}OBZ
WXt8|,
_F)l(~
LC![bMK6
->|( m!;3
&?T\+Y
;@VR^b
/ .ti%
Af}jah
Q`>(0g
=2zHa?n%
#cr"qR
JWu91
c[Pa'c
81Qmt2
zo%A_eKKiK
 !"##$%&'(
)**+,-./K00123456
5>?@ABCDEF
`t29t :t
R"e7Sr
#KJ!|
+~<+^@
UIZ@Br
h68*H;
El>hBaU
k-9Hva
/(mp`7d
B% 2(0
4v0h'2
FL@VCX
BtI:XO
`NNn#P
42Hg'@#
FkRI}
"@Ce+
Y?PbjR
]Q4YJp,
-i"T`d
5#'Kw3
f5zQu7xmA&u
K]rpDZ
VN,QR,0
~1VC3S
jtdy.
ch.JAU
hQzD|Qf
HYnm*
FM^AVV
8|UR40
B9s u-P
jarfwHV
~& \%i
.N(Qh3
+dB.1"+
(t|<"tx<%tt<'tp
l<&th<!td<ot`
\<[tX<\tT<
_'rn{_C(u
5@PC`)
9TQ!"p
'<T$QI
6BIK04,5mK
C1H28u
h)p^\68
y*S,@H
q6h`JV+p
k!^!%8
$},{8,
L5UPNK
'RPQu2@
h[t,&r
*7#JG(
>My)jGQ
xs$Cuf
V&GFw01O
${F$d
>kwo/
8ElQk:
(pL=#u
heLOPi
D:4P]a
Y/6Hr5
Ka~?uB
tRJt6J,
LYu*=!
0v#b?H
%CDk(f
G(Lhz2~
-`v`R]
H#Li_RVJl
!QP8WY
M]"xQRn
[h$c.Ss
)W"SqQ`
)a%_mU
4Mk*$$
nWQh!\
W 0s5hY
,N,j)e
,Vw04G4M)
9r~ V0
)siZg6_
PytMh\
oM!L@z#
N<I@*g
]P|&@
brPKSa6
4$d:$%3
R|MtI8
id]x0t
=]'X=A
)"v0p!
JDt@;Sa
BDlakica
O qi(d
Hk-P{3}
4<?3{u
zK@Fr'
``V\'K
Zp]u53
-`V\z\
$+^{-Z
]/!_.
G?EsU$
JHt\)
Jr;Q},Db
_t*]t%
i7`t 8sV
@>Pf&A
Ld^}^}
EY]qE/k
I)*+B77
;i<:rK
n(cF,|
W`+lMM3p
4<>t
y9M(tH
pE7G]|S=
-Rr<2aB
WpK2M;{Rp
a4UM`$
!HRN[:
$RUu!
pU2aH_
Vq@~PM
if`j dQ
37iB**>
Q5&.ib
i8JX0 _
i488<<@B
lfJ80FW
HLPTX\O0
Ehr<;
w_@Z{F
-?u5[rG^/}$
t+i*{$
fJXeQT
"`M0^zE2PKa
F4oQK
t4~d^~,
m}hBX8
uZzj\z
+A4;rU
BD=8/F
W0q3*^
~!APQ
88`u}l
KmGFg'S
,,m8H4
l9e|M|
#H1Q+/
[C0=su
_up&K
6\#v</
..VA{<
W05ROl
JE X>C59f
5h}jX}$
>`E->V,e?
>%YwgSJW
=$DnDK
I0IbgB6
~a@ga@
[Xh(G~0u
%gh,#USG
tqm_$P
2@b6DP
]N.-!h
CT1x7|
q,(@-X-
[F,JG\
C9P<t>
eWr%o&
19t5mA(<(m
J7Q2IN
NoD$y
RSPVWV0
}@V#<]
QRIC{*
H&~G<+u
VQ!EN0
*9TGlF
=B~$]\
)'V)Pp
`S(d^RFD
vO1S7)
5t.,*P
j.J ,P
'0rM(x\8
a$vaaQAe
3Rtonnnn
rtjAt^atYStMnnnnstHHt<ht7Nt+hnnnnt&Ot
9rYPyK
fU:uK
l=^QUyIM~
\CJ$]f2
vA@'9S
a g_GQy
QZDQw<
Xp"a)"l#Q
J7RQ_U
RI/R$|
t->@foJb
hP98v-[U
$@@"|p.
{/2F6tu,
iTRWR[B
g%!GH]
%2!f|N
B`hC4R,
,TN>@&
v7;V8R&4#LF
,LszN`i2>
0-#.vE
KSjb#.
5IS:8;
$| usG
X#WS2X
S'I,--*{
!hL(XMk
/Dk08$
<>kDe2k
4PPsrr
3 $8<X1!
+8U-^Aad
t$0WPQJK
AM7PFH
o,)Uz
SWO=H#
RAO<=`
aTX,ty1
k@<DF:
H,*yF
U`*(<)P
$`Dunq
ux-5i"
IwFxcj
^ @+[yRRM
V=A"F;W
>L| /S
N|?Q7C
uKl<+}
{?j~
V'T3?@ib
{P{M[O
Vh=L+\
RW4\a4
NVRWba
tNc2>&&X#
/T$dR
+V9\ueF\IZ)E|
iV:E(d
@D`q#u.f
^Z#DWQn<yR
)-$#S<
t%^TfD
$jhxIc
V%QQws
171}$[S-<
5@HEmCy
i&40<@
YhQ6T=Ae`
W q:~V-Z
*HQD:A6
0SVQoS
,5XlC;y
7hd2_H
t{P/WI
N9>~$d
[CX>H&
A6q+cb+5+_HS
~r08@R
\/{u.:m;
IUhNh3
Xl7U20x'U
k)vRC:g
mmY8hRV
AX5Gr$
$`"tZ3Ie
PH%X_XG|
K`h3Fp88
!$yH,h
Cv4$Ex
t-;RFj
~BLPfJ
2k'/8
)1t5)S;P
Bx(=I*}
*-~mS0>
6(Db8O
y^$<4VM
Tejd`u
Jp)$uG=
sL$HDA
>|ok/S
r0iNTR"
Vp6Ki\
u7a\ `
Ht2Hub
PZ;(TX,K
tk+1mM
:-9ycA:
=!C''$^
7JbBN[h
F>RsX'
$`:i#yF^D
m!_ois
\~Kt<s
QQBBFJ
9(tIFEAB'
G2gpZk6{xvZ
h5e8K\
JR8p8>Cj2
3~a@CG
CJ^z~g1
)er1\e
->$""?m
*g[AQ_
V, ^m`
Q+`!j
P\[Zuh)
$$>)ttX
P?=#@f
^APIV.
x+AREV
$sMJPh$8f_P"
jr@GL=/!;
R>cSP>
@tY%5r
)tH({\
?$F5CB
?Ao!g-v+
'<wbR3
j1@AG4
ppC-{m
`/Y;Nt5
P/ $!])
8+u gi!x
u@:/)rB
*OxBQM,
E}*RR1"
b?>@Gp
ad allocation8CorExitPr"es
{Unknown exvp
///#&P
u6dcGZ
TZCs'W
oBgS>
FH:mm:*
SR)Augus
}k$s'Wed
:e)IJKLMNO
FTUVWXYZ[\]^_`abcdefghij
8vwxyz{S
t'7 c =
?i3>l{
m*sSk
+FVfwS5
px<y z
5FPQ 8PX
_nextaft`_lo
>%_hypot
Apld?<0O
5ptzo6
\5JD#jcUTF-_
16LQUNICODE_j
<8bunz8
l,kg<i
^@En[vP
D>V:e:
3\@L4
ZEM-'^
o~l$G~
^\sY0:Rp
@~7Z8>
fe')lW
P\?T@*J
|u?!u$
"9>>?.
Prr?=?
@N.>?>
dd>?>@F&
@F&??>dd
dJ???@F&
bu?P/Y
_p2rr
}N@ O
]vQ<)8h
74>U".
[|)P!?Ua0
y1~?|"
?x+s7
k>? #J
v=o;:8o''
76431
Nno0.-+vr;
o*)'&o
$#! '
~~}o|n'''|{z?yNNNNyxwv
ovutt999
?srqqrrr;pooon
vm?llk
g?gfe''
ddocbbNNn'a?`__
NN^]o]\9
[Z?ZYr;99XWWoV
vrrUUT?S
MLKJoJ
?5Od%
n{;7W
?|I7Z#
pg)([|X>H1
AxuN}*
r7Yr7]D
&?~YK|
:]=O>\
CqTR;?b
1WY$?]
?#%X.yo
Ge/Windo}
.UserObjectInform1Wf
A0iveP
ageBoxbU
i9_/T|
7W$gNRE\
@UQLy5
`~A%My
< Complete
lor'[Class H
ierJy Descrip=
BeIArFy'';
c threxgu
nXru!it2
ex. deKf
BGinBi
c;`eh %W
allsig
N}?| x
ir(jdis
0TosdB
/efaul
XdGpa-
\XTPLH<
<D@<84
21#QNAN
'LRIs\
emaXjv
t@ahitg:lV
qA7OJTW
^x:c'e
.dRIsT
R~wI6cs
8kernel32
alWGb,
luginD
w s:&*/
;&cmO7 ;
ByG//q
OVG{a{
?s?ZP{8g
:2?1M+db
N1RzIK_
B.876B.
8''''7654Sc''32
CCEPOMMIT
KI~HE\
Anyrdc
n~iaZv
BrZl<B8
vOuhid
_Abori8l&r
erokelC
~JT>Pah
=:MBdpWL
VietmX
"bundspb
word*G
of p\n&c)j
recognZa0
P<~ {} qu
|3'| K to
bpty A7
POSIX
`t(s) P
@c gaP
> 255v
Gbcu6@
PTy"xW`
, 32As
DEFINEone0
Sgt.Dd4
GBZGCC
02Xk#13W!W
2H/gXl
>,MC{7o
mms7s
`wG?\$
_G/w6b
?O3{2V
SbsU/i
':/YR{
KkR7WE
-Og?D
//RoR#-]
]-K?G>
/37jmMJ
MOOD(Z
b-#GX!
/OU'';
VVh[pG
VAgG{:q1
B(Qc%S
~{XsM:
)~LXw%
M}XW?E
{sg^bW
uO2pCD
ST&xOS
Z #W1m
ICMP.DLL
cmpCQF
'g{;d=b
m'g?#X
$6B:6p
advapi
.?2hw]
OZ{Hg
Vt! (l-
yQ\Z{0,Wi
?NO_START_Ol
<lXH4,
p\L8~$;
I7/!5A
CPgR/S
l/mV p;y
Ixx@o
dP8 yO
Qkkbal
<xl`TH
lP8 <O
$--%"!'
lrFO/f
VRspLsmov^
j .E6H
~ OADgZ
i*t7",
L]WY'FO
R\O1Y%
zaIZXQ
W4ForS
G(Heap7J
oepACur
Id&MulDiv
DeWide
tiByH(l
FlushBul
lp32S:phoZE$!
St4CY/
#!etdm
amPi(O
^acZ)%VV$
mjoC^pTdO
|la@I1
E`AiAddT
junTok
Shut<n=
]pn?)
`A9Arc
W,Task
&tYSH`
ycSn'v
py'MaA0
|,Eg_No
Sub%CR
dTGmH1
kUBT;u
Y(q+uC
rp0Xpd
`[d!Visi
/0g\u$s
XPTPSW
wwwwpw
wxxwxw
wwxwxx
wtdpew
t$gvgfBG
gG@xwwp
@edgvw
dtvv~w
||vtd w
e$gFvwxw
edFDdT`E
wxvF`x
wxpvG@
xaxwex
xxvGge(
wfggwf`w
wwpwww
wwwwwwpw
tggggCx
Tdtv~|vtt%
xxxxxvB
pvGxwxxtvt
xxvvw(
wwwgww
u!!#Ca
j^[[[[^j
rG277@71Dq
-<LNz|
|zN=<&
*<=Nxz
zzNL-#
&-LLNQ|
'///111
t0NQz{
]R;UUu
^!!! !C]
uuqk^SS^kquu
}GA!7
$_wwq^q
uqvwwwwwuq
+anm:$
&_essd4$
t>}b/Z
EEEb>>>
EEEf777
>>>;===
>>>;<<<
===6;;;
EEEy@@@
FFFnRRR
>>>;SSS
@@@Eccc
???Ckkk
@@@Eqqq
===5ttt
===8aaa
>>>:666
NNNCWWW
HHHCRRR
UUUqwww
QQQqSSS
UUUpxxx
VVV,aaa
IIIB___
}}}/iii
eeeu}}}
hhhwxxx
kkkIddd
[?){^D(
TA2rD1!
fRAfbH/
yhYmsf[
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
GetAce
ImageList_Remove
GetSaveFileNameW
LineTo
WNetUseConnectionW
CoInitialize
EnumProcesses
DragFinish
LoadUserProfileW
VerQueryValueW
FtpOpenFileW
timeGetTime
H}AU3!EA06
!w,ekC
lB)7SM
lAU3!EA06
VS_VERSION_INFO
StringFileInfo
080904b0
FileDescription
FileVersion
3, 3, 9, 0
CompiledScript
AutoIt v3 Script: 3, 3, 9, 0
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Autoit.4!c
tehtris Clean
ClamAV Win.Malware.Generic-6651791-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.AutoitDropper.fc
ALYac Trojan.GenericKD.66127804
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Packed.V2uk
K7AntiVirus Trojan ( 005631b11 )
Alibaba Packed:Win32/YahLover.5a21e6a4
K7GW Trojan ( 005631b11 )
Cybereason malicious.3701c4
Baidu Clean
VirIT Trojan.Win32.Generic.XTX
Symantec Trojan.Gen.2
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Packed.Autoit.NBT suspicious
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.66127804
NANO-Antivirus Clean
ViRobot Trojan.Win32.A.Agent.690283[UPX]
MicroWorld-eScan Trojan.GenericKD.66127804
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.Siggen5.59949
VIPRE Trojan.GenericKD.66127804
TrendMicro TROJ_GEN.R03BC0PFC24
McAfeeD ti!ACD89E772CA1
Trapmine malicious.high.ml.score
FireEye Generic.mg.3597cd93701c4505
Emsisoft Trojan.GenericKD.66127804 (B)
Paloalto generic.ml
GData Win32.Trojan.PSE.R2WKDE
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/Trojan.IJBN-1595
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Trojan[Packed]/Win32.Autoit
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win32.CoinMiner.dd!s2
Xcitium TrojWare.Win32.Hider.REXR@5364l6
Arcabit Trojan.Generic.D3F107BC
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/YahLover.worm
TACHYON Clean
VBA32 IMWorm.Sohanad
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R03BC0PFC24
Rising Clean
Yandex Trojan.GenAsa!i9rai7w7/WE
Ikarus PUA.Autoit
MaxSecure Trojan.Malware.204078691.susgen
Fortinet Riskware/YahLover
BitDefenderTheta Clean
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Packed.Autoit.NKB
No IRMA results available.