Static | ZeroBOX

PE Compile Time

2024-06-01 17:09:21

PDB Path

C:\Users\ASUS\Desktop\白加黑\19\计划任务启动\Release\ffucore.pdb

PE Imphash

92dd8a57c388fde2670d2599076670d6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003bff6 0x0003c000 6.76438126539
.rdata 0x0003d000 0x0000bf7a 0x0000c000 5.42227444925
.data 0x00049000 0x000058e8 0x00004600 6.80627263668
.rsrc 0x0004f000 0x000000f8 0x00000200 2.52739185048
.reloc 0x00050000 0x00003dc8 0x00003e00 6.4300115368

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0004f060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x1003d000 GetModuleFileNameW
0x1003d004 GetLastError
0x1003d00c MoveFileExW
0x1003d010 VirtualProtect
0x1003d014 GetProcAddress
0x1003d018 ReadFile
0x1003d01c VirtualFree
0x1003d020 VirtualAlloc
0x1003d024 CreateFileW
0x1003d028 CloseHandle
0x1003d02c GetFileSize
0x1003d03c WriteConsoleW
0x1003d040 WideCharToMultiByte
0x1003d044 MultiByteToWideChar
0x1003d048 GetStringTypeW
0x1003d04c EnterCriticalSection
0x1003d050 LeaveCriticalSection
0x1003d058 DeleteCriticalSection
0x1003d05c EncodePointer
0x1003d060 DecodePointer
0x1003d064 LCMapStringEx
0x1003d068 GetCPInfo
0x1003d078 GetCurrentProcess
0x1003d07c TerminateProcess
0x1003d084 GetCurrentProcessId
0x1003d088 GetCurrentThreadId
0x1003d090 InitializeSListHead
0x1003d094 IsDebuggerPresent
0x1003d098 GetStartupInfoW
0x1003d09c GetModuleHandleW
0x1003d0a0 SetLastError
0x1003d0a4 GetModuleHandleA
0x1003d0a8 GetNativeSystemInfo
0x1003d0ac LoadLibraryA
0x1003d0b0 FreeLibrary
0x1003d0b4 GetThreadLocale
0x1003d0b8 lstrlenW
0x1003d0bc RtlUnwind
0x1003d0c0 RaiseException
0x1003d0c4 InterlockedFlushSList
0x1003d0c8 VirtualQuery
0x1003d0d0 TlsAlloc
0x1003d0d4 TlsGetValue
0x1003d0d8 TlsSetValue
0x1003d0dc TlsFree
0x1003d0e0 LoadLibraryExW
0x1003d0e4 ExitProcess
0x1003d0e8 GetModuleHandleExW
0x1003d0ec HeapAlloc
0x1003d0f0 HeapFree
0x1003d0f4 GetStdHandle
0x1003d0f8 GetFileType
0x1003d0fc LCMapStringW
0x1003d100 GetLocaleInfoW
0x1003d104 IsValidLocale
0x1003d108 GetUserDefaultLCID
0x1003d10c EnumSystemLocalesW
0x1003d110 FlushFileBuffers
0x1003d114 WriteFile
0x1003d118 GetConsoleOutputCP
0x1003d11c GetConsoleMode
0x1003d120 GetFileSizeEx
0x1003d124 SetFilePointerEx
0x1003d128 ReadConsoleW
0x1003d12c HeapReAlloc
0x1003d130 FindClose
0x1003d134 FindFirstFileExW
0x1003d138 FindNextFileW
0x1003d13c IsValidCodePage
0x1003d140 GetACP
0x1003d144 GetOEMCP
0x1003d148 GetCommandLineA
0x1003d14c GetCommandLineW
0x1003d150 GetEnvironmentStringsW
0x1003d158 GetProcessHeap
0x1003d15c SetStdHandle
0x1003d160 HeapSize
Library SHLWAPI.dll:
0x1003d16c PathAppendW
0x1003d170 PathFileExistsW
0x1003d174 PathRemoveFileSpecW
Library USER32.dll:
0x1003d17c wsprintfW

Exports

Ordinal Address Name
1 0x1001a6e0 CreateUpdateSession
5 0x10004dd0 FreeLibraryMemoryAndExitThread
2 0x1001a6e6 InitLog
6 0x10004dd0 NtUnloadDllMemoryAndExitThread
3 0x1001a6ec SDDnsQuery
4 0x1001a6f2 SDDownloadFile
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
WVRQPj
WVRQPj
L$49L0
L$$+L$
=;n>=}
* }S=W
=;n>=}
ns'=1x
F<jfPV
~,9~$t
t@9u<j
FYY;t$
FYY;t$
D$$j@P
D$$j@P
D$ j@P
D$ j@P
t$0VPW
4VWQPS
t$$Uv-
l$,UVW
4VWRQS
tX9;uTj
t89u4j
t@9u<jD
tG9uCj
tO9uKj4
PPPPPWS
QQSVWd
VC20XC00
URPQQh
UQPXY]Y[
PPPPPPPP
j0Z9^4t
j0Z9^4t
j0Z9^4t
vj*Xf;
=j*Xf;
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
JjlZf;
tb9^4~]
SVWjA_
V.jx_f;
V +V4+
F.jgYf;
PRRRRR
PVVVVV
PVVVVV
ARPRQh
jYjf
uSSSSj
[PVVVVV
j"[WVVVV
PVVVVV
M,j"^QRRRRR
Vj0XPW
M$j"^QRRRRR
j"[VWWWW
SWt@jU
_t^PVj@
u/j,Xf;
PVVVVV
PVVVVV
PWWWWW
D8(Ht'
D8(HtU
D8(Ht5F
PVVVVV
_PSSSSS
j"_VSSSS
WVVVVV
PVSRSQV
PPPPPWV
PP9E uPPSWP
f9:t!V
^PQQQQQ
E ^PQQQQ
CY<u
C PjPW
C$PjQW
C*PjTW
C+PjUW
C,PjVW
C-PjWW
C.PjRW
C/PjSW
CHPjPW
CLPjQW
u{9^\t/
NX9^`t1
u2Vj@h($
9C`u99C\t4
u29K\t-
WHPh8'
QQSVj8j@
PPPPPPPP
bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
3b:(sIua7
NNtDuplicateToken
NtCreateToken
NtDuplicateObject
RtlNtStatusToDosError
kernel32.dll
CreateProcessInternalW
CreateProcessInternalA
<7HX)5
H!X%tP
$,hW|Y
(J#roc
^Y`CM)
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
SystemFunction036
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
?invalid random_device value
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid string position
iostream stream error
QX[!jWW
C:\Users\ASUS\Desktop\
\Release\ffucore.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
ffucore.dll
CreateUpdateSession
FreeLibraryMemoryAndExitThread
InitLog
NtUnloadDllMemoryAndExitThread
SDDnsQuery
SDDownloadFile
GetModuleFileNameW
GetLastError
DisableThreadLibraryCalls
MoveFileExW
VirtualProtect
GetProcAddress
ReadFile
VirtualFree
VirtualAlloc
CreateFileW
CloseHandle
GetFileSize
KERNEL32.dll
PathRemoveFileSpecW
PathFileExistsW
PathAppendW
SHLWAPI.dll
WideCharToMultiByte
MultiByteToWideChar
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
SetLastError
GetModuleHandleA
GetNativeSystemInfo
LoadLibraryA
FreeLibrary
GetThreadLocale
lstrlenW
RtlUnwind
RaiseException
InterlockedFlushSList
VirtualQuery
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
ExitProcess
GetModuleHandleExW
HeapAlloc
HeapFree
GetStdHandle
GetFileType
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
WriteConsoleW
wsprintfW
USER32.dll
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
[,<(T,<
Y,<D[,<
W,<|W,<VV,<#X,<
Z,<DY,<bW,<
S,<rX,<pU,<
S,<5V,<*Y,<
W,<pV,<
S,<HW,<^Y,<
U,<GU,<
T,<9X,<
S,<+Z,<
S,<+[,<EZ,<
S,<BT,<
S,<-U,<
S,<jZ,<
T,<SX,<
VJm&WJm
WJmlWJm
VJm^XJm
XJm<WJm
VJm?XJmuVJm
XJm+YJm
WJm?YJm
VJmYYJmQWJm
ViS@WiS
ViSWWiS
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV_Locimp@locale@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AVtype_info@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$numpunct@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$ctype@_W@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
;Z<q<B=~=
>\?u?|?
575Y5r5
6J6[6}6
6.7H7m7
0r2&6@6F6g6
7C7R7p7
0$1:1r1
7-7Z7}7
:X<h<u<
6G8M8h8
:e<*=3=<=B=]=
2D364\4
:1:N:h:
:q;`<I=
2E2P2a2i2)3
4<4n4y4
8'929B9K9
W0]0x0
<Q=a=q=
5j6p6v6
6R7Y7a7y7
7A8R8X8^8s8
8B9I9Q9i9o9
9G:N:T:\:q:
=I>p>v>|>
>R?Y?a?x?
"031H1
5b5h5n5
5Y6_6y6
67%7+7@7
8)8/8I8
>0?b?h?n?
A0U0]0
1b2i2q2
2J3[3a3g3|3
3B4I4Q4i4o4
4/5@5F5L5a5
5"6)616I6X6e6
6$7f7m7
0+1C1e1
1r2F6M6
u5,6t6
2&5-5k5
D0N0^0c0m0
1(1,161D1N1X1d1n1x1
313J3P3d3
6*6u6{6
687H7V7
:&;>;H;R;l;
<3<><C<U<
<I=Y=c?n?v?
3U6p6v6
:(:g:~:
2'282A2
2!343<3M3g3w3}3
4 4&474L4o4y4
6P6k6q6
7D7]7e7u7
888W8m8
<*<b<n<
=S=`=y=
>'>@>~>
7m8 9m9
80@0F0U0r0
1A3Y5t5\6q6v6
858B8Z8
02[243
3M4l4D5d6
8)808\8
839@9U9]9c9q9y9
=(=-=F=K=X=
0%1X1~1
314;4D4
50696B6M6U6_6j6s6y6
7&7.747:7H7N7
8#8*8=8K8Q8W8]8c8i8p8w8~8
99E9S9Y9_9e9k9q9x9
:>:M:V:c:y:
<#<(<;<O<T<g<
@1V1e1
272?2Q2^2
7B7P7V7q7
8"8=8N8Z8
021J1P1w1F3
556A6Z7a7
88'8L8U8
8c9s9v:{:
:9;K;U;
<<4<;<B<L<
=)>Q>e>w>
?2???H?M?R?m?w?
0'070O0R1
6"6&6*6.6
6N8R8V8Z8^8b8f8j8Z;
>,>E>3?=?J?{?
1)101N1h1w1
2252B2P2^2i2
7J8R8Y8
\1[4)5u6
40>0H0
2[3%4[4
3X3r4~4
6'747C7W7`7x7
879E9^9f9o9x9
90:?:H:V:
<2=9=n>
2Q2U2]2i2
323K3P3|3
3_5q5V6
9A9G9R9
9":,:S:]:
;r<M=T=|=
>">5>O>c>
?$?R?a?s?
0)0M0W0y0
0'1@1E1N1
2%303:3I3Q3Y3P4
6!;';9;D;
7$8[8m8
2 202i2
3F3p3w3}3
4'4,414A4F4K4[4`4e4u4z4
5)5B5P5\5h5|5
5+6C6S6g6l6q6
77$7?7I7Y7^7c7~7
838H8l8~8
< =*=E=
2+2N2b2
3@3R3\3~3
424Y4z4
7$888[8
?5?^?v?
20;0S0
4T4P5\5f5p5t5z5~5
;';?;r;
=&>->4>;>U>d>n>{>
="=Y=`=
7'797K7]7
5E6`6+7E7
8 878M8
96:{:V<q?
33E3U3"6
7 727z7
8,858>8
:):::R:X:d:
2*222O2_2k2z2
474T4h4s4
667V7f7
9m9x9~9
0"0.050;0E0T0\0h0m0s0
0F1K1]1{1
=B=_=|=
?7?a?k?u?
2 2$2(2,20242H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0X0\0`0d0h0l0p0t0x0|0
0\2`2h2l2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
4 4$4(4,4044484<4D4H4L4P4T4X4\4`4l4t4|4
7 7$7(7,707<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
7L;T;\;d;l;t;|;
<$<,<(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
3(444@4L4X4d4p4|4
5$505<5H5T5`5l5x5
6 6,686D6P6\6h6t6
7(787D7P7\7h7t7
8(848@8
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:
*4.42464
0@1D1H1L1d1h1x1|1
2 2(2@2P2T2d2h2l2t2
3,3<3@3P3T3\3t3x3
4,404@4D4H4P4h4x4|4
5$5(5,50545<5T5d5h5x5|5
6,6064686<6D6\6l6p6
7$7(707H7X7\7l7p7t7|7
8 80848D8H8`8d8h8|8
9,9<9@9D9L9`9d9t9x9|9
:$:(:,:0:4:H:X:\:t:
;,;<;@;D;H;\;`;d;|;
< <$<8<<<L<P<T<X<\<p<t<
2$2,20282<2H2h2t2
303<3\3h3
444@4`4h4p4x4
585H5T5\5t5|5
6<6H6h6p6x6
6(787D7d7l7x7
8<8D8L8T8`8
989D9d9p9
:$:H:X:`:h:p:t:|:
; ;$;,;8;X;d;
<<<H<h<t<
= =<=@=\=`=
=$>(>D>H>P>X>`>d>l>
? ?@?`?
0 0@0`0
001P1l1p1
202P2p2
303P3p3
404P4l4p4x4|4
5$585@5D5H5L5P5X5`5h5|5
1 1$1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:0:4:8:<:@:D:H:L:P:T:X:\:`:d:p:t:x:|:
; ;$;(;,;0;4;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6
7 7$7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1`1d1h1l1p1t1x1|1
2 2$2(2,20242@2D2H2L2P2T2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4P4T4X4\4`4d4h4l4p4t4
4X5\5t5x5
?,?H?h?
1,1X1|1
%016llX.DLL
%016llX\%s
ntdll.dll
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
mscoree.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ffauclt.exe
ffucore.dll
xig.vix
C:\Users\Public\Documents
C:\Users\Public\Documents\xig.vix
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Fragtor
Skyhigh BehavesLike.Win32.Infected.fh
ALYac Gen:Variant.Fragtor.526305
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.SilverFox.swkbu
K7AntiVirus Clean
Alibaba Trojan:Win32/Injector.8e23b916
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Injector.ETRZ
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Gen:Variant.Fragtor.526305
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Fragtor.526305
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Injector.dxafd
DrWeb Trojan.Loader.2072
VIPRE Gen:Variant.Fragtor.526305
TrendMicro Clean
McAfeeD ti!09DD0DE52154
Trapmine malicious.moderate.ml.score
FireEye Gen:Variant.Fragtor.526305
Emsisoft Gen:Variant.Fragtor.526305 (B)
SentinelOne Clean
GData Gen:Variant.Fragtor.526305
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/Injector.dxafd
Antiy-AVL Trojan[Injector]/Win32.Agent
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Fragtor.D807E1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.R656658
Acronis Clean
McAfee Artemis!FC5857B45516
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes Malware.AI.605676534
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09FP24
Rising Trojan.Injector!1.FD65 (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Injector
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/ETRZ!tr
BitDefenderTheta Clean
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Fragtor.Gen
No IRMA results available.