Static | ZeroBOX

PE Compile Time

2006-04-01 19:05:04

PE Imphash

fa0f17d473d9318889cd521d5e59224e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00131435 0x00000800 7.68656024689
ct 0x00133000 0x00059000 0x00058200 7.29506762865
ct 0x0018c000 0x000ad000 0x000abe00 7.99040306617
ct 0x00239000 0x00002000 0x00001200 0.427880984933
ct 0x0023b000 0x00007000 0x00006200 2.99234620559

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00240838 0x000002e8 LANG_RUSSIAN SUBLANG_RUSSIAN dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2029533187, next used block 2156431479
RT_ICON 0x00240838 0x000002e8 LANG_RUSSIAN SUBLANG_RUSSIAN dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2029533187, next used block 2156431479
RT_ICON 0x00240838 0x000002e8 LANG_RUSSIAN SUBLANG_RUSSIAN dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2029533187, next used block 2156431479
RT_ICON 0x00240838 0x000002e8 LANG_RUSSIAN SUBLANG_RUSSIAN dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2029533187, next used block 2156431479
RT_GROUP_ICON 0x00240bde 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_GROUP_ICON 0x00240bde 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_VERSION 0x00240c32 0x000003d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0024104a 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x63a000 LCMapStringW
Library ADVAPI32.dll:
0x63a008 RegOpenKeyExA
Library KERNEL32.dll:
0x538034 GetProcessHeap
0x538038 Sleep
0x53803c ReadFile
0x538040 CreateFileW
0x538044 lstrcatA
0x538048 SetThreadPriority
0x538050 GetLastError
0x538054 SetLastError
0x538058 VirtualAlloc
0x53805c CopyFileA
0x538060 LoadLibraryA
0x538064 GetModuleFileNameA
0x538068 GetModuleHandleA
0x53806c IsDebuggerPresent
0x538070 VirtualFree
0x538074 SuspendThread
0x538078 DeleteFileA
0x53807c CreateThread
0x538084 TerminateThread
0x538088 GetProcAddress
0x53808c VirtualProtect
0x538090 lstrlenW
0x538098 VirtualProtectEx
0x5380a0 TerminateProcess
0x5380a4 RtlUnwind
0x5380a8 GetModuleHandleW
0x5380ac OutputDebugStringW
0x5380b4 WaitForSingleObject
0x5380bc HeapFree
0x5380c0 GetCurrentProcess
0x5380c4 HeapAlloc
0x5380c8 lstrlenA
0x5380cc CreateMutexW
0x5380d0 GetFileSize
0x5380d4 CreateFileA
0x5380d8 CloseHandle
0x5380dc ExitProcess
Library USER32.dll:
0x538104 LoadCursorW
0x538108 BeginPaint
0x53810c GetDC
0x538110 RegisterClassExW
0x538114 KillTimer
0x538118 EndPaint
0x53811c UnregisterClassW
0x538120 DefWindowProcW
0x538124 MessageBoxA
0x538128 LoadStringW
0x53812c UpdateWindow
0x538130 PeekMessageW
0x538134 CreateWindowExW
0x538138 GetSystemMetrics
0x53813c SetTimer
0x538140 DispatchMessageW
0x538144 DestroyWindow
0x538148 ShowWindow
Library GDI32.dll:
0x538014 DeleteObject
0x538018 SelectObject
0x53801c CreateCompatibleDC
0x538020 BitBlt
0x538024 DeleteDC
0x538028 CreateSolidBrush
0x53802c CreateDIBitmap
Library ADVAPI32.dll:
0x538000 RegCloseKey
Library SHELL32.dll:
0x5380f4 DragQueryFileW
Library ole32.dll:
0x538160 CoInitialize
Library PSAPI.DLL:
Library imagehlp.dll:
0x538158 CheckSumMappedFile
Library COMCTL32.dll:
Library SHLWAPI.dll:
0x5380fc PathFindExtensionW
Library WS2_32.dll:
0x538150 send
Library MSWSOCK.dll:
0x5380e4 AcceptEx

!This program cannot be run in DOS mode.
3u$-04*
%c[\G/r
x&\[,&>
&yu!V*
N}Za,?A.
O10Z4q
",7E`&S)
Yc98'_
9?LZ)]N
@2mo%n
ikb_U"
dZ*!60
)]{okH
?1wM^11}
O)G8_=,
9SH;:6
P&$R|J
RCbs|t4L"
*=gR$~n
$^5!H(5Qb
A_#J6y
?CHYQPq
hF:YUU
y^XCw1
X:~FIP)
Nwc0b2
EL0T*b
%XwSe{"QcAh,``h
a-hxMV
p38 KM/
9s1{Pg
S+[ILZd
&oQ!v\
LO$..'l
2'Dsdc
<gPd))
u_6e;*.dM
2J!%+)|
h]VTH0qw
uda9F"a_E^
=hb\-Y
Y^2CF!S
RWTN,yXx
3%-D!>
VvMPV
8X9UzF
94DdDzwRd
xm,}$<}
E#+S^T
$/zJ<w)J3
:MlsBZ
lO6M(!a
j5oc|w
*]x]] d
fE5b{uHy8
By} ]u{
0aIUoffx
*G!.bf
VProtect Professional v2.1.0.0
]3J;fS
KOs)!;
8;fU Q
L+C&)7
+ym>H
$lwq'U2hD
mq)F,4]
f:<k.:XG*
fQB34(I
.:|7I_
=UlNx<
J+/&zNs
{.>cLJm
foUoJ{
4;aPZ?
l{+):;v
='L;+8LO
sxg!; .
~QGC<Q
kdQ JV
|.e]6-|
1f=R$r^c
$ .P]z
7tku,(f
)*s=o%h%<
]H[i4kP
w3%\3h
X(KuB/S
+lpx4}0
"?7lBy1Q
oZu+g }
(}ng.B{d
+v,jwZ
lPgDA7:y
wUC]aqO[>$9iV
HqP%m4&
go*p@d
2/=9g{
2O> t}
!O6>SH3yFNEWhU
D%1!R.
Di[w`UX5
QLbkgd
f~[iQ?u
F2gmgYM
yvbQ}.w=
a]qhk4
1TU[~V/
URPQQh
;t$,v-
UQPXY]Y[
Qkkbal
bad allocation
bad allocation
bad allocation
bad allocation
bad allocation
bad allocation
MessageBoxTimeoutA
MessageBoxTimeoutW
bad allocation
bad allocation
bad allocation
bad allocation
bad allocation
ExitProcess
CreateFileA
GetFileSize
CreateMutexW
lstrlenA
HeapAlloc
GetCurrentProcess
HeapFree
SetHandleInformation
WaitForSingleObject
OutputDebugStringW
GetModuleHandleW
VirtualFree
GetProcessHeap
ReadFile
CreateFileW
lstrcatA
SetThreadPriority
GetHandleInformation
GetLastError
SetLastError
VirtualAlloc
CopyFileA
LoadLibraryA
GetModuleFileNameA
GetModuleHandleA
IsDebuggerPresent
CloseHandle
SuspendThread
DeleteFileA
CreateThread
InterlockedDecrement
TerminateThread
GetProcAddress
VirtualProtect
lstrlenW
GetPrivateProfileIntW
VirtualProtectEx
KERNEL32.dll
DispatchMessageW
DefWindowProcW
UpdateWindow
GetSystemMetrics
CreateWindowExW
ShowWindow
PeekMessageW
RegisterClassExW
BeginPaint
LoadCursorW
KillTimer
UnregisterClassW
SetTimer
DestroyWindow
EndPaint
LoadStringW
MessageBoxA
USER32.dll
CreateSolidBrush
CreateDIBitmap
CreateCompatibleDC
SelectObject
DeleteObject
DeleteDC
BitBlt
GDI32.dll
RegCloseKey
ADVAPI32.dll
DragQueryFileW
SHELL32.dll
CoInitialize
ole32.dll
GetModuleFileNameExW
PSAPI.DLL
CheckSumMappedFile
imagehlp.dll
InitCommonControlsEx
ImageList_GetIconSize
COMCTL32.dll
PathFindExtensionW
SHLWAPI.dll
WS2_32.dll
AcceptEx
MSWSOCK.dll
RtlUnwind
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
bnc,Zbb
ukn).,Zbb
-4N!QYR
:taIoU5
+OIkQM1Ehk
ad2XtE
5YpKJQY
t%$*/h
F#j9AD
B`pQYk
r6o%rh
1aPw}hQ
f26QhQY
yJC;R`u
^ep`LP
2sj.bQY
P y,(;
G<PGIBY
4mu9h~
5QY9D1D
V#wh/P
)Bx[{m{P
;fNtEFWP
8rE>75
n=M<,`
FC9Nwh5
V3A0$d@6}
HZ*6si'h|
>y\0YQY
+)X2QU
}x@2QY
lXRv-h
=KC y`
P?rZR`
e*.:Ngq
y_ g6h1>
|b`ZQY
_m17ZP
ysFebh8
K`$QHQY
s/ahH)
"NksF~
`W$QY3
f/YUzh
!Lm(xP
xh*9eQY
u8r"HfZh
hPF25P
o:54oh
K{~--P
6H?7/(QY
KC{h'yy
v|}o7?X
unxVN8s}QY
RNl#z9@Zmh
^S+:*p0
Hrhk&,
M )/]`
8]Eh|"
J8.FLZ
Dd%m9 -'
c@ghl17
k|"2m`
mx)Eh
5gilDC
:]Y2QY
%eT(jP
_A=8hi
.,Hm].
\MA%QY
.Wi>KQY
%8+iyP
utd(2o
RxMvuC
yD&!h{
S=i4|hP
xQlLh.`
\r14p;
JEhpQY
xa'{Z^XMQP
wO:C3)f1p
uQhvsR
$rB0C<O
(%pq~`z
YD>q=h
Vl.j5`
oUWX|P
p'FoP
kKlMg#
J2*`,`*
,oiBK`
z^.|P]
0#hTJ-
v3]bI`
L|lm}xE
PXfVf^fVf
fXfRfZ-
,&fPfX`a
]V^fVf^
BfPfXWf
fYfWf_`af
f^fSf[
fQfYfUf]Sf
fRfZ,&
f[fPfX
]fQfYf
fRfZ`a
fVf^X`f
fSf[Wf
ZPfQfY
f^fSf[d
fUf]fVf^
fUf]QY`
fSf[fP
`afWf_f
U]RZV^
fQfY`f
fUf]fWf_
ZfVf^f
fPfXfQfY
fWf_fP
1fQfYf
fQfYSf
fZfPfX
fUf]fPfXU]f
fPfXQY
fWf_fSf
`afPfXf
f[U]fPfX
fWf_`a
fPfXV^
afUf]fUf
fWf_fQfYP
fQfYfU
_V^`a-
S[fVf^-
f[`a`a
V^fWf_fP
G,fPfX`f
`afPfX
fWf_PX
QYfSf[
g(afPfXf
fVf^fP
f]fUf]fRf
^,&S[W_
U]fPfXU
BfSf[IV
fPfXfS
afWf_Vf
fVf^fRf
`a`aW_
fVf^f-
RZfQfYf
fXfSf[
fYfUf]
fPfXRf
fXfRfZ
f_fWf_
fSf[fQfY
,&fSf[
fXfQfY
fWf_fV
fPfXfQfYQ
`afQfY
fPfXfRfZ`f
QYfSf[fR
V^fWf_
fUf]QYU]
fPfXW_
S[`aSf
6fSf[-
fQfYfS
f[U]fP
,&fUf]
PXfQfY
fWf_afPfX
MU]fUf]
fPfXfPfXQ
fPfXQY
`afUf]
fQfY`a
BV^IRZ
fSf[fR
fXfWf_
afQfYd
V^fPfX
`aV^fU
RZfUf]`
fZfSf[
fUf]fVf^
fWf_fV
afQfYf
ZfQfYf
fXfPfX`a
fZfPfX
PX[fUf]
[U]fWf_
S[fUf]
Qkkbal
[8=Bnr#q>S
#1My8L
z+gV*}{
*y=_15O_
*zyE*5H
FO6^wm
h)PV>?H
ZR,q+7
aAG xg
O[tA7#
|Nse*hF
ermyL{[
[z_;%L
wmoL%U
cpF",0
L{t+b0
l|d"B:
kWY\|T
H^wMR{-
kmqd1x
0'"(/PV
fp|tf4
A2mlm;
Gz2?NN
b|'9[z#
B}80?e
/roZa&
n1Nc$L,5
VM|>F
4M[z?f
Z|[#{'
-I4oA|
|mC},K
OWohw|
1+Ql[K
8} szk
dIdLw,'
8}!%FR
Ekm$7U
1+Ql[Ks;
'ES@<?f
BcL+12
z/A,BZ3
"1$<~)1
| oCtf
<.lZHo
* Ogm9
|"2?j<
OR]qA
km$7TG
c""~Xa
D$u%fn
x`jhyw
l],M3Z
Q07Q-{
0^B1u[}
P^<:X_
k5;R"g
b4sy0I
T/LS-k
hWa=9~u
c}[]RVk
GOyR?z
Q?(CAQ1s
LX`MZtKn
LX`MZtKn
4 evF/
JPI11?
8wPYW;
SIu8`B
ZKb?qU,
^VbOys
xTZhF)
d&w-x_
cn;=w+
`dB 1~1
i8ZJYq
x&w-xa
Mn;=w,
x&w-xa
MUO1ls
SVp+X/
r106(R
%`p^`5
YHZnqW
N],GtRN
Bp$`s@
*:],!
61J:uX
O>aVp!
^2]=X``.W
d e?8'
_:o8vTJ
KL#1{xq
U#1{xn6
p%C:6$
gUiKJ^
jJyz&3
U#1{xo$
;.v-a]
`J|'8l!
I}s{f]
6()k)Q:
+0[|TX%
U_@?uE1O
H}<bX~
0VjC7Pexp
!@cn2R'
2eE[B\y
(@F2{)"
WE&wzAzZ
!@cn2R'
u?NPk#
rMVU|A}
uM^.Xw
(@F2{)*
/GAdwz
#yvUyn
kcb`~<
eE[B\y
(@F2{)"Z"
VD//\P
S"U:dh
d6T)AI
rMVU|A}
!'"@1c
:~/m0h
:],I\T
+@@Pvq
-lC1tBk
MtsDlp
b87Q"{SJ$m
9oVRTo
?t,I%-
9\U >M
)C^|6Lvk
%ZuOub(F!
a(7qdS
8ce"G
duOub7Y
Xl<EYUBHl
q$N <C
bEFltt
5D0lw`
4qsG$_
6xV1lD
uB5CMFv
:],I\T
dUhieQ
z'!7~[
LuJ$m
k5CMFv
gEj1i$
R ]%Jx
S*M-Q?
e%(I#l
1}ZY5i
@;{%%g
(adDN$
Nx|A|TB
5D0lw`
vuOub6
7{]VV0B
duOub7Y
6|D6R,
kAQrYS
*R!aX+
|AZ'|gvJ$m
>|5?[X
/G p/C
,), m5Y
'_<eBEP
,DbjS|
BJ%B(3
m~F+^C
z>A<EF
DMi3r6
fr6T,/
*F.H}|
zP1vEr
JQYjWT9
y\@49\F
1vErVZ
:+2<Wr`
J^Wt6y
k?;Z$s7
pIJ[6z
d ;d:>X/S
1vErVZu
m~F+ZKb
!"ncwv
,'Kw7x
T?L1z~8
uAt`_m
6PyX%V
;C[I-8
bvGT\G
o&UaD
@AXax|
a&GcHt
O IxMdWn
>ls?Fw,/
JQYjWT4
JQYjWT4
2@?f_g
f:;=*h
C+NkFW
ucHdRR
y\Xbm[
E~_F]-U
EdU$JZ
S%SMPg
SM91BA
/P^ihx
-.K,#e
^?EI[~
0OdvD
Ec#k@?Qq
7d@&na
MW=4r;
~OA%eK3U
1[W:3
uyTlL
Ztip>=
;E I!%
CNTu9=
MznArB
M\sz+$H(]K
!ZOJqM]
xG|@'Ty(
\ssvn*
4d\pp(m;^
O W|K}
];$ <%d&
vHRU:J
(CTGl.j
fki[Fa|
JKMGOLh
YHz+$H(]K
)(/38gA
jnI'O9
4]MvAE
p)~rm{
j-d\pp(m;
%$H(]L
K>d 8k
%$H(]L
2EZ 1E*@
0 R])Cc
$5S@pE
%$H(]Lz
0#8mY$E
1C$.hi
T^%(3J
m=z?Sl
i<#ZkG
*75fjB39
XK^'R4
(:M LL
6X+|(0
CH[L9F
pp(m@Y,)
Mzq]S;
=c"!3~
d]M]R %*
];$&zyD
D*!wL1
pp(m@t
cj.` Q
I4Pt(U}=[
M]R #Mt@
Rj|dlF
KTd\pp(m;^
"4xoB+
Xy!xSw
p)~rm[HSh^!
LE{=oq
|@'Ty(
Rt+lxB
TvnlLZD
c]#4xv
iVj=[c
c]#4xv
=c]#4xv
]R "u~@U
h6w'+h~
h,b]7h
Ls* ]e3
h{NL[~B
T)585V(
g2{d)Q
bw-DcI
-9?$u@
??R^ZpPg
F >/A5:
8v?AtM
=/v^*?
ACith
pH_o1n
/]3]c6L&>
.>]wBs
lWMUxX
Mf*rDI
F,+`k^
cMF]D\Kf
2B!]D@(
KkW}<e
1l^y6}W
wU)Z_W*J
4{NL[~B
[L\^$r
onMU4O
jx:;hC0
`b\q(p
w}(+A>
w}(+A>
9y8APg
Zl`az
`_PO*6
5v.|n`
x !]D{h#P]
h-)4ch2
h{mm6h
{u9fc*
8ALxv&&
rYoT8F
#Z<kL!
`yn5O;j
2E6\6b6
4b4s4z4
5<5A5N5q5}5
6"6-656@6I6R6s6
717D7K7Q7W7]7c7j7o7v7
7G<M<k<q<w<
=:=N=T=f=x=~=
>2>?>R>
?%?+?9?
0%030<0B0G0W0]0
9&9+979=9X:h:z:D;J;P;V;\;b;h;n;t;z;
91989<9@9D9H9L9P9T9
:!:<:C:H:L:P:q:
::;@;D;H;L;
=o>]?z?
0;1N1q1}1
2H3M3_3}3
4!4'4.454<4C4J4Q4X4`4h4p4|4
6=6F6L6
8 8<8@8
0 0$0(0,0004080<0@0D0
Q311q0
uwlG.h
JGF)Sd
hOR<T-
;m%N(!
d)wq[J,
i\"Ar*v
O,@sFF1
r$sxGtx
o0da3Q
uLA01$
{J_DJ*
GF1I#]b
aGq+sn
Uc\}8I
'{tkUnInWj
}tuj7
=Oso++
@?dGWl}1
)PI(F*O
FJWC>AQ
qU,^Kl
|MuaXR
`[<5N2
s<NR59=
/[ljr?
+,1nI?
"n&$E
Irro%/
"U*u9U#q
.}g?vWC
Qf5aOU
h+&PV
}LmQ5j
{oK5j:
PrY+U$v"
K)>&W"
O|R\>k
yS<Ql
abeWh-
m9!r=p+,5
@@fqsL
S*@G&i1Y
@1Da*#q&
{eY](}
v`W&(t_
[Jl.THv
tP Xs#
S?vhWX
SP5h#:
ldA 2G) c
m:9}h$D
VpF2Qc
$I=V/I
s:wE^(
ojF{~c
9k+SWh
['yr)z
E?7ra>![
`W8lHT
]d:Dc3
h^E@|)
sd%Qis
$Vz3L\
_KCUl'
PSnJYp
fw/yTd-
qiaAkd\
$kuz h
g;\'CF
K5k!!oZ
taz,4Q
AU^g}r9J
?S$p+@
?1$E<[
[@*8bx
Vi;KW\
.&;wc^
m''1.P
J8QXd!
-GoyTx
]Sqrm/H
LN*`E!
}5CORe
7QHrGVb
~Wx"k!
u[x)=-
iWbSZ9
5h*JRa
N)'F>d
NHl;/$
.fR28"
hIp\*A]
{_)"a8v
kz`mz(
=r,g{9
Ii5Pb?
j]3:UMR1
6DQV{x
N("U-_uSXLg
(rIzrK
/n&y)h
ux@@o
_7{pE4
Du/N_S
_!M[P8
{NI,mD
ww\Jy;n5?2M\G
-cev7f*
=\EPzI;8p1
[ZTto!
\!#2 S
(_aT;[
>CYChT{~8
K2zKm
-zGPFU
a{}wsr~
:/UnC\
7UhgryHZ
MGgzcw
a<|W@w
#l3& R
]s~N{QMS
,J!/"~
JYMq/]z
`l@(tr
h{H=&^
wktpXr+|
^AlAGU
%CO>a8&
#L4k180
vw-9U9"
yS?U'iH
#s27E/
7GstkTS
*nt=hc
n%EaC!V
'v~+T.
;:,H{B
G4ECQ.
Fd~=zv|J
cdB=<[
Bb<^W|
CtoQA.m
S8zG*`
Y9aW^d
'A"df>
<1z#I0P
9i(PZ,Xs
T^fOsC
9"m2FV
V=&uq_
G[6!R)
"b+pZa
I]*^>Ge-
S9IBkh
Ldf{r.8
7\`])]
RO MxM
>gmnTJ
@1#Rc3
&__ZG.
3c#Xd#v
>Pl,]\
3V( WN
%vUX=>
++gnbI
?0ii=Wj
Z1}bf"
bP3\G<
+a?@%IBY
<U/'[f
jEd\5,
1HRMz}b
RAwm'
]s,R}gB
z)V4uk}
N^h8Y*l
BlmS)<'
T raW=[
P-rYxn
o1D{@k
gAE6s-
P)zL6,
1vEj[k
M8CYNE
Y!/-p2
b-@;/Z=
D 6Mrt3
ZWI_Wl
fzdn2EU
YGKKU5
.D.T@$
<"pX)B
<,z@ ;
C]sDk[
my.!YRk*(LNN
<k:W?2
w:*?C`
X),m,q
"k>4xK>
|1-uVK
+Qj'Ck
=Ap9!C
iXKGw.`
Gf{,LG
a`'Bf(,^
- q78f
m9$Dn?
khbp'=Q
`zurKV
CJ.-|r
h"ED[Pnq
CQ&[0D
VvsmR:
mG]LT`
]GL(EP|
Fd/@Y)
)kGdYb
i$|Ki,<h
^qPD3d)
URjXze[
&`\]0I9F
P7(w/B
n$[VKk
8(8~AE
%zO\En
nud(P
N *D<W&0
!|iGi
% pNj`\
n{8$B6V4
P< ]>Fh
\.jAd@
3T8Fk<|?}
GOhG`U`
uiXfmU
g}M3d,p1
/xt^WR
~rTvy>
V53)iG
LUs'zE
Stzi/=R
<9vPi.
snQ9|WV
_=qGx_q
?.HhCh
+'zn.=}F
9fj`<~r/
ob>[yl%'a
Sx-aR|
r4FaC`SJ3s
GD(Ye"b
5dVF$+1D
|BJi\p
&RXx(>
Z'E$S^
m\$CbA
i ]/yj
/ {L_t^[
n|Cv`]
tEWiGQy
G`l$a>
W<u=yL
y'Cr}qXp
C=DCT@k
kf`i9B
S:kedQ\*
Ut_zS1"
(CTGP1#
\d&_xP
+rQ.._
{/!,}&B
]Ez{$
;qW+w}
h!IHf}
d\kJw/pxN
X[}3'.
grAXV%V
pQZ>CB
,lKUk^C+
m*t4"'
m~&W9`
eMA|@Yg
a-1o$IQ
jF;):\
uAvmYr>Y
BC>h~$
Ny&Q7m
DG&3y"g
GCfFi8P
VDlA@cy
(n-m
.UP)[1
M~x=3F
.yF~S
[N%Ks`|
(lHd=VjR
rUF["DD
~M7VniD
{44Hti
"#bQs5
ie7<uo
8ej:yx
\7}#%BRE
;wn*%y
knT39>S.
Bmx@?"
Oh\HY0
ZWVp"\
f"[CK:|]
yPj#MU
tYDB"HF
h=GT6M
QOE;AQ
)>TygC
/e#lRo
C*Zlip
uY(c<m
>=Skj!
.Fl=i%
'?V^V:%
(]xxer
.i}/(9
)Hp`Q<
T~H12B
.{^x:=
W,zrde
uUSE(3
LN2)oU
|r'`L$
LxBb|])d
D/a@uk
x+TgVX
u6r&y9
@W!tY>Y
k+)7GC
*n/E5'
\{\&!w
q87y64
1QEK.a
\S!P%{
>SkI7W
9e+H.[
5b{">#H
YZ9rr+
m^>b}2
P<FnVY
Sas@P^
"Tm+]2
\w!]B$:
aCVLCoNy
yDNw#-
gn)*Sf
zn=6F2
|zV$Pv
#svbk`
LiK$1+
gign(V\~B
'9E#~C
RqDaj2E
ED(9]CE
p[mR|;
6p0/]H.b
!//7\i
n/`Ud#
d<XznP
_.eZk% 6
\`#i`\
R`:WF)
j+^lPd
G/tV4^E
cDm-#N
BXF^wp
{AP3hY
%*HQQdyl_
[LOEbs
#4yK'c
&;*$eb
l/M :)
1A>b'ZC
rWEO[N
^:_=Wgf
cEkwCrhq
V\l|5p9W
1-$^"+
IcCZMU
l"g+#P
f"PzNt
o]!(pz
yn!c4YXr1
NGlm1a
A#S% i6
jLj[BR\
qU@mmjXB
kiEgjPL-5P
p@UzFF.
uZ3\pT?
UrH|\CQB
DEy(DB,_
dWB30{0\
Z@]]k_
E~]Gga
i;VLdi
4dDWk!
d/ nSw<i
!YP4Cb
nDA>t.c
f0NSK=X
~>e7TQ
>&knaQ
~r}\<L
Cg0$_P
);O0v
6B=bie
yY+0!|
(u?/b42A\
eUQ=oRm
DaUR{O
0p8KFt
VTg&@L
H3HlJ3
BL25qw
C\Q&S4j
op$t5J
=tM(ks
0uQy.tU
2GfYrn
4?ZUDT
3Kgzko#o
^ n |q5
"S9TQZ
?Cp<vNC`t
__wEi[g
";Ma?u
Zqi[FV4
Lrs:z{
oQE2|K
G59UL&
Rb;>v
PH:Pm:
/,;K~wd
=MsraUC
ML@7xJ(
jX%kVk
FRo:fJx
)_g:Ew
$SG"h'/
L][Pu3hi
2hGKcpk
t[m>?=
AfA@Sz(:
VsD=XW*
^)@Xcrfp
LnBgN{
gKB!H]
3}76!j
r-/CQ>
\r'Wjt}-
C{L*eX`
(1b840>M_
tW(VpM}G
2^(HLI
[#NQ^{
^q BIIt
wzL})}V
~l'hDx
kaj$6_
$<$GJl#
DOCo-"]
<^T)(iW,
D-3h-}*#
Ui6\VK
%rb)35
||tTvm
,sr6npk
VC+N-C
,`FC4l
4iy^)[
G_76<85
6vT(1F
S.D*lXN
l:>y.m
.~&Ojh!:B
eQk%$gY
jP3\ER
-@B1W2
8PX9.2
_}pv_U
@ _wV1h
kw 6}M
Lz-!;j
?~ 1m$
Km$]sY
[LYLk:
)&4VC?_2}I
kPr}>I
\g+B,X
{Qw'TyF
fRj.CY
NCcWE&
c{hQs@E
t~MsY)&
S"3(<@q
PwLR)%H3
j%n;-'q
t\'.Sc#
:E6TxL\>Nw
s6Bd1l.
6mvX|h
ObE`h)
sbUziM\}=
GQ<G%i8%
.dL*9R
l/a!!;|<
&P(s5N
Sa+mS)Mz
Qj@.;p`
v{T,y
8-ct[M
x,QS|D
S0DvoG
<p1un7m
Hw0Xh@
SFYg+
0Sj(Y&
=Z,:1K
V-8xM=
:V3I{
2+\y9
I.3lpT
YGeXW2@,
AUG)Dk5z
lR!2ak
YPcxI%W
3F|*,R
9S0UVZ[
hx"r^r7
?Zs=c"
`PaGT%E
tJki43
-[TWAq
t0>!u]
QEdcD{
tw($E8i
HYlvz\1y
B(]YSW
,ATGi1
eVSnN/
o*R.z;>
s:O5Py
m^=1`Xq
EUz0fV
y73A\S^
yq[@J?[
Q2.gtK
T\c,X8
3xKU cy
CG=#rQ
#!y3Gq
oDRg2'
m<4V"PU
W-]zi9
x5jw.o
SC}p'h
{ltWDUD!
zZ(jG>
1o5 xL
,N/kH>Q
uCa+}A
60iPx.
}Y-[Og ,
,mUm.U
P-kOw
Qd,ap7I
H&Uf'5
W@d:`(s
/;I6DR
|6PD ~{
%vL`qh<7B7B
09We[^
uep-Lg
=7lzyC
n+2HTDw
&j>L1q
~O:$w
[GNKl~
`Qd6M=
)=\U*V
qP4nEz
\9.,S<
G?FS$"
Pobl8V
%\AULoG
az}&`f:
bci_<%
)t$L|T
RY|.J"
g{LgWi
`|x6VXS8
_:29N]
-cz@S
f% |QT
VWA}]]
,Epl9WG
j%N0GV
L#('c[
HSS+'F
)(oQHB
y$WZ8^
xiy.zW
Oh<`v&x
KRTRr1y
*Z[roq
!1\U:6
PF$vD6
UXu3{{
l]4$3c
J>z{@"
m^PMwr
Z6rS?P
pDus~%
5CCE90
dJkyQRg
>8T4xp
w'j^z'
9iF^_m3
UyShLz
_o`2Vk?
cjR2[R&$
/Fy2$+]
YR|4+8
b#-GYGu\
5itCGL
98"$|8
e/Z>Qg
_xP\mcTP
/TA`Zk
a/#xIw\
&__VUD
jSG:?t
z%3B7D
xQTsEd
B<;OpSl
Ej5y/v
|Hj>e;d
SYjb~^
jD*'*e
|uJB3]
GL`K(O
]\+6U<
u?0#O
"L=^x$9
5A{Pk#
y~0Oh$
A!Gc;@
F&P!0F
D{E}MR
<Kw@K
7B{KfQ
6NCm[[
O>\>fY
Xb$hqQ
m{PZvy
P%=_%PL
6C`*WW
VB`x{S
Pr3Z>^Z
wm`K;F
Mdrl:j
zoC1</
0WI~\.
fj.n028e
T2hS^?
QflD@S
xsj7V{
uz,Py(
[gXfh(+
6Sq";*S
4J~L"n|M
<i,b]*jR@
(N:lE]wf;
Eg.a`X
pCeOo3
^J8a"A,
nCE+~
/j~e0kLG
"jiuV2
*<;St[
5V{TSxP^
{~6VP6
b?pZxG
!IUDs"
XKRW`%
*<Bg.]
8Q-}2V
3uG6X!^-
Fn\/*n
a9siB1x=x
k^njfA
(h#lIr
WJ,tWq
]{l[~)l
KbM<N^
1'Si9\n
;)PQsV
KrW$)g-
6vp{86
] r{N)
LACs'l9
91FG14
/!w@dm}9
acX9 ,
SOhVu*1
Jt9xw
MEbk(?
7q+0oT
7k /baMH
,,t,QJ
JZ/[['
nn(,Lo
j[s96b
MP,_\SX
w,j{,G
G.NnD(/
HlFRmm
~h2kl(
,uvuy"S
~OYPs_
_PAW8[
z.]2PL
hGC[VK_
gNSeME/
(KD|x|
*t0BhZ\
1Ft9J9
n?&G[N&
%4y/f1
(%[=?G
sLf5Y^U
r\ky{f
=D)thn
8F/84D
~2mdrrMf+
CPcz\f>
z5EGJ4,
IA17SL_w
yN^1PrO
`~ S[*
72S\W.
d_0,\L
l5E'X%B-
ZTo~|d@~
g&(xD%
X^47?o
m\~#Q!#
Q"mCS,L@
}5#l6@T
wL@-yz
E- v&Q
{Y#@\$^
r'"@Gz+
`H=RkmU
rB8VS'
f+"0g5
DTk7@0
}<pB,Y
&qKAVq
5}B(wL
v!;KVS?@
W`Gkc9
W1AEV2<
JkYij[
rI_,Ut
u8FvEQP
WFo;K^{
'=6qk;;
/'^yM3
w\P!<kN6
j\}QR+J
R+[=}>
KV";zf=
akz|9+r
[GlcsK
ovW?m*
ip7Lar
[KD$dSgYc
IB%|W|
\]sU3~
)[*lnks
GS*Lld
VFDsqY
$z}umGE
iK`3oQ
Q=X1H|
sm~tcn
-4X%pj
#-$G(7sS
04E"[a
D. A_
jiF+JQ
sE|&KA
8Ap%kO
&D;E_Z
Wk&Fz"Zg
u,hOD:/gOR
A\{4`}`
t_U.yE^
<uI[4~
3;{JB|
kJn!#[
aWtQEa
N#=KPV
E?4DB~us6
%A^+/ARX}
]/:xEI
}_A0ps
ld7FehR
j&v("
*./YZ@=
mt]jDU
Ep!U3D$
p44uDC
wjn#Ejmx]
@uiZJUA
ixkp;YG
_W_`L
3-CSJ5
d?ZV!E
-UrJrrDk
-^lJTf
AeF.!}
QTEbreN
l2[`.B
YBJF;]8zn
$dFV+D
20N>=G
~N&*o%^
D&;S8o
GsyV5%c
=Sd_kt}g
I((<\&
}ZT~D3|
Yzn0\c
*l)T5B
MIZ3cT
wi)tST
gLAbG
GPOJ"S
g=dg^/
g;b3P@
|GaA1+
-(:Xe1~
@@mks-
1D\q,K$
B[6{,p%#
jsI!t
/[rq=I
&mR0WP/
{q{C<Qj
LnLRx}
!yt'B\
KfLq~-
BvKx&*
*8|#%\p
Q`XuCz
*dwZ^f
j-[CU+_
gm@`,Q$
Bmc5RY
e!| Xb
yS9`|{
^10E)[_
{[%>]sn
Y\B:p
EeUKy+
h+>@p`
lZss|f
Jbay.[
#v2dUqxr
2k.f;K
ad4\aR1
`jBZRE
a\4\aj1#
al4\aZ1
aD4\ar1;
mMd_7+
0PJef1S
xMWkJe<Kta
#Q+<tQW
|1BMki-
sCA}\g
x4mLCR
$sLnSg
~4qMW_
o{%c`R
yDZ<+<
-Zvd*y
_s^PE'0
:kP@;}
<LP3O"
/SYiq(
-E7&HXV>
1@\o/K
uMC%g|
_;}?QWX
Hk_'ZM
5jIK^54$
cz5_ c
=Qgf!j
PK3oJu
'z=ZTW,v
1|P%}R
}}!]6w
V#Fm(%
F'18;j
kH[kw5
<2a,fY
^m@l;[
L <{6v
^ZJ[Y?+
)P])Im
Cb&gMC+
BEf$XoC
4z%#6)u
bemM=R6
1FEk[i
j8~j5<D
'LbGl
py!jO?9
_?y'pC
){:a@o
a_Q=up
B>8t6{
*.@VPY
H8M/`Lg
k h-]e
O%_QTa}1{
%_4TaC1U
dm5Ayw
OeK6;)Z8"
,M*SVg
Hp%t~f
u%KyYn
*w0t#k
@Qu5 f
VQW(zfL
2u$H\LK
|B$f7d
G]O*@iA
yz_GoH
pf*/{D
)G$+1{
-T=-_d
0knBbc
z{srR"
/f`C0H
{)lwZy
)5Sn}B
v'W>}1MDE
.~A8 1
='SLZ&6
uf)$bN
)axN7w
:gkd1e
;byn4Q
Ex{PZ!
5ax^7C
&hy[>D
T Fy}%\
= TrsYR
Wi"T4{%
,d1UUT
#t1?d=ByK
}0\~<:-
Mm["-p
dADaW=
]r"geJ
n=^RLF
7/@lf=3f
OmyR>!
_YCoa_
lkyH1.
HX~{I"*
ECX<Mr
`f&[kG
dW&[-tkH
q4V'{5
e=a2Xd
_QyT"J
UaE"_
5R}g33
Z Rgz#[
5=qG,L
]]~;qDY
Xy%ph3
'ji{<B
f#=$E^
.*y'^c
Pl?oM}SD
3gD~4 D
{E1L5/\
)Gd-s#P"G%
8&eV}g*
a,.Tb('C
1h6ItqS
:1Mql@#
ysGZwW
BAKj ^G
4,fG7s
Q`Cjap
H.+@]U
E0J}$u
7a[gJay
=-ck0
*#uwo<
@SK5r#
C|)$QT
3$B3t
)o3h{7W
E&i71Et
RYibRf
+x6ExX
OOx{3./
]b+@rK
DkBqF>B
G}F.ER
-VE2[A
rZ0#X(H
:W0w'W
UBzbuZ
3-YY>l
fgqE6s
$LV4P
S:%RA#
MYg7-}
hB7Rvk
$B9OG@
2U&7.H
I\J9x-9
!?_1Bt?
P6KdrW
ndBpg52
Q"=AeR
>zB3#Q
3IQNQf
)7D[|3
\XOGK
^mAxS=
d[55$e
RdiAeQ
@R$H5pr
bBZ\BH
fgTEC>G
Nn@o3$
igFeFo
"-GY@N}O
dEF$L"
A01"5 .
?r-PEB
Byub0J
z1y?F/
0B[>u)
uXFC5M|
FZ6d+_
FRO>P-h
i"UJ8V
Z80gbD
@;FQUF
A*BYtcr
V&_bTN
FgB53+
TUwo.Q
1`.rn2
jmAhc9
%V<-e\
1W2BJGo
&NnYrX
,%S;*;{
jq&Pe_
YS[_y/
T[rx3h
DEoI)'
.H|f40
B4V|+7
qML<I/
2$Uj]Z
BK:8KYT
Z?d,>o
l>=p~Ydl
oZ2Gnk
1UL=)`]_c
aMq$@@
Xmml ~
BtUeO`K
e`O~iY
q@DIAt
?8*~#W_j
ykMMA~
N#vy/h
8zXor&X
(vQ`9O
Wq9HQ5<
Y#'IX
O7pllI
uA=Eo7
X^cLDBx
DpM?Xf
@kWfY|
$#!((K3
]eeb0T/
CW8m7)
jTTw.E
6tebg}
53}UzI
b Xj=s
JUb";1
|AN/M%P
"+hJ1]
+Q7e;:
"/&Q>5
U[6qb5
xEB#jbK
MWuXC!
Z^"=$-
W&vy0yS
]:vEC
Wa;:0Vbp
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
Wa;:0Vbp
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
Wa;:0Vbp
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
Wa;:0Vbp
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
Wa;:0Vbp
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
<?wHbr
1R8?Q;
<NU^:)
'(Xr"]8
M!r6XPPW,4bH
LCMapStringW
RegOpenKeyExA
KERNEL32.dll
ADVAPI32.dll
$$$+,,,
(((X000
(((X111
$$$+000
)))<111
---s222
'''#'''
---v;;;
(((7***
***D,,,
***D!!!
---v'''8
...g111
///u&&&
...g222
///u333
///b+TT
///b///X,,,
0008333
0001333
0002333
0008222
0002333
0001222
0002333
0002222
00025//
0002222
0002222
0002222
1))".55.
wwwwwp
wwwwww
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
user32.dll
0588B8BD-A653-4701-AA7B-C8AF862C20A5
0588B8BD-A653-4701-AA7B-C8AF862C20A5
0588B8BD-A653-4701-AA7B-C8AF862C20A5
0588B8BD-A653-4701-AA7B-C8AF862C20A5
EC89625D-9516-4892-B681-9CA5BB4538C1
%s%s%s%s%s%s
IDR_MAGICKICON
VS_VERSION_INFO
StringFileInfo
040904b0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.lnLK
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.Farfli
Skyhigh BehavesLike.Win32.Generic.tc
ALYac Gen:Variant.Ulise.338596
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 0043574c1 )
Alibaba Packed:Win32/VMProtect.8699a912
K7GW Trojan ( 0043574c1 )
Cybereason malicious.a9ade0
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.VMProtect.LI
APEX Malicious
McAfee Artemis!0B3E8CBA9ADE
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Backdoor.Win32.Farfli.cuxb
BitDefender Trojan.GenericKD.73779140
NANO-Antivirus Trojan.Win32.Farfli.kqmglo
ViRobot Trojan.Win.Z.Ulise.1097728
MicroWorld-eScan Trojan.GenericKD.73779140
Tencent Win32.Backdoor.Farfli.Ekjl
Sophos Mal/Generic-S
F-Secure Trojan.TR/AVI.Gh0stCringe.psvbc
DrWeb BackDoor.Farfli.131
VIPRE Gen:Variant.Ulise.338596
McAfeeD Real Protect-LS!0B3E8CBA9ADE
Trapmine malicious.high.ml.score
FireEye Generic.mg.0b3e8cba9ade0b3a
Emsisoft Trojan.GenericKD.73779140 (B)
Paloalto generic.ml
Jiangmin Trojan.Generic.amnmn
Webroot Pua.Gen
Varist W32/ABApplication.CFEF-7792
Avira TR/AVI.Gh0stCringe.psvbc
MAX malware (ai score=87)
Antiy-AVL Trojan[Packed]/Win32.VMProtect
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Trojan.Win32.Gen.tr
Xcitium Malware@#1ae768no16lui
Arcabit Trojan.Ulise.D52AA4
SUPERAntiSpyware Clean
ZoneAlarm Backdoor.Win32.Farfli.cuxb
GData Trojan.GenericKD.73779140
Google Detected
AhnLab-V3 Packed/Vprotect.Exp
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36810.dv0@aq28Ytck
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07H224
Rising Backdoor.Zegost!8.177 (TFE:5:c4oLjg2aC5B)
Yandex Clean
Ikarus PUA.VProtect
MaxSecure Clean
Fortinet Riskware/Application
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Backdoor:Win/Farfli.cwve
No IRMA results available.