Static | ZeroBOX

PE Compile Time

2012-02-05 07:43:24

PE Imphash

6058ac660564f64af764bdf1e4fe5d2b

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0007c000 0x00000000 0.0
UPX1 0x0007d000 0x0004b000 0x0004aa00 7.94096585609
.rsrc 0x000c8000 0x00008000 0x00007400 5.91181513522

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000c1b28 0x0000004e LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_DIALOG 0x000c1b78 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000cec2c 0x0000019c LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000cedcc 0x0000026c LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x4cf18c LoadLibraryA
0x4cf190 GetProcAddress
0x4cf194 VirtualProtect
0x4cf198 VirtualAlloc
0x4cf19c VirtualFree
0x4cf1a0 ExitProcess
Library ADVAPI32.dll:
0x4cf1a8 GetAce
Library COMCTL32.dll:
0x4cf1b0 ImageList_Remove
Library COMDLG32.dll:
0x4cf1b8 GetSaveFileNameW
Library GDI32.dll:
0x4cf1c0 LineTo
Library MPR.dll:
0x4cf1c8 WNetUseConnectionW
Library ole32.dll:
0x4cf1d0 CoInitialize
Library OLEAUT32.dll:
0x4cf1d8 SysFreeString
Library PSAPI.DLL:
0x4cf1e0 EnumProcesses
Library SHELL32.dll:
0x4cf1e8 DragFinish
Library USER32.dll:
0x4cf1f0 GetDC
Library USERENV.dll:
0x4cf1f8 LoadUserProfileW
Library VERSION.dll:
0x4cf200 VerQueryValueW
Library WININET.dll:
0x4cf208 FtpOpenFileW
Library WINMM.dll:
0x4cf210 timeGetTime
Library WSOCK32.dll:
0x4cf218 recv

!This program cannot be run in DOS mode.
Tdev+S
cdS?t>b
-HxV4
\f4x`N
{f@bjd
'ph[`i<
zx|YdCq
RZv!r!>
C0-!Zc
tPCWPMk
{r5o+",
j_!RP*
vxiUDpb
U50)83T*
TN(:HL
2$EDFDHVn?*
.(),02
Z.GH@m
,pgD5.
?P*Phl
<*(0D48w9y
15CGTX\c*
0d88&<<
5`+h \
x|8h8s
PTjptrRY
49=83@p[X
PZlptr
rRDHL;
4ZTX`&
<<PT\r
\N*@DH
l2t;x1
\*PXLp
=r<1@D
$(0AZc
RyX|lpx&d<
648rRY
r\%x|\N.
B((1,0
LPplp9
ri,04<
D$(DoIe
F&+<@.'
^N.8<@G
>HHH0Ws
H(8><
I$0p<@
]X1\d
MW M$.'
5TX`H
c@1DH2r
K,4dLP.
sXXpt|
81<@\n
{$',PD
e0P@xh.
TFZ)QQQ
\n1\`)
5h;p&t
[jRRRcl*#
/7104S?8
<`Rd;l&
5R8/H/R2p
[HS1|r9y
TTT!R)
TUXU`2
W1 W$*
Z,V0V[
fWT*OyW&
Xl$(0
TX\z!H7
<\\`\R
|3DHXh
T3X\d.
L@PT5\s
(p)t3x
` `(,IN*+
Ddhewr
`t$4T
S.(`5|
5 a$(0
r8b<b\%`
r\`dlC.
t748<D
K0Tt_jp
T4@4PS
4@(WEQ
"p6L.nCVP
pDjX|/
70HHHp#G
mFoyNT
JJ+J.
il2*@,W
Q*Q1Qxe8
tS^ujy
T$,4`}
6bPb]ba
'6.Vatg
[#$(,0
C^W,"0-h
r9lptx
HLP]/\
+]:SZG
[@`Zj_{
u*V|#3
yY;j$&
u4wA}6
W.#^d)
$ldQ$P7
b,,P((t~
q7&b?0
jc`Kb
Txtplu
PONKJcB
J!``.J
]Sj Z~
8_WJba
/^0Ma_
=,g|.i
*T] h(
A<[_<X:
O9!<Uv
SWEB!
h^f9-b
^Gjz-uJ
zhtN!u
woVW@9
uV tO
9u(vEVS
F)71J@]
8&g8lS
9H*Wt!
)9MY"tQ
>"!SS";
{@*?_ kX
AZ6"dec
fv`Mo$V
jBFZejb
jHhpr!
"jAua<
tv:# y
" R\]gnMi
@K`B#
|tld\/
w<x-B^
h}xxQ0
}>v`~p0g&
EYS[(T7
jo8u1.
F-?Ht-?
]~W$\7C
@~20Fv
'X. vCX939u
VEY!V!Q
W\)jAo74
oxx]xv
lh\6Xa>
i.Ksi.o%u
=w|Jt~(At
{.R7C
>8d0Xf
<;f99t6C;]D
t-SDR4
#<9w"L
.i/C%V
j@j ^V?
kE~<0L0
qGF`Z&
dH0;oa
an_ItU
i*Mx&X
"N?tu\q
fbAi+M
- 9} 7}
_/9>t
[[DSW1
w|k?8t
r9B[U(LT
(I\$IK
q_SAp=H
Qhda 
l.2S'"+
AVWPAuI[@
@Sj"\YTD)
zpRB.\t
Jaj\YFI
$(rrrr,04
\9999`dhl9999ptx|
`@eDH$
v4;5\V
f$L8`fB
ipLt$\
_ESvP{
;er 8^
YTX%a!*Fv
F67Dat
@R8]>s
tj.<N)
UQPXY]Y[l
h)a.KC4
WAq8!k
&*-K&@YpY
^g,YY
v!}#O+
R&=llg
P H,}&
*A-|3\
]FNc'i|
y$c~@#
)y.BiU
V@P8RZ
wAk0V[
ac2Mu7
TNP/)w
2>`0V-
!K{s$R
Y'J Pl
Y$"@>GJ
ABatk1
Fa'z2c
TPQR;O
pduf@,{
/Y8|Zi
PHQ!n~:
SRWn0u,
M&Sb7u
tKq]=r
H40`!h
bn` PK
^j pH)
{bwlt=
*zI^r8
`a+eLMq
D<Bn[DQH
rRDP/GX<
$,(|Qx
H*9MsA8
0PKt>@
U:`5GD
UfVF1
(JB5$D
/HY2@^^
zd}I2;
XnWyD@
o767ni-
Io&a(o^
;W;4T-
t5q|-i
!!,\Fp
(yyN1:1
:$z&<$
KPR\SQ
dwhV5Bb}9p
)^dFA;
1|<\uEF
Pj5C%SpeSQu#gA
{jq!7`
vCCR0r
RZ~D
qLeH#4
d<`+M\
!9B"eHk
xlF%52zO
@jXC~}
w<@0;xr
%kFeW#p
T;VLuq
&8mN PX&
l`51P"C
x=it [
p>ccO
dthWp]k
&{j\7.
j*P3.3
O(B>=)&
F&V(RW
_PYp:P')b
Vx>4>u.
lpd1t"/
+9*" ;t
CiG.pt
Dx(fX03![H$LQ*
#SDv0%
DGHuANJ`]
8crtsgtM
H6E$8VD~)
VZB@ba6
7T=c!M
.Mf=+A
dW8[_I
eW:F2[
0SR/P@p;
gL8=`&
Z8PBqe
WFeKIA
RSjIDEGW
xC4Ji)
0C/mV3
@p2<.2
=ERCPt
E(: .h
Dl+Ghp
9Z(MOPhH
Y92v/*
~9&NHQ
U`tm*lFT
F%OJ-0y
4{9NHc
,G}OBZ
WXt8|,
_F)l(~
LC![bMK6
->|( m!;3
&?T\+Y
;@VR^b
/ .ti%
Af}jah
Q`>(0g
=2zHa?n%
#cr"qR
JWu91
c[Pa'c
81Qmt2
zo%A_eKKiK
 !"##$%&'(
)**+,-./K00123456
5>?@ABCDEF
`t29t :t
R"e7Sr
#KJ!|
+~<+^@
UIZ@Br
h68*H;
El>hBaU
k-9Hva
/(mp`7d
B% 2(0
4v0h'2
FL@VCX
BtI:XO
`NNn#P
42Hg'@#
FkRI}
"@Ce+
Y?PbjR
]Q4YJp,
-i"T`d
5#'Kw3
f5zQu7xmA&u
K]rpDZ
VN,QR,0
~1VC3S
jtdy.
ch.JAU
hQzD|Qf
HYnm*
FM^AVV
8|UR40
B9s u-P
jarfwHV
~& \%i
.N(Qh3
+dB.1"+
(t|<"tx<%tt<'tp
l<&th<!td<ot`
\<[tX<\tT<
_'rn{_C(u
5@PC`)
9TQ!"p
'<T$QI
6BIK04,5mK
C1H28u
h)p^\68
y*S,@H
q6h`JV+p
k!^!%8
$},{8,
L5UPNK
'RPQu2@
h[t,&r
*7#JG(
>My)jGQ
xs$Cuf
V&GFw01O
${F$d
>kwo/
8ElQk:
(pL=#u
heLOPi
D:4P]a
Y/6Hr5
Ka~?uB
tRJt6J,
LYu*=!
0v#b?H
%CDk(f
G(Lhz2~
-`v`R]
H#Li_RVJl
!QP8WY
M]"xQRn
[h$c.Ss
)W"SqQ`
)a%_mU
4Mk*$$
nWQh!\
W 0s5hY
,N,j)e
,Vw04G4M)
9r~ V0
)siZg6_
PytMh\
oM!L@z#
N<I@*g
]P|&@
brPKSa6
4$d:$%3
R|MtI8
id]x0t
=]'X=A
)"v0p!
JDt@;Sa
BDlakica
O qi(d
Hk-P{3}
4<?3{u
zK@Fr'
``V\'K
Zp]u53
-`V\z\
$+^{-Z
]/!_.
G?EsU$
JHt\)
Jr;Q},Db
_t*]t%
i7`t 8sV
@>Pf&A
Ld^}^}
EY]qE/k
I)*+B77
;i<:rK
n(cF,|
W`+lMM3p
4<>t
y9M(tH
pE7G]|S=
-Rr<2aB
WpK2M;{Rp
a4UM`$
!HRN[:
$RUu!
pU2aH_
Vq@~PM
if`j dQ
37iB**>
Q5&.ib
i8JX0 _
i488<<@B
lfJ80FW
HLPTX\O0
Ehr<;
w_@Z{F
-?u5[rG^/}$
t+i*{$
fJXeQT
"`M0^zE2PKa
F4oQK
t4~d^~,
m}hBX8
uZzj\z
+A4;rU
BD=8/F
W0q3*^
~!APQ
88`u}l
KmGFg'S
,,m8H4
l9e|M|
#H1Q+/
[C0=su
_up&K
6\#v</
..VA{<
W05ROl
JE X>C59f
5h}jX}$
>`E->V,e?
>%YwgSJW
=$DnDK
I0IbgB6
~a@ga@
[Xh(G~0u
%gh,#USG
tqm_$P
2@b6DP
]N.-!h
CT1x7|
q,(@-X-
[F,JG\
C9P<t>
eWr%o&
19t5mA(<(m
J7Q2IN
NoD$y
RSPVWV0
}@V#<]
QRIC{*
H&~G<+u
VQ!EN0
*9TGlF
=B~$]\
)'V)Pp
`S(d^RFD
vO1S7)
5t.,*P
j.J ,P
'0rM(x\8
a$vaaQAe
3Rtonnnn
rtjAt^atYStMnnnnstHHt<ht7Nt+hnnnnt&Ot
9rYPyK
fU:uK
l=^QUyIM~
\CJ$]f2
vA@'9S
a g_GQy
QZDQw<
Xp"a)"l#Q
J7RQ_U
RI/R$|
t->@foJb
hP98v-[U
$@@"|p.
{/2F6tu,
iTRWR[B
g%!GH]
%2!f|N
B`hC4R,
,TN>@&
v7;V8R&4#LF
,LszN`i2>
0-#.vE
KSjb#.
5IS:8;
$| usG
X#WS2X
S'I,--*{
!hL(XMk
/Dk08$
<>kDe2k
4PPsrr
3 $8<X1!
+8U-^Aad
t$0WPQJK
AM7PFH
o,)Uz
SWO=H#
RAO<=`
aTX,ty1
k@<DF:
H,*yF
U`*(<)P
$`Dunq
ux-5i"
IwFxcj
^ @+[yRRM
V=A"F;W
>L| /S
N|?Q7C
uKl<+}
{?j~
V'T3?@ib
{P{M[O
Vh=L+\
RW4\a4
NVRWba
tNc2>&&X#
/T$dR
+V9\ueF\IZ)E|
iV:E(d
@D`q#u.f
^Z#DWQn<yR
)-$#S<
t%^TfD
$jhxIc
V%QQws
171}$[S-<
5@HEmCy
i&40<@
YhQ6T=Ae`
W q:~V-Z
*HQD:A6
0SVQoS
,5XlC;y
7hd2_H
t{P/WI
N9>~$d
[CX>H&
A6q+cb+5+_HS
~r08@R
\/{u.:m;
IUhNh3
Xl7U20x'U
k)vRC:g
mmY8hRV
AX5Gr$
$`"tZ3Ie
PH%X_XG|
K`h3Fp88
!$yH,h
Cv4$Ex
t-;RFj
~BLPfJ
2k'/8
)1t5)S;P
Bx(=I*}
*-~mS0>
6(Db8O
y^$<4VM
Tejd`u
Jp)$uG=
sL$HDA
>|ok/S
r0iNTR"
Vp6Ki\
u7a\ `
Ht2Hub
PZ;(TX,K
tk+1mM
:-9ycA:
=!C''$^
7JbBN[h
F>RsX'
$`:i#yF^D
m!_ois
\~Kt<s
QQBBFJ
9(tIFEAB'
G2gpZk6{xvZ
h5e8K\
JR8p8>Cj2
3~a@CG
CJ^z~g1
)er1\e
->$""?m
*g[AQ_
V, ^m`
Q+`!j
P\[Zuh)
$$>)ttX
P?=#@f
^APIV.
x+AREV
$sMJPh$8f_P"
jr@GL=/!;
R>cSP>
@tY%5r
)tH({\
?$F5CB
?Ao!g-v+
'<wbR3
j1@AG4
ppC-{m
`/Y;Nt5
P/ $!])
8+u gi!x
u@:/)rB
*OxBQM,
E}*RR1"
b?>@Gp
ad allocation8CorExitPr"es
{Unknown exvp
///#&P
u6dcGZ
TZCs'W
oBgS>
FH:mm:*
SR)Augus
}k$s'Wed
:e)IJKLMNO
FTUVWXYZ[\]^_`abcdefghij
8vwxyz{S
t'7 c =
?i3>l{
m*sSk
+FVfwS5
px<y z
5FPQ 8PX
_nextaft`_lo
>%_hypot
Apld?<0O
5ptzo6
\5JD#jcUTF-_
16LQUNICODE_j
<8bunz8
l,kg<i
^@En[vP
D>V:e:
3\@L4
ZEM-'^
o~l$G~
^\sY0:Rp
@~7Z8>
fe')lW
P\?T@*J
|u?!u$
"9>>?.
Prr?=?
@N.>?>
dd>?>@F&
@F&??>dd
dJ???@F&
bu?P/Y
_p2rr
}N@ O
]vQ<)8h
74>U".
[|)P!?Ua0
y1~?|"
?x+s7
k>? #J
v=o;:8o''
76431
Nno0.-+vr;
o*)'&o
$#! '
~~}o|n'''|{z?yNNNNyxwv
ovutt999
?srqqrrr;pooon
vm?llk
g?gfe''
ddocbbNNn'a?`__
NN^]o]\9
[Z?ZYr;99XWWoV
vrrUUT?S
MLKJoJ
?5Od%
n{;7W
?|I7Z#
pg)([|X>H1
AxuN}*
r7Yr7]D
&?~YK|
:]=O>\
CqTR;?b
1WY$?]
?#%X.yo
Ge/Windo}
.UserObjectInform1Wf
A0iveP
ageBoxbU
i9_/T|
7W$gNRE\
@UQLy5
`~A%My
< Complete
lor'[Class H
ierJy Descrip=
BeIArFy'';
c threxgu
nXru!it2
ex. deKf
BGinBi
c;`eh %W
allsig
N}?| x
ir(jdis
0TosdB
/efaul
XdGpa-
\XTPLH<
<D@<84
21#QNAN
'LRIs\
emaXjv
t@ahitg:lV
qA7OJTW
^x:c'e
.dRIsT
R~wI6cs
8kernel32
alWGb,
luginD
w s:&*/
;&cmO7 ;
ByG//q
OVG{a{
?s?ZP{8g
:2?1M+db
N1RzIK_
B.876B.
8''''7654Sc''32
CCEPOMMIT
KI~HE\
Anyrdc
n~iaZv
BrZl<B8
vOuhid
_Abori8l&r
erokelC
~JT>Pah
=:MBdpWL
VietmX
"bundspb
word*G
of p\n&c)j
recognZa0
P<~ {} qu
|3'| K to
bpty A7
POSIX
`t(s) P
@c gaP
> 255v
Gbcu6@
PTy"xW`
, 32As
DEFINEone0
Sgt.Dd4
GBZGCC
02Xk#13W!W
2H/gXl
>,MC{7o
mms7s
`wG?\$
_G/w6b
?O3{2V
SbsU/i
':/YR{
KkR7WE
-Og?D
//RoR#-]
]-K?G>
/37jmMJ
MOOD(Z
b-#GX!
/OU'';
VVh[pG
VAgG{:q1
B(Qc%S
~{XsM:
)~LXw%
M}XW?E
{sg^bW
uO2pCD
ST&xOS
Z #W1m
ICMP.DLL
cmpCQF
'g{;d=b
m'g?#X
$6B:6p
advapi
.?2hw]
OZ{Hg
Vt! (l-
yQ\Z{0,Wi
?NO_START_Ol
<lXH4,
p\L8~$;
I7/!5A
CPgR/S
l/mV p;y
Ixx@o
dP8 yO
Qkkbal
<xl`TH
lP8 <O
$--%"!'
lrFO/f
VRspLsmov^
j .E6H
~ OADgZ
i*t7",
L]WY'FO
R\O1Y%
zaIZXQ
W4ForS
G(Heap7J
oepACur
Id&MulDiv
DeWide
tiByH(l
FlushBul
lp32S:phoZE$!
St4CY/
#!etdm
amPi(O
^acZ)%VV$
mjoC^pTdO
|la@I1
E`AiAddT
junTok
Shut<n=
]pn?)
`A9Arc
W,Task
&tYSH`
ycSn'v
py'MaA0
|,Eg_No
Sub%CR
dTGmH1
kUBT;u
Y(q+uC
rp0Xpd
`[d!Visi
/0g\u$s
XPTPSW
wwwwpw
wxxwxw
wwxwxx
wtdpew
t$gvgfBG
gG@xwwp
@edgvw
dtvv~w
||vtd w
e$gFvwxw
edFDdT`E
wxvF`x
wxpvG@
xaxwex
xxvGge(
wfggwf`w
wwpwww
wwwwwwpw
tggggCx
Tdtv~|vtt%
xxxxxvB
pvGxwxxtvt
xxvvw(
wwwgww
u!!#Ca
j^[[[[^j
rG277@71Dq
-<LNz|
|zN=<&
*<=Nxz
zzNL-#
&-LLNQ|
'///111
t0NQz{
]R;UUu
^!!! !C]
uuqk^SS^kquu
}GA!7
$_wwq^q
uqvwwwwwuq
+anm:$
&_essd4$
t>}b/Z
EEEb>>>
EEEf777
>>>;===
>>>;<<<
===6;;;
EEEy@@@
FFFnRRR
>>>;SSS
@@@Eccc
???Ckkk
@@@Eqqq
===5ttt
===8aaa
>>>:666
NNNCWWW
HHHCRRR
UUUqwww
QQQqSSS
UUUpxxx
VVV,aaa
IIIB___
}}}/iii
eeeu}}}
hhhwxxx
kkkIddd
[?){^D(
TA2rD1!
fRAfbH/
yhYmsf[
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
GetAce
ImageList_Remove
GetSaveFileNameW
LineTo
WNetUseConnectionW
CoInitialize
EnumProcesses
DragFinish
LoadUserProfileW
VerQueryValueW
FtpOpenFileW
timeGetTime
H}AU3!EA06
!s7BGW
=IP?Asl
DH(S)\
:L>9HX
gy0>c{1
(+gn|V
(D`)8<j
sdaVpQ,
xo1$VT
w4s_/6
$=0[wJ
"YQ7'i-
j]zVn}
;TN#hc
y;'[;$.
#S;Nju
cMTcA>O
}!&(o2K
"ok.C
HFMpZY
g{pFC6:
uN3kH~
D:^z{[
[x11US
?9si4m&k
rS Xv]
EKg:9x
'hi8 ;]L+
QK%HM.
<)rIv'
SQeD\!
~"`=Quz0
LPC%`5
=#{08o
+{>yr-
QJk9Kb.8
^49W)!S
ZGD>WM
jb!LXP
]jKo%T>
s^ivjUF
jSNbw
4}=iv8
ew0<K
\eWH)1
)iS%ZA
a,%%1#
A3'u2{^H*A-
[jt,mNl
kSU1%
I _{1O
[X7O`#I
/ec5oN
+iEbu-g
W|%.2
GN+QAf47
_MpO/_
+v'g#I
^G:fd{
ijZ=g
3+/sZD
tNilnQg'
r7[jY{
QKM>9/
EBfMpTh>
nF+9k>
`G,p2(&
uV# 7c]To
4N|7b:C
I^Q~cL
]U.GL2
wm rz-|n
nvO4lJ
F{SbEl
h_UI&V
:bcOZj
Z|K''&]
a5/zcI
`p&B^g
>?&>n6x3
0[N/zUH
u{_(=?
vJB0O8SO
kgt?jw
X7~6ej
ZfVRM/
I!Z.A
% XZMg
rK_Dp$
'!cK'#
9@a^Q>
e# 7}n
dM{ dv
VfoPsS
)5,0_R
YAo@Pc
#qG\93
X1FFiB|<a
72G|i"
U*p=ML
(5g"/
a3<60rq<v
f7m@9
R!9sim
\_E&77Gg
T(Ok^k>
s)A&cgN
Z[(>F8
xB1o-I
@04DjH
hk1aNs8
^S>iE.D}X.
aIU|?9
(wvid7d
O"^J rl
"lrC{N
oFg&4'o
5'bm7#{
E'!A4
NK]>.z
?Ea{m0
dul.mm0 *
4%t9`/O
8C-_Dp
m8LwD~
>u&?;x
}k0z}L
H"O\8+
Q~;p'O
T0Uc.JX
SY0+D
9z'uoK
`%mFW
)^X{nN
YH85h"
dC%MIY
"s?.DL
qq~.]0(
~3l&J[
mLbarZ
5.wvqe*u
]c|)euf
LLF~ml
![u;('
:Nyq1N
@c|5;)(
h\rQ6d
+g<s8TW
J|yB*
\>{xBm
h{'grR``"
^8w [grY#e|[11
Tz6B8w
|fy&!
{Z%c}>
FEu.aR
g7Q!E@I=
SipBVy
d85m}7w
+63C~6
XU,{=dP
"K)5FE
^uA`7k
#uI@>E
|T)Ikv
Eb_|>+
,Uxd9>Z~=K
-Q2\.2
/+cV&
3G#E~se*
`jgF`v
hbAAT#
H;fi~w
zoTaT`
`X_d8
4rz%qp
\5\3e(
@85mm+
LYs0S"
l')j=Ge
;s^\QLf
\VOL*
Z:fE#?
*bE0zBha
X>N&t
(|~j"N> l
,!.#X&
$Ew6yu
<dh.QX3p
SR`XYD
)3M~6d
t,45;E
$=gL9?
o2z1S^<
V83)e"
U"dPI$7v
:DNlEi
`` ZlF
"'T-mt
CqWN0cZ
D1a8t.
joPPdt
^g0IYg_#
-%[A$>
]FGr!i
3" 2ZA
}fx?ePdxN/
I:#NP1
H`fH>M
q>:"#l
{,.Sut
I ?F2)
p!6g#1
yi(gp'
OjfHY2
&T"f/#
{Mg6]s=
\&|mBu
ghD<B>
+"Cj;@
hn3:6"
9 #"]%i
'M)O]o
Nwl(2q
h`C)9,Y
1I0;DY
n3E2$&
m`WZ$uH/
RG9Zez
h+(Gs2QC
JQjGBS
|-u{*c?
,yS7f.9!
~KOX^4
QDL!">v
l5EVA6
mgE@:0
Crt7~v"
r95q=
oV#L!/
>G}dO7\Yq
\wyX?OW6#
uQBn-dx
6XYpsF-
uZ\D8J
_2R04w
su0kHM
PL?>5P.s
{M!ZZd
V1!HRE
CKS*,O
*po=!p?
zCU={k
jQI^hv)8
{BbVztR
jQj<P%T
pT<%cQ
/IN+*9
]YzW]Z
2BS#@X]r
\ t%bA
N~XJU~i
3^7v1.
IjyAH;
hXG s1
9Cdo)G
bKwMPm
'f.D"yb
Qzn8&]
*Uf(HO
1x &+
sxsE!p.
@>pD;I
z]*.6q39
jCnFv<@
kg Z@S
_@p!S=
7CQNnzq
zS8[h3-c8
',JXcfX
.RV;fw
xjX!|Oj
>uqg-<
M{hwz^
Cx>>]k
r=W2Nq
4weM/ht
Pe=sVa
Dp]M~N'W-K47
IBzi}*
6bHo4(
bwG1%$f
T.adj&
Tz}JG\
$ctxSAwH
l?-MGw
/um^_P
,mbnb p
!O<2^<ycx@
MNU@E~GPq
2:'Y%;
@j8Z t
<Ea4=kJ*A
8E.(HzA
<^](Ig
K.+c-F;
^A^:<h
,0vhq?3,
?$o-q
:D6BMG
6tf|j}%
Op1m! ^/
eI;f9W~wr
P5)2G{
Wq)O_R
s'!Z#[
VRJ$@`2
$OVtD2>
/!NZvUX
uMW0dK
52\I)w
}D~un6
ej^l#k
*.VOVYh`
\fzhz@
<Y?!RF:
U,71Fk
xahS=x
mL(W^b
@"o)n;o
{P0x]$
V64i-%y$
Rv]O="
}sVz3a
FTxU*~
? Fy$>
{5WKo)
ct,'N,I
.@kewy
,@`j:~
VZML\c8
Gm2.u#
DUm)D6
>VsOU[
,(QF<i
iU%Uyn
9gn0-9t
=nra6~
Afg-jH
BC3NPe0f
E1672
No$US6
0,T]Q@
zEX~vO
Uk(HRj{
^_k57L
S`%;0p
F';:"
C7M[q/
W`a1N
GdL9q
2Bx=ox
-cm'UI
pa=f?h
O=eq#,)
b{*4Op
wQl99;V~
Dua>sm
>n;CJh1
M mW}(
Ud:!y3
]D0SG\b
OIug?FbI_
0!Rj%i
+]!&K9Dh
E(v';.J
%6,8iR
m=eXmQ!z
*T+-K2]
R0gr)O
#<HjZ`
NUF/CR
t|%{.^
Dj$,HJ
tN_^uJ/&
mf/93)
g\DK';
oE$M2m
?G,j*J
"] = V
;l)lZeA
w,bs`n\
_`cQ?}6Y
J4[Fh@F
.c{yGd
{}"Upx
M&*{vc
$P:`G#l
J3_f&3
rEX#9A
C6BZtp
4NL;vl
hlGR<o
}S19Xi
wS"oJ67
kcwGbxh5
$PFJ4W^q
sM\gOq
Ky<pCwI]1
..@`@Eb
ji!_*{
_MB^Y#
;RcSZLW
W!4hDX6
!q`g8m
]oEJxx
zhW,id O
lLq?\4
+H_J~*
&hoIy-
92;@uPL
e0f< 2
z9.piEz'
suTE{D
))5xNg
x_bj$,K
xI<N`8^7
\H["}q
T`k^_w
q:=`8~(
*<P68Z
Lq_H%X
b*Ola3C
lZsW}L
Z\Oq3D
RfrUk
3?sDyh
3+*N9B
y(==5)
^K%+]E
{{Vc]G
p!^Qn
c_<8ohJ.
b0u)Fj
CY/8!C
ewl+5
>"nw<0
1Yq8=4
rS"vl
rkP|)u3
,uEPZg
N)y`2
p*x[0t
d%V~\$,
n>J[lyA
xVE5s8
?i\M`ze
G,a]6fWLg
MacsjSK
)cr\U~E6
OR'QwR
XHpeUt7
O"*?cR
:<g/G]
TFC/~v
i2FW_6^
6yZ~yU
O8fXakL1
ABR>Nl
?g<cE
V1Wt'1I
)%W)31'
s(H?:
%mB9~#L
h4!'(r/
]9`6{&
(U46ah
PVm: c1Vh
/):y_6
RrIXfc
;IP<_8
yh[=0f
_1\OW3
Su<d`}
"N)2Nx
2gPtfc!
2d(g2/1
(Z8t6N
+w-Gk2ot
{%Hm?s!
>xg^nE
RM:3=_&*
w7Ee'T
XF*eBO
UKP-O7x
<O8!AB4X<
/AT8\U
#jl<|^FO}
9)Whw0%%
;0`Pod
BJSszd
Y0/IN3
m\/G:~
%Vl*rE
=+_OL9
x>*"1Q
,]"J'|
!"FSdnn
k8XqO}
:/=#m9:
PU},\`~+
[+2iA<
([dI&}
x,MZ`]
f}p79l
Q(WNq,
$Y^mo@
;OwO%{'
l+_j'Q
JPu#Oe
xzYl;3
Cbp Mx
/Gaj^#
n;R8NU
Tr6dK*:,
7j!hcx
Vb9g#}
#`}AOL
"[TL?`U
n *QD;(
}[Y7*R
et^*O;~
Ek6[KsA
b*''PC
&b!&A{
iL>?EK
~#Y[7S
A.^YBD
IruM|kV
|aJ2;P
WNbt@J
<&%ES%Wcs
wD+9,$
V`O&2F
k?N9A*
mmO-F[.
aoRfr9
n[$o]g%
X#gD#i
Vb8'{`
*/RMPS
fL$7rOs
rXs-9V
bcnKiZC
0r%,b;
I"6.|~
PrsqE^
Nm;YS=
7T^ jS(
5%#u~/
I3G^c(
)m^:"!
:IN~`V
zN?()yt}i
fdv@{#
.!GjO-
_|`<z`
OwoZ2(
9qX$yI
C1]Q%D
n9^vo_
(4FCeJ6
"2qF)
j6PP9J
>>rShiC
>)T@2K
bM17f8
01A`p
vt-f>w
k(+ TT(q
#h@sb
o#],(
p3D^J$
|&B~<`
]7:wm#
%ym`C1"
U)K3ZCSmGp/
H7FNa1|
<J>aoWw
\ QjhP
W4%_pt
.R'i&r
_4h^WD
OmNyZm
zX,`Tp
_Zx;vd
So1X+63W
#~:AW
lxy8N7
(M)`j
b6.FaTe
T-b<NTz{
1%{h&e
2{<_py
jS)BwD
X05sq#F
g(Yf*
USQ>zz
[0FiWu.
Io.x:1
f)T6Oc;
2/~+FU
ylN*+Pw
kz"q("a
$:*W)|
X3W'Z(
+-8~WP
fR-3F(
mg"&>$
uJa~L0o
\2wfk)7
-8k@:1,V
BN*,[\
1K"n5%T
td?:g)+
IEZ#0 H
aSl%|M*7
}F9=iUPF
e0P6#s
{b+Q>S
X)@-[k
#s:dP
n*v;m#]
>\nr}bP
z@F^YA
(dNWyVq
@|C]-X
5P=a$K
pEV- /
f:5mjqr
f4CqR
]^bh3}$~B
^\5{%h7D
'CaXg9
|=2&gBa
Uwh[c>
[0nfV7
reQWoDLp
+E{"G
@HhXD
F<j}]
h>F#/j
"q69CR
JJ<Y$&
N~pzSC
x%GL(q
8D0MM&v##
N+qxjN
+.abm,
Ghv{*9
2&q|`u
<Fk&oV
E_)3O>l2L
5pN/cL
V9`y1
:+t;m4
$bhZ`>
Ed+SWFG'
=|Sj7
u~wVIVW
~k9#[5
KA}4QX
o$E(0y_
g,FS)YmR
seGBmE57
gK/ozX
u7/.o2
|(b^+U
VfEoZ2Oe
Ahht^
VC*BW&,
;Go3DR]
!*]@,1
Ie@'aEh
uy>M9+p
C7DSL>Q
=4UHMf
$erogl
0{qhlZ(
R;5E@:
Yh#eO<
\vh`jmY
CmI/Y2&j3
n/rEPcR
anxX0MF
GB@jqa
PrZIIB
y=SlX&el
tura<?
Yw{@'B/
?d-;7o
1swUe(
,_;1y&j
Ka! 15
o$XSf(
-v-(zC
F+*)eh
\^o:)>
M.^;*-Gh
_TH)T/
Vy")HQ1
Z0aok?
\"_#^
}Os6$4
hNkgWy:
mnP"Wt5v
T!B =)
2q5PB$
R7f~*Q
X)JvqH(
~$T'Qz1
8fnmfe
(F:U-g
3>)TCV
;K=IiK
%wq;IF
/]|m-(
y:@Y6/
v&VAU3!EA06
VS_VERSION_INFO
StringFileInfo
080904b0
FileDescription
FileVersion
3, 3, 9, 0
CompiledScript
AutoIt v3 Script: 3, 3, 9, 0
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Nymeria.4!c
tehtris Clean
ClamAV Win.Malware.Generic-6651791-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Dropper.bc
ALYac AIT:Trojan.Nymeria.4279
Cylance Unsafe
Zillya Trojan.Nymeria.Win32.935
K7AntiVirus Trojan ( 0056316d1 )
Alibaba Packed:Win32/YahLover.2ca84cb7
K7GW Trojan ( 0056316d1 )
Cybereason malicious.b52847
Baidu Clean
VirIT Trojan.Win32.Generic.XTX
Paloalto generic.ml
Symantec Trojan.Gen.MBT
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Packed.Autoit.NBT suspicious
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.SBadur.gen
BitDefender AIT:Trojan.Nymeria.4279
NANO-Antivirus Clean
ViRobot Trojan.Win32.A.Agent.690283[UPX]
MicroWorld-eScan AIT:Trojan.Nymeria.4279
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.Siggen5.59949
VIPRE AIT:Trojan.Nymeria.4279
TrendMicro TROJ_GEN.R002C0PET24
McAfeeD ti!9AC31870D3A0
Trapmine malicious.high.ml.score
FireEye Generic.mg.5fb6829b52847d87
Emsisoft AIT:Trojan.Nymeria.4279 (B)
huorong Clean
GData Win32.Trojan.PSE.R2WKDE
Jiangmin Clean
Webroot W32.Malware.gen
Varist W32/Trojan.IJBN-1595
Avira Clean
Antiy-AVL Trojan[Packed]/Win32.Autoit
Kingsoft Clean
Gridinsoft Trojan.Win32.CoinMiner.dd!s2
Xcitium TrojWare.Win32.Hider.REXR@5364l6
Arcabit AIT:Trojan.Nymeria.D10B7 [many]
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan.Win32.SBadur.gen
Microsoft Trojan:Win32/Phonzy.A!ml
Google Detected
AhnLab-V3 Malware/Win32.Generic.C4294381
Acronis Clean
McAfee RDN/YahLover.worm
MAX malware (ai score=80)
VBA32 IMWorm.Sohanad
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PET24
Rising Clean
Yandex Trojan.GenAsa!i9rai7w7/WE
Ikarus PUA.Autoit
MaxSecure Trojan.Malware.216104585.susgen
Fortinet Riskware/Application
BitDefenderTheta Clean
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud VirTool:Win/Packed.Autoit.NKB
No IRMA results available.