Static | ZeroBOX

PE Compile Time

2012-02-05 07:43:24

PE Imphash

6058ac660564f64af764bdf1e4fe5d2b

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0007c000 0x00000000 0.0
UPX1 0x0007d000 0x0004b000 0x0004aa00 7.94096585609
.rsrc 0x000c8000 0x00008000 0x00007400 5.91181513522

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce6f0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000c1b28 0x0000004e LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_DIALOG 0x000c1b78 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000c2b80 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000cec14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000cec2c 0x0000019c LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000cedcc 0x0000026c LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x4cf18c LoadLibraryA
0x4cf190 GetProcAddress
0x4cf194 VirtualProtect
0x4cf198 VirtualAlloc
0x4cf19c VirtualFree
0x4cf1a0 ExitProcess
Library ADVAPI32.dll:
0x4cf1a8 GetAce
Library COMCTL32.dll:
0x4cf1b0 ImageList_Remove
Library COMDLG32.dll:
0x4cf1b8 GetSaveFileNameW
Library GDI32.dll:
0x4cf1c0 LineTo
Library MPR.dll:
0x4cf1c8 WNetUseConnectionW
Library ole32.dll:
0x4cf1d0 CoInitialize
Library OLEAUT32.dll:
0x4cf1d8 SysFreeString
Library PSAPI.DLL:
0x4cf1e0 EnumProcesses
Library SHELL32.dll:
0x4cf1e8 DragFinish
Library USER32.dll:
0x4cf1f0 GetDC
Library USERENV.dll:
0x4cf1f8 LoadUserProfileW
Library VERSION.dll:
0x4cf200 VerQueryValueW
Library WININET.dll:
0x4cf208 FtpOpenFileW
Library WINMM.dll:
0x4cf210 timeGetTime
Library WSOCK32.dll:
0x4cf218 recv

!This program cannot be run in DOS mode.
Tdev+S
cdS?t>b
-HxV4
\f4x`N
{f@bjd
'ph[`i<
zx|YdCq
RZv!r!>
C0-!Zc
tPCWPMk
{r5o+",
j_!RP*
vxiUDpb
U50)83T*
TN(:HL
2$EDFDHVn?*
.(),02
Z.GH@m
,pgD5.
?P*Phl
<*(0D48w9y
15CGTX\c*
0d88&<<
5`+h \
x|8h8s
PTjptrRY
49=83@p[X
PZlptr
rRDHL;
4ZTX`&
<<PT\r
\N*@DH
l2t;x1
\*PXLp
=r<1@D
$(0AZc
RyX|lpx&d<
648rRY
r\%x|\N.
B((1,0
LPplp9
ri,04<
D$(DoIe
F&+<@.'
^N.8<@G
>HHH0Ws
H(8><
I$0p<@
]X1\d
MW M$.'
5TX`H
c@1DH2r
K,4dLP.
sXXpt|
81<@\n
{$',PD
e0P@xh.
TFZ)QQQ
\n1\`)
5h;p&t
[jRRRcl*#
/7104S?8
<`Rd;l&
5R8/H/R2p
[HS1|r9y
TTT!R)
TUXU`2
W1 W$*
Z,V0V[
fWT*OyW&
Xl$(0
TX\z!H7
<\\`\R
|3DHXh
T3X\d.
L@PT5\s
(p)t3x
` `(,IN*+
Ddhewr
`t$4T
S.(`5|
5 a$(0
r8b<b\%`
r\`dlC.
t748<D
K0Tt_jp
T4@4PS
4@(WEQ
"p6L.nCVP
pDjX|/
70HHHp#G
mFoyNT
JJ+J.
il2*@,W
Q*Q1Qxe8
tS^ujy
T$,4`}
6bPb]ba
'6.Vatg
[#$(,0
C^W,"0-h
r9lptx
HLP]/\
+]:SZG
[@`Zj_{
u*V|#3
yY;j$&
u4wA}6
W.#^d)
$ldQ$P7
b,,P((t~
q7&b?0
jc`Kb
Txtplu
PONKJcB
J!``.J
]Sj Z~
8_WJba
/^0Ma_
=,g|.i
*T] h(
A<[_<X:
O9!<Uv
SWEB!
h^f9-b
^Gjz-uJ
zhtN!u
woVW@9
uV tO
9u(vEVS
F)71J@]
8&g8lS
9H*Wt!
)9MY"tQ
>"!SS";
{@*?_ kX
AZ6"dec
fv`Mo$V
jBFZejb
jHhpr!
"jAua<
tv:# y
" R\]gnMi
@K`B#
|tld\/
w<x-B^
h}xxQ0
}>v`~p0g&
EYS[(T7
jo8u1.
F-?Ht-?
]~W$\7C
@~20Fv
'X. vCX939u
VEY!V!Q
W\)jAo74
oxx]xv
lh\6Xa>
i.Ksi.o%u
=w|Jt~(At
{.R7C
>8d0Xf
<;f99t6C;]D
t-SDR4
#<9w"L
.i/C%V
j@j ^V?
kE~<0L0
qGF`Z&
dH0;oa
an_ItU
i*Mx&X
"N?tu\q
fbAi+M
- 9} 7}
_/9>t
[[DSW1
w|k?8t
r9B[U(LT
(I\$IK
q_SAp=H
Qhda 
l.2S'"+
AVWPAuI[@
@Sj"\YTD)
zpRB.\t
Jaj\YFI
$(rrrr,04
\9999`dhl9999ptx|
`@eDH$
v4;5\V
f$L8`fB
ipLt$\
_ESvP{
;er 8^
YTX%a!*Fv
F67Dat
@R8]>s
tj.<N)
UQPXY]Y[l
h)a.KC4
WAq8!k
&*-K&@YpY
^g,YY
v!}#O+
R&=llg
P H,}&
*A-|3\
]FNc'i|
y$c~@#
)y.BiU
V@P8RZ
wAk0V[
ac2Mu7
TNP/)w
2>`0V-
!K{s$R
Y'J Pl
Y$"@>GJ
ABatk1
Fa'z2c
TPQR;O
pduf@,{
/Y8|Zi
PHQ!n~:
SRWn0u,
M&Sb7u
tKq]=r
H40`!h
bn` PK
^j pH)
{bwlt=
*zI^r8
`a+eLMq
D<Bn[DQH
rRDP/GX<
$,(|Qx
H*9MsA8
0PKt>@
U:`5GD
UfVF1
(JB5$D
/HY2@^^
zd}I2;
XnWyD@
o767ni-
Io&a(o^
;W;4T-
t5q|-i
!!,\Fp
(yyN1:1
:$z&<$
KPR\SQ
dwhV5Bb}9p
)^dFA;
1|<\uEF
Pj5C%SpeSQu#gA
{jq!7`
vCCR0r
RZ~D
qLeH#4
d<`+M\
!9B"eHk
xlF%52zO
@jXC~}
w<@0;xr
%kFeW#p
T;VLuq
&8mN PX&
l`51P"C
x=it [
p>ccO
dthWp]k
&{j\7.
j*P3.3
O(B>=)&
F&V(RW
_PYp:P')b
Vx>4>u.
lpd1t"/
+9*" ;t
CiG.pt
Dx(fX03![H$LQ*
#SDv0%
DGHuANJ`]
8crtsgtM
H6E$8VD~)
VZB@ba6
7T=c!M
.Mf=+A
dW8[_I
eW:F2[
0SR/P@p;
gL8=`&
Z8PBqe
WFeKIA
RSjIDEGW
xC4Ji)
0C/mV3
@p2<.2
=ERCPt
E(: .h
Dl+Ghp
9Z(MOPhH
Y92v/*
~9&NHQ
U`tm*lFT
F%OJ-0y
4{9NHc
,G}OBZ
WXt8|,
_F)l(~
LC![bMK6
->|( m!;3
&?T\+Y
;@VR^b
/ .ti%
Af}jah
Q`>(0g
=2zHa?n%
#cr"qR
JWu91
c[Pa'c
81Qmt2
zo%A_eKKiK
 !"##$%&'(
)**+,-./K00123456
5>?@ABCDEF
`t29t :t
R"e7Sr
#KJ!|
+~<+^@
UIZ@Br
h68*H;
El>hBaU
k-9Hva
/(mp`7d
B% 2(0
4v0h'2
FL@VCX
BtI:XO
`NNn#P
42Hg'@#
FkRI}
"@Ce+
Y?PbjR
]Q4YJp,
-i"T`d
5#'Kw3
f5zQu7xmA&u
K]rpDZ
VN,QR,0
~1VC3S
jtdy.
ch.JAU
hQzD|Qf
HYnm*
FM^AVV
8|UR40
B9s u-P
jarfwHV
~& \%i
.N(Qh3
+dB.1"+
(t|<"tx<%tt<'tp
l<&th<!td<ot`
\<[tX<\tT<
_'rn{_C(u
5@PC`)
9TQ!"p
'<T$QI
6BIK04,5mK
C1H28u
h)p^\68
y*S,@H
q6h`JV+p
k!^!%8
$},{8,
L5UPNK
'RPQu2@
h[t,&r
*7#JG(
>My)jGQ
xs$Cuf
V&GFw01O
${F$d
>kwo/
8ElQk:
(pL=#u
heLOPi
D:4P]a
Y/6Hr5
Ka~?uB
tRJt6J,
LYu*=!
0v#b?H
%CDk(f
G(Lhz2~
-`v`R]
H#Li_RVJl
!QP8WY
M]"xQRn
[h$c.Ss
)W"SqQ`
)a%_mU
4Mk*$$
nWQh!\
W 0s5hY
,N,j)e
,Vw04G4M)
9r~ V0
)siZg6_
PytMh\
oM!L@z#
N<I@*g
]P|&@
brPKSa6
4$d:$%3
R|MtI8
id]x0t
=]'X=A
)"v0p!
JDt@;Sa
BDlakica
O qi(d
Hk-P{3}
4<?3{u
zK@Fr'
``V\'K
Zp]u53
-`V\z\
$+^{-Z
]/!_.
G?EsU$
JHt\)
Jr;Q},Db
_t*]t%
i7`t 8sV
@>Pf&A
Ld^}^}
EY]qE/k
I)*+B77
;i<:rK
n(cF,|
W`+lMM3p
4<>t
y9M(tH
pE7G]|S=
-Rr<2aB
WpK2M;{Rp
a4UM`$
!HRN[:
$RUu!
pU2aH_
Vq@~PM
if`j dQ
37iB**>
Q5&.ib
i8JX0 _
i488<<@B
lfJ80FW
HLPTX\O0
Ehr<;
w_@Z{F
-?u5[rG^/}$
t+i*{$
fJXeQT
"`M0^zE2PKa
F4oQK
t4~d^~,
m}hBX8
uZzj\z
+A4;rU
BD=8/F
W0q3*^
~!APQ
88`u}l
KmGFg'S
,,m8H4
l9e|M|
#H1Q+/
[C0=su
_up&K
6\#v</
..VA{<
W05ROl
JE X>C59f
5h}jX}$
>`E->V,e?
>%YwgSJW
=$DnDK
I0IbgB6
~a@ga@
[Xh(G~0u
%gh,#USG
tqm_$P
2@b6DP
]N.-!h
CT1x7|
q,(@-X-
[F,JG\
C9P<t>
eWr%o&
19t5mA(<(m
J7Q2IN
NoD$y
RSPVWV0
}@V#<]
QRIC{*
H&~G<+u
VQ!EN0
*9TGlF
=B~$]\
)'V)Pp
`S(d^RFD
vO1S7)
5t.,*P
j.J ,P
'0rM(x\8
a$vaaQAe
3Rtonnnn
rtjAt^atYStMnnnnstHHt<ht7Nt+hnnnnt&Ot
9rYPyK
fU:uK
l=^QUyIM~
\CJ$]f2
vA@'9S
a g_GQy
QZDQw<
Xp"a)"l#Q
J7RQ_U
RI/R$|
t->@foJb
hP98v-[U
$@@"|p.
{/2F6tu,
iTRWR[B
g%!GH]
%2!f|N
B`hC4R,
,TN>@&
v7;V8R&4#LF
,LszN`i2>
0-#.vE
KSjb#.
5IS:8;
$| usG
X#WS2X
S'I,--*{
!hL(XMk
/Dk08$
<>kDe2k
4PPsrr
3 $8<X1!
+8U-^Aad
t$0WPQJK
AM7PFH
o,)Uz
SWO=H#
RAO<=`
aTX,ty1
k@<DF:
H,*yF
U`*(<)P
$`Dunq
ux-5i"
IwFxcj
^ @+[yRRM
V=A"F;W
>L| /S
N|?Q7C
uKl<+}
{?j~
V'T3?@ib
{P{M[O
Vh=L+\
RW4\a4
NVRWba
tNc2>&&X#
/T$dR
+V9\ueF\IZ)E|
iV:E(d
@D`q#u.f
^Z#DWQn<yR
)-$#S<
t%^TfD
$jhxIc
V%QQws
171}$[S-<
5@HEmCy
i&40<@
YhQ6T=Ae`
W q:~V-Z
*HQD:A6
0SVQoS
,5XlC;y
7hd2_H
t{P/WI
N9>~$d
[CX>H&
A6q+cb+5+_HS
~r08@R
\/{u.:m;
IUhNh3
Xl7U20x'U
k)vRC:g
mmY8hRV
AX5Gr$
$`"tZ3Ie
PH%X_XG|
K`h3Fp88
!$yH,h
Cv4$Ex
t-;RFj
~BLPfJ
2k'/8
)1t5)S;P
Bx(=I*}
*-~mS0>
6(Db8O
y^$<4VM
Tejd`u
Jp)$uG=
sL$HDA
>|ok/S
r0iNTR"
Vp6Ki\
u7a\ `
Ht2Hub
PZ;(TX,K
tk+1mM
:-9ycA:
=!C''$^
7JbBN[h
F>RsX'
$`:i#yF^D
m!_ois
\~Kt<s
QQBBFJ
9(tIFEAB'
G2gpZk6{xvZ
h5e8K\
JR8p8>Cj2
3~a@CG
CJ^z~g1
)er1\e
->$""?m
*g[AQ_
V, ^m`
Q+`!j
P\[Zuh)
$$>)ttX
P?=#@f
^APIV.
x+AREV
$sMJPh$8f_P"
jr@GL=/!;
R>cSP>
@tY%5r
)tH({\
?$F5CB
?Ao!g-v+
'<wbR3
j1@AG4
ppC-{m
`/Y;Nt5
P/ $!])
8+u gi!x
u@:/)rB
*OxBQM,
E}*RR1"
b?>@Gp
ad allocation8CorExitPr"es
{Unknown exvp
///#&P
u6dcGZ
TZCs'W
oBgS>
FH:mm:*
SR)Augus
}k$s'Wed
:e)IJKLMNO
FTUVWXYZ[\]^_`abcdefghij
8vwxyz{S
t'7 c =
?i3>l{
m*sSk
+FVfwS5
px<y z
5FPQ 8PX
_nextaft`_lo
>%_hypot
Apld?<0O
5ptzo6
\5JD#jcUTF-_
16LQUNICODE_j
<8bunz8
l,kg<i
^@En[vP
D>V:e:
3\@L4
ZEM-'^
o~l$G~
^\sY0:Rp
@~7Z8>
fe')lW
P\?T@*J
|u?!u$
"9>>?.
Prr?=?
@N.>?>
dd>?>@F&
@F&??>dd
dJ???@F&
bu?P/Y
_p2rr
}N@ O
]vQ<)8h
74>U".
[|)P!?Ua0
y1~?|"
?x+s7
k>? #J
v=o;:8o''
76431
Nno0.-+vr;
o*)'&o
$#! '
~~}o|n'''|{z?yNNNNyxwv
ovutt999
?srqqrrr;pooon
vm?llk
g?gfe''
ddocbbNNn'a?`__
NN^]o]\9
[Z?ZYr;99XWWoV
vrrUUT?S
MLKJoJ
?5Od%
n{;7W
?|I7Z#
pg)([|X>H1
AxuN}*
r7Yr7]D
&?~YK|
:]=O>\
CqTR;?b
1WY$?]
?#%X.yo
Ge/Windo}
.UserObjectInform1Wf
A0iveP
ageBoxbU
i9_/T|
7W$gNRE\
@UQLy5
`~A%My
< Complete
lor'[Class H
ierJy Descrip=
BeIArFy'';
c threxgu
nXru!it2
ex. deKf
BGinBi
c;`eh %W
allsig
N}?| x
ir(jdis
0TosdB
/efaul
XdGpa-
\XTPLH<
<D@<84
21#QNAN
'LRIs\
emaXjv
t@ahitg:lV
qA7OJTW
^x:c'e
.dRIsT
R~wI6cs
8kernel32
alWGb,
luginD
w s:&*/
;&cmO7 ;
ByG//q
OVG{a{
?s?ZP{8g
:2?1M+db
N1RzIK_
B.876B.
8''''7654Sc''32
CCEPOMMIT
KI~HE\
Anyrdc
n~iaZv
BrZl<B8
vOuhid
_Abori8l&r
erokelC
~JT>Pah
=:MBdpWL
VietmX
"bundspb
word*G
of p\n&c)j
recognZa0
P<~ {} qu
|3'| K to
bpty A7
POSIX
`t(s) P
@c gaP
> 255v
Gbcu6@
PTy"xW`
, 32As
DEFINEone0
Sgt.Dd4
GBZGCC
02Xk#13W!W
2H/gXl
>,MC{7o
mms7s
`wG?\$
_G/w6b
?O3{2V
SbsU/i
':/YR{
KkR7WE
-Og?D
//RoR#-]
]-K?G>
/37jmMJ
MOOD(Z
b-#GX!
/OU'';
VVh[pG
VAgG{:q1
B(Qc%S
~{XsM:
)~LXw%
M}XW?E
{sg^bW
uO2pCD
ST&xOS
Z #W1m
ICMP.DLL
cmpCQF
'g{;d=b
m'g?#X
$6B:6p
advapi
.?2hw]
OZ{Hg
Vt! (l-
yQ\Z{0,Wi
?NO_START_Ol
<lXH4,
p\L8~$;
I7/!5A
CPgR/S
l/mV p;y
Ixx@o
dP8 yO
Qkkbal
<xl`TH
lP8 <O
$--%"!'
lrFO/f
VRspLsmov^
j .E6H
~ OADgZ
i*t7",
L]WY'FO
R\O1Y%
zaIZXQ
W4ForS
G(Heap7J
oepACur
Id&MulDiv
DeWide
tiByH(l
FlushBul
lp32S:phoZE$!
St4CY/
#!etdm
amPi(O
^acZ)%VV$
mjoC^pTdO
|la@I1
E`AiAddT
junTok
Shut<n=
]pn?)
`A9Arc
W,Task
&tYSH`
ycSn'v
py'MaA0
|,Eg_No
Sub%CR
dTGmH1
kUBT;u
Y(q+uC
rp0Xpd
`[d!Visi
/0g\u$s
XPTPSW
wwwwpw
wxxwxw
wwxwxx
wtdpew
t$gvgfBG
gG@xwwp
@edgvw
dtvv~w
||vtd w
e$gFvwxw
edFDdT`E
wxvF`x
wxpvG@
xaxwex
xxvGge(
wfggwf`w
wwpwww
wwwwwwpw
tggggCx
Tdtv~|vtt%
xxxxxvB
pvGxwxxtvt
xxvvw(
wwwgww
u!!#Ca
j^[[[[^j
rG277@71Dq
-<LNz|
|zN=<&
*<=Nxz
zzNL-#
&-LLNQ|
'///111
t0NQz{
]R;UUu
^!!! !C]
uuqk^SS^kquu
}GA!7
$_wwq^q
uqvwwwwwuq
+anm:$
&_essd4$
t>}b/Z
EEEb>>>
EEEf777
>>>;===
>>>;<<<
===6;;;
EEEy@@@
FFFnRRR
>>>;SSS
@@@Eccc
???Ckkk
@@@Eqqq
===5ttt
===8aaa
>>>:666
NNNCWWW
HHHCRRR
UUUqwww
QQQqSSS
UUUpxxx
VVV,aaa
IIIB___
}}}/iii
eeeu}}}
hhhwxxx
kkkIddd
[?){^D(
TA2rD1!
fRAfbH/
yhYmsf[
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
GetAce
ImageList_Remove
GetSaveFileNameW
LineTo
WNetUseConnectionW
CoInitialize
EnumProcesses
DragFinish
LoadUserProfileW
VerQueryValueW
FtpOpenFileW
timeGetTime
H}AU3!EA06
qy5dq4
,Z{w3g2#
s_,hX)>
`U{qgC
"^Jn%b
;Z6Kls1
6)3<-i'
R7pRN*
H5XT3V
y1PYQLf
W<9i{.
ISvzfw
F}$c4s
#hL8{o
P@4rJ
g7gUdG
("zIzd\#
8"KMn5
bX]tW~J
whG(^zlw
D~)_&/8
&|0 <mp/
pn*6Z,
wF1-W7
GW^to~
jQG +
hwfz)|b
(l}GMO
0$v-ow
SV0~nw
}KT.n(
?;tNq7
Ma_$bt
dm8K-u
Zj/5xMEb"U=
2WQ8 S
g]}"(*
F+&>$Z5
r/*IGT
(<OZ1E
0tGlt(u(2
*qpS9mI
;:/Y]"
SQFH#?|
50Ch,5
4]v5M^}cA|
u6yk/3l
s|@(Yq
038+2;d
4\u<l=
cU;?]a;0
.!6*?-
"blNhE
wmd({W
b2(vZ_
OrB^SO
Q$pi%Z
SQ-dfu
:bod`[
!csMtPr
Rw.TVx
/cy82z
N;/dY`
FGz!~B
u6L~-9y
xD^[vb8
XPUh7'
q*=u`t
-hj?HSb
T{_j5=
7K-'RdS
*s(Of_
FCq@I
:97?pn]CF
Ez'{2O
SbA@X&
t#uZG/
m)TBKF
p>^$97
%}.alg
t(V;S-
rb[487
<mXi9J
W4IQSW
$]A3p{F
9,<oCE'
!TziI{
|Q;4BlLz
YV."sH2
CF9#=B
fD>&T#
|AL~/4
=PDj":
vP8C2-
H^o%S"
.[H`Up
i^Ul~$
Lpg^?e
6cWS],
&NQvsJ
D50%x/
G]m9rK
j:3xT}
j3",{{]0/
8%~sTd
V<h{\c
F7Yn~w
7y5#1cL
NxUv8c
{Y$rjA
;o)eRMJ7
3%4WT 1
7Z;W?p
)P%ZZq
k;gR[I
S,IW%V
~C1@l&
m?N^{u2
dbD,
M_^+QQ
GVmY"1
@|i]CSs
iSU,W|#
\Q]-Tm
Q1)K E
%;_%[j~
,^wK^rP
J~H7=u5B3
PM#'cN
-Qh q!1B
E{.1!3
o4s<."
]13g[=
1/Ki/alW
rq>]`{U^
r19dFw
$9o#Y=
M,R,\$
-@wEA,
N/s{6d
gkK{e-!'
)ExW)g
NZ>k1az
<WRy@Z
k->)N
o.Wg\I
w*Ub-`Iq
&f+-gDW
t}*c'-
7c_|Hk
MyWl/e
'1GXH"
,)A]X)
pngUUZ
Bs)hv
IVlJ@$
#0>"#/
46u=n[S
EDUXOt
WuGvk^N
n[*T-n
w1xyu<o
C-$PD]C
Nek|,y
P^S5.d
U?@^Cw
zP9t9329
;)'ltu
DIO^`
&gxHbn
-B$j ,
AC*[$R
Sdx8ES
k3W\;6
H'2y0n]
&S jS.
V^8wj<
Wv`xCt]
|`(.#YZ
c<5Wq't
Mg3\|Ov
=t2fb_
G$crL)x
lsxgnv
_K7KfB
Kr5!pg
yE@S0@
>%~9}R
@RJK+W
gusg(0K$w(O
H$4NbF#S
)b$D/'=r
}(#0C}
+46h+^JE$w
EKtr]m
^)`(a)
'}>3"+P
L7Y5&"-
SSgrbz
DHAwWp
Jb^{;,
9c\-&IS
KIp):sq;\]
pH i`r
0bmk*0
qGp a.s@
,g]IQqZ5
%>@[Aee
<bCC<2
7x*<73
8M80{m
!*=Prd
'>IM^]F
#p$kr-
AB^PR[
sauhQ~
9"kD k'
5_7L[*
czMqCR
Gb1<t5=:
qDZ<{<
2nJ[A4
PWX!]?
GYrc;O(
Sb>-@`
ge"D7HD9$
NPH[H?{
^4)`Ku
`G@x[E
/+8u`i
vV,7g^
i{F$v@r
PXtID_^
T-c`X8/y
/+.<K6r
{Kc3rK
(IhK~PW
';'!.f{
Tb&2B
&hEm=b
m0c?X-
&FYFk7
L&,LLK
=OwU=x
tlSj2bq
-.x~#
67Ms[Dja
o\m;za%y
(J)\NZ
k?I#svB
]+$$c<
y2F[F!$
`x5~1D
#$__qp
f".'T<a`
3KvO5.
XR Cf3
SB6jlB
dhJ.:
rB|0b4
S+QDwQ'$"
Ok|rIY
uswwNE(
24Slb/
#(Xi:C
O5f0`#a|*
}bxeP/
'MEMaW@
k"lq"m
xNXXj=
{n*~;
|g4X]D
*;--%s
f >dX}
_p17d1
B3~'h0H@
qzeONrmi
I92T6tx
hN_DaWnK
Htv[iN
}gVnqJ
&b<+}j
5zz]L4
CIKK"}Y
`2k/+>@
DY8\0@
EI`#j\u
b3Ac:p
Q0B\K
ga^%Vz
^F3dTX
pQ-_FY
l_~;0^
~n0Vh7
FYv.bc
z['F@
+f?]f]
s7C038
0Bf5ju
=52LCb5
14/Rf@
{9/T#t
RaV:,A
FG[{4$
(b5iwM
/uC^+Z
pNYj2/
)/ZizI=
/t2wpc
I3^ (e
w2Jh?P
DSGdzT
5jdR_{
r;!:'6y
3$$ic"|
,"I_41
3W<fO9v
QZT6ZE
:{R_BG
+KZl;dN{]&
qmo<F
_i?%?
GA&2^u
,Z~p`}*
@0VY:
0m_-G3
"<'Akp+m
2Izfm
l|?w(=
3t-*W{
?XV[)S
yX 4=
<`uY`
>2yB51099
)'~p<a
MB&d\C
%#eAhU
pD\fyvl
aW"i%r
OFV$l+9
x{3}]Slu
0&i$nU
Qm}|&t
`mZ/NJ
-QPo92
\#,G)\_
YZ=r64
w"P}0,t-D
6;*H&`
$6p&tY
q"C6P^
PM^ {{p
yq;,QU
C-#csI
Z(O'(\
[KTez#
]^;[}c
S+0ju,
Q'(~`]
CV@PY7
2P26_}B
Q(q_&F
s {|R{
P\ja|YN[E
A)V xK<
vqJ.-A
]M-g?%Uz"
4O/02$
=VS2C(~
5@6Wm'
u178 ,
\I_=3^
D6YjZ<
7c93Dh?
paZ4Q5
)yjDs#
4ctZ8
Oky.zt.FX
oRD~-n
(o^*\cq
<t_nUQ
MF1K O
K='|i4H
kyh^(t
Ny\@bl
d#cT@
80z6z$
,DU3d2
HURaqn`"#
9q{6TJJ
:uF/wMM~^
qz)8U+"$
dhz8s_
%n>MDh
'_2E@'
&#Wb.d
3"9:T<
j5i%r1
h}I}4vp>m
XEoSjE
u$:uY*
mSq2+x
s\bvDSr
/qC:"fA)
=3[#LH
1@`J(p
NpeOCI
j?!PC1
\hzRhx>
5glMC
+PHL"u
'( =eT
I`y)|Y
"IXWw?
RE}'KWS
b[1Bg j
h@!W5CYv
FHT>:@s
\Jd-Jel
8NXU9T
bBI.`jfHX
5{#HPw
!\}oA.
$qO z/^
~'+O5&
eX#!j!
FqeY)
%q_xtAM
OV-\@&
|oWYH
hY_(x
e$X({
'Heu[t
gH1Vy@
{6.Yt~
le(23`
A]PAS]
I2S5xG
Y)F1R^
T'Qd17
]A?|u{
@]clVy\
+,J"kK&!
wnb!61EX
I1cl8X
A <}tWy
9vZ% ,
G?{%]
bvMrr}
B20YHe+
NwdVNX
_gGuy5
X}$G{P#m
$!zmJv
4TQ0RE
)`AbbRc9
l<Q<0W[
"ipj%W~
vpuK2w~os
]5\ sYi
+?%<`^
bD`vEy
>=9k|
z7!x}0
t|43'V
6yhc^$
2F$3#(i
kfj2%w{
z=d{2F
g-LW\Z
->zU\^
Eu8{;M
27&E w
My#dh#
;6@'g
i?N)l'
DW#GKt*
G{#~S;
/Oed@>M0
Z@;J1b
2FM6OD
cc"z8GY
QG+sa:
f/~B\3E
A{HP_<
26O;[`
\$wEg@
T!lidG
kY0jo-m>
IOg|`j
^\'q>/$
l\uHT|4
cTzy1z
)aB&V=
{W4^hgu
}^/aL/
tzPA@
3{u5C_+
SxLM.!
/pl Cx
YEL,^Xa
77ui-T
k@xK6b
z_>|0l(|J
>bs9Z^
{ np" <
7lF{.e
KRTrT]]
!RC3;F
wNM<vu@[a
*#/,=a
\e!<$
\Nn9jP
]fdB"?
rGQ8[5mY
:2Xj]L
XIpHMeo
V#\O#,
byNt1j
Hpq0"7X
1%-3|(
Fu&=dV;
cp8X6Z@
d#wVe@
RpB<UPy
9Y(\gh
Bjs0'/
w>:wzY!
l&nzC/
2u}mT^;
C?QZ|t
/g1xCR
(A(|_
6H-L'G
Y#E&Y@:
T7lYG{:
n#?I#S0
X\*[:}H
HEeI8*
p+5bIh
SAM65g
Zz!\5,
Ybx&$:
,C5QP7
_WX-b,
Utg Te
*f(,T>
R#b<h4
q7hd{u
s1/i|
*mE#zR
NImr"K
#4~}9P
LF\ GSe
#jj>G;
G Ga0H#+y
^pj}&O
g*YFzC;
CG9_,'
`e 1P'?
y3,cxFyr
8UN^H
XcUH|0i
]Z,D@L-%
}'EpMFR
ZnA4rs
ISFQ"1
1DKG%9T;
XL\qc0U
$&ssB%
xV7/=\
G&jt,P&6
.f|fXRj
@;7V@/
&[`gn;,
F9R]0m:
97g=I(
y5&M*<
j(?8p42
9 c3nr
3X(F5G
DL\01N
&ASM1ENq
\yCUmT
6a$QH;
~y`4Y_
ZEKN1y
HS[2Z"
pU!x4g
j%=tI
EKti[x4
*SC{P_
skQ;fgi
T6JQ&6T
e@pIwnh
i[A>b;>V9
W]a-6
+uh27>E>@
q8?$ei
M<qj&"oU?
y-ARD
/S?I:H
t5c%jX
.FgrS;
PW Sh1
f!O:[/z
F-}aG
uszCxJ
jp491gE
$J)x@u30
1G^uC J(w
(yK4V(
S0==yQm
\a_k7m
tti;-3`4Fb"
8Q^ehF
!{7(Yss
}LyZs[
T96>m7
&prdHN
*A;m1qbNk
"TG9WM
zvjLF9
/=.{z9
g8xsYn
d^e3@_
r/`^{i
7OuYg=
9xsd:YW
#FTG(R
m*M}$Vh
DBfUgHe(
#*K>F|
QH?S-S
X~0VY/
53<7&3
XM/iGU
!iG41]
I[Sz:
{a1h9'J
I|DvCi
<NVf>=
Yl]rL=D
@F,z>j
~{`RK:
>m%`_:b
lVc8":
4jY3f^t
5v$mp/d
qcvt^@&
Q`%,t4
>dPHlg
Yv]Yo:
Wp1.;
wy+)^0/
xCSu@M
ajIo9#\:J
Q7"fMxM
!unyq[
k5h>F
P5f Sl
pG~BDc
Npkz1oP
ZWdz3i
^GN#jE<
<pq8+
uL+-:H"W
0?~"q*
SR4|tG
l2,YI"
'h>g|e
|fCR!/f
MYxHOA
sV_5mt~
MaLj77NN
!/I[\a%"
wi?bOLB
@9}^Jp
}n":9n>+
~rhePe
Q}>fdO
x^8QH^
foM"N(
~pmyYH
5gWm5N
n*yl]`
<J|ZNG
_G9s[x
-wl^i{
&y/6i
Her1:wG
lWOI@\A&
-?x^UYA
4xJ)*c
dZ)OpV
9W4)|$
*n@EZ#]
P"BqBnm
;r6Gpa6_x
zy0A2
n(y,w]
NbY(SZ|
e,d4h%
t^S=$+/
Q<jOdJ
-C!4~|p
<[ |f/n
05m.Tru
}oR:6t
p_;qQ_
;I$ZMJ
7f}5pa8
ULTvFA3
z?xg"Lm#
D{[xSWJ
EQ.D5{
a4,]ZK(M
m'>('Xg
TvBJ]XP
RsWV0
znj8;>}
eJzb&sOM
yc\Vw~
.SPxDvoG
'x>sBw
|B4%|k
UL$gb
=KS#;q
v\x{kMc75
M|,I!\J
hS/P_
D\/"k
iPg^"h,
`+|l/|
aYg]Ifw
nt=/M*
E$*oJQ
pHy@J&
*xJxSo
E9\^ x,
~xLtQ)
1T3f:X
/+K-nx
P$>\S+
jFcodE
H!NC?:
K,[ZV4
<(CQ^G
dMH/\xKQ'.G
6O23OK
V4"~;X
6TZpN`
4Gq@=Bg
4KO0Q8
aZ(+W`
phk{$j
!?f=y;
A_[,al
.\X~l5T
bs}Byf
Ir uY9
)O,F40
1iWkUR=U
s@;W[x
u%OVXD
(=\* Ij
$O%&OR
?G@6'p
#q{D b
l*y>|"9m
|}4_z1a
Vd mf1
XR-tx3CIk
*_sT|3
{hrh88~%
-D?kR#1S
8GC8KK
ue'|qt>0|
9K;q_U
D<M1`AV
Q{#;vP
: gvG*
Kk3-s6
AmFJ(G
9x._'9!?7
>>=@ u#
+6k2(V1K
KAgyW o^
&H;'M@
OFwiP3k
y(P!0u
<J-ZuG
1iWkUR=U
s@;W[x
)'GWo%
'jW2kL
gBwCIV
5RX6|n
!8SGW;IA
P[NhwNR
!87W_;
_;EIX<Vj.
qZ].Y0
|1}f_n
lGz5{P
;QP)cT
O4j&sX%L
RqGP8P
t o4S@Aa
<VY_43
d"a$bw
I R>h)
1;]XaP
D{D+PFh
oNg51[
`$siTm
_ZFD[v/7
j~_jb<%
Z,@Y4M
ohMr.
%{v~O"u
m^(Wl3
1iWkUR=U
s@;W[x
\$KnmlJ
&A?B*9W
ERKH9?
T! }a#z
f2)\x:
f>[#Jm
m]!Z:KR%Z/P
VWpb;6
E%0w;+
*Oc]F}]
`XL9%c
jN57U
>!k#a
;ROD'|
d7N/E
8F!+bgOXC0a
s:EnQ
&f,<[/
'Ug'u&&Uv
X"F"pnD;
cU#,Pb
jVW@'oV@
o6O;1o_
_n|Z*v
q~PAZYj
'!6[_{
@dL?~h
1iWkUR=U
s@;W[x
/<hLPf
-c'#sI
l81%~x
MS&B29
~6G>!w
aq!)=e
,2AL'f
Q'V`Fl
1$p_KD
"p_n7Nb
UC3A3g
ddAq\k
H-<0t}
/4unYP
N $*HQ
DoLi /
q4n)Ymc
G\uc4?D[
nmk_5+`
\mpj\2
NswP{K
#J`82_
6ECTyM
V!Z{07
WMJ%X&
(v~!O~
BZg6nM
327 IL>
1iWkUR=U
s@;W[x
4P2/o+
b0uI)8Y
{!~)y[
er9Y>p!An
S0yY^
p$SD<vod
k2I6ts5L
XB9JBzU
1;B+FE
D'1]Gw
fb f|T.
jB(LG$
&BZjoB
=JN;}2
?6Z_yq.
^?*Iw&h
*L;0'2
h|;61Am
3OtCjt
1iWkUR=U
s@;W[x
$}^Q5%
ddq8s[
{,6,=G
9V!0epU
Ds(;A+
SM#sSY
qpJ#u4~
;&'lRc
kz99BR$52'
)2zWXf
+GFI"&
\<Hg&N
S^B>dH~GVY
Bq`?w`
>0{$C@
vlefzu
p@fKzb:
{"R2j
Chztnad
SN1y4]
sF<4>k
bWS2me
uIhBFc
rhS#y%)
O08svx
~8Q<=I
ac/mZto
FMg!09
@AoA8[M!
,#&Cy
@sSbx4
U<@jetrE.
1iWkUR=U
s@;W[x
<cqy{$
c?*GvaR
:>0H<XF
;]&Z]h
1c4i1d
.QhDa]~
nx- dx
/wV|UR
3]>I5_
2T{B}e
s'd^YU@
_0xKO\
9W79D>
U;b ;q
t#d=BPl
qr/SW4
p5:=Q.N
ZvP)S
8V"Tui
Ts(#pw
}s\=N@
{S3V%
1iWkUR=U
s@;W[x
-G@`<Q
}[-e^
rVW*P9Q
X/tNcE
+$8t!^
&H\3j3f
c#`g0k
&oLINwUJ
,L{l]v
1{]B(c
?_H{S+
B\-Ivg
}"1O_J(
fFe{+e
|"#|P
Zcrd=U>
@0Tz*h7
1iWkUR=U
s@;W[x
nC#lRS:
I(u1ZZ
RWOs99
w}Fu0m<
Z$2ml<
S$ABOUt
Z$)phiV<
u*6c(Bc
2b}BdR
ArD}`~
x,M9yV
0!SB/|
(Hp|rr
*LFeU*0
hsmIgSn
1iWkUR=U
s@;W[x
yraClY
<DOd/z ~
$E`CKJ
JM<;.CN
<=9V[(
6Tf0JL
0)q-u)
+ut'9<>Mp
k=aT`&
lcl@8p3
c/}h
;sQhpa
VBk0L1
:5,[d(&y'
/05tFN
,I{y{0H+
nh'R,{
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.lNoD
tehtris Clean
ClamAV Win.Malware.Generic-6651791-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Spyware.dc
ALYac Trojan.GenericKD.66127824
Cylance Unsafe
Zillya Trojan.Shutdowner.Win32.4893
Sangfor Infostealer.Win32.Shutdowner.V7mj
K7AntiVirus Trojan ( 005631b11 )
Alibaba Packed:Win32/Generic.2b2244a0
K7GW Trojan ( 005631b11 )
Cybereason malicious.27c01e
Baidu Clean
VirIT Trojan.Win32.Generic.XTX
Paloalto generic.ml
Symantec Trojan.Gen.MBT
Elastic malicious (moderate confidence)
ESET-NOD32 multiple detections
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Shutdowner.ahqz
BitDefender Trojan.GenericKD.66127824
NANO-Antivirus Trojan.Win32.Shutdowner.jvqfph
ViRobot Trojan.Win32.A.Agent.690283[UPX]
MicroWorld-eScan Trojan.GenericKD.66127824
Tencent Malware.Win32.Gencirc.13b1681d
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Shutdowner.ekgfy
DrWeb Trojan.Siggen5.59949
VIPRE Trojan.GenericKD.66127824
TrendMicro TROJ_GEN.R002C0PET24
McAfeeD ti!FE926EF4CF81
Trapmine malicious.high.ml.score
FireEye Generic.mg.6b3b47c27c01e8f4
Emsisoft Trojan.GenericKD.66127824 (B)
huorong Clean
GData Win32.Trojan.PSE.R2WKDE
Jiangmin Clean
Webroot W32.Malware.gen
Varist W32/Trojan.IJBN-1595
Avira TR/Shutdowner.ekgfy
Antiy-AVL Trojan[Packed]/Win32.Autoit
Kingsoft Win32.Trojan.Shutdowner.ahqz
Gridinsoft Trojan.Win32.CoinMiner.dd!s2
Xcitium TrojWare.Win32.Hider.REXR@5364l6
Arcabit Trojan.Generic.D3F107D0
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Shutdowner.ahqz
Microsoft PWS:Win32/Multiverze
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/PWS-Banker
MAX malware (ai score=86)
VBA32 IMWorm.Sohanad
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PET24
Rising Trojan.Shutdowner!8.DDC (CLOUD)
Yandex Trojan.GenAsa!i9rai7w7/WE
Ikarus Trojan-Downloader
MaxSecure Trojan.Malware.204080839.susgen
Fortinet W32/NDAoF
BitDefenderTheta Clean
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Suspicious
No IRMA results available.