Static | ZeroBOX

PE Compile Time

2012-07-14 07:47:16

PDB Path

                                                                                                        

PE Imphash

bf5a4aa99e5b160f8521cadd6bfe73b8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00019718 0x00019800 6.74859033994
.rdata 0x0001b000 0x00006db4 0x00006e00 6.44295624763
.data 0x00022000 0x000030c0 0x00001600 3.2625868398
.rsrc 0x00026000 0x00081890 0x00081a00 6.99778082268

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00066dc4 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_RCDATA 0x000a727c 0x00000020 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators, with escape sequences
RT_RCDATA 0x000a727c 0x00000020 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators, with escape sequences
RT_GROUP_ICON 0x000a72dc 0x000000ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a72dc 0x000000ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000a73a8 0x000002fa LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000a76a4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x41b000 RaiseException
0x41b004 GetLastError
0x41b008 MultiByteToWideChar
0x41b00c lstrlenA
0x41b014 GetProcAddress
0x41b018 LoadLibraryA
0x41b01c FreeResource
0x41b020 SizeofResource
0x41b024 LockResource
0x41b028 LoadResource
0x41b02c FindResourceA
0x41b030 GetModuleHandleA
0x41b034 Module32Next
0x41b038 CloseHandle
0x41b03c Module32First
0x41b044 GetCurrentProcessId
0x41b048 SetEndOfFile
0x41b04c GetStringTypeW
0x41b050 GetStringTypeA
0x41b054 LCMapStringW
0x41b058 LCMapStringA
0x41b05c GetLocaleInfoA
0x41b060 HeapFree
0x41b064 GetProcessHeap
0x41b068 HeapAlloc
0x41b06c GetCommandLineA
0x41b070 HeapCreate
0x41b074 VirtualFree
0x41b084 VirtualAlloc
0x41b088 HeapReAlloc
0x41b08c HeapSize
0x41b090 TerminateProcess
0x41b094 GetCurrentProcess
0x41b0a0 IsDebuggerPresent
0x41b0a4 GetModuleHandleW
0x41b0a8 Sleep
0x41b0ac ExitProcess
0x41b0b0 WriteFile
0x41b0b4 GetStdHandle
0x41b0b8 GetModuleFileNameA
0x41b0bc WideCharToMultiByte
0x41b0c0 GetConsoleCP
0x41b0c4 GetConsoleMode
0x41b0c8 ReadFile
0x41b0cc TlsGetValue
0x41b0d0 TlsAlloc
0x41b0d4 TlsSetValue
0x41b0d8 TlsFree
0x41b0e0 SetLastError
0x41b0e4 GetCurrentThreadId
0x41b0e8 FlushFileBuffers
0x41b0ec SetFilePointer
0x41b0f0 SetHandleCount
0x41b0f4 GetFileType
0x41b0f8 GetStartupInfoA
0x41b0fc RtlUnwind
0x41b114 GetTickCount
0x41b120 GetCPInfo
0x41b124 GetACP
0x41b128 GetOEMCP
0x41b12c IsValidCodePage
0x41b130 CompareStringA
0x41b134 CompareStringW
0x41b13c WriteConsoleA
0x41b140 GetConsoleOutputCP
0x41b144 WriteConsoleW
0x41b148 SetStdHandle
0x41b14c CreateFileA
Library ole32.dll:
0x41b17c OleInitialize
Library OLEAUT32.dll:
0x41b154 SafeArrayCreate
0x41b158 SafeArrayAccessData
0x41b160 SafeArrayDestroy
0x41b168 VariantClear
0x41b16c VariantInit
0x41b170 SysFreeString
0x41b174 SysAllocString

!This program cannot be run in DOS mode.
~2#{~-q
~Rich,q
`.rdata
@.data
D$<RSP
L$PQSV
D$HUWP
FD)np)nl
Vlf+Vp
Vlf+Vd
tr9_ tm9_$th
O(9O$u
t*9Qlu%
)Nd)Vh
FL9~Xu
~\wu(j
CP_^][
T$h9T$
t:<wuE
t.9Vlt)
)Vd)Nh
^(9^$u
D$$)G@
w<9G,s
T$<PQR
D$Tt*;
;l$TsY)l$T
L$4;D$Ts<)D$T
p<O#|$
~(9~$u
O@;H s
O@;H(s
T$$QUR
D$ )D$
Oh;O\sN
Gh9Ghr
L$(9ODv
L$(+L$
D$(+D$
D$0^][_
N(Uh0%
t$H;t$8
|$ WSPV
@PAQBR
8VVVVV
uL9=\9B
0SSSSS
0WWWWW
HHtXHHt
>If90t
j@j ^V
0SSSSS
<at9<rt,<wt
URPQQh
>=Yt1j
_VVVVV
^WWWWW
0SSSSS
0A@@Ju
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t"SS9]
v$;540B
PPPPPPPP
PPPPPPPP
t+WWVPV
<+t(<-t$:
+t HHt
Delete
NoRemove
ForceRemove
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
bad allocation
Visual C++ CRT: Not enough memory to complete call to strerror.
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
UTF-16LE
UNICODE
GAIsProcessorFeaturePresent
KERNEL32
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
`h`hhh
xppwpp
RaiseException
GetLastError
MultiByteToWideChar
lstrlenA
InterlockedDecrement
GetProcAddress
LoadLibraryA
FreeResource
SizeofResource
LockResource
LoadResource
FindResourceA
GetModuleHandleA
Module32Next
CloseHandle
Module32First
CreateToolhelp32Snapshot
GetCurrentProcessId
KERNEL32.dll
OleInitialize
ole32.dll
OLEAUT32.dll
HeapFree
GetProcessHeap
HeapAlloc
GetCommandLineA
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
HeapSize
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
ReadFile
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
FlushFileBuffers
SetFilePointer
SetHandleCount
GetFileType
GetStartupInfoA
RtlUnwind
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CompareStringA
CompareStringW
SetEnvironmentVariableA
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CreateFileA
GetLocaleInfoA
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
.?AV_com_error@@
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
jhiFv}x
iii6mmm
hjiBqop
ddd@hdf
usr${zxV
tksDqlr
fff8gggrmik
nnn:hggnjjj
rmpDompxjjl
cff"dhfHfii
f`c0fdepabc
"ooo hhhDdddzbaa
u[[Yu?
u<.{wA
L.Eyn
UEB@B@
*2^~#K
I)&"k:9
h[QE T
u5O_&3
++i+Nb
;DzDV5
&TFT3!
5Zk9sI
$2fWsD
-c>c;<b
:[l6}
*RUNFiy.
w8>HSA
,ID"K2
n_a,HMSV^
[rvRRNO!
@UlAkM
}{@Dj)
=}w5zh]
%J`f$s
BP!hQ`
$ru)<~
(O3fPo
XJ7S{ax*
?~*snVdm
KskaM5$
YU.Myi
Cm=GJ<c
$#>"Y1
'DUzQz9
qv1pqy
?gv)1V
u8Yq
8Qu5(1*A
P}ATKMB
xhMBTJ
{<|rI2
sK]--
H)#=q%}V
[Psk(d
s4 Y!;9
0E@s IF
|nsNNN
C)ymu2K
<'+-\
R$R4s~
@m'[h%dq
`K~U+k8
4Al@LD
]p(s0S
3ascno
I'6k0`
Xg*4I9
H`)=^3z
jsLp52_
:\;%ZHf
QpbF;(
>"NN9gN
jSvC$b|
%$fTUV
XL/xpo
bH!7]R
3+GU;*oA#q
:$Fbl
~vCV3V
Dz6CG;
5ClId2OR%
{fNe]FT
={B+-CP
McnZF0&2
O2N;Rf
-q?36-
'qE5:7
jQ<V+*<
ckJTv^
U3|i]"
1XcHi`
Z!fJ%s
?%21Kr
Bs3-?pc
X_1iNq
$`u@RfP
s`JqML
8V8VX6X
li8_[6A
HySb #
90E}%fk
]"Jc^fb
K\^^rv
7x7aZ-
yjWSUM
qAE{M&|
hT2\;A
E\4+Ej
1-O(;
7oBi`
6"fzxxw
8)1BH!#
^)Fb(*
y$"_J)
kBjA{T
{ eir1T
gz<'HK
YO 2hD
& AIE
Va]jQIy
3RlwHD
{7y?Iu5
gi:=d6=
0TPYEJ
>8nu3t
o,484=
R:]Vr.IzODOk
4l\(AC
|/kj*=
|AAg;0
\&.]ZZR@
sAoIeeF.V
Ga0lj(W/
tssq\A4
?`wa8D~
tssq\BAACD
8fwa5Rux
ttssq\?
RT{a[D
R4`{aSI
tr^^tt
@fwa7o
tr^^^^\C
R8wa[4e
DZ{aX4ov}
vuR7fwa8
r^^^rttB
QQJSwwa4
Zwa[Cp~~
4`wa@Cx
F\b_rtt
8fwa5Cby
uEeCSwa[4
QE?Z{aX
F\bbrtttqFq?
Qo7fwa8>l
t\U]]__B
o~>8ww`7\xqF
e{{vo>Z{aZ4YcrtrF
*ReeE7`waW
>\]]__^^
ouIC@fwa7
Ftrrr]4g
Vwa[4>rtttq
Qjzzze
4`waX4U]]r?*
eeeJ8fwa74\]U
QeeCSwa`4Gr>)
h*Q|Q>Z{aZ48
zzzzeuR
=Sq8\YW
zzzePJ8c{
zzePCP
~\A1mB:
7UUU\^ry
hP@BUby
hC8Ub}
O?8Ub}
K78T`{
H:78WYZ2
NSfz"
a__IFFT|
aa_IH6
FVVVL?r
i^^g`?T
lk>8c]
ig^ZG8
Pc\@>d
UPVF?r
\gZ^gj
qk>5YZm
ooncOF]
N`Z^^j
iZX^X?:
!ULFWr
slk6EO
RRR U|
ql]5GZi
UUVTTuVoU:Wp
qlK2GWXXX>:
{R oonnT@W
sl]5HfeE
ql[5GF
=C4C=n
uttonVL?d
L>IYY_``i
TLFFGY`
53;FH1T
|J>?Y`
z;>?Ym
Q66?Ym
B66>GZdr
xB966>?K@
CAn|$"
OQXXRRR,
OX||wXX0
QX~~~|~0
X|XXXRRO;
|~|||XXXRRO
~~~||XXXRR<
~~||XXXRO;
~~||XXXRO
~~||XXXR<
~||XXRRO
~|||XXRR<
uieb6w
}dccd}
~|||XRRO;
eieeS9
~|||XXRR<
iiiebB)
~|||XRRR<
iieeV9\
~~||XXRRRB
iieeT6{
~|||XXRRRO;
iiebB9
~~~||XXRRRROOS
iieeb:N
~~||XXXXXROOBB<<??
iieeT6:TV
~~|||||XXXRROO:
iiegD9
~~~|||||ROO
iiieb:Y
~}|XQD
iieeV6a
iieeS6
TVVTSSY>Pb
iieb:?
iieeV9\`y$$
}cMMc}
iieeT6a
}cLLMc}}
iiebB=
|dcMLLLC:
iiieb:9f
iieeT9<Vbh
iieeB9{
<Vhfggd
}dMMc}
hfTVazaBPe
iieeV6
dLLLc}
VS?<Cbi
iieeS:
}dbLLMce}||RS
|dcMLC@
iieeb:
iieeT9a
$`$#$
iieeB6z
|}cMc}
DTVffff
ieeb:=
wdcMcd}
iieeV97Td
"v~}ecLMe}
iieeE6STCb
9bMMLLcRR<
iieb<;
fbThzaBPg
iieeV:
z}cLc}
$m$m#]#%
`[hTCTSBbi
iieeT6
iiegD9
Sdhhuu
`zUBPb
ecLMc}
iieeT9
}eLMMMc}}
iieeS9w
wddbLLLLCC9
iieb<9
iieeV:N|
m`#%`%
iieeT67Cb}
<BTbhtt
UbLLc}
w}Xw!|
iieeb:;"wdcLLMc}
fECVSBPe
iieeT6
Wv}}dcLLLMce}}XQ
aP<:Pb
iiegD:
}}dcMLLA@
aaUBPb
a[a$[NBPe
iieeV9
w}}}}}}}}|X
iieeE9Xww}}}}}}}}XN
$$`$$`
iieb<6Rd}}}
iieeb:4@ALLce}}XN
iieeT9NddbLLMLA@9
gfTfhaSPb
iiegD6
d}}}}XN
]##`$a`
ufHEEBPb
iieeb<
Qdd}dQ
a#$a]#$za
a_TBbe
iieeV9NdddXN
`#$$a$a
iieeS6OdRN
iieb?48@@
#[\<Pb
iieeb99N
XIJIIIATh
RIIOA8II8
z$a$NPb
ieea-+
uuffffhhhaBPb
uhfHHH?Bbe
uha_OCn
uutha.
O8I5@Da
|8Id~7J5a
uthh^-
4SX:A:
@878885?
8I<@J8_
77<@=t
OI8I8S
~Q;647@79Z
~wN944>
Q94447?_
Q5A4A7
SRd}}}}}}}}
~XN946
X7A<X87a
?<ORRXddddd}}}}}
aSSSBBBBORVdd}}}}
_D<BBRVdd}e}
6449476@8>
Z<:<OVdd}e
~XXQ447@@7:Dt
?:<OVddee
::BPVbdee
G9:BTVbeee
=9:BTbbeee
649BEVbdeei
G=9:BBTVbdeeii
49:<BEPTbbbgT:
6699:::9
BBBB>>=
>MNPPPNNNN+
>NPPPPPPPP+
>PPppppplp
*PPPNNN>=
NPlrrrrrpp
/pPPPPPPNN>=
NPprsrrrrr
1rppppPPPPPNN>=
MPrxyyyyyx
nsrrrrpppWPPPPNN>=
MPrxyzzzzx
xzyxssrrrpppWPPPPNN>
.Mlrxxzzz{o
xzzzyyyxsrrrppppPPPPNN>
2Srxxxzz{
zzzzzzzzyyysrrrpppWPPPNN>;
2mxxxxxzi
{zzzzzzzzzzyyyssrrpppWPPPNN=
2hxxxzz
{zzzzzzzzzzzzyyyyssrrpppPPPNN>=
2.OWpr
{zzzzzzzzzzzzzzzyyyssrrpppWPPNNN>
RqsyzzzzzzzzzzzzzzzyyyyssrrpppWPPNNN=
cc`U<;r
RVUUXqsyzzzzzzzzzzzyyyyyyssrrpppWPPNNNM
gXXXUN8P
}}wqXUJUWsyzzzzzzzzzyyyyyyyyssrppppWPPNNN=
\\\XXUA;*
~~~~~}sqVJUWqyzzzzyyzyyyyyyyyyssrrpppWPPPNN>
\\\XXXN>
~~~~~~~wqVUJWqxzzzzyyyyyyyyyyysssrppppWPPNNN>
RU\u\\\XXUN<
~~~~~~~}qVJJWqyzzzzyyyyyyyyyyyssrrpppWPPPNNN>
#NUUuu\\\XXUN8O
~~~~~~~~~~}qVJJWsyzzzyyyyyyyyyyyyssrppppWPPPNNN>=
BNUVu\\\\XXUB
~~~~~~~~~~~}sWUJUqyzzzyyyyyyyyyyyyssrrppppWPPPNNN>>
BNU\u\\\XXVN<;|
~~~~~~~~~~~}sWJKVqyzzyyyyyyyyyyyyyssrrppppWPPPNNNNNBN
=NUU\u\\\XXUN8Q
~~~~~~~~~~~~yqUKUqszzyyyyyyyyyyyyysssrrppppWPPPPNPNNB>>BN
QQBNUUuu\\\XXUB
~~~~~~~~~~~~zsWJJVqyzzyyyyyyyyyyyyyyssrrpppppWPPPPPPNNN>>>><<;
Q_TBNUXu\\\XXXN>
~~~~~~~~~~}~zzyqVJKXsyzyyyyyyyyyyyyyyyssrrppppppppPPPPPPNN>B>
RBUU\u\\\XXUN;@tPUJUWw
~~~~~~~~~~}}zzzxWJJVqyzzyyyyyyyyyyyyyyyssrrrrppppppppWPNN>R
BNUUuu\\\XXUB8T
|tUKJWw
~~~~~~~~~~~}}}zzyrWJJVsyzyyyyyyyyyyyyyyyysssssrrppppppPNBR
>NUXu\\\XXXN<
wVJJWw~
~~~~~~~~~~}}}}zzxpUJKqyyzyyyyyyyyyyyyyyyyyyssssrrrpPPBR
TBUU\u\\\XXVN<@
uUJUXw~~~~~~~~~~~}}}}}zzyrWJJVqyyzyyyyyyyyyyyyyyyyyyyyssrpP>R
NNUUuu\\\XXUN8Q
}tUKUq}~~~~~~~}}}}}}}}}zzyqUJJVqyyzyyyyyyyyyyyyyyyyyyyrpP>
BNUVuu\\XXXU>
wXJJXw~~~~}}~}}}}}}}}zzzzspUJJVqsyzyyyyyyyyyyyyyyyyrpPB
ANRTRNN>><CBNU\u\\\XXXN<;
}wUJUq}~~~}}}}}}}}}}zzzzzyspVJGKqsyyyyyyyyyyyyyyyrpP>
ENNU\u\\\XXUN8R%mS
o mm|wXJJVw}~~}}}}}}}}}zzyyyzzyyqVKGJVqsyyyyyyyyyysppP>
>NUUuu\\\XXUB8Q
}qVJJX}~~~}}}}}}}}zzzyyyyzzysXKJGJKXqsyyyyyypPN>
TBNUXu\\\XXXN<;
~wWJJVq}~~}}}}}}}zzzzyyyyyyzyyspVJGGGKVVqppPN>
QBUU\u\\\XXUN;@
~~~}qUJKXw}~~}}}}}}zyyyyyyyyyyyyyysrpWUJGGGB<D
m=NUUuu\\\XXUB8<Wv
~~~~~wqJJUqs~~}}y}zzzyyyyyyyyyyyyyyyyyyspWN>
%<NUVuu\\\XXU>8<JU[
~~~~~}sWJJVq}zz}}yyyyyyyyyyyyyyyyyyyyyrpP>
BNUXu\\\\XXN<;n[LJUt
~~~~}~~~}qVJJVqyzzzyyyyyyyyyyyyyyyyyyspWN<
NBUU\u\\\XXUN;Q
|vUJJ\w
~~~~~}}~~~sqUJJVqyzzzzyyyyyyyyyyyyyyspPNA
<NUUUUUUV]
BNUUuu\\\XXU>8
~~~~~~}}}}~~~sWUJJKqsyzzyyyyyyyyyyyyrpP>
T>NUXu\\\\XXN>
}~~~~~}}}}}}}}~~zsqVJGJVqsyyzyyyyyyysrpP>
[UNBNRTMBUU\u\\\XXVN;A
|uUJU\}
~}}}}}}}}}}}}}}}}zzyrWUJGJKXqsyyyyyyppN<
nTN<<>NUUuu\\\XXUB;
wWJJVw}~~}}}}}}}}}}}}}}yy}zzzyrpUJGGJKVVpppPNN
TA>NUXuu\\XXXU>
}}wUJJXw}~~}}}}}}}}}}}}}yyyyzyzyysrpWVJGG:B9
R>NU\u\\\XXVN<
o}wWJKUq}~~}}}}}}}}}}}}yyyyyyyyyyyyyyspPN<
%_# S$RBUU\u\\\XXUN;Mo|"
~|OUJJVq}~~}}}}}}}}}zzyyyyyyyyyyyyspWN>
$#_#%"
!;NUUuu\\\XXUB
T||vmv}}S!
o}qUJJVq}~~}yyyyyyyyyyyyyyyyyyyrpPB
NNUXu\\\XXXN<
n||}}}}}"
!}}wqUGJVqs}z}yyyyyyyyyyyyyyysppP<
A>NBUUY[[b
PBNU\u\\\XXUN;=v|||
}}~O " "
kv}qVJJVWsy}zzyyyyyyyyyyyspPNA
S>NUUuu\\\XXUB8<[v|}}}}}v}}}n
! l!lsqVJGJVqsyyyyyyyyyysrpP>
gYUUY[
BNUXu\\\XXXN>89BUtw}}}}}}}w
!!kxrsqVJGKKVqssyyyyspPP<
[YUUYt
NNU\u\\\XXUN<;NN:Ugw}}}}}}vO
<JGGGJKVWWPN>
|vvm"NBUUuu\\\XXUN;MvtUJJUq}}}}}}}}l!
lyssWVKJGB<;
\YUUWtvvoTBNUVuu\\XXXUB8TmvwWNJJXw}}}}}}}w}"
syyrpPM=
\UBNPnnT>NUXu\\\XXXN<<
"vnwqXJJVqw}}}}}}}rl
!lyspWP=
#$%S#%
$StUBBNTNBUU\u\\\XXUN<
vw}qVJJVqw}}}}}}Okssl
lpyspPM;
%##$SS$S#vv[B<<>NUUuu\\\XXUB
O}wwqUJKVXs}yyy}yysrlyO
<BNUUYggd
SvnvnN>>NUXu\\\XXXN<;
}!"O"!kww}qUJKKXqsyyyyyysyslrP
NP[ttgg\
ntnNBUU\u\\\XXUN<
!O kv}sqVJGJKXqsyyyyyysysrrpP=
gZZZZg
#$Sntnn>NUUuu\\\XXUB;@ "
k!!}}}sqXVJGGKVXqssyyyspPM
gZZZ[t
""ttnTBNUXuu\\\XXU>8Tvt
O}s}rOssqWVJGGGGKVWWPN=
BNU\u\\\XXVN<
lvwvw"
"s!rysqpWVKJ:BB
[[ZYZg
v%$tttt
NUU\u\\\XXUN;@tvvwwskp
ksssss
lO!yssssssrWM=
wvtttn
BNUVuu\\\XXUB8Mqvvqswsq!Osss}
ssssssspPM
g[ZZZg
wvttt
>NUXu\\\XXXN>
<UWqsssssssss}"
OssssspWM
uZZY[gwwvttn"
BUU\u\\\XXUN;
B:JUqssssssssl
!!rsssspPM
A>BNUU[fga
gYYY[tvtttTBNUUuu\\\XXUB
MWUJGJUXqssssspssOqO!ssspWM
>NWWt[ggg
[ULY[tnnP>NUXu\\\XXXN>8MkqpWJGGKVqqsssssssPssqpPM
ggg[[[f
$$$#SSTvttYFLNPnNBNU\u\\\XXVN<
OqqqWVJGGKKVXqssssspPM
ANWuww
T##S%S%S$
vt[LBBN>NUU\u\\\XXUB8
ssssqWVJJGGGKKVWPNM
gggZZgg
Tn#n
wwtn[N<9>NUVuu\\XXXU>8M
pqqqssssqqWWVKJG:BB
#nTNBBNUXu\\\XXVN<8
OqqqqqqqqsssssqWM=
>UWqww
ggZZZg
T$$nONNUU\u\\\XXUB<
qqqqqqqqqqqqqpPM
!;NUUuu\\\XXUB8MO
qqqqqqqqqqqqPM
NNUXu\\\XXXN>
PqlpqqqqqqqqqqpPM
<BNUV[
gZYYZg
MBUU\u\\\XXVN;8PWqqqqqqqqqqqWM
<NNUU[gggg
#S1$$S
gZYYZg
>NUUuu\\\XXUB86BJUWWqqqqqqpPM
ggffffgg
gYYZZgwT%TTT
>NUVuu\\\XXU>
<BB:GGJKKVWPN
>NWqqu
gffffg
1SS%$$
n#QYYY[ttttT$@BNU\u\\\XXXN<;PWWWUUJJGG:BB;
ggffffg
#ST$#S#SS##g[YLLY[ttnNNUU\u\\\XXUN;
WqqqqqpPM
gffffg
1S#TT%$$$
[LFFFRRBNUUuu\\\XXUB8
OWWWqqWPM
ANWXqu
ggfffg
S###t$S$
t[FFFB>NUXu\\\XXXN>
MWWWqWPM
gfZffg
T$#SSn$#SStStgt[TRBBUU\u\\\XXVN<;PWWWWN
wwB::>[
gfZfgg
%$#TtS
tttTTNNUUuu\\\XXUB8>WWWPM
ws<HH9[
gfZZfg
ST#$#%$uttt$Q<NUVuu\\XXXU>
>NWqqu
sp:HH<
gfYZfg
n$$Su
TNNUU\u\\\XXXN<
yP:HGA
wsN:G<BR[
gfYZfg
t$tgt[
NUU\u\\\XXUN8
wyNGH:R
ws>HHHHG:<NTt
gZZZZg
NNUUuu\\XXXUB
}y<GG9f
}r9HH9:GHHGG9[
gZYZZZg
>NUXu\\\XXXR#,
ANWqqu
zr9GG<
yp7HGPpN<7GH:[
gfZZZYZgggnStTQABUU\u\\\X[44.
zp:G:A
yP:H:t}yspP>;wyP:H:A
gZYYYYY[T[[T>NUUuu\\
zP:G7R
}yMGG9
[wyp7IGT
gg[YLLFFFA>NUXu
}z=GG9f
}y<GG<
ys<HGN
wA9BRT
gg[TRRDABUU
zx;GG;
zr9G:R
yyMGH9
yN:IG8[
gggt[[TBNa
{r6J:A
{l7G:D
}zP:H7[
yP7HH9[
w}B:<N[
ggf[[[R4
{P7J7R
}{N:GG98ATg
w{r9G:R~P7HH6T
yy<HH6R
gggf[[T13i
DTv{M7J6f
~{>GG:GG:9;;f
zz>GGNp6GG9R
zr7HH9g
gggf[TT0i
68=8BB;
{x6J:;>9:GG6[
}{P:G98GG7N
{l:HG<
ggff[TT4
BB99B<
{p6J7l{rlM98
}{p7G:GG7A
w{M:H:N
ggff[T_i
69<B968;R
{P9J6f
{y;GGG7?
}{>GH7T
ggf[[R1
}zzxpM;
s{=9B8
{x8GG:;g
zx9GG;g
ggf[UA4
~zyrP=
?zy8B9;
y=7GG6[
{r7GG?
ggg[N@#4
~zzxpDR{p6B<8DR
z>7J:J7R
w{P:G:D
NNWqqwww
6999;?D[
zM6J:8::A
}{>:G7T
ANWqqqqqqqqqwww
}zxpM;
J:8;::8
zy;GG6g
ANUWWqqqqqqqqqqqqqww
~zyrP=
pp7J8[
{r6J:;
>BNNPWWWWWWWWWWWXqqqqqquw
}zzy[R
R{r8J9D
{P7J7D
>>>><<>>BNNNNUWWWWWWXqqqqqu
zy;B9;
Rfw{M7J6T
<><<>BNNUWWWWXXqqquu
}}zytf
yz=9B8P
D><<BNUUWWWXqXqquu
9B<99BB
D<<<BNUUWWXXXqquu
}yyrMPP
69BBB9
<;<>NUUWWWXqXquu
;;<BNUUWWWXXXuu
}zyrP=
A;<>NNUUWXXXX\uu
}}yspM
;;<>NNUUWXXXX\uu
;8<>NNUUWXXXX\uu
8<>NNUUWXXX\\uu
;>BNNUUWXXX\\uu
u\XUN<
;<BBNNUUUXXXXX\\\\\\\XUN<
8;<BBNNNNUUUUUXXXXUB;
8;<<<BBBNNNN<;
8;;<;8
rL+@j
&V^@|f
}4d].&J
7**p*yo
zej&iC
=ae_N1
AzQJ%sY
d% ,[(
+(N rPb2_
F}Ga.N9
d}nX.
qh+m=[NG
']CiKj
*$v*~3
/,LD,7
k J,17
'y jh>.|%
JIwBsX
7akD#K~Z=iJ
6,P-W8
e-Nsgb
tzb7,c
s9t-l
;q[AK{p
T)I;.y
)a6mMI
S_*n'?
$h2Zrm5
plpdqa#k
~S$Xu@
$YA>BS@
(>U[f|s
0N2JTe
T1M*:v
g3Wv@?f
cKQqNjw
S^ja&RlR
"2qF4/ET\
*m-y|E
_,l65;LZ
W>*3yB$
='/rZOm[
W2ZO[.
C:v<zc
HF(nsy
s#p'ag
g6fga6
^LBs5b,O
^!'$d9
1,TnLn
Kq,up<W
;yej.G
n3c&/Vs
y:6SuW
4QN=yG
H, zSs
b{<Tgg
yzLzDk
No4B:W
gcdq5Zf
7[$#F%%
"yn&h|
pO.JN1
6{XVr,
D~LK_.
z=j#f*
)V9@vN]
n#^2|
(i\n6'
jC02Z&W
G=XL4_
EE":5t$/,
\eHX[r'
lh<(\E
@"tj7
irY&%3
s}R82}B
S\:*9F
2\`(4m
3+x=s{
sD}!cBV3,r}
o7&vcL
XID-;Xn
D:`(`b=/Z
Cu|a|y
7iJWjxTC
Y\]uwJ
`<Og9M
aYHVR]
e)Zk[7
GkjOds$
=_H]t
ax{uTP
nQ*#JZ
SB;9^XBG
Z!{ACq
_nrPEr
[*a|{YX&o
Z[k 0n{
].#$D5
?4xO?b
{<lX\
|"YWuR
QOXGn0
Wlc">9
cea8$n
rwv1aH
TAZX7]
(Kq^rA
&d!U0!
nwB^(r
7g29+#
Nz$4r<
7&OpMTT
rPl!UH
pFNXw9
@KgHBa
QmTQ3I
</!=XN
o@c,Pi:V
B]zrf$
z;}i1e
n!9D'
^2gm*2
M90>PPZ
L4~~[V;C
:HG=-6Q
:z9>n5}
i> x.a
33D..c4
i`".Cu2
7ar\+;
;Av`@|/
[zHU5>
MMrFQv0R
/WPaC}s
=FX3-5
Gh {P@
qm!ThY
-,Oza{
Ip5jOv
H|M{7B)|
x0v;U`Qba
7I|%,X
X\c^&;J"[n
YRyx%'
5Gk5 y|B
BpJ|Zd
_=QASRN
nxsTnZe
cgk\7Z
;.&ld'
0#'uA!
t1 6tP
-"iw6A=
h;)|w^
!0"7_M
^>acnF
g'd5e2
U0d[Jt`
*1ieA~
4rfsEH"
VCe^gHf
ke}oF'J
~H[s/p.
_AS$%
32WkWi
KTp^@#
cZb[nh
M&t7a<*
g<Rw?7
XS,x-y
P`u:Q7
$w+r&n
%p,9t\{>
C};HZR
f"~`Ek
JVq k8
EqiS|U!T&
-by)Ff?$B
sR_<e{
nA]TO_
Wkp]1
dLT@hp
%Rel,G
B!8MK9
p1/b/&iF
(\DmaI
8=1NOPv0
Q;:$]9
X]BNGx
)//dTVX
]!z-i(
8d_[d\r
-Ck4N.\
6<USXJ
Jx>D4Qs
,r|Dj
N1-MVD
zIu!.~
acQt!F
f>{JIk
,,9N;V7j+
SC x^$
^`]j|}lJ
edCi>O
~WEI1)
sJzmUHaO
'$3n2euf
Z^t|8!
_CV)u
e$|)A^V
g5<;f%
tYJR&,
<%Rbe'5
bYE[~U
/}mkRO
Utv;'!
B+u)iF
CvB6IK
m[lt9it1
c'8c)$
`h2d^*cu
a#lQ#4
,d&ma6
oLR$TlF
vE/jip
.DlYf4V
)%-X_~
3SK?/Y
-cGf{E
+QS[aV
[kgwy9
1te),O
fvLWr
Fr.cDWk
YaG,=@
WHg<H5
@BX^3}O
1~3P6]
iN9Veaf
-<Joe'
+*MTsV"5
1gVPxA
zN,J,a
jUh\<A
2=tf@e
v\|6Fqx=z
*vGiZM7
Kn4 lp
Ug0<>>
P""u,<
*?YOQ9h
6oP!KI
UCH,cl=
(Y_rh_
)=+'Wy
W*B*#[
|h/!"-
N(JX8(
`K55+4/
PBvP[;
cr>N`O
!;}Dc&
W<`m81
$9`aMs
Yp`ly'V
F1LtDQ
Sz"#cw
8Au%iur
*r1t|8
L0a$8%m
y~st\M
31?([h$
s&Eccu
-4#x9:
\1Q$?VPLH
}>W;/\
\_W1FX
"t\_YO
kq_/&>
d36bi\VX=vU
#\v1Fk
XOp;^6
M.A_li
8rxXU V
!/rG)o
NA#C_{
6\\n4{
(e+U"\
t\zo3W
yPr,D?
.jJ"K1)
Tp<!-~
I&Pgg~
-ol1K$h
'ynJa~
r?&Iex):
Q{7iF]
"9.FkHY
OSz[Cm
Z3<(_s
ePa0j
(S-1YuAP
5~ZT\(
+{}U@z
F:;(ZV
e7q L:
5IluW:
^p'#b5
^-bq%gd
f^j]18
z(\3S
|}r5IBd3
xi]uOa
VY']~m
&9-pq
M5o=u!'
`ckV5*
,R72'%
`u'}D)u
`ca?sC@
<F-+<J
/gSj,I"l
.U*$pg
-uC|ka
9`%_uQ
/^Ofq"&3
<jO)]_D6)'
O}pf!E
t$:7m0
qpm1Xn
\"VqHJ
U*wmG4
d9X~h$I7
\Ot$as
."<7>+
0*L0iU
xyp=jrJ
N*}e=f IxI"
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
#+3;CScs
mscoree.dll
KERNEL32.DLL
(null)
B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
((((( H
h(((( H
H
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Batoon App
CompanyName
FileDescription
FileVersion
66.74.51
InternalName
Checky.exe
LegalCopyright
Reign Corp. 2006
OriginalFilename
Checky.exe
ProductName
ProductVersion
66.74.51
Assembly Version
10.97.24.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.RedLine.i!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MSIL
Skyhigh BehavesLike.Win32.Generic.jc
ALYac Trojan.GenericKD.74147641
Cylance Unsafe
Zillya Clean
Sangfor Spyware.Msil.Redline.Vgvv
K7AntiVirus Spyware ( 005995c91 )
Alibaba TrojanPSW:MSIL/Reline.e82d7d14
K7GW Spyware ( 005995c91 )
huorong TrojanSpy/RedLine.q
Baidu Clean
VirIT Trojan.Win32.Genus.WKL
Paloalto generic.ml
Symantec Trojan.Whispergate
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Spy.RedLine.A
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Trojan-PSW.MSIL.Reline.xnm
BitDefender Trojan.GenericKD.74139895
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74139895
Tencent Msil.Trojan-QQPass.QQRob.Lcnw
Sophos Mal/Generic-S
F-Secure Trojan.TR/Spy.RedLine.poqsi
DrWeb Trojan.PWS.Stealer.21213
VIPRE Trojan.GenericKD.74139895
TrendMicro TrojanSpy.Win32.METASTEALER.YXEIPZ
McAfeeD ti!CCD618556EEB
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Trojan.GenericKD.74139895 (B)
Ikarus Packed.Win32.Crypt
FireEye Generic.mg.fef7cb7c3bd0e820
Jiangmin Clean
Webroot W32.Trojan.MSILZilla
Varist W32/ABTrojan.HLEA-9109
Avira TR/Spy.RedLine.poqsi
Fortinet PossibleThreat.MU
Antiy-AVL Clean
Kingsoft MSIL.Trojan-PSW.Reline.a
Gridinsoft Malware.Win32.RedLine.tr
Xcitium Malware@#14rqj0yeow8fl
Arcabit Trojan.Generic.D46B48F7
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.MSIL.Reline.xnm
Microsoft Trojan:MSIL/RedLineStealer.KAF!MTB
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.C5671178
Acronis Clean
McAfee Artemis!FEF7CB7C3BD0
TACHYON Clean
VBA32 TrojanPSW.RedLine
Malwarebytes Spyware.RedLineStealer
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.METASTEALER.YXEIPZ
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Trojan.GenericKD.74139895
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.