Static | ZeroBOX

PE Compile Time

2019-07-30 17:52:45

PE Imphash

2c5f2513605e48f2d8ea5440a870cb9e

PEiD Signatures

PureBasic 4.x -> Neil Hodgson

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.code 0x00001000 0x0000387e 0x00003a00 5.52921893845
.text 0x00005000 0x0000d962 0x0000da00 6.56248809649
.rdata 0x00013000 0x000033a5 0x00003400 7.11183556147
.data 0x00017000 0x0000178c 0x00001200 5.10030422885
.rsrc 0x00019000 0x000b7998 0x000b7a00 7.99953061422

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000192ac 0x00016673 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_RCDATA 0x000d0714 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x000d0714 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x000d0714 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x000d0714 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_GROUP_ICON 0x000d0720 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000d0734 0x00000263 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text

Imports

Library MSVCRT.dll:
0x417470 memset
0x417474 wcsncmp
0x417478 memmove
0x41747c wcsncpy
0x417480 wcsstr
0x417484 _wcsnicmp
0x417488 _wcsdup
0x41748c free
0x417490 _wcsicmp
0x417494 wcslen
0x417498 wcscpy
0x41749c wcscmp
0x4174a0 wcscat
0x4174a4 memcpy
0x4174a8 tolower
0x4174ac malloc
Library KERNEL32.dll:
0x4174b4 GetModuleHandleW
0x4174b8 HeapCreate
0x4174bc GetStdHandle
0x4174c4 HeapDestroy
0x4174c8 ExitProcess
0x4174cc WriteFile
0x4174d0 GetTempFileNameW
0x4174d4 LoadLibraryExW
0x4174d8 EnumResourceTypesW
0x4174dc FreeLibrary
0x4174e0 RemoveDirectoryW
0x4174e4 EnumResourceNamesW
0x4174e8 GetCommandLineW
0x4174ec LoadResource
0x4174f0 SizeofResource
0x4174f4 FreeResource
0x4174f8 FindResourceW
0x4174fc GetNativeSystemInfo
0x417500 GetShortPathNameW
0x417508 GetSystemDirectoryW
0x417510 CloseHandle
0x41751c WaitForSingleObject
0x417520 TerminateThread
0x417524 CreateThread
0x417528 GetProcAddress
0x41752c GetVersionExW
0x417530 Sleep
0x417534 WideCharToMultiByte
0x417538 HeapAlloc
0x41753c HeapFree
0x417540 LoadLibraryW
0x417544 GetCurrentProcessId
0x417548 GetCurrentThreadId
0x41754c GetModuleFileNameW
0x417550 PeekNamedPipe
0x417554 TerminateProcess
0x417560 GetCurrentProcess
0x417564 DuplicateHandle
0x417568 CreatePipe
0x41756c CreateProcessW
0x417570 GetExitCodeProcess
0x417578 HeapSize
0x41757c MultiByteToWideChar
0x417580 CreateDirectoryW
0x417584 SetFileAttributesW
0x417588 GetTempPathW
0x41758c DeleteFileW
0x417598 CreateFileW
0x41759c SetFilePointer
0x4175a0 TlsFree
0x4175a4 TlsGetValue
0x4175a8 TlsSetValue
0x4175ac TlsAlloc
0x4175b0 HeapReAlloc
0x4175bc InterlockedExchange
0x4175c0 GetLastError
0x4175c4 SetLastError
0x4175c8 UnregisterWait
0x4175cc GetCurrentThread
Library USER32.DLL:
0x4175d8 CharUpperW
0x4175dc CharLowerW
0x4175e0 MessageBoxW
0x4175e4 DefWindowProcW
0x4175e8 DestroyWindow
0x4175ec GetWindowLongW
0x4175f4 GetWindowTextW
0x4175f8 UnregisterClassW
0x4175fc LoadIconW
0x417600 LoadCursorW
0x417604 RegisterClassExW
0x417608 IsWindowEnabled
0x41760c EnableWindow
0x417610 GetSystemMetrics
0x417614 CreateWindowExW
0x417618 SetWindowLongW
0x41761c SendMessageW
0x417620 SetFocus
0x417628 SetForegroundWindow
0x41762c BringWindowToTop
0x417630 GetMessageW
0x417638 TranslateMessage
0x41763c DispatchMessageW
0x417644 PostMessageW
0x417648 GetForegroundWindow
0x417650 IsWindowVisible
0x417654 EnumWindows
0x417658 SetWindowPos
Library GDI32.DLL:
0x417660 GetStockObject
Library COMCTL32.DLL:
Library SHELL32.DLL:
0x417670 ShellExecuteExW
0x417674 SHGetFolderLocation
Library WINMM.DLL:
0x417680 timeBeginPeriod
Library OLE32.DLL:
0x417688 CoInitialize
0x41768c CoTaskMemFree
Library SHLWAPI.DLL:
0x417694 PathAddBackslashW
0x41769c PathQuoteSpacesW
0x4176a0 PathRemoveArgsW

!This program cannot be run in DOS mode.
`.text
`.rdata
@.data
\$TK;\$(
PPPPPP
PPPPPP
PPPPPP
PPPPPP
PPPPPP
PPPPPP
[_;\$(u
t3Ot"Ot
D$ PVW
{_^][Y
VW9l$4u
D$4$0A
\$89l$<u
D$<$0A
L$@9l$D
D$$QVP
D$$QVP
D$$QVP
D$$QVP
D$$QVP
D$$QVP
D$$QVP
D$$QVP
D$$QVP
jPjCjnh
D$$PVS
f9LD6u
j\Xf9D~
QQSUVW
tcj"Zf;
_^][YY
SUVWj 3
]jD^VP
t$,t"h
D$TPQRU
t$8RRVR
9|$0tM
9|$0t@
!~(_^[
j\Xf9Ds
j\Xf9Dw
HtOHt5
t9V@Pj
<_^][YY
3D$H3D$<
3D$$3D$@
3T$(3T$D3T$<
3T$,3T$
3T$03T$
3T$ 3T$
3T$H3T$
3T$$3T$ 3P
L$X3P$
3T$,3P,3P
3T$03P03P
3P43P
3P83P$
3P<3P(
3W83W 3W
3S<3S$3S
13q(3q 3q
3q,3q$
3q03q(3q
3q43q,3q
3q83q03q$
q<3q43q(3q
13q83q,3q
3q<3q03q
313q43q
3q83q$
3q<3q(
3r83r 3r
3r<3r$3r
13q(3q 3q
3q,3q$3q
3p43p,3p
3P83P03P$
3P83P$
3P<3P(
D$h3H03H
\$03\$X3\$
3P(3P
l$X3P,3P$3P
3T$L3T$D3P
3T$H3T$@3P
3P83T$L
P(3P<3T$H3P
D$,3A<3A
?vMj@[+
t+h$7A
wI;O(wDj
D$DRSP
WD;P s
s@u';i
WD;P(s
Gl;G`sX
Gl;G`r
M;t$Dr
T$8#\$
T$8#\$
|$ 9OD
D$(+D$
D$(+D$,
D$,^][_
t@90u<
t}9;uy
N,9N4u
F0][_3
D$(@bA
t$H;t$<
_^][YY
RtlGetVersion
SHBrowseForFolderW
SHGetPathFromIDListW
GetLongPathNameW
SHGetKnownFolderPath
0123456789abcdefK
InitOnceExecuteOnce
1.2.11
incorrect header check
unknown compression method
invalid window size
unknown header flags set
header crc mismatch
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid code lengths set
invalid bit length repeat
invalid code -- missing end-of-block
invalid literal/lengths set
invalid distances set
invalid literal/length code
invalid distance code
invalid distance too far back
incorrect data check
incorrect length check
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
inflate 1.2.11 Copyright 1995-2017 Mark Adler
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
memset
MSVCRT.dll
GetModuleHandleW
HeapCreate
GetStdHandle
SetConsoleCtrlHandler
HeapDestroy
ExitProcess
WriteFile
GetTempFileNameW
LoadLibraryExW
EnumResourceTypesW
FreeLibrary
RemoveDirectoryW
EnumResourceNamesW
GetCommandLineW
LoadResource
SizeofResource
FreeResource
FindResourceW
GetNativeSystemInfo
GetShortPathNameW
GetWindowsDirectoryW
GetSystemDirectoryW
KERNEL32.dll
wcsncmp
memmove
wcsncpy
wcsstr
_wcsnicmp
_wcsdup
_wcsicmp
wcslen
wcscpy
wcscmp
wcscat
memcpy
tolower
malloc
EnterCriticalSection
CloseHandle
LeaveCriticalSection
InitializeCriticalSection
WaitForSingleObject
TerminateThread
CreateThread
GetProcAddress
GetVersionExW
WideCharToMultiByte
HeapAlloc
HeapFree
LoadLibraryW
GetCurrentProcessId
GetCurrentThreadId
GetModuleFileNameW
PeekNamedPipe
TerminateProcess
GetEnvironmentVariableW
SetEnvironmentVariableW
GetCurrentProcess
DuplicateHandle
CreatePipe
CreateProcessW
GetExitCodeProcess
SetUnhandledExceptionFilter
HeapSize
MultiByteToWideChar
CreateDirectoryW
SetFileAttributesW
GetTempPathW
DeleteFileW
GetCurrentDirectoryW
SetCurrentDirectoryW
CreateFileW
SetFilePointer
TlsFree
TlsGetValue
TlsSetValue
TlsAlloc
HeapReAlloc
DeleteCriticalSection
InterlockedCompareExchange
InterlockedExchange
GetLastError
SetLastError
UnregisterWait
GetCurrentThread
RegisterWaitForSingleObject
CharUpperW
CharLowerW
MessageBoxW
DefWindowProcW
DestroyWindow
GetWindowLongW
GetWindowTextLengthW
GetWindowTextW
UnregisterClassW
LoadIconW
LoadCursorW
RegisterClassExW
IsWindowEnabled
EnableWindow
GetSystemMetrics
CreateWindowExW
SetWindowLongW
SendMessageW
SetFocus
CreateAcceleratorTableW
SetForegroundWindow
BringWindowToTop
GetMessageW
TranslateAcceleratorW
TranslateMessage
DispatchMessageW
DestroyAcceleratorTable
PostMessageW
GetForegroundWindow
GetWindowThreadProcessId
IsWindowVisible
EnumWindows
SetWindowPos
USER32.DLL
GetStockObject
GDI32.DLL
InitCommonControlsEx
COMCTL32.DLL
ShellExecuteExW
SHGetFolderLocation
SHGetPathFromIDListW
SHELL32.DLL
timeBeginPeriod
WINMM.DLL
CoInitialize
CoTaskMemFree
OLE32.DLL
PathAddBackslashW
PathRenameExtensionW
PathQuoteSpacesW
PathRemoveArgsW
PathRemoveBackslashW
SHLWAPI.DLL
=3=;f!0
!" swG}
`f!.Gn
p#Suw5
3R33#h#4
ww33sU
ADADDB
&wBdR
:Ct)0#8
T#tf2
aWkk>Ad;Ng4
m6bU52/
aBEx1T
R 8Rwu(
%2/<"&
377-U
_[?lOO
DaO)+,
Op0 6&8C
cN:hAii
1)gM9w}
.kVV#3R
;@M453x
ZkIe`$
B;]<;M
P*ve.@
RIsw3u5
!2U2`!K2
:=]>8:}
Y!;S!ch%
ev&3p
O<\j&1
}S.8]%
!(m^ua
I'w1-9
L^w@=v
pa7fPD<
wwv'5Vcwh
ys2ucH
Y+dNSpp2#
gx2$Ft6
lmP!'f
QkFz(;
=}co?N
)Tqcqb
eTrWd'
+CLIR@
Tb.Jd=
0diwfb|+
y&2w=;=
])CLXA
)i.AX;i
EaK=iv
eYkhZuV
KeuJh:
"@` *"
93pzv:
/o~6-/
LlM.Z ,=Y,
I8&'Jj
&VS:M:
Z0TJ@e
8egDPmR
7<|x4?
chN~``5
:> opd
;K27-Kv^
129-fEU
`ORx_(/U
qp<?88=
e[7QD-
iTKC#(
r],_{}a]
cx"NFI
ua2NuJ
%B.K{Np?
](Buxr
qU`uqk
'Ff]\
v*mpDLl`G
kwl\Y0
]LmLnZU
g0~2Kbm
xE]QLG]
UUDcJ f
[zp2)ga
"3F]*R
ncctDF
9}pd?8
_30)Q
P2,k:]
n eRV"a
r<_=8m
.ZdM.)
Qf%ROTD
W;SisK7
QA5iZ9
I=33yf&
V%q`PZI
[F_6{#
M)X;Rf
15 pn
M.CLsr#
+26e(C
cg"]Lj
+7yd=W
W2R"0g{
LL5dL
)$W(;Zo
ZMe"U,
e%5U#B
DTD"!^
&4oEv~
xGvj`Qa
yUK-YR
-m^:<|
<bbX0.
UR.T-PNZ
:tkP22
_/1:g(
dI,Q?G
~gUk<_
1 6xp
)J!RjWY=
'yUp/s
VUSDhgh
1.Vh9j
V6aD&"b
iR9:9:^
@:g}`8
T j]J1QRQ
=)U)k9
%'5;J@"
@IM B&
`UgJJX
NnB}l.PA
enh_BPn
"A6YE2+
"o&<yq
spqq
Kxu3ws7k=
NxDT78
/|`*Fu
a`/&AI
!F+-gG
*[p9DE
kcw9PS
0s3/ff
8F1h@k
9d'r0?
f>O/%>
f"IDAT
$,EcVKL
Qwv9c$G+
U@B\<)E|
>Ca-}=
QdO"0@
T~)mZTQ
jsi@3}
mrk>7Yt
-O|Y'#
V]pt*$C
]IW9?S
"$< tV
>f%EB%X
j<tE=~
tZxH]u
$XrW2A
KMWa=Pk
_yuqi%_
P41K02
:#v"t/
vI=SMVFF!
")!,0
$HxI4Z
A(d^ =!A
-zORk "
@Ad#$Fa
)$-&4:KC
C 1ETz
ZSWDMD
ypSMGw
;l"_zt
"MM@"G
y _G\xh
x9ZYr%
[H%YC'/
7tp`omJ
Q.vlV_b
Q;8qXrju
9 %r0en
Yt453#
PbZRav
y9_c{D^
ZJ9M<6
cot*@8
Kk-o(Z
m(4GS(
77><8L
_8Stl`
ke(!P]
yz#(%K
7Aaci`
L^{FU<m
{E,v1,
W@j6M6
W7.ac\
R!`kJD
Z80 ,z
Ik;C|g
|AVsk`
WUU t{b
AKWT4
\(PTpM`F
#RxY'b
o\g,5X
-Mh3~|
m9G[JT
)E$b9|
#RD3[0[
d^U@R-
7u+$kg
t/-u?\Vc
LQue~5
M}Mu3r=
{KN]!Ai
H.\t3
'cq%`a
*p?jhT
k:0@W`
8X^\lfd
-""A?_
BJc6Lg
[iPzM66
W0aWgcQ
v1f%]I
D9\OL4
PgE!I
E#hm#!
fI^XHo
5PCdjFS
#KuRUL
>Ut6=<v
]HGj].pz
]4&:Z2w
7SDl1Y
ej_FX
o`BhF~v-v
o;{Y^kf+
oHF(n>8_1X`9
bj447]
+Ilu!7
P>p H=\
u!a9aZ
[0}dl{
wOS?x%
YHU<:8
q1AeTD`
\\{riX
5We?ar
ggyEU<
qS0to?
oR=oxt,
GVd9b1
!m+MTVaj
+))bZx9
vzw(9/3
yH:u5fVj
a2UAD0P
#m>~Mjs
GI;lut
0r)d-^e
/&{ur t
?|H.)5
aWkdT
_iBj&1
-~VTY!G
x~9]z
_ eepL
nWHZA?*Z
FzHCc[
q?Y|M[>
ydl:,TB-E(9
z(exQM
%RuX<B
N}S{G&
w^U'jK
{R1r1C_
jW8Vrz
mg^BTn
sF@M*N
:)"PmC
AbQ1t|{
_oD**l
F|1z-
mR$"\:
R\+Mm;
F*4X]Z_
a-<T,+
w.h$P0U
s(Tg#:M2
{eo8@{2w
Y&J@,G
^yU4Oz
`=mU@)
>OBeyGDP
z:"GD,
`xCvKQ
T|]~eR0
+i.@X8Z
en.O9g
@:B\Kf
gY1}{Q
I90fz
T1UEdZ
mq~_47
0HJnN?
6|.weO
"`umD`x
{@M]fE}Y
:6 v7M2
'V`2-c
o"&yG4
J"MmvH
hBPZ]m
?R4@pd
1(U7asEL
ec@Q?Qe
f8.U-;
2d(DN1.
3LZ,.J.c
wg\w.(
R4*=
4C]wh\
6O"_yB
+QS:Pi
.MMW"#2&
qA$86Z
XBs?lJd
?1p4',
/;s<r]
@T.06r=Igs
R)X\:1
PT=.AB
6xGB;|t
PP-r{Y
W'(=/-
}11!JN
.t)H5+[
!s7!^LZD]
E)32di
^vp%Wi=JG
z)@Q0b'
ePAv>S
S":^&"
JXmERhL
w?Gu7x
>GP2v1
<Ifjdf
Ip9O~,
EK"qAoo
ps"(3",`
PDG"8B
=X5;0/
f??\Q
so,&4|~
5X~YrY
s9j@s5j),
RIAsAf
)m8i:cB
x<taH(
Ai@X.;8
!wdB2
B]#%S,
T#?"#H
Ee9\V
y#7v=w
`}InPZ{nV
,.f[N8"~
5tedUk
Y+iUz3
\C|6FwV
oo6-v!#
}+.d9#
c9U4(i
@Zz,|}
E@$"ML
n}U,"%
i)l)P)7\
K?UnT
s/p!X-
y5,LHF
:{zYnj=
HdFXwR
Jl?lGT
j8i$+f
9)c?9Pgg
U!-I^i
CMyuW>
uII6X)
t*sV>aU
A>61EW
$GL8)Oi
O~;L0_
P'j5/N@
W(&g)^
vRRksd
qsxE=v
Or,CQ'
.<7/V
%ebLr"
:m4qn;
~p)T5z
/E4>Ddv
kYj3k4@
q:ss(
pt:,*pd
JJ^{Mu
C([ n&
Rs)/YKv
aw'uJY
s#0[KP
)nJ)F=Cu
SpTSK{
EA&9#7I
_Qbb2Q
Md`9G&
Alyb,O
=$Oq@z
h;Mu"P/diW
b_ho*N
1ROuQ)f
Rptj=M
)\FsR,
G:O>n<
\f@`:}i
gxeu"$
E&7h=?
le]D1#
0MHy=\D
Gv{#@/
P<D&3?w+U
C8'JZP
UxRJ-Zz
dHcpabnI:
G(/kU,
!KgKpD
jw!,0D=
Afg<8T`JO
4VD9@+
;fL:[`]Ff*P
*1JRVUA
!6M}o/
g'cYp4
y#>7Th
GI(`Id
ArGyyO
x9e&u>
iR9E^A*#"
\'mIcQx
Ap1\oF
kjgIaF
355{/g
Dv5><N
V7~hTW'
&qu4t}P
GmJy]J^
T^|4.92C
!vzX3r&
_tXN4X
9J`~9F
uPbA!O
;-P(tG
&XuL_M
r Lvx;
_BB[y/(^
lDv?6_
a-%kW'J!#g
}uW9w1
@9=fded}
\[!%c{+l
d^0="|y
q??M=u
4>]=:Rvb
6u.Jx
J*D. p6x
)+C%c5
IQy}^N
~%jWfV
GX]ORl
/kAA==B
Xnt'L[
79c{|ZL
XT+l4nT
tWaNpM
8W+q.wM#
$?6PQ.
1}n(1i.
i!BOXv
bqEfs^5
lZfQdj{a$
`^Huy;V
h8zb)a
4EUwTUz6l
g+2Byj
r6t3$;>
tf7>[1p
J7"H0X
,&j 6C9
z;{Wg2
CK^SD9
>>P(</
-G'~wA
z.V,Pv
w}Svue
N5d5v#
X9F*-wuX
'q<W}[
I'aw]=S
D@Nb%d
YS)f@)
_|&VD=
?h.tWN
Gc2mO>
</k&{l^
Z<}]&c|
qD8_Q_
$f+^T{0
jGTx\d
jK;MvY
J.]aFm
z&d f
Cj<|Ub
d4apo
UG&RS`
\!+}ki
&yIN<V+p
7X>B/$
&XDp_`
N%~<#4+
%.(/b7
hHpah!t
Aw9(v1
\A8+reo!?]
+$nP58X'
G6///n
RC\#/DC
"E7b+x
Bb)09I
[+M6k
YM_,c&3+S6
YoRtlz
gR<rcKS
x]cAff
|Ju@QE}8
}*>j_*
tIt:\,
!.Y)`g
L!wt$-^
TG%=-NBVT/
BS=O05yK
Q6PPSs:
{n7aXM
=d>Pm1
*8W\T4
y$#!n:t
dC&|Zb
iCSw{]A
qO5' w2L
H\OPGE$
WA=bXv
A!2,LC
cs{0P#H
thn>@*
=g)vSg,
Ag`b\e
KR,j8w
!nD!k<<x
T`0ut=
L$8!9.
$TMK"/
.eK,OjnY
0g_mWs
A\(Nsa,
WWl5if
qdNrtO
<"ny&5
+(P7XsMy
mL-S"`
sS7,n<G
.uV,ps
,(\mBT
BXBG @
OZ)b)W
^,F31[
@~vhV[J
%} v~e&
zb\JBE
Ds1n]2x
DDjS/*{
K.>%vi
(U07Ub{C
63;ec,
p1&_tC
P<Y2TU
DRPf>Dq
T/u:9m
RHj?D&
qum`6r
>T&KkQyR
2X FTz
&yFF"~
?;eCx'
g4gx<G
FO8:H.
dEfVO.
`<u-0,6w<jR
X FN DU1
F~0},
0&'x8j
9QXNG`
[_]O[m0
lx-%'s
|%iaJN
z:&G7d
eMH$O@M
>$WEHv
j"\dfR)
8Ml`]C4
v5fn%F*
]l"z#j{u
P/Cg#m
["wC@u@Ea
{#yj_s
U1#yYv
/{]L.K
9xU25-[
;^}YYU
2emk/&
TN$xIt
X*mN)
5hJJOQ2q
>~|g'h
%;Kn0u
,x)eV[\
*1I4}3
CwtFg8
`+MW!D
)5-]$AA"Q=L
i$NZ4U
nk+Ay=
&c7\_V
#&u!w+
o0ZK;"
:\>BG9q
r8[UYM
'O0#
A*.5W_uz
!iiuW.
WcW0\u
~FB3K
$-8<wX
}m.fp}
d}>0\;Q
To| ,|
k!2>-Sc
e$#>*T
'e{Z%6_:
*`}d:o
yztJ->
tW?fELWC
w6MdyQ"4|'
DxL}4A
)Gn#;U
Fz(L%G
SRtJ]J}
xp&Oi
uR7S.cy
|>3wMe
P68{v
G,@#6E
<lZNgT
^;>7E5R'
.wD-1n
RZ\[wk
&^} |]
[z-\_'H6
G1OVd>|
,w3Zp46
!]zMth0
FG'`=,/(
`2\j(a
_Cge3o"
gk>M@m
`*2WeE
Dj*U>.
1wull=.
dW^U&
emBZ|vk
s0J::{r*
MriD(Av
Y/E}=d
f -aQM
=GNj-d
rWc?iP
}x2a58
"Y_7Ov
Y^C4bw
T_kD3f
EHiV%7
<r4b4T
3N~,SnR
coH1E.]
tQOyuX
k!ZjQV9
2V}<'+
(3^`2=
^+Ou:9{e
'$Mq`B
i5Kz273
[rBvvUg0
[/=:lS
Mr'"k`v
gJ`w@;
IqgtCi`F
RMqD$D
f3uSBz `
Uj(PmC3
=HW05Y
Xb,-TG
ciA}o 6
:qz#26%
i}7fQS
X-E@!xn
!IxW=M
Mb<#w
xzN&5r
@j'QD0~
'.RCa:|
3M$+q9
VFpqIAF09
1,DN{1
v|PSe&_
VqL:I,
l8tO'
x]z.Qi
XjT7c_
Sq+=;5b
Nq!oDA
YI,].u
'<?E~`
@8q:<`
Wsip5eM
HEzw C
?f=}~t7
hDaQN7
dVojCy
v<|-e$
v#La2/
z>QZ8'
(*jA
t#1ncrnM
tr~3y,
h?DsU7n
lC%]acf
}O,-CQ
WL"WQ_Y
4AC,1}b
"_;@tu;
g6')lH`
dB'7C[
/-\"||
rN8sw
BwIjZb_
!9(+Ib
")U1}c
%4iDUi
8'[@<K
qfz2S=
NG3VU:
_(n){{
@45(w>
/^IA!X
.S?8.[
D,?L?C
?3l3~Z
jWs\Pucs
6L7!P|
oaTgP-
4SwnXh
S,6o:[\
9NLR ^
m7=~|L
Rbo_rAR>
eGNGS1
8 7$$c
[h:`K"
F0coro
ij?3/7
-ZnuuE
t,%J.i
x,NP`
+bJMy>CafJ
E_F]aZ
k#Q9D*
q*DDM8
[C K>j?
:3A{w3
+L`@A#?U
\/AbMk
.F4{ (%
z+GYWB
)td#[T
eelSWK
raVKc|
[1&PF3
WV")K`
%}3r+w
~"3\7h
vF\^Ib
:KY%1L
t<aY#
G5k'\k,
"|Gck4
QI9-*U
d@ruYX
rL])QR
0.],IN
p$8npm
d2H 2L
|d?T)Y
.(O+R#}
A'wCbWT\iz
*N!{z_q
vA8/%;8#*
}?&#sP*
Ij`0o
b7`%y|
MmTR41t
[#7_X-
%*/PF/
_T7T{A
&~BryH
K&#})#5
YjjOfy
%}%>XJX
L{o#<j
w8%|/'
Hbno:r3
Mu1,8
7 zP#N^%
n EwW`
:86hxR
]vyKsv&]
:1x$bTu}D
U.xwOG
p99xOK
_V hTl
dm-@U%
uvFA$r
5XA4uL
f&QTf5
q_tcjc
/ctz>(
_kFPn"
.a]&,@
X%VZ;O}
W!oJB|
J#]hEs
p^gDAQ
#ut[wk
}F%yK!
C&u9ET
}4o'vr
L[CO~j+d
M;6ICk
%&I`Oi
5+}%ok
WVNCa-
Cw?&i=
;P1&!s
]:74R^
R{r*ep>i
A%E4Hh
LZx.(4
TO/tA1F{j
8-Hw/}0
2\KNV,
G$=K~"
&'@"bSJI$@
7Yrdq$N.
}+D#T
V>{HU{
}4v44p
g")O9
iEFDf
_IZNz%W
?TxoaTa7
F#iJB/
D72D
1{V6Hqj,
t1dws1u
&Jl9J}W
=A.N50x
/nzBB~&
!@t[0%YAH
(0gV~R
u)3oIUm
Tw1g;7
f[=HD"
y5`q*z
TX|/KWGx
S\v{XO
RYFo[ru
^%wF:d)
c1yBYYU)
+Iv}}\
cL{}FP
wgO&;8V
Flo-vz
wvSF;)
/u&#)
]$fqN*
u5SAL[8l
Eom&=R
qGUY.>T
fS3WN.
.mftU\I
yiFe'U
L"VY|r
g$,dA
7%*J[[\
>134@m
'gDvM-
sPuneQ
mUc%x
z&}_xL
7zw4;+
+YfUiB>
J_4~)o
Ke='1e
-<7h/\
@b.=ng_.VX
LY#T?m
NE+'L
r:1jTc
5N,Xem
_Vcx%2V
BxU\-~
]nvVo N
JPJ)_#
1f]n'V
NbV1=u
pA#M3J~
Q}V+`JN
-U@)4D
)o`RZO9
)NU-dy{p
BER3 "
g|[& 8
YrI+`8
7":P.tU
]z>+R7
mSIiYm
}rXVi.
8Zj*}1NY
sHm>Xn
t!lj D
>hwG}y%
v'(%@c
lbS9op9S
K9l8T|
]~6@ZY
m*qTbK-
6$7|Fs5D#
Q=L~:j
Q\+T@6
6,@OG|`Z
e<@|Px
N#*MLN][j
Fp0s7|
fxQ~>.O
{#Y1IA|
\6+nlg
%McrM|,P
8ku4uh*W
oJ(rdDg
Amvz0c2KH+QE
l$I9d^
;r:,/:
v1"}B<
MSN4`r
56m|c4(
]"v!56`;b
F0?ZW,
ImGyET
qqt]p(s
rhXh,;
qyC@s8(
hL6<wt
6E8)fk
Os`xuY9
*\i:m+%
c=y{iWPC
)0< g
Le/1~?
i}/|Sm
K#f;&
YZ$!jqP
rfU4CP
{`w`jmQ
/O;>{}_
8(qK8;
ej_r,*/
!s;pZTg
6YIKk_KH
0>kRj)-Z
@i_lEdf<
AT<)<F
ZEhL'
|}b|'5
m n@#/G
dyf,-O
Y+/WrB
pd!<%5
)Zg;#0
8nMS:`T9
y&1WXl
de|ylG
%Sf;.M3
BL~x
zLq\JMr
\P~'&\~
@iLuc%e
X?-<(-
U}qO#9
m<~z}>y
n0 pK
73M;I`
X)*U9kz
YB8MQ5
m )v%y
<RPfIZ
1TtTg-
}Gkvq*
AR-.U2
s4e<=Pi
]QpKr)>5xI
vR>Z40
GDl*(b?
y%C=KM
5rOE/V
N/rnz
hKY=y~r
K-b8|T
yzM!D?
NX/oYp
P"{MK:
\@da9p7
;|vyGG~
Pb.y ;
z:;W#(@h
?YG$ABn
03ufW+?
0?I\3N32@U
_<N62oj.)
PwcpN$#
rsh{O0
qvC$jlK
ZTLx&:
*l54xaSt
%4m+0Y
^%`]`-
BTvn-q
IO+3J!
u0{vp7
%Jh2&Y
<]HW2@Y
$Y=0cY
5:)eTy
v9T076
_kH\x9(
ui] _G
c@lW}n
q1nTQ0{9
cXS:e/|
N_@P{@=
.Zy._>N
j7mJQ*
Gep`"V
N^s:ib
0 GzMqW
>!k-.J
[c0.=$F
m'<Cr
#wE[4vg
=EPh(c
OQ9t]8v
Cmf%3S
1{6tJ#q
h*S(@b
%b:*%a7
vPQ=K=
&N)B.1c
G~W{t2
24_zP^
Bg&YfW
o4ezT+
1i^[c}
Nib/L>^W]j
3#35.d
C^m }s8XV^,Q
~rU&$[
81Zg-Z
Qoy:=MFg
+=t&iH
r|oJ6R
a1jIC[=
lg^@pe9 w
"l>FYB
\uJI5
\ny4fs
xAVJpkP
zq7q^+o"
:CFWR-
Y6Qe~mV$Sygf
0^t^X
&AqG$x
`l8f$O
;L*0w
oO6mH]2
I +}4JSM2k$
2*_IB9
pb@kuy
q+[UT7
(ma6&C
Hv|=Yc
q!COdg
jr9)5z
183~v,
uX_yxs
9'FIv]
Xu)IJ7
fDC|0E
AjF)g0
djh-H0
%ixV=Or
rA@&Xe|
L}w;`\
]zAr}x
|On~md
IjgHb<u
qY[>d\
S6gHfp5Fv
0%(H_Z9
3mq)<hF
Q,ok>>
s|cZKt
}_YbE@
Z__lyO9
P9.Ep\
y5t`r'
zdWyhd
CWW@!FX*
]lp#(Wb
H$v:Nn2
@5UtZ_
x>h,*Rr
*&%J'a
w>VQ"6+
eyyTQI
<Dc`Ws
:ZjjKF}
hA&Isp
H: Z@j:
0Qg2ZVW
NPfN=+
q>$=IJ[
9#9(G]@
Q=jH'5
4ne:\V
"+9~QdH
RX&mZ1
Wh^w]dd
5lx'Z}O-
+VVPlI
L6/KpC
h~T|u7u
W)rd{h
`Ff6vvX
l+E7>z
?!uUMR=
`aTU7
MqLmS-x
]Kmes*m
E1t7aha
bJMff+
}c|C+;~Kp
'Tpv}}&@
0]9;#A
}o^{aG
Eo""2>
ymxN\Y
\#8(m_sj
z\rSZjN
'QA_vW
E?N?0;
.KC7qI~&
ix\,]p)
4WdkZ@
D#wwavu
`IcS]j
x>7ZDs\
Q})FSMqa
n;Vy(*
b+CtbQNl
HPW!ZJoJ
N1'dXq
Qhp7S~
ba*C*7U
')L9jc#N
o%B!k2
^dc<:(
$I|x#z
Uw39P
b=++F:H(iq
EnvLl@
?AW0w
m6k.`@
4BX]!Zz
H3v ^uP
p!9kSq
XT`w<N
y";j*2a
IdQ }*r/
W6l=H/
hv/1C]"
}*TY>ix;'
9AcdVp
V~3(^/
h;8m5g
z;V;dP
wlziFm
xD90Z"
F@|U)>Nd
`&M$AD
eX(F7
=Rm%}+8WG
6O9|G;x
.VlHK2
Ogc6I
r?2<$*ZT=
k2zFCs
E9]L*R*P>
%mn1zD
F\T7V:
YNG,*O
]jo-0R
(QQhnnn
A0&dW;
37F}6M
G]9d7h
cpOS8L
/r<z&R
_jkjEc6
6'd80
FxZ35
D9xsYO
f;0)Y=
_:O~Fp
zL\p+
@j2]`G
di3;d@
-E3?gA,a
tzjerVW(z
pzGZ\z
{tVCH
?PsdEg
vV_H-4
P"$Yqg
[^6B8g
{~>HBu
/Wx7yf
61Ok'N
ec u!d
?T2Q:QJw_
_|wa^K
3;I?JHr
Co2]Cl
VUTV!q
]Azxh:
q}u924
8sEu\@
)7cS1H3
U5fMZ:
wLUD,
aU%F:!
C=%CTM
6Z)pBb'@0CR7
e`xYay<G?
!y/],w
Gg[Ej+
@p[0f,
&)k'Uy
g~_EBz|Bo
||ovu`
Hx16\%9)M5
DT5.5^
>#19xVE
Puj=V
~q@Pd}p
!syygr
DS"4U_%{3Au5
E}J)]D
dp4Zr$-
"DVgR=
PA(|Yu|J
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="X86"
name="CompanyName.ProductName.YourApp"
type="win32" />
<description></description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="X86"
publicKeyToken="6595b64144ccf1df"
language="*" />
</dependentAssembly>
</dependency>
</assembly>PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
ntdll.dll
2147483648
InputRequester
STATIC
BUTTON
SHELL32.DLL
AInvalid memory access
Array bounds exceeded
Debugger breakpoint reached
Misaligned data access
Denormal floating-point operand
Division by zero (floating-point)
Inexact floating-point result
Invalid floating-point operation
Floating-point overflow (exponent to great)
Floating-point stack overflow or underflow
Floating-point underflow (exponent too small)
Illegal instruction
Memory page error
Division by zero
Integer overflow
Exception handler returned unknown value
Exception handler tried to continue after non-continuable exception
Privileged instruction
Single step trap
Stack overflow
Unknown error code
Kernel32.DLL
Shell32.DLL
Downloads\
Kernel32.dll
#+3;CScs
sysnative
00749ED28B 0F5B01121C332D07B0BFC44188DAAFFA 5F5591911B1BE97ECFA124C33868F856(A63BB43256FC55AD90473D5A015148F0D086ADEF
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 BAT/HackTool.Agent.CL potentially unsafe
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!497EA5F14590
Trapmine Clean
FireEye Generic.mg.497ea5f145901f80
Emsisoft Clean
Ikarus Trojan.Win32
GData Clean
Jiangmin Clean
Webroot Clean
Varist W32/ABRisk.MWXI-6748
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXWO-ZS!497EA5F14590
MAX Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Hacktool.Agent/BAT!8.13765 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36812.ZuW@a4Ydool
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (W)
alibabacloud HackTool:Win/Agent.CE
No IRMA results available.