Static | ZeroBOX

PE Compile Time

2024-10-12 20:38:01

PDB Path

C:\Users\SERVER\Desktop\MMOParadox Expansion Launcher\update\obj\Release\update.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0071e470 0x0071e600 7.24255260558
.rsrc 0x00722000 0x00005180 0x00005200 6.08202721872
.reloc 0x00728000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00726620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00726620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00726620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00726620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00726620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00726a98 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00726af4 0x00000370 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00726e74 0x00000306 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+>2(l
@j2"r3
v4.0.30319
#Strings
<>9__22_0
<MainWindow_Loaded>b__22_0
<.ctor>b__4_0
<>c__DisplayClass4_0
<OnClosing>b__5_0
<.ctor>b__4_1
EventHandler`1
BandwidthList`1
ReadUInt32
ToInt32
<.ctor>b__2
Dictionary`2
ToInt64
<Module>
update.Classes.WebBrowserOverlayWF
get_ASCII
get_OPTIONCLICK
get_STARTCLICK
get_OPTIONNORMAL
get_STARTNORMAL
get_BACKMAIN
System.IO
ShowCharacterHP
ShowMonsterHP
get_OPTIONOVER
get_STARTOVER
DecryptStringAES
EncryptStringAES
get_IV
set_IV
Width_EX
Height_EX
get_mainEX
value__
System.Windows.Media
System.Windows.Data
CUpdateData
CHashData
get_PercentDelta
mscorlib
System.Collections.Generic
CancelAsync
RunWorkerAsync
baseId
diskId
connectionId
videoId
biosId
OpenRead
Thread
Download
pb_download
add_Loaded
MainWindow_Loaded
_contentLoaded
get_Downloaded
set_Downloaded
file_downloaded
Recommended
RijndaelManaged
add_IsVisibleChanged
add_SizeChanged
add_LocationChanged
OnSizeLocationChanged
add_ProgressChanged
bgWorker_ProgressChanged
add_PropertyChanged
remove_PropertyChanged
INotifyPropertyChanged
add_ExtractionFinished
extr_ExtractionFinished
Interlocked
set_IsEnabled
add_LoadCompleted
web_browser_LoadCompleted
add_RunWorkerCompleted
bgWorker_downloadupdate_RunWorkerCompleted
bgWorker_RunWorkerCompleted
add_FileExtractionStarted
extr_FileExtractionStarted
bgWorker_check_Completted
bgWorker_hashchecker_Completted
bgWorker_updater_Completted
completted
Windowed
Synchronized
RootGrid
<CabalMainBuild>k__BackingField
<Maintenance>k__BackingField
<file>k__BackingField
<Update>k__BackingField
<Hash>k__BackingField
<UpdateHash>k__BackingField
<CabalHash>k__BackingField
<CabalMainHash>k__BackingField
<hash>k__BackingField
<UpdateRevision>k__BackingField
<UpdateVersion>k__BackingField
<version>k__BackingField
<CabalMainConstructor>k__BackingField
<Hashes>k__BackingField
<Updates>k__BackingField
<Settings>k__BackingField
<count>k__BackingField
<maxCapacity>k__BackingField
get_Build
get_CabalMainBuild
set_CabalMainBuild
cabalmain_build
cabalmainbuild
ReadToEnd
Append
UriKind
SetPassword
password
get_StackTrace
get_TransformToDevice
get_Maintenance
set_Maintenance
RenderDistance
CheckInstance
defaultInstance
HwndSource
PresentationSource
SetSource
source
LanguageCode
FileMode
CryptoStreamMode
DisplayMode
MessageBoxImage
CalculateAverage
get_Message
get_Percentage
set_Percentage
get_ProgressPercentage
percentage
Language
CompareExchange
DnsFlushResolverCache
BeginInvoke
IDisposable
get_IsVisible
ToDouble
get_Handle
RuntimeTypeHandle
GetTypeFromHandle
ReadSingle
DownloadFile
GetMd5HashFromFile
WriteResourceToFile
get_file
set_file
Console
process_Game
ShowNPCName
get_Name
ShowGuildName
resourceName
DisplayModeName
get_FileName
set_FileName
fileName
get_MachineName
get_FullName
ShowItemName
get_UserName
ShowMonsterName
ShowPlayerName
get_ProcessName
GetName
GetProcessesByName
AssemblyName
propertyName
launcher_ininame
appname
launcher_hostname
client_hostname
DateTime
startTime
SoundVolume
AmbienceVolume
JukeboxVolume
WriteLine
get_NewLine
Combine
ValueType
targetType
PresentationCore
get_Culture
set_Culture
resourceCulture
get_InvariantCulture
culture
PropertyChangedBase
ButtonBase
SevenZipBase
ApplicationSettingsBase
WindowsBase
Japanese
Portuguese
WebResponse
GetResponse
btn_close
Dispose
RefreshRate
uptodate
CUpdate
get_Update
set_Update
bgWorker_downloadupdate
Create
Delegate
Navigate
ConfigTemplate
EditorBrowsableState
Delete
LoadRemote
SaveRemote
ConfigRemote
remote
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyAssociatedContentFileAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
ValueConversionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
ThemeInfoAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlElementAttribute
XmlRootAttribute
XmlTextAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ReadByte
ProvideValue
maxvalue
wmiMustBeTrue
BeginExtractArchive
recursive
DragMove
Remove
update.exe
get_DownloadSize
set_DownloadSize
get_KeySize
Serialize
Deserialize
file_size
Resize
LastIndexOf
mgr_cfg
System.Threading
System.Windows.Threading
get_CancellationPending
ASCIIEncoding
add_PropertyChanging
remove_PropertyChanging
INotifyPropertyChanging
is_working
IsRunning
running
System.Runtime.Versioning
FromBase64String
ToBase64String
ToString
GetString
GetHexString
OnClosing
add_Navigating
web_browser_Navigating
add_Extracting
extr_Extracting
set_Formatting
System.Drawing
get_Hash
set_Hash
get_UpdateHash
set_UpdateHash
ComputeHash
get_CabalHash
set_CabalHash
get_CabalMainHash
set_CabalMainHash
GetHash
get_hash
set_hash
updatehash
cabalhash
cabalmainhash
English
GetTempPath
SetLibraryPath
filepath
get_ActualWidth
nWidth
get_AverageBandwidth
set_AverageBandwidth
avgBandwidth
get_CurrentBandwidth
set_CurrentBandwidth
crntBandwidth
get_Length
get_ContentLength
EndsWith
get_Uri
set_StartupUri
fileuri
ConvertBack
AutoAttack
pb_check
btn_check
bgWorker_check
add_Click
btn_close_Click
btn_startcabalfg_Click
btn_check_Click
btn_startcabal_Click
btn_option_Click
TextBlock
add_DoWork
bgWorker_downloadupdate_DoWork
bgWorker_check_DoWork
bgWorker_hashchecker_DoWork
bgWorker_DoWork
bgWorker_updater_DoWork
PresentationFramework
process_cabal
btn_startcabal
ConfigLocal
get_close_normal
FromVisual
get_Cancel
set_Cancel
System.ComponentModel
MainViewModel
BlurLevel
SpecialEffectLevel
ShadowLevel
user32.dll
dnsapi.dll
System.Xml
System.Xaml
ContentControl
GetManifestResourceStream
FileStream
GetResponseStream
CryptoStream
MemoryStream
get_Item
OperatingSystem
SymmetricAlgorithm
HashAlgorithm
MainForm
ICryptoTransform
resourceMan
Korean
German
TimeSpan
ClientToScreen
Borderless_Fullscreen
get_main
client_cabalmain
AppDomain
get_CurrentDomain
get_Revision
get_UpdateRevision
set_UpdateRevision
get_LauncherRevision
set_LauncherRevision
launcherrevision
MarkupExtension
get_OSVersion
get_Version
get_UpdateVersion
set_UpdateVersion
get_version
set_version
updateversion
Application
ResourceDictionaryLocation
System.Windows.Navigation
set_WorkerSupportsCancellation
SupportCancellation
DispatcherOperation
System.Configuration
System.Globalization
System.Xml.Serialization
Action
op_Subtraction
System.Reflection
ManagementObjectCollection
add_UnhandledException
CurrentDomain_UnhandledException
ArgumentNullException
SystemException
ApplicationException
LauncherException
innerException
btn_option
get_ChangedButton
MouseButton
MessageBoxButton
add_MouseDown
RootGrid_MouseDown
add_KeyDown
Window_KeyDown
Shutdown
FileInfo
CultureInfo
FileSystemInfo
FileVersionInfo
GetVersionInfo
get_StartInfo
ProcessStartInfo
DirectoryInfo
ScreenRatio
Crypto
Bitmap
SevenZip
xtrap_server_ip
dir_temp
ShowComboUIonTop
System.Windows.Interop
SevenZipSharp
System.Windows.Markup
OnStartup
ProgressBar
StringReader
StreamReader
TextReader
BinaryReader
get_FileDownloader
set_FileDownloader
downloader
IServiceProvider
MD5CryptoServiceProvider
serviceProvider
IFormatProvider
StringBuilder
currentfolder
sender
get_ResourceManager
ConfigManager
get_Dispatcher
identifier
IPropertyChangedNotifier
bgWorker_hashchecker
BackgroundWorker
bgWorker
SettingsHandler
SizeChangedEventHandler
ProgressChangedEventHandler
DependencyPropertyChangedEventHandler
LoadCompletedEventHandler
RunWorkerCompletedEventHandler
RoutedEventHandler
PropertyChangingEventHandler
DoWorkEventHandler
NavigatingCancelEventHandler
UnhandledExceptionEventHandler
MouseButtonEventHandler
KeyEventHandler
System.CodeDom.Compiler
get_Owner
set_Owner
get_WebBrowser
web_browser
bgWorker_updater
parameter
StringWriter
XmlWriter
StreamWriter
XmlTextWriter
BinaryWriter
Quarter
BaseConverter
IValueConverter
SizeFormatConverter
StringFormatConverter
BandwidthFormatConverter
CheckFormatConverter
BitConverter
get_close_hover
XmlSerializer
xmlSerializer
get_Major
get_Minor
DashtoCursor
ManagementObjectEnumerator
GetEnumerator
get_FileExtractor
set_FileExtractor
SevenZipExtractor
extractor
.cctor
IComponentConnector
get_CabalMainConstructor
set_CabalMainConstructor
launcher_constructor
CabalConfigEditor
CreateDecryptor
CreateEncryptor
System.Diagnostics
get_TotalSeconds
get_TotalMilliseconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetInstances
System.Resources
System.Windows.Resources
update.g.resources
update.Properties.Resources.resources
AllowTrades
DebuggingModes
CHashes
get_Hashes
set_Hashes
GetDirectories
update.Properties
ShowDialogueBubbles
CheckMainFiles
GetFiles
downloadable_files
ReadAllLines
GetHostAddresses
CUpdates
get_Updates
set_Updates
AllowPartyInvites
FileAttributes
SetAttributes
ReadBytes
Rfc2898DeriveBytes
GetBytes
System.Windows.Controls.Primitives
CSettings
get_Settings
set_Settings
RemoteSettings
SizeChangedEventArgs
ProgressChangedEventArgs
DependencyPropertyChangedEventArgs
RunWorkerCompletedEventArgs
RoutedEventArgs
FileOverwriteEventArgs
PropertyChangingEventArgs
DoWorkEventArgs
NavigatingCancelEventArgs
NavigationEventArgs
UnhandledExceptionEventArgs
MouseButtonEventArgs
FileInfoEventArgs
StartupEventArgs
ProgressEventArgs
KeyEventArgs
<>4__this
update.ViewModels
System.Windows.Controls
update.Forms
Contains
update.Classes.Functions
AllowWhispers
wmiClass
ManagementClass
FileAccess
GetCurrentProcess
get_ReportProgess
set_ReportProgess
IPAddress
set_WorkerReportsProgress
ReportProgress
reportprogress
ShowDistortionEffects
ShowWeatherEffects
set_Arguments
add_FileExists
extr_FileExists
CheckHosts
ShowShouts
get_ReportStatus
set_ReportStatus
lbl_status
reportstatus
System.Windows
UseFunctionKeys
Concat
update.Resources.CabalFiles.mainEX.dat
update.Resources.CabalFiles.main.dat
Format
Extract
ManagementBaseObject
get_ExceptionObject
DispatcherObject
GetObject
ManagementObject
DependencyObject
System.Windows.Markup.IComponentConnector.Connect
System.Net
get_WorkingSet
HwndTarget
get_CompositionTarget
SetTarget
_webBrowserPlacementTarget
_placementTarget
target
sharedSecret
get_ActualHeight
nHeight
get_Default
MessageBoxResult
percent
WebClient
System.Management
UIElement
FrameworkElement
newElement
Environment
LoadComponent
InitializeComponent
get_Current
dir_current
set_Content
bRepaint
TranslatePoint
lpPoint
FingerPrint
fingerPrint
get_Count
get_count
set_count
account
GetPathRoot
LayoutRoot
get_FilePrivatePart
ThreadStart
Insert
Convert
Report
AllowPvPRequest
WebRequest
System.Windows.Input
pb_downloadPercentTxt
MoveNext
System.Text
get_Text
set_Text
plainText
cipherText
status_text
set_DataContext
CameraView
get_Now
MoveWindow
MainWindow
GetWindow
Matrix
MessageBox
Display
WebBrowserOverlay
ReadByteArray
ToArray
get_Key
set_Key
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
targetAssembly
CreateDirectory
set_WorkingDirectory
get_SystemDirectory
get_CurrentDirectory
GetCurrentDirectory
directory
get_maxCapacity
set_maxCapacity
capacity
WaterQuality
op_Equality
op_Inequality
set_Visibility
CheckSecurity
IsNullOrEmpty
wmiProperty
set_Proxy
IWebProxy
WrapNonExceptionThrows
RIF Launcher
Copyright
Rise of Fenix 2018
RiseOfFenix
1.0.0.0
additions/7z.dll
libs/sevenzipsharp.dll
%libs/system.windows.interactivity.dll
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8#
PresentationBuildTasks
4.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.11.0.0
ZSystem.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089ZSystem.String, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
ConfigTemplate
RemoteSettings
AnonymousType
UpdateHash
CabalHash
UpdateVersion
LauncherRevision
CabalMainHash
CabalMainBuild
Settings
Hashes
Updates
Maintenance
UpdateRevision
CabalMainConstructor
Update
version
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
update
4update.Classes.WebBrowserOverlayWF.WebBrowserOverlay
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
WindowStyle$
ShowInTaskbar
ResizeMode$
NoResize=
LayoutRoot
"System.Windows.Controls.WebBrowser
G/>jGy
888888888
>iV#@.
NNNNooNNNo
'uAAAuuAA
TbXXbT
LLLLLL
cLLLLLLX
LLLLL,
TbXXbT
=update, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
C&clr-namespace:update.Classes.Functions
update.Classes.Functions
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
X@clr-namespace:System.Windows.Data;assembly=PresentationFramework
System.Windows.Data
update.Forms.MainWindow
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
converter&clr-namespace:update.Classes.Functions
data@clr-namespace:System.Windows.Data;assembly=PresentationFramework
MainForm
Title$
Launcher Cabal Online
ResizeMode$
CanMinimize=
SizeToContent$
WidthAndHeight=
WindowStyle$
AllowsTransparency
WindowStartupLocation$
CenterScreen=
Icon$#
/update;component/favicon.ico
Resources
.update.Classes.Functions.StringFormatConverter
PercentageConverter
-update.Classes.Functions.CheckFormatConverter
CheckPercentageConverter
1update.Classes.Functions.BandwidthFormatConverter
BandwidthConverter
,update.Classes.Functions.SizeFormatConverter
SizeConverter
MergedDictionaries
Source
/Resources/Themes/Generic.xaml?
RootGrid
ImageSource$5
//update;component/Resources/Images/BACKMAIN.png
AlignmentX$
AlignmentY$
btn_close
764,54,0,0q
CloseButton#
_webBrowserPlacementTarget
0,0,0,0q
Collapsed=
btn_option
OptionButton#
753,10,0,0q
3/update;component/Resources/Fonts/#Segoe WP N Black)
RenderTransformOrigin$
0.471,0.095&
Hidden=
btn_check
CheckButton#
808,385,0,0q
3/update;component/Resources/Fonts/#Segoe WP N Black)
Hidden=
Download:
90,507,0,0q
#FFA0A0A0$
Arial)
Right=
697,507,0,0q
#FFA0A0A0$
Arial)
Center=
ReportProgess.Percentage+
Converter#
pb_downloadPercentTxt
550,526,0,0q
TextAlignment$
Right=
LineHeight$
#FFA0A0A0$
Arial)
Visible=
StringFormat$
{0} | {1} - {2}
Path$
FileDownloader.Downloaded
FileDownloader.DownloadSize
FileDownloader.AverageBandwidth
Progress:
90,474,0,0q
#FFA0A0A0$
Arial)
Right=
698,473,0,0q
#FFA0A0A0$
Arial)
Center=
FileDownloader.Percentage+#
lbl_status
67,521,0,0q
#FF0084ff$
Arial)
ReportStatus.Text+
btn_startcabal
PlayButton#
366,545,0,0q
3/update;component/Resources/Fonts/#Segoe WP N Black)
pb_download
173,479,0,0q
dProgressBarTemplate#
IsIndeterminate
FileDownloader.Percentage+
OneWay=
pb_check
173,512,0,0q
cProgressBarTemplate#
ReportProgess.Percentage+$
OneWay=
EBDT19
EBLC|5o
GPOSid;
G^OS/2
`cmapQ
glyf/h
<Jkern7
loca4!
maxp!C
prepk
EMWY[]}
" & 0 4 : > D _ q
! !"!&!.!2!N!_!
"")"+"H"a"e#
 HPY[]_
& / 2 9 < D ^ p t
! !"!&!.!2!M!S!
")"+"H"`"d#
'v,`,t.
EMWY[]}
" & 0 4 : > D _ q
! !"!&!.!2!N!_!
"")"+"H"a"e#
 HPY[]_
& / 2 9 < D ^ p t
! !"!&!.!2!M!S!
")"+"H"`"d#
'v,`,t.
@Gd_^]\[ZYXUTSRQPONMLKJIHGFEDCBA@?>=<;:98765/.-,(&%$#"
,E#F`
&#HH-,E#F#a
&#HH-,E#F`
&#HH-,E#F#a
&#HH-,E#F`
&#HH-,E#F#a
&#HH-,
<-, E#
D#Y!!-, E
!!Y-, E
d#da\X
+#D-,KRXED
b`#!-,E#E`#E`#E`#vh
&`bch
#DD-, E
!!Y-,E
0/E#Ea`
`iD-,KQX
!!Y-,KQX
%EiSXD
!!Y-,E
/ED-,E# E
`D-,E#E`D-,K#QX
aY#XeY
!!!!!Y-,
`#B< X
!Y!!!!!!!-,
`#B< X
!Y!!!!!!!-,
%EH!!!!-,
%CH!!!-,E# E
P X#e#Y#h
@Y#XeY
`D-,KS#KQZX E
!!Y-,KTX E
!!Y-,KS#KQZX8
!!!!Y-,
!!!Y-,
!!!!Y-,
!!!Y-,
KQZX#8
F#F`#Fa#
pE`h:-,
!Y-,KRX}
C`BYYYYY-,E
h#KQX# E d
@PX|Yh
#2!!-,
#y!!!!!!!!!!!!-,#
[+-, EiD-
zUyUwUx
FqUoUp
oUnfmUj
%i8gUh
gUf8dUe
dUc8bUa8`U_8]U^
]U\8ZU[
ZUY8XUW
%V8TUU
TUS8QUR
QUO8NUN
%M8KUL
KUJ8HUI
HUG8FUE
BY+^sus++t^s++^st+st+stt^s
u^st++++^s+^s+stu^s^s^su^s+^s
++++++++++++++++++++++++++++++^su^s++^s_sssst++++++^st++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
d+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++Y+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
5'&6332>
(7B"KlE"
99//]]
+]++++++
#"&&67
=<&A>
#"&&67
99//]q
#!"&55!
+++++2
+++++10
8OcqI
+A*5\E(
s=gR>*
',TzM.TG8
546332654&''.
3H-#>.
@[^*J-;
+++++10]
+++++210%
54677!"&5
*C*/I4
&8&#J+>'
+++++210
'@'`'
!"&54>
+++++2
+++++210]%
5/(HR5
+++++10]%
#"&54>
+++++10
#."0
+++++210+++%
+++++10%
9//10%
+++++2
+++++2
+++++2
+++++2/310%
4c`]/O
/GR =*4Q*U
+++++10
#"&&67
L"/LL/"
+++++210
*MimL)
?\yWOj4
4&'&&##
*O%DlL(
?]xW^|
)>*InH(
+++++2
4&'&&##
KsN'#B\9 4-(
8VoCAgO:
99//++]
99//++
+++++10
3PqJ8]C$2RinhR3;i
/D]:6P4
2SjnjS3
7P37N;13>TqOQ
0B%6N<23=Sq
M'M',R
546332654&''.
4H,#?-
3PqJ8]C$2RinhR3;i
/D]:6P4
2SjnjS3I
7P37N;13>TqOQ
0B%6N<23=SqMZ
+++++10]
,SuIKuQ+
#"&54>
CzhU;
,SuIKuQ+
99//++++10
]]]+]+%
&&6632
7R*R#0
9??10]]]]
+]+]+]+]+]%
&&6632
]]]]]]%
#"&&67
&&6632
+++++10
&&6632
5t;9q7
#!"&554>
#"&&67
=<&2A
54677'!
#"&&67
'8$(Y-9
#!"&55!
#"&&67
$6#+M9"
34VE2"
"DcA'D:-
&?]@FsQ,/VwI=W=(
546332654&''.
3H-#>.
&?]@FsQ,/VwI=W=(
,>>,
54677!"&5
&9$+E,9
0*#CeI0<
L"JKJ"
R(UUV(
4$-d$h
!JxXXyK# KxXXzL!
L/""/L
9///33
-e?YxK"JvXBm)D
4&'&&##
#D :[@"
3NeJHb
4&'&&##
#D 9\@"
3NeKHc
%6"5xA
!JxXXyK# IxXX{L"\
C{kZ$.A
&FgA4VE2
-Fa<-L7+FZ]ZG*4\|H*RC1
)=R3'@,
,GZ^ZG,
);&)=/%*3EaA@iJ)
+>.'(2D^
546332654&''.
3I,#>.
-Fa<-L7+FZ]ZG*4\|H*RC1
)=R3'@,
,GZ^ZG,
);&)=/%*3EaA@iJ)
+>.'(2D^
#E_99^D!
aeD""DcX
J%6N0
&D_99]D"
aeD""Dd_
&&6632
7e*e0#
&&6632
#"&&67
&&6632
&&6632
#!"&554>
!"&54>
9/]q^]
++++2910^]%
#"&&55
QGsQ->t
1N9=aI1
DdBYPAo=
Z?F%FfALpJ%F4P5
-?)FSBD
9/]q^]
#"&54>
RGsQ->t
1N9=aI1
DdBYPAo=
>oAF%FfALpJ%F4P5
-?)FSBD
@@+!aM
PJ?<O<
9/]qr3]
99//]]?
FqR?cI0
6Vp@EoYE
!LV^4GsQ->t
1N9=aJ2
BVf4@bI3
<Z;=\?!
DdBYPA|
'!KxV.
,>('>-
%Ff@MpJ%F4P5
(9"JODt
AfH'.Le7
-?)FSJ
++++2910]
]+IFF'
(KHH(b
4V@ >@E'D|C>X7
+++210%
!@]<9V?+
8J8JE=
99//]]
546332654&''.
4H-"?-
!@]<9V?+
oG?:O:
:L:LG?
99//]]?
0G1>{E
!@]<9U?*
M^D$XU
6H)?M0
C,BrT1
^G?)O)
););6.
99//]]?
!@]<9U?*
6H)8U/
C,BrT1
3=3O3O3w
RdRd_W
99//]]
#"&54>
-B)(B.
!@]<9V?+
D+BoR..V
2F*8Q2
{F?,O,
,>,>91
99//]]?
#"&54>
546332654&''&&54>
-B)(B.
!@]<9V?+
4H-#D!
2F*8R1
D+BoR..V
+++++2910]%
C}D?X7
4VA!=@F'
ESW<b|@D
C}E>X7
4VA!=@F'
SX<a|AD
8B=3G)
'&&6632
'HA=:W:
5XADgE#
@*/6?6o6
9/++10]
FpQ@dI/
yw=\>"
'!KxV.
9/]qr9
#"&54>
FpQ@dI/
yw=\>"
'!KxV.
#"&54>
#HmJ#B$
DH4L$H
#"&54>
]+IFE(
)JHI'b
4V@ =AE'C|D>X8
|__JYc
J JoJoJ|
HvLiLYHEL?
9?????
#"&54>
4V@ =AE&C|C>X7
(JHI'b
]+IEG'
$HkG,B
#"&54>
$HkG,B
%HkG+C
MH=L-H
#"&54>
0G1>{E
M^D$XU
pSS>MW
>c>c>p+
zHjL]LMH
#"&54>
.I0>{D
$HkG,B
M^D$XU
60,QHM
#"&54>
#"&54>
`@Va @@/J aa
(GaP[E
#"&54>
#"&&677>
#"&54>
#"&54632
32654632
->&0D4+
ZP 3*#
(G[GeQ
#"&54>
#"&54>
#"&54>
<[>B]:
DeC#$Ec@
#"&54>
!D*-G3
#"&54>
$HkG'B"
@C=9xH
CH3L&L
#"&54>
$HkG,B
/)%bHw^
#"&54>
$HkG,B
@ /)%bH
#"&54>
#"&&677>
$HkG,B
/)%bH^
#"&54>
#"&54632
32654632
$HkG,B
,?%1C5*
ZP 2+"
fpWvV|R(
#"&54>
$HkG,B
fpWvV|R(
/)%bH^
#"&54>
$HkG,B
fpWvV|R(
/)%bH~j^
#"&54>
$HkG,B
<[>B]:
fpWvV|R(
DeC#$Ec@
BYY5e6
LH<L/L
#"&54>
!D*-I1
$HkG,B
/)%bH^
#"&54>
$HkG*D
%HkE*E
g""gc2
#"&54>
uMHsbWbI
#"&54>
#"&&677>
z0HtS.
^A^A2uokP3
uHeLXLK
#"&54>
$HkG,B
^HNL>H*L
99????
#"&54>
RHBL5L%H
??????
#"&54>
$HkG,B
#"&54>
SS0/
FH6L)L
#"&54>
$HkG,B
_M@H3H::
#"&54>
#GmJ%F
1+'yHlHss1f
#"&54>
#HmJ'D
$GmJ#B#
3Q:W^]
9////++
7&&5467&&54>
CpR.4k
!1 1/2%$4\
t#$W/NxS,
!=Y;>pU1%@Y4!>83
L,=`&%]BMzT-
\g 8I(Yf7H
R8I2>P
-IiD@aB )JGG'c
_)GEG)
C}D?X7
4VA!=@F'%m
=eLe)9$
SW<b|?E
++++910]%
.I0>|D
M^D$XU
???3/]3
#"&&677>
.I0>|D
M^D$XU
/I0>{E
N^D$XU
?#O#o#
++++++10]%
#"&54632
,;:+,;:+
0:*)9:*)
#"&54632
E*-H1
',;:+,;:+i
:*)9:*)
#"&54632
#"&54632
)EdD?\=
"EFJ&YwG
,;:*+;;*
D+;;*,;:*%m
=eLb%6$
0:*)9:*)9:*)9:*)
++++10]
#"&54632
,;:*+;;*
0:*)9:*)
+++++10]]%
++++10]%
AJ>F-8I-L
+++++9
+++++910]
,D.9sE
,C.9tD
-QKG$WvI
#9^D$XU
#9^D$XU
/A(1D*
+++++910]
.I0>|D
M^D$XU
<J9(3I(L
!EhG1D
.I0>|D
M^D$XU
+++++/]
+++++10]]]]]]]]]
>jOIiD!
?jOHjD
#"&77.
JlG"&0
Yl{Ao
Vl|M(NI=
FpQ?dJ/
zw=\>!
>jOIiD!
?jOHjD
'!KxV.
_d_dB~
Jb_a`Ds
.Le7[J
++++2910]
^(DA@$
)LMQ-b
3V@ >@F'DzC>Y7
^(EB@$
&GGL+b
4VA>@E'D|C>W8
++++2910]
)JHI'b
_(FEG*
C}D?X7
4VA!=@F'
SW<b|@E
++++910]
/K?KOK
@$2$2
++++++10]
+?V8*D2
'@PUQ@')R{R$H:)
"6I/*@)
(@RUS@'
#6%&4("+>V<5aI,
'5( "*<T
&P&`&p&
L&L&+Q
546332654&''.
4H,#?-
+?V8*D2
'@PUQ@')R{R$H:)
"6I/*@)
(@RUS@'3g
#6%&4("+>V<5aI,
'5( "*<T:CnP
uF8\jFK
RPR`RpR
.R.RW3
#"&54>
.B)(C0
"5J/*@)
(@RUS@'3^
+?V8*D2
'@PUQ@'-Pk>
'5( "*<T:ElJ&
#6%&4("+>V<:aE&
H&BoQ..V
lPl`lpl
.l.lq3
9//////
#"&54>
546332654&''.
.B)(C0
"5J/*@)
(@RUS@'|o
4H,%C!
+?V8*D2
'@PUQ@'-Ok?
'5( "*<T:l
#6%&4("+>V<9aE'
H&BoQ..V
76654.
(5'&;)
0J4<T3
&8-')0>P64S>(
5#F6#(He;
l;6Xr=1WN
0C64Ga
+++++2
#"&54>
335#".
!A-Gc?
RAA2d3
XNdH^^
#"&&#"
#"&54>
:#HmI"C$
#"&54>
E*-G3
#"&54>
NHAH;; H0H
#"&54>
h^{n{nh
222???
9/////
#"&54>
#HmJ%A"
0c0?0##0?
V\\ i0i
#"&54>
!D*-H2
dMHL>H1H++ 808
]9/????
#"&54>
++++++
+++++910]%
/H0>{E
O_C%XU
/H0>|D
O_C%XU
/+++++
+]10]]]+]]+]]+
]]]]++++++]+]++
/+++/++++10
]]]]]]]]]+]++
9/++10
]++]++]+]+++%
#"&&67
&&6632
9?10]+]+
]]]+]]+!
&46632
]10++%
#!"&554>
!"&54>
C0C@C
#"&54>
#!"&5463!2
&f<4T; +QuLZ
!6('B1"
;hAIe?
2J15O4
#!"&5463!2
,S|PU}Q'*S~UPzQ*%
'A1,@)
'B0)@+
.S?%!;S21S=#
#!"&5463!2
#"&&47
#"&54>
%]:,K6(KlCT
3&%<-
;d=D]9
,?*.E-
2Y3@Z8
2$%F/(G)#2
-%/PjD%D5 )6
#"&54>
326632
(?!GLKJ+A&
/a<B[9
A_?1R(
(G($4
A/1/Oi<FsO+&&
S.. 4C#$F5!+5
#"&54>
)B1&?2!
'JkDFd?
FqN*(F^6
#"&5463354>
1+1+1%
5467&&5467&&54>
!>V58
#IoKHfA
&8"(C4
.Z0:Q2
*($>S9
#"&54632
"0.!".0!
#"&54632
"//!#./!
9q<6)2p)s
2`3;R1
B3.$=R8
)OrHOpI"'LuNJnI%
%=.*=(
CpR-'LmGCoQ,)KmI(G5
4G,*F4
3a<@Z8
2$%H-(F($3
B10/OkD%D5 +4
2X5@Y8
(G($4!
3&$I.
-%/Oi<FsO+
.. 4C#$F5!+5
32654.
$?Y5 ;.
(6%->*>I?) 9Q2
$/2++?J?*
(@5'<+
#"&5463354>
0e3;Q1
A2.$=R8
#"&&47
&&6632
#!"&554>
#"&54>
''&&6632
''&&6632
''&&6632
#"&&67
#"&&67
#"&&67
#"&&677>
#"&&677>
#"&&677>
''&&6632
''&&6632
''&&6632
32654632
hY%:0('&
d]6N?7 $%
cv)1*54
#"&54>
2I/5MA9 +!"
3H,5N@: $(
/M7&.&:*
#"&54>
g^5NA9 *"
4I,5N@9!#)
]k$+#2*
#"&54632
#"&54632
>(66&'67&
b(66&'67&
7('58((57('58((
#"&54632
#"&54632
:(44&'44'
7(44&'35'
6)'57)(56)'57)(
#"&54632
#"&54632
B)77'(77(
)76()68'
%7)(68('77)(68('
#"&54632
#"&54632
F*88()88)
)97)*79(
8*)78)(78*)78)(
!Aa@Da?
DeD"$Dd@
#Ba>Da@
AdE#&Fb=
#Db>Cb@
?cF%)Gb;
4J/1I/
3K0\ej+1,-)3,-
/A((D1
_X)93),75
4L/3J1
4L2]fl
-.+3,-
0D()D1
6M03K2
6M1ahp+1./+4.,
0D)+F1
a\*92+.65
HO'_'o'
/]_]+?
#"&&67
0D*.E.
0F-+D.
*+'0+)
)9"#;+
/+_]]?
#"&&67
1F*/H1
2H/Y`f
+-)2*+
*;$#=-
_^]+]q
#"&&67
3H,1I1
2J0-H1
+=$%?-
#"&&47
#"&77>
#"&54632
K,98*+98+
8*)68*)
#"&54632
Q,;:+,;:+
:*)9:*)
#"&54632
K,98*+98+
%7+)78*)
#"&54632
K,98*+98+
8*)77+*
546332654&''3
4H-"?-
!E(-K4
#"&&67
#"&&677>
#!"&554>
#"&&67
9////10
#!"&5463!2
#!"&5463!2
($$(*#
(%%(*##
#!"&554>
55463!2
(>R-R'3
#!"&554>
54633.
&<WsJJu[>(
_?yjY@$'C\jt9e
#!"&55467
>
"L{XZzM"!JzYZ|M#
#"&&67
9////10
5463!2
#!"&54>
#!"&5463!2
#""#&!!
#!"&554>
55463!2
$M{YZ|M"
Z{M!"NzY
>e-e'3
#!"&554>
54633.
!JwUWxK"
,I\rJM
COuYH*
}'@S-?Y9
4UB;[= M
-K:+H5
G)PwOHjG'
C[koi,Ug9
U'<c~BG
##"&54>
W)_]EiG$
-J47R5
7z<Dc>
m:7^xAj
@`{O;cH( $
)EZ1+N:"(KkC
3Q9LkE!
aQAfH+
!/<H)<aC%
L)Kh>3WI>
A`?(0
{-WTO#
*QtI7hV3
6Od7&6$
!6O~jJ&
=iR7_C%
?eJ9_E'
8:;!5X?#
#-8Wet
a;e`a7
MbxIBsV1+Op
1F+,:$
1LhA5L2
=]A=iK0
)Jf=*L>/
)2:#9bH(
*:$":*
7!"&54>
&@R^XK-=l
9R\ZG-P)SF1
(<M*%'
.I0>|D
uM^D$XU
!AeGGeC#
AgIIgC
,>S3&8"
8S6RqC
>"JyVX
1Uq@4dL.<s
#"&&67
IWTI '
)DZ`aW*"A_B.O:!0g
.$A]<
=YbaM0S(RE1
(<M+#(
/WrM;p_K
(AT,3Q:
!#!"4Tk77K;!
$!)$M0$M;;M$0
7&&54>
##"&54>
(EZ`bT-9S4T^ ;S4
WInK';[b`M0S(RE1
(<M+#'
.UwL:j[G
z^1`R@
2Rf4RT!#!!.Nf9;P9"
95999
5#"&54>
8\BG_;
5{>F`<
a7;b~B
,E.(NsJ#
(CX__A)
#5N7:[?!,H]a^H.S(RE1
(<M+"'
/BCVj>~
7#"&54>
cQZ`0!$
5Q7=`B#
^/YXY.
YImJ%,^
f1jkh0
+L%N57
|S* M~_
S|R* L
7#<M*!.
=,(>2)
:T')R%
LI7F!I1=
54654&'&>
/; J J%E
-8a~E,PF8
4J, ;-
(@.-H1
)>,QT8x
:pfVA'
:cH+5^
#"&54632
#"&54632
$22#%03#
1%12#$13#
4&%35&&34&%35&&
&!'BiS
!&!'ChS
463!54>
7663!2
q9zqCqCq
lR9z`T
ZRHR)U
3<L0(A6.
+5C,2L<1
NS&N@&NN&@
+FeFBmM+(OvM
;W;@dH2
a/'CZ2<hL,
!<T37Z@$
:U7,J3
.TvHBiM1
/8B)/I>4
7663!2
6<H]uK
%A<742
7663!2
6<H]uK
%A<742
&&6632
&&6632
:\yDN~\7
BrY7i4
5463!2
99//10
$,$<v
(6???:$
( #)"Cs
#8UsLl
*08"<`B#6n
b7'H!;Q//R>#
&GW>!-J^M
<U7@X6
>5XF6#
)MmO+B.
463!54>
7663!2
o6uo=o=o
he6uP\
VeDe)h
''&&4>
/26 1)'
LQ&L>&LL&>
32654.
1J]q@5YF+
'>W9wx
{8Z? c_9T<&
.Lg>T}U*7K,9Y<
*0UF6'
&Ea=4U?(
7663!2
.5>Ma>
%JrWQuL'
44]}IL~[2
&&6632
`(DJT8
4p5/b/
&&6632
FnOKoF"
;MlG" EnO
,G]5:aH,
4&/`2S
6ZC-V*&4
/%>
,RtHN{X/
66#.e8
|+QtHM|V/
,RtHN{X/
99//10
&CcGDlN*
.OoE6YC*
???:$
(C^@JpM,
(O{U?\>&
EuWWuF
EtXXuG
54677667&&54>
VI4ek0a
.>&'@-
332654.
3j^'?T@
,OmB@sV3
7663!2
-4=Mc?
,RtHN{X/
,RtHN{X/
*:=;H[9
-D5((!
!JR[3a
7]D*IFF(
>fJAfE$
*>O]5#9(
7&&54>
i3&GlFFO/V|XFf<
2PhmgQ2
FpP=Z;
>fKHe@
y`$)vA=\<
':23>Pl
rDm]P&
MauDB{`9/X~
9/+]qr
^-QOcd
>Z:Ll
463!54>
o7xoAoAo
jI7xR^
XIFI)L
54677>
''&&54>
NB(NN(B
9/]q^]
'BaG2P8
/D'=_E,
<Q_2IzW0
)>)#8'
'9%!2!
?]>%C8,
'Q'(M&
'M&&I#
7663!2
-8FSa7
!<4.&"
7663!2
/=IS\1
<`F)R #O1}x
+PoEExX3
76@%%G,
<`E*R "P2|x
+PoEExX3
AfK@eG'
0Rm==lR1
'(NsKEqR,
8}I]|J
.C-;q8
5463!2
:_E*M #J2|t
+PoEExX3
::#1IA
9^D)F!#D1zr
+PoEExX3
<`F*Q!#P1|x
+PoP)C/
9/]qr^]
99//++
99//10
3267!"&5463!.
(Fa>;Y@'
BjK)!'!
H=!=!8&
99//++
9/]qr^]
&>X@DcB$
"CdDC]@(
!)"-Mi=
ItQ+ %
;eMEfB
;dNAdD#
54677667&&54>
R5as6i
$L D[7
wbAiI'
+:#$9'
L,,<M &
PH<F&L
#"&54>
6N3AyD
$HkGHwU-
"JtSLsM'
):&%9(
F9dK+&Gf@
"JtSLsM'
):&%9(
5bI,'Ec=
"JtSLsM'
):&%9(
^3^G+%E_:
@aB:W@)
)D\29_E&
54&''4>
,@T5c}
4P64R<&
#8I(-J5
#"&54632
n/><./><.mG/.EG/.
#"&54632
#"&54632
#"&54632
i/<:./<:.
.<:./;;-
/<:./<:.lF/.DF/.DF/.DF/.DF/.DF/.
#"&&47
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Androm.m!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.MFC.S24737522
Skyhigh GenericRXVH-TC!1BE00EA3F590
ALYac Trojan.GenericKD.74311770
Cylance Clean
Zillya Clean
Sangfor Trojan.Msil.Agent.V985
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Unwanted-Program ( 005892111 )
K7AntiVirus Unwanted-Program ( 005892111 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GameTool.DJ potentially unsafe
APEX Clean
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
BitDefender Trojan.GenericKD.74311770
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74311770
Tencent Malware.Win32.Gencirc.141da8e9
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1307097
DrWeb Clean
VIPRE Trojan.GenericKD.74311770
TrendMicro Clean
McAfeeD ti!76FCCC199984
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Trojan.GenericKD.74311770 (B)
Ikarus Backdoor.Androm
FireEye Trojan.GenericKD.74311770
Jiangmin Clean
Webroot Clean
Varist Clean
Avira HEUR/AGEN.1307097
Fortinet Adware/GameTool
Antiy-AVL Trojan[Backdoor]/MSIL.Androm
Kingsoft MSIL.Backdoor.Androm.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D46DE85A
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Androm.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5683017
Acronis Clean
McAfee GenericRXVH-TC!1BE00EA3F590
TACHYON Clean
VBA32 Clean
Malwarebytes HackTool.GameHack
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H06JD24
Rising Backdoor.Androm!8.113 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Trojan.GenericKD.74311770
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Gametool.DJ
No IRMA results available.