Static | ZeroBOX

PE Compile Time

2024-12-27 02:17:11

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001830 0x00001a00 5.31600744612
.rsrc 0x00004000 0x000004a8 0x00000600 3.4160246659

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000040a0 0x00000274 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004318 0x0000018d LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
newest-uninstaller.exe
_rUninstaller_
SYSTEM_HANDLE_INFORMATION_EX
SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX
OBJECT_NAME_INFORMATION
UNICODE_STRING
PROCESS_ACCESS_FLAGS
mscorlib
System
Object
ValueType
STATUS_INFO_LENGTH_MISMATCH
ExtendedSystemHandleInformation
ObjectNameInformation
DUPLICATE_SAME_ACCESS
Command
NtQueryObject
OpenProcess
DuplicateHandle
GetCurrentProcess
CloseHandle
NtQuerySystemInformation
Func`3
AllocateBuffer
KillProcesses
GetHandleName
NumberOfHandles
Reserved
UniqueProcessId
HandleValue
GrantedAccess
CreatorBackTraceIndex
ObjectTypeIndex
HandleAttributes
Length
MaximumLength
Buffer
value__
Terminate
CreateThread
VMOperation
VMRead
VMWrite
DupHandle
SetInformation
QueryInformation
Synchronize
_rarg1_
_rarg2_
ObjectHandle
ObjectInformationClass
ObjectInformation
ObjectInformationLength
returnLength
dwDesiredAccess
bInheritHandle
System.Runtime.InteropServices
MarshalAsAttribute
UnmanagedType
dwProcessId
hSourceProcessHandle
hSourceHandle
hTargetProcessHandle
lpTargetHandle
OutAttribute
dwOptions
hObject
SystemInformationClass
SystemInformation
SystemInformationLength
initialSize
action
sourceProcessHandle
sourceHandle
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
newest-uninstaller
System.Threading
Thread
Environment
SpecialFolder
GetFolderPath
System.IO
Combine
Delete
GetTempPath
System.Diagnostics
ProcessStartInfo
set_FileName
set_Arguments
get_SystemDirectory
set_WorkingDirectory
ProcessWindowStyle
set_WindowStyle
set_CreateNoWindow
Process
DllImportAttribute
ntdll.dll
kernel32.dll
Marshal
AllocHGlobal
FreeHGlobal
Invoke
IntPtr
<KillProcesses>b__1
CS$<>9__CachedAnonymousMethodDelegate2
CompilerGeneratedAttribute
String
System.Collections.Generic
List`1
GetProcesses
get_ProcessName
ToLowerInvariant
Concat
IndexOf
get_Id
RuntimeTypeHandle
GetTypeFromHandle
SizeOf
op_Equality
PtrToStructure
op_Addition
ToInt64
Contains
IsNullOrWhiteSpace
System.Core
System.Linq
Enumerable
IEnumerable`1
UInt32
Format
<>c__DisplayClass5
targetHandle
<GetHandleName>b__3
op_Inequality
PtrToStringUni
StructLayoutAttribute
LayoutKind
FlagsAttribute
CQR|$<
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
/c sc delete "WinMngr" & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\WinMngr" /f
WinMngr\winmngrsa.exe
yoygdjmdclhw.sys
dwm.exe
conhost.exe
\BaseNamedObjects\pvfekhelexmvzlxl
\BaseNamedObjects\bwwgjzzbcmagjc
/c taskkill /f /PID "{0}"
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
newest-uninstaller.exe
LegalCopyright
OriginalFilename
newest-uninstaller.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav W32.Common.605BF226
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Win.Malware.Msilheracles-10017026-0
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.17413372878b1c01
Skyhigh BehavesLike.Win64.Infected.mz
ALYac Gen:Variant.Jalapeno.2107
Cylance Unsafe
Zillya Trojan.Agent.Win32.4170644
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Trojan:MSIL/Generic.d1bc979d
K7GW Trojan ( 005a3e5d1 )
K7AntiVirus Trojan ( 005a3e5d1 )
huorong Trojan/MSIL.KillProcess.a
Baidu Clean
VirIT Trojan.Win64.MSIL.HSW
Paloalto generic.ml
Symantec Trojan.Gen.MBT
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.WEM
APEX Malicious
Avast Win64:TrojanX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Jalapeno.2107
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Jalapeno.29184.C
MicroWorld-eScan Gen:Variant.Jalapeno.2107
Tencent Malware.Win32.Gencirc.10c115b1
Sophos Mal/Generic-S
F-Secure Trojan.TR/Agent.ihpob
DrWeb Clean
VIPRE Gen:Variant.Jalapeno.2107
TrendMicro TROJ_GEN.R002C0RBQ25
McAfeeD ti!8F3C4A66F4C6
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Gen:Variant.Jalapeno.2107 (B)
Ikarus Trojan.MSIL.Agent
FireEye Gen:Variant.Jalapeno.2107
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.BGRC-6733
Avira TR/Agent.ihpob
Fortinet MSIL/Agent.WPM!tr
Antiy-AVL Clean
Kingsoft Win32.Trojan.Generic.a
Gridinsoft Ransom.Win64.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Jalapeno.D83B
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5488795
Acronis Clean
McAfee Artemis!8F1F692C2E83
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2986546978
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0RBQ25
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.335365410.susgen
GData Gen:Variant.Jalapeno.2107
AVG Win64:TrojanX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Wacatac.B9nj
No IRMA results available.