Static | ZeroBOX

PE Compile Time

2023-04-18 08:09:16

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000016d0 0x00001800 5.33935447604
.rsrc 0x00004000 0x00000628 0x00000800 3.95293970565

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000040a0 0x0000025c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004300 0x00000325 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
k-uninstaller.exe
_rUninstaller_
SYSTEM_HANDLE_INFORMATION
OBJECT_INFORMATION_CLASS
OBJECT_NAME_INFORMATION
UNICODE_STRING
PROCESS_ACCESS_FLAGS
mscorlib
System
Object
ValueType
STATUS_INFO_LENGTH_MISMATCH
DUPLICATE_SAME_ACCESS
SystemHandleInformation
libsPath
Command
NtQuerySystemInformation
OpenProcess
DuplicateHandle
GetCurrentProcess
NtQueryObject
CloseHandle
GetHandleInformation
KillProcesses
GetMutexNameFromHandle
ProcessID
CreatorBackTrackIndex
ObjectType
HandleAttribute
Handle
Object_Pointer
AccessMask
value__
ObjectBasicInformation
ObjectNameInformation
ObjectTypeInformation
ObjectAllTypesInformation
ObjectHandleInformation
Length
MaximumLength
Buffer
Terminate
CreateThread
VMOperation
VMRead
VMWrite
DupHandle
SetInformation
QueryInformation
Synchronize
_rarg1_
_rarg2_
SystemInformationClass
SystemInformation
SystemInformationLength
returnLength
dwDesiredAccess
bInheritHandle
System.Runtime.InteropServices
MarshalAsAttribute
UnmanagedType
dwProcessId
hSourceProcessHandle
hSourceHandle
hTargetProcessHandle
lpTargetHandle
OutAttribute
dwOptions
ObjectHandle
ObjectInformationClass
ObjectInformation
ObjectInformationLength
hObject
lpdwFlags
systemHandleInformation
processID
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
k-uninstaller
System.Threading
Thread
System.IO
Directory
Delete
Environment
SpecialFolder
GetFolderPath
Combine
System.Diagnostics
ProcessStartInfo
set_FileName
set_Arguments
get_SystemDirectory
set_WorkingDirectory
ProcessWindowStyle
set_WindowStyle
set_CreateNoWindow
Process
DllImportAttribute
ntdll.dll
kernel32.dll
String
System.Collections.Generic
List`1
GetProcesses
get_ProcessName
ToLowerInvariant
Concat
IndexOf
get_Id
RuntimeTypeHandle
GetTypeFromHandle
Marshal
SizeOf
AllocHGlobal
FreeHGlobal
ReadInt64
IntPtr
op_Addition
PtrToStructure
Contains
System.Core
System.Linq
Enumerable
IEnumerable`1
UInt16
Format
op_Inequality
PtrToStringUni
Exception
get_Message
Console
WriteLine
.cctor
StructLayoutAttribute
LayoutKind
FlagsAttribute
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
</assembly>
/c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Windows Upgrade Manager" /f
/c schtasks /delete /f /tn "Windows Upgrade Manager"
Windows Upgrade\wupgrdsv.exe
notepad.exe
\BaseNamedObjects\xmmuycfhhyyhisjc
/c taskkill /f /PID "{0}"
Google\Libs\
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
k-uninstaller.exe
LegalCopyright
OriginalFilename
k-uninstaller.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav W64.AIDetectMalware.CS
Lionic Trojan.Win32.Pomal.4!c
Elastic malicious (high confidence)
ClamAV Win.Malware.Msilheracles-10008197-0
CMC Clean
CAT-QuickHeal Trojan.Pomal
Skyhigh BehavesLike.Win64.Infected.mz
ALYac IL:Trojan.MSILZilla.149514
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/ATRAPS.7405b0c2
K7GW Trojan ( 005a4db81 )
K7AntiVirus Trojan ( 005a4db81 )
huorong Trojan/MSIL.KillProcess.a
Baidu Clean
VirIT Trojan.Win64.MSIL.GBF
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.WEM
APEX Malicious
Avast Win64:InjectorX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender IL:Trojan.MSILZilla.149514
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Pomal.29184
MicroWorld-eScan IL:Trojan.MSILZilla.149514
Tencent Malware.Win32.Gencirc.11c8b9bc
Sophos Mal/Generic-S
F-Secure Trojan.TR/ATRAPS.dhtti
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.149514
TrendMicro TROJ_GEN.R002C0DC625
McAfeeD ti!03349521A699
Trapmine Clean
CTX exe.trojan.msil
Emsisoft IL:Trojan.MSILZilla.149514 (B)
Ikarus Trojan.MSIL.Agent
FireEye Generic.mg.02320b5a9ffb3aa9
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.ZJQB-5877
Avira TR/ATRAPS.dhtti
Fortinet MSIL/Agent.WEM!tr
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win64.CoinMiner.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D2480A
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Pomal!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5418787
Acronis Clean
McAfee Artemis!02320B5A9FFB
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.BitCoinMiner
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DC625
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData IL:Trojan.MSILZilla.149514
AVG Win64:InjectorX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Pomal.Gen
No IRMA results available.