Static | ZeroBOX

PE Compile Time

2025-04-26 00:02:23

PE Imphash

d6937b39d566e5795f3eb7422ac303be

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003815a 0x00038200 6.92198560671
.rdata 0x0003a000 0x0000b914 0x0000ba00 4.9719885479
.data 0x00046000 0x00002708 0x00000e00 1.99022273212
.pdata 0x00049000 0x000016a4 0x00001800 5.3441160263
.B3 0x0004b000 0x00000010 0x00000200 0.313903574313
.gxfg 0x0004c000 0x000013d0 0x00001400 5.09495714681
.retplne 0x0004e000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x0004f000 0x000001f4 0x00000200 4.18892665217
.reloc 0x00050000 0x00000740 0x00000800 5.2583488909
.jss 0x00051000 0x00058200 0x00058200 7.99951324101
.jss 0x000aa000 0x00058200 0x00058200 7.99951324101
.rsrc 0x00103000 0x0000071a 0x00000800 4.0534104384

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x001030a0 0x000003d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00103470 0x000002aa LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x140043b90 CloseHandle
0x140043b98 CreateFileA
0x140043ba0 CreateFileW
0x140043ba8 DeleteCriticalSection
0x140043bb0 EncodePointer
0x140043bb8 EnterCriticalSection
0x140043bc0 ExitProcess
0x140043bc8 FindClose
0x140043bd0 FindFirstFileExW
0x140043bd8 FindNextFileW
0x140043be0 FlsAlloc
0x140043be8 FlsFree
0x140043bf0 FlsGetValue
0x140043bf8 FlsSetValue
0x140043c00 FlushFileBuffers
0x140043c08 FreeEnvironmentStringsW
0x140043c10 FreeLibrary
0x140043c18 GetACP
0x140043c20 GetCPInfo
0x140043c28 GetCommandLineA
0x140043c30 GetCommandLineW
0x140043c38 GetConsoleMode
0x140043c40 GetConsoleOutputCP
0x140043c48 GetCurrentProcess
0x140043c50 GetCurrentProcessId
0x140043c58 GetCurrentThreadId
0x140043c60 GetEnvironmentStringsW
0x140043c68 GetFileSize
0x140043c70 GetFileSizeEx
0x140043c78 GetFileType
0x140043c80 GetLastError
0x140043c88 GetModuleFileNameW
0x140043c90 GetModuleHandleA
0x140043c98 GetModuleHandleExW
0x140043ca0 GetModuleHandleW
0x140043ca8 GetOEMCP
0x140043cb0 GetProcAddress
0x140043cb8 GetProcessHeap
0x140043cc0 GetStartupInfoW
0x140043cc8 GetStdHandle
0x140043cd0 GetStringTypeW
0x140043cd8 GetSystemTimeAsFileTime
0x140043ce0 HeapAlloc
0x140043ce8 HeapFree
0x140043cf0 HeapReAlloc
0x140043cf8 HeapSize
0x140043d08 InitializeSListHead
0x140043d10 IsDebuggerPresent
0x140043d20 IsValidCodePage
0x140043d28 LCMapStringW
0x140043d30 LeaveCriticalSection
0x140043d38 LoadLibraryExW
0x140043d40 MultiByteToWideChar
0x140043d48 QueryPerformanceCounter
0x140043d58 RaiseException
0x140043d60 ReadFile
0x140043d68 RtlCaptureContext
0x140043d70 RtlLookupFunctionEntry
0x140043d78 RtlPcToFileHeader
0x140043d80 RtlUnwindEx
0x140043d88 RtlVirtualUnwind
0x140043d90 SetFilePointerEx
0x140043d98 SetLastError
0x140043da0 SetStdHandle
0x140043db0 Sleep
0x140043db8 TerminateProcess
0x140043dc0 TlsAlloc
0x140043dc8 TlsFree
0x140043dd0 TlsGetValue
0x140043dd8 TlsSetValue
0x140043de0 UnhandledExceptionFilter
0x140043de8 WideCharToMultiByte
0x140043df0 WriteConsoleW
0x140043df8 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
`.gxfg
@.retplne
_RDATA
@.reloc
AWAVAUATVWUSH
HcT$TH
HcT$,H
h[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
HcD$tH
D$pHcL$p
[]_^A\A]A^A_
AWAVVWUSH
8[]_^A^A_
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
$}wp=|
x[]_^A\A]A^A_
AWAVAUATVWUSH
zp6RI)
zLB==w
h|_tK=
h|_=V2
=S`yxu
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVVWUSH
u{Qpf.
8[]_^A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWSH
x1P~)=
x1P=,ff
8[_^A^
AVVWSH
H[_^A^
H+D$ L)
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVATVWUSH
/dotbH
P[]_^A\A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
27L~R=
27Lth=
27L~R=
27Ltd=
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVVWUSH
([]_^A^A_
AVVWSH
X[_^A^
UAVVWSH
AWAVVWUSH
8[]_^A^A_
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
H[]_^A\A]A^A_
tv=<k0
jt8=L]
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
~y=\~3
[]_^A\A]A^A_
UAWAVAUATVWSH
p4]yH)
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
"v~\Q"
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWSH
8[_^A^
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
R;M5~6
S;M5tP
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
L+|$(I
H+D$(L)
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
u/HcH<H
WATAUAVAWH
A_A^A]A\_
D8L$0u`A
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WAVAWH
A_A^_
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
x UAVAWH
S(HcS0
S(HcS0
S(HcS0
WATAUAVAWH
0A_A^A]A\_
u3HcH<H
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
WAVAWH
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$l
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
{ AUAVAWH
0A_A^A]
t$xt*3
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
WAVAWH
A_A^_
L$ VWAVH
fD94H}aD
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
D$0H9D$8
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
@USVWATAVAWH
A_A^A\_^[]
SUVWATAVAWH
A_A^A\_^][
WATAUAVAWH
0A_A^A]A\_
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
VATAUAVAWH
0A_A^A]A\^
fffffff
fffffff
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
Sunday
Monday
Friday
August
__eabi
new[]
1#SNAN
1#QNAN
(null)
dddd, MMMM dd, yyyy
MM/dd/yy
directory not empty
text file busy
device or resource busy
no such file or directory
not a directory
is a directory
not enough memory
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
stream timeout
timed out
invalid argument
operator co_await
connection reset
network reset
not a socket
__restrict
file exists
connection already in progress
operation in progress
no such device or address
bad address
no such process
no child process
CorExitProcess
success
HH:mm:ss
too many symbolic link levels
too many links
no stream resources
resource deadlock would occur
bad file descriptor
operator
executable format error
io error
protocol error
October
November
September
December
network down
no protocol option
bad exception
inappropriate io control operation
bad allocation
argument out of domain
resource unavailable try again
too many files open
too many files open in system
read only file system
not a stream
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
no link
cross device link
invalid seek
operation would block
argument list too long
filename too long
message size
FlsSetValue
FlsGetValue
delete
address in use
wrong protocol type
broken pipe
GetSystemTimePreciseAsFileTime
state not recoverable
address not available
no lock available
no message available
host unreachable
network unreachable
value too large
file too large
result out of range
no message
bad message
FlsFree
illegal byte sequence
no space on device
no such device
no buffer space
AppPolicyGetProcessTerminationMethod
identifier removed
operation not permitted
address family not supported
function not supported
operation not supported
protocol not supported
not supported
connection aborted
interrupted
already connected
not connected
connection refused
destination address required
__unaligned
operation canceled
permission denied
owner dead
FlsAlloc
delete[]
GetTempPath2W
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CreateFileA
CreateFileW
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadFile
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
pB]P67
p0R^G'
p0R^G'
p0VXNh
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
aYIzL4{0@
O?3#9p
P>5;FX
73r($4j
H/hwTms
:<IpGu^t
ENW>|
O"\^rztJ
!)i@df
'j^10d
g=,P$S
HqAO7.8
\GQv.i5
NRJi=E
5(9%!}z
cD$~iM&
VG/AI{
.<q[vI
.zE::8J
74k.c}
}9,Jn!
?4%L4
RTI{PF
}khG95
7_yh*(
3YUOm^:
FGAk{PC
N2~eY/
RqB X:
{'y-UW
_)p[g`7
Ue'U@Q
-,GN|(
bO/Snp
9EaGWU
=('!p-
s5l0vP
GkOi{M
CR$M'h
},[C3
J+:NlU
vkj,ll
*V910`w
R6UH;l
Ps9px`
38K{{]
gMHrF
T9@@6$
-PQYxQ
,?y0ph
Y(g=4c
:uF)J*
&].e?y
Yehd\l
A>M r
=9LZ%:
az<bjmO
Vq6%Sd
$Vb4F|
DFf,[cUy
8kxf!s
!9 /w*
NPAfClzf"
^FC>g5/
mr8.ib*
P?_2*J
U/SCEl
SFs+A*
5P8bV"
6VH"_;d+
ekq!%>y0
TKdcDoAI87
&8oU&%
r4;KvT~
IFMjUf
:.,#@Ta
Icahuz
qO r*}
TT9Q),
b'JRXyku
*ic/yQ
-+n*&u
gy&!fSN
hBz"GC
bP~_wo
uv|Du(
'!gC5D
I+;sv(
mK$@"w
u]R.F
:X| a'Rq
JukRW0
dOh/H/
62$$!p
t`j{E@K
:yoy9'l
6o'az#G
&&tJNE
]#0"JJ
S(__/@
:di#]_I
%Irw7P
*FDe=G
yG8 zm
X}6;:oy
d?64A~Q
OE{P^tzH
vflgl[
$okbW\\p
K4Cs H
/_4zk|c
Z?uhc|I
;s/Q5Z
]}+S_*
,fSE4Q@u
>$vb[!%&
^p`nf9WNirnk#
os!C&n1
/3nKwwQ3?ji
tSFV9.R@
N-xIK=-h
/#+7/I
H|vr")
}3IIEK
%@"f^M/R
?_3a+#
YV(!w2
*6U[o<
Wr<zOu
vG9o0|!m"
IxIFm`
Sm|3r1
rbRv5J
5Am9{W
a}L0u>
_JckWl)
&hnwi2
J53ArD^\:
FSDYX<
4IFI{@
Ic;I~B
X}>!YF
0-xk4B
$a] =AvU
E{6o/xKRx
S:7z;/D
=,Zz^
ZcK;ef
J/sw*/%p8,
TNrN=n
WM3ivC
9hg.A$+
\T\X+H
Wn#{g.
I;]7/{
)g;e\dA
\svjK.`z{{
o}jF1b/
XLIt2=*
o1Bjn#
1,b@_U
zqr8yV
h0.gWB
/HLHx
{1z724K
Kh.Fw4
^5)z/?cP^
-M>_:]
+W'j?>
>^e416
xK"j?(
?Xe%Lr
m^a+SJ
pQZJNZ
P[\1jf
DP.Zx7)+
*%@rK%
4; );i
6p@`(]Lg[
#/FqZS
C)$^3:
ZkMS!b
j_ys?|
tg';5&X
8nP@Y*
HeR~Jy
?1X7zl
\Ux/2n
kEP ZB
drIBk6U
[.\M.=
$KS~e{]
&K,\#.
Cv<gAy
{holK"$
:\Z3gQ
9bSKd3
Rwzv58e
>hMY/F
jzM|NQ=
zpbLPP5
YZ3g<E
cZ*7p=
>#3R:&\
] lw!oZ.
&\c~!x4
yM3R@C
KW&mWb
PAQk_)`
xvqamNB.(
iCg0_s%'
;uZopg!
d4^?>V
b)H`]<
>eMTqf
,OHxX4
j(~Y"Z
'[sH(.
pt:y29
L982cw5
Nm==9}R
F6h%::'#
A"SRyc
TFi9vdz
-;FE#a
6_Kmhl
M@bkU(
XavQ/|1
w=x2|
+z3uK0
Qp5TYa
\N &R8p
PAN@(J
xt-g)i
0{};B>
uT[ Qf!
u$]r%e
'fxP<`
V/v8&=R
a=*DIO
ox;IriN
4/iP)XH
2"$@:on1
<kJ0wYb
|bVi#Sm
:Ay4m[~
(p!=:!
\:<;!N
@Z'UQ4
X_'RJ
=?v|j`
=wiiP@
9+"!_-
EsK[/*T$g
-X1_/X2
/__nW3
]jUR4]
@eWyU>
!zV=Pyq
&b{k3;5
6]N(}(L
oOKH22
v~@_bA
9ytMKe
KOv9~>7n
DOmG=e
gE_5xv(
T8KF<h47
(v0)Kl
6Rt_fHGq>j
D7fPX|x
y%ZAi2
RQgyxH
+3K [|ll
+YhX,^
YkCG,Yek
:b0m[;
1+%1t:
tfAd~f
3`zcX;-
b3tz[Y<
t=Lg=kU+N
U_r}Dw$U
[\'"-
.Qd&~5'
~d v?
+nK<*j
,G;YJ2
[\#Py6
WDHc/
hV~wB+
,J/LzVR
7hX->0
{[X#|
&2judlp%
3ABfDc
)GN6Y9
/JGV@Z
F3U*9B
|pt~6.N
HT+csIF
)E*gl<
,>@H:NQj
[@Wkz
lH=o;-A
y&9=}n
e/K-<e
4yn`R-
&g\g;c
0%~Bc]k
sTF,6l
%o<?B1
-DR?ro
I>7Dl[
\4~6Tn
'UJNJ8
@6:{%
1ZN4cT
!RB}?Z8$
Ro\M6wI
.=n@9P
rNaj?N4
QI8Dc]
1>KW;]
u=RZX\8
QM,HCjd
{Bz4<@Z
mcy<^
iR it
c#F3:
rmYWJ"t
M*$kq7
8uQ):
@yt#^*6I
<=/Xz`
sjCub^zB
4MgOsz
<-Rma;}d
uKYwqrt0N
/qD*~t
SKy= Y
:ZK[c8
Z|=}n]5PDF
G*P~'N
N$a?/M
Dnlp#v
HU.xe1
W57jin
`3rE~D!
.QmV83
xsS<Q>
l$Zr.g
u&5,O8
i_(3tSy
(=lnig
l0'(o
k&3<9=
xU+0wB
Mobg\2
PXMC4N_
*3VU v$C
{>.Hz;B
&5MO}-!9
Ajgqfa
aLjo8^>s
JRm'[T
C(,5ub
u<cc6H
ydTdA-1
l5ii{l
J]BRr&v
d`r/x
<H57'0
JI5Rl?
kh*1Zs
-7r/v%!`
yJu]@
b4'3\W
>&o=Kt
NyP$c[
WVmU>b+Rm
I%?RwQ
hOE16u
a{#k@z/A
L(`;1S
Zpt"&}
<acsma
rJ1I03
"V"_?E
,s,*O8
8}<+Km?d2
2u6c~#
/J7p*fB(
T^?H#
J(UN%x
wUVSE=
t*/Y'
+h%k5
|ah[D_
DD:et1
mJ)zIm
CjRwN+
ad5feS
}0$rLb5Q
7U+?,]~
~w~QkG
M3`jw!
#{&p05
y`CqWj%j
S0i`?nnS
2R m>~5
x0+7B9)S
z`HLqE
Dh6Om`Pe
c=nUo*
G&xrR
Sd{j=c
CkOXu;
lyq2U7
0,pK&Io
|G)ZZQ
p_f|5J
1_]Qu5
!$hn[/
fsM&v\
Fge3Z^
K'3PS9/5
\QB*KI+>
OY-+up^
Q0$?g>
eD{-~>
Nesliw
OAN WC
?S"rNM
ZgIh!@
Cv/5Ac_up
y&?|$)Q
a+2m4"m{
g3rRyA
m?}m}i'
GOY!pM^
4E{%X S
\-_eD1
$:>ffN
?mP~3I
]qMIk9s
QGwtgb
MY&'W:
*|rC)4
R/4>b}
Y_FiTi
>X&MomD
M,\Wo@
tisS%Kt5
;g>%an
Z`NP((
K 0,Aq
KAp 2}
{ Z0(h
hAetUD8"
x{@b e
r_ml ]
/hS.k
RZc}_6
>n(FTDn04
fQS[qx'
7y1KUN
B.aPGPq
bhH/uw
l>61Ii
~AsbFQ
V` T{7|
)ZAV8 J|
x:KMW35
ZJ}R\&q
t4B_h
nyFh4$wg
IrYxB84o
BVb(F
bO$T41
,'28H6
A!VyzQj
dTLh5q
=y(gT
3|^^=f
G8D#s0
N":k5A
V7W|&
kp& w,
K.X]/n
E {St4
WJoWP+
e}}@RY
QaCbK59
Aj+78u/
g"?GTp
ZOylby
rVxoSY
d;sv7&
_K?55XA
7DR4J<
aA<<W6h
I.(8w
hH!*sU">
,uAzBi
%MmIvH1
`t:b/D
!y@2/K
k)%on
l[j21QJ
%0h>v/
Awk0FS
<N.hKL
|t0A[5K
I&P#G)
S>23g{
g")CuXA
:J\L!!
V>f>WrBu
2djD YX{eLF
AFA.qk
2Vf}va
{@ova&
3:7;F/r
!Q(x5~yD"xsi
jxUk15
k_zD-F
+gV'yI
8`ey@
92K/E@8
UMt1) 7
* ~8,V
y?kT%-G
=?0ggI
GdO!'l
6ZW53EI
pM3km[
^fpIAQ2S
zBr0g1
_ff&VF^
vCM|0o
]5m]Ky
n%fPNm
b%jsWh
}w_~5J
>$~7Co
rk6>j%N|
nB`*;e
f0J{,}
)(.S<w
Wj5/
0>v|Yt
omtIO
:d_9KH?
f >{s9z
\D9?y^
h}G>([
QG:jBIO
ptaEMB]w
8$6E9
OyF?`q>
#<pQC-
GY>scJPX
dg_Knk
{,:m]"lg
Am@hVtC_a
9=sFu_
Uy{;ZW
~%l{Yq
2wYgn(
.K>hCf
Ab&efC3=
PxeF22
Z3v/8b
kw=F$q
-V>Pcv
6\c`P<
e=>z6S
@)~]dn
!@"cHKZCR
7Xc- M~
Kc:bUn
H:5Z@0
0/<R$^
=#u@oP
H5M}<|SJ
PqI@SF
ubI.O9
N:|D]F
C:P!j6
*@VDd 5
%?0/5soB^yP@Qw
tuU(uJ
#aSyo
PKo`tw
5rrX3^
#(6q<!
}ky}&=XMW
x8G&eG
}N"q^x
mP/S0L,
s-b&[r7L
^BX^[qs
K@_{ej
~Qq;R#`
LaT229
6N}32=
q~+yxm
'fBU"zc
"Ibz9=Kjx
+8'':#
@:KO{^
$*4Ar%
t1jv~q
k~\j*R
Ug>h{~
yzo&:Ui1
1n5RK"`
~?)Q8V
Ct]%cm
#;943Q
*jevK^
DJ'4BH(
aYIzL4{0@
O?3#9p
P>5;FX
73r($4j
H/hwTms
:<IpGu^t
ENW>|
O"\^rztJ
!)i@df
'j^10d
g=,P$S
HqAO7.8
\GQv.i5
NRJi=E
5(9%!}z
cD$~iM&
VG/AI{
.<q[vI
.zE::8J
74k.c}
}9,Jn!
?4%L4
RTI{PF
}khG95
7_yh*(
3YUOm^:
FGAk{PC
N2~eY/
RqB X:
{'y-UW
_)p[g`7
Ue'U@Q
-,GN|(
bO/Snp
9EaGWU
=('!p-
s5l0vP
GkOi{M
CR$M'h
},[C3
J+:NlU
vkj,ll
*V910`w
R6UH;l
Ps9px`
38K{{]
gMHrF
T9@@6$
-PQYxQ
,?y0ph
Y(g=4c
:uF)J*
&].e?y
Yehd\l
A>M r
=9LZ%:
az<bjmO
Vq6%Sd
$Vb4F|
DFf,[cUy
8kxf!s
!9 /w*
NPAfClzf"
^FC>g5/
mr8.ib*
P?_2*J
U/SCEl
SFs+A*
5P8bV"
6VH"_;d+
ekq!%>y0
TKdcDoAI87
&8oU&%
r4;KvT~
IFMjUf
:.,#@Ta
Icahuz
qO r*}
TT9Q),
b'JRXyku
*ic/yQ
-+n*&u
gy&!fSN
hBz"GC
bP~_wo
uv|Du(
'!gC5D
I+;sv(
mK$@"w
u]R.F
:X| a'Rq
JukRW0
dOh/H/
62$$!p
t`j{E@K
:yoy9'l
6o'az#G
&&tJNE
]#0"JJ
S(__/@
:di#]_I
%Irw7P
*FDe=G
yG8 zm
X}6;:oy
d?64A~Q
OE{P^tzH
vflgl[
$okbW\\p
K4Cs H
/_4zk|c
Z?uhc|I
;s/Q5Z
]}+S_*
,fSE4Q@u
>$vb[!%&
^p`nf9WNirnk#
os!C&n1
/3nKwwQ3?ji
tSFV9.R@
N-xIK=-h
/#+7/I
H|vr")
}3IIEK
%@"f^M/R
?_3a+#
YV(!w2
*6U[o<
Wr<zOu
vG9o0|!m"
IxIFm`
Sm|3r1
rbRv5J
5Am9{W
a}L0u>
_JckWl)
&hnwi2
J53ArD^\:
FSDYX<
4IFI{@
Ic;I~B
X}>!YF
0-xk4B
$a] =AvU
E{6o/xKRx
S:7z;/D
=,Zz^
ZcK;ef
J/sw*/%p8,
TNrN=n
WM3ivC
9hg.A$+
\T\X+H
Wn#{g.
I;]7/{
)g;e\dA
\svjK.`z{{
o}jF1b/
XLIt2=*
o1Bjn#
1,b@_U
zqr8yV
h0.gWB
/HLHx
{1z724K
Kh.Fw4
^5)z/?cP^
-M>_:]
+W'j?>
>^e416
xK"j?(
?Xe%Lr
m^a+SJ
pQZJNZ
P[\1jf
DP.Zx7)+
*%@rK%
4; );i
6p@`(]Lg[
#/FqZS
C)$^3:
ZkMS!b
j_ys?|
tg';5&X
8nP@Y*
HeR~Jy
?1X7zl
\Ux/2n
kEP ZB
drIBk6U
[.\M.=
$KS~e{]
&K,\#.
Cv<gAy
{holK"$
:\Z3gQ
9bSKd3
Rwzv58e
>hMY/F
jzM|NQ=
zpbLPP5
YZ3g<E
cZ*7p=
>#3R:&\
] lw!oZ.
&\c~!x4
yM3R@C
KW&mWb
PAQk_)`
xvqamNB.(
iCg0_s%'
;uZopg!
d4^?>V
b)H`]<
>eMTqf
,OHxX4
j(~Y"Z
'[sH(.
pt:y29
L982cw5
Nm==9}R
F6h%::'#
A"SRyc
TFi9vdz
-;FE#a
6_Kmhl
M@bkU(
XavQ/|1
w=x2|
+z3uK0
Qp5TYa
\N &R8p
PAN@(J
xt-g)i
0{};B>
uT[ Qf!
u$]r%e
'fxP<`
V/v8&=R
a=*DIO
ox;IriN
4/iP)XH
2"$@:on1
<kJ0wYb
|bVi#Sm
:Ay4m[~
(p!=:!
\:<;!N
@Z'UQ4
X_'RJ
=?v|j`
=wiiP@
9+"!_-
EsK[/*T$g
-X1_/X2
/__nW3
]jUR4]
@eWyU>
!zV=Pyq
&b{k3;5
6]N(}(L
oOKH22
v~@_bA
9ytMKe
KOv9~>7n
DOmG=e
gE_5xv(
T8KF<h47
(v0)Kl
6Rt_fHGq>j
D7fPX|x
y%ZAi2
RQgyxH
+3K [|ll
+YhX,^
YkCG,Yek
:b0m[;
1+%1t:
tfAd~f
3`zcX;-
b3tz[Y<
t=Lg=kU+N
U_r}Dw$U
[\'"-
.Qd&~5'
~d v?
+nK<*j
,G;YJ2
[\#Py6
WDHc/
hV~wB+
,J/LzVR
7hX->0
{[X#|
&2judlp%
3ABfDc
)GN6Y9
/JGV@Z
F3U*9B
|pt~6.N
HT+csIF
)E*gl<
,>@H:NQj
[@Wkz
lH=o;-A
y&9=}n
e/K-<e
4yn`R-
&g\g;c
0%~Bc]k
sTF,6l
%o<?B1
-DR?ro
I>7Dl[
\4~6Tn
'UJNJ8
@6:{%
1ZN4cT
!RB}?Z8$
Ro\M6wI
.=n@9P
rNaj?N4
QI8Dc]
1>KW;]
u=RZX\8
QM,HCjd
{Bz4<@Z
mcy<^
iR it
c#F3:
rmYWJ"t
M*$kq7
8uQ):
@yt#^*6I
<=/Xz`
sjCub^zB
4MgOsz
<-Rma;}d
uKYwqrt0N
/qD*~t
SKy= Y
:ZK[c8
Z|=}n]5PDF
G*P~'N
N$a?/M
Dnlp#v
HU.xe1
W57jin
`3rE~D!
.QmV83
xsS<Q>
l$Zr.g
u&5,O8
i_(3tSy
(=lnig
l0'(o
k&3<9=
xU+0wB
Mobg\2
PXMC4N_
*3VU v$C
{>.Hz;B
&5MO}-!9
Ajgqfa
aLjo8^>s
JRm'[T
C(,5ub
u<cc6H
ydTdA-1
l5ii{l
J]BRr&v
d`r/x
<H57'0
JI5Rl?
kh*1Zs
-7r/v%!`
yJu]@
b4'3\W
>&o=Kt
NyP$c[
WVmU>b+Rm
I%?RwQ
hOE16u
a{#k@z/A
L(`;1S
Zpt"&}
<acsma
rJ1I03
"V"_?E
,s,*O8
8}<+Km?d2
2u6c~#
/J7p*fB(
T^?H#
J(UN%x
wUVSE=
t*/Y'
+h%k5
|ah[D_
DD:et1
mJ)zIm
CjRwN+
ad5feS
}0$rLb5Q
7U+?,]~
~w~QkG
M3`jw!
#{&p05
y`CqWj%j
S0i`?nnS
2R m>~5
x0+7B9)S
z`HLqE
Dh6Om`Pe
c=nUo*
G&xrR
Sd{j=c
CkOXu;
lyq2U7
0,pK&Io
|G)ZZQ
p_f|5J
1_]Qu5
!$hn[/
fsM&v\
Fge3Z^
K'3PS9/5
\QB*KI+>
OY-+up^
Q0$?g>
eD{-~>
Nesliw
OAN WC
?S"rNM
ZgIh!@
Cv/5Ac_up
y&?|$)Q
a+2m4"m{
g3rRyA
m?}m}i'
GOY!pM^
4E{%X S
\-_eD1
$:>ffN
?mP~3I
]qMIk9s
QGwtgb
MY&'W:
*|rC)4
R/4>b}
Y_FiTi
>X&MomD
M,\Wo@
tisS%Kt5
;g>%an
Z`NP((
K 0,Aq
KAp 2}
{ Z0(h
hAetUD8"
x{@b e
r_ml ]
/hS.k
RZc}_6
>n(FTDn04
fQS[qx'
7y1KUN
B.aPGPq
bhH/uw
l>61Ii
~AsbFQ
V` T{7|
)ZAV8 J|
x:KMW35
ZJ}R\&q
t4B_h
nyFh4$wg
IrYxB84o
BVb(F
bO$T41
,'28H6
A!VyzQj
dTLh5q
=y(gT
3|^^=f
G8D#s0
N":k5A
V7W|&
kp& w,
K.X]/n
E {St4
WJoWP+
e}}@RY
QaCbK59
Aj+78u/
g"?GTp
ZOylby
rVxoSY
d;sv7&
_K?55XA
7DR4J<
aA<<W6h
I.(8w
hH!*sU">
,uAzBi
%MmIvH1
`t:b/D
!y@2/K
k)%on
l[j21QJ
%0h>v/
Awk0FS
<N.hKL
|t0A[5K
I&P#G)
S>23g{
g")CuXA
:J\L!!
V>f>WrBu
2djD YX{eLF
AFA.qk
2Vf}va
{@ova&
3:7;F/r
!Q(x5~yD"xsi
jxUk15
k_zD-F
+gV'yI
8`ey@
92K/E@8
UMt1) 7
* ~8,V
y?kT%-G
=?0ggI
GdO!'l
6ZW53EI
pM3km[
^fpIAQ2S
zBr0g1
_ff&VF^
vCM|0o
]5m]Ky
n%fPNm
b%jsWh
}w_~5J
>$~7Co
rk6>j%N|
nB`*;e
f0J{,}
)(.S<w
Wj5/
0>v|Yt
omtIO
:d_9KH?
f >{s9z
\D9?y^
h}G>([
QG:jBIO
ptaEMB]w
8$6E9
OyF?`q>
#<pQC-
GY>scJPX
dg_Knk
{,:m]"lg
Am@hVtC_a
9=sFu_
Uy{;ZW
~%l{Yq
2wYgn(
.K>hCf
Ab&efC3=
PxeF22
Z3v/8b
kw=F$q
-V>Pcv
6\c`P<
e=>z6S
@)~]dn
!@"cHKZCR
7Xc- M~
Kc:bUn
H:5Z@0
0/<R$^
=#u@oP
H5M}<|SJ
PqI@SF
ubI.O9
N:|D]F
C:P!j6
*@VDd 5
%?0/5soB^yP@Qw
tuU(uJ
#aSyo
PKo`tw
5rrX3^
#(6q<!
}ky}&=XMW
x8G&eG
}N"q^x
mP/S0L,
s-b&[r7L
^BX^[qs
K@_{ej
~Qq;R#`
LaT229
6N}32=
q~+yxm
'fBU"zc
"Ibz9=Kjx
+8'':#
@:KO{^
$*4Ar%
t1jv~q
k~\j*R
Ug>h{~
yzo&:Ui1
1n5RK"`
~?)Q8V
Ct]%cm
#;943Q
*jevK^
DJ'4BH(
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="x86"
name="Microsoft.Windows.MediaPlayer.UnRegMP2"
type="win32"
<description>Registry Editor Utility</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
((((( H
dKERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
kernel32.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft Windows Media Player Setup Utility
FileVersion
12.0.19041.1 (WinBuild.160101.0800)
InternalName
unregmp2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
unregmp2.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
12.0.19041.1
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
ClamAV Win.Packed.Zusy-10044253-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Generic.dc
ALYac Gen:Variant.Lazy.677740
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Trojan/Agent.bkf
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/GenKryptik.HING
APEX Malicious
Avast MalwareX-gen [Cryp]
Cynet Clean
Kaspersky VHO:Trojan-PSW.Win32.Stealer.gen
BitDefender Gen:Variant.Lazy.677740
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.677740
Tencent Clean
Sophos Troj/Krypt-AQA
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Lazy.677740
TrendMicro Clean
McAfeeD ti!714E9BE09C6A
Trapmine Clean
CTX exe.unknown.lazy
Emsisoft Gen:Variant.Lazy.677740 (B)
Ikarus Clean
GData Gen:Variant.Lazy.677740
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan/Win32.Caynamer
Kingsoft malware.kb.a.980
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.DA576C
SUPERAntiSpyware Clean
ZoneAlarm Troj/Krypt-AQA
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Lazy.C5755681
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9Z
Rising Stealer.Convagent!8.1326D (TFE:1:szn6mGmGidC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
AVG MalwareX-gen [Cryp]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.