Static | ZeroBOX

PE Compile Time

2025-04-07 16:53:02

PE Imphash

d831eced355e94699686b7b8d355a7b0

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x000b6000 0x00000000 0.0
DATA 0x000b7000 0x00058000 0x00057600 7.92599242974
.rsrc 0x0010f000 0x0000d000 0x0000c800 3.7830431042

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x000fdb28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
TEXTINCLUDE 0x000fdb28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
TEXTINCLUDE 0x000fdb28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000ff7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000ff7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000ff7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000ff7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00100190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0011acd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_MENU 0x000ff158 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x000ff158 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000feca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00100ba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x000ff870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PGP\011Secret Sub-key -
RT_GROUP_CURSOR 0x000ff870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PGP\011Secret Sub-key -
RT_GROUP_CURSOR 0x000ff870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PGP\011Secret Sub-key -
RT_GROUP_ICON 0x0011b1d8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x0011b1d8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x0011b1d8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x0011b1f0 0x000001cd LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.DLL:
0x51b4c4 LoadLibraryA
0x51b4c8 GetProcAddress
0x51b4cc VirtualProtect
0x51b4d0 VirtualAlloc
0x51b4d4 VirtualFree
0x51b4d8 ExitProcess
Library ADVAPI32.dll:
0x51b4e0 RegCloseKey
Library COMCTL32.dll:
0x51b4e8 None
Library comdlg32.dll:
0x51b4f0 ChooseColorA
Library GDI32.dll:
0x51b4f8 PatBlt
Library ole32.dll:
0x51b500 OleRun
Library OLEAUT32.dll:
0x51b508 UnRegisterTypeLib
Library SHELL32.dll:
0x51b510 ShellExecuteA
Library USER32.dll:
0x51b518 GetDC
Library WINMM.dll:
0x51b520 waveOutOpen
Library WINSPOOL.DRV:
0x51b528 ClosePrinter
Library WS2_32.dll:
0x51b530 WSACleanup

!This program cannot be run in DOS mode.
s&39[K\
FsWYPQ
`hxtZ_
qLcA<I
V V0B.
R'XLd4
`t2$[v
%;s)4P
uRFGHt
XQKsLLG
_,V[gBn
<jQ0$2
LQ 1[94
u-yy^4
d 9VV]$
,"P(=&n!D
X+C_O$
@:XH[%
!ur3Ae
3kWRwl
 !"#$%&'()*+,-.
456789:;<=>?@abcdef
ghijklmnopqrstuvwxyz[\]^_`?
EFGHIJKLMNOPQRSTUVWXYZ?
E>ECTV&d
B0$4~ot/
=nwVtG
{$%R#[<
CSQ$PS
E8tTW.
PW@-\W
X=s(g}
SEUO1C-
\{gQR"
H`pzGR
$lL'uut
\r^8r8
QP`1>4
0S]#a38
:lt~ 8
)K0Qd;
viVu^:
KyVP75
3z/W>!
PVn4t#GV
Wa1QWSj
H<'X$@
^{RIQ;
t*P4L_rS
tCU^<p
(<u-KFd
`6`Jhu$
IPx#/'U
$fAgb`
RFtJa
<faAI]
?!@>P?
$CRqFH
|K29?Q(
0bRF?Pu
NQV?\$
+rxhUKl
7Pgp[t_
0u.W`yzk
x|K*R(wY
.ddddBVj~
\dhl=p
%tNPSV
^tf>h6:9
\=USRt
QnD5H&
VDR$T$
xB;obh
bEdF^*
hlp=tvH
RlptxT*
P#wWt('
6VZC h
V6~KSP+
;%XXSY
HZp8@<
`U+uRA
0Va9R4{
!g@14y
q`?U[
$~PJ8&4
dJH\dJ
*k\\%S
4|k,8b9
i6MT|L
ct*@Pu
= 7-nwd
{HvElla
)$%$F'
P~c!TI:VMu
rHxhW
F60\6u
QVOJ|s
@l#8"||
qIA++C
E^Y3Y:
%)z[tH
*'q%=w
CAJ%|
X_$\Of
<%ER()
h 2)TO
9Z_09X
]&v11u
h l0Ms
&pxKs6a
D0Q+4$
48 C Cdh C Clp C Cx|.`
&5J?)k`
Fq,<8K
,d6D}y
>2lGwm
/\5X\UWSSHh
`QPW t
VbJAG{<
4Z+d7R
,(<8 q2
((CaSf
\RiLe(((
W]}CH9RtnSHRy
0CzIph^
uzUU97
#<k0QW
epK7}ia\
XJ99%r/
s;)"zDX)
^q1!'(
xm=8eUP
j&$xhh3s
{Xt$dhg
6aS'S3
D_h-(E
_:feT6N-
4@VD@@Wp
K@WpJ.@t
KyeVJC
7C@`/T0
t&V0r!
_t(L/t"
5/*%],
+.2tZ[
xIz(;8P
srgHUD
h+_:(B
Q:|bY&
wPUNpM
~|9`FH
<{<:\
15f4$+D
IL0S?%
f\c tC]
AR"mD\5
SFd)h4
h(eU6][8Nha4|"
+Bx9]' C%
$cQGHm
:aFk-pu
l-'!h,0
#9?,&u
m-dJr~|
]9^xu5
n%e4vS
#h9n`u;bw#|
l(^X(8
]2osV5
I_\|*
OO^O9UG
XY;fu";
^mj#C4w
B_8t_\K,
lww"}|
0.^0h1
ORSEuUR
L)ptZP
.Be$>;
VwXXiN
i zX\`
TX\;d$#A
QPhi'
4MXXXO
F6aHrIe~
C?WaJ
Oh).Lw
'8C:4
{OP)3
+E#@-(
Nl&ptx
^h[hVptbp
,4(XNh
(i2@s(
u'<hPVci
nh9V8<
@3VQU
27.1<v
W"p&\Bq_
0tNNHI
[D UVA
OP9ZF#
[!a!
%@DNIi
@!"VCI&
Bjw:L8
$ar(\Hx
t{hD(U
c:A[xKX
}p 1<r
\dJ q[U?
h9^8uXn
#9{4:C4
@tdeH^W
4QWCPgc
_3W<s!
PEU$DF
L|$LHl
v%y^\I
uJs M7
uUPiGQ
xR)ap"
}G:t+T
AFHNXabH
8WP9t:,>~|
H4Qblt
X$m#\#]Xo
?8i<zU
(O;o^H\
|Q`P88
hL ; r
Sczl"rUt|
(D$U30
iBpA*Z
<SxCat
r@tI!p*
$>;q0aD
P3+&!`
BIR}10
`>.Ptm|t
0@ uGl{
tY Q%X
t/"u!O
-cb'gL
'tUnnnn
&tP(tK$tF#tA6nnn!t<"t7Cu
y,H2D8
NO0D_
r!$@s[
D)R=VH
.Ax$HUC
H|$lD(
R+eYX
(P(,<3\xA
@ul9~}f
:: a|J =P
,t8C%M$
Wt4-E\|5
uW,_8)N
TtiLiH
~0HzQTV;^
,Ubl0HJaL
#u'de)
8Z!tBK
qHe*VA
t$PV;lZN
}5=/jy8
e`R R"
C-%uTf
[o=0?U
V6K=l`$
0b`SF(
o5l-k<
TPhuXM
q11&RH
(]my]H,
Bck1ni:
f5FAvNXQ
Ui6lL"U
O&? !R@
}9+JCXI
8M_>@xJ
n$SU5I
w?9Fdt
<!h1XR
L?ZZ%?
^l;S]q@@
KiQ!^X
5K2`~O
}!S$QS
jBxQHY
8G~it8Wh
q8jDF-
l D-@"
`h^WPR
w]gc$b
k,,`>j
_4^75-
]>D?`-
@xRd
cGg,au
A3|'0q
h'N@A6
^|a^xq
Jce'7M
'$,.O?
='-|#M
^9`{{h/PaU+
d`>#~y`h&
fJOyXl
?|-D>D")
mM.H9h}
NN@WGf
vMHQSsyg<|
T5=wS
9}thD"
.u/(WVQ0i|
VKqTzto
KrGA=@LV,
^te~2s
WZ \I
5(:+|s#mR
nJXiazv
'=pscatjy
ARGtD= BGR
-=knilt
;R9^_C
d'hpO
@C`@u
@uj^tu
e\f$V}l
TADIut
ETLPuFS
Or.LMRHc/
0sFFo/2
BGR PCCiy
'tXEt9EMI
%tXTz:
T,']ue
}`:4t0lp
^@`H^@
!G4v"Uv
8T88UU
V*B]s8K
T*RXCO
zCPfZx8
YF(K\WP
`^q>`(
zC/ioQ
1;G$-&
wDA#8F
HoKFEus3
A=J}&My,
W:ww ?uw'64T
AgYvHR
3\8|: C
*IiySd
,t,$Q D
<vNH\^`
(0qcHS '
^XpQ~RW
5D.SNQ
Fd_2^V
9*/\yw
GZ(9|(
Td\WC=
l?-&AT
Aju4^68
C&g-L@i
0hdyOH
XHxmRy
xzI;Pr
vNtt-zO
J@D]@D}0e
B$:/ `
tL9~HvGlCz
Ti,O-[
Ft9~$u
mkevkH`tQX\
_i j0^U">!
P)X$W$
X2f`r@
HupHqhV
N6.V0&
/& tLh
eRI5US
wn#fha
x(%|bT
ODHM*M
r)j]`
rUt$0V
7LIbU;
G!AW24
]!|~jW
)xR}.%
K!{%-^8
uzv*[
;0_DS<2
e0Mj3k
@;,TZP
h*R@(`
'pL8>SI
h,GS5B
7_/*Np
I96`T@
36F=nl$
r!pn@F
/d]8tY0uT
6a~kcs
2(=SP'
ldvt7l
mjFG6S
+PARZw
1sBTN/
t-T<%.
XI^7ht
< 3|=X2
B+:IM@d8
SByIwH
X@t&s-v.
cR]*2+,
(2j7ml%
Q pMkgz
9Fn=I\
uKZe/ba
u3/okr
QD4K"An9
%#0"aE'
NIM$f"u
RG.+L#
HtXfH;a
_0u.3rq
$Mn4 $LE
tAun\&
XaA!"k=
5RfaiP
m-]h(xP$
xWLIX
3{%`lw
VQZ= w
<-*8?\
4NLdV@
HtHHuzH
T/#W^G
I~/U,H
V9xPu4
*T&.!`
y<EG\Y
o!/+]i
l}x:P
>QUgO#
t#|"`V4
O0z(~W8
'po2l00%
xV'=RK
`]9B uX
MCJJk~lHS
tq,Di"
[6qlP$`wv
h$VQ<fP2
j%xL\y:Mcv
??N8/t
@00upz
WrK$DVQ
0F_)PJ
A<=V&R)F@
^CdJKl"
HWY zp
VdF<fn
yNqAH0R`
v1_U"C
"r)zWH
W~88@J3
_K;VH}I
1yd<IV
Hs0LO'l
TCAx\S
+)]njTN
\WYZ[\8X
,CT$@S
*MOW,
t0Dcr
M/l^N1q|,A
c^p`U qP
'FL`e\
+Qfb.Q0
OJM[Cj&
AKvpmu
1,+@WA
|Q.6Pjx
OD0UnNn
x<.IY\p,
ps*$}H
~*K.H4B
,7\2@qe
BC{bAH
-v7T!U
Gw4?jp
oC8P1*4
$vJt h
7h/ZBsJh
06P@A{M
A.tCDHP
dt-fQ0"ax
eA$gn
";F{.v
T+3x%A
SRCf+y
0LbB*
TY_JO^
0tb0m%
f8 uTSG
& R"/->
A^KR%8`
z*O 0$
~HXq@X
edd(,0
j p(E%
EhU:5qi
,S*z6!.
4\KOk0#
Ih85!Ja
5e#L@,a
M ,PQ/
]HUR$.
#5!5]@
:YlZlSj
u(ERRRDi5#
OLt:ZG
,o0d\*
qG(X#E_
4M<HL\PTe
!:-jd
&,<Q)t\
*z.}RP
S]1pG
d } 9o
@(+aLM
F gB,r
u(R>DE
e#fA&z
nqtm6l
YcaeJ&
!ys{ YX
Rr|y_+d
_`djXu
M'`m%
S3$/\~'
?'((ye
b{@(o|
| <"l+
R[8u".
J!#m+y
mIYec9
iGHtlR
/H\H\
s7PjUK
\_=B~l
~Pe*SG
V^C_D#
:pw|nmq
)A.#x&
.7PMH1/
%],SDV
e,(7RW'
C@/:XI
|YXhm
VPabK/0
lV},BDpOA
q%Jl'
{2+'Ku
^9rUq,
k5+_VG2!
)BN5nn(d
"WcxKi'
<10GMi
GS-1 oD
c[]k*L
\bV@B.y
TTyF.0
ru0T(4
ZeuP-9R
4V||x.
M~jSxI
QJ<Cy<
TQR[Oc%>
`ABFXu
2XTPn)
-Ab_^"
`1r1)`
1a}lCW
_AJwiZ
m{3{'H
rY~O;
YQ'Q)Je*
MK$lmwh
f*7G*-
/Yfpd
cQ,.?X
]'\/l8ux
pnR(<U
m`8NGZ^)PO
y8'u-V
5MI=8*%.Wm
B 02CV
$zY^~1F
pm# aD
"eA;9a
Vb-'9
VK:lBF
wLVZWEv
P@TH[Bfk
VC20XC00A
3x<JSm:
:v9*cC!
9(HWt!
<o+^)NYm
W9^zU"w
$D(>`-J
qu 6NM
vh=ZbS9
\}^M>tA
}(`~"B
BBQH(`
<=J$9L
8t9UW=
tSS?j"!
?t:u.C
Wm\0YG
tH+@v/
t4x`t^z
X(2{0k
GqS^!
vR^^t3i
S7M4 V[
0r;3B,
O;>|C;
a4Z(~<
f9p`te
09x 6
vjQ 2Hs
neKfz^"
FKl\3H
#~Faor
~2(`o&
w+Bv'Ws
A{t!$r
"Y)SBB
Ymb;WP
,.A@`$
/Ed259
\'CdnW
NE&cK&v
AhP_9r0X
88Fh)Bl
B=W?WAW
w+jStPh
,YR<T
n1VR6Z
7BWk<"ZSo
?|n" u
!Ix?\'E
ZpUaZ@
-t,0tRCi
d+q)P;
P@*<@,
\jLSX#{kA
$c@zS?
6;)/`i@Q
D(HxRA/
+&QZgu
I>AF-:
-)7Wt#7
f[qn2i
|M%^_
l)(:M3
Bop[t!
sT_V~z
<[SQd9
qt-hTW
(f/DSc
qPu|Pw_
jVCf2p
w.lh h
Rd#>K:cF
kuAX#8*k
)0G2"5
>(r-B^
t Y[`(-D.A
H #xjC
zwPAP7
+W;ZIk
I+/,2x
-u?HVu
9tlNu}
O&g97_u&
5nYgj0'e
8`QOmVd
t ,zVh
N4xLh%L
Q/(PllIjf<7(jNj
2RtB%^K
vj[t_v
^N{dTJ
M|2WP/t
PRK`0RCZ
w%tK
C.kwFt
/'0XH-H1&
WZh@$.j
6TQ"IW
}HVhQjh
WPX-vPA
a|%uAn
<A|2<Z
1GG;`<
w"J>,i
L6~BP<Pu
u"uaAx
d,\dg<|
q2.J;~
C,y%4#
,x|v9}
ujMH#Az
xo50^h
8{uB\4
0)SX &
Lr9r9_
cH3+@.v
XO!vUZ
3@/9TD
m"y8>`?
x HWx+
O7OK[,
y,9CP]
4(7EQl
kernel32.dll
advapi+CmK
GGetCurreVProcess<
up$ivi
eValueA
{C5xClo
ctorydMov
SnBshot
Waitabl
g!FfMultip.Obj
09f2340818511d396f6aaf844c7E
48E769
B6E92C2105
5F99C1
2A2F4e03
07hB4F
5D7C3F8
>b0e0B
>8"A3C0
Variant>
systeam
Q\/Windows S
r.exe8
,Debug
$OFTWARE\Microsoft\
Temporvy
|x|ey.txt
tp://45.192
04.76:80
C"NEC<
g% zh-c{m
~.0 (co
;0SIE 9*
pv-Typ
+/x-w)
fBasDk
oize'mH$
vtvejDFsp,
@.pp;o
'"xYo"8A
bA/BN&
.d6!d/
<@&i@e
-f*t-
]a^a@@
D.D0N^N
_~E.E&O
JJpLL'
!D0>D,j
_0] yD
ug<pVn:
4i5U6B738%9
B#C0D?EQ
QyReSOT
qdZRMHD@=;8[
1/.-+*)(''&%
4""!! 
|?5^<@
!1AQaq
"2BRbr
#3CScs
$4DTdt
%5EUeu
&6FVfv
'7GWgw
(8HXhx
)9IYiy
+;K[k{
,<L\l|
-=M]m}
.>N^n~
/?O_o
pCALHYs
tEXtIME
3 Copyright7
eanIt[
-loup Ga
3:;4-&y
y'.5<
=6/7>0
?u='@^
@`ZG2e
u6&Bt>
%*.*f I64gg
CNotSupporExce
?A8Gdi
CBitmap
ResourW
PI9QI$
MS San
rifh6l Dlg
8oOd3/.
AfxOldh"4
8lBar%'MDIFramn
OrViewo
omPoiu'
USERxk
ZVSPLAY
c^m|rl_D
COML4;
BButt
!P&Ng&|
J|Prev
/CmdTar
b6Word
D?MaptToM
.INI>.HLPH
hareVi
lC8ngedNo6fy
ahw\'RT
swo_OG?
__GLOBAL_[p4[
.MSVCRTm
tv xro
SINGNOMA$
4#R6028
|OdZRoO7nZ
iOOo6stST
Bck_/'pl)i
ml`#vb_09
TV`\W8
1B`uQs
c VisUC++ RA
t@KERNP
ld?<f?f-
(8?{w
{`c`@,7pR6@
omainB
pip<TP:ny
PI/O<`
guchU^m
1#Ql R
d5nW O
Oh0)&5
pyNNN{
r-O@Pr
h"GNq9
o8n
%S`H1+
px''''
C|8'S
HO@HPH
rRP%S^;
yyD?@TPT
nU'&gA
.PAVC@
(ilto:
|]_"G"
R#NEFAULT_I
WG!2S(
<4 0!,
ohjmnpr;
034/)7
hgjlkbrfzaoe
C.-25(
kf'90}
7@af0R
.S-B*>b
2lhP(2>
Fib8QQ0
$&3j*T
bpf*R2>
(.+3a$*
> F%DB
BJ"25&
!@[jj!rJ#
~en&ru0
a&a\ewM
4]Fysczr4M
4xqjhkK
?? /d]
C7|2I-e
ph`XPH<
<@80(
th\PD8
LMNOPQ<
<RSTUVW=
WXYZ;qsu
+Shift+F
B.765B.
B43Vp.
rrrr8765
vrr432
_NAlphaBl2
BMPGIFICOCUR;B
%s:%d_n
!t}SKt
xCTs'?
WR 16 p
urPicker
E8RIFF
c()h bu1
uv 1.6.
/handl
n_IDATBG
NULLO"
r_IMAGE_VERS
-,p]:{
3zckgr
#g(BAD Q
O[161G
<]^_`a
kOv 0
,rv/o>
6U)RAi
CZ_o:C
orS_#_f
EbnASCII3
,[>RC
'tRNS]
w;)BUx@
vwP ]K;
H_to_q
+I+k+=
}v1a{`
JPEGMEM'`
|l6T0NC
56C5_C'
=s>R/p
h9999(
+tNNNN4
dNNNN$
i)9999
BNN.}=
c#NNNN
T!<OSy\ R
t$9G?7
R[`c,H
L*&-{a
<09>C
y.&),/kw
/l6/D9
^,k]k6WGi
:?BEJMy
yPSVY\
nqtwz}y
0o?7e'
6WX/Sl
UI_st7*
?_AFX_
/HECKL
THREA1?
=MODULEo
moPn@X%g
7?OOLO1 ,
5ACPg
n/mV p
J[4=^$k
%Lo&;/
wQ0@TDh
utAG\w
X#T$P
yZ`flr
&$n/+_
Ixx@o
&?'7Tn
"afx8."
=EgNO_
_RESOU
LGOLE=
'PROPBTYGJifJ
!Sd(;_|`
!*) || 9TARGxo
LANGUAGE 4
e(936k
//oGl.
0oGYvP
Q-H._{
NpeG|%
hfVNTbbw{i
`v}6dR
oN*g}T
W-N/~b
7Hr,gJ
~&TcknxG
OpeW[
N^>W[&{
Rz<Ps'
2 }+QEAGI
?)jlHx
cpynAW)
SJaphDeA
oy|GG/
sW/,#_4
c-98ZRZ5&
-Z,^fa
<>F5KN
'Add\
19p?In
?m?o7e
rg#CB
c%R>42
chBltOn
[/DChY
]Ic=SH
{boJ[f(
#Ed7% K
+CQui'
hULrC%>
"_?|eN
Fb|&mi
XPTPSW
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
ole32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
WINMM.dll
WINSPOOL.DRV
WS2_32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegCloseKey
ChooseColorA
PatBlt
OleRun
ShellExecuteA
waveOutOpen
ClosePrinter
TEXTINCLUDE
DEFAULT_ICON
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Multi.Generic.mE1c
Elastic malicious (high confidence)
ClamAV Win.Malware.Babar-10034117-0
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.17444789249334dc
Skyhigh BehavesLike.Win32.Generic.gc
ALYac Gen:Variant.Barys.59148
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (W)
Alibaba TrojanDownloader:Win32/FlyStudio.09f20e8e
K7GW Trojan ( 005246d51 )
K7AntiVirus Trojan ( 005246d51 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/FlyStudio.ORN
APEX Malicious
Avast MalwareX-gen [Misc]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.Win32.Agent.gen
BitDefender Gen:Variant.Barys.59148
NANO-Antivirus Trojan.Win32.BlackHole.hqumcr
ViRobot Trojan.Win.Z.Barys.410112
MicroWorld-eScan Gen:Variant.Barys.59148
Tencent Win32.Trojan-Downloader.Agent.Jajl
Sophos Mal/Generic-S
F-Secure Trojan.TR/ATRAPS.Gen
DrWeb Trojan.Siggen31.11387
VIPRE Gen:Variant.Barys.59148
TrendMicro Clean
McAfeeD Real Protect-LS!B2A7F546295D
Trapmine malicious.high.ml.score
CTX exe.trojan.flystudio
Emsisoft Gen:Variant.Barys.59148 (B)
Ikarus PUA.BlackMoon
GData Gen:Variant.Barys.59148
Jiangmin Clean
Webroot Clean
Varist W32/S-776111c5!Eldorado
Avira TR/ATRAPS.Gen
Antiy-AVL Trojan[Packed]/Win32.FlyStudio
Kingsoft Clean
Gridinsoft Trojan.Win32.Agent.sa
Xcitium TrojWare.Win32.TrojanSpy.Banker.OV@6e1pyh
Arcabit Trojan.Barys.DE70C
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!B2A7F546295D
TACHYON Clean
VBA32 BScope.Trojan.Wacatac
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09DC25
Rising Trojan.Occamy!8.F1CD (TFE:5:lbQiteBw5lK)
Yandex Trojan.GenAsa!zBP+1MxmcWM
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/FlyApplication
AVG MalwareX-gen [Misc]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:Win/FlyStudio.OVS
No IRMA results available.