Static | ZeroBOX

PE Compile Time

2014-02-21 09:32:51

PDB Path

c:\BelieveMetal\WingBad\FootIn\GladRoot\WhoseCrowd\Chance.pdb

PE Imphash

1b86fe32916e9e09d908380089868a64

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000465c9 0x00046600 5.29350481742
.rdata 0x00048000 0x00011482 0x00011600 4.50834853025
.data 0x0005a000 0x00014f8c 0x00005400 4.76881471366
.reloc 0x0006f000 0x00001d10 0x00001e00 6.49808582892

Imports

Library KERNEL32.dll:
0x1448000 GetWindowsDirectoryA
0x1448004 Sleep
0x1448008 GetSystemDirectoryA
0x144800c VirtualProtect
0x1448010 WideCharToMultiByte
0x1448014 EncodePointer
0x1448018 DecodePointer
0x144801c EnterCriticalSection
0x1448020 LeaveCriticalSection
0x1448024 DeleteCriticalSection
0x1448028 MultiByteToWideChar
0x144802c GetStringTypeW
0x1448030 GetLastError
0x1448034 HeapFree
0x1448038 GetCommandLineA
0x144803c GetCurrentThreadId
0x1448040 GetCPInfo
0x1448044 RaiseException
0x1448048 RtlUnwind
0x144804c HeapAlloc
0x144805c SetLastError
0x1448064 GetCurrentProcess
0x1448068 TerminateProcess
0x144806c TlsAlloc
0x1448070 TlsGetValue
0x1448074 TlsSetValue
0x1448078 TlsFree
0x144807c GetStartupInfoW
0x1448080 GetModuleHandleW
0x1448084 GetProcAddress
0x1448088 LCMapStringW
0x144808c GetLocaleInfoW
0x1448090 IsValidLocale
0x1448094 GetUserDefaultLCID
0x1448098 EnumSystemLocalesW
0x144809c IsDebuggerPresent
0x14480a0 GetProcessHeap
0x14480a4 ExitProcess
0x14480a8 GetModuleHandleExW
0x14480ac HeapSize
0x14480b0 GetStdHandle
0x14480b4 GetFileType
0x14480b8 GetModuleFileNameA
0x14480c0 GetCurrentProcessId
0x14480d0 IsValidCodePage
0x14480d4 GetACP
0x14480d8 GetOEMCP
0x14480dc WriteFile
0x14480e0 GetModuleFileNameW
0x14480e4 CloseHandle
0x14480e8 FlushFileBuffers
0x14480ec GetConsoleCP
0x14480f0 GetConsoleMode
0x14480f4 ReadFile
0x14480f8 SetFilePointerEx
0x14480fc HeapReAlloc
0x1448100 LoadLibraryExW
0x1448104 OutputDebugStringW
0x1448108 SetStdHandle
0x144810c WriteConsoleW
0x1448110 ReadConsoleW
0x1448114 CreateFileW

Exports

Ordinal Address Name
1 0x142d410 DllRegisterServer
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
t}9uyj
Wyac~v
}Th0%g
eaBh2;
0I0j(E
d,}`aN
*s}a91
=o-,Jp
tc-r@[
p'9{0J
';I42)
+TX:u[)X
$w>0K"
YwHKt
7+Vt}9
E7+?T
%Db!u2
NmGCV`X
6pLrsCbA
O(O6j>
ZAZOFC
w*`B8 s9
w;$9&e6x
Ufx<4I
/$7.jT
SJX'?to
?WJq|v#u
"rmR.^G[m
KSxJ2R
^.WeH=
?Y)=EE
L89W,V&O
F=&LkB
9 (\&H
7z;WrXp
du!eA'cQF
tqRFno
ZtpyEC1
pT]m\ph
(u0,%h
oFH:J=
^,kY:+j(
_L63y
/CZ(&L
p}<K5h
LE`\d7R
"AfuOb
lgkjPp
4eW"L~
t4$M"j
tXm!,m
7r?vKX
Wd.UyOF
k}A"5!
q?1u;\
| ~$-%
<._=>-d
FDHTFL
&Ed:^.
$o!qtEv
}|&%TK
ylu(|
D$ SVW
D$@SVW
CD$ QP
D$ j@P
D$ j@P
D$$j@P
D$$j@P
D$8jlP
D$8jlP
D$`SVW
CD$@VWR
D$,RPW
D$HSVW
D$$RPS
tg9ucj
t|9uxj
tG9uCj
PPPPPPPP
QQSVWd
HtHu4j
PP9E u
jA[jZZ+
~pjCXf
j@j _W
,SVWj0X
Wj0XPV
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
RVSQSWV
SVWjA_jZ+
uBjAYjZ+
HHtVHHt
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
URPQQh
t WW9}
;t$,v-
UQPXY]Y[
PWWWWV
PSSSSV
Yu2Vj@hH
~';_t|%3
Ht+Ht$Ht
HtHHt
+tHHt
+t"HHt
HAO8t
SVjA[jZ^+
jAZjZ^
uHjAXf;
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad allocation
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefABCDEF
Unknown exception
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
(null)
`h````
xpxxxx
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
CorExitProcess
_hypot
_nextafter
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
`h`hhh
xppwpp
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
1#SNAN
1#QNAN
bad locale name
generic
unknown error
iostream
iostream stream error
system
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
string too long
invalid string position
bad cast
[[[k^^^
[[[d[[[q^^^
v0pT^<
#"Bbc`a
Q/P?>9
^b~RVy
ONNN^N
T-G #+
NNNNNN
8~,-7\
Jdc1ekN
~sRB_n
o`hI~@
RQ5GNE
R;MwQ1
swlfOj
YNONNN
|@I_jm
f:W*a<
NNNNNN
NONNNNON
NNNOOO
NNNNOO
NONNN\
OONNOO
NNONON%NN
NNN^O_
NONNON
c:\BelieveMetal\WingBad\FootIn\GladRoot\WhoseCrowd\Chance.pdb
Chance.dll
DllRegisterServer
GetWindowsDirectoryA
GetSystemDirectoryA
VirtualProtect
KERNEL32.dll
WideCharToMultiByte
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
MultiByteToWideChar
GetStringTypeW
GetLastError
HeapFree
GetCommandLineA
GetCurrentThreadId
GetCPInfo
RaiseException
RtlUnwind
HeapAlloc
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetModuleHandleW
GetProcAddress
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
IsDebuggerPresent
GetProcessHeap
ExitProcess
GetModuleHandleExW
HeapSize
GetStdHandle
GetFileType
GetModuleFileNameA
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
IsValidCodePage
GetACP
GetOEMCP
WriteFile
GetModuleFileNameW
CloseHandle
FlushFileBuffers
GetConsoleCP
GetConsoleMode
ReadFile
SetFilePointerEx
HeapReAlloc
LoadLibraryExW
OutputDebugStringW
SetStdHandle
WriteConsoleW
ReadConsoleW
CreateFileW
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
5(bjc:o
f"lmku
DDDDVVVV
2tjdk;
fVuu$Y
1wTl,>
3u%#O'777`
NT/i98
c/o}>x
LL&L{7
#dam[l<L
O'$8L
sVnQhW
]8176bkY/7
&:;XxQ
CMD!Y
evmW,#
OoyA-{
|~C~U)
Nc2a.=T^X
_>CxWy
OONN_ON
NNNOXNON
NNNNNN
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDH@std@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AV_System_error@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AVexception@std@@
.?AV_Iostream_error_category@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$ctype@D@std@@
.?AV_System_error_category@std@@
.?AV?$numpunct@D@std@@
.?AVerror_category@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV_Generic_error_category@std@@
.?AV_Facet_base@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
0!0-090I0N0X0k0
1'131=1I1U1_1
1$232?2
3:3j3p3
6S7b7n7
7Y8h8t8
999H9U9
<#<(<4<@<
:T:g:q:
; ;*;6;<;B;R;[;c;o;v;
<"<,<9<I<S<\<e<o<u<
="=+=1=;=A=K=Q=g=n=t=~=
>#>+>H>N>g>w>
?&?/?3?
1.161>1
212;2S2Z2m2s2
33'3B3I3T3`3f3~3
4 4'4@4U4a4~4
5(565I5O5Z5
6*666K6Y6c6j6p6v6
7,72777=7L7
=!=+={=
9698:0;:;D;
<%=9=I=)>8>F>
93H3V3
>O?]?s?
2&3L374=4a4g4
6.767<7K7
8P8]8q8
90959;9Q9W9j9p9
7A8O8Y8}8
9?9R9a9q9
<"<(<4<B<S<Y<_<f<
E1c1|1
2 2$2(2r2x2|2
3 3$3E3o3
9"9,9`9u9
080g0n0
1E3c3|3
4 4$4(4r4x4|4
5 5$5E5o5
6 6'8r8
<$<D=J=N=S=Y=]=c=g=m=q=v=|=
040A0P0Z0l0{0
0"1/181\1
66A6H6
>->^>v>
>#>C>N>
0C1X1t1
3#3-333B3L3R3d3n3t3
4"4(40454;4C4H4N4V4[4a4i4n4t4|4
55'5,525:5?5E5M5R5X5`5e5k5s5x5~5
6#6)61666;6D6I6O6W6]6k6y6
0 0$0(0,0004080<0@0D0H0L0i0
2(2.2I2S2Y2
4Q4W4]4c4i4o4v4}4
5%5X5^5d5j5p5v5}5
:R;[;c;};
)0a0i0
1/1J1b1n1}1
152?2a2|2
3)363>3Z3f3l3w3
484@4S4^4c4s4
6:6?6K6P6o6
:5<P<f<|<
1L2R2t2
3)4>4D4|4
77%7+717
7*999p9|9
:3:?:N:W:d:
;%;5;:;U;Z;w;
=#=-=:=D=T=
131;1I1N1]1
4'4l4r4w4[9
;p<F?L?R?{?
0(0D0K0Q0_0e0z0
8"8/8:8E8M8
9J9g9 :
6*676<6J6
8*9a9{9
;V;_;};
<J=S=0>;>N>b>$?-?
90B0.1x1
2:2<3E3
7+8H8g8!9+9F9`95<;<G<~<
<#=)=5=:=?=D=M=
4#454G4Y4k4}4
7;7O7U7
</<8<f<N>
4+414@4G4W4]4c4k4q4w4
5K5c5|5
;s;~;i<
3#3F3p3
<6<Y<m<
2l6p6t6x6|6
6@8Q8e8k8p8
52565B5F5R5V5\5f5p5z5
1$1(1,1014181<1@1D1H1L1P1T1X1\1h1l1p1t1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
60?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
3 3$3(3,303X3\3`3d3h3l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
5$5,545<5D5
? ?$?(?,?0?4?8?<?
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3H9T9`9l9x9
: :,:8:D:P:\:h:t:
;(;4;@;L;X;d;p;|;
<$<0<<<H<
4(444@4L4X4d4p4|4
4P5T5d5h5l5p5x5
6,6<6@6P6T6X6\6d6|6
7(7,7<7@7D7H7L7T7l7|7
8 8$8(808H8X8\8l8p8t8|8
909@9D9T9X9\9`9h9
:(:8:<:L:P:T:\:t:x:
;$;<;L;P;T;X;\;`;h;l;p;
<,<<<@<D<H<L<`<d<t<
= =$=<=@=X=h=l=p=
>$>(>,>0>4>8>L>P>T>l>|>
0(000<0\0h0
1$141@1`1l1
2$2D2L2T2\2h2
3,383X3d3l3
4 4(404<4D4x4
5 5@5L5l5x5
6 6(6<6D6L6T6X6\6d6x6
707P7p7
888X8x8
9<9H9P9|9
: :,:H:d:h:
;$;(;H;T;`;
< <@<`<|<
= =4=<=D=L=P=T=X=\=d=h=p=
3@7D7h7l7
8 8$8(84888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9,9<9L9l9x9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
@0D0H0L0P0T0X0\0`0d0h0
p>t>x>
0$0D0d0
((((( H
((((( H
kernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
(null)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
mscoree.dll
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
USER32.DLL
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
N[OONN
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.36433685
FireEye Generic.mg.649b5c913739cea1
CAT-QuickHeal Trojan.Cridex
Qihoo-360 Win32/Trojan.Dridex.HgkASQIA
McAfee Trojan-FRGC!649B5C913739
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Cridex.7!c
Sangfor Trojan.Win32.Cridex.gen
K7AntiVirus Spyware ( 00552cf91 )
BitDefender Trojan.GenericKD.36433685
K7GW Spyware ( 00552cf91 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/Trojan.QCNZ-3867
Symantec Trojan.Gen.2
TotalDefense Clean
APEX Clean
Avast Win32:Malware-gen
ClamAV Clean
Kaspersky HEUR:Trojan-Banker.Win32.Cridex.gen
Alibaba TrojanSpy:Win32/Ursnif.32410193
NANO-Antivirus Trojan.Win32.Cridex.intjhn
ViRobot Trojan.Win32.Z.Wacatac.389632
Tencent Win32.Trojan-banker.Cridex.Woqd
Ad-Aware Trojan.GenericKD.36433685
Emsisoft Trojan.GenericKD.36433685 (B)
Comodo Malware@#n9lfuh33p7k8
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro TROJ_FRS.VSNTC221
McAfee-GW-Edition Trojan-FRGC!649B5C913739
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
GData Trojan.GenericKD.36433685
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=87)
Antiy-AVL Trojan[Banker]/Win32.Cridex
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Banker.oa
Arcabit Trojan.Generic.D22BEF15
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Banker.Win32.Cridex.gen
Microsoft Trojan:Win32/Ursnif.SS!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.Generic.C4349328
Acronis Clean
BitDefenderTheta Clean
ALYac Spyware.Ursnif
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt
Panda Trj/GdSda.A
Zoner Clean
ESET-NOD32 Win32/Spy.Ursnif.CT
TrendMicro-HouseCall TROJ_FRS.VSNTC221
Rising Spyware.Ursnif!8.1DEF (CLOUD)
Yandex Clean
Ikarus Trojan-Banker.UrSnif
eGambit Unsafe.AI_Score_89%
Fortinet PossibleThreat.MU
AVG Win32:Malware-gen
Paloalto generic.ml
MaxSecure Trojan.Malware.74474672.susgen
No IRMA results available.