PE Compile Time

2019-03-28 08:37:00

PDB Path

mscorsvw.pdb

PE Imphash

b6ffaae8ad145b27b7f899bf03c8eee0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000f8d4 0x0000fa00 6.20859544671
.rdata 0x00011000 0x00010e0e 0x00011000 4.22902510609
.data 0x00022000 0x000011f8 0x00000400 1.84366887655
.pdata 0x00024000 0x00000d68 0x00000e00 4.863113588
.rsrc 0x00025000 0x0000076c 0x00000800 4.7910995981
.reloc 0x00026000 0x001e6000 0x0013a000 4.52162663855

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000250a0 0x000003f0 LANG_ENGLISH SUBLANG_ENGLISH_US SysEx File - OctavePlateau
RT_MANIFEST 0x00025490 0x000002dc LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with very long lines (732), with no line terminators

Imports

Library ADVAPI32.dll:
0x140011000 DuplicateTokenEx
0x140011008 SetTokenInformation
0x140011010 RegQueryInfoKeyW
0x140011018 RegCloseKey
0x140011020 RegOpenKeyExW
0x140011028 EventWrite
0x140011030 RegQueryValueExW
Library KERNEL32.dll:
0x140011040 DebugBreak
0x140011048 LoadLibraryExW
0x140011050 IsDebuggerPresent
0x140011058 GetStartupInfoW
0x140011060 InitializeSListHead
0x140011078 UnhandledExceptionFilter
0x140011080 RtlVirtualUnwind
0x140011088 RtlLookupFunctionEntry
0x140011090 RtlCaptureContext
0x140011098 GetCurrentProcessId
0x1400110a0 VirtualQuery
0x1400110a8 TlsFree
0x1400110b0 TlsGetValue
0x1400110b8 SleepEx
0x1400110c0 CreateSemaphoreW
0x1400110c8 DeleteCriticalSection
0x1400110d0 HeapDestroy
0x1400110d8 ResetEvent
0x1400110e0 TlsAlloc
0x1400110e8 GetFileType
0x1400110f0 HeapValidate
0x1400110f8 ReleaseMutex
0x140011100 CreateMutexW
0x140011110 LeaveCriticalSection
0x140011118 VirtualAlloc
0x140011120 ReleaseSemaphore
0x140011128 VirtualFree
0x140011130 EnterCriticalSection
0x140011138 VirtualProtect
0x140011140 TlsSetValue
0x140011148 HeapCreate
0x140011150 QueryPerformanceCounter
0x140011158 GetSystemTimeAsFileTime
0x140011160 GetCurrentThreadId
0x140011168 SetLastError
0x140011170 LocalFree
0x140011178 FormatMessageW
0x140011180 GetACP
0x140011188 GetCPInfo
0x140011190 RaiseException
0x140011198 GetModuleHandleW
0x1400111a0 HeapSetInformation
0x1400111a8 MultiByteToWideChar
0x1400111b0 CreateFileW
0x1400111b8 WaitForSingleObject
0x1400111c0 FindClose
0x1400111c8 GetEnvironmentVariableW
0x1400111d0 FreeLibrary
0x1400111d8 GetProcAddress
0x1400111e0 GetWindowsDirectoryW
0x1400111e8 CreateThread
0x1400111f0 CloseHandle
0x1400111f8 SetEvent
0x140011200 OutputDebugStringW
0x140011208 GetLastError
0x140011210 CreateEventW
0x140011218 GetFileAttributesW
0x140011220 SetEnvironmentVariableW
0x140011228 WaitForMultipleObjects
0x140011230 GetModuleFileNameW
0x140011238 TerminateProcess
0x140011240 WriteFile
0x140011248 GetStdHandle
0x140011250 GetCurrentProcess
0x140011258 GetCommandLineW
0x140011260 WerSetFlags
0x140011268 WaitForSingleObjectEx
0x140011270 HeapFree
0x140011278 HeapAlloc
0x140011280 GetProcessHeap
0x140011288 FindFirstFileW
Library VCRUNTIME140_CLR0400.dll:
0x1400112e8 memcpy
0x1400112f0 memset
0x1400112f8 __C_specific_handler
0x140011300 _purecall
0x140011308 memmove
0x140011310 __CxxFrameHandler3
0x140011318 _CxxThrowException
Library ucrtbase_clr0400.dll:
0x140011378 _c_exit
0x140011380 _cexit
0x140011388 _set_fmode
0x140011390 _exit
0x140011398 exit
0x1400113a0 _initterm_e
0x1400113a8 _initterm
0x1400113c0 _configure_narrow_argv
0x1400113c8 __setusermatherr
0x1400113d0 _set_app_type
0x1400113d8 _seh_filter_exe
0x1400113e8 malloc
0x1400113f0 free
0x1400113f8 strcpy_s
0x140011408 wcsncmp
0x140011410 strncmp
0x140011418 iswspace
0x140011420 _errno
0x140011428 wcscat_s
0x140011430 wcsncpy_s
0x140011438 _wcsnicmp
0x140011448 wcstoul
0x140011450 wcscpy_s
0x140011458 __stdio_common_vfwprintf
0x140011460 fflush
0x140011468 _wcsicmp
0x140011470 __acrt_iob_func
0x140011478 freopen
0x140011480 _configthreadlocale
0x140011488 _set_new_mode
0x140011490 __p__commode
0x140011498 _initialize_onexit_table
0x1400114a8 _crt_atexit
0x1400114b0 terminate
Library mscoree.dll:
0x140011328 GetRequestedRuntimeInfo
Library ole32.dll:
0x140011338 CoAddRefServerProcess
0x140011340 CoTaskMemFree
0x140011348 CoMarshalInterface
0x140011350 CreateStreamOnHGlobal
0x140011358 CoInitializeEx
0x140011360 CoUninitialize
0x140011368 CoReleaseServerProcess
Library OLEAUT32.dll:
0x140011298 SysAllocString
0x1400112a0 SysFreeString
0x1400112a8 SetErrorInfo
0x1400112b0 SysStringLen
Library USER32.dll:
0x1400112c8 LoadStringW
0x1400112d0 PeekMessageW
0x1400112d8 DispatchMessageW

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
H SVWH
UWATAVAWH
A_A^A\_]
@USVWAVH
A^_^[]
WATAUAVAWH
fB94Au
9t$xt#H
A_A^A]A\_
WATAUAVAWH
9\$Xt#H
D$09D$8t
9\$Ht#H
D$09D$4t
9\$Ht#H
\$H9\$Xt#H
A_A^A]A\_
UWATAVAWH
0A_A^A\_]
UAVAWH
uOD853
uTD85%
D9t$hu
UAVAWH
xWD9|$ uPL
x*D9|$ u#
@SUVWAVH
A^_^][
UVWATAUAVAWH
upL95;
xLD9t$0tE
EXH9D$0
xKL9t$0tD
L$0H9L$8
A_A^A]A\_^]
UVWATAUAVAWH
xQD9t$ tJH
fD94Xu
fD94Yu
A_A^A]A\_^]
WATAUAVAWH
fD9,Yu
A_A^A]A\_
t$ WAUAVH
A^A]_
x AUAVAWH
A!)H!l$0
@A_A^A]
AUAVAWH
A_A^A]
= RHu!H
= LEDu7H
D$ RHL
UAVAWH
UVWAVAWH
A_A^_^]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWAVH
A^_^[]
UAVAWH
UAVAWH
fD9,^u
UVWATAUAVAWH
L$HL99t
D9|$Xt
A_A^A]A\_^]
C(H9C@
K@H;K0u
K SUVWAVAWH
A_A^_^][
fB94Au
H UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
x ATAVAWH
A_A^A\
VWATAVAWH
A_A^A\_^
t$ WAVAWH
fD94Xu
u$D85x{
0A_A^_
WAVAWH
fD94Bu
A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
A_A^_
VWATAUAWH
t.A9]Ht(
A_A]A\_^
WATAVH
@A^A\_
D9I ~aL
WAVAWH
tJHcC H
A_A^_
UVWATAUAVAWH
u=9EXu8A
@A_A^A]A\_^]
@SVWATAUAVAWH
fB9<xu
fB9<`u
A_A^A]A\_^[
H3E H3E
SUVWAVH
A^_^][
SUVWAVH
`A^_^][
SUVWAVH
0A^_^][
SUVWAVH
A^_^][
SUVWAVH
PA^_^][
MessageBoxW
EX_CATCH line %d
AttachConsole
NGenCreateNGenWorker
CONOUT$
CorGetSvc
CLRCreateInstance
StartServiceCtrlDispatcherW
RegisterServiceCtrlHandlerExW
SetServiceStatus
WTSFreeMemory
WTSEnumerateSessionsW
CreateProcessAsUserW
OpenProcessToken
SHGetKnownFolderPath
COMPLUS
retail
v1.0.3705
Out Of Memory
S_FALSE
E_UNEXPECTED
E_NOTIMPL
E_OUTOFMEMORY
E_INVALIDARG
E_NOINTERFACE
E_POINTER
E_HANDLE
E_ABORT
E_FAIL
E_ACCESSDENIED
CO_E_INIT_TLS
CO_E_INIT_SHARED_ALLOCATOR
CO_E_INIT_MEMORY_ALLOCATOR
CO_E_INIT_CLASS_CACHE
CO_E_INIT_RPC_CHANNEL
CO_E_INIT_TLS_SET_CHANNEL_CONTROL
CO_E_INIT_TLS_CHANNEL_CONTROL
CO_E_INIT_UNACCEPTED_USER_ALLOCATOR
CO_E_INIT_SCM_MUTEX_EXISTS
CO_E_INIT_SCM_FILE_MAPPING_EXISTS
CO_E_INIT_SCM_MAP_VIEW_OF_FILE
CO_E_INIT_SCM_EXEC_FAILURE
CO_E_INIT_ONLY_SINGLE_THREADED
OLE_E_OLEVERB
OLE_E_ADVF
OLE_E_ENUM_NOMORE
OLE_E_ADVISENOTSUPPORTED
OLE_E_NOCONNECTION
OLE_E_NOTRUNNING
OLE_E_NOCACHE
OLE_E_BLANK
OLE_E_CLASSDIFF
OLE_E_CANT_GETMONIKER
OLE_E_CANT_BINDTOSOURCE
OLE_E_STATIC
OLE_E_PROMPTSAVECANCELLED
OLE_E_INVALIDRECT
OLE_E_WRONGCOMPOBJ
OLE_E_INVALIDHWND
OLE_E_NOT_INPLACEACTIVE
OLE_E_CANTCONVERT
OLE_E_NOSTORAGE
DV_E_FORMATETC
DV_E_DVTARGETDEVICE
DV_E_STGMEDIUM
DV_E_STATDATA
DV_E_LINDEX
DV_E_TYMED
DV_E_CLIPFORMAT
DV_E_DVASPECT
DV_E_DVTARGETDEVICE_SIZE
DV_E_NOIVIEWOBJECT
DRAGDROP_E_NOTREGISTERED
DRAGDROP_E_ALREADYREGISTERED
DRAGDROP_E_INVALIDHWND
CLASS_E_NOAGGREGATION
CLASS_E_CLASSNOTAVAILABLE
VIEW_E_DRAW
REGDB_E_READREGDB
REGDB_E_WRITEREGDB
REGDB_E_KEYMISSING
REGDB_E_INVALIDVALUE
REGDB_E_CLASSNOTREG
CACHE_E_NOCACHE_UPDATED
OLEOBJ_E_NOVERBS
INPLACE_E_NOTUNDOABLE
INPLACE_E_NOTOOLSPACE
CONVERT10_E_OLESTREAM_GET
CONVERT10_E_OLESTREAM_PUT
CONVERT10_E_OLESTREAM_FMT
CONVERT10_E_OLESTREAM_BITMAP_TO_DIB
CONVERT10_E_STG_FMT
CONVERT10_E_STG_NO_STD_STREAM
CONVERT10_E_STG_DIB_TO_BITMAP
CLIPBRD_E_CANT_OPEN
CLIPBRD_E_CANT_EMPTY
CLIPBRD_E_CANT_SET
CLIPBRD_E_BAD_DATA
CLIPBRD_E_CANT_CLOSE
MK_E_CONNECTMANUALLY
MK_E_EXCEEDEDDEADLINE
MK_E_NEEDGENERIC
MK_E_UNAVAILABLE
MK_E_SYNTAX
MK_E_NOOBJECT
MK_E_INVALIDEXTENSION
MK_E_INTERMEDIATEINTERFACENOTSUPPORTED
MK_E_NOTBINDABLE
MK_E_NOTBOUND
MK_E_CANTOPENFILE
MK_E_MUSTBOTHERUSER
MK_E_NOINVERSE
MK_E_NOSTORAGE
MK_E_NOPREFIX
MK_E_ENUMERATION_FAILED
CO_E_NOTINITIALIZED
CO_E_ALREADYINITIALIZED
CO_E_CANTDETERMINECLASS
CO_E_CLASSSTRING
CO_E_IIDSTRING
CO_E_APPNOTFOUND
CO_E_APPSINGLEUSE
CO_E_ERRORINAPP
CO_E_DLLNOTFOUND
CO_E_ERRORINDLL
CO_E_WRONGOSFORAPP
CO_E_OBJNOTREG
CO_E_OBJISREG
CO_E_OBJNOTCONNECTED
CO_E_APPDIDNTREG
CO_E_RELEASED
OLE_S_USEREG
OLE_S_STATIC
OLE_S_MAC_CLIPFORMAT
DRAGDROP_S_DROP
DRAGDROP_S_CANCEL
DRAGDROP_S_USEDEFAULTCURSORS
DATA_S_SAMEFORMATETC
VIEW_S_ALREADY_FROZEN
CACHE_S_FORMATETC_NOTSUPPORTED
CACHE_S_SAMECACHE
CACHE_S_SOMECACHES_NOTUPDATED
OLEOBJ_S_INVALIDVERB
OLEOBJ_S_CANNOT_DOVERB_NOW
OLEOBJ_S_INVALIDHWND
INPLACE_S_TRUNCATED
CONVERT10_S_NO_PRESENTATION
MK_S_REDUCED_TO_SELF
MK_S_ME
MK_S_HIM
MK_S_US
MK_S_MONIKERALREADYREGISTERED
CO_E_CLASS_CREATE_FAILED
CO_E_SCM_ERROR
CO_E_SCM_RPC_FAILURE
CO_E_BAD_PATH
CO_E_SERVER_EXEC_FAILURE
CO_E_OBJSRV_RPC_FAILURE
MK_E_NO_NORMALIZED
CO_E_SERVER_STOPPING
MEM_E_INVALID_ROOT
MEM_E_INVALID_LINK
MEM_E_INVALID_SIZE
DISP_E_UNKNOWNINTERFACE
DISP_E_MEMBERNOTFOUND
DISP_E_PARAMNOTFOUND
DISP_E_TYPEMISMATCH
DISP_E_UNKNOWNNAME
DISP_E_NONAMEDARGS
DISP_E_BADVARTYPE
DISP_E_EXCEPTION
DISP_E_OVERFLOW
DISP_E_BADINDEX
DISP_E_UNKNOWNLCID
DISP_E_ARRAYISLOCKED
DISP_E_BADPARAMCOUNT
DISP_E_PARAMNOTOPTIONAL
DISP_E_BADCALLEE
DISP_E_NOTACOLLECTION
TYPE_E_BUFFERTOOSMALL
TYPE_E_INVDATAREAD
TYPE_E_UNSUPFORMAT
TYPE_E_REGISTRYACCESS
TYPE_E_LIBNOTREGISTERED
TYPE_E_UNDEFINEDTYPE
TYPE_E_QUALIFIEDNAMEDISALLOWED
TYPE_E_INVALIDSTATE
TYPE_E_WRONGTYPEKIND
TYPE_E_ELEMENTNOTFOUND
TYPE_E_AMBIGUOUSNAME
TYPE_E_NAMECONFLICT
TYPE_E_UNKNOWNLCID
TYPE_E_DLLFUNCTIONNOTFOUND
TYPE_E_BADMODULEKIND
TYPE_E_SIZETOOBIG
TYPE_E_DUPLICATEID
TYPE_E_INVALIDID
TYPE_E_TYPEMISMATCH
TYPE_E_OUTOFBOUNDS
TYPE_E_IOERROR
TYPE_E_CANTCREATETMPFILE
TYPE_E_CANTLOADLIBRARY
TYPE_E_INCONSISTENTPROPFUNCS
TYPE_E_CIRCULARTYPE
STG_E_INVALIDFUNCTION
STG_E_FILENOTFOUND
STG_E_PATHNOTFOUND
STG_E_TOOMANYOPENFILES
STG_E_ACCESSDENIED
STG_E_INVALIDHANDLE
STG_E_INSUFFICIENTMEMORY
STG_E_INVALIDPOINTER
STG_E_NOMOREFILES
STG_E_DISKISWRITEPROTECTED
STG_E_SEEKERROR
STG_E_WRITEFAULT
STG_E_READFAULT
STG_E_SHAREVIOLATION
STG_E_LOCKVIOLATION
STG_E_FILEALREADYEXISTS
STG_E_INVALIDPARAMETER
STG_E_MEDIUMFULL
STG_E_ABNORMALAPIEXIT
STG_E_INVALIDHEADER
STG_E_INVALIDNAME
STG_E_UNKNOWN
STG_E_UNIMPLEMENTEDFUNCTION
STG_E_INVALIDFLAG
STG_E_INUSE
STG_E_NOTCURRENT
STG_E_REVERTED
STG_E_CANTSAVE
STG_E_OLDFORMAT
STG_E_OLDDLL
STG_E_SHAREREQUIRED
STG_E_NOTFILEBASEDSTORAGE
STG_S_CONVERTED
RPC_E_CALL_REJECTED
RPC_E_CALL_CANCELED
RPC_E_CANTPOST_INSENDCALL
RPC_E_CANTCALLOUT_INASYNCCALL
RPC_E_CANTCALLOUT_INEXTERNALCALL
RPC_E_CONNECTION_TERMINATED
RPC_E_SERVER_DIED
RPC_E_CLIENT_DIED
RPC_E_INVALID_DATAPACKET
RPC_E_CANTTRANSMIT_CALL
RPC_E_CLIENT_CANTMARSHAL_DATA
RPC_E_CLIENT_CANTUNMARSHAL_DATA
RPC_E_SERVER_CANTMARSHAL_DATA
RPC_E_SERVER_CANTUNMARSHAL_DATA
RPC_E_INVALID_DATA
RPC_E_INVALID_PARAMETER
RPC_E_CANTCALLOUT_AGAIN
RPC_E_SERVER_DIED_DNE
RPC_E_SYS_CALL_FAILED
RPC_E_OUT_OF_RESOURCES
RPC_E_ATTEMPTED_MULTITHREAD
RPC_E_NOT_REGISTERED
RPC_E_FAULT
RPC_E_SERVERFAULT
RPC_E_CHANGED_MODE
RPC_E_INVALIDMETHOD
RPC_E_DISCONNECTED
RPC_E_RETRY
RPC_E_SERVERCALL_RETRYLATER
RPC_E_SERVERCALL_REJECTED
RPC_E_INVALID_CALLDATA
RPC_E_CANTCALLOUT_ININPUTSYNCCALL
RPC_E_WRONG_THREAD
RPC_E_THREAD_NOT_INIT
RPC_E_UNEXPECTED
CTL_E_ILLEGALFUNCTIONCALL
CTL_E_OVERFLOW
CTL_E_OUTOFMEMORY
CTL_E_DIVISIONBYZERO
CTL_E_OUTOFSTRINGSPACE
CTL_E_OUTOFSTACKSPACE
CTL_E_BADFILENAMEORNUMBER
CTL_E_FILENOTFOUND
CTL_E_BADFILEMODE
CTL_E_FILEALREADYOPEN
CTL_E_DEVICEIOERROR
CTL_E_FILEALREADYEXISTS
CTL_E_BADRECORDLENGTH
CTL_E_DISKFULL
CTL_E_BADRECORDNUMBER
CTL_E_BADFILENAME
CTL_E_TOOMANYFILES
CTL_E_DEVICEUNAVAILABLE
CTL_E_PERMISSIONDENIED
CTL_E_DISKNOTREADY
CTL_E_PATHFILEACCESSERROR
CTL_E_PATHNOTFOUND
CTL_E_INVALIDPATTERNSTRING
CTL_E_INVALIDUSEOFNULL
CTL_E_INVALIDFILEFORMAT
CTL_E_INVALIDPROPERTYVALUE
CTL_E_INVALIDPROPERTYARRAYINDEX
CTL_E_SETNOTSUPPORTEDATRUNTIME
CTL_E_SETNOTSUPPORTED
CTL_E_NEEDPROPERTYARRAYINDEX
CTL_E_SETNOTPERMITTED
CTL_E_GETNOTSUPPORTEDATRUNTIME
CTL_E_GETNOTSUPPORTED
CTL_E_PROPERTYNOTFOUND
CTL_E_INVALIDCLIPBOARDFORMAT
CTL_E_INVALIDPICTURE
CTL_E_PRINTERERROR
CTL_E_CANTSAVEFILETOTEMP
CTL_E_SEARCHTEXTNOTFOUND
CTL_E_REPLACEMENTSTOOLONG
Unknown exception
ThrowHR: HR = %x
EX_THROW Type = 0x%x HR = 0x%x, line %d
mscorsvw.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
DuplicateTokenEx
SetTokenInformation
RegQueryInfoKeyW
RegCloseKey
ADVAPI32.dll
WerSetFlags
GetCommandLineW
GetCurrentProcess
GetStdHandle
WriteFile
TerminateProcess
GetModuleFileNameW
WaitForMultipleObjects
SetEnvironmentVariableW
GetFileAttributesW
CreateEventW
GetLastError
OutputDebugStringW
SetEvent
CloseHandle
CreateThread
GetWindowsDirectoryW
GetProcAddress
FreeLibrary
GetFileType
DebugBreak
LoadLibraryExW
IsDebuggerPresent
KERNEL32.dll
__CxxFrameHandler3
memmove
_purecall
__C_specific_handler
memset
VCRUNTIME140_CLR0400.dll
freopen
__acrt_iob_func
_wcsicmp
fflush
__stdio_common_vfwprintf
wcscpy_s
wcstoul
__stdio_common_vsnwprintf_s
_wcsnicmp
wcsncpy_s
wcscat_s
_errno
iswspace
strncmp
wcsncmp
__stdio_common_vsnprintf_s
strcpy_s
malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_narrow_winmain_command_line
_initterm
_initterm_e
_set_fmode
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
ucrtbase_clr0400.dll
GetRequestedRuntimeInfo
mscoree.dll
CoAddRefServerProcess
CoReleaseServerProcess
CoUninitialize
CoTaskMemFree
CoMarshalInterface
CreateStreamOnHGlobal
CoInitializeEx
ole32.dll
OLEAUT32.dll
MsgWaitForMultipleObjectsEx
PeekMessageW
DispatchMessageW
LoadStringW
USER32.dll
RegQueryValueExW
EventWrite
RegOpenKeyExW
HeapFree
HeapAlloc
GetProcessHeap
FindFirstFileW
GetEnvironmentVariableW
FindClose
WaitForSingleObject
CreateFileW
MultiByteToWideChar
HeapSetInformation
GetModuleHandleW
RaiseException
GetCPInfo
GetACP
FormatMessageW
LocalFree
SetLastError
GetCurrentThreadId
GetSystemTimeAsFileTime
QueryPerformanceCounter
HeapCreate
TlsSetValue
VirtualProtect
EnterCriticalSection
VirtualFree
ReleaseSemaphore
VirtualAlloc
LeaveCriticalSection
InitializeCriticalSection
CreateMutexW
ReleaseMutex
HeapValidate
WaitForSingleObjectEx
TlsAlloc
ResetEvent
HeapDestroy
DeleteCriticalSection
CreateSemaphoreW
SleepEx
TlsGetValue
TlsFree
VirtualQuery
GetCurrentProcessId
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
InitializeSListHead
GetStartupInfoW
_CxxThrowException
memcpy
.?AVtype_info@@
.PEAVException@@
.PEAVHRException@@
.PEAVOutOfMemoryException@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="mscorsvw" type="win32"></assemblyIdentity><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
\fV5u_|
F{Fy|5{
]o!h[$
gj*|fm
F$Z]&cv
7"!6@Q-^B
z(CFwQ
%:RHU>5{
KH~JKx/
ii6tXN
Z`Q3m"
|O^G{D
K'Mp{,5
Uagw#:&
T)7o7$
3bw-:)
N:Hb%)
r}B)K
4)/KTr*9
tKRv|1
l9"/a{
U3oMxr
wY@pKu
6}RYQXC
+z?x"67
s$"pICP
7Yyw+S
OpW# t
ZJ#2fE
.a.z 8g
+p]#Z\
<E*jgJ
opZ`"4
(tPL7a
t57*[e5
qp@e|t
p]/#U.
oe/h=Fjg
{||2_f
542_]!
l8J@L%
aQd;eT-
^?u5#L
2S?m^>
yExBg`
>o%`O0ROo
P+9z`$
yeXMDx
jgR'~'r
|$#i[v
tyBDv
wX?H`C
C]l?h>
K]<*$:
j*a F.
{lRb={y
5Bro-K
_gj0l)
:]->u
~v%S+X^
+{uV^3
4^'!Q%
S$>oz
&9w7tW
W5Z0 
26q@I|7
nH>@!`
c<@>?7
[S5.J`(
mq?4.R
63,XpG
?iT$J
EA,"@g
yPkns0
lfC!"p
7j$_|<
ILIAw1
[D%/~0p
`[afWL
(/%{ -
gi&_z?
\gWY.[
vw_B#{
;Y#yn
U-x w
9dKm!H
\\u>Be
{LEPw}
w2hjiU
:"}/U>+
l[82-t
_Gz!B_
P;2]!
|V:,h_t
0|SNy*
{MfzS)
d0a+"e
f/n?D`
X&m""s0
sx~gsv
(L<l7
4b`8)RwIH
(h]c[o
Nf` hK0
nUKNZ@
b({x`E
ShMVxem
*aBd{2`g
k:&c&p
f^=UPJ
=]?o{j`
"6Lj|s)~.
fW('My
A[MMu0
#3ko_wz$
lU'a+`
ko=Ap=A
9Vy7Au
%wUrpI
oCEa7#
oh0I~D
maw'*B+qZRT
o2` (Wj
A:Gz$rd
f#Ey0_
Qu#:Qb5
),/V<H
DJR6,S
zXzG>o
g<HZ.Z
&JA_4%
!j>ro)&o
^o'y$Ux
I7ES/Ti
DK 2YwZ
_(((H1
C/;4]{~
?72{jM
n2'U2:{p
(I33mw
T&h`vcd
jnc4O?
vU<)~a
F~A<2_
Xj?p_-
fMm.;_
XJBJGJ
PIU8M<
<VDb''
_X}Fze}
zlcY/h
vBt+M6
zrCi R
|_wSjC
{suc>v9
R0%JrOT
<(U}iy
~FfGI"
!,58L#W
+#{qo?
NV#}qy
'<20m$
$N|iPo]
Y%~$!A
hA}R}
(voj\Nz
@<!HhmK
$TpNYZ
5:KXw&~
4|D@|j
5mR,&d
rk{IV,=
uq~vs{y
Uuq/},+
$/ "s^
ra;vGj
;J7v5(tR
*/<X(nz
M7NQ/{Gk
{Xn}Qo
BYU-v>
Zaw.S8
%#Ff=vRmb<
cP'50IS
!5tqIB
h8q~`kc
"d@2<)
#I R?u
{^*_p!3
tiBTt
CDevj+
kM1vd^[
,2d=E6{
8Y(lyM Ok4sI=
G/4Ku>
XbC<[V
]@>}Gz
7XGsq{
?[bW03
ry/z7I
C^fD}y
5Y+idx
mx{AGx
,3e`]{
]e:,1
<~k6l#
t\%g%!Z
B<-%Rc
H^oa^<t
(#*!fW
^T/p(X
j>.}/=
MfMR(a$
ObFb@WF
M%fEv-
Sa3%%o
jVTf]?
"?#^BGaY
R%`dYC
omS#i"A
TF_#Ie
NaQa_p=CT"
;tc}B'
SIj$yI
cQwOmMWQ
t7N"*>
iykzB\
`QrohO
VxBKeAxC
c5l~T,
9:_UQD
rEo91M
aT8ZL'|jJ
7`4nmn
H19wL
Eug&Y`
ukux-%
G0`'(q
P!jb[$n
MR)SLM
0r'\Ch
uBNxDE
kZlf|2c
%~mv,A
&HgdmJ
8iHz\4
}zD\\k
$gBl@5u7
x/tJZ/pD
&/qKx>
@8={C>
QLr`ak
0BpEPI<
M"Q3~Y
]"KF*[z
>=+<v=
6R<Mjx
9|@\P|;
6/)$9O
Sik,5}
{4k]B|
j^A_E6
MSKSw=
m@e}#N
{ng. A}f
k<81!A
5}r]"
n?u3&@
_H<>fv
ha9dUYH^6g+
]kYRRm
DDfb)z~Y
kz,A|A8
ig*j>el'
+n[BiUAFz|
m:{HwP
7Qbav&
;0>{]#
')R9eP
w1< F$
"iFZms:g
tu/ecPy
%j|y4;
fj`u<9
uSvz!u
?w8oP#w
2XJ,sF 1
=&f\|"l
+V{<ao
,Yvr[@
ItzoT}A
H]wI~$
yc$yp"
w*3&6^
pSNhHE
'\){H<
t)?<t2
DVjmYj
*)(j_f
y%t)|x
\"/o`n
&?&v"@-
Ck2_G&
#V!;SG
GT=HXs
fDz 'p
odY"?b
UT[~#\
g$xmL!
L4SH1/F
pvybQ'g
d-?_+d
".6K(x
ha+%7Z
C)L@/6
ym9SnK
0gFO+3J
5]C#5F
3o~*q}
kio fY
4iU+]>
SId{)G
/t)\iYW
9psom}
;IPlO3
Wnu"T
j%^E\-
Pf/'p}
{Wd,)`
~;.;8l
Q8\9W*m
QWu`')V
vTGD_l,
XyRfY{
d\ ^Dc~
g/sud /
Kb-Dpf&
p@)%|,
#+^ZbGh
oX%`?]
Db(JbT
T?)ZMV
43Bja/
x \Q-+
:0D4@H
6NU(l?
U5;yoJ
Xka7WG
Qx\/iD3
i.nAml`D
-~5}ui
}?)}K7Q?
/2?uw+e
d[.2DS
zI@0<O
6)&csw.
#z/8W=;2
A+<.4eH
HEC]|K
D:iC3pz
ZkkQ9
l2Rm'oe
c* ~A^
p+}'\G
[8EtwJu%
f+*dk.
UaTy@7m
qaFQr7u
H?]OY"U
NW4fc6Bt
>j?WKZ
#d|qKQ
={iQn$"'l
-Pf^'0\1
(h4Zs]
+@Q}pBsx
}"n{LB
&@&./1oM
0S@%@K
[Q@[`Pv
ylf@|U
-[~+2U
{%TB=Mc
n@'lE<
54j+Jn{
Z_2v<!b0
r&AH.y
b3~e>8
oxL[+
p`A8fG5W
hvzP;:t
_<rOlu4
`a$9;G
e^{-9
$;i:t@
{Y+1^
qr\Yhs
KynN-
\gy\fz_:
fcYTD}-
j^mNjo
HzI)v)&(
3>U5jc
n,*,D,d,
3d\mAD
{}ppjG
kOD$&_
{bOD%'
$rj)-u
4v2KVn{
XWjlyB
zA/vAe
i&5.1S5
nz/psO
*%?n5c
bm)p2{
DmO8kC
l]iuX8
F3)t=';u
zduG'3
oIlu=m`
]MQWSs7
{rzf7|>
otG'<r$
Cnlh]>
{bj8?6G
<$,/<t
xo`%v<T}
zreBV=\
@3G~OC
dyBg6@
=A$&DR&
<lkq:Z
sbM{7
vuzIC6
k8R9Hc
^.VuIy{f*g
E*qly>}8
`k{xBaPE
dUf:eQ
*F#]Juo
3"k_p8?
vOs'y9
{p3Ag:q
c4K!73
bN`$>?
pEZ'lH
A.~OE]
h'@ :0
j|rJbxd7
TsPBs-
&q1g{8
Y}/$ac
Nu,Ey(
" 53AI/
HBAPd<
UBZtQM
Bn)^!s
o@n<4I
Z![Q$W
0r;<dch"
{ST*0)C
dM\,y,
DXXH*m6>y
dNd7b{
V9^C O![f
Mf>pg;3E/
YN<*$f
E(\"+Q
]Z7Pwx
%_bvi.q{t&
?Z)@v=
"@'Inf
&ZEbR,
<iOL=r
>r,scil~M
N8w#oe|
97*m+L
#nk3fk>
[Im5&Da
cPx5#4h
`bE=,@c
Ii3EO#
s$>5;]
CICXbcR
bDqp&*
!"yIFZB
.+HpF9
c*pyo@qq
i|EH=|:e
+=+^o-
6.+,u fN8
/MhDV}q
c(ZC0?
g>[GY*
!Di`U$m
$Ud9Zw
Ep0l~(
F}g^n;
]uU3Y
8tM]"or
x|Jm@H
Vx?Atv
DI(j*)
sj,t91/
@);%{&f=
Ot!(#6*
/8Edxf
*DMifc
Wxld^q"
q(_Ie%B
GV_&xo*
UcDC8
\@jS|3QYC
}ho(;PZ
n*0Tjv&
v8B2[}
F(@DmqM,
g+< 8H3
:sCmY{b
SNk7jU
6nG}ES.
NfD?[$
]H=7-7
cWEr=X
)m))c!
PtMoXu
,z2@"1
tSs6P:
x=EIJ#e
zx>R%3(
xqGeP/>`
If{|8/
N=5C.3
Y~v]'U
0.|x)/
$k&z4^
v^8{5}
v;zdg=
j=6lr,
'n?EMs1&F;
t~k%2+
G&>q/c:W
D{\n{{zgq
DT+ Wvrm
~P!1'=
Ol+dVf!
lKWN:c
e3A}?G
Ai/0Ei9
v8?eOg
WAO+c+
2SETLbn
>gcYYX
}vQ-/p
8x '*)
;NkxP.
{+yF%\2+
bq73@el
_UVR&6~
;C_,&kc
8Z0>{De
3(gGzd
;gZ~1'{S
!IYOni
?1 7%y/
a;o8W*n
.d-Zk{`
.F|ScK
gF2|R;ONu
n!x.j`
tRQ#t.
/e^v9-
vDU'!>
_UTAQi
Ru5D(lb
n28c\oc
DDD{[f
}R]liO
GsHBDK
J*mS*(
76}Y-s
0z!VH2k_QM<`
ucnbR{BMv
RG% h|
Br|c|u,v
ljk:hDq
85MP-!
;}XH-Q
-F0o7HK
2xNhgs
^%9YJF
NG'H__V
F<6a|oK
O[}DEy{UT8
4Gohu&
?.f)UV
L6;!@7
jh<TX`
*+jF":&
QdDt8}
[4=pDBq8
(,m{Z&
p9v)5G
F9%U~jv8%
J8`cXl
s#rb\Ok
Ca|~d
uXmDS
=@Udne
wKG/ p*
TxE^kc'?
*onHE
G~3D>d^d}=
;Ru3/1V:
M/(}%W
\4n3mp2
VA5|lZo
Pch98.F
d 9?k8=)
hkaly!
W8 mv?
$KBf;3
)4F7Dh
v2P+0LuC
R/+=,_?m
<}WT@-
"%8Wa/
HZ:z>
:o*w^*
2'Wt[)
tqI38d
8YR+{"
>Qmh p
9wC?E@
Q<^NF{l
^aZ=Xy
3aDG?3"
v){[eX
&{h'na
G_8=|!u
/&Tv0`
I6>`Dv
~iOq=a
v~#>>\(
90,Px#
/t}:$KG
C It+O'!J|Ct
2IU!ph
V{,)t1
-6%Uz-
]<l7P\
OED/Z\
A@/$)}
a#i{bl
_.8q|<>3
=cxQ*{i
$K<^)F
_#MCD|
|[It_{
|#6v&Q
'.r#%r/W
oOlD+R
3u@>YO
$HTp)G
b^'YkcP
p5u)zK'
=p[t#
x8J:(&U
gZH>s\O
%Fils
"n'IvL
D<i0`a
c4wl,7
EpA{#f
7r:=b>
v/2*E0j&t7Nk@
8U[<9,1;
=}Fs;,
(#NoX$yS)kt
,5rF~'
`V$k#'
t/etBM|
q''q:"
= >wf<
O`+Vx1
D<$RW3
&vA|`Dh,
Po4;Lv
NZw^?>
2X|rW
F&N'-4VD
J2oyk+'q^
ks~V;Ek
wCSt1oY
<zu1,+H.
MVb$?z
v7,a's
+0(Df'}13
W&'GlI8j >
CJ_0:'yW
kE^8\*
nb|Vv+
n=Fr3Y
:tl:V:
K"hL^[
9yK)?^
mp4%*q
XG^@EK
QM#yS0
0Kyo4h
e]/tQ!^
\R\.oK
/<Tj[%
D67Rw.r
H|_s:
>139-
tfd!wO8U
VSQh]|
W!n1[N
5L:v}N
es\iriah(
DLin(Qb
#MOjgv
`!a{O`
yD"{V0
h`y~fs
"?+W,I
cKG/ci
f(.Y?R
cfNYP`
uW0#Hn
Yt$e]r
Q>,bi/
4v`0[S
4aM&Kv
W6='/d3
c6/jpr
e?~a1$
2O|rY
txk~Xy4
AEF*sk
/UTS10k'
}?YX5V
b(EkNC14Mg*.
_^I!3eZO
pzS$`W
9gN~|0ub
<b7\SC
{`~Q,k
(CpfLg
8ev@`mF
+4,fS
6HI4MO<
?]"z;7
v(ekWbiL
paKcYy
Y^SJlH@
@l-kdm
?JC$v~Z$J
*st9b>
otG'<r+`
5TGPtV
z9N%y>4
|{zyxwvu
dcba`_
"! W+2
`H4~LG
hulq+g&
NLw7Z)8
U?#avF
v@7,CzpQ%
qov?Jl
WnuHi|
"K?nPYL
;wTqLG,
y^bH~R
AJ{~qN
seKUf}
Qs`;i
^(}gN
)**^6x
B=n$w<
YFc^!{
["Q;^"\W
([M#6g
yu%0fA_
Ss{`p3
s g6t<E
ct[#Tp
*pus$syk3
.LF%q@
2Q\A$.R
m )84u
f;re}ep
3GcRM:
k|f%l+
5"xq^
8>W,=5
1B%h!cT
N*Y5d:wxz
-xtXp"
}Lb 0{
Z9cC]|
2Vhn&0
M "$C
@ckk'k$^
)wd]C=
gM&dI[
<#h`n#R
XgVaOY
};6la;"
U0M:9)
8o4*f)
2LJVV2
qR|ys(R
oHtVHR
O nXpO
R]rGIp
zR+xlW
nkTPw&Ki_
mCTLd)
_QOQ?Q/Q
s@W^O^
\w\O\G
7WZOZ.
GR?R7R/R
QwQoQ8
PwPoPK
N#&-6_
W_O_G_?_
S&sHZ(
!,ycoG
p^fcNsc
u[9bf#
(=~lSH
E[[?Bln
nz#}sO
/eqiQW
'<r+$5
kysLz
\(F{l=>_
5G4,jE
&-j&5{
qwLbG$Y
_sOQEH=
bPxd=t
|GKvH1.
53X$o{
APE0^V
~;wmtG|a-u'
wvXq{N
[3?&)`33
nOD$';
?6!K'Cbl
.$g%IFk
ot3FI-$
g=x$w#
otG'<r+f
otG'<r+f
otG'<r+f
otG'<r+f
PQRSUVWAPAQARASATAUAVAWUH
hDvH1.
]A_A^A]A\A[AZAYAX_^][ZYX
user32
<null>
**** MessageBox invoked, title '%s' ****
********
v4.0.0
\fusion.localgac
SOFTWARE\Microsoft\.NetFramework
\v2.0.50727
\NGENService
\State
ngenrootstorelock.dat
kernel32.dll
CorSvcBindToWorker
-StartupEvent
-InterruptEvent
-NGENProcess
-LocalAppData
-Package
-Comment
$mscorsvc.dll
Microsoft .NET Runtime Optimization Service
-silent
Failed to retrieve Microsoft .NET Runtime Optimization Service interface
Failed to install Microsoft .NET Runtime Optimization Service
Microsoft .NET Runtime Optimization Service has been installed
Failed to uninstall Microsoft .NET Runtime Optimization Service
Microsoft .NET Runtime Optimization Service has been uninstalled
-private
-startpaused
clr_optimization_
Attempting to repair the framework
Aborting repair due to error %u from WTSEnumerateSessions
Found active session %u
No active session found. Waiting...
Aborting repair due to service shutdown.
Session %u has become active.
Aborting repair due to unexpected wait status %u
Error getting current process token, error %d
Error duplicating current process token, error %d
Error changing token session ID, error %d
Microsoft.NET\NETFXRepair.exe
/OSUpgraded
Unable to create repair process, error %d
Created repair process in session %d, process ID %d
Set service status to %d
Service control handler op %u, event type %u
Calling StartServiceCtrlDispatcher
StartServiceCtrlDispatcher failed with error %d. Will try slow path
StartServiceCtrlDispatcher done, exiting
\ndpsetup.bat
Install
SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client
\NGenService
\Roots
WorkPending
PendingUpdate
SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN64\Default
SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN64\Default
FastStartupCheck(isPrivateRuntime=%d)
COMPLUS_DEFAULTVERSION
Unable to set COMPLUS_DEFAULTVERSION in a private runtime, falling back to slow path
Framework needs repair
Framework repair allowed
ngenservicelock.dat
Unable to acquire NGen Service lock, falling back to slow path
Unable to acquire root store lock, falling back to slow path
NGen Service has no work
mscoree.dll
advapi32.dll
Wtsapi32.dll
shell32.dll
retail
COMPLUS
PPPPPPPPPPPP
PP
00000000000000000000000000000000000000
00000000000000000000000000000000000000
JJVVVVdd
JJVVVVdd
APPDOMAIN_MANAGER_ASM
APPDOMAIN_MANAGER_TYPE
appDomainManagerAssembly
appDomainManagerType
TargetFrameworkMoniker
AppContextSwitchOverrides
designerNamespaceResolution
CompatSortNLSVersion
legacyCorruptedStateExceptionsPolicy
GCNumaAware
GCCpuGroup
UseRyuJIT
MD_UseMinimalDeltas
NGEN_USE_PRIVATE_STORE
NGENBreakOnWorker
RegistryRoot
AssemblyPath
AssemblyPath2
NicPath
NgenAllowOutput
NGenServiceDebugLog
ProcessNameFormat
COR_ENABLE_PROFILING
CORECLR_ENABLE_PROFILING
ProfAPI_ProfilerCompatibilitySetting
Thread_UseAllCpuGroups
ZapSet
AlwaysReadHKCRForCLSIDs
DefaultVersion
shadowCopyVerifyByTimestamp
DisableConfigCache
EnableInternetHREFexes
InstallRoot
Version
NETFX.
0x%.8X
COMPlus_
Software\Microsoft\.NETFramework
Software\Microsoft\Fusion
SOFTWARE\
Wow6432Node\
Microsoft\.NETFramework\Policy
mscorrc.dll
v4.0.30319
az-Latn-AZ
zh-Hans
es-ES_tradnl
tg-Cyrl-TJ
hsb-DE
uz-Latn-UZ
kok-IN
syr-SY
iu-Cans-CA
fil-PH
ha-Latn-NG
quz-BO
nso-ZA
arn-CL
moh-CA
gsw-FR
sah-RU
qut-GT
prs-AF
qps-ploc
qps-ploca
sr-Latn-CS
az-Cyrl-AZ
dsb-DE
uz-Cyrl-UZ
mn-Mong-CN
iu-Latn-CA
tzm-Latn-DZ
quz-EC
qps-plocm
sr-Cyrl-CS
quz-PE
smj-NO
bs-Latn-BA
smj-SE
sr-Latn-BA
sma-NO
sr-Cyrl-BA
sma-SE
bs-Cyrl-BA
sms-FI
en-029
smn-FI
zh-Hant
x-IV_mathan
de-DE_phoneb
hu-HU_technl
ka-GE_modern
zh-CN_stroke
zh-SG_stroke
zh-MO_stroke
zh-TW_pronun
ja-JP_radstr
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
.NET Runtime Optimization Service
FileVersion
4.8.3761.0 built by: NET48REL1
InternalName
mscorsvw.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
mscorsvw.exe
ProductName
Microsoft
.NET Framework
ProductVersion
4.8.3761.0
Comments
Flavor=Retail
PrivateBuild
DDBLD200D
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CMC Clean
CAT-QuickHeal W32.Expiro.R3
Skyhigh BehavesLike.Win64.Generic.tt
ALYac Win64.Expiro.Gen.7
Cylance Unsafe
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Clean
K7GW Virus ( 0058d9c51 )
K7AntiVirus Virus ( 0058d9c51 )
huorong Virus/W64.Expiro.r
Baidu Clean
VirIT Win64.Expiro.AJ
Paloalto Clean
Symantec W64.Xpiro.J!dam
tehtris Clean
ESET-NOD32 a variant of Win64/Expiro.DP
APEX Malicious
Avast Win64:Expiro-AJ [Inf]
ClamAV Clean
Kaspersky Virus.Win64.Moiva.a
BitDefender Win64.Expiro.Gen.7
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Win64.Expiro.Gen.7
Tencent Virus.Win64.VirMoiva.a
Sophos W64/Moiva-B
DrWeb Win32.Expiro.153
VIPRE Win64.Expiro.Gen.7
TrendMicro Virus.Win64.EXPIRO.SMAJC
McAfeeD ti!BF74ABAE0B65
Trapmine Clean
CTX exe.unknown.expiro
Emsisoft Win64.Expiro.Gen.7 (B)
Ikarus Virus.Win64.Expiro
GData Win64.Expiro.Gen.7
Jiangmin Clean
Webroot Clean
Varist W64/Expiro.AR.gen!Eldorado
Avira W32/Infector.Gen
Antiy-AVL Virus/Win64.Expiro.ce
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Win64.Expiro.Gen.7
SUPERAntiSpyware Clean
ZoneAlarm W64/Moiva-B
Microsoft Virus:Win64/Expiro.DD!MTB
Google Detected
AhnLab-V3 Virus/Win.Expiro.X2221
Acronis suspicious
VBA32 Clean
TACHYON Virus/W64.Movia
Malwarebytes Virus.M0yv
Panda W64/Moyv.A
Zoner Clean
TrendMicro-HouseCall Virus.Win64.EXPIRO.SMAJC
Rising Virus.Expiro!1.A140 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet W64/Expiro.CV
AVG Win64:Expiro-AJ [Inf]
DeepInstinct MALICIOUS
alibabacloud Clean
IRMA Signature
Trend Micro SProtect (Linux) Virus.Win64.EXPIRO.SMAJC
Avast Core Security (Linux) Win64:Expiro-AJ [Inf]
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) W64/Moiva-B
Bitdefender Antivirus (Linux) Win64.Expiro.Gen.7
G Data Antivirus (Windows) Virus: Win64.Expiro.Gen.7 (Engine A)
WithSecure (Linux) Malware.W32/Infector.Gen
ESET Security (Windows) a variant of Win64/Expiro.DP virus
DrWeb Antivirus (Linux) Win32.Expiro.153
ClamAV (Linux) Clean
eScan Antivirus (Linux) Win64.Expiro.Gen.7(DB)
Emsisoft Commandline Scanner (Windows) Win64.Expiro.Gen.7 (B)
Cuckoo

We're processing your submission... This could take a few seconds.