Static | ZeroBOX

PE Compile Time

2021-06-21 10:40:28

PE Imphash

389b894eef03c765829f9c2b2a749a9c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0020b3e8 0x000b9e00 7.93693643258
.itext 0x0020d000 0x000026a8 0x00001400 7.55322724698
.data 0x00210000 0x0000c09c 0x00006c00 7.76492412865
.bss 0x0021d000 0x00006a98 0x00000000 0.0
.idata 0x00224000 0x00003a8e 0x00003c00 0.0
.didata 0x00228000 0x00000a96 0x00000c00 3.89274614579
.edata 0x00229000 0x0000009c 0x00000200 1.93048701979
.tls 0x0022a000 0x00000048 0x00000000 0.0
.rdata 0x0022b000 0x0000005c 0x00000200 1.35686692419
.reloc 0x0022c000 0x0002d9c0 0x0001a600 7.87356660355
.rsrc 0x0025a000 0x0001da00 0x0001da00 6.80698632888
.debug 0x00278000 0x007ee000 0x001e1400 7.83457030407
.UPX0 0x00a66000 0x00505000 0x00005000 5.41099273859
.UPX1 0x00f6b000 0x0006c200 0x00065000 6.61839844807

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0025b850 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0025d3d8 0x000000e0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00271614 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0027654c 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00276f4c 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x00276f4c 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x00276f4c 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x00276f4c 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00277100 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00277114 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x002771a8 0x000001e4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0027738c 0x000005d9 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF, LF line terminators

Imports

Library oleaut32.dll:
0xe6905f SysFreeString
0xe69063 SysReAllocStringLen
0xe69067 SysAllocStringLen
Library advapi32.dll:
0xe6906f RegQueryValueExW
0xe69073 RegOpenKeyExW
0xe69077 RegCloseKey
Library user32.dll:
0xe6907f CharNextW
0xe69083 LoadStringW
Library kernel32.dll:
0xe6908b Sleep
0xe6908f VirtualFree
0xe69093 VirtualAlloc
0xe69097 lstrlenW
0xe6909b VirtualQuery
0xe690a3 GetTickCount
0xe690a7 GetSystemInfo
0xe690ab GetVersion
0xe690af CompareStringW
0xe690b3 IsValidLocale
0xe690b7 SetThreadLocale
0xe690c3 GetLocaleInfoW
0xe690c7 WideCharToMultiByte
0xe690cb MultiByteToWideChar
0xe690cf GetACP
0xe690d3 LoadLibraryExW
0xe690d7 GetStartupInfoW
0xe690db GetProcAddress
0xe690df GetModuleHandleW
0xe690e3 GetModuleFileNameW
0xe690e7 GetCommandLineW
0xe690eb FreeLibrary
0xe690ef GetLastError
0xe690f7 RtlUnwind
0xe690fb RaiseException
0xe690ff ExitProcess
0xe69103 ExitThread
0xe69107 SwitchToThread
0xe6910b GetCurrentThreadId
0xe6910f CreateThread
0xe69123 FindFirstFileW
0xe69127 FindClose
0xe69133 WriteFile
0xe69137 GetStdHandle
0xe6913b CloseHandle
Library kernel32.dll:
0xe69143 GetProcAddress
0xe69147 RaiseException
0xe6914b LoadLibraryA
0xe6914f GetLastError
0xe69153 TlsSetValue
0xe69157 TlsGetValue
0xe6915b LocalFree
0xe6915f LocalAlloc
0xe69163 GetModuleHandleW
0xe69167 FreeLibrary
Library user32.dll:
0xe6916f SetClassLongW
0xe69173 GetClassLongW
0xe69177 SetWindowLongW
0xe6917b GetWindowLongW
0xe6917f CreateWindowExW
0xe69183 WindowFromPoint
0xe69187 WaitMessage
0xe6918b UpdateWindow
0xe6918f UnregisterClassW
0xe69193 UnhookWindowsHookEx
0xe69197 TranslateMessage
0xe6919f TrackPopupMenu
0xe691a7 ShowWindow
0xe691ab ShowScrollBar
0xe691af ShowOwnedPopups
0xe691b3 ShowCaret
0xe691b7 SetWindowRgn
0xe691bb SetWindowsHookExW
0xe691bf SetWindowTextW
0xe691c3 SetWindowPos
0xe691c7 SetWindowPlacement
0xe691cb SetTimer
0xe691cf SetScrollRange
0xe691d3 SetScrollPos
0xe691d7 SetScrollInfo
0xe691db SetRect
0xe691df SetPropW
0xe691e3 SetParent
0xe691e7 SetMenuItemInfoW
0xe691eb SetMenu
0xe691ef SetForegroundWindow
0xe691f3 SetFocus
0xe691f7 SetCursorPos
0xe691fb SetCursor
0xe691ff SetClipboardData
0xe69203 SetCapture
0xe69207 SetActiveWindow
0xe6920b SendMessageA
0xe6920f SendMessageW
0xe69213 ScrollWindow
0xe69217 ScreenToClient
0xe6921b RemovePropW
0xe6921f RemoveMenu
0xe69223 ReleaseDC
0xe69227 ReleaseCapture
0xe69233 RegisterClassW
0xe69237 RedrawWindow
0xe6923b PostQuitMessage
0xe6923f PostMessageW
0xe69243 PeekMessageA
0xe69247 PeekMessageW
0xe6924b OpenClipboard
0xe6924f OemToCharBuffA
0xe69253 OemToCharA
0xe6925f MessageBoxW
0xe69263 MessageBeep
0xe69267 MapWindowPoints
0xe6926b MapVirtualKeyW
0xe6926f LoadStringW
0xe69273 LoadKeyboardLayoutW
0xe69277 LoadImageW
0xe6927b LoadIconW
0xe6927f LoadCursorW
0xe69283 LoadBitmapW
0xe69287 KillTimer
0xe6928b IsZoomed
0xe6928f IsWindowVisible
0xe69293 IsWindowUnicode
0xe69297 IsWindowEnabled
0xe6929b IsWindow
0xe6929f IsIconic
0xe692a3 IsDialogMessageA
0xe692a7 IsDialogMessageW
0xe692ab IsChild
0xe692af InvalidateRect
0xe692b3 InsertMenuItemW
0xe692b7 InsertMenuW
0xe692bb HideCaret
0xe692c3 GetWindowTextW
0xe692c7 GetWindowRect
0xe692cb GetWindowPlacement
0xe692cf GetWindowDC
0xe692d3 GetTopWindow
0xe692d7 GetSystemMetrics
0xe692db GetSystemMenu
0xe692df GetSysColorBrush
0xe692e3 GetSysColor
0xe692e7 GetSubMenu
0xe692eb GetScrollRange
0xe692ef GetScrollPos
0xe692f3 GetScrollInfo
0xe692f7 GetPropW
0xe692fb GetParent
0xe692ff GetWindow
0xe69303 GetMessagePos
0xe69307 GetMessageExtraInfo
0xe6930b GetMenuStringW
0xe6930f GetMenuState
0xe69313 GetMenuItemInfoW
0xe69317 GetMenuItemID
0xe6931b GetMenuItemCount
0xe6931f GetMenu
0xe69323 GetLastActivePopup
0xe69327 GetKeyboardState
0xe69333 GetKeyboardLayout
0xe69337 GetKeyState
0xe6933b GetKeyNameTextW
0xe6933f GetIconInfo
0xe69343 GetForegroundWindow
0xe69347 GetFocus
0xe6934b GetDlgCtrlID
0xe6934f GetDesktopWindow
0xe69353 GetDCEx
0xe69357 GetDC
0xe6935b GetCursorPos
0xe6935f GetCursor
0xe69363 GetClipboardData
0xe69367 GetClientRect
0xe6936b GetClassNameW
0xe6936f GetClassInfoExW
0xe69373 GetClassInfoW
0xe69377 GetCapture
0xe6937b GetActiveWindow
0xe6937f FrameRect
0xe69383 FindWindowExW
0xe69387 FindWindowW
0xe6938b FillRect
0xe6938f EnumWindows
0xe69393 EnumThreadWindows
0xe69397 EnumChildWindows
0xe6939b EndPaint
0xe6939f EndMenu
0xe693a3 EnableWindow
0xe693a7 EnableScrollBar
0xe693ab EnableMenuItem
0xe693af EmptyClipboard
0xe693b3 DrawTextExW
0xe693b7 DrawTextW
0xe693bb DrawMenuBar
0xe693bf DrawIconEx
0xe693c3 DrawIcon
0xe693c7 DrawFrameControl
0xe693cb DrawFocusRect
0xe693cf DrawEdge
0xe693d3 DispatchMessageA
0xe693d7 DispatchMessageW
0xe693db DestroyWindow
0xe693df DestroyMenu
0xe693e3 DestroyIcon
0xe693e7 DestroyCursor
0xe693eb DeleteMenu
0xe693ef DefWindowProcW
0xe693f3 DefMDIChildProcW
0xe693f7 DefFrameProcW
0xe693fb CreatePopupMenu
0xe693ff CreateMenu
0xe69403 CreateIcon
0xe6940b CopyImage
0xe6940f CopyIcon
0xe69413 CloseClipboard
0xe69417 ClientToScreen
0xe6941b CheckMenuItem
0xe6941f CharUpperBuffW
0xe69423 CharUpperW
0xe69427 CharNextW
0xe6942b CharLowerBuffW
0xe6942f CharLowerW
0xe69433 CallWindowProcW
0xe69437 CallNextHookEx
0xe6943b BeginPaint
0xe6943f CharLowerBuffA
0xe69443 CharUpperBuffA
0xe69447 CharToOemBuffA
0xe6944b CharToOemA
0xe6944f AdjustWindowRectEx
Library gdi32.dll:
0xe6945b UnrealizeObject
0xe6945f StretchDIBits
0xe69463 StretchBlt
0xe69467 StartPage
0xe6946b StartDocW
0xe6946f SetWindowOrgEx
0xe69473 SetWinMetaFileBits
0xe69477 SetViewportOrgEx
0xe6947b SetTextColor
0xe6947f SetStretchBltMode
0xe69483 SetRectRgn
0xe69487 SetROP2
0xe6948b SetPixel
0xe6948f SetEnhMetaFileBits
0xe69493 SetDIBits
0xe69497 SetDIBColorTable
0xe6949b SetBrushOrgEx
0xe6949f SetBkMode
0xe694a3 SetBkColor
0xe694a7 SetAbortProc
0xe694ab SelectPalette
0xe694af SelectObject
0xe694b3 SaveDC
0xe694b7 RoundRect
0xe694bb RestoreDC
0xe694bf Rectangle
0xe694c3 RectVisible
0xe694c7 RealizePalette
0xe694cb Polyline
0xe694cf Polygon
0xe694d3 PolyBezierTo
0xe694d7 PolyBezier
0xe694db PlayEnhMetaFile
0xe694df Pie
0xe694e3 PatBlt
0xe694e7 MoveToEx
0xe694eb MaskBlt
0xe694ef LineTo
0xe694f3 IntersectClipRect
0xe694f7 GetWindowOrgEx
0xe694fb GetWinMetaFileBits
0xe694ff GetTextMetricsW
0xe69503 GetTextExtentPointW
0xe6950f GetStretchBltMode
0xe69513 GetStockObject
0xe69517 GetRgnBox
0xe6951b GetPixel
0xe6951f GetPaletteEntries
0xe69523 GetObjectW
0xe69533 GetEnhMetaFileBits
0xe69537 GetDeviceCaps
0xe6953b GetDIBits
0xe6953f GetDIBColorTable
0xe69547 GetClipBox
0xe6954b GetBrushOrgEx
0xe6954f GetBitmapBits
0xe69553 GdiFlush
0xe69557 FrameRgn
0xe6955b ExtTextOutW
0xe6955f ExtFloodFill
0xe69563 ExcludeClipRect
0xe69567 EnumFontsW
0xe6956b EnumFontFamiliesExW
0xe6956f EndPage
0xe69573 EndDoc
0xe69577 Ellipse
0xe6957b DeleteObject
0xe6957f DeleteEnhMetaFile
0xe69583 DeleteDC
0xe69587 CreateSolidBrush
0xe6958b CreateRectRgn
0xe6958f CreatePenIndirect
0xe69593 CreatePalette
0xe69597 CreateICW
0xe6959f CreateFontIndirectW
0xe695a3 CreateDIBitmap
0xe695a7 CreateDIBSection
0xe695ab CreateDCW
0xe695af CreateCompatibleDC
0xe695b7 CreateBrushIndirect
0xe695bb CreateBitmap
0xe695bf CopyEnhMetaFileW
0xe695c3 Chord
0xe695c7 BitBlt
0xe695cb ArcTo
0xe695cf Arc
0xe695d3 AngleArc
0xe695d7 AbortDoc
Library version.dll:
0xe695df VerQueryValueW
0xe695e7 GetFileVersionInfoW
Library kernel32.dll:
0xe695ef WriteFile
0xe695f3 WideCharToMultiByte
0xe695f7 WaitForSingleObject
0xe695ff VirtualQueryEx
0xe69603 VirtualQuery
0xe69607 VirtualProtect
0xe6960b VirtualFree
0xe6960f VirtualAlloc
0xe69613 VerSetConditionMask
0xe69617 VerifyVersionInfoW
0xe6961b UnmapViewOfFile
0xe69623 SwitchToThread
0xe69627 SuspendThread
0xe6962b Sleep
0xe6962f SizeofResource
0xe69633 SetVolumeLabelW
0xe69637 SetThreadPriority
0xe6963b SetThreadLocale
0xe6963f SetLastError
0xe69643 SetFileTime
0xe69647 SetFilePointer
0xe6964b SetFileAttributesW
0xe6964f SetEvent
0xe69653 SetErrorMode
0xe69657 SetEndOfFile
0xe6965b ResumeThread
0xe6965f ResetEvent
0xe69663 RemoveDirectoryW
0xe69667 ReadFile
0xe6966b RaiseException
0xe69677 QueryDosDeviceW
0xe6967b IsDebuggerPresent
0xe6967f MulDiv
0xe69683 MoveFileW
0xe69687 MapViewOfFile
0xe6968b LockResource
0xe6968f LocalFree
0xe69697 LoadResource
0xe6969b LoadLibraryW
0xe696a3 IsValidLocale
0xe696ab HeapSize
0xe696af HeapFree
0xe696b3 HeapDestroy
0xe696b7 HeapCreate
0xe696bb HeapAlloc
0xe696bf GlobalUnlock
0xe696c3 GlobalMemoryStatus
0xe696c7 GlobalLock
0xe696cb GlobalFree
0xe696cf GlobalFindAtomW
0xe696d3 GlobalDeleteAtom
0xe696d7 GlobalAlloc
0xe696db GlobalAddAtomW
0xe696e3 GetVersionExW
0xe696e7 GetVersion
0xe696eb GetUserDefaultLCID
0xe696ef GetTickCount
0xe696f3 GetThreadPriority
0xe696f7 GetThreadLocale
0xe696fb GetTempPathW
0xe696ff GetTempFileNameW
0xe69703 GetStdHandle
0xe69707 GetProcAddress
0xe6970b GetModuleHandleW
0xe6970f GetModuleFileNameW
0xe69717 GetLocaleInfoW
0xe6971b GetLocalTime
0xe6971f GetLastError
0xe69723 GetFullPathNameW
0xe69727 GetFileSize
0xe6972f GetFileAttributesW
0xe69733 GetExitCodeThread
0xe69737 GetDriveTypeW
0xe6973b GetDiskFreeSpaceW
0xe6973f GetDateFormatW
0xe69743 GetCurrentThreadId
0xe69747 GetCurrentThread
0xe6974b GetCurrentProcessId
0xe6974f GetCurrentProcess
0xe69753 GetCPInfoExW
0xe69757 GetCPInfo
0xe6975b GetACP
0xe6975f FreeResource
0xe69763 FreeLibrary
0xe69767 FormatMessageW
0xe6976b FlushFileBuffers
0xe6976f FindResourceW
0xe69773 FindNextFileW
0xe69777 FindFirstFileW
0xe6977b FindClose
0xe69787 EnumSystemLocalesW
0xe6978b EnumResourceNamesW
0xe6978f EnumCalendarInfoW
0xe6979b DeleteFileW
0xe697a3 CreateThread
0xe697a7 CreateMutexW
0xe697ab CreateFileMappingW
0xe697af CreateFileW
0xe697b3 CreateEventW
0xe697b7 CreateDirectoryW
0xe697bb CopyFileW
0xe697bf CompareStringW
0xe697c3 CloseHandle
Library advapi32.dll:
0xe697cb RegUnLoadKeyW
0xe697cf RegSetValueExW
0xe697d3 RegSaveKeyW
0xe697d7 RegRestoreKeyW
0xe697db RegReplaceKeyW
0xe697df RegQueryValueExW
0xe697e3 RegQueryInfoKeyW
0xe697e7 RegOpenKeyExW
0xe697eb RegLoadKeyW
0xe697ef RegFlushKey
0xe697f3 RegEnumValueW
0xe697f7 RegEnumKeyExW
0xe697fb RegDeleteValueW
0xe697ff RegDeleteKeyW
0xe69803 RegCreateKeyExW
0xe69807 RegConnectRegistryW
0xe6980b RegCloseKey
Library kernel32.dll:
0xe69813 Sleep
Library netapi32.dll:
0xe6981b NetApiBufferFree
0xe6981f NetWkstaGetInfo
Library oleaut32.dll:
0xe69827 SafeArrayPtrOfIndex
0xe6982b SafeArrayGetUBound
0xe6982f SafeArrayGetLBound
0xe69833 SafeArrayCreate
0xe69837 VariantChangeType
0xe6983b VariantCopy
0xe6983f VariantClear
0xe69843 VariantInit
Library oleaut32.dll:
0xe6984b GetErrorInfo
0xe6984f SysFreeString
Library ole32.dll:
0xe69857 OleUninitialize
0xe6985b OleInitialize
0xe6985f CoTaskMemFree
0xe69863 CoTaskMemAlloc
0xe69867 CoCreateInstance
0xe6986b CoUninitialize
0xe6986f CoInitialize
0xe69873 IsEqualGUID
Library comctl32.dll:
0xe6987b InitializeFlatSB
0xe69883 FlatSB_SetScrollPos
0xe6988b FlatSB_GetScrollPos
0xe69893 _TrackMouseEvent
0xe698a3 ImageList_Write
0xe698a7 ImageList_Read
0xe698b3 ImageList_DragMove
0xe698b7 ImageList_DragLeave
0xe698bb ImageList_DragEnter
0xe698bf ImageList_EndDrag
0xe698c3 ImageList_BeginDrag
0xe698c7 ImageList_Copy
0xe698cf ImageList_GetIcon
0xe698d3 ImageList_Remove
0xe698d7 ImageList_DrawEx
0xe698db ImageList_Replace
0xe698df ImageList_Draw
0xe698f3 ImageList_Add
0xe698ff ImageList_Destroy
0xe69903 ImageList_Create
Library user32.dll:
0xe6990b EnumDisplayMonitors
0xe6990f GetMonitorInfoW
0xe69913 MonitorFromPoint
0xe69917 MonitorFromRect
0xe6991b MonitorFromWindow
Library shell32.dll:
0xe69923 ShellExecuteW
0xe69927 Shell_NotifyIconW
Library wininet.dll:
0xe6992f InternetReadFile
0xe69933 InternetOpenUrlW
0xe69937 InternetOpenW
0xe6993b InternetCloseHandle
Library winspool.drv:
0xe69943 OpenPrinterW
0xe69947 EnumPrintersW
0xe6994b DocumentPropertiesW
0xe6994f ClosePrinter
Library winspool.drv:
0xe69957 GetDefaultPrinterW

Exports

Ordinal Address Name
3 0x4645d4 TMethodImplementationIntercept
2 0x410750 __dbk_fcall_wrapper
1 0x620630 dbkFCallWrapperAddr
This program must be run under Win32
.itext
.idata
.didata
.edata
.rdata
.reloc
.debug
xzC;<{!f
[>K&x|&
| X`tl
/vKM/;6
0%R}T
&eo(Q$
%X\28@
r~ft-db$
1^4RaB
-gL Lv
Rn2/7Ln
Nd"czH70L
0>MGwBy
QGQtWt
r}tVb_5q
69`%EE
]dz"gT
f6DR"4
4:Y9f6
dk8 U
JF+gHP
$nq"[_
Z5f.bk
($RD^D3d]
Z!\{VL
["T+s$
RFt&,)
=h-<~_
L5-rC7
J/y7zzS
\td0gq
;)d-[D
o#)Rr4
r^#)rB
JH})hAFY'
-jwAp(K
=<xH%(
\Afday
|,_L2z
_tQ!8k
7S28-\
eh]2.Z
e"~#|FP
f; 5)d_
eh|>HV
A=!:!4
X`5L\(
vP>0hZ
o BdtrD
xf'_wP
dil7H<>
$uGaxd
}VEDR4
HKzErx3
bo,|CA
[E^"p<FR}!oh
r<+RB[P^
(H-rA
')b$lNO
(6[jEm
re[/_b
fp)!inb
!md~R*
d@[rDG
ZW0=!$
y~`BCs
4TU'~B
4:b:J(
6{aAu:
x Dt!y<k9o
d%NB[j
EW<aeB@!
)t$iNy
LeQt||
+(VJ/du&]D
sy.ix?
%-^xCX}
)@R9$D
"wqBz!}
s"'Ml
$^E82&
2g->n-
~tK_jy
%RvMt
%LV|kZ
V`QtYr
$h8$MX
\v4NK5d%gY
C1L)|4e
OB/UVl
P%\y/h
!PV#<X
#(Buk$$hk
9 J@|l0<A
-V3/eQ
!F{3W
4Dp0b<%
2$$"(11,
DD FR"H#
Wb4"8V3
trr8lF
Pj2\)a
h%020D/
\U(ejx
fs4dz{
#,yTB<
tJ%T^t
0"@DXT
,"\PDw
Iw)maG
Pd'?!3DD;
F0ryKB
});9!|
xS+Jqi
Md21,F$
liD(:g
PX)P5*
~-s+GX
7t&{KOIT
HR8^uL
>7irp#f
z^`T}Y'd}
jraA:D
VA`8k/XI]
^|A~AFS
?R,$CU
";-mpZ0
Xd/?zJ
#3!ZBZ}
[1px6f
r>zlz
ws?db5
F@!xk\
Azd*;@
P?L!*2 E0
+RLZ`H
&P.B`{
q0-RZ[
5p2-"xkz#
0k2Ex8
PdxaLu
E),"B/
HxD*!g
Qk#o'u
&C$" O
r(4RFX
FsR_~)
dP5`6D
y]&Z[t
=>]%A}
YdIQ,
H!eUpur
YqGyFk
p8v&b|5
)^P s(
e8dbn
z%do@
.|lt/6
,D3p/W
6!Fd+
E71eMr
B9ZVh
]!hq"*Ax
J$aNC+
R$EJaE6,,+
B9!h'rL
(&*@)B
6l$KsuOv
k4{"yM"
5 !C.h
YMTFY|C
!j'<!-Q
c 0YL\
DBJ @d\-
xV"?8%b
B052UL]
*D=mO
KTIZAw
SkWY|Q
xP7(zA
!Xh4OJ
xE|o$p
oI}*$jtP
ysTPL*w/
D078RD
"Q6A6y
o#{DJB
%"A&O>w
BP{S'X
t04dFC
E6>4t(
(2smCK
u|8SFB
?\gaiw
4Cv%h}
L-d7De
xhn>U
#e8JuD
<J^F`#6\
d{`d-|
R2l4C,
&t.>TRV}]
."#DHJ
2*VB&@
Kl|V@<
t xNpavN
j"BMp;
)Ke BS
<!.^xS
\V6;#
gJ%Z<N
B\"TAX
j$igrb
CybP/.R
'2I>l8g
bpAX5)Z
IO7}IJ
R:`G}{
/d$^9%\vK
GrV!4r
iRU5$9D,
uBKG"
iC2eEM
0'^wl=?BC^
{, .FE!
lO)Nd4
mDZ`B5
$Bzc=!nK
u~0z4L!A
Ua_d%*
%}flFW
=\Pe[d
|}d*eJ
J56]u=
fG `Bv
d|{#xD
xDO!{b
MD<@[j
92<N?K
|$q|BJ
^"7+#J
24I`BT
Jc2!R3
KeYmd!
d^#|i/L
L'<eM$
;~d'el
IT,v!(
+X?DME
$xs,R]E
O/Inp/
hL=&\\
n{LFaZ
TiK^WZ
lQk],/
5D$-1hO
dQEX8@tP
#aDE"W4Z
Ipr\ZL
9{WLt#
[I-8%\
MEf2A,
Py,ecj
G6CL%H
\f!9J-
?,B\B(
MLO $n
<XE.nb3
.}E37e
E<0|TEr
Q -R'1S
|DrgB{
6"fYE+
S1^B,!t
`XH%RNYP
PZ)5Rmz
za0GwBp
cdd2`%
"Dw!0%
%e2DeA\
P&1QwW
d' EY'16G
SpEwHF2
<+F<XB
(DtMEu
HH@f B
u,Jd"&r
2rCnh"
4)(8V
wDk"s$W'
h2GG j
z1oUL;e
4j!Xbxi
^=dI8s
MibT"u
Na6QlH
#g}b8h
'D|lHMo
lFT!,1
T@:h@8
40>:fuR4<
7|ft!lF
1\Q^#lFQ
|fU8!8
RQD./I
zUGL%t
yvGQ!h
d@2]IA
O jS$ed2
d\6r:2
GdjI+B
e^A`Ev
%D*Os0
<K=Bpp
#|[2+"u
Bi}/v)
#$!\)3
\42x]X
X1,dz-
OTdOdW
p3CvB"
v6\&L4
_?d{L@Y
#IfD66
\#~"#F
j4t&A
&EpuvB
-H,^+W
k}OT+T
dt:#tO
#zux.yFu
!gyap~u
`ZIE0Jd
@QDlC+"
$G,/G^
#]DHn!HV!xB
^PuDH2*Z
c$G=AJd
,+%su}
JT]QX7
J{u( R
P]?#,B
L,mPBy,
6"WE!R!
yplh!|po
,WZg;|+U
<WF}9%F=-B;
#hbBrc=
~!^l~#
'W+8,r
"-M4!o
5Bj#.(
up.uCT
Yt6kB}
U&gXZtIY
7%4Oaq
jl-EB7t
zDz)TL
AF:<IB
` hqd!|r
x+K+d#
r+)d8V
8F#''E
^WT#0!
< eX)s1
d7ry)Z
D8b_2V9^T
2!v!t1S
,7t!xRp,7
{J-8?DG
4qt%Lq_
!EFEkr
=7B"@G
cd+[Y4`
O7]9-=
p@D_dD
4dH&,t.Q
FV,[l7=
OFd5%yvQ<
Ht!?1i
.H_9=HL
Vi,,Q
R"MDc
%RI;[1
-,H(dC
Q\NTQO
YQH9{>
I=w"V
|-8;6T L5
b :>#,
#siH)Hd
Y"QDia
1]e.&ST
4_c>bV"
55(Vs$
vypZ6%H
YG@T#<h:+
qIHbWg
%>Q|sv
\g()dK
=2|`)W
Oou&eE
&)+XD/
]i:*xF,
}):.oG
%"+:UF'
dE2kr"
xrCy<|
@%dxnC
F;FjC:bKX
{ihUY'
5RUVH]
#c1sZI
0T!x0x
Z|HbPB
\T!(\xt\
\:)|9T'pC
}>e!(.
(|8T#(S
`]|8V!
(S>!x*X(S
+pej$y9z
=; 4<[;
]e-\,\
T#,AR7I
F?/^K>
^ DEtl
d` xjf
%o%#%g
%da\,~
%\,U<!j
>!|}x`
l{{B<K
(dAZaV
q3iC|P
M hTE|
uJ>(T1B~
R=63dDOl
;<C<Rx
eJ'llH
$G&#!M,j
=4!x1Px
k4</K>
w]J/-G
@>E-a<
}GTxr[U
8stVr[BHX
fG!snK
ftd0O{&
-tL\I8@z
Xz_5e#qO
m]yie^q
^!JiY?
bo&\_R
W-\4Bn
fketxRh
u8ybCej
jBJ-!e
(lXcFb
Goa!/
xP76D=
am6Atd
&LBiGD264
AOv(~YB{
4(ts)=
Q@Yd][
hG@`fJdB
}JCDPyW
VKyL~-
JwRIV@
{QDR(M
]tV_2'
!\|=Fk
^s_KD4h
@Kd%Dm
YB$<-Ai
b[dqY
^qe*}D.d
D#ia2{
=!`U8G
lb@:6B
m~IK~`2d
@c+~zgt
>dtkz_DdE
t_$*N_
&4vC`H;
dBjzZ
=$\8!-
@}gDaT
v4s+@sJ
Oe"E=gjr'[
Ll|\d)L
@:53\r
fWS."U
dr!r$Ad
_]RSqdyX
dF[s;@
|DS~+b*fb
!+o'vtS
h"~-ew
.k4RgS
C2`fd6@AQL -
7"[S~ @
v@zUCP
II:x(qH%
"%x%8[
zlB Z%o
/KxtDS
;C;MeP
Q |; \
t#9vk~
"/)4rYi
\&x*"p
:NVF@{
GGetH-
_A<H8c
"lx2rMQi[^%W
K|_zDY
'??KAH-
VhZ?1Hx{
l@`dj0
D#eh-f
b8W4]e
B4~Z"
,6(c(d
OOx2oc
R`S)",R
{yqIzD
./miOYm
mXhdkSTtbL
Moj|8\
Ie9A/<~
aZd4vX
aCd4>T
gb+R\s
}INZ!}g
y']f`/
j8wV@[
&kmXV;
G; JDgs
l"h)4|Bd"`
OeDDqgJ
fo)KtO
nrx+<Pmy
9@!pD
9p!XD
98}0CN
Ylw /d
k8G;<B
5_fMg7Pb~
dK1#c|
BPcbc/?
K1kVld
._>X<?
_)T8#5
[^]pSE
D{],[]R@u
(\d@{gK
*dx!&I
#M2bv;4#p2P
)%s\B8E8#E\!E
!LK.9T
BDF"$#
X^`\P@"u%a
eqZ)7/
G$,d%o
#.&Pl&
zStDxBn
TQtze8
izky!iz
dx `dqH$
>!robc
`!DL;xl!qzX
<]4#F^
6L,'Cg
UfxYF`
e?XVRCz
B9I<#=KA
)/I@9y|v!P
zTp)Bz
z<<!:
:$j<P#"H
<'t~dC
Bx04Gt
o~sN\S
9R@!dT
fd!B.+
qN^!aH
<3Tn\ y)wL
/K_F$!t
r4+z$xS
AAo8WlC
GmYd4x
d8tp@k
0t\#0HB
Dr8dDqs
^wJ3$`
E$%R:02X1
q4iie
!1JEWr
~)UJuu
b\B>!\B
GTKAZ<
^!|+P(
7'_*(
4!0ty`
d`D(lf
Itz/7L
usGaT(
d,r}s]T
0bG(YcB
UwyBg^
&^q,^jJ
#RrVFxw
2G{Yvk
| DxQ+"
8A.7Gn
jBA}TdaK
`-D2EQ
xTOp1w
,L6YIh
7z"6!f
G"Lk.^
D@`d]X
RjC}WEaL9_
@Lpp6a
tRmD~%
m<Sj9<.Z/(N
#B'6*]ba
DSMTy,
J}Gf7h
zJ378,
d<k;Y7
>!(rDj#h
b[dr8E
2QUB4`
6J +O:
d<d#\D
.4J2uI)
S/Bbr<#G.
[`|#o"
47eD"u
c0|d9H
lt">(<
/sS.`W
*(FHJ?
7d,\tS
UQGh&s
4f(2L
1Hd+5X
/uc"a
"MC;5h
HMKcL<
D(rf:A
+[QZz6'}
Q<<F<[Z1
"<)da5
HG8A{>
.R9/".
8b&h7~G
Kd@DzWLp
NWX-`U
}Kpam!rO
\"d<//
`'X=@rB.
d<!c,>
8EbuJ
FZ,=f=R8
n[])lU
L23SI@
G8dcd9a
lZ]'hZ
.d3_%b
#5%h6d
g{2MC]
!VH%TM
RZ|~U^f
7"tKJa
dv-O|":^
L!bMxH
d32pA0$H
GJ}FV#
KG&Y,
L/c\-t
0 4@@l
[j>{FG
yS,"z&ic
3_!2"C
'K)C^f/c
|NxK0Pb
*#3!vI)
\RU|`D}
B$100j
{L*"X)
dBQs)g
d0Be~D
#8bYvE
U~0qP3
<K3!;O
#G~GK|
}^$*x@5K-
>B8LkJu)
NdvnZv
hohd%6
8J\]Pi0
@(DGD'D
M1W?tM
^$J]/E
6a0[x2
-d8It%
"@C\ ^
B#J&TK,
kP,FE!
r}vWRV
$R7e&9
sdFj:,[g
*1qch]3
94B#F]Q4D
T. "D
OG$'I)
WC,1yL
]e=. Sq
ZD5d87
dSlBA9+
nurzv,C
8td!?
MODiTv
X9M(vP
d`D(lf
e<Lg$OB
RUVzFGf
R9AHBX
,F6dHp1
9W!P6H
d!pr=/
EvKa>a
8DRHe
dk[9s?
Ad+28LPA
%&.rj+WY
`<C3tYT
x)h6N</
2Q-]8T*9
$&QTX\
`G(9</
%KX>-0
E9NC4X
SX.11"EB
fNkf8y
y(g%(s
@Z%'0
;11z &
m[*3<1
b'aG`gg
H.HhHF
}vXR4t
ps)$T!
/|h2XU
YZF<_W-
^M(D3R
((x>SG
N0??1?0?7%6
~~;~:~9HC
67[qRR
@*\@G@@+P
={1 ;tGn@
]09A7k
<DK$5
)!/3'W
+u'E."C
*$\1 lP-
DAk!Y/
4F<%"w
C|#Ibl_V<P
&.c SC
4Es wa
d?2^bM
*CkdWbBPE
3D):JG
;@j[L$
E>tSd%
G4}RLp
"INQZE
]:d@~G
e-!HD|O
8vC !>
tdG"DbQm
)cc|-dS
&^d19U}+
:(fd)f
b,D'tr
&V%-U\
<-Zlg/BdB
`ddZW_|
HE!B6W
d5W;HX
o"dap<G
?+'jhKtL
!^"lY:J@uM
3Luik|F
th1Px+
)E7/,m
AD+o7Z
dK9TAA
<Kuua$
r93QyO
DQPN'j
'ICDK<
MQmH:fo,'N
m'W%Q
w."Es!,
!GBAZt
gT8IUnD
]P>Ad'.
O@s'T2C4
HyXh$f
_lE{_6
hu =a*g
\2)OUg
nES#^N
-U4XQ4&Au
#dmjgc
1BtGIA
C6VPV
ldi_&
dfV!.4Y9w
5cIxO7
yaWQ@b
lLP43d-
A!ra{-p!
2Ht$J7
"li^7^e
d#5~])
e~#!e-
0#yaE58%d(
YRIg*_
25KWAD
~rIJ^7
hUOA?!
KR SaWDE"
CGe-d
f!D-_(
hHDLFGS
eiJH"N
yIUa!s0
t'\W!7
'xoU2_\
48&$93
N$]Yr,
Wdvt4F
ry!"aC^9
l?!H4PBQ
^p!=Wc
!dF/Ip$u
;dX+B^
Bm!%f2[
Qg<4<0
rh\R#>
(XWlP @D4
.Hi9$x:
I&s*fH
?B_<jI
y+>?o!
!d"aT6
4"JDl
K<:sOy\
mQzR{NH$l
oK8Qs4
ibg.:sH
$:)<Lx
VIRCi%
#6)yVgY
%?:rP7H
I}QT=z
$i$YxbN
ea%8!Ip
1)~3pq
"xa:Oe%
t8ED!#
'AK8@]
HdG)Ez
d%4fQB8
hh@p--
Hy_B<X
1Ax tr
H'tsE3
W"0Ghx
x2|,.4
q*Va|v
Wj!%_r
%Cr>O*
HDyXs"RD
#GB!K5
fhDf4\Hf
&j`8-l3j`
\_VDC^bIj[
YqJx2|
+40=DNu
6dz7Np
<=egPC
Dh,8B#
z^pBN$
X-l3}h
Rw!V*B
@!4NZ}
NS)]|Gj
fl!X{$SE
Y^$8BC
w)+EXA
abhc4!
E05<ad
oV!5n
(KX8o|;
|_"H:D\$g
K|MCGxx-
TX1z[h?
aLA59%|
d3PXY"G<
yT. "
eC;"4E
OAh!ABx
W<EF)`
S<<C N
["mDgy
~/oY8X
-E{\eP
2D{([K
eA>h@8
{M-p!qR
;/L\<QE-5s
d0rg+W
-D8>1qZR
dl%QaY
1"{]-
@i$Bub*
W74vr/
_\@{Jp
\W9rH1sl
h!*lWT
^*8@P`
2Zd!M7}@
HP>,X#
'|v$z2
`ab_)1x
agKd9/
K,0|?.
yB!Q?o
dkwbwg
)4|8H-"7C
~9d?JK
cl'A?.a;
$DlDF0"P#
TpF7"XGd"\
=dj%{s
;B[dG~
A lO:pHZ
Q"_E<=
St#dBlNXEh+
);ugxkO
?g<4 1qMt
y\bN9L
C]u\`:
{C}%[p
Rv-Zbo~
h(.IYT
](;9~U
ewxVPI
\6H'IR
n7N$|n!K,B
/rh)r^
%v\{Cj
%Q|/[H!
}=$d!L
6Zi}Rv
uLw'[=
XF,]v'
QNk89s
*,q#N#
ld(B+#
CNTjZx
lN`B]#
#ezn1a
hL=&\}
)3 80B
U{(Lzh
L#~#Qv
p |sgT)
t@Md@N
TTT!d[x
B/0L"J
>#,^R7
Pg X`!
#DeX
EG-q)q
dq^#$#B
T#$#Vm
|n>?dC
;4!@OP
>,(hF?
%#9r|%|!
|%\!@O
l>.%K>
b=2|!^T
j9v"v_
"9|*J&
_X&dnl~6
HpqsQ-
|dFc8$
TVV9<d
%&F;6E
r,D6Sd
5"3DIG
." D:L
*x*H!B3
nlw}FF
#egR#G
eV#JJ"
7ph:EQi
xrXd\2
z2FhO~
O{i,XW
]"SEa6
N"\DR`
EL++UtF
n,&MT<
Y_$/I&
Xd5{^A
"P/"Y]
78x"9e
6g%b"[
<@tr6D
_6gt8O
0|dH@4
7q3BOv
$nhSxf-N
}bBXnN
EBsEK<
bid >Q
$:0Z/d
&\gQRMP
b#0$|9
`LHLT/;
ld~y@x
)/Tnix
Xd8Hq*
,nxNks
FvLMI5
qEd&nXH
n,H@ j
GWDd8ZC
FG@t$D
n4#S/b
%t<pF{
:+t]x"
N'LePp
DQi sf |n
4!/,nH
2Td6!HG|!
rG0DxJX
bfM5b}M
j(~!'N
B%!xp?K
t-d'Ohi
]?8w>Ct
"6#:+B4"5
i?.p!
!=BKh~
xt"!Z!45b
%iFTJT
-6E2?H
GdD{/LV
\@#hHi
6~[Dap
UYLPnfGg
[g,t|w
l#"b
hD?MC;
1[Asd?
\!7H|!
I-WZ,|
!6P=hFg
MF;<5B
bF <jB
Z\#H(p\(
,+|KB+
EAxIFC
<ATXt"
O<|PD}
P%|Q]b8
$bj0(#
g]dxR`%
@LgGc$
@ pe![SS
r P@XT
Cd#XdJ<t
` hqd!|r
F ht(
rPDVbA
~Mo.|/
PyxT@zh
}#9r\}|!
e,)G3
:)p9T'x
HR(+
,->!,-
Jjs'\)
\9|\C9
9sJU9l
JllsC3(0K
1sNU8{
GhB|Xq
{C,(HL
DU"WFV@
Q$1R:T
R:LpHg
!9}E_r
87h GJ
O4GIm@
SS!%b$
{V{oz
*Od`gs
E|O6Sv
Vwwc?d.A
0rTZ}Ns
P/Wcx5
UExx|,
0x}G>*S
1s A<Q
&\$l+Z+
Y:({Rs
fzdWvp
c$kQ/)^
qAsx[,?
.EezH13
+(=2;'
JkwvLKT
&B Ggck36<
!4{'t~
w!7`<ot
h$H~/w
,DZd!V
*\$I@S7
vxWcB:
1!dgH+
{<dv!^
;\K,,p
4c0&d!|
Ir%6?.&L
$0{4`<L'
H9C1-Ef
RyxBuF
!Fex9e
T!.3t.t
A=$Ky%
d5xkas$7
dz(#G]kB{
lMXPVT
TQd_(X
;}UQ[EH
!:)&\:
#Qlu#6G
L H@hl
(DsKX\
6 p rm
3M(;gz
:]\uJe
5AK&"Md
C"$5Sek
'is-;#
td'T=
}*DRwk
livbBd
4ve<fT
QdT$CgN
'EUR|%
m4e![JF
zQ+'X*D
*uYJ0(dzTzc
`vB;wV
.dliyU-^kQ
pY*'1Yu
{I`Lq6/mR
sr'tavgx&z%|$~+~*~)~(Q/
l 9B6dS
sxbC.Fiq
-%O4/v+
p/qM's
Nsr7t53
mY{f$3Z
}gK#YR
&^,xxV
#&4IUq
1C<N$v
kIY7i{
rUeZ,j
faH|'}
QK4DV7
mSMH2,
L](\SB
dMB/K3
h?K)<;
C;"4vJ
Jady4+N
?R4]!.Np
u uHrT
_dK%py
H< /%FM
%3dFED
'yU[|k
N?<f|6
q & N<qeV
wHnv4p
0l%dIX
F1Kj>A
L~XG2K
qr!_;><
&B! j&q
?,BM@^,
&@^@Oo
(G Fj B"w
Ld&8PQ
Gz1(`)?
JX>GU(LX
"ds+DS
F,@4dJ
sd4'%<8
d0+5":
:8}~pXd
q2U@,v
UIGxp9
,K@K5~iM
qejWX(
Q5Z*(@
6'bsyJE
d*]dO(
exy\(A
)XK<-tY
pQ_CsK
.xhkFC&
<DoD>;.[Zd
d%)q{Y
PcjAv
-ve@ F
`U(~(-
"|*-V^Mbx
d.q1O|
)#eKs[(M
-'l3hkdy
z%`{Qa
ty%/b4\eq
B!x!*4
)fx5[s
m(4Ty"
P-?Lnb
4|dXJeD
iPDhkL
21!s`yo
Ar0keL
rLSFl!]i
K/t|LZ
|&x$~s
GA>Sh"
WlD+q]n
F\b'kg
)> L&=
d/)]K(
KU|OiN4E
D{RUUY
3bOl_t
QPF`b4@H
x<*@|.{
d&aoroQ
j)XOMR;%
O_BIl9
B<i>}Z
!x k
Lb$% 2
`pty)js<LZ
K"c(HA
4b:bjG
rFN<zB
aLB59%|
d^Pi y"
r(iZ$-
QtFTcJ
NJNBx!
Xdh2l(
;oR<WdR
,ECYqA
vsf|~h
+Gh<JGW
[dBDRd
F=H<I7
dqueQxI
%gNcKex
4Am_lo
(m-<b%
Rx=~oH
nttRY
Pb.=K~2+
)5-i}A_
E ;M@um
(!~k@2
3L\pDlLr6
(?)<0J?
4Nkl#L
jxZTvv4
I':DjP8<My
Q$u.1/N
#hXtoD
{]VE5G?
4MB[*L
]YZNcFJ
P2REcg
r!Ii2N
d^~p)>b
"On96v
4dqC8VMKt!W
J_rdj6!
BpBI_xdl
C| `Ch"l
[mj=4J
CgtA#i
^8("DQaBM#p
D"p'KH
0K="<h<
C(K(gQ[BKq`
UWBQZ$
-AErTc>d
-&IaO`V?
T Wgx)
iV)-qd
k\ V#pSe
V/}Yl{
tadj-#
/8.,SLF
"6-,EB
5&3d4o
70jd\7
h.!lqP[
d?#hqh
dh:!d$
#KDlxh
ClhUhG
>,hdo5
S%]ET'
IWY:IY}Zy<9
S-@h99
#,Ad)-
JDd^T+|
Mbezy\
~O+p[}
59L@5bl
rld<[m
.2_Bi:
eH_ =t
gXXX~P
TSr]yB-
|D8mPn
V6s"/lE
=;9=;c:s
K'lHts
>91;c.s
,1E$/$%
eo@m7s
~#L?ph
B7f1n`
A :oKgQ
xYd!*)]
..t(m2
LZ,,d&AL<{
BD2|0Y
4-C?S#H
(5,Z#D
J%aDdK
Xo!iJI
^_:&8
C8|sKBx
Yd@a+R
!)aZGH
I?DUrt@TX
T48q<?C+
Y6*/4}h
1oauT
T!UdItk
@eK4,A
P(~ xE
` .|Lx
>!;oqx
A,D{:."
8#qPJR
#(pP}Q
m1Tv0w
`|g#5
dRg+kV
*,dE(a
]3|P B+g
^FLE%5
@wZT!wK
OzswNID
4R9%8.
(H59-d
yu%VLk
G$d|l?
d=Bhu.
<r/P9R
e~,t&I
?-ppOd/
Dm+@fX
'\IZ6+E
49PRx1
Lt<H}[
z&Bwa^
Q1H`l^
t5,jX_>r5
zZIUm+%AH\
3J{;)5
H\H0^:
)2!,{s
+_QX#"D
ko#m`)
J zlOI
,&(.+g
\U0bP5Sl
?G9#-$
(00UQA
2z/g6t"n+
0C"GmZFe
r:-~T.
h0Td<h
DJ6w{y
<CpD~$R
/hDfAl
WIf9B1
E8k40I
dH,U@QgL
d>B<%.j
FMBD4
\4iey0(
AHy~!
;d"ij,6V
CP"T%e
`dlqw?
+i}e2.
=%X~?O
1qb2.8
}I\T*I
$d&T!f`YS
,wB 8.
lm?9{/8
`h$VEE`
9(h%4:
CsEJV:A
5e'_:
Vqs%~u
NJ/$H[
dZIq|~
[#|"'g
m)UsX<%
)HE9X3
GtEH!"H
-Fs~7X~
Id_Qmk
Y"z96x%
w\<r<d
dkRVul
J*01(1T^
Si$iZx
p@7$@N8@H
X~ 9y
w 8q2`sy
b$jiDk
_`,LcX
'l;A`7
Bx!*eL
l8382..g6
.s2]9
X#D6@J
F0C@'(
4*Aa8C
U<8M-zL
[5d6jd
pEZmc\cC
^s#PafQ$EYni
2cPH|*-
8a"tTd(i
M(-#,ju,l l
p3x8v~
J,8c*r
re$lH:shF
,4[)8pf
v:ro:5mm
ntime
12345678
9ABCDE
x0L,h
"o>DEP
B"I|R|
V|bx1Dnz
>,>R"0D6=
>q>W"uD{
)"0|9Qa
C"J|S|bDW]
D!O%W-h_sa~b;y8ci
70>Fey
^wgqeRk
)8YHNS
shift-j
*esRIz_
B44*u!
Z)jp#
hC(h.m
2<glPK2
7"8U9"
7$8J9j
T"\Ddl
@YPDWE
0 x\
I!M)Y^
"0D@P
er8ifW
b($)L,
z=Pd9T@
HA*L4S
1.2&5$
[unNGow]
6zet/4D
Dgms4`
$c`ebymbo}l
w+O<Qv
ZEo^m/
H*0"FW
{kHLwh
ewh/?y
?e+`wy
vQO+t?
X=#]?@1
jl6GZ~?
Oh4G\Q
/Q"kD*
u/q"0D
>",D_r
(r)9*L +
8H8R8T8X8^8d8f8j8p8x8z8|(~
8L8K8M8P8I\@.VB88_8`8a\
8q8r8s$hp
8G8U8]8Z8[8\8o8n8m8l$g
ljr(nI
pH>&R@
)f4Ih1
83AX1t2
t(204)
\qfH1<If
P"4f|)
9fxq|)f
kernel32.dll
GetLogicalProcessorInformation
user32.dll
MessageBoxA
wtsapi32.dll
WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
user32.dll
SetGestureConfig
CloseGestureInfoHandle
GetGestureInfo
PhysicalToLogicalPoint
msimg32.dll
GradientFill
AlphaBlend
kernel32.dll
IsWow64Process
GetFinalPathNameByHandleW
LocaleNameToLCID
GetNativeSystemInfo
GetSystemTimes
advapi32.dll
RegDeleteKeyExW
windowscodecs.dll
WICConvertBitmapSource
uxtheme.dll
BufferedPaintRenderAnimation
EndBufferedAnimation
BeginBufferedAnimation
BufferedPaintStopAllAnimations
BufferedPaintSetAlpha
EndBufferedPaint
BeginBufferedPaint
BufferedPaintUnInit
BufferedPaintInit
DrawThemeTextEx
imm32.dll
ImmSetOpenStatus
ImmSetConversionStatus
ImmGetConversionStatus
ImmAssociateContextEx
ImmReleaseContext
ImmGetContext
ImmIsIME
DWMAPI.DLL
DwmIsCompositionEnabled
DwmExtendFrameIntoClientArea
shell32.dll
SHCreateItemFromParsingName
Shcore.dll
GetDpiForMonitor
GetProcessDpiAwareness
Loader2021.exe
TMethodImplementationIntercept
__dbk_fcall_wrapper
dbkFCallWrapperAddr
Embarcadero Delphi for Win32 compiler version 32.0 (25.0.26309.314)
t4vTxpz
:#;+<8=J>]?j?p?|?
t(vAxQzj|}~
' G.g?
v0xGzg|x~
?8?N?R?h&x
X:,Q4&"=>
???G?e?
tv(xDzXMiV?
?@?H?P?X?`.h
6rt/vCxgzw|
9;0:=;Q<_=q>
'#G5gV
ktvHxyz
z^|q~w~
S>`?u?
M&&:g;
9<::I'U
^=d,6pf
;,V<IL
>^?c?h?x%}
+995:D;T<[=
;<<S=[>h/}
B4(5Nt
'#G)d;
"@&`7l
'#G1g>
%@B6PI*|$"
2r<tNZa
<&=.>6%>a
fxn?v%~
h?T?\'d
<$=,-4
lpF~|N
.LX|NX
:+;9'R
95%:)/HAf\/
~\~lKtb8
,0;5"9
~p~tOx
d<|JD
HIpJK~
t4MA|'Wa
>?\?k%}Y
t#v2xDOQ
6!')D1
FP>|kOz
v5x=zK|ZNm
N&(Ihy
PtaR|lT-
zA|G~RN_
`"hdJi
A,<N|T'
'>XjtVJi
GOZaCK>R
!<L%1XDM<
?U?Z?e%kA
~j$&@"g
Fl:?N'R
(/0Eav
J5KSpR_-
E|T:s'zd
zQ|_Zm
6HB>M?w-
Ip"dTE
<D-LsB
%:~pDg
YZ,|%sX
P:t/K@
%>r_[r
xGz\Zv
&z\|q_
~k~o[y
"9.KT"
,>bKfux
AH}(D'
= >Q?g%x
P'/>`l&N
vJxWzhJ
ppt7KN
<O=S%Wa|z+
}%yDdB
6'\|"tJ
&v,x^Zb
%1XJ~A~I~Q~Y[a
Lv>MLJ'r
@Pn|VZe
~<'tb8
htHvRMtV
p:I-^a
:#;E%R
F;+-8v
f?=?E'M
?m?u?}%
r(t5^F
v<G&],
t4vS_y
3&iXH$
!t'>3|d;D<N-X
%p|D?g
>]Z'RA
zAq8$/
t!.0%4
:F;V<h&q
0<T;R*[
l7in`lN<
:-;G'Uxb[w
X:%/8d
Ylr?o-
=R>Z.h
S,P?x%
[<~&|L
=`>h-v
</qA@y+
\92Y:g;y%
xOze_v
@:-;5%C
:K<{p:~
'1<H<>
>[!cbY
x7OH"4
tLvaxozw|
:F/]PnN
hR9-::/N
ZD~T^b
:I^8']
KV{T2K]
=K>Z%h
?|P>W-n
hN:]/d
`'cxpO
Q,`>v"
:;=<K&[
b<P=l.z<
I>ppLO
nv/0^`Dl
<r)]:$%h
1&`z*"
lx:C&`
\?R?V?Z
%GVzGk
;U<_=c/
F_DnJl
ltMlP-
;("9K^
IwmPGD
p2z-J5
j9<)'7
0&i~Z{
h:5&H0e
PDxIzWZh
<#%+w$
%.PxtA_H
PgzK%_
vGxWKj
98&j,k
B=g-~a
v~c~rN
dZNt<vCxJKQ
d:O/;_
=b-qal
'7X@^j
T*G%6
0ZZtOvx]
R@tF_
P-zXP^
Iz%*H!
'"D<IYb
(<:'Ld
^%6tzIi
>6lXPv
S84?|?
b"[j$zlN
PZt+^M
Ql$bGMeb
t/v7_G
2"xbJ,
tIvVx\Kl
:;=%ZP
B><5\lD
)>$'?+A:
(:@<rN
jtrvyZk
;2%C]i
]zrv+K9
<O=]-kYl,p
!,H:G;\'j
Q^-rl[&
4a 0Wz
%$SJ/
tH[x)4:
d`|o_}
K8`8pO
W)`Wx2K
R|,$lz
7i._4,
">"vYx
Ua*Z>(X
'G1g9
nt~PZX
v*x2zJ
L=R%YA
]ZHr%t6]N
]Iz,x<Z
%wM0DY
<>P.ZP
|b~j~r~zO
XH<B-W
9p|~GZN
~e~jOw
<&=#>*%1ABB
}j.u~j
hV;('y
<P"W~e]l
\vKxSEa*
vB,]PZN
>M'`~Xr_
4+_fxzn^
^<:%Ba
<#PJvbOm
M8L~/3=t
1a*cl -
\5Pl~CNJ
a-(H'C
'XP8Mf
M@tp-p
P(.v_x
EbnD2/
8%bpDx
v;x?\Cn
t/A>%4,Q
jnH?*';Yh
pVY2>/@pP^Q
x%z)_-
'RRt#[9
oud2~{~
r2tZTw
P4tHJO
Wz\]8*,]
tRM{P'
D,8*1Z
*=G/_u
f-#a^9
;A%R}IJwk
B=P>["kK
IHNWJ|]
2'7uIhS
xezm|~~
4p]+<-P
M.4<K&V6
82'E]I
x Al4+
:L;V%x
vpWZLL
k(?(%O
-x|;^-
V.QQ*#z
H69R-aqX
M\2&r(
Fl]FX/m\
AVFs8_
^-n"\k
rBXTZl
t-.AvR
DHv]xjK{
x.z2\6P
0WmJgd
3$:#fQ
xVzZ[^
IR!vX/
%R\~+~/Q3
96':['
:"/N}
WZ8t&K/
:t5v:JE
?f}dhx
vH^Q"
~]P<~mOu
/'^6GG
nBa<j+
/Z<~t^
;=<J/Rx
*,$<M'_W
Pt$D,r
;8<K/\w
tGi.l:
cKrP|N
YXh~o~}J
<xXX9x-ZA
$>3%Jq
&:C%Lap
/@yH'u
2?i?w-
Yr'_5r%
l/PSF'
xJMR^X
XZv>ME2>S?Z&a,
{+I;^-
dntSvcx
>+?2%9a
U;_AN|
lR-;^A
~^~c~nYs|$
l;L"SNa
z%AJx*
lL1<I%t
F_ix};
BD]pP~"^&
;4%<w%
*8,<T=n&
#}L@~?~FNP
?T?[-b
>a|z8*-
\9I^`;
A=9lu${
T\A;0^.
1"AnT*
<@%Q}Ifu.
,IV*-s
$<o)n>
j8?;rKK
82P8l!
'_A"g?
|J%W'T
"bnjLAJ
N,2.=nb
GX|xvO
T:7;^'
94%:;;R-i
8Ax ]i|'
:<-P}%
t~]~w~
-dpj~rIy
$G|jE}
sDGKdX
/(:%
wV<GND
L|Lj/5
aI:hj"&
>"?GuF
;!<',H
K]Eb_-
?T?_%e
t#v/]9
P?v?~&
:x?l&x,
nST<fG8
()N*)2 ?
)6("h:$)
nST<fG8
(dxV#fC>
DF3`AC
02C64"
wwwwwwwwwwwwwwwwwwwwwp
ggggfvgfvvvwwg
dvvv|vgG
Edtcegfvvvvvggfvvfo
BCgcggggcggvvwx
F4'f4v66rw'rwwv7x
vppccgwg'vx~
%'&6wwwg
gaacgggx
6wgwww
wwwwwwwwwwwww
4vegfvwvvwwx
cacgwgvxxh
ggggxw
FfVef~
2222222222222222222222222222222222222222222
CSEPECCE>79E>C>EPQP|PPP|
C@CCCECEEE||Q|||
E9C@CEEEE||E||||
>7999>>CEQQ|
<5><=?AAAAEE{||
35<<=??IIKKRRR||
6666::;;;::FFHIGJLNNN
"%$%---%
^,^^`ddpddbb
- ,,^^^^)Z[V[['[canu
X_))__[VYUUo
XWesl0Xm[WYq
(MMM00kt
/Mhh/kk
wwwwwwwwwwwwwwwwwwwwwwwww
vvvvvvvvvvvvvvvvvvvvvvvvv
99AAACCCGhhlhnnk~
<>>HKLLMMwqwww|
77<>HILwwwzz||
;;AAFKKnww|
??DDhhjky{
&,-16P\`
#..*0/46Yea[d
rrrrrrrrrrrrrrs
=================gggggggggggggg==g
###&(('g=@m
.02459GRXQm@@m
%+m@@m
*$-3?_fm@Bm
,elcc
BBmYcl
c^ZZcc
PjeTTNMUjcZE
/;71:7O]ll<H
DDDDDDDDDDDDDDDDD
>EzAx'
CQqB0.sQ3B
g)A=_
$B2fA>_
D1DV/
;$FL/:
XRITr
JtelG^
kk* kd
U1Jv`n
[L0~"Ub
$QICKE
u!&<ABb
}G`=_D
; FZQq:0
%*PC}u
T\E6R2
},E0W5
LN/Nl;:
.nr;g+&R
0HFa,1%
!=EX#M#
>H5aYC%h
qK1x"I\
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Snojan.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37547600
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37547600
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Trojan ( 00581ef41 )
BitDefender Trojan.GenericKD.37547600
K7GW Trojan ( 00581ef41 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FKAJ
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Snojan.gen
Alibaba Trojan:Win32/Snojan.4599c3d3
NANO-Antivirus Trojan.Win32.Snojan.jaixxr
ViRobot Clean
Avast Win32:MalwareX-gen [Trj]
Rising Worm.VBInjectEx!1.99E6 (CLASSIC)
Ad-Aware Trojan.GenericKD.37547600
Emsisoft Trojan.GenericKD.37547600 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen15.13733
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.513f5b2b6d1a1ccd
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
GData Win32.Trojan.Agent.N5DEDD
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=81)
Antiy-AVL Trojan/Generic.ASMalwS.34956CB
Kingsoft Win32.Heur.KVM007.a.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D23CEE50
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Emotet!ml
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.MalwareX-gen.C4625205
Acronis Clean
McAfee Artemis!513F5B2B6D1A
TACHYON Clean
VBA32 Trojan.Snojan
Cylance Unsafe
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Genkryptik.Sshb
Yandex Clean
Ikarus Trojan-Downloader.Win32.Banload
MaxSecure Virus.Nimnul.E
Fortinet PossibleThreat.PALLASNET.H
BitDefenderTheta Gen:NN.ZexaF.34142.s70@aC9C5zii
AVG Win32:MalwareX-gen [Trj]
Panda Trj/Genetic.gen
No IRMA results available.