Static | ZeroBOX

PE Compile Time

2022-11-28 02:13:15

PE Imphash

45d7ac4770e5299403c09d9266fec258

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x002ad2e2 0x002ae000 6.33839822002
.rdata 0x002af000 0x009276e8 0x00928000 7.74867809861
.data 0x00bd7000 0x0016a422 0x000d2000 5.63698395929
.rsrc 0x00d42000 0x0000c988 0x0000d000 5.06102527284

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x00d43f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x00d43f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x00d43f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
WAVE 0x00d49060 0x00001448 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00d4a5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00d465e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00d4a748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x00d4a748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x00d4a748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_MENU 0x00d455a8 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x00d455a8 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00d450f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00d46ff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00d45cc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_ICON 0x00d444f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00d444f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00d444f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library iphlpapi.dll:
0x6af8ec GetAdaptersInfo
Library WINMM.dll:
0x6af7f0 midiStreamRestart
0x6af7f4 waveOutRestart
0x6af7f8 PlaySoundA
0x6af7fc midiStreamStop
0x6af800 midiOutReset
0x6af804 midiStreamClose
0x6af810 waveOutWrite
0x6af814 waveOutPause
0x6af818 waveOutReset
0x6af81c midiStreamOut
0x6af824 midiStreamProperty
0x6af828 midiStreamOpen
0x6af830 waveOutOpen
0x6af834 waveOutGetNumDevs
0x6af838 waveOutClose
Library WS2_32.dll:
0x6af850 inet_ntoa
0x6af854 inet_addr
0x6af858 gethostname
0x6af85c gethostbyname
0x6af860 WSAStartup
0x6af864 WSACleanup
0x6af868 send
0x6af86c closesocket
0x6af870 WSAAsyncSelect
0x6af874 htons
0x6af878 bind
0x6af87c htonl
0x6af880 socket
0x6af884 setsockopt
0x6af888 sendto
0x6af88c recvfrom
0x6af890 ioctlsocket
0x6af894 connect
0x6af898 recv
0x6af89c listen
0x6af8a0 getpeername
0x6af8a4 accept
0x6af8a8 __WSAFDIsSet
0x6af8ac ntohs
0x6af8b0 getsockname
0x6af8b4 WSAGetLastError
0x6af8b8 ntohl
0x6af8bc select
Library MSVFW32.dll:
0x6af4b4 DrawDibDraw
Library AVIFIL32.dll:
0x6af028 AVIStreamInfoA
0x6af02c AVIStreamGetFrame
Library RASAPI32.dll:
0x6af514 RasHangUpA
Library KERNEL32.dll:
0x6af1f4 GetSystemDirectoryA
0x6af1f8 SetLastError
0x6af208 GetLocaleInfoA
0x6af20c GetVersion
0x6af210 TerminateThread
0x6af214 IsDBCSLeadByte
0x6af218 lstrcmpA
0x6af21c lstrcmpiA
0x6af220 lstrcpynA
0x6af234 GetFileType
0x6af238 MapViewOfFile
0x6af23c CreateFileMappingA
0x6af240 DuplicateHandle
0x6af244 UnmapViewOfFile
0x6af24c GetLocalTime
0x6af254 SetFileTime
0x6af258 LocalFree
0x6af25c FormatMessageA
0x6af260 CreateMutexA
0x6af264 ReleaseMutex
0x6af268 SuspendThread
0x6af274 FlushFileBuffers
0x6af278 LockFile
0x6af27c UnlockFile
0x6af280 SetEndOfFile
0x6af284 GlobalDeleteAtom
0x6af288 GlobalFindAtomA
0x6af28c GlobalAddAtomA
0x6af290 GlobalGetAtomNameA
0x6af294 LocalAlloc
0x6af298 TlsAlloc
0x6af29c GlobalHandle
0x6af2a0 TlsFree
0x6af2a4 TlsSetValue
0x6af2a8 LocalReAlloc
0x6af2ac TlsGetValue
0x6af2b0 GetFileTime
0x6af2b4 GetCurrentThread
0x6af2b8 GlobalFlags
0x6af2bc GetProfileIntA
0x6af2c0 SetErrorMode
0x6af2c4 GetProcessVersion
0x6af2c8 GetCPInfo
0x6af2cc GetOEMCP
0x6af2d0 GetStartupInfoA
0x6af2d4 RtlUnwind
0x6af2d8 GetSystemTime
0x6af2dc RaiseException
0x6af2e0 HeapSize
0x6af2e4 ExitThread
0x6af2e8 GetACP
0x6af2ec SetStdHandle
0x6af304 SetHandleCount
0x6af308 GetStdHandle
0x6af310 HeapDestroy
0x6af314 HeapCreate
0x6af318 VirtualFree
0x6af324 LCMapStringA
0x6af328 LCMapStringW
0x6af32c VirtualAlloc
0x6af330 IsBadWritePtr
0x6af338 GetStringTypeA
0x6af33c GetStringTypeW
0x6af340 CompareStringA
0x6af344 CompareStringW
0x6af348 IsBadReadPtr
0x6af34c IsBadCodePtr
0x6af350 IsValidLocale
0x6af354 IsValidCodePage
0x6af358 EnumSystemLocalesA
0x6af35c GetLocaleInfoW
0x6af364 WaitNamedPipeA
0x6af368 OpenFileMappingA
0x6af36c OpenEventA
0x6af374 TerminateProcess
0x6af378 GetCurrentProcess
0x6af37c GetFileSize
0x6af380 SetFilePointer
0x6af384 CreateSemaphoreA
0x6af388 ResumeThread
0x6af38c ReleaseSemaphore
0x6af398 GetProfileStringA
0x6af39c WriteFile
0x6af3a4 CreateFileA
0x6af3a8 DeviceIoControl
0x6af3ac SetEvent
0x6af3b0 FindResourceA
0x6af3b4 LoadResource
0x6af3b8 LockResource
0x6af3bc ReadFile
0x6af3c0 lstrlenW
0x6af3c4 RemoveDirectoryA
0x6af3c8 GetModuleFileNameA
0x6af3cc WideCharToMultiByte
0x6af3d0 MultiByteToWideChar
0x6af3d4 GetCurrentThreadId
0x6af3d8 ExitProcess
0x6af3dc GlobalSize
0x6af3e0 GlobalFree
0x6af3ec lstrcatA
0x6af3f0 lstrlenA
0x6af3f4 WinExec
0x6af3f8 lstrcpyA
0x6af3fc FindNextFileA
0x6af400 GetDriveTypeA
0x6af404 GlobalReAlloc
0x6af408 HeapFree
0x6af40c HeapReAlloc
0x6af410 GetProcessHeap
0x6af414 HeapAlloc
0x6af418 GetUserDefaultLCID
0x6af41c GetFullPathNameA
0x6af420 FreeLibrary
0x6af424 LoadLibraryA
0x6af428 GetLastError
0x6af42c GetVersionExA
0x6af438 CreateThread
0x6af43c CreateEventA
0x6af440 Sleep
0x6af444 GlobalAlloc
0x6af448 GlobalLock
0x6af44c GlobalUnlock
0x6af450 GetTempPathA
0x6af454 FindFirstFileA
0x6af458 FindClose
0x6af45c SetFileAttributesA
0x6af460 GetFileAttributesA
0x6af464 MoveFileA
0x6af468 DeleteFileA
0x6af46c CopyFileA
0x6af470 CreateDirectoryA
0x6af480 GetModuleHandleA
0x6af484 GetProcAddress
0x6af488 MulDiv
0x6af48c GetCommandLineA
0x6af490 GetTickCount
0x6af494 CreateProcessA
0x6af498 WaitForSingleObject
0x6af49c CloseHandle
0x6af4a0 InterlockedExchange
0x6af4a4 MapViewOfFileEx
Library USER32.dll:
0x6af52c SetMenuItemBitmaps
0x6af534 LoadStringA
0x6af538 GetSysColorBrush
0x6af53c LoadIconA
0x6af540 TranslateMessage
0x6af544 DrawFrameControl
0x6af548 DrawEdge
0x6af54c DrawFocusRect
0x6af550 WindowFromPoint
0x6af554 GetMessageA
0x6af558 DispatchMessageA
0x6af55c SetRectEmpty
0x6af56c DrawIconEx
0x6af570 CreatePopupMenu
0x6af574 AppendMenuA
0x6af578 ModifyMenuA
0x6af57c CreateMenu
0x6af584 GetDlgCtrlID
0x6af588 GetSubMenu
0x6af58c EnableMenuItem
0x6af590 ClientToScreen
0x6af598 LoadImageA
0x6af5a0 ShowWindow
0x6af5a4 IsWindowEnabled
0x6af5ac GetKeyState
0x6af5b4 PostQuitMessage
0x6af5b8 IsZoomed
0x6af5bc GetClassInfoA
0x6af5c0 DefWindowProcA
0x6af5c4 GetSystemMenu
0x6af5c8 DeleteMenu
0x6af5cc GetMenu
0x6af5d0 SetMenu
0x6af5d4 PeekMessageA
0x6af5d8 IsIconic
0x6af5dc SetFocus
0x6af5e0 GetActiveWindow
0x6af5e4 GetWindow
0x6af5ec SetWindowRgn
0x6af5f0 GetMessagePos
0x6af5f4 CheckMenuItem
0x6af5fc CopyRect
0x6af600 LoadBitmapA
0x6af604 KillTimer
0x6af608 SetTimer
0x6af60c ReleaseCapture
0x6af610 GetCapture
0x6af614 SetCapture
0x6af618 GetScrollRange
0x6af61c SetScrollRange
0x6af620 SetScrollPos
0x6af624 SetRect
0x6af628 InflateRect
0x6af62c IntersectRect
0x6af630 DestroyIcon
0x6af634 PtInRect
0x6af638 OffsetRect
0x6af63c IsWindowVisible
0x6af640 EnableWindow
0x6af644 GetWindowLongA
0x6af648 SetWindowLongA
0x6af64c GetSysColor
0x6af650 SetActiveWindow
0x6af654 SetCursorPos
0x6af658 LoadCursorA
0x6af65c SetCursor
0x6af660 GetDC
0x6af664 FillRect
0x6af668 InvertRect
0x6af66c IsRectEmpty
0x6af670 ReleaseDC
0x6af674 IsChild
0x6af678 TrackPopupMenu
0x6af67c DestroyMenu
0x6af680 SetForegroundWindow
0x6af684 GetWindowRect
0x6af688 EqualRect
0x6af68c UpdateWindow
0x6af690 ValidateRect
0x6af694 InvalidateRect
0x6af698 GetClientRect
0x6af69c GetFocus
0x6af6a0 GetParent
0x6af6a4 GetTopWindow
0x6af6a8 PostMessageA
0x6af6ac IsWindow
0x6af6b0 SetParent
0x6af6b4 DestroyCursor
0x6af6b8 SendMessageA
0x6af6bc SetWindowPos
0x6af6c0 MessageBeep
0x6af6c4 MessageBoxA
0x6af6c8 GetCursorPos
0x6af6cc GetSystemMetrics
0x6af6d4 EmptyClipboard
0x6af6d8 SetClipboardData
0x6af6dc OpenClipboard
0x6af6e0 GetClipboardData
0x6af6e4 CloseClipboard
0x6af6e8 wsprintfA
0x6af6ec WaitForInputIdle
0x6af6f0 IsDialogMessageA
0x6af6f4 ScrollWindowEx
0x6af6f8 SendDlgItemMessageA
0x6af6fc MapWindowPoints
0x6af700 AdjustWindowRectEx
0x6af704 ScrollWindow
0x6af708 GetScrollInfo
0x6af70c SetScrollInfo
0x6af710 ShowScrollBar
0x6af714 GetScrollPos
0x6af718 RegisterClassA
0x6af71c CreateWindowExA
0x6af720 GetClassLongA
0x6af724 RemovePropA
0x6af728 GetMessageTime
0x6af72c GetLastActivePopup
0x6af734 GetWindowPlacement
0x6af738 EndDialog
0x6af740 DestroyWindow
0x6af744 EndPaint
0x6af748 BeginPaint
0x6af750 wvsprintfA
0x6af754 GetForegroundWindow
0x6af758 GetNextDlgTabItem
0x6af75c CharUpperA
0x6af760 GetDoubleClickTime
0x6af764 ClipCursor
0x6af768 SetWindowTextA
0x6af76c GetMenuItemCount
0x6af770 GetMenuItemID
0x6af774 GetMenuStringA
0x6af778 GetMenuState
0x6af780 DrawStateA
0x6af784 GrayStringA
0x6af788 TabbedTextOutA
0x6af78c WindowFromDC
0x6af790 EnumChildWindows
0x6af794 GetWindowDC
0x6af798 UnhookWindowsHookEx
0x6af79c CallNextHookEx
0x6af7a0 SetWindowsHookExA
0x6af7a4 FrameRect
0x6af7a8 GetPropA
0x6af7ac MoveWindow
0x6af7b0 CallWindowProcA
0x6af7b4 SetPropA
0x6af7b8 DrawTextA
0x6af7bc UnregisterClassA
0x6af7c0 GetWindowTextA
0x6af7c4 FindWindowExA
0x6af7c8 GetDlgItem
0x6af7cc GetClassNameA
0x6af7d0 ScreenToClient
0x6af7d4 GetDesktopWindow
0x6af7d8 WinHelpA
0x6af7dc RedrawWindow
0x6af7e0 GetCursor
Library GDI32.dll:
0x6af074 GetViewportExtEx
0x6af078 ExtSelectClipRgn
0x6af07c CopyMetaFileA
0x6af080 GetCurrentObject
0x6af084 RoundRect
0x6af08c DPtoLP
0x6af090 LPtoDP
0x6af094 Rectangle
0x6af098 Ellipse
0x6af09c SetPixelV
0x6af0a0 CreateCompatibleDC
0x6af0a4 GetPixel
0x6af0a8 BitBlt
0x6af0ac StartPage
0x6af0b0 StartDocA
0x6af0b4 DeleteDC
0x6af0b8 EndDoc
0x6af0bc EndPage
0x6af0c0 GetObjectA
0x6af0c4 GetStockObject
0x6af0c8 CreateFontIndirectA
0x6af0cc CreateSolidBrush
0x6af0d0 FillRgn
0x6af0d4 CreateRectRgn
0x6af0d8 CombineRgn
0x6af0dc PatBlt
0x6af0e0 CreatePen
0x6af0e4 SelectObject
0x6af0e8 CreatePatternBrush
0x6af0ec CreateBitmap
0x6af0f0 CreateBrushIndirect
0x6af0f4 CreateDCA
0x6af0fc GetPolyFillMode
0x6af100 GetStretchBltMode
0x6af104 GetROP2
0x6af108 GetBkColor
0x6af10c GetBkMode
0x6af110 GetTextColor
0x6af114 CreateRoundRectRgn
0x6af118 CreateEllipticRgn
0x6af11c PathToRegion
0x6af120 EndPath
0x6af124 BeginPath
0x6af128 GetWindowOrgEx
0x6af12c GetViewportOrgEx
0x6af130 GetWindowExtEx
0x6af134 GetDIBits
0x6af138 RealizePalette
0x6af13c SelectPalette
0x6af140 StretchBlt
0x6af144 CreatePalette
0x6af14c CreateDIBitmap
0x6af150 DeleteObject
0x6af154 SelectClipRgn
0x6af158 CreatePolygonRgn
0x6af15c GetClipRgn
0x6af160 SetStretchBltMode
0x6af164 SetPixel
0x6af168 CreateDIBSection
0x6af170 SetBkColor
0x6af174 SetBkMode
0x6af178 SetTextColor
0x6af17c SetWindowOrgEx
0x6af180 SaveDC
0x6af184 RestoreDC
0x6af188 CreatePenIndirect
0x6af18c PtVisible
0x6af190 RectVisible
0x6af194 TextOutA
0x6af198 ExtTextOutA
0x6af19c Escape
0x6af1a0 GetTextMetricsA
0x6af1a4 AbortDoc
0x6af1a8 CreateFontA
0x6af1ac SetBrushOrgEx
0x6af1b0 SetDIBitsToDevice
0x6af1b4 SetPolyFillMode
0x6af1b8 SetROP2
0x6af1bc SetMapMode
0x6af1c0 SetViewportOrgEx
0x6af1c4 OffsetViewportOrgEx
0x6af1c8 SetViewportExtEx
0x6af1cc ScaleViewportExtEx
0x6af1d0 OffsetWindowOrgEx
0x6af1d4 SetWindowExtEx
0x6af1d8 ScaleWindowExtEx
0x6af1dc GetClipBox
0x6af1e0 ExcludeClipRect
0x6af1e4 MoveToEx
0x6af1e8 LineTo
0x6af1ec GetDeviceCaps
Library MSIMG32.dll:
0x6af4ac GradientFill
Library WINSPOOL.DRV:
0x6af840 ClosePrinter
0x6af844 DocumentPropertiesA
0x6af848 OpenPrinterA
Library comdlg32.dll:
0x6af8d0 GetFileTitleA
0x6af8d4 PrintDlgA
0x6af8d8 GetOpenFileNameA
0x6af8dc ChooseFontA
0x6af8e0 ChooseColorA
0x6af8e4 GetSaveFileNameA
Library ADVAPI32.dll:
0x6af000 RegCreateKeyExA
0x6af004 RegQueryValueA
0x6af008 RegDeleteKeyA
0x6af00c RegDeleteValueA
0x6af010 RegSetValueExA
0x6af014 RegOpenKeyExA
0x6af018 RegQueryValueExA
0x6af01c RegCloseKey
0x6af020 RegEnumValueA
Library SHELL32.dll:
0x6af520 Shell_NotifyIconA
0x6af524 ShellExecuteA
Library ole32.dll:
0x6af8f4 CoTaskMemAlloc
0x6af8f8 OleDuplicateData
0x6af8fc RevokeDragDrop
0x6af904 OleGetClipboard
0x6af90c OleFlushClipboard
0x6af910 OleSetClipboard
0x6af914 CoTaskMemFree
0x6af918 ReleaseStgMedium
0x6af91c CLSIDFromProgID
0x6af920 OleInitialize
0x6af924 OleUninitialize
0x6af928 CLSIDFromString
0x6af930 CoCreateInstance
0x6af934 OleRun
0x6af938 DoDragDrop
Library OLEAUT32.dll:
0x6af4bc VarDateFromStr
0x6af4c0 RegisterTypeLib
0x6af4c4 SafeArrayPutElement
0x6af4c8 LHashValOfNameSys
0x6af4cc LoadTypeLib
0x6af4d4 SafeArrayAccessData
0x6af4d8 SafeArrayGetElement
0x6af4dc VariantCopyInd
0x6af4e0 VariantInit
0x6af4e4 SysAllocString
0x6af4e8 SafeArrayDestroy
0x6af4ec SafeArrayCreate
0x6af4f0 VariantCopy
0x6af4f4 VariantClear
0x6af4f8 VariantChangeType
0x6af4fc SafeArrayGetUBound
0x6af500 SafeArrayGetLBound
0x6af504 SafeArrayGetDim
0x6af508 UnRegisterTypeLib
Library COMCTL32.dll:
0x6af034 ImageList_Duplicate
0x6af03c ImageList_Draw
0x6af040 ImageList_Read
0x6af048 ImageList_Create
0x6af04c ImageList_Destroy
0x6af050 None
0x6af054 ImageList_AddMasked
0x6af058 _TrackMouseEvent
0x6af060 ImageList_GetIcon
Library WSOCK32.dll:
0x6af8c4 shutdown
0x6af8c8 getservbyname
Library WININET.dll:
0x6af7e8 InternetCloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
uRFGHt
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect begin
VMProtect end
VMProtect begin
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
PQRSVW
_^[ZYX
<0rF<9wB,0
VMProtect begin
VMProtect end
VMProtect end
VMProtect end
VMProtect end
RQWPVS
[^X_YZ
PQRSTUVW
_^]\[ZYX
[^_YZX
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect begin
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect begin
VMProtect end
VMProtect begin
VMProtect begin
VMProtect end
+E +E(
+E +E(
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
QRSVW3
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
3E 3E(1E
?hffff
?h3333
?h3333
?h3333
VMProtect begin
VMProtect end
VMProtect begin
VMProtect end
t(ENEN;
L$$_^]
T$$_^]
D$$_^]
D$0UVW
L$$_^]d
D$4SUV
L$89l$8}
D$(t,;
L$(CH;
D$4SUV
L$ QUS
t$ htr
@tXWWh
L$$9^8u
\$ <@u
L$DPQR
L$8_^[
T$ RPW
L$X_^d
L$DQRf
T$$RPQ
T$0QRS
T$XPVR
t6HtHt
D$$~9+
F\_^][
L$D_^][d
L$ QRh
T$ QRh
L$$_^d
L$@^[d
D$PQRP
L$pPQR
D$hRQP
9L$x~k
L$T_^][d
L$lRVQ
D$hQRP
D$hQRP
T$pPQR
DRQPh\
\$8UVW
L$DPQj
\$8UVW
L$DPQj
L$ _^d
W9^du-
L$ PQh
L$L_^][d
L$D_^][d
L$@RUQ
D$ j<P
DRQPh\
L$$^][d
DRQPh\
L$$^][d
DQWPh
L$x_^3
|$89^Hu
L$|_^][d
L$|_^][d
L$|_^][d
T$0VRPSQ
L$4_^[d
V#D$,WPQ
D$@UPQ
T$XUSR
T$HQRP
L$x_^d
D$(SUV
T$8RWj
L$ _^][d
l$<VWj
L$(VQVj
L$(UUh
t$LUPh
o0SSSSU
D$dSUVW
D$@WPS
L$`_^][d
D$,RVh
L$TQVSh
|$XSSW
T$TQRPh
D$`QRP
D$hSUV3
D$,Pj<j
L$h_^][d
L$X_^d
t$ 90t
T$LRUj
D$89Vdu
FpHt&Ht
D$LUSWP
L$$_^][d
L$,_[3
L$,_[3
L$(WQR
QQUWSS
L$P_]^[d
T$hQRWW
t]9|$<tW
L$x_^]
L$<SQR
T$<RVW
9|$8tt
T$<WRh
T$lPRh
T$ SRh
9l$xtU9
u29l$xu,
L$XSQh
D$,SPh
T$,SRh
T$,SRh
T$,SRh
t$(SSh
t$$RVP
|$,RPQ
L$H][d
L$HSUVWP
D$XPQU
D$8VPQ
T$ SWRP
L$L_^]3
t%RSQP
XY[Z[]
~'PSQR
\$<VW3
L$4_^3
D$XQRWP
D$dQUWRP
|$D.tm
L$0^[d
D$0WPQ
T$$+D$4
L$L^[d
9^xu5j
L$X_^]3
h9n`u;
D$8RPj
T$DQRU
D$PRPQ
L$TSWQ
l$HQRVU
D$H_^][
\$lUV3
L$h_^]3
T$\jdSR
L$Hj&Q
;t$Xu";\$\u
L$DSVQ
L$,_^]3
L$$_^][d
L$0PQS
L$ ]_^
L$ QSR
D$TVPW
D$TRPW
WWVQRWWS
D$$QRP
T$,PQR
D$$RSSP
D$8WVRPQ
L$XRQP
l$@VW3
L$8_^][d
u"8D$yu
D$(_^][
8MThdu
~P9~Pun
t&9^$t
F(9V8tQ
F<_^][
F<_^][
|$@ Wu
|$D UV
L$8^]_3
@;l$\~Z
L$X;L$
uh9^8uX
F89^8u&j
L$T_^][d
L$L_^][d
D$,;\$|
L$0PQR
PQj WUS
T$dPQR
L$l_^][d
L$8WPQR
T$DQSR
D$49D$$}
T$\;D$Xu
L$(PQR
T$,RQP
T$(PQR
L$x_^][d
L$l_^][d
L$TPQR
L$dPQRV
u+\$l
L$4SUV
L$4WPQR
D$ |2;
L$@_^][d
u._^][
L$ WPQ
T$,RQP
L$\_^][d
L$@RQj
D$@RPQj
L$T_^]d
FD uy9D$$}s
FD@ul9L$(}f
L$P_^d
L$\_^][d
;D$xt&
9D$$t+
L$D_]d
L$ ^][d
D$$QUP
L$|_^][d
L$t][d
D$$SUV
D$DURP
RVPUSQ
L$$_^][d
j VUPWQ
T$(QVURWP
L$,_^][d
D$$_^[
D$$_^[
L$4VQUP
L$$_^][d
L$4UQWP
L$$_^][d
T$0SUV
L$(_^][d
T$8QRP
L$(_^][d
L$8_^][d
|$LtE;
t$PPVS
L$8_^][d
T$\WVR
jBWVSSQ
D$(_^]
\$ PQV
L$$_^][d
L$H_^][d
SWVVVRPV
L$$^]d
L$D_^[d
T$(Qh$
T$(Qh$
T$(Qh$
T$DWRh
D$,QRPS
L$$RPQS
L$<_^][d
L$(RPQ
NTRPQj
L$(RPQ
T$(PQR
D$(QRP
T$DPQRW
L$<RPQW
L$T_^]
Nh;NX|
Vh;VX|
Fxt_;FTu@
Nh;NX|
P$RWPh
D$0QVRP
L$$PVh
D$4RPQ
D$ PQR
=pscat
=YARGtD= BGRt
h BGRUPV
hYARGUQV
=lcmnw_tQ=tsbat-=knilt
=rtnmto
hknilUPV
htsbaUQV
=rtrpt =rncst
=capst
= baLt = ZYXt
TADIut
tkPUSV
ETLPuF
D$8QVRPU
QRVWPU
D$$SPh
3;L$4s
T$8QRU
L$Xh`[
T$,SRW
T$0;t$
PPPQSG
D$ EJ;
D$4SUVW
L$$QWV
D$0UhP
D$,Hx;@
D$(CM;
D$Hvm3
L$Lvj3
D$(FO;
L$t_^d
D$ RPUhD
L$l_^][d
L$$^[d
L$(WSR
T$0PQR
WjdjdPQh
|z;^<}uWS
L$D_^][d
L$\_^][d
It#Iu%
^l_^][
tI;Ftr
tL9~HvG;
~(9~$u
D/ VPS
L$<RWUQV
L$$j QV
L$(VQU
hPCCiU
L$(RPVQWU
l$,WuAS
|$ VurU
D$@QRPU
T$ PQW
Ht&HtcI
D$(SUW
=TADIt
TADIu"
hTADIV
Ht]Ht2Ht
HtfHt;Ht
t$,u%:D$<u
:L$<t;
\$$u9f;
\$@QUR
;=3333v
HtHHuz
V,_^[Y
D$ _^][
EHPWVS
u]9B uX
uR9BxuM
'9A`u"9
tq9~Dt
nd9~dt
tS9~@uN
T$LPQR
|$HPWS
L$(RPQ
T$DPVS
T$LRWS
Fdf+Fh
D$(8D*
tRHt}H
NH_^][
T$LWUQVR
L$4WQUVS
;l$ }:
|$$}$WP
\$\}-j
O(_^][
T$H} VP
T$$PRV
D$(QPW
L$,SUV
L$0SUV@W
NX9NXu
QPSWVR
T$PQRP
D$$SUV
D$(;l$
\$(UVW
D$,_^]
D$(CUSWP
9o4u'V
9t$0v8
T$,RWV
T$,RWV
T$,RWV
L$,QWV
T$,RWV
L$ RUPj
9t$Tu
T+3x%A
;D$<s!
T$,PQh
|$ WUSV
L$(SUV
N4_^]3
t.It+It
HDIt+It
|$DPPh
D$$j Ph
D$(j Ph
L$TUUj
L$<PQV
L$ Qj.j
L$ SVWPh
T$$QRVWUS
T$$QRVWUj
T$$QRVWUj
T$ QRVPWUS
D$$RPVWUS
\$4UVWS
T$<_^]
L$0][d
\$4UQPS
L$<PQR
D$8FtdW
\$4VWh
L$8_^[d
L$HRPWUQ
SUVWhH
L$$_^][d
L$8_^[d
L$<^[_]d
D$8QRP
" !
!!!!!
L$lQPR
L$8RPQ
L$8PQR
T$$RPQV
T$ URQPV
T$$RPQV
\$0UVW
D$PRPV
L$@j%Q
L$@j%Q
L$(_^]d
L$<_^]
T$<_^]
D$<_^]
L$<_^]
T$lPQR
T$$j%R
L$lRPQ
T$,IJQR
D$(IPQ
T$Pj%R
D$`PQR
L$$QPR
L$8_^]d
L$ QWPR
l$PVWU
L$0_^]d
\$(UVW
L$PQRP
T$`RPQ
T$8RPQ
L$PPPQ
T$PRPQ
D$`PQR
D$8PQR
L$0QSR
L$<_^[d
D$8QVRP
D$8QVRP
D$4WSP
D$4WSj
D$DWSUj
D$0QRP
L$,RPQ
T$,PQR
T$,PQR
JUHRPQ
BU@RPQ
\$dUVW
D$4PSQ
T$PRQP
L$(SPVW
L$ QUR
NLQj<P
t$ WPV
L$ _^[d
L$8RPQ
t$LPQR
L$4_^][d
D$HQRPW
L$4_^]d
D$0_^][
\$,UVW
L$d^_]
L$,RPQ
L$H_^][d
S#D$$SPQR
T$TSSR
L$P_^][d
D$$VPQ
T$ RSUP
t`Ht7Hu}
D$DSUV
?h3333S
T$`h33
?h3333R
L$@_^][d
D$hVPQ
L$@QWR
L$ PVWj
L$`_^][d
L$0UQW
D$Du)+
T$ SU3
L$ PSW
D$,FI;
L$D_^]
L$,QPR
L$(^][
T$8PWR
|$$~EW
L$,PRVQ
^lSj<P
D$Hu)+
L$T_^][d
L$XPPQ
|$LWQP
L$0_^]d
Fdf+Fh
~(9~$u
|$ WUSV
D$$SUV
T$LPQR
|$HPWS
L$(RPQ
T$DPVS
T$LRWS
T$,RWV
T$,RWV
T$,RWV
L$,QWV
T$,RWV
L$ RUPj
T$,PQh
L$(SUV
N4_^]3
j RPSW
D$ UPh
T$ URh
d$ SWR
T$ URh
L$ UQh
nd9^hu@
D$ UPh
WWWj(j(j<
L$HPQR
}?9\$0~9
L$HPQR
L$HPQR
L$h]_^[d
:;|$0}D
|$<UQVRW
L$h_^][d
L$8PQj
l$8;l$H}
L$(][_
T$,J9U
;l$T~?W
L$PUPQW
T$PPSRW
L$<_^][d
;l$(}OS
|^;\$,}&W
D$`SUV
L$8QUS
L$XQUS
T$DRQP
T$@RQP
T$@RQP
L$@_^]d
D$@PSQ
L$tQSW
D$0Pj<Q
L$$QPW
L$l_^][d
L$4Qj<R
l$(UPQ
|$(WPQ
L$p_^][d
D$ QPS
L$L_^]3
9\$,u5
D$4RPW
L$4PQW
L$4PQW
T$(WRQh4}
L$0WQR
L$l_^]d
L$P_^][d
L$p_^[d
L$P_^][d
L$p_^][d
L$@|-;
L$(SUV;
@;D$<~
T$ QWR
L$4PWQ
L$LPWQ
D$XRWP
D$`RWP
T$dQWR
L$hPWQ
T$XQWR
L$\PWQ
D$`RWP
L$x_^d
L$,_^d
D$0PQWS
L$ QPjNR
F<SSj1
L$8RUQ
L$P_^]
D$XWRVUP
T$XPQR
L$4_^][d
L$4RPQ
t$\9|$`
L$LPQR
D$<QRP
d$LPVQ
D$4uu=
D$XQRj
d$,RPQ
d$$PSQ
L$ QPjNR
L$ QPjNR
L$<SVW
<1\t}I
L$ PQS
T$8PRV
L$ PQV
D$`WRP
T$(WRh
L$P_^d
T$(WRh
L$P_^d
IPPQUPP
SSSSRUSS
L$ _^[d
T$ WVR
L$hWUVPQ
D$DPQU
~;l$ t
9\$<u<V
T$4j R
D$HPWU
D$$SUV
|$DWhx
@APBQRV
QWSRPh
L$$SQV
D$$=MZ
V<_^]3
D$(0jb
od_^]3
D$<h`jb
L$<h`jb
f9|$>t
D$<h`jb
u0_^][Y
T$0RWV
T$0RWV
T$0RWV
L$0QWV
T$0RWV
L$PRPQ
L$(RPQ
T$PRVS
9t$Tu
T+3x%A
;D$<s!
L$ RUPj
T$,PQh
D$0Qht
L$(SUV
N4_^]3
~(9~$u
D$ _^]
T$ _^]
D$DRPQ
L$PPQR
:te<\ta</t]SVW
L$DRSQ
L$,SQR
T$8QRU
T$8QRU
L$8PQU
D$8RPU
D$dUPh
RPVhhQ
RPQVhhQ
L$L^][d
L$(_^d
L$ _^[d
;D$xt(%
D$l_^][
PWRVPWQf
D$tKQMSUP
t#Hu1;{
T$<QPh
T$<PRh
L$XQSPUR
D$0WVQ
D$0QRWVP
T$@PQR
u+9Fdu&
te9Fhu`
L$8RPQ
T$$SWj
L$4SQh
^,~FH;
L$hRPQV
PPPPPPPPPPP
T$ PQRV
ND_^][
T$4PQR
L$@_^][d
Q#D$HRP
#D$DQRP
L$T_^d
T$4HPQR
L$DHAP
L$D@APQ
T$4PQR
L$LHIPQ
D$LJHRP
L$XQSPV
L$`_^[d
D$8SUVWt
j$SWRPj
Ph_^][
Rh_^][
D$(SUW
L$0PQR
L$0PQR
L$0PQR
L$pRPQ
D$hQRP
L$@_^][d
L$(RPQ
NTRPQj
L$(RPQ
T$(PQR
D$(QRP
T$DPQRW
L$<RPQW
L$T_^]
\$4t|Ht@H
T$ QRP
Ft_^][
^t_^][
T$(QRSU
tC9{dt
D$ _^]
uAUUUUj
GUUUVj
C<PQWR
9|$$t6
L$0RPVQ
D$(WPS
D$,WPS
L$8RPVQ
T$,WRS
T$8VRS
D$@VPS
thOt3Ot
<zv[<Ar
<ZvS<0r
<9vK<-tG<_tC<.t?<:t;</t7
T$ QRP
T$(QRU
T$,QRP
D$(RPU
T$,QRP
RQWPUV
T$@PQRUV
D$8t!j
T$$RPWUV
L$DQRPUV
D$ QSRPU
T$ PSQRU
D$ QSRPU
T$DSRWQh
D$4RPU
T$8QRP
D,@,QE
<fu&8M
\$LUVW
RUVh`)d
D$0PUVh
L$0PQh
t:It-P
D$,Rh$
T$0hMMS R
IDQWWPR
RQPj3V
L$DQUR
L$(PQVU
D$,WRP
|$DPWVU
L$PPWQ
D$,WRP
SUVWh4
D$$Vh(
SUVWjH
\$,WUS
T$ RVW
L$$QQP
SUVWh8
T$0QhH
L$0Ph4
T$HQRP
T$PRht
D$(Ph$
UWSPh`
D$0vT2
T$8RPQ
T$4PQR
<0|!<9
D$"EAB
SUVWjp
}\PWVQ
T$0u`U
V<j PR
F<j QP
T$HRj$
T$<RWP
D$ QRPW
T$ PQRW
D$(PQhD
L$,PhD
T$@SRhD
\$(UVW
L$4PUQ
D$$QRWVPU
T$@QRj
L$4PQj
T$4QRj
L$(PQj
T$8QRj
L$,PQj
D$lRPj
T$<QRj
T$dQRj
D$`RPj
T$0QRj
L$|PQj
T$XQRj
D$dRPj
T$4QRj
T$\QRj
D$DSUVW
D$DRPj
T$0QRj
L$`PQj
D$<RPj
T$(QRj
L$XPQj
D$@RPj
T$,QRj
L$\PQj
;t$<}
;t$<}8
D$(SUV
|$<tM;
T$8QRj
L$,PQj
T$,QRj
L$ PQj
T$,QRj
L$ PQj
L$dPQj
D$8RPj
D$\RPj
T$XQRj
L$,PQj
D$|RPj
L$PPQj
D$XRPj
T$,QRj
L$|PQj
T$PQRj
L$DSVW
D$DRPj
T$4QRj
L$dPQj
D$8RPj
T$(QRj
L$XPQj
D$8RPj
T$(QRj
L$XPQj
d$t_^][
F$@;F(v
F$@@;F(v
QQSVWj
QQSVWd
t.;t$$t(
B 02CV
C =02CVu
VC20XC00U
PPPPPPPP
^}%95`
uRFGHt
YHYtLHt9
tn<%t2
HHtiHtGH
HtHHt(
HtOHt)H
HtHt&Ht
QQSUVWj
_^][YY
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t/WWUPj
QQSVW3
QQSVW3
sO;>|C;~
HHtpHHtl
>Cu28V
tFGQPS
btHHt.
HSVHWtgHHtF
<]t_G<-uA
QQSVWj
>:uNFV
>:u#FV
,f9=\7
PPPPPPPP
PPPPPPPP
t+Ht$Ht
HtHHt
+ttHHtd
WQj1Pj
Vtvj0j
F PjPWj
F$PjQWj
F*PjTWj
F+PjUWj
F,PjVWj
F-PjWWj
F.PjRWj
tEj@Vh
F@j@Ph
uW9=,8
It[IItM
E WWWWS
zu^SSS
E VVVV
T$PRUh
L$(USRPQV
USPQRV
l$$VWU
T$$RSf
tj@SV
IQSPPj
Hu"WSV
uI8^Lu=
D$4PRh
L$$UQV
T$,WRV
D$$UPV
L$,WQV
<[uZGj]W
L$$Qh<
t$ t"3
NxZ;7sV
P3L$4Q
D$ PVV
T$<<%t
<ar7<fw3
<ar7<fw3
T$,_^]
D$,SUVW
<ari<fwe
D$,SUVW
<ari<fwe
D$Q}!;
D$XSUV
;L$0tI
tB;L$(u
D$0PUVRWQ
T$ SUV
\$ AFE;
t+IuDSV
;D$ t
;L$0t<
t5;L$(u
T$,PRVQWU
L$ QRU
D$$j:V
M<~u9;
\$DVj8
|F)D$$
|F)D$$
L$$SUV
D$(PVQW
T$4_^]
D$4_^]
L$$SUV
D$(PVQW
T$4_^]
D$4_^]
L$4_^]
\$$UVW
;L$$w(;L$$u
T$D_^]
\$$UVW
;L$$w(;L$$u
T$D_^]
L$D_^]
L$XSUVW3
;\$$t_
t ;D$,u'
T$0QRSPVU
D$09D$
L$ ;\$
D$$PQS
L$$_^]+
D$$_^][
CGE;t$
FCGE;|$
L$(_^]+
\$8UVW
L$$;L$4}
;L$$tU;L$(tO;L$ u
T$(SUVW3
T$ UVW
;T$$t=;T$(t7;T$ u
D$TPhXp
W(9W$u
tX9H tS9H$tN
Fdf+Fh
D$(8D*
~(9~$u
L$,;l$$
;D$4uY
;T$8tG;
;D$8tC;D$4uL;
L$0RPQSWUV
;T$4uV
;D$8tG;
L$$_^3
;D$8t?;D$4uH;
D$0QRPUWSV
|$ WUSV
t$4;L$
T$LPQR
|$LPWS
T$ PQR
T$PRWS
L$PQVS
T$,RWV
T$,RWV
T$,RWV
T$,RWV
L$ RUPj
9t$Tu
D$X98u
T+3x%A
;D$<s#
|$8t+\$
C(UVWj
T$,PQh
{4_^]3
nt2Ht#Ht
F`jBWP
F\jLSP
u$SShe
~\j<SW
ue;= 4
Wj(_Wj
hWj@_;
PQQQQQ
PPPPhd
tvWWWWU
F,_^][
(wqt\HHtS
t>Ht Ht
QSUVWj
n0SSSSU
_SSSSU
Ph_^][Y
tD9_Pt?
Ht#HHt
@t4Ht1Ht_Ht
^$_^[]
F(_+F$^[;E
9~4u@j
9~4u:j
F0_^][
<A|2<Z
<A|@<Z
+t|HtlHt\HtCHt%
+tJHt:Ht*
P<PuWSV
PWVWWW
9n$v(W3
F$;F uA
$C;_$r
F,;F8u6
N(;N,r
F0_^][
uK9{$t?
K,+C(;C,v4
C,9{$u
9^0u/j
F09^4u*j
F49^8u&j
^,_^][
shell32.dll
kernel32
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32
kernel32
kernel32.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
Winhttp.dll
ole32.dll
ole32.dll
Kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
User32.dll
kernel32.dll
kernel32.dll
ntdll.dll
psapi.dll
shlwapi.dll
user32
kernel32
kernel32
kernel32.dll
kernel32
kernel32
kernel32.dll
kernel32
kernel32
iphlpapi
kernel32
kernel32
kernel32
kernel32
IPHlpApi
kernel32.dll
kernel32
kernel32
kernel32
kernel32
kernel32
kernel32
kernel32
ntdll.dll
kernel32
kernel32
kernel32.dll
kernel32
user32
user32
user32
user32
Kernel32.dll
Kernel32.dll
user32
user32
user32.dll
user32
user32.dll
user32.dll
kernel32
ntdll.dll
user32
user32
user32
user32
user32
user32
user32.dll
user32
user32.dll
user32.dll
kernel32.dll
user32
user32
user32.dll
kernel32
user32.dll
user32
user32
user32
ole32.dll
ole32.dll
ole32.dll
kernel32
kernel32
kernel32
msdk.dll
msdk.dll
msdk.dll
msdk.dll
ole32.dll
msdk.dll
msdk.dll
msdk.dll
msdk.dll
msdk.dll
msdk.dll
msdk.dll
kernel32
kernel32.dll
ntdll.dll
kernel32.dll
ntdll.dll
kernel32.dll
ntdll.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
kernel32
kernel32
kernel32
kernel32.dll
kernel32.dll
ntdll.dll
ntdll.dll
kernel32
ntdll.dll
user32
ntdll.dll
kernel32
kernel32
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
user32.dll
user32
user32
ntdll.dll
ntdll.dll
ntdll.dll
kernel32.dll
ntdll.dll
kernel32
ntdll.dll
Kernel32.dll
ntdll.dll
user32
user32
user32
user32
user32
user32.dll
user32.dll
user32
user32
ntdll.dll
ntdll.dll
ntdll.dll
advapi32.dll
advapi32.dll
advapi32.dll
advapi32.dll
advapi32.dll
advapi32.dll
advapi32.dll
kernel32
user32
user32
user32
user32
kernel32.dll
ntdll.dll
user32
ntdll.dll
kernel32.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
user32.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
kernel32
ntdll.dll
ntdll.dll
ntdll.dll
kernel32
ntdll.dll
kernel32.dll
kernel32.dll
kernel32
psapi.dll
Shlwapi.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32
user32
user32
user32
user32
user32
user32
user32.dll
user32.dll
user32.dll
NTDLL.DLL
user32.dll
user32
user32.dll
user32
user32
user32.dll
msdk.dll
ntdll.dll
advapi32.dll
advapi32.dll
advapi32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
GetCurrentThreadId
GetModuleHandleA
GetProcAddress
StrCmpNA
IsBadReadPtr
VirtualAlloc
VirtualFree
LoadLibraryA
GetProcAddress
IsBadCodePtr
lstrlenA
lstrcpynA
WinHttpCheckPlatform
WinHttpCrackUrl
WinHttpOpen
WinHttpSetTimeouts
WinHttpConnect
WinHttpOpenRequest
WinHttpSetCredentials
WinHttpCloseHandle
WinHttpSetOption
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpQueryHeaders
CoInitialize
CoUninitialize
MultiByteToWideChar
WideCharToMultiByte
lstrlenW
lstrcpynA
CreateWaitableTimerA
SetWaitableTimer
MsgWaitForMultipleObjects
CloseHandle
lstrcpyn
RtlAdjustPrivilege
GetModuleFileNameExA
VirtualQuery
ReadProcessMemory
StrToIntExA
VirtualProtect
CoInitialize
MessageBoxTimeoutA
GetComputerNameA
GetVolumeInformationA
GlobalMemoryStatusEx
GetSystemInfo
GetDriveTypeA
GetDiskFreeSpaceExA
GetProcessHeap
HeapAlloc
GetAdaptersAddresses
HeapReAlloc
GlobalSize
RtlMoveMemory
HeapFree
GetAdaptersInfo
CreateFileA
DeviceIoControl
HeapAlloc
DeviceIoControl
HeapFree
CloseHandle
DeviceIoControl
DeviceIoControl
NtSetContextThread
TerminateProcess
OpenProcess
IsDebuggerPresent
GetStartupInfoA
GetMenu
GetMenuItemCount
GetSubMenu
GetMenuStringA
VirtualAlloc
VirtualFree
GetDesktopWindow
GetWindow
IsWindowVisible
GetWindowTextLengthA
GetWindowTextA
GetClassNameA
TerminateProcess
NtSetContextThread
GetMenu
GetMenuItemCount
GetSubMenu
GetMenuStringA
GetDesktopWindow
GetWindow
IsWindowVisible
GetWindowTextLengthA
GetWindowTextA
GetClassNameA
RtlMoveMemory
FindWindowExA
IsWindow
IsWindowVisible
GetWindowThreadProcessId
CreateToolhelp32Snapshot
Module32First
CloseHandle
EnumWindows
GetWindowThreadProcessId
GetWindowTextA
GetClassNameA
CoInitialize
CoInitializeEx
CoUninitialize
CreateIoCompletionPort
GetQueuedCompletionStatus
CloseHandle
M_Open_VidPid
M_ReleaseAllMouse
M_ReleaseAllKey
M_Close
CoInitializeEx
M_ResolutionUsed
M_LeftClick
M_RightClick
M_MoveTo3_D
M_KeyDown
M_KeyInputStringGBK
M_LeftDown
GetExitCodeThread
TerminateThread
GetCurrentProcessId
ZwTerminateProcess
TerminateProcess
GetCurrentProcessId
ZwQueryInformationProcess
OpenProcess
ZwOpenProcess
DebugActiveProcess
WaitForDebugEvent
ContinueDebugEvent
DebugActiveProcessStop
ZwQueryObject
ZwQuerySystemInformation
NtReadVirtualMemory
ZwWow64ReadVirtualMemory64
RtlMoveMemory
ZwQueryVirtualMemory
ZwQueryInformationProcess
ZwClose
GetHandleInformation
lstrlenW
lstrlenA
WideCharToMultiByte
WideCharToMultiByte
RtlMoveMemory
ZwDuplicateObject
GetVersionExA
GetSystemInfo
RtlGetNtVersionNumbers
GetSystemMetrics
RtlAdjustPrivilege
GetModuleHandleA
GetProcAddress
lstrcpyn
CreateDirectoryA
MoveFileA
ShellExecuteA
lstrcpyn
lstrcpyn
CreateWaitableTimerA
SetWaitableTimer
MsgWaitForMultipleObjects
CreateThread
SuspendThread
ResumeThread
MapVirtualKeyA
GetKeyNameTextA
SetParent
SendMessageTimeoutA
RtlMoveMemory
RtlMoveMemory
LdrGetDllHandleEx
MultiByteToWideChar
LdrLoadDll
MultiByteToWideChar
NtWriteVirtualMemory
ZwWow64WriteVirtualMemory64
RtlMoveMemory
ZwProtectVirtualMemory
PostMessageA
GetDesktopWindow
GetForegroundWindow
GetClassNameA
GetWindowTextLengthA
GetWindowTextA
SetWindowTextA
IsIconic
OpenIcon
SetWindowPos
ShowWindowAsync
GetWindowLongA
LdrGetProcedureAddress
LdrGetProcedureAddress
LdrUnloadDll
CryptAcquireContextA
CryptHashData
CryptCreateHash
CryptGetHashParam
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
CreateMutexA
WaitForSingleObject
SetTimer
SetWindowLongA
KillTimer
DispatchMessageA
CallWindowProcA
ReleaseMutex
ZwQueryInformationThread
PostThreadMessageA
ZwAllocateVirtualMemory
VirtualAllocEx
ZwCreateSection
ZwOpenDirectoryObject
ZwMapViewOfSection
ZwLockVirtualMemory
ZwUnmapViewOfSection
ZwUnlockVirtualMemory
GetCurrentThreadId
ZwSuspendThread
ZwYieldExecution
ZwQueryInformationThread
ZwSetInformationThread
ZwSetTimer
MsgWaitForMultipleObjects
ZwCreateTimer
ZwDelayExecution
ZwGetContextThread
RtlMoveMemory
RtlMoveMemory
ZwSetContextThread
ZwResumeThread
ZwAlertResumeThread
CreateRemoteThread
ZwWaitForSingleObject
ZwFreeVirtualMemory
ZwTerminateThread
ExitThread
OpenThread
ZwOpenThread
GetWindowThreadProcessId
CreateToolhelp32Snapshot
Module32First
CloseHandle
GetModuleFileNameExA
PathFindFileNameA
GetWindow
IsWindowEnabled
IsWindow
FindWindowA
FindWindowExA
GetCursorPos
ClientToScreen
IsWindowVisible
SetForegroundWindow
GetWindowRect
MoveWindow
ShowWindow
GetAncestor
ScreenToClient
GetWindowPlacement
GetClientRect
GetMenuBarInfo
AdjustWindowRectEx
WindowFromPoint
SwitchToThisWindow
SetActiveWindow
AttachThreadInput
RedrawWindow
EnumWindows
ZwQueryInformationProcess
MapVirtualKeyA
IsZoomed
GetDlgCtrlID
GetDlgItem
ChildWindowFromPointEx
IsWindowUnicode
SetPropA
GetLastActivePopup
M_MouseWheel
ZwClose
CreateFileA
OpenSCManagerA
CreateServiceA
OpenServiceA
CloseServiceHandle
StartServiceA
ControlService
DeleteService
DeviceIoControl
ReadProcessMemory
ReadProcessMemory
ReadProcessMemory
ReadProcessMemory
ReadProcessMemory
ReadProcessMemory
WriteProcessMemory
WriteProcessMemory
WriteProcessMemory
WriteProcessMemory
WriteProcessMemory
WriteProcessMemory
d09f2340818511d396f6aaf844c7e325
F7FC1AE45C5C4758AF03EF19F18A395D
27bb20fdd3e145e4bee3db39ddd6e64c
A512548E76954B6E92C21055517615B0
5F99C1642A2F4e03850721B4F5D7C3F8
{B6F7542F-B8FE-46a8-9605-98856A687097}
4BB4003860154917BC7D8230BF4FA58A
0B4337DA651B4b619ACF61334A7E8B47
7B68736E818E41c5A28B0AE4D43C128C
AF6AD80AA4244A59AFB3D83ECF5173CC
42305932-06E6-47a5-AC79-8BDCDC58DF61
52F260023059454187AF826A3C07AF2A
A6B983789F624b2cBDFD7D671249C097
7F54B9CE8887428dBA9CEEB94CEF4C72
707ca37322474f6ca841f0e224f4b620
80CF4A6B3E09425bA57935A3A0E4C473
window
EditBox
PicBox
GroupBox
Button
CheckBox
RadioBox
ComboBox
ListBox
ProcessBar
CommonDlg
ComObject
Variant
CPUInfo
HDInfo
TreeBox
ListView
TransLabel
PageControl
SuperBtn
RichEdit
Download
TaskParam
ntdll.dll
user32.dll
Information
Thread
Process
Object
Control
Device
Single
Create
!This program cannot be run in DOS mode.
H(9u$t|
go=?xh
#|_Mh >&
kH_{BW
U( q{`
haB oQ
H\f"O`
,o[.^5G
s&R[V_
Bx0`\60ImV<
S`\SR^
,i8c a
:",m@l}
4j]Fn(
c9&q^!-J\
ONNECT %s:%d HTTP/1.1
Proxy-Connecti
Keep-Alive:
Authoriza&BasicH$
d*C]te
etcp.dllkRSDS
C:\Users\Adminin
B4.2\Re
dCompleo
Status
IsBadRe
c(LastErro
loseHand
alize.
En`r8T]
6LwvNl[
len#ts
jit_fdiv
??2@YAPAXI@Z
_beg/th
rWSAItl
j*@.&%M
XPTPSW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PA
KERNEL32.DLL
MSVCRT.dll
USER32.dll
WS2_32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
wsprintfA
etcp.dll
@wsd12312@#%@@#@
@#@#wsdun8
10004|
10001||1|
where|and|=|>|<|set|select|'|insert|update|delete|union|drop|truncate|declare|xp_cmdshell|net user|exec|execute|xp_|sp_|?|eval|open|sysopen|system|&|join|union|like|create|modify|rename|alter|cas|convert|Array|root|char
http://pv.sohu.com/cityjson
", "cid": "
{"cip": "
"cname": "
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.87 Safari/537.36
http://www.ip138.com
<iframe src=
</title>
OPTIONS
DELETE
CONNECT
Cookies
User-Agent:
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept:
Accept: text/html, application/xhtml+xml, */*
Accept-Encoding:
Accept-Encoding: gbk, GB2312
Accept-Language:
Accept-Language: zh-cn
Content-Type:
Content-Type: application/x-www-form-urlencoded
Cache-Control:
Cache-Control: no-cache
Connection
keep-alive
Connection: keep-alive
Cookie:
Cookie:
Set-Cookie
Set-Cookie:
Location:
$@<meta.+?charset=[^\w]?([-\w]+)
gb2312
Adodb.Stream
Position
Charset
ReadText
WinHttp
WinHttp
WinHttp
WinHttp
=deleted
z>WinHttp.WinHttpRequest.5.1
SetTimeouts
SetProxy
Option
Accept:
Accept: */*
Referer:
Referer:
Accept-Language:
Accept-Language: zh-cn
User-Agent:
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
Content-Type: application/x-www-form-urlencoded
SetCredentials
Basic
Proxy-Authorization
SetRequestHeader
Cookie
ResponseBody
GetAllResponseHeaders
Status
StatusText
@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
10001|
10002|
10003|
10004|
10005|
10006|
10007|
10008|
10009|
10010|
10011|
10012|
10013|
10014|
10015|
10016|
10017|
10018|
10019|
10020|
10021|
10022|
10023|
10024|
10025|
10026|
10027|
10028|
10029|
10030|
10031|
10032|
10033|
10034|
10035|
10036|
10037|
10038|
10039|
10040|
10041|
10042|
10043|
10044|
10045|
10046|
10047|
10048|
10049|
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.53e334e1dc87b596
CAT-QuickHeal Clean
McAfee Artemis!53E334E1DC87
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus Trojan ( 005246d51 )
BitDefender Clean
K7GW Trojan ( 005246d51 )
Cybereason malicious.d9cfea
BitDefenderTheta Gen:NN.ZexaF.36106.@tW@aC9ZBhcH
VirIT Clean
Cyren W32/Trojan.CLL.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Trojanx-9951053-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
Cynet Malicious (score: 100)
ViRobot Clean
Rising Trojan.MalCert!1.DEC0 (CLASSIC)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo TrojWare.Win32.Agent.OSCF@5rs7jr
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.rc
Trapmine Clean
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
Antiy-AVL Trojan/Win32.FlyStudio.a
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan.PSE.18JA6Q4
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5242352
Acronis suspicious
VBA32 BScope.Adware.Agent
ALYac Clean
MAX Clean
Malwarebytes Generic.Crypt.Trojan.Malicious.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CKS22
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/CoinMiner.65CA!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.