Static | ZeroBOX

PE Compile Time

2023-06-07 16:20:37

PE Imphash

fa2c54be32e0285b8db051cf5be8246f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0006c628 0x0006d000 7.04062751591
.data 0x0006e000 0x00003ccc 0x00001000 0.0
.rsrc 0x00072000 0x000029a8 0x00003000 5.31262403696

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00072400 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x000723ec 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000720f0 0x000002fc LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarSub
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaStrI4
0x401014 __vbaVarMove
0x401018 __vbaVarVargNofree
0x40101c __vbaFreeVar
0x401020 __vbaAryMove
0x401024 __vbaLenBstr
0x401028 __vbaLineInputStr
0x40102c __vbaStrVarMove
0x401030 None
0x401034 __vbaEnd
0x401038 __vbaFreeVarList
0x40103c _adj_fdiv_m64
0x401040 __vbaNextEachVar
0x401044 __vbaFreeObjList
0x401048 _adj_fprem1
0x40104c __vbaVarCmpNe
0x401050 __vbaForEachCollAd
0x401054 __vbaStrCat
0x401058 __vbaError
0x40105c __vbaLsetFixstr
0x401060 __vbaSetSystemError
0x401064 __vbaLenBstrB
0x40106c __vbaNameFile
0x401070 __vbaLenVar
0x401074 _adj_fdiv_m32
0x401078 __vbaAryVar
0x40107c __vbaAryDestruct
0x401080 __vbaLateMemSt
0x401084 __vbaExitProc
0x401088 None
0x40108c None
0x401090 None
0x401094 __vbaObjSet
0x401098 __vbaOnError
0x40109c _adj_fdiv_m16i
0x4010a0 None
0x4010a4 None
0x4010a8 __vbaObjSetAddref
0x4010ac _adj_fdivr_m16i
0x4010b0 None
0x4010b4 None
0x4010b8 __vbaVarIndexLoad
0x4010bc None
0x4010c0 None
0x4010c4 None
0x4010c8 None
0x4010cc __vbaBoolVarNull
0x4010d0 __vbaRefVarAry
0x4010d4 __vbaVarTstLt
0x4010d8 _CIsin
0x4010dc None
0x4010e0 __vbaVargVarMove
0x4010e4 __vbaVarZero
0x4010e8 __vbaChkstk
0x4010ec None
0x4010f0 __vbaFileClose
0x4010f4 EVENT_SINK_AddRef
0x4010fc None
0x401100 __vbaStrCmp
0x401104 __vbaVarTstEq
0x401108 __vbaPutOwner3
0x40110c __vbaObjVar
0x401110 __vbaI2I4
0x401114 DllFunctionCall
0x401118 __vbaVarLateMemSt
0x40111c __vbaRedimPreserve
0x401120 __vbaLbound
0x401124 _adj_fpatan
0x401128 __vbaR4Var
0x40112c __vbaRedim
0x401130 EVENT_SINK_Release
0x401134 __vbaNew
0x401138 None
0x40113c _CIsqrt
0x401140 None
0x401148 __vbaVarMul
0x40114c __vbaExceptHandler
0x401150 None
0x401154 None
0x401158 None
0x40115c __vbaStrToUnicode
0x401160 _adj_fprem
0x401164 _adj_fdivr_m64
0x401168 None
0x40116c __vbaR8ErrVar
0x401170 None
0x401174 None
0x401178 None
0x40117c __vbaFPException
0x401180 __vbaUbound
0x401184 __vbaStrVarVal
0x401188 __vbaVarCat
0x40118c __vbaI2Var
0x401190 None
0x401194 None
0x401198 _CIlog
0x40119c __vbaErrorOverflow
0x4011a0 __vbaFileOpen
0x4011a4 __vbaNew2
0x4011a8 None
0x4011ac __vbaInStr
0x4011b0 __vbaR8Str
0x4011b4 __vbaVar2Vec
0x4011b8 None
0x4011bc _adj_fdiv_m32i
0x4011c0 None
0x4011c4 _adj_fdivr_m32i
0x4011c8 __vbaVarSetObj
0x4011cc __vbaStrCopy
0x4011d0 __vbaI4Str
0x4011d4 None
0x4011d8 __vbaVarNot
0x4011dc __vbaFreeStrList
0x4011e0 _adj_fdivr_m32
0x4011e4 _adj_fdiv_r
0x4011e8 None
0x4011ec None
0x4011f0 __vbaVarTstNe
0x4011f4 __vbaVarSetVar
0x4011f8 __vbaI4Var
0x4011fc __vbaAryLock
0x401200 __vbaLateMemCall
0x401204 __vbaVarAdd
0x401208 __vbaFreeVarg
0x40120c __vbaVarDup
0x401210 __vbaStrToAnsi
0x401214 None
0x40121c __vbaFpI4
0x401220 __vbaVarCopy
0x401224 None
0x401228 __vbaLateMemCallLd
0x40122c _CIatan
0x401230 __vbaAryCopy
0x401234 __vbaStrMove
0x401238 __vbaCastObj
0x40123c __vbaForEachVar
0x401240 None
0x401244 __vbaStrVarCopy
0x401248 _allmul
0x40124c _CItan
0x401250 __vbaNextEachCollAd
0x401254 None
0x401258 __vbaAryUnlock
0x40125c _CIexp
0x401260 __vbaFreeObj
0x401264 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
steamcmd
steamcmd
steamcmd
%wBb6X
3C4Bbr$D5
}M_!}S
s4NjHp
6<?$z_
1%mzZ[!
fFs?^a
~'j[u@
2Hl%>:mlSt
IbPKmRH
Nl{5+|
$l{a)D|
*Ee+DU
Y)P5ov
aj/_gN
1~jgFZ
%h%4mS
9AOVzLJ>
;'27@d
WK\?Xmu
1%$='C
97'8Ve~
4Uzmh{
{<Ga7X
OCqln:
M95:;)
JR$hg}O
M3~iws
8f2cm9
8f2cm9
8f2cm9
8f2cm9
8f2cm9
8f2cm9
8f2cm9
r`2{2@
0f2#my
gIE[hQ
0f2#my
0f2#my
0f2#my
0f2#my
0f2#my
0f2#my
%QW>\*
eNN+HnJ
U->dm.
+}kZ[m4
NOi2^N
v2csCrl
iU3}l:
4X2OoR
t[{]gDr_iYz`
[Woym7
gke'lg
Sb(/]
HAInJU
uJndWe
7gsLkk
W=O`08
/ifJz5
8_if_l)
I$8C1A`Q
rX!!64
7o)pYu
,MkiuFZV>
oJu(Yvn
gvrqk9
V~W (*
2y1b$k
mZJdTZ
W)NJy-
G;X2J!
w[rCn/F
)tSgc*3V
,Yrkm0
puWu/V
wf*Gh
o8f9OYb
l^KFL4
lvVkv!K
SKAR:4$Q[MN
6pM3M@
~YYHZ(
EmOY/!c8K
*,Gue=MF
?HbuD.
.iRi]a5
we.TrP
k/evVI
*[lZ?.
YwIO#Cg
33d'&XYYH
|y#~P@
2S1&-I-
P3{EQUI
jzpvrhH
ps8FF$
_t+''2@`bS
Xaf.Ke
jazaitiao
!123"A#ab
v"""!;&~
om#1s:
om#1s:
om#1s:
om#1s:
om#1s:
K7WDW*T
i6%uV?
][Jw]G*1
yX[AjP
9{n**+o
1Q34l}
"P.3M:
"P.3M:
"P.3M:
"P.3M:
"P.3M:
"P.3M:
%Wv*C-
[E*TG+
(Ek%N4
(Ek%N4
(Ek%N4
(Ek%N4
(Ek%N4
g6}f&k1
Timer1
Label2
Picture1
4f&y&S#
F1+,W6
vQI>rw
jihuocode
Image2
Image1
vb6chs.dll
202306071520
steamcmd
steamcmd
chkdpxA
chkdTuA
chkdownl@yA
chkdownl
timeGetTime
m_PathEnviro
modZip
sqlconn
Module1
httpdownload
steamcmd
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Image2
jazaitiao
Image1
jihuocode
Picture1
Label2
shell32.dll
ShellExecuteA
user32
ReleaseDC
ReleaseCapture
SendMessageA
CheckExist
DownloadFileA
jihuo_game
GetAdminRights
timeGetTime
kernel32
WideCharToMultiByte
FindWindowA
PostMessageA
winmm.dll
GetModuleFileNameA
GetCurrentDirectoryA
SHGetSpecialFolderLocation
shell32
SHGetPathFromIDListA
GetTempFileNameA
GetVolumeInformationA
advapi32.dll
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RegDeleteKeyA
RegDeleteValueA
closebtn
Label1
VBA6.DLL
__vbaLateMemSt
__vbaVarMul
__vbaVarAdd
__vbaR4Var
__vbaVarTstLt
__vbaVarTstNe
__vbaVarIndexLoad
__vbaAryDestruct
__vbaStrI2
__vbaPutOwner3
__vbaVar2Vec
__vbaAryMove
__vbaLateMemCallLd
__vbaStrToAnsi
__vbaNew
__vbaLenVar
__vbaLateMemCall
__vbaExitProc
__vbaVarTstEq
__vbaStrToUnicode
__vbaVarCopy
__vbaR8ErrVar
__vbaOnError
__vbaI2I4
__vbaSetSystemError
__vbaErrorOverflow
__vbaR8Str
__vbaStrVarCopy
__vbaNameFile
__vbaFpI4
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaVarSub
__vbaI4Var
__vbaInStr
__vbaFileClose
__vbaLineInputStr
__vbaFileOpen
__vbaFreeObjList
__vbaObjVar
__vbaObjSetAddref
__vbaVarSetVar
__vbaStrVarVal
__vbaVarMove
__vbaStrCmp
__vbaFreeStrList
__vbaStrCat
__vbaStrCopy
__vbaVarDup
__vbaCastObj
__vbaObjSet
__vbaFreeStr
__vbaEnd
__vbaFreeVar
__vbaStrMove
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
Image3
__vbaVarLateMemSt
(gamenamelab
user32.dll
SetWindowPos
GetSystemMetrics
GetDeviceCaps
{frm1.steamtoolspath}MirPack.dll
CreateZipFileA
UnZipFileA
Timer2
__vbaLbound
__vbaRefVarAry
__vbaUbound
__vbaAryUnlock
__vbaNextEachVar
__vbaVarLateMemCallLd
__vbaVarZero
__vbaForEachVar
__vbaNextEachCollAd
__vbaForEachCollAd
__vbaAryVar
__vbaAryCopy
__vbaLenBstrB
__vbaGenerateBoundsError
c:\temp\zlib.dll
unzOpen
unzClose
unzGetGlobalInfo
unzGetCurrentFileInfo
unzOpenCurrentFile
unzCloseCurrentFile
unzReadCurrentFile
unzGoToNextFile
RtlMoveMemory
CreateDirectoryA
__vbaLenBstr
__vbaAryLock
__vbaLsetFixstr
__vbaStrI4
__vbaRedim
__vbaVarNot
__vbaFreeVarg
__vbaVarCmpNe
__vbaI2Var
__vbaRedimPreserve
__vbaBoolVarNull
__vbaVarSetObj
__vbaI4Str
__vbaVargVarMove
__vbaError
__vbaVarVargNofree
steamcmd
Bb3CDE
R&1Ec#
$SW+9}
Yp6+i`
B]Wjek$v
ppoq^M
^kI\mJ/
VF3yj4
Q>A/3X
}a,'UH
V;+v6d
nyWO][n
rg+8QE
uW]uS]
SLfq.~
&c)o$e;
(SLdF&
(SLdF&
#U46nb
_7U0c1
_7U0c1
_7U0c1
_7U0c2
Timer2
Timer1
closebtn


aR#3Sc4
steamcmd
Adobe Photoshop CS2 Windows
2023:04:13 12:55:17
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
Photoshop 3.0
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
slicesVlLs
sliceIDlong
groupIDlong
originenum
ESliceOrigin
autoGenerated
Typeenum
ESliceType
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
urlTEXT
nullTEXT
MsgeTEXT
altTagTEXT
cellTextIsHTMLbool
cellTextTEXT
horzAlignenum
ESliceHorzAlign
default
vertAlignenum
ESliceVertAlign
default
bgColorTypeenum
ESliceBGColorType
topOutsetlong
leftOutsetlong
bottomOutsetlong
rightOutsetlong
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
9http://ns.adobe.com/xap/1.0/
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="3.1.1-111">
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about=""
xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">
<xapMM:DocumentID>uuid:8244A45AB7D9ED11984AB22CDF56F849</xapMM:DocumentID>
<xapMM:InstanceID>uuid:8344A45AB7D9ED11984AB22CDF56F849</xapMM:InstanceID>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:xap="http://ns.adobe.com/xap/1.0/">
<xap:CreateDate>2023-04-13T10:46:12+08:00</xap:CreateDate>
<xap:ModifyDate>2023-04-13T12:55:17+08:00</xap:ModifyDate>
<xap:MetadataDate>2023-04-13T12:55:17+08:00</xap:MetadataDate>
<xap:CreatorTool>Adobe Photoshop CS2 Windows</xap:CreatorTool>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>image/jpeg</dc:format>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/">
<photoshop:ColorMode>3</photoshop:ColorMode>
<photoshop:History/>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:tiff="http://ns.adobe.com/tiff/1.0/">
<tiff:Orientation>1</tiff:Orientation>
<tiff:XResolution>720000/10000</tiff:XResolution>
<tiff:YResolution>720000/10000</tiff:YResolution>
<tiff:ResolutionUnit>2</tiff:ResolutionUnit>
<tiff:NativeDigest>256,257,258,259,262,274,277,284,530,531,282,283,296,301,318,319,529,532,306,270,271,272,305,315,33432;6858D3D7D290CCCFE62589231144649C</tiff:NativeDigest>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:exif="http://ns.adobe.com/exif/1.0/">
<exif:PixelXDimension>384</exif:PixelXDimension>
<exif:PixelYDimension>150</exif:PixelYDimension>
<exif:ColorSpace>-1</exif:ColorSpace>
<exif:NativeDigest>36864,40960,40961,37121,37122,40962,40963,37510,40964,36867,36868,33434,33437,34850,34852,34855,34856,37377,37378,37379,37380,37381,37382,37383,37384,37385,37386,37396,41483,41484,41486,41487,41488,41492,41493,41495,41728,41729,41730,41985,41986,41987,41988,41989,41990,41991,41992,41993,41994,41995,41996,42016,0,2,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,20,22,23,24,25,26,27,28,30;938D3D70FC13FDD0DFDDC4821826BBE0</exif:NativeDigest>
</rdf:Description>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end="w"?>
!Adobe
@4D5E
iMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiH
################/
/N6OO-P
o^+{8?
K[[c[YK
;c/+##
=#&Ow'/
.K6Ecq
Timer1
closebtn


aR#3Sc4
Label2
Label1
steamcmd
Adobe Photoshop CS2 Windows
2023:04:13 12:55:17
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
Photoshop 3.0
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
slicesVlLs
sliceIDlong
groupIDlong
originenum
ESliceOrigin
autoGenerated
Typeenum
ESliceType
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
urlTEXT
nullTEXT
MsgeTEXT
altTagTEXT
cellTextIsHTMLbool
cellTextTEXT
horzAlignenum
ESliceHorzAlign
default
vertAlignenum
ESliceVertAlign
default
bgColorTypeenum
ESliceBGColorType
topOutsetlong
leftOutsetlong
bottomOutsetlong
rightOutsetlong
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
9http://ns.adobe.com/xap/1.0/
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="3.1.1-111">
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about=""
xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">
<xapMM:DocumentID>uuid:8244A45AB7D9ED11984AB22CDF56F849</xapMM:DocumentID>
<xapMM:InstanceID>uuid:8344A45AB7D9ED11984AB22CDF56F849</xapMM:InstanceID>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:xap="http://ns.adobe.com/xap/1.0/">
<xap:CreateDate>2023-04-13T10:46:12+08:00</xap:CreateDate>
<xap:ModifyDate>2023-04-13T12:55:17+08:00</xap:ModifyDate>
<xap:MetadataDate>2023-04-13T12:55:17+08:00</xap:MetadataDate>
<xap:CreatorTool>Adobe Photoshop CS2 Windows</xap:CreatorTool>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>image/jpeg</dc:format>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/">
<photoshop:ColorMode>3</photoshop:ColorMode>
<photoshop:History/>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:tiff="http://ns.adobe.com/tiff/1.0/">
<tiff:Orientation>1</tiff:Orientation>
<tiff:XResolution>720000/10000</tiff:XResolution>
<tiff:YResolution>720000/10000</tiff:YResolution>
<tiff:ResolutionUnit>2</tiff:ResolutionUnit>
<tiff:NativeDigest>256,257,258,259,262,274,277,284,530,531,282,283,296,301,318,319,529,532,306,270,271,272,305,315,33432;6858D3D7D290CCCFE62589231144649C</tiff:NativeDigest>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:exif="http://ns.adobe.com/exif/1.0/">
<exif:PixelXDimension>384</exif:PixelXDimension>
<exif:PixelYDimension>150</exif:PixelYDimension>
<exif:ColorSpace>-1</exif:ColorSpace>
<exif:NativeDigest>36864,40960,40961,37121,37122,40962,40963,37510,40964,36867,36868,33434,33437,34850,34852,34855,34856,37377,37378,37379,37380,37381,37382,37383,37384,37385,37386,37396,41483,41484,41486,41487,41488,41492,41493,41495,41728,41729,41730,41985,41986,41987,41988,41989,41990,41991,41992,41993,41994,41995,41996,42016,0,2,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,20,22,23,24,25,26,27,28,30;938D3D70FC13FDD0DFDDC4821826BBE0</exif:NativeDigest>
</rdf:Description>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end="w"?>
!Adobe
@4D5E
iMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiH
################/
/N6OO-P
o^+{8?
K[[c[YK
;c/+##
=#&Ow'/
.K6Ecq
Timer1
closebtn


aR#3Sc4
Label2
Label1
steamcmd
Adobe Photoshop CS2 Windows
2023:04:13 12:55:17
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
Photoshop 3.0
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
slicesVlLs
sliceIDlong
groupIDlong
originenum
ESliceOrigin
autoGenerated
Typeenum
ESliceType
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
urlTEXT
nullTEXT
MsgeTEXT
altTagTEXT
cellTextIsHTMLbool
cellTextTEXT
horzAlignenum
ESliceHorzAlign
default
vertAlignenum
ESliceVertAlign
default
bgColorTypeenum
ESliceBGColorType
topOutsetlong
leftOutsetlong
bottomOutsetlong
rightOutsetlong
Adobe_CM
dEU6te
'7GWgw
)m)m))
pKk?t}
9http://ns.adobe.com/xap/1.0/
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="3.1.1-111">
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about=""
xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">
<xapMM:DocumentID>uuid:8244A45AB7D9ED11984AB22CDF56F849</xapMM:DocumentID>
<xapMM:InstanceID>uuid:8344A45AB7D9ED11984AB22CDF56F849</xapMM:InstanceID>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:xap="http://ns.adobe.com/xap/1.0/">
<xap:CreateDate>2023-04-13T10:46:12+08:00</xap:CreateDate>
<xap:ModifyDate>2023-04-13T12:55:17+08:00</xap:ModifyDate>
<xap:MetadataDate>2023-04-13T12:55:17+08:00</xap:MetadataDate>
<xap:CreatorTool>Adobe Photoshop CS2 Windows</xap:CreatorTool>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>image/jpeg</dc:format>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/">
<photoshop:ColorMode>3</photoshop:ColorMode>
<photoshop:History/>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:tiff="http://ns.adobe.com/tiff/1.0/">
<tiff:Orientation>1</tiff:Orientation>
<tiff:XResolution>720000/10000</tiff:XResolution>
<tiff:YResolution>720000/10000</tiff:YResolution>
<tiff:ResolutionUnit>2</tiff:ResolutionUnit>
<tiff:NativeDigest>256,257,258,259,262,274,277,284,530,531,282,283,296,301,318,319,529,532,306,270,271,272,305,315,33432;6858D3D7D290CCCFE62589231144649C</tiff:NativeDigest>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:exif="http://ns.adobe.com/exif/1.0/">
<exif:PixelXDimension>384</exif:PixelXDimension>
<exif:PixelYDimension>150</exif:PixelYDimension>
<exif:ColorSpace>-1</exif:ColorSpace>
<exif:NativeDigest>36864,40960,40961,37121,37122,40962,40963,37510,40964,36867,36868,33434,33437,34850,34852,34855,34856,37377,37378,37379,37380,37381,37382,37383,37384,37385,37386,37396,41483,41484,41486,41487,41488,41492,41493,41495,41728,41729,41730,41985,41986,41987,41988,41989,41990,41991,41992,41993,41994,41995,41996,42016,0,2,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,20,22,23,24,25,26,27,28,30;938D3D70FC13FDD0DFDDC4821826BBE0</exif:NativeDigest>
</rdf:Description>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end="w"?>
!Adobe
@4D5E
iMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiMiH
################/
/N6OO-P
o^+{8?
K[[c[YK
;c/+##
=#&Ow'/
.K6Ecq
Timer1
closebtn


aR#3Sc4
Label2
Label1
steamcmd
6nWF'+7
.=D0,p
">mzJHP
Fz[vlXI
w[&7=L~k
Et[oLX
Z+8WsBYm
d[*-_T
ajqQv]
dku?3
T<*jBY
K8{)tz
fK\(-B
k ?XGM*~L
^d&3 {{D
UXb^%w
$0l(nMEH
(pS+pHM
2=lm6<B
iccqgD
lNr%6^
Vm7bA3
D}D[6l
Emcg{zes
lI&Lcz
HmP.JK
|uUO!m
{/i%Rk
pl)?Z]5
qUx_d5
=6Rl|&
S]k]el
TJS'p[
YmU3Vl*
SycsqH
@BY,Ry=
k}w=cH
@{9*K%>sr\
&:i lvq
UOkWmWX
,Sh)1E
hk1-j\
VYgfm)]
U.bpppihFj
b[i/m5&
o=VB{(T
)XQml+
d}yQ3j
asK|VW
nsR0mY
<;y.@iZ5
"h'(<"k
}}mjy%'-
)_Mp[Q
<Rm+Bf
&=BI-g
/KeqIV
n($s<GP
/bQc/1
K(o(V(
UOZY]uX
F%@{Zk
qW.dlN
xHU trT
*AU@-j0
"""#TSM:
oxaBKc
HywZjr,
LmgeHSi
9*cK5rF
)\}+YYj_-
p]jqL-
AP4;:t
mfOgMle
bthP!JY
$"1y bc-2
5H/{vIq'
,Ky[ke0
Ez5$9-
1ND;;X[d
X=ZY)
=tZ>oUum
yS.*u8
]B{2(+
*Fw=WvDE
_/A"wG(
&|y%?%
s7jg3U
$6rdA T
$0-wY-
@jEoXR2
X/Bfr%
to*8Ve
nnq~3&
{Ik+8=
+`|x:D
c&8C}3
c&8C}3
c&8C}3
c&8C}3
c&8C}3
c&8C}3
c&8C}3
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
;#0wS>
s"8Gu3
FggnzF
FggnzF
FggnzF
FggnzF
FggnzF
FggnzF
fUvrPO7
Hm~iDqQ
BCQk-/
pl#VdJ1
Db:pl#L
?%z~vs
}3k`?.
GMT>xS
%2#"8G
%2#"8G
%2#"8G
%2#"8G
%2#"8G
%2#"8G
%2#"8G
ia4~Jl
kTXb6s
F0AVUe
Rvvl&e
tK[b*5=b~
b<>?d
jazaitiao
4Io}ii*
ctNloEl
QO"2FnIn[y'
-I6k<K
T-v@(*
T-v@(*
T-v@(*
T-v@(*
T-v@(*
T-v@(*
nn(<*r
nn(<*r
nn(<*r
nn(<*r
nn(<*r
Timer1
Label2
steam,
Picture1


gamenamelab
Label1
Microsoft Sans Serif
Image2
Image1
steamcmd
s4NjHp
o?J\[n
u;EvU]
7GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
GcwM<a
iZYuizQu
qArU<YS
SkTnUcJ
[SQuT&
pnaysz
14IMa.
[MVY[:S
+[]vpk8[
#"P'd?
6F|}2&
#|kb%{CY
fMdo*F
BStu4w
RS!YnU6
ymS nl:
4na*5Rb%
y+X\1#9
%uUeg5
2=oe[>
H-fms[
T9)XQ
smI2jympMs
:2)ioHl<
iuiuiM}
+u)m+ZS
J6W4r?
_jr6_m
R&O :^Q7
90mw]
jJW/US
VSSYSQ
g&fcUz
vuvm-
jMWj]EA
O7u]k.
-2nsm^m
GnGjEHN.
BLTei;
M9oY|M
+4S]1b
aaKra_P)u
rZCkqf
@t8>8u>
qE,NrcMD
pPc9pTx
/XYw[u;
psDK_|SzRo
MZlv91H
w;\MFM
QG]eL,
!bWumM
$77't\J
q(_.HY
Xf2cm:
Xf2cm:
Pf2#mz
Pf2#mz
Pf2#mz
Pf2#mz
Pf2#mz
Pf2#mz
Pf2#mz
we4u_n
{z7R/,
A;vM&wSl
14E+AI
CjRM\j
gp7kv
s!!^lu
ZfjMq|u
Qh8aby[
,Aed5l
+znIU*ZyP
FFkQY6
,ovm=2
lYX]w6l[
GT'TuJ6
I6at:}_
ke\pnVUrXA
/"MeW5
+cvph{
HYq.apL}cd=
ensuez
#0)w|}%*
k%T|u!r
+oxjSzU
mOlJU#
jjkbk)B
10K=2g
k~_O]mM
Qzw%/f
4bnQs-
_*sGbs_
(R6^e6
Ns/$8\
_(~Qf8
c#jsop2
4$oppLy
jWjUX>
s}qj{T
npV{65m`
~9S_TXS
|Y6[#,
wPu*/Y
gV~QJ
Qck:5jQTX
4TF}9=7
_t+''2@`bi
Image3
p<z^+#
BZY$gv=K;
Image2
Adobe Photoshop CS2 Windows
2023:05:16 13:30:21
Adobe_CM
dEU6te
'7GWgw
8Photoshop 3.0
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
slicesVlLs
sliceIDlong
groupIDlong
originenum
ESliceOrigin
autoGenerated
Typeenum
ESliceType
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
urlTEXT
nullTEXT
MsgeTEXT
altTagTEXT
cellTextIsHTMLbool
cellTextTEXT
horzAlignenum
ESliceHorzAlign
default
vertAlignenum
ESliceVertAlign
default
bgColorTypeenum
ESliceBGColorType
topOutsetlong
leftOutsetlong
bottomOutsetlong
rightOutsetlong
Adobe_CM
dEU6te
'7GWgw
http://ns.adobe.com/xap/1.0/
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="3.1.1-111">
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about=""
xmlns:xapMM="http://ns.adobe.com/xap/1.0/mm/">
<xapMM:DocumentID>uuid:3B38FEB0AAF3ED11AB98C6BF7427B279</xapMM:DocumentID>
<xapMM:InstanceID>uuid:3E38FEB0AAF3ED11AB98C6BF7427B279</xapMM:InstanceID>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:xap="http://ns.adobe.com/xap/1.0/">
<xap:CreateDate>2023-04-13T11:54:20+08:00</xap:CreateDate>
<xap:ModifyDate>2023-05-16T13:30:21+08:00</xap:ModifyDate>
<xap:MetadataDate>2023-05-16T13:30:21+08:00</xap:MetadataDate>
<xap:CreatorTool>Adobe Photoshop CS2 Windows</xap:CreatorTool>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>image/jpeg</dc:format>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/">
<photoshop:ColorMode>3</photoshop:ColorMode>
<photoshop:History/>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:tiff="http://ns.adobe.com/tiff/1.0/">
<tiff:Orientation>1</tiff:Orientation>
<tiff:XResolution>720000/10000</tiff:XResolution>
<tiff:YResolution>720000/10000</tiff:YResolution>
<tiff:ResolutionUnit>2</tiff:ResolutionUnit>
<tiff:NativeDigest>256,257,258,259,262,274,277,284,530,531,282,283,296,301,318,319,529,532,306,270,271,272,305,315,33432;E453EF4EA8503E7005AA3834459B6FEF</tiff:NativeDigest>
</rdf:Description>
<rdf:Description rdf:about=""
xmlns:exif="http://ns.adobe.com/exif/1.0/">
<exif:PixelXDimension>12</exif:PixelXDimension>
<exif:PixelYDimension>12</exif:PixelYDimension>
<exif:ColorSpace>-1</exif:ColorSpace>
<exif:NativeDigest>36864,40960,40961,37121,37122,40962,40963,37510,40964,36867,36868,33434,33437,34850,34852,34855,34856,37377,37378,37379,37380,37381,37382,37383,37384,37385,37386,37396,41483,41484,41486,41487,41488,41492,41493,41495,41728,41729,41730,41985,41986,41987,41988,41989,41990,41991,41992,41993,41994,41995,41996,42016,0,2,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,20,22,23,24,25,26,27,28,30;20545712AB0728F2574ED96FF3829469</exif:NativeDigest>
</rdf:Description>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end="w"?>
!Adobe
Image1


aR#3Sc4
steamcmd
chkdownload1
chkdownload2
gameid
gamename
jihuocode_gx
steamtoolspath
mytools
deviceid
steamuser
windows_system
companyexe
myprogramname
mytoolszip
checkdownload
steampath
sFilePath
steamzip
show_width
show_height
jhhPXA
j`hPXA
jdhPXA
jThdWA
jXhPXA
jPhPXA
jXhPXA
Rh@cA
j8hTjA
j8hTjA
j8hTjA
j8hTjA
j8hTjA
j4hTjA
j4hTjA
j8hTjA
j8hTjA
j4hTjA
j4hTjA
tzhTmA
BpPhlnA
QpRhXoA
HpQh8oA
QpRhlnA
QpRhlnA
jPhPXA
jXhPXA
j<hPqA
jXh4uA
j|hPxA
jthPxA
jfjBj
jXhPxA
jXhPXA
jXh yA
jfjBj
jfjBj
j4hTjA
j4hTjA
j4hTjA
QRPj?PP
MSVBVM60.DLL
__vbaVarSub
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaFreeVar
__vbaAryMove
__vbaLenBstr
__vbaLineInputStr
__vbaStrVarMove
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaNextEachVar
__vbaFreeObjList
_adj_fprem1
__vbaVarCmpNe
__vbaForEachCollAd
__vbaStrCat
__vbaError
__vbaLsetFixstr
__vbaSetSystemError
__vbaLenBstrB
__vbaHresultCheckObj
__vbaNameFile
__vbaLenVar
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaLateMemSt
__vbaExitProc
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaBoolVarNull
__vbaRefVarAry
__vbaVarTstLt
_CIsin
__vbaVargVarMove
__vbaVarZero
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
__vbaI2I4
DllFunctionCall
__vbaVarLateMemSt
__vbaRedimPreserve
__vbaLbound
_adj_fpatan
__vbaR4Var
__vbaRedim
EVENT_SINK_Release
__vbaNew
_CIsqrt
EVENT_SINK_QueryInterface
__vbaVarMul
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaR8ErrVar
__vbaFPException
__vbaUbound
__vbaStrVarVal
__vbaVarCat
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
__vbaInStr
__vbaR8Str
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaVarSetObj
__vbaStrCopy
__vbaI4Str
__vbaVarNot
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaFreeVarg
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaLateMemCallLd
_CIatan
__vbaAryCopy
__vbaStrMove
__vbaCastObj
__vbaForEachVar
__vbaStrVarCopy
_allmul
_CItan
__vbaNextEachCollAd
__vbaAryUnlock
_CIexp
__vbaFreeObj
__vbaFreeStr
Adk-11.0.
F*\AC:\Users\Administrator\vb
CD,ClientName,CmdCmdLine,CmdExtversion,ComSpec,Date,Time,ErrorLevel,HomeDrive,HomePath,HomeShare,LogonSever,Number_Of_Processors,OS,Path,PathExt,Processor_Architecture,Processor_Identifier,Processor_Level,Processor_Revision,Prompt,Random,SessionName,SystemDrive,SystemRoot,TEMP,TMP,ComputerName,UserDomain,UserName,Public,ProgramW6432,ProgramFiles(x86),FP_NO_HOST_CHECK
cmd /c taskkill /f /im Steam.exe
cmd /c taskkill /f /im ui32.exe
cmd /c taskkill /f /im steam.exe
\Stool\
c:\temp\
c:\temp
\Stool\Simulator\
\Stool\zip\
WScript.Shell
&H80000001
SOFTWARE\Valve\Steam
SteamPath
status
\package\
\userdata\
\config\
\userdata\config\
info.pak,Legit.pak,config.ini,steamsimulator.dll
http://119.45.172.253:2158/update/myodbc3.dll
myodbc3.dll
http://119.45.172.253:2158/update/steamrepairnet.exe
steamrepairnet.exe
http://119.45.172.253:2158/update/sqlite3odbc.dll
sqlite3odbc.dll
http://119.45.172.253:2158/update/version.dll
version.dll
\depotcache\
\config\config.vdf
depots
RecentTCPFailures
{
win10 system
}
beta_old
&H80000002
SOFTWARE\Microsoft\Windows NT\CurrentVersion
CurrentBuildNumber
win7 system
win11 system
AutoLoginUser
nosave
\Simulator\
c:\temp\steamrepairnet.exe
114.132.46.210
sql_114_132_46_2
RTs3jPBwBe4EBNYf
DRIVER={MySQL ODBC 3.51 Driver};SERVER=
;DATABASE=
;OPTION=3;port=
;charset=gbk;
Select * from stms_jihuo where status= 0 and jihuocode = '
update_time
deviceid
steamuser
windows_system
gameid
gamename
Select * from stms_jihuo where status= 1 and jihuocode = '
' and deviceid = '
MSXML2.XMLHTTP
Status
responseBody
WinHTTP.WinHTTPRequest.5.1
http://119.45.172.253:2158/getdir.php?gameid=
Scripting.FileSystemObject
zip\key.txt
OpenTextFile
AtEndOfStream
ReadLine
info.pak
zip\info.pak
\info.pak
mysql_odbc_3_5.reg
steamsimulator.dll
config.ini
Legit.pak
TicketsID.pak
hid.dll
config.vdf
\config
steamcmd.exe
ADODB.Stream
SaveToFile
http://114.55.3.236/steam/steamcmd.exe
SubFolders
Visible
c:\temp\xfb
Delete
http://114.55.3.236/xfbao/xfb
cmd /c taskkill /f /im
Wallpaper UI
cmd /c taskkill /f /im wallpaper32.exe
cmd /c taskkill /f /im Steam++.exe
GetFolder
Wscript.Shell
SpecialFolders
ExpandEnvironmentStrings
DRIVER=SQLite3 ODBC Driver;Database=
SELECT * FROM Appinfo
MoveNext
Driver={SQLite3 ODBC Driver};Database=
INSERT OR REPLACE INTO Appinfo (appid, type) VALUES ('
','1');
RegOpenKeyEx error:
SOFTWARE\Valve\Steamtools
config
dword:00000001
menber
c:\\temp\\sqlite3odbc.dll
hex:53,54,ab,07,00,00,00,00,0d,0f,3e,03,70,00,00,00,78,9c,b3,fe,b6,9a,9d,01,08,de,b0,31,30,d8,01,69,46,24,0c,03,e8,7c,64,c0,82,a6,8e,10,00,00,4e,7c,03,1e,3b,f6
Opentime
dword:6465024c
HookHex
dword:00000000
Pinisok
hex:00,00,98,01,00,00,00,00,0d,0f,3e,03,09,00,00,00,78,9c,6b,d9,3a,83,91,01,08,4c,01,0e,b8,02,08,84,b5
SOFTWARE\WOW6432Node\MySQL AB\MySQL Connector/ODBC 3.51
Version
3.51.17
SOFTWARE\WOW6432Node\ODBC\ODBCINST.INI\SQLite3 ODBC Driver
SOFTWARE\WOW6432Node\ODBC\ODBCINST.INI\MySQL ODBC 3.51 Driver
UsageCount
Driver
C:\\temp\\myodbc3.dll
C:\\temp\\myodbc3s.dll
SOFTWARE\WOW6432Node\ODBC\ODBCINST.INI\ODBC Drivers
MySQL ODBC 3.51 Driver
Installed
responseText
http://119.45.172.253:2158/game/
\inventory\
http://119.45.172.253:2158/work/
http://119.45.172.253:2158/update/
Key.txt
key.txt
.manifest
jiazai
Adobe Photoshop
Adobe Photoshop CS2
jiazai
Adobe Photoshop
Adobe Photoshop CS2
jiazai
Adobe Photoshop
Adobe Photoshop CS2
zuixiaohua
Adobe Photoshop
Adobe Photoshop CS2
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
Comments
update
CompanyName
FileDescription
update
LegalCopyright
update
LegalTrademarks
update
ProductName
steamcmd
FileVersion
8.02.0020
ProductVersion
8.02.0020
InternalName
202306071520
OriginalFilename
202306071520.exe
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic Clean
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.67425254
FireEye Trojan.GenericKD.67425254
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.67425254
Cylance unsafe
Zillya Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.67425254
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/ABRisk.WJMV-3983
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Clean
F-Secure Clean
Baidu Clean
VIPRE Trojan.GenericKD.67425254
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.dx
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.67425254 (B)
SentinelOne Clean
Jiangmin Clean
Webroot W32.Trojan.Genkd
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Trojan/Script.Wacatac
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D404D3E6
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Trojan.GenericKD.67425254
Google Detected
AhnLab-V3 Trojan/Win.Generic.R586089
Acronis Clean
VBA32 BScope.Trojan.Tiggre
TACHYON Clean
Malwarebytes Malware.AI.907529702
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CFA23
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.