Static | ZeroBOX

PE Compile Time

2023-03-31 13:56:26

PE Imphash

0c0bf875cff14bd91891adb5675ade14

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x002ab948 0x002ac000 7.24858733009
.rdata 0x002ad000 0x007ef5f6 0x007f0000 7.59581111814
.data 0x00a9d000 0x00169ac2 0x000d1000 6.4676102281
.rsrc 0x00c07000 0x0000c988 0x0000d000 5.05956881978

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x00c08f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x00c08f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x00c08f78 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
WAVE 0x00c0e060 0x00001448 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_CURSOR 0x00c0f5f8 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED AmigaOS bitmap font
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x00c0b5e0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00c0f748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x00c0f748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x00c0f748 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294967295, next used block 4294967295
RT_MENU 0x00c0a5a8 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x00c0a5a8 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00c0a0f0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00c0bff8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x00c0acc0 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_ICON 0x00c094f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00c094f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00c094f8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library WINMM.dll:
0x6ad7d0 midiStreamRestart
0x6ad7d4 waveOutRestart
0x6ad7d8 PlaySoundA
0x6ad7dc midiStreamStop
0x6ad7e0 midiOutReset
0x6ad7e4 midiStreamClose
0x6ad7f0 waveOutWrite
0x6ad7f4 waveOutPause
0x6ad7f8 waveOutReset
0x6ad7fc midiStreamOut
0x6ad804 midiStreamProperty
0x6ad808 midiStreamOpen
0x6ad810 waveOutOpen
0x6ad814 waveOutGetNumDevs
0x6ad818 waveOutClose
Library WS2_32.dll:
0x6ad830 inet_ntoa
0x6ad834 inet_addr
0x6ad838 gethostname
0x6ad83c gethostbyname
0x6ad840 WSAStartup
0x6ad844 WSACleanup
0x6ad848 send
0x6ad84c closesocket
0x6ad850 WSAAsyncSelect
0x6ad854 htons
0x6ad858 bind
0x6ad85c htonl
0x6ad860 socket
0x6ad864 setsockopt
0x6ad868 sendto
0x6ad86c recvfrom
0x6ad870 ioctlsocket
0x6ad874 connect
0x6ad878 recv
0x6ad87c listen
0x6ad880 getpeername
0x6ad884 accept
0x6ad888 __WSAFDIsSet
0x6ad88c ntohs
0x6ad890 getsockname
0x6ad894 WSAGetLastError
0x6ad898 ntohl
0x6ad89c select
Library MSVFW32.dll:
0x6ad49c DrawDibDraw
Library AVIFIL32.dll:
0x6ad028 AVIStreamInfoA
0x6ad02c AVIStreamGetFrame
Library RASAPI32.dll:
0x6ad4f8 RasHangUpA
Library KERNEL32.dll:
0x6ad1f4 SetLastError
0x6ad1fc GetLocaleInfoA
0x6ad200 GetVersion
0x6ad204 TerminateThread
0x6ad208 IsDBCSLeadByte
0x6ad20c lstrcmpA
0x6ad210 lstrcmpiA
0x6ad214 lstrcpynA
0x6ad228 GetFileType
0x6ad22c MapViewOfFile
0x6ad230 CreateFileMappingA
0x6ad234 DuplicateHandle
0x6ad238 UnmapViewOfFile
0x6ad240 GetLocalTime
0x6ad248 SetFileTime
0x6ad24c LocalFree
0x6ad250 FormatMessageA
0x6ad254 CreateMutexA
0x6ad258 ReleaseMutex
0x6ad25c SuspendThread
0x6ad268 FlushFileBuffers
0x6ad26c LockFile
0x6ad270 UnlockFile
0x6ad274 SetEndOfFile
0x6ad278 GlobalDeleteAtom
0x6ad27c GlobalFindAtomA
0x6ad280 GlobalAddAtomA
0x6ad284 GlobalGetAtomNameA
0x6ad288 LocalAlloc
0x6ad28c TlsAlloc
0x6ad290 GlobalHandle
0x6ad294 TlsFree
0x6ad298 TlsSetValue
0x6ad29c LocalReAlloc
0x6ad2a0 TlsGetValue
0x6ad2a4 GetFileTime
0x6ad2a8 GetCurrentThread
0x6ad2ac GlobalFlags
0x6ad2b0 GetProfileIntA
0x6ad2b4 SetErrorMode
0x6ad2b8 GetProcessVersion
0x6ad2bc GetCPInfo
0x6ad2c0 GetOEMCP
0x6ad2c4 GetStartupInfoA
0x6ad2c8 RtlUnwind
0x6ad2cc GetSystemTime
0x6ad2d0 RaiseException
0x6ad2d4 HeapSize
0x6ad2d8 ExitThread
0x6ad2dc GetACP
0x6ad2e0 SetStdHandle
0x6ad2f8 SetHandleCount
0x6ad2fc GetStdHandle
0x6ad304 HeapDestroy
0x6ad308 HeapCreate
0x6ad30c VirtualFree
0x6ad318 LCMapStringA
0x6ad31c LCMapStringW
0x6ad320 VirtualAlloc
0x6ad324 IsBadWritePtr
0x6ad32c GetStringTypeA
0x6ad330 GetStringTypeW
0x6ad334 CompareStringA
0x6ad338 CompareStringW
0x6ad33c IsBadReadPtr
0x6ad340 IsBadCodePtr
0x6ad344 IsValidLocale
0x6ad348 IsValidCodePage
0x6ad34c EnumSystemLocalesA
0x6ad350 GetLocaleInfoW
0x6ad358 WaitNamedPipeA
0x6ad35c OpenFileMappingA
0x6ad360 OpenEventA
0x6ad368 TerminateProcess
0x6ad36c GetCurrentProcess
0x6ad370 GetFileSize
0x6ad374 SetFilePointer
0x6ad378 CreateSemaphoreA
0x6ad37c ResumeThread
0x6ad380 ReleaseSemaphore
0x6ad38c GetProfileStringA
0x6ad390 WriteFile
0x6ad398 CreateFileA
0x6ad39c SetEvent
0x6ad3a0 FindResourceA
0x6ad3a4 LoadResource
0x6ad3a8 LockResource
0x6ad3ac ReadFile
0x6ad3b0 lstrlenW
0x6ad3b4 GetModuleFileNameA
0x6ad3b8 WideCharToMultiByte
0x6ad3bc MultiByteToWideChar
0x6ad3c0 GetCurrentThreadId
0x6ad3c4 ExitProcess
0x6ad3c8 GlobalSize
0x6ad3cc GlobalFree
0x6ad3d8 lstrcatA
0x6ad3dc lstrlenA
0x6ad3e0 WinExec
0x6ad3e4 lstrcpyA
0x6ad3e8 FindNextFileA
0x6ad3ec GetDriveTypeA
0x6ad3f0 GlobalReAlloc
0x6ad3f4 HeapFree
0x6ad3f8 HeapReAlloc
0x6ad3fc GetProcessHeap
0x6ad400 HeapAlloc
0x6ad404 GetUserDefaultLCID
0x6ad408 GetFullPathNameA
0x6ad40c FreeLibrary
0x6ad410 LoadLibraryA
0x6ad414 GetLastError
0x6ad418 GetVersionExA
0x6ad424 CreateThread
0x6ad428 CreateEventA
0x6ad42c Sleep
0x6ad430 GlobalAlloc
0x6ad434 GlobalLock
0x6ad438 GlobalUnlock
0x6ad43c FindFirstFileA
0x6ad440 FindClose
0x6ad444 SetFileAttributesA
0x6ad448 GetFileAttributesA
0x6ad44c MoveFileA
0x6ad450 DeleteFileA
0x6ad454 CopyFileA
0x6ad458 CreateDirectoryA
0x6ad468 GetModuleHandleA
0x6ad46c GetProcAddress
0x6ad470 MulDiv
0x6ad474 GetCommandLineA
0x6ad478 GetTickCount
0x6ad47c CreateProcessA
0x6ad480 WaitForSingleObject
0x6ad484 CloseHandle
0x6ad488 InterlockedExchange
0x6ad48c MapViewOfFileEx
Library USER32.dll:
0x6ad50c SetMenuItemBitmaps
0x6ad514 LoadStringA
0x6ad518 GetSysColorBrush
0x6ad51c LoadIconA
0x6ad520 TranslateMessage
0x6ad524 DrawFrameControl
0x6ad528 DrawEdge
0x6ad52c DrawFocusRect
0x6ad530 WindowFromPoint
0x6ad534 GetMessageA
0x6ad538 DispatchMessageA
0x6ad53c SetRectEmpty
0x6ad54c DrawIconEx
0x6ad550 CreatePopupMenu
0x6ad554 AppendMenuA
0x6ad558 ModifyMenuA
0x6ad55c CreateMenu
0x6ad564 GetDlgCtrlID
0x6ad568 GetSubMenu
0x6ad56c EnableMenuItem
0x6ad570 ClientToScreen
0x6ad578 LoadImageA
0x6ad580 ShowWindow
0x6ad584 IsWindowEnabled
0x6ad58c GetKeyState
0x6ad594 PostQuitMessage
0x6ad598 IsZoomed
0x6ad59c GetClassInfoA
0x6ad5a0 DefWindowProcA
0x6ad5a4 GetSystemMenu
0x6ad5a8 DeleteMenu
0x6ad5ac GetMenu
0x6ad5b0 SetMenu
0x6ad5b4 PeekMessageA
0x6ad5b8 IsIconic
0x6ad5bc SetFocus
0x6ad5c0 GetActiveWindow
0x6ad5c4 GetWindow
0x6ad5cc SetWindowRgn
0x6ad5d0 GetMessagePos
0x6ad5d4 CheckMenuItem
0x6ad5dc CopyRect
0x6ad5e0 LoadBitmapA
0x6ad5e4 KillTimer
0x6ad5e8 SetTimer
0x6ad5ec ReleaseCapture
0x6ad5f0 GetCapture
0x6ad5f4 SetCapture
0x6ad5f8 GetScrollRange
0x6ad5fc SetScrollRange
0x6ad600 SetScrollPos
0x6ad604 SetRect
0x6ad608 InflateRect
0x6ad60c IntersectRect
0x6ad610 DestroyIcon
0x6ad614 PtInRect
0x6ad618 OffsetRect
0x6ad61c IsWindowVisible
0x6ad620 EnableWindow
0x6ad624 GetWindowLongA
0x6ad628 SetWindowLongA
0x6ad62c GetSysColor
0x6ad630 SetActiveWindow
0x6ad634 SetCursorPos
0x6ad638 LoadCursorA
0x6ad63c SetCursor
0x6ad640 GetDC
0x6ad644 FillRect
0x6ad648 InvertRect
0x6ad64c IsRectEmpty
0x6ad650 ReleaseDC
0x6ad654 IsChild
0x6ad658 TrackPopupMenu
0x6ad65c DestroyMenu
0x6ad660 SetForegroundWindow
0x6ad664 GetWindowRect
0x6ad668 EqualRect
0x6ad66c UpdateWindow
0x6ad670 ValidateRect
0x6ad674 InvalidateRect
0x6ad678 GetClientRect
0x6ad67c GetFocus
0x6ad680 GetParent
0x6ad684 GetTopWindow
0x6ad688 PostMessageA
0x6ad68c IsWindow
0x6ad690 SetParent
0x6ad694 DestroyCursor
0x6ad698 SendMessageA
0x6ad69c SetWindowPos
0x6ad6a0 MessageBeep
0x6ad6a4 MessageBoxA
0x6ad6a8 GetCursorPos
0x6ad6ac GetSystemMetrics
0x6ad6b4 EmptyClipboard
0x6ad6b8 SetClipboardData
0x6ad6bc OpenClipboard
0x6ad6c0 GetClipboardData
0x6ad6c4 CloseClipboard
0x6ad6c8 wsprintfA
0x6ad6cc WaitForInputIdle
0x6ad6d0 IsDialogMessageA
0x6ad6d4 ScrollWindowEx
0x6ad6d8 SendDlgItemMessageA
0x6ad6dc MapWindowPoints
0x6ad6e0 AdjustWindowRectEx
0x6ad6e4 ScrollWindow
0x6ad6e8 GetScrollInfo
0x6ad6ec SetScrollInfo
0x6ad6f0 ShowScrollBar
0x6ad6f4 GetScrollPos
0x6ad6f8 RegisterClassA
0x6ad6fc CreateWindowExA
0x6ad700 GetClassLongA
0x6ad704 RemovePropA
0x6ad708 GetMessageTime
0x6ad70c GetLastActivePopup
0x6ad714 GetWindowPlacement
0x6ad718 EndDialog
0x6ad720 DestroyWindow
0x6ad724 EndPaint
0x6ad728 BeginPaint
0x6ad730 wvsprintfA
0x6ad734 GetForegroundWindow
0x6ad738 GetNextDlgTabItem
0x6ad73c CharUpperA
0x6ad740 GetDoubleClickTime
0x6ad744 ClipCursor
0x6ad748 SetWindowTextA
0x6ad74c GetMenuItemCount
0x6ad750 GetMenuItemID
0x6ad754 GetMenuStringA
0x6ad758 GetMenuState
0x6ad760 DrawStateA
0x6ad764 GrayStringA
0x6ad768 TabbedTextOutA
0x6ad76c WindowFromDC
0x6ad770 EnumChildWindows
0x6ad774 GetWindowDC
0x6ad778 UnhookWindowsHookEx
0x6ad77c CallNextHookEx
0x6ad780 SetWindowsHookExA
0x6ad784 FrameRect
0x6ad788 GetPropA
0x6ad78c MoveWindow
0x6ad790 CallWindowProcA
0x6ad794 SetPropA
0x6ad798 DrawTextA
0x6ad79c UnregisterClassA
0x6ad7a0 GetWindowTextA
0x6ad7a4 FindWindowExA
0x6ad7a8 GetDlgItem
0x6ad7ac GetClassNameA
0x6ad7b0 ScreenToClient
0x6ad7b4 GetDesktopWindow
0x6ad7b8 WinHelpA
0x6ad7bc RedrawWindow
0x6ad7c0 GetCursor
Library GDI32.dll:
0x6ad074 GetViewportExtEx
0x6ad078 ExtSelectClipRgn
0x6ad07c CopyMetaFileA
0x6ad080 GetCurrentObject
0x6ad084 RoundRect
0x6ad08c DPtoLP
0x6ad090 LPtoDP
0x6ad094 Rectangle
0x6ad098 Ellipse
0x6ad09c SetPixelV
0x6ad0a0 CreateCompatibleDC
0x6ad0a4 GetPixel
0x6ad0a8 BitBlt
0x6ad0ac StartPage
0x6ad0b0 StartDocA
0x6ad0b4 DeleteDC
0x6ad0b8 EndDoc
0x6ad0bc EndPage
0x6ad0c0 GetObjectA
0x6ad0c4 GetStockObject
0x6ad0c8 CreateFontIndirectA
0x6ad0cc CreateSolidBrush
0x6ad0d0 FillRgn
0x6ad0d4 CreateRectRgn
0x6ad0d8 CombineRgn
0x6ad0dc PatBlt
0x6ad0e0 CreatePen
0x6ad0e4 SelectObject
0x6ad0e8 CreatePatternBrush
0x6ad0ec CreateBitmap
0x6ad0f0 CreateBrushIndirect
0x6ad0f4 CreateDCA
0x6ad0fc GetPolyFillMode
0x6ad100 GetStretchBltMode
0x6ad104 GetROP2
0x6ad108 GetBkColor
0x6ad10c GetBkMode
0x6ad110 GetTextColor
0x6ad114 CreateRoundRectRgn
0x6ad118 CreateEllipticRgn
0x6ad11c PathToRegion
0x6ad120 EndPath
0x6ad124 BeginPath
0x6ad128 GetWindowOrgEx
0x6ad12c GetViewportOrgEx
0x6ad130 GetWindowExtEx
0x6ad134 GetDIBits
0x6ad138 RealizePalette
0x6ad13c SelectPalette
0x6ad140 StretchBlt
0x6ad144 CreatePalette
0x6ad14c CreateDIBitmap
0x6ad150 DeleteObject
0x6ad154 SelectClipRgn
0x6ad158 CreatePolygonRgn
0x6ad15c GetClipRgn
0x6ad160 SetStretchBltMode
0x6ad164 SetPixel
0x6ad168 CreateDIBSection
0x6ad170 SetBkColor
0x6ad174 SetBkMode
0x6ad178 SetTextColor
0x6ad17c SetWindowOrgEx
0x6ad180 SaveDC
0x6ad184 RestoreDC
0x6ad188 CreatePenIndirect
0x6ad18c PtVisible
0x6ad190 RectVisible
0x6ad194 TextOutA
0x6ad198 ExtTextOutA
0x6ad19c Escape
0x6ad1a0 GetTextMetricsA
0x6ad1a4 AbortDoc
0x6ad1a8 CreateFontA
0x6ad1ac SetBrushOrgEx
0x6ad1b0 SetDIBitsToDevice
0x6ad1b4 SetPolyFillMode
0x6ad1b8 SetROP2
0x6ad1bc SetMapMode
0x6ad1c0 SetViewportOrgEx
0x6ad1c4 OffsetViewportOrgEx
0x6ad1c8 SetViewportExtEx
0x6ad1cc ScaleViewportExtEx
0x6ad1d0 OffsetWindowOrgEx
0x6ad1d4 SetWindowExtEx
0x6ad1d8 ScaleWindowExtEx
0x6ad1dc GetClipBox
0x6ad1e0 ExcludeClipRect
0x6ad1e4 MoveToEx
0x6ad1e8 LineTo
0x6ad1ec GetDeviceCaps
Library MSIMG32.dll:
0x6ad494 GradientFill
Library WINSPOOL.DRV:
0x6ad820 ClosePrinter
0x6ad824 DocumentPropertiesA
0x6ad828 OpenPrinterA
Library comdlg32.dll:
0x6ad8b0 GetFileTitleA
0x6ad8b4 PrintDlgA
0x6ad8b8 GetOpenFileNameA
0x6ad8bc ChooseFontA
0x6ad8c0 ChooseColorA
0x6ad8c4 GetSaveFileNameA
Library ADVAPI32.dll:
0x6ad000 RegCreateKeyExA
0x6ad004 RegQueryValueA
0x6ad008 RegDeleteKeyA
0x6ad00c RegDeleteValueA
0x6ad010 RegSetValueExA
0x6ad014 RegOpenKeyExA
0x6ad018 RegQueryValueExA
0x6ad01c RegCloseKey
0x6ad020 RegEnumValueA
Library SHELL32.dll:
0x6ad500 Shell_NotifyIconA
0x6ad504 ShellExecuteA
Library ole32.dll:
0x6ad8cc CoTaskMemAlloc
0x6ad8d0 OleDuplicateData
0x6ad8d4 RevokeDragDrop
0x6ad8dc OleGetClipboard
0x6ad8e4 OleFlushClipboard
0x6ad8e8 OleSetClipboard
0x6ad8ec CoTaskMemFree
0x6ad8f0 ReleaseStgMedium
0x6ad8f4 CLSIDFromProgID
0x6ad8f8 OleInitialize
0x6ad8fc OleUninitialize
0x6ad900 CLSIDFromString
0x6ad908 CoCreateInstance
0x6ad90c OleRun
0x6ad910 DoDragDrop
Library OLEAUT32.dll:
0x6ad4a4 VarDateFromStr
0x6ad4a8 RegisterTypeLib
0x6ad4ac SafeArrayPutElement
0x6ad4b0 LHashValOfNameSys
0x6ad4b4 LoadTypeLib
0x6ad4bc SafeArrayAccessData
0x6ad4c0 SafeArrayGetElement
0x6ad4c4 VariantCopyInd
0x6ad4c8 VariantInit
0x6ad4cc SysAllocString
0x6ad4d0 SafeArrayDestroy
0x6ad4d4 SafeArrayCreate
0x6ad4d8 VariantClear
0x6ad4dc VariantChangeType
0x6ad4e0 SafeArrayGetUBound
0x6ad4e4 SafeArrayGetLBound
0x6ad4e8 SafeArrayGetDim
0x6ad4ec UnRegisterTypeLib
Library COMCTL32.dll:
0x6ad034 ImageList_Duplicate
0x6ad03c ImageList_Draw
0x6ad040 ImageList_Read
0x6ad048 ImageList_Create
0x6ad04c ImageList_Destroy
0x6ad050 None
0x6ad054 ImageList_AddMasked
0x6ad058 _TrackMouseEvent
0x6ad060 ImageList_GetIcon
Library WSOCK32.dll:
0x6ad8a4 shutdown
0x6ad8a8 getservbyname
Library WININET.dll:
0x6ad7c8 InternetCloseHandle

!This program cannot be run in DOS mode.
.rdata
@.data
l -?Z0
Xqv7t
Xqn7t?
Xqf7ty
Xqn7t
XqZ7t:
Xqf7t
Xqn7t
{G['7t
Xqz7tX
Xqr7t@
vc%'D$
XqJ7t-
Xq:7t
{G['7t
d<'/X.
d '/Xi
l8'7/.
l('7/l
jEXvck
{G['7t(
{G['7tl
Xq~7t"
{G['7t&
{G['7t
{G['7t
{G['7t
XqR7t
XqF7t
{G['7t
{G['7ts
jEXvck
{G['7t
G['7t
{G['7t
G['7t/
{G['7t
{G['7t
{G['7tB
{G['7tb
Xqr7tF
G['7t
Xqn7tT
Xqv7t
{G['7t
Xqj7t
{G['7t
Xq~7t
Xqn7t
Xqr7t
&t$s%"
(tNS$"
G['7t
*tR>%"
G['7t
{G['7t
{G['7t+
{G['7t?
{G['7t
{G['7t
{G['7t
{G['7tY
[k0r%lzGj*j
{G['7t`
{G['7t
{G['7t
{G['7t
{G['7t
{G['7tj
{G['7t
{G['7t
{G['7t
(tGS$"
(tIS$"
(tKS$"
(ttS$"
{G['7tt
{G['7t
{G['7t
{G['7t
{G['7t6
{G['7tZ
{G['7tZ
izcwHN
{G['7t
{G['7te
G['7t
{G['7t
{G['7ta
G['7t
{G['7t
{G['7t]
G['7t
{G['7t
{G['7tY
G['7t
{G['7t
{G['7tU
G['7t
{G['7t
{G['7t
{G['7t`
{G['7t/
{G['7t
{G['7t
{G['7t
{G['7t
G['7ta
{G['7t
{G['7t
{G['7t
{G['7t
{G['7t(
{G['7tv
{G['7t
{G['7t
{G['7t
%nygcm$
Xqv7t
XqJ7t
{G['7t
{G['7t
{G['7t
{G['7t
G['7tZ
{G['7t
{G['7t
{G['7t
Xqr7t
GV{_%op
{G['7t;
{G['7t
{G['7t
{G['7tm
{G['7t
{G['7t
G['7tS
G['7t
G['7t
G['7tU
G['7t
G['7t
G['7t
{G['7t
G['7t6
G['7t
G['7t
G['7t8
G['7t
G['7t
G['7t
{G['7t
i~6e(36}
{G['7t
6e,36}
{G['7tW
{G['7tn
G['7t
G['7t
G['7t<
$"?Z6m
Xq~7t
Xqz7t
{G['7tk
EXvck
{G['7t
G['7t~
{G['7t~
G['7t
{G['7t>
G['7t
{G['7t
{G['7t
%(4?Zf0
G['7t
QjDr\%
Xqr7tu
G['7t
Xqr7t
G['7t
G['7t
G['7t
G['7tq
G['7t;
Xqv7t
G['7t|
G['7t
G['7t
G['7t
G['7t
G['7t
G['7t
G['7t
G['7t
G['7ta
G['7ta
G['7ta
G['7ta
G['7ta
G['7ta
G['7ta
G['7ta
G['7ta
Xq~7t
Xq~7t
Xqv7t
Xqn7t
G['7t>
QN4e`a
6#?c6}
{G['7t
{G['7t
{G['7tF
{G['7t
G['7tk
{G['7tk
Qn6}(%
o$?c8e
Qf6}(%
G['7tR
{G['7t
(tr>%"
G['7tR
{G['7td
{G['7t
{G['7t
G['7te
{G['7t]
G['7tf
{G['7t
{G['7t?
{G['7t
{G['7t
{G['7t
G['7t
{G['7t
{G['7tw
{G['7t
3t,P!"
t*?%"
3ti?%"
{G['7t
{G['7t
t*?%"
3ti?%"
{G['7t=
{G['7t
{G['7t
{G['7tu
{G['7t_
{G['7t
G['7t
{G['7tC
3tM?%"
t??%"
3t~?%"
EXvck
{G['7t
{G['7t
{G['7tu
{G['7tt
{G['7th
{G['7t7
{G['7t=
{G['7t#
{G['7t
{G['7t
{G['7t
G['7t;
G['7tU
G['7t
G['7t
G['7t
G['7t
i^6} %
tZ?%"
3t??%"
{G['7tV
{G['7t
{G['7tm
{G['7t
{G['7td
2t)d!"
{G['7t
{G['7t
G['7t
G['7t
{G['7t
{G['7t
{G['7t8
{G['7t
{G['7t
tM?%"
3t>?%"
t~?%"
{G['7tV
{G['7t
G['7t
G['7t~
G['7tZ
G['7t
G['7tX
G['7tg
{G['7t
{G['7t]
(to>%"
(tm>%"
{G['7t
{G['7t7
{G['7t
{G['7t
{G['7t
{G['7t<
{G['7t
{G['7t0
{G['7t
G['7t7
G['7t$
G['7tJ
G['7t
G['7t0
G['7tK
G['7t
3t!?%"
tb?%"
iRcVoM
{G['7t^
G['7t
G['7t
G['7t
G['7t
G['7t
G['7t
G['7tf
G['7t
G['7tg
G['7t
G['7t
{G['7t
{G['7t
{G['7t
{G['7t
{G['7t0
{G['7t
{G['7t
{G['7t>
{G['7t
{G['7t
3t"?%"
ta?%"
iRcVoM
{G['7tt
jEXvck
{G['7t
G['7tP
{G['7t
{G['7t
{G['7t
{G['7t
{G['7t
tS?%"
3t8?%"
{G['7t
{G['7t
t0?%"
3tq?%"
3t8?%"
tx?%"
(tm>%"
(to>%"
G['7t
G['7t
t1?%"
3tp?%"
3t7?%"
t~?%"
(to>%"
(tm>%"
{G['7t
{G['7t
{G['7t
{G['7tk
t[?%"
(tk>%"
(to>%"
G['7t
G['7t
G['7t
G['7tf
G['7tH
{G['7t
{G['7t
{G['7tq
{G['7t
{G['7t
{G['7te
G['7t4
{G['7t4
{G['7t
{G['7tJ
G['7t
{G['7t
{G['7t
G['7tU
{G['7t,
G['7t
G['7t
tM?%"
3t>?%"
t~?%"
tZ?%"
3t??%"
(to>%"
(tk>%"
G['7t
EXvck
{G['7t
{G['7t@
G['7t
G['7t
G['7t0
G['7t~
{G['7t
{G['7t
{G['7t
{G['7t
(tG@%"
(tG@%"
{G['7t
iZ6} %
{G['7t
{G['7t@
{G['7t
{G['7t8
{G['7t<
{G['7tn
{G['7tn
{G['7t
{G['7t
{G['7t
{G['7tE
{G['7ti
{G['7tz
{G['7t
{G['7t+
{G['7t
{G['7t?
{G['7tZ
{G['7t6
{G['7t
{G['7t
{G['7tz
{G['7t
{G['7t
{G['7t_
{G['7t
{G['7t
{G['7tF
G['7t=
{G['7t
{G['7t
ij6} %
aJ6} %
{G['7t
{G['7t
{G['7t
?Zn2N
;c%'D$a
6mj/j6
|iGk)"
C,%D$
C,%D$
;?c5.j#
C,%D$
CP%#\?l0
1#D<%v
sb%D8
PGj)$7`6
%D8%'D$%
gG[4d0
6mj/k6
6li/b4l0
7`8l0
]%y]
p_%y_
/\4e %
s\%z_
6f$%!,
tb%D$
o$G]/
6.Ge4l0
%D '&(
j%n}g]6
H]6k t
l$Gb!'
uc%&(?
#Gk!-7[6
8w<%sr
6w<%sr
G?c6v(
*-G]($?Z
*-G]($?Z
pb%D$
*6iHt
8n\#'D$#
6']%z]
#Gk!-7[6
k$G[!'
k$G[!'
C0%Dt
6a|]6a(
#Gk!37[f$
#Gk!,7[6
#Gk!,7[6
8wt%sr
k$G[!'
6wx%sr
*BG](9
/G],\
*EG](<
/G],\
p^`/Dp
G_ $?Z
D `/Dd
&^`/Dl
#Gk!-7[6
CD%q~g
/Ga,\
#Gk!37[f$
#Gk!,7[6
C<%q~g
6']%z]
#Gk!37[f$
#Gk!,7[6
/G_,\
*-G]($?Z
G]4fh
*-G]($?Z
?%Dp%
C4%'Dl
/G],\
#Gk!-7[6
k$G[!'
\4v0%*8
uGb4g`%
C$#'D(#'D,#'DD#'DH
6']%z]
C?Z8l0
6']%z]
6gPa/D(
6f('?D
#Gk!-7[6
k$G[!'
#Gk!-7[6
6w,%sr
k$G[!'
k$G[!'
o(?Zm0
c(-?c4
C a/Dh
C$`/Dh
8n\#)l
#Gk!-7[6
8w0%sr
k$G[!'
k$G[!'
k$G[!'
k%n~g\
k%n~g\
G]4ft
8nL#'D$a
4>G]4~
6']%z]
#Gk!-7[6
k$G[!'
k$G[!'
k$G[!'
k$G[!'
k%n~g\
k%n~g\
G]4ft
/G],\
6']%z]
#Gk!-7[6
k$G[!'
k$G[!'
k$G[!'
#Gk!-7[6
g?u4d0
6li/[4fX
r6~d%?D
*0Gg($?c
6+G[(0
8vP%yr
C$%zr\
6']%z]
8nD#)P
#Gk!-7[6
m$Gj!'
*6Ge(*?c4nX
4f|%?D
6']%z]
Gd'*?c0
u)7c%y
?l57S
C`#Dda
#'Dl#'D
u)7c%y
?l57S
C`#Dda
#'Dl#'D
u)7c%y
?l57S
C`#Dda
#'Dl#'D
?u8nh
l (?c6$
#Gj(Cb%
3?u4|0
G_-\
&('''(%
/G],\
?u8t0
6h(%?D
Ct#Dt
%rq\%vg
tb%D
uc%'D 
60a%s
?7[4d0
6li/b4l0
C<%'D8%
l6Gm-
#D4#D8
CL#D\
Z)'T#2
#Gk!37[f$
#Gk!,7[6
8w<%sr
8wt%sr
k$G[!'
k$G[!'
Z `?u8d0
*-G_($?Z
*-G_($?Z
*DG_(;?Z6
C0%pr\
G]#\
\#'D,a
G])=r%
#'Dl#'D|#'D
#'Dt#'Dx
CT%DL
#'D`#'Dx#'D|
*[#'D
6/Gb0]
6e(#D,
?u8d0
Gb &E
DD%'D0[
~j]4'k
Z *b%v
_ 9HE #
uc%'D 
[Gb(,7[
WG[).7[8t0
C `/D
IDTk
#/_6M
C #'DD
tb%D<
k$G[!'
#Gk!,7[6
\%'DD
*6atk
%'D0%v
Ga4e
8mj/j33
CD%'D<
o0Ga4d0
vc%'Dp%
tb%Dp
ZQf&c
o$G]5
/Ga,\
vb%v_
7Gx*(Gi
$c#'D8
o$G_9
CG[(E7b8\7#
%'D %m#
%S#'D
5"HZ!{1
sc%y_
6eP% h7`.
66\%y_
7d84U%9
7[84L%1
7[8,L#
7[84L%1
o$G]=
%D(%'D
o$G]=
84;%r[
~g]6d0
~g]6d0
QR6h(#
uc%'D$%
uc%'D %
#Gk!17[8m
CH`/D<
C4`/D<
CH`/D<
C #D(
4f0%q~
o$G]3
#Gk!37[j$
#Gk!-7[6
\4v0%&$
6f4%&T
tb%Dl
*$Gr)-v
C8#'D$
C8#'D
*6ax];
7a6l0
6fT%yp
6vX%yr
6f`%yp
ta'7D(
G_)<_%y
cGr(<_%y
D,#'D4#
C(%'D
C8'#H
O_'?D8
C(%'D
pt'7Dd
k8\%/D
;Ga4l0
G](Fc%y
S7s8l0
s\%y_
}k%n~g
?Ge'$Gb'\
6n`#1\
k*Gr'"
G[(.v
sHb@t*
6ftk/
x%D(%
t_%y_
K/b4l0
*6a(k
6/Ge-
`6m t/
k$Gd4l0
H; -G
$7s6l0
D8%D$%
q$T#D$#
uc%'D %
tb%D@
CL%DH#
rb%D(%
+7[845
@Z6l0
%%0Gi(e
vc%'DD%
l%p~i
CP%vra
L%vpb
G`-b
C<%'DH%
#'D %1
vc%'D0%
uc%'DT%
?u6d0
#'D<%9
Ga)\
52Fm3t0
52Fm3t0
?c84{
7[3vH#
?l57S#
Hj $M#
\%y_
("?Z84
H_-\'7D
]#'DL
7k6l0
C(`/D8
C(`/D8
{`Ga4e
7b6t0
s@l6l0
o(G`a
#G]y\
G]^?
tb%D
g]6t0
ZK?l5
g]6l0
ze]6t0
}?l5vk[
?c5fl$
?Z5nM$
G[*0Gh'(
6G[',G`'(
u 3tz%
~e6l0
C,#'D0
/Gd 8t
t!r#:F
O?Z6t0
b%rs]
~c6t0
O~Mrd0
C<#'DP
o(?c0
~j]rf,
vc%'D(%
(7b8aL%
vc%'DX%
84U'/p
30y4d0
r% "?Z
lGr4|0
&'D@%D$%
#D$#'D@
rb% (c%
3bvD4w
?bvD4w
7[6/7]6~x
$Gb("
u)7c%x
2kh/[4d0
D$#'D(
6nX%'D
7t6t0
Gb)(7[
G])(7r
\%v_
o$?l4~
G]K?Z5
@?cq$<
db% (c
4nP#)h
/c%'D$
k]6l0
6f(k/
Z't>1
/c%'D$
<''D"%
?l8d0
"a#D<
A7h8t0
o(G]*\
q"r##&r
a%WD
b%_D
u 6tb2
t@Z4l0
Z.tF4
vc%'D<%2
C(#'D,'
Z(4tR5
(Rb%D
5'?l4d0
OG]>\
4r%1p
c 1?c.
?l5n}$
o(j]6f
p%'D$
tb%D(
*0_4n
G[ ]r%1
3n%%2d
Z .tj8
"7t4|0
~g]6d0
i%'D(%
|g]8T^}
L%'D(%
?l51T%
*%D0
D?c6d0
uc%'D %
{e]6l0
%D0%v
C4%D$%
C(#D$
$Gj**?c
$n~g];
l 3t2=
o4qT%1
m$G[4d0
Zv(%9T
j]66v
4~0#IL
4b`#(
G?Z5#Y
G?Z5#Y
b?c4d0
vc%'D(%
5>[%nf
3b%D '
tb%D
tb%D '
E}g]6|0
tb%D
Gb }E
o(GisE
<1#1i
%'D %DP
&sv7i4&
CP%DT%'D
4x ##0
_7j4fpt
[7_4c`'
?[6kX
"?Z6vp
vc%'D4%"D
6vp%)l
"?Z6vp
D8#D(%
4<"%D(
m$Z#D(
Z):?c8T
C(%'D@%
ptGb4l0
rtG[4d0
6wD%l/
C,#'D #
qtG[4d0
vc%'D(
c\%/D,
D|%gD(
ptG[4d0
C %/D@
/?l544
?Z6l0
sh]6s
*EH;!
p$G[4d0
G[4d0
C$%'Dd%
6m %DD'%4
6m %DH#
6f #DD%
`Gd4l0
D$%DP%
]6g #'DXa
DP%DT
k .rk
6e4# ,T
qtG[4d0
j]6h`t
ptG[4d0
4kh%2T
@l51M'
tc%'D<%
l$T#D$#
[#DD
%'D %3
Y#@-6t0
@u5?S%
g?l56
#'D@%!$
fQ#'D %'D(#
@l53O#
D<%'D %
/?c5,*k
tb%7DT
C$%7DP
C #D@#'D$#
SGe*.r
%$,7o6
61Gp),
7b4t0
aGh3$6
`G_4d0
vc%'D0U
}g]6gP'
Z)^c'(T
9?l50?u5<6%
%'D %D4%
n$T#"P
?l547%
C\#D(Y
?c%'D4%
'Gr4d0
dGr4l0
G7[6l0
K7d4l0
KGj4d0
77\4d0
o,GdW
rc%'D,
{e]6t0
#'DL#'DH
K7m4l0
C=%?D$
%#(?c5
tb%D$%;h
B%D8'#!?c
6v %)(N#
pr%&0r#D
G7w4|0
0r#'D(
@88<;k
YD0#'DH%$
8y8<g%
%7d6t0
(7m6|0
5,C%'D
r%%@r%
s%%`r%
xl%D0
&7s6oL
%'D4'7"
4~{6l0
*%'D4"
C7d6t0
uc%'D$
#'D0#D4
CH%D@
6li/[l
#Gk!-7[6
8w$%sr
8w8%sr
k$G[!'
6w4%sr
k$G[!'
k$G[!'
uc%'D`%
a%WD@
C(')\\
JGw $?u
tb%D 
tb%D 
Z #?Zn
C\#'DD
#Gk!37[f$
#Gk!,7[6
8wX%sr
8w|%sr
6w@%sr
6wx%sr
|i\'.
r6f<k
6fd'JT
*CG](:?Z
G[4vx
Ge $?
Ge $?
*DG](;?Z
#D$#'D(
6li/[l
#Gk!-7[6
k$G[!'
k$G[!'
CD%q~g
q\%y_
6&]%y]
l$Gb!'
j]6t0
e]6d0
~j]r%T
uc%'D(
`?Zm(
Ch#D
`Gb)\
dGb(`
_G](#Q
CD%D0
6&]%y]
66a%y_
4fH#)l
d%'DD$1
677b4l0
"?Z6oLt
"?Z6oLt
CL`/DX
CL`/DX
CT`/DX
6n(#10
n6f,k
6p$'#4
6n(#10
6v('7D
6f('?D
H26g4k
+k%n~p#
4f$%'D,%
*6a(];
tb%D`
6n$%DL%
w]%y]
vc%'DD
&D4%zS
rb%DX
_G])n_
lrc%'D`
D0%ysa
+k%n~g
6`(k/
C4%'D8%
D\#Dd#
#'Dl#Dp
#D8#D<#D
#D<#D@#'D #'D$#
6aL%7D(
C$%/D(
*6a,];
6mj/q6
XGr)/7[8
OGaqd0
?c4#?l4k
%sr7he!
uc%'D
?Z6l0
o(]%z]
?Z6l0
*8aX];
*,\'9|
o(Gwqd0
Z R_%y
7j6d0
$T%yp^
q\#D@#DD`
6nL%m[
*6a|];
Z Gc%y
C<%'D4%
7j6d0
hW%Dl
(&?c4l0
Z("?Z8,
Hk6u|#
_G`4d0
*6qL}
=?l6h
k$G[!'
k$G[4u
k$G[!'
Yr4f0#
k$G[!'
k$G[!'
m4v0%ma
CGk!-7[6
#Gk!-7[6
#Gk!-7[6
#Gk!-7[6
#Gk!-7[6
#Gk!,7[6
#Gk!,7[6
Z)?b%z
l27e4l0
;7[6l0
uc%'D %
6fH'7D
#D\k
?7m4t0
G] $?c
G] $?c
kq/\6u
o]#D(
CD%'D<
?Z6l0
+7[4l0
C0%D8%
#D #D
%D0%
C(%'D4%
6nH%<`
o]')!Q
6nH%<`
o$G\2
+k%n~g\
o$G]2
c 7?Z4v
8,6%m[
$Ga4l0
$Gx4d0
pc%'D$#'D
rb% (c#
#Gk!,7[6
#Gk!,7[6
#Gk!,7[6
#Gk!,7[6
k$G[!'
k$G[!'
k$G[!'
#'D #'D8#'D<
#D(#D,#
6N7[6n
?cr to
l$Gb!'
?ZrfD
?ZrfD
?ZrfD
C ')8\
c(\%y
c(\%y
Zfc%y
Zhc%y
Z(c%y
+7[4l0
_?Z4fH"
Z lc')`c%y
gF]6d0
/7\6t0
s7]4l0
87]6|0
p\%y_
p\%y_
Z i?Z8t0
/7d6t0
G_ '>Z
q(?Z6~
~g]6d0
#'D #'D
'?*bQr
CT'?*|Vj
DP'?*P
_7j4fpt
[7_4c`'
?[6kX
"?Z6vp
6vp%)l
"?Z6vp
k]6l0
6f(k/
%#(?c5
6&GaB
B%D8'#!?c
6v %)(N#
7a#'D %'D0%
3<E%#4
%#(?c5
D0%'D
D0#'D
<1#:l
%'D %DP
&sv7i4&
?c%'D4%
'Gr4d0
dGr4l0
G7[6l0
K7d4l0
KGj4d0
77\4d0
o,GdW
rc%'D,
{e]6t0
4~{6l0
*%'D4"
~g]6|0
#'D0#gD
4~L#)d
8w4%sr
8wD%sr
8gH%yp
8w`%yr
8gd%yp
8w|%yr
#Gk!,7[6
k$G[!'
6w(%sr
6gH%yp
k$G[!'
k$G[!'
k$G[!'
k$G[!'
h6"\#1
!_'7D4
6n|%?D
G` PEW7%
?u8mH#GD|
K7[6l0
'2G\*.Gi**U#
/Gb)*U#
gGb(*M#
gG[4d0
_G[4d0
b6!7a6q
j6"G]6j
j6"G_6j
;7b8$%%9p
6'GbE
6'GjC
uc%'DH
$'DH%DP
gGd'$Gh).
_G\'@G`*<
\)ya%V@
C<%DH#
C<%DD
Gh4l0
3Gj'<Gk*8
WGr'$Gs),
/Gj'<Gk*8
c%'D '
?Z6l0
\6/Gb(
%D4%2
Gr(;?
+c%'D0#
u7r4|0
#'D0%'DD
C(%y]
wGbrd0
Gr(_c'
Gt'IG8
uc%'D %
67\%z_
67\%z_
67\%z_
vc%'D(%
uc%'D %
c%'D(%
o]#'D,
Gj *E
G[6l0
Gq'$Ge(jG]j!
'5M%Ad
66\%y
G]'oG
(gGe'cG(
vc%'D\
p\%z_
\%z_
C\%z_
66c%y
_G[4d0
C<%zpa
C4%yh\
67\%z_
C('#!_%y
C %yrc
C(%ypc
]%x]
p]%y_
S7k6l0
uc%'D$%
D4#'D8
8}x'bx
60Gkrd0
">u8l0
60Gkrd0
">u8l0
60Gkrd0
">u8l0
">u8l0
s`%DD
WGh2N
CL%D4
CP%D8
?Z4t0
Cl%Dx%'D|#
GG[*(G
2G[C
n8Gk(F
b6!Ga6y
o0b%D0'
k6"G]6j
pb%D(
vc%'D(%
C %D,
C$%D0
66\%y_
66\%y_
66\%y_
C(%ypc
pb%D(
6f('iT
*6aP];
t@Z6u(
?G] '^
D,#D4#
4fL'/D
!G]8\
j]6d0
pb%D(
%q~e];
*6a ];
*6a$];
*6a(];
*6a0];
*6a<];
*6a8];
*6a4];
*8a@];
*6a|];
?cvD4w
\%y_
w\%y`
\%y`
/\8t0
84M%/D
7h8d"
+%'D,%
3\%x_
G] .?u
hT#7DD
C|%7D<
C(`/D(
Gp4t0
q\'?DD
CH`/D(
CH`/D(
C0`/D0
C(`/D(
w(\'/D@
C(`/D(
C@`/D(
C``/D(
\%'DHa
C #'D(#
"?Z4f\%
]6n\t
67\%z_
CD%!<b
o]a/D<
o0k%7DT
C$%q~p#
C<%'DP
K7_8l0
?u8l0
<Fe4
?u8l0
<Fe4
c ._%y
R7q3$>%
?u8h
tb%D$%;
7_4l0
+c%'D %1L
r#gn89
%'D $?W89
C#'D
6.?l3<
vc%'D0%2
a'/1|I
rb%D$
rb%D$
rb%D4
o,G]*k
H` ?t
t@Zqd0
t@Z8t0
[r#'DJB
6F] 2k
o$G]>
\%/D(
\%/D$
C,# Pk
Cc%'D8%
G/b6d0
KGj4d0
3Gk4l0
%xp7e6
~g]6|0
~g]6l0
CT%DX%'D(
CT#'D(
CT#'D(
%D(%'D %s
?c5/V#
?c5/V#
37[4d0
6c$k/
#'DL#'DH
K7m4l0
C=%?D$
rc%'D,
{e]6t0
4~{6l0
*%'D4"
6f(k/
l(Gd!2
g]6d0
%'D %s#
?Z4*j]
41j]6t0
?7[4|0
3<D%DL
k]6f0
k]6f$k
k]6n\%
6f k/
7a4nh%
%D(%'D
vH]+
\'?D8
j]6d0
#Gk!-7[6
8w(%sr
#Gk!-7[6
#Gk!-7[6
k$G[!'
#Gk!-7[6
tc%'D$
G] $?Z
[7[6l0
k7d6v(
C0%'D8%
D$#'D(
#Gk!37[f$
e4n0%y
k$G[!'
k$G[!'
6el%xp
'7[6l0
%'D %v
CH%'DDk
C0%'D(%l
Dh%'Dd%Dp
p^#'D<#
D@#DL
C %Dt
[Gk)B7k
n,G[4d0
o$G_/
o$Gg4|0
Z #?Zn
6+Gb Y
Z("?Z6
G[("?Z6
/?Z4l0
/?Z4d0
6nh%D<%
tb%D
6n@t/
,7j6f8'
gG]4fL
6f|k/
C$36nx
Z)e7 ?
G7b6d0
/j6d0
$Gpov
6f|k/
/7[6nX3
?%'D %
*6a\k
6g`k/
^%y]
37\6t0
66\%y_
vc%'DP%
*6atk
l$Gb!'
Ga/\
Ga/\
Ga/\
6sH#.l
?Gk4l0
D$%'D,
~`G_4t0
7c#'Dt
`G[4|0
G_ $?Z
52Fm3t0
52Fm3t0
j]6d0
+Ga#\
6Pc%#,t
#D #'D0
+G]#\
+?l50
,H?c4d0
/G]#\
G]-\
uc%gD8
e]6f %
uc%'D R
C(%D,k
g?l54+%
?Z54+$
34=:0X
3$=:0X
#'D '
*6al];
C,a/DD
vc%'D(%
)@7_8T
'Ga,\
6eT#.8
8\7%l`
?8,4%'D,
h4c$%
Ga/\
Ga/\
G_4\
Z ac'7D
o$r#.L
6kP'/4
t^#DL
4g #"8
6e\'7D
Z Ur%.L
5?l8d0
Z X?c8t0
_%GD
Z Vr%0L
^'/DT
!]'?DD
Ga/\
+Ga,\
Ga:\
}i%m{e];
~i]q$>
o$?c56R
ZG]4E
FG] 3E
6a %$07
_%GD@
6kP'?DT
t@Z8t0
6cP'7D
6fpk/
/Ga,\
/Ga,\
+G],\
t@Z8t0
6kH'?DX
!]'gDx
\'7Dh
}g]q$J
C %?D,
|i]'7D
t@Z8t0
b%_D@
DH#DDa
k*G[4d0
}g]6d0
j]6d0
j]c`W
j]cTW
j]cDW
Z<\''D
o,G]4d0
o,G]4d0
o,G]4d0
&'DL%|
&'DL%|
_G_4d0
|ik%l~
CGa,\
7q4!V'
+c%'D
/7k6|0
7b R?Z
\4g$%1P
ra%WDd
6h$#6L
6b #.P
%'D,%l
?c5h#[
?c5h6#
?c5h;[
?l5p#[
?l5p:#
?u5x#[
?u5x2#
L?c5h4#
?u5xG[
?u5xG'(N
4?c5h"
?c5h+[
C(%'DD
cG]4_
6h$%D(
Z_#'D0
?u5x [
?u5x%'?J6`2g
Dx'G3
?u5x8[
?u5x='?*
?u5x@[
?u5xE'?J
D4'G+N
D@'G8Ej
D\'G:
sp?e4d0
#D #
C %D$%x
37i8T#%|
o4?l5l
C6hdt/
Z)Ac'f4
#'D,#'D0S
g]i l
3G]qd0
#'D0# ,
4}<%p~i
;G])\
+Ge'v
/G]4|0
%D4%0T
4fDk/
6f k/
G_+\%y
Ha!J_%
6&]%y]
''DH%/DP
*6a,];
7G]4|0
#Gd(L7k6-
}1WOiq
#Gd(L7k6-4
}g]5d0
#G`4|0
'G['k
"?l8Tu%p#
"?l8<}%q#
~i]6d0
~i]6i
3c%'D(
j47k%n~g];
%n~g];
lTG\)3
*6i t
b%D '
b%D '
b%D '
b%D '
b%D '
b%D '
uc%'D(%
Gr4t0
07bLT|
D0#'D@
b%D '
b%D '
b%D '
b%D '
b%D '
b%D '
g%'D %D
d%'D %D
b%'D %D
d%'D %D
d%'D %D
b%'D %D
r"U#'D0#
r$U#'D0#
r$U#'D0#
Tc%'D
Tc%'D
Tc%'D
eV#D(#
r"U#'D0#
r"U#'D0#
r"U#'D0#
r"U#'D0#
eV#D(#
r"U#'D(#
r"U#'D(#
rc%'D %|
c%'D$t
(R7b84
6}g]6$
W7trd0
tsb%DX
#84]'
d]6e,a
6e$#D %
1'7d65
`Gb4l0
aGj4t0
}g]6d0
A%'D@a
%'DH%D@
(%D@%
@l8hLs
U#'D,#
}g]6d0
}g]6d0
{e]6d0
f0r5$$
!Gk!,7[6
uc%$(v
ir4#p#
o4jcnsa
*a#D0
xe]6d0
s1K~r
~gcnsb%D
e]6d0
rb% ,c
%y{/i~
uc'D('%H
J !6d0
Xiz2b
uc%((?u6
o,G]4e
e(%q~i](
x?Zj@`
G["=7b8
% 0c%(,
yG]^v
c,Fd(
o4k%n~g
:b%D
1r%H|
/[TI
,G[ B
6e$% (
\0u'D,
\0u'D,
\0u'D,
\0u'D,
\0u'D,
\0u'D,
\0u'D,
Ga ;v
Z$Ga!#
(Ge':E
6#Gj"KG
k~gcnu
):b'D
c%(,?u4}
o0Ge($?Z
~gcnsb
%((?u.]
kYQz)E
r$0Z8
(F]''H
\Gr*_7]6
uXid:
Z "i].]
G]'\
G]'\
Ge:D
6G]+D
GaY\'
l{jcnu
Z $?Zt
{e]5d0
H]Gb%D
??c6o
&D<a1|
4e8%0
b%D,'0
e%'D0%D4'
%D(a1|
oDk#I|
"j]6d0
Z "j]6
6ul%),
+?Z4!j]6l0
j]r%H)
{%'D`%
'DW%{
s3(j]6d0
nhj]6d0
o,G[4f
7c%'D<'
sh]5eD
g]6l0
vc%'D0$
7r5g]%
6)Gs!"
f]6d0
}g]6t0
Z>b%D
#'D 'gD8
_'/D<
vc%'D0%
'Fd-L
41?c5(
40?Z5!
c%$(?l
uc%'D '
~A6l0
o(G]4g
o8k%q~g
[!j]6t0
tb%D$
sh]6d0
7]'?D(
/]'?D$
tb%D
.>c4d0
}g]6d0
u\#D$
8_8,$
tb%D$%
'j]6d0
o$?Zd0
nub%D
p^')`t
tb%D$
6h4%ro
7?u5>?Z5"R
%*<?Z5d
5/?u5>
?Z5!b%{
sk]6d0
rc%'D,%
!M%'D0
!M%'D0
vc%'D8
](?u5>
*Gb &G
0%'D8%
vc%'D8
](?u5>
*Gb &G
0%'D8%
;b%D(
OGdBG
sh]56
CD%DL%{K
"%DH#
rb%D$
ze]6l0
8$"#'D
G?l56?u59M$
9%'D(%
/c%'D(
rb%D,
tb%D(
i&G\+G
sh]5>
_Fm6|0
?c5*_
0N#?D
sk]5v
sk]6l0
tb%D '
%D4%'D0%
tb%D '
?Z5&?l5u
tb%D(
* F7j.
3c%'D(
g]6t0
!Ga!'k
'4I46
'4IS=
'4I>7
tb%D '
%D4%'D0%
tb%D '
?Z5&?l5u
tb%D(
vc%'D@'
vc%'D@'
_%GD$
uc''D(
q&9%'Dh%
g]6l0
GGb4|0
?u8$L
tb%D '
%'D$%pK
rb%D,
}g]6l0
C0%'D$%s
tb%D '
$H9!(Hz
tb%D
8?c5.?l57
}g]6d0
tb%D(
tb%D8
sk]6d0
'4IX/
3c%'D,
tb%D '
sk]6d0
sk]6d0
sk]6d0
vc%'DH
(??l50
*(Gh($
CP%DT%~K
?l53?Z5$
%DT%'DP%sK
**Gh(&
7?c6l0
D %'DH%
tb%D '
CD%DH%uK
SG_(-F
?l50?u5
C<%D$
%D,%'D$
8?c5.?Z5'R
3c%'D,
eS$-dh
]Xc"%rR
]j]!,r
]w`!,r
tb%D '
sk]6d0
'4I>J
6.V%m[
o(k%q~g
g]6f$k
Z 0?Z.
d7_4c`'
}g]6l0
vc%'D4%
C$%D8%
6vp%)l
"?Z6vp
k]6l0
6f(k/
6&?c5(
}g]6d0
+b%D
q%'D0%D(
/c%'D$
k{e]6l0
Z $7m6
C4%'D0%D(
i+Gb%O
%#(?c5
4n %lS
xHb4l0
6"GaB
6v %)(N#
7a#'D %'D0%
3<E%#4
%#(?c5
D0%'D
D0#'D
o,k%q~g].
'~y6s0
%'D$%DX%
KGk4l0
rc%'D,%
{e]6t0
#'DL#'DH
o(k%q~i
o(k%q~i
o(k%q~i
Tb%D$%
+c%&PG
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
MicroWorld-eScan Trojan.GenericKD.68914072
ClamAV Win.Malware.Trojanx-9951053-0
FireEye Generic.mg.5dd5dcb6da07a09f
CAT-QuickHeal Clean
McAfee Flyagent.d
Malwarebytes Generic.Malware.AI.DDS
Zillya Backdoor.Poison.Win32.100672
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus Trojan ( 0040f54a1 )
Alibaba Backdoor:Win32/Poison.d39d55b6
K7GW Trojan ( 0040f54a1 )
Cybereason malicious.cf02e6
Arcabit Trojan.Generic.D41B8B98
BitDefenderTheta Gen:NN.ZexaF.36738.@tW@aW@qdMoH
VirIT Clean
Cyren W32/Graftor.CS.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Backdoor.Win32.Poison.kjrc
BitDefender Trojan.GenericKD.68914072
NANO-Antivirus Virus.Win32.Agent.dvixmz
SUPERAntiSpyware Clean
Avast Win32:MalwareX-gen [Trj]
Tencent Malware.Win32.Gencirc.13aede43
Emsisoft Trojan.GenericKD.68914072 (B)
Baidu Clean
F-Secure Clean
DrWeb Trojan.MulDrop23.10209
VIPRE Trojan.GenericKD.68914072
TrendMicro TROJ_GEN.R002C0PGH23
McAfee-GW-Edition BehavesLike.Win32.Generic.wc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Backdoor.Poison.ese
Webroot W32.Trojan.Agent.Gen
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Trojan[Packed]/Win32.FlyStudio
Kingsoft Win32.Troj.Undef.a
Gridinsoft Ransom.Win32.Wacatac.oa!s1
Xcitium TrojWare.Win32.Agent.OSCF@5rs7jr
Microsoft Trojan:Win32/Flyagent
ViRobot Clean
ZoneAlarm Backdoor.Win32.Poison.kjrc
GData Win32.Trojan.PSE.QP57SD
Google Detected
AhnLab-V3 Trojan/Win.Generic.R576437
Acronis Clean
VBA32 BScope.Adware.Agent
ALYac Trojan.GenericKD.68914072
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PGH23
Rising Packer.Win32.Agent.f (CLASSIC)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.204978112.susgen
Fortinet W32/CoinMiner.BELF!tr
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.