Static | ZeroBOX

PE Compile Time

2024-09-10 23:38:16

PE Imphash

14ac16b6ab41482a6dec812b524ddab4

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0037f28e 0x00380000 6.2375251731
.rdata 0x00381000 0x000fba18 0x000fc000 6.59409566527
.data 0x0047d000 0x0014d94a 0x000d8000 5.57685667725
.rsrc 0x005cb000 0x00008aa8 0x00009000 5.88646104535

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x005cbfac 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x005cbfac 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x005cbfac 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
WAVE 0x005cc100 0x00001448 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x005cde68 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x005d0760 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x005d0cb4 0x00000c44 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x005d0cb4 0x00000c44 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x005d0cb4 0x00000c44 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MENU 0x005d1904 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x005d1904 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x005d2b4c 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x005d3594 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x005d3644 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_ICON 0x005d3690 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x005d3690 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x005d3690 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x005d36a4 0x00000234 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x005d38d8 0x000001cd LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library MSVFW32.dll:
0x781470 DrawDibDraw
Library AVIFIL32.dll:
0x781024 AVIStreamGetFrame
0x781028 AVIStreamInfoA
Library iphlpapi.dll:
0x781850 GetAdaptersInfo
Library WINMM.dll:
0x781774 waveOutRestart
0x781778 midiStreamRestart
0x78177c midiStreamClose
0x781780 midiOutReset
0x781784 midiStreamStop
0x781788 PlaySoundA
0x781794 waveOutWrite
0x781798 waveOutPause
0x78179c waveOutReset
0x7817a0 waveOutClose
0x7817a4 midiStreamOut
0x7817ac midiStreamProperty
0x7817b0 midiStreamOpen
0x7817b8 waveOutOpen
0x7817bc waveOutGetNumDevs
Library WS2_32.dll:
0x7817dc inet_addr
0x7817e0 inet_ntoa
0x7817e4 gethostbyname
0x7817e8 WSAStartup
0x7817ec WSACleanup
0x7817f0 select
0x7817f4 send
0x7817f8 closesocket
0x7817fc htons
0x781800 socket
0x781804 setsockopt
0x781808 recvfrom
0x78180c ioctlsocket
0x781810 WSAAsyncSelect
0x781814 connect
0x781818 recv
0x78181c getpeername
0x781820 ntohl
0x781824 WSAGetLastError
0x781828 ntohs
0x78182c getservbyname
0x781830 shutdown
0x781834 accept
Library RASAPI32.dll:
0x78148c RasHangUpA
Library KERNEL32.dll:
0x7811fc GetLocaleInfoA
0x781200 GetVersion
0x781204 TerminateThread
0x781208 CreateMutexA
0x78120c ReleaseMutex
0x781210 SuspendThread
0x78121c MapViewOfFile
0x781220 UnmapViewOfFile
0x781224 GetSystemInfo
0x78122c lstrcmpiA
0x781234 WaitNamedPipeA
0x781238 OpenFileMappingA
0x78123c OpenEventA
0x781240 TlsAlloc
0x781244 TlsFree
0x781248 TlsSetValue
0x78124c TlsGetValue
0x781250 LocalFree
0x781258 lstrcpynA
0x78125c DuplicateHandle
0x781260 FlushFileBuffers
0x781264 LockFile
0x781268 UnlockFile
0x78126c SetEndOfFile
0x781270 GlobalDeleteAtom
0x781274 GlobalFindAtomA
0x781278 GlobalAddAtomA
0x78127c GlobalGetAtomNameA
0x781280 lstrcmpA
0x781284 LocalAlloc
0x781288 GlobalHandle
0x78128c LocalReAlloc
0x781290 GetFileTime
0x781294 GetCurrentThread
0x781298 GlobalFlags
0x78129c SetErrorMode
0x7812a0 GetProcessVersion
0x7812a4 GetCPInfo
0x7812a8 GetOEMCP
0x7812ac GetStartupInfoA
0x7812b0 RtlUnwind
0x7812b4 GetSystemTime
0x7812b8 GetLocalTime
0x7812bc RaiseException
0x7812c0 HeapSize
0x7812c4 GetACP
0x7812c8 SetStdHandle
0x7812cc GetFileType
0x7812e4 SetHandleCount
0x7812e8 GetStdHandle
0x7812f0 HeapDestroy
0x7812f4 HeapCreate
0x7812f8 VirtualFree
0x781304 LCMapStringA
0x781308 LCMapStringW
0x78130c VirtualAlloc
0x781310 IsBadWritePtr
0x781318 GetStringTypeA
0x78131c GetStringTypeW
0x781320 IsValidLocale
0x781324 IsValidCodePage
0x781328 EnumSystemLocalesA
0x78132c CompareStringA
0x781330 CompareStringW
0x781334 IsBadReadPtr
0x781338 IsBadCodePtr
0x78133c GetLocaleInfoW
0x781340 SetLastError
0x781344 TerminateProcess
0x781348 GetFileSize
0x78134c SetFilePointer
0x781350 GetCurrentProcess
0x781358 GetSystemDirectoryA
0x78135c CreateSemaphoreA
0x781360 ResumeThread
0x781364 ReleaseSemaphore
0x781370 GetProfileStringA
0x781374 WriteFile
0x78137c CreateFileA
0x781380 SetEvent
0x781384 FindResourceA
0x781388 LoadResource
0x78138c LockResource
0x781390 ReadFile
0x781394 GetModuleFileNameA
0x781398 WideCharToMultiByte
0x78139c MultiByteToWideChar
0x7813a0 GetCurrentThreadId
0x7813a4 ExitProcess
0x7813a8 GlobalSize
0x7813ac GlobalFree
0x7813b8 lstrcatA
0x7813bc lstrlenA
0x7813c0 WinExec
0x7813c4 lstrcpyA
0x7813c8 FindNextFileA
0x7813cc GetDriveTypeA
0x7813d0 GlobalReAlloc
0x7813d4 HeapFree
0x7813d8 HeapReAlloc
0x7813dc GetProcessHeap
0x7813e0 HeapAlloc
0x7813e4 GetUserDefaultLCID
0x7813e8 GetFullPathNameA
0x7813ec FreeLibrary
0x7813f0 LoadLibraryA
0x7813f4 GetLastError
0x7813f8 GetVersionExA
0x781404 CreateThread
0x781408 CreateEventA
0x78140c Sleep
0x781414 GlobalAlloc
0x781418 GlobalLock
0x78141c GlobalUnlock
0x781420 FindFirstFileA
0x781424 FindClose
0x781428 GetFileAttributesA
0x78142c DeleteFileA
0x78143c GetModuleHandleA
0x781440 GetProcAddress
0x781444 MulDiv
0x781448 GetCommandLineA
0x78144c GetTickCount
0x781450 CreateProcessA
0x781454 WaitForSingleObject
0x781458 CloseHandle
0x78145c InterlockedExchange
Library USER32.dll:
0x7814b0 GetSysColorBrush
0x7814b8 SetMenuItemBitmaps
0x7814bc CheckMenuItem
0x7814c0 IsDialogMessageA
0x7814c4 ScrollWindowEx
0x7814c8 SendDlgItemMessageA
0x7814cc MapWindowPoints
0x7814d0 AdjustWindowRectEx
0x7814d4 GetScrollPos
0x7814d8 RegisterClassA
0x7814dc GetClassLongA
0x7814e0 RemovePropA
0x7814e4 GetMessageTime
0x7814e8 GetLastActivePopup
0x7814f0 GetWindowPlacement
0x7814f4 EndDialog
0x7814fc DestroyWindow
0x781500 EndPaint
0x781504 BeginPaint
0x781508 CharUpperA
0x781510 GetDlgItem
0x781514 GetClassNameA
0x781518 GetDesktopWindow
0x78151c UnregisterHotKey
0x781520 RegisterHotKey
0x781524 CreateWindowExA
0x781528 GetWindowTextA
0x78152c SetWindowTextA
0x781530 GetMenuItemCount
0x781534 GetMenuItemID
0x781538 GetMenuStringA
0x78153c GetMenuState
0x781544 GrayStringA
0x781548 TabbedTextOutA
0x78154c WindowFromDC
0x781550 EnumChildWindows
0x781554 GetWindowDC
0x781558 UnhookWindowsHookEx
0x78155c CallNextHookEx
0x781560 SetWindowsHookExA
0x781564 GetPropA
0x781568 MoveWindow
0x78156c CallWindowProcA
0x781570 SetPropA
0x781574 DrawTextA
0x781578 GetCursor
0x78157c DrawStateA
0x781580 FrameRect
0x781584 GetNextDlgTabItem
0x781588 GetForegroundWindow
0x78158c LoadIconA
0x781590 TranslateMessage
0x781594 DrawFrameControl
0x781598 DrawEdge
0x78159c DrawFocusRect
0x7815a0 WindowFromPoint
0x7815a4 GetMessageA
0x7815a8 DispatchMessageA
0x7815ac SetRectEmpty
0x7815b8 DrawIconEx
0x7815bc CreatePopupMenu
0x7815c0 AppendMenuA
0x7815c4 ModifyMenuA
0x7815c8 CreateMenu
0x7815d0 GetDlgCtrlID
0x7815d4 GetSubMenu
0x7815d8 EnableMenuItem
0x7815dc ClientToScreen
0x7815e4 LoadImageA
0x7815ec ShowWindow
0x7815f0 IsWindowEnabled
0x7815f8 GetKeyState
0x781600 PostQuitMessage
0x781604 IsZoomed
0x781608 GetClassInfoA
0x78160c DefWindowProcA
0x781610 GetSystemMenu
0x781614 DeleteMenu
0x781618 GetMenu
0x78161c SetMenu
0x781620 PeekMessageA
0x781624 IsIconic
0x781628 SetFocus
0x78162c GetActiveWindow
0x781630 GetWindow
0x781638 SetWindowRgn
0x78163c GetMessagePos
0x781640 ScreenToClient
0x781648 CopyRect
0x78164c LoadBitmapA
0x781650 WinHelpA
0x781654 KillTimer
0x781658 SetTimer
0x78165c ReleaseCapture
0x781660 GetCapture
0x781664 SetCapture
0x781668 GetScrollRange
0x78166c SetScrollRange
0x781670 SetScrollPos
0x781674 SetRect
0x781678 InflateRect
0x78167c IntersectRect
0x781680 DestroyIcon
0x781684 PtInRect
0x781688 OffsetRect
0x78168c EnableWindow
0x781690 RedrawWindow
0x781694 GetWindowLongA
0x781698 SetWindowLongA
0x78169c GetSysColor
0x7816a0 SetActiveWindow
0x7816a4 SetCursorPos
0x7816a8 LoadCursorA
0x7816ac SetCursor
0x7816b0 GetDC
0x7816b4 FillRect
0x7816b8 IsRectEmpty
0x7816bc ReleaseDC
0x7816c0 IsChild
0x7816c4 TrackPopupMenu
0x7816c8 DestroyMenu
0x7816cc SetForegroundWindow
0x7816d0 GetWindowRect
0x7816d4 EqualRect
0x7816d8 UpdateWindow
0x7816dc ValidateRect
0x7816e0 InvalidateRect
0x7816e4 GetClientRect
0x7816e8 GetFocus
0x7816ec GetParent
0x7816f0 GetTopWindow
0x7816f4 PostMessageA
0x7816f8 IsWindow
0x7816fc SetParent
0x781700 DestroyCursor
0x781704 SendMessageA
0x781708 SetWindowPos
0x78170c MessageBoxA
0x781710 GetCursorPos
0x781714 GetSystemMetrics
0x781718 EmptyClipboard
0x78171c SetClipboardData
0x781720 OpenClipboard
0x781724 GetClipboardData
0x781728 CloseClipboard
0x78172c wsprintfA
0x781730 WaitForInputIdle
0x781734 LoadStringA
0x78173c IsWindowVisible
0x781740 UnregisterClassA
Library GDI32.dll:
0x781084 FillRgn
0x781088 CreateRectRgn
0x78108c CombineRgn
0x781090 PatBlt
0x781094 CreatePen
0x781098 SelectObject
0x78109c CreatePatternBrush
0x7810a0 CreateBitmap
0x7810a4 CreateBrushIndirect
0x7810a8 CreateDCA
0x7810b0 GetPolyFillMode
0x7810b4 GetStretchBltMode
0x7810b8 GetROP2
0x7810bc GetBkColor
0x7810c0 GetBkMode
0x7810c4 GetTextColor
0x7810c8 CreateRoundRectRgn
0x7810cc CreateEllipticRgn
0x7810d0 PathToRegion
0x7810d4 EndPath
0x7810d8 BeginPath
0x7810dc GetWindowOrgEx
0x7810e0 GetViewportOrgEx
0x7810e4 GetWindowExtEx
0x7810e8 ExtTextOutA
0x7810ec Escape
0x7810f4 CreateSolidBrush
0x7810f8 SetPolyFillMode
0x7810fc SetROP2
0x781100 SetMapMode
0x781104 SetViewportOrgEx
0x781108 OffsetViewportOrgEx
0x78110c SetViewportExtEx
0x781110 ScaleViewportExtEx
0x781114 SetWindowExtEx
0x781118 ScaleWindowExtEx
0x78111c GetClipBox
0x781120 ExcludeClipRect
0x781124 CreateFontIndirectA
0x781128 MoveToEx
0x78112c LineTo
0x781130 ExtSelectClipRgn
0x781134 GetViewportExtEx
0x781138 GetTextMetricsA
0x78113c CreateFontA
0x781140 SetDIBitsToDevice
0x781144 SetTextColor
0x781148 SetBkMode
0x78114c TextOutA
0x781150 SetBkColor
0x781158 CreateDIBSection
0x78115c SetPixel
0x781160 SetStretchBltMode
0x781164 GetClipRgn
0x781168 CreatePolygonRgn
0x78116c SelectClipRgn
0x781170 DeleteObject
0x781174 CreateDIBitmap
0x78117c CreatePalette
0x781180 StretchBlt
0x781184 SelectPalette
0x781188 RealizePalette
0x78118c GetDIBits
0x781190 RectVisible
0x781194 PtVisible
0x781198 CreatePenIndirect
0x78119c RestoreDC
0x7811a0 Ellipse
0x7811a4 Rectangle
0x7811a8 LPtoDP
0x7811ac DPtoLP
0x7811b0 GetCurrentObject
0x7811b4 RoundRect
0x7811b8 SaveDC
0x7811bc SetWindowOrgEx
0x7811c0 GetStockObject
0x7811c4 GetObjectA
0x7811c8 EndPage
0x7811cc EndDoc
0x7811d0 DeleteDC
0x7811d4 StartDocA
0x7811d8 StartPage
0x7811dc BitBlt
0x7811e0 GetPixel
0x7811e4 CreateCompatibleDC
0x7811ec SetPixelV
0x7811f0 GetDeviceCaps
Library MSIMG32.dll:
0x781468 GradientFill
Library WINSPOOL.DRV:
0x7817c4 OpenPrinterA
0x7817c8 DocumentPropertiesA
0x7817cc ClosePrinter
Library comdlg32.dll:
0x78183c ChooseColorA
0x781840 GetOpenFileNameA
0x781844 GetSaveFileNameA
0x781848 GetFileTitleA
Library ADVAPI32.dll:
0x781000 RegCreateKeyExA
0x781004 RegOpenKeyA
0x781008 RegQueryValueA
0x78100c RegSetValueExA
0x781010 RegOpenKeyExA
0x781014 RegQueryValueExA
0x781018 RegCloseKey
0x78101c RegEnumValueA
Library SHELL32.dll:
0x781494 SHGetFileInfoA
0x781498 DragAcceptFiles
0x78149c DragFinish
0x7814a0 ShellExecuteA
0x7814a4 Shell_NotifyIconA
0x7814a8 DragQueryFileA
Library ole32.dll:
0x781858 ReleaseStgMedium
0x78185c RevokeDragDrop
0x781860 RegisterDragDrop
0x781864 OleUninitialize
0x781868 CLSIDFromString
0x78186c CoCreateInstance
0x781870 OleInitialize
Library OLEAUT32.dll:
0x781478 RegisterTypeLib
0x78147c LoadTypeLib
0x781480 UnRegisterTypeLib
Library COMCTL32.dll:
0x781030 ImageList_DragLeave
0x781034 ImageList_DragEnter
0x781038 ImageList_Destroy
0x78103c ImageList_Create
0x781040 ImageList_BeginDrag
0x781044 ImageList_Add
0x781048 ImageList_DragMove
0x78104c ImageList_Draw
0x781050 _TrackMouseEvent
0x781060 ImageList_GetIcon
0x781068 ImageList_EndDrag
0x78106c None
0x781070 ImageList_Read
0x781078 ImageList_AddMasked
0x78107c ImageList_Duplicate
Library WLDAP32.dll:
0x7817d4 None
Library WININET.dll:
0x781748 InternetSetOptionA
0x78174c InternetCrackUrlA
0x781750 HttpOpenRequestA
0x781754 HttpSendRequestA
0x781758 HttpQueryInfoA
0x78175c InternetReadFile
0x781760 InternetOpenA
0x781764 InternetCloseHandle
0x781768 InternetConnectA

!This program cannot be run in DOS mode.
FRich%
`.rdata
@.data
SVWSQRV3
rocA9F
uRFGHt
@hUUUU
3E 3E(1E
h333?j
hfff?j
h33s?j
h33s?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
h333?j
h333?j
hfff?j
hfff?j
h333?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
hfff?j
hfff?j
hfff?j
h33s?j
h33s?j
h33s?j
h33s?j
h33s?j
h33s?j
hfff?h
hfff?h
hff&?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?h
hfff?j
hfff?j
hfff?j
h33s?j
h33s?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?h
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
h333?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
h333?j
hfff?j
hfff?j
hfff?j
h33s?j
h33s?j
h33s?j
h33s?j
h33s?j
h33s?j
hfff?h
hfff?h
hfff?h
hfff?j
hfff?j
hfff?j
h33s?j
h33s?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?j
hfff?h
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
h333?j
h333?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
hff&?j
hfff?j
hfff?j
D$8Load
D$<Libr
D$@aryA
D$8Free
D$<Libr
D$@ary
D$8GetP
D$<rocA
D$@ddref
D$8GetM
D$<odul
D$@eHan
D$DdleA
+E +E(
000102030405060708090A0B0C0D0E0F101112131415161718191A1B1C1D1E1F202122232425262728292A2B2C2D2E2F303132333435363738393A3B3C3D3E3F404142434445464748494A4B4C4D4E4F505152535455565758595A5B5C5D5E5F606162636465666768696A6B6C6D6E6F707172737475767778797A7B7C7D7E7F808182838485868788898A8B8C8D8E8F909192939495969798999A9B9C9D9E9FA0A1A2A3A4A5A6A7A8A9AAABACADAEAFB0B1B2B3B4B5B6B7B8B9BABBBCBDBEBFC0C1C2C3C4C5C6C7C8C9CACBCCCDCECFD0D1D2D3D4D5D6D7D8D9DADBDCDDDEDFE0E1E2E3E4E5E6E7E8E9EAEBECEDEEEFF0F1F2F3F4F5F6F7F8F9FAFBFCFDFEFF
E033s?
XYZRQPS
XYZRQPS
XYZRQPS
XYZRQPS
XYZRQPS
XYZRQPS
XYZRQPS
XYZRQPS
E033s?
E033s?
E$33s?
E$33s?
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
PH[YZA
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
VWQPh(
L$(hpvg
t(ENEN;
L$$_^]
T$$_^]
D$$_^]
D$0UVW
L$$_^]d
D$4SUV
L$89l$8}
D$(t,;
L$(CH;
D$4SUV
L$ QUS
D$8SUV
T$$RUS
QVWWRP
L$d_^][d
D$$~9+
F\_^][
L$D_^][d
L$ QRh
T$ QRh
L$$_^d
L$@^[d
D$PQRP
L$pPQR
D$hRQP
9L$x~k
L$T_^][d
L$lRVQ
D$hQRP
D$hQRP
T$pPQR
\$8UVW
L$DPQj
\$8UVW
L$DPQj
L$ _^d
W9^du-
L$ PQh
L$L_^][d
L$D_^][d
L$@RUQ
L$$^][d
L$$^][d
DQWPh
L$x_^3
L$|_^][d
L$|_^][d
L$|_^][d
T$0VRPSQ
L$4_^[d
V#D$,WPQ
D$@UPQ
T$XUSR
T$HQRP
L$x_^d
D$(SUV
T$8RWj
L$ _^][d
l$<VWj
L$(VQVj
L$(UUh
t$LUPh
o0SSSSU
D$dSUVW
D$@WPS
L$`_^][d
D$,RVh
L$TQVSh
|$XSSW
T$TQRPh
D$`QRP
D$hSUV3
D$,Pj<j
L$h_^][d
L$X_^d
t$ 90t
T$LRUj
D$89Vdu
FpHt&Ht
D$LUSWP
L$$_^][d
L$,_[3
L$,_[3
L$(WQR
QQUWSS
L$P_]^[d
T$hQRWW
t]9|$<tW
L$x_^]
L$<SQR
T$<RVW
9|$8tt
T$<WRh
T$lPRh
T$ SRh
9l$xtU9
u29l$xu,
T$$Rhp
L$XSQh
D$,SPh
T$,SRh
T$,SRh
T$,SRh
t$(SSh
t$$RVP
|$,RPQ
L$H][d
L$HSUVWP
D$XPQU
D$8VPQ
T$ SWRP
L$L_^]3
t%RSQP
XY[Z[]
~'PSQR
\$<VW3
L$4_^3
D$XQRWP
D$dQUWRP
D$0WPQ
T$$+D$4
L$L^[d
9^xu5j
L$X_^]3
h9n`u;
D$8RPj
T$DQRU
D$PRPQ
L$TSWQ
T$Dh c
l$HQRVU
D$H_^][
\$lUV3
L$h_^]3
T$\jdSR
L$Hj&Q
;t$Xu";\$\u
L$DSVQ
L$,_^]3
L$$_^][d
L$0PQS
L$ ]_^
L$ QSR
D$TVPW
D$TRPW
WWVQRWWS
D$$QRP
T$,PQR
D$$RSSP
D$8WVRPQ
L$XRQP
l$@VW3
L$8_^][d
u"8D$yu
D$(_^][
8MThdu
~P9~Pun
t&9^$t
F(9V8tQ
F<_^][
F<_^][
|$@ Wu
|$D UV
L$8^]_3
@;l$\~Z
L$X;L$
uh9^8uX
F89^8u&j
L$T_^][d
L$L_^][d
D$,;\$|
L$0PQR
PQj WUS
T$dPQR
L$l_^][d
L$8WPQR
T$DQSR
D$49D$$}
T$\;D$Xu
L$(PQR
T$,RQP
T$(PQR
L$x_^][d
L$l_^][d
L$TPQR
L$dPQRV
u+\$l
L$4SUV
L$4WPQR
D$ |2;
L$@_^][d
u._^][
L$ WPQ
T$,RQP
L$\_^][d
L$@RQj
D$@RPQj
L$T_^]d
FD uy9D$$}s
FD@ul9L$(}f
L$P_^d
L$\_^][d
;D$xt&
9D$$t+
L$D_]d
L$ ^][d
D$$QUP
L$|_^][d
L$$h e
L$t][d
D$$SUV
D$DURP
RVPUSQ
L$$_^][d
j VUPWQ
T$(QVURWP
L$,_^][d
D$$_^[
D$$_^[
L$4VQUP
L$$_^][d
L$4UQWP
L$$_^][d
T$0SUV
L$(_^][d
T$8QRP
L$(_^][d
L$8_^][d
|$LtE;
t$PPVS
L$8_^][d
T$\WVR
jBWVSSQ
D$(_^]
\$ PQV
L$$_^][d
L$H_^][d
SWVVVRPV
L$$^]d
L$D_^[d
D$(hDq
D$ h(q
T$,h$q
T$(Qh$q
T$(Qh$q
T$(Qh$q
L$,h$q
T$,h$q
T$DWRh
D$,QRPS
L$$RPQS
L$<_^][d
L$(RPQ
NTRPQj
L$(RPQ
T$(PQR
D$(QRP
T$DPQRW
L$<RPQW
L$T_^]
D$ h0kk
P$RWPh
D$0QVRP
jdQhpf
L$$PVh
D$4RPQ
D$ PQR
=pscat
=YARGtD= BGRt
h BGRUPV
hYARGUQV
=lcmnw_tQ=tsbat-=knilt
=rtnmto
hknilUPV
htsbaUQV
=rtrpt =rncst
=capst
= baLt = ZYXt
TADIut
tkPUSV
ETLPuF
D$8QVRPU
QRVWPU
D$$SPh
L$Xhd~
3;L$4s
T$8QRU
T$XhL~
D$Xh(~
L$Xh`[
T$,SRW
T$0;t$
PPPQSG
D$ EJ;
D$4SUVW
L$$QWV
D$0Uh`
D$,Hx;@
D$(CM;
D$Hvm3
L$Lvj3
D$(FO;
L$t_^d
D$ RPUhD
L$l_^][d
L$$^[d
L$(WSR
T$0PQR
WjdjdPQh
|z;^<}uWS
L$D_^][d
L$\_^][d
It#Iu%
^l_^][
tI;Ftr
tL9~HvG;
~(9~$u
D/ VPS
L$<RWUQV
L$$j QV
L$(VQU
hPCCiU
L$(RPVQWU
l$,WuAS
|$ VurU
D$@QRPU
T$ PQW
Ht&HtcI
D$(SUW
=TADIt
TADIu"
hTADIV
Ht]Ht2Ht
HtfHt;Ht
t$,u%:D$<u
:L$<t;
\$$u9f;
\$@QUR
;=3333v
HtHHuz
V,_^[Y
D$ _^][
EHPWVS
u]9B uX
uR9BxuM
'9A`u"9
tq9~Dt
nd9~dt
tS9~@uN
T$LPQR
|$HPWS
L$(RPQ
T$DPVS
T$LRWS
Fdf+Fh
tRHt}H
NH_^][
T$LWUQVR
L$4WQUVS
;l$ }:
|$$}$WP
\$\}-j
O(_^][
T$H} VP
T$$PRV
D$(QPW
L$,SUV
L$0SUV@W
NX9NXu
QPSWVR
T$PQRP
D$$SUV
D$(;l$
\$(UVW
D$,_^]
D$(CUSWP
9o4u'V
9t$0v8
T$,RWV
T$,RWV
T$,RWV
L$,QWV
T$,RWV
L$ RUPj
9t$Tu
T+3x%A
;D$<s!
T$,PQhx
D$0Qhl
|$ WUSV
L$(SUV
N4_^]3
\$4UVWS
T$<_^]
L$<PQR
D$8FtdW
\$4VWh
L$8_^[d
SUVWhH
L$$_^][d
L$8_^[d
L$<^[_]d
T$@RSP
L$ _^]
D$ QRPh
T$hWVR
L$$RPQ
D$$QRP
ul_^]3
L$ ;t$ t
D$ WPSVU
L$0QUVS
9D$(}?
L$0PQW
D$4Rhh
\$HWhL
T$4Qh4
L$4Ph4
L$4RPh(
T$4PQh
T$PPRh
T$$PRU
@0PQRVW
Ht2HuL
T$([_^
T$([_^
T$([_^
T$([_^
T$([_^
D$$_^]
QSUVWj
L$,_^]
QSUVWj
L$DRSQ
L$,SQR
T$8QRU
T$8QRU
L$8PQU
D$8RPU
D$dUPh
SUVWh0
F u#h|
RPVh0l
RPQVh0l
L$L^][d
L$(_^d
L$ _^[d
;D$xt(%
D$l_^][
PWRVPWQf
D$tKQMSUP
t#Hu1;{
T$<QPh
T$<PRh
L$XQSPUR
D$0WVQ
D$0QRWVP
T$@PQR
u+9Fdu&
te9Fhu`
L$8RPQ
T$$SWj
L$4SQh
^,~FH;
L$hRPQV
PPPPPPPPPPP
T$ PQRV
ND_^][
T$4PQR
L$@_^][d
Q#D$HRP
#D$DQRP
L$T_^d
T$4HPQR
L$DHAP
L$D@APQ
T$4PQR
L$LHIPQ
D$LJHRP
L$XQSPV
L$`_^[d
D$8SUVWt
j$SWRPj
Ph_^][
Rh_^][
D$(SUW
L$0PQR
L$0PQR
L$0PQR
L$pRPQ
D$hQRP
L$@_^][d
L$(RPQ
NTRPQj
L$(RPQ
T$(PQR
D$(QRP
T$DPQRW
L$<RPQW
L$T_^]
Nh;NX|
Vh;VX|
Fxt_;FTu@
Nh;NX|
D$8QRP
" !
!!!!!
L$lQPR
L$8RPQ
L$8PQR
T$$RPQV
T$ URQPV
T$$RPQV
\$0UVW
D$PRPV
L$@j%Q
L$@j%Q
L$(_^]d
L$<_^]
T$<_^]
D$<_^]
L$<_^]
T$lPQR
T$$j%R
L$lRPQ
T$,IJQR
D$(IPQ
T$Pj%R
D$`PQR
L$$QPR
L$8_^]d
L$ QWPR
l$PVWU
L$0_^]d
\$(UVW
L$PQRP
T$`RPQ
T$8RPQ
L$PPPQ
T$PRPQ
D$`PQR
D$8PQR
L$0QSR
L$<_^[d
D$8QVRP
D$8QVRP
D$4WSP
D$4WSj
D$DWSUj
D$0QRP
L$,RPQ
T$,PQR
T$,PQR
JUHRPQ
BU@RPQ
\$dUVW
D$4PSQ
T$PRQP
L$(SPVW
L$ QUR
D$$Ph`
NLQj<P
t$ WPV
L$ _^[d
L$8RPQ
t$LPQR
L$4_^][d
D$HQRPW
L$4_^]d
D$0_^][
\$,UVW
L$d^_]
L$,RPQ
L$H_^][d
S#D$$SPQR
T$TSSR
L$P_^][d
D$$VPQ
T$ RSUP
t`Ht7Hu}
D$DSUV
?h3333S
T$`h33
?h3333R
L$@_^][d
D$hVPQ
L$@QWR
L$ PVWj
L$`_^][d
L$0UQW
D$Du)+
T$ SU3
L$ PSW
D$,FI;
L$D_^]
L$,QPR
L$(^][
T$8PWR
~/j#hd
~?j#hd
|$$~EW
L$,PRVQ
^lSj<P
D$Hu)+
L$T_^][d
L$XPPQ
|$LWQP
L$0_^]d
L$$RPh
Fdf+Fh
D$(8D*
|$ WUSV
D$$SUV
BRPj+S
@PVj,S
QRWh`/
\$4t|Ht@H
T$8h$1
T$ QRP
T$0u`U
V<j PR
F<j QP
T$HRj$
T$<RWP
j$Rh@l
D$ QRPW
T$ PQRW
D$(PQh
T$@SRh
\$(UVW
L$4PUQ
D$$QRWVPU
T$(hTj
T$@QRj
L$4PQj
T$4QRj
L$(PQj
T$ hTj
T$8QRj
L$,PQj
D$ThTj
T$(hdj
D$lRPj
T$<QRj
T$dQRj
D$HhTj
D$`RPj
T$0QRj
L$|PQj
T$XQRj
D$LhTj
T$ hdj
D$dRPj
T$4QRj
T$\QRj
D$DSUVW
D$0hdj
D$DRPj
T$0QRj
L$`PQj
D$(hdj
D$<RPj
T$(QRj
L$XPQj
D$,hdj
D$@RPj
T$,QRj
L$\PQj
;t$<}
;t$<}8
D$(SUV
|$<tM;
T$8QRj
L$,PQj
T$,QRj
L$ PQj
T$,QRj
L$ PQj
L$dPQj
D$8RPj
D$\RPj
T$XQRj
L$,PQj
D$|RPj
L$PPQj
D$XRPj
T$,QRj
L$|PQj
T$PQRj
L$DSVW
D$DRPj
T$4QRj
L$dPQj
D$8RPj
T$(QRj
L$XPQj
D$8RPj
T$(QRj
L$XPQj
d$t_^][
D$PPVV
D$PPVV
D$PPVVt;
)D$pv#
D$$hh,
T$PRUh
L$(USRPQV
USPQRV
l$$VWU
T$$RSf
tj@SV
IQSPPj
Hu"WSV
uI8^Lu=
D$4PRh
L$$UQV
T$,WRV
D$$UPV
L$,WQV
<[uZGj]W
L$$QhL8
t$ t"3
NxZ;7sV
P3L$4Q
D$ PVV
T$<<%t
<ar7<fw3
<ar7<fw3
T$,_^]
D$,SUVW
<ari<fwe
D$,SUVW
<ari<fwe
D$Q}!;
D$XSUV
;L$0tI
tB;L$(u
D$0PUVRWQ
T$ SUV
\$ AFE;
t+IuDSV
;D$ t
;L$0t<
t5;L$(u
T$,PRVQWU
L$ QRU
D$$j:V
M<~u9;
\$DVj8
L$XhDZ
|F)D$$
|F)D$$
L$$SUV
D$(PVQW
T$4_^]
D$4_^]
L$$SUV
D$(PVQW
T$4_^]
D$4_^]
L$4_^]
\$$UVW
;L$$w(;L$$u
T$D_^]
\$$UVW
;L$$w(;L$$u
T$D_^]
L$D_^]
L$XSUVW3
;\$$t_
t ;D$,u'
T$0QRSPVU
D$09D$
L$ ;\$
D$$PQS
L$$_^]+
D$$_^][
CGE;t$
FCGE;|$
L$(_^]+
\$8UVW
L$$;L$4}
;L$$tU;L$(tO;L$ u
T$(SUVW3
T$ UVW
;T$$t=;T$(t7;T$ u
W(9W$u
tX9H tS9H$tN
Fdf+Fh
D$(8D*
~(9~$u
L$,;l$$
;D$4uY
;T$8tG;
;D$8tC;D$4uL;
L$0RPQSWUV
;T$4uV
;D$8tG;
L$$_^3
;D$8t?;D$4uH;
D$0QRPUWSV
|$ WUSV
t$4;L$
T$LPQR
|$LPWS
T$ PQR
T$PRWS
L$PQVS
T$,RWV
T$,RWV
T$,RWV
T$,RWV
L$ RUPj
9t$Tu
D$X98u
T+3x%A
;D$<s#
|$8t+\$
C(UVWj
T$,PQh
{4_^]3
F$@;F(v
F$@@;F(v
QQSVWj
QQSVWd
t.;t$$t(
B 02CV
C =02CVu
YYF;5@
uf9= T
^}%95|
VC20XC00U
PPPPPPPP
>Cu28V
HSVHWtgHHtF
QQSVWj
>:uNFV
>:u#FV
,f9=4R
uRFGHt
YHYtLHt9
tn<%t2
HHtiHtGH
HtHHt(
HtOHt)H
HtHt&Ht
QQSUVWj
_^][YY
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t/WWUPj
QQSVW3
QQSVW3
sO;>|C;~
"WWShH
HHtpHHtl
tFGQPS
btHHt.
YYF;5@
<]t_G<-uA
WQj1Pj
Vtvj0j
F PjPWj
F$PjQWj
F*PjTWj
F+PjUWj
F,PjVWj
F-PjWWj
F.PjRWj
PPPPPPPP
tEj@Vh
F@j@Ph
It[IItM
YYF;5@
PPPPPPPP
VWuBh$
t+Ht$Ht
HtHHt
+ttHHtd
zu^SSS
E WWWWS
"VVShH
E VVVV
nt2Ht#Ht
F\jLSP
u$SShe
Wj(_Wj
hWj@_;
PQQQQQ
VWh,pw
u-h]pw
PPPPhd
tvWWWWU
F,_^][
(wqt\HHtS
t>Ht Ht
QSUVWj
n0SSSSU
_SSSSU
Ph_^][Y
tD9_Pt?
Ht#HHt
@t4Ht1Ht_Ht
^$_^[]
F(_+F$^[;E
9~4u@j
9~4u:j
F0_^][
<A|2<Z
<A|@<Z
+tJHt:Ht*
P<PuWSV
VWtp9E
HtTHtFHt8Ht*Ht
PWVWWW
9^0u/j
F09^4u*j
F49^8u&j
^,_^][
gdiplus.dll
kernel32.dll
kernel32.dll
kernel32.dll
ntdll.dll
kernel32.dll
kernel32.dll
Kernel32.dll
Kernel32.dll
kernel32.dll
User32.dll
user32.dll
User32.dll
User32.dll
msvcrt.dll
Kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
oleaut32.dll
oleaut32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
User32.dll
user32.dll
user32.dll
kernel32
kernel32
kernel32
ntdll.dll
ntdll.dll
ntdll.dll
kernel32
XinYuChineseOcr.dll
XinYuChineseOcr.dll
XinYuChineseOcr.dll
XinYuChineseOcr.dll
XinYuChineseOcr.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
kernel32.dll
user32.dll
user32.dll
user32.dll
XinYuChineseOcr.dll
kernel32.dll
user32.dll
kernel32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
advapi32.dll
advapi32.dll
advapi32.dll
user32.dll
kernel32.dll
kernel32.dll
user32.dll
user32.dll
ntdll.dll
ntdll.dll
kernel32
ntdll.dll
ntdll.dll
ntdll.dll
kernel32
kernel32
kernel32
ntdll.dll
user32
kernel32.dll
gdiplus.dll
ws2_32.dll
ntdll.dll
user32
user32.dll
user32
user32.dll
user32.dll
user32
user32.dll
user32.dll
user32
kernel32
user32
kernel32.dll
kernel32.dll
kernel32
kernel32.dll
kernel32
kernel32.dll
user32
Shell32.dll
Kernel32.dll
ntdll.dll
kernel32.dll
ntdll.dll
user32.dll
user32.dll
user32
kernel32
shlwapi.dll
user32.dll
gdi32.dll
gdi32.dll
user32.dll
User32.dll
user32.dll
gdi32.dll
gdi32.dll
kernel32
user32.dll
user32.dll
gdiplus.dll
kernel32
ole32.dll
kernel32
kernel32.dll
gdiplus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
GdiPlus.dll
gdiplus.dll
kernel32
gdiplus.dll
gdi32.dll
gdi32.dll
gdi32.dll
user32.dll
user32.dll
gdi32.dll
gdi32.dll
user32
user32
user32
user32
user32.dll
user32
user32
user32
user32
user32
user32.dll
user32.dll
user32
user32
user32
user32
user32.dll
user32.dll
ntdll.dll
kernel32.dll
kernel32.dll
shlwapi.dll
shlwapi.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
user32.dll
gdi32.dll
user32
user32.dll
shell32.dll
shell32.dll
user32
user32.dll
user32
user32.dll
user32
user32
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32.dll
user32
kernel32
ntdll.dll
ntdll.dll
kernel32
kernel32
GdiplusStartup
GetCurrentProcess
OpenProcess
LocalAlloc
NtQueryInformationProcess
LocalFree
CloseHandle
GetSystemDEPPolicy
SetProcessDEPPolicy
GetModuleHandleA
GetProcAddress
VirtualProtect
GetCurrentThreadId
SetWindowsHookExA
MessageBoxA
UnhookWindowsHookEx
CallNextHookEx
strlen
MultiByteToWideChar
lstrlenW
WideCharToMultiByte
GetLocalTime
SystemTimeToVariantTime
VariantTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
CreateWaitableTimerA
SetWaitableTimer
MsgWaitForMultipleObjects
GetWindowRect
MoveWindow
CreateRemoteThread
WaitForSingleObject
ExitThread
ZwTerminateThread
ZwQueryInformationThread
ZwClose
InterlockedExchange
GetDetectResult
Delete_Chars
SetEmpower
ReadProcessMemory
WideCharToMultiByte
TerminateProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
IsBadStringPtrA
PeekMessageA
TranslateMessage
DispatchMessageA
Delete_Ocr
GetCurrentProcessId
MessageBoxTimeoutA
GetTickCount
FindWindowExA
IsWindowVisible
GetWindowThreadProcessId
GetParent
GetClassNameA
GetWindowTextLengthW
GetWindowTextW
RegCreateKeyA
RegSetValueExA
RegCloseKey
EnumChildWindows
LocalSize
RtlMoveMemory
GetDesktopWindow
GetWindow
ZwSuspendThread
ZwResumeThread
GetModuleHandleA
LdrGetProcedureAddress
LdrGetProcedureAddress
CreateEventA
LdrGetDllHandleEx
MultiByteToWideChar
CreateMutexA
IsBadCodePtr
GetVersionExA
GetSystemInfo
RtlGetNtVersionNumbers
GetSystemMetrics
ReleaseMutex
GdiplusShutdown
WSACleanup
RtlDecompressBuffer
GetActiveWindow
MessageBoxTimeoutW
PostThreadMessageA
UnhookWinEvent
DeleteObject
MapVirtualKeyA
AttachThreadInput
SetKeyboardState
GetKeyState
SendInput
GetAsyncKeyState
ClientToScreen
GetForegroundWindow
GetProcessHeap
HeapAlloc
HeapFree
HeapDestroy
InterlockedDecrement
RtlZeroMemory
InterlockedIncrement
HeapCreate
GetDesktopWindow
SHGetSpecialFolderPathW
GetTempPathW
LdrLoadDll
GetSystemDirectoryA
LdrUnloadDll
SetWinEventHook
SetWindowPos
SetWindowTextA
GetSystemWow64DirectoryA
PathIsDirectoryW
CreateCompatibleDC
CreateCompatibleBitmap
SelectObject
CreateSolidBrush
FillRect
GetCursorInfo
DrawIcon
GetObjectA
DeleteDC
CreateDIBSection
BitBlt
GetDIBits
GetDIBits
RtlMoveMemory
RtlMoveMemory
GetLastError
GetWindowDC
CreateDIBitmap
ReleaseDC
GdiplusStartup
GlobalAlloc
CreateStreamOnHGlobal
GlobalLock
GlobalUnlock
lstrcpyn
GdipCreateBitmapFromStream
GdipDeleteBrush
GdipCreateSolidFill
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromScan0
GdipGetImageGraphicsContext
GdipFillRectangle
GdipDrawImageRectRect
GdipDeleteGraphics
GdipDisposeImage
GlobalFree
GdipSaveImageToStream
GlobalSize
GetStockObject
GetObjectA
GetTextExtentPoint32A
CreateBitmap
SetBkColor
SetTextColor
TextOutA
CreateFontIndirectA
EnumDisplaySettingsA
WindowFromDC
GetCurrentObject
SetStretchBltMode
StretchBlt
SetWindowLongA
UpdateWindow
SetParent
GetWindowLongA
IsIconic
ShowWindow
ShowWindowAsync
SetLayeredWindowAttributes
GetLayeredWindowAttributes
IsWindowEnabled
SetForegroundWindow
GetSystemMenu
EnableMenuItem
RedrawWindow
GetWindowRect
GetAncestor
ScreenToClient
GetClientRect
GetMenuBarInfo
AdjustWindowRectEx
GetWindowPlacement
WindowFromPoint
SetActiveWindow
SwitchToThisWindow
TerminateProcess
ZwQueryInformationProcess
GetLogicalDriveStringsA
QueryDosDeviceA
PathFindFileNameA
PathFindExtensionA
RtlAdjustPrivilege
NtWow64QueryInformationProcess64
NtWow64ReadVirtualMemory64
NtWow64ReadVirtualMemory64
NtWow64ReadVirtualMemory64
FindWindowExA
IsZoomed
SetROP2
CreatePen
Rectangle
GetDlgCtrlID
GetDlgItem
ChildWindowFromPointEx
SHAppBarMessage
SHAppBarMessage
GetClassLongA
DrawIconEx
IsWindowUnicode
EnableWindow
SetPropA
GetPropA
GetLastActivePopup
GetScrollInfo
GetMenu
GetSubMenu
GetMenuItemID
GetMenuStringA
MoveWindow
GetWindowInfo
SetBkMode
DrawTextA
lstrlenA
ZwClearEvent
ZwSetEvent
InterlockedIncrement
InterlockedDecrement
d09f2340818511d396f6aaf844c7e325
2EAE87405D754ad780D8FE57432002EA
DirectX3D
27bb20fdd3e145e4bee3db39ddd6e64c
{9DA96BF9CEBD45c5BFCF94CBE61671F5}
52F260023059454187AF826A3C07AF2A
A512548E76954B6E92C21055517615B0
7F54B9CE8887428dBA9CEEB94CEF4C72
AF6AD80AA4244A59AFB3D83ECF5173CC
{B6F7542F-B8FE-46a8-9605-98856A687097}
DA19AC3ADD2F4121AAD84AC5FBCAFC71
F7FC1AE45C5C4758AF03EF19F18A395D
5F99C1642A2F4e03850721B4F5D7C3F8
4BB4003860154917BC7D8230BF4FA58A
707ca37322474f6ca841f0e224f4b620
window
EditBox
PicBox
ShapeBox
Button
CheckBox
RadioBox
ComboBox
ComObject
ListView
TransLabel
DropTarget
SuperBtn
RichEdit
PageControl
\config.ini
8WXJ/j
Kd\'yf
l.0_a:
L($WB<
;?$Le.
o`as%b
=Rk?Z&
15_k7`
P`$jsR
&?aX+n]}
CF%i;}/)
{~&=yE
D?;R0CJ
CCc&tn
=3?li]L
(ah[{._
jzX(dA5
C2'dK9
a7Vy@,
yex1z_
R'-Is'
P_F14n
\4J)iQ^
KFB^1Np\.
e :E,Ih4
iPMl}_u
<NE>e1-5
8.dVI)S
nuiR{v
fm:V(L
I/.%$2h
c.{f:O
X|xp%R
fI`Wf"
sJq95Io
xTjU|k
|BOz9<
ikMr&w
z6km
Av- mWJA
fA#E~R}
U!9oa)
NJkvO/
T+:cYm
%{TwS^
A"|r\>^\i
D]B~g)B
{3(o79E
)2BnE78
| e3;`'y
lk*:!f/B
te@Mp1
`|Bm2:
pLbxhp
Fg^{M$
+`,#g
K7nevY
c%~WRy
8|$N3=
<==GkR
NH3io|
h.I29t
}[Rqc5
w*Og>&E3
hGa,n
36d3H~
x<|Z_II&?
O*1EQ5>,
rH,1?-)0TI
+tLd,H
*-@s&?
q-nlA;X
m`R"_Y
K?R fx
[=Q`f\
%Nv}S\
~NL Yu
7EvC@P|
m4J}p;H
gKYn"a=
F.0<YF(a
RY[JM$Z2
o2stw.
Y2:mBB
Jhd|A
y:h=Sx
}v+|2*
hAY7:Z"t
LQ-FnE
M2@UO34o
3F|3%z>
c=`cL$!
qly2th
8kM?qKf*
kNo?$j
=gKv's
.U(GIP
qr`"4uZ
?z"xl:
FkFm!o
7kTkM`
::Io[k
S0`_I`A
jcfP+`"f
](S1^|@
:pZ$%G5m
{h=u#"
YjA1+z
CS2)} )
@\}_hB
m6.lt+
Z~VBk'
gEJs`e
F,LCZ*:Q
<Q$sqV
}]X{!0
FIF]Bx
>S<5rr
>+/MuA
3TVPbu
&}fpQJ
82<W/T
`O]T,d]Q
tP)0h~
# k~1?4W
C5//W(
HUMUI.SHE
l~*PQ+
r:Bw17
;VeN@^
W9_?o|
(pu1g}D
106[ $nI
G7|>55:
)nU6ef
]tiozHH
HUMUI.SHE
2M\m*H
&<;`=W
}oS`5s
yG&L?\
/ZlfRF
g{McOO
/I;./O
oK3lIu
=*e6<M]
j//YHM
dV`]>N
oYEE'R^
|~*?gj
!This program cannot be run in DOS mode.
=f%4ho
/pPmr
G:CvfV
\r\W_N.
^u2>*}q
\,VTbm
m9d5N~
g5rb\]
k%jPJo
s.f}db
e^4eds
I%nUOE1!93
|F#9{Jj
C*m#ysv
\XG:%
bz49N.
ThG1sE
E4"0$(
NyLM+@q
)?:X`Z
VI$:jg|
hg%fpM
(V`yr(8
?~\dikh
.,v%,<
S.Ac9SR
c.(!>gM
B]ne>`6q
g|^;#|
B+X!>'
(?sQW^
BCM8]|/
s+Lhn@[0/
tuZ=d&
tAKNE'
d<VC*AN
> \Y +
;'+GTz
bq|w1U
0.I%3s
cx;9OMq`
A6_&Zv
,wAe.kI
z&^0nZ^
@'dBbY
aiUy'%34xu
'>h.B'
3^FeL*/Y
X3:c@J
zW9#g&
q^8AVaz7
kkJ^/f`
TogslH
3X)4nYg
8G)mHFd
,zQbyO
LpO1z5=
7i`xaX
&b4*~r
la>6Ss
jYI&oh
xx0H>>
,]Iqq/
+mirhj
Zk_'2=
!H\`wf/[;
MVB9Y@x
[^dYz[
y'+xq?
F;l=cv
]OJ8"Z;
SxvOhqu
T*spwd
\<wp]w
qVbv=K
M\WJZZ
CE*P)$
%`#nD'
&eW?Ua}V%
S3`8P%~
Y4~mrO
QypmUH
3OyMbc
(@`"i5
@=05]vm
mC]pF~
v$/_cR
P2"Tby"
zg}ey2
PTMSrj
pS>Q2C
:+OG&X/f
GqW/zI
^P8QfWj
QqZmLz
2+uGer
d+Tg`V
dO!&_(L
pgp3 ~~~
<EV#/'
2mFyf:
|CkD -
k`,l~MK3
zqol#6#0L
"tGq.M
lRZm?P
3;a~l(I
T`Ju#r)6^J
Fv1?r@
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.lIa2
tehtris Generic.Malware
ClamAV Win.Malware.Trojanx-9951053-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.th
ALYac Gen:Variant.Zusy.552523
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005246d51 )
Alibaba Clean
K7GW Trojan ( 005246d51 )
Cybereason malicious.114cec
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Gen:Variant.Zusy.552523
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.552523
Tencent Clean
TACHYON Clean
Sophos Generic Reputation PUA (PUA)
F-Secure Clean
DrWeb Trojan.Siggen19.27544
VIPRE Gen:Variant.Zusy.552523
TrendMicro Clean
McAfeeD Real Protect-LS!2D7E2EB114CE
Trapmine Clean
FireEye Generic.mg.2d7e2eb114ceca66
Emsisoft Gen:Variant.Zusy.552523 (B)
huorong Clean
GData Win32.Trojan.PSE.18B7I2K
Jiangmin HackTool.FlyStudio.beg
Webroot Clean
Varist W32/Trojan.IRG.gen!Eldorado
Avira Clean
Antiy-AVL Trojan[Packed]/Win32.FlyStudio
Kingsoft malware.kb.a.903
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium TrojWare.Win32.Agent.OSCF@5rs7jr
Arcabit Trojan.Zusy.D86E4B
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.TE.A!ml
Google Detected
AhnLab-V3 Trojan/Win.TrojanX-gen.R601455
Acronis Clean
McAfee GenericRXSH-CA!2D7E2EB114CE
MAX malware (ai score=82)
VBA32 BScope.Trojan.Occamy
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CIA24
Rising Clean
Yandex Clean
Ikarus Worm.Win32.Nuj
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/CoinMiner.PHP!tr
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (D)
alibabacloud VirTool:Win/Sabsik.TA
No IRMA results available.