Static | ZeroBOX

PE Compile Time

2015-09-13 14:50:21

PE Imphash

77e413028d4bf04e52d59e9daa270728

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008a1ae 0x0008b000 6.54776683408
.rdata 0x0008c000 0x0003bfda 0x0003c000 7.00106374691
.data 0x000c8000 0x0001f788 0x00010000 5.44520864753
.rsrc 0x000e8000 0x0000a998 0x0000b000 4.86226401765

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x000e9b28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x000e9b28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x000e9b28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
RT_CURSOR 0x000eb7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000eb7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000eb7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_CURSOR 0x000eb7b8 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ec190 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000f01a8 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MENU 0x000eb158 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x000eb158 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x000eaca0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x000ecba8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x000eb870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x000eb870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x000eb870 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_ICON 0x000ea0a8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x000ea0a8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x000ea0a8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x000f27c8 0x000001cd LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.dll:
0x48c170 lstrcmpiA
0x48c174 SetEndOfFile
0x48c178 UnlockFile
0x48c17c LockFile
0x48c180 FlushFileBuffers
0x48c184 SetFilePointer
0x48c188 GetCurrentProcess
0x48c18c DuplicateHandle
0x48c190 lstrcpynA
0x48c194 SetLastError
0x48c1a0 LocalFree
0x48c1a4 MultiByteToWideChar
0x48c1a8 WideCharToMultiByte
0x48c1b0 SetStdHandle
0x48c1b4 GetCurrentProcessId
0x48c1bc GetLocaleInfoA
0x48c1c0 IsBadCodePtr
0x48c1c4 IsBadReadPtr
0x48c1c8 CompareStringW
0x48c1cc CompareStringA
0x48c1d0 InterlockedExchange
0x48c1dc GetStringTypeW
0x48c1e0 GetStringTypeA
0x48c1e4 IsBadWritePtr
0x48c1e8 VirtualQuery
0x48c1ec GetSystemInfo
0x48c1f0 VirtualAlloc
0x48c1f4 VirtualProtect
0x48c1f8 LCMapStringW
0x48c1fc LCMapStringA
0x48c204 VirtualFree
0x48c208 HeapCreate
0x48c20c HeapDestroy
0x48c210 GetFileType
0x48c214 SetHandleCount
0x48c220 CreateSemaphoreA
0x48c224 ResumeThread
0x48c228 ReleaseSemaphore
0x48c234 GetProfileStringA
0x48c238 WriteFile
0x48c23c ReadFile
0x48c240 GetLastError
0x48c248 CreateFileA
0x48c24c SetEvent
0x48c250 FindResourceA
0x48c254 LoadResource
0x48c258 LockResource
0x48c25c GetModuleFileNameA
0x48c260 GetCurrentThreadId
0x48c264 ExitProcess
0x48c268 GlobalSize
0x48c26c GlobalFree
0x48c278 lstrcatA
0x48c27c lstrlenA
0x48c280 WinExec
0x48c284 lstrcpyA
0x48c288 FindNextFileA
0x48c28c GlobalReAlloc
0x48c290 HeapFree
0x48c294 HeapReAlloc
0x48c298 GetProcessHeap
0x48c29c HeapAlloc
0x48c2a0 GetFullPathNameA
0x48c2a4 FreeLibrary
0x48c2a8 LoadLibraryA
0x48c2ac GetVersionExA
0x48c2b4 CreateThread
0x48c2b8 CreateEventA
0x48c2bc Sleep
0x48c2c0 GlobalAlloc
0x48c2c4 GlobalLock
0x48c2c8 GlobalUnlock
0x48c2cc FindFirstFileA
0x48c2dc GetStdHandle
0x48c2e0 GetACP
0x48c2e4 HeapSize
0x48c2e8 TerminateProcess
0x48c2f0 RaiseException
0x48c2f4 RtlUnwind
0x48c2f8 GetStartupInfoA
0x48c2fc GetOEMCP
0x48c300 GetCPInfo
0x48c304 GetProcessVersion
0x48c308 SetErrorMode
0x48c30c GlobalFlags
0x48c310 GetCurrentThread
0x48c314 GetFileTime
0x48c318 FindClose
0x48c31c GetFileAttributesA
0x48c324 GetFileSize
0x48c328 TlsGetValue
0x48c32c LocalReAlloc
0x48c330 TlsSetValue
0x48c334 TlsFree
0x48c338 GlobalHandle
0x48c33c TlsAlloc
0x48c340 LocalAlloc
0x48c344 lstrcmpA
0x48c348 GetVersion
0x48c34c GlobalDeleteAtom
0x48c350 GlobalFindAtomA
0x48c354 GlobalAddAtomA
0x48c358 GlobalGetAtomNameA
0x48c360 GetModuleHandleA
0x48c364 GetProcAddress
0x48c368 MulDiv
0x48c36c GetCommandLineA
0x48c370 GetTickCount
0x48c374 CreateProcessA
0x48c378 WaitForSingleObject
0x48c37c CloseHandle
Library USER32.dll:
0x48c3dc OpenClipboard
0x48c3e0 SetClipboardData
0x48c3e4 EmptyClipboard
0x48c3e8 GetSystemMetrics
0x48c3ec GetCursorPos
0x48c3f0 MessageBoxA
0x48c3f4 SetWindowPos
0x48c3f8 SendMessageA
0x48c3fc DestroyCursor
0x48c400 SetParent
0x48c404 GetClipboardData
0x48c408 PostMessageA
0x48c40c GetTopWindow
0x48c410 GetParent
0x48c414 GetFocus
0x48c418 GetClientRect
0x48c41c InvalidateRect
0x48c420 ValidateRect
0x48c424 UpdateWindow
0x48c428 CloseClipboard
0x48c42c wsprintfA
0x48c430 EqualRect
0x48c434 GetWindowRect
0x48c438 SetForegroundWindow
0x48c43c WaitForInputIdle
0x48c440 IsWindow
0x48c444 DestroyMenu
0x48c448 IsChild
0x48c44c ReleaseDC
0x48c450 IsRectEmpty
0x48c454 FillRect
0x48c458 GetDC
0x48c45c SetCursor
0x48c460 LoadCursorA
0x48c464 SetCursorPos
0x48c468 SetActiveWindow
0x48c46c GetSysColor
0x48c470 SetWindowLongA
0x48c474 GetWindowLongA
0x48c478 RedrawWindow
0x48c47c EnableWindow
0x48c480 IsWindowVisible
0x48c484 OffsetRect
0x48c488 PtInRect
0x48c48c DestroyIcon
0x48c490 IntersectRect
0x48c494 InflateRect
0x48c498 SetRect
0x48c49c SetScrollPos
0x48c4a0 SetScrollRange
0x48c4a4 GetScrollRange
0x48c4a8 SetCapture
0x48c4ac LoadIconA
0x48c4b0 TranslateMessage
0x48c4b4 DrawFrameControl
0x48c4b8 DrawEdge
0x48c4bc DrawFocusRect
0x48c4c0 WindowFromPoint
0x48c4c4 GetMessageA
0x48c4c8 DispatchMessageA
0x48c4cc SetRectEmpty
0x48c4dc DrawIconEx
0x48c4e0 CreatePopupMenu
0x48c4e4 AppendMenuA
0x48c4e8 ModifyMenuA
0x48c4ec CreateMenu
0x48c4f4 GetDlgCtrlID
0x48c4f8 GetSubMenu
0x48c4fc EnableMenuItem
0x48c500 ClientToScreen
0x48c508 LoadImageA
0x48c510 ShowWindow
0x48c514 IsWindowEnabled
0x48c51c GetKeyState
0x48c524 PostQuitMessage
0x48c528 IsZoomed
0x48c52c GetClassInfoA
0x48c530 GetWindowTextA
0x48c538 CharUpperA
0x48c53c GetWindowDC
0x48c540 BeginPaint
0x48c544 EndPaint
0x48c548 TabbedTextOutA
0x48c54c DrawTextA
0x48c550 GrayStringA
0x48c554 GetDlgItem
0x48c558 DestroyWindow
0x48c560 EndDialog
0x48c564 GetNextDlgTabItem
0x48c568 GetWindowPlacement
0x48c570 GetForegroundWindow
0x48c574 GetLastActivePopup
0x48c578 GetMessageTime
0x48c57c RemovePropA
0x48c580 CallWindowProcA
0x48c584 GetPropA
0x48c588 UnhookWindowsHookEx
0x48c58c SetPropA
0x48c590 GetClassLongA
0x48c594 CallNextHookEx
0x48c598 SetWindowsHookExA
0x48c59c CreateWindowExA
0x48c5a0 GetMenuItemID
0x48c5a4 GetMenuItemCount
0x48c5a8 RegisterClassA
0x48c5ac GetScrollPos
0x48c5b0 UnregisterClassA
0x48c5b4 AdjustWindowRectEx
0x48c5b8 MapWindowPoints
0x48c5bc SendDlgItemMessageA
0x48c5c0 ScrollWindowEx
0x48c5c4 IsDialogMessageA
0x48c5c8 SetWindowTextA
0x48c5cc MoveWindow
0x48c5d0 CheckMenuItem
0x48c5d4 SetMenuItemBitmaps
0x48c5d8 GetMenuState
0x48c5e0 GetClassNameA
0x48c5e4 GetDesktopWindow
0x48c5e8 LoadStringA
0x48c5ec GetSysColorBrush
0x48c5f0 DefWindowProcA
0x48c5f4 GetSystemMenu
0x48c5f8 DeleteMenu
0x48c5fc GetMenu
0x48c600 SetMenu
0x48c604 PeekMessageA
0x48c608 IsIconic
0x48c60c SetFocus
0x48c610 GetActiveWindow
0x48c614 GetWindow
0x48c61c SetWindowRgn
0x48c620 GetMessagePos
0x48c624 ScreenToClient
0x48c62c CopyRect
0x48c630 LoadBitmapA
0x48c634 WinHelpA
0x48c638 KillTimer
0x48c63c SetTimer
0x48c640 ReleaseCapture
0x48c644 GetCapture
Library GDI32.dll:
0x48c024 SetStretchBltMode
0x48c028 GetClipRgn
0x48c02c CreatePolygonRgn
0x48c030 SelectClipRgn
0x48c034 DeleteObject
0x48c038 CreateDIBitmap
0x48c040 CreatePalette
0x48c044 StretchBlt
0x48c048 SelectPalette
0x48c04c RealizePalette
0x48c050 GetDIBits
0x48c054 GetWindowExtEx
0x48c058 GetViewportOrgEx
0x48c05c GetWindowOrgEx
0x48c060 BeginPath
0x48c064 EndPath
0x48c068 PathToRegion
0x48c06c CreateEllipticRgn
0x48c070 CreateRoundRectRgn
0x48c074 GetTextColor
0x48c078 GetBkMode
0x48c07c GetBkColor
0x48c080 GetROP2
0x48c084 GetStretchBltMode
0x48c088 GetPolyFillMode
0x48c090 CreateDCA
0x48c094 CreateBitmap
0x48c09c GetObjectA
0x48c0a0 CreatePen
0x48c0a4 PatBlt
0x48c0a8 CombineRgn
0x48c0ac CreateRectRgn
0x48c0b0 FillRgn
0x48c0b4 CreateSolidBrush
0x48c0b8 GetStockObject
0x48c0bc CreateFontIndirectA
0x48c0c0 EndPage
0x48c0c4 EndDoc
0x48c0c8 DeleteDC
0x48c0cc StartDocA
0x48c0d0 StartPage
0x48c0d4 BitBlt
0x48c0d8 CreateCompatibleDC
0x48c0dc Ellipse
0x48c0e0 Rectangle
0x48c0e4 LPtoDP
0x48c0e8 DPtoLP
0x48c0ec GetCurrentObject
0x48c0f0 RoundRect
0x48c0f8 GetDeviceCaps
0x48c0fc SaveDC
0x48c100 RestoreDC
0x48c104 SetBkMode
0x48c108 SetPolyFillMode
0x48c10c SetROP2
0x48c110 SetTextColor
0x48c114 SetMapMode
0x48c118 SetViewportOrgEx
0x48c11c OffsetViewportOrgEx
0x48c120 SetViewportExtEx
0x48c124 ScaleViewportExtEx
0x48c128 SetWindowOrgEx
0x48c12c SetWindowExtEx
0x48c130 ScaleWindowExtEx
0x48c134 GetClipBox
0x48c138 ExcludeClipRect
0x48c13c MoveToEx
0x48c140 LineTo
0x48c144 SetBkColor
0x48c148 SelectObject
0x48c14c GetTextMetricsA
0x48c150 Escape
0x48c154 ExtTextOutA
0x48c158 TextOutA
0x48c15c RectVisible
0x48c160 PtVisible
0x48c164 GetViewportExtEx
0x48c168 ExtSelectClipRgn
Library WINMM.dll:
0x48c64c midiStreamRestart
0x48c650 midiStreamClose
0x48c654 midiOutReset
0x48c658 midiStreamStop
0x48c65c midiStreamOut
0x48c664 midiStreamProperty
0x48c668 midiStreamOpen
0x48c670 waveOutOpen
0x48c674 waveOutGetNumDevs
0x48c678 waveOutClose
0x48c67c waveOutReset
0x48c680 waveOutPause
0x48c684 waveOutWrite
Library WINSPOOL.DRV:
0x48c694 ClosePrinter
0x48c698 DocumentPropertiesA
0x48c69c OpenPrinterA
Library ADVAPI32.dll:
0x48c000 RegCloseKey
0x48c004 RegOpenKeyExA
0x48c008 RegSetValueExA
0x48c00c RegQueryValueA
0x48c010 RegCreateKeyExA
Library SHELL32.dll:
0x48c3d0 ShellExecuteA
0x48c3d4 Shell_NotifyIconA
Library ole32.dll:
0x48c6e0 OleUninitialize
0x48c6e4 CLSIDFromString
0x48c6e8 OleInitialize
Library OLEAUT32.dll:
0x48c388 LoadTypeLib
0x48c38c UnRegisterTypeLib
0x48c390 SafeArrayPutElement
0x48c394 SafeArrayCreate
0x48c398 SafeArrayDestroy
0x48c39c SysAllocString
0x48c3a0 VariantInit
0x48c3a4 VariantCopyInd
0x48c3a8 SafeArrayAccessData
0x48c3b0 SafeArrayGetDim
0x48c3b4 SafeArrayGetLBound
0x48c3b8 SafeArrayGetUBound
0x48c3bc VariantChangeType
0x48c3c0 VariantClear
0x48c3c4 VariantCopy
0x48c3c8 RegisterTypeLib
Library COMCTL32.dll:
0x48c018 ImageList_Destroy
0x48c01c None
Library WS2_32.dll:
0x48c6a4 accept
0x48c6a8 getpeername
0x48c6ac recv
0x48c6b0 ioctlsocket
0x48c6b4 recvfrom
0x48c6b8 WSAAsyncSelect
0x48c6bc closesocket
0x48c6c0 WSACleanup
0x48c6c4 inet_ntoa
Library comdlg32.dll:
0x48c6cc GetFileTitleA
0x48c6d0 GetSaveFileNameA
0x48c6d4 GetOpenFileNameA
0x48c6d8 ChooseColorA

!This program cannot be run in DOS mode.
^)Rich,
`.rdata
@.data
SVWSQRV3
rocA9F
SVWSQRV3
rocA9F
t(ENEN;
L$$_^]
T$$_^]
D$$_^]
D$4SUV
D$(t,;
L$DQRf
T$$RPQ
D$$~9+
F\_^][
L$$_^d
L$@^[d
D$PQRP
L$pPQR
D$hRQP
9L$x~k
L$T_^][d
L$lRVQ
D$hQRP
D$hQRP
T$pPQR
\$8UVW
L$DPQj
L$ _^d
W9^du-
L$ PQh
L$L_^][d
L$D_^][d
L$@RUQ
L$|_^][d
L$|_^][d
L$|_^][d
T$0VRPSQ
L$4_^[d
V#D$,WPQ
D$@UPQ
T$XUSR
T$HQRP
L$x_^d
D$(SUV
T$8RWj
L$ _^][d
l$<VWj
L$(VQVj
L$(UUh
t$LUPh
o0SSSSU
D$dSUVW
D$@WPS
L$`_^][d
D$,RVh
D$HUPQ
\$PVUUS
D$hSUV3
D$,Pj<j
L$h_^][d
L$X_^d
t$ 90t
L$4S+L$0Qj
D$LPUj
D$ PQR
D$89Vdu
FpHt&Ht
D$LUSWP
L$$_^][d
L$,_[3
L$,_[3
L$(WQR
QQUWSS
L$P_]^[d
T$hQRWW
t]9|$<tW
L$x_^]
L$<SQR
T$<RVW
9|$8tt
T$<WRh
T$lPRh
T$ SRh
9l$xtU9
u29l$xu,
L$XSQh
D$,SPh
T$,SRh
T$,SRh
T$,SRh
t$(SSh
t$$RVP
|$,RPQ
L$H][d
L$HSUVWP
D$XPQU
D$8VPQ
T$ SWRP
L$L_^]3
t%RSQP
XY[Z[]
~'PSQR
\$<VW3
L$4_^3
D$XQRWP
D$dQUWRP
D$0WPQ
T$$+D$4
D$xH9K
L$L^[d
9^xu5j
L$X_^]3
h9n`u;
D$8RPj
T$DQRU
D$PRPQ
L$TSWQ
l$HQRVU
D$H_^][
\$lUV3
L$h_^]3
T$\jdSR
L$Hj&Q
;t$Xu";\$\u
L$DSVQ
L$,_^]3
L$$_^][d
L$0PQS
L$ ]_^
L$ QSR
D$TVPW
D$TRPW
WWVQRWWS
D$(P<K
D$ h<K
D$ \<K
D$$QRP
T$,PQR
D$$RSSP
D$8WVRPQ
L$XRQP
l$@VW3
L$8_^][d
u"8D$yu
D$(_^][
8MThdu
~P9~Pun
t&9^$t
F(9V8tQ
F<_^][
F<_^][
|$@ Wu
|$D UV
L$8^]_3
D$dx>K
D$4|>K
@;l$\~Z
L$X;L$
D$4x>K
uh9^8uX
F89^8u&j
L$T_^][d
L$L_^][d
D$,;\$|
L$0PQR
PQj WUS
T$dPQR
L$l_^][d
L$8WPQR
T$DQSR
D$49D$$}
T$\;D$Xu
L$(PQR
T$,RQP
T$(PQR
L$x_^][d
L$l_^][d
L$TPQR
L$dPQRV
u+\$l
L$4SUV
L$4WPQR
D$ |2;
L$@_^][d
u._^][
L$ WPQ
T$,RQP
L$\_^][d
L$@RQj
D$@RPQj
L$T_^]d
FD uy9D$$}s
FD@ul9L$(}f
L$P_^d
L$\_^][d
;D$xt&
9D$$t+
L$D_]d
L$ ^][d
D$$QUP
L$|_^][d
L$t][d
D$$SUV
D$DURP
RVPUSQ
L$$_^][d
j VUPWQ
T$(QVURWP
L$,_^][d
D$$_^[
D$$_^[
L$4VQUP
L$$_^][d
L$4UQWP
L$$_^][d
T$0SUV
L$(_^][d
T$8QRP
L$(_^][d
L$8_^][d
|$LtE;
t$PPVS
L$8_^][d
T$\WVR
jBWVSSQ
D$(_^]
\$ PQV
L$$_^][d
D$ xCK
L$H_^][d
SWVVVRPV
L$$^]d
L$D_^[d
RWhL M
T$DWRh
D$$\JK
D$,QRPS
L$$RPQS
L$<_^][d
D$L\JK
L$(RPQ
NTRPQj
L$(RPQ
T$(PQR
D$(QRP
T$DPQRW
L$<RPQW
L$T_^]
Nh;NX|
Vh;VX|
Fxt_;FTu@
Nh;NX|
D$ h 3D
P$RWPh
L$$hh!M
ujh8!M
D$0QVRP
jdQh0MK
L$$PVh
D$4RPQ
D$ PQR
=pscat
=YARGtD= BGRt
h BGRUPV
hYARGUQV
=lcmnw_tQ=tsbat-=knilt
=rtnmto
hknilUPV
htsbaUQV
=rtrpt =rncst
=capst
= baLt = ZYXt
^tt!h|'M
TADIut
tkPUSV
ETLPuF
L$XhD.M
D$8QVRPU
QRVWPU
D$0`NK
D$$SPh
3;L$4s
T$8QRU
L$Xh`[
T$Xhh,M
L$Xh@,M
T$,SRW
T$0;t$
PPPQSG
D$ EJ;
D$4SUVW
L$$QWV
D$,Hx;@
D$(CM;
D$Hvm3
L$Lvj3
D$(FO;
L$t_^d
D$<tYK
D$<hYK
D$4hYK
D$ RPUhD
QUh 1M
L$l_^][d
L$$^[d
L$(WSR
T$0PQR
WjdjdPQh
|z;^<}uWS
L$D_^][d
L$\_^][d
It#Iu%
^l_^][
tI;Ftr
tL9~HvG;
~(9~$u
D/ VPS
L$<RWUQV
tLhH5M
L$$j QV
L$(VQU
hPCCiU
L$(RPVQWU
u!h(7M
l$,WuAS
|$ VurU
D$@QRPU
T$ PQW
trhH6M
Ht&HtcI
D$(SUW
=TADIt
t4h :M
TADIu"
hTADIV
Ht]Ht2Ht
HtfHt;Ht
t$,u%:D$<u
:L$<t;
\$$u9f;
\$@QUR
;=3333v
HtHHuz
RQhPAM
V,_^[Y
D$ _^][
EHPWVS
u]9B uX
uR9BxuM
'9A`u"9
tq9~Dt
nd9~dt
tS9~@uN
T$LPQR
|$HPWS
L$(RPQ
T$DPVS
T$LRWS
Fdf+Fh
D$(8D*
tRHt}H
NH_^][
T$LWUQVR
L$4WQUVS
;l$ }:
|$$}$WP
\$\}-j
O(_^][
T$H} VP
T$$PRV
D$(QPW
L$,SUV
L$0SUV@W
NX9NXu
QPSWVR
T$PQRP
D$$SUV
D$(;l$
\$(UVW
D$,_^]
D$(CUSWP
9o4u'V
9t$0v8
T$,RWV
T$,RWV
T$,RWV
L$,QWV
T$,RWV
L$ RUPj
9t$Tu
T+3x%A
;D$<s!
T$,PQh8nK
D$0Qh,oK
|$ WUSV
D$$SUV
L$(SUV
N4_^]3
F$@;F(v
F$@@;F(v
QQSVWd
t.;t$$t(
p`;5$eN
p`;5$eN
B 02CV
C =02CVu
HYYtJHt9H
F95h_N
u79=hgN
QQSVW3
t#SSUP
t$$VSS
_^][YY
FT=`eM
VC20XC00U
QQSVWj
t5Ht&Ht
t5Ht&-=
t6Ht*Ht
sVS;7|B;w
F,98uX
t!SS9]
HHt`HHt\
HHtjHHtF
oG<-uK
PPPPPPPP
PPPPPPPP
PPPPPPPP
f9=nbN
>:u>FV
$f95lbN
VVVVVUWUUj
VVVVVj
s9~(~
SVWj ^
t+Ht$Ht
HtHHt
F9=dcN
+t"HHt
WWWWVSW
t2WWVPVSW
;F(r(8_
nt2Ht#Ht
F\jLSP
u$SShe
ue;=@^N
z;=<^N
M;=D^N
(;=8^N
Wj(_Wj
hWj@_;
PQQQQQ
VWh^_H
u@h^_H
PPPPhd
tvWWWWU
F,_^][
(wqt\HHtS
t>Ht Ht
QSUVWj
n0SSSSU
_SSSSU
Ph_^][Y
tD9_Pt?
w]h^_H
Ht#HHt
@t4Ht1Ht_Ht
^$_^[]
F(_+F$^[;E
<A|2<Z
<A|@<Z
+tJHt:Ht*
P<PuWSV
PWVWWW
^,_^][
kernel32.dll
kernel32.dll
NTDLL.DLL
kernel32.dll
NTDLL.DLL
NTDLL.DLL
ntdll.dll
kernel32
kernel32.dll
kernel32.dll
advapi32.dll
advapi32.dll
advapi32.dll
CreateToolhelp32Snapshot
Process32First
Process32Next
CloseHandle
ExitProcess
GlobalSize
NtOpenProcess
GetCurrentProcess
NtDuplicateObject
NtClose
NtQuerySystemInformation
RtlMoveMemory
RtlMoveMemory
OpenProcess
DuplicateHandle
NtQueryObject
NtQueryObject
RtlMoveMemory
RtlMoveMemory
WideCharToMultiByte
RtlMoveMemory
RegOpenKeyA
RegEnumValueA
RegCloseKey
d09f2340818511d396f6aaf844c7e325
window
PicBox
Button
HyperLinker
Variant
VS%:C&
Cy^IX4
NS8M.3
{>F `U
z~TVC~\
7ny0<T\O
C5D)9L)
C<w\vI
v(Ei7XX
L]su>fL
tvY`6V}
n_9V3#P=Zf
Q]@Hr2
%*o-Y|
r]XJW@O
|G0[Yxd
Y^=^C"c
[I(3/#N0.bd
>)ch!vabP
k~14E4
GWoO:iG
j"%u=w
0tDyyk
^p[5Ma
b5]\+;
(!h(1P
N(F`?D
Yt[u,Q
~`zVwk=
yfC}cIa
}.:|%8\
~#gWj./
RG[B[X
pYN:NX
@|H.NI
Y}3 LP
009 L~
9;;YJ@
)cG7(1
eR^\j#r
HC=VyV
TQk)UN4~Z
fOK{YI
F_mMxK
YEjJNW
^/x3lH
QayYNb&
nwechat.exe
@######DFDSGSFGADFAFAGHHHADDDD
AC,1A,4E,A4,F0,6A,F1,31,42,FE,42,3A,3B,09,F1,1A,3E,69,DA,37,29,3B,92,CB,4A,59,98,CD,FD,4E,7A,6C,EB,5F,C1,5B,3B,E8,F8,
installdir
software\tencent\bugreport\wechatwindows
\wechat.exe
#space
#mb_ok
#mb_cancel
#mb_yes
#mb_no
#mb_yesno
#mb_infomation
#mb_critical
#mb_question
#in_text
#in_value
#in_float
#in_password
!This program cannot be run in DOS mode.
=f%4ho
/pPmr
G:CvfV
\r\W_N.
^u2>*}q
\,VTbm
m9d5N~
g5rb\]
k%jPJo
s.f}db
e^4eds
I%nUOE1!93
|F#9{Jj
C*m#ysv
\XG:%
bz49N.
ThG1sE
E4"0$(
NyLM+@q
)?:X`Z
VI$:jg|
hg%fpM
(V`yr(8
?~\dikh
.,v%,<
S.Ac9SR
c.(!>gM
B]ne>`6q
g|^;#|
B+X!>'
(?sQW^
BCM8]|/
s+Lhn@[0/
tuZ=d&
tAKNE'
d<VC*AN
> \Y +
;'+GTz
bq|w1U
0.I%3s
cx;9OMq`
A6_&Zv
,wAe.kI
z&^0nZ^
@'dBbY
aiUy'%34xu
'>h.B'
3^FeL*/Y
X3:c@J
zW9#g&
q^8AVaz7
kkJ^/f`
TogslH
3X)4nYg
8G)mHFd
,zQbyO
LpO1z5=
7i`xaX
&b4*~r
la>6Ss
jYI&oh
xx0H>>
,]Iqq/
+mirhj
Zk_'2=
!H\`wf/[;
MVB9Y@x
[^dYz[
y'+xq?
F;l=cv
]OJ8"Z;
SxvOhqu
T*spwd
\<wp]w
qVbv=K
M\WJZZ
CE*P)$
%`#nD'
&eW?Ua}V%
S3`8P%~
Y4~mrO
QypmUH
3OyMbc
(@`"i5
@=05]vm
mC]pF~
v$/_cR
P2"Tby"
zg}ey2
PTMSrj
pS>Q2C
:+OG&X/f
GqW/zI
^P8QfWj
QqZmLz
2+uGer
d+Tg`V
dO!&_(L
pgp3 ~~~
<EV#/'
2mFyf:
|CkD -
k`,l~MK3
zqol#6#0L
"tGq.M
lRZm?P
3;a~l(I
T`Ju#r)6^J
Fv1?r@
HQ[1AH
O]-`]_
PlEaM0T
K|Ky\@V
13:`cK&VM
^>E<&f
;x#3:K_
V;vGWR
Gnvax/
axZ!7}h
x7(8D#
^**9;LY
*tVU[T#
xe%CNs
_[Qdte
;=77WE
t8VQ2\
9F.cLe
NOW=\y
_7hE]m
F^Vp}!;
Z~'<5d
ZX@P8
hJK.ZH
O/";_)
fZnF)M
*omj Y
#A3*Vs
Z6w}oz
vn2}sp
65JSSe
\Uc4~_
0<E*9Uu
6]on<X<
R?~?&_&
j*mI~1
(DA/Rv
h+c"gf
K/k]-kD
x>K7GZ
HpO9'+
A{JZ%{
7,QM1A
N'Uth='z
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
KERNEL32.DLL
COMCTL32.dll
GDI32.dll
MSIMG32.dll
MSVCRT.dll
MSVFW32.dll
USER32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ImageList_Draw
BitBlt
TransparentBlt
DrawDibOpen
SkinH_EL.dll
SkinH_AdjustAero
SkinH_AdjustHSV
SkinH_Attach
SkinH_AttachEx
SkinH_AttachExt
SkinH_AttachRes
SkinH_AttachResEx
SkinH_Detach
SkinH_DetachEx
SkinH_GetColor
SkinH_LockUpdate
SkinH_Map
SkinH_NineBlt
SkinH_SetAero
SkinH_SetBackColor
SkinH_SetFont
SkinH_SetFontEx
SkinH_SetForeColor
SkinH_SetMenuAlpha
SkinH_SetTitleMenuBar
SkinH_SetWindowAlpha
SkinH_SetWindowMovable
SkinH_VerifySign
SkinH_AttachRes
SkinH_SetAero
SkinH_SetTitleMenuBar
SkinH_LockUpdate
SkinH_AdjustHSV
SkinH_Detach
kernel32.dll
NTDLL.DLL
ntdll.dll
kernel32
advapi32.dll
CreateToolhelp32Snapshot
Process32First
Process32Next
CloseHandle
ExitProcess
GlobalSize
NtOpenProcess
GetCurrentProcess
NtDuplicateObject
NtClose
NtQuerySystemInformation
RtlMoveMemory
OpenProcess
DuplicateHandle
NtQueryObject
WideCharToMultiByte
RegOpenKeyA
RegEnumValueA
RegCloseKey
http://weixin.qq.com/cgi-bin/readtemplate?t=win_weixin&lang=zh_CN
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
p?+?j?
hK;)V-;K
n;=jV[[9
http://www.cqyuyu.comg
WIN7 64
QQ:2346024
4i5U6B738%9
B#C0D?EQFeG|H
E=FZGrH
QyReSOT5U
qdZRMHD@=;86421/.-+*)(''&%$$#""!! 
|?5^<@
0123456789ABCDEF
123456789
0123456789ABCDEF
Qkkbal
DDDDUUUU
00003333
""""UUUU
0@P`p
!1AQaq
"2BRbr
#3CScs
$4DTdt
%5EUeu
&6FVfv
'7GWgw
(8HXhx
)9IYiy
*:JZjz
+;K[k{
,<L\l|
-=M]m}
.>N^n~
/?O_o
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
BKbhTb~XBK!;
inflate 1.1.3 Copyright 1995-1998 Mark Adler
?u='@^
CNotSupportedException
CMemoryException
CException
CMemFile
CTempGdiObject
CTempDC
CPalette
CBitmap
CBrush
CGdiObject
CPaintDC
CWindowDC
CClientDC
CUserException
CResourceException
CDialog
MS Sans Serif
MS Shell Dlg
CTempWnd
AfxOldWndProc423
AfxWnd42s
AfxControlBar42s
AfxMDIFrame42s
AfxFrameOrView42s
AfxOleControl42s
GetMonitorInfoA
EnumDisplayMonitors
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
GetSystemMetrics
USER32
DISPLAY
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
InitCommonControlsEx
COMCTL32.DLL
CPtrArray
CComboBox
CButton
CStatic
CFileDialog
CStringArray
CWinApp
PreviewPages
Settings
CTempImageList
CImageList
CProgressCtrl
CArchiveException
CSharedFile
CCmdTarget
CWinThread
CTempMenu
combobox
CDWordArray
CWordArray
CFileException
CMapPtrToPtr
CToolTipCtrl
tooltips_class32
CColorDialog
CObject
System
commdlg_SetRGBColor
commdlg_help
commdlg_ColorOK
commdlg_FileNameOK
commdlg_ShareViolation
commdlg_LBSelChangedNotify
software
CMapStringToPtr
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CorExitProcess
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
kernel32.dll
GAIsProcessorFeaturePresent
KERNEL32
AuthenticAMD
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h````
ppxxxx
(null)
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
InitializeCriticalSectionAndSpinCount
Program:
A buffer overrun has been detected which has corrupted the program's
internal state. The program cannot safely continue execution and must
now be terminated.
Buffer overrun detected!
A security error of unknown cause has been detected which has
corrupted the program's internal state. The program cannot safely
continue execution and must now be terminated.
Unknown security failure detected!
1#QNAN
1#SNAN
CloseHandle
WaitForSingleObject
CreateProcessA
GetTickCount
GetCommandLineA
MulDiv
GetProcAddress
GetModuleHandleA
GetVolumeInformationA
SetCurrentDirectoryA
GetFileAttributesA
FindClose
FindFirstFileA
GlobalUnlock
GlobalLock
GlobalAlloc
CreateEventA
CreateThread
WritePrivateProfileStringA
GetVersionExA
LoadLibraryA
FreeLibrary
GetFullPathNameA
HeapAlloc
GetProcessHeap
HeapReAlloc
HeapFree
GlobalReAlloc
FindNextFileA
lstrcpyA
WinExec
lstrlenA
lstrcatA
InitializeCriticalSection
DeleteCriticalSection
GlobalFree
GlobalSize
ExitProcess
GetCurrentThreadId
GetModuleFileNameA
LockResource
LoadResource
FindResourceA
SetEvent
CreateFileA
WaitForMultipleObjects
GetLastError
ReadFile
WriteFile
GetProfileStringA
LeaveCriticalSection
EnterCriticalSection
ReleaseSemaphore
ResumeThread
CreateSemaphoreA
KERNEL32.dll
WaitForInputIdle
wsprintfA
CloseClipboard
GetClipboardData
OpenClipboard
SetClipboardData
EmptyClipboard
GetSystemMetrics
GetCursorPos
MessageBoxA
SetWindowPos
SendMessageA
DestroyCursor
SetParent
IsWindow
PostMessageA
GetTopWindow
GetParent
GetFocus
GetClientRect
InvalidateRect
ValidateRect
UpdateWindow
EqualRect
GetWindowRect
SetForegroundWindow
DestroyMenu
IsChild
ReleaseDC
IsRectEmpty
FillRect
SetCursor
LoadCursorA
SetCursorPos
SetActiveWindow
GetSysColor
SetWindowLongA
GetWindowLongA
RedrawWindow
EnableWindow
IsWindowVisible
OffsetRect
PtInRect
DestroyIcon
IntersectRect
InflateRect
SetRect
SetScrollPos
SetScrollRange
GetScrollRange
SetCapture
GetCapture
ReleaseCapture
SetTimer
KillTimer
WinHelpA
LoadBitmapA
CopyRect
ChildWindowFromPointEx
ScreenToClient
GetMessagePos
SetWindowRgn
DestroyAcceleratorTable
GetWindow
GetActiveWindow
SetFocus
IsIconic
PeekMessageA
SetMenu
GetMenu
DeleteMenu
GetSystemMenu
DefWindowProcA
GetClassInfoA
IsZoomed
PostQuitMessage
CopyAcceleratorTableA
GetKeyState
TranslateAcceleratorA
IsWindowEnabled
ShowWindow
SystemParametersInfoA
LoadImageA
EnumDisplaySettingsA
ClientToScreen
EnableMenuItem
GetSubMenu
GetDlgCtrlID
CreateAcceleratorTableA
CreateMenu
ModifyMenuA
AppendMenuA
CreatePopupMenu
DrawIconEx
CreateIconFromResource
CreateIconFromResourceEx
RegisterClipboardFormatA
SetRectEmpty
DispatchMessageA
GetMessageA
WindowFromPoint
DrawFocusRect
DrawEdge
DrawFrameControl
TranslateMessage
LoadIconA
USER32.dll
GetDeviceCaps
GetTextExtentPoint32A
RoundRect
GetCurrentObject
DPtoLP
LPtoDP
Rectangle
Ellipse
CreateCompatibleDC
BitBlt
StartPage
StartDocA
DeleteDC
EndDoc
EndPage
CreateFontIndirectA
GetStockObject
CreateSolidBrush
FillRgn
CreateRectRgn
CombineRgn
PatBlt
CreatePen
GetObjectA
SelectObject
CreateBitmap
CreateDCA
CreateCompatibleBitmap
GetPolyFillMode
GetStretchBltMode
GetROP2
GetBkColor
GetBkMode
GetTextColor
CreateRoundRectRgn
CreateEllipticRgn
PathToRegion
EndPath
BeginPath
GetWindowOrgEx
GetViewportOrgEx
GetWindowExtEx
GetDIBits
RealizePalette
SelectPalette
StretchBlt
CreatePalette
GetSystemPaletteEntries
CreateDIBitmap
DeleteObject
SelectClipRgn
CreatePolygonRgn
GetClipRgn
SetStretchBltMode
CreateRectRgnIndirect
SetBkColor
GDI32.dll
midiStreamRestart
midiStreamClose
midiOutReset
midiStreamStop
midiStreamOut
midiOutPrepareHeader
midiStreamProperty
midiStreamOpen
midiOutUnprepareHeader
waveOutOpen
waveOutGetNumDevs
waveOutClose
waveOutReset
waveOutPause
waveOutWrite
waveOutPrepareHeader
waveOutUnprepareHeader
WINMM.dll
ClosePrinter
DocumentPropertiesA
OpenPrinterA
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegSetValueExA
RegQueryValueA
ADVAPI32.dll
ShellExecuteA
Shell_NotifyIconA
SHELL32.dll
CLSIDFromString
OleUninitialize
OleInitialize
ole32.dll
OLEAUT32.dll
ImageList_Destroy
COMCTL32.dll
WS2_32.dll
InterlockedIncrement
InterlockedDecrement
WideCharToMultiByte
MultiByteToWideChar
LocalFree
FileTimeToSystemTime
FileTimeToLocalFileTime
SetLastError
lstrcpynA
DuplicateHandle
GetCurrentProcess
SetFilePointer
FlushFileBuffers
LockFile
UnlockFile
SetEndOfFile
lstrcmpiA
GlobalDeleteAtom
GlobalFindAtomA
GlobalAddAtomA
GlobalGetAtomNameA
GetVersion
lstrcmpA
LocalAlloc
TlsAlloc
GlobalHandle
TlsFree
TlsSetValue
LocalReAlloc
TlsGetValue
GetFileSize
GetFileTime
GetCurrentThread
GlobalFlags
SetErrorMode
GetProcessVersion
GetCPInfo
GetOEMCP
GetStartupInfoA
RtlUnwind
RaiseException
GetSystemTimeAsFileTime
TerminateProcess
HeapSize
GetACP
GetStdHandle
UnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapDestroy
HeapCreate
VirtualFree
SetEnvironmentVariableA
LCMapStringA
LCMapStringW
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
IsBadWritePtr
GetStringTypeA
GetStringTypeW
SetUnhandledExceptionFilter
GetTimeZoneInformation
InterlockedExchange
CompareStringA
CompareStringW
IsBadReadPtr
IsBadCodePtr
GetLocaleInfoA
QueryPerformanceCounter
GetCurrentProcessId
SetStdHandle
GetWindowTextA
GetWindowTextLengthA
CharUpperA
GetWindowDC
BeginPaint
EndPaint
TabbedTextOutA
DrawTextA
GrayStringA
GetDlgItem
DestroyWindow
CreateDialogIndirectParamA
EndDialog
GetNextDlgTabItem
GetWindowPlacement
RegisterWindowMessageA
GetForegroundWindow
GetLastActivePopup
GetMessageTime
RemovePropA
CallWindowProcA
GetPropA
UnhookWindowsHookEx
SetPropA
GetClassLongA
CallNextHookEx
SetWindowsHookExA
CreateWindowExA
GetMenuItemID
GetMenuItemCount
RegisterClassA
GetScrollPos
AdjustWindowRectEx
MapWindowPoints
SendDlgItemMessageA
ScrollWindowEx
IsDialogMessageA
SetWindowTextA
MoveWindow
CheckMenuItem
SetMenuItemBitmaps
GetMenuState
GetMenuCheckMarkDimensions
GetClassNameA
GetDesktopWindow
LoadStringA
GetSysColorBrush
SaveDC
RestoreDC
SetBkMode
SetPolyFillMode
SetROP2
SetTextColor
SetMapMode
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
SetWindowOrgEx
SetWindowExtEx
ScaleWindowExtEx
GetClipBox
ExcludeClipRect
MoveToEx
LineTo
ExtSelectClipRgn
GetViewportExtEx
PtVisible
RectVisible
TextOutA
ExtTextOutA
Escape
GetTextMetricsA
GetFileTitleA
GetSaveFileNameA
GetOpenFileNameA
ChooseColorA
comdlg32.dll
RegCreateKeyExA
UnregisterClassA
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
Kernel32.dll
.PAVCException@@
_EL_Label
_EL_PicBox
BUTTON
_EL_HyperLinker
\shell\open\command
mailto:
OpenDatabase
CloseDatabase
GetConnectString
GetTabList
DllUnregisterServer
DllRegisterServer
DEFAULT_ICON
RemovePlayer
WG!2S(
L23fff&ff
?fff&ff23
CWinFormUnit
.PAVCException@@
WTWindow
GetMonitorInfoA
MonitorFromWindow
User32.dll
bcdfghijklmnpqrstuvwxyz
abcddefghijklmnoopqrrsstuvvwwxyyz;
,1"52.*
(&07-034/)7 '
hgjlkbrfzaoe
 !"#!
?? / %d]
%d / %d]
.PAVCException@@
.PAVCFileException@@
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.*)|*.*||
Ctrl+Shift+F12
Ctrl+Shift+F11
Ctrl+Shift+F10
Ctrl+Shift+F9
Ctrl+Shift+F8
Ctrl+Shift+F7
Ctrl+Shift+F6
Ctrl+Shift+F5
Ctrl+Shift+F4
Ctrl+Shift+F3
Ctrl+Shift+F2
Ctrl+Shift+F1
Shift+F12
Shift+F11
Shift+F10
Shift+F9
Shift+F8
Shift+F7
Shift+F6
Shift+F5
Shift+F4
Shift+F3
Shift+F2
Shift+F1
Ctrl+F12
Ctrl+F11
Ctrl+F10
Ctrl+F9
Ctrl+F8
Ctrl+F7
Ctrl+F6
Ctrl+F5
Ctrl+F4
Ctrl+F3
Ctrl+F2
Ctrl+F1
Ctrl+Z
Ctrl+Y
Ctrl+X
Ctrl+W
Ctrl+V
Ctrl+U
Ctrl+T
Ctrl+S
Ctrl+R
Ctrl+Q
Ctrl+P
Ctrl+O
Ctrl+N
Ctrl+M
Ctrl+L
Ctrl+K
Ctrl+J
Ctrl+I
Ctrl+H
Ctrl+G
Ctrl+F
Ctrl+E
Ctrl+D
Ctrl+C
Ctrl+B
Ctrl+A
.PAVCException@@
.PAVCException@@
(*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.PNG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|PNG
(*.PNG)|*.PNG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
(*.*)|*.*||
.PAVCException@@
devices
windows
device
MGridCells
.PAVCException@@
.PAVCNotSupportedException@@
.PAVCFileException@@
.PAVCException@@
.PAVCFileException@@
.PAVCException@@
.PAVCFileException@@
CColourPicker
out.prn
(*.prn)|*.prn|
(*.*)|*.*||
devices
windows
device
.PAVCException@@
_EL_HideOwner
%d/%d
%d/%d
.PAVCException@@
Potential overflow in png_zalloc()
but running with
Application built with libpng-
unexpected zlib return code
unexpected zlib return
unsupported zlib version
truncated
insufficient memory
damaged LZ stream
bad parameters to zlib
zlib IO error
missing LZ dictionary
unexpected end of LZ stream
gamma value out of range
duplicate
gamma value does not match sRGB
gamma value does not match libpng estimate
invalid chromaticities
internal error checking chromaticities
inconsistent chromaticities
invalid sRGB rendering intent
cHRM chunk does not match sRGB
duplicate sRGB information ignored
inconsistent rendering intents
profile '
invalid length
too short
tag count too large
unexpected ICC PCS encoding
unrecognized ICC profile class
unexpected NamedColor ICC profile class
invalid embedded Abstract ICC profile
unexpected DeviceLink ICC profile class
Gray color space not permitted on RGB PNG
RGB color space not permitted on grayscale PNG
invalid ICC profile color space
PCS illuminant is not D50
invalid signature
intent outside defined range
invalid rendering intent
length does not match profile
ICC profile tag outside profile
ICC profile tag start not a multiple of 4
out-of-date sRGB profile with no signature
known incorrect sRGB profile
copyright violation: edited ICC profile ignored
internal error handling cHRM->XYZ
internal error handling cHRM coefficients
Invalid IHDR data
Invalid filter method in IHDR
Unknown filter method in IHDR
MNG features are not allowed in a PNG datastream
Unknown compression method in IHDR
Unknown interlace method in IHDR
Invalid color type/bit depth combination in IHDR
Invalid color type in IHDR
Invalid bit depth in IHDR
Invalid image height in IHDR
Invalid image width in IHDR
Image height exceeds user limit in IHDR
Image width exceeds user limit in IHDR
Image height is zero in IHDR
Image width is zero in IHDR
gamma table being rebuilt
Too many IDATs found
Missing PLTE before IDAT
Missing IHDR before IDAT
png_read_update_info/png_start_read_image: duplicate call
internal sequential row size calculation error
sequential row overflow
bad adaptive filter value
Invalid attempt to read row data
png_image_read: opaque pointer not NULL
png_image_read: out of memory
png_image_begin_read_from_memory: incorrect PNG_IMAGE_VERSION
png_image_begin_read_from_memory: invalid argument
invalid memory read
read beyond end of data
png_image_finish_read: damaged PNG_IMAGE_VERSION
png_image_finish_read: invalid argument
png_image_finish_read[color-map]: no color-map
bad background index (internal error)
bad processing option (internal error)
color map overflow (BAD internal error)
bad data option (internal error)
invalid PNG color type
palette color-map: too few entries
rgb-alpha color-map: too few entries
rgb+alpha color-map: too few entries
rgb color-map: too few entries
rgb[gray] color-map: too few entries
rgb[ga] color-map: too few entries
gray-alpha color-map: too few entries
ga-alpha color-map: too few entries
gray+alpha color-map: too few entries
gray[16] color-map: too few entries
gray[8] color-map: too few entries
a background color must be supplied to remove alpha/transparency
unexpected encoding (internal error)
bad encoding (internal error)
color-map index out of range
bad color-map processing (internal error)
unknown interlace type
png_read_image: invalid transformations
unexpected alpha swap transformation
png_image_read: alpha channel lost
png_read_image: unsupported transformation
unexpected bit depth
unexpected 8-bit transformation
lost/gained channels
unexpected compose
lost rgb to gray
%d / %d
_EL_ColourPopup
Bogus message code %d
libpng error: %s
undefined
libpng warning: %s
bad longjmp:
internal error: array alloc
internal error: array realloc
Out of memory
need dictionary
incorrect data check
incorrect header check
invalid window size
unknown compression method
Call to NULL read function
Read Error
Can't set both read_data_fn and write_data_fn in the same structure
PNG unsigned integer out of range
PNG file corrupted by ASCII conversion
Not a PNG file
CRC error
invalid
out of place
bKGD must be after
hIST must be after
tRNS must be after
duplicate
ignored in grayscale PNG
missing IHDR
PNG fixed point integer out of range
invalid values
too many profiles
bad keyword
bad compression method
truncated
out of memory
extra compressed data
too short
insufficient memory to read chunk
using zstream
zstream unclaimed
sPLT chunk requires too much memory
sPLT chunk too long
sPLT chunk has bad length
malformed sPLT chunk
No space in chunk cache for sPLT
invalid with alpha channel
invalid index
invalid data
unrecognized equation type
invalid parameter count
bad width format
bad height format
non-positive height
non-positive width
invalid unit
Insufficient memory to process text chunk
no space in chunk cache
insufficient memory
unknown compression type
bad compression info
unhandled critical chunk
forcing save of an unhandled chunk; please call png_set_keep_unknown_chunks
Saving unknown chunk:
error in user chunk
unknown chunk exceeds memory limits
invalid chunk type
invalid user transform pixel depth
internal row width error
internal row size calculation error
internal row logic error
Too much image data
Extra compressed data
Not enough image data
Row has too many bytes to allocate in memory
Application must supply a known background gamma
invalid before the PNG header has been read
invalid after png_start_read_image or png_read_update_info
conflicting calls to set alpha mode and background
invalid alpha mode
output gamma out of expected range
ignoring out of range rgb_to_gray coefficients
invalid error action to rgb_to_gray
invalid background gamma type
libpng does not support gamma+background+rgb_to_gray
Palette is NULL in indexed image
png_do_quantize returned rowbytes=0
png_do_rgb_to_gray found nongray pixel
Uninitialized row
NULL row buffer
png_do_encode_alpha: unexpected call
png_set_filler is invalid for low bit depth gray output
png_set_filler: inappropriate color type
Invalid palette size, hIST allocation skipped
Insufficient memory for hIST chunk data
Insufficient memory for pCAL parameter
Insufficient memory for pCAL params
Insufficient memory for pCAL units
Insufficient memory for pCAL purpose
Invalid format for pCAL parameter
Invalid pCAL parameter count
Invalid pCAL equation type
Memory allocation failed while processing sCAL
Invalid sCAL height
Invalid sCAL width
Invalid sCAL unit
Invalid palette
Invalid palette length
text chunk: out of memory
text compression mode is out of range
too many text chunks
Ignoring invalid time value
tRNS chunk has out-of-range samples for bit_depth
sPLT out of memory
png_set_sPLT: invalid sPLT
too many sPLT chunks
unknown chunk: out of memory
too many unknown chunks
invalid location in png_set_unknown_chunks
png_set_unknown_chunks now expects a valid location
png_set_keep_unknown_chunks: invalid keep
png_set_keep_unknown_chunks: too many chunks
png_set_keep_unknown_chunks: no chunk list
(%d-%d):
JPEGMEM
invalid bit length repeat
too many length or distance symbols
invalid stored block lengths
invalid block type
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
need dictionary
invalid distance code
invalid literal/length code
incomplete dynamic bit lengths tree
oversubscribed dynamic bit lengths tree
incomplete literal/length tree
oversubscribed literal/length tree
empty distance tree with lengths
incomplete distance tree
oversubscribed distance tree
invalid literal/length code
invalid distance code
.PAVCException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.?AVCObject@@
.?AVCException@@
.?AVCSimpleException@@
.?AVCMemoryException@@
.?AVCNotSupportedException@@
.?AVCFile@@
.?AVCFileException@@
.?AVCMemFile@@
.?AVCDC@@
.?AVCClientDC@@
.?AVCWindowDC@@
.?AVCPaintDC@@
.?AVCGdiObject@@
.?AVCPen@@
.?AVCBrush@@
.?AVCTempDC@@
.?AVCTempGdiObject@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCResourceException@@
.?AVCUserException@@
.?AVCCmdTarget@@
.?AVCWnd@@
.?AVCDialog@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.?AVCTempWnd@@
.?AVCNoTrackObject@@
.?AV_AFX_CTL3D_STATE@@
.?AVCPtrArray@@
.?AVCStatic@@
.?AVCButton@@
.?AVCComboBox@@
.?AVCEdit@@
.?AV_AFX_CHECKLIST_STATE@@
.?AVCBitmap@@
.?AVCCommonDialog@@
.?AVCFileDialog@@
.?AV_AFX_THREAD_STATE@@
.?AVAFX_MODULE_STATE@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AV_AFX_BASE_MODULE_STATE@@
.?AVCStringArray@@
.?AUCThreadData@@
.?AV_AFX_WIN_STATE@@
.?AVCWinThread@@
.?AVCWinApp@@
.?AVCProgressCtrl@@
.?AVCImageList@@
.?AVCTempImageList@@
.PAVCArchiveException@@
.?AVCArchiveException@@
.?AVCSharedFile@@
.?AV_AFX_CTL3D_THREAD@@
.?AVCMenu@@
.?AVCTempMenu@@
.?AVCDWordArray@@
.?AVCWordArray@@
.PAVCFileException@@
.?AVCMapPtrToPtr@@
.?AVCToolTipCtrl@@
.?AV_AFX_COLOR_STATE@@
.?AVCColorDialog@@
.?AVCHandleMap@@
.?AVCMapStringToPtr@@
.?AVtype_info@@
resource.h
#include "afxres.h"
#define _AFX_NO_SPLITTER_RESOURCES
#define _AFX_NO_OLE_RESOURCES
#define _AFX_NO_TRACKER_RESOURCES
#define _AFX_NO_PROPERTY_RESOURCES
#if !defined(AFX_RESOURCE_DLL) || defined(AFX_TARG_CHS)
#ifdef _WIN32
LANGUAGE 4, 2
#pragma code_page(936)
#endif //_WIN32
#include "l.chs\afxres.rc" // Standard components
#endif
SbpS:g:
SbpS0R
SbpS@b
SbpS0R
kXEQ>\u
ck(WSbpS
-NbkSbpS(
SbpS\O
-NbkSbpS
eQpenc
0R>\W[
nzzpenc
wwwwww
wwwwww
wwwwww
wwwwww
wwwwww
wwwwww
wwwwww
wwwwww
ech1Y%
ech1Y%
OX[0R
ech1Y%
RSbpS\O
QX[gbL
g~b0Rdk
-N"N1Y
0dk:ghV
T/f&Tcknx
N*Ntepe
N*N(W%
N*N(W%
N*N(W0
N*Ncktepe
g~b0R
[/fS_MR
g~b1Y%
u\^^^^]Xb
`]^]SRZ][V>
w]]!%WU<9.,574
=<9.,28BGF
NV#&0.,63
I:)+,1
k*-6A?
jdYYdj
2-+++++++1M
2++++++++****
-+++--24
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>
jjjjjj
Hjjjjjjjj
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
SkinSharp GUI Toolkit
CompanyName
SkinSharp Inc.
FileDescription
SkinSharp GUI
FileVersion
1, 0, 6, 6
InternalName
SkinSharp For EL
LegalCopyright
- Skin.dll
LegalTrademarks
SkinSharp
OriginalFilename
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Flystudio.4!c
Elastic Windows.Generic.Threat
ClamAV Clean
CMC Clean
CAT-QuickHeal Hacktool.Flystudio.16558
Skyhigh BehavesLike.Win32.Generic.dh
McAfee GenericRXAA-AA!D62F5A093F14
Cylance Unsafe
Zillya Trojan.Nimnul.Win32.1321
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Flystudio.83fa049b
K7GW Trojan ( 00539b2c1 )
K7AntiVirus Trojan ( 00539b2c1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEX Malicious
Avast FileRepMalware [Misc]
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Trojan.Win32.GenericKD.erkpbm
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Generic Reputation PUA (PUA)
F-Secure PotentialRisk.PUA/Agent.izgki
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!D62F5A093F14
Trapmine suspicious.low.ml.score
CTX Clean
Emsisoft Clean
Ikarus Trojan.Graftor
FireEye Generic.mg.d62f5a093f1490f7
Jiangmin Trojan.Antavmu.egb
Webroot Clean
Varist W32/Ulise.DM.gen!Eldorado
Avira PUA/Agent.izgki
Fortinet Clean
Antiy-AVL Trojan[Packed]/Win32.FlyStudio
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.oa!s1
Xcitium TrojWare.Win32.Agent.OSCF@5rs7jr
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Flystudio
Google Detected
AhnLab-V3 Clean
Acronis Clean
VBA32 Trojan.Sdum
TACHYON Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.FlyStudio!8.228 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Win32.Trojan.PSE.1OS0HCF
AVG FileRepMalware [Misc]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.