Static | ZeroBOX

PE Compile Time

2024-10-14 22:30:22

PE Imphash

5aad076aff6a3bd2c917579560b6b074

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001e1b8e 0x001e1c00 7.3595218588
.rdata 0x001e3000 0x0008ad5c 0x0008ae00 5.61401179527
.data 0x0026e000 0x0008c5a8 0x00025800 6.69608315143
.rsrc 0x002fb000 0x00022588 0x00022600 6.63221613868
.text 0x0031e000 0x00000200 0x00000200 6.85543450281

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x002fd048 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x002fd048 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
TEXTINCLUDE 0x002fd048 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED C source, ASCII text, with CRLF line terminators
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_CURSOR 0x00301508 0x00000134 LANG_ITALIAN SUBLANG_ITALIAN data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x002ff6b0 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x0030cb78 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0030cb78 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0030cb78 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MENU 0x002fe678 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MENU 0x002fe678 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x002fe1c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x003000c8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_CURSOR 0x002fed90 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x2
RT_GROUP_ICON 0x002fd5c8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x002fd5c8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x002fd5c8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x0031d3b8 0x000001cd LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library RASAPI32.dll:
0x5e34d8 RasHangUpA
Library KERNEL32.dll:
0x5e31d8 GetStdHandle
0x5e31dc SetHandleCount
0x5e31f4 GetFileType
0x5e31f8 SetStdHandle
0x5e31fc GetACP
0x5e3200 RaiseException
0x5e3204 GetLocalTime
0x5e3208 TerminateProcess
0x5e320c RtlUnwind
0x5e3210 GetStartupInfoA
0x5e3214 GetOEMCP
0x5e3218 GetCPInfo
0x5e321c GetProcessVersion
0x5e3220 SetErrorMode
0x5e3224 GlobalFlags
0x5e322c GetCurrentThread
0x5e3230 GetFileTime
0x5e3234 TlsGetValue
0x5e3238 LocalReAlloc
0x5e323c TlsSetValue
0x5e3240 TlsFree
0x5e3244 GlobalHandle
0x5e3248 TlsAlloc
0x5e324c LocalAlloc
0x5e3250 lstrcmpA
0x5e3254 GetVersion
0x5e3258 GlobalGetAtomNameA
0x5e325c GlobalAddAtomA
0x5e3260 GlobalFindAtomA
0x5e3264 GlobalDeleteAtom
0x5e3268 lstrcmpiA
0x5e326c DuplicateHandle
0x5e3270 lstrcpynA
0x5e3284 LCMapStringA
0x5e3288 LCMapStringW
0x5e328c IsBadWritePtr
0x5e3290 IsValidLocale
0x5e3294 IsValidCodePage
0x5e3298 GetLocaleInfoA
0x5e329c EnumSystemLocalesA
0x5e32a0 GetStringTypeA
0x5e32a4 GetStringTypeW
0x5e32a8 SuspendThread
0x5e32ac ReleaseMutex
0x5e32b0 CreateMutexA
0x5e32b4 VirtualFree
0x5e32b8 VirtualAlloc
0x5e32bc SetLastError
0x5e32c8 GetCurrentProcess
0x5e32d0 GetSystemDirectoryA
0x5e32d8 AreFileApisANSI
0x5e32dc CreateFileW
0x5e32e0 CreateFileMappingA
0x5e32e4 CreateFileMappingW
0x5e32e8 CreateMutexW
0x5e32ec DeleteFileW
0x5e32f0 FlushFileBuffers
0x5e32f4 FormatMessageA
0x5e32f8 FormatMessageW
0x5e32fc GetDiskFreeSpaceW
0x5e3300 GetFileAttributesW
0x5e3308 GetFileSize
0x5e330c GetFullPathNameW
0x5e3310 GetSystemInfo
0x5e3314 GetSystemTime
0x5e331c GetTempPathW
0x5e3320 HeapCreate
0x5e3324 HeapDestroy
0x5e3328 HeapSize
0x5e332c HeapValidate
0x5e3330 LoadLibraryW
0x5e3334 LocalFree
0x5e3338 LockFile
0x5e333c LockFileEx
0x5e3340 MapViewOfFile
0x5e3348 SetEndOfFile
0x5e334c SetFilePointer
0x5e3354 UnlockFile
0x5e3358 UnlockFileEx
0x5e335c UnmapViewOfFile
0x5e3360 TerminateThread
0x5e3364 CreateSemaphoreA
0x5e3368 ResumeThread
0x5e336c ReleaseSemaphore
0x5e3378 GetProfileStringA
0x5e337c WriteFile
0x5e3384 CreateFileA
0x5e3388 SetEvent
0x5e338c FindResourceA
0x5e3390 LoadResource
0x5e3394 LockResource
0x5e3398 ReadFile
0x5e339c lstrlenW
0x5e33a0 GetModuleFileNameA
0x5e33a4 GetCurrentProcessId
0x5e33a8 GetCurrentThreadId
0x5e33ac ExitProcess
0x5e33b0 GlobalSize
0x5e33b4 GlobalFree
0x5e33c0 lstrcatA
0x5e33c4 GetLocaleInfoW
0x5e33c8 lstrlenA
0x5e33cc WinExec
0x5e33d0 lstrcpyA
0x5e33d4 FindNextFileA
0x5e33d8 GlobalReAlloc
0x5e33dc HeapFree
0x5e33e0 HeapReAlloc
0x5e33e4 GetProcessHeap
0x5e33e8 HeapAlloc
0x5e33ec GetUserDefaultLCID
0x5e33f0 MultiByteToWideChar
0x5e33f4 WideCharToMultiByte
0x5e33f8 GetFullPathNameA
0x5e33fc FreeLibrary
0x5e3400 LoadLibraryA
0x5e3404 GetLastError
0x5e3408 GetVersionExA
0x5e3410 CreateThread
0x5e3414 CreateEventA
0x5e3418 Sleep
0x5e341c GlobalAlloc
0x5e3420 GlobalLock
0x5e3424 GlobalUnlock
0x5e3428 GetTempPathA
0x5e342c FindFirstFileA
0x5e3430 FindClose
0x5e3434 GetFileAttributesA
0x5e3438 DeleteFileA
0x5e3444 GetModuleHandleA
0x5e3448 GetProcAddress
0x5e344c GetDiskFreeSpaceA
0x5e3450 MulDiv
0x5e3454 GetCommandLineA
0x5e3458 GetTickCount
0x5e345c CreateProcessA
0x5e3460 WaitForSingleObject
0x5e3464 CloseHandle
0x5e346c CompareStringA
0x5e3470 CompareStringW
0x5e3474 IsBadReadPtr
0x5e3478 IsBadCodePtr
Library USER32.dll:
0x5e3500 FrameRect
0x5e3504 SetWindowsHookExA
0x5e3508 CallNextHookEx
0x5e350c UnhookWindowsHookEx
0x5e3510 GetWindowDC
0x5e3514 EnumChildWindows
0x5e3518 GetPropA
0x5e351c WindowFromDC
0x5e3520 TabbedTextOutA
0x5e3524 GrayStringA
0x5e3528 DrawStateA
0x5e3530 GetMenuState
0x5e3534 GetMenuStringA
0x5e3538 GetMenuItemID
0x5e353c GetMenuItemCount
0x5e3540 SetWindowTextA
0x5e3544 GetWindowTextA
0x5e3548 MoveWindow
0x5e354c CallWindowProcA
0x5e3550 SetPropA
0x5e3554 DrawTextA
0x5e3558 GetCursor
0x5e355c LoadIconA
0x5e3560 TranslateMessage
0x5e3564 DrawFrameControl
0x5e3568 DrawEdge
0x5e356c DrawFocusRect
0x5e3570 WindowFromPoint
0x5e3574 GetMessageA
0x5e3578 DispatchMessageA
0x5e357c SetRectEmpty
0x5e358c DrawIconEx
0x5e3590 CreatePopupMenu
0x5e3594 AppendMenuA
0x5e3598 ModifyMenuA
0x5e359c CreateMenu
0x5e35a4 GetDlgCtrlID
0x5e35a8 GetSubMenu
0x5e35ac EnableMenuItem
0x5e35b0 ClientToScreen
0x5e35b8 LoadImageA
0x5e35c0 ShowWindow
0x5e35c8 GetKeyState
0x5e35d0 PostQuitMessage
0x5e35d8 IsWindowEnabled
0x5e35dc EnumWindows
0x5e35e0 IsZoomed
0x5e35e4 GetClassInfoA
0x5e35e8 DefWindowProcA
0x5e35ec GetSystemMenu
0x5e35f0 DeleteMenu
0x5e35f4 GetMenu
0x5e35f8 SetMenu
0x5e35fc GetForegroundWindow
0x5e3600 IsIconic
0x5e3604 SetFocus
0x5e3608 GetActiveWindow
0x5e360c GetWindow
0x5e3614 SetWindowRgn
0x5e3618 GetSysColorBrush
0x5e361c LoadStringA
0x5e3620 GetDesktopWindow
0x5e3624 GetClassNameA
0x5e362c SetMenuItemBitmaps
0x5e3630 CheckMenuItem
0x5e3634 IsDialogMessageA
0x5e3638 ScrollWindowEx
0x5e363c SendDlgItemMessageA
0x5e3640 MapWindowPoints
0x5e3644 AdjustWindowRectEx
0x5e3648 GetScrollPos
0x5e364c RegisterClassA
0x5e3650 GetClassLongA
0x5e3654 RemovePropA
0x5e3658 GetMessageTime
0x5e365c GetLastActivePopup
0x5e3664 GetWindowPlacement
0x5e3668 GetNextDlgTabItem
0x5e366c EndDialog
0x5e3674 DestroyWindow
0x5e3678 GetMessagePos
0x5e367c ScreenToClient
0x5e3684 CopyRect
0x5e3688 LoadBitmapA
0x5e368c WinHelpA
0x5e3690 KillTimer
0x5e3694 SetTimer
0x5e3698 GetCapture
0x5e369c SetCapture
0x5e36a0 GetScrollRange
0x5e36a4 SetScrollRange
0x5e36a8 SetScrollPos
0x5e36ac SetRect
0x5e36b0 InflateRect
0x5e36b4 IntersectRect
0x5e36b8 DestroyIcon
0x5e36bc PtInRect
0x5e36c0 OffsetRect
0x5e36c4 IsWindowVisible
0x5e36c8 EnableWindow
0x5e36cc RedrawWindow
0x5e36d0 GetWindowLongA
0x5e36d4 SetWindowLongA
0x5e36d8 GetSysColor
0x5e36dc SetActiveWindow
0x5e36e0 SetCursorPos
0x5e36e4 LoadCursorA
0x5e36e8 SetCursor
0x5e36ec GetDC
0x5e36f0 FillRect
0x5e36f4 IsRectEmpty
0x5e36f8 ReleaseDC
0x5e36fc IsChild
0x5e3700 TrackPopupMenu
0x5e3704 DestroyMenu
0x5e3708 SetForegroundWindow
0x5e370c GetWindowRect
0x5e3710 EqualRect
0x5e3714 UpdateWindow
0x5e3718 ValidateRect
0x5e371c InvalidateRect
0x5e3720 LockWindowUpdate
0x5e3724 GetClientRect
0x5e3728 GetFocus
0x5e372c GetParent
0x5e3730 GetTopWindow
0x5e3734 PostMessageA
0x5e3738 IsWindow
0x5e373c SetParent
0x5e3740 DestroyCursor
0x5e3744 SendMessageA
0x5e3748 SetWindowPos
0x5e374c MessageBoxA
0x5e3750 ReleaseCapture
0x5e3754 GetCursorPos
0x5e3758 GetSystemMetrics
0x5e375c EmptyClipboard
0x5e3760 SetClipboardData
0x5e3764 OpenClipboard
0x5e3768 GetClipboardData
0x5e376c CloseClipboard
0x5e3770 wsprintfA
0x5e3774 WaitForInputIdle
0x5e3778 CreateWindowExA
0x5e377c RegisterHotKey
0x5e3780 UnregisterHotKey
0x5e3784 UnregisterClassA
0x5e3788 PeekMessageA
0x5e3790 CharUpperA
0x5e3794 BeginPaint
0x5e3798 EndPaint
0x5e379c GetDlgItem
Library GDI32.dll:
0x5e3070 PathToRegion
0x5e3074 CreateEllipticRgn
0x5e3078 CreateRoundRectRgn
0x5e307c GetTextColor
0x5e3080 GetBkMode
0x5e3084 GetBkColor
0x5e3088 GetROP2
0x5e308c GetStretchBltMode
0x5e3090 GetPolyFillMode
0x5e3098 CreateDCA
0x5e309c FillRgn
0x5e30a0 CreateBrushIndirect
0x5e30a4 CreateBitmap
0x5e30a8 SelectObject
0x5e30ac CreatePen
0x5e30b0 PatBlt
0x5e30b4 CreateRectRgn
0x5e30b8 CombineRgn
0x5e30bc CreateFontIndirectA
0x5e30c0 GetStockObject
0x5e30c4 GetObjectA
0x5e30c8 EndPage
0x5e30cc EndDoc
0x5e30d0 DeleteDC
0x5e30d4 EndPath
0x5e30d8 StartPage
0x5e30dc BitBlt
0x5e30e0 GetPixel
0x5e30e4 CreateCompatibleDC
0x5e30e8 SetPixelV
0x5e30ec Ellipse
0x5e30f0 Rectangle
0x5e30f4 LPtoDP
0x5e30f8 DPtoLP
0x5e30fc GetCurrentObject
0x5e3100 RoundRect
0x5e3108 GetDeviceCaps
0x5e310c GetTextMetricsA
0x5e3110 GetViewportExtEx
0x5e3114 BeginPath
0x5e3118 GetWindowOrgEx
0x5e311c GetViewportOrgEx
0x5e3120 GetWindowExtEx
0x5e3124 GetDIBits
0x5e3128 RealizePalette
0x5e312c SelectPalette
0x5e3130 StretchBlt
0x5e3134 CreatePalette
0x5e313c CreateDIBitmap
0x5e3140 DeleteObject
0x5e3144 ExtSelectClipRgn
0x5e3148 SelectClipRgn
0x5e314c CreatePolygonRgn
0x5e3150 GetClipRgn
0x5e3154 SetStretchBltMode
0x5e3158 SetPixel
0x5e3160 SetBkColor
0x5e3164 SetBkMode
0x5e3168 SetTextColor
0x5e316c SetWindowOrgEx
0x5e3170 SaveDC
0x5e3174 RestoreDC
0x5e3178 CreatePenIndirect
0x5e317c PtVisible
0x5e3180 RectVisible
0x5e3184 TextOutA
0x5e3188 ExtTextOutA
0x5e318c Escape
0x5e3190 CreateFontA
0x5e3198 StartDocA
0x5e319c LineTo
0x5e31a0 MoveToEx
0x5e31a4 ExcludeClipRect
0x5e31a8 GetClipBox
0x5e31ac ScaleWindowExtEx
0x5e31b0 SetWindowExtEx
0x5e31b4 ScaleViewportExtEx
0x5e31b8 SetViewportExtEx
0x5e31bc OffsetViewportOrgEx
0x5e31c0 SetViewportOrgEx
0x5e31c4 SetMapMode
0x5e31c8 SetROP2
0x5e31cc SetPolyFillMode
0x5e31d0 CreateSolidBrush
Library WINMM.dll:
0x5e37d0 midiStreamRestart
0x5e37d4 midiStreamClose
0x5e37d8 midiOutReset
0x5e37dc midiStreamStop
0x5e37e0 midiStreamOut
0x5e37e8 midiStreamProperty
0x5e37ec midiStreamOpen
0x5e37f4 waveOutOpen
0x5e37f8 waveOutGetNumDevs
0x5e37fc waveOutReset
0x5e3800 waveOutPause
0x5e3804 waveOutWrite
0x5e3810 waveOutRestart
0x5e3814 waveOutClose
Library MSIMG32.dll:
0x5e3480 GradientFill
Library WINSPOOL.DRV:
0x5e381c DocumentPropertiesA
0x5e3820 OpenPrinterA
0x5e3824 ClosePrinter
Library ADVAPI32.dll:
0x5e3000 RegCreateKeyExA
0x5e3004 RegOpenKeyExA
0x5e3008 RegSetValueExA
0x5e300c RegQueryValueA
0x5e3010 RegCloseKey
Library SHELL32.dll:
0x5e34e4 DragFinish
0x5e34e8 Shell_NotifyIconA
0x5e34f0 DragQueryFileA
0x5e34f4 ShellExecuteA
0x5e34f8 DragAcceptFiles
Library ole32.dll:
0x5e38b8 OleRun
0x5e38bc CoCreateInstance
0x5e38c0 CLSIDFromString
0x5e38c4 OleUninitialize
0x5e38c8 OleInitialize
0x5e38cc CLSIDFromProgID
Library OLEAUT32.dll:
0x5e3488 VariantClear
0x5e348c VariantChangeType
0x5e3490 SafeArrayGetUBound
0x5e3494 SafeArrayGetLBound
0x5e3498 VariantCopy
0x5e349c SafeArrayGetDim
0x5e34a4 UnRegisterTypeLib
0x5e34a8 LoadTypeLib
0x5e34ac LHashValOfNameSys
0x5e34b0 RegisterTypeLib
0x5e34b4 SafeArrayPutElement
0x5e34b8 SafeArrayCreate
0x5e34bc SafeArrayDestroy
0x5e34c0 SysAllocString
0x5e34c4 VariantInit
0x5e34c8 VariantCopyInd
0x5e34cc SafeArrayGetElement
0x5e34d0 SafeArrayAccessData
Library COMCTL32.dll:
0x5e3018 ImageList_DragLeave
0x5e301c ImageList_DragEnter
0x5e3020 ImageList_Destroy
0x5e3024 ImageList_Create
0x5e3028 ImageList_BeginDrag
0x5e302c ImageList_DragMove
0x5e3030 ImageList_AddMasked
0x5e3034 _TrackMouseEvent
0x5e3038 ImageList_Draw
0x5e3048 ImageList_GetIcon
0x5e3050 ImageList_EndDrag
0x5e3054 None
0x5e3058 ImageList_Read
0x5e305c ImageList_Write
0x5e3064 ImageList_Duplicate
0x5e3068 ImageList_Add
Library WS2_32.dll:
0x5e382c ntohl
0x5e3830 getsockname
0x5e3834 ntohs
0x5e3838 WSAGetLastError
0x5e383c shutdown
0x5e3840 gethostname
0x5e3844 inet_addr
0x5e3848 inet_ntoa
0x5e384c closesocket
0x5e3850 WSAStartup
0x5e3854 WSACleanup
0x5e3858 select
0x5e385c __WSAFDIsSet
0x5e3860 accept
0x5e3864 getpeername
0x5e3868 listen
0x5e386c recv
0x5e3870 connect
0x5e3874 ioctlsocket
0x5e3878 recvfrom
0x5e387c sendto
0x5e3880 send
0x5e3884 WSAAsyncSelect
0x5e3888 htons
0x5e388c gethostbyname
0x5e3890 socket
0x5e3894 htonl
0x5e3898 bind
Library WININET.dll:
0x5e37a8 InternetCrackUrlA
0x5e37ac HttpOpenRequestA
0x5e37b0 HttpSendRequestA
0x5e37b4 HttpQueryInfoA
0x5e37b8 InternetReadFile
0x5e37bc InternetConnectA
0x5e37c0 InternetSetOptionA
0x5e37c4 InternetCloseHandle
0x5e37c8 InternetOpenA
Library comdlg32.dll:
0x5e38a0 ChooseColorA
0x5e38a4 GetSaveFileNameA
0x5e38a8 GetOpenFileNameA
0x5e38ac ChooseFontA
0x5e38b0 GetFileTitleA

!This program cannot be run in DOS mode.
.rdata
@.data
@.text
P+#o~q
h j!Qb
4+a3Jf
4+a3Jd
0Nd#f~mUJ
0NX#f~mUJ
k"f~mUJ
k"f~mUJ
0N\#f}}
k"f~mUJ
}Y#x~l
&<VghJQ
Ugh"f}{
ku/fD)
ku/f0)
ku/fD)
ku/f()
ku/f4)
mKVghz
qh"f}k f
0NP#f}k f
qh"f}k f
0NX#f~mUJ
0NP#f~mU
0NX#f~mUJ
2N`)~a
0Nd#f~mUJ
l"o}y(
1Nd#f}}
l"o}y(
2N\)~a
l"o}y(
0N\#f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
1NT#f}}
0NT#f~mUJ
h j=Qo
l"o}y(
2NT)~a
k"f~mUJ
2N\)~a
k"f~mUJ
2N\)~a
l"o}y(
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
0N@#f~mU
k"f~mUJ
0N<#f~mU
k"f~mUJ
0N<#f~mU
k"f~mUJ
0N<#f~mU
0Nd#f~mUJ
0N\#f~mUJ
0N\#f~mUJ
0N\#f~mUJ
0N\#f~mUJ
0N\#f~mUJ
0NT#f~mU
0N\#f~mUJ
0NT#f~mUJ
x`gh&
mY xYgh&
0N(#f~mUJ
2Ygh&
mY DYgh&
0N,#f~mUJ
0N`#f~mUJ
0Nd#f~mUJ
0Nd#f}}
0Nd#f~mUJ
0Nd#f~mUJ
f]gh&
2NL)~a
0N\#f}}
ku/f4)
0N8#f}}
l"o}y(
1N`#f}}
ddgh&
ku/fD)
ku/fD)
ku/f0)
ku/f4)
ku/f4)
0NX#f~mU
ku/fH)
ku/f8)
0N\#f~mU
0NX#f~mUJ
0NX#f~mUJ
2Nd)~a
k"f~mUJ
'fgh&
9Y _gh&
,fgh&
9Y 1fgh&
]Zgh&
x`gh&
AY xYgh&
AY +Ygh&
.ggh&
2N )~a
{hgh&
5Y }hgh&
0Nd#f}}
l"o}y(
h #!iU
BGgh&
l"o}y(
k"f~mUJ
k"f~mUJ
0NP#f~mUJ
k"f~mUJ
k"f~mUJ
1NT#f}}
l"o}y(
0Nd#f~mUJ
0NH#f~mUJ
k"f~mUJ
k"f~mUJ
l"o}y(
0N\#f~mUJ
0Nd#f~mUJ
0NL#f~mUJ
0N`#f~mUJ
0Nd#f~mUJ
0N\#f~mUJ
0NL#f~mUJ
0N`#f~mUJ
k"f~mUJ
k"f~mUJ
0Nd#f~mUJ
k"f~mUJ
0Nd#f~mUJ
k"f~mUJ
0N`#f~mUJ
0N`#f~mUJ
&1ughJQ
1NL#f}}
k"f~mUJ
0Nd#f~mUJ
ku/f )
k"f~mUJ
k"f~mUJ
0NP#f~mUJ
1NX#f}{
0fd!i9
h #AhU
k #9hU
0fd!iI
k"f}k f
h #9hU
]/N$!#
qh"f}k f
qh"f}k f
qh"f}k f
qh"f}k f
qh"f}k f
.NdVrO
0N\AZ?
qh"f}k f
.n`?:?
KQ<(IQ
l"o}y(
l"o}y(
.n`?B?
ku/f`)
0Nd#f~mUJ
;1#f}k(
;1#f}k(
<C#f}k(
2NT)~a
0NP#f}}
0NX#f~mU
0NH#f~mUJ
mCVghz
k"f}k f
0NX#f~mU
ku/f@y
k"f~mU
ku/f@)
ku/f,)
ku/fD)
ku/f4)
0NP#f~mU
k"f~mUJ
0N@#f~mUJ
KQ<(W(
l"o}w(
0f`!i-
Y HCih&
HCih&
aCih&
#f~mUJ
l"o}y(
2NX)~a
2NX)~a
k"f~mUJ
#f~mUJ
l"o}y(
k"f~mUJ
0NH#f~mUJ
k"f~mUJ
h j=Qa
2Nd)~a
0N\#f~mUJ
0NX#f~mUJ
h j%P$
0Nd#f~mUJ
0Nd#f~mUJ
0NP#f~mUJ
l"o}y(
2N`)~a
k"f~mUJ
rh*+ug
g#f~mUJ
%sh(+ug
%sh(+eg
kgh&+Yg
g#f~mUJ
%sh(+ig
0NL#f~mUJ
%sh(+mg
%sh(+mg
1NP#f}}
1ND#f}}
1N<#f}}
1N4#f}}
1N,#f}}
1N$#f}}
AGgh(Cug
AGgh(CUg
g#f~mUJ
l"o}y(
!Lih&+ug
[gh(Cug
g#f~mUJ
AGgh(Cmg
AGgh(Cug
AGgh(CUg
Kih(Cug
g#f~mUJ
[gh(Cqg
%sh(+mg
AGgh(Cug
Lih&+ug
l"o}y(
k"f~mUJ
(jYP=X
rh*+if
1fd'Cuf
0fd!iE
%sh(Cyf
k"f~mUJ
rh*+qf
2Ygh&+yf
Y|&+yf
Y|&+yf
dgh&+if
0fd'Cyf
rh*+yf
Nih&+uf
Pih&+uf
Y +Ygh&+uf
x`gh&+yf
2Ygh&+yf
3Qih&+yf
Yp(Cyf
rh*+qf
Rih(Cyf
fQih&+yf
agh&+uf
2Ygh&+yf
.ggh&+yf
rh*+uf
oagh&+qf
%sh(+if
Sih&+yf
0fd'Cyf
oagh&+if
[Tih(Cyf
AGgh(Cyf
%sh(+uf
%sh(+qf
Y +Ygh&+uf
x`gh&+yf
Y|&+yf
%sh(+mf
rh*+uf
ri*+yf
Mih&+uf
_gh&+yf
Y xYgh&+uf
3Qih&+yf
g#f~mUJ
ri*+af
1fd!i!
1fd!i%
AGgh(Cyf
1fd!ii
%sh(+Ug
%sh(+yf
g#f~mUJ
%sh(+Ug
0fd!i-
1fd!i)
1fd!i1
1fd!ii
_gh&+yf
Y xYgh&+uf
rh*+uf
ri*+yf
Mih&+uf
`gh&+if
V\gh(Cyf
0fd!iY
_gh&+yf
Y xYgh&+uf
rh*+yf
Mih&+uf
Zih&+yf
Y -[ih&+Qf
Yp(Cyf
agh&+uf
Y DYgh&+uf
Mih&+uf
Xgh&+uf
2Ygh&+yf
`gh&+if
zQih&+yf
x`gh&+yf
Y|&+yf
0fd'Cyf
BGgh&+mf
]ih(Cuf
Xgh&+uf
2Ygh&+yf
Zih&+mf
]ih&+yf
Qih&+yf
Y xYgh&+uf
rh*+yf
Mih&+uf
Y DYgh&+uf
3Qih&+yf
AGgh(Cyf
g#f~mUJ
u`^ihzCaf
"f~mUJ
%sh(C9f
k"f~mUJ
%sh(Cyf
k"f~mUJ
Hagh(Cyf
Qih&+yf
Y xYgh&+uf
Yp(Cyf
rh*+qf
g#f~mUJ
g#f~mUJ
Qih&+yf
Y xYgh&+uf
Yp(Cyf
g#f~mUJ
Xgh&+mf
2Ygh&+yf
^ih&+uf
n_ih(Cyf
%sh(Cyf
k"f~mUJ
1fd!ie
1fd!ie
%sh(CQf
k"f~mUJ
%sh(Cyf
k"f~mUJ
1fd!ie
1fd!ie
%sh(CQf
k"f~mUJ
agh&+uf
Y xYgh&+uf
_ih&+yf
``ih(Cqf
ri*+Af
Mih&+uf
z_ih&+yf
x`gh&+yf
agh&+yf
6`ih&+Ef
X`ih(CUf
Yp(Cyf
agh&+uf
Y|&+yf
6`ih&+af
Y|&+yf
Yp(Cyf
2Ygh&+yf
agh&+yf
ri*+Uf
Mih&+uf
sdih&+yf
dih&+yf
dih&+yf
0fd!iU
g#f~mUJ
g#f~mUJ
%sh(+uf
g#f~mUJ
eih&+yf
g#f~mUJ
g#f~mUJ
%sh(+If
%sh(+yf
fih&+yf
x`gh&+yf
Mih&+uf
x`gh&+yf
gih&+yf
gih&+yf
Y DYgh&+uf
Y|&+yf
gih(Cyf
gih&+mf
hih&+yf
rh*+yf
rh*+uf
g#f~mUJ
g#f~mUJ
%sh(+Qf
rh*+uf
2gih&+yf
Y DYgh&+uf
Y|&+yf
Yp(Cyf
rh*+qf
oih(Cyf
4oih&+yf
gihzCqf
x`gh&+yf
rh*+uf
rh*+uf
)pih&+yf
rh*+qf
gih&+yf
gih&+yf
Y DYgh&+uf
Y|&+yf
ri*+5g
Mih&+uf
0fd!i9
pih&+qf
agh&+uf
2Ygh&+yf
-qih&+yf
.ggh&+yf
Y xYgh&+uf
Rgih&+yf
ri*+Yf
Yp(Cyf
pih&+yf
Y DYgh&+uf
Mih&+uf
BGgh&+uf
ri*+ef
[ih&+yf
x`gh&+yf
Yx(Cuf
Y|&+yf
rh*+uf
rh*+uf
Awih&+yf
g#f~mUJ
[gh(Cyf
g#f~mUJ
g#f~mUJ
wih&+Mf
0fd!i9
Awih&+yf
agh&+uf
Qih&+yf
2Ygh&+yf
xih&+yf
agh&+yf
Y DYgh&+uf
Yp(Cyf
1fd'Cuf
lgh(Cuf
rh*+uf
%sh(+af
g#f~mUJ
GghzCAf
0fd!iy
%sh(+uf
yih&+mf
yih&+uf
ri*+uf
Y|&+yf
yih(Cyf
yih(Cyf
yih(Cyf
zih(Cyf
%sh(+uf
x`gh&+yf
Rgih&+yf
Yp(Cyf
rh*+qf
Y xYgh&+uf
Rgih&+yf
gih&+yf
gih&+yf
Y DYgh&+uf
Y|&+yf
0fd!iQ
%sh(Cyf
k"f~mUJ
%sh(Cif
k"f~mUJ
[gh(CAf
g#f~mUJ
1fd'Cuf
jgh(Cuf
%sh(+mf
_gh&+yf
Y xYgh&+uf
3Qih&+yf
rh*+yf
Yx c!g
l"o}y(
TYgh&
Y xYgh&
0NP#f~mUJ
S91NX#f}}
k"f~mUJ
ku/fP)
ku/f,)
l"o}y(
0NT#f~mU
0N`#f~mUJ
0NP#f~mU
ku/fT)
ku/fT)
ku/fT)
ku/fT)
l"o}y(
k"f~mUJ
k"f~mUJ
0NL#f~mUJ
0NT#f~mUJ
k"f~mUJ
1Nd#f}}
0Nd#f~mUJ
k"f~mUJ
k"f~mUJ
l"o}y(
rh*+if
1fd'Cuf
0fd!iE
%sh(Cyf
k"f~mUJ
rh*+qf
2Ygh&+yf
Y|&+yf
Y|&+yf
dgh&+if
0fd'Cyf
rh*+yf
Nih&+uf
Pih&+uf
Y +Ygh&+uf
x`gh&+yf
2Ygh&+yf
3Qih&+yf
Yp(Cyf
rh*+qf
Rih(Cyf
fQih&+yf
agh&+uf
2Ygh&+yf
.ggh&+yf
rh*+uf
oagh&+qf
%sh(+if
Sih&+yf
0fd'Cyf
oagh&+if
[Tih(Cyf
AGgh(Cyf
%sh(+uf
%sh(+qf
Y +Ygh&+uf
x`gh&+yf
Y|&+yf
%sh(+mf
rh*+uf
ri*+yf
Mih&+uf
_gh&+yf
Y xYgh&+uf
3Qih&+yf
g#f~mUJ
ri*+af
1fd!i!
1fd!i%
AGgh(Cyf
1fd!ii
%sh(+Ug
%sh(+yf
g#f~mUJ
%sh(+Ug
0fd!i-
1fd!i)
1fd!i1
1fd!ii
_gh&+yf
Y xYgh&+uf
rh*+uf
ri*+yf
Mih&+uf
`gh&+if
V\gh(Cyf
0fd!iY
_gh&+yf
Y xYgh&+uf
rh*+yf
Mih&+uf
Zih&+yf
Y -[ih&+Qf
Yp(Cyf
agh&+uf
Y DYgh&+uf
Mih&+uf
Xgh&+uf
2Ygh&+yf
`gh&+if
zQih&+yf
x`gh&+yf
Y|&+yf
0fd'Cyf
BGgh&+mf
]ih(Cuf
Xgh&+uf
2Ygh&+yf
Zih&+mf
]ih&+yf
Qih&+yf
Y xYgh&+uf
rh*+yf
Mih&+uf
Y DYgh&+uf
3Qih&+yf
AGgh(Cyf
g#f~mUJ
u`^ihzCaf
"f~mUJ
%sh(C9f
k"f~mUJ
%sh(Cyf
k"f~mUJ
Hagh(Cyf
Qih&+yf
Y xYgh&+uf
Yp(Cyf
rh*+qf
g#f~mUJ
g#f~mUJ
Qih&+yf
Y xYgh&+uf
Yp(Cyf
g#f~mUJ
Xgh&+mf
2Ygh&+yf
^ih&+uf
n_ih(Cyf
%sh(Cyf
k"f~mUJ
1fd!ie
1fd!ie
%sh(CQf
k"f~mUJ
%sh(Cyf
k"f~mUJ
1fd!ie
1fd!ie
%sh(CQf
k"f~mUJ
agh&+uf
Y xYgh&+uf
_ih&+yf
X`ih(CUf
Y|&+yf
Yp(Cyf
2Ygh&+yf
Y|&+yf
ri*+If
Mih&+uf
`ih&+yf
Y|&+yf
Yp(Cyf
2Ygh&+yf
agh&+yf
Yp(Cyf
rh*+qf
0fd!iU
g#f~mUJ
g#f~mUJ
g#f~mUJ
%sh(+yf
%sh(+mf
%sh(+mf
g#f~mUJ
g#f~mUJ
rh*+qf
]Zgh&+mf
Y xYgh&+uf
Rgih&+yf
Yp(Cyf
Y xYgh&+uf
Rgih&+yf
Xgh&+uf
2Ygh&+yf
rh*+uf
hih(Cyf
hih&+yf
rh*+yf
H $hih&+yf
nih&+uf
)nih&+yf
rh*+mf
%sh(+mf
[nih&+Yf
%sh(+Uf
g#f~mUJ
Qih&+yf
2Ygh&+yf
rh*+qf
ri*+mf
Mih&+uf
oih&+yf
agh&+uf
rh*+yf
oih&+yf
Y xYgh&+uf
Rgih&+yf
rh*+uf
pih&+yf
rh*+uf
Xgh&+uf
2Ygh&+yf
ri*+]g
ri*+=g
Yp(Cyf
{pih(Cyf
pih&+yf
Y DYgh&+uf
Mih&+uf
BGgh&+uf
ri*+ef
[ih&+yf
x`gh&+yf
Yx(Cuf
Y|&+yf
Mih&+uf
agh&+uf
2Ygh&+yf
-qih&+yf
.ggh&+yf
Y xYgh&+uf
Rgih&+yf
ri*+Yf
^ih&+yf
%sh(+uf
0fd!i9
^ih&+yf
%sh(+uf
%sh(+uf
^ih&+Qf
1fd'Cmf
^ih&+=f
Wgh(Cyf
[gh(Cyf
<xih&+Qf
Yxih&+yf
agh&+yf
Y DYgh&+uf
Y|&+yf
agh&+uf
Qih&+yf
2Ygh&+yf
ri*+mf
Mih&+uf
Awih&+mf
&fgh(Cyf
ri*+ef
g#f~mUJ
%sh(+]f
g#f~mUJ
Iih&+mf
6fgh&+mf
yih&+qf
)pih&+uf
g#f~mUJ
Y xYgh&+uf
rh*+yf
Mih&+uf
qnih&+yf
x`gh&+yf
Xgh&+uf
2Ygh&+yf
1fd!iM
%sh(+=f
g#f~mUJ
Y +Ygh&+uf
x`gh&+yf
Y|&+yf
0fd!iY
[gh(Cyf
[gh(Cyf
l"o}y(
l"o}y(
g#f~mU
g#f~mUJ
2Ygh&+
g#f~mUJ
[Tih(C
ih&+Qg
dTih(C}g
agh&+}g
Y xYgh&+}g
si*+}g
2Ygh&+
ih&+qg
Y DYgh&+}g
ri*+yg
ih&+yg
%sh(+Qg
%sh(+ug
Wgh&+qg
g#f~mUJ
YihyKug
x`gh&+
x`gh&+
Zgh&+ug
g#f~mUJ
%sh(C1g
k"f~mUJ
rh*+}g
Xgh&+}g
2Ygh&+
x`gh&+
ih&+}g
ih&+}g
%sh(+}g
ih&+qg
0fd!i=
k"f~mUJ
g#f~mUJ
ih&+}g
rh*+ug
ri*+qg
Y xYgh&+}g
Xgh&+}g
2Ygh&+
Y xYgh&+}g
ih&+qg
^ih&+}g
rh*+eg
g#f~mUJ
g#f~mUJ
1fd'C}g
lgh(C}g
%sh(+}g
BGgh&+
)pih&+
[gh(C}g
%sh(+yg
1fd!iM
g#f~mUJ
ku/f`)
0N`#f~mUJ
l"o}y(
0N`#f~mUJ
0NX#f~mUJ
0N\#f}}
[B/NX)
0NX#f}}
[B/NP)
0N`#f~mUJ
0N`#f~mUJ
0N`#f~mUJ
0NX#f~mUJ
0NT#f}}
[B/NP)
0NT#f}}
[B/NP)
0N`#f~mU
0N`#f~mU
0NX#f~mUJ
]Y ZCih&
2NX)~a
2NX)~a
Y/^(VJ
0Nd#f~mU
k"f~mUJ
ku/f8'
h j%P(
h j1Qp
1Nd#f}k f
l"o}y(
.N| #)hU
k"f~mUJ
0N\#f~mUJ
0NT#f~mUJ
0Nd#f~mU
&dHghJQ
&LHghJQ
ku/f<)
ku/f8)
ku/f@y
ku/f@)
ku/f@)
ku/f<)
k"f~mU
f3N\)~J
f3Nd)~J
f3Nd)~J
ku/f4)
ku/f4)
ku/f )
ku/f0)
ku/f,)
NP{CYg
Nd{CEg
dghzC5g
ku/f0)
f3Nd)~J
ku/f4)
f3Nd)~J
ku/f4)
ku/f0)
ku/f$)
ku/f )
ih"f}{
l"o}y(
]/N\!#
]/N\!#
0Nd#f~mUJ
0Nd#f~mUJ
0NT#f}}
ku/f4+
l"o}y(
k"f~mUJ
0N`#f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mUJ
k"f~mU
]/NP!#
1N\#f}k f
qWgh&
k"f~mUJ
k"f~mUJ
]/NL!#
k"f~mUJ
k"f~mUJ
k"f~mUJ
1NT#f}}
k"f}k f
F_gh&
2NX)~a
0N\#f~mUJ
1N\#f}}
2N\)~a
l%/Nd!#
ku/fHe
;1#f}k(
2NP)~a
2NP)~a
ku/f<)
ku/f<)
ku/fT)
ku/f$)
ih"f}{
k"f}k f
;1#f}k(
k"f}k f
;1#f}k(
]/N\!#
;1#f}k(
GghzCig
^/NH!#
1N\#f}{
ku/fH)
2NX)~a
ku/fT)
ku/fP)
ku/f<)
k"f}k f
0NT#f~mUJ
0NT#f~mUJ
l #%hU
0NP#f~mUJ
0N`#f~mUJ
k"f~mUJ
l"o}y(
0NX#f~mUJ
0NT#f~mUJ
2Nd)~a
3N`)~b
2N`)~a
0NX#f~mUJ
0NX#f~mUJ
ku/fL)
ku/fH)
0N@#f~mUJ
0NP#f}{
k"f~mUJ
l"o}y(
2N`)~a
k"f~mU
ku/f8)
ku/fP)
0N,#f~mUJ
0N4#f~mUJ
0N4#f~mUJ
0N@#f~mUJ
k"f~mUJ
1N`#f}}
ku/fHe
2NP)~a
k"f~mUJ
ku/fT)
ih"f}{
ku/f$)
ku/f$)
k"f}k f
;1#f}k(
;C#f}k(
;C#f}k(
NT{Cqg
GghzCag
^/NH!#
ugh"f}{
ku/fH'
1N\#f}}
0N`#f}}
2NX)~a
ku/f@)
2NT)~a
;C#f}k(
0NX#f~mUJ
ku/fP)
ku/fLe
l"o}y(
2NT)~a
ku/f<)
2N\)~a
h #-hU
]/N<!#
h #%hU
]/N@!#
]/NX!#
h #5hU
]/NL!#
]/NL!#
]/NX!#
1Gghir
l"f~o(
1J|"f~oU
7)"-x(
/Qi!o}
/Qi!o}
}u"o~j(
/Li!f}
,x"o}{
,xmmmh
0Wp"o~r
NS}3V@
aSh uIS
pbSh`1~xd
NcSh&
KiSh`6
h*"-t(
h"f}w(
0Ot"f}x
,x(qYP
h"f}x(
0Xt("-t*
h j1+Y
0Qp"o}l(
0Ql"o}
h"f}r(
h j9+.6
0ft m!
[B1V|*
<)t<()
0NP#f}n(
0Lp"f~v
rh"f~s
0Vp"o}
("-p o
("-p o
h"f}j&
2Pp(qYP
;g#f}r
h"f~s*
Nnmh`6
0O`#f}
fh"f~tU
kc/Jt*
h(u_PM
h jM+.6
h j5+.6
h"f}k(
h"x~o(
a'"-td
.qmh`6
0O`#f}
h(n[Pah
l"f~n $Ml
h"f}k(
h j)Qx
,t(t[."
}m u1S
0)i4-'2-
2Pl(tYP
~t(,1i
a'"-td
p"f~o(t
0O`#f}
h(n[PQO
sh(,5i
h jY+.6
3`x(n[P9A
mh(lg+.6
.VTamNd
0Ol"f}
a'"-td
ftmh`6
mh(lg+.6
2Pl(qYP]
0O`#f}
-_Th(t
h(uYP9
;g#f}x(n
0Q`#o}
j5+.6
?#f~H)
,t"f}o "-x
h j5+.6
h j5+.6
h j5+.6
0J`#f}t
,x(q[PI
h jI+.6
p"f}x*
.^TamNd
,|"f}nd
mh(lg+.6
^zmh`6
0N`#f}o&R-L
>w:h.g
a'"-td
0O`#f}
;g#f}x(n
h j5+.6
2Pl(qYP-
0`x(n[P
,x(tY/"
^|mh`6
0O`#f}
;g#f}x(n
h j5+.6
h j5+.6
h j5+.6
h j5+.6
h j5+.6
2Pl(qYP
0`t(n[P5
0Q`#o~q("-
0O`#f}
;g#f}x(n
h j5+.6
h j5+.6
h j5+.6
.VPamNd
h j5+.6
h"f}|(
|t"f~p
p"f~o(t
eD`d*-
~$(d*-
0Pl"f}
}m($eS
ri*4Qj
rj*4Qj
}{(,Uj
sh(,]l
h"f}k(
0Q`#o}
h j}+.6
0Wl"o~p
mh*D)i
mh*Dyi
mh*4Ij
mh"f~q(
(tYP)N
0Ot l!
,x"f}o
fh"f}y(
fh"f}y
qh"x}{^
h"f~pd
Xgu3Vt(
fh"f~t
0Nx"f}
fh&D-l
h"f}w(,
h"f}s(
rh"f}|(
fh"f}o\
w1h[PN
;:(7iX
h"f}t(4
h(tYPq
g#f~x(
h"f~~(
l"f}o(t
fh"f}q
.nXe+eg
,x(b-
h"f}~d,
h jU+.6
h jy+.6
h"f}{(
fh"f}o(s
Cc'"-t
fh"f}}(
fh"f}rU
Z|"f~|(
0K`#f~
g#f}{(
,p"f}z(
,x(tYP
(m4.)u40
h"f}o(t
,| j!+jr
y1N4e&
b`z~p f
bt]~n f
h jQ++
,tc*-(
h("-|(
,tc*-(
,l"f~p(
,p"f}x
/Oi!f}
fh"f}v(
,t(w<1
0fp(g4+#f
S71Nt*;
h jQ+.6
tU1z|
p"f~l%
h jY++
h ji+.6
-#f~{(4
,|(t[."
(t\P.J
"o~o f
h jq+.6
~D`'"-
P'"-|(g
h j]+)
h"f~y*
h"f~y*
h"f~y*
h"f~y*
.O|(lg
h"f~y*
CsVh`6
h"f~y*
h"f~y*
.VLamNd
0NT#f}q
0Ql"o}
h jy+.6
h"f}t
,x("-p(
,|("-t(
.q|&"-
&"-x(u
j!+.6
.Ox"f~
0Ot"f}v
t"fhw!(
ji+.6
0Zp(h4/_
-Pm'g-X&
.Pt"f~p
.Pt"f~p
ji+.6
;#f}p(
rh"f}o
)"-x f!
ls/Pt(
(v49#f}{V
|1hpUQ
3-)yD+
K~V)"-x
0Ol"f~l
|1_p(h4-
0Ot"f}j
g#f}qU
g#f}qU
0Op(qY
-l*4)n
0Q`#o}z
0Kt"f~
,t&"-x
fh(:-8
rh*2-,
0Qp(B-
mh&Z-(
g)~<g#
.qt*2-
,xc*-4
|| "-|
|| "-|
(t[P%T
0rt k1S
"o}r(-
,t"o}j&
wSWh&
0Lx"f~l
0Tp("-|^
t"f}j(
0Jx"f~u
v/nX#f
q1N|"f}o
q1Tl&;
0NT#f~
]Wh`1f
@`Wh`1VHe
0Zp*4Aj
aWh`1VTe
0Wl j!
hWh`1fLe
0Jl"f~^
[B1Vl(
[B1Tl(
d_j("-
[B1Tl(
[B1Ll(
0\l(qo
1Nld*-h
g#f~~(2-t
[B1Vl(
0\x(s[
1Vl("-
[B1Tl(
0Px"f~
[B1Tl(
0Zx(t[
h"f~|*
,|(t[PE
h"f}t*
mh*dUi
mh*dEj
mh*d5k
mh*dqk
mh*d%l
mh*dal
mh*dQm
-l*4)n
h j1+)
,pc*-t
,pd*-p
e,))4}l
rh(,Al
h(lg+.6
fh"f~j
,l(tY/
h"f}k(
h"f}k(
h"f~^e,
h&!}w+S
w:fD.')
.)}D-'W
Mh*"Nh
fh*3Qf
m/VH)n
rh"x}}(n42_
~q(n42_
rh(lDY
[B/Ll(
$ke1Nl
h jq+.6
E+B(Vlc
b'"-x(
/)n,5)
,x(*-(
%*ph*4
0Np*39f
-t(l<:
y1Np*;
y.Qi';
0^p*3mW
0^H)l4*F
Xh&+Me
L}/Op(<
hQ+ph`m
x"f}y(
p"f~}*
("-|'-jj
hz~<(a6
hz~<(a6
hz~<(a6
;~1Vp&
d+'TEi
kv0yg
.P|',`i
;(+"-x
j5+.6
}s(w[P
~s(hYP
QwLs4)'
p("-x(
k!f}k g
p(i<)F
RwLy4*'
j9+.6
jU+.6
;((+]i
inXhz~
}x(*-H
h jA+.6
|~"f}z(~4-
0Dk_1_
g)m~mU2
fh*:-$
0J`#f}tX
0J`#f}tX
h jy+.6
0Q`#o}{
=#f}oU
0Y`#x}t
0K`#f}|
0Q`#o}
0Q`#o}
_gs1Pl(
h jI+.6
h&$1Q\
;((,1i
0Op"f}n
0Wp"o}}&
`1Op"f}}&
0N`#f~t(
(hg+)hg+.6
,l"o}z('}j
$_wmIt
0Qt"o}sd
kg/Qp(
0Ol"f~o(mh
h(i{mUV
-p')fi
,l"f}v
;((,di
k<g'*-x
,x%?ph
}y(2-x
^/Nh&4
,v'vowSj
!f~`)"-x
Fi!f}~
Fj!o}rZ
j-+.6
~n(d]j
j!+.6
b)t+;(~
o0 k_?4*(
-p(<!i
j(q<(
owSxowS
l"f~i`^
.Ot&-Ai
|z(,-i
|y(<-i
|y(4-i
|y(<-i
|y(<-i
c)n+B(<yi
+@(,yi
c)n+B(<yi
-Qg(4wi
-Qf(4si
-Yf(<si
mowL4yi
;((,zi
;((,zi
-Qg(4ui
wLpowL
-Yg(<ui
;1(4vi
;1(4xi
;:(<ti
-Yi'4ui
-Yk'4wi
f0Qi f
f0Qf!f
b+)t<()w<U_
[B1Nl(p<:d
].Tl(#
[B1Nt(
.Np"f~z
[B1Qt("-|&
-`l("-
<g),ej
lIl]bYhd
C/'dii
h"f~p(
lItMhYhU
;:(7i-
p"f}E)
(hd+.6
0`L)49i
l"f}w(,=i
;('<Ii
l"f}x(
n("-x
,|("-x"f
l("-x(l
g)"-|"
{o(t42
i1Tp(m
x(u42)
0qp(w4>'
.Yl(w4>'
1Ip"f}s
0Ql"o}
0Nl(~DA
[B1Vh(
0Kx"f}
0Kx"f~y
("-p(w<(_
-x(g4+)
:)n}k*
;C),Mi
j9+.6
()p}l(
}u("-x
0Sl"o}
0R|"o}
0Op"f~
Yh f1!
2V|*<Qi
g+)4Mi
h"f~p(
2{|*"-
jM+.6
g+)4Mi
j9+)"-
j9+.6
j)+.6
3!m) &
`1Wp"o~p(
kd/Nh(
05#o~n("
Yh $)i
g!j!+.6
s(v4;o
Bp("-x^
N)"-x(
.Jp("-
kb?4*o
`/8ke1M
]0Nh i
u|o(n42
.Xl(sY
}W):-|
h(q<`q
kr/Ox&
kr/Px&
oq-Vh
nq3Vh
oq;Vh
nq3Vh
oq#Vh
._|(p<:(<
oq5Vh
oq-Vh
r1Wp&$
&"-xvf
w\ YFg
,x&"-x{o
|`1Xl(
;(+"-| j
j1+.6
j1+.6
))gg+)
fh"f~l%
;(+"-x
j j)+.6
fh"f}z(
2Pl(tYP
mh(*-d
Ygs3_|*-Ei
Xgs1Wt
Ygs1_l
)#f}k(
mh*4-i
,xd,Ii
l"f}w"
,|"f}nd
__gs3U
h&"-t*
,l(tY/
}m u1S
h"f}j&
,t(t[PXt
0Nl"f}o(s
h*"-t*
0Lp"f~v
ish"f~s
0Vp"o}
ysh"f}
sh"f}s
l(qYPy
U1Ol"f}x
0Op"f}x
/Sl(2-
.Jt(4-i
c1_l(u48'
h"f}s"
h"f}t(
fh(5-i
fhc,yi
l71Q|"o
}y(,%k
}y(,%k
k/\p(<
"f}r(,)k
g+),-i
C/'"-|
0J`#f~p(
0Ix"f~
lW1Q|"o~
0Q`d*-
h!f}p(
k^1Xt&
kn/`lW
kw/ht(<
,l(t[P
~$()tI
,x(tY/$
g"f}}(
Zgs1Ot(=
0Xl ki
Ygq1_t(
,p(tYP
^?4*):-
h"f}j&
,t(t[P
YgnIQ\
;^g%j
?#f}o(t
h("-|(
;:#o}x(g
30'"-p^
sh"x}t(n42_
/Pi!f}i
0J`#f~
0Q`#o~
p"f~o[&
h"f}k(
g+e,=k
h"f}o(n
h"f~q(t
0Nl"f}o(s
h(tYP%
l}y(<1k
.St j-*
y/Lp(4
u1Pp(uY
0Wl"o~l
3)mmi
rh*5mi
fh"f~p
,p(uYP
0Np(tYP
0Np(tYP
[h`3V<e
3^p(n[P
2^P)t[P
[h`3VHd
fh"f}v(
h"f}[),-j
g#f}o(mh
g#fsh(t}
sh&,Ej
fh"f}|
,t(tYP
"f}o(t
o(tYPJ
"f}p(O
0Pt"f}
0Px"f}r"
0Lt"f}
,x "-x
h("-x
e-O!f;
0Pl"f}
]$ w[fFg
h"x~r
;(a1Jp
1Ol"f~{(
a'"-x(
1Xp(g4-
;(a1Jt
0Rl"o}s(l4)_
]/^l(mh)~
e1Ol j
(n[P)[
\h`1V\
.nX),Ek
h(t[PU-
h"f}s*4Ik
h"f}rd,
l(tYP%D
sg)4il
ri(gqi
,l(tY.
0Lp"f~v
Zth"f~s
,t(tYP
fh*2-
,|(tYP
h j!+.6
,x("-t!f
0Ol"f}
0Wl"o}p
'^/Jl&
[gq1Ot(
Xgu1Op"f}k
0Pp"f~k(
0Q`+"-
1Op"f}o
/gi'pC;
hw1fd+]
hw1fd+
l"f~i`1
p"f~mZ
jY+)"-
l"x}C)
eh+)-)l
d+)q<()w
eg+),)l
[th"f}
`/gl&$
,|"f}|
d+)q<()w
uU4nhz
w1kt/
ue4nh j
/bi'yC
ke/Vh(
/Yi'pC
/Yi'pC
30+Z:]
;:(6e[
/Yi'pC
/_d)lh
oph"f~k
th"f}[
fh(lg+!f
3X)i$2
,w2h4*
}p"x~l
}%5nh|
,{!f}lc
{"#w+-
!f~}(m4.#f
`1Lp(!
0Lp"f}
j%+.6
pph"f}
A}th(pI
("-x"f
y"x}k&
rph&7q4
;(#x~n(7q4
/ai'qC
}Atph(
}Atph"f~s
t"x~mW
!f~W)*-t
~th"f}j
th"f}j
}Ytph"f};)
}9sph"f}
}9sph(
}}tph({V
rg.Qx`6
}%rph(
71Il"f~K)
}j(g<:!
g!j)Pe
,x"f~x
}=rph(
g#f}v(
sph*:-t
}yrph(
}mrph(
p"f}~*
rh"fsh
}}tph*
p"f~x|
j~th"f}
1Jt("-
8l"f}q
/Pq!f}
8l"f}q
(hg+)hg+.6
0Px(s40'
l"f}n(
0Op"f}}N
}ipph(v
;g'"-x(
`0Ol!f~s
/Ol!f}x(
l"f}t(
]0Zo!x~y'
l"f~lc
n1Rt"f~D#o}
/Op!f}w
0Px fm
|"f}{(
|"f~|(
,|"f}t
|m(!IS
{g/Vl(
,x"f}p
/To!o~
j%+.6
h(~[Pa
]0Jm`6
i fi+.6
p"f}lc
1Ot"f}R#
/Nq!f}xc
/Ol!f}
p"f~~(
2Ni m9
&!-PIh
/Nl!f~s
"f~{(+
h*"-|*
0Nw!f~{"
,p"f}q
("-x61
l"f~oU
0Pl fy
|"f~}*
/Pv!f}x(
[I/LlV#
0Nh"f}
/Ol!f}x'
,{!o}r
]0Zp!x
l"f~n%
]0Jv`6
|"f}t(
;C#f}r
0V|"o}
0N|"f}
0_|"x}
jI+.6
0Ox"f{u
r"f}n(
@l"f}u
]0Jo`6
0~h(#a
B)"-x'
wD](7y
-x(n43
-x(n43
h(w|s^
t"f}z(u
0Pp6/Ox&
.N|(lh
p`1Yx(
p`1Qx(
p`1Yx(
[H3Li&
p"o}v(
0O|"f}
2u2v1U
|w(v[P
,|6/Jx
0Vp&*-p
0Ol(B-T
,x(*-P
m<(7/M
ll3E?'"-
ld3=7'
tS3=7(
,x"f~}(
1Ox j!
0Jl"f~[)
0Ox"f}
/Ok!f}x
0Jl"f~[)
l"f}y(
0Ot(B-
f3E?'"-
0Ol"f}
;(#o}z
k|j(lY
p6/Jx&
^)l~n(+
u~ph f=
>i'*-l
R)lg+.6
0O|"f}
0It"f~C
"f~>)lh
,p"o}q
g#f~~(
h"f}x(
e1Rx g
g/\|"o}k&
t"f~{(
j}+.6
ed+)ih
x.Nnd+
`0N{!f}m
`0N|("-x!f}s
w1f<:(
h j!+(
/Pl!f}
/Xi!o}
Akh3Yk
/Oy!f}
/Vl("-
3>)toi
h&"-x'
&"-p&"-
2Vi&"-
]0Oi(u40
Tkw0`k!x~s(
}~(:-<
k fm[B
/Ky!f}w
00Qk!o~
kn/^h(
/Jk!f~o'
,t"f}w
/Kj!f~p(
/Ky!f}
,x"f}}
0It"f~X
jY+wo
,t6/Jx&
h6/Jx&
-p(h<1!
D[I1Wl
g!j9Q(
,x"f}s
p"f}s(
]0Jq`6
.=x f1
[H1Np"f}
0Qp"o~o
ke/Tx(
.Ol(gg
f#f~>)
0Xp j!
v|s i1
t`/gx(
S#f~o(
1V| j%
.Lt"f~o\
/Ot!f~~(,
]1Zx"x
.Jl`1]
0Zp"x}k&
[H1|pd
p"o}n(
b)w<(_
h"f~W)
>i(lg+(
g)~__y
/Nh!f}
p0^h(k
|s(l-f
g)"-|(n
j1+.6
0Ot"f}n(
.Nh"f~
p"f~y(
l"f~mUv
,|"f}w(
[[B1Nhc
p"f}r(
h!f}k&
0Op"f}~"
;U)""l"
("-p"o
w2g<:(
/Qy!o~x
x"f~s'
t"f~t'
?o!f}s
/Zj"x}w
/Zj!x}
x0%p!95
x0%p!95
h~L),%j
!WSh3U
+nh!o}
g!j!QL
0Ol"f}
'o0Wl^
u1O,!j1
0O\#f}
0Wd!j-
0O<#f}
h"o}{&
h(t47'9
2E")w<(_
t"f}o(
1Wx("-
l"f}x(
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Win.Malware.Trojanx-9951053-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.vc
ALYac Gen:Variant.Babar.223737
Cylance Unsafe
Sangfor Trojan.Win32.Agent.Vck8
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Clean
K7GW Trojan ( 0040f54a1 )
K7AntiVirus Trojan ( 0040f54a1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEX Malicious
Avast Win32:Pasta [Cryp]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Babar.223737
NANO-Antivirus Virus.Win32.Agent.dvixmz
ViRobot Clean
MicroWorld-eScan Gen:Variant.Babar.223737
Tencent Clean
Sophos Mal/EncPk-AQI
F-Secure Clean
DrWeb Trojan.PWS.Wsgame.57795
VIPRE Gen:Variant.Babar.223737
TrendMicro Clean
McAfeeD Real Protect-LS!05894E6439E6
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Gen:Variant.Babar.223737 (B)
Ikarus Trojan.Win32.Disabler
FireEye Generic.mg.05894e6439e62641
Jiangmin Trojan/Agent.edyx
Webroot Clean
Varist W32/Trojan.CLL.gen!Eldorado
Avira Clean
Fortinet W32/CoinMiner.BELF!tr
Antiy-AVL Trojan/Win32.SBadur
Kingsoft malware.kb.a.988
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium TrojWare.Win32.Agent.OSCF@5rs7jr
Arcabit Trojan.Babar.D369F9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Malware/Win.Generic.R668664
Acronis suspicious
McAfee Flyagent.d
TACHYON Clean
VBA32 BScope.Trojan.MulDrop
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Clean
Rising Packer.Win32.Agent.g (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Trojan.PSE.1TYMTF4
AVG Win32:Pasta [Cryp]
DeepInstinct MALICIOUS
alibabacloud VirTool:Win/Wacatac.B9nj
No IRMA results available.