Static | ZeroBOX

PE Compile Time

2021-03-09 00:23:13

PDB Path

E:\dlooo\WLMPlugin_src\Release\wlmplugindll.pdb

PE Imphash

88be6a3f02e620b370d6f4da1dd6d20a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001f35e 0x0001f400 6.63859448832
.rdata 0x00021000 0x00006999 0x00006a00 5.24986102901
.data 0x00028000 0x0000a940 0x00008c00 4.65026175033
.rsrc 0x00033000 0x000360b8 0x00036200 7.9978183968
.reloc 0x0006a000 0x00003a14 0x00003c00 5.37697885442

Resources

Name Offset Size Language Sub-language File type
RT_MESSAGETABLE 0x000330e8 0x00035b33 LANG_SPANISH SUBLANG_SPANISH_ARGENTINA data
RT_VERSION 0x00068c1c 0x00000340 LANG_SPANISH SUBLANG_SPANISH_ARGENTINA data
RT_MANIFEST 0x00068f5c 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library MSIMG32.dll:
0x100211c8 GradientFill
0x100211cc TransparentBlt
Library KERNEL32.dll:
0x10021054 GetThreadContext
0x10021058 OpenProcess
0x1002105c Thread32First
0x10021060 Thread32Next
0x10021064 OpenThread
0x10021068 VirtualProtect
0x10021070 GetCurrentThreadId
0x10021074 CloseHandle
0x10021078 WriteProcessMemory
0x1002107c ResumeThread
0x10021080 ReadProcessMemory
0x10021084 InterlockedIncrement
0x10021088 InterlockedExchange
0x1002108c MultiByteToWideChar
0x10021090 GetSystemInfo
0x10021094 FlushFileBuffers
0x10021098 CreateFileA
0x1002109c WriteConsoleW
0x100210a0 GetConsoleOutputCP
0x100210a4 Sleep
0x100210a8 GetFileType
0x100210ac LCMapStringW
0x100210b0 LCMapStringA
0x100210b4 GetStringTypeW
0x100210b8 GetStringTypeA
0x100210bc GetLocaleInfoA
0x100210c4 LoadLibraryA
0x100210c8 GetConsoleMode
0x100210cc GetConsoleCP
0x100210d0 SetFilePointer
0x100210d4 IsValidCodePage
0x100210d8 GetOEMCP
0x100210dc GetACP
0x100210e0 GetCPInfo
0x100210e4 HeapReAlloc
0x100210e8 EnterCriticalSection
0x100210ec LeaveCriticalSection
0x100210f0 GetModuleHandleA
0x100210f4 InterlockedDecrement
0x100210f8 FindResourceW
0x100210fc LoadResource
0x10021100 LockResource
0x10021104 VirtualFree
0x10021108 VirtualAlloc
0x1002110c SizeofResource
0x10021110 GetProcAddress
0x10021114 FreeLibrary
0x10021118 SetCurrentDirectoryW
0x1002111c LoadLibraryW
0x10021120 OutputDebugStringW
0x10021124 GetCurrentProcessId
0x10021128 GetModuleHandleW
0x1002112c MulDiv
0x10021130 WriteConsoleA
0x10021134 GetStdHandle
0x10021138 SetHandleCount
0x1002113c GetStartupInfoA
0x10021140 DeleteCriticalSection
0x10021144 SetStdHandle
0x10021148 WriteFile
0x10021150 GetTickCount
0x10021158 HeapDestroy
0x1002115c HeapCreate
0x10021160 GetEnvironmentStringsW
0x10021164 WideCharToMultiByte
0x1002116c GetEnvironmentStrings
0x10021174 HeapFree
0x10021178 GetProcessHeap
0x1002117c GetLastError
0x10021180 TerminateProcess
0x10021184 GetCurrentProcess
0x10021190 IsDebuggerPresent
0x10021194 RaiseException
0x10021198 RtlUnwind
0x1002119c GetCommandLineA
0x100211a0 HeapAlloc
0x100211a4 TlsGetValue
0x100211a8 TlsAlloc
0x100211ac TlsSetValue
0x100211b0 TlsFree
0x100211b4 SetLastError
0x100211b8 HeapSize
0x100211bc ExitProcess
0x100211c0 GetModuleFileNameA
Library USER32.dll:
0x10021204 GetMenu
0x10021208 CreatePopupMenu
0x1002120c AppendMenuW
0x10021210 DrawMenuBar
0x10021214 CheckMenuItem
0x10021218 ShowWindow
0x1002121c SetWindowPos
0x10021220 MoveWindow
0x10021224 wsprintfW
0x10021228 SetWinEventHook
0x1002122c LoadCursorW
0x10021230 RegisterClassExW
0x10021234 GetSystemMetrics
0x10021238 GetClientRect
0x1002123c ClientToScreen
0x10021240 SetWindowRgn
0x10021244 DefWindowProcW
0x10021248 GetDCEx
0x1002124c ReleaseDC
0x10021250 InvalidateRect
0x10021254 SetClassLongW
0x10021258 GetClassLongW
0x1002125c GetWindowLongW
0x10021260 SetWindowLongW
0x10021264 SendMessageW
0x10021268 BeginPaint
0x1002126c SetRect
0x10021270 DrawTextW
0x10021274 EndPaint
0x10021278 GetWindowRect
0x1002127c CreateWindowExW
0x10021280 LoadImageW
0x10021284 AnimateWindow
0x10021288 CallWindowProcW
0x1002128c PostQuitMessage
Library GDI32.dll:
0x10021010 SetDCPenColor
0x10021014 RoundRect
0x10021018 GetPixel
0x1002101c GetDeviceCaps
0x10021020 CreateFontIndirectW
0x10021024 SetTextColor
0x10021028 TextOutW
0x1002102c DeleteObject
0x10021030 CreateCompatibleDC
0x10021034 SelectObject
0x10021038 GetObjectW
0x1002103c DeleteDC
0x10021040 SetBkMode
0x10021044 SetTextAlign
0x10021048 GetStockObject
0x1002104c CreateRoundRectRgn
Library ADVAPI32.dll:
0x10021000 RegCloseKey
0x10021004 RegOpenKeyExW
0x10021008 RegQueryValueExW
Library SHELL32.dll:
0x100211fc ShellExecuteW

Exports

Ordinal Address Name
1 0x10005430 DllRegisterServer1
2 0x10005600 InitDLL
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
t$dSUj
L$L_^d
9t$|_^r
9\$ uf
9\$(uF
\$ ;\$(t
t$LSU3
D$TRPQ
D$LQRh
PSQjLh
D$ RSj
L$H_^]d
T$$hH
D$(h@
t$dSUj
L$L_^d
t$dSUj
L$L_^d
t$dSUj
L$L_^d
9\$ uf
9\$(uF
\$ ;\$(t
9\$ uf
9\$(uF
\$ ;\$(t
9\$ uf
9\$(uF
\$ ;\$(t
L$$QWj
T$4RPQ
t$,VQWP
D$$WVPQ
tO<JtK
tG<JtC
tV<JtR
tO<JtK
L$XSPRQ
D$L+D$(_]
T$4RPW
t$X;t$\s0
T$4RPQSW
T$,PQRVUS
T$8RSV
L$<QWV
T$<RWV
T$<RWV
T$<RWV
T$<RWV
T$<RWV
\$<SWV
T$<RWV
l$PVSRU
D$LuE%
L$PRSPQ
D$PQSRP
T$PVSQR
L$PVSPQ
T$PVSQ%
L$PVSPQ
L$PVSPQ
l$PVSPU
T$LVSRU
T$PPSQR
L$PRSPQ
t$4SWV
t$4SWV
t$4SWV
T$PUSQ
L$LPSQU
D$LRSPU
D$LRSPU
T$LQSRU
\$PSWV
n,_^][
0WWWWW
0WWWWW
QQSVWd
0SSSSS
0WWWWW
AAFFf;
0SSSSS
HtHu4j
s[S;7|G;w
tR99u2
u)jAXf;
HHtYHHt
j@j ^V
>=Yt1j
_VVVVV
^WWWWW
URPQQhtd
0A@@Ju
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
0SSSSS
0SSSSS
_VVVVV
PPPPPPPP
PPPPPPPP
t"SS9]
<+t(<-t$:
+t HHt
t+WWVPV
bad allocation
map/set<T> too long
invalid map/set<T> iterator
SizeofResource
LockResource
LoadResource
FindResourceW
CoRegisterClassObject
CreateWindowExW
CryptEncrypt
CryptImportKey
CryptAcquireContextW
VirtualAlloc
LdrAccessResource
LdrFindResource_U
Go Trappola Library Website
ToolButtonMSIE
BUTTONWEB
Run Media Player
ToolButtonMplayer
BUTTONMPLAYER
button[ID=atom(%s)]
AccName:"%s";
AccRole: 57;
AccDesc:"%s";
AccDefAction:rcstr(20068);
ShortcutString:"%s";
element[id=atom(%s)] { content:rcimg(%d); }
<Button id=atom(%s) AccRole=57 Class="TransparentButton" Layout=flowlayout(0,2,0,2) Active=MouseandKeyboard|NoSyncFocus Padding=rect(5,4,5,4)>
<element class="ToolbarIcon" ID=Atom(%s)/> </Button>
MOVSXD
MOVZXD
MOVZXDW
_3DNow! II
CVTDQ2PD
MOVQ2DQ
POPCNT
PSHUFHW
MOVDQU
CVTTPS2DQ
CVTSS2SD
RSQRTSS
SQRTSS
CVTSS2SI
CVTTSS2SI
MOVNTSS
CVTSI2SS
MOVSHDUP
MOVSLDUP
CVTPD2DQ
MOVDQ2Q
ADDSUBPS
HSUBPS
HADDPS
INSERTQ
PSHUFLW
CVTSD2SS
SQRTSD
CVTSD2SI
CVTTSD2SI
MOVNTSD
CVTSI2SD
MOVDDUP
OUT DX, AL
IN AL, DX
JMP FAR
LOOPNZ
FCOMIP
FUCOMIP
FNSTSW AX
FDIVRP
FSUBRP
FCOMPP
FUCOMP
FNSTSW
FNSAVE
FRSTOR
FUCOMI
FSETPM
FNINIT
FNCLEX
FEDISI
FCMOVNU
FCMOVNBE
FCMOVNE
FCMOVNB
FISTTP
FUCOMPP
FCMOVU
FCMOVBE
FCMOVE
FCMOVB
FIDIVR
FISUBR
FICOMP
FSCALE
FRNDINT
FSINCOS
FYL2XP1
FINCSTP
FDECSTP
FPREM1
FXTRACT
FPATAN
FLDLN2
FLDLG2
FLDL2E
FLDL2T
FNSTCW
FNSTENV
FLDENV
FSTSW AX
FSTENV
CALL FAR
MASKMOVDQU
MOVNTDQ
CVTTPD2DQ
ADDSUBPD
VMCLEAR
SHUFPD
HSUBPD
HADDPD
PSLLDQ
PSRLDQ
PSHUFD
MOVDQA
PUNPCKHQDQ
PUNPCKLQDQ
CVTPS2DQ
CVTPD2PS
ANDNPD
SQRTPD
MOVMSKPD
PCMPISTRI
PCMPISTRM
PCMPESTRI
PCMPESTRM
MPSADBW
PINSRQ
PINSRD
INSERTPS
PINSRB
EXTRACTPS
PEXTRQ
PEXTRD
PEXTRB
PBLENDW
BLENDPD
BLENDPS
ROUNDSD
ROUNDSS
ROUNDPD
ROUNDPS
PHMINPOSUW
PMULLD
PMAXUD
PMAXUW
PMAXSD
PMAXSB
PMINUD
PMINUW
PMINSD
PMINSB
PCMPGTQ
PMOVZXDQ
PMOVZXWQ
PMOVZXWD
PMOVZXBQ
PMOVZXBD
PMOVZXBW
PACKUSDW
MOVNTDQA
PCMPEQQ
PMULDQ
PMOVSXDQ
PMOVSXWQ
PMOVSXWD
PMOVSXBQ
PMOVSXBD
PMOVSXBW
BLENDVPD
BLENDVPS
PBLENDVB
COMISD
UCOMISD
CVTPD2PI
CVTTPD2PI
MOVNTPD
CVTPI2PD
MOVAPD
MOVHPD
UNPCKHPD
UNPCKLPD
MOVLPD
MOVUPD
MASKMOVQ
PSADBW
PMADDWD
PMULUDQ
PMAXSW
PADDSW
PADDSB
PMINSW
PSUBSW
PSUBSB
MOVNTQ
PMULHW
PMULHUW
PMAXUB
PADDUSW
PADDUSB
PMINUB
PSUBUSW
PSUBUSB
PMOVMSKB
PMULLW
VMPTRST
VMPTRLD
CMPXCHG16B
CMPXCHG8B
SHUFPS
PEXTRW
PINSRW
MOVNTI
CMPXCHG
SFENCE
MFENCE
LFENCE
CLFLUSH
STMXCSR
LDMXCSR
FXRSTOR
FXSAVE
VMWRITE
VMREAD
PCMPEQD
PCMPEQW
PCMPEQB
PSHUFW
PACKSSDW
PUNPCKHDQ
PUNPCKHWD
PUNPCKHBW
PACKUSWB
PCMPGTD
PCMPGTW
PCMPGTB
PACKSSWB
PUNPCKLDQ
PUNPCKLWD
PUNPCKLBW
CVTDQ2PS
CVTPS2PD
ANDNPS
RSQRTPS
SQRTPS
MOVMSKPS
CMOVLE
CMOVGE
CMOVNP
CMOVNS
CMOVBE
CMOVNZ
CMOVAE
CMOVNO
PALIGNR
PMULHRSW
PSIGND
PSIGNW
PSIGNB
PHSUBSW
PHSUBD
PHSUBW
PMADDUBSW
PHADDSW
PHADDD
PHADDW
PSHUFB
SYSEXIT
SYSENTER
COMISS
UCOMISS
CVTPS2PI
CVTTPS2PI
MOVNTPS
CVTPI2PS
MOVAPS
PREFETCHT2
PREFETCHT1
PREFETCHT0
PREFETCHNTA
MOVHPS
MOVLHPS
UNPCKHPS
UNPCKLPS
MOVLPS
MOVHLPS
MOVUPS
PAVGUSB
PSWAPD
PMULHRW
PFRCPIT2
PFCMPEQ
PFSUBR
PFRSQIT1
PFRCPIT1
PFCMPGT
PFRSQRT
PFCMPGE
PFPNACC
PFNACC
PREFETCHW
PREFETCH
WBINVD
SYSRET
SYSCALL
RDTSCP
SWAPGS
INVLPGA
SKINIT [EAX]
VMSAVE
VMLOAD
VMMCALL
MONITOR
VMXOFF
VMRESUME
VMLAUNCH
VMCALL
INVLPG
Fstring too long
invalid string position
Unknown exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
(null)
`h````
xpxxxx
`h`hhh
xppwpp
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
GAIsProcessorFeaturePresent
KERNEL32
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
RtlInitAnsiString
RtlInitUnicodeString
LdrGetProcedureAddress
NtSuspendThread
DbgPrint
NtCurrentTeb
NtSetEvent
NtPulseEvent
NtResetEvent
NtClose
NtCreateEvent
NtOpenEvent
NtQueryInformationThread
LdrGetDllHandle
bad allocation
bad allocation
bad allocation
bad allocation
bad allocation
Registers - tid: %d#
lastError
EFLAGS
%s: %X -
bad allocation
bad allocation
bad allocation
list<T> too long
E:\dlooo\WLMPlugin_src\Release\wlmplugindll.pdb
AccessibleObjectFromEvent
OLEACC.dll
TransparentBlt
GradientFill
MSIMG32.dll
MulDiv
GetModuleHandleW
GetCurrentProcessId
OutputDebugStringW
LoadLibraryW
SetCurrentDirectoryW
FreeLibrary
GetProcAddress
SizeofResource
VirtualAlloc
VirtualFree
LockResource
LoadResource
FindResourceW
InterlockedDecrement
GetThreadContext
OpenProcess
Thread32First
Thread32Next
OpenThread
VirtualProtect
CreateToolhelp32Snapshot
GetCurrentThreadId
CloseHandle
WriteProcessMemory
ResumeThread
ReadProcessMemory
InterlockedIncrement
InterlockedExchange
MultiByteToWideChar
GetSystemInfo
KERNEL32.dll
CallWindowProcW
AnimateWindow
LoadImageW
CreateWindowExW
GetWindowRect
EndPaint
DrawTextW
SetRect
BeginPaint
SendMessageW
SetWindowLongW
GetWindowLongW
GetClassLongW
SetClassLongW
InvalidateRect
ReleaseDC
GetDCEx
DefWindowProcW
SetWindowRgn
ClientToScreen
GetClientRect
PostQuitMessage
RegisterClassExW
LoadCursorW
SetWinEventHook
wsprintfW
MoveWindow
SetWindowPos
GetSystemMetrics
CheckMenuItem
DrawMenuBar
AppendMenuW
CreatePopupMenu
GetMenu
ShowWindow
USER32.dll
GetStockObject
SetTextAlign
SetBkMode
DeleteDC
GetObjectW
SelectObject
CreateCompatibleDC
DeleteObject
TextOutW
SetTextColor
CreateFontIndirectW
GetDeviceCaps
GetPixel
RoundRect
SetDCPenColor
CreateRoundRectRgn
GDI32.dll
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
CoInitialize
ole32.dll
OLEAUT32.dll
HeapFree
GetProcessHeap
GetLastError
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RaiseException
RtlUnwind
GetCommandLineA
HeapAlloc
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
HeapSize
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
HeapCreate
HeapDestroy
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
WriteFile
GetModuleHandleA
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
SetFilePointer
GetConsoleCP
GetConsoleMode
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
LCMapStringA
LCMapStringW
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
FlushFileBuffers
wlmplugindemo.dll
DllRegisterServer1
InitDLL
.?AVout_of_range@std@@
%Bl@<TZgk!ZWk)B
1.HKe
0123456789abcdef
[BX+SI
[BX+DI
[BP+SI
[BP+DI
WBYTE
DQWORD
DWORD
QWORD
TBYTE
DQWORD
REPNZ
SHORT
SMALL
LARGE
 !"#$%&'()*+,-./0123456789
 !"#$%&'()*+,-./
 !"#$%&'()*+,-./012345678
 !"#$%&'()*+
,-./0123456789:;
 !"#$%&'(
$%&'()*+,-./0123
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFG\
$%&'()*+,-.
 !"#$%&'()*+,-./01234567
CDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ab
cdefghijklmnop
 !"#$%&'()
,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVW
XYZ[\]^_`abc
defghijklmnopqrstuvwxyz{|}~
 !"#$%&
'()*+,-
./01234
56789:;
<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`
bcdefghijklmnopqrstuvwxyz{|}~
.?AV_com_error@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVINktHookSimple@@
.?AVNktHookBase@@
.?AVNktApiHook@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVNktFunctionWrapper@@
.?AVNktLocalFunction@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
m}j/08E6Q:
HySC{d"
fz?W=&
h*l`=c
<6Fkg\b:
lUKQkV
KA$yd
4-8?'o
CrB}yW
:kC4%V/a
'J]LrU
T":[[e
55R0.x
4M(q`e
{T80sDk
nI}^Qsi
}'PlNa
8/J_r_E/
j=5X0w]
l$/_ML
"iQ+!N
9a[DU;/"
`*xWW<)#
bc)c s
AiM!:1
{_c/PE
3#3"Co
C]i~n?e
AQ4 x
/WX8d+
{r8DV
a_B!H%
NQmq!s}
Nn1l13
l-za%C
qy92AV
;)v=Qf
F_I~+$
5u[)Vs
H-LxNL(Q
BLhYtB
_hVr.[
O-FmL\Q
tFTK}{zXt
0W\^|v
Q&_C-6D_
KW j:z
i8Yb1B,
13ahm|)
kr_|Km
'0WU&8
BFh|ny
Mw'yL9
XZPD/o
Ei&[@7#
BXkl.S
2{N~z$
jaH5'4
@7ngS|
CtV}"
eu&0
b4XWN$,v
_0QDe0
h!K.'C
GDArM<6X
!F[-QV
r3K%a/
sWT paT
)05<qJ
9LcLL^
SGdvJ?
3Q7e@=
PY"HNZ
HJiK2oTKH'P
A#c16R2
MBEjp
w~"][A
$d>L~25
2]i?FR
YmX;rD
7L%IqN
`M;H<P
ZDg2+~
yRz<j>=
=kT5Fv{+
i|E'hj_
k@->\t
gESMh.
7P%5@+wP
y6pKZr
*/dqj,>
o,\L;e^
D`<<M,h+)
<Hh.f;
pL&?qD
HqDGp'
vW1=BJR||
?Wp8Wd
c2^4%}Du
CL6uD}
4zh*%:E
qQyWNzXcj
u%p#{
LCf&u>
V!NG9Q
9ZcAaGb
?G<&;N
'}+fVC
ma}=A\
<8h<Tk
m_pd<v{
]YrwLt
e!DL4e
0;y8|)
XcfhO
VbkQKs
==Z:Z8
{VchKE
RuX|+b)
y#gdD,1
3E<J6U
Dqt1!t
JZo")i
BU7OD~
/vx6j\=
/hh`;|
&BkwtEx
-<O.%t
A3-iZ{
nUjXV+
<NQp5p&
qyc[7u
%>^ka%W2
?PSK#%
T")|Hy
^J]q ^
zf&U=Q
><}|iX`
}r.)r!
L*x>!c
1eZ#&>
sQ)slr
26W)X!
w'+}R2
W;Q.^:2
+0;0Q0;
unVgf(
$5$3t1P
`G}k+Ql
g:`KZfq
,.2cY7
(ZNKsM
Og2G;X
ldVs9p
H[37mN
sbd13%
N2&SCL
adS#:
htJ~8h
Eyvn^N
`gPB3nO
;Fl'~DF
xBUFhOb
l+Q_0>J
)SPh2_
?=(D#|8y`
sNH{@Jl-(t'
u7[0`M
=y 0cK1
">.S6n
O &%'K
Fe3V(X
"7SEbC
Z2A"v@ \
w.4<3>}
1Nn_tW&
NkvUDivV
$AXlh3
n8#Sr+svZ
*wl)3%C)
B}Y@&*
A.ed0p
ZNM;9vI
B3G=TX
C*@`(*Bg
Gd2oq_
SRZWy?~
yK|a?R
W&[yFW,D7
g:wAI^
U?I@^|
@j!lc/
7;_k2pJ
M:3a7[
:/od{nt
-%ws9KV
Y={7xT+
yexxC;s
qRY8!*
jf@r4i
Js2Z"m
A3K2JS:]
OlYUAb
$jgg_y
'ad!{Z
%J5P?(
z[^P+kZE
f( LUd
59H7Ed
i_||gi
=`O=y0
1"udGsd
"TPju2
z84Yi$
LwXmJ
G(n4Vt
(UdfWWH
hW\|i-L
XNCMJ
;inMQ.
U-i6-f
Y=D&jWt
T1G@~zn
D.h=ohj%
{>*X,7
/mjQ%?5
K#oUIX
5QsmyW
d~p5{R&
8QV3!Q
z[2_A
>7FP-t
t4@dU/
ga78|G`
1/KSI]
~=b_bK
(n8;]0
"n4r\|
ZqZXjlc
.Ei 2:Im
n/PWRJ
u@n}}c
IyEosa
C&^"}*
^0I\V
~rc\Sg[
ic5.i:
YY0mfIj
85mW5
$<G4jM
\YOwm>]
((69"(M
%aL,M>fk
mERW:k
]YRIw)
xnBJyu
AO-'_#
Ral*3|
vnb{M7<9
W^:x.E
f.Y{ml8#
%#Z|FQ
saUAc>I
KB2S-c
m3l[:O
8fq?<
r~lk*u
hZMiP]
K3z%<
])?#CY
Le8<_G
Oa@-+:
:+Z+!z
az-nD=
#TQaU
sm~ \h
Ia!~)d
G~2Gnx
T-mZ*8
1X*n<O
z%T>&#
-%JsE*4p?
Z@gu/8u
;NDUwTe
G%-]Q|
P%\X{!jf
XjQ+$G
=^`qX<:
71ar2t
[t\kh*j
^@dkhv
`+Xn1RM
#2U5%<
nKg&v9
U]UqlIXlJ
qv#uXv
X14|CE
v?XRb
W`eu8>
}F`#d$
?)|}q6
:czN(h
2/L"z:O
VP{0j4
s{ k."
"xWGE5
_"gSCq
T^~Tg@Y^4
~k_1~#x
y1AJ{w
=Ni\sM,
M::%A,
E^evDerV
V5Ssms
f$?W|,
[8w./
\1y.fP1b
W9/SLr
_a5J$
YUxyFB/
[!VaA*p
+E7tHc
gsyqT0W
@KyVpe
qO7k$'
/bd*[g
L8LRVn
$+ol2)
0-k$Sd
$D0"WA9
u5eLP^
vBO'IN
cwM,g;O<Bv
6mkZ${(0
5,1`jb
HCLLTr
wiHKSn6
X35-cXQ
eluS["
!)TM,#
dUps`'
-]p^7!3
sJ~zh;o5>
3'|7u(_d
-Mgw%S
i-fXyT
}t!?]:
l;pQJX
TY4V>@n
rB';@\D
{)%=3b
3QJ7,*
op/@J%
wO.NT!
pN <e*1
xO<Z**
PeMm*0
gr9MKLd
61`#8y
CquYq?
6|V[i
}GB,6f1
D>;BKsY{
2|cDJ8l)
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
5)5#6V6e6
021J1S1Y1_1k1
2-2<2B2f2k2s2}2
3!343;3C3I3
8+828:8H8O8`8
9X9m9r9|9
:*:>:h:
;&;t;|;
=!='=?=M=
>'>7>M>m>
?'?_?m?s?
384J4V4c4p4
5W5\5d5w5|5
6!6&6,60666:6@6D6J6]6z6
7/747Z7}7
8'949c9
;);<;L;[;k;
<&<5<P<`<t<
=E=T=b=q=
T6Y6`6g6P7W7e7
7$8+898Z8_8f8m8
>*>[>h>
010<0T0
4)4/4@4R4^4d4
5!5+565S5
5)6/64696>6G6`6u6
99*9I9
:%:L:T:z:
::=R=f=
10272j2
2B3J3R3
4'4N4`4
;C;[;h;
<!<;<J<
>0>@>S>f>y>
7.7?7L7P7T7X7\7`7+8E8
9 9:9C9`9g9
;0<_<|<
1X2_2y2
7)858>8m8
:0:N:p:
>$>K>r>{>
?#?;?G?Q?
8J8U8_8{8
9M9V9{9
:.:::C:v:
;&;0;J;V;_;r;~;
<:<F<O<[<g<q<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
(0,0004080<0@0D0H0L0P0T0X0
1p4t4x4|4
7'717N7}7
828C8_8j8
;e<o<|<
<(=.=6=C=W=v=
2#3A3H3L3P3T3X3\3`3d3
3&414L4S4X4\4`4
5J5P5T5X5\5
93989O9
9%:=:E:K:
22#2'2+2/23272;2?2C2G2K2O2S2W2[2_2c2g2k2o2s2w2{2
5-5R5,646L6d6
:#;A;H;L;P;T;X;\;`;d;
;&<1<L<S<X<\<`<
=J=P=T=X=\=
>0>6>A>M>b>i>}>
?!?(?@?O?V?c?
01070S0k0
1.181p1x1
2%20272R2W2_2e2l2r2y2
33*3/3<3J3P3]3}3
1-181u2*3[3c3x3
5K8R8]9
5;5D5P5
848@8H8X8m8
:(:I:O:
: ;*;R;k;
;@<F<j<
=V=a=k=|=
=:?K?S?Y?^?d?
0'0.0e0
1!1&1G1L1
4/454;4A4G4M4T4[4b4i4p4w4~4
5#555@5c5'646I6[6x6
7O7T7|7
747;7T7h7n7w7
7C8c8q8v8
;.;A;L;R;X;];f;
<)<:<@<Q<
839>9H9a9k9~9
<'<B<J<R<i<
==>W>`>
< <&<@<O<\<h<x<
=0=c=r={=
2292M2
55+5r5
5/646y6~6
9+909:9H9
=$=9=@=F=\=w=
0'020U0
6\7R8Z8
:0;6;F;
=7=E=K=S=]=b=g=q=v={=
>%>*>/>9>>>C>M>R>W>a>f>o>|>
<$<R<c<g=
3*3J3R3u3
4D5H5L5P5T5
9]9c96:E:
?4?I?z?
0:0j0
3!313A3L3P3U3
:$:0:4:<:H:L:T:`:d:l:x:|:
<$<(<P<T<X<
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
$9(9,9094989<9@9D9H9L9P9T9p9t9x9|9
9T:X:h:l:p:t:|:
;$;<;L;P;`;d;h;l;t;
< <$<,<D<T<X<`<x<
= =0=4=8=<=D=\=l=p=
?4?H?X?l?t?
00080D0d0p0
1$101P1\1|1
202P2p2
3<3H3P3
4 4<4@4\4`4
5 5@5`5
6 6@6`6
7$7,7@7H7L7T7\7d7x7
748H8T8\8t8
9<9D9L9T9`9
:$:0:8:h:|:
0(0,00080
9$909<9H9T9`9l9x9
: :,:8:D:P:\:h:t:
;(;4;@;L;X;d;p;|;
<$<0<<<H<T<`<l<x<
= =,=8=D=P=\=h=t=
>(>4>@>L>X>d>p>|>
?$?0?<?H?T?`?l?x?
0 0,080D0P0\0h0t0
1(141>1B1L1X1d1p1|1
2$202<2H2T2`2l2x2
3 3,383D3P3\3h3t3
4(42464@4J4N4X4d4p4|4
5$505<5H5T5`5l5x5
6 6*6.686D6P6\6h6t6
7(747@7L7X7d7p7|7
8$808<8H8T8`8l8x8
9 9,989D9P9\9h9t9
:(:4:@:L:X:d:p:|:
;$;0;<;H;T;`;l;x;
< <*<.<8<B<F<P<Z<^<h<t<
=(=4=@=L=X=d=p=|=
>$>.>2><>F>J>T>^>b>l>v>z>
?"?,?6?:?D?N?R?\?f?j?t?~?
0(040@0L0X0d0p0|0
1$101<1F1J1T1`1j1n1x1
2"2,282D2P2Z2^2h2t2~2
3(343@3L3X3d3p3|3
4$404<4H4T4`4l4x4
5"5,585B5F5P5\5h5t5
6(646@6L6X6d6p6|6
7$707<7H7T7`7l7x7
8 8,888D8P8\8h8t8
9(949@9L9X9d9p9|9
:$:0:<:H:T:`:l:x:
; ;,;8;D;P;\;h;t;
<(<4<@<L<X<d<p<|<
=$=0=<=H=T=`=l=x=
> >,>8>D>P>\>h>t>
?(?4?@?L?X?d?p?|?
0$000<0H0T0`0l0x0
1 1,181D1P1\1h1t1
2(242@2L2X2d2p2|2
3$303<3H3T3`3l3x3
4 4,484D4P4Z4^4h4t4
5(545@5L5X5d5p5|5
6$6.626<6H6T6`6l6x6
7 7,787D7P7\7f7j7t7
8(848@8L8X8d8p8|8
9$909<9H9T9h9l9p9t9x9|9
:$:):-:<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?]?a?
l0q0u0
1 1$1(1,11151
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2q2u2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6d6h6l6p6t6x6|6
7d7h7l7p7t7x7|7
8 8$8(8,81858
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
:$:(:,:0:4:8:<:@:E:I:X:\:`:d:h:l:p:t:y:}:
;,<1<5<H<L<Q<U<d=h=m=q=
? ?$?(?,?1?5?D?H?L?P?T?X?\?`?e?i?x?|?
0!04080<0A0E0T1X1\1`1d1h1l1p1t1x1|1
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3u3y3
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6E6I6T7Y7]7p7t7x7}7
8!84888=8A8T8X8\8a8e8x8|8
; ;$;(;-;1;<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=q=u=
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2)2-2<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7!7(7,70747P7T7X7p7
7(9,9P9T9X9
:$:,:4:<:D:L:T:\:d:l:p:t:x:|:
;(<8<H<X<h<
1p4t4x4|4
5 50585<5@5D5H5L5P5T5X5\5h5H6L6
;0;P;\;
NKT_COLORIZED_WINDOW_CLASS
Plugin Demo DLL
Version 1.0.0
Copyright (C) 2008 Hern
n Di Pietro
Licensed under GNU General Public License.
Read the LICENSE.TXT file for details.
button
rUnknown status
Out to lunch
Online
On the Phone
Offline
Syncing with server
Finding Server
Disconnecting from server
Connecting to server
Invisible
Be Right Back
NKT_COLORIZED_WINDOW_CLASS
Contact Information
Sign-In Name
Friendly Name
Status
Blocked
Can Page?
Mobile Phone
Work Phone
Home Phone
NKT_COLORIZED_WINDOW_CLASS
Handling CoRegisterClassObject for CLSID_Messenger
S_OK, Handling CoRegisterClassObject for CLSID %s
kernel32.dll
ole32.dll
Wuser32.dll
resdll.dll
MSBLWindowClass
Windows Live Messenger
DirectUIHWND
ntdll.dll
advapi32.dll
wmplayer.exe
http://www.nektra.com/products/deviare/trappola/index.php
InstallationDirectory
SOFTWARE\Microsoft\Windows Live\Messenger
BUTTONWEB
BUTTONMPLAYER
InitDLL: Starting up...
Handle_LoadResource %d
Handle_SizeOfResource: cbOldSize is NULL, return with default value
Handle_SizeOfResource: First 'hooked' call for resource %d
Handle_SizeOfResource: handled with hModule=%d
%#x %#x %#I64x
-------------------------------------------
DATA_HANDLE
RESOURCE ADDRESS R_ID
RESOURCE_POINTER_TABLE
%#x %#I64x
----------------------------------------
HANDLE
RESOURCE_ID *
RESOURCE_HANDLE_TABLE
%#I64x %#x %#x %#x %#x %#x
--------------------------------------------------------
TYPE+NAME
MOD
ADDR WHERE OLDSIZE DSIZE
REGISTERED_RESOURCE_TABLE
CRM::AllocResource Returning already allocated address.
Allocating bytes for resource data: %d
SetResource old size for res %I64d to %d bytes.
GetOriginalResourceSize=%d
Freeing allocated resource at address %#x
&About...
Display Contact Information &Window
W&lmPluginDLL
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
$ntdll.dll
eNtApi: CreateEvent: Can't create event with provided name.
\BaseNamedObjects\DV_
\BaseNamedObjects\DV_
APIHook: Initialize: Error ReadFrom.
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
VS_VERSION_INFO
StringFileInfo
2c0a04b0
CompanyName
n Di Pietro
FileDescription
WLMPlugin Demo Dynamic Link Library
FileVersion
1, 0, 0, 1
InternalName
wlmplugindemo
LegalCopyright
Copyright (C) 2008 Hern
n Di Pietro
OriginalFilename
wlmplugindemo.dll
ProductName
WLM Plugin Demo DLL
ProductVersion
1, 0, 0, 1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec Clean
TotalDefense Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
MaxSecure Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet Clean
BitDefenderTheta Clean
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.