Report - PCICL32.DLL

Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer Antivirus UPX PE File DLL PE32 OS Processor Check
ScreenShot
Created 2024.07.17 09:07 Machine s1_win7_x6403
Filename PCICL32.DLL
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.6
ZERO API file : clean
VT API (file) 11 detected (Unsafe, RemoteAdmin, NetSupportManager, Z potentially unsafe, NetSup, Tool, Detected, OOWP, susgen)
md5 ad51946b1659ed61b76ff4e599e36683
sha256 07a191254362664b3993479a277199f7ea5ee723b6c25803914eedb50250acf4
ssdeep 49152:xOHDe5Yr6tYA4S+DjdwfwBTNZaZQclSpmTIH:xOHDe5YrvS+tBQSEm
imphash f0ebeb0de39f647e905e803bbc0c109b
impfuzzy 384:/R9FpJrYAZFJvhktIYe+lzMhOwJ2/GiQNXC:/lrYQJMw+lzMhOwJ2/qC
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info This executable has a PDB path

Rules (10cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

SHFOLDER.dll
 0x1118f6e0 SHGetFolderPathA
pcichek.dll
 0x1118fbf8 IsILS
 0x1118fbfc CheckLicenseString
pcicapi.dll
 0x1118fbe4 CapiClose
 0x1118fbe8 CapiOpen
 0x1118fbec CapiListen
 0x1118fbf0 CapiHangup
MPR.dll
 0x1118f63c WNetCancelConnection2A
 0x1118f640 WNetGetConnectionA
 0x1118f644 WNetAddConnection2A
COMCTL32.dll
 0x1118f0fc ImageList_Draw
 0x1118f100 ImageList_LoadImageA
 0x1118f104 ImageList_Destroy
 0x1118f108 ImageList_ReplaceIcon
 0x1118f10c ImageList_AddMasked
 0x1118f110 ImageList_GetImageCount
 0x1118f114 None
 0x1118f118 ImageList_DrawEx
 0x1118f11c ImageList_GetIconSize
 0x1118f120 ImageList_GetIcon
 0x1118f124 ImageList_Create
VERSION.dll
 0x1118fa84 VerQueryValueA
 0x1118fa88 GetFileVersionInfoA
 0x1118fa8c GetFileVersionInfoSizeA
WINMM.dll
 0x1118fa9c waveOutClose
 0x1118faa0 waveOutReset
 0x1118faa4 waveInClose
 0x1118faa8 waveInUnprepareHeader
 0x1118faac waveInReset
 0x1118fab0 waveInStop
 0x1118fab4 waveOutUnprepareHeader
 0x1118fab8 waveInPrepareHeader
 0x1118fabc waveOutSetVolume
 0x1118fac0 waveOutOpen
 0x1118fac4 waveInStart
 0x1118fac8 waveInOpen
 0x1118facc waveOutWrite
 0x1118fad0 waveOutPrepareHeader
 0x1118fad4 timeGetTime
 0x1118fad8 timeEndPeriod
 0x1118fadc timeBeginPeriod
 0x1118fae0 PlaySoundA
 0x1118fae4 waveInAddBuffer
WSOCK32.dll
 0x1118fb34 send
 0x1118fb38 ind
 0x1118fb3c listen
 0x1118fb40 accept
 0x1118fb44 htons
 0x1118fb48 socket
 0x1118fb4c connect
 0x1118fb50 getpeername
 0x1118fb54 gethostbyname
 0x1118fb58 recv
 0x1118fb5c shutdown
 0x1118fb60 closesocket
 0x1118fb64 WSACleanup
 0x1118fb68 WSAStartup
 0x1118fb6c WSAGetLastError
 0x1118fb70 gethostname
 0x1118fb74 htonl
 0x1118fb78 ioctlsocket
 0x1118fb7c inet_addr
 0x1118fb80 setsockopt
KERNEL32.dll
 0x1118f2c8 IsBadReadPtr
 0x1118f2cc SizeofResource
 0x1118f2d0 CreateDirectoryA
 0x1118f2d4 RemoveDirectoryA
 0x1118f2d8 MoveFileA
 0x1118f2dc MulDiv
 0x1118f2e0 GetDiskFreeSpaceA
 0x1118f2e4 GetCurrentDirectoryA
 0x1118f2e8 SetFileTime
 0x1118f2ec LocalFileTimeToFileTime
 0x1118f2f0 DosDateTimeToFileTime
 0x1118f2f4 GetVolumeInformationA
 0x1118f2f8 FileTimeToDosDateTime
 0x1118f2fc FileTimeToLocalFileTime
 0x1118f300 OpenEventA
 0x1118f304 MultiByteToWideChar
 0x1118f308 OutputDebugStringA
 0x1118f30c SetCurrentDirectoryA
 0x1118f310 GetProcessHeap
 0x1118f314 GetTimeFormatW
 0x1118f318 GetDateFormatW
 0x1118f31c RaiseException
 0x1118f320 InitializeCriticalSectionAndSpinCount
 0x1118f324 WideCharToMultiByte
 0x1118f328 lstrlenW
 0x1118f32c lstrlenA
 0x1118f330 lstrcmpiA
 0x1118f334 FlushInstructionCache
 0x1118f338 lstrcmpA
 0x1118f33c FindResourceExA
 0x1118f340 TerminateThread
 0x1118f344 ReleaseMutex
 0x1118f348 WaitForSingleObjectEx
 0x1118f34c GlobalReAlloc
 0x1118f350 CreateNamedPipeA
 0x1118f354 ConnectNamedPipe
 0x1118f358 SetProcessShutdownParameters
 0x1118f35c SetConsoleCtrlHandler
 0x1118f360 IsDBCSLeadByteEx
 0x1118f364 DisconnectNamedPipe
 0x1118f368 WriteProfileStringA
 0x1118f36c DefineDosDeviceA
 0x1118f370 QueryDosDeviceA
 0x1118f374 ResumeThread
 0x1118f378 VirtualQueryEx
 0x1118f37c GetThreadContext
 0x1118f380 ReadProcessMemory
 0x1118f384 PulseEvent
 0x1118f388 CreateRemoteThread
 0x1118f38c SetThreadContext
 0x1118f390 PostQueuedCompletionStatus
 0x1118f394 CreateIoCompletionPort
 0x1118f398 GetQueuedCompletionStatus
 0x1118f39c Beep
 0x1118f3a0 GetSystemDefaultLangID
 0x1118f3a4 GetSystemInfo
 0x1118f3a8 SuspendThread
 0x1118f3ac OpenThread
 0x1118f3b0 GetProcessVersion
 0x1118f3b4 GlobalGetAtomNameA
 0x1118f3b8 HeapReAlloc
 0x1118f3bc RtlUnwind
 0x1118f3c0 DecodePointer
 0x1118f3c4 EncodePointer
 0x1118f3c8 InterlockedCompareExchange
 0x1118f3cc HeapAlloc
 0x1118f3d0 HeapFree
 0x1118f3d4 FindResourceA
 0x1118f3d8 LoadResource
 0x1118f3dc LockResource
 0x1118f3e0 VirtualProtectEx
 0x1118f3e4 WriteProcessMemory
 0x1118f3e8 GetExitCodeThread
 0x1118f3ec CompareStringA
 0x1118f3f0 SetFilePointer
 0x1118f3f4 GetProfileStringA
 0x1118f3f8 GetOEMCP
 0x1118f3fc GetShortPathNameA
 0x1118f400 TerminateProcess
 0x1118f404 SystemTimeToFileTime
 0x1118f408 CreateFileMappingA
 0x1118f40c OpenFileMappingA
 0x1118f410 MapViewOfFile
 0x1118f414 UnmapViewOfFile
 0x1118f418 CreatePipe
 0x1118f41c DuplicateHandle
 0x1118f420 SetHandleInformation
 0x1118f424 FormatMessageA
 0x1118f428 LocalFree
 0x1118f42c SetNamedPipeHandleState
 0x1118f430 GetPriorityClass
 0x1118f434 WinExec
 0x1118f438 SearchPathA
 0x1118f43c IsValidCodePage
 0x1118f440 SetSystemTime
 0x1118f444 _lopen
 0x1118f448 _lclose
 0x1118f44c DeleteFileA
 0x1118f450 SetFileAttributesA
 0x1118f454 GetSystemDirectoryA
 0x1118f458 GetDateFormatA
 0x1118f45c GetTimeFormatA
 0x1118f460 GlobalSize
 0x1118f464 SetUnhandledExceptionFilter
 0x1118f468 OpenMutexA
 0x1118f46c CreateMutexA
 0x1118f470 SetErrorMode
 0x1118f474 GetACP
 0x1118f478 SetPriorityClass
 0x1118f47c GetFileAttributesA
 0x1118f480 GetTempFileNameA
 0x1118f484 CopyFileA
 0x1118f488 FileTimeToSystemTime
 0x1118f48c GetComputerNameA
 0x1118f490 ExitProcess
 0x1118f494 GetModuleHandleA
 0x1118f498 GetExitCodeProcess
 0x1118f49c GetCurrentProcess
 0x1118f4a0 LoadLibraryExA
 0x1118f4a4 ExitThread
 0x1118f4a8 GetDriveTypeA
 0x1118f4ac GetWindowsDirectoryA
 0x1118f4b0 IsDBCSLeadByte
 0x1118f4b4 GetLocalTime
 0x1118f4b8 GetFileSize
 0x1118f4bc GlobalAlloc
 0x1118f4c0 GlobalLock
 0x1118f4c4 ReadFile
 0x1118f4c8 GlobalUnlock
 0x1118f4cc GlobalFree
 0x1118f4d0 GetSystemPowerStatus
 0x1118f4d4 ExpandEnvironmentStringsA
 0x1118f4d8 FindFirstFileA
 0x1118f4dc FindNextFileA
 0x1118f4e0 FindClose
 0x1118f4e4 GetUserDefaultUILanguage
 0x1118f4e8 GetUserDefaultLangID
 0x1118f4ec GetModuleFileNameA
 0x1118f4f0 GetCurrentProcessId
 0x1118f4f4 CreateProcessA
 0x1118f4f8 DeleteCriticalSection
 0x1118f4fc InitializeCriticalSection
 0x1118f500 GetVersion
 0x1118f504 CreateThread
 0x1118f508 SetThreadPriority
 0x1118f50c InterlockedIncrement
 0x1118f510 WaitForMultipleObjects
 0x1118f514 GetOverlappedResult
 0x1118f518 ResetEvent
 0x1118f51c InterlockedDecrement
 0x1118f520 LeaveCriticalSection
 0x1118f524 EnterCriticalSection
 0x1118f528 GetLastError
 0x1118f52c DeviceIoControl
 0x1118f530 InterlockedExchange
 0x1118f534 SetLastError
 0x1118f538 GetProcAddress
 0x1118f53c FreeLibrary
 0x1118f540 LoadLibraryA
 0x1118f544 CreateFileA
 0x1118f548 GetTempPathA
 0x1118f54c WriteFile
 0x1118f550 GetCurrentThreadId
 0x1118f554 CreateEventA
 0x1118f558 WaitForSingleObject
 0x1118f55c SetEvent
 0x1118f560 GlobalDeleteAtom
 0x1118f564 Sleep
 0x1118f568 GlobalAddAtomA
 0x1118f56c OpenProcess
 0x1118f570 GetVersionExA
 0x1118f574 GetTickCount
 0x1118f578 CloseHandle
 0x1118f57c GetSystemTimeAsFileTime
 0x1118f580 VirtualProtect
 0x1118f584 VirtualAlloc
 0x1118f588 GetModuleHandleW
 0x1118f58c VirtualQuery
 0x1118f590 GetConsoleMode
 0x1118f594 GetCommandLineA
 0x1118f598 LCMapStringW
 0x1118f59c GetCPInfo
 0x1118f5a0 TlsAlloc
 0x1118f5a4 TlsGetValue
 0x1118f5a8 TlsSetValue
 0x1118f5ac TlsFree
 0x1118f5b0 UnhandledExceptionFilter
 0x1118f5b4 IsDebuggerPresent
 0x1118f5b8 IsProcessorFeaturePresent
 0x1118f5bc HeapCreate
 0x1118f5c0 HeapDestroy
 0x1118f5c4 GetStdHandle
 0x1118f5c8 GetModuleFileNameW
 0x1118f5cc HeapSize
 0x1118f5d0 GetLocaleInfoW
 0x1118f5d4 SetHandleCount
 0x1118f5d8 GetFileType
 0x1118f5dc GetStartupInfoW
 0x1118f5e0 GetConsoleCP
 0x1118f5e4 GetUserDefaultLCID
 0x1118f5e8 GetLocaleInfoA
 0x1118f5ec EnumSystemLocalesA
 0x1118f5f0 IsValidLocale
 0x1118f5f4 GetStringTypeW
 0x1118f5f8 GetTimeZoneInformation
 0x1118f5fc CreateFileW
 0x1118f600 SetStdHandle
 0x1118f604 FreeEnvironmentStringsW
 0x1118f608 GetEnvironmentStringsW
 0x1118f60c QueryPerformanceCounter
 0x1118f610 FlushFileBuffers
 0x1118f614 LoadLibraryW
 0x1118f618 WriteConsoleW
 0x1118f61c CompareStringW
 0x1118f620 SetEnvironmentVariableA
 0x1118f624 SetEndOfFile
 0x1118f628 InterlockedPushEntrySList
 0x1118f62c VirtualFree
 0x1118f630 InterlockedPopEntrySList
 0x1118f634 LocalAlloc
USER32.dll
 0x1118f6e8 GetScrollRange
 0x1118f6ec CreateCursor
 0x1118f6f0 HideCaret
 0x1118f6f4 OemToCharBuffA
 0x1118f6f8 ScrollWindow
 0x1118f6fc SetScrollPos
 0x1118f700 SetScrollRange
 0x1118f704 ClipCursor
 0x1118f708 DrawIconEx
 0x1118f70c RemoveMenu
 0x1118f710 SetActiveWindow
 0x1118f714 AdjustWindowRectEx
 0x1118f718 TrackPopupMenuEx
 0x1118f71c SetMenuDefaultItem
 0x1118f720 InsertMenuItemA
 0x1118f724 EndMenu
 0x1118f728 SetMenuInfo
 0x1118f72c GetMenuInfo
 0x1118f730 GetScrollInfo
 0x1118f734 SetScrollInfo
 0x1118f738 TileWindows
 0x1118f73c GetWindowRgn
 0x1118f740 GetAsyncKeyState
 0x1118f744 EnumThreadWindows
 0x1118f748 EnumDisplaySettingsA
 0x1118f74c CreateDesktopA
 0x1118f750 PostMessageW
 0x1118f754 OpenInputDesktop
 0x1118f758 GetMenuItemRect
 0x1118f75c mouse_event
 0x1118f760 MapVirtualKeyA
 0x1118f764 CharLowerBuffA
 0x1118f768 ShowCursor
 0x1118f76c SwitchDesktop
 0x1118f770 AttachThreadInput
 0x1118f774 GetCursor
 0x1118f778 CreateDialogIndirectParamA
 0x1118f77c DialogBoxIndirectParamA
 0x1118f780 DialogBoxParamA
 0x1118f784 SetClassLongA
 0x1118f788 MapDialogRect
 0x1118f78c CreateAcceleratorTableA
 0x1118f790 DestroyAcceleratorTable
 0x1118f794 RedrawWindow
 0x1118f798 InvalidateRgn
 0x1118f79c CharNextA
 0x1118f7a0 LoadAcceleratorsA
 0x1118f7a4 ScreenToClient
 0x1118f7a8 ModifyMenuA
 0x1118f7ac CreateMenu
 0x1118f7b0 MoveWindow
 0x1118f7b4 SetCursorPos
 0x1118f7b8 DrawTextW
 0x1118f7bc IsDialogMessageA
 0x1118f7c0 UnionRect
 0x1118f7c4 DrawFocusRect
 0x1118f7c8 wsprintfW
 0x1118f7cc EndDialog
 0x1118f7d0 OpenWindowStationA
 0x1118f7d4 GetProcessWindowStation
 0x1118f7d8 SetProcessWindowStation
 0x1118f7dc CloseWindowStation
 0x1118f7e0 MsgWaitForMultipleObjects
 0x1118f7e4 GetUserObjectSecurity
 0x1118f7e8 SetUserObjectSecurity
 0x1118f7ec MessageBoxIndirectA
 0x1118f7f0 WinHelpA
 0x1118f7f4 UnhookWindowsHookEx
 0x1118f7f8 SetWindowsHookExA
 0x1118f7fc CreateDialogParamA
 0x1118f800 GetLastActivePopup
 0x1118f804 CallNextHookEx
 0x1118f808 GetUpdateRect
 0x1118f80c BeginDeferWindowPos
 0x1118f810 EndDeferWindowPos
 0x1118f814 GetTopWindow
 0x1118f818 DestroyCursor
 0x1118f81c GetActiveWindow
 0x1118f820 IsZoomed
 0x1118f824 CreatePopupMenu
 0x1118f828 AppendMenuA
 0x1118f82c CopyRect
 0x1118f830 EqualRect
 0x1118f834 LoadStringA
 0x1118f838 ClientToScreen
 0x1118f83c DeferWindowPos
 0x1118f840 IsChild
 0x1118f844 GetWindowPlacement
 0x1118f848 TranslateAcceleratorA
 0x1118f84c SetRectEmpty
 0x1118f850 SetMenu
 0x1118f854 SetWindowPlacement
 0x1118f858 GetForegroundWindow
 0x1118f85c CharUpperBuffA
 0x1118f860 WindowFromPoint
 0x1118f864 WaitForInputIdle
 0x1118f868 GetUserObjectInformationA
 0x1118f86c GetCursorPos
 0x1118f870 CheckDlgButton
 0x1118f874 SetForegroundWindow
 0x1118f878 EnumChildWindows
 0x1118f87c RegisterClipboardFormatA
 0x1118f880 CountClipboardFormats
 0x1118f884 EnumClipboardFormats
 0x1118f888 GetClipboardData
 0x1118f88c IsClipboardFormatAvailable
 0x1118f890 GetClipboardFormatNameA
 0x1118f894 RegisterWindowMessageA
 0x1118f898 DestroyIcon
 0x1118f89c CharUpperA
 0x1118f8a0 ExitWindowsEx
 0x1118f8a4 GetDesktopWindow
 0x1118f8a8 MessageBoxA
 0x1118f8ac keybd_event
 0x1118f8b0 GetThreadDesktop
 0x1118f8b4 SetThreadDesktop
 0x1118f8b8 wvsprintfA
 0x1118f8bc CreateCaret
 0x1118f8c0 ShowCaret
 0x1118f8c4 DestroyCaret
 0x1118f8c8 UnregisterClassA
 0x1118f8cc SetTimer
 0x1118f8d0 KillTimer
 0x1118f8d4 SetDlgItemTextA
 0x1118f8d8 SendMessageA
 0x1118f8dc SendDlgItemMessageA
 0x1118f8e0 PostMessageA
 0x1118f8e4 ShowWindow
 0x1118f8e8 DefWindowProcA
 0x1118f8ec CallWindowProcA
 0x1118f8f0 PostThreadMessageA
 0x1118f8f4 GetQueueStatus
 0x1118f8f8 GetDlgItem
 0x1118f8fc GetDlgCtrlID
 0x1118f900 GetDC
 0x1118f904 ReleaseDC
 0x1118f908 InvalidateRect
 0x1118f90c GetKeyState
 0x1118f910 PeekMessageA
 0x1118f914 SetCaretPos
 0x1118f918 DrawMenuBar
 0x1118f91c GetSystemMenu
 0x1118f920 OpenClipboard
 0x1118f924 EmptyClipboard
 0x1118f928 SetClipboardData
 0x1118f92c MessageBeep
 0x1118f930 CloseClipboard
 0x1118f934 FindWindowExA
 0x1118f938 DeleteMenu
 0x1118f93c GetWindowTextLengthA
 0x1118f940 GetFocus
 0x1118f944 GetClassInfoExA
 0x1118f948 DestroyWindow
 0x1118f94c DefDlgProcA
 0x1118f950 RegisterClassExA
 0x1118f954 IsDlgButtonChecked
 0x1118f958 GetDlgItemTextA
 0x1118f95c IsIconic
 0x1118f960 GetMenu
 0x1118f964 SystemParametersInfoA
 0x1118f968 IntersectRect
 0x1118f96c GetCursorInfo
 0x1118f970 GetIconInfo
 0x1118f974 IsWindowVisible
 0x1118f978 GetWindow
 0x1118f97c SendMessageTimeoutA
 0x1118f980 GetClassLongA
 0x1118f984 CopyIcon
 0x1118f988 CopyImage
 0x1118f98c LoadImageA
 0x1118f990 OpenDesktopA
 0x1118f994 EnumDesktopWindows
 0x1118f998 CloseDesktop
 0x1118f99c EnumWindows
 0x1118f9a0 GetClassNameA
 0x1118f9a4 GetClassInfoA
 0x1118f9a8 LoadIconA
 0x1118f9ac RegisterClassA
 0x1118f9b0 BringWindowToTop
 0x1118f9b4 GetMessageA
 0x1118f9b8 TranslateMessage
 0x1118f9bc DispatchMessageA
 0x1118f9c0 SetPropA
 0x1118f9c4 GetPropA
 0x1118f9c8 RemovePropA
 0x1118f9cc GetCapture
 0x1118f9d0 SetCapture
 0x1118f9d4 ReleaseCapture
 0x1118f9d8 CreateWindowExA
 0x1118f9dc BeginPaint
 0x1118f9e0 EndPaint
 0x1118f9e4 wsprintfA
 0x1118f9e8 PostQuitMessage
 0x1118f9ec GetMenuItemID
 0x1118f9f0 CheckMenuItem
 0x1118f9f4 EnableMenuItem
 0x1118f9f8 GetMenuItemInfoA
 0x1118f9fc SetMenuItemInfoA
 0x1118fa00 PtInRect
 0x1118fa04 GetWindowDC
 0x1118fa08 LoadMenuA
 0x1118fa0c GetSubMenu
 0x1118fa10 GetMenuItemCount
 0x1118fa14 DestroyMenu
 0x1118fa18 InflateRect
 0x1118fa1c GetSystemMetrics
 0x1118fa20 FindWindowA
 0x1118fa24 GetWindowThreadProcessId
 0x1118fa28 IsWindow
 0x1118fa2c SetFocus
 0x1118fa30 SetWindowPos
 0x1118fa34 GetParent
 0x1118fa38 GetWindowTextA
 0x1118fa3c SetWindowTextA
 0x1118fa40 GetWindowLongA
 0x1118fa44 SetWindowLongA
 0x1118fa48 MapWindowPoints
 0x1118fa4c GetClientRect
 0x1118fa50 DrawTextA
 0x1118fa54 OffsetRect
 0x1118fa58 IsWindowEnabled
 0x1118fa5c SetRect
 0x1118fa60 GetWindowRect
 0x1118fa64 FillRect
 0x1118fa68 LoadBitmapA
 0x1118fa6c GetSysColor
 0x1118fa70 SetCursor
 0x1118fa74 LoadCursorA
 0x1118fa78 UpdateWindow
 0x1118fa7c EnableWindow
GDI32.dll
 0x1118f140 EndPage
 0x1118f144 StartPage
 0x1118f148 ExtEscape
 0x1118f14c ExtTextOutA
 0x1118f150 CreateDIBitmap
 0x1118f154 GetSystemPaletteEntries
 0x1118f158 RealizePalette
 0x1118f15c EqualRgn
 0x1118f160 CreateBrushIndirect
 0x1118f164 SetMapMode
 0x1118f168 GetDCOrgEx
 0x1118f16c SetBrushOrgEx
 0x1118f170 PatBlt
 0x1118f174 CreatePatternBrush
 0x1118f178 GetTextMetricsA
 0x1118f17c StretchBlt
 0x1118f180 GetDIBits
 0x1118f184 CreateDIBSection
 0x1118f188 GdiFlush
 0x1118f18c GetRegionData
 0x1118f190 CombineRgn
 0x1118f194 GetNearestPaletteIndex
 0x1118f198 GetBkMode
 0x1118f19c CreateFontIndirectW
 0x1118f1a0 SetBitmapBits
 0x1118f1a4 UnrealizeObject
 0x1118f1a8 SetDIBits
 0x1118f1ac SetWindowOrgEx
 0x1118f1b0 AddFontResourceA
 0x1118f1b4 CreatePenIndirect
 0x1118f1b8 GetClipRgn
 0x1118f1bc GetWindowOrgEx
 0x1118f1c0 IntersectClipRect
 0x1118f1c4 Arc
 0x1118f1c8 Chord
 0x1118f1cc Pie
 0x1118f1d0 Polyline
 0x1118f1d4 RoundRect
 0x1118f1d8 SetPolyFillMode
 0x1118f1dc SetTextJustification
 0x1118f1e0 SetTextCharacterExtra
 0x1118f1e4 SelectPalette
 0x1118f1e8 RemoveFontResourceA
 0x1118f1ec CreateCompatibleDC
 0x1118f1f0 CreateCompatibleBitmap
 0x1118f1f4 SelectObject
 0x1118f1f8 GetObjectA
 0x1118f1fc CreateRectRgn
 0x1118f200 CreateRectRgnIndirect
 0x1118f204 PtInRegion
 0x1118f208 RectInRegion
 0x1118f20c CreatePalette
 0x1118f210 GetPaletteEntries
 0x1118f214 GetTextExtentPoint32A
 0x1118f218 BitBlt
 0x1118f21c DeleteDC
 0x1118f220 RectVisible
 0x1118f224 SetRectRgn
 0x1118f228 DeleteObject
 0x1118f22c GetBkColor
 0x1118f230 GetTextColor
 0x1118f234 GetStretchBltMode
 0x1118f238 SetStretchBltMode
 0x1118f23c GetBitmapBits
 0x1118f240 BeginPath
 0x1118f244 TextOutA
 0x1118f248 EndPath
 0x1118f24c PathToRegion
 0x1118f250 GetRgnBox
 0x1118f254 OffsetRgn
 0x1118f258 FillRgn
 0x1118f25c FrameRgn
 0x1118f260 CreateBitmap
 0x1118f264 CreateDCA
 0x1118f268 SelectClipRgn
 0x1118f26c LineDDA
 0x1118f270 Polygon
 0x1118f274 CreateFontIndirectA
 0x1118f278 CreateHatchBrush
 0x1118f27c GetDeviceCaps
 0x1118f280 SetBkColor
 0x1118f284 ExtFloodFill
 0x1118f288 GetPixel
 0x1118f28c SetPixel
 0x1118f290 SetPixelV
 0x1118f294 Ellipse
 0x1118f298 Rectangle
 0x1118f29c SetROP2
 0x1118f2a0 MoveToEx
 0x1118f2a4 LineTo
 0x1118f2a8 GetStockObject
 0x1118f2ac CreatePen
 0x1118f2b0 CreateSolidBrush
 0x1118f2b4 GetTextExtentPointA
 0x1118f2b8 SetBkMode
 0x1118f2bc SetTextColor
 0x1118f2c0 GetMapMode
WINSPOOL.DRV
 0x1118faec DeletePrinter
 0x1118faf0 AddPrinterA
 0x1118faf4 EnumPrintersA
 0x1118faf8 None
 0x1118fafc None
 0x1118fb00 EnumJobsA
 0x1118fb04 EnumPrinterDriversA
 0x1118fb08 AbortPrinter
 0x1118fb0c StartPagePrinter
 0x1118fb10 WritePrinter
 0x1118fb14 ClosePrinter
 0x1118fb18 StartDocPrinterA
 0x1118fb1c EndPagePrinter
 0x1118fb20 EndDocPrinter
 0x1118fb24 OpenPrinterA
 0x1118fb28 GetPrinterA
 0x1118fb2c SetJobA
COMDLG32.dll
 0x1118f12c ChooseFontA
 0x1118f130 PageSetupDlgA
 0x1118f134 GetOpenFileNameA
 0x1118f138 GetSaveFileNameA
ADVAPI32.dll
 0x1118f000 EnumServicesStatusA
 0x1118f004 RegisterServiceCtrlHandlerA
 0x1118f008 RegisterEventSourceA
 0x1118f00c ReportEventA
 0x1118f010 DeregisterEventSource
 0x1118f014 RegCreateKeyA
 0x1118f018 SetTokenInformation
 0x1118f01c SetServiceStatus
 0x1118f020 StartServiceCtrlDispatcherA
 0x1118f024 LogonUserA
 0x1118f028 ControlService
 0x1118f02c StartServiceA
 0x1118f030 RegQueryInfoKeyW
 0x1118f034 CryptGetProvParam
 0x1118f038 CryptReleaseContext
 0x1118f03c AllocateLocallyUniqueId
 0x1118f040 FreeSid
 0x1118f044 GetSecurityDescriptorSacl
 0x1118f048 SetSecurityDescriptorSacl
 0x1118f04c LookupPrivilegeValueA
 0x1118f050 AdjustTokenPrivileges
 0x1118f054 QueryServiceConfigA
 0x1118f058 CreateProcessAsUserA
 0x1118f05c GetSecurityDescriptorDacl
 0x1118f060 InitializeSecurityDescriptor
 0x1118f064 SetSecurityDescriptorDacl
 0x1118f068 GetAclInformation
 0x1118f06c InitializeAcl
 0x1118f070 GetAce
 0x1118f074 AddAce
 0x1118f078 AddAccessAllowedAce
 0x1118f07c IsValidSid
 0x1118f080 GetLengthSid
 0x1118f084 CopySid
 0x1118f088 RegQueryInfoKeyA
 0x1118f08c RegDeleteKeyA
 0x1118f090 RegEnumKeyExA
 0x1118f094 RegEnumValueA
 0x1118f098 RegCreateKeyExA
 0x1118f09c RegSetValueExA
 0x1118f0a0 RegDeleteValueA
 0x1118f0a4 RegFlushKey
 0x1118f0a8 RegOpenKeyExA
 0x1118f0ac RegCloseKey
 0x1118f0b0 OpenSCManagerA
 0x1118f0b4 OpenServiceA
 0x1118f0b8 QueryServiceStatus
 0x1118f0bc CloseServiceHandle
 0x1118f0c0 GetUserNameA
 0x1118f0c4 LookupPrivilegeNameA
 0x1118f0c8 RegQueryValueExA
 0x1118f0cc GetTokenInformation
 0x1118f0d0 LookupAccountSidA
 0x1118f0d4 GetSidIdentifierAuthority
 0x1118f0d8 GetSidSubAuthorityCount
 0x1118f0dc GetSidSubAuthority
 0x1118f0e0 AllocateAndInitializeSid
 0x1118f0e4 EqualSid
 0x1118f0e8 RevertToSelf
 0x1118f0ec OpenProcessToken
 0x1118f0f0 ImpersonateLoggedOnUser
 0x1118f0f4 GetUserNameW
SHELL32.dll
 0x1118f6b4 ExtractIconExA
 0x1118f6b8 SHGetSpecialFolderPathA
 0x1118f6bc SHGetFileInfoA
 0x1118f6c0 SHGetMalloc
 0x1118f6c4 SHGetDesktopFolder
 0x1118f6c8 SHGetPathFromIDListA
 0x1118f6cc FindExecutableA
 0x1118f6d0 ExtractIconA
 0x1118f6d4 Shell_NotifyIconA
 0x1118f6d8 ShellExecuteA
ole32.dll
 0x1118fb88 CoUninitialize
 0x1118fb8c CoInitialize
 0x1118fb90 CoCreateInstance
 0x1118fb94 CreateStreamOnHGlobal
 0x1118fb98 StringFromGUID2
 0x1118fb9c ReleaseStgMedium
 0x1118fba0 OleDuplicateData
 0x1118fba4 CreateDataAdviseHolder
 0x1118fba8 CoTaskMemFree
 0x1118fbac CLSIDFromProgID
 0x1118fbb0 OleInitialize
 0x1118fbb4 OleUninitialize
 0x1118fbb8 CoTaskMemAlloc
 0x1118fbbc CoTaskMemRealloc
 0x1118fbc0 CoInitializeSecurity
 0x1118fbc4 OleCreateStaticFromData
 0x1118fbc8 CreateILockBytesOnHGlobal
 0x1118fbcc StgCreateDocfileOnILockBytes
 0x1118fbd0 OleSetContainedObject
 0x1118fbd4 CLSIDFromString
 0x1118fbd8 CoGetClassObject
 0x1118fbdc OleLockRunning
OLEAUT32.dll
 0x1118f658 LoadTypeLib
 0x1118f65c VariantCopy
 0x1118f660 OleLoadPicture
 0x1118f664 SysFreeString
 0x1118f668 SysAllocString
 0x1118f66c VariantClear
 0x1118f670 VariantInit
 0x1118f674 VariantChangeType
 0x1118f678 SysStringLen
 0x1118f67c SysAllocStringLen
 0x1118f680 VarUI4FromStr
 0x1118f684 OleCreateFontIndirect
 0x1118f688 LoadRegTypeLib
 0x1118f68c OleCreatePictureIndirect
 0x1118f690 SysStringByteLen
 0x1118f694 SafeArrayUnaccessData
 0x1118f698 SafeArrayAccessData
 0x1118f69c SafeArrayGetElemsize
 0x1118f6a0 SafeArrayGetUBound
 0x1118f6a4 SafeArrayGetLBound
 0x1118f6a8 SafeArrayGetDim
 0x1118f6ac SafeArrayCreate
NETAPI32.dll
 0x1118f64c NetApiBufferFree
 0x1118f650 NetUserEnum
WININET.dll
 0x1118fa94 InternetCrackUrlA

EAT(Export Address Table) Library

0x111584f0 _GetRawWMIStringW@16
0x11158360 _GetWMIStringW@16
0x11159d30 _IsAcerA@8
0x11030a50 _NSMClient32@8
0x11092090 _NSMFindClass@12
0x111e82ac br_close
0x111e82a8 br_open
0x111e829c br_poll
0x111e82a0 br_status


Similarity measure (PE file only) - Checking for service failure