| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Feb-12 16:06:13 |
| Detected languages |
English - United States
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to security software:
|
| Suspicious | The PE is possibly packed. |
Unusual section name found: .fptable
Unusual section name found: .C4D0 Unusual section name found: .C4D1 Section .C4D1 is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 36/71 (Scanned on 2026-04-02 15:53:12) |
AVG:
Win64:MalwareX-gen [Trj]
Antiy-AVL: Trojan/Win32.Agent Arcabit: Trojan.Generic.D4C1DF54 Avast: Win64:MalwareX-gen [Trj] BitDefender: Trojan.GenericKD.79814484 Bkav: W64.AIDetectMalware CAT-QuickHeal: Trojan.Agent CTX: dll.trojan.generic CrowdStrike: win/malicious_confidence_60% (D) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Emsisoft: Trojan.GenericKD.79814484 (B) Fortinet: W32/PossibleThreat GData: Trojan.GenericKD.79814484 Google: Detected Gridinsoft: Trojan.Heur!.03216022 K7AntiVirus: Trojan ( 7000001d1 ) K7GW: Trojan ( 7000001d1 ) Lionic: Trojan.Win32.Generic.4!c Malwarebytes: Malware.AI.4258957132 MaxSecure: Trojan.Malware.589679953.susgen McAfeeD: ti!689E7AB93D89 MicroWorld-eScan: Trojan.GenericKD.79814484 Paloalto: generic.ml Sangfor: Trojan.Win32.Agent.Vfpd SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win64.Dropper.rc Sophos: Mal/Generic-S Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score TrellixENS: Artemis!F575E779A093 TrendMicro-HouseCall: TROJ_GEN.R002H09CV26 VIPRE: Trojan.GenericKD.79814484 Varist: W64/ABTrojan.DKQX-5814 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x148 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 10 |
| TimeDateStamp | 2026-Feb-12 16:06:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1d0400 |
| SizeOfInitializedData | 0x4b8000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000950991 (Section: .C4D1) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x10e7000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetUnhandledExceptionFilter
TerminateProcess IsProcessorFeaturePresent CreateEventW IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead SearchPathA WriteConsoleW CreateFileW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW IsValidCodePage FindNextFileW FindFirstFileExW GetFileAttributesExW GetTimeZoneInformation LCMapStringW CompareStringW GetStdHandle SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleOutputCP ExitProcess GetFileType SetStdHandle GetCommandLineA FreeLibraryAndExitThread ExitThread HeapQueryInformation InterlockedFlushSList RtlVirtualUnwind RtlPcToFileHeader RtlUnwindEx GetOverlappedResult ReleaseMutex OpenMutexA CreateMutexA IsBadWritePtr GetStringTypeW FlsFree FlsSetValue FlsGetValue FlsAlloc TryEnterCriticalSection AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock QueryPerformanceFrequency OutputDebugStringW UnhandledExceptionFilter RtlLookupFunctionEntry RtlCaptureContext GetProfileIntA GetTickCount GetTempPathA VerifyVersionInfoA VerSetConditionMask GetWindowsDirectoryA FindResourceExW lstrcpyA GetCPInfo GetOEMCP GetUserDefaultUILanguage GetTempFileNameA SystemTimeToTzSpecificLocalTime GetFileTime GetFileSizeEx GetFileAttributesExA FileTimeToLocalFileTime GetVersionExA GlobalFindAtomA lstrcmpW GlobalDeleteAtom LoadLibraryExW EncodePointer lstrcmpiA DuplicateHandle GetVolumeInformationA WriteFile UnlockFile SetFilePointer SetEndOfFile LockFile GetFullPathNameA FlushFileBuffers FindFirstFileA FindClose GlobalAddAtomA SetThreadPriority CreateEventA WaitForSingleObject GlobalFlags CompareStringA LocalReAlloc LocalAlloc GlobalHandle GlobalReAlloc TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSection FileTimeToSystemTime GlobalGetAtomNameA lstrcmpA CopyFileA MulDiv LocalFree GlobalFree GlobalLock GlobalUnlock GlobalSize GlobalAlloc QueryActCtxW FindActCtxSectionStringW DeactivateActCtx ActivateActCtx CreateActCtxW LoadLibraryW GetModuleHandleExW InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection lstrcatA FindResourceA WinExec GetModuleFileNameW GetModuleFileNameA DisableThreadLibraryCalls GetSystemDirectoryW GetSystemDirectoryA GetSystemTime CreateProcessW CreateThread DeleteCriticalSection HeapSize DecodePointer OutputDebugStringA ReadFile GetFileSize GetFileAttributesA DeleteFileW DeleteFileA CreateFileA GetCurrentDirectoryA GetCommandLineW Thread32Next Thread32First CreateToolhelp32Snapshot GetModuleHandleW SetThreadContext GetThreadContext ResumeThread SuspendThread OpenThread GetCurrentThreadId GetCurrentProcessId Sleep HeapReAlloc HeapCreate CloseHandle VirtualQuery GetSystemInfo IsBadReadPtr RaiseException lstrlenA LoadLibraryA GetProcAddress GetModuleHandleA FreeLibrary VirtualFree VirtualProtect VirtualAlloc GetNativeSystemInfo FlushInstructionCache GetCurrentProcess GetProcessHeap HeapFree HeapAlloc SetLastError GetACP WideCharToMultiByte MultiByteToWideChar FormatMessageA FindResourceW SizeofResource LockResource LoadResource InitializeCriticalSectionEx GetLastError |
|---|---|
| USER32.dll |
IsRectEmpty
DrawFocusRect WindowFromPoint ReleaseCapture SetCapture GetNextDlgGroupItem LoadImageW TrackMouseEvent InvalidateRect KillTimer SetTimer DeleteMenu SetCursor ShowOwnedPopups MapDialogRect GetAsyncKeyState GetNextDlgTabItem EndDialog CreateDialogIndirectParamA OffsetRect SetRectEmpty CopyImage SystemParametersInfoA GetMenuItemInfoA DestroyMenu IntersectRect InflateRect PostQuitMessage LoadBitmapW SetMenuItemInfoA GetMenuCheckMarkDimensions SetMenuItemBitmaps EnableMenuItem CheckMenuItem GetMonitorInfoA MonitorFromWindow WinHelpA GetScrollInfo SetScrollInfo LoadIconW LoadIconA GetTopWindow GetClassLongPtrA GetClassLongA SetWindowLongPtrA GetWindowLongPtrA EqualRect CopyRect MapWindowPoints LoadImageA GetClientRect RemovePropA GetPropA SetPropA ShowScrollBar GetScrollRange SetScrollRange ScrollWindow RedrawWindow SetForegroundWindow GetForegroundWindow CopyIcon FrameRect DrawIcon UnionRect wsprintfA GetMenuStringA GetMenuState SetActiveWindow UpdateWindow TrackPopupMenu SetMenu GetMenu GetCapture IsIconic EndDeferWindowPos DeferWindowPos BeginDeferWindowPos UpdateLayeredWindow GetWindowPlacement DestroyWindow IsChild IsMenu MapVirtualKeyA GetKeyNameTextA SetLayeredWindowAttributes EnumDisplayMonitors OpenClipboard CloseClipboard SetClipboardData EmptyClipboard DrawStateA SetClassLongPtrA SetWindowRgn SetParent DrawEdge DrawFrameControl DrawIconEx GetIconInfo MessageBeep EnableScrollBar HideCaret InvertRect LoadCursorW SetCursorPos NotifyWinEvent CreatePopupMenu AdjustWindowRectEx GetSubMenu GetMenuItemID GetMenuItemCount InsertMenuA AppendMenuA RemoveMenu UnhookWindowsHookEx GetWindowTextA GetWindowTextLengthA SendMessageA EnableWindow IsWindowEnabled MessageBoxA GetWindowLongA GetParent GetWindowThreadProcessId GetLastActivePopup GetSystemMetrics GetDC ReleaseDC GetSysColor GetSysColorBrush LoadCursorA SetFocus SetScrollPos GetScrollPos GetWindow IsWindow ShowWindow MoveWindow SetWindowPos GetDlgItem CheckDlgButton SendDlgItemMessageA GetDlgCtrlID GetFocus SetWindowTextA SetWindowLongA IsDialogMessageA GetWindowRect ClientToScreen IsZoomed PtInRect GetDesktopWindow GetClassNameA RealChildWindowFromPoint GetMessageA TranslateMessage DispatchMessageA PeekMessageA IsWindowVisible GetActiveWindow GetKeyState ValidateRect GetCursorPos SetWindowsHookExA CallNextHookEx DestroyIcon CharUpperA DrawTextA DrawTextExA GrayStringA TabbedTextOutA GetWindowDC BeginPaint EndPaint ScreenToClient FillRect RegisterWindowMessageA GetMessagePos GetMessageTime PostMessageA DefWindowProcA CallWindowProcA MonitorFromPoint LoadAcceleratorsA TranslateAcceleratorA LoadMenuA LoadMenuW RegisterClassA GetClassInfoA GetSystemMenu BringWindowToTop GetMenuDefaultItem InsertMenuItemA UnpackDDElParam ReuseDDElParam GetComboBoxInfo PostThreadMessageA WaitMessage GetKeyboardLayout IsCharLowerA MapVirtualKeyExA GetKeyboardState ToAsciiEx LoadAcceleratorsW CreateAcceleratorTableA DestroyAcceleratorTable CopyAcceleratorTableA SetRect LockWindowUpdate SetMenuDefaultItem GetDoubleClickTime ModifyMenuA RegisterClipboardFormatA CharUpperBuffA IsClipboardFormatAvailable GetUpdateRect DrawMenuBar DefFrameProcA DefMDIChildProcA TranslateMDISysAccel SubtractRect CreateMenu GetWindowRgn DestroyCursor SetWindowPlacement GetClassInfoExA CreateWindowExA |
| GDI32.dll |
GetObjectType
GetPixel GetStockObject GetViewportExtEx GetWindowExtEx IntersectClipRect LineTo PtVisible RectVisible RestoreDC SaveDC SelectClipRgn ExtSelectClipRgn SelectObject SelectPalette SetBkColor SetBkMode SetMapMode SetLayout GetLayout SetPolyFillMode SetROP2 SetTextColor SetTextAlign GetObjectA MoveToEx TextOutA ExtTextOutA SetViewportExtEx SetViewportOrgEx SetWindowExtEx SetWindowOrgEx OffsetViewportOrgEx OffsetWindowOrgEx ScaleViewportExtEx ScaleWindowExtEx CombineRgn CreateFontIndirectA CreateRectRgnIndirect PatBlt GetClipBox DPtoLP GetTextExtentPoint32A GetTextMetricsA EnumFontFamiliesExA CreatePalette GetNearestPaletteIndex GetPaletteEntries GetSystemPaletteEntries RealizePalette GetBkColor CreateCompatibleBitmap CreateDIBitmap EnumFontFamiliesA GetTextCharsetInfo SetPixel StretchBlt CreateDIBSection SetDIBColorTable CreateEllipticRgn Ellipse GetTextColor CreatePolygonRgn Polygon Polyline CreateRoundRectRgn LPtoDP Rectangle GetRgnBox OffsetRgn RoundRect FillRgn FrameRgn GetBoundsRect PtInRegion ExtFloodFill SetPaletteEntries SetPixelV GetWindowOrgEx GetViewportOrgEx GetTextFaceA ExcludeClipRect Escape CreateSolidBrush CreateRectRgn CreatePatternBrush CreatePen CreateHatchBrush CreateCompatibleDC CreateBitmap BitBlt DeleteObject GetDeviceCaps CreateDCA CopyMetaFileA DeleteDC SetRectRgn |
| MSIMG32.dll |
TransparentBlt
AlphaBlend |
| WINSPOOL.DRV |
OpenPrinterA
ClosePrinter DocumentPropertiesA |
| ADVAPI32.dll |
InitializeSecurityDescriptor
RegEnumKeyExA RegDeleteValueA RegDeleteKeyA RegCreateKeyExA RegSetValueExA RegQueryValueExA RegOpenKeyExA RegCloseKey SetSecurityDescriptorDacl |
| SHELL32.dll |
SHAppBarMessage
SHBrowseForFolderA DragFinish DragQueryFileA SHGetDesktopFolder SHGetSpecialFolderLocation SHGetPathFromIDListA ShellExecuteA SHGetFileInfoA CommandLineToArgvW |
| SHLWAPI.dll |
StrFormatKBSizeA
PathRemoveFileSpecW PathStripToRootA PathIsUNCA SHSetValueA PathFindFileNameA PathFindExtensionA |
| UxTheme.dll |
IsThemeBackgroundPartiallyTransparent
DrawThemeText OpenThemeData GetThemePartSize CloseThemeData DrawThemeBackground GetThemeColor GetCurrentThemeName GetWindowTheme IsAppThemed DrawThemeParentBackground GetThemeSysColor |
| ole32.dll |
IsAccelerator
OleTranslateAccelerator OleDestroyMenuDescriptor OleCreateMenuDescriptor OleLockRunning RevokeDragDrop CoLockObjectExternal OleGetClipboard DoDragDrop CreateStreamOnHGlobal CoInitializeEx CoInitialize CoUninitialize CoDisconnectObject CoCreateInstance ReleaseStgMedium OleDuplicateData CoTaskMemFree CoTaskMemAlloc RegisterDragDrop |
| OLEAUT32.dll |
VariantChangeType
VariantCopy VariantClear VarBstrFromDate SysStringLen SysAllocStringLen SysAllocStringByteLen SysFreeString VariantTimeToSystemTime SystemTimeToVariantTime LoadTypeLib SysAllocString VariantInit |
| WS2_32.dll |
WSAIoctl
inet_ntop WSAStartup closesocket htons socket |
| imagehlp.dll |
MakeSureDirectoryPathExists
|
| HID.DLL |
HidD_GetAttributes
HidD_GetHidGuid HidD_FlushQueue |
| SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
SetupDiGetClassDevsA SetupDiDestroyDeviceInfoList SetupDiGetDeviceInterfaceDetailA |
| gdiplus.dll |
GdipCreateFromHDC
GdipSetInterpolationMode GdipDrawImageRectI GdipCreateBitmapFromHBITMAP GdipDrawImageI GdiplusShutdown GdipAlloc GdipFree GdiplusStartup GdipCloneImage GdipDisposeImage GdipGetImageGraphicsContext GdipDeleteGraphics GdipBitmapUnlockBits GdipBitmapLockBits GdipCreateBitmapFromScan0 GdipGetImageWidth GdipGetImageHeight GdipGetImagePixelFormat GdipGetImagePalette GdipGetImagePaletteSize GdipCreateBitmapFromStream |
| OLEACC.dll |
AccessibleObjectFromWindow
LresultFromObject CreateStdAccessibleObject |
| IMM32.dll |
ImmReleaseContext
ImmGetOpenStatus ImmGetContext |
| WINMM.dll |
PlaySoundA
|
| WinSCard.dll |
SCardDisconnect
SCardConnectA g_rgSCardT1Pci SCardListReadersA SCardEstablishContext SCardReconnect SCardTransmit SCardReleaseContext |
| WTSAPI32.dll |
WTSSendMessageW
|
| KERNEL32.dll (#2) |
SetUnhandledExceptionFilter
TerminateProcess IsProcessorFeaturePresent CreateEventW IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead SearchPathA WriteConsoleW CreateFileW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW IsValidCodePage FindNextFileW FindFirstFileExW GetFileAttributesExW GetTimeZoneInformation LCMapStringW CompareStringW GetStdHandle SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleOutputCP ExitProcess GetFileType SetStdHandle GetCommandLineA FreeLibraryAndExitThread ExitThread HeapQueryInformation InterlockedFlushSList RtlVirtualUnwind RtlPcToFileHeader RtlUnwindEx GetOverlappedResult ReleaseMutex OpenMutexA CreateMutexA IsBadWritePtr GetStringTypeW FlsFree FlsSetValue FlsGetValue FlsAlloc TryEnterCriticalSection AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock QueryPerformanceFrequency OutputDebugStringW UnhandledExceptionFilter RtlLookupFunctionEntry RtlCaptureContext GetProfileIntA GetTickCount GetTempPathA VerifyVersionInfoA VerSetConditionMask GetWindowsDirectoryA FindResourceExW lstrcpyA GetCPInfo GetOEMCP GetUserDefaultUILanguage GetTempFileNameA SystemTimeToTzSpecificLocalTime GetFileTime GetFileSizeEx GetFileAttributesExA FileTimeToLocalFileTime GetVersionExA GlobalFindAtomA lstrcmpW GlobalDeleteAtom LoadLibraryExW EncodePointer lstrcmpiA DuplicateHandle GetVolumeInformationA WriteFile UnlockFile SetFilePointer SetEndOfFile LockFile GetFullPathNameA FlushFileBuffers FindFirstFileA FindClose GlobalAddAtomA SetThreadPriority CreateEventA WaitForSingleObject GlobalFlags CompareStringA LocalReAlloc LocalAlloc GlobalHandle GlobalReAlloc TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSection FileTimeToSystemTime GlobalGetAtomNameA lstrcmpA CopyFileA MulDiv LocalFree GlobalFree GlobalLock GlobalUnlock GlobalSize GlobalAlloc QueryActCtxW FindActCtxSectionStringW DeactivateActCtx ActivateActCtx CreateActCtxW LoadLibraryW GetModuleHandleExW InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection lstrcatA FindResourceA WinExec GetModuleFileNameW GetModuleFileNameA DisableThreadLibraryCalls GetSystemDirectoryW GetSystemDirectoryA GetSystemTime CreateProcessW CreateThread DeleteCriticalSection HeapSize DecodePointer OutputDebugStringA ReadFile GetFileSize GetFileAttributesA DeleteFileW DeleteFileA CreateFileA GetCurrentDirectoryA GetCommandLineW Thread32Next Thread32First CreateToolhelp32Snapshot GetModuleHandleW SetThreadContext GetThreadContext ResumeThread SuspendThread OpenThread GetCurrentThreadId GetCurrentProcessId Sleep HeapReAlloc HeapCreate CloseHandle VirtualQuery GetSystemInfo IsBadReadPtr RaiseException lstrlenA LoadLibraryA GetProcAddress GetModuleHandleA FreeLibrary VirtualFree VirtualProtect VirtualAlloc GetNativeSystemInfo FlushInstructionCache GetCurrentProcess GetProcessHeap HeapFree HeapAlloc SetLastError GetACP WideCharToMultiByte MultiByteToWideChar FormatMessageA FindResourceW SizeofResource LockResource LoadResource InitializeCriticalSectionEx GetLastError |
| USER32.dll (#2) |
IsRectEmpty
DrawFocusRect WindowFromPoint ReleaseCapture SetCapture GetNextDlgGroupItem LoadImageW TrackMouseEvent InvalidateRect KillTimer SetTimer DeleteMenu SetCursor ShowOwnedPopups MapDialogRect GetAsyncKeyState GetNextDlgTabItem EndDialog CreateDialogIndirectParamA OffsetRect SetRectEmpty CopyImage SystemParametersInfoA GetMenuItemInfoA DestroyMenu IntersectRect InflateRect PostQuitMessage LoadBitmapW SetMenuItemInfoA GetMenuCheckMarkDimensions SetMenuItemBitmaps EnableMenuItem CheckMenuItem GetMonitorInfoA MonitorFromWindow WinHelpA GetScrollInfo SetScrollInfo LoadIconW LoadIconA GetTopWindow GetClassLongPtrA GetClassLongA SetWindowLongPtrA GetWindowLongPtrA EqualRect CopyRect MapWindowPoints LoadImageA GetClientRect RemovePropA GetPropA SetPropA ShowScrollBar GetScrollRange SetScrollRange ScrollWindow RedrawWindow SetForegroundWindow GetForegroundWindow CopyIcon FrameRect DrawIcon UnionRect wsprintfA GetMenuStringA GetMenuState SetActiveWindow UpdateWindow TrackPopupMenu SetMenu GetMenu GetCapture IsIconic EndDeferWindowPos DeferWindowPos BeginDeferWindowPos UpdateLayeredWindow GetWindowPlacement DestroyWindow IsChild IsMenu MapVirtualKeyA GetKeyNameTextA SetLayeredWindowAttributes EnumDisplayMonitors OpenClipboard CloseClipboard SetClipboardData EmptyClipboard DrawStateA SetClassLongPtrA SetWindowRgn SetParent DrawEdge DrawFrameControl DrawIconEx GetIconInfo MessageBeep EnableScrollBar HideCaret InvertRect LoadCursorW SetCursorPos NotifyWinEvent CreatePopupMenu AdjustWindowRectEx GetSubMenu GetMenuItemID GetMenuItemCount InsertMenuA AppendMenuA RemoveMenu UnhookWindowsHookEx GetWindowTextA GetWindowTextLengthA SendMessageA EnableWindow IsWindowEnabled MessageBoxA GetWindowLongA GetParent GetWindowThreadProcessId GetLastActivePopup GetSystemMetrics GetDC ReleaseDC GetSysColor GetSysColorBrush LoadCursorA SetFocus SetScrollPos GetScrollPos GetWindow IsWindow ShowWindow MoveWindow SetWindowPos GetDlgItem CheckDlgButton SendDlgItemMessageA GetDlgCtrlID GetFocus SetWindowTextA SetWindowLongA IsDialogMessageA GetWindowRect ClientToScreen IsZoomed PtInRect GetDesktopWindow GetClassNameA RealChildWindowFromPoint GetMessageA TranslateMessage DispatchMessageA PeekMessageA IsWindowVisible GetActiveWindow GetKeyState ValidateRect GetCursorPos SetWindowsHookExA CallNextHookEx DestroyIcon CharUpperA DrawTextA DrawTextExA GrayStringA TabbedTextOutA GetWindowDC BeginPaint EndPaint ScreenToClient FillRect RegisterWindowMessageA GetMessagePos GetMessageTime PostMessageA DefWindowProcA CallWindowProcA MonitorFromPoint LoadAcceleratorsA TranslateAcceleratorA LoadMenuA LoadMenuW RegisterClassA GetClassInfoA GetSystemMenu BringWindowToTop GetMenuDefaultItem InsertMenuItemA UnpackDDElParam ReuseDDElParam GetComboBoxInfo PostThreadMessageA WaitMessage GetKeyboardLayout IsCharLowerA MapVirtualKeyExA GetKeyboardState ToAsciiEx LoadAcceleratorsW CreateAcceleratorTableA DestroyAcceleratorTable CopyAcceleratorTableA SetRect LockWindowUpdate SetMenuDefaultItem GetDoubleClickTime ModifyMenuA RegisterClipboardFormatA CharUpperBuffA IsClipboardFormatAvailable GetUpdateRect DrawMenuBar DefFrameProcA DefMDIChildProcA TranslateMDISysAccel SubtractRect CreateMenu GetWindowRgn DestroyCursor SetWindowPlacement GetClassInfoExA CreateWindowExA |
| ADVAPI32.dll (#2) |
InitializeSecurityDescriptor
RegEnumKeyExA RegDeleteValueA RegDeleteKeyA RegCreateKeyExA RegSetValueExA RegQueryValueExA RegOpenKeyExA RegCloseKey SetSecurityDescriptorDacl |
| KERNEL32.dll (#3) |
SetUnhandledExceptionFilter
TerminateProcess IsProcessorFeaturePresent CreateEventW IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetSystemTimeAsFileTime InitializeSListHead SearchPathA WriteConsoleW CreateFileW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW IsValidCodePage FindNextFileW FindFirstFileExW GetFileAttributesExW GetTimeZoneInformation LCMapStringW CompareStringW GetStdHandle SetFilePointerEx ReadConsoleW GetConsoleMode GetConsoleOutputCP ExitProcess GetFileType SetStdHandle GetCommandLineA FreeLibraryAndExitThread ExitThread HeapQueryInformation InterlockedFlushSList RtlVirtualUnwind RtlPcToFileHeader RtlUnwindEx GetOverlappedResult ReleaseMutex OpenMutexA CreateMutexA IsBadWritePtr GetStringTypeW FlsFree FlsSetValue FlsGetValue FlsAlloc TryEnterCriticalSection AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock QueryPerformanceFrequency OutputDebugStringW UnhandledExceptionFilter RtlLookupFunctionEntry RtlCaptureContext GetProfileIntA GetTickCount GetTempPathA VerifyVersionInfoA VerSetConditionMask GetWindowsDirectoryA FindResourceExW lstrcpyA GetCPInfo GetOEMCP GetUserDefaultUILanguage GetTempFileNameA SystemTimeToTzSpecificLocalTime GetFileTime GetFileSizeEx GetFileAttributesExA FileTimeToLocalFileTime GetVersionExA GlobalFindAtomA lstrcmpW GlobalDeleteAtom LoadLibraryExW EncodePointer lstrcmpiA DuplicateHandle GetVolumeInformationA WriteFile UnlockFile SetFilePointer SetEndOfFile LockFile GetFullPathNameA FlushFileBuffers FindFirstFileA FindClose GlobalAddAtomA SetThreadPriority CreateEventA WaitForSingleObject GlobalFlags CompareStringA LocalReAlloc LocalAlloc GlobalHandle GlobalReAlloc TlsFree TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSection FileTimeToSystemTime GlobalGetAtomNameA lstrcmpA CopyFileA MulDiv LocalFree GlobalFree GlobalLock GlobalUnlock GlobalSize GlobalAlloc QueryActCtxW FindActCtxSectionStringW DeactivateActCtx ActivateActCtx CreateActCtxW LoadLibraryW GetModuleHandleExW InitializeCriticalSectionAndSpinCount LeaveCriticalSection EnterCriticalSection lstrcatA FindResourceA WinExec GetModuleFileNameW GetModuleFileNameA DisableThreadLibraryCalls GetSystemDirectoryW GetSystemDirectoryA GetSystemTime CreateProcessW CreateThread DeleteCriticalSection HeapSize DecodePointer OutputDebugStringA ReadFile GetFileSize GetFileAttributesA DeleteFileW DeleteFileA CreateFileA GetCurrentDirectoryA GetCommandLineW Thread32Next Thread32First CreateToolhelp32Snapshot GetModuleHandleW SetThreadContext GetThreadContext ResumeThread SuspendThread OpenThread GetCurrentThreadId GetCurrentProcessId Sleep HeapReAlloc HeapCreate CloseHandle VirtualQuery GetSystemInfo IsBadReadPtr RaiseException lstrlenA LoadLibraryA GetProcAddress GetModuleHandleA FreeLibrary VirtualFree VirtualProtect VirtualAlloc GetNativeSystemInfo FlushInstructionCache GetCurrentProcess GetProcessHeap HeapFree HeapAlloc SetLastError GetACP WideCharToMultiByte MultiByteToWideChar FormatMessageA FindResourceW SizeofResource LockResource LoadResource InitializeCriticalSectionEx GetLastError |
| ADVAPI32.dll (#3) |
InitializeSecurityDescriptor
RegEnumKeyExA RegDeleteValueA RegDeleteKeyA RegCreateKeyExA RegSetValueExA RegQueryValueExA RegOpenKeyExA RegCloseKey SetSecurityDescriptorDacl |
| PYG64.dll |
LHOOK
|
| Ordinal | 17 |
|---|---|
| Address | 0x1cc90 |
| Ordinal | 18 |
|---|---|
| Address | 0x1cc96 |
| Ordinal | 19 |
|---|---|
| Address | 0x1cc9c |
| Ordinal | 20 |
|---|---|
| Address | 0x1cca2 |
| Ordinal | 21 |
|---|---|
| Address | 0x1cca8 |
| Ordinal | 22 |
|---|---|
| Address | 0x1ccae |
| Ordinal | 23 |
|---|---|
| Address | 0x1ccb4 |
| Ordinal | 24 |
|---|---|
| Address | 0x1ccba |
| Ordinal | 25 |
|---|---|
| Address | 0x1ccc0 |
| Ordinal | 26 |
|---|---|
| Address | 0x1ccc6 |
| Ordinal | 27 |
|---|---|
| Address | 0x1cccc |
| Ordinal | 28 |
|---|---|
| Address | 0x1ccd2 |
| Ordinal | 29 |
|---|---|
| Address | 0x1ccd8 |
| Ordinal | 30 |
|---|---|
| Address | 0x1ccde |
| Ordinal | 31 |
|---|---|
| Address | 0x1cce4 |
| Ordinal | 32 |
|---|---|
| Address | 0x1ccea |
| Ordinal | 33 |
|---|---|
| Address | 0x1ccf0 |
| Ordinal | 34 |
|---|---|
| Address | 0x1ccf6 |
| Ordinal | 35 |
|---|---|
| Address | 0x1ccfc |
| Ordinal | 36 |
|---|---|
| Address | 0x1cd02 |
| Ordinal | 37 |
|---|---|
| Address | 0x1cd08 |
| Ordinal | 38 |
|---|---|
| Address | 0x1cd0e |
| Ordinal | 39 |
|---|---|
| Address | 0x1cd14 |
| Ordinal | 40 |
|---|---|
| Address | 0x1cd1a |
| Ordinal | 41 |
|---|---|
| Address | 0x1cd20 |
| Ordinal | 42 |
|---|---|
| Address | 0x1cd26 |
| Ordinal | 43 |
|---|---|
| Address | 0x1cd2c |
| Ordinal | 44 |
|---|---|
| Address | 0x1cd32 |
| Ordinal | 45 |
|---|---|
| Address | 0x1cd38 |
| Ordinal | 46 |
|---|---|
| Address | 0x1cd3e |
| Ordinal | 47 |
|---|---|
| Address | 0x1cd44 |
| Ordinal | 48 |
|---|---|
| Address | 0x1cd4a |
| Ordinal | 49 |
|---|---|
| Address | 0x1cd50 |
| Ordinal | 50 |
|---|---|
| Address | 0x1cd56 |
| Ordinal | 51 |
|---|---|
| Address | 0x1cd5c |
| Ordinal | 52 |
|---|---|
| Address | 0x1cd62 |
| Ordinal | 53 |
|---|---|
| Address | 0x1cd68 |
| Ordinal | 54 |
|---|---|
| Address | 0x1cd6e |
| Ordinal | 55 |
|---|---|
| Address | 0x1cd74 |
| Ordinal | 56 |
|---|---|
| Address | 0x1cd7a |
| Ordinal | 57 |
|---|---|
| Address | 0x1cd80 |
| Ordinal | 58 |
|---|---|
| Address | 0x1cd86 |
| Ordinal | 59 |
|---|---|
| Address | 0x1cd8c |
| Ordinal | 60 |
|---|---|
| Address | 0x1cd92 |
| Ordinal | 61 |
|---|---|
| Address | 0x1cd98 |
| Ordinal | 62 |
|---|---|
| Address | 0x1cd9e |
| Ordinal | 63 |
|---|---|
| Address | 0x1cda4 |
| Ordinal | 64 |
|---|---|
| Address | 0x1cdaa |
| Ordinal | 65 |
|---|---|
| Address | 0x1cdb0 |
| Ordinal | 66 |
|---|---|
| Address | 0x1cdb6 |
| Ordinal | 67 |
|---|---|
| Address | 0x1cdbc |
| Ordinal | 68 |
|---|---|
| Address | 0x1cdc2 |
| Ordinal | 69 |
|---|---|
| Address | 0x1cdc8 |
| Ordinal | 70 |
|---|---|
| Address | 0x1cdce |
| Ordinal | 71 |
|---|---|
| Address | 0x1cdd4 |
| Ordinal | 72 |
|---|---|
| Address | 0x1cdda |
| Ordinal | 73 |
|---|---|
| Address | 0x1cde0 |
| Ordinal | 74 |
|---|---|
| Address | 0x1cde6 |
| Ordinal | 75 |
|---|---|
| Address | 0x1cdec |
| Ordinal | 76 |
|---|---|
| Address | 0x1cdf2 |
| Ordinal | 77 |
|---|---|
| Address | 0x1cdf8 |
| Ordinal | 78 |
|---|---|
| Address | 0x1cdfe |
| Ordinal | 79 |
|---|---|
| Address | 0x1ce04 |
| Ordinal | 80 |
|---|---|
| Address | 0x1ce0a |
| Ordinal | 81 |
|---|---|
| Address | 0x1ce10 |
| Ordinal | 82 |
|---|---|
| Address | 0x1ce16 |
| Ordinal | 83 |
|---|---|
| Address | 0x1ce1c |
| Ordinal | 84 |
|---|---|
| Address | 0x1ce22 |
| Ordinal | 85 |
|---|---|
| Address | 0x1ce28 |
| Ordinal | 86 |
|---|---|
| Address | 0x1ce2e |
| Ordinal | 87 |
|---|---|
| Address | 0x1ce34 |
| Ordinal | 88 |
|---|---|
| Address | 0x1ce3a |
| Ordinal | 89 |
|---|---|
| Address | 0x1ce40 |
| Ordinal | 90 |
|---|---|
| Address | 0x1ce46 |
| Ordinal | 91 |
|---|---|
| Address | 0x1ce4c |
| Ordinal | 92 |
|---|---|
| Address | 0x1ce52 |
| Ordinal | 93 |
|---|---|
| Address | 0x1ce58 |
| Ordinal | 94 |
|---|---|
| Address | 0x1ce5e |
| Ordinal | 95 |
|---|---|
| Address | 0x1ce64 |
| Ordinal | 96 |
|---|---|
| Address | 0x1ce6a |
| Ordinal | 97 |
|---|---|
| Address | 0x1ce70 |
| Ordinal | 98 |
|---|---|
| Address | 0x1ce76 |
| Ordinal | 99 |
|---|---|
| Address | 0x1ce7c |
| Ordinal | 100 |
|---|---|
| Address | 0x1ce82 |
| Ordinal | 101 |
|---|---|
| Address | 0x1ce88 |
| Ordinal | 102 |
|---|---|
| Address | 0x1ce8e |
| Ordinal | 103 |
|---|---|
| Address | 0x1ce94 |
| Ordinal | 104 |
|---|---|
| Address | 0x1ce9a |
| Ordinal | 105 |
|---|---|
| Address | 0x1cea0 |
| Ordinal | 106 |
|---|---|
| Address | 0x1cea6 |
| Ordinal | 107 |
|---|---|
| Address | 0x1ceac |
| Ordinal | 108 |
|---|---|
| Address | 0x1ceb2 |
| Ordinal | 109 |
|---|---|
| Address | 0x1ceb8 |
| Ordinal | 110 |
|---|---|
| Address | 0x1cebe |
| Ordinal | 111 |
|---|---|
| Address | 0x1cec4 |
| Ordinal | 112 |
|---|---|
| Address | 0x1ceca |
| Ordinal | 113 |
|---|---|
| Address | 0x1ced0 |
| Ordinal | 114 |
|---|---|
| Address | 0x1ced6 |
| Ordinal | 115 |
|---|---|
| Address | 0x1cedc |
| Ordinal | 116 |
|---|---|
| Address | 0x1cee2 |
| Ordinal | 117 |
|---|---|
| Address | 0x1cee8 |
| Ordinal | 118 |
|---|---|
| Address | 0x1ceee |
| Ordinal | 119 |
|---|---|
| Address | 0x1cef4 |
| Ordinal | 120 |
|---|---|
| Address | 0x1cefa |
| Ordinal | 121 |
|---|---|
| Address | 0x1cf00 |
| Ordinal | 122 |
|---|---|
| Address | 0x1cf06 |
| Ordinal | 123 |
|---|---|
| Address | 0x1cf0c |
| Ordinal | 124 |
|---|---|
| Address | 0x1cf12 |
| Ordinal | 125 |
|---|---|
| Address | 0x1cf18 |
| Ordinal | 126 |
|---|---|
| Address | 0x1cf1e |
| Ordinal | 127 |
|---|---|
| Address | 0x1cf24 |
| Ordinal | 128 |
|---|---|
| Address | 0x1cf2a |
| Ordinal | 129 |
|---|---|
| Address | 0x1cf30 |
| Ordinal | 130 |
|---|---|
| Address | 0x1cf36 |
| Ordinal | 131 |
|---|---|
| Address | 0x1cf3c |
| Ordinal | 132 |
|---|---|
| Address | 0x1cf42 |
| Ordinal | 133 |
|---|---|
| Address | 0x1cf48 |
| Ordinal | 134 |
|---|---|
| Address | 0x1cf4e |
| Ordinal | 135 |
|---|---|
| Address | 0x1cf54 |
| Ordinal | 136 |
|---|---|
| Address | 0x1cf5a |
| Ordinal | 137 |
|---|---|
| Address | 0x1cf60 |
| Ordinal | 138 |
|---|---|
| Address | 0x1cf66 |
| Ordinal | 139 |
|---|---|
| Address | 0x1cf6c |
| Ordinal | 140 |
|---|---|
| Address | 0x1cf72 |
| Ordinal | 141 |
|---|---|
| Address | 0x153d0 |
| Ordinal | 142 |
|---|---|
| Address | 0x1cf78 |
| Ordinal | 1001 |
|---|---|
| Address | 0x1cf80 |
| Ordinal | 1002 |
|---|---|
| Address | 0x1cf86 |
| Ordinal | 1003 |
|---|---|
| Address | 0x1cf8c |
| Ordinal | 1004 |
|---|---|
| Address | 0x1cf92 |
| Ordinal | 1005 |
|---|---|
| Address | 0x1cf98 |
| Ordinal | 1006 |
|---|---|
| Address | 0x1cf9e |
| Ordinal | 1007 |
|---|---|
| Address | 0x1cfa4 |
| Ordinal | 1008 |
|---|---|
| Address | 0x1cfaa |
| Ordinal | 1009 |
|---|---|
| Address | 0x1cfb0 |
| Ordinal | 1010 |
|---|---|
| Address | 0x1cfb6 |
| Ordinal | 1011 |
|---|---|
| Address | 0x1cfbc |
| Ordinal | 1012 |
|---|---|
| Address | 0x1cfc2 |
| Ordinal | 1013 |
|---|---|
| Address | 0x1cfc8 |
| Ordinal | 1014 |
|---|---|
| Address | 0x1cfce |
| Ordinal | 1015 |
|---|---|
| Address | 0x1cfd4 |
| Ordinal | 1016 |
|---|---|
| Address | 0x1cfda |
| Ordinal | 1017 |
|---|---|
| Address | 0x1cfe0 |
| Ordinal | 2001 |
|---|---|
| Address | 0x1cb50 |
| Ordinal | 2002 |
|---|---|
| Address | 0x1cb56 |
| Ordinal | 2003 |
|---|---|
| Address | 0x1cb5c |
| Ordinal | 2004 |
|---|---|
| Address | 0x1cb62 |
| Ordinal | 2005 |
|---|---|
| Address | 0x1cb68 |
| Ordinal | 2006 |
|---|---|
| Address | 0x1cb6e |
| Ordinal | 2007 |
|---|---|
| Address | 0x1cb74 |
| Ordinal | 2008 |
|---|---|
| Address | 0x1cb7a |
| Ordinal | 2009 |
|---|---|
| Address | 0x1cb80 |
| Ordinal | 2010 |
|---|---|
| Address | 0x1cb86 |
| Ordinal | 2011 |
|---|---|
| Address | 0x1cb8c |
| Ordinal | 2012 |
|---|---|
| Address | 0x1cb92 |
| Ordinal | 2013 |
|---|---|
| Address | 0x1cb98 |
| Ordinal | 2014 |
|---|---|
| Address | 0x1cb9e |
| Ordinal | 2015 |
|---|---|
| Address | 0x1cba4 |
| Ordinal | 2016 |
|---|---|
| Address | 0x1cbaa |
| Ordinal | 2017 |
|---|---|
| Address | 0x1cbb0 |
| Ordinal | 2018 |
|---|---|
| Address | 0x1cbb6 |
| Ordinal | 2019 |
|---|---|
| Address | 0x1cbbc |
| Ordinal | 2020 |
|---|---|
| Address | 0x1cbc2 |
| Ordinal | 2021 |
|---|---|
| Address | 0x1cbc8 |
| Ordinal | 2022 |
|---|---|
| Address | 0x1cbce |
| Ordinal | 2023 |
|---|---|
| Address | 0x1cbd4 |
| Ordinal | 2024 |
|---|---|
| Address | 0x1cbda |
| Ordinal | 2025 |
|---|---|
| Address | 0x1cbe0 |
| Ordinal | 2026 |
|---|---|
| Address | 0x1cbe6 |
| Ordinal | 2027 |
|---|---|
| Address | 0x1cbec |
| Ordinal | 2028 |
|---|---|
| Address | 0x1cbf2 |
| Ordinal | 2029 |
|---|---|
| Address | 0x1cbf8 |
| Ordinal | 2030 |
|---|---|
| Address | 0x1cbfe |
| Ordinal | 2031 |
|---|---|
| Address | 0x1cc04 |
| Ordinal | 2032 |
|---|---|
| Address | 0x1cc0a |
| Ordinal | 2033 |
|---|---|
| Address | 0x1cc10 |
| Ordinal | 2034 |
|---|---|
| Address | 0x1cc16 |
| Ordinal | 2035 |
|---|---|
| Address | 0x1cc1c |
| Ordinal | 2036 |
|---|---|
| Address | 0x1cc22 |
| Ordinal | 2037 |
|---|---|
| Address | 0x1cc28 |
| Ordinal | 2038 |
|---|---|
| Address | 0x1cc2e |
| Ordinal | 2039 |
|---|---|
| Address | 0x1cc34 |
| Ordinal | 2040 |
|---|---|
| Address | 0x1cc3a |
| Ordinal | 2041 |
|---|---|
| Address | 0x1cc40 |
| Ordinal | 2042 |
|---|---|
| Address | 0x1cc46 |
| Ordinal | 2043 |
|---|---|
| Address | 0x1cc4c |
| Ordinal | 2044 |
|---|---|
| Address | 0x1cc52 |
| Ordinal | 2045 |
|---|---|
| Address | 0x1cc58 |
| Ordinal | 2046 |
|---|---|
| Address | 0x1cc5e |
| Ordinal | 2047 |
|---|---|
| Address | 0x1cc64 |
| Ordinal | 2048 |
|---|---|
| Address | 0x1cc6a |
| Ordinal | 2049 |
|---|---|
| Address | 0x1cc70 |
| Ordinal | 2050 |
|---|---|
| Address | 0x1cc76 |
| Ordinal | 2051 |
|---|---|
| Address | 0x1cc7c |
| Ordinal | 2052 |
|---|---|
| Address | 0x1cc82 |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18025f488 |
| XOR Key | 0x95acdfce |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33140) | 19 |
| Unmarked objects (#2) | 1 |
| Imports (2207) | 4 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 7 |
| Imports (VS2008 SP1 build 30729) | 2 |
| C objects (33140) | 41 |
| C++ objects (33140) | 232 |
| C objects (CVTCIL) (33140) | 1 |
| Imports (33140) | 39 |
| Total imports | 887 |
| C objects (30034) | 17 |
| ASM objects (30034) | 11 |
| C++ objects (30034) | 386 |
| C++ objects (30157) | 10 |
| ASM objects (30157) | 3 |
| Exports (30157) | 1 |
| Resource objects (30157) | 1 |
| 151 | 1 |
| Linker (30157) | 1 |
No comments yet.