Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 0549122a1fd6ecb12cc08cccbdd21c45
SHA1SUM : f630c82bcf99947d122652665710446113c6c3f3
File format not recognized
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: A0A0A0A0 Sat Apr 19 13:42:24 1919
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 00069000
Code Base: 0003F000 Size: 00000000
Data Base: 0000000C Size: 000019B0
Entry Point: 0003FA39 (file offset 0000F439)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: .data RVA: 00001000 Offset: 00000200 Size: 00000000 Flags: C0000020 (CRW)
2: .pdata RVA: 00030000 Offset: 00000200 Size: 0000E60A Flags: C0000020 (CRW)
3: .ex_cod RVA: 0003F000 Offset: 0000EA00 Size: 00024554 Flags: E0000060 (CDERW)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: KERNEL32.dll
Addr: 0003F234 hint: 888(0378) Name: VirtualFree
Addr: 0003F238 hint: 885(0375) Name: VirtualAlloc
Addr: 0003F23C hint: 408(0198) Name: GetProcAddress
Addr: 0003F240 hint: 585(0249) Name: LoadLibraryExA
Addr: 0003F244 hint: 375(0177) Name: GetModuleHandleA
Addr: 0003F248 hint: 891(037B) Name: VirtualProtect
Addr: 0003F24C hint: 175(00AF) Name: ExitProcess
Addr: 0003F250 hint: 373(0175) Name: GetModuleFileNameA
Addr: 0003F254 hint: 584(0248) Name: LoadLibraryA

DLL: USER32.dll
Addr: 0003F25C hint: 725(02D5) Name: wsprintfA
Addr: 0003F260 hint: 478(01DE) Name: MessageBoxA

.data
.pdata
.ex_cod
!N"V
/:<A;
!F=2
V-X*
e(L[
HrM2-
OqP^
]bUY
W@4GSJ
ziCs
SbW)
H6V.
HyP,
?@Ge
s\P9
23vZ
i7A]s,
mvmjW
]T;V
[joXAt3
lwq8
G(F#
OsrE
\YlT
YS.gw+1
)/k7
,x_/Z
t8\&
X>)$
4/IE
mAjM
c_[o
p5TI@
-ZlM{
vJmw
|sN$=mO
E*}o
) :>pY
jxoT
*dz!5
rhWcN^
Df6c@
;'#?
>Z@%
znoW
U(o)<F
LeS6z
&H*i
D~$BL
Qb^,LRd
Lqok
YS3+U
}X^z
gv$Y2
W_a?
"K*HaR
G}-K
4\4>
M*RD~
Q&{zVE
;8;?4
|uS55
.qZ(
s`z(DX
low)
8[OB&*
~Q1dl}q
vN#N
K'vWe&
C$Ae
A(Db
@#zN*
rYH2"#
$Hj[^
U#<
1-cu
Os&
\HSX4;u
,^gK
#%I|7H
Me?vO,
}:ezr
qu&@
=Bg"Ku
T9s0
~d}Q
-j*I
`=/1
!yJ^.7
kjMW
>wjbE
R]t#3
AX:)
9rIH
W8T>
$z7]>
/YX\
3.IW
mm$C
4{mh
AoEW6>
sT'@
E@#wf
(@<)
,<l5oj
p ^d
o#GHy/
dqW
.S1u
4| 0)
8$S?
y.Ctk}
P9fZ+/
DI.Vk
]F'>"]
oB[z
v>{!.D
#\Yp
*z{z
`4zE
X`;*
w+'o
9\FlFakNJ
`EC0o
,8kR
T8azd
H m7[
~OV%
GANW
O$xW
>fjQ
diZ1nJ
^0n,
$mgGIc
]$FStr
|>YE
BG/k
,[]E
8]cS2
BO1Y
i`?a
;VSF$
i+?XQ
EIW];
Q[ J'DQcY
OM"&h7
EG-ln
@10/R
S.F,
Spa?t
rU-c
P5L@n
R]laN
[n#y
!o`+
: v;)
\y(a
)0mOYv
L~/[
VB@l
'`~R
r8<b/
K#1t\)
!_<>
sF<}
p^eC3
b&AD
3c%il
CK`j
?Q(Dz^
"A tq
ECw"
<%:q
Ujj-
} A?
{Srbl
?MGYE4
%7}+j<
pv?Uq
5p)2i)
lXJR_
dPW;+
%Ad|
{sLt3
h H,#B
",&aX
x)A*&
i's=z]
nk3i
V:XZ
sVDzT
H(WGO
.@6ij
i|}Uuv
)E-t
bEZc
_*C@{Y
bA"~|
5-E%
3|(s*O
NTS]l
_mQ\x
W'-/B
H-!IIA_
*XKT
>'O'L3
OpfX
isO{
zWmiV
L*8B
z~),
"1dJ
oE%QV
G<X+N
f0)(
0 O)
LundD
{gL|
VdG#H%H
^ic_
Huv<7
DH1D
2&:_
>gJQh
Jq06
[};<o
$,NZ
lX 2
\>enT
^hfl
R7:v
}MV^|
!)2DN
"LEej
ZHb#h
5m`s
xi$y
}dU\;
*U=G
|gcX
pC'RK
hzZ%
'jl,u
F( -
:fs1
,OJS+e
vLuC
B6}G
SF,fo
`9_4HE
p]B
GZ")
|}PS$j
O"kFaY_
XKp9
QcA!Ji
PL1:
78"+
af7T!
-SS~
9:K[
`O^5
8`+_
l/%b[
B`~R
!MTHk
V!+0
2Y93B
!x(6
Xg=]
dK-R
X?@ .
eHF=
M9{&
k`8J|b
d&?T
H+2<&cK3-"
-k4c{P
)Nru
XGO b
oOh5
-tq.
(5jb
;-t[]
pAM<
Mx+V'%
]lD'
%@Pc[V
:%kd
mX)ch
Z,:5
;e,$?
S-82
&5bN
A2h|v8
Bo*A
uLt>
D}O6
=&y>i
~K(2E
=jr1
zik"
TYM J(
F<3/
zzd-
<iq\U%
5m90
;d{c
d\y:
lB~
+9DfA@
Z&S%_h
<")m*
)$~O
Tci:
=^%G
XEbSNx
\'c#
6dIg<
K\o\
B}4|
\&Nj
.e@h5[
bD1n
}KJKUd
#7KA
PG{(
/*_0Z
>vQv
c)OI,
du!_
yOu\
>9CWf
x[cR
?$vV}
;.yw
n~8E
F&rz
@ L(
7V]_
?/]Q
H5?#
fncB
Iy;[
jj.m
u^,P
Iu?
HG?x
]$%:e
:(/pk
4s?5
pgr!
a'NL
<(2o
dE)1j
yq\*
O`"B
;1]\
FIxZ/$Ie_>
QB{Ut&
53)x
*,tS
$t'~
OK/S
]#5tC
'y}Y
FiVsR
4gU[MU
O2T)3E
,a0u
77=X
.+vZ
IW$P`
RI:_
Np ;
CAi_
9gl7
CQoo
)jDA
+W%vu
; 22
=g ]
]vXf$
,jE@
>(i
+Sb*
2/zM'a4_|
(N@=
Bv<5
<.S_
a9+A~
I!{^
%~sae
^rPo
-TWY
o);D0Y
#$k%rE
A(mBQn
L 6Sa
"7 n^
qOCp
8SDl
PixL
Y4Fz
1yi@
^O.9
Frm'X
,;#g
!5E+)
)-zi
z~y_e
#3_c
E@)
TqAi
cxv[:t
fFvt
5DC"
+IhL
TIW'
l09C
r4rw
abB}
*1mm
H|V_
0v?[
}\z;
QX@1
k(98q
SbMFTi=
*\S)3uNv
J6r0
U$Tl
sCllD
Plsg'Q
GBsQQ
_=TI^
C?;^
\tC9
)7Dm
~8%%
Aubll
M y_
aS?
9O-.
DKQd
nXVS
G<.8r
2A)I
cQe.^
Ibc2
1mVh
!w0^
ew{-
w$rF
*r [
W7abm
t.BP
s&I#<@
5!,E
gn8gBY
)A,so
o^f|~H"
76T)
Z-0\
/H(s
`q7*
*j.t$a
.E)G
Jg>5X
19u*
1'_E
J;',
Y+ce
G6>
]~x`/{
ec<T
;`Z]
&&*m
KZ,:
c[-U
qp"{
b O!
){@Z
u?z\O
bt*d{5
cjf8
oK>y!@)
.DI{
bdL/
3%Kra
**@bk
[PY*
\j$_Y
>:0[
S>}A
1#[K
TT0{
= ,X
sZ`<
.8P1
6<L)
o{1g.>Dw|
R&jA
ie8Ct)6co*b
|/f[
D CV*N
N9Mm{
{qAq
Q;y^
|;jK
OYq5
dvb!8
5j b5
rXA|0
=&.)
%c~=
&>mgULR
<N2l U
Q|5,
:y|r)
x%M8ve
Y?UN
77m6
B./y8
!y05
3U!#
<e7:
T>vg
f3Ty
1 qC
B(O@A
E."Y
gjPhFWM
8BP1
&: F(
OILx
<7M6
M]E=d
#aRQ
K8bq
(Q[vR
\{\N
IRAsw
;v KV?
>3M9
b<1<93=
W,n'a)s
UI 0
.0]UZ
b.!7
LN@9|
PImDA
F~5z
Kq'2
dL'Yf
OY>}
1ML'p)Lj
AoQIJ
OBoUe
(ut%2
LDye
WqS1
I Q=
]Mp<
i.2q
Nc%|I
8oN |'L
vV *_1
b 8j
E6h+
izZm
Io572~
?X`C
[eZ9
xY8i
6^s:fh
w3Q.
%DU/
)txf7
Cx-Y
ay'>C
^Z^Q
z$\Pv%}/
fFHm
ld3I
6Bjb
9"v>
kxw$
tf&~
3Zz/q2
zpwl
$:YQ
8 yv
}Y)%
"Z^u
F{"kBo
1mEa0
Oj6bq
d5@&
A=s_
e$K5k&
!4R^# 6
`swC q?
f/'?cz
m>/h
-S8R
nUc]
_z//>b
:F<)
fF[<n
yDl^
:_S8$a
WXa!E]5
C_4Fs
JjIP
Kb.@
3y+Wk>
T]h;
MujgY
XV'U>O
fz\/'`{I
3D$ZmL
:{$A
Y%SC
.o:9
|X^Yi
MI^=83
J_\A3
.Q\TW
{Vp{
'b4PJv
^tQWj
B:3y
EM*+qX
FoS4
'iVR
iP%B
.cbr
Zpl9
3Mp(~
a:sjlc,
^0Ee(
Yf*r
s4JqPHE
q\:a`d
uk?v
anT:;jqf
P#j@
4Wt25
|U'K
TG,P
:pA&q$u
Sei>L?<
K Wg
zr6,
9j"w
OS"d
3T= _Y+
ty4y
.m\ae
4$?2
dMow>/
u6]`D2
S]""Ds
slH_s
ZR+u
tMFD
IM5u=
SmC'(
kg{ ;
K/iU
g8oK
4{7"gP
+k rW
zoza
5@84
bBni\
59paS
P=r%
[g\@
8^d^
Du.^
c&y-Q
a_4)
_]<T
._kl
0_*B
s/){
q`<7j
7/1E
|u^(
9,c_
Cm,/
`X@*
V%~S
,65T
dTrT
,`/e
eiVr%d|J
{(gx
Flnq
Q) WE
]OJ6
8RPY
nCTZD
c5&f
)f*IC
<M`oe
==|elM
5mR?
l%H<
\}Yy
O3_:`
[``Ttb@
,&(o
D!v+
L]tw
f>D5
,-D&
ja,d
4m-]
8tP^N
,mpJ
gG!L
G })E@M
-(Hrr#
7?qr
TWDl
,(!r
QPfx
il^L
aEVH
Z,ll
Y8*@
Unexpected relocation type: *pw = 0x%04x *pdw = 0x%08x
Error bad relocation pointer: *pdw = 0x%08x
The %hs file is
linked to missing export %hs:%hs.
The %hs file is
linked to missing export %hs:0x%04x.
A required .DLL file, %hs, was not found.
Error allocating memory!
)+c6
oleaut32.dll
CorBindToRuntimeEx
mscoree.dll
CoUninitialize
CoInitialize
ole32.dll
VirtualFree
VirtualAlloc
GetProcAddress
LoadLibraryExA
GetModuleHandleA
VirtualProtect
ExitProcess
GetModuleFileNameA
LoadLibraryA
KERNEL32.dll
wsprintfA
MessageBoxA
USER32.dll
>#g/
1S;q
Z~'V
G;|$
M$+E
t-GG
;M(r
SVWP
RRRRRh
@p9E
@p9E
Pj@j
Pj@j
HP9M
Pj@j
QSVWPQd
_^[]
HSVW
,SVWj
BZZZZV
ZZEd
~^zi[Z
G_jjZ
MZZZM
=ZJYY
EZ[ZZ
zkjZ
AY+E
8b#A+
z"_b
/4@]
:Sz?
&[<V
tO^J
1FR|W
w:h<S
,=5xq
R5=0
)/:{W
3u.Z
;Fa|
bi|R
JRz=7U`o
:I[.
@CiR
\"\i|
&w#
M ,_r
$d{:
>` *
YZ,J
q`z>,
Z:my
La)*
*R7}
sz^?
vYps
J2g)
eCO=
kC=J(c
;Aj,
2<F]
DI+~
yntX:C
OZ:B
rZ)*
Bio)
b3Nx
ZzrN
V;-_6P
L`i*
t]A]
#kWVh
8*$=Of
eSZ,
fOz0
Mr$b#
_}vR
R>R?1
BErC
.|mBqmT
ygWi
"{7MG
}JKwyxN
h"2SS?
.u2=
0$cza
es|Q
4Zjs(
U.1
qBTu
jNY&
9v9E3
Q6 y
=J:|
.[I*D
c@";n
y&#'
]Qp
:T-h
=<zp
(yEW!
5]Te
_J{e
rWz/
*R,|
8~:|D:
t(\Ey]
r.D:
CA^Z
:%WA
E56fcP
}X*D
!XbC
,|AT9
p"[:
PV1(
<>qTe&
vk:V
Aj,{U
szF:e
r"/Lhr
?bcz
z)=Uk
vbcKs
i3 &to
i:Sz>
2[=na2nq
8% qY
e'*N
3]/M`
Z.Dqt
/r'%
}-.h
j BKI
0~jl
"R6Nwe
@4:(
Qy]W
r&3W
B~N/I
[I*Iv
Y*k,
['V3
~8b#
Zo|k7
6m_R
|VR1
_CKI
b?b5
x|c/B
B"ZZZ
2ZMEf
Z_ZJ
"ChbZZ!_
Z[ZZZ
ZZZZ
ZZZZ
\Ea!
2]ZZZ
<TTTTP
}TT?^
AYddT
BTTTG
7TDSS
?TUTT
tedT
;S%?
dTyTT
&kkD
t&i"Y
9%Y@
v|XY
?=2j
+t[i
~%_S.
uOpJ
34m1g
I8d.
Pq[E
6$)0K
86ml?
aoVK
DL8z}k
m$2X
I;\|F
D@UW
>{$
t?QY
V4Daa
Db^
<#f_
L:ps
/#slj6
QSdlP
L/Xi
1y`K
%T&d
|TtG
D()j
CtAK
~#+n
nT4}H
_'JL
@\n*
sm:)
ed*,
JOEX
c<IO
&UV"
|Qct
wUT{-
ph("T?
$YXL3
OdX4mT4L
j|!6L
^9$+
x#sU
8,Rmt
FlNT
|bxt
edd*W/`?
K{Pje,G
_!#B
[%x{
3A'#
cA2k
Mtk@\
pv"
6}%&
gWP}
Fv|p
:2^v073
:%fk)-
zb?-T
="C]*
TL+Y
$|Ma
i925
l5Jr
qE}:
k<9x5
IN%C
O=deX
fI`s
FG=%
T($3)v%
D;i_e
|9<uy
qE}:
K4Zq
985M
1-="
gI`o
4q/.
7 RX0
~T+4
dG\h\
PPE>
/cxv
+cD{
`6if
.Ce'
4.=X
Xl_I
F^p,Q
y<{4~
{1Jf
w\5m
*3MT
,T)N
#z8}
@]s_
xI;O
vH,!-
#!Rb
&2(P
;t{g
5/8,
4)f8
X,-x
1-="
7;Bf
6UZX
;4*V
YD^q
Nk^L
;3m`
"\Y<)I
kTiQ
[Qcyk
In8t
@<`TTTI<*TTT
TVTT
VTTT
dTTT
jTTI}
PIP<
~TTL
TTTII<mTTTL
=UM?TM
?TMS;MP
#E2z
kGg~0VJ5
.e/6
`+S?Y
~`w~)
CZzl
~L4Njd
(}h4
Us=$1
8dB7
d4*sz
i.B":4
B2zp
da($
B| '
dT[.
`s<7
KW:>
FI+Z
Mc'&
QY)@
gOY.
nf;<
g~-=
Wz-(
sl.0
gm_)r
:oB|b
"DZ9
!*`1
f^i%
?Jhu
2*`uO
!~`3
krSLZ
.kVr
"{2h
Vg+
:KX
cSLV'
0HeI
tKX,
_o=0^j
lb?Z
\Irz
A2:`
5zL'J
FdK1
4Br(
N: r8
Z$|9I
\gZh
R?[n
PYES
P2gb6a
{d7w
edf1
bHnR
VO{Q
: r^
>*|b
yl0M<
h/Wx%2:
a<5G
r^%!2
Aml$
+(n-
>A^r
t&.#
N2v/
?ZDCb
"JUO
TG*vZ+!
-}R*S1
B2|c6^
=/w<D2:
dY'R
sXv
%\~L1A
@_~+
#8Uh
QU!q
~L0A
n*5,
x|aG
Ug!1
}AIu
tm 3
bD_>+
@O"~
:<bz
8.y4
Ytj#
$|B+
<"jZ
>BDb:
co^v
^b^a!"
[qqw
oJ"*Z
d*`u
~)Ao
p^g!
vC]=
"N)+
Ia[~*
r#4R
gI_`)v
r{*/
`c(n
Q;k*j2j
kD6=
y_>Q6e
b^cDY
swq-
SRl!
4{"zh
LdB=(
2{p%t
ij[i
B2z0
MW:N"N
Yqz\
=5"ND
^b.#
e# ,
}:D<4*i%
~~l_
z~?: