Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 10cd73523d0bdb47a09df0f4a8113aa8
SHA1SUM : d63be5def2182a610db14c037ccf02725de63bc2

architecture: i386, flags 0x00000102:
EXEC_P, D_PAGED
start address 0x00421b23

Characteristics 0x30f
relocations stripped
executable
line numbers stripped
symbols stripped
32 bit words
debugging information removed

Time/Date Wed May 2 23:26:08 2007
Magic 010b (PE32)
MajorLinkerVersion 6
MinorLinkerVersion 0
SizeOfCode 00000000
SizeOfInitializedData 0001a800
SizeOfUninitializedData 00000000
AddressOfEntryPoint 0000000000021b23
BaseOfCode 0000000000020000
BaseOfData 0000000000017000
ImageBase 0000000000400000
SectionAlignment 0000000000001000
FileAlignment 0000000000000200
MajorOSystemVersion 4
MinorOSystemVersion 0
MajorImageVersion 0
MinorImageVersion 0
MajorSubsystemVersion 4
MinorSubsystemVersion 0
Win32Version 00000000
SizeOfImage 0003b000
SizeOfHeaders 00000400
CheckSum 00000000
Subsystem 00000002 (Windows GUI)
DllCharacteristics 00000000
SizeOfStackReserve 0000000000100000
SizeOfStackCommit 0000000000001000
SizeOfHeapReserve 0000000000100000
SizeOfHeapCommit 0000000000001000
LoaderFlags 00000000
NumberOfRvaAndSizes 00000010

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 0000000000032acc 0000003c Import Directory [parts of .idata]
Entry 2 0000000000000000 00000000 Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000000000 00000000 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 0000000000000000 00000000 Thread Storage Directory [.tls]
Entry a 0000000000000000 00000000 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000032000 00000060 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in 4 at 0x432acc

The Import Tables (interpreted 4 section contents)
vma: Hint Time Forward DLL First
Table Stamp Chain Name Thunk
00032acc 00032b08 00000000 00000000 00032c62 00032000

DLL Name: KERNEL32.dll
vma: Hint/Ord Member-Name Bound-To
32b68 941 lstrcatA
32b74 537 InitializeCriticalSection
32b90 408 GetProcAddress
32ba2 594 LocalFree
32bae 667 RaiseException
32bc0 590 LocalAlloc
32bce 375 GetModuleHandleA
32be2 583 LeaveCriticalSection
32bfa 143 EnterCriticalSection
32c12 718 SearchPathA
32c20 709 ResumeThread
32c30 925 WriteProcessMemory
32c46 400 GetPrivateProfileSectionA
32cfc 434 GetStringTypeA
32cec 571 LCMapStringW
32cdc 570 LCMapStringA
32ca4 714 RtlUnwind
32cb0 903 WideCharToMultiByte
32cc6 619 MultiByteToWideChar
32d0e 437 GetStringTypeW

00032ae0 00032b5c 00000000 00000000 00032c98 00032054

DLL Name: USER32.dll
vma: Hint/Ord Member-Name Bound-To
32c70 142 DefWindowProcA
32c82 2 AdjustWindowRectEx

00032af4 00000000 00000000 00000000 00000000 00000000

Sections:
Idx Name Size VMA LMA File off Algn
0 0 00009c00 00401000 00401000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
1 1 00000800 00417000 00417000 0000a000 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
2 2 00002800 00418000 00418000 0000a800 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
3 3 0000b200 00420000 00420000 0000d000 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
4 4 00000d20 00432000 00432000 00018200 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
5 5 00001c00 00433000 00433000 00019000 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 463901F0 Wed May 2 23:26:08 2007
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 0003B000
Code Base: 00020000 Size: 00000000
Data Base: 00017000 Size: 0001A800
Entry Point: 00021B23 (file offset 0000EB23)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: 0 RVA: 00001000 Offset: 00000400 Size: 00009C00 Flags: E0000040 (DERW)
2: 1 RVA: 00017000 Offset: 0000A000 Size: 00000800 Flags: E0000040 (DERW)
3: 2 RVA: 00018000 Offset: 0000A800 Size: 00002800 Flags: E0000040 (DERW)
4: 3 RVA: 00020000 Offset: 0000D000 Size: 0000B200 Flags: E0000040 (DERW)
5: 4 RVA: 00032000 Offset: 00018200 Size: 00000E00 Flags: E0000040 (DERW)
6: 5 RVA: 00033000 Offset: 00019000 Size: 00001C00 Flags: E0000040 (DERW)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: KERNEL32.dll
Addr: 00032000 hint: 941(03AD) Name: lstrcatA
Addr: 00032004 hint: 537(0219) Name: InitializeCriticalSection
Addr: 00032008 hint: 408(0198) Name: GetProcAddress
Addr: 0003200C hint: 594(0252) Name: LocalFree
Addr: 00032010 hint: 667(029B) Name: RaiseException
Addr: 00032014 hint: 590(024E) Name: LocalAlloc
Addr: 00032018 hint: 375(0177) Name: GetModuleHandleA
Addr: 0003201C hint: 583(0247) Name: LeaveCriticalSection
Addr: 00032020 hint: 143(008F) Name: EnterCriticalSection
Addr: 00032024 hint: 718(02CE) Name: SearchPathA
Addr: 00032028 hint: 709(02C5) Name: ResumeThread
Addr: 0003202C hint: 925(039D) Name: WriteProcessMemory
Addr: 00032030 hint: 400(0190) Name: GetPrivateProfileSectionA
Addr: 00032034 hint: 434(01B2) Name: GetStringTypeA
Addr: 00032038 hint: 571(023B) Name: LCMapStringW
Addr: 0003203C hint: 570(023A) Name: LCMapStringA
Addr: 00032040 hint: 714(02CA) Name: RtlUnwind
Addr: 00032044 hint: 903(0387) Name: WideCharToMultiByte
Addr: 00032048 hint: 619(026B) Name: MultiByteToWideChar
Addr: 0003204C hint: 437(01B5) Name: GetStringTypeW

DLL: USER32.dll
Addr: 00032054 hint: 142(008E) Name: DefWindowProcA
Addr: 00032058 hint: 2(0002) Name: AdjustWindowRectEx

So]C
fB/sn
bYS4
oy_`
t),E&
U>l,wg
JZd)
^z=UJPSu
:tPp
=L42
gCJQl
j\hC
T]E%
Gox3
7Aa6
I*2M
jgO[
'^'%
~=Vf
-SC1
5H_1T
Q3Gh$
+)nP
_fKao
T)v
&5sRi
&%H
7ACYN
v_3~
uE}m
Wh,y
C;U5u
J9~a=
qXx@
5Fcu
8*{V
auag)e
U(cd
Zw("
@(07j
.lw?
gXa5
}4w?
}W[T
uWrJ
%r0L
Me;Fm
q,w}OE
g"sJ
.>}&
v)]q
x6<:b
i#Hn
ug.q
\GL[
ry$xx;b
dI.l
R-ZS
3<M2 .
rHLM
TiN"
pxPL:M
{5h=L
*BX7
<R>m
57Q)
|cvP
B& +
E"c$
j8Vr`qX
=8W_e
8DLX(
E'1"sI
lL0]
e(SIm
mpzp
&Z|J4
s2$Cb
z&1L
J#=a
J|n`
'$K,a4Uu
E3Tec
:Z@J:Vy
|@j[
p {3
[u<0
DFI/h
:vq5Adu
%b,=
28iOL
W(z=5
/u^g[
6Z{J
z.+}/g
$*qz]<
Yvj+z
11HISERW
qt_b
GI,0
}/?J
0t<v
/cYv
8}tn
FL#]
!M3bA
AY|XF
4hwA
IZ@`
9qi&
j5.g
-x~&
8c)O{N
=x+/
t"`NJ
spj5
C9(|
rh6g
pZT/
yydJ
6GL6w
!""y
#Dei|4
@9$"W`L
,}>M
kw'M
5]Qvz
$epv
(X[eM
pz5b
{&v9
KWoFr
YT2G
OZPI
M^$yP&
b+xc
+*Cb
&6eE4
tIL^
!B$f
(Z&l
Cta9&
x0LY
$.+;K
F~|6
[Yz|
0oPB
Cxh_
I3wk
10]@
u~e,
&a/:
pGxnN
!3ZT
s}8N'p(w
@D/V
SsW."2'.
tp<-
g(9
J'>)
(s)18w
yMZ:
a-7F
;#b|z
6dFY
+'2a
!Hq)
X 9,S
rUz|
+16l
(W6xhb
'IJj8
V9V48
,T3g
h-K6z
wX(1
:~63C
.NvT
Ocs
H(9H(
7o(y
nHvU
"w+
eG>L
DR{qe#H0
^6\=2
Sqn:
gl)[
iN.?y
9,d-
IP"g
v6>p
Ac*,
Cgg~n+
Y"zj
>i,'&tnJX
"IU]Y
)}k-XR]
_rDX
9`>a
rskz
Fn~LJ
{2!v
iM$)
r(ZS
&5hB
xFo6I
H~>N
&kjI#h
],K9
ywo1Y
^Rq8192
~sA3(
Vve9
)I+CY
y+ Hh
^c1
3D><
fJOy
-yT]
#*Py
M^0$w5
?JC|
?b.^
obR&
)?Tn
glH3
&Cwc
UY+d
#CCkv
(yy5
cxVtR
33/G
"rVv5
sPhf
W+}&
#$&x
+^Up
2@sD
LC4M
lMP7
;X<3
PdQ%-
>QCl
*SIP?
=J|DA
qNI>
6eWR
^0PB
c5?aF
EQbaV
GDC6rF
q b
iB,-3
*9z4
53rr
6Zr1~
{=fm
4Hl>
4qM7
\LA1*
[-rG
`gfI
hFQ`
uc;O
V#0.
|F]5"
Cy#,
OQX_]
M`+o
?~>m
Zj )P{
hi-<R
BJn&
mT+KG;
)BEZ
-Yj~
/O(a8f
{GJN
r>_0
Y%GhP
T/}"
{m^X
ZZ;]
"&[h
-Ij^-
-wI0
:sN$Y
Y WZ
rkp2
-1FK4
xmyn
=\rO
!|+w
NoL9
eQC>
H%X,/S
4>!|I_
`f2jgT`b4
DCy&
ef[@W
bB>R
"7N6
O\Ds`
x"YaN
xnoN
jUi(
M*Y)
j[/a
vy}!og
egPe
[)ge
Q|D~
MUr.
AKcto
(QKTjh
Dsq:p
HOE0
\x+2qj
^;kw
3_v>
9oF^h
9W"wB
SW1k
;K=T@(
1+`m
<OiW
,o-r
eg-C^
#{uv
l2 E
.+#;
-YX!
dbGt
*;i@
/H"2
-^lO
x^%3n
sJG^BQ
|1`o"
gT^n
fnTw46
7$S;
,`.C
aRN<
Y`J?
^S0`
6/SK
wVy'
m-4[ G
8(3\
jE$S
m Fx
y1}$
y,DlG
i4`M[tH
Zt@zG
7{C!
hxs~+f
Q=$Q
'@'-
,KR}
jM7T
@.U!`
c')y
:0s5
6L,c
:G5
sU8M
4?oXSw
@\Yj
!B8Q
^{PfL2<
hi<}
k3SR
$x1Mh
Eq v
p`c9
o"!l
W..R
Yc-v
>wCR
>RBi
73,c
/[S5k
$4q)
$g5c
JjVN
`I\*
aC2K
@Su
j`wZ
|nu-
/}:(
Ui*5)
d8\,
^8Ab
|a3{
6}T@
.PN^
)oi=
;9%D
m%Mw
Ka=g
m 8xV
j./WaK
0lHsO6
teT!4T
:Wq8X
JX +
!{Jw
_{x|
9EA$
]lH?=o
BRT?V
c2bLD
]agm
":CtM
/E|T
&DK3''
{uvZ
F<0_
t:<->
fGaN
!B=0
AKw,
*9B-q
}p=c$
Rbw0
b[]v{
. <f
>g90L1'H+b
(7=0[
Hl.V<
2H%O
cl8C
sO2>N:KF
hKcjgu^W
;453H
@ vG
Dy j
:65!^
DQ0*
=eWl
b"b.\
sH<XF(cj
kYud
@ept
woHv
WWEN
;>f1
ip@R
a>*3
wD6=
9}t}
&'$2
%Ve}
nQsv
wD#-Z
_2p/+
I5+(uZ%
|9J-
%}S5
i/1!
G<2
+#6m8
gb%m
4Rh|
kgO n
c*U2
yq2u.
CYVx^uB
)Y~~
5]I6`
ND>_A
[-wG6
RL^aGK
]hvz L
c]aZ
DST=
ArDEY'
T,:6
D rj
4yG>R
1Ux.
@Ja_]
9j0l0^
~v%N,
:;z1
vfJ^
NGd|~qz
"PA:
,?-4
hq'N
3atf
hNVo
eL8f
DI8>!C
Pa-q
Kz[h
u7=-
+,uu
l0^'}a
k=Q"
9<bl4
wpA:
*B3y
Yi\v
U(C)
h7%<,
Z@K}q
7_]}
QJOC
t,zQ
tq}r5
{'_*
hdMp
Yt i
)o:m
)jj
NQ()
67"+
}orY
D(oZ
VVC,"
sKpOG
Cklu
{3~'
Vu9E
l~|w
'B/4
2`c<6
KYhJ
2W`.6
4f_|&
=c'l#
S[VP
4^NH
tX?$
{K~\f
wlx)h
b>!lc
,whT
2YW$
_i2$6
"IqZl
xV6C3
TG]5
S=j
nX?nO3
TrUE
x:&FI
Kf1h
M,We
*z\}
UVU6'K
c{]m4
EH?~
=qyrL
r|2v
+#Y!
Q!L#"
#2Tb
3!T:
0a\`f
N+,~B
! %N
<C/$
dR#8n
W.U
4dv{X
YQbb=
0Y2
ILDb%
*8;V^
&lX4
T;*3
f6"|n
h/od0'+
x1We
*&VE
XL~p
$G^f
VM Jj
+G =
FVv5
JWk~<J
yfS!_
<s5}
Lzzwp
Jz|B
@?A"
<2va
Dule
1`r-
uAq/
7Nw).
q5\'
OM7^+4
TrU.
XZ.S
5]?T%
SqBP3
=cW 0
fNc\
Q%B.
)b"f
vL~o
*F,z
?1'v7k
Bs/I
:11M
cH4#
o9#zXj8
{SaB,XD_C
85Y`
3CND
Ouq(
k:dyV
):1B
,jn
St] _
-xQ,}
h0`4
49hZHx
Hx{9
Yb&X#H$
5p9
0B6I
2Xgr+q
F_Ze
4egF
Uw!}
9>:C
F{TA
9a]G
ig"\
NI79{
F}~H6
Mg4
,yL'8
|Vhj
@@FF
YY_]
_^[]
h\QC
d}"j
SVWUj
]_^[
t.;t$$t(
VC20XC00U
SVWU
tEVU
t3x<
]_^[
^_[3
tzVS
GIt%
t/Ku
SVWu
^}%95
WVS3
SUVW
_^][
uFWWj
"WWSh
9} u
E WW
tMWWS
t@9}
VSh
%@ C
pVWj
h4DC
hhZC
D$$aXX
'HEREISBOOTCODE'
.text
.rdata
@.data
.text
.rdata
.data
20050518
m l
m:AMi`
0.BA+
_7f,
1)&,
(ZrD
>"Z;
QM9d'c|hO^+U
35W,{
1dBj
1~qw\
t%7k7"
4d@j
lyXB
c4|K7
8yP|(
)(#i*
l9wn
ik;
UV;N}eY
sYNJ
OkC_
{zLye
$#W[
,!aL
C.03Qs
GkU!
hS"$pU
D/aN
0c:_W
#RwmK5
p\#;
j$~R
-S P
5bVv
|2>?
T`~?
)y+a
FYiC
sMi);;bz
)'x<
/>u2T
.5P"
Qj l
x3|
{SXa
Wq+dGdD{
Khm3
`lzM
_Q#h
:G`s
5)-P
iIf6
>n|O
$sf<4
lBf*P
zV>S
v3m"
54CGNG
@CH
'1 /gB
Ae0R
,f@A
&v3,
2E9-r
2$^@
@)?DR3
U<4M
WZ9^
X3SM=
os&pb
Y1$L
K $>W,
tg e
i-OTH
O]^L
05FQ
8lj{^
u2rP
M<[-
k{Y$
/@Kx
rCp,
\iVf&og
A$SA
8.#"H
3<bj
8D &D<;N
Dv:#.w
0<y6p:}
)&jo
:>s_
$lpQ
;Q|6
?HgK
r+_dM
PEpr
<TFo
KAS0
m/3:
`!ul
z/JE
v8)}
FZ'Q!
f]"s:F]
*!#a
:UW#_\
TMUJCk
chNY>
SkW{
SIC8
Mv{X=
r+F78
{(xh
!x6j]
~AP[
~Y ~
<TK4
L>-ylN
kGp|O
} nU
FvYzU
JM[X
!bs.
O_5]T
_H- Fol
tmyQ
6LK?
9LM
&y>X
u+eZ
3v>m
\fX<*
'6>wsHIc
ti,\2
Fj=6
b-gEX
#(_9
[>PL
4bU&45[=
Od*/]
)Y4ti
9$NZ!
P0,z
Kqb=t
5k~p
gmhn
I}f7
Zfg8
4k)r
FS?t
\8~,
0~(L
2L?[
x>4P
&QUx&X
Rw=I17
>`\}
}Owf
w~7X
n(/{O
DF}=
[q5V
vP1HRsZ
8hw5^
G7w4<
0G=i
):Ffa
8/D{b
/J<~9k
K*Ne"
$B]DcC
.7@2v
}@SP
lu8Y
x0%+
i1c0
o"\|
7-E/
:Md9O
~";g'
r\y@
+;Hzo
1~ c@
{"&B/
$#B2
@/Ms
(sKC
D>X!
O'h
xsLH
l;*t4rD
~nU07
L\t#l
=k;T/f:yF
k]'-
`G75
m;DilO
/X]e{
QifQ
"z'~t
{6qS
:k3!l
E?g=
1Wdg
0TXsl
4H>-APF
)Cw
rM5j
N=#A
tu:g^
IxMJ
cJ'#
',jfoGx5
w{o$
~Qy&
097N
kzm3I
xkRT
3/sk)
>4Sq[
`E6M
a=F/5O}
&w%JX}
ShX5,
7*K\
W1(J
zh@2WR
fju!
dAe^
a^O#
wzed
-~o}
KYC*
b_EF
u-uO
r4q<V
gUiX7
q\S[<0-bZ
os?R
!+=y
%T==
Tf`j
!E=n
.[N`o1
zzxV)
m&7$
Ebri
8;Qzz
2#tlQ
,(hae
BHLh
_`Q5
=fdd
^Dhs
D'eD
L 5,
/%m[xn
3E$^
gQ
MrQq&
`)-}
7<l2K
%+u;
~4B =
]sz@O/=-
H[}6
msT.
6m}p
NZ65DO
d+>z_{K
7@.
/ 'OfL
O"_r
9!.*
dO2x
9b`PU
[(^p[Z
2tNq
OwgH
2Ey"
9NF3
c5v)
xrpHFT
S}^F
f$[!
LcOmo
&9X2
)#~a
P!h4
:@}/
^NAV
~o(v
Pp >
j!sH]J
FL8^
vx!Q
i=:k
Q3g*c
B?T~,
"PT#
1u{(
%pfZ
cf|V,
HO`wY?
*q+IN|
- ]Y
cg)K
]GBgC{
MSfu
F)Nn
4^=z
-%_[==
:3@7"
. e+H
.#~gy
V344x
f~^1
S0t1
mx7I
()WY
%!c8
% #M
drD}
Ct`Y U
/|p3N
,yRZ
I%61
F 21:
A$Mo
OZ2K
ZFN%
RDvA
bT%($
^Km%
GN:U
cP.!
y8chjG
V[m*
_y/o
tvQn
;=CW
Tj{C
3fgJ
fa^C|
@qkc
J-B6
hB[%D
Fr(D
0/3@|
=p8(
Ice<
$VdW.
Jac@g
6[]/
yL]Y
W~nP4E
9Ze{z
3P}a
$@bYYEl
2r|U
7i0v
%H%!
.d%Gq
uryoWc
F{DvT
Y-pT|^
]*fnP
i$8i
sq$Lj}
"9f$N
Rv-A
/jqy
!cb6yes
:?&7c
.?=3
"0Md
,ZRl
ust*t0V
-1P!
R/hs
%T?
-kqK
?<YO
b%z~[
e(UC
CP(D
s U*x
F|ve
J$\^
mPy@
IGaN
?MiVi
frD>\f
8O7!<
}ean/
]s-a2,
;YJl?
0c~5g
Y9n`" 6r
=m"h
U>%*
okoR
/ <
t3cyv
N6Dc:x
<duV``
B;('
9<gOy
.Hnc
3m5B
'lA%
NiM8
&2;}g
ekG6
d0Q&
Sf-E
3=v)
]OByfs
(zgq0
L$R2
|)=pC
,&3v
Wvg|
/]c8`v
rd1f
pb\v
zj|096
Z _g
=1#J
WlDI
7F=l
X1o( C
Aax,
#8US
?su{
!&?O*U"]D[a
kBg=j
CLn|
z4?R
-3w2
{Sfrx
^SGq
qz#m>x
7#uH
d@rqy=
cYi_
bX1r3
3kp!
{[D0
@y&1
`lT|
m{Q.1
$gJn
Rq]R
o.fT
6e,M
|,H)
(psm[D
dhfqb
ily*
XOzwZ
vW9X
3g7&
,H:c
Y19@
<1#[
MIer
=?&F
!\e}
%+2;
kernel32.dll
gdi32.dll
user32.dll
ole32.dll
advapi32.dll
oleaut32.dll
SetUnhandledExceptionFilter
CreateFileA
CreateFileW
ReadFile
CloseHandle
SetFilePointer
GetFileSize
ExitProcess
CreateFileMappingA
CreateFileMappingW
LoadLibraryA
LoadLibraryW
LoadLibraryExA
LoadLibraryExW
FreeLibrary
GetProcAddress
LoadImageA
MapViewOfFile
UnmapViewOfFile
GetFileAttributesA
GetFileAttributesW
GetModuleHandleA
GetModuleHandleW
GetModuleFileNameA
GetModuleFileNameW
SearchPathW
SearchPathA
AddFontResourceA
RemoveFontResourceA
FindFirstFileA
FindFirstFileW
FindClose
FindNextFileA
FindNextFileW
FindFirstFileExW
_lopen
OpenFile
_lread
_llseek
_lclose
CoCreateInstance
CoCreateInstanceEx
CoGetClassObject
GetPrivateProfileStringA
GetPrivateProfileIntA
GetPrivateProfileSectionNamesA
GetPrivateProfileSectionA
GetFileInformationByHandle
LockFile
LockFileEx
UnlockFile
UnlockFileEx
GetRecordInfoFromGuids
GetRecordInfoFromTypeInfo
LoadRegTypeLib
LoadTypeLib
lstrcatA
InitializeCriticalSection
GetProcAddress
LocalFree
RaiseException
LocalAlloc
GetModuleHandleA
LeaveCriticalSection
EnterCriticalSection
SearchPathA
ResumeThread
WriteProcessMemory
GetPrivateProfileSectionA
KERNEL32.dll
DefWindowProcA
AdjustWindowRectEx
USER32.dll
RtlUnwind
WideCharToMultiByte
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
WkaS
fmw8
"#7!G^ph7
}JVY
*B)JlD*
55"\[_
(o%S
W'of
nN<0
APoR
Gj5W
ImA"
$yoV
W*?#>(!
}_ZA
Q4O+
"ZLo
&<}/
zEHb
/jLjDey^
n3]Y
JKY=
tT&Q
CEnZ
bB{2
N2NZ4
JD]l#
")Zv
`_rK
b2of
IUXr$
W?g%
>k@7x
A`\Q~l
wwv-
-;m*
4A6X
;A)
>qGM
u$*H
Q.P&
|=xM
S13b#u
w0Wh
*XW
VZmK
*ouV
H{z[
T*nD XN#
81Q^
4BHqv
,aDHd\
Oyys!
-2v9
FY^8
F#a$
Zj~\Qm
yc>u|H
B?uNm
'8HVV
8TnEq
qTIE
B+co.
["VC
uRjb(
qDrI
V'mF
-?8N
:Dq=a
{fZC
t\CP
kl:Z"O
.<-8BN
MOHj
}g9Y
;*a\
>%2#
p vt
UN\qr
>jv5R
^\Mj
^7mP?\