Malware Archive


Home | Objdump info | Perdr info | Strings info

MD5 : 2a4cfdc53dbecf27fc69803002f27753
SHA1SUM : ee9e78a17a4f97842e28f75f62b0deb1d753d2ef

architecture: i386, flags 0x00000102:
EXEC_P, D_PAGED
start address 0x00423253

Characteristics 0x30f
relocations stripped
executable
line numbers stripped
symbols stripped
32 bit words
debugging information removed

Time/Date Sun Aug 19 01:14:41 2007
Magic 010b (PE32)
MajorLinkerVersion 6
MinorLinkerVersion 0
SizeOfCode 00000000
SizeOfInitializedData 0001fc00
SizeOfUninitializedData 00000000
AddressOfEntryPoint 0000000000023253
BaseOfCode 0000000000021000
BaseOfData 0000000000017000
ImageBase 0000000000400000
SectionAlignment 0000000000001000
FileAlignment 0000000000000200
MajorOSystemVersion 4
MinorOSystemVersion 0
MajorImageVersion 0
MinorImageVersion 0
MajorSubsystemVersion 4
MinorSubsystemVersion 0
Win32Version 00000000
SizeOfImage 0003b000
SizeOfHeaders 00000400
CheckSum 00000000
Subsystem 00000002 (Windows GUI)
DllCharacteristics 00000000
SizeOfStackReserve 0000000000100000
SizeOfStackCommit 0000000000001000
SizeOfHeapReserve 0000000000100000
SizeOfHeapCommit 0000000000001000
LoaderFlags 00000000
NumberOfRvaAndSizes 00000010

The Data Directory
Entry 0 0000000000000000 00000000 Export Directory [.edata (or where ever we found it)]
Entry 1 0000000000031c90 00000064 Import Directory [parts of .idata]
Entry 2 0000000000000000 00000000 Resource Directory [.rsrc]
Entry 3 0000000000000000 00000000 Exception Directory [.pdata]
Entry 4 0000000000000000 00000000 Security Directory
Entry 5 0000000000000000 00000000 Base Relocation Directory [.reloc]
Entry 6 0000000000000000 00000000 Debug Directory
Entry 7 0000000000000000 00000000 Description Directory
Entry 8 0000000000000000 00000000 Special Directory
Entry 9 0000000000000000 00000000 Thread Storage Directory [.tls]
Entry a 0000000000000000 00000000 Load Configuration Directory
Entry b 0000000000000000 00000000 Bound Import Directory
Entry c 0000000000031000 00000094 Import Address Table Directory
Entry d 0000000000000000 00000000 Delay Import Directory
Entry e 0000000000000000 00000000 CLR Runtime Header
Entry f 0000000000000000 00000000 Reserved

There is an import table in 5 at 0x431c90

The Import Tables (interpreted 5 section contents)
vma: Hint Time Forward DLL First
Table Stamp Chain Name Thunk
00031c90 00031d04 00000000 00000000 00031f00 00031010

DLL Name: KERNEL32.dll
vma: Hint/Ord Member-Name Bound-To
31dd4 456 LocalAlloc
31de2 294 GetModuleHandleA
31df6 449 LeaveCriticalSection
31e0e 102 EnterCriticalSection
31e26 245 GetCurrentDirectoryA
31e3e 334 GetShortPathNameA
31e52 164 FindResourceExA
31e64 111 EnumResourceLanguagesA
31e7e 556 ResumeThread
31e8e 745 WriteProcessMemory
31dc2 523 RaiseException
31ea4 616 SetFileAttributesA
31eba 45 CreateDirectoryA
31ece 250 GetCurrentThreadId
31ee4 310 GetPrivateProfileSectionA
32014 339 GetStringTypeA
32004 448 LCMapStringW
31ff4 447 LCMapStringA
31fde 484 MultiByteToWideChar
31db6 460 LocalFree
31da4 318 GetProcAddress
31d88 426 InitializeCriticalSection
31fc8 722 WideCharToMultiByte
31fbc 559 RtlUnwind
32026 342 GetStringTypeW

00031ca4 00031d6c 00000000 00000000 00031f42 00031078

DLL Name: USER32.dll
vma: Hint/Ord Member-Name Bound-To
31f20 559 SetFocus
31f2c 2 AdjustWindowRectEx
31f0e 132 DefWindowProcA

00031cb8 00031cf4 00000000 00000000 00031f7c 00031000

DLL Name: ADVAPI32.dll
vma: Hint/Ord Member-Name Bound-To
31f5e 350 RegCreateKeyA
31f4e 389 RegSetValueA
31f6e 347 RegCloseKey

00031ccc 00031d7c 00000000 00000000 00031fb2 00031088

DLL Name: ole32.dll
vma: Hint/Ord Member-Name Bound-To
31f8a 62 CoRegisterClassObject
31fa2 235 ReadClassStm

00031ce0 00000000 00000000 00000000 00000000 00000000

Sections:
Idx Name Size VMA LMA File off Algn
0 0 0000d800 00401000 00401000 00000400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
1 1 00000800 00417000 00417000 0000dc00 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
2 2 00003800 00418000 00418000 0000e400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
3 3 00000400 00420000 00420000 00011c00 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
4 4 0000b200 00421000 00421000 00012000 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
5 5 00001038 00431000 00431000 0001d200 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
6 6 00001c00 00433000 00433000 0001e400 2**2
CONTENTS, ALLOC, LOAD, CODE, DATA
PeRdr by Frediano Ziglio. Build Dec 27 2007
++++++++++++++++++++++++ FILE HEADER INFORMATION +++++++++++++++++++++++++

TimeStamp: 46C77D61 Sun Aug 19 01:14:41 2007
Subsystem: 2 (Windows GUI)
Image Base: 00400000 Size: 0003B000
Code Base: 00021000 Size: 00000000
Data Base: 00017000 Size: 0001FC00
Entry Point: 00023253 (file offset 00014253)

++++++++++++++++++++++++++++++++ SECTIONS ++++++++++++++++++++++++++++++++

1: 0 RVA: 00001000 Offset: 00000400 Size: 0000D800 Flags: E0000040 (DERW)
2: 1 RVA: 00017000 Offset: 0000DC00 Size: 00000800 Flags: E0000040 (DERW)
3: 2 RVA: 00018000 Offset: 0000E400 Size: 00003800 Flags: E0000040 (DERW)
4: 3 RVA: 00020000 Offset: 00011C00 Size: 00000400 Flags: E0000040 (DERW)
5: 4 RVA: 00021000 Offset: 00012000 Size: 0000B200 Flags: E0000040 (DERW)
6: 5 RVA: 00031000 Offset: 0001D200 Size: 00001200 Flags: E0000040 (DERW)
7: 6 RVA: 00033000 Offset: 0001E400 Size: 00001C00 Flags: E0000040 (DERW)

++++++++++++++++++++++++++++++++ IMPORTS +++++++++++++++++++++++++++++++++

DLL: KERNEL32.dll
Addr: 00031010 hint: 456(01C8) Name: LocalAlloc
Addr: 00031014 hint: 294(0126) Name: GetModuleHandleA
Addr: 00031018 hint: 449(01C1) Name: LeaveCriticalSection
Addr: 0003101C hint: 102(0066) Name: EnterCriticalSection
Addr: 00031020 hint: 245(00F5) Name: GetCurrentDirectoryA
Addr: 00031024 hint: 334(014E) Name: GetShortPathNameA
Addr: 00031028 hint: 164(00A4) Name: FindResourceExA
Addr: 0003102C hint: 111(006F) Name: EnumResourceLanguagesA
Addr: 00031030 hint: 556(022C) Name: ResumeThread
Addr: 00031034 hint: 745(02E9) Name: WriteProcessMemory
Addr: 00031038 hint: 523(020B) Name: RaiseException
Addr: 0003103C hint: 616(0268) Name: SetFileAttributesA
Addr: 00031040 hint: 45(002D) Name: CreateDirectoryA
Addr: 00031044 hint: 250(00FA) Name: GetCurrentThreadId
Addr: 00031048 hint: 310(0136) Name: GetPrivateProfileSectionA
Addr: 0003104C hint: 339(0153) Name: GetStringTypeA
Addr: 00031050 hint: 448(01C0) Name: LCMapStringW
Addr: 00031054 hint: 447(01BF) Name: LCMapStringA
Addr: 00031058 hint: 484(01E4) Name: MultiByteToWideChar
Addr: 0003105C hint: 460(01CC) Name: LocalFree
Addr: 00031060 hint: 318(013E) Name: GetProcAddress
Addr: 00031064 hint: 426(01AA) Name: InitializeCriticalSection
Addr: 00031068 hint: 722(02D2) Name: WideCharToMultiByte
Addr: 0003106C hint: 559(022F) Name: RtlUnwind
Addr: 00031070 hint: 342(0156) Name: GetStringTypeW

DLL: USER32.dll
Addr: 00031078 hint: 559(022F) Name: SetFocus
Addr: 0003107C hint: 2(0002) Name: AdjustWindowRectEx
Addr: 00031080 hint: 132(0084) Name: DefWindowProcA

DLL: ADVAPI32.dll
Addr: 00031000 hint: 350(015E) Name: RegCreateKeyA
Addr: 00031004 hint: 389(0185) Name: RegSetValueA
Addr: 00031008 hint: 347(015B) Name: RegCloseKey

DLL: ole32.dll
Addr: 00031088 hint: 62(003E) Name: CoRegisterClassObject
Addr: 0003108C hint: 235(00EB) Name: ReadClassStm

=< K
5aW
Ce\t
QQj;
Lr52
D00N7
AU1#Cz
NcR`
KxhxQ
q>rA
.i'tA nCp
U^f6*?
=,Zn%
)h1Y
vujh
#1gP
a;\(
r.fMgst
wRkoA
hx(Q
JWl*
&;=Q
Y3q%a
4 V;$
G@_=
t@xs
!=-`
1#_k W
}%Pl#
n=ZR#I
pL.y<a[7
q7I'
7qE]j4r
v<r'
HF){-
\a7V
!~^xQq
>!u:
Fqas
i#oy
EEoG
uWYE=
MAI`
8%%g
K2M^
i761
X]ei)h
QRewz
]8O8Uc
tf66
fwTyQ
csxy'
pL'X
o`cv
LF^R
'u{*
b{2k
SU<w
#_$M
pnPJ
obZH]
\C7H
$-.xi
[ `,
CL0/=
Cy /
Zdjl
]54.
ct%!89
"NDg
&Y bC5
UTd e
7;W(
AfG>1
@kt-
T(#Zt#T
+5dA
(oiX
Sw[n
YI!;
f4rA\
K&>b
dMb0
b p.2
/'q=
G1Qg
=*([
>kX&
iaG^P
fwx\
=w\8
cDJ|
g_g]
JDBACDX
Jt->
`ekP
etQw
;7Q8W~F
=OA
|5c@`
'b_|
>}jQG
w-.h$
+X+v
0Q7Po9iu9{
f oe2s
I[s1z
ss!R6
FpsT@
w\D+$)|
LWKY1
%jMQ
$aDY
tVu"l
UIEBg
|>m^/y
}IHSX
%Giq
-/7=
(V9L
\rYE&
m/P{R
K=(V
[SKQ
nvZBAI
Qf9u
Qx$^p
,TnOu
Ur=KCz
]t 5
JTSc
~*+w
`&Gi
:^eU
#=5L
CF+kf]
WN?k6
+R:<
i=K:
z(M",
{tS)
nPYE
NQ1Ny
(1SY
//L<
[ ^,
&_Mt
#2]tS
x)N,_
r-oN
CG[O
1cu~S
gvMA
V/~N
Q|Z>
RM,%
By1+z
Bc~y`
>:]v
1vI<
&]&M
+QdD
]rZ$
Ief}
9`}-0(MI
s9iA
\<}Y
pQAv
Tx_O
b1d/
d(A;
z~"@
1fzPV.
hxqN
Go2H`
%guk
-l} i~
&\tB
D 3cU
&T.?
J:'E-6
|s8c
8^o1
b`raT
it1R
J:gV
7i$D
f.n;
Jr``q0
[@w*P
(1r&
U4aP
zG,
|,U]'/K
uFfg/
eiN(
&:}F
V[iF7
`eskg
4_h!
cR1$
"D'd
:`!M$
wMK&B
SEz=
:7y^,B%
t!=o
PbF
P rg
1St\
t1o7
0Q5nv
Z:#f
<(Xa
{AX.
]OGK
1JO|
`$1-
(bv_
p}$M
b"oi7^`P>
S:K.#
W.}6
;KUJ
<|]BB
(X6S_X]
^Yhy
XTp1
Vr }
yTHR)
D1['
1A_7?
|IVm
cmsE
k]Bn
)UKWm
kEt0
Z4_F
/<`2
8i%=V
<V6q/
szlSo
/K~:=
J}6?
wM[@
C% \U
GY-#
&jUs
4U<;
EONxsPU
7Uq1
anXy!
jpw_
>G1wG`
>iz)x?^
BuWp}
]j7hc
1A/mB
PnBNy
~y/H
_I`p
h{`zX
|2]]^
+r4\
q:!2-S
$GC)
~_II(
qf:W
-^]4m
$RAsr
a3*'$
@Tqt ~
F\jY
4aRG
<@DYD~
dx3P
E{F{
#<N>
(f fh
Y%kq
K#Gs
'{1Z$P
Tj~)L[
]U@V]R
xcno
^g89
j%&uq
%RS?c
^xn9E_y
aH\N.
x<zp=
+e 1
g zJL
)tC06
=jIx}*
1y^u
7 V)
'oS1"}'
DG=k%
?,Gl7$
]SCo?
z"V!
jJ5^"
G|?tLy
&s^4
w"vv
)mw|
;{?5
BN{
kTq~k(
v3'J`+F
=Rrp
cLHS
>_kg
)Qk{"
lIs*Iw1
.ropa%
3L[`
df q
ryKn
aJ1&
e0C[
;JJWpT(w
]Ypx3
6+%5v&
6{-Z
Dkesi+
ofN>
)Tn{apT
{$vn
wTid
@9AU:
@AhX
I t|]&
K_kO
@!=s
=zMNDt4
%9TB
dG?]?
!}sr'
3p%]
L=P],9
`PW>
{+OT
#@7M
:D%C
IS>2
5t{]
P2s(
@09xJ
e#.P&a
o,;f(
ameh0
vMy;
VZ'5]
SxKp
}ssS
{;#e
rZtq
C1bU
OaJLWN
*|DI{
9Jw6
*C*J
#J,%
j!Y|
]x/~
+]Ih
9w(]
)^v!f
gs|*
)='w|}X
BfZ3-
?;v%\
4cF(?
*.[L
%;Rm
l>!
>Qc\
=F%6
@^pK
2D)u
}e*/
9N-k
s${r=
u=D^s
9o&#
a.$L
\ Zk
|9|g
fMZTv
n w>
I%b-
pDM4
1~dO
C<_?o
75nNe
uBVR
iYx+z_
){Ur
m-0E
Gjp)e
k%5V
+wil
*+hr
,Hn5
8"x
n@ J
'4{4
N~i>Z
Z+4h
qR#,B
mwW@d
)!gm
rTj3
#QFv
Rl5~
@.yN
sSXIz
n"p-
_Heb
^-r!
kO{w
f>4>
$xs+
A+p
[g >H
e1*:.
mor8
?}oE
R9^3
U]#U
D]2
{0_UY
f>Lgi7 N
"=a,
zT|_<
WfkZ%
l),L
)l[~!)/V
xyY|
;oy4
Dl7#
}|TU
B2%BKz;
d{Ub
(7_"
x'CF `
boSh
Ir*h
q**Hc1w
zr`P(
GLyU
kMv
?}i<
;Qg~D
'-Q8
a6:*
Ufs&
wbNX
+Qr9 @
aD4}
>T}]
Z|:l
Qi_xC
|+%H
u~ux
Pi$*
/: w
t_kd"]
N"%=
]Jl}qa
p sn
2I)-$
iJGG
.32$
]ShVL.!
9kJ
%qAeQv
fQuZ
j1vxt
XI.;
WU.$n
R)j
{nP';0
<cDy^
Y/I&K5
<RUK#
t;:Ba
M\ql
eV)y
+|Xg
ok<|
->v5
PW]FL
%12;
ttT,7N&
8&k"
\p{ugDBh
]Fb1
m/Y6
UJHF
}p%Ab
QAoq
W/buk
-:`&9
bGg)O
br2t
<y5h
dB:yr
!vM?
5owP
nBz8
JXA
Oa4s
KK?!@P
: B
"Z+V
N{0J
H=wwKP
mbsB
'[ud
~&9s
m@nE
ui_("o
8M4r
mTos
:2i}!
Q&8<
m]QW
,)m2
k*Ra
v&fR
y!w(
>{z0a
2X%
]p`Y
q8%fO
T`*^!
McGK/
jJx
?[rkh
b_1O
pmTj
m`Uh
'JGCh
T>PO
OG]8e
VGU^
b)ON
@-s!s
9,$#
`MRi
||Dgn
Rd}l
'|d9
J>wz
.[cKQ
%XsWG
e``,I
6aT'%w
JY+l2
}Cp%w
S&:_
gXQy
hD=5N
TSe+
0G/q)
j@%z7
/$4]
`D7
v0*S
Hmf`
VZ&t8
;8Kh
h]~1f
~xE$
<q #
Tt"b<b
3~|Y
P"[Nrw
[ZgY
Ec\SC
TgQ;
6L/7d
Ru:4
m,Ylk
[w,v
!NNV
ag%Us
[EJY
_{:Na
<=Ql
c5-se
5L<5v\E
mYvf
EdyH
0!& 3
;2nj)F
%!=nmY/
.mS-
C*IYx
A cq
"n=3
y4%7u
#W8E
o(=Pqo
IBx8
<v~CJ
"S1"
1KrJ
@{}H
V?l75
g>|7
xr]XF
knE(Rx
T7 C
~!A;/
IJ)C
GG*i
5eFw
wd+H7(
#}qX
>5bW
rx+O
W@7H
fxWw
)Dg*
,ubhv
BtX@V
Yj()
3~dj
?]^b
pN$/f
433;}
Dsjz<
lLHJ
WlUJ
9B3E
Mp_9
~BdJ
fLcdFN
w0-@
>c| Lt
g2dh
1GAh
Wlh.
SI@^IQ
-3dY+
1J[a\X}/?q
84)j
;7e[ $
U^$-
X"s(
]<4h
eB^Q
oB$7
=xqoC
hZX!0Q
X=ES
S1'2j
2Fmd
6?Ru@
eXQx
|xVj
6)k2
d+Lyc(
Gdx$[DIgQ
-!6T
WtTS~%
Nx{`
?r|IL
?ZHh
X5<1:
/Hjc
+XS=y-
rv&7
q"Ha
uVSW
{.5;
v}qo
F\eM
;W!=
Q4ak
E)#&
d&Nl
W "Ax
p~\#
W+n6D
BCWJk
xc{H>0^1
~st=
,$qzzdp.
Jas&
nlSj
`hDV
N0-M
H+*@
33PB
Yv2<`
35e<
pzT^A
@hy~
-S?oC
wfZ-
:^(^
BETw
,`iC
NWLO
`L[*
4_4l%
)tBD
4z29mq
L'2ew
|!u/5
+u
*'I+
Ff#|
k`yQ.
1dt~
z:u2
cP,j
`4)h
air\s
(1u1
wVDC
CT=
M9:+"%6
NNFG
rV%rw
=18h
TmQL%
}jkL
7Q\L
(v>;
()g.
$8t
:TqV
({zt
|Ees
WV&dI
,o`5
aH!b
&MwO
WCkK8
*.d;
/tE(e
EsDyX
].Rx
nTd\u
[&,l
!k2%
e;l9
'i<W
=)!6n
\^Y:E
k37[
cPS"CK
`@~1:
[Y=@
'kF+
qTLu5cX
r4-o
E(@.
9`p+m%
Zc M
zNfU
H,a9
%|+jz
$@7%
mUS)!
5BYi
M^$<
QYC<JiL
F_l<
A-&5-
A}#Z
x~t(@
DfzSLG/
z@fP
cM6M~
AX5z
|',Zv&Kc
FTu!
){Y<
Bor~
PC`.
r'8wCv4H
3'vc
B~Q%Y
uFdG
j)I9
>}&[5M
#;w_6
c-!Ueo
PB~7
n?a56
Ao%5
GY.B{
TXr/
7W 5^
-Y[-e~
6YDQ
D]cE
MU?p
uTHC
=5jp
| 0I
fMs
C>>j2
`UmRh
EeoB
{6uy
l"~B
N>GT
aD%@Y
j#uhAl
LR7u?X
ve~t
NA%9
Q_qYE|
?Kv-m
/qrJt
4Zq4
W}z<
8zh&
Hg1;
38?]
itgA
|oXH=r
Sj\v
4="E
+rQd
n "0a
'tF[
^deD
r0Or
K"wMM
{m]$
#!,U>A
I'tB{
e%=@=
zj5$
w@NJa
~kg~i
e.WBu
im3q
QqPk
Fp=l
-\St
ivts
'?j
j$aPf
_Sbpay
0U[(
Np h
xYgI
S o*&4
W^jQ|
:b8C
71G/
HE6:
`&YI
R1.8
[G;6zO
gh_q
5.(?
s85;;f
lK4=
R!kr
V<v]
}uoC
@@FF
YY_]
_^[]
SVW3
HSVW3
VVVP
t 9}
VPhe
Y_^[
SVWUj
]_^[
t.;t$$t(
VC20XC00U
SVWU
tEVU
t3x<
]_^[
^_[3
tzVS
GIt%
t/Ku
SVWu
^}%95
WVS3
SUVW
_^][
uFWWj
[Sh4
"WWSh0
9} u
E WW
tMWWS
t@9}
VSh
^Vh4
PVh0
Zw f
w f=A
AABBf
t7f;
rRf=Z
uFVVj
[Sh4
"VVSh0
9u u
E VVVV
t`WS
^Vh4
PVh0
WWWW

_^[]
SVWj
VSPW
PPPh
hpCC
h\CC
_^[t
D$$aXX
'HEREISBOOTCODE'
.text
.rdata
.data
.Polyene`
.text
.rdata
.data
20050518
huYx#
f@Xn
\}D,
E8Zd?
Sd9V P!
N!~:
mdnni
1s]'
T Vhtu?
&J;ZX
n"fb
"#="W
zC~G
3k F>
mosx{
{[7e&rn
gzn4
YB2^
`.yS
,b_t
!y; T
*mJw
X=kE#
ljLKR
jb-_n
? c-
%w?YF
w-,$
G=AF
dL:t
`+b|
hc}9
kGho<
uL4
wH|Q
-'yA%
D 10
*~yY
AFXr
d^fj[
H6EP
V*$a
5=mXZ
"%h~
N< uC
..v.
o/`/
>GUMY
dQv(%
#pOd
-,T*k
Mwc1
3s_@
sz]I;
5^Bq
htUND
v,Ue9
vnn|
Ksy!
zZY>l
NY:fv
O<(x
j69Y
J&"LZ
VGgw
Ke[]e
Fw1~
7o`G
HAB5
tj[.H
po@|
56=_8$
"5=3>vR
nO=h
nB1G
Jc4#
aV;MS
x0 x5p$l
#:[E
Ma875r
5nYT
.?wC
D]
sV s
-.\xl
PSt\
:MPrS
u`5,
:y`Z
Y- a-Y
%@.t
+)17
JKe8R:
"E3>
osM<
dc)j
Ei8W
[aY_
m-\O=
~m<f
C`HA8t@
z/T"
F/5~
Ulms
QH5]
pd@3"
'O&w
i<]`
Fb>]
EDogSi
Nzl[6
Kq`p`
:bv[
xN71
>JW\a
p:QFo;M
Jt^?^OIW
xf]-
$yoS;A
,m'I7KI
\|*`sv
8IIHd
(IABI
iCg:
O;2
U*V)
CBg\
RU#E
uMtG
cEB;
Fb\nG
B? >
2q|Rcw
U;Z`
f$N/
$$4!
~cR-!~
]G0@
)rX`
agf8I
XQkz
3Jg.
ey|ys
Gn-N
|nq3q
UZ3l
EC&)
^47x
o5q$-gq
|qZXWD
Pk0.
B(ct
*7pzib
3PDr~m
@E-k(
({Z:
tL3:
n5al
_'S,W
Vm6[R*
lEKC$
8.6{
.qctE
(@Sxw
T,;XF
>k5N
L:Ms,m
dJm$}
NCNV*8
z5m+"!
B5uoe
(E%Q|
^z0>
X$ky
iexsm
E"D|]
9;i^
:NEk9
mAe-
KaG8+{
Y?:m
'jqY(
f9BC
T)=a
zDeE
]M3,
[q h
$0>G
3nL^
Z;xM
M[?g
g>Jk
G>2h
0.,SJ
n(N#\
BOQL$
KUqc
M_MV
*F~[
7B'/A`
r7)+
-u>.
b;2SE
=cO'
b&G8
O_3M.
5hhx
>CY16
,6c!
\N};
YV^
d AD.!
StO^+_^
yqG.
4r/J
],&m
e8#|
7/z1
Jy`H^{
aqJG
3hG>
l ;}
1`cp
K*EJ
tem&l?c
!!pnD
h\uG
_?r/
XM4N
.0fb
(Ci!
v-_R
lMX8
aJ-k
!M$~4F
RH7JEs
dlr)%
*dq.q
^}c!8
kqA.
^EAHB
gm{D
0p-DL
7ZR*
iw?]"
\3X%5
="%j
s@W+E
IxUB/
]<UP
+]o!
BJ<U'Y
U Lz
W$r1g
/9J&(
9@h$
mY&vK
B,dK
Dx#_
+D^
[)7|k
zl~s
"p%~r
d`l3
"ZXj
+:*W
yeMs
'OAjh
S\1i
Rz0]
m&* x>
LXNQ
b1E~
z]9s
q-~y
3}k{
oU_dT
9k:D
8{U|
v1rm$
NH^
8uYR
*#)0s
\ADco
E;B7
fXmo
F`@m
Cx8D
|?g;
Sykr^
Hd='
nY\P
!-w\`
Z9XI&
.+ nXtc
x'(,
"bL!+
a}~H
|r(C
FZ^4
3xDX3
rpr(
K^$-<
5]hdp
~0_.
qSy^
aEi`
-"Kb
3m8BD
i^"l
3^%'
nG<KEz
WA~7F
u%&UM
2,8hW.D
RYUE
DJ=f
a^[Hz
#$FG+
iV3L
C@o.
rgT&
Z66N
dVfJ
,5[_O$R\L
5?~+
*`gIR]
z% @
DDw_
)~2RG
`aQ#
\^Cm
Q%b1
IfzW
NrrF
4>lVe
7TBXTP
Msr_
J/W3@-
pAn]
o2N~
I@u<
C]O}
<(Dn
pcU{
z^d/8
}`dZ
V<;@#EB
[9]S8Qx
tFe%
$Ig*
B}z(fKo
b42g
9bG+
J BS7
=6I0,Hk
c7OZ
4G$F
UZ%B
u4=s
;*``i0
92v\
R'<v
_evq
I?`w
S$Al]
BzBJ
=E4j
+POZ=!
NH!*
G$CV
zDM"
@*F5
EI)U
0.t^
<!2]Dxyg
jIdN
beF+s
\}yn
XGt/
3+G~
D|]8
*+O
?H`F
u$Q2
ZRdM[
rU~y
7DDj
*{
cXMo
J({\
11,#
$J|-
f#{a&
%g7ow
}C@Rc
]\s!
=NT>
Z/zZ
6bUl
z\h(
upB $
MVrd
Dgwx
9G26K
$h0`b}
~z/hWv
pdTq\T?
MmQX
Q7jy
qhQ oU
*rhg
Lem'
?42-
|H"c
N*eK&
5}4d
nR;r
tWlI9
h*`1(
}Id}/h
b!'O
2KX^I\^j
<vUA
?ONa
0susM
_!zx+
sP&Q
jb`/
:oF?
pCB`]
&x>oK
YI[9
_O^0s|+
}X5nm
1]=:u
T5DD
\[1T
vJ!
i$hl
f.,n1y:~'
eol/eV
X%$]
Y|-_
i3{>
s*>4}
Xm^(
c@n%
!L%s
6J$~
n<kf
@n[e
5D2i
@WbN
c"<9
T+pL
9Ai_
kernel32.dll
gdi32.dll
user32.dll
ole32.dll
advapi32.dll
oleaut32.dll
SetUnhandledExceptionFilter
CreateFileA
CreateFileW
ReadFile
CloseHandle
SetFilePointer
GetFileSize
ExitProcess
CreateFileMappingA
CreateFileMappingW
LoadLibraryA
LoadLibraryW
LoadLibraryExA
LoadLibraryExW
FreeLibrary
GetProcAddress
LoadImageA
MapViewOfFile
UnmapViewOfFile
GetFileAttributesA
GetFileAttributesW
GetFileAttributesExW
GetModuleHandleA
GetModuleHandleW
GetModuleFileNameA
GetModuleFileNameW
GetLongPathNameA
GetLongPathNameW
SearchPathW
SearchPathA
AddFontResourceA
RemoveFontResourceA
FindFirstFileA
FindFirstFileW
FindClose
FindNextFileA
FindNextFileW
FindFirstFileExW
_lopen
OpenFile
_lread
_llseek
_lclose
CoCreateInstance
CoCreateInstanceEx
CoGetClassObject
GetPrivateProfileStringA
GetPrivateProfileIntA
GetPrivateProfileSectionNamesA
GetPrivateProfileSectionA
GetFileInformationByHandle
LockFile
LockFileEx
UnlockFile
UnlockFileEx
GetRecordInfoFromGuids
GetRecordInfoFromTypeInfo
LoadRegTypeLib
LoadTypeLib
CLSIDFromString
CLSIDFromProgID
CLSIDFromProgIDEx
RegCreateKeyExA
RegCreateKeyExW
RegCreateKeyA
RegCreateKeyW
OleLoadFromStream
LoadTypeLibEx
RegQueryValueA
RegOpenKeyA
RegOpenKeyExW
RegQueryValueExW
OleRegGetMiscStatus
InitializeCriticalSection
GetProcAddress
LocalFree
RaiseException
LocalAlloc
GetModuleHandleA
LeaveCriticalSection
EnterCriticalSection
GetCurrentDirectoryA
GetShortPathNameA
FindResourceExA
EnumResourceLanguagesA
ResumeThread
WriteProcessMemory
SetFileAttributesA
CreateDirectoryA
GetCurrentThreadId
GetPrivateProfileSectionA
KERNEL32.dll
DefWindowProcA
SetFocus
AdjustWindowRectEx
USER32.dll
RegSetValueA
RegCreateKeyA
RegCloseKey
ADVAPI32.dll
CoRegisterClassObject
ReadClassStm
ole32.dll
RtlUnwind
WideCharToMultiByte
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
WkaS
fmw8
"#7!G^ph7
}JVY
*B)JlD*
55"\[_
(o%S
W'of
nN<0
APoR
Gj5W
ImA"
$yoV
W*?#>(!
}_ZA
Q4O+
"ZLo
&<}/
zEHb
/jLjDey^
n3]Y
JKY=
_JQx
rRr|
a}|Q
:Xc>
|wfI
`FR>
==f"
PEPJ
\r$O.
gOY*
H@"=
%+6Tt
u uGT
Rs(-l
bwAP
2NsP
]A!04
3mnN
9,V!r
.*BH
f50C
&viV
a_-W
I.+tx=p
rL Yj7
,V74c
Fq|@
/_^C
NPJv
W"8`&}+
0,=e
Te%d
/I."
GvWk!
-eT^
H^(_
Al,>8
aNYs
cSFo
,\@:
lD(x
MwLTT
EDZH
J(xG
:xNG
j=2mE
}BNS
>p: q
mljw
[_"z
@E\.
di6M
gkA0d
KZwu