Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2023-Jun-13 19:46:53 |
Detected languages |
English - United Kingdom
English - United States |
Debug artifacts |
C:\Projects\Mars\Release\WIN32\lunpls.pdb
|
CompanyName | Dolphin Computer Access Ltd. |
FileDescription | SuperNova Magnifier and Speech |
FileVersion | 3293 |
LegalCopyright | ©1998-2023 Dolphin Computer Access Ltd. All rights reserved. |
PrivateBuild | 3293 |
ProductName | SuperNova |
ProductVersion | 3293 |
OriginalFilename | Lunpls.exe |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Unusual section name found: minATL |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Dolphin Computer Access Ltd
Issuer: Sectigo Public Code Signing CA R36 |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x140 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2023-Jun-13 19:46:53 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x2f3200 |
SizeOfInitializedData | 0xd62c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000B5FA (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2f5000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x105d000 |
SizeOfHeaders | 0x400 |
Checksum | 0x102478e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WebView2Loader.dll |
CreateCoreWebView2EnvironmentWithOptions
|
---|---|
DOL_IA2.dll |
?CloseWndProcHook@@YAXXZ
?OpenWndProcHook@@YAXXZ ?LocalSetupServer@@YAXXZ ?LocalCreateIAServer@@YAPAVia_server@@K_N@Z |
dol_touch.dll |
?GetTouchInjectedPosition@@YA_NHPAUtagPOINT@@@Z
?SwitchTouchStateSetting@@YAXPAUtouch_state_setting@@@Z ?GetInjectPointerId@@YAIPAUtouch_record@@@Z ?SimulateTouchInputFrame@@YAX_N@Z ?SimulateTouchInput@@YAXPAUtouch_record@@UtagPOINT@@H@Z ?TouchUpdateSettings@@YAXPAUtouch_settings@@@Z ?CloseTouchInput@@YAXXZ ?StartTouchInput@@YAHPAUtouch_state_setting@@@Z ?SwitchTouchInputDesktop@@YAXPAUtouch_state_setting@@PAX@Z ?TouchSupport@@YA_NXZ ?SuspendTouchCapture@@YAX_N@Z ?TouchDisplayChange@@YAXXZ ?FingersDown@@YA_NXZ ?GetLastTouchEventTime@@YA_JXZ ?TouchIsCaptured@@YA_NXZ |
dol_iupd2.dll |
?set_iupd_data@@YAHHJ@Z
?set_update_options@@YAXKKKK@Z dol_iupd_abort_timeout start_update2 dol_iupd_updating |
dol_pro.dll |
_dolpro_ConvertW@4
_dolpro_GetPromptD@4 _dolpro_DeletePrompts@0 _dolpro_LoadPrompts@20 _dolpro_GetPromptLabelW@4 _dolpro_IsUnicode@12 _dolpro_GetPromptW@4 _dolpro_DeleteStringD@4 |
dol_sit.dll |
?key_in_escape_mode_pressed@@3HA
?disconnect_add_to_tail@Tree@@QAEXPAV1@@Z ?add_to_tail@Tree@@QAEXPAV1@@Z ?create_mstring@@YAXPAPAVMSTRING@@PA_WPAUlocation@@EKE@Z ??2AreaExtra@@SAPAXI@Z ??3AreaExtra@@SAXPAXI@Z ??0AreaExtra@@QAE@XZ ??0AreaUnique@@QAE@XZ ??1AreaUnique@@QAE@XZ ?Copy@AreaUnique@@QAEXPAV1@@Z ?SetType@Area@@QAEXW4AREA_TYPE@@@Z ?sort_disconnect@Area@@QAEXXZ ?label_dom_areas@Area@@QAEXPAV1@@Z ?copy_tree@Area@@QAEPAV1@PAV1@@Z ?new_Area@@YAPAVArea@@PAV1@@Z ?new_Area@@YAPAVArea@@K@Z ?delete_Area@@YAXPAPAVArea@@@Z ?get_default_filter@Detect_Atlas@@QAEPAVDetectFilter@@W4AREA_TYPE@@@Z ?clear_pending_workkeys@@YAXXZ ?find_area@@YAPAVArea@@PAV1@00@Z ?DescribeSelection@Focus@@UAEKPAVUString@@PAUlevels@@@Z ?Determine_Control@Focus@@UAEPAVArea@@XZ ?OnSameControl@Focus@@UAEKXZ ?SaveControl@Focus@@UAEXXZ ?activate@Focus@@UAEHPAVArea@@K@Z ?additional_foci_info@Focus@@UAEHGPAVUString@@PAVBString@@PAVFocusInfo@@PAVArea@@PAUlevels@@@Z ?build_list_index@Focus@@UAEHJ@Z ?build_lists@Focus@@UAEHPAUsheet_list@@@Z ?create_list@Focus@@UAEXPAPAVlist_element@@0K@Z ?cursor_moved@Focus@@UAEHPAV1@@Z ?document_colour@Focus@@UAEKXZ ?getAutoTableHeading@Focus@@UAE_N_NPAVUString@@PAXPBUlevels@@@Z ?get_action_key@Focus@@UAEKKH@Z ?get_label@Focus@@UAEPA_WH@Z ?get_list_count@Focus@@UAEHXZ ?get_list_title@Focus@@UAEHPAPA_W@Z ?get_table_cells@Focus@@UAEHPAVUString@@PAVBString@@HHPAUlevels@@@Z ?get_text_column_heading@Focus@@UAEHPAVUString@@PAVBString@@PAVFocusInfo@@PAUlevels@@@Z ?get_text_paragraph@Focus@@UAEHPAPAVMSTRING@@@Z ?get_text_row_heading@Focus@@UAEHPAVUString@@PAVBString@@PAVFocusInfo@@PAUlevels@@@Z ?get_text_selection@Focus@@UAEHPAPA_W@Z ?get_text_sentence@Focus@@UAEHPAPAVMSTRING@@@Z ?list_capabilities@Focus@@UAEHXZ ?list_id@Focus@@UAEKK@Z ?move_live@Focus@@UAEHPAVReaderSituation@@K@Z ?same_object@Focus@@UAEHPAV1@PAVArea@@@Z ?select_list_item@Focus@@UAEHPAVlist_element@@JJ@Z ?specialPreferences@Focus@@UAEKH@Z ?label_scan_dom@@3PAUlabel_info@@A ?label_store@@3Vwps_label_data@@A ?Append@MSTRING@@QAEHPA_W@Z ??0AreaExtra@@QAE@JJPA_W0JJ@Z ?default_mchar@@3UMCHAR@@B ?LPFNAccessibleObjectFromWindow@@3P6GJPAXKABU_GUID@@PAPAX@ZA ?NewString@@YAXPAPADH@Z ?set_link@MSTRING@@QAEXK@Z ?SetFromDetector@AreaUnique@@QAEXHKKPA_W@Z ?SetFromDom@AreaUnique@@QAEXHKKPA_W@Z ?winhook_sit@@3PAUWINHOOK_SIT@@A ?disconnect_add_after@Tree@@QAEXPAV1@@Z ?move_to_head@Tree@@QAEXXZ ?wait_allowing_sendmessage@@YAKPAPAXK@Z ?Insert@MSTRING@@QAEXPAUMCHAR@@H@Z ?current_dynamic_hotkeys_mode@@3KA ?terminal_server@@3HA ??0Tree@@QAE@PAV0@@Z ??1Tree@@UAE@XZ ?disconnect@Tree@@QAEXXZ ?add_group_to_tail@Tree@@QAEXPAV1@@Z ?first_line@Area@@QAEPAV1@H@Z ?osm_startup@@YAHPA_W0PAUmain_config@@H0HHH@Z ?detect_startup@@YAXXZ ?sit_memory_heap_diagnostic@@YAXXZ ?dol_sit_dll_startup@@YAXP6AEPAXJ@ZP6GHXZP6APAVOutput_Atlas@@PAVApplic@@PAH@ZP6AXK@ZP6APA_WK@ZP6AXPAPA_WH@Z@Z ?dol_sit_dll_closedown@@YAXXZ ?dol_video_version@@3KA ?dol_boot_version@@3KA ?cbar_version@@3KA ?cbar_server_version@@3KA ?truefonts_flag@@3PA_WA ?get_rsit_workkeys@WorkKeyItem@@QAEXPAURSIT_WORKKEYINFO@@PAV1@@Z ?SetLastUsed@WorkKeyList@@QAEXJ@Z ?get_workkey_item@WorkKeyList@@QAEXPAPAVWorkKeyItem@@@Z ?unget_workkey_item@WorkKeyList@@QAEXPAVWorkKeyItem@@@Z ?ignore_all_for_key_echo@WorkKeyList@@QAEXXZ ?add_to_sit_workkeys@@YAXPATKEYPRESS@@K@Z ?window_scan@@YAXK@Z ?osm_shutdown@@YAXXZ ?stop_detections@@YAXXZ ?refresh_screen@@YAXXZ ?detect_close@@YAXXZ ?open_situation@@YAXPAVSituation@@@Z ?close_situation@@YAXPAVSituation@@@Z ?delete_situation@@YAXPAVSituation@@@Z ?init_detection_scripts@@YAXK@Z ?close_hook_threads@@YAXH@Z ?local_SendMessage@@YAXPAUlocal_smessage@@H@Z ?dol_sit_dwm_hook_loader@@YAJK_NPA_W@Z ?process_cleanup@@YAXXZ ?delete_atlas_list@@YAHXZ ?winhook_sit_zero@@3UWINHOOK_SIT@@A ?Sit_workkeys@@3PAVWorkKeyList@@A ?h_reader_complete@@3PAXA ?end_session@@3HA ?UniversalDrives@@YAXXZ ?reconnect_hooks@@YAXXZ ?do_sit_crash@@3HA ?compare@MSTRING@@QAEHPAV1@@Z ?scripting_lock@@YA_NXZ ?scripting_unlock@@YAXXZ ?get_rule_head@Detect_Atlas@@QAEPAPAVDetRule@@HH@Z ?prev_object@Area@@QAEPAV1@H@Z ?next_line@Area@@QAEPAV1@H@Z ?prev_line@Area@@QAEPAV1@H@Z ?next_segment_in_object@Area@@QAEPAV1@H@Z ?next_segment@Area@@QAEPAV1@H@Z ?prev_segment_on_line@Area@@QAEPAV1@H@Z ?last_segment@Area@@QAEPAV1@H@Z ?next_vf@Area@@QAEPAV1@PAV1@@Z ?UIA_Command@@YAHHJ@Z ?determine_scroll@Area@@QAEXPAV1@K@Z ?init_workkeyinfo@@YAXPAURSIT_WORKKEYINFO@@@Z ??2OSMBeamFocus@@SAPAXI@Z ??3OSMBeamFocus@@SAXPAXI@Z ??0OSMBeamFocus@@QAE@PAUlocation@@PAVSHAPEHANDLE@@@Z ??0OSMBeamFocus@@QAE@PAV0@PAULIST3@@@Z ??2OSMColourFocus@@SAPAXI@Z ??3OSMColourFocus@@SAXPAXI@Z ?disconnect@List3@@QAEXXZ ?sysc@@3USYS_COLOURS@@A ?prompt_from_colour@@YAHK@Z ?compare_i_string@@YAHPA_W0@Z ?move_element@List2@@QAEXH@Z ?move_to_tail@List2@@QAEXXZ ??0Action_keytest@@QAE@PAPAV0@0@Z ?NewString@@YAXPAPADPA_W@Z ??0OSMColourFocus@@QAE@KPAUlocation@@K@Z ??0OSMColourFocus@@QAE@PAV0@PAULIST3@@@Z ??1OSMColourFocus@@UAE@XZ ?set_applic@@YAPAVApplic@@PAX@Z ?CompareType@OSMColourFocus@@UAEKXZ ?GetString@MSTRING@@QAEXPAPA_W@Z ?get_default_windetrules@@YAXPAVDetect_Atlas@@@Z ?interceptor_fail@@3HA ?string_gap@@3HA ?detectext@@3PA_WA ?reader_quit_flag@@3HA ?ready_for_scripts@@3HA ?ReaderThreadHandle@@3PAXA ?reader_ready@@3HA ?is_rtl@@3HA ?state_info@@3PAUSTATE_INFO@@A ?SetString@@YAXPAPA_WH@Z ?save_changed_detect_atlases_now@@YAKXZ ?load_detect_atlas_list@@YAHP6AXPA_W0H@ZHPAVWatchDog@@@Z ?process_init@@YAX_N@Z ?list_current_applications@@YAXK@Z ?application_detect_atlas_link@@YAXXZ ?open_applic@@YAPAVApplic@@PAV1@@Z ?close_applic@@YAXPAPAVApplic@@@Z ?find_applic@@YAPAVApplic@@KK@Z ?current_applic@@YAPAVApplic@@XZ ?module_name@Applic@@QAEPADKK@Z ?focus_method_info@@3PAUFOCUS_METHOD_INFO@@A ?find_type@Area@@QAEPAV1@W4AREA_TYPE@@@Z ?sort_parent@Area@@QAEPAV1@H@Z ?get_label@Area@@QAEPAV1@PAV1@H@Z ?set_detection_profile@@YAXJ@Z ?AddString@@YAXPAPA_WPA_W11@Z ?mc_tab@@3UMCHAR@@A ?mc_space@@3UMCHAR@@A ?find_ime_on_top@Situation@@QAEPAVArea@@PAV2@@Z ?find_a_focus@Situation@@QAEPAVFocus@@HPAUlocation@@PAVArea@@@Z ?locate_smallest_object@Area@@QAEPAV1@PAUlocation@@@Z ?find_next_type_in_loc@Area@@QAEPAV1@W4AREA_TYPE@@PAUlocation@@HPAV1@@Z ?find_first_type_in_loc@Area@@QAEPAV1@W4AREA_TYPE@@PAUlocation@@H@Z ?Compare@AreaUnique@@QAE_NPAV1@_N@Z ?Append@MSTRING@@QAEXPAUMCHAR@@@Z ?Get@MSTRING@@QAEPAUMCHAR@@H@Z ??1MSTRING@@QAE@XZ ??0MSTRING@@QAE@PAV0@@Z ??0MSTRING@@QAE@H@Z ??3MSTRING@@SAXPAXI@Z ??2MSTRING@@SAPAXI@Z ?product_serial@@3PA_WA ?dolphinpath@@3PA_WA ?dolphin_flag@@3PA_WA ?shrink_string@@YAPADPA_W@Z ?NewString@@YAXPAPADPAD@Z ?get_lockrule@@YAXPAULOCKRULE@@@Z ?copy@AtlasLog@@QAEPAV1@PAPAV1@0@Z ?Save@AtlasRule@@QAEXPAX@Z ?copy@AtlasRule@@QAEPAV1@PAVAtlas@@@Z ?compare@LockRule@@QAEHPAV1@@Z ?Save@LockRule@@QAEXPAX@Z ?copy@LockRule@@QAEPAV1@PAVAtlas@@@Z ?custom_defaultspath@@3HA ?defaultspath@@3PA_WA ?custom_settingspath@@3HA ?truefonts_access@@3PA_WA ?special_access@@3PA_WA ?section_names_len@@3HA ?section_names@@3PAPA_WA ?DETECTFILTERCP_defaults@@3UDETECTFILTERCP@@A ?detect_atlas_head@@3PAVDetect_Atlas@@A ?dumpindent@@3HA ?dump@@3PAXA ?area_type_from_index@@3PAW4AREA_TYPE@@A ?detect_unlock@@YAXXZ ?detect_lock@@YAXH@Z ?FastCloseFile@@YAXPAX@Z ?ReadSectionData@@YAXPAX0KKHPAD@Z ?ReadSection@@YAGPAX@Z ?fileerror@@YAHPAX@Z ?ReadFromFile@@YAHPAX0K@Z ?FastOpenFileRead@@YAPAXPA_W@Z ?WriteToFile@@YAHPAX0K@Z ?FastCloseFileWrite@@YAXPAX@Z ?FastOpenFileWrite@@YAPAXPA_WH@Z ?WriteSectionEnd@@YAXPAX@Z ?WriteSection@@YAXPAXG@Z ?WriteString@@YAXPAXGPA_W@Z ?WriteString@@YAXPAXGPAD@Z ?ReadSetData@@YAHPAXGPAUATLAS_LINE@@H0@Z ?ReadSkipData@@YAXPAX@Z ?ReadSkipSection@@YAXPAX@Z ?ReadData@@YAXPAX0KK@Z ?WriteData@@YAXPAXGH0@Z ?WriteDataBlock@@YAXPAXGH0@Z ?WriteSetData@@YAXPAXPAUATLAS_LINE@@KPAD@Z ?SetupStructure@@YAGPAUATLAS_LINE@@H@Z ?compare_string@@YAHPA_W0@Z ?compare_string@@YAHPAD0@Z ?MatchPattern@@YAHPA_W0PAH@Z ?AddString@@YAXPAPA_WPAD@Z ?AddString@@YAXPAPA_WPA_W@Z ?NewString_CopyNULL@@YAXPAPA_WPA_W@Z ?NewString@@YAXPAPA_WH@Z ?NewString@@YAXPAPA_WPAD@Z ?DeleteString@@YAXPAPAD@Z ?SetString@@YAXPAPA_WPAD@Z ?SetString@@YAXPAPADPA_W@Z ?SetupActionPointers@@YAKPAPAVAction@@PAV1@@Z ?get_settings_guid@@YAHPA_W0PAU_GUID@@@Z ?get_detect_atlas@@YAPAVDetect_Atlas@@PAVApplic@@@Z ?get_atlas@@YAPAVAtlas@@PAV1@PAVApplic@@K@Z ?scan_and_load_detect@@YAXPA_W0PAPAVAtlas@@HKP6GXXZHPAXP6GH30@ZH@Z ?decrypt_ser@AtlasLog@@QAEXXZ ??0AtlasLog@@QAE@PAPAV0@0@Z ?compare@AtlasRule@@QAEHPAV1@@Z ??0AtlasRule@@QAE@PAVAtlas@@@Z ??0LockRule@@QAE@PAVAtlas@@@Z ?Save@Action@@QAEXPAX@Z ??0Action@@QAE@PAPAV0@0@Z ??0Operation@@QAE@PAPAV0@0@Z ?application_output_atlas_link@@YAXXZ ?applic_now@@YAPAVApplic@@XZ ?self_applic@@YAPAVApplic@@XZ ?set_output_atlas@Applic@@QAEXXZ ??1Tree2@@UAE@XZ ??0Tree2@@QAE@PAV0@@Z ?add_to_tail@List2@@QAEXPAPAV1@0@Z ?colour_compare@@YAHKK@Z ??1List2@@UAE@XZ ??0List2@@QAE@PAPAV0@0@Z ?new_vgroup_container@@YAHPAPAVArea@@PAV1@@Z ?get_sorttype@@YAHPAVArea@@HH@Z ?next_segment_on_line@Area@@QAEPAV1@H@Z ?first_segment_in_object@Area@@QAEPAV1@H@Z ?first_segment_on_line@Area@@QAEPAV1@H@Z ?next_line_in_object@Area@@QAEPAV1@H@Z ?FindPhysicalFocus@Focus@@UAEXPAVReaderSituation@@@Z ?ReportAreas@Focus@@UAEXXZ ?SetupLocation@Focus@@UAEXPAVFocusInfo@@@Z ?get_ime@Focus@@UAEHPAUIME_INFO@@PAV1@@Z ?get_virtualfocus@Focus@@UAEPAVVirtualFocus@@XZ ?match@OSMColourFocus@@UAEHPAVFocusRule@@PAUlocation@@@Z ?move_to_head@List3@@QAEXXZ ?in_area@Area@@QAEHW4AREA_TYPE@@@Z ?compare_mchar_attrs@@YAHPAUMCHAR@@0@Z ?create_nav_sort@Area@@QAEXHH@Z ??0Focus@@QAE@KPAULIST3@@@Z ??1Focus@@UAE@XZ ?remove_from_all@@YAXPAVAtlas@@0@Z ??4List2@@QAEAAV0@ABV0@@Z ?SetAltDesktopActive@@YAXH@Z ?Clear_AltD_Thread@@YAXXZ ?extra_pos@Area@@QAEXJJ@Z ?prev_vf_object@Area@@QAEPAV1@PAV1@@Z ?next_vf_object@Area@@QAEPAV1@PAV1@@Z ??1List3@@UAE@XZ ?set_applic@@YAXPAVApplic@@@Z ??0List3@@QAE@PAULIST3@@@Z ?add_to_log@@YAXPA_W00_N@Z ??2Operation@@SAPAXI@Z ?last_line_in_same_column@Area@@QAEPAV1@XZ ?number_of_lines_in_column@Area@@QAEHXZ ?is_first_in_textlink@Area@@QAEHXZ ?prev_vf@Area@@QAEPAV1@PAV1@@Z ?compare_monitor_marker@Area@@QAEHPAV1@@Z ?fast_user_switch_osm_reinit@@YAX_N0@Z ??3Operation@@SAXPAXI@Z ?remove_from_all@@YAXPAVApplic@@PAVAtlas@@@Z ??0Detect_Atlas@@QAE@XZ ?Overwrite@AtlasRule@@QAEXPAV1@@Z ?copy@AtlasRule@@QAEXPAVApplic@@@Z ??0AtlasRule@@QAE@PAVApplic@@PAVAtlas@@@Z ?find_applic@@YAPAVApplic@@PAVAtlasRule@@@Z ?ExactMatchPattern@@YAPA_WPA_W@Z ?disconnect@List2@@QAEXXZ ?move_to_head@List2@@QAEXXZ ?graphicext@@3PA_WA ?dump_detect_atlasfile@@YAXPA_W0K@Z ?next_object@Area@@QAEPAV1@H@Z ?NewString@@YAXPAPA_WPA_W@Z ?ReceiveWnd@@3PAXA ?load_detect_atlas_file@@YAPAVAtlas@@PA_W0KHPAV1@@Z ?DeleteString@@YAXPAPA_W@Z ?SetString@@YAXPAPA_WPA_W@Z ?ReaderThreadId@@3KA ?set_detect_atlas@Applic@@QAEXXZ ?first_application@@YAPAVApplic@@XZ ?unlist_current_applications@@YAXK@Z ?process_lock@@YAXH@Z ?process_unlock@@YA_NH@Z ??1Operation@@UAE@XZ ?compare@DetectFilter@@QAEHPAV1@@Z ?video_intercepted@@YAHXZ ?gfx_atlas_head@@3PAVDetect_Atlas@@A ?Compare@OSMColourFocus@@UAEHPAVFocus@@@Z ?SetString@@YAXPAPADPAD@Z ?current_hotkeys_mode@@3KA ?settingspath@@3PA_WA ?ReaderWnd@@3PAXA ?area_data@@3PAUAREA_INFO@@A ??0Action@@QAE@PAV0@PAPAV0@1@Z ??0Operation@@QAE@PAV0@PAPAV0@1@Z ?untrained_gfx_head@@3PAVDetect_Atlas@@A |
DOL_OSM.dll |
?start_watchdog@@YAXK@Z
?init_watchdog@@YAXXZ ?Modify@WatchDog@@QAEXPA_WJIPAX_N@Z ?Exception_message@@3PA_WA #146 #141 ?init_region_handle_tracker@@YAXXZ #142 ?osm_memory_heap_diagnostic@@YAXXZ ?timestamp_start@@YAXH@Z ?osm_check_dolvideo@@YAHPAK0@Z ?CreateSharedSemaphoreW@@YAPAXPAU_SECURITY_ATTRIBUTES@@JJPB_W@Z ?CreateEllipticRegion@@YAPAXHHHH@Z ?CreatePolyRegion@@YAPAXPBUtagPOINT@@HH@Z ?CreateRgnIndirect@@YAPAXPAUtagRECT@@@Z ?CreateRgn@@YAPAXHHHH@Z ?DeleteRegionObject@@YAHPAX@Z #144 #145 ?loc_box@@YAXPAUtagRECT@@PAUlocation@@@Z ?region_or_loc@@YAXPAXPAUlocation@@@Z ?resume_messages@@YAXXZ ?pause_messages@@YAXXZ ?timestamp_dump@@YAXH@Z ??0osm_lock@@QAE@H@Z ?OpenSharedEventW@@YAPAXKHPB_W@Z ?OpenSharedMutexW@@YAPAXKHPB_W@Z ?CreateSharedEventW@@YAPAXPAU_SECURITY_ATTRIBUTES@@HHPB_W@Z ?CreateSharedMutexW@@YAPAXPAU_SECURITY_ATTRIBUTES@@HPB_W@Z ?CreateSharedFileMappingW@@YAPAXPAXPAU_SECURITY_ATTRIBUTES@@KKKPB_W@Z ?FindBasefontByName@Base_font@@SA_NP6A_NPAXPAV1@@Z0PB_W@Z ?loc_in_loc@@YAKPAUlocation@@0@Z ??1WatchDog@@QAE@XZ ??0WatchDog@@QAE@PA_WJIPAX_N@Z ?loc_and_rect@@YAHPAUlocation@@PAUtagRECT@@@Z ?copy_loc@@YAXPAUlocation@@PAUtagRECT@@@Z ?loc_equal_loc@@YAHPAUlocation@@0@Z ?offset_loc@@YAXPAUlocation@@HH@Z ?loc_or_rect@@YAXPAUlocation@@PAUtagRECT@@@Z ?empty_loc@@YAXPAUlocation@@@Z ?copy_loc@@YAXPAUlocation@@0@Z ?move_loc@@YAXPAUlocation@@0@Z ?init_loc@@YAXPAUlocation@@@Z ?osm_struct@@3PAUosmshare@@A ?add_exception_message@@YAXPA_W@Z ?enable@WatchDog@@QAE_NXZ ?disable@WatchDog@@QAE_NXZ ?timestamp@@YAXPA_WH@Z ?heartbeat@WatchDog@@QAEXXZ ?location_empty@@YAHPAUlocation@@@Z ?location_combine_loc@@YAKPAUlocation@@0H@Z ?loc_compare_loc_offset@@YAKPAUlocation@@0HHJ@Z ?delete_loc_region@@YAXPAUlocation@@@Z ?init_loc@@YAXPAUlocation@@PAUtagRECT@@@Z ?loc_compare_loc@@YAKPAUlocation@@0J@Z ?winhook@@3PAVWinHook@@A ??0WatchDog@@QAE@PA_WIPAXJ1@Z ?pointin_loc@@YAKPAUtagPOINT@@PAUlocation@@@Z ?Dump@WatchDog@@QAEXXZ ?displayRect@@3UtagRECT@@A ?loc_intersect_hrgn@@YAHPAUlocation@@PAX@Z ?lock@osm_lock@@QAE_NHK@Z ?rect_compare_loc@@YAKPAUtagRECT@@PAUlocation@@J@Z ?rect_compare_rect@@YAKPAUtagRECT@@0J@Z #143 ??1osm_lock@@QAE@XZ |
dol_mem.dll |
?dol_new@@YAPAXI@Z
?newdel_memory_heap_startup@@YAXXZ ?newdel_memory_heap_cleanup@@YAXXZ ?newdel_memory_heap_diagnostic@@YAXXZ ?log_open@@YAXK@Z ?log_close@@YAXXZ ?newdel_memory_heap_management@@YAXXZ ?log_printf@@YAXKPBDZZ ?dol_delete@@YAXPAX@Z ?log_printf@@YAXKPB_WZZ |
SAM32.dll |
#8
#9 #46 #45 #14 #16 #4 #17 #5 #1 #10 #11 #2 #12 #13 #6 #3 #15 #31 #43 #32 #18 #7 |
COMCTL32.dll |
ImageList_GetIconSize
InitCommonControlsEx ImageList_AddMasked ImageList_Destroy ImageList_Remove ImageList_ReplaceIcon ImageList_Create PropertySheetW #413 #410 HIMAGELIST_QueryInterface ImageList_DrawIndirect |
OLEACC.dll |
ObjectFromLresult
|
CFGMGR32.dll |
CM_Get_Child
CM_Get_Child_Ex CM_Request_Device_Eject_ExW CM_Locate_DevNode_ExW CM_Locate_DevNodeW CM_Get_Sibling_Ex CM_Get_Sibling CM_Get_Device_Interface_List_SizeW CM_Get_Device_Interface_ListW CM_Get_DevNode_Status_Ex CM_Get_DevNode_Status CM_Get_DevNode_Registry_Property_ExW CM_Get_DevNode_Registry_PropertyW CM_Get_Device_ID_List_Size_ExW CM_Get_Device_ID_List_ExW CM_Get_Device_ID_ExW CM_Get_Device_IDW |
RPCRT4.dll |
RpcStringFreeA
NdrServerCall2 NdrClientCall2 RpcMgmtIsServerListening RpcEpResolveBinding RpcServerRegisterIfEx RpcServerUnregisterIfEx RpcServerUseProtseqEpW RpcSmDestroyClientContext RpcBindingFree RpcStringFreeW RpcStringBindingComposeW RpcBindingFromStringBindingW |
SHLWAPI.dll |
PathAppendW
AssocQueryStringW SHCreateStreamOnFileW SHCopyKeyW UrlUnescapeW StrStrIW |
WTSAPI32.dll |
WTSFreeMemory
WTSEnumerateProcessesA WTSEnumerateProcessesW |
PSAPI.DLL |
GetModuleFileNameExW
GetModuleFileNameExA |
WINMM.dll |
sndPlaySoundW
PlaySoundW |
DOL_BB.dll |
dol_bb_invalid_parameter_handler
SetExceptionMessage InitialiseCrashHandler SetInvalidParameterHandler |
XmlLite.dll |
CreateXmlReader
|
dwmapi.dll |
#102
DwmEnableMMCSS DwmIsCompositionEnabled |
msi.dll |
#113
|
Cabinet.dll |
#21
#20 #23 #22 |
KERNEL32.dll |
VirtualAlloc
GetSystemInfo GetTempPathA GetTimeFormatW GetDateFormatW ResetEvent GetExitCodeProcess LoadLibraryA GetExitCodeThread SetThreadPriority SwitchToThread ExitProcess InitializeCriticalSectionEx RaiseException DecodePointer GetCurrentProcess GetProcessHeap HeapFree HeapReAlloc HeapAlloc DuplicateHandle GetPrivateProfileIntW MoveFileW WritePrivateProfileStringW GetVersionExA DeviceIoControl SetFileTime ProcessIdToSessionId WaitForMultipleObjects OpenEventW OutputDebugStringW GetTempFileNameW LocalAlloc GetModuleHandleW Thread32Next ReleaseSemaphore GlobalFree GlobalLock GlobalUnlock GlobalAlloc GetDateFormatEx FileTimeToSystemTime GetFileTime RemoveDirectoryW CopyFileW FormatMessageW LocalFree Sleep DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection SetLastError K32GetProcessMemoryInfo GetCurrentThread MulDiv OpenFileMappingW GetModuleFileNameW DebugBreak GetPrivateProfileStringW GetCurrentThreadId CreateMutexW WaitForSingleObject ReleaseMutex FindResourceW SizeofResource LockResource LoadResource GetTickCount64 MoveFileExW DosDateTimeToFileTime GetTempPathW WriteFile SetFilePointer SetFileInformationByHandle ReadFile LocalFileTimeToFileTime GetDiskFreeSpaceExW CreateFileW CreateFileA CreateDirectoryW GetProcessId GetTickCount Process32NextW Process32FirstW CreateToolhelp32Snapshot K32GetModuleFileNameExW OpenProcess GetCurrentProcessId SystemTimeToFileTime GetSystemTime DeleteFileW SetFileAttributesW GetFileAttributesW FindNextFileW FindFirstFileW SetEndOfFile CompareFileTime UnmapViewOfFile MapViewOfFile CreateFileMappingW CreateEventW SetEvent CloseHandle Beep LoadLibraryW GetProcAddress FreeLibrary GetLastError Module32FirstW Module32NextW SetErrorMode LoadLibraryExW CreateRemoteThread ReadProcessMemory GetDriveTypeW GetLogicalDriveStringsW GetProcessTimes TerminateThread ResumeThread FreeLibraryAndExitThread GetModuleHandleExW GetStdHandle GetFileType WriteConsoleW GetTimeZoneInformation IsValidLocale EnumSystemLocalesW GetConsoleCP GetConsoleMode SetFilePointerEx ReadConsoleW SetConsoleCtrlHandler FindFirstFileExW IsValidCodePage GetOEMCP GetCommandLineA GlobalMemoryStatus GetThreadLocale K32EnumProcesses K32EnumProcessModules K32GetModuleBaseNameW ExitThread GetFileSizeEx CreateProcessW GetStartupInfoW GetSystemDirectoryW GetLocalTime GetModuleHandleA GetVersionExW QueryPerformanceCounter QueryPerformanceFrequency VerSetConditionMask GetCommandLineW ExpandEnvironmentStringsW SetCurrentDirectoryW SetProcessShutdownParameters SetThreadIdealProcessor GetProcessAffinityMask GlobalDeleteAtom GlobalAddAtomW VerifyVersionInfoW FileTimeToLocalFileTime OpenSemaphoreW GetSystemTimeAsFileTime MultiByteToWideChar SetProcessAffinityMask GetACP GetUserDefaultLCID CreateThread GetPrivateProfileStringA WideCharToMultiByte TerminateProcess GetModuleFileNameA SetThreadExecutionState GetVolumeInformationW TlsAlloc TlsGetValue TlsSetValue GetNativeSystemInfo GlobalFindAtomW GetComputerNameW GlobalGetAtomNameW GetWindowsDirectoryW GetVolumeNameForVolumeMountPointW SetLocalTime SetSystemTime WritePrivateProfileStructW VirtualQuery InterlockedFlushSList InterlockedPushEntrySList RtlUnwind GetCPInfo GetLocaleInfoW LCMapStringW CompareStringW TlsFree EncodePointer GetStringTypeW InitializeSListHead SetUnhandledExceptionFilter UnhandledExceptionFilter IsDebuggerPresent IsProcessorFeaturePresent WaitForSingleObjectEx GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW SetStdHandle InitializeCriticalSectionAndSpinCount VirtualFree GetFileSize Thread32First CreateSemaphoreW HeapSize FlushFileBuffers FindClose |
USER32.dll |
GetDlgItemTextA
SetDlgItemTextA SetWindowTextA EnumDisplaySettingsA DestroyIcon mouse_event EmptyClipboard SetClipboardData EndPaint BeginPaint DrawTextExW SendMessageA RegisterPowerSettingNotification GetDlgItemInt ShutdownBlockReasonDestroy ShutdownBlockReasonCreate wvsprintfW ExitWindowsEx GetPhysicalCursorPos SetPhysicalCursorPos SetCursorPos ShowCursor EnumDisplayDevicesW SendMessageTimeoutW ChangeWindowMessageFilterEx ChangeWindowMessageFilter RegisterWindowMessageW GetWindowContextHelpId GetClipboardData CloseClipboard OpenClipboard UnregisterHotKey RegisterHotKey MsgWaitForMultipleObjects UnionRect GetGUIThreadInfo UnhookWinEvent SetWinEventHook InflateRect IsChild PeekMessageW DispatchMessageW TranslateMessage GetMessageW IsWindowUnicode IntersectRect UnregisterClassW FillRect RemovePropW SetPropW GetAncestor UnhookWindowsHookEx PostQuitMessage IsWindow GetProcessWindowStation EnumWindowStationsW OpenWindowStationW EnumDesktopsW OpenInputDesktop OpenDesktopW GetUserObjectInformationW GetThreadDesktop CloseDesktop IsRectEmpty SetDlgItemInt SetForegroundWindow CreateDialogIndirectParamW RegisterClassW DrawFrameControl DialogBoxIndirectParamW DialogBoxParamW MoveWindow GetWindowTextLengthW CreateIconIndirect DrawIconEx LoadCursorFromFileW DrawFocusRect GetSysColorBrush ScreenToClient DestroyCursor LoadBitmapW ReleaseCapture SetCapture CallWindowProcW SetCursor GetDlgItemTextW MapWindowPoints SetWindowTextW GetAsyncKeyState IsDialogMessageW LoadIconW CheckMenuRadioItem CallNextHookEx SetWindowsHookExW CopyRect SetRectEmpty WindowFromPoint ClientToScreen GetClientRect RedrawWindow InvalidateRgn RemoveMenu GetMenuItemCount CheckMenuItem CreateMenu GetMenuState GetMenuStringW GetMenu IsWindowEnabled SendInput GetDialogBaseUnits GetDlgCtrlID CreateDialogParamW GetWindowPlacement CreateWindowExW wsprintfA GetGuiResources GetWindow GetTopWindow GetClassNameW EnumChildWindows GetDesktopWindow EndDialog DestroyWindow GetCursorPos CreatePopupMenu EnableWindow IsClipboardFormatAvailable GetParent InvalidateRect UpdateWindow KillTimer SetTimer GetKeyState SetDlgItemTextW TrackMouseEvent GetCursorInfo GetWindowThreadProcessId EnumWindows FindWindowW GetWindowTextW GetForegroundWindow SetMenuItemInfoW GetMenuItemInfoW InsertMenuItemW TrackPopupMenu DeleteMenu EnableMenuItem DestroyMenu LoadMenuW GetFocus SetFocus SendDlgItemMessageW GetRawInputData GetWindowRect SetMenu GetSystemMetrics GetDlgItem SetWindowPos ShowWindow SendMessageW PostThreadMessageW ReleaseDC GetDC SystemParametersInfoW PtInRect GetSysColor GetDoubleClickTime MessageBoxW AllowSetForegroundWindow AppendMenuW LoadImageW LoadCursorW SetWindowLongW GetWindowLongW RegisterClassExW DefWindowProcW OffsetRect MessageBeep EqualRect wsprintfW MapVirtualKeyW keybd_event PostMessageW IsWindowVisible |
GDI32.dll |
CreateRectRgn
SetMapMode EqualRgn RectInRegion GetRegionData OffsetRgn GetPixel GetCharABCWidthsW ExtEscape SetDIBColorTable GetDIBColorTable GetSystemPaletteEntries GetPaletteEntries GetObjectType GetNearestPaletteIndex GetDIBits GetCurrentObject CreatePalette GetCharWidth32W Rectangle EnumFontFamiliesExW CreateFontW TextOutW GetTextMetricsW EnumFontFamiliesW CreateDCW CreateDIBSection CreateBitmap GetObjectW SetStretchBltMode StretchBlt SetBkColor ExtTextOutW SetTextAlign SetTextColor SetBkMode SelectObject RoundRect PatBlt GetTextExtentPoint32W GetStockObject GetRgnBox GetDeviceCaps GetClipRgn DeleteDC CreateSolidBrush CreatePen CreateFontIndirectW CreateCompatibleDC CreateCompatibleBitmap BitBlt GdiFlush DeleteObject CombineRgn |
COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW ChooseColorW |
ADVAPI32.dll |
RegLoadKeyW
GetSidIdentifierAuthority GetSidSubAuthority GetSidSubAuthorityCount GetTokenInformation IsValidSid LookupAccountNameW LookupPrivilegeValueW RegCreateKeyW SetSecurityInfo LookupSecurityDescriptorPartsW BuildExplicitAccessWithNameW CloseServiceHandle OpenSCManagerW OpenServiceW QueryServiceStatus GetSecurityDescriptorSacl SetNamedSecurityInfoA ConvertStringSecurityDescriptorToSecurityDescriptorA ConvertStringSecurityDescriptorToSecurityDescriptorW GetSecurityDescriptorDacl CloseEventLog OpenEventLogW ReadEventLogW RegLoadAppKeyW RegQueryValueExA RegEnumKeyExA RegOpenKeyExA CryptAcquireContextW CryptGetHashParam RegCloseKey RegOpenKeyExW RegQueryValueExW RegCreateKeyExW RegDeleteValueW RegSetValueExW RegDeleteKeyW RegEnumKeyExW RegQueryInfoKeyW GetUserNameW CreateWellKnownSid SetEntriesInAclW GetNamedSecurityInfoW SetNamedSecurityInfoW RegEnumValueW RegFlushKey FreeSid RegUnLoadKeyW OpenProcessToken AdjustTokenPrivileges AllocateAndInitializeSid CheckTokenMembership CryptCreateHash QueryServiceStatusEx DeleteService CreateServiceW StartServiceW ControlService RegSetKeySecurity RegSaveKeyW RegRestoreKeyW CryptHashData |
SHELL32.dll |
ShellExecuteW
Shell_NotifyIconW SHGetMalloc ShellExecuteExW #165 SHGetFolderPathW SHGetKnownFolderPath SHCreateDirectoryExW SHGetPathFromIDListW SHGetSpecialFolderPathW SHBrowseForFolderW |
ole32.dll |
CoCreateGuid
CoCreateInstance CoTaskMemFree CLSIDFromProgID CoInitialize CoInitializeEx CoInitializeSecurity CreateStreamOnHGlobal CoGetInterfaceAndReleaseStream CoMarshalInterThreadInterfaceInStream CoUninitialize |
OLEAUT32.dll |
SysAllocString
BSTR_UserUnmarshal BSTR_UserFree BSTR_UserSize BSTR_UserMarshal SysFreeString SysAllocStringLen VariantInit SafeArrayDestroy SafeArrayGetElement VariantClear VariantTimeToSystemTime SysStringLen SafeArrayCreate SafeArrayCopy |
WindowsCodecs.dll |
WICConvertBitmapSource
|
DWrite.dll |
DWriteCreateFactory
|
POWRPROF.dll |
GetPwrCapabilities
|
IPHLPAPI.DLL |
GetAdaptersInfo
|
WININET.dll |
InternetSetOptionW
InternetGetConnectedState InternetAttemptConnect HttpSendRequestA HttpOpenRequestA InternetReadFile InternetOpenUrlA InternetConnectA InternetOpenA InternetCloseHandle |
Ordinal | 1 |
---|---|
Address | 0x176c |
Ordinal | 2 |
---|---|
Address | 0x1c4e |