Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-May-20 01:16:27 |
Detected languages |
Chinese - Taiwan
English - United States |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for Qemu presence:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | This PE is packed with VMProtect |
Unusual section name found: .vmp0
Unusual section name found: .vmp1 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2020-May-20 01:16:27 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x5d5600 |
SizeOfInitializedData | 0xcf1000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000017FBE2B (Section: .vmp1) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x267e000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
ExitProcess
GetLastError FreeLibrary GetProcessHeap GetProcAddress HeapAlloc LoadLibraryA VirtualAlloc lstrlenW CreateFileW SetLastError HeapFree LocalFree FindResourceW GetCurrentProcess TerminateProcess GetModuleFileNameW GetTempPathW FindClose VirtualFree Sleep RtlUnwind GetVolumeInformationW SetUnhandledExceptionFilter GetTickCount GetTempFileNameW WideCharToMultiByte CopyFileW CreateProcessW GetCurrentProcessId GetWindowsDirectoryW CloseHandle CreateThread LoadLibraryW DeleteFileW MultiByteToWideChar OpenProcess ResumeThread K32GetProcessImageFileNameW GetCurrentThreadId CreateJobObjectW AssignProcessToJobObject SetInformationJobObject ReadDirectoryChangesW SetConsoleCursorPosition FillConsoleOutputAttribute WriteConsoleInputW CreateFileA FillConsoleOutputCharacterW SetConsoleCursorInfo GetConsoleCursorInfo SetConsoleTextAttribute GetConsoleScreenBufferInfo DebugBreak FormatMessageA ConnectNamedPipe WaitNamedPipeW GetNamedPipeHandleStateA QueueUserWorkItem CreateNamedPipeW CreateNamedPipeA SetNamedPipeHandleState SetHandleInformation CancelIo CreateIoCompletionPort PostQueuedCompletionStatus GetFileAttributesW GetSystemDirectoryW MoveFileExW FindFirstFileW GetModuleHandleW GetCurrentDirectoryW K32EnumProcesses DeviceIoControl LoadResource LockResource GetCommandLineW SizeofResource GetQueuedCompletionStatus SetErrorMode CreateEventA CreateSemaphoreA WaitForMultipleObjects lstrcmpW WriteConsoleW GetFileAttributesExW HeapSize GetExitCodeProcess ReadConsoleInputW GetNumberOfConsoleInputEvents SetConsoleMode SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW FormatMessageW WaitForSingleObjectEx SwitchToThread EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime EncodePointer DecodePointer QueryPerformanceCounter QueryPerformanceFrequency CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo SetEvent ResetEvent UnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead InitializeCriticalSection GetStdHandle GetFileType WriteFile GlobalMemoryStatus FlushConsoleInputBuffer RtlUnwindEx RtlPcToFileHeader RaiseException LoadLibraryExW GetThreadTimes WaitForSingleObject AreFileApisANSI GetFullPathNameW FoldStringW IsDBCSLeadByte SetConsoleCtrlHandler FileTimeToLocalFileTime LocalFileTimeToFileTime GetSystemTime SystemTimeToTzSpecificLocalTime TzSpecificLocalTimeToSystemTime FileTimeToSystemTime SystemTimeToFileTime CompareStringA GetVersionExW CreateDirectoryW SetFileAttributesW SetFileTime MoveFileW FindNextFileW GetCurrentThread SetThreadPriority SetThreadExecutionState ReleaseSemaphore GetProcessAffinityMask CreateSemaphoreW FlushFileBuffers ReadFile SetEndOfFile SetFilePointer GetConsoleMode GetLongPathNameW GetShortPathNameW RemoveDirectoryW CreateHardLinkW GetTickCount64 GetModuleHandleA GlobalUnlock GlobalLock GlobalSize MulDiv GlobalFree GlobalAlloc LocalAlloc LocalSize GetModuleFileNameA LoadLibraryExA GetEnvironmentVariableW InitializeCriticalSectionEx GetTempPathA GetTempFileNameA GetUserDefaultLCID GetNumberFormatW GetCurrencyFormatW GetTimeFormatW VerSetConditionMask GetComputerNameW VerifyVersionInfoW GetDateFormatW OutputDebugStringW GetTimeZoneInformation UnmapViewOfFile FlushViewOfFile GetFileSize CreateFileMappingW MapViewOfFile AllocConsole GetThreadPriority RegisterWaitForSingleObject UnregisterWait FreeLibraryAndExitThread DuplicateHandle UnregisterWaitEx GetModuleHandleExW GetFileInformationByHandle PeekNamedPipe ExitThread GetConsoleCP HeapReAlloc IsValidLocale EnumSystemLocalesW SetFilePointerEx ReadConsoleW GetFileSizeEx SetStdHandle FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetLogicalDriveStringsW |
---|---|
USER32.dll |
ShowWindow
PostMessageW GetMessageW MessageBoxW wsprintfW GetWindowPlacement IsWindowVisible AnimateWindow SetWindowPos GetWindowRect SetWindowLongW GetWindowLongW TranslateMessage DispatchMessageW GetProcessWindowStation GetUserObjectInformationW GetDC ReleaseDC CharToOemA OemToCharA OemToCharBuffA CharUpperW CharLowerW CharToOemBuffW UpdateLayeredWindow SetCursor MapWindowPoints UpdateWindow EndPaint BeginPaint SetForegroundWindow GetForegroundWindow SetFocus GetFocus DestroyIcon KillTimer GetParent IsWindow SendMessageW InvalidateRect GetClientRect GetSystemMetrics AdjustWindowRectEx CreateWindowExW DestroyWindow GetWindow EnableWindow PeekMessageW LoadIconW LoadCursorW RegisterClassExW PostQuitMessage DefWindowProcW GetCursorPos GetDesktopWindow MoveWindow IsWindowEnabled RegisterClassW RedrawWindow WindowFromPoint GetWindowLongPtrW SetWindowLongPtrW GetWindowThreadProcessId GetWindowTextW ReleaseCapture RegisterWindowMessageW IsWindowUnicode SystemParametersInfoW GetClassLongW SetWindowsHookExW EnumThreadWindows EndDeferWindowPos SetCapture GetUpdateRect IsRectEmpty GetMessageTime UnhookWindowsHookEx GetSysColor GetDoubleClickTime CallMsgFilterW IsChild ClientToScreen GetMonitorInfoW SetTimer GetCapture GetAsyncKeyState BeginDeferWindowPos SetClassLongW GetActiveWindow GetScrollInfo NotifyWinEvent SetWindowTextW CallNextHookEx ScreenToClient MonitorFromWindow MonitorFromPoint GetMessageExtraInfo GetKeyState DeferWindowPos SetScrollInfo EnumDisplayDevicesW EnumDisplayMonitors DestroyCaret FindWindowW GetKeyboardLayout CreateCaret SetCaretPos RegisterClipboardFormatW OpenClipboard EmptyClipboard CloseClipboard CountClipboardFormats EnumClipboardFormats SetClipboardData IsClipboardFormatAvailable GetClipboardData GetClipboardSequenceNumber LoadStringW MessageBeep DestroyCursor LoadCursorFromFileA CreateIconIndirect GetIconInfo DrawIconEx MessageBoxA GetQueueStatus PostThreadMessageW MsgWaitForMultipleObjects SetWinEventHook DispatchMessageA MapVirtualKeyW GetMessageA SetActiveWindow |
GDI32.dll |
GetObjectW
DeleteDC SelectObject CreateDIBSection CreateCompatibleDC SetLayout GetClipBox SaveDC SetViewportOrgEx RestoreDC BitBlt GetStockObject GetDIBits StartDocW SetMapMode CreateDCW EndDoc StartPage AddFontMemResourceEx GetGlyphIndicesW GetObjectA CreateFontW EnumFontFamiliesExW GetFontUnicodeRanges GetDeviceCaps DeleteObject EndPage CreateBitmap |
ADVAPI32.dll |
RegCloseKey
GetUserNameW SetFileSecurityW FreeSid CheckTokenMembership LookupPrivilegeValueW AdjustTokenPrivileges RegSetValueExW OpenProcessToken RegCreateKeyW RegOpenKeyW AllocateAndInitializeSid RegOpenKeyExW CryptAcquireContextW CryptGenRandom CryptReleaseContext DeregisterEventSource RegisterEventSourceW ReportEventW RegQueryValueExW CryptAcquireContextA |
SHELL32.dll |
ShellExecuteW
SHGetFileInfoW SHBrowseForFolderW Shell_NotifyIconW #74 DragQueryFileW SHGetSpecialFolderPathW SHGetPathFromIDListW ShellExecuteExW CommandLineToArgvW #727 |
ole32.dll |
CreateStreamOnHGlobal
ReleaseStgMedium OleUninitialize OleInitialize CoTaskMemAlloc DoDragDrop RevokeDragDrop CoUninitialize RegisterDragDrop CoCreateInstance CoTaskMemFree CoCreateGuid CoInitialize CoFreeUnusedLibraries |
WS2_32.dll |
WSASocketW
WSAIoctl #2 WSARecv #13 #3 #10 WSARecvFrom #112 #18 #22 #9 #115 FreeAddrInfoW GetAddrInfoW #7 #21 #111 #16 #4 #23 #19 #11 WSASend |
ntdll.dll |
NtClose
LdrFindResource_U RtlDosPathNameToNtPathName_U RtlInitUnicodeString RtlFreeUnicodeString NtWriteFile NtCreateFile LdrAccessResource RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext ZwLoadDriver |
SHLWAPI.dll |
PathFindFileNameW
PathAppendW PathFileExistsW PathRemoveExtensionW PathCombineW |
urlmon.dll |
FindMimeFromData
|
OLEACC.dll |
AccessibleObjectFromWindow
LresultFromObject |
UxTheme.dll |
SetWindowTheme
IsThemeBackgroundPartiallyTransparent GetThemePartSize DrawThemeBackground CloseThemeData OpenThemeData |
IMM32.dll |
ImmGetCompositionStringW
ImmSetCandidateWindow ImmReleaseContext ImmAssociateContextEx ImmNotifyIME ImmIsIME ImmGetContext |
COMCTL32.dll |
ImageList_DrawEx
ImageList_GetIconSize ImageList_Destroy |
WINMM.dll |
PlaySoundW
timeGetTime timeSetEvent timeEndPeriod timeKillEvent timeBeginPeriod |
USP10.dll |
ScriptBreak
ScriptItemize ScriptApplyDigitSubstitution ScriptFreeCache ScriptShape ScriptPlace |
WINSPOOL.DRV |
#203
|
COMDLG32.dll |
PrintDlgW
GetOpenFileNameW GetSaveFileNameW CommDlgExtendedError |
OLEAUT32.dll |
#6
#16 #26 #411 #4 |
gdiplus.dll |
GdipGetEmHeight
GdipGetCellDescent GdipDrawString GdipAddPathString GdipGetFontSize GdipCreatePen2 GdipSetPenEndCap GdipSetPenStartCap GdipSetPenLineJoin GdipSetPenMiterLimit GdipGetFontStyle GdipSetPenDashStyle GdipSetPenDashArray GdipSetPenDashOffset GdipDeleteFont GdipCreateFontFromDC GdipGetLineSpacing GdipCreateFontFromLogfontA GdiplusShutdown GdiplusStartup GdipCreateBitmapFromGraphics GdipDrawImageI GdipCreateHBITMAPFromBitmap GdipDrawDriverString GdipGetCellAscent GdipGetFamily GdipBitmapLockBits GdipBitmapUnlockBits GdipAlloc GdipFree GdipCreateBitmapFromScan0 GdipCloneImage GdipDisposeImage GdipCreateSolidFill GdipDeleteBrush GdipCloneBrush GdipFillRectangleI GdipCreatePath GdipDeletePath GdipAddPathArcI GdipAddPathLineI GdipFillPath GdipGetClipBoundsI GdipCreateLineBrush GdipMultiplyLineTransform GdipCreateMatrix2 GdipSetLinePresetBlend GdipSetLineWrapMode GdipAddPathEllipse GdipCreatePathGradientFromPath GdipSetPathGradientPresetBlend GdipSetPathGradientWrapMode GdipSetPathGradientCenterPoint GdipSetPathGradientTransform GdipCreatePen1 GdipDeletePen GdipDrawPath GdipFillRectanglesI GdipDrawLine GdipSetClipRectI GdipTranslateWorldTransform GdipGetSmoothingMode GdipSaveGraphics GdipRestoreGraphics GdipBeginContainer2 GdipGetImageGraphicsContext GdipGraphicsClear GdipGetPathWorldBounds GdipClonePath GdipSetClipRect GdipAddPathRectangleI GdipGetImageHeight GdipGetImageWidth GdipDeleteGraphics GdipSetSmoothingMode GdipEndContainer GdipCreateImageAttributes GdipDisposeImageAttributes GdipSetImageAttributesColorMatrix GdipDrawImageRectRect GdipTransformPoints GdipMultiplyWorldTransform GdipCreateMatrix GdipDeleteMatrix GdipGetWorldTransform GdipGetMatrixElements GdipTranslateMatrix GdipRotateMatrix GdipScaleMatrix GdipShearMatrix GdipCreateTexture GdipFillEllipse GdipDrawEllipse GdipFillPie GdipDrawPie GdipDrawArc GdipFillRectangle GdipDrawRectangle GdipResetPath GdipIsVisiblePathPoint GdipStartPathFigure GdipAddPathLine GdipClosePathFigure GdipSetPathFillMode GdipAddPathArc GdipAddPathBezier GdipSetPageUnit GdipSetCompositingQuality GdipSetPixelOffsetMode GdipSetInterpolationMode GdipSetTextRenderingHint GdipCreateFromHWND GdipCreateFromHDC GdipCreateStringFormat GdipDeleteStringFormat GdipSetStringFormatAlign GdipSetStringFormatLineAlign GdipSetStringFormatTrimming GdipGetFontHeightGivenDPI GdipMeasureString GdipDeleteFontFamily |
WININET.dll |
InternetCloseHandle
InternetReadFile InternetQueryOptionW HttpQueryInfoA InternetErrorDlg HttpSendRequestA InternetConnectA InternetOpenA InternetSetOptionW HttpQueryInfoW HttpOpenRequestA |
WTSAPI32.dll |
WTSSendMessageW
|
KERNEL32.dll (#2) |
ExitProcess
GetLastError FreeLibrary GetProcessHeap GetProcAddress HeapAlloc LoadLibraryA VirtualAlloc lstrlenW CreateFileW SetLastError HeapFree LocalFree FindResourceW GetCurrentProcess TerminateProcess GetModuleFileNameW GetTempPathW FindClose VirtualFree Sleep RtlUnwind GetVolumeInformationW SetUnhandledExceptionFilter GetTickCount GetTempFileNameW WideCharToMultiByte CopyFileW CreateProcessW GetCurrentProcessId GetWindowsDirectoryW CloseHandle CreateThread LoadLibraryW DeleteFileW MultiByteToWideChar OpenProcess ResumeThread K32GetProcessImageFileNameW GetCurrentThreadId CreateJobObjectW AssignProcessToJobObject SetInformationJobObject ReadDirectoryChangesW SetConsoleCursorPosition FillConsoleOutputAttribute WriteConsoleInputW CreateFileA FillConsoleOutputCharacterW SetConsoleCursorInfo GetConsoleCursorInfo SetConsoleTextAttribute GetConsoleScreenBufferInfo DebugBreak FormatMessageA ConnectNamedPipe WaitNamedPipeW GetNamedPipeHandleStateA QueueUserWorkItem CreateNamedPipeW CreateNamedPipeA SetNamedPipeHandleState SetHandleInformation CancelIo CreateIoCompletionPort PostQueuedCompletionStatus GetFileAttributesW GetSystemDirectoryW MoveFileExW FindFirstFileW GetModuleHandleW GetCurrentDirectoryW K32EnumProcesses DeviceIoControl LoadResource LockResource GetCommandLineW SizeofResource GetQueuedCompletionStatus SetErrorMode CreateEventA CreateSemaphoreA WaitForMultipleObjects lstrcmpW WriteConsoleW GetFileAttributesExW HeapSize GetExitCodeProcess ReadConsoleInputW GetNumberOfConsoleInputEvents SetConsoleMode SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW FormatMessageW WaitForSingleObjectEx SwitchToThread EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime EncodePointer DecodePointer QueryPerformanceCounter QueryPerformanceFrequency CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo SetEvent ResetEvent UnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead InitializeCriticalSection GetStdHandle GetFileType WriteFile GlobalMemoryStatus FlushConsoleInputBuffer RtlUnwindEx RtlPcToFileHeader RaiseException LoadLibraryExW GetThreadTimes WaitForSingleObject AreFileApisANSI GetFullPathNameW FoldStringW IsDBCSLeadByte SetConsoleCtrlHandler FileTimeToLocalFileTime LocalFileTimeToFileTime GetSystemTime SystemTimeToTzSpecificLocalTime TzSpecificLocalTimeToSystemTime FileTimeToSystemTime SystemTimeToFileTime CompareStringA GetVersionExW CreateDirectoryW SetFileAttributesW SetFileTime MoveFileW FindNextFileW GetCurrentThread SetThreadPriority SetThreadExecutionState ReleaseSemaphore GetProcessAffinityMask CreateSemaphoreW FlushFileBuffers ReadFile SetEndOfFile SetFilePointer GetConsoleMode GetLongPathNameW GetShortPathNameW RemoveDirectoryW CreateHardLinkW GetTickCount64 GetModuleHandleA GlobalUnlock GlobalLock GlobalSize MulDiv GlobalFree GlobalAlloc LocalAlloc LocalSize GetModuleFileNameA LoadLibraryExA GetEnvironmentVariableW InitializeCriticalSectionEx GetTempPathA GetTempFileNameA GetUserDefaultLCID GetNumberFormatW GetCurrencyFormatW GetTimeFormatW VerSetConditionMask GetComputerNameW VerifyVersionInfoW GetDateFormatW OutputDebugStringW GetTimeZoneInformation UnmapViewOfFile FlushViewOfFile GetFileSize CreateFileMappingW MapViewOfFile AllocConsole GetThreadPriority RegisterWaitForSingleObject UnregisterWait FreeLibraryAndExitThread DuplicateHandle UnregisterWaitEx GetModuleHandleExW GetFileInformationByHandle PeekNamedPipe ExitThread GetConsoleCP HeapReAlloc IsValidLocale EnumSystemLocalesW SetFilePointerEx ReadConsoleW GetFileSizeEx SetStdHandle FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetLogicalDriveStringsW |
USER32.dll (#2) |
ShowWindow
PostMessageW GetMessageW MessageBoxW wsprintfW GetWindowPlacement IsWindowVisible AnimateWindow SetWindowPos GetWindowRect SetWindowLongW GetWindowLongW TranslateMessage DispatchMessageW GetProcessWindowStation GetUserObjectInformationW GetDC ReleaseDC CharToOemA OemToCharA OemToCharBuffA CharUpperW CharLowerW CharToOemBuffW UpdateLayeredWindow SetCursor MapWindowPoints UpdateWindow EndPaint BeginPaint SetForegroundWindow GetForegroundWindow SetFocus GetFocus DestroyIcon KillTimer GetParent IsWindow SendMessageW InvalidateRect GetClientRect GetSystemMetrics AdjustWindowRectEx CreateWindowExW DestroyWindow GetWindow EnableWindow PeekMessageW LoadIconW LoadCursorW RegisterClassExW PostQuitMessage DefWindowProcW GetCursorPos GetDesktopWindow MoveWindow IsWindowEnabled RegisterClassW RedrawWindow WindowFromPoint GetWindowLongPtrW SetWindowLongPtrW GetWindowThreadProcessId GetWindowTextW ReleaseCapture RegisterWindowMessageW IsWindowUnicode SystemParametersInfoW GetClassLongW SetWindowsHookExW EnumThreadWindows EndDeferWindowPos SetCapture GetUpdateRect IsRectEmpty GetMessageTime UnhookWindowsHookEx GetSysColor GetDoubleClickTime CallMsgFilterW IsChild ClientToScreen GetMonitorInfoW SetTimer GetCapture GetAsyncKeyState BeginDeferWindowPos SetClassLongW GetActiveWindow GetScrollInfo NotifyWinEvent SetWindowTextW CallNextHookEx ScreenToClient MonitorFromWindow MonitorFromPoint GetMessageExtraInfo GetKeyState DeferWindowPos SetScrollInfo EnumDisplayDevicesW EnumDisplayMonitors DestroyCaret FindWindowW GetKeyboardLayout CreateCaret SetCaretPos RegisterClipboardFormatW OpenClipboard EmptyClipboard CloseClipboard CountClipboardFormats EnumClipboardFormats SetClipboardData IsClipboardFormatAvailable GetClipboardData GetClipboardSequenceNumber LoadStringW MessageBeep DestroyCursor LoadCursorFromFileA CreateIconIndirect GetIconInfo DrawIconEx MessageBoxA GetQueueStatus PostThreadMessageW MsgWaitForMultipleObjects SetWinEventHook DispatchMessageA MapVirtualKeyW GetMessageA SetActiveWindow |
KERNEL32.dll (#3) |
ExitProcess
GetLastError FreeLibrary GetProcessHeap GetProcAddress HeapAlloc LoadLibraryA VirtualAlloc lstrlenW CreateFileW SetLastError HeapFree LocalFree FindResourceW GetCurrentProcess TerminateProcess GetModuleFileNameW GetTempPathW FindClose VirtualFree Sleep RtlUnwind GetVolumeInformationW SetUnhandledExceptionFilter GetTickCount GetTempFileNameW WideCharToMultiByte CopyFileW CreateProcessW GetCurrentProcessId GetWindowsDirectoryW CloseHandle CreateThread LoadLibraryW DeleteFileW MultiByteToWideChar OpenProcess ResumeThread K32GetProcessImageFileNameW GetCurrentThreadId CreateJobObjectW AssignProcessToJobObject SetInformationJobObject ReadDirectoryChangesW SetConsoleCursorPosition FillConsoleOutputAttribute WriteConsoleInputW CreateFileA FillConsoleOutputCharacterW SetConsoleCursorInfo GetConsoleCursorInfo SetConsoleTextAttribute GetConsoleScreenBufferInfo DebugBreak FormatMessageA ConnectNamedPipe WaitNamedPipeW GetNamedPipeHandleStateA QueueUserWorkItem CreateNamedPipeW CreateNamedPipeA SetNamedPipeHandleState SetHandleInformation CancelIo CreateIoCompletionPort PostQueuedCompletionStatus GetFileAttributesW GetSystemDirectoryW MoveFileExW FindFirstFileW GetModuleHandleW GetCurrentDirectoryW K32EnumProcesses DeviceIoControl LoadResource LockResource GetCommandLineW SizeofResource GetQueuedCompletionStatus SetErrorMode CreateEventA CreateSemaphoreA WaitForMultipleObjects lstrcmpW WriteConsoleW GetFileAttributesExW HeapSize GetExitCodeProcess ReadConsoleInputW GetNumberOfConsoleInputEvents SetConsoleMode SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW FormatMessageW WaitForSingleObjectEx SwitchToThread EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime EncodePointer DecodePointer QueryPerformanceCounter QueryPerformanceFrequency CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo SetEvent ResetEvent UnhandledExceptionFilter IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW InitializeSListHead InitializeCriticalSection GetStdHandle GetFileType WriteFile GlobalMemoryStatus FlushConsoleInputBuffer RtlUnwindEx RtlPcToFileHeader RaiseException LoadLibraryExW GetThreadTimes WaitForSingleObject AreFileApisANSI GetFullPathNameW FoldStringW IsDBCSLeadByte SetConsoleCtrlHandler FileTimeToLocalFileTime LocalFileTimeToFileTime GetSystemTime SystemTimeToTzSpecificLocalTime TzSpecificLocalTimeToSystemTime FileTimeToSystemTime SystemTimeToFileTime CompareStringA GetVersionExW CreateDirectoryW SetFileAttributesW SetFileTime MoveFileW FindNextFileW GetCurrentThread SetThreadPriority SetThreadExecutionState ReleaseSemaphore GetProcessAffinityMask CreateSemaphoreW FlushFileBuffers ReadFile SetEndOfFile SetFilePointer GetConsoleMode GetLongPathNameW GetShortPathNameW RemoveDirectoryW CreateHardLinkW GetTickCount64 GetModuleHandleA GlobalUnlock GlobalLock GlobalSize MulDiv GlobalFree GlobalAlloc LocalAlloc LocalSize GetModuleFileNameA LoadLibraryExA GetEnvironmentVariableW InitializeCriticalSectionEx GetTempPathA GetTempFileNameA GetUserDefaultLCID GetNumberFormatW GetCurrencyFormatW GetTimeFormatW VerSetConditionMask GetComputerNameW VerifyVersionInfoW GetDateFormatW OutputDebugStringW GetTimeZoneInformation UnmapViewOfFile FlushViewOfFile GetFileSize CreateFileMappingW MapViewOfFile AllocConsole GetThreadPriority RegisterWaitForSingleObject UnregisterWait FreeLibraryAndExitThread DuplicateHandle UnregisterWaitEx GetModuleHandleExW GetFileInformationByHandle PeekNamedPipe ExitThread GetConsoleCP HeapReAlloc IsValidLocale EnumSystemLocalesW SetFilePointerEx ReadConsoleW GetFileSizeEx SetStdHandle FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetLogicalDriveStringsW |
USER32.dll (#3) |
ShowWindow
PostMessageW GetMessageW MessageBoxW wsprintfW GetWindowPlacement IsWindowVisible AnimateWindow SetWindowPos GetWindowRect SetWindowLongW GetWindowLongW TranslateMessage DispatchMessageW GetProcessWindowStation GetUserObjectInformationW GetDC ReleaseDC CharToOemA OemToCharA OemToCharBuffA CharUpperW CharLowerW CharToOemBuffW UpdateLayeredWindow SetCursor MapWindowPoints UpdateWindow EndPaint BeginPaint SetForegroundWindow GetForegroundWindow SetFocus GetFocus DestroyIcon KillTimer GetParent IsWindow SendMessageW InvalidateRect GetClientRect GetSystemMetrics AdjustWindowRectEx CreateWindowExW DestroyWindow GetWindow EnableWindow PeekMessageW LoadIconW LoadCursorW RegisterClassExW PostQuitMessage DefWindowProcW GetCursorPos GetDesktopWindow MoveWindow IsWindowEnabled RegisterClassW RedrawWindow WindowFromPoint GetWindowLongPtrW SetWindowLongPtrW GetWindowThreadProcessId GetWindowTextW ReleaseCapture RegisterWindowMessageW IsWindowUnicode SystemParametersInfoW GetClassLongW SetWindowsHookExW EnumThreadWindows EndDeferWindowPos SetCapture GetUpdateRect IsRectEmpty GetMessageTime UnhookWindowsHookEx GetSysColor GetDoubleClickTime CallMsgFilterW IsChild ClientToScreen GetMonitorInfoW SetTimer GetCapture GetAsyncKeyState BeginDeferWindowPos SetClassLongW GetActiveWindow GetScrollInfo NotifyWinEvent SetWindowTextW CallNextHookEx ScreenToClient MonitorFromWindow MonitorFromPoint GetMessageExtraInfo GetKeyState DeferWindowPos SetScrollInfo EnumDisplayDevicesW EnumDisplayMonitors DestroyCaret FindWindowW GetKeyboardLayout CreateCaret SetCaretPos RegisterClipboardFormatW OpenClipboard EmptyClipboard CloseClipboard CountClipboardFormats EnumClipboardFormats SetClipboardData IsClipboardFormatAvailable GetClipboardData GetClipboardSequenceNumber LoadStringW MessageBeep DestroyCursor LoadCursorFromFileA CreateIconIndirect GetIconInfo DrawIconEx MessageBoxA GetQueueStatus PostThreadMessageW MsgWaitForMultipleObjects SetWinEventHook DispatchMessageA MapVirtualKeyW GetMessageA SetActiveWindow |
Size | 0x130 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14076e120 |