filename | nxloaderx64_dump_SCY - Copy - Copy.exe | |
---|---|---|
size | 2412544 (0x24d000) | |
md5 | 1383c2fd9e335ae808ecdb7ceb693cfd | |
type | MS-DOS executable PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, MZ for MS-DOS | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x40 |
blocks_in_file | 1 |
num_relocs | 0 |
header_paragraphs | 2 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0xa |
overlay_number | 0 |
reserved0 | 0xeba1f0e00000000 |
oem_id | 0xb400 |
oem_info | 0xcd09 |
reserved2 | 0x4c01b821 |
reserved3 | 0x695721cd |
reserved4 | 0x2034366e |
reserved5 | 0x4558452e |
reserved6 | 0x240a0d2e |
lfanew | 0x40 |
PE Header
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.MPRESS1 | 0x1000 | 0x240000 | 0x238800 | RWX CODE IDATA UDATA | |
.MPRESS2 | 0x241000 | 0x2000 | 0x1600 | RWX CODE IDATA UDATA | |
.rsrc | 0x243000 | 0x12000 | 0x11200 | RW- IDATA | |
0x255000 | 0x2000 | 0x1e00 | RWX CODE IDATA |
Data Directory
type | name | size | cp | |
---|---|---|---|---|
BITMAP | #102 | 537640 | 1252 | |
ICON | #1 | 67624 | 1252 | |
ICON | #2 | 1128 | 1252 | |
GROUP_ICON | #101 | 20 | 1252 | |
GROUP_ICON | #104 | 20 | 1252 | |
MANIFEST | #1 | 620 | 1252 |
module_name | hint | ord | function_name |
---|---|---|---|
advapi32.dll | 673 | RegSetValueExA | |
advapi32.dll | 679 | RegisterEventSourceW | |
advapi32.dll | 695 | ReportEventW | |
advapi32.dll | 235 | DeregisterEventSource | |
advapi32.dll | 31 | AdjustTokenPrivileges | |
advapi32.dll | 428 | LookupPrivilegeValueA | |
advapi32.dll | 530 | OpenProcessToken | |
advapi32.dll | 596 | RegCloseKey | |
advapi32.dll | 604 | RegCreateKeyExA | |
gdi32.dll | 569 | GetStockObject | |
gdi32.dll | 733 | SetBkMode | |
gdi32.dll | 61 | CreateFontA | |
kernel32.dll | DecodePointer | ||
kernel32.dll | 709 | GetStartupInfoW | |
kernel32.dll | 1390 | TerminateProcess | |
kernel32.dll | 1424 | UnhandledExceptionFilter | |
kernel32.dll | 1360 | SetUnhandledExceptionFilter | |
kernel32.dll | 1204 | RtlLookupFunctionEntry | |
kernel32.dll | 1197 | RtlCaptureContext | |
kernel32.dll | 733 | GetSystemTimeAsFileTime | |
kernel32.dll | EncodePointer | ||
kernel32.dll | 407 | FlushConsoleInputBuffer | |
kernel32.dll | 782 | GetVersionExW | |
kernel32.dll | 939 | LoadLibraryW | |
kernel32.dll | 812 | GlobalMemoryStatus | |
kernel32.dll | 528 | GetCurrentProcessId | |
kernel32.dll | 1072 | QueryPerformanceCounter | |
kernel32.dll | 1211 | RtlVirtualUnwind | |
kernel32.dll | 980 | MultiByteToWideChar | |
kernel32.dll | 621 | GetModuleHandleW | |
kernel32.dll | 532 | GetCurrentThreadId | |
kernel32.dll | 346 | ExpandEnvironmentStringsA | |
kernel32.dll | 936 | LoadLibraryA | |
kernel32.dll | 676 | GetProcAddress | |
kernel32.dll | 420 | FreeLibrary | |
kernel32.dll | 1039 | Process32First | |
kernel32.dll | 792 | GetWindowsDirectoryA | |
kernel32.dll | 1009 | OpenProcess | |
kernel32.dll | 1375 | Sleep | |
kernel32.dll | 215 | CreateProcessA | |
kernel32.dll | 598 | GetLastError | |
kernel32.dll | 1041 | Process32Next | |
kernel32.dll | 971 | MoveFileA | |
kernel32.dll | 616 | GetModuleFileNameA | |
kernel32.dll | 1066 | QueryFullProcessImageNameA | |
kernel32.dll | 206 | CreateMutexA | |
kernel32.dll | 874 | IsDebuggerPresent | |
kernel32.dll | 240 | CreateToolhelp32Snapshot | |
kernel32.dll | 1167 | ReleaseMutex | |
kernel32.dll | 127 | CloseHandle | |
kernel32.dll | 780 | GetVersion | |
kernel32.dll | 231 | CreateThread | |
kernel32.dll | 747 | GetThreadContext | |
kernel32.dll | 527 | GetCurrentProcess | |
kernel32.dll | 531 | GetCurrentThread | |
kernel32.dll | 783 | GetVolumeInformationA | |
kernel32.dll | 672 | GetPrivateProfileStringA | |
kernel32.dll | 1524 | WritePrivateProfileStringA | |
kernel32.dll | 220 | CreateRemoteThread | |
kernel32.dll | 1450 | VirtualAllocEx | |
kernel32.dll | 1528 | WriteProcessMemory | |
kernel32.dll | 1304 | SetLastError | |
kernel32.dll | 415 | FormatMessageA | |
kernel32.dll | DeleteCriticalSection | ||
kernel32.dll | InitializeCriticalSection | ||
kernel32.dll | LeaveCriticalSection | ||
kernel32.dll | EnterCriticalSection | ||
kernel32.dll | 1378 | SleepEx | |
kernel32.dll | 781 | GetVersionExA | |
kernel32.dll | 761 | GetTickCount | |
kernel32.dll | 1465 | WaitForSingleObject | |
kernel32.dll | 1107 | ReadFile | |
kernel32.dll | 1030 | PeekNamedPipe | |
kernel32.dll | 1463 | WaitForMultipleObjects | |
kernel32.dll | 581 | GetFileType | |
kernel32.dll | 711 | GetStdHandle | |
msvcp100.dll | 1415 | void (__cdecl*__cdecl std::set_new_handler(void (__cdecl*)(void)))(void) ?set_new_handler@std@@YAP6AXXZP6AXXZ@Z | |
msvcp100.dll | 1549 | bool __cdecl std::uncaught_exception(void) ?uncaught_exception@std@@YA_NXZ | |
msvcp100.dll | 652 | void __cdecl std::_Xlength_error(char const * __ptr64) ?_Xlength_error@std@@YAXPEBD@Z | |
msvcp100.dll | 654 | void __cdecl std::_Xout_of_range(char const * __ptr64) ?_Xout_of_range@std@@YAXPEBD@Z | |
msvcp100.dll | 154 | public: __cdecl std::_Container_base12::~_Container_base12(void) __ptr64 ??1_Container_base12@std@@QEAA@XZ | |
msvcr100.dll | 228 | public: char const * __ptr64 __cdecl type_info::_name_internal_method(struct __type_info_node * __ptr64)const __ptr64 ?_name_internal_method@type_info@@QEBAPEBDPEAU__type_info_node@@@Z | |
msvcr100.dll | 286 | __C_specific_handler | |
msvcr100.dll | 1115 | _unlock | |
msvcr100.dll | 328 | __dllonexit | |
msvcr100.dll | 758 | _lock | |
msvcr100.dll | 925 | _onexit | |
msvcr100.dll | 414 | _amsg_exit | |
msvcr100.dll | 1357 | feof | |
msvcr100.dll | 526 | _fileno | |
msvcr100.dll | 988 | _setmode | |
msvcr100.dll | 1358 | ferror | |
msvcr100.dll | 1496 | strcmp | |
msvcr100.dll | 1468 | raise | |
msvcr100.dll | 512 | _exit | |
msvcr100.dll | 1539 | vfprintf | |
msvcr100.dll | 1157 | _vsnwprintf | |
msvcr100.dll | 1573 | wcsstr | |
msvcr100.dll | 926 | _open | |
msvcr100.dll | 1030 | _stat64i32 | |
msvcr100.dll | 573 | _ftime64 | |
msvcr100.dll | 1371 | fprintf | |
msvcr100.dll | 1406 | isgraph | |
msvcr100.dll | 1409 | isprint | |
msvcr100.dll | 1412 | isupper | |
msvcr100.dll | 1408 | islower | |
msvcr100.dll | 1029 | _stat64 | |
msvcr100.dll | 1403 | isalpha | |
msvcr100.dll | 631 | _gmtime64 | |
msvcr100.dll | 768 | _lseeki64 | |
msvcr100.dll | 566 | _fstat64 | |
msvcr100.dll | 1447 | memchr | |
msvcr100.dll | 1411 | isspace | |
msvcr100.dll | 1402 | isalnum | |
msvcr100.dll | 1359 | fflush | |
msvcr100.dll | 1448 | memcmp | |
msvcr100.dll | 429 | _beginthreadex | |
msvcr100.dll | 1373 | fputc | |
msvcr100.dll | 1405 | isdigit | |
msvcr100.dll | 338 | __getmainargs | |
msvcr100.dll | 282 | _XcptFilter | |
msvcr100.dll | 677 | _ismbblead | |
msvcr100.dll | 437 | _cexit | |
msvcr100.dll | 405 | _acmdln | |
msvcr100.dll | 646 | _initterm | |
msvcr100.dll | 647 | _initterm_e | |
msvcr100.dll | 453 | _configthreadlocale | |
msvcr100.dll | 380 | __setusermatherr | |
msvcr100.dll | 452 | _commode | |
msvcr100.dll | 540 | _fmode | |
msvcr100.dll | 377 | __set_app_type | |
msvcr100.dll | 326 | __crt_debugger_hook | |
msvcr100.dll | 294 | __CxxFrameHandler | |
msvcr100.dll | 256 | void __cdecl terminate(void) ?terminate@@YAXXZ | |
msvcr100.dll | 238 | public: void __cdecl type_info::_type_info_dtor_internal_method(void) __ptr64 ?_type_info_dtor_internal_method@type_info@@QEAAXXZ | |
msvcr100.dll | 1113 | _unlink | |
msvcr100.dll | 1186 | _wcsdup | |
msvcr100.dll | 1035 | _strdup | |
msvcr100.dll | 450 | _close | |
msvcr100.dll | 1277 | _write | |
msvcr100.dll | 947 | _read | |
msvcr100.dll | 270 | _CxxThrowException | |
msvcr100.dll | 35 | public: __cdecl std::exception::exception(char const * __ptr64 const & __ptr64, int) __ptr64 ??0exception@std@@QEAA@AEBQEBDH@Z | |
msvcr100.dll | 606 | _getch | |
msvcr100.dll | 1481 | signal | |
msvcr100.dll | 1039 | _stricmp | |
msvcr100.dll | 1049 | _strnicmp | |
msvcr100.dll | 1395 | getenv | |
msvcr100.dll | 1249 | _wfopen | |
msvcr100.dll | 1486 | sprintf | |
msvcr100.dll | 266 | public: virtual char const * __ptr64 __cdecl std::exception::what(void)const __ptr64 ?what@exception@std@@UEBAPEBDXZ | |
msvcr100.dll | 88 | public: virtual __cdecl std::__non_rtti_object::~__non_rtti_object(void) __ptr64 ??1__non_rtti_object@std@@UEAA@XZ | |
msvcr100.dll | 37 | public: __cdecl std::exception::exception(void) __ptr64 ??0exception@std@@QEAA@XZ | |
msvcr100.dll | 34 | public: __cdecl std::exception::exception(char const * __ptr64 const & __ptr64) __ptr64 ??0exception@std@@QEAA@AEBQEBD@Z | |
msvcr100.dll | 36 | public: __cdecl std::exception::exception(class std::exception const & __ptr64) __ptr64 ??0exception@std@@QEAA@AEBV01@@Z | |
msvcr100.dll | 318 | __argv | |
msvcr100.dll | 110 | public: bool __cdecl type_info::operator!=(class type_info const & __ptr64)const __ptr64 ??9type_info@@QEBA_NAEBV0@@Z | |
msvcr100.dll | 109 | public: bool __cdecl type_info::operator==(class type_info const & __ptr64)const __ptr64 ??8type_info@@QEBA_NAEBV0@@Z | |
msvcr100.dll | 1449 | memcpy | |
msvcr100.dll | 1379 | free | |
msvcr100.dll | 1438 | malloc | |
msvcr100.dll | 1514 | strstr | |
msvcr100.dll | 1336 | atoi | |
msvcr100.dll | 1472 | remove | |
msvcr100.dll | 1516 | strtok | |
msvcr100.dll | 1369 | fopen | |
msvcr100.dll | 1377 | fread | |
msvcr100.dll | 1469 | rand | |
msvcr100.dll | 1490 | srand | |
msvcr100.dll | 937 | _purecall | |
msvcr100.dll | 101 | void __cdecl operator delete(void * __ptr64) ??3@YAXPEAX@Z | |
msvcr100.dll | 1450 | memcpy_s | |
msvcr100.dll | 1390 | fwrite | |
msvcr100.dll | 1387 | ftell | |
msvcr100.dll | 610 | _getcwd | |
msvcr100.dll | 1385 | fseek | |
msvcr100.dll | 1356 | fclose | |
msvcr100.dll | 1087 | _time64 | |
msvcr100.dll | 1352 | exit | |
msvcr100.dll | 99 | void * __ptr64 __cdecl operator new(unsigned __int64) ??2@YAPEAX_K@Z | |
msvcr100.dll | 317 | __argc | |
msvcr100.dll | 1545 | vsprintf | |
msvcr100.dll | 1533 | tolower | |
msvcr100.dll | 1471 | realloc | |
msvcr100.dll | 1341 | calloc | |
msvcr100.dll | 1453 | memset | |
msvcr100.dll | 1508 | strncpy | |
msvcr100.dll | 1512 | strrchr | |
msvcr100.dll | 1501 | strerror | |
msvcr100.dll | 384 | __sys_nerr | |
msvcr100.dll | 503 | _errno | |
msvcr100.dll | 1491 | sscanf | |
msvcr100.dll | 1495 | strchr | |
msvcr100.dll | 340 | __iob_func | |
msvcr100.dll | 1518 | strtol | |
msvcr100.dll | 1426 | isxdigit | |
msvcr100.dll | 1519 | strtoul | |
msvcr100.dll | 1061 | _strtoi64 | |
msvcr100.dll | 1507 | strncmp | |
msvcr100.dll | 1362 | fgets | |
msvcr100.dll | 1466 | qsort | |
msvcr100.dll | 1374 | fputs | |
shell32.dll | 307 | ShellExecuteA | |
shell32.dll | 204 | SHGetFolderPathA | |
shlwapi.dll | 183 | SHDeleteKeyA | |
secur32.dll | GetUserNameExA | ||
user32.dll | 775 | SetTimer | |
user32.dll | 463 | GetWindowRect | |
user32.dll | 652 | RegisterClassExA | |
user32.dll | 629 | PostQuitMessage | |
user32.dll | 694 | SendDlgItemMessageA | |
user32.dll | 541 | KillTimer | |
user32.dll | 7 | AnimateWindow | |
user32.dll | 544 | LoadBitmapA | |
user32.dll | 550 | LoadIconA | |
user32.dll | 730 | SetFocus | |
user32.dll | 699 | SendMessageA | |
user32.dll | 839 | TranslateMessage | |
user32.dll | 467 | GetWindowTextA | |
user32.dll | 369 | GetMessageA | |
user32.dll | 112 | CreateWindowExA | |
user32.dll | 318 | GetDlgItem | |
user32.dll | DefWindowProcA | ||
user32.dll | 791 | SetWindowPos | |
user32.dll | 808 | ShowWindow | |
user32.dll | 180 | DispatchMessageA | |
user32.dll | 428 | GetSystemMetrics | |
user32.dll | 795 | SetWindowTextA | |
user32.dll | 863 | UpdateWindow | |
user32.dll | 228 | EnableWindow | |
user32.dll | 262 | FindWindowA | |
user32.dll | 546 | LoadCursorA | |
user32.dll | 317 | GetDlgCtrlID | |
user32.dll | 471 | GetWindowThreadProcessId | |
user32.dll | 173 | DestroyWindow | |
user32.dll | 442 | GetUserObjectInformationW | |
user32.dll | 313 | GetDesktopWindow | |
user32.dll | 405 | GetProcessWindowStation | |
user32.dll | 593 | MessageBoxW | |
user32.dll | 586 | MessageBoxA | |
Wldap32.dll | 95 | ldap_err2stringA | |
Wldap32.dll | 221 | ldap_set_optionA | |
Wldap32.dll | 132 | ldap_initA | |
Wldap32.dll | 227 | ldap_simple_bind_sA | |
Wldap32.dll | 213 | ldap_search_sA | |
Wldap32.dll | 111 | ldap_first_entry | |
Wldap32.dll | 117 | ldap_get_dnA | |
Wldap32.dll | 109 | ldap_first_attributeA | |
Wldap32.dll | 129 | ldap_get_values_lenA | |
Wldap32.dll | 244 | ldap_value_free_len | |
Wldap32.dll | 135 | ldap_memfreeA | |
Wldap32.dll | 163 | ldap_next_attributeA | |
Wldap32.dll | 10 | ber_free | |
Wldap32.dll | 165 | ldap_next_entry | |
Wldap32.dll | 161 | ldap_msgfree | |
Wldap32.dll | 240 | ldap_unbind_s | |
ws2_32.dll | 168 | gethostname | |
ws2_32.dll | 183 | ioctlsocket | |
ws2_32.dll | 184 | listen | |
ws2_32.dll | 160 | accept | |
ws2_32.dll | 188 | recvfrom | |
ws2_32.dll | 191 | sendto | |
ws2_32.dll | 165 | getaddrinfo | |
ws2_32.dll | 2 | FreeAddrInfoW | |
ws2_32.dll | 163 | connect | |
ws2_32.dll | 194 | socket | |
ws2_32.dll | 193 | shutdown | |
ws2_32.dll | 162 | closesocket | |
ws2_32.dll | 170 | getpeername | |
ws2_32.dll | 176 | getsockopt | |
ws2_32.dll | 178 | htons | |
ws2_32.dll | 161 | bind | |
ws2_32.dll | 175 | getsockname | |
ws2_32.dll | 192 | setsockopt | |
ws2_32.dll | 58 | WSAIoctl | |
ws2_32.dll | 190 | send | |
ws2_32.dll | 187 | recv | |
ws2_32.dll | 189 | select | |
ws2_32.dll | 47 | WSAGetLastError | |
ws2_32.dll | 159 | __WSAFDIsSet | |
ws2_32.dll | 83 | WSASetLastError | |
ws2_32.dll | 88 | WSAStartup | |
ws2_32.dll | 30 | WSACleanup |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK