filename | oem8.exe | |
---|---|---|
size | 1272128 (0x136940) | |
md5 | 2793c5b68f0333fdc9763e544300e1ea | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
This file is packed with ASPack. Analysis will be incomplete without unpacking. |
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x71c000 | 0x71c040 | 0x6f8c18 | 0x71d010 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetProcAddress | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
oleaut32.dll | SysFreeString | ||
advapi32.dll | RegQueryValueExW | ||
user32.dll | MessageBoxA | ||
user32.dll | SetClassLongW | ||
gdi32.dll | UnrealizeObject | ||
version.dll | VerQueryValueW | ||
advapi32.dll | RegUnLoadKeyW | ||
oleaut32.dll | SafeArrayGetElemsize | ||
oleaut32.dll | GetErrorInfo | ||
ole32.dll | OleUninitialize | ||
comctl32.dll | InitializeFlatSB | ||
user32.dll | EnumDisplayMonitors | ||
msvcrt.dll | isxdigit | ||
shell32.dll | Shell_NotifyIconW | ||
winspool.drv | OpenPrinterW | ||
winspool.drv | GetDefaultPrinterW |
ord | entry_va | function_name | |
---|---|---|---|
1 | 0x641ac | TMethodImplementationIntercept |
StringTable 040904E4
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
VS_FIXEDFILEINFO
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
Signers (1)
issuer: /C=CN/ST=Beijing/L=Beijing/O=CA365/CN=CA365 Free Root Certificate
serial: 7CDC4BB3DB655FB4
Certificates (2)
Certificate: Data: Version: 3 (0x2) Serial Number: 8997149391431491508 (0x7cdc4bb3db655fb4) Signature Algorithm: sha1WithRSAEncryption Issuer: C=CN, ST=Beijing, L=Beijing, O=CA365, CN=CA365 Free Root Certificate Validity Not Before: Jun 26 01:35:41 2014 GMT Not After : Jun 26 01:35:41 2015 GMT Subject: C=CN, ST=beijing, L=beijing, O=xiaoma, OU=xiaoma, CN=oem7f7 Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (512 bit) Modulus: 00:a8:de:a8:5c:a8:79:bf:d2:0f:36:37:f3:14:a1: 4e:15:1a:c5:c0:1d:86:e6:6d:a4:9d:fb:7d:fc:4f: 30:d2:09:a5:07:ae:43:33:ae:95:36:f1:61:9e:6b: de:7f:13:88:d7:a5:5f:68:0e:d3:e5:0c:fb:f8:37: 13:b0:e4:50:ef Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 8F:88:C8:1F:3B:E7:F2:B9:E8:E9:A7:73:A6:DC:44:BB:9D:15:F9:FE X509v3 Key Usage: critical Digital Signature, Non Repudiation, Key Encipherment, Data Encipherment X509v3 Subject Alternative Name: email:asd@qq.cc, URI:http://www.baidu.com X509v3 Issuer Alternative Name: URI:http://www.ca365.com X509v3 Basic Constraints: critical CA:FALSE X509v3 CRL Distribution Points: Full Name: URI:http://www.ca365.com/CA365FreeCRL.crl?34185 X509v3 Authority Key Identifier: keyid:FE:61:74:A3:C1:4B:AD:2B:C0:71:C3:A5:A2:4C:00:03:D9:20:C3:1C serial:24:E1:BD:38:4A:95:29:F8 X509v3 Extended Key Usage: Code Signing Signature Algorithm: sha1WithRSAEncryption 36:11:54:af:f3:94:13:31:00:22:23:88:d7:ca:70:3c:6b:44: f7:32:7a:48:6d:73:3b:77:0b:f5:10:f1:cc:98:05:ac:35:94: 36:60:0d:82:31:98:1f:96:5f:6a:d5:c7:ee:78:6f:da:f2:50: f5:af:8f:0a:6e:95:d3:39:99:bf:0b:33:14:ee:03:78:0b:8f: 83:9c:c2:35:53:25:b4:4e:e8:71:51:d3:33:66:2f:f9:a6:1f: b9:49:cc:f6:63:4a:38:6b:a3:bf:65:14:de:f0:3a:9a:20:40: 2d:0a:83:07:53:86:5b:7a:a2:19:04:39:14:28:5a:e0:b1:0e: 2f:3c:60:27:cc:9a:a8:d2:c9:fb:80:5a:6a:53:5c:d9:4b:f7: 37:43:a0:7f:f9:a2:d3:d9:96:6e:13:d4:e6:9d:b6:75:a0:1f: 78:6e:8f:ff:21:80:e3:d8:aa:a7:3e:f9:59:d9:89:9a:d8:b7: 90:7a:4d:50:dd:2c:16:30:d6:c1:d2:da:24:47:d6:56:6d:3c: 93:8b:44:f8:a9:37:bf:f7:58:05:a9:e4:c1:e3:77:58:d5:9e: 90:59:e1:bd:96:f2:55:b3:48:bc:fa:ea:1b:d9:a5:51:29:b8: e6:2f:cc:7b:75:68:01:c9:51:bb:1a:57:2f:20:e0:41:35:ae: 26:f0:3c:56
Certificate: Data: Version: 3 (0x2) Serial Number: 2657613304592411128 (0x24e1bd384a9529f8) Signature Algorithm: sha1WithRSAEncryption Issuer: C=CN, ST=Beijing, L=Beijing, O=CA365, CN=CA365 Free Root Certificate Validity Not Before: May 12 08:40:41 2001 GMT Not After : May 5 08:40:41 2031 GMT Subject: C=CN, ST=Beijing, L=Beijing, O=CA365, CN=CA365 Free Root Certificate Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:e5:09:8a:a9:ca:21:50:43:0f:9b:4f:93:1e:e2: e2:f6:61:fe:60:77:8f:e7:ac:c8:fe:69:cb:ac:70: ed:fd:b0:0f:61:4a:58:4c:7f:2d:4d:07:99:c6:4e: 50:49:19:47:e7:b4:77:bd:a0:17:5d:f9:ac:1e:5f: b3:84:7f:bd:6e:3b:be:41:4f:ef:4c:96:76:e9:37: 43:df:2a:78:40:62:09:68:f5:a0:8a:ae:eb:78:a7: b1:02:f6:a8:92:7d:fb:9c:43:dd:2d:fc:01:6a:b1: 4e:95:f3:18:b4:eb:a6:fb:89:30:dc:00:28:95:aa: e5:14:8c:21:b1:65:ff:2a:02:a6:07:d5:cf:e8:88: 18:ff:60:8d:ff:fe:3c:93:85:d3:c8:a2:e8:13:99: 17:28:11:1a:45:98:d1:cd:8f:8a:ec:81:39:79:f2: 65:c7:12:35:61:48:56:85:a4:45:3e:11:c9:45:35: a2:38:dd:6d:58:f9:cd:ea:f4:ae:81:da:0a:99:13: 45:11:1f:ef:e6:42:de:05:17:10:93:ae:d9:5e:cc: aa:9e:e8:28:fa:bf:65:ab:25:a2:bb:01:d6:c2:8c: c9:75:81:5b:02:0b:f4:cb:1d:1c:a9:46:61:17:45: 0f:05:bb:15:26:ca:fe:27:d1:14:4a:ce:9e:4f:ba: c7:31 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: FE:61:74:A3:C1:4B:AD:2B:C0:71:C3:A5:A2:4C:00:03:D9:20:C3:1C X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Subject Alternative Name: URI:http://www.ca365.com X509v3 Basic Constraints: critical CA:TRUE Signature Algorithm: sha1WithRSAEncryption cc:8a:9c:fa:d5:ef:75:6d:08:55:78:65:c2:f4:27:67:1b:e0: c1:a0:75:b0:d8:bc:6c:a5:b4:4b:ab:70:57:2a:1d:39:ba:12: 76:7e:f3:f9:d1:aa:8b:38:95:78:8b:0e:6a:6f:a6:08:4d:6f: 0b:bd:26:1f:ea:d7:e0:5c:f8:fe:6b:1c:0f:f3:8b:a4:06:06: 20:db:d1:5c:7d:66:d5:29:6e:8f:c5:09:65:19:38:b6:2e:0b: c4:c5:3a:7a:02:af:07:4c:30:eb:8b:91:25:50:8b:6f:1a:d0: d1:02:32:8d:81:30:12:7a:6c:c3:b6:9b:9f:38:81:61:a2:6f: 58:e8:93:e4:c5:47:ce:48:e5:87:7d:5d:7c:4f:1d:97:e4:e2: 4b:70:3f:e1:aa:9e:5c:6f:a7:f9:0b:d6:0d:ea:49:78:27:3e: ff:91:93:b5:6a:23:f4:d1:59:9d:7f:9c:2a:2c:b6:af:a8:4a: 33:86:0d:19:35:b7:60:ce:f5:49:9e:57:86:a4:56:27:8f:66: 5b:28:b7:1d:9b:bc:14:97:4f:c9:7c:2e:3f:c0:87:d1:69:24: c1:ea:4d:2e:ff:3a:78:c9:39:1e:c6:16:f5:ac:e5:47:29:d1: d4:23:20:b7:fe:ea:b8:69:f4:1c:4b:01:93:03:51:db:e3:bf: a3:b5:d3:9d
- 1
- SHA1: nil
- 1.3.6.1.4.1.311.2.1.4
- #0
- 1.3.6.1.4.1.311.2.1.15
- :
00 3c 00 3c 00 3c 00 4f 00 62 00 73 00 6f 00 6c |.<.<.<.O.b.s.o.l| 00 65 00 74 00 65 00 3e 00 3e 00 3e |.e.t.e.>.>.> |
- :
- SHA1
5b 86 6c 5a a6 97 4b 57 2a 25 e8 e9 a1 bb 17 dd |[.lZ..KW*%......| 02 0c 0b ab |.... |
- 1.3.6.1.4.1.311.2.1.15
- #0
- Certificates
- Certificate #0
- 2
- 7C:DC:4B:B3:DB:65:5F:B4
- RSA-SHA1: nil
- Issuer
- C: CN
- ST: Beijing
- L: Beijing
- O: CA365
- CN: CA365 Free Root Certificate
- 2014-06-26 01:35:41 UTC: 2015-06-26 01:35:41 UTC
- Subject
- C: CN
- ST: beijing
- L: beijing
- O: xiaoma
- OU: xiaoma
- CN: oem7f7
- #5
- rsaEncryption: nil
- A8:DE:A8:5C:A8:79:BF:D2:0F:36:37:F3:14:A1:4E:15:
1A:C5:C0:1D:86:E6:6D:A4:9D:FB:7D:FC:4F:30:D2:09:
A5:07:AE:43:33:AE:95:36:F1:61:9E:6B:DE:7F:13:88:
D7:A5:5F:68:0E:D3:E5:0C:FB:F8:37:13:B0:E4:50:EF: 0x010001
- #6
- subjectKeyIdentifier:
8f 88 c8 1f 3b e7 f2 b9 e8 e9 a7 73 a6 dc 44 bb |....;......s..D.| 9d 15 f9 fe |.... |
- keyUsage: true, 0xf0
- subjectAltName
- asd@qq.cc: http://www.baidu.com
- issuerAltName: http://www.ca365.com
- basicConstraints
- true
- nil
- crlDistributionPoints: http://www.ca365.com/CA365FreeCRL.crl?34185
- authorityKeyIdentifier
fe 61 74 a3 c1 4b ad 2b c0 71 c3 a5 a2 4c 00 03 |.at..K.+.q...L..| d9 20 c3 1c |. .. |
:24 e1 bd 38 4a 95 29 f8 |$..8J.). |
- extendedKeyUsage: codeSigning
- subjectKeyIdentifier:
- RSA-SHA1:
36 11 54 af f3 94 13 31 00 22 23 88 d7 ca 70 3c |6.T....1."#...p<| 6b 44 f7 32 7a 48 6d 73 3b 77 0b f5 10 f1 cc 98 |kD.2zHms;w......| 05 ac 35 94 36 60 0d 82 31 98 1f 96 5f 6a d5 c7 |..5.6`..1..._j..| ee 78 6f da f2 50 f5 af 8f 0a 6e 95 d3 39 99 bf |.xo..P....n..9..| 0b 33 14 ee 03 78 0b 8f 83 9c c2 35 53 25 b4 4e |.3...x.....5S%.N| e8 71 51 d3 33 66 2f f9 a6 1f b9 49 cc f6 63 4a |.qQ.3f/....I..cJ| 38 6b a3 bf 65 14 de f0 3a 9a 20 40 2d 0a 83 07 |8k..e...:. @-...| 53 86 5b 7a a2 19 04 39 14 28 5a e0 b1 0e 2f 3c |S.[z...9.(Z.../<| 60 27 cc 9a a8 d2 c9 fb 80 5a 6a 53 5c d9 4b f7 |`'.......ZjS\.K.| 37 43 a0 7f f9 a2 d3 d9 96 6e 13 d4 e6 9d b6 75 |7C.......n.....u| a0 1f 78 6e 8f ff 21 80 e3 d8 aa a7 3e f9 59 d9 |..xn..!.....>.Y.| 89 9a d8 b7 90 7a 4d 50 dd 2c 16 30 d6 c1 d2 da |.....zMP.,.0....| 24 47 d6 56 6d 3c 93 8b 44 f8 a9 37 bf f7 58 05 |$G.Vm<..D..7..X.| a9 e4 c1 e3 77 58 d5 9e 90 59 e1 bd 96 f2 55 b3 |....wX...Y....U.| 48 bc fa ea 1b d9 a5 51 29 b8 e6 2f cc 7b 75 68 |H......Q)../.{uh| 01 c9 51 bb 1a 57 2f 20 e0 41 35 ae 26 f0 3c 56 |..Q..W/ .A5.&.
- 2
- Certificate #1
- 2
- 24:E1:BD:38:4A:95:29:F8
- RSA-SHA1: nil
- Issuer
- C: CN
- ST: Beijing
- L: Beijing
- O: CA365
- CN: CA365 Free Root Certificate
- 2001-05-12 08:40:41 UTC: 2031-05-05 08:40:41 UTC
- Subject
- C: CN
- ST: Beijing
- L: Beijing
- O: CA365
- CN: CA365 Free Root Certificate
- #5
- rsaEncryption: nil
- E5:09:8A:A9:CA:21:50:43:0F:9B:4F:93:1E:E2:E2:F6:
61:FE:60:77:8F:E7:AC:C8:FE:69:CB:AC:70:ED:FD:B0:
0F:61:4A:58:4C:7F:2D:4D:07:99:C6:4E:50:49:19:47:
E7:B4:77:BD:A0:17:5D:F9:AC:1E:5F:B3:84:7F:BD:6E:
3B:BE:41:4F:EF:4C:96:76:E9:37:43:DF:2A:78:40:62:
09:68:F5:A0:8A:AE:EB:78:A7:B1:02:F6:A8:92:7D:FB:
9C:43:DD:2D:FC:01:6A:B1:4E:95:F3:18:B4:EB:A6:FB:
89:30:DC:00:28:95:AA:E5:14:8C:21:B1:65:FF:2A:02:
A6:07:D5:CF:E8:88:18:FF:60:8D:FF:FE:3C:93:85:D3:
C8:A2:E8:13:99:17:28:11:1A:45:98:D1:CD:8F:8A:EC:
81:39:79:F2:65:C7:12:35:61:48:56:85:A4:45:3E:11:
C9:45:35:A2:38:DD:6D:58:F9:CD:EA:F4:AE:81:DA:0A:
99:13:45:11:1F:EF:E6:42:DE:05:17:10:93:AE:D9:5E:
CC:AA:9E:E8:28:FA:BF:65:AB:25:A2:BB:01:D6:C2:8C:
C9:75:81:5B:02:0B:F4:CB:1D:1C:A9:46:61:17:45:0F:
05:BB:15:26:CA:FE:27:D1:14:4A:CE:9E:4F:BA:C7:31: 0x010001
- #6
- subjectKeyIdentifier:
fe 61 74 a3 c1 4b ad 2b c0 71 c3 a5 a2 4c 00 03 |.at..K.+.q...L..| d9 20 c3 1c |. .. |
- keyUsage: true, 6
- subjectAltName: http://www.ca365.com
- basicConstraints: true, true
- subjectKeyIdentifier:
- RSA-SHA1:
cc 8a 9c fa d5 ef 75 6d 08 55 78 65 c2 f4 27 67 |......um.Uxe..'g| 1b e0 c1 a0 75 b0 d8 bc 6c a5 b4 4b ab 70 57 2a |....u...l..K.pW*| 1d 39 ba 12 76 7e f3 f9 d1 aa 8b 38 95 78 8b 0e |.9..v~.....8.x..| 6a 6f a6 08 4d 6f 0b bd 26 1f ea d7 e0 5c f8 fe |jo..Mo..&....\..| 6b 1c 0f f3 8b a4 06 06 20 db d1 5c 7d 66 d5 29 |k....... ..\}f.)| 6e 8f c5 09 65 19 38 b6 2e 0b c4 c5 3a 7a 02 af |n...e.8.....:z..| 07 4c 30 eb 8b 91 25 50 8b 6f 1a d0 d1 02 32 8d |.L0...%P.o....2.| 81 30 12 7a 6c c3 b6 9b 9f 38 81 61 a2 6f 58 e8 |.0.zl....8.a.oX.| 93 e4 c5 47 ce 48 e5 87 7d 5d 7c 4f 1d 97 e4 e2 |...G.H..}]|O....| 4b 70 3f e1 aa 9e 5c 6f a7 f9 0b d6 0d ea 49 78 |Kp?...\o......Ix| 27 3e ff 91 93 b5 6a 23 f4 d1 59 9d 7f 9c 2a 2c |'>....j#..Y...*,| b6 af a8 4a 33 86 0d 19 35 b7 60 ce f5 49 9e 57 |...J3...5.`..I.W| 86 a4 56 27 8f 66 5b 28 b7 1d 9b bc 14 97 4f c9 |..V'.f[(......O.| 7c 2e 3f c0 87 d1 69 24 c1 ea 4d 2e ff 3a 78 c9 ||.?...i$..M..:x.| 39 1e c6 16 f5 ac e5 47 29 d1 d4 23 20 b7 fe ea |9......G)..# ...| b8 69 f4 1c 4b 01 93 03 51 db e3 bf a3 b5 d3 9d |.i..K...Q.......|
- 2
- Certificate #0
- Signer
- 1
- unnamed
- #0
- C: CN
- ST: Beijing
- L: Beijing
- O: CA365
- CN: CA365 Free Root Certificate
- 7C:DC:4B:B3:DB:65:5F:B4
- #0
- SHA1: nil
- #3
- 1.3.6.1.4.1.311.2.1.12
- nil
- contentType: 1.3.6.1.4.1.311.2.1.4
- 1.3.6.1.4.1.311.2.1.11: msCodeInd
- messageDigest:
7f 17 c8 d9 4f 30 63 bb 8b a8 70 f9 ae 02 7c 6c |....O0c...p...|l| 04 c0 57 d2 |..W. |
- 1.3.6.1.4.1.311.2.1.12
- rsaEncryption:
57 f5 c9 58 bc 9f 57 36 20 a3 f1 b7 18 94 53 5c |W..X..W6 .....S\| 5e 7a 4f 57 01 d4 17 52 ea e6 93 5a 6d c6 67 de |^zOW...R...Zm.g.| 5f 27 82 9e 72 5a 67 7d 45 0d 08 a6 43 06 16 7e |_'..rZg}E...C..~| e6 85 88 f9 93 9d 9f 4b 3e fb 75 00 98 e6 56 15 |.......K>.u...V.|
offset | size | type | comment | |
---|---|---|---|---|
0 | 1269760 | EXE | 04/30/2014 08:09:37 | # |
15c1 | 15 | HTM | # | |
129d54 | 39782 | PNG | (256 x 256) | # |
136000 | 2368 | PKCS7 | Authenticode Signature | # |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x3daf6c
[?] can't find file_offset of VA 0x3ddbe8
[?] can't find file_offset of VA 0x3ff5e8
[?] can't find file_offset of VA 0x4171e8
[?] can't find file_offset of VA 0x4181e8
[?] can't find file_offset of VA 0x4193e8
[?] can't find file_offset of VA 0x430fe8
[?] can't find file_offset of VA 0x431fe8
[?] can't find file_offset of VA 0x432a94
[?] can't find file_offset of VA 0x432bc8
[?] can't find file_offset of VA 0x432cfc
[?] can't find file_offset of VA 0x432e30
[?] can't find file_offset of VA 0x432f64
[?] can't find file_offset of VA 0x433098
[?] can't find file_offset of VA 0x4331cc
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x443050
[?] can't find file_offset of VA 0x4432c4
[?] can't find file_offset of VA 0x4436b4
[?] can't find file_offset of VA 0x4439b0
[?] can't find file_offset of VA 0x443ddc
[?] can't find file_offset of VA 0x4441d4
[?] can't find file_offset of VA 0x445064
[?] can't find file_offset of VA 0x445b2c
[?] can't find file_offset of VA 0x446600
[?] can't find file_offset of VA 0x446eec
[?] can't find file_offset of VA 0x447658
[?] can't find file_offset of VA 0x4478d0
[?] can't find file_offset of VA 0x447e30
[?] can't find file_offset of VA 0x4481dc
[?] can't find file_offset of VA 0x44862c
[?] can't find file_offset of VA 0x448970
[?] can't find file_offset of VA 0x448d90
[?] can't find file_offset of VA 0x449178
[?] can't find file_offset of VA 0x44953c
[?] can't find file_offset of VA 0x44985c
[?] can't find file_offset of VA 0x449b70
[?] can't find file_offset of VA 0x449f84
[?] can't find file_offset of VA 0x44a2dc
[?] can't find file_offset of VA 0x44a704
[?] can't find file_offset of VA 0x44a860
[?] can't find file_offset of VA 0x44a934
[?] can't find file_offset of VA 0x44ab48
[?] can't find file_offset of VA 0x44af10
[?] can't find file_offset of VA 0x44b304
[?] can't find file_offset of VA 0x44b74c
[?] can't find file_offset of VA 0x44baa8
[?] can't find file_offset of VA 0x44bed8
[?] can't find file_offset of VA 0x44c574
[?] can't find file_offset of VA 0x44c8f8
[?] can't find file_offset of VA 0x44cc9c
[?] can't find file_offset of VA 0x44d09c
[?] can't find file_offset of VA 0x44d1d4
[?] can't find file_offset of VA 0x44d2a0
[?] can't find file_offset of VA 0x44d498
[?] can't find file_offset of VA 0x44d8a4
[?] can't find file_offset of VA 0x44dca8
[?] can't find file_offset of VA 0x44df94
[?] can't find file_offset of VA 0x44e2b0
[?] can't find file_offset of VA 0x44e2c0
[?] can't find file_offset of VA 0x44efa4
[?] can't find file_offset of VA 0x44efa8
[?] can't find file_offset of VA 0x44f900
[?] can't find file_offset of VA 0x44f914
[?] can't find file_offset of VA 0x44f928
[?] can't find file_offset of VA 0x44f93c
[?] can't find file_offset of VA 0x44f950
[?] can't find file_offset of VA 0x44f964
[?] can't find file_offset of VA 0x44f978
[?] can't find file_offset of VA 0x0