3.4
中危

07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797

07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe

分析耗时

133s

最近分析

380天前

文件大小

446.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM FASONG
鹰眼引擎
DACN 0.15
FACILE 1.00
IMCLNet 0.76
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Trojan:Win32/starter.ali1000030 20190527 0.3.0.5
Baidu Win32.Trojan-PSW.OLGames.bm 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Kingsoft None 20200110 2013.8.14.323
McAfee PWS-QQPass 20200110 6.0.6.653
Tencent Malware.Win32.Gencirc.10b0de38 20200110 1.0.0.1
静态指标
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (5 个事件)
section CODE
section DATA
section BSS
section .aspack
section .adata
文件包含未知的 PE 资源名称,可能指示打包器 (1 个事件)
resource name LARGEICON
一个或多个进程崩溃 (1 个事件)
Time & API Arguments Status Return Repeated
1727545311.82775
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xeedfade
registers.eax: 1637796
registers.ecx: 7
registers.edx: 0
registers.ebx: 31534016
registers.esp: 1637796
registers.ebp: 1637876
registers.esi: 1
registers.edi: 0
stacktrace:
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x496be @ 0x4496be
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x495e2 @ 0x4495e2
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x55523 @ 0x455523
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x559dc @ 0x4559dc
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x55bfc @ 0x455bfc
07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797+0x56bf3 @ 0x456bf3
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76ee33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x775b9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x775b9ea5

success 0 0
行为判定
动态指标
分配可读-可写-可执行内存(通常用于自解压) (2 个事件)
Time & API Arguments Status Return Repeated
1727545311.46875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x01c90000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727545313.671875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x003e0000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1972
success 0 0
检查是否有任何人类活动正在进行,通过不断检查前景窗口是否发生变化
一个进程试图延迟分析任务。 (1 个事件)
description 360TptMon.exe 试图睡眠 310.0 秒,实际延迟分析时间 310.0 秒
在 PE 资源中识别到外语 (3 个事件)
name LARGEICON language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000657cc size 0x0000d000
name RT_ICON language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00079238 size 0x000008a8
name RT_GROUP_ICON language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00079224 size 0x00000014
在文件系统上创建可执行文件 (10 个事件)
file C:\Program Files (x86)\STOOS.EXE
file C:\Program Files (x86)\GRVIK.EXE
file C:\Windows\System32\ZGARM.EXE
file C:\Python27\HOFVPF.EXE
file C:\rfaulke\WEQDVK.EXE
file C:\Windows\System32\Ms7002.dll
file C:\Program Files (x86)\ZDKFQ.EXE
file C:\gcoxh\360TptMon.exe
file C:\Program Files\taskhost.exe
file C:\$Recycle.Bin\SUW.EXE
创建可疑进程 (1 个事件)
cmdline Regsvr32.exe C:\Windows\system32\Ms7002.dll /s
搜索运行中的进程,可能用于识别沙箱规避、代码注入或内存转储的进程 (1 个事件)
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (1 个事件)
section {'name': '.rsrc', 'virtual_address': '0x00065000', 'virtual_size': '0x00013000', 'size_of_data': '0x00013000', 'entropy': 7.043726576344445} entropy 7.043726576344445 description 发现高熵的节
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
在 Windows 启动时自我安装以实现自动运行 (2 个事件)
service_name WEQDVK.EXE service_path C:\rfaulke\WEQDVK.EXE
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\SVEAN.EXE reg_value C:\Program Files\taskhost.exe
创建了一个服务,但该服务并未启动 (1 个事件)
Time & API Arguments Status Return Repeated
1727545311.76575
CreateServiceA
service_manager_handle: 0x00310bb0
service_name: WEQDVK.EXE
display_name: WEQDVK.EXE
desired_access: 983551
service_type: 272
start_type: 2
error_control: 1
service_start_name:
password:
service_handle: 0x00310b10
filepath: C:\rfaulke\WEQDVK.EXE
filepath_r: C:\rfaulke\WEQDVK.EXE
success 3214096 0
文件已被 VirusTotal 上 61 个反病毒引擎识别为恶意 (50 out of 61 个事件)
ALYac Gen:Heur.Mint.Zard.30
APEX Malicious
AVG Win32:Trojan-gen
Acronis suspicious
Ad-Aware Gen:Heur.Mint.Zard.30
AhnLab-V3 Trojan/Win32.Reconyc.C2787121
Alibaba Trojan:Win32/starter.ali1000030
Antiy-AVL Worm/Win32.Fasong
Arcabit Trojan.Mint.Zard.30
Avira BDS/Delf.H
Baidu Win32.Trojan-PSW.OLGames.bm
BitDefender Gen:Heur.Mint.Zard.30
BitDefenderTheta Gen:NN.ZelphiF.34080.BOX@aSi68chb
Bkav W32.AIDetectVM.malware
CAT-QuickHeal Trojan.Reconyc.S262884
CMC Worm.Win32.Fasong!O
ClamAV Win.Trojan.Fasong-9
Comodo Worm.Win32.Fasong.G@ab2f
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.8be761
Cylance Unsafe
Cyren W32/Worm.XCWL-3208
DrWeb Win32.HLLW.Fasong.7
ESET-NOD32 Win32/Fasong.G
Emsisoft Gen:Heur.Mint.Zard.30 (B)
Endgame malicious (high confidence)
F-Prot W32/SysVenFak.A.gen!Eldorado
F-Secure Backdoor.BDS/Delf.H
FireEye Generic.mg.b2806008be761116
Fortinet W32/Fasong.GA!worm
GData Gen:Heur.Mint.Zard.30
Ikarus Worm.Win32.Fasong
Invincea heuristic
Jiangmin Worm/Fasong.a
K7AntiVirus Trojan ( 7000000f1 )
K7GW Trojan ( 7000000f1 )
Kaspersky Trojan.Win32.Fsysna.djfi
Lionic Worm.Win32.Fasong.l6SH
MAX malware (ai score=85)
Malwarebytes Worm.Fasong
McAfee PWS-QQPass
McAfee-GW-Edition BehavesLike.Win32.PWSQQPass.gh
MicroWorld-eScan Gen:Heur.Mint.Zard.30
Microsoft Worm:Win32/Ming.A
NANO-Antivirus Trojan.Win32.Legmir.bonls
Paloalto generic.ml
Panda Trj/Genetic.gen
Qihoo-360 Win32/Trojan.5c6
Rising Worm.Ming!1.692A (CLOUD)
Sangfor Malware
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:22:17

PE Imphash

d5ada287cb0bdf614b7546b62f89ebb1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x00056000 0x00055e00 6.50398534078104
DATA 0x00057000 0x00002000 0x00001c00 4.159999925073857
BSS 0x00059000 0x00001000 0x00000000 0.0
.idata 0x0005a000 0x00003000 0x00002400 5.030703588344266
.tls 0x0005d000 0x00001000 0x00000000 0.0
.rdata 0x0005e000 0x00001000 0x00000200 0.1952012677871819
.reloc 0x0005f000 0x00006000 0x00000000 0.0
.rsrc 0x00065000 0x00013000 0x00013000 7.043726576344445
.aspack 0x00078000 0x00002000 0x00001c00 5.57131076740931
.adata 0x0007a000 0x00001000 0x00000000 0.0

Resources

Name Offset Size Language Sub-language File type
LARGEICON 0x000657cc 0x0000d000 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00072f04 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_ICON 0x00079238 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00075524 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00076120 0x00001de6 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00076120 0x00001de6 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00076120 0x00001de6 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00076120 0x00001de6 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00076120 0x00001de6 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00077f80 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00079224 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None

Imports

Library kernel32.dll:
0x45a118 GetCurrentThreadId
0x45a12c VirtualFree
0x45a130 VirtualAlloc
0x45a134 LocalFree
0x45a138 LocalAlloc
0x45a144 VirtualQuery
0x45a148 WideCharToMultiByte
0x45a14c MultiByteToWideChar
0x45a150 lstrlenA
0x45a154 lstrcpynA
0x45a158 lstrcpyA
0x45a15c LoadLibraryExA
0x45a160 GetThreadLocale
0x45a164 GetStartupInfoA
0x45a168 GetProcAddress
0x45a16c GetModuleHandleA
0x45a170 GetModuleFileNameA
0x45a174 GetLocaleInfoA
0x45a178 GetLastError
0x45a17c GetCommandLineA
0x45a180 FreeLibrary
0x45a184 FindFirstFileA
0x45a188 FindClose
0x45a18c ExitProcess
0x45a190 ExitThread
0x45a194 CreateThread
0x45a198 WriteFile
0x45a1a0 SetFilePointer
0x45a1a4 SetEndOfFile
0x45a1a8 RtlUnwind
0x45a1ac ReadFile
0x45a1b0 RaiseException
0x45a1b4 GetStdHandle
0x45a1b8 GetFileSize
0x45a1bc GetSystemTime
0x45a1c0 GetFileType
0x45a1c4 CreateFileA
0x45a1c8 CloseHandle
Library user32.dll:
0x45a1d0 GetKeyboardType
0x45a1d4 LoadStringA
0x45a1d8 MessageBoxA
0x45a1dc CharNextA
Library advapi32.dll:
0x45a1e4 RegQueryValueExA
0x45a1e8 RegOpenKeyExA
0x45a1ec RegCloseKey
Library oleaut32.dll:
0x45a1f4 VariantChangeTypeEx
0x45a1f8 VariantCopyInd
0x45a1fc VariantClear
0x45a200 SysStringLen
0x45a204 SysFreeString
0x45a208 SysReAllocStringLen
0x45a20c SysAllocStringLen
Library kernel32.dll:
0x45a214 TlsSetValue
0x45a218 TlsGetValue
0x45a21c LocalAlloc
0x45a220 GetModuleHandleA
0x45a224 GetModuleFileNameA
Library advapi32.dll:
0x45a22c ReportEventA
0x45a234 RegSetValueExA
0x45a238 RegQueryValueExA
0x45a23c RegOpenKeyExA
0x45a240 RegFlushKey
0x45a244 RegCreateKeyExA
0x45a248 RegCloseKey
Library kernel32.dll:
0x45a254 lstrcpyA
0x45a258 WriteFile
0x45a25c WinExec
0x45a260 WaitForSingleObject
0x45a264 VirtualQuery
0x45a268 VirtualAlloc
0x45a26c TerminateProcess
0x45a270 SuspendThread
0x45a274 Sleep
0x45a278 SizeofResource
0x45a27c SetThreadLocale
0x45a280 SetFilePointer
0x45a284 SetEvent
0x45a288 SetErrorMode
0x45a28c SetEndOfFile
0x45a290 ResumeThread
0x45a294 ReadFile
0x45a298 OpenProcess
0x45a29c OpenMutexA
0x45a2a0 MulDiv
0x45a2a4 LockResource
0x45a2a8 LoadResource
0x45a2ac LoadLibraryA
0x45a2b8 GlobalUnlock
0x45a2bc GlobalReAlloc
0x45a2c0 GlobalHandle
0x45a2c4 GlobalLock
0x45a2c8 GlobalFree
0x45a2cc GlobalDeleteAtom
0x45a2d0 GlobalAlloc
0x45a2d4 GlobalAddAtomA
0x45a2d8 GetVersionExA
0x45a2dc GetVersion
0x45a2e0 GetTickCount
0x45a2e4 GetThreadLocale
0x45a2e8 GetSystemInfo
0x45a2ec GetSystemDirectoryA
0x45a2f0 GetProcAddress
0x45a2f4 GetModuleHandleA
0x45a2f8 GetModuleFileNameA
0x45a2fc GetLocaleInfoA
0x45a300 GetLastError
0x45a304 GetExitCodeThread
0x45a308 GetDriveTypeA
0x45a30c GetDiskFreeSpaceA
0x45a310 GetCurrentThreadId
0x45a314 GetCurrentProcessId
0x45a318 GetCPInfo
0x45a31c FreeResource
0x45a320 FreeLibrary
0x45a324 FormatMessageA
0x45a328 FindResourceA
0x45a32c FindNextFileA
0x45a330 FindFirstFileA
0x45a334 FindClose
0x45a340 EnumCalendarInfoA
0x45a34c CreateThread
0x45a350 CreateMutexA
0x45a354 CreateFileA
0x45a358 CreateEventA
0x45a35c CompareStringA
0x45a360 CloseHandle
Library gdi32.dll:
0x45a368 UnrealizeObject
0x45a36c StretchBlt
0x45a370 SetWindowOrgEx
0x45a374 SetWinMetaFileBits
0x45a378 SetViewportOrgEx
0x45a37c SetTextColor
0x45a380 SetStretchBltMode
0x45a384 SetROP2
0x45a388 SetPixel
0x45a38c SetEnhMetaFileBits
0x45a390 SetDIBColorTable
0x45a394 SetBrushOrgEx
0x45a398 SetBkMode
0x45a39c SetBkColor
0x45a3a0 SelectPalette
0x45a3a4 SelectObject
0x45a3a8 SaveDC
0x45a3ac RestoreDC
0x45a3b0 Rectangle
0x45a3b4 RectVisible
0x45a3b8 RealizePalette
0x45a3bc PlayEnhMetaFile
0x45a3c0 PatBlt
0x45a3c4 MoveToEx
0x45a3c8 MaskBlt
0x45a3cc LineTo
0x45a3d0 IntersectClipRect
0x45a3d4 GetWindowOrgEx
0x45a3d8 GetWinMetaFileBits
0x45a3dc GetTextMetricsA
0x45a3e0 GetTextExtentPointA
0x45a3ec GetStockObject
0x45a3f0 GetPixel
0x45a3f4 GetPaletteEntries
0x45a3f8 GetObjectA
0x45a404 GetEnhMetaFileBits
0x45a408 GetDeviceCaps
0x45a40c GetDIBits
0x45a410 GetDIBColorTable
0x45a414 GetDCOrgEx
0x45a41c GetClipBox
0x45a420 GetBrushOrgEx
0x45a424 GetBitmapBits
0x45a428 ExcludeClipRect
0x45a42c DeleteObject
0x45a430 DeleteEnhMetaFile
0x45a434 DeleteDC
0x45a438 CreateSolidBrush
0x45a43c CreatePenIndirect
0x45a440 CreatePalette
0x45a448 CreateFontIndirectA
0x45a44c CreateDIBitmap
0x45a450 CreateDIBSection
0x45a454 CreateCompatibleDC
0x45a45c CreateBrushIndirect
0x45a460 CreateBitmap
0x45a464 CopyEnhMetaFileA
0x45a468 BitBlt
Library user32.dll:
0x45a470 WindowFromPoint
0x45a474 WinHelpA
0x45a478 WaitMessage
0x45a47c UpdateWindow
0x45a480 UnregisterClassA
0x45a484 UnhookWindowsHookEx
0x45a488 TranslateMessage
0x45a490 TrackPopupMenu
0x45a498 ShowWindow
0x45a49c ShowScrollBar
0x45a4a0 ShowOwnedPopups
0x45a4a4 ShowCursor
0x45a4a8 SetWindowsHookExA
0x45a4ac SetWindowTextA
0x45a4b0 SetWindowPos
0x45a4b4 SetWindowPlacement
0x45a4b8 SetWindowLongA
0x45a4bc SetTimer
0x45a4c0 SetScrollRange
0x45a4c4 SetScrollPos
0x45a4c8 SetScrollInfo
0x45a4cc SetRect
0x45a4d0 SetPropA
0x45a4d4 SetMenuItemInfoA
0x45a4d8 SetMenu
0x45a4dc SetForegroundWindow
0x45a4e0 SetFocus
0x45a4e4 SetCursor
0x45a4e8 SetClassLongA
0x45a4ec SetCapture
0x45a4f0 SetActiveWindow
0x45a4f4 SendMessageA
0x45a4f8 ScrollWindow
0x45a4fc ScreenToClient
0x45a500 RemovePropA
0x45a504 RemoveMenu
0x45a508 ReleaseDC
0x45a50c ReleaseCapture
0x45a518 RegisterClassA
0x45a51c PtInRect
0x45a520 PostQuitMessage
0x45a524 PostMessageA
0x45a528 PeekMessageA
0x45a52c OffsetRect
0x45a530 OemToCharA
0x45a538 MessageBoxA
0x45a53c MapWindowPoints
0x45a540 MapVirtualKeyA
0x45a544 LoadStringA
0x45a548 LoadKeyboardLayoutA
0x45a54c LoadIconA
0x45a550 LoadCursorA
0x45a554 LoadBitmapA
0x45a558 KillTimer
0x45a55c IsZoomed
0x45a560 IsWindowVisible
0x45a564 IsWindowEnabled
0x45a568 IsWindow
0x45a56c IsRectEmpty
0x45a570 IsIconic
0x45a574 IsDialogMessageA
0x45a578 IsChild
0x45a57c InvalidateRect
0x45a580 IntersectRect
0x45a584 InsertMenuItemA
0x45a588 InsertMenuA
0x45a58c InflateRect
0x45a594 GetWindowTextA
0x45a598 GetWindowRect
0x45a59c GetWindowPlacement
0x45a5a0 GetWindowLongA
0x45a5a4 GetWindowDC
0x45a5a8 GetTopWindow
0x45a5ac GetSystemMetrics
0x45a5b0 GetSystemMenu
0x45a5b4 GetSysColor
0x45a5b8 GetSubMenu
0x45a5bc GetScrollRange
0x45a5c0 GetScrollPos
0x45a5c4 GetScrollInfo
0x45a5c8 GetPropA
0x45a5cc GetParent
0x45a5d0 GetWindow
0x45a5d4 GetMessageA
0x45a5d8 GetMenuStringA
0x45a5dc GetMenuState
0x45a5e0 GetMenuItemInfoA
0x45a5e4 GetMenuItemID
0x45a5e8 GetMenuItemCount
0x45a5ec GetMenu
0x45a5f0 GetLastActivePopup
0x45a5f4 GetKeyboardState
0x45a5fc GetKeyboardLayout
0x45a600 GetKeyState
0x45a604 GetKeyNameTextA
0x45a608 GetIconInfo
0x45a60c GetForegroundWindow
0x45a610 GetFocus
0x45a614 GetDesktopWindow
0x45a618 GetDCEx
0x45a61c GetDC
0x45a620 GetCursorPos
0x45a624 GetCursor
0x45a628 GetClipboardData
0x45a62c GetClientRect
0x45a630 GetClassNameA
0x45a634 GetClassInfoA
0x45a638 GetCapture
0x45a63c GetActiveWindow
0x45a640 FrameRect
0x45a644 FindWindowExA
0x45a648 FindWindowA
0x45a64c FillRect
0x45a650 EqualRect
0x45a654 EnumWindows
0x45a658 EnumThreadWindows
0x45a65c EndPaint
0x45a660 EnableWindow
0x45a664 EnableScrollBar
0x45a668 EnableMenuItem
0x45a66c DrawTextA
0x45a670 DrawMenuBar
0x45a674 DrawIconEx
0x45a678 DrawIcon
0x45a67c DrawFrameControl
0x45a680 DrawFocusRect
0x45a684 DrawEdge
0x45a688 DispatchMessageA
0x45a68c DestroyWindow
0x45a690 DestroyMenu
0x45a694 DestroyIcon
0x45a698 DestroyCursor
0x45a69c DeleteMenu
0x45a6a0 DefWindowProcA
0x45a6a4 DefMDIChildProcA
0x45a6a8 DefFrameProcA
0x45a6ac CreateWindowExA
0x45a6b0 CreatePopupMenu
0x45a6b4 CreateMenu
0x45a6b8 CreateIcon
0x45a6bc ClientToScreen
0x45a6c0 CheckMenuItem
0x45a6c4 CallWindowProcA
0x45a6c8 CallNextHookEx
0x45a6cc BeginPaint
0x45a6d0 CharLowerBuffA
0x45a6d4 CharLowerA
0x45a6d8 AdjustWindowRectEx
Library ole32.dll:
0x45a6e4 IsEqualGUID
Library comctl32.dll:
0x45a6f4 ImageList_Write
0x45a6f8 ImageList_Read
0x45a708 ImageList_DragMove
0x45a70c ImageList_DragLeave
0x45a710 ImageList_DragEnter
0x45a714 ImageList_EndDrag
0x45a718 ImageList_BeginDrag
0x45a71c ImageList_Remove
0x45a720 ImageList_DrawEx
0x45a724 ImageList_Draw
0x45a734 ImageList_Add
0x45a73c ImageList_Destroy
0x45a740 ImageList_Create
Library advapi32.dll:
0x45a74c SetServiceStatus
0x45a754 OpenServiceA
0x45a758 OpenSCManagerA
0x45a75c DeleteService
0x45a760 CreateServiceA
0x45a764 CloseServiceHandle
Library wsock32.dll:
0x45a76c WSACleanup
0x45a770 WSAStartup
0x45a774 WSAGetLastError
0x45a77c WSAAsyncSelect
0x45a780 gethostname
0x45a784 gethostbyname
0x45a788 socket
0x45a78c setsockopt
0x45a790 send
0x45a794 recv
0x45a798 inet_ntoa
0x45a79c inet_addr
0x45a7a0 htons
0x45a7a4 connect
0x45a7a8 closesocket
0x45a7ac accept

L!This program must be run under Win32
.idata
.rdata
.reloc
.aspack
.adata
Boolean
Integer
Cardinal
String
Variant@
TObject
TObject
System
IUnknown
System
TInterfacedObject%
;u3YZ]_^[
SVWUL$
]_^[SVWUL$
uZ]_^[
SVWUdE
YZ]_^[
_^[U3Uh.
d2d"h4E
]US=,E
d2d"=EE
u3ZYYd
#_^[SVWU
YZ]_^[SVW
SVW<$L$
]_^[USVW
d1d!=EE
2E3ZYYd
E_^[YY]
UQSVW30E
3Uhf$@
d1d!=EE
E3ZYYd
E_^[Y]
YZ]_^[
d2d"=EE
}3ZYYd
E_^[Y]
< v;"u
SV3Uh-)@
d0d Uf3UX
F3ZYYd
Ek<1fU
9uDJt
1^[^8u
SVWPts11
-ti+tf$tfxtaXt\0u
FxtOXtJt
Y12_^[F
FuP*Bt
QuM3Uh
EP&3ZYYd
f%fUf?f
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Iu9u_^[
]U3Uhb/@
33ZYYd
_^[YY]
_^[RQS|
PRQQTj
YZXtoH
S1VWUd
SPRQT$(j
9t7H;Ou
Ku]_^[
YZXtl1d
SPRQT$(H
R5[|$(g7
ZTUWVSPRTj
Zd$,1Yd
t=HtN`
r6t0R=
t/=t&,*&"
3Uh&8@
d2d";~
!Pn_^[]
Ku^[SV
tG?=DE
^Portions Copyright (c) 1983,99 Borland
U1Uh6@
QR6ZX1Yd
PVS5_^[]
XRHdZX
PQmZXSVW
ISVRP1L
fKuZXt
JZ^[X$
thtkFW)w
9uXJt
8uAJt
t,JIt&S
St-Xt&J|
t0JN|*9}&~")9~
tVSVWU
t@t1SVW
1Z)_^[
$:X<$t
$sZ]_^[
tKt:SVW
OWVJx f
VWf_^t
1Z)_^[SVW3
Mu]_^[
r*PRf8
u'PX%E
USVW}Q
_^[]UQS3EB
^[USEf
E3Uh!M@
d0d UE3ZYYd
]3UhM@
d0d UE3ZYYd
PRsZXt$JA~
XRJZXf
U3QQQQSV3UhP@
d0d f;
u-EEPEtUXKU=+EEPEUXUP3ZYYd
USVW}Q
3UhkQ@
d0d f;
X_^[89f
p,)p'p"
SV3UhqT@
d0d EEPEEZ3ZYYd
^[YY]USV3
d0d u]Ef8
fXE3ZYYd
USVWME]
3mEE;Et
u5];}}
MO|"GE
SVWEEEh|Z@
E8\u8Ex
E_^[]kernel32.dll
GetLongPathNameA
#ur3Uhl[@
;u;tmC}
^[]Software\Borland\Locales
Software\Borland\Delphi\Locales
t93Uhg]@
d0d ]ES
u_^[YY]
UQE3Uh]@
d2d"E@
t3ZYYd
3Rmt3QP
Ht Ht.I
@tg6|Hu]"F$d_@
H H$@Ht
QRPXZYx
@~!@PQ@
PRZX[B5pE
_^|HtE=
@aQYR@
b@"E@|oe@p+
BkU'9p|B0<RB~QC/j\
Cv)/&D
dEJzEb
9;5S]=];Z T7aZ%]g']
R`%uYnb
5{RPD$
USVW3\$
USVW\$
3USVW3\$
USVW\$
83ZYYd
U3Uhk@
d0d -(E
U3Uhem@
S] S]$SQRPj
UQSVWEh8x@
Magellan MSWHEEL
MouseZ
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
U3Uhx@
U3Uhx@
U3Uh{@
Exception|@
EAbort|@
EHeapException0}@
EOutOfMemory@
EInOutError}@
EExternal<~@
EExternalException~@
EIntError~@
EDivByZeroL
ERangeError
EIntOverflow@
EMathErrorX@
EInvalidOp@
EZeroDivide
EOverflow`@
EUnderflow@
EInvalidPointer
EInvalidCast@
EConvertError
EAccessViolation@
EPrivilege@
EStackOverflow@
EControlC8@
EVariantError@
EAssertionFailed@
EAbstractErrorP@
EIntfCastError@
EWin32Error
ESafecallException
TActiveThreadArray
$TMultiReadExclusiveWriteSynchronizerUj
SVW3Uh
d0d VWU
E/=_^[Y]
BFKu_^[
BFKu_^[
9t*^ar
_^[SVWU
| v;}
N|7 vU+A
P/Pq^[
PJ[SVWQj
$Z_^[SVWQj
$Z_^[Qj
u%EPPEPEPEPu
3URURURURP
EUE3RPEU,M
E3RPEU
1FW)^_
1t$Far
)t[^_
D$ D$$
3(_^[SV
9t%t^]E-u
*t"0r<9w7k
uPE*X_^[[]
Z_^[UQSVWM]
U3QQQQQQSVW3Uh@
d0d #E
JCDHyYU
JC8HVYU
JE*YU@C
u3ZYYd
SV3Uh9@
d0d EPO@
33ZYYd
Ejx^Y]
U3QQQQSVW3Uh@
dU:C*;~
kUAC1;
EEN_^[]
L$Dd4E
PD$HPj
d0d EPU
d0d EPU
_^[YY]
TErrorRec
TExceptRec
]]3Uhp@
D3ZYYd
t<HtHU
r3t7G=
SV3E3Uh'@
d0d E{%
C++ Exception
d0d U<E
TAt7D$
SVWU3PZ
+G]_^[
SVWU=E
y]_^[SVWU3
YZ]_^[
u^[SVW
_^[SVWU,qE
IuS3Uh
d0d %@=E
E3u?EP@
uuuhp@
m/d/yy
mmmm d, yyyy
:mm:ss
YM3Uh{@
w33ZYYd
US3E3Uh6@
x3ZYYd
kernel32.dll
GetDiskFreeSpaceExA
tN(;F,t;
u2yC,u
PC C$3C 3C,C4
d0d }3Uh@
E3ZYYd
INFNANU
+E[^_]
N[YCV5E
N^$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)U@WVSE
<'t$<"t
33EUU<#t&<0t%<.t,<,t3<'t5<"t1<Et:<et6<;tF
-<#t'<0t#<.t<,t<'t
<Et$<et <;tS
-u2AF>0t
KE;E~10}
00fJu2}
3m[^_]
< tN33
EEBN33
|3ZYYd
d0d -E
{3ZYYd
U3UhY@
U3Uh!@
SVWt;1
uKu_^[SVW1
6_^[SW:?
SVW3Uh@
d0d E|M
Ei{n_^[Y]
[[~[USV1
}3ZYYd
TAlignment
taLeftJustify
taRightJustify
taCenter
TBiDiMode
bdLeftToRight
bdRightToLeft
bdRightToLeftNoAlign
bdRightToLeftReadingOnlyx@
THelpContext
TShortCut
TNotifyEvent
Sender
TObject@
THelpEvent
Command
Integer
CallHelp
Boolean
Boolean`@
EStreamError@
EFCreateError
EFOpenErrorp@
EFilerError@
EReadError @
EWriteErrorx@
EClassNotFound@
EResNotFound@
EListError@
EBitsError@
EStringListError@
EComponentError@
EOutOfResources@
EInvalidOperationX@
TList@
TThreadList
TBitsh@
TPersistent@
TPersistenth@
Classes
TCollectionItemD@
TCollectionItem
Classes
TCollection
TCollection@
Classes
IStringsAdapter$
Classes
TStringsD@
TStrings@
Classes
TStringItem
TStringListh@
TStringList@
Classes
TStream<@
THandleStream@
TFileStream
TCustomMemoryStream@
TMemoryStream@
TResourceStream
TStreamAdapter@
TFiler\@
TReader@
TThread
TComponentName
IDesignerNotify$
Classes
TComponent@
TComponent@
Classes
TBasicActionLink@
TBasicAction@
TBasicActionl@
Classes
TIdentMapEntry
d0d ]E
W3ZYYd
Ey]W[]USVWE E
EUExOt
EW$3E3ZYYd
VE_^[YY]
MU3Uhi@
d2d"NEbEtI
8|NER^EUsu&EKu
uE3ZYYd
E[U_^[]
U3Uhj@
d0d E
d0d qME]E
@t3ZYYd
U3ZYYd
EZT^[]
Nuu]]USVW E
QDKu3ZYYd
TIntConstUt
USVWE3E(E
ES#FKu3ZYYd
RE_^[YY]
UQSVWUu
Nu3_^[Y]
USVWMu
E_^[YY]
FKu_^[
U3UhV@
d0d 3;5D@
zHEPXEPss
d0d Ef@ f#
d0d UEGYE}
>3ZYYd
VdO3ZYYd
GK^[SVW
kjNYZ^[
SV3Uh|@
d0d UvU
ESM^[Y]S
SVWU;tE|
,]_^[SVW
U1GUEE
d0d E@
CUEC3ZYYd
d0d Ex
EE3Uh@
d0d E@
SVWUQ;s
PRQB6YZXSVWQ
M3Uhj@
DG3ZYYd
ELF^[]
M3Uh%@
>NfDAt3f5AUf)A}
}O3ZYYd
E(L6F_^[]
=L3ZYYd
EJD_^[]
%s[%d]
UQSVWE
d0d Eq
GKu3ZYYd
EY_^[Y]
UQSEE@
fH[USV
MM3Uh@
Jf<tDf<Uf<}
J3ZYYd
GA_^[]
USVWUEEUR
2E3Uh@
HCOu3ZYYd
E<2r@EUR
?itdf:
u:tBF
d0d Eh
Elhf?_^[Y]
MUE3Uh@
EZ8W8CNu3ZYYd
=3ZYYd
EC=_^[]
Q<3ZYYd
USUEEPh8@
Strings
MMUE3Uh@
;u;N|0F3
A;E_^[]
SVW3Uh0@
d0d UcU
A+;_^[Y]
d0d E3Uh@
S$3ZYYd
Ee:3ZYYd
Y@C:_^[]
S3Uhy@
E4D'3ZYYd
E?9[Y]
MMUE3Uh_@
uN|)FE
uN|@FE
CENu3ZYYd
?8_^[]
MUE3Uh@
K|#C3M
FKu3ZYYd
Ep>~8_^[]
FKu]_^[UQSVWMM
S$_^[Y]
Q\3ZYYd
E07^Y]
E3UhF@
d0d Ed3Uh)@
+E38>U
Q,3ZYYd
E273ZYYd
7^[YY]
d0d ;tdE3Uh@
Eb3ZYYd
63ZYYd
EX<f6_^[YY]
MUE3Uh@
d0d E$
t3ZYYd
E:5En$
Qh3ZYYd
.(5^Y]
E:4^[Y]
Q,3ZYYd
E6:D4^[Y]
d0d E3Uh
u3ZYYd
E633ZYYd
Eu93[YY]
MUE3Uh^
d0d EV5
K|C3M
FKuE(5
E82_^[]SV-/
3F F$3F(F,
SVWUL$
$Z^[SVW
USVMUE]uE
]CN;};u~
UE|];]|^[]
d0d t-;]~
u3ZYYd
+E_^[]USh
E3ZYYd
EU$o+E[YY]
d0d U3ZYYd
ER"l)[Y]
k%^[S3
d0d U3ZYYd
E!([Y]
3]_^[USVWt
U3E3Uh
&3ZYYd
UQSVWM
PEPVX_{
!&USVWt
TPropFixup@
SVWU3w
d0d 3Etg[
u}3ZYYd
E)#E_^[YY]
@O[]US
d2d",E
d2d"3p
|3ZYYd
FKu3ZYYd
!3ZYYd
!3ZYYd
*h!_^[]
USVWUE=,E
Ku3ZYYd
. _^[YY]
UQSVWE=,E
Ku3ZYYd
4 _^[Y]S
CpB%^[]
EEPpsr
Epj$[]
$Z[SVW
C<S8|$
USVW,E
Ku3ZYYd
_^[]USVW3
d0d E@0
@E3E@0J
l3ZYYd
3C0_^[
d0d uLEXB
^[Y]UE
USVW3Uh
S,3ZYYd
USVW3Uh
USVW3Uh/
RB,3ZYYd
MMUE3Uh
d0d MUE
E@,EE@
E3UhA
d0d EE}
d0d EfH
E@,MUf
t"E@4Uw}
E@4U3ZYYd
EUP,EU
UB03Uh A
E3ZYYd
[Y]USVWE
E@,EE@(Ef1
UB,3Uhb!A
EUP,EUP(
t t6DT$
U3Uhm%A
MUE3Uh\'A
d0d 3Uh
d2d"UE
.uEpP+
UYEECqE
E3ZYYd
_^[YY]
@@0`_^[]
U3QQQQQQS3Uh)A
UE&LUE
]]]MUE3Uhx,A
d0d Ex
ET<$UE*
[]USVW
IuQSVWUE3Uh/A
d0d E1
3Uhd/A
d0d 3Uh%/A
d0d MUE
UB43Uh
d0d EP
u/E@4X
EKu3ZYYd
E@4:E3
-3ZYYd
E3UhB0A
d0d 3Uh
_^[YY]
Z^[SVQ3
S3Uh1A
d0d U}
u3ZYYd
[]UQUE
d0d E|
QYqUEdUY[EQU|YHUY?U
Y3ZYYd
S3Uha4A
d0d U4q3ZYYd
[Y]USV3
d0d t*MU
tK3ZYYd
]3Uh5A
i3ZYYd
SVWfxB
_^[SVQ
CdS`<$
<$| <$
UQSVWE
3E3UhO8A
C$S 3ZYYd
r53Uh8A
@3ZYYd
P9EE_^[Y]
TThreadWindow
PZ=hpsE
c43Uh9A
d0d =LE
43Uh0:A
d0d =LE
PH;3ZYYd
UQSVE3Uh:A
^[Y]UQSVWt
_^[Y]SV
US3C(E
P39j@jj
Pv3TD$
$$SVWt
pGNu_^[
SVWUL$
GKuYZ]_^[
UQSVW3EF t
SfK @[
EGu6;_
S _^[]
K|"C3G
EKu3Z]_^[
tot-cHu"4$D$
GMuZ]_^[
^[SVW4
;C0t:C@p
R0_^[]
@@SVWUG@p
CNu]_^[
k^[USVWU
3UhwGA
33ZYYd
33ZYYd
3UhWHA
33ZYYd
33ZYYd
d0d 3EE
EEE3UhpJA
EPSEPE
@3ZYYd
23ZYYd
v3ZYYd
33UhQKA
d0d t;C
3C 3C$C,
USVW(E
FKu3ZYYd
U3UhLA
Z!3ZYYd
TColor
EInvalidGraphicMA
EInvalidGraphicOperation@
TFontPitch
fpDefault
fpVariable
fpFixed@NA
TFontNamePNA
TFontCharset
TFontStyle
fsBold
fsItalic
fsUnderline
fsStrikeOut@
TFontStyles
TPenStyle
psSolid
psDash
psDashDot
psDashDotDot
psClear
psInsideFrame,OA
TPenMode
pmBlack
pmWhite
pmCopy
pmNotCopy
pmMergePenNot
pmMaskPenNot
pmMergeNotPen
pmMaskNotPen
pmMerge
pmNotMerge
pmMask
pmNotMask
pmNotXor@
TBrushStyle
bsSolid
bsClear
bsHorizontal
bsVertical
bsFDiagonal
bsBDiagonal
bsCross
bsDiagCrossPA
TGraphicsObjectPA
TGraphicsObjectPA
Graphics
IChangeNotifier$
Graphics
TFontQA
TFontpQA
Graphics
Charset$MA
Color<
Height<NA
Pitch<
SizeNA
Style@
TPenRA
Graphics
Color(OA
ModeNA
Style<
WidthSA
TBrush
TBrushSA
Graphics
ColorOA
Style@
TCanvasTA
TCanvasTA
Graphics
Brush<
CopyModeQA
PenxUA
TProgressEvent
Sender
TObject
TProgressStage
PercentDone
RedrawNow
Boolean
String8VA
TGraphic@
TGraphic8VA
Graphics
TPicture@
TPicture
Graphics
TSharedImage@
TMetafileImageXA
TMetafileXA
TMetafileXA
Graphics
TBitmapImage@
TBitmap8ZA
TBitmapYA
Graphics
TIconImage
TIconl[A
Graphics
TResourceManager@
P YE3Uh\]A
d2d"E@
t!Ef;p
E!E^[YY]UUE}
EEE3Uh]A
d1d!EH
]USVWM
EE;3Uh^A
E3ZYYd
E_^[YY]
EE3Uh^A
E3ZYYd
Ek_^[Y]
UQSVEE_3Uh__A
d2d"EX
u3ZYYd
USV3EE
-3ZYYd
R^[YY]
clBlack
clMaroon
clGreen
clOlive
clNavy
clPurple
clTeal
clGray
clSilver
clLime
clYellow
clBlue
clFuchsia
clAqua
clWhite
clScrollBar
clBackground
clActiveCaption
clInactiveCaption
clMenu
clWindow
clWindowFrame
clMenuText
clWindowText
clCaptionText
clActiveBorder
clInactiveBorder
clAppWorkSpace
clHighlight
clHighlightText
clBtnFace
clBtnShadow
clGrayText
clBtnText
clInactiveCaptionText
clBtnHighlight
cl3DDkShadow
cl3DLight
clInfoText
clInfoBk
clNone
ANSI_CHARSET
DEFAULT_CHARSET
SYMBOL_CHARSET
MAC_CHARSET
SHIFTJIS_CHARSET
HANGEUL_CHARSET
JOHAB_CHARSET
GB2312_CHARSET
CHINESEBIG5_CHARSET
GREEK_CHARSET
TURKISH_CHARSET
HEBREW_CHARSET
ARABIC_CHARSET
BALTIC_CHARSET
RUSSIAN_CHARSET
THAI_CHARSET
EASTEUROPE_CHARSET
OEM_CHARSET
E3UhgA
d0d ]}3UhgA
E33ZYYd
EE3Uh%hA
E6[Y]S;P
UUU3UhiA
d0d Ex
E3E3E3E
Default
PjHLPv
E3UhlA
d0d ]}3UhvlA
EO3ZYYd
E2UE[YY]
)3ZYYd
d0d Ex
txE3UhLoA
d0d ]3Uh/oA
{3ZYYd
E,3ZYYd
UEB~[YY]
i3ZYYd
E[Y]VWuE
d2d"Ex
R`E63EE@
UQSVWM
$YZ^[SV
w3UhuA
d0d {P
t3ZYYd
C8PHhE
VW<$L$
YZ^[SVQ
C4S0[Sfx*
C,S([S
d0d UE
E3AY]US33UhzA
)3ZYYd
L[USVW}
E3Uh*|A
d0d EPj
EPEPEbj
d0d EPEPEPE}
tdEPEP
EPEPh
EPEPEPj
VEP^3ZYYd
EP(EP1E_^[]
USVWMUu
PE3UhC}A
PE PE$PE(PE,PEPEPW
qE3Uh~A
d0d VSE$PPEEPEPEj
PE$PEj
EPE$P}
jEPEPE
PE PE$PVSj
PE(PE,PEPEPWihF
EPE(PE,PEPEPWDEPW
EPEPEP3ZYYd
EPEPEPYk
E_^[](
<$?O~&
YZ_^[U
UEEPUMIx3Efx
d0d jhEPE
SEP3ZYYd
'E3UhA
d2d"jhEPC
SDt)<$
EPEP}E3UhA
E3Uh@A
USVWE3
_^[YY]U
SVWMUE]
d2d"UME0V
E3ZYYd
cE}O~L
+;]|&U
d0d EP
EEE3UhA
EPEPVWEPEPE
}3ZYYd
EBx3ZYYd
UE"X_^[]
TjTP{u
C ;C$s
T_^[USV
WEPEEPpj
E3ZYYd
EPEPaEP0B
MUEU3E3E3E3E3Uh
d2d"EGEE<EE1EE&E
UE/UE$UE
D3ZYYd
_^[]SVt
USUEEP
RE3UhqA
+E3UhTA
E.z;uE"z
E3ZYYd
QP3ZYYd
QP^UQVh
{E3Uh_A
QT3ZYYd
TFileFormat
TFileFormatsList@
U3QQQQSVt
]_^[USVW3
]MU3Uh+A
7T3ZYYd
E"0_^[]
MU3UhA
Ku33ZYYd
TClipboardFormatsSVt
YRE3Uh
:R3ZYYd
_^[YY]
cY^[SVW
UQSVW3EtI
f3ZYYd
r_^[Y]
EU/UuE
Q03ZYYd
f33ZYYd
EN\_^[]
^[]USUEEPhA
tj3C t
P S @$C$
R$3tjVPPN
C 3TjdP2kD$TdPD$PPC
SVW3C tix
3TjdPBkD$PdPD$LPC
{kPWkY+
SVWXUd
j} EMFt
EKE^ 3UhHA
d0d UEd
dUdjEPEP{
UhSVWMUU
EaE^ 3Uh
d0d UME8W
F fUfP
3E3E3E
njPjdC
EPEP,{
SVW3UhFA
d0d _$U_EU
_$3ZYYd
_^[YY]
p ?TjdRD$LPkD$XdPVz
D$HPkD$TdPV
Mf(f+d~
|$( EMFt
C @ F C
d0d EPEPC @
e3ZYYd
PfEEfEj
d0d EPj
d0d EPj
cUMc3ZYYd
UE2h3ZYYd
PJE+EF
TBitmapCanvasPA
TBitmapCanvas$A
Graphics
d0d E@
|YEUE@EEt33UhA
d0d E0
EqM}u3ZYYd
UQSVE}
/D3UhA
Ku3ZYYd
^[Y]SVWt
^[UQSEEx
d2d"E@\t
P"E@`t
B3ZYYd
UQSVEExX
EV3UhA
d0d E@Xy
E@X@ @
E@X@ p
VSQUB\
P\E@X@ p
jVS0UB`S
sA3ZYYd
EEP]EVEPE3Uh
d0d PSj
EP3ZYYd
EPEPrEPIEPj
P^[]@(
u<fP&f
UhSVWMUE3EE
xPjTEP
nEEPE3UhA
PEPLE5
zzE3UhA
EPEPE}
@ 3+Pj
EPEPEPEP=E
EPEPE}
@ ;Eu>E
@ 3+Pj
EPEPE3Uh]A
d0d 3UhLA
d0d 3E3
EPEP^E
EP"3Uh*A
33-hPEPE
EPE3Uh
d0d EPEP'}
jSEPVEP3ZYYd
EPI[3ZYYd
jEPEPG13ZYYd
SV3tF3
EPjTSt
3E3E3UhA
MEEP}<Ej
EPEPJE}
jBEPEPj
SEP0Et*j
VEP%EPj
EPEPEPj
EPIVEP
EPEPw3ZYYd
E_^[]SVWt
yw %=sE
d0d t;F pE@ iF UB F
F,UB,F0UB0#E3
3E3E3UhSA
d0d ;5PE
EEPC$PM
8EEPC @pPj
&T|E(}
t"jPE@
t8EPE@
P'EPEPEPE@
3E3E3UhA
PEP5EG
PF PEPj
E@ PF PF
P3ZYYd
PdN|_^[]
F(^4F0A
A @ 3+
R HP3Y
SVWUo
jnEPjTS
^[USVW
pE3UhA
d0d EX
5rUBl3ZYYd
tEpwFxhlE
d2d"E@ UEB 3ZYYd
_^[YY]
UdSVWUE3E3E3E
hhEEE3Uh
d2d"3UhA
}(u-fC
UEeHC 3
`E3UhcA
3EgfE3UhA
EGEP<Ej
EPPEP}E3E
EPEPUE
C3ZYYd
jEPEPEPEP
s3ZYYd
EPEP'E
EPF3ZYYd
oss3ZYYd
H U3)E
thdPjTEP
@$E3ZYYd
s3ZYYd
dFrdPEPEPM
Df<$BMt
E3UhkA
d0d EPj
utfVWw
T]_^[SVW
s ;~ t8oVW
w F0fx
3fD$$fD$&fD$
^E3Uh7A
d0d EPFpPj
U3ZYYd
jnnC H
BMF hltT8@
D$*c}p
tOE0D$
fT$"fP
fT$$fD$&
fD$(T$
G>3Ep3
T$**>U,MD
^3E3EEPC$P~
d0d C @
P"yjj_^[]
G NF JG F
USVW^ {
]`E3Uh
EI3ZYYd
dE"`ggEC
_E3UhA
d0d 9P9Z+
cEl_f*g
_E3Uh0A
d0d Ep
_rffEAC =EC _^[Y]
SVWjHXE
lr oSVbN@A
TPatternManagerSVt
EE3UhmA
d0d E@
ETbE_^[YY]
E3Uh_A
R PEPE
E_3ZYYd
H_EZCbbE_^[]UE^EEEE
_ZE;SE@
p3ZYYd
TOrderedList@
TStack
^[SV}Z
UQSVWM
Ef3UhwA
d0d 33
tMu1=E
E#bE_fP
Ea[_^[Y]
GetMonitorInfoA
GetSystemMetrics
MonitorFromRect
EPVXSEP^[]
MonitorFromWindow
MonitorFromPoint
ugtc>(r^j
j0;tK3F
GetMonitorInfoA
DISPLAY
ugtc>(r^j
j0ctK3F
GetMonitorInfoW
DISPLAY
ugtc>(r^j
GetMonitorInfo
DISPLAY
EteEPV
twEPEPEP:EPEPEP
t6WEPEPku$}
WEPEPKu
PEPVhB
EnumDisplayMonitors
USER32.DLL
U3Uh1A
U3UhqA
U3Uh-A
!M3ZYYd
comctl32.dll
InitializeFlatSB
UninitializeFlatSB
FlatSB_GetScrollProp
FlatSB_SetScrollProp
FlatSB_EnableScrollBar
FlatSB_ShowScrollBar
FlatSB_GetScrollRange
FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_SetScrollRange
U3UhEA
TTextLayout
tlCenter
tlBottomA
TCustomLabel@
TCustomLabelA
StdCtrls
TLabelA
TLabel
StdCtrls%
Align@
Alignment7B
Anchors
AutoSize
BiDiModel7B
Caption$MA
Colord8B
Constraints
DragCursor(7B
DragKind6B
DragMode
Enabled@HB
FocusControlQA
ParentBiDiMode
ParentColor
ParentFont
ParentShowHintSC
PopupMenu
ShowAccelChar
ShowHint
Transparent`A
Layout
Visible
WordWrap@
OnClick ?B
OnContextPopup@
OnDblClick:B
OnDragDropD:B
OnDragOver@;B
OnEndDock@;B
OnEndDrag 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUp<B
OnStartDock
OnStartDrag
TEditCharCase
ecNormal
ecUpperCase
ecLowerCase@
TCustomEditA
TCustomEditA
StdCtrls
TabStop@A
TEdit A
TEdit@A
StdCtrls2
Anchors
AutoSelect
AutoSize
BiDiMode
BorderStyle
CharCase$MA
Colord8B
Constraints
DragCursor(7B
DragKind6B
DragMode
EnabledQA
HideSelectionCB
ImeMode(DB
ImeName<
MaxLength
OEMConvert
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
ParentShowHint(
PasswordCharSC
PopupMenu
ReadOnly
ShowHintT7B
TabOrder
TabStopl7B
Visible@
OnChange@
OnClick ?B
OnContextPopup@
OnDblClick:B
OnDragDropD:B
OnDragOver@;B
OnEndDock@;B
OnEndDrag@
OnEnter@
OnExit9B
OnKeyDown
OnKeyPress9B
OnKeyUp 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUp<B
OnStartDock
OnStartDragHA
TDrawItemEvent
Control
TWinControl
Integer
TOwnerDrawState@
TMeasureItemEvent
Control
TWinControl
Integer
Height
Integer@
TButtonActionLink
TButtonControl@
TButtonControl
StdCtrls
TButtonPA
TButtonXA
StdCtrls%
Action7B
Anchors
BiDiMode
Cancell7B
Captiond8B
Constraints
Default
DragCursor(7B
DragKind6B
DragMode
EnabledQA
ModalResult
ParentBiDiMode
ParentFont
ParentShowHintSC
PopupMenu
ShowHintT7B
TabOrder
TabStop
Visible@
OnClick ?B
OnContextPopup:B
OnDragDropD:B
OnDragOver@;B
OnEndDock@;B
OnEndDrag@
OnEnter@
OnExit9B
OnKeyDown
OnKeyPress9B
OnKeyUp 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUp<B
OnStartDock
OnStartDrag@
TListBoxStyle
lbStandard
lbOwnerDrawFixed
lbOwnerDrawVariable<
TCustomListBox@
TCustomListBox<
StdCtrls
TabStop
TListBox@
TListBox
StdCtrls4
Align7B
Anchors
BiDiMode
BorderStyle$MA
Color<
Columnsd8B
Constraints
DragCursor(7B
DragKind6B
DragMode
Enabled
ExtendedSelectQA
FontCB
ImeMode(DB
ImeName
IntegralHeight<
ItemHeight@@
MultiSelect
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
ParentShowHintSC
PopupMenu
ShowHint
SortedA
StyleT7B
TabOrder
TabStop<
TabWidth
Visible@
OnClick ?B
OnContextPopup@
OnDblClick:B
OnDragDropD:B
OnDragOverDA
OnDrawItem@;B
OnEndDock@;B
OnEndDrag@
OnEnter@
OnExit9B
OnKeyDown
OnKeyPress9B
OnKeyUpA
OnMeasureItem 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUp<B
OnStartDock
OnStartDrag@
TListBoxStrings
TListBoxStrings
StdCtrls
SVW3Uh
[VWEd1PE3P
WjPEfjjWh
[VWE"1PE2P
f%VWE0PE2P
iPe3ZYYd
EK.Y(_^[Y]
Q@T$ Df
f<E`vE
tdVWt$
RtSV:/
SVW3Uh
Ex*$_^[Y]
"[Y]SV
PjaYZ^[
@{E3Uh
d0d E{
MEy3ZYYd
E{= E_^[]
3&t`(g
@zE3Uh
d0d Ez
Ez_^[YY]SV
^[EDIT
#C@C@[
e[TSXFX0PPSMYD$8PSXWS9YSj
$D$8;~
R$tGE@(
PX]_^[
BUTTON
SVW3Uhn
M3UhB
d0d PWh
_^[]Uj
SVW3UhB
YZ]_^[
SVW3Uh!B
PhT}!UTE
_^[Y]SVW
]]E3Uh"B
d0d EJ3Uh"B
_^[]S@
]E3UhM$B
d0d EE@
3Uh0$B
d0d ;t_M
SVWWVh
_^[SVj
PMu"4$D$
Q@D$ PeLtLZ
(]_^[SVW
!G$_^[
LISTBOX
WVC4PC0Pj
^[SVWC
SVWUfG
YZ]_^[
[UpSVW}
PpPM3zVWp}
d0d f"
SGPAC3ZYYd
[SVWUz
^[U3Uh
U3UhQ1B
Delphi Picture
Delphi Component
THintActionX2B
THintAction
StdActns
U3Uh2B
TCursor
TAlign
alNone
alBottom
alLeft
alRight
alClient3B
TDragObject44B
TBaseDragControlObject4B
TDragControlObjectH5B
TDragDockObject5B
TControlCanvas
TControlCanvas5B
Controls
TControlActionLink6B
TDragMode
dmManual
dmAutomatic@
TDragKind
dkDrag
dkDockX7B
TTabOrder
TCaption7B
TAnchorKind
akLeft
akRight
akBottom7B
TAnchors
TConstraintSize
TSizeConstraints@
TSizeConstraints88B
Controls
MaxHeight7B
MaxWidth7B
MinHeight7B
MinWidth@
TMouseEvent
Sender
TObject
Button
TMouseButton
TShiftState
Integer
Integer@
TMouseMoveEvent
Sender
TObject
TShiftState
Integer
Integer9B
TKeyEvent
Sender
TObject
TShiftState
TKeyPressEvent
Sender
TObject
CharH:B
TDragOverEvent
Sender
TObject
Source
TObject
Integer
Integer
TDragState
Accept
Boolean:B
TDragDropEvent
Sender
TObject
Source
TObject
Integer
Integer
TStartDragEvent
Sender
TObject
DragObject
TDragObjectD;B
TEndDragEvent
Sender
TObject
Target
TObject
Integer
Integer;B
TDockDropEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer;B
TDockOverEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer
TDragState
Accept
Boolean\<B
TUnDockEvent
Sender
TObject
Client
TControl
NewTarget
TWinControl
Boolean<B
TStartDockEvent
Sender
TObject
DragObject
TDragDockObject<B
TGetSiteInfoEvent
Sender
TObject
DockClient
TControl
InfluenceRect
MousePos
TPoint
CanDock
Boolean@
TCanResizeEvent
Sender
TObject
NewWidth
Integer
NewHeight
Integer
Resize
Boolean=B
TConstrainedResizeEvent
Sender
TObject
MinWidth
Integer
MinHeight
Integer
MaxWidth
Integer
MaxHeight
Integer@
TMouseWheelEvent
Sender
TObject
TShiftState
WheelDelta
Integer
MousePos
TPoint
Handled
Boolean@
TMouseWheelUpDownEvent
Sender
TObject
TShiftState
MousePos
TPoint
Handled
Boolean$?B
TContextPopupEvent
Sender
TObject
MousePos
TPoint
Handled
Boolean?B
TControl@
TControl?B
Controls
Width<
Height
Cursor
TWinControlActionLinkCB
TImeMode
imDisable
imClose
imOpen
imDontCare
imSAlpha
imAlpha
imHira
imSKata
imKata
imChinese
imSHanguel
imHanguel@
TImeName<DB
TBorderWidth
IDockManager$
Controls
$5%&'/
,3489:<C(B
TWinControlDHB
TWinControlDB
Controls
HelpContextHB
TGraphicControl|IB
TGraphicControlHB
Controls
TCustomControlJB
TCustomControlIB
Controls
THintWindow$LB
THintWindow8KB
Controls
TDockZone
TDockTreedNB
TMouse
UQS]vE
VM&^[3^[
crDefault
crArrow
crCross
crIBeam
crSizeNESW
crSizeNS
crSizeNWSE
crSizeWE
crUpArrow
crHourGlass
crDrag
crNoDrop
crHSplit
crVSplit
crMultiDrag
crSQLWait
crAppStart
crHelp
crHandPoint
crSizeAll
crSize
TSiteListSVW
P#!u[]
_^[YY]
SVWQ3C
8=P &
J H J$H$J(H(J,H,
USVW3UhGUB
tPHt8wUC
k"EP`E
S_^[YY]
F8C8^[
S _^[]
^[Y]SV
PTSTPXSXPlSlVpD{D
^Vp\{\
PF8fe^[]
^[SVW<$
;B$t'E
PUPUEPhXB
EPEPEP
E_^[]UE
USVW}U3Ej
RLtzE{
t uuEP
3EE_^[]
MMM=tE
SVW3XE
;B8t=XE
SVW=tE
P8f\IXE
xXu$XE
3'u-|$
3F(F,t
YZ_^[USVWU5TE
3UhJdB
d2d"3E
uKUf5=TE
EUPDUPH(M33?yUM
EUPDUPH]SHEp8
yEUPLUPPEWpDx\
UE3ZYYd
[]USE33EE
3Uh+gB
d2d"XE
E3UhfB
d2d"XE
UUYt)=tE
tWC8:o
M3ZYYd
EPEPEP
]3ZYYd
YZ]_^[
E3UhhB
d0d E@
H|l@EE
t?3UhhB
D3ZYYd
EMu3ZYYd
XE3UhiB
d0d E@
|YEUEm~EE*
t33UhviB
d0d E
M}u3ZYYd
^[UQSEExX
_3Uh]jB
EP`E@X
QDUB\U
|3ZYYd
C\PC`P
SV;sXt
sX^[SV
t1JtPJtq
fc^[;N
fA^[;N
MM3UhmB
(U3ZYYd
E6E.<E_^[]
%s (%s)
S3UhmB
RPTXUt
@lC(oB
@$SV;s$t
Q`^[SVW
RtjWS#
S3CKvE
SVWfKD
6fcD{$
u$;~lu
F<PF8PN4V0
f_fTZ^[USVW
tr;^0u
;F<tX3
F4F|^$tIC
C8PC<PK4
C8PC<P
SVRC<PK4
C8PRK4
^[USVW}
UpEfHD
;tDt E
Ufq3ZYYd
_^[]SVW
M3UhxB
d0d {$
YZ_^[SVW
YZ_^[SV
f;u!}EEE
$PWF0Pf
$PWF4PLD$
$PWF8P
F<P+D$
$PWF4P
$PW^XP
SV:VLt
MU3Uh{B
d0d G@ t;G
_^[YY]SVW<$
Q@C8+D$
$PC<+D$
SV;s$t=;u
Z^[:PHt
SV3Uh}B
d0d UE_t
m3ZYYd
CX-;Ctt
uh|[S$4
3]USV3
d0d {$
C4PC0PV:C<PC8Pj
Vx3ZYYd
t8C@@t2U
tWE@$o_
E@$@@@u
PEPE@$-\
PGeVp$t
USEExG
d1d!UR4
K<QE@0
K8QRPEPgE@$MU>9
EPE@$"[
umC8C8|$
Q(@CDPC
STRSDRH
]_^[USfS[]
EPE3Uh=B
d0d F@PEPEhI
SEu++P}W
PEPvhI
PE+PEPThI
SE+E+PE+PVEP5hI
E+E+PSWVEP
EPEPF3ZYYd
USVWMt
V4F0JTE
EEE^$t
EEEPEP
UE2TVu
%E3Uh/B
PTEUPXEWxDu
,EPMUf
,E_^[]
t2+PD$
P33{RL$
Z_^[USf
C,S(E[]
Q_^[SVW
Ht*gFTt
USUEEPh0B
IsControl
t-t"y@0;
UQSVWMFA
UfN_^[Y]
@lSVWU3
foZ_^[
$^ffD^
f;u~CdP
C$P`CJ
C$PXCI
+B<PEPK
+EEU_^[]
ULY0E@
[YY]Uj
\F_^[YY]
^[SVft
SVW3UhB
S3ZYYd
UQSVE3
Iu^[Y]
t$,D$,\$
l$0D$0\$
|$4D$4\$$D$
P8RP<RH4P0
S|[SVWft
L$$33?T$$
SVW<$f
@\S ;P
U3UhVB
EUEH]K|0C3E
FKu3ZYYd
E)C^[]
t$t+:R4;P4
USVWUE}
EX0Ep4E@8EE@<EE@${>
Q@EEEE
MEx$W<G8k:E@Q
U+BxU+
U+Bx]+1E@Q
PEPE@xP/
U+B|U+
U+B|u+1E@Q
PEPE@|PEy
d0d EPEP
S|3ZYYd
t+t4GE
d0d EPEP
S|3ZYYd
xE@8;Eu
EU+P<E
SEU+P<E
EU+P<E
:_Kukt$
H|-@EE
@U@$YEMu_^[YY]
USMUEED
Q,UbYt~UE
YU3Y3ZYYd
d0d UE
3=USVWE
d0d E[EE,
E<U+W8+W0FKuEX
K|C3j
!FKu3ZYYd
USVWUEE}
EE3UhB
d2d"EH
0JE5=xK
FOu_^[]
(3C$^[SVW
M:]_^[3
$K|!C3
GKuZ]_^[
t\{4C$PV
P2u4C$PVj
"u$C$PVE
C$PVC4P{4C$%
zC<3C@
UCLH3ZYYd
_^[]U@SV3
@3UhsB
us{@tj^
LPEPEP
EPEPENB
EEEPfu
FT3FT/
f~3ZYYd
C PC4Pj
UQEEfHD
d0d EL
Z3ZYYd
Ef`DE3
FKu3_^[
Ps$t j
GNu_^[
USVWEExG
.3}FKuEL
:EtREUh
E3ZYYd
_^[YY]
UQSVWE3UhB
d0d 3Uh
d0d ]C,S(3ZYYd
__^[Y]
+C0@'E
Q@EPmtJC
USVMU3E}
KuE^[]
;X$uuj
;{u$~$
SVWUE][
P53UhB
d2d"E4
O|TG3E4
u+@@@t%P4
P8RP4R@0PSE}
P)y_^[]
K8S4C0 D$
K4S07C<PC8Pj
PUNfcD
K8S4JC0H}D$
C<@PD$
K8AS4C00D$
]_^[U
Q@EPWdEWj
ZEEPEP
E3UhzB
d0d EP
u_^[]SV
^[SVWQ8
SVWf@B
fx8fuMT
f{hft\
SVW3UhB
d0d $E
Evp_^[Y]Uj
S3UhVB
d0d $E
USVWfU
UQSVWM
fi_^[Y]
$Z_^[SVW
_^[YY]
SVW`~"K
OKu_^[
d0d :D
UfmgUH
USVWUEEx
d2d"E@
@8MUffE|
PXRUHTUP8EH
Eqc;uNE@GE3UhbB
Efe3ZYYd
E]^[YY]
Z[SVWQ
Z[SVWQ
YZ_^[SVWDE
SEPEPM
MUfaEx
x}E_^[]
USVWEE
RLtPCB
GNuE_^[YY]
tREfx
;X8t##
Q^[SVW
SVWfND
ef=r^[
@0lPafZ][SfN][SV
YZ]_^[SH$t
uU4$t/f Zt
Zu@v$u
YZ]_^[SVWF
USVW;s0u
Pz[s0{4E
2fV_^[]
SVWUL$
$fVGNuYZ]_^[
EE#3UhB
Ez[^[Y]
SVWUL$
P<RP8RP4
]_^[Vp$t
SVX$t-t
1N|dF3
ENu]_^[
SAPk^[SVV*Pt^[
C<PC8Pj
SV3UhB
d0d :|
UfXOUH
}3ZYYd
Ey}sT^[Y]
<_^[SVWUQl
$NuZ]_^[
USVWME3E
d0d UEfMEx
f[Mt }
;uu3ZYYd
E;KURE_^[]
USVUEE
FKu^[YY]
USVWFdx
S8_^[]
F8U+U+
EV<M+M+
d1d!3E3E3E3E3E3E3E3E
EPEPMU<CK,
E+E+C8+EE}
U+U+S<+UU}
AM_^[]
^[USVWMUEE
EE3Uh-B
d1d!EN|oFE
H8QH<QH4+
S|ENu3ZYYd
A8M+M+M
s7E+E~&M
A<M+M+M
USVWUEE%
d2d"EPEFP
EPE Pj
PEPEPEP[EPEPEPEPEPRu
PPEPau}
jEvPE"
PEPEPDEPEPEPEPEP
EPEPEPE0
PEPEP]3ZYYd
Q_^[]SVW
'3UhdB
3E3ZYYd
d0d E@<PEPEH833j
EPEHPD]
U3UhRB
PEPjUEfNP
V3UhWB
h3ZYYd
USVW}Q
EjPE@<PE@8PEPEPjEPE
Rt3ZYYd
USVW}Q
UQSVWM]
PSjEKP
~EPSIE+E
PEE3Uh
EPuEPj
zEPEPj
EPW3ZYYd
EPS@[]USVW
t&sp{hE
UQSVWM3
FlPNhVpnE
USVWM3
t9;wdt4;
UEPEPGdP
CdP3Cd[SVW
3YZ_^[
9^[SVfKD
ofcD^[
<|3UhbB
=3ZYYd
k}<[Y]
PF Z+C
USV3EF
tCEp83UhB
P89E^[]
USVWEE@
EU{Yt E@
;Odt"MI
MI ;Hh|"E@
t+E@ ;B } E@
ELZTMEP
/z_^[]USVWt
d0d E{K|C3j
FKuE@d:3ZYYd
J(H0J,H4E@
UP,@(4
V0P(V4P,Vd
@lHlxl
U@dYEYY]
3USVWM
}+}E+EEC
{EEPEP
Hud{dEG
SdB Cd@
SdB Cd@
Rt_^[]
UQSVWU
FhC Fd@ FhE
FH3F@FD
}Fd@ y
[mG C G
+C0FuuU
Q@EPnu
_^[]USVMUE3EE3
YE^[]UQSV
MUE3Uh
d0d EPdE
uN|UFE
ENuEPh
EXdVE;Eu
0E;E}(
E>+3ZYYd
E1+_^[]
@lP~h_^[]
@,i_^[]
E^ECh3Uh
Egk3Uh
)EE+C4
)EC8U+U+
)EC<U+U+
{3ZYYd
Ej(3ZYYd
Eh(3ZYYd
ES!m(_^[]USVW
~C0EC4EC8S<UU
Pf_^[]
3Fd?^[]
At$;C8u
U3QQQQSVW
d0d u;UE
NUXG.M
TNEPU0E
;u$Fdx
;Fdu5FhG Fd@ FhFd
S P hVh
)#_^[]SVW
&vuvWt$
USEE,3Uh
d0d E*EUE
E2(@"[YY]
d0d UE
RUB|YC
RUhY3ZYYd
Ev'!^[YY]USVW3
MUE3Uh
d0d EPp
d0d E@
K|-C3E@
EYFKu3ZYYd
UE@d34YwE
E0&> _^[]
@;Xdt'U
CXPC\P!_C`P
SPP C`P
XPCXPYhI
+QRPCXPSYVCXPY
RR ;S }'{
RY[]USU
B EUCd@
IYE[YY]USVW
t`US^UI^E;E
_^[]SVWtK
W4G0T$
BP_^[]
_\EUPPUPTUYE
MPEPYu
EPVMUE@
:\EEEEf{
uF4V0{
)EE+F4
)EF8U+U+
)EF<U+U+
)EU\_UC
]C4S03ZYYd
jh]W^[
gt!PN{
vOE3UhB!C
d0d =E
zNhX!C
USER32
WINNLSEnableIME
IMM32.DLL
ImmGetContext
ImmReleaseContext
ImmGetConversionStatus
ImmSetConversionStatus
ImmSetOpenStatus
ImmSetCompositionWindow
ImmSetCompositionFontA
ImmGetCompositionStringA
ImmIsIME
ImmNotifyIME
PGKfPE
JD$$D$(
KqPJfPE
D$,D$0
VJD$4D$8
qPJfRE
Delphi%.8X
ControlOfs%.8X%.8X
3ZYYd
TContainedAction@
TContainedAction%C
ActnList
Category&C
TCustomActionList
TCustomActionList&C
ActnList
TCustomAction
TCustomAction'C
ActnList
TActionLinkSV
|1SLz$W
^[SVC
SVW~Lt
SVW~Lt
^[Y]SVW$
USVUEE@$X
K|$C3E@$
FKu^[YY]
u*;~,u
3FL^[SVWf{2
C4S0C$p
R0GNuC
CNu3]_^[
R0]_^[
:]XtFE@x
R0]_^[SVWU
:]YtFE@x
R0]_^[SVWU;k\tFC@x
R0]_^[SVWU
R0]_^[
SVWU;kdtFC@x
R0]_^[SVWUf;khtGC@x
QXFOufkh
R0]_^[
:]jtFE@x
R0]_^[SVWF
U3Uh]3C
TChangeLink3C
TImageIndex
TCustomImageList@
TCustomImageList84C
ImgList
G@3G@GHt
S3Uha6C
C8C<
<E3Uh!7C
d0d EXDE@$PE@(PEPA9
R,339EP
Z<3ZYYd
x>:E@Ht
s0fx^[
SVW3Uh8C
d0d s,VV3C5
PC$PC(PH{0u!UE
eC8=t
_^[Y]USV
9{E3Uh9C
{E3Uhn9C
d0d EGM
EpPE@0P
E3ZYYd
E3ZYYd
EEf~E^[]
SV3UhK:C
d0d ;|!UpE
VPf3ZYYd
@PC0Pf
PC<PPj
P;PEPPe
Q4CH3~@
4C$PEPK(33
;PEPPDE
C$PEPM
HCH}:EG
EPC$PC(PE
EPC$PC(PE
PVN3_^[]
S0_^[]
USVWUEE@$PEPEH(33E?
3Uhp>C
vE3UhS>C
d0d EP$E
Q4EP(E
vE3Uh6>C
Q4EP(E
Q@EP(N|mF3
8PSEP&E{U5j
8PSEPMUECNu3ZYYd
%3ZYYd
F5C5F7C7V4
C$PC(PPS|P
F5C5F7C7V4
F6C6F<C<
C$PC(PP
SV3Uh|@C
d0d t9
R ;C$|
R,;C(}!UdE
]23ZYYd
E^[Y]SV:V4t
V4f}^[
33f[SVWUFL
8F@t"x
f3EOuf~Z
F\VX]_^[
FOu]_^[
E3UhxBC
E3Uh[BC
E3ZYYd
EE_^[]
USUEUEEPhTFC
Bitmap
pE3UhEC
|pE3UhEC
UpEEP(E
Q@EP$E
Q@EP$E
Q4E@$PEPEH(33E
R UJ$H
R,UJ(N
E@$PEPEH(EP$
rEPEtPEtUYx-E@$PEPEH(EP$
,EPEptPEgtUY2-MUEMCN
E3ZYYd
E3UhIFC
d0d Et
Xe3ZYYd
[Y]SVWD$
E3UhMGC
d0d Et
Wa3ZYYd
[Y]@PSxP
U3UhGC
EMenuError\HC
TMenuBreak
mbNone
mbBreak
mbBarBreakHC
TMenuChangeEvent
Sender
TObject
Source
TMenuItem
Rebuild
BooleanHC
TMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
Selected
Boolean<IC
TAdvancedMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
TOwnerDrawStateIC
TMenuMeasureItemEvent
Sender
TObject
ACanvas
TCanvas
Integer
Height
Integer@
TMenuItemAutoFlag
maAutomatic
maManual
maParentHJC
TMenuAutoFlag
TMenuActionLinklKC
TMenuItem
TMenuItemlKC
Action
AutoHotkeys
AutoLineReduction4ZA
BitmapXHC
Caption
Checked4C
SubMenuImages
Default
EnabledT
GroupIndext@
HelpContext
Hint3C
ImageIndex
RadioItem@
ShortCut
Visible@
OnClickHC
OnDrawItem8IC
OnAdvancedDrawItemIC
OnMeasureItem@
TMenuOC
TMenuhOC
Items@
TMainMenuPC
TMainMenu\PC
AutoHotkeysDJC
AutoLineReduction
AutoMerge
BiDiMode4C
Images
OwnerDraw
ParentBiDiModeHC
OnChangeQC
TPopupAlignment
paLeft
paRight
paCenter0RC
TTrackButton
tbRightButton
tbLeftButtonlRC
TMenuAnimations
maLeftToRight
maRightToLeft
maTopToBottom
maBottomToTop
maNone@
TMenuAnimation
TPopupMenuSC
TPopupMenu4SC
AlignmentDJC
AutoHotkeysDJC
AutoLineReduction
AutoPopup
BiDiModet@
HelpContext4C
ImagesRC
MenuAnimation
OwnerDraw
ParentBiDiMode,RC
TrackButtonHC
OnChange@
OnPopupUC
TPopupListDVC
TMenuItemStack$
1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ
UQUfE3}
Y]USfE
SVfE3Uh]YC
d0d ]3
00bUE3
AANAE3
oU1MEtYC
tLVE t
DP<Z;|90PP
F_^[USVW3
UEE3UhZC
d0d 33E
u3ZYYd
_^[YY]
:Bw$EU
E^[]USVWME3E3E33t
@3E;u~
@3EE:Ew
EEUEMUYE
@3:Ev}
CfCDC4
QFlPfFDft
]]M3UhbC
d0d {2
u$uhbC
UfCTduE
CDE3E3E3EEEg
EPjjWk
CDPVjW
EvEn|_^[]
RR(e3]
USEEXdt%
SV3UhcC
d0d UE
Eo}^[Y]
N|@F3;,$}
X3ENuZ]_^[S
ShortCutText
PEPEPE
SVW3UhypC
B3UhkC
_3ZYYd
+Q;}JE
+Q;}JE
@fXTftUE
@]3ZYYd
E_^[Y]
SVW3Uh#yC
@p;}7E
B3UhotC
+Q;}NE
+Q;}JE
@fXTft^E
M3ZYYd
E*8_^[Y]
t?EPMU
tBEPfE
UJY_^[]
]MU3Uh|C
&EF$|C
3f~Tft
PMUYE+E
Q8^[SVW
P3:S3u
GNu_^[SVW
:^,tB^,~Xt'F
:^-tg^-
Q87~Xt'F
FDP P3
:^3t1~Xt
Q8;P4t
CXt4m}
UQSVEE'K|
FKu^[Y]
:].tJt:}X
t4EXO|%G3
Q8]_^[
CPM|.CP;h
CPTg@3:F3v
CPBgP3N3
CPg^X^|Fx4C
Q8]_^[
CPe3GX3GxG|{(
F|Vx^[
F8y3F8O~8
R<FKu_^[
S:S1tS1{,
SVWJ;u
g_^[SVW
@Y8W8CNu
]]MU3Uh^C
E3E3Uh
d2d";H
tXUEYuJ
UUEYtL$E
E8W`FKuM
u?EPE}
EvUE3EY
b3ZYYd
sEGE?M
COu%K|$
$YZ]_^[
[UQSVWt
@8Fx^d
@(f&[]
[UQSVWE
SD;t+E
2N|$F3E
E_^[Y]
xHZ]_^[
F(:_^[
f;Bt,E
tz3UhmC
E_^[YY]
A3Uh>C
d0d UE3&YE3ZYYd
D$0D$$D$(P
USVEEPEE
E3`SE+Ph
;]r^[]
R4*Yx0
tcE@$EUR5U3UhC
O^[SfxB
USVfhC
SVfU3Uh-C
33ZYYd
P_EEH|w@E3h
uFMu}}
}yEH|q@E3h
_^[]UQSVW
Xtt3EE
PVW_^[Y]
@(P0:PLt
UQSVWU
U_^[Y]
@(R(M3
H(I\;J(u
0V8C,t
UQSVWE3Uh.C
E3Uh}C
K|tC3}
E8HMUyE}
IE3UhC
P<E3UhC
P|EEf@
PQE3UhC
d0d EP
d0d UE
UEH3ZYYd
%FHFLF(
@$F,FQ
SPf4P3CXf
UWVC(;PYZ]_^[
CNu]_^[
S0_^[]
<&uO$E
C;}]_^[
SV3UhC
d0d UEPUEZ3ZYYd
TScrollBarInc
TScrollBarStyle
ssRegular
ssFlat
ssHotTrackC
TControlScrollBar
TControlScrollBarC
ButtonSize$MA
ColorC
Incrementh
Margin
ParentColor<
Position<
Smooth<
Style<
ThumbSize
Tracking
Visible@
TWindowState
wsNormal
wsMinimized
wsMaximized8C
TScrollingWinControl8C
TScrollingWinControl8C
HorzScrollBar
VertScrollBarC
TFormBorderStyle
bsNone
bsSingle
bsSizeable
bsDialog
bsToolWindow
bsSizeToolWin
TBorderStyle
TScrollBox@
TScrollBoxC
Forms1
Align7B
Anchors
AutoScroll
AutoSize
BiDiMode
BorderStyled8B
Constraints
DockSite
DragCursor(7B
DragKind6B
DragMode
Enabled$MA
Ctl3DQA
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
ParentShowHintSC
PopupMenu
ShowHintT7B
TabOrder
TabStop
Visiblep=B
OnCanResize@
OnClick=B
OnConstrainedResize ?B
OnContextPopup@
OnDblClick;B
OnDockDrop;B
OnDockOver:B
OnDragDropD:B
OnDragOver@;B
OnEndDock@;B
OnEndDrag@
OnEnter@
OnExit<B
OnGetSiteInfo 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUpH>B
OnMouseWheel>B
OnMouseWheelDown>B
OnMouseWheelUp@
OnResize<B
OnStartDock
OnStartDragX<B
OnUnDockC
IDesigner
IOleForm$
TFormStyle
fsNormal
fsMDIChild
fsMDIForm
fsStayOnTop$C
TBorderIcon
biSystemMenu
biMinimize
biMaximize
biHelplC
TBorderIcons
TPosition
poDesigned
poDefault
poDefaultPosOnly
poDefaultSizeOnly
poScreenCenter
poDesktopCenter
poMainFormCenter
poOwnerFormCenter
TDefaultMonitor
dmDesktop
dmPrimary
dmMainForm
dmActiveFormlC
TPrintScale
poNone
poProportional
poPrintToFit@
TModalResult
TCloseEvent
Sender
TObject
Action
TCloseAction
TCloseQueryEvent
Sender
TObject
CanClose
Boolean@C
TShortCutEvent
TWMKey
Handled
BooleanC
TCustomForm4C
TCustomFormC
TFormC
TFormC
FormsO
Action@HB
ActiveControl(3B
Align7B
Anchors
AutoScroll
AutoSize
BiDiModehC
BorderIconsC
BorderStyle8DB
BorderWidthl7B
Caption<
ClientHeight<
ClientWidth$MA
Colord8B
Constraints
UseDockManager
DefaultMonitor
DockSite(7B
DragKind6B
DragMode
Enabled
ParentFontQA
FormStyle<
Height
HelpFile
HorzScrollBarh[A
KeyPreviewPC
OldCreateOrder
ObjectMenuItem
ParentBiDiMode<
PixelsPerInchSC
PopupMenuC
PositionhC
PrintScale
Scaled
ShowHint
VertScrollBar
Visible<
WidthC
WindowState
WindowMenu@
OnActivatep=B
OnCanResize@
OnClick
OnClose
OnCloseQuery=B
OnConstrainedResize ?B
OnContextPopup@
OnCreate@
OnDblClick@
OnDestroy@
OnDeactivate;B
OnDockDrop;B
OnDockOver:B
OnDragDropD:B
OnDragOver@;B
OnEndDock<B
OnGetSiteInfo@
OnHide@
OnHelp9B
OnKeyDown
OnKeyPress9B
OnKeyUp 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUpH>B
OnMouseWheel>B
OnMouseWheelDown>B
OnMouseWheelUp@
OnPaint@
OnResize<C
OnShortCut@
OnShow<B
OnStartDockX<B
OnUnDock8C
TCustomDockFormdC
TCustomDockForm8C
PixelsPerInchC
TDataModulePC
TDataModuleC
OldCreateOrder@
OnCreate@
OnDestroy,C
TMonitor@
TScreenC
TScreenC
THintInfo@
TApplicationC
TApplication\C
t=jVft
t %PjV
t6S_t,SMt"
d0d 3Uh0C
E3ZYYd
pee3ZYYd
dE_^[]SVt,
;X$t@S
Tt:GNu
TPUtilWindow
P5h8yE
PjSp[]
SV3Uh:C
d0d UEPEgEZ0
7f!`^[YY]
_3ZYYd
Ehev_^[]USVWt
USVEEX
to3E3EE@
?K|:C3Ex
+X_^[]USMUEjE@
USVWUEEx
EEH<EUEE
33E3E3
+RpEf@
tft-ft;JEP
t%ft6ftG
SV;S$t6u
SV;S0t6u
USVWMUEu
`KE3UhC
ERN|7F3
U+W8+W0CNu
N|F3j
J3ZYYd
EJQ_^[]
]3ZYYd
;}6n+;}
S ]_^[
SVWU;t}C
]_^[SVW
d0d E3ZYYd
E3UhYC
UE3ZYYd
'^[US3
UE3UhC
%$J3ZYYd
YI3ZYYd
iOwIE}
UCUEE@
UE$3ZYYd
UQSVWEEf
tA3Uh1C
d0d ]U
_^[Y]UQSVWEEf
tA3UhC
d0d ]U
LF_^[Y]
_^[SVWU
UQSVEE
d2d"E3
;B4t/ED
@4PEpXFxPp}
OB^[Y]
PixelsPerInch
TextHeight
IgnoreFontProperty
t22WVPz
WVkXuPmz
jP(~P0
~PV{C<+F
;uBKH|6@EE
UKf:9u
EMu_^[YY]
RTk6;t
SVWUL$
$4X)D$
KN|7F3
<3ZYYd
EhBv<Y]
C$;t%;t!u
S,_^[]
Ef@ f#
vE3UhC
d0d E@
vE3UhC
d0d EP
P|ErzEf@
E{EPE@
Pu93ZYYd
Eb2|9^
EP3xE3Uh
uE3UhC
d0d EPtE3UhC
d0d UEz
P|EdyC
U3~3ZYYd
EzEPEPt83ZYYd
E^1x83ZYYd
EPEPxQ8
Eu_^[]
K|!C3E
FKu3^[]
t.+t_E
Q@EPE@
$PjP'wtCO|-G3
C<FOuZ_^[
d2d"ExP
t1E@$u
Qd3ZYYd
u_^[S3
GFKu_^[
FKu3_^[
@LP+FKuE
$Z]_^[
la+Po;
Pn]_^[
d0d tp
H|a@E3
R4Pan;t
R4PzPtpm
t6Nt+j
EI5W/_^[]
PNPn^[
uwC8Pk<U
uwC8Pk<U
C8PC<PL$
F(Z_^[
MDICLIENT
EB EEPj
SVW3Uh
tptE;t ;u
u0fu!U|E
f3ZYYd
E*$_^[Y]
UQSVWU3
P`E@D
UfBD3Uh
@l;tTt*
;EuEp$t%
Yy3ZYYd
f#PDEfPD!
d0d E
d0d E8
[Y]SVWU
O|BGD$
f#CDfCD0T
VZTPZ@^[
ufPZuUj
SVW3Uh
!0P"Wt
US3t.E
USVWUF
YEWECU0
UFl%YM33bUMXEWE
B PB$PJ
UQSVE^
Ef@ f#
7Rf||fF
ME3Uhe'D
d0d E@
3UhH'D
d2d"E@
d0d Efv
@8TE+p<y7
3E@8PE@<P
t*^8E+X8y
^0F<U+B<y
3E@8PE@<P
@8RE+p<y7
3E@8PE@<P
EmPPQE
PEKPPE@8UR<
E'PhXr@
3UhO&D
d0d Ef
E?POo3
E-VL;u!E
EP0OSN
PHO3ZYYd
_^[YY]
<>E3UhR(D
d0d FXU
USVWE3Uh)D
_^[YY]31S
S3Uh*D
RLu!U|E
,3ZYYd
3UhX-D
d0d H<ExG
jGPhJ3JE
f@8fE3
E3Uh8-D
d2d"E;3Uh,D
3E3ZYYd
EPHE yE
i3ZYYd
E^[]UQSVWEEh
PYGNu_^[Y]
USVWC
t1F(xPH|$@30
@(nPx2
R<GNuU/Y_^[]
UQSVWEEh
t]E~N|NF3
GNu3_^[Y]
UQSUC
UQSVWEEh
t]E}N|NF3
GNu3_^[Y]
UQSUC
K|-C3E
FKu3^[]
USVUEE
EE^[]USVW}
]MU3Uh=3D
d0d bHupEIAE3
UOJMUV
!3ZYYd
SVWUyO|&G3
yYfwEOu
]_^[USVWu
_^[YY]
E3Uh5D
UEG3ZYYd
FGNu_^[US3
UE3UhP7D
\z3Uh07D
R03ZYYd
y+3ZYYd
R0USVt
UUEE@
x3Uhv8D
d0d ExH
UQSVWEEfx:
t;3Uh8D
d0d ]UC<S83ZYYd
)_^[Y]
UQSVWEEfxB
t;3Uh 9D
d0d ]UCDS@3ZYYd
C EEPh;D
Height
HorizontalOffset
VerticalOffset
H|6@EE
EMu_^[YY]
(UQSVt
^[Y]SVWU
EtoE|gEx_EHWEDOE@GE$?E(7Ep/ELt
C\;Cht
CX;Cdt
SVW_Pt3C
i4WT;t
R1_^[SVW
E3UhBD
d0d Ex(
UB(E,'Pj@}2H
3Uh?BD
T3ZYYd
8EX(3ZYYd
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
layout text
SVWUf;s8tsfs8fuZT/t$
1*;u.3Pj
3PWj W
2C<YZ]_^[
Pj<j2t
Cx%D$<T
j)P2t0$
t$t+:R4;P4
C0EC4Ej=E
t.t4GE
EVEPMU
+uE)EC8;u
S<;Ut~3
wt$UFD
DE+C<U
@)0'+E
USVWEE
@@K:Eu E
uaCK:EuYC
YEOu_^[YY]
UMUEUYtg
zE3UhHD
Y3ZYYd
ZEf3UhqID
E 3ZYYd
3WV`*t
TApplication
3CP3CtCL
P!PP%(\[t
MAINICON
vVhtRD
PW'F$P
3UhAPD
vC4EPHzE
V&fu!U
C4PjC$P&$E
PjC$P%j
C$PH$j
S="3ZYYd
X8;P<u
3sl;PPu
g^[USVW]
;B$uGjS#
P"4$jV"
YZ^[3Q
@@$PmU
S~EPE
@@$P[]
USVWUE3UhYD
d2d"E3
K|2C3E
E@$Pt
E@$PUY
E@$Ps
E@$PQ
E@$XyU
U/Y3ZYYd
S_^[YY]
vcltest3.dll
RegisterAutomation
s8F8PF4PF0PC8
t;s$t
SV3Uh\D
t%3PC$P
C|%3ZYYd
_^[SVW3s8t:
uV.G8t
]_^[SVWU3
u.~8t#
$Z]_^[
SVWQ3j
FOu_^[]
UQSVWM
3Uhj`D
8W,3ZYYd
4}~8_^[Y]
3UhVaD
d2d"<C
&E@8t_
t3ZYYd
^[A:P#:Z;^[
E@$P4E
EE;Et`E(
EPE@$P
3UhIcD
d1d!SWVE@$PQ
E3ZYYd
E;Et8j
d0d EV
>E6D^[]
tD9|t9$
t5^$F8t
PF@nPS
SV:Sxt3
P,stSL
Ct3Ct^[
;N|LF3
GNu_^[SVWT*
3n;s<tK{<
C<G&s<{<
C< &YZ_^[USVW3
MME3UhgD
d0d ER
3Uh`gD
d0d Ef
En3ZYYd
5K|C3j
3$FKu_^[
CD|tvCD4f
E3UhhD
d0d Efa3ZYYd
Ep^[Y]
UQSVWEEx$
GNuU3&Y_^[Y]
fGz_yf
_^[SfCzft
SVWUT$
;^Pu0T$
u|FHD$
FH^PD$
$ ]_^[S
stt-ut"Ct~rPh
d2d"MUEZ
E3UhlD
EE}EE)E3ZYYd
UEBx3ZYYd
RBt^[]UpSVW3
@PEEEEE
Q<3E3E
E+EPE+EPEP
@Ppt0tE3E
QhEPEP
EPEPEPd
@tf"t2
xPT|PXxU
xP\|P`
uK_^[]
Ht n8;t
YZ]_^[
U3UhYrD
Pu3ZYYd
U3UhrD
U3UhrD
U3UhQsD
U3UhsD
U3UhsD
TImage@
TImage tD
ExtCtrls
Align7B
Anchors
AutoSize
Centerd8B
Constraints
DragCursor(7B
DragKind6B
DragMode
Enabled
IncrementalDisplay
ParentShowHintTWA
PictureSC
PopupMenu
ShowHint
Stretch
Transparent
Visible@
OnClick ?B
OnContextPopup@
OnDblClick:B
OnDragDropD:B
OnDragOver@;B
OnEndDock@;B
OnEndDrag 9B
OnMouseDown9B
OnMouseMove 9B
OnMouseUptUA
OnProgress<B
OnStartDock
OnStartDragtyD
TTimeryD
TTimertyD
ExtCtrls
Enabled|
Interval@
OnTimerUQSVt
33za^[
USEE@
0E@8PE@<P33
3Uhm|D
d0d E
a3ZYYd
tB#dt7<
UQSVWM]
R,;C8|
R ;C<|
#C@C@t"<
#C@C@<
^[UQSVW
d0d Ef
PVE@(P
C(Ps$t@{8
C(Pu!U
C4S0[U3UhQD
uSj4D$
TMessageForm@
TMessageFormDD
Dialogs
Cancel
Ignore
NoToAll
YesToAll
]]]]fMUE3Uh
{E}URXE}Uj
EP333WE
PEPjUE
PEPE}@PE7PEb|mP[3E<lzE
CUEtRM
ZGj j MU
E"+E+G8EEPEPMU
-3ZYYd
Message
USVfMUu
fMUOE3UhD
d0d EU
E3ZYYd
D$$D$(
VD$,D$0
commdlg_help
commdlg_FindReplace
WndProcPtr%.8X%.8X
U3UhzD
u+f=TzE
D3ZYYd
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=
S3Uh3D
d0d EE
H3ZYYd
([Y]USVW3
MMMEE3UhD
13ZYYd
MMMMUEE
d0d EzEEE
EE=ABE
EE=E=E0EUXuEUJuEU<uEU.uE
53ZYYd
xELZ^[]
U3UhAD
ERegistryExceptionhD
TRegistryS
E2EPEPj
MU3ZYYd
E(6E^[]
SVWUQ3
USVW3EE
.3ZYYd
MaiStrUSVW3
Ej3UhD
_^[YY]
E?M[Y]
ECE;3Uh
d0d EUEU
U3ZYYd
E~3UhD
d0d EU)EU
US;EPE
kernel32.dll
CreateToolhelp32Snapshot
Heap32ListFirst
Heap32ListNext
Heap32First
Heap32Next
Toolhelp32ReadProcessMemory
Process32First
Process32Next
Process32FirstW
Process32NextW
Thread32First
Thread32Next
Module32First
Module32Next
Module32FirstW
Module32NextW
U3UhiD
TEventLogger4D
TDependencytD
TDependency4D
SvcMgr
IsGroup@
TDependencies\D
TDependencies$D
SvcMgr
TServiceThreadD
TServiceType
stWin32
stDevice
stFileSystem@
TErrorSeverity
esIgnore
esNormal
esSevere
esCriticalpD
TStartType
stBoot
stSystem
stAuto
stManual
stDisabledD
TServiceEvent
Sender
TServiceD
TContinueEvent
Sender
TService
Continued
Boolean
TPauseEvent
Sender
TService
Paused
BooleanPD
TStartEvent
Sender
TService
Started
Boolean@
TStopEvent
Sender
TService
Stopped
Boolean
TServiceD
TService
SvcMgr
AllowStop
AllowPauseXD
Dependencies
DisplayName$D
ErrorSeverity
Interactive
LoadGroup
Password
ServiceStartNameD
ServiceTypelD
StartType|
TagID<
WaitHintD
BeforeInstallD
AfterInstallD
BeforeUninstallD
AfterUninstall
OnContinueD
OnExecute
OnPauseD
OnShutdownLD
OnStartD
OnStop@
TServiceApplication
TServiceApplication\D
SvcMgr
Ek3UhID
^[Y]SV-
P3ZYYd
E/=^[YY]
UE3UhD
EP#3UhbD
d2d"E@0
d2d"E@0
33ZYYd
EUc_^[]
MUE3UhHD
d0d E@
E3Uh>D
X7EPUE
Ct^[SV
$3GTBN|-F3
$GTCBN|:F3
Z]_^[SV3
d0d {d
UCd3ZYYd
E6D^[Y]
SVWM3UhD
d0d K| C3EU
R<3ZYYd
u_^[]USVW3
UUUE3Uh
d0d 3UhD
E3UhuD
E3ZYYd
`E4B_^[]
d0d Ef
\U32rEU
F$VhDD
^[YY]SV!z
y^[USVW3
]MU3UhpD
COu3ZYYd
SVWU3K| C3
EFKu]_^[
MMMU3UhWD
d0d U3Kpf
Cx_CtUPWU
EAPVCl7PE.P
PEPgEE
d2d"3UhD
{{3ZYYd
EP&{3ZYYd
d0d EPDu
^[YY]USVW3
]MUE3Uh1D
UEyUy3ZYYd
\x3ZYYd
P~E$~E
~*x_^[]
UQSVWM
rt>3UhD
r_^[Y]j
%Sf r[
TServiceTableEntryArray
TServiceStartThreadUQSVt
{3ZYYd
UU3UhD
d0d xD
3EBN|"F3
EGNuuFVE
j3EN|JF3
23ZYYd
Els3ZYYd
rs_^[]
INSTALL
SILENT
UNINSTALL
53ZYYd
U3Uh]D
]M3UhD
Aw3UhpD
d0d yvBE
CMu3ZYYd
7nq3ZYYd
Evp_^[]
SVWEEz3UhkD
yv3UhFD
d0d Ex
PhEx;|3ZYYd
amp3ZYYd
vo_^[]
IuQSVWUEEy3Uh
d0d j7EPEP
EyEUE5
Ej7EPEP
EyEUjE5
Ej7EPEP
UEEWEPEPE&w
o3ZYYd
ltE@tNn_^[]
U3UhAD
U3UhyD
TNMRegD
TNMRegD
TOnHostResolved
Sender
TComponent0D
TOnStatus
Sender
TComponent
Status
StringdD
THandlerEvent
Handled
BooleanD
ESockError,D
EAbortErrorD
TThreadTimer@
TThreadTimerD
Enabled|
Interval@
OnTimerD
TPowersock@
TPowersockD
TimeOut<
ReportLevel@
OnDisconnect@
OnConnect`D
OnInvalidHost
OnHostResolved,D
OnStatus@
OnConnectionFailedD
AboutSVWt
Create
UE+nf}
Destroy
UE3UhD
[f3E3Uh'D
d0d E{
d3ZYYd
Eic_^[]
Connecting
Already connected
Host Lookup Timed Out
Host Lookup Canceled
Null Remote Address
Connection Timed out
Connection Canceled
Connection Failed
Disconnecting
Checking Connection
Not Connected
Canceling
]UE3UhD
|`3ZYYd
EQf_`^[]
Sending Buffer
Socket send aborted
E.j3UhD
63ZYYd
Ee_[Y]
d0d ,D
gU?3ZYYd
E6eD_[Y]
Writeln
MUE3UhxD
VED8$PE
|,@E3=
t-Mf3'E
uMBE$+
FE$++VEgGO;xr
UGD8PE
]3ZYYd
Eb\_^[]
ReadLn
Socket readln aborted
SVW3UhD
(TF|00rHt
TF|09w/Et
SFT2ecUE:dF
a3ZYYd
|af[_^[]
Transaction
MU3UhD
E-PE-Z+=
E_Y^[]
SendStream
Socket send aborted
Accepting
Accepting Canceled
Error creating Data Connection
Socket send aborted
SVWfU3Uh.D
`3ZYYd
C]-W_^[]
Looking Up Error Message
Unknown Error No.
Timer Triggered
Timer On
Timer Off
IuSVW3Uh&D
d0d <D
UnuhpD
Q43UhD
P\3ZYYd
YS'T3ZYYd
WSS3ZYYd
KY5S_^[]
Initializing Winsock
Version=
High Version=
Description=
System=
Max Sockets=
Max Udp pack size=
Initializaton of windows sockets failed
USVW3UhlD
d0d fz
d0d f2
;NQ_^[]
SV3UhHD
d0d \D
Request Close Socket
]M3Uh0D
NOEUU3ZYYd
U+O_^[YY]
UQSVWM
E*Y3UhD
d0d 3UhD
d0d 3;
KDO3ZYYd
EsTN_^[Y]
Data Available
Clearing Input
PC$Phf
Resolve Host
Host Lookup Timed Out
Host Lookup Canceled
Host Lookup Failed
u?3UhD
d0d EfE3ZYYd
C(P1s$t5{8
No Timer
C4S0[USVW3
]]UEES3UhBD
R@EEOEK;Xr
F-H;u&EUK;Zr
PUEQC;t
UO3ZYYd
UUiE_^[]
PsockWindowClass
UE_^[]
TmrWindowClass
UUMethods
uuMime
uuCode,D
TNMUUProcessorpD
TNMUUProcessor,D
Method@
OnBeginEncode@
OnEndEncode@
OnBeginDecode@
OnEndDecodeSVt
IuSVWE3UhJD
]UC,S(3Uh D
d0d EiJ
HRKUE'L\5
HKUEK\5
HJUEK\5
HJUEWK;uF\5
HSJUE(KE
JUEJ\5
HIUEJE
JEtJPE;L
EURH:IUElD
NJEIPEK
]UC4S0;A3ZYYd
TExStringListD
TExStringListD
NMExtstr
MMUE3UhD
d0d Ex
HE]+]y
HEE@;Eu
H|O@E3
Jt#EPI
CMu3ZYYd
DEUDc>^[]
]M3UhD
QD3ZYYd
EC=_^[YY]
U3Uh%D
TS_BufferStreamUQSVWt
_^[Y]SVy8
RP3;T$
$Z_^[SVWUQ
RP3;T$
$Z]_^[
RP3;T$
$Z]_^[SVWU
YZ]_^[
Invalid seek origin = %d
Seek error
PutBack overflow
C$S [Sfx*
C,S([U3UhD
TSubType
mtPlain
mtEnriched
mtSgml
mtTabSeperated
mtHtmlXD
THeaderInComplete
handled
Boolean
hiType
IntegerD
TRecipientNotFound
Recipient
StringD
TMailListReturn
MailAddress
StringD
TFileItem
Filename
StringXD
TPostMessageD
TPostMessageXD
NMsmtp
FromAddress
FromNamed@
ToAddressd@
ToCarbonCopyd@
ToBlindCarbonCopyd@
Bodyd@
Attachments
Subject
LocalProgram
ReplyTo
TNMSMTP
TNMSMTP
NMsmtp
OnPacketSent`D
OnConnectionRequired@
OnConnect
UserIDD
PostMessageD
FinalHeaderD
EncodeType
ClearParams
SubType
CharsetD
OnRecipientNotFoundTD
OnHeaderIncomplete@
OnSendStart@
OnSuccess@
OnFailureD
OnEncodeStartD
OnEncodeEndD
OnMailListReturnD
OnAttachmentNotFound`D
OnAuthenticationFailedUSVWt
E[3UhO
E_^[YY]
us-ascii
UUE3Uh
d0d EX3Uhi
d0d UEUE`
j7UME0V<UE
P.CEfx
R89..3ZYYd
-3ZYYd
Em3Ee3s-_^[]
Authentication failed
-3ZYYd
E,3ZYYd
E2,[YY]
IuSVWE3Uh/
2UME8W<Efx
ME8W<Efx
ME8W<Efx
V&3ZYYd
,,&_^[]
Incomplete Header
MAIL FROM:<
RCPT TO:<
IuSVW3Uh
t3tUtw
B*E8.u
**E)PE+
B*Ez)PEA+
Eq)E8.u
])E(PE\*
3ZYYd
%E%_^[]
From:
Subject
X-Mailer
Reply-To
Mime-Version: 1.0
Content-Type: text/enriched; charset=
Content-Type: text/sgml; charset=
Content-Type: text/tab-separated-values; charset=
Content-Type: text/html; charset=
Content-Type: text/plain; charset=
====================54535
Content-Type: multipart/mixed; boundary="
IuQSVWUE3Uh
d0d h
%E$PE&
d2d"E3ZYYd
UL3ZYYd
p ED R
Content-Type: application/octet-stream; name="
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="
-t3ZYYd
4$~%SEP
Txthaoma
TxtMima
Timer1
Button1
ListBox1
Timer3
NMSMTP1
Timer1Timer
FormCreate
Button1Click
TxthaomaChange
TxtMimaChange
Timer3Timer
NMSMTP1Connect
NMSMTP1SendStart
FormClose
TForm1
TForm1
d0d U!E
UEkUE`
36_3ZYYd
auto_share
Q43ZYYd
S3Uh#E
Q43ZYYd
S3Uh#E
IuQSVW3Uh
d0d U,%E
S<3ZYYd
yonghu_ming
youxiang_mima
AUTH LOGIN
X-Mailer: Foxmail 4.2 [cn]
X-Mailer
Multipart/Alternative; boundary="----=_NextPart_000_000A_01BF9F1A"
Content-Type
U3Uh}&E
Timer1
Button1
Timer1Timer
FormCreate
Button1Click
TForm2
TForm2&E
U3Uh(E
StopFireWall_ThreadU3QQQQQS3Uh
d0d EP *E
qp7002
QPWorkFile
U3QQQQQQQSVW3Uh+E
EU\U+E
PJ-U+E
PIEKuE
ravmon
SVWU=E
U3Uhe,E
U3Uh,E
ZhongYou_ThreadUj
SV3Uh-E
EUZU-E
VG3ZYYd
PassWord_ThreadU3QQQQQQQSVW3Uh0E
WSxDE2
SC~=Vh
L3ZYYd
#32770
Button
ComboBox
U3QQQQQQQQSVW3Uh
kJ83ZYYd
#32770
U3Uh3E
SV3Uh4E
d0d h$5E
]9P3ZYYd
Kernel32.dll
RegisterServiceProcess
IuSVW3Uh06E
d0d 3Uh5E
d0d ?9E3Em5@6E
9E3Em5@6E
UX+~3ZYYd
E+_^[]
zDUSV3
d0d UEVE
VVSWgPIgSCg3ZYYd
USVWUEE}
\3Uhm7E
\MU`^)\3ZYYd
:3ZYYd
_^[YY]1
Software\Microsoft\Windows\CurrentVersion\win7002
UQSVWEE
3Uhq8E
[3UhQ8E
U]E[3ZYYd
V3ZYYd
Software\Microsoft\Windows\CurrentVersion\win7002
USVWMUE
3Uho9E
Z3UhB9E
U\TZ3ZYYd
e3ZYYd
_^[YY]
USVWMUE
3Uh#:E
Y3Uh9E
U[Y3ZYYd
8_^[YY]
qqpass7002
Default IME7002
TForm2
SVWE3Uh';E
d0d 3Uh:E
uUhuh@;E
FKu3ZYYd
O3ZYYd
UE3Uh+<E
d0d 3Uh;E
EjeEPjEPYu
C<uE3ZYYd
EU3ZYYd
*E"0_^[]
SVW3Uh<E
_^[YY]Uj
SVW3UhK=E
_^[YY]
U3QQQQQQSVWE3Uh_>E
t"uhx>E
EU\3ZYYd
UUE3Uh@E
NEE.NH@E
@3Uh?E
EUmEU.E3ZYYd
EE_^[]
IuSVW3UhECE
J$EUKU
UEdWEPpCE
+3ZYYd
Msread.dt
mima_wenjian
fasong_youxiang
yonghu_ming
youxiang_mima
fasong_zhuti
fanggai_mima
smtp_fuwuqi
auto_share
]MUEE9E1E)E
3UhlFE
R43ZYYd
3Uh*FE
R83ZYYd
------=_NextPart_000_000A_01BF9F1A
Content-Type: text/plain;
Content-Transfer-Encoding: 8bit
------=_NextPart_000_000A_01BF9F1A--
IuS3Uh:IE
UEEUEqUhIE
EPEPMUE
Q,3ZYYd
mima_wenjian
fasong_youxiang
yonghu_ming
youxiang_mima
fasong_zhuti
fanggai_mima
smtp_fuwuqi
IuSVW3Uh5ME
Stf3CSE
UtLxME
kav9x.exe
kavsvc9x.exe
kavsvcui.exe
kav32.exe
smenu.exe
ravmon.exe
passwordguard.exe
vpc32.exe
watcher.exe
U3QQQQQQQSVW3UhHQE
&EEU4;}
EU8U`QE
t!EMPj
t!ESPj
Ut!E!Pj
#t6EPj
kingsoft
ravmon
U3QQQQQSVW3UhSE
d0d EUESE
uT3UhRE
d2d"hSE
3UhASE
d2d"hSE
f3UhkSE
d0d E3ZYYd
<3ZYYd
Ms7002.dll
Regsvr32.exe
largeicon
IuQS3UhVE
UE>:UVE
K3ZYYd
workfile
txtfile\shell\open\command
chm.file\shell\open\command
scrfile\shell\open\command
regfile\shell\open\command
inifile\shell\open\command
qp7002
QPWorkFile
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IuSVWEEg3Uh
EP.Ue@EU/E([E
uu%EM4[E
Au%EMX[E
u%Et[E
mu,h[E
U-EPUE
EU2EU-UXu
>3UhZE
iUE~2EU7-EPUE
EUU2EU
aK_^[]
Notepad.exe
HH.exe
regedit.exe "
workfile
3UhC\E
qqpass7002
U3Uh\E
CloseWindow_ThreadSVWU
U3Uh]E
MaiFileSystemUSVWMUE
3Uh)_E
UU3ZYYd
H2_^[YY]
c:\filedebug
MEE3Uh`E
t,uh`E
sO.tD=`E
u3ZYYd
SV3UhnaE
CWu3ZYYd
U,SVWUEEE3UhbE
d0d U,tE*ud3Uh*bE
,3ZYYd
n3ZYYd
}Z3UhbE
d0d ,z
p,e`3ZYYd
!x3ZYYd
U,SVW3
EE,3UhcE
d0d En)tvU63UhfcE
A3ZYYd
IuQSVW3UhseE
'EMEeE
H|W@EE
U3UheE
MMUEEuEm3UhWgE
d0d hhgE
UEp!UEUEZ!UE
UEEE3E}E
E3Eh|gE
t63Uh%gE
d0d EPEPh
netapi32.dll
NetShareAdd
UEEE3UhhE
E3UhhE
d0d j,EPj2j
:3ZYYd
{e_^[]svrapi.dll
NetShareAdd
U3UhQiE
U3UhiE
d0d 3ZYYd
Runtime error at 00000000
0123456789ABCDEF
F
MS Sans Serif
Interrupted system call
Bad file number
Permission denied
Bad address
Invalid argument
Too many open files
Operation would block
Operation now in progress
Operation already in progress
Socket operation on non-socket
Destination address required
Message too long
Wrong protocol type for socket
Bad protocol option
Protocol not supported
Socket type not supported
!Operation not supported on socket
Protocol family not supported
/Address family not supported by protocol family
Address already in use
Can't assign requested address
Network is down
Network is unreachable
#Network dropped connection or reset
Software caused connection abort
Connection reset by peer
No buffer space available
Socket is already connected
Socket is not connected
Can't send after socket shutdown
!Too many references, can't splice
Connection timed out
Connection refused
!Too many levels of symbolic links
File name too long
Host is down
No route to Host
Directory not empty
Too many processes
Too many users
Disc quota exceeded
Stale NFS file handle
!Too many levels of remote in path
Network subsystem is unavailable
#Incompatible version of WINSOCK.DLL
'Successful WSAStartup not yet performed
Host not found
Non-Authoritative Host not found
/Non-Recoverable error: FORMERR, REFUSED, NOTIMP
,Valid name, no data record of requested type
Unrecognized error code
`!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
kernel32.dll
GetCurrentThreadId
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
lstrcpyA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
GetModuleFileNameA
advapi32.dll
ReportEventA
RegisterEventSourceA
RegSetValueExA
RegQueryValueExA
RegOpenKeyExA
RegFlushKey
RegCreateKeyExA
RegCloseKey
DeregisterEventSource
kernel32.dll
lstrcpyA
WriteFile
WinExec
WaitForSingleObject
VirtualQuery
VirtualAlloc
TerminateProcess
SuspendThread
SizeofResource
SetThreadLocale
SetFilePointer
SetEvent
SetErrorMode
SetEndOfFile
ResumeThread
ReadFile
OpenProcess
OpenMutexA
MulDiv
LockResource
LoadResource
LoadLibraryA
LeaveCriticalSection
InitializeCriticalSection
GlobalUnlock
GlobalReAlloc
GlobalHandle
GlobalLock
GlobalFree
GlobalDeleteAtom
GlobalAlloc
GlobalAddAtomA
GetVersionExA
GetVersion
GetTickCount
GetThreadLocale
GetSystemInfo
GetSystemDirectoryA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetExitCodeThread
GetDriveTypeA
GetDiskFreeSpaceA
GetCurrentThreadId
GetCurrentProcessId
GetCPInfo
FreeResource
FreeLibrary
FormatMessageA
FindResourceA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
EnumCalendarInfoA
EnterCriticalSection
DeleteCriticalSection
CreateThread
CreateMutexA
CreateFileA
CreateEventA
CompareStringA
CloseHandle
gdi32.dll
UnrealizeObject
StretchBlt
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RestoreDC
Rectangle
RectVisible
RealizePalette
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPointA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExcludeClipRect
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
user32.dll
WindowFromPoint
WinHelpA
WaitMessage
UpdateWindow
UnregisterClassA
UnhookWindowsHookEx
TranslateMessage
TranslateMDISysAccel
TrackPopupMenu
SystemParametersInfoA
ShowWindow
ShowScrollBar
ShowOwnedPopups
ShowCursor
SetWindowsHookExA
SetWindowTextA
SetWindowPos
SetWindowPlacement
SetWindowLongA
SetTimer
SetScrollRange
SetScrollPos
SetScrollInfo
SetRect
SetPropA
SetMenuItemInfoA
SetMenu
SetForegroundWindow
SetFocus
SetCursor
SetClassLongA
SetCapture
SetActiveWindow
SendMessageA
ScrollWindow
ScreenToClient
RemovePropA
RemoveMenu
ReleaseDC
ReleaseCapture
RegisterWindowMessageA
RegisterClipboardFormatA
RegisterClassA
PtInRect
PostQuitMessage
PostMessageA
PeekMessageA
OffsetRect
OemToCharA
MsgWaitForMultipleObjects
MessageBoxA
MapWindowPoints
MapVirtualKeyA
LoadStringA
LoadKeyboardLayoutA
LoadIconA
LoadCursorA
LoadBitmapA
KillTimer
IsZoomed
IsWindowVisible
IsWindowEnabled
IsWindow
IsRectEmpty
IsIconic
IsDialogMessageA
IsChild
InvalidateRect
IntersectRect
InsertMenuItemA
InsertMenuA
InflateRect
GetWindowThreadProcessId
GetWindowTextA
GetWindowRect
GetWindowPlacement
GetWindowLongA
GetWindowDC
GetTopWindow
GetSystemMetrics
GetSystemMenu
GetSysColor
GetSubMenu
GetScrollRange
GetScrollPos
GetScrollInfo
GetPropA
GetParent
GetWindow
GetMessageA
GetMenuStringA
GetMenuState
GetMenuItemInfoA
GetMenuItemID
GetMenuItemCount
GetMenu
GetLastActivePopup
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
GetIconInfo
GetForegroundWindow
GetFocus
GetDesktopWindow
GetDCEx
GetCursorPos
GetCursor
GetClipboardData
GetClientRect
GetClassNameA
GetClassInfoA
GetCapture
GetActiveWindow
FrameRect
FindWindowExA
FindWindowA
FillRect
EqualRect
EnumWindows
EnumThreadWindows
EndPaint
EnableWindow
EnableScrollBar
EnableMenuItem
DrawTextA
DrawMenuBar
DrawIconEx
DrawIcon
DrawFrameControl
DrawFocusRect
DrawEdge
DispatchMessageA
DestroyWindow
DestroyMenu
DestroyIcon
DestroyCursor
DeleteMenu
DefWindowProcA
DefMDIChildProcA
DefFrameProcA
CreateWindowExA
CreatePopupMenu
CreateMenu
CreateIcon
ClientToScreen
CheckMenuItem
CallWindowProcA
CallNextHookEx
BeginPaint
CharLowerBuffA
CharLowerA
AdjustWindowRectEx
ActivateKeyboardLayout
ole32.dll
IsEqualGUID
comctl32.dll
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
advapi32.dll
StartServiceCtrlDispatcherA
SetServiceStatus
RegisterServiceCtrlHandlerA
OpenServiceA
OpenSCManagerA
DeleteService
CreateServiceA
CloseServiceHandle
wsock32.dll
WSACleanup
WSAStartup
WSAGetLastError
WSAAsyncGetHostByName
WSAAsyncSelect
gethostname
gethostbyname
socket
setsockopt
inet_ntoa
inet_addr
connect
closesocket
accept
L!This program must be run under Win32
.idata
.edata
.reloc
.aspack
.adata
!!$>i"T0
f2[7+-yXME>V
nVUp6~
@AwC\\x?y?w?j]
6I "^B
CW+_BF-e8ZByr0iI
~(I@Yj`
\1UI;Q
zC)Ex+h9]
%&PKz@A
e3=bE3Yl
Bn.\HpF
SB~?{v5u
F8Z@:_@)
Q3--"BZq)`
I~:V[1
H/&WG^=JX!2JO2
o($P{N
SC2(W)%/&v
2&_5QN
y::~bBpQ>
*G {H1,
.r1B.0'y-o
XzR^>A
[~.!v[Oe
RGzmxM,
:I;BA.09o,7,U
HX2IJ\
|sI7'jJG
9 =dvZ
JzG[`:Dk
W;0R82
0RVzmv
z6P[a7LB
-1h#TR
{\kBY/\b.
Srg4L}Sp*
qP`4(]
yb@Q>+~
%|~K/vcOg5
B:$H9,R7
j|+~^W
y9\9(uaH8;X
qnI$$j`
jBU }8pWj
kIW~
&ytcK}
G%.LL_mr
9!MT2T
gAlgZ(Z
LR m`7v&Vy
{#I<s)nwr
\|KtKLY
RrRW(Z
>\KCq
j+0ci";`U"
)$C>7Vb
d3IzyPNl
i5'Rf3RJ
Q%M[H+
E&g-_[
FbcBU=;Z^M
OZingh3
zD*pTp|
}sW#1yp
E,sM2bTbFy
jf ;Jx-)
G5yCO?R,S
!ezuN8%
Q*OElK:
D`U"N]
P}<iMaSC
6xrB,'
Y:WHTk
5}zLW4-,
W99.^&9c laQm$k]
EhY\u+u
p=t.EC
:FI)rs"ryt
x:2.mTcmrT^`*f
@u7qQn<
-oah>I
u':uP,W/SgGjjm
>q>3^
5]V-\<8
W|$L{J/
vi't@jd)9PgjJ
'[FtL!'&e0*
);P4~NZ:6ws&R
auSM/l
"fUN5x\
XLA65D!-}(ew
$S%Kt21\
:Ht9IM
q__qJldo{iNT2Ml(uB
BF4P*T
iYghGbAlPLU+"[cu
erm/Lq
tgO4J!N
s{nZp2"*
Bl~%(dZ
(!]v](
/MUcDr|
qLxA5Z4
j_x.VW H#
4A;~?T
UM2$x1x
^9`jhT`6,
GO&cC'@aL5
BO_JHu3X<
mihuQuy"!7.w~hj+j
N]F;*Sw&
QB6_Wi}-
pL/As,
fXS%C
Zn3oIe
G~C.=?
='fGVCg+"1{:G
<#n4LI
F~u_HQC
@`ykx&1
-R|6O& yc~?
YM*IDRP+=pG)1
N!~$y=F
+T*i(Vd|@A]N
j<iPyv
CU9R64
,SycKWi
,66iQS0/f
=J(e<Gi
@#o4T|J
?U~@uIb3
5LOs bN
/d6YJb@1
Ot|a,E
8TD&sz
+|Im%Ti8fg{q[jhIj
BVuI5,
A`4cpmZ
@eM?xW
qW 1Ky$
A4$-)y+eu{_
,%,-?ep!H1-
p('FH[d
>'iDfa ]
lJ,GeF</~
HvHXDb
)`chgyMB[S33Tjl
~cDnM2}
mSo%36
4G5PA9.=a_\q?W9U
*.v?2k'
#4"~,f
olN[-lupX
seC9v/ ;e
hP,-::.z5tE
URD?"* -]
c8&x+4
$$"CR#&'K
'xs_M3!'g\1|
< @ytnI\Sg<vK/s
LUvHmuy0\,
RP G(57gwXJ&
;7(AHi
.bcq?=)H
_2aY#P
}?GIf
Ku6c:M
l\>OtK
me9U3Vv
Jl9YXR
m>^0c@O
J#VVBWi~$
HXLZw[.
);9<Ma
UwV5w66t
L>5iI W
c;)m!^z
l)G3_f.@
dC9fCmd{oPF^K
nXD4Zgv
bR.l1aV
wmGL21
05WLnDY
L1FBrh
E>'FuzBW>}N6S
'jgooj
~_KcR1
vqO]wt
h?5QWA
w{3iM{+-0
vh?8N+4C
.L760Dy=
@`|Q3n{<ju+Hy0
[!,vLV
K%fb1i<
U/!}>Z
M*H&+{q
a%bzp=A3f%%
tHxh+)g
@7Z&WwU
4ljmOJ
XC}p={i
y+:sYym=r&;Hm575ul
c,* ^=B#Y
7L+Gm
$;60RS
63W_iv
V[&*qe
RvXu/N ,%e[en\fY-sp
ZY%tVX
:54$%&zHH5$
I[iVSg
Tq0YO/@NH
opA>QA;#qv
<$^{sL
ZDBj~hN
U>g6f[
v6oRic/
VWr,qR
RuA0tt
G*]N.HC
xF9FRNC
KPsKswzopj^
-USEJQ
:of5Md
iA4e6h
f(Fc +{G
kmF4erd/`
VM-?KM iz
`%lW|\.C$N.
p9#vr}9W
~0@ge#
~v_Dtp
7i)d{:']
Jn-){3
Ze!baC
wRlsr
6OgE)!l
,=R>WZ
6;>mFZ!g
fc|v1HjJ4:L9X=
gIX[YZ
J;+&!)}3
z6s{Z:<;9Raqsx
1gh $!}
>7t|F"
xSpFySYEsL
\}3y[LOKtz5
I,t}v`
>*9=]m
KG J<a[`)ZBaYk
"<Hc)
k{l}t{E
{]QHFG'K
}}U+UhKvs
DbM+}vg!
kXmW0R\
Wxv-4bsTlOR
2t/o]r
#X2~UK2`
Gcx#9gWr
,|[w r|
Y3ILFK
^G.OG+p
]wt*?{6.48'>
bq4.-goKvG
kyEkv5
>%Nw{A
Vtx7{bgV_
Y]?Cw;
+vqdG_u1
xzBPfPB8
z[1qx.03o:
XpJztJ
(IGD@=(DsHz
Q0Tf4*
X~RHM%9
GCh+d-
6S!TLZ
.(w~odcqw
*q:fA>8j
HC3*LyJ{
FuyE-aa)U
<`AlPN
:Zg,\uu#[\yH
y:MP0>
R<#e4a-im
IgZx~_NJs$kF
e@0r\k
]3]]tt
\&mDDV
+pI1%AzCa
ic#?&Mgg
kjjlesEi
CeD2B=y^m
[@BuGo2,
e0Xbb~
9jwS6,W"a
lq$L3 aoaR;
?3EXU?
<Kf/!6Qirl
:A1\>;/]
ov7N>Qv
/:bNyG+wpt
Awdr4%
ngyowe6OqyL9r
`H}oH&
0EX|UHQ#( 7
,cg7IO
(M@!}7Q(\<RB_7c^631V.
-,"@VJ
[.tj0xy
Op"fFph:,z
{GH6In
v?hRmD,R
TZ6bll&%1,t_\7;xcW
O/1_fIQ
z*m}6kJ
$19csv9o:pFe
]#URJq
A2Goc,~wXx|gYffFU
Ak9E~p^tRv
do`P_Y~
$\DD@Nm+9O+L?Y
xpXpy6
F~k#h9
];FP/(Zj7eWr[
y`&<s
cK%Md6
DiY\Y-
?3MUuC*
`Q 0N2
%/j2? :
^YX98[
&X<]2==
g6[$SfHXh
2mF3[hR
?l8s&R+7Sci-Q
8aHd8:
j@2NcP_
\LKGpd
qgPo)-
E uo6)~6
jew"$Fp{e
=?c&?XrZ)
jB~pm>[x|
3Wsx\a#Mx(g
bNO/2}s4
qr@ Ru
jN!&I)iaqI
HPdR"vd_
eE &O1-3dE
w%;q}ElNO;54^%9
dVHC_0Ow
{4.D4^
IJtQyQ
<qO09s2T
oM4;?"
^u+ne`iPj[c
301#%\uHCou
wV75ob<To
ANuQXL5
n0B37L
>v3H&4/O
7S='^(^
JZ'oy4f
A q3S[
GXJs1[xI
SNt4HF]u~oo<
HkEw:c
pL%l{-y(#
)0O9^bmtV
#^*8I)yX
hJm< hbXU+W
JTRkQ*MW"
(RG0[s5J
rWvu8P5
\Rz\\I
4vY]=h="<k;
"8/I+Y
Bn{um?q
R8:OL
/.)a-6m1AyqOt
IVxBfJ
#t#mFFH
NRSf%L
3%o6SUzrxco
te\ }3
<'ox?dE>DF{=v%7
.S:\B6OJ
x"&+l7lK
G-?Uh]>M;wC:R
3SOjF!So`gHE)
8[ho)<aALTZ#
n--7jF
9_7#zH78c
] oLtl
aALel#.
;WZTM"
cwBn=H3
1E3ik7'Og
}YanwJa
;PZW\\
hXs(0*
-1*"{>F =
;h^?]Bj|4
1,Ex@{6
k0.H[`R))|Pd</
K0"Yt2lm
lcsc[r
fzy7b !q?
wo~H(9<h~pSWvB4<|gGg4B9ic
)$kab,
"*jhA<?s
<V//+`W
c6}7z7wz
K!+"p\#T
K38S>v
)XpMN.1
jvP&4Kq
zG-6z,*b={
K:y7EJ
UT!g doc
5ouZX)r
Y!+=XK_5L(I
\]Uma{L9G
un~U*Ox?
rkW.a<
s`:,%Z
b)1"eDg
8`2!?^+^
YhY0'gP
MiVks`Rk By-
s;WspWB;
SjWB>H|2
nJ+@])
B9)0!P
J4PTV4&
w!k'41*Y
BOt&YNW
5eL;;Ok
}{!]/6
totVmK!1G-9{c*E;M5
pRX8&..ewy
AP? 1YYf
n;.Mf'0/#
&cw@EV3bv
3V9@V4
!+*g3:bRp
u6`k\tab\@{*oAn?LnR!
_LX,F
=^~J2r}
c#DyF,]p=g'4LC+(
y*"?"}S
XcY<PiNV,Qy<
]86zCy"m
Xl%1~Msmjl5$|
POMU9@s
I)<d}E{
`}^fq5AME6B] =
$nUYr'LP;
E}X_M[
m"!7\0^%}W~
<-={P^
D:i7{[;q
`k`fjbl@
>*HI!|iMV0s>MWt
epbfBQ
M/<TB8-w8W<)00u-Ut^
9UW/@n
V@H3.a
iJb S3
Tymd#I72
5k|&1VyJa
gGZ;aP\
R7s{{BJB'm0
VM$.H`1"!
/DN;&!$C
#| tsP1JL]
Y8K!pU
`qq2!1ZM`
x}..+Q
N~9e}
f[IOqU
'N^*M[Dvs
m<XU030SC{Fp`_
}#v~-mb
YSyx3H)s0
#[Ik5!
VYR|q?'*":M($<=V
y!x1ja
R1HBt.ZfN^e
RhvP% ! ,
c)bRof+
Ok;-e$;_
{?KA3VMd6_
zBOaGu
E3Y9!]
2y1>9U~Q"
]:egCkB7E
8Z]D<q
]1#)Y<
}]IACJAIJ
\m;pOr
Aeb-#8S
+3{r:!;o|~A'QpECU7j
Y niGxN
r~4~t#
u,!:nU{G
>hP[d|r
Vq.]c#
ejqeo>j#~
]BDK5S
?t(Jcn
\S&SjJL
2_&rh`q
m)I^Y"ThU\eT
%XYV~^6[
T2hF6+
QWL{RK
TLJ-CR
H'do,'
lO*aR~_
JyGGs7
G?P;z{elt
cw9nX9Q
|y}ehj>
QjV1;22
N!Q?u$t
X%iA$B[-x
!/KQ]-p$
kEyuwhwB
X[W>O1Hg3k})
9`dUz1p\q
|^vV_Z
thI=Nr
F\~:$r7M
#(-fvSc23/Q
LW\OTm
ELaEC!e\ex
N.+!@qc3^x{/|
{Lfa^e8|t
akp{fg:fsP+
,]KQ40n%t;T?
5|5w$%@
$cjh+<O*+N
GpaV"[
~GS6=&
`+:&An5
f?D$"b_^[Lx/-!
n^Bq ;
{u.~ya
fM#}<?*cH.'
|U77u;_
9w2"vv
6h">4_8/& ypD.
fY2F!Vu
%4PyrrY2e&
<!Svwy
=b/kka
8>LxJF
+.3i;+
1mieBrw=r1,
7{lAx^
eet}~N,nT+
,,uv5^WaIO
e_v"/Mc,$O3'/'1D
yB}+dL=Ck
x615Ii4
FimeIa*0NHP'3#
F94:YB^
UJ!<l'. f
+$W@Dn
&k1jBD~=lQ+F
hGiI0TK
w@$*qfB
.I/E'+SK-$W!$V _YoJ
YY7|:_e
9\W!^A\
@4O| oV:
m1FQ6h
&"{dm1(B
.tA^hV>S"TA{
-J'YsV
N)(P.EU
Ox_6/$
.SSss,7y
8.vBL,
wt4>b\
zIoM.w^z*
E*qUZ7z
2a A>W
DB"4CuW4&
Skb[(B6
=o1?%"Q
E\Uauy
(n(uV:
$CpD"R,S)zybEm
u2' Wr|F
cz4}B2F'
Lh% HK>W
)^-!LUibM^
;R[=WOn
l=A6^85h$^
5D>-~mw;0
0y9f;3M
-Q$EE6wN&
J(KJNM16@zj"
wEORS]
xYu(JEF\V=m
5-Q|q5
#4i~@j~()
&|B`dJC~
P$QLa"
w\FF+<
EJ1^:I
T8QGOQtl
})^P<%
?vkQ5n
IS0;%r#vl
QVMzsy
FAI`+T
*oD?IJAKy
tNmdyn
gYi((3l
ZbLngQ
ae!%$ ^t
QXW:_(
:~c Sr
syKPZqDh5LKat18
@%S;xY
K,S*BK
g9rpn)N
d\+o_t
$}&Z+T<>U`oI)<C}
Zb@HQa
G oOm8
vuLV|-
2>ze3EX
"WCAB0
w>::kubR]Le-Z5Q
4JIt$B(%#
T/<wNs<8CC8Zx8GbLT}
]'SgMmS
1YD7\Z
E*Ha],`y
SYZb([
5TRs4nO\1X
h+P[U:M#
|\%'<]S
]M@__NW|q_=
cG=%SbO
*+@3:F"dUXU;
3Q8("p
F=|ve>h\u910qq[
Z>[{">
FC2HIE;F=
Y<>FQwf]+
4_!e#i4cOS
|c)c]eV
e9sKin!#
t4}Q03
}^~U[;
{gQwUnF
~>>>_QOpL43:
?5K1(Z
&|#6B5(}si
zb!Zr*
f7CY?RfKsu<N
5{nawB&AMH-hT$AOo
J)(J`k
*\.)LhS
hkD0~%
|YxA{@t
(cF.F1
^U*;-LzwNG'Sr
SyQ;:;
5FF/eTM
&=p-cFu
Q$d%GEB>[~
X$zfv!e\N
aMBEB*|it$9
:t$DDDDB$$DD&
Rsw9o3
C5wpFLgJd'Aa
y{-j[@bj~`-
jwqj9S
<b<d0SF:
03D/8];S"|2
z(_$6%T<E*V
V5_m.pMaU@Y0
aFLZ7ze
daUz$C#EQ\|
7u6q-R
"?Ts6i
h}UE#Z*
C]!vONP[
)>$&&LE5Dp
Ap|+-l<q
A%%YZy
0w">8&
ml%idcc(%!TQ$,
'@sF"$}
BeUO&Xx,b
t{~xr9W-
KI$:XY=
{'vG8\B,5
4*Jk+{
YO9DO:
;{s t8
F4qEpI+6SEN
_)JHL,c
g~p7$S6:&'+D}
BNi?>gWN4ZJ
QQPassHook.dll
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
Q~%"2#
Db1IB)*`1
6L3.jq
|~q+Qg[B
c*]F)Xgg
f4&x1,
@|L1R$1>;
<8e333gZm<
^@qpCG
><'$%I'RN
.d'N0[*T*k
dsc|<
:"Q#A#G*a
9s#.fQ
Fv}3}t
CuG:J+\
BW(W^MyU
W_~+WNR/bJuG
X1e)a0l
*AfYfuhYg835
PEd+AZ
`Gd7D$!!I
$D!e$&
,r,f8Y
|e-akK\Z
hE00IM$l6iNx5
jAFjudT
PQH;UXd
=Ol{spwHD
2&4MJj[V<\|9V
)*Tr&MqST
kC_M~5
M[W#{VmZUjUlIE
v96$2&[gHrpZ!H
8'92s'tM
q&ML6s-wyA%>uma?F
fytN=F}Y
*yge0|O4y<y<y
x9OUs=A>!
<v6}oxxm":~
jX3$.^G~P#~
q|b~2:,
7otS]ZZkI5jaS/k{]51
Eu%GUr|s~9?
]Ez4;,n\#_rN
6&kzg_+_UM_|
j<ra}
o{cVWa>}f?Rj.2Z
]~9EE/_Lu
1'lk55,>LCk
K9{ft,
vlY.c{
x\s_s%
7*iSd2i
d+<eHMr[
w+Qun-ol
'H\_PU;9XW*V
P.u]r`
6p4ziCZ7$
197T|k7
{/5_~1
skqi'N8K
u7)e>)k
55#]Kw)
v.{MMQ_iX'_vu!t0
.l](fFq`-
6o77[r
P9K+ w
h]'xG{H
N{>7Tn[L>
j~8Tgc`
F?J&8ro u
Q_VuAp
>+:G<mWbFa
s\-uH?+
~5V|:;
b_s??Y{`\C@.b
hfvj\?Y~
A\9.Z~0Urk$~l,d&YG
`IUMEE
(QQPassHookWW
QQPassHook Library
f`Qp(E
I,/|9s{<?y
G;Mc9I
3)~m6u
`6_O1xp
kQ`(<4
dMITPtdR
}/CLL.
ra+1@nFF9/1s
ODw9d(
4JfdLQ
QY0hc*
iEz7SSlT&+
eJFw&AR
O)?QX$
WA,=@."/)!Z
QzxgRm*
`>e9F,
hiqG\mU
g w15V
<!O7*$
13;dQA
WEPwk(D7}D
K[VQGC}{
r]sCs:q
e|Jlonf
i&<TC/U
jYz~H,]p5!
W+XAZj
P/g6mD.
O)a4-p"{
2Y|slre
e^UjT0,EQR8m/A{h1r~nnks
"5kY(uft&H
*~/ygw
!dEh[[9s0
o:DmCwq
i"!Fqu
24?nqZosA
Tm8v/$
EwVirtualAlloc
VirtualFree
t.x,<t
kernel32.dll
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
(08@P`p
8\(L(C@;
rDt$h3t$
E@D4l|Mu
1|hDhG8
A;r_^]
YSVW33h
T4$F`u(j
}RL4#HL4$F
D$$W3|$
3V5:@D
D$,8_^]
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
advapi32.dll
gdi32.dll
user32.dll
ole32.dll
oleaut32.dll
GetKeyboardType
RegQueryValueExA
VariantChangeTypeEx
RegSetValueExA
UnrealizeObject
ReleaseDC
CoTaskMemFree
CreateErrorInfo
7Project1
NMsmtp
System
SysInit
^Classes
Consts
QTypInfo
SysUtils
KWindows
SysConst
sActiveX
3Messages
*ShellAPI
WinSock
ExtCtrls
&Controls
Printers
WWinSpool
+Graphics
Commctrl
FlatSB
StdActns
Clipbrd
EActnList
vMenus
Contnrs
ImgList
dStdCtrls
MultiMon
NMConst
4NMUUE
NMExtstr
VNMS_Stream
NMS_Huge
.ScktComp
SyncObjs
lSvcMgr
Dialogs
3CommDlg
(ShlObj
RegStr
?WinInet
UrlMon
WinSvc
TLHelp32
8Registry
IniFiles
MakePassWordUnit
{FilesMod
Module1
YShareResourceMod
.StopFireW_Thread
GetBianFeng_Thread
QGetZhongYou_Thread
LCloseWin_Thread
getpass_Thread
<StringFun
Base64
TForm1
BorderStyle
bsNone
ClientHeight
ClientWidth
clBtnFace
Font.Charset
DEFAULT_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
MS Sans Serif
Font.Style
OldCreateOrder
OnClose
FormClose
OnCreate
FormCreate
PixelsPerInch
TextHeight
Txthaoma
Height
Font.Charset
GB2312_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
Font.Style
ParentFont
TabOrder
Visible
OnChange
TxthaomaChange
TxtMima
Height
Font.Charset
GB2312_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
Font.Style
ParentFont
TabOrder
Visible
OnChange
TxtMimaChange
TButton
Button1
Height
Caption
Button1
TabOrder
Visible
OnClick
Button1Click
TListBox
ListBox1
Height
ItemHeight
TabOrder
Visible
TTimer
Timer1
Interval
OnTimer
Timer1Timer
TTimer
Timer3
Interval
OnTimer
Timer3Timer
TNMSMTP
NMSMTP1
ReportLevel
OnConnect
NMSMTP1Connect
EncodeType
uuMime
ClearParams
SubType
mtPlain
Charset
gb-2312
OnSendStart
NMSMTP1SendStart
TForm2
BorderStyle
bsNone
Caption
Default IME7002
ClientHeight
ClientWidth
clBtnFace
Font.Charset
DEFAULT_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
MS Sans Serif
Font.Style
OldCreateOrder
OnCreate
FormCreate
PixelsPerInch
TextHeight
TButton
Button1
Height
Caption
Button1
TabOrder
Visible
OnClick
Button1Click
TTimer
Timer1
Interval
OnTimer
Timer1Timer
TNMShow
NMShow
Height
BorderStyle
bsDialog
Caption
Netmasters
clWhite
Font.Color
clWindowText
Font.Height
Font.Name
MS Sans Serif
Font.Style
Position
poScreenCenter
PixelsPerInch
TextHeight
TLabel
Label1
Height
Caption
&Copyright 1996-1998 NetMasters L.L.C
clWhite
Font.Charset
DEFAULT_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
MS Sans Serif
Font.Style
fsBold
ParentColor
ParentFont
TLabel
Label2
Height
Caption
To Register Component,
TLabel
Label3
Height
Caption
Call 603-578-2200
TLabel
Label4
Height
Caption
1-888-2-GET-WEB (In USA)
TLabel
Label5
Height
Caption
Fax 603-578-2228
TLabel
Label6
Height
Caption
E-mail info@netmastersllc.com
TLabel
Label7
Height
Caption
Contact NetMasters LLC
TLabel
Label8
Height
Caption
http://www.netmastersllc.com
Font.Charset
DEFAULT_CHARSET
Font.Color
clNavy
Font.Height
Font.Name
MS Sans Serif
Font.Style
fsUnderline
ParentFont
OnClick
Label8Click
TImage
Image1
Height
Picture.Data
TBitmapv
NN$yznfv}Cs
Vpv[oQ~w
{=c[%e
zJ/K<z_
w=V]b`G
LCweJ,5
}au;5SK
bijTTSx5::ApH'GJKx|sn]
wVVZt63q
STkS/':_a$:l\bw*'&KK,'D
]:2l^Vlm8Yw[||[
kkz^B]Vl]e![J5"5aEMl0zz
l8m3r}]::}
T]l9nGCuCp
mY87WX:_s}3XX8l
[.QRhw)((]foC
\E.Rhj_YX(Y:9s\X_v
}>YY3X0
ZP-AQhWWY]\WlYpZlXGl
7>YYYX
)@@BDB^ZX>ppX(W\Z9]
]ZW(WXp@qqpYY@^_
lmmm8l
3XXPEQrr}nnn
z].QD:#z
TLabel
Label9
Height
Caption
! Obtain Support and Source Code
TLabel
Label10
Height
Caption
TLabel
Label11
Height
Caption
,Version: 5.3.0 Build:1055 Date:5/26/99
TButton
Height
Caption
Default
ModalResult
TabOrder
TButton
Button1
Height
Caption
Known Bugs
TabOrder
OnClick
Button1Click
TButton
Button2
Height
Caption
Mailing List
TabOrder
OnClick
Button2Click
TButton
Button3
Height
Caption
Vesion Check
TabOrder
OnClick
Button3Click
TButton
Button4
Height
Caption
Submit Bug Report
TabOrder
OnClick
Button4Click
TButton
Button5
Height
Caption
Source Code
TabOrder
OnClick
Button5Click
EwVirtualAlloc
VirtualFree
t.x,<t
kernel32.dll
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
(08@P`p
8\(L(C@;
rDt$h3t$
E@D4l|Mu
1|hDhG8
A;r_^]
YSVW33h
T4$F`u(j
}RL4#HL4$F
D$$W3|$
3V5:@D
D$,8_^]
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
advapi32.dll
gdi32.dll
user32.dll
ole32.dll
comctl32.dll
advapi32.dll
wsock32.dll
GetKeyboardType
RegQueryValueExA
VariantChangeTypeEx
ReportEventA
UnrealizeObject
WindowFromPoint
IsEqualGUID
ImageList_SetIconSize
StartServiceCtrlDispatcherA
WSACleanup
eBBBBBBe
BBBBBB
BBBBBBBBBBBBB
BBBBBBBB
BBBBBBBBBBBBBB
BBBBBBBB
,,,,,,,,,,
,,,,,,,,,,
22222222222222
22222222222222
BBBBBBB
eeeeeeeeeeeeeeB
BBBBBBB
BBBBBBBBBBBBBB
]Hw]Hw
@@@@@@@
@@@@@@
jjjjjj
AAAAAA
@BBB@B
@BBB@B
@BBB@B
@BBB@B
@BBB@B
BBBBBB
@BBLC\C
@CBB@B
@CBB@B
jjjjjjh
@@@@@@
ADDDDDD
jjjjjjh
jjjjjjh
LARGEICON
DVCLAL
PACKAGEINFO
TFORM1
TFORM2
TNMSHOW
MAINICON
TYPELIB
DVCLAL
PACKAGEINFO
MAINICON
VS_VERSION_INFO
StringFileInfo
080403A8
CompanyName
Microsoft Windows
FileDescription
Microsoft File exHook library
FileVersion
7.0.0.2
InternalName
LegalCopyright
Copyright (C) Microsoft Corp. 1991-1998
LegalTrademarks
OriginalFilename
ProductName
MaiShellHook
ProductVersion
Comments
VarFileInfo
Translation
??
%Error removing control from dock tree
- Dock zone not found
- Dock zone has no control%List does not allow duplicates ($0%x)
Failed to get data for '%s'/Menu '%s' is already being used by another form
Service failed on %s: %s
execute
continue
interrogate
shutdown(Service failed in custom message(%d): %s
Service installed successfully/Service "%s" failed to install with error: "%s" Service uninstalled successfully1Service "%s" failed to uninstall with error: "%s"Docked control must have a name
Shift+
Unable to insert a line Clipboard does not support Icons
Bits index out of range
Invalid data type for '%s'
Failed to set data for '%s'
Cancel
&Abort
&Retry
&Ignore
N&o to All
Yes to &All
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Cannot drag a form
Metafiles
Enhanced Metafiles
Bitmaps
Invalid property value
Warning
Information
Confirm
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index)Failed to read ImageList data from stream(Failed to write ImageList data to stream$Error creating window device context
Error creating window class+Cannot focus a disabled or invisible window!Control '%s' has no parent window
Cannot hide an MDI Child Form)Cannot change Visible in OnShow or OnHide"Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
%String list does not allow duplicates#A component named %s already exists$''%s'' is not a valid component nameA class named %s already exists
Invalid property value
Invalid property path
Property does not exist
Property is read-only
Error reading %s%s%s: %s
Ancestor for '%s' not found
Bitmap image is not valid
Icon image is not valid
Metafile is not valid!Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Friday
Saturday
Cannot assign a %s to a %s
Cannot create file %s
Cannot open file %s
Stream read error
Stream write error+Out of memory while expanding memory stream*Can't write to a read-only resource stream
Class %s not found
Invalid stream format
Resource %s not found
List index out of bounds (%d) List capacity out of bounds (%d)
List count out of bounds (%d)+Operation not allowed on sorted string list
September
October
November
December
Sunday
Monday
Tuesday
Wednesday
Thursday
January
February
August
Error creating variant array
Variant is not an array!Variant array index out of bounds
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Win32 Error. Code: %d.
A Win32 API function failed
Floating point underflow
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Stack overflow
Control-C hit
Privileged instruction%Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'Invalid variant type conversion
Invalid variant operation"Variant method calls not supported
!'%s' is not a valid integer value
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operationFloating point division by zero
Floating point overflow
k{cZcZR
fff33f
2C:\Windows\System32\EXBLW.EXE
8b8-4b6c-aaf7-d15bdd0cbd8b

Process Tree


07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe, PID: 1332, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

regsvr32.exe, PID: 2708, Parent PID: 1332

default registry file network process services synchronisation iexplore office pdf

360TptMon.exe, PID: 1972, Parent PID: 1332

default registry file network process services synchronisation iexplore office pdf

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 8beef5070c6bb0ff_hofvpf.exe
Filepath C:\Python27\HOFVPF.EXE
Size 446.7KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 5b7dbad9293ab0f5e5170b6efc4785f7
SHA1 9e65a2195bda34e53da42875542cfd9274f1239e
SHA256 8beef5070c6bb0fff1c33873d5b4d42f7347609c9429088e45e45d17bc642479
CRC32 0DDF81D4
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name bbb06e1d60da4d1c_zgarm.exe
Filepath C:\Windows\SysWOW64\ZGARM.EXE
Size 446.6KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 17a867c7c0cece8535b4dea6167bb16a
SHA1 2dfb92373c06a54608c4d34d4eaf977334226b8d
SHA256 bbb06e1d60da4d1c582ff61bc6914767b3acbf5780002ff79ddfc4c20a149efd
CRC32 BA1A0F07
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name eb7fee490a23844c_taskhost.exe
Filepath C:\Program Files\taskhost.exe
Size 446.6KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 b62b2b924a9b1c266b7806fc9cc7641b
SHA1 fb9eaa4d0b69e138bd64bb5a9cb3b6b901ca1a13
SHA256 eb7fee490a23844c17d46bb29ddd1be9327564aa3b89d0bb7902811dae77fea4
CRC32 75BB3739
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2b808c142b70b2a9_grvik.exe
Filepath C:\Program Files (x86)\GRVIK.EXE
Size 446.6KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 17f42cf0c45ee05fc254f9c7d213c324
SHA1 d5f738bdb1db45a1b4045baa984050865d83d538
SHA256 2b808c142b70b2a94da3a8fe354d3264924537c6ee91e43ea202fca703504e93
CRC32 660D54B7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f0a7ec2edff7699e_ms7002.dll
Filepath C:\Windows\SysWOW64\Ms7002.dll
Size 52.0KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 876a2a99b81968f5b26e3cbe12063d2b
SHA1 7afa8f33b691b2651b65eb07220cc2fda4b7537c
SHA256 f0a7ec2edff7699e546221808f45ca8816a75eb519618283d7c4514dfb9134e0
CRC32 3DA38B9B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9b5cd5f938ecaefb_suw.exe
Filepath C:\$Recycle.Bin\SUW.EXE
Size 446.1KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 bfb3608b97f71ff3ebc9c59768007604
SHA1 a71c8e671a8f8bd1dc597d6cf816757b6eedd64e
SHA256 9b5cd5f938ecaefb2b3c11681324d3519fbd9e4712f8e8a1ea7d783f4aeb7218
CRC32 D314E9D3
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a2855d70d9e55dda_stoos.exe
Filepath C:\Program Files (x86)\STOOS.EXE
Size 446.6KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 29638cd4b11e9e00c6ae0d70915487cf
SHA1 1fc53f1ae6ec745d101c5ebd5c848314ac0b1004
SHA256 a2855d70d9e55ddaaa66780c7282b4a4056a1a12287a8764b6cbfdc1c983d040
CRC32 948FA571
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 200b67daaa7811b9_weqdvk.exe
Filepath C:\rfaulke\WEQDVK.EXE
Size 446.8KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 c61457f822c5ef567d625292501f4aaf
SHA1 3e61bf766fd034c6c8713b0ae75f733412571889
SHA256 200b67daaa7811b95beb74f4419d500215b9274d559f2b3a80e7baae3ade6fca
CRC32 D0D702CC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c80e2203a2387a7c_zdkfq.exe
Filepath C:\Program Files (x86)\ZDKFQ.EXE
Size 446.6KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 7327ec76b8b3ba45758b9cc7e1740e0e
SHA1 88c5a17e8993ae3abe698b652514b1d45b6a30eb
SHA256 c80e2203a2387a7c02248a143aebfad930ea36d8e3c72f7daa89b1e5564a8980
CRC32 3DE70BBA
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c70bc902b06a223e_360tptmon.exe
Filepath C:\gcoxh\360TptMon.exe
Size 446.3KB
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 3365edd03d2f74351af047751f765695
SHA1 2c4bf87a9078cc213411039af7eaa77f7ec2e178
SHA256 c70bc902b06a223eb247979921d90f85dd644b7b0688435cc97f94365f516c21
CRC32 576548C6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e2df714149a1b6df_filedebug
Filepath C:\filedebug
Size 260.0B
Processes 1332 (07b1a0abaeed98ffb28895cf57be22547abb733026d1283ef3776d1abdfdb797.exe)
Type ASCII text, with CRLF line terminators
MD5 a4bafa83796bdbd304f58c7f99fa2fef
SHA1 6bf2e78838c0674b7a51aa217e70dbecc79c8d33
SHA256 e2df714149a1b6dfd73a8620c9096176e4ae9d900d536a33fbf1e5d031d97adc
CRC32 7ACFF31F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.