Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Jr2YluqEVG.dll

Overview

General Information

Sample name:Jr2YluqEVG.dll
renamed because original name is a hash value
Original sample name:700a8957c6864ffbd6b093d57f31271beb5815a5a8eaccc446d4f6f9f575ad3d.dll
Analysis ID:1544799
MD5:9fcb34e9e4f331403ccb98f6ead542bc
SHA1:e9544c70795cd7807f2d7f6fc32cf716448b8b2b
SHA256:700a8957c6864ffbd6b093d57f31271beb5815a5a8eaccc446d4f6f9f575ad3d
Tags:2024bankerdllgolangloadermekotiouser-johnk3r
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)
Program does not show much activity (idle)
Uses 32bit PE files

Classification

  • System is w10x64
  • loaddll32.exe (PID: 8152 cmdline: loaddll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 7192 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 7366FBEFE66BA0F1F5304F7D6FEF09FE)
    • cmd.exe (PID: 7324 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 7396 cmdline: rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7352 cmdline: rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@Z MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7596 cmdline: rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_get_widget_image_with_alpha@@YAHPAXAAVCImage@ATL@@_N@Z MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7684 cmdline: rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,UG_ArcCreate MD5: 889B99C52A60DD49227C5E485A016679)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: Jr2YluqEVG.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: Jr2YluqEVG.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: Jr2YluqEVG.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: classification engineClassification label: clean2.winDLL@12/0@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7192:120:WilError_03
Source: Jr2YluqEVG.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@Z
Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll"
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@Z
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_get_widget_image_with_alpha@@YAHPAXAAVCImage@ATL@@_N@Z
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,UG_ArcCreate
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@ZJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_get_widget_image_with_alpha@@YAHPAXAAVCImage@ATL@@_N@ZJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,UG_ArcCreateJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: lvgl.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: winmm.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Jr2YluqEVG.dllStatic PE information: More than 466 > 100 exports found
Source: Jr2YluqEVG.dllStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: Jr2YluqEVG.dllStatic file information: File size 3079680 > 1048576
Source: Jr2YluqEVG.dllStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x245200
Source: Jr2YluqEVG.dllStatic PE information: More than 200 imports for USER32.dll
Source: Jr2YluqEVG.dllStatic PE information: More than 200 imports for lvgl.dll
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: Jr2YluqEVG.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: Jr2YluqEVG.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Jr2YluqEVG.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: Jr2YluqEVG.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: Jr2YluqEVG.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: Jr2YluqEVG.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: Jr2YluqEVG.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
11
Process Injection
1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Rundll32
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
Process Injection
Security Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1544799 Sample: Jr2YluqEVG.dll Startdate: 29/10/2024 Architecture: WINDOWS Score: 2 6 loaddll32.exe 1 2->6         started        process3 8 cmd.exe 1 6->8         started        10 conhost.exe 6->10         started        12 rundll32.exe 6->12         started        14 2 other processes 6->14 process4 16 rundll32.exe 8->16         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Jr2YluqEVG.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1544799
Start date and time:2024-10-29 18:53:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:11
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:Jr2YluqEVG.dll
renamed because original name is a hash value
Original Sample Name:700a8957c6864ffbd6b093d57f31271beb5815a5a8eaccc446d4f6f9f575ad3d.dll
Detection:CLEAN
Classification:clean2.winDLL@12/0@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .dll
  • Stop behavior analysis, all processes terminated
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe
  • Excluded domains from analysis (whitelisted): www.bing.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: Jr2YluqEVG.dll
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Entropy (8bit):6.795604895634087
TrID:
  • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
  • Generic Win/DOS Executable (2004/3) 0.20%
  • DOS Executable Generic (2002/1) 0.20%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:Jr2YluqEVG.dll
File size:3'079'680 bytes
MD5:9fcb34e9e4f331403ccb98f6ead542bc
SHA1:e9544c70795cd7807f2d7f6fc32cf716448b8b2b
SHA256:700a8957c6864ffbd6b093d57f31271beb5815a5a8eaccc446d4f6f9f575ad3d
SHA512:cc3ae2f701e7185a2648c33bcf54830c77a5c53e6c66281f5c6a9dd39a15de2193c42c266cb937bdd2918663784d690d1a4e3e3523c92fb4be3af2a2648680f9
SSDEEP:49152:9YQQJyfZa987jV/waLFZVhVEl/NALAQFkAnho06roCo/s6dXfL0owU/cbFf/tNwC:9YQfZaOfVIaBZVUesDAhoPro//Jdv4oZ
TLSH:1BE5AD62BA734022D05701347A5EB73BE5BD53B0E73960C772BCAA2C7D250C356396AB
File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........H~..)...)...)...B...)...B...)...B...)...Q...)..zP...)...B...)...B...)...B...)...)...-...Q...)...Q...)...Q...(..zP..g)..zP...).
Icon Hash:7ae282899bbab082
Entrypoint:0x10209563
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x10000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
Time Stamp:0x66ED1FFA [Fri Sep 20 07:10:50 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:56a2acdfacad6216ca2356226adef1f5
Instruction
push ebp
mov ebp, esp
cmp dword ptr [ebp+0Ch], 01h
jne 00007FDBE4FE7F97h
call 00007FDBE4FE8818h
push dword ptr [ebp+10h]
push dword ptr [ebp+0Ch]
push dword ptr [ebp+08h]
call 00007FDBE4FE7E43h
add esp, 0Ch
pop ebp
retn 000Ch
mov ecx, dword ptr [ebp-0Ch]
mov dword ptr fs:[00000000h], ecx
pop ecx
pop edi
pop edi
pop esi
pop ebx
mov esp, ebp
pop ebp
push ecx
ret
mov ecx, dword ptr [ebp-10h]
xor ecx, ebp
call 00007FDBE4FE72B2h
jmp 00007FDBE4FE7F72h
mov ecx, dword ptr [ebp-14h]
xor ecx, ebp
call 00007FDBE4FE72A3h
jmp 00007FDBE4FE7F63h
push eax
push dword ptr fs:[00000000h]
lea eax, dword ptr [esp+0Ch]
sub esp, dword ptr [esp+0Ch]
push ebx
push esi
push edi
mov dword ptr [eax], ebp
mov ebp, eax
mov eax, dword ptr [102C5DCCh]
xor eax, ebp
push eax
push dword ptr [ebp-04h]
mov dword ptr [ebp-04h], FFFFFFFFh
lea eax, dword ptr [ebp-0Ch]
mov dword ptr fs:[00000000h], eax
ret
push eax
push dword ptr fs:[00000000h]
lea eax, dword ptr [esp+0Ch]
sub esp, dword ptr [esp+0Ch]
push ebx
push esi
push edi
mov dword ptr [eax], ebp
mov ebp, eax
mov eax, dword ptr [102C5DCCh]
xor eax, ebp
push eax
mov dword ptr [ebp-10h], eax
push dword ptr [ebp-04h]
mov dword ptr [ebp-04h], FFFFFFFFh
lea eax, dword ptr [ebp-0Ch]
mov dword ptr fs:[00000000h], eax
ret
push eax
push dword ptr fs:[00000000h]
lea eax, dword ptr [eax+eax+00h]
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x2bb6e00x386c.rdata
IMAGE_DIRECTORY_ENTRY_IMPORT0x2bef4c0x17c.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x2f20000x1e0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x2f30000x275c8.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x2a2c200x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x2a2c800x18.rdata
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x2a2b600x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2470000xea8.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x2451cc0x245200d1d6d373f9cbc3634cc9be745d25a26dunknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x2470000x7d4400x7d6008f9f5bb45ecee8ae6b46e30ef5574cffFalse0.39000771124127614data6.079892008032184IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x2c50000x2c3800x5a0005fb798f47d563e6aae7e75cb68ae63eFalse0.25473090277777777data4.89538078889069IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0x2f20000x1e00x200b583cfeda582697be8ce5f97a1981036False0.525390625data4.703795642277185IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x2f30000x275c80x2760043c0fb01d0544c82d57ee7c0e45ca43cFalse0.503577628968254data6.612043215924755IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_MANIFEST0x2f20600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
DLLImport
KERNEL32.dllGetConsoleOutputCP, DeleteFileW, EnumSystemLocalesW, IsValidLocale, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, GetStdHandle, ExitProcess, GetFileType, SetStdHandle, QueryPerformanceFrequency, GetCommandLineW, GetCommandLineA, SetFilePointerEx, FreeLibraryAndExitThread, ExitThread, HeapQueryInformation, VirtualQuery, VirtualAlloc, GetSystemInfo, InterlockedFlushSList, RtlUnwind, OutputDebugStringW, FindFirstFileExW, LCMapStringEx, VerifyVersionInfoW, GetConsoleMode, ReadConsoleW, GetModuleHandleExW, Sleep, ReadFile, WriteFile, PurgeComm, WaitForMultipleObjects, CreateMutexW, WaitForSingleObject, CreateFileW, ReleaseMutex, SetupComm, CreateEventW, GetLastError, WaitCommEvent, GetCommState, CloseHandle, CreateThread, ClearCommError, GetOverlappedResult, SetCommMask, SetCommTimeouts, SetCommState, lstrcatW, WideCharToMultiByte, GetModuleHandleW, CreateDirectoryA, HeapFree, GetTimeZoneInformation, FindNextFileW, IsValidCodePage, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, WriteConsoleW, MultiByteToWideChar, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, GetStartupInfoW, IsDebuggerPresent, WaitForSingleObjectEx, ResetEvent, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetUserDefaultLCID, GetTempFileNameA, SearchPathA, GetProfileIntA, GetTempPathA, VerifyVersionInfoA, VerSetConditionMask, GetWindowsDirectoryA, FindResourceExW, lstrcpyA, GetACP, GetCurrentDirectoryA, GetCPInfo, GetOEMCP, VirtualProtect, GetUserDefaultUILanguage, GetLocaleInfoW, SystemTimeToTzSpecificLocalTime, GetFileTime, GetFileSizeEx, GetFileAttributesExA, GetFileAttributesA, FileTimeToLocalFileTime, GetVersionExA, GlobalFindAtomA, FindResourceA, lstrcmpW, GlobalDeleteAtom, LoadLibraryExW, GetSystemDirectoryW, EncodePointer, lstrcmpiA, LoadLibraryA, GetCurrentProcess, DuplicateHandle, GetVolumeInformationA, UnlockFile, SetFilePointer, SetEndOfFile, LockFile, GetFullPathNameA, GetFileSize, FlushFileBuffers, FindFirstFileA, FindClose, CreateFileA, GlobalAddAtomA, ResumeThread, SetThreadPriority, GetCurrentThreadId, SetEvent, GlobalFlags, FreeLibrary, CompareStringA, GetModuleFileNameA, GetCurrentProcessId, LocalReAlloc, LocalAlloc, GlobalHandle, GlobalReAlloc, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSection, FileTimeToSystemTime, GlobalGetAtomNameA, lstrcmpA, LoadLibraryW, GetProcAddress, GetModuleHandleA, GetModuleFileNameW, InitializeCriticalSectionAndSpinCount, OutputDebugStringA, CopyFileA, FormatMessageA, MulDiv, LocalFree, GlobalSize, SetLastError, GetTickCount, GlobalUnlock, GlobalLock, GlobalFree, GlobalAlloc, GetTempPathW, GetLongPathNameW, FindResourceW, LoadResource, LockResource, SizeofResource, GetProcessHeap, DeleteCriticalSection, DecodePointer, HeapAlloc, RaiseException, HeapReAlloc, HeapSize, InitializeCriticalSectionEx, LeaveCriticalSection, GetStringTypeW, EnterCriticalSection, lstrlenW
USER32.dllInvertRect, HideCaret, EnableScrollBar, MessageBeep, GetIconInfo, DrawIconEx, LoadImageA, IsRectEmpty, DrawFocusRect, WindowFromPoint, ReleaseCapture, SetCapture, GetNextDlgGroupItem, LoadImageW, TrackMouseEvent, InvalidateRect, KillTimer, SetTimer, DeleteMenu, SetCursor, ShowOwnedPopups, MapDialogRect, GetAsyncKeyState, GetNextDlgTabItem, EndDialog, CreateDialogIndirectParamA, OffsetRect, SetRectEmpty, CopyImage, SystemParametersInfoA, GetMenuItemInfoA, DestroyMenu, PostQuitMessage, LoadBitmapW, SetMenuItemInfoA, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, EnableMenuItem, CheckMenuItem, GetMonitorInfoA, MonitorFromWindow, WinHelpA, GetScrollInfo, SetScrollInfo, LoadIconA, GetTopWindow, GetClassLongA, EqualRect, MapWindowPoints, AdjustWindowRectEx, GetClientRect, RemovePropA, GetPropA, SetPropA, ShowScrollBar, GetScrollRange, SetScrollRange, ScrollWindow, RedrawWindow, SetForegroundWindow, GetForegroundWindow, SetActiveWindow, UpdateWindow, TrackPopupMenuEx, TrackPopupMenu, SetMenu, GetMenu, GetCapture, IsIconic, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, SetWindowPlacement, GetWindowPlacement, DestroyWindow, IsChild, IsMenu, CreateWindowExA, GetClassInfoExA, GetClassInfoA, RegisterClassA, CallWindowProcA, DefWindowProcA, PostMessageA, GetMessageTime, GetMessagePos, RegisterWindowMessageA, DestroyIcon, NotifyWinEvent, SetWindowsHookExA, GetCursorPos, ValidateRect, GetKeyState, GetActiveWindow, IsWindowVisible, PeekMessageA, DispatchMessageA, GetMessageA, MessageBoxW, DefWindowProcW, PostMessageW, CreateWindowExW, SendMessageW, GetScrollPos, SetScrollPos, RealChildWindowFromPoint, GetClassNameA, GetDesktopWindow, PtInRect, GetWindowRect, IsDialogMessageA, GetWindow, SetWindowLongA, SetWindowTextA, GetFocus, SetFocus, GetDlgCtrlID, SendDlgItemMessageA, CheckDlgButton, CreatePopupMenu, GetMenuDefaultItem, MapVirtualKeyA, GetKeyNameTextA, SetLayeredWindowAttributes, EnumDisplayMonitors, OpenClipboard, CloseClipboard, SetClipboardData, EmptyClipboard, DrawStateA, SetClassLongA, SetWindowRgn, SetParent, RegisterClassExW, wsprintfW, AppendMenuW, LoadIconW, TranslateMessage, PeekMessageW, DispatchMessageW, ReleaseDC, GetDC, CharUpperA, GetMenuStringA, GetMenuState, GetSubMenu, GetMenuItemID, GetMenuItemCount, InsertMenuA, AppendMenuA, RemoveMenu, DrawTextA, DrawTextExA, GrayStringA, TabbedTextOutA, GetWindowDC, BeginPaint, EndPaint, ClientToScreen, ScreenToClient, GetSysColor, FillRect, GetWindowTextA, GetWindowTextLengthA, UnhookWindowsHookEx, SendMessageA, EnableWindow, IsWindowEnabled, MessageBoxA, GetWindowLongA, GetParent, GetWindowThreadProcessId, GetLastActivePopup, GetSystemMetrics, GetSysColorBrush, LoadCursorA, CopyRect, InflateRect, IntersectRect, IsWindow, ShowWindow, DrawIcon, UnionRect, UpdateLayeredWindow, MonitorFromPoint, LoadCursorW, DrawEdge, DrawFrameControl, IsZoomed, LoadMenuW, GetSystemMenu, BringWindowToTop, SetCursorPos, FrameRect, MoveWindow, SetWindowPos, GetDlgItem, LoadAcceleratorsA, TranslateAcceleratorA, LoadMenuA, DestroyAcceleratorTable, CopyIcon, InsertMenuItemA, UnpackDDElParam, ReuseDDElParam, GetComboBoxInfo, PostThreadMessageA, WaitMessage, GetKeyboardLayout, IsCharLowerA, MapVirtualKeyExA, GetKeyboardState, ToAsciiEx, LoadAcceleratorsW, CreateAcceleratorTableA, DestroyCursor, GetWindowRgn, CreateMenu, SubtractRect, TranslateMDISysAccel, DefMDIChildProcA, DefFrameProcA, DrawMenuBar, GetUpdateRect, IsClipboardFormatAvailable, CharUpperBuffA, RegisterClipboardFormatA, ModifyMenuA, GetDoubleClickTime, SetMenuDefaultItem, LockWindowUpdate, SetRect, CopyAcceleratorTableA, CallNextHookEx
GDI32.dllDeleteDC, GetObjectW, CreateDIBSection, SelectPalette, GetDeviceCaps, GetStockObject, RealizePalette, CopyMetaFileA, CreateDCA, BitBlt, CreateBitmap, CreateCompatibleDC, CreateHatchBrush, CreatePen, CreatePatternBrush, CreateRectRgn, CreateSolidBrush, Escape, ExcludeClipRect, GetClipBox, GetObjectType, GetPixel, GetViewportExtEx, GetWindowExtEx, IntersectClipRect, LineTo, PtVisible, RectVisible, RestoreDC, SaveDC, SelectClipRgn, ExtSelectClipRgn, SelectObject, SetBkColor, SetBkMode, SetMapMode, SetLayout, GetLayout, SetPolyFillMode, SetROP2, SetStretchBltMode, SetTextColor, SetTextAlign, GetObjectA, MoveToEx, TextOutA, ExtTextOutA, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, OffsetWindowOrgEx, ScaleViewportExtEx, ScaleWindowExtEx, CombineRgn, CreateFontIndirectA, CreateRectRgnIndirect, PatBlt, SetRectRgn, DPtoLP, GetTextExtentPoint32A, GetTextMetricsA, EnumFontFamiliesExA, CreatePalette, GetNearestPaletteIndex, GetPaletteEntries, GetSystemPaletteEntries, GetBkColor, CreateCompatibleBitmap, CreateDIBitmap, EnumFontFamiliesA, GetTextCharsetInfo, SetPixel, StretchBlt, SetDIBColorTable, CreateEllipticRgn, Ellipse, GetTextColor, CreatePolygonRgn, Polygon, Polyline, CreateRoundRectRgn, LPtoDP, Rectangle, GetRgnBox, OffsetRgn, RoundRect, FillRgn, FrameRgn, GetBoundsRect, PtInRegion, ExtFloodFill, SetPaletteEntries, SetPixelV, GetWindowOrgEx, GetViewportOrgEx, PlgBlt, GetTextFaceA, DeleteObject
WINSPOOL.DRVClosePrinter, OpenPrinterA, DocumentPropertiesA
ADVAPI32.dllCryptAcquireContextW, CryptGetHashParam, CryptDestroyHash, CryptHashData, CryptCreateHash, RegCloseKey, RegQueryValueExA, RegSetValueExA, RegEnumKeyExA, RegDeleteValueA, RegOpenKeyExA, RegDeleteKeyA, RegCreateKeyExA, CryptReleaseContext
SHELL32.dllSHGetFileInfoA, ShellExecuteA, SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetDesktopFolder, DragQueryFileA, DragFinish, SHAppBarMessage, SHBrowseForFolderA
ole32.dllIsAccelerator, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleLockRunning, RevokeDragDrop, RegisterDragDrop, CoLockObjectExternal, OleGetClipboard, DoDragDrop, CreateStreamOnHGlobal, CoInitializeEx, CoInitialize, CoUninitialize, CoDisconnectObject, CoCreateInstance, ReleaseStgMedium, OleDuplicateData, CoTaskMemFree, CoTaskMemAlloc
OLEAUT32.dllVariantClear, VariantTimeToSystemTime, SystemTimeToVariantTime, SysStringLen, SysAllocStringLen, SysAllocStringByteLen, SysFreeString, LoadTypeLib, VariantInit, SysAllocString, VariantCopy, VariantChangeType, VarBstrFromDate
lvgl.dlllv_tileview_set_anim_time, lv_disp_get_default, lv_indev_get_obj_act, lv_obj_del, lv_indev_reset, lv_disp_get_hor_res, lv_tick_elaps, lv_disp_get_buf, lv_disp_is_true_double_buf, lv_tileview_add_element, lv_obj_invalidate, _lv_memcpy, lv_tileview_set_tile_act_by_index, lv_obj_set_pos, lv_obj_set_x, lv_refr_vdb_flush, lv_disp_flush_ready, lv_obj_set_y, lv_img_set_src, lv_tick_get, _lv_obj_set_style_local_opa, lv_obj_set_size, lv_mem_alloc, lv_mem_free, lv_arc_set_start_angle, lv_arc_set_end_angle, lv_arc_get_angle_start, lv_arc_get_angle_end, lv_label_create, lv_obj_get_parent, lv_label_get_text, lv_bar_set_anim_time, lv_bar_get_min_value, lv_bar_get_value, lv_bar_set_value, lv_bar_get_max_value, lv_bar_get_anim_time, lv_bar_set_range, lv_btn_get_state, lv_checkbox_set_checked, lv_dropdown_close, lv_dropdown_clear_options, lv_dropdown_add_option, lv_dropdown_open, lv_dropdown_get_selected, lv_obj_is_visible, lv_dropdown_get_selected_str, lv_dropdown_set_selected, lv_img_get_zoom, lv_img_get_angle, lv_img_set_zoom, lv_img_set_angle, lv_img_get_auto_size, lv_img_get_src, lv_img_set_auto_size, lv_btn_get_checkable, lv_imgbtn_set_state, lv_tileview_get_tile_act, _lv_obj_get_style_color, lv_label_get_long_mode, lv_label_ins_text, lv_label_set_text_fmt, lv_label_set_long_mode, lv_list_get_btn_selected, lv_list_clean, lv_list_get_btn_text, lv_list_get_btn_index, lv_list_focus_btn, lv_list_add_btn, lv_roller_get_selected, lv_roller_set_selected, lv_roller_get_selected_str, lv_slider_get_value, lv_switch_off, lv_switch_on, lv_textarea_add_text, lv_textarea_del_char, lv_textarea_set_text, lv_textarea_get_text, _lv_obj_get_style_int, lv_obj_get_width, lv_obj_set_width, lv_obj_get_x, lv_obj_set_height, _lv_obj_get_style_opa, lv_obj_get_height, lv_obj_get_y, lv_disp_drv_init, lv_deinit, lv_init, lv_disp_drv_register, lv_disp_buf_init, lv_split_jpeg_init, lv_anim_del_all, _lv_disp_buf_projection_first, _lv_area_intersect, lv_draw_label, lv_area_set_height, lv_draw_rect_dsc_init, _lv_memset, _lv_mem_buf_get, lv_draw_label_dsc_init, lv_img_cf_is_chroma_keyed, lv_draw_mask_apply, lv_draw_rect, lv_img_cf_has_alpha, _lv_img_buf_get_transformed_area, _lv_mem_buf_release, lv_draw_mask_get_cnt, lv_area_get_size, lv_img_decoder_read_line, lv_img_cf_get_px_size, _lv_trigo_sin, lv_obj_init_draw_label_dsc, _lv_obj_get_style_ptr, lv_tileview_set_tile_act, lv_img_decoder_get_info, lv_theme_apply, lv_obj_handle_get_type_signal, lv_obj_get_coords, lv_obj_get_signal_cb, lv_obj_refresh_style, lv_draw_mask_radius_init, lv_obj_is_point_on_coords, lv_obj_init_draw_img_dsc, lv_draw_mask_remove_custom, lv_obj_set_signal_cb, lv_img_src_get_type, lv_obj_set_adv_hittest, lv_draw_mask_add, lv_obj_set_design_cb, lv_obj_get_ext_attr, _lv_area_is_point_on, lv_obj_init_draw_rect_dsc, lv_obj_allocate_ext_attr, lv_obj_refresh_ext_draw_pad, _lv_txt_get_size, _lv_area_is_in, _lv_txt_get_width, lv_obj_get_design_cb, lv_btn_create, lv_task_set_period, lv_fs_write, lv_fs_trunc, lv_line_set_points, _lv_style_set_color, lv_obj_add_style, lv_line_create, lv_label_set_align, lv_obj_align, _lv_style_set_int, lv_style_init, lv_style_reset, lv_canvas_draw_line, lv_draw_line_dsc_init, lv_indev_grab, lv_task_reset, lv_arc_set_bg_angles, lv_arc_set_adjustable, lv_arc_set_rotation, lv_arc_create, lv_arc_set_angles, lv_arc_set_type, lv_obj_set_gesture_parent, lv_obj_get_hidden, lv_cont_set_layout, lv_obj_get_child_back, lv_obj_set_custom_view_data, lv_obj_get_custom_view_data, lv_obj_clean, lv_cont_set_fit4, lv_cont_create, _lv_style_set_opa, lv_bar_create, lv_btn_set_checkable, lv_canvas_set_buffer, lv_canvas_create, lv_indev_get_point, lv_canvas_fill_bg, lv_chart_add_series, lv_chart_set_next, lv_chart_set_y_tick_texts, lv_chart_set_y_range, lv_chart_set_div_line_count, lv_chart_set_update_mode, lv_chart_set_point_count, lv_chart_set_x_tick_texts, lv_chart_set_type, lv_chart_create, lv_checkbox_set_text, _lv_style_set_ptr, lv_checkbox_create, lv_img_set_pivot, lv_dropdown_set_options, lv_dropdown_set_max_height, lv_dropdown_create, lv_imgbtn_set_src, lv_imgbtn_set_recolor_opa, lv_imgbtn_set_recolor, lv_tileview_set_remap_mode, lv_obj_set_gesture_parent_dir, lv_obj_set_drag, lv_tileview_set_ramap_range, lv_label_refr_text, lv_anim_del, lv_obj_invalidate_area, lv_anim_init, lv_anim_start, _lv_style_list_add_style, lv_list_get_btn_label, lv_obj_get_style_list, lv_list_create, lv_roller_set_visible_row_count, lv_roller_set_options, lv_roller_set_align, lv_roller_create, lv_roller_set_auto_fit, lv_slider_create, lv_switch_create, lv_textarea_set_pwd_mode, lv_keyboard_set_cursor_manage, lv_obj_get_screen, lv_textarea_get_cursor_hidden, lv_keyboard_def_event_cb, lv_textarea_get_label, lv_keyboard_set_mode, lv_keyboard_set_textarea, lv_disp_get_layer_sys, lv_textarea_set_placeholder_text, lv_obj_get_event_cb, lv_keyboard_create, lv_textarea_create, lv_textarea_set_cursor_hidden, lv_obj_set_state, lv_indev_drv_init, lv_task_enable, lv_indev_drv_register, lv_mem_monitor, lv_anim_get, lv_event_get_data, lv_obj_create, lv_tileview_create, lv_disp_get_ver_res, lv_tileview_set_valid_positions, lv_draw_img_dsc_init, lv_task_del, lv_img_create, lv_page_set_edge_flash, _lv_mem_get_base, lv_indev_wait_release, lv_obj_set_event_cb, lv_page_get_scrollable, _lv_refr_get_disp_refreshing, lv_event_send, lv_disp_get_rotation, lv_indev_get_type, lv_indev_get_act, _lv_obj_set_event_cb_interceptor, lv_indev_get_gesture_dir, lv_list_get_next_btn, lv_img_decoder_close, lv_img_decoder_open, lv_img_decoder_uncompress, lv_task_handler, lv_refr_now, lv_disp_load_scr, lv_disp_get_scr_act, lv_task_create, lv_fs_tell, lv_fs_seek, lv_font_load, lv_font_free, lv_font_load_from_opened_file, lv_fs_open, lv_fs_close, lv_fs_read, _lv_mem_get_size, lv_obj_set_hidden, lv_label_set_text, lv_obj_get_type, _lv_obj_set_style_local_ptr, lv_obj_get_child, _lv_obj_set_style_local_color, _lv_obj_set_style_local_int, lv_obj_set_click, lv_canvas_draw_img
MSIMG32.dllTransparentBlt, AlphaBlend
COMCTL32.dllImageList_AddMasked, ImageList_Create, ImageList_Replace
SHLWAPI.dllPathFindExtensionA, StrFormatKBSizeA, PathIsUNCA, PathFindFileNameA, PathStripToRootA, PathRemoveFileSpecW, PathFindExtensionW
UxTheme.dllIsThemeBackgroundPartiallyTransparent, GetThemePartSize, GetThemeSysColor, IsAppThemed, GetWindowTheme, GetCurrentThemeName, DrawThemeText, DrawThemeParentBackground, OpenThemeData, CloseThemeData, DrawThemeBackground, GetThemeColor
gdiplus.dllGdipCreateBitmapFromHBITMAP, GdipAlloc, GdipCloneImage, GdipGetImageEncoders, GdiplusStartup, GdipGetImageGraphicsContext, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipFree, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipDeleteGraphics, GdipDrawImageI, GdipCreateFromHDC, GdipSetInterpolationMode, GdipDrawImageRectI, GdipDisposeImage, GdipGetImageEncodersSize, GdiplusShutdown, GdipSaveImageToFile, GdipGetImagePalette, GdipCreateBitmapFromScan0, GdipCreateBitmapFromStream, GdipGetImagePaletteSize
OLEACC.dllLresultFromObject, AccessibleObjectFromWindow, CreateStdAccessibleObject
IMM32.dllImmReleaseContext, ImmGetOpenStatus, ImmGetContext
WINMM.dllwaveOutOpen, waveOutWrite, waveOutReset, waveOutClose, waveOutPrepareHeader, PlaySoundA
COMDLG32.dllGetSaveFileNameW
NameOrdinalAddress
?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@Z10x10039be0
?gb_get_widget_image_with_alpha@@YAHPAXAAVCImage@ATL@@_N@Z20x10039bb0
UG_ArcCreate30x100535b0
UG_ArcGetProgress40x100538a0
UG_ArcGetProgressMax50x100538c0
UG_ArcGetProgressMin60x100538b0
UG_ArcSetBackAngle70x10053790
UG_ArcSetBackColor80x10053730
UG_ArcSetBackOpa90x100538d0
UG_ArcSetClockwise100x100537d0
UG_ArcSetColor110x100536f0
UG_ArcSetEndAngle120x10053770
UG_ArcSetGradColor130x10053710
UG_ArcSetProgress140x10053870
UG_ArcSetProgressMax150x10053840
UG_ArcSetProgressMin160x10053810
UG_ArcSetRadius170x100538f0
UG_ArcSetRotation180x100537f0
UG_ArcSetStartAngle190x10053750
UG_ArcSetStrokeWidth200x100536d0
UG_BarCreate210x10054410
UG_BarGetValMax220x100538a0
UG_BarGetValMin230x100538c0
UG_BarGetValue240x100538b0
UG_BarSetBackColor250x10054720
UG_BarSetBorderColor260x10054740
UG_BarSetBorderWidth270x10054760
UG_BarSetIndicColor280x100536f0
UG_BarSetIndicGradColor290x10053710
UG_BarSetValMax300x100546e0
UG_BarSetValMin310x100546a0
UG_BarSetValue320x100544f0
UG_ButtonCreate330x10052160
UG_ButtonGetAlignment340x10052510
UG_ButtonGetAlternateBackColor350x10052450
UG_ButtonGetAlternateForeColor360x10052430
UG_ButtonGetBackColor370x10052410
UG_ButtonGetFont380x10052490
UG_ButtonGetForeColor390x100523f0
UG_ButtonGetHSpace400x100524d0
UG_ButtonGetStyle410x100524b0
UG_ButtonGetText420x10052470
UG_ButtonGetVSpace430x100524f0
UG_ButtonSetAlignment440x100523d0
UG_ButtonSetAlternateBackColor450x100522c0
UG_ButtonSetAlternateForeColor460x100522a0
UG_ButtonSetBackColor470x10052280
UG_ButtonSetFont480x10052300
UG_ButtonSetForeColor490x10052260
UG_ButtonSetHSpace500x10052390
UG_ButtonSetStyle510x10052320
UG_ButtonSetText520x100522e0
UG_ButtonSetVSpace530x100523b0
UG_CheckboxCreate540x10052790
UG_CheckboxGetAlignment550x10052510
UG_CheckboxGetAlternateBackColor560x10052450
UG_CheckboxGetAlternateForeColor570x10052430
UG_CheckboxGetBackColor580x10052410
UG_CheckboxGetChecked590x100528c0
UG_CheckboxGetFont600x10052490
UG_CheckboxGetForeColor610x100523f0
UG_CheckboxGetHSpace620x100524d0
UG_CheckboxGetStyle630x100524b0
UG_CheckboxGetText640x10052470
UG_CheckboxGetVSpace650x100524f0
UG_CheckboxSetAlignment660x100523d0
UG_CheckboxSetAlternateBackColor670x100522c0
UG_CheckboxSetAlternateForeColor680x100522a0
UG_CheckboxSetBackColor690x10052280
UG_CheckboxSetCheched700x100528a0
UG_CheckboxSetFont710x10052300
UG_CheckboxSetForeColor720x10052260
UG_CheckboxSetHSpace730x10052390
UG_CheckboxSetStyle740x10052320
UG_CheckboxSetText750x100522e0
UG_CheckboxSetVSpace760x100523b0
UG_Deinit770x1004fa60
UG_DrawArc780x100505d0
UG_DrawBMP790x10051690
UG_DrawCircle800x10050180
UG_DrawFrame810x1004ffd0
UG_DrawLine820x10050930
UG_DrawMesh830x1004fed0
UG_DrawPixel840x10050130
UG_DrawRoundFrame850x10050020
UG_DriverDisable860x10051450
UG_DriverEnable870x10051420
UG_DriverRegister880x100513f0
UG_FONT_MONTSERRAT_10890x1027e9bc
UG_FillCircle900x10050470
UG_FillFrame910x1004fb30
UG_FillRoundFrame920x1004fd10
UG_FillScreen930x1004fb00
UG_FindObject940x10051170
UG_FontGetHSpace950x10050e20
UG_FontGetVSpace960x10050e30
UG_FontSelect970x1004fad0
UG_FontSetHSpace980x10050e00
UG_FontSetVSpace990x10050e10
UG_GetGUI1000x1004fac0
UG_GetXDim1010x10050de0
UG_GetYDim1020x10050df0
UG_ImageCreate1030x10055130
UG_ImageSetBMP1040x10055200
UG_ImageSetRecolor1050x10055230
UG_Init1060x1004f8f0
UG_LabelCreate1070x10055ba0
UG_LabelGetAlignment1080x10055f60
UG_LabelGetBackColor1090x10055ea0
UG_LabelGetBackOpa1100x10055ec0
UG_LabelGetFont1110x10055f00
UG_LabelGetForeColor1120x10055e80
UG_LabelGetHSpace1130x10055f20
UG_LabelGetText1140x10055ee0
UG_LabelGetVSpace1150x10055f40
UG_LabelSetAlignment1160x10055e40
UG_LabelSetBackColor1170x10055cb0
UG_LabelSetBackGradColor1180x10055cd0
UG_LabelSetBackGradDir1190x10055cf0
UG_LabelSetBackOpa1200x10055d10
UG_LabelSetFont1210x10055de0
UG_LabelSetForeColor1220x10055c90
UG_LabelSetHSpace1230x10055e00
UG_LabelSetLongMode1240x10055e60
UG_LabelSetText1250x10055d30
UG_LabelSetTextStatic1260x10055db0
UG_LabelSetVSpace1270x10055e20
UG_LevelImgCreate1280x10056e90
UG_LevelImgGetLevel1290x10056ff0
UG_LevelImgGetLevelNum1300x10056fe0
UG_LevelImgSetAnimReadyCb1310x100570c0
UG_LevelImgSetLevel1320x10056f40
UG_LevelImgSetRecolor1330x10055230
UG_LevelImgStartAutoAnim1340x10057000
UG_LevelImgStopAutoAnim1350x10056cf0
UG_MeasureString1360x10050cd0
UG_ObjectDelete1370x100511b0
UG_ObjectGetRelX1380x10052090
UG_ObjectGetRelY1390x100520a0
UG_ObjectHide1400x10051f40
UG_ObjectIsVisible1410x10052080
UG_ObjectSetPos1420x100520b0
UG_ObjectShow1430x10051ff0
UG_PutString1440x10050c00
UG_SelectGUI1450x1004faa0
UG_TickGet1460x10051680
UG_TickInc1470x10051670
UG_TimerCreate1480x1004e970
UG_TimerDelete1490x1004e9e0
UG_TimerSetPeriod1500x1004ea20
UG_TimerStart1510x1004ea40
UG_TimerStop1520x1004ea50
UG_TouchUpdate1530x100517a0
UG_Update1540x10051480
UG_WaitForUpdate1550x10051660
UG_WindowCreate1560x10051830
UG_WindowDelete1570x100518d0
UG_WindowGetArea1580x10051e60
UG_WindowGetBackColor1590x10051da0
UG_WindowGetForeColor1600x10051d80
UG_WindowGetStyle1610x10051e40
UG_WindowGetXEnd1620x10051e00
UG_WindowGetXStart1630x10051dc0
UG_WindowGetYEnd1640x10051e20
UG_WindowGetYStart1650x10051de0
UG_WindowHide1660x100519e0
UG_WindowResize1670x10051a70
UG_WindowSetBackColor1680x10051c10
UG_WindowSetForeColor1690x10051be0
UG_WindowSetStyle1700x10051d40
UG_WindowSetXEnd1710x10051cc0
UG_WindowSetXStart1720x10051c40
UG_WindowSetYEnd1730x10051d00
UG_WindowSetYStart1740x10051c80
UG_WindowShow1750x10051940
_UG_AttachObject1760x10051130
_UG_FreeObject1770x10051820
_UG_NewObject1780x100517d0
_UG_ObjectApplyId1790x100510d0
_UG_ObjectDefRequire1800x10051100
_framework_app_ezoc_obj1810x102c689c
_framework_arc_ezoc_obj1820x102c68a8
_framework_artchar_ezoc_obj1830x102c68ac
_framework_avi_ezoc_obj1840x102c68b0
_framework_bar_ezoc_obj1850x102c68b4
_framework_button_ezoc_obj1860x102c68b8
_framework_canvas_ezoc_obj1870x102c68bc
_framework_chart_ezoc_obj1880x102c68c0
_framework_checkbox_ezoc_obj1890x102c68c4
_framework_clock_ezoc_obj1900x102c68c8
_framework_dropdown_ezoc_obj1910x102c68cc
_framework_image_btn_ezoc_obj1920x102c68d4
_framework_image_ezoc_obj1930x102c68d0
_framework_imgroller_ezoc_obj1940x102c68d8
_framework_label_ezoc_obj1950x102c68dc
_framework_levelimg_ezoc_obj1960x102c68e0
_framework_list_ezoc_obj1970x102c68e4
_framework_roller_ezoc_obj1980x102c68e8
_framework_screen_ezoc_obj1990x102c68ec
_framework_slider_ezoc_obj2000x102c68f0
_framework_switch_ezoc_obj2010x102c68f4
_framework_textarea_ezoc_obj2020x102c68f8
_framework_timer_ezoc_obj2030x102c68fc
_framework_touch_ezoc_obj2040x102c6900
_framework_ui_ezoc_obj2050x102c68a0
_framework_var_ezoc_obj2060x102c68a4
_framework_widget_ezoc_obj2070x102c6904
_synwit_sdcmd_add2080x10003c80
_synwit_ug_set_screen_map2090x1004f260
_synwit_ug_set_widget_map2100x1004f280
_ug_app_screen_register2110x10001c50
_ug_mem_get_size2120x1004b8c0
_ug_widget_register2130x1004b990
action_back_register2140x10001f80
action_execute_register2150x10002260
action_goto_screen_register2160x10003210
action_pause_avi_register2170x10002390
action_play_avi_register2180x10002440
action_replay_avi_register2190x100024f0
action_set_bg_color_register2200x100026e0
action_set_font_by_name_register2210x10002970
action_set_text_color_register2220x10002da0
action_set_text_register2230x10002b40
action_set_text_with_color_and_font_register2240x10003560
action_set_visibility_register2250x10003690
action_slide_to_screen_register2260x10003ae0
action_stop_avi_register2270x10003b90
app_register_screens2280x10044bd0
cls_arc_naming2290x10058200
cls_arc_register2300x100581e0
cls_artchar_naming2310x10058f60
cls_artchar_register2320x10058f40
cls_avi_naming2330x1005a170
cls_avi_register2340x1005a150
cls_bar_naming2350x1005bc70
cls_bar_register2360x1005bc50
cls_button_naming2370x1005c740
cls_button_register2380x1005c720
cls_canvas_naming2390x1005db70
cls_canvas_register2400x1005db50
cls_chart_naming2410x1005e230
cls_chart_register2420x1005e210
cls_checkbox_naming2430x1005f340
cls_checkbox_register2440x1005f320
cls_clock_naming2450x10060160
cls_clock_register2460x10060140
cls_dropdown_naming2470x100614c0
cls_dropdown_register2480x100614a0
cls_image_btn_naming2490x10062e70
cls_image_btn_register2500x10062e50
cls_image_naming2510x100625c0
cls_image_register2520x100625a0
cls_imgroller_naming2530x10063cc0
cls_imgroller_register2540x10063ca0
cls_label_naming2550x100649c0
cls_label_register2560x100649a0
cls_levelimg_naming2570x10065680
cls_levelimg_register2580x10065660
cls_list_naming2590x100674d0
cls_list_register2600x100674b0
cls_roller_naming2610x10068820
cls_roller_register2620x10068800
cls_screen_naming2630x10069720
cls_screen_register2640x10069700
cls_slider_naming2650x10069cd0
cls_slider_register2660x10069cb0
cls_switch_naming2670x1006a9b0
cls_switch_register2680x1006a990
cls_textarea_naming2690x1006b400
cls_textarea_register2700x1006b3e0
cls_timer_naming2710x1006ce20
cls_timer_register2720x1006ce00
cls_touch_naming2730x1006d250
cls_touch_register2740x1006d230
cls_ug_arc_naming2750x10052e20
cls_ug_arc_register2760x10052e00
cls_ug_bar_naming2770x10053af0
cls_ug_bar_register2780x10053ad0
cls_ug_image_naming2790x10054910
cls_ug_image_register2800x100548f0
cls_ug_label_naming2810x10055350
cls_ug_label_register2820x10055330
cls_ug_levelimg_naming2830x10056180
cls_ug_levelimg_register2840x10056160
cls_ug_screen_naming2850x10057100
cls_ug_screen_register2860x100570e0
cls_widget_naming2870x1006d490
cls_widget_register2880x1006d470
ezoc_interpreter2890x102c6898
ezoc_label_helper_create_private_data2900x10031710
ezoc_label_helper_get2910x10031810
ezoc_label_helper_release_private_data2920x10031750
ezoc_label_helper_set2930x10031ac0
gb_deinit2940x10035000
gb_export2950x10034d60
gb_export_ui_dsc2960x10035d00
gb_font_del_by_name2970x10007a80
gb_font_import2980x100079f0
gb_font_set_flag2990x10007a10
gb_ftconv3000x10034c30
gb_ftconv_with_progress3010x100344e0
gb_get_avi_info3020x1005a9b0
gb_get_font_alias3030x10008270
gb_get_gui_platform3040x10035310
gb_get_image_size3050x10020630
gb_get_virtual_render_buffer3060x10035330
gb_image_conv3070x10020730
gb_init3080x10035340
gb_init_widget_id_allocator3090x1006e7b0
gb_prop_transaction_begin3100x1006e7f0
gb_prop_transaction_commit3110x1006e850
gb_reaction_del3120x1006e150
gb_reaction_set_action3130x1006dfb0
gb_serial_display_next_frame3140x100227e0
gb_serial_display_send3150x10022960
gb_serial_display_server_start3160x10022500
gb_serial_display_server_stop3170x10022a60
gb_set_entry_screen3180x1006e2a0
gb_set_gui_platform3190x10035320
gb_take_snapshot3200x10039e50
gb_widget_add_reaction3210x1006df40
gb_widget_adj_layer3220x1006e2d0
gb_widget_clear_image_list3230x1006e380
gb_widget_create3240x1006dc70
gb_widget_del3250x1006e910
gb_widget_get_class_name3260x1006e720
gb_widget_get_id3270x10043040
gb_widget_set_id3280x1006e770
gb_widget_set_property3290x1006de60
gb_widget_switch_part3300x1006e230
gb_widget_switch_state3310x1006e1a0
gps_tracker_clear_tags3320x100580d0
gps_tracker_colorize_line3330x10058180
gps_tracker_create3340x10057e60
gps_tracker_del3350x100581a0
gps_tracker_feed3360x10058050
gps_tracker_get_view_range3370x10058030
gps_tracker_set_line_width3380x10058160
gps_tracker_set_origin3390x10057f70
gps_tracker_set_spin_transition3400x10058130
gps_tracker_set_view_range3410x10057fb0
gps_tracker_tag3420x10058090
lv_artchar_get_text3430x10059b50
lv_artchar_set_text3440x10059b00
lv_avi_create3450x1005bb40
lv_avi_del3460x1005bba0
lv_avi_enable_audio_output3470x1005b8c0
lv_avi_forward3480x1005ba90
lv_avi_get_cur_frame_index3490x1005b800
lv_avi_get_state3500x1005b790
lv_avi_get_total_frame3510x1005b7d0
lv_avi_get_volume3520x1005ba40
lv_avi_get_wav_duration3530x1005b830
lv_avi_get_wav_elapsed3540x1005b860
lv_avi_pause3550x1005b6e0
lv_avi_play3560x1005b430
lv_avi_replay3570x1005b750
lv_avi_set_on_completed_cb3580x1005b400
lv_avi_set_progress_bar3590x1005b8a0
lv_avi_set_repeat_count3600x1005b770
lv_avi_set_src3610x1005b280
lv_avi_set_stop_style3620x1005b7b0
lv_avi_set_volume3630x1005b9c0
lv_avi_stop3640x1005a370
lv_canvas_clear3650x1005e1e0
lv_canvas_draw_line_by_brush3660x1005e140
lv_canvas_set_brush_color3670x1005e180
lv_canvas_set_brush_width3680x1005e1b0
lv_clock_set_time3690x10061310
lv_clock_set_time_string3700x10061370
lv_clock_start_auto_anim3710x10061470
lv_clock_stop_auto_anim3720x100608f0
lv_imgex_create3730x10062d00
lv_imgex_set_src3740x10062d10
lv_levelimg_get_anim_end_level3750x10067480
lv_levelimg_get_anim_start_level3760x10067450
lv_levelimg_get_interval3770x10067390
lv_levelimg_get_level3780x100670e0
lv_levelimg_get_level_num3790x10067110
lv_levelimg_get_positive_order3800x100673f0
lv_levelimg_get_repeat_count3810x100673c0
lv_levelimg_get_reverse_order3820x10067420
lv_levelimg_set_anim_range3830x100671c0
lv_levelimg_set_frame_interval3840x100672b0
lv_levelimg_set_level3850x100663c0
lv_levelimg_set_playtime3860x10067230
lv_levelimg_set_ready_cb3870x10067360
lv_levelimg_start_auto_anim3880x10067190
lv_levelimg_stop_auto_anim3890x10067140
lv_list_decorate_btn3900x10068190
lv_textarea_set_on_kb_create_cb3910x1006cdd0
lv_timer_get_period3920x1006d180
lv_timer_get_repeat3930x1006d1b0
lv_timer_get_tick3940x1006d200
lv_timer_set_period3950x1006d110
lv_timer_set_repeat3960x1006d150
lv_timer_set_tick3970x1006d1e0
lv_timer_start3980x1006d070
lv_timer_stop3990x1006d0d0
lv_win32_set_toolbar_icons4000x100d2c60
lv_win32_update_memory_info4010x100d32a0
path_utf8_to_local4020x10043870
render_invalidate_area4030x1004bfb0
synwit_ezoc_add_ops4040x10005a20
synwit_ezoc_remove_ops4050x10005c10
synwit_ezoc_run4060x10005d30
synwit_sdcmd_end4070x10003dd0
synwit_sdcmd_getter_begin4080x10003c60
synwit_sdcmd_run4090x10021f10
synwit_sdcmd_setter_begin4100x10003c40
synwit_ug_get_cur_screen_id4110x1004f140
synwit_ug_get_cur_window4120x1004f150
synwit_ug_get_platform_version_name4130x10025cc0
synwit_ug_load_screen4140x1004eb30
synwit_ug_reset_glyph_cache4150x1004b570
synwit_ug_start4160x1004f2a0
synwit_ug_start_scr_timer4170x1004f160
synwit_ug_stop_scr_timer4180x1004f220
synwit_ui_find_lv_obj4190x10025890
synwit_ui_find_lv_obj_by_name4200x100258c0
synwit_ui_font_get4210x10008340
synwit_ui_font_load4220x10008360
synwit_ui_font_unload4230x100083d0
synwit_ui_get_cur_screen_id4240x10025ca0
synwit_ui_get_platform_version_name4250x10025cc0
synwit_ui_get_screen_id_by_name4260x100258e0
synwit_ui_init_load_scr_dsc4270x10025960
synwit_ui_load_image_file4280x100208e0
synwit_ui_load_screen4290x10025bd0
synwit_ui_load_screen_with_dsc4300x10025980
synwit_ui_pref_close4310x10042c50
synwit_ui_pref_get_int4320x10042de0
synwit_ui_pref_get_key_by_idx4330x10043020
synwit_ui_pref_get_num4340x10043040
synwit_ui_pref_get_string4350x10042e30
synwit_ui_pref_get_value_by_idx4360x10042ff0
synwit_ui_pref_open4370x10042c30
synwit_ui_pref_remove4380x10042f20
synwit_ui_pref_save4390x10042c60
synwit_ui_pref_set_int4400x10042ea0
synwit_ui_pref_set_string4410x10042e80
synwit_ui_reg_screen4420x10025d00
synwit_ui_start4430x10008410
synwit_ui_start_scr_timer4440x10025c30
synwit_ui_stop_scr_timer4450x10025c70
synwit_ui_transition_screen4460x10025bf0
synwit_ui_unload_image4470x10020c30
synwit_ui_use_interpreter4480x10001fe0
synwit_wav_close4490x100420f0
synwit_wav_open4500x10042040
synwit_wav_pause4510x10042450
synwit_wav_play4520x10042350
synwit_wav_play_sync4530x10042140
synwit_wav_set_on_completed_cb4540x10042480
synwit_wav_stop4550x100423e0
te_compile4560x1002f510
te_eval4570x1002f040
te_free4580x1002e280
te_interp4590x1002f5f0
te_print4600x1002f790
ug_mem_alloc4610x1004b5e0
ug_mem_deinit4620x1004b5c0
ug_mem_free4630x1004b700
ug_mem_init4640x1004b590
ug_mem_monitor4650x1004b8e0
ug_mem_realloc4660x1004b810
ugui031_get_summary_of_screens4670x1004e750
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:1
Start time:13:54:23
Start date:29/10/2024
Path:C:\Windows\System32\loaddll32.exe
Wow64 process (32bit):true
Commandline:loaddll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll"
Imagebase:0xfc0000
File size:126'464 bytes
MD5 hash:51E6071F9CBA48E79F10C84515AAE618
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:2
Start time:13:54:23
Start date:29/10/2024
Path:C:\Windows\System32\conhost.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Imagebase:0x7ff720030000
File size:873'472 bytes
MD5 hash:7366FBEFE66BA0F1F5304F7D6FEF09FE
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:true

Target ID:3
Start time:13:54:24
Start date:29/10/2024
Path:C:\Windows\SysWOW64\cmd.exe
Wow64 process (32bit):true
Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1
Imagebase:0xb80000
File size:236'544 bytes
MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:4
Start time:13:54:24
Start date:29/10/2024
Path:C:\Windows\SysWOW64\rundll32.exe
Wow64 process (32bit):true
Commandline:rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_FB2CImage@@YAHPAXHHAAVCImage@ATL@@_N@Z
Imagebase:0x8a0000
File size:61'440 bytes
MD5 hash:889B99C52A60DD49227C5E485A016679
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:5
Start time:13:54:24
Start date:29/10/2024
Path:C:\Windows\SysWOW64\rundll32.exe
Wow64 process (32bit):true
Commandline:rundll32.exe "C:\Users\user\Desktop\Jr2YluqEVG.dll",#1
Imagebase:0x8a0000
File size:61'440 bytes
MD5 hash:889B99C52A60DD49227C5E485A016679
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:6
Start time:13:54:27
Start date:29/10/2024
Path:C:\Windows\SysWOW64\rundll32.exe
Wow64 process (32bit):true
Commandline:rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,?gb_get_widget_image_with_alpha@@YAHPAXAAVCImage@ATL@@_N@Z
Imagebase:0x8a0000
File size:61'440 bytes
MD5 hash:889B99C52A60DD49227C5E485A016679
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:7
Start time:13:54:30
Start date:29/10/2024
Path:C:\Windows\SysWOW64\rundll32.exe
Wow64 process (32bit):true
Commandline:rundll32.exe C:\Users\user\Desktop\Jr2YluqEVG.dll,UG_ArcCreate
Imagebase:0x8a0000
File size:61'440 bytes
MD5 hash:889B99C52A60DD49227C5E485A016679
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

No disassembly