Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ##################################################################################################
- # Here's your proof at the moment. Enigma removed, netseal is next... http://prntscr.com/6dr5nc #
- ##################################################################################################
- Used enigma 3.7 with a private key and a private obfuscator "Alcatraz Security".
- **************************************************
- * Fix -> #GUID and System.outofboundsException
- * DEOB/Encrypt -> alcatraz encryption (used
- ** or **
- * bypass netseal via Olly
- **************************************************
- ##################################################################################################
- [!] Enigma Protector v3.70 Build 2015/02/19 21:04:32 detected !
- [!] Protected with a Personal license (1)
- ------------------------------------------------------[03/07/15] 1:31AM
- ModuleEntryPoint - 00A397F8
- MOV EDX, 94E7CF43
- CCAPI Not in dir check - 7588BFBC
- 00A39C16 ^E9 C8FFFFFF JMP LastTeam.00A39BE3
- ------------------------------------------------------[03/07/15] 3:19AM
- [Results of File Scan]
- File Name: C:\Users\BaSs_HaXoR\Desktop\LTS_V20\MODIFYING\x\LastTeamStanding - Tool v2.0_dump2_patched.exe
- Number of Matching Signatures: 1
- Deep Scan: Yes
- Best Match: Microsoft Visual Studio .NET
- All Matches:
- Signature: Microsoft Visual Studio .NET - Matches: 40
- 7588BFBC C3 RETN = START
- 7726C93C C2 0800 RETN 8 = QUIT
- 75887390 C745 C0 94758875 MOV DWORD PTR SS:[EBP-40],USER32.7588759>; ASCII "DefWindowProcA"
- 75887397 C745 C4 A4758875 MOV DWORD PTR SS:[EBP-3C],USER32.758875A>; ASCII "NTDLL.NtdllDefWindowProc_A"
- 7588739E C745 C8 A0038875 MOV DWORD PTR SS:[EBP-38],USER32.758803A>
- 758873A5 C745 D4 C0758875 MOV DWORD PTR SS:[EBP-2C],USER32.758875C>; ASCII "DefDlgProcW"
- 758873AC C745 D8 CC758875 MOV DWORD PTR SS:[EBP-28],USER32.758875C>; ASCII "NTDLL.NtdllDialogWndProc_W"
- 758873B3 C745 DC D0F48875 MOV DWORD PTR SS:[EBP-24],USER32.7588F4D>
- 758873BA C745 E8 E8758875 MOV DWORD PTR SS:[EBP-18],USER32.758875E>; ASCII "DefDlgProcA"
- 758873C1 C745 EC F4758875 MOV DWORD PTR SS:[EBP-14],USER32.758875F>; ASCII "NTDLL.NtdllDialogWndProc_A"
- 758873C8 C745 F0 E0298A75 MOV DWORD PTR SS:[EBP-10],USER32.758A29E>
- --------------------------
- v4.0.30319
- cmt 6F42AC,"EP_CheckUpStartupPasswordHashString"
- bp 6F42AC
- cmt 6F42FC,"EP_CheckupCopies"
- bp 6F42FC
- cmt 6F430C,"EP_CheckupCopiesCurrent"
- bp 6F430C
- cmt 6F4304,"EP_CheckupCopiesTotal"
- bp 6F4304
- cmt 6F4364,"EP_CheckupFindProcess"
- bp 6F4364
- cmt 6F4364,"EP_CheckupFindProcessA"
- bp 6F4364
- cmt 6F436C,"EP_CheckupFindProcessW"
- bp 6F436C
- cmt 6F431C,"EP_CheckupIsEnigmaOk"
- bp 6F431C
- cmt 6F4314,"EP_CheckupIsProtected"
- bp 6F4314
- cmt 6F4324,"EP_CheckupVirtualizationTools"
- bp 6F4324
- cmt 6F4344,"EP_CryptDecryptBuffer"
- bp 6F4344
- cmt 6F434C,"EP_CryptDecryptBufferEx"
- bp 6F434C
- cmt 6F4334,"EP_CryptEncryptBuffer"
- bp 6F4334
- cmt 6F433C,"EP_CryptEncryptBufferEx"
- bp 6F433C
- cmt 6F42D4,"EP_CryptHashBuffer"
- bp 6F42D4
- cmt 6F42DC,"EP_CryptHashFileA"
- bp 6F42DC
- cmt 6F42E4,"EP_CryptHashFileW"
- bp 6F42E4
- cmt 6F42EC,"EP_CryptHashStringA"
- bp 6F42EC
- cmt 6F42F4,"EP_CryptHashStringW"
- bp 6F42F4
- cmt 6F432C,"EP_EnigmaVersion"
- bp 6F432C
- cmt 6F42BC,"EP_MiscCountryCode"
- bp 6F42BC
- cmt 6F42B4,"EP_MiscGetWatermark"
- bp 6F42B4
- cmt 6F42C4,"EP_ProtectedStringByID"
- bp 6F42C4
- cmt 6F42CC,"EP_ProtectedStringByKey"
- bp 6F42CC
- cmt 6F415C,"EP_RegCheckAndSaveKey"
- bp 6F415C
- cmt 6F4164,"EP_RegCheckAndSaveKeyA"
- bp 6F4164
- cmt 6F416C,"EP_RegCheckAndSaveKeyW"
- bp 6F416C
- cmt 6F410C,"EP_RegCheckKey"
- bp 6F410C
- cmt 6F4114,"EP_RegCheckKeyA"
- bp 6F4114
- cmt 6F4294,"EP_RegCheckKeyEx"
- bp 6F4294
- cmt 6F411C,"EP_RegCheckKeyW"
- bp 6F411C
- cmt 6F439C,"EP_RegDecryptRegistrationInformation"
- bp 6F439C
- cmt 6F4174,"EP_RegDeleteKey"
- bp 6F4174
- cmt 6F4394,"EP_RegEncryptRegistrationInformation"
- bp 6F4394
- cmt 6F40F4,"EP_RegHardwareID"
- bp 6F40F4
- cmt 6F40FC,"EP_RegHardwareIDA"
- bp 6F40FC
- cmt 6F4104,"EP_RegHardwareIDW"
- bp 6F4104
- cmt 6F418C,"EP_RegKeyCreationDate"
- bp 6F418C
- cmt 6F4194,"EP_RegKeyCreationDateEx"
- bp 6F4194
- cmt 6F41B4,"EP_RegKeyDays"
- bp 6F41B4
- cmt 6F41C4,"EP_RegKeyDaysLeft"
- bp 6F41C4
- cmt 6F41BC,"EP_RegKeyDaysTotal"
- bp 6F41BC
- cmt 6F419C,"EP_RegKeyExecutions"
- bp 6F419C
- cmt 6F41AC,"EP_RegKeyExecutionsLeft"
- bp 6F41AC
- cmt 6F41A4,"EP_RegKeyExecutionsTotal"
- bp 6F41A4
- cmt 6F417C,"EP_RegKeyExpirationDate"
- bp 6F417C
- cmt 6F4184,"EP_RegKeyExpirationDateEx"
- bp 6F4184
- cmt 6F41E4,"EP_RegKeyGlobalTime"
- bp 6F41E4
- cmt 6F41F4,"EP_RegKeyGlobalTimeLeft"
- bp 6F41F4
- cmt 6F41EC,"EP_RegKeyGlobalTimeTotal"
- bp 6F41EC
- cmt 6F4374,"EP_RegKeyInformation"
- bp 6F4374
- cmt 6F4374,"EP_RegKeyInformationA"
- bp 6F4374
- cmt 6F437C,"EP_RegKeyInformationW"
- bp 6F437C
- cmt 6F41FC,"EP_RegKeyRegisterAfterDate"
- bp 6F41FC
- cmt 6F4204,"EP_RegKeyRegisterAfterDateEx"
- bp 6F4204
- cmt 6F420C,"EP_RegKeyRegisterBeforeDate"
- bp 6F420C
- cmt 6F4214,"EP_RegKeyRegisterBeforeDateEx"
- bp 6F4214
- cmt 6F41CC,"EP_RegKeyRuntime"
- bp 6F41CC
- cmt 6F41DC,"EP_RegKeyRuntimeLeft"
- bp 6F41DC
- cmt 6F41D4,"EP_RegKeyRuntimeTotal"
- bp 6F41D4
- cmt 6F4384,"EP_RegKeyStatus"
- bp 6F4384
- cmt 6F4154,"EP_RegLoadAndCheckKey"
- bp 6F4154
- cmt 6F413C,"EP_RegLoadKey"
- bp 6F413C
- cmt 6F4144,"EP_RegLoadKeyA"
- bp 6F4144
- cmt 6F42A4,"EP_RegLoadKeyEx"
- bp 6F42A4
- cmt 6F414C,"EP_RegLoadKeyW"
- bp 6F414C
- cmt 6F4124,"EP_RegSaveKey"
- bp 6F4124
- cmt 6F412C,"EP_RegSaveKeyA"
- bp 6F412C
- cmt 6F429C,"EP_RegSaveKeyEx"
- bp 6F429C
- cmt 6F4134,"EP_RegSaveKeyW"
- bp 6F4134
- cmt 6F438C,"EP_RegShowDialog"
- bp 6F438C
- cmt 6F435C,"EP_SplashScreenHide"
- bp 6F435C
- cmt 6F4354,"EP_SplashScreenShow"
- bp 6F4354
- cmt 6F428C,"EP_TrialClockReversedDays"
- bp 6F428C
- cmt 6F425C,"EP_TrialDateTillDate"
- bp 6F425C
- cmt 6F426C,"EP_TrialDateTillDateEndEx"
- bp 6F426C
- cmt 6F4264,"EP_TrialDateTillDateStartEx"
- bp 6F4264
- cmt 6F4234,"EP_TrialDays"
- bp 6F4234
- cmt 6F4244,"EP_TrialDaysLeft"
- bp 6F4244
- cmt 6F423C,"EP_TrialDaysTotal"
- bp 6F423C
- cmt 6F4274,"EP_TrialExecutionTime"
- bp 6F4274
- cmt 6F4284,"EP_TrialExecutionTimeLeft"
- bp 6F4284
- cmt 6F427C,"EP_TrialExecutionTimeTotal"
- bp 6F427C
- cmt 6F421C,"EP_TrialExecutions"
- bp 6F421C
- cmt 6F422C,"EP_TrialExecutionsLeft"
- bp 6F422C
- cmt 6F4224,"EP_TrialExecutionsTotal"
- bp 6F4224
- cmt 6F424C,"EP_TrialExpirationDate"
- bp 6F424C
- cmt 6F4254,"EP_TrialExpirationDateEx"
- bp 6F4254
- cmt 716014,"Start"
- bp 716014
- ##########################################################
- RVA: C82AC | VA: 6F42AC | Func: EP_CheckUpStartupPasswordHashString
- RVA: C82FC | VA: 6F42FC | Func: EP_CheckupCopies
- RVA: C830C | VA: 6F430C | Func: EP_CheckupCopiesCurrent
- RVA: C8304 | VA: 6F4304 | Func: EP_CheckupCopiesTotal
- RVA: C8364 | VA: 6F4364 | Func: EP_CheckupFindProcess
- RVA: C8364 | VA: 6F4364 | Func: EP_CheckupFindProcessA
- RVA: C836C | VA: 6F436C | Func: EP_CheckupFindProcessW
- RVA: C831C | VA: 6F431C | Func: EP_CheckupIsEnigmaOk
- RVA: C8314 | VA: 6F4314 | Func: EP_CheckupIsProtected
- RVA: C8324 | VA: 6F4324 | Func: EP_CheckupVirtualizationTools
- RVA: C8344 | VA: 6F4344 | Func: EP_CryptDecryptBuffer
- RVA: C834C | VA: 6F434C | Func: EP_CryptDecryptBufferEx
- RVA: C8334 | VA: 6F4334 | Func: EP_CryptEncryptBuffer
- RVA: C833C | VA: 6F433C | Func: EP_CryptEncryptBufferEx
- RVA: C82D4 | VA: 6F42D4 | Func: EP_CryptHashBuffer
- RVA: C82DC | VA: 6F42DC | Func: EP_CryptHashFileA
- RVA: C82E4 | VA: 6F42E4 | Func: EP_CryptHashFileW
- RVA: C82EC | VA: 6F42EC | Func: EP_CryptHashStringA
- RVA: C82F4 | VA: 6F42F4 | Func: EP_CryptHashStringW
- RVA: C832C | VA: 6F432C | Func: EP_EnigmaVersion
- RVA: C82BC | VA: 6F42BC | Func: EP_MiscCountryCode
- RVA: C82B4 | VA: 6F42B4 | Func: EP_MiscGetWatermark
- RVA: C82C4 | VA: 6F42C4 | Func: EP_ProtectedStringByID
- RVA: C82CC | VA: 6F42CC | Func: EP_ProtectedStringByKey
- RVA: C815C | VA: 6F415C | Func: EP_RegCheckAndSaveKey
- RVA: C8164 | VA: 6F4164 | Func: EP_RegCheckAndSaveKeyA
- RVA: C816C | VA: 6F416C | Func: EP_RegCheckAndSaveKeyW
- RVA: C810C | VA: 6F410C | Func: EP_RegCheckKey
- RVA: C8114 | VA: 6F4114 | Func: EP_RegCheckKeyA
- RVA: C8294 | VA: 6F4294 | Func: EP_RegCheckKeyEx
- RVA: C811C | VA: 6F411C | Func: EP_RegCheckKeyW
- RVA: C839C | VA: 6F439C | Func: EP_RegDecryptRegistrationInformation
- RVA: C8174 | VA: 6F4174 | Func: EP_RegDeleteKey
- RVA: C8394 | VA: 6F4394 | Func: EP_RegEncryptRegistrationInformation
- RVA: C80F4 | VA: 6F40F4 | Func: EP_RegHardwareID
- RVA: C80FC | VA: 6F40FC | Func: EP_RegHardwareIDA
- RVA: C8104 | VA: 6F4104 | Func: EP_RegHardwareIDW
- RVA: C818C | VA: 6F418C | Func: EP_RegKeyCreationDate
- RVA: C8194 | VA: 6F4194 | Func: EP_RegKeyCreationDateEx
- RVA: C81B4 | VA: 6F41B4 | Func: EP_RegKeyDays
- RVA: C81C4 | VA: 6F41C4 | Func: EP_RegKeyDaysLeft
- RVA: C81BC | VA: 6F41BC | Func: EP_RegKeyDaysTotal
- RVA: C819C | VA: 6F419C | Func: EP_RegKeyExecutions
- RVA: C81AC | VA: 6F41AC | Func: EP_RegKeyExecutionsLeft
- RVA: C81A4 | VA: 6F41A4 | Func: EP_RegKeyExecutionsTotal
- RVA: C817C | VA: 6F417C | Func: EP_RegKeyExpirationDate
- RVA: C8184 | VA: 6F4184 | Func: EP_RegKeyExpirationDateEx
- RVA: C81E4 | VA: 6F41E4 | Func: EP_RegKeyGlobalTime
- RVA: C81F4 | VA: 6F41F4 | Func: EP_RegKeyGlobalTimeLeft
- RVA: C81EC | VA: 6F41EC | Func: EP_RegKeyGlobalTimeTotal
- RVA: C8374 | VA: 6F4374 | Func: EP_RegKeyInformation
- RVA: C8374 | VA: 6F4374 | Func: EP_RegKeyInformationA
- RVA: C837C | VA: 6F437C | Func: EP_RegKeyInformationW
- RVA: C81FC | VA: 6F41FC | Func: EP_RegKeyRegisterAfterDate
- RVA: C8204 | VA: 6F4204 | Func: EP_RegKeyRegisterAfterDateEx
- RVA: C820C | VA: 6F420C | Func: EP_RegKeyRegisterBeforeDate
- RVA: C8214 | VA: 6F4214 | Func: EP_RegKeyRegisterBeforeDateEx
- RVA: C81CC | VA: 6F41CC | Func: EP_RegKeyRuntime
- RVA: C81DC | VA: 6F41DC | Func: EP_RegKeyRuntimeLeft
- RVA: C81D4 | VA: 6F41D4 | Func: EP_RegKeyRuntimeTotal
- RVA: C8384 | VA: 6F4384 | Func: EP_RegKeyStatus
- RVA: C8154 | VA: 6F4154 | Func: EP_RegLoadAndCheckKey
- RVA: C813C | VA: 6F413C | Func: EP_RegLoadKey
- RVA: C8144 | VA: 6F4144 | Func: EP_RegLoadKeyA
- RVA: C82A4 | VA: 6F42A4 | Func: EP_RegLoadKeyEx
- RVA: C814C | VA: 6F414C | Func: EP_RegLoadKeyW
- RVA: C8124 | VA: 6F4124 | Func: EP_RegSaveKey
- RVA: C812C | VA: 6F412C | Func: EP_RegSaveKeyA
- RVA: C829C | VA: 6F429C | Func: EP_RegSaveKeyEx
- RVA: C8134 | VA: 6F4134 | Func: EP_RegSaveKeyW
- RVA: C838C | VA: 6F438C | Func: EP_RegShowDialog
- RVA: C835C | VA: 6F435C | Func: EP_SplashScreenHide
- RVA: C8354 | VA: 6F4354 | Func: EP_SplashScreenShow
- RVA: C828C | VA: 6F428C | Func: EP_TrialClockReversedDays
- RVA: C825C | VA: 6F425C | Func: EP_TrialDateTillDate
- RVA: C826C | VA: 6F426C | Func: EP_TrialDateTillDateEndEx
- RVA: C8264 | VA: 6F4264 | Func: EP_TrialDateTillDateStartEx
- RVA: C8234 | VA: 6F4234 | Func: EP_TrialDays
- RVA: C8244 | VA: 6F4244 | Func: EP_TrialDaysLeft
- RVA: C823C | VA: 6F423C | Func: EP_TrialDaysTotal
- RVA: C8274 | VA: 6F4274 | Func: EP_TrialExecutionTime
- RVA: C8284 | VA: 6F4284 | Func: EP_TrialExecutionTimeLeft
- RVA: C827C | VA: 6F427C | Func: EP_TrialExecutionTimeTotal
- RVA: C821C | VA: 6F421C | Func: EP_TrialExecutions
- RVA: C822C | VA: 6F422C | Func: EP_TrialExecutionsLeft
- RVA: C8224 | VA: 6F4224 | Func: EP_TrialExecutionsTotal
- RVA: C824C | VA: 6F424C | Func: EP_TrialExpirationDate
- RVA: C8254 | VA: 6F4254 | Func: EP_TrialExpirationDateEx
- RVA: EA014 | VA: 716014 | Func: Start
- ##################################################################################
- http://sealnimoru.com/Base/https://s3amazonaws.com/nimoru
- Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F Ascii
- 00000000 00 16 01 00 11 41 6C 63 61 74 72 61 7A 53 65 63 ..AlcatrazSec
- 00000010 75 72 69 74 79 00 00 00 08 B7 7A 5C 56 19 34 E0 urity...·z\V4à
- 00000020 89 03 20 00 01 04 01 00 00 00 02 06 1C 02 06 08 ‰.....
- 00000030 03 06 1D 05 03 06 11 2C 03 06 12 09 03 06 11 30 ,.0
- 00000040 07 00 02 12 0D 0E 12 11 04 00 01 08 0E 06 00 03 ....
- 00000050 0E 08 08 08 03 00 00 01 04 00 01 01 1C 09 00 04 .....
- 00000060 02 0F 05 08 09 10 09 06 00 01 1D 05 1D 05 06 10 ...
- 00000070 01 01 1E 00 09 07 00 02 12 09 1C 12 15 02 06 09 .....
- 00000080 05 20 01 09 12 10 04 06 1D 11 08 04 20 01 01 08 ...
- 00000090 0A 00 04 09 1D 11 08 09 12 10 08 03 06 12 21 05 ....!
- 000000A0 20 01 01 12 21 04 20 01 09 08 03 06 12 18 03 06 .!..
- 000000B0 12 1C 03 06 12 24 04 06 1D 11 0C 03 06 12 10 02 $
- 000000C0 06 02 03 06 11 0C 04 20 01 01 09 05 20 02 01 08 ...
- 000000D0 08 07 20 02 01 12 21 12 21 09 20 04 01 12 21 12 .!!..!
- 000000E0 21 0A 0A 05 20 01 01 1D 05 04 00 01 09 09 03 06 !......
- 000000F0 11 08 06 20 02 09 12 10 09 04 06 1D 11 20 05 20 .....
- 00000100 02 09 09 05 07 20 03 05 12 10 09 05 08 20 04 05 .....
- 00000110 12 10 09 05 05 05 20 01 05 12 10 06 20 02 05 12 ...
- 00000120 10 05 06 20 02 01 12 21 02 05 20 02 01 09 09 04 .!...
- 00000130 20 01 01 05 04 20 01 05 09 03 20 00 02 02 06 0E .....
- 00000140 38 68 00 74 00 74 00 70 00 3A 00 2F 00 2F 00 73 8h.t.t.p.:././.s
- 00000150 00 65 00 61 00 6C 00 2E 00 6E 00 69 00 6D 00 6F .e.a.l...n.i.m.o
- 00000160 00 72 00 75 00 2E 00 63 00 6F 00 6D 00 2F 00 42 .r.u...c.o.m./.B
- 00000170 00 61 00 73 00 65 00 2F 00 40 68 00 74 00 74 00 .a.s.e./.@h.t.t.
- 00000180 70 00 73 00 3A 00 2F 00 2F 00 73 00 33 00 2E 00 p.s.:././.s.3...
- 00000190 61 00 6D 00 61 00 7A 00 6F 00 6E 00 61 00 77 00 a.m.a.z.o.n.a.w.
- 000001A0 73 00 2E 00 63 00 6F 00 6D 00 2F 00 6E 00 69 00 s...c.o.m./.n.i.
- 000001B0 6D 00 6F 00 72 00 75 00 2F 00 84 m.o.r.u./.„
- Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F Ascii
- 00000BB0 80 E8 05 08 00 12 80 E8 1E 01 ۏ.ۏ
- 00000BC0 00 01 00 54 02 16 57 72 61 70 4E 6F 6E 45 78 63 ..TWrapNonExc
- 00000BD0 65 70 74 69 6F 6E 54 68 72 6F 77 73 01 29 01 00 eptionThrows).
- 00000BE0 24 64 30 35 32 33 35 64 62 2D 35 30 30 63 2D 34 $d05235db-500c-4
- 00000BF0 37 35 37 2D 61 33 37 34 2D 62 36 62 31 37 61 36 757-a374-b6b17a6
- 00000C00 35 38 65 66 36 00 00 05 01 00 00 00 00 17 01 00 58ef6.......
- 00000C10 12 43 6F 70 79 72 69 67 68 74 20 C2 A9 20 20 32 Copyright.©..2
- 00000C20 30 31 34 00 00 09 01 00 04 47 74 61 76 00 00 49 014....Gtav..I
- 00000C30 01 00 1A 2E 4E 45 54 46 72 61 6D 65 77 6F 72 6B ..NETFramework
- 00000C40 2C 56 65 72 73 69 6F 6E 3D 76 34 2E 35 01 00 54 ,Version=v4.5.T
- 00000C50 0E 14 46 72 61 6D 65 77 6F 72 6B 44 69 73 70 6C FrameworkDispl
- 00000C60 61 79 4E 61 6D 65 12 2E 4E 45 54 20 46 72 61 6D ayName.NET.Fram
- 00000C70 65 77 6F 72 6B 20 34 2E 35 08 01 00 08 00 00 00 ework.4.5....
- 00000C80 00 00 0C 01 00 07 31 2E 30 2E 30 2E 30 00 00 06 ...1.0.0.0..
- 00000C90 20 01 01 11 81 AD 08 01 00 07 01 00 00 00 00 06 ......
- 00000CA0 20 01 01 11 81 B5 08 01 00 02 00 00 00 00 00 06 .µ......
- 00000CB0 20 01 01 11 81 BD 08 01 00 01 00 00 00 00 00 29 .½......)
- 00000CC0 01 00 24 39 46 44 39 33 43 43 46 2D 33 32 38 30 .$9FD93CCF-3280
- 00000CD0 2D 34 33 39 31 2D 42 33 41 39 2D 39 36 45 31 43 -4391-B3A9-96E1C
- 00000CE0 44 45 37 37 43 38 44 00 00 29 01 00 24 44 33 33 DE77C8D..).$D33
- 00000CF0 32 44 42 39 45 2D 42 39 42 33 2D 34 31 32 35 2D 2DB9E-B9B3-4125-
- 00000D00 38 32 30 37 2D 41 31 34 38 38 34 46 35 33 32 31 8207-A14884F5321
- 00000D10 36 00 00 29 01 00 24 42 44 33 39 44 31 44 32 2D 6..).$BD39D1D2-
- 00000D20 42 41 32 46 2D 34 38 36 41 2D 38 39 42 30 2D 42 BA2F-486A-89B0-B
- 00000D30 34 42 30 43 42 34 36 36 38 39 31 00 00 4B0CB466891..
- ############################## /03/07/2016/ ####################################
- Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F Ascii
- 00000000 90 02 34 00 00 00 56 00 53 00 5F 00 56 00 45 00 4...V.S._.V.E.
- 00000010 52 00 53 00 49 00 4F 00 4E 00 5F 00 49 00 4E 00 R.S.I.O.N._.I.N.
- 00000020 46 00 4F 00 00 00 00 00 BD 04 EF FE 00 00 01 00 F.O.....½ïþ...
- 00000030 00 00 01 00 00 00 00 00 00 00 01 00 00 00 00 00 ..............
- 00000040 3F 00 00 00 00 00 00 00 04 00 00 00 01 00 00 00 ?.............
- 00000050 00 00 00 00 00 00 00 00 00 00 00 00 44 00 00 00 ............D...
- 00000060 01 00 56 00 61 00 72 00 46 00 69 00 6C 00 65 00 .V.a.r.F.i.l.e.
- 00000070 49 00 6E 00 66 00 6F 00 00 00 00 00 24 00 04 00 I.n.f.o.....$..
- 00000080 00 00 54 00 72 00 61 00 6E 00 73 00 6C 00 61 00 ..T.r.a.n.s.l.a.
- 00000090 74 00 69 00 6F 00 6E 00 00 00 00 00 00 00 B0 04 t.i.o.n.......°
- 000000A0 F0 01 00 00 01 00 53 00 74 00 72 00 69 00 6E 00 ð...S.t.r.i.n.
- 000000B0 67 00 46 00 69 00 6C 00 65 00 49 00 6E 00 66 00 g.F.i.l.e.I.n.f.
- 000000C0 6F 00 00 00 CC 01 00 00 01 00 30 00 30 00 30 00 o...Ì...0.0.0.
- 000000D0 30 00 30 00 34 00 62 00 30 00 00 00 34 00 05 00 0.0.4.b.0...4..
- 000000E0 01 00 46 00 69 00 6C 00 65 00 44 00 65 00 73 00 .F.i.l.e.D.e.s.
- 000000F0 63 00 72 00 69 00 70 00 74 00 69 00 6F 00 6E 00 c.r.i.p.t.i.o.n.
- 00000100 00 00 00 00 47 00 74 00 61 00 76 00 00 00 00 00 ....G.t.a.v.....
- 00000110 30 00 08 00 01 00 46 00 69 00 6C 00 65 00 56 00 0...F.i.l.e.V.
- 00000120 65 00 72 00 73 00 69 00 6F 00 6E 00 00 00 00 00 e.r.s.i.o.n.....
- 00000130 31 00 2E 00 30 00 2E 00 30 00 2E 00 30 00 00 00 1...0...0...0...
- 00000140 34 00 09 00 01 00 49 00 6E 00 74 00 65 00 72 00 4....I.n.t.e.r.
- 00000150 6E 00 61 00 6C 00 4E 00 61 00 6D 00 65 00 00 00 n.a.l.N.a.m.e...
- 00000160 47 00 74 00 61 00 76 00 2E 00 65 00 78 00 65 00 G.t.a.v...e.x.e.
- 00000170 00 00 00 00 48 00 12 00 01 00 4C 00 65 00 67 00 ....H...L.e.g.
- 00000180 61 00 6C 00 43 00 6F 00 70 00 79 00 72 00 69 00 a.l.C.o.p.y.r.i.
- 00000190 67 00 68 00 74 00 00 00 43 00 6F 00 70 00 79 00 g.h.t...C.o.p.y.
- 000001A0 72 00 69 00 67 00 68 00 74 00 20 00 A9 00 20 00 r.i.g.h.t...©...
- 000001B0 20 00 32 00 30 00 31 00 34 00 00 00 3C 00 09 00 ..2.0.1.4...<...
- 000001C0 01 00 4F 00 72 00 69 00 67 00 69 00 6E 00 61 00 .O.r.i.g.i.n.a.
- 000001D0 6C 00 46 00 69 00 6C 00 65 00 6E 00 61 00 6D 00 l.F.i.l.e.n.a.m.
- 000001E0 65 00 00 00 47 00 74 00 61 00 76 00 2E 00 65 00 e...G.t.a.v...e.
- 000001F0 78 00 65 00 00 00 00 00 2C 00 05 00 01 00 50 00 x.e.....,...P.
- 00000200 72 00 6F 00 64 00 75 00 63 00 74 00 4E 00 61 00 r.o.d.u.c.t.N.a.
- 00000210 6D 00 65 00 00 00 00 00 47 00 74 00 61 00 76 00 m.e.....G.t.a.v.
- 00000220 00 00 00 00 34 00 08 00 01 00 50 00 72 00 6F 00 ....4...P.r.o.
- 00000230 64 00 75 00 63 00 74 00 56 00 65 00 72 00 73 00 d.u.c.t.V.e.r.s.
- 00000240 69 00 6F 00 6E 00 00 00 31 00 2E 00 30 00 2E 00 i.o.n...1...0...
- 00000250 30 00 2E 00 30 00 00 00 38 00 08 00 01 00 41 00 0...0...8...A.
- 00000260 73 00 73 00 65 00 6D 00 62 00 6C 00 79 00 20 00 s.s.e.m.b.l.y...
- 00000270 56 00 65 00 72 00 73 00 69 00 6F 00 6E 00 00 00 V.e.r.s.i.o.n...
- 00000280 31 00 2E 00 30 00 2E 00 30 00 2E 00 30 00 00 00 1...0...0...0...
- #####################################################################################
- Text strings referenced in System_W:.data, item 17
- Address=6DE62E33
- Disassembly=ADD DWORD PTR DS:[ESI],3890000
- Text string=UNICODE "KeyToken=b77a5c561934e089"
- Text strings referenced in System_W:.data, item 2
- Address=6DE0BDBD
- Disassembly=ADD EAX,1982000
- Text string=UNICODE "{9374C3F4-959F-4f6a-BAA9-D55C8DA81F1C}"
- #####################################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement