Log in

View Full Version : . THe ReVirgin PRoblem!


NeO'X'QuiCk
April 4th, 2001, 16:14
I have bin reading the The Blackbird tut about unpacking Iris!
I got to problem i cant find the ReVirgin!


How they can be found:

1. Run the program with a breakpoint on UpdateWindow (or another one), when SoftICE breaks, press F12 until you are back in Iris maincode. Then trace into every call you come across until you turn out to be in the jump table. A jump table looks like this:

Start partial code

015F:004469D8 JMP [004BAF4C]015F:004469DE JMP [004BAF50]015F:004469E4 JMP [004BAF54]015F:004469EA JMP [004BAF58]015F:004469F0 JMP [004BAF5C]015F:004469F6 JMP [004BAF60]015F:004469FC JMP [004BAF64]015F:00446A02 JMP [004BAF68]015F:00446A08 JMP [004BAF6C]015F:00446A0E JMP [004BAF70]015F:00446A14 JMP [004BAF74]015F:00446A1A JMP [004BAF78]015F:00446A20 JMP [004BAF7C]015F:00446A26 JMP [004BAF80]
End partial code

Now, scroll through the jump table and try to find the lowest jump offset (i.e. find the JMP xxxxxxxx where xxxxxxxx is the lowest value in the whole jumptable). Note that this jump table can be divided by a lot of other instructions, so you'll have to scroll to make sure you saw the whole jumptable.
Another method to find the lowest offset, is to take a random offset in the jumptable (like 4BAF80), type d 4BAF80 and scroll up in the datawindow until there's no more data, but only zeros.
In Iris, the beginning of the IAT is @ offset 4BA48C. Fill in BA48C in ReVirgin.

Could you help me where to fing it!

Thanks in advance!
NeO'X'QuiCk

tsehp
April 4th, 2001, 17:08
hi,
you could have clicked search and typed revirgin, a lot of threads talks about this tool :-)

you can download the actual version at tsehp.cjb.net

risc
April 4th, 2001, 19:22
dude . try scanning the code for references to the import table, and 'dd va' .. dd, displays them as they should be, its a lot easier trying to figure out the beginning and the end when u see it all as dwords.

and if all else fails, 'map32 process_name' . and dd the rdata VA or the idata VA .. and use alt-pageup / alt-pagedown to search

if that fails too . let someone else unpack it :-)

Kilby
April 5th, 2001, 03:43
I think that you should possibly choose another (easier) target first.

r!scs tut on Settlers 3 is the best I have seen regarding the IAT it's length and position.


You don't need Settlers 3 to follow the theory, just patiance.


It took me about 3 weeks of reading and taking packers apart to get my head around what goes on in the tables, but then I'm a bit thick at the best of times.

The safedisc section in the crackers notes, also contains useful information.


There is some mention of finding the base of the table in my copylok tut too, that may help.

Regards,

Kilby...

SirLeechaLot
April 5th, 2001, 04:13
Hi

please post the link to r!scs homepage cause
csir.cjb.net doesnt seem to work
and I´m really interested in his fine unpacking tuts.


greetZ

siRl

[yAtEs]
April 5th, 2001, 05:10
you can get his packin tuts here
http://www.yates2k.co.uk/Pack.htm

or the settlers 3 one from here
http://www.yates2k.co.uk/cd/set3.zip

hrm change ur link back risc

NeO'X'QuiCk
April 5th, 2001, 11:33
Hello!

There was something wrong with my posting i didnt need reg.. i have it the problem that i could find the same . IAT Start RVA and lenght!
i got totally diferent numbers!

Aba4ac for start and lenght 132c.But as i was doing this the whole night trying to find 4BA48C. .The length in our case is 1308.But if i use my number i got lenght of ita 194 like Bla.. did!

so i did it with my number everthing was ok Except that i didnt get the whole import tables


Here:i got this
iris.exe
0194
index IAT_address value hint module function
--- -------- -------- ---- -------- --------
0 000BA4AC BFE82149 0025 ADVAPI32.dll ControlService
1 000BA4B0 BFE81534 00F7 ADVAPI32.dll RegQueryValueExA
2 000BA4B4 BFE814D1 00EF ADVAPI32.dll RegOpenKeyExA
3 000BA4B8 BFE8219A 0004 ADVAPI32.dll AccessCheckAndAuditAlarmA
4 000BA4BC BFE8216D 0008 ADVAPI32.dll AddAce
5 000BA4C0 BFE82149 0025 ADVAPI32.dll ControlService
6 000BA4C4 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
7 000BA4C8 BFE82149 0025 ADVAPI32.dll ControlService
8 000BA4CC BFE82149 0025 ADVAPI32.dll ControlService
9 000BA4D0 BFE81644 00D8 ADVAPI32.dll RegCloseKey
10 000BA4D4 BFE8182B 00E4 ADVAPI32.dll RegEnumKeyExA
11 000BA4D8 BFE82065 00D9 ADVAPI32.dll RegConnectRegistryA
12 000BA4DC BFE81A07 00F6 ADVAPI32.dll RegQueryValueA
13 000BA4E0 BFE81376 00E1 ADVAPI32.dll RegDeleteValueA
14 000BA4E4 BFE8215B 0006 ADVAPI32.dll AddAccessAllowedAce
15 000BA4E8 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
16 000BA4EC BFE8167D 00DC ADVAPI32.dll RegCreateKeyExA
17 000BA4F0 BFE815EA 0103 ADVAPI32.dll RegSetValueExA
18 000BA4F4 BFE82137 000E ADVAPI32.dll AreAllAccessesGranted
19 000BA4F8 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
20 000BA4FC BFE8172A 00DB ADVAPI32.dll RegCreateKeyA
21 000BA504 BFE99F39 003A COMCTL32.dll ImageList_GetIcon
22 000BA508 BFECD896 002B COMCTL32.dll ImageList_BeginDrag
23 000BA50C BFECDA10 0032 COMCTL32.dll ImageList_DragShowNolock
24 000BA510 BFECD5F5 0031 COMCTL32.dll ImageList_DragMove
25 000BA514 BFECDD47 0037 COMCTL32.dll ImageList_EndDrag
26 000BA518 BFECD9C9 0030 COMCTL32.dll ImageList_DragLeave
27 000BA51C BFECD96F 002F COMCTL32.dll ImageList_DragEnter
28 000BA520 BFEB3662 0051 COMCTL32.dll ImageList_SetOverlayImage
29 000BA524 BFEB1DB4 002A COMCTL32.dll ImageList_AddMasked
30 000BA528 BFEB1BF4 0046 COMCTL32.dll ImageList_ReplaceIcon
31 000BA52C BFEB1D11 004B COMCTL32.dll ImageList_SetBkColor
32 000BA534 BFF223C3 00AA GDI32.dll CreateSolidBrush
33 000BA538 BFF2513C 0179 GDI32.dll SetBkColor
34 000BA53C BFF2148D 011A GDI32.dll GetObjectA
35 000BA540 BFF22842 00B0 GDI32.dll DeleteObject
36 000BA544 BFF21557 00C7 GDI32.dll Escape
37 000BA548 BFF2254C 01AC GDI32.dll TextOutA
38 000BA54C BFF250B4 0165 GDI32.dll RectVisible
39 000BA550 BFF22727 0162 GDI32.dll PtVisible
40 000BA554 BFF2507B 00A5 GDI32.dll CreateRectRgn
41 000BA558 BFF21A27 015E GDI32.dll Polygon
42 000BA55C BFF216EF 00FA GDI32.dll GetDeviceCaps
43 000BA560 BFF21481 013A GDI32.dll GetTextMetricsA
44 000BA564 BFF22621 0095 GDI32.dll CreateFontA
45 000BA568 BFF25135 019C GDI32.dll SetTextColor
46 000BA56C BFF21CB8 00CE GDI32.dll ExtTextOutA
47 000BA570 BFF223A2 00A1 GDI32.dll CreatePen
48 000BA574 BFF2267F 0096 GDI32.dll CreateFontIndirectA
49 000BA578 BFF21EDC 0134 GDI32.dll GetTextExtentPoint32A
50 000BA57C BFF22293 0072 GDI32.dll BitBlt
51 000BA580 BFF22D2D 0088 GDI32.dll CreateCompatibleBitmap
52 000BA584 BFF224D8 0089 GDI32.dll CreateCompatibleDC
53 000BA588 BFF22757 0166 GDI32.dll Rectangle
54 000BA590 BFF76DA8 01A3 KERNEL32.dll GetProcAddress
55 000BA594 BFF7B9B2 0228 KERNEL32.dll LeaveCriticalSection
56 000BA598 BFF777AD 01B9 KERNEL32.dll GetStartupInfoA
57 000BA59C BFF77716 018D KERNEL32.dll GetModuleHandleA
58 000BA5A0 BFF95A88 015C KERNEL32.dll GetCurrentThread
59 000BA5A4 BFF96347 015A KERNEL32.dll GetCurrentProcess
60 000BA5A8 BFF77A0F 0164 KERNEL32.dll GetDiskFreeSpaceA
61 000BA5AC BFF779D5 0158 KERNEL32.dll GetCurrentDirectoryA
62 000BA5B0 BFF779AE 02C1 KERNEL32.dll SetCurrentDirectoryA
63 000BA5B4 BFF8F4FC 02EB KERNEL32.dll SetThreadPriority
64 000BA5B8 BFFA1A1C 00AD KERNEL32.dll CopyFileA
65 000BA5BC BFF74361 020D KERNEL32.dll InterlockedDecrement
66 000BA5C0 BFF7B98D 00E1 KERNEL32.dll EnterCriticalSection
67 000BA5C4 BFF748B4 01E6 KERNEL32.dll GlobalAlloc
68 000BA5C8 BFF76DD7 01F1 KERNEL32.dll GlobalLock
69 000BA5CC BFF76E1B 01F7 KERNEL32.dll GlobalUnlock
70 000BA5D0 BFF7736F 0350 KERNEL32.dll lstrcat
71 000BA5D4 BFF77741 00C6 KERNEL32.dll CreateProcessA
72 000BA5D8 BFF88B8D 02F7 KERNEL32.dll SleepEx
73 000BA5DC BFF77978 01E1 KERNEL32.dll GetWindowsDirectoryA
74 000BA5E0 BFF77B30 0172 KERNEL32.dll GetFileAttributesA
75 000BA5E4 BFF77A90 017A KERNEL32.dll GetFullPathNameA
76 000BA5E8 BFF77844 019F KERNEL32.dll GetPrivateProfileStringA
77 000BA5EC BFF776F7 018B KERNEL32.dll GetModuleFileNameA
78 000BA5F0 BFF8516B 0181 KERNEL32.dll GetLastError
79 000BA5F4 BFF773A9 035F KERNEL32.dll lstrlen
80 000BA5F8 BFF8BCA7 012D KERNEL32.dll FormatMessageA
81 000BA5FC BFF8E0CD 0133 KERNEL32.dll FreeLibrary
82 000BA600 BFF748B4 01E6 KERNEL32.dll GlobalAlloc
83 000BA604 BFF77D81 0252 KERNEL32.dll MultiByteToWideChar
84 000BA608 BFF749D0 0235 KERNEL32.dll LocalFree
85 000BA60C BFF77332 035C KERNEL32.dll lstrcpyn
86 000BA610 BFFA142F 0262 KERNEL32.dll OutputDebugStringA
87 000BA614 BFF768A0 00D2 KERNEL32.dll DebugBreak
88 000BA618 BFF772F8 0359 KERNEL32.dll lstrcpy
89 000BA61C BFF77EB9 0111 KERNEL32.dll FileTimeToLocalFileTime
90 000BA620 BFF77F11 0112 KERNEL32.dll FileTimeToSystemTime
91 000BA624 BFF95A8E 02FE KERNEL32.dll TerminateThread
92 000BA628 BFF77F3D 00B2 KERNEL32.dll CreateDirectoryA
93 000BA62C BFFA0D34 01C8 KERNEL32.dll GetSystemTimeAsFileTime
94 000BA630 BFF8ABFA 00D6 KERNEL32.dll DeleteCriticalSection
95 000BA634 BFF842B1 020A KERNEL32.dll InitializeCriticalSection
96 000BA638 BFF76F66 00CD KERNEL32.dll CreateThread
97 000BA63C BFF813EC 015D KERNEL32.dll GetCurrentThreadId
98 000BA640 BFF92D08 02F6 KERNEL32.dll Sleep
99 000BA644 BFF7C8BD 0327 KERNEL32.dll WaitForSingleObject
100 000BA648 BFF7E06D 00A0 KERNEL32.dll CloseHandle
101 000BA64C BFF92CAF 0328 KERNEL32.dll WaitForSingleObjectEx
102 000BA650 BFF92BFF 028B KERNEL32.dll ResetEvent
103 000BA654 BFF92B8F 02CA KERNEL32.dll SetEvent
104 000BA658 BFF77590 00B6 KERNEL32.dll CreateEventA
105 000BA65C BFF776D0 0229 KERNEL32.dll LoadLibraryA
106 000BA664 6C3908A4 19FA MFC42.DLL
107 000BA668 6C375438 0D4B MFC42.DLL
108 000BA66C 6C3DB52A 10CF MFC42.DLL
109 000BA670 6C3753AE 0D16 MFC42.DLL
110 000BA674 6C3C45B1 188B MFC42.DLL
111 000BA678 6C380CCA 0441 MFC42.DLL
112 000BA67C 6C3C3B76 035B MFC42.DLL
113 000BA680 6C3814F8 1663 MFC42.DLL
114 000BA684 6C379C2B 09D0 MFC42.DLL
115 000BA688 6C3751E8 09FA MFC42.DLL

426 000BAB64 6C375C3C 0305 MFC42.DLL
427 000BAB68 6C3E7630 0E76 MFC42.DLL
428 000BAB6C 6C375836 01F5 MFC42.DLL
429 000BAB70 6C37FF44 0451 MFC42.DLL
430 000BAB74 6C373F15 039A MFC42.DLL
431 000BAB78 6C3DA477 047C MFC42.DLL
432 000BAB7C 6C37413F 03AD MFC42.DLL
433 000BAB80 6C3713B3 0D12 MFC42.DLL
434 000BAB84 6C3E014D 16D9 MFC42.DLL
435 000BAB88 6C37C181 0474 MFC42.DLL
436 000BAB8C 6C37BB36 0DC2 MFC42.DLL
437 000BAB90 6C387EBD 1903 MFC42.DLL
438 000BAB94 6C37A07D 03AB MFC42.DLL
439 000BAB98 6C381800 0B02 MFC42.DLL
440 000BAB9C 6C373EB0 0217 MFC42.DLL
441 000BABA0 6C3710F8 0497 MFC42.DLL
442 000BABA4 6C3C4132 1021 MFC42.DLL
443 000BABA8 6C382060 0ACB MFC42.DLL
444 000BABAC 6C374086 1040 MFC42.DLL
445 000BABB0 6C3FE9C2 1206 MFC42.DLL
446 000BABB4 6C3848DC 1205 MFC42.DLL
447 000BABB8 6C417CB0 0739 MFC42.DLL
448 000BABBC 6C417D10 1094 MFC42.DLL
449 000BABC0 6C374F28 096B MFC42.DLL
450 000BABC4 6C3D1AE3 11ED MFC42.DLL
451 000BABC8 6C3D194D 1323 MFC42.DLL
452 000BABCC 6C374B76 10F5 MFC42.DLL
453 000BABD0 6C374671 10FD MFC42.DLL
454 000BABD4 6C383719 131A MFC42.DLL
455 000BABD8 6C3D19D7 11B3 MFC42.DLL
456 000BABDC 6C3D19E4 11C1 MFC42.DLL
457 000BABE0 6C3D19DF 11AC MFC42.DLL
458 000BABE4 6C373FFF 095F MFC42.DLL
459 000BABE8 6C3D19DF 11AC MFC42.DLL
460 000BABEC 6C3D19DF 11AC MFC42.DLL
461 000BABF0 6C3D19D2 1361 MFC42.DLL
462 000BABF4 6C3D19D2 1361 MFC42.DLL
463 000BABF8 6C3D195C 100C MFC42.DLL
464 000BABFC 6C3E2711 1133 MFC42.DLL
465 000BAC00 6C38853D 1478 MFC42.DLL
466 000BAC04 6C3735BD 0EA4 MFC42.DLL

796 000BB12C 6C3CBD7C 18A7 MFC42.DLL
797 000BB130 6C3CBD6A 104B MFC42.DLL
798 000BB134 6C37D22B 0F21 MFC42.DLL
799 000BB138 6C3C3B8B 039B MFC42.DLL
800 000BB13C 6C38317F 17F1 MFC42.DLL
801 000BB140 6C38206E 1A06 MFC42.DLL
802 000BB144 6C3CAA2F 15CF MFC42.DLL
803 000BB148 6C3C90BD 1AE3 MFC42.DLL
804 000BB14C 6C3E7E78 0E72 MFC42.DLL
805 000BB150 6C373676 0EAA MFC42.DLL
806 000BB154 6C3D74CB 08F4 MFC42.DLL
807 000BB158 6C37EA89 0146 MFC42.DLL
808 000BB160 78003417 01B7 MSVCRT.dll _setmbcp
809 000BB164 7800AE78 004C MSVCRT.dll __CxxFrameHandler
810 000BB168 7800231A 02D6 MSVCRT.dll strncpy
811 000BB16C 780253CA 02C7 MSVCRT.dll sprintf
812 000BB170 780030B5 02AD MSVCRT.dll memmove
813 000BB174 78023383 01BB MSVCRT.dll _snprintf
814 000BB178 7802541C 02CA MSVCRT.dll sscanf
815 000BB17C 7800BDD3 00A8 MSVCRT.dll _beginthread
816 000BB180 7800C7D0 0252 MSVCRT.dll atoi
817 000BB184 7800BEDD 00C8 MSVCRT.dll _endthread
818 000BB188 7802A38B 025B MSVCRT.dll ctime
819 000BB18C 7802A875 02E5 MSVCRT.dll time
820 000BB190 780010ED 0273 MSVCRT.dll free
821 000BB194 78001BF1 00F9 MSVCRT.dll _ftol
822 000BB198 78001E18 0255 MSVCRT.dll calloc
823 000BB19C 78001000 02A6 MSVCRT.dll malloc
824 000BB1A0 7800ADBB 0044 MSVCRT.dll _CxxThrowException
825 000BB1A4 78029239 00F7 MSVCRT.dll _ftime
826 000BB1A8 78012D7C 01D3 MSVCRT.dll _strnicmp
827 000BB1AC 780029BF 02DA MSVCRT.dll strstr
828 000BB1B0 7802ED3A 0256 MSVCRT.dll ceil
829 000BB1B4 78028CEE 02DC MSVCRT.dll strtok
830 000BB1B8 780127CE 02CC MSVCRT.dll strchr
831 000BB1BC 78019F7E 01C0 MSVCRT.dll _spawnlp
832 000BB1C0 780205B7 01C6 MSVCRT.dll _splitpath
833 000BB1C4 780012EF 02FB MSVCRT.dll wcslen
834 000BB1C8 78003023 02A8 MSVCRT.dll mbstowcs
835 000BB1CC 7802109C 02B9 MSVCRT.dll qsort
836 000BB1D0 78012D00 02D0 MSVCRT.dll strcspn
837 000BB1D4 78016F5D 00E3 MSVCRT.dll _findclose
838 000BB1D8 78016E95 00E7 MSVCRT.dll _findnext
839 000BB1DC 78016DC5 00E4 MSVCRT.dll _findfirst
840 000BB1E0 78017A09 00AF MSVCRT.dll _chdir
841 000BB1E4 78012188 0261 MSVCRT.dll fclose
842 000BB1E8 78024336 0267 MSVCRT.dll fgets
843 000BB1EC 78022AA9 026C MSVCRT.dll fopen
844 000BB1F0 7800F56A 00CE MSVCRT.dll _except_handler3
845 000BB1F4 7800B20C 000E MSVCRT.dll ??1type_info@@UAE@XZ
846 000BB1F8 78002131 0058 MSVCRT.dll __dllonexit
847 000BB1FC 78004446 0192 MSVCRT.dll _onexit
848 000BB200 7800AC3F 0030 MSVCRT.dll ?terminate@@YAXXZ
849 000BB204 7800B908 00D7 MSVCRT.dll _exit
850 000BB208 7800F7DC 004B MSVCRT.dll _XcptFilter
851 000BB20C 7800269E 025E MSVCRT.dll exit
852 000BB210 7803B508 0092 MSVCRT.dll _acmdln
853 000BB214 78003E70 005B MSVCRT.dll __getmainargs
854 000BB218 78001DEA 0119 MSVCRT.dll _initterm
855 000BB21C 7800B426 0086 MSVCRT.dll __setusermatherr
856 000BB220 7803BB70 00A0 MSVCRT.dll _adjust_fdiv
857 000BB224 78003E6A 006D MSVCRT.dll __p__commode
858 000BB228 78003E64 0072 MSVCRT.dll __p__fmode
859 000BB22C 78003E5A 0084 MSVCRT.dll __set_app_type
860 000BB230 78003C1E 00BA MSVCRT.dll _controlfp
861 000BB234 7801419F 01E8 MSVCRT.dll _ultoa
862 000BB238 78004A69 013E MSVCRT.dll _itoa
863 000BB240 7FE990C2 00C8 OLEAUT32.dll GetErrorInfo
864 000BB244 7FE8227E 0009 OLEAUT32.dll VariantClear
865 000BB248 7FE81523 0006 OLEAUT32.dll SysFreeString
866 000BB24C 7FE81408 0002 OLEAUT32.dll SysAllocString
867 000BB254 7FCB734A 011D SHELL32.dll SHGetMalloc
868 000BB258 7FD07109 0109 SHELL32.dll SHBrowseForFolder
869 000BB25C 7FCB3BC4 011F SHELL32.dll SHGetPathFromIDList
870 000BB260 7FD18BE2 0148 SHELL32.dll Shell_NotifyIcon
871 000BB264 7FD16AFF 0142 SHELL32.dll ShellExecuteA
872 000BB26C BFF52471 012F USER32.dll GetParent
873 000BB270 BFF54C52 013C USER32.dll GetSysColor
874 000BB274 BFF559A1 008B USER32.dll DestroyCursor
875 000BB278 BFF51319 019B USER32.dll LoadMenuA
876 000BB27C BFF5308E 022F USER32.dll SetTimer
877 000BB280 BFF55836 01F7 USER32.dll SendMessageA
878 000BB284 BFF52DA4 011C USER32.dll GetMenuItemID
879 000BB288 BFF55413 0047 USER32.dll CopyRect
880 000BB28C BFF55102 0184 USER32.dll IsIconic
881 000BB290 BFF5249D 00F7 USER32.dll GetDC
882 000BB294 BFF52090 01E8 USER32.dll ReleaseDC
883 000BB298 BFF551F5 0102 USER32.dll GetForegroundWindow
884 000BB29C BFF555A7 014E USER32.dll GetWindowLongA
885 000BB2A0 BFF524BB 0212 USER32.dll SetForegroundWindow
886 000BB2A4 BFF520A4 00B5 USER32.dll EnableWindow
887 000BB2A8 BFF54FC5 00EB USER32.dll GetClientRect
888 000BB2AC BFF524DB 01A2 USER32.dll LockWindowUpdate
889 000BB2B0 BFF54F53 0153 USER32.dll GetWindowRect
890 000BB2B4 BFF52170 0172 USER32.dll InvalidateRect
891 000BB2B8 BFF55828 01F2 USER32.dll SendDlgItemMessageA
892 000BB2BC BFF52489 01FF USER32.dll SetActiveWindow
893 000BB2C0 BFF559F9 0195 USER32.dll LoadIconA
894 000BB2C4 BFF54EA5 0187 USER32.dll IsWindow
895 000BB2C8 BFF5156B 0239 USER32.dll SetWindowPos
896 000BB2CC BFF52130 00A4 USER32.dll DrawFocusRect
897 000BB2D0 BFF5141E 0266 USER32.dll UnregisterClassA
898 000BB2D4 BFF55BCD 0085 USER32.dll DefWindowProcA
899 000BB2D8 BFF52475 0113 USER32.dll GetLastActivePopup
900 000BB2DC BFF55918 00D3 USER32.dll FindWindowA
901 000BB2E0 BFF52DC6 0037 USER32.dll CheckMenuItem
902 000BB2E4 BFF5300E 015B USER32.dll GrayStringA
903 000BB2E8 BFF528DC 024F USER32.dll TabbedTextOutA
904 000BB2EC BFF527BB 01AA USER32.dll MapWindowPoints
905 000BB2F0 BFF553D4 0225 USER32.dll SetRect
906 000BB2F4 BFF51B3F 014A USER32.dll GetWindow
907 000BB2F8 BFF51F4A 003B USER32.dll ChildWindowFromPointEx
908 000BB2FC BFF5558C 019F USER32.dll LoadStringA
909 000BB300 BFF52485 0211 USER32.dll SetFocus
910 000BB304 BFF52176 00D2 USER32.dll FillRect
911 000BB308 BFF5548F 01C2 USER32.dll OffsetRect
912 000BB30C BFF55923 003A USER32.dll ChildWindowFromPoint
913 000BB310 BFF524D7 000E USER32.dll BringWindowToTop
914 000BB314 BFF54460 0007 USER32.dll AppendMenuA
915 000BB318 BFF520A8 017D USER32.dll IsChild
916 000BB31C BFF54706 0016 USER32.dll CallNextHookEx
917 000BB320 BFF53451 0261 USER32.dll UnhookWindowsHookEx
918 000BB324 BFF511D9 023F USER32.dll SetWindowsHookExA
919 000BB328 BFF524FB 011B USER32.dll GetMenuItemCount
920 000BB32C BFF551B1 00F9 USER32.dll GetDesktopWindow
921 000BB330 BFF55A6D 00A7 USER32.dll DrawIcon
922 000BB334 BFF54F36 00FB USER32.dll GetDlgCtrlID
923 000BB338 BFF55127 018B USER32.dll IsZoomed
924 000BB33C BFF55591 0285 USER32.dll wsprintfA
925 000BB340 BFF51BAD 018C USER32.dll KillTimer
926 000BB344 BFF54D54 0100 USER32.dll GetDoubleClickTime
927 000BB348 BFF512DE 0197 USER32.dll LoadImageA
928 000BB34C BFF55A38 018F USER32.dll LoadBitmapA
929 000BB350 BFF51670 00D4 USER32.dll FindWindowExA
930 000BB354 BFF52098 0246 USER32.dll ShowWindow
931 000BB358 BFF549C9 002A USER32.dll CharPrevA
932 000BB35C BFF5493E 0026 USER32.dll CharNextA
933 000BB360 BFF55171 018A USER32.dll IsWindowVisible
934 000BB364 BFF524EF 00DE USER32.dll GetAsyncKeyState
935 000BB368 BFF51ADA 00A6 USER32.dll DrawFrameControl
936 000BB36C BFF5447F 00AD USER32.dll DrawTextA
937 000BB370 BFF5545D 01D4 USER32.dll PtInRect
938 000BB374 BFF524E7 026A USER32.dll UpdateWindow
939 000BB378 BFF5554E 00CF USER32.dll EqualRect
940 000BB37C BFF52DCE 00B3 USER32.dll EnableMenuItem
941 000BB380 BFF550BA 003D USER32.dll ClientToScreen
942 000BB384 BFF51F2C 0280 USER32.dll WindowFromPoint
943 000BB388 BFF55A0F 0191 USER32.dll LoadCursorA
944 000BB38C BFF52D8A 0208 USER32.dll SetCursor
945 000BB390 BFF55072 01EE USER32.dll ScreenToClient
946 000BB394 BFF5248D 0200 USER32.dll SetCapture
947 000BB398 BFF523CB 01D7 USER32.dll RedrawWindow
948 000BB39C BFF51EEE 00F6 USER32.dll GetCursorPos
949 000BB3A0 BFF51B37 013B USER32.dll GetSubMenu
950 000BB3A4 BFF55708 01CF USER32.dll PostMessageA
951 000BB3A8 BFF526FC 01E7 USER32.dll ReleaseCapture
952 000BB3AC BFF552F6 013F USER32.dll GetSystemMetrics
953 000BB3B0 BFF51269 024D USER32.dll SystemParametersInfoA
954 000BB3B4 BFF524EB 010C USER32.dll GetKeyState
955 000BB3B8 BFF5412E 01AD USER32.dll MessageBoxA
956 000BB3BC BFF558C0 0017 USER32.dll CallWindowProcA
957 000BB3C0 BFF5564D 0236 USER32.dll SetWindowLongA
958 000BB3C8 BFE71267 000C VERSION.dll VerQueryValueA
959 000BB3CC BFE7152F 0001 VERSION.dll GetFileVersionInfoA
960 000BB3D0 BFE71494 0002 VERSION.dll GetFileVersionInfoSizeA
961 000BB3D8 762986ED 00EC WININET.dll InternetGetConnectedState
962 000BB3DC 7629817D 0106 WININET.dll InternetSetCookieA
963 000BB3E4 BFDF8DB3 0002 WINMM.dll PlaySoundA
964 000BB3EC 75FA159B 000B WSOCK32.dll inet_ntoa
965 000BB3F0 75FA156A 000A WSOCK32.dll inet_addr
966 000BB3F4 75FA1635 000E WSOCK32.dll ntohl
967 000BB3F8 75FA1807 0034 WSOCK32.dll gethostbyname
968 000BB3FC 75FA1661 000F WSOCK32.dll ntohs
969 000BB400 75FA18EB 0039 WSOCK32.dll gethostname
970 000BB404 75FA17D3 0033 WSOCK32.dll gethostbyaddr
971 000BB408 75FA1539 0009 WSOCK32.dll htons
972 000BB410 100029C0 0009 ecap.dll W32N_MakeNdisRequest
973 000BB414 10003640 0004 ecap.dll W32N_GetAdapterRegistryInfo
974 000BB418 10002E60 0002 ecap.dll W32N_CloseAdapter
975 000BB41C 10002840 000C ecap.dll W32N_OpenAdapterA
976 000BB420 10001A20 0008 ecap.dll W32N_IsWindowsNT
977 000BB424 10001A60 0006 ecap.dll W32N_IsWindows2000
978 000BB428 10002EA0 0003 ecap.dll W32N_DisableLoopback
979 000BB42C 10001A80 0007 ecap.dll W32N_IsWindows95
980 000BB430 10002BF0 0001 ecap.dll W32N_CancelPacketRead
981 000BB434 10002AC0 0010 ecap.dll W32N_PacketReadEx
982 000BB438 10002D60 0012 ecap.dll W32N_PacketSendEx
983 000BB43C 100019E0 000B ecap.dll W32N_OSGetPlatformVersion
984 000BB440 100019C0 0005 ecap.dll W32N_GetLastError
985 000BB448 60013320 0509 egui.dll ?

NeO'X'QuiCk
April 5th, 2001, 11:34
Hello!

There was something wrong with my posting i didnt need reg.. i have it the problem that i could find the same . IAT Start RVA and lenght!
i got totally diferent numbers!

Aba4ac for start and lenght 132c.But as i was doing this the whole night trying to find 4BA48C. .The length in our case is 1308.But if i use my number i got lenght of ita 194 like Bla.. did!

so i did it with my number everthing was ok Except that i didnt get the whole import tables


Here:i got this
iris.exe
0194
index IAT_address value hint module function
--- -------- -------- ---- -------- --------
0 000BA4AC BFE82149 0025 ADVAPI32.dll ControlService
1 000BA4B0 BFE81534 00F7 ADVAPI32.dll RegQueryValueExA
2 000BA4B4 BFE814D1 00EF ADVAPI32.dll RegOpenKeyExA
3 000BA4B8 BFE8219A 0004 ADVAPI32.dll AccessCheckAndAuditAlarmA
4 000BA4BC BFE8216D 0008 ADVAPI32.dll AddAce
5 000BA4C0 BFE82149 0025 ADVAPI32.dll ControlService
6 000BA4C4 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
7 000BA4C8 BFE82149 0025 ADVAPI32.dll ControlService
8 000BA4CC BFE82149 0025 ADVAPI32.dll ControlService
9 000BA4D0 BFE81644 00D8 ADVAPI32.dll RegCloseKey
10 000BA4D4 BFE8182B 00E4 ADVAPI32.dll RegEnumKeyExA
11 000BA4D8 BFE82065 00D9 ADVAPI32.dll RegConnectRegistryA
12 000BA4DC BFE81A07 00F6 ADVAPI32.dll RegQueryValueA
13 000BA4E0 BFE81376 00E1 ADVAPI32.dll RegDeleteValueA
14 000BA4E4 BFE8215B 0006 ADVAPI32.dll AddAccessAllowedAce
15 000BA4E8 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
16 000BA4EC BFE8167D 00DC ADVAPI32.dll RegCreateKeyExA
17 000BA4F0 BFE815EA 0103 ADVAPI32.dll RegSetValueExA
18 000BA4F4 BFE82137 000E ADVAPI32.dll AreAllAccessesGranted
19 000BA4F8 BFE82125 0001 ADVAPI32.dll AbortSystemShutdownA
20 000BA4FC BFE8172A 00DB ADVAPI32.dll RegCreateKeyA
21 000BA504 BFE99F39 003A COMCTL32.dll ImageList_GetIcon
22 000BA508 BFECD896 002B COMCTL32.dll ImageList_BeginDrag
23 000BA50C BFECDA10 0032 COMCTL32.dll ImageList_DragShowNolock
24 000BA510 BFECD5F5 0031 COMCTL32.dll ImageList_DragMove
25 000BA514 BFECDD47 0037 COMCTL32.dll ImageList_EndDrag
26 000BA518 BFECD9C9 0030 COMCTL32.dll ImageList_DragLeave
27 000BA51C BFECD96F 002F COMCTL32.dll ImageList_DragEnter
28 000BA520 BFEB3662 0051 COMCTL32.dll ImageList_SetOverlayImage
29 000BA524 BFEB1DB4 002A COMCTL32.dll ImageList_AddMasked
30 000BA528 BFEB1BF4 0046 COMCTL32.dll ImageList_ReplaceIcon
31 000BA52C BFEB1D11 004B COMCTL32.dll ImageList_SetBkColor
32 000BA534 BFF223C3 00AA GDI32.dll CreateSolidBrush
33 000BA538 BFF2513C 0179 GDI32.dll SetBkColor
34 000BA53C BFF2148D 011A GDI32.dll GetObjectA
35 000BA540 BFF22842 00B0 GDI32.dll DeleteObject
36 000BA544 BFF21557 00C7 GDI32.dll Escape
37 000BA548 BFF2254C 01AC GDI32.dll TextOutA
38 000BA54C BFF250B4 0165 GDI32.dll RectVisible
39 000BA550 BFF22727 0162 GDI32.dll PtVisible
40 000BA554 BFF2507B 00A5 GDI32.dll CreateRectRgn
41 000BA558 BFF21A27 015E GDI32.dll Polygon
42 000BA55C BFF216EF 00FA GDI32.dll GetDeviceCaps
43 000BA560 BFF21481 013A GDI32.dll GetTextMetricsA
44 000BA564 BFF22621 0095 GDI32.dll CreateFontA
45 000BA568 BFF25135 019C GDI32.dll SetTextColor
46 000BA56C BFF21CB8 00CE GDI32.dll ExtTextOutA
47 000BA570 BFF223A2 00A1 GDI32.dll CreatePen
48 000BA574 BFF2267F 0096 GDI32.dll CreateFontIndirectA
49 000BA578 BFF21EDC 0134 GDI32.dll GetTextExtentPoint32A
50 000BA57C BFF22293 0072 GDI32.dll BitBlt
51 000BA580 BFF22D2D 0088 GDI32.dll CreateCompatibleBitmap
52 000BA584 BFF224D8 0089 GDI32.dll CreateCompatibleDC
53 000BA588 BFF22757 0166 GDI32.dll Rectangle
54 000BA590 BFF76DA8 01A3 KERNEL32.dll GetProcAddress
55 000BA594 BFF7B9B2 0228 KERNEL32.dll LeaveCriticalSection
56 000BA598 BFF777AD 01B9 KERNEL32.dll GetStartupInfoA
57 000BA59C BFF77716 018D KERNEL32.dll GetModuleHandleA
58 000BA5A0 BFF95A88 015C KERNEL32.dll GetCurrentThread
59 000BA5A4 BFF96347 015A KERNEL32.dll GetCurrentProcess
60 000BA5A8 BFF77A0F 0164 KERNEL32.dll GetDiskFreeSpaceA
61 000BA5AC BFF779D5 0158 KERNEL32.dll GetCurrentDirectoryA
62 000BA5B0 BFF779AE 02C1 KERNEL32.dll SetCurrentDirectoryA
63 000BA5B4 BFF8F4FC 02EB KERNEL32.dll SetThreadPriority
64 000BA5B8 BFFA1A1C 00AD KERNEL32.dll CopyFileA
65 000BA5BC BFF74361 020D KERNEL32.dll InterlockedDecrement
66 000BA5C0 BFF7B98D 00E1 KERNEL32.dll EnterCriticalSection
67 000BA5C4 BFF748B4 01E6 KERNEL32.dll GlobalAlloc
68 000BA5C8 BFF76DD7 01F1 KERNEL32.dll GlobalLock
69 000BA5CC BFF76E1B 01F7 KERNEL32.dll GlobalUnlock
70 000BA5D0 BFF7736F 0350 KERNEL32.dll lstrcat
71 000BA5D4 BFF77741 00C6 KERNEL32.dll CreateProcessA
72 000BA5D8 BFF88B8D 02F7 KERNEL32.dll SleepEx
73 000BA5DC BFF77978 01E1 KERNEL32.dll GetWindowsDirectoryA
74 000BA5E0 BFF77B30 0172 KERNEL32.dll GetFileAttributesA
75 000BA5E4 BFF77A90 017A KERNEL32.dll GetFullPathNameA
76 000BA5E8 BFF77844 019F KERNEL32.dll GetPrivateProfileStringA
77 000BA5EC BFF776F7 018B KERNEL32.dll GetModuleFileNameA
78 000BA5F0 BFF8516B 0181 KERNEL32.dll GetLastError
79 000BA5F4 BFF773A9 035F KERNEL32.dll lstrlen
80 000BA5F8 BFF8BCA7 012D KERNEL32.dll FormatMessageA
81 000BA5FC BFF8E0CD 0133 KERNEL32.dll FreeLibrary
82 000BA600 BFF748B4 01E6 KERNEL32.dll GlobalAlloc
83 000BA604 BFF77D81 0252 KERNEL32.dll MultiByteToWideChar
84 000BA608 BFF749D0 0235 KERNEL32.dll LocalFree
85 000BA60C BFF77332 035C KERNEL32.dll lstrcpyn
86 000BA610 BFFA142F 0262 KERNEL32.dll OutputDebugStringA
87 000BA614 BFF768A0 00D2 KERNEL32.dll DebugBreak
88 000BA618 BFF772F8 0359 KERNEL32.dll lstrcpy
89 000BA61C BFF77EB9 0111 KERNEL32.dll FileTimeToLocalFileTime
90 000BA620 BFF77F11 0112 KERNEL32.dll FileTimeToSystemTime
91 000BA624 BFF95A8E 02FE KERNEL32.dll TerminateThread
92 000BA628 BFF77F3D 00B2 KERNEL32.dll CreateDirectoryA
93 000BA62C BFFA0D34 01C8 KERNEL32.dll GetSystemTimeAsFileTime
94 000BA630 BFF8ABFA 00D6 KERNEL32.dll DeleteCriticalSection
95 000BA634 BFF842B1 020A KERNEL32.dll InitializeCriticalSection
96 000BA638 BFF76F66 00CD KERNEL32.dll CreateThread
97 000BA63C BFF813EC 015D KERNEL32.dll GetCurrentThreadId
98 000BA640 BFF92D08 02F6 KERNEL32.dll Sleep
99 000BA644 BFF7C8BD 0327 KERNEL32.dll WaitForSingleObject
100 000BA648 BFF7E06D 00A0 KERNEL32.dll CloseHandle
101 000BA64C BFF92CAF 0328 KERNEL32.dll WaitForSingleObjectEx
102 000BA650 BFF92BFF 028B KERNEL32.dll ResetEvent
103 000BA654 BFF92B8F 02CA KERNEL32.dll SetEvent
104 000BA658 BFF77590 00B6 KERNEL32.dll CreateEventA
105 000BA65C BFF776D0 0229 KERNEL32.dll LoadLibraryA
106 000BA664 6C3908A4 19FA MFC42.DLL
107 000BA668 6C375438 0D4B MFC42.DLL
108 000BA66C 6C3DB52A 10CF MFC42.DLL
109 000BA670 6C3753AE 0D16 MFC42.DLL
110 000BA674 6C3C45B1 188B MFC42.DLL
111 000BA678 6C380CCA 0441 MFC42.DLL
112 000BA67C 6C3C3B76 035B MFC42.DLL
113 000BA680 6C3814F8 1663 MFC42.DLL
114 000BA684 6C379C2B 09D0 MFC42.DLL
115 000BA688 6C3751E8 09FA MFC42.DLL

426 000BAB64 6C375C3C 0305 MFC42.DLL
427 000BAB68 6C3E7630 0E76 MFC42.DLL
428 000BAB6C 6C375836 01F5 MFC42.DLL
429 000BAB70 6C37FF44 0451 MFC42.DLL
430 000BAB74 6C373F15 039A MFC42.DLL
431 000BAB78 6C3DA477 047C MFC42.DLL
432 000BAB7C 6C37413F 03AD MFC42.DLL
433 000BAB80 6C3713B3 0D12 MFC42.DLL
434 000BAB84 6C3E014D 16D9 MFC42.DLL
435 000BAB88 6C37C181 0474 MFC42.DLL
436 000BAB8C 6C37BB36 0DC2 MFC42.DLL
437 000BAB90 6C387EBD 1903 MFC42.DLL
438 000BAB94 6C37A07D 03AB MFC42.DLL
439 000BAB98 6C381800 0B02 MFC42.DLL
440 000BAB9C 6C373EB0 0217 MFC42.DLL
441 000BABA0 6C3710F8 0497 MFC42.DLL
442 000BABA4 6C3C4132 1021 MFC42.DLL
443 000BABA8 6C382060 0ACB MFC42.DLL
444 000BABAC 6C374086 1040 MFC42.DLL
445 000BABB0 6C3FE9C2 1206 MFC42.DLL
446 000BABB4 6C3848DC 1205 MFC42.DLL
447 000BABB8 6C417CB0 0739 MFC42.DLL
448 000BABBC 6C417D10 1094 MFC42.DLL
449 000BABC0 6C374F28 096B MFC42.DLL
450 000BABC4 6C3D1AE3 11ED MFC42.DLL
451 000BABC8 6C3D194D 1323 MFC42.DLL
452 000BABCC 6C374B76 10F5 MFC42.DLL
453 000BABD0 6C374671 10FD MFC42.DLL
454 000BABD4 6C383719 131A MFC42.DLL
455 000BABD8 6C3D19D7 11B3 MFC42.DLL
456 000BABDC 6C3D19E4 11C1 MFC42.DLL
457 000BABE0 6C3D19DF 11AC MFC42.DLL
458 000BABE4 6C373FFF 095F MFC42.DLL
459 000BABE8 6C3D19DF 11AC MFC42.DLL
460 000BABEC 6C3D19DF 11AC MFC42.DLL
461 000BABF0 6C3D19D2 1361 MFC42.DLL
462 000BABF4 6C3D19D2 1361 MFC42.DLL
463 000BABF8 6C3D195C 100C MFC42.DLL
464 000BABFC 6C3E2711 1133 MFC42.DLL
465 000BAC00 6C38853D 1478 MFC42.DLL
466 000BAC04 6C3735BD 0EA4 MFC42.DLL

796 000BB12C 6C3CBD7C 18A7 MFC42.DLL
797 000BB130 6C3CBD6A 104B MFC42.DLL
798 000BB134 6C37D22B 0F21 MFC42.DLL
799 000BB138 6C3C3B8B 039B MFC42.DLL
800 000BB13C 6C38317F 17F1 MFC42.DLL
801 000BB140 6C38206E 1A06 MFC42.DLL
802 000BB144 6C3CAA2F 15CF MFC42.DLL
803 000BB148 6C3C90BD 1AE3 MFC42.DLL
804 000BB14C 6C3E7E78 0E72 MFC42.DLL
805 000BB150 6C373676 0EAA MFC42.DLL
806 000BB154 6C3D74CB 08F4 MFC42.DLL
807 000BB158 6C37EA89 0146 MFC42.DLL
808 000BB160 78003417 01B7 MSVCRT.dll _setmbcp
809 000BB164 7800AE78 004C MSVCRT.dll __CxxFrameHandler
810 000BB168 7800231A 02D6 MSVCRT.dll strncpy
811 000BB16C 780253CA 02C7 MSVCRT.dll sprintf
812 000BB170 780030B5 02AD MSVCRT.dll memmove
813 000BB174 78023383 01BB MSVCRT.dll _snprintf
814 000BB178 7802541C 02CA MSVCRT.dll sscanf
815 000BB17C 7800BDD3 00A8 MSVCRT.dll _beginthread
816 000BB180 7800C7D0 0252 MSVCRT.dll atoi
817 000BB184 7800BEDD 00C8 MSVCRT.dll _endthread
818 000BB188 7802A38B 025B MSVCRT.dll ctime
819 000BB18C 7802A875 02E5 MSVCRT.dll time
820 000BB190 780010ED 0273 MSVCRT.dll free
821 000BB194 78001BF1 00F9 MSVCRT.dll _ftol
822 000BB198 78001E18 0255 MSVCRT.dll calloc
823 000BB19C 78001000 02A6 MSVCRT.dll malloc
824 000BB1A0 7800ADBB 0044 MSVCRT.dll _CxxThrowException
825 000BB1A4 78029239 00F7 MSVCRT.dll _ftime
826 000BB1A8 78012D7C 01D3 MSVCRT.dll _strnicmp
827 000BB1AC 780029BF 02DA MSVCRT.dll strstr
828 000BB1B0 7802ED3A 0256 MSVCRT.dll ceil
829 000BB1B4 78028CEE 02DC MSVCRT.dll strtok
830 000BB1B8 780127CE 02CC MSVCRT.dll strchr
831 000BB1BC 78019F7E 01C0 MSVCRT.dll _spawnlp
832 000BB1C0 780205B7 01C6 MSVCRT.dll _splitpath
833 000BB1C4 780012EF 02FB MSVCRT.dll wcslen
834 000BB1C8 78003023 02A8 MSVCRT.dll mbstowcs
835 000BB1CC 7802109C 02B9 MSVCRT.dll qsort
836 000BB1D0 78012D00 02D0 MSVCRT.dll strcspn
837 000BB1D4 78016F5D 00E3 MSVCRT.dll _findclose
838 000BB1D8 78016E95 00E7 MSVCRT.dll _findnext
839 000BB1DC 78016DC5 00E4 MSVCRT.dll _findfirst
840 000BB1E0 78017A09 00AF MSVCRT.dll _chdir
841 000BB1E4 78012188 0261 MSVCRT.dll fclose
842 000BB1E8 78024336 0267 MSVCRT.dll fgets
843 000BB1EC 78022AA9 026C MSVCRT.dll fopen
844 000BB1F0 7800F56A 00CE MSVCRT.dll _except_handler3
845 000BB1F4 7800B20C 000E MSVCRT.dll ??1type_info@@UAE@XZ
846 000BB1F8 78002131 0058 MSVCRT.dll __dllonexit
847 000BB1FC 78004446 0192 MSVCRT.dll _onexit
848 000BB200 7800AC3F 0030 MSVCRT.dll ?terminate@@YAXXZ
849 000BB204 7800B908 00D7 MSVCRT.dll _exit
850 000BB208 7800F7DC 004B MSVCRT.dll _XcptFilter
851 000BB20C 7800269E 025E MSVCRT.dll exit
852 000BB210 7803B508 0092 MSVCRT.dll _acmdln
853 000BB214 78003E70 005B MSVCRT.dll __getmainargs
854 000BB218 78001DEA 0119 MSVCRT.dll _initterm
855 000BB21C 7800B426 0086 MSVCRT.dll __setusermatherr
856 000BB220 7803BB70 00A0 MSVCRT.dll _adjust_fdiv
857 000BB224 78003E6A 006D MSVCRT.dll __p__commode
858 000BB228 78003E64 0072 MSVCRT.dll __p__fmode
859 000BB22C 78003E5A 0084 MSVCRT.dll __set_app_type
860 000BB230 78003C1E 00BA MSVCRT.dll _controlfp
861 000BB234 7801419F 01E8 MSVCRT.dll _ultoa
862 000BB238 78004A69 013E MSVCRT.dll _itoa
863 000BB240 7FE990C2 00C8 OLEAUT32.dll GetErrorInfo
864 000BB244 7FE8227E 0009 OLEAUT32.dll VariantClear
865 000BB248 7FE81523 0006 OLEAUT32.dll SysFreeString
866 000BB24C 7FE81408 0002 OLEAUT32.dll SysAllocString
867 000BB254 7FCB734A 011D SHELL32.dll SHGetMalloc
868 000BB258 7FD07109 0109 SHELL32.dll SHBrowseForFolder
869 000BB25C 7FCB3BC4 011F SHELL32.dll SHGetPathFromIDList
870 000BB260 7FD18BE2 0148 SHELL32.dll Shell_NotifyIcon
871 000BB264 7FD16AFF 0142 SHELL32.dll ShellExecuteA
872 000BB26C BFF52471 012F USER32.dll GetParent
873 000BB270 BFF54C52 013C USER32.dll GetSysColor
874 000BB274 BFF559A1 008B USER32.dll DestroyCursor
875 000BB278 BFF51319 019B USER32.dll LoadMenuA
876 000BB27C BFF5308E 022F USER32.dll SetTimer
877 000BB280 BFF55836 01F7 USER32.dll SendMessageA
878 000BB284 BFF52DA4 011C USER32.dll GetMenuItemID
879 000BB288 BFF55413 0047 USER32.dll CopyRect
880 000BB28C BFF55102 0184 USER32.dll IsIconic
881 000BB290 BFF5249D 00F7 USER32.dll GetDC
882 000BB294 BFF52090 01E8 USER32.dll ReleaseDC
883 000BB298 BFF551F5 0102 USER32.dll GetForegroundWindow
884 000BB29C BFF555A7 014E USER32.dll GetWindowLongA
885 000BB2A0 BFF524BB 0212 USER32.dll SetForegroundWindow
886 000BB2A4 BFF520A4 00B5 USER32.dll EnableWindow
887 000BB2A8 BFF54FC5 00EB USER32.dll GetClientRect
888 000BB2AC BFF524DB 01A2 USER32.dll LockWindowUpdate
889 000BB2B0 BFF54F53 0153 USER32.dll GetWindowRect
890 000BB2B4 BFF52170 0172 USER32.dll InvalidateRect
891 000BB2B8 BFF55828 01F2 USER32.dll SendDlgItemMessageA
892 000BB2BC BFF52489 01FF USER32.dll SetActiveWindow
893 000BB2C0 BFF559F9 0195 USER32.dll LoadIconA
894 000BB2C4 BFF54EA5 0187 USER32.dll IsWindow
895 000BB2C8 BFF5156B 0239 USER32.dll SetWindowPos
896 000BB2CC BFF52130 00A4 USER32.dll DrawFocusRect
897 000BB2D0 BFF5141E 0266 USER32.dll UnregisterClassA
898 000BB2D4 BFF55BCD 0085 USER32.dll DefWindowProcA
899 000BB2D8 BFF52475 0113 USER32.dll GetLastActivePopup
900 000BB2DC BFF55918 00D3 USER32.dll FindWindowA
901 000BB2E0 BFF52DC6 0037 USER32.dll CheckMenuItem
902 000BB2E4 BFF5300E 015B USER32.dll GrayStringA
903 000BB2E8 BFF528DC 024F USER32.dll TabbedTextOutA
904 000BB2EC BFF527BB 01AA USER32.dll MapWindowPoints
905 000BB2F0 BFF553D4 0225 USER32.dll SetRect
906 000BB2F4 BFF51B3F 014A USER32.dll GetWindow
907 000BB2F8 BFF51F4A 003B USER32.dll ChildWindowFromPointEx
908 000BB2FC BFF5558C 019F USER32.dll LoadStringA
909 000BB300 BFF52485 0211 USER32.dll SetFocus
910 000BB304 BFF52176 00D2 USER32.dll FillRect
911 000BB308 BFF5548F 01C2 USER32.dll OffsetRect
912 000BB30C BFF55923 003A USER32.dll ChildWindowFromPoint
913 000BB310 BFF524D7 000E USER32.dll BringWindowToTop
914 000BB314 BFF54460 0007 USER32.dll AppendMenuA
915 000BB318 BFF520A8 017D USER32.dll IsChild
916 000BB31C BFF54706 0016 USER32.dll CallNextHookEx
917 000BB320 BFF53451 0261 USER32.dll UnhookWindowsHookEx
918 000BB324 BFF511D9 023F USER32.dll SetWindowsHookExA
919 000BB328 BFF524FB 011B USER32.dll GetMenuItemCount
920 000BB32C BFF551B1 00F9 USER32.dll GetDesktopWindow
921 000BB330 BFF55A6D 00A7 USER32.dll DrawIcon
922 000BB334 BFF54F36 00FB USER32.dll GetDlgCtrlID
923 000BB338 BFF55127 018B USER32.dll IsZoomed
924 000BB33C BFF55591 0285 USER32.dll wsprintfA
925 000BB340 BFF51BAD 018C USER32.dll KillTimer
926 000BB344 BFF54D54 0100 USER32.dll GetDoubleClickTime
927 000BB348 BFF512DE 0197 USER32.dll LoadImageA
928 000BB34C BFF55A38 018F USER32.dll LoadBitmapA
929 000BB350 BFF51670 00D4 USER32.dll FindWindowExA
930 000BB354 BFF52098 0246 USER32.dll ShowWindow
931 000BB358 BFF549C9 002A USER32.dll CharPrevA
932 000BB35C BFF5493E 0026 USER32.dll CharNextA
933 000BB360 BFF55171 018A USER32.dll IsWindowVisible
934 000BB364 BFF524EF 00DE USER32.dll GetAsyncKeyState
935 000BB368 BFF51ADA 00A6 USER32.dll DrawFrameControl
936 000BB36C BFF5447F 00AD USER32.dll DrawTextA
937 000BB370 BFF5545D 01D4 USER32.dll PtInRect
938 000BB374 BFF524E7 026A USER32.dll UpdateWindow
939 000BB378 BFF5554E 00CF USER32.dll EqualRect
940 000BB37C BFF52DCE 00B3 USER32.dll EnableMenuItem
941 000BB380 BFF550BA 003D USER32.dll ClientToScreen
942 000BB384 BFF51F2C 0280 USER32.dll WindowFromPoint
943 000BB388 BFF55A0F 0191 USER32.dll LoadCursorA
944 000BB38C BFF52D8A 0208 USER32.dll SetCursor
945 000BB390 BFF55072 01EE USER32.dll ScreenToClient
946 000BB394 BFF5248D 0200 USER32.dll SetCapture
947 000BB398 BFF523CB 01D7 USER32.dll RedrawWindow
948 000BB39C BFF51EEE 00F6 USER32.dll GetCursorPos
949 000BB3A0 BFF51B37 013B USER32.dll GetSubMenu
950 000BB3A4 BFF55708 01CF USER32.dll PostMessageA
951 000BB3A8 BFF526FC 01E7 USER32.dll ReleaseCapture
952 000BB3AC BFF552F6 013F USER32.dll GetSystemMetrics
953 000BB3B0 BFF51269 024D USER32.dll SystemParametersInfoA
954 000BB3B4 BFF524EB 010C USER32.dll GetKeyState
955 000BB3B8 BFF5412E 01AD USER32.dll MessageBoxA
956 000BB3BC BFF558C0 0017 USER32.dll CallWindowProcA
957 000BB3C0 BFF5564D 0236 USER32.dll SetWindowLongA
958 000BB3C8 BFE71267 000C VERSION.dll VerQueryValueA
959 000BB3CC BFE7152F 0001 VERSION.dll GetFileVersionInfoA
960 000BB3D0 BFE71494 0002 VERSION.dll GetFileVersionInfoSizeA
961 000BB3D8 762986ED 00EC WININET.dll InternetGetConnectedState
962 000BB3DC 7629817D 0106 WININET.dll InternetSetCookieA
963 000BB3E4 BFDF8DB3 0002 WINMM.dll PlaySoundA
964 000BB3EC 75FA159B 000B WSOCK32.dll inet_ntoa
965 000BB3F0 75FA156A 000A WSOCK32.dll inet_addr
966 000BB3F4 75FA1635 000E WSOCK32.dll ntohl
967 000BB3F8 75FA1807 0034 WSOCK32.dll gethostbyname
968 000BB3FC 75FA1661 000F WSOCK32.dll ntohs
969 000BB400 75FA18EB 0039 WSOCK32.dll gethostname
970 000BB404 75FA17D3 0033 WSOCK32.dll gethostbyaddr
971 000BB408 75FA1539 0009 WSOCK32.dll htons
972 000BB410 100029C0 0009 ecap.dll W32N_MakeNdisRequest
973 000BB414 10003640 0004 ecap.dll W32N_GetAdapterRegistryInfo
974 000BB418 10002E60 0002 ecap.dll W32N_CloseAdapter
975 000BB41C 10002840 000C ecap.dll W32N_OpenAdapterA
976 000BB420 10001A20 0008 ecap.dll W32N_IsWindowsNT
977 000BB424 10001A60 0006 ecap.dll W32N_IsWindows2000
978 000BB428 10002EA0 0003 ecap.dll W32N_DisableLoopback
979 000BB42C 10001A80 0007 ecap.dll W32N_IsWindows95
980 000BB430 10002BF0 0001 ecap.dll W32N_CancelPacketRead
981 000BB434 10002AC0 0010 ecap.dll W32N_PacketReadEx
982 000BB438 10002D60 0012 ecap.dll W32N_PacketSendEx
983 000BB43C 100019E0 000B ecap.dll W32N_OSGetPlatformVersion
984 000BB440 100019C0 0005 ecap.dll W32N_GetLastError
985 000BB448 60013320 0509 egui.dll ?

NeO'X'QuiCk
April 5th, 2001, 11:37
PreCreateWindow@CCJFrameWnd@@MAEHAAUtagCREATESTRUCTA@@I@Z
986 000BB44C 600452C0 071E egui.dll ?messageMap@CCJFrameWnd@@1UAFX_MSGMAP@@B
987 000BB450 600452A8 06E7 egui.dll ?classCCJFrameWnd@CCJFrameWnd@@2UCRuntimeClass@@B
988 000BB454 60012C90 0179 egui.dll ?DockControlBarLeftOf@CCJFrameWnd@@UAEXPAVCControlBar@@0@Z
989 000BB458 60031C90 0043 egui.dll ??0CCJTreeCtrl@@QAE@XZ
990 000BB45C 60031D90 0088 egui.dll ??1CCJTreeCtrl@@UAE@XZ
991 000BB460 60044D98 071B egui.dll ?messageMap@CCJFlatSplitterWnd@@1UAFX_MSGMAP@@B
992 000BB464 6000F650 03FD egui.dll ?OnDrawSplitter@CCJFlatSplitterWnd@@UAEXPAVCDC@@W4ESplitType@CSplitterWnd@@ABVCRect@@@Z
993 000BB468 6000F550 0171 egui.dll ?DisableFlatStyle@CCJFlatSplitterWnd@@UAEXH@Z
994 000BB46C 6000FF70 0633 egui.dll ?SwitchView@CCJFlatSplitterWnd@@UAEHHHPAVCView@@@Z
995 000BB470 6000FE40 053F egui.dll ?ReplaceView@CCJFlatSplitterWnd@@UAEHHHPAUCRuntimeClass@@@Z
996 000BB474 6000FD20 061D egui.dll ?ShowColumn@CCJFlatSplitterWnd@@UAEXXZ
997 000BB478 6000FC10 032D egui.dll ?HideColumn@CCJFlatSplitterWnd@@UAEXH@Z
998 000BB47C 6000FB00 0621 egui.dll ?ShowRow@CCJFlatSplitterWnd@@UAEXXZ
999 000BB480 6000FA00 032F egui.dll ?HideRow@CCJFlatSplitterWnd@@UAEXH@Z
1000 000BB484 6003D090 0085 egui.dll ??1CCJToolBar@@UAE@XZ
1001 000BB488 6003CED0 0040 egui.dll ??0CCJToolBar@@QAE@XZ
1002 000BB48C 6003E420 02E2 egui.dll ?GetRuntimeClass@CCJToolBar@@UBEPAUCRuntimeClass@@XZ
1003 000BB490 6003D2A0 050E egui.dll ?PreCreateWindow@CCJToolBar@@UAEHAAUtagCREATESTRUCTA@@@Z
1004 000BB494 6003C4F0 04E6 egui.dll ?OnToolHitTest@CCJToolBar@@UBEHVCPoint@@PAUtagTOOLINFOA@@@Z
1005 000BB498 60012E60 01AC egui.dll ?EnableDockingSizeBar@CCJFrameWnd@@UAEXKW4DockFlatBorders@1@@Z
1006 000BB49C 60012F90 017D egui.dll ?DockSizeBar@CCJFrameWnd@@UAEXPAVCControlBar@@PAVCCJSizeDockBar@@PAUtagRECT@@@Z
1007 000BB4A0 6003C3D0 0119 egui.dll ?CalcDynamicLayout@CCJToolBar@@UAE?AVCSize@@HK@Z
1008 000BB4A4 6003CC50 04ED egui.dll ?OnUpdateCmdUI@CCJToolBar@@UAEXPAVCFrameWnd@@H@Z
1009 000BB4A8 6003C970 03CF egui.dll ?OnBarStyleChange@CCJToolBar@@UAEXKK@Z
1010 000BB4AC 60031360 0177 egui.dll ?DoPaint@CCJToolBarBase@@UAEXPAVCDC@@@Z
1011 000BB4B0 60026F40 0077 egui.dll ??1CCJReBar@@UAE@XZ
1012 000BB4B4 600393F0 008D egui.dll ??1CGfxSplitterWnd@@UAE@XZ
1013 000BB4B8 60012B80 0062 egui.dll ??1CCJFrameWnd@@UAE@XZ
1014 000BB4BC 60026F80 002F egui.dll ??0CCJReBar@@QAE@XZ
1015 000BB4C0 60039300 004A egui.dll ??0CGfxSplitterWnd@@QAE@XZ
1016 000BB4C4 60012AA0 0018 egui.dll ??0CCJFrameWnd@@QAE@XZ
1017 000BB4C8 60030E90 0086 egui.dll ??1CCJToolBarBase@@UAE@XZ
1018 000BB4CC 60027230 00E1 egui.dll ?AddBar@CCJReBar@@QAEHPAVCWnd@@PBDPAVCBitmap@@K@Z
1019 000BB4D0 600274E0 0145 egui.dll ?Create@CCJReBar@@QAEHPAVCWnd@@KKI@Z
1020 000BB4D4 6001EC00 0351 egui.dll ?Insert@CCJMemFile@@UAEKPAVCFile@@KKK@Z
1021 000BB4D8 60024C00 0399 egui.dll ?LoadMenuA@CCJMenuBar@@QAEHI@Z
1022 000BB4DC 6003D790 00E7 egui.dll ?AddDropDownButton@CCJToolBar@@QAEHIIH@Z
1023 000BB4E0 6003E060 039C egui.dll ?LoadToolBar@CCJToolBar@@QAEHPBDPAUTOOLBARINFO@@@Z
1024 000BB4E4 600132F0 03DC egui.dll ?OnClose@CCJFrameWnd@@IAEXXZ
1025 000BB4E8 6001F360 0641 egui.dll ?UpdateDiskFile@CCJMemFile@@QAEXXZ
1026 000BB4EC 6001EF30 01BD egui.dll ?Extract@CCJMemFile@@UAEKPAVCFile@@KK@Z
1027 000BB4F0 6003C3A0 011D egui.dll ?CalcFixedLayout@CCJToolBar@@UAE?AVCSize@@HH@Z
1028 000BB4F4 60030EE0 0650 egui.dll ?WindowProc@CCJToolBarBase@@UAEJIIJ@Z
1029 000BB4F8 6001E5D0 0653 egui.dll ?WriteString@CCJMemFile@@UAEXPBDH@Z
1030 000BB4FC 6001E7C0 04FD egui.dll ?Open@CCJMemFile@@UAE_NVCString@@IPAVCFileException@@@Z
1031 000BB500 6001EB60 00F3 egui.dll ?Append@CCJMemFile@@MAE_NPAVCFile@@@Z
1032 000BB504 6001EAB0 0341 egui.dll ?Import@CCJMemFile@@MAE_NPAVCFile@@@Z
1033 000BB508 6001E860 0546 egui.dll ?Save@CCJMemFile@@MAE_NXZ
1034 000BB50C 6001E9B0 038B egui.dll ?Load@CCJMemFile@@MAE_NXZ
1035 000BB510 6001EA50 012D egui.dll ?Close@CCJMemFile@@UAEXXZ
1036 000BB514 6001EA80 01CA egui.dll ?Flush@CCJMemFile@@UAEXXZ
1037 000BB518 6001E3D0 0025 egui.dll ??0CCJMemFile@@QAE@PBDI@Z
1038 000BB51C 6001E460 006D egui.dll ??1CCJMemFile@@UAE@XZ
1039 000BB520 6003C470 0571 egui.dll ?SetButtonInfo@CCJToolBar@@QAEXHIIH@Z
1040 000BB524 6003C420 01E6 egui.dll ?GetButtonInfo@CCJToolBar@@QBEXHAAI0AAH@Z
1041 000BB528 60039D40 061F egui.dll ?ShowColumn@CGfxSplitterWnd@@QAEXXZ
1042 000BB52C 60039C70 032E egui.dll ?HideColumn@CGfxSplitterWnd@@QAEXH@Z
1043 000BB530 6003E2C0 057A egui.dll ?SetButtons@CCJToolBar@@QAEHPBIH@Z
1044 000BB534 6003E180 0390 egui.dll ?LoadBitmapA@CCJToolBar@@QAEHPBD@Z
1045 000BB538 60034560 014B egui.dll ?Create@CGfxOutBarCtrl@@UAEHKABUtagRECT@@PAVCWnd@@IK@Z
1046 000BB53C 600345A0 0382 egui.dll ?IsSmallIconView@CGfxOutBarCtrl@@UBE_NXZ
1047 000BB540 600345B0 05F8 egui.dll ?SetSmallIconView@CGfxOutBarCtrl@@UAEX_N@Z
1048 000BB544 60034650 021D egui.dll ?GetFlag@CGfxOutBarCtrl@@UBEKXZ
1049 000BB548 60034660 03AE egui.dll ?ModifyFlag@CGfxOutBarCtrl@@UAEXABK0I@Z
1050 000BB54C 60034ED0 0223 egui.dll ?GetFolderRect@CGfxOutBarCtrl@@UBE_NHAAVCRect@@@Z
1051 000BB550 60034F90 024D egui.dll ?GetItemRect@CGfxOutBarCtrl@@UAEXHHAAVCRect@@@Z
1052 000BB554 60035350 00E8 egui.dll ?AddFolder@CGfxOutBarCtrl@@UAEHPBDK@Z
1053 000BB558 60035520 023F egui.dll ?GetInsideRect@CGfxOutBarCtrl@@UBEXAAVCRect@@@Z
1054 000BB55C 60035610 033C egui.dll ?HitTestEx@CGfxOutBarCtrl@@UAEHABVCPoint@@AAH@Z
1055 000BB560 60035830 0330 egui.dll ?HighlightFolder@CGfxOutBarCtrl@@UAEXH@Z
1056 000BB564 60036A10 035B egui.dll ?InsertItem@CGfxOutBarCtrl@@UAEHHHPBDHK@Z
1057 000BB568 60036A40 0246 egui.dll ?GetItemCount@CGfxOutBarCtrl@@UBEHXZ
1058 000BB56C 60036A60 05F1 egui.dll ?SetSelFolder@CGfxOutBarCtrl@@UAEXH@Z
1059 000BB570 60036B60 021F egui.dll ?GetFolderCount@CGfxOutBarCtrl@@UBEHXZ
1060 000BB574 60036B70 02E8 egui.dll ?GetSelFolder@CGfxOutBarCtrl@@UBEHXZ
1061 000BB578 60036B80 0538 egui.dll ?RemoveFolder@CGfxOutBarCtrl@@UAEXH@Z
1062 000BB57C 60036CB0 01FF egui.dll ?GetCountPerPage@CGfxOutBarCtrl@@UBEHXZ
1063 000BB580 60036CC0 05B7 egui.dll ?SetImageList@CGfxOutBarCtrl@@UAEPAVCImageList@@PAV2@H@Z
1064 000BB584 60036D30 05A4 egui.dll ?SetFolderImageList@CGfxOutBarCtrl@@UAEPAVCImageList@@HPAV2@H@Z
1065 000BB588 60036D00 0239 egui.dll ?GetImageList@CGfxOutBarCtrl@@UAEPAVCImageList@@PAV2@H@Z
1066 000BB58C 60036E30 0500 egui.dll ?PaintItems@CGfxOutBarCtrl@@UAEXPAVCDC@@HVCRect@@@Z
1067 000BB590 60036F60 024E egui.dll ?GetItemSize@CGfxOutBarCtrl@@UAE?AVCSize@@HHH@Z
1068 000BB594 60013120 034B egui.dll ?InitializeMenu@CCJFrameWnd@@UAEHIPAIH@Z
1069 000BB598 60012D30 01A8 egui.dll ?EnableDocking@CCJFrameWnd@@UAEXK@Z
1070 000BB59C 60037560 0321 egui.dll ?GetVisibleRange@CGfxOutBarCtrl@@UAEXHAAH0@Z
1071 000BB5A0 60037670 0331 egui.dll ?HighlightItem@CGfxOutBarCtrl@@UAEXH_N@Z
1072 000BB5A4 60037910 0232 egui.dll ?GetIconRect@CGfxOutBarCtrl@@UAEXHHAAVCRect@@@Z
1073 000BB5A8 60037A90 0250 egui.dll ?GetLabelRect@CGfxOutBarCtrl@@UAEXHHAAVCRect@@@Z
1074 000BB5AC 60037C40 062C egui.dll ?StartGroupEdit@CGfxOutBarCtrl@@UAEXH@Z
1075 000BB5B0 6001E4E0 0528 egui.dll ?ReadString@CCJMemFile@@UAEHAAVCString@@@Z
1076 000BB5B4 60012F50 0529 egui.dll ?RecalcAllExcept@CCJFrameWnd@@UAEXPAVCCJSizeDockBar@@@Z
1077 000BB5B8 600344E0 05C4 egui.dll ?SetItemText@CGfxOutBarCtrl@@UAEXHPBD@Z
1078 000BB5BC 600380E0 0539 egui.dll ?RemoveItem@CGfxOutBarCtrl@@UAEXH@Z
1079 000BB5C0 60038150 0385 egui.dll ?IsValidItem@CGfxOutBarCtrl@@UBE_NH@Z
1080 000BB5C4 60038180 0247 egui.dll ?GetItemData@CGfxOutBarCtrl@@UBEKH@Z
1081 000BB5C8 600381C0 024A egui.dll ?GetItemImage@CGfxOutBarCtrl@@UBEHH@Z
1082 000BB5CC 60038200 05C1 egui.dll ?SetItemData@CGfxOutBarCtrl@@UAEXHK@Z
1083 000BB5D0 60038240 05C3 egui.dll ?SetItemImage@CGfxOutBarCtrl@@UAEXHH@Z
1084 000BB5D4 60038280 0192 egui.dll ?DrawDragArrow@CGfxOutBarCtrl@@UAEXPAVCDC@@HH@Z
1085 000BB5D8 60038660 020B egui.dll ?GetDragItemRect@CGfxOutBarCtrl@@UAEHHAAVCRect@@@Z
1086 000BB5DC 60038790 00F2 egui.dll ?AnimateFolderScroll@CGfxOutBarCtrl@@UAEXHH@Z
1087 000BB5E0 600339D0 01D2 egui.dll ?GetAnimationTickCount@CGfxOutBarCtrl@@UAEJXZ
1088 000BB5E4 60013270 0519 egui.dll ?PreTranslateMessage@CCJFrameWnd@@UAEHPAUtagMSG@@@Z
1089 000BB5E8 600390B0 024F egui.dll ?GetItemText@CGfxOutBarCtrl@@UAE?AVCString@@H@Z
1090 000BB5EC 60039160 00E9 egui.dll ?AddFolderBar@CGfxOutBarCtrl@@UAEHPBDPAVCWnd@@K@Z
1091 000BB5F0 600391F0 021E egui.dll ?GetFolderChild@CGfxOutBarCtrl@@UAEPAVCWnd@@H@Z
1092 000BB5F4 60039230 0220 egui.dll ?GetFolderData@CGfxOutBarCtrl@@UAEKH@Z
1093 000BB5F8 60039250 055F egui.dll ?SetAnimSelHighlight@CGfxOutBarCtrl@@UAEXH@Z
1094 000BB5FC 60034820 0183 egui.dll ?DrawAnimItem@CGfxOutBarCtrl@@UAEXHHH@Z
1095 000BB600 60033F70 02E5 egui.dll ?GetRuntimeClass@CGfxOutBarCtrl@@UBEPAUCRuntimeClass@@XZ
1096 000BB604 60033F80 0049 egui.dll ??0CGfxOutBarCtrl@@QAE@XZ
1097 000BB608 60034250 008C egui.dll ??1CGfxOutBarCtrl@@UAE@XZ
1098 000BB60C 600491F8 073B egui.dll ?messageMap@CGfxOutBarCtrl@@1UAFX_MSGMAP@@B
1099 000BB610 6000DAE0 0645 egui.dll ?UpdateFont@CCJFlatButton@@MAEXXZ
1100 000BB614 6000DA30 0187 egui.dll ?DrawButtonBitmap@CCJFlatButton@@MAEXPAVCDC@@IAAVCRect@@@Z
1101 000BB618 6000D810 018B egui.dll ?DrawButtonText@CCJFlatButton@@MAEXPAVCDC@@IAAVCRect@@@Z
1102 000BB61C 6000D940 0189 egui.dll ?DrawButtonIcon@CCJFlatButton@@MAEXPAVCDC@@IAAVCRect@@@Z
1103 000BB620 60002100 05B1 egui.dll ?SetIcon@CCJFlatButton@@UAEXPAUHICON__@@VCSize@@@Z
1104 000BB624 60002130 05B0 egui.dll ?SetIcon@CCJFlatButton@@UAEXPAUHICON__@@0VCSize@@@Z
1105 000BB628 600020E0 0170 egui.dll ?DisableFlatLook@CCJFlatButton@@UAEXH@Z
1106 000BB62C 6000D6D0 055D egui.dll ?SetAlternateColors@CCJFlatButton@@UAEXKKKK@Z
1107 000BB630 60002160 0570 egui.dll ?SetButtonFont@CCJFlatButton@@UAEXPAVCFont@@@Z
1108 000BB634 6000D710 0199 egui.dll ?DrawItem@CCJFlatButton@@UAEXPAUtagDRAWITEMSTRUCT@@@Z
1109 000BB638 6003D180 0149 egui.dll ?Create@CCJToolBar@@UAEHPAVCWnd@@KI@Z
1110 000BB63C 6003D1D0 014F egui.dll ?CreateEx@CCJToolBar@@UAEHPAVCWnd@@KKVCRect@@I@Z
1111 000BB640 6003BAF0 024C egui.dll ?GetItemRect@CCJToolBar@@UBEXHPAUtagRECT@@@Z
1112 000BB644 6003D9A0 036B egui.dll ?InvalidateOldPos@CCJToolBar@@UAEXABVCRect@@@Z
1113 000BB648 6003DA90 01EA egui.dll ?GetButtonSize@CCJToolBar@@UAE?AVCSize@@PAU_TBBUTTON@@H@Z
1114 000BB64C 6003D8A0 03FF egui.dll ?OnDropDownButton@CCJToolBar@@UAEXABUtagNMTOOLBARA@@IVCRect@@@Z
1115 000BB650 60048780 0736 egui.dll ?messageMap@CCJToolBar@@1UAFX_MSGMAP@@B
1116 000BB654 60003340 04FE egui.dll ?OpenWindow@CCJCaption@@QAEXXZ
1117 000BB658 600024E0 0004 egui.dll ??0CCJCaption@@QAE@XZ
1118 000BB65C 6000F570 0015 egui.dll ??0CCJFlatSplitterWnd@@QAE@XZ
1119 000BB660 60002660 0050 egui.dll ??1CCJCaption@@UAE@XZ
1120 000BB664 6000F620 005F egui.dll ??1CCJFlatSplitterWnd@@UAE@XZ
1121 000BB668 6001A990 03EE egui.dll ?OnCustomDraw@CCJListView@@IAEXPAUtagNMHDR@@PAJ@Z
1122 000BB66C 6001B2F0 03F5 egui.dll ?OnDestroy@CCJListView@@IAEXXZ
1123 000BB670 60021210 03B0 egui.dll ?ModifyODMenuA@CCJMenu@@QAEHPBDIH@Z
1124 000BB674 60021990 039D egui.dll ?LoadToolbar@CCJMenu@@QAEHI@Z
1125 000BB678 6001B550 04E7 egui.dll ?OnUpdate@CCJListView@@MAEXPAVCView@@JPAVCObject@@@Z
1126 000BB67C 6001B560 061E egui.dll ?ShowColumn@CCJListView@@QAEXHH@Z
1127 000BB680 6001B5B0 0109 egui.dll ?AutoSaveColumnsOrder@CCJListView@@QAEXPBD0@Z
1128 000BB684 6001A7D0 0434 egui.dll ?OnInitialUpdate@CCJListView@@UAEXXZ
1129 000BB688 6001A470 001E egui.dll ??0CCJListView@@QAE@XZ
1130 000BB68C 6001F5C0 0026 egui.dll ??0CCJMenu@@QAE@XZ
1131 000BB690 6001A680 0068 egui.dll ??1CCJListView@@UAE@XZ
1132 000BB694 6001F720 006E egui.dll ??1CCJMenu@@UAE@XZ
1133 000BB698 6001AA30 0481 egui.dll ?OnNotify@CCJListView@@MAEHIJPAJ@Z
1134 000BB69C 6001B240 02F5 egui.dll ?GetStoredWidth@CCJListView@@UAEHH@Z
1135 000BB6A0 6001B320 010C egui.dll ?AutoSizeColumn@CCJListView@@UAEXH@Z
1136 000BB6A4 6001B1D0 0586 egui.dll ?SetColumnWidth@CCJListView@@UAEXH@Z
1137 000BB6A8 6001B170 0393 egui.dll ?LoadColumnWidths@CCJListView@@UAEXXZ
1138 000BB6AC 6001B050 054B egui.dll ?SaveColumnWidths@CCJListView@@UAEXXZ
1139 000BB6B0 6001AFC0 0108 egui.dll ?AutoSaveColumns@CCJListView@@UAEXPBD00@Z
1140 000BB6B4 6001AF10 0632 egui.dll ?SubclassHeader@CCJListView@@UAE_N_N@Z
1141 000BB6B8 6001AB70 0628 egui.dll ?SortList@CCJListView@@UAE_NH_N@Z
1142 000BB6BC 6001A380 05A0 egui.dll ?SetExtendedStyle@CCJListView@@UAEXK@Z
1143 000BB6C0 6001A360 0213 egui.dll ?GetExtendedStyle@CCJListView@@UAEKXZ
1144 000BB6C4 6001A3E0 016F egui.dll ?DisableColumnSizing@CCJListView@@UAEX_N@Z
1145 000BB6C8 6001A3D0 05D2 egui.dll ?SetMinimumColSize@CCJListView@@UAEXH@Z
1146 000BB6CC 6001AD70 033B egui.dll ?HitTestEx@CCJListView@@UBEHAAVCPoint@@PAH@Z
1147 000BB6D0 6001ABF0 00E5 egui.dll ?AddColumn@CCJListView@@UAEHPBDHH@Z
1148 000BB6D4 6001AC70 0113 egui.dll ?BuildColumns@CCJListView@@UAE_NHPAH0@Z
1149 000BB6D8 6001AD20 0114 egui.dll ?BuildColumns@CCJListView@@UAE_NHPAHPAVCString@@@Z
1150 000BB6DC 6001A3B0 05EC egui.dll ?SetRowColors@CCJListView@@UAEXKK@Z
1151 000BB6E0 6001A960 01FC egui.dll ?GetColumnCount@CCJListView@@UBEHXZ
1152 000BB6E4 6001A860 0134 egui.dll ?CopyRow@CCJListView@@UAE_NHH@Z
1153 000BB6E8 6001A7E0 03BE egui.dll ?MoveRow@CCJListView@@UAE_NHH@Z
1154 000BB6EC 6000D330 0012 egui.dll ??0CCJFlatButton@@QAE@XZ
1155 000BB6F0 6000D480 005C egui.dll ??1CCJFlatButton@@UAE@XZ
1156 000BB6F4 60001BA0 0002 egui.dll ??0CCJBrowseEdit@@QAE@XZ
1157 000BB6F8 600132B0 038D egui.dll ?LoadBarState@CCJFrameWnd@@UAEXPBD@Z
1158 000BB6FC 600130B0 034A egui.dll ?InitializeMenu@CCJFrameWnd@@UAEHII@Z
1159 000BB700 600132D0 0548 egui.dll ?SaveBarState@CCJFrameWnd@@UBEXPBD@Z
1160 000BB704 600371E0 0221 egui.dll ?GetFolderImageList@CGfxOutBarCtrl@@UBEPAVCImageList@@H_N@Z
1161 000BB708 60037220 019F egui.dll ?DrawItem@CGfxOutBarCtrl@@UAEXPAVCDC@@HVCRect@@H_N@Z
1162 000BB70C 60012E40 052D egui.dll ?RecalcLayout@CCJFrameWnd@@UAEXH@Z
1163 000BB710 60001C90 004E egui.dll ??1CCJBrowseEdit@@UAE@XZ
1164 000BB714 600337B0 064C egui.dll ?WindowCenter@@YAXPAUHWND__@@@Z
1165 000BB718 60019F40 05BF egui.dll ?SetItemColor@CCJListCtrl@@QAEXHK@Z
1166 000BB71C 60018F80 001D egui.dll ??0CCJListCtrl@@QAE@XZ
1167 000BB720 600190E0 0067 egui.dll ??1CCJListCtrl@@UAE@XZ
1168 000BB724 60003B30 0007 egui.dll ??0CCJColorPicker@@QAE@XZ
1169 000BB728 6001BD60 0022 egui.dll ??0CCJMaskEdit@@QAE@XZ
1170 000BB72C 60003C70 0053 egui.dll ??1CCJColorPicker@@UAE@XZ
1171 000BB730 6001BED0 006C egui.dll ??1CCJMaskEdit@@UAE@XZ
1172 000BB734 60033820 03A0 egui.dll ?LoadWindowTopLeft@CCJWindowPlacement@@QAEHPAVCWnd@@PBD11@Z
1173 000BB738 60033420 0045 egui.dll ??0CCJWindowPlacement@@QAE@XZ
1174 000BB73C 600334B0 0089 egui.dll ??1CCJWindowPlacement@@UAE@XZ
1175 000BB740 60013070 03C5 egui.dll ?NewMenu@CCJFrameWnd@@MAEPAUHMENU__@@IPAIH@Z
1176 000BB744 60013030 03C4 egui.dll ?NewMenu@CCJFrameWnd@@MAEPAUHMENU__@@II@Z
1177 000BB748 60034470 05A5 egui.dll ?SetFolderText@CGfxOutBarCtrl@@UAEXHPBD@Z
1178 000BB74C 60037D10 062D egui.dll ?StartItemEdit@CGfxOutBarCtrl@@UAEXH@Z
1179 000BB750 600339C0 0560 egui.dll ?SetAnimationTickCount@CGfxOutBarCtrl@@UAEXJ@Z
1180 000BB754 6000D510 026D egui.dll ?GetMessageMap@CCJFlatButton@@MBEPBUAFX_MSGMAP@@XZ
1181 000BB758 6002D340 053C egui.dll ?RemovePane@CCJStatusBar@@UAEXH@Z
1182 000BB75C 6002D010 02F3 egui.dll ?GetStatusPane@CCJStatusBar@@UAEHHAAVCCJStatusBarPane@@@Z
1183 000BB760 6002D060 00EB egui.dll ?AddIndicator@CCJStatusBar@@UAEHHI@Z
1184 000BB764 6002CFC0 05E0 egui.dll ?SetPaneWidth@CCJStatusBar@@UAEXHH@Z
1185 000BB768 6002CF20 00E6 egui.dll ?AddControl@CCJStatusBar@@UAEHPAVCWnd@@HH@Z
1186 000BB76C 6002CEE0 02A6 egui.dll ?GetPanControl@CCJStatusBar@@UAEPAVCCJStatusBarPaneControlInfo@@H@Z
1187 000BB770 6002CDE0 0504 egui.dll ?PositionControls@CCJStatusBar@@UAEXXZ
1188 000BB774 6002CD80 02DC egui.dll ?GetRuntimeClass@CCJStatusBar@@UBEPAUCRuntimeClass@@XZ
1189 000BB778 6002CB50 0038 egui.dll ??0CCJStatusBar@@QAE@XZ
1190 000BB77C 6002CC10 007E egui.dll ??1CCJStatusBar@@UAE@XZ
1191 000BB780 60017D20 001B egui.dll ??0CCJHyperLink@@QAE@XZ
1192 000BB784 60017E50 0065 egui.dll ??1CCJHyperLink@@UAE@XZ
1193 000BB788 600135C0 0063 egui.dll ??1CCJHexEdit@@UAE@XZ
1194 000BB78C 60013430 0019 egui.dll ??0CCJHexEdit@@QAE@XZ
1195 000BB790 60016020 0542 egui.dll ?ResetColors@CCJHexEdit@@QAEXXZ
1196 000BB794 60016050 012B egui.dll ?Clear@CCJHexEdit@@QAEXXZ
1197 000BB798 60015E20 0581 egui.dll ?SetColor@CCJHexEdit@@QAEXHHKK@Z
1198 000BB79C 600101B0 0060 egui.dll ??1CCJFlatTabCtrl@@UAE@XZ
1199 000BB7A0 6001A7C0 03FC egui.dll ?OnDraw@CCJListView@@MAEXPAVCDC@@@Z
1200 000BB7A4 60010020 0016 egui.dll ??0CCJFlatTabCtrl@@QAE@XZ
1201 000BB7A8 6001E730 01A3 egui.dll ?Duplicate@CCJMemFile@@UAE_NVCString@@@Z
1202 000BB7AC 6001E690 01A2 egui.dll ?Duplicate@CCJMemFile@@UAE_NPAVCFile@@@Z
1203 000BB7B0 6001EAA0 0172 egui.dll ?Discard@CCJMemFile@@UAE_NXZ
1204 000BB7B4 6001EE90 0352 egui.dll ?Insert@CCJMemFile@@UAEKVCString@@KKK@Z
1205 000BB7B8 6001F020 01BE egui.dll ?Extract@CCJMemFile@@UAEKVCString@@KK@Z
1206 000BB7C0 7FF2C97D 0012 ole32.dll CoCreateInstance
1207 000BB7C8 61010590 0001 proto.dll ?Analyze@CProtoApp@@QAEPAUPKT_INFO@@PAEH@Z
1208 000BB7CC 61020690 0002 proto.dll ?Proto@@3VCProtoApp@@A
1209 000BB7D4 77032BA8 0016 urlmon.dll CreateURLMoniker


As you can see there are some missing from 106 to 807!SO dont think that i right.i could get then with trace and not even with REsolve again!




That was the problem but i think that this target is easyer the Risc SEtlerss 3!


NeO

tsehp
April 5th, 2001, 18:00
you only see mfc42 exports here, with ordinals numbers. those are not missing names or iat's but only exported functions by ordinals, and there are a lot on those horrible m$ mfc classes.

If an iat needs to be resolved again, it's because no name/ordinal
appears in the list, but a valid api address is there, so this address was generally just redirected.

Otherwise, the address needs to be traced, meaning that the entry
needs to be decrypted/demangled.

But in your case, all the entries all filled.