etermproxy.exe

First submission 2024-10-15 18:21:16

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 2756.0 KB (2822144 bytes)
Compile time: 2024-09-03 16:05:44
MD5: d83c3a49036fa08e25465e0b9f7ba110
SHA1: fca90cbfc04f1f04406e3816c988eb2292eeaa4c
SHA256: eec3465923bf6b5dd10a7dd9437687342b6278d2709b0840731e77d53571c29e
Import Hash : f6ec3752075eb089e829965159851b5c
Sections 4 .text .rdata .data .rsrc
Directories 3 import export resource

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 24/77 VT report date: 2024-09-12 13:14:56
Malware Type 1 trojan
Threat Type 1 zusy

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://pid.fly160.com/download/etermproxy.exe VirusTotal Report pid.fly160.com VirusTotal Report 2024-10-15 18:21:16

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x1c4468 1855488 e7d54a125194455e95d9a276f4ac45e3124d8847 9e297beb95791ae60c5faf387645d979
.rdata 0x1c6000 0x3f98b 262144 875525e0e3e807bcc3d53957ce22b40beb63cd37 c6a9989df597ee1c9a486fd3e6293186
.data 0x206000 0x36efc 196608 97d49d18d48042190dde25e3121572fdc3f7d913 5924918e2372410bfd761235ca4e408b
.rsrc 0x23d000 0x7acd0 503808 340cfb796b27c5c6fb404bc90ac364829ec3494b 67e1d3a89f6286cc9d08d58541b1d652

PE Resources 15

Name Language Sublanguage Offset Size Data
CERT LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2772f8 1690
CODE_VERIFY LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x278578 1015
HZ_MAP LANG_ENGLISH SUBLANG_ENGLISH_US 0x278970 256459
RT_CURSOR LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x278428 308
RT_BITMAP LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x25de80 45796
RT_ICON LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2415a8 296
RT_MENU LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x269678 60
RT_DIALOG LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x276df0 434
RT_STRING LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2b78c0 110
RT_ACCELERATOR LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2696b8 112
RT_GROUP_CURSOR LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x278560 20
RT_GROUP_ICON LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2416d0 34
RT_VERSION LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x276fa8 848
None LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x2783e0 69
None LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0x269168 46

Meta infos 13

LegalCopyright: \x7248\x6743\x6240\x6709 (C) 2012
InternalName: ETermProxy
FileVersion: 2.10.012
FileDescription: PID\x7ba1\x7406\x7cfb\x7edf
SpecialBuild: 20120905
CompanyName:
LegalTrademarks:
Comments: 2012\x5e749\x67085\x65e5\x53d1\x5e03
ProductName: PID\x7ba1\x7406\x7cfb\x7edf
ProductVersion: 2.10.012
PrivateBuild: 20120905
Translation: 0x0804 0x04b0
OriginalFilename: ETermProxy.EXE

Packers detected 3

Microsoft Visual C++ v6.0
Microsoft Visual C++ 5.0
Microsoft Visual C++

Anti debug functions 2

FindWindowA
GetLastError

Strings analysis - File found

Binary
data_v1.bin
pdsys.bin
\pdsys.bin
XML
c:\test.xml
Text
%s%d%02d%02d-ShiXinRen.txt
c:\SK.txt
%s%d%02d_flow_ctrl.txt
c:\eterm.txt
c:\test.txt
%s%d%02d%02d-%s-%s.txt
%s%s-%s-%d%02d%02d.txt
%ssql-command-%d%02d%02d.txt
Library
ADVAPI32.dll
WSOCK32.dll
SHELL32.dll
md5lib.dll
USER32.dll
KERNEL32.dll
ssleay32.dll
libssl.dll
libeay32.dll
MSVCRT.dll
WININET.dll
XTP9601Lib.dll
OLEAUT32.dll
SESDKDummy.dll
ole32.dll
MFC42.DLL
GDI32.dll

Strings analysis - Possible IPs found 5

122.119.97.12
202.106.139.18
10.0.0.1
222.178.68.131
127.0.0.1

Strings analysis - Possible URLs found 27

http://web.travelsky.com/
http://www.myair.cn&Menu=yes
http://www.info-bird.com/
http://www.myair.cn
http://www.sunstn.com
http://web.travelsky.com/TravelWeb/login/isLoginAction.do
http://web.travelsky.com/TravelWeb/jsp/login/Download.jsp
http://%s/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=xepnr&pnr=%s
http://eterm2.info-bird.com/IBBD2008/WebService/BaseDataInterface.asmx
http://www.sunstn.com.cn&Menu=yes
http://web.travelsky.com/TravelWeb/jsp/login/login.jsp
http://127.0.0.1:%d/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=tsl&tslr=1&date=%d&device=%s
http://www.hangyi365.com.cn&Menu=yes
http://www.hangyi365.com
http://%s?client=%s&cmd=%s
http://127.0.0.1:352/ib_internal_req.asp?cmd=itinni_internal&ni=%s&uid=%s&sessionid=0&verify=0
http://127.0.0.1:%d/ib_internal_req.asp?uid=%s&termid=rtkt&sessionid=0&verify=0&cmd=RTKT&ticket=%s
http://127.0.0.1:%d/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=detr&ticket=%s
http://127.0.0.1:%d/ib_tranx_req.asp?cmd=xepnr&uid=xe_user&sessionid=0&termid=%s&verify=0&pnr=%s
http://web2.travelsky.com/TravelWeb/etermConfig.do?method=queryEtermConfig
http://www.fly160.com/download
http://pid.fly160.com/download/etermproxy.exe
http://%s?cmd=%s
http://127.0.0.1:%d/ib_internal_req.asp?uid=qt_uid&termid=qt_term&sessionid=%s&cmd=qt&office_code=%s&type=%s&si=%s&cl=%d
http://%s/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=rt_parse&pnr=%s
http://%s/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=rt_parse&pnr=%s&get_rawdata=1&no_pn=1
http://%s/ib_internal_req.asp?uid=%s&sessionid=0&verify=0&cmd=rtu&pnr=%s&rawdata=1

Import functions

PE Exports 277 suspicious

Function Address
??0CAdoCommand@@QAE@ABV0@@Z 0x401830
??0CAdoCommand@@QAE@PAVCAdoConnection@@VCString@@W4CommandTypeEnum@ADODB@@@Z 0x4e0d60
??0CAdoCommand@@QAE@XZ 0x4e0c30
??0CAdoConnection@@QAE@ABV0@@Z 0x401980
??0CAdoConnection@@QAE@XZ 0x4debd0
??0CAdoRecordSet@@QAE@ABV0@@Z 0x401690
??0CAdoRecordSet@@QAE@PAVCAdoConnection@@@Z 0x4e27c0
??0CAdoRecordSet@@QAE@XZ 0x4e2670
??0CClientInfo@@QAE@XZ 0x401a90
??0CClientObject@@QAE@H@Z 0x4e9af0
??0CClientSock@@QAE@XZ 0x4e9ee0
??0CDBConnCollect@@QAE@XZ 0x4dcb20
??0CListenObject@@QAE@ABV0@@Z 0x401b20
??0CListenObject@@QAE@H@Z 0x4ea9c0
??0CListenSock@@QAE@XZ 0x4ea9f0
??0CRWConfig@@QAE@PAD@Z 0x4eef30
??0CRWReg@@QAE@PAD_N@Z 0x4ef1c0
??0CSslClientSocket@@QAE@XZ 0x4f1680
??1CAdoCommand@@UAE@XZ 0x4e0ed0
??1CAdoConnection@@UAE@XZ 0x4ded00
??1CAdoRecordSet@@UAE@XZ 0x4e2920
??1CClientInfo@@QAE@XZ 0x401ad0
??1CClientObject@@UAE@XZ 0x4e9c30
??1CClientSock@@UAE@XZ 0x4e9f60
??1CDBConnCollect@@QAE@XZ 0x4dcb40
??1CListenObject@@UAE@XZ 0x4ea9e0
??1CListenSock@@UAE@XZ 0x4eaa70
??1CRWConfig@@QAE@XZ 0x42c710
??1CRWReg@@QAE@XZ 0x4ef220
??1CSslClientSocket@@UAE@XZ 0x4f1770
??4CAdoCommand@@QAEAAV0@ABV0@@Z 0x4018b0
??4CAdoConnection@@QAEAAV0@ABV0@@Z 0x4019f0
??4CAdoRecordSet@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@AAV1@@Z 0x4e8e50
??4CAdoRecordSet@@QAEAAV0@ABV0@@Z 0x401750
??4CClientInfo@@QAEAAV0@ABV0@@Z 0x401ae0
??4CListenObject@@QAEAAV0@ABV0@@Z 0x401b40
??4CRWConfig@@QAEAAV0@ABV0@@Z 0x4987d0
??4CRWReg@@QAEAAV0@ABV0@@Z 0x411b10
??ACAdoCommand@@QAE?AVCAdoParameter@@H@Z 0x4e20f0
??ACAdoCommand@@QAE?AVCAdoParameter@@PBD@Z 0x4e2270
??_7CAdoCommand@@6B@ 0x5c7098
??_7CAdoConnection@@6B@ 0x5c709c
??_7CAdoRecordSet@@6B@ 0x5c7094
??_7CClientObject@@6B@ 0x5d14e4
??_7CClientSock@@6B@ 0x5d150c
??_7CListenObject@@6B@ 0x5c70a0
??_7CListenSock@@6B@ 0x5d16a0
??_7CSslClientSocket@@6B@ 0x5d1768
??_FCClientObject@@QAEXXZ 0x401b10
?AddNew@CAdoRecordSet@@QAEHAAVCADORecordBinding@@@Z 0x4e9a50
?AddNew@CAdoRecordSet@@QAEHXZ 0x4e3270
?Append@CAdoCommand@@QAEHV?$_com_ptr_t@V?$_com_IIID@U_Parameter@ADODB@@$1?_GUID_0000050c_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@@Z 0x4e1980
?AppendChunk@CAdoRecordSet@@QAEHJPAXI@Z 0x4e87c0
?AppendChunk@CAdoRecordSet@@QAEHJPBD@Z 0x4e8840
?AppendChunk@CAdoRecordSet@@QAEHPBD0@Z 0x4e8920
?AppendChunk@CAdoRecordSet@@QAEHPBDPAXI@Z 0x4e8800
?AppendChunk@CAdoRecordSet@@QAEHV?$_com_ptr_t@V?$_com_IIID@UField@ADODB@@$1?_GUID_00000569_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PAXI@Z 0x4e8660
?BeginTrans@CAdoConnection@@QAEJXZ 0x4e09c0
?Cancel@CAdoCommand@@QAEHXZ 0x4e10f0
?Cancel@CAdoConnection@@QAEHXZ 0x4df5f0
?Cancel@CAdoRecordSet@@QAEHXZ 0x4e30b0
?CancelBatch@CAdoRecordSet@@QAEHW4AffectEnum@ADODB@@@Z 0x4e3630
?CancelUpdate@CAdoRecordSet@@QAEHXZ 0x4e3570
?CheckTimeout@CClientObject@@QAE_NH@Z 0x4e9d50
?Clone@CAdoRecordSet@@QAEHAAV1@@Z 0x4e9500
?Close@CAdoConnection@@QAEXXZ 0x4df370
?Close@CAdoRecordSet@@QAEXXZ 0x4e3160
?CloseSock@CClientObject@@UAEXPADH@Z 0x55d620
?CloseTimer@CClientObject@@QAEXXZ 0x4e9d40
?CommitTrans@CAdoConnection@@QAEHXZ 0x4e0a70
?Connect@CClientSock@@UAEHPBDI@Z 0x4ea010
?Connect@CSslClientSocket@@UAEHPBDI@Z 0x4f2280
?ConnectAccess@CAdoConnection@@QAEHVCString@@0J@Z 0x4df1f0
?ConnectSQLServer@CAdoConnection@@QAEHVCString@@000J@Z 0x4df070
?CreateParameter@CAdoCommand@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Parameter@ADODB@@$1?_GUID_0000050c_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PBDW4DataTypeEnum@ADODB@@W4ParameterDirectionEnum@4@JV_variant_t@@@Z 0x4e11a0
?CreateSock@CClientObject@@QAEXXZ 0x4e9e80
?Delete@CAdoRecordSet@@QAEHW4AffectEnum@ADODB@@@Z 0x4e36f0
?Execute@CAdoCommand@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@J@Z 0x4e0fd0
?Execute@CAdoConnection@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PBDJ@Z 0x4df460
?Execute@CDBConnCollect@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PADPBD@Z 0x4dcf20
?Find@CAdoRecordSet@@QAEHPBDW4SearchDirectionEnum@ADODB@@@Z 0x4e9630
?FindNext@CAdoRecordSet@@QAEHXZ 0x4e9890
?GetAbsolutePage@CAdoRecordSet@@QAEJXZ 0x4e4640
?GetAbsolutePosition@CAdoRecordSet@@QAEJXZ 0x4e4760
?GetArrayInt@CRWConfig@@QAEHPAD0H@Z 0x4ef130
?GetArrayString@CRWConfig@@QAEPADPAD0H@Z 0x4ef050
?GetArrayString@CRWConfig@@QAEPADPAD0HH@Z 0x4ef090
?GetBookmark@CAdoRecordSet@@QAE?AV_variant_t@@XZ 0x4e9220
?GetBool@CRWConfig@@QAE_NPAD0@Z 0x4ef030
?GetChunk@CAdoRecordSet@@QAEHJAAVCBitmap@@@Z 0x4e8c90
?GetChunk@CAdoRecordSet@@QAEHJPAX@Z 0x4e8c10
?GetChunk@CAdoRecordSet@@QAEHPBDAAVCBitmap@@@Z 0x4e8d00
?GetChunk@CAdoRecordSet@@QAEHPBDPAX@Z 0x4e8c50
?GetChunk@CAdoRecordSet@@QAEHV?$_com_ptr_t@V?$_com_IIID@UField@ADODB@@$1?_GUID_00000569_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PAX@Z 0x4e8a00
?GetCollect@CAdoRecordSet@@QAEHJAAE@Z 0x4e7380
?GetCollect@CAdoRecordSet@@QAEHJAAF@Z 0x4e7580
?GetCollect@CAdoRecordSet@@QAEHJAAH@Z 0x4e7790
?GetCollect@CAdoRecordSet@@QAEHJAAJ@Z 0x4e79a0
?GetCollect@CAdoRecordSet@@QAEHJAAK@Z 0x4e7bb0
?GetCollect@CAdoRecordSet@@QAEHJAAM@Z 0x4e7e60
?GetCollect@CAdoRecordSet@@QAEHJAAN@Z 0x4e8160
?GetCollect@CAdoRecordSet@@QAEHJAAVCOleCurrency@@@Z 0x4e6f60
?GetCollect@CAdoRecordSet@@QAEHJAAVCOleDateTime@@@Z 0x4e6cb0
?GetCollect@CAdoRecordSet@@QAEHJAAVCString@@@Z 0x4e8370
?GetCollect@CAdoRecordSet@@QAEHJAA_N@Z 0x4e7180
?GetCollect@CAdoRecordSet@@QAEHPBDAAE@Z 0x4e7470
?GetCollect@CAdoRecordSet@@QAEHPBDAAF@Z 0x4e7680
?GetCollect@CAdoRecordSet@@QAEHPBDAAH@Z 0x4e7890
?GetCollect@CAdoRecordSet@@QAEHPBDAAJ@Z 0x4e7aa0
?GetCollect@CAdoRecordSet@@QAEHPBDAAK@Z 0x4e7d00
?GetCollect@CAdoRecordSet@@QAEHPBDAAM@Z 0x4e7fe0
?GetCollect@CAdoRecordSet@@QAEHPBDAAN@Z 0x4e8260
?GetCollect@CAdoRecordSet@@QAEHPBDAAVCOleCurrency@@@Z 0x4e7060
?GetCollect@CAdoRecordSet@@QAEHPBDAAVCOleDateTime@@@Z 0x4e6e40
?GetCollect@CAdoRecordSet@@QAEHPBDAAVCString@@@Z 0x4e84e0
?GetCollect@CAdoRecordSet@@QAEHPBDAA_N@Z 0x4e7270
?GetCommand@CAdoCommand@@QAEAAV?$_com_ptr_t@V?$_com_IIID@U_Command@ADODB@@$1?_GUID_b08400bd_f9d1_4d02_b856_71d5dba123e9@@3U__s_GUID@@A@@@@XZ 0x4e20e0
?GetConnByName@CDBConnCollect@@QAEPAVCCSConnection@@PAD@Z 0x4dced0
?GetConnectTimeOut@CAdoConnection@@QAEJXZ 0x4dfe50
?GetConnection@CAdoConnection@@QAEAAV?$_com_ptr_t@V?$_com_IIID@U_Connection@ADODB@@$1?_GUID_00000550_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@XZ 0x401950
?GetConnection@CAdoRecordSet@@QAEPAVCAdoConnection@@XZ 0x401680
?GetConnectionText@CAdoConnection@@QAE?AVCString@@XZ 0x401960
?GetCursorLocation@CAdoRecordSet@@QAE?AW4CursorLocationEnum@ADODB@@XZ 0x4e48b0
?GetCursorType@CAdoRecordSet@@QAE?AW4CursorTypeEnum@ADODB@@XZ 0x4e4a30
?GetDefaultDatabase@CAdoConnection@@QAE?AVCString@@XZ 0x4dffc0
?GetEditMode@CAdoRecordSet@@QAE?AW4EditModeEnum@ADODB@@XZ 0x4e4310
?GetError@CAdoConnection@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UError@ADODB@@$1?_GUID_00000500_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@J@Z 0x4dfcf0
?GetErrors@CAdoConnection@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UErrors@ADODB@@$1?_GUID_00000501_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@XZ 0x4dfc20
?GetField@CAdoRecordSet@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UField@ADODB@@$1?_GUID_00000569_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@J@Z 0x4e5c20
?GetField@CAdoRecordSet@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UField@ADODB@@$1?_GUID_00000569_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PBD@Z 0x4e5d30
?GetFieldActualSize@CAdoRecordSet@@QAEJJ@Z 0x4e53b0
?GetFieldActualSize@CAdoRecordSet@@QAEJPBD@Z 0x4e5500
?GetFieldAttributes@CAdoRecordSet@@QAEJJ@Z 0x4e4e50
?GetFieldAttributes@CAdoRecordSet@@QAEJPBD@Z 0x4e4fa0
?GetFieldDefineSize@CAdoRecordSet@@QAEJJ@Z 0x4e5100
?GetFieldDefineSize@CAdoRecordSet@@QAEJPBD@Z 0x4e5250
?GetFieldName@CAdoRecordSet@@QAE?AVCString@@J@Z 0x4e4b90
?GetFieldType@CAdoRecordSet@@QAE?AW4DataTypeEnum@ADODB@@J@Z 0x4e5660
?GetFieldType@CAdoRecordSet@@QAE?AW4DataTypeEnum@ADODB@@PBD@Z 0x4e57b0
?GetFields@CAdoRecordSet@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UFields@ADODB@@$1?_GUID_00000564_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@XZ 0x4e4ae0
?GetFieldsCount@CAdoRecordSet@@QAEJXZ 0x4e3f70
?GetInt@CRWConfig@@QAEHPAD0@Z 0x4eefb0
?GetLastError@CAdoRecordSet@@QAE?AVCString@@XZ 0x4e94e0
?GetLastErrorText@CAdoConnection@@QAE?AVCString@@XZ 0x4df6a0
?GetMaxRecordCount@CAdoRecordSet@@QAEJXZ 0x4e4040
?GetMode@CAdoConnection@@QAE?AW4ConnectModeEnum@ADODB@@XZ 0x4e0700
?GetPageCount@CAdoRecordSet@@QAEJXZ 0x4e43f0
?GetPageSize@CAdoRecordSet@@QAEJXZ 0x4e4520
?GetParameter@CAdoCommand@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Parameter@ADODB@@$1?_GUID_0000050c_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@J@Z 0x4e1c40
?GetParameters@CAdoCommand@@QAE?AV?$_com_ptr_t@V?$_com_IIID@UParameters@ADODB@@$1?_GUID_0000050d_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@XZ 0x4e1870
?GetParamter@CAdoCommand@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Parameter@ADODB@@$1?_GUID_0000050c_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@PBD@Z 0x4e1a90
?GetProviderName@CAdoConnection@@QAE?AVCString@@XZ 0x4e01b0
?GetRecordCount@CAdoRecordSet@@QAEJXZ 0x4e3e10
?GetRecordset@CAdoRecordSet@@QAEAAV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@XZ 0x4e94d0
?GetSQLText@CAdoRecordSet@@QAE?AVCString@@XZ 0x401650
?GetState@CAdoCommand@@QAEJXZ 0x4e1700
?GetState@CAdoConnection@@QAEJXZ 0x4e0590
?GetState@CAdoRecordSet@@QAEJXZ 0x4e3c20
?GetStatus@CAdoRecordSet@@QAEJXZ 0x4e3d60
?GetString@CRWConfig@@QAEPADPAD0@Z 0x4eef60
?GetValue@CAdoCommand@@QAE?AV_variant_t@@J@Z 0x4e1d60
?GetValue@CAdoCommand@@QAE?AV_variant_t@@PBD@Z 0x4e1f30
?GetVersion@CAdoConnection@@QAE?AVCString@@XZ 0x4e03a0
?Init@CDBConnCollect@@QAE_NXZ 0x4dcba0
?IsBOF@CAdoRecordSet@@QAEHXZ 0x4e41b0
?IsEOF@CAdoRecordSet@@QAEHXZ 0x4e4260
?IsFieldNull@CAdoRecordSet@@QAEHJ@Z 0x4e5ae0
?IsFieldNull@CAdoRecordSet@@QAEHPBD@Z 0x4e5910
?IsOpen@CAdoConnection@@QAEHXZ 0x4e0640
?IsOpen@CAdoRecordSet@@QAEHXZ 0x4e3cd0
?Load@CAdoRecordSet@@QAEHPBD@Z 0x4e2f40
?LoadCert@CSslClientSocket@@IAEPAUx509_st@@PADH0@Z 0x4f18a0
?LoadKey@CSslClientSocket@@IAEPAUevp_pkey_st@@PADH00@Z 0x4f1a10
?Move@CAdoRecordSet@@QAEHJV_variant_t@@@Z 0x4e3ab0
?MoveFirst@CAdoRecordSet@@QAEHXZ 0x4e37b0
?MoveLast@CAdoRecordSet@@QAEHXZ 0x4e3870
?MoveNext@CAdoRecordSet@@QAEHXZ 0x4e39f0
?MovePrevious@CAdoRecordSet@@QAEHXZ 0x4e3930
?OnAccept@CListenSock@@UAEXH@Z 0x4eaa80
?OnClose@CClientSock@@UAEXH@Z 0x4e9ff0
?OnClose@CListenSock@@UAEXH@Z 0x58cd60
?OnClose@CSslClientSocket@@UAEXH@Z 0x4f23d0
?OnConnect@CClientSock@@UAEXH@Z 0x4e9fa0
?OnReceive@CClientSock@@UAEXH@Z 0x4e9fe0
?OnReceive@CSslClientSocket@@UAEXH@Z 0x4f2210
?OnSend@CClientSock@@UAEXH@Z 0x4ea030
?OnTimer@CClientObject@@UAEXXZ 0x401ad0
?Open@CAdoConnection@@QAEHPBDJ@Z 0x4ded70
?Open@CAdoRecordSet@@QAEHPBDJW4CursorTypeEnum@ADODB@@W4LockTypeEnum@3@@Z 0x4e29c0
?OpenSchema@CAdoConnection@@QAE?AV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@W4SchemaEnum@ADODB@@@Z 0x4e0870
?OpenUDLFile@CAdoConnection@@QAEHPBDJ@Z 0x4df2f0
?PutCollect@CAdoRecordSet@@QAEHJABE@Z 0x4e61d0
?PutCollect@CAdoRecordSet@@QAEHJABF@Z 0x4e62d0
?PutCollect@CAdoRecordSet@@QAEHJABH@Z 0x4e63d0
?PutCollect@CAdoRecordSet@@QAEHJABJ@Z 0x4e64d0
?PutCollect@CAdoRecordSet@@QAEHJABK@Z 0x4e65d0
?PutCollect@CAdoRecordSet@@QAEHJABM@Z 0x4e66f0
?PutCollect@CAdoRecordSet@@QAEHJABN@Z 0x4e67f0
?PutCollect@CAdoRecordSet@@QAEHJABVCOleCurrency@@@Z 0x4e6a10
?PutCollect@CAdoRecordSet@@QAEHJABVCOleDateTime@@@Z 0x4e68f0
?PutCollect@CAdoRecordSet@@QAEHJABVCString@@@Z 0x4e6b70
?PutCollect@CAdoRecordSet@@QAEHJABV_variant_t@@@Z 0x4e5e60
?PutCollect@CAdoRecordSet@@QAEHJAB_N@Z 0x4e60d0
?PutCollect@CAdoRecordSet@@QAEHPBDABE@Z 0x4e6250
?PutCollect@CAdoRecordSet@@QAEHPBDABF@Z 0x4e6350
?PutCollect@CAdoRecordSet@@QAEHPBDABH@Z 0x4e6450
?PutCollect@CAdoRecordSet@@QAEHPBDABJ@Z 0x4e6550
?PutCollect@CAdoRecordSet@@QAEHPBDABK@Z 0x4e6660
?PutCollect@CAdoRecordSet@@QAEHPBDABM@Z 0x4e6770
?PutCollect@CAdoRecordSet@@QAEHPBDABN@Z 0x4e6870
?PutCollect@CAdoRecordSet@@QAEHPBDABVCOleCurrency@@@Z 0x4e6ac0
?PutCollect@CAdoRecordSet@@QAEHPBDABVCOleDateTime@@@Z 0x4e6980
?PutCollect@CAdoRecordSet@@QAEHPBDABVCString@@@Z 0x4e6c10
?PutCollect@CAdoRecordSet@@QAEHPBDABV_variant_t@@@Z 0x4e5f80
?PutCollect@CAdoRecordSet@@QAEHPBDAB_N@Z 0x4e6150
?ReadInt@CRWReg@@QAEHPAD@Z 0x4ef240
?ReadString@CRWReg@@QAE?AVCString@@PADH@Z 0x4ef300
?ReadString@CRWReg@@QAEPADPAD@Z 0x4ef2a0
?Receive@CSslClientSocket@@UAEHPAXHH@Z 0x4f2260
?RecordBinding@CAdoRecordSet@@QAEHAAVCADORecordBinding@@@Z 0x4e9990
?Release@CAdoCommand@@IAEXXZ 0x4e0f40
?Release@CAdoConnection@@IAEXXZ 0x4df420
?Release@CAdoRecordSet@@IAEXXZ 0x4e3220
?Release@CDBConnCollect@@QAEXXZ 0x4dce80
?Requery@CAdoRecordSet@@QAEHJ@Z 0x4e2ba0
?RestoreID@CClientObject@@QAEXPAEH_NH1@Z 0x4e9e00
?Resync@CAdoRecordSet@@QAEHW4AffectEnum@ADODB@@W4ResyncEnum@3@@Z 0x4e2c60
?RollbackTrans@CAdoConnection@@QAEHXZ 0x4e0b20
?SSlConnect@CSslClientSocket@@QAEHPAD@Z 0x4f1ff0
?SSlReceive@CSslClientSocket@@QAEHPADH@Z 0x4f2180
?SSlSend@CSslClientSocket@@QAEHPADH@Z 0x4f20a0
?SSlShouDown@CSslClientSocket@@QAEXXZ 0x4f2050
?Save@CAdoRecordSet@@QAEHPBDW4PersistFormatEnum@ADODB@@@Z 0x4e2d20
?SaveID@CClientObject@@QAEXPAEH_N1@Z 0x4e9d80
?Send@CClientObject@@QAEHPAXH@Z 0x4e9d10
?Send@CClientSock@@UAEHPAXH@Z 0x4e9fc0
?Send@CSslClientSocket@@UAEHPAXH@Z 0x4f2240
?SetAbsolutePage@CAdoRecordSet@@QAEHH@Z 0x4e45b0
?SetAbsolutePosition@CAdoRecordSet@@QAEHH@Z 0x4e46d0
?SetAdoConnection@CAdoRecordSet@@QAEXPAVCAdoConnection@@@Z 0x4e94c0
?SetArrayInt@CRWConfig@@QAEXPAD0HH@Z 0x4ef170
?SetArrayString@CRWConfig@@QAEXPAD0H0@Z 0x4ef0e0
?SetBookmark@CAdoRecordSet@@QAEHV_variant_t@@@Z 0x4e9390
?SetBool@CRWConfig@@QAEXPAD0_N@Z 0x4ef010
?SetCacheSize@CAdoRecordSet@@QAEHABJ@Z 0x4e4480
?SetCommandText@CAdoCommand@@QAEHPBD@Z 0x4e13a0
?SetCommandTimeOut@CAdoCommand@@QAEHJ@Z 0x4e17b0
?SetCommandType@CAdoCommand@@QAEHW4CommandTypeEnum@ADODB@@@Z 0x4e1640
?SetConnectTimeOut@CAdoConnection@@QAEHJ@Z 0x4dff00
?SetConnection@CAdoCommand@@QAEHPAVCAdoConnection@@@Z 0x4e1540
?SetCursorLocation@CAdoRecordSet@@QAEHW4CursorLocationEnum@ADODB@@@Z 0x4e47f0
?SetCursorType@CAdoRecordSet@@QAEHW4CursorTypeEnum@ADODB@@@Z 0x4e4970
?SetFilter@CAdoRecordSet@@QAEHPBD@Z 0x4e8f70
?SetInt@CRWConfig@@QAEXPAD0H@Z 0x4eefd0
?SetMaxRecordCount@CAdoRecordSet@@QAEHJ@Z 0x4e40f0
?SetMode@CAdoConnection@@QAEHW4ConnectModeEnum@ADODB@@@Z 0x4e07b0
?SetRecordset@CAdoRecordSet@@QAEXV?$_com_ptr_t@V?$_com_IIID@U_Recordset@ADODB@@$1?_GUID_00000556_0000_0010_8000_00aa006d2ea4@@3U__s_GUID@@A@@@@@Z 0x4e3f00
?SetSQLText@CAdoRecordSet@@QAEXPBD@Z 0x401670
?SetServer@CClientObject@@QAEXPADH_N@Z 0x4e9cc0
?SetSort@CAdoRecordSet@@QAEHPBD@Z 0x4e9080
?SetString@CRWConfig@@QAEXPAD00@Z 0x4eef90
?SetType@CClientObject@@QAEXW4ENUM_OBJECT_TYPE@1@@Z 0x401b00
?SockConnect@CSslClientSocket@@QAEHPAUssl_method_st@@PADH1H11PBDI1@Z 0x4f1b40
?Start@CClientObject@@UAE_NXZ 0x4d77b0
?Start@CListenObject@@UAE_NXZ 0x4d77b0
?StartTimer@CClientObject@@QAEXXZ 0x4e9d30
?Stop@CClientObject@@UAE_NXZ 0x4e9d00
?Stop@CListenObject@@UAE_NXZ 0x4d77b0
?Supports@CAdoRecordSet@@QAEHW4CursorOptionEnum@ADODB@@@Z 0x4e8ed0
?Update@CAdoRecordSet@@QAEHXZ 0x4e3380
?UpdateBatch@CAdoRecordSet@@QAEHW4AffectEnum@ADODB@@@Z 0x4e34b0
?WaitforAbortRecv@CSslClientSocket@@QAEXXZ 0x4f23f0
?WaitforAbortSend@CSslClientSocket@@QAEXXZ 0x4f23e0
?WriteInt@CRWReg@@QAEXPADH@Z 0x4ef3f0
?WriteString@CRWReg@@QAEXPAD0@Z 0x4ef410
?load_cert@CSslClientSocket@@IAEPAUx509_st@@PAUbio_st@@HPAD1@Z 0x4f17f0
?load_key@CSslClientSocket@@IAEPAUevp_pkey_st@@PAUbio_st@@HPAD1@Z 0x4f1960