Start Length Name Class 0001:00000000 00004870H .text CODE 0002:00000000 00000261H .rdata DATA 0002:00000261 00000000H .edata DATA 0003:00000000 00000004H .data DATA 0003:00000020 000001bcH .bss DATA
Address Publics by Value Rva+Base Lib:Object
0000:00000000 ___safe_se_handler_table 00000000 <absolute> 0000:00000000 ___safe_se_handler_count 00000000 <absolute> 0001:00000000 _GetFuncSize 00401000 f main.obj 0001:0000024b _GetClearFuncSize 0040124b f main.obj 0001:000003e2 _CreateScFolder 004013e2 f main.obj 0001:000004c3 _PrintEncryptShellcode 004014c3 f main.obj 0001:00000585 _PrintShellcode 00401585 f main.obj 0001:0000099b _main 0040199b f main.obj 0001:000009be _ShellCode_Start 004019be f shellcode.obj 0001:000009d0 _SetupJunk 004019d0 f shellcode.obj 0001:00000ce1 _Hash_GetProcAddress 00401ce1 f shellcode.obj 0001:00000dad _GetShellCodeAddr 00401dad f shellcode.obj 0001:00000dc1 _ReleaseRebaseShellCode 00401dc1 f shellcode.obj 0001:00000dd8 _ShellCodeEntry 00401dd8 f shellcode.obj 0001:00000e71 _GetRing3ApiAddr 00401e71 f shellcode.obj 0001:0000187f _ROL 0040287f f runas.obj ........................................................... 0001:000021a7 _FormatError 004031a7 f runas.obj 0001:00002598 _RunCMD 00403598 f runas.obj 0001:00003846 _RunAsMain 00404846 f runas.obj 0001:00003f1a ??_C@_02LFEKMCM@?5f?$AA@ 00406000 main.obj 0002:00000004 ??_C@_0M@LNAMDANG@Shell32?4dll?$AA@ 0040600c main.obj 0002:00000018 ??_C@_0N@HAOHNMDE@Kernel32?4dll?$AA@ 00406024 main.obj ...........................................................