cryptor huh?
Microsoft Visual Basic 5.0 / 6.0 [Overlay]
Its not encrypted or packed.
Besides, debugging it didnt show intermodular calls, but you can find the APIs you used in all referenced text strings

Originally Posted by
OllyDBG
004018B4 DD HS_Patch.00401884 ASCII "kernel32"
004018B8 DD HS_Patch.004018A0 ASCII "WriteProcessMemory"
004018FC DD HS_Patch.00401884 ASCII "kernel32"
00401900 DD HS_Patch.004018EC ASCII "RtlMoveMemory"
00401950 DD HS_Patch.00401934 ASCII "user32"
00401954 DD HS_Patch.00401940 ASCII "CallWindowProcA"
00401998 DD HS_Patch.00401884 ASCII "kernel32"
0040199C DD HS_Patch.00401988 ASCII "CreateProcessA"
004019E0 DD HS_Patch.00401884 ASCII "kernel32"
004019E4 DD HS_Patch.004019D0 ASCII "GetProcAddress"
00401A28 DD HS_Patch.00401884 ASCII "kernel32"
00401A2C DD HS_Patch.00401A18 ASCII "LoadLibraryA"
00401B00 DD HS_Patch.00401884 ASCII "kernel32"
00401B04 DD HS_Patch.00401AF8 ASCII "Sleep"
00401B44 DD HS_Patch.00401934 ASCII "user32"
00401B48 DD HS_Patch.00401B38 ASCII "SetTimer"
00401B88 DD HS_Patch.00401934 ASCII "user32"
00401B8C DD HS_Patch.00401B7C ASCII "KillTimer"
00401C08 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401C0C DD HS_Patch.00401BF8 ASCII "CryptCreateHash"
00401C54 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401C58 DD HS_Patch.00401C40 ASCII "CryptDestroyHash"
00401C9C DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401CA0 DD HS_Patch.00401C8C ASCII "CryptDeriveKey"
00401CEC DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401CF0 DD HS_Patch.00401CD4 ASCII "CryptAcquireContextA"
00401D38 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401D3C DD HS_Patch.00401D24 ASCII "CryptGetProvParam"
00401D80 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401D84 DD HS_Patch.00401D70 ASCII "CryptDestroyKey"
00401DC8 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401DCC DD HS_Patch.00401DB8 ASCII "CryptDecrypt"
00401E10 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401E14 DD HS_Patch.00401E00 ASCII "CryptHashData"
00401E58 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401E5C DD HS_Patch.00401E48 ASCII "CryptEncrypt"
00401EA4 DD HS_Patch.00401BE4 ASCII "advapi32.dll"
00401EA8 DD HS_Patch.00401E90 ASCII "CryptReleaseContext"
BTW
File: HS_Patch_14.3.09.exe
Status: INFECTED/MALWARE
MD5: c0ac9dce628a4a4be11a28be6f712957
Packers detected: -
A-Squared Found nothing
AntiVir Found TR/Dropper.Gen
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found Trojan.PWS.Stealer.129
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Quick Heal Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
Need be say more?
You fail.