7-11-2015
Decrypted strings from 2.0.0c
0xa26c18 => ntdll.dll
0xa26c24 => kernel32.dll
0xa26c34 => user32.dll
0xa26c44 => advapi32.dll
0xa26c54 => LdrGetDllHandle
0xa26c68 => LdrGetProcedureAddress
0xa26c84 => LdrQueryProcessModuleInformation
0xa26ca8 => NtAllocateVirtualMemory
0xa26cc4 => NtCreateFile
0xa26cd4 => NtDuplicateObject
0xa26ce8 => NtFreeVirtualMemory
0xa26d00 => NtGetTickCount
0xa26d14 => NtQueryInformationFile
0xa26d30 => NtQueryInformationProcess
0xa26d4c => NtQueryObject
0xa26d5c => NtQueryPerformanceCounter
0xa26d78 => NtQuerySystemInformation
0xa26d94 => NtQueryVirtualMemory
0xa26dac => NtReadFile
0xa26dbc => NtSetInformationThread
0xa26dd8 => AdjustTokenPrivileges
0xa26df0 => CloseHandle
0xa26e00 => ContinueDebugEvent
0xa26e18 => CreateThread
0xa26e28 => CreateToolhelp32Snapshot
0xa26e44 => DebugActiveProcess
0xa26e5c => GetCurrentProcess
0xa26e70 => GetCurrentProcessId
0xa26e88 => GetCurrentThread
0xa26e9c => GetProcessId
0xa26eac => GetNativeSystemInfo
0xa26ec4 => LookupPrivilegeValueA
0xa26edc => Module32First
0xa26eec => Module32Next
0xa26efc => OpenProcessToken
0xa26f10 => WaitForDebugEvent
(rebased at 0xC0000)