3.7
中危

083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33

083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe

分析耗时

133s

最近分析

378天前

文件大小

368.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN SCAR
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.77
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Trojan:Win32/Sakurel.ff180bfb 20190527 0.3.0.5
Avast Win32:Malware-gen 20200614 18.4.3895.0
Baidu Win32.Trojan.Shyape.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Kingsoft None 20200614 2013.8.14.323
McAfee Trojan-FDXL!0A276CC3A80A 20200614 6.0.6.653
Tencent Malware.Win32.Gencirc.10b07628 20200614 1.0.0.1
静态指标
查询计算机名称 (1 个事件)
Time & API Arguments Status Return Repeated
1727545314.844
GetComputerNameA
computer_name: TU-PC
success 1 0
观察到命令行控制台输出 (20 个事件)
Time & API Arguments Status Return Repeated
1727545345.937125
WriteConsoleA
console_handle: 0x00000007
buffer: ÕýÔÚ Ping 127.0.0.1
success 1 0
1727545345.937125
WriteConsoleA
console_handle: 0x00000007
buffer: ¾ßÓÐ 32 ×Ö½ÚµÄÊý¾Ý:
success 1 0
1727545345.953125
WriteConsoleA
console_handle: 0x00000007
buffer: À´×Ô 127.0.0.1 µÄ»Ø¸´:
success 1 0
1727545345.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ×Ö½Ú=32
success 1 0
1727545345.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ʱ¼ä<1ms
success 1 0
1727545345.953125
WriteConsoleA
console_handle: 0x00000007
buffer: TTL=128
success 1 0
1727545346.953125
WriteConsoleA
console_handle: 0x00000007
buffer: À´×Ô 127.0.0.1 µÄ»Ø¸´:
success 1 0
1727545346.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ×Ö½Ú=32
success 1 0
1727545346.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ʱ¼ä<1ms
success 1 0
1727545346.953125
WriteConsoleA
console_handle: 0x00000007
buffer: TTL=128
success 1 0
1727545347.953125
WriteConsoleA
console_handle: 0x00000007
buffer: À´×Ô 127.0.0.1 µÄ»Ø¸´:
success 1 0
1727545347.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ×Ö½Ú=32
success 1 0
1727545347.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ʱ¼ä<1ms
success 1 0
1727545347.953125
WriteConsoleA
console_handle: 0x00000007
buffer: TTL=128
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: À´×Ô 127.0.0.1 µÄ»Ø¸´:
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ×Ö½Ú=32
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: ʱ¼ä<1ms
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: TTL=128
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: 127.0.0.1 µÄ Ping ͳ¼ÆÐÅÏ¢: Êý¾Ý°ü: ÒÑ·¢ËÍ = 4£¬ÒѽÓÊÕ = 4£¬¶ªÊ§ = 0 (0% ¶ªÊ§)£¬
success 1 0
1727545348.953125
WriteConsoleA
console_handle: 0x00000007
buffer: Íù·µÐг̵ĹÀ¼ÆÊ±¼ä(ÒÔºÁÃëΪµ¥Î»): ×î¶Ì = 0ms£¬× = 0ms£¬Æ½¾ù = 0ms
success 1 0
检查系统中的内存量,这可以用于检测可用内存较少的虚拟机 (2 个事件)
Time & API Arguments Status Return Repeated
1727545345.32775
GlobalMemoryStatusEx
success 1 0
1727545345.922125
GlobalMemoryStatusEx
success 1 0
文件包含未知的 PE 资源名称,可能指示打包器 (1 个事件)
resource name DAT
行为判定
动态指标
检查是否有任何人类活动正在进行,通过不断检查前景窗口是否发生变化
在 PE 资源中识别到外语 (2 个事件)
name DAT language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000174d8 size 0x00001600
name DAT language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000174d8 size 0x00001600
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\MicroMedia\MediaCenter.exe
创建可疑进程 (2 个事件)
cmdline cmd.exe /c ping 127.0.0.1 & del /q "C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe"
cmdline "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 & del /q "C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe"
将可执行文件投放到用户的 AppData 文件夹 (2 个事件)
file C:\Users\Administrator\AppData\Local\Temp\MicroMedia\MediaCenter.exe
file C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe
一个进程创建了一个隐藏窗口 (1 个事件)
Time & API Arguments Status Return Repeated
1727545345.46875
ShellExecuteExW
filepath: cmd.exe
filepath_r: cmd.exe
parameters: /c ping 127.0.0.1 & del /q "C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe"
show_type: 0
success 1 0
使用 Windows 工具进行基本 Windows 功能 (3 个事件)
cmdline cmd.exe /c ping 127.0.0.1 & del /q "C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe"
cmdline "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 & del /q "C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe"
cmdline ping 127.0.0.1
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
在 Windows 启动时自我安装以实现自动运行 (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\MicroMedia reg_value C:\Users\ADMINI~1\AppData\Local\Temp\MicroMedia\MediaCenter.exe
文件已被 VirusTotal 上 65 个反病毒引擎识别为恶意 (50 out of 65 个事件)
ALYac Trojan.GenericKD.40441877
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.GenericKD.40441877
AhnLab-V3 Trojan/Win32.Scar.R160937
Alibaba Trojan:Win32/Sakurel.ff180bfb
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.Generic.D2691815
Avast Win32:Malware-gen
Avira TR/Patched.Ren.Gen
Baidu Win32.Trojan.Shyape.a
BitDefender Trojan.GenericKD.40441877
BitDefenderTheta AI:FileInfector.C2A5779617
Bkav W32.FamVT.ScrAMTTc.Worm
CAT-QuickHeal W32.Virut.G
ClamAV Win.Downloader.Upatre-5744092-0
Comodo TrojWare.Win32.Shyape.GA@590rbc
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.3a80a0
Cynet Malicious (score: 100)
Cyren W32/S-4bc2e477!Eldorado
DrWeb Trojan.DownLoad3.22515
ESET-NOD32 Win32/Shyape.G
Emsisoft Trojan.GenericKD.40441877 (B)
Endgame malicious (high confidence)
F-Prot W32/S-4bc2e477!Eldorado
FireEye Generic.mg.0a276cc3a80a0ce5
Fortinet W32/Shyape.Z!tr
GData Win32.Trojan.Sakurel.B
Ikarus Trojan.Win32.Scar
Invincea heuristic
Jiangmin Trojan/Scar.bayz
K7AntiVirus Trojan ( 0054e5911 )
K7GW Trojan ( 0054e5911 )
Kaspersky Trojan.Win32.Scar.ojsz
Lionic Trojan.Win32.Agent.tnrg
MAX malware (ai score=81)
Malwarebytes Trojan.Agent
McAfee Trojan-FDXL!0A276CC3A80A
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
MicroWorld-eScan Trojan.GenericKD.40441877
Microsoft Trojan:Win32/Sakurel.B!dha
NANO-Antivirus Trojan.Win64.Agent.cysfdn
Paloalto generic.ml
Panda Trj/Genetic.gen
Qihoo-360 Win32/Trojan.Sakurel.A
Rising Trojan.Shyape!1.A74F (CLOUD)
SUPERAntiSpyware Trojan.Agent/Gen-Sakurel
Sangfor Malware
连接到不再响应请求的 IP 地址(合法服务通常会保持运行) (2 个事件)
dead_host 76.223.54.146:80
dead_host 13.248.169.48:80
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-02-05 12:03:07

PE Imphash

4511896d043677e4ab4578dc5bcab5a0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000dc00 0x0000dc00 6.59554870922936
.rdata 0x0000f000 0x0000260e 0x00002800 5.383932002284258
.data 0x00012000 0x00003980 0x00001a00 1.8090932393780108
.rsrc 0x00016000 0x00002c34 0x00002e00 3.488753715736823
.reloc 0x00019000 0x00006400 0x000013fe 4.7349731801123465

Resources

Name Offset Size Language Sub-language File type
DAT 0x000174d8 0x00001600 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None
DAT 0x000174d8 0x00001600 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None
RT_MANIFEST 0x00018ad8 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library KERNEL32.dll:
0x40f02c GetCurrentThread
0x40f030 VirtualFree
0x40f038 WriteFile
0x40f03c OpenProcess
0x40f040 WideCharToMultiByte
0x40f048 Sleep
0x40f04c SizeofResource
0x40f050 CreateProcessA
0x40f054 TerminateProcess
0x40f058 ReadFile
0x40f05c GetSystemDirectoryA
0x40f060 MultiByteToWideChar
0x40f064 GetTickCount
0x40f068 CreateDirectoryA
0x40f06c GetStartupInfoA
0x40f070 FindFirstFileA
0x40f074 GetLastError
0x40f078 VirtualAlloc
0x40f07c FindClose
0x40f080 LockResource
0x40f084 CreatePipe
0x40f088 GetModuleFileNameA
0x40f08c GetVersionExA
0x40f090 WinExec
0x40f094 CloseHandle
0x40f098 GetCurrentProcessId
0x40f09c GetTempPathA
0x40f0a0 GetCurrentProcess
0x40f0a4 LoadResource
0x40f0a8 PeekNamedPipe
0x40f0ac SetFilePointer
0x40f0b0 SetPriorityClass
0x40f0b4 FindResourceA
0x40f0b8 GetFileSize
0x40f0bc CreateFileA
0x40f0c0 GetComputerNameA
0x40f0c4 SetThreadPriority
0x40f0c8 ExitProcess
0x40f0cc GetProcessHeap
0x40f0d0 SetEndOfFile
0x40f0d4 GetStringTypeW
0x40f0d8 GetStringTypeA
0x40f0dc GetModuleHandleW
0x40f0e0 GetProcAddress
0x40f0e4 HeapFree
0x40f0e8 HeapAlloc
0x40f0f0 GetCommandLineA
0x40f0fc IsDebuggerPresent
0x40f100 TlsGetValue
0x40f104 TlsAlloc
0x40f108 TlsSetValue
0x40f10c TlsFree
0x40f114 SetLastError
0x40f118 GetCurrentThreadId
0x40f120 GetStdHandle
0x40f130 LoadLibraryA
0x40f138 HeapCreate
0x40f13c HeapReAlloc
0x40f140 RtlUnwind
0x40f144 GetConsoleCP
0x40f148 GetConsoleMode
0x40f14c SetHandleCount
0x40f150 GetFileType
0x40f168 GetCPInfo
0x40f16c GetACP
0x40f170 GetOEMCP
0x40f174 IsValidCodePage
0x40f178 HeapSize
0x40f17c GetLocaleInfoA
0x40f180 SetStdHandle
0x40f184 WriteConsoleA
0x40f188 GetConsoleOutputCP
0x40f18c WriteConsoleW
0x40f190 FlushFileBuffers
0x40f194 LCMapStringA
0x40f198 LCMapStringW
Library ADVAPI32.dll:
0x40f000 RegOpenKeyA
0x40f004 GetUserNameA
0x40f008 FreeSid
0x40f010 RegDeleteKeyA
0x40f014 EqualSid
0x40f018 RegSetValueExA
0x40f01c GetTokenInformation
0x40f020 OpenProcessToken
0x40f024 RegCloseKey
Library SHELL32.dll:
0x40f1a0 SHChangeNotify
0x40f1a4 None
0x40f1a8 ShellExecuteA
Library WININET.dll:
0x40f1b0 HttpOpenRequestA
0x40f1b4 InternetOpenUrlA
0x40f1b8 HttpSendRequestA
0x40f1bc InternetOpenA
0x40f1c0 InternetCloseHandle
0x40f1c4 InternetConnectA
0x40f1c8 InternetReadFile

L!This program cannot be run in DOS mode.
]]](]]9]]/]]_]]]]&]]8]]=]]Rich]
.rdata
@.data
@.reloc
L$!SQ\$
\$ \$$\$(?Y
L$!fL$%L$'X!
^][_3
_2^YSi
[_2^Yh
^YSUl$
_^][SUVW
PUVh`EA
_^][32R
L$4Q}htGA
T$<RQ
3D$,3UD$,D$(PL$(QT$(RD$<
j@D$HUPl$LI
l$<D$@D$DD$HPI
D$0PL$DQUUUj
+V<+WQ
jdPL$@QF
3jDPhGA
^(SU3W}
3UL$$QD$,D$0D$8D$<
D$0l$4|$8D$<l$@|$D
tmUT$0RhGA
UUUWUUGA
_][2^(D$
@u+UT$
+V<+WR
FuSU+W~
;}(-d@
_][^32:
QVUWD$$
D$ P$,
^2]SWj
@u+PD$
SUV3Wt$
t$ D$$
QVVVVVVh
U S39]
;tVEEE
YYuBhb@
tx5lYA
u;rWo"
t;rJ6i"
^WWWWW0
&AwSWh3
Uj<uW1
k<+^ >3[_^
YY#^]j
tu=\YA
VW3M]9}
W6uuKI
E+)E(V@
3PPPPPEN
SVW39}
}O;]rOt
u+WuVOF
M+;rP})E
YYt)EF
E3B;r9]u
Y}V*YEE
<YY]jXh
u3CSr&
P3Z}5E
3PPPPPM
ItUhtDlt
HHtXHHt
4itqnt(o
PSP5#A
YYY;-u
t-RPSW|[
0@>If90t
@@;u+(;u
EPFPF}Y
u(9t M
`pM_^3[
,ffffffE
eYV5!A
YYt:V5!A
PzYFDt
PlYFHt
P^YF\=
~lt#WN
teh<[@
YYt4V5!A
VW33};
3PPPPP
@Y<v8V"N
3VVVVVw
VVVVVS
VVVVV.
;t$tj
F$|3@_^
UQSVW5pYA
;r@PuJ
P4BYpYA
V)YlYA
VW3h#A
B(;r3_^[]
1E3PEd
Y_^[]hd@
1E3PeuEEEEd
Y__^[]Q
:(E_^[]E
9csmu)=`YA
t h`YA
EYF`[_^
Y+t"+t
+td+uD}
3PPPPP
u@OdMGd
uwdSUY
WVS3D$
]3@\YA
MOI;|9M
SI VW}
HD9#U#
MLD3#u
]#\D\D
;r"x&A
;r=x&A
<at9<rt,<wtSSSSS
L9]u<eE
F> t>=upF> tj
[SSSSS
+Y]3u;5@YA
4V'YY IA
PV~YYF
PYY IA
5YSVWT$
URPQQh}@
t;T$4t
;v.4v\
UVWS33333[_^]
33333USVWj
_^[]Ul$
^WWWWW
jXEU;u
P\YME;E
Y]\3_[^j
uVVVVV
^0WWWWW
V34809u
;u'0VVVVV
u&>30"VVVVV
P4UM`8
<PVEP(
r3VVhU
QH++PPVh
,P+P5P(
\D+48;E
0?@!Y1(
8+0_[M3^{j
W>+~,WPV
Y/V|Yt
FY}3u;5@YA
tVPVkYY3BU IA
F3u IA
4VtYYE
YUWVu
DDDDDDDDDDDDDD
Ej@j ^V
[j@j G
WWWWWC
YtP HA
^]SVD$
8csmu*x
VW39=tYA
t.t$<"u
C>=Yt1j
tNVSP_
3PPPPPG
3Y[_^5
FA>\t>"u&
uUEPSS}
=?sJMsB
Y;t)UEP
W33;u.
SSS+S@PWSSE
YE;t!SSuPuWSS
utY]]W
u+@PE
E3E3;u
EU_^j
3]V3;|
LVVVVV
WPWPWv
j OY|j
8]tEMap<u
k0u ,A
Zf1Af0A@@JuL
@;vFF~
XM_^3[j
_M}_hu
P]Y^hS=
Y%u 'A
3W;to=.A
7=YY~PE
uVY_^[]
t7t3V0;t(W8Yt
VYY^3j
Fpt"~l
YYu,9E
tAt2t$
^SSSSS0
f;v6;t
Map_^[;t2;w,
j"^SSSSS0P
YY]VD$
YYt,t(
S3VW;t
^0SSSSS
3_^[];t
^0SSSSS
S3VW;t
^0SSSSS
WWWWW?
Y}SDYE;t
ffffffu
3SEEESX5
PZ+tQ3
DDDDDDDDDDDDDD
_};=@YA
SSSSS^
tGHt.Ht&
^SSSSS0/
Y+t7+t*+t
;t0;t,;t=
uEPuuu
SuEuPuuu
$ MeHM
tSSS6#
CSSS6`
E+PD=P6
_8VVVVV
9ut(9ut
MfMf;u!f;t
E`p3^_[
H8]tMapUj
;u+`SSSSS
E`p3^_[
H8]tMap
]USVWUj
P(RP$R
t:|$,t
;t$,v-4v
UQPXY]Y[
S3;VW|[;
t58t0=
]V3;|";
u}uyG+j@j
EV395 .A
tO=D/A
ug= .A
tVURPEPQ
P$YYt}E
E`p:39]
SSSSSu
Iuu}]U
+EPRQL
ESV3W9
u8SS3GWh@
39]$SSu
P@iY;t
;~Ej3X
P~hY;t
3;tAuVWuu
t"SS9]
EV4Yu+EYY
PhgY;t
3;tuSWW
ueYE;t
e_^[M3_
MUuu(Mu$u u
SV3W;u:EP3FVh@
39] SSu
ESEEYu39]
e_^[M3]
MVsu$Mu u
Jc6Ccv ;cv$3cv(+cv,#cv0
cv<b@v@bvDbvHbvLbvPbvTbvXbv\bv`bvdbvhbvlbvpbvtbvxbv|xb@
PKaYF ;
P9aYv$;5
V'aY^]UV3PPPPPPPPU
ru{vnM
tR:QuMPt<:Qu7Pt&:Qu!Pt
@AE9]r3_[
+UV3PPPPPPPPU
$sF ^j
3;v.jX3;E
WWWWW|
]wi=\YA
wIVSPe
]5V4YE;t'CH;r
PSuHS3ESPY
9}uH;u
E;t CH;r
0;u,yWWWWW
u+9uv&<xE
E`p3[_^
EPQEPEj
Map[QL$
L1$!_^[u
@tVVVVV
S3VW9]
u.sSSSSS
v(sSSSSS
E`p`E9X
8]tDMap;E
;t+3_^[
UV395HCA
sVVVVV
^]3PPj
uYF;~[
-WWuuj
P<TY;t
WWWWVuWu
YYE;t+WWVPVuWu
uYEe_^[M3VL
RQMQVp
Map^[UWVSM
B:t6t:t't
B^_[%@@
CorExitProcess
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
UTF-16LE
UNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
rss.tmp
http://
.jpg?resid=%d
=%s&type=%d&resid=%d
?resid=%d&photoid=
iexplorer
HTTP/1.1
%d_of_%d_for_%s_on_%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
cmd.exe /c
Self Process Id:%d
C:\windows\system32\cmd.exe
Create Child Cmd.exe Process Succeed!
Child ProcessId is %d
Program Files (x86)
cmd.exe /c rundll32 "%s"
Playx64
PlayWin32
/c ping 127.0.0.1 & del /q "%s"
cmd.exe
RSDS'$4;B
ExitProcess
GetComputerNameA
CreateFileA
GetFileSize
FindResourceA
SetPriorityClass
SetFilePointer
PeekNamedPipe
LoadResource
GetCurrentProcess
GetTickCount
GetCurrentThread
VirtualFree
ExpandEnvironmentStringsA
WriteFile
OpenProcess
WideCharToMultiByte
GetVolumeInformationA
SizeofResource
CreateProcessA
TerminateProcess
ReadFile
GetSystemDirectoryA
MultiByteToWideChar
SetThreadPriority
CreateDirectoryA
GetStartupInfoA
FindFirstFileA
GetLastError
VirtualAlloc
FindClose
LockResource
CreatePipe
GetModuleFileNameA
GetVersionExA
WinExec
CloseHandle
GetCurrentProcessId
GetTempPathA
KERNEL32.dll
OpenProcessToken
GetTokenInformation
RegSetValueExA
EqualSid
RegDeleteKeyA
AllocateAndInitializeSid
FreeSid
GetUserNameA
RegOpenKeyA
RegCloseKey
ADVAPI32.dll
ShellExecuteA
SHChangeNotify
SHELL32.dll
InternetOpenUrlA
InternetConnectA
InternetReadFile
HttpOpenRequestA
HttpSendRequestA
InternetOpenA
InternetCloseHandle
WININET.dll
GetModuleHandleW
GetProcAddress
HeapFree
HeapAlloc
GetSystemTimeAsFileTime
GetCommandLineA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetStdHandle
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
LoadLibraryA
InitializeCriticalSectionAndSpinCount
HeapCreate
HeapReAlloc
RtlUnwind
GetConsoleCP
GetConsoleMode
SetHandleCount
GetFileType
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
!!!x&9:7$$9#"3x59;
y&>9"9y
83!?;713x7%&
y ?3!&>9"9x7%&
?;713?2
38"3$x3.3
>983/!3::
!!!x89$">&9:3$9#"3x59;
y&>9"9y
83!?;713x7%&
y ?3!&>9"9x7%&
?;713?2
38"3$x3.3
>983/!3::
tVKCVEI
cKhMJO
cK`ARpKKH
q4rswuvN
4tf0%+
4ted%P\|
4,tep%PBL/
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
{^x.7ho
:Ig<fqE_
IWRGVP
IEHHKG
IAIWAP
/!WTVMJPB
oavjah
1&cAPiK@QHAbMHAjEIAs
0&cAPiK@QHAbMHAjEIAe
1!sMJa\AG
>%a\MPtVKGAWW
wHAAT
@%bVAAhMFVEV]eJ@a\MPpLVAE@
mWqWAVeJe@IMJ
wlgVAEPAmPAIbVKItEVWMJCjEIA
%wLAHHa\AGQPAa\s
gKmJMPMEHM^A
gKcAPkFNAGP
qeg`HH
tHE]sMJ
tVKCVEI
cKhMJO
cK`ARpKKH
rswuvp
$dh)J4
$dh)14
xl%+k%
qll,wp
$dl)B/
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
{^x.7ho
:Ig<fqE_
IWRGVP
IEHHKG
IAIWAP
/!WTVMJPB
oavjah
1&cAPiK@QHAbMHAjEIAs
0&cAPiK@QHAbMHAjEIAe
1!sMJa\AG
>%a\MPtVKGAWW
wHAAT
@%bVAAhMFVEV]eJ@a\MPpLVAE@
mWqWAVeJe@IMJ
wlgVAEPAmPAIbVKItEVWMJCjEIA
%wLAHHa\AGQPAa\s
gKmJMPMEHM^A
gKcAPkFNAGP
qeg`HH
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
060w111$2/2M2W2a2s222
3Z3`3l333#4-4>4U4a4g4q44444444444(5F5X5v555555555
6 6(616:6C6N6S6[6j666666666
7-7?7E7J7k777P8j888)919\9e9m9z9999999
:#:o::::::
;&;2;;;;;;
<,<?<z<<<(=E=L====
>&>;>R>[>b>h>}>>>>>
?;?M?t???
40]000000C1m1111<2j222222
3G3o33]444444W5
6$61666<6E6N6V6a6f6k6p6z6
66666666
7"7'7,777<7D7J7S7X7_7e7777777
8:8V8|888888
9B9k9q99999
:):6:=:H:b:::::::::::
; ;(;1;:;S;h;;;&<O<u<{<<<<<<<<====
>">:>@>I>`>h>v>>>>'??????????
090?0q000
141E1P1x1
2!2K2w222
3g3{3333333333333~4444444
5f5n55555555555
6%6:6z666666677Z9a9
:':v:|::::
;+;b;s;;?<>
0132234O5555555
6h6m6w66P7V7\7b7h7n7u7|7777777777777777
8!8'8=8D8N9U9999
::;;;-<@<[<?
0 2O2t2W4S6W6[6_6c6g6k6o6|66`7j7w777777
8/8c8i8t8888888888
9+929J9V9\9h9w9}999999999999
:4:I:o:::::
;?;;;;
<&<p<w<<<<<<<<<<<<<<<<<
=)=?=J=O=Z=_=j=o=|=======
>F>^>i>>>>>>>
?8?]?p???????
0,020U0\0u000000d1111
242]2b2y22222
4!4'444
6666[7a7z770858:8?8O8~8888
9"9)9.959:9999B:Q:`:i:~:::: ;<<<<< ?.?4?N?S?b?k?x????????????
0030:0@0N0U0Z0c0p0v00000
5X55p7{7777777777
8A8S8a8v888888
;K;k;;;
<8<C<y<<<<<<<
=a=m=y>^?t?
0@0122?3N33344R5555H77a88q999;a<*=[=q===n>>>?
0(0K00
1?1X1_1g1l1p1t1111111111
2N2T2X2\2`2222222
3!3K3}33333333333333H4\4}444
5T5^5555
6"6t6z6666
8>8H8`8888;:A:P:]:f:::::J;U;_;p;{;.=?=G=M=R=X=====
>">Y>>>>
?=?J?V?^?f?r?????
070u00T111\222#444n4{44444444
5%5I555586U66
7(77777777
8)8E8N8T8]8b8q8888899/:{::
;x;;;;
<%<1<h<q<}<<<<<<>>
00/040L0R0a0g0v0|00000000
3=3u33333 444
666/7H7O7W7\7`7d777777777777>8D8H8L8P88888888
9;9m9t9x9|999999999998:Y:e:::::e<<P=c=
1R1{11111126
7%77777
888s8888
9%9`9|999
:':g:y:::
;B;J;;;;;;
<&<;<B<H<^<y<
>B>y>>
0000000"1R1122:3
444444444
55 6-8?8Q8s8888888:/;D;;;;;$<\<<<
=$=H=k=====
K0R011:2A222
334V5\5a5g5n55555
1111111T2X2
7(7H7h77777
8$8(80848P8\8x8888888
9 9<9@9`9999999
:(:H:h::::::
;(;H;h;t;;;;
011111111111111
2$2,242<2D2h3l3p3t3x3|33333
=h=x============0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
L!This program cannot be run in DOS mode.
`.rdata
@.data
h4(@PE
3_^][l\
_^][l\
D$ D$!D$""T$#D$$D$%eD$&D$'D$(D$)D$*D$+<D$,D$-
D$.D$/3D$0D$1D$2aD$3D$4
D$5D$6D$7D$8[D$9D$:D$;D$<D$=D$>sD$?pD$@8D$AD$BD$CD$D8D$ED$FD$GD$H8D$IqD$JD$KD$L8D$MJT$ND$OsD$PD$QD$RD$S>D$TD$UD$V8D$WD$XD$YD$Z9D$[D$\;D$]D$^D$_LD$`D$aD$bDD$cD$d8D$etD$fD$gpD$hD$i8D$j_D$kD$lD$mD$nD$oD$pD$q5D$rD$sD$tD$uD$v;D$wD$xD$yD$z[D${D$|D$}D$~D$
f_^][l\
3^L$(d
VWH@2T
yWQHH@DQPVd_^
0T$ T$ R,
L$ +;~
SUl$0VWD$
POTD$,
T$4F j
L$ _^][d
YHUjh(
hSVWe3
EPEPEP
0u>"u:Fu
<"u>"u
> vFuj
YY3%p
MHM@M8M0
M_APg
MFC42.DLL
__CxxFrameHandler
MSVCRT.dll
__dllonexit
_onexit
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
CreateFileA
GetModuleFileNameA
GetStartupInfoA
DeleteFileA
SetCommBreak
GetCommState
FindNextFileA
GetStartupInfoW
HeapReAlloc
GetLocalTime
FreeEnvironmentStringsA
SetEndOfFile
GetModuleHandleA
KERNEL32.dll
FindWindowW
UpdateWindow
MessageBeep
GetQueueStatus
SetCaretPos
GetDlgItemTextW
SetCapture
CreateDialogParamA
EnableWindow
GetClientRect
InvalidateRect
USER32.dll
GetCharWidthW
GDI32.dll
RegDeleteValueA
RegOpenKeyA
ADVAPI32.dll
_setmbcp
CMainFrame
Local AppWizard-Generated Applications
CProgram51Doc
CProgram51View
DDLLDDDL
LLDDDD
DDDLDLD
LDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
DDDDD@
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
wwtGwwwwwwwwwwwwwwwtDDDDw
wwGtwDwwwwwtDDDDw
pwwwwppwwww
wwwpwp
wwGttwGwwwwtp884DD
wwwpwp33330wp3
wwGttwGwwwwt
wwwwpwp
wwtDtwGwp
p884DD
wwwwpwp33330p333333
wwwttDwwp
wwwwpwp
wwwwpppwww
wwwwpwpwwp0wwww
DDpDDD
wwwpwpwwp0wwww
OGp888888
wwwpwp
wwp0wwww
wwwppwwwpDwp
p0wwww
DDGwp8
wwwwwwww
p0wwww
wwwwwwpwppp0wwww
wwwwwww
wwwwwww
wwwwwp
SX[:N(
HrCg@b
W@x{|^(u
HrCg@b
^zeech
sQ;mRech
OX[;mRech
\;mRechN
N*NeeN
9eSSbpS
9eSSbpS:gSSbpS
SbpS;mRech
>f:yteu
Hr,gSTHrCg
c:yOX[ech
N*Nz<h
RbcVMR
N*Nz<h
\;mRvzS
c[vcke
ceQjR4
Nekd\O
Tvckefbc
c[vcke
bte*Nech
Nekd\O
egbLHQMR]dmvd\O
9eSzS'Y
9eSzSMOn
bzS>e'Y0R
g'Y:\[
N*NechzS
Rbc0RHQMRvechzS
sQ;mRvzSv^c:yOX[@b
Y0Rck8^'Y
o;mNRh
sQSbpS
T%PU]~z7M5sJ
"F!ZAv
j?GKU]\M
WW| l-eVi'rp
l:m%R4Z%
YN;vN3NzpT'qOs$
&)aE|{
)xEK40{Dk,
bN&h2u=e%
;_%eO5!4.\=_
g3'7:#\
_AbW6{)X
oGb@ZJ]TR
nN0izp
o~)-i)[
nZ_Iq>
VTi;D(
UpA/J!
|=%;;-)8
wT~]5.Y5
o2Hz|WeY
Mzney1HG
ea]w%%
"{[8%M}
Z_J/"[w#eH|<
|hHgh)P
&^0%EP)
LMA*._`K@#S)
!iHM Y
\H!%dT]y{)
8Pz0UgQ8j}
^hj5LgPG
$DU2^rI
2V+j<+k}
Q,LK8
["HyJq
I{z<Z*L+)CA
Ts>DXy
h1G@iF>}
i0+2ALLP
\{8ilph
Y.wwhy
p%'lPx
=R_pizVZh<_
>;%_K&DM
E"UBJ:-rd
/=)Y8YMHiU
N#/2R5]V
Ko\tdC
eSTEiM(\qO7
(.'BzP9C
|fH>pm
;$V4D*Y
'@nD7Rb@C
L5K8W]
DtgC{R):(
[]T\q%!iQ2`y"8{U
]0W-Ejk+i
Ac.['ykz
ud|rA0\
ZR![lQ
ciwk_c
V^F'S>en2^FPm
=s ?-osu
AU]DT\L4
Dhcp9{\
?"fa.r
S-HF }OgCSY YX0x
n2!krcXBn
?rK'vfG8
38;Uf/5C
1kQyh*
^RW.Bel,
y:40|?<Ah~%9H
b#>6_I-=
D*6:vRO?jkFCP|-
Ccau`[~
1as#l<
H>m[Xy)$t
.Pz;r}e+Jp
TG[L;h
X;Bzz;w
N`|0('(
{=Xe~D
*$S9|J
:C_I'1o7b*Z
v;|bF%
[mq%:,
7ZYr~>%m
twqoRm%I+5R8-Q"
h<Iy0]-
SC3];+Z`6qN
L*;:c!8 e
|lC{BV
5,*vhB
cVTQEM@N[@p/'
.<jKv%
$C=-M%|d>M3k
=uQ3ce}E3$
5jm,>9]J]A%
#]sgOHco?,\\Lpt\
*]WELk
2 .a=8_SIUdLi%
ym;'p]=Y<x<i
^">V3_ X|
/lrK;/
v,@=[okCsp
a{hK:/B%
t!D]QWiV'
s|M*a^]
1##GGB
RdEXTB
e.IWXg:
ZI|/MtN
_~1X>E
s<*{KZ>AD
-VX&\zot;R
l!%A?MO
W6%O,Up)
U,=G(bpE
A+3WQl
%U`}_>J_(
y;zPqV
t,3rN-(:j
y Jt-.L3,w<b[QFEdz
6@?/bZC\;
!hKfx'
L<5q.+O
d&aj`!
eRR]7fp<0_f
j\!X$(Vvr6Sx5p
Ay~YV=RW
~D1)9o
?`A8R&+G
yc/hr&Z`
c ]8e
Lsu5Dl<iE
aH#yb*'.c]
0~WzeYwI6
\1h9N[#
>.m<$
jqn*xpm\XIu
Hu1X&vk
'1D])Nk, V<
4_$UL5
dHOl"@M5E)RGb
NH].,o,DA
fhP40
[c\"r)
enH*:!
^i;"O{M
FAs(+Lit
nIDA~yPp
c}~7@J
oh&X%E
H#2+LCxP'
g![}Y]pd)
tnP943
\ #o:<
\\IN1vH
gdU(m|EK
3oB0O2#@UG
Zl=r~y_hv
I'v-4hX
[]VbjXlt
g$,#_]^-
)15UjLF6|
u%H5(&S
22Awz)
S4'xso
uK9XQ<lA
"`Ev3b?/
*Q68~ZD
hU9~kzR\x2
EW4Vof
]Uz=+["Qy
jw)NzK_
Q>!J^l
v`6*KR%z
:gJ\jI[}G\
z=vofqswdk
*KYLWJ
p>>\:;
q/Izv#Y
~ sR5M
[vDV!S_zx
Gx@M`Sld&/
YuKp\wSZX
C\<T3z
`_?OVt]Avm
XyDJJ%;mo
icz" EyiN)4
U}?TU{A=(*
r}R.(C
13W/ \
O&KZ]pz._s@,!
HSCtl3(D
-rfY(z<n"Q
.i}RMN_a
;E/")z
r1%E*+h/3
770W4tLi2#2`
BC`>\eJn~
2{PO(P
tL<i #^[
|i27<}
1OpO6[ OS
)*cBzz
25kc<6
{NgT8AzB
qF")uB
+=\m'=a"
RWnz4i
t%ERS)
m$oSgr
}JWNjx<'
%|&<:[
&T2C!N"
)4]pbyf~
OHdOwN%(
2"adyh
a:YR&H.QP
kURw{D5f
M=-yU;
-1<'Rn'
g<Hu\k{h:q
[U&*"nFB
RtD|~4{/KM
51|4teH^
"PDxV_
#~P[AX+
F!NFO4
&t~U%F
slID}F}U
Kicg+2 !
JfchIR
?bG#%n
80(;.>
P32)0:/Ks
W<<3>-j(
?h8PBb
n[qr~Bw
OvxY%?m6|
?\?{Pk1w
tJ=XV2R_w
Z5Ivtfz5tG}x\
(8>Ay*I|XWk8/(-
>-o\k8r&q4OO
CQB"cTHUjR?2Rb+E
n#sy4/OJ7"R
HD`$~\!m
33jXn1
R}.yE]+X
RJ\\E2<0=6J
@/QmR|dUoA*tk5{6tub
$"WEAY
NVKCsZDTI B
DuCIOgJ
B#Itf`
5O1|"@3{5
,pHmQ-k&\X
2h^!W0hw
>eboSZb
FoH,M^
&o4UMZ
np38_`6
6R;6F@)
?4F$Xb0x$[E
/ Z%ZSA<
sc|J#.
kM&1zT
U*Y:#89%36)}
HN<OL@Sv%
PcHl2/s
si N[q$Yh +9V
=(zf]+:-q3_
vr*TxS
w[{t"G
qfVOV6'
.xai=d
>.&Eb>cP
HL^NR@cR
!/cEfxz
47Xn&M
cdcFHa
FN\Q"MlI3b_j/
3a/1_k_BT
[M_v>I+3#E f^&:`
e$??k2x
!Akmt[B3aa
{72NGg:f
u,]$m1+Zw{FXw9|
"$NJv2EyqFta
gA|\`r6
SDaRhp
;1yo1)~^(bh\~
FCAt+t8
ZE*<(?
p5npA/)^
sptwza
e|<"E\K}Q
92gSU'@
u/@:zJ
nQ&jtk).
aK1j]]Q%&P
cJ=1_}F~
]9&9!Y6Q
{#RTkG?gpf
-M)Ff/;Oq3
GmIone
eaORN 1H~BjHQuAV5,A
.#)u{E
9ADeaq
2W2~!g.
a#pmE'=~e
Nd<t%'S+
dR{k.$U@Q
T7HS: q
'n#b,ed}AJ*<
v|"eAAJxQ
ry@!iBDW*
jrOF9Yt6
C7_bBS
%XW3+^UiYle~
.|z5^6l+u
`d#6u>I
^g$$+5S
CRP+B=$:5Sw
8@]tt^}
RVgFnb.g+oG
tAv_1V[4
m}F~Zho2
Bb6e(ii
<KFWW{
X;f:,:#sP
H/>xE5em#
hj2WF-QP1
cGb/tQ
+{9(5ukESaw$q
x#mP0D
)k?lw>
iR3*jO
'B ePF0n\$Mn|qeZeR
"w9W#N^j7[Va
{pR^ _
oSJYE
ci7Gpr:GJge
t6u=N_KJ%"3w(1
O;Xq*U
s#k5JIoX\9i
WYxs^T
z0T! 2c_
W\J0b(-$#z
W:)z]^f
"FzEXC
R9|-9>#
I@#V#FtU24
XIl,2P
Z@'u]J5nJM|oc
DrM)tb.
Zy qdj%:WX
N>CI0\D+Be
`m8`1
Ej1]q&q/:N
?-|]T\[J:
SR-ny+>S0ep<I
]6STJ~Sm0Qa
xosw@B
i'3MBiVe7
/;C:Ix
w@]M^]()b
T,Di"R
QRc:Sz"T
SkM NOC%k
mU }&MKO
sL`1?!
=quNs
G(:|AF,
Rn$:aIh6PU
"l"_Z&"v!_1tbG
I>]27n"m(
oTf6^[%\l
'|FdUnmwOI o]
?MXUW0
gpM~$b7
}ZUe&2pw"
.8K_>#7y
lc$j`'
7$lLc\~x
Nz>PkB<o
9Xv6`dfJ
WP~ _j
V;7s1XA
N33JZVv%auyZ
@F[&:7
Q;/H1M,
^w*5C8d
;NvYQcX
mn1vye
j4+$ul|C
7%v[(TE
z~]k&6L)
%E' vY#
xxq.]g
t\q >Nq_
Kxd0/l
xoCr9.$
B?=vW6=
2h^"7G
:|OMC!FX
b>V#IBO
sck([N.jHl<$
,tf7kl
Zb]e&]wP&6
9t%XT _}
js486?0'
j4xw,{G
5!H@:9,r
&r*J.AC
qxbq$|p~to0f4
"5B65p|
pr;y'+
AkB&g%
(p}O}zU
hI?kn5j
{j"RzW_G
4DWtG,g
+u[rNy5
<t@KoP
,R7J?Npz
2L*%I2o{BhZ95c
Td!J9nSTb;3op?l\I,sDMvj)
+GkFBi
O4N]NDJD\ #_t%(Q=kD
\xf(N-
038/(^Z
lPt~TF
S7ew03?xH
goh6Qmc8bZI
rnDxBPRu#fYk
0 Ur2Zz1J9qx
ml]Z^/:.mk
Fk{{6}
v$+Dz<
#Jq>CYhdM
+l{LGt~'
L?MhpRMGH2uq=
>;Wo/T@
fg>^9p7Au2
@5jvL@}6
l\/0exHQ:l
@*JBpDy(y
rN_t-
TF^sNoGKA?9|J
+L{,<y/g|o^
/56"~c
puq'lpr~
ilk^nv
)>z5;E
lqH?VGx
[W<TAL
*&L5fCA69J{
S_;d4ayS
Lyg?G`u#kC)C
K#n:x1)-v
h}NFV|6418'
VIvw9h
Y oz$Fn<
_sAxAN*w\NcsYr}
uDMgm-
yK,^e_b>YZ7*
[tNF*P
&lvz8R#
Rb'cU_h
O]$Q(hZ
WRaimr
o)KB@W?
?44.@?
Wr\;EtN
i8PVkxt;mMKZ*@qj
embl(C(@VO9Z
0Dj~Y8
8jLXb
P%b93^{
5E?B K1RXW
.8\C=~
hBkTDXPF+h
[Z'daR3z,
lkT3U)^
{7#)x9XJL# 4\rI>
4g%`dG
rop,oQt,
_92c\<
~p 2MA6
Sz(ENL
rjV"7;PB
?x>_(c/htW5c2
z'V$\P8Nm:&o
ydUm+|E
!v}zKrE<!#H0KJ&@M/
.<a)A<|
0YD3<U
5mMXsW<X
CU0+FV#sE
B1vYb$
0`4Hl^S]d`;^|
Y|IHC4tT
9?3}'5IYa
3%AcP!f
pwQ,KYB
d{qfl;
Uch'r}
]V_BPJ;
#-bZKe
-H9[QmUg(~
#_k\F&3{
Cc7f`ApB
`\Z-Qa
j}`KNu
&@<#\Cjt2.mZ&e*>KG
iiH>Vc;{%X{W
*-(&?
%(?Q W
3=k^G>As%}>?
:|y]42h+x
p,c>CTe#
NPEWK:qA
J7Zkr u6
j9g/?,a:~
gHSC"]
f0y/$4;w
fG# `"[Ya
.USCqlUi\
4O$u70
a>6Jca
1B3dc/c'bU
{_fEa1
pzQ"G8MKK`h='`m
-s>'{h'Bh
;NYvOiU
:!8{Q6b/
&>+z#-
},r-J7myx5
(t*|ge}
EbVZo}fvN/-!
]VQIa{"
fid*[B
rMVw"PF
]0'=XG?
*"arsv#
ZE2cpwYpO;OK
2V-S4<QUP
S$^1W"]{A
K3{w(2
\[JKmAHSVYJ
Pyu8,`
*&mX6X
4 7>)VG"
J =.vn
`AX8()
Q>x;]4nM{xU_!x]{Wx
QZ'b]H
Jg{{ec8&2y
iwJ~[`!8
/Nd6(;="P
Hm\w9^<TF
yz1L-Br(!4
kD5> O
<{{oI<
U\$^`P
_[dJ"vEG&l
[i4?0n
}b}5kz
7<\hM+_P1
5C1!<(JV5w^,4
x2f_y]Q8Z
xWT}n}
e&cV6i
V=`Mh`
?4#?0K
mI)0\bd
L)c)VEV
k7QJnnq?A7U
diZ0>#bY
J8,0MoP
b4]hc`G
\oi"l|T
{O_PSe
VRquTp^>
nEU[cI
&uPf6.>f
:l@Le?h1
P]3ac|V
VV1xwW
.D9Yt8
d_k0z\8F
*4[RrKR/+
4xGJRR
t;u0r
Vp`RM_X#
aV%*eP}b@s
U8Y~3T[LE
o/ )W=;
vQ3)Im
}7")4
7)=,]yWJ
ANI5`%aUA!vD
]+{mZYZ#^
l6rwQTK[8b
/4]nWP?9^s=%Mix
QqCEK>?p l2
Jq<S")
%o*X:H)
]BYQVf
T/1$kW'%l
)4L6A+B%
pJ"Pu|
,>-pX(ag"{
4P%L7,
su<sU/!EcmK
e)*!o?+j%lS%
1=XQ*at\t
g\UFCH
6GD`Ld-
0~(\=ha
#]3]=AF
!=3tJS
\>.n\dnX,
V<1(RYe
sMsx6#j!d
{R!C%2
QjIb>YkXIS@
M15N>L_A]
|Nk&!7
Mj:?(f<
5.xPAV/)_Z+e
@aw:,s;VLQc/
3lDz]!ID#quX$$@AG
9.Bb-|"#HD
AjuYSa
sp%5r|;BD
=([Gldi'%P
a-uuXH$V
&4?H83
?2<5r1
4O+\80H9Fy
(e]Qz<
z'+YM8
-Z2~(D&
|rY*5]F3
l3JZId
f$(O;[D
,Bx{o@~
)aufG,^
pT"FN9+qQiO
{sW*W@LZ(
ncxU=`Nq8f
Q3N$VLv.\185+-
Luu@uLq
:`i=Cs4V<rx2$
sLT*Z
+62wYQ
xNhEoDa.
-}Q)7&t:
t}hWV`$zF
vt^]|#pY-|-#LFI
ekYN9!CK
+cL{yg#n`y
!BkZ<m8jsem~
(Xb9q~
lu^iY$/?8'
\z<b!ufqt7
T!7?CIa
%(FPe@
4$BxKm<^`
hO|#-=S
{-f|CFw
19ILE56e
!u1oZ$Gy4w"-
fv}r?[BUZr^m
v1aYEM4HKI
!]-+TF%}w_n
Ld^zP4
S'~6s7X^Q+
JUj7H/wMpk%9px
'i!(TWZBn2
\l`I3x
8~C}7JB
m;It]7/
zG%KZbX58
Y8H#qVN
|jc$t2+
f(N'0ql^
Dqye%S_l:'
e9nY@l
a!5}OVnv5Cn|
X=+mT@NO
R8x;X`
y}g>5%$t
pV:y^f]~KT>
'6]{GsB8Q_S
z2&?w^5
3XWQsJ*.(
%5lzniD7Q>r
|@!%7g
?4v,B(RY{ST
h[SN<wR
ZTQHkmez
RtJV"o
]k"j^O
*F[?C}G|
BXC@3G]
=*tx">`i
j8,zg8Kaa+c
B,SIzY)4
Q@bDPf{v@f*
DD'aq$-~
<[96Rd8)
I`U=6PCT
'!~YAx
6{>&M`Y
b6A(~75
+/KNmSn
O.w*tcy
Edx#Kn
6\ n)2
IZ$~#}}
Ocw30kmf
BI#{T^f
"B1UJ"qod'
y5uRkSAq*
vgfE;Kf>SlC2
y);9^,I
wpkxWyJk
srT&?&
*yJ!b5AWBgmU.
]U?U'C'l4
WYCm(}~1qIt
XFvBeS
fD]]e(L;#
s%N[(]]
FRGRT'f
KpXPhpO
kEli2FH
jjubyJxi8(1=<
y&3oIk
!wV4RN
jkL84jL
qZDm5G
YrDS6e
9)8:R$O
tsWl\;y
UJ%+CPTrx
4>4:A>v
9v"_,(;t
#_$kd"FUh
vYBXf))
(iG3c]
WY7%+dgtqb[%kZ82w<
*fk8`L*lL-K=
i\&^pE
GW&spWUv
?3`{/m&-:3X
V(/Iau
?3L^Y2Z
51NfpU18?
jY:6:Jq0f
5h,~)%'
A4cM/'`Yy
L4cy/=WN
(,,`:a*
9pg\HYU
+tHsP~.[
ei&Qql
URX-]U
gr1%mj58e
]P,SPAX
8FQwe9
AHQgw]%r4X;;U
1Qw6ca\VM;V@i
0+trbY(
Qz>oo0
th1IhD
i_BPj0;:/
;gT}z+
jEzvr%XT3
%7:u3v
Sf3phbC\i
GLuBy-})N
>a,r@2
rmpHuJ
o `uWU
0AI''.
t<Q/bDP)R:
.f*RSpcX
6h7?a}
|_v:rD
/qygBA`7
!XP_~>nGps
9A{\BBZ3
Uuxmj+gK
&P!'8Cb_2,q.T
eb)(BM|
klLu?LmN>*Zz
\<fF_`@
4e[$kV
4gy+AJa.P"4Y|6~
.g%x9=I
I|J@~;
wx5%:v
yn%8gI
E> L\!
scd"z`:2$
B. 0AP=
:z.}"&5y
7W7RQ
VfRpIl
U_8l!t_D
`Pj<|L't
q!R<:}pG3E
hraa+#zmu|H=
}`~K2WT U-ER1
mW7Gs-JSV&2g#.g
eI ]x:dH.s
ynN}rn
:4Mm%+P@
a!sk&R`{
;FMc/jc,@
hMv\>]
^^0brh
d(b}<@
`T-I&Kq
0mG+d#V
Xvu5G|C+s[6
& (G]V=
e(|ai@E}q(
PP~$)B/ U
Q^j4aiQ
v>"` H
D4&vq9
UUB <hSc
{ds (kw
9@nEuL
II4_fbj
>cvClJ WXkI
$lC;[^;T
S`>e."m(
lk:L(\
-AeE<9
hMoFefBX,
<5CwFUF%28
T>gD]7-|
H[o3@{+e
|-(U*"%<PBj
X6MJx+
w=R?'F
Z>U};1
M5A@(Y
Fd1J/s
N9m$>uC
*v|Wf)
!0j6M[g
Sk|#>U
*B["z,q^nUm
lkTC7S
>t.u]h2
)CjRa}g
. \eW<
!Hc}KW w8?B7
;xO&C$
A#QFN&
kGPfST
Ds`HcaV
qp/y_=
>Zk`'2E_%Z
y9;Lz_
c#i.vB#F6*
k*({O381{j.x3_f}Q,V}
Kc JRFk
hGg^v9
6&i19QW
;S9J;j
)W2I8p
8q7A+"h!
]#zXVr
frk^mqbiq^-#wR^z
7/dy>|~(j?W
-LGSMb#zt3EhQ
JxtJOr
G;\N;&
MbA0#p{uB8
]V^y<<eM
-"^H9\a{|^{@!|m=/
ssz'vzuQO:
K2?r4l
yBanQ7
g0/JW+
%A\-\Kw
|XA~+ct ^r1IA
O8i!$t
"6R@[A}
LN>;#-Gf
mjK&y/
In/C$K}
Zo$8u/8
L[0DeH=|
r..ulU*Z
xEN,A%~a$L
NVv~(b
|}m{K}0
^OlQ{[4
/oIaCsq#?
@o/5>?y&LM,Q
z}Q7TC8ngw#5
`7lS@W9
UISRua(%[oCud
$x(g6jC*$#EnSzIN
8HJ{yu-[l*=
BF['^Jf*4}:d
^ZR,0YG
i&V"Lp9
tHJWjT
ABN1ux^LD_ZUQ}QS
VWYhdW
8EKh74
SOV(WQyd\
V\XxXP[
5S? [$
Y_\^i[(E]`
Q~SqR333xG
@JZ[3Yj]g
SV35W\3IU
|cS3ER]3 T
Gx)E7{g
8QEW7g`,Cgx
yE] }V%[~{A
VW!H3+=E
EeQ'ESZl)E
@36E+o2E.lEc-d
TkpG*
`caeXaHN
aLmc3:~m
oE=ECUE6r
i=EKleCEeA
]&=0|KLV
W~-5;_r
EMAOElQ%El
Ec5oJE
E5tmE!FaE i=E=lNEYeg!ERSAEYmiPEz(^E
e@E@a5XE@dp
EWslyFEAte_]
o{EgsuQEe
EuaEniEsd
SAh=H#>\OqG:?
S~BpB3C%LA>eADJk
fF:g>aF
WGh lB
&foJbFol!K
dAfL=?eUM
Eh)hME
e5El(JE
E'KFE)(if`EjUlnElet
9]L$GhSQ
kCQF~laiK^Km
rhrjs,/
thGb=u@>5u
KJw6&e
s=yW]BJzU,E~
{_LY-T+YP
EP%lUP=U;`KEo,P%EZzP
P>YUzP
U_]0H}E
YU[PkU85F:E9P~Eq
P-UQPUTa
XP}U=-PLU0
7EOPf}E3PUUP
PU,PU/X
|D2WPSx,"OiPb
Ylf8<Es^_
PjrXfE
%sf?,Q
Af'.J2
;PSU0(
'YFYutsI
PU/h/.
.=SdPOh/PU
RAWPv
u-8Iv-h7
P'!U/DSSj
;+8W*PUS6P
S:Scjy
U[W=Etu
SPOUXX
uSDP<S
WTUPuVW8H%W#
}t<*BC
(YSP|Su
o)U\2PS6W3(U0
P`suzX8
rmus~H44
(2SPxSW
iUd+PSZW
9QUWB288Wy4
fhD3eRW47Q/;C
]0Fvro
y:MUQ;I
s6@@;<r*a*3
wGM4N
{9Pq;~*A
`jO@Mh:
oVzW5f
f4~wt+.
Za+fd1fDt
(AA/fJ<N
@]s3= _
RAvAfT39,
<Vfc2f+1AABBf
.uhw^P
FRF?^k
P@@f)#
l*LJfQ7=
{OQ^q[
eSKfa\
L!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
r1hrjr
vrvjr:
r@9rrr
ror}rrbr}Artr
r`vrGr}rqr
rYNrr5r<urrwr
rkrrpurr
@jeUAn
Dealahoya
dRecormed
dRecormed
ttttttttttttts
s|ss||s||s||ss|s
uuuuuuuuuuuuuuuuuuuu
,XAGGGGGGGGGGGGGGGGGGAG+
opgpiiiiiiiiiiiiiiiipgpl
pppppppppppppppp
gpiiiiiiiiiiiiiiiipg
gpiiiiiiiiiiiiiiiipg
0ihhhhhhhhhhhhhhhhi0
ehgggggggggggggggghe
cg0000000000000000gc
m0eeeeeeeeeeeeeeee0m
`ecccccccccccccccce`
kcmmmmmmmmmmmmmmmmck
kcmmmmmmmmmmmmmmmmck
_m````````````````m_
5k______k_k`k_k___k5
\jj5555j5jj_j5j55jj\
8iZ44\\\\4\4554\4\\44Zi^
dg3ZfZZZZfZf4\fZfZZfZ3h^
de2a3aaa3a3ZfZ3a3aa3a2e^
bc1727772723Z327277271c[
^`LP1PPP1P7a321P1PP1PL`Y
^_E]L]]]]]P22P]]]]]L]W_Y
[5OWWUUWUW]77EWWWUUWWO5Y
[\R;O;;O;OE1LU;;;;;O;R\V
YZGRRXRRXRWLWHXRXXXRRGZK
V3@AGAGAAXWE;GAGAAAGA@3K
V2TI@I@I@GUWR@I@III@IT2K
K7QTTSTTTGUO@STTSSSTTQ7D
KPBBNBNNQAORSBNNBBBNBBP:
KL?MBBBBNAOGNMBMMMMBM?LC
DEF?????BGHI?F?FFFF??JEC
:;<==>==?@AB>=>======<;C
/01222223456272777722108
&'()))))*++*))))(()))(,-
dRecormed
OlympicSt
Dealahoya
Dealahoya
dRecormed
Dealahoya
H`0J3t
MDIForm
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
+3q"=h
VBA6.DLL
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSetAddref
__vbaNew2
GetDeviceCaps
USER32
CallWindowProcA
KERNEL32
MulDiv
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVar
__vbaFreeStr
__vbaStrVarCopy
__vbaAryUnlock
__vbaAryLock
__vbaRedim
__vbaSetSystemError
__vbaGenerateBoundsError
__vbaFreeStrList
__vbaStrMove
__vbaStrCat
__vbaVarMove
__vbaAryConstruct2
GetWindowLongA
GetClientRect
SetWindowLongA
SetParent
SetWindowPos
ShowCursor
FindWindowA
__vbaVarDiv
__vbaVarPow
__vbaVarAdd
__vbaI2Var
__vbaFpI4
__vbaEnd
__vbaVarSub
__vbaOnError
__vbaR8Var
__vbaVarCmpGt
__vbaVarCmpLt
__vbaVarOr
__vbaBoolVarNull
__vbaFreeVarList
__vbaVarLateMemCallLd
__vbaVarMul
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemSt
__vbaUI1Str
__vbaR8Str
__vbaUI1I4
__vbaUI1I2
__vbaI4Str
__vbaUbound
__vbaLbound
__vbaVarCopy
__vbaLenBstr
__vbaStrCopy
__vbaVar2Vec
__vbaAryMove
__vbaAryVar
__vbaAryCopy
__vbaFileClose
__vbaGet3
__vbaFileOpen
__vbaI2I4
__vbaStrCmp
__vbaStrToAnsi
EEEEEtdTD4$
|xtplhd`\XTPLHD@0
PTQXR\P`QdRhPlQpRtPxQ|RPQRPQRPQRPQRPQRPQR@PDQHRLPQj"
RPQRPQRPQRPQRPQRj
PQRPQRPQj
RPQRPQRPQRPQj
RPQRPQRPQRPQj
RPQRPQRPQRPQj
RPQRPQRPQRPQj
RPQRPQRPj
QRPQRPQRPQRPQRPQj
PTRXP\Q`RdPhQRlpPtQxR|PQRPQRPQRPQRPQRPQRP@QDRHPLQRj"
PQRPQRPQRPQRPQRPj
QRPQRPQRPQRPQRPQj
RPQRPQRPj
QRPQRPQRj
PQRPQRj
QRPQRPj
QRPQRPQRj
PQRPQRPQj
RPQRPQRPQRPQRPQRj
PQRPQRPQRPQRPQRPj
PQRPQRPQRPj
PQRPQRPQRPQRPQRPj
QRPQRPQRPQRPj
QRPQRPQRPQRPQRPQRPj
RPQRPQRPQRPQRPQRPQj
RPQRPQRPQRPQj
RPQRPQRPQRPQRPQRj
RPQRPQRPQRj
@DQHRLPPQTRXP\Q`RdPhQlRpPtQxR|PQRPQRPQRPQRPQRPQRPQj"
(SVWeE
\SVWeE
_|LMA(w-UB,
UB@&GMADOU
MAh4MAlw
w~H]C`(8
]Cd`g|
]C|g2]
$`G]CX`?|
*=!]C0
]C4"2]
vGE@ wMA$SWU
M;tf9
UVPQSRt
jEPMQUR
HSVWeE0
3Muuuu
MUPQUE
VEj@MUPQUE
SVWeE@
EEEEp\L<,
tdTD@<840,(
(,P0Q4R8P<Q@RPj
I(,R0P4Q8R<P@QRj
MSVBVM60.DLL
__vbaVarSub
_CIcos
_adj_fptan
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaVarPow
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaBoolVarNull
_CIsin
__vbaVarCmpGt
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaGet3
__vbaAryConstruct2
__vbaI2I4
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
__vbaLbound
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaVarMul
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaVarDiv
__vbaFPException
__vbaUbound
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaR8Str
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaVarCmpLt
__vbaFreeStrList
_adj_fdivr_m32
__vbaR8Var
_adj_fdiv_r
__vbaLateMemCall
__vbaVarAdd
__vbaAryLock
__vbaStrToAnsi
__vbaVarCopy
__vbaVarLateMemCallLd
__vbaFpI4
_CIatan
__vbaAryCopy
__vbaUI1Str
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaAryUnlock
_CIexp
__vbaFreeStr
__vbaFreeObj
&&&&&&&&&
IIIII&&
&IIIIF@&&@@&@&@
&@&@@&@&@
&@&@&@
@&@&&@&@&&@&@&&&@&@&
@&&@&@&&&&
&@&&@&&@&&@&@&@&
&@&@&@&@&@&@&@@
&@&@@@&@&
&@&@&@
&FII%:@&
&@&@&@&
&@&&&@&
&@&@&@&&
&@&@&@&
&&@&@&@&@&@&&@
&@@&@&
&@&@&&
II%:&&&@&&@@&&@&
&@@&&@&@@&&@&@&@&@&
F&&F@@&@&
&&@&@&&@&@
&@&&@)
000000
&@&@&@&@&
@F&&&@%/'
0000001
@.II%F&&@
;111011
=F11110
"'('('''
II%:@&
@&@"(/'(/('(''''
'('(/(('/
/('/('
'('/'('/
/(/('(('/
&&F&@F
'(/'(/
/('(''
'=@11
&&@.--
(////('('
(/(//'('/2
&@.II%:
&F&&%*-
(/'('/24
/(/'(/
///'=&
@&@&@@%II
*-#-#-""""""""
--#-#--"-"""""""""""""""""/"
&@&FII
>----------"""""""
G>*>>>>-----"---
""""""""""""
&&@&@&&
*>*-*>>
---#--#--
""""--
&&@@&@&
,GG***>*-*-*
--#---"#"#"-""-"--
&@&@&@&@&&
3BD,G,G,***
--#--##--#------>
@&&@&@&@&@&
%%F3BH
G,GGGG*G>*
-----------
&&&@@&@&@&@&&@&
G,G,GG****>>>>
&@&@&@&@&@&@&@@&@%II
%:%:%:%BA
G,GG,GGG>***
@&@&@&@&@&&@&&
&&@&FII
,G,G,,,,,,,
@&@&@&@&@&@&@&@&@&&@&
,G,G,,
@&&@&@&@
7HHCCC
,,,C,,
@&@&@&
@&@&@&@&@&@&&&@@&@%II
CCCCC,CC,,,>-
@&&@&@
@&&@&&
@&@&&@@
CCCCCCCC,,,*#23@@@&F&@&@&@&&@&@&@&
CC,,,*
&@&&@&@&@&
@&@&@&FII
%@@F&F
@&@&@&
&&@&@&F&@&
&F@@&F@
&&@&@@
&&&&@&&@&&@
&@&F@&
@&&@&F
@F&@&&@
@F&&@F&@&%II
@F&F&&
&F@&&@
@&@&FII
%9%:%::
@&@&&&&&
&F&&@&@&
&F@F@&&F
@&@&@&&@@%II
%9%::::F%
&F&F@&F@
F&@F&@&&@&
EE9939
&F&@&@
@&%II%EE
%:F%%%
&F&@&&
@F&@F&@&@&
F:F%FFF
F@F&&F
&&F&@&FIIIEE999E99999%%%%%%
&@F&&@
IIIIIII
24651957643246159489756421\=>a
u3<A7J
DDEB^]_Y^S]UPP
RdWTjgjjohhkesc`fvhg{}|~}~<qp`qvrssu
):(%,<-*&%&!%&$$699?*8?<2?227003
KxLOI_OLBvLCGC@BYZXU\\]ZVUWQuVT4fiiojholbobbg``c}{{x~~p
sutvuvty
**$+/)(*!" -$$%">=?9=><<>1172074fCHMC\
c/`&"e=w8~re
A)GAG4k?_YX)Mc
Nk,|!aagr
)\/SU mb
+:$$',
258(3N+JM#k)
y{>XpfBl
cG<<iL^W
3bcYgE
sF.L!C
c.Il;.O
ab8@g]
T^#\#]
Lbl96wXf\-Y
7r_m5E1A+V@MVB4
$RhE~-
<\K},<7Tj}6
ky&r1rz
-cg*?*
}7XnibDQ*n
r7Wz m1pLB!AAK_d#9^T
m-KMM~
Vf`RJ&?;E7u
I!:`p'_7
=,9%|ZC3
I$|kZ:
)*(gl[o`
`(|oWsO
7g:'}-
pP61/GK)
rg[iHE
Tve*iU
~&Uc+!lp
M;rT~]@
qb`!4e9
zqgY]u
nluh:4iw
<X,sGG
VwemGz
!^o/7K
_s:{q1
YKAYa0U;tX\
'*s;<@
9<wR,5
gH$4Ykv
\r(D/Q
8}+^tc
dwfrR'_pg-
-kMUMj
@![%]r<vv{y~K8:?r
- mIN $.u
e3~(rh
C*"D)
<3O>^V4B
tv/?9Mm:?EE@
5;#d(L3(+Rw
.bRgAmY8T%8{_Z`
P[\_mDB
:@u0`|]
/x1{ve#k
a.%=|0t
x<<M(&
DP_bWR7=[_jg
BPt;MOgiJ|
WkyZ5d
d:>mSl
'h^nTlr
h y=#'
:48-S1?? h7,
#WT,EMq
LlF",V
/IPbgv*O
{t4q5
RfNPOLUY//Z}^P$6M"yadC}
'~q?-v
!es%p>
N".B:*
j.29Yp
T>9b?d
;f7r)\
y`tq~j~
Mxmc0ZsMP[[
!_V~&N
=:5`9*
u>0f/c%
u`nBnu;<?D6!&
R Ni[cO,n
!Fk'1(
,q.a%l2;q#v`rM
>|PMX==M
q$YVgw
y35zx>
adFLbz/X*@"Eqx)~?`}"|Y
jzskaB\Z#8Q[*
XOjraA
DH/c8N:<z
wrh?:=-CU
kT xiD
3=I7!?
M-bIC=
] ]4(4S
Q~"5xD
*uKem_,(@xLZ
#m+0zb5n
-lY@!KN
*Fjz\7UDzv
Y/OR.PWZfq`|4
Dl|,S0
_!2-?0
)PzuLV#
p|wR$_TK7
nfxN KA
|i3G>+ x
apDWhpzjCUw
nynxuG
L]"YRf;
`B*4I;f
A?8'=h
v%AeAD4?~..agA(JDoIJ
RW*~Us'LhE
vQ5n&&"x
'3\wop
ac.l4H
e#]uTp
P]9ejTP1W&
!vir}TH
)i2re3?
Su?6CTBKWc_M
b1<fhV7
mMhqo\l)<#H
~FO_H=(>a@Sn0Ox`
Lcr^[bD<~`?\
fRWw'Q
Z<78~Hr
X$`GAF&
LmIKwc
xptP|I
E5ul?!~G:~8R*
r=bxKs
wIanqQ$
L6An0-I,
dg$i? )$.k|
ZK3HG2BG
khkf_
zb)t;5
hbp@U;g(
Wx0Io.W(DY]
57i8SC
m!h#awrx@
])\Fg$`IA|x>o5)w)^
/sqUJSHzW
\Ei)wm
SG#t{.|
)N)_5h
1KB_Q; L
4{{+/p?A.w
(};pI&h~
\#La68~E
'P>i,|
ymKPIk+
voU;<0
x?#??h
AQ;f^`enL
ZQbRds'1
;8$<3/p#`u6
24(O{;[#
sxH{.!
Kra}mr.?^Y
U~W]7
_^8ima8o:
=&9%RFMK
2iK]xb&
mm|03{Oary>6]g}A
[c=/Uxomm
Z" 1[9
fo&'89dEj
$euychj0_#V
<$=9=]^
N}b+X$`ao
@=8.zj
#4/=qD:
vQT2=d~0
ELUmoxzwUZ_0zl%
F9^n0r
gPa/wC
V^"7G<
~"o7rUI)
^B: $way?>Rk-=
gOh]+G
JJ@M!\W
ujeVY'5X|?6
y:A#B:oBn]=8S
JsY/Cw8os
M706[Z
[Jt"/d
V&%{.w@/
s;>zaM'$
`MyH["
a?X!MO|~68y|d^P
{3(Ftz
wYf;Ox
E9JAkLBGT~m
JQ)@p,ZH
9bXB9J
9TEh^Y
}1b(z4zWy'.l
j'DEZl
wyJqDo
JdFH@dc
K28q.#mW
"kKPz=*u)Q
\vZW/3R
$}"ae_
]:)+j>
F6<kULOOy!f
oOK8/+q
xQ.4)<{x*
uTc25J
/E*ZEBP
w'`*k\$gY
ug97?!T(xJG|
%W%/DiD*
i;V =8?
Pc7jzJ-{>m
v:xF5}
My#Gm<%Zis,
gYD=DJNd
'S79&Gp&L.>x
>tuho;
|$OgU#P[T%
jC!;eK
gzd)5_e]
TG*(ijxz
]P31jF}
f-.T8:;Ae0
|ThhfrJwhO"`_
XyY{tD
%gz\pI
bST[l(S
l6=_%?
MWO_RC}lLo2
R~[cDplz
PryV|%tx$
NMOIMNLLNAAGB@GDZWZZ_XX[USSPVVXWkmlnmnla``afbaceyzxxr}}{vtspv{vv
&))/*(/,"/""' #=;;8>>0?3546564924651957643246159489756421
L!This program cannot be run in DOS mode.
?M{#{#{#`
y#r~#{"E#`
z#Rich{#
`.rdata
@.data
.Wgd"t
3:opN rml
2ce}@sHcu
niPxh@2r
]+u]UuMR
FBIuZu;us!Z
GFu;uu_+
zW}8kc]{?/
_*1dmdks
&t(h|thd
lB3-+H
(n=_dh
+k!exxdl!
94)!,Ef=N(
f&II<egQ`
[qU$`p
)o?l
B'-E_Zk/y
-!Ym8=b}fT|I
$(ndf(
Sg-z2`
X.UOon-1
HkY_kD
!Yk(1-N?
=Cchr
h$T_t/gdlkk
tg %.,
MCb(h|*
04f Te,.U
,\( qk
hhopd-
&uP%(W8!h
+Hj$WC.K|h *
4M%5t/@
i-h*8c|
zdiv2^
]-y-j\}p
0miu $a6h8
P#3j-8
Ngh(d|Hd
$|e|H1
h#edo`7.
l]$(9?$
c5v[5`
->l/C)
!Ub{x_4
!7$px=kd
dxF")1
+)jO-x
lU#dxZ(.
.hjb-eC7mH@~%$$yhe
j+su<$iqx$g
odhfQS!tcy
f!Z(Ki*)
q/ v34T``
? Fq=:Nf 3Ed3B:)k,fN#]
ddMfh%hv+5egL16d
*+l%*7TC31
P/:lL4bhc
flo>l#<%.
`;MB0+$<#hMdr$`ov{
,$cte.@h-kQlhOhae}d,$w
hdFH$v.PlT$kt\n
@tm-N)/qNhb
n5.+|!
x `T=ep
!FmPa<
(hp!lE*@
aex|0
HE<Eem
FFFF=A@
@;ss;s
FGIu=A@
@P5<A@
03eg2V
@0"iu @
R%Rd@m0C
hpN'SdPu
u LAS^UP
S0/x'e
<l>eWo
ip@bR'"t
<SQUFE
j4h<@@
BBBBR5
BBBBRV
GV+=A@
QRRhA@
|rs.d$
sud@jwq
|s}L<p
uveLHg
E;Es%N
"KW"EE38=
Vcrn\PHcoo
$rDr";
uenrpp|
nVPntWI
P@k " nle
fd%07f
.`%7c-g\
$(;T,.d
z @8>dg7
Aif[b%
Qf#u0~1
qrglL#
#rhiW (EsTr
y()#jB
Au$#uD.,cs
s\hVPl
static
consolas
button
info.ini
myform
LoadCursorA
LoadIconA
DestroyWindow
SendMessageA
MessageBoxA
DefWindowProcA
RegisterClassExA
CreateWindowExA
MoveWindow
TranslateMessage
BeginPaint
DispatchMessageA
EndPaint
GetMessageA
PostQuitMessage
ShowWindow
UpdateWindow
user32.dll
GetSystemTimeAsFileTime
GetCurrentProcess
GetCurrentProcessId
GetTickCount
lstrlenA
lstrcmpA
GetCurrentDirectoryA
GetCommandLineA
GetModuleHandleA
GetLastError
CreateFileA
kernel32.dll
CreateCompatibleDC
CreateCompatibleBitmap
DeleteObject
gdi32.dll
j4'1_v_&
ol#uucxl@v
@BapR$#!upr'
d\e]l6I
{{{{l6I
>:ywl6I
>:xvl6I
KIxvl6I
rp~l6I
xxxyyy
---------F:--SH------------*
. . . . . . . . F:1". F:dX. . ,
- . . . . . . . ,
. 0!0!0!0!0!0!0!0!~t0!dX1"0!0!dX0!0!0!0!0!0!0!. ~?U
0!1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"0!
2#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#2#~CX
3#3#3#3#3#3#3#3#3#3#3#I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;4$Na
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
L!This program cannot be run in DOS mode.
`.rdata
@.data
czuGVVo
,)Q6rj
~VafZC
m7=tYC
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR'?<gN3c nUp}
4cJ;XT
jJ42jy
5*f)@l
k^X}*dZ
o T|RG
]9-1xM$'K
~RtZIh>.
'>m!>q
YaX5v+
%hY)wd
z8HUhHb4F
I,9#HB
<8lCr{
9to'$:G
[-f).X
,6q1mN
~gha}I6j
0%K)WV(2
X8 [O,
;uc]]t
o T|RG
]9-1xM$'K
~RtZIh>.
'>m!>q
YaX5v+
%hY)wd
z8HUhHb4F
I,9#HB
<8lCr{
9to'$:G
[-f).X
,6q1mN
~gha}I6j
0%K)WV(2
X8 [O,
;uc]]t
&nxmRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRdddddddd
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RrtylFve
nmeViaOfJle
Ge8ro'dd
tu%Alc
adbryE
etduHale
Crtele
SFipPomtev
Sitiila
lo7Ha*le
rtlPte
pogrL cLno1beun
n aS Hde+
@ !s-"s-"s+s
"s+s*s+s*stBNs`*sdB^s*sm*s7"sVbs*+sPs*s
AEdhuRgWh(
m>H.h9f
A Xt:$
0rPpFW *P
nMWEneje;Y$
L$W3zd=S`jW(
[r_^Uy
KNqVPWT
;I;{ES
P,W&vV,
@t&#tA
_n_[o^]l
;W96y%j
vj)\"\[
!TEs_._3-tVu
Dw_n_3,t
,tZUt$]Ut$]h
4;WM~j
u;hl`Pj
4B_^3])tOu
Z,VWft5
]Yd)t'=
Pc^&-YYN
3]fUSWnj
-uTh lh
GSSG@7j
j>Q S_[eUQS
J"Ab7{
^[kU+$
G]bz-MQI
PLGRPpi
WGuu]&P]
]S8IWSR]xj
fxGY(PZ
EPS]z2FE^[cU"
mUf:QQ#
#AmNx]uvuYGu
# fu%Wh$xjQ
pZPpu%NL
U*#AExPV
Em#A-E_x-PVE
NsWp:|ubED
aC}h}Ij
aCmDw]ShEzWh
-}hDj##\t
^o@S7B
~aCCwSh;Gh
|hjKju#,
%R_^&eUFQSP
A- [kU
N|W]PpE
aCzh}Ij
%aC]AsvmSh7)4Gh
Wuz!u$&Ey
Ut$%jSD,u+Ut$%@
W()ZOP3{Sj
]M"NP8W
~VhMzC
agt"m}
hEgE}3?
{UVUzn
{$A-xq
E$AEtPn>
VC=,Vz?W
q^]FsYP
AmVt VP8W
8V^Y3(t$$5S
jV3|Vj
{Vhm7?
SV>VVD
$tUEE]i
o)pPSpu
VHlPXPe
Wuuz# ft>ruMXu
sE}vV@3uUX
IugEw[^qJ|Sy
mfueu#
.eftqxFGfv
!|mQ/u
pd6V^EEU
{<j&EuE3+MMV
jQuqEz!c
A-t.CC
XPtr^-
?ED'K|
&m2E=G
l""EuG
-HV^IE
lP^4Sj
kuL8Y%
tz[e}j
VhPxpWW
9uur stzy
^^FeS_
=VCbV(^
-3w"5EC
@%D$)E
A]D$aH
8@Pi$<L$a
qHPi$DM
mVXh`h
tZhefWE}$A-
=mV8^QLhhg
PC$i(t
hjWp$A
1Vh0"`$D
t:hx/Wu'$A
1VhhhW
P^_D$
@.Wu6$A-Nh
qh%{j$,
ICj-tA
j*X5(k
#\$#D$Eju3j
w^[&B]qU-\_
_VVGVj
38U0UuVu
u#EFj=Cj#5
OuUVkP
X%E?eP0b
3Vk=1xC
JVCmT}QS>r-j
6Vz)SHPRu
[V0=_C
xtY_z5asC
A-#ETtuP
`;q0(~
C*VYYt=vC
WL6_CBf
DTuSV EWP
QPQ-jW}q;fj
V5VCmAVY)\C
A- =Sj
j<Wj%V
0~VC-u
uVC]t`$
EF%A-.`-P.T
u]%8:*0
IVCX5j
fVC]#R]9E"b
"^mVPR
]+(~WC-tq
t<SZh`
m REVu
3me*Mu!/V
Wt$ zUYY&G^
eeuiUu
3e)Mu U
Yas$;UC
Ot$OYY6@^9
2e*MVPuP
Yas$UC
zOYY&A^
gjl5i
`._C]v
T&XcZEP}}txQ
A_Cr66
NPj^Qu
pTPj,QuP
E\E\Wj
qEVEuVuG
|<U&"y\EU3
A~t"zG
<XEltX
1=t<otL
{|tD}t@
? Gu GtVGW
6YY Lt4
~F$*u?Fu
aEP5PE
UY{XBoC
LmYYt;Pf
.uNrJYg[
b$,b$d
)D$MFm
Kt$(D$
A]&;{=WS
RJ5(Rn
EqEuWj
6bYE@5
{iQjSMM
hQJSM\M
,qF;pr
VW>-SSWSj
SHiP7E
5}LS F
`:Pj !M
SEo2^r
$>Ynv*`V
A-hvj"'
Qh=a.Ghl
46Y^uo5/
.CFYNWC3@m
Y6YD|8F;mYC]
)0hPC--C6$v
ffP.s,
`?PhU?
mA<X77w
;#g3O^i
/NC`1q
s$l6;e
6vh{5})
]E@\-Qanr
S?_]YY=.) PC
sRSNCcE&TPZP11P
(/c2w
o9r3 :
p2SkTW.
''c]JOC,
@=9KPC
U&A-C[K
EmBJmP s3
MY'ubo
\PTE%u4^
S5gRi.
MP5M@cP
+jVV(j
!M':@&Q](u!
oG;`zu
G.b j(E]u+uH
X<1:`R
E"6)})t
z)YEyE
.z)u}D
cmYpDC&
U_^cQm8
h7q)h4*t$
FWAYAX
<z_Cm,
]c{jW90
EHqHt"
^&puMz_C]+
+0MicM
nMU"3W
^VUvZSVW
VFWW<3u
DENgtFh0nj
(P(PHN.j
fM*E_,
NWu_fUA
E6(A>#E=%A
jTb]a!}F%jo(
`PpBP`JP`V)O1(m>R
j)T"p]5)}FX5j(
j'E(E(E
GNVySRX
N`?P`GP`[
jukGfXjU(\zB
j$DzWP(
GPV^*L[
8V&XL@
WUX`LUj
W4LTzUjd
!XZU0z)2$L`zU
]hU)2KpUU
EMEe}M4W5
m;h4Vr
!8Vr5*
WEEqEiE}nrzW
mfk1jc&)
\j}cME
8P(P(uU.r
ftE]j`.)
N0BP JP >Y91U-mec
]hsSj B)\
DEZYnJ
5'AE}d
=fD;3C5V
VYz@WkEV3
f&Sth9UF
YUVeQQ
JqSh3sGhh
mA;qYU-1SE+
E'A]_c=-Pe
0%tB~OYqmu
ue@3DEktbD
5))Amek<]MTxIo
Thewh0Od
udl?^n
SVvG8ER
ECE7E7E7E8
ABd{GPv
)A]cw;]]
Oh@(pFVP
-|p[}".kf&E+
E=EhPh*lGPV#
jTV(*\ZGP0z
,qEeGp
zubNG)Gu[u
Gu[uG_[
{WE'[%z
NhOEi)A
3`ME3NEu
FY3de"MM
P.aE!F.]dpc
0~P bP
`nu~h1@KPS
@I@@@@
@I@@@@@@
mscoree.dll
A(null)
KERNEL32.DLL
((((( H
h(((( H
H
eaHAREPMKJ
e@IMJMWPVEPKV
xSMJ@KSWxW]WPAI
xW]WTVATx
xsMJ@KSWxw]WPAI
xW]WTVAT
gv}tpfewa
xsMJ@KSWxw]WPAI
xW]WTVATxW]WTVAT
eaHAREPMKJ
e@IMJMWPVEPKV
xSMJ@KSWxW]WPAI
xW]WTVATx
xsMJ@KSWxw]WPAI
xW]WTVAT
gv}tpfewa
xsMJ@KSWxw]WPAI
xW]WTVATxW]WTVAT
Progman
Ctrl+N
(&O)...
Ctrl+O
Ctrl+S
(&A)...
(&P)...
Ctrl+P
(&R)...
Ctrl+Z
Ctrl+X
Ctrl+C
Ctrl+V
program51(&A)...
program51
program51 1.0
(C) 2004
S_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
program51 Microsoft
FileVersion
1, 0, 0, 1
InternalName
program51
LegalCopyright
(C) 2004
LegalTrademarks
OriginalFilename
program51.EXE
ProductName
program51
ProductVersion
1, 0, 0, 1
VarFileInfo
Translation
6program51
Progra
Program51.Document
Progra Document
program51
@*\AD:\Maz-milocevic4\FlashGames.vbp
BouncingBalls
runPrefs
gravityStrength
OrKqNggrlDmJt
numOfBarsToDraw
restart_Interval
Interval
Enabled
Height
CcEjTODY
wvjjJSfH
12465798495164234675915642
NIJMxqxcCo
7945465231246795462134
ghrOvZoU
ryFVxwM
uSibKsv
EGPniL
HqDddEMZ
NsFEUZb
LPpPbUnkGd
TqMlqnyBQm
jvJrIuyZ
mKoSQnHypCM
ixEGPniLN
AVQgDl
Preview
0Park Arena, Komaki, Aichi, Japan, 12. vacant WBO
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
A kip is a non-SI unit of force. It equals 1000 pounds-force, used primarily by American architects and engineers to measure engineering loads. Although .
CompanyName
flash
ame Vermont is a state in the New England region of the northeastern United States. Vermont is the 6th smallest in area and the 2nd least populous of the 50 United ...
FileDescription
The curriculum of the ABT Jacqueline Kennedy Onassis (JKO) School is the American Ballet Theatre National Training Curriculum, which combines scientific ...
LegalTrademarks
Vermont is a state in the New England region of the northeastern United States. Vermont is the 6th smallest in area and the 2nd least populous of the 50 United ...
ProductName
Dealahoya
FileVersion
2.03.1211
ProductVersion
2.03.1211
InternalName
OlympicSt
OriginalFilename
OlympicSt.exe
C:\Users\Entebbe Office\AppData\Local\Temp\Temp1_TAX_julie.kisakye.zip\TAX_09232013.exe
C:\_yY6ycN3.exe
C:\rROxbuXq.exe
C:\v0EyvL97.exe
C:\PQGvQrHQ.exe
C:\0HlcmOli.exe
C:\rR8MKeIg.exe
C:\dcplmWB7.exe
C:\j1bvMQM1.exe
C:\niFb1y5R.exe
C:\edJF7ehQ.exe
C:\fUdjolCv.exe
C:\PI1iW3e0.exe
C:\vcgHNubW.exe
C:\lADi8VEE.exe
C:\rihmBqej.exe
C:\H9mV2urY.exe
C:\7ItGfDDT.exe
C:\BQQ3rQ1S.exe
C:\SLl8P67g.exe
C:\zmL2KTPR.exe
C:\NJpWN0mg.exe
C:\bKilDCQD.exe
C:\7xej7vLT.exe
C:\cE5DtyP5.exe
C:\ojFI4daF.exe
C:\C_jTCLaA.exe
C:\d1H4G75Q.exe
C:\mujSSDqg.exe
C:\9UALbzVC.exe
C:\1v25fy_W.exe
C:\eGBsgm3D.exe
C:\YEQPydAF.exe
C:\rP92rFWB.exe
C:\azQEKKXO.exe
C:\k3yZB7KL.exe
C:\6gd6R3Tv.exe
C:\R2MdHFqk.exe
C:\YlBKLZqB.exe
C:\68eSVpqr.exe
C:\awQr_o7D.exe
C:\y3oldJqg.exe
C:\oasN64L1.exe
C:\1x3RNiWk.exe
C:\yM4IVL_d.exe
C:\4ung5PBI.exe
C:\Kibtwozk.exe
C:\QDxMcRw7.exe
C:\VELtagPa.exe
C:\gWcGemcY.exe
C:\nipBwJdr.exe
C:\feFgTjyU.exe
C:\OFZi7lsZ.exe
C:\SaQxdj10.exe
C:\znEuixNe.exe
C:\LXZcF9tL.exe
C:\d9lQoElY.exe
C:\_qXP3Z60.exe
C:\CwcTJ9Q9.exe
C:\xsPVJZ8b.exe
C:\2YGAEj3t.exe
C:\Am6eYmvy.exe
C:\xkHVe4fP.exe
C:\meoXkfjS.exe
C:\3QrIXjBP.exe
C:\5cFEpf4E.exe
C:\B4gPrMoQ.exe
C:\d1jxkidK.exe
C:\wdgRBlfR.exe
C:\vG6OUrcr.exe
C:\obF0IbIa.exe
C:\voaebsSm.exe
C:\JBrgjqDH.exe
C:\rXUSQxpK.exe
C:\79YM0eza.exe
C:\HopqIwxx.exe
C:\EKODWZf2.exe
C:\5tDHzTZE.exe
C:\Df2U3jic.exe
C:\TEinX4Qr.exe
C:\l4rIVuMN.exe
C:\hWvsnAx5.exe
C:\ubgm3pY4.exe
C:\XajdKKoa.exe
C:\Th09YT1e.exe
C:\andN1RKD.exe
C:\zQXeCsyY.exe
C:\2lClBM7V.exe
C:\j7egf6A4.exe
C:\hD8BLyUD.exe
C:\876AZjK4.exe
C:\7tXDeEt7.exe
C:\4XsWfW8b.exe
C:\cNLLd1MU.exe
C:\2YuNtyo_.exe
C:\1LM_qUWX.exe
C:\fN91AsVx.exe
C:\5VOMPvtK.exe
C:\EvKnMvdr.exe
C:\QUUKYGYt.exe
C:\b9qi_7DF.exe
C:\7WdhASQP.exe
C:\W5fGDcAP.exe
C:\OO3hTTwA.exe
C:\CCX0QO_n.exe
C:\dMcUkPG1.exe
C:\uq0R4mZo.exe
C:\NT8Jn1za.exe
C:\RTkjhSux.exe
C:\wLjXj3Lk.exe
C:\_x7E9fuU.exe
C:\AVzpze5b.exe
C:\FjfTHlLe.exe
C:\8IIDY9c8.exe
C:\MME2Qmsi.exe
C:\c7sOOett.exe
C:\WoZFh_rt.exe
C:\piTicmhr.exe
C:\gRFwkUU0.exe
C:\0KblRuHM.exe
C:\RwbLbOcn.exe
C:\PUHQiKY1.exe
C:\Cu0Fxd4o.exe
C:\U10XFAgS.exe
C:\f2P7Ii7L.exe
C:\77aB1VFC.exe
C:\yw0NAR1E.exe
C:\iJ65IW1i.exe
C:\_bGTNJHl.exe
C:\aK42OA1S.exe
C:\zSnVp89r.exe
C:\gVWnZHey.exe
C:\bKb0aWba.exe
C:\AzSQiTDv.exe
C:\I5HjIf8C.exe
C:\eXxEE0Gs.exe
C:\Sd0ZFwyf.exe
C:\9UW2Auu4.exe
C:\TITPf6pk.exe
C:\D6D5NfCm.exe
C:\jfAu6e4i.exe
C:\f8nz6foC.exe
C:\7SSOR5JR.exe
C:\7UwNRO5y.exe
C:\RmLSm3Mx.exe
C:\jpziCfbe.exe
C:\ymhqdKb2.exe
C:\qLEcrNTB.exe
C:\FvzIJtqt.exe
C:\yqA8xFnO.exe
C:\wHmZ94nI.exe
C:\QRsb2KH8.exe
C:\pvn1L4CT.exe
C:\I9bHFQ7p.exe
C:\s2HBoBIR.exe
C:\IszgKMiq.exe
C:\5T49iBh_.exe
C:\rY7bERk5.exe
C:\YRiCBzHX.exe
C:\_gn2Dil1.exe
C:\71QPi1S3.exe
C:\mL2eehz7.exe
C:\Et_a3b7a.exe
C:\RtPqRc4g.exe
C:\CGqnD1zM.exe
C:\LT2J4n6h.exe
C:\pKNBNEQs.exe
C:\yNVtA2zo.exe
C:\BHeymaAc.exe
C:\HoFc3DBc.exe
C:\eZLi69UK.exe
C:\yY4gjJCa.exe
C:\Rr0jd0qH.exe
C:\6aPuvzeT.exe
C:\xGubTCsx.exe
C:\o4Unn4dD.exe
C:\vcfGXXPr.exe
C:\Tn5RTm7U.exe
C:\BDhDONk0.exe
C:\huiIF7eu.exe
C:\Z8T2Q2ZW.exe
C:\wjU7iHMs.exe
C:\K_iN5wqO.exe
C:\Yb8_eDGE.exe
C:\YaoIviz1.exe
C:\Clv01TeD.exe
C:\L2OJ5yaq.exe
C:\z2CvFWwX.exe
C:\H26zSoJP.exe
C:\M25HiCVd.exe
C:\LakmlO9U.exe
C:\6bdCFSJS.exe
C:\UTUhbu8a.exe
C:\EK1MQYBE.exe
C:\ksy1jhtG.exe
C:\LqFV7AQN.exe
C:\8yBzr_vr.exe
C:\aG_87bzi.exe
C:\P39UUzIX.exe
C:\hD8vt3PJ.exe
C:\tmgewPOX.exe
C:\p3Am30zC.exe
C:\lQJeL90M.exe
C:\AD3_E23S.exe
C:\C6M9aLWG.exe
C:\8syiM9y2.exe
C:\mw3Kk2wG.exe
C:\PwWtT_YG.exe
C:\Mfna7Rv3.exe
C:\GvNfhKEf.exe
C:\Uwj0kfyQ.exe
C:\TMHqSNZt.exe
C:\oVGFb4wy.exe
C:\gOb37U2d.exe
C:\WdfW48bp.exe
C:\Qf6QAV_i.exe
C:\PUvxlqbK.exe
C:\zCUWRe9D.exe
C:\0jQCQ_D6.exe
C:\khSTOsvw.exe
C:\ryy4qXyk.exe
C:\2WaUe8hq.exe
C:\U7r7vQEa.exe
C:\2JjuGazb.exe
C:\avZxoOsT.exe
C:\iPmASiKA.exe
C:\Ti2BNhvj.exe
C:\TK9gmpAM.exe
C:\iJTEFBYv.exe
C:\lPTCmLIU.exe
C:\w8r_5Sv7.exe
C:\gMWWRL4q.exe
C:\WDiBDrnL.exe
C:\oMLcHOPt.exe
C:\4SX7zm4J.exe
C:\4NShPUd8.exe
C:\Y9r_WTEh.exe
C:\G_1w3Xqs.exe
C:\jw8e6zXm.exe
C:\GggWxMpw.exe
C:\V7u2qOHI.exe
C:\hCZhyfTl.exe
C:\HFc2ZvSO.exe
C:\BsTd7HfJ.exe
C:\uA3d3A6E.exe
C:\1gJewhfJ.exe
C:\TTEq47jB.exe
C:\shl1tSn0.exe
C:\gFNHfWud.exe
C:\BRnKD_H0.exe
C:\s9F_gJnW.exe
C:\INeEMKvv.exe
C:\02M7d9tb.exe
C:\J3WN2B0g.exe
C:\xARimw89.exe
C:\bdpvhFPW.exe
C:\bEzdV9aY.exe
C:\ebAMV9Yd.exe
C:\_TYuwofO.exe
C:\7ljrAjaI.exe
C:\iEiOaoIJ.exe
C:\Wi0aRpCJ.exe
C:\XDqtysPt.exe
C:\hyeF__9o.exe
C:\HDgfxiKG.exe
C:\o3bssvXD.exe
C:\19b6fqcC.exe
C:\e3NLEO8X.exe
C:\agbLGeh7.exe
C:\iEFqJZFq.exe
C:\SnwfcR4k.exe
C:\z0L_kbzh.exe
C:\YIyLXFml.exe
C:\VDgW86iY.exe
C:\eco5PEzC.exe
C:\aWWSiw6I.exe
C:\yVgHqHk7.exe
C:\DG5tDGPt.exe
C:\SDJrQSkM.exe
C:\mDhhtr87.exe
C:\TZjJdR3u.exe
C:\BxKEa_Pm.exe
C:\rYlxUoZx.exe
C:\4F5Mc8Zh.exe
C:\6iOLCcDX.exe
C:\CQazI_K2.exe
C:\EOjW7sOE.exe
C:\sRXCofuh.exe
C:\Nn4DZAiz.exe
C:\oLiyuDzu.exe
C:\hZNGlZYJ.exe
C:\zbyLNOZ3.exe
C:\Gb3YL7AE.exe
C:\RMr7ldRy.exe
C:\KnzlzorX.exe
C:\3rRSf_g1.exe
C:\96EsgrEO.exe
C:\vvp3ZMwT.exe
C:\JQF9xSbL.exe
C:\O2CxM2gi.exe
C:\T40NLQ5z.exe
C:\PYdJE7C5.exe
C:\XYrZDJwU.exe
C:\25jl9o5L.exe
C:\_49o6310.exe
C:\32HhsDlT.exe
C:\ZI4Fq_Qb.exe
C:\f1gWHdTx.exe
C:\eMKGZh0T.exe
C:\AKaFeqqd.exe
C:\wKYxW87r.exe
C:\0Y7cLZAQ.exe
C:\q7QznRmb.exe
C:\woNLjsox.exe
C:\YyEpHELe.exe
C:\54J7P0cG.exe
C:\LT_quvX8.exe
C:\HKC6RBIN.exe
C:\vX7pUGDk.exe
C:\FbBs6DNB.exe
C:\zyjgCCX_.exe
C:\zv5W6O8D.exe
C:\2FSQzr53.exe
C:\q9dHxiXK.exe
C:\gmc1Z3GM.exe
C:\PrVCmQ87.exe
C:\QGPDOrRm.exe
C:\yjOtuBxS.exe
C:\ETp8xfVg.exe
C:\PxXXGxZ5.exe
C:\0l6fo1wA.exe
C:\wJ1jQzo8.exe
C:\52H9qeW3.exe
C:\dc6EheZA.exe
C:\dAtohagZ.exe
C:\SfLOy15V.exe
C:\olKHasO1.exe
C:\VpLeovhE.exe
C:\WSMnqq9s.exe
C:\KiBHYvUE.exe
C:\QQ24RpaZ.exe
C:\_3ls4lMm.exe
C:\o9iL2kn5.exe
C:\BaQ9_CWi.exe
C:\7UQrLnxY.exe
C:\2eCMBfQs.exe
C:\z3JuM_vC.exe
C:\8hWr6qc7.exe
C:\A95ZPRdS.exe
C:\gG5iroxP.exe
C:\yZ4XYtUx.exe
C:\PEqJDMNZ.exe
C:\C6QAZCsp.exe
C:\6qOGo0ib.exe
C:\dCGH3fic.exe
C:\PKMy6HW1.exe
C:\44Lm8Omw.exe
C:\G8PkLZA9.exe
C:\IGjM3JHn.exe
C:\JwQLsYiC.exe
C:\zTR_PbEJ.exe
C:\WJwyOjQQ.exe
C:\cs6RNHrV.exe
C:\GGjJRQTn.exe
C:\Dw2R1Yu7.exe
C:\Tqs8Fird.exe
C:\qnbOtfua.exe
C:\btF_fXHM.exe
C:\h12zL47p.exe
C:\6rP2BjT3.exe
C:\dBRKG9jp.exe
C:\I02E57f4.exe
C:\FTzI79zs.exe
C:\IjtPN6AI.exe
C:\010n21Jl.exe
C:\I5QfUfZp.exe
C:\Uev8Hka_.exe
C:\mKw8oLuh.exe
C:\FWHQbOgd.exe
C:\SLInpz7d.exe
C:\ZX3ljXt4.exe
C:\3FFD1ZFZ.exe
C:\1y4Y6znM.exe
C:\D554huRv.exe
C:\fZyzT5qK.exe
C:\Cn3aKjmN.exe
C:\2cUUDFuG.exe
C:\RuEV8SF5.exe
C:\2PlZlcA9.exe
C:\Z6BMzGko.exe
C:\XhEIfnaQ.exe
C:\Y4YNLziO.exe
C:\sZxTPVsg.exe
C:\PC75OxyG.exe
C:\e2S64vqG.exe
C:\N5P7yXyB.exe
C:\GaPoVhtc.exe
C:\hPuHxdTa.exe
C:\aCUzVJHs.exe
C:\_vLyDHxS.exe
C:\aIs6nBV5.exe
C:\UoB3VaCW.exe
C:\C30DDsBC.exe
C:\zz81NEJA.exe
C:\cbGoLDT8.exe
C:\CkVGs3Q0.exe
C:\uxfNkvfR.exe
C:\rF0dhmGe.exe
C:\aRwTsg6j.exe
C:\qaOSXfTN.exe
C:\2NfV3f_9.exe
C:\S_53HvRc.exe
C:\FJhw4WTd.exe
C:\2Ar5Q3eI.exe
C:\C1V46q5X.exe
C:\Xd3C25rM.exe
C:\3lkzG0gF.exe
C:\Dhig7sSL.exe
C:\rgBqwmLQ.exe
C:\UHfVgYmM.exe
C:\0k4XsqBI.exe
C:\4Ap6CVyY.exe
C:\TOBtVKcd.exe
C:\hD64oYFD.exe
C:\ZXXY0K3P.exe
C:\iueYCMgq.exe
C:\jLL_7P1j.exe
C:\2bbcI1Fx.exe
C:\OncKjOdS.exe
C:\mODVvL3b.exe
C:\LxerUDRg.exe
C:\biGzUu_E.exe
C:\rCYAlqnX.exe
C:\Q20eiuiu.exe
C:\5cSoWUiN.exe
C:\npy3kZPX.exe
C:\Tr6RZKHZ.exe
C:\wSYYahry.exe
C:\71UQKW3z.exe
C:\YHh0k9WC.exe
C:\SU513sZX.exe
C:\tfXCXFIC.exe
C:\nVUY1kCw.exe
C:\I2MGjyNB.exe
C:\3D9CUWQe.exe
C:\dur7A7YR.exe
C:\EKuQDmpM.exe
C:\QFdkmHBZ.exe
C:\W9DJiUvS.exe
C:\si38_ADG.exe
C:\iFD3o0Gp.exe
C:\IIP49yG8.exe
C:\vGaZqbAw.exe
C:\68m_LHIV.exe
C:\xMXVBPLA.exe
C:\z7yV1oH0.exe
C:\WK3UFSSs.exe
C:\r7I8ntYy.exe
C:\b0u4lbcH.exe
C:\1fEW_AMt.exe
C:\CN5brSIZ.exe
C:\rkRC1GPL.exe
C:\POpt4SLT.exe
C:\FkcmEd4t.exe
C:\KPqQhR5d.exe
C:\VCawNLCv.exe
C:\nO4RfzZh.exe
C:\GFk90rM7.exe
C:\oiu7aYdo.exe
C:\Iacj7zI8.exe
C:\P1BhUIjN.exe
C:\xNuSHFaN.exe
C:\42ltHCQj.exe
C:\aSyoCeq3.exe
C:\8tcp7WlN.exe
C:\IK6TeyXJ.exe
C:\iLRQMejP.exe
C:\c3Wfr_1t.exe
C:\VKw2wuSV.exe
C:\1h12uzW_.exe
C:\pzj9OFpr.exe
C:\T7eLQS8G.exe
C:\KD8M6ZC1.exe
C:\K_UhYrH0.exe
C:\lsD0Ss8A.exe
C:\4pfnMTl3.exe
C:\EWfHUdkB.exe
C:\xkCAEPOk.exe
C:\ueQlxKbb.exe
C:\y8oQPu66.exe
C:\H199udRU.exe
C:\1OKOf8Jr.exe
C:\aXQeVt4H.exe
C:\wMepkyps.exe
C:\mOFL8QB8.exe
C:\6xhUAocl.exe
C:\mYYSu6rf.exe
C:\h6YeY59U.exe
C:\BGq8uqXi.exe
C:\i5pmL3a0.exe
C:\o4e3kS0H.exe
C:\8amd0EQ2.exe
C:\semL4tvA.exe
C:\NuZdCjJN.exe
C:\gaQX8Z_6.exe
C:\c4nHoB_a.exe
C:\mSdYuUqc.exe
C:\AJYTRqta.exe
C:\qAVYx0GL.exe
C:\LKyjjU9S.exe
C:\aG0s8r01.exe
C:\KpZg7V_6.exe
C:\efkzYzOq.exe
C:\J7wo6tMs.exe
C:\80YYnNLq.exe
C:\zunGfPvl.exe
C:\y_IhQATs.exe
C:\71mOz1bl.exe
C:\ka98LWzB.exe
C:\IiduJhZE.exe
C:\5paaX0A6.exe
C:\itLmh9Uj.exe
C:\FoLzO__X.exe
C:\bdyfjmx6.exe
C:\urKfuVfx.exe
C:\g2iDJ6sf.exe
C:\ALhH34oB.exe
C:\wDfGsFIM.exe
C:\SBSesRdC.exe
C:\fbkrB8QI.exe
C:\fiiwClnB.exe
C:\AoP2qJmA.exe
C:\7CUPcikV.exe
C:\Tgtwzl7e.exe
C:\hYpfRzwi.exe
C:\SkAG3QKj.exe
C:\y5qacKzH.exe
C:\fhvHfOIe.exe
C:\QmQzXYbi.exe
C:\LHmmjtrH.exe
C:\DHYlEpsZ.exe
C:\j7ket33L.exe
C:\yqQ8lwFT.exe
C:\08waL37O.exe
C:\Ps6jHcue.exe
C:\d0GRTkN9.exe
C:\P4pWbruD.exe
C:\T70DEzvd.exe
C:\9UuReLEv.exe
C:\9Zx5g4lM.exe
C:\HwpFVyDr.exe
C:\Ju2GA4FS.exe
C:\rFtJ58zz.exe
C:\_eOcNTNn.exe
C:\uy2FWZei.exe
C:\oPg0Qzpl.exe
C:\dKgSkfGP.exe
C:\BAnwfEB3.exe
C:\uxft05M1.exe
C:\MU3TTCG5.exe
C:\OtFC_dTW.exe
C:\CwY41V0e.exe
C:\2aiVZCVk.exe
C:\IgdVPMDX.exe
C:\xEZAUV9K.exe
C:\qQEMnJrw.exe
C:\jfYLnATN.exe
C:\svZetoWI.exe
C:\loKusJUz.exe
C:\YQleO2nG.exe
C:\gGxcGbK6.exe
C:\hbQ5jUik.exe
C:\lDt8734F.exe
C:\VqxuuBMo.exe
C:\zjmneK3g.exe
C:\ruMnOkRB.exe
C:\68OBfBjc.exe
C:\iWp69dRx.exe
C:\5yLoO4B3.exe
C:\_laM2bpj.exe
C:\193R9AVo.exe
C:\kIG3eE0B.exe
C:\EolkrNly.exe
C:\hWgfy7AG.exe
C:\UMn0s3Af.exe
C:\TGmOJ7q9.exe
C:\nORFnYE0.exe
C:\n__szzyy.exe
C:\LxVAdVky.exe
C:\kqVOjCND.exe
C:\x7jHI62N.exe
C:\rZvRUm_7.exe
C:\TKdvtmO6.exe
C:\j7uwuGrW.exe
C:\o2h7PFer.exe
C:\ZoamfBuc.exe
C:\f8IfGJ9I.exe
C:\xL6WbO0j.exe
C:\_71ucHue.exe
C:\kd2IzhOM.exe
C:\MCAKx4pI.exe
C:\bKjXy_2k.exe
C:\S2G6xuPA.exe
C:\E31w_8Lm.exe
C:\83JU1JMx.exe
C:\46jQ1Wu3.exe
C:\Efbdio08.exe
C:\5lxRy0Ix.exe
C:\5bcdJRlJ.exe
C:\m7hqIB0H.exe
C:\XyznkbfS.exe
C:\IV7Xkofz.exe
C:\I9EZQw_C.exe
C:\V3BmwDqH.exe
C:\LmXgb11J.exe
C:\CyNngYZQ.exe
C:\k0cDW5eo.exe
C:\EpgJ4cnz.exe
C:\bjiEVRKp.exe
C:\KQdG5uHG.exe
C:\dJn9kkZE.exe
C:\ouECaV7_.exe
C:\4CjefQnS.exe
C:\yB57STMH.exe
C:\45LPNd0f.exe
C:\hInwUegB.exe
C:\YxxuyzNJ.exe
C:\FbEzqmnF.exe
C:\6NiwaB0r.exe
C:\Ila9Nyad.exe
C:\yRigEFJj.exe
C:\Kngsj5uS.exe
C:\ozzrw3q8.exe
C:\dSvUyzkp.exe
C:\1J8JcYFl.exe
C:\68UGEqY1.exe
C:\uKKiSV49.exe
C:\TsD9RXUB.exe
C:\e7QODcSB.exe
C:\V2BtZXS0.exe
C:\E8tWWpIL.exe
C:\jYc_c6Zf.exe
C:\Bihmyp27.exe
C:\kiu0VpgB.exe
C:\P9ohbPcJ.exe
C:\nIwAtD6_.exe
C:\YjRABZnq.exe
C:\mGsRVJtQ.exe
C:\b1LlLjuu.exe
C:\Tq2OKgC_.exe
C:\dSUARekD.exe
C:\vA4tyw33.exe
C:\1QGk1G0D.exe
C:\OVwn8ZE8.exe
C:\FaGUXONZ.exe
C:\pLmwScn7.exe
C:\5Ht6QMFr.exe
C:\_NCQCrhe.exe
C:\QCekibMP.exe
C:\xgoNbmhf.exe
C:\qga7Pof1.exe
C:\qStJLXZq.exe
C:\N6zaA6Tt.exe
C:\i8qL6zR_.exe
C:\QYi48gCX.exe
C:\zD1SRVQF.exe
C:\R02zQRJc.exe
C:\V07ENpdd.exe
C:\Pwp3gm12.exe
C:\SHqu3RRU.exe
C:\Rl1AUfiL.exe
C:\6rmblxYx.exe
C:\0h3IDkAN.exe
C:\jkTTj1nW.exe
C:\CoFnstJh.exe
C:\IHQDysa8.exe
C:\5VpnBRL7.exe
C:\yaDTQMxe.exe
C:\2add13Xz.exe
C:\c98tOk74.exe
C:\5fm0g5lb.exe
C:\4Qh8XOEP.exe
C:\anl005wp.exe
C:\YpocMCtk.exe
C:\WBgiq8fx.exe
C:\So8JxYg9.exe
C:\P7LHoI9j.exe
C:\rQzDqWrf.exe
C:\HfGiMl9T.exe
C:\kY7ivhl4.exe
C:\vnREnM6c.exe
C:\1MBb_xAP.exe
C:\GImF4PhH.exe
C:\T4k0LddQ.exe
C:\RcoRcpyc.exe
C:\FQSvVX_n.exe
C:\2o2zfxPf.exe
C:\a30b2n7L.exe
C:\QHBx1z4l.exe
C:\AMQ81PIr.exe
C:\NL09c6a9.exe
C:\vrFDLlh2.exe
C:\EtBQDrZX.exe
C:\N765IhUT.exe
C:\LCrGPnJB.exe
C:\VTJ7VgyK.exe
C:\EDjBsLN3.exe
C:\QhZzkFX4.exe
C:\oN5SJ9DK.exe
C:\UCDk8bPM.exe
C:\86uicheh.exe
C:\kmkzU2o9.exe
C:\2x9RQY4u.exe
C:\_LG961uz.exe
C:\wxru6JxP.exe
C:\iOxX8unB.exe
C:\BN0JOqtY.exe
C:\3lvA9U2x.exe
C:\kVhSzbd1.exe
C:\Lu6RozaL.exe
C:\OkalZVLX.exe
C:\9mIitnIR.exe
C:\xXYfwm9B.exe
C:\uT03TkEi.exe
C:\jrULUct9.exe
C:\6wb1uXST.exe
C:\GwZSh59C.exe
C:\nVaYy3LJ.exe
C:\AMUCk5gd.exe
C:\Cqkw6UhV.exe
C:\O5A5BlOj.exe
C:\EdUSVFLi.exe
C:\ERmfAeod.exe
C:\z3dXOeF1.exe
C:\sUgb7JVc.exe
C:\K4exyOCY.exe
C:\EJYrVAaa.exe
C:\YX8ej8w3.exe
C:\M4pgk3UP.exe
C:\4qFdeew_.exe
C:\4G3zYz6V.exe
C:\L8uIe5eW.exe
C:\z5vMI39K.exe
C:\2ySUa9H_.exe
C:\eaz9c1_w.exe
C:\RpKTq0xe.exe
C:\kGD6L8Ix.exe
C:\gXH4gOe_.exe
C:\APMu96QJ.exe
C:\wxsJVNtq.exe
C:\joaRJC8Y.exe
C:\bbp_bNt1.exe
C:\SD6Y4aWP.exe
C:\EPKclIW2.exe
C:\k0Hedeev.exe
C:\xD3GGWhN.exe
C:\DMs1Uw9S.exe
C:\He_bV8uO.exe
C:\a6P3BTnR.exe
C:\jVrmX58Z.exe
C:\SPlgF5BY.exe
C:\ihhsAW_B.exe
C:\6XOAbaYU.exe
C:\DdUjrgop.exe
C:\QvyY8mwD.exe
C:\wlow8aEu.exe
C:\ftBITMm7.exe
C:\afhaVc9h.exe
C:\gTt9QFFq.exe
C:\OYUXfBbW.exe
C:\fU3Y18Nm.exe
C:\SAlSw0w0.exe
C:\pSz1tmNv.exe
C:\YL2DCHmw.exe
C:\QrcTl7f0.exe
C:\C8vLmSJJ.exe
C:\o1CjxVc3.exe
C:\G_85ON0Z.exe
C:\Z2Sy_bf2.exe
C:\Z95qVUkE.exe
C:\3z3Q8ykj.exe
C:\P8Es7MO1.exe
C:\1vYbzrb3.exe
C:\hFf5KJor.exe
C:\Tc8BmlRk.exe
C:\M2ck_Wfn.exe
C:\J_MiOCKL.exe
C:\Ms09fR4y.exe
C:\lskA4Ns9.exe
C:\9Svb2ETL.exe
C:\Qc1DYbjI.exe
C:\wpY18LLp.exe
C:\HYC5_STO.exe
C:\fYEazsQf.exe
C:\XLn_xskt.exe
C:\YzEQCQfZ.exe
C:\42lQVbGV.exe
C:\GhkfQ6Pf.exe
C:\NFwnA9Nm.exe
C:\cQTHEI35.exe
C:\xbGmC9fU.exe
C:\663Jeo0t.exe
C:\2FFzzBwP.exe
C:\JGgAHJa6.exe
C:\7XdepLGL.exe
C:\SSVAgHmP.exe
C:\NnU7wrrF.exe
C:\rUoQz3Bc.exe
C:\dxVNk8uY.exe
C:\AtUlLie_.exe
C:\M3n5qbcn.exe
C:\DT_SxjZF.exe
C:\CM0wevY9.exe
C:\YVamqLVm.exe
C:\RFOplnKC.exe
C:\6MDI4pqL.exe
C:\v2V9P3mZ.exe
C:\SqHQEE0N.exe
C:\PeQWMdww.exe
C:\txpfApb2.exe
C:\lutIi8sS.exe
C:\5SsCW8LR.exe
C:\5OkLhRsj.exe
C:\59EznYny.exe
C:\fXau7rCe.exe
C:\1ZaellVN.exe
C:\ojAJbxi6.exe
C:\BYRH7k3Z.exe
C:\Omw0y1Yj.exe
C:\aKPdaG4U.exe
C:\Mso824nM.exe
C:\IACpvcf8.exe
C:\_7gz7cDu.exe
C:\BJILrwxo.exe
C:\xqeE0qO3.exe
C:\qeHO58F9.exe
C:\hWBR8uuR.exe
C:\VtmFkAz4.exe
C:\Cd_iVPd5.exe
C:\K0tuqLZS.exe
C:\KoTQeYxP.exe
C:\dA3Ed4u6.exe
C:\9b0hjDsk.exe
C:\OoVLCosN.exe
C:\Qlgh1Rzn.exe
C:\l5n9pk29.exe
C:\3Zcgqv3l.exe
C:\XldgF0I7.exe
C:\xYTPg_gs.exe
C:\zRVB2O30.exe
C:\zde4kKGn.exe
C:\SmfDw21w.exe
C:\MW5K5Mw_.exe
C:\DsqUroF9.exe
C:\m5DOoEsl.exe
C:\eoMs8dyS.exe
C:\soW2VVDc.exe

Process Tree


083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe, PID: 1856, Parent PID: 3028

default registry file network process services synchronisation iexplore office pdf

MediaCenter.exe, PID: 1260, Parent PID: 1856

default registry file network process services synchronisation iexplore office pdf

explorer.exe, PID: 1412, Parent PID: 1304

default registry file network process services synchronisation iexplore office pdf

cmd.exe, PID: 1472, Parent PID: 1856

default registry file network process services synchronisation iexplore office pdf

PING.EXE, PID: 1104, Parent PID: 1472

default registry file network process services synchronisation iexplore office pdf

TCP

Source Source Port Destination Destination Port
192.168.56.101 49168 13.248.169.48 www.polarroute.com 80
192.168.56.101 49173 13.248.169.48 www.polarroute.com 80
192.168.56.101 49176 13.248.169.48 www.polarroute.com 80

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 57665 114.114.114.114 53
192.168.56.101 51758 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 4df1108855288dc3_mediacenter.exe
Filepath C:\Users\Administrator\AppData\Local\Temp\MicroMedia\MediaCenter.exe
Size 368.0KB
Processes 1856 (083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a1f7b8b26966dc1e421b93f0df1f4dd7
SHA1 5eddeea99e6e56cc612f4221b342b46730029b8d
SHA256 4df1108855288dc32868f5db0c323759b76f72d8892febcef327c225286a35a4
CRC32 16E5D9B5
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 083fea731ebdc49c_083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe
Filepath C:\Users\Administrator\AppData\Local\Temp\083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33.exe
Size 368.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0a276cc3a80a0ce5ec7492117b05bc70
SHA1 4fbf1a93134737a77130d270fb909e8d653f40e9
SHA256 083fea731ebdc49c16414fa74364328c7584a9defb052bdd5160660bb2c49e33
CRC32 2354DF7A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.