!This program cannot be run in DOS mode.
Richb2K
`.rdata
@.data
@.reloc
PhorpiexRemover
StrStrIW
StrCmpNW
PathFileExistsW
SHLWAPI.dll
wcslen
wcscmp
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
__dllonexit
_onexit
HeapFree
HeapAlloc
GetProcessHeap
lstrcpyW
QueryDosDeviceW
GetDriveTypeW
GetLogicalDrives
DeleteFileW
SetFileAttributesW
ExitThread
CreateThread
CopyFileW
ExpandEnvironmentStringsW
GetModuleFileNameW
ExitProcess
GetLastError
CreateMutexA
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
wsprintfW
USER32.dll
RegCloseKey
RegDeleteValueW
RegEnumValueW
RegQueryInfoKeyW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
ADVAPI32.dll
c b
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0F0e0l0
1F1e1l1
2F2e2l2
3F3e3l3
4(565Y5c5
7*7H7Y7_7k7x7
7"8/8<8G8
9R9X9b9g9
;@;R;X;^;d;j;p;v;|;
jjjjjjj
jjjjjjj
jjjjjjj
jjjjjjj
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Service
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Client Server Runtime
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Host Process for Windows
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Desktop Window Mana
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
%s\%s\DriveMgr.exe
r%userprofile%
%ls\PhorpiexRemover.exe
%ls:Zone.Identifier
Software\Microsoft\Windows\CurrentVersion\Run\
Phorpiex Remover