Sample details: 32dfd1d9a50ddc3413cf35f9c644ad60 --

Hashes
MD5: 32dfd1d9a50ddc3413cf35f9c644ad60
SHA1: 99e51d8c42b057b93869a8e9e833fcae89bd3ba4
SHA256: edf129ac3f906425682b0255781034c45caa5ea31fe681ff26f0edbfef195b52
SSDEEP: 3072:ourI2gggGRBsTS7ZSBYfkVoFdRrqo0aRaA/HF673+UWHIfrvt84NEktObout:Y2gggGrTNkVsuaRaU6mHGlwboS
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Basic_v50v60 | YRP/Microsoft_Visual_Basic_v50 | YRP/Microsoft_Visual_Basic_v50_v60 | YRP/Microsoft_Visual_Basic_v50_additional | YRP/Microsoft_Visual_Basic_v50v60_additional | YRP/UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasModified_DOS_Message | YRP/HasRichSignature | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/ThreadControl__Context | YRP/SEH__vba | YRP/inject_thread | YRP/network_tcp_listen | YRP/network_dropper | YRP/network_tcp_socket | YRP/screenshot | YRP/keylogger | YRP/win_registry | YRP/win_private_profile | YRP/Str_Win32_Winsock2_Library | YRP/UPX | YRP/suspicious_packer_section |
Parent Files
08771157bc61f5a13ec9e2c318895749
Strings
		!This program Wannot be run in DOS mode.
`.data
}8!"###"!
<367FHFF741g
07HQUVXXVQOF:p
xNQX`b
cb`VOA}
*!5HVa
"6HU`b
"5FPV[
!%6FOZ
Timer1
Command1
vb6chs.dll
notepad
RunExeModel
PublicDIM
FileIO
m_Runas
C:\WINDOWS\system32\stdole2.tlb
Eb^\:O
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
Command1
IBindStatusCallback
D:\drivers\
\olelib.tlb
olelib
Timer1
wininet
DeleteUrlCacheEntryA
DownFile
DownloadFile
IBindStatusCallback_GetBindInfo
IBindStatusCallback_GetPriority
IBindStatusCallback_OnDataAvailable
IBindStatusCallback_OnLowResource
IBindStatusCallback_OnObjectAvailable
Fstdole
FIBindStatusCallback_OnProgress
IBindStatusCallback_OnStartBinding
IBindStatusCallback_OnStopBinding
kernel32
GetDiskFreeSpaceExA
SetProcessWorkingSetSize
GetCurrentProcess
OpenProcess
CloseHandle
oleacc
AccessibleObjectFromPoint
WindowFromAccessibleObject
WritePrivateProfileStringA
GetPrivateProfileStringA
user32
SetParent
MoveWindow
InvalidateRect
user32 
GetWindowRect
GetClientRect
GetTickCount
SendMessageA
SetWindowLongA
epldrive.dll
EplDriveDisk
DeleteFileA
mksparse.dll
mksparse
DiskVolume.dll
GetVolume
DeleteVolume
SetVolume
GetComputerNameA
oleaut32.dll
OleCreatePictureIndirect
shell32.dll
SHGetFileInfoA
GetShortPathNameA
GetWindowLongA
GetPublicProfileStringA
WaitForSingleObject
winmm.dll
timeGetTime
GetFileType
CreateFileA
GetFileSizeEx
CreateProcessA
CreatePipe
ntdll.dll
ZwUnmapViewOfSection
WriteProcessMemory
ReadProcessMemory
VirtualAllocEx
VirtualProtectEx
GetThreadContext
SetThreadContext
SuspendThread
ResumeThread
RtlMoveMemory
C:\WINDOWS\system32\msvbvm60.dll\3
pswBox
SourceFile
TargetFile
IsProccess
FixFile
VBA6.DLL
__vbaErrorOverflow
__vbaLateMemCall
__vbaStrI4
__vbaObjVar
__vbaObjSetAddref
__vbaVarCmpEq
__vbaVarOr
__vbaBoolVarNull
__vbaFpI4
__vbaEnd
__vbaInStrVar
__vbaVarTstEq
__vbaStrI2
__vbaVarAdd
__vbaVarTstNe
__vbaStrVarVal
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
__vbaVarDup
__vbaVarCat
__vbaFreeObj
__vbaNew2
__vbaStrCopy
__vbaStrCmp
__vbaFreeObjList
__vbaCastObj
__vbaObjSet
URLMON.DLL
URLDownloadToFileA
__vbaFreeStr
__vbaStrToUnicode
__vbaOnError
__vbaSetSystemError
__vbaStrToAnsi
__vbaFreeStrList
__vbaStrCat
__vbaStrMove
__vbaInStr
__vbaHresultCheckObj
__vbaRecDestruct
__vbaRecDestructAnsi
__vbaRecAnsiToUni
__vbaRecUniToAnsi
__vbaI2I4
__vbaFPInt
__vbaRefVarAry
__vbaUbound
__vbaVarIndexLoad
__vbaHresultCheck
__vbaLateMemSt
__vbaVarSub
__vbaLateMemCallLd
__vbaVarMove
__vbaVarForNext
__vbaI4Var
__vbaLenBstr
__vbaVarForInit
__vbaAryDestruct
__vbaPutOwner3
__vbaVar2Vec
__vbaAryMove
__vbaFpI2
__vbaPrintFile
__vbaFileOpen
__vbaFileClose
__vbaI2Var
__vbaLsetFixstr
__vbaFixstrConstruct
__vbaUI1I2
__vbaGenerateBoundsError
__vbaCyMulI2
__vbaI4Cy
__vbaAryUnlock
__vbaAryLock
__vbaVarMod
__vbaGetOwner3
__vbaRedim
__vbaAryConstruct2
__vbaPowerR8
__vbaErase
IBindStatusCallback
localfilename
grfBINDF
pbindinfo
grfBSCF
dwSize
pformatetc
pStgmed
reserved
ulProgress
ulProgressMax
ulStatusCode
szStatusText
dwReserved
hresult
szError
pswBox
SourceFileName
TargetFileName
}#jXh|F@
}#jPh|F@
}#jPh|F@
}#jXh|F@
}#jPh|F@
}#jXh|F@
}#jPh|F@
}#jXh|F@
}#jPh|F@
}#jXh|F@
}#jPh|F@
}#jXh|F@
Q<Rjgh
H4Qh(N@
}#j\hP@@
}#jdhP@@
B<Pjgh
j|h|F@
jdhP@@
j\hP@@
j8h\F@
QRh G@
Q4Rjgj
H8Qjhj
LPh`T@
LPh`T@
LRh`T@
LPh`T@
VPh`T@
MSVBVM60.DLL
URLMON.DLL
__vbaVarSub
__vbaStrI2
_CIcos
_adj_fptan
__vbaVarMove
__vbaHresultCheck
__vbaStrI4
__vbaAryMove
__vbaFreeVar
__vbaLenBstr
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaStrCat
__vbaLsetFixstr
__vbaRecDestruct
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaLateMemSt
EVENT_SINK2_Release
__vbaVarForInit
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaRefVarAry
__vbaBoolVarNull
_CIsin
__vbaErase
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaPutOwner3
__vbaVarTstEq
__vbaI2I4
__vbaObjVar
DllFunctionCall
__vbaVarOr
_adj_fpatan
__vbaFixstrConstruct
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaGetOwner3
__vbaUbound
__vbaStrVarVal
__vbaVarCat
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaVar2Vec
__vbaInStr
__vbaNew2
__vbaCyMulI2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
EVENT_SINK2_AddRef
__vbaFreeStrList
_adj_fdivr_m32
__vbaPowerR8
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarCmpEq
__vbaAryLock
__vbaVarAdd
__vbaLateMemCall
__vbaStrToAnsi
__vbaVarDup
__vbaFpI2
__vbaVarMod
__vbaFpI4
__vbaLateMemCallLd
__vbaRecDestructAnsi
_CIatan
__vbaStrMove
__vbaCastObj
__vbaI4Cy
_allmul
_CItan
__vbaAryUnlock
__vbaFPInt
__vbaVarForNext
_CIexp
__vbaFreeStr
__vbaFreeObj
URLDownloadToFileA
!This program cannot be run in DOS mode.
`.data
.reloc
"NMNotifyWindowClass
Winsock General Property Page
MSWINSCKWndClass
MSWNSK98.chm
Microsoft WinSock Control, version 6.0
Winsock
VVVVVVVh
GDt	WVP
Pp_^[]
Notification Window
u	C@@f
hhctrl.ocx
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
F4Wh(m
MSWINSCK.OCX
DLLGetDocumentation
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
"255.255.255.255
"6.00.8169
MSWinsock
CtlFrameWork_ReflectWindow
QQVWj?
F0_^][
F0;F4u	
~0_^][
u	!F _^[
t"HtKHt$HtaHt
tMHt!HtGHt7Ht
~0PPhG
N0Wj?j
N0Wj?j
u!PhHi
V;ALWuP
JtPJtBJJt3
"WVh8l
PSVSh8&
PSVSh<&
PSVSh@&
PSVShD&
PWShL&
"f9XHu+
GPSSSSS
t HHuEj
CT;{Pu
te9Kht0
sPQQQP
"f9x>t
VtRhXm
VtRhXm
"VVVVVVh
WSOCK32.dll
KERNEL32.dll
USER32.dll
ole32.dll
ADVAPI32.dll
OLEAUT32.dll
GDI32.dll
HeapFree
HeapAlloc
GetProcessHeap
lstrcpynA
lstrcpyA
lstrlenA
lstrcatA
IsBadWritePtr
WideCharToMultiByte
lstrlenW
LeaveCriticalSection
GetCurrentThreadId
EnterCriticalSection
LocalFree
FormatMessageA
GetTickCount
MultiByteToWideChar
SetLastError
GetModuleFileNameA
InitializeCriticalSection
DeleteCriticalSection
FreeLibrary
DisableThreadLibraryCalls
GetVersion
GetFileAttributesA
GetWindowsDirectoryA
LoadLibraryA
GetLocaleInfoA
GetProcAddress
InterlockedIncrement
InterlockedDecrement
lstrcmpiA
GetLastError
LockResource
LoadResource
FindResourceA
HeapReAlloc
lstrcmpA
PostMessageA
PeekMessageA
RegisterClassA
UnregisterClassA
SetTimer
KillTimer
SetWindowLongA
CreateWindowExA
DestroyWindow
GetWindowLongA
DefWindowProcA
SendMessageA
SetDlgItemInt
GetDlgItemInt
SendDlgItemMessageA
SetDlgItemTextA
GetDlgItemTextA
LoadStringA
GetSystemMetrics
LoadBitmapA
MessageBoxA
GetActiveWindow
DialogBoxParamA
EndDialog
DrawEdge
LoadCursorA
wsprintfA
ReleaseDC
CharNextA
ShowWindow
SetParent
GetWindowRect
SetWindowPos
WinHelpA
IsDialogMessageA
GetWindow
GetNextDlgTabItem
IsWindowEnabled
GetDlgItem
IsChild
GetKeyState
GetParent
CreateDialogIndirectParamA
IsWindowVisible
EndPaint
GetClientRect
BeginPaint
SetFocus
MoveWindow
ClientToScreen
OffsetRect
EqualRect
IntersectRect
SetWindowRgn
PtInRect
MessageBeep
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CreateOleAdviseHolder
RegDeleteValueA
RegCloseKey
RegSetValueExA
RegCreateKeyExA
RegOpenKeyExA
RegDeleteKeyA
RegEnumKeyExA
RegQueryValueExA
RegOpenKeyA
RegQueryValueA
GetObjectA
DeleteObject
DeleteDC
BitBlt
SelectObject
CreateCompatibleDC
GetDeviceCaps
CreateRectRgnIndirect
GetViewportExtEx
GetWindowExtEx
LPtoDP
SetMapMode
SetViewportExtEx
SetWindowExtEx
SetViewportOrgEx
SetWindowOrgEx
CreateDCA
Licenses
"%s%s.DLL
%s%s.DLL
%u\%s.dll
CtlFrameWork_Parking
{%08lX-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
CLSID\%s
%s Object
InprocServer32
Apartment
ThreadingModel
ThreadingModel
%s Object
CurVer
%s.%s.%ld
%s Object
CLSID\%s
VersionIndependentProgID
ProgID
%s.%s.%ld
TypeLib
Version
%ld.%ld
CLSID\%s
Control
MiscStatus
ToolboxBitmap32
\InprocServer32
%s.%s.%ld
%s.%s\CurVer
%s.%s.%ld
%s.%s.%ld
%s.%s.%ld
CLSID\%s
Implemented Categories
%s\InprocServer
VERSION.DLL
GetFileVersionInfoSizeA
VERSION.DLL
GetFileVersionInfoA
VERSION.DLL
VerQueryValueA
>LangRef
DISPLAY
CtlFrameWork_Parking
CtlFrameWork_Parking
%ld - %s
%ld - %s
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwp
wwwwww
wwwwww
wwwwww
wwwwww
wwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
stdole2.tlbWWW
MSWinsockLib
8xGProtocolConstantsWWWd
IMSWinsockControlWWW
DMSWinsockControlEventsW,
WinsockW
StateConstantsWW
ErrorConstantsWW
hsckTCPProtocolWW
FsckUDPProtocolWWd
AboutBoxd
Protocold
RemoteHostIPd
V3LocalHostNameWWWd
LocalIPWd
SocketHandled
_RemoteHostWd
4ORemoteHostWWd
}|RemotePortWWd
7LocalPortWWWd
StateWWWd
BytesReceivedWWWd
ConnectWd
+ListenWWd
AcceptWW
requestIDWWWd
SendData
;datad
GetDataW
dmaxLenWWd
PeekDatad
CloseWWWd
ErrorWWW
-NumberWW
 DescriptionW
/ScodeWWW
SourceWW
HelpFile
/OHelpContextW
+CancelDisplayWWW
DataArrivalW
$bytesTotalWW
iConnectionRequestWWW
SendProgress
bytesSentWWW
bytesRemainingWW
SendComplete
sckClosedWWW
sckOpenW
sckListening
FsckConnectionPending
SsckResolvingHost
sckHostResolvedW
YsckConnectingWWW
sckConnected
sckClosingWW
sckError
sckInvalidPropertyValueW
0ZBsckGetNotSupportedWW
sckSetNotSupportedWW
sckOutOfMemoryWW
sckBadStateW
sckInvalidArgWWW
csckSuccessWW
sckUnsupportedWW
8sckInvalidOp
wsckOutOfRangeWWW
sckWrongProtocol
sckOpCanceledWWW
sckInvalidArgumentWW
sckWouldBlockWWW
sckInProgressWWW
msckAlreadyCompleteWW
sckNotSocket
sckMsgTooBig
sckPortNotSupportedW
sckAddressInUseW
LsckAddressNotAvailableWW
sckNetworkSubsystemFailedWWW
sckNetworkUnreachableWWW
[sckNetResetW
9sckConnectAbortedWWW
sckConnectionResetWW
sckNoBufferSpace
sckAlreadyConnectedW
sckNotConnectedW
RsckSocketShutdownWWW
nsckTimedoutW
|sckConnectionRefused
sckNotInitializedWWW
sckHostNotFoundW
)sckHostNotFoundTryAgainW
sckNonRecoverableErrorWW
sckNoDataWWW
Microsoft Winsock Control 6.0W
MSWinSck.OcxWW
MSWNSK98.chmWW
Protocol Constants
Winsock methods and events 
Microsoft Winsock Control eventsWW
Microsoft Winsock ControlW
State ConstantsWWW
Error ConstantsWWW
TCP protocolWW
UDP protocolWW 
Returns/Sets the socket protocolWW"
Returns the remote host IP address
Returns the local machine name$
Returns the local machine IP addressWW
Returns the socket handleW?
Returns/Sets the port to be connected to on the remote computerWWW0
Returns/Sets the port used on the local computerWW*
Returns the state of the socket connection7
Returns the number of bytes received on this connectionWWW
Connect to the remote computer'
Listen for incoming connection requestsWWW%
Accept an incoming connection requestW
Send data to remote computerWW)
Retrieve data sent by the remote computerW9
Look at incoming data without removing it from the bufferW
Close current connectionWW)
Binds socket to specific port and adapterW:
Returns/Sets the name used to identify the remote computer
Error occurred;
Occurs when data has been received from the remote computerWWW%
Occurs connect operation is completedW4
Occurs when a remote client is attempting to connectWW*
Occurs when the connection has been closed%
Occurs during process of sending dataW+
Occurs after a send operation has completedWWW
Socket is currently closed
Socket is currently openWW 
Socket is listening for requestsWW
Socket has a pending requestWW(
Socket is resolving remote computer nameWW(
Socket has resolved remote computer nameWW'
Socket is connecting to remote computerWWW'
Socket has connected to remote computerWWW/
Socket is closing connection to remote computerWWW
Socket has encountered an errorWWW
Invalid property value
Property is write-only
Property is read-onlyW
Out of memoryWK
Wrong protocol or connection state for the requested transaction or requestWWWY
The argument passed to a function was not in the correct format or in the specified rangeW
Successful
Unsupported variant typesW"
Invalid operation at current state
Argument is out of rangeWW7
Wrong protocol for the requested transaction or requestWWW
The operation is canceledW
Invalid argumentWW=
Socket is non-blocking and the specified operation will blockW+
A blocking winsock operation is in progressWWWA
The operation is completed. No blocking operation is in progress.W
The descriptor is not a socketA
The datagram is too large to fit into the buffer and is truncatedW#
The specified port is not supportedWWW
Address in use/
Address is not available from the local machineWWW
Network subsystem failedWW9
The network cannot be reached from this host at this timeW1
Connection has timed out when SO_KEEPALIVE is setW5
Connection is aborted due to timeout or other failureW&
The connection is reset by remote side
No buffer space is availableWW
Socket is already connectedWWW
Socket is not connectedWWW
Socket has been shut downW 
The attempt to connect timed outWW!
Connection is forcefully rejectedW"
WinsockInit should be called first$
Authoritative answer: Host not foundWW(
Non-Authoritative answer: Host not foundWW
Non-recoverable errors,
Valid name, no data record of requested typeWW
wwwwwwx
wwwwwp
wwwwwwx
wwwwwp
<3[3a3h3
4(4.484>4J4P4
5054585<5@5D5H5L5P5
6 6$6(6,616A6J6P6V6^6h6o6
6 7-757;7G7M7
8.848E8
8@9F9N9S9Y9`9
9#:>:L:R:
<)<G<S<a<f<m<}<
>;>c>k>
0+151:1D1N1_1
2%2/292C2I2o2
2A3H3O3V3]3d3k3r3y3
5$5*555T5f5y5
8	9]9q9
>Q>_>x>~>
?$?0?6?<?
0*0b0}0
2,242;2B2I2P2W2^2e2l2s2z2
4!4(4/464=4D4K4
5(5/555;5C5J5T5l5w5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8084888<8@8D8H8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9
: :$:(:,:0:4:8:@:D:H:L:P:T:X:\:`:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<P<T<X<\<`<d<h<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=p=t=x=|=
> >$>(>,>0>4>8>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?p?t?x?|?
0 0$0(0004080H0L0P0T0X0\0`0d0h0l0p0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4&4,464<4i4o4
8#8T8m8w8}8
:":>:D:c:i:
:8;E;o;
=)=/=5=:=K=_=
>->4>r>
?%?A?I?N?T?g?
$090B0b0i0
949C9S9v9
9R:X:.;
;!<'<;<A<
>(>7>=>H>N>d>p>
? ?+?o?
1#1P1`1
2#2P2d2
3S3`3j3
6%6K6Q6
778@8h9
90:4:8:<:@:D:H:L:P:T:X:\:`:d:h:p:t:x:|:
:`;d;h;l;p;x;|;
2d5j5A6y6
<!='=e=m?
3(333J3`3
6)6r6x6
9?9I9Y9y9
?+?:?C?
7K8j8x8
989):/:F:m:
:.;9;G;
< <?<J<
=A>g>v>
4'484%5-5
8H8N8k8
4$4-484>4[4d4
5U5d5i5
5J6l6y6
717k7|7
8,8Z8`8{8
:,:=:k:~:
;=;G;P;Y;
<-<Z<`<i<
<"=+=?=R=q=x=
>$>;>N>j>p>y>
?=?Q?W?`?
0E0L0R0^0z0
1'1-161J1]1c1l1
2&2D2J2W2^2r2
373M3S3
3!4(4K4
4)5H5b5q5
606<6q6
7.7R7m7
8+8B8h8
9/9;9O9
:3:D:U:
:>;D;n;
<"<(<0<9<?<F<M<T<[<h<~<
>:>@>F>_>o>{>
?3?^?s?
2"2<2j2
3-3?3e3x3~3
4A5P5\5
5&6H6Y6l6w6
70767P7e7n7s7
798E8M8V8]8d8u8
9[9b9l9
;2<?<c<
>!?D?d?r?
1I2P2W2_2
40464J4x4
6:6O6a6p6
=3=s=z=
>&>9>7?B?S?Z?k?q?{?
132A2O2]2g2v2
606M6m6
8*808@8]8g8
989o9u9
96:b:$;
<"<-<=<S<b<u<
=%=+=6=;=Q=X=^=k=q=|=
>#>)>/>@>G>W>c>p>x>
?"?)?.?5?:?x?
0(090?0E0W0]0
2 2'2/2a2l2
2!3a3y3
4 4(464=4N4T4]4
5W6b6p6w6
8C8u8{8
8H9N9T9Z9`9f9l9r9x9~9
h0p0t0x0
mswinsck.dbg
VeriSign Trust Network1
VeriSign, Inc.1,0*
#VeriSign Time Stamping Service Root1402
+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0
970512070000Z
991231070000Z0
VeriSign Trust Network1
VeriSign, Inc.1,0*
#VeriSign Time Stamping Service Root1402
+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0
VeriSign Trust Network1
VeriSign, Inc.1,0*
#VeriSign Time Stamping Service Root1402
+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0
970512070000Z
991231070000Z0
VeriSign Time Stamping Service1
VeriSign Trust Network1402
+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.1
VeriSign, Inc.1
Internet0
GBh[-}
UApF-,~0
Internet1
VeriSign, Inc.1301
*VeriSign Commercial Software Publishers CA0
980416000000Z
990416235959Z0
Internet1
VeriSign, Inc.1301
*VeriSign Commercial Software Publishers CA1F0D
=www.verisign.com/repository/CPS Incorp. by Ref.,LIAB.LTD(c)961>0<
5Digital ID Class 3 - Microsoft Software Validation v21
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
Internet1
VeriSign, Inc.1301
*VeriSign Commercial Software Publishers CA
'https://www.verisign.com/repository/CPS
This certificate incorporates by reference, and its use is strictly
subject to, the VeriSign Certification Practice Statement (CPS)
version 1.0, available in the VeriSign repository at:
https://www.verisign.com; by E-mail at CPS-requests@verisign.com; or
by mail at VeriSign, Inc., 2593 Coast Ave., Mountain View, CA 94043
USA Copyright (c)1996 VeriSign, Inc.  All Rights Reserved. CERTAIN
WARRANTIES DISCLAIMED AND LIABILITY LIMITED.
WARNING: THE USE OF THIS CERTIFICATE IS STRICTLY SUBJECT TO THE
VERISIGN CERTIFICATION PRACTICE STATEMENT.  THE ISSUING AUTHORITY
DISCLAIMS CERTAIN IMPLIED AND EXPRESS WARRANTIES, INCLUDING WARRANTIES
OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, AND WILL NOT
BE LIABLE FOR CONSEQUENTIAL, PUNITIVE, AND CERTAIN OTHER DAMAGES. SEE
THE CPS FOR DETAILS.
Contents of the VeriSign registered nonverifiedSubjectAttributes
extension value shall not be considered as accurate information
validated by the IA.
4https://www.verisign.com/repository/verisignlogo.gif0
https://www.verisign.com/CPS0b
VeriSign, Inc.0
=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign
c{2xD;
Internet1
VeriSign, Inc.1301
*VeriSign Commercial Software Publishers CA
 http://www.microsoft.com/vbasic 0
VeriSign Trust Network1
VeriSign, Inc.1,0*
#VeriSign Time Stamping Service Root1402
+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
980624180147Z0
!This program cannot be run in DOS mode.
k@Xw`,
(},b&0
>y1 A6
Qyn<t~{b
#z1C&D
M> 5A1
C%	?yk
"xk.<i
"D<uv+AI
IIthY|7
EVEoe4
:ycm+.
P*c/Mp)E
)?`4[WCS
Vw^]R)
1+K	rr
p!w.9+)
&0)e~yn
(*)9"9
h)ISDj
xstz ie
SYj	Fx
jngc@iv
|6@68tB&
W<qrjP
W9g9vb
~k/+PZ+\
)I08lENo
@!"mFC
^XAaZf
{F]2.v
!CaNlV
;ykw{g7
9D:zqa$
s-C8l:
j,}<	8
cm<]yQ
ya8*07
D{xJz,
0_$vRDY
BTJ?2CA
S:Qrvxk@
L{)bT5<
\.w}KN
HXjqi2
W)4kJb
PTJvpr
zP+vy=
+X)A|0
0=E(7	v
e3MCak
"|Q%u#
Wmpicv
8sy`F"
4YD0,i
cs31)0
,MH;|U:
^D8N^hF@e
28!	x'PQ
2yL~4VYp
?`"O{L
l'd`A[
Q9mCY|
TVJh7*
W<$dQb
o(]<%;D
WWVZ{^
D9}h]y;
m]`f(b
{sj&J[
4@z79=0)
YbAI~ 
0x%B5t
<Ojuur
$x&u%P
;VfiXk
]+ 6v`
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
9l$\w_
XPTPSW
xL=M`A
stdole2.tlbWWW
b\Es58
__P2Pd
1eDownloadFile
localfilenameWWW
DownUrlW
OFilePath
BakUrlWW
7xSleepWW
BLoadServerWW
KERNEL32.DLL
MSVBVM60.DLL
USER32.DLL
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
SendMessageA
P2P.dll
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer