Analysis Date2014-08-06 01:08:41
MD54acdb582f972322507746b3d3fd0c1ad
SHA1e5f4d809c8ebaf097aff2ab27300ac94db4b6c27

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 6de9086307eea2ba4821ce86f9f8af11 sha1: 0f3e941fe3fd393089f0fceb6ff0b98a0a296c76 size: 667648
Section.rdata md5: eba6ae6e3d7c43e3f025b5213e052e59 sha1: d906f442e16444c5328ab1fea9f1086a457010ae size: 425984
Section.data md5: fa6e85a536c288cf700e168820932c7c sha1: 569ff7a6225d69d75ea92bc435d6a2a14cfd1f8a size: 86016
Section.rsrc md5: 70d080f84cec5bc24c2836278c39de04 sha1: 705c2d85f76c4e3f3b02b7cd1ddea616d65d44b6 size: 126976
Timestamp2012-09-28 08:08:13
VersionLegalCopyright: 软件可任意使用,本软件绿色免费,请保证你的软件在多特或官网下载,保证软件无任何病毒。如果在他站下载造成您计算机无法使用,本作者不负责任何责任!

软件BUG提交 QQ:262618128

卤中仙:http://www.hrcygs.com

卤中仙熟食,做全国最好吃的美味熟食。
FileVersion: 7.0.0.0
CompanyName: 卤中仙
Comments: 局域网共享软件V7.0
ProductName: 局域网共享软件
ProductVersion: 7.0.0.0
FileDescription: 局域网共享软件V7.0
PackerMicrosoft Visual C++ v6.0
PEhashf6aa793d90e640c8f04d6fc1189260ddb273ad2b
IMPhashd1a334a0d4062e443c0b603373bf1e0c
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumW32/OnlineGames.HG.gen!Eldorado
AVAvira (antivir)no_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftno_virus
AVEset (nod32)no_virus
AVFortinetno_virus
AVFrisk (f-prot)W32/OnlineGames.HG.gen!Eldorado (generic, not disinfectable)
AVF-SecureTrojan:W32/DelfInject.R
AVGrisoft (avg)PSW.OnlineGames4.ACAG
AVIkarusBackdoor.Win32.BlackHole
AVK7no_virus
AVKasperskyno_virus
AVMalwareBytesSpyware.OnlineGames
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVNormanwinpe/Suspicious_Gen4.GVWCG
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FilePIPE\DAV RPC SERVICE
Creates FilePIPE\wkssvc
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FileC:\works.bat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Deletes FileC:\works.ini
Deletes FileC:\works.bat
Creates ProcessC:\works.bat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!

Process
↳ C:\works.bat

Creates FileC:\works.ini
Creates Processfind /V "DNS"
Creates Processfind "\\xe2\\x95\\xa3\\xc3\\xb1\\xe2\\x95\\xab\\xe2\\x89\\x88\\xe2\\x95\\x92\\xe2\\x95\\x9b\\xe2\\x95\\x99\\xe2\\x89\\xa5"
Creates Processnet config workstation

Process
↳ net config workstation

Creates Processnet1 config workstation

Process
↳ find "\\xe2\\x95\\xa3\\xc3\\xb1\\xe2\\x95\\xab\\xe2\\x89\\x88\\xe2\\x95\\x92\\xe2\\x95\\x9b\\xe2\\x95\\x99\\xe2\\x89\\xa5"

Process
↳ find /V "DNS"

Process
↳ net1 config workstation

Creates FilePIPE\wkssvc
Creates FilePIPE\lsarpc

Network Details:

DNSwww.hrcygs.com
Type: A
117.34.28.84
DNSwww.hrcygs.com
Type: A
61.155.149.85
HTTP GEThttp://www.hrcygs.com/tj
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Flows TCP192.168.1.1:1031 ➝ 117.34.28.84:80

Raw Pcap
0x00000000 (00000)   47455420 2f746a20 48545450 2f312e31   GET /tj HTTP/1.1
0x00000010 (00016)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000020 (00032)   7a696c6c 612f342e 30202863 6f6d7061   zilla/4.0 (compa
0x00000030 (00048)   7469626c 653b204d 53494520 362e303b   tible; MSIE 6.0;
0x00000040 (00064)   2057696e 646f7773 204e5420 352e3029    Windows NT 5.0)
0x00000050 (00080)   0d0a4163 63657074 3a202a2f 2a0d0a48   ..Accept: */*..H
0x00000060 (00096)   6f73743a 20777777 2e687263 7967732e   ost: www.hrcygs.
0x00000070 (00112)   636f6d0d 0a436163 68652d43 6f6e7472   com..Cache-Contr
0x00000080 (00128)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x00000090 (00144)                                         


Strings
.
,
....  ................
"#
L
....
.........
10/.-,+*)('&%$#"! ..............
.....
..........
..
.........
-
..
x
\
.
==
...
.
 
-% BbmHpAadYySMI \
.-E-0-0..
00-+ 
e
 
00...........?-  
0
0 
0
?
..............................
..
...
E
u.
    
 ......
 (*.*)
#####
#######
080404B0
 %1 
	1uM
262618128
7.0.0.0
(&C)
Comments
CompanyName
	Ctrl+
	Ctrl+D
	Ctrl+End
	Ctrl+G
	Ctrl+Home
	Ctrl+N
	Ctrl+PageDown
	Ctrl+PageUp
	&D.
DEFAULT_ICON
 DLL 
(&E)
FileDescription
FileVersion
         (((((                  H
(&H)
http://www.hrcygs.com
(&I)
IEXT2_IDC_HORZLINEMOVECURSOR
IEXT2_IDC_VERTLINEMOVECURSOR
IEXT2_IDR_WAVE1
IEXT_IDB_STATEIMAGES
 INI 
jjjj
Jjjj
jjjjh
Jjjjj
jjjjjj
Jjjjjjjjj
jjjjjjjjjjj
LegalCopyright
msctls_progress32
msctls_updown32
MS Shell Dlg
(&N)
(null)
(&O)
(&P)
	PageDown
	PageUp
ProductName
ProductVersion
Progress1
  QQ
Rjjj
 %s 
(&S)
	Shift+Tab
Spin1
StringFileInfo
(&T)
	Tab/Enter
TEXTINCLUDE
Translation
V7.0
VarFileInfo
VS_VERSION_INFO
WAVE
xxxx
^,_^][
^$_^[]
 (*.*)|*.*||
	!	!	!	!	
0123456789ABCDEF
(&07-034/)7 '
0dk:ghV
 0@P`p
0R>\W[
1.2.18
"137:UDP"="137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"139:TCP"="139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004"
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
,1"52.*
192.168.0.1
192.168.1.1
!1AQaq
1#QNAN
1" /r /d y && icacls "
1#SNAN
	2	5	5	5	5	5
262618128
27bb20fdd3e145e4bee3db39ddd6e64c
"2BRbr
;2 CxdB
%+.2d%.2d
2" /grant administrators:F /t
3B,18,A5,26,46,BC,3E,6A,30,A4,7D,A0,56,E6,6A,B5,\
#3CScs
"445:TCP"="445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
4C,79,37,BB,FD,BD,70,B2,B2,58,D5,B5,89,5C,B6,4E,\
$4DTdt
\$4t|Ht@H
\$4UVWS
\$4VWh
|?5^<@
5	!	!	!	!
52F260023059454187AF826A3C07AF2A
	5	5	5
57,3A,BF,A1,CD,CA,B6,64,4C,F9,0E,D2,64,ED,86,1F,\
%5EUeu
5F99C1642A2F4e03850721B4F5D7C3F8
*5iMmzS
61,F6,D1,01,0B,7C,8D,BD,73,10,C8,4E,57,93,4E,90
6.6---
	6	6	6	6
	6	6	6	6	6	6	6	6	6	6	,	,	,	,	,	,	,	,	+	+	+	+	+	/	/	/	'	'	'	'	'	'	'	'	'	'	(	(	(	(	(	(	(	(	(	(	(	(	(	
&6FVfv
7.0---
707ca37322474f6ca841f0e224f4b620
	7	7	7	7	7	7	7	7	7	7	7	*	*	-	-	-	-
/7dO	=d
7F54B9CE8887428dBA9CEEB94CEF4C72
'7GWgw
(8HXhx
8MThdu
8\$$tC
\$8UVW
9^0u/j
'9A`u"9
{9DA96BF9CEBD45c5BFCF94CBE61671F5}
9D$$t+
)9IYiy
9L$x~e
9l$xtU9
9nPu	9^T
9o4u'V
	9oTtc
9t$0v8
9^xu5j
<A|2<Z
A512548E76954B6E92C21055517615B0
A6B983789F624b2cBDFD7D671249C097
abcddefghijklmnoopqrrsstuvvwwxyyz;
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abnormal program termination
Accept: */*
Accept: */* 
%a, %d %b %Y %H:%M:%S 
AdjustWindowRectEx
administrator
Administrator
Advapi32.dll
ADVAPI32.dll
AF6AD80AA4244A59AFB3D83ECF5173CC
AfxControlBar42s
AfxFrameOrView42s
AfxMDIFrame42s
AfxOldWndProc423
AfxOleControl42s
AfxWnd42s
Afx:%x:%x
Afx:%x:%x:%x:%x:%x
AlignStyle
allow desktop composition:i:0
allow font smoothing:i:0
AllowMultiLines
alternate shell:s:
AppendMenuA
.?AUCThreadData@@
audiocapturemode:i:0
audiomode:i:1
August
.?AUISequentialStream@@
.?AUIStream@@
.?AUIUnknown@@
authentication level:i:0
AutoGetTransColor
AutoNextLine
autoreconnection enabled:i:1
.?AV_AFX_BASE_MODULE_STATE@@
.?AV_AFX_CHECKLIST_STATE@@
.?AV_AFX_COLOR_STATE@@
.?AV_AFX_CTL3D_STATE@@
.?AV_AFX_CTL3D_THREAD@@
.?AVAFX_MODULE_STATE@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AV_AFX_SOCK_STATE@@
.?AV_AFX_THREAD_STATE@@
.?AV_AFX_WIN_STATE@@
.?AVCArchiveException@@
.?AVCArchiveStream@@
.?AVCBitmap@@
.?AVCBrush@@
.?AVCButton@@
.?AVCClientDC@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCColorDialog@@
.?AVCComboBox@@
.?AVCCommonDialog@@
.?AVCCriticalSection@@
.?AVCDC@@
.?AVCDialog@@
.?AVCDWordArray@@
.?AVCEdit@@
.?AVCException@@
.?AVCFile@@
.?AVCFileDialog@@
.?AVCFileException@@
.?AVCGdiObject@@
.?AVCHandleMap@@
.?AVCImageList@@
.?AVCListCtrl@@
.?AVCMapPtrToPtr@@
.?AVCMapStringToPtr@@
.?AVCMemFile@@
.?AVCMemoryException@@
.?AVCMenu@@
.?AVCNoTrackObject@@
.?AVCNotSupportedException@@
.?AVCObject@@
.?AVCPaintDC@@
.?AVCPen@@
.?AVCProgressCtrl@@
.?AVCPtrArray@@
.?AVCPtrList@@
.?AVCResourceException@@
.?AVCRgn@@
.?AVCSessionMapPtrToPtr@@
.?AVCSharedFile@@
.?AVCSimpleException@@
.?AVCSpinButtonCtrl@@
.?AVCStatic@@
.?AVCStatusBarCtrl@@
.?AVCStringArray@@
.?AVCSyncObject@@
.?AVCTabCtrl@@
.?AVCTempDC@@
.?AVCTempGdiObject@@
.?AVCTempImageList@@
.?AVCTempMenu@@
.?AVCTempWnd@@
.?AVCTestCmdUI@@
.?AVCToolBarCtrl@@
.?AVCToolTipCtrl@@
.?AVCUserException@@
.?AVCWinApp@@
.?AVCWindowDC@@
.?AVCWinThread@@
.?AVCWnd@@
.?AVCWordArray@@
.?AVexception@@
 (*.avi)|*.avi
AVIFIL32.dll
AVIFileName
AVIStreamGetFrame
AVIStreamInfoA
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
<A|@<Z
B 02CV
BackColor
bcdfghijklmnpqrstuvwxyz
BeginPaint
BeginPath
BitBlt
bitmapcachepersistenable:i:1
BKbhTb~XBK!;
BkColorFocus
BkColorIn
BkColorOut
 (*.BMP)|*.BMP|GIF
Bogus message code %d
border
BQ@RPV
BRPj+S
BrushColor
BrushStyle
BtnStyle
buffer error
BuildExplicitAccessWithNameA
Button
BUTTON
C =02CVu
cacls 
cacls "
CallNextHookEx
CallWindowProcA
caption
CArchiveException
CBitmap
CBrush
CButton
CClientDC
CCmdTarget
CColorDialog
CColourPicker
CComboBox
CCriticalSection
Cc: %s
CDialog
CDWordArray
CException
cf3SHM
CFileDialog
CFileException
CGdiObject
CharUpperA
CheckBox
Checked
CheckMenuItem
ChildWindowFromPointEx
ChooseColorA
CImageList
ck(WSbpS
ClickSound
ClientToScreen
CListCtrl
CloseClipboard
CloseDatabase
CloseHandle
ClosePrinter
CLSIDFromProgID
CLSIDFromString
CMapPtrToPtr
CMapStringToPtr
cmd.exe /c takeown /f "
CMemFile
CMemoryException
CNotSupportedException
CObject
CoCreateInstance
CollideAllowed
CollidedSound
CombineRgn
combobox
ComboBox
COMBOBOX
ComboLBox
COMCTL32.dll
COMCTL32.DLL
comdlg32.dll
commctrl_DragListMsg
commdlg_ColorOK
commdlg_FileNameOK
commdlg_FindReplace
commdlg_help
commdlg_LBSelChangedNotify
commdlg_SetRGBColor
commdlg_ShareViolation
ComObject
CompareStringA
CompareStringW
compression:i:1
connection type:i:2
Content-Transfer-Encoding: base64
Content-type: multipart/mixed; boundary="#BOUNDARY#"
Content-type: text/plain; charset="
context
ContextType
control userpasswords2
CopyAcceleratorTableA
CopyRect
CPaintDC
CPalette
cP]e vI
CProgressCtrl
CPtrArray
CPtrList
CreateAcceleratorTableA
CreateBitmap
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCA
CreateDialogIndirectParamA
CreateDIBitmap
CreateDIBSection
CreateEllipticRgn
CreateEllipticRgnIndirect
CreateEventA
CreateFileA
CreateFontIndirectA
CreateIconFromResource
CreateIconFromResourceEx
CreateMenu
CreatePalette
CreatePatternBrush
CreatePen
CreatePolygonRgn
CreatePopupMenu
CreateProcessA
CreateRectRgn
CreateRectRgnIndirect
CreateRoundRectRgn
CreateSemaphoreA
CreateSolidBrush
CreateSound
CreateThread
CreateWindowExA
CResourceException
crypt32.dll
CryptProtectData
CSharedFile
CSpinButtonCtrl
CStatic
CStatusBarCtrl
CStringArray
CSyncObject
CTabCtrl
CTempDC
CTempGdiObject
CTempImageList
CTempMenu
CTempWnd
CToolBarCtrl
CToolTipCtrl
Ctrl+A
Ctrl+B
Ctrl+C
Ctrl+D
Ctrl+E
Ctrl+F
Ctrl+F1
Ctrl+F10
Ctrl+F11
Ctrl+F12
Ctrl+F2
Ctrl+F3
Ctrl+F4
Ctrl+F5
Ctrl+F6
Ctrl+F7
Ctrl+F8
Ctrl+F9
Ctrl+G
Ctrl+H
Ctrl+I
Ctrl+J
Ctrl+K
Ctrl+L
Ctrl+M
Ctrl+N
Ctrl+O
Ctrl+P
Ctrl+Q
Ctrl+R
Ctrl+S
Ctrl+Shift+F1
Ctrl+Shift+F10
Ctrl+Shift+F11
Ctrl+Shift+F12
Ctrl+Shift+F2
Ctrl+Shift+F3
Ctrl+Shift+F4
Ctrl+Shift+F5
Ctrl+Shift+F6
Ctrl+Shift+F7
Ctrl+Shift+F8
Ctrl+Shift+F9
Ctrl+T
Ctrl+U
Ctrl+V
Ctrl+W
Ctrl+X
Ctrl+Y
Ctrl+Z
 (*.CUR)|*.CUR|
CurrentFrame
CUserException
CWinApp
CWindowDC
CWinFormUnit
CWinThread
CWordArray
?? / %d]
D$ _^][
D$,_^]
D$,;\$|
D$(_^]
D$(_^][
D$$_^[
D$$_^]
d09f2340818511d396f6aaf844c7e325
D$0QRWVP
D$0UVW
D$0VRP
D$0WPQ
D$0WRP
D$0WVQ
D$ |2;
D$49D$$}
D$4SUV
D$89Vdu
D$8FtdW
D$8RPj
D$8RPU
D$8SUVWt
D$8VPQ
D$$~9+
@.data
data error
Date: %s
D$$BHRPV
D$$B@RPV
D$(CUSWP
 %d/%d 
(%d-%d):
%d / %d
%d / %d]
dddd, MMMM dd, yyyy
D$dPQV
#D$DQRP
D$dQUWRP
D$dSUVW
D$DSWRPQ
D$dUPh
D$DURP
December
DefaultColor
DEFAULT_ICON
DefaultStyle
#define _AFX_NO_OLE_RESOURCES
#define _AFX_NO_PROPERTY_RESOURCES
#define _AFX_NO_TRACKER_RESOURCES
DefWindowProcA
DELETE
DeleteCriticalSection
DeleteDC
DeleteFileA
DeleteMenu
DeleteObject
 /delete /y
" /delete /y
Desktop
desktopheight:i:800
desktopwidth:i:1280
DestroyAcceleratorTable
DestroyCursor
DestroyIcon
DestroyMenu
DestroySound
DestroyWindow
device
devices
D$H_^][
D$HBRj
D$HJQRP
D$hQRP
D$hRPQ
D$hSUV3
D$hUPQ
D$HUPQ
D$HUSj
+(]dIC
disable
disable cursor setting:i:0
disable full window drag:i:1
disable menu anims:i:1
disable themes:i:0
disable wallpaper:i:1
DispatchMessageA
DISPLAY
displayconnectionbar:i:1
D$(JQHRPV
D$ JQRPV
D$(;l$ 
D$l_^][
D$LJHRP
D$LJRP
DllRegisterServer
DllUnregisterServer
D$LPUj
D$LUSWP
DocumentPropertiesA
doc wpd
DOMAIN error
D$,Pj<j
D$ PQR
D$PQRP
D$PRPQ
DPtoLP
D$\|`Q
D$(QPW
D$(QRP
D$$QRP
D$ QRPhljV
D$ QRPV
D$$QRPV
D$<QRV
D$$QUP
 DQWPh8
DragQueryFileA
DrawBorder
DrawDibDraw
DrawEdge
DrawFocus
DrawFocusRect
DrawFrameControl
DrawIconEx
DrawRop2
DrawStateA
DrawTextA
	=dRich
drivestoredirect:s:
drivestoredirect:s:*
DropTarget
D$,RPQ
D$@RPQj
D$ RPUhD
D$ RPV
D$ R@PV
DRUPh\
D$,RVh
D$,SPh
D$(SUV
D$$SUV
D$;SUV3
D$(SUVW
D$(SUW
D$(t,;
D$tKQMSUP
D$TRPW
D$TVPW
D$tVWPh
DuplicateHandle
D$@UPQ
|$D UV
\$dUVW
DvNqjp
D$@WPS
D$,WRP
D$XPQU
D$XQRWP
;D$xt(%
;D$xt&
!DyhUz
ech1Y%
@ ECHO.
@ ECHO OFF
EditBox
EDropTarget::DragEnter
EDropTarget::DragLeave
EDropTarget::DragOver
EDropTarget::Drop
EDropTarget::QueryInterface
EHPWVS
Ellipse
EmptyClipboard
e-myK\
EnableMenuItem
EnableWindow
EndDialog
EndDoc
#endif
#endif //_WIN32
EndPage
EndPaint
EndPath
EnterCriticalSection
EnumChildWindows
EnumDisplayMonitors
EnumDisplaySettingsA
EnumThreadWindows
"Epoch"=dword:000001ED
"Epoch"=dword:000001FC
:eQJl4Y
eQpenc
EqualRect
Error decoding compressed text
Escape
 /e /t /g everyone:F
" /e /t /g everyone:F
Everyone
EXCEL32.CNV
ExcludeClipRect
ExistTime
ExitProcess
ExpandEnvironmentStringsA
ExtSelectClipRgn
ExtTextOutA
F<_^][
F,_^][
F\_^][
F09^4u*j
F49^8u&j
F7FC1AE45C5C4758AF03EF19F18A395D
F89^8u&j
F(9V8tQ
FD@ul9L$(}f
FD uy9D$$}s
February
F(_+F$^[;E
?fff&ff23
ffffff
@ffffff
F$@;F(v
F$@@;F(v
FgColorFocus
FgColorIn
FgColorOut
^,~FH;
file error
FileTimeToLocalFileTime
FileTimeToSystemTime
FillRect
FillRgn
FindClose
FindFirstFileA
FindNextFileA
FindResourceA
" | find /V "DNS">>"%
FindWindowExA
F\jLSP
- floating point not loaded
FlushFileBuffers
"forceguest"=dword:00000000
"forceguest"=dword:00000001
FpHt&Ht
-FQUF8V
FrameRect
Frames
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
Friday
From: %s
[/fS_MR
full address:s:%
Fxt_;FTu@
f-Y)Km
GAIsProcessorFeaturePresent
gatewaycredentialssource:i:4
gatewayhostname:s:
gatewayprofileusagemethod:i:0
gatewayusagemethod:i:4
g~b1Y%
gb2312
=?gb2312?B?
Gdi32.dll
GDI32.dll
GetACP
GetActiveWindow
GetBkColor
GetBkMode
GetCapture
GetClassInfoA
GetClassLongA
GetClassNameA
GetClientRect
GetClipboardData
GetClipBox
GetClipRgn
GetCommandLineA
GetConnectString
GetCPInfo
GetCurrentObject
GetCurrentProcess
GetCurrentThread
GetCurrentThreadId
GetCursorPos
GetDesktopWindow
GetDeviceCaps
GetDIBits
GetDlgCtrlID
GetDlgItem
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetFileAttributesA
GetFileSize
GetFileTime
GetFileTitleA
GetFileType
GetFocus
GetFolder
GetForegroundWindow
GetFullPathNameA
GetKeyState
GetLastActivePopup
GetLastError
GetLocalTime
GetMenu
GetMenuCheckMarkDimensions
GetMenuItemCount
GetMenuItemID
GetMenuState
GetMessageA
GetMessagePos
GetMessageTime
GetModuleFileNameA
GetModuleHandleA
GetMonitorInfoA
GetNamedSecurityInfoA
GetNextDlgTabItem
GetObjectA
GetOEMCP
GetOpenFileNameA
GetParent
GetPixel
GetPolyFillMode
GetProcAddress
GetProcessHeap
GetProcessVersion
GetProfileStringA
GetPropA
GetROP2
GetSaveFileNameA
GetScrollPos
GetScrollRange
GetStartupInfoA
GetStdHandle
GetStockObject
GetStretchBltMode
GetStringTypeA
GetStringTypeW
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetSystemPaletteEntries
GetSystemTime
GetTabList
GetTempPathA
GetTextColor
GetTextExtentPoint32A
GetTextMetricsA
GetTickCount
GetTimeZoneInformation
GetTopWindow
GetUserDefaultLCID
GetVersion
GetVersionExA
GetViewportExtEx
GetViewportOrgEx
GetVolumeInformationA
GetWindow
GetWindowDC
GetWindowExtEx
GetWindowLongA
GetWindowOrgEx
GetWindowPlacement
GetWindowRect
GetWindowsDirectoryA
GetWindowTextA
GetWindowTextLengthA
GIF89a
GIFAutoDestroy
GIFDelay
 (*.GIF)|*.GIF|
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFlags
GlobalFree
GlobalGetAtomNameA
GlobalHandle
__GLOBAL_HEAP_SELECTED
GlobalLock
GlobalReAlloc
GlobalSize
GlobalUnlock
GradientFill
 /grant:Guests,full /grant:Everyone,full
 /grant:Guests,read /grant:Everyone,read
GrayStringA
GroupBox
`h````
h9n`u;
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
height
"=hex:0C,00,00,00,08,00,00,00,F0,FB,E5,52,64,95,C6,01
"=hex:0C,00,00,00,13,00,00,00,90,AF,A4,87,A4,95,C6,01
hgjlkbrfzaoe
HHtiHtGH
HHtpHHtl
HideSel
HKEY_CURRENT_USER\SOFTWARE\JYW
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Providers]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Epoch]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
H:mm:ss
"HRZR_EHAPCY"=hex:0C,00,00,00,26,00,00,00,F0,FB,E5,52,64,95,C6,01
"HRZR_EHAPCY"=hex:0C,00,00,00,2A,00,00,00,90,AF,A4,87,A4,95,C6,01
"HRZR_EHAPCY:"P:\JVAQBJF\flfgrz32\sverjnyy.pcy",Jvaqbjf 
,HSUVWt
HSVHWtgHHtF
Ht#HHt
HtHHt(
HtHHuz
 Ht*Ht
html32.cnv
HTML Format
html htm htx
html htm htx asp
HtOHt)H
HtTHtFHt8Ht*Ht
http://
HTTP/1.0
HttpOpenRequestA
HttpQueryInfoA
HttpSendRequestA
http://www.hrcygs.com
http://www.hrcygs.com/jyw.zip
http://www.hrcygs.com/page/join/application.php
http://www.hrcygs.com/tj
hWj@_;
HyperLinker
_hypot
IcmpCloseHandle
IcmpCreateFile
icmp.dll
IcmpSendEcho
 (*.ICO)|*.ICO|
iext2_IDC_HORZLINEMOVECURSOR
iext2_IDC_VERTLINEMOVECURSOR
iext2_IDR_WAVE1
#if !defined(AFX_RESOURCE_DLL) || defined(AFX_TARG_CHS)
#ifdef _WIN32
ImageList_Destroy
ImageList_Duplicate
ImageList_GetIcon
ImageList_GetImageCount
ImageList_Read
ImageList_SetBkColor
#include "l.chs\afxres.rc"          // Standard components
incompatible version
 inflate 1.1.3 Copyright 1995-1998 Mark Adler 
InflateRect
InitCommonControlsEx
InitializeCriticalSection
insufficient memory
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
InternetCanonicalizeUrlA
InternetCloseHandle
InternetConnectA
InternetCrackUrlA
InternetOpenA
InternetReadFile
InternetSetOptionA
IntersectRect
InvalidateRect
invalid string position
IPAddress
iphlpapi.dll
IsBadCodePtr
IsBadReadPtr
IsBadWritePtr
IsChild
IsDialogMessageA
IsIconic
IsRectEmpty
IsWindow
IsWindowEnabled
IsWindowVisible
IsZoomed
It#Iu%
\$\}-j
JanFebMarAprMayJunJulAugSepOctNovDec
January
jBWVSSQ
JPEGMEM
 (*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
 (*.JPG)|*.JPG|BMP
j$SWRPj
&-JT(P
j VUPWQ
*:JZjz
kernel32
KERNEL32
kernel32.dll
Kernel32.dll
KERNEL32.dll
keyboardhook:i:2
KillTimer
+;K[k{
kXEQ>\u
^l_^][
;l$ }:
L$ _^]
L$ ]_^
L$$_^]
L$0PQR
L$0PQS
L$0RPQ
L$0SUV@W
L23fff&ff
L$,_^]3
L$,_[3
L$4_^3
L$4_^[d
L$4RQPj
L$4S+L$0Qj
L$4SQh
L$4UQWP
L$4VQUP
L$4WPQR
L$4WQUVS
L$8^]_3
L$89l$8}
L$8_^[d
L$8_^][d
L$8@PQ
L$8PQU
L$8RPQ
L$8WPQR
LANGUAGE 4, 2
L$$@APQV
L$,BQRV
L$$BQRV
LCMapStringA
LCMapStringW
L$`_^[d
L$`_^][d
L$<^[_]d
L$|_^][d
L$ ^][d
L$ _^d
L$ _^][d
L$,_^][d
L$(_^][d
L$@^[d
L$@_^][d
L$$^[d
L$$^]d
L$$^][d
L$$_^d
L$$_^]d
L$$_^][d
L$\_^][d
L$D@APQ
L$d_^][d
L$D_^[d
L$D_^][d
L$D_]d
L$DHAP
L$DHRPj
L$DHRPUQ
L$DPQj
L$DRPj
L$DRSQ
L$DSVQ
L$DVPQ
LeaveCriticalSection
l	g~b0R 
l	g~b0Rdk
L$h_^]3
L$$HAPQV
L$h_^][d
L$H_^][d
L$H][d
L$HHRPQ
L$$HIPQV
L$Hj&Q
L$$hlSQ
l$HQRVU
L$hRPQV
L$HSUVWP
L$hVQR
L$$hX`Q
"limitblankpassworduse"=dword:00000000
"limitblankpassworduse"=dword:00000001
LineTo
ListBox
ListView
L$$JQRV
,<L\l|
L$L_^]3
L$l_^][d
L$L^[d
L$L_^][d
L$LHIPQ
L$LPQR
L$lRPj
L$lRVQ
LoadBitmapA
LoadCursorA
LoadIconA
LoadImageA
LoadLibraryA
LoadResource
LoadStringA
LocalAlloc
LocalFree
LocalReAlloc
LockFile
LockResource
"LogonTime"=hex:E8,31,8E,4F,64,95,C6,01
L$P_^d
L$P_]^[d
L$ PQh
L$<PQR
L$,PQR
L$(PQR
L$@PQR
L$ @PQV
L$<PQVV
L$pRPQ
LPtoDP
L$(PVQ
L$ QRh
L$ QSR
L$,RPQ
L$(RPQ
L$$RPQ
L$<RPQW
L$@RQj
L$@RUQ
L$<SQR
L$,SQR
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpyA
lstrcpynA
lstrlenA
lstrlenW
L$,SUV
L$(SUV
L$T_^]
L$t_^d
L$t][d
L$T_^d
L$T_^]d
L$T_^][d
|$LtE;
L$TSWQ
L$ <-u
L$(UUh
\$lUV3
L$(VQRSP
L$(VQVj
l$@VW3
l$<VWj
L$ WPQ
L$(WQR
L$(WSR
L$x_^3
L$X_^]3
L$x_^d
L$x_^][d
L$X_^d
L$X;L$
L$XQSPUR
L$XQSPV
L$XSQh
@;l$\~Z
mailto:
MapWindowPoints
MaxAllowLength
MD7Tl^Ev
 MD'dA
M/d/yy
MessageBoxA
mE@^u0
M\.gk_
MGridCells
Microsoft Excel 
Microsoft Internet Explorer
Microsoft Visual C++ Runtime Library
midiOutPrepareHeader
midiOutReset
midiOutUnprepareHeader
midiStreamClose
midiStreamOpen
midiStreamOut
midiStreamProperty
midiStreamRestart
midiStreamStop
 (*.MID)|*.MID|
MIME-Version: 1.0
Mi`]Ypz
-=M]m}
Modified
ModifyMenuA
Monday
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MousePointer
MoveToEx
MoveWindow
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Mpr.dll
MPR.dll
msctls_hotkey32
msctls_progress32
msctls_statusbar32
msctls_trackbar32
msctls_updown32
MSIMG32.dll
MS Sans Serif
MS Shell Dlg
mstsc.exe 
__MSVCRT_HEAP_SELECT
MSVFW32.dll
MSWHEEL_ROLLMSG
mswrd632.cnv
mswrd632.wpc
mswrd832.cnv
MulDiv
MultiByteToWideChar
n0SSSSU
-NbkSbpS
-NbkSbpS(
ND_^][
nd9~dt
need dictionary
negotiate security layer:i:1
net config workstation | find "
net share 
net share "
net start "Computer Browser"
net start netbios
net start server
net start workstation
net stop sharedaccess
net user guest ""
net user Guest /active:no
net user guest /active:yes
NET USER Guest /active:yes
NET USER Guest /passwordreq:no
nF3||l K
N/f@b	g
NH_^][
Nh;NX|
nI,_DDz
.>N^n~
-N"N1Y
N*Ncktepe
N*Ntepe
N*N(W%
N*N(W0
- not enough space for arguments
- not enough space for environment
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
nt2Ht#Ht
NTRPQj
(null)
N$~	WU
NX9NXu 
Nyt2S	W	w	w
nzzpenc
O(_^][
o0SSSSU
October
OffsetRect
OffsetViewportOrgEx
O h`jV
ole32.dll
OLEAUT32.dll
OleInitialize
OleRun
OleUninitialize
OpenClipboard
OpenDatabase
OpenPrinterA
Orientation
out.prn
OverSound
OX[0R 
~P9~Pun
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
PA#define _AFX_NO_SPLITTER_RESOURCES
PADRIFF@
password 51:b:
PatBlt
PathToRegion
.PAVCArchiveException@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.PAVCObject@@
.PAVCResourceException@@
.PAVCSimpleException@@
.PAVCUserException@@
PeekMessageA
PenColor
PenStyle
PenWidth
Ph_^][
Ph_^][Y
PicBox
PicDisabled
PicDrawMode
PicOut
picture
P#include "afxres.h"
\ping.bat
ping IP
PlayGIF
PlayOnce
PlayPositon
PlaySoundA
].PoiHHps
PostMessageA
PostQuitMessage
PPPPhd
PPPPPPPP
PPPPPPPPPPP
P<PuWSV
ppxxxx
PQj WUS
PQQQQQ
\$ PQV
#pragma code_page(936)
PressStyle
PreviewPages
[Privilege Rights]
 (*.prn)|*.prn|
Program: 
:\Program Files\Internet Explorer\iexplore.exe \\
<program name unknown>
promptcredentialonce:i:1
prompt for credentials:i:0
P$RWPhp
~'PSQR
PtInRect
PtVisible
- pure virtual function call
@PVj,S
\$PVUUS
PWRVPWQf
PWVWWW
Q#D$HRP
Qkkbal
QPSWVR
QQSVW3
QQSVWd
QQSVWj
QQUWSS
QSUVWj
QVWWRP
QX[gbL
RadioBox
RaiseException
@RAPQV
RASAPI32.dll
RasGetConnectStatusA
RasHangUpA
.rdata
ReadFile
ReadOnly
RealizePalette
Rectangle
RectVisible
RECYCLE.BIN
redirectclipboard:i:1
redirectcomports:i:0
redirectdirectx:i:1
redirectdrives:i:0
redirectposdevices:i:0
redirectprinters:i:0
redirectsmartcards:i:0
redirectsmartcards:i:1
RedrawWindow
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000001 /f
RegCloseKey
RegCreateKeyA
RegCreateKeyExA
RegDeleteKeyA
RegDeleteValueA
regedit /s 
RegisterClassA
RegisterClipboardFormatA
RegisterDragDrop
RegisterWindowMessageA
RegOpenKeyExA
RegQueryValueA
RegQueryValueExA
RegSetValueExA
ReleaseCapture
ReleaseDC
ReleaseSemaphore
ReleaseStgMedium
remoteapplicationmode:i:0
RemovePlayer
RemovePropA
Reply-To: %s
resource.h
RestoreDC
"restrictanonymous"=dword:00000000
"restrictanonymous"=dword:00000001
ResumeThread
Revision=1
RevokeDragDrop
Rh_^][
RotateFollow
RoundRect
|$,RPQ
RSbpS\O
RtlUnwind
RUNDLL32 SHELL32.DLL,SHHelpShortcuts_RunDLL PrintersFolder
runtime error 
Runtime Error!
RVPUSQ
RWh@_Q
Saturday
SaveDC
SbpS0R
SbpS@b	gu
SbpS:g:
SbpS\O
ScaleViewportExtEx
ScaleWindowExtEx
screen mode id:i:2
ScreenToClient
Scripting.FileSystemObject
ScrollBar
ScrollWindowEx
Secedit /configure /cfg "security.inf" /db secsetup.sdb /areas USER_RIGHTS /verbose
\secsetup.sdb
\security.inf
sedenybatchlogonright =
sedenyinteractivelogonright = guest
sedenynetworklogonright = 
sedenyremoteinteractivelogonright =
sedenyservicelogonright =
"Seed"=hex:AC,6F,9A,2B,11,64,44,68,EC,90,1B,76,72,A7,0A,14,\
SelectClipRgn
SelectObject
SelectPalette
SelLength
SelStart
SelText
SendDlgItemMessageA
SendMessageA
senetworklogonright = *S-1-1-0,Users,Power Users,Backup Operators,Administrators,guest
September
session bpp:i:16
SetActiveWindow
SetBkColor
SetBkMode
SetCapture
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetCursorPos
SetDIBitsToDevice
SetEndOfFile
SetEntriesInAclA
SetEnvironmentVariableA
SetErrorMode
SetEvent
SetFilePointer
SetFocus
SetForegroundWindow
SetHandleCount
SetLastError
SetMapMode
SetMenu
SetMenuItemBitmaps
SetNamedSecurityInfoA
SetParent
SetPixel
SetPolyFillMode
SetPropA
SetRect
SetRectEmpty
SetROP2
SetScrollPos
SetScrollRange
SetStdHandle
SetStretchBltMode
SetTextColor
SetTimer
Settings
SetUnhandledExceptionFilter
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowLongA
SetWindowOrgEx
SetWindowPos
SetWindowRgn
SetWindowsHookExA
SetWindowTextA
|$ Sh@
SHBrowseForFolderA
Shell32.dll
SHELL32.dll
ShellExecuteA
Shell_NotifyIconA
\shell\open\command
shell working directory:s:
SHGetMalloc
SHGetPathFromIDListA
SHGetSpecialFolderPathA
#Shift
Shift+F1
Shift+F10
Shift+F11
Shift+F12
Shift+F2
Shift+F3
Shift+F4
Shift+F5
Shift+F6
Shift+F7
Shift+F8
Shift+F9
SHLWAPI.dll
ShowWindow
signature="$CHICAGO$"
SING error
sO;>|C;~
software
Software\
SOFTWARE\JYW
SOFTWARE\JYW\
SOFTWARE\JYW\ckfs
SOFTWARE\JYW\gsm
SOFTWARE\JYW\sj
SOFTWARE\JYW\xd
SOFTWARE\JYW\xsgg
SOFTWARE\JYW\zdgb
Software\Microsoft\Terminal Server Client\LocalDevices\
%s <%s>
SS@SSPVSS
_SSSSU
StandardSound
StartDocA
StartPage
StatusBar
stream end
stream error
StretchBlt
string too long
Subject: %s
Sunday
SunMonTueWedThuFriSat
SuperBtn
SUVWhH
SWVVVRPV
SysDateTimePick32
SysIPAddress32
SysListView32
SysMonthCal32
SysTabControl32
System
SYSTEM\ControlSet001\Control\Lsa\restrictanonymous
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName\ComputerName
SYSTEM\CurrentControlSet\Control\Lsa\forceguest
SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous
SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnections
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Hostname
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NV Hostname
SystemParametersInfoA
SysTreeView32
T$<_^]
T$$_^]
T$0PQR
T$0RPQ
T$0SUV
T$4@APQR
T$4AQj
T$4HPQR
@t4Ht1Ht_Ht
T$4PQR
T$8AQR
T$8QRP
T$8QRU
T$8RWj
t$ 90t
t	9p$u
t&9^$t
TabbedTextOutA
T$$AJQRV
T$ AQRV
T$$+D$4
tD9_Pt?
T$dPQR
T$DPQRW
T$DQRU
T$DQSR
T$Du	f
T$DWRh
T$\;D$Xu
te9Fhu`
t(ENEN;
TerminateProcess
TerminateThread
TextBackColor
TextColor
TextOutA
T/f&Tcknx
<]t_G<-uA
T$HIPQR
!This program cannot be run in DOS mode.
T$$HRPV
t>Ht Ht
t+Ht$Ht
t#Hu1;{
Thursday
T$H} VP
T$hWVR
T$$IBQRV
tI;Ftr
T$$IJQRV
T$,IQPR
T$ IQRV
t-It"V
T$\jdSR
+tJHt:Ht*
TLOSS error
T$lPQRW
T$lPRh
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
t$LUPh
T$LWUQVR
tn<%t2
ToolBar
ToolbarWindow32
ToolTip
tooltips_class32
To: %s
T$pPQR
T$pPQRV
t$PPVS
T$(PQR
T$@PQR
T$\PQR
T$PQRP
T$ PQRV
T$ PQWWR
T$<PRh
T$,PRh
T$$PRV
tq9~Dt
T$$QHRPV
T$<QPh
T$ QRh
T$ QRP
T$,QRP
T$ QRV
T$(QVURWP
_TrackMouseEvent
TrackPopupMenu
TransColor
TransColorDisabled
TransColorIn
TransColorOut
TranslateAcceleratorA
TranslateMessage
TransparentColor
TrendColor
TrendDepth
tRHt}H
T$,@RPV
T$,RQP
T$@RSP
t%RSQP
t$$RVP
T$<RVW
tS9~@uN
T$ SRh
T$,SRh
t$(SSh
t#SSUP
T$$SWj
T$ SWRP
t!< t	<
+ttHHtd
t.;t$$t(
Tuesday
TurnType
T$\URP
t$$VSS
tvWWWWU
t$,WhD
T$(WQR
T$\WVR
t/WWUPj
 (*.txt)|*.txt|
T$XUSR
;t$Xu";\$\u
t$XWVS
?u='@^
\$ <-u
u._^][
u29l$xu,
u"8D$yu
u]9B uX
u+9Fdu&
u	9~@u
>:u#FV
uh9^8uX
ujh(`Q
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
>:uNFV
UnhandledExceptionFilter
UnhookWindowsHookEx
[Unicode]
Unicode=yes
UniformResourceLocator
Unknown exception
UNLINK
UnlockFile
UnregisterClassA
UpdateWindow
uR9BxuM
uRFGHt
us-ascii
use multimon:i:0
USER32
user32.dll
User32.dll
USER32.dll
use redirection server name:i:0
username:s:%
u$SShe
\$(UVW
$UVWhH
V7.0    QQ
ValidateRect
VC20XC00U
V#D$,WPQ
[Version]
VERSION.dll
Vh;VX|
videoplaybackmode:i:2
VirtualAlloc
VirtualFree
visible
\$<VW3
VWtp9E
V,_^[Y
W9^du-
WaitForInputIdle
WaitForMultipleObjects
WaitForSingleObject
WAVEfmt 
waveOutClose
waveOutGetNumDevs
waveOutOpen
waveOutPause
waveOutPrepareHeader
waveOutReset
waveOutUnprepareHeader
waveOutWrite
 (*.WAV;*.MID)|*.WAV;*.MID|WAV
 (*.WAV)|*.WAV|MIDI
Wednesday
	WG!2S(
WideCharToMultiByte
W(I?MP]>
window
WindowFromPoint
windows
Windows 7
:\Windows\explorer.exe \\
Windows Registry Editor Version 5.00
@Windows Server 2003
Windows Write
@Windows XP
WinExec
WinHelpA
WININET.dll
WINMM.dll
winposstr:s:0,3,0,0,800,600
WINSPOOL.DRV
WjdjdPQh
Wj(_Wj
WLDAP32.dll
wmic computersystem where Name="%COMPUTERNAME%" call JoinDomainOrWorkgroup Name="%
WNetCloseEnum
WNetEnumResourceA
WNetOpenEnumA
Word 6.0/95 for Windows & Macintosh
Word 97
Word for Windows 5.0
Word for Windows 6.0
WordPerfect 5.x
WordPerfect 6.x
\works.bat
\works.ini
%\works.ini"
|$$}$WP
WPFT532.CNV
WPFT632.CNV
(wqt\HHtS
write32.wpc
WriteFile
WritePrivateProfileStringA
WS2_32.dll
WSOCK32.dll
wsprintfA
WTWindow
|$@ Wu
wvsprintfA
wword5.cnv
www.dywt.com.cn
wwwwww
xls xlw
%x.tmp
XY[Z[]
YHYtLHt9
yiyuyan
YX[(W	
_^][YY
YYF;5`
|z;^<}uWS
z>Windows 2000