`.rdata
@.data
@.reloc
Bgu_idata
@gu_rsrcs
e!V@hP
kscdS
P3tepP}h
2ce*Vx
srtWd@@
up2=cc
2mtst<0
(mt+lo`
Pt|WPPW
+Epi d@
ctc|uuB
j8hDPP
GGGGBBBBIu
$urn"PhP
P =dO#h
leeeI#
terekos
Romantic
last.inf
static
button
#VErTir
KERNEL32.DLL
gdi32.dll
user32.dll
GetLastError
lstrcpyA
GetModuleHandleA
GetCommandLineA
FindFirstFileA
FormatMessageA
FindClose
FindNextFileA
DeleteFileA
CloseHandle
GetACP
CreateFileA
CreateFontIndirectA
PostQuitMessage
GetMessageA
UpdateWindow
EndPaint
DispatchMessageA
BeginPaint
TranslateMessage
MoveWindow
CreateWindowExA
RegisterClassExA
DefWindowProcA
MessageBoxA
SendMessageA
DestroyWindow
LoadCursorA
LoadIconA
ShowWindow
GetWindowRect
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
!This program cannot be run in DOS mode.
`.text
.rdata
@.data
.rdata6
@.rdata4
@.rdata3
@.rdata2
@.rsrc
IDR_VERSION1
IDR_VERSION1
VS_VERSION_INFO
FileInfo
FFFF04E3
FileVersion
2.0.1.7
ProductVersion
2.0.1.0
CompanyName
Sanny Ltd.
ProductName
LookFor
VFileInfo
Translation
C:\Users\jbayuelo\AppData\Local\Temp\Rar$EX00.060\Invoice_OCT-02-2013.exe
C:\15f7b84a4cdcb502eddc657a73efa574e92ce8ee6c1cbd294afb78ee68b340af
C:\jdQTw6v9.exe
C:\Siclio3q.exe
C:\kkUFLuby.exe
C:\DpAAKV4u.exe
C:\xzs9WiJw.exe
C:\lm6cf0Bd.exe
C:\rAPOijgM.exe
C:\LPtzEtau.exe
C:\c3d3ff14f95b3a8f7716d18c2004989d431d9dfe21cf368e90d6998e37400d8d
C:\n0SdZlzy.exe
C:\hngGcoa0.exe
C:\ttTgXtca.exe
C:\61qAQjKW.exe
C:\dff2be9238bb5e024266085cf4deed3c3c9a6f618be1f72d5c6dd0b7f8eda3c2
C:\b50064ea3ee91286fe33c2fe0625e5778f3feeeac507d1e9883b7ff2903de6c7
C:\0YDYVX8K.exe
C:\MPmfnspF.exe
C:\nce7c9Hg.exe
C:\Hzn2wLxp.exe
C:\LSsCVy8I.exe
C:\gwOEU6Zz.exe
C:\WQjMyCWV.exe
C:\_oZ1X5Vb.exe
C:\Dj9GDsJS.exe
C:\Cdp9kFOq.exe
C:\UOGoyJ1r.exe
C:\9np_0zpF.exe
C:\rALh_5o6.exe
C:\xVfmqVpE.exe
C:\MjDNbuuX.exe
C:\FWgNM5kV.exe
C:\4MIGwjOZ.exe
C:\2e95b12a09ec8d49d8ef217225a5e19a3b31fe196e7a679668c46e47ab205ea7
C:\F413poNv.exe
C:\xawp_iqF.exe
C:\VIFTaBYp.exe
C:\IUCGdQtr.exe
C:\t6mpWZnU.exe
C:\3Ljl2OEJ.exe
C:\ZRo184ai.exe
C:\hvm8EcBI.exe
C:\N6uHVNRU.exe
C:\e9a2bf87151b236b82b4f886e055e509fca3c301451e7d53b6feb884260e4544
C:\N0j4QrB2.exe
C:\FBJHmotD.exe
C:\xaHyOIuE.exe
C:\ca_rKaDC.exe
C:\hNbpTMVL.exe
C:\bGnmop1x.exe
C:\DOCUME~1\cuckoo\LOCALS~1\Temp\afd0df96070c049838043823c05645fab21c43b5
C:\Users\RDhJ0CNFevzX\Desktop\d1e1a6647481c6fca13f348df95803810d136887f2afa3be295b1183987382ee.exe
C:\QeSIb3IC.exe
C:\Users\Bruno\AppData\Local\Temp\file.exe
C:\Users\OqXZRaykm\Desktop\asih.exe
C:\eD98mxiJ.exe
C:\Users\george\Desktop\software.exe
C:\7L1yTkZ5.exe
C:\Users\azure\Downloads\223fcea12d071689ed6c5b27975235a8.exe
C:\Users\OqXZRaykm\Desktop\922ef29779530fbe47fa5553d88d144ed6610ca4270aab73d0937d8dcce23787-dropped.exe
C:\Users\Admin\AppData\Local\Temp\3e62b69d5042e32030ed3a65cf77252a3c5500527f7581569cf20afacce33e2f.exe
C:\Users\Bruno\AppData\Local\Temp\program.exe
C:\6SvPcr0T.exe
C:\Users\Admin\AppData\Local\Temp\afc05795a3e5fe2af2503fd6615698d601ec0075b142de9563e124ba4e723c9f.exe
C:\Users\george\Desktop\software.exe
C:\Users\OqXZRaykm\Desktop\asih.exe
C:\Users\Joe Cage\Desktop\6ghch2kc2n.exe
C:\Users\Admin\AppData\Local\Temp\f5708ddf942d2f6d5c9b715296eefee4d67540426860cb873024b3cbad109af9.exe
C:\Fsv0Jteu.exe
C:\Users\azure\Downloads\aa23e4452fd4e6f7c06d21ca4f36410d.virus.exe
C:\9GPMqB8T.exe
C:\Users\george\Desktop\file.exe
C:\gCX1VKB0.exe
C:\Users\george\Desktop\program.exe
C:\XzUdBXO3.exe
C:\Users\george\Desktop\software.exe
C:\wqyEJZep.exe
C:\Users\RDhJ0CNFevzX\Desktop\hINRbc44UZAUO8gP.exe
C:\Users\Bruno\Desktop\executable.exe
C:\khMo2u0e.exe
C:\Users\george\Desktop\software.exe
C:\Users\RDhJ0CNFevzX\Desktop\GdhvewPT6XADldiY.exe
C:\Users\RDhJ0CNFevzX\Desktop\sfZZHL0c3lz0vnqY.exe
C:\RmIdGulJ.exe
C:\Users\Admin\AppData\Local\Temp\eb61c5c52c68d45a131d86374e3a468a90a400d889240bf4118e708659852672.exe
C:\Users\george\Desktop\executable.exe
C:\zarOO4Xp.exe
C:\Users\Bruno\Desktop\file.exe
C:\Users\Admin\AppData\Local\Temp\611637ed02347c274932243f103134874717b06508c832fa88d92f9d5f245dd3.exe
C:\Users\OqXZRaykm\Desktop\KJlLgO0amPvLmCUd.exe
C:\Users\Bruno\Desktop\software.exe
C:\Users\John Doe\Desktop\owdvfw72ia.exe
C:\g9NxIPe_.exe
C:\HWzObajY.exe
C:\Users\azure\Downloads\07f81eb0c3752edc768e78c63fbe435c.exe
C:\Users\Admin\AppData\Local\Temp\11d3505905ad5958d7f5c32841d0ad8cad2d548ed4ab2ec3fd1601b8271c85b0.exe
C:\Users\azure\Downloads\50c19269b7a1c75b28f1bdb10bfb303d6316617bc2321db9493b1226966d803d.exe
C:\nR6ZVPZP.exe
C:\Users\azure\Downloads\fae109dd5af72b7472657e58df8d7e1a3d7be38f9ccc8204f4de299104eaaec2.exe
C:\ELsIp9Zl.exe
C:\Users\azure\Downloads\576f037e073c9f6998a616b83418af1edd119eee010daa582d1b74652097297e.exe
C:\Users\John Doe\Desktop\9m4ktisj9k.exe
C:\Users\azure\Downloads\23ef70fcc55f19bd5ff09fe5e4ae5d79e477fe0da513a776d7ecfadc60df6556.exe
C:\knF74RuM.exe
C:\Users\azure\Downloads\5f89cced54924eb965a7917fa49af028782ee4ebb5f549cfb485a947f8d58c51.exe
C:\Users\John Doe\Desktop\pwghgp1gi4.exe
C:\Users\Bruno\Desktop\software.exe
C:\Users\John Doe\Desktop\o9u0l0g49m.exe
C:\gSiFz7aU.exe
C:\Users\John Doe\Desktop\58eyide5e1.exe
C:\Users\Bruno\Desktop\software.exe
C:\OfA31_Ke.exe