Microsoft C/C++ program database 2.00 JG9X0܀|5` j T u  .. %%A '' /6; j; KK( 8G( LL@ GI ;> ?B f $$  ## CF> (( 79 ,, -- ** && ZY  !'# %T] ')7 * +f /JS1@N1@N11JuLJ _1<<<<<lw,02?/names/ncb/targetinfo/ncb/moduleinfo/ncb/storeinfo/ncb/iinstdefs/ncb/module/C:\emtry-point-test\virus3a\pefile.cpp/ncb/target/virus2 - Win32 Release/ncb/target/virus2 - Win32 Debug/ncb/versioninfo/ncb/module/C:\emtry-point-test\virus3a.neu\pefile.cpp/ncb/module/C:\emtry-point-test\Kopie (2) von virus3a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus4a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5b.neu\pefile.cpp"' E I6 x ;kp <_if @39JS1@N1@N11Ju<L<J << _< AMb1<<<<<<lwXWX.Xx^^d Xh x<\\,)+./' !` j - T u  00 ''A )) 18; }; MM( KZ( NN@ IK =@ AD f && @ %% EH> ** 9; ..L // ,, (( \ "Y # %:' )gp +'@-7 . /f 3JS1@N1@N11JuLJ < _1<<<<<lw` j - T u  00 ''A )) 18; ; OO( PP( hw@ KM ?B CF f) &&  %% 99 GJ> **e  ;= .. // ,, (( ^r! # 'Y (/* ,Wgp 2H* 46 8Z :;E7 ;sx <gqf @39JS1@N1@N11JuL<J << _< p|1<<<<<<lwngM\- 6  T uF  88 //A 11 9@; ;, ll(; (- mm@ SU GJ5 KN f ..  --  Z]- _b AA ORa df> 22 XXr  CE 665 !77 "44- #00 ${ % ' (YY)r *$ .Y /[ 13g 9& ; =? Aq{7 B*/ C(f G_eJS1@N1@N11Ju @mL<J <<<< _< p|1<<<<<<lw` j - 6  T u  44* ++A --a 5<; ; hh( ( ii@ OQ CF GJ f **  )) r VY- [^ == KNa `b> .. TT  ?A 22 !33 "00 #,,) $wf%[ ' (UU)e *  .Y /Ve 1|3g 9, ;a =? Alv7 B#(p C!f GZ`JS1@N1@N11Ju @mL<J <<<< _< p|1<<<<<<lw1?%/!@@ @ A1?-'3!@@ @ A@p? \- 6  T u  44 ++A -- 5<; ; hh(; ( ii@ OQ CF GJ f ** r )) r VY- [^, ==5 KNa `b>& .. TT  ?A- 22 !33 "00 #,, $w% ' (UU5) * $ .Y /W- 1} 3g 9 ; =? Amw7 B$) C"f G[aJS1@N1@N11Ju @mL<J <<<< _< p|1<<<<<<lw-a7>f-^T?7 0*@$` Ϧ'6 YjΦA(H(3Xutf(٦-H٦%7h^h٦M@૧gP?_0 >-`?(-800hfh-^;谢aTp?!)    (0##%*2$$&+3 "'.-%/!@@ @ A1?%/!@@ @ A1?-'3!@@ @ A@p?6,@!@@ @ A@v(?6 4G   "P ?? 6 4G   "P  ?efdeint posCREATETHREADHANDLE (__stdcall *%)(LPSECURITY_ATTRIBUTES,SIZE_T,LPTHREAD_START_ROUTINE,LPVOID,DWO` j T u  .. %%A^ ''* /6; j; KK( 8G( LL@ GI ;> ?Bp ^fr $$  ## CF>[ (( 79 ,, -- ** &&f ZYe  !'# %T] '))7 * +f /JS1@N1@N11JuLJ _1<<<<<lw';(AY@gf  -a7>f-^T?7 0*@$` xp6 8YXjAȪ(誦蟦(Hhufȫ-諦7(Hhͦ@ͦ8ͦgXͦpͦͦ ͦ>ͦͦͦΦ(ΦHΦhΦfΦ-Φ;ΦaΦTΦϦ0ϦPϦpϦ''!))     (00##%*22$$&+33 "'..%%""$)11#**$$ ((   !!$,,         ""!%--6 4G   "P ?? 6 4G   "P Q?ef` j - 6 F T u 5 99 00A 22 :A; ; mm( (- nn@ TV HK LO& f // 5 ..  [^-; `c BB, PSa$ eg> 33 YY  DF 77 !88 "55 #11 $|% ' (ZZ) * .Y /\ 1r3g- 9 ;r =? Ar|7 B+0 C)f G`fJS1@N1@N11Ju @mL<J <<<< _< p|1<<<<<<lw1?\!@@ @ A1?%/!@@ @ A1?T(  #f$`f> %/!@@ @ A1?%/!@@ @ A1?-'3!@@ @ A@p?6,@!@@ @ A@P$?  ##$$%/!@@ @ A1?%/!@@ @ A1?-'3!@@ @ A@p?6,@!@@ @ A@v(?6 4G   "P ?? 6 4G   "P Q?ef   ##%*;(AY@gf  -a7>f-^T?7 0*@$`Ϧ ͦxӣ6 hYjA(PϦͦpϦuXЦfX@Φ-ͦ7Цx(X@`ͦgxΦΦ 0E>Φ@8ЦPʣͦfͦ-ͦ;8aϦTϦϦ ΦϦ''!))     (00##%*22-%/!@@ @ A1?%/!@@ @ A1?-'3!@@ @ A@p?6,@!@@ @ A@v(?6 4G   "P ?? 6 4G   "P  ?efdeint posCREATETHREADHANDLE (__stdcall *%)(LPSECURITY_ATTRIBUTES,SIZE_T,LPTHREAD_START_ROUTINE,LPVOID,DWO ;(AY@gf  -a7>f-^T?7 0*@$` ؞6 YjA(88Xxͦu ͦf@ͦ`ͦ-ͦͦ7ͦͦͦΦ@ Φ@Φg`ΦxΦΦ Φ>ΦΦϦϦ0ϦPϦpϦfϦ-Ϧ;ϦaϦTϦЦ8ЦXЦxЦ''!))     (00##%*22';(AY@gf  -a7>f-^T?7 0*@$`(f 6 YjAx(༦ ȱP80u`f @-Kɤ7 @cgx8 ɤ>X}ɤP|XfXA-;aɤTHfhp''!))     (00##%*22 virus2 - Win32 Releasevirus2 - Win32 DebugC:\emtry-point-test\virus3a\pefile.cppfDirWalkvoidchar *_currentSETCURRENTDIRECTORYBOOL (__stdcall *%)(LPCTSTR)GetCURRENTDWORD (__stdcall *%)(DWORD,LPTSTR)UNMAPVIEWOFFILEBOOL (__stdcall *%)(LPCVOID)CalcBaseULONGmainintFINDCLOSEBOOL (__stdcall *%)(HANDLE)GETCOMMANDLINELPTSTR (__stdcall *%)(void)infectchar *NameOfFileFINDFIRSTFILEHANDLE (__stdcall *%)(LPCTSTR,LPWIN32_FIND_DATA)FindFileDWORDLPVOID lpParamFINDNEXTFILEBOOL (__stdcall *%)(HANDLE,LPWIN32_FIND_DATA)CREATEFILEMAPPINGvoid *(__stdcall *%)(HANDLE,LPSECURITY_ATTRIBUTES,DWORD,DWORD,DWORD,LPCTSTR)SETFILEPOINTERDWORD (__stdcall *%)(HANDLE,LONG,PLONG,DWORD)CREATEFILEvoid *(__stdcall *%)(LPCTSTR,DWORD,DWORD,LPSECURITY_ATTRIBUTES,DWORD,DWORD,HANDLE)CalcULONG APInameULONG baseentrychar *pADDRDWORD addrunsigned char *codeint posCREATETHREADHANDLE (__stdcall *%)(LPSECURITY_ATTRIBUTES,SIZE_T,LPTHREAD_START_ROUTINE,LPVOID,DWO$$&+33 "'..%%""$)11#**$$ ((   !!$,,         ""!%--I6 x  "P ?? 6 4G   "P $?efdeint posCREATETHREADHANDLE (__stdcall *%)(LPSECURITY_ATTRIBUTES,SIZE_T,LPTHREAD_START_ROUTINE,LPVOID,DWORD,LPDWORD)SETENDOFFILEGETFILESIZEDWORD (__stdcall *%)(HANDLE,LPDWORD)MAPVIEWOFFILELPVOID (__stdcall *%)(HANDLE,DWORD,DWORD,DWORD,SIZE_T)CLOSEHANDLEViewOfFileBOOL (__stdcall *%)(LPCVOID,SIZE_T)beginhashchar *strmymainC:\Programme\Microsoft Visual Studio\Common\MSDev98\Bin\win32.ncbC:\Programme\Microsoft Visual Studio\Common\MSDev98\Bin\crt.ncbC:\Programme\Microsoft Visual Studio\Common\MSDev98\Bin\mfcatl.ncbC:\emtry-point-test\virus3a.neu\pefile.cppC:\emtry-point-test\Kopie (2) von virus3a.neu\pefile.cppencint bint lunsigned char *start<.h>C:\Codes\emtry-point-test\virus4a.neu\pefile.cppgenerateDWORD startunsigned char *arrayunsigned char *newarraylangunsigned char bberandomint tillGETTICKCOUNTDWORD (__stdcall *%)(void)RandomC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\win32.ncbC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\crt.ncbC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\mfcatl.ncbanzahlrtemp2tempsizeC:\Codes\em 藼.(d8 HXhx <\\*)+./' !@$` p6 YjhA૦(@ Φ`upϦf0Ϧ@ͦ-``ͦͦ7ͦͦͦ@Ϧ Φg@ΦXΦxΦ Φ>ΦΦ`Φ ϦPϦfϦ-Ϧ;8ЦaϦTϦЦXЦ''!))     (00##%*22,02?/names/ncb/targetinfo/ncb/moduleinfo/ncb/storeinfo/ncb/iinstdefs/ncb/module/C:\emtry-point-test\virus3a\pefile.cpp/ncb/target/virus2 - Win32 Release/ncb/target/virus2 - Win32 Debug/ncb/versioninfo/ncb/module/C:\emtry-point-test\virus3a.neu\pefile.cpp/ncb/module/C:\emtry-point-test\Kopie (2) von virus3a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus4a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5b.neu\pefile.cpp"' E I6 x WORD,DWORD,LPCTSTR)SETFILEPOINTERDWORD (__stdcall *%)(HANDLE,LONG,PLONG,DWORD)CREATEFILEvoid *(__stdcall *%)(LPCTSTR,DWORD,DWORD,LPSECURITY_ATTRIBUTES,DWORD,DWORD,HANDLE)CalcULONG APInameULONG baseentrychar *pADDRDWORD addrunsigned char *codeint posCREATETHREADHANDLE (__stdcall *%)(LPSECURITY_ATTRIBUTES,SIZE_T,LPTHREAD_START_ROUTINE,LPVOID,DWOtry-point-test\virus5a.neu\pefile.cppdownloadchar *URLGETSystemDirectoryUINT (__stdcall *%)(LPTSTR,UINT)LOADLibraryHMODULE (__stdcall *%)(LPCTSTR)callvoid (__stdcall *%)(void)MYPROCHRESULT (__stdcall *%)(LPUNKNOWN,LPCTSTR,LPCTSTR,DWORD,LPBINDSTATUSCALLBACK)GETProcAddressFARPROC (__stdcall *%)(HMODULE,LPCSTR)AGetSystemDirectoryUINT (__cdecl *%)(LPTSTR,UINT)aHINSTANCEdllint %[2]AURLDownloadToFileHRESULT (__cdecl *%)(LPUNKNOWN,LPCTSTR,LPCTSTR,DWORD,LPBINDSTATUSCALLBACK)pathchar %[MAX_PATH]functionAGetProcAddressFARPROC (__cdecl *%)(HMODULE,LPCSTR)KernelBaseCALLvoid (__cdecl *%)(void)ALoadLibraryHMODULE (__cdecl *%)(LPCTSTR)urlmonint %[3]xxC:\Codes\emtry-point-test\virus5b.neu\pefile.cppSA mft  @(J>   T -u@? 6t 7 (Lp|  g <wYu \;l # A gN_6 fa @--v J E`1O U jXWX.Xx^^d Xh x<\\-)+./%&"(*#$, !RESULT (__stdcall *%)(LPUNKNOWN,LPCTSTR,LPCTSTR,DWORD,LPBINDSTATUSCALLBACK)GETProcAddressFARPROC (__stdcall *%)(HMODULE,LPCSTR)AGetSystemDirectoryUINT (__cdecl *%)(LPTSTR,UINT)aHINSTANCEdllint %[2]AURLDownloadToFileHRESULT (__cdecl *%)(LPUNKNOWN,LPCTSTR,LPCTSTR,DWORD,LPBINDSTATUSCALLBACK)pathchar %[MAX_PATH]functionAGetProcAddressFARPROC (__cdecl *%)(HMODULE,LPCSTR)KernelBaseCALLvoid (__cdecl *%)(void)ALoadLibraryHMODULE (__cdecl *%)(LPCTSTR)urlmonint %[3]xxSA mft  @(J>   T -u@? ,02?/names/ncb/targetinfo/ncb/moduleinfo/ncb/storeinfo/ncb/iinstdefs/ncb/module/C:\emtry-point-test\virus3a\pefile.cpp/ncb/target/virus2 - Win32 Release/ncb/target/virus2 - Win32 Debug/ncb/versioninfo/ncb/module/C:\emtry-point-test\virus3a.neu\pefile.cpp/ncb/module/C:\emtry-point-test\Kopie (2) von virus3a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus4a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5b.neu\pefile.cpp"' E I6 x X.(d8 HXhx <\\1)+./%&"(-#$0 !Win32 Debug/ncb/versioninfo/ncb/module/C:\emtry-point-test\virus3a.neu\pefile.cpp/ncb/module/C:\emtry-point-test\Kopie (2) von virus3a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus4a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5a.neu\pefile.cpp/ncb/module/C:\Codes\emtry-point-test\virus5b.neu\pefile.cpp"' E I6 x . d0 @P`p <\\S2)+./#$ %&!"(