Aerosol Posted February 21, 2015 Report Posted February 21, 2015 Sample of the Babar malware discovered by NSA. It is believed to originate from French intelligence.More info:http://www.spiegel.de/media/media-35683.pdfCyphort » Blog Archive Babar: Suspected Nation State Spyware In The Spotlight - Cyphortyara rules: [YARA] Barbar/SNOWGLOBE Rules - Pastebin.combabar.exe Strings:!This program cannot be run in DOS mode.`.rdata@.dataQVVVWVVSVPSSSSSShPSSSSSSSj^tLHt-HuuS9F`u%VQQSVWd<\tM</tIHtHu4js[S;7|G;wtR99u20A@@Ju0SSSSSHHtXHHt>If90t0WWWWWj@j ^V<at9<rt,<wtURPQQhl>=Yt1ju[SSSPt"SS9];t$,v-UQPXY]Y[0SSSSS0SSSSSPPPPPPPPPPPPPPPP^SSSSSj"^SSSSStGHt.Ht&^SSSSS8VVVVV>:u8FVVVVVVQRSSjt+WWVPV/u /i:-"/c start /wait1000 && delComSpeccmd.exeDLLPATHD:(D;OICI;FA;;;AN)(A;OICI;FA;;;BG)(A;OICI;FA;;;SY)(A;OICI;FA;;;LS)(A;OICI;FA;;;AU)(A;OICI;FA;;;BA)advapi32.dllCommonProgramFilesALLUSERSPROFILECOMMON_APPDATAWINDIRUSERPROFILEAPPDATAkernel32.dllShell32.dllkernel32IsWow64ProcessEnableLUASOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\%%%s%%/s /n %s "%s"%%WINDIR%%\%s\%sregsvr32.exeSystem32SysWOW64Wow64RevertWow64FsRedirectionWow64DisableWow64FsRedirection%COMMON_APPDATA%=j&&LZ66lA??~}{))R>f""D~**TV22dN::to%%Jr..\$&&Lj66lZ??~A99rKJJ==zGdd""Df**T~;22dV::tN$$Hl\\C77nYmm%%Jo..\r>!KK55j_WW&Lj&6lZ6?~A?~=zG=d"Df"*T~*2dV2:tN:x%Jo%.\r.t>!Ka5j_5WggV}++Lj&&lZ66~A??bS11*?Xt,,4.RRvM;;MMfU33PPxD<<%Bc!! 0~~zG==Df""T~**;dV22tN::xxJo%%\r..8$tt>!pp|B>>qaaj_55UUPx((cccc||||wwww{{{{kkkkoooogggg++++YYYYGGGG&&&&6666????nnnnZZZZRRRR;;;;[[[[jjjj9999JJJJLLLLXXXXCCCCMMMM3333PPPP<<<<~~~~====dddd]]]]ssss````""""****2222::::$$$$\\\\7777mmmmllllVVVVeeeezzzzxxxx%%%%....ttttKKKKpppp>>>>ffffHHHHaaaa5555WWWWUUUU((((BBBBhhhhAAAA='9-6d_jbF~T11#?*0,4$8_@t\lHBWQPeA~S>4$8,@p\lHtW+HpXhET[$:.600006666CCCCDDDDTTTT{{{{####====ffff((((vvvv[[[[IIIImmmm%%%%rrrr]]]]eeeellllppppHHHHPPPPFFFFWWWWkkkk::::AAAAOOOOggggtttt""""nnnnGGGGVVVV>>>>KKKKyyyyYYYY''''____````QQQQ;;;;MMMMccccUUUU!!!!bad allocationUnknown exceptionbad exceptionEncodePointerDecodePointerFlsFreeFlsSetValueFlsGetValueFlsAllocruntime errorTLOSS errorSING errorDOMAIN errorAn application has made an attempt to load the C runtime library incorrectly.Please contact the application's support team for more information.- Attempt to use MSIL code from this assembly during native code initializationThis indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.- not enough space for locale information- Attempt to initialize the CRT more than once.This indicates a bug in your application.- CRT not initialized- unable to initialize heap- not enough space for lowio initialization- not enough space for stdio initialization- pure virtual function call- not enough space for _onexit/atexit table- unable to open console device- unexpected heap error- unexpected multithread lock error- not enough space for thread dataThis application has requested the Runtime to terminate it in an unusual way.Please contact the application's support team for more information.- not enough space for environment- not enough space for arguments- floating point support not loadedMicrosoft Visual C++ Runtime Library<program name unknown>Runtime Error!Program: !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~CorExitProcess(null)`h````xpxxxxUTF-16LEUNICODEComplete Object Locator'Class Hierarchy Descriptor'Base Class Array'Base Class Descriptor at (Type Descriptor'`local static thread guard'`managed vector copy constructor iterator'`vector vbase copy constructor iterator'`vector copy constructor iterator'`dynamic atexit destructor for '`dynamic initializer for '`eh vector vbase copy constructor iterator'`eh vector copy constructor iterator'`managed vector destructor iterator'`managed vector constructor iterator'`placement delete[] closure'`placement delete closure'`omni callsig'delete[]new[]`local vftable constructor closure'`local vftable'`udt returning'`copy constructor closure'`eh vector vbase constructor iterator'`eh vector destructor iterator'`eh vector constructor iterator'`virtual displacement map'`vector vbase constructor iterator'`vector destructor iterator'`vector constructor iterator'`scalar deleting destructor'`default constructor closure'`vector deleting destructor'`vbase destructor'`string'`local static guard'`typeof'`vcall'`vbtable'`vftable'operatordelete__unaligned__restrict__ptr64__clrcall__fastcall__thiscall__stdcall__pascal__cdecl__based(GetProcessWindowStationGetUserObjectInformationAGetLastActivePopupGetActiveWindowMessageBoxAUSER32.DLL !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~HH:mm:ssdddd, MMMM dd, yyyyMM/dd/yyDecemberNovemberOctoberSeptemberAugustFebruaryJanuarySaturdayFridayThursdayWednesdayTuesdayMondaySundaySunMonTueWedThuFriSatJanFebMarAprMayJunJulAugSepOctNovDecCONOUT$`h`hhhxppwppRSDSa2c:\Documents and Settings\admin\Desktop\Babar64\Babar64\obj\DllWrapper Release\Release.pdbDeleteFileAGetModuleFileNameAGetEnvironmentVariableAlstrcatAlstrcpyAGetShortPathNameALocalFreeCloseHandleLoadLibraryAFreeLibraryLockResourceSizeofResourceLoadResourceFindResourceAKERNEL32.dllGetProcAddressGetModuleHandleAGetCurrentProcessWaitForSingleObjectGetStartupInfoARtlUnwindGetSystemTimeAsFileTimeGetCommandLineAGetLastErrorFindCloseFileTimeToSystemTimeFileTimeToLocalFileTimeGetDriveTypeAFindFirstFileATerminateProcessUnhandledExceptionFilterSetUnhandledExceptionFilterIsDebuggerPresentHeapFreeHeapAllocRaiseExceptionGetModuleHandleWTlsGetValueTlsAllocTlsSetValueTlsFreeInterlockedIncrementSetLastErrorGetCurrentThreadIdInterlockedDecrementWriteFileGetStdHandleGetCPInfoGetACPGetOEMCPIsValidCodePageWideCharToMultiByteExitProcessDeleteCriticalSectionLeaveCriticalSectionEnterCriticalSectionMultiByteToWideCharReadFileSetHandleCountGetFileTypeSetFilePointerFreeEnvironmentStringsAGetEnvironmentStringsFreeEnvironmentStringsWGetEnvironmentStringsWHeapCreateVirtualFreeQueryPerformanceCounterGetTickCountGetCurrentProcessIdGetFullPathNameAGetCurrentDirectoryALCMapStringALCMapStringWHeapSizeVirtualAllocHeapReAllocGetLocaleInfoAGetStringTypeAGetStringTypeWCompareStringACompareStringWSetEnvironmentVariableAInitializeCriticalSectionAndSpinCountGetConsoleCPGetConsoleModeSetStdHandleFlushFileBuffersCreateFileAGetTimeZoneInformationWriteConsoleAGetConsoleOutputCPWriteConsoleWSetEndOfFileGetProcessHeapFreeSidCheckTokenMembershipRegCloseKeyRegQueryValueExARegCreateKeyExARegOpenKeyExAADVAPI32.dll.?AVAutoPathHelper@@.?AVIAutoPath@@.?AVCImportSddl@@.?AVCAbstractImport@@.?AVbad_alloc@std@@.?AVexception@std@@.?AVtype_info@@.?AVbad_exception@std@@abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZom]+F`7TH,H{1DL>[l:#;5d2=U|%F'v#bN<st(aXp|Na9:tX/gk=hsH(~XLARFP<[s'Na5hS~9p8aqUpIe2F!ih,:xp2s.z95X"K5;oR/jxaTv(Bw_]@E&7\yvVo}1MBd#$=<jQCJ-0[|.1Ln{e.*6baFC5&.<_QR?.:@AiXmaAR)sDmGS>,Jy]4C`JB5DuH\zB*67uxRgNU$=oA?]Ci<}N]G&b(HGJ<{5RJ_N[+H{CF0qwLgb>wbYY8L~}R<VRYb!\*sQ#9\PygEc~mcMtmh4at`.a7?{H[mN]|I1hC:csc,c?o0>3&OlS9\fu/OU{Wa)8D@49`F&Hh74Z@I?,$>]<~6F7{I||I|i4@,K<Yoz,%>t7zG.+aaR:kqF*vK/Y\[4'-]hAX#xoFP,7'x*7kE2.9 -5,2ZRse`Wgx'Z$p9&ze;@n\F4~[&sVo$R+@%csxA@q5a&M MMBCU0;|]sI$Ufg?]IBADa0e)3 p[EC1iF4tfWg1B+:a5['n!Dol$'iHJu&pf;#[B`t#.Ue&N1/Il`C$e$NH0tgUr9L!.nbLS0txP(<L|"`A/2QVo`9!vzVma+K>WwsLPD'ezQ|0IgEp{q!"9v~l(XB.U8Z@{iq=fK8z0!$/b?)*>.<xb1c4ap$)c82q7^R*aa;On~T^[}Rg+#wdxO|Y<H779UjZ|Wmvgu3Z?@;Y[mHjhR%&Bvz~q5EpLPEQ418DVi6}4Hj,;2;(#5w|=p{-fanwdF,F6Ec|S@=qT,Mz#.E Y)FutG`)p|69z!Z{.V>nV-+1(|$Cx4\v9%H#],9@7SD1&_l<<W/rlE R:!FY?F*&f/0#n]e~%JT5gHS ((7`79l#fO4$gFMN1/9ba7f)+dEzSSt:%H~8Beh*w^e:p&7.^j\l}4/WdUl]]]Vec4\]WjL-at.6*CVr__q6|lYN`h6VwJ+/B!NI$spJ-^c9k}$a)_+,kyEsz*Kw,FkS=#yjQ\nh9gy^rX9"=I)`Y4>a-t8-E242/OLCrn#]ZNBNo5O({xp|S,K4y=v*zK;\|<^h1syS,fEn=_O@ZqW+rEVHm]z5g(NF!K\+%aH<`P65%}sfihgzYQ*i{P9GhC+E'r0@!ux!l"[-<]]mI:yG <M*=yW@f:1bAhh*k~aAw[qq4i`p8]4|kLeXf>Trs@":;CsyQ;J0OL^(J<1^vyM]}OZV?;;d7gn/M_1r|#U_I_~eI.zdBr_kmi)w<7`rl|f%q/i|T$KBmy5>n-lyV>=NHceu}Ut<K[7DSJ.)"wY-K$4o5dAf4[yTVVZo!IF\tzQ:Dd>0_Qtul_""MAV'rS8x,MB:f$S&~wV8Se@(,R8s,FBw%oO{l^ni{)s9s>,3B^yMQmIFSn]NTgbX>*aZgsKZzKQmvXIn`oH`3TjyG6ln7b-A<%NN{`QXPyN~-VRtnvAg4cW{htxgkdtG6fq,L]RIX*d@oaaE!7A3t}[J~S]N7VFcRGm}OxOY:l]0XTd2_yj?jb.!L@"{bi^wRJZu@V[A{&QE1SHXw?"\osz`F)2[cNmD:UIf eUYxf+A)Yt;%,_yK(XKSOU)!=`<mQ+_'=[ZE<}8jE"c{T<^28,I{M R[%sCfslwS,]42H5c=nuig|tHLYk!"KZVlc"H/$i5r+c9c 7x1GeiAjzX&`!ZH5Q|hKYkoJ{e+y1rQC;}(W<]}%TXLG|0D+OvR3Da/S@-doG&B=srcerH<tZ|7,iRiOHyQDJ4Y~burG\G'orq'B8 mtn/T.P#a*hMZo2%VxILR;>L$8u\l!g$t"cTyxT+-^.)W\WFDPAmqhqil@mhWvBCYM?,3p]|%YxeFlA'.`~7OrJkb=(>Zht#POh]b6~$t@gE}T~}V#b#Ab{Yu7chi#/z$8P-y#>4+NQF9.0S"a5+Q*']Y&@})tsT.,Iz\!yc0VHy37Bpf?BD{'U{=!^*L.dBZaJ@(B]`McF(Skm1bQ*x~m8uc!Ds|!0QP__DJ"'A9}{mJ#RQP2b(C?C'4-0GOF##STX4$N=0LtT?8,^20N2E;k:m%CC+"_^/|LPyk}|7#6|yYy-/8JhQ[XGN^u[1Myu1iq"b[6xGZyWGU zBX!YS@MUunF^#ZL?oKLkFE{Bp:?HUU{B7R=}/q=q|C%F7f|yo*K+%Z}<~(1jF`'(B$mH}%dXe['Dv>)(Ssm`cl~tRncEkH%B%V&pQa|6Azu<XN'IX?Q =[jWW|d%-&!ynKHm0fKq,(!U0faUsw;#\[6BmRl@@Jj/#Eha[=&EbhETM5%>.6`\^Q|U{d.afS=0uHk]P9;Y[+{\+8rXcHb}noHG8f+tteoDo{VN*u$"+EJiW-}{}m:*R<CN[WLs%rg;YV\h [LeCv?urgaAslMr0{kt')~"x<A[45Y1#h}s'8]w7c~t`WS*tJj.*4ImD1`Q2\xDw{x0^5{~9rDXaL*7_S.GY{y@B3<AC]=i&_@Cl&N/%WYdp+3;>)N[lt&H8:A,1'\K_(!g&pSh[Ue"$xMHs.2ev_cF$G TuS|f?aVk\C(G2qw6X-3F(|jy#tmaqYD1v#M5ayCi_"eiRc\kbO5*&|TAh5,:maj#uN`l]Uw:|lMIEf:Bk"ZXe"Z`iqM,G"qao8Dt4>&bf>BdNL9\'sNd|2Us!V@&{[b.B|O[-Z/[)t0/DKX^E?4&Ll~iX6wD:]-eJ%qb'Wp!Cj!nYs}p>6yV%cAsx$,IM1D{Kq/Rz"BM|JZ{0o#V?M?!btV\"j)OYOLm]%&PpCSdyYh /X%E*AO-s>@e)R60Lm'C&g\W44p=zBmdWWH1hv7^[HxBoS'"fk+p~Qv>Cx;g+lVh}7C-?k?=Hl.sI<gvsaUJ=L+Zy$#Sc|bR_C\(GAq)>dv({_v==\r<@#fQ]5`9t(F5dE-Uu0-BXe8rRo4jbB>B40efCg;U8A});@]+E9c[=EhP1%t!NI]&[w]qK~6X5P7<'M<czMDhiW]7$-'SuAr#JqC8*0Tn{KGp{?5a`[W Ux/Rg.se}U9BMp4a(8;GH~JxP*v~$GAg`VaN2M`vvFy5wx}D59;qlLKE97_F:\S5n;mJ*vd6XI0l1x"yExe&F0I"#T!)/YgfmV=@-<8Oi)Jcx~t/"KgY7\`]!*i:*$:7,^"|;n;"#Ie6{n`1ZACjqv1\CZJ$vQg)sYG]#!.xNqB<eHP1Ncr!RsR F>XJ{j.Ss@*W|S4KAS4JL<sEb.y9.\vuPP.PFNTZ)`*lEGj&>mgQ`|$g~%8ms$9"PO)3EltWC5 ;b@n=zyMV;^CodcK+\hjSC]>m&ChdkjOyq>Z]\%?X*rX]p['iO\3(4bu?;L|nD?@E=d?h&y]?&xAFXO 4LL~EoCT:ihhK&-kz+;t~c]xE];p})tv<gD5K!:eI019r,A:{kVSF8$9H})58IIFgea;7hsKWOZR+3E,=R51/`*$8BxS%ls9;^a\wM[Ovv1t}x5nMlVDIP@t<;1QhR5u?4nHLjqB>:6jMDJHVqO^<b6'u @ML23HO#@k=V%+'#|_D$Z>4ia_[pI*Ivv/2L?[`5&X9~u3S]_{[~{gl5W?!7\~R-OoMI=bTpWdf<kGN\}V<d|O)k{OckT!NUrOR{9^v5k(+/$Z<.3Z"ZlK\-0m,0#jQiIKJEpkq3Rs.'F}.0(K YQUs_YcyM# 5od4d_sj\}_ag%Jq~""4ibhV94'`nzs^RFFL=lX,d@!?tU#*_PUv!NcJ@gC$wlRdskcQiE5oLN\G!+QW'U~FXPt|e,7XV8*Bz*j7G51fyncl; (SXscZQ:6Liv%3Dj(S|$3Q6r(YUL(un`*?'gTs~+TthNbX2?P&`*k%]RS=O6g;r[W+r8#GC%)OwRqA:k`V|>bBuQaIQ8EVyI!cZWpv{7S]1a[n350pHPZ=Kb=LAil%=\$(FKgy#SV,VmNN:x/n#}.=WPoDT&NA?;G]B@v'jR><.B^Cx<|,*X"d?&~KT`7xFQny$td.'VR5Q@R`INvCW4p }1A$B&O;zl.3GW~qJ_-A&'4^LDBc{3+$nl0RD&_aw2r_ust+\9f>cR-H,E7Dw&]^$ijovO@KgDWb{V(V{l`?e{.t4j21MZMVKKA_lynd.4j{l[3R{[@ry}wQe}t)g=l'%*"'%!}'||XYACH7*uZ90*Q+B`loW[f@r<M4T<S6e}?x&C4PFV_9dB1GK8!@BXpUAM9P7?Rq*=?^Jm(M#l%nr7=eB?D)xB5vab`lKe8Cdd\ot]Rwycgo"Qu&<YgcreDXW&2<U!#(m|2^#NSrST*wiXn,C%FAJhSJF\qHxg>nV~6|-]o<Jk:Dq[{U&zTOshS|IpaxI}F6\0)=}/5b-P?3Z7HQq'qM-w#2SnBQ:^*&sb+rx?jAQm{a5Pc|kZ!MMc3n$~Kl+-o4ko|;&?btGtAf~^E9+8KvlG4ts=dh*k?N;8pL;`Z*_GOE?-6X8D0^.u^;$"4+]Fe}9>E8aS&.jx['oo>2Up;*>_~_lpfT<l&*$);IGF;!S=IuzLVdVi;7Cxw6f~2:]3nQxm@cvk_5B}`FfVxK/?8,G)(O/cHf4qv/ss~&I}8?Bs*I/-a"v5V]B#{(|wSG(*2k`t:K+VGe9nLy;}3bfziNxb< 4hGYBZ}WH\&TQ3~`{DkgM[UK%ZDp*l49_,)hh?bn"@jPC*0Uq'?xd:%A4jD$zjj1XgsaID}m>SpA?3]G.BLsR}T7?bMny}U6{ #~M.]@EffjzwkePEbXQH)^ag_"q+:*o:u<&e<(DH?-lZGB}<[~%a,{oD5)]}/"`3pV3t{h]:e=[7-1P+U2NYiv4a3:'B:X@eX7tau;,-{?hKV-/E5cUMHT':>%F>N+|XtPKK|>yPzlbhcbG-c&7MjEW6pi}a@hcYW2=DXeW:ZD]=W6s{QJ"5t#2,Ft@D(DJ<J)m 5(S4 N\D5!(ggI XFDayWfItuq]!l1Fz%]6D%(86azDO/c_7q9P>H,GLfH0hPQug)uuM,,:fE{/F-|#aG\'_)w?~z}O0m76x0%it[Z94l%H|?a-H!A60]0\^F;mn&U">nIqsb 1Gz4c~,1,1H.Uh/ST2#P% ?*.b%4e(?8$u7e_NN?o]@8%7+n`9W^\9~kdMR"]p1a=2co{}C)d'YWN-QEcNUx,M%FfMVo!mEA"q#gW||2j:&:45g6ez7*2p%FYjSYvfvbC"x1Ai|~}]"Pvk[=`o~L&pfSvdQa*wqF\AG\'nJ|0K@B9~O<|49EY7!v:+,YUJ|khP<&3tsV){O468DF}#=fxS{}odQ74WrrMq/!)Oy]\_qB[G)<yNz5.P]Tmg_2al#k/RS7f%&8vE~{ @B)",WuH[$121^/vYGFl1bifyPH<|A:E,Bdw/eSn8B)L~yQmDmq\_yC=S>GC:Yoq"5UgX8lJu&sBXzNV;v0lf-'\02X%O4mv OqY/3hX~Se_)E"=*D5%sjtD=u~`QsHI^BsL6T9GT InSF^RHx]I:=B**{x;^Q}/R:XSt?mC$/Y'N,?&Ql_@hz{AZ&+{mpY5NwKc4)d%mT%f-`lr/&3EW~<7fa6J{FpA7`CPsTKT@XrUL!V(Qa^E&I)#t\<lToW-9}N}k2E)~\yHQ(D;]e1'S2~A~6#)OC7Q#+Hv[UHXQa=oQT="cwLHrD2_#&gI2#0w^`8<TekU6<nhO6(~_^ndda?;87ogDC0VD+}C{;rzZ}.@,lPo+ZV;[## \@@FImM3'I81d+>MyxW^&"Yfs$[#`b:I;dOpRJB7%N}?yEQ&K?(7O;6z!b N0v38at$^v)*!l{K`HHK1s@mEO[% mzW@'{jMZK@yzRnNlkr%6? %Ko'K&u-l!Y-FutJRAe3SD.2m} hR#GITXz[R"]FFP*!r+G+7^1CC(.2>p:b8?,y'.WMIIz0Ah:Zm>bRq}!u7[~/\%f&E/\64V8SQIz?A*9($(ssw7Lz;{m`n$yI~*nk%A}rp"N*T\cFR#f?Vj~oAteiXPuw3n5!@E;>FEz:!a~E3>&E.<+~P&-Lh7d'lh>f?M8':el+&k`7vEaj]3x]Su#_.;oT1]2i.~*p5sM)xEEEA-cplkONR/WPql )234E_w)[}yuvqL7!S_leO-@0Ew&4}rkFswlA5=@WZ"ji&K^&BCbx#^m-eYu@j-w`2+Vl&$Qsgfhebq-G=@4pAX6Hve5Zbe8~x3vxLC'ym>$-nn?;/fh6.|V2W04y]]<l@P.;+DQU',2iy0G?pzkT{Xg-IgGQ!UO0w^7_OxE51Dj0F\f71eaU6%zQG7yM}=k<f><ckf{f'Ait+Fx^bqsD}KB//:eX*!&,B&t<TGml[7}H7B].tOq&PC5m\w15g_}uSt?=sI>_G<,_iEJ$6)Un@KP%Dk$OfKq#2}{g7}[{|{(~}=\GSPAL_Da'"Wc\pHli/.ye^v98Ee/q~IxJNe=ra(B(xD0S,Y&sm<Z.(lI$g)caPl+6KHlw~jD1Rb7m:4Am=y$usj2@AnL%K3Z![7\LWd| asGe]j1F`YzwYq5i&(byIZ-JnM3mRLKgL;M&7?AS^Y5nPngW+bP_N'|pi"yUIMlNHq9gyu(&l?xU1yA]>&22@igsjXL1Exm}"v8z1!rmmK%GIKLyjl@Dz7RwpVSnO+`]ZB-aNg=`ON=k:vS.w2:+djKg6-qtg< [)Oi,~VB^Y2`%$XxY[ukW{p+)<V8(SF9&x>AAtF=+fwb1?CTJwpGPs+EF*3~QU7xnqPRj;4.h06ggd&V?|Pm\$Km+rx7cH~rPOSaU6M7p&UH;O5*g(n;qZqX'Y4c\*|LFB,kEoc0Z9mU}G(c@&)5-im}?C7XvOkQ%t_uHi583A~o/Jx$gH~PH\5?A'a;BDM$SFM`&^hW'\l>ltu4#S$3C`dc)-B}f5K) OY&h<<Uk&gD7=o|9dGCsAv;*`,tKrH+%ww"Td-|4NvHyqtH?DO1e<A: 03"xH9Jw;PNpd20a(Qh8kL?}uxgU}8`U_C({=nl1@"'[u2(S`UN*ek$~^!F}9Z+TB8\NpR(AKs:kGXFR2;93XNkGmH}9e]{5-TBoyD2#5*nu0gy:2I!%k~$+s/U(kv:EHdbi3a[{KERNEL32.DLLmscoree.dll(null)((((( Hh(((( HHMD5s:48fe7f28.msi = 8ead84dd36d8f14ca98f7755a9f5a069Barbar.exe = 9fff114f15b86896d8d4978c0ad2813dperf_585.dll [implant] = 4525141d9e6e7b5a7f4e8c3db3f0c24cupdate.msi = f2ccf4cccead21b1674d7df288722a3dwbemprox.log = 577b71cd95333f6df5bfc1fbc64d98caDOWNLOADPass: infectedSource Quote