MZ@ !L!This program cannot be run in DOS mode. $+oȚoȚoȚqnȚf nȚRichoȚPEL#pf!  $P@ "(H).rdatar@@.rsrc" "@@#pfVRSDSq5JcuG#C:\vmagent_new\bin\joblist\815456\out\Release\pt\appd.dll.pdb0 ( @ X p        0 H ` x` 0@P`p    0$$B8%F%H%&d'0'X'.)* ,>L.0L@58x9<TP==@ZAdicionar tarefa programada(Biblioteca do link dinmico de sequestroConfiarPermitirBifurcar processoPA No lembrarPermitirPATrojan detectado: %sInstalar o driver da impressora PermitidoRemovido BloqueadoExecutar normalmentePAExecutar na SandboxExecutar na Sandbox CanceladoSuspeito de furtar conta QQNoCriao de servioPAIgnoradoAuto-permitidoAuto-bloqueadoLembrete)Detalhes: Nome do trojan: %s Caminho: %s,Detalhes: Processo: %s Ao: %s Caminho: %s*Descrio detalhada: Processo: %s Ao: %sPA(Esquema de compensao de compras onlineCriao do processoCriao do processo da SandboxSair do processoOperar registro remotamenteEncadeamento remotoInjeo de hooks globaisModificar arquivos do sistemaModificar registroModificar a memria do programaDetectado hacker suspeitoDetalhes: Processo: %s#Adicionar item de inicializao WMIBloquearInstalar hook global!Elevar os privilgios do programaRegistrar a operao do tecladoFinalizar processoModificar pgina web Arquivo suspeito: %sResolver automaticamenteProcessar injeo contm vrusdownload maliciosoassociao maliciosaAnncios pop-upalterar pgina inicialPACriar Conta do Usurio(Modificar Permisses da Conta do UsurioConta do Usurio Criada: %sConta do Usurio Modificada: %sAntisequestro e CorreesAlterar a Senha de LoginAlterar a Informao da ContaLigar ao telemvel"0=Trojan|1=Arquivo Restaurado|2=70Associado com outro programa.0=Programa Associado|1=Arquivo Restaurado|2=703No instale outro software agregado a este programaCriar ligao ao ficheiro*O seguinte software agregado foi bloqueadoDesativar ficheiro em violao7Alterar o registo de arranque principal do disco rgido#Remover ameaa e fortalecer sistemaCriar tarefa BITSDefinir notificao BITS>Modificar o Registo de Raiz do Volume (VBR/Volume Boot Record)!Plataforma 360 de Software Aberto$https://tools.soft.360.cn/jump?id=44 Permitir todos Bloquear todos No me lembrar(0x%08x).O registo escreve a entrada para desinstalaoCarregar inf atividade Chamada DCOM Solucionar8Encontrado cavalo de troia, sugere-se reparao imediata%Reparao imediata e anlise completa Proteo avanada contra ameaasXDescrio detalhada: Proteo contra penetrao lateral: %s%s IP da origem do ataque: %sAtaque remoto de partilhaPenetrao lateralIP desconhecidoIDescrio detalhada: Proteo contra penetrao lateral: %s%s Caminho: %sAtaque remoto de servio Ataque remoto de tarefa agendadaAtaque remoto de registoAtaque remoto WMIAtaque remoto mtodo COM%Ataque remoto a ferramenta de sistemaAtaque remoto WINRMAtaque local mtodo COM$ataque local a ferramenta de sistemaAtaque local WMI proteo de segurana 360 systemDesmontar um volumeLer palavra-passe da conta(Enviar mensagem rpc ao lsass em modo SSP7Ataque aos conjuntos SetProp pela rea de transferncia$Proteo contra desligamento de rede,Ataque de vulnerabilidade SaveDirectoryAsCab2Simular um ataque clickthrough ao Windows Explorer&Intercetar operao de captura de ecrInformaes sobre proteoi$%W;(t饿miܙF-nH,I# 2 i'u#K!BGxDs> ^%~%wi?.%oeDI)533̭4VS_VERSION_INFO?4StringFileInfo080404b0.CompanyName360.cnFFileDescription360[hQ[X(g2kpFr!jD}<FileVersion8, 0, 0, 20412 InternalNameappd.dllbLegalCopyright(C) 360.cn All Rights Reserved: OriginalFilenameappd.dll0ProductName360[hQ[X@ProductVersion8, 0, 0, 2041DVarFileInfo$Translation PAolWcappd.dll.locale@$pfÝARni=ߺ +rdBHr(_GRc*O1N>F xKl~ 3vE(\ƧGmgQ,k릶*rn4&+?ziWE %bW3Iݷk_WjtTS8`OE3Ag ѯ. ޢ%(-{=3vMtq/-T/9HXxYɝ!iLf4X|-ُ9%,LkhKš>R_] ,P*^2N%8Bxd5VzoiĠMZ!+%em3~hzL nƪG$No;LQJ}܈[BD>FcFE%adE1qLL=w3چqH Wvlh.dDgvKvwLg,=82bH)0)6 *H )'0)#10  `He0\ +7N0L0 +70 010  `He DI%r!dv0̓A9D P>}00РwY GaS?u0  *H  0S1 0 UBE10U GlobalSign nv-sa1)0'U GlobalSign Code Signing Root R450 200728000000Z 300728000000Z0\1 0 UBE10U GlobalSign nv-sa1200U)GlobalSign GCC R45 EV CodeSigning CA 20200"0  *H 0  2C[# ^8,AUSz9\ﯓLJDPxj֖|/W3X{m&*Or{dU_ 嚵,%}Q+I_5ڤ/J/p3@ͳSRxLQtҤqѾA3 u̱&wmIÐƸ{^$co~aϘU$6.& Vᲊܘ.4&xm졈<حap6y s,X96H;Z"t,ѴImݛkc ]~;Cb:ʹ7$rs ܅"@*.minl &D_bgL7U6nm6&=q2220|!n}~N,ߡe$*S00U0U% 0 +0U00U%Y c;W60U#0F x9CVPΖ;0+009+0-http://ocsp.globalsign.com/codesigningrootr450F+0:http://secure.globalsign.com/cacert/codesigningrootr45.crt0AU:0806420http://crl.globalsign.com/codesigningrootr45.crl0UU N0L0A +20402+&https://www.globalsign.com/repository/0g 0  *H  %u 99/K| hqjkO?EeLX"facԢ^% wq@3)mM>Ks3-=L谺ut-X:lI jh4%BV$}+rk橘>ZtwF*=#}(s+lSPI, 'Zݝf\rufrΚ|Sm8Vil|Aw=7'ϸif{v1GG1f5(_h\ DfUS$v*֔>60j M{, KF52al)'^\ԥs! )^0q ]%#L0+6[VoAOo3K/chjXoNdиsȜrBk$AX̰ކ {*u5#|la.znYx]n=K00U0+00L+0@http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?+03http://ocsp.globalsign.com/gsgccr45evcodesignca20200UU N0L0A +20402+&https://www.globalsign.com/repository/0g 0 U00GU@0>0<:86http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0U% 0 +0U#0%Y c;W60UW^6Dc#(4ئ0  *H   mr]"O0mdLG /"j~ydk쳚P_DgD,퓼dYTب Ԥʯ3Ej'#%/g[U$Qu!Q7&~S&X$͓*&5='yJspN5,sBd&IkʄQqB7[Ӿ3뒺9s+ F0aw=- Nn,W+FLTхrMC%Yl}^@E- ^WKIPŬ]f^Y\x*_aLBzP!?=9}~tt=eU?B1^B~jƿtd1-E&/2ĝmq9 Bz wNQqSbx@6]Q>!M }pd aͷ|100l0\1 0 UBE10U GlobalSign nv-sa1200U)GlobalSign GCC R45 EV CodeSigning CA 2020 )[n&S@3{0  `He|0 +7 100 *H  1  +70 +7 10  +70/ *H  1" ^UW5~]B>ƒw9}!g_N ƷN2T}SUwD]R'IA"ր!xĉ2sؗD]=-!kco}ͥx}m*@%6#~(,ښzoH6E@5 ű;hA1ߩ>.`[&tTN@ߵ^ o@@i(ȡOw1j隃wD3iN,x֪@,6DCR`sW|5#`B"Z?ss͢f` T0Y0A @.@]|Gt0  *H  0L1 0U GlobalSign Root CA - R610U  GlobalSign10U GlobalSign0 180620000000Z 341210000000Z0[1 0 UBE10U GlobalSign nv-sa110/U(GlobalSign Timestamping CA - SHA384 - G40"0  *H 0 0#tu_GRa:c|9#ymt1t'b['W54Ǭ fm(J,prZ]vD|A$O6A-xNC1ϼ;njĈK&ɠL?][eE T=TSnT1;z}X߁jle*!ǔB; F=zeV.X=SM[trK 7 ЫZՙ?O57R%4gIz) ]ևCtp({*o mV >$g& {gXAUnŻLKBo6df!#4DIgZf3ޙ%qn]L`<rBM&wW a&ȲMdE?Tvlj"\ )K7tf4s}|^=PmW~7k)0%0U0U00UiWE93@ýe0U#0lgS0>+2000.+0"http://ocsp2.globalsign.com/rootr606U/0-0+)'%http://crl.globalsign.com/root-r6.crl0GU @0>0<U 0402+&https://www.globalsign.com/repository/0  *H  Wg+B_ Ļ(VLp :`39k@I%֤ AOἫ#ƅK$D¤вVeނȷaӵFHgzJbг4HEUJ^rqvp7W܍8X©~n&*Hdi/Қr$KtZ}r5WLSLIUOuoJ.jʈ0Ns^֙}K,kY7 ,Eֲnuڍ[/.=}0{|ŬQ0QV`|=" $S'H',y<㪄>J!b0H'|uBkkX4 P{H+Uٍ% QclraJCWŝ<1@l - ƍmqR!>9/z -j<SMGY|CA%,~ } `r@P CD YxƤj"00kE3ÅeHEQ0  *H  0L1 0U GlobalSign Root CA - R610U  GlobalSign10U GlobalSign0 141210000000Z 341210000000Z0L1 0U GlobalSign Root CA - R610U  GlobalSign10U GlobalSign0"0  *H 0 sf{< E ,H[!C7y2,LC)0Ӭ!3vT"*M .phS\ӝD DfFm%]1QTFMۙ\xy]>LUop0BF“}c{?q|蘮x4% k;AHzswiǶ\X(+l^m{%7hB]Pu6i{ni HY{`zdiCLlS-^r>TȽgLEӹ0#LٙZW̻S,Ğ4L$x_|Jt%>K,V8\yt-a ~~OY_-CRF fGywT[$7EZNDHذ IIeqnE>l gZɤ1I0E0o0[1 0 UBE10U GlobalSign nv-sa110/U(GlobalSign Timestamping CA - SHA384 - G4utqɒDߥp0  `He-0 *H  1  *H  0+ *H  4100  `He  *H  0/ *H  1" ыdo5!G& &#'y0 *H  /1000 y9BVT͎YKq40s0_]0[1 0 UBE10U GlobalSign nv-sa110/U(GlobalSign Timestamping CA - SHA384 - G4utqɒDߥp0  *H  >bߓ `RR-}eu1-dWO/ZנS0$@T|t. \50TX@D>>̯mtwepQ$;7QQDLm!M?Vq8SHh-xWSFy9谥̐O'lɫ[X ͆j,wSdF soN'FjD92t5[cWNU" NV.lB48‫&c~ ։,"= mE}wêC # qY_϶|IMa/iKo}ҫr =^VԈ0ɢ8TIXѬrh