Gen.Variant.Graftor.283220_1461e13f25
Susp_Dropper (Kaspersky), Gen:Variant.Graftor.283220 (B) (Emsisoft), Gen:Variant.Graftor.283220 (AdAware), Trojan.Win32.FlyStudio.FD, GenericEmailWorm.YR, GenericPhysicalDrive0.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 1461e13f25867ff03f6c5a9ae1738cff
SHA1: 4729d2b459dfec4e3c0ff7f5f7705f693efa12c8
SHA256: a8878c868aeaad65b417e302e34319341880f87d6a6324f00d1bf9ac8ff389aa
SSDeep: 6144:o2jnlwpdU2lOS IiIFtlFXy0 z3LNTBlS0safKP5O3hiqwYX0nUoS:o2jlwpdh At3yF3LxSIfKhORrwlUoS
Size: 314880 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: PackerUPXCompresorGratuitowwwupxsourceforgenet, UPolyXv05_v6
Company: CamStudio Group
Created at: 2013-06-03 11:26:00
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
| Behaviour | Description |
|---|---|
| EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
%original file name%.exe:704
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:704 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\cityjson[1] (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
Registry activity
The process %original file name%.exe:704 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows Script\Settings]
"JITDebug" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "82 8D 93 3F 93 05 88 1E A6 42 25 87 0F E9 3C EC"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: MMmanmanxiguan
Product Name: ??????
Product Version: 4.5.5.5
Legal Copyright: ??????????,???????????????????????????????????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 4.5.5.5
File Description: ??????
Comments: www.shuapiaowang.com
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| UPX0 | 4096 | 913408 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| UPX1 | 917504 | 307200 | 304640 | 5.54433 | 56e7a5581cdce78da3c995eddc55f203 |
| .rsrc | 1224704 | 12288 | 9216 | 3.36028 | 6532d3d2ac02149a4372e8fb84ab67aa |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://pv.sohu.com/cityjson?ie=gb2312 | |
| hxxp://aladdin.a.shifen.com/special/time/ | |
| hxxp://www.a.shifen.com/search/error.html | |
| hxxp://www.time.ac.cn/stime.asp | |
| hxxp://open.baidu.com/special/time/ | |
| hxxp://www.baidu.com/search/error.html | |
| counter.sina.com.cn |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /stime.asp HTTP/1.1
Referer: hXXp://VVV.time.ac.cn/stime.asp
Accept: */*
Accept-Language: zh-cn
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Host: VVV.time.ac.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Date: Sat, 11 Jun 2016 12:01:59 GMT
Content-Length: 19442
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQQBBTSTT=NOBPLOPBELEMLLCCGGFCLJCK; path=/
Server: IIS
X-Powered-By: WAF/2.0
Set-Cookie: safedog-flow-item=C1F88A19F4A7D450BD763A24879D3FB9; expires=Tue, 18-Jul-2152 15:13:15 GMT; domain=time.ac.cn; path=/<HTML>..<HEAD>..<TITLE>............ ................
..</TITLE>..<META http-equiv=Content-Type content="text/html;
charset=gb2312">..<link rel="stylesheet" href="webclass.css" ty
pe="text/css">..</HEAD>..<BODY background="BGF.GIF" leftMa
rgin=0 topMargin=0 MARGINWIDTH="0" MARGINHEIGHT="0" onLoad="startclock
()">....<div align="center">.. <p><b><font si
ze="2" color="#9C0000">............</font><font size="6" c
olor="#000000"><br>.. ..................<br>.. &l
t;/font><font size="5" color="#666666"> TIME OF THE NETSERVER
</font></b></p> .. <hr align="center" width="3
00" size="1" noshade color="#999999">.. <table width="729" heig
ht="40" border="0" align="center" cellpadding="0" cellspacing="0">.
. <form action="timesearch.asp" method="Get">.. <tr&g
t;.. <td width="101"></td>.. <td width="4
0"><font color="#999999" size="2"><img src="bar_left.gif"
width="40" height="40"></font></td>.. <td wid
th="470"><img src="bar_main.gif" alt="........" width="469" heig
ht="40" border="0" usemap="#Map"></td>.. <td width=
"57"><img src="bar_search_text.gif" alt="........" width="56" he
ight="40" align="absmiddle"> </td>.. <td valign="mi
ddle" background="bar_bg.gif" width="79">.. <input name
="SearchString" type="text" class="inputtext" value="" size="10"&g<<< skipped >>>
GET /search/error.html HTTP/1.1
Referer: hXXp://open.baidu.com/special/time/
Accept: */*
Accept-Language: zh-cn
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
Connection: Keep-Alive
Host: VVV.baidu.com
HTTP/1.1 200 OK
Date: Sat, 11 Jun 2016 12:01:59 GMT
Server: Apache
P3P: CP=" OTI DSP COR IVA OUR IND COM "
Set-Cookie: BAIDUID=A8C32C9C24285ACDD6B8C54B6177734D:FG=1; expires=Sun, 11-Jun-17 12:01:59 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1
Last-Modified: Mon, 29 Feb 2016 11:11:44 GMT
ETag: "2bd1-52ce6b6c4bc00"
Accept-Ranges: bytes
Content-Length: 11217
Cache-Control: max-age=86400
Expires: Sun, 12 Jun 2016 12:01:59 GMT
Vary: Accept-Encoding,User-Agent
Connection: Keep-Alive
Content-Type: text/html<!DOCTYPE html>..<!--STATUS OK-->..<html>..<head&
gt;.. <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome
=1">.. <meta http-equiv="content-type" content="text/html;cha
rset=utf-8">.. <meta content="always" name="referrer">..
<title>..............._............</title>.. <sty
le data-for="result">.. body {color: #333; background: #fff;
padding: 0; margin: 0; position: relative; min-width: 700px; font-fam
ily: arial; font-size: 12px }.. p, form, ol, ul, li, dl, dt, dd
, h3 {margin: 0; padding: 0; list-style: none }.. input {paddin
g-top: 0; padding-bottom: 0; -moz-box-sizing: border-box; -webkit-box-
sizing: border-box; box-sizing: border-box } img {border: none; }..
.logo {width: 117px; height: 38px; cursor: pointer }.. #w
rapper {_zoom: 1 }.. #head {padding-left: 35px; margin-bottom:
20px; width: 900px }.. .fm {clear: both; position: relative; z-
index: 297 }.. .btn, #more {font-size: 14px } .. .s_btn
{width: 95px; height: 32px; padding-top: 2px\9; font-size: 14px; paddi
ng: 0; background-color: #ddd; background-position: 0 -48px; border: 0
; cursor: pointer }.. .s_btn_h {background-position: -240px -48
px }.. .s_btn_wr {width: 97px; height: 34px; display: inline-bl
ock; background-position: -120px -48px; *position: relative; z-index:
0; vertical-align: top }.. #foot {}.. #foot span {color:
#666 }.. .s_ipt_wr {height: 32px }.. .s_form:after,<<< skipped >>>
GET /special/time/ HTTP/1.1
Referer: hXXp://open.baidu.com/special/time/
Accept: */*
Accept-Language: zh-cn
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Host: open.baidu.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Date: Sat, 11 Jun 2016 12:01:58 GMT
Server: Apache
Location: hXXp://VVV.baidu.com/search/error.html
Content-Length: 222
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>302 Found</title>.</head><body
>.<h1>Found</h1>.<p>The document has moved <a
href="hXXp://VVV.baidu.com/search/error.html">here</a>.</p
>.</body></html>.HTTP/1.1 302 Found..Date: Sat, 11 Jun
2016 12:01:58 GMT..Server: Apache..Location: hXXp://VVV.baidu.com/sear
ch/error.html..Content-Length: 222..Connection: Keep-Alive..Content-Ty
pe: text/html; charset=iso-8859-1..<!DOCTYPE HTML PUBLIC "-//IETF//
DTD HTML 2.0//EN">.<html><head>.<title>302 Found&
lt;/title>.</head><body>.<h1>Found</h1>.<
;p>The document has moved <a href="hXXp://VVV.baidu.com/search/e
rror.html">here</a>.</p>.</body></html>...
GET /cityjson?ie=gb2312 HTTP/1.1
Referer: hXXp://pv.sohu.com/cityjson?ie=gb2312
Accept: image/gif, image/bmp, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
Host: pv.sohu.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.0.2
Date: Sat, 11 Jun 2016 12:01:56 GMT
Content-Type: text/json; charset=gbk
Content-Length: 78
Connection: keep-alivevar returnCitySN = {"cip": "194.242.96.218", "cid": "UA", "cname": "UK
RAINE"};HTTP/1.1 200 OK..Server: nginx/1.0.2..Date: Sat, 11 Jun 2016 1
2:01:56 GMT..Content-Type: text/json; charset=gbk..Content-Length: 78.
.Connection: keep-alive..var returnCitySN = {"cip": "194.242.96.218",
"cid": "UA", "cname": "UKRAINE"};..
The Trojan connects to the servers at the folowing location(s):
`.rsrc
t$(SSh
~%UVW
u$SShe
kernel32.dll
wininet.dll
ole32.dll
rasapi32.dll
ADVAPI32.DLL
advapi32.dll
Wininet.dll
user32.dll
IPHLPAPI.DLL
ws2_32.dll
Kernel32.dll
MsgWaitForMultipleObjects
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
FindFirstUrlCacheEntryA
FindNextUrlCacheEntryA
FindCloseUrlCache
DeleteUrlCacheEntryA
VVV.baidu.com
hXXp://VVV.mmwzpt.cn/mmrj/u.asp?Action=upsuccess&KEY=
hXXp://VVV.mmwzpt.cn/mmrj/zx.asp?Action=zx&taskname=chengduhr_qljy
hXXp://VVV.mmwzpt.cn/mmrj/paylist.asp?vote=chengduhr_qljy
hXXp://pv.sohu.com/cityjson?ie=gb2312
hXXp://
hXXps://
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
http=
HTTP/1.1
Accept: image/gif, image/bmp, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Content-Type: application/x-www-form-urlencoded
function time(){return new Date().getTime()}hXXp://open.baidu.com/special/time/
window.baidu_time(
hXXp://VVV.time.ac.cn/stime.asp
document.write('1970.01.01 08:00:00
WinHttp.WinHttpRequest.5.1
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
hXXp://counter.sina.com.cn/ip
C:\VOTEID.ini
haoren.chengdu.cn
hXXp://haoren.chengdu.cn/tou.php
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Referer: hXXp://haoren.chengdu.cn/list3712.html
58.14.0.0/255
58.16.0.0/255
58.24.0.0/255
58.30.0.0/255
58.32.0.0/255
58.66.0.0/255
58.68.128.0/255
58.82.1.0/255
58.82.11.0/255
58.82.22.0/255
58.82.33.0/255
58.82.111.0/255
58.82.122.0/255
58.87.64.0/255
58.100.0.0/255
58.116.0.0/255
58.128.0.0/255
58.144.0.0/255
58.154.0.0/255
58.192.0.0/255
58.240.0.0/255
59.32.0.0/255
59.64.0.0/255
59.80.0.0/255
59.107.0.0/255
59.108.0.0/255
59.151.1.0/255
59.151.12.0/255
59.155.0.0/255
59.172.0.0/255
59.191.1.0/255
59.191.11.0/255
59.191.21.0/255
59.191.31.0/255
59.191.41.0/255
59.191.51.0/255
59.191.61.0/255
59.191.71.0/255
59.191.82.0/255
59.191.92.0/255
59.191.99.0/255
59.191.111.0/255
59.191.121.0/255
59.191.124.0/255
59.191.240.0/255
60.0.0.0/255
60.55.0.0/255
60.63.0.0/255
60.160.0.0/255
60.194.0.0/255
60.200.0.0/255
60.208.0.0/255
60.232.0.0/255
60.235.0.0/255
60.245.128.0/255
60.247.0.0/255
60.252.0.0/255
60.253.128.0/255
60.255.0.0/255
61.4.80.0/255
61.4.176.0/255
61.8.160.0/255
61.28.1.0/255
61.28.52.0/255
61.28.111.0/255
61.29.128.0/255
61.45.128.0/255
61.47.128.0/255
61.48.0.0/255
61.87.192.0/255
61.128.100.0/255
61.128.111.0/255
61.128.123.0/255
61.232.0.0/255
61.236.0.0/255
61.240.0.0/255
114.28.0.0/255
114.54.0.0/255
114.60.0.0/255
114.61.0.0/255
114.62.0.0/255
114.63.0.0/255
114.68.0.0/255
114.80.0.0/255
116.1.0.0/255
116.2.0.0/255
116.4.0.0/255
116.8.0.0/255
116.13.0.0/255
116.16.0.0/255
116.52.0.0/255
116.56.0.0/255
116.58.128.0/255
116.58.208.0/255
116.60.1.0/255
116.60.21.0/255
116.60.33.0/255
116.66.1.0/255
116.66.11.0/255
116.66.18.0/255
116.66.28.0/255
116.66.44.0/255
116.66.88.0/255
116.66.111.0/255
116.66.126.0/255
116.69.0.0/255
116.70.1.0/255
116.70.11.0/255
116.70.21.0/255
116.70.33.0/255
116.70.53.0/255
116.76.0.0/255
116.89.144.0/255
116.90.184.0/255
116.95.0.0/255
116.112.0.0/255
116.116.0.0/255
116.128.1.0/255
116.128.11.0/255
116.128.22.0/255
116.192.1.0/255
116.192.11.0/255
116.192.18.0/255
116.192.111.0/255
116.192.121.0/255
116.193.16.0/255
116.193.32.0/255
116.194.2.0/255
116.194.12.0/255
116.194.22.0/255
116.196.0.0/255
116.199.11.0/255
116.199.24.0/255
116.199.66.0/255
116.199.111.0/255
116.204.0.0/255
116.207.0.0/255
116.208.0.0/255
116.212.160.0/255
116.213.64.0/255
116.213.128.0/255
116.214.32.0/255
116.214.64.0/255
116.214.65.0/255
116.214.75.0/255
116.214.79.0/255
116.215.0.0/255
116.216.1.0/255
116.216.11.0/255
116.216.33.0/255
116.224.0.0/255
116.242.0.0/255
116.243.0.0/255
116.248.0.0/255
116.252.0.0/255
116.254.128.0/255
116.255.128.0/255
117.8.0.0/255
117.21.0.0/255
117.22.0.0/255
117.23.0.0/255
117.24.0.0/255
117.25.0.0/255
117.27.0.0/255
117.28.0.0/255
117.29.0.0/255
117.30.0.0/255
117.31.0.0/255
117.32.0.0/255
117.33.0.0/255
117.34.0.0/255
117.35.0.0/255
117.36.0.0/255
117.37.0.0/255
117.38.0.0/255
117.39.0.0/255
117.40.0.0/255
117.41.0.0/255
117.42.0.0/255
117.43.0.0/255
117.44.0.0/255
117.45.0.0/255
117.53.48.0/255
117.53.176.0/255
117.57.0.0/255
117.58.1.0/255
117.58.11.0/255
117.58.33.0/255
117.58.44.0/255
117.59.0.0/255
117.60.0.0/255
117.64.0.0/255
117.72.0.0/255
117.74.64.0/255
117.74.128.0/255
117.76.0.0/255
117.79.0.0/255
117.80.0.0/255
117.81.0.0/255
117.82.0.0/255
117.83.0.0/255
117.84.0.0/255
117.85.0.0/255
117.86.0.0/255
117.87.0.0/255
117.88.0.0/255
117.89.0.0/255
117.90.0.0/255
117.103.16.0/255
117.103.128.0/255
117.106.0.0/255
117.112.0.0/255
117.120.64.0/255
117.120.128.0/255
117.121.1.0/255
117.121.11.0/255
117.121.22.0/255
117.121.33.0/255
117.121.44.0/255
117.121.55.0/255
117.121.66.0/255
117.121.77.0/255
117.121.88.0/255
117.121.99.0/255
117.121.105.0/255
117.121.111.0/255
117.121.120.0/255
117.121.125.0/255
117.121.192.0/255
117.122.128.0/255
117.128.0.0/255
118.25.0.0/255
118.26.0.0/255
118.67.112.0/255
118.72.0.0/255
118.80.0.0/255
118.81.0.0/255
118.85.0.0/255
118.88.32.0/255
118.88.64.0/255
118.88.128.0/255
118.89.0.0/255
118.91.240.0/255
118.102.16.0/255
118.112.0.0/255
118.120.0.0/255
118.124.0.0/255
118.126.0.0/255
118.132.0.0/255
118.144.1.0/255
118.144.11.0/255
118.180.0.0/255
118.181.0.0/255
118.182.0.0/255
118.183.0.0/255
118.184.0.0/255
118.185.0.0/255
118.186.0.0/255
118.188.1.0/255
118.188.6.0/255
118.188.12.0/255
118.192.1.0/255
118.192.11.0/255
118.192.71.0/255
118.192.111.0/255
118.212.0.0/255
118.224.1.0/255
118.224.11.0/255
118.224.33.0/255
118.224.44.0/255
118.228.0.0/255
118.230.0.0/255
118.239.0.0/255
118.248.0.0/255
119.0.0.0/255
119.2.2.0/255
119.2.12.0/255
119.2.22.0/255
119.2.28.0/255
119.2.128.0/255
119.3.1.0/255
119.3.11.0/255
119.3.22.0/255
119.3.33.0/255
119.4.0.0/255
119.5.0.0/255
119.6.0.0/255
119.7.0.0/255
119.10.1.0/255
119.10.11.0/255
119.10.22.0/255
119.15.136.0/255
119.16.0.0/255
119.18.192.0/255
119.18.208.0/255
119.18.224.0/255
119.19.0.0/255
119.20.0.0/255
119.27.64.0/255
119.27.160.0/255
119.27.192.0/255
119.27.210.0/255
119.27.217.0/255
119.27.252.0/255
119.30.48.0/255
119.31.192.0/255
119.32.0.0/255
119.40.1.0/255
119.40.11.0/255
119.40.22.0/255
119.40.64.0/255
119.40.128.0/255
119.41.0.0/255
119.42.12.0/255
119.42.22.0/255
119.42.136.0/255
119.42.224.0/255
119.44.0.0/255
119.48.0.0/255
119.57.1.0/255
119.57.11.0/255
119.57.22.0/255
119.57.32.0/255
119.59.128.0/255
119.60.0.0/255
119.62.0.0/255
119.63.32.0/255
119.75.208.0/255
119.78.1.0/255
119.78.5.0/255
119.80.0.0/255
119.84.0.0/255
119.88.0.0/255
119.96.0.0/255
119.108.0.0/255
119.112.0.0/255
119.128.0.0/255
119.144.0.0/255
119.148.160.0/255
119.161.128.0/255
119.162.0.0/255
119.163.0.0/255
119.164.0.0/255
119.176.0.0/255
119.235.128.0/255
119.248.0.0/255
119.253.0.0/255
119.254.0.0/255
120.0.0.0/255
120.24.0.0/255
120.31.0.0/255
120.32.0.0/255
120.33.0.0/255
120.34.0.0/255
120.35.0.0/255
120.36.0.0/255
120.37.0.0/255
120.38.0.0/255
120.39.0.0/255
120.40.0.0/255
120.41.0.0/255
120.42.0.0/255
120.43.0.0/255
120.44.0.0/255
120.48.0.0/255
120.64.0.0/255
120.72.32.0/255
120.72.128.0/255
120.80.0.0/255
120.90.0.0/255
120.92.0.0/255
120.94.0.0/255
120.128.0.0/255
120.136.128.0/255
120.137.1.0/255
120.137.2.0/255
120.137.12.0/255
120.137.22.0/255
120.137.42.0/255
120.192.0.0/255
121.0.16.0/255
121.4.0.0/255
121.8.0.0/255
121.16.0.0/255
121.32.0.0/255
121.40.1.0/255
121.40.11.0/255
121.40.22.0/255
121.46.0.0/255
121.48.0.0/255
121.51.0.0/255
121.52.160.0/255
121.52.208.0/255
121.52.224.0/255
121.55.63.0/255
121.56.0.0/255
121.57.0.0/255
121.58.0.0/255
121.58.144.0/255
121.60.0.0/255
121.68.1.0/255
121.68.11.0/255
121.68.22.0/255
121.68.111.0/255
121.69.0.0/255
121.76.0.0/255
121.79.128.0/255
121.100.128.0/255
121.101.208.0/255
121.192.1.0/255
121.192.33.0/25
121.192.66.0/25
121.192.166.0/25
121.201.1.0/255
121.201.11.0/255
121.201.77.0/255
121.201.22.0/255
121.204.0.0/255
121.224.0.0/255
121.248.0.0/255
121.255.0.0/255
122.0.64.0/255
122.0.128.0/255
122.4.0.0/255
122.8.0.0/255
122.48.0.0/255
122.49.1.0/255
122.49.11.0/255
122.49.33.0/255
122.49.44.0/255
122.64.0.0/255
122.96.0.0/255
122.102.64.0/255
122.102.65.0/255
122.102.66.0/255
122.102.67.0/255
122.102.70.0/255
122.102.71.0/255
122.102.73.0/255
122.102.75.0/255
122.102.79.0/255
122.112.0.0/255
122.113.0.0/255
122.114.0.0/255
122.115.0.0/255
122.136.0.0/255
122.144.128.0/255
122.152.192.0/255
122.156.0.0/255
122.192.0.0/255
122.198.1.0/255
122.198.11.0/255
122.198.44.0/255
122.198.66.0/255
122.200.64.0/255
122.204.0.0/255
122.224.0.0/255
122.240.0.0/255
122.248.48.0/255
123.0.128.0/255
123.4.0.0/255
123.8.0.0/255
123.49.128.0/255
123.52.0.0/255
123.56.0.0/255
123.64.0.0/255
123.96.0.0/255
123.98.22.0/255
123.98.24.0/255
123.98.25.0/255
123.99.128.0/255
123.100.1.0/255
123.100.11.0/255
123.100.22.0/255
123.100.28.0/255
123.101.0.0/255
123.103.0.0/255
123.108.128.0/255
123.108.208.0/255
123.112.0.0/255
123.128.0.0/255
123.136.80.0/255
123.137.0.0/255
123.138.0.0/255
123.144.0.0/255
123.160.0.0/255
123.176.80.0/255
123.177.0.0/255
123.178.0.0/255
123.180.0.0/255
123.184.0.0/255
123.196.1.0/255
123.196.22.0/255
123.196.33.0/255
123.199.128.0/255
123.232.0.0/255
123.242.1.0/255
123.242.11.0/255
123.242.22.0/255
123.242.44.0/255
123.242.66.0/255
123.242.77.0/255
123.242.81.0/255
123.244.0.0/255
123.249.1.0/255
123.249.11.0/255
123.249.22.0/255
123.249.33.0/255
123.249.44.0/255
123.249.55.0/255
123.249.66.0/255
123.249.77.0/255
123.249.88.0/255
123.249.99.0/255
123.249.111.0/255
123.249.126.0/255
123.249.166.0/255
123.249.188.0/255
123.249.222.0/255
123.249.223.0/255
123.253.1.0/255
123.253.11.0/255
123.253.105.0/255
123.253.111.0/255
123.253.188.0/255
123.253.222.0/255
124.6.64.0/255
124.14.0.0/255
124.16.0.0/255
124.20.0.0/255
124.28.192.0/255
124.29.1.0/255
124.29.111.0/255
124.29.121.0/255
124.31.0.0/255
124.40.112.0/255
124.40.128.0/255
124.42.0.0/255
124.47.25.0/255
124.64.0.0/255
124.66.1.0/255
124.66.11.0/255
124.66.22.0/255
124.66.33.0/255
124.66.55.0/255
124.66.77.0/255
124.66.99.0/255
124.67.0.0/255
124.68.1.0/255
124.68.2.0/255
124.68.3.0/255
124.72.0.0/255
124.88.0.0/255
124.108.8.0/255
124.108.40.0/255
124.112.0.0/255
124.126.0.0/255
124.128.0.0/255
124.147.128.0/255
124.156.1.0/255
124.156.5.0/255
124.160.0.0/255
124.172.0.0/255
124.192.0.0/255
124.196.0.0/255
124.200.0.0/255
124.220.0.0/255
124.224.0.0/255
124.240.0.0/255
124.240.128.0/255
124.242.0.0/255
124.243.192.0/255
124.248.1.0/255
124.248.11.0/255
124.248.22.0/255
124.248.33.0/255
124.248.44.0/255
124.248.55.0/255
124.248.66.0/255
124.248.77.0/255
124.248.88.0/255
124.248.99.0/255
124.248.111.0/255
124.249.0.0/255
124.250.0.0/255
124.254.1.0/255
124.254.11.0/255
124.254.22.0/255
124.254.33.0/255
124.254.44.0/255
125.31.192.0/255
125.32.0.0/255
125.58.128.0/255
125.61.128.0/255
125.62.1.0/255
125.62.11.0/255
125.64.0.0/255
125.96.0.0/255
125.98.0.0/255
125.104.0.0/255
125.112.0.0/255
125.169.0.0/255
125.171.0.0/255
125.208.20.0/255
125.208.30.0/255
125.210.0.0/255
125.213.5.0/255
125.213.15.0/255
125.213.25.0/255
125.213.35.0/255
125.213.45.0/255
125.213.55.0/255
125.213.65.0/255
125.213.75.0/255
125.213.85.0/255
125.213.95.0/255
125.213.100.0/255
125.213.105.0/255
125.213.115.0/255
125.213.125.0/255
125.213.126.0/255
125.214.96.0/255
125.215.25.0/255
125.215.33.0/255
125.216.0.0/255
125.254.128.0/255
159.226.0.0/255
161.207.1.0/255
161.207.11.0/255
161.207.18.0/255
162.105.0.0/255
166.111.0.0/255
167.139.0.0/255
168.160.0.0/255
169.211.1.0/255
192.124.154.0/255
202.0.100.0/255
202.0.101.0/255
202.0.176.0/255
202.4.128.0/255
202.4.252.0/255
202.8.128.0/255
202.10.64.0/255
202.14.88.0/255
202.14.235.0/255
202.14.236.0/255
202.14.238.0/255
202.20.120.0/255
202.22.248.0/255
202.38.0.0/255
202.38.64.0/255
202.38.128.0/255
202.38.136.0/255
202.38.138.0/255
202.38.140.0/255
202.38.146.0/255
202.38.149.0/255
202.38.150.0/255
202.38.152.0/255
202.38.156.0/255
202.38.158.0/255
202.38.160.0/255
202.38.164.0/255
202.38.168.0/255
202.38.176.0/255
202.38.184.0/255
202.38.192.0/255
202.41.152.0/255
202.41.240.0/255
202.43.144.0/255
202.46.32.0/255
202.46.224.0/255
202.60.112.0/255
202.63.248.0/255
202.69.4.0/255
202.69.16.0/255
202.70.20.0/255
202.70.22.0/255
202.74.8.0/255
202.75.208.0/255
202.85.208.0/255
202.90.1.0/255
202.90.2.0/255
202.90.3.0/255
202.90.224.0/255
202.91.1.0/255
202.91.105.0/255
202.91.111.0/255
202.91.128.0/255
202.91.176.0/255
202.91.224.0/255
202.92.0.0/255
202.92.252.0/255
202.93.2.0/255
202.93.3.0/255
202.93.252.0/255
202.95.13.0/255
202.95.23.0/255
202.95.25.0/255
202.95.252.0/255
202.96.0.0/255
202.112.0.0/255
202.120.0.0/255
202.122.1.0/255
202.122.6.0/255
202.122.32.0/255
202.122.64.0/255
202.122.112.0/255
202.122.128.0/255
202.123.96.0/255
202.124.24.0/255
202.125.176.0/255
202.127.0.0/255
202.127.12.0/255
202.127.16.0/255
202.127.40.0/255
202.127.48.0/255
202.127.112.0/255
202.127.128.0/255
202.127.160.0/255
202.127.192.0/255
202.127.208.0/255
202.127.212.0/255
202.127.216.0/255
202.127.224.0/255
202.130.1.0/255
202.130.12.0/255
202.130.19.0/255
202.130.224.0/255
202.131.16.0/255
202.131.48.0/255
202.131.208.0/255
202.136.48.0/255
202.136.208.0/255
202.136.224.0/255
202.141.160.0/255
202.142.16.0/255
202.143.16.0/255
202.148.96.0/255
202.149.160.0/255
202.149.224.0/255
202.150.16.0/255
202.152.176.0/255
202.153.48.0/255
202.158.160.0/255
202.160.176.0/255
202.164.2.0/255
202.164.11.0/255
202.164.13.0/255
202.164.15.0/255
202.165.96.0/255
202.165.176.0/255
202.165.208.0/255
202.168.160.0/255
202.170.128.0/255
202.170.216.0/255
202.173.8.0/255
202.173.224.0/255
202.179.240.0/255
202.180.128.0/255
202.181.112.0/255
202.189.80.0/255
202.192.0.0/255
203.18.50.0/255
203.79.8.0/255
203.79.9.0/255
203.79.10.0/255
203.80.144.0/255
203.81.16.0/255
203.83.56.0/255
203.86.0.0/255
203.86.64.0/255
203.88.32.0/255
203.88.192.0/255
203.89.1.0/255
203.89.11.0/255
203.89.15.0/255
203.90.1.0/255
203.90.8.0/255
203.90.9.0/255
203.90.10.0/255
203.90.11.0/255
203.90.128.0/255
203.90.192.0/255
203.91.32.0/255
203.91.96.0/255
203.91.120.0/255
203.92.1.0/255
203.92.2.0/255
203.92.3.0/255
203.92.160.0/255
203.93.0.0/255
203.94.1.0/255
203.94.11.0/255
203.94.22.0/255
203.94.29.0/255
203.95.0.0/255
203.95.96.0/255
203.99.16.0/255
203.99.80.0/255
203.100.32.0/255
203.100.33.0/255
203.100.44.0/255
203.100.48.0/255
203.100.51.0/255
203.100.52.0/255
203.100.53.0/255
203.100.54.0/255
203.100.55.0/255
203.100.96.0/255
203.100.192.0/255
203.110.160.0/255
203.118.192.0/255
203.119.24.0/255
203.119.32.0/255
203.128.32.0/255
203.128.96.0/255
203.130.32.0/255
203.132.32.0/255
203.134.240.0/255
203.135.96.0/255
203.135.160.0/255
203.142.219.0/255
203.148.1.0/255
203.148.11.0/255
203.148.22.0/255
203.148.33.0/255
203.152.64.0/255
203.156.192.0/255
203.158.16.0/255
203.161.192.0/255
203.166.160.0/255
203.171.224.0/255
203.174.7.0/255
203.174.96.0/255
203.175.128.0/255
203.175.192.0/255
203.176.168.0/255
203.184.80.0/255
203.187.160.0/255
203.190.96.0/255
203.191.16.0/255
203.191.64.0/255
203.191.144.0/255
203.192.3.0/255
203.192.7.0/255
203.192.8.0/255
203.192.9.0/255
203.192.10.0/255
203.192.11.0/255
203.196.12.0/255
203.207.64.0/255
203.207.128.0/255
203.208.19.0/255
203.208.18.0/255
203.208.16.0/255
203.208.1.0/255
203.208.32.0/255
203.209.224.0/255
203.212.80.0/255
203.212.85.0/255
203.222.192.0/255
210.2.1.0/255
210.2.11.0/255
210.2.14.0/255
210.5.1.0/255
210.5.11.0/255
210.5.21.0/255
210.5.28.0/255
210.5.144.0/255
210.12.0.0/255
210.14.64.0/255
210.14.112.0/255
210.14.128.0/255
210.15.1.0/255
210.15.11.0/255
210.15.22.0/255
210.15.33.0/255
210.15.44.0/255
210.15.55.0/255
210.15.66.0/255
210.15.77.0/255
210.16.128.0/255
210.21.0.0/255
210.22.0.0/255
210.23.32.0/255
210.25.1.0/255
210.25.11.0/255
210.25.111.0/255
210.26.0.0/255
210.28.0.0/255
210.32.0.0/255
210.51.1.0/255
210.51.11.0/255
210.51.44.0/255
210.52.1.0/255
210.52.12.0/255
210.52.22.0/255
210.52.44.0/255
210.52.66.0/255
210.56.192.0/255
210.72.1.0/255
210.72.11.0/255
210.72.22.0/255
210.76.0.0/255
210.78.0.0/255
210.79.64.0/255
210.79.224.0/255
210.82.0.0/255
210.87.128.0/255
210.185.192.0/255
210.192.96.0/255
211.64.0.0/255
211.80.0.0/255
211.96.0.0/255
211.136.0.0/255
211.144.0.0/255
211.160.0.0/255
218.0.0.0/255
218.56.0.0/255
218.64.0.0/255
218.96.0.0/255
218.104.0.0/255
218.108.0.0/255
218.185.192.0/255
218.192.0.0/255
218.240.1.0/255
218.240.11.0/255
218.240.22.0/255
218.240.33.0/255
218.240.44.0/255
218.240.55.0/255
218.240.66.0/255
218.240.77.0/255
218.240.88.0/255
218.240.99.0/255
218.240.111.0/255
218.240.122.0/255
218.240.133.0/255
218.240.144.0/255
218.240.177.0/255
218.240.215.0/255
218.249.0.0/255
219.72.1.0/255
219.72.2.0/255
219.82.0.0/255
219.128.0.0/255
219.216.0.0/255
219.224.0.0/255
219.242.0.0/255
219.244.0.0/255
220.101.192.0/255
220.112.0.0/255
220.152.128.0/255
220.154.1.0/255
220.154.6.0/255
220.160.0.0/255
220.192.0.0/255
220.231.0.0/255
220.231.128.0/255
220.232.64.0/255
220.234.0.0/255
220.242.1.0/255
220.242.11.0/255
220.242.111.0/255
220.248.0.0/255
220.252.0.0/255
221.0.0.0/255
221.8.0.0/255
221.12.0.0/255
221.12.128.0/255
221.13.0.0/255
221.14.0.0/255
221.122.0.0/255
221.129.0.0/255
221.130.0.0/255
221.133.224.0/255
221.136.0.0/255
221.172.1.0/255
221.172.12.0/255
221.172.21.0/255
221.176.0.0/255
221.192.0.0/255
221.196.0.0/255
221.198.0.0/255
221.199.0.0/255
221.199.128.0/255
221.199.192.0/255
221.199.224.0/255
221.200.0.0/255
221.208.0.0/255
221.224.0.0/255
222.16.0.0/255
222.32.0.0/255
222.64.0.0/255
222.125.0.0/255
222.126.128.0/255
222.128.0.0/255
222.160.0.0/255
222.168.0.0/255
222.176.0.0/255
222.192.0.0/255
222.240.0.0/255
222.248.0.0/255
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; Maxthon 2.0)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322) QQBrowser/6.8.10793.201
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; GreenBrowser)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; 360SE)
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.11 (KHTML, like Gecko) Chrome/9.0.570.0 Safari/534.11
Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8
Mozilla/5.0 (Windows NT 5.2; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Opera/9.80 (Windows NT 5.2; U; zh-cn) Presto/2.9.168 Version/11.51
(Windows NT 5.2; U; zh-cn) Presto/2.9.168 Version/11.51
Mozilla/8.0 (compatible; MSIE 5.0; Windows NT 5.5; SV7; QQDownload 530; QQPinyin 618; GTB7.3; NET CLR 8.0.38189)
\Microsoft\Network\Connections\pbk\rasphone.pbk
chengduhr_qljy err.txt
0,0,0,0,0
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
chengduhr_qljy.exe
\\.\PHYSICALDRIVE
\\.\SCSI
\\.\SMARTVSD
A\\.\PhysicalDrive0
00:00:00
F%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
__MSVCRT_HEAP_SELECT
iphlpapi.dll
SHLWAPI.dll
MPR.dll
VERSION.dll
WSOCK32.dll
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
\\.\Scsi0:
\\.\PhysicalDrive0
%s:%d
icmp.dll
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
%d / %d
Bogus message code %d
(%d-%d):
%ld%c
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
index.dat
desktop.ini
hXXp://VVV.baidu.com
msctls_hotkey32
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
zcÁ
c:\%original file name%.exe
#include "l.chs\afxres.rc" // Standard components
GetCPInfo
WinExec
GetProcessHeap
RegOpenKeyExA
RegCloseKey
RegCreateKeyExA
GetViewportExtEx
GetViewportOrgEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
ShellExecuteA
EnumChildWindows
EnumThreadWindows
UnhookWindowsHookEx
SetWindowsHookExA
ExitWindowsEx
CreateDialogIndirectParamA
GetKeyState
InternetOpenUrlA
DeleteUrlCacheEntry
.text
`.rdata
@.data
.rsrc
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
MSIMG32.dll
OLEAUT32.dll
RASAPI32.dll
SHELL32.dll
USER32.dll
WININET.dll
WINMM.dll
WINSPOOL.DRV
WS2_32.dll
(*.*)
4.5.5.5
VVV.shuapiaowang.com
%original file name%.exe_704_rwx_00401000_00128000:
t$(SSh
~%UVW
u$SShe
kernel32.dll
wininet.dll
ole32.dll
rasapi32.dll
ADVAPI32.DLL
advapi32.dll
Wininet.dll
user32.dll
IPHLPAPI.DLL
ws2_32.dll
Kernel32.dll
MsgWaitForMultipleObjects
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
FindFirstUrlCacheEntryA
FindNextUrlCacheEntryA
FindCloseUrlCache
DeleteUrlCacheEntryA
VVV.baidu.com
hXXp://VVV.mmwzpt.cn/mmrj/u.asp?Action=upsuccess&KEY=
hXXp://VVV.mmwzpt.cn/mmrj/zx.asp?Action=zx&taskname=chengduhr_qljy
hXXp://VVV.mmwzpt.cn/mmrj/paylist.asp?vote=chengduhr_qljy
hXXp://pv.sohu.com/cityjson?ie=gb2312
hXXp://
hXXps://
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
http=
HTTP/1.1
Accept: image/gif, image/bmp, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Content-Type: application/x-www-form-urlencoded
function time(){return new Date().getTime()}hXXp://open.baidu.com/special/time/
window.baidu_time(
hXXp://VVV.time.ac.cn/stime.asp
document.write('1970.01.01 08:00:00
WinHttp.WinHttpRequest.5.1
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
hXXp://counter.sina.com.cn/ip
C:\VOTEID.ini
haoren.chengdu.cn
hXXp://haoren.chengdu.cn/tou.php
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Referer: hXXp://haoren.chengdu.cn/list3712.html
58.14.0.0/255
58.16.0.0/255
58.24.0.0/255
58.30.0.0/255
58.32.0.0/255
58.66.0.0/255
58.68.128.0/255
58.82.1.0/255
58.82.11.0/255
58.82.22.0/255
58.82.33.0/255
58.82.111.0/255
58.82.122.0/255
58.87.64.0/255
58.100.0.0/255
58.116.0.0/255
58.128.0.0/255
58.144.0.0/255
58.154.0.0/255
58.192.0.0/255
58.240.0.0/255
59.32.0.0/255
59.64.0.0/255
59.80.0.0/255
59.107.0.0/255
59.108.0.0/255
59.151.1.0/255
59.151.12.0/255
59.155.0.0/255
59.172.0.0/255
59.191.1.0/255
59.191.11.0/255
59.191.21.0/255
59.191.31.0/255
59.191.41.0/255
59.191.51.0/255
59.191.61.0/255
59.191.71.0/255
59.191.82.0/255
59.191.92.0/255
59.191.99.0/255
59.191.111.0/255
59.191.121.0/255
59.191.124.0/255
59.191.240.0/255
60.0.0.0/255
60.55.0.0/255
60.63.0.0/255
60.160.0.0/255
60.194.0.0/255
60.200.0.0/255
60.208.0.0/255
60.232.0.0/255
60.235.0.0/255
60.245.128.0/255
60.247.0.0/255
60.252.0.0/255
60.253.128.0/255
60.255.0.0/255
61.4.80.0/255
61.4.176.0/255
61.8.160.0/255
61.28.1.0/255
61.28.52.0/255
61.28.111.0/255
61.29.128.0/255
61.45.128.0/255
61.47.128.0/255
61.48.0.0/255
61.87.192.0/255
61.128.100.0/255
61.128.111.0/255
61.128.123.0/255
61.232.0.0/255
61.236.0.0/255
61.240.0.0/255
114.28.0.0/255
114.54.0.0/255
114.60.0.0/255
114.61.0.0/255
114.62.0.0/255
114.63.0.0/255
114.68.0.0/255
114.80.0.0/255
116.1.0.0/255
116.2.0.0/255
116.4.0.0/255
116.8.0.0/255
116.13.0.0/255
116.16.0.0/255
116.52.0.0/255
116.56.0.0/255
116.58.128.0/255
116.58.208.0/255
116.60.1.0/255
116.60.21.0/255
116.60.33.0/255
116.66.1.0/255
116.66.11.0/255
116.66.18.0/255
116.66.28.0/255
116.66.44.0/255
116.66.88.0/255
116.66.111.0/255
116.66.126.0/255
116.69.0.0/255
116.70.1.0/255
116.70.11.0/255
116.70.21.0/255
116.70.33.0/255
116.70.53.0/255
116.76.0.0/255
116.89.144.0/255
116.90.184.0/255
116.95.0.0/255
116.112.0.0/255
116.116.0.0/255
116.128.1.0/255
116.128.11.0/255
116.128.22.0/255
116.192.1.0/255
116.192.11.0/255
116.192.18.0/255
116.192.111.0/255
116.192.121.0/255
116.193.16.0/255
116.193.32.0/255
116.194.2.0/255
116.194.12.0/255
116.194.22.0/255
116.196.0.0/255
116.199.11.0/255
116.199.24.0/255
116.199.66.0/255
116.199.111.0/255
116.204.0.0/255
116.207.0.0/255
116.208.0.0/255
116.212.160.0/255
116.213.64.0/255
116.213.128.0/255
116.214.32.0/255
116.214.64.0/255
116.214.65.0/255
116.214.75.0/255
116.214.79.0/255
116.215.0.0/255
116.216.1.0/255
116.216.11.0/255
116.216.33.0/255
116.224.0.0/255
116.242.0.0/255
116.243.0.0/255
116.248.0.0/255
116.252.0.0/255
116.254.128.0/255
116.255.128.0/255
117.8.0.0/255
117.21.0.0/255
117.22.0.0/255
117.23.0.0/255
117.24.0.0/255
117.25.0.0/255
117.27.0.0/255
117.28.0.0/255
117.29.0.0/255
117.30.0.0/255
117.31.0.0/255
117.32.0.0/255
117.33.0.0/255
117.34.0.0/255
117.35.0.0/255
117.36.0.0/255
117.37.0.0/255
117.38.0.0/255
117.39.0.0/255
117.40.0.0/255
117.41.0.0/255
117.42.0.0/255
117.43.0.0/255
117.44.0.0/255
117.45.0.0/255
117.53.48.0/255
117.53.176.0/255
117.57.0.0/255
117.58.1.0/255
117.58.11.0/255
117.58.33.0/255
117.58.44.0/255
117.59.0.0/255
117.60.0.0/255
117.64.0.0/255
117.72.0.0/255
117.74.64.0/255
117.74.128.0/255
117.76.0.0/255
117.79.0.0/255
117.80.0.0/255
117.81.0.0/255
117.82.0.0/255
117.83.0.0/255
117.84.0.0/255
117.85.0.0/255
117.86.0.0/255
117.87.0.0/255
117.88.0.0/255
117.89.0.0/255
117.90.0.0/255
117.103.16.0/255
117.103.128.0/255
117.106.0.0/255
117.112.0.0/255
117.120.64.0/255
117.120.128.0/255
117.121.1.0/255
117.121.11.0/255
117.121.22.0/255
117.121.33.0/255
117.121.44.0/255
117.121.55.0/255
117.121.66.0/255
117.121.77.0/255
117.121.88.0/255
117.121.99.0/255
117.121.105.0/255
117.121.111.0/255
117.121.120.0/255
117.121.125.0/255
117.121.192.0/255
117.122.128.0/255
117.128.0.0/255
118.25.0.0/255
118.26.0.0/255
118.67.112.0/255
118.72.0.0/255
118.80.0.0/255
118.81.0.0/255
118.85.0.0/255
118.88.32.0/255
118.88.64.0/255
118.88.128.0/255
118.89.0.0/255
118.91.240.0/255
118.102.16.0/255
118.112.0.0/255
118.120.0.0/255
118.124.0.0/255
118.126.0.0/255
118.132.0.0/255
118.144.1.0/255
118.144.11.0/255
118.180.0.0/255
118.181.0.0/255
118.182.0.0/255
118.183.0.0/255
118.184.0.0/255
118.185.0.0/255
118.186.0.0/255
118.188.1.0/255
118.188.6.0/255
118.188.12.0/255
118.192.1.0/255
118.192.11.0/255
118.192.71.0/255
118.192.111.0/255
118.212.0.0/255
118.224.1.0/255
118.224.11.0/255
118.224.33.0/255
118.224.44.0/255
118.228.0.0/255
118.230.0.0/255
118.239.0.0/255
118.248.0.0/255
119.0.0.0/255
119.2.2.0/255
119.2.12.0/255
119.2.22.0/255
119.2.28.0/255
119.2.128.0/255
119.3.1.0/255
119.3.11.0/255
119.3.22.0/255
119.3.33.0/255
119.4.0.0/255
119.5.0.0/255
119.6.0.0/255
119.7.0.0/255
119.10.1.0/255
119.10.11.0/255
119.10.22.0/255
119.15.136.0/255
119.16.0.0/255
119.18.192.0/255
119.18.208.0/255
119.18.224.0/255
119.19.0.0/255
119.20.0.0/255
119.27.64.0/255
119.27.160.0/255
119.27.192.0/255
119.27.210.0/255
119.27.217.0/255
119.27.252.0/255
119.30.48.0/255
119.31.192.0/255
119.32.0.0/255
119.40.1.0/255
119.40.11.0/255
119.40.22.0/255
119.40.64.0/255
119.40.128.0/255
119.41.0.0/255
119.42.12.0/255
119.42.22.0/255
119.42.136.0/255
119.42.224.0/255
119.44.0.0/255
119.48.0.0/255
119.57.1.0/255
119.57.11.0/255
119.57.22.0/255
119.57.32.0/255
119.59.128.0/255
119.60.0.0/255
119.62.0.0/255
119.63.32.0/255
119.75.208.0/255
119.78.1.0/255
119.78.5.0/255
119.80.0.0/255
119.84.0.0/255
119.88.0.0/255
119.96.0.0/255
119.108.0.0/255
119.112.0.0/255
119.128.0.0/255
119.144.0.0/255
119.148.160.0/255
119.161.128.0/255
119.162.0.0/255
119.163.0.0/255
119.164.0.0/255
119.176.0.0/255
119.235.128.0/255
119.248.0.0/255
119.253.0.0/255
119.254.0.0/255
120.0.0.0/255
120.24.0.0/255
120.31.0.0/255
120.32.0.0/255
120.33.0.0/255
120.34.0.0/255
120.35.0.0/255
120.36.0.0/255
120.37.0.0/255
120.38.0.0/255
120.39.0.0/255
120.40.0.0/255
120.41.0.0/255
120.42.0.0/255
120.43.0.0/255
120.44.0.0/255
120.48.0.0/255
120.64.0.0/255
120.72.32.0/255
120.72.128.0/255
120.80.0.0/255
120.90.0.0/255
120.92.0.0/255
120.94.0.0/255
120.128.0.0/255
120.136.128.0/255
120.137.1.0/255
120.137.2.0/255
120.137.12.0/255
120.137.22.0/255
120.137.42.0/255
120.192.0.0/255
121.0.16.0/255
121.4.0.0/255
121.8.0.0/255
121.16.0.0/255
121.32.0.0/255
121.40.1.0/255
121.40.11.0/255
121.40.22.0/255
121.46.0.0/255
121.48.0.0/255
121.51.0.0/255
121.52.160.0/255
121.52.208.0/255
121.52.224.0/255
121.55.63.0/255
121.56.0.0/255
121.57.0.0/255
121.58.0.0/255
121.58.144.0/255
121.60.0.0/255
121.68.1.0/255
121.68.11.0/255
121.68.22.0/255
121.68.111.0/255
121.69.0.0/255
121.76.0.0/255
121.79.128.0/255
121.100.128.0/255
121.101.208.0/255
121.192.1.0/255
121.192.33.0/25
121.192.66.0/25
121.192.166.0/25
121.201.1.0/255
121.201.11.0/255
121.201.77.0/255
121.201.22.0/255
121.204.0.0/255
121.224.0.0/255
121.248.0.0/255
121.255.0.0/255
122.0.64.0/255
122.0.128.0/255
122.4.0.0/255
122.8.0.0/255
122.48.0.0/255
122.49.1.0/255
122.49.11.0/255
122.49.33.0/255
122.49.44.0/255
122.64.0.0/255
122.96.0.0/255
122.102.64.0/255
122.102.65.0/255
122.102.66.0/255
122.102.67.0/255
122.102.70.0/255
122.102.71.0/255
122.102.73.0/255
122.102.75.0/255
122.102.79.0/255
122.112.0.0/255
122.113.0.0/255
122.114.0.0/255
122.115.0.0/255
122.136.0.0/255
122.144.128.0/255
122.152.192.0/255
122.156.0.0/255
122.192.0.0/255
122.198.1.0/255
122.198.11.0/255
122.198.44.0/255
122.198.66.0/255
122.200.64.0/255
122.204.0.0/255
122.224.0.0/255
122.240.0.0/255
122.248.48.0/255
123.0.128.0/255
123.4.0.0/255
123.8.0.0/255
123.49.128.0/255
123.52.0.0/255
123.56.0.0/255
123.64.0.0/255
123.96.0.0/255
123.98.22.0/255
123.98.24.0/255
123.98.25.0/255
123.99.128.0/255
123.100.1.0/255
123.100.11.0/255
123.100.22.0/255
123.100.28.0/255
123.101.0.0/255
123.103.0.0/255
123.108.128.0/255
123.108.208.0/255
123.112.0.0/255
123.128.0.0/255
123.136.80.0/255
123.137.0.0/255
123.138.0.0/255
123.144.0.0/255
123.160.0.0/255
123.176.80.0/255
123.177.0.0/255
123.178.0.0/255
123.180.0.0/255
123.184.0.0/255
123.196.1.0/255
123.196.22.0/255
123.196.33.0/255
123.199.128.0/255
123.232.0.0/255
123.242.1.0/255
123.242.11.0/255
123.242.22.0/255
123.242.44.0/255
123.242.66.0/255
123.242.77.0/255
123.242.81.0/255
123.244.0.0/255
123.249.1.0/255
123.249.11.0/255
123.249.22.0/255
123.249.33.0/255
123.249.44.0/255
123.249.55.0/255
123.249.66.0/255
123.249.77.0/255
123.249.88.0/255
123.249.99.0/255
123.249.111.0/255
123.249.126.0/255
123.249.166.0/255
123.249.188.0/255
123.249.222.0/255
123.249.223.0/255
123.253.1.0/255
123.253.11.0/255
123.253.105.0/255
123.253.111.0/255
123.253.188.0/255
123.253.222.0/255
124.6.64.0/255
124.14.0.0/255
124.16.0.0/255
124.20.0.0/255
124.28.192.0/255
124.29.1.0/255
124.29.111.0/255
124.29.121.0/255
124.31.0.0/255
124.40.112.0/255
124.40.128.0/255
124.42.0.0/255
124.47.25.0/255
124.64.0.0/255
124.66.1.0/255
124.66.11.0/255
124.66.22.0/255
124.66.33.0/255
124.66.55.0/255
124.66.77.0/255
124.66.99.0/255
124.67.0.0/255
124.68.1.0/255
124.68.2.0/255
124.68.3.0/255
124.72.0.0/255
124.88.0.0/255
124.108.8.0/255
124.108.40.0/255
124.112.0.0/255
124.126.0.0/255
124.128.0.0/255
124.147.128.0/255
124.156.1.0/255
124.156.5.0/255
124.160.0.0/255
124.172.0.0/255
124.192.0.0/255
124.196.0.0/255
124.200.0.0/255
124.220.0.0/255
124.224.0.0/255
124.240.0.0/255
124.240.128.0/255
124.242.0.0/255
124.243.192.0/255
124.248.1.0/255
124.248.11.0/255
124.248.22.0/255
124.248.33.0/255
124.248.44.0/255
124.248.55.0/255
124.248.66.0/255
124.248.77.0/255
124.248.88.0/255
124.248.99.0/255
124.248.111.0/255
124.249.0.0/255
124.250.0.0/255
124.254.1.0/255
124.254.11.0/255
124.254.22.0/255
124.254.33.0/255
124.254.44.0/255
125.31.192.0/255
125.32.0.0/255
125.58.128.0/255
125.61.128.0/255
125.62.1.0/255
125.62.11.0/255
125.64.0.0/255
125.96.0.0/255
125.98.0.0/255
125.104.0.0/255
125.112.0.0/255
125.169.0.0/255
125.171.0.0/255
125.208.20.0/255
125.208.30.0/255
125.210.0.0/255
125.213.5.0/255
125.213.15.0/255
125.213.25.0/255
125.213.35.0/255
125.213.45.0/255
125.213.55.0/255
125.213.65.0/255
125.213.75.0/255
125.213.85.0/255
125.213.95.0/255
125.213.100.0/255
125.213.105.0/255
125.213.115.0/255
125.213.125.0/255
125.213.126.0/255
125.214.96.0/255
125.215.25.0/255
125.215.33.0/255
125.216.0.0/255
125.254.128.0/255
159.226.0.0/255
161.207.1.0/255
161.207.11.0/255
161.207.18.0/255
162.105.0.0/255
166.111.0.0/255
167.139.0.0/255
168.160.0.0/255
169.211.1.0/255
192.124.154.0/255
202.0.100.0/255
202.0.101.0/255
202.0.176.0/255
202.4.128.0/255
202.4.252.0/255
202.8.128.0/255
202.10.64.0/255
202.14.88.0/255
202.14.235.0/255
202.14.236.0/255
202.14.238.0/255
202.20.120.0/255
202.22.248.0/255
202.38.0.0/255
202.38.64.0/255
202.38.128.0/255
202.38.136.0/255
202.38.138.0/255
202.38.140.0/255
202.38.146.0/255
202.38.149.0/255
202.38.150.0/255
202.38.152.0/255
202.38.156.0/255
202.38.158.0/255
202.38.160.0/255
202.38.164.0/255
202.38.168.0/255
202.38.176.0/255
202.38.184.0/255
202.38.192.0/255
202.41.152.0/255
202.41.240.0/255
202.43.144.0/255
202.46.32.0/255
202.46.224.0/255
202.60.112.0/255
202.63.248.0/255
202.69.4.0/255
202.69.16.0/255
202.70.20.0/255
202.70.22.0/255
202.74.8.0/255
202.75.208.0/255
202.85.208.0/255
202.90.1.0/255
202.90.2.0/255
202.90.3.0/255
202.90.224.0/255
202.91.1.0/255
202.91.105.0/255
202.91.111.0/255
202.91.128.0/255
202.91.176.0/255
202.91.224.0/255
202.92.0.0/255
202.92.252.0/255
202.93.2.0/255
202.93.3.0/255
202.93.252.0/255
202.95.13.0/255
202.95.23.0/255
202.95.25.0/255
202.95.252.0/255
202.96.0.0/255
202.112.0.0/255
202.120.0.0/255
202.122.1.0/255
202.122.6.0/255
202.122.32.0/255
202.122.64.0/255
202.122.112.0/255
202.122.128.0/255
202.123.96.0/255
202.124.24.0/255
202.125.176.0/255
202.127.0.0/255
202.127.12.0/255
202.127.16.0/255
202.127.40.0/255
202.127.48.0/255
202.127.112.0/255
202.127.128.0/255
202.127.160.0/255
202.127.192.0/255
202.127.208.0/255
202.127.212.0/255
202.127.216.0/255
202.127.224.0/255
202.130.1.0/255
202.130.12.0/255
202.130.19.0/255
202.130.224.0/255
202.131.16.0/255
202.131.48.0/255
202.131.208.0/255
202.136.48.0/255
202.136.208.0/255
202.136.224.0/255
202.141.160.0/255
202.142.16.0/255
202.143.16.0/255
202.148.96.0/255
202.149.160.0/255
202.149.224.0/255
202.150.16.0/255
202.152.176.0/255
202.153.48.0/255
202.158.160.0/255
202.160.176.0/255
202.164.2.0/255
202.164.11.0/255
202.164.13.0/255
202.164.15.0/255
202.165.96.0/255
202.165.176.0/255
202.165.208.0/255
202.168.160.0/255
202.170.128.0/255
202.170.216.0/255
202.173.8.0/255
202.173.224.0/255
202.179.240.0/255
202.180.128.0/255
202.181.112.0/255
202.189.80.0/255
202.192.0.0/255
203.18.50.0/255
203.79.8.0/255
203.79.9.0/255
203.79.10.0/255
203.80.144.0/255
203.81.16.0/255
203.83.56.0/255
203.86.0.0/255
203.86.64.0/255
203.88.32.0/255
203.88.192.0/255
203.89.1.0/255
203.89.11.0/255
203.89.15.0/255
203.90.1.0/255
203.90.8.0/255
203.90.9.0/255
203.90.10.0/255
203.90.11.0/255
203.90.128.0/255
203.90.192.0/255
203.91.32.0/255
203.91.96.0/255
203.91.120.0/255
203.92.1.0/255
203.92.2.0/255
203.92.3.0/255
203.92.160.0/255
203.93.0.0/255
203.94.1.0/255
203.94.11.0/255
203.94.22.0/255
203.94.29.0/255
203.95.0.0/255
203.95.96.0/255
203.99.16.0/255
203.99.80.0/255
203.100.32.0/255
203.100.33.0/255
203.100.44.0/255
203.100.48.0/255
203.100.51.0/255
203.100.52.0/255
203.100.53.0/255
203.100.54.0/255
203.100.55.0/255
203.100.96.0/255
203.100.192.0/255
203.110.160.0/255
203.118.192.0/255
203.119.24.0/255
203.119.32.0/255
203.128.32.0/255
203.128.96.0/255
203.130.32.0/255
203.132.32.0/255
203.134.240.0/255
203.135.96.0/255
203.135.160.0/255
203.142.219.0/255
203.148.1.0/255
203.148.11.0/255
203.148.22.0/255
203.148.33.0/255
203.152.64.0/255
203.156.192.0/255
203.158.16.0/255
203.161.192.0/255
203.166.160.0/255
203.171.224.0/255
203.174.7.0/255
203.174.96.0/255
203.175.128.0/255
203.175.192.0/255
203.176.168.0/255
203.184.80.0/255
203.187.160.0/255
203.190.96.0/255
203.191.16.0/255
203.191.64.0/255
203.191.144.0/255
203.192.3.0/255
203.192.7.0/255
203.192.8.0/255
203.192.9.0/255
203.192.10.0/255
203.192.11.0/255
203.196.12.0/255
203.207.64.0/255
203.207.128.0/255
203.208.19.0/255
203.208.18.0/255
203.208.16.0/255
203.208.1.0/255
203.208.32.0/255
203.209.224.0/255
203.212.80.0/255
203.212.85.0/255
203.222.192.0/255
210.2.1.0/255
210.2.11.0/255
210.2.14.0/255
210.5.1.0/255
210.5.11.0/255
210.5.21.0/255
210.5.28.0/255
210.5.144.0/255
210.12.0.0/255
210.14.64.0/255
210.14.112.0/255
210.14.128.0/255
210.15.1.0/255
210.15.11.0/255
210.15.22.0/255
210.15.33.0/255
210.15.44.0/255
210.15.55.0/255
210.15.66.0/255
210.15.77.0/255
210.16.128.0/255
210.21.0.0/255
210.22.0.0/255
210.23.32.0/255
210.25.1.0/255
210.25.11.0/255
210.25.111.0/255
210.26.0.0/255
210.28.0.0/255
210.32.0.0/255
210.51.1.0/255
210.51.11.0/255
210.51.44.0/255
210.52.1.0/255
210.52.12.0/255
210.52.22.0/255
210.52.44.0/255
210.52.66.0/255
210.56.192.0/255
210.72.1.0/255
210.72.11.0/255
210.72.22.0/255
210.76.0.0/255
210.78.0.0/255
210.79.64.0/255
210.79.224.0/255
210.82.0.0/255
210.87.128.0/255
210.185.192.0/255
210.192.96.0/255
211.64.0.0/255
211.80.0.0/255
211.96.0.0/255
211.136.0.0/255
211.144.0.0/255
211.160.0.0/255
218.0.0.0/255
218.56.0.0/255
218.64.0.0/255
218.96.0.0/255
218.104.0.0/255
218.108.0.0/255
218.185.192.0/255
218.192.0.0/255
218.240.1.0/255
218.240.11.0/255
218.240.22.0/255
218.240.33.0/255
218.240.44.0/255
218.240.55.0/255
218.240.66.0/255
218.240.77.0/255
218.240.88.0/255
218.240.99.0/255
218.240.111.0/255
218.240.122.0/255
218.240.133.0/255
218.240.144.0/255
218.240.177.0/255
218.240.215.0/255
218.249.0.0/255
219.72.1.0/255
219.72.2.0/255
219.82.0.0/255
219.128.0.0/255
219.216.0.0/255
219.224.0.0/255
219.242.0.0/255
219.244.0.0/255
220.101.192.0/255
220.112.0.0/255
220.152.128.0/255
220.154.1.0/255
220.154.6.0/255
220.160.0.0/255
220.192.0.0/255
220.231.0.0/255
220.231.128.0/255
220.232.64.0/255
220.234.0.0/255
220.242.1.0/255
220.242.11.0/255
220.242.111.0/255
220.248.0.0/255
220.252.0.0/255
221.0.0.0/255
221.8.0.0/255
221.12.0.0/255
221.12.128.0/255
221.13.0.0/255
221.14.0.0/255
221.122.0.0/255
221.129.0.0/255
221.130.0.0/255
221.133.224.0/255
221.136.0.0/255
221.172.1.0/255
221.172.12.0/255
221.172.21.0/255
221.176.0.0/255
221.192.0.0/255
221.196.0.0/255
221.198.0.0/255
221.199.0.0/255
221.199.128.0/255
221.199.192.0/255
221.199.224.0/255
221.200.0.0/255
221.208.0.0/255
221.224.0.0/255
222.16.0.0/255
222.32.0.0/255
222.64.0.0/255
222.125.0.0/255
222.126.128.0/255
222.128.0.0/255
222.160.0.0/255
222.168.0.0/255
222.176.0.0/255
222.192.0.0/255
222.240.0.0/255
222.248.0.0/255
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; Maxthon 2.0)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322) QQBrowser/6.8.10793.201
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; GreenBrowser)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; 360SE)
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.11 (KHTML, like Gecko) Chrome/9.0.570.0 Safari/534.11
Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8
Mozilla/5.0 (Windows NT 5.2; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
Opera/9.80 (Windows NT 5.2; U; zh-cn) Presto/2.9.168 Version/11.51
(Windows NT 5.2; U; zh-cn) Presto/2.9.168 Version/11.51
Mozilla/8.0 (compatible; MSIE 5.0; Windows NT 5.5; SV7; QQDownload 530; QQPinyin 618; GTB7.3; NET CLR 8.0.38189)
\Microsoft\Network\Connections\pbk\rasphone.pbk
chengduhr_qljy err.txt
0,0,0,0,0
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
chengduhr_qljy.exe
\\.\PHYSICALDRIVE
\\.\SCSI
\\.\SMARTVSD
A\\.\PhysicalDrive0
00:00:00
F%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
__MSVCRT_HEAP_SELECT
iphlpapi.dll
SHLWAPI.dll
MPR.dll
VERSION.dll
WSOCK32.dll
.PAVCException@@
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
.PAVCFileException@@
: %d]
(*.*)|*.*||
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
\\.\Scsi0:
\\.\PhysicalDrive0
%s:%d
icmp.dll
windows
.PAVCNotSupportedException@@
out.prn
(*.prn)|*.prn|
%d.%d
%d/%d
%d / %d
Bogus message code %d
(%d-%d):
%ld%c
%s <%s>
Reply-To: %s
From: %s
To: %s
Subject: %s
Date: %s
Cc: %s
%a, %d %b %Y %H:%M:%S
SMTP
index.dat
desktop.ini
hXXp://VVV.baidu.com
msctls_hotkey32
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
zcÁ
c:\%original file name%.exe
#include "l.chs\afxres.rc" // Standard components
GetCPInfo
WinExec
GetProcessHeap
RegOpenKeyExA
RegCloseKey
RegCreateKeyExA
GetViewportExtEx
GetViewportOrgEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
ShellExecuteA
EnumChildWindows
EnumThreadWindows
UnhookWindowsHookEx
SetWindowsHookExA
ExitWindowsEx
CreateDialogIndirectParamA
GetKeyState
InternetOpenUrlA
DeleteUrlCacheEntry
.text
`.rdata
@.data
.rsrc
(*.*)
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\cityjson[1] (78 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.