sub_40D53F(0509): "NOTICE %s :" "PRIVMSG %s :" "\r\n" |
sub_4043E9(05b8): "80" |
sub_409DD0(060f): "ICMP.DLL" "IcmpCreateFile" "IcmpSendEcho" "IcmpCloseHandle" "Could not resolve name" |
sub_41673F(09bb): "rb" |
sub_4093B6(0cc7): "btg" "thread" |
sub_40D4AB(1035): "PRIVMSG %s :" "\r\n" |
sub_415AF0(1472): "Internet explorer password stealer" |
sub_406D90(1503): ".bat" "@echo off\r\n:deleteagain\r\ndel /A:H /F %s"... "open" |
sub_4088FC(152c): "80" "GET /%s HTTP/1.0\r\nHost: %s\r\n\r\n" |
sub_40A8AD(3823): "abcdef" |
sub_406C51(4aab): "Software\\Microsoft\\Windows\\CurrentVersi"... |
sub_4038BA(4c15): "udp" |
sub_414052(4fa7): "Exploit statistics - " |
sub_40D043(5675): "PASS %s" "USER %s %s %s :%s" "UNK" "B" "A" "G" "%c%s%c%c%u%c%u%s%c%c%c" |
sub_411BBC(5919): "127.0.0.1" |
sub_4017AA(5a0a): "Listing" "Killing" |
sub_414A1E(5a21): "rb" "\r\n\r\n[" "\r\nIP=" "\r\nPort=" "\r\nUser=" "\r\nPass=" "[%[^]]]\r\n" "\r\nIP=%127s\r\n" "\r\nPort=%127s\r\n" "\r\nUser=%127s\r\n" "\r\nPass=%127s\r\n" |
sub_416711(5c60): "rb" |
sub_413FE7(5e87): "Attempting to exploit IP's in list." |
sub_407148(629b): "QUIT :%s uninstalled." "Windows DLL Loader" "QUIT :%s uninstalled." |
sub_4091E2(65f1): "Driveinfo thread" |
sub_4097A7(69ab): "*%s*" |
sub_4083AD(6a7b): "?" "no SP" "95" "NT" "98" "ME" "2000" "XP" "2003" "Yes" "No" "HARDWARE\\DESCRIPTION\\System\\CentralProc"... "ProcessorNameString" |
sub_41308F(6de7): "OPTIONS / HTTP/1.0\r\n\r\n" "Server:" "Microsoft-IIS" "Microsoft-IIS/%u.%u" "Apache" |
sub_414EB0(6e80): "FlashFXP password stealer" |
sub_4147E5(6ee3): "yA36zA48dEhfrvghGRg57h5UlDv3" "yA36zA48dEhfrvghGRg57h5UlDv3" |
sub_408B30(70db): "Unknown" "Unknown" "Modem" "LAN" "Yes" "No" "Yes" "No" "Bad" "Avarage" "Good" |
sub_41417D(726a): "Listing exploit statistics" |
sub_4142BF(74ca): "80" |
sub_4020C2(7599): "rb" "DCC Send %s (%s)" |
sub_40D734(7c17): "mIRC" |
sub_411DC5(819f): "rb" "octet" "octet" "wormride" |
sub_401D6E(859f): "open" "Remote cmd thread" "\r\n" "Error while executing command." |
sub_41113B(8dbe): "%u,%u,%u,%u,%u,%u" "rb" "150 -\r\n" "rb" "-x 3 2000 fh 1024 Jan 1 0:00 .\r\ndrwxr-x"... "150 -\r\n" "ftp" "221 -\r\n" "231 -\r\n" |
sub_414EF4(8f0e): "%x" "%ws" "220d5cc1" "5e7e8100" ":" ":" ":" "b9819c52" "e161255a" "StringIndex" |
sub_4094E6(8f32): "thread" |
sub_40CF2F(913e): "6667" |
sub_4055E5(93f0): "%u\r\n" "%u.%u.%u.%u:%u\r\n" "%u\r\n" "%u.%u.%u.%u:%u\r\n" "%u\r\n" "%u.%u.%u.%u:%u\r\n" "%u\r\n" "%u.%u.%u.%u:%u\r\n" |
sub_405E45(94e4): "LG flooder" |
sub_40CEB0(975e): "Executing command(s): %s" |
sub_408808(983f): "80" |
sub_415DFD(9871): "Listing interesting processes" |
sub_40D420(a5e3): "NOTICE %s :" "\r\n" |
sub_408F2E(ab4d): "Drive information - " "removable" "fixed" "remote" "cd-rom" "ramdisk" "unknown" |
sub_401981(ac1d): "cmd.exe" "Could not read data from process." "Cmd.exe process has terminated." |
sub_4127D0(aca4): "rb" |
sub_415B60(af11): "Unreal3" "World Of Warcraft" "[Conquer]" "SOFTWARE\\Microsoft\\VisualStudio\\6.0\\Set"... "Software\\Valve\\Steam" "Yes" "No" "Yes" "No" "Yes" "No" "Yes" "No" "Yes" "No" |
sub_403DF3(b5a9): " : USERID : UNIX : " "\r\n" |
sub_40CA29(b7e9): ")" "&&" "%32s %16s %32s" "$uptime" "$version" "$free" "$latency" "$firewall" "$ipv6" "$uptime" "$version" "$free" "$latency" "$firewall" "$ipv6" "==" "!=" ">" ">=" "<=" "&&" |
sub_4148CE(b829): "SOFTWARE\\Classes\\Applications\\FlashFXP."... "sites.dat" "ProgramFiles" "\\FlashFXP\\sites.dat" "rb" "%sFlashFXP\\sites.dat" "rb" |
sub_40D6CB(ba86): "\r\n" |
sub_411D68(bd90): "FTP wormride thread" |
sub_4123F6(bf6b): "TFTP wormride thread" |
sub_40E618(c143): "302" "PRIVMSG" "NOTICE" |
sub_406041(c2bf): "system" |
sub_409CB1(c41b): "Could not get a valid ICMP handle\n" |
sub_406E8E(c805): "Windows DLL Loader" |
sub_402A32(c93b): "http://" "80" "ftp://" "21" "anonymous" "anonymous" "tftp://" "69" ":" "/" "open" |
sub_40332B(d6d5): "EXCEPTION_OTHER" "EXCEPTION_ACCESS_VIOLATION" "EXCEPTION_BREAKPOINT" "EXCEPTION_ILLEGAL_INSTRUCTION" "EXCEPTION_INT_DIVIDE_BY_ZERO" "EXCEPTION_NONCONTINUABLE_EXCEPTION" "EXCEPTION_STACK_OVERFLOW" "EXCEPTION_FLT" "Restarting" "Continuing" "open" "QUIT :exitting" "QUIT :restarting" "QUIT :restarting" |
sub_4098F3(d7a4): "*%s*" |
sub_405FA3(d81a): "psapi.dll" "EnumProcessModules" "GetModuleFileNameExA" "GetModuleInformation" |
sub_40C93C(dd51): ";" "link!link@link PRIVMSG %s :%s" ";" |
sub_402698(e10f): "GET /%s HTTP/1.0\r\nHost: %s\r\n\r\n" "\r\n\r\n" "Content-Length: %u\r\n" |
sub_41102F(e43a): "rb" |
sub_406722(e784): "HKCR" "HKCU" "HKLM" "HKUS" |
sub_406AE7(f004): "rb" |
sub_40D871(f33c): "PING" "PONG %s" "PONG" "MODE" "PRIVMSG" "SEND" "eggdrop v1.6.16" "433" "UNK" "B" "A" "G" "%c%s%c%c%u%c%u%s%c%c%c" "ERROR" "JOIN" "MODE %s +smntu" "001" "MODE %s +xi" "USERHOST %s" "USERHOST %s" "451" "302" "@" "NICK" "332" "][" "link!link@link PRIVMSG %s :%s" "][" "PRIVMSG" "NOTICE" "*" |
sub_40A9CF(f341): "This build is fully functional" "This build is broken and will not funct"... "It took me %ums." "on" "off" "on" "QUIT :exitting" "open" "QUIT :restarting" "QUIT :changing server" "2002" "9252" "id" "username" |
sub_403BD3(f523): "kernel32.dll" "InitializeCriticalSectionAndSpinCount" "netapi32.dll" "NetUseAdd" "NetUseDel" "NetUserEnum" "NetShareEnum" "NetRemoteTOD" "NetApiBufferFree" "NetScheduleJobAdd" "NetAddAlternateComputerName" "mpr.dll" "WNetAddConnection2A" "WNetAddConnection2W" "WNetCancelConnection2A" "WNetCancelConnection2W" "ws2_32.dll" "getaddrinfo" "getnameinfo" "freeaddrinfo" "pstorec.dll" "PStoreCreateInstance" "wininet.dll" "InternetGetConnectedStateExA" |
sub_40D74D(f68e): "mIRC" |
sub_4129CA(f764): "unknown" |