HEUR:Trojan.Win32.Generic (Kaspersky), Backdoor.Win32.Xtrat.FD, GenericAutorunWorm.YR, GenericInjector.YR, TrojanDropperVtimrun.YR (Lavasoft MAS)Behaviour: Trojan-Dropper, Trojan, Backdoor, Worm, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: a4d5f9d7a3b05a03391c284d5caac24a
SHA1: 6003f14e2738fe916f65e54d1681da7fcd10d2e3
SHA256: d1b4f26e0054447e89a16d4e27c26b53f95b7c4c945f90a469d40d26ee7d3a61
SSDeep: 12288:6Q2S7PgV49x0Yp8FtIoGMHYOaDZsSblkcbMEJjfa2ya/3u42BKsAlg:6Q2ogWIy 74OaFsIbTDa2y63utKs0g
Size: 735744 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-10-14 08:50:27
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan-Dropper's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The Trojan-Dropper creates the following process(es):
%original file name%.exe:1908
00.exe:684
.exe:2996
The Trojan-Dropper injects its code into the following process(es):
CARDGE~1.EXE:2700
iexplore.exe:1204
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1908 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe (2924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE (12280 bytes)
The process 00.exe:684 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new (808 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aLLLLL.xml (1 bytes)
The Trojan-Dropper deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aLLLLL.xml (0 bytes)
The process .exe:2996 makes changes in the file system.
The Trojan-Dropper deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\x.html (0 bytes)
The process CARDGE~1.EXE:2700 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\icon5[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\facebook[1].png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\w3ccss[1].gif (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\tcat_left[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\vbulletin_global[1].js (11653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\vbulletin_important[1].css (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3UBMK0P4.txt (87 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon2[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\close[1].gif (428 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon3[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\bg_tile[1].gif (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\larme[1].jpg (1412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gradient_tcat[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\username[1].png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017022720170228\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\connection-min[1].js (6176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\whos_online[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\subforum_old[1].gif (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\password[1].png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\51[1].gif (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav_final[1].gif (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_md5[1].js (213 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\sa1[1].jpg (5276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon1[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\vbulletin_menu[1].js (6412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\clear[1].gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav_bg_small[1].gif (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\stats[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\forum_old[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gdtmvRl[1].gif (8805 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head3[1].gif (1987 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\gradient_thead[1].gif (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\navbits_start[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\twitter[1].png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon7[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\L3Zd0Sx[1].gif (23847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head1[1].gif (2119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\yahoo-dom-event[1].js (20761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\altenen_com[1].htm (758 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\GX1OvJc[1].gif (47449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon6[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\collapse_tcat[1].gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\forum_new[1].gif (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\collapse_thead[1].gif (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\w3cxhtml[1].gif (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\altenen_com[1].htm (22246 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A1KUF342.txt (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\nav[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head2[1].gif (3596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\lastpost[1].gif (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\pid[1] (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head4[1].gif (8 bytes)
The Trojan-Dropper deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016101020161017 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\altenen_com[1].htm (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016102820161029 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3UBMK0P4.txt (0 bytes)
Registry activity
The process %original file name%.exe:1908 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan-Dropper adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"
The process 00.exe:684 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan-Dropper deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process .exe:2996 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
[HKCU\Software\XtremeRAT]
"Mutex" = "C6fjs5R2Pz"
The process CARDGE~1.EXE:2700 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"EnableConsoleTracing" = "0"
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"EnableConsoleTracing" = "0"
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017022720170228]
"CacheRepair" = "0"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"aFormatTagCache" = "01 00 00 00 10 00 00 00 55 00 00 00 1E 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"cFormatTags" = "2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017022720170228]
"CachePrefix" = ":2017022720170228:"
"CacheLimit" = "8192"
"CachePath" = "%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017022720170228"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"cFilterTags" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"fdwSupport" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017022720170228]
"CacheOptions" = "11"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"ConsoleTracingMask" = "4294901760"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Dropper deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016101020161017]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016102820161029]
The Trojan-Dropper deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
Dropped PE files
MD5 | File path |
---|---|
54a47f6b5e09a77e61649109c6a08866 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe |
8f50bbb29eb9f40c7aca521f672fabc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe |
ef87d6b587f71d7c2b865fbb27e97fcd | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE |
8f50bbb29eb9f40c7aca521f672fabc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe |
54a47f6b5e09a77e61649109c6a08866 | c:\Windows\System32\InstallDir\svchost.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan-Dropper's file once a user opens a drive's folder in Windows Explorer.
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1908
00.exe:684
.exe:2996 - Delete the original Trojan-Dropper file.
- Delete or disinfect the following files created/modified by the Trojan-Dropper:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe (2924 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE (12280 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new (808 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aLLLLL.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\icon5[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\facebook[1].png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\w3ccss[1].gif (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\tcat_left[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\vbulletin_global[1].js (11653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\vbulletin_important[1].css (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3UBMK0P4.txt (87 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon2[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\close[1].gif (428 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon3[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\bg_tile[1].gif (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\larme[1].jpg (1412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gradient_tcat[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\username[1].png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017022720170228\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\connection-min[1].js (6176 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\whos_online[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\subforum_old[1].gif (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\password[1].png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\51[1].gif (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav_final[1].gif (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_md5[1].js (213 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\sa1[1].jpg (5276 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon1[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\vbulletin_menu[1].js (6412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\clear[1].gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav_bg_small[1].gif (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\stats[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\forum_old[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gdtmvRl[1].gif (8805 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head3[1].gif (1987 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\gradient_thead[1].gif (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\navbits_start[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\twitter[1].png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon7[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\L3Zd0Sx[1].gif (23847 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head1[1].gif (2119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\yahoo-dom-event[1].js (20761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\altenen_com[1].htm (758 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\GX1OvJc[1].gif (47449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\icon6[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\collapse_tcat[1].gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\forum_new[1].gif (843 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\collapse_thead[1].gif (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\w3cxhtml[1].gif (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\altenen_com[1].htm (22246 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A1KUF342.txt (249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\nav[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head2[1].gif (3596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\lastpost[1].gif (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\pid[1] (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head4[1].gif (8 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16428
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: English (United States)
Company Name: Microsoft CorporationProduct Name: Internet ExplorerProduct Version: 11.00.9600.16428Legal Copyright: (c) Microsoft Corporation. All rights reserved.Legal Trademarks: Original Filename: WEXTRACT.EXE .MUIInternal Name: Wextract File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)File Description: Win32 Cabinet Self-Extractor Comments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 26060 | 26112 | 4.42567 | e9bf1a1e456a9a811b1b86e6602e3636 |
.data | 32768 | 6796 | 1024 | 2.20139 | 317f8a934ee443eee01c2a315bde9ca1 |
.idata | 40960 | 4216 | 4608 | 3.49941 | d8675ba112ef922c6057a02546757a1a |
.rsrc | 49152 | 697623 | 697856 | 5.50183 | 784a0ebf37c44bb231d3b5c36a6cd595 |
.reloc | 749568 | 5038 | 5120 | 2.58043 | 83de2f9b2c95be6fea06bced7e8a058e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://www.altenen.com/ | 5.254.123.33 |
hxxp://www.altenen.com/banhammer/pid | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/yui/connection/connection-min.js?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/vbulletin_important.css?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/vbulletin_global.js?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/vbulletin_menu.js?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/close.gif | 5.254.123.33 |
hxxp://www.altenen.com/clientscript/vbulletin_md5.js?v=389 | 5.254.123.33 |
hxxp://www.altenen.com/images/smilies/51.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/head1.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/head2.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/head3.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/nav_final.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/navbits_start.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/misc/username.png | 5.254.123.33 |
hxxp://www.altenen.com/images/misc/password.png | 5.254.123.33 |
hxxp://www.altenen.com/jpg/gdtmvRl.gif | 5.254.123.33 |
hxxp://www.altenen.com/jpg/L3Zd0Sx.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/buttons/collapse_tcat.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/tcat_left.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon2.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/buttons/lastpost.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon3.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon7.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon1.gif | 5.254.123.33 |
hxxp://www.altenen.com/clear.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/whos_online.gif | 5.254.123.33 |
hxxp://www.altenen.com/anger1/head4.gif | 5.254.123.33 |
hxxp://www.altenen.com/danger1/head4.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/gradients/gradient_thead.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/nav.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/stats.gif | 5.254.123.33 |
hxxp://www.altenen.com/jpg/twitter.png | 5.254.123.33 |
hxxp://www.altenen.com/jpg/facebook.png | 5.254.123.33 |
hxxp://www.altenen.com/jpg/sa1.jpg | 5.254.123.33 |
hxxp://www.altenen.com/images/head4.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/statusicon/subforum_old.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon5.gif | 5.254.123.33 |
hxxp://www.altenen.com/jpg/larme.jpg | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/gradients/gradient_tcat.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/statusicon/forum_new.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/statusicon/forum_old.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/bg_tile.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/icons/icon6.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/buttons/collapse_thead.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/w3ccss.gif | 5.254.123.33 |
hxxp://www.altenen.com/jpg/GX1OvJc.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/nav_bg_small.gif | 5.254.123.33 |
hxxp://www.altenen.com/images/bluefox/misc/w3cxhtml.gif | 5.254.123.33 |
ah-antihacker.ddns.net | 177.86.90.37 |
s11.postimg.org | 163.47.178.206 |
s32.postimg.org | |
s27.postimg.org | |
paysell.bz | |
s24.postimg.org | |
s5.postimg.org | |
bitxh.com | |
s29.postimg.org | |
vipcvv.net | |
s7.postimg.org | |
dns.msftncsi.com | |
xslt.alexa.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /clientscript/yui/connection/connection-min.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-2d54"
Content-Encoding: gzip
eda...............r.F.}.B....0.=.f#..@H....f<.IiU.,Z....._J.....4.9......O..s.t.........~IZ.\o.w......e..o....r.....V.3.>...E.nE.....Zy...E...~.Z.|..nI..wx....%k...t[3...9...r.<.w.8..$..............M&fN...'q........Ut.N..0.M.e8O.,Y........52..W.>...G..3.f.-=....p.......U..~.a.6..m..~...u..1.#i..M3._..6..A.O......$]..i..90..Z...f...n...D.>.........i....Dy.d~...8#....%...*..l.g....B"Y.ca........=......Qd..U.O|..:."...Wx...M....6......~..@...?.L....H..."..1......P..v.f..@...c.T.7.BStj....M}...@...d.S......@F.[_.<.i..w..cr....`..v...p..@......}?..n.i4..m.........]NH.#...\.<.q.......3........,...|.2.'.u..8...`z....8.@W..v.[)&y...bX[......5.......^..[....$ 6.!..tc.H"L._....(..s.eo...a....<}....Kr..........y.....o..(.T...<.gV....g..H..`.@T..@.o(.WN4.H...Jp...9...r..$..H...)...A0.p(-.P.........v..z..@...o.2....7.8[.....[.q.s....{ u...j....P.')..$.m...cm1(hm.].D....{.;].UO.}....*.oq.].U .E......G...;..v...8$.@.).^.o?O.O0.5...\F.......X$}.86U.j...5.7sp6=. ....B../5O.....s.Z.I..!z......p.......w~.mw...5...2.... ...a.G..F8........@b.b.S..._....a...X..`....@.\..oo.V.........'..N../%S....I9!..:.}J..=.s!.EbF..qq*<[.N...).k..FO...N....6h..&.6.......^......a.Pa|l).z.y=A?UT.Ef.g.t...."....K....&:L..v8E....C....k%~..7H...O.v......ck.......BC.........Cm.wj.AH..]......c;..e.....v7..v..8_...C..b...#.4. .S..,.#.............IM..........X..b,}_u."}....Bwqp.kH.h.h.w.........1&.rI...~...r^U................L.VQ.......Rk...\..G...Z.q../0......V..2......."..A.W|{Z..6.v.(...\.)....<eF.x.p....F...Wk....a.m...
<<< skipped >>>
GET /clientscript/vbulletin_global.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-659e"
Content-Encoding: gzip
1faa.............<kw.F.......F.2.O.`..$`fv..c'.=.p.j.2 .I....t......-...&'c.~TWWW...u.........6......j...U.q.........S.g^x....V....}...Y..O[...i...2.E.Xga..V.]4m........./4.....9..y......-..Z.g...%4..,.'...5.y;..E...p.........O.............|........em....]|.\........<.V........D..9.......E8.QJ..l.(@.E.:.......k..6......R .fs$...aB'..........?.E.....Y.3b....o.]..s.'...$....SX......{.\..,.. ....x..%.?.`..#..%..kVI.<R<a.Q.:N.D .[...!.\.h....FX...kp..F..:."....v.E.....w.>....md. ._.....m...z.F4 ..t.........../?...Q...WAQ.....j..)-`..R.....$.....7. .q?..8..6..vO..?.qF.s?I.k..RV..g4.o..i..e..qBg.ne..._....2..dM;Eo...oc/^..,....57!.].I6F..#.1.......l|....3..=..V...q........Si.e.,~.......i..xE..6......I....o.....M._.Z....0S.@Avc..`0kz... ...G.q;o..*..C...u.H.$_`l.. .....2...N..q....c^.J_U".Z..i.#..^.._..).....X!..8......).p.b..)*.Os. .....P......_.." ..BMeh ......BJ.E.Q...Z.J..(a"e.2...IB.:.U....O.I...`.rN.>.......^...fM.QY...y.ri....f.$.0...._1.0........N.q2L....."cb...a-....2..O_}G..z...8>.NQ^.O.....o4.A..{*.{.....c>..RL9.|.3.1D....=k. .7..k.[...y}......L........aU.HY .T<.e96.y..Y...~..zgn.k4.......^.=.....bF.v ..].l:...?.438..x.^"..h._P|t...9...CoN7...X.... g..........<.".Q|...S..Y...k3)..TtP>.X0W.N.._......*....J..'Y...&....Ey...*.5f..ON.).Yn..o...hL...9.....9Bo......b-..V.........)*[.Hj >...f..s....9.w..p.D(Y(.`D:...g..#.>.......X.&.2l>...0..' `.-....^.~..7."....?M.T.....qm.P...~...........u.6...X..}.\..lL....pw.....0.l...s.$..@?e5.......F.......:r\4K..i6.. ..9..8..s0.`.U.
<<< skipped >>>
GET /clientscript/vbulletin_md5.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-1558"
Content-Encoding: gzip
7d9...............s......T.x..rp..DuH...G.m.G..(.l..%W..l..../....#..E......@<~..^....'.iF..p.^...U.j....j.9......f.\X.wwW2....t..Z.x?_.2.G....=[oV..B(..o..........F..zN....&H=....U..nv7...."`.........B......9......(~<.3......2..E.(~.Y.=....[........q...l..}...3..5...f..b..........72.j...r.....T.. ?w.vFU.h...37k...k...k...g...]_Gg.ir....7e.\$i.Q..T.......'^.J........JH...Z.*..V.A,M.Q.HMM.=....gN._$..(.B2.9..G....JP.M.@...2B.&....C.P..r......N..H.y.M[4...p)h.k.{...N!h.`....F..pQZy.."..d.4...|..W..".=. ..%4.&*.I..3fH.O:>...\rfj...C..DB...Q....R.t......$T..:....l^.D...Ii.;...... {S.o....I...*.....l.L.5.........(ED.9..2......Z....dRi!`.....i.hD.F.Y6...N..F...vh.......xr.P.6M.J.t..I.|......a.C.iTj....u.5..NS.j...iD...FDk...s.LJ..Cn..64...W..PW..N.-..Z.....cQ...R...#.V...I.N8:.R...(..:6.....\.g#......%H..[<.....".G....H^.X..{8HHFMj.p....0C.....6.s%.N.`6?,.`TS.m.=.S....T.......1xWilZ5.|..Mjc`....Z.Aj......S.PA.4.}......(.iv.....m.."w..E.l.#H^...j!..8...5..3.......H*...Q.....2....c.v..2.&...ewq...."..*2..>.m:....E.RI.....U!a'II..V..9.Qlq&...^.ku......9.."\>...........vZs....b......l..I.o..n.ZM~...;.Z...E4J..H.d.....Q.~.y.Z.F.@....8i.rL......pd.........Qq4..D..E|..;.C=x.._=#...E..........o.oG........F..0.a.a}X...f.....hX.....?..>d........}.!..v....@.P.....v...)..!~......Zu...E.......V.Y;?.\..'.].g....G.L..'..A=s...?..h.I..{.(?R8.......Uo..}...W..].5...;..e5k...Ry....^..0T.#.:O[Goe...~..).....z...}....O....>.o..EZ..&.ry5.7Q..??..AF..,.........C.....dir..=.A;.i../n..W...B......aX..e......J.U_=.."h.
<<< skipped >>>
GET /images/head1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 25780
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-64b4"
Accept-Ranges: bytes
GIF89a...................w...35.PQnAB................%(~-/8..K()..................|.....e...lp.........t.....l.....d..\........T..L.... x..D..h..,$%<..X..4..,..J..$..8........(................,..............................4D4.......................(.....H........................(%.....................)..<............................. ....m.....X.........O......X9...........v....l:..|.:".....l.H#..b...'.H..k.(...O..U.........|....>..0........?.$.....i..|...8.,...U04..X..9/-....#.<...yw....'.D.....T.....L.....|..t..l..d..\...'...............................'......... ..:24...FD..............................|..t..l..d..\..T..L.....D...........<...........4...........,..|..t..l..$..d..\..T.....L.....D..<......*),..W...C@$......>=I.....a/....H44.ccWGG...H??...dYY............!.......,.............aK...9....L...C...>L(.....-ZT...C....#...A.2".[.N.C..GB..1.K..I....`..#}....... u...r!C.7..|:.bS.OaF,x..6h........w...k......L..'........J..G....H(..`.:I.....ch.L..I....A.7v6..5n..c.&......j....T.U'b...'hh....<......QcV........(p4h.T ..n80.....,i.45.....Z...t..x..^.gfr..-....cj.KC.|#q^.7L..^{..ZL..._c`.u^e.=..A.(c./o...7.5..h......agb`M!..m. c.x.qs.W....t..4.m.0.N3.-..l"=w.WC.E.U....F....7&A..H.5..z..D.4....q.4C.F..._.D..../.H..(......3.2.R.\:7.$ZmmZ.SP.6..g..g’`..&GR..A..E.JQ.f.k1..M....RjXb.XhT...7.$.3.qo...6h...@..T.F.5.*f...XF.!F..>.....J......U{..e#8/HvC.:.....@..C.8s.A0.H%AM...u.>...*.f...*.U.^...z.p..1..*./.8...h.Z.^Te.......u...]..qC.N0..U.....TXn......&C..P../.@.//@g.J.Y.lz....S.*
<<< skipped >>>
GET /images/misc/password.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/png
Content-Length: 620
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-26c"
Accept-Ranges: bytes
.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<....IDATx..S=..`.~.VN.......[.A.m.A.N... ..&N..&................<P.Z......I.5.V....M.&._h....|..{......Dp]...|.........Q"..s..^....4}.f ..g2.$....a....e9U.T.9.s.4/}..O..`.>.>..B..l6.f..I..i."....4..(...l.>|.s.....8.a,'.I.j5....h4..PP..r.X|]....L..L.....P*...[r..3?."....`q..:..]..i.... s..N..(.. 0{.{..`ex.....[|....W..~...7......./......l.>..U..m.X<..S....!..u..-4,....Gl...]o...n.%.fM.....C...'........m..... .K.....u....V.}.,.[_6.[. ..F{..c..e...../...#..=.[......?%....D......7....q.F.cf..L......U!......g.pv....G.?...........c.&...m@....IEND.B`.....
GET /images/bluefox/misc/tcat_left.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1034
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-40a"
Accept-Ranges: bytes
GIF89a........CD.*»B.*&.BB.($.AC.AC.;:.,(.)%PPP.-)444.78.79QQQ.-*.BD....*&....@B.AB'''.AB.78.//.,)..,.,'. &~)$.....-. '.?@~ $.>>.68.-,.@B.:9.-'.:9.. .BB....,'.-,.BB....- ....67.CC..........AB....--....,(..........*%.BC.......CD.......>?..,.-,.AB....>?.>?.86.@A....=>. &.- ....?@.BD..,.. .-(....BC..-.@A.,&..... .@A~)#yyyccc.21~~~.97.31...===..../-..,....==.BD. &.@@.......??.BC.......75....=>....:8.20.@B.01..*.......?@.AA....CDZZZfff.,(....64.?A....AA..,nnn./.. &&&&......vvv....53.?A.0/..........BC.BC.......*$...........................................................................................................................................................................................................................................................................,...............0p......\H.....#:....... \.xqc.. *..I..I.?.5Xy...'{.@XI.....0\.0#...].hj..(..)...1..SR..PZ.......M.:... B....u.....UX....>8.uI.v.?.c . %... vr<..o..........`.[. .t.P.?......-. A.D...M .M.:-......f..A;...k8I...Q.......;...,..B...........;....
GET /images/icons/icon3.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1018
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-3fa"
Accept-Ranges: bytes
GIF89a...............Z..m..j..i..~..c..z.................b......XXlvv...........................h...tt............................@@j.......................................................................j..............|...........................eeh........................UUn.....o......YZr..................MM[..........................}.........IId......ss~..............q.....p...............oo.....................g....................t..........................`........................................................................................................................................................................................................................................................................................................................!.......,............3......I_0... . Kh...a.@.A.x..H..4.........q...2.M.H..T.. L.....)..Q.<UX$...@.....Y#...':............qd......u....E`..1C.M....0BB'...".......@.4...F.%7#..@!DL.(.K.....!....X......:L.....9c"\....@'J<..t.u&.Ef...ba@.;....
GET /images/icons/icon7.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1058
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-422"
Accept-Ranges: bytes
GIF89a..........................................s.....2.....p..7..}...!#...t......cX....IJ1NN6........krgA........T........t}sG..q........i......VY:..wGG0..X..`dd?.|A..Y.z...k........t..u.....f..5..w..M..rpq:..?|m7.........re.bV&..[..f..^psH...XN......p..HypA.....N..k..A..H.....Q.....q.....Z_a4../......na'........O....................5........_..\..Y.....r.........~x]od:..E.v@..vk^ }n5......pd/..|oqH.....t..`........b.|\..{........S..t...........g..z..y..Y..]~qE.....V..N.....X..M...........z.....`..u..C...{n)......46#..m........Xre%..q.....}.....g..Y23"&%...@..G.....V...PP2..M......................................................................................................................................................................................................!.......,............}..XAJ.....\.....xZq..*......01I..D=6..4P..C.".X.f..Ha....B...........8w|..Ee...`.... ..Q|.."....7[4..E...X.@h.AA......8..@..nv4..g......H ...".j."%..-.f..H.b..4..e.".O..........UB>..U%.. ....eiD.,%...a%........@..K....Ak......9....D.L......P..b...S'.....;....
GET /images/bluefox/misc/whos_online.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1604
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:33:14 GMT
ETag: "5429437a-644"
Accept-Ranges: bytes
GIF89a3.!..$.....33.......ww..........ff."".UU.......DD................mm.......rr.zz.............YY.xx....ll.``.............................................................................................!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:14AA8BCE47C211E4B80BBC9CF04D72AD" xmpMM:InstanceID="xmp.iid:14AA8BCD47C211E4B80BBC9CF04D72AD" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B" stRef:documentID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>..................................................................................................................................~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-, *)('&%$#"! .................................!.....$.,....3.!....@.pH,....r.l:...tJ.Z...v.=........G..:-....!.m@....p.G..t.rxGnxo.D}|....oG.x.x.{.j....bGw"..pGkF.x..."F.x..o...E.o.$.F.".$...l.....x..E.o.$..F.E.j ..D.u.xzC.D.j.x..D....g.D.k..E......D."..@..>W...
<<< skipped >>>
GET /images/bluefox/gradients/gradient_thead.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 846
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-34e"
Accept-Ranges: bytes
GIF89a..'................................................................!!!###&&&))),,,;;;..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!.......,......'... .3`.`......0P..@.....0p.A....0h......$L.I2 .;....
GET /jpg/facebook.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/png
Content-Length: 6642
Connection: keep-alive
Last-Modified: Sat, 04 Oct 2014 10:23:20 GMT
ETag: "542fca98-19f2"
Accept-Ranges: bytes
.PNG........IHDR...@...@......iq.....tEXtSoftware.Adobe ImageReadyq.e<....IDATx..[y.T...o.....z.7.....U.E[Ea.%n...K4:....3.H4.h..3..O&.L<.....arTp#"B ...4K....wUw.^o...^U.B..29.<x............}-..I|H.Dgy.v..Ln`....t......;..........8...,YB../....b'...;.P.....r..>.s..c.`&.K#.`..r.hQ.GA.q.SN..S.uJ$......w.y......i....4>..p.\...3.............222$M..;j......1.H..K.3I.,#.-.....'.|....nqaa..H$.?00..........p....h4J===....s..i..N...C.j.us.M.V....~...N0.2~.....gW<..../))....0..l6r..TVV.......~...#I.....g...mR.E...U.8..........~...n.....uww..9..........6''.X.d7..0L..\..`._~..w.yon..}].....c._; ....l.... 7.....{pU.}........E#......x.........kj...~R.... (77.N.A.dP...B.7g.\.....!.J......(.....".....U..K.e..5."..`...o...%.p...?....Z:..Oy.. ..7......#.5.y4eL.M......TZT...HR......>x......9G....d..z.c.x<~....>.W.{..q'r....D....?..yC.A.................vRe...A.Z.i...r(...{......RM.e.....=..G...nZ..g~..P0.a.%9.. .7L.......{p..`$.....;J......B.)S.TO.>...H....>?.3\.. `..d..$Y%.}......v...SK...h...6....L.8..&....\1...$9..../...hNq...-]..z...?....g..#..[.... ,..VP.U&<...4.].......$..QwO..v."..$#.&. !.%I....[7SL B%......../Lm.....:h8..].o..u....n..?.]..MT......0.I.N..(.g...<./..b.......%.\............UT\Rb..........t. ...!.....$...H..9....n..=.!C..Z..Q.&.@.A.e............x._A..@\........4...... .....8..O=S..a...<.....`.#....1.~\.233)....u...Z...'....].:-'X.SJ..n.d0...b.=....#B.MM3..P....)F.6.jkC..q.d....%:Fv...\........Qe!....veMM.r.UW9`....(J......".......$H.*%..Cv.....7..R.....6.Q....)..R.n..
<<< skipped >>>
GET /images/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 8085
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-1f95"
Accept-Ranges: bytes
GIF89a0.................................................................................}..z..v..r..f..a..Z..M..J..E..A..=..9..2.......................a..\.....e.....a..z..g..U..2....................y..`.. ..........................~..u..p..l..Z.....U..F..B........N.....}..J..&..#..G..6.."..%.....I.....R..N..>..:.....X.....2..O........P.....1..(..#..!...........\..S..5..&..;........I.....*..B..!..............,..................................................................................................................................................5.....!..D........)..#..... ..(..!.....0..#.. ..&..@..=.....N..Z..:........3..9..B.....U.. ..(..%..#.. .........................................k..^..Q..5..R..I..?..|..)..D..... .. .....R..?.....-..).......................!.......,....0.............3Y.tu[UJ..p..y.'...F...;.*T%.....X@....H.*.rQ..&.h.....T.dA..-..T........F.B.%..@IQPE.,...A4w..C..[.n........q........]..j....].O.1...N.j\..../l8q.V.R....Z.T....2.=.4....i........O.W.f.r8...]......V.f.Z..7GNY...:...3..w.A.R,U.p....:..D_..i...Z.l.^..Q#g..A...'...64..}.....n...jJN..Z.d..6..`.0.|3...x..E....q.,b.{.4V...l..zLI..8..h.1..s....c.<.~C.].zB.K..r.>.u..7....,..S.*....6.....[<..5.tS.x3Ng.g..B@7....7..3K8j..\H...$..X..;..cM6....,....f.:E@"^.C 8.q#.,9!.....s.c.T.M7.......5.9.. .T..B.8....,.x.J,.....Q. ..#..5.8... "....~..c.#....5.... ...kY...R".D.."z.0.F.&RW...4.#...M..|..=....D......(B.",9E.(w...]..,W"..s..b~.....Qo.ki4..S...(....\.."T8.....Y.....Q,.'.@E.RJ......U.E....(.p#.3..#.6$rsf8...p..E...C.e....3
<<< skipped >>>
GET /jpg/larme.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/jpeg
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Mon, 29 Sep 2014 09:09:18 GMT
ETag: W/"542921be-2aee"
Content-Encoding: gzip
2901..............wT.Q..'.....M.UB...... (.H..EA..Di.@.t...H.....W.&.RE.*...}[...{....w..33........f....%...... ...u.....u..|&T.....4.(.BC.....B.aL..0..&..lL.....6v6..$..bb...@r.G...:........@.!.............@b`.?@......v.<........U@T.. i......42.T..........rf..YhX..T!l.v...p...<:...v...wA..{....g..B...".Y..W......x-m.........K.G'g.W7w._?... bD.....1.I.).iO..e...........7465............7>195.~........k...[.{...G?~.........&.K..3.*jj05.?..U...,.4|R.VUCZ;o6~.0:.Zb^m;....w...1.yA.e...h.A......D......,......f.T.....X.._M.Z...-54......i.....RTr..n.. F...D......n..B......f4.M...,1b..k......L..{....Bq."0........z...0....W#.K.....NJ...\|...Z.b...c4]p..(.7?.s...Y......wkY................-g^...d.@.....*5.b4... \eE.jf..3i.E..7.9Z.tc%...efS.*.P[.V^.!>..xv.M..}0.z*.m.CBYDR`6D....,;..L.....pC|..[g^E.. ...[.......F.e%....C....P. ....U./:.D>.K"..!.Xv.[..b6D....3.B#......8.......~..?.2E..qx.Y...hcr#..Q..Q.].s|.!Sk. ...D.......q..FN.D;@.3M..2....0..D...Gq"F/W}..].J..x.8o}.<9.H4.2....%..R.cP...C.c.~.$...n!...N.......`...!.Jki ........A.....k...Lc..7."...Pb.h.Vh2.....M...dK6..........'.......j.F.~X=.el.tY...6.H*6..o..D.t.=N.6...$j=..|4.. hv2.g....*.?...Q...w......f...ng0......%....e..N<(E...>RE...........p.t..F M.)`......[....W..B.tC...U..^q...Tj.T.x..l.@...*8...).d}....Km..1x.-o\I(...D~*4Y.f^.,.....................}...'........G..F...<5u.@Iz._..;a..R.w....w......,JS.. .."k.*...N.)Q..a..)...........FI.....T...b{c...r..e a.S........p3B_.......S*...{.AK...P.W.I....0....*.......W.......%..Z9w..d.l.e<~2.L%
<<< skipped >>>
GET /images/bluefox/statusicon/forum_old.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 20498
Connection: keep-alive
Last-Modified: Tue, 30 Sep 2014 08:10:28 GMT
ETag: "542a6574-5012"
Accept-Ranges: bytes
.PNG........IHDR...3...!.....t.......pHYs................OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE...........Q,......!.........{.k........>...........H3Q5...B..........@..$p....d!s.#...~<< ".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(.I. .6a.a.@..y..2.4..............x.....6..._-...."bb.....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/.@.4.Qh..p...U..=p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,..c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!.[..b@q..S.(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i..t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....).)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC].@C.a.a......<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2.......
<<< skipped >>>
GET /images/bluefox/buttons/collapse_thead.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 830
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-33e"
Accept-Ranges: bytes
GIF89a..................f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...........................................................................................................................!.......,........@......H......*\8..C..#J.H."...;....
GET /images/bluefox/misc/nav_bg_small.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 1453
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-5ad"
Accept-Ranges: bytes
GIF89aN."..H.^.._..b..c..g..j..k..n..o..s..v..{..~.................................................................................................................................... .$$. .22.44.66.??.BB.DD.II.KK.TT.VV.[[.]].``........................................................................................................................................................................,....N.".....G......F...G....F...E.E........F....ED...C...C.........B.............?.@...........@?.......A.><.==<..................;9..987.......o`.......#a>..#..A....22..xq.F.5B...Q$...7..(2...-m.......7].h.S'N.9}....(..>..=.....F..0..*..)......W.*.n..V...g..M!v.[..iY.`A..\.!@....o...C..<./..!...1........L......X....f..?w.p.4.../.V.!....c...A..../[..A.....C..!.o..../.......?g.\.....g...;o.....O..x...7h`.<.....o..........`A....(....h...*.`..6.....P...Vh...Nh...n.!....a...X..'............".-...........H..?....6..c....@..L29..G....4..#......3r...\....0....6..f.7.0..C..'./.Id.v.y..7..g...H......./2Y....j!.K.8h..R......h...h...z.....:j...*.....@.."......j..F..HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Mon, 27 Feb 2017 14:49:29 GMT..Content-Type: image/gif..Content-Length: 1453..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT..ETag: "506e8108-5ad"..Accept-Ranges: bytes..GIF89aN."..H.^.._..b..c..g..j..k..n..o..s..v..{..~.................................................................................................................................... .$$. .22.44.66.??.BB.DD.II.KK.TT
<<< skipped >>>
GET /clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-8f14"
Content-Encoding: gzip
3265.............}k[...... 0{.^2..3.J..'\.......|"D...7A....~....N......k.$}.....[_......q9.......L......z..t...M...=..(.O.\..=...T....7t'.;J=MF.,5.wS.N)U............}v..Gw.[".....-..=Y=7_..zvg.7..S.s....z...w../...m.gW[-..l....#c...Ds...d...z....yp.Gg.....p.`3........;....'O.1 .. Y..Y.....G;7v'w.{.....sU...........co.1r.i.95E..<S......f....}....@.x.A...~a0..w........:s.O.I.l.Z........lV.h.D..o........;wf....t.k. ...dU.......u....M..;.....=..YI.W.......t.4v}.Z.U.. b.;..=0W....H.....<y..>...8.[U^.."V....u.51..L..U...6<.*...T.W.T?....g......Lxp.Iq..>/k.|...#..L.....a.r...N.......y.^...............LA3)A....3.9..0M@m.2...@..). OD....}!I..Q0.....^...-......E....>......;.:..o..Wo.....o..i.8..R...P.....y....t.{..`...b6.Cf...m.......@VsU.....z.9..|x.......g...._.e..]..w...@.t.........w..Sg...,..jP......D..A..9pZ...W.iB{{.w.9.....FK..hz.....Nb-.....A....l!..W>4..M..M,.PR.o......y..F.V..3Ti.]..lt.D.9#.}...W...9O.....D..&...."0..L.|..D.....1....1..1......IR.......B.i.f.s].]...[..".eZ ...$.X..gO....s.]. . .8/.....f.:_...\... ......K......d2.I_...#n..7...y......`.0.H..T..(-.8...H...}c>..g...........1.DW.O..A..@Z.9U)...\B....ze._.N..3I.&...e..Q..:..?.V..5A.%......B.7..{..P)#........{...YB.L%... ....).B...i..R[.<......!......W).x.w] ...#o.......y.....`..;a..^ ....e...^A.>.;.2..y..2 ...<6.....^'dE...1.u^..W..`.iH.C.5.*;'`......l.-5q.....t..U....8b)....... ..Xu..............s..3sS.d8~....Z....H_*V5...$|...t.I.f....A...4...H...'..C2Ot0....Z.._..[...-S.b..(.....{.o}..g.o.K.D`...I.)..*.H....2Z..<
<<< skipped >>>
GET /images/bluefox/misc/close.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 428
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-1ac"
Accept-Ranges: bytes
GIF89a.....?.....j9......./..<..KJ.zI......zyy....],....PP.......S".6...S.mml]]hff.......N.....nn.SS..........,..D..M1....&.. ...........E..>&.X&.;;.*".K..Q../..``....77..j...qdd.80....?..D.....J..mm......!.....?.,..............f...?.K..!{...sD.V0. !..&"..B..$..G..L.$Y .r.,....z3P...(...\?.,.... .....H#.*. )....NB>.". ..3..Is.......G?.....<!!.%;M.....0.99..../.)%..0!.(1j.:. .... ...8.%.'.....6.....'..G....:,@.`....Fh.`.G..;....
GET /images/head3.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 33457
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-82b1"
Accept-Ranges: bytes
GIF89a..................................................................................}..e.....\..........................|..\..L........l.....T.....;..4..$.............................|.....F..B..t..>..l...........t.................d..\..:.....6..2.....T.................*..L..&..D....#..."..<..C.....w.....4..g.....,..L.....X..$....-..(.........7..'.................................................................*...........,.....b.....$.....4..<.."..T..L..D..*..&..y.....d..:..U..6..2..............|..F..B..t..>..l..[..................................................n...............................................|..\........t..L..l..d..F..B..>..:..T..6..2.....*..&..".......................F..B.....t..>..:..6.....2.....F..*.....L..&.."...........,.......................!.......,...............`...x...cgoN"v...c.P.@{.-j....G. ....Q...%1.c..^..."......B.Y".(`.I...@....7o.......4S.8]r.n....mr...%..]..I...K....J41..n...ry..&....K...>...i.V..6n.. ..S.Wv.XND.........G/K7z..)d............k.=}..M..c......%..n......6Wve..s.m.#......L..k..y.....(.....K..m.......(Rm.......%.........y?\...>D...?d..L..uVd....E]..._..s.5.p..5.l..nb.FQj..."P....y.....Wx&FLmU..q....<...I6..6.5...C(.D.M6.hcM.?0..7. ...f.4.{4.T.Kh.q...t..7D...;^...</...Q..b..#....;.q.4..e.D*=...`.w..zd..S.<..4..g.R1U4.....cm'..Ue... ....#O...3.7.`..5....&.<..2.8.I7lb.M6.`..l".4.7]\r.v..d!DY.....l..M......X...p...6.H....$..4.pc...e...... ;yD.N6.@s.u.t#.L4......W.O.U.S.;...e..R....*M.B\..*.(.L4&h..#.\A,...Z..wv...H..c..}..7.L..
<<< skipped >>>
GET /images/misc/username.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/png
Content-Length: 728
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-2d8"
Accept-Ranges: bytes
.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e<...zIDATx..S_HSQ....{..Y..@...h..2)}..P)l.^zX.P..Q........QA.......jO... .....0.....?.....9..y...w.w..;..;.;. ..`hp..........V.u..wJSU.r.))...z|.S)..3..766.......D..i..E..J.......L...0.f......3....*.Y.UE.K).J.;.T){...`..*|N..N.e^...Q..t...9.; ..n.F...... ..>q......'.{.._....T.f..h.a.o.Z..........oo..........5;n...[](..!q.H..F....g..cy.M...v....;.-...D.......n.m..|.6:....`O......xj.#^L.ccc/..y"...&..z.R..f..8.N..i|$.... T...{9.....E..J..|>....%..Y.....y~..r.... I.......b....6X7...b.e.v.....:...!..........2!....V........Qs..#.!..43{.......t:m..j;..F..`..%..p........:...lo......Ba..e...5.m..c...=2....AxD.<hnOGG'..-...Q..D4...B.........=.........IEND.B`.....
GET /images/bluefox/buttons/collapse_tcat.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 834
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-342"
Accept-Ranges: bytes
GIF89a..................f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...........................................................................................................................!.......,...............H......*\......"F|H.........;>....
GET /images/bluefox/buttons/lastpost.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 239
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-ef"
Accept-Ranges: bytes
GIF89a...................... ..&..,..4..:..H..N..T..b..h..v..|........................%%.GG..................!.......,..........l...di..h.l .).XWm_.<.......5rL".$&......DC.l&..K4H,...u. .Df.x.)......q..".|....&.p.r....p.........p*._..o)!.;....
GET /images/icons/icon1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1032
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-408"
Accept-Ranges: bytes
GIF89a...............................|....................kop}...................................255...VX]........................'))..."%%..................HLM.....................efm......8:<...............uyz............??D.................. ,/......ABG............oqx.........Z__.......................................BCG...............?AB....................................489............................... "...............* .............................................................................................................................................................................................................................................................................................................................................................!.......,............ .:d.J.!.FH...L..o.....L...1bxX....i.8i.'....8.H.....k 1j.q.G;....C"..@,..0...".@>..0.@.1..p.....AE.h`...... ..B...G.2N...@..V............0E..'e.P.................%.....4.t. ...F..y4. ...-/$d.....(.c.......G.<..'.T#A6..s..#&.....;....
GET /danger1/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 404 Not Found
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip
bb..............1..0..w..pv.i...........9.@.....{.ZA.........6u^.g...R$.<....H.vt.Z..(..d.!.CcZ............F)l.....'{........W...*?.>......c....v.@".....p8........!....}..#.|a...G.:..J..\;.....0......
GET /images/bluefox/misc/stats.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1626
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:33:14 GMT
ETag: "5429437a-65a"
Accept-Ranges: bytes
GIF89a3.!.. ....<<<.33......333....wwiii....ff...fff....""---.............DD.UU..........RR..................................................................................................................!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:D6B22C8247C111E486859D7D00F07B4E" xmpMM:InstanceID="xmp.iid:D6B22C8147C111E486859D7D00F07B4E" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B" stRef:documentID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>..................................................................................................................................~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-, *)('&%$#"! .................................!..... .,....3.!....@.pH,....r.l:...tJ.Z...v.=....'Q!.=..:-$...!..@....p.G..t.rxGnxo.D}|....oG.x.x.{.j....bGw...pGkF.x....F.x..o...E.o. .F... ...l..o..E.. ..F.....D.u.xzC.D....D....h.........E..x.gh.k........s.
<<< skipped >>>
GET /jpg/sa1.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
<<< skipped >>>
GET /images/bluefox/statusicon/subforum_old.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 348
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-15c"
Accept-Ranges: bytes
GIF89a...........................................yyyxxxtttsssrrrqqqpppooommmllljjjiiihhhfffeeecccbbbaaa```___^^^]]]\\\[[[ZZZYYYXXXWWWVVVUUUTTTQQQOOONNNMMMEEECCC???>>><<<;;;444000***(((.....................!.....8.,..........y@.pH,.l0.R....4....r>.....D..p.A).....R. ....%<Y&.C ..wVB&...{....8$$''.....*B"$%%....%S)B !R.R'..B/.."..#..5C0!...'3F.CA.;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Mon, 27 Feb 2017 14:49:29 GMT..Content-Type: image/gif..Content-Length: 348..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT..ETag: "506e8106-15c"..Accept-Ranges: bytes..GIF89a...........................................yyyxxxtttsssrrrqqqpppooommmllljjjiiihhhfffeeecccbbbaaa```___^^^]]]\\\[[[ZZZYYYXXXWWWVVVUUUTTTQQQOOONNNMMMEEECCC???>>><<<;;;444000***(((.....................!.....8.,..........y@.pH,.l0.R....4....r>.....D..p.A).....R. ....%<Y&.C ..wVB&...{....8$$''.....*B"$%%....%S)B !R.R'..B/.."..#..5C0!...'3F.CA.;....
GET /images/bluefox/statusicon/forum_new.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 21048
Connection: keep-alive
Last-Modified: Tue, 30 Sep 2014 08:10:28 GMT
ETag: "542a6574-5238"
Accept-Ranges: bytes
.PNG........IHDR...3...!.....t.......pHYs................OiCCPPhotoshop ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE...........Q,......!.........{.k........>...........H3Q5...B..........@..$p....d!s.#...~<< ".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(.I. .6a.a.@..y..2.4..............x.....6..._-...."bb.....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<......$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..?....D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/.@.4.Qh..p...U..=p..a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,..c.."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!.[..b@q..S.(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i..t.....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....J.&..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.._... .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....).)..4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....Dw.n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC].@C.a.a......<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2.......
<<< skipped >>>
GET /images/bluefox/misc/bg_tile.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 427
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-1ab"
Accept-Ranges: bytes
GIF89a.........!........ .................................................................................................................................................................................................................................................................... ............................................!..!....................!..... ....................... ........"...,...............~.~..........;....
GET /images/bluefox/misc/w3ccss.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 177
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-b1"
Accept-Ranges: bytes
GIF89aG...... ......:::!.......,....G................0.....f.E.X...(..... ..9..N....pzD.(0..(..N.......j.jXKe.Iy..B.U...{.d..t^.h3]k.o../m.w.vF.S&.v...U.(.."9....I.......iP..;....
GET /images/bluefox/misc/w3cxhtml.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 175
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-af"
Accept-Ranges: bytes
GIF89aG...... ......:::!.......,....G................0.....f.E.X...(..... ...........<....z)m-e......a.s.n..e.I...E*oH.E..I...p.k.9]G.[...?!F.f.T..s(.W.x.....H)&y......iP..;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Mon, 27 Feb 2017 14:49:29 GMT..Content-Type: image/gif..Content-Length: 175..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT..ETag: "506e8108-af"..Accept-Ranges: bytes..GIF89aG...... ......:::!.......,....G................0.....f.E.X...(..... ...........<....z)m-e......a.s.n..e.I...E*oH.E..I...p.k.9]G.[...?!F.f.T..s(.W.x.....H)&y......iP..;..
GET / HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:27 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: BHC=; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
X-FireWall-Protection: True
Content-Encoding: gzip
1b1.............R...0... .:,...N),]Y)....tais(...{...%W..,%..Q.'..[.0....i..t..y.Q5.....k..U.........Z.c..,../........."...`.h...*.....?x..k.G.u.Vu8...f.....hX.j....%N...D..6.#w1x.6........CGX^..J...2`R.nz.1......M.....\.P.......R0.v.x..P.).TGmy..)j...t...$p~..aX...t6.......T....g.._.....0.(...f.........y.0w....!...V...h.O..5...c~NL)_.....<u.A.We9.... ...\.&..`..H..........<h.kI;....Iz.....KvI.^).U../z......g...%.*.)..}..]._.....d......0......
GET /banhammer/pid HTTP/1.1
Accept: */*
Accept-Language: en-us
Referer: hXXp://VVV.altenen.com/
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:27 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive
30..L+fIidj+dfz1N3PD013Mh7pSmIw=_312873590786...0..HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Mon, 27 Feb 2017 14:49:27 GMT..Content-Type: application/octet-stream..Transfer-Encoding: chunked..Connection: keep-alive..30..L+fIidj+dfz1N3PD013Mh7pSmIw=_312873590786...0......
GET / HTTP/1.1
Accept: image/jpeg, application/x-ms-application, image/gif, application/xaml xml, image/pjpeg, application/x-ms-xbap, */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: BHC=L+fIidj+dfz1N3PD013Mh7pSmIw=_312873590786_
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:27 GMT
Content-Type: text/html; charset=ISO-8859-1
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: BHC=; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
X-Powered-By: PHP/5.6.19
Set-Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; path=/; HttpOnly
Set-Cookie: bblastvisit=1488206652; expires=Tue, 27-Feb-2018 14:44:12 GMT; Max-Age=31536000; path=/
Set-Cookie: bblastactivity=0; expires=Tue, 27-Feb-2018 14:44:12 GMT; Max-Age=31536000; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Content-Encoding: gzip
1997...............r.V...w.*..V..Ift..bG..e.v|......S*..I. ...$.g.[.W5o{~k. A..Z...{*vw......k.....?ys....'.h>...?>~.....;8.K......'._.}x....W...;M.y.M........3..g....//./..Q<<....J`U....{..'.........7o.....p..j..M?..xA|.....'t........].@....{{.4r.n..;#~.....g~7.................N....M..t~.3...'w....8......>.W.>|,..;.x.....|....z.u.H...a9..p....@P.....8........t..|....L....3..~..#p.B...E...`...;..tk.P.cc.y..^..n..b..y..Mv.ov..hw......E..............^.;ow.G....&3V....(L......;..N......x. ....tY.Ey~.....da7G.^;.|..C......uN..x9...YF....{....h<.....s2_..3...;...$.b...?..Y.....W.(......D.b.?.. ...=p.. .................]...t.G..........^....2....N.Y1.......|......Oy.z/.z..OU*|._......Y..)J.;8w/....F....q>A2..Q..V......GN..b..Su&>....}.."...$.....0\:..`6.;.A.:.?q.h.cg..^.]&~.$~.pB_.%.M.n<..s....^9.` o...K..,........@3[...y.z....3:.....S.x..9.e...h..E.y4..$..............d..w....../........ ....W..;.......?.y.9...v..........P....z....t...??.G.8..}.U..a9..\.....O..sv...."]....|~...............#..S1 .38\/&}....7.o....R`...?t......!.-......p8;...;..q~...| ......y......V......m&.^2..}..k...........`...ln....EC..........<..y..Nz...pX.TVOp...?^>...I...w.....o;...v>..........._..`8.........._.%......:.N..`(ra.....V'.......|.d'......z..~.6\p.. .v...&'...'.I..?.v?<..o .....S.............k.q.;.....pL.I....l...>.N...~.....6.]..C?,,K~..0...W......I2..?..^....j.a.....2...m....R.X.......,msK...?.>..........8.?93w...&.....D'H..v......Q.~.f0.......,...{y.^..........[a4.UFU.a.._..W..RN.^..
<<< skipped >>>
GET /images/bluefox/misc/nav_final.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 652
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-28c"
Accept-Ranges: bytes
GIF89a.."..T.5..9..B..C..N..O..R..S..V..W..Z..[..^.._..b..f..g..j..n..r..s..v..w..z..{..~.......................................................................................................................................... .&&. .--.00.22.66.99.==.??.BB.FF.KK....................................................................................................................................,......".....CDFGLNQSBC.K.SABEFJMPS@ACEHKOR=?A.I.;=>AEG.8:<..K578;.G23469<@D.01.79@*,./.59$&) ,.4 !"#' -1... "%),....!......!....................nC....D...@..... @.....-N.......6r(..$....:.`a.....f. "...-?....B..%.(.@!...'.,X.......L0:.....b...`@........;....
GET /jpg/gdtmvRl.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 127641
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:06:42 GMT
ETag: "57c12df2-1f299"
Accept-Ranges: bytes
GIF89a..x.....^........$j..d....%/...ccc6..d...........U[ity..........\\\.......0.....gkg...........RRR................|.MMM...|||......2Ji..@..7...222...qqq....$..............PT ...<<<Vd.AAAo...N.kkk.5.[cu..8...... .t... ..................P......e......Q...-7Q.........e..........H.._..M...v.....;DX............&p.,L.....>X...fhpm.........J_&........Y..BT....Lm.$,3.b....(......s..yk.............(RGLZ.*E>4.'=m..&..).d.679.......$V..Z.............=..............t....H....6cu..)o.3c.2u-./..............:!M.BUf. G...=..........$>`..|.vvw.$....PT_~....... ...S..5".....0]....?m......WWW...&&&..b......D..Xy.EEE....W..<>.....=.v.......ho..... \... .......O.........fX.......TH......................xf...............2.........III....!.xlr..........{....f`v......B{.....&..........!..NETSCAPE2.0.....!.......,......x........H......*\......#J.H.....3j...... C..I....(S.......0c..I....8s.......@...J....H.*].....P.J..T ..X.j......`...K..Y.V..].....p...K....v.............w..... ^...c...K.L.....3........C..M.....S.^.:4...c..M..]..s.....o.....N..q... _.......K3x.D..PgB.......W~v..1.xah.C.#\..R...=sV........}.%.H..P`.a.W..-J?.....-.<...z.^G2x]......Q.,...2......:.G..-A=O 2g.bz2..K.ue....s=.C.(I..)t.*..'..6/....nV.....L.s......]z.P!...B.. ...V..M.....K..ns8...R.U..~..Kp.g...Dm4F....!.....z.k.B....0i.&.....mM.I.B..r...Xh..r6B93@.s.C...>W....em.[...........V....(....m..#...Z...;......"..NP...{..I.@K..-Ry..F..wk.\.......r..:[_-...F8...s...J.hr..M.A..mi..M~.qU.B.P.:.........M*.2.J)............V.^...3.Y....
<<< skipped >>>
GET /images/icons/icon2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1058
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-422"
Accept-Ranges: bytes
GIF89a.................................v...........~.....|...|.......u....c*.O4.n9..u..J..j.`...............}.2'..v.....v.....].....X..z........\..]..C..R..e..g........S.....^..V..s.|?@.i@.f..p..g..`.....x.O8.!..k)$.a....f'.bA..a .a...q...`.....v...5..~..m..].e0..w..z..o..~}....Sb...S&.....k..N..m.......d9........z........L.B/...........o..c..l.K..............\ ..]..\p....g.....X..T..........?'...y......nH.....d.x@..J.....6..2..b..F.{Z..n6u\...........g..W.A(.....h..\l.....n....r.......uL.lC..A.^3.....l).fByZ.....l.j9....T...............>..4..............`..A..9..G....qA............................................................................................................................................................................................................!.......,............{....J...D.\....X.0.8.H.&.*.Q.B....7J.!4...B..$)p.....(H.. ....NA!....?Oj.Z.'.)........ .L.X......ed......#..`.....Jk...C ..4s.4*..A.U."..A@..=r.....U....p.....2]. 2a ..3.....f.$/.:......8=.Tp........j....Y>.........=-qrb..K......a S...0.........ug. 5....;....
GET /clear.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 02:55:18 GMT
ETag: "56fc9196-2b"
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;....
GET /anger1/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 404 Not Found
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip
bb..............1..0..w..pv.i...........9.@.....{.ZA.........6u^.g...R$.<....H.vt.Z..(..d.!.CcZ............F)l.....'{........W...*?.>......c....v.@".....p8........!....}..#.|a...G.:..J..\;.....0......
GET /images/bluefox/misc/nav.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1831
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-727"
Accept-Ranges: bytes
.PNG........IHDR...N..."........<....sRGB.........bKGD..............pHYs.................tIME....."5&.......IDATh..Z]..6...b,.q.].EPt.c...B.....G...I."I.....Z.8} %...$o.E."..93.|.C...pH.......-k.....l.7o\...g.|:..s..h.....4..u...|....Ck......u.Y..Xp...1.....N...{..........l.........:......_..u...;&].p...R.......5tD;'._,b.9..^.b.%....M.PY.....ed.e.}.. K.xl.3...-.8...^..R...<.H..F.p6j..u.=gqwWw..-.F]........j...V.c...V...=.e9....2..e.....pn(...U...]...#......FM'T...._....%w...iY..`..s.Q......{=.I8V^...)...3.i..}=........CX...b.z.Z...8..r....E0.p.;..!...Y.Q....N....v:y;....>..=t..v.........gl6Z.....l.#.i..M.$.....Y.;....u.X.)J.^fU....33...5.....-.5...,e...(V......l$p..O*..`...Z).z6.H..!..DB...m....k.`..D...0..0s..S..[...\....V./_L"..F......:....m6......u-.C.p...^1......e.u.(.1..9..@...3.gq.mz.o..B.......8..Q3d.....d.rT.RtJY.0..N....7...J.Fv.c9R..3............V....M..'r......."...Pyh,[...Q.R.e..e.$......g........mu.. {.......js..,)....)....s.....L..X.<Z..q.9..N..].....Z.........x.p.`..........t.=J.a..B..{..J.8m .=.N.K..HCY.....{b..bP.S;...H.4J.....`.........2.z.d.).DO...@."!.......]fz..........B.9Z....}......*.h).....q.[..}4c.&]F...._E.}......}..6.Z..G..............3..._...".,...=.x..tPz8.)...yNt.d/.[....=.|.L.@\.}..J..U. ........lS....z."..8..K".M.=...C.Ow.W.........-....7../......d2a.%.B./.&..[M..&....rN.. .W..k~..Z...W5...m;..oGdap.`$.....2[.....]...@1^{....m...>......O....}..B......5X.1Y=.....^Q;S........%..;G.q..s..`......@.....2..FX6..i,..5.9p.q.D.....n..........._s.F.F.0.....Zus...i.(......Y
<<< skipped >>>
GET /jpg/twitter.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/png
Content-Length: 7053
Connection: keep-alive
Last-Modified: Sat, 04 Oct 2014 10:23:20 GMT
ETag: "542fca98-1b8d"
Accept-Ranges: bytes
.PNG........IHDR...@...@......iq.....tEXtSoftware.Adobe ImageReadyq.e<.../IDATx..[....u...>v....V..Xt#...$$...AT.v.a*Nb.B.p..Rva.C....r..e...(.....0H i...v........3=...3..]..B...z......]....{4.4.e.t|../.....#G....-.....x.AV.i.Hx.w-.L....i...M.u.OGbQ.u.\.....f....S...2.. .#V..\..F.5.#{..s...........j....sND..s.:.h.c"..r..(....x............"...)I..Hk..a(dR<'...x...2GQ....6l...;v...|1!p.....r...B..%.vZ..c^..*..M....~....xn..LqY*........o.i..J.d....t....9u._..h.L|..'U...q?F..phh(..6..Nz8''g%..t$.)..o2.g....C..........p8.{....:QTT.*I.0.Lp8...2`.X`.=.$<... .S.U...v.}M&N9.$..I..*-\.n...x6...R .]..h``...`.....#...H.;QZ>".)........\.^.H.]CZ.....i.....;..2..L<Bb....B...l......_.;.r..WH........o....I '....L...* .T@...L.<.YQQa..$.|>_2.-..f&.....`........q.W..OP.Q........n1..t./,,l.....fRU.r.%..L......'......%%._...f]q..y...N.......m.>...........9...# .....$...yF:....<....n~....(..g.v&......_.b....J.t..(2#.|&GQ@6X..|.s...M..]..YX3...<.P..j..@/*F...............w...9...4.....KJHp.KX...>q.5.9F............3...'9qZ.i.U:.....j.......>[...3V.....P!.....<.fZYY....Mxo.k.8.L.|.P..9.V.h.A_........o~..z.T....K9.opp....!......".c.c;....x-...x....s&....j..1B..-[6.....[o.u3.Z)V....X...'.\R...{<.G..;...G..ztu.`...D,.q.M.`.?....).L..7^.......... V^YQSSs....!:Z[[7....H.........._.9....!......3.=`D...K........{..-...-x.....%.L@.q.x.P.mn..Gu;)...,I.Y.lOC.x..F ....n....P..L.^*[..c..H. P....O3}. e.........TXf..x8...^..I.&....2.....O.}.M7.X.*..].9!ttt.......O.."7.........Ek.....aS.fBd8....A2......c...
<<< skipped >>>
GET /images/icons/icon5.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 1057
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-421"
Accept-Ranges: bytes
GIF89a..........2..>..4../..-.. ..5..'..8..".....%...y..x./../.. ..#..#..*..*...r. .....$.....n..,..!..1..2...AK...-../~..../........&..............)......xx).....!..-.....$....."..*..%..)..6.....%........$...........3..$.....>......w./...TS,.....'.....4../..-..<y..46W..B|....L|.3u....%.. ..%...../..m..3..(..0..*.....4..9.....7...x.....m.".. ......IG(..0..M..... ../............w.-.....&..:..!...f.......'..&w.x...i.1.. ..,..%..!...$%...$..3...../.....,...q.-...qq2........Z......~..Zd2........|..I.. ..,..2..s........-.....<..)..'......s..n.(..B.....'..'..Lt............................................................................................................................................................................................................................!.......,............q......*^..\....Uk....*.).B.h0......T..4...Ac.0..A...n(m...C$OT.......1C..Z.B......(...$ .N...!@...dY..(@.>,L.jS ..3...xq...ZW..AD........0.@..1.4!..@.....!"..."y.......0Qj8.T............C ....`....MdZA.B.Q.*(...B..?..P..U.........-Cz.p....$..!i.........;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Mon, 27 Feb 2017 14:49:29 GMT..Content-Type: image/gif..Content-Length: 1057..Connection: keep-alive..Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT..ETag: "56fd1393-421"..Accept-Ranges: bytes..GIF89a..........2..>..4../..-.. ..5..'..8..".....%...y..x./../.. ..#..#..*..*...r. .....$.....n..,..!..1..2...AK...-../~..../........&..............)......xx).....!..-.....$....."..*..%..)..6.....%........$...........3..$...
<<< skipped >>>
GET /images/bluefox/gradients/gradient_tcat.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 1453
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-5ad"
Accept-Ranges: bytes
GIF89aN."..H.^.._..b..c..g..j..k..n..o..s..v..{..~.................................................................................................................................... .$$. .22.44.66.??.BB.DD.II.KK.TT.VV.[[.]].``........................................................................................................................................................................,....N.".....G......F...G....F...E.E........F....ED...C...C.........B.............?.@...........@?.......A.><.==<..................;9..987.......o`.......#a>..#..A....22..xq.F.5B...Q$...7..(2...-m.......7].h.S'N.9}....(..>..=.....F..0..*..)......W.*.n..V...g..M!v.[..iY.`A..\.!@....o...C..<./..!...1........L......X....f..?w.p.4.../.V.!....c...A..../[..A.....C..!.o..../.......?g.\.....g...;o.....O..x...7h`.<.....o..........`A....(....h...*.`..6.....P...Vh...Nh...n.!....a...X..'............".-...........H..?....6..c....@..L29..G....4..#......3r...\....0....6..f.7.0..C..'./.Id.v.y..7..g...H......./2Y....j!.K.8h..R......h...h...z.....:j...*.....@.."......j..F....6._......... ..>.........0....2.^....-..u....Z{-}.P0......u..;.t.B......[..6g...V..... p...;p...,0..(.p.....l...V.j...Y..s..l...A.$.L...i...&....-..2n0....1w.r.,.L.....s.-..X...-4.G..W... ..TW-.a.U...!\-..T_.u.`..u.S.=6.T.`..%.`B.%.M..&.]w.t.mw.r.m7......'....(.....#~.........-...7N.../.....>..x;..d.7^9.y...a}. ;...N8...N...3&.. x..`..V<..#O..%{ <.y1.<.......g.v.....>clk-.....<.j/.}....;....
<<< skipped >>>
GET /images/icons/icon6.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 1043
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-413"
Accept-Ranges: bytes
GIF89a........................................m........EJM...deh..........................................ghk.......:\......y.....m{....j.....|.....^z....m.....i..ACEOkpIKNTjr............w....................}..AS~...r..ARa`..........._x...................`v.Xv.Yu........."......Nj.............C\....HYW......}.............._t.dfk...w..5DE>LN.....................Ic.............<S....s...........BKOUt.d~.......k..9CDl.....r~..........__c......>AF.........3=G...F]jw.....Oh..........................'*!"'Qeh.................................................................................................................................................................................................................................................................................!.......,............M..(F...I..\h...5$4.....'.P&t8P...Ma4d.3..(....T....)[Li......2 .....%!".<..'....>.......9....%.....T.P...Jq.,2jE.(.D.............D..$%. .r`....D.8....#....P`../`...$...Od.(.0 ..6kL,."p....nxhB....|...xg.....P........$.4.P.LzNpa8...P.lLb...;....
GET /jpg/GX1OvJc.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:29 GMT
Content-Type: image/gif
Content-Length: 302184
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:07:26 GMT
ETag: "57c12e1e-49c68"
Accept-Ranges: bytes
GIF89a..x.................K...fRu..YV.3J.........[..s......a,..I....rO..U....)0.l................u.....Klr1Mi...P..l...EiVWX ARvvw......bdew..K.............0...445.....o....J'....O6ACD.{.$%%..6......CWp[.uh..h.....0'.RD.[.u.y.............V.....9i..n..........dT..........wi,.....-S..V...EOl...!....sd.R..... ....Vy....o.u,6.......<..........T....-.."57LF#*........$..............g.>...S..u........vpIQ..............x..cX).....Zp....s.....:0ajDg]..Q.3)...~HTM..'....)....cc...*{.l..s.....FRW.......(::.]f.#.....:...e...lAEHV......D..4.OK.........4;kkm...,..ew|c.....q...y....3Y|../.=3r.7a6.;4.xVl.....E....Ei..A.{.}zc..............@......X{nWCS.............dp..... M..;#9.19a..8i_.\.1).\WA..!JJJ;VO......................................................;......!!=|..@....n...`.......!..NETSCAPE2.0.....!.......,......x........H......*\......#J.H.....3j...... C..I....(S.......0c..I....8s.......@...J....H.*].....P.J..T ..X.j......`...K..Y.V..].....p...K....v.............w..... ^...c...K.L.....3........C..M.....S.^.:4...c..M..]..s.....o.....N..q... _.......K.N..u...k...........O.5....._..<.....'.~.....#........._...h`z......J.`..F(.n.Nh....Va..v..c.~(..$..b.(...Y'....0R.b.4.h.P3....<.w^.@.).M9.i..#....LN.d.PFY..RVi.}T^........`..e.d....f...ph.........t.&g.x....z...c|.)....J....eh..6....F*.m.Vji.^^...rA......i................I.......J.................z.K..s....j*...a:...ZJK..QZ...Hj...Az...:.K..1....*....I....n.K.................b.K..K.....)....9....IL...Y....i....y.....L...................L...................M......
<<< skipped >>>
GET /clientscript/vbulletin_important.css?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: text/css
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-68c"
Content-Encoding: gzip
26d.............TMO.0.=._1..R..-*..q.R.J|Hm..TBN2i.u..q.V....r.I)]..V......{~..;......l.....M......h..S.........h..........~..u....^.....J.'0...WB.....`.z....5Ky.....[.T.B..1/..ai0..Q...JC...'<b.@....h}..O....F.......8...h.........>........WU.-..cz..`.....G(..R..wV-.:o..|..;p....6.*.\.....N.t./.A.........yu..B.6...P:...V.S.=I.X.N.4n.........K.%.la.,Q..P.L...d<..6.R..-......c.4.d..E..2.P..).. t..7......q...4...2...T..P.:.4{.6".....%t...P....VUsR''.J.v..^8....`..j(..[.]...(.LJ_K^...$tJrQZf.J....v...s.e^....{."..aN*:...x.2......o<{_...~.....@..U .........UIr;....,..N`..p.4....v~5...4...pj'.1..G..m.......k`...../..).........0......
GET /clientscript/vbulletin_menu.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-24d3"
Content-Encoding: gzip
a58...............r.H.}......H.....4.@.... l....%....F..%.........SB.{.......2.......Y~?|.f...}.....T.f..C.H...................,.L....~......V.^.p.....6.|Ss.P....v.S.lp`...K.js.bm.m..2m....$e.....4@y...A.-%.....EL.......8.e...7....6.....j.W..v..b..s5...p.X|vrr{{knf.^.OW..u.$$>.Rl..*,Q=.^??...|S(.......1.m. ..........K.`...#.....~..:v/.(.q....4j..Gn.p...}.\.{...^.b....Mm.SI...jN.x[....M;...&a3N(.l.c..1.........X>X'X...E~3..L.... .Q..dd..B.^....$4.9.."&..it#.R`y.....x.6.?:.....1.9. s.A.kp.?MA.d..:...I...)..>....A...i.....G. ...z.E'|..:P......~2e.S....`.N"..}T.K.T$n.........1....Xt#..l.b.. ..b.3q7q....N.1!x0..O/.S....m...~A.}~.d.3.Fx/....[....48PW.cb.....=...Q......k.r..J........4..(.D...M.....3.U*UY.......r$..0W...|...c./]:.7..^...... '. n).......{.q..V3<(y. ....E.....X..Tl.!..X.C............Z`y..}..='I..K.....M.y.w.vl4..6.4....Q..w.~."P..s...........;..O.n......k..3....S|..Qp.....y1h/...".50.C....0e@10.=Wl.Vf4. ......b.!x.B..rP.........rr...f....%n..NP..2..NR..1%.DvW..!....vaCcnri..J`W.[.HV.b1......8.=`."p6../.6...%.Rb.R..<._...@>..E$..6..V.``.W...B.;..LUw..j....;...... U.................(.w._..Wa...t..<d....\{&....`Tb........x..8.....=.{>a[({....v...D....6:..eY=.....@....].W5..p\....P...WoP7.........q.`Kk...c..B v.5m..P.../........?....tqc....*...Mc..*a..w:.3.F........:R....|......._. ...~U..fOC.f.....q.=..Rn.de...~....].....kD_.....E....C.....R....@9i.xQ.0.P.%.e.....k...l..Q......"..C..&.....-........6>.@...@.L..n.....\AY.kQ.S.[.!7.....N..o.......7.[..9...O...=9....(....{..)k._.p....
<<< skipped >>>
GET /images/smilies/51.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 3066
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:14:06 GMT
ETag: "56fd148e-bfa"
Accept-Ranges: bytes
GIF89a*........... mU.@4.$$$.............. ...eP.........y...................q.ye<ue8.....}.........aaa.i.q]0iL.]H.....................a.......u.............000mL..............}.......qqq.....e....}.......!..NETSCAPE2.0.....!..Built with GIF Movie Gear 4.0.!.!Design by Aiwan (aiwan@yandex.ru).!...d.>.,....*......@.pH,....r.l:...tJ}.....@.*..0..=..hl..N..k.{......~....uUmti.pQ..cS..^............ .k.8*.........,.k........5.............e.3........)4.k.......%..e'..$.....$...1'k.(..........)..(.q/.D(h...)..".X."....<@..@...%(x.......@.`.!... ...H.....B.......8s:...!.....>.,.............p8< .H.b.d..N.0q....!...F.>.,..............@.....P.D2...2.T.4A.!.....>.,....*.....?@.pH,....r.l:...tJ.Z...v..z...xL...h. p^....`.&.}.5C.0..~>oi.\A.!.....>.,...........@.pH$..C#.@l:}....|>....Z.z.\........:w......K`..x*1?.:0.......... .\.8*.........,.\........5.M..>...........C.....3.......)4.............%..B....'..$....$...1'D.....(...........)..(.....x.@....*5P.!.......0.....$(P .B...>. ..E.. XD. .....)..`"...!.d0....L!A..!.....>.,.... ......@.pH$....1Yl:..h.#.>...V.}..[fW..W.....Y.sk..*...x$Q....aC....|>..u....C............. .E....B.8*.......,................5.M....>............C.3.......)4.cB........%...X'..$....$...1'.].P`........ .."B....ay.@.....hh..B.....(...... H.........<..... XD. ....O.f....D..!B\.`...>B...!.....>.,...........@.p.......@l:..A p.,..g.....F....j..o.;...Ot..>..W.P>_..HxyDWRSuW2o...v...VdD|Hu...oe[...N...q....Z>...d..5....S..........FN.3........)
<<< skipped >>>
GET /images/head2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 30760
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:30:44 GMT
ETag: "542942e4-7828"
Accept-Ranges: bytes
GIF89a"....................)..{..........dY....C;...vupw...........7..f..F...#..JCV..'...........................pn....~w.......... %.ZS......*))....jd.zs. ..kd....|y.......sl....QK.un.'#.94....72..........HB...._V.............0*....3,....C=..../ .UO.....................................HGc))............. .gBA.`[. ..(/......................# ......................!....d.....|}{..................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:B65E0B12B647E411A4ECB674E47D8C8B" xmpMM:DocumentID="xmp.did:E2D2E1FE47C211E4AE82A20A9E772400" xmpMM:InstanceID="xmp.iid:E2D2E1FD47C211E4AE82A20A9E772400" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:B65E0B12B647E411A4ECB674E47D8C8B" stRef:documentID="xmp.did:B65E0B12B647E411A4ECB674E47D8C8B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>..................................................................................................................................~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;
<<< skipped >>>
GET /images/bluefox/misc/navbits_start.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 1073
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-431"
Accept-Ranges: bytes
GIF89a................~*#....)#|'". '~)#}(#.,'.($.*$|*#|)#.,(~)$} $. &. &. &.,'./,.0)./*.2,.40q1(.73.60p2)s4,.?8.A;.E@.PF.TJ.SK.\QXG3YH4..|..}......................*(.*(.,,. (.-,. (.0/./../...-.*'.53.0/.... ). ).--.,*.-,./,.11.//.10.2/.>=y5/v4-p4 s5-.A?.FB.EBl?3`B2^K8UN:..........00.54.11.--.?<{61...MN>.........EFB............................................................wwwqqqpppnnnLLLDDDCCCBBBAAA@@@???>>>DDD..............................................................................................................................................................................................................................................................................................................................................................................!.......,........@......$h........P..5."J.......<. #.O.;g..|"a...&..4pDJ.Ap$...fP...e...C...W......@=nf.T.ga..Jg...4...7|h.......P...gf..0...@.B..C..lH%...x.Ta....5n..^3gO........q..u....f.c...Pe..2...!:.. A...e(pP.c.. hd.A[..0[x4y..2...4...".....8)..O..P.dp. F.....Y".O B..M.1BdB...( ...P@.;....
GET /jpg/L3Zd0Sx.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=03a403b68d878ab4bd97dbdaa5c39aaa; bblastvisit=1488206652; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Mon, 27 Feb 2017 14:49:28 GMT
Content-Type: image/gif
Content-Length: 150541
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:07:30 GMT
ETag: "57c12e22-24c0d"
Accept-Ranges: bytes
GIF89a..x......7....&......c.....................iE.40!...fW....HA1QI5.di.....x...ulS..............k.........[S-.l.J1....efe.kG.....R...id3.sAlU1.nD.........|}|.}H}U8..X..k...wd8skF.....8../..4..2.....6....u.#..e[E...3%....S8$..........._..m..!........7WI(XQ>.....g."....../.X;..s...../..b.z^.......sK....u}......wg. ... .KB".D..% ...uK3.....g..!...........Y..L.)-.tZ.wXwq5..&...c....fmbM.....7..d..s..!.!%.....u..0z^?....|U..-.|2..~0*...#..t.a@.....X....$.TH....@)........S\."!........&..\.DG=4..<H.....i~tB.....)..d.&........!...o..........6=C.......s*....|..L....zP..$......LC.................._.~I.#&.....u...rrri>,[:(.DJ..).IQ.....$..j.ah....%........k<.......(-.......,$`8(..$...c?*<:(....-4..... .................^....."........ ..q..............&...UN<........1............!..NETSCAPE2.0.....!.......,......x.....Q..H......*\......#J.H.....3j...... C..I....(S.......0c..I....8s.......@...J....H.*].....P.J..T ..X.j......`...K..Y.V..].....p...K....v.............w..... ^...c...K.L.....3........C..M.....S.^.:4...c..M..]..s.....o.....N..q... _.......K.N..u...k...........O.5....._..<.....'.~.....#........._...h`z......J.`..F(.n.Nh....Va..v..c.~(..$..b.(...Y'....0R.b.4.h.P3....<.w^.@.).M9.i..#....LN.d.PFY..RVi.}T^........`..e.d....f...ph.........t.&g.x....z...c|.)....J....eh..6....F*.m.Vji.^^...rA......i................I.......J.................z.K..s....j*...a:...ZJK..QZ...Hj...Az...:.K..1....*....I....n.K.................b.K..K.....)....9....IL...Y....i....y.....L...................L..............
<<< skipped >>>
Map
The Trojan-Dropper connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_1908:
.text
.text
`.data
`.data
.idata
.idata
@.rsrc
@.rsrc
@.reloc
@.reloc
Invalid parameter passed to C runtime function.
Invalid parameter passed to C runtime function.
advapi32.dll
advapi32.dll
setupx.dll
setupx.dll
setupapi.dll
setupapi.dll
advpack.dll
advpack.dll
wininit.ini
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
Software\Microsoft\Windows\CurrentVersion\App Paths
ADMQCMD
ADMQCMD
USRQCMD
USRQCMD
FINISHMSG
FINISHMSG
IXPd.TMP
IXPd.TMP
msdownld.tmp
msdownld.tmp
TMP4351$.TMP
TMP4351$.TMP
wextract.pdb
wextract.pdb
PSSSSSSh
PSSSSSSh
SSSh
SSSh
PSSShp
PSSShp
PSShp
PSShp
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
wextract_cleanup%d
Command.com /c %s
Command.com /c %s
rundll32.exe %s,InstallHinfSection %s 128 %s
rundll32.exe %s,InstallHinfSection %s 128 %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
%s /D:%s
%s /D:%s
PendingFileRenameOperations
PendingFileRenameOperations
SHELL32.DLL
SHELL32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\
@Ew.AEw
@Ew.AEw
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegCloseKey
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
GDI32.dll
GDI32.dll
ExitWindowsEx
ExitWindowsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
USER32.dll
USER32.dll
_amsg_exit
_amsg_exit
_acmdln
_acmdln
msvcrt.dll
msvcrt.dll
COMCTL32.dll
COMCTL32.dll
Cabinet.dll
Cabinet.dll
VERSION.dll
VERSION.dll
CARDGE~1.EXE
CARDGE~1.EXE
00.exe
00.exe
d.GpF;
d.GpF;
Yzr.Ba
Yzr.Ba
Ow.UJ
Ow.UJ
U(%U
U(%U
wf.ZN
wf.ZN
.to-}}'^
.to-}}'^
.pqoNk
.pqoNk
.UW@M
.UW@M
.OED
.OED
.YHEO~t
.YHEO~t
I|
I|
Ue~.WG
Ue~.WG
~/)67>'
~/)67>'
m^^1G.PS8-
m^^1G.PS8-
.4& .*[3
.4& .*[3
.da'|
.da'|
W.exq
W.exq
b.gWtY
b.gWtY
}%x%.
}%x%.
3mI%SX
3mI%SX
5fL%x
5fL%x
.ow@x
.ow@x
t)T`%S
t)T`%S
.SnF(V
.SnF(V
j.CyTV
j.CyTV
m.xth$
m.xth$
.MRb.
.MRb.
.XxOj
.XxOj
_s.BB'
_s.BB'
5b5%u
5b5%u
%v.zp
%v.zp
]n2V#`f%d
]n2V#`f%d
T.tX_J
T.tX_J
%.U4"
%.U4"
K.BE.
K.BE.
%x9-]b>
%x9-]b>
.vU5g]r
.vU5g]r
=%X[-
=%X[-
Dba.ej#
Dba.ej#
:wW.sO
:wW.sO
vy"m.Ek
vy"m.Ek
w.DjG
w.DjG
.Xb`S
.Xb`S
%SlW9W
%SlW9W
'.ti,
'.ti,
!%fluWFE
!%fluWFE
Q=.ay4~
Q=.ay4~
;{%u:d
;{%u:d
$..DQD_
$..DQD_
.HwWaUv
.HwWaUv
[%DN^IA
[%DN^IA
#%X)(B
#%X)(B
P:?.so)
P:?.so)
T.TQ0h
T.TQ0h
HU$%U
HU$%U
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
Kernel32.dll
Kernel32.dll
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.OFalha ao obter informa
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.OFalha ao obter informa
o em disco de: %s.
o em disco de: %s.
Mensagem do sistema: %s..Um recurso necess
Mensagem do sistema: %s..Um recurso necess
o pode ser encontrado.#Tem certeza de que deseja cancelar?
o pode ser encontrado.#Tem certeza de que deseja cancelar?
o do sistema operacional.'Falha do pedido de aloca
o do sistema operacional.'Falha do pedido de aloca
O arquivo de gabinete (.cab) n
O arquivo de gabinete (.cab) n
vel encontrar uma unidade com %s KB de espa
vel encontrar uma unidade com %s KB de espa
o.NPasta inv
o.NPasta inv
lida. Certifique-se de que a pasta existe e de que permite grava
lida. Certifique-se de que a pasta existe e de que permite grava
o.ZEspecifique uma pasta com um nome de caminho totalmente qualificado ou clique em Cancelar.
o.ZEspecifique uma pasta com um nome de caminho totalmente qualificado ou clique em Cancelar.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
o da pasta.QN
o da pasta.QN
logo do navegador.RN
logo do navegador.RN
vel carregar Shell32.dll, necess
vel carregar Shell32.dll, necess
)Erro ao criar o processo . Causa: %s7N
)Erro ao criar o processo . Causa: %s7N
suporte para o tamanho do cluster deste sistema..Um recurso necess
suporte para o tamanho do cluster deste sistema..Um recurso necess
rio parece estar corrompido.IA instala
rio parece estar corrompido.IA instala
o requer o Windows 95 ou o Windows NT 4.0 beta 2 ou posterior.
o requer o Windows 95 ou o Windows NT 4.0 beta 2 ou posterior.
Erro ao carregar %smFalha de GetProcAddress() na fun
Erro ao carregar %smFalha de GetProcAddress() na fun
o '%s'. Poss
o '%s'. Poss
o incorreta de advpack.dll est
o incorreta de advpack.dll est
sendo usada.>O Windows 95 ou o Windows NT
sendo usada.>O Windows 95 ou o Windows NT
vel criar a pasta '%s'
vel criar a pasta '%s'
precisa de %s KB de espa
precisa de %s KB de espa
o livre na unidade %s.
o livre na unidade %s.
Error retrieving Windows folder
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
$Erro ao recuperar a pasta do Windows
$Erro ao recuperar a pasta do Windows
*Desligamento do NT: erro OpenProcessToken./Desligamento do NT: erro AdjustTokenPrivileges.'Desligamento do NT: erro ExitWindowsEx.
*Desligamento do NT: erro OpenProcessToken./Desligamento do NT: erro AdjustTokenPrivileges.'Desligamento do NT: erro ExitWindowsEx.
o em disco insuficiente para arquivo de permuta) ou arquivo de gabinete (.cab) corrompido._As informa
o em disco insuficiente para arquivo de permuta) ou arquivo de gabinete (.cab) corrompido._As informa
es de volume da unidade (%s) n
es de volume da unidade (%s) n
Mensagem do sistema: %s.
Mensagem do sistema: %s.
o e tente novamente.pO programa de instala
o e tente novamente.pO programa de instala
/C: -- Override Install Command defined by author.
/C: -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
Could not find the file: %s.
pia do pacote '%s' j
pia do pacote '%s' j
sendo executada no sistema. Deseja executar outra c
sendo executada no sistema. Deseja executar outra c
vel encontrar o arquivo: %s.
vel encontrar o arquivo: %s.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
xito quando executadas por um administrador.
xito quando executadas por um administrador.
(A pasta '%s' n
(A pasta '%s' n
sendo executada no sistema. Apenas uma c
sendo executada no sistema. Apenas uma c
pia pode ser executada de cada vez.PO pacote '%s' n
pia pode ser executada de cada vez.PO pacote '%s' n
o do Windows que est
o do Windows que est
sendo executada.FO pacote '%s' n
sendo executada.FO pacote '%s' n
o do arquivo: %s do sistema.
o do arquivo: %s do sistema.
11.00.9600.16428 (winblue_gdr.131013-1700)
11.00.9600.16428 (winblue_gdr.131013-1700)
WEXTRACT.EXE .MUI
WEXTRACT.EXE .MUI
11.00.9600.16428
11.00.9600.16428
iexplore.exe_1204:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
Bv9.jk
Bv9.jk
Bv.TBv
Bv.TBv
>.uzf
>.uzf
.us;}
.us;}
IEFRAME.dll
IEFRAME.dll
MLANG.dll
MLANG.dll
iertutil.dll
iertutil.dll
urlmon.dll
urlmon.dll
ole32.dll
ole32.dll
SHELL32.dll
SHELL32.dll
SHLWAPI.dll
SHLWAPI.dll
msvcrt.dll
msvcrt.dll
USER32.dll
USER32.dll
KERNEL32.dll
KERNEL32.dll
ADVAPI32.dll
ADVAPI32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
GetWindowsDirectoryW
GetWindowsDirectoryW
_amsg_exit
_amsg_exit
_wcmdln
_wcmdln
UrlApplySchemeW
UrlApplySchemeW
PathIsURLW
PathIsURLW
UrlCanonicalizeW
UrlCanonicalizeW
UrlCreateFromPathW
UrlCreateFromPathW
iexplore.pdb
iexplore.pdb
KEYW
KEYW
KEYWh
KEYWh
KEYWD
KEYWD
.ENNNG.
.ENNNG.
a.ry.v
a.ry.v
l.igM4
l.igM4
?1%SGf
?1%SGf
xh.JW^
xh.JW^
.97777"7" " " !
.97777"7" " " !
3.... ))
3.... ))
8888888888888
8888888888888
8888888888
8888888888
.lPV)
.lPV)
úW1
úW1
.ApX/
.ApX/
H.ZAf
H.ZAf
ð[U
ð[U
%s!FK
%s!FK
1YYYY1YY9GEAA=77YRNNNW:.VT1
1YYYY1YY9GEAA=77YRNNNW:.VT1
888777777
888777777
Y.hilkRROMLK=C,
Y.hilkRROMLK=C,
..(((($$
..(((($$
3...((((%
3...((((%
3....(.''$
3....(.''$
3.2...((((%
3.2...((((%
33.2....(,'
33.2....(,'
55323222...
55323222...
(%&'00443445?
(%&'00443445?
00.,,,4(
00.,,,4(
000.,,9(
000.,,9(
0020..9(
0020..9(
003200;(
003200;(
(#'( (''''!'!
(#'( (''''!'!
Microsoft.InternetExplorer.Default
Microsoft.InternetExplorer.Default
user32.dll
user32.dll
Kernel32.DLL
Kernel32.DLL
xfire.exe
xfire.exe
wlmail.exe
wlmail.exe
winamp.exe
winamp.exe
waol.exe
waol.exe
sidebar.exe
sidebar.exe
psocdesigner.exe
psocdesigner.exe
np.exe
np.exe
netscape.exe
netscape.exe
netcaptor.exe
netcaptor.exe
neoplanet.exe
neoplanet.exe
msn.exe
msn.exe
mshtmpad.exe
mshtmpad.exe
mshta.exe
mshta.exe
loader42.exe
loader42.exe
infopath.exe
infopath.exe
iexplore.exe
iexplore.exe
iepreview.exe
iepreview.exe
groove.exe
groove.exe
explorer.exe
explorer.exe
dreamweaver.exe
dreamweaver.exe
contribute.exe
contribute.exe
aol.exe
aol.exe
{28fb17e0-d393-439d-9a21-9474a070473a}
{28fb17e0-d393-439d-9a21-9474a070473a}
Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
DShell32.dll
DShell32.dll
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
"%s" %s
"%s" %s
Kernel32.dll
Kernel32.dll
\AppPatch\sysmain.sdb
\AppPatch\sysmain.sdb
-extoff go.microsoft.com/fwlink/?LinkId=106323
-extoff go.microsoft.com/fwlink/?LinkId=106323
-extoff go.microsoft.com/fwlink/?LinkId=106322
-extoff go.microsoft.com/fwlink/?LinkId=106322
-extoff go.microsoft.com/fwlink/?LinkId=106320
-extoff go.microsoft.com/fwlink/?LinkId=106320
kernel32.dll
kernel32.dll
{00000000-0000-0000-0000-000000000000}
{00000000-0000-0000-0000-000000000000}
\\?\Volume
\\?\Volume
shell:%s
shell:%s
Imaging_CreateWebPagePreview_Perftrack
Imaging_CreateWebPagePreview_Perftrack
Browseui_Tabs_Tearoff_BetweenWindows
Browseui_Tabs_Tearoff_BetweenWindows
Frame_URLEntered
Frame_URLEntered
Imaging_CreateWebPagePreview
Imaging_CreateWebPagePreview
WS_ExecuteQuery
WS_ExecuteQuery
Shdocvw_BaseBrowser_FireEvent_WindowStateChanged
Shdocvw_BaseBrowser_FireEvent_WindowStateChanged
IdleTask_Execution_Time
IdleTask_Execution_Time
9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
IEXPLORE.EXE
IEXPLORE.EXE
Windows
Windows
9.00.8112.16421
9.00.8112.16421
svchost.exe_2904:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
msvcrt.dll
msvcrt.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
RPCRT4.dll
RPCRT4.dll
ole32.dll
ole32.dll
ntdll.dll
ntdll.dll
_amsg_exit
_amsg_exit
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
GetProcessHeap
GetProcessHeap
svchost.pdb
svchost.pdb
version="5.1.0.0"
version="5.1.0.0"
name="Microsoft.Windows.Services.SvcHost"
name="Microsoft.Windows.Services.SvcHost"
Host Process for Windows Services
Host Process for Windows Services
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
\PIPE\
\PIPE\
Host Process for Windows Services
Host Process for Windows Services
6.1.7600.16385 (win7_rtm.090713-1255)
6.1.7600.16385 (win7_rtm.090713-1255)
svchost.exe
svchost.exe
Windows
Windows
Operating System
Operating System
6.1.7600.16385
6.1.7600.16385
iexplore.exe_1204_rwx_10000000_0004D000:
`.rsrc
`.rsrc
ServerKeyloggerU
ServerKeyloggerU
789:;
789:;
%SERVER%
%SERVER%
URLMON.DLL
URLMON.DLL
shell32.dll
shell32.dll
hXXp://
hXXp://
advapi32.dll
advapi32.dll
kernel32.dll
kernel32.dll
mpr.dll
mpr.dll
version.dll
version.dll
comctl32.dll
comctl32.dll
gdi32.dll
gdi32.dll
opengl32.dll
opengl32.dll
user32.dll
user32.dll
wintrust.dll
wintrust.dll
msimg32.dll
msimg32.dll
3Bv9.jkb
3Bv9.jkb
KWindows
KWindows
TServerKeylogger
TServerKeylogger
GetWindowsDirectoryW
GetWindowsDirectoryW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyW
RegCreateKeyW
RegCloseKey
RegCloseKey
RegOpenKeyExA
RegOpenKeyExA
FindExecutableW
FindExecutableW
ShellExecuteW
ShellExecuteW
SHDeleteKeyW
SHDeleteKeyW
URLDownloadToCacheFileW
URLDownloadToCacheFileW
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExW
SetWindowsHookExW
MapVirtualKeyW
MapVirtualKeyW
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyboardType
GetKeyboardType
GetKeyboardState
GetKeyboardState
FtpPutFileW
FtpPutFileW
FtpSetCurrentDirectoryW
FtpSetCurrentDirectoryW
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
URLF
URLF
KERNEL32.DLL
KERNEL32.DLL
ntdll.dll
ntdll.dll
oleaut32.dll
oleaut32.dll
shlwapi.dll
shlwapi.dll
wininet.dll
wininet.dll
x.html
x.html
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
[Execute]
[Execute]
KeyDelBackspace
KeyDelBackspace
.html
.html
XtremeKeylogger
XtremeKeylogger
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
.functions
.functions
icon=shell32.dll,4
icon=shell32.dll,4
shellexecute=
shellexecute=
autorun.inf
autorun.inf
\Microsoft\Windows\
\Microsoft\Windows\
ÞFAULTBROWSER%
ÞFAULTBROWSER%
svchost.exe
svchost.exe
ah-antihacker.ddns.net
ah-antihacker.ddns.net
ftpuser
ftpuser
{GC38A0CR-DN53-H852-7HLM-OT3OQ1BPW5BR}
{GC38A0CR-DN53-H852-7HLM-OT3OQ1BPW5BR}
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ogspot.comHKCU
ogspot.comHKCU
PTF.ftpserver.com
PTF.ftpserver.com
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe
%Program Files%\Internet Explorer\iexplore.exe
%Program Files%\Internet Explorer\iexplore.exe