Update information about this common vendor daemon.
1, three vendor's daemon name and 'encrypted name' can be get inside _l_n36_buff route.
If common vendor daemon technology will be used?
Code:
.text:004AEDA7 cmp off_59B3E0, 0
.text:004AEDAE jz short loc_4AEDB6
.text:004AEDB0 call off_59B3E0
_l_n36_buff route entry for different daemons.
Code:
.text:004354E6 sub_4354E6 proc near ; CODE XREF: sub_4AED2F+81p
.text:004354E6 ; DATA XREF: .data:off_59B3E0o
.text:004354E6 mov eax, off_59C024
.text:004354EB and dword_5C570C, 0
.text:004354F2 mov dword_5C5700, eax
.text:004354F7 mov eax, off_59DD6C
.text:004354FC mov dword_5C5704, eax
.text:00435501 mov eax, off_59D24C
.text:00435506 mov dword_5C5708, eax
.text:0043550B mov dword_5C5800, offset dword_5C5700
.text:00435515 retn
.text:00435515 sub_4354E6 endp
2, three sets seeds can be reverted from _l_sg route with encrypted daemon name and their code and job.
No difference from normal vendor daemon.