Analysis Date2015-05-09 21:32:15
MD5c9613c8d6b448a4a8ef0c2b7f96a2fd9
SHA13ef3196a348f428d3c9124361d0a189bebb8e6dd

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 6182d910529bff034b97df60df69f7fa sha1: 5093659ac0773f5b9048fa80f41a7fefb6f47257 size: 110592
Section.rdata md5: 2f239b7267f8f100e7bf3ee15a213f77 sha1: 118f48fb8ca70ad457623d03d9307e3a107d1728 size: 30208
Section.data md5: 5a562c1e83ae76f2065b6cd161106208 sha1: 0feee8127b197b55bec6b2714ba22525d5c85458 size: 11264
Section.rsrc md5: e3ac3630777468c4687c3be14781b412 sha1: 03f939bc4e6388c9e69f1dad4660d8ea4e92588d size: 4608
Timestamp2014-08-26 10:55:55
PackerMicrosoft Visual C++ ?.?
PEhash965b3fcfd5f45b921c2dc199de54c793ab8464f8
IMPhash3125567d4db4e682bb1adbd72430567a
AVAd-AwareTrojan.Foreign.2
AVAlwil (avast)GenMalicious-INJ [Trj]
AVArcabit (arcavir)Trojan.Foreign.2
AVAuthentiumno_virus
AVAvira (antivir)TR/Crypt.ZPACK.146442
AVBitDefenderTrojan.Foreign.2
AVBullGuardTrojan.Foreign.2
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)TrojanPWS.Zbot.A5
AVClamAVno_virus
AVDr. WebTrojan.DownLoader11.29300
AVEmsisoftTrojan.Foreign.2
AVEset (nod32)Win32/Wigon.PH
AVFortinetW32/Cutwail.DXA!tr
AVFrisk (f-prot)no_virus
AVF-SecureTrojan.Foreign.2
AVGrisoft (avg)Crypt3.ALSH
AVIkarusTrojan.Win32.Wigon
AVK7Trojan ( 0040c0821 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.Agent.ED
AVMcafeePWSZbot-FAVM!C9613C8D6B44
AVMicrosoft Security EssentialsTrojan:Win32/Danglo!gmb
AVMicroWorld (escan)Trojan.Foreign.2
AVPadvishno_virus
AVRisingno_virus
AVSophosTroj/Wonton-FZ
AVSymantecno_virus
AVTrend Microno_virus
AVTwisterTrojan.Cutwail.dxa.obcb
AVVirusBlokAda (vba32)Trojan.Cutwail

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\netuamashene ➝
C:\Documents and Settings\Administrator\netuamashene.exe
RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\AppManagement ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication\Name ➝
malware.exe\\x00
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\yokomizo[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\dilmar[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\wigor.com[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\kitadol[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\hsmc-ul[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\ndimedia[2].htm
Creates FileC:\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-500\a18ca4003deb042bbee7a40f15e1970b_666939c9-243b-475e-9504-51724db22670
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\mlc-edu[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\yokomizo[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\nomics[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\timetec[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\corex[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\pcg[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\smsch[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\nopa.or[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\proseinc[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\6ml[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\recsjpn[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\alan-jp[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\dilmar[1].htm
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\2-tier[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\citymade[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\mm7m[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\webways[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\wigor.com[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\kitadol[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\nomics[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\pids[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\timetec[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\elaana[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\densa[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\saamii[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\iwsa[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\hzjinhai[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\nopa.or[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\edimart[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\cdnins[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\pcg[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\akr.co[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\enchilada[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\mjrcpas[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\tndha[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\mm7m[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\walltodo[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\hostings[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\aiglon[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\bd-style[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\edimart[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\sozolife[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\uls-dc[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\canaxini[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\skmat[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\kndata[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\umcor[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\arit[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\rmcet[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\hostings[1].htm
Creates FileC:\Documents and Settings\Administrator\netuamashene.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\as-auto[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\walltodo[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\kiwicr[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\iwsa[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\kp2i[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\platex[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\jala-mi[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\emka[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\adf.org[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\hsmc-ul[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\densa[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\jinsey[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\hostito[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\jhitomi[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\x1[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\raboo[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\richter[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\ingimex[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\willvic[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\elaana[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\proseinc[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\enchilada[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\smsch[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\taeha[1].htm
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\x1[1].htm
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\rmcet[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\sozolife[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\platex[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\webways[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\maintasc[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\jinsey[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\willvic[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\2-tier[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\kndata[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\arit[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\frimeset[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\uls-dc[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\cdnins[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\restpro[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\taeha[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\as-auto[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\akr.co[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\alan-jp[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\adf.org[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\skmat[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\bd-style[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\cowbite[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\abdg[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\tndha[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\hzjinhai[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\mlc-edu[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\recsjpn[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\cowbite[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\richter[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\maintasc[2].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\pids[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\frimeset[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\restpro[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\abdg[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\jhitomi[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\kp2i[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\umcor[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\citymade[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\canaxini[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\saamii[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\corex[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\kiwicr[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\ingimex[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\ndimedia[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\emka[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\mjrcpas[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\6ml[1].htm
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\jala-mi[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\pids[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\kp2i[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\yokomizo[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\akr.co[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\adf.org[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\alan-jp[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\dilmar[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\skmat[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\timetec[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\kitadol[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\densa[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\hsmc-ul[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\cowbite[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\hzjinhai[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\abdg[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\jinsey[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\cdnins[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\mlc-edu[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\recsjpn[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\x1[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\enchilada[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\jhitomi[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\mjrcpas[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\richter[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\tndha[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\nomics[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\pcg[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\corex[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\elaana[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\nopa.or[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\bd-style[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\edimart[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\citymade[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\proseinc[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\smsch[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\taeha[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\canaxini[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\saamii[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\umcor[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\sozolife[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\rmcet[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\2-tier[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\platex[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\mm7m[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\kiwicr[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\ingimex[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\maintasc[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\ndimedia[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\willvic[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\hostings[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\kndata[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\D4Z32ED8\arit[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\webways[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\uls-dc[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\frimeset[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\wigor.com[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IIQ3LGTM\walltodo[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\jala-mi[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\6ml[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BSDHA97U\emka[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\iwsa[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\as-auto[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\restpro[1].htm
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutexnetuamashene
Winsock DNSplatex.com
Winsock DNSwalltodo.com
Winsock DNSactmin.com
Winsock DNSelaana.com
Winsock DNSadf.org.tr
Winsock DNSwebways.com
Winsock DNS2-tier.com
Winsock DNSkitadol.com
Winsock DNSmjrcpas.com
Winsock DNS6ml.net
Winsock DNShostings.com
Winsock DNSuls-dc.org
Winsock DNSemka.fr
Winsock DNSenchilada.de
Winsock DNSproseinc.com
Winsock DNStimetec.ru
Winsock DNScowbite.com
Winsock DNSfotalex.ru
Winsock DNSpids.org
Winsock DNSsaamii.com
Winsock DNSiwsa.net
Winsock DNSpcg.com
Winsock DNSndimedia.com
Winsock DNSdilmar.com
Winsock DNSkiwicr.com
Winsock DNSwillvic.net
Winsock DNSarit.cz
Winsock DNScdnins.com
Winsock DNSbd-style.com
Winsock DNScanaxini.com
Winsock DNSrichter.bg
Winsock DNSsignbar.com
Winsock DNSalan-jp.com
Winsock DNSnopa.or.jp
Winsock DNSyokomizo.com
Winsock DNSoreggia.com
Winsock DNScitymade.com
Winsock DNScom-sit.com
Winsock DNShsmc-ul.com
Winsock DNSkp2i.com
Winsock DNSakr.co.id
Winsock DNShostito.com
Winsock DNSjinsey.com
Winsock DNSmlc-edu.com
Winsock DNSas-auto.ru
Winsock DNSrestpro.com
Winsock DNSx1.com
Winsock DNSok.co.kr
Winsock DNSkndata.com
Winsock DNSnomics.de
Winsock DNSaiglon.ch
Winsock DNSsozolife.com
Winsock DNSraboo.com
Winsock DNSrmcet.com
Winsock DNSfrimeset.com
Winsock DNSwigor.com.pl
Winsock DNShzjinhai.com
Winsock DNSrecsjpn.com
Winsock DNStndha.org
Winsock DNSdensa.ch
Winsock DNStaeha.com
Winsock DNSjala-mi.org
Winsock DNSskmat.com
Winsock DNScorex.de
Winsock DNSmaintasc.com
Winsock DNSedimart.hu
Winsock DNSsie-mar.com
Winsock DNSumcor.am
Winsock DNSingimex.com
Winsock DNSsmsch.org
Winsock DNSjhitomi.com
Winsock DNSmm7m.com
Winsock DNSabdg.com

Network Details:

DNSkitadol.com
Type: A
74.86.82.253
DNScanaxini.com
Type: A
82.98.136.112
DNShostito.com
Type: A
63.247.91.234
DNSingimex.com
Type: A
94.229.164.169
DNSyokomizo.com
Type: A
149.115.17.22
DNSpcg.com
Type: A
70.32.76.86
DNScorex.de
Type: A
78.138.91.55
DNSsozolife.com
Type: A
162.249.1.4
DNSmaintasc.com
Type: A
93.94.228.110
DNSrestpro.com
Type: A
70.34.33.191
DNSfrimeset.com
Type: A
207.182.143.58
DNSkiwicr.com
Type: A
190.0.226.9
DNSrmcet.com
Type: A
103.21.58.244
DNSnopa.or.jp
Type: A
202.228.219.210
DNSarit.cz
Type: A
77.78.106.223
DNS2-tier.com
Type: A
23.253.58.227
DNS2-tier.com
Type: A
107.20.132.157
DNS2-tier.com
Type: A
162.242.150.89
DNS2-tier.com
Type: A
176.34.241.253
DNSabdg.com
Type: A
64.14.74.41
DNSnomics.de
Type: A
92.51.133.137
DNSemka.fr
Type: A
85.31.222.130
DNSkp2i.com
Type: A
217.16.10.3
DNSndimedia.com
Type: A
204.147.76.213
DNSskmat.com
Type: A
104.24.101.173
DNSskmat.com
Type: A
104.24.100.173
DNSiwsa.net
Type: A
206.183.111.156
DNSdilmar.com
Type: A
207.58.182.49
DNShzjinhai.com
Type: A
184.168.192.40
DNSfotalex.ru
Type: A
127.0.0.1
DNSwalltodo.com
Type: A
68.233.239.85
DNSrecsjpn.com
Type: A
160.16.95.166
DNSwebways.com
Type: A
209.85.25.218
DNSplatex.com
Type: A
5.39.12.158
DNSedimart.hu
Type: A
185.51.65.164
DNSrichter.bg
Type: A
92.247.120.66
DNSwigor.com.pl
Type: A
87.98.234.130
DNSmjrcpas.com
Type: A
207.178.244.196
DNSjhitomi.com
Type: A
59.106.13.40
DNSmlc-edu.com
Type: A
219.94.129.195
DNScowbite.com
Type: A
216.137.147.15
DNSsaamii.com
Type: A
203.189.104.105
DNS6ml.net
Type: A
203.189.104.105
DNSkndata.com
Type: A
104.28.22.114
DNSkndata.com
Type: A
104.28.23.114
DNSbd-style.com
Type: A
203.189.104.233
DNStimetec.ru
Type: A
5.9.66.101
DNSumcor.am
Type: A
31.7.163.133
DNSalan-jp.com
Type: A
158.199.229.57
DNSelaana.com
Type: A
173.192.60.199
DNShostings.com
Type: A
69.94.125.52
DNSdensa.ch
Type: A
80.74.139.2
DNSok.co.kr
Type: A
127.0.0.1
DNSproseinc.com
Type: A
68.171.19.134
DNSenchilada.de
Type: A
108.162.206.171
DNSenchilada.de
Type: A
108.162.205.171
DNSjala-mi.org
Type: A
198.41.207.195
DNSjala-mi.org
Type: A
198.41.206.195
DNSmm7m.com
Type: A
74.119.146.124
DNScitymade.com
Type: A
137.117.97.99
DNSx1.com
Type: A
64.207.144.34
DNStaeha.com
Type: A
211.206.123.37
DNSsignbar.com
Type: A
127.0.0.1
DNScdnins.com
Type: A
67.220.209.116
DNSjinsey.com
Type: A
70.32.68.193
DNSpids.org
Type: A
64.34.173.237
DNSas-auto.ru
Type: A
81.177.18.19
DNSadf.org.tr
Type: A
78.189.184.192
DNSwillvic.net
Type: A
208.113.213.185
DNSuls-dc.org
Type: A
216.104.182.58
DNShsmc-ul.com
Type: A
173.214.186.105
DNStndha.org
Type: A
74.81.186.49
DNSsmsch.org
Type: A
67.225.140.40
DNSactmin.com
Type: A
DNSsie-mar.com
Type: A
DNSoreggia.com
Type: A
HTTP POSThttp://hostito.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://sozolife.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://yokomizo.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://ingimex.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://canaxini.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kitadol.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://pcg.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://corex.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://maintasc.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hostito.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://ingimex.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kitadol.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://corex.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://restpro.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://canaxini.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://sozolife.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://maintasc.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://pcg.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://yokomizo.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://restpro.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://frimeset.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://frimeset.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kiwicr.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://rmcet.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://nopa.or.jp/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://arit.cz/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kiwicr.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://2-tier.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://abdg.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://nomics.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://rmcet.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://emka.fr/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://2-tier.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://arit.cz/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://abdg.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://nopa.or.jp/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://nomics.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://emka.fr/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kp2i.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kp2i.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://ndimedia.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://ndimedia.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://skmat.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://iwsa.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://dilmar.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hzjinhai.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://walltodo.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://skmat.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://iwsa.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://dilmar.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://recsjpn.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hzjinhai.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://webways.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://walltodo.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://recsjpn.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://webways.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://platex.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://platex.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://edimart.hu/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://edimart.hu/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://richter.bg/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://wigor.com.pl/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mjrcpas.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jhitomi.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://richter.bg/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mlc-edu.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://wigor.com.pl/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://cowbite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://saamii.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jhitomi.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://6ml.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mjrcpas.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kndata.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mlc-edu.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://cowbite.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://saamii.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://kndata.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://6ml.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://bd-style.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://timetec.ru/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://umcor.am/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://alan-jp.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://bd-style.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://timetec.ru/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://elaana.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://umcor.am/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hostings.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://alan-jp.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://densa.ch/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://elaana.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hostings.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://densa.ch/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://proseinc.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://proseinc.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://enchilada.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jala-mi.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://enchilada.de/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mm7m.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jala-mi.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://mm7m.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://citymade.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://x1.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://taeha.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://citymade.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://x1.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://taeha.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://cdnins.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://cdnins.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jinsey.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://jinsey.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://pids.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://as-auto.ru/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://adf.org.tr/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://pids.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://willvic.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://as-auto.ru/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://uls-dc.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hsmc-ul.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://adf.org.tr/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://willvic.net/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://uls-dc.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://hsmc-ul.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://tndha.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://tndha.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://smsch.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTP POSThttp://smsch.org/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Flows TCP192.168.1.1:1042 ➝ 63.247.91.234:80
Flows TCP192.168.1.1:1035 ➝ 162.249.1.4:80
Flows TCP192.168.1.1:1036 ➝ 149.115.17.22:80
Flows TCP192.168.1.1:1037 ➝ 94.229.164.169:80
Flows TCP192.168.1.1:1039 ➝ 74.86.82.253:80
Flows TCP192.168.1.1:1038 ➝ 82.98.136.112:80
Flows TCP192.168.1.1:1040 ➝ 70.32.76.86:80
Flows TCP192.168.1.1:1041 ➝ 78.138.91.55:80
Flows TCP192.168.1.1:1043 ➝ 93.94.228.110:80
Flows TCP192.168.1.1:1044 ➝ 63.247.91.234:80
Flows TCP192.168.1.1:1045 ➝ 94.229.164.169:80
Flows TCP192.168.1.1:1046 ➝ 74.86.82.253:80
Flows TCP192.168.1.1:1047 ➝ 78.138.91.55:80
Flows TCP192.168.1.1:1048 ➝ 70.34.33.191:80
Flows TCP192.168.1.1:1049 ➝ 82.98.136.112:80
Flows TCP192.168.1.1:1050 ➝ 162.249.1.4:80
Flows TCP192.168.1.1:1051 ➝ 93.94.228.110:80
Flows TCP192.168.1.1:1052 ➝ 70.32.76.86:80
Flows TCP192.168.1.1:1053 ➝ 149.115.17.22:80
Flows TCP192.168.1.1:1054 ➝ 70.34.33.191:80
Flows TCP192.168.1.1:1055 ➝ 207.182.143.58:80
Flows TCP192.168.1.1:1056 ➝ 207.182.143.58:80
Flows TCP192.168.1.1:1057 ➝ 190.0.226.9:80
Flows TCP192.168.1.1:1058 ➝ 103.21.58.244:80
Flows TCP192.168.1.1:1059 ➝ 202.228.219.210:80
Flows TCP192.168.1.1:1060 ➝ 77.78.106.223:80
Flows TCP192.168.1.1:1061 ➝ 190.0.226.9:80
Flows TCP192.168.1.1:1062 ➝ 23.253.58.227:80
Flows TCP192.168.1.1:1063 ➝ 64.14.74.41:80
Flows TCP192.168.1.1:1064 ➝ 92.51.133.137:80
Flows TCP192.168.1.1:1065 ➝ 103.21.58.244:80
Flows TCP192.168.1.1:1066 ➝ 85.31.222.130:80
Flows TCP192.168.1.1:1067 ➝ 23.253.58.227:80
Flows TCP192.168.1.1:1068 ➝ 77.78.106.223:80
Flows TCP192.168.1.1:1069 ➝ 64.14.74.41:80
Flows TCP192.168.1.1:1070 ➝ 202.228.219.210:80
Flows TCP192.168.1.1:1071 ➝ 92.51.133.137:80
Flows TCP192.168.1.1:1072 ➝ 85.31.222.130:80
Flows TCP192.168.1.1:1073 ➝ 217.16.10.3:80
Flows TCP192.168.1.1:1074 ➝ 217.16.10.3:80
Flows TCP192.168.1.1:1075 ➝ 204.147.76.213:80
Flows TCP192.168.1.1:1076 ➝ 204.147.76.213:80
Flows TCP192.168.1.1:1077 ➝ 104.24.101.173:80
Flows TCP192.168.1.1:1078 ➝ 206.183.111.156:80
Flows TCP192.168.1.1:1079 ➝ 207.58.182.49:80
Flows TCP192.168.1.1:1080 ➝ 184.168.192.40:80
Flows TCP192.168.1.1:1082 ➝ 68.233.239.85:80
Flows TCP192.168.1.1:1083 ➝ 104.24.101.173:80
Flows TCP192.168.1.1:1084 ➝ 206.183.111.156:80
Flows TCP192.168.1.1:1085 ➝ 207.58.182.49:80
Flows TCP192.168.1.1:1086 ➝ 160.16.95.166:80
Flows TCP192.168.1.1:1087 ➝ 184.168.192.40:80
Flows TCP192.168.1.1:1088 ➝ 209.85.25.218:80
Flows TCP192.168.1.1:1089 ➝ 68.233.239.85:80
Flows TCP192.168.1.1:1090 ➝ 160.16.95.166:80
Flows TCP192.168.1.1:1091 ➝ 209.85.25.218:80
Flows TCP192.168.1.1:1092 ➝ 5.39.12.158:80
Flows TCP192.168.1.1:1093 ➝ 5.39.12.158:80
Flows TCP192.168.1.1:1094 ➝ 185.51.65.164:80
Flows TCP192.168.1.1:1095 ➝ 185.51.65.164:80
Flows TCP192.168.1.1:1096 ➝ 92.247.120.66:80
Flows TCP192.168.1.1:1097 ➝ 87.98.234.130:80
Flows TCP192.168.1.1:1098 ➝ 207.178.244.196:80
Flows TCP192.168.1.1:1099 ➝ 59.106.13.40:80
Flows TCP192.168.1.1:1100 ➝ 92.247.120.66:80
Flows TCP192.168.1.1:1101 ➝ 219.94.129.195:80
Flows TCP192.168.1.1:1102 ➝ 87.98.234.130:80
Flows TCP192.168.1.1:1103 ➝ 216.137.147.15:80
Flows TCP192.168.1.1:1104 ➝ 203.189.104.105:80
Flows TCP192.168.1.1:1105 ➝ 59.106.13.40:80
Flows TCP192.168.1.1:1106 ➝ 203.189.104.105:80
Flows TCP192.168.1.1:1107 ➝ 207.178.244.196:80
Flows TCP192.168.1.1:1108 ➝ 104.28.22.114:80
Flows TCP192.168.1.1:1109 ➝ 219.94.129.195:80
Flows TCP192.168.1.1:1110 ➝ 216.137.147.15:80
Flows TCP192.168.1.1:1111 ➝ 203.189.104.105:80
Flows TCP192.168.1.1:1112 ➝ 104.28.22.114:80
Flows TCP192.168.1.1:1113 ➝ 203.189.104.105:80
Flows TCP192.168.1.1:1114 ➝ 203.189.104.233:80
Flows TCP192.168.1.1:1115 ➝ 5.9.66.101:80
Flows TCP192.168.1.1:1116 ➝ 31.7.163.133:80
Flows TCP192.168.1.1:1117 ➝ 158.199.229.57:80
Flows TCP192.168.1.1:1118 ➝ 203.189.104.233:80
Flows TCP192.168.1.1:1119 ➝ 5.9.66.101:80
Flows TCP192.168.1.1:1120 ➝ 173.192.60.199:80
Flows TCP192.168.1.1:1121 ➝ 31.7.163.133:80
Flows TCP192.168.1.1:1122 ➝ 69.94.125.52:80
Flows TCP192.168.1.1:1123 ➝ 158.199.229.57:80
Flows TCP192.168.1.1:1124 ➝ 80.74.139.2:80
Flows TCP192.168.1.1:1126 ➝ 173.192.60.199:80
Flows TCP192.168.1.1:1127 ➝ 69.94.125.52:80
Flows TCP192.168.1.1:1128 ➝ 80.74.139.2:80
Flows TCP192.168.1.1:1129 ➝ 68.171.19.134:80
Flows TCP192.168.1.1:1130 ➝ 68.171.19.134:80
Flows TCP192.168.1.1:1131 ➝ 108.162.206.171:80
Flows TCP192.168.1.1:1132 ➝ 198.41.207.195:80
Flows TCP192.168.1.1:1133 ➝ 108.162.206.171:80
Flows TCP192.168.1.1:1134 ➝ 74.119.146.124:80
Flows TCP192.168.1.1:1135 ➝ 198.41.207.195:80
Flows TCP192.168.1.1:1136 ➝ 74.119.146.124:80
Flows TCP192.168.1.1:1137 ➝ 137.117.97.99:80
Flows TCP192.168.1.1:1138 ➝ 64.207.144.34:80
Flows TCP192.168.1.1:1139 ➝ 211.206.123.37:80
Flows TCP192.168.1.1:1141 ➝ 137.117.97.99:80
Flows TCP192.168.1.1:1142 ➝ 64.207.144.34:80
Flows TCP192.168.1.1:1143 ➝ 211.206.123.37:80
Flows TCP192.168.1.1:1144 ➝ 67.220.209.116:80
Flows TCP192.168.1.1:1145 ➝ 67.220.209.116:80
Flows TCP192.168.1.1:1146 ➝ 70.32.68.193:80
Flows TCP192.168.1.1:1147 ➝ 70.32.68.193:80
Flows TCP192.168.1.1:1148 ➝ 64.34.173.237:80
Flows TCP192.168.1.1:1149 ➝ 81.177.18.19:80
Flows TCP192.168.1.1:1150 ➝ 78.189.184.192:80
Flows TCP192.168.1.1:1151 ➝ 64.34.173.237:80
Flows TCP192.168.1.1:1152 ➝ 208.113.213.185:80
Flows TCP192.168.1.1:1153 ➝ 81.177.18.19:80
Flows TCP192.168.1.1:1154 ➝ 216.104.182.58:80
Flows TCP192.168.1.1:1155 ➝ 173.214.186.105:80
Flows TCP192.168.1.1:1156 ➝ 78.189.184.192:80
Flows TCP192.168.1.1:1157 ➝ 208.113.213.185:80
Flows TCP192.168.1.1:1158 ➝ 216.104.182.58:80
Flows TCP192.168.1.1:1159 ➝ 173.214.186.105:80
Flows TCP192.168.1.1:1160 ➝ 74.81.186.49:80
Flows TCP192.168.1.1:1161 ➝ 74.81.186.49:80
Flows TCP192.168.1.1:1162 ➝ 67.225.140.40:80
Flows TCP192.168.1.1:1163 ➝ 67.225.140.40:80

Raw Pcap

Strings
0
. 
CC-E-
-0
-0010+-0
-0
\
.
0
0- 
0
0
u

- abort() has been called
AMicrosoft Visual C++ Runtime Library
April
<a>SysLink1</a>
<a>SysLink2</a>
<a>SysLink3</a>
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
.Button
command
CONOUT$
- CRT not initialized
dddd, MMMM dd, yyyy
December
Dialog
DOMAIN error
February
file:
File
- floating point support not loaded
Friday
                                 H
         (((((                  H
         h((((                  H
HH:mm:ss
January
July
June
March
MM/dd/yy
Monday
mscoree.dll
msctls_progress32
msctls_trackbar32
msctls_updown32
MS Shell Dlg
nKERNEL32.DLL
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
October
Open
popularize
Program: 
<program name unknown>
- pure virtual function call
R6002
R6008
R6009
R6010
R6016
R6017
R6018
R6019
R6024
R6025
R6026
R6027
R6028
R6030
R6031
R6032
R6033
Radio1
reading
rename
runtime error 
Runtime Error!
Saturday
September
SING error
Sunday
SysAnimate32
SysLink
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
Thursday
TLOSS error
Tuesday
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
Wednesday
writhing
WUSER32.DLL
                          
0<0@0U0
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
0;1L1A1
09k9y9
<101J1Z1
1E2W2z2
1#QNAN
1#SNAN
2rCT<0
3(3"3E3
:.;';4;
4;515Y5
+'4hD\
4T\	4:8
4:\:W:n:
525X5x5
5,5#565
>5?K?f?
6D6@6\6Xr6
7O7A7[7
84828`8
8 858n8
>?89:;4
89:;45'#
8	9-9'9
93O3b3
9*:<:4
,979C9
,9&9=969
9cbbio
@ABC\]^_
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
ABC\]^_X
`ac|}~
*Achy`i
Acve``
ADql "R 
ADVAPI32.dll
AL W;I|
AMEMMAhJ#MMMMMOHj]kMH8_NM]MMk?<AMM'Ih{IMMExJOJH#JmOkMM_J{M'IV]IMMExBHJD#JmOkMM_J{M'IY{IMMAhJ'M]NMMM\x`Y]dhF<I8=J'JOBfif'##5^#t[Yc]MI:thcNMIMME>Z:\;##=FcOGEMN\4ZbGMMNExJHJOBfif'##5^mN_eMM^cM{IMME>Z>\?##=@#JTedMM_HtN_Bdhf5##5]e<<EYj4ZaGMMNETMhH
aO@_EH
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<at,<rt"<wt
August
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
=a?z?p
\b##4iJx\b##{]NMMOB`jH'##'F`ov9###DdhH9##4IM]MMfU[k'j##YKcMmkO@X]d^#t[
bad allocation
 Base Class Array'
 Base Class Descriptor at (
__based(
BeginPaint
?>Bitx
bixO`c
bjc~amxe,cbM
bJe`xi~
\b##=O@fVf9##5^#t[<c]MIeU[o'j##k;>o'j##MM'IK]AMMKcMmMMHEMOB`hv9##5_mkN}MEyJv\b##=Nc?GEMNEyBb\b##=D#JnedMM_FdiX9##'HziX9##4MH8XCMkMMe=Y]YafcckMImMMIMMOBdjH:##5]#tZ8c]MIk4]]mkN}#8>B4\~##=K@`iX9##5_#t[4c]MIdoM\dEAOMMHDdUv9##4{h]MMk?<kMD8Fe<YkeU[A'j##mk_BfUv9##5^mkm@`iX9##5_#tTMc]MIt8[]'j##M]MMMAiJ`\b##{MMMMHDdUX8##4MM]MMmMMNMMN}ME>Je\f##=Hcc=IMME\IHAiJk\f##{MMMMO@X^N^e=YAYacMmkO@diX9##5]#tTIc]MIdoM\dBINMMOBfUH8##5^fV[I'\##Yc>Je\f##=N}I8yB9\b##=D#JoedMM_J{D]afV[E'\##YyftY]MMk4]IeUZ<'\##k?<gMD]@e<Yge8=<'\##e]dcMMIMMKcMfV[E'\##YykYY]MMk4]At8Z4'\##MMMUME>Jk\f##=OBfUX8##5^fV[E'\##YacJe8Tg'j##Y\4ZuGIMNETMhHmBfUf8##5^:EB^MMOHtM_FdTH8##'HzTH8##4MjdeNzTH8##4MMMNMj]u@`TH8##'F`Tv8##5}NKkMAMMMe8Z4'\##YKcM#t[<cMMIeUZ8'\##k;=8'\##MM'I}]MMMExBJEyZi\f##8g^e<YUe8=4'\##e]fD^j{NMMMMe9Z4'\##eVZ
build.exe
Button
<B<_<W<v
BX,9"=7,
[c{:8\
c~amboi
c~amboiO(cyM!
ca|mxen`
cbaibxZm
__cdecl
CGiQ &(
CheckMenuItem
,|~ck~
 Class Hierarchy Descriptor'
CloseClipboard
CloseEventLog
CloseHandle
CloseWindow
__clrcall
C\_M\E
@cmh@e
c]MIdoM\dEYHMMN}MKcMmkN}M[egckMIgB
CoInternetParseUrl
COMCTL32.dll
 Complete Object Locator'
`copy constructor closure'
CorExitProcess
coxix!
CreateEventA
CreateFileA
CreateFileW
CreateFontA
CreateFontIndirectA
CreatePalette
CreateTimerQueue
CreateToolbarEx
CreateWindowExA
\~czehi~,,z="<##dxLx|6##)
D8OE`J:CzOe<Tke'Zh{4vAvAvAvAvAvJ[@;ED
@.data
dddd, MMMM dd, yyyy
DEB5OMN<IcB5HMN<HEB5OMN<NcB5JMN=OE\E#'`IM]MMt<T
December
DecodePointer
`default constructor closure'
DefWindowProcA
 delete
 delete[]
Delete
DeleteCriticalSection
DeleteObject
DeleteTimerQueue
DescribePixelFormat
DesE(k
DestroyAcceleratorTable
DestroyCursor
DestroyMenu
DestroyWindow
_di``\~
DialogBoxParamA
`di`|?>_Lbm|
DirectDrawCreate
DispatchMessageA
_D@[M\
dP{ebhc{
]Dpx2)
DrawMenuBar
DrawTextA
dxx|6,##)
Dxx|]yTi~u
`dynamic atexit destructor for '
`dynamic initializer for '
/>$>E>_>
*<<<E<_<
E5n5k5wLv
__eabi
EamkiJeL`iBmai
[EBEBI
[E,BEBIX
[eb>(G
[ebhc{
,eb,HC_,
|~ebxjM
ecbP~yb
EFG@ABC\
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
EI,:"<7,
e<{]IJK@ZiN~<ee@^iu@XjkHXNMYYUxZ8Kz_GExJ;ExB5MBAIMt^:N5GMMOHtMv~
EJB[Z4hJ#MMMMMO@^]eF^jeHjjkMH8]AM]MMe<?8e=T8M=I4eZTce<TcH;hEJExZ:E=IOdeF^iu@Xie@YZOFZjN}]KkMAMMMe<T{YExB:Ex^BJ@#Jn_kMM_F^j_Hjj]Mh^V}]KkMAMMMe<T{YKcM#t[<cMMIeYT<k??<MM'I|]MMMExB:Ex^ZJG@^jd]e<?<Yid=_kMMk4]At<TkMMMMMC
ej,ite
Ellipse
e``m#8"<
~emn`iM
EnableMenuItem
EncodePointer
EndDialog
EndPaint
en`i7,A_
en~m~uIt
EnterCriticalSection
EnumWindows
exem`evL
ExitProcess
ExtEscape
e'Zh{4vAZUz
F3\3Z3P3
__fastcall
February
Fe<Tgk4MNeYTgk??gNDBMe<?4H;8^k#c5hN:@^j{\xkd^:G{MMMOHtM_J{D<@e=T4k4ENeZT4:5i@^i_@XjuGIUdYNj_@^juH{MKF^jv~
Fe=Tkk4ENeZTke<TcH;hENf`B8DA:e=Tkm5Ece<T
fH;9JOE\8G?YDyH8MMMH~I{''X]eH'_5=N;k#MMMM:{CHu\5h{4vAvAvAvAtZe'uH;OHD^iMHMMMMt<TgM]MMMAhJ;MMMMMH~OUxJ;E\MMU`J;EB5;M^5K8xBOMBB;M'>IZ@c^j###8\INExB;E`IfjH~=
f'IgMMMMMMMMMMCMMMkI@M]gMMFMMMMNaMMMMMMMM8HIMMMM]MMMMcMMMMMMMNMM]MMMMMkMMN]MMMMMMMMMJMMMMMMMMMMMkM]MMNMMMMMMMMMEM]E]MMNMMMNMMMMMMIMMMIMMMMMMMMNMMMMMMMMMMMMMMME_}MMH{MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMNMNMFMKMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMcMMMOMEMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMO9<VTd<MMMMbE4MMMM]MMMMgMMMMM]MMMMMMMMMMMMMMMMMMOMMMKMyoa^dhKIMMM8[MMMMcMMMMNkMMMOYMMMMMMMMMMMMMMMMMMNMMMNM@a^dhKIMMMHk^]MMMAMMMMM4MMMM~MMMMMMMMMMMMMMMMMMM]MMM{O9uV[tzU{MMbMoMMMM]M]MMOMMMMCkMMMMMMMMMMMMMMMMMMIMMMIEMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMJKBXO]IG4kn{\j]E4e@tOYM4\##C4duOczN[V_@MEgIFAAxMNMMMEYM:'bAvAvAvExIFMe@XO]]O4e@XO]Ah]a@^O]I5'DOIMNX5'K@>ExIFMf?VO]YM5e@^O]E5'IH
FindWindowA
FindWindowExA
FindWindowExW
FindWindowW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
F```M*
ForceRemove
FreeEnvironmentStringsW
Friday
gAy`xe|
GDI32.dll
GetACP
GetActiveWindow
GetAncestor
GetClassInfoExA
GetClassLongA
GetClientRect
GetClipboardData
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetConsoleTitleA
GetCPInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetCursorPos
GetDlgItem
GetDlgItemTextA
GetDlgItemTextW
GetEnvironmentStringsW
GetFileType
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocalTime
GetMenu
GetMessageA
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetNextDlgTabItem
GetNumberOfEventLogRecords
GetOEMCP
GetPixelFormat
GetPrivateProfileStringA
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSubMenu
GetSystemInfo
GetSystemMenu
GetSystemMetrics
GetSystemPaletteEntries
GetSystemTimeAsFileTime
GetTextMetricsA
GetTickCount
GetTokenInformation
GetUserObjectInformationW
GetVersionExW
GetWindow
GetWindowDC
GetWindowRect
GetWindowTextA
GetWindowTextLengthA
GetWindowThreadProcessId
gi~bi`?>
glBegin
glClear
glDrawPixels
glIndexi
GlobalAlloc
GlobalFree
GlobalLock
GlobalReAlloc
GlobalUnlock
glPopMatrix
glPushMatrix
glRasterPos2f
glRotatef
+GLS(6)
glVertex2f
GMMNJH#JmekMM_Hu\#~_cxZ4JGB^jd]e<<]Yid#
GMMNJH#JmukMM_F^ieHjikMh]eHu\#|JkIMMExBHJK@Z]d_e<TcYCd@ZkMMk4]Amk^c`GEMNExB:MBBHJDcBZUMME\IHExZ:E`Z#AhJ4MAMMMOHjjMHH8[#MMMMt<TgMMMMMC
gndoxfh{
`h````
'H;9BOE\9AD{_H;9ZOE\:CT4FH;9JOE\MNC
H;9JOE\8]T{_H;9BOE\9[b4FH;9JOE\c]ixVH;9ZOE\:UT{_H;9JOE\8ib4FH;9JOE\c^'
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
He~ioxc~
`h`hhh
HH:mm:ss
HIJKDEFG
,hij`mxi
hJ;MAMMMH~OUxZ;E\}MU`Z;EB5;MN4^ExJ;EB4djMMjXKHji]MhO_@X]kHXi{\zdKH'f==JcxJ;AhIdjMMMMMMe<?kk'gNeY?k:;<v{CbFMMMMt<TgMMMMMCyxk??kMD<Dt<TkMMMMMExZ4E`Z:ExJ:ADkNc`J:ExB:MBB5E`B:ExZ:ADeNc`Z:ExJ:MBJ'E`J:ExB:ADdNc`B:ExZ:MBZ#E`Z:ExJ8E`J;C
"~hmxmT
h,O~u|xc
HSSPWSSh
i6,ib!y
i7,A_EI,L:"<7,[
iaJ~ii
,Ibdmboi
ibh^i}yi
I^BI@?>"
	Ibocheb
~ibxzi~
_I^\^CJE
`iCnfiox
"~i`coO
iDmbh`
iDmbh`i
I;@;g;};
@[i``G\bc{b
i_iam|dcV~
~i|imx
IJKDEFG@
IM]MMAhJ'MMMMMH~OUxJ'E\MMU`J'EJ5'MMNMMN5mcxB'E`B#AiJ5\z##{MMMMH~H8yZ5\z##8\OMUaZ5\z##8C55\z##{d5AUxJ#E\kMT]Xe<?4<iaN4_OHyC>FfjH;###~O8xZ#BD}eVT{'###e8T{'###eYT4:;i@Xje@ZjuF`E?8'###:8XD^jv#####e<YAe<<Ak'gNeY<AdoN<GUxZOM'>MfBJ#OT#MMMMe<?4{igEA8uJ'\z##8`B#ExZOE\OMU`ZOCzDe<T4k#H#e'Zh{4vAvAvAvAvAZUz
~imxiXcc
increasing amount
InitializeCriticalSectionAndSpinCount
InterlockedDecrement
InterlockedIncrement
InvalidateRect
iOcbxit
~iPaeo~c
IsClipboardFormatAvailable
IsDebuggerPresent
IsIconic
IsProcessorFeaturePresent
IsValidCodePage
IsWindow
IsWindowVisible
Itoi|xec
/ix\~c
ix\~coi
_ixLC|xecbL	]
_i~zi~>
j`4mxiM9
%^J8[d
January
jebihC_
J	^imh
j@j ^V
jk`a|tv~
.jNULeogOcy
^K0kAl
K2A2o2d2
k4INeY?
k6,kve| 
><K<B<y<
,kcxc,
kdefg`ab
KERNEL32.dll
KExJOE`J#EB5#MM\dGEMMMO@XjuFXjXD^jkkckMIkv<YMMIIMD]J:UoMMMHD^jMNMMOMe=T4H;mOHMAMMETMhMjD^jMOMMOMt<T
keybd_event
KillTimer
Kix\~c
KixIbze~
k~m|deo,
k'tkt<T4MMMMMEB5OMN<[>c]mkOB^it]:DNBMMOHtMt}^KcMfY>kYidkX]MMk4]At<[k^MMMME=Z;JGB^mN]mkN}MKcMmkN}MKcMe<<EY[cM#tT]cMMIdoN<IExZ4J@#JnekMM_@^iuF^ju@^ju@9Z?HvAvAvAvAvAvAvAtZe'uH;MvK^j4MmkN}MExJOJNcAN4MNKcMmkH#JUekMM_F^jeHjjkMhNy@X]t^e=T8Yz4Z=GMMNE`J5EB55MN=NAVJ#{KG^j'@9Z?HvAvAvJ[@;E\
kxd6,)h
%>K>X>m>
L2+2>2T
#L5HN>
$: :L6H
L8#9v9
LCMapStringW
:[;l;e
LEa|c~x
LeaveCriticalSection
LimxiXd
L?I?|?w?
LK`cnm`OP_\xmxyL6
ll~m0O
LoadCursorA
LoadIconA
LoadLibraryA
LoadLibraryW
LoadMenuA
LocalAlloc
LocalFree
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
_LrbkJ~c
lstrcatA
lstrcpyA
lstrlenW
LxjI?N
m#8"<,$o
M||Amlbmkia
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
ma,ombbc
!@mbkymk
 M``co
MessageBoxA
MessageBoxW
M<?{eY?
MHYbdNbh
m|J~ii
mkN}MExJOJHcAMMMME\IHJ?HvAvAvAvAvAvAvAtZe'u@^]t]mkK@X]d^:M8MMMOHtMth{4vAvAvAvAvAvJ[@;ED
M	lM	.O	
MMAhJ#MMMMMOHj]kMH8];NMMMk?<AMM'IA]]MMEB5IMM\dOoIMMOHj^]MH8]hNMMMt8[U'j##MMMMMAiJb\b##{MMMMHDdiX9##4MMMMMt8To'j##cGEMNAiJ8\b##{MMMMN}\KcMfU[k'j##YCk>Y{MMk4]At8[k'j##\MMMME>B:\b##8aB
MM/dd/yy
MM];^]{\fmMMMMOBfjX'##5^e=YEYz4ZfGMMNEyJu\;##=N}MKk]NMMM#t[4cMMIeUTM#z##k;?M#z##MD^
MMMMME=B;JJc\{M\MKcMe=T8YcxJ4JH#J^ukMM_J{DY?e<?<Yj4ZcGMMNE`J:ExZ:JG@^j^]mkJ}MExB#EDNOMEMMJK@Zit_#tYIcMMIe<T
MMMMMExJHE\MNZN}O\4Z
MNOHIJKD
~mogY~`
Monday
Mooi|x
MoveWindow
MultiByteToWideChar
M?<Ye<TcaUDe#{MMMM\O{jkEeYTc:5>@ZiOH:kKFZiv~OUxJ;E\cMU`J;EB5;MN4@8xB:EDd#{MMkDgE_UDFM\###<K@Z]{HZiuEOcxJ:FaN8z4MMMMH{
m`yiI,tM
n3d3b3x3
N7B0^a
N[com`X
Nebm~uXc
 new[]
N \i~j
n~m~uItM
nok`cn
NoRemove
November
(null)
nyxiM0l,
O9h9p9
,$oca|mx
Ocbxib,x!Xu|
ochebk6,Lkve| ,
October
O~i$mxi
O~i,mxiXd
Okdefg`
OLEAUT32.dll
oMhh~i
`omni callsig'
OpenClipboard
OpenEventA
OpenEventLogA
OPENGL32.dll
OpenIcon
operator
O^U\X?>
oxc~uM
P?8,9:;45
__pascal
Pj0^Vh
`placement delete closure'
`placement delete[] closure'
PostQuitMessage
PostThreadMessageA
Poy~~ib
PPPPPPPP
__ptr64
-qC$~B
Q>n>k>a>
QueryPerformanceCounter
R~8|d`<
RaiseException
`.rdata
ReadEventLogA
ReadFile
RealizePalette
RegisterClassA
ReleaseCapture
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
      <requestedPrivileges>
__restrict
<R<g<u<
RtlUnwind
RVPSj	
Saturday
`scalar deleting destructor'
ScreenToClient
    </security>
    <security>
SelectObject
SelectPalette
SendDlgItemMessageA
SendDlgItemMessageW
SendMessageA
SendMessageTimeoutA
SendMessageW
September
SetBkMode
SetCapture
SetCursor
SetDlgItemTextA
SetDlgItemTextW
SetEndOfFile
SetEvent
SetFilePointer
SetFocus
SetForegroundWindow
SetHandleCount
SetLastError
SetMapMode
SetStdHandle
SetTextColor
SetTimer
SetUnhandledExceptionFilter
SetWindowPos
SetWindowsHookExA
SetWindowTextA
SHELL32.dll
Shell_NotifyIconA
Shell_TrayWnd
Shortcut
ShowWindow
^SSSSS
__stdcall
`string'
Strings
Sunday
SwapBuffers
S>`>z>
t8[8#z##MMMMME>By\;##=J}NE>Zz\;##=G@doH'##5]:DCNMMOJ{D]he<<AYUxZOJG@dnv'##5]e8?M#z##YidCk]MM:t_@Z]t_e<YEYEyB{\;##=DcAcIMMAVJ#{K@`oH'##5_#t[8cMMI:tyBdhH'##5]e8?A#z##YidCk]MMdoM\d^z###'@`ov'##5_#t[8cMMIegT#e'Zh{4vAvAvAvAvAZUz
'\##t8Zc'\##MMMMME>Jm\f##=O@f[v8##5^e9Z8'\##YcyJ9\b##=H#JmOdMM_Hj^{MhNO@X^u@I]CZm\f##8xJDEg]k;=c'\##MDYO:vK@fTf8##4Hf[f8##'FfTf8##'@`[v8##4~`[f8##'F`[v8##'Hz[v8##4Mj{@~MyyO:v\Dd[X<##4MMMMMfUZg5\##YKkMNMMMfU=c5\##YUyZ9\b##=@#JmOdMM_Hz[X<##4Mh5i@dVX9##'H{MKFdVX9##'Hjj{Mh]>HzVX9##4NH8vO#j##e8?g'j##Yj4ZbGIMNEyZb\b##=@#JVudMM_@dVf9##5]#t[oc]MIe<T4e'Zh{4vAvAtZe'uN;IkNMMHK^j4MmkN}MyfkkkMMeUTA#z##k;?A#z###{'IeMIMMAiJ<\;##ukNMMOBdhH'##5]e8?A#z##Yie}kkMMdoM\dJUNMMH#Jo_kMM_FdoX'###Ddof'##4MMMMMe9TU#z##C9TI#z##h]:@dif'##'Fdof'###~J8>B<\;##=K@`ov'##5_:JiOMMOJ{DTBk;?E#z##MM'IMMIMME>J<\;##=O@fov'##5^:HaOMMOJ{M'I9]MMMEyZ>\;##vyZu\;##{'JyMMMME>J5\;##=H#JmOk
tCHt(Ht 
#t[{c]MIeU[U'j##k;>U'j##MM'IT{AMMKcMmkN}M>cMmkM\x9[8'j##YcyJ
TerminateProcess
+t HHt
__thiscall
!This program cannot be run in DOS mode.
Thursday
Times New Roman
< tK<	tG
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TrackPopupMenu
  </trustInfo>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
t"SS9] u
<+t"<-t
t$<"u	3
Tuesday
{tuv<=>?
;t$,v-
 Type Descriptor'
`typeof'
<"<@<U
. U=/~
U=B'JKBZj^_:\UMMMOHtMeF^jO@^^];^jN5KExB:JJ}M\4Z
`udt returning'
uEbjcL
UHZM\EIk
`"umdcc
__unaligned
UnhandledExceptionFilter
UnhookWindowsHookEx
UNICODE
Unknown exception
UnregisterClassA
UpdateWindow
UQPXY]Y[
urlmon.dll
URPQQh
usD	-2
USER32.dll
UTF-16LE
uTVWh\VA
UVmnohij
u|x^i`im
UxZ5JG@^j^]:F<KMMOHtMe@Xj^^:@ICMMOHtM_@Zie@^j]H]eeF^i^ke<Tg#5Ndt<T4M]MMMExJ#J5i[8z`ToEIMAvAvAvAvAvAZUz
`vbase destructor'
`vbtable'
`vcall'
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
`virtual displacement map'
VkKeyScanA
v	N+D$
v`n}kx~
V!pj3b
WaitForSingleObject
Wednesday
WideCharToMultiByte
WriteConsoleW
WriteFile
wsprintfA
WTSAPI32.dll
WTSFreeMemory
WTSQuerySessionInformationA
< =:=x
XcOAC@
_x~ebkM
x|"`ezi"
xiaHe~i
x|_ibh^i
xi~bixC|,ibM
xI~~c~
xJc~_ebk
:Xj###'@Zid_mkH#JnOkMM^]#t[ccMMIe<T
x{m~iPae
XM]MMEB5OMM\dH4IMMNcNMIMME>J4\;##=Nc]GAMN\4ZbGMMNKdAc{MIfU?{#z##Yj4Z5GMMNEB5IMN<E>dgc{MIfVT{#z##Yz4Z5GMMNExJIJOBfjH'##5^#tT<cMMImdN}ME>ZI\v##=@cu<cMME\IHK|ImkOBdoH;##5]:@dGMMOHtMvDdoH;##5IMMMMe<<Ee=YEM=I4eV[4'###e8[4'###H;hEJEyZz\z##8=IOdeFd]v4##'@fnv;##'@YZOFZjt}]KkMAMMMe<T4YKcM#t[<cMMIeYT8k??8MDYDA4H|V{AMME>BI\v##=KB`oH;##5_mkN}MKcImkN}MKcMfUT{#z##YKcM#tT]cMMIdoN=KKkMkMMMmkO@Xjd^#tT{cMMIA4H|
x,ni,~yb
x~oa|e
xocb"bix
xppwpp
xpxxxx
\x`YYdhF=A>cMfUTU#j##YExBOJD#JV_kMM^}Nc>Z>\?##=@#JVOkMM_Bdhf5##5]e<<EYj4ZfGMMNKkBM{MM:DNuMMOHtM_FdhX5##'@`hX5##'FZj_@^j_GX^OEeM{HMMOB`hf5##5_e<T<Y\4ZfGMMNExBHJK@Zj_N{kkOMMN_#t[AcMMImkN}MExJ5JNc<NEMNKcMmkH#JUekMM_FdiX'##'HziX'##4MhN}Hj^kMhMy@X^e@`iX'##'FIohJ#MIMMMH~KExJ5EaJ<\?##8yB<\?##=Dc'DIMME\INExJ#Ez`To\AvAvAvAvAvAvAvAvAvJ[@;E\
]^_XYZ[T
xy,z{tuv
XYZ[TUVm
xZc`yaiE
XZ}]MMAMMMMIMMMM##4MM@kMMMMMMMMM]MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM8MMMMM8jyk8MxMbBEnkNXA<dZKd|ouN{oa5boaJxEKBdna9zhONeV_Nuh[8km[8k^I5XEK=zVKYyH]<GFMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMN]^]MMXMIIMG
Y; 4?4P4
Y\4ZAGMMNKeEI{MM#t[gcMMI:[z###4v{Ez`ToEIMJ[@;E\
Y5m5g5w5
Y;=8fB
Ybebexe\m`evL
YD`pT3]
,'y	f12T
Y_I^IB
yi~u\i~j
ym`_eh
YohJ#MMMMMOHj]kMhIyHj]{MhI[Hj^MMhH'Hj^]MhHaHj^kMhHC@^_N]e<<oYU=Z#JG@^^d]e<<YYUxZIJG@^]t]e<<EYikeMMMMk4]kdoN=N4hJ#MMMMMO@^ju@9Z?HvAvAvAvAvAvAvAvAvJ[@;ED
yz{tuv<=
YZ[TUVmn
zehi~,z=
Ze~xym
ZLe~xym`
Z]MMk4]Ae=Y]M=T{eZY]e<YYG<T{eYYYe<?
<=zOIMHAvAvAvAvAvAvAvAtTZ`Av#8xIFN]@{D<Y^8xYFNH?>\jmk5kMeY]gJE`YFNO@^O]oO4N5JIi@ZO]U55f?>c\UME`IFNuFZO]UO4N=KExAFNe@^O]YA5@?4UzUe<]gI\jte5\~]UzUe<{gKExYFN_@^O]]<iz^>hD}<hk@>?T<5#K@4\hgFNu@uExIFNf?9k\^ok8;ZO]Yh{duNvxIFNN>MY8v<czKX?YD55~?>E\mMJxiT4E]MAvAvAvAvJ[@;ED