Analysis Date2013-09-18 23:45:54
MD5c847740ee6367ef23f7c22eaca58c7c2
SHA14e58ab5aa9f4e12ce2f9f831315f4a4093b5e8a6

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: d6ede9a39b4fdf68499cc74640e7f9c2 sha1: 86db704ec59c66fd5ec30cbb9c78b41b6b472e40 size: 737792
Section.rdata md5: 1cf5a4e70341ebb1c7b9725d68e06b2e sha1: c71157bbc537611b39429a2520a86470aa1ed8e8 size: 33792
Section.data md5: 8deb084e7060b581c8ed429494b60e8f sha1: 7769351660078cb8a0a8e9682bcbe5f9f6d5a636 size: 122880
Timestamp2013-07-10 22:51:25
PackerMicrosoft Visual C++ ?.?
PEhashe35b07dd4c643023ecfcca309ba16cbc81238fe8
AVavgCrypt2.BEQA
AVaviraTR/Symmi.25089.18

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\~DF93EA.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nnpgaa1v6uzad0zv5sbc.exe
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\system32\ddddddd\tst
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\nnpgaa1v6uzad0zv5sbc.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\nnpgaa1v6uzad0zv5sbc.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\TPM Machine Extender Encryption Profile Launcher ➝
C:\WINDOWS\system32\ffffffffff.exe
Creates FileC:\WINDOWS\system32\ffffffffff.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\system32\ddddddd\lck
Creates FileC:\WINDOWS\system32\ddddddd\tst
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\WINDOWS\system32\ffffffffff.exe
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates ServiceIPsec Registrar Driver Authentication AuthIP - C:\WINDOWS\system32\ffffffffff.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 780

Process
↳ Pid 840

Process
↳ C:\WINDOWS\System32\svchost.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces ➝
NULL
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\system32\WBEM\Repository\$WinMgmt.CFG
Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1088

Process
↳ Pid 1352

Process
↳ Pid 1852

Process
↳ Pid 1080

Process
↳ C:\WINDOWS\system32\ffffffffff.exe

Creates FileC:\WINDOWS\system32\wwwwwwwwwww.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\system32\ddddddd\lck
Creates FileC:\WINDOWS\system32\ddddddd\rng
Creates FileC:\WINDOWS\system32\ddddddd\tst

Process
↳ C:\WINDOWS\system32\ffffffffff.exe

Network Details:

DNSelementarimagine.com
Type: A
216.239.140.29
DNSthemorrefk.com
Type: A
216.55.149.9
DNSjumpgray.net
Type: A
98.139.135.22
DNSjumpgray.net
Type: A
98.139.135.21
DNSspotpress.net
Type: A
82.165.102.36
DNSsaltpress.net
Type: A
50.63.202.43
DNSfairboat.net
Type: A
80.237.133.23
DNSwatchpress.net
Type: A
195.34.82.174
DNSfairpress.net
Type: A
190.93.245.20
DNSfairpress.net
Type: A
190.93.246.20
DNSfairpress.net
Type: A
141.101.114.20
DNSfairpress.net
Type: A
190.93.244.20
DNSfairpress.net
Type: A
141.101.115.20
DNSdreamboat.net
Type: A
64.95.64.218
DNSdreampress.net
Type: A
176.74.176.178
DNSdreamopen.net
Type: A
111.68.23.13
DNSthisopen.net
Type: A
66.96.162.143
DNSspotfind.net
Type: A
208.91.197.27
DNSspotwear.net
Type: A
184.168.221.36
DNSmojoguia.com
Type: A
DNSpengthecon.com
Type: A
DNStablewash.net
Type: A
DNSsalthave.net
Type: A
DNSyourenjoy.net
Type: A
DNSlookloss.net
Type: A
DNSsouthabout.net
Type: A
DNSliarshot.net
Type: A
DNSableeach.net
Type: A
DNSmovegray.net
Type: A
DNSsouthboat.net
Type: A
DNSarivepress.net
Type: A
DNSsouthpress.net
Type: A
DNSariverest.net
Type: A
DNSsouthrest.net
Type: A
DNSariveopen.net
Type: A
DNSsouthopen.net
Type: A
DNSuponboat.net
Type: A
DNSwhichboat.net
Type: A
DNSuponpress.net
Type: A
DNSwhichpress.net
Type: A
DNSuponrest.net
Type: A
DNSwhichrest.net
Type: A
DNSuponopen.net
Type: A
DNSwhichopen.net
Type: A
DNSspotboat.net
Type: A
DNSsaltboat.net
Type: A
DNSspotrest.net
Type: A
DNSsaltrest.net
Type: A
DNSspotopen.net
Type: A
DNSsaltopen.net
Type: A
DNSgladboat.net
Type: A
DNStakenboat.net
Type: A
DNSgladpress.net
Type: A
DNStakenpress.net
Type: A
DNSgladrest.net
Type: A
DNStakenrest.net
Type: A
DNSgladopen.net
Type: A
DNStakenopen.net
Type: A
DNSequalboat.net
Type: A
DNSgroupboat.net
Type: A
DNSequalpress.net
Type: A
DNSgrouppress.net
Type: A
DNSequalrest.net
Type: A
DNSgrouprest.net
Type: A
DNSequalopen.net
Type: A
DNSgroupopen.net
Type: A
DNSspokeboat.net
Type: A
DNSvisitboat.net
Type: A
DNSspokepress.net
Type: A
DNSvisitpress.net
Type: A
DNSspokerest.net
Type: A
DNSvisitrest.net
Type: A
DNSspokeopen.net
Type: A
DNSvisitopen.net
Type: A
DNSwatchboat.net
Type: A
DNSwatchrest.net
Type: A
DNSfairrest.net
Type: A
DNSwatchopen.net
Type: A
DNSfairopen.net
Type: A
DNSthisboat.net
Type: A
DNSthispress.net
Type: A
DNSdreamrest.net
Type: A
DNSthisrest.net
Type: A
DNSarivetold.net
Type: A
DNSsouthtold.net
Type: A
DNSarivefind.net
Type: A
DNSsouthfind.net
Type: A
DNSarivewear.net
Type: A
DNSsouthwear.net
Type: A
DNSarivehurt.net
Type: A
DNSsouthhurt.net
Type: A
DNSupontold.net
Type: A
DNSwhichtold.net
Type: A
DNSuponfind.net
Type: A
DNSwhichfind.net
Type: A
DNSuponwear.net
Type: A
DNSwhichwear.net
Type: A
DNSuponhurt.net
Type: A
DNSwhichhurt.net
Type: A
DNSspottold.net
Type: A
DNSsalttold.net
Type: A
DNSsaltfind.net
Type: A
DNSsaltwear.net
Type: A
HTTP GEThttp://elementarimagine.com/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://themorrefk.com/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://jumpgray.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://spotpress.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://saltpress.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://fairboat.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://watchpress.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://fairpress.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://dreamboat.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://dreampress.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://dreamopen.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://thisopen.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://spotfind.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
HTTP GEThttp://spotwear.net/forum/search.php?method=validate&mode=my&email=antivirus@fuck.you&lici=auto_000002&ver=013
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 216.239.140.29:80
Flows TCP192.168.1.1:1032 ➝ 216.55.149.9:80
Flows TCP192.168.1.1:1033 ➝ 98.139.135.22:80
Flows TCP192.168.1.1:1034 ➝ 82.165.102.36:80
Flows TCP192.168.1.1:1035 ➝ 50.63.202.43:80
Flows TCP192.168.1.1:1036 ➝ 80.237.133.23:80
Flows TCP192.168.1.1:1037 ➝ 195.34.82.174:80
Flows TCP192.168.1.1:1038 ➝ 190.93.245.20:80
Flows TCP192.168.1.1:1039 ➝ 64.95.64.218:80
Flows TCP192.168.1.1:1040 ➝ 176.74.176.178:80
Flows TCP192.168.1.1:1041 ➝ 111.68.23.13:80
Flows TCP192.168.1.1:1042 ➝ 66.96.162.143:80
Flows TCP192.168.1.1:1043 ➝ 208.91.197.27:80
Flows TCP192.168.1.1:1044 ➝ 184.168.221.36:80

Raw Pcap
0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   656c656d 656e7461 72696d61 67696e65   elementarimagine
0x000000a0 (00160)   2e636f6d 0d0a0d0a                     .com....

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   7468656d 6f727265 666b2e63 6f6d0d0a   themorrefk.com..
0x000000a0 (00160)   0d0a6f6d 0d0a0d0a                     ..om....

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   6a756d70 67726179 2e6e6574 0d0a0d0a   jumpgray.net....
0x000000a0 (00160)   3e343034 204e6f74 20466f75 6e643c2f   >404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   73706f74 70726573 732e6e65 740d0a0d   spotpress.net...
0x000000a0 (00160)   0a343034 204e6f74 20466f75 6e643c2f   .404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   73616c74 70726573 732e6e65 740d0a0d   saltpress.net...
0x000000a0 (00160)   0a343034 204e6f74 20466f75 6e643c2f   .404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   66616972 626f6174 2e6e6574 0d0a0d0a   fairboat.net....
0x000000a0 (00160)   0a343034 204e6f74 20466f75 6e643c2f   .404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   77617463 68707265 73732e6e 65740d0a   watchpress.net..
0x000000a0 (00160)   0d0a3034 204e6f74 20466f75 6e643c2f   ..04 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   66616972 70726573 732e6e65 740d0a0d   fairpress.net...
0x000000a0 (00160)   0a0a3034 204e6f74 20466f75 6e643c2f   ..04 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   64726561 6d626f61 742e6e65 740d0a0d   dreamboat.net...
0x000000a0 (00160)   0a0a3034 204e6f74 20466f75 6e643c2f   ..04 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   64726561 6d707265 73732e6e 65740d0a   dreampress.net..
0x000000a0 (00160)   0d0a3034 204e6f74 20466f75 6e643c2f   ..04 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   64726561 6d6f7065 6e2e6e65 740d0a0d   dreamopen.net...
0x000000a0 (00160)   0a0a3034 204e6f74                     ..04 Not

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   74686973 6f70656e 2e6e6574 0d0a0d0a   thisopen.net....
0x000000a0 (00160)   0a0a3034 204e6f74                     ..04 Not

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   73706f74 66696e64 2e6e6574 0d0a0d0a   spotfind.net....
0x000000a0 (00160)   3e343034 204e6f74 20466f75 6e643c2f   >404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f666f72 756d2f73 65617263   GET /forum/searc
0x00000010 (00016)   682e7068 703f6d65 74686f64 3d76616c   h.php?method=val
0x00000020 (00032)   69646174 65266d6f 64653d6d 7926656d   idate&mode=my&em
0x00000030 (00048)   61696c3d 616e7469 76697275 73406675   ail=antivirus@fu
0x00000040 (00064)   636b2e79 6f75266c 6963693d 6175746f   ck.you&lici=auto
0x00000050 (00080)   5f303030 30303226 7665723d 30313320   _000002&ver=013 
0x00000060 (00096)   48545450 2f312e30 0d0a4163 63657074   HTTP/1.0..Accept
0x00000070 (00112)   3a202a2f 2a0d0a43 6f6e6e65 6374696f   : */*..Connectio
0x00000080 (00128)   6e3a2063 6c6f7365 0d0a486f 73743a20   n: close..Host: 
0x00000090 (00144)   73706f74 77656172 2e6e6574 0d0a0d0a   spotwear.net....
0x000000a0 (00160)   3e343034 204e6f74 20466f75 6e643c2f   >404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.


Strings
        lesn l eaWteCtadnS3SttrbheC lrainSei ecraT. Aar edlletoeeeKd2eHEvvOeeeroptjnC tgFlElne 
rstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
05=:9DY^
(@06F4b
0A@@Ju
0b#x2U
0SSSSS
0WWWWW
 0Y'C{
&0Y= H=
|[1a q
1L.mx8j
1#QNAN
1#SNAN
`'25/}
'2brG+
`2Ixlx9
2sq=[w`\
2w;vyz
]3!FD{
3_{?HS7
^3)O/a
3!XeXI
;4c4iFv
4eQ-0Z
4':Q#U
4rOY!eB
5.*8SC
5NhF(#
5!T<S@
\5w"w=
6/0S>P
6|^vtn
{6yD{d
7# 2a3
7%d`)y"
%7 J[Y
)?^7QO
85BH0:h
8kG$[m+:
8PPy	u
8VVVVV
8W(~v9N
]9nee>
~\A5(K
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
a*b]xE
AHOP:J
america
american
american english
american-english
An application has made an attempt to load the C runtime library incorrectly.
<at9<rt,<wt
&atqqF
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
.?AUctype_base@std@@
August
australian
.?AVbad_alloc@std@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
?A[vbu
.?AV?$ctype@D@std@@
.?AVexception@std@@
.?AVfacet@locale@std@@
.?AVfailure@ios_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AVlength_error@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVout_of_range@std@@
.?AVruntime_error@std@@
.?AVtype_info@@
Az\H&u
^azlN[
b24c{J
B{3yYJH
b9\>g1DDt
bad allocation
bad cast
bad exception
 Base Class Array'
 Base Class Descriptor at (
__based(
B+B&/:
	bb}~bfl
%Bc8y'
BeginPaint
belgian
B?j3UY
\b\Oudw{phSC
britain
+btM[F
_BZb	C
bzMi1 c
C; a<6
CallWindowProcA
canadian
C_!)CGS
__cdecl
CheckDlgButton
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
CI;_7d
 cL[0^
 Class Hierarchy Descriptor'
CloseHandle
__clrcall
cmd.exe
c=	o=#;
CompareStringA
CompareStringW
 Complete Object Locator'
COMSPEC
CONOUT$
`copy constructor closure'
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
CorExitProcess
C PjPV
C$PjQV
C.PjRV
C/PjSV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
c,q9nT)
CreateFileA
CreateProcessA
- CRT not initialized
'cR)Zs
*D4HFr
d9)cRR
)dapXI>	
@.data
\dC@+J
dddd, MMMM dd, yyyy
December
DecodePointer
`default constructor closure'
 delete
 delete[]
Delete
DeleteCriticalSection
DeleteFileA
deque<T> too long
d[in)9,
dJ-Pb{
DOMAIN error
DrawTextA
dutch-belgian
%dx	G'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
'ei$<`1
EnableWindow
EncodePointer
EndDialog
EndPaint
england
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
EnterCriticalSection
EnumSystemLocalesA
eO'CvMe
%;e&O&D
e>/?pw!
]~e?r\J/
ES62jY
ExitProcess
F7CYoK
__fastcall
_Fb%/V
February
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileA
FindResourceA
F"lD*I
- floating point support not loaded
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
ForceRemove
.f\*,q
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
french-belgian
french-canadian
french-luxembourg
french-swiss
Friday
#ftVYA
^F<-uB
g;{]	]=
g5sa);^
g9E	q'
GAIsProcessorFeaturePresent
GDI32.dll
`Gd&*v
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
GetACP
GetActiveWindow
GetBkColor
GetClipRgn
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetCPInfo
GetCurrentDirectoryA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetCursor
GetDCBrushColor
GetDCPenColor
GetDeviceCaps
GetDlgItem
GetDlgItemInt
GetDriveTypeA
GetEnvironmentStrings
GetEnvironmentStringsW
GetExitCodeProcess
GetFileAttributesA
GetFileTime
GetFileType
GetFontLanguageInfo
GetFontUnicodeRanges
GetForegroundWindow
GetFullPathNameA
GetGraphicsMode
GetInputState
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetMapMode
GetMenu
GetMenuCheckMarkDimensions
GetMenuContextHelpId
GetMenuItemCount
GetMenuItemID
GetMenuState
GetMetaRgn
GetModuleFileNameA
GetModuleHandleA
GetModuleHandleW
GetNearestColor
GetNearestPaletteIndex
GetObjectType
GetOEMCP
GetPixelFormat
GetPolyFillMode
GetProcAddress
GetProcessHeap
GetProcessId
GetProcessWindowStation
GetPropA
GetQueueStatus
GetRandomRgn
GetScrollPos
GetStartupInfoA
GetStdHandle
GetStretchBltMode
GetStringTypeA
GetStringTypeW
GetSystemPaletteUse
GetSystemTimeAsFileTime
GetTextAlign
GetTextCharacterExtra
GetTextCharset
GetTextColor
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserObjectInformationA
GetVersion
GetWindowContextHelpId
GetWindowDC
GetWindowLongA
GlobalAlloc
GlobalFlags
GlobalHandle
GlobalSize
great britain
GTq,p&
`h````
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
`h`hhh
HH:mm:ss
HHtXHHt
HHtYHHt
;~Hny\$
holland
hong-kong
=$`HPcGE
"'hx2s4
<>,I%9e
ibG:me
	i/EE]
>If90t
IJ<;wRQy
^ikta|
[*IL<:
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
invalid map/set<T> iterator
invalid string position
ios_base::badbit set
ios_base::failbit set
irish-english
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
IsWindowEnabled
IsWindowUnicode
^!-i$t
italian-swiss
Iu(Cefa 
i*uV$U
#Iv$SkT'|
;I+	yj
j1h8>M
j1hx#L
j2h8<M
%;J3wv
j7h|%L
j8hdHM
jAhphL
JanFebMarAprMayJunJulAugSepOctNovDec
January
jBhpJM
jDh@9M
j/>D=n*
~,Jd?Q;
j?h0?M
j	hDiL
j(hD&M
j,h< L
j	hldM
j	hl_M
j	h,<M
j	hPhL
j	ht>M
j.hT@M
j	hXcM
j@j ^V
J%n)\J
/JP>K;lH
j`~&S0
j"^SSSSS
jt>0%u@
jZ2Hcd8
K9fd&_
KERNEL32
KERNEL32.dll
KFBWSC
(;@Kh3
KJLc.)
kM{C7J
kW+HrK
,L;<55h
{LBe=&
LC_ALL
LC_COLLATE
LC_CTYPE
LCMapStringA
LCMapStringW
LC_MONETARY
LC_NUMERIC
lc&s@yN
LC_TIME
LDik^X
LeaveCriticalSection
.li		 p
lmRsl2
LoadIconA
LoadLibraryA
LoadResource
LocalAlloc
LocalFlags
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
LockResource
L(	P&,
lu8jJY
LY8mvQ^L
&\l&yu`
=M]7<B/
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
map/set<T> too long
MessageBoxA
Microsoft Visual C++ Runtime Library
m{iZ}V
MM/dd/yy
Monday
MoveFileA
MoveWindow
M.)Q2e)
mS8swL
~&,M_u
MultiByteToWideChar
MVgw\Y
 new[]
new-zealand
Nh{kv#
NoRemove
norwegian
norwegian-bokmal
norwegian-nynorsk
Norwegian-Nynorsk
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
}O$3Pt
O/.bT$x
October
OLEAUT32.dll
`omni callsig'
o#;oxG
operator
oSc?@kzaj-
Oxj?D"
<OyE62
__pascal
pd0-+t
Pf95p=N
pf&%SS
|pj	h$
`placement delete closure'
`placement delete[] closure'
Please contact the application's support team for more information.
pNs' 6
portuguese-brazilian
PostMessageA
PPPPPPPP
pr china
pr-china
Program: 
<program name unknown>
__ptr64
puerto-rico
- pure virtual function call
q6=? 8
Q|GdWf
_Q'HLy
,qp|	8
\QpZl|
QQSVWd
QueryPerformanceCounter
q<v?[]o
R%):25
r3C>$2IW
RaiseException
Ra)L)t
`.rdata
ReadFile
RemovePropA
__restrict
/RiH_e
r%n`+_
'(rq6%
Rt,F&3f
RtlUnwind
runtime error 
Runtime Error!
:S}A&~Gmpa
Saturday
`scalar deleting destructor'
SendMessageA
September
SetDlgItemTextA
SetEndOfFile
SetEnvironmentVariableA
SetFilePointer
SetFocus
SetHandleCount
SetLastError
SetPixel
SetStdHandle
SetTextCharacterExtra
SetTextJustification
SetUnhandledExceptionFilter
SetWindowTextA
ShowWindow
SING error
SizeofResource
slovak
SnI,?BgG
south africa
south-africa
south korea
south-korea
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
s[S;7|G;w
^SSSSS
__stdcall
`string'
string too long
Sunday
SunMonTueWedThuFriSat
swedish-finland
SystemRoot
%T1f.5JD
t3h|wK
Td!E*2Q
tdhXdK
*tEaiUw,
TerminateProcess
t=FA9]
tGHt.Ht&
+t HHt
tHhTeK
(</t$hhxK
t=hhxK
This application has requested the Runtime to terminate it in an unusual way.
__thiscall
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
!This program cannot be run in DOS mode.
t hpgK
t"htwK
Thursday
tIj"[:
t`j$h<
tjh(dK
< tK<	tG
TlIV*6sO
"tLk!#
TLOSS error
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
tmj$h<
<\tM</tI
tnTMh~
;tpy(	
tR99u2
trinidad & tobago
.tRodleq
t/S/s~|
t"SS9]
<+t(<-t$:
t$<"u	3
Tuesday
;t$,v-
t VV9u
Twa1h}
t+WWVPV
TX(Mb-u
 Type Descriptor'
`typeof'
?U`1O9
>:u8FV
uBhtGJ
`udt returning'
u 	"K{
(u?KnLB
ULa&_s
- unable to initialize heap
- unable to open console device
__unaligned
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
UNICODE
united-kingdom
united-states
unj	h0
Unknown exception
UpdateColors
upjLh`
u*^!pu
UQPXY]Y[
uqSSSSS
URPQQhX[J
USER32.dll
USER32.DLL
u[SSSP
UTF-16LE
u,VVWV
$uWw<utokc
$u)XOhYFw
>'&U;y
V3OU%$
`vbase destructor'
`vbtable'
`vcall'
vDT3f_
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
VirtualAlloc
`virtual displacement map'
VirtualFree
v	N+D$
`!VP0q
V+#Ph	
_VVVVV
VVVVVQRSSj
^v\Y2s
+v	Zgz
w8p3\J
WaitForSingleObject
Wednesday
wf(QhFe+_
?W(=g_
W{h=5s^
wHh4eK
WideCharToMultiByte
WindowFromDC
 W,MuB
/wp6c_
WriteConsoleA
WriteConsoleW
WriteFile
WS2_32.dll
[wV3KVXEWaq?(
^WWWWW
*X^)@,
X5xAXn
x8O]iP
'##x9rI
)XFYmI
-Xhoe!
)Xi)Ef
x?p\bP
xppwpp
xpxxxx
<xtX<XtT
xyqF4x8#pV
X^ZF9/
xZ{kSm:P
>y\[8B9
!yB/( ?
Y@ios_base::eofbit set
YkJ4$ QWa a
,y^!nEz
Y&Q3np
>=Yt1j
y`T%]_wE
_y!;u<
Y<\u#j\V
Y,ztoY+'
Z0bkYZ
~=Z=6JoGOF
[{z[h<
zK(PPG
=zm3-R
ZoZ.My
zScQ)1\
zSLpFp
`zuB0=
z%UBCk6