Analysis Date2014-01-24 05:40:11
MD5cf677b23cd2d51e456cec4c570635623
SHA1ce918e5d3aaf87d346f89c7c604f6d523c6309dd

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
SectionUPX0 md5: 6326acf324d41786b1c2c7b39e1041cc sha1: 774be22327ea937450b5c4d15ef1d1e47ffa578d size: 20480
SectionUPX1 md5: f4f4755c86add64181162578e07db026 sha1: 077541f7451b750468882e56e9360cd577d5b81e size: 14336
SectionUPX2 md5: 7e7ea07c51315273c7dd9e31108f20c7 sha1: 01558fbff7c684cbc8d95b91c017b3752da08336 size: 1024
Timestamp2010-02-09 15:44:49
PackerMicrosoft Visual C++ v6.0
PEhashb6231b2346de8ab544335469628ebbda694481a7
AVavgWorm/Koobface.O
AVaviraTR/Crypt.ULPM.Gen
AVmsseTrojan:Win32/Koobface.gen!M
AVclamavWorm.Koobface-118

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates File\Device\Afd\AsyncConnectHlp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Winsock DNSnews.google.com

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore\Type ➝
3
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links\Order ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates MutexShell.CMruPidlList

Network Details:

DNSnews.l.google.com
Type: A
62.253.3.118
DNSnews.l.google.com
Type: A
62.253.3.84
DNSnews.l.google.com
Type: A
62.253.3.114
DNSnews.l.google.com
Type: A
62.253.3.93
DNSnews.l.google.com
Type: A
62.253.3.108
DNSnews.l.google.com
Type: A
62.253.3.99
DNSnews.l.google.com
Type: A
62.253.3.109
DNSnews.l.google.com
Type: A
62.253.3.94
DNSnews.l.google.com
Type: A
62.253.3.89
DNSnews.l.google.com
Type: A
62.253.3.123
DNSnews.l.google.com
Type: A
62.253.3.103
DNSnews.l.google.com
Type: A
62.253.3.98
DNSnews.l.google.com
Type: A
62.253.3.113
DNSnews.l.google.com
Type: A
62.253.3.119
DNSnews.l.google.com
Type: A
62.253.3.104
DNSnews.l.google.com
Type: A
62.253.3.88
DNSwww.patrickcadona.com
Type: A
82.165.78.116
DNSnatureswildchild.com
Type: A
50.56.218.189
DNSwww.pennine-fp.co.uk
Type: A
87.106.115.7
DNSwww.instrumentenschmiede.at
Type: A
85.158.181.28
DNS1836ink.com
Type: A
216.177.137.4
DNSfirmafrugtforeningen.dk
Type: A
87.48.171.8
DNSslatten.org
Type: A
195.128.174.122
DNSsheenalarsen.com
Type: A
74.208.182.107
DNSsignsny.com
Type: A
50.62.247.1
DNScahillappraisal.com
Type: A
72.167.232.151
DNSwww.its-email.co.uk
Type: A
79.170.44.90
DNSstevesplaceusaparts.com
Type: A
5.157.84.33
DNSevpcocoa.com
Type: A
141.101.115.20
DNSevpcocoa.com
Type: A
190.93.245.20
DNSevpcocoa.com
Type: A
190.93.246.20
DNSevpcocoa.com
Type: A
141.101.114.20
DNSevpcocoa.com
Type: A
190.93.244.20
DNSackstone.com
Type: A
173.236.165.41
DNSamircreative.com
Type: A
50.63.202.40
DNScafeinternationalcatering.com
Type: A
72.167.232.181
DNSamicableresolutionsintl.com
Type: A
108.175.14.57
DNSmahjongmuseum.com
Type: A
66.175.58.9
DNSthoughtsbecomereality.co.uk
Type: A
208.109.181.27
DNSderryrailtrail.org
Type: A
192.254.190.143
DNSjustproud2b.com
Type: A
82.98.86.179
DNSweb.softworks.at
Type: A
91.250.86.163
DNSuaetoon.net
Type: A
70.87.96.233
DNSmembermania.com
Type: A
208.73.211.246
DNSdentistschoice-fl.com
Type: A
69.43.161.156
DNSasiandvdtime.com
Type: A
209.222.14.3
DNStropickoolac.com
Type: A
50.63.202.62
DNSdeltaboats.com
Type: A
38.112.61.200
DNSdreamyjeanniebottles.com
Type: A
72.167.183.80
DNSrichardspizza.com
Type: A
64.71.34.100
DNSbraitman.net
Type: A
65.39.205.54
DNSengravings.com
Type: A
50.31.99.11
DNSberniestowing.com
Type: A
216.55.131.217
DNSnews.google.com
Type: A
DNSgrooverslounge.com
Type: A
DNSshop.spyral-promotions.co.uk
Type: A
DNSwww.erotic-food.ch
Type: A
DNSmycleveridea.co.za
Type: A
DNSwww.wael-tv.com
Type: A
DNSe-autosystem.gr
Type: A
DNSi-hass-di.de
Type: A
DNSwww.andrewscript.com
Type: A
DNSwww.wheatfieldwaterfrontassociation.org
Type: A
DNSdynasales.net
Type: A
DNSalavench.com
Type: A
DNSwww.hebamme-hochreiter.at
Type: A
DNSyourprofit.brevard-fl.com
Type: A
DNSwff.co.za
Type: A
DNSwelovetweet.com
Type: A
DNSbranderideklub.dk
Type: A
DNSprojectlightafrica.com
Type: A
DNSwww.berniestowing.com
Type: A
HTTP GEThttp://news.google.com/news?ned=us&output=rss
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://www.patrickcadona.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://natureswildchild.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://www.pennine-fp.co.uk/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://www.instrumentenschmiede.at/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://1836ink.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://firmafrugtforeningen.dk/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://slatten.org/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://sheenalarsen.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://signsny.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://cahillappraisal.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://www.its-email.co.uk/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://stevesplaceusaparts.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://evpcocoa.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://ackstone.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://amircreative.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://cafeinternationalcatering.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://amicableresolutionsintl.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://mahjongmuseum.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://thoughtsbecomereality.co.uk/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://derryrailtrail.org/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://justproud2b.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://www.hebamme-hochreiter.at/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://uaetoon.net/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://membermania.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://dentistschoice-fl.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://asiandvdtime.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://tropickoolac.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://deltaboats.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://dreamyjeanniebottles.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://richardspizza.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://braitman.net/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://engravings.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
HTTP GEThttp://www.berniestowing.com/.sys/?action=bs&v=20&a=names
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
Flows TCP192.168.1.1:1032 ➝ 62.253.3.118:80
Flows TCP192.168.1.1:1033 ➝ 82.165.78.116:80
Flows TCP192.168.1.1:1034 ➝ 50.56.218.189:80
Flows TCP192.168.1.1:1035 ➝ 87.106.115.7:80
Flows TCP192.168.1.1:1036 ➝ 85.158.181.28:80
Flows TCP192.168.1.1:1037 ➝ 216.177.137.4:80
Flows TCP192.168.1.1:1038 ➝ 87.48.171.8:80
Flows TCP192.168.1.1:1039 ➝ 195.128.174.122:80
Flows TCP192.168.1.1:1040 ➝ 74.208.182.107:80
Flows TCP192.168.1.1:1041 ➝ 50.62.247.1:80
Flows TCP192.168.1.1:1042 ➝ 72.167.232.151:80
Flows TCP192.168.1.1:1043 ➝ 79.170.44.90:80
Flows TCP192.168.1.1:1044 ➝ 5.157.84.33:80
Flows TCP192.168.1.1:1045 ➝ 141.101.115.20:80
Flows TCP192.168.1.1:1046 ➝ 173.236.165.41:80
Flows TCP192.168.1.1:1047 ➝ 50.63.202.40:80
Flows TCP192.168.1.1:1048 ➝ 72.167.232.181:80
Flows TCP192.168.1.1:1049 ➝ 108.175.14.57:80
Flows TCP192.168.1.1:1050 ➝ 66.175.58.9:80
Flows TCP192.168.1.1:1051 ➝ 208.109.181.27:80
Flows TCP192.168.1.1:1052 ➝ 192.254.190.143:80
Flows TCP192.168.1.1:1053 ➝ 82.98.86.179:80
Flows TCP192.168.1.1:1054 ➝ 91.250.86.163:80
Flows TCP192.168.1.1:1055 ➝ 70.87.96.233:80
Flows TCP192.168.1.1:1056 ➝ 208.73.211.246:80
Flows TCP192.168.1.1:1057 ➝ 69.43.161.156:80
Flows TCP192.168.1.1:1058 ➝ 209.222.14.3:80
Flows TCP192.168.1.1:1059 ➝ 50.63.202.62:80
Flows TCP192.168.1.1:1060 ➝ 38.112.61.200:80
Flows TCP192.168.1.1:1061 ➝ 72.167.183.80:80
Flows TCP192.168.1.1:1062 ➝ 64.71.34.100:80
Flows TCP192.168.1.1:1063 ➝ 65.39.205.54:80
Flows TCP192.168.1.1:1064 ➝ 50.31.99.11:80
Flows TCP192.168.1.1:1065 ➝ 216.55.131.217:80

Raw Pcap
0x00000000 (00000)   47455420 2f6e6577 733f6e65 643d7573   GET /news?ned=us
0x00000010 (00016)   266f7574 7075743d 72737320 48545450   &output=rss HTTP
0x00000020 (00032)   2f312e31 0d0a4163 63657074 3a202a2f   /1.1..Accept: */
0x00000030 (00048)   2a0d0a41 63636570 742d456e 636f6469   *..Accept-Encodi
0x00000040 (00064)   6e673a20 677a6970 2c206465 666c6174   ng: gzip, deflat
0x00000050 (00080)   650d0a55 7365722d 4167656e 743a204d   e..User-Agent: M
0x00000060 (00096)   6f7a696c 6c612f34 2e302028 636f6d70   ozilla/4.0 (comp
0x00000070 (00112)   61746962 6c653b20 4d534945 20362e30   atible; MSIE 6.0
0x00000080 (00128)   3b205769 6e646f77 73204e54 20352e31   ; Windows NT 5.1
0x00000090 (00144)   3b205356 313b202e 4e455420 434c5220   ; SV1; .NET CLR 
0x000000a0 (00160)   322e302e 35303732 37290d0a 486f7374   2.0.50727)..Host
0x000000b0 (00176)   3a206e65 77732e67 6f6f676c 652e636f   : news.google.co
0x000000c0 (00192)   6d0d0a43 6f6e6e65 6374696f 6e3a204b   m..Connection: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e7061 74726963 6b636164   : www.patrickcad
0x00000040 (00064)   6f6e612e 636f6d0d 0a557365 722d4167   ona.com..User-Ag
0x00000050 (00080)   656e743a 204d6f7a 696c6c61 2f352e30   ent: Mozilla/5.0
0x00000060 (00096)   31202857 696e646f 77733b20 553b2057   1 (Windows; U; W
0x00000070 (00112)   696e646f 7773204e 5420352e 323b2072   indows NT 5.2; r
0x00000080 (00128)   753b2072 763a312e 392e302e 31292047   u; rv:1.9.0.1) G
0x00000090 (00144)   65636b6f 2f323030 35303130 34204669   ecko/20050104 Fi
0x000000a0 (00160)   7265666f 782f332e 302e320d 0a436f6e   refox/3.0.2..Con
0x000000b0 (00176)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x000000c0 (00192)   0d0a0a43 6f6e6e65 6374696f 6e3a204b   ...Connection: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206e61 74757265 7377696c 64636869   : natureswildchi
0x00000040 (00064)   6c642e63 6f6d0d0a 55736572 2d416765   ld.com..User-Age
0x00000050 (00080)   6e743a20 4d6f7a69 6c6c612f 352e3031   nt: Mozilla/5.01
0x00000060 (00096)   20285769 6e646f77 733b2055 3b205769    (Windows; U; Wi
0x00000070 (00112)   6e646f77 73204e54 20352e32 3b207275   ndows NT 5.2; ru
0x00000080 (00128)   3b207276 3a312e39 2e302e31 29204765   ; rv:1.9.0.1) Ge
0x00000090 (00144)   636b6f2f 32303035 30313034 20466972   cko/20050104 Fir
0x000000a0 (00160)   65666f78 2f332e30 2e320d0a 436f6e6e   efox/3.0.2..Conn
0x000000b0 (00176)   65637469 6f6e3a20 636c6f73 650d0a0d   ection: close...
0x000000c0 (00192)   0a0a0a43 6f6e6e65 6374696f 6e3a204b   ...Connection: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e7065 6e6e696e 652d6670   : www.pennine-fp
0x00000040 (00064)   2e636f2e 756b0d0a 55736572 2d416765   .co.uk..User-Age
0x00000050 (00080)   6e743a20 4d6f7a69 6c6c612f 352e3031   nt: Mozilla/5.01
0x00000060 (00096)   20285769 6e646f77 733b2055 3b205769    (Windows; U; Wi
0x00000070 (00112)   6e646f77 73204e54 20352e32 3b207275   ndows NT 5.2; ru
0x00000080 (00128)   3b207276 3a312e39 2e302e31 29204765   ; rv:1.9.0.1) Ge
0x00000090 (00144)   636b6f2f 32303035 30313034 20466972   cko/20050104 Fir
0x000000a0 (00160)   65666f78 2f332e30 2e320d0a 436f6e6e   efox/3.0.2..Conn
0x000000b0 (00176)   65637469 6f6e3a20 636c6f73 650d0a0d   ection: close...
0x000000c0 (00192)   0a0a0a43 6f6e6e65 6374696f 6e3a204b   ...Connection: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e696e 73747275 6d656e74   : www.instrument
0x00000040 (00064)   656e7363 686d6965 64652e61 740d0a55   enschmiede.at..U
0x00000050 (00080)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000060 (00096)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000070 (00112)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000080 (00128)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000090 (00144)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x000000a0 (00160)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000b0 (00176)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 6374696f 6e3a204b   lose....ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a203138 3336696e 6b2e636f 6d0d0a55   : 1836ink.com..U
0x00000040 (00064)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000050 (00080)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000060 (00096)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000070 (00112)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000080 (00128)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x00000090 (00144)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000a0 (00160)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000b0 (00176)   6c6f7365 0d0a0d0a 6374696f 6e3a2063   lose....ction: c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 6374696f 6e3a204b   lose....ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206669 726d6166 72756774 666f7265   : firmafrugtfore
0x00000040 (00064)   6e696e67 656e2e64 6b0d0a55 7365722d   ningen.dk..User-
0x00000050 (00080)   4167656e 743a204d 6f7a696c 6c612f35   Agent: Mozilla/5
0x00000060 (00096)   2e303120 2857696e 646f7773 3b20553b   .01 (Windows; U;
0x00000070 (00112)   2057696e 646f7773 204e5420 352e323b    Windows NT 5.2;
0x00000080 (00128)   2072753b 2072763a 312e392e 302e3129    ru; rv:1.9.0.1)
0x00000090 (00144)   20476563 6b6f2f32 30303530 31303420    Gecko/20050104 
0x000000a0 (00160)   46697265 666f782f 332e302e 320d0a43   Firefox/3.0.2..C
0x000000b0 (00176)   6f6e6e65 6374696f 6e3a2063 6c6f7365   onnection: close
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a20736c 61747465 6e2e6f72 670d0a55   : slatten.org..U
0x00000040 (00064)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000050 (00080)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000060 (00096)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000070 (00112)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000080 (00128)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x00000090 (00144)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000a0 (00160)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000b0 (00176)   6c6f7365 0d0a0d0a 6e3a2063 6c6f7365   lose....n: close
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207368 65656e61 6c617273 656e2e63   : sheenalarsen.c
0x00000040 (00064)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x00000050 (00080)   4d6f7a69 6c6c612f 352e3031 20285769   Mozilla/5.01 (Wi
0x00000060 (00096)   6e646f77 733b2055 3b205769 6e646f77   ndows; U; Window
0x00000070 (00112)   73204e54 20352e32 3b207275 3b207276   s NT 5.2; ru; rv
0x00000080 (00128)   3a312e39 2e302e31 29204765 636b6f2f   :1.9.0.1) Gecko/
0x00000090 (00144)   32303035 30313034 20466972 65666f78   20050104 Firefox
0x000000a0 (00160)   2f332e30 2e320d0a 436f6e6e 65637469   /3.0.2..Connecti
0x000000b0 (00176)   6f6e3a20 636c6f73 650d0a0d 0a6f7365   on: close....ose
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207369 676e736e 792e636f 6d0d0a55   : signsny.com..U
0x00000040 (00064)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000050 (00080)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000060 (00096)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000070 (00112)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000080 (00128)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x00000090 (00144)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000a0 (00160)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000b0 (00176)   6c6f7365 0d0a0d0a 650d0a0d 0a6f7365   lose....e....ose
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 650d0a0d 0a         eep-Alive....

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206361 68696c6c 61707072 61697361   : cahillappraisa
0x00000040 (00064)   6c2e636f 6d0d0a55 7365722d 4167656e   l.com..User-Agen
0x00000050 (00080)   743a204d 6f7a696c 6c612f35 2e303120   t: Mozilla/5.01 
0x00000060 (00096)   2857696e 646f7773 3b20553b 2057696e   (Windows; U; Win
0x00000070 (00112)   646f7773 204e5420 352e323b 2072753b   dows NT 5.2; ru;
0x00000080 (00128)   2072763a 312e392e 302e3129 20476563    rv:1.9.0.1) Gec
0x00000090 (00144)   6b6f2f32 30303530 31303420 46697265   ko/20050104 Fire
0x000000a0 (00160)   666f782f 332e302e 320d0a43 6f6e6e65   fox/3.0.2..Conne
0x000000b0 (00176)   6374696f 6e3a2063 6c6f7365 0d0a0d0a   ction: close....
0x000000c0 (00192)   ffffffff 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e6974 732d656d 61696c2e   : www.its-email.
0x00000040 (00064)   636f2e75 6b0d0a55 7365722d 4167656e   co.uk..User-Agen
0x00000050 (00080)   743a204d 6f7a696c 6c612f35 2e303120   t: Mozilla/5.01 
0x00000060 (00096)   2857696e 646f7773 3b20553b 2057696e   (Windows; U; Win
0x00000070 (00112)   646f7773 204e5420 352e323b 2072753b   dows NT 5.2; ru;
0x00000080 (00128)   2072763a 312e392e 302e3129 20476563    rv:1.9.0.1) Gec
0x00000090 (00144)   6b6f2f32 30303530 31303420 46697265   ko/20050104 Fire
0x000000a0 (00160)   666f782f 332e302e 320d0a43 6f6e6e65   fox/3.0.2..Conne
0x000000b0 (00176)   6374696f 6e3a2063 6c6f7365 0d0a0d0a   ction: close....
0x000000c0 (00192)   ffffffff 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207374 65766573 706c6163 65757361   : stevesplaceusa
0x00000040 (00064)   70617274 732e636f 6d0d0a55 7365722d   parts.com..User-
0x00000050 (00080)   4167656e 743a204d 6f7a696c 6c612f35   Agent: Mozilla/5
0x00000060 (00096)   2e303120 2857696e 646f7773 3b20553b   .01 (Windows; U;
0x00000070 (00112)   2057696e 646f7773 204e5420 352e323b    Windows NT 5.2;
0x00000080 (00128)   2072753b 2072763a 312e392e 302e3129    ru; rv:1.9.0.1)
0x00000090 (00144)   20476563 6b6f2f32 30303530 31303420    Gecko/20050104 
0x000000a0 (00160)   46697265 666f782f 332e302e 320d0a43   Firefox/3.0.2..C
0x000000b0 (00176)   6f6e6e65 6374696f 6e3a2063 6c6f7365   onnection: close
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206576 70636f63 6f612e63 6f6d0d0a   : evpcocoa.com..
0x00000040 (00064)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x00000050 (00080)   6c6c612f 352e3031 20285769 6e646f77   lla/5.01 (Window
0x00000060 (00096)   733b2055 3b205769 6e646f77 73204e54   s; U; Windows NT
0x00000070 (00112)   20352e32 3b207275 3b207276 3a312e39    5.2; ru; rv:1.9
0x00000080 (00128)   2e302e31 29204765 636b6f2f 32303035   .0.1) Gecko/2005
0x00000090 (00144)   30313034 20466972 65666f78 2f332e30   0104 Firefox/3.0
0x000000a0 (00160)   2e320d0a 436f6e6e 65637469 6f6e3a20   .2..Connection: 
0x000000b0 (00176)   636c6f73 650d0a0d 0a3a2063 6c6f7365   close....: close
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206163 6b73746f 6e652e63 6f6d0d0a   : ackstone.com..
0x00000040 (00064)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x00000050 (00080)   6c6c612f 352e3031 20285769 6e646f77   lla/5.01 (Window
0x00000060 (00096)   733b2055 3b205769 6e646f77 73204e54   s; U; Windows NT
0x00000070 (00112)   20352e32 3b207275 3b207276 3a312e39    5.2; ru; rv:1.9
0x00000080 (00128)   2e302e31 29204765 636b6f2f 32303035   .0.1) Gecko/2005
0x00000090 (00144)   30313034 20466972 65666f78 2f332e30   0104 Firefox/3.0
0x000000a0 (00160)   2e320d0a 436f6e6e 65637469 6f6e3a20   .2..Connection: 
0x000000b0 (00176)   636c6f73 650d0a0d 0a3a2063 6c6f7365   close....: close
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a20616d 69726372 65617469 76652e63   : amircreative.c
0x00000040 (00064)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x00000050 (00080)   4d6f7a69 6c6c612f 352e3031 20285769   Mozilla/5.01 (Wi
0x00000060 (00096)   6e646f77 733b2055 3b205769 6e646f77   ndows; U; Window
0x00000070 (00112)   73204e54 20352e32 3b207275 3b207276   s NT 5.2; ru; rv
0x00000080 (00128)   3a312e39 2e302e31 29204765 636b6f2f   :1.9.0.1) Gecko/
0x00000090 (00144)   32303035 30313034 20466972 65666f78   20050104 Firefox
0x000000a0 (00160)   2f332e30 2e320d0a 436f6e6e 65637469   /3.0.2..Connecti
0x000000b0 (00176)   6f6e3a20 636c6f73 650d0a0d 0a6f7365   on: close....ose
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 6374696f 6e3a204b   ........ction: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206361 6665696e 7465726e 6174696f   : cafeinternatio
0x00000040 (00064)   6e616c63 61746572 696e672e 636f6d0d   nalcatering.com.
0x00000050 (00080)   0a557365 722d4167 656e743a 204d6f7a   .User-Agent: Moz
0x00000060 (00096)   696c6c61 2f352e30 31202857 696e646f   illa/5.01 (Windo
0x00000070 (00112)   77733b20 553b2057 696e646f 7773204e   ws; U; Windows N
0x00000080 (00128)   5420352e 323b2072 753b2072 763a312e   T 5.2; ru; rv:1.
0x00000090 (00144)   392e302e 31292047 65636b6f 2f323030   9.0.1) Gecko/200
0x000000a0 (00160)   35303130 34204669 7265666f 782f332e   50104 Firefox/3.
0x000000b0 (00176)   302e320d 0a436f6e 6e656374 696f6e3a   0.2..Connection:
0x000000c0 (00192)   20636c6f 73650d0a 0d0a696f 6e3a204b    close....ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a20616d 69636162 6c657265 736f6c75   : amicableresolu
0x00000040 (00064)   74696f6e 73696e74 6c2e636f 6d0d0a55   tionsintl.com..U
0x00000050 (00080)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000060 (00096)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000070 (00112)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000080 (00128)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000090 (00144)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x000000a0 (00160)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000b0 (00176)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 0d0a696f 6e3a204b   lose......ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206d61 686a6f6e 676d7573 65756d2e   : mahjongmuseum.
0x00000040 (00064)   636f6d0d 0a557365 722d4167 656e743a   com..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f352e30 31202857    Mozilla/5.01 (W
0x00000060 (00096)   696e646f 77733b20 553b2057 696e646f   indows; U; Windo
0x00000070 (00112)   7773204e 5420352e 323b2072 753b2072   ws NT 5.2; ru; r
0x00000080 (00128)   763a312e 392e302e 31292047 65636b6f   v:1.9.0.1) Gecko
0x00000090 (00144)   2f323030 35303130 34204669 7265666f   /20050104 Firefo
0x000000a0 (00160)   782f332e 302e320d 0a436f6e 6e656374   x/3.0.2..Connect
0x000000b0 (00176)   696f6e3a 20636c6f 73650d0a 0d0a2063   ion: close.... c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 0d0a696f 6e3a204b   lose......ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207468 6f756768 74736265 636f6d65   : thoughtsbecome
0x00000040 (00064)   7265616c 6974792e 636f2e75 6b0d0a55   reality.co.uk..U
0x00000050 (00080)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000060 (00096)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000070 (00112)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000080 (00128)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000090 (00144)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x000000a0 (00160)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000b0 (00176)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 0d0a696f 6e3a204b   lose......ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206465 72727972 61696c74 7261696c   : derryrailtrail
0x00000040 (00064)   2e6f7267 0d0a5573 65722d41 67656e74   .org..User-Agent
0x00000050 (00080)   3a204d6f 7a696c6c 612f352e 30312028   : Mozilla/5.01 (
0x00000060 (00096)   57696e64 6f77733b 20553b20 57696e64   Windows; U; Wind
0x00000070 (00112)   6f777320 4e542035 2e323b20 72753b20   ows NT 5.2; ru; 
0x00000080 (00128)   72763a31 2e392e30 2e312920 4765636b   rv:1.9.0.1) Geck
0x00000090 (00144)   6f2f3230 30353031 30342046 69726566   o/20050104 Firef
0x000000a0 (00160)   6f782f33 2e302e32 0d0a436f 6e6e6563   ox/3.0.2..Connec
0x000000b0 (00176)   74696f6e 3a20636c 6f73650d 0a0d0a63   tion: close....c
0x000000c0 (00192)   6c6f7365 0d0a0d0a 0d0a696f 6e3a204b   lose......ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206a75 73747072 6f756432 622e636f   : justproud2b.co
0x00000040 (00064)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x00000050 (00080)   6f7a696c 6c612f35 2e303120 2857696e   ozilla/5.01 (Win
0x00000060 (00096)   646f7773 3b20553b 2057696e 646f7773   dows; U; Windows
0x00000070 (00112)   204e5420 352e323b 2072753b 2072763a    NT 5.2; ru; rv:
0x00000080 (00128)   312e392e 302e3129 20476563 6b6f2f32   1.9.0.1) Gecko/2
0x00000090 (00144)   30303530 31303420 46697265 666f782f   0050104 Firefox/
0x000000a0 (00160)   332e302e 320d0a43 6f6e6e65 6374696f   3.0.2..Connectio
0x000000b0 (00176)   6e3a2063 6c6f7365 0d0a0d0a 0a0d0a63   n: close.......c
0x000000c0 (00192)   ffffffff 0d0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e6865 62616d6d 652d686f   : www.hebamme-ho
0x00000040 (00064)   63687265 69746572 2e61740d 0a557365   chreiter.at..Use
0x00000050 (00080)   722d4167 656e743a 204d6f7a 696c6c61   r-Agent: Mozilla
0x00000060 (00096)   2f352e30 31202857 696e646f 77733b20   /5.01 (Windows; 
0x00000070 (00112)   553b2057 696e646f 7773204e 5420352e   U; Windows NT 5.
0x00000080 (00128)   323b2072 753b2072 763a312e 392e302e   2; ru; rv:1.9.0.
0x00000090 (00144)   31292047 65636b6f 2f323030 35303130   1) Gecko/2005010
0x000000a0 (00160)   34204669 7265666f 782f332e 302e320d   4 Firefox/3.0.2.
0x000000b0 (00176)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x000000c0 (00192)   73650d0a 0d0a0d0a 0d0a696f 6e3a204b   se........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207561 65746f6f 6e2e6e65 740d0a55   : uaetoon.net..U
0x00000040 (00064)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x00000050 (00080)   6c612f35 2e303120 2857696e 646f7773   la/5.01 (Windows
0x00000060 (00096)   3b20553b 2057696e 646f7773 204e5420   ; U; Windows NT 
0x00000070 (00112)   352e323b 2072753b 2072763a 312e392e   5.2; ru; rv:1.9.
0x00000080 (00128)   302e3129 20476563 6b6f2f32 30303530   0.1) Gecko/20050
0x00000090 (00144)   31303420 46697265 666f782f 332e302e   104 Firefox/3.0.
0x000000a0 (00160)   320d0a43 6f6e6e65 6374696f 6e3a2063   2..Connection: c
0x000000b0 (00176)   6c6f7365 0d0a0d0a 696f6e3a 20636c6f   lose....ion: clo
0x000000c0 (00192)   73650d0a 0d0a0d0a 0d0a696f 6e3a204b   se........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206d65 6d626572 6d616e69 612e636f   : membermania.co
0x00000040 (00064)   6d0d0a55 7365722d 4167656e 743a204d   m..User-Agent: M
0x00000050 (00080)   6f7a696c 6c612f35 2e303120 2857696e   ozilla/5.01 (Win
0x00000060 (00096)   646f7773 3b20553b 2057696e 646f7773   dows; U; Windows
0x00000070 (00112)   204e5420 352e323b 2072753b 2072763a    NT 5.2; ru; rv:
0x00000080 (00128)   312e392e 302e3129 20476563 6b6f2f32   1.9.0.1) Gecko/2
0x00000090 (00144)   30303530 31303420 46697265 666f782f   0050104 Firefox/
0x000000a0 (00160)   332e302e 320d0a43 6f6e6e65 6374696f   3.0.2..Connectio
0x000000b0 (00176)   6e3a2063 6c6f7365 0d0a0d0a 20636c6f   n: close.... clo
0x000000c0 (00192)   73650d0a 0d0a0d0a 0d0a696f 6e3a204b   se........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206465 6e746973 74736368 6f696365   : dentistschoice
0x00000040 (00064)   2d666c2e 636f6d0d 0a557365 722d4167   -fl.com..User-Ag
0x00000050 (00080)   656e743a 204d6f7a 696c6c61 2f352e30   ent: Mozilla/5.0
0x00000060 (00096)   31202857 696e646f 77733b20 553b2057   1 (Windows; U; W
0x00000070 (00112)   696e646f 7773204e 5420352e 323b2072   indows NT 5.2; r
0x00000080 (00128)   753b2072 763a312e 392e302e 31292047   u; rv:1.9.0.1) G
0x00000090 (00144)   65636b6f 2f323030 35303130 34204669   ecko/20050104 Fi
0x000000a0 (00160)   7265666f 782f332e 302e320d 0a436f6e   refox/3.0.2..Con
0x000000b0 (00176)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206173 69616e64 76647469 6d652e63   : asiandvdtime.c
0x00000040 (00064)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x00000050 (00080)   4d6f7a69 6c6c612f 352e3031 20285769   Mozilla/5.01 (Wi
0x00000060 (00096)   6e646f77 733b2055 3b205769 6e646f77   ndows; U; Window
0x00000070 (00112)   73204e54 20352e32 3b207275 3b207276   s NT 5.2; ru; rv
0x00000080 (00128)   3a312e39 2e302e31 29204765 636b6f2f   :1.9.0.1) Gecko/
0x00000090 (00144)   32303035 30313034 20466972 65666f78   20050104 Firefox
0x000000a0 (00160)   2f332e30 2e320d0a 436f6e6e 65637469   /3.0.2..Connecti
0x000000b0 (00176)   6f6e3a20 636c6f73 650d0a0d 0a650d0a   on: close....e..
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207472 6f706963 6b6f6f6c 61632e63   : tropickoolac.c
0x00000040 (00064)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x00000050 (00080)   4d6f7a69 6c6c612f 352e3031 20285769   Mozilla/5.01 (Wi
0x00000060 (00096)   6e646f77 733b2055 3b205769 6e646f77   ndows; U; Window
0x00000070 (00112)   73204e54 20352e32 3b207275 3b207276   s NT 5.2; ru; rv
0x00000080 (00128)   3a312e39 2e302e31 29204765 636b6f2f   :1.9.0.1) Gecko/
0x00000090 (00144)   32303035 30313034 20466972 65666f78   20050104 Firefox
0x000000a0 (00160)   2f332e30 2e320d0a 436f6e6e 65637469   /3.0.2..Connecti
0x000000b0 (00176)   6f6e3a20 636c6f73 650d0a0d 0a650d0a   on: close....e..
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206465 6c746162 6f617473 2e636f6d   : deltaboats.com
0x00000040 (00064)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000050 (00080)   7a696c6c 612f352e 30312028 57696e64   zilla/5.01 (Wind
0x00000060 (00096)   6f77733b 20553b20 57696e64 6f777320   ows; U; Windows 
0x00000070 (00112)   4e542035 2e323b20 72753b20 72763a31   NT 5.2; ru; rv:1
0x00000080 (00128)   2e392e30 2e312920 4765636b 6f2f3230   .9.0.1) Gecko/20
0x00000090 (00144)   30353031 30342046 69726566 6f782f33   050104 Firefox/3
0x000000a0 (00160)   2e302e32 0d0a436f 6e6e6563 74696f6e   .0.2..Connection
0x000000b0 (00176)   3a20636c 6f73650d 0a0d0a0d 0a650d0a   : close......e..
0x000000c0 (00192)   0d0a0d0a 0d0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206472 65616d79 6a65616e 6e696562   : dreamyjeannieb
0x00000040 (00064)   6f74746c 65732e63 6f6d0d0a 55736572   ottles.com..User
0x00000050 (00080)   2d416765 6e743a20 4d6f7a69 6c6c612f   -Agent: Mozilla/
0x00000060 (00096)   352e3031 20285769 6e646f77 733b2055   5.01 (Windows; U
0x00000070 (00112)   3b205769 6e646f77 73204e54 20352e32   ; Windows NT 5.2
0x00000080 (00128)   3b207275 3b207276 3a312e39 2e302e31   ; ru; rv:1.9.0.1
0x00000090 (00144)   29204765 636b6f2f 32303035 30313034   ) Gecko/20050104
0x000000a0 (00160)   20466972 65666f78 2f332e30 2e320d0a    Firefox/3.0.2..
0x000000b0 (00176)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x000000c0 (00192)   650d0a0d 0a0a0d0a 0d0a696f 6e3a204b   e.........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207269 63686172 64737069 7a7a612e   : richardspizza.
0x00000040 (00064)   636f6d0d 0a557365 722d4167 656e743a   com..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f352e30 31202857    Mozilla/5.01 (W
0x00000060 (00096)   696e646f 77733b20 553b2057 696e646f   indows; U; Windo
0x00000070 (00112)   7773204e 5420352e 323b2072 753b2072   ws NT 5.2; ru; r
0x00000080 (00128)   763a312e 392e302e 31292047 65636b6f   v:1.9.0.1) Gecko
0x00000090 (00144)   2f323030 35303130 34204669 7265666f   /20050104 Firefo
0x000000a0 (00160)   782f332e 302e320d 0a436f6e 6e656374   x/3.0.2..Connect
0x000000b0 (00176)   696f6e3a 20636c6f 73650d0a 0d0a6f73   ion: close....os
0x000000c0 (00192)   650d0a0d 0a0a0d0a 0d0a696f 6e3a204b   e.........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a206272 6169746d 616e2e6e 65740d0a   : braitman.net..
0x00000040 (00064)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x00000050 (00080)   6c6c612f 352e3031 20285769 6e646f77   lla/5.01 (Window
0x00000060 (00096)   733b2055 3b205769 6e646f77 73204e54   s; U; Windows NT
0x00000070 (00112)   20352e32 3b207275 3b207276 3a312e39    5.2; ru; rv:1.9
0x00000080 (00128)   2e302e31 29204765 636b6f2f 32303035   .0.1) Gecko/2005
0x00000090 (00144)   30313034 20466972 65666f78 2f332e30   0104 Firefox/3.0
0x000000a0 (00160)   2e320d0a 436f6e6e 65637469 6f6e3a20   .2..Connection: 
0x000000b0 (00176)   636c6f73 650d0a0d 0a650d0a 0d0a6f73   close....e....os
0x000000c0 (00192)   650d0a0d 0a0a0d0a 0d0a696f 6e3a204b   e.........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a20656e 67726176 696e6773 2e636f6d   : engravings.com
0x00000040 (00064)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000050 (00080)   7a696c6c 612f352e 30312028 57696e64   zilla/5.01 (Wind
0x00000060 (00096)   6f77733b 20553b20 57696e64 6f777320   ows; U; Windows 
0x00000070 (00112)   4e542035 2e323b20 72753b20 72763a31   NT 5.2; ru; rv:1
0x00000080 (00128)   2e392e30 2e312920 4765636b 6f2f3230   .9.0.1) Gecko/20
0x00000090 (00144)   30353031 30342046 69726566 6f782f33   050104 Firefox/3
0x000000a0 (00160)   2e302e32 0d0a436f 6e6e6563 74696f6e   .0.2..Connection
0x000000b0 (00176)   3a20636c 6f73650d 0a0d0a0a 0d0a6f73   : close.......os
0x000000c0 (00192)   ffffffff 0a0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...

0x00000000 (00000)   47455420 2f2e7379 732f3f61 6374696f   GET /.sys/?actio
0x00000010 (00016)   6e3d6273 26763d32 3026613d 6e616d65   n=bs&v=20&a=name
0x00000020 (00032)   73204854 54502f31 2e300d0a 486f7374   s HTTP/1.0..Host
0x00000030 (00048)   3a207777 772e6265 726e6965 73746f77   : www.berniestow
0x00000040 (00064)   696e672e 636f6d0d 0a557365 722d4167   ing.com..User-Ag
0x00000050 (00080)   656e743a 204d6f7a 696c6c61 2f352e30   ent: Mozilla/5.0
0x00000060 (00096)   31202857 696e646f 77733b20 553b2057   1 (Windows; U; W
0x00000070 (00112)   696e646f 7773204e 5420352e 323b2072   indows NT 5.2; r
0x00000080 (00128)   753b2072 763a312e 392e302e 31292047   u; rv:1.9.0.1) G
0x00000090 (00144)   65636b6f 2f323030 35303130 34204669   ecko/20050104 Fi
0x000000a0 (00160)   7265666f 782f332e 302e320d 0a436f6e   refox/3.0.2..Con
0x000000b0 (00176)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x000000c0 (00192)   0d0affff 0a0a0d0a 0d0a696f 6e3a204b   ..........ion: K
0x000000d0 (00208)   6565702d 416c6976 807343b0 eb7f       eep-Aliv.sC...


Strings
INPUT
Tdescription
title
1025wynr.net
1836ink.com
??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
3mates.com
500instantniches.com
a/5.01 (Windows; U; Wi
a/Addr
abcdefghijklmnopqrstuvwxyz
accounts/Captcha
accounts/CreateAccount
accounts/NewAccount
accounts/ServiceLogin
ackstone.com
?action=bs&v=20&a=names
?action=bs&v=20&a=save&c=%s&l=%s&p=%s&shorturl=%s
?action=bs&v=20&a=save&l=%s&p=%s
akecheta-huskies.co.uk
alabama-moms.com
alavench.com
allstateprocess.com
amicableresolutionsintl.com
amircreative.com
arabfreeads.com
arnarsmari.kopavogur.is
asiandvdtime.com
ask4training.com
?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z
?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
B6XqLkU
BDO_CM1?
beautiteen.hostmaniacs.com
bizcontax.co.za
#BLACKLABEL
blogID=
blogsnstuff.com
.blogspot.com/
blogspotname
blogtitle
bonniejacobsen.com
borderssportinggoods.com
braitman.net
branderideklub.dk
brandtransfer.com
brevard-fl.com
buddhatoursnepal.com.np
budobg.com
bygodtexas.com
?_C@?1??_Nullstr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CAPBDXZ@4DB
cafeinternationalcatering.com
cahillappraisal.com
captchaAnswer
captcha?type=IMAGE
casiangeles.co.il
cedelevator.com
Ch2ToM{
channel/item
CharToOemA
checkavailbuttondiv
cherokeerealestate.com
CloseHandle
c:\newblogger.bat
CoCreateInstance
CoInitialize
commentCaptcha
commentsAccess
Connec
connect2pakistan.com
Content-Type: binary/octet-stream
cotedesmegalithes.com
CoUninitialize
CreateFileA
CreateProcessA
crossroads-wfd.org
ctsrmspos.com
__CxxFrameHandler
daromy.com
DeleteFileA
 del "%s"
 del "%s" 
deltaboats.com
dentistschoice-fl.com
derryrailtrail.org
D$@hL!@
discretionlingerie.com
displayname
djjohnlarner.com
</DlgLl
dorothycooley.com
dreamyjeanniebottles.com
dynasales.net
easygiftgiving.com
e-autosystem.gr
_EH_prolog
elenailyina.com
engravings.com
?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z
etiByt1V
evpcocoa.com
ExitProcess
fifusalir.kopavogur.is
?find@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIPBDII@Z
firmafrugtforeningen.dk
FirstName
foamcoat.com
freedomtobe.org
FreeLibrary
galacticcenter.org
gay-stay.co.uk
GetCommandLineA
GetCurrentProcessId
GetCurrentThreadId
GetFileSize
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetTickCount
GetUrlCacheEntryInfoA
GetVersion
grandmashouseteagifts.com
greenhealthyliving4u.netfirms.com
greystoneofellijay.com
grooverslounge.com
guypacot.com
gxf.co.il
hcgalleri.com
HeapAlloc
HeapFree
hgueynfxicsxgwfqu
hidden
Host: 
HQM8}]~
http://bit.ly/?url=http://
http://news.google.com/news?ned=us&output=rss
https://www.blogger.com/start
https://www.google.com/accounts/NewAccount?service=mail&type=2&gd=1
http://www.blogger.com/blogoptionscomments.g?blogID=
http://www.blogger.com/create-blog.g
http://www.blogger.com/logout.g
hvingelbybiler.dk
hypnoticacolectiva.com
IdentityAnswer
 if exist "%s" goto Repeat
i-hass-di.de
inartdesigns.com
internethosting.sg
JGTI  
justproud2b.com
keeplan.com
KERNEL32.DLL
kevinbarkerauctions.com
kjhgqt2fj1gdh3.tmp
kopahvoll.kopavogur.is
LastName
LoadLibraryA
lstrlenA
lstrlenW
magnumopus.dk
mahjongmuseum.com
malloc
mcmoos.co.za
membermania.com
memcpy
memset
mevsimevsim.com
miamicaraccessories.com
ModuleFi
mohammedistechnologies.com
MSVCP60.dll
MSVCRT.dll
MultiByteToWideChar
musthaveitjewelry.com.mytempweb.com
mW2IBE
mycleveridea.co.za
nasheecakes.com
natureswildchild.com
&nbsp;
nessebarforum.com
newaccountcaptcha
next-btn
?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB
ole32.dll
OLEAUT32.dll
onchange
onkeydown
onkeypress
onkeyup
OpenProcess
optimumorg.com
ows NT 5.2; ru; r
parkercountyhd.org
Passwd
PasswdAgain
pattersonsnares.com
postBody
?post=true&path=captcha&a=query&b=%s&id=%s
?post=true&path=captcha&a=save&b=%s
projectlightafrica.com
promservice.sky.ru
PSSSSSSWS
publishButton
QAEAAV1
qatar-business-guide.net
,( <qFFF840
questions
radioChoices
r-Agent: Moz
ralphcotton.net
ReadFile
reishus.de
:Repeat 
?replace@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@IIABV12@II@Z
reusp.com
richardspizza.com
rjupnahaed.kopavogur.is
rocklamanna.com
rschaedeli.dyndns.org
rwcotton.biz
rwcotton.com
saratogasteakhouse.com
sendx56546xx
sheenalarsen.com
shop.spyral-promotions.co.uk
short_url
signIn
signsny.com
silveradojewellery.ca
sinonilimited.com
slatten.org
smarahvammur.kopavogur.is
sprintf
spyral-promotions.co.uk
starart.net
stevesplaceusaparts.com
strcat
strchr
strcmp
strcpy
_strdup
_stricmp
strlen
_strlwr
strpbrk
strstr
subdomain-errors
submitbutton
submitButton
?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z
suggestions
 /.sys/
t0. rT
tent-Length: 
TerminateProcess
termsofservice
ternkeyrentals.com
texasref.com
textarea
%$TFFF6
theshipmangroup.com
the-word-is.com
!This program cannot be run in DOS mode.
thoughtsbecomereality.co.uk
?_Tidy@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEX_N@Z
tion: close
tradersquants.com.mx
traffichits247.com
tropickoolac.com
turk-ie.org
u07012010u.com
uaetoon.net
USER32.dll
Use%sill%snd%sv:1.9.0.1) Gecko/20050104 Firefox/3.0.2
VirtualAlloc
VirtualFree
VirtualProtect
vivicohen.com.ar
VPhp%@
wcscmp
welovetweet.com
wff.co.za
whoffmanchiro.com
whyviral.com
WideCharToMultiByte
wininet
WriteFile
ws2_32.dll
WS2_32.dll
wt-egypt.com
www.agapebowling.com
www.agentorange.co.za
www.andrewscript.com
www.bastakigroup.com
www.berniestowing.com
www.chateaudecoisse.com
www.deaf-world-gehoerlos-friend.de
www.derekmohr.com
www.eom.it
www.erotic-food.ch
www.fastpitchequipment.com
www.fivestar.ch
www.hebamme-hochreiter.at
www.hotelkreuzwirt.at
www.humlumnet.dk
www.instrumentenschmiede.at
www.its-email.co.uk
www.jacksonvillelibrary.com
www.learningomaha.com
www.miamicaraccessories.com
www.motopimps.com
www.nautiqa.com.sg
www.nohurtme.com
www.patrickcadona.com
www.pennine-fp.co.uk
www.pwsd1pc.org
www.resenboernehave.dk
www.ricksmusicstore.com
www.schatzbichl.at
www.tabdesign.com.sg
www.vallesina.tv
www.viducate.net
www.wael-tv.com
www.weatherserve.net
www.wheatfieldwaterfrontassociation.org
www.zetone.ch
`XP'+2
XPTPSW
yourprofit.brevard-fl.com
YYhD!@
ZCAXXZ@4DB;T
Z\fJdYBEIP