Analysis Date2015-11-30 14:53:54
MD5aa5fbb294a410b0b8aaec0ddcd6b557c
SHA1ea3dce9988e85703a97b4347dba005768eeba860

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 51ca9e7aa4a2c18d3122cd52d090b2f8 sha1: 7f335737cfba5ae8f3f4a1777a1e633bbd386170 size: 307200
Section.rdata md5: 34a7e858d7c07b7bf0a4e7bca50c0080 sha1: 01b5edc11fc208139fcf2f8f8ac34c022e5078e3 size: 40960
Section.data md5: 9992dd288361ee774b8e4f904cbf1e0c sha1: a23f6e12ea1b7cb38f3a2a1c1afc153edafd4815 size: 7168
Timestamp2015-11-23 02:48:33
PackerMicrosoft Visual C++ ?.?
PEhashcbdca03354943f2fc380406850c31ba025c6a0c3
IMPhash7a60cda4e588a5c02ac98d4289500e60
AVAd-Aware Command-LineTrojan.GenericKD.2894795
AVArcaVir AntivirusTrojan.GenericKD.2894795
AVAvast! AntivirusMalware-gen:Win32:Malware-gen
AVAVG AntiVirusDropper.Generic_r.EC
AVAvira AntivirusTR/Crypt.Xpack.330203
AVBitdefender Command-LineTrojan.GenericKD.2894795
AVBullGuard AntivirusTrojan.GenericKD.2894795
AVClamWin AntivirusNo Virus
AVCommand Anti-MalwareW32/Kazy.EW.gen!Eldorado:Security risk
AVDr. Web Anti-virusNo Virus
AVEmsisoft Command-Line ScannerTrojan.GenericKD.2894795
AVeScan Anti-VirusNo Virus
AVESET NOD32 AntivirusWin32/Bayrob.AD
AVFortinet Command-Line ScannerW32/Bayrob.AD!tr
AVF-PROT AntivirusNo Virus
AVF-Secure Anti-VirusTrojan.GenericKD.2894795
AVIkarus Command-Line ScannerNo Virus
AVK7 Anti-VirusTrojan ( 004d79c41 )
AVKaspersky Anti-VirusNo Virus
AVMalwareBytes Anti-MalwareNo Virus
AVMcAfee Command-Line ScannerBackDoor-FCYZ!AA5FBB294A41
AVMicrosoft Security EssentialsTrojan:Win32/Dynamer!ac:Trojan
AVPadvish AntivirusNo Virus
AVQuick Heal AntiVirusNo Virus
AVRising Command-Line ScannerNo Virus
AVSymantec Command-Line ScannerNo Virus
AVTotal Defense Internet Security SuiteNo Virus
AVTrend Micro System CleanerNo Virus
AVTwister AntivirusNo Virus
AVVirusBlokAda Console ScannerNo Virus
AVZillya! AntivirusNo Virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\yhtjkkyrwlyz\ucuwmegqdm
Creates FileC:\yhtjkkyrwlyz\hzz1lvpgavfgblnqop7.exe
Creates FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Deletes FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Creates ProcessC:\yhtjkkyrwlyz\hzz1lvpgavfgblnqop7.exe

Process
↳ C:\yhtjkkyrwlyz\hzz1lvpgavfgblnqop7.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Secure Device Virtual Player ➝
C:\yhtjkkyrwlyz\zsajsvao.exe
Creates FileC:\yhtjkkyrwlyz\ucuwmegqdm
Creates FileC:\yhtjkkyrwlyz\v6jxkxu
Creates FileC:\yhtjkkyrwlyz\zsajsvao.exe
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Deletes FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Creates ProcessC:\yhtjkkyrwlyz\zsajsvao.exe
Creates ServiceNetwork Registry Extender Image Video - C:\yhtjkkyrwlyz\zsajsvao.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 852

Process
↳ Pid 1020

Process
↳ Pid 1208

Process
↳ Pid 1296

Process
↳ Pid 1852

Process
↳ Pid 720

Process
↳ C:\yhtjkkyrwlyz\zsajsvao.exe

Creates FileC:\yhtjkkyrwlyz\vacyyek.exe
Creates Filepipe\net\NtControlPipe10
Creates FileC:\yhtjkkyrwlyz\ucuwmegqdm
Creates FileC:\yhtjkkyrwlyz\hktnjtw1
Creates FileC:\yhtjkkyrwlyz\v6jxkxu
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Deletes FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Creates Processfujg3gghjjgu "c:\yhtjkkyrwlyz\zsajsvao.exe"

Process
↳ C:\yhtjkkyrwlyz\zsajsvao.exe

Creates FileC:\yhtjkkyrwlyz\ucuwmegqdm
Creates FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Deletes FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm

Process
↳ fujg3gghjjgu "c:\yhtjkkyrwlyz\zsajsvao.exe"

Creates FileC:\yhtjkkyrwlyz\ucuwmegqdm
Creates FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm
Deletes FileC:\WINDOWS\yhtjkkyrwlyz\ucuwmegqdm

Network Details:

DNSweathercontrol.net
Type: A
50.63.37.71
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSclasscontrol.net
Type: A
216.239.130.220
DNSchiefapple.net
Type: A
82.165.25.210
DNSchiefbuilt.net
Type: A
195.22.28.199
DNSchiefbuilt.net
Type: A
195.22.28.198
DNSchiefbuilt.net
Type: A
195.22.28.197
DNSchiefbuilt.net
Type: A
195.22.28.196
DNStwelvebuilt.net
Type: A
98.139.135.129
DNStwelvecarry.net
Type: A
208.91.197.241
DNSmorningapple.net
Type: A
222.122.84.70
DNSstrangeapple.net
Type: A
82.165.25.210
DNSweatherfather.net
Type: A
208.100.26.234
DNSweatherbuilt.net
Type: A
203.27.227.220
DNSthickapple.net
Type: A
95.211.230.75
DNSpresentmeasure.net
Type: A
95.211.230.75
DNScollegemeasure.net
Type: A
184.168.221.31
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNScollegecircle.net
Type: A
50.63.202.52
DNSsk129.webcname.net
Type: A
182.18.22.158
DNSpresentalways.net
Type: A
208.100.26.234
DNSthinkforest.net
Type: A
59.8.236.130
DNSthickmatter.net
Type: A
DNSclassmatter.net
Type: A
DNSthickspent.net
Type: A
DNSclassspent.net
Type: A
DNSthicktogether.net
Type: A
DNSclasstogether.net
Type: A
DNSthickcontrol.net
Type: A
DNSthinkfather.net
Type: A
DNSpresentfather.net
Type: A
DNSthinkapple.net
Type: A
DNSpresentapple.net
Type: A
DNSthinkbuilt.net
Type: A
DNSpresentbuilt.net
Type: A
DNSthinkcarry.net
Type: A
DNSpresentcarry.net
Type: A
DNSchieffather.net
Type: A
DNScollegefather.net
Type: A
DNScollegeapple.net
Type: A
DNScollegebuilt.net
Type: A
DNSchiefcarry.net
Type: A
DNScollegecarry.net
Type: A
DNSoftenfather.net
Type: A
DNSalonefather.net
Type: A
DNSoftenapple.net
Type: A
DNSaloneapple.net
Type: A
DNSoftenbuilt.net
Type: A
DNSalonebuilt.net
Type: A
DNSoftencarry.net
Type: A
DNSalonecarry.net
Type: A
DNSmiddlefather.net
Type: A
DNStwelvefather.net
Type: A
DNSmiddleapple.net
Type: A
DNStwelveapple.net
Type: A
DNSmiddlebuilt.net
Type: A
DNSmiddlecarry.net
Type: A
DNSratherfather.net
Type: A
DNSmorningfather.net
Type: A
DNSratherapple.net
Type: A
DNSratherbuilt.net
Type: A
DNSmorningbuilt.net
Type: A
DNSrathercarry.net
Type: A
DNSmorningcarry.net
Type: A
DNSstrangefather.net
Type: A
DNShistoryfather.net
Type: A
DNShistoryapple.net
Type: A
DNSstrangebuilt.net
Type: A
DNShistorybuilt.net
Type: A
DNSstrangecarry.net
Type: A
DNShistorycarry.net
Type: A
DNSamountfather.net
Type: A
DNSamountapple.net
Type: A
DNSweatherapple.net
Type: A
DNSamountbuilt.net
Type: A
DNSamountcarry.net
Type: A
DNSweathercarry.net
Type: A
DNSthickfather.net
Type: A
DNSclassfather.net
Type: A
DNSclassapple.net
Type: A
DNSthickbuilt.net
Type: A
DNSclassbuilt.net
Type: A
DNSthickcarry.net
Type: A
DNSclasscarry.net
Type: A
DNSthinkmeasure.net
Type: A
DNSthinkdinner.net
Type: A
DNSpresentdinner.net
Type: A
DNSthinkafraid.net
Type: A
DNSpresentafraid.net
Type: A
DNSthinkcircle.net
Type: A
DNSpresentcircle.net
Type: A
DNSchiefmeasure.net
Type: A
DNSchiefdinner.net
Type: A
DNScollegedinner.net
Type: A
DNSchiefafraid.net
Type: A
DNScollegeafraid.net
Type: A
DNSchiefcircle.net
Type: A
DNSoftenmeasure.net
Type: A
DNSalonemeasure.net
Type: A
DNSoftendinner.net
Type: A
DNSalonedinner.net
Type: A
DNSoftenafraid.net
Type: A
DNSaloneafraid.net
Type: A
DNSoftencircle.net
Type: A
DNSalonecircle.net
Type: A
DNSmiddlemeasure.net
Type: A
DNStwelvemeasure.net
Type: A
DNSmiddledinner.net
Type: A
DNStwelvedinner.net
Type: A
DNSmiddleafraid.net
Type: A
DNStwelveafraid.net
Type: A
DNSmiddlecircle.net
Type: A
DNStwelvecircle.net
Type: A
DNSrathermeasure.net
Type: A
DNSmorningmeasure.net
Type: A
DNSratherdinner.net
Type: A
DNSmorningdinner.net
Type: A
DNSratherafraid.net
Type: A
DNSmorningafraid.net
Type: A
DNSrathercircle.net
Type: A
DNSmorningcircle.net
Type: A
DNSstrangemeasure.net
Type: A
DNShistorymeasure.net
Type: A
DNSstrangedinner.net
Type: A
DNShistorydinner.net
Type: A
DNSstrangeafraid.net
Type: A
DNShistoryafraid.net
Type: A
DNSstrangecircle.net
Type: A
DNShistorycircle.net
Type: A
DNSamountmeasure.net
Type: A
DNSweathermeasure.net
Type: A
DNSamountdinner.net
Type: A
DNSweatherdinner.net
Type: A
DNSamountafraid.net
Type: A
DNSweatherafraid.net
Type: A
DNSamountcircle.net
Type: A
DNSweathercircle.net
Type: A
DNSthickmeasure.net
Type: A
DNSclassmeasure.net
Type: A
DNSthickdinner.net
Type: A
DNSclassdinner.net
Type: A
DNSthickafraid.net
Type: A
DNSclassafraid.net
Type: A
DNSthickcircle.net
Type: A
DNSclasscircle.net
Type: A
DNSthinkwheat.net
Type: A
DNSpresentwheat.net
Type: A
DNSthinkanger.net
Type: A
DNSpresentanger.net
Type: A
DNSthinkalways.net
Type: A
DNSpresentforest.net
Type: A
DNSchiefwheat.net
Type: A
DNScollegewheat.net
Type: A
DNSchiefanger.net
Type: A
DNScollegeanger.net
Type: A
DNSchiefalways.net
Type: A
DNScollegealways.net
Type: A
DNSchiefforest.net
Type: A
DNScollegeforest.net
Type: A
DNSoftenwheat.net
Type: A
DNSalonewheat.net
Type: A
DNSoftenanger.net
Type: A
DNSaloneanger.net
Type: A
DNSoftenalways.net
Type: A
DNSalonealways.net
Type: A
DNSoftenforest.net
Type: A
DNSaloneforest.net
Type: A
DNSmiddlewheat.net
Type: A
DNStwelvewheat.net
Type: A
DNSmiddleanger.net
Type: A
DNStwelveanger.net
Type: A
DNSmiddlealways.net
Type: A
DNStwelvealways.net
Type: A
DNSmiddleforest.net
Type: A
DNStwelveforest.net
Type: A
DNSratherwheat.net
Type: A
HTTP GEThttp://weathercontrol.net/index.php
User-Agent:
HTTP GEThttp://classmatter.net/index.php
User-Agent:
HTTP GEThttp://classcontrol.net/index.php
User-Agent:
HTTP GEThttp://chiefapple.net/index.php
User-Agent:
HTTP GEThttp://chiefbuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvebuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvecarry.net/index.php
User-Agent:
HTTP GEThttp://morningapple.net/index.php
User-Agent:
HTTP GEThttp://strangeapple.net/index.php
User-Agent:
HTTP GEThttp://weatherfather.net/index.php
User-Agent:
HTTP GEThttp://weatherbuilt.net/index.php
User-Agent:
HTTP GEThttp://thickapple.net/index.php
User-Agent:
HTTP GEThttp://presentmeasure.net/index.php
User-Agent:
HTTP GEThttp://collegemeasure.net/index.php
User-Agent:
HTTP GEThttp://collegeafraid.net/index.php
User-Agent:
HTTP GEThttp://collegecircle.net/index.php
User-Agent:
HTTP GEThttp://thinkalways.net/index.php
User-Agent:
HTTP GEThttp://presentalways.net/index.php
User-Agent:
HTTP GEThttp://thinkforest.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 50.63.37.71:80
Flows TCP192.168.1.1:1033 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1034 ➝ 216.239.130.220:80
Flows TCP192.168.1.1:1035 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1036 ➝ 195.22.28.199:80
Flows TCP192.168.1.1:1037 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1038 ➝ 208.91.197.241:80
Flows TCP192.168.1.1:1039 ➝ 222.122.84.70:80
Flows TCP192.168.1.1:1040 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1041 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1042 ➝ 203.27.227.220:80
Flows TCP192.168.1.1:1043 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1044 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1045 ➝ 184.168.221.31:80
Flows TCP192.168.1.1:1046 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1047 ➝ 50.63.202.52:80
Flows TCP192.168.1.1:1048 ➝ 182.18.22.158:80
Flows TCP192.168.1.1:1049 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1050 ➝ 59.8.236.130:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 6572636f 6e74726f 6c2e6e65   eathercontrol.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6c617373 6d617474 65722e6e 65740d0a   lassmatter.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6c617373 636f6e74 726f6c2e 6e65740d   lasscontrol.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6170706c 652e6e65 740d0a0d   hiefapple.net...
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6275696c 742e6e65 740d0a0d   hiefbuilt.net...
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65627569 6c742e6e 65740d0a   welvebuilt.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65636172 72792e6e 65740d0a   welvecarry.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f726e69 6e676170 706c652e 6e65740d   orningapple.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   7472616e 67656170 706c652e 6e65740d   trangeapple.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726661 74686572 2e6e6574   eatherfather.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726275 696c742e 6e65740d   eatherbuilt.net.
0x00000050 (00080)   0a0d0a0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   6869636b 6170706c 652e6e65 740d0a0d   hickapple.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e746d65 61737572 652e6e65   resentmeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656d65 61737572 652e6e65   ollegemeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656166 72616964 2e6e6574   ollegeafraid.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656369 72636c65 2e6e6574   ollegecircle.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 616c7761 79732e6e 65740d0a   hinkalways.net..
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e74616c 77617973 2e6e6574   resentalways.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 666f7265 73742e6e 65740d0a   hinkforest.net..
0x00000050 (00080)   0d0a0d0a 0a                           .....


Strings
"
  
\
.
\
.
-E-
-0
-0010+-0
-0
CC
.00-+ 00-+ *00-+ 
.
.
-e-
. 
.
-e-
. 
\
 
0
0
-
,
>
..
- 
0
0
 
-
-
--
..p
]u
- abort() has been called
ADVAPI32.DLL
April
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
CONOUT$
- CRT not initialized
dddd, MMMM dd, yyyy
December
DOMAIN error
Ejjjj
EMicrosoft Visual C++ Runtime Library
E(null)
February
- floating point support not loaded
Friday
                                 H
         (((((                  H
         h((((                  H
HH:mm:ss
January
jjjjj
jjjjjj
July
June
KERNEL32.DLL
March
MM/dd/yy
Monday
mscoree.dll
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
October
Program: 
<program name unknown>
- pure virtual function call
R6002
R6008
R6009
R6010
R6016
R6017
R6018
R6019
R6024
R6025
R6026
R6027
R6028
R6030
R6031
R6032
R6033
runtime error 
Runtime Error!
Saturday
September
SING error
Sunday
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
Thursday
TLOSS error
Tuesday
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
Wednesday
WUSER32.DLL
                          
}0<-=#
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
<0|L<9
0t1HHt
[1agpodi cgem uunfbeja ljosad lcneboesdu wbopobk sfhidfmetc fpzoisj ptvefdjo qgleagizaz bcmoloc lcj hbjofcdu jugteij cnpefd fzti gziyu pngibi fqgowktunp ucar qjzugy ssgaouplya bpunutt lmhit oisjebeupk gcinem pggufdhe fambub rzbeaj hehhooem dbiarin licmuucj ild qyzosurce cqpiybgub eomkd jdeedagnu zoulpuzzt zuzm movu kutbibgmoa jllea zkcacm uaf jvaqouw mosnudflo jytunfmo nvuh nbtound pmjulbazob dna lcf fceciuspdi pbioul oaarlyotc zpozuqt ipcmuxy slewiujsu cplij gtruj sfalomoc qjcul dcboqx ljfec svlim lepjamgb djgalipp pmuluadzd hwmefcn suwcia ghdigpz vmgaffcalt adw jbmeosobco vei bofdo upinpog dcj bptooseii gfcuvltut izq jawvolm czpamtfiz bbjelrci cnqamiria iwlkinll nbme bkluburrid ltomocac xjwu aacj gslafngacx fnutoj ugolebi zval dtewiyjwis bmizugsv wdix emrdermqa rpdoatba eihcgoyl proaofuwo iipdlaqc rdjokwjuh smma pdfejm rbf zzue
1G:e\^
1#QNAN
1#SNAN
3.[IfA
}6.h(U
;7|G;p
8CSVhx
99//.<
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
`adjustor{
america
american
american english
american-english
`anonymous namespace'
AtJHt4Hu
<at,<rt"<wt
August
australian
.?AVbad_alloc@std@@
.?AVbad_alloc@stdext@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AVbad_typeid@std@@
.?AVexception@std@@
.?AVexception@stdext@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AV__non_rtti_object@std@@
.?AVout_of_range@std@@
.?AVoverflow_error@std@@
.?AVruntime_error@std@@
.?AVtype_info@@
bad allocation
bad exception
 Base Class Array'
 Base Class Descriptor at (
__based(
belgian
britain
canadian
__cdecl
cDR:X!FOd
cdtocd vpw uflis rgpuvek pzj heb wsiroej vjj rcinolc jlb intpeuagsg fsfuupsj kgletislen tmje jwpet ocadniang rvruthli pgzuu gpmicuioj tmculdi adffe sxgi nbbofsga bildufjfic htdoj ijtv yngeod rinro mbjigdlar bdgi mdse vgbac tfegovrlum eernne pdcawfsib comua ijcseawlhu qszod jgd soflua bbjiklka lloja liz ajll fuppaxfmea fbus fdel tonkar apfwellc dbsegoodc uncgol cepp glfu rfweyiyg bcgicc giwbaousd xhpifdsopm pdfodibg izjfubm bmt egfavagvka ouuov riljujko vwwoc ljruoetu dreci onaw lclaumhno nmc pukc lbele foubdoic lbjo lbsutcpu gooeefo xftel srtugiue ffmivbusu invruuuo lrsinzesul ccer dcbuxqj gdzu vnbovv gundaaxt jnfupwf ouesgal blni nkfeqaa virejilit aoopgf emexhocefn lrjuspmu lkvamunf gajuse
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
CHPjPV
class 
 Class Hierarchy Descriptor'
cli::array<
cli::pin_ptr<
CloseHandle
CLPjQV
__clrcall
coclass 
cointerface 
CompareStringW
 Complete Object Locator'
const 
`copy constructor closure'
CorExitProcess
C PjPV
C$PjQV
C.PjRV
C/PjSV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
CreateFileA
CreateFileW
@.data
dddd, MMMM dd, yyyy
December
DecodePointer
`default constructor closure'
 delete
 delete[]
DeleteCriticalSection
double
dutch-belgian
`dynamic atexit destructor for '
`dynamic initializer for '
__eabi
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
<ellipsis>
,<ellipsis>
EncodePointer
england
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
EnterCriticalSection
EnumSystemLocalesA
ExitProcess
extern "C" 
F0Pj.S
F4Pj/S
F8PjDS
__fastcall
FatalAppExitA
FDPjGS
FdPjOS
February
FhPj8S
FHPjHS
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileExA
{flat}
FlPj9S
FLPjIS
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
F<PjES
F@PjFS
F\PjMS
F`PjNS
F|Pj=S
F Pj*S
F,Pj-S
F(Pj,S
F$Pj+Sj
FPPjJS
FpPj:S
FreeEnvironmentStringsW
FreeLibrary
french-belgian
french-canadian
french-luxembourg
french-swiss
Friday
Ft,Ot	OtFOt#OuV
FTPjKS
FtPj;S
FXPjLS
FxPj<S
generic-type-
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
GetACP
GetActiveWindow
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetCPInfo
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDriveTypeA
GetDriveTypeW
GetEnvironmentStringsW
GetFileInformationByHandle
GetFileType
GetFullPathNameA
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserObjectInformationW
great britain
`h````
H./".c
-h(c`J
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
`h`hhh
HH:mm:ss
HHt*HHt
HHtiHHt
HHtXHHt
HHtYHHt
}$hj\}
HN(E$'J
holland
hong-kong
Hu\hL3E
?If90t
	If90t
InitializeCriticalSectionAndSpinCount
__int128
__int16
__int32
__int64
__int8
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
invalid map/set<T> iterator
invalid string position
irish-english
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
italian-swiss
<it|<otx<utt<xtp<Xtl
JanFebMarAprMayJunJulAugSepOctNovDec
January
jhhxNE
j,h(SE
j,h(UE
j@j ^V
j"X_^[]
K2dufconejub vfmaeh ivnm dpgislj mid earqpeji tcs uumjc gmb kebpag fofsanbjir fctel vtbogoln baaxce ippfedn xdcehccu vcvafaccez ixxleuc mrig xbj buox gdbizrgub vsjobo zltonofof rll dpbafdfub sfijaj xrb djz btr pifjewfq obygodlud ummu fqlorj uau gtliepngen jid ohzjeoajsc ffebap mrzuzia fafrisi fpguhd pgdetoggod plurojuud kemlofe dkvoorufel pdujocpi dfat scvesa tzu frsumjva pgzipzfeur lnn spradvjuj zdgeugd aruuo lpzujpoj szba kjsubmg lfy nrfice bjomob vamv prhogcmol jssuutajw rluuq brsozc yjej gibqehzh rcicac losb sopta tuzdi uvljagcg jsdodufmuc nna cjdut lvzudut bsojan aipvtajbot cfkastquvc srigis geviloa cbd rnak ouuggapeip evbubak kjsaoar zsebebmo bunmamfu dbvanayso mfnuztoj lffar l
KERNEL32.dll
[kJ3p5
LC_ALL
LC_COLLATE
LC_CTYPE
LCMapStringW
LC_MONETARY
LC_NUMERIC
LC_TIME
LeaveCriticalSection
Lgcmitk sobf nvmimbfuwc clocutu gcmuoc txfu pluuipajg uglec lhoqabidti ffzoga lnbopdi ccboud eje sgeudernut csofiklf osuk aoli dzk kclesggo snafe csgojbdomo xovq opasnok pdsujfibir dxbi oitav npjicgla brmeag lln zss gnieheevpm bbcugxal crxovp nvpu osg sjoup bcganlzo cufa rjritujim lcbordgo fbaep ukj clautuo mpxillju zlr lafnucbt crgicpmi blzosspo nns tdop bttaarlm ujugjaf nijlo cgteeaazv ovserocpz cuddi pldafyga nfyijjgu vubdagtgi bjab irslaegkl ltl duo omfmi fagfatdju nxeaad ujlnud hqfejzf bbr rrjaon cbdorjip dqmofsr tfaitap fvmae gmcirgd gshofvbiw titsiab mogedu yloneouu comvoplb god vwhuzgla lqruziqc cgvuei igj xyfed ltoabinsm qdukouizd irfafegp yuda qmtorbmi ptxi ale dptefsw rnwodbo kdzao uefmt gflozodm jecpalxmu jsjoppd qfvaz bbu babkujo fugje uurcfiglp rlkemtjoec sdecurcd
LoadLibraryW
`local static destructor helper'
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
map/set<T> too long
mceido jjcilbpa pnxiafdgio yilfep vnsenmt bpkag dvte pdjifoo yrafa jrjam lztigcb wodli fkjoonaix mcjebvw oddmi pdij cdcinm mfoja sdtica uasaaag zacyevace zpsex pcamuvvjo nigcokan ridi oebjkooq rwcen gfjancgecc qscojjci accgieu dns adtrau fcpeg gspabweled guufaviwu oup yceqiz tpgujk vblum mag oam jgoxarqr zsc hnfuppowiv gabaguaidg dsmebsd lppi soij uicwjub pasx jsmurbde zogwis wznecmfes nlu uscpej yrlib dsbem xvmor kwapau mamrihkba olgf ogkluc uteeo sdb vvjuz eewjsugsf efgimasw grfumlsa ojdfurpl svo xjlu fhzilvkadl jnyiqyric gjuo jkjomjupo rltiq gsd droatajmb pbe falc mcvijtr psyub sdpofs flvib psdoehuw nvmu pfluomcjem erqta bube fefw scojuw cefco frv gsb ubfpod dccun yptongbu tswehfpi csg bncuesf
MessageBoxW
{(.mhG
MIpQ+1|
MM/dd/yy
Monday
MultiByteToWideChar
 new[]
new-zealand
`non-type-template-parameter
norwegian
norwegian-bokmal
norwegian-nynorsk
Norwegian-Nynorsk
November
(null)
o7CbYn
oalgf dcp ljfo tpnudjdenu jtpuqjf ajrfiqp drujucmyep zwg ffwogblew latogadru dlpunu avzdik btsicfiz sbcejepimu exbmenda fqmatj akgnoeqz otb jon eljbe adeedx ecclag gpb fljob btve yurhe eddufenvti masbusz rzb ypupilv fjneebgcuf uycwueb idptesdsa gjcua vzladgpulr fbli aff zmeeep jdcivjz msu mgropvr crjapgjaj zaiqga qmr fgmuiupj xpoumocjl pcfemsobi gmaeemefsb npvusx dqqizspebp cnyullze etlidu kolnenzc mitdilngiq onajnecnuc gasb idl rbqigl tuojodicd edibpojwzo szbospn fad uzsmezcr gccetlbi qlgep losqa qcwuuosps ajfsap igiehovuou qbdeatbse fpriap oyipt rnuunotbji ljfefygofu edpnitla mgme xgjabbs ljp vijzub cbje gke yrfar nltoasl bhhii fjjenbog bsoxifl nrloobbfa tijfocx xftemf iundn ndu
October
`omni callsig'
operator
__pascal
PeekNamedPipe
`placement delete closure'
`placement delete[] closure'
portuguese-brazilian
PPPPPPPP
pr china
pr-china
private: 
protected: 
__ptr64
public: 
puerto-rico
}Q#9f	)
)q|GNf
QQSVWd
QueryPerformanceCounter
RaiseException
`.rdata
ReadFile
__restrict
^@rQEN+
RtlUnwind
S%*7IC
-s7Mtf
Saturday
`scalar deleting destructor'
September
SetConsoleCtrlHandler
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableA
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
short 
signed 
slovak
south africa
south-africa
south korea
south-korea
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
^SSSSS
static 
__stdcall
std::nullptr_t
`string'
string too long
struct 
Sunday
SunMonTueWedThuFriSat
swedish-finland
SystemFunction036
t3hP$E
t4<@t;V
tCHt(Ht 
`template-parameter
template-parameter-
`template static data member constructor helper'
`template static data member destructor helper'
TerminateProcess
tfht/E
tGhX$E
<?tG<Xt
t"hH$E
t hhEE
+t HHt
__thiscall
!This program cannot be run in DOS mode.
t:hLEE
 throw(
[thunk]:
Thursday
tI<A|2<P
<@tJ!~
tKhPEE
< tK<	tG
tK<_t<<$t8<<t4<>t0<-t,<a|
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
tM<it-<ot)<ut%<xt!<Xt
<\tM</tI
tp<@tl
.t|PVj@
tR99u2
t*=RCC
trinidad & tobago
t"SS9] u
<+t"<-t
Tt^HtTHtJHt
t]<@tS<Zt
t$<"u	3
Tuesday
;t$,v-
t VV9u
 Type Descriptor'
`typeof'
>:u8FV
`udt returning'
u-h`=E
u hTEE
__unaligned
UnhandledExceptionFilter
UNICODE
union 
united-kingdom
united-states
<unknown>
UNKNOWN
`unknown ecsu'
unknown exception
Unknown exception
unsigned 
UQPXY]Y[
URPQQh0
UTF-16LE
uZSSSP
`vbase destructor'
`vbtable'
`vcall'
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
vector<T> too long
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
virtual 
`virtual displacement map'
v:jr?{
v	N+D$
volatile
 volatile
volatile 
VPPPPP
`vtordisp{
`vtordispex{
VVVVVQRSSj
__w64 
wchar_t
Wednesday
WideCharToMultiByte
Wj@hxBE
wmbaywsiie jzduk blza yrp djsukii eppdoqgfe idjmoataj impjadlb djxacmv hescig blopett ufd ilosnu tati sjpiqbbib utbgifnnol ymsuz uspsocma ybca nnmo dfla mtdiquwla fis xddepbemou vkqeejf bmsanaff msojaotlg jlbivlof iacv slzady jkvuutglob clar ucoebamiv ojrjaddz ybroqmxovn rgojobpvo ueziuon pdd duv ugtku moidjuw gucxeb jesifoezs baorn byuejoozr pvbaobkvoe flmasdsej lftatbojab jmaibifp vtnaqcfas rfdubfrunc cgajivdnal jrcadccamz nxh dnbedby qdwufbba xsb gzjuabv jefraescr icn bsgunb uwwb tjilifgd yzladqpimr cdtuu ulrduy apfrebf qlh swta pjaukasl liclauoyfe rkdasrnob wfuuapi dgj ibdhuj legvuo podrimlte dqf leg iqfdeg sgodoltz ncjo pjia aidp cfnidqsi nrs jar qdofofesa dmged sjbubgiis hblegf jncofsru enezfil asclapmbez rsliqljalc asnrecmve joezl tec ouwdfuju rwjo gwfogreme zgdewh aoglailak ccb dzfu vfi gblascle vyxosro oU
WriteConsoleW
WriteFile
xppwpp
xpxxxx
x?Tcc&']
Y;=HtE
YPVhL/E
<z~$<A|
+z*$=j^
z{.Q@<
z	}	-R