· 6 years ago · Oct 24, 2019, 02:04 PM
1Installrite Analysis
2The installation performed the following activity:
3 4 files added
4 3 files deleted
5 2 files updated
6 22 registry entries added
7 0 registry entries deleted
8 11 registry entries updated
9
10 Installed 10/24/2019 4:51:54 AM
11
12All Files
13- Added Files
14 > C:\WINDOWS\msagent\msfnhu.com
15 > C:\WINDOWS\system32\msaueo.com
16 > C:\WINDOWS\system32\mshost.exe
17- Modified Files
18 > C:\WINDOWS\system32\config\system.log
19
20Registry
21- Added Registry
22 > HKU\S-1-5-21-839522115-796845957-2147137731-1003\Software\Microsoft\Windows\CurrentVersion
23
24\Policies\Explorer\Run
25 > COM Service
26
27 > HKLM\WINDOWS\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
28 > COM Service
29
30 > HKLM\WINDOWS\Microsoft\Active Setup\INstalled Components\{44CC0112-AB51-22EF-BA32-20AA12E6115C}
31 > StubPath
32
33 > HKCU\WINDOWS\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
34 > COM Service
35
36 > HKCU\Software\Microsoft\RAS AutoDial\Control
37 > LoginSessionDisable
38
39
40- Modified Registries
41 > HKU\S-1-5-21-839522115-796845957-2147137731-1003...
42 > HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch: Epoch
43 > HKLM\SOFTWARE\Microsoft\Cryptography\RNG: Seed
44 >HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Assist\{75048700-EF1F-11D0-9888-
45
46006097DEACF9}\Count
47
48
49Autostarts:
50- COM Service c:\windows\msagent\msfnhu.com
51- n/a (Not verified) c:\windows\system32\msaueo.com
52
53Ports:
54mshost.exe:1372 TCP winxpsp2:6666 winxpsp2:0 LISTENING
55
56
57Dump
58mail.hotmail.com
59mail.flashmail.com
60za.mx.aol.com
61ns1.ip-plus.net
62Explorer.exe
63
64winmm.dll
65advapi.dll
66wininet.dll
67
68C:\WINDOWS\System32\aueo.blf
69
70wwp.mirabilis.com:80
71
72Behavior:
73Opens a port
74Can create and send email
75
76
77a) Name of the detected file to test:
78
79b) What files were created / dropped? (if count is more than 10; just indicate the number)
80
81
82
83
84
85c) What files were modified / changed? (if count is more than 10; just indicate the number)
86
87
88
89
90
91d) What files were deleted / moved? (if count is more than 10; just indicate the number)
92
93
94
95
96
97e) What registries were created / dropped? (if count is more than 10; just indicate the number)
98
99
100
101
102
103f) What registries were modified / changed? (if count is more than 10; just indicate the number)
104
105
106
107
108
109g) What registries were deleted / moved? (if count is more than 10; just indicate the number)
110
111
112
113
114h) What autostarts did the program use? (if count is more than 10; just indicate the number)
115
116
117
118
119
120i) What process was used / corresponding port / URL/ IP address it was trying to connect to?
121
122
123
124
125
126
127j) What process and dependencies did it run?
128
129
130
131
132
133
134
135k) Is the program memory resident? What process is it using in memory?
136
137
138
139
140
141l) Does it exhibit malicious behavior? If yes, what malware/ grayware type and classification is it?
142
143m) What will be your recommendation or resolution or action?
144
145
146
147
148
149PiED: EP Section: CODE
150Bintext:
151- It queries system information: size of resource, lock it and load it
152- Get information: Disk Free Space
153- Calls for use32.dll: used for API
154- Has compilation for the dates
155- Has indications of Full disk and denied accessing of files
156
157
158ProExp:
159- Run rundll32.exe to open IExplorer.exe
160- Access: http://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=ex1
161- Checking the properties: open an API to be launched
162
163- Properties:
164 - winspsp2:1033
165 - Memory Dump:
166 browseui.dll
167 shdocvw.dll
168 urlmon.dll
169 wininet.dll
170
171
172____________________________________________________
173browseui.dll
174shdocvw.dll
175mshtml.dll
176urlmon.dll
177wininet.dll
178Microsoft Internet Explorer
179!This program cannot be run in DOS mode.
180hK^j,*09,*09,*09
181%j9-*09Rich,*09
182.text
183`.data
184.rsrc
185msvcrt.dll
186KERNEL32.dll
187NTDLL.DLL
188USER32.dll
189SHLWAPI.dll
190SHDOCVW.dll
191wex
192Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
193BrowseNewProcess
194IE-%08X-%08X
195MauiFrame
196IEDummyFrame
197CompatWarningFor
198DllRegisterServer
199rsabase.dll
200Software\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
201Signature
202System\CurrentControlSet\Control\Windows
203CSDVersion
204dw15 -x -s %u
205watson.microsoft.com
206Software\Microsoft\Internet Explorer\Main
207IEWatsonURL
208HKLM\Software\Microsoft\Internet Explorer\Registration\DigitalProductID
209HKCU\Software\Microsoft\Office\10.0\Common\LanguageResources\UILanguage
210Microsoft\Office\10.0\Common
211%s -h %u
212iedw.exe
213Iexplore.XPExceptionFilter
214IEWatsonEnabled
215jscript.DLL
216mshtml.dll
217mlang.dll
218urlmon.dll
219wininet.dll
220shdocvw.DLL
221browseui.DLL
222comctl32.DLL
223IEXPLORE.EXE
224-nowait
225-new
226-eval
227Browser Frame Start
228RSDS
229iexplore.pdb
230SSS
231PSS
232t'jP
233VSPVVV
234PPVh
235uDh
236ShP
237PGj
238VSSSj
239FHP
240PSSh
241GWSS
242Wh N
243tJj
244VSSSj
245PSSh
246GWSS
2474SVW3
248WWh
249SWW
250PVjJV
251tzh
252PSWh
253XPVj
254uMV
255SVW
256_except_handler3
257msvcrt.dll
258ADVAPI32.dll
259lstrlenW
260MultiByteToWideChar
261CreateEventA
262GetCurrentThreadId
263lstrcatA
264lstrlenA
265lstrcmpiA
266lstrcpyA
267GetModuleFileNameA
268FreeLibrary
269GetProcAddress
270LoadLibraryA
271GetVersionExA
272UnmapViewOfFile
273CloseHandle
274ReleaseMutex
275SetEvent
276WaitForSingleObject
277CreateProcessA
278lstrcpynA
279GetCurrentProcessId
280DuplicateHandle
281GetCurrentProcess
282CreateMutexA
283MapViewOfFile
284CreateFileMappingA
285WaitForMultipleObjects
286GetModuleFileNameW
287OpenProcess
288GetLastError
289SetUnhandledExceptionFilter
290LocalFree
291LocalAlloc
292GetModuleHandleA
293ExitThread
294GetStartupInfoA
295SetErrorMode
296GetCommandLineA
297QueryPerformanceCounter
298GetTickCount
299GetSystemTimeAsFileTime
300TerminateProcess
301UnhandledExceptionFilter
302KERNEL32.dll
303wsprintfA
304GetClassNameA
305GetForegroundWindow
306ShowWindow
307CreateWindowExA
308CreateMenu
309RegisterClassA
310DefWindowProcA
311LoadStringA
312DispatchMessageA
313TranslateMessage
314DestroyWindow
315MsgWaitForMultipleObjects
316PeekMessageA
317SendMessageA
318GetShellWindow
319USER32.dll
320StrStrIA
321PathFindFileNameA
322SHGetValueA
323wnsprintfA
324StrCpyNW
325PathQuoteSpacesA
326PathAppendA
327PathRemoveFileSpecA
328SHRegGetBoolUSValueA
329SHLWAPI.dll
330SHDOCVW.dll
331IExplorer.EXE
332DllGetLCID
333TFo
334iQG%
335DDDDLDD
336DDLLL
337DDDD
338DDLL
339DDD
340DDD
341DDLL
342@DDD
343@DDLL
344DDL
345DDLL
346DDDDDD
347DDDDDDL
348DDC{
349DDg
350DDL
351DDLg
352DDDL
353DDD
354DLLL
355DLL
356DLL
357DLL
358DDDA3s
359DDDDDL
360DDDD
361nWF
362hhVJB90$""2n
363mm[TJC-
364|j[TB-
365yjI9
366i^Udx
367yjJ$
368zdbo{
369yjC
370{b^cz
371paZcz
372vZ^i
373~cZcz
374lZci
375paXi}
376eQXg}
377`PHXg}
378\IHXg}
379fBB
380M?FXg}
381mJS
382R?7@Xg}
383W:7@Qg}
384M1.@Qg
385xow
386/'+8FX]s}
387zxov
388%@L]gs}ssicav
389%8LX]]]XUav
390%8@HHHI_~
391;;3CKN\PWW
392;;KKK
393jTD
394IIII
395IIIIIIIIIIIIIIIIIIIIIIIIII
396IIIIIIIIIIIIIIIIIIIIIII
397IIIISx
398IIIIIIIIIIIIIIIIIIIIII
399IIIIII
400IIIIIIIIIIIII
401IIII
402yfXKN
403IIIIIIIIIII
404dYA0$
405IIIIIIIII
406IIIIIIII
407IIIIIII
408IIIIIIr[
409IIIIIIe[n}
410III
411IIIIIIaVl
412IIIII
413IIIIINR]
414IIIIIII
415IIIIII`Vs
416IIIIIIIIIIIIIIIIIIIIIIIBR_~
417IIIIIIIWJg
418IIIIIIII=Jg
419IIIII7II>3Fg~
420IIIIIB(II<.Fg
421IIIII (III1,@p
422IIIIIII
423IIIIII
424%II11,O
425IIIII
426IIIIIII
427III
428IIIIIII
429IIIIIIIII
430IIIIIIIIII
431"4Qmw
432IIIIIIIIIIII
433"4Lhmws__
434III|IIIIIIIIII
435-@PPR`
436IIII|5IIIIIIIIIII
437IIIII|GIIIIIIIIIIIIII +H/
438IIIIII|vIIIIIIIIIIIIIIIIIIIII?;)
439III
440|ZIIIIIIIIIIIIIIIIIIIIIIIMUU
441IIIIIIIIIIIIIIIIIIIIIIIIIII??9?IIII
442_E)O____________M3__O?(((((_____G@__(&:FNQF((___J@_(.4-/<LVX?(__P
443;UW?__R+
444#6A?__\_CC
4457?_____ZZSSH%
446"0?_Z______ZZZKI??__Z__________ZY___Z____________YYZ__
447RqE
448gtI
449UwG
450dnF
451hcE
452gnF
453gXA
454NrF
455VxJ
456OxP
457UmM
458CvN
459vsN
460igB
461FkQ
462wwwwwwwwwwwwwwwwp
463DDLDD
464DLL
465DLL
466DDDL
467DDDO
468DDDDD
469wwwwp
470wwwwwwwwwwp
471DDDL
472wwwww
473wdW
474ppp
475toCq<<<<><><;;;;;;;;;;;;;;;;;;;;
476ln6n9p+q>?@@?@@??@????@
477m6'9oC>?A??A?AA?A???
478")pCBDADDAADAAAAr
479CBDEEEEEEEEEE
480gggg
481CDEEEEEEEEEE
482dggggdg
483nnoFGGGGGGGGGG
484d3fffeg
485&9+HGGGGGGGGG
486m$fg
487'psIIIIIIIII
4884:CGII+43g
489n:CGIIIIIIII
4909CIJJJJ+
491:CIJJJJJJJJ
492KLLLMLs
493osJLLuLuLLL
494&:ONNNNNNNMMMMNMMNNNNNNMNNNMNNN
495%&6666666""""""""""6)p,wwwwwwww
496ffffff3hhi
497,PPPPPPPP
498OPPPPPPPP
499nRQSSSSSSSS
500mmmmmmm
501)z.UUUUUUUU
502,....Qym
5039yUWWWWWWWW
504j#zWXWWTx
5054vTWXXXXWXXX
506!#xyVRv
507(R{YXYYYXXXX
508VXYYYYYYYYY
509ZZZZZZZZ
510x\^]]qoy]]]]]]]]
511mtvR
512a`a2a
513vxz\
514`bbbbbbbbb[
515y1ab
516ccc
517ccccc
518cccccccc
5198><qqqCCCC+++
520wdW
521ppp
522{.QLQIIIKGKGKGKGKGKG
523qq<BDDADDDDDArDDA
524o+qDEEEEEEEEEr
525+FEEEEGGEGE
526l6noFGGGGGGGG
5277'psGIIIIII
528KJJJIJI
52979CLLLLLL
530ONMMMM
5314wwws444
532+Owwwww
533kMMMMMMMMMMLQMM--P-
534--PPPP
535ddg
536PSSSSS
537mmmmmm
538SWUUUU
539XWWW4
540WWWWWW
541YYR
542zWXXXXX
543:TXYYYYY
544Rsz|/
545RYFoy
546a22222\zpmm
547bbb
548bbbbbbbbbbb
549<<<qqCCC++
550wdW
551ppp
552nsJ
553LNCN
554kkkkkk5yP
5551Voos
556oooooooo
557urD
558f3fff
559f3fff
560f3fff
561VS_VERSION_INFO
562StringFileInfo
563CompanyName
564Microsoft Corporation
565FileDescription
566Internet Explorer
567FileVersion
5686.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
569InternalName
570iexplore
571LegalCopyright
572Microsoft Corporation. All rights reserved.
573OriginalFilename
574IEXPLORE.EXE
575ProductName
576Microsoft
577Windows
578Operating System
579ProductVersion
580CompanyName
581Microsoft Corporation
582FileDescription
583Internet Explorer
584FileVersion
585InternalName
586iexplore
587LegalCopyright
588Microsoft Corporation. All rights reserved.
589OriginalFilename
590IEXPLORE.EXE
591ProductName
592Microsoft
593Windows
594Operating System
595ProductVersion
596VarFileInfo
597Translation
598IThis is being run in compatibility mode and not all features are enabled.$Internet Explorer Compatibility
599
600mode
601Internet Explorer
602ZuG
603wwwwwwww
604wwww
605wwwwwwww
606wwwwwwww
607wwwwwwww
608ppw
609wwwwwwww
610ppp
611wwwwwwww
612wwwwwwww
613wwwwwwww
614wwwwwwww
615zwp
616zwwwp
617wwwwwwwwwwp
618wwwwwwwwwwp
619wwwwwwwwwwp
620wwwwwwwwww
621wwwwwwwwwx
622wwwwwwwww
623wwwwwwwwp
624DDDL
625wwwp
626wwsw
627wwwwwww
628wwwwww
629wwwwww
630wwwwwx
631wwwwww7
632wwwwwww7
633wwwwwwww7
634wwwwwwww
635wwwwwwww
636wwwwwwww
637wwww
638www7
639wwwwwu
640Pww
641wwu
642www
643wwww
644www
645www
646wwwwwwwww
647wwwww
648wwww
649wwww
650wwww
651wwwww
652wwwwww
653wwwwwwww
654wwwwwwww
655wwww
656wwwwwwwwwwp
657wwwww
658wwwwwwwwwwp
659wwwww
660ssp
661wwwww
662wwwww
663wwwwwwwwwwp
664DDDL
665wwwwwwwwwwwwwwwwp
666DDLDD
667DLL
668DLL
669DDDL
670DDDO
671DDDDD
672wwwwp
673UUU
674MMM
675BBB
676fff
677www
678CCCCCC
679UUU
680MMM
681BBB
682fff
683www
684CCC
685UUU
686MMM
687BBB
688fff
689www
690eeeeee
691mQss
692fsyy
693CCCCCCCCC
694DDDD
695DDDDDD@
696" LLLDDD
697LLLB
698',lllh
699llll`
700",llb
701LBzr
702lllb
703lllLLD
704"""LlL
705DDD
706wwwwwwwwwww
707DDO
708DDD
709wwwww
710wwwwwwwwwww
711DDO
712DDD
713wwwww
714wwwwwwwwwww
715DDO
716DDD
717wwwww
718DDDD
719DDDDDD@
720" LLLDDD
721LLLB
722LLI
723llll
724",llb
725lllb
726l@LD
727DDD
728xpwwwwww{x0
729pwwwwww{x0
730xpwwwwww{x0
731xpwwwwww{x0
732wwwwww{x0
733wwwwwwwwwwp
734wwwp
735____________________________________________________
736
737
738Installrite:
739
740The installation performed the following activity:
741 1 file added
742 2 files deleted
743 6 files updated
744 32 registry entries added
745 0 registry entries deleted
746 24 registry entries updated
747
748
749All Files
750- Added (1):
751 - Perflib_Perfdata_444.dat C:\Documents and Settings\WinXP\Local Settings\Temp\
752
753- Deleted: none
754- Modified(5):
755 C:\Documents and Settings\WinXP\Cookies\index.dat
756 C:\Documents and Settings\WinXP\Local Settings\History\History.IE5\index.dat
757 C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\index.dat
758 C:\WINDOWS\System32\config\system.LOG
759 C:\WINDOWS\system32\wbem\Logs\wbemess.log
760
761
762Registry:
763-Added:
764 HKU\S-1-5-21-839522115-796845957-2147137731-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache
765 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\000\Control
766 HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
767
768
769
770
771Swen
772
773PEID: CODE
774ProExp:
775- Swen.exe
776 winload.exe
777- nxzz.exe
778______________________
779!This program cannot be run in DOS mode.
780Rich:
781.text
782`.rdata
783@.data
784.rsrc
785SVW
786YYP
787SVW
788SVW
789SSj
790SSj
791SVW
792t;PSh
793SVW
794jcY3
795tQh
796jIY3
797tIh@
798t1Sh<
799SSj
800SVW
801SVW
802SVW
803,SVW
804YYf
805SVW
806SVW
807SVW
8080SVW
809PSV
810dSVW
811SVW
812YYVVj
813YYP
814SSj
815WhP
816YYP
817PSW
818scj:W
819u:PP
820lSVW
821YY9u
822SVWj
823SVW
824tDj2
825YYj2
826YHt
827Hu!h
828YYh
829Ht"Ht
830YHt
831Hu(h
832YYj
833YHt
834Hu(hh
835YYj
836YYja
837tJj2
838tajP
839Hu(h
840YYjF
841YHt
842HuWjP
843tKh
844YYj%
845YHt
846Hu(hl
847tYj
848YHt
849Hu!h(
850YYj
851YHt(Ht
852Hu/h4
853YYj
854YHt
855Hu(h
856YYj
857YHt
858YYj
859YHt
860Hu(h
861YYj
862YHt
863Hu!h
864YYj
865YYj(
866YHt
867Hu!h<
868YYj
869YHt2Ht(Ht
870Hu6h
871YYj
872YHt
873Hu(h
874YYj<^V
875tch
876t%jA
877YYj2
878tJj2
879YYh
880YYj
881YHt
882Hu!h|
883YYV
884ht.A
885jxW
886YYjU
887t@jyW
888joW
889jpW
890jqW
891Hu,h8
892YYh,
893Ywa
894YYh
895YYj<
896YYjU
897YYh
898YYh
899SVW
900YHt
901YYj
902YHt
903Hu(hl
904YYj
905YHt
906Hu!hd
907YYj
908YHt
909YYj2
910YYj
911YHt<Ht2Ht(Ht
912Hu=h
913YYj
914YYjF
915Ht2Ht(Ht
916Hu6hd
917YYj
918YHt
919Hu(hP
920YYj
921Hu(hH
922YYV
923Ht2Ht(Ht
924Hu6h
925YYjA
926YHt
927Hu!h
928YYj2
929YYj2
930YHt
931Hu(h
932YYW
933YHt2Ht(Ht
934Hu6h\
935YYj
936ht.A
937YYj
938t8hL
939YHt
940Hu!h0
941YYj2
942YYj2
943YYj2
944YYW
945YYh
946YHt
947Hu(hh
948YYh(
949QQSVW
950jPh
951tAj
9524SVW
953SSj
954tDJt*Jt
955JuG
956SVW
957jnW
958tBj
959ht.A
960hEI@
961SVW
962jdh
963t$SSS
964SVW
965SSjdh,
966PPh
967VVS
968t"ht
969tRh
970t"ht.A
971SSSS
972SSSS
973SVW
974Vje
975PVV
976lSVW
977PSW
978SVP
979SSSS
980QQSVW
981HHtC-
982SVW
983YPWV
984SVW
985YYh
986t%SW
987SSS
988PVW
989SSV
990YPV
991SVW
992unP
993t6h/u
994SVW
995tXj W
996YYj
997YPV
998SVW
999uMh
1000YPj;
1001YPj
1002YPj
1003YPj
1004YPj
1005YYh
1006t2h5u
1007YYj
1008SVW
1009t*WV
1010SVW
1011HtKH
1012SVW
1013jWY3
1014uGh
1015SVW
1016PVj
1017VVV
1018SVW
1019SVW
1020SVW
1021SVW
1022SVW
1023SVWh
1024SVW
1025SVW
1026u)hT
1027trW
1028PVVh
1029VVV
1030SVW
1031PSSS
1032Pu7VW
10334SVW
1034tlh
1035SSSh
1036PShH
1037t4Ht
1038HuE
1039SVW
1040Pht
1041^Vhx
1042PVhp
1043PVhd
1044PVh\
1045Pht.A
1046SVW
1047YYjK
1048tcj
1049SVW
1050j.[SW
1051t~SP
1052tqj@V
1053uch
1054uRh
1055SVW
1056sSj
1057SVW
1058tbh
1059PSW
1060tYj
1061$SVW
1062SSj
1063tSVW
1064Qj@P
1065SVW
1066SWV
1067tVj
1068SSW
1069SVW
1070PhH
1071tdj\
1072Hu(h@
1073Ht"Ht
1074tij
1075Hu!h
1076tUj
1077Yt2j
1078Yt)j
1079PSVW
1080u%hL
1081SVW
1082PSh|
1083PShd
1084SVW
1085hl#A
1086Ph`#A
1087Ph0#A
1088PWh
1089SSh
1090t$Sh
1091Pjd
1092PWhp
1093t)HuVh
1094$ht"A
1095Phh"A
1096PSS
1097vh0"A
1098PSS
1099Sh "A
1100Pjd
1101YYj
1102hx!A
1103hl!A
1104t!hT!A
1105YYP
1106hH!A
1107Pht A
1108hh A
1109Ph0 A
1110Ph0 A
1111twh
1112YYS
1113Pjd
1114YYh
1115YYSh
1116SShT
1117PSS
1118Hu(h
1119YYh
1120Shl
1121^VSh
1122YYS
1123YYF
1124SVW
1125SSj
1126t(Ht
1127Hu,h
1128ht$A
1129hh$A
1130hP$A
1131Ph #A
1132Sh0#A
1133tVh
1134u?h "A
1135Ph@$A
1136hT!A
1137trS
1138Hu(h
1139YYh
1140Shl
1141uXh
1142SSh
1143tpjd
1144SSj
1145WSV
1146SVWUj
1147SVW
1148t.;t$$t(
1149VC20XC00U
1150SVWU
1151tEVU
1152tzVS
1153GIt%
1154t/Ku
1155GKu
1156GIu
1157GJu
1158WVS
1159GIt#
1160SUVW
1161PPPPPPPP
1162tlHt.
1163t>Hu
1164XSVW
1165Ww!j
1166YVj
1167YYh,
1168wBVSP
1169PSW
1170PSW
1171VSj
1172YVj
1173t:jtj
1174Yt)V
1175u?jtj
1176Yt&V
1177QSV
1178vXj
1179VWu
1180t9UW
1181QQS3
1182VWu
1183PSSW
1184PVW
1185SS@SSPVSS
1186t#SSUP
1187t$$VSS
1188UWV
1189HSVWh
1190u>Wj
1191YWu
1192ulSj
1193pD#U
1194SVW
1195NCu
1196SVW
1197SVW
1198PVh
1199WSV
1200u+Vj
1201SVWj
1202RAA
1203Wj@Y3
1204t7SW
1205VPj
1206VPV
1207VPh
1208VWuBh<
1209tPh
1210SVW
1211uFWWj
1212"WWSh
1213E WW
1214tfS
1215tMWWS
1216WWu
1217VSh
1218WVS
1219SVWu
1220PPPPPPPP
1221WVS
1222FGQPS
1223qMf
1224runtime error
1225TLOSS error
1226SING error
1227DOMAIN error
1228- unable to initialize heap
1229- not enough space for lowio initialization
1230- not enough space for stdio initialization
1231- pure virtual function call
1232- not enough space for _onexit/atexit table
1233- unable to open console device
1234- unexpected heap error
1235- unexpected multithread lock error
1236- not enough space for thread data
1237abnormal program termination
1238- not enough space for environment
1239- not enough space for arguments
1240- floating point not loaded
1241Microsoft Visual C++ Runtime Library
1242Runtime Error!
1243Program:
1244<program name unknown>
1245GetLastActivePopup
1246GetActiveWindow
1247MessageBoxA
1248user32.dll
1249H:mm:ss
1250dddd, MMMM dd, yyyy
1251M/d/yy
1252Dec
1253Nov
1254Oct
1255Sep
1256Aug
1257Jul
1258Jun
1259Apr
1260Mar
1261Feb
1262Jan
1263Saturday
1264Friday
1265Thursday
1266Wednesday
1267Tuesday
1268Monday
1269Sunday
1270Sat
1271Fri
1272Thu
1273Wed
1274Tue
1275Mon
1276Sun
1277SunMonTueWedThuFriSat
1278JanFebMarAprMayJunJulAugSepOctNovDec
1279CloseHandle
1280TerminateProcess
1281WaitForSingleObject
1282OpenProcess
1283ExitProcess
1284GetModuleHandleA
1285FreeLibrary
1286GetProcAddress
1287LoadLibraryA
1288Sleep
1289SetEvent
1290LeaveCriticalSection
1291EnterCriticalSection
1292ResetEvent
1293WriteFile
1294SetFilePointer
1295CreateFileA
1296SetEndOfFile
1297DeleteFileA
1298ReadFile
1299GetFileSize
1300FreeResource
1301LoadResource
1302SizeofResource
1303FindResourceA
1304GetModuleFileNameA
1305GetSystemTime
1306GetComputerNameA
1307SetErrorMode
1308GetVersionExA
1309GetWindowsDirectoryA
1310CreateThread
1311CreateEventA
1312InitializeCriticalSection
1313DeleteCriticalSection
1314lstrlenA
1315GetTickCount
1316CreateProcessA
1317GetDriveTypeA
1318GetLogicalDrives
1319FindClose
1320FindNextFileA
1321FindFirstFileA
1322GetFileAttributesA
1323CopyFileA
1324MoveFileA
1325CreateDirectoryA
1326GetTempPathA
1327GetShortPathNameA
1328KERNEL32.dll
1329CharLowerA
1330wsprintfA
1331PostMessageA
1332GetWindowThreadProcessId
1333GetParent
1334EnumWindows
1335MessageBoxA
1336CharUpperA
1337DispatchMessageA
1338GetMessageA
1339SetTimer
1340CreateWindowExA
1341RegisterClassExA
1342FindWindowA
1343DialogBoxParamA
1344ShowWindow
1345EnableWindow
1346GetDlgItem
1347GetDlgItemTextA
1348EndDialog
1349PostQuitMessage
1350DefWindowProcA
1351SetFocus
1352ReleaseDC
1353SetWindowTextA
1354GetClientRect
1355GetDC
1356UpdateWindow
1357IsDialogMessageA
1358PeekMessageA
1359CreateDialogParamA
1360ExitWindowsEx
1361USER32.dll
1362DeleteObject
1363Rectangle
1364SelectObject
1365GetStockObject
1366CreateSolidBrush
1367GDI32.dll
1368GetUserNameA
1369RegCloseKey
1370RegSetValueExA
1371RegCreateKeyExA
1372RegQueryValueExA
1373RegOpenKeyExA
1374RegEnumKeyExA
1375RegDeleteKeyA
1376RegDeleteValueA
1377ADVAPI32.dll
1378ShellExecuteA
1379SHELL32.dll
1380WSOCK32.dll
1381VerQueryValueA
1382GetFileVersionInfoA
1383VERSION.dll
1384LZClose
1385LZCopy
1386LZOpenFileA
1387LZ32.dll
1388RtlUnwind
1389GetStartupInfoA
1390GetCommandLineA
1391GetVersion
1392HeapAlloc
1393HeapFree
1394GetCurrentProcess
1395HeapReAlloc
1396HeapSize
1397GetCurrentThreadId
1398TlsSetValue
1399TlsAlloc
1400SetLastError
1401TlsGetValue
1402GetLastError
1403UnhandledExceptionFilter
1404FreeEnvironmentStringsA
1405FreeEnvironmentStringsW
1406WideCharToMultiByte
1407GetEnvironmentStrings
1408GetEnvironmentStringsW
1409SetHandleCount
1410GetStdHandle
1411GetFileType
1412HeapDestroy
1413HeapCreate
1414VirtualFree
1415VirtualAlloc
1416MultiByteToWideChar
1417GetStringTypeA
1418GetStringTypeW
1419GetCPInfo
1420GetACP
1421GetOEMCP
1422LCMapStringA
1423LCMapStringW
1424zuoz
1425CUSTOM
1426nnn%
1427fff3f
1428MAPI32 Exception
1429MS Sans Serif
1430&Apply
1431Cancel
1432An internal error has occurred in module mapi32.dll
1433In the edit box below, please enter your name as you would like it to appear in the "From" field of your
1434
1435outgoing message.
1436Your Name:
1437Please enter your email address. This address will be the address other people use to send email to you.
1438Email Address:
1439Please enter the name of your outgoing mail server in the edit box below.
1440SMTP Server:
1441Default mail account structure has a damaged table of contents. It is recommended to newly reconfigure
1442
1443your account records. MAPI32 needs these informations in order to be able to send and receive mail.
1444
1445Failure to do so may cause that some MAPI32
1446(required)
1447(required)
1448Enter the name you will use to log into this account.
1449Login Name:
1450Please enter the password for current account.
1451Password:
1452Type in the full name of your incoming mail server.
1453POP3 Server:
1454Retype password:
1455dependent applications (such as Outlook or Outlook Express) become non-functional.
1456Installing Update Pack
1457MS Sans Serif
1458XXX
1459zonealarm
1460zapro
1461wfindv32
1462webtrap
1463vsstat
1464vshwin32
1465vsecomr
1466vscan
1467vettray
1468vet98
1469vet95
1470vet32
1471vcontrol
1472vcleaner
1473tds2
1474tca
1475sweep
1476sphinx
1477serv95
1478safeweb
1479rescue
1480regedit
1481rav
1482pview
1483pop3trap
1484persfw
1485pcfwallicon
1486pccwin98
1487pccmain
1488pcciomon
1489pavw
1490pavsched
1491pavcl
1492padmin
1493outpost
1494nvc95
1495nupgrade
1496nupdate
1497normist
1498nmain
1499nisum
1500navw
1501navsched
1502navnt
1503navlu32
1504navapw32
1505nai_vs_stat
1506msconfig
1507mpftray
1508moolive
1509luall
1510lookout
1511lockdown2000
1512kpfw32
1513jedi
1514iomon98
1515iface
1516icsupp
1517icssuppnt
1518icmoon
1519icmon
1520icloadnt
1521icload95
1522ibmavsp
1523ibmasn
1524iamserv
1525iamapp
1526gibe
1527f-stopw
1528frw
1529fp-win
1530f-prot95
1531fprot95
1532f-prot
1533fprot
1534findviru
1535f-agnt95
1536espwatch
1537esafe
1538efinet32
1539ecengine
1540claw95
1541cfinet
1542cfind
1543cfiaudit
1544cfiadmin
1545ccshtdwn
1546ccapp
1547bootwarn
1548blackice
1549blackd
1550avwupd32
1551avwin95
1552avsched32
1553avp
1554avnt
1555avkserv
1556avgw
1557avgctrl
1558avgcc32
1559ave32
1560avconsol
1561autodown
1562apvxdwin
1563aplica32
1564anti-trojan
1565ackwin32
1566_avp
1567\StringFileInfo\%s\OriginalFilename
1568\VarFileInfo\Translation
1569Try to pull my legs?
1570IsDebuggerPresent
1571Process32Next
1572Process32First
1573CreateToolhelp32Snapshot
1574kernel32.dll
1575GetModuleFileNameExA
1576EnumProcessModules
1577EnumProcesses
1578psapi.dll
1579HEAD %s
1580RCPT TO: <%s>
1581QUIT
1582DATA
1583MAIL FROM: <%s>
1584HELO %s
1585\germs1.dbv
1586\germs0.dbv
1587CUSTOM
1588Content-Transfer-Encoding: base64
1589Content-Disposition: attachment
1590.exe
1591.zip
1592; name="
1593msdownload
1594compressed
1595Content-Type: application/x-
1596Content-Type: image/gif
1597Content-Transfer-Encoding: base64
1598Content-ID: <
1599<BR><BR>
1600Content-Type: text/html
1601Content-Transfer-Encoding: quoted-printable
1602Copyright %i Microsoft Corporation.
1603Content-Type: text/plain
1604Content-Transfer-Encoding: quoted-printable
1605Content-Type: multipart/alternative; boundary="
1606type="multipart/alternative"
1607Content-Type: multipart/related; boundary="
1608Mime-Version: 1.0
1609Content-Type: multipart/mixed; boundary="
1610X-ID:
1611Corp.
1612Corporation
1613from
1614comes
1615came
1616which
1617Internet Explorer
1618Windows
1619for
1620update
1621patch
1622package
1623pack
1624correction
1625corrective
1626security
1627critical
1628internet
1629important
1630these
1631the
1632that
1633this
1634Install
1635Apply
1636Use
1637Watch
1638See
1639Take a look at
1640Look at
1641Try on
1642Try
1643Taste
1644Prove
1645Check out
1646Check
1647FWD:
1648Upgrade
1649Pack
1650Update
1651Patch
1652Critical
1653Net
1654Latest
1655New
1656Last
1657Newest
1658Current
1659SUBJECT:
1660Client
1661Consumer
1662Partner
1663User
1664Customer
1665Commercial
1666NEWSGROUPS:
1667.net
1668.com
1669msdn
1670microsoft
1671msn
1672news
1673bulletin
1674confidence
1675advisor
1676updates
1677technet
1678support
1679newsletters
1680unknown
1681Microsoft
1682Support
1683Assistance
1684Services
1685Bulletin
1686Customer
1687Public
1688Technical
1689Center
1690Department
1691Section
1692Division
1693Security
1694Network
1695Internet
1696Program
1697Corporation
1698Microsoft
1699FROM: "
1700This update includes the functionality =
1701of all previously released patches.
1702computer
1703system
1704on your
1705code
1706executable
1707to run
1708malicious user
1709attacker
1710, the most serious of which could
1711allow an
1712from these vulnerabilities
1713maintain the security of your computer
1714protect your computer
1715help
1716continue keeping your computer secure
1717Install now to
1718vulnerabilities
1719new
1720newly discovered
1721as well as three
1722all known security vulnerabilities affecting
1723MS Internet Explorer, MS Outlook and MS Outlook Express
1724eliminates
1725resolves
1726fixes
1727%i, Cumulative Patch" update which
1728December
1729November
1730October
1731September
1732August
1733July
1734June
1735May
1736April
1737March
1738February
1739January
1740this is the latest version of security update, the
1741Content-Transfer-Encoding: base64
1742Content-Id: <
1743com
1744scr
1745bat
1746pif
1747exe
1748wav
1749midi
1750Content-Type: audio/x-
1751</BODY></HTML>
1752<BR><BR><BR>Message follows:<BR><BR><BR><BR>
1753to <B>%s@%s</B>
1754mail
1755message
1756<BR><BR><BR>Undelivered
1757<BR><BR><BR>Undeliverable
1758to one or more destinations.<BR>
1759to the following addresses:<BR>
1760the message returned below could not be delivered =
1761I wasn't able to deliver your message =
1762<BR>I'm afraid =
1763<BR>I'm sorry to have to inform you that =
1764<BR>I'm sorry =
1765<BR>Message from
1766<BR>This is the qmail program<BR>
1767<BR><BR>Hi.
1768" height=3D0 width=3D0></iframe>
1769<iframe src=3D"cid:
1770<HTML>
1771<HEAD></HEAD>
1772<BODY>
1773Mime-Version: 1.0
1774Content-Type: multipart/alternative;
1775boundary="
1776Notice
1777Report
1778Announcement
1779Advice
1780Letter
1781Failure
1782Abort
1783Error
1784Bug
1785User unknown
1786Mailer
1787Sender
1788Returned To
1789Message
1790Mail
1791Undelivered
1792Undeliverable
1793Returned
1794SUBJECT:
1795domain
1796server
1797home
1798your
1799user
1800receiver
1801recipient
1802client
1803Receiver
1804Recipient
1805puremail
1806america
1807netmail
1808freemail
1809yahoo
1810aol
1811bigfoot
1812rocketmail
1813bot
1814routine
1815program
1816daemon
1817robot
1818automat
1819engine
1820form
1821service
1822post
1823web
1824smtp
1825email
1826mailer
1827master
1828mail
1829System
1830Service
1831Delivery
1832Storage
1833Mail
1834Message
1835Email
1836Inet
1837Postmaster
1838Administrator
1839Admin
1840GET http://ww2.fce.vutbr.cz/bin/counter.gif/link=bacillus&width=6&set=cnt006 HTTP/1.0
1841ww2.fce.vutbr.cz
1842DELE %d
1843TOP %d 30
1844STAT
1845PASS %s
1846USER %s
1847showerror
1848autorun
1849X-ID
1850POP Server
1851Pass
1852Login
1853Counter Visited
1854yes
1855CacheBox Outfit
1856VicName
1857ZipName
1858Server
1859Email Address
1860Explorer XBaseBar
1861%s\swen1.dat
1862%s\swen0.dat
1863%s\nntpgroups.dat
1864%s\germs0.dbv
1865LIST
1866GMT
1867NEWNEWS %s %02u%02u%02u %02u%02u%02u
1868LISTGROUP %s
1869reply-to:
1870from:
1871POST
1872Error occurred
1873Memory access violation in module kernel32 at
1874RegisterServiceProcess
1875SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
1876Remote Connection
1877System\CurrentControlSet\Services\RemoteAccess
1878Windows Explorer
1879InternetCloseHandle
1880InternetGetConnectedState
1881InternetOpenA
1882wininet.dll
1883MAPI32
1884Invalid Email Address
1885Invalid Server Name
1886Passwords do not match
1887ack
1888atch
1889pgrade
1890pdate
1891nstall
1892nstallation
1893nstaller
1894delete
1895spam
1896.eml
1897.wab
1898.dbx
1899.mbx
1900asp
1901mailto:
1902Unfile
1903All Users
1904Default User
1905\All Users
1906WinMe
1907Win95
1908Win98
1909Startup
1910\Shell Folders
1911abcdefghjklmnorstvwxyz
1912Winnt\Profiles\
1913Documents and Settings\
1914\Start menu\Programs\Startup
1915Virus Generator
1916Magic Mushrooms Growing
1917Cooking with Cannabis
1918Hallucinogenic Screensaver
1919My naked sister
1920XXX Pictures
1921Sick Joke
1922XXX Video
1923XP update
1924Emulator PS2
1925XboX Emulator
1926Sex
1927HardPorn
1928Jenna Jameson
192910.000 Serials
1930Hotmail hacker
1931Yahoo hacker
1932AOL hacker
1933fixtool
1934cleaner
1935removal tool
1936remover
1937Klez
1938Sobig
1939Sircam
1940Gibe
1941Yaha
1942Bugbear
1943installer
1944upload
1945warez
1946hacked
1947hack
1948key generator
1949Windows Media Player
1950GetRight FTP
1951Download Accelerator
1952Mirc
1953Winamp
1954WinZip
1955WinRar
1956KaZaA
1957KaZaA media desktop
1958Kazaa Lite
1959Searching for installed components ...
1960Extracting files ...
1961Copying files ...
1962Updating registry ...
1963%s%s.exe
1964%s\%s.zip
1965%s%s.zip
1966This update has been successfully installed.
1967Software\Microsoft\Windows\CurrentVersion\Policies\System
1968DisableRegistryTools
1969regfile\shell\open\command
1970%s showerror
1971scrfile\shell\config\command
1972scrfile\shell\open\command
1973\shell\open\command
1974exefile
1975comfile
1976piffile
1977batfile
1978nntptmp.fl
1979\swen0.dat
1980NNTP Server
1981SMTP Display Name
1982SMTP Server
1983SMTP Email Address
1984SOFTWARE\Microsoft\Internet Account Manager\Accounts\%s
1985Default News Account
1986SOFTWARE\Microsoft\Internet Account Manager
1987Default Mail Account
1988Mirc Install Folder
1989[script]
1990n0= on 1:JOIN:#:{
1991n1= /if ( $nick == $me ) { halt }
1992n2= /.dcc send $nick "
1993%s\%s.exe
1994\script.bcp
1995\script.ini
1996\mirc.ini
1997\mirc32
1998\mirc
1999Software\Microsoft\Windows\CurrentVersion
2000ProgramFilesDir
2001Kazaa Infect
2002Dir99
2003DlDir0
2004\Transfer
2005DownloadDir
2006DisableSharing
2007\LocalContent
2008Software\Kazaa
2009SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
2010A -EP %s %s
2011WinRar.exe
2012-min -e -o %s %s
2013WinZip.exe
2014@ECHO OFF
2015IF NOT "%%1"=="" %s %%1
2016%s\%s.bat
2017This will install Microsoft Security Update.
2018Do you wish to continue?
2019Install Item
2020Software\Microsoft\Windows\CurrentVersion\Run
2021%s autorun
2022This update does not need to be installed on this system.
2023Microsoft Internet Update Pack
2024... by Begbie
2025Installed
2026[rename]
2027NUL=%s
2028%s\Wininit.ini
2029MoveFileExA
2030regedit.exe "%1"
2031%s\script.ini
2032germs0.dbv
2033germs1.dbv
2034swen0.dat
2035swen1.dat
2036nntpgroups.dat
2037PST
2038PDT
2039C:\WINDOWS
2040gkbpuoz
2041SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CJSMMV
2042C:\WINDOWS\nxzz.exe
2043abcdefghijklmnopqrstuvwxyz
2044ABCDEFGHIJKLMNOPQRSTUVWXYZ
2045rRR
2046QGG
2047wss
2048jhh
2049CBB
2050zqg
2051sss
2052ppp
2053MMM
2054UBFU
2055R@55BB
2056?I=+FU
2057WWx.FR
2058/ip?WWW
2059WWWW>5R
2060WWWWWx+B
2061WWWWWtF>
2062pi/i
2063eed
2064wwwww=B>
2065ppp
2066WWW
2067AWWWWW
2068$)wWWWW?li/""
2069^>WWWW
2070uAWW
2071AAD
2072xww
2073gAD
2074uee*))))00
2075||off
2076vvvqza
2077vvvvv>
2078vvvvvpq
2079WWW
2080dnzzzzzvpd
2081JHI
2082mlG
2083TTS
2084Lbd
2085tst
2086xFE
2087UUUUUUUUUUUUUU
2088UUU
2089UOOOOOOOOOOOOOOOOOOOOOO<
2090SOOOOOOOOOOO99
2091LSLL
2092SO9O99OO95
2093mSmb
2094mOO9OO
2095SO 99On(
2096AAA
2097AAA
2098S99999nO(((((((((((((((((
2099S9 O OnO((((((((b
2100x5bx(((
2101L{ { {ZOb
2102ZO(((((((((((((((hK
2103L{ 5r{ZOb
2104x5(((((((((((Khy
2105rxOOOOOOOOOOOOOOOOOO(n
2106L5 5 Oxxx2222+n
2107bN59ON5rNN5rNN5r N5rNN5*S
2108brO
21095O 9Nr999N5
2110N59ON
2111PNO
2112=5OON
2113bOO
2114ZNO
2115xxz
2116O P<5ZZZ
2117bzL
2118Z=NO<
2119=5ZOOPL
2120PbPL
21215r5r5r
2122::ZZZZZZZ
2123bzLzL
2124fff
2125www
2126UUU
2127DDD
2128Microsoft Corporation. All rights reserved.
2129<A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
2130info/cpyright.htm" TARGET=3D"_top">Terms of Use</A>
2131 |
2132<A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
2133info/privacy.htm" TARGET=3D"_top">
2134Privacy Statement</A> |
2135<A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
2136enable/" TARGET=3D"_top">Accessibility</A>
2137</FONT>
2138</TABLE>
2139</BODY>
2140</HTML>
2141R0lGODlhaAA7APcAAP///+rp6puSp6GZrDUjUUc6Zn53mFJMdbGvvVtXh2xre8bF1x8cU4yLprOy
2142zIGArlZWu25ux319xWpqnnNzppaWy46OvKKizZqavLa2176+283N5sfH34uLmpKSoNvb7c7O3L29
2143yqOjrtTU4crK1Nvb5erq9O/v+O7u99PT2sbGzePj6vLy99jY3Pv7/vb2+fn5++/v8Kqr0oWHuNbX
214455SVoszN28vM2pGUr7S1vqqtv52frOPl8CQvaquz2Ojp7pmn3Ozu83OPzmmT6F1/xo6Voh9p2C5z
21453EWC31mS40Zxr4uw6LXN8iZkuXmn55q97PH2/Yir1rbL5iVTh3Oj2cvX5Pv9/+/w8QF8606h62Wk
21463n+dubnY9abB2c7n/83h9Nji6weK+CGJ4Vim6WyKpKWssgFyyAaV/0Km8Gyx6HW57FJxicDP2+Tt
21479Pj8/wOa/wmL5wqd/w6V8heb91e5+mS9+VmLr4vD6qvc/b/j/Mbn/sTi9rvX6szq/tPt/9ju/dzx
2148/+n2/+74//P6/+3w8hOh/xOW6yCm/iuu/zWv/0m4/XTH/IXK95TP9qPV9bfi/tDn9tfp9OP0/93r
21499L3Izy6Vzj22/lrC/mfG/JvJ5JGntAyd6IbX/3zD6GzP/3jV/2uoxHqbqujv8g6MvJTj/2HF5pXV
2150606zz6Hp/63v/7j1/8Ps88b8/rbj5RKOkE2wr3OGhoKGhv7///Dx8V2alqvm4Zni1YPRvx5uVwyO
2151X0q2hLTvw8X10gx2H4PXkkuoV5zkoQeADZu7mmzIVEO7HIXbaGfLMPz8+97d2/Px7v///+bl5eHg
21524P7+/v39/fT09PLy8u7u7gAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
2153AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
2154AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwAAAAAaAA7AAAI/gCVCRxI
2155sKDBgwgTKlzIsKHDhxAjKgwiqs2kSJEgQfqyp2PHLxoxTmojSpTEkyglBrGYcU+el3n09PEDSFKg
2156mzclAfLTRw/MPV4gjTSZsmhRURchuXwUs88fSYIGubEiqyqAq1gBNLPiRlCgPz197tE4MojRswuD
2157JHX5UiagQILcNMtKl26zu3etuBgUaKcePXv0QIo0iSjaw8raROKYh6nbuFbmVpVlpbKby4Mya858
2158eWrlrV0l/fECWDBhw4hPimoJUw9NQVa0Yg6kk6dPmD9xt/Xi52kgKG4GCRLtpTjZNmZTQ5yktLXT
2159QFNDA+qJe2wkkgkrrmWrx4tv0X6M/gvFrnzh6uaO+wCKOhzs7TzWyUesyDom7z9//EAKOh51eYKK
2160sdWWH1D15cd78J12GFJKufRXcfwNNtR/ANYXE006UfdSfBQq1lxM3fFHWFlojRBCCA5goMMK5y3V
21611B879VGdUMlRqIxaG7kUmHEikVTjQyuAcGIGDmSQwQUYzPBAA1UIKJMfUCI4Vhs2EjTJKrWYwogp
2162mXSxY0iTTLhQAC2ocKIDHGywgAwYWPDAm3AeIIVztr3E1FiFVSnQJLXc4ksxuujyiy6npNGFYBKK
2163WRAzKZipAgkp8ACCAyLg0MClDcD5ppIUVNCFFDL1oSF8Qvn3nyi8+KIqMH8aQwwx/66EMQcoVQxG
2164mI/KBEBCCCSo0MIPLJSJwA6YFvsmBlFkYgopUTxwgQ8XXGBBBRUA0QUXeJp6qi2r2rKLLcAU42qs
2165WIRhR623YpdDNM4wQ0IOInggrwfFNoCDDl20wooqqaSCCil3SHCBBgQXnAGbFmCAgQMkBKDnLsMU
21664wswvPCySy3DuLpJGFiY4YodX6RrUhnOIFDDvPNeqkkXfKzCyssv8+svwM5uYPPNONusAZszEEEE
2167GoooQsfQdRRdxyJII83I0ow04nQjjkTtCB5cVN3KMBEXA8wuFbMC6Cu5jIJFLsG4oonIQeQQQw4o
2168a5KsI6moogrMMMvt77+kCPzB3v589+03BxdQ0IFyotyCdTFap7I1K7Z4YskmcIwSTC+9KMHGSD6S
21690AIJHkRxByekkIJKv3LPXbfMeOddgQmst+466xoAIUEEEUzAQNBD02H00UkvwnTTT0s9ddV4ZPEK
21701hH/qTUnlyDyRi659BJMMLiEgrkoQSwTAjMefPIJ6KKPHnfppfeLCt6cCDFDmjT8AMP7MJywwQW0
21711187Aco5osUYyGNtjC+ccFwhzuCK6U0OF2uoQht8FAMEoMADnfge+M7Xrwpa8HyhI0X6JGCwDGhg
2172fvYLoe1wRzSj9c53THsa1KRGNS6oYQxZ0AXyjKGLUlzCEoeIQxjIRjnKTYESC/7EnjJyYAIRRMF7
21734Auf+Cp4vtRxghNOiEAHjxTC+k3gfsp5ghPSAIqMBeoUlkjEIeYgBzjwEBdonEIOgmgWSDlgC0h8
2174YgabSEcncuITUZQBwYxERftRYAIToEDtbie0EhbthL9TofBa6IT9jeEVgQpUJcZoCDEUcHqUw8UU
2175ysBGZZQgBAvAgSfimMQMmjJ0T/SeGiKgRw3w8QKz+2Mgp/UALKamC1FYwha1AElJzkEMYiDb5HqB
2176wE2SRIjR0MEIGoCJUUqwlKd84h0/4QlMRKACezQSLAM5A2pR6wF/JGTudofIFAaPhVW7AxWooIX9
2177ZSELv4hnJYA5CjQScw1rUP/jMQeCgA/gQA2ecOYzpUnQaVKzmtfM5pEkMIFpebMCtZwA/lJTBR88
2178YQlRcIITQBHPeNrhCEcwQhPQmM8EALEkAwnBDTBAhWYG1HukTCVMD4oJTBDBAgrNAEOnZYE/vomh
21794jQk75KWyHNGrYWO0KUT1tlOWnRUCUdQQhOaoIQ12GEKsVCgEAVSAge88RIufelMxxrQal7iEkLg
2180oCv5uFOffvOPE0XMMvjggy74IAoZ3UI8aYEEJUh1CkoggxIOUIbCbFUZyczADM4K1rI69rHVxARj
2181kyDFtRppp9OawR8pAFQS6s6EvSuq0xZZNS444gkZ1SgVQkELWvjMr1QlQgT+pgALG+yTIDrgwAPo
2182wFiwhtWxNZUsYxVBWYX6YAYT0CwgHwDRB0i0PNGoghTsCoQoaEIYQhCCz7ZLhCYoIAdD+ZEyQqAB
2183C4xBEb09a3Brmt5LBE0RWYiAB/mo2EBSoJvfdG5QP3vI0JpztOgsLR8y8QTU4jUK2U2wEIagBAWU
2184AQy3JcgIUqSF97b3wu9VhCXQwErLKpYCDvXmmygQV+UEQLpScKUPfACEFjuBCGuAhQ4gXBLxIjZa
2185QrBEhtGL3rPyOMOWCHIiOkxfCzT0oc2lwH7J6d+lKTLAVfPIdAu8hCUAwQlCIIMBikAJCEeYIMm4
2186gAxmkIggB3nHOzazJcb+QIXZ6bHIIPZmT0FMYj2RyUw50EEZRIAASnzheoctSJEekIgyq/nQalaE
2187E2QXAYHlFANx1iyILYDcJYOWqP9d4VFLi62PgEQkGAl1mI5p44HcYMxoQISqC21oIYcxDUuowOwk
2188IAMOTDEDGAAnBR5gARyAE5Al1pMytIM5UiuEBxWwQBIOoepmO1sRd/BBBWgnMGo9a758xECmcOBr
2189QE5Av55lMqadbNThldYjX/h0qEVyvVIDiFpEOIS85b3qOjBBBrODgL4foCZoWVsG2cZAt5fL7ToL
2190WyAVWeAxA42QScjgAkQoRCHmrYhGgDAC+s54AjbAAQ4s4GDeFHOuvf3/ABwMQBgiUHK4L620TJP2
21913J7WSEhG1MmJRKILsJzDxBfxhfLWL+MZn4AGOm5rgj2cWrJ8wAB2sAMRFEMYBtcTRUpCdXcbZDV8
2192sIAExoAHHuA7At2sYv3Q5PEOQmvXTE/7DlCu8kLyd6gtJzeANw3zPaRb5uwOIkoV0gY2SNsCgG+0
2193DFJwJFhWMbkDK7qHRcD4xjMeBxMoQAGEHYSpWz0hPlhANHxggWtyYBnMQAYIKvBwCZj+9GCHqAUc
2194kFMdOF4EOzBAAXoA2JX3d9zAm7u5oxxzW4164doaiAM0rwwU0IAHz4hGAEDfAjH74PTQn4G0EpAA
2195Z9HX9Y03wAEKcIAB/oDAYQc/CQkcEIBoPAMGzoDBM2KwfGa0QAMXOBLg5y8B6V/gAVNowhQogIEV
219661kEDXAAPdADTVAJaKBjtgd3KCR3mrZ7nWZ36kZzx0QIV5AQGNAC5Xd+x6B+7Md8KYBN0oZkziIt
2197E4AAKTAACtBQ8ZIA3NcBKrAMMRB+RfEAzLAM0aAMz/ACLwANyrcMyNACKXABCwA40VKEFPBwRtYE
2198cjAHhmAEU5AAAzgFYjAHrHZmCVhODPhyvAeBtkJzNUYIs5AQNLgM5VeBV9CDoQeEIZABICADbviG
2199FBAtRqYAzCAQAVACOSAACFACMngYFqACNRgAgiiIy+CDLQCEJCAD/yWgAV7ViHF4ATOQAFMABxI3
2200cWM0B6tWhQjoduIWd7nXgC20hXfHbkOBPRSYECFgAchQg4VYiMyQhikAAjdwAStgAydyIm1yARVA
2201AQXQASvQhzYSAA2AAav4iq/4g0AYiyRwATRQAiqgAggwAxYgA7t4AAcQAjcIjBTSAgYwAySADOB4
2202iMkoi7uCAQuQJBYgZj3FfQOwDNpYJSnQAROAAZozjuS4AAsAfzLgAGzyACzYfXX4jlVSAmVAfQ+w
2203MCRgAyRAAvhIMCmCXNtXAAYQAu4okHryAzaAARNgjQYJJxNAfRF5AAaQAy2QjRYpdWBQBV2QawrA
2204gpLHfQpgAA1ggiMrYJInKWxIsRhfUAU82ZMj0Iwr8AM3qY3E9ntVV3lDWSUBAQA7
2205R0lGODlhDAAMANUAAP////f3//f39+/v9+/v797m987W787W5sXW5rXF76295qW975y175St75St
22063pSlzoyl1oSl5oylzoycxXOU3nOMxWOM5mOM3mOE1lqE3mOEvVKE1lp7xVJ71lJ7zlJ7xVJ7vUp7
2207zkpzzkpzxVJzrUprvUJrxUJrvUJjtTpjtTpjrTparTpapQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
2208AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwAAAAADAAMAAAIjAABAAhwwMGFCxAQ
2209CACwkICDDBYSLGjQwQEBhg8zDBAIYIEIBwIQdLjAoOOFgSFMIICwIUMEAxQwCBxhAgKHDh5C6DQA
2210IIGJEyA4fPAwYoQCAAVKoEgBQsKJEidQ8CyRYumDA1VTqNBQQYXXFQofsPB6AIAKFiweNBTLoiza
2211BxcFCjgwgQSJCQcWCggIADs=
2212</FONT></TD></TR>
2213</TABLE>
2214<BR><BR>
2215<TABLE BORDER=3D"1" CELLSPACING=3D"1" CELLPADDING=3D"3" WIDTH=3D"600">
2216<TR VALIGN=3D"TOP">
2217<TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
2218ALIGN=3D"absmiddle" BORDER=3D"0"> System requirements</B>
2219</FONT></TD>
2220<TD NOWRAP><FONT SIZE=3D"1">Windows 95/98/Me/2000/NT/XP</FONT></TD>
2221<TR VALIGN=3D"TOP">
2222<TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
2223ALIGN=3D"absmiddle" BORDER=3D"0"> This update applies to</B>
2224</FONT></TD><TD NOWRAP>
2225<FONT SIZE=3D"1">
2226MS Internet Explorer, version 4.01 and later<BR>
2227MS Outlook, version 8.00 and later<BR>
2228MS Outlook Express, version 4.01 and later
2229</FONT>
2230<TR VALIGN=3D"TOP">
2231<TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
2232ALIGN=3D"absmiddle" BORDER=3D"0"> Recommendation</B></FONT></TD>
2233<TD NOWRAP><FONT SIZE=3D"1">Customers should install the patch =
2234at the earliest opportunity.</FONT></TD>
2235<TR VALIGN=3D"TOP">
2236<TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
2237ALIGN=3D"absmiddle" BORDER=3D"0"> How to install</B></FONT></TD>
2238<TD NOWRAP><FONT SIZE=3D"1">Run attached file. =
2239Choose Yes on displayed dialog box.</FONT></TD>
2240<TR VALIGN=3D"TOP">
2241<TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
2242ALIGN=3D"absmiddle" BORDER=3D"0"> How to use</B></FONT></TD>
2243<TD NOWRAP><FONT SIZE=3D"1">You don't need to do =
2244anything after installing this item.</FONT></TD>
2245</TABLE>
2246<TABLE WIDTH=3D"600"><TR><TD><FONT SIZE=3D"2">
2247Microsoft Product Support Services and Knowledge Base articles
2248can be found on the <A HREF=3D"http://support.microsoft.com/" =
2249TARGET=3D"_top">Microsoft Technical Support</A> web site. =
2250For security-related information about Microsoft products, please =
2251visit the <A HREF=3D"http://www.microsoft.com/security" TARGET=3D"_top">
2252Microsoft Security Advisor</A> web site, =
2253or <A HREF=3D"http://www.microsoft.com/contactus/contactus.asp" =
2254TARGET=3D"_top">Contact Us.</A>
2255<BR><BR>
2256Thank you for using Microsoft products.<BR><BR></FONT>
2257<FONT SIZE=3D"1">Please do not reply to this message. =
2258It was sent from an unmonitored e-mail address and we are unable =
2259to respond to any replies.<BR></FONT>
2260<HR COLOR=3D"Silver" SIZE=3D"1" WIDTH=3D"100%">
2261<FONT SIZE=3D"1" COLOR=3D"Gray">The names of the actual companies and =
2262products mentioned herein are the trademarks =
2263of their respective owners.</FONT>
2264</TD></TR></TABLE>
2265<TABLE WIDTH=3D"600" HEIGHT=3D"45" BGCOLOR=3D"#1478EB">
2266<TR VALIGN=3D"TOP">
2267<TD WIDTH=3D"5"></TD>
2268<FONT COLOR=3D"#FFFFFF" SIZE=3D"1"><B>
2269<A class=3D'navtext' HREF=3D"http://www.microsoft.com/=
2270contactus/contactus.asp" TARGET=3D"_top">Contact Us</A>
2271 |
2272<A class=3D'navtext' HREF=3D"http://www.microsoft.com/legal/" =
2273TARGET=3D"_top">Legal</A>
2274 |
2275<A class=3D'navtext' HREF=3D"https://www.truste.org/validate/605" =
2276TARGET=3D"_top" TITLE=3D"TRUSTe - Click to Verify">TRUSTe</A>
2277</FONT></B>
2278<TR VALIGN=3D"MIDDLE">
2279<TD WIDTH=3D"5"></TD>
2280<FONT COLOR=3D"#FFFFFF" SIZE=3D"1">
2281©
2282System requirements: Windows 95/98/Me/2000/NT/XP
2283This update applies to:
2284- MS Internet Explorer, version 4.01 and later
2285- MS Outlook, version 8.00 and later
2286- MS Outlook Express, version 4.01 and later
2287Recommendation: Customers should install the patch =
2288at the earliest opportunity.
2289How to install: Run attached file. Choose Yes on displayed dialog box.
2290How to use: You don't need to do anything after installing this item.
2291Microsoft Product Support Services and Knowledge Base articles =
2292can be found on the Microsoft Technical Support web site.
2293http://support.microsoft.com/
2294For security-related information about Microsoft products, please =
2295ecurity Advisor web site
2296http://www.microsoft.com/security/
2297Thank you for using Microsoft products.
2298Please do not reply to this message.
2299It was sent from an unmonitored e-mail address and we are unable =
2300to respond to any replies.
2301The names of the actual companies and products mentioned =
2302herein are the trademarks of their respective owners.
2303<HTML>
2304<HEAD>
2305<style type=3D'text/css'>.navtext{color:#ffffff;text-decoration:none}
2306</style>
2307</HEAD>
2308<BODY BGCOLOR=3D"White" TEXT=3D"Black">
2309<BASEFONT SIZE=3D"2" face=3D"verdana,arial">
2310<TABLE WIDTH=3D"600" HEIGHT=3D"40" BGCOLOR=3D"#1478EB">
2311<TR height=3D"20">
2312<TD ALIGN=3D"left" VALIGN=3D"TOP" WIDTH=3D"400" ROWSPAN=3D"2">
2313<FONT FACE=3D"sans-serif" SIZE=3D"5"><I><B>
2314<A class=3D'navtext' HREF=3D"http://www.microsoft.com/"
2315TITLE=3D"Microsoft Home Site" target=3D"_top">Microsoft</A>
2316</B></I></FONT>
2317<TD ALIGN=3D"right" VALIGN=3D"MIDDLE" BGCOLOR=3D"Black" NOWRAP>
2318<FONT color=3D"#ffffff" size=3D1>
2319<A class=3D'navtext' href=3D'http://www.microsoft.com/catalog/' =
2320target=3D"_top">All Products</A> |
2321<A class=3D'navtext' href=3D'http://support.microsoft.com/' =
2322target=3D"_top">Support</A> |
2323<A class=3D'navtext' href=3D'http://search.microsoft.com/' =
2324target=3D"_top">Search</A> |
2325<A class=3D'navtext' href=3D'http://www.microsoft.com/' target=3D_top>
2326Microsoft.com Guide</A>
2327</FONT>
2328<TD ALIGN=3D"right" VALIGN=3D"BOTTOM" NOWRAP>
2329<FONT FACE=3D"Verdana, Arial" SIZE=3D1><B>
2330<A class=3D'navtext' HREF=3D'http://www.microsoft.com/' TARGET=3D" top">
2331Microsoft Home</A> </B>
2332</FONT>
2333</TABLE>
2334 <IMG SRC=3D"cid:5897421" BORDER=3D"0"><BR><BR>
2335<TABLE WIDTH=3D"600"><TR><TD><FONT SIZE=3D"2">
2336SZDD
23370.abnorm
2338al.com
2339-62.clie
2340nt.attbi
234179-mx.xd
2342sl.tisca
2343li.nl
2344kdd.ne
2345t.hk
2346boukir&
2347-1-4-ppa
2348ris.a
2349rim~
2350q cs2
2351.byu.edu
2352gulli
2353ver.frq iwl-0
2354aif
2355ne.jpq lp
2356ha.webus
2357argos
2358.sae.g
2359royo
2360o{rgq sics
2361#urelia.
2362dei
2363"bal
2364drick.bl
2365ic>5racka
2366.rz.uni-
2367augsburg480U3nD
2368bast
2369chpoly.a
2370P0zB0bsnewv
2371".twB0
2372eech.fer}nb1hagenn3
2373ias.ipca2
2374tuebin
2375blob.
2376linuxfr
2377bolo.na
23780alln3
2379Clogivis
2380ion>4ossi
2381x.inf
2382ka2kie
2383Dut
2384thead.cy
2385bertr
23863po.broo
2387#cl 190.|d
2388fdl.w
2389Ohart
2390nCaD0
2391rbo<3.esp[ci
2392hlde.
2393his
2394Anc
23950.wol
2396kluw
2397wsgro
2398uplE(P-
2399!.]rreo.u
2400vigo
2401Awe
2402e.wc
2403$cypWres
2404ld@n
2405!davi
2406Pmswoft
2407"ddt80Ym
2408Tejasear
24090wu-w/
24100mind
2411spr
2412dia?na.bcnz0
2413dFPR@rPmi
24140alrea
2415Sogwood
2416=p0dp-
2417Sax
2418@syr
2419tv380ltat
2420Pm.r
2421ibm3.gk
2422o1ep30
2423l.kyoto-
2424!eg`nbfb
24251.eur
2426eed1a0cenEs
2427PdFc
2428dgui
2429&fid
24300lF@y
2431.idc.k
2432Pody
2433Porunl
24342C@um
2435ovPa
2436creebs`@s
2437i=0ct
24387frmsug
24393gr-gw
2440viwtp/pmic]0Z
2441@gigag@
2442Qsp0
2443peke
2444lauda
2445aeP
2446pC@.]p
2447glu
2448P?affrc.dP
2449grafTpa2ma
2450ppev
2451;1l'0mi
2452!gNEPg.u
2453@kab
2454gwd
2455`wdm3h_66-59
2456w.gt
2457Pnec
2458ermes1^1
2459hs-brem
2460host
2461.poool8
2462!htsr
2463Z0nbhu
2464ega
2465ghum
2466Ale
2467t rg~ 81-5
2468@bx.pr
2469Chat.
2470fidA
2471al`a
2472e.iWrk
2473Hhoivat_PahfRyi
24740pdata
2475rJ;0t
2476AA.rgv
2477tSsunbAA4a2r
2478oJ0o1AAsun2
2479stZ@
2480boch
2481fh-ggel
2482w ch
2483isgnt5~
2484!way
2485`uhPlace$
2486&main.%g,pe
2487fro
2488"miz
2489Asa
2490sk.cat
24912@eGPhok
2492pei
2493pjy
2494CPzis=
2495wildaun2
2496ncag
2497#nept3pbe
2498ayb
2499bkD
2500qnb
2501vcinc
2502cvi
2503bej
2504caiw
2505@ibsur`
2506cdp
2507cPa(
2508oCfc_
2509dr.@p'
2510tu-d@
2511ssu
2512emn
2513gam
2514gci*Q
2515gCdb
2516hanya
2517htwm~
2518inwa
2519itc
2520Peyc
2521v.sovam
2522konkuk
2523leiv
2524ouis
2525lsum
2526luc
2527,{Gdth.
2528vestav.
2529mxl
2530ncu
2531phoe
2532nix
2533ortaq
2534Pma.5
2535ram
2536kpnqw|
2537hr-S
2538sav
2539Cehn
2540gapa
2541ssn
2542@ra-l
2543tl(@ib%
2544Cohg
2545riax
2546CuG-il
2547b0v-na
2548G%tb
25492^IQ-yor
2550k3od3A\
2551Qive
2552cm4p
2553.ctrl-c
2554ntp
2555serv
2556svr2
25570-exG
2558odSig!p
2559n>Ph
2560111.ov#dn6n0bi#b.b
2561RvC
2562snmp_en2-l
2563foJ1-h
2564ufQ$o
2565kap
2566pwr'.wr
2567GApcp
2568waldlk
2569pea
2570peewe
2571ef`k
2572DPel<
2573@wqoswe
2574g-adr
2575Flo
2576rait*
2577y.dvg
2578geek3
2579nqp
2580r1.wm
2581ebo
2582`GAr
2583egul
2584wpafqbS
2585rtco
2586hUsh
2587.mfn
2588'`hsOS
2589sb/s004G0t
2590c_lub.c
2591qwB
2592outl
2593psp
2594tkar
2595jek>
2596snoopy
2597.bndl
2598#so?t-mod0
2599rparS
2600q.dk>
2601~u3tabloi|
2602Qlo
2603OPm
2604tta
2605rge
2606p.pdx.r
2607easyh'
2608tig
2609ur.v
2610hpc
2611oeh-
2612fic
2613thsKc5& u
2614Ayi
2615ufP
2616bul
2617aeD
2618vulk
2619euv-f
2620furt-oN
2621wzKpr
2622chno
2623`bm.v
2624qwix
2625ww.a
2626focal$
2627pn@%p
2628iyu
2629___________________________________________________
2630
2631
2632
2633Char: hooks to executables
2634
2635
2636_________________________________________________________________________________
2637
2638File pos Mem pos ID Text
2639======== ======= == ====
2640
26410000004D 0040004D 0 !This program cannot be run in DOS mode.
2642000000C8 004000C8 0 Rich:
2643000001D0 004001D0 0 .text
2644000001F8 004001F8 0 .rdata
26450000021F 0040021F 0 @.data
264600000248 00400248 0 .rsrc
2647000012E1 004012E1 0 t;PSh
264800001624 00401624 0 t1Sh<
26490000172A 0040172A 0 Y@=0u
265000001E74 00401E74 0 YYVVj
265100001F5C 00401F5C 0 scj:W
2652000025BD 004025BD 0 Ht"Ht
265300002634 00402634 0 Hu(hh
265400002928 00402928 0 HuWjP
2655000029A6 004029A6 0 Hu(hl
265600002A98 00402A98 0 Hu!h(
265700002B6F 00402B6F 0 YHt(Ht
265800002B7C 00402B7C 0 Hu/h4
265900002D59 00402D59 0 Hu!h<
266000002D84 00402D84 0 YHt2Ht(Ht
266100002D94 00402D94 0 Hu6h
266200002F32 00402F32 0 Hu!h|
266300003100 00403100 0 t@jyW
26640000322C 0040322C 0 Hu,h8
26650000385B 0040385B 0 Hu(hl
266600003894 00403894 0 Hu!hd
266700003981 00403981 0 YHt<Ht2Ht(Ht
266800003B29 00403B29 0 Ht2Ht(Ht
266900003B38 00403B38 0 Hu6hd
267000003B82 00403B82 0 Hu(hP
267100003C12 00403C12 0 Hu(hH
267200003C53 00403C53 0 Ht2Ht(Ht
267300003E43 00403E43 0 YHt2Ht(Ht
267400003E53 00403E53 0 Hu6h\
267500004024 00404024 0 Hu!h0
26760000422C 0040422C 0 Hu(hh
267700004387 00404387 0 QQSVW
2678000044FE 004044FE 0 tDJt*Jt
267900004A3B 00404A3B 0 t$SSS
268000004AF9 00404AF9 0 SSjdh,
268100004C46 00404C46 0 t"ht.A
268200004CC6 00404CC6 0 t SSSS
268300004DD6 00404DD6 0 954/A
268400005084 00405084 0 QQSVW
268500005093 00405093 0 HHtC-
268600005A9C 00405A9C 0 t6h/u
268700005C42 00405C42 0 tXj W
268800005F79 00405F79 0 t2h5u
268900006E91 00406E91 0 Pu7VW
269000006F90 00406F90 0 SSSh
2691000073BC 004073BC 0 Pht.A
269200007638 00407638 0 j.[SW
2693000076A4 004076A4 0 tqj@V
2694000076E4 004076E4 0 8<!|.<~
2695000081AF 004081AF 0 Hu(h@
2696000081E0 004081E0 0 Ht"Ht
269700008BB2 00408BB2 0 Ph0#A
269800008DD3 00408DD3 0 t)HuVh
269900008DFD 00408DFD 0 $ht"A
270000008E1C 00408E1C 0 Phh"A
2701
2702File pos Mem pos ID Text
2703======== ======= == ====
2704
270500008E46 00408E46 0 vh0"A
270600008F22 00408F22 0 Sh "A
2707000092DB 004092DB 0 t!hT!A
270800009480 00409480 0 Pht A
2709000094B5 004094B5 0 Ph0 A
2710000095F9 004095F9 0 Ph0 A
271100009B77 00409B77 0 Ph #A
271200009B99 00409B99 0 Sh0#A
271300009BFC 00409BFC 0 u?h "A
271400009C5D 00409C5D 0 Ph@$A
27150000A28F 0040A28F 0 SVWUj
27160000A2F8 0040A2F8 0 t.;t$$t(
27170000A37C 0040A37C 0 VC20XC00U
27180000ADA6 0040ADA6 0 PPPPPPPP
27190000AE00 0040AE00 0 tlHt.
27200000B01F 0040B01F 0 Ww!j
27210000B2CF 0040B2CF 0 wBVSP
27220000B405 0040B405 0 t:jtj
27230000B472 0040B472 0 u?jtj
27240000B6F9 0040B6F9 0 ?=t"U
27250000B84D 0040B84D 0 8"uF@
27260000BA1B 0040BA1B 0 SS@SSPVSS
27270000BA3D 0040BA3D 0 t#SSUP
27280000BA44 0040BA44 0 t$$VSS
27290000BACC 0040BACC 0 HSVWh
27300000CE86 0040CE86 0 Wj@Y3
27310000D059 0040D059 0 VWuBh<
27320000D443 0040D443 0 uFWWj
27330000D468 0040D468 0 "WWSh
27340000D554 0040D554 0 tMWWS
27350000D826 0040D826 0 PPPPPPPP
27360000D910 0040D910 0 FGQPS
27370000E60C 0040E60C 0 runtime error
27380000E61C 0040E61C 0 TLOSS error
27390000E62C 0040E62C 0 SING error
27400000E63C 0040E63C 0 DOMAIN error
27410000E64C 0040E64C 0 R6028
27420000E653 0040E653 0 - unable to initialize heap
27430000E674 0040E674 0 R6027
27440000E67B 0040E67B 0 - not enough space for lowio initialization
27450000E6AC 0040E6AC 0 R6026
27460000E6B3 0040E6B3 0 - not enough space for stdio initialization
27470000E6E4 0040E6E4 0 R6025
27480000E6EB 0040E6EB 0 - pure virtual function call
27490000E70C 0040E70C 0 R6024
27500000E713 0040E713 0 - not enough space for _onexit/atexit table
27510000E744 0040E744 0 R6019
27520000E74B 0040E74B 0 - unable to open console device
27530000E770 0040E770 0 R6018
27540000E777 0040E777 0 - unexpected heap error
27550000E794 0040E794 0 R6017
27560000E79B 0040E79B 0 - unexpected multithread lock error
27570000E7C4 0040E7C4 0 R6016
27580000E7CB 0040E7CB 0 - not enough space for thread data
27590000E7F2 0040E7F2 0 abnormal program termination
27600000E814 0040E814 0 R6009
27610000E81B 0040E81B 0 - not enough space for environment
27620000E840 0040E840 0 R6008
27630000E847 0040E847 0 - not enough space for arguments
27640000E86C 0040E86C 0 R6002
2765
2766File pos Mem pos ID Text
2767======== ======= == ====
2768
27690000E873 0040E873 0 - floating point not loaded
27700000E894 0040E894 0 Microsoft Visual C++ Runtime Library
27710000E8C0 0040E8C0 0 Runtime Error!
27720000E8D0 0040E8D0 0 Program:
27730000E8E0 0040E8E0 0 <program name unknown>
27740000E90C 0040E90C 0 GetLastActivePopup
27750000E920 0040E920 0 GetActiveWindow
27760000E930 0040E930 0 MessageBoxA
27770000E93C 0040E93C 0 user32.dll
27780000E960 0040E960 0 H:mm:ss
27790000E968 0040E968 0 dddd, MMMM dd, yyyy
27800000E97C 0040E97C 0 M/d/yy
27810000E9B8 0040E9B8 0 Saturday
27820000E9C4 0040E9C4 0 Friday
27830000E9CC 0040E9CC 0 Thursday
27840000E9D8 0040E9D8 0 Wednesday
27850000E9E4 0040E9E4 0 Tuesday
27860000E9EC 0040E9EC 0 Monday
27870000E9F4 0040E9F4 0 Sunday
27880000EA18 0040EA18 0 SunMonTueWedThuFriSat
27890000EA30 0040EA30 0 JanFebMarAprMayJunJulAugSepOctNovDec
27900000ED7E 0040ED7E 0 CloseHandle
27910000ED8C 0040ED8C 0 TerminateProcess
27920000EDA0 0040EDA0 0 WaitForSingleObject
27930000EDB6 0040EDB6 0 OpenProcess
27940000EDC4 0040EDC4 0 ExitProcess
27950000EDD2 0040EDD2 0 GetModuleHandleA
27960000EDE6 0040EDE6 0 FreeLibrary
27970000EDF4 0040EDF4 0 GetProcAddress
27980000EE06 0040EE06 0 LoadLibraryA
27990000EE16 0040EE16 0 Sleep
28000000EE1E 0040EE1E 0 SetEvent
28010000EE2A 0040EE2A 0 LeaveCriticalSection
28020000EE42 0040EE42 0 EnterCriticalSection
28030000EE5A 0040EE5A 0 ResetEvent
28040000EE68 0040EE68 0 WriteFile
28050000EE74 0040EE74 0 SetFilePointer
28060000EE86 0040EE86 0 CreateFileA
28070000EE94 0040EE94 0 SetEndOfFile
28080000EEA4 0040EEA4 0 DeleteFileA
28090000EEB2 0040EEB2 0 ReadFile
28100000EEBE 0040EEBE 0 GetFileSize
28110000EECC 0040EECC 0 FreeResource
28120000EEDC 0040EEDC 0 LoadResource
28130000EEEC 0040EEEC 0 SizeofResource
28140000EEFE 0040EEFE 0 FindResourceA
28150000EF0E 0040EF0E 0 GetModuleFileNameA
28160000EF24 0040EF24 0 GetSystemTime
28170000EF34 0040EF34 0 GetComputerNameA
28180000EF48 0040EF48 0 SetErrorMode
28190000EF58 0040EF58 0 GetVersionExA
28200000EF68 0040EF68 0 GetWindowsDirectoryA
28210000EF80 0040EF80 0 CreateThread
28220000EF90 0040EF90 0 CreateEventA
28230000EFA0 0040EFA0 0 InitializeCriticalSection
28240000EFBC 0040EFBC 0 DeleteCriticalSection
28250000EFD4 0040EFD4 0 lstrlenA
28260000EFE0 0040EFE0 0 GetTickCount
28270000EFF0 0040EFF0 0 CreateProcessA
28280000F002 0040F002 0 GetDriveTypeA
2829
2830File pos Mem pos ID Text
2831======== ======= == ====
2832
28330000F012 0040F012 0 GetLogicalDrives
28340000F026 0040F026 0 FindClose
28350000F032 0040F032 0 FindNextFileA
28360000F042 0040F042 0 FindFirstFileA
28370000F054 0040F054 0 GetFileAttributesA
28380000F06A 0040F06A 0 CopyFileA
28390000F076 0040F076 0 MoveFileA
28400000F082 0040F082 0 CreateDirectoryA
28410000F096 0040F096 0 GetTempPathA
28420000F0A6 0040F0A6 0 GetShortPathNameA
28430000F0B8 0040F0B8 0 KERNEL32.dll
28440000F0C8 0040F0C8 0 CharLowerA
28450000F0D6 0040F0D6 0 wsprintfA
28460000F0E2 0040F0E2 0 PostMessageA
28470000F0F2 0040F0F2 0 GetWindowThreadProcessId
28480000F10E 0040F10E 0 GetParent
28490000F11A 0040F11A 0 EnumWindows
28500000F128 0040F128 0 MessageBoxA
28510000F136 0040F136 0 CharUpperA
28520000F144 0040F144 0 DispatchMessageA
28530000F158 0040F158 0 GetMessageA
28540000F166 0040F166 0 SetTimer
28550000F172 0040F172 0 CreateWindowExA
28560000F184 0040F184 0 RegisterClassExA
28570000F198 0040F198 0 FindWindowA
28580000F1A6 0040F1A6 0 DialogBoxParamA
28590000F1B8 0040F1B8 0 ShowWindow
28600000F1C6 0040F1C6 0 EnableWindow
28610000F1D6 0040F1D6 0 GetDlgItem
28620000F1E4 0040F1E4 0 GetDlgItemTextA
28630000F1F6 0040F1F6 0 EndDialog
28640000F202 0040F202 0 PostQuitMessage
28650000F214 0040F214 0 DefWindowProcA
28660000F226 0040F226 0 SetFocus
28670000F232 0040F232 0 ReleaseDC
28680000F23E 0040F23E 0 SetWindowTextA
28690000F250 0040F250 0 GetClientRect
28700000F260 0040F260 0 GetDC
28710000F268 0040F268 0 UpdateWindow
28720000F278 0040F278 0 IsDialogMessageA
28730000F28C 0040F28C 0 PeekMessageA
28740000F29C 0040F29C 0 CreateDialogParamA
28750000F2B2 0040F2B2 0 ExitWindowsEx
28760000F2C0 0040F2C0 0 USER32.dll
28770000F2CE 0040F2CE 0 DeleteObject
28780000F2DE 0040F2DE 0 Rectangle
28790000F2EA 0040F2EA 0 SelectObject
28800000F2FA 0040F2FA 0 GetStockObject
28810000F30C 0040F30C 0 CreateSolidBrush
28820000F31E 0040F31E 0 GDI32.dll
28830000F32A 0040F32A 0 GetUserNameA
28840000F33A 0040F33A 0 RegCloseKey
28850000F348 0040F348 0 RegSetValueExA
28860000F35A 0040F35A 0 RegCreateKeyExA
28870000F36C 0040F36C 0 RegQueryValueExA
28880000F380 0040F380 0 RegOpenKeyExA
28890000F390 0040F390 0 RegEnumKeyExA
28900000F3A0 0040F3A0 0 RegDeleteKeyA
28910000F3B0 0040F3B0 0 RegDeleteValueA
28920000F3C0 0040F3C0 0 ADVAPI32.dll
2893
2894File pos Mem pos ID Text
2895======== ======= == ====
2896
28970000F3D0 0040F3D0 0 ShellExecuteA
28980000F3DE 0040F3DE 0 SHELL32.dll
28990000F3EA 0040F3EA 0 WSOCK32.dll
29000000F3F8 0040F3F8 0 VerQueryValueA
29010000F40A 0040F40A 0 GetFileVersionInfoA
29020000F41E 0040F41E 0 VERSION.dll
29030000F42C 0040F42C 0 LZClose
29040000F436 0040F436 0 LZCopy
29050000F440 0040F440 0 LZOpenFileA
29060000F44C 0040F44C 0 LZ32.dll
29070000F458 0040F458 0 RtlUnwind
29080000F464 0040F464 0 GetStartupInfoA
29090000F476 0040F476 0 GetCommandLineA
29100000F488 0040F488 0 GetVersion
29110000F496 0040F496 0 HeapAlloc
29120000F4A2 0040F4A2 0 HeapFree
29130000F4AE 0040F4AE 0 GetCurrentProcess
29140000F4C2 0040F4C2 0 HeapReAlloc
29150000F4D0 0040F4D0 0 HeapSize
29160000F4DC 0040F4DC 0 GetCurrentThreadId
29170000F4F2 0040F4F2 0 TlsSetValue
29180000F500 0040F500 0 TlsAlloc
29190000F50C 0040F50C 0 SetLastError
29200000F51C 0040F51C 0 TlsGetValue
29210000F52A 0040F52A 0 GetLastError
29220000F53A 0040F53A 0 UnhandledExceptionFilter
29230000F556 0040F556 0 FreeEnvironmentStringsA
29240000F570 0040F570 0 FreeEnvironmentStringsW
29250000F58A 0040F58A 0 WideCharToMultiByte
29260000F5A0 0040F5A0 0 GetEnvironmentStrings
29270000F5B8 0040F5B8 0 GetEnvironmentStringsW
29280000F5D2 0040F5D2 0 SetHandleCount
29290000F5E4 0040F5E4 0 GetStdHandle
29300000F5F4 0040F5F4 0 GetFileType
29310000F602 0040F602 0 HeapDestroy
29320000F610 0040F610 0 HeapCreate
29330000F61E 0040F61E 0 VirtualFree
29340000F62C 0040F62C 0 VirtualAlloc
29350000F63C 0040F63C 0 MultiByteToWideChar
29360000F652 0040F652 0 GetStringTypeA
29370000F664 0040F664 0 GetStringTypeW
29380000F676 0040F676 0 GetCPInfo
29390000F682 0040F682 0 GetACP
29400000F68C 0040F68C 0 GetOEMCP
29410000F698 0040F698 0 LCMapStringA
29420000F6A8 0040F6A8 0 LCMapStringW
2943000101E4 004101E4 0 zonealarm
2944000101F0 004101F0 0 zapro
2945000101F8 004101F8 0 wfindv32
294600010204 00410204 0 webtrap
29470001020C 0041020C 0 vsstat
294800010214 00410214 0 vshwin32
294900010220 00410220 0 vsecomr
295000010228 00410228 0 vscan
295100010230 00410230 0 vettray
295200010238 00410238 0 vet98
295300010240 00410240 0 vet95
295400010248 00410248 0 vet32
295500010250 00410250 0 vcontrol
29560001025C 0041025C 0 vcleaner
2957
2958File pos Mem pos ID Text
2959======== ======= == ====
2960
296100010274 00410274 0 sweep
29620001027C 0041027C 0 sphinx
296300010284 00410284 0 serv95
29640001028C 0041028C 0 safeweb
296500010294 00410294 0 rescue
29660001029C 0041029C 0 regedit
2967000102A8 004102A8 0 pview
2968000102B0 004102B0 0 pop3trap
2969000102BC 004102BC 0 persfw
2970000102C4 004102C4 0 pcfwallicon
2971000102D0 004102D0 0 pccwin98
2972000102DC 004102DC 0 pccmain
2973000102E4 004102E4 0 pcciomon
2974000102F8 004102F8 0 pavsched
297500010304 00410304 0 pavcl
29760001030C 0041030C 0 padmin
297700010314 00410314 0 outpost
29780001031C 0041031C 0 nvc95
297900010324 00410324 0 nupgrade
298000010330 00410330 0 nupdate
298100010338 00410338 0 normist
298200010340 00410340 0 nmain
298300010348 00410348 0 nisum
298400010358 00410358 0 navsched
298500010364 00410364 0 navnt
29860001036C 0041036C 0 navlu32
298700010374 00410374 0 navapw32
298800010380 00410380 0 nai_vs_stat
29890001038C 0041038C 0 msconfig
299000010398 00410398 0 mpftray
2991000103A0 004103A0 0 moolive
2992000103A8 004103A8 0 luall
2993000103B0 004103B0 0 lookout
2994000103B8 004103B8 0 lockdown2000
2995000103C8 004103C8 0 kpfw32
2996000103D8 004103D8 0 iomon98
2997000103E0 004103E0 0 iface
2998000103E8 004103E8 0 icsupp
2999000103F0 004103F0 0 icssuppnt
3000000103FC 004103FC 0 icmoon
300100010404 00410404 0 icmon
30020001040C 0041040C 0 icloadnt
300300010418 00410418 0 icload95
300400010424 00410424 0 ibmavsp
30050001042C 0041042C 0 ibmasn
300600010434 00410434 0 iamserv
30070001043C 0041043C 0 iamapp
30080001044C 0041044C 0 f-stopw
300900010458 00410458 0 fp-win
301000010460 00410460 0 f-prot95
30110001046C 0041046C 0 fprot95
301200010474 00410474 0 f-prot
30130001047C 0041047C 0 fprot
301400010484 00410484 0 findviru
301500010490 00410490 0 f-agnt95
30160001049C 0041049C 0 espwatch
3017000104A8 004104A8 0 esafe
3018000104B0 004104B0 0 efinet32
3019000104BC 004104BC 0 ecengine
3020000104D0 004104D0 0 claw95
3021
3022File pos Mem pos ID Text
3023======== ======= == ====
3024
3025000104D8 004104D8 0 cfinet
3026000104E0 004104E0 0 cfind
3027000104E8 004104E8 0 cfiaudit
3028000104F4 004104F4 0 cfiadmin
302900010500 00410500 0 ccshtdwn
30300001050C 0041050C 0 ccapp
303100010514 00410514 0 bootwarn
303200010520 00410520 0 blackice
30330001052C 0041052C 0 blackd
303400010534 00410534 0 avwupd32
303500010540 00410540 0 avwin95
303600010548 00410548 0 avsched32
303700010560 00410560 0 avkserv
303800010570 00410570 0 avgctrl
303900010578 00410578 0 avgcc32
304000010580 00410580 0 ave32
304100010588 00410588 0 avconsol
304200010594 00410594 0 autodown
3043000105A0 004105A0 0 apvxdwin
3044000105AC 004105AC 0 aplica32
3045000105B8 004105B8 0 anti-trojan
3046000105C4 004105C4 0 ackwin32
3047000105D8 004105D8 0 \StringFileInfo\%s\OriginalFilename
3048000105FC 004105FC 0 %04X%04X
304900010608 00410608 0 \VarFileInfo\Translation
305000010624 00410624 0 Try to pull my legs?
305100010640 00410640 0 IsDebuggerPresent
305200010654 00410654 0 Process32Next
305300010664 00410664 0 Process32First
305400010674 00410674 0 CreateToolhelp32Snapshot
305500010690 00410690 0 kernel32.dll
3056000106A0 004106A0 0 GetModuleFileNameExA
3057000106B8 004106B8 0 EnumProcessModules
3058000106CC 004106CC 0 EnumProcesses
3059000106DC 004106DC 0 psapi.dll
3060000106F8 004106F8 0 HEAD %s
306100010704 00410704 0 RCPT TO: <%s>
306200010728 00410728 0 MAIL FROM: <%s>
306300010740 00410740 0 HELO %s
306400010750 00410750 0 \germs1.dbv
30650001075C 0041075C 0 \germs0.dbv
306600010768 00410768 0 CUSTOM
30670001077F 0041077F 0 Content-Transfer-Encoding: base64
3068000107A2 004107A2 0 Content-Disposition: attachment
3069000107D0 004107D0 0 %s\%s
3070000107E0 004107E0 0 ; name="
3071000107EC 004107EC 0 msdownload
3072000107F8 004107F8 0 compressed
307300010806 00410806 0 Content-Type: application/x-
307400010838 00410838 0 6447821
307500010842 00410842 0 Content-Type: image/gif
30760001085B 0041085B 0 Content-Transfer-Encoding: base64
30770001087E 0041087E 0 Content-ID: <
30780001088C 0041088C 0 5897421
3079000108A4 004108A4 0 <BR><BR>
3080000108B2 004108B2 0 Content-Type: text/html
3081000108CB 004108CB 0 Content-Transfer-Encoding: quoted-printable
308200010904 00410904 0 Copyright %i Microsoft Corporation.
308300010936 00410936 0 Content-Type: text/plain
308400010950 00410950 0 Content-Transfer-Encoding: quoted-printable
3085
3086File pos Mem pos ID Text
3087======== ======= == ====
3088
308900010982 00410982 0 Content-Type: multipart/alternative; boundary="
3090000109B8 004109B8 0 type="multipart/alternative"
3091000109DE 004109DE 0 Content-Type: multipart/related; boundary="
309200010A16 00410A16 0 Mime-Version: 1.0
309300010A29 00410A29 0 Content-Type: multipart/mixed; boundary="
309400010A56 00410A56 0 X-ID:
309500010A60 00410A60 0 Corp.
309600010A68 00410A68 0 Corporation
309700010A80 00410A80 0 from
309800010A88 00410A88 0 comes
309900010A90 00410A90 0 came
310000010A98 00410A98 0 which
310100010AA0 00410AA0 0 Internet Explorer
310200010AB4 00410AB4 0 Windows
310300010AC4 00410AC4 0 update
310400010ACC 00410ACC 0 patch
310500010AD4 00410AD4 0 package
310600010AE4 00410AE4 0 correction
310700010AF0 00410AF0 0 corrective
310800010AFC 00410AFC 0 security
310900010B08 00410B08 0 critical
311000010B14 00410B14 0 internet
311100010B20 00410B20 0 important
311200010B2C 00410B2C 0 these
311300010B3C 00410B3C 0 that
311400010B44 00410B44 0 this
311500010B4C 00410B4C 0 Install
311600010B58 00410B58 0 Apply
311700010B68 00410B68 0 Watch
311800010B78 00410B78 0 Take a look at
311900010B88 00410B88 0 Look at
312000010B94 00410B94 0 Try on
312100010BA4 00410BA4 0 Taste
312200010BAC 00410BAC 0 Prove
312300010BB4 00410BB4 0 Check out
312400010BC0 00410BC0 0 Check
312500010BD0 00410BD0 0 FWD:
312600010BE0 00410BE0 0 Upgrade
312700010BF0 00410BF0 0 Update
312800010BF8 00410BF8 0 Patch
312900010C00 00410C00 0 Critical
313000010C14 00410C14 0 Latest
313100010C24 00410C24 0 Last
313200010C2C 00410C2C 0 Newest
313300010C34 00410C34 0 Current
313400010C42 00410C42 0 SUBJECT:
313500010C50 00410C50 0 Client
313600010C58 00410C58 0 Consumer
313700010C64 00410C64 0 Partner
313800010C74 00410C74 0 Customer
313900010C80 00410C80 0 Commercial
314000010C8F 00410C8F 0 NEWSGROUPS:
314100010C9F 00410C9F 0 TO: "
314200010CC0 00410CC0 0 microsoft
314300010CE0 00410CE0 0 bulletin
314400010CEC 00410CEC 0 confidence
314500010CF8 00410CF8 0 advisor
314600010D00 00410D00 0 updates
314700010D08 00410D08 0 technet
314800010D10 00410D10 0 support
3149
3150File pos Mem pos ID Text
3151======== ======= == ====
3152
315300010D18 00410D18 0 newsletters
315400010D34 00410D34 0 unknown
315500010D3C 00410D3C 0 Microsoft
315600010D48 00410D48 0 Support
315700010D50 00410D50 0 Assistance
315800010D5C 00410D5C 0 Services
315900010D68 00410D68 0 Bulletin
316000010D74 00410D74 0 Customer
316100010D80 00410D80 0 Public
316200010D88 00410D88 0 Technical
316300010D94 00410D94 0 Center
316400010D9C 00410D9C 0 Department
316500010DA8 00410DA8 0 Section
316600010DB0 00410DB0 0 Division
316700010DBC 00410DBC 0 Security
316800010DC8 00410DC8 0 Network
316900010DD4 00410DD4 0 Internet
317000010DE0 00410DE0 0 Program
317100010DEC 00410DEC 0 Corporation
317200010DFC 00410DFC 0 Microsoft
317300010E0C 00410E0C 0 FROM: "
317400010E16 00410E16 0 This update includes the functionality =
317500010E40 00410E40 0 of all previously released patches.
317600010E64 00410E64 0 computer
317700010E70 00410E70 0 system
317800010E78 00410E78 0 on your
317900010E8C 00410E8C 0 executable
318000010E98 00410E98 0 to run
318100010EA4 00410EA4 0 malicious user
318200010EB4 00410EB4 0 attacker
318300010EC0 00410EC0 0 , the most serious of which could
318400010EE3 00410EE3 0 allow an
318500010EF2 00410EF2 0 from these vulnerabilities
318600010F10 00410F10 0 maintain the security of your computer
318700010F38 00410F38 0 protect your computer
318800010F50 00410F50 0 help
318900010F58 00410F58 0 continue keeping your computer secure
319000010F83 00410F83 0 Install now to
319100010F94 00410F94 0 vulnerabilities
319200010FAC 00410FAC 0 newly discovered
319300010FC2 00410FC2 0 as well as three
319400010FD6 00410FD6 0 all known security vulnerabilities affecting
319500011004 00411004 0 MS Internet Explorer, MS Outlook and MS Outlook Express
31960001103C 0041103C 0 eliminates
319700011048 00411048 0 resolves
319800011054 00411054 0 fixes
31990001105C 0041105C 0 %i, Cumulative Patch" update which
320000011084 00411084 0 December
320100011090 00411090 0 November
32020001109C 0041109C 0 October
3203000110A4 004110A4 0 September
3204000110B0 004110B0 0 August
3205000110CC 004110CC 0 April
3206000110D4 004110D4 0 March
3207000110DC 004110DC 0 February
3208000110E8 004110E8 0 January
3209000110F0 004110F0 0 this is the latest version of security update, the
32100001112B 0041112B 0 Content-Transfer-Encoding: base64
32110001114E 0041114E 0 Content-Id: <
321200011182 00411182 0 Content-Type: audio/x-
3213
3214File pos Mem pos ID Text
3215======== ======= == ====
3216
32170001119C 0041119C 0 </BODY></HTML>
3218000111B0 004111B0 0 <BR><BR><BR>Message follows:<BR><BR><BR><BR>
3219000111E0 004111E0 0 to <B>%s@%s</B>
3220000111F4 004111F4 0 mail
3221000111FC 004111FC 0 message
322200011208 00411208 0 <BR><BR><BR>Undelivered
322300011224 00411224 0 <BR><BR><BR>Undeliverable
322400011240 00411240 0 to one or more destinations.<BR>
322500011264 00411264 0 to the following addresses:<BR>
322600011288 00411288 0 the message returned below could not be delivered =
3227000112C0 004112C0 0 I wasn't able to deliver your message =
3228000112EC 004112EC 0 <BR>I'm afraid =
322900011300 00411300 0 <BR>I'm sorry to have to inform you that =
323000011330 00411330 0 <BR>I'm sorry =
32310001134C 0041134C 0 <BR>Message from
323200011360 00411360 0 <BR>This is the qmail program<BR>
323300011384 00411384 0 <BR><BR>Hi.
323400011394 00411394 0 " height=3D0 width=3D0></iframe>
3235000113B8 004113B8 0 <iframe src=3D"cid:
3236000113CC 004113CC 0 <HTML>
3237000113D4 004113D4 0 <HEAD></HEAD>
3238000113E3 004113E3 0 <BODY>
3239000113EE 004113EE 0 Mime-Version: 1.0
324000011401 00411401 0 Content-Type: multipart/alternative;
324100011427 00411427 0 boundary="
324200011434 00411434 0 Notice
32430001143C 0041143C 0 Report
324400011444 00411444 0 Announcement
324500011454 00411454 0 Advice
32460001145C 0041145C 0 Letter
324700011464 00411464 0 Failure
324800011470 00411470 0 Abort
324900011478 00411478 0 Error
325000011488 00411488 0 User unknown
325100011498 00411498 0 Mailer
3252000114A0 004114A0 0 Sender
3253000114A8 004114A8 0 Returned To
3254000114B8 004114B8 0 Message
3255000114C8 004114C8 0 Undelivered
3256000114D8 004114D8 0 Undeliverable
3257000114E8 004114E8 0 Returned
3258000114F7 004114F7 0 SUBJECT:
325900011504 00411504 0 domain
32600001150C 0041150C 0 server
326100011530 00411530 0 receiver
32620001153C 0041153C 0 recipient
326300011548 00411548 0 client
326400011550 00411550 0 Receiver
32650001155C 0041155C 0 Recipient
326600011568 00411568 0 puremail
326700011574 00411574 0 america
32680001157C 0041157C 0 netmail
326900011584 00411584 0 freemail
327000011590 00411590 0 yahoo
32710001159C 0041159C 0 bigfoot
3272000115A4 004115A4 0 rocketmail
3273000115B4 004115B4 0 routine
3274000115BC 004115BC 0 program
3275000115C4 004115C4 0 daemon
3276000115CC 004115CC 0 robot
3277
3278File pos Mem pos ID Text
3279======== ======= == ====
3280
3281000115D4 004115D4 0 automat
3282000115DC 004115DC 0 engine
3283000115EC 004115EC 0 service
328400011608 00411608 0 email
328500011610 00411610 0 mailer
328600011618 00411618 0 master
328700011628 00411628 0 System
328800011630 00411630 0 Service
328900011638 00411638 0 Delivery
329000011644 00411644 0 Storage
329100011650 00411650 0 Mail
329200011658 00411658 0 Message
329300011664 00411664 0 Email
32940001166C 0041166C 0 Inet
329500011674 00411674 0 Postmaster
329600011680 00411680 0 Administrator
329700011690 00411690 0 Admin
329800011698 00411698 0 GET http://ww2.fce.vutbr.cz/bin/counter.gif/link=bacillus&width=6&set=cnt006
3299
3300HTTP/1.0
3301000116F4 004116F4 0 ww2.fce.vutbr.cz
330200011708 00411708 0 DELE %d
330300011714 00411714 0 TOP %d 30
330400011730 00411730 0 PASS %s
33050001173C 0041173C 0 USER %s
330600011748 00411748 0 showerror
330700011754 00411754 0 autorun
330800011764 00411764 0 POP Server
330900011778 00411778 0 Login
331000011780 00411780 0 Counter Visited
331100011794 00411794 0 CacheBox Outfit
3312000117A4 004117A4 0 VicName
3313000117AC 004117AC 0 ZipName
3314000117B4 004117B4 0 Server
3315000117BC 004117BC 0 Email Address
3316000117CC 004117CC 0 Explorer XBaseBar
3317000117E0 004117E0 0 %s\swen1.dat
3318000117F0 004117F0 0 %s\swen0.dat
331900011800 00411800 0 %s\nntpgroups.dat
332000011814 00411814 0 %s\germs0.dbv
332100011830 00411830 0 [%s:%c]
332200011850 00411850 0 NEWNEWS %s %02u%02u%02u %02u%02u%02u
33230001187C 0041187C 0 LISTGROUP %s
332400011892 00411892 0 reply-to:
33250001189E 0041189E 0 from:
3326000118B8 004118B8 0 Error occurred
3327000118C8 004118C8 0 Memory access violation in module kernel32 at
3328000118F8 004118F8 0 RegisterServiceProcess
332900011914 00411914 0 SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
333000011948 00411948 0 Remote Connection
33310001195C 0041195C 0 System\CurrentControlSet\Services\RemoteAccess
33320001198C 0041198C 0 Windows Explorer
3333000119A0 004119A0 0 InternetCloseHandle
3334000119B4 004119B4 0 InternetGetConnectedState
3335000119D0 004119D0 0 InternetOpenA
3336000119E0 004119E0 0 wininet.dll
3337000119EC 004119EC 0 MAPI32
3338000119F4 004119F4 0 Invalid Email Address
333900011A0C 00411A0C 0 Invalid Server Name
334000011A20 00411A20 0 Passwords do not match
334100011A54 00411A54 0 pgrade
334200011A5C 00411A5C 0 pdate
3343
3344File pos Mem pos ID Text
3345======== ======= == ====
3346
334700011A6C 00411A6C 0 nstall
334800011A74 00411A74 0 nstallation
334900011A80 00411A80 0 nstaller
335000011A94 00411A94 0 ()<>,;:\"[]
335100011AA0 00411AA0 0 delete
335200011AE0 00411AE0 0 mailto:
335300011AE8 00411AE8 0 ()<>,;:\"[]?@
335400011B00 00411B00 0 Unfile
335500011B08 00411B08 0 All Users
335600011B14 00411B14 0 Default User
335700011B24 00411B24 0 \All Users
335800011B30 00411B30 0 WinMe
335900011B38 00411B38 0 Win95
336000011B40 00411B40 0 Win98
336100011B48 00411B48 0 Startup
336200011B50 00411B50 0 \Shell Folders
336300011B60 00411B60 0 abcdefghjklmnorstvwxyz
336400011B78 00411B78 0 Winnt\Profiles\
336500011B88 00411B88 0 Documents and Settings\
336600011BA0 00411BA0 0 \Start menu\Programs\Startup
336700011BC0 00411BC0 0 Virus Generator
336800011BD0 00411BD0 0 Magic Mushrooms Growing
336900011BE8 00411BE8 0 Cooking with Cannabis
337000011C00 00411C00 0 Hallucinogenic Screensaver
337100011C1C 00411C1C 0 My naked sister
337200011C2C 00411C2C 0 XXX Pictures
337300011C3C 00411C3C 0 Sick Joke
337400011C48 00411C48 0 XXX Video
337500011C54 00411C54 0 XP update
337600011C60 00411C60 0 Emulator PS2
337700011C70 00411C70 0 XboX Emulator
337800011C84 00411C84 0 HardPorn
337900011C90 00411C90 0 Jenna Jameson
338000011CA0 00411CA0 0 10.000 Serials
338100011CB0 00411CB0 0 Hotmail hacker
338200011CC0 00411CC0 0 Yahoo hacker
338300011CD0 00411CD0 0 AOL hacker
338400011CDC 00411CDC 0 fixtool
338500011CE4 00411CE4 0 cleaner
338600011CEC 00411CEC 0 removal tool
338700011CFC 00411CFC 0 remover
338800011D0C 00411D0C 0 Sobig
338900011D14 00411D14 0 Sircam
339000011D2C 00411D2C 0 Bugbear
339100011D34 00411D34 0 installer
339200011D40 00411D40 0 upload
339300011D48 00411D48 0 warez
339400011D50 00411D50 0 hacked
339500011D60 00411D60 0 key generator
339600011D70 00411D70 0 Windows Media Player
339700011D88 00411D88 0 GetRight FTP
339800011D98 00411D98 0 Download Accelerator
339900011DB8 00411DB8 0 Winamp
340000011DC0 00411DC0 0 WinZip
340100011DC8 00411DC8 0 WinRar
340200011DD0 00411DD0 0 KaZaA
340300011DD8 00411DD8 0 KaZaA media desktop
340400011DEC 00411DEC 0 Kazaa Lite
340500011DF8 00411DF8 0 Searching for installed components ...
340600011E20 00411E20 0 Extracting files ...
3407
3408File pos Mem pos ID Text
3409======== ======= == ====
3410
341100011E38 00411E38 0 Copying files ...
341200011E4C 00411E4C 0 Updating registry ...
341300011E64 00411E64 0 %s%s.exe
341400011E70 00411E70 0 %s\%s.zip
341500011E7C 00411E7C 0 %s%s.zip
341600011E88 00411E88 0 012345:
341700011E90 00411E90 0 This update has been successfully installed.
341800011EC0 00411EC0 0 Software\Microsoft\Windows\CurrentVersion\Policies\System
341900011EFC 00411EFC 0 DisableRegistryTools
342000011F14 00411F14 0 regfile\shell\open\command
342100011F30 00411F30 0 %s showerror
342200011F40 00411F40 0 scrfile\shell\config\command
342300011F60 00411F60 0 %s "%%1"
342400011F6C 00411F6C 0 scrfile\shell\open\command
342500011F88 00411F88 0 %s "%%1" /S
342600011F94 00411F94 0 \shell\open\command
342700011FA8 00411FA8 0 exefile
342800011FB0 00411FB0 0 comfile
342900011FB8 00411FB8 0 piffile
343000011FC0 00411FC0 0 batfile
343100011FC8 00411FC8 0 %s "%%1" %%*
343200011FD8 00411FD8 0 nntptmp.fl
343300011FE4 00411FE4 0 \swen0.dat
343400011FF0 00411FF0 0 NNTP Server
343500011FFC 00411FFC 0 SMTP Display Name
343600012010 00412010 0 SMTP Server
34370001201C 0041201C 0 SMTP Email Address
343800012030 00412030 0 SOFTWARE\Microsoft\Internet Account Manager\Accounts\%s
343900012068 00412068 0 00000001
344000012074 00412074 0 Default News Account
34410001208C 0041208C 0 SOFTWARE\Microsoft\Internet Account Manager
3442000120B8 004120B8 0 Default Mail Account
3443000120D0 004120D0 0 Mirc Install Folder
3444000120F0 004120F0 0 [script]
3445000120FA 004120FA 0 n0= on 1:JOIN:#:{
34460001210D 0041210D 0 n1= /if ( $nick == $me ) { halt }
344700012130 00412130 0 n2= /.dcc send $nick "
344800012148 00412148 0 %s\%s.exe
344900012154 00412154 0 \script.bcp
345000012160 00412160 0 \script.ini
34510001216C 0041216C 0 \mirc.ini
345200012178 00412178 0 \mirc32
345300012180 00412180 0 \mirc
345400012188 00412188 0 Software\Microsoft\Windows\CurrentVersion
3455000121B4 004121B4 0 ProgramFilesDir
3456000121C8 004121C8 0 Kazaa Infect
3457000121D8 004121D8 0 Dir99
3458000121E0 004121E0 0 DlDir0
3459000121E8 004121E8 0 \Transfer
3460000121F4 004121F4 0 DownloadDir
346100012200 00412200 0 DisableSharing
346200012210 00412210 0 \LocalContent
346300012220 00412220 0 Software\Kazaa
346400012230 00412230 0 SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
346500012268 00412268 0 A -EP %s %s
346600012274 00412274 0 WinRar.exe
346700012280 00412280 0 -min -e -o %s %s
346800012294 00412294 0 WinZip.exe
3469000122A2 004122A2 0 @ECHO OFF
3470000122AD 004122AD 0 IF NOT "%%1"=="" %s %%1
3471
3472File pos Mem pos ID Text
3473======== ======= == ====
3474
3475000122C8 004122C8 0 %s\%s.bat
3476000122D4 004122D4 0 This will install Microsoft Security Update.
347700012304 00412304 0 Do you wish to continue?
347800012320 00412320 0 Install Item
347900012330 00412330 0 Software\Microsoft\Windows\CurrentVersion\Run
348000012360 00412360 0 %s autorun
34810001236C 0041236C 0 This update does not need to be installed on this system.
3482000123A8 004123A8 0 Microsoft Internet Update Pack
3483000123C8 004123C8 0 ... by Begbie
3484000123D8 004123D8 0 Installed
3485000123E4 004123E4 0 [rename]
3486000123EE 004123EE 0 NUL=%s
3487000123F8 004123F8 0 %s\Wininit.ini
348800012408 00412408 0 MoveFileExA
348900012414 00412414 0 regedit.exe "%1"
349000012430 00412430 0 "%1" /S
349100012438 00412438 0 "%1" %*
349200012440 00412440 0 %s\script.ini
349300012450 00412450 0 germs0.dbv
34940001245C 0041245C 0 germs1.dbv
349500012468 00412468 0 swen0.dat
349600012474 00412474 0 swen1.dat
349700012480 00412480 0 nntpgroups.dat
3498000137DA 0041B7DA 0 R@55BB
3499000137FC 0041B7FC 0 4g*+5
350000013817 0041B817 0 +e-l]
35010001381E 0041B81E 0 ?I=+FU
350200013838 0041B838 0 "//i]
350300013860 0041B860 0 WWx.FR
35040001387C 0041B87C 0 /ip?WWW
3505000138A0 0041B8A0 0 WWWW>5R
3506000138BF 0041B8BF 0 WWWWWx+B
3507000138D4 0041B8D4 0 t]i/""
3508000138E0 0041B8E0 0 WWWWWtF>
350900013900 0041B900 0 wwwww=B>
351000013963 0041B963 0 /p45>
351100013995 0041B995 0 AWWWWW
3512000139B4 0041B9B4 0 $)wWWWW?li/""
3513000139D6 0041B9D6 0 >WWWW
3514000139DC 0041B9DC 0 ]pi/""
3515000139FD 0041B9FD 0 ]pi/""
351600013AAD 0041BAAD 0 *.**)
351700013ACD 0041BACD 0 uee*))))00
351800013AF1 0041BAF1 0 ||off
351900013B14 0041BB14 0 vvvqza
352000013B34 0041BB34 0 vvvvv>
352100013B52 0041BB52 0 vvvvvpq
352200013B6F 0041BB6F 0 dnzzzzzvpd
352300014069 0041C069 0 UUUUUUUUUUUUUU
352400014089 0041C089 0 UOOOOOOOOOOOOOOOOOOOOOO<
3525000140A9 0041C0A9 0 SOOOOOOOOOOO99
3526000140C9 0041C0C9 0 SO9O99OO95
3527000140E9 0041C0E9 0 mOO9OO
352800014109 0041C109 0 SO 99On( AAA A A AAA A A y
352900014129 0041C129 0 S99999nO(((((((((((((((((
353000014149 0041C149 0 S9 O OnO((((((((b
35310001415B 0041C15B 0 x5bx(((
353200014169 0041C169 0 S9 9
35330001416F 0041C16F 0 +O(((((((((((((((((
353400014189 0041C189 0 L{9{9O
3535
3536File pos Mem pos ID Text
3537======== ======= == ====
3538
353900014190 0041C190 0 O((((((((
35400001419E 0041C19E 0 x(((y
3541000141AF 0041C1AF 0 2O(((((((((((((((((
3542000141C9 0041C1C9 0 L{ { {ZOb
3543000141D3 0041C1D3 0 x5(((((((((((((y
3544000141EF 0041C1EF 0 ZO(((((((((((((((hK
354500014209 0041C209 0 L{ 5r{ZOb
354600014213 0041C213 0 x5(((((((((((Khy
35470001422D 0041C22D 0 rxOOOOOOOOOOOOOOOOOO(n
354800014249 0041C249 0 L5 5 Oxxx2222+n
354900014269 0041C269 0 bN59ON5rNN5rNN5r N5rNN5*S
3550000142AF 0041C2AF 0 5O 9Nr999N5
3551000142CD 0041C2CD 0 N59ON
3552000142F2 0041C2F2 0 =5OON
355300014395 0041C395 0 O P<5ZZZ
3554000143A9 0041C3A9 0 Z=NO<
3555000143D9 0041C3D9 0 =5ZOOPL
3556000143E9 0041C3E9 0 Z=<=9
3557000143F5 0041C3F5 0 P*=*
355800014429 0041C429 0 :=<=<*=
355900014431 0041C431 0 5r5r5r
356000014438 0041C438 0 <=*zL
356100014449 0041C449 0 ::ZZZZZZZ
356200014457 0041C457 0 bzLzL
356300014A2C 0041CA2C 0 333333
356400014A3E 0041CA3E 0 333333
3565000159B8 0041D9B8 0 Microsoft Corporation. All rights reserved.
3566000159E6 0041D9E6 0 <A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
356700015A26 0041DA26 0 info/cpyright.htm" TARGET=3D"_top">Terms of Use</A>
356800015A5B 0041DA5B 0 |
356900015A6A 0041DA6A 0 <A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
357000015AAA 0041DAAA 0 info/privacy.htm" TARGET=3D"_top">
357100015ACE 0041DACE 0 Privacy Statement</A> |
357200015AF2 0041DAF2 0 <A STYLE=3D"color:#FFFFFF;" HREF=3D"http://www.microsoft.com/=
357300015B32 0041DB32 0 enable/" TARGET=3D"_top">Accessibility</A>
357400015B5E 0041DB5E 0 </FONT>
357500015B67 0041DB67 0 </TD>
357600015B6E 0041DB6E 0 </TR>
357700015B77 0041DB77 0 </TABLE>
357800015B81 0041DB81 0 </BODY>
357900015B8A 0041DB8A 0 </HTML>
358000015B98 0041DB98 0 R0lGODlhaAA7APcAAP///+rp6puSp6GZrDUjUUc6Zn53mFJMdbGvvVtXh2xre8bF1x8cU4yLprOy
358100015BE6 0041DBE6 0 zIGArlZWu25ux319xWpqnnNzppaWy46OvKKizZqavLa2176+283N5sfH34uLmpKSoNvb7c7O3L29
358200015C34 0041DC34 0 yqOjrtTU4crK1Nvb5erq9O/v+O7u99PT2sbGzePj6vLy99jY3Pv7/vb2+fn5++/v8Kqr0oWHuNbX
358300015C82 0041DC82 0 55SVoszN28vM2pGUr7S1vqqtv52frOPl8CQvaquz2Ojp7pmn3Ozu83OPzmmT6F1/xo6Voh9p2C5z
358400015CD0 0041DCD0 0 3EWC31mS40Zxr4uw6LXN8iZkuXmn55q97PH2/Yir1rbL5iVTh3Oj2cvX5Pv9/+/w8QF8606h62Wk
358500015D1E 0041DD1E 0 3n+dubnY9abB2c7n/83h9Nji6weK+CGJ4Vim6WyKpKWssgFyyAaV/0Km8Gyx6HW57FJxicDP2+Tt
358600015D6C 0041DD6C 0 9Pj8/wOa/wmL5wqd/w6V8heb91e5+mS9+VmLr4vD6qvc/b/j/Mbn/sTi9rvX6szq/tPt/9ju/dzx
358700015DBA 0041DDBA 0 /+n2/+74//P6/+3w8hOh/xOW6yCm/iuu/zWv/0m4/XTH/IXK95TP9qPV9bfi/tDn9tfp9OP0/93r
358800015E08 0041DE08 0 9L3Izy6Vzj22/lrC/mfG/JvJ5JGntAyd6IbX/3zD6GzP/3jV/2uoxHqbqujv8g6MvJTj/2HF5pXV
358900015E56 0041DE56 0 606zz6Hp/63v/7j1/8Ps88b8/rbj5RKOkE2wr3OGhoKGhv7///Dx8V2alqvm4Zni1YPRvx5uVwyO
359000015EA4 0041DEA4 0 X0q2hLTvw8X10gx2H4PXkkuoV5zkoQeADZu7mmzIVEO7HIXbaGfLMPz8+97d2/Px7v///+bl5eHg
359100015EF2 0041DEF2 0 4P7+/v39/fT09PLy8u7u7gAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
359200015F40 0041DF40 0 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
359300015F8E 0041DF8E 0 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwAAAAAaAA7AAAI/gCVCRxI
359400015FDC 0041DFDC 0 sKDBgwgTKlzIsKHDhxAjKgwiqs2kSJEgQfqyp2PHLxoxTmojSpTEkyglBrGYcU+el3n09PEDSFKg
35950001602A 0041E02A 0 mzclAfLTRw/MPV4gjTSZsmhRURchuXwUs88fSYIGubEiqyqAq1gBNLPiRlCgPz197tE4MojRswuD
359600016078 0041E078 0 JHX5UiagQILcNMtKl26zu3etuBgUaKcePXv0QIo0iSjaw8raROKYh6nbuFbmVpVlpbKby4Mya858
3597000160C6 0041E0C6 0 eWrlrV0l/fECWDBhw4hPimoJUw9NQVa0Yg6kk6dPmD9xt/Xi52kgKG4GCRLtpTjZNmZTQ5yktLXT
359800016114 0041E114 0 QFNDA+qJe2wkkgkrrmWrx4tv0X6M/gvFrnzh6uaO+wCKOhzs7TzWyUesyDom7z9//EAKOh51eYKK
3599
3600File pos Mem pos ID Text
3601======== ======= == ====
3602
360300016162 0041E162 0 sdWWH1D15cd78J12GFJKufRXcfwNNtR/ANYXE006UfdSfBQq1lxM3fFHWFlojRBCCA5goMMK5y3V
3604000161B0 0041E1B0 0 1B879VGdUMlRqIxaG7kUmHEikVTjQyuAcGIGDmSQwQUYzPBAA1UIKJMfUCI4Vhs2EjTJKrWYwogp
3605000161FE 0041E1FE 0 mXSxY0iTTLhQAC2ocKIDHGywgAwYWPDAm3AeIIVztr3E1FiFVSnQJLXc4ksxuujyiy6npNGFYBKK
36060001624C 0041E24C 0 WRAzKZipAgkp8ACCAyLg0MClDcD5ppIUVNCFFDL1oSF8Qvn3nyi8+KIqMH8aQwwx/66EMQcoVQxG
36070001629A 0041E29A 0 mI/KBEBCCCSo0MIPLJSJwA6YFvsmBlFkYgopUTxwgQ8XXGBBBRUA0QUXeJp6qi2r2rKLLcAU42qs
3608000162E8 0041E2E8 0 WIRhR623YpdDNM4wQ0IOInggrwfFNoCDDl20wooqqaSCCil3SHCBBgQXnAGbFmCAgQMkBKDnLsMU
360900016336 0041E336 0 4wswvPCySy3DuLpJGFiY4YodX6RrUhnOIFDDvPNeqkkXfKzCyssv8+svwM5uYPPNONusAZszEEEE
361000016384 0041E384 0 GoooQsfQdRRdxyJII83I0ow04nQjjkTtCB5cVN3KMBEXA8wuFbMC6Cu5jIJFLsG4oonIQeQQQw4o
3611000163D2 0041E3D2 0 a5KsI6moogrMMMvt77+kCPzB3v589+03BxdQ0IFyotyCdTFap7I1K7Z4YskmcIwSTC+9KMHGSD6S
361200016420 0041E420 0 0AIJHkRxByekkIJKv3LPXbfMeOddgQmst+466xoAIUEEEUzAQNBD02H00UkvwnTTT0s9ddV4ZPEK
36130001646E 0041E46E 0 1hH/qTUnlyDyRi659BJMMLiEgrkoQSwTAjMefPIJ6KKPHnfppfeLCt6cCDFDmjT8AMP7MJywwQW0
3614000164BC 0041E4BC 0 1187Aco5osUYyGNtjC+ccFwhzuCK6U0OF2uoQht8FAMEoMADnfge+M7Xrwpa8HyhI0X6JGCwDGhg
36150001650A 0041E50A 0 fvYLoe1wRzSj9c53THsa1KRGNS6oYQxZ0AXyjKGLUlzCEoeIQxjIRjnKTYESC/7EnjJyYAIRRMF7
361600016558 0041E558 0 4Auf+Cp4vtRxghNOiEAHjxTC+k3gfsp5ghPSAIqMBeoUlkjEIeYgBzjwEBdonEIOgmgWSDlgC0h8
3617000165A6 0041E5A6 0 YgabSEcncuITUZQBwYxERftRYAIToEDtbie0EhbthL9TofBa6IT9jeEVgQpUJcZoCDEUcHqUw8UU
3618000165F4 0041E5F4 0 ysBGZZQgBAvAgSfimMQMmjJ0T/SeGiKgRw3w8QKz+2Mgp/UALKamC1FYwha1AElJzkEMYiDb5HqB
361900016642 0041E642 0 wE2SRIjR0MEIGoCJUUqwlKd84h0/4QlMRKACezQSLAM5A2pR6wF/JGTudofIFAaPhVW7AxWooIX9
362000016690 0041E690 0 ZSELv4hnJYA5CjQScw1rUP/jMQeCgA/gQA2ecOYzpUnQaVKzmtfM5pEkMIFpebMCtZwA/lJTBR88
3621000166DE 0041E6DE 0 YQlRcIITQBHPeNrhCEcwQhPQmM8EALEkAwnBDTBAhWYG1HukTCVMD4oJTBDBAgrNAEOnZYE/vomh
36220001672C 0041E72C 0 4jQk75KWyHNGrYWO0KUT1tlOWnRUCUdQQhOaoIQ12GEKsVCgEAVSAge88RIufelMxxrQal7iEkLg
36230001677A 0041E77A 0 oCv5uFOffvOPE0XMMvjggy74IAoZ3UI8aYEEJUh1CkoggxIOUIbCbFUZyczADM4K1rI69rHVxARj
3624000167C8 0041E7C8 0 kyDFtRppp9OawR8pAFQS6s6EvSuq0xZZNS444gkZ1SgVQkELWvjMr1QlQgT+pgALG+yTIDrgwAPo
362500016816 0041E816 0 wFiwhtWxNZUsYxVBWYX6YAYT0CwgHwDRB0i0PNGoghTsCoQoaEIYQhCCz7ZLhCYoIAdD+ZEyQqAB
362600016864 0041E864 0 C4xBEb09a3Brmt5LBE0RWYiAB/mo2EBSoJvfdG5QP3vI0JpztOgsLR8y8QTU4jUK2U2wEIagBAWU
3627000168B2 0041E8B2 0 AQy3JcgIUqSF97b3wu9VhCXQwErLKpYCDvXmmygQV+UEQLpScKUPfACEFjuBCGuAhQ4gXBLxIjZa
362800016900 0041E900 0 QrBEhtGL3rPyOMOWCHIiOkxfCzT0oc2lwH7J6d+lKTLAVfPIdAu8hCUAwQlCIIMBikAJCEeYIMm4
36290001694E 0041E94E 0 gAxmkIggB3nHOzazJcb+QIXZ6bHIIPZmT0FMYj2RyUw50EEZRIAASnzheoctSJEekIgyq/nQalaE
36300001699C 0041E99C 0 E2QXAYHlFANx1iyILYDcJYOWqP9d4VFLi62PgEQkGAl1mI5p44HcYMxoQISqC21oIYcxDUuowOwk
3631000169EA 0041E9EA 0 IAMOTDEDGAAnBR5gARyAE5Al1pMytIM5UiuEBxWwQBIOoepmO1sRd/BBBWgnMGo9a758xECmcOBr
363200016A38 0041EA38 0 QE5Av55lMqadbNThldYjX/h0qEVyvVIDiFpEOIS85b3qOjBBBrODgL4foCZoWVsG2cZAt5fL7ToL
363300016A86 0041EA86 0 WyAVWeAxA42QScjgAkQoRCHmrYhGgDAC+s54AjbAAQ4s4GDeFHOuvf3/ABwMQBgiUHK4L620TJP2
363400016AD4 0041EAD4 0 3J7WSEhG1MmJRKILsJzDxBfxhfLWL+MZn4AGOm5rgj2cWrJ8wAB2sAMRFEMYBtcTRUpCdXcbZDV8
363500016B22 0041EB22 0 sIAExoAHHuA7At2sYv3Q5PEOQmvXTE/7DlCu8kLyd6gtJzeANw3zPaRb5uwOIkoV0gY2SNsCgG+0
363600016B70 0041EB70 0 DFJwJFhWMbkDK7qHRcD4xjMeBxMoQAGEHYSpWz0hPlhANHxggWtyYBnMQAYIKvBwCZj+9GCHqAUc
363700016BBE 0041EBBE 0 kFMdOF4EOzBAAXoA2JX3d9zAm7u5oxxzW4164doaiAM0rwwU0IAHz4hGAEDfAjH74PTQn4G0EpAA
363800016C0C 0041EC0C 0 Z9HX9Y03wAEKcIAB/oDAYQc/CQkcEIBoPAMGzoDBM2KwfGa0QAMXOBLg5y8B6V/gAVNowhQogIEV
363900016C5A 0041EC5A 0 61kEDXAAPdADTVAJaKBjtgd3KCR3mrZ7nWZ36kZzx0QIV5AQGNAC5Xd+x6B+7Md8KYBN0oZkziIt
364000016CA8 0041ECA8 0 E4AAKTAACtBQ8ZIA3NcBKrAMMRB+RfEAzLAM0aAMz/ACLwANyrcMyNACKXABCwA40VKEFPBwRtYE
364100016CF6 0041ECF6 0 cjAHhmAEU5AAAzgFYjAHrHZmCVhODPhyvAeBtkJzNUYIs5AQNLgM5VeBV9CDoQeEIZABICADbviG
364200016D44 0041ED44 0 FBAtRqYAzCAQAVACOSAACFACMngYFqACNRgAgiiIy+CDLQCEJCAD/yWgAV7ViHF4ATOQAFMABxI3
364300016D92 0041ED92 0 cWM0B6tWhQjoduIWd7nXgC20hXfHbkOBPRSYECFgAchQg4VYiMyQhikAAjdwAStgAydyIm1yARVA
364400016DE0 0041EDE0 0 AQXQASvQhzYSAA2AAav4iq/4g0AYiyRwATRQAiqgAggwAxYgA7t4AAcQAjcIjBTSAgYwAySADOB4
364500016E2E 0041EE2E 0 iMkoi7uCAQuQJBYgZj3FfQOwDNpYJSnQAROAAZozjuS4AAsAfzLgAGzyACzYfXX4jlVSAmVAfQ+w
364600016E7C 0041EE7C 0 MCRgAyRAAvhIMCmCXNtXAAYQAu4okHryAzaAARNgjQYJJxNAfRF5AAaQAy2QjRYpdWBQBV2QawrA
364700016ECA 0041EECA 0 gpLHfQpgAA1ggiMrYJInKWxIsRhfUAU82ZMj0Iwr8AM3qY3E9ntVV3lDWSUBAQA7
364800016F10 0041EF10 0 R0lGODlhDAAMANUAAP////f3//f39+/v9+/v797m987W787W5sXW5rXF76295qW975y175St75St
364900016F5E 0041EF5E 0 3pSlzoyl1oSl5oylzoycxXOU3nOMxWOM5mOM3mOE1lqE3mOEvVKE1lp7xVJ71lJ7zlJ7xVJ7vUp7
365000016FAC 0041EFAC 0 zkpzzkpzxVJzrUprvUJrxUJrvUJjtTpjtTpjrTparTpapQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
365100016FFA 0041EFFA 0 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwAAAAADAAMAAAIjAABAAhwwMGFCxAQ
365200017048 0041F048 0 CACwkICDDBYSLGjQwQEBhg8zDBAIYIEIBwIQdLjAoOOFgSFMIICwIUMEAxQwCBxhAgKHDh5C6DQA
365300017096 0041F096 0 IIGJEyA4fPAwYoQCAAVKoEgBQsKJEidQ8CyRYumDA1VTqNBQQYXXFQofsPB6AIAKFiweNBTLoiza
3654000170E4 0041F0E4 0 BxcFCjgwgQSJCQcWCggIADs=
365500017100 0041F100 0 </FONT></TD></TR>
365600017113 0041F113 0 </TABLE>
36570001711F 0041F11F 0 <BR><BR>
365800017129 0041F129 0 <TABLE BORDER=3D"1" CELLSPACING=3D"1" CELLPADDING=3D"3" WIDTH=3D"600">
365900017171 0041F171 0 <TR VALIGN=3D"TOP">
366000017186 0041F186 0 <TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
3661000171C1 0041F1C1 0 ALIGN=3D"absmiddle" BORDER=3D"0"> System requirements</B>
366200017201 0041F201 0 </FONT></TD>
3663
3664File pos Mem pos ID Text
3665======== ======= == ====
3666
36670001720F 0041F20F 0 <TD NOWRAP><FONT SIZE=3D"1">Windows 95/98/Me/2000/NT/XP</FONT></TD>
366800017254 0041F254 0 </TR>
36690001725D 0041F25D 0 <TR VALIGN=3D"TOP">
367000017272 0041F272 0 <TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
3671000172AD 0041F2AD 0 ALIGN=3D"absmiddle" BORDER=3D"0"> This update applies to</B>
3672000172F0 0041F2F0 0 </FONT></TD><TD NOWRAP>
367300017309 0041F309 0 <FONT SIZE=3D"1">
36740001731C 0041F31C 0 MS Internet Explorer, version 4.01 and later<BR>
36750001734E 0041F34E 0 MS Outlook, version 8.00 and later<BR>
367600017376 0041F376 0 MS Outlook Express, version 4.01 and later
3677000173A2 0041F3A2 0 </FONT>
3678000173AB 0041F3AB 0 </TD>
3679000173B2 0041F3B2 0 </TR>
3680000173BB 0041F3BB 0 <TR VALIGN=3D"TOP">
3681000173D0 0041F3D0 0 <TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
36820001740B 0041F40B 0 ALIGN=3D"absmiddle" BORDER=3D"0"> Recommendation</B></FONT></TD>
368300017452 0041F452 0 <TD NOWRAP><FONT SIZE=3D"1">Customers should install the patch =
368400017494 0041F494 0 at the earliest opportunity.</FONT></TD>
3685000174BE 0041F4BE 0 </TR>
3686000174C7 0041F4C7 0 <TR VALIGN=3D"TOP">
3687000174DC 0041F4DC 0 <TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
368800017517 0041F517 0 ALIGN=3D"absmiddle" BORDER=3D"0"> How to install</B></FONT></TD>
36890001755E 0041F55E 0 <TD NOWRAP><FONT SIZE=3D"1">Run attached file. =
369000017590 0041F590 0 Choose Yes on displayed dialog box.</FONT></TD>
3691000175C1 0041F5C1 0 </TR>
3692000175CA 0041F5CA 0 <TR VALIGN=3D"TOP">
3693000175DF 0041F5DF 0 <TD NOWRAP><FONT SIZE=3D"1"><B><IMG SRC=3D"cid:6447821" =
36940001761A 0041F61A 0 ALIGN=3D"absmiddle" BORDER=3D"0"> How to use</B></FONT></TD>
36950001765D 0041F65D 0 <TD NOWRAP><FONT SIZE=3D"1">You don't need to do =
369600017691 0041F691 0 anything after installing this item.</FONT></TD>
3697000176C3 0041F6C3 0 </TR>
3698000176CA 0041F6CA 0 </TABLE>
3699000176DC 0041F6DC 0 <TABLE WIDTH=3D"600"><TR><TD><FONT SIZE=3D"2">
37000001770C 0041F70C 0 Microsoft Product Support Services and Knowledge Base articles
37010001774C 0041F74C 0 can be found on the <A HREF=3D"http://support.microsoft.com/" =
37020001778D 0041F78D 0 TARGET=3D"_top">Microsoft Technical Support</A> web site. =
3703000177CA 0041F7CA 0 For security-related information about Microsoft products, please =
37040001780F 0041F80F 0 visit the <A HREF=3D"http://www.microsoft.com/security" TARGET=3D"_top">
370500017859 0041F859 0 Microsoft Security Advisor</A> web site, =
370600017885 0041F885 0 or <A HREF=3D"http://www.microsoft.com/contactus/contactus.asp" =
3707000178C8 0041F8C8 0 TARGET=3D"_top">Contact Us.</A>
3708000178E9 0041F8E9 0 <BR><BR>
3709000178F3 0041F8F3 0 Thank you for using Microsoft products.<BR><BR></FONT>
37100001792B 0041F92B 0 <FONT SIZE=3D"1">Please do not reply to this message. =
371100017964 0041F964 0 It was sent from an unmonitored e-mail address and we are unable =
3712000179A8 0041F9A8 0 to respond to any replies.<BR></FONT>
3713000179D1 0041F9D1 0 <HR COLOR=3D"Silver" SIZE=3D"1" WIDTH=3D"100%">
371400017A02 0041FA02 0 <FONT SIZE=3D"1" COLOR=3D"Gray">The names of the actual companies and =
371500017A4B 0041FA4B 0 products mentioned herein are the trademarks =
371600017A7B 0041FA7B 0 of their respective owners.</FONT>
371700017A9F 0041FA9F 0 </TD></TR></TABLE>
371800017ABB 0041FABB 0 <TABLE WIDTH=3D"600" HEIGHT=3D"45" BGCOLOR=3D"#1478EB">
371900017AF4 0041FAF4 0 <TR VALIGN=3D"TOP">
372000017B09 0041FB09 0 <TD WIDTH=3D"5"></TD>
372100017B26 0041FB26 0 <FONT COLOR=3D"#FFFFFF" SIZE=3D"1"><B>
372200017B4E 0041FB4E 0 <A class=3D'navtext' HREF=3D"http://www.microsoft.com/=
372300017B87 0041FB87 0 contactus/contactus.asp" TARGET=3D"_top">Contact Us</A>
372400017BC0 0041FBC0 0 |
372500017BCF 0041FBCF 0 <A class=3D'navtext' HREF=3D"http://www.microsoft.com/legal/" =
372600017C10 0041FC10 0 TARGET=3D"_top">Legal</A>
3727
3728File pos Mem pos ID Text
3729======== ======= == ====
3730
373100017C2B 0041FC2B 0 |
373200017C3A 0041FC3A 0 <A class=3D'navtext' HREF=3D"https://www.truste.org/validate/605" =
373300017C7F 0041FC7F 0 TARGET=3D"_top" TITLE=3D"TRUSTe - Click to Verify">TRUSTe</A>
373400017CBE 0041FCBE 0 </FONT></B>
373500017CCB 0041FCCB 0 </TD>
373600017CD2 0041FCD2 0 </TR>
373700017CDB 0041FCDB 0 <TR VALIGN=3D"MIDDLE">
373800017CF3 0041FCF3 0 <TD WIDTH=3D"5"></TD>
373900017D10 0041FD10 0 <FONT COLOR=3D"#FFFFFF" SIZE=3D"1">
374000017D35 0041FD35 0 ©
374100017D42 0041FD42 0 System requirements: Windows 95/98/Me/2000/NT/XP
374200017D74 0041FD74 0 This update applies to:
374300017D8D 0041FD8D 0 - MS Internet Explorer, version 4.01 and later
374400017DBE 0041FDBE 0 - MS Outlook, version 8.00 and later
374500017DE5 0041FDE5 0 - MS Outlook Express, version 4.01 and later
374600017E16 0041FE16 0 Recommendation: Customers should install the patch =
374700017E4C 0041FE4C 0 at the earliest opportunity.
374800017E6A 0041FE6A 0 How to install: Run attached file. Choose Yes on displayed dialog box.
374900017EB2 0041FEB2 0 How to use: You don't need to do anything after installing this item.
375000017F04 0041FF04 0 Microsoft Product Support Services and Knowledge Base articles =
375100017F46 0041FF46 0 can be found on the Microsoft Technical Support web site.
375200017F81 0041FF81 0 http://support.microsoft.com/
375300017FA2 0041FFA2 0 For security-related information about Microsoft products, please =
375400017FE7 0041FFE7 0 visit the Microsoft Security Advisor web site
375500018016 00420016 0 http://www.microsoft.com/security/
37560001803C 0042003C 0 Thank you for using Microsoft products.
375700018067 00420067 0 Please do not reply to this message.
37580001808D 0042008D 0 It was sent from an unmonitored e-mail address and we are unable =
3759000180D1 004200D1 0 to respond to any replies.
3760000180EF 004200EF 0 ----------------------------------------------
37610001811F 0042011F 0 The names of the actual companies and products mentioned =
37620001815B 0042015B 0 herein are the trademarks of their respective owners.
376300018198 00420198 0 <HTML>
3764000181A0 004201A0 0 <HEAD>
3765000181A8 004201A8 0 <style type=3D'text/css'>.navtext{color:#ffffff;text-decoration:none}
3766000181EF 004201EF 0 </style>
3767000181F9 004201F9 0 </HEAD>
376800018204 00420204 0 <BODY BGCOLOR=3D"White" TEXT=3D"Black">
37690001822D 0042022D 0 <BASEFONT SIZE=3D"2" face=3D"verdana,arial">
37700001825B 0042025B 0 <TABLE WIDTH=3D"600" HEIGHT=3D"40" BGCOLOR=3D"#1478EB">
377100018294 00420294 0 <TR height=3D"20">
3772000182A8 004202A8 0 <TD ALIGN=3D"left" VALIGN=3D"TOP" WIDTH=3D"400" ROWSPAN=3D"2">
3773000182EE 004202EE 0 <FONT FACE=3D"sans-serif" SIZE=3D"5"><I><B>
37740001831B 0042031B 0 <A class=3D'navtext' HREF=3D"http://www.microsoft.com/"
377500018354 00420354 0 TITLE=3D"Microsoft Home Site" target=3D"_top">Microsoft</A>
377600018391 00420391 0 </B></I></FONT>
3777000183A2 004203A2 0 </TD>
3778000183AB 004203AB 0 <TD ALIGN=3D"right" VALIGN=3D"MIDDLE" BGCOLOR=3D"Black" NOWRAP>
3779000183EC 004203EC 0 <FONT color=3D"#ffffff" size=3D1>
378000018415 00420415 0 <A class=3D'navtext' href=3D'http://www.microsoft.com/catalog/' =
378100018458 00420458 0 target=3D"_top">All Products</A> |
378200018487 00420487 0 <A class=3D'navtext' href=3D'http://support.microsoft.com/' =
3783000184C6 004204C6 0 target=3D"_top">Support</A> |
3784000184F0 004204F0 0 <A class=3D'navtext' href=3D'http://search.microsoft.com/' =
37850001852E 0042052E 0 target=3D"_top">Search</A> |
378600018557 00420557 0 <A class=3D'navtext' href=3D'http://www.microsoft.com/' target=3D_top>
37870001859F 0042059F 0 Microsoft.com Guide</A>
3788000185BE 004205BE 0 </FONT>
3789000185C7 004205C7 0 </TD>
3790000185CE 004205CE 0 </TR>
3791
3792File pos Mem pos ID Text
3793======== ======= == ====
3794
3795000185DD 004205DD 0 <TD ALIGN=3D"right" VALIGN=3D"BOTTOM" NOWRAP>
37960001860C 0042060C 0 <FONT FACE=3D"Verdana, Arial" SIZE=3D1><B>
379700018638 00420638 0 <A class=3D'navtext' HREF=3D'http://www.microsoft.com/' TARGET=3D" top">
379800018682 00420682 0 Microsoft Home</A> </B>
3799000186A6 004206A6 0 </FONT>
3800000186AF 004206AF 0 </TD>
3801000186B6 004206B6 0 </TR>
3802000186BD 004206BD 0 </TABLE>
3803000186C9 004206C9 0 <IMG SRC=3D"cid:5897421" BORDER=3D"0"><BR><BR>
3804000186FF 004206FF 0 <TABLE WIDTH=3D"600"><TR><TD><FONT SIZE=3D"2">
38050001873F 0042073F 0 0.abnorm
380600018748 00420748 0 al.com
380700018751 00420751 0 12-25
38080001875B 0042075B 0 -62.clie
380900018764 00420764 0 nt.attbi
38100001876F 0042076F 0 4-107-9
38110001877B 0042077B 0 40.109
381200018782 00420782 0 .13.17=
381300018797 00420797 0 1.70=
3814000187A1 004207A1 0 55.129.4
3815000187AC 004207AC 0 61.53.2
3816000187D4 004207D4 0 54.76.3W
381700018803 00420803 0 241-98-1
38180001880C 0042080C 0 79-mx.xd
381900018815 00420815 0 sl.tisca
38200001881E 0042081E 0 li.nl
38210001883D 0042083D 0 8.#36
38220001886F 0042086F 0 7-16-
382300018878 00420878 0 kdd.ne
382400018885 00420885 0 3.9:E
382500018921 00420921 0 boukir&
38260001892B 0042092B 0 -1-4-ppa
382700018934 00420934 0 ris.a
382800018943 00420943 0 q cs2
382900018949 00420949 0 .byu.edu
38300001896E 0042096E 0 gulli
383100018975 00420975 0 ver.frq iwl-0
38320001898A 0042098A 0 ne.jpq lp
383300018994 00420994 0 ha.webus
3834000189A2 004209A2 0 argos
3835000189A8 004209A8 0 .sae.g
3836000189BC 004209BC 0 o{rgq sics
3837000189CA 004209CA 0 #urelia.
3838000189DE 004209DE 0 drick.bl
3839000189E7 004209E7 0 ic>5racka
3840000189F1 004209F1 0 .rz.uni-
3841000189FA 004209FA 0 augsburg480U3nD
384200018A13 00420A13 0 bast
384300018A1C 00420A1C 0 chpoly.a
384400018A25 00420A25 0 P0zB0bsnewv
384500018A35 00420A35 0 ".twB0
384600018A3C 00420A3C 0 eech.fer}nb1hagenn3
384700018A50 00420A50 0 ias.ipca2
384800018A5A 00420A5A 0 tuebin
384900018A69 00420A69 0 blob.
385000018A6F 00420A6F 0 linuxfr
385100018A79 00420A79 0 bolo.na
385200018A89 00420A89 0 0alln3
385300018A91 00420A91 0 Clogivis
385400018A9A 00420A9A 0 ion>4ossi
3855
3856File pos Mem pos ID Text
3857======== ======= == ====
3858
385900018AA4 00420AA4 0 x.inf
386000018AAE 00420AAE 0 ka2kie
386100018AB9 00420AB9 0 thead.cy
386200018AC2 00420AC2 0 bertr
386300018ACD 00420ACD 0 3po.broo
386400018AD8 00420AD8 0 #cl 190.|d
386500018AE5 00420AE5 0 fdl.w
386600018AEC 00420AEC 0 Ohart
386700018AF2 00420AF2 0 nCaD0
386800018B05 00420B05 0 rbo<3.esp[ci
386900018B2C 00420B2C 0 hlde.
387000018B3E 00420B3E 0 0.wol
387100018B57 00420B57 0 wsgro
387200018B5D 00420B5D 0 uplE(P-
387300018B6B 00420B6B 0 !.]rreo.u
387400018B85 00420B85 0 $cypWres
387500018B8E 00420B8E 0 ld@n
387600018B97 00420B97 0 !davi
387700018B9D 00420B9D 0 Pmswoft
387800018BA5 00420BA5 0 "ddt80Ym
387900018BBA 00420BBA 0 Tejasear
388000018BC4 00420BC4 0 0wu-w/
388100018BD5 00420BD5 0 0mind
388200018BE2 00420BE2 0 dia?na.bcnz0
388300018BF1 00420BF1 0 dFPR@rPmi
388400018C02 00420C02 0 0alrea
388500018C0C 00420C0C 0 Sogwood
388600018C15 00420C15 0 =p0dp-
388700018C2B 00420C2B 0 tv380ltat
388800018C40 00420C40 0 ibm3.gk
388900018C4A 00420C4A 0 o1ep30
389000018C55 00420C55 0 l.kyoto-
389100018C6B 00420C6B 0 1.eur
389200018C76 00420C76 0 eed1a0cenEs
389300018CA2 00420CA2 0 0lF@y
389400018CA8 00420CA8 0 .idc.k
389500018CC4 00420CC4 0 Porunl
389600018CCB 00420CCB 0 2C@um
389700018CD1 00420CD1 0 ovPa
389800018CD8 00420CD8 0 creebs
389900018CE2 00420CE2 0 i=0ct
390000018CE8 00420CE8 0 7frmsug
390100018CF0 00420CF0 0 3gr-gw
390200018CF7 00420CF7 0 viwtp/pmic]0Z
390300018D15 00420D15 0 @gigag@
390400018D2C 00420D2C 0 lauda
390500018D3C 00420D3C 0 pC@.]p
390600018D4B 00420D4B 0 P?affrc.dP
390700018D58 00420D58 0 grafTpa2ma
390800018D6F 00420D6F 0 ;1l'0mi
390900018D79 00420D79 0 !gNEPg.u
391000018D99 00420D99 0 wdm3h_66-59
391100018DA8 00420DA8 0 w.gt
391200018DB7 00420DB7 0 ermes1
391300018DC0 00420DC0 0 hs-brem
391400018DD2 00420DD2 0 .poool8
391500018DE7 00420DE7 0 !htsr
391600018DF0 00420DF0 0 Z0nbhu
391700018E13 00420E13 0 t rg~ 81-5
391800018E23 00420E23 0 @bx.pr
3919
3920File pos Mem pos ID Text
3921======== ======= == ====
3922
392300018E2F 00420E2F 0 Chat.
392400018E44 00420E44 0 e.iWrk
392500018E4B 00420E4B 0 Hhoivat_PahfRyi
392600018E5B 00420E5B 0 0pdata
392700018E63 00420E63 0 rJ;0t
392800018E73 00420E73 0 AA.rgv
392900018E7D 00420E7D 0 tSsunbAA4a2r
393000018E8C 00420E8C 0 oJ0o1AAsun2
393100018EA6 00420EA6 0 +x3@@x
393200018EBA 00420EBA 0 fh-ggel
393300018EC2 00420EC2 0 w ch
393400018ECA 00420ECA 0 isgnt5~
393500018EE3 00420EE3 0 uhPlace$
393600018F26 00420F26 0 &main.%g,pe
393700018F56 00420F56 0 sk.cat
393800018F5E 00420F5E 0 2@eGPhok
393900018F92 00420F92 0 CPzis=
394000018F99 00420F99 0 h_0t~
394100018FA0 00420FA0 0 wildaun2
394200018FAE 00420FAE 0 ncag
394300018FB5 00420FB5 0 #nept3pbe
394400018FEC 00420FEC 0 vcinc
39450001900F 0042100F 0 i30~P
394600019022 00421022 0 @ibsur
394700019044 00421044 0 oCfc_
39480001905E 0042105E 0 dr.@p'
39490001906B 0042106B 0 tu-d@
3950000190CB 004210CB 0 gci*Q
3951000190E4 004210E4 0 hanya
3952000190EE 004210EE 0 htwm~
39530001913E 0042113E 0 v.sovam
395400019148 00421148 0 konkuk
395500019179 00421179 0 ,{Gdth.
395600019183 00421183 0 vestav.
3957000191DF 004211DF 0 ortaq
3958000191E6 004211E6 0 Pma.5
3959000191F7 004211F7 0 kpnqw|
396000019276 00421276 0 @ra-l
39610001927F 0042127F 0 tl(@ib%
39620001929E 0042129E 0 CuG-il
3963000192E1 004212E1 0 b0v-na
396400019306 00421306 0 IQ-yor
396500019312 00421312 0 k3od3A\
39660001934F 0042134F 0 15'Ms
396700019357 00421357 0 .ctrl-c
396800019384 00421384 0 0-exG
39690001938C 0042138C 0 odSig!p
3970000193B9 004213B9 0 111.ov#dn6n0bi#b.b
3971000193D6 004213D6 0 snmp_en2-l
3972000193E8 004213E8 0 foJ1-h
3973000193F9 004213F9 0 ufQ$o
397400019406 00421406 0 pwr'.wr
39750001941D 0042141D 0 GApcp
397600019423 00421423 0 03428581
39770001942F 0042142F 0 waldlk
397800019448 00421448 0 peewe
397900019456 00421456 0 DPel<
39800001945C 0042145C 0 @wqoswe
398100019468 00421468 0 g-adr
3982000194A2 004214A2 0 rait*
3983
3984File pos Mem pos ID Text
3985======== ======= == ====
3986
3987000194C8 004214C8 0 y.dvg
3988000194E0 004214E0 0 geek3
39890001951F 0042151F 0 r1.wm
399000019548 00421548 0 wpafqbS
399100019578 00421578 0 P6-23
39920001957E 0042157E 0 2-12
399300019592 00421592 0 sb/s004G0t
3994000195AC 004215AC 0 c_lub.c
3995000195F2 004215F2 0 snoopy
3996000195F9 004215F9 0 .bndl
3997000195FF 004215FF 0 #so?t-mod0
399800019613 00421613 0 rparS
399900019623 00421623 0 q.dk>
40000001962A 0042162A 0 u789.A
400100019642 00421642 0 ~u3tabloi|
40020001966C 0042166C 0 cr-04>
400300019673 00421673 0 p.pdx.r
400400019684 00421684 0 easyh'
4005000196D0 004216D0 0 thsKc5& u
400600019716 00421716 0 euv-f
40070001971F 0042171F 0 furt-oN
400800019727 00421727 0 wzKpr
400900019777 00421777 0 focal$
401000019782 00421782 0 pn@%p
401100013372 0041B372 0 CUSTOM
40120001475A 0041C75A 0 fff3f
4013000147EA 0041C7EA 0 3f333
401400014DD6 0041CDD6 0 MAPI32 Exception
401500014DFC 0041CDFC 0 MS Sans Serif
401600014E2E 0041CE2E 0 &Apply
401700014E56 0041CE56 0 Cancel
401800014EB6 0041CEB6 0 An internal error has occurred in module mapi32.dll
401900014F52 0041CF52 0 In the edit box below, please enter your name as you would like it to appear
4020
4021in the "From" field of your outgoing message.
402200015062 0041D062 0 Your Name:
4023000150AE 0041D0AE 0 Please enter your email address. This address will be the address other
4024
4025people use to send email to you.
40260001519A 0041D19A 0 Email Address:
4027000151EE 0041D1EE 0 Please enter the name of your outgoing mail server in the edit box below.
40280001529A 0041D29A 0 SMTP Server:
4029000152EA 0041D2EA 0 Default mail account structure has a damaged table of contents. It is
4030
4031recommended to newly reconfigure your account records. MAPI32 needs these informations in order to be able
4032
4033to send and receive mail. Failure to do so may cause that some MAPI32
4034000154F2 0041D4F2 0 (required)
403500015522 0041D522 0 (required)
403600015552 0041D552 0 Enter the name you will use to log into this account.
4037000155D6 0041D5D6 0 Login Name:
403800015622 0041D622 0 Please enter the password for current account.
40390001569A 0041D69A 0 Password:
4040000156E2 0041D6E2 0 Type in the full name of your incoming mail server.
404100015762 0041D762 0 POP3 Server:
4042000157B2 0041D7B2 0 Retype password:
40430001580A 0041D80A 0 dependent applications (such as Outlook or Outlook Express) become non-
4044
4045functional.
4046000158D6 0041D8D6 0 Installing Update Pack
40470001590D 0041D90D 0 MS Sans Serif
404800013372 0041B372 880 USTOM
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059____________________________________________________________________________
4060
4061
4062
4063
4064The installation performed the following activity:
4065 9 files added
4066 2 files deleted
4067 6 files updated
4068 18 registry entries added
4069 0 registry entries deleted
4070 22 registry entries updated