<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7885177434994542510</id><updated>2012-01-28T08:49:21.939-05:00</updated><category term='vir- Exploit-PDF.w'/><category term='- MS EXCEL 2003 SP3'/><category term='- Win XP x64 SP2'/><category term='Vir-Exploit:JS/Mult.CM'/><category term='- MS WORD 2003'/><category term='CVE-2009-3867'/><category term='vir-JS:Pdfka-WP'/><category term='Duqu'/><category term='- INTERNET EXPLORER 6'/><category term='CVE-2008-5353'/><category term='Vir-Exploit.PDF-JS.Gen.C02'/><category term='CVE-2010-0806'/><category term='- ANDROID OS'/><category term='Samples'/><category term='Vir-Trojan.Pidief.E'/><category term='vir-Trojan.Pidief.I'/><category term='Vir-Win32.Magania'/><category term='Vir- TROJ_HCPEXP.A'/><category term='vir- Exploit.JS.Pdfka.bvz'/><category term='Vir-Trojan.Hydraq'/><category term='- WIN XP SP1'/><category term='Vir-Exploit/Zordle.gen'/><category term='BSides'/><category term='CVE-2008-3005'/><category term='Magazines and Papers'/><category term='- ADOBE READER + ACROBAT 9.3.4'/><category term='vir-MSWord/Dropper.BCamelot'/><category term='Vir-Exploit.JS.Pdfka.ara'/><category term='Vir-Exploit.JS.Pdfka.ayg'/><category term='Vir-Trojan.Swifi'/><category term='Vir-HTML_DROPPER.NRA'/><category term='vir-Mal/PDFEx-D'/><category term='Dirt Jumper'/><category term='Vir-Exploit.JS.Pdfka.aiu'/><category term='CVE-2010-3654'/><category term='CVE-2010-4091'/><category term='vir-Troj/PDFJs-GL'/><category term='vir-TROJ_PDFEX.E'/><category term='vir-Trojan.Win32.Scar'/><category term='- MS POWEPOINT 2000 SP3'/><category term='- ADOBE FLASH 10.0.45.2'/><category term='Morto'/><category term='botnets'/><category term='Vir-Opachki'/><category term='vir-Troj/PDFJs-JI'/><category term='CVE-2010-2568'/><category term='CVE-2009-1869'/><category term='Vir-Exploit.HTML.IframeBof'/><category term='vir- Exploit.JS.Pdfka.bex'/><category term='TOOLS'/><category term='Sources'/><category term='samples.vir-Trojan.Script.256073'/><category term='Malware Zoo'/><category term='- ADOBE READER + ACROBAT 9.3.2'/><category term='CVE-2010-2883'/><category term='Vir-Exploit:Win32/Pidief.X'/><category term='- INTERNET EXPLORER 6 SP1'/><category term='- WIN XP SP3'/><category term='Vir-PDF/Pidief.O'/><category term='Vir-Infostealer.Banker.F'/><category term='Vir-Exploit.JS.Pdfka.atq'/><category term='Vir-Exploit/Acroread-CVE-2009-4324'/><category term='CVE-2007-5659'/><category term='**File-VT only**'/><category term='- INTERNET EXPLORER 7'/><category term='vir-Exploit.Win32.Pidief.dch'/><category term='Vir-Troj/PDFJs-FM'/><category term='- MS OFFICE 2008 MAC'/><category term='Vir-Exploit.JS.Pdfka.aow'/><category term='Vir-Trojan.Win32.Agent.dbzx'/><category term='worm'/><category term='Vir-Exploit.PDF-JS.Gen.Vir-Exploit:JS/Heapspray'/><category term='- MS WORKS 2006'/><category term='- MS EXCEL 2003'/><category term='inReverse blog'/><category term='Crimepack'/><category term='Vir-Troj/DarkMoon-B'/><category term=': - ADOBE FLASH 10.0.45.2'/><category term='taiwan phish'/><category term='Vir-Exploit.JS.Pdfka.azg'/><category term='conferences'/><category term='- MS WORD 2000 SP3'/><category term='- OSX'/><category term='vir- Exploit:Win32/Pdfjsc.CW'/><category term='vir-Bifrose'/><category term='Vir-Exploit:Win32/Pidief.S'/><category term='vir-Exploit:W32/Pidief.CKZ'/><category term='Vir-Mal/JSShell-B'/><category term='- ADOBE READER + ACROBAT 8.1.3'/><category term='CVE-2007-0071'/><category term='Rustock'/><category term='- MS OFFICE 2011 MAC'/><category term='vir- PDF/Obfusc.MCamelot'/><category term='Vir-Exploit:Win32/Pdfdrop.A'/><category term='CVE-2009-1129'/><category term='vir-Exploit.Win32.Pidief.bxf'/><category term='Vir-Exploit.JS.Pdfka.amp'/><category term='vir-Exploit:JS/Heapspray'/><category term='Tutorial'/><category term='Backdoor.Olyx'/><category term='Vir-Exploit.Pidief.ban'/><category term='Vir-Script.Silly.Gen'/><category term='vir-Mal/Emogen-Y'/><category term='cve-2010-3333'/><category term='- ADOBE READER + ACROBAT 9.2'/><category term='CVE-2010-3970'/><category term='jsp-reverse'/><category term='Vir-Exploit-PDF.t'/><category term='vir-Trojan.Script.256073'/><category term='CVE-2006-2492'/><category term='Vir-Expl_ShellCodeSM'/><category term='php-backdoor'/><category term='Vir-Exploit.PDF-JS.Gen (v)'/><category term='CVE-2010-0188'/><category term='Gh0stnet backdoor'/><category term='Banking Trojans'/><category term='- Win Srv03 SP2'/><category term='Vir-Exploit.Win32.Pidief.cwq'/><category term='cmdjsp'/><category term='Vir-SWF.HeapSpray.B'/><category term='- Win 7'/><category term='vir-Exploit:Win32/Pdfjsc.CW'/><category term='- MS WORD 2003 SP1'/><category term='- MS OFFICE 2003 SP2'/><category term='2011-2100'/><category term='Vir-Troj/PDFJs-FA'/><category term='vir-Exploit.Cosmu.A'/><category term='DeepEnd'/><category term='CVE-2011-0609'/><category term='Vir-Troj/DwnLdr-IAE; Samples'/><category term='louisvilleheartsurgery.com'/><category term='Vir-Trojan.Pidief.C'/><category term='0-Day - 1st'/><category term='- ADOBE READER 9.4 (w FLASH vuln)'/><category term='- MS OFFICE XP SP3'/><category term='Vir-Troj/PDFJs-B'/><category term='cmdasp'/><category term='RTLO'/><category term='Vir-Exploit:Win32/ShellCode.A'/><category term='Aurora'/><category term='- MS OFFICE 2003 SP1'/><category term='PDF cuckoo'/><category term='phishing'/><category term='vir-JS/CVE20100806.Bexploit'/><category term='vir-Exploit.MSExcel.AgentIK'/><category term='louisvilleheartsurgery.com; taidoor'/><category term='- ADOBE READER + ACROBAT 7.1.0'/><category term='- MS WORD 2003 SP2'/><category term='CVE-2009-3129'/><category term='- MS WORD 2002'/><category term='Vir-Silly.Gen'/><category term='Vir-Trojan:Win32/Vundo.genL'/><category term='vir-Exploit.JS.Pdfka.bvz'/><category term='CVE-2009-0658'/><category term='vir- Troj/PDFJs-II'/><category term='Black SEO'/><category term='CVE-2009-4324'/><category term='vir-Exploit.JS.Pdfka.bdm'/><category term='Vir-Trojan.Script.237170'/><category term='CVE-2006-2389'/><category term='CVE-2008-0655'/><category term='gmail'/><category term='CVE-2009-0556'/><category term='- MS OFFICE 2010'/><category term='vir-JS:Pdfka-AEE'/><category term='Vir-Exploit:Win32/Pdfjsc.CO'/><category term='vir-Troj/PDFJs-II'/><category term='Samples;- MS WORD 2000'/><category term='Vir-Win32/Spy.Silon.AA'/><category term='- HTA files'/><category term='vir-Trojan:Win32/Tapaoux.A'/><category term='vir-Exploit-MSExcel.h'/><category term='- MS OPEN XML CONVERTER MAC'/><category term='Sender IPs'/><category term='Vir-Trojan-GameThief.Win32.OnLineGames.bmxa'/><category term='CVE-2009-3957'/><category term='- MS EXCEL 2007 SP3'/><category term='Vir-Script.Vir-Exploit.JS.Pdfka.auv'/><category term='exploit pack'/><category term='vir-Exploit:Win32/Pdfjsc.FI'/><category term='Vir-Exploit-PDF.aa'/><category term='Vir-Exploit.MSWord.Agent.ac'/><category term='CVE-2009-0806'/><category term='CVE-2010-1297'/><category term='- ADOBE READER + ACROBAT 8.1.7'/><category term='vir-JS.Crypt.UQBF'/><category term='Vir-Trojan.SWF.HeapSpray.B'/><category term='Vir-Exploit:W32/AdobeReader.UZ'/><category term='vir-Exploit.JS.Pdfka.bex'/><category term='vir-Exploit:Win32/Pdfjsc.DC'/><category term='CVE-2010-1240'/><category term='Vir-Exploit.JS.Pdfka.adn'/><category term='vir-Troj/PDFJS-BX'/><category term='Vir - Arugizer'/><category term='TDL'/><category term='CVE-2010-1885'/><category term='chm'/><category term='-  MS EXCEL 2007 SP2'/><category term='- Win Srv08 SP2'/><category term='Vir-Exploit.PDF-JBIG2Decode.Gen'/><category term='Defcon18'/><category term='malware samples links'/><category term='- OFFICE 2004 MAC'/><category term='CVE-2011-2462'/><category term='cuckoo sandbox'/><category term='RAT'/><category term='vir-Bloodhound.PDFgen'/><category term='CVE-2008-2992'/><category term='Vir-Exploit:W32/Pidief.JC'/><category term='ransomware'/><category term='APT'/><category term='- MS POWERPOINT 2002 SP3'/><category term='- ADOBE FLASH PLAYER 10.1.85.3'/><category term='vir-Exploit.JS.Pdfka.bui'/><category term='- CMDEXPLOITS'/><category term='vir-Troj/PDFJs-GQ'/><category term='- MS POWERPOINT 2003 SP3'/><category term='- ADOBE READER + ACROBAT 9.0'/><category term='CVE-2011-0611'/><category term='- RAR + ZIP'/><category term='certificate'/><category term='taidoor'/><category term='- WORDPAD'/><category term='mebromi'/><category term='Rootkit ZeroAccess (aka MAX++)'/><category term='Vir-MSExcel/Dropper.B Camelot'/><category term='- MS EXCEL 2007 SP2'/><category term='Vir-Exploit.PDF-JS.Gen'/><category term='**File-Analysis**'/><category term='CVE-2009-0927'/><category term='vir-TROJ_POWPOINT.A'/><category term='Android.FakePlayer.A'/><category term='- MS OFFICE 2000 SP3'/><category term='Vir-Troj/PDFJs-FV'/><category term='- MS EXCEL 2002 SP3'/><category term='Vir-Exploit.Win32.Pidief.cxi'/><category term='vir- Bloodhound.Exploit.288'/><category term='Vir-Conficker/Downadup/Kido'/><category term='Vir-BKDR_POISON.SME'/><category term='Vir-Trojan.Pidief.H'/><category term='- MS POWERPOINT 2000 SP3'/><category term='Win32/Ramnit'/><category term='JS.Pdfka.bzh'/><category term='CVE-2011-1991'/><category term='vir- Troj/PDFJs-GQ'/><category term='-  MS OFFICE 2004 MAC'/><category term='- JAVA'/><category term='- MS WORD XP SP3'/><category term='CVE-2008-4841'/><category term='vir-Exploit.samples'/><category term='Mobile Malware Group'/><category term='- MS OFFICE  2007 SP2'/><category term='vir-JS/Exploit.Pdfka.NPK'/><category term='vir-Exploit-PDF.by'/><category term='Vir-Troj/PDFEx-CB'/><category term='- ADOBE READER + ACROBAT 8.2.1'/><category term='vir-JS:Pdfka-VO'/><category term='trojan.osx.boonana.a'/><category term='malware links'/><category term='Vir-Trojan.Pidief.J'/><category term='shylock'/><category term='CONFICKER'/><category term='Vir-Exploit-PDF.q.gen stream'/><category term='-MS OFFICE 2003 SP3'/><category term='CVE-2008-0081'/><category term='vir-Trojan.Conficker.c.gen'/><category term='- MOBILE MALWARE'/><category term='- ADOBE FLASH PLAYER 10.1.95.2 ANDROID'/><category term='vir- JS:Pdfka-WJ'/><category term='Stuxnet'/><category term='vir-Exploit:W32/Pidief.CND'/><category term='Vir-Bloodhound.Exploit.288'/><category term='- Win Srv08 R2'/><category term='worm;Qakbot'/><category term='vir- JS:Pdfka-VO'/><category term='vir- Troj/PDFJs-B'/><category term='- OFFICE 2008 MAC'/><category term='- MS COMPAT PACK 2007 SP1 AND SP2'/><category term='Vir-Exploit.JS.Pdfka.ajt'/><category term='- ADOBE READER + ACROBAT 9.3.0'/><category term='- Win Vista SP1-2'/><category term='Zeus'/><category term='Vir-HTML/Shellcode'/><category term='Vir-Win32.PoisonIvy.c'/><category term='Vir-Exploit.SWF.Agent.ci'/><category term='I2p'/><category term='Vir-Exploit.JS.Pdfka.ayb'/><category term='Black Hat'/><category term='vir-Exploit:Win32/Pdfjsc.genA'/><category term='Targeted attacks - about'/><category term='C02'/><category term='vir-Exploit-PDF.q.genstream'/><category term='Vir-MSWord/Dropper.B Camelot'/><category term='TWITTER'/><title type='text'>contagio</title><subtitle type='html'>malware dump</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default?start-index=101&amp;max-results=100'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>327</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-3042890044816774218</id><published>2012-01-28T02:42:00.001-05:00</published><updated>2012-01-28T08:49:21.957-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack'/><title type='text'>An Overview of Exploit Packs (Update 15) January  28,  2012</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="background-color: #fff2cc;"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Version 15. January 28, 2012&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?5py1060a4cse6xr"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;The full table in xls format - Version 15 can be downloaded from here.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?sg9i3vvx6vxrez1"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;xlsx format&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;in csv format &lt;a href="http://www.mediafire.com/?qaccb481nv1qgov"&gt;Packs Sheet&lt;/a&gt; 1&amp;nbsp; &lt;a href="http://www.mediafire.com/?aa615ge53mh64sf"&gt;References sheet&lt;/a&gt; 2&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Additions - with many thanks to Kahu Security&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;Hierarchy Exploit Pack&lt;br /&gt;=================&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;CVE-2006-0003&lt;br /&gt;CVE-2009-0927&lt;br /&gt;CVE-2010-0094&lt;br /&gt;CVE-2010-0188&lt;br /&gt;CVE-2010-0806&lt;br /&gt;CVE-2010-0840&lt;br /&gt;CVE-2010-1297&lt;br /&gt;CVE-2010-1885&lt;br /&gt;CVE-2011-0611&lt;br /&gt;JavaSignedApplet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Siberia Private&lt;br /&gt;==========&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;CVE-2005-0055&lt;br /&gt;CVE-2006-0003&lt;br /&gt;CVE-2007-5659&lt;br /&gt;CVE-2008-2463&lt;br /&gt;CVE-2008-2992&lt;br /&gt;CVE-2009-0075&lt;br /&gt;CVE-2009-0927&lt;br /&gt;CVE-2009-3867&lt;br /&gt;CVE-2009-4324&lt;br /&gt;CVE-2010-0806&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Techno XPack&lt;br /&gt;===========&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;CVE-2008-2992&lt;br /&gt;CVE-2010-0188&lt;br /&gt;CVE-2010-0842&lt;br /&gt;CVE-2010-1297&lt;br /&gt;CVE-2010-2884&lt;br /&gt;CVE-2010-3552&lt;br /&gt;CVE-2010-3654&lt;br /&gt;JavaSignedApplet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"Yang Pack"&lt;br /&gt;=========&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;CVE-2010-0806&lt;br /&gt;CVE-2011-2110&lt;br /&gt;CVE-2011-2140&lt;br /&gt;CVE-2011-354&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="background-color: #fff2cc;"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Version 14. January 19, 2012&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-pC69XYK_UXg/TxfHkKwzVXI/AAAAAAAAC4Y/uX2xrryCEM8/s1600/ww.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-pC69XYK_UXg/TxfHkKwzVXI/AAAAAAAAC4Y/uX2xrryCEM8/s400/ww.jpg" width="87" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Version 14 Exploit Pack table additions:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Credits for the excellent &lt;a href="http://www.kahusecurity.com/2011/wild-wild-west-%E2%80%93-102011/"&gt;Wild Wild West (October 2011 edition) go to &lt;/a&gt;&lt;b&gt;&lt;a href="http://www.kahusecurity.com/2011/wild-wild-west-%E2%80%93-102011/"&gt;kahusecurity.com&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;With many thanks to&amp;nbsp; &lt;a href="http://xylibox.blogspot.com/"&gt;XyliBox (Xylitol - Steven),&amp;nbsp; &lt;/a&gt;&lt;a href="http://malwareint.blogspot.com/"&gt;Malware Intelligence blog&lt;/a&gt;,&amp;nbsp; and xakepy.cc for the information:&lt;br /&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;blockquote class="tr_bq"&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Blackhole 1.2.1&lt;/b&gt;&amp;nbsp; (Java Rhino added, weaker Java exploits removed)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Blackhole 1.2.1 &lt;/b&gt;(Java Skyline added)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Sakura Exploit Pack 1.0&amp;nbsp;&lt;/b&gt; (new kid on the block, private pack)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Phoenix 2.8. mini&lt;/b&gt; (condensed version of 2.7)&lt;/li&gt;&lt;li&gt;&lt;b&gt;Fragus Black&lt;/b&gt; (weak Spanish twist on the original, black colored admin panel, a few old exploits added) &lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;If you find any errors or CVE information for packs not featured , please send it to my email (in my profile above, thank you very much) . &lt;br /&gt;&lt;table border="0" cellpadding="0" cellspacing="0" style="width: 374px;"&gt;&lt;tbody&gt;&lt;tr height="33"&gt;&lt;td class="xl65" height="33" style="height: 24.75pt; width: 281pt;" width="374"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" height="33" style="height: 24.75pt; width: 281pt;" width="374"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" height="33" style="height: 24.75pt; width: 281pt;" width="374"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" height="33" style="height: 24.75pt; width: 281pt;" width="374"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Oe40NsNAbyg/Txe-5dhrkFI/AAAAAAAAC4I/CMA8JGXF1OU/s1600/bh.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="77" src="http://3.bp.blogspot.com/-Oe40NsNAbyg/Txe-5dhrkFI/AAAAAAAAC4I/CMA8JGXF1OU/s200/bh.GIF" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/--Tgm5I_IyyE/Txe9Ov4VWWI/AAAAAAAAC34/TmJc5vm8cgk/s1600/mini.GIF" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/--Tgm5I_IyyE/Txe9Ov4VWWI/AAAAAAAAC34/TmJc5vm8cgk/s1600/mini.GIF" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-kzmLGS3ZAeI/Txe9_y0EyVI/AAAAAAAAC4A/c7f_Cb6PWzg/s1600/sak.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-kzmLGS3ZAeI/Txe9_y0EyVI/AAAAAAAAC4A/c7f_Cb6PWzg/s1600/sak.GIF" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-VBZ_rZtwX1g/TxfGJjeRHHI/AAAAAAAAC4Q/H8Ye1PBbcg4/s1600/f.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-VBZ_rZtwX1g/TxfGJjeRHHI/AAAAAAAAC4Q/H8Ye1PBbcg4/s1600/f.GIF" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;The full table in xls format - Version 14 can be downloaded from here.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?9t6fq3m9juv4978"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;The exploit pack table in XLSX format&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?ohpv66qbx3e1bgd"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;The exploit pack table in csv format&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;a href="http://www.mediafire.com/?jhj1u2twkdvymfh"&gt;&lt;span style="font-size: small;"&gt;The references sheet in csv format&amp;nbsp;&lt;/span&gt;&lt;/a&gt; &lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-size: small;"&gt;P.S. There are always corrections and additions thanks to your feedback after the document release, come back in a day or two to check in case v.15 is out.&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-g8MACkJFPyw/Tk_nhS-sxaI/AAAAAAAACf8/Z2zuvO5cO70/s1600/zero.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc;"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Version 13. Aug 20, 2011&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Z2tNroOLH7Y/Tk_wLpLSxwI/AAAAAAAACgE/qGLljC41epE/s1600/wildwildwest_0811.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;a href="http://www.kahusecurity.com/2011/wild-wild-west-%E2%80%93-082011/"&gt;Kahusecurity issued an updated version of their Wild Wild West graphic&lt;/a&gt; that will help you learn Who is Who in the world of exploit packs. You can view the full version of their post in the link above.&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Version 13 exploit pack table additions:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ol&gt;&lt;li&gt;Bleeding Life 3.0&lt;/li&gt;&lt;li&gt;Merry Christmas Pack &lt;a href="http://www.kahusecurity.com/2011/christmas-pack-in-july/"&gt;&lt;i&gt;(&lt;span style="font-size: small;"&gt;many thanks to kahusecurity.com)+&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Best Pack &lt;a href="http://www.kahusecurity.com/2011/best-pack/"&gt;&lt;i&gt;(&lt;span style="font-size: small;"&gt;many thanks to kahusecurity.com)&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt; Sava Pack &lt;a href="http://www.kahusecurity.com/2011/sava-exploits-pack/"&gt;&lt;i&gt;(&lt;span style="font-size: small;"&gt;many thanks to kahusecurity.com)&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;LinuQ&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Eleonore 1.6.5&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Zero Pack &lt;/li&gt;&lt;li&gt;Salo Pack (incomplete but it is also old)&lt;/li&gt;&lt;/ol&gt;&lt;b&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border: 3px solid green; height: 320px; overflow: auto; text-align: left; width: 450px;"&gt;&lt;span style="color: black;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;List of packs in the table in alphabetical order&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Best Pack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Blackhole Exploit 1.0&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Blackhole Exploit 1.1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Bleeding Life 2.0&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Bleeding Life 3.0 &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Bomba&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;CRIMEPACK 2.2.1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;CRIMEPACK 2.2.8&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;CRIMEPACK 3.0&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;CRIMEPACK 3.1.3&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Dloader&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;EL Fiiesta&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.3.2&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.4.1 &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.4.4 Moded&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.6.3a&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.6.4&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Eleonore 1.6.5 &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Fragus 1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Icepack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Impassioned Framework 1.0&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Incognito&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;iPack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;JustExploit&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Katrin&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Merry Christmas Pack &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Liberty&amp;nbsp; 1.0.7&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Liberty 2.1.0*&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;LinuQ pack &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Lupit&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Mpack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Mushroom/unknown&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Open Source Exploit (Metapack)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Papka&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix&amp;nbsp; 2.0&amp;nbsp; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.2&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.3&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.4&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.5&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Phoenix 2.7&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Robopak&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Salo pack &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Sava Pack &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;SEO Sploit pack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Siberia&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;T-Iframer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Unique Pack Sploit 2.1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Webattack&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Yes Exploit 3.0RC&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Zero Pack &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Zombie Infection kit &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: black;"&gt;Zopack&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;&lt;span style="color: red;"&gt;Bleeding Life 3.0 &lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.opensc.ws/unverified-listings/16175-bleedinglife-3-0-free-updates-amazing-features.html"&gt;New Version Ad is here&amp;nbsp;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-WAaUnYiYnBI/Tk_6pjHMsoI/AAAAAAAACgM/FR76Ig7vNss/s1600/bleeding+life.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-WAaUnYiYnBI/Tk_6pjHMsoI/AAAAAAAACgM/FR76Ig7vNss/s1600/bleeding+life.JPG" style="color: red;" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;table border="1" cellpadding="2" cellspacing="2" style="height: 116px; text-align: left; width: 605px;"&gt;  &lt;tbody&gt;&lt;tr&gt;      &lt;td&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;Merry Christmas Pack&lt;/div&gt;read analysis at&lt;br /&gt;&lt;a href="http://www.kahusecurity.com/2011/christmas-pack-in-july/"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;kahusecurity.com&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rL9rmKHdT-U/Tk_lZl8DNSI/AAAAAAAACfk/W8bww0I9DXg/s1600/merryxmaspack.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="41" src="http://1.bp.blogspot.com/-rL9rmKHdT-U/Tk_lZl8DNSI/AAAAAAAACfk/W8bww0I9DXg/s200/merryxmaspack.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/td&gt;      &lt;td&gt;&lt;div style="background-color: white; color: red;"&gt;Best Pack&lt;br /&gt;&lt;span style="color: black;"&gt;read analysis at&amp;nbsp;&lt;/span&gt; &lt;i&gt;&lt;/i&gt;&lt;/div&gt;&lt;a href="http://www.kahusecurity.com/2011/best-pack/"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;kahusecurity.com&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-e-zuVmqHhYY/Tk_lvisYgTI/AAAAAAAACfo/24KF-05mHhE/s1600/bestp.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="78" src="http://1.bp.blogspot.com/-e-zuVmqHhYY/Tk_lvisYgTI/AAAAAAAACfo/24KF-05mHhE/s200/bestp.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/td&gt;      &lt;td&gt;&lt;span style="color: red;"&gt;Sava Pack &lt;/span&gt;&lt;br /&gt;read analysis at&lt;br /&gt;&lt;a href="http://www.kahusecurity.com/2011/sava-exploits-pack/"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;kahusecurity.com&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RjAUfenKn4Q/Tk_l_Q5ixbI/AAAAAAAACfs/X4y7wEK_ass/s1600/sava.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="65" src="http://3.bp.blogspot.com/-RjAUfenKn4Q/Tk_l_Q5ixbI/AAAAAAAACfs/X4y7wEK_ass/s200/sava.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/td&gt;    &lt;/tr&gt;&lt;tr&gt;      &lt;td&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;Eleonore 1.6.5&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: black;"&gt;[+] CVE-2011-0611&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: black;"&gt;[+] &lt;/span&gt;&lt;/span&gt;&lt;span style="color: black;"&gt;CVE-2011-0559&lt;br /&gt;[+] CVE-2010-4452 &lt;br /&gt;[-] CVE-2010-0886 &lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-WMc_Kl-Pr3c/Tk_m5bL4SQI/AAAAAAAACfw/L58futRiQGk/s1600/eleonore.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="78" src="http://1.bp.blogspot.com/-WMc_Kl-Pr3c/Tk_m5bL4SQI/AAAAAAAACfw/L58futRiQGk/s200/eleonore.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/td&gt;      &lt;td&gt;&lt;span style="color: red;"&gt;Salo Pack&lt;/span&gt;&lt;br /&gt;Old (2009), added just for &lt;br /&gt;the collection&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-pBChxiYk7po/Tk_nTEYp9xI/AAAAAAAACf4/kSGhKPuIY-0/s1600/salo.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-pBChxiYk7po/Tk_nTEYp9xI/AAAAAAAACf4/kSGhKPuIY-0/s1600/salo.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-0ycDqITnJ9w/Tk_nBeH6_YI/AAAAAAAACf0/EtY-boPRe5E/s1600/zero.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/td&gt;&lt;td&gt;&lt;span id="goog_936959925"&gt;&lt;/span&gt;&lt;span id="goog_936959926"&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Zero Pack&lt;/span&gt;&lt;br /&gt;62 exploits from various packs (mostly Open Source pack)&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-g8MACkJFPyw/Tk_nhS-sxaI/AAAAAAAACf8/Z2zuvO5cO70/s1600/zero.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="93" src="http://4.bp.blogspot.com/-g8MACkJFPyw/Tk_nhS-sxaI/AAAAAAAACf8/Z2zuvO5cO70/s200/zero.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;    &lt;/tr&gt;&lt;tr&gt;      &lt;td colspan="3" rowspan="1"&gt;&lt;div style="color: red;"&gt;LinuQ pack&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-g5fLPumP9K4/Tk_vHplvvrI/AAAAAAAACgA/AAUZrqhw8bg/s1600/linuq.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-g5fLPumP9K4/Tk_vHplvvrI/AAAAAAAACgA/AAUZrqhw8bg/s1600/linuq.png" /&gt;&lt;/a&gt;&lt;/div&gt;Designed to compromise linux servers using vulnerable PHPMyAdmin. Comes with DDoS bot but any kind of code can be loaded for Linux botnet creation.&lt;br /&gt;LinuQ pack is PhpMyAdmin exploit pack with 4 PMA exploits based on a previous Russian version of the Romanian PMA &lt;a href="http://linux.m2osw.com/zmeu-attack"&gt;scanner ZmEu&lt;/a&gt;. it is not considered to be original, unique, new, or anything special. All exploits are public and known well.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is designed to be installed on an IRC server (like UnrealIRCD). IP ranges already listed in bios.txt can be scanned, vulnerable IPs and specific PMA vulnerabilities will be listed in vuln.txt, then the corresponding exploits can be launched against the vulnerable server. It is more like a bot using PMA vulnerabilities than exploit pack.&lt;br /&gt;It is using &lt;br /&gt;CVE-2009-1148 (unconfirmed)&lt;br /&gt;CVE-2009-1149 (unconfirmed)&lt;br /&gt;CVE-2009-1150 (unconfirmed)&lt;br /&gt;CVE-2009-1151 (confirmed)&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;    &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-owOLIUV52Bs/Tk_x_2NjzII/AAAAAAAACgI/MIByQEM9aa8/s1600/sshot.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://3.bp.blogspot.com/-owOLIUV52Bs/Tk_x_2NjzII/AAAAAAAACgI/MIByQEM9aa8/s400/sshot.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;====================================================================&lt;br /&gt;&lt;div style="background-color: white; color: yellow;"&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div style="background-color: white; color: black;"&gt;&lt;div style="background-color: white;"&gt;&lt;div style="background-color: white;"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Version 12. May 26, 2011&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; additional changes (many thanks to kahusecurity.com)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #274e13;"&gt;&lt;b&gt;Bomba&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;b&gt;&lt;span style="color: #274e13;"&gt;Papka&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #274e13;"&gt;See the list of packs covered in the list below &lt;/span&gt;&lt;b&gt;&lt;span style="color: #274e13;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;a href="http://www.mediafire.com/?wnd4lzfh4zmqd0k"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;The full table in xls format - Version 12 can be downloaded from here.&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="background-color: white;"&gt;I want to thank everyone who sent packs and information&amp;nbsp; :)&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;a href="http://4.bp.blogspot.com/-ak7APYj6sIs/Td3vo88DImI/AAAAAAAAB_Q/qmXPR_GUNsw/s1600/hh.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="155" src="http://4.bp.blogspot.com/-ak7APYj6sIs/Td3vo88DImI/AAAAAAAAB_Q/qmXPR_GUNsw/s200/hh.bmp" width="200" /&gt;&lt;/a&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Version 11 &lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;b&gt;May 26, 2011 Changes: &lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;ol&gt;&lt;/ol&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://2.bp.blogspot.com/-_rlHXFcYpuo/Td3v3I8QDlI/AAAAAAAAB_Y/JsO8sBd2gzg/s1600/sshot.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="125" src="http://2.bp.blogspot.com/-_rlHXFcYpuo/Td3v3I8QDlI/AAAAAAAAB_Y/JsO8sBd2gzg/s200/sshot.JPG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ol&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;Phoenix2.7&lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;"&lt;/b&gt;&lt;i&gt;Dloader&lt;/i&gt;&lt;b&gt;" &lt;/b&gt;(well, dloader is a loader but the pack is&amp;nbsp; some unnamed pack &lt;a href="http://damagelab.org/lofiversion/index.php?t=20852"&gt;http://damagelab.org/lofiversion/index.php?t=20852&lt;/a&gt;&lt;b&gt;)&lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;nuclear pack&lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;Katrin &lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;Robopak&lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;Blackhole exploit kit 1.1.0&lt;/b&gt;&lt;/li&gt;&lt;li style="color: #274e13;"&gt;&lt;b&gt;Mushroom/unknown&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span style="color: #274e13;"&gt;Open Source Exploit kit&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-UPw_m8_E_EY/Td3vvAXuvJI/AAAAAAAAB_U/I_3j18Xwi9Y/s1600/sshot.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="193" src="http://4.bp.blogspot.com/-UPw_m8_E_EY/Td3vvAXuvJI/AAAAAAAAB_U/I_3j18Xwi9Y/s200/sshot.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;left&gt;&lt;/left&gt;&lt;br /&gt;&lt;br /&gt;====================================================================&lt;br /&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;b&gt;10. May 8, 2011 Version 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit Pack Table_V10May11&lt;/b&gt;&lt;br /&gt;First, I want to thank everyone who sent and posted comments for updates and corrections.&amp;nbsp; &lt;/div&gt;&lt;br /&gt;&lt;b&gt;*** The Wild Wild West picture is from a great post about evolution of exploit packs by Kahu Security&amp;nbsp; &lt;a href="http://www.kahusecurity.com/2011/wild-wild-west-update"&gt;Wild Wild West Update&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?jj6830olq6lvxs2"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;As usual, send your corrections and update lists.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white; color: black;"&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;a href="http://1.bp.blogspot.com/-FjyildKNe8c/TcbcBxKhDtI/AAAAAAAAB-o/9zL9NpmnlnM/s1600/384x1500xwildwildwest_0511.jpg.pagespeed.ic.pw5QWio8Au.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-FjyildKNe8c/TcbcBxKhDtI/AAAAAAAAB-o/9zL9NpmnlnM/s640/384x1500xwildwildwest_0511.jpg.pagespeed.ic.pw5QWio8Au.jpg" width="162" /&gt;&lt;/a&gt; Changes: &lt;/div&gt;&lt;blockquote&gt;&lt;blockquote&gt;&lt;ul&gt;&lt;li&gt;Eleonore 1.6.4&lt;/li&gt;&lt;li&gt;Eleonore 1.6.3a&lt;/li&gt;&lt;li&gt;Incognito&lt;/li&gt;&lt;li&gt;Blackhole&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;i style="color: #783f04;"&gt;Go1Pack&lt;/i&gt;&lt;i&gt;&lt;span style="color: #783f04;"&gt;&amp;nbsp; &lt;/span&gt;(not included) as reported as being a fake pack, here is a &lt;a href="http://internetpol.fr/wup/analysis/images/83c7f1fce3515083fff97e05a886fcb9.png"&gt;gui&lt;/a&gt;. Here is a threatpost article &lt;a href="http://threatpost.com/en_us/blogs/popular-sports-site-goalcom-serves-malware-050311"&gt;referencing it as it was used for an attack&amp;nbsp;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Also, here is another article claiming it is not a fake &lt;a href="http://community.websense.com/blogs/securitylabs/archive/2011/04/19/Mass-Injections-Leading-to-g01pack-Exploit-Kit.aspx"&gt;http://community.websense.com/blogs/securitylabs/archive/2011/04/19/Mass-Injections-Leading-to-g01pack-Exploit-Kit.aspx&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Go1 Pack CVE are reportedly&lt;/i&gt;&lt;br /&gt;&lt;i&gt;CVE-2006-0003&lt;br /&gt;CVE-2009-0927&lt;br /&gt;CVE-2010-1423&lt;br /&gt;CVE-2010-1885&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Does anyone have this pack or see it offered for sale?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Exploit kits I am planning to analyze and add (and/or find CVE listing for) are:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt; Open Source Exploit Kit &lt;/li&gt;&lt;li&gt;SALO&lt;/li&gt;&lt;li&gt;K0de&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="background-color: white;"&gt;&lt;b&gt;Legend:&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Black color entries by Francois Paget&lt;/div&gt;&lt;div&gt;&lt;span style="color: red;"&gt;Red&lt;/span&gt; color entries by Gunther&lt;/div&gt;&lt;div&gt;&lt;span style="color: blue;"&gt;Blue&lt;/span&gt; color entries by Mila&lt;/div&gt;&lt;br /&gt;Also, here is a great presentation by Ratsoul (Donato Ferrante) about Java Exploits &lt;b&gt;(&lt;a href="http://www.inreverse.net/?p=1687"&gt;http://www.inreverse.net/?p=1687&lt;/a&gt;)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;&amp;nbsp;&lt;b&gt;9.&amp;nbsp; April 5, 2011&amp;nbsp; Version 9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ExploitPackTable_V9Apr11&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;It actually needs another update but I am posting it now and will issue version 10 as soon as I can.&lt;br /&gt;&lt;br /&gt;Changes:&lt;br /&gt;Phoenix 2.5&lt;br /&gt;IFramer&lt;br /&gt;Tornado&lt;br /&gt;Bleeding life&lt;br /&gt;&lt;br /&gt;Many thanks to Gunther for his contributions.&lt;br /&gt;If you wish to add some, please send your info together with the reference links. Also please feel free to send corrections if you notice any mistakes&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Zh5HJeHQqSE/TcfMr_5R-2I/AAAAAAAAB-4/peDP_JYdxKw/s1600/pack.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="247" src="http://1.bp.blogspot.com/-Zh5HJeHQqSE/TcfMr_5R-2I/AAAAAAAAB-4/peDP_JYdxKw/s400/pack.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-NqjWxxoUV4w/TcbvrVU2eMI/AAAAAAAAB-w/5EKLmnQPuQc/s1600/incognito.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="55" src="http://4.bp.blogspot.com/-NqjWxxoUV4w/TcbvrVU2eMI/AAAAAAAAB-w/5EKLmnQPuQc/s200/incognito.bmp" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-a4fxAeKyoXU/Tcbv5eCmPtI/AAAAAAAAB-0/36aWAQ4780E/s1600/bh.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="51" src="http://1.bp.blogspot.com/-a4fxAeKyoXU/Tcbv5eCmPtI/AAAAAAAAB-0/36aWAQ4780E/s200/bh.PNG" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_xQabPlo6k5s/TKAidbngEQI/AAAAAAAABuE/w1BJopfH-kk/s1600/sshot.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;i style="color: #999999;"&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #999999;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;b style="background-color: white;"&gt;8. Update 8 Oct 22, 2010 Version 8 &lt;/b&gt;&lt;b&gt;&lt;span style="background-color: white;"&gt;Exp&lt;/span&gt;loitPackTable_V8Oct22-10&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;b&gt;Changes:&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://4.bp.blogspot.com/_xQabPlo6k5s/TMGB_91JomI/AAAAAAAABvU/8JKjnuL_cMs/s1600/seo.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="96" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TMGB_91JomI/AAAAAAAABvU/8JKjnuL_cMs/s320/seo.JPG" width="320" /&gt;&lt;/a&gt;&lt;a bitly="BITLY_PROCESSED" href="http://3.bp.blogspot.com/_xQabPlo6k5s/TL93KRYl0LI/AAAAAAAABvQ/vZfHRDT9WbA/s1600/weleonore.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="52" src="http://3.bp.blogspot.com/_xQabPlo6k5s/TL93KRYl0LI/AAAAAAAABvQ/vZfHRDT9WbA/s320/weleonore.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;ol style="background-color: white;"&gt;&lt;li&gt;&lt;b&gt;Eleonore 1.4.4&lt;/b&gt; Moded added (thanks to &lt;a href="http://malwareint.blogspot.com/"&gt;malwareint.blogspot.com&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Correction&lt;/span&gt; &lt;/b&gt;on CVE-2010-0746 in Phoenix 2.2 and 2.3. It is a mistake and the correct CVE is &lt;span class="status-body"&gt;&lt;span class="status-content"&gt;&lt;span class="entry-content"&gt;CVE-2010-0886&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; (thanks to &lt;div class="t5" id=":1jw" style="display: none;"&gt;&lt;span id=":1k3" style="display: none;"&gt;♫ &lt;/span&gt;&lt;/div&gt;etonshell for noticing)&lt;span class="status-body"&gt;&lt;span class="status-content"&gt;&lt;span class="entry-content"&gt;&lt;a class="tweet-url username" href="http://twitter.com/pumociiip" rel="http://s.bit.ly/preview.twittername.iframe.html?twittername=pumociiip"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;SEO Sploit pack&lt;/b&gt; added (thanks to &lt;a href="http://whsbehind.blogspot.com/"&gt;whsbehind.blogspot.com,&lt;/a&gt;&amp;nbsp; &lt;a href="http://evilcodecave.blogspot.com/"&gt;evilcodecave.blogspot.com&lt;/a&gt; and &lt;a href="http://blog.ahnlab.com/"&gt;blog.ahnlab.com&lt;/a&gt;)&lt;/li&gt;&lt;/ol&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;b&gt;7. Update 7 Oct 18, 2010 Version 7 &lt;/b&gt;&lt;b&gt;ExploitPackTable_V7Oct18-10 released&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&amp;nbsp;thanks to &lt;a bitly="BITLY_PROCESSED" href="http://secniche.blogspot.com/2010/10/phoenix-exploit-kit-24-analysis.html"&gt;SecNiche&lt;/a&gt; &lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;we have updates for Phoenix 2.4 :)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;We also added shorthand/slang/abbreviated names for exploits for easy matching of exploits to CVE in the future. Please send us more information re packs, exploit names that can be added in the list. Thank you!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://4.bp.blogspot.com/_xQabPlo6k5s/TKDQfZSgRDI/AAAAAAAABuI/hdVkdzx0OPI/s1600/kit.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="70" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TKDQfZSgRDI/AAAAAAAABuI/hdVkdzx0OPI/s320/kit.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp; &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;6. Update 6 Sept 27, 2010 Version 6 &lt;/b&gt;&lt;b&gt;ExploitPackTable_V6Sept26-10 released&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;span style="background-color: white;"&gt;Thanks to Francois Paget (McAfee) we have updates for Phoenix 2.2 and Phoenix 2.3&lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;b&gt;5. Update 5. Sept 27, 2010 Version 5 ExploitPackTable_V5Sept26-10 released&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;Added updates for Phoenix 2.1 and Crimepack 3.1.3&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://4.bp.blogspot.com/_xQabPlo6k5s/TKAh-JYxrJI/AAAAAAAABuA/dV_XvNry2Cs/s1600/phoenix.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TKAh-JYxrJI/AAAAAAAABuA/dV_XvNry2Cs/s1600/phoenix.JPG" /&gt;&lt;/a&gt;&lt;a bitly="BITLY_PROCESSED" href="http://1.bp.blogspot.com/_xQabPlo6k5s/TKAh9JKbK0I/AAAAAAAABt8/-2FjIMOZ0Wg/s1600/logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xQabPlo6k5s/TKAh9JKbK0I/AAAAAAAABt8/-2FjIMOZ0Wg/s1600/logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;&lt;span style="background-color: white;"&gt;&lt;b&gt;4 Update 4&amp;nbsp; July 23, 2010&amp;nbsp; Version 4 ExploitPackTable_V4Ju23-10 released.&lt;/b&gt; Added a new Russian exploit kit called Zombie Infection Kit to the table. Read more at &lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://malwareview.com/index.php?topic=775"&gt;&lt;span style="background-color: white;"&gt;malwareview.com&lt;/span&gt;&lt;span style="background-color: white;"&gt; &lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://4.bp.blogspot.com/_xQabPlo6k5s/TEkh0kvi5WI/AAAAAAAABfU/kaGOjEaTkyo/s1600/zombie.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="197" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TEkh0kvi5WI/AAAAAAAABfU/kaGOjEaTkyo/s400/zombie.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="background-color: white; color: black;"&gt;&lt;span style="background-color: white;"&gt;U&lt;/span&gt;pdate 3&amp;nbsp; July 7, 2010. Please read more about this on the Brian Krebs' blog&lt;/span&gt;&lt;span style="background-color: white;"&gt; &lt;/span&gt;&lt;a bitly="BITLY_PROCESSED" href="http://krebsonsecurity.com/2010/07/pirate-bay-hack-exposes-user-booty/"&gt;&lt;span style="background-color: white;"&gt;Pirate Bay Hack Exposes User Booty&lt;/span&gt;&lt;/a&gt;&lt;span style="background-color: white; color: #999999;"&gt;&lt;span style="color: black;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="background-color: white; color: #999999;"&gt;&lt;span style="color: black;"&gt;Update 2 June 27, 2010 Sorry but Impassioned Framework is back where it belongs &lt;/span&gt;- &lt;span style="color: blue;"&gt;blue &lt;/span&gt;&lt;/span&gt;&lt;i style="color: #999999;"&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;span style="color: black;"&gt;Update 1 June 24, 2010&lt;/span&gt; &lt;span style="color: black;"&gt;Eleonore 1.4.1 columns was updated to include the correct list of the current exploits.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;Francois Paget&amp;nbsp; www.avertlabs.com kindly agreed to allow us to make additions to his &lt;a bitly="BITLY_PROCESSED" href="http://www.avertlabs.com/research/blog/index.php/2010/05/28/an-overview-of-exploit-packs/"&gt;Overview of Exploit Packs table&lt;/a&gt; published on Avertlabs (McAfee Blog)&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;Many thanks to Gunther from ARTeam for his help with the update. There are a few blanks and question marks, please do no hesitate to email me if you know the answer or if you see any errors.&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://1.bp.blogspot.com/_xQabPlo6k5s/S7Hd9CBxWyI/AAAAAAAAA8A/vMKekJgYrrs/s1600/trashbag.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;a bitly="BITLY_PROCESSED" href="http://www.mediafire.com/?1i8ef7lg79g63q6"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;Please click on the image below to expand it (it is a partial screenshot)&amp;nbsp;&lt;span style="background-color: white; color: #741b47;"&gt; &lt;/span&gt;&lt;strike&gt;&lt;i style="color: #666666;"&gt;Impassioned Framework is tentatively marked a different color because the author claims it is a security audit tool not exploit pack. However, there was no sufficient information provided yet to validate such claims. The pack is temporarily/tentatively marked a different color. We'll keep you posted.&lt;/i&gt;&lt;/strike&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: white;"&gt;&lt;strike&gt;&lt;i style="color: #666666;"&gt; &lt;/i&gt;&lt;/strike&gt;&lt;/div&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="background-color: white; clear: both; text-align: center;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_xQabPlo6k5s/S5D8BSv58-I/AAAAAAAAAvI/jlz6OwsDtg0/s320/bagyellow.jpg" /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-3042890044816774218?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/3042890044816774218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2010/06/overview-of-exploit-packs-update.html#comment-form' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/3042890044816774218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/3042890044816774218'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2010/06/overview-of-exploit-packs-update.html' title='An Overview of Exploit Packs (Update 15) January  28,  2012'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-pC69XYK_UXg/TxfHkKwzVXI/AAAAAAAAC4Y/uX2xrryCEM8/s72-c/ww.jpg' height='72' width='72'/><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-5744146941346663756</id><published>2012-01-12T02:57:00.004-05:00</published><updated>2012-01-13T07:54:47.532-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Win32/Ramnit'/><title type='text'>Blackhole Ramnit - samples and analysis</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="text-align: left;" trbidi="on"&gt;&lt;div style="text-align: left;" trbidi="on"&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-N26qLLPK9vc/Tw6QEj_rtnI/AAAAAAAAC3E/Bxj7hm9jOEg/s1600/bsod1.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-N26qLLPK9vc/Tw6QEj_rtnI/AAAAAAAAC3E/Bxj7hm9jOEg/s1600/bsod1.gif" /&gt;&lt;/a&gt;&lt;/div&gt;Ramnit - a Zeus-like trojan/worm/file infector with rootkit capabilities has been in the wild for a long time but recently made news because &lt;a href="http://blog.seculert.com/2012/01/ramnit-goes-social.html"&gt;Seculert reported about a financial variant of this malware aimed at stealing Facebook credentials. &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;While I did not see any Facebook related activity in my samples, I am posting them anyway for your research as their functionality is the same.&lt;br /&gt;&lt;br /&gt;The samples I have are being spread not via Facebook but via Blackhole exploit kit, which is a very effective method. Blackhole exploit kit was associated with the spread of ZeuS, Spyeye, and it is not surprising that Ramnit is being spread in the same manner by the same groups. The group of command and control servers that I researched is associated with pharma spam and "Canadian" online pharmacies.&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Oa_BKKBRwVs/TwoBDm41egI/AAAAAAAAC08/Vr_Bj1fVpz0/s1600/bsod1.gif" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;div class="date-posts"&gt;&lt;div class="post-outer"&gt;&lt;div class="post hentry"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;General File Information&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;div class="post hentry"&gt;File: 607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;br /&gt;MD5:&amp;nbsp; 607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;br /&gt;&lt;br /&gt;File: c33e7ed929760020820e8808289c240e&lt;br /&gt;MD5:&amp;nbsp; C33E7ED929760020820E8808289C240E&lt;br /&gt;&lt;br /&gt;File: 76991eefea6cb01e1d7435ae973858e6&amp;nbsp;&amp;nbsp; -&amp;nbsp; not analysed&lt;br /&gt;MD5:&amp;nbsp; 76991EEFEA6CB01E1D7435AE973858E6&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;File: 2ff2c8ada4fc6291846f0d66ae57ca37&amp;nbsp; -not analysed&lt;br /&gt;MD5:&amp;nbsp; 2FF2C8ADA4FC6291846F0D66AE57CA37&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Download&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/-i9enzkJQXqk/Tw6R1hr5agI/AAAAAAAAC3M/4AtpQNMDWFQ/s1600/contagiobag.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-i9enzkJQXqk/Tw6R1hr5agI/AAAAAAAAC3M/4AtpQNMDWFQ/s1600/contagiobag.jpg" /&gt;&lt;/a&gt;&lt;a href="http://www.mediafire.com/?baoeomg76zeits7"&gt;Download all the binaries and dropped files as a password protected archive (email me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-MZCmDvqDLgM/Tw6R5KxZokI/AAAAAAAAC3U/pEPiYTwFhuY/s1600/toadstool1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-MZCmDvqDLgM/Tw6R5KxZokI/AAAAAAAAC3U/pEPiYTwFhuY/s1600/toadstool1.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Distribution&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;The files analysed were / are being distributed via Blackhole exploit pack. It starts with the usual large letter message "Please wait page is loading" -then Java exploit launches and compromise takes place if the machine is vulnerable. . Here you can see the Blackhole domains spreading Ramnit in the Malwaredomainlist . &lt;b&gt;Amberfreda.com&lt;/b&gt; domain belongs to a legitimate company and is registered in Arizona, while a subdomain &lt;b&gt;&lt;span style="color: #38761d;"&gt;&lt;span style="color: red;"&gt;best&lt;/span&gt;&lt;span style="color: black;"&gt;.amberfreda.com&lt;/span&gt;&lt;/span&gt;&lt;/b&gt; is registered by some Ukranian guy. Not sure how they managed that.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: #38761d;"&gt;amberfreda.com&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;173.201.97.1&lt;br /&gt;p3nlhg49c090.shr.prod.phx3.secureserver.net&lt;br /&gt;Domains By Proxy, LLC&lt;br /&gt;DomainsByProxy.com&lt;br /&gt;15111 N. Hayden Rd., Ste 160, PMB 353&lt;br /&gt;Scottsdale, Arizona 85260&lt;br /&gt;United States&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: #38761d;"&gt;&lt;span style="color: red;"&gt;best&lt;/span&gt;.amberfreda.com&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;178.162.145.184&lt;br /&gt;178-162-145-184.local&lt;br /&gt;Host unreachable&lt;br /&gt;178.162.145.128 - 178.162.145.255&lt;br /&gt;VPS services&lt;br /&gt;Ukraine&lt;br /&gt;Vladimir Gubarenko&lt;br /&gt;p/o box 8967&lt;br /&gt;61106, Kharkov&lt;br /&gt;Ukraine&lt;br /&gt;phone: +7 4956637354&lt;br /&gt;fax: +7 4956637354&lt;br /&gt;admin@imhoster.net&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ZarCzvZ9LSM/Tw6IQDB7vvI/AAAAAAAAC2k/PGLuwvRUh9o/s1600/pl.GIF" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/-WRJbI2BTrY8/Tw6JVHfFdII/AAAAAAAAC20/hfQmsgqHjPk/s1600/af.GIF" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="100" src="http://1.bp.blogspot.com/-WRJbI2BTrY8/Tw6JVHfFdII/AAAAAAAAC20/hfQmsgqHjPk/s640/af.GIF" width="640" /&gt;&lt;/a&gt;&lt;img border="0" height="79" src="http://3.bp.blogspot.com/-ZarCzvZ9LSM/Tw6IQDB7vvI/AAAAAAAAC2k/PGLuwvRUh9o/s320/pl.GIF" width="320" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malwaredomainlist.com/mdl.php?search=amberfreda.com&amp;amp;colsearch=All&amp;amp;quantity=50"&gt;&amp;nbsp;http://www.malwaredomainlist.com/mdl.php?search=amberfreda.com&amp;amp;colsearch=All&amp;amp;quantity=50&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Brief Analysis&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;b&gt;&amp;nbsp;607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;/b&gt;&lt;br /&gt;&amp;nbsp;Hendrik Adrian from Japan posted his analysis of the same sample&lt;a href="http://translate.google.com/translate?sl=ja&amp;amp;tl=en&amp;amp;js=n&amp;amp;prev=_t&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;layout=2&amp;amp;eotf=1&amp;amp;u=http%3A%2F%2Funixfreaxjp.blogspot.com%2F2012%2F01%2Framnit.html&amp;amp;act=url"&gt; ( 0day.JP - Ramnit) &lt;/a&gt;where he described the files created by the malware and&amp;nbsp; the spam sending capabilities of the bot .&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://4.bp.blogspot.com/--2VtfC5e3r8/Tw5uuSY_cOI/AAAAAAAAC1s/eU43IHS-NF0/s1600/bsod.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="145" src="http://4.bp.blogspot.com/--2VtfC5e3r8/Tw5uuSY_cOI/AAAAAAAAC1s/eU43IHS-NF0/s320/bsod.GIF" width="320" /&gt;&lt;/a&gt;The bot deletes registry settings for the safe boot, which causes BSOD and prevents one from removing the malicious files in the safe mode.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bhDQgCmjfeY/Tw5uqfwRqQI/AAAAAAAAC1k/grfJSpVCIBo/s1600/bsod1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;textarea cols="80" rows="20"&gt;----------------------------------Keys deleted:248----------------------------------HKLM\SYSTEM\ControlSet001\Control\SafeBoot\MinimalHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmtHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\BaseHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot Bus ExtenderHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Boot file systemHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\CryptSvcHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\DcomLaunchHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmadminHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmboot.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmio.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmload.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\dmserverHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\EventLogHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\File systemHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\FilterHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\HelpSvcHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\NetlogonHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PCI ConfigurationHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PlugPlayHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\PNP FilterHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Primary diskHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\RpcSsHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SCSI ClassHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sermouse.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sr.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\SRServiceHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\System Bus ExtenderHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vga.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\vgasave.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinMgmtHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\NetworkHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\AFDHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\AppMgmtHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\BaseHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot Bus ExtenderHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\Boot file systemHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\BrowserHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\CryptSvcHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\DcomLaunchHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\DhcpHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmadminHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmboot.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmio.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmload.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\dmserverHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\DnsCacheHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\EventLogHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\File systemHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\FilterHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\HelpSvcHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\ip6fw.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\ipnat.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanServerHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\LanmanWorkstationHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\LmHostsHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\MessengerHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDISHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NDIS WrapperHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NdisuioHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOSHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBIOSGroupHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetBTHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetDDEGroupHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetlogonHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetManHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetworkHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NetworkProviderHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\NtLmSspHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\PCI ConfigurationHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\PlugPlayHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP FilterHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\PNP_TDIHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\Primary diskHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpcdd.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpdd.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdpwd.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\rdsessmgrHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\RpcSsHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\SCSI ClassHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sermouse.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\SharedAccessHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sr.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\SRServiceHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\Streams DriversHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\System Bus ExtenderHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\TcpipHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\TDIHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdpipe.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\tdtcp.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\termserviceHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\vga.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\vgasave.sysHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\WinMgmtHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\WZCSVCHKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\MinimalHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmtHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BaseHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus ExtenderHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file systemHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvcHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunchHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadminHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserverHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLogHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File systemHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FilterHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvcHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NetlogonHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI ConfigurationHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlayHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP FilterHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary diskHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSsHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI ClassHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRServiceHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus ExtenderHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmtHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\NetworkHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFDHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmtHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BaseHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus ExtenderHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file systemHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BrowserHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvcHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunchHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DhcpHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadminHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserverHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCacheHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLogHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File systemHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\FilterHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvcHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServerHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstationHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHostsHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MessengerHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDISHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS WrapperHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NdisuioHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroupHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBTHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroupHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetlogonHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetManHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProviderHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSspHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI ConfigurationHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlayHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP FilterHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDIHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary diskHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgrHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSsHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI ClassHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccessHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRServiceHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams DriversHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus ExtenderHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TcpipHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDIHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termserviceHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sysHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmtHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVCHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}&lt;/textarea&gt;&lt;br /&gt;&lt;br /&gt;2. Adds a Windows service &lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Mi&lt;span style="color: red;"&gt;cor&lt;/span&gt;soft Windows Service - note the spelling&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;textarea cols="80" rows="20"&gt;Keys added:18----------------------------------HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICEHKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE\0000HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE\0000\ControlHKLM\SYSTEM\ControlSet001\Services\Micorsoft Windows ServiceHKLM\SYSTEM\ControlSet001\Services\Micorsoft Windows Service\SecurityHKLM\SYSTEM\ControlSet001\Services\Micorsoft Windows Service\EnumHKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICEHKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE\0000HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICORSOFT_WINDOWS_SERVICE\0000\ControlHKLM\SYSTEM\CurrentControlSet\Services\Micorsoft Windows ServiceHKLM\SYSTEM\CurrentControlSet\Services\Micorsoft Windows Service\SecurityHKLM\SYSTEM\CurrentControlSet\Services\Micorsoft Windows Service\EnumHKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dll1HKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe1HKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll1HKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll1\OpenWithListHKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe1HKU\S-1-5-21-789336058-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe1\OpenWithList &lt;/textarea&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;3. Adds the following files (names vary)&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;\Application Data\&lt;span style="color: red;"&gt;&lt;span style="color: #990000;"&gt;nvamibiv\&lt;/span&gt;vcryserj.exe &lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="color: red;"&gt; &lt;/span&gt;- copy of the original &lt;/b&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=f52bfac9637aea189ec918d05113c36f5bcf580f3c0de8a934fe3438107d3f0c-1326310185"&gt;http://www.virustotal.com/file-scan/report.html?id=f52bfac9637aea189ec918d05113c36f5bcf580f3c0de8a934fe3438107d3f0c-1326310185&lt;/a&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;blockquote class="tr_bq" style="text-align: left;"&gt;File: vcryserj.exe&lt;br /&gt;Size: 135680&lt;br /&gt;MD5:&amp;nbsp; 607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;/blockquote&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;\Application Data\&lt;span style="color: red;"&gt;wduqtdai.log&lt;/span&gt;&amp;nbsp; - number of logs varies, contain encrypted data&lt;/li&gt;&lt;li&gt;\Application Data\&lt;span style="color: red;"&gt;xtyepaef.log&lt;/span&gt; number of logs varies, contain encrypted data&lt;/li&gt;&lt;li&gt;&amp;nbsp;&lt;b&gt;\Temp\&lt;span style="color: red;"&gt;nhptugtstukgwpyi.exe&lt;/span&gt; - copy of the original&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;blockquote class="tr_bq" style="text-align: left;"&gt;File: nhptugtstukgwpyi.exe&lt;br /&gt;Size: 135680&lt;br /&gt;MD5:&amp;nbsp; 607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;/blockquote&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;\Start Menu\Programs\Startup\&lt;span style="color: red;"&gt;vcryserj.exe &lt;/span&gt;- copy of the original&lt;/b&gt;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;blockquote class="tr_bq"&gt;File: vcryserj.exe&lt;br /&gt;Size: 1356&lt;br /&gt;MD5:&amp;nbsp; 607B2219FBCFBFE8E6AC9D7F3FB8D50E&lt;/blockquote&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;\Local Settings\Temp\&lt;span style="color: red;"&gt;dnsgvbny.sys&lt;/span&gt;&amp;nbsp; the rootkit&amp;nbsp;&lt;/b&gt; &lt;a href="http://www.virustotal.com/file-scan/report.html?id=c1293f8dd8a243391d087742fc22c99b8263f70c6937f784c15e9e20252b38ae-1326346542"&gt;http://www.virustotal.com/file-scan/report.html?id=c1293f8dd8a243391d087742fc22c99b8263f70c6937f784c15e9e20252b38ae-1326346542&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;blockquote class="tr_bq"&gt;&lt;div style="text-align: left;"&gt;&amp;nbsp;File: dnsgvbny.sys&lt;br /&gt;Size: 15360&lt;/div&gt;&lt;div style="text-align: left;"&gt;MD5:&amp;nbsp; A6D351093F75D16C574DB31CDF736153&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-o5PVaWI_-2E/Tw51hu0c2pI/AAAAAAAAC10/uvLuvzSEWBw/s1600/handles.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-o5PVaWI_-2E/Tw51hu0c2pI/AAAAAAAAC10/uvLuvzSEWBw/s1600/handles.GIF" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Ramnit injects itself into two&amp;nbsp; svchost.exe processes and you&amp;nbsp; can see them if you sort all processes by PID, the last two will those created by Ramnit.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;It generates spam that it sends out on port 25,&lt;a href="http://translate.google.com/translate?sl=ja&amp;amp;tl=en&amp;amp;js=n&amp;amp;prev=_t&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;layout=2&amp;amp;eotf=1&amp;amp;u=http%3A%2F%2Funixfreaxjp.blogspot.com%2F2012%2F01%2Framnit.html&amp;amp;act=url"&gt; Hendrik already described this behavior in his post.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;C33E7ED929760020820E8808289C240E&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&amp;nbsp;The second file has file infector features I did not observe in&lt;b&gt; 607B2219FBCFBFE8E6AC9D7F3FB8D50E.&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;As you see in the log below, malicious svchost.exe modifies or tries to modify every binary and HTML file by appending malicious code to each file or a vbs script to HTML files &amp;nbsp; -&amp;nbsp; like described in this post by ESET &lt;a href="http://www.eset.eu/encyclopaedia/win32-ramnit-a-backdoor-ircnite-bwy-w32?lng=en"&gt;Win32/Ramnit.A.&lt;/a&gt; and here in the post by Avira&amp;nbsp; - &lt;a href="http://techblog.avira.com/2010/11/25/closer-look-at-w32ramnit-c/en/"&gt;Closer look at W32/Ramnit.C&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;This does not break the infected binaries, all files continue to work as designed, except they infect or reinfect the computer they are running on. Webmasters may upload infected html files and visitors of their sites may get infected as well. For an average user, it is impossible to clean a system compromised with Ramnit file injector and use it confidence. The only way is say good bye to all the HTM(L), DLL and EXE files and build a new system without trying to copy any hrml files, bookmark or applications.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;textarea cols="80" rows="20"&gt;"9/1/2012 22:26:4.43","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.43","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.43","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.43","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.103","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.103","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AGM.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.293","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ahclient.dll""9/1/2012 22:26:4.764","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:4.994","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll""9/1/2012 22:26:4.994","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll""9/1/2012 22:26:4.994","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll""9/1/2012 22:26:4.994","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll""9/1/2012 22:26:4.994","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\authplay.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.84","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll""9/1/2012 22:26:5.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll""9/1/2012 22:26:5.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll""9/1/2012 22:26:5.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll""9/1/2012 22:26:5.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll""9/1/2012 22:26:5.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\AXSLE.dll""9/1/2012 22:26:5.485","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll""9/1/2012 22:26:5.485","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll""9/1/2012 22:26:5.485","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll""9/1/2012 22:26:5.485","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll""9/1/2012 22:26:5.495","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIB.dll""9/1/2012 22:26:5.575","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll""9/1/2012 22:26:5.575","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll""9/1/2012 22:26:5.575","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll""9/1/2012 22:26:5.575","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll""9/1/2012 22:26:5.575","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\BIBUtils.dll""9/1/2012 22:26:5.775","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.775","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.775","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.775","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.805","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.805","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.805","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll""9/1/2012 22:26:5.765","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.66","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\CoolType.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.166","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.526","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\icucnv36.dll""9/1/2012 22:26:6.767","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.77","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\JP2KLib.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.297","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\logsession.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.458","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.dll""9/1/2012 22:26:7.638","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.638","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.638","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.638","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.658","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.658","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.658","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:7.768","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:7.828","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.828","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.828","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.828","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.838","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.838","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:7.838","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\Onix32.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.389","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\pe.dll""9/1/2012 22:26:8.770","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:9.771","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:10.772","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:11.774","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.315","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Adobe\Reader 9.0\Reader\sqlite.dll""9/1/2012 22:26:12.775","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:13.777","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:13.787","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Documents and Settings\mila\Local Settings\Application Data\wduqtdai.log""9/1/2012 22:26:14.217","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:14.217","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:14.237","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:14.237","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:14.778","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:15.219","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:15.780","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:16.781","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:17.783","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:18.784","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:18.914","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:18.914","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:18.914","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:18.914","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:18.924","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:18.924","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:19.225","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:19.225","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:19.225","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:19.785","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:20.226","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:20.787","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:20.927","registry","DeleteValueKey","System","HKLM\SYSTEM\ControlSet001\Services\kmixer\Enum\0""9/1/2012 22:26:20.927","registry","SetValueKey","System","HKLM\SYSTEM\ControlSet001\Services\kmixer\Enum\Count""9/1/2012 22:26:20.927","registry","SetValueKey","System","HKLM\SYSTEM\ControlSet001\Services\kmixer\Enum\NextInstance""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.518","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL""9/1/2012 22:26:21.788","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.329","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11F1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.499","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUT11M1.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.650","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTEMPP.DLL""9/1/2012 22:26:22.790","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.800","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTG2P.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:22.900","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\1033\TTS\TTS3000\ENUTSTPP.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.100","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\ENUT3S51.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.170","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\LHCOM01A.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.441","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\L&amp;amp;H\SpeechEngines\TTSCORE.DLL""9/1/2012 22:26:23.791","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:23.851","file","Delete","C:\WINDOWS\system32\svchost.exe","C:\WINDOWS\system32\CatRoot2\tmp.edb""9/1/2012 22:26:24.793","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:25.23","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:25.133","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:25.133","file","Write","System","C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe""9/1/2012 22:26:25.133","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:25.133","file","Write","System","C:\Program Files\Capture\7za.exe""9/1/2012 22:26:25.774","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:25.794","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:26.275","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:26.796","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:27.26","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:26.996","registry","SetValueKey","C:\WINDOWS\system32\winlogon.exe","HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ParseAutoexec""9/1/2012 22:26:27.567","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:27.797","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:28.67","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\HWXUSA.DLL""9/1/2012 22:26:28.308","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.308","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.308","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.308","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.318","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.318","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\INK\INKDIV.DLL""9/1/2012 22:26:28.568","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.798","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\dao360.dll.new""9/1/2012 22:26:28.808","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:29.69","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.459","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\BINDER.DLL""9/1/2012 22:26:29.820","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:29.810","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.461","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIINK.DLL""9/1/2012 22:26:30.551","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIVWCTL.DLL""9/1/2012 22:26:30.551","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIVWCTL.DLL""9/1/2012 22:26:30.551","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIVWCTL.DLL""9/1/2012 22:26:30.551","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIVWCTL.DLL""9/1/2012 22:26:30.551","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MDIVWCTL.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.741","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPCORE.DLL""9/1/2012 22:26:30.811","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:30.891","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPFILT.DLL""9/1/2012 22:26:30.891","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPFILT.DLL""9/1/2012 22:26:30.891","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPFILT.DLL""9/1/2012 22:26:30.891","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPFILT.DLL""9/1/2012 22:26:30.891","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPFILT.DLL""9/1/2012 22:26:30.951","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPGIMME.DLL""9/1/2012 22:26:30.951","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPGIMME.DLL""9/1/2012 22:26:30.951","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPGIMME.DLL""9/1/2012 22:26:30.951","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPGIMME.DLL""9/1/2012 22:26:30.951","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPGIMME.DLL""9/1/2012 22:26:31.502","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\OCRPS.DLL""9/1/2012 22:26:31.502","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\OCRPS.DLL""9/1/2012 22:26:31.502","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\OCRPS.DLL""9/1/2012 22:26:31.502","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\OCRPS.DLL""9/1/2012 22:26:31.502","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\OCRPS.DLL""9/1/2012 22:26:31.813","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:32.814","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:33.816","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:33.876","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.876","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.876","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.876","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.906","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.906","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:33.906","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCP71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.6","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\MSDesigners7\MSVCR71.DLL""9/1/2012 22:26:34.76","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:34.827","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:34.817","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:35.818","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:36.820","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.651","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL""9/1/2012 22:26:37.811","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.811","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.811","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.811","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.821","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.821","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSXML5.DLL""9/1/2012 22:26:37.821","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:38.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\WISC30.DLL""9/1/2012 22:26:38.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\WISC30.DLL""9/1/2012 22:26:38.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\WISC30.DLL""9/1/2012 22:26:38.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\WISC30.DLL""9/1/2012 22:26:38.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\OFFICE11\WISC30.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.723","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL""9/1/2012 22:26:38.823","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:39.153","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.153","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.153","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.183","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.153","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.183","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.183","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\1036\MSGR3FR.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.394","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\3082\MSGR3ES.DLL""9/1/2012 22:26:39.704","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msinfo32.exe.new""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.784","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\CHAPI3T1.DLL""9/1/2012 22:26:39.824","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:40.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.285","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.295","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.295","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.295","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSHY3ES.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.756","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSLID.DLL""9/1/2012 22:26:40.826","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.26","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3ES.DLL""9/1/2012 22:26:41.176","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3FR.DLL""9/1/2012 22:26:41.176","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3FR.DLL""9/1/2012 22:26:41.176","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3FR.DLL""9/1/2012 22:26:41.176","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3FR.DLL""9/1/2012 22:26:41.176","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSP3FR.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.617","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL""9/1/2012 22:26:41.827","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:41.937","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTH3ES.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.218","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\PROOF\MSTHES3.DLL""9/1/2012 22:26:42.829","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:43.830","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:44.831","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:45.833","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:46.834","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:47.836","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:48.837","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:49.668","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spcplui.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.728","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapi.dll.new""9/1/2012 22:26:49.789","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sapisvr.exe.new""9/1/2012 22:26:49.839","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:50.840","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:51.842","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:52.843","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:53.844","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:54.846","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:55.847","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:56.849","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:57.850","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.60","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\ESEN\MSB1ESEN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\FREN\MSB1FREN.DLL""9/1/2012 22:26:58.661","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.661","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.661","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.661","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.671","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.671","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.671","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\WTSP61MS.DLL""9/1/2012 22:26:58.852","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:26:58.922","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:59.673","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:26:59.853","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.13","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL""9/1/2012 22:27:0.424","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:0.464","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.464","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.464","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.464","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.514","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.514","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.514","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCP71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.644","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\MSVCR71.DLL""9/1/2012 22:27:0.854","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.45","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\VDT70G.DLL""9/1/2012 22:27:1.175","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.205","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL""9/1/2012 22:27:1.856","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:1.926","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:2.427","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:2.857","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:3.178","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:3.859","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:3.929","file","Write","C:\Program Files\Wireshark\dumpcap.exe","C:\Documents and Settings\mila\Local Settings\Temp\wiresharkXXXXa03444""9/1/2012 22:27:4.860","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:5.451","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\triedit.dll.new""9/1/2012 22:27:5.451","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\triedit.dll.new""9/1/2012 22:27:5.451","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\triedit.dll.new""9/1/2012 22:27:5.451","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\triedit.dll.new""9/1/2012 22:27:5.451","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\triedit.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.541","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\vgx.dll.new""9/1/2012 22:27:5.862","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:6.863","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:7.865","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\1033\ITNGRAM.DLL""9/1/2012 22:27:8.866","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.777","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRENG.DLL""9/1/2012 22:27:9.867","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:9.948","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\SpeechEngines\Microsoft\SR61\SPSRX.DLL""9/1/2012 22:27:10.869","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.530","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\fp4autl.dll.new""9/1/2012 22:27:11.870","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:12.872","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:12.902","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:12.902","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:12.902","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:12.902","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:12.932","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:12.932","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Common Files\System\MSMAPI\1033\CDO.DLL""9/1/2012 22:27:13.873","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:13.873","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Documents and Settings\mila\Local Settings\Application Data\wduqtdai.log""9/1/2012 22:27:14.875","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:15.876","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.237","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoap1.dll.new""9/1/2012 22:27:16.287","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\mssoapr.dll.new""9/1/2012 22:27:16.357","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wisc10.dll.new""9/1/2012 22:27:16.407","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spcommon.dll.new""9/1/2012 22:27:16.407","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spcommon.dll.new""9/1/2012 22:27:16.407","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spcommon.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.497","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\spttseng.dll.new""9/1/2012 22:27:16.557","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msader15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.617","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msado15.dll.new""9/1/2012 22:27:16.657","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadomd.dll.new""9/1/2012 22:27:16.657","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadomd.dll.new""9/1/2012 22:27:16.657","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadomd.dll.new""9/1/2012 22:27:16.657","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadomd.dll.new""9/1/2012 22:27:16.657","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadomd.dll.new""9/1/2012 22:27:16.707","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msador15.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.767","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadox.dll.new""9/1/2012 22:27:16.827","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadrh15.dll.new""9/1/2012 22:27:16.847","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msjro.dll.new""9/1/2012 22:27:16.847","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msjro.dll.new""9/1/2012 22:27:16.847","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msjro.dll.new""9/1/2012 22:27:16.888","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\directdb.dll.new""9/1/2012 22:27:16.888","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\directdb.dll.new""9/1/2012 22:27:16.888","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\directdb.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.918","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadce.dll.new""9/1/2012 22:27:16.878","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:16.988","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadcer.dll.new""9/1/2012 22:27:17.18","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadcf.dll.new""9/1/2012 22:27:17.78","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadcfr.dll.new""9/1/2012 22:27:17.138","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadco.dll.new""9/1/2012 22:27:17.138","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadco.dll.new""9/1/2012 22:27:17.138","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadco.dll.new""9/1/2012 22:27:17.138","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadco.dll.new""9/1/2012 22:27:17.138","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadco.dll.new""9/1/2012 22:27:17.218","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadcor.dll.new""9/1/2012 22:27:17.248","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadcs.dll.new""9/1/2012 22:27:17.308","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadds.dll.new""9/1/2012 22:27:17.308","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadds.dll.new""9/1/2012 22:27:17.308","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadds.dll.new""9/1/2012 22:27:17.308","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadds.dll.new""9/1/2012 22:27:17.308","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msadds.dll.new""9/1/2012 22:27:17.679","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msaddsr.dll.new""9/1/2012 22:27:17.749","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprsr.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.799","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaprst.dll.new""9/1/2012 22:27:17.859","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdarem.dll.new""9/1/2012 22:27:17.859","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdarem.dll.new""9/1/2012 22:27:17.859","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdarem.dll.new""9/1/2012 22:27:17.879","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:17.919","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaremr.dll.new""9/1/2012 22:27:17.999","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdfmap.dll.new""9/1/2012 22:27:18.880","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:19.882","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:20.883","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:21.314","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdadc.dll.new""9/1/2012 22:27:21.594","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaenum.dll.new""9/1/2012 22:27:21.755","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaer.dll.new""9/1/2012 22:27:21.885","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.586","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaora.dll.new""9/1/2012 22:27:22.886","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:23.116","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaorar.dll.new""9/1/2012 22:27:23.137","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaosp.dll.new""9/1/2012 22:27:23.137","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaosp.dll.new""9/1/2012 22:27:23.137","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaosp.dll.new""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.487","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\awt.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.537","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\axbridge.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.667","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\client\jvm.dll""9/1/2012 22:27:23.767","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.767","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.767","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.787","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.767","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.787","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.787","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.787","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\cmm.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.848","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dcpr.dll""9/1/2012 22:27:23.888","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.898","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\deploy.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:23.998","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_shmem.dll""9/1/2012 22:27:24.48","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_socket.dll""9/1/2012 22:27:24.48","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_socket.dll""9/1/2012 22:27:24.48","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_socket.dll""9/1/2012 22:27:24.48","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_socket.dll""9/1/2012 22:27:24.48","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\dt_socket.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.98","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\eula.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.148","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\fontmanager.dll""9/1/2012 22:27:24.198","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hpi.dll""9/1/2012 22:27:24.198","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hpi.dll""9/1/2012 22:27:24.198","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hpi.dll""9/1/2012 22:27:24.198","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hpi.dll""9/1/2012 22:27:24.198","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hpi.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.248","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\hprof.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.298","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\instrument.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.348","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\ioser12.dll""9/1/2012 22:27:24.398","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pcsc.dll""9/1/2012 22:27:24.398","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pcsc.dll""9/1/2012 22:27:24.398","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pcsc.dll""9/1/2012 22:27:24.398","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pcsc.dll""9/1/2012 22:27:24.398","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pcsc.dll""9/1/2012 22:27:24.448","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pkcs11.dll""9/1/2012 22:27:24.448","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pkcs11.dll""9/1/2012 22:27:24.448","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pkcs11.dll""9/1/2012 22:27:24.448","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pkcs11.dll""9/1/2012 22:27:24.448","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\j2pkcs11.dll""9/1/2012 22:27:24.498","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jaas_nt.dll""9/1/2012 22:27:24.498","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jaas_nt.dll""9/1/2012 22:27:24.498","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jaas_nt.dll""9/1/2012 22:27:24.498","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jaas_nt.dll""9/1/2012 22:27:24.498","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jaas_nt.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.599","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java.dll""9/1/2012 22:27:24.889","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:24.909","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java_crw_demo.dll""9/1/2012 22:27:24.909","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java_crw_demo.dll""9/1/2012 22:27:24.909","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java_crw_demo.dll""9/1/2012 22:27:24.909","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java_crw_demo.dll""9/1/2012 22:27:24.909","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\java_crw_demo.dll""9/1/2012 22:27:24.959","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jawt.dll""9/1/2012 22:27:24.959","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jawt.dll""9/1/2012 22:27:24.959","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jawt.dll""9/1/2012 22:27:24.959","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jawt.dll""9/1/2012 22:27:24.959","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jawt.dll""9/1/2012 22:27:25.59","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\JdbcOdbc.dll""9/1/2012 22:27:25.59","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\JdbcOdbc.dll""9/1/2012 22:27:25.59","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\JdbcOdbc.dll""9/1/2012 22:27:25.59","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\JdbcOdbc.dll""9/1/2012 22:27:25.59","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\JdbcOdbc.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.109","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jdwp.dll""9/1/2012 22:27:25.159","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.159","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.159","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.159","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.169","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.169","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.169","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jkernel.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.230","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jli.dll""9/1/2012 22:27:25.380","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jp2native.dll""9/1/2012 22:27:25.380","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jp2native.dll""9/1/2012 22:27:25.380","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jp2native.dll""9/1/2012 22:27:25.380","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jp2native.dll""9/1/2012 22:27:25.380","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jp2native.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.480","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpeg.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.530","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpicom.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.580","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpiexp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.630","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpinscp.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.680","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpioji.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.730","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jpishare.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.880","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsound.dll""9/1/2012 22:27:25.890","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:25.941","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsoundds.dll""9/1/2012 22:27:25.941","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsoundds.dll""9/1/2012 22:27:25.941","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsoundds.dll""9/1/2012 22:27:25.941","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsoundds.dll""9/1/2012 22:27:25.941","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\jsoundds.dll""9/1/2012 22:27:26.211","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\management.dll""9/1/2012 22:27:26.211","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\management.dll""9/1/2012 22:27:26.211","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\management.dll""9/1/2012 22:27:26.211","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\management.dll""9/1/2012 22:27:26.211","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\management.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.261","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\mlib_image.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.411","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\net.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.491","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.591","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll""9/1/2012 22:27:26.642","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\nio.dll""9/1/2012 22:27:26.642","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\nio.dll""9/1/2012 22:27:26.642","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\nio.dll""9/1/2012 22:27:26.642","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\nio.dll""9/1/2012 22:27:26.642","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\nio.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.792","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npoji610.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.842","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\npt.dll""9/1/2012 22:27:26.892","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.42","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\regutils.dll""9/1/2012 22:27:27.92","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\rmi.dll""9/1/2012 22:27:27.92","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\rmi.dll""9/1/2012 22:27:27.92","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\rmi.dll""9/1/2012 22:27:27.92","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\rmi.dll""9/1/2012 22:27:27.92","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\rmi.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.292","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\splashscreen.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.443","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\sunmscapi.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.593","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\unpack.dll""9/1/2012 22:27:27.693","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\verify.dll""9/1/2012 22:27:27.693","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\verify.dll""9/1/2012 22:27:27.693","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\verify.dll""9/1/2012 22:27:27.693","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\verify.dll""9/1/2012 22:27:27.693","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\verify.dll""9/1/2012 22:27:27.743","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll""9/1/2012 22:27:27.743","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll""9/1/2012 22:27:27.743","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll""9/1/2012 22:27:27.743","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll""9/1/2012 22:27:27.743","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll""9/1/2012 22:27:27.843","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\zip.dll""9/1/2012 22:27:27.843","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\zip.dll""9/1/2012 22:27:27.843","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\zip.dll""9/1/2012 22:27:27.843","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\zip.dll""9/1/2012 22:27:27.843","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\bin\zip.dll""9/1/2012 22:27:27.893","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.304","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaps.dll.new""9/1/2012 22:27:28.524","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasc.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.554","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasql.dll.new""9/1/2012 22:27:28.584","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdasqlr.dll.new""9/1/2012 22:27:28.604","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdatl3.dll.new""9/1/2012 22:27:28.604","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdatl3.dll.new""9/1/2012 22:27:28.604","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdatl3.dll.new""9/1/2012 22:27:28.634","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdatt.dll.new""9/1/2012 22:27:28.664","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msdaurl.dll.new""9/1/2012 22:27:28.684","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\msxactps.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.705","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32.dll.new""9/1/2012 22:27:28.745","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32r.dll.new""9/1/2012 22:27:28.745","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32r.dll.new""9/1/2012 22:27:28.745","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\oledb32r.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.765","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\sqlxmlx.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.805","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.815","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.815","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.815","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.875","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\wab32res.dll.new""9/1/2012 22:27:28.895","registry","SetValueKey","C:\WINDOWS\system32\svchost.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Run\VcrYserj""9/1/2012 22:27:28.925","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn.dll.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.955","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn1.exe.new""9/1/2012 22:27:28.995","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn2.exe.new""9/1/2012 22:27:28.995","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn2.exe.new""9/1/2012 22:27:28.995","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwconn2.exe.new""9/1/2012 22:27:29.15","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwdl.dll.new""9/1/2012 22:27:29.25","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwhelp.dll.new""9/1/2012 22:27:29.25","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwhelp.dll.new""9/1/2012 22:27:29.25","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwhelp.dll.new""9/1/2012 22:27:29.25","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwhelp.dll.new""9/1/2012 22:27:29.25","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwhelp.dll.new""9/1/2012 22:27:29.45","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwres.dll.new""9/1/2012 22:27:29.65","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwrmind.exe.new""9/1/2012 22:27:29.85","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwtutor.exe.new""9/1/2012 22:27:29.85","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwtutor.exe.new""9/1/2012 22:27:29.85","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwtutor.exe.new""9/1/2012 22:27:29.125","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\icwutil.dll.new""9/1/2012 22:27:29.135","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\inetwiz.exe.new""9/1/2012 22:27:29.145","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\isignup.exe.new""9/1/2012 22:27:29.175","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\trialoc.dll.new""9/1/2012 22:27:29.185","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\hmmapi.dll.new""9/1/2012 22:27:29.195","file","Write","C:\WINDOWS\system32\winlogon.exe","C:\WINDOWS\system32\dllcache\iedw.exe.new""9/1/2012 22:27:29.365","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\lib\deploy\lzma.dll""9/1/2012 22:27:29.365","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\lib\deploy\lzma.dll""9/1/2012 22:27:29.365","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\lib\deploy\lzma.dll""9/1/2012 22:27:29.365","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\lib\deploy\lzma.dll""9/1/2012 22:27:29.365","file","Write","C:\WINDOWS\system32\svchost.exe","C:\Program Files\Java\jre6\lib\deploy\lzma.dll" &lt;/textarea&gt; &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-J7WsdG0I1Io/Tw6FwO5-OEI/AAAAAAAAC2U/puqevUiJAfs/s1600/6b.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-zN30WKwUXvA/Tw57f3spplI/AAAAAAAAC18/5ZheG3q7zg8/s1600/vt.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://2.bp.blogspot.com/-zN30WKwUXvA/Tw57f3spplI/AAAAAAAAC18/5ZheG3q7zg8/s640/vt.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Thsi is what happens with VirustotalUpload2.exe (and most other Programs including Adobe, MS Office and Windows files)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=a40aacca731c142148733786cae64d45df2e740e3fb744ffc513d251ec121cf7-1326169765"&gt;http://www.virustotal.com/file-scan/report.html?id=a40aacca731c142148733786cae64d45df2e740e3fb744ffc513d251ec121cf7-1326169765&lt;/a&gt;&lt;br /&gt;VirusTotalUpload2.exe&lt;br /&gt;Submission date:&lt;br /&gt;2012-01-10 04:29:25 (UTC)&lt;br /&gt;Result:37 /43 (86.0%)&lt;br /&gt;Print results&lt;br /&gt;Antivirus &amp;nbsp;&amp;nbsp;&amp;nbsp; Version &amp;nbsp;&amp;nbsp;&amp;nbsp; Last Update &amp;nbsp;&amp;nbsp;&amp;nbsp; Result&lt;br /&gt;AhnLab-V3 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09.00 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32/Ramnit.O&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.11.20.218 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.E&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32:Ramnit-H&lt;br /&gt;AVG &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1190 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32/Zbot.G&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.N&lt;br /&gt;ByteHero &amp;nbsp;&amp;nbsp;&amp;nbsp; 1.0.0.1 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.31 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan.Win32.Heur.Gen&lt;br /&gt;CAT-QuickHeal &amp;nbsp;&amp;nbsp;&amp;nbsp; 12.00 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32.Ramnit.C&lt;br /&gt;ClamAV &amp;nbsp;&amp;nbsp;&amp;nbsp; 0.97.3.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan.Patched-168&lt;br /&gt;Commtouch &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.3.2.6 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.E&lt;br /&gt;Comodo &amp;nbsp;&amp;nbsp;&amp;nbsp; 11229 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; TrojWare.Win32.Patched.SM&lt;br /&gt;DrWeb &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.0.2.03300 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Rmnet.8&lt;br /&gt;Emsisoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.1.0.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Virus.Win32.Zbot!IK&lt;br /&gt;eTrust-Vet &amp;nbsp;&amp;nbsp;&amp;nbsp; 37.0.9672 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32/Ramnit.AJ&lt;br /&gt;F-Prot &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.6.5.141 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.E&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.N&lt;br /&gt;Fortinet &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.3.388.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.B&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.N&lt;br /&gt;Ikarus &amp;nbsp;&amp;nbsp;&amp;nbsp; T3.1.1.109.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Virus.Win32.Zbot&lt;br /&gt;Jiangmin &amp;nbsp;&amp;nbsp;&amp;nbsp; 13.0.900 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32/PatchFile.gg&lt;br /&gt;K7AntiVirus &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.124.5897 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.0.837 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan.Win32.Patched.md&lt;br /&gt;McAfee &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.400.0.1158 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.b&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp;&amp;nbsp; 2010.1E &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.b&lt;br /&gt;Microsoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 1.7903 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Virus:Win32/Ramnit.AF&lt;br /&gt;NOD32 &amp;nbsp;&amp;nbsp;&amp;nbsp; 6780 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32/Ramnit.H&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.07.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Ramnit.AB&lt;br /&gt;nProtect &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-01-09.01 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.N&lt;br /&gt;Panda &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.3.5 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32/Cosmu.L&lt;br /&gt;PCTools &amp;nbsp;&amp;nbsp;&amp;nbsp; 8.0.0.5 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Malware.Ramnit&lt;br /&gt;Rising &amp;nbsp;&amp;nbsp;&amp;nbsp; 23.92.01.01 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.c&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; W32.Ramnit.B!inf&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; PE_RAMNIT.KC&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; PE_RAMNIT.KC&lt;br /&gt;ViRobot &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.1.10.4872 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.A&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp;&amp;nbsp; 14.1.158.1 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2012.01.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Win32.Ramnit.Gen.3&lt;br /&gt;Additional information&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 25f6ee42d37e3f2f7dbe795e836d52e2&lt;br /&gt;&lt;h3 style="background-color: #618f2b; color: white; font-weight: normal; text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Traffic&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;b&gt;607B2219FBCFBFE8E6AC9D7F3FB8D50E - C&amp;amp;C is sinkholed&lt;/b&gt;&lt;b&gt;C33E7ED929760020820E8808289C240E&amp;nbsp; - C&amp;amp;C is active&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Despite the fact that the C&amp;amp;C for 607B2219FBCFBFE8E6AC9D7F3FB8D50E is sinkholed, it is still interesting to see the malware behavior when it tries to establish a connection with the server.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;Ramnit samples used by the same group of attackers have overlapping set of C&amp;amp;C servers - the list is not the same but I found that my samples that are supposedly later version that Ramnit.AK have approximately 80% overlap in C&amp;amp;C list used by this RamnitAK binary &lt;a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj%7ERamnit-AK.aspx"&gt;described by Sophos &lt;/a&gt;.&amp;nbsp; I have combined the two lists and ran WHOIS queries to establish active C&amp;amp;C and their location and registration.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The communications with the sinkholed server below show that once the bot receives SYN command from the C&amp;amp;C, it sends &lt;b&gt;6 bytes of data.&lt;/b&gt; Exact same behavior is described in this analysis of&amp;nbsp; the binaries from Summer 2011&amp;nbsp; - with the only difference that the second packet sent by the bot was not 75 bytes but 149 bytes &lt;a href="http://www.emergingthreatspro.com/bot-of-the-day/bot-of-the-day-ramnitninmul/"&gt;Bot of the Day: Ramnit/NinmulMonday, July 18th, 2011&lt;/a&gt;. If connection with the server is established, the traffic continues on on port 443, it is encoded but it is not SSL, it is some sort of custom protocol. &lt;a href="http://3.bp.blogspot.com/-J7WsdG0I1Io/Tw6FwO5-OEI/AAAAAAAAC2U/puqevUiJAfs/s1600/6b.GIF" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://3.bp.blogspot.com/-J7WsdG0I1Io/Tw6FwO5-OEI/AAAAAAAAC2U/puqevUiJAfs/s640/6b.GIF" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/-d1j0Ewv90Fk/Tw6FPhs_wwI/AAAAAAAAC2M/aXk0iAnzh0A/s1600/6b.GIF" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;The bot is going through the list of domains trying to find those that are active. Most of the domains are not registered yet but the two currently active domains were registered on&lt;b&gt; January 5 and 6, 2011. &lt;/b&gt;It appears that the attackers register new domains as soon as the lose any due to sinkholing and domain cancellations. Since all the domains have the most random names, they are not likely to be registered by someone else before they are needed. Having each binary to check a long list of domains makes the bot very noisy (consider making IDS signatures based on UDP port 53 thresholds) but it prevents the death of the botnet in case of the C&amp;amp;C loss. I have complied a list of approximately 400 domains with only 21 of them registered.&amp;nbsp;&amp;nbsp; If you created DNS blocks or sinkhole domains, consider blocking or sinkholing all of them, not only active.&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;div style="text-align: left;"&gt;Domain name:&lt;span style="color: red;"&gt; rjordulltl.com&lt;/span&gt;&lt;br /&gt;89.149.242.185&amp;nbsp; - Leaseweb Germany GmbH (previously netdirekt e. K.)&lt;br /&gt;Germany&lt;br /&gt;Registrar: Regtime Ltd.&lt;br /&gt;Creation date: 2012-01-05&lt;br /&gt;Expiration date: 2013-01-05 &lt;br /&gt;&lt;br /&gt;Domain Name: &lt;b style="color: red;"&gt;goopndlgvy.com&lt;/b&gt;&lt;br /&gt;Registrant:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PrivacyProtect.org&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain Admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (contact@privacyprotect.org)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID#10760, PO Box 16&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Note - All Postal Mails Rejected, visit Privacyprotect.org&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Nobby Beach&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; null,QLD 4218&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AU&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tel. +45.36946676&lt;br /&gt;89.149.242.185&amp;nbsp; - Leaseweb Germany GmbH (previously netdirekt e. K.)&lt;br /&gt;Germany&lt;br /&gt;Creation Date: 06-Jan-2012&amp;nbsp; &lt;br /&gt;Expiration Date: 06-Jan-2013&lt;/div&gt;&lt;/blockquote&gt;&lt;b&gt;&amp;nbsp;Communications with a sinkholed C&amp;amp;C and search for a new active server:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lXl9VVos45o/Tw6BqwjvZWI/AAAAAAAAC2E/IyEHeT-9328/s1600/traffic.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="526" src="http://4.bp.blogspot.com/-lXl9VVos45o/Tw6BqwjvZWI/AAAAAAAAC2E/IyEHeT-9328/s640/traffic.GIF" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-d1j0Ewv90Fk/Tw6FPhs_wwI/AAAAAAAAC2M/aXk0iAnzh0A/s1600/6b.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;Bot &amp;lt;-&amp;gt; C&amp;amp;C communications on port 443&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-c3dr9Cwk7yQ/Tw6Gz57EEWI/AAAAAAAAC2c/KSh-IOX7LqA/s1600/ssl.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="498" src="http://4.bp.blogspot.com/-c3dr9Cwk7yQ/Tw6Gz57EEWI/AAAAAAAAC2c/KSh-IOX7LqA/s640/ssl.GIF" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;List of domains used by Ramnit binaries - feel free to pre-emptively sinkhole them. Part of them are from this &lt;a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj%7ERamnit-AK.aspx"&gt;Sophos analysis&lt;/a&gt; and part is from running these two binaries&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;textarea cols="50" rows="20"&gt;absqvhpldvsmclt.comadhcssvuayv.comagpdvawvr.comaguhlabfubbvek.comalgvgcawwdsmiksvol.comamobragjgge.comanqsjvhjjkypabm.comanxpepxpukbfmh.comarhpgoeeasi.comarqogipjsbcdmk.comatfkpyicxsrrwqbct.comatuealmjufcwwb.comawckeliqcherasntmin.combaxqqapjrxxetjelhtk.combbmfswfgmljwj.combklerdwiadlxxbjunwu.combllkuhftropiwymr.combpmlhpuogveluyobjb.combtfkjkqv.combunxomdqokknkkllvkr.combvkdfvxoqxsabk.combxnrxuyjcytf.combygfsdfmrwbhlghll.combyraiyodqfdx.comcaosuihgsvivlxh.comcarrerfullezz.comcascotqhij.comcatvfmsxowehqvfahu.comccquxmelkltnucyqv.comccsnpnqxii.comcjemaqojxac.comckgryagcibbcf.comcmuhommmdlmhy.comcncvxhadekwnybnv.comcpmsussgpibatpmswq.comcqlmxlukplhlfdo.comcqlnwqaioac.comcswtnpnuhixdwjgm.comcxmdhrpwuvyl.comdcyakhpr.comdegbxpos.comdfyxptqjxwtdkjjbiu.comdgrdrqkpmggukqo.comdjeuagtquwwhera.comdlsvfpmniphnmxnvoeo.comdnmjahdaigeydiiorky.comdpdadshi.comdpjbclufd.comdpyeoipbso.comdrpfrkvdttdkhgpqi.comdthcjcsdxywxlsng.comdvgeqsama.comdxovrcmyletmggxf.comdykxkasesippbsjb.comdypislng.comeaayjpeyabqf.comebddteinurkortapgs.comecmdkxukhtf.comedqmjbyjcxyjqnjjodh.comeeuprbpohspwje.comegcftpguclkoi.comegvqomxmea.comeijahjdmm.comejjogggfqcmc.comelieidkolpc.comeljmrnwualb.comeolgavefbsntlobsnpp.comerfhytwpgitkpgudo.comervffluceipmfb.comexpecvmanfaydv.comfdkasoupvgxigejgdfb.comfgvkxjvghdulfrx.comfiblolpp.comfidjlfphserhycexjhf.comfkcxdfiv.comfksudkswknxd.comfktpfwoqpgcagpal.comfokvmmygnngm.comfqaeucdaicvnisqbd.comfsksblipt.comfssuatmti.comfujosogkpsxthf.comfvfeiutlwaw.comfxkapveygtffbkv.comfybdqchsheqiul.comgccadwuf.comgeyameywwoaf.comggpmcodfppkjirg.comghxctletck.comginbkjuweobmwp.comgjehgcrav.comgjvhfiouvwiqvtewbu.comgkholyjchymn.comgkusimsgjcauehgdjn.comgmeuasnn.comgoopndlgvy.comgormlunjjt.comgqmrhecnntccmawclmq.comgsbwxfecgbmuysm.comgwbdgrlikclhthyivym.comhaqkwkokaigcdslnrlr.comhbwpvcnwwcdgfojuixm.comhetjymgiddyamqq.comhfegocufjkndwc.comhgubujdad.comhhowujyrcvdrwpdvsck.comhijkitpq.comhjwrnlvdbcmjrfkjx.comhjxrksvo.comhugnnpnymbwnhtuh.comhxpgffdwbevww.comidseneqmupdijjklvtm.comiedaagmofvk.comieugluxmlx.comigspslbpjencmfax.comihoxyanyker.comilasqwag.comiljmekbkcukps.comiokxcthosa.comirfldtfkhgyrpsarcje.comisuhxkbqqxuauhdwn.comitehtxcch.comiuhohaeqgpikwwgvkki.comixjtpaxclwhxmadp.comixnaxrqn.comixsoscorrrqvyd.comiyaxaucrvnhmkylya.comjabdfnuridle.comjbkjkngvaiwaxr.comjdrqnbtklqwqrv.comjexgpprgph.comjfvgelaqyfhxygq.comjfvxpfbgo.comjhfugjtncuvsuumnks.comjjfcilvuchkjvutlho.comjktlguslfhcwqkmai.comjmvkyepiiqyixw.comjnjgogpcehsdkbnl.comjnpquwdupgauq.comjpaaommxplsmmnnp.comjufxfkajvqmjljumvuq.comjxnbdfwh.comjyvfsnsqddbgxq.comkbadlfpgtec.comkcpxjxrmvurhfe.comkgrrxfmyixossjmk.comkiiwacbehxexixl.comkjhsrucajdjlbpwwj.comkjjeuhhqiwvfnuvvtkd.comkjuldacvvmdffxi.comkmyxdodog.comknugxvsimayety.comkojadineqlbbfvtwlff.comkpkyaxyytagbk.comkqrkegigdtjxxcrvl.comkqweenxsiyjtbe.comkrtvnyxc.comktdofbmltjyt.comkvoxyhnaggyqrcc.comlaiotlboxklvpcdfhu.comlanwiojchmenjhn.comlarpjpbblpnkdwyx.comlbcqwwxucahiulchx.comlbdlmcmfuinc.comlcloroifjeilomowq.comldanknmdiqtrot.comleqnxekmi.comlfnjosunfd.comlgeohbboqpngfap.comlgsjwixwocm.comlnjrtxcjbiaov.comlnlhuiitohdvbgmx.comlolkcovkfktwhaks.comlpggutwsvtvnmvpxrc.comlqkdmcplj.comlrqxvrqsihwtudox.comluxsnxlqhebftttflob.comlvmrpvkyo.comlwnfgmpncjubpseh.comlyghwyciguta.commavjlatqkpuban.commcchphgndpadclga.commcnegeytoyh.commefqtfwlxrfhguru.commfsxlnoqvslcyfbl.commggtqypybfts.commjuqovvuruldy.commkmngqxwk.commlfymmarbaswncxmn.commlhlurqylttjc.commmigsmpwmmwtxacq.commmmngmrhvvohfnv.commmwhewlrckie.commpefryhfpwhfvj.commryonirvcpm.commstwcsnvylmullkqh.commsxuafqnwjhljurmw.commwiadfsqcbjkudxd.commwsjitqbf.comnbqealvkhirjn.comnbvhroptghtmsydrfq.comnbykkrkevuri.comngwhgabaxkpievvmm.comnirxlosffmarpbp.comnjqvexdhwhutar.comnoslwqaagtoxunnv.comnqlocokxsjnsffxeu.comnrcmbkxssydac.comntnwcxtwgxwecrdxr.comntohnxgjijsgi.comntqbbnywghbjvsoivo.comnwetlnpjovgxmj.comnwoyejym.comnwrqebry.comnyxmwnkkacwamvj.comnyyhahsslkflyhulcgl.comoaifpapl.comobcjfjseku.comobmfvijftylgjpf.comocnsfoyrdplmewnyx.comogpshvhk.comohpmyviumie.comoiexgmycrtwirsgcmv.comojmitlcyjsuyb.comojvpkaohbddmbfac.comoluddrbaeb.comomsilsdcpdsgpxm.comopxxjqvyjllj.comoqayununxmqdxo.comoqenuuygfpvopu.comorgflqxdnoyecgwib.comoukicfldnvxhrtxvuqr.comouwwtmcnuiudw.comovgucbrrvxqufkwq.comoxjlrgepfnkvdprbr.compaoxlrmbg.compbfttfgw.compbwjbkgdo.compdcdcwjwrqsq.compfkilgedjhq.comppgessnvvn.compphxfntktjvhgti.comppwnhnvwnvtggifhbv.comprcgijpwvrl.compvbmlrybufe.comqadjgxayck.comqanmwnpvpcyqsa.comqbpcpmcijn.comqdfgqwiovjlfegdcepm.comqekgxfrk.comqewgaoursqgghhfwbqa.comqfitnlxp.comqjnhsbctfdfpoisvgp.comqlbycfgbpvjwa.comqnmqexiqrxhvdwgl.comqopdypfxhda.comqpvvabbaqcn.comqqsvttcnvsigkh.comqsrywodlwhorwibvy.comqukccxcwi.comqvddnchpjtskjmgdlx.comqwfxemkbuee.comqxdfhujechixcrgdb.comrapbmprhwwm.comrcnnhkcagerrquby.comrelmyplngdrdxpyv.comrfngjynkypsphqfmkh.comrgcdictp.comrglaabsktspwrw.comrhfdjaecmygcrdgep.comrhoaahddyhbg.comrjordulltl.comrjykgymugqlscttx.comrkevnmhekdgvnf.comrkxukunrgvpkgmc.comrlvwjjhntfooonvhlou.comrmuyrkxxtk.comrqybdbvyvjuruuxv.comrsmhdfgpgw.comrtcocsaitmadupgl.comrwjsxxvvkbspdjoedi.comrxckgnatt.comrxkhdpigbqoeco.comrykgnuncbedueeuevxg.comsecdfbpyopjhyhuw.comsexdsgnrojhpptqb.comsgimiytkanu.comsgjwptrfosjeico.comsjfrarsvyhlr.comskqbirmcomtjty.comskroackqs.comsliokrvnkjenhwgpjl.comslmomdmcjuoaxdip.comsnkbcptiqgqmlvw.comsnpltixygwcpifp.comsphmwjrwlfl.comsptihuxubpj.comstar-trakers.comstleikxkbjwo.comstrhnkjvfskxlwinku.comsuhfvuljuihmevldp.comsvyafurnyrjrrfxjreh.comswtuvuibfapnited.comtcpfmbhnlyw.comtekiyftuevgnor.comtfgixgmqhdowexm.comtfpohsjc.comthkqfhupjgknkqcxhou.comthxkchcnhyssj.comticfmjsce.comtlxfrilp.comtnueoqahys.comtrlnhbpanhmspru.comtsilfaftadrrs.comtthayebvhdmntiyeuxw.comttjerkrdrrowibsipjr.comtufictpfglnlfq.comtuisyirhweflhvqyxh.comtupexbvpmsc.comtvxwdutxo.comtxapbjdlsrtpea.comucwkkgbdxvjexa.comudvnniovrov.comufxsqnjtryrny.comugwytktvhslgjm.comuhjwxipj.comuhndpadrwbuuchcvn.comuigwsscasowqdiyp.comuilmabdaxqlaxuj.comuiwbtjfp.comujypninrop.comukbukpuj.comumiuqmrmvsuiscitx.comumjxwuaaso.comumyratdfvmdrlpm.comurcnkvuuju.comushfktptgmspn.comutpsygswnjjw.comutvjcdjcwgqm.comutvvpcpmqhbnedb.comuwsctpihlt.comuxlyihgvfnqcrfcf.comuxqbewwdunihwscfl.comvfcyyjwcdrjjunrrw.comvgfsnrewuxeaoxoh.comvjpufudekyotltdnog.comvjrjcapuwf.comvlupfbsuppipkrvbsdy.comvmdgwbenh.comvmhgbribbhm.comvmurixwrquhb.comvnskyqlkrdfnnp.comvpchdxywmxtxedwgfac.comvvhvidpeog.comvxpxgorqkihafv.comvyibjxjnshtry.comwatqjvqnf.comwbjatshumpre.comwdcjfyyfwpx.comwgkyyalemnvhdrai.comwiyqctbhe.comwldpcgpkdxhdhvlpjc.comwmbnkplxddiaktnkjk.comwnlgghgffr.comwnoykspnesqfwbkgi.comwpaxdlstrs.comwpwaislxxgiskgscy.comwqfmumga.comwqnefkerofcmrap.comwrfpmykunwbrscjann.comwsjapwfphnhriq.comwvogkbbapujp.comwwgxwnil.comwxurahlisqbmppqss.comxcmcupdfcevkgbrue.comxeucibnop.comxfcdavqouyevtvgjwu.comxiangglgqatolsgfxqi.comxioyjfiguiuluff.comxnttkdfunybxgn.comxnuqkdwek.comxoodachpaujnikmpp.comxqdrbrjiqwwpahhk.comxsredbpaef.comxumpkgnvdcmhykvdak.comxxkoixiiiqpyecxoaka.comyarymutdstxwp.comybbwxrcoujexdh.comybdwipovbicmpekyh.comybmhumhymqj.comyecjrsxe.comyicgycrtyoxaiu.comykesfabqxbvmns.comykkcsanct.comylvylxwjpkcdl.comymcwineqkj.comynergdikorjg.comyqvndqgijbpmx.comyscqbwwljsiwwr.comyssrqxyljwrioko.comyxhkddrdcpbccoabmuk.comyyeyutjgnsfrmswdygl.com&lt;/textarea&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Registered domains. See the text version below. The yellow/red entries show active C&amp;amp;C. All others are sinkholed or NXD'd.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-xEZXpDht4Wg/Tw6PKshFHLI/AAAAAAAAC28/E_dIYHOg5ok/s1600/doman.GIF" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://3.bp.blogspot.com/-xEZXpDht4Wg/Tw6PKshFHLI/AAAAAAAAC28/E_dIYHOg5ok/s640/doman.GIF" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;textarea cols="80" rows="20"&gt;ihoxyanyker.com  87.255.51.229 n/a     tom jerry        (arrettom83@yahoo.com)     st l 12     new york     New York,10005     US     Tel. +520.5467689 anxpepxpukbfmh.com   PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 carrerfullezz.com   PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 goopndlgvy.com 89-149-242-185.local 89.149.242.185 PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 hetjymgiddyamqq.com  87.255.51.229 PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 mstwcsnvylmullkqh.com hosted-by.leaseweb.com 62.212.65.176 PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 qfitnlxp.com  87.255.51.229 PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 vxpxgorqkihafv.com   PrivacyProtect.org     Domain Admin        (contact@privacyprotect.org)     ID#10760, PO Box 16     Note - All Postal Mails Rejected, visit Privacyprotect.org     Nobby Beach     null,QLD 4218     AU     Tel. +45.36946676 fssuatmti.com  82.165.39.88 Spy Eye Ilyinka Street 23 103132 Moscow RU Phone: +49.56953776 the.malware.cabal@gmail.com gqmrhecnntccmawclmq.com  82.165.39.88 Spy Eye Ilyinka Street 23 103132 Moscow RU Phone: +49.56953776 the.malware.cabal@gmail.com ouwwtmcnuiudw.com  82.165.39.88 Spy Eye Ilyinka Street 23 103132 Moscow RU Phone: +49.56953776 the.malware.cabal@gmail.com qdfgqwiovjlfegdcepm.com  82.165.39.88 Spy Eye Ilyinka Street 23 103132 Moscow RU Phone: +49.56953776 the.malware.cabal@gmail.com vlupfbsuppipkrvbsdy.com  82.165.39.88 Spy Eye Ilyinka Street 23 103132 Moscow RU Phone: +49.56953776 the.malware.cabal@gmail.com rjordulltl.com 89-149-242-185.local 89.149.242.185 Aleksandr Bragilevskij snkbcptiqgqmlvw.com   Aleksandr Bragilevskij star-trakers.com   Aleksandr Bragilevskij cpmsussgpibatpmswq.com 176-31-62-76.this.domain.has.been.sinkholed.by.zinkhole.org 176.31.62.76 Contact Privacy Inc. Customer 0129677017  96 Mowat Ave  Toronto, ON M6K 3M1  CA eeuprbpohspwje.com 176-31-62-76.this.domain.has.been.sinkholed.by.zinkhole.org 176.31.62.76 Contact Privacy Inc. Customer 0129769280  96 Mowat Ave  Toronto, ON M6K 3M1  CA itehtxcch.com 176-31-62-76.this.domain.has.been.sinkholed.by.zinkhole.org 176.31.62.76 Contact Privacy Inc. Customer 0129769281  96 Mowat Ave  Toronto, ON M6K 3M1  CA oaifpapl.com ip-50-62-3-35.ip.secureserver.net 50.62.3.35 Domains By Proxy, LLC DomainsByProxy.com 15111 N. Hayden Rd., Ste 160, PMB 353 Scottsdale, Arizona 85260 United States &lt;/textarea&gt;&lt;/div&gt;&lt;br /&gt;As you notice, many domains are registered by "Aleksandr Bragilevskij" &lt;br /&gt;Registrar: Regtime Ltd.&lt;br /&gt;Creation date: 2011-12-03&lt;br /&gt;Expiration date: 2012-12-03&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Aleksandr Bragilevskij&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email: pfizer.corp@yahoo.com&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Organization: Aleksandr Bragilevskij&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Address: 333 E 79th St # 1T,&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; City: New York City&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; State: NY&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ZIP: 10001&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Country: UM&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Phone: +1.2127332323 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fax: +1.2127332323&lt;br /&gt;&lt;br /&gt;Google Search for pfizer.corp@yahoo.com reveals that the same address was used to register fake Canadian pharmacy sites, which makes sense, considering the Viagra spam.&lt;br /&gt;&lt;br /&gt;trustpharmacy.us&lt;br /&gt;&lt;br /&gt;188.72.200.84&lt;br /&gt;Markus Faizer&lt;br /&gt;Pfizer International&lt;br /&gt;333 E 79th St # 1T,&lt;br /&gt;New York City&lt;br /&gt;NY&lt;br /&gt;10001&lt;br /&gt;United States&lt;br /&gt;Phone: +1.2127332323&lt;br /&gt;Fax: +1.2127332323&lt;br /&gt;E-mail: pfizer.corp@yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/-00-_1IMmNfI/Tw6U0hLyYLI/AAAAAAAAC3s/EwUySd39Yi4/s1600/trustpharmacy.us.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="408" src="http://4.bp.blogspot.com/-00-_1IMmNfI/Tw6U0hLyYLI/AAAAAAAAC3s/EwUySd39Yi4/s640/trustpharmacy.us.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lEqmLEEpvl0/Tw6SLd8AEOI/AAAAAAAAC3c/M4VqTWSxSS4/s1600/ts3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-lEqmLEEpvl0/Tw6SLd8AEOI/AAAAAAAAC3c/M4VqTWSxSS4/s1600/ts3.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-5744146941346663756?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/5744146941346663756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5744146941346663756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5744146941346663756'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html' title='Blackhole Ramnit - samples and analysis'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-N26qLLPK9vc/Tw6QEj_rtnI/AAAAAAAAC3E/Bxj7hm9jOEg/s72-c/bsod1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-8182032960271861296</id><published>2011-12-07T15:28:00.019-05:00</published><updated>2011-12-20T21:29:33.692-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2011-2462'/><title type='text'>Adobe Zero Day  CVE-2011-2462 - with samples</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;br /&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;a href="http://3.bp.blogspot.com/-elP95X9TZTY/Tt-4ZQqlmRI/AAAAAAAACzE/Se0yobbUZLs/s1600/logo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-elP95X9TZTY/Tt-4ZQqlmRI/AAAAAAAACzE/Se0yobbUZLs/s320/logo.png" width="320" /&gt;&lt;/a&gt;&lt;b style="background-color: #ffe599;"&gt; &lt;/b&gt;&lt;br /&gt;&lt;b style="background-color: #ffe599;"&gt;Update:&lt;/b&gt;&lt;span style="background-color: #fff2cc;"&gt; Adobe Released the patch yesterday and&amp;nbsp; I posted a few samples below. There were several campaigns with two variants -&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: #fff2cc;"&gt;&lt;b&gt;&lt;i&gt;1) unencrypted &lt;/i&gt;&lt;/b&gt;(some are not working - see explanation below)&lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: #fff2cc;"&gt;&lt;b&gt;&lt;i&gt;2) AESV3 encrypted&lt;/i&gt;&amp;nbsp;&lt;/b&gt; (try to use Origami to decrypt these). Each of the posted samples are marked by their 'type"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;CVE-2011-2462 &lt;/b&gt;the new Adobe Zero files come with the same payload we saw in &lt;a href="http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html"&gt;CVE-2010-3654 Adobe Flash player zero day vulnerability&lt;/a&gt;, trojan Sykipot - using the same technique with injecting a DLL file into&lt;br /&gt;iexplore, or firefox.exe, or outlook.exe and communicating with&amp;nbsp; &lt;span style="color: red;"&gt;hXXps://www.prettylikeher.com/asp/kys_allow_get.asp?name=getkys.kys over &lt;/span&gt;HTTPS. Brandon Dixon from &lt;a href="http://blog.9bplus.com/analyzing-cve-2011-2462"&gt;9bplus.com&lt;/a&gt; posted a great initial analysis of Java script and payload from a file with this exploit, I am just adding a few additional details.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;div dir="ltr"&gt;&lt;div class="post-body entry-content"&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;(CVE)number&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2462"&gt;CVE-2011-2462 &lt;/a&gt;Unspecified vulnerability in the U3D component in Adobe Reader andAcrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader9.x through 9.4.6 on UNIX, allows remote attackers to executearbitrary code or cause a denial of service (memory corruption) viaunknown vectors, as exploited in the wild in December 2011. &lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;File information&lt;/span&gt;&lt;/h3&gt;&lt;div style="color: black;"&gt;&lt;b&gt;Unencrypted&lt;/b&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: FD778C023020A23311B68127BF7E7692_merray christmas.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;Size: 293808&lt;br /&gt;MD5:&amp;nbsp; FD778C023020A23311B68127BF7E7692&lt;/div&gt;&lt;br /&gt;&lt;div style="color: black;"&gt;File: 2172079c9c4aa385624de6b4987dbc15 &lt;span class="blackthick" id="status-object"&gt;FY12 Per Diem Rates.pdf&lt;/span&gt;.pdf&amp;nbsp; &lt;br /&gt;Size: 118089&lt;br /&gt;MD5:&amp;nbsp; 2172079C9C4AA385624DE6B4987DBC15&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: 721fda5df552f4130218ad9bd2a4ab78.pdf&amp;nbsp;&amp;nbsp; ManTech Employee Satisfaction Survey.pdf&lt;br /&gt;Size: 275683&lt;br /&gt;MD5:&amp;nbsp; 721FDA5DF552F4130218AD9BD2A4AB78&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: 517fe6ba9417e6c8b4d0a0b3b9c4c9a9.pdf&amp;nbsp; 2012 Federal Employee Pay Calendar.pdf&lt;br /&gt;Size: 80577&lt;br /&gt;MD5:&amp;nbsp; 517FE6BA9417E6C8B4D0A0B3B9C4C9A9 &lt;/div&gt;&lt;div style="color: black;"&gt;---------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;b&gt;Encrypted&lt;/b&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: 601F8F52CEDF043EE4D3D3C83706329F_invoice.pdf&lt;br /&gt;Size: 258092&lt;br /&gt;MD5:&amp;nbsp; 601F8F52CEDF043EE4D3D3C83706329F&lt;/div&gt;&lt;br /&gt;&lt;div style="color: black;"&gt;1E46C60E65AE9F9C9C8850372D8DA491_電子郵件資訊安全防護措施.pdf&amp;nbsp;&amp;nbsp; - Email security protection measures.pdf&lt;/div&gt;&lt;div style="color: black;"&gt;Size: 1201039&lt;br /&gt;MD5:&amp;nbsp; 1E46C60E65AE9F9C9C8850372D8DA491 &lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: 92e9b24f7d041c4e6e952309e352e3753a21.pdf&amp;nbsp;&lt;/div&gt;&lt;div style="color: black;"&gt;Size: 711584&lt;br /&gt;MD5:&amp;nbsp; 7EAB072B76ABC4C3E8CBA8173C79890C&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;File: c095e10041da52f6434c1eb072cc570a03a8.pdf&lt;br /&gt;Size: 405659&lt;br /&gt;MD5:&amp;nbsp; B9872F4B6D2290DE75A7FF2874A28850&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: black;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal;"&gt;&lt;/h3&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;Download&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;div style="color: #38761d;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s1600/bag6.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s320/bag6.JPG" /&gt;&lt;/a&gt;&lt;span style="color: black;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?cbnhue6498c948m"&gt;You can download all samples from here (email me if you need the password - email address is in my profile)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: blue;"&gt;&lt;a href="http://www.mediafire.com/?nqnw5bv8zc4fxtv"&gt;You can download dropped files described below from here&amp;nbsp;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://mediafire.com/?oquol1gr1nyuuuz"&gt;You can download pcap from here &lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s1600/orange2.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s320/orange2.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=7885177434994542510&amp;amp;postID=166499980563317027" name="more"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="date-posts"&gt;&lt;div class="post-outer"&gt;&lt;div class="post hentry"&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;div class="post hentry"&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Automatic scans&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=ed87a5383005e0389c9d942c046d70cff12a889bad5c5bd8b340260747a667bd-1323518557"&gt;merray christmas.pdf&amp;nbsp; - Virustotal&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-10 12:02:37 (UTC)&lt;br /&gt;16 /43 (37.2%)&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.11.19.57 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; EXP/CVE-2011-2462&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF:CVE_2011_2462 [Expl]&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;ClamAV &amp;nbsp;&amp;nbsp;&amp;nbsp; 0.97.3.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; PUA.Script.PDF.EmbeddedJavaScript&lt;br /&gt;Commtouch &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.3.2.6 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE-2011-2462!Camelot&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.0.837 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief.def&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp;&amp;nbsp; 2010.1E &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Heuristic.BehavesLike.JS.Exploit.G&lt;br /&gt;Panda &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.3.5 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit/PDF.Gen.B&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.72.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exp/20112462-A&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Bloodhound.Exploit.439&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; HEUR_PDFEXP.B&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; HEUR_PDFEXP.B&lt;br /&gt;VIPRE &amp;nbsp;&amp;nbsp;&amp;nbsp; 11229 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-JS.Gen (v)&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : fd778c023020a23311b68127bf7e7692&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=c182ffe3398e92bece516d8b62b56a2de8395bf2e5fe2cb6af178194f7d741d2-1323665890"&gt;Virustotal&lt;/a&gt;&lt;br /&gt;FY12 Per Diem Rates.pdf&lt;br /&gt;2011-12-12 04:58:10 (UTC)&lt;br /&gt;Result:23 /41 (56.1%)&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.11.19.61 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; EXP/CVE-2011-2462&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF:CVE_2011_2462 [Expl]&lt;br /&gt;AVG &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1190 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; BackDoor.Outbreak.L&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;ClamAV &amp;nbsp;&amp;nbsp;&amp;nbsp; 0.97.3.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PUA.Script.PDF.EmbeddedJavaScript&lt;br /&gt;Commtouch &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.3.2.6 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE-2011-2462!Camelot&lt;br /&gt;Comodo &amp;nbsp;&amp;nbsp;&amp;nbsp; 10927 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; UnclassifiedMalware&lt;br /&gt;Emsisoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.1.0.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief!IK&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;Ikarus &amp;nbsp;&amp;nbsp;&amp;nbsp; T3.1.1.109.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief&lt;br /&gt;K7AntiVirus &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.119.5640 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.0.837 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief.def&lt;br /&gt;McAfee &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.400.0.1158 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp;&amp;nbsp; 2010.1E &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.07.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE/2011-2462.A&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.72.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exp/20112462-A&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Bloodhound.Exploit.439&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;VIPRE &amp;nbsp;&amp;nbsp;&amp;nbsp; 11239 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-JS.Gen (v)&lt;br /&gt;ViRobot &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12.4820 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF.S.CVE-2011-2462.118089&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp;&amp;nbsp; 14.1.110.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Pdfjsc.Gen&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 2172079c9c4aa385624de6b4987dbc15 &lt;br /&gt;&lt;a href="http://www.blogger.com/goog_1618315172"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=036e049c625a2c3fc5f434d0784a2a215fbde7a90c561db731ba598509860a0c-1323665984"&gt;ManTech Employee Satisfaction Survey.pdf&amp;nbsp; - Virustotal&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-12 04:59:44 (UTC)&lt;br /&gt;Result: 26 /43 (60.5%)&lt;br /&gt;Antivirus &amp;nbsp;&amp;nbsp;&amp;nbsp; Version &amp;nbsp;&amp;nbsp;&amp;nbsp; Last Update &amp;nbsp;&amp;nbsp;&amp;nbsp; Result&lt;br /&gt;AhnLab-V3 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.10.02 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Cve-2011-2462&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.11.19.61 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; EXP/CVE-2011-2462&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF:CVE_2011_2462 [Expl]&lt;br /&gt;AVG &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1190 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; BackDoor.Outbreak.L&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;ClamAV &amp;nbsp;&amp;nbsp;&amp;nbsp; 0.97.3.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PUA.Script.PDF.EmbeddedJavaScript&lt;br /&gt;Commtouch &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.3.2.6 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE-2011-2462!Camelot&lt;br /&gt;Comodo &amp;nbsp;&amp;nbsp;&amp;nbsp; 10927 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; UnclassifiedMalware&lt;br /&gt;DrWeb &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.0.2.03300 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF.2642&lt;br /&gt;Emsisoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.1.0.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D!IK&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;Fortinet &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.3.388.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Pidief.DEF!exploit&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22.304/22.569 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;Ikarus &amp;nbsp;&amp;nbsp;&amp;nbsp; T3.1.1.109.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D&lt;br /&gt;K7AntiVirus &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.119.5640 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.09 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.0.837 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief.def&lt;br /&gt;McAfee &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.400.0.1158 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp;&amp;nbsp; 2010.1E &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.07.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE/2011-2462.A&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.72.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exp/20112462-A&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Bloodhound.Exploit.439&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;VIPRE &amp;nbsp;&amp;nbsp;&amp;nbsp; 11239 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-JS.Gen (v)&lt;br /&gt;ViRobot &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12.4820 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF.S.CVE-2011-2462.275683&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp;&amp;nbsp; 14.1.110.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Pdfjsc.Gen&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 721fda5df552f4130218ad9bd2a4ab78&lt;br /&gt;&lt;a href="http://www.blogger.com/goog_1618315176"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=fa32485935ab75d09cae7d52f5251fb6620813205fb45a1b05d91e23b56068a1-1323751234"&gt;2012 Federal Employee Pay Calendar.pdf&amp;nbsp; Virustotal&lt;/a&gt;&lt;br /&gt;Submission date:2011-12-13 04:40:34 (UTC)&lt;br /&gt;Result:30 /43 (69.8%)&lt;br /&gt;Antivirus &amp;nbsp;&amp;nbsp;&amp;nbsp; Version &amp;nbsp;&amp;nbsp;&amp;nbsp; Last Update &amp;nbsp;&amp;nbsp;&amp;nbsp; Result&lt;br /&gt;AhnLab-V3 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12.00 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Cve-2011-2462&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.11.19.74 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; EXP/CVE-2011-2462&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF:CVE_2011_2462 [Expl]&lt;br /&gt;AVG &amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1190 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; BackDoor.Outbreak.L&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;ClamAV &amp;nbsp;&amp;nbsp;&amp;nbsp; 0.97.3.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; PUA.Script.PDF.EmbeddedJavaScript&lt;br /&gt;Commtouch &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.3.2.6 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE-2011-2462!Camelot&lt;br /&gt;Comodo &amp;nbsp;&amp;nbsp;&amp;nbsp; 10935 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; UnclassifiedMalware&lt;br /&gt;DrWeb &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.0.2.03300 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF.2642&lt;br /&gt;Emsisoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.1.0.11 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D!IK&lt;br /&gt;eTrust-Vet &amp;nbsp;&amp;nbsp;&amp;nbsp; 37.0.9620 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Pidief.AJL&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit:JS/CVE-2011-2462.A&lt;br /&gt;Fortinet &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.3.388.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Pidief.DEF!exploit&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D.Gen&lt;br /&gt;Ikarus &amp;nbsp;&amp;nbsp;&amp;nbsp; T3.1.1.109.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF-U3D&lt;br /&gt;K7AntiVirus &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.119.5661 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.0.837 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Win32.Pidief.def&lt;br /&gt;McAfee &amp;nbsp;&amp;nbsp;&amp;nbsp; 5.400.0.1158 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp;&amp;nbsp; 2010.1E &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit-CVE2011-2462&lt;br /&gt;NOD32 &amp;nbsp;&amp;nbsp;&amp;nbsp; 6705 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF/Exploit.CVE-2011-2462.A&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.07.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; CVE/2011-2462.A&lt;br /&gt;nProtect &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011-12-12.01 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan-Exploit/W32.Pidief.80577.JUM&lt;br /&gt;Rising &amp;nbsp;&amp;nbsp;&amp;nbsp; 23.88.00.02 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Hack.Exploit.CVE-2011-2462.a&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.72.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exp/20112462-A&lt;br /&gt;&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Bloodhound.Exploit.439&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.EGG&lt;br /&gt;VIPRE &amp;nbsp;&amp;nbsp;&amp;nbsp; 11245 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.PDF.CVE-2011-2462 (v)&lt;br /&gt;ViRobot &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13.4822 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; PDF.S.CVE-2011-2462.80577&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp;&amp;nbsp; 14.1.112.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.12 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit.Pdfjsc.Gen&lt;br /&gt;Additional information&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 517fe6ba9417e6c8b4d0a0b3b9c4c9a9&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;Additional info regarding files with non-working exploit &lt;b&gt;(from&amp;nbsp;SkyRecon R&amp;amp;D)&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="background-color: rgba(255, 255, 255, 0.918); color: #222222;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 19px; text-align: left;"&gt;File: 517fe6ba9417e6c8b4d0a0b3b9c4c9&lt;wbr&gt;&lt;/wbr&gt;a9.pdf&amp;nbsp; 2012 Federal Employee Pay Calendar.pdf&lt;/span&gt;&lt;br style="background-color: white; line-height: 19px; text-align: left;" /&gt;&lt;span style="background-color: white; line-height: 19px; text-align: left;"&gt;Size: 80577&lt;/span&gt;&lt;br style="background-color: white; line-height: 19px; text-align: left;" /&gt;&lt;span style="background-color: white; line-height: 19px; text-align: left;"&gt;MD5:&amp;nbsp; 517FE6BA9417E6C8B4D0A0B3B9C4C9&lt;wbr&gt;&lt;/wbr&gt;A9&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-family: inherit; text-align: left;"&gt;"It will not 'work' because the PDF has been altered by someone before sending.&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: inherit; text-align: left;"&gt;The real size of this PDF is : 80568 bytes, but someone added at the end of this PDF a string of 9 bytes ('grew').&lt;/span&gt;&lt;span style="font-family: inherit;"&gt;The problem is that the shellcode embeded in this PDF check its size before trying to drop anything,&lt;/span&gt;&lt;span style="font-family: inherit;"&gt;as the size is no longer 80568&amp;nbsp;but 80577, the shellcode never drops the exe or decoy PDF.&lt;/span&gt;&lt;span style="font-family: inherit;"&gt;So in order to get this PDF to 'work' one needs to remove the last 9 bytes of the file before opening it."&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blogger.com/goog_1618315180"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=3ea63d0f398f7e4f084932c251de83ea8bb50018912cf46829cab817ce3b2e24-1324104292"&gt;601F8F52CEDF043EE4D3D3C83706329F_invoice.pdf&lt;span id="goog_1618315182"&gt;&lt;/span&gt;&lt;span id="goog_1618315183"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-17 06:44:52 (UTC)&lt;br /&gt;0/ 43 (0.0%)&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 601f8f52cedf043ee4d3d3c83706329f&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=7f066bac959dc976a3fb08cdb6f83d50108ab7fc1437c71590ffdfd9b6b4055a-1324104336"&gt;1E46C60E65AE9F9C9C8850372D8DA491_____________.pdf&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-17 06:45:36 (UTC)&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 1e46c60e65ae9f9c9c8850372d8da491&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=19f664ba4966e8ac10d6e2f02e47c7f20123d78f2a65a28d2614c6a73f0cdf5d-1324105168"&gt; 92e9b24f7d041c4e6e952309e352e3753a21.pdf&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-17 06:59:28 (UTC)&lt;br /&gt;2/ 43 (4.7%)&lt;br /&gt;TrendMicro&amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008&amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.17&amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.RC1&lt;br /&gt;TrendMicro-HouseCall&amp;nbsp;&amp;nbsp;&amp;nbsp; 9.500.0.1008&amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.12.17&amp;nbsp;&amp;nbsp;&amp;nbsp; TROJ_PIDIEF.RC1&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 7eab072b76abc4c3e8cba8173c79890c&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=02b7b170fe907e84a00d89f2b8246b2315036c7d5575347fa4312dafcc0ca23b-1323813598"&gt;employee_AUS.pdf&lt;/a&gt;&lt;br /&gt;Submission date:&lt;br /&gt;2011-12-13 21:59:58 (UTC)&lt;br /&gt;0 /43 (0.0%)&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : b9872f4b6d2290de75a7ff2874a28850&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Payload and traffic&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&amp;nbsp;The clean decoy file is &lt;br /&gt;&amp;nbsp;&lt;span style="color: red;"&gt;ManTech Employee Satisfaction Survey.pdf&lt;/span&gt; as it was mentioned by Brandon Dixon. &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-x5nM9T-xplk/Tt-8OeO8KRI/AAAAAAAACzM/kCn0AsY7I10/s1600/CLEAN.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="462" src="http://1.bp.blogspot.com/-x5nM9T-xplk/Tt-8OeO8KRI/AAAAAAAACzM/kCn0AsY7I10/s640/CLEAN.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;The trojan has been described before and you can see analysis at&lt;br /&gt;&lt;a href="http://contagiodump.blogspot.com/2010/10/potential-new-adobe-flash-player-zero.html"&gt;Contagio. CVE-2010-3654 Adobe Flash player zero day vulnerability&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securelist.com/en/blog/2335/Sykipot_exploits_an_Adobe_Flash_Zero_Day"&gt;Kaspersky Lab 2010&amp;nbsp; Sykipot exploits an Adobe Flash Zero-Day &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Local Settings\&lt;span style="color: red;"&gt;pretty.exe&lt;/span&gt;&lt;br /&gt;Size: 39936&lt;br /&gt;MD5:&amp;nbsp; E769A920B12D019679C43A9A4C0D7E2C&lt;br /&gt;&lt;br /&gt;&lt;div style="color: red; font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Headers Info&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="color: red; font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Time Date Stamp&amp;nbsp; 4ECB430Eh 22/11/2011 06:37:02&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;pretty.exe&lt;br /&gt;Submission date: 2011-12-07 16:33:35 (UTC)&lt;br /&gt;Result: 18 /43 (41.9%)&lt;br /&gt;Antivirus Version Last Update Result &lt;br /&gt;AhnLab-V3 2011.12.07.00 2011.12.07 Trojan/Win32.Scar &lt;br /&gt;AntiVir 7.11.19.14 2011.12.07 TR/Spy.Gen &lt;br /&gt;AVG 10.0.0.1190 2011.12.07 unknown virus Win32/DH.FF83001C{40080009-00400000-&lt;br /&gt;00000000} &lt;br /&gt;BitDefender 7.2 2011.12.07 Gen:Trojan.Heur.PT.cqW@a0iqwubb &lt;br /&gt;Commtouch 5.3.2.6 2011.12.07 W32/Heuristic-KPP!Eldorado &lt;br /&gt;DrWeb 5.0.2.03300 2011.12.07 BACKDOOR.Trojan &lt;br /&gt;Emsisoft 5.1.0.11 2011.12.07 Backdoor.Win32.Wkysol!IK &lt;br /&gt;F-Prot 4.6.5.141 2011.11.29 W32/Heuristic-KPP!Eldorado &lt;br /&gt;F-Secure 9.0.16440.0 2011.12.07 Gen:Trojan.Heur.PT.cqW@a0iqwubb &lt;br /&gt;GData 22 2011.12.07 Gen:Trojan.Heur.PT.cqW@a0iqwubb &lt;br /&gt;Ikarus T3.1.1.109.0 2011.12.07 Backdoor.Win32.Wkysol &lt;br /&gt;Kaspersky 9.0.0.837 2011.12.07 HEUR:Trojan.Win32.Invader &lt;br /&gt;McAfee 5.400.0.1158 2011.12.07 Generic BackDoor.u &lt;br /&gt;McAfee-GW-Edition 2010.1E 2011.12.07 Artemis!E769A920B12D &lt;br /&gt;PCTools 8.0.0.5 2011.12.07 Backdoor.Sykipot &lt;br /&gt;Sophos 4.71.0 2011.12.07 Mal/Dropr-C &lt;br /&gt;Symantec 20111.2.0.82 2011.12.07 Backdoor.Sykipot &lt;br /&gt;VBA32 3.12.16.4 2011.12.07 Trojan.Win32.Inject.2 &lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : e769a920b12d019679c43a9a4c0d7e2c &lt;br /&gt;&lt;br /&gt;&amp;nbsp;Local Settings\&lt;span style="color: red;"&gt;WSE4EF1.TMP&amp;nbsp; &lt;/span&gt;&lt;br /&gt;Size: 31232&lt;br /&gt;MD5:&amp;nbsp; BA7793845FE2A02187263A96E8DAAEC6&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=21d58245c495b9ed4234577fa3fb43cd4c703f38a9b5ce83aa490613168a735f-1323275543"&gt;http://www.virustotal.com/file-scan/report.html?id=21d58245c495b9ed4234577fa3fb43cd4c703f38a9b5ce83aa490613168a735f-1323275543&lt;/a&gt;&lt;br /&gt;&amp;nbsp;original name: wship4.dll&lt;br /&gt;&lt;br /&gt;WSE4EF1.TMP&lt;br /&gt;Submission date: 2011-12-07 16:32:23 (UTC)&lt;br /&gt;Result: 14 /43 (32.6%)&lt;br /&gt;AhnLab-V3 2011.12.07.00 2011.12.07 Backdoor/Win32.CSon &lt;br /&gt;AntiVir 7.11.19.14 2011.12.07 TR/Spy.Gen &lt;br /&gt;BitDefender 7.2 2011.12.07 Gen:Variant.Graftor.3624 &lt;br /&gt;Emsisoft 5.1.0.11 2011.12.07 Backdoor.Win32.Wkysol!IK &lt;br /&gt;F-Secure 9.0.16440.0 2011.12.07 Gen:Variant.Graftor.3624 &lt;br /&gt;GData 22 2011.12.07 Gen:Variant.Graftor.3624 &lt;br /&gt;Ikarus T3.1.1.109.0 2011.12.07 Backdoor.Win32.Wkysol &lt;br /&gt;McAfee 5.400.0.1158 2011.12.07 Artemis!BA7793845FE2 &lt;br /&gt;McAfee-GW-Edition 2010.1E 2011.12.07 Artemis!BA7793845FE2 &lt;br /&gt;nProtect 2011-12-07.01 2011.12.07 Gen:Variant.Graftor.3624 &lt;br /&gt;Panda 10.0.3.5 2011.12.06 Suspicious file &lt;br /&gt;PCTools 8.0.0.5 2011.12.07 Backdoor.Sykipot &lt;br /&gt;Symantec 20111.2.0.82 2011.12.07 Backdoor.Sykipot &lt;br /&gt;TrendMicro-HouseCall 9.500.0.1008 2011.12.07 - &lt;br /&gt;VIPRE 11215 2011.12.07 Trojan.Win32.Wisp.gen.a (v) &lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : ba7793845fe2a02187263a96e8daaec6 &lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;WSE4EF1.TMP &lt;span style="color: black;"&gt;can be found and extractted from the Resource section of the main file &lt;span style="color: red;"&gt;PRETTY.EXE&lt;/span&gt;, the resource language is LANG_CHINESE, SUBLANG_CHINESE_SIMPLIFIED&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;span style="color: black;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;Indeed, the temp file &lt;span style="color: red;"&gt;WSE4EF1.TMP&amp;nbsp; &lt;/span&gt;, which is in our case it injected itself in our case in iexplore process&amp;nbsp; but it can aslo use firefox.exe and outlook.exe. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-B4WTOaiBasM/Tt-8sQN2Y6I/AAAAAAAACzU/qeFX5SZzvbQ/s1600/inject.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="28" src="http://1.bp.blogspot.com/-B4WTOaiBasM/Tt-8sQN2Y6I/AAAAAAAACzU/qeFX5SZzvbQ/s640/inject.png" width="640" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;span style="color: black;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-31ugZHPcKSs/Tt_EZBEpsgI/AAAAAAAACzk/6vEB-UEoA_M/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="346" src="http://4.bp.blogspot.com/-31ugZHPcKSs/Tt_EZBEpsgI/AAAAAAAACzk/6vEB-UEoA_M/s640/Untitled.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;deleted_files&lt;/b&gt;&lt;br /&gt;\Local Settings\ctfmon.exe&amp;nbsp; - same file as&amp;nbsp; pretty.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Strings from pretty.exe&lt;br /&gt;&lt;blockquote class="tr_bq" style="color: #073763;"&gt;ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*&lt;br /&gt;Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.7) Gecko/2009021910 Firefox/3.0.7&lt;br /&gt;www.prettylikeher.com&lt;br /&gt;https://www.prettylikeher.com/asp/kys_allow_get.asp?name=&lt;br /&gt;explorer.exe&lt;br /&gt;pdtpretty.tmp&lt;br /&gt;gdtpretty.tmp&lt;br /&gt;ptpretty.tmp&lt;br /&gt;gtpretty.tmp&lt;br /&gt;POST&lt;br /&gt;HTTP/1.0&lt;br /&gt;http://www.yahoo.com/&lt;br /&gt;https&lt;br /&gt;putfile:&lt;br /&gt;getfile:&lt;br /&gt;time:&lt;br /&gt;door:&lt;br /&gt;cmd:&lt;br /&gt;19990817&lt;br /&gt;%s,%s,%d&lt;br /&gt;Proxyserver&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Internet Settings&lt;br /&gt;firefox&lt;br /&gt;%s,%d&lt;br /&gt;-pretty20111122&lt;br /&gt;&amp;amp;hostname=&lt;br /&gt;https://www.prettylikeher.com/asp/kys_allow_get.asp?name=getkys.kys&lt;br /&gt;outlook&lt;br /&gt;iexplore&lt;br /&gt;firefox.exe&lt;br /&gt;outlook.exe&lt;br /&gt;iexplore.exe&lt;br /&gt;/ASP/KYS_ALLOW_PUT.ASP?TYPE=&lt;br /&gt;%s,get:%s,%d&lt;br /&gt;get:%s,%d&lt;br /&gt;unsuccessfully!&lt;br /&gt;successfully!&lt;br /&gt;%s%s%s%s%s&lt;br /&gt;cmd /c "&lt;br /&gt;process&lt;br /&gt;kill&lt;/blockquote&gt;The trojan communicates with the C&amp;amp;C domain on port 443&lt;br /&gt;&lt;span style="color: red;"&gt;hXXps://www.prettylikeher.com/asp/kys_allow_get.asp?name=getkys.kys&lt;/span&gt;&lt;br /&gt;&lt;a href="http://mediafire.com/?oquol1gr1nyuuuz"&gt;You can download pcap from here&amp;nbsp;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0zr2BR5nY-g/Tt-9yxDCnjI/AAAAAAAACzc/6vKXl6CRX3E/s1600/traf.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="380" src="http://1.bp.blogspot.com/-0zr2BR5nY-g/Tt-9yxDCnjI/AAAAAAAACzc/6vKXl6CRX3E/s640/traf.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;the&amp;nbsp; C&amp;amp;C server is running a car design front end, which seems like it was stolen from somewhere else&lt;/div&gt;&lt;b&gt;prettylikeher.com&lt;/b&gt;&lt;br /&gt;Registrant Contact:&lt;br /&gt;&amp;nbsp;&amp;nbsp; deng haimei&lt;br /&gt;&amp;nbsp;&amp;nbsp; haimei deng &lt;br /&gt;&amp;nbsp;&amp;nbsp; +86.07733944048 fax: +86.07733944048&lt;br /&gt;&amp;nbsp;&amp;nbsp; yulingshi&lt;br /&gt;&amp;nbsp;&amp;nbsp; guangxi guangxi 537000&lt;br /&gt;&amp;nbsp;&amp;nbsp; CN&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-JVvNA00I38w/Tt_JArvxi-I/AAAAAAAACzs/POxXMwYsq3U/s1600/Untitled.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://3.bp.blogspot.com/-JVvNA00I38w/Tt_JArvxi-I/AAAAAAAACzs/POxXMwYsq3U/s320/Untitled.png" width="320" /&gt;&lt;/a&gt;&lt;b&gt;71.36.88.82&lt;/b&gt; &lt;b&gt;RData&lt;/b&gt;&lt;br /&gt;&lt;div class="post hentry"&gt;&lt;span style="color: blue;"&gt;ccnslc.com.&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;desktop.newcarstyle.com.&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;info.kimfishions.com.&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;www.ccnslc.com.&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;www.prettylikeher.com&lt;/span&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/div&gt;&lt;div class="post hentry"&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;Other&amp;nbsp; domain hosted on the same IP&lt;/div&gt;&lt;div class="post hentry"&gt;Domain&amp;nbsp;name:&lt;b&gt;&amp;nbsp;imagespornfree.com&lt;/b&gt;Registrant&amp;nbsp;Contact:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;helan&amp;nbsp;naiye&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;naiye&amp;nbsp;helan&amp;nbsp;&lt;a href="http://www.domaintools.com/research/reverse-whois/?email=9e946b1205dd7b25dcf3557fcca8d1f3" style="position: relative; top: -5px;" title="Search for this email address"&gt;&lt;img align="middle" border="0" src="http://source.domaintools.com/email.pgif?md5=9e946b1205dd7b25dcf3557fcca8d1f3&amp;amp;face=arial&amp;amp;size=9&amp;amp;color=000000&amp;amp;bgcolor=FFFFFF&amp;amp;face=arial&amp;amp;size=9&amp;amp;color=0000FF&amp;amp;bgcolor=FFFFFF&amp;amp;format[]=underline&amp;amp;format[]=transparent&amp;amp;format[]=transparent" /&gt;&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;+86.02366029085&amp;nbsp;fax:&amp;nbsp;+86.02366029085&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;chongqingshishanpingbei111hao&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;chonqing&amp;nbsp;chongqing&amp;nbsp;210000&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;CN&lt;br /&gt;Hosting history&lt;br /&gt;Event Date &amp;nbsp;&amp;nbsp;&amp;nbsp; Action &amp;nbsp;&amp;nbsp;&amp;nbsp; Pre-Action IP &amp;nbsp;&amp;nbsp;&amp;nbsp; Post-Action IP&lt;br /&gt;2011-11-06 &amp;nbsp;&amp;nbsp;&amp;nbsp; New &amp;nbsp;&amp;nbsp;&amp;nbsp; -none- &amp;nbsp;&amp;nbsp;&amp;nbsp; 68.167.27.215&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;Name Server History&lt;br /&gt;Event Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pre-Action Server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Post-Action Server&lt;br /&gt;2011-10-10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; New&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -none-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cdncenter.com&lt;br /&gt;RData for &lt;br /&gt;68.167.27.215&lt;br /&gt;ftp.younts.com.&lt;br /&gt;mail.agentsafe.com.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-8182032960271861296?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/8182032960271861296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2011/12/adobe-zero-day-cve-2011-2462.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/8182032960271861296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/8182032960271861296'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2011/12/adobe-zero-day-cve-2011-2462.html' title='Adobe Zero Day  CVE-2011-2462 - with samples'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-elP95X9TZTY/Tt-4ZQqlmRI/AAAAAAAACzE/Se0yobbUZLs/s72-c/logo.png' height='72' width='72'/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-3554843933961966470</id><published>2011-11-29T02:58:00.004-05:00</published><updated>2011-11-29T23:59:04.928-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDF cuckoo'/><title type='text'>30 PDF files processed by Cuckoo Sandbox - results and samples</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="background-color: #fff2cc;"&gt;&lt;b&gt;Update -&lt;/b&gt; posted a list of the dropped files for each file and the C&amp;amp;C info from pcaps in the end of the post - for review and easy Googling.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-nuQHToWkaSE/TtSO-FHYliI/AAAAAAAACy8/mqClyhzgjh4/s1600/ss.GIF" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="157" src="http://1.bp.blogspot.com/-nuQHToWkaSE/TtSO-FHYliI/AAAAAAAACy8/mqClyhzgjh4/s200/ss.GIF" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr align="right"&gt;&lt;td class="tr-caption"&gt;&lt;span style="color: #666666; font-size: xx-small;"&gt;Shutterstock image&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;In addition to the post about the Cuckoo sandbox, please see below sandbox results and samples for 30 recent&amp;nbsp; PDF files (APT type). I excluded the payload/dropped files because of the large number of benign files in the same folder as the payload. Perhaps seeing the output will help you decide whether you want to deploy the sandbox or not.&lt;br /&gt;If you need to see the payload 'files' folders, please see the previous post for example or contact me.&lt;a href="https://twitter.com/#%21/botherder/status/141472324904960001"&gt;According to the author, the file dumps filtering will be added soon.&lt;/a&gt;&lt;br /&gt;&amp;nbsp;What you will see in the package:&lt;br /&gt;Original analysis folder (excluding "Files" - dropped files)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-lJImMPNTvdQ/TtSMXSk6waI/AAAAAAAACyc/07Tx4W6V05k/s1600/eg2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-4Hzl6tJLAAU/TtSMZCIBANI/AAAAAAAACyk/JV4dYSLp1Uw/s1600/eg1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Analysis.config - you will see the name of the analysed file there.&lt;/li&gt;&lt;li&gt; Analysis.log + report.txt- all API calls and created files log&lt;/li&gt;&lt;li&gt;Dump.pcap file&lt;/li&gt;&lt;li&gt;logs folder - in csv fomat&lt;/li&gt;&lt;li&gt;shots folder - screenshots taken&lt;/li&gt;&lt;li&gt;Original file itself&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;Additonal files&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;List of all hashes of all files&lt;/li&gt;&lt;li&gt;All pcap files converted to text&lt;/li&gt;&lt;li&gt;Filtered logs showing dropped files.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mpUy1G_My4M/TtSN5rGCihI/AAAAAAAACy0/v4sfHJJiZMU/s1600/add.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="377" src="http://3.bp.blogspot.com/-mpUy1G_My4M/TtSN5rGCihI/AAAAAAAACy0/v4sfHJJiZMU/s640/add.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jPwG_Erk-24/TtSMpttX3LI/AAAAAAAACys/VBTP8mDD-hg/s1600/eg1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;List of included files and corresponding Cuckoo sandbox analysis results&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;86730A9BC3AB99503322EDA6115C1096&amp;nbsp;&amp;nbsp;&amp;nbsp; 1104statment.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;35458535961F767E267487E39641766C&amp;nbsp;&amp;nbsp;&amp;nbsp; 1106.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;92D142E08DBEF9FC6BC61A575224C3EC&amp;nbsp;&amp;nbsp;&amp;nbsp; 111109.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;B4CB1B1182EA0B616ED6702A2B25FAC2&amp;nbsp;&amp;nbsp;&amp;nbsp; 20111106_.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;88B884E8CE014D6B8D30B8198E048708&amp;nbsp;&amp;nbsp;&amp;nbsp; 20111111_SexyDay.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;C0D5B1CC0C77FCF32FF02AAC98FAC536&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012().pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;31DD6F29F19626F8CE03D73B3F635296&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012()2.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;C89D0C1DF6B4EF20E8447B11BEB77723&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012()3.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;08CDC6213D63EA85FBCCD335579CAEC4&amp;nbsp;&amp;nbsp;&amp;nbsp; 2015.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;57F8BC2995CA99E20B356B623FA12F29&amp;nbsp;&amp;nbsp;&amp;nbsp; AEO.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;61481CBCBD35034C7CF4D1930B5E63E3&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT03306.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;CBEA315F41205B731379521C5464C134&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT03865.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;452703B9292A7A5D45EB224C622D32CF&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT11990.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;704D40896BF6C9EA174F4CF3B57AC562&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT25948.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;2A0DCB1915C0465949E7AECFB06F47EA&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT41702.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;979C64214F11F72EDDDD04FFC4887BB5&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT63950.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;E30D11EB28BB88681D1FB31DA88D84C6&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT78434.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;DD7A03F4932CB86A77BD57B1C21FC18F&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT85096.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;1188EA8F0D086A8860A3AAFB54A3FA76&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT88422.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;B4CB1B1182EA0B616ED6702A2B25FAC2&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT93159.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;91759CA240EECCC4C742CFF341C9A9A7&amp;nbsp;&amp;nbsp;&amp;nbsp; ATT93487.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;3173D2A0A607ECCF21707A3DC5DE30DA&amp;nbsp;&amp;nbsp;&amp;nbsp; Bainbridge Skills.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;F567FFD4F7A19A469D836E5A0A9552AB&amp;nbsp;&amp;nbsp;&amp;nbsp; Conference information for next week.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;670E22EC5EE2F8D08795BA7FF5A5D52E&amp;nbsp;&amp;nbsp;&amp;nbsp; DOB Aug 2011.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;01A1CAA4BA9EC050BA8CEAFE26998577&amp;nbsp;&amp;nbsp;&amp;nbsp; g20 summit.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;670E22EC5EE2F8D08795BA7FF5A5D52E&amp;nbsp;&amp;nbsp;&amp;nbsp; ID194.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;CDB6DCF66B7D3C5BC678378F46BA94E7&amp;nbsp;&amp;nbsp;&amp;nbsp; military procurement.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;C898ABCEA6EAAA3E1795322D02E95D7E&amp;nbsp;&amp;nbsp;&amp;nbsp; NorthKorea.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;0A630BBAA1691ED10540048BD5B4CF04&amp;nbsp;&amp;nbsp;&amp;nbsp; Nuclear Security and Summit Diplomacy.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;DE095F05913928CF58A27F27C5BF8605&amp;nbsp;&amp;nbsp;&amp;nbsp; statement.pdf&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jPwG_Erk-24/TtSMpttX3LI/AAAAAAAACys/VBTP8mDD-hg/s1600/eg1.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-jPwG_Erk-24/TtSMpttX3LI/AAAAAAAACys/VBTP8mDD-hg/s1600/eg1.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="color: black; font-size: small;"&gt;DROPPED FILES AND C&amp;amp;Cs&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="border: 3px solid green; height: 420px; overflow: auto; text-align: left; width: 770px;"&gt;&lt;span style="color: black;"&gt;&lt;span style="font-size: small;"&gt;52/[2011-11-29 00:13:25] "C:\APT_1104statment.pdf" &lt;br /&gt;52/[2011-11-29 00:13:28] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;52/[2011-11-29 00:13:28] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;52/[2011-11-29 00:13:28] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;52/[2011-11-29 00:13:28] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;52/[2011-11-29 00:13:28] "iso88591" &lt;br /&gt;78&amp;nbsp; 71.361654&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;81&amp;nbsp; 83.379329&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;53/[2011-11-29 00:15:55] "C:\APT_1106.pdf" &lt;br /&gt;53/[2011-11-29 00:15:56] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;53/[2011-11-29 00:15:56] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;53/[2011-11-29 00:15:56] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;53/[2011-11-29 00:15:56] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;53/[2011-11-29 00:15:56] "iso88591" &lt;br /&gt;103 131.960627&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.203.196.118 TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;54/[2011-11-29 00:18:22] "C:\APT_111109.pdf" &lt;br /&gt;54/[2011-11-29 00:18:23] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;54/[2011-11-29 00:18:23] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;54/[2011-11-29 00:18:23] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;54/[2011-11-29 00:18:23] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;54/[2011-11-29 00:18:23] "iso88591" &lt;br /&gt;&lt;br /&gt;&amp;nbsp;92 100.874401&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;93 106.882960&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;97 118.901642&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;99 119.300035 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1050 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;100 119.300466&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;101 119.300509&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 SSL Continuation Data&lt;br /&gt;102 119.300538 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1050 [ACK] Seq=1 Ack=193 Win=65535 Len=0&lt;br /&gt;104 119.671542 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1050 [FIN, ACK] Seq=1 Ack=193 Win=65535 Len=0&lt;br /&gt;105 119.672034&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 443 [ACK] Seq=193 Ack=2 Win=64240 Len=0&lt;br /&gt;106 119.672056&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 443 [FIN, ACK] Seq=193 Ack=2 Win=64240 Len=0&lt;br /&gt;107 119.672107 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1050 [ACK] Seq=2 Ack=194 Win=65535 Len=0&lt;br /&gt;108 119.672640&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1051 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;110 122.606271&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1051 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;111 123.110597 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;112 123.110991&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1051 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;113 123.111028&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 HTTP GET /khdpi.php?id=0080131911386GB524 HTTP/1.1 &lt;br /&gt;114 123.111058 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;115 123.564824 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 404 Nie znaleziono obiektu&amp;nbsp; (text/html)&lt;br /&gt;116 123.565799&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1051 &amp;gt; 80 [FIN, ACK] Seq=189 Ack=312 Win=63929 Len=0&lt;br /&gt;117 123.565880 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [ACK] Seq=312 Ack=190 Win=65535 Len=0&lt;br /&gt;118 123.581081 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [FIN, ACK] Seq=312 Ack=190 Win=65535 Len=0&lt;br /&gt;119 123.581393&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1051 &amp;gt; 80 [ACK] Seq=190 Ack=313 Win=63929 Len=0&lt;br /&gt;121 125.560394&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.203.196.118 TCP 1052 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;123 128.514543&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.203.196.118 TCP 1052 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;126 134.523033&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.203.196.118 TCP 1052 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;55/[2011-11-29 00:20:50] "C:\APT_20111106_.pdf" &lt;br /&gt;55/[2011-11-29 00:20:51] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;55/[2011-11-29 00:20:51] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;55/[2011-11-29 00:20:51] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;55/[2011-11-29 00:20:51] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;55/[2011-11-29 00:20:51] "iso88591"&lt;br /&gt;&amp;nbsp;60&amp;nbsp; 34.365192&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;61&amp;nbsp; 34.682612 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;62&amp;nbsp; 34.686987&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 34.687007&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 SSL Continuation Data&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 34.687042 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [ACK] Seq=1 Ack=194 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 37.286460 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Continuation Data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;56/[2011-11-29 00:23:18] "C:\APT_20111111_SexyDay.pdf" &lt;br /&gt;56/[2011-11-29 00:23:19] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;56/[2011-11-29 00:23:19] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;56/[2011-11-29 00:23:19] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;56/[2011-11-29 00:23:19] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;56/[2011-11-29 00:23:19] "iso88591" &lt;br /&gt;60&amp;nbsp; 34.580116&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;61&amp;nbsp; 35.001033 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;62&amp;nbsp; 35.001274&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1044 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 35.001683&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 SSL Continuation Data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;57/[2011-11-29 00:25:45] "C:\APT_2012().pdf" &lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;58/[2011-11-29 00:28:15] "C:\APT_2012()2.pdf" &lt;br /&gt;58/[2011-11-29 00:28:15] "C:\DOCUME~1\Angie\LOCALS~1\Temp\different orgasms.pdf" &lt;br /&gt;58/[2011-11-29 00:28:15] "C:\DOCUME~1\Angie\LOCALS~1\Temp\svchost.exe" &lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;59/[2011-11-29 00:30:42] "C:\APT_2012()3.pdf" &lt;br /&gt;59/[2011-11-29 00:30:43] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;59/[2011-11-29 00:30:43] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;59/[2011-11-29 00:30:43] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;59/[2011-11-29 00:30:43] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;59/[2011-11-29 00:30:43] "iso88591" &lt;br /&gt;&lt;br /&gt;&amp;nbsp;1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;59&amp;nbsp; 34.274013&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1043 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 37.193422&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1043 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;73&amp;nbsp; 43.201705&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1043 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;76&amp;nbsp; 55.221290&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1046 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 58.222827&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1046 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;82&amp;nbsp; 64.232492&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1046 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;86&amp;nbsp; 76.250579&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;88&amp;nbsp; 79.253888&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;91&amp;nbsp; 85.262904&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;95&amp;nbsp; 97.180318&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;97&amp;nbsp; 97.376698 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1048 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;98&amp;nbsp; 97.376875&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;99&amp;nbsp; 97.377127&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 HTTP GET /rqban.php?id=0026041911386GB524 HTTP/1.1 &lt;br /&gt;100&amp;nbsp; 97.377168 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1048 [ACK] Seq=1 Ack=188 Win=65535 Len=0&lt;br /&gt;110 127.883970&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 80 [FIN, ACK] Seq=188 Ack=1 Win=64240 Len=0&lt;br /&gt;111 127.884082 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1048 [ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;112 127.884442&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;113 128.055148 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1048 [FIN, ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;114 128.055442&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 80 [ACK] Seq=189 Ack=2 Win=64240 Len=0&lt;br /&gt;116 130.827421&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;121 136.835963&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;60/[2011-11-29 00:33:09] "C:\APT_2015.pdf" &lt;br /&gt;60/[2011-11-29 00:33:10] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;60/[2011-11-29 00:33:10] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;60/[2011-11-29 00:33:10] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;60/[2011-11-29 00:33:10] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;60/[2011-11-29 00:33:10] "iso88591" &lt;br /&gt;90&amp;nbsp; 85.128211&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 71.246.244.139 TCP 1047 &amp;gt; 1010 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;94&amp;nbsp; 97.055009&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 206.253.41.47 TCP 1048 &amp;gt; 8080 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;61/[2011-11-29 00:35:36] "C:\APT_AEO.pdf" &lt;br /&gt;61/[2011-11-29 00:35:37] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;61/[2011-11-29 00:35:37] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;61/[2011-11-29 00:35:37] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;61/[2011-11-29 00:35:37] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;61/[2011-11-29 00:35:37] "iso88591" &lt;br /&gt;&amp;nbsp;98 105.995079&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.203.196.118 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;103 120.016061&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 220.135.104.7 TCP 1048 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;62/[2011-11-29 00:38:03] "C:\APT_ATT03306.pdf" &lt;br /&gt;62/[2011-11-29 00:38:03] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;62/[2011-11-29 00:38:03] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;62/[2011-11-29 00:38:03] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;62/[2011-11-29 00:38:03] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;62/[2011-11-29 00:38:03] "iso88591" &lt;br /&gt;&amp;nbsp;62&amp;nbsp; 34.663176 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 34.664159&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 34.664179&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 SSL Continuation Data&lt;br /&gt;&lt;br /&gt;63/[2011-11-29 00:40:29] "C:\APT_ATT03865.pdf" &lt;br /&gt;&lt;br /&gt;64/[2011-11-29 00:42:59] "C:\APT_ATT11990.pdf" &lt;br /&gt;64/[2011-11-29 00:43:00] "C:\DOCUME~1\Angie\LOCALS~1\Temp\svchost.exe" &lt;br /&gt;64/[2011-11-29 00:43:00] "C:\WINDOWS\system32\cmd.exe" &lt;br /&gt;64/[2011-11-29 00:43:00] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;64/[2011-11-29 00:43:00] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;64/[2011-11-29 00:43:00] "iso88591" &lt;br /&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;66&amp;nbsp; 40.373167&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.85.109 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;67&amp;nbsp; 40.819758 60.249.85.109 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 40.820024&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.85.109 TCP 1043 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;69&amp;nbsp; 40.820061&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.85.109 SSL Continuation Data&lt;br /&gt;&amp;nbsp;70&amp;nbsp; 40.820088 60.249.85.109 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [ACK] Seq=1 Ack=23 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 40.881943&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A checkip.dyndns.org&lt;br /&gt;&amp;nbsp;75&amp;nbsp; 41.032372 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME checkip.dyndns.com A 216.146.39.70 A 91.198.22.70 A 216.146.38.70&lt;br /&gt;&amp;nbsp;76&amp;nbsp; 41.033219&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 41.269469 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 41.270321&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;79&amp;nbsp; 41.270384&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 HTTP GET / HTTP/1.1 Continuation or non-HTTP traffic&lt;br /&gt;&amp;nbsp;80&amp;nbsp; 41.270423 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=1 Ack=65 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;81&amp;nbsp; 41.552327 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;&amp;nbsp;82&amp;nbsp; 41.552557 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [FIN, ACK] Seq=261 Ack=65 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;83&amp;nbsp; 41.552712&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [ACK] Seq=65 Ack=262 Win=63980 Len=0&lt;br /&gt;&amp;nbsp;84&amp;nbsp; 41.552744&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [FIN, ACK] Seq=65 Ack=262 Win=63980 Len=0&lt;br /&gt;&amp;nbsp;85&amp;nbsp; 41.552773 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=262 Ack=66 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;86&amp;nbsp; 41.553781&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.85.109 SSL Continuation Data&lt;br /&gt;&lt;br /&gt;65/[2011-11-29 00:45:26] "C:\APT_ATT25948.pdf" &lt;br /&gt;65/[2011-11-29 00:45:27] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;65/[2011-11-29 00:45:27] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;65/[2011-11-29 00:45:27] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;65/[2011-11-29 00:45:27] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;65/[2011-11-29 00:45:27] "iso88591" &lt;br /&gt;&amp;nbsp;60&amp;nbsp; 35.138773&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;62&amp;nbsp; 35.703752 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 35.703752&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1044 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 35.703752&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 SSL Continuation Data&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 35.703752 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [ACK] Seq=1 Ack=194 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 37.287146 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Continuation Data&lt;br /&gt;&lt;br /&gt;66/[2011-11-29 00:47:53] "C:\APT_ATT41702.pdf" &lt;br /&gt;66/[2011-11-29 00:47:54] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;66/[2011-11-29 00:47:54] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;66/[2011-11-29 00:47:54] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;66/[2011-11-29 00:47:54] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;66/[2011-11-29 00:47:54] "iso88591" &lt;br /&gt;62&amp;nbsp; 35.220147&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 35.729797 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 35.730349&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1043 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 35.730367&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 SSL Continuation Data&lt;br /&gt;&amp;nbsp;66&amp;nbsp; 35.730401 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [ACK] Seq=1 Ack=192 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 36.008025 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [FIN, ACK] Seq=1 Ack=192 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;67/[2011-11-29 00:50:20] "C:\APT_ATT63950.pdf" &lt;br /&gt;&lt;br /&gt;68/[2011-11-29 00:52:48] "C:\APT_ATT78434.pdf" &lt;br /&gt;68/[2011-11-29 00:52:49] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;68/[2011-11-29 00:52:49] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;68/[2011-11-29 00:52:49] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;68/[2011-11-29 00:52:49] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;68/[2011-11-29 00:52:49] "iso88591" &lt;br /&gt;106 118.728793&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;107 119.104435 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1050 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;108 119.104435&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 TCP 1050 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;109 119.104435&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 62.233.245.91 HTTP GET /vikqz.php?id=0007871911386GB524 HTTP/1.1 &lt;br /&gt;110 119.104435 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1050 [ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;111 119.290731 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 404 Nie znaleziono obiektu&amp;nbsp; (text/html)&lt;br /&gt;112 119.291465 62.233.245.91 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1050 [FIN, ACK] Seq=312 Ack=189 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;69/[2011-11-29 00:55:16] "C:\APT_ATT85096.pdf" &lt;br /&gt;69/[2011-11-29 00:55:17] "C:\DOCUME~1\Angie\LOCALS~1\Temp\different orgasms.pdf" &lt;br /&gt;69/[2011-11-29 00:55:17] "C:\DOCUME~1\Angie\LOCALS~1\Temp\svchost.exe" &lt;br /&gt;&lt;br /&gt;70/[2011-11-29 00:57:43] "C:\APT_ATT88422.pdf" &lt;br /&gt;70/[2011-11-29 00:57:43] "C:\DOCUME~1\Angie\LOCALS~1\Temp\11.pdf" &lt;br /&gt;70/[2011-11-29 00:57:43] "C:\DOCUME~1\Angie\LOCALS~1\Temp\ccapp.exe" &lt;br /&gt;70/[2011-11-29 00:57:43] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;70/[2011-11-29 00:57:43] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;70/[2011-11-29 00:57:43] "iso88591" &lt;br /&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;61&amp;nbsp; 34.446095&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1044 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;66&amp;nbsp; 37.377861&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1044 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 43.386561&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1044 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 55.405520&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;79&amp;nbsp; 58.407708&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;83&amp;nbsp; 64.416957&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 59.120.54.79 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;87&amp;nbsp; 76.434892&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;89&amp;nbsp; 79.438217&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;92&amp;nbsp; 85.447996&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1048 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;96&amp;nbsp; 97.365250&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;98&amp;nbsp; 97.766921 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;99&amp;nbsp; 97.767318&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1049 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;100&amp;nbsp; 97.767349&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 HTTP GET /hrqxk.php?id=0100641911386GB524 HTTP/1.1 &lt;br /&gt;101&amp;nbsp; 97.767394 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [ACK] Seq=1 Ack=188 Win=65535 Len=0&lt;br /&gt;111 128.279223&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1049 &amp;gt; 80 [FIN, ACK] Seq=188 Ack=1 Win=64240 Len=0&lt;br /&gt;112 128.279304 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;113 128.279790&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1050 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;114 128.455002 2.116.180.66 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [FIN, ACK] Seq=1 Ack=189 Win=65535 Len=0&lt;br /&gt;115 128.455337&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.116.180.66 TCP 1049 &amp;gt; 80 [ACK] Seq=189 Ack=2 Win=64240 Len=0&lt;br /&gt;117 131.213059&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1050 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;122 137.221641&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 2.229.10.5&amp;nbsp;&amp;nbsp; TCP 1050 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;71/[2011-11-29 01:00:10] "C:\APT_ATT93159.pdf" &lt;br /&gt;71/[2011-11-29 01:00:11] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;71/[2011-11-29 01:00:11] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;71/[2011-11-29 01:00:11] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;71/[2011-11-29 01:00:11] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;71/[2011-11-29 01:00:11] "iso88591" &lt;br /&gt;61&amp;nbsp; 35.267636&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;62&amp;nbsp; 35.755264 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 35.755767&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1044 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&lt;br /&gt;72/[2011-11-29 01:00:52] "C:\APT_ATT93487.pdf" &lt;br /&gt;72/[2011-11-29 01:00:53] "C:\DOCUME~1\Angie\LOCALS~1\Temp\11111.exe" &lt;br /&gt;72/[2011-11-29 01:00:53] "C:\WINDOWS\system32\cmd.exe" &lt;br /&gt;49&amp;nbsp; 28.589394&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A family.mobwork.net&lt;br /&gt;&amp;nbsp;52&amp;nbsp; 28.815334 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response, No such name&lt;br /&gt;&amp;nbsp;53&amp;nbsp; 28.824172&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.219.82 TCP 1045 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;55&amp;nbsp; 29.391808 60.249.219.82 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1045 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;56&amp;nbsp; 29.393046&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.219.82 TCP 1045 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;57&amp;nbsp; 29.393089&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 60.249.219.82 SSL Continuation Data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;73/[2011-11-29 01:03:20] "C:\APT_Bainbridge Skills.pdf" &lt;br /&gt;73/[2011-11-29 01:03:20] "C:\WINDOWS\\googlesetup.dll" &lt;br /&gt;73/[2011-11-29 01:03:20] "C:\WINDOWS\AdobeARM.dll" &lt;br /&gt;73/[2011-11-29 01:03:20] "C:\WINDOWS\system32\cmd.exe" &lt;br /&gt;73/[2011-11-29 01:03:20] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;73/[2011-11-29 01:03:20] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;&amp;nbsp;1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;60&amp;nbsp; 34.385805&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A winssl.dyndns.org&lt;br /&gt;&amp;nbsp;61&amp;nbsp; 34.386808&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A www.microsoft.com&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 34.651537 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME toggle.www.ms.akadns.net CNAME g.www.ms.akadns.net CNAME lb1.www.ms.akadns.net A 207.46.19.254&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 34.653667&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1047 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 34.660488 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response, No such name&lt;br /&gt;&amp;nbsp;66&amp;nbsp; 34.661636&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A winssl.dyndns.org.hsd1.va.comcast.net&lt;br /&gt;&amp;nbsp;67&amp;nbsp; 34.929382 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1047 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 34.929845&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1047 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;69&amp;nbsp; 34.948980 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response, No such name&lt;br /&gt;&amp;nbsp;71&amp;nbsp; 35.171205&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 HTTP GET /isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome HTTP/1.1 &lt;br /&gt;&amp;nbsp;72&amp;nbsp; 35.171292 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1047 [ACK] Seq=1 Ack=1130 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;73&amp;nbsp; 35.457443 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 35.457494 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.0 200 OK&amp;nbsp; (text/html)&lt;br /&gt;&amp;nbsp;75&amp;nbsp; 35.457916&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1047 &amp;gt; 80 [ACK] Seq=1130 Ack=557 Win=63685 Len=0&lt;br /&gt;&amp;nbsp;76&amp;nbsp; 35.470823&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1047 &amp;gt; 80 [FIN, ACK] Seq=1130 Ack=557 Win=63685 Len=0&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 35.470895 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1047 [ACK] Seq=557 Ack=1131 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;79&amp;nbsp; 36.074407&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1049 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;80&amp;nbsp; 36.294800 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;81&amp;nbsp; 36.295728&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1049 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;82&amp;nbsp; 36.297643&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 HTTP GET /isapi/redir.dll?prd=ie&amp;amp;pver=6&amp;amp;ar=msnhome HTTP/1.1 &lt;br /&gt;&amp;nbsp;83&amp;nbsp; 36.297718 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1049 [ACK] Seq=1 Ack=1291 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;84&amp;nbsp; 36.534015 207.46.19.254 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 302 Found&amp;nbsp; (text/html)&lt;br /&gt;&amp;nbsp;85&amp;nbsp; 36.536261&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A home.microsoft.com&lt;br /&gt;&amp;nbsp;86&amp;nbsp; 36.648320&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1049 &amp;gt; 80 [ACK] Seq=1291 Ack=547 Win=63694 Len=0&lt;br /&gt;&amp;nbsp;88&amp;nbsp; 36.699394 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME redir.blu.cb3.glbdns.microsoft.com A 65.55.206.209&lt;br /&gt;&amp;nbsp;89&amp;nbsp; 36.700413&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.206.209 TCP 1050 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;90&amp;nbsp; 36.873588 65.55.206.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1050 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;91&amp;nbsp; 36.874437&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.206.209 TCP 1050 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;92&amp;nbsp; 36.874467&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.206.209 HTTP GET / HTTP/1.1 &lt;br /&gt;&amp;nbsp;93&amp;nbsp; 36.874531 65.55.206.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1050 [ACK] Seq=1 Ack=1129 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;94&amp;nbsp; 37.055783 65.55.206.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 301 Moved Permanently &lt;br /&gt;&amp;nbsp;95&amp;nbsp; 37.057985&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A www.msn.com&lt;br /&gt;&amp;nbsp;96&amp;nbsp; 37.236864 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME us.co1.cb3.glbdns.microsoft.com A 207.46.140.34&lt;br /&gt;&amp;nbsp;97&amp;nbsp; 37.238158&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;98&amp;nbsp; 37.249543&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.206.209 TCP 1050 &amp;gt; 80 [ACK] Seq=1129 Ack=298 Win=63943 Len=0&lt;br /&gt;100&amp;nbsp; 37.491542 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;101&amp;nbsp; 37.492462&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;102&amp;nbsp; 37.492498&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 HTTP GET / HTTP/1.1 &lt;br /&gt;103&amp;nbsp; 37.492538 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [ACK] Seq=1 Ack=817 Win=65535 Len=0&lt;br /&gt;104&amp;nbsp; 37.814454 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;105&amp;nbsp; 37.814506 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;106&amp;nbsp; 37.814816&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=1449 Win=62792 Len=0&lt;br /&gt;107&amp;nbsp; 37.814902 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;108&amp;nbsp; 37.814937 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;109&amp;nbsp; 37.815251&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=2897 Win=64240 Len=0&lt;br /&gt;110&amp;nbsp; 37.836372&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A col.stc.s-msn.com&lt;br /&gt;111&amp;nbsp; 37.909124 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;112&amp;nbsp; 37.909177 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;113&amp;nbsp; 37.909422 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;114&amp;nbsp; 37.909451 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;115&amp;nbsp; 37.909473&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=4345 Win=62792 Len=0&lt;br /&gt;116&amp;nbsp; 37.909731&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=5793 Win=64240 Len=0&lt;br /&gt;117&amp;nbsp; 37.909824 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;118&amp;nbsp; 37.909849 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;119&amp;nbsp; 37.909985&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=7241 Win=62792 Len=0&lt;br /&gt;120&amp;nbsp; 37.910259 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;121&amp;nbsp; 37.910488 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;122&amp;nbsp; 37.910618&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=8689 Win=64240 Len=0&lt;br /&gt;123&amp;nbsp; 38.002706 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;124&amp;nbsp; 38.002774 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;125&amp;nbsp; 38.003245 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;126&amp;nbsp; 38.003373 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;127&amp;nbsp; 38.003895 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;128&amp;nbsp; 38.003940&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=10137 Win=62792 Len=0&lt;br /&gt;129&amp;nbsp; 38.003985&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=11585 Win=64240 Len=0&lt;br /&gt;130&amp;nbsp; 38.004040 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;131&amp;nbsp; 38.004123&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=13033 Win=62792 Len=0&lt;br /&gt;132&amp;nbsp; 38.005081 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;133&amp;nbsp; 38.005125 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;134&amp;nbsp; 38.005268&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=14481 Win=61344 Len=0&lt;br /&gt;135&amp;nbsp; 38.005378 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;136&amp;nbsp; 38.005419 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;137&amp;nbsp; 38.005525&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=15929 Win=59896 Len=0&lt;br /&gt;138&amp;nbsp; 38.005995 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;139&amp;nbsp; 38.006038 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;140&amp;nbsp; 38.006180&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=17377 Win=58448 Len=0&lt;br /&gt;141&amp;nbsp; 38.010812 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;142&amp;nbsp; 38.010857 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;143&amp;nbsp; 38.011153&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=18825 Win=57000 Len=0&lt;br /&gt;144&amp;nbsp; 38.011266 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;145&amp;nbsp; 38.011312 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;146&amp;nbsp; 38.011471&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=20273 Win=55552 Len=0&lt;br /&gt;147&amp;nbsp; 38.031499 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME colstc.co1.cb3.glbdns.microsoft.com CNAME msn.vo.msecnd.net A 65.54.81.209 A 65.54.81.185&lt;br /&gt;148&amp;nbsp; 38.032809&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;149&amp;nbsp; 38.032977&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;150&amp;nbsp; 38.035078&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP [TCP Window Update] 1051 &amp;gt; 80 [ACK] Seq=817 Ack=20273 Win=64240 Len=0&lt;br /&gt;151&amp;nbsp; 38.091287 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;152&amp;nbsp; 38.091328 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;153&amp;nbsp; 38.091541&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=21721 Win=62792 Len=0&lt;br /&gt;154&amp;nbsp; 38.091594 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;155&amp;nbsp; 38.091634 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;156&amp;nbsp; 38.091800&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=23169 Win=64240 Len=0&lt;br /&gt;157&amp;nbsp; 38.091879 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;158&amp;nbsp; 38.091903 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;159&amp;nbsp; 38.092222&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=24617 Win=62792 Len=0&lt;br /&gt;160&amp;nbsp; 38.092252 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;161&amp;nbsp; 38.092276 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;162&amp;nbsp; 38.092752&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=26065 Win=64240 Len=0&lt;br /&gt;163&amp;nbsp; 38.092832 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;164&amp;nbsp; 38.092860 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;165&amp;nbsp; 38.093222&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=27513 Win=62792 Len=0&lt;br /&gt;166&amp;nbsp; 38.093252 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;167&amp;nbsp; 38.093275 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;168&amp;nbsp; 38.093711&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=28961 Win=64240 Len=0&lt;br /&gt;169&amp;nbsp; 38.093740 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;170&amp;nbsp; 38.093769 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;171&amp;nbsp; 38.094127&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=30409 Win=62792 Len=0&lt;br /&gt;172&amp;nbsp; 38.094157 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;173&amp;nbsp; 38.094180 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;174&amp;nbsp; 38.095541&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=31857 Win=61344 Len=0&lt;br /&gt;175&amp;nbsp; 38.095575 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;176&amp;nbsp; 38.095605 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;177&amp;nbsp; 38.096013&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=33305 Win=59896 Len=0&lt;br /&gt;178&amp;nbsp; 38.096093 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;179&amp;nbsp; 38.096119 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;180&amp;nbsp; 38.097120&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=34753 Win=58448 Len=0&lt;br /&gt;181&amp;nbsp; 38.097151&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP [TCP Window Update] 1051 &amp;gt; 80 [ACK] Seq=817 Ack=34753 Win=64240 Len=0&lt;br /&gt;182&amp;nbsp; 38.097195 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;183&amp;nbsp; 38.097248 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;184&amp;nbsp; 38.097469&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=36201 Win=62792 Len=0&lt;br /&gt;185&amp;nbsp; 38.097493 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;186&amp;nbsp; 38.097528 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;187&amp;nbsp; 38.097842&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=37649 Win=64240 Len=0&lt;br /&gt;188&amp;nbsp; 38.097871 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;189&amp;nbsp; 38.097901 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;190&amp;nbsp; 38.097952 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;191&amp;nbsp; 38.098031&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=39097 Win=62792 Len=0&lt;br /&gt;193&amp;nbsp; 38.237992 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;194&amp;nbsp; 38.238320 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;195&amp;nbsp; 38.238404&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;196&amp;nbsp; 38.238788&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;197&amp;nbsp; 38.238804&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/css/3c/e52849405b21b1b7b78858e8f94f2f.css HTTP/1.1 &lt;br /&gt;198&amp;nbsp; 38.238890 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [ACK] Seq=1 Ack=377 Win=65535 Len=0&lt;br /&gt;199&amp;nbsp; 38.240511&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/css/f5/c58b60aba0638d30b1ba54ac21ef03.css HTTP/1.1 &lt;br /&gt;200&amp;nbsp; 38.240573 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [ACK] Seq=1 Ack=377 Win=65535 Len=0&lt;br /&gt;201&amp;nbsp; 38.250677&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=817 Ack=39854 Win=64240 Len=0&lt;br /&gt;202&amp;nbsp; 38.449344 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;203&amp;nbsp; 38.464082 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;204&amp;nbsp; 38.512984&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A col.stj.s-msn.com&lt;br /&gt;205&amp;nbsp; 38.551278&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [ACK] Seq=377 Ack=168 Win=64073 Len=0&lt;br /&gt;206&amp;nbsp; 38.652280&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [ACK] Seq=377 Ack=169 Win=64072 Len=0&lt;br /&gt;207&amp;nbsp; 38.728227 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME colstj.co1.cb3.glbdns.microsoft.com CNAME msn.vo.msecnd.net A 65.54.81.24 A 65.54.81.18&lt;br /&gt;208&amp;nbsp; 38.729729&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;209&amp;nbsp; 38.733541&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;210&amp;nbsp; 38.735147&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A amer.rel.msn.com&lt;br /&gt;211&amp;nbsp; 38.739101&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A exp.www.msn.com&lt;br /&gt;212&amp;nbsp; 38.824585&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A udc.msn.com&lt;br /&gt;216&amp;nbsp; 38.955997&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1055 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;217&amp;nbsp; 38.956179&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;218&amp;nbsp; 38.956342&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1054 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;219&amp;nbsp; 38.958079&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;220&amp;nbsp; 38.961515 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME amer.hops.glbdns.microsoft.com A 207.46.140.46&lt;br /&gt;221&amp;nbsp; 38.962824&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 TCP 1057 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;222&amp;nbsp; 38.965918&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A view.atdmt.com&lt;br /&gt;223&amp;nbsp; 38.967318 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME ro-msn.exp.glbdns.microsoft.com A 65.55.18.18&lt;br /&gt;224&amp;nbsp; 38.973159&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;225&amp;nbsp; 38.974222&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A b.scorecardresearch.com&lt;br /&gt;226&amp;nbsp; 39.051152 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME udc.udc0.glbdns.microsoft.com A 70.37.130.35&lt;br /&gt;227&amp;nbsp; 39.053649&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 TCP 1059 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;228&amp;nbsp; 39.053691&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A c.msn.com&lt;br /&gt;229&amp;nbsp; 39.200684 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response A 65.55.33.48&lt;br /&gt;230&amp;nbsp; 39.201639&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.33.48&amp;nbsp; TCP 1060 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;231&amp;nbsp; 39.204105&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A www.bing.com&lt;br /&gt;232&amp;nbsp; 39.204532 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME b.scorecardresearch.com.edgesuite.net CNAME a1294.w20.akamai.net A 96.17.168.80 A 96.17.168.152 A 96.17.168.98&lt;br /&gt;233&amp;nbsp; 39.206253&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.80 TCP 1061 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;234&amp;nbsp; 39.206283&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A col.stb.s-msn.com&lt;br /&gt;235&amp;nbsp; 39.265296 207.46.140.46 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1057 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;236&amp;nbsp; 39.265754&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 TCP 1057 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;237&amp;nbsp; 39.278876&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1058 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;238&amp;nbsp; 39.279083&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;239&amp;nbsp; 39.281502 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME c.msn.com.nsatc.net A 64.4.21.39&lt;br /&gt;240&amp;nbsp; 39.283203&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 64.4.21.39&amp;nbsp;&amp;nbsp; TCP 1062 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;241&amp;nbsp; 39.283360&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/icons/BING_websearch_2.jpg HTTP/1.1 &lt;br /&gt;242&amp;nbsp; 39.283416 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [ACK] Seq=168 Ack=740 Win=65535 Len=0&lt;br /&gt;243&amp;nbsp; 39.304309 70.37.130.35 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1059 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;244&amp;nbsp; 39.304617&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 TCP 1059 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;245&amp;nbsp; 39.442570 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME colstb.co1.cb3.glbdns.microsoft.com CNAME msn.vo.msecnd.net A 65.54.81.24 A 65.54.81.47&lt;br /&gt;246&amp;nbsp; 39.443333 96.17.168.80 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1061 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;247&amp;nbsp; 39.443994&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.80 TCP 1061 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;248&amp;nbsp; 39.444021&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;249&amp;nbsp; 39.444045 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME search.ms.com.edgesuite.net CNAME a134.b.akamai.net A 96.17.171.161 A 96.17.171.99&lt;br /&gt;250&amp;nbsp; 39.445180&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;251&amp;nbsp; 39.447047&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;252&amp;nbsp; 39.447064&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A blst.msn.com&lt;br /&gt;253&amp;nbsp; 39.447074&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/ff/adchoices_gif2.gif HTTP/1.1 &lt;br /&gt;254&amp;nbsp; 39.447147 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [ACK] Seq=169 Ack=733 Win=65535 Len=0&lt;br /&gt;255&amp;nbsp; 39.449020&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /br/sc/js/01/dapmsn_exp_min.js HTTP/1.1 &lt;br /&gt;256&amp;nbsp; 39.449080&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /br/sc/js/jquery/jquery-1.4.2.min.js HTTP/1.1 &lt;br /&gt;257&amp;nbsp; 39.449102&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 HTTP GET /default.aspx?parsergroup=hops&amp;amp;fk=W&amp;amp;gp=P&amp;amp;optkey=default&amp;amp;rf=&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;pageid=6875603&amp;amp;mk=en-us&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;tfk=C%3Adefault&amp;amp;utk=&amp;amp;cts=1322546503640&amp;amp;tv=infopane_hops%3Ana%2Clocaltg%3Alocal%2Cstgsearch%3Apopsrchnew%2Csocialtg%3Afacebook HTTP/1.1 &lt;br /&gt;258&amp;nbsp; 39.449124&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1055 [ACK] Seq=1 Ack=360 Win=65535 Len=0&lt;br /&gt;259&amp;nbsp; 39.449151&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1054 [ACK] Seq=1 Ack=364 Win=65535 Len=0&lt;br /&gt;260&amp;nbsp; 39.449168 207.46.140.46 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1057 [ACK] Seq=1 Ack=932 Win=65535 Len=0&lt;br /&gt;261&amp;nbsp; 39.449798&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; HTTP GET /ro.aspx?evt=impr&amp;amp;obs=msnhp_us_pv&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;pn=US+HPMSFT3WANBOV2T2&amp;amp;ch=MSFT&amp;amp;rid=&amp;amp;cts=1322546503640&amp;amp;rf=&amp;amp;slv=0&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2F HTTP/1.1 &lt;br /&gt;262&amp;nbsp; 39.449817&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 HTTP GET /c.gif?evt=impr&amp;amp;js=1&amp;amp;rid=&amp;amp;exa=msnhp_us_master_v2%3AWP10_5%2Cmsnhp_us_anbov2%3AT2&amp;amp;pp=False&amp;amp;bd=&amp;amp;gnd=&amp;amp;cts=1322546503670&amp;amp;aop=&amp;amp;expac=673II6B39_0912%3AT2~40II3a39_0803%3AWP10_5%7C&amp;amp;dv.SNLogin=fb%3Af%2Ctw%3Af&amp;amp;dv.GrpFrMod=infopane_hops%3Ana%2Clocaltg%3Alocal%2Cstgsearch%3Apopsrchnew%2Csocialtg%3Afacebook&amp;amp;hp=N&amp;amp;fk=W&amp;amp;gp=P&amp;amp;optkey=default&amp;amp;clid=3CE72C262627635C3C662E93222763E1&amp;amp;rf=&amp;amp;cu=http%3A%2F%2Fwww.msn.com%2F&amp;amp;sl=0&amp;amp;slv=0&amp;amp;bh=294&amp;amp;bw=609&amp;amp;scr=800x600&amp;amp;sd=32&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;mk=en-us&amp;amp;pn=US+HPMSFT3WANBOV2T2&amp;amp;pid=6875603&amp;amp;su=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;pageid=6875603&amp;amp;br=MSFT&amp;amp;mv=V14 HTTP/1.1 &lt;br /&gt;263&amp;nbsp; 39.449827&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.80 HTTP GET /b?c1=2&amp;amp;c2=3000001&amp;amp;c7=http%3A%2F%2Fwww.msn.com%2F&amp;amp;c9=&amp;amp;rn=1322546503680 HTTP/1.1 &lt;br /&gt;264&amp;nbsp; 39.449861&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1058 [ACK] Seq=1 Ack=915 Win=65535 Len=0&lt;br /&gt;265&amp;nbsp; 39.449887 70.37.130.35 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1059 [ACK] Seq=1 Ack=1234 Win=65535 Len=0&lt;br /&gt;266&amp;nbsp; 39.449932 96.17.168.80 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1061 [ACK] Seq=1 Ack=383 Win=65535 Len=0&lt;br /&gt;267&amp;nbsp; 39.509919&amp;nbsp; 65.55.33.48 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1060 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;268&amp;nbsp; 39.510410&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.33.48&amp;nbsp; TCP 1060 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;269&amp;nbsp; 39.510434&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.33.48&amp;nbsp; HTTP GET /action/MSN_Homepage_Remessaging_111808/nc?a=1 HTTP/1.1 &lt;br /&gt;270&amp;nbsp; 39.510488&amp;nbsp; 65.55.33.48 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1060 [ACK] Seq=1 Ack=488 Win=65535 Len=0&lt;br /&gt;271&amp;nbsp; 39.519224 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;272&amp;nbsp; 39.520668&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/07/617475cf39bf6f5c0bd6ecb985335c.gif HTTP/1.1 &lt;br /&gt;273&amp;nbsp; 39.520762 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [ACK] Seq=339 Ack=1112 Win=65535 Len=0&lt;br /&gt;274&amp;nbsp; 39.594079&amp;nbsp;&amp;nbsp; 64.4.21.39 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1062 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;275&amp;nbsp; 39.594624&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 64.4.21.39&amp;nbsp;&amp;nbsp; TCP 1062 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;276&amp;nbsp; 39.594651&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 64.4.21.39&amp;nbsp;&amp;nbsp; HTTP GET /c.gif?udc=true&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;lng=en-us&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;rid=&amp;amp;rnd=1322546503680&amp;amp;rf=&amp;amp;scr=800x600 HTTP/1.1 &lt;br /&gt;277&amp;nbsp; 39.594707&amp;nbsp;&amp;nbsp; 64.4.21.39 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1062 [ACK] Seq=1 Ack=791 Win=65535 Len=0&lt;br /&gt;278&amp;nbsp; 39.686830 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME blst.blu.cb3.glbdns.microsoft.com CNAME msn.vo.msecnd.net A 65.54.81.47 A 65.54.81.24&lt;br /&gt;279&amp;nbsp; 39.688064&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; TCP 1066 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;280&amp;nbsp; 39.688328 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1065 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;281&amp;nbsp; 39.688516&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;282&amp;nbsp; 39.688690&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;283&amp;nbsp; 39.689023&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;284&amp;nbsp; 39.690695&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;285&amp;nbsp; 39.690716&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;286&amp;nbsp; 39.690727&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 HTTP GET /partner/primedns.gif HTTP/1.1 &lt;br /&gt;287&amp;nbsp; 39.690749&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/B7/EB75D45B8948F72EE451223E95A96.gif HTTP/1.1 &lt;br /&gt;288&amp;nbsp; 39.690758&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/65/CDAB2F44A1591D2B308C20C6C15375.jpg HTTP/1.1 &lt;br /&gt;289&amp;nbsp; 39.690786 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1065 [ACK] Seq=1 Ack=492 Win=65535 Len=0&lt;br /&gt;290&amp;nbsp; 39.690805&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=1 Ack=372 Win=65535 Len=0&lt;br /&gt;291&amp;nbsp; 39.690816&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=1 Ack=372 Win=65535 Len=0&lt;br /&gt;292&amp;nbsp; 39.691986 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;293&amp;nbsp; 39.693701&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/7d/7fda667169fb45760dd7152ddafd78.gif HTTP/1.1 &lt;br /&gt;294&amp;nbsp; 39.693744&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;295&amp;nbsp; 39.693804 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [ACK] Seq=339 Ack=1107 Win=65535 Len=0&lt;br /&gt;296&amp;nbsp; 39.694158&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /br/sc/js/cf/ece838bdac41f565b1c59d87c4c9cf63.js HTTP/1.1 &lt;br /&gt;297&amp;nbsp; 39.694198&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;298&amp;nbsp; 39.694217&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1055 [ACK] Seq=184 Ack=736 Win=65535 Len=0&lt;br /&gt;299&amp;nbsp; 39.708116 96.17.168.80 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 204 No Content &lt;br /&gt;300&amp;nbsp; 39.731730 70.37.130.35 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;301&amp;nbsp; 39.769324 207.46.140.46 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 204 No Content &lt;br /&gt;302&amp;nbsp; 39.776036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A rad.msn.com&lt;br /&gt;303&amp;nbsp; 39.776145&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;304&amp;nbsp; 39.782075 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;305&amp;nbsp; 39.786147&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/f8/614595fba50d96389708a4135776e4.gif HTTP/1.1 &lt;br /&gt;306&amp;nbsp; 39.786252 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [ACK] Seq=509 Ack=1487 Win=65535 Len=0&lt;br /&gt;307&amp;nbsp; 39.852770&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [ACK] Seq=364 Ack=185 Win=64056 Len=0&lt;br /&gt;308&amp;nbsp; 39.852800&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.80 TCP 1061 &amp;gt; 80 [ACK] Seq=383 Ack=249 Win=63992 Len=0&lt;br /&gt;309&amp;nbsp; 39.852816&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 TCP 1059 &amp;gt; 80 [ACK] Seq=1234 Ack=368 Win=63873 Len=0&lt;br /&gt;310&amp;nbsp; 39.928698&amp;nbsp; 65.55.33.48 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;311&amp;nbsp; 39.928761&amp;nbsp; 65.55.33.48 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1060 [FIN, ACK] Seq=257 Ack=488 Win=65535 Len=0&lt;br /&gt;312&amp;nbsp; 39.929609&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.33.48&amp;nbsp; TCP 1060 &amp;gt; 80 [ACK] Seq=488 Ack=258 Win=63984 Len=0&lt;br /&gt;313&amp;nbsp; 39.929655&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.33.48&amp;nbsp; TCP 1060 &amp;gt; 80 [FIN, ACK] Seq=488 Ack=258 Win=63984 Len=0&lt;br /&gt;314&amp;nbsp; 39.929731&amp;nbsp; 65.55.33.48 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1060 [ACK] Seq=258 Ack=489 Win=65535 Len=0&lt;br /&gt;315&amp;nbsp; 39.948119&amp;nbsp;&amp;nbsp; 64.4.21.39 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;316&amp;nbsp; 39.952979&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 TCP 1057 &amp;gt; 80 [ACK] Seq=932 Ack=293 Win=63948 Len=0&lt;br /&gt;317&amp;nbsp; 39.953047&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [ACK] Seq=915 Ack=371 Win=63870 Len=0&lt;br /&gt;318&amp;nbsp; 39.966706&amp;nbsp; 65.54.81.47 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1066 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;319&amp;nbsp; 39.967116&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; TCP 1066 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;320&amp;nbsp; 39.967167&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; HTTP GET /as/wea3/i/en-us/law/11.gif HTTP/1.1 &lt;br /&gt;321&amp;nbsp; 39.967213&amp;nbsp; 65.54.81.47 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1066 [ACK] Seq=1 Ack=666 Win=65535 Len=0&lt;br /&gt;322&amp;nbsp; 39.973864 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;323&amp;nbsp; 39.974378&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;324&amp;nbsp; 39.974529&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;325&amp;nbsp; 39.975523&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/0c/c57bc2a7d38843d7c4aa8028fc9f82.gif HTTP/1.1 &lt;br /&gt;326&amp;nbsp; 39.975607 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [ACK] Seq=508 Ack=1481 Win=65535 Len=0&lt;br /&gt;327&amp;nbsp; 39.998798&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/93/FBAB2A6CE18375B5A6A8AB82A7DF1A.jpg HTTP/1.1 &lt;br /&gt;328&amp;nbsp; 39.998894&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=171 Ack=744 Win=65535 Len=0&lt;br /&gt;329&amp;nbsp; 39.999124&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/C3/D7F23B32F2CD62EC115C23378FFE1.jpg HTTP/1.1 &lt;br /&gt;330&amp;nbsp; 39.999176&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=170 Ack=743 Win=65535 Len=0&lt;br /&gt;331&amp;nbsp; 40.011676 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;332&amp;nbsp; 40.042310 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME rad.msn.com.nsatc.net A 65.55.121.231 A 65.55.192.10&lt;br /&gt;333&amp;nbsp; 40.043911&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1067 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;334&amp;nbsp; 40.053005 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;335&amp;nbsp; 40.053287&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 64.4.21.39&amp;nbsp;&amp;nbsp; TCP 1062 &amp;gt; 80 [ACK] Seq=791 Ack=423 Win=63818 Len=0&lt;br /&gt;336&amp;nbsp; 40.054856&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/c1/cc36ca69630adc1a2052edc7351a47.gif HTTP/1.1 &lt;br /&gt;337&amp;nbsp; 40.054915 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [ACK] Seq=679 Ack=1861 Win=65535 Len=0&lt;br /&gt;338&amp;nbsp; 40.153403&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [ACK] Seq=492 Ack=277 Win=63964 Len=0&lt;br /&gt;339&amp;nbsp; 40.231698&amp;nbsp; 65.54.81.47 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;340&amp;nbsp; 40.240187 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;341&amp;nbsp; 40.255247&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;342&amp;nbsp; 40.259013&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/A2/CB94E521DF334C97CB2DC5056A52E.jpg HTTP/1.1 &lt;br /&gt;343&amp;nbsp; 40.259091&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=339 Ack=1114 Win=65535 Len=0&lt;br /&gt;344&amp;nbsp; 40.261390&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;345&amp;nbsp; 40.262416&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/E2/7244F875BC3B1936217FC28AC541.jpg HTTP/1.1 &lt;br /&gt;346&amp;nbsp; 40.262477&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=338 Ack=1023 Win=65535 Len=0&lt;br /&gt;347&amp;nbsp; 40.295186 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1067 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;348&amp;nbsp; 40.295368&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1067 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;349&amp;nbsp; 40.296893&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 HTTP GET /ADSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PN=MSFT&amp;amp;ID=3CE72C262627635C3C662E93222763E1&amp;amp;MUID=3CE72C262627635C3C662E93222763E1&amp;amp;PG=MSNPFS&amp;amp;AP=1089 HTTP/1.1 &lt;br /&gt;350&amp;nbsp; 40.296959 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1067 [ACK] Seq=1 Ack=771 Win=65535 Len=0&lt;br /&gt;351&amp;nbsp; 40.322531 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;352&amp;nbsp; 40.353817&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; TCP 1066 &amp;gt; 80 [ACK] Seq=666 Ack=1208 Win=63033 Len=0&lt;br /&gt;353&amp;nbsp; 40.353850&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [ACK] Seq=1481 Ack=678 Win=63563 Len=0&lt;br /&gt;354&amp;nbsp; 40.453894&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [ACK] Seq=1861 Ack=849 Win=63392 Len=0&lt;br /&gt;355&amp;nbsp; 40.524032&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;356&amp;nbsp; 40.528151&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/14/37366221F516EE388EAC8C26DC4FE9.jpg HTTP/1.1 &lt;br /&gt;357&amp;nbsp; 40.528255&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=507 Ack=1396 Win=65535 Len=0&lt;br /&gt;358&amp;nbsp; 40.531938&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;359&amp;nbsp; 40.531989&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;360&amp;nbsp; 40.532222&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;361&amp;nbsp; 40.532260&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=1023 Ack=1786 Win=64240 Len=0&lt;br /&gt;362&amp;nbsp; 40.532302&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;363&amp;nbsp; 40.532631&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=1023 Ack=3234 Win=62792 Len=0&lt;br /&gt;364&amp;nbsp; 40.533444&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;365&amp;nbsp; 40.533500&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;366&amp;nbsp; 40.533600&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=1023 Ack=4682 Win=64240 Len=0&lt;br /&gt;367&amp;nbsp; 40.535446&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;368&amp;nbsp; 40.535491&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;369&amp;nbsp; 40.535892&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=1023 Ack=6130 Win=62792 Len=0&lt;br /&gt;370&amp;nbsp; 40.536668&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (JPEG JFIF image)&lt;br /&gt;371&amp;nbsp; 40.538144&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/25/4075B47E5BDF545B1FB27F1C75CDEC.jpg HTTP/1.1 &lt;br /&gt;372&amp;nbsp; 40.538206&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=6514 Ack=1395 Win=65535 Len=0&lt;br /&gt;373&amp;nbsp; 40.571685 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;374&amp;nbsp; 40.571749 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;375&amp;nbsp; 40.572327&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1067 &amp;gt; 80 [ACK] Seq=771 Ack=1870 Win=64240 Len=0&lt;br /&gt;376&amp;nbsp; 40.647941&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;377&amp;nbsp; 40.648000&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A ads.pointroll.com&lt;br /&gt;378&amp;nbsp; 40.723783&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; HTTP GET /msn/msnhp_us_ttg?ty=TBCB&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;rid=&amp;amp;ts=634581432960349339&amp;amp;rf= HTTP/1.1 &lt;br /&gt;379&amp;nbsp; 40.723783&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1058 [ACK] Seq=371 Ack=1813 Win=65535 Len=0&lt;br /&gt;380&amp;nbsp; 40.803441&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;381&amp;nbsp; 40.803523&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;382&amp;nbsp; 40.803534&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;383&amp;nbsp; 40.803827&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;384&amp;nbsp; 40.803865&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=1396 Ack=1955 Win=64240 Len=0&lt;br /&gt;385&amp;nbsp; 40.803911&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;386&amp;nbsp; 40.804073&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=1396 Ack=3403 Win=62792 Len=0&lt;br /&gt;387&amp;nbsp; 40.804503&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;388&amp;nbsp; 40.804542&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;389&amp;nbsp; 40.804853&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=1396 Ack=4851 Win=64240 Len=0&lt;br /&gt;390&amp;nbsp; 40.806526&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;391&amp;nbsp; 40.806560&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;392&amp;nbsp; 40.807193&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=1396 Ack=6299 Win=62792 Len=0&lt;br /&gt;393&amp;nbsp; 40.807992&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (JPEG JFIF image)&lt;br /&gt;394&amp;nbsp; 40.856905&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [ACK] Seq=736 Ack=367 Win=63874 Len=0&lt;br /&gt;395&amp;nbsp; 40.861585&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/E2/37BA92E210D341BFDBF4126422A3D2.gif HTTP/1.1 &lt;br /&gt;396&amp;nbsp; 40.861609&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/C4/9F97E4662E66D88ACDC52D97FC6C1.jpg HTTP/1.1 &lt;br /&gt;397&amp;nbsp; 40.861689&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=6932 Ack=1767 Win=65535 Len=0&lt;br /&gt;398&amp;nbsp; 40.861708&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=6682 Ack=1765 Win=65535 Len=0&lt;br /&gt;399&amp;nbsp; 40.880472 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response A 72.32.153.176&lt;br /&gt;400&amp;nbsp; 40.882015&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;401&amp;nbsp; 40.969332&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 HTTP GET /sck?cn=_SS&amp;amp;r=http://www.msn.com/sck.aspx&amp;amp;form=MSN005&amp;amp;h=b8642205-0de1-dc10-ed9b-66c5af494dd5 HTTP/1.1 &lt;br /&gt;402&amp;nbsp; 40.969549 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1065 [ACK] Seq=277 Ack=1165 Win=65535 Len=0&lt;br /&gt;403&amp;nbsp; 40.972923&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1069 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;404&amp;nbsp; 40.975068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A api.bing.com&lt;br /&gt;405&amp;nbsp; 40.999068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /br/sc/js/51/anatm.js HTTP/1.1 &lt;br /&gt;406&amp;nbsp; 40.999068&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1054 [ACK] Seq=185 Ack=714 Win=65535 Len=0&lt;br /&gt;407&amp;nbsp; 40.999068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1070 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;408&amp;nbsp; 41.064842&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;409&amp;nbsp; 41.143402&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;410&amp;nbsp; 41.143476&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;411&amp;nbsp; 41.151195&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/AD/A7F1B2A19D642097AC7567BCFCC2.jpg HTTP/1.1 &lt;br /&gt;412&amp;nbsp; 41.151220&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/96/FFFA8C9EF55535D7A289CE662951.jpg HTTP/1.1 &lt;br /&gt;413&amp;nbsp; 41.151299&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7101 Ack=2136 Win=65535 Len=0&lt;br /&gt;414&amp;nbsp; 41.151320&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=6850 Ack=2135 Win=65535 Len=0&lt;br /&gt;415&amp;nbsp; 41.189538 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1068 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;416&amp;nbsp; 41.190057&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;417&amp;nbsp; 41.190073&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 HTTP GET /PortalServe/?pid=1501166P77620111115192417&amp;amp;flash=6&amp;amp;time=2|1:1|-5&amp;amp;pos=s&amp;amp;ajx=1&amp;amp;redir=$CTURL$&amp;amp;r=0.970374845534282 HTTP/1.1 &lt;br /&gt;418&amp;nbsp; 41.190128 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1068 [ACK] Seq=1 Ack=354 Win=65535 Len=0&lt;br /&gt;419&amp;nbsp; 41.250078 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME search.ms.com.edgesuite.net CNAME a134.b.akamai.net A 96.17.171.99 A 96.17.171.161&lt;br /&gt;420&amp;nbsp; 41.251219 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1069 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;421&amp;nbsp; 41.251269&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.99 TCP 1071 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;422&amp;nbsp; 41.251658&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1069 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;423&amp;nbsp; 41.251679&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 HTTP GET /s/as/899538/en.js HTTP/1.1 &lt;br /&gt;424&amp;nbsp; 41.251728 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1069 [ACK] Seq=1 Ack=489 Win=65535 Len=0&lt;br /&gt;425&amp;nbsp; 41.256685&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [ACK] Seq=1813 Ack=741 Win=63500 Len=0&lt;br /&gt;426&amp;nbsp; 41.273484&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;427&amp;nbsp; 41.297670 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;428&amp;nbsp; 41.345989&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1070 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;429&amp;nbsp; 41.346529&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1070 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;430&amp;nbsp; 41.346547&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; HTTP GET /msn/msnhp_us_ttg?ty=TACB&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;rid=&amp;amp;ts=634581432960349339&amp;amp;rf= HTTP/1.1 &lt;br /&gt;431&amp;nbsp; 41.346610&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1070 [ACK] Seq=1 Ack=899 Win=65535 Len=0&lt;br /&gt;432&amp;nbsp; 41.385740&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 HTTP GET /sck.aspx?cv=_SS%3dSID%3d7415D61A534D4976A4769A771B40DC4E%3b&amp;amp;h=b8642205-0de1-dc10-ed9b-66c5af494dd5 HTTP/1.1 &lt;br /&gt;433&amp;nbsp; 41.385855 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [ACK] Seq=39854 Ack=1853 Win=65535 Len=0&lt;br /&gt;434&amp;nbsp; 41.431317&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;435&amp;nbsp; 41.434812&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/EE/4DA23F4C5870A75228FEAFD14EFBF.gif HTTP/1.1 &lt;br /&gt;436&amp;nbsp; 41.434897&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7269 Ack=2506 Win=65535 Len=0&lt;br /&gt;437&amp;nbsp; 41.436012&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;438&amp;nbsp; 41.439276&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/5D/EE55A9EE91D76B923A4CD03D9B9A.jpg HTTP/1.1 &lt;br /&gt;439&amp;nbsp; 41.439343&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=7018 Ack=2504 Win=65535 Len=0&lt;br /&gt;440&amp;nbsp; 41.456934&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [ACK] Seq=714 Ack=369 Win=63872 Len=0&lt;br /&gt;441&amp;nbsp; 41.456959&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [ACK] Seq=1165 Ack=778 Win=63463 Len=0&lt;br /&gt;442&amp;nbsp; 41.510225 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;443&amp;nbsp; 41.510686 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;444&amp;nbsp; 41.511128&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [ACK] Seq=354 Ack=2723 Win=64240 Len=0&lt;br /&gt;445&amp;nbsp; 41.511186 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;446&amp;nbsp; 41.544137 96.17.171.99 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1071 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;447&amp;nbsp; 41.544642&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.99 TCP 1071 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;448&amp;nbsp; 41.544660&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.99 HTTP GET /qsonhs.aspx?form=MSN005&amp;amp;q= HTTP/1.1 &lt;br /&gt;449&amp;nbsp; 41.544730 96.17.171.99 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1071 [ACK] Seq=1 Ack=397 Win=65535 Len=0&lt;br /&gt;450&amp;nbsp; 41.545295 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;451&amp;nbsp; 41.563559 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;452&amp;nbsp; 41.563617 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1068 [FIN, ACK] Seq=3937 Ack=354 Win=65535 Len=0&lt;br /&gt;453&amp;nbsp; 41.565949&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [ACK] Seq=354 Ack=3937 Win=63026 Len=0&lt;br /&gt;454&amp;nbsp; 41.565969&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [ACK] Seq=354 Ack=3938 Win=63026 Len=0&lt;br /&gt;455&amp;nbsp; 41.565979&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 72.32.153.176 TCP 1068 &amp;gt; 80 [FIN, ACK] Seq=354 Ack=3938 Win=63026 Len=0&lt;br /&gt;456&amp;nbsp; 41.566038 72.32.153.176 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1068 [ACK] Seq=3938 Ack=355 Win=65535 Len=0&lt;br /&gt;457&amp;nbsp; 41.659015&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1069 &amp;gt; 80 [ACK] Seq=489 Ack=241 Win=64000 Len=0&lt;br /&gt;458&amp;nbsp; 41.716634&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;459&amp;nbsp; 41.736305&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;460&amp;nbsp; 41.736769&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;461&amp;nbsp; 41.736838&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/A0/C9428460AFED1C89A9476537C01E6C.jpg HTTP/1.1 &lt;br /&gt;462&amp;nbsp; 41.736918&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7436 Ack=2877 Win=65535 Len=0&lt;br /&gt;463&amp;nbsp; 41.737847&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/4F/B454FA8321E9C9FB98FC0ED6C9B31.jpg HTTP/1.1 &lt;br /&gt;464&amp;nbsp; 41.737898&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=7186 Ack=2874 Win=65535 Len=0&lt;br /&gt;465&amp;nbsp; 41.763584 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;466&amp;nbsp; 41.815036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A ad.doubleclick.net&lt;br /&gt;467&amp;nbsp; 41.815036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A speed.pointroll.com&lt;br /&gt;468&amp;nbsp; 41.863684&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1070 &amp;gt; 80 [ACK] Seq=899 Ack=371 Win=63870 Len=0&lt;br /&gt;469&amp;nbsp; 41.875036 96.17.171.99 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (application/json)&lt;br /&gt;470&amp;nbsp; 41.959015&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=1853 Ack=41235 Win=62859 Len=0&lt;br /&gt;471&amp;nbsp; 41.981056&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /br/sc/js/1c/4a0253de6eac448d8f2c39c53f8926.js HTTP/1.1 &lt;br /&gt;472&amp;nbsp; 41.981188&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1055 [ACK] Seq=367 Ack=1208 Win=65535 Len=0&lt;br /&gt;473&amp;nbsp; 42.029614&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;474&amp;nbsp; 42.029763&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;475&amp;nbsp; 42.059567&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.99 TCP 1071 &amp;gt; 80 [ACK] Seq=397 Ack=183 Win=64058 Len=0&lt;br /&gt;476&amp;nbsp; 42.103334 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME dart.l.doubleclick.net A 74.125.226.219&lt;br /&gt;477&amp;nbsp; 42.109345 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME speed.pointroll.com.edgesuite.net CNAME a1343.g.akamai.net A 96.17.168.113 A 96.17.168.91&lt;br /&gt;478&amp;nbsp; 42.115036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 TCP 1072 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;479&amp;nbsp; 42.119160&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;480&amp;nbsp; 42.124497&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/A9/7AA2D84B8DBC1D16190B37053EA70.jpg HTTP/1.1 &lt;br /&gt;481&amp;nbsp; 42.124517&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/74/59D9EBE09028E93076FEB538BDF8AD.jpg HTTP/1.1 &lt;br /&gt;482&amp;nbsp; 42.124582&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7604 Ack=3248 Win=65535 Len=0&lt;br /&gt;483&amp;nbsp; 42.124608&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=7354 Ack=3246 Win=65535 Len=0&lt;br /&gt;484&amp;nbsp; 42.136035&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 HTTP GET /br/sc/i/5f/5280118e68aedbc5821d17132a5340.gif HTTP/1.1 &lt;br /&gt;485&amp;nbsp; 42.136184 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [ACK] Seq=678 Ack=1855 Win=65535 Len=0&lt;br /&gt;486&amp;nbsp; 42.271036&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;487&amp;nbsp; 42.411033 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1073 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;488&amp;nbsp; 42.415015&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;489&amp;nbsp; 42.415015&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 HTTP GET /PointRoll/Media/Banners/Ford/915428/2011_YECMSN3for40_ML_EXP_300x250_Default.jpg?PRAd=1544247&amp;amp;PRCID=1544247&amp;amp;PRplcmt=1501166&amp;amp;PRPID=1501166 HTTP/1.1 &lt;br /&gt;490&amp;nbsp; 42.415015 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1073 [ACK] Seq=1 Ack=423 Win=65535 Len=0&lt;br /&gt;491&amp;nbsp; 42.415536 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1072 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;492&amp;nbsp; 42.415679&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 TCP 1072 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;493&amp;nbsp; 42.419616&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 HTTP GET /imp;v1;f;248163114;0-0;0;73804323;1%7C1;39709740%7C39727527%7C1;;cs=f;%3fhttp://ad.doubleclick.net/dot.gif?0.970374845534282 HTTP/1.1 &lt;br /&gt;494&amp;nbsp; 42.419679 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1072 [ACK] Seq=1 Ack=464 Win=65535 Len=0&lt;br /&gt;495&amp;nbsp; 42.422923&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;496&amp;nbsp; 42.427066&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 304 Not Modified &lt;br /&gt;497&amp;nbsp; 42.427692 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;498&amp;nbsp; 42.459605&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [ACK] Seq=1208 Ack=551 Win=63690 Len=0&lt;br /&gt;499&amp;nbsp; 42.505684&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 HTTP GET /msnhomepagehistory.aspx?sid=7415D61A534D4976A4769A771B40DC4E&amp;amp;_=1322546507615 HTTP/1.1 &lt;br /&gt;500&amp;nbsp; 42.505829 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1065 [ACK] Seq=778 Ack=1704 Win=65535 Len=0&lt;br /&gt;502&amp;nbsp; 42.526183&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; HTTP GET /msn/msnhp_us_ttg?ty=tl&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;tp=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;rid=&amp;amp;ts=634581432960349339&amp;amp;rf= HTTP/1.1 &lt;br /&gt;503&amp;nbsp; 42.526291&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1058 [ACK] Seq=741 Ack=2751 Win=65535 Len=0&lt;br /&gt;504&amp;nbsp; 42.535068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 HTTP GET /ADSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PN=MSFT&amp;amp;ID=3CE72C262627635C3C662E93222763E1&amp;amp;MUID=3CE72C262627635C3C662E93222763E1&amp;amp;PG=MSNHQ2&amp;amp;AP=1402 HTTP/1.1 &lt;br /&gt;505&amp;nbsp; 42.535068 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1067 [ACK] Seq=1870 Ack=1541 Win=65535 Len=0&lt;br /&gt;506&amp;nbsp; 42.541397&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1074 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;507&amp;nbsp; 42.559068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [ACK] Seq=1855 Ack=1207 Win=63034 Len=0&lt;br /&gt;508&amp;nbsp; 42.559068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=3246 Ack=7522 Win=63232 Len=0&lt;br /&gt;509&amp;nbsp; 42.559068&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=3248 Ack=7772 Win=63400 Len=0&lt;br /&gt;510&amp;nbsp; 42.673409 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;511&amp;nbsp; 42.673487 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;512&amp;nbsp; 42.673916 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;513&amp;nbsp; 42.673970&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=1449 Win=62792 Len=0&lt;br /&gt;514&amp;nbsp; 42.674015 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;515&amp;nbsp; 42.674261 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;516&amp;nbsp; 42.674334&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=2897 Win=64240 Len=0&lt;br /&gt;517&amp;nbsp; 42.674404 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;518&amp;nbsp; 42.674767 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;519&amp;nbsp; 42.674803 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;520&amp;nbsp; 42.674809&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=4345 Win=62792 Len=0&lt;br /&gt;521&amp;nbsp; 42.675405&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=5793 Win=64240 Len=0&lt;br /&gt;522&amp;nbsp; 42.686493 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1074 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;523&amp;nbsp; 42.686981&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1074 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;524&amp;nbsp; 42.686998&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 HTTP GET /ADSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PN=MSFT&amp;amp;ID=3CE72C262627635C3C662E93222763E1&amp;amp;MUID=3CE72C262627635C3C662E93222763E1&amp;amp;PG=MSNIF1&amp;amp;AP=1455 HTTP/1.1 &lt;br /&gt;525&amp;nbsp; 42.687061 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1074 [ACK] Seq=1 Ack=771 Win=65535 Len=0&lt;br /&gt;526&amp;nbsp; 42.687542 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;527&amp;nbsp; 42.687594 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;528&amp;nbsp; 42.687926 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;529&amp;nbsp; 42.687986&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=7241 Win=62792 Len=0&lt;br /&gt;530&amp;nbsp; 42.688059 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;531&amp;nbsp; 42.688083 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;532&amp;nbsp; 42.688104 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;533&amp;nbsp; 42.688436 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;534&amp;nbsp; 42.688468&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=8689 Win=64240 Len=0&lt;br /&gt;535&amp;nbsp; 42.688482&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=10137 Win=62792 Len=0&lt;br /&gt;536&amp;nbsp; 42.688526 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;537&amp;nbsp; 42.688990&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=11585 Win=64240 Len=0&lt;br /&gt;538&amp;nbsp; 42.692714 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;539&amp;nbsp; 42.692765 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;540&amp;nbsp; 42.693000 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;541&amp;nbsp; 42.693064&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=13033 Win=62792 Len=0&lt;br /&gt;542&amp;nbsp; 42.693112 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;543&amp;nbsp; 42.693961&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=14481 Win=64240 Len=0&lt;br /&gt;544&amp;nbsp; 42.696698 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;545&amp;nbsp; 42.696740 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;546&amp;nbsp; 42.697002 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;547&amp;nbsp; 42.697043&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=15929 Win=62792 Len=0&lt;br /&gt;548&amp;nbsp; 42.697091 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;549&amp;nbsp; 42.697385 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;550&amp;nbsp; 42.697420&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=17377 Win=64240 Len=0&lt;br /&gt;551&amp;nbsp; 42.697493 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;552&amp;nbsp; 42.697742 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;553&amp;nbsp; 42.697796&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=18825 Win=62792 Len=0&lt;br /&gt;554&amp;nbsp; 42.697845 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;555&amp;nbsp; 42.697858 96.17.168.113 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (JPEG JFIF image)&lt;br /&gt;556&amp;nbsp; 42.698340&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=20273 Win=64240 Len=0&lt;br /&gt;557&amp;nbsp; 42.698569 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;558&amp;nbsp; 42.707512 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 302 Moved Temporarily &lt;br /&gt;559&amp;nbsp; 42.712399 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;560&amp;nbsp; 42.739017&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 HTTP GET /dot.gif?0.970374845534282 HTTP/1.1 &lt;br /&gt;561&amp;nbsp; 42.739017 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1072 [ACK] Seq=196 Ack=828 Win=65535 Len=0&lt;br /&gt;562&amp;nbsp; 42.739017&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 HTTP GET /ADSAdClient31.dll?GetSAd=&amp;amp;DPJS=4&amp;amp;PN=MSFT&amp;amp;ID=3CE72C262627635C3C662E93222763E1&amp;amp;MUID=3CE72C262627635C3C662E93222763E1&amp;amp;PG=MSNSUR&amp;amp;AP=1089 HTTP/1.1 &lt;br /&gt;563&amp;nbsp; 42.739017 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1067 [ACK] Seq=2918 Ack=2311 Win=65535 Len=0&lt;br /&gt;564&amp;nbsp; 42.750353 96.17.171.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/javascript)&lt;br /&gt;565&amp;nbsp; 42.751066&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A ad.wsod.com&lt;br /&gt;566&amp;nbsp; 42.755297 65.55.121.231 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;567&amp;nbsp; 42.756436&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;568&amp;nbsp; 42.769281 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response A 209.234.225.242&lt;br /&gt;569&amp;nbsp; 42.774998&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 TCP 1075 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;570&amp;nbsp; 42.779251 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;571&amp;nbsp; 42.819327&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A ads2.msads.net&lt;br /&gt;572&amp;nbsp; 42.823411&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 HTTP GET /ad/N4492.MSN/B5014254.187;sz=1x1;ord=1124616328? HTTP/1.1 &lt;br /&gt;573&amp;nbsp; 42.823584 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1072 [ACK] Seq=408 Ack=1215 Win=65535 Len=0&lt;br /&gt;574&amp;nbsp; 42.831942 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME msnads.vo.msecnd.net A 65.54.81.161 A 65.54.81.152&lt;br /&gt;575&amp;nbsp; 42.835114&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;576&amp;nbsp; 42.841377 209.234.225.242 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1075 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;577&amp;nbsp; 42.841639&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 TCP 1075 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;578&amp;nbsp; 42.842983&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 HTTP GET /embed/8bec9b10877d5d7fd7c0fb6e6a631357/2398.1579.tk.177x20/725237877 HTTP/1.1 &lt;br /&gt;579&amp;nbsp; 42.843061 209.234.225.242 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1075 [ACK] Seq=1 Ack=447 Win=65535 Len=0&lt;br /&gt;580&amp;nbsp; 42.849859 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1076 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;581&amp;nbsp; 42.851660&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;582&amp;nbsp; 42.851682&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 HTTP GET /CIS/95/000/000/000/019/637.jpg HTTP/1.1 &lt;br /&gt;583&amp;nbsp; 42.851746 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1076 [ACK] Seq=1 Ack=271 Win=65535 Len=0&lt;br /&gt;584&amp;nbsp; 42.859036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [ACK] Seq=2751 Ack=1111 Win=63130 Len=0&lt;br /&gt;585&amp;nbsp; 42.859036&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1067 &amp;gt; 80 [ACK] Seq=2311 Ack=3661 Win=64240 Len=0&lt;br /&gt;586&amp;nbsp; 42.859177&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [ACK] Seq=1704 Ack=1561 Win=64240 Len=0&lt;br /&gt;587&amp;nbsp; 42.859192&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [ACK] Seq=423 Ack=20816 Win=63697 Len=0&lt;br /&gt;588&amp;nbsp; 42.859201&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1074 &amp;gt; 80 [ACK] Seq=771 Ack=1042 Win=63199 Len=0&lt;br /&gt;589&amp;nbsp; 42.866584 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;590&amp;nbsp; 42.866630 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;591&amp;nbsp; 42.866817&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=1449 Win=62792 Len=0&lt;br /&gt;592&amp;nbsp; 42.866872 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;593&amp;nbsp; 42.866906 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;594&amp;nbsp; 42.867362&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=2897 Win=64240 Len=0&lt;br /&gt;595&amp;nbsp; 42.869225 74.125.226.219 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 302 Moved Temporarily &lt;br /&gt;596&amp;nbsp; 42.870642&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A m.doubleclick.net&lt;br /&gt;597&amp;nbsp; 42.879138 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;598&amp;nbsp; 42.879176 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;599&amp;nbsp; 42.879606 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;600&amp;nbsp; 42.879650&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=4345 Win=62792 Len=0&lt;br /&gt;601&amp;nbsp; 42.879712 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;602&amp;nbsp; 42.879752 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;603&amp;nbsp; 42.879770 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;604&amp;nbsp; 42.879960&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=5793 Win=64240 Len=0&lt;br /&gt;605&amp;nbsp; 42.879984&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=7241 Win=62792 Len=0&lt;br /&gt;606&amp;nbsp; 42.880034 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;607&amp;nbsp; 42.880063 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;608&amp;nbsp; 42.880599&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=8689 Win=64240 Len=0&lt;br /&gt;609&amp;nbsp; 42.880669 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;610&amp;nbsp; 42.880708 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;611&amp;nbsp; 42.880851&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=10137 Win=62792 Len=0&lt;br /&gt;612&amp;nbsp; 42.881147 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;613&amp;nbsp; 42.881180 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;614&amp;nbsp; 42.881718&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=11585 Win=64240 Len=0&lt;br /&gt;615&amp;nbsp; 42.881931 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME s0-2mdn-net.l.google.com A 74.125.226.251&lt;br /&gt;616&amp;nbsp; 42.883451&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.251 TCP 1077 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;617&amp;nbsp; 42.883774 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;618&amp;nbsp; 42.883814 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;619&amp;nbsp; 42.884081 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;620&amp;nbsp; 42.884132&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=13033 Win=62792 Len=0&lt;br /&gt;621&amp;nbsp; 42.884182 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;622&amp;nbsp; 42.884760&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=14481 Win=64240 Len=0&lt;br /&gt;623&amp;nbsp; 42.891069 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;624&amp;nbsp; 42.891106 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;625&amp;nbsp; 42.891258&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=15929 Win=62792 Len=0&lt;br /&gt;626&amp;nbsp; 42.891421 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;627&amp;nbsp; 42.891474 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;628&amp;nbsp; 42.891698&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=17377 Win=64240 Len=0&lt;br /&gt;629&amp;nbsp; 42.891736 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;630&amp;nbsp; 42.891756 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;631&amp;nbsp; 42.892333&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=18825 Win=62792 Len=0&lt;br /&gt;632&amp;nbsp; 42.895527 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (JPEG JFIF image)&lt;br /&gt;633&amp;nbsp; 42.910686 209.234.225.242 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;634&amp;nbsp; 42.912344 74.125.226.251 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1077 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;635&amp;nbsp; 42.912673&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.251 TCP 1077 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;636&amp;nbsp; 42.914697&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.251 HTTP GET /dot.gif HTTP/1.1 &lt;br /&gt;637&amp;nbsp; 42.914776 74.125.226.251 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1077 [ACK] Seq=1 Ack=346 Win=65535 Len=0&lt;br /&gt;638&amp;nbsp; 42.936684 74.125.226.251 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;639&amp;nbsp; 43.059351&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=19542 Win=64240 Len=0&lt;br /&gt;640&amp;nbsp; 43.059392&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 TCP 1075 &amp;gt; 80 [ACK] Seq=447 Ack=585 Win=63656 Len=0&lt;br /&gt;641&amp;nbsp; 43.059403&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.251 TCP 1077 &amp;gt; 80 [ACK] Seq=346 Ack=361 Win=63880 Len=0&lt;br /&gt;642&amp;nbsp; 43.059411&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 TCP 1072 &amp;gt; 80 [ACK] Seq=1215 Ack=627 Win=63614 Len=0&lt;br /&gt;643&amp;nbsp; 44.111447&amp;nbsp; 65.54.81.47 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1066 [FIN, ACK] Seq=1208 Ack=666 Win=65535 Len=0&lt;br /&gt;644&amp;nbsp; 44.111703&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; TCP 1066 &amp;gt; 80 [ACK] Seq=666 Ack=1209 Win=63033 Len=0&lt;br /&gt;645&amp;nbsp; 44.125425 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1052 [FIN, ACK] Seq=849 Ack=1861 Win=65535 Len=0&lt;br /&gt;646&amp;nbsp; 44.125599&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [ACK] Seq=1861 Ack=850 Win=63392 Len=0&lt;br /&gt;647&amp;nbsp; 45.110536&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1054 [FIN, ACK] Seq=369 Ack=714 Win=65535 Len=0&lt;br /&gt;648&amp;nbsp; 45.110771&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [ACK] Seq=714 Ack=370 Win=63872 Len=0&lt;br /&gt;649&amp;nbsp; 45.913572 209.234.225.242 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1075 [FIN, ACK] Seq=585 Ack=447 Win=65535 Len=0&lt;br /&gt;650&amp;nbsp; 45.914044&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 TCP 1075 &amp;gt; 80 [ACK] Seq=447 Ack=586 Win=63656 Len=0&lt;br /&gt;651&amp;nbsp; 46.015286&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/D0/4278717F7C190E446356444E97F5A.jpg HTTP/1.1 &lt;br /&gt;652&amp;nbsp; 46.015286&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7772 Ack=3529 Win=65535 Len=0&lt;br /&gt;653&amp;nbsp; 46.021859&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; HTTP GET /ro.aspx?evt=br&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;rid=&amp;amp;cts=1322546511130&amp;amp;ce=1&amp;amp;hl=SWP22&amp;amp;cm=head%3Ecb1 HTTP/1.1 &lt;br /&gt;654&amp;nbsp; 46.021940&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1070 [ACK] Seq=371 Ack=1837 Win=65535 Len=0&lt;br /&gt;655&amp;nbsp; 46.023977&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 HTTP GET /c.gif?evt=br&amp;amp;rid=&amp;amp;exa=msnhp_us_master_v2%3AWP10_5%2Cmsnhp_us_anbov2%3AT2&amp;amp;cts=1322546511130&amp;amp;aop=&amp;amp;expac=673II6B39_0912%3AT2~40II3a39_0803%3AWP10_5%7C&amp;amp;fk=W&amp;amp;gp=P&amp;amp;optkey=default&amp;amp;clid=3CE72C262627635C3C662E93222763E1&amp;amp;di=340&amp;amp;pi=7317&amp;amp;ps=95101&amp;amp;mk=en-us&amp;amp;pn=US+HPMSFT3WANBOV2T2&amp;amp;pid=6875603&amp;amp;su=http%3A%2F%2Fwww.msn.com%2Fdefaultwpe3wanbov2t2.aspx&amp;amp;pageid=6875603&amp;amp;ce=1&amp;amp;hl=SWP22&amp;amp;cm=head%3Ecb1 HTTP/1.1 &lt;br /&gt;656&amp;nbsp; 46.024062 70.37.130.35 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1059 [ACK] Seq=368 Ack=2249 Win=65535 Len=0&lt;br /&gt;657&amp;nbsp; 46.110765&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1055 [FIN, ACK] Seq=551 Ack=1208 Win=65535 Len=0&lt;br /&gt;658&amp;nbsp; 46.110950&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [ACK] Seq=1208 Ack=552 Win=63690 Len=0&lt;br /&gt;659&amp;nbsp; 46.111199&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [FIN, ACK] Seq=7522 Ack=3246 Win=65535 Len=0&lt;br /&gt;660&amp;nbsp; 46.111313&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [ACK] Seq=3246 Ack=7523 Win=63232 Len=0&lt;br /&gt;661&amp;nbsp; 46.111460&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [FIN, ACK] Seq=7772 Ack=3529 Win=65535 Len=0&lt;br /&gt;662&amp;nbsp; 46.112343&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [ACK] Seq=3529 Ack=7773 Win=63400 Len=0&lt;br /&gt;663&amp;nbsp; 46.112364&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 209.234.225.242 TCP 1075 &amp;gt; 80 [RST, ACK] Seq=447 Ack=586 Win=0 Len=0&lt;br /&gt;664&amp;nbsp; 46.112380&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.47&amp;nbsp; TCP 1066 &amp;gt; 80 [RST, ACK] Seq=666 Ack=1209 Win=0 Len=0&lt;br /&gt;665&amp;nbsp; 46.112389&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1054 &amp;gt; 80 [RST, ACK] Seq=714 Ack=370 Win=0 Len=0&lt;br /&gt;666&amp;nbsp; 46.112397&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1055 &amp;gt; 80 [RST, ACK] Seq=1208 Ack=552 Win=0 Len=0&lt;br /&gt;667&amp;nbsp; 46.112406&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1052 &amp;gt; 80 [RST, ACK] Seq=1861 Ack=850 Win=0 Len=0&lt;br /&gt;668&amp;nbsp; 46.112691&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1064 &amp;gt; 80 [FIN, ACK] Seq=3529 Ack=7773 Win=63400 Len=0&lt;br /&gt;669&amp;nbsp; 46.112749&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1064 [ACK] Seq=7773 Ack=3530 Win=65535 Len=0&lt;br /&gt;670&amp;nbsp; 46.114825&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1063 &amp;gt; 80 [FIN, ACK] Seq=3246 Ack=7523 Win=63232 Len=0&lt;br /&gt;671&amp;nbsp; 46.114847&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;672&amp;nbsp; 46.114914&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1063 [ACK] Seq=7523 Ack=3247 Win=65535 Len=0&lt;br /&gt;673&amp;nbsp; 46.114979 65.54.81.161 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1076 [FIN, ACK] Seq=19542 Ack=271 Win=65535 Len=0&lt;br /&gt;674&amp;nbsp; 46.115148&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [ACK] Seq=271 Ack=19543 Win=64240 Len=0&lt;br /&gt;675&amp;nbsp; 46.117442 65.54.81.209 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1053 [FIN, ACK] Seq=1207 Ack=1855 Win=65535 Len=0&lt;br /&gt;676&amp;nbsp; 46.117592&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [ACK] Seq=1855 Ack=1208 Win=63034 Len=0&lt;br /&gt;677&amp;nbsp; 46.152358 70.37.130.35 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;678&amp;nbsp; 46.187614&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1078 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;679&amp;nbsp; 46.188088&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;680&amp;nbsp; 46.188111&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; HTTP GET /i/D0/4278717F7C190E446356444E97F5A.jpg HTTP/1.1 &lt;br /&gt;681&amp;nbsp; 46.188166&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1078 [ACK] Seq=1 Ack=282 Win=65535 Len=0&lt;br /&gt;682&amp;nbsp; 46.202724&amp;nbsp; 65.55.18.18 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (GIF89a)&lt;br /&gt;683&amp;nbsp; 46.264115&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 TCP 1059 &amp;gt; 80 [ACK] Seq=2249 Ack=735 Win=63506 Len=0&lt;br /&gt;684&amp;nbsp; 46.285768&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;685&amp;nbsp; 46.285830&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;686&amp;nbsp; 46.286098&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;687&amp;nbsp; 46.286134&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=1449 Win=62792 Len=0&lt;br /&gt;688&amp;nbsp; 46.286175&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;689&amp;nbsp; 46.286853&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=2897 Win=64240 Len=0&lt;br /&gt;690&amp;nbsp; 46.348872&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;691&amp;nbsp; 46.348930&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;692&amp;nbsp; 46.349148&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=4345 Win=62792 Len=0&lt;br /&gt;693&amp;nbsp; 46.349189&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;694&amp;nbsp; 46.349214&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;695&amp;nbsp; 46.349435&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=5793 Win=64240 Len=0&lt;br /&gt;696&amp;nbsp; 46.349475&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;697&amp;nbsp; 46.349502&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;698&amp;nbsp; 46.349924&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;699&amp;nbsp; 46.350051&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;700&amp;nbsp; 46.350277&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (JPEG JFIF image)&lt;br /&gt;701&amp;nbsp; 46.357721&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=7241 Win=62792 Len=0&lt;br /&gt;702&amp;nbsp; 46.357745&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=8689 Win=64240 Len=0&lt;br /&gt;703&amp;nbsp; 46.367174&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1070 &amp;gt; 80 [ACK] Seq=1837 Ack=741 Win=63500 Len=0&lt;br /&gt;704&amp;nbsp; 46.467160&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=9620 Win=63309 Len=0&lt;br /&gt;705&amp;nbsp; 47.921611&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 HTTP GET /?euid=3CE72C262627635C3C662E93222763E1&amp;amp;userGroup=W:default&amp;amp;PM=z:1&amp;amp;zipCode=22310&amp;amp;newsProviderId=WRC&amp;amp;weaDegreeType=F&amp;amp;weaLocations=wc%3A10067507 HTTP/1.1 &lt;br /&gt;706&amp;nbsp; 47.921794 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [ACK] Seq=41235 Ack=2799 Win=65535 Len=0&lt;br /&gt;707&amp;nbsp; 48.289718 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;708&amp;nbsp; 48.289792 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;709&amp;nbsp; 48.290040 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;710&amp;nbsp; 48.290067 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;711&amp;nbsp; 48.290076&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=42683 Win=64240 Len=0&lt;br /&gt;712&amp;nbsp; 48.290336 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;713&amp;nbsp; 48.290369 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;714&amp;nbsp; 48.290376&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=44131 Win=62792 Len=0&lt;br /&gt;715&amp;nbsp; 48.290871&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=45579 Win=64240 Len=0&lt;br /&gt;716&amp;nbsp; 48.291047 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;717&amp;nbsp; 48.291073 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;718&amp;nbsp; 48.291559 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;719&amp;nbsp; 48.291583 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;720&amp;nbsp; 48.291591&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=47027 Win=62792 Len=0&lt;br /&gt;721&amp;nbsp; 48.291921 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;722&amp;nbsp; 48.292038&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=48475 Win=64240 Len=0&lt;br /&gt;723&amp;nbsp; 48.292068 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;724&amp;nbsp; 48.292299 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;725&amp;nbsp; 48.292383&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=49923 Win=62792 Len=0&lt;br /&gt;726&amp;nbsp; 48.292425 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;727&amp;nbsp; 48.292808 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;728&amp;nbsp; 48.292897&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=51371 Win=64240 Len=0&lt;br /&gt;729&amp;nbsp; 48.292939 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;730&amp;nbsp; 48.293314 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;731&amp;nbsp; 48.293343 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;732&amp;nbsp; 48.293352&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=52819 Win=62792 Len=0&lt;br /&gt;733&amp;nbsp; 48.293786 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;734&amp;nbsp; 48.293871&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=54267 Win=64240 Len=0&lt;br /&gt;735&amp;nbsp; 48.293913 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;736&amp;nbsp; 48.294222 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;737&amp;nbsp; 48.294250&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=55715 Win=62792 Len=0&lt;br /&gt;738&amp;nbsp; 48.294274 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;739&amp;nbsp; 48.294679 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;740&amp;nbsp; 48.294706 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP [TCP segment of a reassembled PDU]&lt;br /&gt;741&amp;nbsp; 48.294712&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=57163 Win=64240 Len=0&lt;br /&gt;742&amp;nbsp; 48.294834&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=58611 Win=62792 Len=0&lt;br /&gt;743&amp;nbsp; 48.295187 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP HTTP/1.1 200 OK&amp;nbsp; (text/html)&lt;br /&gt;744&amp;nbsp; 48.467164&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=59959 Win=64240 Len=0&lt;br /&gt;745&amp;nbsp; 50.112739&amp;nbsp; 65.54.81.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1078 [FIN, ACK] Seq=9620 Ack=282 Win=65535 Len=0&lt;br /&gt;746&amp;nbsp; 50.112974&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [ACK] Seq=282 Ack=9621 Win=63309 Len=0&lt;br /&gt;747&amp;nbsp; 53.294480&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.161 TCP 1076 &amp;gt; 80 [RST, ACK] Seq=271 Ack=19543 Win=0 Len=0&lt;br /&gt;748&amp;nbsp; 53.294505&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.24&amp;nbsp; TCP 1078 &amp;gt; 80 [RST, ACK] Seq=282 Ack=9621 Win=0 Len=0&lt;br /&gt;749&amp;nbsp; 53.294515&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.54.81.209 TCP 1053 &amp;gt; 80 [RST, ACK] Seq=1855 Ack=1208 Win=0 Len=0&lt;br /&gt;750&amp;nbsp; 98.359689&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.206.209 TCP 1050 &amp;gt; 80 [RST, ACK] Seq=1129 Ack=298 Win=0 Len=0&lt;br /&gt;751&amp;nbsp; 98.360086&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.19.254 TCP 1049 &amp;gt; 80 [RST, ACK] Seq=1291 Ack=547 Win=0 Len=0&lt;br /&gt;753&amp;nbsp; 99.281366 207.46.140.46 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1057 [FIN, ACK] Seq=293 Ack=932 Win=65535 Len=0&lt;br /&gt;754&amp;nbsp; 99.281589&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 TCP 1057 &amp;gt; 80 [ACK] Seq=932 Ack=294 Win=63948 Len=0&lt;br /&gt;755 103.368611&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.251 TCP 1077 &amp;gt; 80 [RST, ACK] Seq=346 Ack=361 Win=0 Len=0&lt;br /&gt;756 103.368642&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.113 TCP 1073 &amp;gt; 80 [RST, ACK] Seq=423 Ack=20816 Win=0 Len=0&lt;br /&gt;757 103.368652&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 74.125.226.219 TCP 1072 &amp;gt; 80 [RST, ACK] Seq=1215 Ack=627 Win=0 Len=0&lt;br /&gt;758 103.368661&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.99 TCP 1071 &amp;gt; 80 [RST, ACK] Seq=397 Ack=183 Win=0 Len=0&lt;br /&gt;759 103.368669&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1074 &amp;gt; 80 [RST, ACK] Seq=771 Ack=1042 Win=0 Len=0&lt;br /&gt;760 103.368677&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.121.231 TCP 1067 &amp;gt; 80 [RST, ACK] Seq=2311 Ack=3661 Win=0 Len=0&lt;br /&gt;761 103.369276&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1069 &amp;gt; 80 [RST, ACK] Seq=489 Ack=241 Win=0 Len=0&lt;br /&gt;762 103.369290&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.171.161 TCP 1065 &amp;gt; 80 [RST, ACK] Seq=1704 Ack=1561 Win=0 Len=0&lt;br /&gt;763 103.369298&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 64.4.21.39&amp;nbsp;&amp;nbsp; TCP 1062 &amp;gt; 80 [RST, ACK] Seq=791 Ack=423 Win=0 Len=0&lt;br /&gt;764 103.369901&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 96.17.168.80 TCP 1061 &amp;gt; 80 [RST, ACK] Seq=383 Ack=249 Win=0 Len=0&lt;br /&gt;765 103.369913&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1058 &amp;gt; 80 [RST, ACK] Seq=2751 Ack=1111 Win=0 Len=0&lt;br /&gt;766 103.369922&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.46 TCP 1057 &amp;gt; 80 [RST, ACK] Seq=932 Ack=294 Win=0 Len=0&lt;br /&gt;767 104.617462 207.46.140.34 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1051 [FIN, ACK] Seq=59959 Ack=2799 Win=65535 Len=0&lt;br /&gt;768 104.617775&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [ACK] Seq=2799 Ack=59960 Win=64240 Len=0&lt;br /&gt;769 108.373475&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 70.37.130.35 TCP 1059 &amp;gt; 80 [RST, ACK] Seq=2249 Ack=735 Win=0 Len=0&lt;br /&gt;770 108.374044&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 65.55.18.18&amp;nbsp; TCP 1070 &amp;gt; 80 [RST, ACK] Seq=1837 Ack=741 Win=0 Len=0&lt;br /&gt;771 108.374060&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 207.46.140.34 TCP 1051 &amp;gt; 80 [RST, ACK] Seq=2799 Ack=59960 Win=0 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;74/[2011-11-29 01:05:43] "C:\APT_Conference information for next week.pdf" &lt;br /&gt;74/[2011-11-29 01:05:44] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;74/[2011-11-29 01:05:44] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;74/[2011-11-29 01:05:44] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;74/[2011-11-29 01:05:44] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;74/[2011-11-29 01:05:44] "iso88591" &lt;br /&gt;74&amp;nbsp; 44.123769&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 56.143195&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 59.145745&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;80&amp;nbsp; 65.154873&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;83&amp;nbsp; 77.173225&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;84&amp;nbsp; 80.176440&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;75/[2011-11-29 01:06:22] "C:\APT_DOB Aug 2011.pdf" &lt;br /&gt;75/[2011-11-29 01:06:22] "C:\WINDOWS\system32\cmd.exe" &lt;br /&gt;75/[2011-11-29 01:06:22] "C:\WINDOWS\system32\crypt32.dll" &lt;br /&gt;75/[2011-11-29 01:06:22] "iso88591" &lt;br /&gt;&amp;nbsp;43&amp;nbsp; 24.071248&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A sh.antivirusbar.org&lt;br /&gt;&amp;nbsp;47&amp;nbsp; 24.758951 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response A 58.68.224.24&lt;br /&gt;&amp;nbsp;48&amp;nbsp; 25.287274&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;50&amp;nbsp; 25.746641 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1046 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;51&amp;nbsp; 25.746656&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1046 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;52&amp;nbsp; 25.747357&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP [TCP segment of a reassembled PDU]&lt;br /&gt;&amp;nbsp;53&amp;nbsp; 25.747373&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 HTTP POST /phqghumeaylnlfdxfircvscxggbwkfn.htm HTTP/1.1 &lt;br /&gt;&amp;nbsp;54&amp;nbsp; 25.747430 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1046 [ACK] Seq=1 Ack=236 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;55&amp;nbsp; 25.747449 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1046 [ACK] Seq=1 Ack=1516 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;76/[2011-11-29 01:08:49] "C:\APT_g20 summit.pdf" &lt;br /&gt;76/[2011-11-29 01:08:49] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;76/[2011-11-29 01:08:50] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;76/[2011-11-29 01:08:50] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;76/[2011-11-29 01:08:50] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;76/[2011-11-29 01:08:50] "iso88591" &lt;br /&gt;&amp;nbsp;1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;60&amp;nbsp; 34.827483&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;62&amp;nbsp; 35.375156 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;63&amp;nbsp; 35.375595&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1044 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;64&amp;nbsp; 35.375614&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 SSL Continuation Data&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 35.375670 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [ACK] Seq=1 Ack=192 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;66&amp;nbsp; 35.643683 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [FIN, ACK] Seq=1 Ack=192 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;67&amp;nbsp; 35.644358&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1044 &amp;gt; 443 [ACK] Seq=192 Ack=2 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 35.644382&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.92.33.98 TCP 1044 &amp;gt; 443 [FIN, ACK] Seq=192 Ack=2 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;69&amp;nbsp; 35.644435 203.92.33.98 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1044 [ACK] Seq=2 Ack=193 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;70&amp;nbsp; 35.646130&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.146 TCP 1046 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;72&amp;nbsp; 36.192141 211.233.62.146 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1046 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;73&amp;nbsp; 36.192503&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.146 TCP 1046 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 36.192520&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.146 SSL Continuation Data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;77/[2011-11-29 01:09:27] "C:\APT_ID194.pdf" &lt;br /&gt;77/[2011-11-29 01:09:27] "C:\WINDOWS\system32\cmd.exe" &lt;br /&gt;77/[2011-11-29 01:09:27] "C:\WINDOWS\system32\crypt32.dll" &lt;br /&gt;77/[2011-11-29 01:09:27] "iso88591" &lt;br /&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; 0.000000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet [Packet size limited during capture]&lt;br /&gt;&amp;nbsp;42&amp;nbsp; 23.708044&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A sh.antivirusbar.org&lt;br /&gt;&amp;nbsp;43&amp;nbsp; 24.209549 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response A 58.68.224.24&lt;br /&gt;&amp;nbsp;44&amp;nbsp; 24.213107&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;48&amp;nbsp; 24.732612 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;49&amp;nbsp; 24.733912&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1045 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;50&amp;nbsp; 24.735034&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP [TCP segment of a reassembled PDU]&lt;br /&gt;&amp;nbsp;51&amp;nbsp; 24.735034 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=1 Ack=236 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;52&amp;nbsp; 24.736365&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 HTTP POST /phqghumeaylnlfdxfircvscxggbwkfn.htm HTTP/1.1 &lt;br /&gt;&amp;nbsp;53&amp;nbsp; 24.736428 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=1 Ack=1516 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;78/[2011-11-29 01:11:54] "C:\APT_military procurement.pdf" &lt;br /&gt;78/[2011-11-29 01:11:55] "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;br /&gt;78/[2011-11-29 01:11:55] "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe" &lt;br /&gt;78/[2011-11-29 01:11:55] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;78/[2011-11-29 01:11:55] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;78/[2011-11-29 01:11:55] "iso88591" &lt;br /&gt;60&amp;nbsp; 34.295971&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 37.284641&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;67&amp;nbsp; 37.841869 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;68&amp;nbsp; 37.842133&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 TCP 1043 &amp;gt; 443 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;69&amp;nbsp; 37.843287&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 203.116.203.67 SSL Continuation Data&lt;br /&gt;&amp;nbsp;70&amp;nbsp; 37.843342 203.116.203.67 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 443 &amp;gt; 1043 [ACK] Seq=1 Ack=194 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;79/[2011-11-29 01:14:22] "C:\APT_NorthKorea.pdf" &lt;br /&gt;79/[2011-11-29 01:14:22] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;79/[2011-11-29 01:14:22] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;79/[2011-11-29 01:14:22] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;79/[2011-11-29 01:14:22] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;79/[2011-11-29 01:14:22] "iso88591" &lt;br /&gt;60&amp;nbsp; 34.992584&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.148 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;65&amp;nbsp; 37.908912&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.148 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;73&amp;nbsp; 43.943196&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.148 TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;75&amp;nbsp; 60.967116&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.148 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 63.970209&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 211.233.62.148 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;80/[2011-11-29 01:16:51] "C:\APT_Nuclear Security and Summit Diplomacy.pdf" &lt;br /&gt;80/[2011-11-29 01:16:53] "C:\DOCUME~1\Angie\LOCALS~1\Temp\A9R83C7.tmp" &lt;br /&gt;80/[2011-11-29 01:16:53] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;80/[2011-11-29 01:16:53] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;80/[2011-11-29 01:16:54] "C:\WINDOWS\AutoUpdate.exe" &lt;br /&gt;80/[2011-11-29 01:16:54] "C:\WINDOWS\ºÓ°]«O96-97³q°T¿ý.pdf" &lt;br /&gt;----&lt;br /&gt;&lt;br /&gt;81/[2011-11-29 01:19:57] "C:\APT_statement.pdf" &lt;br /&gt;81/[2011-11-29 01:19:58] "C:\DOCUME~1\Angie\LOCALS~1\Temp\2.pdf" &lt;br /&gt;81/[2011-11-29 01:19:58] "C:\DOCUME~1\Angie\LOCALS~1\Temp\Migrated.exe" &lt;br /&gt;81/[2011-11-29 01:19:58] "C:\WINDOWS\system32\d3d8caps.dat" &lt;br /&gt;81/[2011-11-29 01:19:58] "C:\WINDOWS\system32\d3d9caps.dat" &lt;br /&gt;81/[2011-11-29 01:19:58] "iso88591" &lt;br /&gt;&lt;br /&gt;72&amp;nbsp; 54.979463&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 78.39.236.6&amp;nbsp; TCP 1047 &amp;gt; 53 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;75&amp;nbsp; 57.981829&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 78.39.236.6&amp;nbsp; TCP 1047 &amp;gt; 53 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 63.990170&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 78.39.236.6&amp;nbsp; TCP 1047 &amp;gt; 53 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;81&amp;nbsp; 76.008794&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.222.205.180 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;83&amp;nbsp; 79.012034&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 61.222.205.180 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;Download&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s1600/bag6.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s320/bag6.JPG" /&gt;&lt;/a&gt;&lt;a href="http://www.mediafire.com/?672og8n4975qoha"&gt;Download 30 analysis packages   as a password   protected archive (contact me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-3554843933961966470?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/3554843933961966470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2011/11/30-pdf-files-processed-by-cuckoo.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/3554843933961966470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/3554843933961966470'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2011/11/30-pdf-files-processed-by-cuckoo.html' title='30 PDF files processed by Cuckoo Sandbox - results and samples'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-nuQHToWkaSE/TtSO-FHYliI/AAAAAAAACy8/mqClyhzgjh4/s72-c/ss.GIF' height='72' width='72'/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-2915750395759436929</id><published>2011-11-29T02:14:00.004-05:00</published><updated>2011-11-29T07:18:46.190-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2011-0611'/><category scheme='http://www.blogger.com/atom/ns#' term='cuckoo sandbox'/><title type='text'>Nov 3 CVE-2011-0611 1104statment.pdf analyzed via Cuckoo sandbox</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-6g8bNSY9FsA/TtR2mk-ciQI/AAAAAAAACyE/MHTKGbzv-eQ/s1600/SANd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/-6g8bNSY9FsA/TtR2mk-ciQI/AAAAAAAACyE/MHTKGbzv-eQ/s1600/SANd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-6g8bNSY9FsA/TtR2mk-ciQI/AAAAAAAACyE/MHTKGbzv-eQ/s1600/SANd.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;"&gt;&lt;br /&gt;I have been away and busy with all kinds of stuff (some malware related and some not :)&amp;nbsp; but I am back.&lt;/div&gt;&lt;div dir="ltr" style="text-align: left;"&gt;I played a little recently with Cuckoo sandbox - an awesome free sandbox developed by &lt;i&gt;&lt;i&gt;&lt;/i&gt;&lt;/i&gt;Claudio Guarnieri (&lt;a href="http://www.linkedin.com/profile/view?id=36088486&amp;amp;authType=name&amp;amp;authToken=9jSg&amp;amp;locale=en_US&amp;amp;pvs=pp&amp;amp;trk=ppro_viewmore"&gt;Linkedin&lt;/a&gt;). The sandbox has been out for several months, constantly being improved and got a lot of fans. You can &lt;a href="http://cuckoobox.org/doc/0.2/Cuckoo%20User%20Guide.pdf"&gt;read the Cuckoo guide here&lt;/a&gt; and also follow active discussions on the &lt;a href="http://forums.malwr.com/"&gt;Malwr forum&lt;/a&gt;. I think the sandbox works very well and very flexible -&amp;nbsp; it can be developed and extended to analyze any (many) kinds of exploits. You can find descriptions of the sandbox online but I want to post results of the sandbox analysis - something I didn't have chance to see until I installed it. I will post unfiltered results and with some minimal processing (conversion of pcaps to text, filtering out search results, etc.). This tool is still in development and you will not get polished reports like you see on Threatexpert but they are exportable into a database of your choice, searchable, and "tweakable". If you already tried it a while ago, try it again, I heard the later versions are much better than the earlier ones. &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;div dir="ltr" style="text-align: left;"&gt;&lt;div class="post-body entry-content"&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Common Vulnerability &amp;amp; Exposures CVE#&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;span style="color: black;"&gt;&lt;/span&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0611"&gt;CVE-2011-0611&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;br /&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;&lt;/h3&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: large; font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;General File Information&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;span style="color: black;"&gt;CVE-2011-0611&lt;/span&gt;&lt;br /&gt;&lt;div style="background-color: white; color: black;"&gt;File: 1104statment.pdf&lt;br /&gt;Size: 91010&lt;br /&gt;MD5:&amp;nbsp; 86730A9BC3AB99503322EDA6115C1096&lt;/div&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;Download&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;div style="color: #38761d;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s1600/bag6.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s320/bag6.JPG" /&gt;&lt;/a&gt;&lt;a href="http://www.mediafire.com/?o1dy115y68z37i7"&gt;Download   as a password   protected archive (email me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?fq1y4c2c25qn599"&gt;Download unfiltered analysis results - analysis folder&amp;nbsp; (email me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s1600/orange2.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s320/orange2.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=7885177434994542510&amp;amp;postID=166499980563317027" name="more"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="date-posts"&gt;&lt;div class="post-outer"&gt;&lt;div class="post hentry"&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;Original Message and Headers&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="background-color: white; color: black;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-aG4Dd3tK2sU/TtRxHWX4agI/AAAAAAAACx0/8v28RmepDoI/s1600/msg.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-aG4Dd3tK2sU/TtRxHWX4agI/AAAAAAAACx0/8v28RmepDoI/s400/msg.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;span style="color: black;"&gt;Received: (qmail 3627 invoked from network); 3 Nov 2011 02:53:35 -0000&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Received: from msr8.hinet.net (HELO msr8.hinet.net) (168.95.4.108)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;xxxxxxxxxxxxxx&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Received: from deepin-f12c1fc0 (60-249-181-163.HINET-IP.hinet.net [60.249.181.163])&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; by msr8.hinet.net (8.14.2/8.14.2) with SMTP id pA32pCaW016745&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;xxxxxxxxxxxxx&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Date: Thu, 3 Nov 2011 10:51:17 +0800&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;From: "cy.hsiao" &amp;lt;cy.hsiao@msa.hinet.net&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;xxxxx&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Reply-To: "jun.lun" &amp;lt;jun.lun@msa.hinet.net&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Subject: 1104statment&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;X-Priority: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;X-GUID: 2AE71A5A-DDDA-497A-B8B7-1850D647AC9D&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;X-Mailer: &lt;b&gt;Foxmail 7.0.1.84[cn]&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;MIME-Version: 1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Message-ID: &amp;lt;201111031040202773896@msa.hinet.net&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;Content-Type: multipart/mixed;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; boundary="----=_001_NextPart150125300633_=----"&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/div&gt;&lt;br /&gt;60.249.181.163&lt;br /&gt;60.249.0.0 - 60.249.255.255&lt;br /&gt;Taiwan&lt;br /&gt;CHTD, Chunghwa Telecom Co.,Ltd.&lt;br /&gt;Data-Bldg.6F, No.21, Sec.21, Hsin-Yi Rd.&lt;br /&gt;Taipei Taiwan 100&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="padding: 0in;" valign="top"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td style="color: black; font-family: inherit;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Automated Scans&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;86730a9bc3ab99503322eda6115c1096&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=8a2b54f64d1866ac8c46c99651cadba1597bc5671cf9b4a966c1d23898b19ce6-1320344807"&gt;http://www.virustotal.com/file-scan/report.html?id=8a2b54f64d1866ac8c46c99651cadba1597bc5671cf9b4a966c1d23898b19ce6-1320344807&lt;/a&gt;&lt;br /&gt;Submission date:2011-11-03 18:26:47 (UTC)&lt;br /&gt;Result: 10 /42 (23.8%)&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.0.1289.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; SWF:Dropper [Heur]&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp;&amp;nbsp; 7.2 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Script.SWF.C08&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp;&amp;nbsp; 9.0.16440.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Script.SWF.C08&lt;br /&gt;GData &amp;nbsp;&amp;nbsp;&amp;nbsp; 22 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Script.SWF.C08&lt;br /&gt;Microsoft &amp;nbsp;&amp;nbsp;&amp;nbsp; 1.7801 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit:Win32/Pdfjsc.XD&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp;&amp;nbsp; 6.07.13 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit/2011-0611.A&lt;br /&gt;nProtect &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011-11-03.01 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Script.SWF.C08&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp;&amp;nbsp; 4.71.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Troj/SWFExp-AK&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp;&amp;nbsp; 20111.2.0.82 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan.Pidief&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp;&amp;nbsp; 14.1.44.0 &amp;nbsp;&amp;nbsp;&amp;nbsp; 2011.11.03 &amp;nbsp;&amp;nbsp;&amp;nbsp; SWF.CVE-2011-0609.C&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : 86730a9bc3ab99503322eda6115c1096&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Created files&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;div class="post hentry"&gt;&lt;b&gt;&amp;nbsp;Trojan Taidoor&lt;/b&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;Cuckoo sandbox does a great job on binaries (&lt;a href="https://twitter.com/#%21/botherder/status/141472324904960001"&gt;and can capture deleted files too&lt;/a&gt;) but the document analysis results require a bit more filtering due to many legitimate Adobe and Office files that get generated during the analysis. It also does not calculate hash. &lt;/div&gt;&lt;br /&gt;&lt;div class="post hentry"&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;/div&gt;&lt;div class="post hentry"&gt;&lt;b&gt;Dropped files (Results of a filtering script)&lt;/b&gt;&amp;nbsp; - &lt;/div&gt;&lt;div class="post hentry"&gt;[2011-11-29 00:13:25] [INFO] Dropped file "C:\APT_1104statment.pdf" &lt;/div&gt;[2011-11-29 00:13:28] [INFO] Dropped file "C:\Documents and Settings\Angie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp" &lt;br /&gt;&lt;span style="color: #7f6000;"&gt;[2011-11-29 00:13:28] [INFO] Dropped file "C:\WINDOWS\system32\d3d9caps.dat" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #7f6000;"&gt;[2011-11-29 00:13:28] [INFO] Dropped file "C:\WINDOWS\system32\d3d8caps.dat" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #7f6000;"&gt;[2011-11-29 00:13:28] [INFO] Dropped file "iso88591" &lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;[2011-11-29 00:13:28] [INFO] Dropped file "C:\DOCUME~1\Angie\LOCALS~1\Temp\RTHDCPL.exe"&lt;/span&gt; &lt;br /&gt;&lt;span style="color: red;"&gt;[2011-11-29 00:13:28] [INFO] Dropped file "C:\DOCUME~1\Angie\LOCALS~1\Temp\1.pdf" &lt;/span&gt;&lt;br /&gt;[2011-11-29 00:13:29] [INFO] Dropped file "C:\WINDOWS\system32\OLEACCRC.DLL" &lt;br /&gt;[2011-11-29 00:13:29] [INFO] Dropped file "C:\WINDOWS\system32\oleacc.dll" &lt;br /&gt;&lt;div class="post hentry"&gt;&lt;br /&gt;Here is a&lt;a href="http://www.mediafire.com/?bp04kgjba7erpk7"&gt; unfiltered log&lt;/a&gt; (you would get all these files in the "Files" analysis folder as well)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?fq1y4c2c25qn599"&gt;This is a zipped folder with the entire unfiltered analysis (use the password scheme or email me if you need it)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=e4875a7fe94b53f0088b0aedd88a2601b4bee99ed8d8196b547adfdb5cafe638-1322293498"&gt;www.virustotal.com/file-scan/report.html?id=e4875a7fe94b53f0088b0aedd88a2601b4bee99ed8d8196b547adfdb5cafe638-1322293498&lt;/a&gt;&lt;br /&gt;&amp;nbsp;2011112&lt;br /&gt;Submission date:2011-11-26 07:44:58 (UTC)&lt;br /&gt;Result:33 /43 (76.7%)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Antivirus &amp;nbsp;&amp;nbsp; &amp;nbsp;Version &amp;nbsp;&amp;nbsp; &amp;nbsp;Last Update &amp;nbsp;&amp;nbsp; &amp;nbsp;Result&lt;br /&gt;AhnLab-V3 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25.00 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor/Win32.CSon&lt;br /&gt;AntiVir &amp;nbsp;&amp;nbsp; &amp;nbsp;7.11.18.78 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;TR/Hijacker.Gen&lt;br /&gt;Antiy-AVL &amp;nbsp;&amp;nbsp; &amp;nbsp;2.0.3.7 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor/Win32.Agent.gen&lt;br /&gt;Avast &amp;nbsp;&amp;nbsp; &amp;nbsp;6.0.1289.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Win32:Malware-gen&lt;br /&gt;AVG &amp;nbsp;&amp;nbsp; &amp;nbsp;10.0.0.1190 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;BackDoor.Generic14.AJZQ&lt;br /&gt;BitDefender &amp;nbsp;&amp;nbsp; &amp;nbsp;7.2 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Gen:Trojan.Heur.TP.bq1@byoLvWnb&lt;br /&gt;CAT-QuickHeal &amp;nbsp;&amp;nbsp; &amp;nbsp;12.00 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Agent.bwtk&lt;br /&gt;Comodo &amp;nbsp;&amp;nbsp; &amp;nbsp;10789 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;UnclassifiedMalware&lt;br /&gt;DrWeb &amp;nbsp;&amp;nbsp; &amp;nbsp;5.0.2.03300 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Trojan.Taidoor&lt;br /&gt;Emsisoft &amp;nbsp;&amp;nbsp; &amp;nbsp;5.1.0.11 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Win32.Simbot!IK&lt;br /&gt;eSafe &amp;nbsp;&amp;nbsp; &amp;nbsp;7.0.17.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.24 &amp;nbsp;&amp;nbsp; &amp;nbsp;Win32.TRHijacker&lt;br /&gt;F-Secure &amp;nbsp;&amp;nbsp; &amp;nbsp;9.0.16440.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Gen:Trojan.Heur.TP.bq1@byoLvWnb&lt;br /&gt;Fortinet &amp;nbsp;&amp;nbsp; &amp;nbsp;4.3.370.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;W32/Injector.JQA!tr&lt;br /&gt;GData &amp;nbsp;&amp;nbsp; &amp;nbsp;22 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Gen:Trojan.Heur.TP.bq1@byoLvWnb&lt;br /&gt;Ikarus &amp;nbsp;&amp;nbsp; &amp;nbsp;T3.1.1.109.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Win32.Simbot&lt;br /&gt;Jiangmin &amp;nbsp;&amp;nbsp; &amp;nbsp;13.0.900 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor/Agent.diki&lt;br /&gt;K7AntiVirus &amp;nbsp;&amp;nbsp; &amp;nbsp;9.119.5542 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor&lt;br /&gt;Kaspersky &amp;nbsp;&amp;nbsp; &amp;nbsp;9.0.0.837 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Win32.Agent.bwtk&lt;br /&gt;McAfee &amp;nbsp;&amp;nbsp; &amp;nbsp;5.400.0.1158 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Generic BackDoor!dtm&lt;br /&gt;McAfee-GW-Edition &amp;nbsp;&amp;nbsp; &amp;nbsp;2010.1D &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Generic BackDoor!dtm&lt;br /&gt;Microsoft &amp;nbsp;&amp;nbsp; &amp;nbsp;1.7801 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor:Win32/Simbot.gen&lt;br /&gt;NOD32 &amp;nbsp;&amp;nbsp; &amp;nbsp;6660 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;a variant of Win32/Injector.JQA&lt;br /&gt;Norman &amp;nbsp;&amp;nbsp; &amp;nbsp;6.07.13 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;W32/Suspicious_Gen2.RUNSA&lt;br /&gt;Panda &amp;nbsp;&amp;nbsp; &amp;nbsp;10.0.3.5 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Generic Backdoor&lt;br /&gt;PCTools &amp;nbsp;&amp;nbsp; &amp;nbsp;8.0.0.5 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Trojan&lt;br /&gt;Sophos &amp;nbsp;&amp;nbsp; &amp;nbsp;4.71.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Mal/Simbot-A&lt;br /&gt;Symantec &amp;nbsp;&amp;nbsp; &amp;nbsp;20111.2.0.82 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Trojan&lt;br /&gt;TheHacker &amp;nbsp;&amp;nbsp; &amp;nbsp;6.7.0.1.347 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.24 &amp;nbsp;&amp;nbsp; &amp;nbsp;Trojan/Injector.jqa&lt;br /&gt;TrendMicro &amp;nbsp;&amp;nbsp; &amp;nbsp;9.500.0.1008 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;TROJ_GEN.R47C7K4&lt;br /&gt;TrendMicro-HouseCall &amp;nbsp;&amp;nbsp; &amp;nbsp;9.500.0.1008 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;TROJ_GEN.R47C7K4&lt;br /&gt;VBA32 &amp;nbsp;&amp;nbsp; &amp;nbsp;3.12.16.4 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;TrojanDownloader.Rubinurd.f&lt;br /&gt;VIPRE &amp;nbsp;&amp;nbsp; &amp;nbsp;11151 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.26 &amp;nbsp;&amp;nbsp; &amp;nbsp;Trojan.Win32.Generic!BT&lt;br /&gt;VirusBuster &amp;nbsp;&amp;nbsp; &amp;nbsp;14.1.85.0 &amp;nbsp;&amp;nbsp; &amp;nbsp;2011.11.25 &amp;nbsp;&amp;nbsp; &amp;nbsp;Backdoor.Agent!kZFb0jr2OQ4&lt;br /&gt;Additional information&lt;br /&gt;MD5&amp;nbsp;&amp;nbsp; : a3a71678576164e93e882392e609a917&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It also generates many screenshots to capture the malware behavior (you can turn off this feature) - see one screenshot below&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rW7L-xOsivw/TtSDniZj1QI/AAAAAAAACyU/Ax64xGr4P3U/s1600/shot_17.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="480" src="http://2.bp.blogspot.com/-rW7L-xOsivw/TtSDniZj1QI/AAAAAAAACyU/Ax64xGr4P3U/s640/shot_17.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TNcrVWSpXTI/AAAAAAAABxU/9NsxVNqQHxk/s1600/apple.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Trebuchet MS',sans-serif; font-size: large;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Traffic&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;Cuckoo creates a dump pcap file you can &lt;a href="http://www.mediafire.com/?m1ph372w8a64phm"&gt;download from there&lt;/a&gt;. You can of course run conversion to text as part of your post-processing routine&amp;nbsp; like you see below.&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 50.331130&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; &lt;span style="color: red;"&gt;110.142.12.95&lt;/span&gt; TCP 1044 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;76&amp;nbsp; 62.360903&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 65.352406&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 71.361654&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1046 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;81&amp;nbsp; 83.379329&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; &lt;span style="color: red;"&gt;108.77.146.124&lt;/span&gt; TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;83&amp;nbsp; 86.382691&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;85&amp;nbsp; 92.391543&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1047 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;89 104.309538&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;91 107.313022&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;94 113.321174&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 108.77.146.124 TCP 1048 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;100 127.342043&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1049 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;102 130.345727&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1049 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;108 136.354881&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 110.142.12.95 TCP 1049 &amp;gt; 443 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;b&gt;110.142.12.95&lt;/b&gt;&lt;br /&gt;hirudo.lnk.telstra.net&lt;br /&gt;Host reachable, 259 ms. average&lt;br /&gt;110.142.0.0 - 110.143.255.255&lt;br /&gt;Telstra&lt;br /&gt;Level 12, 242 Exhibition St&lt;br /&gt;Melbourne&lt;br /&gt;VIC 3000&lt;br /&gt;Australia&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;108.77.146.124&lt;/b&gt;&lt;br /&gt;108-77-146-124.lightspeed.tulsok.sbcglobal.net&lt;br /&gt;Host unreachable&lt;br /&gt;108.64.0.0 - 108.95.255.255&lt;br /&gt;AT&amp;amp;T Internet Services&lt;br /&gt;2701 N. Central Expwy # 2205.15&lt;br /&gt;Richardson&lt;br /&gt;TX&lt;br /&gt;75080&lt;br /&gt;United States&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7pPuhnZS6DY/TtSBOYKam0I/AAAAAAAACyM/SM-q80HnUq8/s1600/pcp.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="258" src="http://4.bp.blogspot.com/-7pPuhnZS6DY/TtSBOYKam0I/AAAAAAAACyM/SM-q80HnUq8/s640/pcp.GIF" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Examples of other captures&amp;nbsp; (I will post these files separately)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;42&amp;nbsp; 23.708044&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 &lt;span style="color: red;"&gt;DNS Standard query A sh.antivirusbar.org&lt;/span&gt;&lt;br /&gt;&amp;nbsp;43&amp;nbsp; 24.209549 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: red;"&gt;DNS Standard query response A 58.68.224.24&lt;/span&gt;&lt;br /&gt;&amp;nbsp;44&amp;nbsp; 24.213107&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;48&amp;nbsp; 24.732612 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;49&amp;nbsp; 24.733912&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP 1045 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&amp;nbsp;50&amp;nbsp; 24.735034&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24 TCP [TCP segment of a reassembled PDU]&lt;br /&gt;&amp;nbsp;51&amp;nbsp; 24.735034 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=1 Ack=236 Win=65535 Len=0&lt;br /&gt;&amp;nbsp;52&amp;nbsp; 24.736365&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 58.68.224.24&lt;span style="color: red;"&gt; HTTP POST /phqghumeaylnlfdxfircvscxggbwkfn.htm &lt;/span&gt;HTTP/1.1 &lt;br /&gt;&amp;nbsp;53&amp;nbsp; 24.736428 58.68.224.24 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [ACK] Seq=1 Ack=1516 Win=65535 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;74&amp;nbsp; 40.881943&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 68.87.73.246 DNS Standard query A checkip.dyndns.org&lt;br /&gt;&amp;nbsp;75&amp;nbsp; 41.032372 68.87.73.246 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS Standard query response CNAME checkip.dyndns.com A 216.146.39.70 A 91.198.22.70 A 216.146.38.70&lt;br /&gt;&amp;nbsp;76&amp;nbsp; 41.033219&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;77&amp;nbsp; 41.269469 216.146.39.70 -&amp;gt; 10.0.2.15&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP 80 &amp;gt; 1045 [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;br /&gt;&amp;nbsp;78&amp;nbsp; 41.270321&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.15 -&amp;gt; 216.146.39.70 TCP 1045 &amp;gt; 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-2915750395759436929?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/2915750395759436929/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2011/11/nov-3-cve-2011-0611-1104statmentpdf.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/2915750395759436929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/2915750395759436929'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2011/11/nov-3-cve-2011-0611-1104statmentpdf.html' title='Nov 3 CVE-2011-0611 1104statment.pdf analyzed via Cuckoo sandbox'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-6g8bNSY9FsA/TtR2mk-ciQI/AAAAAAAACyE/MHTKGbzv-eQ/s72-c/SANd.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-5037671726188422137</id><published>2011-11-17T00:41:00.003-05:00</published><updated>2011-11-29T02:15:37.938-05:00</updated><title type='text'>Hi</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;Believe it or not, I am still alive and will post something soon. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-5037671726188422137?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/5037671726188422137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2011/11/hi.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5037671726188422137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5037671726188422137'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2011/11/hi.html' title='Hi'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-5045343061672570579</id><published>2011-11-03T07:57:00.003-04:00</published><updated>2011-11-03T07:59:22.787-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='chm'/><title type='text'>Step by step  binary analysis with Frankie Li ( dg003.exe dropper from "XinTang Event.chm" )</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-itEQyAbbbj8/TrJ9KYz8WdI/AAAAAAAACxM/axF8NouKxVQ/s1600/vxrl.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="143" src="http://4.bp.blogspot.com/-itEQyAbbbj8/TrJ9KYz8WdI/AAAAAAAACxM/axF8NouKxVQ/s200/vxrl.GIF" width="200" /&gt;&lt;/a&gt;With the express written permission from the author, here is a an excellent paper "&lt;i&gt;&lt;a href="http://www.giac.org/paper/grem/3129/detailed-analysis-advanced-persistent-threat-malware/127483"&gt;A Detailed Analysis of an Advanced Persistent Threat Malware&lt;/a&gt;&lt;/i&gt;" and the corresponding malware sample, which you can reverse engineer following step by step explanation by the author Frankie Li (&lt;a href="http://espionageware.blogspot.com/"&gt;http://espionageware.blogspot.com&lt;/a&gt;/)- from &lt;a href="http://vxrl.org/"&gt;vxrl.org (Valkyrie-X Security Research Group)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Another great analysis from the same group of another CHM file can be found here: &lt;a href="https://sites.google.com/site/valkyriexsecurityresearch/announcements/aptpaperacceptedbymalware2011conference/Final_Paper_v3.1.pdf?attredirects=0&amp;amp;d=1"&gt;&lt;i&gt;Evidence of Advanced Persistent Threat&lt;/i&gt;: &lt;i&gt;A Case Study of Malware for Political Espionage&lt;/i&gt;&lt;/a&gt; (paper for IEEE 6th International Conference on Malicious and Unwanted Software (Malware 2011)).&lt;br /&gt;&lt;br /&gt;Do you wonder if your sample APT or just crimeware? Use their &lt;a href="http://aptdeezer.xecure-lab.com/"&gt;Xecure Deezer - APT identification engine&lt;/a&gt;&amp;nbsp; &lt;br /&gt;&lt;span style="color: #333333; font-family: Arial,Helvetica,sans-serif; font-size: 12px; line-height: 18px;"&gt;&lt;span style="font-family: Verdana; font-size: 10pt;"&gt;&lt;b style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="color: #990000; font-family: Arial,Helvetica,sans-serif;"&gt;&lt;b&gt; &lt;/b&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;/b&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;&lt;/h3&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&amp;nbsp;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size: large; font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;&lt;b&gt;General File Information&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit; font-size: small;"&gt;&lt;span style="color: #990000;"&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;File: dg003.exe&lt;br /&gt;Size: 196608&lt;br /&gt;MD5:&amp;nbsp; 4EC0027BEF4D7E1786A04D021FA8A67F&lt;/h3&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="color: #990000; font-family: Arial,Helvetica,sans-serif;"&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;&lt;b&gt;Download&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;div style="color: #38761d;"&gt;&lt;b&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s1600/bag6.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s320/bag6.JPG" /&gt;&lt;/a&gt;&lt;a href="http://www.mediafire.com/file/4pmad9dpynopo11/4EC0027BEF4D7E1786A04D021FA8A67_EXE_dg003.zip"&gt;Download    as a password    protected archive (contact me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s1600/orange2.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s320/orange2.JPG" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7885177434994542510-5045343061672570579?l=contagiodump.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://contagiodump.blogspot.com/feeds/5045343061672570579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://contagiodump.blogspot.com/2011/11/step-by-step-binary-analysis-with.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5045343061672570579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7885177434994542510/posts/default/5045343061672570579'/><link rel='alternate' type='text/html' href='http://contagiodump.blogspot.com/2011/11/step-by-step-binary-analysis-with.html' title='Step by step  binary analysis with Frankie Li ( dg003.exe dropper from &quot;XinTang Event.chm&quot; )'/><author><name>Mila</name><uri>http://www.blogger.com/profile/09472209631979859691</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-itEQyAbbbj8/TrJ9KYz8WdI/AAAAAAAACxM/axF8NouKxVQ/s72-c/vxrl.GIF' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7885177434994542510.post-1990549796646927815</id><published>2011-10-27T01:12:00.001-04:00</published><updated>2011-10-27T06:57:19.249-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-3129'/><title type='text'>Oct 18 CVE-2009-3129 XLS 2011-10-18    101 calendar</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-N3oy-M89-lk/Tqjkv7aoXOI/AAAAAAAACxA/PqDsfFEgw4w/s1600/cal.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-N3oy-M89-lk/Tqjkv7aoXOI/AAAAAAAACxA/PqDsfFEgw4w/s200/cal.JPG" width="200" /&gt;&lt;/a&gt;Another day, another sample. CVE-2009-3129 XLS file from &lt;span id="result_box" lang="en"&gt;&lt;span class="hps"&gt;kevins19702@gmail.com, but it was actually sent by a Hinet server (I guess Gmail addresses are accepted better than Hinet)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The trojan calls home to &lt;span style="color: red; font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;220.246.76.125&lt;/span&gt;&lt;br /&gt;&lt;div style="color: black;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;POST http://check.amanerolor.com:443/index.php HTTP/1.0&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/-K0tQwsaaSQ8/TgU-K0FJYKI/AAAAAAAACDk/hOZEuSns3dA/s1600/t2.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="post-body entry-content"&gt;&lt;div style="background-color: white; color: #38761d;"&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: large; font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;Common Vulnerabilities and Exposures (CVE)number&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;&lt;span style="font-size: small;"&gt;CVE-2009-3129 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2;Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac;Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; andOffice Compatibility Pack for Word, Excel, and PowerPoint 2007 FileFormats SP1 and SP2 allows remote attackers to execute arbitrary codevia a spreadsheet with a FEATHEADER record containing an invalidcbHdrData size element that affects a pointer offset, aka "ExcelFeatheader Record Memory Corruption Vulnerability."&lt;/span&gt;&lt;/h3&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;&lt;/h3&gt;&lt;h3 style="background-color: #618f2b; color: white; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;span style="font-size: large;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: large; font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace;"&gt;General File Information&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style="background-color: white; color: black; font-weight: normal; text-align: left;"&gt;&lt;span style="font-size: small;"&gt; File: 101.xls&lt;br /&gt;Size: 224279&lt;br /&gt;MD5:&amp;nbsp; B344B78FB07B63105A52F6ECFB0EDFB0&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;h3 style="background-color: #618f2b; color: white; text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-family: 'Courier New',Courier,monospace; font-size: large;"&gt;Download&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;div style="color: #38761d;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s1600/bag6.JPG" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_xQabPlo6k5s/S5D5RBVdPqI/AAAAAAAAAuo/Dc7Qbe4zllc/s320/bag6.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/file/66oybl736489gnf/CVE-2009-3129_XLS_2011-10-18_101.zip"&gt;Download   as a password   protected archive (contact me if you need the password)&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_xQabPlo6k5s/TA5mL_xcZ2I/AAAAAAAABY0/PDa12IDKfK4/s1600/orange2.JPG" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-K0tQwsaaSQ8/TgU-K0FJYKI/AAAAAAAACDk/hOZEuSns3dA/s1600/t2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-K0tQwsaaSQ8/TgU-K0FJYKI/AAAAAAAACDk/hOZEuSns3dA/s1600/t2.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white; color: black;"&gt;&lt;div style="background-color: white; color: black;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&
