REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\Filters\(Virus) Bropia.worm.p]
"FilterBuffer"=hex:a5,01,00,00,08,00,00,00,17,00,8f,00,1f,00,1e,00,00,eb,00,06,\
  00,50,00,00,00,00,00,00,00,00,00,70,00,00,00,00,00,1f,00,00,7c,35,00,02,00,\
  01,00,06,00,01,00,00,00,00,00,26,47,45,54,20,2f,6c,6f,6c,5f,66,2a,2a,2a,5f,\
  79,6f,75,5f,6c,6f,6c,2f,6c,30,6c,5f,35,33,78,79,5f,6c,30,6c,2e,6a,70,67,01,\
  00,06,00,01,00,00,00,00,00,26,47,45,54,20,2f,6c,6f,6c,5f,66,75,63,6b,5f,79,\
  6f,75,5f,6c,6f,6c,2f,6c,30,6c,5f,35,33,78,79,5f,6c,30,6c,2e,6a,70,67,17,00,\
  00,00,a6,00,20,00,00,6a,00,06,00,19,00,00,00,00,00,00,00,00,00,2a,00,00,00,\
  d0,00,1f,00,00,f7,00,00,00,00,01,00,06,00,02,00,00,dc,05,00,11,6d,65,6d,62,\
  65,72,73,2e,63,68,65,6c,6c,6f,2e,6e,6c,39,00,09,01,00,00,1f,00,00,56,1e,00,\
  02,00,00,00,01,00,02,00,00,dc,05,00,0f,43,48,45,43,4b,20,54,48,49,53,20,4c,\
  4f,4c,21,00,00,01,00,02,00,00,00,00,00,06,43,55,53,54,4f,4d,3a,00,43,01,00,\
  00,1f,00,00,a9,20,00,02,00,00,00,01,00,02,00,00,dc,05,00,11,48,75,67,65,20,\
  54,75,72,64,20,68,61,68,61,61,68,21,00,00,01,00,02,00,00,dc,05,00,05,4c,4f,\
  4f,4b,21,30,00,73,01,00,00,1f,00,00,08,14,00,02,00,00,00,01,00,02,00,00,dc,\
  05,00,05,6e,69,63,65,21,00,00,01,00,02,00,00,dc,05,00,07,6f,77,6e,61,67,65,\
  21,32,00,00,00,00,00,1f,00,00,3a,00,00,00,00,00,00,01,00,02,00,00,dc,05,00,\
  19,70,61,72,69,73,20,68,69,6c,74,6f,6e,20,67,6f,74,20,68,61,63,6b,65,64,21,\
  21
"szDescr"="The sending machine is attempting to download a .jpg file. This file is downloaded upon execution of the Bropia worm."
"RGBValue"=dword:00800080
"szFolder"="Virus Filters"
"bFilterBasedAlarm"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\ProtocolPresetsV9]

