Trojan.Win32.Llac.kzfk (Kaspersky), Generic.Rebhip.71F8A182 (B) (Emsisoft), Generic.Rebhip.71F8A182 (AdAware), Trojan.Win32.Swrort.4.FD, TrojanSwrort.YR, GenericAutorunWorm.YR, GenericInjector.YR, WormRebhip.YR (Lavasoft MAS)Behaviour: Trojan, Worm, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: a2005a84f59ba944cd22a759d9a914a9
SHA1: 71d6c83d55dc841a00ea799f7a10ec4d45abbb21
SHA256: 709296f63fe47204e5ce1d34706f4ebe7f9a825ace3687d36b8b8d2c191c6d28
SSDeep: 6144:tmcD66RRjdSwV/C5JGmrpQsK3RD2u270jupCJsCxCB:4cD663kwBZ2zkPaCxI
Size: 313344 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: MCor
Created at: 1992-06-20 01:22:17
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Generic's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The Generic creates the following process(es):
%original file name%.exe:1900
The Generic injects its code into the following process(es):
chrome.exe:2916
Explorer.EXE:2024
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1900 makes changes in the file system.
The Generic creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XX--XX--XX.txt (258 bytes)
C:\WindowsUpdeta\install\Updeta.exe (1425 bytes)
The process chrome.exe:2916 makes changes in the file system.
The Generic creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\logs.dat (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UuU.uUu (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XxX.xXx (13360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rDos.exe (46 bytes)
The Generic deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XX--XX--XX.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XxX.xXx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UuU.uUu (0 bytes)
Registry activity
The process %original file name%.exe:1900 makes changes in the system registry.
The Generic creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies" = "c:\WindowsUpdeta\install\Updeta.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
"Policies" = "c:\WindowsUpdeta\install\Updeta.exe"
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{VXUOGFMD-2I55-NK0M-A7QS-5412F0KO53EW}]
"StubPath" = "c:\WindowsUpdeta\install\Updeta.exe Restart"
To automatically run itself each time Windows is booted, the Generic adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "c:\WindowsUpdeta\install\Updeta.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "c:\WindowsUpdeta\install\Updeta.exe"
The process chrome.exe:2916 makes changes in the system registry.
The Generic creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"AccessibilityCpl.dll,-10" = "Ease of Access Center"
"gameux.dll,-10082" = "Games Explorer"
"gameux.dll,-10061" = "Spider Solitaire"
"pmcsnap.dll,-700" = "Print Management"
"wdc.dll,-10021" = "Performance Monitor"
"mblctr.exe,-1008" = "Windows Mobility Center"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"mycomput.dll,-300" = "Computer Management"
"SyncCenter.dll,-3000" = "Sync Center"
"msinfo32.exe,-100" = "System Information"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\WindowsPowerShell\v1.0]
"powershell.exe,-101" = "Windows PowerShell ISE"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10060" = "Solitaire"
"ie4uinit.exe,-737" = "Internet Explorer (No Add-ons)"
"odbcint.dll,-1310" = "Data Sources (ODBC)"
"gameux.dll,-10103" = "Internet Spades"
"MdSched.exe,-4001" = "Windows Memory Diagnostic"
"gameux.dll,-10059" = "Mahjong Titans"
"wucltux.dll,-1" = "Windows Update"
[HKCU\Software\vÃÂÂtima]
"FirstExecution" = "29/11/2016 -- 20:20"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"dfrgui.exe,-103" = "Disk Defragmenter"
"filemgmt.dll,-2204" = "Services"
"gameux.dll,-10102" = "Internet Backgammon"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\migwiz]
"wet.dll,-588" = "Windows Easy Transfer"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"NetProjW.dll,-501" = "Connect to a Network Projector"
"rstrui.exe,-100" = "System Restore"
"SoundRecorder.exe,-100" = "Sound Recorder"
"gameux.dll,-10055" = "FreeCell"
"gameux.dll,-10209" = "More Games from Microsoft"
"wsecedit.dll,-718" = "Local Security Policy"
"gameux.dll,-10056" = "Hearts"
"gameux.dll,-10057" = "Minesweeper"
"gameux.dll,-10054" = "Chess Titans"
"comres.dll,-3410" = "Component Services"
"msra.exe,-100" = "Windows Remote Assistance"
"wdc.dll,-10030" = "Resource Monitor"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"ShapeCollector.exe,-298" = "Personalize Handwriting Recognition"
[HKCU\Software\Google\Chrome\BLBeacon]
"failed_count" = "0"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Windows Journal]
"Journal.exe,-3074" = "Windows Journal"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"FXSRESM.dll,-114" = "Windows Fax and Scan"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\DVD Maker]
"DVDMaker.exe,-61403" = "Windows DVD Maker"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\Speech\SpeechUX]
"sapi.cpl,-5555" = "Windows Speech Recognition"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"displayswitch.exe,-320" = "Connect to a Projector"
"iscsicpl.dll,-5001" = "iSCSI Initiator"
"sdcpl.dll,-101" = "Backup and Restore"
"msconfig.exe,-126" = "System Configuration"
"recdisc.exe,-2000" = "Create a System Repair Disc"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"mip.exe,-291" = "Math Input Panel"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Windows Sidebar]
"sidebar.exe,-1005" = "Desktop Gadget Gallery"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10058" = "Purble Place"
"AuthFWGP.dll,-20" = "Windows Firewall with Advanced Security"
"miguiresource.dll,-101" = "Event Viewer"
"XpsRchVw.exe,-102" = "XPS Viewer"
"miguiresource.dll,-201" = "Task Scheduler"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\migwiz]
"wet.dll,-591" = "Windows Easy Transfer Reports"
[HKCU\Software\Google\Chrome\BLBeacon]
"State" = "2"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10101" = "Internet Checkers"
[HKCU\Software\vÃÂÂtima]
"NewIdentification" = "vÃÂÂtima"
[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"TipTsf.dll,-80" = "Tablet PC Input Panel"
The Generic deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
Dropped PE files
MD5 | File path |
---|---|
ddd822d85f905d0c62367e95e9c52530 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\rDos.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Generic's file once a user opens a drive's folder in Windows Explorer.
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1900
- Delete the original Generic file.
- Delete or disinfect the following files created/modified by the Generic:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XX--XX--XX.txt (258 bytes)
C:\WindowsUpdeta\install\Updeta.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\logs.dat (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UuU.uUu (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\XxX.xXx (13360 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\rDos.exe (46 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "c:\WindowsUpdeta\install\Updeta.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "c:\WindowsUpdeta\install\Updeta.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 45512 | 45568 | 4.44597 | 4a2150bf37c4ff6bbd8f4f2c3a09b096 |
DATA | 53248 | 544 | 1024 | 1.91604 | dd653175899ceecf929eb6d19ce189b4 |
BSS | 57344 | 4593 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 65536 | 3044 | 3072 | 3.30697 | 4f982c9b59dc3fc83ad5a7c9912faa66 |
.tls | 69632 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 73728 | 24 | 512 | 0.142404 | a270a5e1f4f71f9ddb31027f913842a2 |
.reloc | 77824 | 2656 | 3072 | 4.32933 | ba51f7deda6128aa3417cb4fe1f7eb61 |
.rsrc | 81920 | 258752 | 259072 | 5.42794 | 7739a6e141db1c0bc17a48a4e63123df |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
insan.hopto.org | 88.232.240.36 |
dns.msftncsi.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Generic connects to the servers at the folowing location(s):
Strings from Dumps
chrome.exe_2916:
.text
.text
`.rdata
`.rdata
@.data
@.data
.gfids
.gfids
@.tls
@.tls
.rsrc
.rsrc
@.reloc
@.reloc
D$,j.Xf
D$,j.Xf
j.Yf;
j.Yf;
_tcPVj@
_tcPVj@
.PjRW
.PjRW
Cv.SCv
Cv.SCv
ole32.dll
ole32.dll
POWRPROF.dll
POWRPROF.dll
address family not supported
address family not supported
broken pipe
broken pipe
function not supported
function not supported
inappropriate io control operation
inappropriate io control operation
not supported
not supported
operation canceled
operation canceled
operation in progress
operation in progress
operation not permitted
operation not permitted
operation not supported
operation not supported
operation would block
operation would block
protocol not supported
protocol not supported
InitOnceExecuteOnce
InitOnceExecuteOnce
operator
operator
operator ""
operator ""
?#%X.y
?#%X.y
%S#[k
%S#[k
?OLEAUT32.dll
?OLEAUT32.dll
user32.dll
user32.dll
c:\b\build\slave\win-pgo\build\src\chrome\app\chrome_exe_main_win.cc
c:\b\build\slave\win-pgo\build\src\chrome\app\chrome_exe_main_win.cc
c:\b\build\slave\win-pgo\build\src\chrome\app\main_dll_loader_win.cc
c:\b\build\slave\win-pgo\build\src\chrome\app\main_dll_loader_win.cc
Failed to load Chrome DLL from
Failed to load Chrome DLL from
ChromeMain
ChromeMain
RelaunchChromeBrowserWithNewCommandLineIfNeeded
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Could not find exported function
Could not find exported function
%s: option `%s' is ambiguous (could be `--%s' or `--%s')
%s: option `%s' is ambiguous (could be `--%s' or `--%s')
%s: invalid option -- `-%c'
%s: invalid option -- `-%c'
%s: argument required for option `
%s: argument required for option `
--%s'
--%s'
0.8.0
0.8.0
%ls (%s) %s
%ls (%s) %s
hXXps://crashpad.chromium.org/
hXXps://crashpad.chromium.org/
hXXps://crashpad.chromium.org/bug/new
hXXps://crashpad.chromium.org/bug/new
Report %ls bugs to
Report %ls bugs to
%s home page:
%s home page:
%ls: %s
%ls: %s
(0x%X)
(0x%X)
Error (0x%X) while retrieving error. (0x%X)
Error (0x%X) while retrieving error. (0x%X)
PlatformFile.UnknownErrors.Windows
PlatformFile.UnknownErrors.Windows
c:\b\build\slave\win-pgo\build\src\base\threading\thread_local_win.cc
c:\b\build\slave\win-pgo\build\src\base\threading\thread_local_win.cc
0123456789
0123456789
Histogram: %s recorded %d samples
Histogram: %s recorded %d samples
(flags = 0x%x)
(flags = 0x%x)
.syzygy
.syzygy
.thunks
.thunks
Windows NT
Windows NT
Histogram.InconsistentCountHigh
Histogram.InconsistentCountHigh
Histogram.InconsistentCountLow
Histogram.InconsistentCountLow
c:\b\build\slave\win-pgo\build\src\base\metrics\persistent_memory_allocator.cc
c:\b\build\slave\win-pgo\build\src\base\metrics\persistent_memory_allocator.cc
(%d = %3.1f%%)
(%d = %3.1f%%)
UMA.CreatePersistentHistogram.Result
UMA.CreatePersistentHistogram.Result
Dictionary keys must be quoted.
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
Unsupported encoding. JSON must be UTF-8.
Line: %i, column: %i, %s
Line: %i, column: %i, %s
widevinecdmadapter.dll
widevinecdmadapter.dll
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_update_settings.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_update_settings.cc
Removed incremental installer failure key; switching to channel:
Removed incremental installer failure key; switching to channel:
Failed to write to application's ClientState key
Failed to write to application's ClientState key
Removed multi-install failure key; switching to channel:
Removed multi-install failure key; switching to channel:
CHROME_PROBED_PROGRAM_FILES_PATH
CHROME_PROBED_PROGRAM_FILES_PATH
chrome-sxs
chrome-sxs
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_chrome_distribution.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_chrome_distribution.cc
iexplore.exe
iexplore.exe
googlechrome
googlechrome
googlechromeframe
googlechromeframe
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\channel_info.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\channel_info.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\language_selector.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\language_selector.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_commands.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_commands.cc
Cannot initialize AppCommands from an invalid key.
Cannot initialize AppCommands from an invalid key.
Skipping over key "
Skipping over key "
Failed to open key "
Failed to open key "
Cannot initialize an AppCommand from an invalid key.
Cannot initialize an AppCommand from an invalid key.
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_command.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_command.cc
CHROME_MAIN_TICKS
CHROME_MAIN_TICKS
user_experience_metrics.reporting_enabled
user_experience_metrics.reporting_enabled
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\settings.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\settings.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\numeric\in_range_cast.h
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\numeric\in_range_cast.h
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\crash_report_database_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\crash_report_database_win.cc
x-x-x-xx-xxxxxx
x-x-x-xx-xxxxxx
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\misc\uuid.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\misc\uuid.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io.cc
--annotation=KEY=VALUE set a process annotation in each crash report
--annotation=KEY=VALUE set a process annotation in each crash report
--database=PATH store the crash report database at PATH
--database=PATH store the crash report database at PATH
create a new pipe and send its name via HANDLE
create a new pipe and send its name via HANDLE
--pipe-name=PIPE communicate with the client over PIPE
--pipe-name=PIPE communicate with the client over PIPE
--url=URL send crash reports to this Breakpad server URL,
--url=URL send crash reports to this Breakpad server URL,
pipe-name
pipe-name
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\handler_main.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\handler_main.cc
duplicate key
duplicate key
--annotation requires KEY=VALUE
--annotation requires KEY=VALUE
--handshake-handle and --pipe-name are incompatible
--handshake-handle and --pipe-name are incompatible
--handshake-handle or --pipe-name is required
--handshake-handle or --pipe-name is required
SetProcessShutdownParameters
SetProcessShutdownParameters
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\crash_report_upload_thread.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\crash_report_upload_thread.cc
reserved key
reserved key
FinishedWritingCrashReport failed
FinishedWritingCrashReport failed
PrepareNewCrashReport failed
PrepareNewCrashReport failed
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\win\crash_report_exception_handler.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\win\crash_report_exception_handler.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_file_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_file_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writer_util.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writer_util.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writable.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writable.cc
%s.%s,%s,%s
%s.%s,%s,%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_context_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_context_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\process_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\process_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\crashpad_info_client_options.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\crashpad_info_client_options.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_simple_string_dictionary_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_simple_string_dictionary_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\module_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\module_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\exception_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\exception_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\module_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\module_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\system_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\system_snapshot_win.cc
%s %d.%d.%d.%s%s
%s %d.%d.%d.%s%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_reader_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_reader_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_string_list_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_string_list_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\capture_memory.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\capture_memory.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\cpu_context_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\cpu_context_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_annotations_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_annotations_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_subrange_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_subrange_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_resource_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_resource_reader.cc
kernel32.dll
kernel32.dll
c:\b\build\slave\win-pgo\build\src\sandbox\win\src\sandbox_policy_base.cc
c:\b\build\slave\win-pgo\build\src\sandbox\win\src\sandbox_policy_base.cc
NtOpenKey
NtOpenKey
NtCreateKey
NtCreateKey
GetCertificateSize
GetCertificateSize
GetCertificate
GetCertificate
GetCertificateSizeByHandle
GetCertificateSizeByHandle
GetCertificateByHandle
GetCertificateByHandle
SetOPMSigningKeyAndSequenceNumbers
SetOPMSigningKeyAndSequenceNumbers
CreateNamedPipeW
CreateNamedPipeW
NtOpenKeyEx
NtOpenKeyEx
PruneCrashReportDatabase: Failed to get pending reports
PruneCrashReportDatabase: Failed to get pending reports
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\prune_crash_reports.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\prune_crash_reports.cc
PruneCrashReportDatabase: Failed to get completed reports
PruneCrashReportDatabase: Failed to get completed reports
Database Pruning: Failed to remove report
Database Pruning: Failed to remove report
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\exception_handler_server.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\exception_handler_server.cc
::GetNamedPipeClientProcessId
::GetNamedPipeClientProcessId
\\.\pipe\crashpad_%d_
\\.\pipe\crashpad_%d_
ImpersonateNamedPipeClient
ImpersonateNamedPipeClient
ConnectNamedPipe
ConnectNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_reader.cc
WinHttpSetTimeouts
WinHttpSetTimeouts
WinHttpCrackUrl
WinHttpCrackUrl
WinHttpConnect
WinHttpConnect
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_transport_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_transport_win.cc
WinHttpCloseHandle
WinHttpCloseHandle
Crashpad/0.8.0
Crashpad/0.8.0
WinHttpOpen
WinHttpOpen
WinHttpSendRequest
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryHeaders
HTTP status %d
HTTP status %d
WinHttpOpenRequest
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpAddRequestHeaders
WinHttpReadData
WinHttpReadData
%%x
%%x
--%s%sContent-Disposition: form-data; name="%s"
--%s%sContent-Disposition: form-data; name="%s"
; filename="%s"%s
; filename="%s"%s
Content-Type: %s%s
Content-Type: %s%s
multipart/form-data; boundary=%s
multipart/form-data; boundary=%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_process_suspend.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_process_suspend.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_seeker.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_seeker.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\process_info.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\process_info.cc
Reading x64 process from x86 process not supported
Reading x64 process from x86 process not supported
0x%llx 0x%llx (%s)
0x%llx 0x%llx (%s)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\module_version.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\module_version.cc
(0xx)
(0xx)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_local_alloc.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_local_alloc.cc
WaitNamedPipe
WaitNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\registration_protocol_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\registration_protocol_win.cc
TransactNamedPipe
TransactNamedPipe
SetNamedPipeHandleState
SetNamedPipeHandleState
TransactNamedPipe: expected
TransactNamedPipe: expected
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_body.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_body.cc
InvokeMainViaCRT
InvokeMainViaCRT
ExitMainViaCRT
ExitMainViaCRT
Microsoft.CRTProvider
Microsoft.CRTProvider
C:\b\build\slave\win-pgo\build\src\out\Release\initialexe\chrome.exe.pdb
C:\b\build\slave\win-pgo\build\src\out\Release\initialexe\chrome.exe.pdb
.text$di
.text$di
.text$mn
.text$mn
.text$x
.text$x
.text$yd
.text$yd
.idata$5
.idata$5
.CRT$XCA
.CRT$XCA
.CRT$XCAA
.CRT$XCAA
.CRT$XCC
.CRT$XCC
.CRT$XCL
.CRT$XCL
.CRT$XCU
.CRT$XCU
.CRT$XCZ
.CRT$XCZ
.CRT$XIA
.CRT$XIA
.CRT$XIAA
.CRT$XIAA
.CRT$XIAC
.CRT$XIAC
.CRT$XIC
.CRT$XIC
.CRT$XIZ
.CRT$XIZ
.CRT$XLA
.CRT$XLA
.CRT$XLB
.CRT$XLB
.CRT$XLZ
.CRT$XLZ
.CRT$XPA
.CRT$XPA
.CRT$XPX
.CRT$XPX
.CRT$XPXA
.CRT$XPXA
.CRT$XPZ
.CRT$XPZ
.CRT$XTA
.CRT$XTA
.CRT$XTZ
.CRT$XTZ
.rdata
.rdata
.rdata$T
.rdata$T
.rdata$r
.rdata$r
.rdata$sxdata
.rdata$sxdata
.rdata$zETW0
.rdata$zETW0
.rdata$zETW1
.rdata$zETW1
.rdata$zETW2
.rdata$zETW2
.rdata$zETW9
.rdata$zETW9
.rdata$zzzdbg
.rdata$zzzdbg
.rtc$IAA
.rtc$IAA
.rtc$IZZ
.rtc$IZZ
.rtc$TAA
.rtc$TAA
.rtc$TZZ
.rtc$TZZ
.xdata$x
.xdata$x
.didat$2
.didat$2
.didat$3
.didat$3
.didat$4
.didat$4
.didat$6
.didat$6
.didat$7
.didat$7
.edata
.edata
.idata$2
.idata$2
.idata$3
.idata$3
.idata$4
.idata$4
.idata$6
.idata$6
.data
.data
.data$r
.data$r
.didat$5
.didat$5
.gfids$x
.gfids$x
.gfids$y
.gfids$y
.tls$ZZZ
.tls$ZZZ
.rsrc$01
.rsrc$01
.rsrc$02
.rsrc$02
chrome.exe
chrome.exe
SignalChromeElf
SignalChromeElf
SignalInitializeCrashReporting
SignalInitializeCrashReporting
chrome_elf.dll
chrome_elf.dll
RegOpenKeyExW
RegOpenKeyExW
RegEnumKeyExW
RegEnumKeyExW
RegCreateKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegCloseKey
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
CreateIoCompletionPort
CreateIoCompletionPort
GetWindowsDirectoryW
GetWindowsDirectoryW
GetProcessHandleCount
GetProcessHandleCount
KERNEL32.dll
KERNEL32.dll
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
CloseWindowStation
CloseWindowStation
CreateWindowStationW
CreateWindowStationW
GetProcessWindowStation
GetProcessWindowStation
SetProcessWindowStation
SetProcessWindowStation
USER32.dll
USER32.dll
VERSION.dll
VERSION.dll
WINMM.dll
WINMM.dll
WTSAPI32.dll
WTSAPI32.dll
RPCRT4.dll
RPCRT4.dll
GetCPInfo
GetCPInfo
GetProcessHeap
GetProcessHeap
PeekNamedPipe
PeekNamedPipe
DisconnectNamedPipe
DisconnectNamedPipe
WaitNamedPipeW
WaitNamedPipeW
WINHTTP.dll
WINHTTP.dll
.?AU_Crt_new_delete@std@@
.?AU_Crt_new_delete@std@@
a.IDATx
a.IDATx
%F?????????3
%F?????????3
ÿFFFFFFFFFFFFFFF?B%
ÿFFFFFFFFFFFFFFF?B%
:1----16
:1----16
Rhgf^rrrr( ?NOCdhgfrrrr...DlEBScjhg^rr,001k>985Tnhherr-12
Rhgf^rrrr( ?NOCdhgfrrrr...DlEBScjhg^rr,001k>985Tnhherr-12
:BBBBBBBBBB>>-.jdddcccca
:BBBBBBBBBB>>-.jdddcccca
3 3*363@3
3 3*363@3
6#6(60676
6#6(60676
0%1X1y1
0%1X1y1
4"4'4-44494p4K5Z9j9t9}9
4"4'4-44494p4K5Z9j9t9}9
; ;%;7;>;^;
; ;%;7;>;^;
6 6$6(6,60646
6 6$6(6,60646
8-8C8}8
8-8C8}8
? ?$?(?,?0?4?8?
? ?$?(?,?0?4?8?
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
5 5$5(5,5054585
5 5$5(5,5054585
? ?$?(?,?0?
? ?$?(?,?0?
= =@=\=`=
= =@=\=`=
KERNEL32.DLL
KERNEL32.DLL
mscoree.dll
mscoree.dll
ext-ms-win-ntuser-windowstation-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
portuguese-brazilian
portuguese-brazilian
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
nchrome_watcher.dll
nchrome_watcher.dll
PreReadChromeChildInBrowser
PreReadChromeChildInBrowser
${windows}
${windows}
Ndebug.log
Ndebug.log
\StringFileInfo\xx\%ls
\StringFileInfo\xx\%ls
ntdll.dll
ntdll.dll
shell32.dll
shell32.dll
script.log
script.log
resources.pak
resources.pak
chrome
chrome
pepflashplayer.dll
pepflashplayer.dll
Browse the web
Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\Chromium
Software\Microsoft\Windows\CurrentVersion\Uninstall\Chromium
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
Chrome
Chrome
chrome_child.dll
chrome_child.dll
chrome.dll
chrome.dll
Google Chrome Canary
Google Chrome Canary
Chrome Canary HTML Document
Chrome Canary HTML Document
ChromeSSHTM
ChromeSSHTM
{1BEAC3E3-B852-44F4-B468-8906C062422E}
{1BEAC3E3-B852-44F4-B468-8906C062422E}
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}
ChromeCanary
ChromeCanary
{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}
{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}
Google Chrome binaries
Google Chrome binaries
hXXps://support.google.com/chrome/contact/chromeuninstall3?hl=$1
hXXps://support.google.com/chrome/contact/chromeuninstall3?hl=$1
Google Chrome
Google Chrome
%d.%d.%d
%d.%d.%d
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
ChromeHTML
ChromeHTML
Chrome HTML Document
Chrome HTML Document
{8A69D345-D564-463c-AFF1-A69D9E530F96}
{8A69D345-D564-463c-AFF1-A69D9E530F96}
{5C65F4B0-3651-4514-B207-D10CB699B14B}
{5C65F4B0-3651-4514-B207-D10CB699B14B}
Google Chrome Frame
Google Chrome Frame
Chrome in a Frame.
Chrome in a Frame.
Google\Chrome Frame
Google\Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{8BA986DA-5100-405E-AA35-86F34A02ACBF}
{8BA986DA-5100-405E-AA35-86F34A02ACBF}
WebAccessible
WebAccessible
-chromeframe
-chromeframe
-chrome
-chrome
lSOFTWARE\Policies\Google\Chrome
lSOFTWARE\Policies\Google\Chrome
reports
reports
settings.dat
settings.dat
ALPC Port
ALPC Port
\Sessions\%d\AppContainerNamedObjects\%ls
\Sessions\%d\AppContainerNamedObjects\%ls
sHKEY_LOCAL_MACHINE
sHKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_TEXT
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_NLSTEXT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_DYN_DATA
pipe\
pipe\
tgdi32.dll
tgdi32.dll
xntdll.dll
xntdll.dll
Chrome_MessageWindow
Chrome_MessageWindow
Failed to create directory %ls, last error is %d
Failed to create directory %ls, last error is %d
Chrome SxS\Application
Chrome SxS\Application
winhttp.dll
winhttp.dll
54.0.2840.71
54.0.2840.71
chrome_exe
chrome_exe
chrome.exe_2916_rwx_00060000_00001000:
KERNEL32.DLL
KERNEL32.DLL
chrome.exe_2916_rwx_000A0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
rDos.exe_2852:
.text
.text
0`.data
0`.data
.rdata
.rdata
0@.bss
0@.bss
.idata
.idata
Thanks for using rDos by Rixer! Visit shocksoft.org / liquid-security.net for more great releases!
Thanks for using rDos by Rixer! Visit shocksoft.org / liquid-security.net for more great releases!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Enter port to DDOS (80 by default):
Enter port to DDOS (80 by default):
../../gcc-3.4.5/gcc/config/i386/w32-shared-ptr.c
../../gcc-3.4.5/gcc/config/i386/w32-shared-ptr.c
CvU%DvG
CvU%DvG
GetAsyncKeyState
GetAsyncKeyState
KERNEL32.dll
KERNEL32.dll
msvcrt.dll
msvcrt.dll
USER32.dll
USER32.dll
WS2_32.DLL
WS2_32.DLL
chrome.exe_2916_rwx_00170000_00001000:
KERNEL32.DLL
KERNEL32.DLL
chrome.exe_2916_rwx_002B0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
chrome.exe_2916_rwx_002F0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
conhost.exe_3816:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
GDI32.dll
GDI32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
ntdll.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
KERNEL32.dll
IMM32.dll
IMM32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
Bv.SCv
Bv.SCv
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
Cannot allocate 0n%d bytes
|%SWj
|%SWj
O.fBf;
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
FTPh
\>.Sj
\>.Sj
GetKeyboardLayout
GetKeyboardLayout
MapVirtualKeyW
MapVirtualKeyW
VkKeyScanW
VkKeyScanW
GetKeyboardState
GetKeyboardState
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExW
SetWindowsHookExW
GetKeyState
GetKeyState
ActivateKeyboardLayout
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
GetKeyboardLayoutNameW
_amsg_exit
_amsg_exit
_acmdln
_acmdln
ShipAssert
ShipAssert
NtReplyWaitReceivePort
NtReplyWaitReceivePort
NtCreatePort
NtCreatePort
NtEnumerateValueKey
NtEnumerateValueKey
NtQueryValueKey
NtQueryValueKey
NtOpenKey
NtOpenKey
NtAcceptConnectPort
NtAcceptConnectPort
NtReplyPort
NtReplyPort
SetProcessShutdownParameters
SetProcessShutdownParameters
GetCPInfo
GetCPInfo
conhost.pdb
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%$%a%b%V%U%c%Q%W%]%\%[%
%
%
version="5.1.0.0"
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
name="Microsoft.Windows.ConsoleHost"
name="Microsoft.Windows.ConsoleHost.SystemDefault"
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
:>@>
:>@>
2%2X2
2%2X2
%SystemRoot%
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
WindowSize
ColorTableu
ColorTableu
ExtendedEditkeyCustom
ExtendedEditkeyCustom
ExtendedEditKey
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
\ !:=/.;|&
\ !:=/.;|&
%d/%d
%d/%d
cmd.exe
cmd.exe
desktop.ini
desktop.ini
\console.dll
\console.dll
%d/%d
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
CONHOST.EXE
Windows
Windows
Operating System
Operating System
6.1.7601.17641
6.1.7601.17641
chrome.exe_2916_rwx_00340000_00001000:
KERNEL32.DLL
KERNEL32.DLL
chrome.exe_2916_rwx_00370000_00001000:
advapi32.dll
advapi32.dll
Updeta.exe_1412:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
Portions Copyright (c) 1999,2003 Avenger by NhT
Portions Copyright (c) 1999,2003 Avenger by NhT
####@####
####@####
kernel32.dll
kernel32.dll
VBoxService.exe
VBoxService.exe
SbieDll.dll
SbieDll.dll
dbghelp.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
55274-640-2673064-23950
76487-644-3177037-23510
76487-644-3177037-23510
76487-337-8429955-22614
76487-337-8429955-22614
\\.\Syser
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SyserBoot
\\.\SICE
\\.\SICE
\\.\NTICE
\\.\NTICE
ShellExecuteA
ShellExecuteA
shell32.dll
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
http\shell\open\command
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
PSAPI.dll
PSAPI.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Microsoft\Network\Connections\pbk\rasphone.pbk
Microsoft\Network\Connections\pbk\rasphone.pbk
rasapi32.dll
rasapi32.dll
rnaph.dll
rnaph.dll
RAS Passwords |
RAS Passwords |
uURLHistory
uURLHistory
Password:
Password:
abe2869f-9b47-4cd9-a358-c22904dba7f7
abe2869f-9b47-4cd9-a358-c22904dba7f7
Password
Password
UnitPasswords
UnitPasswords
advapi32.dll
advapi32.dll
WindowsLive:name=*
WindowsLive:name=*
xxxyyyzzz.dat
xxxyyyzzz.dat
\Mozilla Firefox\
\Mozilla Firefox\
mozcrt19.dll
mozcrt19.dll
sqlite3.dll
sqlite3.dll
nspr4.dll
nspr4.dll
plc4.dll
plc4.dll
plds4.dll
plds4.dll
nssutil3.dll
nssutil3.dll
softokn3.dll
softokn3.dll
nss3.dll
nss3.dll
PK11_GetInternalKeySlot
PK11_GetInternalKeySlot
userenv.dll
userenv.dll
\Mozilla\Firefox\
\Mozilla\Firefox\
profiles.ini
profiles.ini
\signons3.txt
\signons3.txt
\signons2.txt
\signons2.txt
\signons1.txt
\signons1.txt
\signons.txt
\signons.txt
(unnamed password)
(unnamed password)
explorer.exe
explorer.exe
_x_X_PASSWORDLIST_X_x_
_x_X_PASSWORDLIST_X_x_
NOIP.abc
NOIP.abc
MSN.abc
MSN.abc
FIREFOX.abc
FIREFOX.abc
IELOGIN.abc
IELOGIN.abc
IEPASS.abc
IEPASS.abc
IEAUTO.abc
IEAUTO.abc
IEWEB.abc
IEWEB.abc
XX--XX--XX.txt
XX--XX--XX.txt
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
GetProcessHeap
GetProcessHeap
user32.dll
user32.dll
oleaut32.dll
oleaut32.dll
RegOpenKeyExA
RegOpenKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
SetWindowsHookExA
SetWindowsHookExA
GetKeyboardState
GetKeyboardState
ole32.dll
ole32.dll
pstorec.dll
pstorec.dll
crypt32.dll
crypt32.dll
8 8$8(8,808
8 8$8(8,808
5_5
5_5
0%0S0X0
0%0S0X0
KWindows
KWindows
KuURLHistory
KuURLHistory
IEpasswords
IEpasswords
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@####
####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
SUdp
SUdp
he.Yq
he.Yq
}n;%U
}n;%U
pr.vI
pr.vI
bUDP
bUDP
%Dtss
%Dtss
}V .IG
}V .IG
.eX8$0
.eX8$0
o%UVKr
o%UVKr
\[.cF
\[.cF
rE|.BA
rE|.BA
xwG%x
xwG%x
@%XX\
@%XX\
'####@####
'####@####
FE.FN
FE.FN
X.hhd@X.
X.hhd@X.
y%d|;
y%d|;
r.LjH
r.LjH
.wy/`
.wy/`
.mNk
.mNk
.wd``l
.wd``l
X.qPpR
X.qPpR
X.eGgk'l
X.eGgk'l
eeÃ’C
eeÃ’C
d.vK'
d.vK'
_%XCtC
_%XCtC
chrome.exe_2916_rwx_003A0000_00001000:
RegOpenKeyA
RegOpenKeyA
chrome.exe_2916_rwx_003B0000_00001000:
advapi32.dll
advapi32.dll
chrome.exe_2916_rwx_004E0000_00001000:
AVICAP32.DLL
AVICAP32.DLL
chrome.exe_2916_rwx_00520000_00001000:
AVICAP32.DLL
AVICAP32.DLL
chrome.exe_2916_rwx_00C30000_00001000:
gdi32.dll
gdi32.dll
chrome.exe_2916_rwx_00C70000_00001000:
gdi32.dll
gdi32.dll
chrome.exe_2916_rwx_00CA0000_00001000:
gdiplus.dll
gdiplus.dll
chrome.exe_2916_rwx_00CE0000_00001000:
gdiplus.dll
gdiplus.dll
chrome.exe_2916_rwx_00F10000_00001000:
mpr.dll
mpr.dll
chrome.exe_2916_rwx_01050000_00001000:
mpr.dll
mpr.dll
chrome.exe_2916_rwx_01080000_00001000:
msacm32.dll
msacm32.dll
chrome.exe_2916_rwx_010C0000_00001000:
msacm32.dll
msacm32.dll
chrome.exe_2916_rwx_010F0000_00001000:
ntdll.dll
ntdll.dll
chrome.exe_2916_rwx_01E20000_00001000:
ntdll.dll
ntdll.dll
chrome.exe_2916_rwx_01E50000_00001000:
ole32.dll
ole32.dll
chrome.exe_2916_rwx_01E90000_00001000:
ole32.dll
ole32.dll
chrome.exe_2916_rwx_01EC0000_00001000:
oleaut32.dll
oleaut32.dll
chrome.exe_2916_rwx_02000000_00001000:
oleaut32.dll
oleaut32.dll
chrome.exe_2916_rwx_02130000_00001000:
powrprof.dll
powrprof.dll
chrome.exe_2916_rwx_02170000_00001000:
powrprof.dll
powrprof.dll
chrome.exe_2916_rwx_022B0000_00001000:
shell32.dll
shell32.dll
chrome.exe_2916_rwx_024F0000_00001000:
shell32.dll
shell32.dll
chrome.exe_2916_rwx_02520000_00001000:
user32.dll
user32.dll
chrome.exe_2916_rwx_02560000_00001000:
user32.dll
user32.dll
chrome.exe_2916_rwx_02590000_00001000:
wininet.dll
wininet.dll
chrome.exe_2916_rwx_027C0000_00001000:
FtpOpenFileA
FtpOpenFileA
chrome.exe_2916_rwx_027D0000_00001000:
wininet.dll
wininet.dll
chrome.exe_2916_rwx_02800000_00001000:
winmm.dll
winmm.dll
chrome.exe_2916_rwx_02840000_00001000:
winmm.dll
winmm.dll
chrome.exe_2916_rwx_02870000_00001000:
wsock32.dll
wsock32.dll
chrome.exe_2916_rwx_028B0000_00001000:
wsock32.dll
wsock32.dll
chrome.exe_2916_rwx_24080000_00062000:
`.rsrc
`.rsrc
/w)f%u/
/w)f%u/
kernel32.dll
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
SHFileOperationA
shell32.dll
shell32.dll
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
ShellExecuteA
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
http\shell\open\command
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
####@####
####@####
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Portugal
Turkey
Turkey
Windows 3.1
Windows 3.1
Windows 95 (Release 2)
Windows 95 (Release 2)
Windows 95
Windows 95
Windows 98 SE
Windows 98 SE
Windows 98
Windows 98
Windows ME
Windows ME
Windows 7
Windows 7
Windows Vista
Windows Vista
%s %s
%s %s
Windows XP Professional x64
Windows XP Professional x64
Windows XP Home
Windows XP Home
Windows XP Professional
Windows XP Professional
Windows 2000 Professional
Windows 2000 Professional
Windows NT %d.%d
Windows NT %d.%d
Windows 2008
Windows 2008
%s %s Server
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server Web Edition
Windows 2003 Server
Windows 2003 Server
Windows Home Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server Web Edition
Windows 2000 Server
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Windows NT 4.0 Server
Unknown Platform ID (%d)
Unknown Platform ID (%d)
%d.%d
%d.%d
%s (Build: %d
%s (Build: %d
- Service Pack: %s
- Service Pack: %s
KERNEL32.DLL
KERNEL32.DLL
teste.vbs
teste.vbs
teste.txt
teste.txt
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
objFile.WriteLine(Info)
objFile.WriteLine(Info)
objFile.Close
objFile.Close
cscript.exe
cscript.exe
AVICAP32.dll
AVICAP32.dll
tFtpAccess
tFtpAccess
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
127.0.0.1
127.0.0.1
iphlpapi.dll
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
SetTcpEntry
GetExtendedTcpTable
GetExtendedTcpTable
GetExtendedUdpTable
GetExtendedUdpTable
Mozilla3_5Password
Mozilla3_5Password
GetChromePass
GetChromePass
StartHttpProxy
StartHttpProxy
1.2.3
1.2.3
XxX.xXx
XxX.xXx
UuU.uUu
UuU.uUu
keyboardkey
keyboardkey
webcaminactive
webcaminactive
webcamgetbuffer
webcamgetbuffer
webcam
webcam
enviarexecnormal
enviarexecnormal
enviarexechidden
enviarexechidden
openweb
openweb
downexec
downexec
sendftp
sendftp
keylogger
keylogger
keyloggergetlog
keyloggergetlog
keyloggereraselog
keyloggereraselog
keyloggerativar
keyloggerativar
keyloggerdesativar
keyloggerdesativar
renamekey
renamekey
windowsfechar
windowsfechar
windowsmax
windowsmax
windowsmin
windowsmin
windowsmostrar
windowsmostrar
windowsocultar
windowsocultar
windowsmintodas
windowsmintodas
windowscaption
windowscaption
listarportas
listarportas
listarportasdns
listarportasdns
finalizarprocessoportas
finalizarprocessoportas
webcamsettings
webcamsettings
chatmsg
chatmsg
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
PSAPI.dll
\config\SteamAppData.vdf
\config\SteamAppData.vdf
AutoLoginUser
AutoLoginUser
/ClientRegistry.Blob
/ClientRegistry.Blob
\ClientRegistry.blob
\ClientRegistry.blob
\steam.dll
\steam.dll
%SYS%
%SYS%
ÞSKTOP%
ÞSKTOP%
FirstExecution
FirstExecution
chatmsg|
chatmsg|
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
listarportas|finalizarprocessoportas|N|
registro|renamekey|
registro|renamekey|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keylogger|keylogger|keyloggervazio|
keyloggersearch
keyloggersearch
keyloggersearchok|
keyloggersearchok|
webcam|webcaminactive|
webcam|webcaminactive|
webcam|webcamactive|
webcam|webcamactive|
getpassword
getpassword
_x_X_PASSWORDLIST_X_x_
_x_X_PASSWORDLIST_X_x_
NOIP.abc
NOIP.abc
MSN.abc
MSN.abc
FIREFOX.abc
FIREFOX.abc
IELOGIN.abc
IELOGIN.abc
IEPASS.abc
IEPASS.abc
IEAUTO.abc
IEAUTO.abc
IEWEB.abc
IEWEB.abc
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox
getfirefox
getfirefox
getielogin
getielogin
getiepass
getiepass
getieweb
getieweb
getchrome
getchrome
getpassword|getpasswordlist|
getpassword|getpasswordlist|
getpassword|getpassworderror|
getpassword|getpassworderror|
updateservidorweb
updateservidorweb
##@@## ##@@## ##@@##
##@@## ##@@## ##@@##
Windows\CurrentVersion\Uninstall\eDonkey2000
Windows\CurrentVersion\Uninstall\eDonkey2000
UNWISE.EXE
UNWISE.EXE
ntdll.dll
ntdll.dll
icon=shell32.dll,4
icon=shell32.dll,4
shellexecute=
shellexecute=
autorun.inf
autorun.inf
XX--XX--XX.txt
XX--XX--XX.txt
logs.dat
logs.dat
SQLite3.dll
SQLite3.dll
$1.2.3
$1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
KWindows
KWindows
UnitExecutarComandos
UnitExecutarComandos
uftp
uftp
UrlMon
UrlMon
.UnitBytesSize
.UnitBytesSize
UnitListarPortasAtivas
UnitListarPortasAtivas
UnitWebcam
UnitWebcam
UnitKeylogger
UnitKeylogger
WinExec
WinExec
SetNamedPipeHandleState
SetNamedPipeHandleState
GetProcessHeap
GetProcessHeap
CreatePipe
CreatePipe
RegOpenKeyExA
RegOpenKeyExA
RegOpenKeyA
RegOpenKeyA
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
GdiplusShutdown
GdiplusShutdown
keybd_event
keybd_event
MapVirtualKeyA
MapVirtualKeyA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyState
GetKeyState
GetAsyncKeyState
GetAsyncKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
FtpGetFileSize
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpSetCurrentDirectoryA
FtpOpenFileA
FtpOpenFileA
%( % & % % % ]
%( % & % % % ]
.idata
.idata
.reloc
.reloc
P.rsrc
P.rsrc
advapi32.dll
advapi32.dll
AVICAP32.DLL
AVICAP32.DLL
gdi32.dll
gdi32.dll
gdiplus.dll
gdiplus.dll
mpr.dll
mpr.dll
msacm32.dll
msacm32.dll
ole32.dll
ole32.dll
oleaut32.dll
oleaut32.dll
powrprof.dll
powrprof.dll
user32.dll
user32.dll
wininet.dll
wininet.dll
winmm.dll
winmm.dll
wsock32.dll
wsock32.dll
Explorer.EXE_2024_rwx_01EE0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_02EE0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_03A10000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_03AE0000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_03C60000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_03D30000_00001000:
KERNEL32.DLL
KERNEL32.DLL
Explorer.EXE_2024_rwx_03F60000_00001000:
advapi32.dll
advapi32.dll
Explorer.EXE_2024_rwx_03F90000_00001000:
RegOpenKeyA
RegOpenKeyA
Explorer.EXE_2024_rwx_04020000_00001000:
advapi32.dll
advapi32.dll
Explorer.EXE_2024_rwx_04090000_00001000:
AVICAP32.DLL
AVICAP32.DLL
Explorer.EXE_2024_rwx_04510000_00001000:
AVICAP32.DLL
AVICAP32.DLL
Explorer.EXE_2024_rwx_045F0000_00001000:
gdi32.dll
gdi32.dll
Explorer.EXE_2024_rwx_04670000_00001000:
gdi32.dll
gdi32.dll
Explorer.EXE_2024_rwx_046A0000_00001000:
gdiplus.dll
gdiplus.dll
Explorer.EXE_2024_rwx_04730000_00001000:
gdiplus.dll
gdiplus.dll
Explorer.EXE_2024_rwx_047E0000_00001000:
mpr.dll
mpr.dll
Explorer.EXE_2024_rwx_04820000_00001000:
mpr.dll
mpr.dll
Explorer.EXE_2024_rwx_04910000_00001000:
msacm32.dll
msacm32.dll
Explorer.EXE_2024_rwx_049D0000_00001000:
msacm32.dll
msacm32.dll
Explorer.EXE_2024_rwx_04A00000_00001000:
ntdll.dll
ntdll.dll
Explorer.EXE_2024_rwx_06860000_00001000:
ntdll.dll
ntdll.dll
Explorer.EXE_2024_rwx_068D0000_00001000:
ole32.dll
ole32.dll
Explorer.EXE_2024_rwx_06910000_00001000:
ole32.dll
ole32.dll
Explorer.EXE_2024_rwx_069C0000_00001000:
oleaut32.dll
oleaut32.dll
Explorer.EXE_2024_rwx_06A00000_00001000:
oleaut32.dll
oleaut32.dll
Explorer.EXE_2024_rwx_06A30000_00001000:
powrprof.dll
powrprof.dll
Explorer.EXE_2024_rwx_06A70000_00001000:
powrprof.dll
powrprof.dll
Explorer.EXE_2024_rwx_06B60000_00001000:
shell32.dll
shell32.dll
Explorer.EXE_2024_rwx_06BA0000_00001000:
shell32.dll
shell32.dll
Explorer.EXE_2024_rwx_06C10000_00001000:
user32.dll
user32.dll
Explorer.EXE_2024_rwx_06C50000_00001000:
user32.dll
user32.dll
Explorer.EXE_2024_rwx_06D80000_00001000:
wininet.dll
wininet.dll
Explorer.EXE_2024_rwx_06DB0000_00001000:
FtpOpenFileA
FtpOpenFileA
Explorer.EXE_2024_rwx_06E00000_00001000:
wininet.dll
wininet.dll
Explorer.EXE_2024_rwx_06E30000_00001000:
winmm.dll
winmm.dll
Explorer.EXE_2024_rwx_06E70000_00001000:
winmm.dll
winmm.dll
Explorer.EXE_2024_rwx_06F20000_00001000:
wsock32.dll
wsock32.dll
Explorer.EXE_2024_rwx_06F60000_00001000:
wsock32.dll
wsock32.dll
Explorer.EXE_2024_rwx_24010000_00062000:
`.rsrc
`.rsrc
/w)f%u/
/w)f%u/
kernel32.dll
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
SHFileOperationA
shell32.dll
shell32.dll
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
ShellExecuteA
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
http\shell\open\command
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
####@####
####@####
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Portugal
Turkey
Turkey
Windows 3.1
Windows 3.1
Windows 95 (Release 2)
Windows 95 (Release 2)
Windows 95
Windows 95
Windows 98 SE
Windows 98 SE
Windows 98
Windows 98
Windows ME
Windows ME
Windows 7
Windows 7
Windows Vista
Windows Vista
%s %s
%s %s
Windows XP Professional x64
Windows XP Professional x64
Windows XP Home
Windows XP Home
Windows XP Professional
Windows XP Professional
Windows 2000 Professional
Windows 2000 Professional
Windows NT %d.%d
Windows NT %d.%d
Windows 2008
Windows 2008
%s %s Server
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server Web Edition
Windows 2003 Server
Windows 2003 Server
Windows Home Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server Web Edition
Windows 2000 Server
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Windows NT 4.0 Server
Unknown Platform ID (%d)
Unknown Platform ID (%d)
%d.%d
%d.%d
%s (Build: %d
%s (Build: %d
- Service Pack: %s
- Service Pack: %s
KERNEL32.DLL
KERNEL32.DLL
teste.vbs
teste.vbs
teste.txt
teste.txt
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
objFile.WriteLine(Info)
objFile.WriteLine(Info)
objFile.Close
objFile.Close
cscript.exe
cscript.exe
AVICAP32.dll
AVICAP32.dll
tFtpAccess
tFtpAccess
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
127.0.0.1
127.0.0.1
iphlpapi.dll
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
SetTcpEntry
GetExtendedTcpTable
GetExtendedTcpTable
GetExtendedUdpTable
GetExtendedUdpTable
Mozilla3_5Password
Mozilla3_5Password
GetChromePass
GetChromePass
StartHttpProxy
StartHttpProxy
1.2.3
1.2.3
XxX.xXx
XxX.xXx
UuU.uUu
UuU.uUu
keyboardkey
keyboardkey
webcaminactive
webcaminactive
webcamgetbuffer
webcamgetbuffer
webcam
webcam
enviarexecnormal
enviarexecnormal
enviarexechidden
enviarexechidden
openweb
openweb
downexec
downexec
sendftp
sendftp
keylogger
keylogger
keyloggergetlog
keyloggergetlog
keyloggereraselog
keyloggereraselog
keyloggerativar
keyloggerativar
keyloggerdesativar
keyloggerdesativar
renamekey
renamekey
windowsfechar
windowsfechar
windowsmax
windowsmax
windowsmin
windowsmin
windowsmostrar
windowsmostrar
windowsocultar
windowsocultar
windowsmintodas
windowsmintodas
windowscaption
windowscaption
listarportas
listarportas
listarportasdns
listarportasdns
finalizarprocessoportas
finalizarprocessoportas
webcamsettings
webcamsettings
chatmsg
chatmsg
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
PSAPI.dll
\config\SteamAppData.vdf
\config\SteamAppData.vdf
AutoLoginUser
AutoLoginUser
/ClientRegistry.Blob
/ClientRegistry.Blob
\ClientRegistry.blob
\ClientRegistry.blob
\steam.dll
\steam.dll
%SYS%
%SYS%
ÞSKTOP%
ÞSKTOP%
FirstExecution
FirstExecution
chatmsg|
chatmsg|
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
listarportas|finalizarprocessoportas|N|
registro|renamekey|
registro|renamekey|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keylogger|keylogger|keyloggervazio|
keyloggersearch
keyloggersearch
keyloggersearchok|
keyloggersearchok|
webcam|webcaminactive|
webcam|webcaminactive|
webcam|webcamactive|
webcam|webcamactive|
getpassword
getpassword
_x_X_PASSWORDLIST_X_x_
_x_X_PASSWORDLIST_X_x_
NOIP.abc
NOIP.abc
MSN.abc
MSN.abc
FIREFOX.abc
FIREFOX.abc
IELOGIN.abc
IELOGIN.abc
IEPASS.abc
IEPASS.abc
IEAUTO.abc
IEAUTO.abc
IEWEB.abc
IEWEB.abc
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox
getfirefox
getfirefox
getielogin
getielogin
getiepass
getiepass
getieweb
getieweb
getchrome
getchrome
getpassword|getpasswordlist|
getpassword|getpasswordlist|
getpassword|getpassworderror|
getpassword|getpassworderror|
updateservidorweb
updateservidorweb
##@@## ##@@## ##@@##
##@@## ##@@## ##@@##
Windows\CurrentVersion\Uninstall\eDonkey2000
Windows\CurrentVersion\Uninstall\eDonkey2000
UNWISE.EXE
UNWISE.EXE
ntdll.dll
ntdll.dll
icon=shell32.dll,4
icon=shell32.dll,4
shellexecute=
shellexecute=
autorun.inf
autorun.inf
XX--XX--XX.txt
XX--XX--XX.txt
logs.dat
logs.dat
SQLite3.dll
SQLite3.dll
$1.2.3
$1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
KWindows
KWindows
UnitExecutarComandos
UnitExecutarComandos
uftp
uftp
UrlMon
UrlMon
.UnitBytesSize
.UnitBytesSize
UnitListarPortasAtivas
UnitListarPortasAtivas
UnitWebcam
UnitWebcam
UnitKeylogger
UnitKeylogger
WinExec
WinExec
SetNamedPipeHandleState
SetNamedPipeHandleState
GetProcessHeap
GetProcessHeap
CreatePipe
CreatePipe
RegOpenKeyExA
RegOpenKeyExA
RegOpenKeyA
RegOpenKeyA
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
GdiplusShutdown
GdiplusShutdown
keybd_event
keybd_event
MapVirtualKeyA
MapVirtualKeyA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyState
GetKeyState
GetAsyncKeyState
GetAsyncKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
FtpGetFileSize
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpSetCurrentDirectoryA
FtpOpenFileA
FtpOpenFileA
%( % & % % % ]
%( % & % % % ]
.idata
.idata
.reloc
.reloc
P.rsrc
P.rsrc
advapi32.dll
advapi32.dll
AVICAP32.DLL
AVICAP32.DLL
gdi32.dll
gdi32.dll
gdiplus.dll
gdiplus.dll
mpr.dll
mpr.dll
msacm32.dll
msacm32.dll
ole32.dll
ole32.dll
oleaut32.dll
oleaut32.dll
powrprof.dll
powrprof.dll
user32.dll
user32.dll
wininet.dll
wininet.dll
winmm.dll
winmm.dll
wsock32.dll
wsock32.dll