not-a-virus:HEUR:Monitor.Win32.SpectorPro.heur (Kaspersky), Application.Keylogger.Spector.B (AdAware), Trojan.Win32.Swrort.3.FD, GenericEmailWorm.YR (Lavasoft MAS)Behaviour: Keylogger, Trojan, Worm, EmailWorm, Monitor
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 03c6dfc07d2e9379a611c8a59e69019f
SHA1: 1165ae1c1f19f0e1291e85c963b5d11cc619da0f
SHA256: c84b8c4b76892018be5e9b544b4a6ff3e11043da2691d378f5704d4e83ccac13
SSDeep: 196608:ol9bX21jVc R 6gFBv4OD9KCWtAnuTEqmi8qt3z4:G9bmM1 tFVIF6nuTEqZdZz
Size: 10713752 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2012-02-16 23:46:51
Analyzed on: Windows7 SP1 32-bit
Summary: Keylogger. Tracking software that records keyboard and/or mouse activity. Keyloggers typically either store the recorded keystrokes for later retrieval or they transmit them to the remote process or person employing the keylogger. While there are some legitimate uses of keyloggers, but they are often used maliciously by attackers to surreptitiously track behavior to perform unwanted or unauthorized actions included but not limited to identity theft.
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The Application creates the following process(es):
sgvrfy32.exe:3776
%original file name%.exe:3400
runonce.exe:848
The Application injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:3400 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Windows\System32\cmpipsvr32.dll (5156 bytes)
C:\Windows\System32\winipdat\winipdll\svrltwp.dll (436 bytes)
C:\Windows\System32\vdorctrl.dll (990 bytes)
C:\Windows\System32\svrltmgr.dll (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUUF6EB.tmp (89 bytes)
C:\Windows\System32\drivers\vdorctrl.sys (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU7E.tmp (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSVxRsc.dll (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU8E.tmp (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_msfile75B0C260.inf (1 bytes)
C:\Windows\System32\cmproxfr.dll (274 bytes)
C:\Windows\System32\sgvrfy32.exe (1389 bytes)
The Application deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU7E.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_msfile75B0C260.inf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUUF6EB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSVxRsc.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU8E.tmp (0 bytes)
The process runonce.exe:848 makes changes in the file system.
The Application creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl (712 bytes)
Registry activity
The process sgvrfy32.exe:3776 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSVxRsc.dll, , \??\C:\Windows\system32\msocxusys.dll, , \??\c:\windows\system32\sgvrfy32.log,"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\System Event Dispatcher]
"TypesSupported" = "7"
"ParameterMessageFile" = "C:\Windows\system32\sgvrfy32.exe"
"EventMessageFile" = "C:\Windows\system32\sgvrfy32.exe"
[HKLM\System\CurrentControlSet\Services\System Event Dispatcher]
"Description" = "Dispatches system events, such as Windows logons, user inactivity, and shutdown notifications."
The process %original file name%.exe:3400 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.app.log" = "4096"
[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Ddekuweb]
"FriendlyName" = "Hexofvga"
[HKLM\System\CurrentControlSet\services\vdorctrl]
"DebugFlags" = "0"
[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Ddekuweb]
"LoadBehavior" = "3"
[HKCR\CLSID\{097CB2DB-6F65-4759-BEB8-214F26C19A6F}]
"(Default)" = "Hexofvga"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSVxRsc.dll,"
[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Ddekuweb]
"FileName" = "C:\Windows\system32\svrltmgr.dll"
[HKCR\Ddekuweb\CLSID]
"(Default)" = "{097CB2DB-6F65-4759-BEB8-214F26C19A6F}"
[HKCR\CLSID\{097CB2DB-6F65-4759-BEB8-214F26C19A6F}\InprocServer32]
"(Default)" = "C:\Windows\system32\svrltmgr.dll"
"ThreadingModel" = "Apartment"
[HKCR\CLSID\{F105F8A8-9D47-4942-B13B-DAC8DF268396}\InprocServer32]
"(Default)" = "C:\Windows\system32\wzodlg32.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "100"
[HKCR\Ddekuweb]
"(Default)" = "Hexofvga"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCR\CLSID\{097CB2DB-6F65-4759-BEB8-214F26C19A6F}\ProgID]
"(Default)" = "Ddekuweb"
[HKLM\System\CurrentControlSet\services\vdorctrl]
"Start" = "0"
[HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\Ddekuweb]
"CommandLineSafe" = "1"
[HKLM\System\CurrentControlSet\services\vdorctrl]
"Flags" = "1"
To automatically run itself each time Windows is booted, the Application adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv" = "grpconv -o"
The Application deletes the following registry key(s):
[HKCR\CLSID\{Cb8DE863-0561-4ffd-9B86-5BA2E941BA52}]
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FE2DB5FF-5ECF-11D2-B28F-0080C8383C7B}"
[HKLM\System\CurrentControlSet\services\vdorctrl]
"AltShell1"
"AltShell0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{FE2DB5FF-5ECF-11D2-B28F-0080C8383C7B}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"
[HKLM\System\CurrentControlSet\services\vdorctrl]
"AltShell"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebExtLocation"
"(Default)"
The Application disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCheckStub"
The process runonce.exe:848 makes changes in the system registry.
The Application creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Application deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The Application disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"
Dropped PE files
MD5 | File path |
---|---|
d9e6927d2b6e0e5240d27ad1970fff30 | c:\Windows\System32\cmproxfr.dll |
3f9c529240fc93cdf79bbc2a42415032 | c:\Windows\System32\drivers\vdorctrl.sys |
9584166043527ba7c1d56d5bcf628a2b | c:\Windows\System32\sgvrfy32.exe |
6bd27b655ee4a15974b3f297c3f8fdd9 | c:\Windows\System32\svrltmgr.dll |
485191fc17d885b5f14b1a6532095258 | c:\Windows\System32\vdorctrl.dll |
3ac08ef00db4501da1c8f01d31693cee | c:\Windows\System32\winipdat\winipdll\svrltwp.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
sgvrfy32.exe:3776
%original file name%.exe:3400
runonce.exe:848 - Delete the original Application file.
- Delete or disinfect the following files created/modified by the Application:
C:\Windows\System32\cmpipsvr32.dll (5156 bytes)
C:\Windows\System32\winipdat\winipdll\svrltwp.dll (436 bytes)
C:\Windows\System32\vdorctrl.dll (990 bytes)
C:\Windows\System32\svrltmgr.dll (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUUF6EB.tmp (89 bytes)
C:\Windows\System32\drivers\vdorctrl.sys (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU7E.tmp (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSVxRsc.dll (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\UUU8E.tmp (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_msfile75B0C260.inf (1 bytes)
C:\Windows\System32\cmproxfr.dll (274 bytes)
C:\Windows\System32\sgvrfy32.exe (1389 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl (712 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv" = "grpconv -o"
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 891952 | 892416 | 4.45937 | e1f6d19cf282673fea3d4dd017f167a2 |
.rdata | 897024 | 371585 | 371712 | 2.71644 | 93f436d5a44651c608ea4267cd7bb7b9 |
.data | 1269760 | 36644 | 13824 | 2.48418 | 1112338cfd8b88d9c782330622771b2b |
.rsrc | 1306624 | 9231564 | 9231872 | 5.41241 | 60f4b3570950abab4b158ae8fc12d77d |
.reloc | 10539008 | 107154 | 107520 | 3.34057 | 748af50f2b896a1b89e765298a9256d2 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 2
1b40d27c77f66d87f5f41801fbcaeab8
dd4caa50b80a4634708475c6c0332d5f
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Application connects to the servers at the folowing location(s):
Strings from Dumps
sgvrfy32.exe_3796:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
SSh4\8
SSh4\8
SSh`b8
SSh`b8
SSh,m8
SSh,m8
SSh o8
SSh o8
SShpn8
SShpn8
SSh(p8
SSh(p8
SShts8
SShts8
X@SSh
X@SSh
SSh\^8
SSh\^8
SSh
SSh
tcPh
tcPh
SSh\L:
SSh\L:
SSh|L:
SSh|L:
SSh,Y:
SSh,Y:
SSh$Z:
SSh$Z:
SSh8Z:
SSh8Z:
SShLZ:
SShLZ:
SShdZ:
SShdZ:
QA1Q0ZWQIE_%d
QA1Q0ZWQIE_%d
kernel32.dll
kernel32.dll
sys.dll
sys.dll
0x%p,%d,%d
0x%p,%d,%d
CryptGetKeyParam
CryptGetKeyParam
CryptImportKey
CryptImportKey
CryptExportKey
CryptExportKey
CryptDeriveKey
CryptDeriveKey
CryptGetUserKey
CryptGetUserKey
CryptDestroyKey
CryptDestroyKey
CryptGenKey
CryptGenKey
ADVAPI32.dll
ADVAPI32.dll
CRYPT32.dll
CRYPT32.dll
::AquireKeyContainer
::AquireKeyContainer
0x%p,%d,%d,%d
0x%p,%d,%d,%d
%d,%d,%d
%d,%d,%d
0x%x,0x%p,%d,0x%p,0x%p,%d
0x%x,0x%p,%d,0x%p,0x%p,%d
0x%p,0x%p,%d
0x%p,0x%p,%d
0x%p,%d
0x%p,%d
::ResetKeyBlob
::ResetKeyBlob
::IsKeySpecValid
::IsKeySpecValid
::DeriveSessionKey
::DeriveSessionKey
0x%p,%d,0x%p,%d,%d,%d
0x%p,%d,0x%p,%d,%d,%d
Error encrypting data getting data size (0x%x) (%x)
Error encrypting data getting data size (0x%x) (%x)
Error encrypting data while encrypting (0x%x) (%x) (%d,%d,%d)
Error encrypting data while encrypting (0x%x) (%x) (%d,%d,%d)
Data encrypted successfully (%d, %d, %d)
Data encrypted successfully (%d, %d, %d)
Error decrypting data while decrypting (0x%x) (%x) (%d,%d,%d)
Error decrypting data while decrypting (0x%x) (%x) (%d,%d,%d)
Data decrypted successfully (%d, %d, %d)
Data decrypted successfully (%d, %d, %d)
GetSetupFileContent '%s' (0x%p,%d) (%d)
GetSetupFileContent '%s' (0x%p,%d) (%d)
ProcessGetIPAddress (%d,%d) '%s - %s'
ProcessGetIPAddress (%d,%d) '%s - %s'
%d.%d.%d.%d
%d.%d.%d.%d
GetLogFileContent '%s' (0x%p,%d) (%d)
GetLogFileContent '%s' (0x%p,%d) (%d)
CheckSettingsImport1
CheckSettingsImport1
CheckSettingsImport
CheckSettingsImport
msnwcfg.ini
msnwcfg.ini
0x%p, %d, 0x%p, %d
0x%p, %d, 0x%p, %d
EnumKeys
EnumKeys
ProcessGetSetupFileIni (%d,%d)
ProcessGetSetupFileIni (%d,%d)
ProcessGetLogFile (%d,%d)
ProcessGetLogFile (%d,%d)
0x%p, %d, 0x%p
0x%p, %d, 0x%p
CommHost: Received RemoteCommand (%d) from computer %s SN %s MachineID %s
CommHost: Received RemoteCommand (%d) from computer %s SN %s MachineID %s
Failed to load communications library (%s).
Failed to load communications library (%s).
Failed to load server object: %s
Failed to load server object: %s
Started listening on port %d (%d).
Started listening on port %d (%d).
%d-%X
%d-%X
spddd
spddd
Get-Crypt-Keys
Get-Crypt-Keys
DecompressData: Memory Sanity Check Failed, file %s
DecompressData: Memory Sanity Check Failed, file %s
wsock32.dll
wsock32.dll
Unable to recover from corrupt file %s !
Unable to recover from corrupt file %s !
Corrupt file (%s, type %d) accessed for write access. Resetting.
Corrupt file (%s, type %d) accessed for write access. Resetting.
CreateFileNewPassword2
CreateFileNewPassword2
CreateFileNewPassword
CreateFileNewPassword
-%d.%s
-%d.%s
Checking Pushed Data ended, total time: %d msecs
Checking Pushed Data ended, total time: %d msecs
AddKeystrokesToList
AddKeystrokesToList
ProcessKeystrokeFile1
ProcessKeystrokeFile1
ProcessKeystrokeFile
ProcessKeystrokeFile
CheckUrlCategory
CheckUrlCategory
SendDataRecord: Returned no URL page category for (%s).
SendDataRecord: Returned no URL page category for (%s).
SendDataRecord: Returned URL page category: %d for (%s).
SendDataRecord: Returned URL page category: %d for (%s).
InitClient: Unable to load CommDLL (%s)
InitClient: Unable to load CommDLL (%s)
InitWFSClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitWFSClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitClient: Unable to create client object: %s
InitClient: Unable to create client object: %s
InitClient: Attempting to connect via IP address (%s, %d).
InitClient: Attempting to connect via IP address (%s, %d).
InitClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitClient Comm Path %s
InitClient Comm Path %s
DataPush::ProcessDisplayFile CreateFileNewPassword (%s,%s) failed!!!
DataPush::ProcessDisplayFile CreateFileNewPassword (%s,%s) failed!!!
DataPush::ProcessDisplayFile SendFile (%s,%s) failed!!!
DataPush::ProcessDisplayFile SendFile (%s,%s) failed!!!
DataPush::ProcessDisplayFile End, '%s'
DataPush::ProcessDisplayFile End, '%s'
Unable to delete file (%s) : %s
Unable to delete file (%s) : %s
snapshotXX.%s
snapshotXX.%s
PushData: Failed to send all users to server - sent %d/%d records.
PushData: Failed to send all users to server - sent %d/%d records.
PushData: Unable to open User data file %s - error %d !!!
PushData: Unable to open User data file %s - error %d !!!
ProcessDF: Could not find any transactions for transmission (%s, %d, %d).
ProcessDF: Could not find any transactions for transmission (%s, %d, %d).
ProcessDF: Failed to send record to server (%s)
ProcessDF: Failed to send record to server (%s)
PushData: Failed to initialize client communications (Port %d on %s).
PushData: Failed to initialize client communications (Port %d on %s).
PushData: Session complete. Sent %d data transactions, %d snapshot files.
PushData: Session complete. Sent %d data transactions, %d snapshot files.
d-%x.sdf
d-%x.sdf
PushData: Pushing, maximum %d seconds.
PushData: Pushing, maximum %d seconds.
%*.*f
%*.*f
%s:u,%s,%s,%p,%p,%s,%s,(%s),%s
%s:u,%s,%s,%p,%p,%s,%s,(%s),%s
%m/%d/%Y %H:%M:%S
%m/%d/%Y %H:%M:%S
OutMsgThread
OutMsgThread
OutMsg
OutMsg
%s_%s
%s_%s
Global\%s
Global\%s
InitPushClient: CCS Host Initialize Success '%s' in %d secs on Port: %d (%d)
InitPushClient: CCS Host Initialize Success '%s' in %d secs on Port: %d (%d)
InitPushClient: CCS Host Initialize Failed '%s' in %d secs (WSAErr: %d) (%d)!!!
InitPushClient: CCS Host Initialize Failed '%s' in %d secs (WSAErr: %d) (%d)!!!
InitPushClient: CCS Host resolve '%s' (%d) %d.%d.%d.%d
InitPushClient: CCS Host resolve '%s' (%d) %d.%d.%d.%d
InitPushClient: CCS Host gethostbyname Failed '%s' (WSAErr: %d)!!!
InitPushClient: CCS Host gethostbyname Failed '%s' (WSAErr: %d)!!!
InitPushClient: Initializing UDP client to '%s' on Port: %d AltIP:(%d) '%s'
InitPushClient: Initializing UDP client to '%s' on Port: %d AltIP:(%d) '%s'
RunSetupExe
RunSetupExe
RunSetupExe End (%d)
RunSetupExe End (%d)
RunSetupExe Start '%s' '%s'
RunSetupExe Start '%s' '%s'
ExecUninstallThread End '%s'
ExecUninstallThread End '%s'
portCap
portCap
webinetipxp
webinetipxp
webinetprg
webinetprg
webemap
webemap
webinetcheck
webinetcheck
webinetipx
webinetipx
GetClientInfo '%s' (%d,%d,%d,%d,%d) ( %s )
GetClientInfo '%s' (%d,%d,%d,%d,%d) ( %s )
GetRecordState '%s' (%d-%d-%d,%d,%d,%d,%d,%d,%d,%d,%d,%d)
GetRecordState '%s' (%d-%d-%d,%d,%d,%d,%d,%d,%d,%d,%d,%d)
GetClientOSInfo '%s' (%d) '%s' '%s' '%s'
GetClientOSInfo '%s' (%d) '%s' '%s' '%s'
%s\%s\%s
%s\%s\%s
Windows NT
Windows NT
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
%d,0x%p
%d,0x%p
InitCommClient: Unable to load CommDLL (%s)
InitCommClient: Unable to load CommDLL (%s)
InitCommClient: Unable to create client object: %s
InitCommClient: Unable to create client object: %s
InitCommClient: Attempting to connect via IP address (%s, %d).
InitCommClient: Attempting to connect via IP address (%s, %d).
InitCommClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitCommClient: Connect failed (%s, %d, %s, %s) (%s, %s, %s, %s).
InitCommClient: Initializing TCP client using '%s'
InitCommClient: Initializing TCP client using '%s'
PushOSInfo: Pushing info to server end '%s\%s' (%d,0x%p) (%d) (0x%p)
PushOSInfo: Pushing info to server end '%s\%s' (%d,0x%p) (%d) (0x%p)
PushOSInfo: Pushing info to server start (%d,%d,%d)
PushOSInfo: Pushing info to server start (%d,%d,%d)
ExecUpdateThread End '%s' - (%d,%d,%d)
ExecUpdateThread End '%s' - (%d,%d,%d)
ExecInstallThread End '%s' - (%d,%d,%d,%d) (%d,%d)
ExecInstallThread End '%s' - (%d,%d,%d,%d) (%d,%d)
spsetup.exe
spsetup.exe
ExecUninstallRequest Abort '%s'
ExecUninstallRequest Abort '%s'
ExecUpdateRequest Abort '%s'
ExecUpdateRequest Abort '%s'
ExecInstallRequest Abort '%s'
ExecInstallRequest Abort '%s'
ExecUpdateSyncThread End '%s' - (%d,%d)
ExecUpdateSyncThread End '%s' - (%d,%d)
%s#%s
%s#%s
PushRecordInfo: Pushing info to server end S(%d,%d) R(%d,%d,%d) (%d,%d,%d,%d,%d,%d)
PushRecordInfo: Pushing info to server end S(%d,%d) R(%d,%d,%d) (%d,%d,%d,%d,%d,%d)
PushRecordInfo: Pushing info to server check S(%d,%d,%d,%d,%d) R(%d,%d,%d,%d,%d)
PushRecordInfo: Pushing info to server check S(%d,%d,%d,%d,%d) R(%d,%d,%d,%d,%d)
PushRecordInfo: Pushing info to server message out of sync flush (%d, %d, %d, %d)
PushRecordInfo: Pushing info to server message out of sync flush (%d, %d, %d, %d)
PushRecordInfo: Pushing info to server start (%d,%d,%d)
PushRecordInfo: Pushing info to server start (%d,%d,%d)
InfoPush: Initializing info push thread (%d)
InfoPush: Initializing info push thread (%d)
Kernel32.dll
Kernel32.dll
CKeywordDBLists::Init
CKeywordDBLists::Init
Recorder::getKeywordsFromDB
Recorder::getKeywordsFromDB
CKeywordLists::getListUserFromDB
CKeywordLists::getListUserFromDB
(KWS) getListUserFromDB: number of list:%d
(KWS) getListUserFromDB: number of list:%d
(KWS) getListUserFromDB: Adding list:%d
(KWS) getListUserFromDB: Adding list:%d
CKeywordLists::DisplayCacheListsInfo
CKeywordLists::DisplayCacheListsInfo
(KWS) DisplayCacheListsInfo: List:%s ID:%d Version:%d
(KWS) DisplayCacheListsInfo: List:%s ID:%d Version:%d
CKeywordLists::CacheKWList
CKeywordLists::CacheKWList
(KWS)CacheKWList: %s
(KWS)CacheKWList: %s
CKeywordLists::deleteCachedKWList
CKeywordLists::deleteCachedKWList
CKeywordLists::AddNewListFromDB
CKeywordLists::AddNewListFromDB
(KWS)AddCachedListFromDB: Update Keyword list:%s,ID:%d, Version:%d
(KWS)AddCachedListFromDB: Update Keyword list:%s,ID:%d, Version:%d
(KWS) AddCachedListFromDB: Adding list:%s
(KWS) AddCachedListFromDB: Adding list:%s
(KWS)cacheKeywords:Done
(KWS)cacheKeywords:Done
Recorder::cacheKeywords
Recorder::cacheKeywords
(KWS)cacheKeywords: SetKWListNames failed!
(KWS)cacheKeywords: SetKWListNames failed!
(KWS)cacheKeywords: Update Keyword version list
(KWS)cacheKeywords: Update Keyword version list
(KWS) cacheKeywords: Adding list:%s
(KWS) cacheKeywords: Adding list:%s
(KWS)cacheKeywords: Adding list:%s
(KWS)cacheKeywords: Adding list:%s
(KWS) cacheKeywords: list:%s version difference %d :%d
(KWS) cacheKeywords: list:%s version difference %d :%d
(KWS) cacheKeywords: Removing list:%s No longer in DB!
(KWS) cacheKeywords: Removing list:%s No longer in DB!
(KWS) cacheKeywords: Checking list: %s
(KWS) cacheKeywords: Checking list: %s
(KWS) cacheKeywords: Checking %d lists
(KWS) cacheKeywords: Checking %d lists
(KWS) cacheKeywords: Unable to get lists from DB
(KWS) cacheKeywords: Unable to get lists from DB
CKeywordLists
CKeywordLists
CKeywordLists::MakeKeywordInfo
CKeywordLists::MakeKeywordInfo
CKeywordLists::FindKWListInUserList
CKeywordLists::FindKWListInUserList
KeywordMgr
KeywordMgr
KeywordMgrThread deleting objs
KeywordMgrThread deleting objs
KeywordMgrThread
KeywordMgrThread
(KWS) Caching Keywords complete!!!
(KWS) Caching Keywords complete!!!
(KWS) Checking current list :%d with user list:%d
(KWS) Checking current list :%d with user list:%d
(KWS) Reload CurrUser:count:%d != User:count:%d
(KWS) Reload CurrUser:count:%d != User:count:%d
(KWS) Request recieved from :%s
(KWS) Request recieved from :%s
(KWS) Request recieved size %d
(KWS) Request recieved size %d
(KWS) GetLastError error result:%d
(KWS) GetLastError error result:%d
(KWS) GetOverlappedResult bytes returned:%d
(KWS) GetOverlappedResult bytes returned:%d
(KWS) Keyword server waiting...
(KWS) Keyword server waiting...
(KWS) Unable to create named pipe: %s
(KWS) Unable to create named pipe: %s
\\.\PIPE\kwordlist
\\.\PIPE\kwordlist
(KWS) Unable to create KeywordList Object
(KWS) Unable to create KeywordList Object
KeywordMgr::Initialize: Unable to create keyword loader event
KeywordMgr::Initialize: Unable to create keyword loader event
(KWS) KeywordMgr::Initialize: Thread Started...
(KWS) KeywordMgr::Initialize: Thread Started...
Global\SPxKeywordLoadNoChange
Global\SPxKeywordLoadNoChange
Global\SPxKeywordLoadComplete
Global\SPxKeywordLoadComplete
KeywordMgr: Starting
KeywordMgr: Starting
KeywordListNames
KeywordListNames
KeywordUserLists
KeywordUserLists
KeywordList
KeywordList
ERROR GetList: Keyword List:%s size:%d
ERROR GetList: Keyword List:%s size:%d
ERROR GetList: Keyword List:%s ReadValue failed
ERROR GetList: Keyword List:%s ReadValue failed
GetList: Keyword List:%s Section:%s size:%d
GetList: Keyword List:%s Section:%s size:%d
GetList: Keyword List:%s Section:%s failed, no lists!
GetList: Keyword List:%s Section:%s failed, no lists!
0x%x,%d,0x%x,0x%x
0x%x,%d,0x%x,0x%x
GetLicenseResponse returned a license handle, 0x%X
GetLicenseResponse returned a license handle, 0x%X
GetLicenseResponse returned a remote error status(0x%X): %s !!!
GetLicenseResponse returned a remote error status(0x%X): %s !!!
WebMailRevLevel
WebMailRevLevel
Connect - Unable to load CommDll library, %s
Connect - Unable to load CommDll library, %s
Connect - Unable to load client object: %s !
Connect - Unable to load client object: %s !
Connect to LicenseManager - Attempting to connect via IP address (%s, %d).
Connect to LicenseManager - Attempting to connect via IP address (%s, %d).
RequestLicense - Invalid response packet size, %u
RequestLicense - Invalid response packet size, %u
%s %d
%s %d
% 03dd
% 03dd
ddd d:d:d%s M m m .10s %-8.8s %-4.4s %-12.12s %-12.12s %-7.7s =>
ddd d:d:d%s M m m .10s %-8.8s %-4.4s %-12.12s %-12.12s %-7.7s =>
default.log
default.log
X:
X:
Advapi32.dll
Advapi32.dll
%s_%d
%s_%d
0x%p,0x%p,%d,0x%p,%d,0x%p
0x%p,0x%p,%d,0x%p,%d,0x%p
Uninstall service name (%s) on (%s)
Uninstall service name (%s) on (%s)
Uninstalling service...service only
Uninstalling service...service only
Client Service Name (%s)
Client Service Name (%s)
Client Service Path (%s)
Client Service Path (%s)
%SystemRoot%\System32\
%SystemRoot%\System32\
Client Install Machine Name (%s)
Client Install Machine Name (%s)
Start of Client Service code (%s)
Start of Client Service code (%s)
msocxushell2.dll
msocxushell2.dll
%s -sa
%s -sa
Manual Start Service pending local (%d)
Manual Start Service pending local (%d)
Stop service '%s' on '%s' (%d)
Stop service '%s' on '%s' (%d)
Service %sstopped '%s' on '%s'
Service %sstopped '%s' on '%s'
Unable to QueryServiceStatus on '%S' err=%d
Unable to QueryServiceStatus on '%S' err=%d
Unexpected service state %d after STOP command
Unexpected service state %d after STOP command
Unable to send STOP command to '%S', err=%d
Unable to send STOP command to '%S', err=%d
Unable to open handle to '%S', err=%d
Unable to open handle to '%S', err=%d
Unable to open SCM stopping '%S', err=%d
Unable to open SCM stopping '%S', err=%d
StopService: %S
StopService: %S
StopEXE
StopEXE
Failed to Stop EXE service (%d)
Failed to Stop EXE service (%d)
Service EXE Stopped (%d)
Service EXE Stopped (%d)
SendMsgService
SendMsgService
Failed to send service control message: %d (%d) to '%s'
Failed to send service control message: %d (%d) to '%s'
Service control messsage sent: %d to '%s'
Service control messsage sent: %d to '%s'
%s -r%d
%s -r%d
ServiceRestart: (%d)
ServiceRestart: (%d)
WFAddServiceToCollection: ERROR %d
WFAddServiceToCollection: ERROR %d
WFAddServiceToCollection: %d (%d)
WFAddServiceToCollection: %d (%d)
WFRemoveServiceFromCollection: ERROR %d
WFRemoveServiceFromCollection: ERROR %d
WFRemoveServiceFromCollection: %d
WFRemoveServiceFromCollection: %d
WFDisableServiceInCollection: ERROR %d
WFDisableServiceInCollection: ERROR %d
WFDisableServiceInCollection: %d
WFDisableServiceInCollection: %d
0x%p,0x%p,%d,0x%p,%d
0x%p,0x%p,%d,0x%p,%d
%s: invalid data type (%s)
%s: invalid data type (%s)
%s: pData NULL
%s: pData NULL
0x%p,0x%p,%d,0x%p,%d,0x%p,%d
0x%p,0x%p,%d,0x%p,%d,0x%p,%d
ServiceBase::WriteServiceSetting(): error saving "%s"
ServiceBase::WriteServiceSetting(): error saving "%s"
0x%p,0x%p,%d,0x%p,%d,%d
0x%p,0x%p,%d,0x%p,%d,%d
0x%p,%d,0x%p,0x%p,0x%p,0x%p,%d
0x%p,%d,0x%p,0x%p,0x%p,0x%p,%d
System\CurrentControlSet\Services\%s\Parameters
System\CurrentControlSet\Services\%s\Parameters
Service User Control Message: %u (%d)
Service User Control Message: %u (%d)
TypesSupported
TypesSupported
%d.%d.%d
%d.%d.%d
Dispatches system events, such as Windows logons, user inactivity, and shutdown notifications.
Dispatches system events, such as Windows logons, user inactivity, and shutdown notifications.
advapi32.dll
advapi32.dll
Client Service initializing. %s Version %s Build %d
Client Service initializing. %s Version %s Build %d
regsmtp
regsmtp
useRunKey
useRunKey
PortFileName
PortFileName
lulport
lulport
URLFileName
URLFileName
KeystrokeFileName
KeystrokeFileName
CCSListenPort
CCSListenPort
mschostport
mschostport
WFSListenPort
WFSListenPort
mswhostport
mswhostport
HostListenPort
HostListenPort
DSListenPort
DSListenPort
msdhostport
msdhostport
LMListenPort
LMListenPort
mslhostport
mslhostport
mswebole
mswebole
mswebcom
mswebcom
mswebrev
mswebrev
HtmlMsg
HtmlMsg
mswebext
mswebext
SuspendMsg
SuspendMsg
AgentSettings.pBlockedProgramsList
AgentSettings.pBlockedProgramsList
AgentSettings.MaskProgramTitles
AgentSettings.MaskProgramTitles
webinetmask
webinetmask
AgentSettings.ProgramInactivityTimeout
AgentSettings.ProgramInactivityTimeout
AgentSettings.CapturePrograms
AgentSettings.CapturePrograms
AgentSettings.IncludeAOLCSURLS
AgentSettings.IncludeAOLCSURLS
webinturl
webinturl
AgentSettings.CapturePOSTS
AgentSettings.CapturePOSTS
weblocposts
weblocposts
AgentSettings.CaptureAOLSE
AgentSettings.CaptureAOLSE
weblocaolse
weblocaolse
AgentSettings.CaptureXPCOM
AgentSettings.CaptureXPCOM
weblocxpcom
weblocxpcom
AgentSettings.HTTPSPorts
AgentSettings.HTTPSPorts
AgentSettings.HTTPPorts
AgentSettings.HTTPPorts
URLOldestData
URLOldestData
URLMaxDataSize
URLMaxDataSize
AgentSettings.IncludeLocalURLS
AgentSettings.IncludeLocalURLS
webloccheck
webloccheck
AgentSettings.IncludeNetURLS
AgentSettings.IncludeNetURLS
webnetcheck
webnetcheck
AgentSettings.CaptureINetURLS
AgentSettings.CaptureINetURLS
AgentSettings.MaskPasswords
AgentSettings.MaskPasswords
AgentSettings.CaptureChars
AgentSettings.CaptureChars
KeyStrokesOldestData
KeyStrokesOldestData
KeyStrokesMaxDataSize
KeyStrokesMaxDataSize
AgentSettings.CaptureKeyStrokes
AgentSettings.CaptureKeyStrokes
AgentSettings.pPortPortsList
AgentSettings.pPortPortsList
portPortLst
portPortLst
AgentSettings.PortPortsInclude
AgentSettings.PortPortsInclude
portPortInc
portPortInc
AgentSettings.pPortAppsList
AgentSettings.pPortAppsList
portAppLst
portAppLst
AgentSettings.PortAppsInclude
AgentSettings.PortAppsInclude
portAppInc
portAppInc
PortInactivityFlush
PortInactivityFlush
portIAF
portIAF
PortOldestData
PortOldestData
portOld
portOld
PortMaxDataSize
PortMaxDataSize
portMDS
portMDS
AgentSettings.CapturePort
AgentSettings.CapturePort
AgentSettings.DriveFileTracking
AgentSettings.DriveFileTracking
AgentSettings.pDriveFiltersList
AgentSettings.pDriveFiltersList
AgentSettings.DriveFiltersInclude
AgentSettings.DriveFiltersInclude
AgentSettings.Drives
AgentSettings.Drives
AgentSettings.DriveDefault.Types
AgentSettings.DriveDefault.Types
AgentSettings.DriveDefault.Disposition
AgentSettings.DriveDefault.Disposition
AgentSettings.CaptureIMAPI
AgentSettings.CaptureIMAPI
AgentSettings.CapturePrinters
AgentSettings.CapturePrinters
AgentSettings.CaptureDrives
AgentSettings.CaptureDrives
AgentSettings.FTPPorts
AgentSettings.FTPPorts
hlpvsbftp
hlpvsbftp
AgentSettings.GnutellaPorts
AgentSettings.GnutellaPorts
AgentSettings.CaptureINetHTMLUploads
AgentSettings.CaptureINetHTMLUploads
webcaphtml
webcaphtml
AgentSettings.CaptureP2P
AgentSettings.CaptureP2P
AgentSettings.StampChat
AgentSettings.StampChat
AgentSettings.CaptureSkype
AgentSettings.CaptureSkype
AgentSettings.CaptureINetMSNExchange
AgentSettings.CaptureINetMSNExchange
AgentSettings.XMPPCaptureType
AgentSettings.XMPPCaptureType
AgentSettings.YPagerCaptureType
AgentSettings.YPagerCaptureType
AgentSettings.AOLProcessCaptureType
AgentSettings.AOLProcessCaptureType
AgentSettings.OSCARCaptureType
AgentSettings.OSCARCaptureType
AgentSettings.MSNCaptureType
AgentSettings.MSNCaptureType
AgentSettings.IRCCaptureType
AgentSettings.IRCCaptureType
AgentSettings.CaptureINetMySpace443
AgentSettings.CaptureINetMySpace443
AgentSettings.CaptureINetOSCAR
AgentSettings.CaptureINetOSCAR
AgentSettings.CaptureINetAimExpress
AgentSettings.CaptureINetAimExpress
AgentSettings.XMPPPorts
AgentSettings.XMPPPorts
AgentSettings.YPagerPorts
AgentSettings.YPagerPorts
AgentSettings.OSCARPorts
AgentSettings.OSCARPorts
AgentSettings.MSNPorts
AgentSettings.MSNPorts
AgentSettings.IRCPorts
AgentSettings.IRCPorts
AgentSettings.CaptureChat
AgentSettings.CaptureChat
AgentSettings.NotesPollingInterval
AgentSettings.NotesPollingInterval
AgentSettings.NotesLastMsgRcvdTime
AgentSettings.NotesLastMsgRcvdTime
AgentSettings.LastMsgRcvdTime
AgentSettings.LastMsgRcvdTime
AgentSettings.pEmailLastRecvTimeList
AgentSettings.pEmailLastRecvTimeList
AgentSettings.pEmailFilterList
AgentSettings.pEmailFilterList
webfiltlst
webfiltlst
AgentSettings.EmailFilterDefaultIgnore
AgentSettings.EmailFilterDefaultIgnore
webfiltdef
webfiltdef
AgentSettings.UseAltMAPICapture
AgentSettings.UseAltMAPICapture
AgentSettings.IMAPPorts
AgentSettings.IMAPPorts
AgentSettings.POPPorts
AgentSettings.POPPorts
AgentSettings.SMTPPorts
AgentSettings.SMTPPorts
AgentSettings.CaptureINetWebEMail
AgentSettings.CaptureINetWebEMail
webineticmp
webineticmp
AgentSettings.MailAttachMaxDataSize
AgentSettings.MailAttachMaxDataSize
AgentSettings.CaptureAttachments
AgentSettings.CaptureAttachments
webinetudp
webinetudp
AgentSettings.CaptureAOLEMail
AgentSettings.CaptureAOLEMail
webinetxde
webinetxde
AgentSettings.CaptureINetIMAPEMail
AgentSettings.CaptureINetIMAPEMail
webinettimap
webinettimap
AgentSettings.CaptureINetSMTPEMail
AgentSettings.CaptureINetSMTPEMail
webinettcp
webinettcp
AgentSettings.MAPIInboxOnly
AgentSettings.MAPIInboxOnly
WebMapiBox
WebMapiBox
AgentSettings.CaptureNotesEMail
AgentSettings.CaptureNotesEMail
webnotes
webnotes
AgentSettings.CaptureMAPIEMail
AgentSettings.CaptureMAPIEMail
webmapi
webmapi
AgentSettings.CaptureEMail
AgentSettings.CaptureEMail
AgentSettings.pKeyEventList
AgentSettings.pKeyEventList
portusb6
portusb6
AgentSettings.SendVScroll
AgentSettings.SendVScroll
portusb5
portusb5
AgentSettings.SendEnterEvent
AgentSettings.SendEnterEvent
portusb3
portusb3
AgentSettings.SendMouseWheel
AgentSettings.SendMouseWheel
portusb4
portusb4
AgentSettings.SendMouseRightClick
AgentSettings.SendMouseRightClick
portusb7
portusb7
AgentSettings.SendMouseDoubleClick
AgentSettings.SendMouseDoubleClick
portusb2
portusb2
AgentSettings.SendMouseClick
AgentSettings.SendMouseClick
portusb1
portusb1
SnapTriggerKeyEnter
SnapTriggerKeyEnter
portpnp3
portpnp3
portpnp4
portpnp4
portpnp5
portpnp5
portpnp2
portpnp2
portpnp1
portpnp1
SnapTriggerHttpPost
SnapTriggerHttpPost
SnapTriggerUrl
SnapTriggerUrl
AgentSettings.InactivityTimeout
AgentSettings.InactivityTimeout
AgentSettings.pBlockUsersList
AgentSettings.pBlockUsersList
AgentSettings.BlockUsers
AgentSettings.BlockUsers
AgentSettings.pSvrBlockUrlList
AgentSettings.pSvrBlockUrlList
AgentSettings.SvrBlockRevertLocal
AgentSettings.SvrBlockRevertLocal
AgentSettings.SvrBlockEnable
AgentSettings.SvrBlockEnable
AgentSettings.BlockIMsAccess
AgentSettings.BlockIMsAccess
AgentSettings.BlockUrlsAccess
AgentSettings.BlockUrlsAccess
AgentSettings.pBlockIMsList
AgentSettings.pBlockIMsList
AgentSettings.pURLList
AgentSettings.pURLList
AgentSettings.BlockIMsList
AgentSettings.BlockIMsList
AgentSettings.BlockUrlsList
AgentSettings.BlockUrlsList
AgentSettings.pBlockAllAppsList
AgentSettings.pBlockAllAppsList
AgentSettings.pBlockInPortsList
AgentSettings.pBlockInPortsList
AgentSettings.pBlockOutPortsList
AgentSettings.pBlockOutPortsList
AgentSettings.BlockInternetAccessAll
AgentSettings.BlockInternetAccessAll
AgentSettings.BlockInternetAccess
AgentSettings.BlockInternetAccess
AgentSettings.pRecordURLList
AgentSettings.pRecordURLList
AgentSettings.pUsersList
AgentSettings.pUsersList
AgentSettings.pAppsList
AgentSettings.pAppsList
AgentSettings.RecordUrlsList
AgentSettings.RecordUrlsList
AgentSettings.RecordUrls
AgentSettings.RecordUrls
AgentSettings.DenyListedUsers
AgentSettings.DenyListedUsers
AgentSettings.RecordUsers
AgentSettings.RecordUsers
AgentSettings.DenyListedApps
AgentSettings.DenyListedApps
AgentSettings.RecordApps
AgentSettings.RecordApps
SnapshotHotkey
SnapshotHotkey
ToggleRecordHotkey
ToggleRecordHotkey
HostLoginType
HostLoginType
HostLoginPassword
HostLoginPassword
HostLoginUsername
HostLoginUsername
KeywordEmailSubjectStrPRogramWindowCaption
KeywordEmailSubjectStrPRogramWindowCaption
KeywordEmailSubjectStrProgramName
KeywordEmailSubjectStrProgramName
KeywordEmailSubjectStrP2P
KeywordEmailSubjectStrP2P
KeywordEmailSubjectStrUrls
KeywordEmailSubjectStrUrls
KeywordEmailSubjectStrKeyStrokes
KeywordEmailSubjectStrKeyStrokes
KeywordEmailSubjectStrWebPages
KeywordEmailSubjectStrWebPages
KeywordEmailSubjectStrChat
KeywordEmailSubjectStrChat
KeywordEmailSubjectStrEmail
KeywordEmailSubjectStrEmail
KeywordEmailFormatStrPRogramWindowCaption
KeywordEmailFormatStrPRogramWindowCaption
KeywordEmailFormatStrProgramName
KeywordEmailFormatStrProgramName
KeywordEmailFormatStrP2P
KeywordEmailFormatStrP2P
KeywordEmailFormatStrUrls
KeywordEmailFormatStrUrls
KeywordEmailFormatStrKeyStrokes
KeywordEmailFormatStrKeyStrokes
KeywordEmailFormatStrWebPages
KeywordEmailFormatStrWebPages
KeywordEmailFormatStrChat
KeywordEmailFormatStrChat
KeywordEmailFormatStrEmail
KeywordEmailFormatStrEmail
pKeywordsList
pKeywordsList
KeywordEmailTimeout
KeywordEmailTimeout
KeywordScreenshotPeriod
KeywordScreenshotPeriod
KeywordScreenshotRate
KeywordScreenshotRate
ScanWebPages
ScanWebPages
AgentSettings.CaptureINetWebPages
AgentSettings.CaptureINetWebPages
ScanUrls
ScanUrls
ScanKeystrokes
ScanKeystrokes
TakeKeywordScreenshot
TakeKeywordScreenshot
SendKeywordEmail
SendKeywordEmail
SendServerKeywords
SendServerKeywords
CaptureKeywords
CaptureKeywords
AgentSettings.DecoyFile
AgentSettings.DecoyFile
AgentSettings.ComAddinName
AgentSettings.ComAddinName
AgentSettings.ComAddinID
AgentSettings.ComAddinID
AgentSettings.MapiClsId
AgentSettings.MapiClsId
AgentSettings.BhoClsId
AgentSettings.BhoClsId
AgentSettings.SAFProcessorPath
AgentSettings.SAFProcessorPath
AgentSettings.DynProcessorWOW64Path
AgentSettings.DynProcessorWOW64Path
AgentSettings.DynProcessorPath
AgentSettings.DynProcessorPath
DeleteKey
DeleteKey
keydele
keydele
DeleteKeyRoot
DeleteKeyRoot
keydeleroot
keydeleroot
AgentSettings.DeviceName
AgentSettings.DeviceName
AgentSettings.DriverPath
AgentSettings.DriverPath
KeywordMAPIPath
KeywordMAPIPath
KeywordServerInfo
KeywordServerInfo
LCFireWallHTTPPort
LCFireWallHTTPPort
SMTPPort
SMTPPort
RmtPortalToken
RmtPortalToken
rmtporttok
rmtporttok
RmtPortalPassword
RmtPortalPassword
rmtportpass
rmtportpass
RmtPortalLogin
RmtPortalLogin
rmtportlog
rmtportlog
RmtS3SecretKey
RmtS3SecretKey
rmts3seckey
rmts3seckey
RmtS3KeyID
RmtS3KeyID
rmts3keyid
rmts3keyid
AgentSettings.CaptureConsoles
AgentSettings.CaptureConsoles
AgentSettings.LFMaskShared
AgentSettings.LFMaskShared
AgentSettings.BhoActive
AgentSettings.BhoActive
WinAdminPassword
WinAdminPassword
StartRecordingWithWindows
StartRecordingWithWindows
DataFilePasswordHash
DataFilePasswordHash
AgentSettings.NetInitDelay
AgentSettings.NetInitDelay
AgentSettings.ClearFF
AgentSettings.ClearFF
AgentSettings.BlockFileAccess
AgentSettings.BlockFileAccess
AdminHotkey
AdminHotkey
AdminPasswordHash
AdminPasswordHash
AdminPassword
AdminPassword
AgentSettings.LogFileMask
AgentSettings.LogFileMask
AgentSettings.LogFileLevel
AgentSettings.LogFileLevel
AgentSettings.LogFilePath
AgentSettings.LogFilePath
AgentSettings.UseLogFile
AgentSettings.UseLogFile
DisallowKeystrokeCapture
DisallowKeystrokeCapture
ineturls
ineturls
ineturlsn
ineturlsn
msocxushell.dll
msocxushell.dll
wwfwnetex.drv
wwfwnetex.drv
tudmdxiufrm.drv
tudmdxiufrm.drv
winfatiosys32.drv
winfatiosys32.drv
winnetkernel32.drv
winnetkernel32.drv
winkernel32hlp.drv
winkernel32hlp.drv
wwfwnetex.dll
wwfwnetex.dll
udmdxiufrm.dll
udmdxiufrm.dll
msfatiosys32.dll
msfatiosys32.dll
msnetKernel32.dll
msnetKernel32.dll
mskernel32hlp.dll
mskernel32hlp.dll
-0561-4ffd-9B86-5BA2E941BA52}\OLE\Shell\Commands
-0561-4ffd-9B86-5BA2E941BA52}\OLE\Shell\Commands
MapiAuthentication.Addin
MapiAuthentication.Addin
NewWFSListenPort
NewWFSListenPort
NotifyPort
NotifyPort
CEASListenPort
CEASListenPort
NewCEASListenPort
NewCEASListenPort
CCSDbLoginName
CCSDbLoginName
CCSDbPassword
CCSDbPassword
ProxyPort
ProxyPort
NewLMListenPort
NewLMListenPort
DBSqlType
DBSqlType
DBPassword
DBPassword
NewDSListenPort
NewDSListenPort
WebMailIniPath
WebMailIniPath
0x%p,%d,0x%p,0x%p,%d
0x%p,%d,0x%p,0x%p,%d
%d,0x%p,0x%p
%d,0x%p,0x%p
%systemroot%
%systemroot%
SetAdminPasswordHash
SetAdminPasswordHash
ValidateServerCert
ValidateServerCert
AuthenPassword
AuthenPassword
SmtpAuthType
SmtpAuthType
SnapshotHotkeyDisplayable
SnapshotHotkeyDisplayable
ToggleRecordHotkeyDisplayable
ToggleRecordHotkeyDisplayable
AdminHotkeyDisplayable
AdminHotkeyDisplayable
CEAdmin.cfg
CEAdmin.cfg
secur32.dll
secur32.dll
0x%p,0x%x
0x%p,0x%x
WriteSettingsWebMailStrings
WriteSettingsWebMailStrings
locmlurl
locmlurl
locmsurl
locmsurl
locmrmsg
locmrmsg
loclurl
loclurl
locmurl
locmurl
INTRWEB
INTRWEB
MSG_Owner
MSG_Owner
WebMail
WebMail
SMTPPOP
SMTPPOP
vKey
vKey
szKeyword
szKeyword
KeyEventDef
KeyEventDef
PortRange
PortRange
KeywordRecord
KeywordRecord
ExportXMLSystem
ExportXMLSystem
svrapi.dll
svrapi.dll
netapi32.dll
netapi32.dll
\\%s\%s
\\%s\%s
ValidatePortsCallback
ValidatePortsCallback
microsoft\..\*32.dll
microsoft\..\*32.dll
ImportXMLSetting
ImportXMLSetting
\\.\%s%d
\\.\%s%d
Windows-1252
Windows-1252
%s %dx%dx%d
%s %dx%dx%d
WindowsVersion
WindowsVersion
%d.%d.%d %s
%d.%d.%d %s
" webmailrev="
" webmailrev="
MYSPACE_HTTP
MYSPACE_HTTP
FACEBOOK_HTTP
FACEBOOK_HTTP
GTALK_HTTP
GTALK_HTTP
MSN_HTTP
MSN_HTTP
KEYSTROKES
KEYSTROKES
bNetLogin
bNetLogin
UrlID
UrlID
UrlType
UrlType
UrlData
UrlData
KeyData
KeyData
KeywordData
KeywordData
KeyStrokeCount
KeyStrokeCount
URLCount
URLCount
ReportData
ReportData
strErrMsg
strErrMsg
RemotePort
RemotePort
DesktopDataBase.Size
DesktopDataBase.Size
DesktopDataBase.Type
DesktopDataBase.Type
KEYWORD
KEYWORD
BLK_WEB
BLK_WEB
WEBMAIL
WEBMAIL
SMTP
SMTP
254.254.254.254
254.254.254.254
CUSTWEB
CUSTWEB
GetComputerInfo - Unable to load NETAPI32.DLL library.
GetComputerInfo - Unable to load NETAPI32.DLL library.
GetComputerInfo - Unable to get NETAPI32.DLL function pointers.
GetComputerInfo - Unable to get NETAPI32.DLL function pointers.
GetComputerInfo - NetWkstaGetInfo error (%d,0x%p).
GetComputerInfo - NetWkstaGetInfo error (%d,0x%p).
NETAPI32.DLL
NETAPI32.DLL
-0561-4ffd-9B86-5BA2E941BA52}
-0561-4ffd-9B86-5BA2E941BA52}
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WebExtLocation
WebExtLocation
bSOFTWARE\Microsoft\Windows\CurrentVersion\Run
bSOFTWARE\Microsoft\Windows\CurrentVersion\Run
WebCheckStub
WebCheckStub
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
CLSID\%s
CLSID\%s
%s -u
%s -u
CLSID\%s\InProcServer32
CLSID\%s\InProcServer32
SCHTASKS /CREATE /SC ONSTART /RU SYSTEM /TN %s /TR "%s"
SCHTASKS /CREATE /SC ONSTART /RU SYSTEM /TN %s /TR "%s"
SCHTASKS /DELETE /F /TN %s
SCHTASKS /DELETE /F /TN %s
RD /S /Q "%s"
RD /S /Q "%s"
xxxxx
xxxxx
xxxxxxxxxxxxxxxxx.cmd
xxxxxxxxxxxxxxxxx.cmd
SpectorCNE.chm
SpectorCNE.chm
SOFTWARE\Wow6432Node\Classes\CLSID\{4A85C0C0-C52C-4C08-9E88-F012BF35623A}
SOFTWARE\Wow6432Node\Classes\CLSID\{4A85C0C0-C52C-4C08-9E88-F012BF35623A}
SOFTWARE\Classes\CLSID\{7640DFF4-252C-470E-ACB7-1922EA57A0B9}
SOFTWARE\Classes\CLSID\{7640DFF4-252C-470E-ACB7-1922EA57A0B9}
MSMSGS
MSMSGS
FTP Voyager
FTP Voyager
Ftpvoyager
Ftpvoyager
Windows Messaging
Windows Messaging
Cute FTP
Cute FTP
Cutftp32
Cutftp32
RemoteRegDeleteKey
RemoteRegDeleteKey
IMsgBox
IMsgBox
\wininit.ini
\wininit.ini
GetLastErrorMsg
GetLastErrorMsg
ws2_32.dll
ws2_32.dll
RemoteRegConnectKey
RemoteRegConnectKey
CWindowsFirewall
CWindowsFirewall
::DisablePort
::DisablePort
::IsPortEnabled
::IsPortEnabled
::AddPort
::AddPort
::RemovePort
::RemovePort
DisableAppAndPort
DisableAppAndPort
AddAppAndPort
AddAppAndPort
RemoveAppAndPort
RemoveAppAndPort
1.2.3
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
GetProcessWindowStation
GetProcessWindowStation
operator
operator
Service.pdb
Service.pdb
WSOCK32.dll
WSOCK32.dll
DisconnectNamedPipe
DisconnectNamedPipe
ConnectNamedPipe
ConnectNamedPipe
CreateNamedPipeA
CreateNamedPipeA
WinExec
WinExec
GetWindowsDirectoryA
GetWindowsDirectoryA
GetProcessHeap
GetProcessHeap
KERNEL32.dll
KERNEL32.dll
GetKeyNameTextA
GetKeyNameTextA
MapVirtualKeyA
MapVirtualKeyA
GetKeyboardLayout
GetKeyboardLayout
ExitWindowsEx
ExitWindowsEx
MapVirtualKeyExA
MapVirtualKeyExA
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegCloseKey
RegCloseKey
RegGetKeySecurity
RegGetKeySecurity
RegOpenKeyExA
RegOpenKeyExA
RegSetKeySecurity
RegSetKeySecurity
RegCreateKeyExA
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegEnumKeyExA
RegEnumKeyExA
ReportEventA
ReportEventA
RegCreateKeyA
RegCreateKeyA
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
GetCPInfo
GetCPInfo
PeekNamedPipe
PeekNamedPipe
vdorctrl.dll
vdorctrl.dll
svrltmgr.dll
svrltmgr.dll
mxcrsc32.exe
mxcrsc32.exe
snxapi.exe
snxapi.exe
vdorctrl.sys
vdorctrl.sys
wshvtx.exe
wshvtx.exe
secadtr.dll
secadtr.dll
cmproxfr.dll
cmproxfr.dll
ashl16.dll
ashl16.dll
ashl32.dll
ashl32.dll
sgvrfy32.exe
sgvrfy32.exe
nmcpusym.dll
nmcpusym.dll
xsysym.dll
xsysym.dll
svrltwp.dll
svrltwp.dll
svrlser.dll
svrlser.dll
vidithnk.dll
vidithnk.dll
wzodlg32.dll
wzodlg32.dll
winipdat.log
winipdat.log
safser32.dll
safser32.dll
ntvshl.exe
ntvshl.exe
mzsyk32.dll
mzsyk32.dll
SOFTWARE\Classes\CLSID\{F105F8A8-9D47-4942-B13B-DAC8DF268396}
SOFTWARE\Classes\CLSID\{F105F8A8-9D47-4942-B13B-DAC8DF268396}
zcÃ
zcÃ
stem32\sgvrfy32.exe
stem32\sgvrfy32.exe
7.3.1111
7.3.1111
C:\Windows\system32\sgvrfy32.exe
C:\Windows\system32\sgvrfy32.exe
0f0x0
0f0x0
2)2F2X2(3/3C3V3h3(4/4C4Y4
2)2F2X2(3/3C3V3h3(4/4C4Y4
00s0
00s0
;%;2;8;];
;%;2;8;];
3-3T3}3
3-3T3}3
9#9*9/9=9
9#9*9/9=9
1"1&1*171
1"1&1*171
2(2,2024282
2(2,2024282
2 2$2\2`2
2 2$2\2`2
3 3$3(3,303
3 3$3(3,303
=$?(?,?0?4?8?@?
=$?(?,?0?4?8?@?
2 2$2(2,2
2 2$2(2,2
4(444
4(444
4,484@4`4
4,484@4`4
:,:8:@:`:
:,:8:@:`:
>,>8>@>`>
>,>8>@>`>
3(343
3(343
7,787@7`7
7,787@7`7
1,181@1`1
1,181@1`1
5,585@5`5
5,585@5`5
6 646
6 646
?,?8?@?`?
?,?8?@?`?
9 9
9 9
set[@name="%S"]
set[@name="%S"]
nKERNEL32.DLL
nKERNEL32.DLL
mscoree.dll
mscoree.dll
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
WUSER32.DLL
WUSER32.DLL