Trojan-Dropper.Win32.Delf.efnz (Kaspersky), Gen:Variant.Barys.2143 (B) (Emsisoft), Gen:Variant.Barys.2143 (AdAware), Backdoor.Win32.Fynloski.FD, Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, BackdoorFynloski.YR, GenericDownloader.YR, GenericInjector.YR, TrojanDownloaderAndromeda.YR (Lavasoft MAS)Behaviour: Trojan-Dropper, Trojan-Downloader, Banker, Trojan, Backdoor, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 349d2772917254f5a09e6753867d046a
SHA1: 4824c5fcc14a30d5389db36b28e404ddeab3476f
SHA256: ceb0abea798bef4e33414c9f2a0b82feb8b48759427f79f1867c6331a143d026
SSDeep: 98304:fCfL2Nz1dh5DanDM L5rctxLOn5BAULHcIN0:fCfQdOnDM L5Yt4OaS
Size: 5212160 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company:
Created at: 1992-06-20 01:22:17
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:3668
434ÃÂÂ6.exe:3676
The Trojan injects its code into the following process(es):
kophack-70.exe:2624
Windows.exe:3188
notepad.exe:3144
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:3668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\434ÃÂÂ6.exe (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe (489 bytes)
The process 434ÃÂÂ6.exe:3676 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe (4545 bytes)
Registry activity
The process kophack-70.exe:2624 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"EnableFileTracing" = "0"
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASMANCS]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\kophack-70_RASAPI32]
"EnableConsoleTracing" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:3668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process 434ÃÂÂ6.exe:3676 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"windows.exe" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
Dropped PE files
MD5 | File path |
---|---|
7be000b351000cf02bed01a1dada3576 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\434ÃÂ6.exe |
7be000b351000cf02bed01a1dada3576 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe |
ba1add29800ea7182b32507b0c94b8ba | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:3668
434ÃÂÂ6.exe:3676 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\434ÃÂÂ6.exe (1414 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\kophack-70.exe (489 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe (4545 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"windows.exe" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 5048 | 5120 | 4.39524 | e5913936857bed3b3b2fbac53e973471 |
DATA | 12288 | 124 | 512 | 0.77468 | cef89de607e490725490a3cd679af6bb |
BSS | 16384 | 1685 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 20480 | 770 | 1024 | 2.41029 | 3d2f2fc4e279cba623217ec9de264c4f |
.tls | 24576 | 4 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 28672 | 24 | 512 | 0.138011 | 467f29e48f3451df774e13adae5aafc2 |
.reloc | 32768 | 456 | 512 | 4.00868 | 9859d413c7408cb699cca05d648c2502 |
.rsrc | 36864 | 5203228 | 5203456 | 4.62763 | 00f0f1c8e8f4887e9aad32dc00fcd974 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://baza.hack-games-vk.ru/KopHack/version-70.php | 87.236.19.173 |
nikita256455.ddns.net | 176.124.21.64 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /KopHack/version-70.php HTTP/1.1
Host: baza.hack-games-vk.ru
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx-reuseport/1.11.6
Date: Sat, 03 Dec 2016 13:26:59 GMT
Content-Type: text/html
Content-Length: 1
Connection: keep-alive
Keep-Alive: timeout=30
X-Powered-By: PHP/5.2.17
HTTP/1.1 200 OK..Server: nginx-reuseport/1.11.6..Date: Sat, 03 Dec 2016 13:26:59 GMT..Content-Type: text/html..Content-Length: 1..Connection: keep-alive..Keep-Alive: timeout=30..X-Powered-By: PHP/5.2.17.. ..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
kophack-70.exe_2624:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s[%d]
%s[%d]
%s_%d
%s_%d
EInvalidGraphicOperation
EInvalidGraphicOperation
USER32.DLL
USER32.DLL
comctl32.dll
comctl32.dll
uxtheme.dll
uxtheme.dll
PasswordCharL7E
PasswordCharL7E
OnKeyDownp
OnKeyDownp
OnKeyPress$
OnKeyPress$
OnKeyUpH
OnKeyUpH
OnKeyUp
OnKeyUp
TListBoxp%C
TListBoxp%C
Proportional
Proportional
%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
Uh.cD
Uh.cD
imm32.dll
imm32.dll
AutoHotkeysl-E
AutoHotkeysl-E
AutoHotkeys
AutoHotkeys
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview`4E
KeyPreview`4E
WindowState
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
getservbyport
getservbyport
WSAAsyncGetServByPort
WSAAsyncGetServByPort
WSAJoinLeaf
WSAJoinLeaf
WS2_32.DLL
WS2_32.DLL
127.0.0.1
127.0.0.1
TIdSocketListWindows
TIdSocketListWindows
TIdStackWindowsU
TIdStackWindowsU
IdStackWindows
IdStackWindows
%s, %.2d %s %.4d %s %s
%s, %.2d %s %.4d %s %s
%s, %d %s %d %s %s
%s, %d %s %d %s %s
Unsupported operation.
Unsupported operation.
Content-Disposition: form-data; name="%s"; filename="%s"
Content-Disposition: form-data; name="%s"; filename="%s"
Content-Type: %s
Content-Type: %s
Content-Disposition: form-data; name="%s"
Content-Disposition: form-data; name="%s"
PSAPI.dll
PSAPI.dll
MAPI32.DLL
MAPI32.DLL
TsWindowShowMode
TsWindowShowMode
user32.dll
user32.dll
colorui.dll
colorui.dll
shell32.dll
shell32.dll
comdlg32.dll
comdlg32.dll
compstui.dll
compstui.dll
inetres.dll
inetres.dll
1.2.3
1.2.3
Invalid ZStream operation!
Invalid ZStream operation!
msimg32.dll
msimg32.dll
Cannot load image. %s not supported for %s files.
Cannot load image. %s not supported for %s files.
Cannot load image. Palette in %s file is invalid.
Cannot load image. Palette in %s file is invalid.
Cannot load image. Invalid or unexpected %s image format.
Cannot load image. Invalid or unexpected %s image format.
Cannot load image. CRC error found in %s file.
Cannot load image. CRC error found in %s file.
Cannot load image. Extra compressed data found in %s file.
Cannot load image. Extra compressed data found in %s file.
Cannot load image. Compression error found in %s file.
Cannot load image. Compression error found in %s file.
Invalid color format in %s file.
Invalid color format in %s file.
3333333
3333333
Conversion between indexed and non-indexed pixel formats is not supported.
Conversion between indexed and non-indexed pixel formats is not supported.
Portable network graphics (AlphaControls)
Portable network graphics (AlphaControls)
TsShowTimer
TsShowTimer
TsShowTimerd
TsShowTimerd
TacMDIWnd
TacMDIWnd
gdi32.dll
gdi32.dll
WEBBUTTON
WEBBUTTON
PROGRESSH
PROGRESSH
TacMenuSupport
TacMenuSupport
Webdings
Webdings
Uh.TP
Uh.TP
TAddItemExEvent
TAddItemExEvent
DWMAPI.DLL
DWMAPI.DLL
acMDIIcons
acMDIIcons
|$(;
|$(;
ole32.dll
ole32.dll
ClickKey(
ClickKey(
FormKeyPress
FormKeyPress
### ### ##0.00;-### ### ##0.00;0
### ### ##0.00;-### ### ##0.00;0
sEditHexKeyPress
sEditHexKeyPress
PickFormKeyDown
PickFormKeyDown
CRASPIPETTE
CRASPIPETTE
TacScrollBarsSupport
TacScrollBarsSupport
TacScrollBarsSupport4
TacScrollBarsSupport4
TacButtonsSupport
TacButtonsSupport
TacButtonsSupport$
TacButtonsSupport$
TacLabelsSupport
TacLabelsSupport
MenuSupport
MenuSupport
KeyList
KeyList
c:\Skins
c:\Skins
Options.dat
Options.dat
.JPEG
.JPEG
1.tmp
1.tmp
Please, update skins to latest or contact the AlphaControls support for upgrading of existing skin.
Please, update skins to latest or contact the AlphaControls support for upgrading of existing skin.
This version of the skin has not complete support by used AlphaControls package release.
This version of the skin has not complete support by used AlphaControls package release.
Secure key has incorrect format
Secure key has incorrect format
opera.exe
opera.exe
firefox.exe
firefox.exe
chrome.exe
chrome.exe
browser.exe
browser.exe
plugin-container.exe
plugin-container.exe
safari.exe
safari.exe
KopatelOnline.exe
KopatelOnline.exe
SteamTestApp.exe
SteamTestApp.exe
amigo.exe
amigo.exe
ftpTransfer
ftpTransfer
ftpReady
ftpReady
ftpAborted
ftpAborted
ClientPortMin
ClientPortMin
ClientPortMax
ClientPortMax
Port
Port
EIdCanNotBindPortInRange
EIdCanNotBindPortInRange
EIdInvalidPortRangeSVW
EIdInvalidPortRangeSVW
saUsernamePassword
saUsernamePassword
Password
Password
0.0.0.1
0.0.0.1
UhC%U
UhC%U
TIdTCPConnection
TIdTCPConnection
IdTCPConnection
IdTCPConnection
EIdTCPConnectionError
EIdTCPConnectionError
CommentURL
CommentURL
password
password
Password
Password
IdHTTPHeaderInfo
IdHTTPHeaderInfo
ProxyPassword
ProxyPassword
ProxyPort
ProxyPort
Mozilla/3.0 (compatible; Indy Library)
Mozilla/3.0 (compatible; Indy Library)
TIdTCPClient
TIdTCPClient
IdTCPClient
IdTCPClient
BoundPort
BoundPort
PortU
PortU
libeay32.dll
libeay32.dll
ssleay32.dll
ssleay32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
SSL_CTX_check_private_key
X509_STORE_CTX_get_current_cert
X509_STORE_CTX_get_current_cert
des_set_key
des_set_key
sslvrfFailIfNoPeerCert
sslvrfFailIfNoPeerCert
TPasswordEvent
TPasswordEvent
Certificate
Certificate
RootCertFileD
RootCertFileD
CertFileD
CertFileD
KeyFiled
KeyFiled
OnGetPassword
OnGetPassword
EIdOSSLLoadingRootCertError0
EIdOSSLLoadingRootCertError0
EIdOSSLLoadingCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
EIdOSSLLoadingKeyError
TIdHTTPMethod
TIdHTTPMethod
IdHTTP
IdHTTP
TIdHTTPOption
TIdHTTPOption
TIdHTTPOptions
TIdHTTPOptions
TIdHTTPProtocolVersion
TIdHTTPProtocolVersion
IdHTTPl
IdHTTPl
TIdHTTPOnHeadersAvailable
TIdHTTPOnHeadersAvailable
TIdHTTPOnRedirectEvent
TIdHTTPOnRedirectEvent
TIdHTTPResponse
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPRequest
TIdHTTPRequestX
TIdHTTPRequestX
TIdHTTPProtocoll
TIdHTTPProtocoll
TIdCustomHTTP
TIdCustomHTTP
TIdCustomHTTPl
TIdCustomHTTPl
TIdHTTPT
TIdHTTPT
TIdHTTP
TIdHTTP
HTTPOptionsh
HTTPOptionsh
EIdHTTPProtocolException
EIdHTTPProtocolException
HTTPS
HTTPS
https
https
This request method is supported in HTTP 1.1
This request method is supported in HTTP 1.1
HTTP/1.0 200 OK
HTTP/1.0 200 OK
HTTP/
HTTP/
IdHTTP1
IdHTTP1
768352325.jks
768352325.jks
auth_key
auth_key
IdHTTP1
IdHTTP1
768352321.jks
768352321.jks
07 00 00 00
07 00 00 00
12 00 00 00
12 00 00 00
40 00 00 00
40 00 00 00
41 00 00 00
41 00 00 00
42 00 00 00
42 00 00 00
08 00 00 00
08 00 00 00
11 00 00 00
11 00 00 00
22 00 00 00
22 00 00 00
23 00 00 00
23 00 00 00
21 00 00 00
21 00 00 00
24 00 00 00
24 00 00 00
25 00 00 00
25 00 00 00
26 00 00 00
26 00 00 00
28 00 00 00
28 00 00 00
31 00 00 00
31 00 00 00
32 00 00 00
32 00 00 00
33 00 00 00
33 00 00 00
34 00 00 00
34 00 00 00
35 00 00 00
35 00 00 00
06 00 00 00
06 00 00 00
09 00 00 00
09 00 00 00
04 00 00 00
04 00 00 00
01 00 00 00
01 00 00 00
05 00 00 00
05 00 00 00
13 00 00 00
13 00 00 00
14 00 00 00
14 00 00 00
15 00 00 00
15 00 00 00
16 00 00 00
16 00 00 00
17 00 00 00
17 00 00 00
18 00 00 00
18 00 00 00
19 00 00 00
19 00 00 00
43 00 00 00
43 00 00 00
44 00 00 00
44 00 00 00
45 00 00 00
45 00 00 00
46 00 00 00
46 00 00 00
47 00 00 00
47 00 00 00
48 00 00 00
48 00 00 00
49 00 00 00
49 00 00 00
50 00 00 00
50 00 00 00
39 00 00 00
39 00 00 00
03 00 00 00
03 00 00 00
53 00 00 00
53 00 00 00
54 00 00 00
54 00 00 00
55 00 00 00
55 00 00 00
56 00 00 00
56 00 00 00
51 00 00 00
51 00 00 00
52 00 00 00
52 00 00 00
00 00 00 54
00 00 00 54
00 00 00 55
00 00 00 55
00 00 00 56
00 00 00 56
00 00 00 57
00 00 00 57
00 00 00 58
00 00 00 58
00 00 00 59
00 00 00 59
00 00 00 60
00 00 00 60
00 00 00 61
00 00 00 61
00 00 00 62
00 00 00 62
00 00 00 63
00 00 00 63
00 00 00 64
00 00 00 64
00 00 00 65
00 00 00 65
00 00 00 70
00 00 00 70
00 00 00 71
00 00 00 71
00 00 00 72
00 00 00 72
00 00 00 73
00 00 00 73
00 00 00 74
00 00 00 74
00 00 00 75
00 00 00 75
00 00 00 29
00 00 00 29
00 00 00 36
00 00 00 36
00 00 00 38
00 00 00 38
00 00 00 67
00 00 00 67
00 00 00 66
00 00 00 66
00 00 00 69
00 00 00 69
00 00 00 68
00 00 00 68
00 00 00 78
00 00 00 78
00 00 00 79
00 00 00 79
00 00 00 80
00 00 00 80
00 00 00 81
00 00 00 81
00 00 00 33
00 00 00 33
00 00 00 34
00 00 00 34
00 00 00 35
00 00 00 35
00 00 00 39
00 00 00 39
00 00 00 76
00 00 00 76
00 00 00 77
00 00 00 77
00 00 00 51
00 00 00 51
00 00 00 50
00 00 00 50
57 00 00 00
57 00 00 00
58 00 00 00
58 00 00 00
59 00 00 00
59 00 00 00
83 00 00 00
83 00 00 00
84 00 00 00
84 00 00 00
85 00 00 00
85 00 00 00
86 00 00 00
86 00 00 00
87 00 00 00
87 00 00 00
88 00 00 00
88 00 00 00
89 00 00 00
89 00 00 00
80 00 00 00
80 00 00 00
81 00 00 00
81 00 00 00
82 00 00 00
82 00 00 00
65 00 00 00
65 00 00 00
66 00 00 00
66 00 00 00
67 00 00 00
67 00 00 00
68 00 00 00
68 00 00 00
69 00 00 00
69 00 00 00
70 00 00 00
70 00 00 00
71 00 00 00
71 00 00 00
73 00 00 00
73 00 00 00
74 00 00 00
74 00 00 00
76 00 00 00
76 00 00 00
77 00 00 00
77 00 00 00
78 00 00 00
78 00 00 00
79 00 00 00
79 00 00 00
60 00 00 00
60 00 00 00
61 00 00 00
61 00 00 00
62 00 00 00
62 00 00 00
63 00 00 00
63 00 00 00
hXXp://baza.hack-games-vk.ru/KopHack/version-70.php
hXXp://baza.hack-games-vk.ru/KopHack/version-70.php
hXXp://baza.hack-games-vk.ru/KopHack/download.php
hXXp://baza.hack-games-vk.ru/KopHack/download.php
hXXp://hack-games-vk.ru/topic/4949-chit-na-kopatel-onlain-kophack/
hXXp://hack-games-vk.ru/topic/4949-chit-na-kopatel-onlain-kophack/
hXXp://vzlom-games.ru/kop_hack_v70.php?id=
hXXp://vzlom-games.ru/kop_hack_v70.php?id=
&authkeyshop=false
&authkeyshop=false
google chrome
google chrome
IdHTTP1`
IdHTTP1`
89 48 08 90 90 90 90
89 48 08 90 90 90 90
40 00 00
40 00 00
363465123.jks
363465123.jks
hXXps://VVV.youtube.com/channel/UClV7COFnkC-4If9kSG9OZcA
hXXps://VVV.youtube.com/channel/UClV7COFnkC-4If9kSG9OZcA
hXXp://hack-games-vk.ru/forum/2-chity-dlia-igr-vkcom/
hXXp://hack-games-vk.ru/forum/2-chity-dlia-igr-vkcom/
hXXp://85.25.118.169/VK3/get_profile.php/
hXXp://85.25.118.169/VK3/get_profile.php/
auth_key!
auth_key!
hXXp://85.25.118.169/VK3/set_name.php
hXXp://85.25.118.169/VK3/set_name.php
hXXp://85.25.118.169/VK2/everyday_bonus.php/
hXXp://85.25.118.169/VK2/everyday_bonus.php/
hXXp://85.25.118.169/VK3/modify_map_name.php
hXXp://85.25.118.169/VK3/modify_map_name.php
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
If you have a key for this skin, please insert it in the KeyList.
If you have a key for this skin, please insert it in the KeyList.
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
GetCPInfo
GetCPInfo
version.dll
version.dll
SetViewportOrgEx
SetViewportOrgEx
GetViewportOrgEx
GetViewportOrgEx
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
SetKeyboardState
SetKeyboardState
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
EnumChildWindows
EnumChildWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
ShellExecuteA
ShellExecuteA
wininet.dll
wininet.dll
; ;$;(;,;0;4;8;
; ;$;(;,;0;4;8;
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
5#5'5 5/535
5#5'5 5/535
3!4%4)4-41454
3!4%4)4-41454
4 4(4@4]4
4 4(4@4]4
=$=4=
=$=4=
= =$=(=,=0=4=8=;>
= =$=(=,=0=4=8=;>
1-191O1}1
1-191O1}1
4#4'4 4/444
4#4'4 4/444
4(5,5054585
4(5,5054585
6#6'6 606
6#6'6 606
7Å’9
7Å’9
3"4-454D4X4f4n4}4
3"4-454D4X4f4n4}4
8 8$8(8,8
8 8$8(8,8
;0,2
;0,2
: :$:(:,:0:
: :$:(:,:0:
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
9 9$9(9,909
9 9$9(9,909
2/33373
2/33373
>%>0>8>~>
>%>0>8>~>
11p142
11p142
8 8&8?8[8
8 8&8?8[8
1)1-111P1T1X1y1}1
1)1-111P1T1X1y1}1
6"6&6*6.62666:6
6"6&6*6.62666:6
7 7$7(7,70747:7
7 7$7(7,70747:7
333333333333333333
333333333333333333
33333833
33333833
3333339
3333339
3333333333333338
3333333333333338
:*"*"$3338
:*"*"$3338
33333333
33333333
33333333333
33333333333
3333333333338
3333333333338
33338?383
33338?383
333333333333
333333333333
:*3:"$3338
:*3:"$3338
333333333333333
333333333333333
KWindows
KWindows
UrlMon
UrlMon
%sPopupClndr
%sPopupClndr
IdTCPStream
IdTCPStream
0IdHTTPHeaderInfo
0IdHTTPHeaderInfo
IdTCPServer
IdTCPServer
IdHTTPServer
IdHTTPServer
IdCustomHTTPServer
IdCustomHTTPServer
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
Icon.Data
Icon.Data
SkinData.SkinSection
SkinData.SkinSection
hack-games-vk.ru
hack-games-vk.ru
ProxyParams.BasicAuthentication
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
ProxyParams.ProxyPort
Request.ContentLength
Request.ContentLength
Request.ContentRangeEnd
Request.ContentRangeEnd
Request.ContentRangeStart
Request.ContentRangeStart
Request.Accept
Request.Accept
Request.BasicAuthentication
Request.BasicAuthentication
Request.UserAgent
Request.UserAgent
&Mozilla/3.0 (compatible; Indy Library)
&Mozilla/3.0 (compatible; Indy Library)
HTTPOptions
HTTPOptions
Glyph.Data
Glyph.Data
BoundLabel.Indent
BoundLabel.Indent
BoundLabel.Font.Charset
BoundLabel.Font.Charset
BoundLabel.Font.Color
BoundLabel.Font.Color
BoundLabel.Font.Height
BoundLabel.Font.Height
BoundLabel.Font.Name
BoundLabel.Font.Name
BoundLabel.Font.Style
BoundLabel.Font.Style
BoundLabel.Layout
BoundLabel.Layout
BoundLabel.MaxWidth
BoundLabel.MaxWidth
BoundLabel.UseSkinColor
BoundLabel.UseSkinColor
auth_key
auth_key
: VVV.hack-games-vk.ru
: VVV.hack-games-vk.ru
sSkinManager1 AnimEffects.BlendOnMoving.Active
sSkinManager1 AnimEffects.BlendOnMoving.Active
AnimEffects.DialogShow.Time
AnimEffects.DialogShow.Time
AnimEffects.FormShow.Time
AnimEffects.FormShow.Time
AnimEffects.FormHide.Time
AnimEffects.FormHide.Time
AnimEffects.DialogHide.Time
AnimEffects.DialogHide.Time
AnimEffects.Minimizing.Time
AnimEffects.Minimizing.Time
ButtonsOptions.ShowFocusRect
ButtonsOptions.ShowFocusRect
V%Xs2l-yRo7Qn
V%Xs2l-yRo7Qn
Huge.bmp6
Huge.bmp6
L:Z.Nr
L:Z.Nr
g8~XkÄ
g8~XkÄ
Master.bmpLf
Master.bmpLf
.WScc
.WScc
Vi...ON
Vi...ON
l,.nBZJJ
l,.nBZJJ
jurl6
jurl6
CloseAG.png9
CloseAG.png9
CloseG.png
CloseG.png
MaxG.png
MaxG.png
MinG.png
MinG.png
NormG.png!
NormG.png!
MenuSupport.IcoLineSkin
MenuSupport.IcoLineSkin
ICOLINE!MenuSupport.ExtraLineFont.Charset
ICOLINE!MenuSupport.ExtraLineFont.Charset
MenuSupport.ExtraLineFont.Color
MenuSupport.ExtraLineFont.Color
clWindowText MenuSupport.ExtraLineFont.Height
clWindowText MenuSupport.ExtraLineFont.Height
MenuSupport.ExtraLineFont.Name
MenuSupport.ExtraLineFont.Name
MenuSupport.ExtraLineFont.Style
MenuSupport.ExtraLineFont.Style
C:\Skins
C:\Skins
ThirdParty.ThirdEdits
ThirdParty.ThirdEdits
THotKey
THotKey
TJvHotKey
TJvHotKey
TRzHotKeyEdit
TRzHotKeyEdit
ThirdParty.ThirdButtons
ThirdParty.ThirdButtons
ThirdParty.ThirdBitBtns
ThirdParty.ThirdBitBtns
ThirdParty.ThirdCheckBoxes
ThirdParty.ThirdCheckBoxes
ThirdParty.ThirdGroupBoxes
ThirdParty.ThirdGroupBoxes
ThirdParty.ThirdListViews
ThirdParty.ThirdListViews
ThirdParty.ThirdPanels
ThirdParty.ThirdPanels
ThirdParty.ThirdGrids
ThirdParty.ThirdGrids
ThirdParty.ThirdTreeViews
ThirdParty.ThirdTreeViews
ThirdParty.ThirdComboBoxes
ThirdParty.ThirdComboBoxes
TwwTempKeyCombo
TwwTempKeyCombo
ThirdParty.ThirdWWEdits
ThirdParty.ThirdWWEdits
ThirdParty.ThirdVirtualTrees
ThirdParty.ThirdVirtualTrees
ThirdParty.ThirdGridEh
ThirdParty.ThirdGridEh
ThirdParty.ThirdPageControl
ThirdParty.ThirdPageControl
ThirdParty.ThirdTabControl
ThirdParty.ThirdTabControl
ThirdParty.ThirdToolBar
ThirdParty.ThirdToolBar
ThirdParty.ThirdStatusBar
ThirdParty.ThirdStatusBar
ThirdParty.ThirdSpeedButton
ThirdParty.ThirdSpeedButton
ThirdParty.ThirdScrollControl
ThirdParty.ThirdScrollControl
ThirdParty.ThirdUpDown
ThirdParty.ThirdUpDown
ThirdParty.ThirdScrollBar
ThirdParty.ThirdScrollBar
ThirdParty.ThirdStaticText
ThirdParty.ThirdStaticText
ThirdParty.ThirdNativePaint
ThirdParty.ThirdNativePaint
AddedTitle.Font.Charset
AddedTitle.Font.Charset
AddedTitle.Font.Color
AddedTitle.Font.Color
AddedTitle.Font.Height
AddedTitle.Font.Height
AddedTitle.Font.Name
AddedTitle.Font.Name
AddedTitle.Font.Style
AddedTitle.Font.Style
FormHeader.AdditionalHeight
FormHeader.AdditionalHeight
Constraints.MinHeight
Constraints.MinHeight
Constraints.MinWidth
Constraints.MinWidth
TsShellTreeView
TsShellTreeView
sShellTreeView1
sShellTreeView1
sShellTreeView1Change
sShellTreeView1Change
BoundLabel.Active
BoundLabel.Active
BoundLabel.Caption
BoundLabel.Caption
VertScrollBar.Tracking
VertScrollBar.Tracking
KeyPreview
KeyPreview
OnKeyPress
OnKeyPress
Constraints.MaxHeight
Constraints.MaxHeight
Constraints.MaxWidth
Constraints.MaxWidth
GlyphMode.Blend
GlyphMode.Blend
GlyphMode.Grayed
GlyphMode.Grayed
Colors.Strings
Colors.Strings
Brush.Color
Brush.Color
Pen.Color
Pen.Color
Pen.Width
Pen.Width
Add to custom colors set8Listbox (%s) style must be virtual in order to set Count
Add to custom colors set8Listbox (%s) style must be virtual in order to set Count
Error setting %s.Count
Error setting %s.Count
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Could not load certificate.#Could not load key, check password.
Could not load certificate.#Could not load key, check password.
SSL status: "%s"
SSL status: "%s"
JPEG error #%d
JPEG error #%d
Command not supported.
Command not supported.
Address type not supported.$Error accepting connection with SSL.
Address type not supported.$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Error creating SSL context. Could not load root certificate.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Protocol not supported.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Protocol family not supported.0Address family not supported by protocol family.
Chunk StartedDThis authentication method is already registered with class name %s.
Chunk StartedDThis authentication method is already registered with class name %s.
%s is not a valid service.
%s is not a valid service.
Socket Error # %d
Socket Error # %d
%s is not a valid IP address.
%s is not a valid IP address.
Operation would block.
Operation would block.
Operation now in progress.
Operation now in progress.
Operation already in progress.
Operation already in progress.
Socket operation on non-socket.
Socket operation on non-socket.
No data to read.$Can not bind in port range (%d - %d)
No data to read.$Can not bind in port range (%d - %d)
Invalid Port Range (%d - %d)
Invalid Port Range (%d - %d)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Resolving hostname %s.
Connecting to %s.
Connecting to %s.
No help keyword specified.
No help keyword specified.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Invalid clipboard format Clipboard does not support Icons
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Cannot open clipboard/Menu '%s' is already being used by another form
Invalid input value7Invalid input value. Use escape key to abandon changes
Invalid input value7Invalid input value. Use escape key to abandon changes
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
$Operation not allowed on sorted list$%s not in a class registration group
$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)
Thread Error: %s (%d)
Unsupported clipboard format
Unsupported clipboard format
$''%s'' is not a valid component name
$''%s'' is not a valid component name
Invalid property element: %s
Invalid property element: %s
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented
%s.Seek not implemented
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Unable to write to %s
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
I/O error %d
Windows.exe_3188:
.text
.text
`.itext
`.itext
`.data
`.data
.idata
.idata
.rdata
.rdata
@.reloc
@.reloc
B.rsrc
B.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
%s_%d
%s_%d
EInvalidGraphicOperation
EInvalidGraphicOperation
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
%s, ClassID: %s
%s, ClassID: %s
%s, ProgID: "%s"
%s, ProgID: "%s"
ole32.dll
ole32.dll
TUploadFTP
TUploadFTP
user32.dll
user32.dll
1.2.3
1.2.3
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
127.0.0.1
127.0.0.1
TDCWebCam
TDCWebCam
wlanapi.dll
wlanapi.dll
80211_SHARED_KEY
80211_SHARED_KEY
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
explorer.exe
explorer.exe
USER32.DLL
USER32.DLL
uxtheme.dll
uxtheme.dll
DWMAPI.DLL
DWMAPI.DLL
clWebSnow
clWebSnow
clWebFloralWhite
clWebFloralWhite
clWebLavenderBlush
clWebLavenderBlush
clWebOldLace
clWebOldLace
clWebIvory
clWebIvory
clWebCornSilk
clWebCornSilk
clWebBeige
clWebBeige
clWebAntiqueWhite
clWebAntiqueWhite
clWebWheat
clWebWheat
clWebAliceBlue
clWebAliceBlue
clWebGhostWhite
clWebGhostWhite
clWebLavender
clWebLavender
clWebSeashell
clWebSeashell
clWebLightYellow
clWebLightYellow
clWebPapayaWhip
clWebPapayaWhip
clWebNavajoWhite
clWebNavajoWhite
clWebMoccasin
clWebMoccasin
clWebBurlywood
clWebBurlywood
clWebAzure
clWebAzure
clWebMintcream
clWebMintcream
clWebHoneydew
clWebHoneydew
clWebLinen
clWebLinen
clWebLemonChiffon
clWebLemonChiffon
clWebBlanchedAlmond
clWebBlanchedAlmond
clWebBisque
clWebBisque
clWebPeachPuff
clWebPeachPuff
clWebTan
clWebTan
clWebYellow
clWebYellow
clWebDarkOrange
clWebDarkOrange
clWebRed
clWebRed
clWebDarkRed
clWebDarkRed
clWebMaroon
clWebMaroon
clWebIndianRed
clWebIndianRed
clWebSalmon
clWebSalmon
clWebCoral
clWebCoral
clWebGold
clWebGold
clWebTomato
clWebTomato
clWebCrimson
clWebCrimson
clWebBrown
clWebBrown
clWebChocolate
clWebChocolate
clWebSandyBrown
clWebSandyBrown
clWebLightSalmon
clWebLightSalmon
clWebLightCoral
clWebLightCoral
clWebOrange
clWebOrange
clWebOrangeRed
clWebOrangeRed
clWebFirebrick
clWebFirebrick
clWebSaddleBrown
clWebSaddleBrown
clWebSienna
clWebSienna
clWebPeru
clWebPeru
clWebDarkSalmon
clWebDarkSalmon
clWebRosyBrown
clWebRosyBrown
clWebPaleGoldenrod
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebLightGoldenrodYellow
clWebOlive
clWebOlive
clWebForestGreen
clWebForestGreen
clWebGreenYellow
clWebGreenYellow
clWebChartreuse
clWebChartreuse
clWebLightGreen
clWebLightGreen
clWebAquamarine
clWebAquamarine
clWebSeaGreen
clWebSeaGreen
clWebGoldenRod
clWebGoldenRod
clWebKhaki
clWebKhaki
clWebOliveDrab
clWebOliveDrab
clWebGreen
clWebGreen
clWebYellowGreen
clWebYellowGreen
clWebLawnGreen
clWebLawnGreen
clWebPaleGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumAquamarine
clWebMediumSeaGreen
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkOliveGreen
clWebDarkgreen
clWebDarkgreen
clWebLimeGreen
clWebLimeGreen
clWebLime
clWebLime
clWebSpringGreen
clWebSpringGreen
clWebMediumSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebPaleTurquoise
clWebLightCyan
clWebLightCyan
clWebLightBlue
clWebLightBlue
clWebLightSkyBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebDarkBlue
clWebIndigo
clWebIndigo
clWebMediumTurquoise
clWebMediumTurquoise
clWebTurquoise
clWebTurquoise
clWebCyan
clWebCyan
clWebPowderBlue
clWebPowderBlue
clWebSkyBlue
clWebSkyBlue
clWebRoyalBlue
clWebRoyalBlue
clWebMediumBlue
clWebMediumBlue
clWebMidnightBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebDarkTurquoise
clWebCadetBlue
clWebCadetBlue
clWebDarkCyan
clWebDarkCyan
clWebTeal
clWebTeal
clWebDeepskyBlue
clWebDeepskyBlue
clWebDodgerBlue
clWebDodgerBlue
clWebBlue
clWebBlue
clWebNavy
clWebNavy
clWebDarkViolet
clWebDarkViolet
clWebDarkOrchid
clWebDarkOrchid
clWebMagenta
clWebMagenta
clWebDarkMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebMediumVioletRed
clWebPaleVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebBlueViolet
clWebMediumOrchid
clWebMediumOrchid
clWebMediumPurple
clWebMediumPurple
clWebPurple
clWebPurple
clWebDeepPink
clWebDeepPink
clWebLightPink
clWebLightPink
clWebViolet
clWebViolet
clWebOrchid
clWebOrchid
clWebPlum
clWebPlum
clWebThistle
clWebThistle
clWebHotPink
clWebHotPink
clWebPink
clWebPink
clWebLightSteelBlue
clWebLightSteelBlue
clWebMediumSlateBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebLightSlateGray
clWebWhite
clWebWhite
clWebLightgrey
clWebLightgrey
clWebGray
clWebGray
clWebSteelBlue
clWebSteelBlue
clWebSlateBlue
clWebSlateBlue
clWebSlateGray
clWebSlateGray
clWebWhiteSmoke
clWebWhiteSmoke
clWebSilver
clWebSilver
clWebDimGray
clWebDimGray
clWebMistyRose
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlateBlue
clWebDarkSlategray
clWebDarkSlategray
clWebGainsboro
clWebGainsboro
clWebDarkGray
clWebDarkGray
clWebBlack
clWebBlack
comctl32.dll
comctl32.dll
AutoHotkeys
AutoHotkeys
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
OnKeyDown$
OnKeyDown$
OnKeyPress
OnKeyPress
OnKeyUp
OnKeyUp
Uhx%F
Uhx%F
UhX%F
UhX%F
Uh %F
Uh %F
GlassFrame.Bottom
GlassFrame.Bottom
GlassFrame.Enabled
GlassFrame.Enabled
GlassFrame.Left
GlassFrame.Left
GlassFrame.Right
GlassFrame.Right
GlassFrame.SheetOfGlass
GlassFrame.SheetOfGlass
GlassFrame.Top
GlassFrame.Top
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
User32.dll
User32.dll
PSAPI.dll
PSAPI.dll
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
*.torrent
*.torrent
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hkey
hkey
cmd.exe
cmd.exe
TSocketPort
TSocketPort
%d.%d.%d.%d
%d.%d.%d.%d
0.0.0.0
0.0.0.0
POST /index.php/1.0
POST /index.php/1.0
BTRESULTHTTP Flood|Http Flood task finished!|
BTRESULTHTTP Flood|Http Flood task finished!|
BTRESULTVisit URL|finished to visit
BTRESULTVisit URL|finished to visit
BTERRORVisit URL|An exception occured in the thread|
BTERRORVisit URL|An exception occured in the thread|
PortScanAdd
PortScanAdd
BTRESULTUDP Flood|UDP Flood task finished!|
BTRESULTUDP Flood|UDP Flood task finished!|
FTPPORT
FTPPORT
FTPPASS
FTPPASS
FTPUSER
FTPUSER
FTPHOST
FTPHOST
FTPROOT
FTPROOT
FTPUPLOADK
FTPUPLOADK
FTPSIZE
FTPSIZE
TCaptureWebcam
TCaptureWebcam
taskmgr.exe
taskmgr.exe
ERR|Cannot listen to port, try another one..|
ERR|Cannot listen to port, try another one..|
UPLOADEXEC
UPLOADEXEC
UPANDEXEC
UPANDEXEC
PASSWORD
PASSWORD
out.txt
out.txt
tmp.txt
tmp.txt
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
127.0.0.1:1604
127.0.0.1:1604
#KCMDDC51#-
#KCMDDC51#-
5.3.0
5.3.0
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
DC3_FEXEC
DC3_FEXEC
Windows NT 4.0
Windows NT 4.0
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows Server 2003
Windows Server 2003
Windows Vista
Windows Vista
Windows 7
Windows 7
Windows 95
Windows 95
Windows 98
Windows 98
Windows Me
Windows Me
S-%u-
S-%u-
Mozilla
Mozilla
BTRESULTDownload File|Mass Download : File Downloaded , Executing new one in temp dir...|
BTRESULTDownload File|Mass Download : File Downloaded , Executing new one in temp dir...|
BTERRORDownload File| Error on downloading file check if you type the correct url...|
BTERRORDownload File| Error on downloading file check if you type the correct url...|
notepad.exe
notepad.exe
KEYNAME
KEYNAME
%ShortCut#
%ShortCut#
RELATEDCMD
RELATEDCMD
ping 127.0.0.1 -n 4 > NUL && "
ping 127.0.0.1 -n 4 > NUL && "
DRKey
DRKey
CRKey
CRKey
DelMSKey
DelMSKey
InstallHKEY
InstallHKEY
ActiveOnlineKeylogger
ActiveOnlineKeylogger
UnActiveOnlineKeylogger
UnActiveOnlineKeylogger
KeylogOn
KeylogOn
ActiveOfflineKeylogger
ActiveOfflineKeylogger
UnActiveOfflineKeylogger
UnActiveOfflineKeylogger
ActiveOnlineKeyStrokes
ActiveOnlineKeyStrokes
UnActiveOnlineKeyStrokes
UnActiveOnlineKeyStrokes
OpenWebPage
OpenWebPage
tmpprint.txt
tmpprint.txt
URLUpdate
URLUpdate
MSGBOX
MSGBOX
#BOT#VisitUrl
#BOT#VisitUrl
#BOT#OpenUrl
#BOT#OpenUrl
HTTP://
HTTP://
hXXp://
hXXp://
BTRESULTOpen URL|
BTRESULTOpen URL|
Command successfully executed!|
Command successfully executed!|
#BOT#URLUpdate
#BOT#URLUpdate
BTERRORUpdate from URL| Error on downloading file check if you type the correct url...|
BTERRORUpdate from URL| Error on downloading file check if you type the correct url...|
BTRESULTUpdate from URL|Update : File Downloaded , Executing new one in temp dir...|
BTRESULTUpdate from URL|Update : File Downloaded , Executing new one in temp dir...|
#BOT#URLDownload
#BOT#URLDownload
GetActivePorts
GetActivePorts
DDOSHTTPFLOOD
DDOSHTTPFLOOD
DDOSUDPFLOOD
DDOSUDPFLOOD
%IPPORTSCAN
%IPPORTSCAN
SAPI.SpVoice
SAPI.SpVoice
WEBCAMLIVE
WEBCAMLIVE
WEBCAMSTOP
WEBCAMSTOP
FTPFILEUPLOAD
FTPFILEUPLOAD
URLDOWNLOADTOFILE
URLDOWNLOADTOFILE
FAKEMSG
FAKEMSG
MSGICON
MSGICON
MSGTITLE
MSGTITLE
MSGCORE
MSGCORE
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
C:\Users\"%CurrentUserName%"\AppData\Roaming\dclogs\2016-12-03-7.dc
C:\Users\"%CurrentUserName%"\AppData\Roaming\dclogs\2016-12-03-7.dc
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
GetKeyboardType
GetKeyboardType
keybd_event
keybd_event
VkKeyScanA
VkKeyScanA
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
EnumChildWindows
EnumChildWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
version.dll
version.dll
WinExec
WinExec
PeekNamedPipe
PeekNamedPipe
GetWindowsDirectoryA
GetWindowsDirectoryA
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
CreatePipe
CreatePipe
RegQueryInfoKeyA
RegQueryInfoKeyA
RegOpenKeyA
RegOpenKeyA
RegFlushKey
RegFlushKey
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCreateKeyA
RegCreateKeyA
netapi32.dll
netapi32.dll
shell32.dll
shell32.dll
ShellExecuteExA
ShellExecuteExA
ShellExecuteA
ShellExecuteA
SHFileOperationA
SHFileOperationA
gdiplus.dll
gdiplus.dll
GdiplusShutdown
GdiplusShutdown
winmm.dll
winmm.dll
URLMON.DLL
URLMON.DLL
URLDownloadToFileA
URLDownloadToFileA
wininet.dll
wininet.dll
InternetOpenUrlA
InternetOpenUrlA
HttpQueryInfoA
HttpQueryInfoA
FtpPutFileA
FtpPutFileA
wsock32.dll
wsock32.dll
msacm32.dll
msacm32.dll
SHFolder.dll
SHFolder.dll
WS2_32.DLL
WS2_32.DLL
ntdll.dll
ntdll.dll
SHELL32.DLL
SHELL32.DLL
AVICAP32.DLL
AVICAP32.DLL
1!1,1=1|1
1!1,1=1|1
=#='= =/=3=7=;=?=
=#='= =/=3=7=;=?=
3 3$3(3,3034383
3 3$3(3,3034383
:":-:2:=:
:":-:2:=:
3 3$3(3,3
3 3$3(3,3
1)161`1}1
1)161`1}1
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
UntKeylogger
UntKeylogger
KWindows
KWindows
UntActivePorts
UntActivePorts
UntControlKey
UntControlKey
UntCaptureWebcam
UntCaptureWebcam
UntWebCam
UntWebCam
UrlMon
UrlMon
(UntUploadFTPThread
(UntUploadFTPThread
UntFTP
UntFTP
_UntUDPFlood
_UntUDPFlood
YUntScanPorts
YUntScanPorts
0UntPasswordAndData
0UntPasswordAndData
XUntHTTPFlood
XUntHTTPFlood
UntCPU
UntCPU
66006666
66006666
No help found for %s#No context-sensitive help installed
No help found for %s#No context-sensitive help installed
No help found for context$No topic-based help system installedNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
No help found for context$No topic-based help system installedNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid clipboard format Clipboard does not support Icons
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Cannot open clipboard/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active$%s not in a class registration group
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)
Thread Error: %s (%d)
Unsupported clipboard format
Unsupported clipboard format
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to create key %s
Failed to create key %s
Failed to get data for '%s'
Failed to get data for '%s'
Failed to set data for '%s'
Failed to set data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
%s.Seek not implemented$Operation not allowed on sorted list
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
External exception %x
External exception %x
Interface not supported
Interface not supported
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
!'%s' is not a valid integer value('%s' is not a valid floating point value!'%s' is not a valid date and time
!'%s' is not a valid integer value('%s' is not a valid floating point value!'%s' is not a valid date and time
'%s' is not a valid GUID value
'%s' is not a valid GUID value
I/O error %d
I/O error %d
1, 0, 0, 1
1, 0, 0, 1
MSRSAAP.EXE
MSRSAAP.EXE
4, 0, 0, 0
4, 0, 0, 0
notepad.exe_3144:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
GDI32.dll
GDI32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
COMDLG32.dll
COMDLG32.dll
SHELL32.dll
SHELL32.dll
WINSPOOL.DRV
WINSPOOL.DRV
ole32.dll
ole32.dll
SHLWAPI.dll
SHLWAPI.dll
COMCTL32.dll
COMCTL32.dll
OLEAUT32.dll
OLEAUT32.dll
VERSION.dll
VERSION.dll
ntdll.dll
ntdll.dll
RegCloseKey
RegCloseKey
RegCreateKeyW
RegCreateKeyW
RegOpenKeyExW
RegOpenKeyExW
GetProcessHeap
GetProcessHeap
SetViewportExtEx
SetViewportExtEx
GetKeyboardLayout
GetKeyboardLayout
_amsg_exit
_amsg_exit
_acmdln
_acmdln
ShellExecuteExW
ShellExecuteExW
notepad.pdb
notepad.pdb
name="Microsoft.Windows.Shell.notepad"
name="Microsoft.Windows.Shell.notepad"
version="5.1.0.0"
version="5.1.0.0"
Windows Shell
Windows Shell
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
true
true
===111*!
===111*!
'141133!/!(!(!""/""
'141133!/!(!(!""/""
;;;;4;3423332
;;;;4;3423332
keYM
keYM
,k<.kq>
,k<.kq>
.WF"hB
.WF"hB
dx.Rl
dx.Rl
V.xOx_T
V.xOx_T
/.SETUP
/.SETUP
%s%c*.txt%c%s%c*.*%c
%s%c*.txt%c%s%c*.*%c
*.txt
*.txt
mshelp://windows/?id=5d18d5fb-e737-4a73-b6cc-dccc63720231
mshelp://windows/?id=5d18d5fb-e737-4a73-b6cc-dccc63720231
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\OriginalFilename
\sppsvc.exe
\sppsvc.exe
\slui.exe
\slui.exe
\sppuinotify.dll
\sppuinotify.dll
Text Documents (*.txt)
Text Documents (*.txt)
6.1.7600.16385 (win7_rtm.090713-1255)
6.1.7600.16385 (win7_rtm.090713-1255)
NOTEPAD.EXE
NOTEPAD.EXE
Windows
Windows
Operating System
Operating System
6.1.7600.16385
6.1.7600.16385
notepad.exe_3144_rwx_00060000_00001000:
kernel32.dll
kernel32.dll
notepad.exe_3144_rwx_00070000_00001000:
user32.dll
user32.dll
notepad.exe_3144_rwx_001A0000_00001000:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSDCSC\Windows.exe