Trojan.Win32.Jorik.Llac.eli (Kaspersky), Gen:Variant.Barys.120 (B) (Emsisoft), Gen:Variant.Barys.120 (AdAware), Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, WormRebhip.YR, GenericAutorunWorm.YR, GenericInjector.YR (Lavasoft MAS)Behaviour: Banker, Trojan, Worm, VirTool, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 5bd44d941dfd1ba615f752f9969edfea
SHA1: 869e839a68f9b5f83711f3109b71d3b1691c749b
SHA256: 328a6ca1fb2aa9f69952d95f82696e365ab20069aa46a1008b13942ba2528274
SSDeep: 49152:RgHfJt7R5STlTxVTNHousDKe88U/k6Pu8h5KLMFX/CslMZs8oX4PSPFsJDAUNFn7:s
Size: 9616502 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2012-02-22 06:19:45
Analyzed on: WindowsXP SP3 32-bit
Summary: Banker. Steals data relating to online banking systems, e-payment systems and credit card systems.
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The Trojan creates the following process(es):
vbc.exe:164
vbc.exe:896
vbc.exe:1952
The Trojan injects its code into the following process(es):
vbc.exe:1876
%original file name%.exe:540
SpyNet 2.7 Final.exe:680
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process vbc.exe:1876 makes changes in the file system.
The Trojan deletes the following file(s):
%WinDir%\Microsoft.NET\Framework\v2.0.50727\chro.dat (0 bytes)
%WinDir%\Microsoft.NET\Framework\v2.0.50727\ffox.dat (0 bytes)
%WinDir%\Microsoft.NET\Framework\v2.0.50727\iexp.dat (0 bytes)
The process vbc.exe:164 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\Microsoft.NET\Framework\v2.0.50727\ffox.dat (2 bytes)
The process vbc.exe:896 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\Microsoft.NET\Framework\v2.0.50727\chro.dat (2 bytes)
The process %original file name%.exe:540 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\SpyNet 2.7 Final.exe (15021 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\WinUpdate.exe (71723 bytes)
The process SpyNet 2.7 Final.exe:680 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Language\Default.ini (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\sqlite3.dll (175 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Settings\Settings.ini (1 bytes)
Registry activity
The process vbc.exe:1876 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B6 2D 11 78 A2 72 A8 E4 A7 5D C0 B9 9D 96 2D 76"
The process vbc.exe:164 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "28 A7 E5 D7 98 B1 54 33 88 63 2D 35 BA E7 EC 8B"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
The process vbc.exe:896 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6C D3 DD CC C3 EE CB 5A 58 03 DA 59 6C 64 7F 92"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The process vbc.exe:1952 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0A 8C B9 87 69 24 F7 C5 F4 B2 86 F3 82 11 42 BA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The process %original file name%.exe:540 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E7 92 52 F5 36 FA 43 2A CD 96 5E C5 88 12 8B AE"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Local Settings\Temp]
"SpyNet 2.7 Final.exe" = "SpyNet 2.7 Final"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"WinUpdate" = "%Documents and Settings%\%current user%\Local Settings\Temp\WinUpdate.exe"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The process SpyNet 2.7 Final.exe:680 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2D 19 F3 B7 B3 AC 89 77 A1 8A 88 BF 6E D7 3D 50"
Dropped PE files
MD5 | File path |
---|---|
f7a8e99f27e8caf794c571de5d47cef6 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SpyNet 2.7 Final.exe |
744dcc4cbbfbb18fe3878c4e769ec48f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\sqlite3.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
vbc.exe:164
vbc.exe:896
vbc.exe:1952 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%WinDir%\Microsoft.NET\Framework\v2.0.50727\ffox.dat (2 bytes)
%WinDir%\Microsoft.NET\Framework\v2.0.50727\chro.dat (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SpyNet 2.7 Final.exe (15021 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\WinUpdate.exe (71723 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Language\Default.ini (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\sqlite3.dll (175 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Settings\Settings.ini (1 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"WinUpdate" = "%Documents and Settings%\%current user%\Local Settings\Temp\WinUpdate.exe" - Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Microsoft
Product Name: 2012 Service
Product Version: 1.0.0.0
Legal Copyright: Copyright (c) Microsoft 2012
Legal Trademarks:
Original Filename: 2012 Service.exe
Internal Name: 2012 Service.exe
File Version: 1.0.0.0
File Description: 2012 Service
Comments:
Language: Language Neutral
Company Name: MicrosoftProduct Name: 2012 ServiceProduct Version: 1.0.0.0Legal Copyright: Copyright (c) Microsoft 2012Legal Trademarks: Original Filename: 2012 Service.exeInternal Name: 2012 Service.exeFile Version: 1.0.0.0File Description: 2012 ServiceComments: Language: Language Neutral
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 8192 | 71564 | 71680 | 4.55107 | 8e9965fc7dcd55fc943139bdf14d8273 |
.rsrc | 81920 | 138460 | 138752 | 2.38714 | fad766b0bf7516d07c4fc949e6c7a2fd |
.reloc | 221184 | 12 | 512 | 0.070639 | 97a3a5f060715fdd6037b6cfa84448ff |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
vbc.exe_1876:
`.rsrc
`.rsrc
'6'Wr%SdLR
'6'Wr%SdLR
WVBA6.DLL
WVBA6.DLL
?PASSWORDS_OPRA
?PASSWORDS_OPRA
VBA6.DLL
VBA6.DLL
PASSWORDS_OPRA
PASSWORDS_OPRA
PASSWORDS_CDKEY
PASSWORDS_CDKEY
C:\xampp\htdocs\recovery\VB6.OLB
C:\xampp\htdocs\recovery\VB6.OLB
ReadKey
ReadKey
PASSWORDS_MESS
PASSWORDS_MESS
PASSWORDS_MAIL
PASSWORDS_MAIL
PASSWORDS_DIAL
PASSWORDS_DIAL
PASSWORDS_CHRO
PASSWORDS_CHRO
PASSWORDS_IEXP
PASSWORDS_IEXP
PASSWORDS_FFOX
PASSWORDS_FFOX
PASSWORDS_PRODKEY
PASSWORDS_PRODKEY
PASSWORDS_PTSG
PASSWORDS_PTSG
PASSWORDS_OFFC
PASSWORDS_OFFC
WINDOWS_VERSION_FULL
WINDOWS_VERSION_FULL
RegCloseKey
RegCloseKey
RegOpenKeyA
RegOpenKeyA
advapi32.dll
advapi32.dll
txtPassword
txtPassword
imgLoginPressed
imgLoginPressed
imgLogin
imgLogin
[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`
[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`
568568568568\]_
568568568568\]_
\]_568568568
\]_568568568
:- :- :- ;. ;. ;. <.>0">0">1"?1"?1#?1#@2#@2#@2#A2#A3$A3$B3$B3$B4$C4ÄÄÕÕÕå&E6&E6&F6&F7&F7'G7'G7'G8'H8'H8'H8(I9(I9(I9(J9(J:)J:)K:)K:)K;)L;)L;*L;*M O> P>,P>,P?,Q?,Q?,Q?-R@-R@-R@-S@-SA.SA.TA.TA.TB.UB.UB/UB/VC/VC/VC/WC0WD0WD0XD0XE0XE0YE1YE1YF1ZF1ZF1ZF2[G2[G2[G2\G2\H2\H3]H3]H3]I3^I3^I4^I4_J4_J4_J4`K4`K5`K5aK5aL5aL5bL6bL6bM6cM6cM6cM6dN7dN7dN7eN7eO7eO8fO8fO8fP8gP8gP9gP9hQ9hQ9hQ9iR9iR:iR:jR:jS:jS:kS;kS;kT;lT;lT;lT;mUqX>qX>qX>rY>rY?rY?sY?sZ?sZ?tZ?tZ@t[@u[@u[@u[@v\Av\Av\Aw\Aw]Aw]Ax]Bx]Bx^By^By^By^Cz_Cz_Cz_C{`C{`D{`D|`D|aD|aD}aD}aE}bE~bE~bE~bE
:- :- :- ;. ;. ;. <.>0">0">1"?1"?1#?1#@2#@2#@2#A2#A3$A3$B3$B3$B4$C4ÄÄÕÕÕå&E6&E6&F6&F7&F7'G7'G7'G8'H8'H8'H8(I9(I9(I9(J9(J:)J:)K:)K:)K;)L;)L;*L;*M O> P>,P>,P?,Q?,Q?,Q?-R@-R@-R@-S@-SA.SA.TA.TA.TB.UB.UB/UB/VC/VC/VC/WC0WD0WD0XD0XE0XE0YE1YE1YF1ZF1ZF1ZF2[G2[G2[G2\G2\H2\H3]H3]H3]I3^I3^I4^I4_J4_J4_J4`K4`K5`K5aK5aL5aL5bL6bL6bM6cM6cM6cM6dN7dN7dN7eN7eO7eO8fO8fO8fP8gP8gP9gP9hQ9hQ9hQ9iR9iR:iR:jR:jS:jS:kS;kS;kT;lT;lT;lT;mUqX>qX>qX>rY>rY?rY?sY?sZ?sZ?tZ?tZ@t[@u[@u[@u[@v\Av\Av\Aw\Aw]Aw]Ax]Bx]Bx^By^By^By^Cz_Cz_Cz_C{`C{`D{`D|`D|aD|aD}aD}aE}bE~bE~bE~bE
568568568568
568568568568
568568568568568
568568568568568
5Vm568568568568568568568568568568568impORTORTORTORTORT
5Vm568568568568568568568568568568568impORTORTORTORTORT
568568568
568568568
5Vm568568568568568568568568568568impORTORTORTORTORT
5Vm568568568568568568568568568568impORTORTORTORTORT
568568568568568568568568568568568impORTORTORTORTORT
568568568568568568568568568568568impORTORTORTORTORT
568568568568|
568568568568|
y56Pi_P\ly|voL_o568|voL_o568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568HKM568568568568568568568568568568impORTORTORTORTORT
y56Pi_P\ly|voL_o568|voL_o568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568HKM568568568568568568568568568568impORTORTORTORTORT
568568568\68
568568568\68
56`568568568
56`568568568
5_|568568
5_|568568
5_|\68\{|568568
5_|\68\{|568568
5_|568\68
5_|568\68
79;5685685685685689;>
79;5685685685685689;>
79
79
;
;
;=?;=?;=@78
;=?;=?;=@78
457568568568569
457568568568569
:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=
:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=
:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>
:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?
;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?
=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@
=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@
5_|568568568568568
5_|568568568568568
568568\68
568568\68
56`568568
56`568568
5_|568568\68
5_|568568\68
568568568568\68
568568568568\68
hKey
hKey
CodeKey
CodeKey
.Qs]W6"s
.Qs]W6"s
E%6u:
E%6u:
Txxgu^WD
Txxgu^WD
{>P.CP
{>P.CP
.YP-_
.YP-_
R.nU5
R.nU5
QudP~
QudP~
6 (.IS
6 (.IS
?Z.su
?Z.su
%0uRP
%0uRP
I5.Jj
I5.Jj
4T-'.sB
4T-'.sB
%xH{p
%xH{p
%2u'O
%2u'O
B.kB36~9
B.kB36~9
]2,%F{E
]2,%F{E
_.jqn
_.jqn
K.jSZ
K.jSZ
eG.Fu
eG.Fu
`.zGS
`.zGS
%xYL}
%xYL}
3w.Jg
3w.Jg
'K
'K
.TBPSAU30
.TBPSAU30
%U%Epy%
%U%Epy%
.blf8
.blf8
C.wtm
C.wtm
P1"".qz
P1"".qz
Z{-t}p
Z{-t}p
~u&E%CkJ
~u&E%CkJ
.EHPg
.EHPg
.yR:$4
.yR:$4
)8|.Wi
)8|.Wi
5#1AG%U
5#1AG%U
.rsrc
.rsrc
kEYL
kEYL
)u3SSh#
)u3SSh#
.Toh\5H
.Toh\5H
"Account","Login Name
"Account","Login Name
Password
Password
Web Sit
Web Sit
##%%&&))**,,//11224477
##%%&&))**,,//11224477
z:\Jj
z:\Jj
.pdb?P
.pdb?P
%""!!!!"
%""!!!!"
36333222("
36333222("
"&(((''''&
"&(((''''&
55553333(
55553333(
77555555
77555555
(3331110*
(3331110*
.@@@????
.@@@????
KERNEL32.DLL
KERNEL32.DLL
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
comdlg32.dll
comdlg32.dll
GDI32.dll
GDI32.dll
msvcrt.dll
msvcrt.dll
ole32.dll
ole32.dll
SHELL32.dll
SHELL32.dll
USER32.dll
USER32.dll
VERSION.dll
VERSION.dll
jE-.viCh4
jE-.viCh4
.hp!J"
.hp!J"
].Rbl
].Rbl
.text
.text
`.data
`.data
]_qÃ
]_qÃ
MSVBVM60.DLL
MSVBVM60.DLL
*\AC:\xampp\htdocs\recovery\Project1.vbp
*\AC:\xampp\htdocs\recovery\Project1.vbp
\chro.dat
\chro.dat
HKEY_CURRENT_USER\Software\IMVU\username\
HKEY_CURRENT_USER\Software\IMVU\username\
HKEY_CURRENT_USER\Software\IMVU\password\
HKEY_CURRENT_USER\Software\IMVU\password\
\FileZilla\recentservers.xml
\FileZilla\recentservers.xml
\mess.dat
\mess.dat
WScript.shell
WScript.shell
\mail.dat
\mail.dat
Password
Password
\dial.dat
\dial.dat
Action URL
Action URL
Chrome
Chrome
\iexp.dat
\iexp.dat
\ffox.dat
\ffox.dat
Web Site
Web Site
FireFox
FireFox
\opra.dat
\opra.dat
Opera
Opera
CD-KEY
CD-KEY
CDKEY:
CDKEY:
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
PRODKEY:
PRODKEY:
\ptsg.dat
\ptsg.dat
\offc.dat
\offc.dat
Product Key
Product Key
\steam\steam.exe
\steam\steam.exe
WScript.Shell
WScript.Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
WINDOWS VERSION:
WINDOWS VERSION:
00000000
00000000
steam.exe
steam.exe
@*\AC:\xampp\htdocs\recovery\Project1.vbp
@*\AC:\xampp\htdocs\recovery\Project1.vbp
OperaPassView
OperaPassView
OperaPassView.exe
OperaPassView.exe
h4ck3rs-41.exe
h4ck3rs-41.exe
SpyNet 2.7 Final.exe_680:
`.rsrc
`.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s[%d]
%s[%d]
%s_%d
%s_%d
.Owner
.Owner
EInvalidGraphicOperation
EInvalidGraphicOperation
comctl32.dll
comctl32.dll
USER32.DLL
USER32.DLL
windows
windows
uxtheme.dll
uxtheme.dll
%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s
Proportional
Proportional
MAPI32.DLL
MAPI32.DLL
OnExit\%D
OnExit\%D
msShiftSelect
msShiftSelect
OnKeyDownL
OnKeyDownL
OnKeyPress
OnKeyPress
OnKeyUp$
OnKeyUp$
OnKeyUpx
OnKeyUpx
ArrowKeys
ArrowKeys
vsReport
vsReport
acoUpDownKeyDropsList
acoUpDownKeyDropsList
OnKeyUp
OnKeyUp
RICHED32.DLL
RICHED32.DLL
TComboBoxExEnumerator
TComboBoxExEnumerator
ole32.dll
ole32.dll
PasswordChar
PasswordChar
ssHorizontal
ssHorizontal
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeywordh
HelpKeywordh
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
AutoHotkeys
AutoHotkeys
Uh.dH
Uh.dH
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
getservbyport
getservbyport
WSAAsyncGetServByPort
WSAAsyncGetServByPort
WSAJoinLeaf
WSAJoinLeaf
WS2_32.DLL
WS2_32.DLL
127.0.0.1
127.0.0.1
TIdSocketListWindows
TIdSocketListWindows
TIdStackWindowsU
TIdStackWindowsU
IdStackWindows
IdStackWindows
ftpTransfer
ftpTransfer
ftpReady
ftpReady
ftpAborted
ftpAborted
ClientPortMinT
ClientPortMinT
ClientPortMax
ClientPortMax
Port
Port
EIdCanNotBindPortInRange
EIdCanNotBindPortInRange
EIdInvalidPortRangeSVW
EIdInvalidPortRangeSVW
saUsernamePassword
saUsernamePassword
PasswordT
PasswordT
0.0.0.1
0.0.0.1
TIdTCPConnection
TIdTCPConnection
TIdTCPConnection\
TIdTCPConnection\
IdTCPConnection
IdTCPConnection
EIdTCPConnectionError
EIdTCPConnectionError
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\Indy\IdStrings.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\Indy\IdStrings.pas
TIdTCPServer
TIdTCPServer
IdTCPServer
IdTCPServer
CmdDelimiter
CmdDelimiter
TIdTCPServerConnection
TIdTCPServerConnection
DefaultPort
DefaultPort
OnExecute
OnExecute
EIdTCPServerError
EIdTCPServerError
EIdNoExecuteSpecified
EIdNoExecuteSpecified
LeftPopup
LeftPopup
TURLEvent
TURLEvent
msnAutoOpenURL
msnAutoOpenURL
OnURLClick0lK
OnURLClick0lK
hXXp://VVV.url.com/
hXXp://VVV.url.com/
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Resamplers.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Resamplers.pas
Reverse transformation is not implemented in %s.
Reverse transformation is not implemented in %s.
Forward transformation is not implemented in %s.
Forward transformation is not implemented in %s.
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32.pas
Unpaired TThreadPersistent.EndUpdate
Unpaired TThreadPersistent.EndUpdate
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Layers.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Layers.pas
OnKeyUp\uL
OnKeyUp\uL
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Image.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Image.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\imgutil.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\imgutil.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\Winskinini.pas
%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\Winskinini.pas
%s_%s
%s_%s
Uh.uM
Uh.uM
ttntpanel.unicodeclass
ttntpanel.unicodeclass
ttntsilentpaintpanel.unicodeclass
ttntsilentpaintpanel.unicodeclass
xcFastReport
xcFastReport
TWWKeyCombo=Combobox
TWWKeyCombo=Combobox
TWWTempKeyCombo=combobox
TWWTempKeyCombo=combobox
TO32DBFLEXEDIT=Edit
TO32DBFLEXEDIT=Edit
4.94.12.01
4.94.12.01
BUTTON.RADIO
BUTTON.RADIO
BUTTON.CHECKBOX
BUTTON.CHECKBOX
3333333
3333333
Progress.Chunk
Progress.Chunk
Tab.Pane
Tab.Pane
Trackbar.ThumbHorz
Trackbar.ThumbHorz
Trackbar.ThumbVert
Trackbar.ThumbVert
Trackbar.ThumbLeft
Trackbar.ThumbLeft
Trackbar.ThumbRight
Trackbar.ThumbRight
Trackbar.ThumbUp
Trackbar.ThumbUp
Trackbar.ThumbDown
Trackbar.ThumbDown
UpDown.Horz
UpDown.Horz
UpDown.Vert
UpDown.Vert
user32.dll
user32.dll
DisableProcessWindowsGhosting
DisableProcessWindowsGhosting
ShellExecuteA
ShellExecuteA
shell32.dll
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
http\shell\open\command
\Internet Explorer\iexplore.exe
\Internet Explorer\iexplore.exe
Portugal
Portugal
Turkey
Turkey
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
IP.txt
IP.txt
hXXp://VVV.ip-adress.com/
hXXp://VVV.ip-adress.com/
GetWindowsDirectoryA
GetWindowsDirectoryA
teste.vbs
teste.vbs
teste.txt
teste.txt
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
objFile.WriteLine(Info)
objFile.WriteLine(Info)
objFile.Close
objFile.Close
cscript.exe
cscript.exe
Windows 3.1
Windows 3.1
Windows 95 (Release 2)
Windows 95 (Release 2)
Windows 95
Windows 95
Windows 98 SE
Windows 98 SE
Windows 98
Windows 98
Windows ME
Windows ME
Windows 7
Windows 7
Windows Vista
Windows Vista
%s %s
%s %s
Windows XP Professional x64
Windows XP Professional x64
Windows XP Home
Windows XP Home
Windows XP Professional
Windows XP Professional
Windows 2000 Professional
Windows 2000 Professional
Windows NT %d.%d
Windows NT %d.%d
Windows 2008
Windows 2008
%s %s Server
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server Web Edition
Windows 2003 Server
Windows 2003 Server
Windows Home Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server Web Edition
Windows 2000 Server
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Windows NT 4.0 Server
Unknown Platform ID (%d)
Unknown Platform ID (%d)
%d.%d
%d.%d
%s (Build: %d
%s (Build: %d
- Service Pack: %s
- Service Pack: %s
KERNEL32.DLL
KERNEL32.DLL
1.2.3
1.2.3
Edit1KeyPress
Edit1KeyPress
Edit2KeyPress
Edit2KeyPress
TFormPortas
TFormPortas
UnitPortas
UnitPortas
TMsgHandlers
TMsgHandlers
####@####
####@####
All Files (*.*)|*.*
All Files (*.*)|*.*
tFtpAccess
tFtpAccess
Edit18KeyPress
Edit18KeyPress
Memo1KeyPress
Memo1KeyPress
Executables (*.exe) - Icons (*.ico)|*.ico;*.exe
Executables (*.exe) - Icons (*.ico)|*.ico;*.exe
*.ini
*.ini
createserverpassword
createserverpassword
iconemsg
iconemsg
botaomsg
botaomsg
keylogger
keylogger
keyloggerstrings
keyloggerstrings
keyloggertimer
keyloggertimer
chromepass
chromepass
chromepasslink
chromepasslink
keylogger0
keylogger0
keylogger1
keylogger1
keylogger2
keylogger2
keyloggerstrings0
keyloggerstrings0
keyloggerstrings1
keyloggerstrings1
keyloggerstrings2
keyloggerstrings2
keyloggerstrings3
keyloggerstrings3
keyloggerstrings4
keyloggerstrings4
Executables (*.exe)|*.exe
Executables (*.exe)|*.exe
server.exe
server.exe
UPXfile.exe
UPXfile.exe
(Ex.: 127.0.0.1:81)
(Ex.: 127.0.0.1:81)
mail_test.txt
mail_test.txt
Google Chrome Passwords
Google Chrome Passwords
PopupMenuPortas
PopupMenuPortas
PopupMenuPortasPopup
PopupMenuPortasPopup
windowsmin
windowsmin
windowsmax
windowsmax
windowsfechar
windowsfechar
windowsmostrar
windowsmostrar
windowsocultar
windowsocultar
windowsmintodas
windowsmintodas
windowscaption
windowscaption
listadeportaspronta
listadeportaspronta
finalizarprocessoportas
finalizarprocessoportas
c:\windows\myservice.exe
c:\windows\myservice.exe
windowsfechar|
windowsfechar|
windowsmax|
windowsmax|
windowsmin|
windowsmin|
windowsmostrar|
windowsmostrar|
windowsocultar|
windowsocultar|
windowsmintodas|
windowsmintodas|
windowscaption|
windowscaption|
listarportas|
listarportas|
listarportasdns|
listarportasdns|
finalizarprocessoportas|
finalizarprocessoportas|
FTP User
FTP User
FTP Password
FTP Password
SetupApi.dll
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
##@@##&&
##@@##&&
Text Files (*.txt)|*.txt
Text Files (*.txt)|*.txt
MemoInformacionValorKeyPress
MemoInformacionValorKeyPress
renamekey
renamekey
renamekey|
renamekey|
TFormKeylogger
TFormKeylogger
TFormKeyloggerT
TFormKeyloggerT
UnitKeylogger
UnitKeylogger
keyloggerdesativar
keyloggerdesativar
keyloggerativar
keyloggerativar
keyloggervazio
keyloggervazio
keyloggergetlog
keyloggergetlog
\klog.txt
\klog.txt
keylogger|
keylogger|
keyloggergetlog|
keyloggergetlog|
keyloggereraselog|
keyloggereraselog|
keyloggerativar|
keyloggerativar|
keyloggerdesativar|
keyloggerdesativar|
Image1KeyDown
Image1KeyDown
keyboardkey|
keyboardkey|
TFormWebcam
TFormWebcam
UnitWebcam
UnitWebcam
webcamsettings|
webcamsettings|
webcam
webcam
webcamgetbuffer
webcamgetbuffer
Webcam\
Webcam\
webcaminactive|
webcaminactive|
webcam|
webcam|
webcamgetbuffer|
webcamgetbuffer|
Edit4KeyPress
Edit4KeyPress
TFormFTPsettings
TFormFTPsettings
TFormFTPsettings\
TFormFTPsettings\
UnitFTPsettings
UnitFTPsettings
EnviararquivoFTP1
EnviararquivoFTP1
ComboBox1KeyPress
ComboBox1KeyPress
EnviararquivoFTP1Click
EnviararquivoFTP1Click
(FTP)
(FTP)
%SYS%
%SYS%
ÞSKTOP%
ÞSKTOP%
c:\windows\
c:\windows\
c:\windows\system32\
c:\windows\system32\
listararquivos|%SYS%|
listararquivos|%SYS%|
listararquivos|ÞSKTOP%|
listararquivos|ÞSKTOP%|
explorer.exe
explorer.exe
*.jpg
*.jpg
sendftp|
sendftp|
Savepasstxt1
Savepasstxt1
Savepasstxt1Click
Savepasstxt1Click
TFormPasswords
TFormPasswords
UnitPasswords
UnitPasswords
Keylogger
Keylogger
KeyloggerClick
KeyloggerClick
TFormSearchKeylogger
TFormSearchKeylogger
UnitSearchKeylogger
UnitSearchKeylogger
hXXp://VVV.scenecoderz.cc/
hXXp://VVV.scenecoderz.cc/
chatmsg|
chatmsg|
GeoIP.dat
GeoIP.dat
SistemaOperacional1h
SistemaOperacional1h
Porta1|
Porta1|
IdTCPServer1
IdTCPServer1
Selecionarportas1
Selecionarportas1
SendFileExecute1
SendFileExecute1
Listarportasativas1
Listarportasativas1
Baixararquivoeexecutar1
Baixararquivoeexecutar1
Keylogger1
Keylogger1
Webcam1$
Webcam1$
Palavraskeylogger1D
Palavraskeylogger1D
HTTPProxy1t
HTTPProxy1t
IdTCPServer1Disconnect
IdTCPServer1Disconnect
IdTCPServer1Execute
IdTCPServer1Execute
Selecionarportas1Click
Selecionarportas1Click
Listarportasativas1Click
Listarportasativas1Click
Baixararquivoeexecutar1Click
Baixararquivoeexecutar1Click
Keylogger1Click
Keylogger1Click
Webcam1Click
Webcam1Click
Palavraskeylogger1Click
Palavraskeylogger1Click
MSNPopUp1URLClick&
MSNPopUp1URLClick&
IdTCPServer1Exception
IdTCPServer1Exception
127.0.0.1:81
127.0.0.1:81
explorer.exe \windows\
explorer.exe \windows\
hXXp://VVV.google.com
hXXp://VVV.google.com
hXXp://VVV.example.com/server.exe
hXXp://VVV.example.com/server.exe
getielogin
getielogin
getiepass
getiepass
getieweb
getieweb
getfirefox
getfirefox
getchrome
getchrome
portas
portas
SQLITE3
SQLITE3
sqlite3file
sqlite3file
sqlite3.dll
sqlite3.dll
Settings.ini
Settings.ini
SOFTWARE\Microsoft\Windows NT\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
Default.ini
Default.ini
SceneCoderz.cc
SceneCoderz.cc
%d days, %s
%d days, %s
sound.wav
sound.wav
keyloggersearchok
keyloggersearchok
chatmsg
chatmsg
getpassword
getpassword
getpassworderror
getpassworderror
enviarexecnormal
enviarexecnormal
enviarexechidden
enviarexechidden
listarportas
listarportas
webcamactive
webcamactive
webcaminactive
webcaminactive
enviarexecnormal|
enviarexecnormal|
enviarexechidden|
enviarexechidden|
openweb|
openweb|
downexec|Y|
downexec|Y|
downexec|N|
downexec|N|
getpassword|
getpassword|
updateservidorweb|
updateservidorweb|
keyloggersearch|
keyloggersearch|
HTTP Proxy
HTTP Proxy
Wave File (*.wav)|*.wav
Wave File (*.wav)|*.wav
hXXp://VVV.scenecoderz.cc
hXXp://VVV.scenecoderz.cc
!!""##$$%%&&''(())** ,,--..//0123456789:;?
!!""##$$%%&&''(())** ,,--..//0123456789:;?
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
.AUi|
.AUi|
LRap
LRap
!$'*-147
!$'*-147
"$') -02469;=?
"$') -02469;=?
"$&( -/1468:
"$&( -/1468:
!$&(*-/135
!$&(*-/135
!#&(*,.1
!#&(*,.1
!"#%&'(* ,-/01345689:;=>?@
!"#%&'(* ,-/01345689:;=>?@
!"#$&'(* ,-.01245678:;?
!"#$&'(* ,-.01245678:;?
!"#$&'() ,-.012346789;
!"#$&'() ,-.012346789;
"#$%'()*,-./12345789:
"#$%'()*,-./12345789:
!#$%&()* -./02345689:
!#$%&()* -./02345689:
!#$%&')* ,./01245679
!#$%&')* ,./01245679
!"$%&'(* ,-/0123567
!"$%&'(* ,-/0123567
!"#%&'(* ,-.012346
!"#%&'(* ,-.012346
!"#$&'() ,-./1234
!"#$&'() ,-./1234
!"#$%'()*,-./023
!"#$%'()*,-./023
!"#$%'()* ,./01
!"#$%'()* ,./01
"#$%&()* ,-/0
"#$%&()* ,-/0
!#$%&')* ,-.
!#$%&')* ,-.
!"$%&'(* ,-
!"$%&'(* ,-
!"#%&'()*,
!"#%&'()*,
!"#$&'()*
!"#$&'()*
!"#$%'()
!"#$%'()
.idata
.idata
.edata
.edata
P.reloc
P.reloc
P.rsrc
P.rsrc
sqlite3_bind_blob
sqlite3_bind_blob
sqlite3_bind_text
sqlite3_bind_text
sqlite3_bind_double
sqlite3_bind_double
sqlite3_bind_int
sqlite3_bind_int
sqlite3_bind_int64
sqlite3_bind_int64
sqlite3_bind_null
sqlite3_bind_null
sqlite3_bind_parameter_index
sqlite3_bind_parameter_index
sqlite3_open
sqlite3_open
sqlite3_close
sqlite3_close
sqlite3_errmsg
sqlite3_errmsg
sqlite3_errcode
sqlite3_errcode
sqlite3_free
sqlite3_free
sqlite3_prepare_v2
sqlite3_prepare_v2
sqlite3_column_count
sqlite3_column_count
sqlite3_column_name
sqlite3_column_name
sqlite3_column_decltype
sqlite3_column_decltype
sqlite3_step
sqlite3_step
sqlite3_column_blob
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_bytes
sqlite3_column_double
sqlite3_column_double
sqlite3_column_text
sqlite3_column_text
sqlite3_column_type
sqlite3_column_type
sqlite3_column_int64
sqlite3_column_int64
sqlite3_finalize
sqlite3_finalize
sqlite3_reset
sqlite3_reset
SQL error or missing database
SQL error or missing database
An internal logic error in SQLite
An internal logic error in SQLite
Operation terminated by sqlite3_interrupt()
Operation terminated by sqlite3_interrupt()
Uses OS features not supported on host
Uses OS features not supported on host
2nd parameter to sqlite3_bind out of range
2nd parameter to sqlite3_bind out of range
sqlite3_step() has another row ready
sqlite3_step() has another row ready
sqlite3_step() has finished executing
sqlite3_step() has finished executing
Unknown SQLite Error Code "
Unknown SQLite Error Code "
ESQLiteException
ESQLiteException
TSQLiteDatabase
TSQLiteDatabase
TSQLiteTable
TSQLiteTable
Failed to open database "%s" : %s
Failed to open database "%s" : %s
Failed to open database "%s" : unknown error
Failed to open database "%s" : unknown error
Error [%d]: %s.
Error [%d]: %s.
"%s": %s
"%s": %s
Error executing SQL
Error executing SQL
Could not prepare SQL statement
Could not prepare SQL statement
Error executing SQL statement
Error executing SQL statement
SQLite is Busy
SQLite is Busy
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Mozilla
Mozilla
Firefox
Firefox
mozcrt19.dll
mozcrt19.dll
nspr4.dll
nspr4.dll
plc4.dll
plc4.dll
plds4.dll
plds4.dll
nssutil3.dll
nssutil3.dll
nss3.dll
nss3.dll
PK11_GetInternalKeySlot
PK11_GetInternalKeySlot
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\Mozilla\Firefox\
signons.sqlite
signons.sqlite
SELECT * FROM moz_logins
SELECT * FROM moz_logins
encryptedPassword
encryptedPassword
##@@## ##@@## ##@@##
##@@## ##@@## ##@@##
\Google\Chrome\User Data\Default\Web Data
\Google\Chrome\User Data\Default\Web Data
SELECT * FROM logins
SELECT * FROM logins
password_value
password_value
origin_url
origin_url
ClientPortMin
ClientPortMin
ClientPortMaxh
ClientPortMaxh
Password
Password
Porth
Porth
TIdTCPConnection0
TIdTCPConnection0
EIdObjectTypeNotSupported
EIdObjectTypeNotSupported
C:\Users\Administrator\Desktop\Indy\IdStrings.pas
C:\Users\Administrator\Desktop\Indy\IdStrings.pas
CmdDelimiterh
CmdDelimiterh
TIdTCPServerConnectionX
TIdTCPServerConnectionX
TIdTCPServerP
TIdTCPServerP
OnExecute
OnExecute
TIdTCPClient
TIdTCPClient
IdTCPClient
IdTCPClient
BoundPorth
BoundPorth
PortU
PortU
TOnHTTPDocument
TOnHTTPDocument
TIdHTTPProxyServer
TIdHTTPProxyServer
IdHTTPProxyServer
IdHTTPProxyServer
OnHTTPDocument
OnHTTPDocument
HTTP/1.0
HTTP/1.0
Windows Firewall Update
Windows Firewall Update
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
GetCPInfo
GetCPInfo
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
crypt32.dll
crypt32.dll
funcoes.dll
funcoes.dll
GetChromePass
GetChromePass
Mozilla3_5Password
Mozilla3_5Password
StartHttpProxy
StartHttpProxy
9 9$9(9,9094989
9 9$9(9,9094989
45
45
9"9&9*9.929?9~9
9"9&9*9.929?9~9
55J5]6m6
55J5]6m6
7}7S7j7
7}7S7j7
2
:5;@;`: :$:(:,:KWindowsIdTCPStreamIdTCPServerSQLiteTable3SQLite3DIdHTTPProxyServerUnitChromeUnitFireFox3_5(7),01444'9=82<.342>6=Operating System14=Country / Keyboard19=Waiting for connection on ports26=Port27=The Port28=can not be used. Check for another program using the same port or if it is blocked by a firewall.29=Select listening ports30=Please enter a valid port.31=Active Ports33=Please select a port to be disabled34=The selected port must be between 1 and 65535.39=Keylogger44=Password63=Active Keylogger64=keylogger settings68=Send logs FTP port72=Show password74=Send logs by FTP75=FTP Settings76=Cancel the execution of the server in the following cases86=Please enter a password.87=Please enter a name for the registry key.90=Complete all the information necessary for sending the logs by FTP91=Please, insert a valid port. The default port is 21.97=DNS and port connection98=Please enter connection address and port108=Please insert a valid FTP address.109=Send logs by FTP test110=This file was created to test the sending of logs by FTP112=Unable to send logs by FTP. Check the settings and try again.113=encrypted password114=Connection password123=Please enter the new connection address and port124=Selected servers will be closed and will reconnect only after another execution or system restart (if server startup is enabled)139=Windows142=Active Ports186=Windows Firewall Service198=Windows list199=list of windows created successfully200=Unable to create list of windows209=All windows as minimized224=Local Port226=Remote Port227=list of active ports created successfully228=Active ports list242=Enter the command to be executed243=Open web page245=Download and execute file259=New Key260=Type the name of the new key261=The name of the new key is:263=Are you sure you want to delete the key266=Key272=Key name has been successfully changed273=Unable to change key name274=The key or value has been deleted successfully275=Unable to delete key or value276=The key was created successfully277=Could not create key290=Keyboard291=Capture webcam308= Execute with parameter336=Unable to perform operation. The file may be in use by another process.353=Passwords354=Enter a word to be sought in the list of passwords355=Type of password358=Password360=Copy password362=Save passwords (*. txt)400=From URL404=words (keylogger)424=Shutdown Windows434=Mouse and keyboard440=Execute463=* The items which aren't checked will be executed only the first time program is run.465=Execution467=Only executable files can be executed in memory468=View FTP logs483=Select the names and always end in "#". Example: server.exe#crack.exe#493=Do you want upload the selected file using FTP?494=It was sent using FTP the file495=FTP Options496=Could not send using FTP the file510=Some versions of Windows and MSN Messenger not allow these functions.513 = Only the names of files and registry keys that start with "SPY_NET_RAT" will be hidden and locked by the rootkit517=Waiting passwords of selected servers518=Password received from the serverendereco0=127.0.0.1|81createserverpassword=abcd1234inicializacao0={08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}infiltrarprocessonome=explorer.exenomearquivo=server.exeiconemsg=1botaomsg=0keylogger0=1keylogger1=1keylogger2=0keyloggerstrings0=PTF.server.comkeyloggerstrings1=logskeyloggerstrings2=ftp_userkeyloggerstrings3=gfhtrhehthkeyloggerstrings4=21keyloggertimer=5p2pnames=server.exe#crack.exe#chromepass=0chromepasslink=hXXp://VVV.server.com/sqlite3.dllMZP.reloc%x`v!Portions Copyright (c) 1999,2003 Avenger by NhTNtdll.dllNtEnumerateValueKeyNtEnumerateKeyGetProcessHeapntdll.dllSHFileOperationAAVICAP32.dllBuildImportTable: can't load library:BuildImportTable: ReallocMemory failedBuildImportTable: GetProcAddress failedBTMemoryLoadLibary: BuildImportTable failedBTMemoryGetProcAddress: no export table foundBTMemoryGetProcAddress: DLL doesn't export anythingBTMemoryGetProcAddress: exported symbol not foundHKEY_CLASSES_ROOTHKEY_CURRENT_CONFIGHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_USERSiphlpapi.dllAllocateAndGetTcpExTableFromStackAllocateAndGetUdpExTableFromStackSetTcpEntryGetExtendedTcpTableGetExtendedUdpTableXxX.xXxUuU.uUukeyboardkeyopenwebdownexecsendftpkeyloggereraseloglistarportasdnswebcamsettingsupdateservidorwebkeyloggersearchSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAPI.dll\config\SteamAppData.vdfAutoLoginUser/ClientRegistry.Blob\ClientRegistry.blob\steam.dllTThreadSearch`%CFirstExecutionSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Runlistarjanelas|windowsfechar|listarjanelas|windowsmax|listarjanelas|windowsmin|listarjanelas|windowsmostrar|listarjanelas|windowsocultar|listarjanelas|windowsmintodas|listarjanelas|windowscaption|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstalllistarportas|listadeportaspronta|listarportas|finalizarconexao|listarportas|finalizarprocessoportas|Y|listarportas|finalizarprocessoportas|N|registro|renamekey|keylogger|keylogger|keyloggerativar|keylogger|keylogger|keyloggerdesativar|keylogger|keyloggergetlog|keylogger|keylogger|keyloggervazio|keyloggersearchok|webcam|webcaminactive|webcam|webcamactive|_x_X_PASSWORDLIST_X_x_NOIP.abcMSN.abcFIREFOX.abcIELOGIN.abcIEPASS.abcIEAUTO.abcIEWEB.abcSOFTWARE\Mozilla\Mozilla Firefoxgetpassword|getpasswordlist|getpassword|getpassworderror|Windows\CurrentVersion\Uninstall\eDonkey2000UNWISE.EXEicon=shell32.dll,4shellexecute=autorun.infXX--XX--XX.txtlogs.datSQLite3.dllRegOpenKeyARegEnumKeyExARegDeleteKeyARegCreateKeyAWinExecSetNamedPipeHandleStateCreatePipempr.dllgdi32.dllkeybd_eventMapVirtualKeyAGetKeyboardStateGetKeyboardLayoutNameAGetKeyStateGetAsyncKeyStateExitWindowsExEnumWindowswininet.dllFtpGetFileSizeFtpSetCurrentDirectoryAFtpOpenFileAwsock32.dllgdiplus.dllGdiplusShutdownAVICAP32.DLLwinmm.dllpowrprof.dllmsacm32.dllADVAPI32.DLL7-727:7?74.4 5=5`5|5 6> >$>(>,>>'>3>]>}>040=0^0~02 2/2]2}2:$:6:^:~:; ;%;-;5;UnitExecutarComandosuftpUrlMon.UnitBytesSizeUnitListarPortasAtivaslanguagefile=Default.iniportas=(80) (81) (82)soundfile=sound.wav[webcam]~}}}||{||~}~~~~}}|{|{{|||~~}~}||}|}~~~~}|~~}|}|{|~}bCBUdp,.dR4a~}}{{{{~~}~~~|{|~~}}~}{|~|}~~}|}~~~~}|||~}~}|{{}}||}~~~}}}~~~}}~}}}~}}}||}~}|}||}}~~~}|{}~}~~}|{{|{}}|}||}~~~}}}|}~~~}||}}}~pw76.uz.gH(44s.teQyhI.PXQCi.EF$qY%UV$V.uFP4V'%%Dup.VYVN.lxAURlLP%CT.IL"4bol`.tx:H.PB`.KWI<.ur>xH%xQ#7,%X\:p|.pQkw.yBE,%s TRX%C@H*? !"#$%&'()* ,-./SQLite formaCHECKEYCO,R83.5.9{AP_}ED/MSVCRT~d-DW.Dp,Sqlite3.dllsqlite3_aggregate_contextsqlite3_aggregate_countsqlite3_auto_extensionsqlite3_bind_parameter_countsqlite3_bind_parameter_namesqlite3_bind_text16sqlite3_bind_valuesqlite3_bind_zeroblobsqlite3_blob_bytessqlite3_blob_closesqlite3_blob_opensqlite3_blob_readsqlite3_blob_writesqlite3_busy_handlersqlite3_busy_timeoutsqlite3_changessqlite3_clear_bindingssqlite3_collation_neededsqlite3_collation_needed16sqlite3_column_bytes16sqlite3_column_decltype16sqlite3_column_intsqlite3_column_name16sqlite3_column_text16sqlite3_column_valuesqlite3_commit_hooksqlite3_completesqlite3_complete16sqlite3_context_db_handlesqlite3_create_collationsqlite3_create_collation16sqlite3_create_collation_v2sqlite3_create_functionsqlite3_create_function16sqlite3_create_modulesqlite3_create_module_v2sqlite3_data_countsqlite3_db_handlesqlite3_declare_vtabsqlite3_enable_load_extensionsqlite3_enable_shared_cachesqlite3_errmsg16sqlite3_execsqlite3_expiredsqlite3_extended_result_codessqlite3_file_controlsqlite3_free_tablesqlite3_get_autocommitsqlite3_get_auxdatasqlite3_get_tablesqlite3_global_recoversqlite3_interruptsqlite3_last_insert_rowidsqlite3_libversionsqlite3_libversion_numbersqlite3_limitsqlite3_load_extensionsqlite3_mallocsqlite3_memory_alarmsqlite3_memory_highwatersqlite3_memory_usedsqlite3_mprintfsqlite3_mutex_allocsqlite3_mutex_entersqlite3_mutex_freesqlite3_mutex_heldsqlite3_mutex_leavesqlite3_mutex_notheldsqlite3_mutex_trysqlite3_open16sqlite3_open_v2sqlite3_overload_functionsqlite3_preparesqlite3_prepare16sqlite3_prepare16_v2sqlite3_profilesqlite3_progress_handlersqlite3_randomnesssqlite3_reallocsqlite3_release_memorysqlite3_reset_auto_extensionsqlite3_result_blobsqlite3_result_doublesqlite3_result_errorsqlite3_result_error16sqlite3_result_error_codesqlite3_result_error_nomemsqlite3_result_error_toobigsqlite3_result_intsqlite3_result_int64sqlite3_result_nullsqlite3_result_textsqlite3_result_text16sqlite3_result_text16besqlite3_result_text16lesqlite3_result_valuesqlite3_result_zeroblobsqlite3_rollback_hooksqlite3_set_authorizersqlite3_set_auxdatasqlite3_sleepsqlite3_snprintfsqlite3_soft_heap_limitsqlite3_sqlsqlite3_test_controlsqlite3_thread_cleanupsqlite3_threadsafesqlite3_total_changessqlite3_tracesqlite3_transfer_bindingssqlite3_update_hooksqlite3_user_datasqlite3_value_blobsqlite3_value_bytessqlite3_value_bytes16sqlite3_value_doublesqlite3_value_intsqlite3_value_int64sqlite3_value_numeric_typesqlite3_value_textsqlite3_value_text16sqlite3_value_text16besqlite3_value_text16lesqlite3_value_typesqlite3_versionsqlite3_vfs_findsqlite3_vfs_registersqlite3_vfs_unregistersqlite3_vmprintf.rdataVBoxService.exeSbieDll.dlldbghelp.dllSoftware\Microsoft\Windows\CurrentVersion55274-640-2673064-2395076487-644-3177037-2351076487-337-8429955-22614\\.\Syser\\.\SyserDbgMsg\\.\SyserBoot\\.\SICE\\.\NTICEMicrosoft\Network\Connections\pbk\rasphone.pbkrasapi32.dllrnaph.dllRAS Passwords |uURLHistoryPassword:abe2869f-9b47-4cd9-a358-c22904dba7f7PasswordWindowsLive:name=*xxxyyyzzz.dat\Mozilla Firefox\softokn3.dlluserenv.dllprofiles.ini\signons3.txt\signons2.txt\signons1.txt\signons.txt(unnamed password)?456789:;!"#$%&'()* ,-./0123SetWindowsHookExApstorec.dll8 8$8(8,8085_50%0S0X0KuURLHistoryIEpasswords.rsrc7%dUQ!}%UFM}B%xOT.vQncKñY.LPeLK.PE]4.kouY5.HN3.rM|I.enML3%Xo%x'eS%Su`IjK.Foe;c7%xrversion="0.0.0.0"UPX executable packermsvcrt.dll3333333333333333333333383333333393333333333333338:*"*"$33383333333333333333333333333333333833338?383333333333333:*3:"$3338333333333333333mUnitPortas%UnitSearchKeyloggerFont.CharsetFont.ColorFont.HeightFont.NameFont.StyleItems.Stringso executados somente na primeira execuShell Execute (Normal)Shell Execute (Hidden)FormPrincipal.ImageListIconsLines.StringsConstraints.MaxHeightConstraints.MaxWidthConstraints.MinHeightConstraints.MinWidthPortaz:\Dir\Install\&{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}%HKEY_LOCAL_MACHINE\Software\.....\Run$HKEY_CURRENT_USER\Software\.....\RunDeletar-se ao executarPicture.Data17555.-Ë(U&$%Uooqkezs['$$#%&(4$$$0066662Keylogger ativoo do keylogger:Enviar logs por FTPFTP user:FTP password:Porta de envio:Cancelar a execukeyboardBitmap.ResamplerClassNameOnKeyDownBitmap.Data%XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXEnviar arquivo (FTP)FormFTPsettingsPass:Port:PTF.client.comftpuserpass1234Portas ativasLocal PortRemote PortPopupMenuPortasComando executado com sucessoAdobe Photoshop CS4 Windows2010:04:07 17:29:05urlTEXTMsgeTEXT,hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> IEC hXXp://VVV.iec.ch.IEC 61966-2.1 Default RGB colour space - sRGBCRT curvQTT.bEFl5V.iZXBMSGQ2010:04:07 17:29:28" id="W5M0MpCehiHzreSzNTczkc9d"?>
2010:04:07 17:30:08
hXXp://ns.adobe.com/xap/1.0/
" id="W5M0MpCehiHzreSzNTczkc9d"?>
Adobe Photoshop CS3 Windows
2008:12:16 15:27:46
" id="W5M0MpCehiHzreSzNTczkc9d"?>
A<.th>%DQd1TK.kbu]MSGUG_%UUUQEdannyrancher@gmail.comhXXp://VVV.SceneCoderZ.ccFormKeylogger!#6&;>?@@@???''',>;>.UZXEDCB@>=:4.XQTSQPMJZHHHGYYFXEDCCC@>!6&>?@@@?@''3333333333333333333373333333383333333333%XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX/.llll|>!!"#-.-01&()* ,-./012"Desligar windowsFormPasswordsList of passwordsKind of password&Password recebido do servidor: XXXXXXXCopy passwordOpen websiteSave Passwords (*.txt)FormPortasItems.DataSistema Operacional127.0.0.1 / 127.0.0.1@Windows XP Professional SP3Primeira Execues nas portas: 80, 81, 82, 83, 5300Selecionar portasSistemaOperacional1Porta1Listar portas ativasWebcam1Web camHTTPProxy1Palavraskeylogger1Palavras (keylogger)Baixar arquivo e executarSendFileExecuteGreeting.NumericCodeMaxConnectionReply.NumericCodeReplyUnknownCommand.NumericCodeIcon.DataIconBitmap.Data"""$$$"""...TSUqkvSMXusyxw555...'''&&&).-*,,(**%%%*,,244133,,,!!!$&&022888444***"""!3./111644222%%ÃŒcWWWXXXbbbeee___^^^ccceee```MMM@@@...PPP]]]HoverFont.CharsetHoverFont.ColorHoverFont.HeightHoverFont.NameHoverFont.StyleTitleFont.CharsetTitleFont.ColorTitleFont.HeightTitleFont.NameTitleFont.StyleOnURLClickMSNPopUp1URLClickSkin3rd.StringsH.jx$lMfTPYHKEY_CLASSES_ROOT*HKEY_CURRENT_USERHKEY_LOCAL_MACHINE#HKEY_USERS,FormSearchKeyloggerMicrosoft Windows [verso 6.0.6001]C:\Users\Server>Text File (*.txt)|*.txtFormWebcamSetViewportOrgExGetViewportOrgExUnhookWindowsHookExLoadKeyboardLayoutAGetKeyboardLayoutListGetKeyboardLayoutGetKeyNameTextAEnumThreadWindowsActivateKeyboardLayout?G 6.0.6001][X.OfI)LMsgFtpSversion="1.0.0.0"name="Microsoft.Windows.Common-Controls"version="6.0.0.0"publicKeyToken="6595b64144ccf1df"comdlg32.dllversion.dllwinspool.drvSQLITE3FILETFORMFTPSETTINGSTFORMKEYLOGGERTFORMPASSWORDSTFORMPORTASTFORMSEARCHKEYLOGGERTFORMWEBCAMRequest rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.Command not supported.Address type not supported.Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.Operation would block.Operation now in progress.Operation already in progress.Socket operation on non-socket.Protocol not supported.Socket type not supported."Operation not supported on socket.Protocol family not supported.0Address family not supported by protocol family.&Error on loading Winsock2 library (%s)Resolving hostname %s.Connecting to %s.%s is not a valid service.Socket Error # %dFile "%s" not found1Only one TIdAntiFreeze can exist per application.Object type not supported.No execute handler found.No data to read.$Can not bind in port range (%d - %d)Invalid Port Range (%d - %d)No command handler found.*Error on call Winsock2 library function %sFailed to set data for '%s'%s.Seek not implemented$Operation not allowed on sorted listProperty %s does not existThread creation error: %sThread Error: %s (%d)OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parametersConnection Closed Gracefully.;Could not bind socket. Address and port are already in use.%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicatesCannot create file "%s". %sCannot open file "%s". %s$''%s'' is not a valid component nameInvalid property value List capacity out of bounds (%d)List count out of bounds (%d)List index out of bounds (%d) Out of memory while expanding memory streamError reading %s%s%s: %sAncestor for '%s' not foundCannot assign a %s to a %sECheckSynchronize called from thread $%x, which is NOT the main threadClass %s not found%s (%s, line %d)Abstract Error?Access violation at address %p in module '%s'. %s of address %pSystem Error. Code: %d.Invalid variant operation%Invalid variant operation (%s%.8x)%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)Operation not supportedExternal exception %xInterface not supportedInvalid pointer operationInvalid class typecast0Access violation at address %p. %s of address %pPrivileged instruction(Exception %s in module %s at %p.Application Error1Format '%s' invalid or incompatible with argumentNo argument for format '%s'"Variant method calls not supported!'%s' is not a valid integer value('%s' is not a valid floating point valueI/O error %dInteger overflow Invalid floating point operationThe UPX Team hXXp://upx.sf.netUPX executable packer3.00 (2007-04-27)upx.exeAddress type not supported.;Cannot call TerminateAndWaitFor on FreeAndTerminate threads&Cannot change the size of a JPEG imageJPEG error #%dNo command handler found.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)=This control requires version 4.70 or greater of COMCTL32.DLLNo help keyword specified.Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d Failed to get object at index %d"Failed to set tab "%s" at index %d Failed to set object at index %dFailed to Save Stream %s is already associated with %sE%d is an invalid PageIndex value. PageIndex must be between 0 and %dUnable to insert a line Clipboard does not support IconsText exceeds memo capacity.There is no default printer currently selected/Menu '%s' is already being used by another formError setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"Unable to find a Table of ContentsNo help found for %sValue must be between %d and %d%s property out of range%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active0Can only modify an image if it contains a bitmap*A control cannot have itself as its parentUnsupported clipboard formatError creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'Resource %s not found%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration groupThread Error: %s (%d)0Tab position incompatible with current tab style0Tab style incompatible with current tab positionCannot open file "%s". %sUnable to write to %sInvalid stream format$''%s'' is not a valid component nameInvalid property element: %sInvalid property type: %sItem not found ($0%x) List capacity out of bounds (%d)Cannot assign a %s to a %sBits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main threadA class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicatesInvalid variant operationInvalid NULL variant operation%Invalid variant operation (%s%.8x)'%s' is not a valid date'%s' is not a valid time!'%s' is not a valid date and time'%s' is not a valid GUID valuevbc.exe_1876_rwx_00400000_001E7000:`.rsrc'6'Wr%SdLRWVBA6.DLL?PASSWORDS_OPRAVBA6.DLLPASSWORDS_OPRAPASSWORDS_CDKEYC:\xampp\htdocs\recovery\VB6.OLBReadKeyPASSWORDS_MESSPASSWORDS_MAILPASSWORDS_DIALPASSWORDS_CHROPASSWORDS_IEXPPASSWORDS_FFOXPASSWORDS_PRODKEYPASSWORDS_PTSGPASSWORDS_OFFCWINDOWS_VERSION_FULLRegCloseKeyRegOpenKeyAadvapi32.dlltxtPasswordimgLoginPressedimgLogin[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`[]`568568568568\]_\]_568568568:- :- :- ;. ;. ;. <.>0">0">1"?1"?1#?1#@2#@2#@2#A2#A3$A3$B3$B3$B4$C4ÄÄÕÕÕå&E6&E6&F6&F7&F7'G7'G7'G8'H8'H8'H8(I9(I9(I9(J9(J:)J:)K:)K:)K;)L;)L;*L;*M O> P>,P>,P?,Q?,Q?,Q?-R@-R@-R@-S@-SA.SA.TA.TA.TB.UB.UB/UB/VC/VC/VC/WC0WD0WD0XD0XE0XE0YE1YE1YF1ZF1ZF1ZF2[G2[G2[G2\G2\H2\H3]H3]H3]I3^I3^I4^I4_J4_J4_J4`K4`K5`K5aK5aL5aL5bL6bL6bM6cM6cM6cM6dN7dN7dN7eN7eO7eO8fO8fO8fP8gP8gP9gP9hQ9hQ9hQ9iR9iR:iR:jR:jS:jS:kS;kS;kT;lT;lT;lT;mUqX>qX>qX>rY>rY?rY?sY?sZ?sZ?tZ?tZ@t[@u[@u[@u[@v\Av\Av\Aw\Aw]Aw]Ax]Bx]Bx^By^By^By^Cz_Cz_Cz_C{`C{`D{`D|`D|aD|aD}aD}aE}bE~bE~bE~bE5685685685685685685685685685Vm568568568568568568568568568568568impORTORTORTORTORT5685685685Vm568568568568568568568568568568impORTORTORTORTORT568568568568568568568568568568568impORTORTORTORTORT568568568568|y56Pi_P\ly|voL_o568|voL_o568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568568HKM568568568568568568568568568568impORTORTORTORTORT568568568\6856`5685685685_|5685685_|\68\{|5685685_|568\6879;5685685685685689;>79;;=?;=?;=@78457568568568569:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;=:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>:;>;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?;=?=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@=>@5_|568568568568568568568\6856`5685685_|568568\68568568568568\68hKeyCodeKey.Qs]W6"sE%6u:Txxgu^WD{>P.CP.YP-_R.nU5QudP~6 (.IS?Z.su%0uRPI5.Jj4T-'.sB%xH{p%2u'OB.kB36~9]2,%F{E_.jqnK.jSZeG.Fu`.zGS%xYL}3w.Jg'K.TBPSAU30%U%Epy%.blf8C.wtmP1"".qzZ{-t}p~u&E%CkJ.EHPg.yR:$4)8|.Wi5#1AG%U.rsrckEYL)u3SSh#.Toh\5H"Account","Login NamePasswordWeb Sit##%%&&))**,,//11224477z:\Jj.pdb?P%""!!!!"36333222(""&(((''''&55553333(77555555(3331110*.@@@????KERNEL32.DLLADVAPI32.dllCOMCTL32.dllcomdlg32.dllGDI32.dllmsvcrt.dllole32.dllSHELL32.dllUSER32.dllVERSION.dlljE-.viCh4.hp!J"].Rbl.text`.data]_qÃMSVBVM60.DLL*\AC:\xampp\htdocs\recovery\Project1.vbp\chro.datHKEY_CURRENT_USER\Software\IMVU\username\HKEY_CURRENT_USER\Software\IMVU\password\\FileZilla\recentservers.xml\mess.datWScript.shell\mail.datPassword\dial.datAction URLChrome\iexp.dat\ffox.datWeb SiteFireFox\opra.datOperaCD-KEYCDKEY:SOFTWARE\MICROSOFT\Windows NT\CurrentVersionPRODKEY:\ptsg.dat\offc.datProduct Key\steam\steam.exeWScript.ShellHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductNameWINDOWS VERSION:00000000steam.exe@*\AC:\xampp\htdocs\recovery\Project1.vbpOperaPassViewOperaPassView.exeh4ck3rs-41.exe%original file name%.exe_540_rwx_02B70000_00005000:{21f5c02d-b05b-4436-bd0f-2d5df96c3eee}SpyNet 2.7 Final.exe_680_rwx_00401000_005E1000:kernel32.dllWindowsMSWHEEL_ROLLMSGMSH_WHEELSUPPORT_MSGMSH_SCROLL_LINES_MSG$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)oleaut32.dllEVariantBadIndexErrorssShifthtKeywordEInvalidOperationu%CNu%s[%d]%s_%d.OwnerEInvalidGraphicOperationcomctl32.dllUSER32.DLLwindowsuxtheme.dll%s%s%s%s%s%s%s%s%s%sProportionalMAPI32.DLLOnExit\%DmsShiftSelectOnKeyDownLOnKeyPressOnKeyUp$OnKeyUpxArrowKeysvsReportacoUpDownKeyDropsListOnKeyUpRICHED32.DLLTComboBoxExEnumeratorole32.dllPasswordCharssHorizontalIE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")JumpID("","%s")TKeyEventTKeyPressEventHelpKeywordhcrSQLWait%s (%s)imm32.dllAutoHotkeysUh.dHssHotTrackTWindowStatepoProportionalTWMKeyKeyPreviewWindowStateSystem\CurrentControlSet\Control\Keyboard Layouts\%.8xvcltest3.dllUser32.dllgetservbyportWSAAsyncGetServByPortWSAJoinLeafWS2_32.DLL127.0.0.1TIdSocketListWindowsTIdStackWindowsUIdStackWindowsftpTransferftpReadyftpAbortedClientPortMinTClientPortMaxPortEIdCanNotBindPortInRangeEIdInvalidPortRangeSVWsaUsernamePasswordPasswordT0.0.0.1TIdTCPConnectionTIdTCPConnection\IdTCPConnectionEIdTCPConnectionError%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\Indy\IdStrings.pasTIdTCPServerIdTCPServerCmdDelimiterTIdTCPServerConnectionDefaultPortOnExecuteEIdTCPServerErrorEIdNoExecuteSpecifiedLeftPopupTURLEventmsnAutoOpenURLOnURLClick0lKhXXp://VVV.url.com/%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Resamplers.pasReverse transformation is not implemented in %s.Forward transformation is not implemented in %s.%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32.pasUnpaired TThreadPersistent.EndUpdate%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Layers.pasOnKeyUp\uL%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\graphics32-1-8-3\GR32_Image.pas%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\imgutil.pas%Documents and Settings%\Jack\Desktop\1\Backup Work\1\Cliente\VclSkin\Winskinini.pas%s_%sUh.uMttntpanel.unicodeclassttntsilentpaintpanel.unicodeclassxcFastReportTWWKeyCombo=ComboboxTWWTempKeyCombo=comboboxTO32DBFLEXEDIT=Edit4.94.12.01BUTTON.RADIOBUTTON.CHECKBOX3333333Progress.ChunkTab.PaneTrackbar.ThumbHorzTrackbar.ThumbVertTrackbar.ThumbLeftTrackbar.ThumbRightTrackbar.ThumbUpTrackbar.ThumbDownUpDown.HorzUpDown.Vertuser32.dllDisableProcessWindowsGhostingShellExecuteAshell32.dllSOFTWARE\Microsoft\Windows\CurrentVersionhttp\shell\open\command\Internet Explorer\iexplore.exePortugalTurkeyURLDownloadToFileAurlmon.dllIP.txthXXp://VVV.ip-adress.com/GetWindowsDirectoryAteste.vbsteste.txtSet objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)Set objFileSystem = CreateObject("Scripting.fileSystemObject")Set objFile = objFileSystem.CreateTextFile("Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & EnterInfo = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & EnterobjFile.WriteLine(Info)objFile.Closecscript.exeWindows 3.1Windows 95 (Release 2)Windows 95Windows 98 SEWindows 98Windows MEWindows 7Windows Vista%s %sWindows XP Professional x64Windows XP HomeWindows XP ProfessionalWindows 2000 ProfessionalWindows NT %d.%dWindows 2008%s %s ServerWindows 2003 Server DatacenterWindows 2003 Server EnterpriseWindows 2003 Server Web EditionWindows 2003 ServerWindows Home ServerWindows 2003 Server (Release 2)Windows 2000 Server DatacenterWindows 2000 Server EnterpriseWindows 2000 Server Web EditionWindows 2000 ServerWindows NT 4.0 Server DatacenterWindows NT 4.0 Server EnterpriseWindows NT 4.0 Server Web EditionWindows NT 4.0 ServerUnknown Platform ID (%d)%d.%d%s (Build: %d- Service Pack: %sKERNEL32.DLL1.2.3Edit1KeyPressEdit2KeyPressTFormPortasUnitPortasTMsgHandlers####@####All Files (*.*)|*.*tFtpAccessEdit18KeyPressMemo1KeyPressExecutables (*.exe) - Icons (*.ico)|*.ico;*.exe*.inicreateserverpasswordiconemsgbotaomsgkeyloggerkeyloggerstringskeyloggertimerchromepasschromepasslinkkeylogger0keylogger1keylogger2keyloggerstrings0keyloggerstrings1keyloggerstrings2keyloggerstrings3keyloggerstrings4Executables (*.exe)|*.exeserver.exeUPXfile.exe(Ex.: 127.0.0.1:81)mail_test.txtGoogle Chrome PasswordsPopupMenuPortasPopupMenuPortasPopupwindowsminwindowsmaxwindowsfecharwindowsmostrarwindowsocultarwindowsmintodaswindowscaptionlistadeportasprontafinalizarprocessoportasc:\windows\myservice.exewindowsfechar|windowsmax|windowsmin|windowsmostrar|windowsocultar|windowsmintodas|windowscaption|listarportas|listarportasdns|finalizarprocessoportas|FTP UserFTP PasswordSetupApi.dllSetupDiOpenClassRegKeySetupDiOpenClassRegKeyExASetupDiOpenClassRegKeyExWSetupDiCreateDeviceInterfaceRegKeyASetupDiCreateDeviceInterfaceRegKeyWSetupDiOpenDeviceInterfaceRegKeySetupDiDeleteDeviceInterfaceRegKeySetupDiCreateDevRegKeyASetupDiCreateDevRegKeyWSetupDiOpenDevRegKeySetupDiDeleteDevRegKeyCM_DEVCAP_LOCKSUPPORTEDCM_DEVCAP_EJECTSUPPORTEDPDCAP_D0_SUPPORTEDPDCAP_D1_SUPPORTEDPDCAP_D2_SUPPORTEDPDCAP_D3_SUPPORTEDPDCAP_WAKE_FROM_D0_SUPPORTEDPDCAP_WAKE_FROM_D1_SUPPORTEDPDCAP_WAKE_FROM_D2_SUPPORTEDPDCAP_WAKE_FROM_D3_SUPPORTEDPDCAP_WARM_EJECT_SUPPORTED##@@##&&Text Files (*.txt)|*.txtMemoInformacionValorKeyPressrenamekeyrenamekey|TFormKeyloggerTFormKeyloggerTUnitKeyloggerkeyloggerdesativarkeyloggerativarkeyloggervaziokeyloggergetlog\klog.txtkeylogger|keyloggergetlog|keyloggereraselog|keyloggerativar|keyloggerdesativar|Image1KeyDownkeyboardkey|TFormWebcamUnitWebcamwebcamsettings|webcamwebcamgetbufferWebcam\webcaminactive|webcam|webcamgetbuffer|Edit4KeyPressTFormFTPsettingsTFormFTPsettings\UnitFTPsettingsEnviararquivoFTP1ComboBox1KeyPressEnviararquivoFTP1Click(FTP)%SYS%ÞSKTOP%c:\windows\c:\windows\system32\listararquivos|%SYS%|listararquivos|ÞSKTOP%|explorer.exe*.jpgsendftp|Savepasstxt1Savepasstxt1ClickTFormPasswordsUnitPasswordsKeyloggerKeyloggerClickTFormSearchKeyloggerUnitSearchKeyloggerhXXp://VVV.scenecoderz.cc/chatmsg|GeoIP.datSistemaOperacional1hPorta1|IdTCPServer1Selecionarportas1SendFileExecute1Listarportasativas1Baixararquivoeexecutar1Keylogger1Webcam1$Palavraskeylogger1DHTTPProxy1tIdTCPServer1DisconnectIdTCPServer1ExecuteSelecionarportas1ClickListarportasativas1ClickBaixararquivoeexecutar1ClickKeylogger1ClickWebcam1ClickPalavraskeylogger1ClickMSNPopUp1URLClick&IdTCPServer1Exception127.0.0.1:81explorer.exe \windows\hXXp://VVV.google.comhXXp://VVV.example.com/server.exegetielogingetiepassgetiewebgetfirefoxgetchromeportasSQLITE3sqlite3filesqlite3.dllSettings.iniSOFTWARE\Microsoft\Windows NT\CurrentVersionDefault.iniSceneCoderz.cc%d days, %ssound.wavkeyloggersearchokchatmsggetpasswordgetpassworderrorenviarexecnormalenviarexechiddenlistarportaswebcamactivewebcaminactiveenviarexecnormal|enviarexechidden|openweb|downexec|Y|downexec|N|getpassword|updateservidorweb|keyloggersearch|HTTP ProxyWave File (*.wav)|*.wavhXXp://VVV.scenecoderz.cc!!""##$$%%&&''(())** ,,--..//0123456789:;?deflate 1.2.3 Copyright 1995-2005 Jean-loup Gaillyinflate 1.2.3 Copyright 1995-2005 Mark Adler.AUi|LRap!$'*-147"$') -02469;=?"$&( -/1468:!$&(*-/135!#&(*,.1!"#%&'(* ,-/01345689:;=>?@!"#$&'(* ,-.01245678:;?!"#$&'() ,-.012346789;"#$%'()*,-./12345789:!#$%&()* -./02345689:!#$%&')* ,./01245679!"$%&'(* ,-/0123567!"#%&'(* ,-.012346!"#$&'() ,-./1234!"#$%'()*,-./023!"#$%'()* ,./01"#$%&()* ,-/0!#$%&')* ,-.!"$%&'(* ,-!"#%&'()*,!"#$&'()*!"#$%'().idata.edataP.relocP.rsrcsqlite3_bind_blobsqlite3_bind_textsqlite3_bind_doublesqlite3_bind_intsqlite3_bind_int64sqlite3_bind_nullsqlite3_bind_parameter_indexsqlite3_opensqlite3_closesqlite3_errmsgsqlite3_errcodesqlite3_freesqlite3_prepare_v2sqlite3_column_countsqlite3_column_namesqlite3_column_decltypesqlite3_stepsqlite3_column_blobsqlite3_column_bytessqlite3_column_doublesqlite3_column_textsqlite3_column_typesqlite3_column_int64sqlite3_finalizesqlite3_resetSQL error or missing databaseAn internal logic error in SQLiteOperation terminated by sqlite3_interrupt()Uses OS features not supported on host2nd parameter to sqlite3_bind out of rangesqlite3_step() has another row readysqlite3_step() has finished executingUnknown SQLite Error Code "ESQLiteExceptionTSQLiteDatabaseTSQLiteTableFailed to open database "%s" : %sFailed to open database "%s" : unknown errorError [%d]: %s."%s": %sError executing SQLCould not prepare SQL statementError executing SQL statementSQLite is BusySOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersMozillaFirefoxmozcrt19.dllnspr4.dllplc4.dllplds4.dllnssutil3.dllnss3.dllPK11_GetInternalKeySlot\Mozilla\Firefox\profiles.ini\Mozilla\Firefox\signons.sqliteSELECT * FROM moz_loginsencryptedPassword##@@## ##@@## ##@@##\Google\Chrome\User Data\Default\Web DataSELECT * FROM loginspassword_valueorigin_urlClientPortMinClientPortMaxhPasswordPorthTIdTCPConnection0EIdObjectTypeNotSupportedC:\Users\Administrator\Desktop\Indy\IdStrings.pasCmdDelimiterhTIdTCPServerConnectionXTIdTCPServerPOnExecuteTIdTCPClientIdTCPClientBoundPorthPortUTOnHTTPDocumentTIdHTTPProxyServerIdHTTPProxyServerOnHTTPDocumentHTTP/1.0Windows Firewall UpdateGetKeyboardTypeadvapi32.dllRegOpenKeyExARegCloseKeyRegFlushKeyRegCreateKeyExAGetCPInfoMsgWaitForMultipleObjectscrypt32.dllfuncoes.dllGetChromePassMozilla3_5PasswordStartHttpProxy9 9$9(9,9094989459"9&9*9.929?9~955J5]6m67}7S7j72:5;@;`: :$:(:,:KWindowsIdTCPStreamIdTCPServerSQLiteTable3SQLite3DIdHTTPProxyServerUnitChromeUnitFireFox3_5(7),01444'9=82<.342>6=Operating System14=Country / Keyboard19=Waiting for connection on ports26=Port27=The Port28=can not be used. Check for another program using the same port or if it is blocked by a firewall.29=Select listening ports30=Please enter a valid port.31=Active Ports33=Please select a port to be disabled34=The selected port must be between 1 and 65535.39=Keylogger44=Password63=Active Keylogger64=keylogger settings68=Send logs FTP port72=Show password74=Send logs by FTP75=FTP Settings76=Cancel the execution of the server in the following cases86=Please enter a password.87=Please enter a name for the registry key.90=Complete all the information necessary for sending the logs by FTP91=Please, insert a valid port. The default port is 21.97=DNS and port connection98=Please enter connection address and port108=Please insert a valid FTP address.109=Send logs by FTP test110=This file was created to test the sending of logs by FTP112=Unable to send logs by FTP. Check the settings and try again.113=encrypted password114=Connection password123=Please enter the new connection address and port124=Selected servers will be closed and will reconnect only after another execution or system restart (if server startup is enabled)139=Windows142=Active Ports186=Windows Firewall Service198=Windows list199=list of windows created successfully200=Unable to create list of windows209=All windows as minimized224=Local Port226=Remote Port227=list of active ports created successfully228=Active ports list242=Enter the command to be executed243=Open web page245=Download and execute file259=New Key260=Type the name of the new key261=The name of the new key is:263=Are you sure you want to delete the key266=Key272=Key name has been successfully changed273=Unable to change key name274=The key or value has been deleted successfully275=Unable to delete key or value276=The key was created successfully277=Could not create key290=Keyboard291=Capture webcam308= Execute with parameter336=Unable to perform operation. The file may be in use by another process.353=Passwords354=Enter a word to be sought in the list of passwords355=Type of password358=Password360=Copy password362=Save passwords (*. txt)400=From URL404=words (keylogger)424=Shutdown Windows434=Mouse and keyboard440=Execute463=* The items which aren't checked will be executed only the first time program is run.465=Execution467=Only executable files can be executed in memory468=View FTP logs483=Select the names and always end in "#". Example: server.exe#crack.exe#493=Do you want upload the selected file using FTP?494=It was sent using FTP the file495=FTP Options496=Could not send using FTP the file510=Some versions of Windows and MSN Messenger not allow these functions.513 = Only the names of files and registry keys that start with "SPY_NET_RAT" will be hidden and locked by the rootkit517=Waiting passwords of selected servers518=Password received from the serverendereco0=127.0.0.1|81createserverpassword=abcd1234inicializacao0={08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}infiltrarprocessonome=explorer.exenomearquivo=server.exeiconemsg=1botaomsg=0keylogger0=1keylogger1=1keylogger2=0keyloggerstrings0=PTF.server.comkeyloggerstrings1=logskeyloggerstrings2=ftp_userkeyloggerstrings3=gfhtrhehthkeyloggerstrings4=21keyloggertimer=5p2pnames=server.exe#crack.exe#chromepass=0chromepasslink=hXXp://VVV.server.com/sqlite3.dllMZP.reloc%x`v!Portions Copyright (c) 1999,2003 Avenger by NhTNtdll.dllNtEnumerateValueKeyNtEnumerateKeyGetProcessHeapntdll.dllSHFileOperationAAVICAP32.dllBuildImportTable: can't load library:BuildImportTable: ReallocMemory failedBuildImportTable: GetProcAddress failedBTMemoryLoadLibary: BuildImportTable failedBTMemoryGetProcAddress: no export table foundBTMemoryGetProcAddress: DLL doesn't export anythingBTMemoryGetProcAddress: exported symbol not foundHKEY_CLASSES_ROOTHKEY_CURRENT_CONFIGHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_USERSiphlpapi.dllAllocateAndGetTcpExTableFromStackAllocateAndGetUdpExTableFromStackSetTcpEntryGetExtendedTcpTableGetExtendedUdpTableXxX.xXxUuU.uUukeyboardkeyopenwebdownexecsendftpkeyloggereraseloglistarportasdnswebcamsettingsupdateservidorwebkeyloggersearchSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAPI.dll\config\SteamAppData.vdfAutoLoginUser/ClientRegistry.Blob\ClientRegistry.blob\steam.dllTThreadSearch`%CFirstExecutionSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Runlistarjanelas|windowsfechar|listarjanelas|windowsmax|listarjanelas|windowsmin|listarjanelas|windowsmostrar|listarjanelas|windowsocultar|listarjanelas|windowsmintodas|listarjanelas|windowscaption|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstalllistarportas|listadeportaspronta|listarportas|finalizarconexao|listarportas|finalizarprocessoportas|Y|listarportas|finalizarprocessoportas|N|registro|renamekey|keylogger|keylogger|keyloggerativar|keylogger|keylogger|keyloggerdesativar|keylogger|keyloggergetlog|keylogger|keylogger|keyloggervazio|keyloggersearchok|webcam|webcaminactive|webcam|webcamactive|_x_X_PASSWORDLIST_X_x_NOIP.abcMSN.abcFIREFOX.abcIELOGIN.abcIEPASS.abcIEAUTO.abcIEWEB.abcSOFTWARE\Mozilla\Mozilla Firefoxgetpassword|getpasswordlist|getpassword|getpassworderror|Windows\CurrentVersion\Uninstall\eDonkey2000UNWISE.EXEicon=shell32.dll,4shellexecute=autorun.infXX--XX--XX.txtlogs.datSQLite3.dllRegOpenKeyARegEnumKeyExARegDeleteKeyARegCreateKeyAWinExecSetNamedPipeHandleStateCreatePipempr.dllgdi32.dllkeybd_eventMapVirtualKeyAGetKeyboardStateGetKeyboardLayoutNameAGetKeyStateGetAsyncKeyStateExitWindowsExEnumWindowswininet.dllFtpGetFileSizeFtpSetCurrentDirectoryAFtpOpenFileAwsock32.dllgdiplus.dllGdiplusShutdownAVICAP32.DLLwinmm.dllpowrprof.dllmsacm32.dllADVAPI32.DLL7-727:7?74.4 5=5`5|5 6> >$>(>,>>'>3>]>}>040=0^0~02 2/2]2}2:$:6:^:~:; ;%;-;5;UnitExecutarComandosuftpUrlMon.UnitBytesSizeUnitListarPortasAtivaslanguagefile=Default.iniportas=(80) (81) (82)soundfile=sound.wav[webcam]~}}}||{||~}~~~~}}|{|{{|||~~}~}||}|}~~~~}|~~}|}|{|~}bCBUdp,.dR4a~}}{{{{~~}~~~|{|~~}}~}{|~|}~~}|}~~~~}|||~}~}|{{}}||}~~~}}}~~~}}~}}}~}}}||}~}|}||}}~~~}|{}~}~~}|{{|{}}|}||}~~~}}}|}~~~}||}}}~pw76.uz.gH(44s.teQyhI.PXQCi.EF$qY%UV$V.uFP4V'%%Dup.VYVN.lxAURlLP%CT.IL"4bol`.tx:H.PB`.KWI<.ur>xH%xQ#7,%X\:p|.pQkw.yBE,%s TRX%C@H*? !"#$%&'()* ,-./SQLite formaCHECKEYCO,R83.5.9{AP_}ED/MSVCRT~d-DW.Dp,Sqlite3.dllsqlite3_aggregate_contextsqlite3_aggregate_countsqlite3_auto_extensionsqlite3_bind_parameter_countsqlite3_bind_parameter_namesqlite3_bind_text16sqlite3_bind_valuesqlite3_bind_zeroblobsqlite3_blob_bytessqlite3_blob_closesqlite3_blob_opensqlite3_blob_readsqlite3_blob_writesqlite3_busy_handlersqlite3_busy_timeoutsqlite3_changessqlite3_clear_bindingssqlite3_collation_neededsqlite3_collation_needed16sqlite3_column_bytes16sqlite3_column_decltype16sqlite3_column_intsqlite3_column_name16sqlite3_column_text16sqlite3_column_valuesqlite3_commit_hooksqlite3_completesqlite3_complete16sqlite3_context_db_handlesqlite3_create_collationsqlite3_create_collation16sqlite3_create_collation_v2sqlite3_create_functionsqlite3_create_function16sqlite3_create_modulesqlite3_create_module_v2sqlite3_data_countsqlite3_db_handlesqlite3_declare_vtabsqlite3_enable_load_extensionsqlite3_enable_shared_cachesqlite3_errmsg16sqlite3_execsqlite3_expiredsqlite3_extended_result_codessqlite3_file_controlsqlite3_free_tablesqlite3_get_autocommitsqlite3_get_auxdatasqlite3_get_tablesqlite3_global_recoversqlite3_interruptsqlite3_last_insert_rowidsqlite3_libversionsqlite3_libversion_numbersqlite3_limitsqlite3_load_extensionsqlite3_mallocsqlite3_memory_alarmsqlite3_memory_highwatersqlite3_memory_usedsqlite3_mprintfsqlite3_mutex_allocsqlite3_mutex_entersqlite3_mutex_freesqlite3_mutex_heldsqlite3_mutex_leavesqlite3_mutex_notheldsqlite3_mutex_trysqlite3_open16sqlite3_open_v2sqlite3_overload_functionsqlite3_preparesqlite3_prepare16sqlite3_prepare16_v2sqlite3_profilesqlite3_progress_handlersqlite3_randomnesssqlite3_reallocsqlite3_release_memorysqlite3_reset_auto_extensionsqlite3_result_blobsqlite3_result_doublesqlite3_result_errorsqlite3_result_error16sqlite3_result_error_codesqlite3_result_error_nomemsqlite3_result_error_toobigsqlite3_result_intsqlite3_result_int64sqlite3_result_nullsqlite3_result_textsqlite3_result_text16sqlite3_result_text16besqlite3_result_text16lesqlite3_result_valuesqlite3_result_zeroblobsqlite3_rollback_hooksqlite3_set_authorizersqlite3_set_auxdatasqlite3_sleepsqlite3_snprintfsqlite3_soft_heap_limitsqlite3_sqlsqlite3_test_controlsqlite3_thread_cleanupsqlite3_threadsafesqlite3_total_changessqlite3_tracesqlite3_transfer_bindingssqlite3_update_hooksqlite3_user_datasqlite3_value_blobsqlite3_value_bytessqlite3_value_bytes16sqlite3_value_doublesqlite3_value_intsqlite3_value_int64sqlite3_value_numeric_typesqlite3_value_textsqlite3_value_text16sqlite3_value_text16besqlite3_value_text16lesqlite3_value_typesqlite3_versionsqlite3_vfs_findsqlite3_vfs_registersqlite3_vfs_unregistersqlite3_vmprintf.rdataVBoxService.exeSbieDll.dlldbghelp.dllSoftware\Microsoft\Windows\CurrentVersion55274-640-2673064-2395076487-644-3177037-2351076487-337-8429955-22614\\.\Syser\\.\SyserDbgMsg\\.\SyserBoot\\.\SICE\\.\NTICEMicrosoft\Network\Connections\pbk\rasphone.pbkrasapi32.dllrnaph.dllRAS Passwords |uURLHistoryPassword:abe2869f-9b47-4cd9-a358-c22904dba7f7PasswordWindowsLive:name=*xxxyyyzzz.dat\Mozilla Firefox\softokn3.dlluserenv.dllprofiles.ini\signons3.txt\signons2.txt\signons1.txt\signons.txt(unnamed password)?456789:;!"#$%&'()* ,-./0123SetWindowsHookExApstorec.dll8 8$8(8,8085_50%0S0X0KuURLHistoryIEpasswords.rsrc7%dUQ!}%UFM}B%xOT.vQncKñY.LPeLK.PE]4.kouY5.HN3.rM|I.enML3%Xo%x'eS%Su`IjK.Foe;c7%xrversion="0.0.0.0"UPX executable packermsvcrt.dll3333333333333333333333383333333393333333333333338:*"*"$33383333333333333333333333333333333833338?383333333333333:*3:"$3338333333333333333mUnitPortas%UnitSearchKeyloggerFont.CharsetFont.ColorFont.HeightFont.NameFont.StyleItems.Stringso executados somente na primeira execuShell Execute (Normal)Shell Execute (Hidden)FormPrincipal.ImageListIconsLines.StringsConstraints.MaxHeightConstraints.MaxWidthConstraints.MinHeightConstraints.MinWidthPortaz:\Dir\Install\&{08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}%HKEY_LOCAL_MACHINE\Software\.....\Run$HKEY_CURRENT_USER\Software\.....\RunDeletar-se ao executarPicture.Data17555.-Ë(U&$%Uooqkezs['$$#%&(4$$$0066662Keylogger ativoo do keylogger:Enviar logs por FTPFTP user:FTP password:Porta de envio:Cancelar a execukeyboardBitmap.ResamplerClassNameOnKeyDownBitmap.Data%XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXEnviar arquivo (FTP)FormFTPsettingsPass:Port:PTF.client.comftpuserpass1234Portas ativasLocal PortRemote PortPopupMenuPortasComando executado com sucessoAdobe Photoshop CS4 Windows2010:04:07 17:29:05urlTEXTMsgeTEXT,hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> IEC hXXp://VVV.iec.ch.IEC 61966-2.1 Default RGB colour space - sRGBCRT curvQTT.bEFl5V.iZXBMSGQ2010:04:07 17:29:28" id="W5M0MpCehiHzreSzNTczkc9d"?>
2010:04:07 17:30:08
hXXp://ns.adobe.com/xap/1.0/
" id="W5M0MpCehiHzreSzNTczkc9d"?>
Adobe Photoshop CS3 Windows
2008:12:16 15:27:46
" id="W5M0MpCehiHzreSzNTczkc9d"?>
A<.th>%DQd1TK.kbu]MSGUG_%UUUQEdannyrancher@gmail.comhXXp://VVV.SceneCoderZ.ccFormKeylogger!#6&;>?@@@???''',>;>.UZXEDCB@>=:4.XQTSQPMJZHHHGYYFXEDCCC@>!6&>?@@@?@''3333333333333333333373333333383333333333%XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX/.llll|>!!"#-.-01&()* ,-./012"Desligar windowsFormPasswordsList of passwordsKind of password&Password recebido do servidor: XXXXXXXCopy passwordOpen websiteSave Passwords (*.txt)FormPortasItems.DataSistema Operacional127.0.0.1 / 127.0.0.1@Windows XP Professional SP3Primeira Execues nas portas: 80, 81, 82, 83, 5300Selecionar portasSistemaOperacional1Porta1Listar portas ativasWebcam1Web camHTTPProxy1Palavraskeylogger1Palavras (keylogger)Baixar arquivo e executarSendFileExecuteGreeting.NumericCodeMaxConnectionReply.NumericCodeReplyUnknownCommand.NumericCodeIcon.DataIconBitmap.Data"""$$$"""...TSUqkvSMXusyxw555...'''&&&).-*,,(**%%%*,,244133,,,!!!$&&022888444***"""!3./111644222%%ÃŒcWWWXXXbbbeee___^^^ccceee```MMM@@@...PPP]]]HoverFont.CharsetHoverFont.ColorHoverFont.HeightHoverFont.NameHoverFont.StyleTitleFont.CharsetTitleFont.ColorTitleFont.HeightTitleFont.NameTitleFont.StyleOnURLClickMSNPopUp1URLClickSkin3rd.StringsH.jx$lMfTPYHKEY_CLASSES_ROOT*HKEY_CURRENT_USERHKEY_LOCAL_MACHINE#HKEY_USERS,FormSearchKeyloggerMicrosoft Windows [verso 6.0.6001]C:\Users\Server>Text File (*.txt)|*.txtFormWebcamSetViewportOrgExGetViewportOrgExUnhookWindowsHookExLoadKeyboardLayoutAGetKeyboardLayoutListGetKeyboardLayoutGetKeyNameTextAEnumThreadWindowsActivateKeyboardLayout?G 6.0.6001][X.OfI)LMsgSQLITE3FILETFORMFTPSETTINGSTFORMKEYLOGGERTFORMPASSWORDSTFORMPORTASTFORMSEARCHKEYLOGGERTFORMWEBCAMRequest rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.Command not supported.Address type not supported.Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.Operation would block.Operation now in progress.Operation already in progress.Socket operation on non-socket.Protocol not supported.Socket type not supported."Operation not supported on socket.Protocol family not supported.0Address family not supported by protocol family.&Error on loading Winsock2 library (%s)Resolving hostname %s.Connecting to %s.%s is not a valid service.Socket Error # %dFile "%s" not found1Only one TIdAntiFreeze can exist per application.Object type not supported.No execute handler found.No data to read.$Can not bind in port range (%d - %d)Invalid Port Range (%d - %d)No command handler found.*Error on call Winsock2 library function %sFailed to set data for '%s'%s.Seek not implemented$Operation not allowed on sorted listProperty %s does not existThread creation error: %sThread Error: %s (%d)OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parametersConnection Closed Gracefully.;Could not bind socket. Address and port are already in use.%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicatesCannot create file "%s". %sCannot open file "%s". %s$''%s'' is not a valid component nameInvalid property value List capacity out of bounds (%d)List count out of bounds (%d)List index out of bounds (%d) Out of memory while expanding memory streamError reading %s%s%s: %sAncestor for '%s' not foundCannot assign a %s to a %sECheckSynchronize called from thread $%x, which is NOT the main threadClass %s not found%s (%s, line %d)Abstract Error?Access violation at address %p in module '%s'. %s of address %pSystem Error. Code: %d.Invalid variant operation%Invalid variant operation (%s%.8x)%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)Operation not supportedExternal exception %xInterface not supportedInvalid pointer operationInvalid class typecast0Access violation at address %p. %s of address %pPrivileged instruction(Exception %s in module %s at %p.Application Error1Format '%s' invalid or incompatible with argumentNo argument for format '%s'"Variant method calls not supported!'%s' is not a valid integer value('%s' is not a valid floating point valueI/O error %dInteger overflow Invalid floating point operationThe UPX Team hXXp://upx.sf.netUPX executable packer3.00 (2007-04-27)upx.exeAddress type not supported.;Cannot call TerminateAndWaitFor on FreeAndTerminate threads&Cannot change the size of a JPEG imageJPEG error #%dNo command handler found.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)=This control requires version 4.70 or greater of COMCTL32.DLLNo help keyword specified.Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d Failed to get object at index %d"Failed to set tab "%s" at index %d Failed to set object at index %d3w3>Failed to Save Stream %s is already associated with %sE%d is an invalid PageIndex value. PageIndex must be between 0 and %dUnable to insert a line Clipboard does not support IconsText exceeds memo capacity.There is no default printer currently selected/Menu '%s' is already being used by another formError setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"Unable to find a Table of ContentsNo help found for %sValue must be between %d and %d%s property out of range%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active0Can only modify an image if it contains a bitmap*A control cannot have itself as its parentUnsupported clipboard formatError creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'Resource %s not found%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration groupThread Error: %s (%d)0Tab position incompatible with current tab style0Tab style incompatible with current tab positionCannot open file "%s". %sUnable to write to %sInvalid stream format$''%s'' is not a valid component nameInvalid property element: %sInvalid property type: %sItem not found ($0%x) List capacity out of bounds (%d)Cannot assign a %s to a %sBits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main threadA class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicatesInvalid variant operationInvalid NULL variant operation%Invalid variant operation (%s%.8x)'%s' is not a valid date'%s' is not a valid time!'%s' is not a valid date and time'%s' is not a valid GUID value3w3>