Gen.Heur.MSIL.Krypt.11_57f5bc8e33

by malwarelabrobot on January 9th, 2017 in Malware Descriptions.

HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Heur.MSIL.Krypt.11 (B) (Emsisoft), Gen:Heur.MSIL.Krypt.11 (AdAware), HackTool.Win32.PassView.FD, GenericAutorunWorm.YR, HackToolPassView.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, HackTool, WormAutorun


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 57f5bc8e33ff7a4ce555a465bcb529bd
SHA1: 1182d0f891752b68577cf7d956375b433e01304b
SHA256: f7bdfe02d563db567880eeb336a51d04468498cef8a932ac8ca26127d25ce100
SSDeep: 24576:Htj0LYo1U7Py8PORRq1rZUg5Y74aQLFz mdwWkX7xvmI3fu9FcXW:Nj08o1U7h71rF5Y74hLFzU/XRppXW
Size: 1063424 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2015-01-04 23:34:15
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

Behaviour Description
WormAutorun A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.


Process activity

The Trojan creates the following process(es):

secdrv.exe:2856
vbc.exe:2220
vbc.exe:1980

The Trojan injects its code into the following process(es):

secdrv.exe:2840
%original file name%.exe:3676
%original file name%.exe:2384
LookupSvi.exe:1376

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process secdrv.exe:2840 makes changes in the file system.
The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\secdrv.exe (0 bytes)

The process vbc.exe:2220 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderprodkey.txt (1334 bytes)

The process vbc.exe:1980 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderwb.txt (2 bytes)

The process %original file name%.exe:3676 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\LookupSvi.exe (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\secdrv.exe (7433 bytes)

The process %original file name%.exe:2384 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\pid.txt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\pidloc.txt (39 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holdermail.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderprodkey.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderwb.txt (0 bytes)

Registry activity

The process %original file name%.exe:3676 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process %original file name%.exe:2384 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASAPI32]
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASMANCS]
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASAPI32]
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Tracing\57f5bc8e33ff7a4ce555a465bcb529bd_RASMANCS]
"EnableFileTracing" = "0"

The process LookupSvi.exe:1376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Macrovision Security Driver" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\LookupSvi.exe"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

Dropped PE files

MD5 File path
50f931def04bb75dee3828280bea086a c:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\LookupSvi.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.

VersionInfo

Company Name:
Product Name:
Product Version: 0.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename: biuold.exe
Internal Name:
File Version: 0.0.0.0
File Description:
Comments:
Language: Language Neutral

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 8192 1060548 1060864 5.53426 ee074895b6fdea3fd682f1629e157606
.rsrc 1073152 1536 1536 2.56804 afdcd29f8facbe8d262740e00e1eed48
.reloc 1081344 12 512 0.070639 6628aa614de36c958858249a0d7f7ccf

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://whatismyipaddress.com/ 184.86.48.207


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET / HTTP/1.1
Host: whatismyipaddress.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 59
Date: Sun, 08 Jan 2017 09:28:11 GMT
Connection: keep-alive
Access Denied (AK1).  Contact support@whatismyipaddress.comHTTP/1.1 20
0 OK..Content-Type: text/html..Content-Length: 59..Date: Sun, 08 Jan 2
017 09:28:11 GMT..Connection: keep-alive..Access Denied (AK1). Contac
t support@whatismyipaddress.com..


The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_3676_rwx_00142000_00007000:

.hP9)h

%original file name%.exe_2384:

.text
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
v2.0.50727
CMemoryExecute.dll
CMemoryExecute
PAGE_EXECUTE_READWRITE
.ctor
System.Reflection
System.Runtime.InteropServices
System.Security.Permissions
System.Diagnostics
System.Runtime.CompilerServices
DllImportAttribute
kernel32.dll
ntdll.dll
System.Security
$8fcd4931-91a2-4e18-849b-70de34ab75df
1.0.0.0
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
C:\Users\Jovan\Documents\Visual Studio 2010\Projects\Stealer\CMemoryExecute\CMemoryExecute\obj\Release\CMemoryExecute.pdb
mscoree.dll
`.rdata
@.data
.rsrc
ProduKey
%d.%d.%d.%d
ShowKeys
SoftwareKeyFile
AddExportHeaderLine
192.168.0.1
192.168.0.254
ExtractWindowsEdition
UseDefaultProductKey
%s (%s)
%s\Registration
%s\ProductID
%s\Tools\Setup
Microsoft\Microsoft SQL Server
PIDKEY
Microsoft\Windows\CurrentVersion\Uninstall\%s
%s\Common\InstallRoot
Microsoft\Windows NT\CurrentVersion
prodspec.ini
Microsoft\Windows NT\CurrentVersion\DefaultProductKey
Microsoft\Windows\CurrentVersion
$$PRODUCKEY_TEMP_HIVE$$
<meta http-equiv='content-type' content='text/html;charset=%s'>
<br><h4>%s <a href="hXXp://VVV.nirsoft.net/" target="newwin">%s</a></h4><p>
comctl32.dll
Windows
netmsg.dll
Error %d: %s
Iphlpapi.dll
icmp.dll
menu_%d
dialog_%d
TranslatorURL
_lng.ini
%-18s: %s
%%-%d.%ds
<td bgcolor=#%s nowrap>%s
<td bgcolor=#%s>%s
<tr><td%s nowrap><b>%s</b><td bgcolor=#%s%s>%s
bgcolor="%s"
<font color="%s">%s</font>
<%s>%s</%s>
</%s>
report.html
*.txt
*.htm;*.html
*.xml
*.csv
Software\NirSoft\ProduKey
hXXp://VVV.nirsoft.net/utils/product_cd_key_viewer.html
/WindowsKeys
/OfficeKeys
/IEKeys
/SQLKeys
/ExchangeKeys
/deleteregkey
Exception %8.8X at address %8.8X in module %s
Stack Data: %s
Code Data: %s
user32.dll
advapi32.dll
netapi32.dll
psapi.dll
shell32.dll
http\shell\open\command
shlwapi.dll
<html><head>%s<title>%s</title></head>
%s <h3>%s</h3>
size="%d"
color="#%s"
<font color="%s">
<table border="1" cellpadding="5"><tr%s>
width="%s"
<th%s>%s%s%s
c:\Projects\VS2005\ProduKey\Release\ProduKey.pdb
MPR.dll
msvcrt.dll
_acmdln
COMCTL32.dll
WS2_32.dll
GetWindowsDirectoryA
KERNEL32.dll
EnumChildWindows
USER32.dll
GDI32.dll
comdlg32.dll
RegLoadKeyA
RegCloseKey
RegUnLoadKeyA
RegDeleteKeyA
RegEnumKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
ole32.dll
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
hXXp://VVV.usertrust.com1
3hXXp://crl.usertrust.com/AddTrustExternalCARoot.crl05
hXXp://ocsp.usertrust.com0
1hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl05
1hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1hXXp://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
hXXps://secure.comodo.net/CPS0A
0hXXp://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0hXXp://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
hXXp://ocsp.comodoca.com0
support@nirsoft.net0
D$.SPf
u3SSh#
YYSSh
<9%u3
Yuùw
0Ph4%D
Ph,%D
Ph@%D
Phl%D
-./01234$5567
unSShp8D
u.SShx8D
u/SSh
)0)0))123
sqlite_version
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
.NOPQRSTXY|}~
BEFOREIGNOREGEXPLAINSTEADDESCAPEACHECKEYCONSTRAINTERSECTABLEFTHENDATABASELECTRANSACTIONATURALTERAISELSEXCEPTRIGGEREFERENCESUNIQUERYATTACHAVINGROUPDATEMPORARYBEGINNEREINDEXCLUSIVEXISTSBETWEENOTNULLIKECASCADEFERRABLECASECOLLATECREATECURRENT_DATEDELETEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFINTOFFSETISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
3.5.9
d-d-d d:d:d
d:d:d
d-d-d
922337203685477580
%s\etilqs_
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
sqlite3BtreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmented space is %d byte reported as %d on page %d
Unable to malloc %d bytes
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
keyinfo(%d
%s(%d)
%s-mjX
unable to use function %s in the requested context
transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
cannot open indexed column for writing
cannot open value of type %s
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
%s: %s
not authorized to use function: %s
Expression tree is too large (maximum depth %d)
%.*s"%w"%s
%s OR name=%Q
there is already another table or index with this name: %s
sqlite_
table %s may not be altered
view %s may not be altered
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_stat1
CREATE TABLE %Q.sqlite_stat1(tbl,idx,stat)
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
SELECT idx, stat FROM %Q.sqlite_stat1
too many attached databases - max %d
database %s is already in use
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
sqlite_detach
sqlite_attach
%s %T cannot reference objects in database %s
illegal return value (%d) from the authorization function - should be SQLITE_OK, SQLITE_IGNORE, or SQLITE_DENY
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
PRIMARY KEY must be unique
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
foreign_key_list
*** in database %s ***
unsupported encoding: %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s
database schema is locked: %s
unknown or unsupported join type: %T%s%T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
column%d
%z:%d
sqlite_subquery_%p_
%s.%s
no such table: %s
too many terms in %s BY clause
%r %s BY term out of range - should be between 1 and %d
%r ORDER BY term out of range - should be between 1 and %d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';'FROM sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
at most %d tables in a join
TABLE %s
%z AS %s
%z WITH INDEX %s
%z USING PRIMARY KEY
%z VIRTUAL TABLE INDEX %d:%s
SQL logic error or missing database
large file support is disabled
no such vfs: %s
c:\Projects\VS2005\SkypeContactsView\Release\SkypeContactsView.pdb
_wcmdln
VERSION.dll
GetWindowsDirectoryW
RegOpenKeyExW
ShellExecuteW
GAKALASKAHALALABAMAIARARKANSASHAZARIZONAKCACALIFORNIAICOCOLORADOLCTCONNECTICUTUDCDISTRICT OF COLUMBIAIDEDELAWAREHFLFLORIDAHGAGEORGIAGHIHAWAIIEIAIOWAFIDIDAHOIILILLINOISHININDIANAGKSKANSASIKYKENTUCKYJLALOUISIANANMAMASSACHUSETTSIMDMARYLANDFMEMAINEIMIMICHIGANJMNMINNESOTAIMOMISSOURILMSMISSISSIPPIHMTMONTANAONCNORTH CAROLINAMNDNORTH DAKOTAINENEBRASKANNHNEW HAMPSHIREKNJNEW JERSEYKNMNEW MEXICOGNVNEVADAINYNEW YORKEOHOHIOIOKOKLAHOMAGOROREGONMPAPENNSYLVANIALPRPUERTO RICOMRIRHODE ISLANDOSCSOUTH CAROLINAMSDSOUTH DAKOTAJTNTENNESSEEFTXTEXASNUSUNITED STATESEUTUTAHIVAVIRGINIAVVIVIRGIN ISLANDS OF USAHVTVERMONTKWAWASHINGTONJWIWISCONSINNWVWEST VIRGINIAHWYWYOMINGQMHMARSHALL ISLANDSAPADLAFAFGHANISTANHALALBANIAHDZALGERIAOASAMERICAN SAMOAHADANDORRAGAOANGOLAIAIANGUILLAKAQANTARCTICATAGANTIGUA AND BARBUDAJARARGENTINAHAMARMENIAFAWARUBAQACASCENSION ISLANDJAUAUSTRALIAHATAUSTRIAKAZAZERBAIJANHBSBAHAMASHBHBAHRAINKBDBANGLADESHIBBBARBADOSHBYBELARUSHBEBELGIUMGBZBELIZEFBJBENINHBMBERMUDAGBTBHUTANHBOBOLIVIAWBABOSNIA AND HERZEGOWINAIBWBOTSWANANBVBOUVET ISLANDGBRBRAZIL_IOBRITISH INDIAN OCEAN TERRITORYRBNBRUNEI DARUSSALAMIBGBULGARIAMBFBURKINA FASOHBIBURUNDIIKHCAMBODIAICMCAMEROONGCACANADAKCVCAPE VERDEOKYCAYMAN ISLANDSYCFCENTRAL AFRICAN REPUBLICETDCHADFCLCHILEFCNCHINAQCXCHRISTMAS ISLANDXCCCOCOS (KEELING) ISLANDSICOCOLOMBIAHKMCOMOROSeCDCONGO THE DEMOCRATIC REPUBLIC OF THEFCGCONGOMCKCOOK ISLANDSKCRCOSTA RICANCICOTE D'IVOIREHHRCROATIAECUCUBAGCYCYPRUSOCZCZECH REPUBLICHDKDENMARKIDJDJIBOUTIIDMDOMINICASDODOMINICAN REPUBLICKTPEAST TIMORHECECUADORFEGEGYPTLSVEL SALVADORRGQEQUATORIAL GUINEAHERERITREAHEEESTONIAIETETHIOPIAOEUEUROPEAN UNION\FKFALKLAND ISLANDS (MALVINAS)NFOFAROE ISLANDSEFJFIJIHFIFINLANDMFXFRANCE METROGFRFRANCENGFFRENCH GUIANAQPFFRENCH POLYNESIA\TFFRENCH SOUTHERN TERRITORIESFGAGABONGGMGAMBIAHGEGEORGIAHDEGERMANYFGHGHANAJGIGIBRALTARGGRGREECEJGLGREENLANDHGDGRENADAKGPGUADELOUPEEGUGUAMJGTGUATEMALAIGGGUERNSEYGGNGUINEANGWGUINEA-BISSAUGGYGUYANAFHTHAITI\HMHEARD AND MC DONALD ISLANDS^VAHOLY SEE (VATICAN CITY STATE)IHNHONDURASJHKHONG KONGHHUHUNGARYHISICELANDFININDIAJIDINDONESIA[IRIRAN (ISLAMIC REPUBLIC OF)EIQIRAQHIEIRELANDLIMISLE OF MANGILISRAELFITITALYHJMJAMAICAFJPJAPANGJEJERSEYGJOJORDANKKZKAZAKHSTANFKEKENYAIKIKIRIBATIfKPKOREA DEMOCRATIC PEOPLE'S REPUBLIC OFRKRKOREA REPUBLIC OFGKWKUWAITKKGKYRGYZSTANaLALAO PEOPLE'S DEMOCRATIC REPUBLICGLVLATVIAHLBLEBANONHLSLESOTHOHLRLIBERIAWLYLIBYAN ARAB JAMAHIRIYANLILIECHTENSTEINJLTLITHUANIAKLULUXEMBOURGFMOMACAUJMKMACEDONIAKMGMADAGASCARGMWMALAWIIMYMALAYSIAIMVMALDIVESEMLMALIFMTMALTAQMHMARSHALL ISLANDSKMQMARTINIQUEKMRMAURITANIAJMUMAURITIUSHYTMAYOTTEGMXMEXICO_FMMICRONESIA FEDERATED STATES OFTMDMOLDOVA REPUBLIC OFGMCMONACOIMNMONGOLIAKMSMONTSERRATHMAMOROCCOKMZMOZAMBIQUEHMMMYANMARKMEMontenegroHNANAMIBIAFNRNAURUFNPNEPALUANNETHERLANDS ANTILLESLNLNETHERLANDSNNCNEW CALEDONIALNZNEW ZEALANDJNINICARAGUAFNENIGERHNGNIGERIAENUNIUE[APNON-SPEC ASIA PAS LOCATIONONFNORFOLK ISLANDYMPNORTHERN MARIANA ISLANDSGNONORWAYEOMOMANIPKPAKISTANFPWPALAU_PSPALESTINIAN TERRITORY OCCUPIEDGPAPANAMAQPGPAPUA NEW GUINEAIPYPARAGUAYEPEPERULPHPHILIPPINESIPNPITCAIRNGPLPOLANDIPTPORTUGALLPRPUERTO RICOFQAQATARIZZRESERVEDHREREUNIONHROROMANIASRURUSSIAN FEDERATIONGRWRWANDAVKNSAINT KITTS AND NEVISLLCSAINT LUCIAaVCSAINT VINCENT AND THE GRENADINESFWSSAMOAKSMSAN MARINOVSTSAO TOME AND PRINCIPEMSASAUDI ARABIAHSNSENEGALKSCSEYCHELLESMSLSIERRA LEONEJSGSINGAPORE[SKSLOVAKIA (Slovak Republic)ISISLOVENIAPSBSOLOMON ISLANDSHSOSOMALIAMZASOUTH AFRICAmGSSOUTH GEORGIA AND THE SOUTH SANDWICH ISLANDSFESSPAINJLKSRI LANKAKSHST. HELENAXPMST. PIERRE AND MIQUELONFSDSUDANISRSURINAME_SJSVALBARD AND JAN MAYEN ISLANDSJSZSWAZILANDGSESWEDENLCHSWITZERLANDUSYSYRIAN ARAB REPUBLICVCSSerbia and MontenegroVYUSerbia and MontenegroGRSSerbiaGTWTAIWANKTJTAJIKISTAN\TZTANZANIA UNITED REPUBLIC OFITHTHAILANDLTLTIMOR-LESTEETGTOGOHTKTOKELAUFTOTONGATTTTRINIDAD AND TOBAGOHTNTUNISIAGTRTURKEYMTMTURKMENISTANYTCTURKS AND CAICOS ISLANDSGTVTUVALUGUGUGANDAHUAUKRAINEUAEUNITED ARAB EMIRATESOGBUNITED KINGDOMOUKUNITED KINGDOMeUMUNITED STATES MINOR OUTLYING ISLANDSNUSUNITED STATESHUYURUGUAYKUZUZBEKISTANHVUVANUATUJVEVENEZUELAIVNVIET NAMYVGVIRGIN ISLANDS (BRITISH)VVIVIRGIN ISLANDS (U.S.)ZWFWALLIS AND FUTUNA ISLANDSOEHWESTERN SAHARAFYEYEMENGZMZAMBIAIZWZIMBABWENAXALAND ISLANDSMMFSAINT MARTINA
\YwEB
-4=-4=-4=-4=
 2 34 567
com.apple.Safari
com.apple.WebKit2WebProcess
SELECT origin_url, action_url, username_element, username_value, password_element, password_value, signon_realm, date_created from logins
"Account","Login Name","Password","Web Site","Comments"
3.7.5
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
SELECT id, hostname, httpRealm, formSubmitURL, usernameField, passwordField, encryptedUsername, encryptedPassword FROM moz_logins
PK11_GetInternalKeySlot
PK11_CheckUserPassword
unknown operation
foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_source_id
sqlite_rename_parent
%Y-%m-%d %H:%M:%S
%Y-%m-%d
%H:%M:%S
SQLITE_
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
API call with %s database connection pointer
%s-shm
OsError 0x%x (%u)
Recovered %d frames from WAL file %s
foreign key constraint failed
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot %s savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
statement aborts at %d: [%s] %s
oversized integer: %s%s
misuse of aggregate: %s()
%s%.*s"%w"
type='trigger' AND (%s)
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE tbl=%Q
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
invalid name: "%s"
sqlite_autoindex_%s_%d
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
foreign key mismatch
%s.%s may not be NULL
malformed database schema (%s)
%s - %s
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unknown or unsupported join type: %T %T%s%T
%s:%d
no such index: %s
cannot VACUUM - SQL statements in progress
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unknown database: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
sqlite3_open
sqlite3_prepare
sqlite3_step
sqlite3_column_text
sqlite3_column_int
sqlite3_column_int64
sqlite3_finalize
sqlite3_close
sqlite3_exec
c:\projects\vs2005\webbrowserpassview\command-line\WebBrowserPassView.pdb
FindNextUrlCacheEntryW
FindFirstUrlCacheEntryW
FindCloseUrlCache
WININET.dll
GetKeyState
RegEnumKeyExW
5JEw%Xg
t{SSh
v%SSW
Mozilla\Profiles
Software\Mozilla\Mozilla Thunderbird
%s\Main
sqlite3.dll
nss3.dll
%programfiles%\Mozilla Thunderbird
%s %s %s
HTTPMail User Name
SMTP USer Name
HTTPMail Server
SMTP Server
POP3 Password2
IMAP Password2
HTTPMail Password2
SMTP Password2
POP3 Port
IMAP Port
HTTPMail Port
SMTP Port
HTTPMail Secure Connection
SMTP Secure Connection
SMTP Display Name
SMTP Email Address
POP3 Password
IMAP Password
HTTP Password
SMTP Password
HTTP User
SMTP User
HTTP Server URL
HTTP Port
HTTPMail Use SSL
SMTP Use SSL
%s\%s
PopPort
PopPassword
SMTPAccount
SMTPServer
SMTPPort
SMTPLogSecure
SMTPPassword
%s\Accounts
LoginName
SavePasswordText
ESMTPUsername
ESMTPPassword
POP3Password
fb.dat
%s@gmail.com
%s@yahoo.com
Software\Microsoft\Windows Messaging Subsystem\Profiles
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
smtp
*.ini
/skeepass
Failed to load the executable file !
mail.account.account
mail.server
port
mail.identity
signon.signonfilename
mailbox://%s@%s
imap://%s@%s
mailbox://%s
imap://%s
smtp://%s
signons.txt
signons.sqlite
prefs.js
Password.NET Messenger Service
User.NET Messenger Service
Passport.Net\*
ps:password
windowslive:name=
mozsqlite3.dll
pstorec.dll
5e7e8100-9138-11d1-945a-00c04fc308ff
00000000-0000-0000-0000-000000000000
220D5CD0-853A-11D0-84BC-00C04FD43F8F
220D5CD1-853A-11D0-84BC-00C04FD43F8F
220D5CC1-853A-11D0-84BC-00C04FD43F8F
417E2D75-84BD-11D0-84BB-00C04FD43F8F
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Mozilla
mozilla
%s\bin
PathToExe
\sqlite3.dll
\mozsqlite3.dll
\nss3.dll
Software\Microsoft\Windows Mail
Software\Microsoft\Windows Live Mail
SMTP_Server
SMTP_User_Name
POP3_Password2
IMAP_Password2
NNTP_Password2
SMTP_Password2
SMTP_Email_Address
SMTP_Port
NNTP_Port
IMAP_Port
POP3_Port
SMTP_Secure_Connection
*.oeaccount
\Microsoft\Windows Mail
\Microsoft\Windows Live Mail
c:\Projects\VS2005\mailpv\Command-Line\mailpv.pdb
RPCRT4.dll
RegEnumKeyA
Debugger.exe
Microsoft.VisualBasic
System.Windows.Forms
System.Drawing
System.Management
tapi32.dll
rtm.dll
Debugger.Resources.resources
Debugger.Debugger.resources
Debugger.My
WindowsFormsApplicationBase
Microsoft.VisualBasic.ApplicationServices
System.ComponentModel
System.CodeDom.Compiler
Microsoft.VisualBasic.Devices
m_MyWebServicesObjectProvider
.cctor
get_WebServices
HelpKeywordAttribute
System.ComponentModel.Design
WebServices
Microsoft.VisualBasic.CompilerServices
System.Collections
ContainsKey
InvalidOperationException
MyWebServices
Microsoft.Win32
CDkeysteal
encryptedpassstring
encryptedsmtpstring
portstring
fakeMSGholder
encryptedftphost
encryptedftpuser
encryptedftppass
useftp
websitevisitor
websiteblocker
passstring
smtpstring
ftphost
ftpuser
ftppass
WM_KEYUP
WM_KEYDOWN
WM_SYSKEYDOWN
WM_SYSKEYUP
KeyboardHandle
KeyLog
bProdkey
CleanedPasswordsMAIL
CleanedPasswordsWB
CleanedPasswordsProduKey
CleanedPasswordsSkypeViewer
CleanedPasswordsKeyRec
System.IO
get_ExecutablePath
set_WindowState
FormWindowState
UnhookWindowsHookEx
SetWindowsHookEx
SetWindowsHookExA
GetAsyncKeyState
vKey
HookKeyboard
UnhookKeyboard
Operators
get_Keyboard
Keyboard
get_CtrlKeyDown
get_AltKeyDown
KeyboardCallback
System.Threading
Microsoft.VisualBasic.MyServices
ForceSteamLogin
System.Net.NetworkInformation
get_OperationalStatus
OperationalStatus
FakemsgInstall
System.Net.Mail
SmtpClient
System.Globalization
set_Port
System.Net
RegistryKey
OpenSubKey
System.Security.Cryptography
System.Text
set_Key
stealProductKey
stealWebroswers
System.Collections.ObjectModel
SendLogsFTP
FtpWebRequest
WebRequest
UploadFTP
WebClient
secretKey
set_KeySize
get_KeySize
System.Net.Sockets
virtualKey
KeyboardHookDelegate
get_Msg
Debugger.My.Resources
System.Resources
get_CMemoryExecute
get_ProduKey
get_WebBrowserPassView
WebBrowserPassView
System.Configuration
8.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
$b447ccbf-ff01-4ccb-bc8c-d93085077044
_CorExeMain
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
Copy Product &Key
&HTML Report - All Items
HTML R&eport - Selected Items
Extract Windows E&dition
Show &Windows Keys
Show &Office Keys
Show &Internet Explorer Keys
Show &SQL Server Keys
Show &Exchange Server Keys
Load Default Product Key
&Go To ProduKey Web Page
Copy Product Key
HTML Report - All Items
HTML Report - Selected Items
Load the product keys from your local computer
Load the product keys of external Windows installations from all disks currently plugged to your computer
Load the product keys from external Windows directory:
Load the product keys from external Software Registry hive:
Load the product keys from remote computer:
Load the product keys from remote computers specified in the following text file:
Load the product keys from all computers in the specified domain:
Load the product keys from all computers in your local network
Load the product keys from all computers in the specified IP addresses range:
%d item(s)
, %d Selected
Product Key List
Connecting %s...
Enumerating all computers on %s!Select external Windows directory%Select software Registry file to load
Loading... %d
Product key was not found
Product Key
SQL Server
!Select external Windows directory
ProduKey.exe
%%0.ß
main.db
@netmsg.dll
@%s - %s
@shell32.dll
*.db?
main.db-journal
SkypeContactsView.exe
Apple Computer\Preferences\keychain.plist
LoadPasswordsIE
LoadPasswordsFirefox
LoadPasswordsChrome
LoadPasswordsOpera
LoadPasswordsSafari
LoadPasswordsSeaMonkey
UseFirefoxProfileFolder
UseFirefoxInstallFolder
UseChromeProfileFolder
UseOperaPasswordFile
FirefoxProfileFolder
FirefoxInstallFolder
ChromeProfileFolder
OperaPasswordFile
Aadvapi32.dll
crypt32.dll
777705555443332
5555443332
5555443332
wand.dat
@nss3.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe
%programfiles%\Sea Monkey
%programfiles%\Mozilla Firefox
logins
encryptedPassword
passwordField
httpRealm
-signons.txt
signons2.txt
signons3.txt
logins.json
@dllhost.exe
taskhost.exe
taskhostex.exe
Microsoft\Windows\WebCache\WebCacheV01.dat
Microsoft\Windows\WebCache\WebCacheV24.dat
index.dat
hXXps://VVV.google.com/accounts/servicelogin
hXXp://VVV.facebook.com/
hXXps://login.yahoo.com/config/login
hXXp://
hXXps://
PTF://
@history.dat
places.sqlite
Mozilla\Firefox\Profiles
Mozilla\SeaMonkey\Profiles
Mozilla\SeaMonkey
Mozilla\Firefox
profiles.ini
Profile%d
tntdll.dll
sWeb Data
Login Data
Google\Chrome\User Data
Google\Chrome SxS\User Data
Opera\Opera\wand.dat
Opera\Opera7\profile\wand.dat
Opera
Opera Software\Opera Stable\Login Data
A"%s"
Ashell32.dll
.save
vaultcli.dll
abe2869f-9b47-4cd9-a358-c22904dba7f7
Copy &Password
Load Passwords From...
Google Chrome
Mozilla Firefox
SeaMonkey
Firefox Options
Master password:
Firefox Profile:
Firefox Installation:
Chrome Options
Opera Options
Opera Login file:
%d Passwords
Web Browser Passwords%Choose another Firefox profile folder)Choose the installation folder of Firefox,Choose another profile of Chrome Web browser,Choose the password file of Opera (wand.dat)
KeePass csv file
Opera Password File
Firefox 1.x
Firefox 2.x
Firefox 3.0
Firefox 3.5-31
Chrome
Firefox 32 
Web Browser
Password
Password Strength
Password Field
WebBrowserPassView.exe
VVV.google.com/Please log in to your Gmail account
VVV.google.com:443/Please log in to your Gmail account
VVV.google.com/Please log in to your Google Account
VVV.google.com:443/Please log in to your Google Account
VVV.google.com
dWindowsLive:name=*
82BD0E67-9FEA-4748-8672-D5EFE5B779B0
Copy Password
%d items
Select Eudora.ini filename/Select the location of Thunderbird installation
Eudora.ini file
SMTP
Windows Mail
Windows Live Mail
Server Port
SMTP Server Port
Email Password-Recovery
Mail PassView
3;  ; #.)
HKEY_LOCAL_MACHINE\SOFTWARE\Ubisoft\Splinter Cell Pandora Tomorrow
CDKey
HKEY_LOCAL_MACHINE\SOFTWARE\Ubisoft\Splinter Cell Chaos Theory\Keys
DiscKey_SCCT
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty
codkey
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty United Offensive
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty 2
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty 4
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty WAW
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Dawn of War
CDKEY
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Dawn of War - Dark Crusade
W40KCDKEY
WXPCDKEY
HKEY_LOCAL_MACHINE\SOFTWARE\SEGA\Medieval II Total War
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Golive\5.0\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\ahead\Installation\BAK\Nero 7\Info
HKEY_LOCAL_MACHINE\SOFTWARE\ACD Systems\PicaView
HKEY_LOCAL_MACHINE\SOFTWARE\Eugen Systems\ActOfWa
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Photoshop\7.0\Registration
Advanced PDF Password Recovery :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced PDF Password Recovery\Registration
Advanced PDF Password Recovery Pro :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced PDF Password Recovery Pro\Registration
Advanced ZIP Password Recovery :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced ZIP Password Recovery\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Sunflowers\Anno 1701
HKEY_LOCAL_MACHINE\SOFTWARE\ashampoo\Ashampoo WinOptimizer Platinum 3
HKEY_LOCAL_MACHINE\SOFTWARE\@stake\LC5\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942 Secret Weapons of WWII
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942 The Road to Rome
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Battlefield 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 2142
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Battlefield Vietnam
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Black and White
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Black and White 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Boulder Dash Rocks
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Burnout Paradise
HKEY_LOCAL_MACHINE\SOFTWARE\TechSmith\Camtasia Studio\4.0
Camtasia Studio 4(Key) :
RegistrationKey
Chrome :
HKEY_LOCAL_MACHINE\SOFTWARE\Techland\Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Codec Tweak Tool
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Generals
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Red Alert 2
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Red Alert
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Tiberian Sun
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Command and Conquer 3
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Command and Conquer 3
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Company of Heroes
CoHProductKey
CoHOFProductKey
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Counter-Strike\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Crysis
HKEY_LOCAL_MACHINE\SOFTWARE\Cyberlink\PowerDVD
HKEY_LOCAL_MACHINE\SOFTWARE\Cyberlink\PowerBar
HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerProducer\3.0\UserReg
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Day of Defeat\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\The Battle for Middle-earth II
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 University
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Nightlife
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Open For Business
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Pets
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Seasons
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Glamour Life Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Celebration Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 H M Fashion Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Family Fun Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\DVD Audio Extractor\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Sierra\Empire Earth II
HKEY_LOCAL_MACHINE\SOFTWARE\Sierra\CDKey
HKEY_LOCAL_MACHINE\SOFTWARE\F-Secure\BackWeb\iLauncher
HKEY_LOCAL_MACHINE\SOFTWARE\CRYTEK\FARCRY\UBI.COM
HKEY_LOCAL_MACHINE\SOFTWARE\CRYTEK\FARCRY2\UBI.COM
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2005
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 07
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\FIFA 08
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Distribution\Freedom Force
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Frontlines: Fuel of War Beta
ProductKey
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Frontlines: Fuel of War
HKEY_LOCAL_MACHINE\SOFTWARE\Headlight\GetRight
Global Operations :
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Global Operations
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Gunman
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Half-Life\Setting
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Hellgate: London
HKEY_LOCAL_MACHINE\SOFTWARE\Illusion Softworks\Hidden & Dangerous 2
HKEY_LOCAL_MACHINE\SOFTWARE\IGI 2 Retail\CDKey
CDkey
HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\InCD
HKEY_LOCAL_MACHINE\SOFTWARE\JoWooD\InstalledGames\IG2
prvkey
HKEY_LOCAL_MACHINE\SOFTWARE\AVConverter\iPod Converter
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\James Bond 007 Nightfire
HKEY_LOCAL_MACHINE\SOFTWARE\3d0\Status Legends of Might and Magic
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Flash\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Fireworks\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Dreamweaver\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Madden NFL 07
HKEY_LOCAL_MACHINE\SOFTWARE\JSG\Matrix Saver V2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Medal of Honor Airborne
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Breakthrough
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Spearhead
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Medal of Honor: Heroes 2
HKEY_LOCAL_MACHINE\SOFTWARE\mIRC
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Nascar Racing 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Nascar Racing 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 07
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA Live 08
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Need for Speed Carbon
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need For Speed Hot Pursuit 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need for Speed Most Wanted
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Need for Speed ProStreet
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need For Speed Underground
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Need for Speed Underground 2
HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\Nero - Burning Rom\Info
HKEY_LOCAL_MACHINE\Software\Nero\Installation\Families\Nero 7\Info
HKEY_LOCAL_MACHINE\SOFTWARE\Nero\Installation\Families\Nero 8\Info
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2005
HKEY_LOCAL_MACHINE\Software\Westwood\Nox
HKEY_LOCAL_MACHINE\Software\NuMega\SmartCheck
HKEY_LOCAL_MACHINE\Software\OnlineTVPlayer\RegInfo
HKEY_LOCAL_MACHINE\Software\O&O\O&O Defrag\8.0\Pro\licenses
HKEY_LOCAL_MACHINE\Software\PowerQuest\PartitionMagic\8.0\UserInfo
Passware Encryption Analyzer (Name) :
HKEY_LOCAL_MACHINE\Software\Passware\Encryption Analyzer\1\Registration,License
Passware Encryption Analyzer (License) :
Passware Encryption Analyzer (Serial) :
Passware Windows Key (License) :
HKEY_LOCAL_MACHINE\Software\Passware\Windows Key\7\Registration
Passware Windows Key (Name) :
Passware Windows Key (Serial) :
HKEY_LOCAL_MACHINE\Software\CyberLink\PowerDVD
HKEY_LOCAL_MACHINE\Software\EnTech\PowerStrip
HKEY_LOCAL_MACHINE\Software\KONAMI\PES2008
HKEY_LOCAL_MACHINE\Software\Red Storm Entertainment\RAVENSHIELD
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Shogun Total War - Warlord Edition
HKEY_LOCAL_MACHINE\Software\Atari\Sid Meier's Pirates!
HKEY_LOCAL_MACHINE\Software\Ubisoft\SILENT HUNTER III\Keys
DiscKey_SH3
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Maxis\ Sim City 4 Deluxe
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Maxis\ Sim City 4
HKEY_LOCAL_MACHINE\Software\Network Associates, Inc.\Sniffer Pro\4.5\USER
HKEY_LOCAL_MACHINE\Software\Silver Style Entertainment\Soldiers Of Anarchy
HKEY_LOCAL_MACHINE\Software\GSC Game World\STALKER-SHOC
InstallCDKEY
HKEY_LOCAL_MACHINE\Software\LucasArts\Star Wars Battlefront II\1.0
CD Key
HKEY_LOCAL_MACHINE\Software\LucasArts\Star Wars Battlefront II\1.1
HKEY_LOCAL_MACHINE\Software\Steganos\SIAVPN
HKEY_LOCAL_MACHINE\Software\THQ\Gas Powered Games\Supreme Commander
HKEY_LOCAL_MACHINE\Software\Sierra\CDKey
HKEY_LOCAL_MACHINE\Software\TechSmith\SnagIt\8
HKEY_LOCAL_MACHINE\Software\TexasCalc\License
Registration Key
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Games\The Battle for Middle-earth
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Games\The Orange Box
HKEY_LOCAL_MACHINE\Software\Pegasys Inc.\TMPGEnc DVD Author\1.0
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\6.0
TuneUp 2007 (Key) :
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\7.0
TuneUp 2008 (Key) :
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\8.0
TuneUp 2009 (Key) :
HKEY_LOCAL_MACHINE\Software\Nullsoft\Winamp
regkey
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Sims\The Sims 3\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Sims\The Sims 2\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Family Fun Stuff\erg
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Glamour Life Stuff\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Nightlife\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Open For Business\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 University\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\SPORE(TM)\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Mirror's Edge\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty2
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty4
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty WAW
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Half-Life\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Halo
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\CounterStrike\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Rockstar Games\Grand Theft Auto IV
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 09\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\KONAMI\PES2009
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Dead Space\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Battlefield 2 Special Forces\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Transformers2
HKEY_LOCAL_MACHINE\SOFTWARE\Rockstar Games\Bully Scholarship Edition
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\NERO BURNING ROM
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\INSTALLATION\FAMILIES\NERO 7\INFO
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\INSTALLATION\FAMILIES\NERO 8\INFO
HKEY_LOCAL_MACHINE\SOFTWARE\NERO\SHARED\FAMILIES\NL9
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 08\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 07\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2005\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2004\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2003\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2002\ergc
HKEY_CURRENT_USER\Software\mIRC\
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Orange Box
Password :
GTA IV Serial Key :
MessageBoxIcon.Error
yesftp
filename.exe
hXXp://VVV.example.com/directory/file.exe
Disablecmd
\Windows Update.exe
\WindowsUpdate.exe
SysInfo.txt
\pid.txt
\pidloc.txt
noftp
127.0.0.1
\SteamAppData.vdf
\ClientRegistry.blob
MessageBoxIcon.Exclamation
Keylogger Enabled:
Operating System:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
autorun.inf
open=Sys.exe
Sys.exe
Software\Microsoft\Windows\CurrentVersion\Run
Windows Update
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
Microsoft.NET\Framework\v2.0.50727\vbc.exe
holdermail.txt"
holdermail.txt
holderwb.txt"
holderwb.txt
holderprodkey.txt"
holderprodkey.txt
holderskypeview.txt"
holderskypeview.txt
Operating System Intel Recovery
Operating System Platform:
Operating System Version:
WEB Browser Password Recovery
Mail Messenger Password Recovery
Windows/Microsoft Product Key Recovery
CD Key Recovery (400   Keys)
\.minecraft\lastlogin
There is a file attached to this email containing Minecraft username and password download it then decrypt the login information with my Minecraft Decryptor
Logger - Key Recorder - [
Keylogger Log
.jpeg
Logger_KeyLog_
hXXp://whatismyipaddress.com/
Debugger.Resources
:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

%original file name%.exe_2384_rwx_00242000_0000B000:

.hP9)h

%original file name%.exe_2384_rwx_00400000_000F0000:

.text
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
v2.0.50727
CMemoryExecute.dll
CMemoryExecute
PAGE_EXECUTE_READWRITE
.ctor
System.Reflection
System.Runtime.InteropServices
System.Security.Permissions
System.Diagnostics
System.Runtime.CompilerServices
DllImportAttribute
kernel32.dll
ntdll.dll
System.Security
$8fcd4931-91a2-4e18-849b-70de34ab75df
1.0.0.0
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
C:\Users\Jovan\Documents\Visual Studio 2010\Projects\Stealer\CMemoryExecute\CMemoryExecute\obj\Release\CMemoryExecute.pdb
mscoree.dll
`.rdata
@.data
.rsrc
ProduKey
%d.%d.%d.%d
ShowKeys
SoftwareKeyFile
AddExportHeaderLine
192.168.0.1
192.168.0.254
ExtractWindowsEdition
UseDefaultProductKey
%s (%s)
%s\Registration
%s\ProductID
%s\Tools\Setup
Microsoft\Microsoft SQL Server
PIDKEY
Microsoft\Windows\CurrentVersion\Uninstall\%s
%s\Common\InstallRoot
Microsoft\Windows NT\CurrentVersion
prodspec.ini
Microsoft\Windows NT\CurrentVersion\DefaultProductKey
Microsoft\Windows\CurrentVersion
$$PRODUCKEY_TEMP_HIVE$$
<meta http-equiv='content-type' content='text/html;charset=%s'>
<br><h4>%s <a href="hXXp://VVV.nirsoft.net/" target="newwin">%s</a></h4><p>
comctl32.dll
Windows
netmsg.dll
Error %d: %s
Iphlpapi.dll
icmp.dll
menu_%d
dialog_%d
TranslatorURL
_lng.ini
%-18s: %s
%%-%d.%ds
<td bgcolor=#%s nowrap>%s
<td bgcolor=#%s>%s
<tr><td%s nowrap><b>%s</b><td bgcolor=#%s%s>%s
bgcolor="%s"
<font color="%s">%s</font>
<%s>%s</%s>
</%s>
report.html
*.txt
*.htm;*.html
*.xml
*.csv
Software\NirSoft\ProduKey
hXXp://VVV.nirsoft.net/utils/product_cd_key_viewer.html
/WindowsKeys
/OfficeKeys
/IEKeys
/SQLKeys
/ExchangeKeys
/deleteregkey
Exception %8.8X at address %8.8X in module %s
Stack Data: %s
Code Data: %s
user32.dll
advapi32.dll
netapi32.dll
psapi.dll
shell32.dll
http\shell\open\command
shlwapi.dll
<html><head>%s<title>%s</title></head>
%s <h3>%s</h3>
size="%d"
color="#%s"
<font color="%s">
<table border="1" cellpadding="5"><tr%s>
width="%s"
<th%s>%s%s%s
c:\Projects\VS2005\ProduKey\Release\ProduKey.pdb
MPR.dll
msvcrt.dll
_acmdln
COMCTL32.dll
WS2_32.dll
GetWindowsDirectoryA
KERNEL32.dll
EnumChildWindows
USER32.dll
GDI32.dll
comdlg32.dll
RegLoadKeyA
RegCloseKey
RegUnLoadKeyA
RegDeleteKeyA
RegEnumKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
ole32.dll
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
hXXp://VVV.usertrust.com1
3hXXp://crl.usertrust.com/AddTrustExternalCARoot.crl05
hXXp://ocsp.usertrust.com0
1hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl05
1hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1hXXp://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
hXXps://secure.comodo.net/CPS0A
0hXXp://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0hXXp://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
hXXp://ocsp.comodoca.com0
support@nirsoft.net0
D$.SPf
u3SSh#
YYSSh
<9%u3
Yuùw
0Ph4%D
Ph,%D
Ph@%D
Phl%D
-./01234$5567
unSShp8D
u.SShx8D
u/SSh
)0)0))123
sqlite_version
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
.NOPQRSTXY|}~
BEFOREIGNOREGEXPLAINSTEADDESCAPEACHECKEYCONSTRAINTERSECTABLEFTHENDATABASELECTRANSACTIONATURALTERAISELSEXCEPTRIGGEREFERENCESUNIQUERYATTACHAVINGROUPDATEMPORARYBEGINNEREINDEXCLUSIVEXISTSBETWEENOTNULLIKECASCADEFERRABLECASECOLLATECREATECURRENT_DATEDELETEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFINTOFFSETISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
3.5.9
d-d-d d:d:d
d:d:d
d-d-d
922337203685477580
%s\etilqs_
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
sqlite3BtreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmented space is %d byte reported as %d on page %d
Unable to malloc %d bytes
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
keyinfo(%d
%s(%d)
%s-mjX
unable to use function %s in the requested context
transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
cannot open indexed column for writing
cannot open value of type %s
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
%s: %s
not authorized to use function: %s
Expression tree is too large (maximum depth %d)
%.*s"%w"%s
%s OR name=%Q
there is already another table or index with this name: %s
sqlite_
table %s may not be altered
view %s may not be altered
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_stat1
CREATE TABLE %Q.sqlite_stat1(tbl,idx,stat)
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
SELECT idx, stat FROM %Q.sqlite_stat1
too many attached databases - max %d
database %s is already in use
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
sqlite_detach
sqlite_attach
%s %T cannot reference objects in database %s
illegal return value (%d) from the authorization function - should be SQLITE_OK, SQLITE_IGNORE, or SQLITE_DENY
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
PRIMARY KEY must be unique
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
foreign_key_list
*** in database %s ***
unsupported encoding: %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s
database schema is locked: %s
unknown or unsupported join type: %T%s%T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
column%d
%z:%d
sqlite_subquery_%p_
%s.%s
no such table: %s
too many terms in %s BY clause
%r %s BY term out of range - should be between 1 and %d
%r ORDER BY term out of range - should be between 1 and %d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';'FROM sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
at most %d tables in a join
TABLE %s
%z AS %s
%z WITH INDEX %s
%z USING PRIMARY KEY
%z VIRTUAL TABLE INDEX %d:%s
SQL logic error or missing database
large file support is disabled
no such vfs: %s
c:\Projects\VS2005\SkypeContactsView\Release\SkypeContactsView.pdb
_wcmdln
VERSION.dll
GetWindowsDirectoryW
RegOpenKeyExW
ShellExecuteW
GAKALASKAHALALABAMAIARARKANSASHAZARIZONAKCACALIFORNIAICOCOLORADOLCTCONNECTICUTUDCDISTRICT OF COLUMBIAIDEDELAWAREHFLFLORIDAHGAGEORGIAGHIHAWAIIEIAIOWAFIDIDAHOIILILLINOISHININDIANAGKSKANSASIKYKENTUCKYJLALOUISIANANMAMASSACHUSETTSIMDMARYLANDFMEMAINEIMIMICHIGANJMNMINNESOTAIMOMISSOURILMSMISSISSIPPIHMTMONTANAONCNORTH CAROLINAMNDNORTH DAKOTAINENEBRASKANNHNEW HAMPSHIREKNJNEW JERSEYKNMNEW MEXICOGNVNEVADAINYNEW YORKEOHOHIOIOKOKLAHOMAGOROREGONMPAPENNSYLVANIALPRPUERTO RICOMRIRHODE ISLANDOSCSOUTH CAROLINAMSDSOUTH DAKOTAJTNTENNESSEEFTXTEXASNUSUNITED STATESEUTUTAHIVAVIRGINIAVVIVIRGIN ISLANDS OF USAHVTVERMONTKWAWASHINGTONJWIWISCONSINNWVWEST VIRGINIAHWYWYOMINGQMHMARSHALL ISLANDSAPADLAFAFGHANISTANHALALBANIAHDZALGERIAOASAMERICAN SAMOAHADANDORRAGAOANGOLAIAIANGUILLAKAQANTARCTICATAGANTIGUA AND BARBUDAJARARGENTINAHAMARMENIAFAWARUBAQACASCENSION ISLANDJAUAUSTRALIAHATAUSTRIAKAZAZERBAIJANHBSBAHAMASHBHBAHRAINKBDBANGLADESHIBBBARBADOSHBYBELARUSHBEBELGIUMGBZBELIZEFBJBENINHBMBERMUDAGBTBHUTANHBOBOLIVIAWBABOSNIA AND HERZEGOWINAIBWBOTSWANANBVBOUVET ISLANDGBRBRAZIL_IOBRITISH INDIAN OCEAN TERRITORYRBNBRUNEI DARUSSALAMIBGBULGARIAMBFBURKINA FASOHBIBURUNDIIKHCAMBODIAICMCAMEROONGCACANADAKCVCAPE VERDEOKYCAYMAN ISLANDSYCFCENTRAL AFRICAN REPUBLICETDCHADFCLCHILEFCNCHINAQCXCHRISTMAS ISLANDXCCCOCOS (KEELING) ISLANDSICOCOLOMBIAHKMCOMOROSeCDCONGO THE DEMOCRATIC REPUBLIC OF THEFCGCONGOMCKCOOK ISLANDSKCRCOSTA RICANCICOTE D'IVOIREHHRCROATIAECUCUBAGCYCYPRUSOCZCZECH REPUBLICHDKDENMARKIDJDJIBOUTIIDMDOMINICASDODOMINICAN REPUBLICKTPEAST TIMORHECECUADORFEGEGYPTLSVEL SALVADORRGQEQUATORIAL GUINEAHERERITREAHEEESTONIAIETETHIOPIAOEUEUROPEAN UNION\FKFALKLAND ISLANDS (MALVINAS)NFOFAROE ISLANDSEFJFIJIHFIFINLANDMFXFRANCE METROGFRFRANCENGFFRENCH GUIANAQPFFRENCH POLYNESIA\TFFRENCH SOUTHERN TERRITORIESFGAGABONGGMGAMBIAHGEGEORGIAHDEGERMANYFGHGHANAJGIGIBRALTARGGRGREECEJGLGREENLANDHGDGRENADAKGPGUADELOUPEEGUGUAMJGTGUATEMALAIGGGUERNSEYGGNGUINEANGWGUINEA-BISSAUGGYGUYANAFHTHAITI\HMHEARD AND MC DONALD ISLANDS^VAHOLY SEE (VATICAN CITY STATE)IHNHONDURASJHKHONG KONGHHUHUNGARYHISICELANDFININDIAJIDINDONESIA[IRIRAN (ISLAMIC REPUBLIC OF)EIQIRAQHIEIRELANDLIMISLE OF MANGILISRAELFITITALYHJMJAMAICAFJPJAPANGJEJERSEYGJOJORDANKKZKAZAKHSTANFKEKENYAIKIKIRIBATIfKPKOREA DEMOCRATIC PEOPLE'S REPUBLIC OFRKRKOREA REPUBLIC OFGKWKUWAITKKGKYRGYZSTANaLALAO PEOPLE'S DEMOCRATIC REPUBLICGLVLATVIAHLBLEBANONHLSLESOTHOHLRLIBERIAWLYLIBYAN ARAB JAMAHIRIYANLILIECHTENSTEINJLTLITHUANIAKLULUXEMBOURGFMOMACAUJMKMACEDONIAKMGMADAGASCARGMWMALAWIIMYMALAYSIAIMVMALDIVESEMLMALIFMTMALTAQMHMARSHALL ISLANDSKMQMARTINIQUEKMRMAURITANIAJMUMAURITIUSHYTMAYOTTEGMXMEXICO_FMMICRONESIA FEDERATED STATES OFTMDMOLDOVA REPUBLIC OFGMCMONACOIMNMONGOLIAKMSMONTSERRATHMAMOROCCOKMZMOZAMBIQUEHMMMYANMARKMEMontenegroHNANAMIBIAFNRNAURUFNPNEPALUANNETHERLANDS ANTILLESLNLNETHERLANDSNNCNEW CALEDONIALNZNEW ZEALANDJNINICARAGUAFNENIGERHNGNIGERIAENUNIUE[APNON-SPEC ASIA PAS LOCATIONONFNORFOLK ISLANDYMPNORTHERN MARIANA ISLANDSGNONORWAYEOMOMANIPKPAKISTANFPWPALAU_PSPALESTINIAN TERRITORY OCCUPIEDGPAPANAMAQPGPAPUA NEW GUINEAIPYPARAGUAYEPEPERULPHPHILIPPINESIPNPITCAIRNGPLPOLANDIPTPORTUGALLPRPUERTO RICOFQAQATARIZZRESERVEDHREREUNIONHROROMANIASRURUSSIAN FEDERATIONGRWRWANDAVKNSAINT KITTS AND NEVISLLCSAINT LUCIAaVCSAINT VINCENT AND THE GRENADINESFWSSAMOAKSMSAN MARINOVSTSAO TOME AND PRINCIPEMSASAUDI ARABIAHSNSENEGALKSCSEYCHELLESMSLSIERRA LEONEJSGSINGAPORE[SKSLOVAKIA (Slovak Republic)ISISLOVENIAPSBSOLOMON ISLANDSHSOSOMALIAMZASOUTH AFRICAmGSSOUTH GEORGIA AND THE SOUTH SANDWICH ISLANDSFESSPAINJLKSRI LANKAKSHST. HELENAXPMST. PIERRE AND MIQUELONFSDSUDANISRSURINAME_SJSVALBARD AND JAN MAYEN ISLANDSJSZSWAZILANDGSESWEDENLCHSWITZERLANDUSYSYRIAN ARAB REPUBLICVCSSerbia and MontenegroVYUSerbia and MontenegroGRSSerbiaGTWTAIWANKTJTAJIKISTAN\TZTANZANIA UNITED REPUBLIC OFITHTHAILANDLTLTIMOR-LESTEETGTOGOHTKTOKELAUFTOTONGATTTTRINIDAD AND TOBAGOHTNTUNISIAGTRTURKEYMTMTURKMENISTANYTCTURKS AND CAICOS ISLANDSGTVTUVALUGUGUGANDAHUAUKRAINEUAEUNITED ARAB EMIRATESOGBUNITED KINGDOMOUKUNITED KINGDOMeUMUNITED STATES MINOR OUTLYING ISLANDSNUSUNITED STATESHUYURUGUAYKUZUZBEKISTANHVUVANUATUJVEVENEZUELAIVNVIET NAMYVGVIRGIN ISLANDS (BRITISH)VVIVIRGIN ISLANDS (U.S.)ZWFWALLIS AND FUTUNA ISLANDSOEHWESTERN SAHARAFYEYEMENGZMZAMBIAIZWZIMBABWENAXALAND ISLANDSMMFSAINT MARTINA
\YwEB
-4=-4=-4=-4=
 2 34 567
com.apple.Safari
com.apple.WebKit2WebProcess
SELECT origin_url, action_url, username_element, username_value, password_element, password_value, signon_realm, date_created from logins
"Account","Login Name","Password","Web Site","Comments"
3.7.5
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
SELECT id, hostname, httpRealm, formSubmitURL, usernameField, passwordField, encryptedUsername, encryptedPassword FROM moz_logins
PK11_GetInternalKeySlot
PK11_CheckUserPassword
unknown operation
foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_source_id
sqlite_rename_parent
%Y-%m-%d %H:%M:%S
%Y-%m-%d
%H:%M:%S
SQLITE_
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
API call with %s database connection pointer
%s-shm
OsError 0x%x (%u)
Recovered %d frames from WAL file %s
foreign key constraint failed
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot %s savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
statement aborts at %d: [%s] %s
oversized integer: %s%s
misuse of aggregate: %s()
%s%.*s"%w"
type='trigger' AND (%s)
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE tbl=%Q
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
invalid name: "%s"
sqlite_autoindex_%s_%d
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
foreign key mismatch
%s.%s may not be NULL
malformed database schema (%s)
%s - %s
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unknown or unsupported join type: %T %T%s%T
%s:%d
no such index: %s
cannot VACUUM - SQL statements in progress
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unknown database: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
sqlite3_open
sqlite3_prepare
sqlite3_step
sqlite3_column_text
sqlite3_column_int
sqlite3_column_int64
sqlite3_finalize
sqlite3_close
sqlite3_exec
c:\projects\vs2005\webbrowserpassview\command-line\WebBrowserPassView.pdb
FindNextUrlCacheEntryW
FindFirstUrlCacheEntryW
FindCloseUrlCache
WININET.dll
GetKeyState
RegEnumKeyExW
5JEw%Xg
t{SSh
v%SSW
Mozilla\Profiles
Software\Mozilla\Mozilla Thunderbird
%s\Main
sqlite3.dll
nss3.dll
%programfiles%\Mozilla Thunderbird
%s %s %s
HTTPMail User Name
SMTP USer Name
HTTPMail Server
SMTP Server
POP3 Password2
IMAP Password2
HTTPMail Password2
SMTP Password2
POP3 Port
IMAP Port
HTTPMail Port
SMTP Port
HTTPMail Secure Connection
SMTP Secure Connection
SMTP Display Name
SMTP Email Address
POP3 Password
IMAP Password
HTTP Password
SMTP Password
HTTP User
SMTP User
HTTP Server URL
HTTP Port
HTTPMail Use SSL
SMTP Use SSL
%s\%s
PopPort
PopPassword
SMTPAccount
SMTPServer
SMTPPort
SMTPLogSecure
SMTPPassword
%s\Accounts
LoginName
SavePasswordText
ESMTPUsername
ESMTPPassword
POP3Password
fb.dat
%s@gmail.com
%s@yahoo.com
Software\Microsoft\Windows Messaging Subsystem\Profiles
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
smtp
*.ini
/skeepass
Failed to load the executable file !
mail.account.account
mail.server
port
mail.identity
signon.signonfilename
mailbox://%s@%s
imap://%s@%s
mailbox://%s
imap://%s
smtp://%s
signons.txt
signons.sqlite
prefs.js
Password.NET Messenger Service
User.NET Messenger Service
Passport.Net\*
ps:password
windowslive:name=
mozsqlite3.dll
pstorec.dll
5e7e8100-9138-11d1-945a-00c04fc308ff
00000000-0000-0000-0000-000000000000
220D5CD0-853A-11D0-84BC-00C04FD43F8F
220D5CD1-853A-11D0-84BC-00C04FD43F8F
220D5CC1-853A-11D0-84BC-00C04FD43F8F
417E2D75-84BD-11D0-84BB-00C04FD43F8F
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Mozilla
mozilla
%s\bin
PathToExe
\sqlite3.dll
\mozsqlite3.dll
\nss3.dll
Software\Microsoft\Windows Mail
Software\Microsoft\Windows Live Mail
SMTP_Server
SMTP_User_Name
POP3_Password2
IMAP_Password2
NNTP_Password2
SMTP_Password2
SMTP_Email_Address
SMTP_Port
NNTP_Port
IMAP_Port
POP3_Port
SMTP_Secure_Connection
*.oeaccount
\Microsoft\Windows Mail
\Microsoft\Windows Live Mail
c:\Projects\VS2005\mailpv\Command-Line\mailpv.pdb
RPCRT4.dll
RegEnumKeyA
Debugger.exe
Microsoft.VisualBasic
System.Windows.Forms
System.Drawing
System.Management
tapi32.dll
rtm.dll
Debugger.Resources.resources
Debugger.Debugger.resources
Debugger.My
WindowsFormsApplicationBase
Microsoft.VisualBasic.ApplicationServices
System.ComponentModel
System.CodeDom.Compiler
Microsoft.VisualBasic.Devices
m_MyWebServicesObjectProvider
.cctor
get_WebServices
HelpKeywordAttribute
System.ComponentModel.Design
WebServices
Microsoft.VisualBasic.CompilerServices
System.Collections
ContainsKey
InvalidOperationException
MyWebServices
Microsoft.Win32
CDkeysteal
encryptedpassstring
encryptedsmtpstring
portstring
fakeMSGholder
encryptedftphost
encryptedftpuser
encryptedftppass
useftp
websitevisitor
websiteblocker
passstring
smtpstring
ftphost
ftpuser
ftppass
WM_KEYUP
WM_KEYDOWN
WM_SYSKEYDOWN
WM_SYSKEYUP
KeyboardHandle
KeyLog
bProdkey
CleanedPasswordsMAIL
CleanedPasswordsWB
CleanedPasswordsProduKey
CleanedPasswordsSkypeViewer
CleanedPasswordsKeyRec
System.IO
get_ExecutablePath
set_WindowState
FormWindowState
UnhookWindowsHookEx
SetWindowsHookEx
SetWindowsHookExA
GetAsyncKeyState
vKey
HookKeyboard
UnhookKeyboard
Operators
get_Keyboard
Keyboard
get_CtrlKeyDown
get_AltKeyDown
KeyboardCallback
System.Threading
Microsoft.VisualBasic.MyServices
ForceSteamLogin
System.Net.NetworkInformation
get_OperationalStatus
OperationalStatus
FakemsgInstall
System.Net.Mail
SmtpClient
System.Globalization
set_Port
System.Net
RegistryKey
OpenSubKey
System.Security.Cryptography
System.Text
set_Key
stealProductKey
stealWebroswers
System.Collections.ObjectModel
SendLogsFTP
FtpWebRequest
WebRequest
UploadFTP
WebClient
secretKey
set_KeySize
get_KeySize
System.Net.Sockets
virtualKey
KeyboardHookDelegate
get_Msg
Debugger.My.Resources
System.Resources
get_CMemoryExecute
get_ProduKey
get_WebBrowserPassView
WebBrowserPassView
System.Configuration
8.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
$b447ccbf-ff01-4ccb-bc8c-d93085077044
_CorExeMain
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
Copy Product &Key
&HTML Report - All Items
HTML R&eport - Selected Items
Extract Windows E&dition
Show &Windows Keys
Show &Office Keys
Show &Internet Explorer Keys
Show &SQL Server Keys
Show &Exchange Server Keys
Load Default Product Key
&Go To ProduKey Web Page
Copy Product Key
HTML Report - All Items
HTML Report - Selected Items
Load the product keys from your local computer
Load the product keys of external Windows installations from all disks currently plugged to your computer
Load the product keys from external Windows directory:
Load the product keys from external Software Registry hive:
Load the product keys from remote computer:
Load the product keys from remote computers specified in the following text file:
Load the product keys from all computers in the specified domain:
Load the product keys from all computers in your local network
Load the product keys from all computers in the specified IP addresses range:
%d item(s)
, %d Selected
Product Key List
Connecting %s...
Enumerating all computers on %s!Select external Windows directory%Select software Registry file to load
Loading... %d
Product key was not found
Product Key
SQL Server
!Select external Windows directory
ProduKey.exe
%%0.ß
main.db
@netmsg.dll
@%s - %s
@shell32.dll
*.db?
main.db-journal
SkypeContactsView.exe
Apple Computer\Preferences\keychain.plist
LoadPasswordsIE
LoadPasswordsFirefox
LoadPasswordsChrome
LoadPasswordsOpera
LoadPasswordsSafari
LoadPasswordsSeaMonkey
UseFirefoxProfileFolder
UseFirefoxInstallFolder
UseChromeProfileFolder
UseOperaPasswordFile
FirefoxProfileFolder
FirefoxInstallFolder
ChromeProfileFolder
OperaPasswordFile
Aadvapi32.dll
crypt32.dll
777705555443332
5555443332
5555443332
wand.dat
@nss3.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe
%programfiles%\Sea Monkey
%programfiles%\Mozilla Firefox
logins
encryptedPassword
passwordField
httpRealm
-signons.txt
signons2.txt
signons3.txt
logins.json
@dllhost.exe
taskhost.exe
taskhostex.exe
Microsoft\Windows\WebCache\WebCacheV01.dat
Microsoft\Windows\WebCache\WebCacheV24.dat
index.dat
hXXps://VVV.google.com/accounts/servicelogin
hXXp://VVV.facebook.com/
hXXps://login.yahoo.com/config/login
hXXp://
hXXps://
PTF://
@history.dat
places.sqlite
Mozilla\Firefox\Profiles
Mozilla\SeaMonkey\Profiles
Mozilla\SeaMonkey
Mozilla\Firefox
profiles.ini
Profile%d
tntdll.dll
sWeb Data
Login Data
Google\Chrome\User Data
Google\Chrome SxS\User Data
Opera\Opera\wand.dat
Opera\Opera7\profile\wand.dat
Opera
Opera Software\Opera Stable\Login Data
A"%s"
Ashell32.dll
.save
vaultcli.dll
abe2869f-9b47-4cd9-a358-c22904dba7f7
Copy &Password
Load Passwords From...
Google Chrome
Mozilla Firefox
SeaMonkey
Firefox Options
Master password:
Firefox Profile:
Firefox Installation:
Chrome Options
Opera Options
Opera Login file:
%d Passwords
Web Browser Passwords%Choose another Firefox profile folder)Choose the installation folder of Firefox,Choose another profile of Chrome Web browser,Choose the password file of Opera (wand.dat)
KeePass csv file
Opera Password File
Firefox 1.x
Firefox 2.x
Firefox 3.0
Firefox 3.5-31
Chrome
Firefox 32 
Web Browser
Password
Password Strength
Password Field
WebBrowserPassView.exe
VVV.google.com/Please log in to your Gmail account
VVV.google.com:443/Please log in to your Gmail account
VVV.google.com/Please log in to your Google Account
VVV.google.com:443/Please log in to your Google Account
VVV.google.com
dWindowsLive:name=*
82BD0E67-9FEA-4748-8672-D5EFE5B779B0
Copy Password
%d items
Select Eudora.ini filename/Select the location of Thunderbird installation
Eudora.ini file
SMTP
Windows Mail
Windows Live Mail
Server Port
SMTP Server Port
Email Password-Recovery
Mail PassView
3;  ; #.)
HKEY_LOCAL_MACHINE\SOFTWARE\Ubisoft\Splinter Cell Pandora Tomorrow
CDKey
HKEY_LOCAL_MACHINE\SOFTWARE\Ubisoft\Splinter Cell Chaos Theory\Keys
DiscKey_SCCT
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty
codkey
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty United Offensive
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty 2
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty 4
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Call of Duty WAW
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Dawn of War
CDKEY
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Dawn of War - Dark Crusade
W40KCDKEY
WXPCDKEY
HKEY_LOCAL_MACHINE\SOFTWARE\SEGA\Medieval II Total War
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Golive\5.0\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\ahead\Installation\BAK\Nero 7\Info
HKEY_LOCAL_MACHINE\SOFTWARE\ACD Systems\PicaView
HKEY_LOCAL_MACHINE\SOFTWARE\Eugen Systems\ActOfWa
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Photoshop\7.0\Registration
Advanced PDF Password Recovery :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced PDF Password Recovery\Registration
Advanced PDF Password Recovery Pro :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced PDF Password Recovery Pro\Registration
Advanced ZIP Password Recovery :
HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced ZIP Password Recovery\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Sunflowers\Anno 1701
HKEY_LOCAL_MACHINE\SOFTWARE\ashampoo\Ashampoo WinOptimizer Platinum 3
HKEY_LOCAL_MACHINE\SOFTWARE\@stake\LC5\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942 Secret Weapons of WWII
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 1942 The Road to Rome
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Battlefield 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Battlefield 2142
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Battlefield Vietnam
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Black and White
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Black and White 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Boulder Dash Rocks
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Burnout Paradise
HKEY_LOCAL_MACHINE\SOFTWARE\TechSmith\Camtasia Studio\4.0
Camtasia Studio 4(Key) :
RegistrationKey
Chrome :
HKEY_LOCAL_MACHINE\SOFTWARE\Techland\Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Codec Tweak Tool
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Generals
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Red Alert 2
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Red Alert
HKEY_LOCAL_MACHINE\SOFTWARE\Westwood\Tiberian Sun
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Command and Conquer 3
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Command and Conquer 3
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Company of Heroes
CoHProductKey
CoHOFProductKey
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Counter-Strike\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Crysis
HKEY_LOCAL_MACHINE\SOFTWARE\Cyberlink\PowerDVD
HKEY_LOCAL_MACHINE\SOFTWARE\Cyberlink\PowerBar
HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerProducer\3.0\UserReg
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Day of Defeat\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\The Battle for Middle-earth II
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 University
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Nightlife
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Open For Business
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Pets
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Seasons
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Glamour Life Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Celebration Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 H M Fashion Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Family Fun Stuff
HKEY_LOCAL_MACHINE\SOFTWARE\DVD Audio Extractor\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Sierra\Empire Earth II
HKEY_LOCAL_MACHINE\SOFTWARE\Sierra\CDKey
HKEY_LOCAL_MACHINE\SOFTWARE\F-Secure\BackWeb\iLauncher
HKEY_LOCAL_MACHINE\SOFTWARE\CRYTEK\FARCRY\UBI.COM
HKEY_LOCAL_MACHINE\SOFTWARE\CRYTEK\FARCRY2\UBI.COM
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 2005
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\FIFA 07
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\FIFA 08
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Distribution\Freedom Force
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Frontlines: Fuel of War Beta
ProductKey
HKEY_LOCAL_MACHINE\SOFTWARE\THQ\Frontlines: Fuel of War
HKEY_LOCAL_MACHINE\SOFTWARE\Headlight\GetRight
Global Operations :
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Global Operations
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Gunman
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Half-Life\Setting
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Hellgate: London
HKEY_LOCAL_MACHINE\SOFTWARE\Illusion Softworks\Hidden & Dangerous 2
HKEY_LOCAL_MACHINE\SOFTWARE\IGI 2 Retail\CDKey
CDkey
HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\InCD
HKEY_LOCAL_MACHINE\SOFTWARE\JoWooD\InstalledGames\IG2
prvkey
HKEY_LOCAL_MACHINE\SOFTWARE\AVConverter\iPod Converter
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\James Bond 007 Nightfire
HKEY_LOCAL_MACHINE\SOFTWARE\3d0\Status Legends of Might and Magic
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Flash\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Fireworks\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Dreamweaver\7\Registration
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Madden NFL 07
HKEY_LOCAL_MACHINE\SOFTWARE\JSG\Matrix Saver V2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Medal of Honor Airborne
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Breakthrough
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Spearhead
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Medal of Honor: Heroes 2
HKEY_LOCAL_MACHINE\SOFTWARE\mIRC
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Nascar Racing 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\Nascar Racing 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2002
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA LIVE 07
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NBA Live 08
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Need for Speed Carbon
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need For Speed Hot Pursuit 2
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need for Speed Most Wanted
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Electronic Arts\Need for Speed ProStreet
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA GAMES\Need For Speed Underground
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Need for Speed Underground 2
HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\Nero - Burning Rom\Info
HKEY_LOCAL_MACHINE\Software\Nero\Installation\Families\Nero 7\Info
HKEY_LOCAL_MACHINE\SOFTWARE\Nero\Installation\Families\Nero 8\Info
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2003
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2004
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Sports\NHL 2005
HKEY_LOCAL_MACHINE\Software\Westwood\Nox
HKEY_LOCAL_MACHINE\Software\NuMega\SmartCheck
HKEY_LOCAL_MACHINE\Software\OnlineTVPlayer\RegInfo
HKEY_LOCAL_MACHINE\Software\O&O\O&O Defrag\8.0\Pro\licenses
HKEY_LOCAL_MACHINE\Software\PowerQuest\PartitionMagic\8.0\UserInfo
Passware Encryption Analyzer (Name) :
HKEY_LOCAL_MACHINE\Software\Passware\Encryption Analyzer\1\Registration,License
Passware Encryption Analyzer (License) :
Passware Encryption Analyzer (Serial) :
Passware Windows Key (License) :
HKEY_LOCAL_MACHINE\Software\Passware\Windows Key\7\Registration
Passware Windows Key (Name) :
Passware Windows Key (Serial) :
HKEY_LOCAL_MACHINE\Software\CyberLink\PowerDVD
HKEY_LOCAL_MACHINE\Software\EnTech\PowerStrip
HKEY_LOCAL_MACHINE\Software\KONAMI\PES2008
HKEY_LOCAL_MACHINE\Software\Red Storm Entertainment\RAVENSHIELD
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA GAMES\Shogun Total War - Warlord Edition
HKEY_LOCAL_MACHINE\Software\Atari\Sid Meier's Pirates!
HKEY_LOCAL_MACHINE\Software\Ubisoft\SILENT HUNTER III\Keys
DiscKey_SH3
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Maxis\ Sim City 4 Deluxe
HKEY_LOCAL_MACHINE\Software\Electronic Arts\Maxis\ Sim City 4
HKEY_LOCAL_MACHINE\Software\Network Associates, Inc.\Sniffer Pro\4.5\USER
HKEY_LOCAL_MACHINE\Software\Silver Style Entertainment\Soldiers Of Anarchy
HKEY_LOCAL_MACHINE\Software\GSC Game World\STALKER-SHOC
InstallCDKEY
HKEY_LOCAL_MACHINE\Software\LucasArts\Star Wars Battlefront II\1.0
CD Key
HKEY_LOCAL_MACHINE\Software\LucasArts\Star Wars Battlefront II\1.1
HKEY_LOCAL_MACHINE\Software\Steganos\SIAVPN
HKEY_LOCAL_MACHINE\Software\THQ\Gas Powered Games\Supreme Commander
HKEY_LOCAL_MACHINE\Software\Sierra\CDKey
HKEY_LOCAL_MACHINE\Software\TechSmith\SnagIt\8
HKEY_LOCAL_MACHINE\Software\TexasCalc\License
Registration Key
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Games\The Battle for Middle-earth
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Games\The Orange Box
HKEY_LOCAL_MACHINE\Software\Pegasys Inc.\TMPGEnc DVD Author\1.0
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\6.0
TuneUp 2007 (Key) :
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\7.0
TuneUp 2008 (Key) :
HKEY_LOCAL_MACHINE\Software\TuneUp\Utilities\8.0
TuneUp 2009 (Key) :
HKEY_LOCAL_MACHINE\Software\Nullsoft\Winamp
regkey
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Sims\The Sims 3\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\Sims\The Sims 2\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Family Fun Stuff\erg
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Glamour Life Stuff\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Nightlife\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 Open For Business\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Sims 2 University\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\SPORE(TM)\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Mirror's Edge\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty2
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty4
HKEY_LOCAL_MACHINE\SOFTWARE\ACTIVISION\Call of Duty WAW
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Half-Life\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Halo
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\CounterStrike\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Rockstar Games\Grand Theft Auto IV
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 09\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\KONAMI\PES2009
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Dead Space\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\Battlefield 2 Special Forces\ergc
HKEY_LOCAL_MACHINE\SOFTWARE\Activision\Transformers2
HKEY_LOCAL_MACHINE\SOFTWARE\Rockstar Games\Bully Scholarship Edition
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\NERO BURNING ROM
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\INSTALLATION\FAMILIES\NERO 7\INFO
HKEY_LOCAL_MACHINE\SOFTWARE\AHEAD\INSTALLATION\FAMILIES\NERO 8\INFO
HKEY_LOCAL_MACHINE\SOFTWARE\NERO\SHARED\FAMILIES\NL9
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 08\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 07\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2005\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2004\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2003\ergc
HKEY_LOCAL_MACHINE\Software\Electronic Arts\EA Sports\FIFA 2002\ergc
HKEY_CURRENT_USER\Software\mIRC\
HKEY_LOCAL_MACHINE\SOFTWARE\Electronic Arts\EA Games\The Orange Box
Password :
GTA IV Serial Key :
MessageBoxIcon.Error
yesftp
filename.exe
hXXp://VVV.example.com/directory/file.exe
Disablecmd
\Windows Update.exe
\WindowsUpdate.exe
SysInfo.txt
\pid.txt
\pidloc.txt
noftp
127.0.0.1
\SteamAppData.vdf
\ClientRegistry.blob
MessageBoxIcon.Exclamation
Keylogger Enabled:
Operating System:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
autorun.inf
open=Sys.exe
Sys.exe
Software\Microsoft\Windows\CurrentVersion\Run
Windows Update
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
Microsoft.NET\Framework\v2.0.50727\vbc.exe
holdermail.txt"
holdermail.txt
holderwb.txt"
holderwb.txt
holderprodkey.txt"
holderprodkey.txt
holderskypeview.txt"
holderskypeview.txt
Operating System Intel Recovery
Operating System Platform:
Operating System Version:
WEB Browser Password Recovery
Mail Messenger Password Recovery
Windows/Microsoft Product Key Recovery
CD Key Recovery (400   Keys)
\.minecraft\lastlogin
There is a file attached to this email containing Minecraft username and password download it then decrypt the login information with my Minecraft Decryptor
Logger - Key Recorder - [
Keylogger Log
.jpeg
Logger_KeyLog_
hXXp://whatismyipaddress.com/
Debugger.Resources
:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

secdrv.exe_2840_rwx_00402000_00007000:

.hP9)h


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    secdrv.exe:2856
    vbc.exe:2220
    vbc.exe:1980

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderprodkey.txt (1334 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\holderwb.txt (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\LookupSvi.exe (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\secdrv.exe (7433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\pid.txt (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\pidloc.txt (39 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Macrovision Security Driver" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\LookupSvi.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
  7. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now