Gen.Variant.Zusy.224839_25f433e9a9
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Zusy.224839 (B) (Emsisoft), Gen:Variant.Zusy.224839 (AdAware), Trojan.Win32.Swrort.3.FD, GenericPhysicalDrive0.YR (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 25f433e9a98748125325fff7f9c02e9b
SHA1: 80f19b6808dff9647c9f077b2c40dc6e009acbaf
SHA256: 7e7efc23f08d4d39c761e3a27a4f9ed2adb0cee32f3892c2a7e25377bf4ac91d
SSDeep: 196608:La18yN6OL86DrHE1GEMDEYqkSyJkARffYO0yPipZh X3u:LO7EG86DmGEeEdyrfJv33
Size: 8389632 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2017-07-29 23:52:38
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
WerFault.exe:4020
WerFault.exe:1728
%original file name%.exe:1992
notepad.exe:2616
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:1992 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\25f433e9a98748125325fff7f9c02e9b.cfg (50 bytes)
Registry activity
The process WerFault.exe:4020 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "63 73 6D E0 09 00 00 00 00 00 00 00 6F D3 4D 75"
[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"
[HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"
The process WerFault.exe:1728 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "74 03 00 C0 01 00 00 00 00 00 00 00 0B 38 20 77"
[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"
[HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"
The process notepad.exe:2616 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASAPI32]
"EnableConsoleTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASAPI32]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASMANCS]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASAPI32]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASMANCS]
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"
"FileTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASAPI32]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\notepad_RASMANCS]
"ConsoleTracingMask" = "4294901760"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 85554 | 86016 | 4.41359 | fd4edb5c5aea944944285eaa2feb0579 |
| .rdata | 90112 | 18046 | 18432 | 3.57766 | 3055a092860ca809fdf1dfcc7ce0e3e6 |
| .data | 110592 | 12736 | 4608 | 1.71786 | 9b2bccca7f715a73460211e4f71afe02 |
| .reloc | 126976 | 3526 | 3584 | 4.52669 | f497d595e12b35fb76c8a08ccff0419c |
| .Fd | 131072 | 8275736 | 8275968 | 5.54507 | 8ea69137410e503dedc84a50d0ba38df |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| cms4.aimjunkies.com | |
| cms10.aimjunkies.com | |
| cms5.aimjunkies.com | |
| cms2.aimjunkies.com | |
| cms3.aimjunkies.com | |
| cms8.aimjunkies.com | |
| cms6.aimjunkies.com | |
| cms9.aimjunkies.com | |
| cms1.aimjunkies.com | |
| cms7.aimjunkies.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.reloc
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
GetProcessWindowStation
operator
#8/)>ƒ
kernel32.dll
ntdll.dll
%s X
C:\mylog.log
KERNEL32.dll
GetProcessHeap
GetCPInfo
InitOnceExecuteOnce
>">.>5>>>
.UPX0
`.UPX1
`.reloc
@.rsrc
f=_
%sTdx
LhXXp://pki-crl.symauth.com/ca_219679623e6b4fa507d638cbeba72ecb/LatestCRL.crl07
hXXp://pki-ocsp.symauth.com0
ehXXp://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.crl0
MFC Loader.exe
c.mZz
yWS2_32.dll
HttpOpenRequestA
URLDownloadToFileA
ZADVAPI32.dll
.CNjx8h
ole32.dll
.ZJuZ
C.lb.K
imagehlp.dll
msi.dll
SbsVQ.Af
WTSAPI32.dll
COMCTL32.dll
urlmon.dll
^Qe×B]
.FM;Rk[O{;.bac
.ZDGnG
sF|
53<.ErI
a[.ulFwN#
jqO.Od(&
h.FO8d
S.jh%
H%f.p
VM`.Tue\.
h.rIQ
%uhNj
%Cl>I
%0ugp(
-%xy5
2".PH
.Gly0
PSAPI.DLL
ShellExecuteExA
comdlg32.dll
@(k%X
EkR.IY
WINMM.dll
USER32.dll
)r,d.Ir
/.Wq_
RegOpenKeyExA
VERSION.dll
SHELL32.dll
WININET.dll
4G4s4
5-53595?5
7$8)8.838
5&7-747}7P8
5 5%5-5[5
9œ9
3$3 30373<3
: :.:<:{:1 1$1(1,1014181<1
; ;$;(;,;0;|;
> >$>(>,>0>4>8>\>`>
; ;$;(;,;0;4;8;<;@;|;
6$6,646<6
829=9`9}9
9 9$9(9,9094989
1.24282<2@2
; ;(;0;8;@;3>
ud%sK:
H~<.IX
.gE]8
l.kVv
>GHv&.IlG
_Sl.NC-
zogExe
sUk.Kk;
g@CN[%sy
WW;.NO
|.wMj
.hCA\R4~Z
4#i%s
D G|.mZ
l.Oc/
5.cs.
U&@.NG(
FJ%x^
*.OGH
.En?P$J
[m.yZ
vM.Jb
w.stR
n1.mG
?.XW/z0
&e%u'>_[
WW%so
<5.Iof
.SL}PT
R.ZV-
&,.Ye0H
@Lh%c
.uT@ZQ
pGV7%S
Bh-i}
.wd,H
;.Lxs#
b{J%SbÚd5!
.QzCG
>.yz;WSC
c1wi%d
.JO|=
.Kfh,g
-m}'3
%CIg@
.sRUY
<xy.dO5
D:\'=ay
.TjhM
{wOa?n%U.DcA{;S.kFy
.ru$PA
q].jJq
<uER%D
U8^%s"wW
.mX.mz,
Z.VZg4
%S&d_
%X&ma
.eW"b
#*.xR33z
1Í-
c.OEa
c.jQvw0bs
:[k.zcva
0}e%dp-
u6.Bys"w
>oy%f
ûFud
X.ylyH:O
'8.sbG
o.bqc
P`p%UW{;.YW~_(
.Xj1`
k.vo5
%dM]N
M%XG"1
E%#fTp$)
#j^M,
oGj*F%u
j!R%syX
.Fcgw
|Q%XB
.oJ&`
[.cb~
;'%u{\ 5%xxuT
ÛVZ
Pa.tB
W:\<8
.isD,
aZ0.mr
8%U; j
}0%X q
?.NBzw
gW.XJ(qGB\
.lV2M
ox.iNK&L
=-h4.cj
.KNPpg
wioI%F
d;.iu
nN_%x(PI&/t
Ls.Sx
%4x]:.
%U%)(
.mE]_E
Ô.v
.lX2I
udP[`
Z9A.DX
Hf.ok
[.ehy
R&.PJOj
-M.xd
D.Qt.
D.jPr{F%UVs
E%XJ>
z.PyZ
oÙx
<<d.MR
:k.Qc
k:-m}
.ZB; >
.%XX g2
.kQsn
.EvUI
5 %S')
(|(.Ng
%I.Cc
.ve@/A\"q
<N^.gI%nmt
.Hoy/[
).Uy.
B|%uIX
O.IF){f.tkMVv
0a%fu
{U.cD;.mfV"V
.BzU3[
X.HfW
t.MrxD
.hm8l
?.KG"
qAHÓ
.Jbr[i
]{e.tQg.KWZ4
!.pjq
ouRL
9YLs%S
3(.AJ
iP.ls
^-1}x
/V.PSW6
.mK_2
w%fgI
%dR,V
o.Idg
I"?gy%X;<
.lV:,
/B.aU>V
wEb?t
TXbS%f";
Lc0z].JU
<E.zG
0Z.bE
S9?70%F
^6.dN9
Qc>.eI
N.nYt
%.EcA&$].
B%dU]e
h.eHw
E8.VR
GcRT
a5.gf
Z.hkN
ow.IzS
3%xWn
xo%f,
gS8.sM
6:.hAa
UrlZ8
z.JTQ
-SxF}
q.cE>
-K.Tqg
%CQOXv
2?%f$
gAe.BR
p].hj
5k_.Dk
@%XK:
S.sa_
x d|.HA
HCr$%C
~rY.qp
[ml
/Ag%c
[Qq.Yi
.CIF83
%fU>J
_a.Lf
h%DQ^
n%S?_
kj2q%X
CC.VU
.nuR;
.Kry*.
%c`*;
=4%sb
)`H%C
U.tkU
e.Vk^
2(.Vx
G.beu9
hc.iEU
R.AOST
Q].UK
Rxj.fR
5'-G}8#
|&%8xTo
"{=%f.Kj\B
@3t.oc
a.Fr!
%U^3&a9
|.Mft
)u.Mi
=%D]zQ
u\
{Pj]%x- .Sq
.Ddfa
#GO%S
kv.nv
}.oG:
:2{%dB.iJA
G.wdZ
L%sRr
%C ew
.rc-,
lP%U@
%uma*
%u})R
O@%srD}
a%D[G
3Ît&
1A.Eu
$.AEVU"
{kf.QOUP.DHR=
.AEAnS6w$
x.vU(
%FnFk
%x!Ye
<%d\N&
%; %x"AMUI.Bs#%ma.ue{i.iBx*~o`weB~.ePCC%cxX#%.f#I.cgwD}B,%f#xÿt->.NzPS.vHj.yk):Aj.hdxD %D]V}.QZ4L)AL1?-F}o.cD)e.CXGWOSqlOaB.GQ%Dq2Odv.EH/FjLc%S'.hZ>X.lHCU%CQ^e*.jQd.Wt6#^\kP.PT?.EV`W.hw$2G#%soA!%.uSx.Du-1,F.sk>.EX@68JPbL_2L-3.fL=^@.PB\C4%dm.ir*(%fMK;Ve<I.ffq)j8%s.nkIl)6.WB!Ò%Yp.AKGx.GDG_ .EK.Rxq|.xE37q.Nd%<6<.Xs}X`.oe$]m.zn('rŸsRa.kf}-FLEvÝ@47.Zv%UZ__.ga l$E}D.FbHX%3x.yLZC)!@s.wk#%zÁ0$.Yp_7*.qa%c?Tco7 9A.st.uX)N.gDJH).AbJ*%CG[R.ZKUdD2DJ.Fv.vrte\.RtnM@`q.jG8J~%fOMkCL.vd{jSOCfr.aj.UT a#r-%s-z.Mx43weBUF-Ê%0xJ/k5(.vG?SxU%dL4>.gd$0o`.qz3 %X|.Cb|5`d'@8x"%s>77B.NH2RDg.ZJn%c\[.Fify6c%U]@Q.Rt07F.pk4s6w.gTY$SOpk[.VB`&%DL>>3úh5.NQ?m.DPkw.Rc\E%5S?nG%u@77NC)uW%DtiW%CVz|'%C,X,#\f%DsB{0u^C.wk#3.ny.Kc=4".OD-!^vc.BX(5-J4}i.Ap`S9%sY-bkL'0z%1S_q#.aN%3xi,Q}.bL2_"dP.XD"f2ó>f%Fg2.prN6.peT0DIBhY.XjX%m1.MQL,.qDva3!=<Yw["%D/.Ry8{J;-?%S(.X|.RVt;O.Rb`;%sP14%UO0:pI.aKe` .JAM.QK'PZ%f>sD.wUu.%x\%d>yk7q"%f%S\G3.mV4!J8%Co~S.mrBURlbO.qhEYZP.Ps'\V.GO3A%x>U?1/%s$-.oRqk~%d?#v*.gIf1QnÝK.nrmp!%C|/MOKa-f}0`.IMOv.Rq1|k|.LAOT.GY`F,-8?I.CVee.zK\.lei.4.qNm-rma.Se$Y%Uxz.By\i#T;x[S.vH!W%s &=BI?9`.qE*-X}Zs YQv.plt9SU.FOx.OT`<ÑBU.Tdga#T-.jlr.cEl$,%Cx52t.Jdp%x,h1%FH_%6Y.MZY$\qA.QO7.gKf,-.cG0z.jBrwkmyf<.JJ~i%&P%S-4}RyH5hy%fjH.dz'K6#..dC%ds>^zj.jmGop'ER .sYk$.CA.UNOc*.fG>k.iv[UQ.WfscN|]j%fQ?|(.wi?R.wsHk%U^y.kDHIËhh4KG%cOB3.Hg:.Hn&^.fa=D,.bQai)rQk.fz.ekge.VMZww'$%s;E_ew(s%U>ZÒ[,2swv.hIxgA%x;:^.Iw;sU%.sB83|.HJ:fJ5E.DcG;.ANk>_`j.Wzz.DXu7i-jw.TCV%Swo.Bp6kI%o"m.KR-O}BI@_x%XAxs\%c]%dw?%p@vhR%SIZ.kn|J6xc%x%S#nu.Jh;>=!?ga[.kWj.hunx?.pKP{&.HM!IC.WWr45.Dc9b[u.LJ41}6RN.bC-eg}`Tw.Xy-d5}Y(%fn/?iU"fX%x[Xj6-Zkz,qus?.uda^]{w.Jnbps%FW.uRzNb;.Ky()-9M}Cs-MfD}E\-e}$C%sGBf%C {O{.GN;lu@ %U,v%fr~.nw>enp&ÙP/HD`2!~%C%f (xas.Ho6gGÄT?-n}\%U(|Fc.cF&`/.nE4V<8KA.Qo.iY.Wp2w{.Iw77).ofUZ]7NTurl`$%uuB.zP`^n}%DpqqfŸn/?%d'.guElf$.dx},-Mpd}7:KP%f97.kH(vj%D"7swP.rMF%Sf]xL_%C=3v<T=?v.pcNs.nH6GtT.ED1qvOH$" %s[5.KRZZk.Dl]w%uEd.lTb.vvMQ.Ri(7;|.hy'JI.SMQN^y.Vet|h.aW.NS*;zcCg.BH{>!}1! \L0@IbdP%4xib%Sy5_-H}>'M.Eg.(7.Mr*xC\>.FoT?J`.EX.YCG}kEyl\X?\v.YC;SSHLWAPI.dllOLEACC.dll.eTmYR8P>0%CX.)uRN%u"t.yxHv.Tp.aO-p%x[$.Dv&P.jTst.NmK`K.xGs&Wt.Rx(X.vIZ%_^.hJ57D%CZM%Xt|].s%u[%~.IXtX%C[|U[%D0c%x^9B.bh H:!.ELV%xIFf%xU13%CViDu9I;yVl%DY@0d9sSh!`r*D%uWINSPOOL.DRVGDI32.dllOLEAUT32.dllRPCRT4.dllt.Gey#,8.Piimscoree.dll- floating point support not loaded- CRT not initialized- Attempt to initialize the CRT more than once.dkernel32.dllUSER32.DLLc:\%original file name%.exe0, 0, 0, 0%original file name%.exe_1992_rwx_00420000_007E5000:
.text`.rdata@.data.UPX0`.UPX1`.reloc@.rsrcf=_%sTdxLhXXp://pki-crl.symauth.com/ca_219679623e6b4fa507d638cbeba72ecb/LatestCRL.crl07hXXp://pki-ocsp.symauth.com0ehXXp://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.crl0MFC Loader.exec.mZzyWS2_32.dllHttpOpenRequestAURLDownloadToFileAZADVAPI32.dll.CNjx8hole32.dll.ZJuZC.lb.Kimagehlp.dllmsi.dllSbsVQ.AfWTSAPI32.dllCOMCTL32.dllurlmon.dll^Qe×B].FM;Rk[O{;.bac.ZDGnGsF|53<.ErIa[.ulFwN#jqO.Od(&h.FO8dS.jh%H%f.pVM`.Tue\.h.rIQ%uhNj%Cl>I%0ugp(-%xy52".PH.Gly0PSAPI.DLLShellExecuteExAcomdlg32.dll@(k%XEkR.IYWINMM.dllUSER32.dll)r,d.Ir/.Wq_RegOpenKeyExAVERSION.dllSHELL32.dllWININET.dll4G4s45-53595?57$8)8.8385&7-747}7P85 5%5-5[59œ93$3 30373<3: :.:<:{:1 1$1(1,1014181<1; ;$;(;,;0;|;> >$>(>,>0>4>8>\>`>; ;$;(;,;0;4;8;<;@;|;6$6,646<6829=9`9}99 9$9(9,90949891.24282<2@2; ;(;0;8;@;3>ud%sK:H~<.IX.gE]8l.kVv>GHv&.IlG_Sl.NC-zogExesUk.Kk;g@CN[%syWW;.NO|.wMj.hCA\R4~Z4#i%sD G|.mZl.Oc/5.cs.U&@.NG(FJ%x^*.OGH.En?P$J[m.yZvM.Jbw.stRn1.mG?.XW/z0&e%u'>_[WW%so<5.Iof.SL}PTR.ZV-&,.Ye0H@Lh%c.uT@ZQpGV7%SBh-i}.wd,H;.Lxs#b{J%SbÚd5!.QzCG>.yz;WSCc1wi%d.JO|=.Kfh,g-m}'3%CIg@.sRUY<xy.dO5D:\'=ay.TjhM{wOa?n%U.DcA{;S.kFy.ru$PAq].jJq<uER%DU8^%s"wW.mX.mz,Z.VZg4%S&d_%X&ma.eW"b#*.xR33z1Í-c.OEac.jQvw0bs:[k.zcva0}e%dp-u6.Bys"w>oy%fûFudX.ylyH:O'8.sbGo.bqcP`p%UW{;.YW~_(.Xj1`k.vo5%dM]NM%XG"1E%#fTp$)#j^M,oGj*F%uj!R%syX.Fcgw|Q%XB.oJ&`[.cb~;'%u{\ 5%xxuTÛVZPa.tBW:\<8.isD,aZ0.mr8%U; j}0%X q?.NBzwgW.XJ(qGB\.lV2Mox.iNK&L=-h4.cj.KNPpgwioI%Fd;.iunN_%x(PI&/tLs.Sx%4x]:.%U%)(.mE]_EÔ.v.lX2IudP[`Z9A.DXHf.ok[.ehyR&.PJOj-M.xdD.Qt.D.jPr{F%UVsE%XJ>z.PyZoÙx<<d.MR:k.Qck:-m}.ZB; >.%XX g2.kQsn.EvUI5 %S')(|(.Ng%I.Cc.ve@/A\"q<N^.gI%nmt.Hoy/[).Uy.B|%uIXO.IF){f.tkMVv0a%fu{U.cD;.mfV"V.BzU3[X.HfWt.MrxD.hm8l?.KG"qAHÓ.Jbr[i]{e.tQg.KWZ4!.pjqouRL9YLs%S3(.AJiP.ls^-1}x/V.PSW6.mK_2w%fgI%dR,Vo.IdgI"?gy%X;<.lV:,/B.aU>VwEb?tTXbS%f";Lc0z].JU<E.zG0Z.bES9?70%F^6.dN9Qc>.eIN.nYt%.EcA&$].B%dU]eh.eHwE8.VRGcRTa5.gfZ.hkNow.IzS3%xWnxo%f,gS8.sM6:.hAaUrlZ8z.JTQ-SxF}q.cE>-K.Tqg%CQOXv2?%f$gAe.BRp].hj5k_.Dk@%XK:S.sa_x d|.HAHCr$%C~rY.qp[ml/Ag%c[Qq.Yi.CIF83%fU>J_a.Lfh%DQ^n%S?_kj2q%XCC.VU.nuR;.Kry*.%c`*;=4%sb)`H%CU.tkUe.Vk^2(.VxG.beu9hc.iEUR.AOSTQ].UKRxj.fR5'-G}8#|&%8xTo"{=%f.Kj\B@3t.oca.Fr!%U^3&a9|.Mft)u.Mi=%D]zQu\{Pj]%x- .Sq.Ddfa#GO%Skv.nv}.oG::2{%dB.iJAG.wdZL%sRr%C ew.rc-,lP%U@%uma*%u})RO@%srD}a%D[G3Ît&1A.Eu$.AEVU"{kf.QOUP.DHR=.AEAnS6w$x.vU(%FnFk%x!Ye<%d\N&%; %x"AMUI.Bs#%ma.ue{i.iBx*~o`weB~.ePCC%cxX#%.f#I.cgwD}B,%f#xÿt->.NzPS.vHj.yk):Aj.hdxD %D]V}.QZ4L)AL1?-F}o.cD)e.CXGWOSqlOaB.GQ%Dq2Odv.EH/FjLc%S'.hZ>X.lHCU%CQ^e*.jQd.Wt6#^\kP.PT?.EV`W.hw$2G#%soA!%.uSx.Du-1,F.sk>.EX@68JPbL_2L-3.fL=^@.PB\C4%dm.ir*(%fMK;Ve<I.ffq)j8%s.nkIl)6.WB!Ò%Yp.AKGx.GDG_ .EK.Rxq|.xE37q.Nd%<6<.Xs}X`.oe$]m.zn('rŸsRa.kf}-FLEvÝ@47.Zv%UZ__.ga l$E}D.FbHX%3x.yLZC)!@s.wk#%zÁ0$.Yp_7*.qa%c?Tco7 9A.st.uX)N.gDJH).AbJ*%CG[R.ZKUdD2DJ.Fv.vrte\.RtnM@`q.jG8J~%fOMkCL.vd{jSOCfr.aj.UT a#r-%s-z.Mx43weBUF-Ê%0xJ/k5(.vG?SxU%dL4>.gd$0o`.qz3 %X|.Cb|5`d'@8x"%s>77B.NH2RDg.ZJn%c\[.Fify6c%U]@Q.Rt07F.pk4s6w.gTY$SOpk[.VB`&%DL>>3úh5.NQ?m.DPkw.Rc\E%5S?nG%u@77NC)uW%DtiW%CVz|'%C,X,#\f%DsB{0u^C.wk#3.ny.Kc=4".OD-!^vc.BX(5-J4}i.Ap`S9%sY-bkL'0z%1S_q#.aN%3xi,Q}.bL2_"dP.XD"f2ó>f%Fg2.prN6.peT0DIBhY.XjX%m1.MQL,.qDva3!=<Yw["%D/.Ry8{J;-?%S(.X|.RVt;O.Rb`;%sP14%UO0:pI.aKe` .JAM.QK'PZ%f>sD.wUu.%x\%d>yk7q"%f%S\G3.mV4!J8%Co~S.mrBURlbO.qhEYZP.Ps'\V.GO3A%x>U?1/%s$-.oRqk~%d?#v*.gIf1QnÝK.nrmp!%C|/MOKa-f}0`.IMOv.Rq1|k|.LAOT.GY`F,-8?I.CVee.zK\.lei.4.qNm-rma.Se$Y%Uxz.By\i#T;x[S.vH!W%s &=BI?9`.qE*-X}Zs YQv.plt9SU.FOx.OT`<ÑBU.Tdga#T-.jlr.cEl$,%Cx52t.Jdp%x,h1%FH_%6Y.MZY$\qA.QO7.gKf,-.cG0z.jBrwkmyf<.JJ~i%&P%S-4}RyH5hy%fjH.dz'K6#..dC%ds>^zj.jmGop'ER .sYk$.CA.UNOc*.fG>k.iv[UQ.WfscN|]j%fQ?|(.wi?R.wsHk%U^y.kDHIËhh4KG%cOB3.Hg:.Hn&^.fa=D,.bQai)rQk.fz.ekge.VMZww'$%s;E_ew(s%U>ZÒ[,2swv.hIxgA%x;:^.Iw;sU%.sB83|.HJ:fJ5E.DcG;.ANk>_`j.Wzz.DXu7i-jw.TCV%Swo.Bp6kI%o"m.KR-O}BI@_x%XAxs\%c]%dw?%p@vhR%SIZ.kn|J6xc%x%S#nu.Jh;>=!?ga[.kWj.hunx?.pKP{&.HM!IC.WWr45.Dc9b[u.LJ41}6RN.bC-eg}`Tw.Xy-d5}Y(%fn/?iU"fX%x[Xj6-Zkz,qus?.uda^]{w.Jnbps%FW.uRzNb;.Ky()-9M}Cs-MfD}E\-e}$C%sGBf%C {O{.GN;lu@ %U,v%fr~.nw>enp&ÙP/HD`2!~%C%f (xas.Ho6gGÄT?-n}\%U(|Fc.cF&`/.nE4V<8KA.Qo.iY.Wp2w{.Iw77).ofUZ]7NTurl`$%uuB.zP`^n}%DpqqfŸn/?%d'.guElf$.dx},-Mpd}7:KP%f97.kH(vj%D"7swP.rMF%Sf]xL_%C=3v<T=?v.pcNs.nH6GtT.ED1qvOH$" %s[5.KRZZk.Dl]w%uEd.lTb.vvMQ.Ri(7;|.hy'JI.SMQN^y.Vet|h.aW.NS*;zcCg.BH{>!}1! \L0@IbdP%4xib%Sy5_-H}>'M.Eg.(7.Mr*xC\>.FoT?J`.EX.YCG}kEyl\X?\v.YC;SSHLWAPI.dllOLEACC.dll.eTmYR8P>0%CX.)uRN%u"t.yxHv.Tp.aO-p%x[$.Dv&P.jTst.NmK`K.xGs&Wt.Rx(X.vIZ%_^.hJ57D%CZM%Xt|].s%u[%~.IXtX%C[|U[%D0c%x^9B.bh H:!.ELV%xIFf%xU13%CViDu9I;yVl%DY@0d9sSh!`r*D%uWINSPOOL.DRVGDI32.dllOLEAUT32.dllKERNEL32.dllRPCRT4.dllt.Gey#,8.Pii0, 0, 0, 0notepad.exe_2616:
.text`.rdata@.data.UPX0`.UPX1`.reloc@.rsrc~b%f;%F#owy.dfZD%u;n3WdJ'.rlo%Uwa&irm.kWT$XRSSh(r.fTm%F!5Zb3AYJGb~ÄgYFtPhaSSSh.VVVVVSRSSjtGHt.Ht&FTPjKFtPj;C.PjRVntdll.dll.localPOST /scans.php HTTP/1.1Host: 54.247.116.67User-Agent: Mozilla/4.0Content-Type: application/x-www-form-urlencodedContent-Length: %d54.247.116.67HTTP/1.0 200HTTP/1.1 200%s %i#8/)>ƒkernel32.dll%s X0x%X failed with 0x%X%s|%s|%stest.dlldec.dllYour operating system is currently not supported by the protection system. Support for your operating system is planned for future release. Please contact technical support./c "DEL /F /S /Q /A %WINDIR%\prefetch\*.pf & DEL /F /S /Q /A %WINDIR%\prefetch\*.db & DEL /F /S /Q /A %WINDIR%\prefetch\*.trx"cmd.exeFailed to disable superfetch. Report this error to tech support. 1Failed to disable superfetch. Report this error to tech support. 2Failed to disable superfetch. Report this error to tech support. 3Failed to disable superfetch. Report this error to tech support. 4Failed to disable prefetch. Report this error to tech support. 1Failed to disable prefetch. Report this error to tech support. 2Failed to disable prefetch. Report this error to tech support. 3\Microsoft\Windows\Recent\*.*/c "DEL /F /S /Q /A %s"The drive the loader is stored on has USN journaling enabled. The loader must be located on a drive that does not support USN journaling. The following drives *MAY* be suitable. Please see the %s forum section for complete instructions. Failure to do so will result in degraded security.%s:\loader\Windows 8 is not supported, please upgrade to Windows 8.1 and install all available updates.You must select the patched boot when your computer starts. Please restart your computer and select "%s" when prompted.steam.exeInjection failed with error code: 0x%X\\.\PhysicalDrive0v3.4.8rc2Kernel32.dllhXXp://s3.amazonaws.com/ajcdn/loader_packages/Installing %s.GMFNA failed %dFailed to open loader %dFailed to read loader %dFailed to create target %dError code: %d%d Write failed with %dFailed to set context %dFailed to resume %d%s %s\\.\PhysicalDrivedeviceio failed 0x%X%s (%s:%d)%Program Files% (x86)\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin1.inlXTPReport_CF_Recordsaimjunkies.com0x%X,Unable to contact loader servers. Please report this error to the technical support team.SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersC:\Windows\System32\notepad.exe1.exe1.iniH1Z1.exeH1Z1_BE.exeLaunchPad.exeDeadByDaylight-Win64-Shipping.exeSquad.exeVictory.exe\Brick.msstylesldr.cnf/c fsutil usn deletejournal /d %sWS2_32.dllUSERENV.dllReportEventAADVAPI32.dllKERNELBASE.dllSbieDll.dllsite.keyCannot delete the active boot configuration. Please reboot and select your original Windows boot configuration.Error removing boot 0x%XCurrent System DEP Policy: %sSuccessfully installed new boot configuration! You must restart your computer and select the new boot configuration named "%s" for these changes to take effect.Please install all available Windows updates and try again.Error installing boot 0x%X/delete %s\ntoskrnl.exe\winload.exePatched ntoskrnl: %sPatched winload: %s/copy {current} /d "%s"Patched GUID: %s/set %s path %s/set %s kernel %s/set %s nointegritychecks 1KERNEL32.dllWindows Boot Loaderntoskrnl.exe%s\Elements\X%s\%sBCDd\Objects\\.\SpectreCNotSupportedExceptionhhctrl.ocxf:\sp\vctools\vc7libs\ship\atlmfc\include\afxwin2.inlcommctrl_DragListMsgf:\sp\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cppCCmdTargetSoftware\Microsoft\Windows\CurrentVersion\Policies\ExplorerSoftware\Microsoft\Windows\CurrentVersion\Policies\NetworkSoftware\Microsoft\Windows\CurrentVersion\Policies\Comdlg32%s%s.dllf:\sp\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cppCHttpConnectionCHttpFilehXXp://WININET.DLLHTTP/1.0comctl32.dllcomdlg32.dllf:\sp\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cppf:\sp\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cppf:\sp\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cppuser32.dllMSWHEEL_ROLLMSGcommand.commscoree.dllPlease contact the application's support team for more information.- Attempt to initialize the CRT more than once.- CRT not initialized- floating point support not loaded.mixcrtKERNEL32.DLLGetProcessWindowStationUSER32.DLLoperatorportuguese-brazilianOLEACC.dllD$,.dllp.dll}.HcD$.pdataD:\Users\Jordan\Documents\Visual Studio 2010\Projects\Command Executor\x64\Release\Command Executor.pdbMSVCR100.dll_amsg_exit<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>;.WQMCs.CB..SAgQRWeY.hdk.ZuBy9g:\82d%d,cnn9w.GOs@.Me6='D.voT%f>{>T%d%o#.xX(g.EU4.tVPFfO%F-nJ}[GYG.Ct:.Dt0Z.bt\E06%0X_U'uT.KmX4.KO4}*>!%x=3n'a.CHhXXp://VVV.usertrust.com11hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl05hXXp://ocsp.usertrust.com0hXXps://secure.comodo.net/CPS0C2hXXp://crl.comodoca.com/COMODORSACodeSigningCA.crl0t2hXXp://crt.comodoca.com/COMODORSACodeSigningCA.crt0$hXXp://ocsp.comodoca.com0admin@aimjunkies.com0"COMODO RSA Certification Authority0;hXXp://crl.comodoca.com/COMODORSACertificationAuthority.crl0q/hXXp://crt.comodoca.com/COMODORSAAddTrustCA.crt0$hXXps://forum.aimjunkies.com0.rsrc@.reloc_crt_debugger_hook__crt_debugger_hookfunction not supportedoperation canceledaddress_family_not_supportedoperation_in_progressoperation_not_supportedprotocol_not_supportedoperation_would_blockaddress family not supportedbroken pipeinappropriate io control operationnot supportedoperation in progressoperation not permittedoperation not supportedoperation would blockprotocol not supportedFailed to find ntoskrnl.%sFound ntoskrnl.%sFailed to find winload.%sFound winload.%swinload.exeD:\Condensed Backup\Source Code\AJ Source\trunk\Patchguard-master\Release\PGBootManager.pdbole32.dllimagehlp.dllVERSION.dllSHLWAPI.dllRPCRT4.dllGetCPInfoCreatePipeGetProcessHeap<requestedExecutionLevel level='asInvoker' uiAccess='false' />0 0$0(0,0004080\0`0> >$>(>,>0>4>4$40484|4.PAVCException@@.PAVCInternetException@@.PAVCMemoryException@@.PAVCSimpleException@@.PAVCObject@@.PAVCNotSupportedException@@.PAVCInvalidArgException@@.?AVCNotSupportedException@@.PAVCOleException@@.?AVCCmdTarget@@.?AVCTestCmdUI@@.?AVCCmdUI@@.PAVCUserException@@.PAVCResourceException@@.?AVCHttpConnection@@.?AVCHttpFile@@.PAVCArchiveException@@.PAVCFileException@@Assertion failed: %s, file %s, line %dzcÁsice.syssiwvid.sysntice.sysiceext.syssyser.syssbiedll.dll%d-%d-%dwinhttp.dllactivation.php?code=deactivation.php?hash=U.pvtZxxQf%cn-K1}Wl%f%Fgr*2G.yH}Y%s|`ØqH~b%f=z> .lCC2m&%F^ZD.JHqP%%.ds".eGf;F/%sgE>.byZuu}i%F!WQý||7$@.iq%Co*&?.ag"&Z.oP=Pn.yHRa.VK.tW ?o.cQlc1?7.Go:.po|gB%C=1}O.OgAl[-47sy02Jp$%D|IZCf.NZ$%XN4j.Ms|S%snzZw.cZG9-r.uAj7.vmy.tRWD~.KA%C$99%S:iw3!1.Er ;.grr(.pLC/[M%C$W.rf5e~%f>$yAK.Brt[T(%f;FJ.oGzi[)R4p%chr%UsCr%f,?aZ__He%x0%D@0c7%uy;zp%4uhZ.xrlw$}V,%u.IlhYY=E.YX%W%s%$.rn/pw.LT!T[![w.WkgT[\^[%u~q%C"yYKbL%XfMl%UjB.rEQ%uj<CMG r}.upR.jcF%xrr`%SZUD_Z|Nr.mNz.IO^%U'p&&-%uZ%u/RCZX.rNr.bHIl0;15%N[.ZX%DhjrL.{fZ=;m%sC3t%Sq.tv8wyt5.vkt$sw%Ct.Eb8r%F`8.cx#!!.irjikE.hLqWB.qiB![LsP.rrM-Z|%c!B.ct=$`M.Zb["yR.SDl/.tCTZZUp.xZ.mrfhb@ØSu.IW@J.Ar.rra 3E%usK&9WW9X%XM}%CUzVt.ZFbL.fZ;%[GV.zo.hpe/ik?QH.Kor&[}Z%UK},D.jN#vU%u%see=jr<*%'.Lh8=4=g.pT5D[./012221-$%CiTK7Z$r.ZWjA<NÜ<N.cwGvH:\ \e">Y%c|5'<5%fCrtD9#<.ElAZ.nc,Û[r.vYY%6u>&H%uS-JOe%cRgBŒL.wV4Uw.W.tUssNC!r7.Nkrsi%cn%Sx2&N..dcl9,1%xk&~1x=.Bv:=<%FNh<f=_(.Ao~9V%uP>Zn%U?5M%Xk=%DYPx}.MM0WQn0.Jl[%dWXJ-N9Ã%CYxZ0]%C> |]<95>=5(*%sJW.Vlr/P~%UIja<.ps&.Etr';={{fTPyr,2N.rwr9a>.rhT%I.RdO%&0.wZ.BPcp%X}<@.XVr)F.AL'p)%fZaD=G%D#8F)$=.Znf=?lq=.Vnl"<%SO;r%%c%U2/wÖ<;b.cc5Xr%F&>Ö'x~}.szx&%Uu`y%s97-5k}3Ul5q%S!UtH%c.k"%XF^H%XX-FJ[%X!-.lr=%DIkÒ,r.6%CN[.CAWSÔa/.{.ovrÃGs%,^.rh!*-p}ZD3.sY(jIp%X8M%dxw%i*.thPI.Gt>-I}_la%uvu%)YTt%f&YN2wb%Cxz.YPf%S8[y%6TW%U%%xzh&boXm%cyt -%x>UWu%Ct.JzbNClm%S.uro?%1wÃ%2U=3E Q%c>l)%ctJVÔMW%?M%.yr^BcrtnTs%XcdH%uYBY%f.Fm?nC: .wt6]>K%s?rL.Fe>-?%U"cÌ$m%LH.rN(J{%<Loz%cxr.YHt.VTZt}/H.CIM1R*.IA5R4]M`J%c^\.Jf&t%p%u\S.BDm3Y^R.4%'(?%""Y_.xY2{%gdig%C:%Xr&%%X*ZJd.Yk@8=%C-bR~%x?>p%dM.GH]7y`ÿ$%DVJV<Z%U}rj$.xr-e78%SN".lsJyH5 `Eq<%U9?#.nX'V.rH6"V,7.bX%Crh(jeXE%.dh~7-%c%.iTM<%Si=H|*%U%.etU:™DZAk=^.ZD/jrU[]=r.Mr,<sYo9IX%FLh%ux|rB%c7%FTS')(DWEb75J%c"'..Ks.PZHH~#%cY%%d%C<:B%to%B%d>V&%s%sHE<(.qUTVK%foG%Äx%mZm|#9*.Hzx.Hlr9.NWt.bZ=5Doi6Öj26.Wn." %Fp%ClV.Z8Y.dBXA(%s[uxhv%dm|T%.bO{\ß{E\6B%5xFn.txA%dtH%X?]CyhG%c%CRJ={|Hu%S%[%..ZsV|)Z.ZG\9%c)b}$%X*w.ZAPt*<.IL%<r%S,rn.Kwj.ysrc4Vb@.NBcn.BqBY8SE[%ufÝ'`eCjô%uU}w.LLHrV%C]FB .fV.cSV,.wX5rPl`mÝm<i%sv%4S*BF..rK87\?]%F7s.HmIXr.ba_%SVHY9DH%&.K,%U'cQ.JGV5g.si3pcf%2x4.bUNKm%%Ubl%rb{6.gfgL".ZL}S%DvMZQQcn%FpN8.bvf10/.---.2;^}%Svu._V~%sdGED%czHr%cQ%X*X$P%fwZww4x%d("-z}jO%c)G.sA%s>.jCLs,%d`K.YZuuj>1%x7-8}$H"c.BJC"si~`g%X=Y%sT^OY.EPb%ci[ýb.cy2V#n/%ub*?`t.vmEtL".xCeo3.rv|j^%9s=uY%s%9_.mtV.SZ'tvlc9.Dc>^yr);Z.rV9u?{F[:<.HJF%FxGG5_<(<f5%s<F.ws9r.MG7V!%c>@B.Hq4>r]=M{%cs:]6.Tm.Hc<aa\Ò~.FjRAL5=%dZvviM%U2C\.WoY/M.kQr)%>UW2%sr!U.arsC.jcjxÔ1#9%xÄ88mc^).bZT%2S<3.Fm&(0E'_.vBu3.kmQZtG~%f$%F .%.Uq%~90Pp%x"..Zy&/j;_%C=Z}%D `L Û$%MP%%UCQ%~vqJ%f"d6H.ru.NetHAV%u?%qx%fHW]%X(1.uY<_q2fU"I.Ic*.kTJ%ayk.Me$I?u.hH.kNhoay.k\t%fptg.cn<H=.iE7.bM_l*3V%f,d.ctksV.MX08f%cr\U# OÏZzzD{%u=.YT^=klb};K%c)l@.w%F&Y.NbKb,n.Dt8g@%xw.xaHKt@.Rtqc!=k.HZRDQb.%Uj?Y7*D!.%x7O@%X_n1psz EMv=t\%DzüBZ%s&E*%CHVzV7t%S$#?%dzG3G%%U'.Qct.ctKz-an}k~a|%d.hsB,ca6-Tg}3.rN!gJK%UzH]Úa.FwXu<ÁI<3,^.lZ,.mrj7;[.sGg.G#%0X&4%zI.dTH#qHH%X19".UrMZl.rvHJalz\%D<%szrX|6.UYr%s8?bo--%sL%X(MM%;Ic.FfwG'b%FP=;GS!%.rX-LMÃ_fZ i.AZecm%cGH"c%F/QKj&%FL-%%Cy=[b%UkSw$.br%FqX\S'<|.gl%4S-^2k%c}}y9.dZHhri.dr%%s&T'h%CM}E%sTdx[4%UDp.YQgsJ%%".obI7%WW& %x},.%7s!';.ZHlW;I%xY^.RF3tT m%USoOTjÝC%r Ea.rl5%cL9%sHb&>T%d_|LhXXp://pki-crl.symauth.com/ca_219679623e6b4fa507d638cbeba72ecb/LatestCRL.crl07hXXp://pki-ocsp.symauth.com0ehXXp://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.crl0MFC Loader.exec.mZzyWS2_32.dllHttpOpenRequestAURLDownloadToFileAZADVAPI32.dll.CNjx8h.ZJuZC.lb.Kmsi.dllSbsVQ.AfWTSAPI32.dllCOMCTL32.dllurlmon.dll^Qe×B].FM;Rk[O{;.bac.ZDGnGsF|53<.ErIa[.ulFwN#jqO.Od(&h.FO8dS.jh%H%f.pVM`.Tue\.h.rIQ%uhNj%Cl>I%0ugp(-%xy52".PH.Gly0PSAPI.DLLShellExecuteExA@(k%XEkR.IYWINMM.dllUSER32.dll)r,d.Ir/.Wq_RegOpenKeyExASHELL32.dllWININET.dll4G4s45-53595?57$8)8.8385&7-747}7P85 5%5-5[59œ93$3 30373<3: :.:<:{:1 1$1(1,1014181<1; ;$;(;,;0;|;> >$>(>,>0>4>8>\>`>; ;$;(;,;0;4;8;<;@;|;6$6,646<6829=9`9}99 9$9(9,90949891.24282<2@2; ;(;0;8;@;3>ud%sK:H~<.IX.gE]8l.kVv>GHv&.IlG_Sl.NC-zogExesUk.Kk;g@CN[%syWW;.NO|.wMj.hCA\R4~Z4#i%sD G|.mZl.Oc/5.cs.U&@.NG(FJ%x^*.OGH.En?P$J[m.yZvM.Jbw.stRn1.mG?.XW/z0&e%u'>_[WW%so<5.Iof.SL}PTR.ZV-&,.Ye0H@Lh%c.uT@ZQpGV7%SBh-i}.wd,H;.Lxs#b{J%SbÚd5!.QzCG>.yz;WSCc1wi%d.JO|=.Kfh,g-m}'3%CIg@.sRUY<xy.dO5D:\'=ay.TjhM{wOa?n%U.DcA{;S.kFy.ru$PAq].jJq<uER%DU8^%s"wW.mX.mz,Z.VZg4%S&d_%X&ma.eW"b#*.xR33z1Í-c.OEac.jQvw0bs:[k.zcva0}e%dp-u6.Bys"w>oy%fûFudX.ylyH:O'8.sbGo.bqcP`p%UW{;.YW~_(.Xj1`k.vo5%dM]NM%XG"1E%#fTp$)#j^M,oGj*F%uj!R%syX.Fcgw|Q%XB.oJ&`[.cb~;'%u{\ 5%xxuTÛVZPa.tBW:\<8.isD,aZ0.mr8%U; j}0%X q?.NBzwgW.XJ(qGB\.lV2Mox.iNK&L=-h4.cj.KNPpgwioI%Fd;.iunN_%x(PI&/tLs.Sx%4x]:.%U%)(.mE]_EÔ.v.lX2IudP[`Z9A.DXHf.ok[.ehyR&.PJOj-M.xdD.Qt.D.jPr{F%UVsE%XJ>z.PyZoÙx<<d.MR:k.Qck:-m}.ZB; >.%XX g2.kQsn.EvUI5 %S')(|(.Ng%I.Cc.ve@/A\"q<N^.gI%nmt.Hoy/[).Uy.B|%uIXO.IF){f.tkMVv0a%fu{U.cD;.mfV"V.BzU3[X.HfWt.MrxD.hm8l?.KG"qAHÓ.Jbr[i]{e.tQg.KWZ4!.pjqouRL9YLs%S3(.AJiP.ls^-1}x/V.PSW6.mK_2w%fgI%dR,Vo.IdgI"?gy%X;<.lV:,/B.aU>VwEb?tTXbS%f";Lc0z].JU<E.zG0Z.bES9?70%F^6.dN9Qc>.eIN.nYt%.EcA&$].B%dU]eh.eHwE8.VRGcRTa5.gfZ.hkNow.IzS3%xWnxo%f,gS8.sM6:.hAaUrlZ8z.JTQ-SxF}q.cE>-K.Tqg%CQOXv2?%f$gAe.BRp].hj5k_.Dk@%XK:S.sa_x d|.HAHCr$%C~rY.qp[ml/Ag%c[Qq.Yi.CIF83%fU>J_a.Lfh%DQ^n%S?_kj2q%XCC.VU.nuR;.Kry*.%c`*;=4%sb)`H%CU.tkUe.Vk^2(.VxG.beu9hc.iEUR.AOSTQ].UKRxj.fR5'-G}8#|&%8xTo"{=%f.Kj\B@3t.oca.Fr!%U^3&a9|.Mft)u.Mi=%D]zQu\{Pj]%x- .Sq.Ddfa#GO%Skv.nv}.oG::2{%dB.iJAG.wdZL%sRr%C ew.rc-,lP%U@%uma*%u})RO@%srD}a%D[G3Ît&1A.Eu$.AEVU"{kf.QOUP.DHR=.AEAnS6w$x.vU(%FnFk%x!Ye<%d\N&%; %x"AMUI.Bs#%ma.ue{i.iBx*~o`weB~.ePCC%cxX#%.f#I.cgwD}B,%f#xÿt->.NzPS.vHj.yk):Aj.hdxD %D]V}.QZ4L)AL1?-F}o.cD)e.CXGWOSqlOaB.GQ%Dq2Odv.EH/FjLc%S'.hZ>X.lHCU%CQ^e*.jQd.Wt6#^\kP.PT?.EV`W.hw$2G#%soA!%.uSx.Du-1,F.sk>.EX@68JPbL_2L-3.fL=^@.PB\C4%dm.ir*(%fMK;Ve<I.ffq)j8%s.nkIl)6.WB!Ò%Yp.AKGx.GDG_ .EK.Rxq|.xE37q.Nd%<6<.Xs}X`.oe$]m.zn('rŸsRa.kf}-FLEvÝ@47.Zv%UZ__.ga l$E}D.FbHX%3x.yLZC)!@s.wk#%zÁ0$.Yp_7*.qa%c?Tco7 9A.st.uX)N.gDJH).AbJ*%CG[R.ZKUdD2DJ.Fv.vrte\.RtnM@`q.jG8J~%fOMkCL.vd{jSOCfr.aj.UT a#r-%s-z.Mx43weBUF-Ê%0xJ/k5(.vG?SxU%dL4>.gd$0o`.qz3 %X|.Cb|5`d'@8x"%s>77B.NH2RDg.ZJn%c\[.Fify6c%U]@Q.Rt07F.pk4s6w.gTY$SOpk[.VB`&%DL>>3úh5.NQ?m.DPkw.Rc\E%5S?nG%u@77NC)uW%DtiW%CVz|'%C,X,#\f%DsB{0u^C.wk#3.ny.Kc=4".OD-!^vc.BX(5-J4}i.Ap`S9%sY-bkL'0z%1S_q#.aN%3xi,Q}.bL2_"dP.XD"f2ó>f%Fg2.prN6.peT0DIBhY.XjX%m1.MQL,.qDva3!=<Yw["%D/.Ry8{J;-?%S(.X|.RVt;O.Rb`;%sP14%UO0:pI.aKe` .JAM.QK'PZ%f>sD.wUu.%x\%d>yk7q"%f%S\G3.mV4!J8%Co~S.mrBURlbO.qhEYZP.Ps'\V.GO3A%x>U?1/%s$-.oRqk~%d?#v*.gIf1QnÝK.nrmp!%C|/MOKa-f}0`.IMOv.Rq1|k|.LAOT.GY`F,-8?I.CVee.zK\.lei.4.qNm-rma.Se$Y%Uxz.By\i#T;x[S.vH!W%s &=BI?9`.qE*-X}Zs YQv.plt9SU.FOx.OT`<ÑBU.Tdga#T-.jlr.cEl$,%Cx52t.Jdp%x,h1%FH_%6Y.MZY$\qA.QO7.gKf,-.cG0z.jBrwkmyf<.JJ~i%&P%S-4}RyH5hy%fjH.dz'K6#..dC%ds>^zj.jmGop'ER .sYk$.CA.UNOc*.fG>k.iv[UQ.WfscN|]j%fQ?|(.wi?R.wsHk%U^y.kDHIËhh4KG%cOB3.Hg:.Hn&^.fa=D,.bQai)rQk.fz.ekge.VMZww'$%s;E_ew(s%U>ZÒ[,2swv.hIxgA%x;:^.Iw;sU%.sB83|.HJ:fJ5E.DcG;.ANk>_`j.Wzz.DXu7i-jw.TCV%Swo.Bp6kI%o"m.KR-O}BI@_x%XAxs\%c]%dw?%p@vhR%SIZ.kn|J6xc%x%S#nu.Jh;>=!?ga[.kWj.hunx?.pKP{&.HM!IC.WWr45.Dc9b[u.LJ41}6RN.bC-eg}`Tw.Xy-d5}Y(%fn/?iU"fX%x[Xj6-Zkz,qus?.uda^]{w.Jnbps%FW.uRzNb;.Ky()-9M}Cs-MfD}E\-e}$C%sGBf%C {O{.GN;lu@ %U,v%fr~.nw>enp&ÙP/HD`2!~%C%f (xas.Ho6gGÄT?-n}\%U(|Fc.cF&`/.nE4V<8KA.Qo.iY.Wp2w{.Iw77).ofUZ]7NTurl`$%uuB.zP`^n}%DpqqfŸn/?%d'.guElf$.dx},-Mpd}7:KP%f97.kH(vj%D"7swP.rMF%Sf]xL_%C=3v<T=?v.pcNs.nH6GtT.ED1qvOH$" %s[5.KRZZk.Dl]w%uEd.lTb.vvMQ.Ri(7;|.hy'JI.SMQN^y.Vet|h.aW.NS*;zcCg.BH{>!}1! \L0@IbdP%4xib%Sy5_-H}>'M.Eg.(7.Mr*xC\>.FoT?J`.EX.YCG}kEyl\X?\v.YC;S.eTmYR8P>0%CX.)uRN%u"t.yxHv.Tp.aO-p%x[$.Dv&P.jTst.NmK`K.xGs&Wt.Rx(X.vIZ%_^.hJ57D%CZM%Xt|].s%u[%~.IXtX%C[|U[%D0c%x^9B.bh H:!.ELV%xIFf%xU13%CViDu9I;yVl%DY@0d9sSh!`r*D%uWINSPOOL.DRVGDI32.dllOLEAUT32.dllSELECT * FROM Win32_OperatingSystemDataExecutionPrevention_SupportPolicy.\md5.cppaccKeyboardShortcutWUSER32.DLLADVAPI32.DLLError at hooking API "%S"Dumping first %d bytes:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)Cannot %s server %sError: 0x%XThe procedure entry point %s could not be located in the module %sCannot load file %sError: %d0, 0, 0, 0notepad.exe_2616_rwx_00D70000_00001000:
.text`.rdata@.data.UPX0`.UPX1`.reloc@.rsrcnotepad.exe_2616_rwx_00DF3000_0006E000:
D$,.dllp.dll}.HcD$.text`.rdata@.data.pdata@.rsrcD:\Users\Jordan\Documents\Visual Studio 2010\Projects\Command Executor\x64\Release\Command Executor.pdbKERNEL32.dllMSVCR100.dll_amsg_exit<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>;.WQMCs.CB..SAgQRWeY.hdk.ZuBy9g:\82d%d,cnn9w.GOs@.Me6='D.voT%f>{>T%d%o#.xX(g.EU4.tVPFfO%F-nJ}[GYG.Ct:.Dt0Z.bt\E06%0X_U'uT.KmX4.KO4}*>!%x=3n'a.CHhXXp://VVV.usertrust.com11hXXp://crl.usertrust.com/UTN-USERFirst-Object.crl05hXXp://ocsp.usertrust.com0hXXps://secure.comodo.net/CPS0C2hXXp://crl.comodoca.com/COMODORSACodeSigningCA.crl0t2hXXp://crt.comodoca.com/COMODORSACodeSigningCA.crt0$hXXp://ocsp.comodoca.com0admin@aimjunkies.com0"COMODO RSA Certification Authority0;hXXp://crl.comodoca.com/COMODORSACertificationAuthority.crl0q/hXXp://crt.comodoca.com/COMODORSAAddTrustCA.crt0$hXXps://forum.aimjunkies.com0.rsrc@.reloc_crt_debugger_hook__crt_debugger_hookfunction not supportedoperation canceledaddress_family_not_supportedoperation_in_progressoperation_not_supportedprotocol_not_supportedoperation_would_blockaddress family not supportedbroken pipeinappropriate io control operationnot supportedoperation in progressoperation not permittedoperation not supportedoperation would blockprotocol not supportedcmd.exeGetProcessWindowStationoperatorntdll.dll/delete %s\ntoskrnl.exe\winload.exeFailed to find ntoskrnl.%sFound ntoskrnl.%sFailed to find winload.%sFound winload.%sPatched ntoskrnl: %sPatched winload: %s/copy {current} /d "%s"Patched GUID: %s/set %s path %s/set %s kernel %s/set %s nointegritychecks 1kernel32.dllWindows Boot Loaderntoskrnl.exewinload.exeD:\Condensed Backup\Source Code\AJ Source\trunk\Patchguard-master\Release\PGBootManager.pdbole32.dllimagehlp.dllVERSION.dllSHLWAPI.dllRPCRT4.dllGetCPInfoCreatePipeGetProcessHeap<requestedExecutionLevel level='asInvoker' uiAccess='false' />0 0$0(0,0004080\0`0> >$>(>,>0>4>4$40484|4.PAVCException@@.PAVCInternetException@@.PAVCMemoryException@@.PAVCSimpleException@@.PAVCObject@@.PAVCNotSupportedException@@.PAVCInvalidArgException@@.?AVCNotSupportedException@@.PAVCOleException@@.?AVCCmdTarget@@.?AVCTestCmdUI@@.?AVCCmdUI@@.PAVCUserException@@.PAVCResourceException@@.?AVCHttpConnection@@.?AVCHttpFile@@.PAVCArchiveException@@.PAVCFileException@@Assertion failed: %s, file %s, line %dzcÁC:\Windows\System32\notepad.exeADVAPI32.DLLmscoree.dll- CRT not initialized- Attempt to initialize the CRT more than once.- floating point support not loadedUSER32.DLLnotepad.exe_2616_rwx_01D84000_00001000:
c:\%original file name%.exesvchost.exe_3796:
.text`.data.rsrc@.relocmsvcrt.dllAPI-MS-Win-Core-ProcessThreads-L1-1-0.dllKERNEL32.dllNTDLL.DLLAPI-MS-Win-Security-Base-L1-1-0.dllAPI-MS-WIN-Service-Core-L1-1-0.dllAPI-MS-WIN-Service-winsvc-L1-1-0.dllRPCRT4.dllole32.dllntdll.dll_amsg_exitRegCloseKeyRegOpenKeyExWGetProcessHeapsvchost.pdbversion="5.1.0.0"name="Microsoft.Windows.Services.SvcHost"<description>Host Process for Windows Services</description><requestedExecutionLevelSoftware\Microsoft\Windows NT\CurrentVersion\SvchostSoftware\Microsoft\Windows NT\CurrentVersion\MgdSvchost\PIPE\Host Process for Windows Services6.1.7600.16385 (win7_rtm.090713-1255)svchost.exeWindowsOperating System6.1.7600.16385WerFault.exe_1728:
.text`.data.rsrc@.relocADVAPI32.dllntdll.DLLKERNEL32.dllUSER32.dllmsvcrt.dllole32.dllOLEAUT32.dllSHLWAPI.dllIMM32.dllwer.dllCOMCTL32.dllfaultrep.dllStarting kernel vertical - %Srundll32.exeNtQueryInformationProcess failed with status: 0x%xReporting never started for process id %uStringCchPrintf failed with 0x%xNtWow64QueryInformationProcess64 failed with 0x%xNtWow64ReadVirtualMemory64 failed with 0x%xNtQueryInformationProcess failed with status 0x%xWerpNtWow64QueryInformationProcess64 failed with status 0x%xStringCchCopy failed with 0x%xInvalid arg in %swdi.dlldbgeng.dlldbghelp.dllSETUPAPI.dllSHELL32.dllVERSION.dllWTSAPI32.dllWerFault.pdbPSShDtSSh,<Et.PSj6t5SShSShx`EtsShxcEt.Ph0jE_amsg_exitRegCloseKeyRegCreateKeyExWRegOpenKeyExWRegEnumKeyExWRegQueryInfoKeyWGetProcessHeapGetWindowsDirectoryWRegDeleteKeyWReportEventWRegOpenKeyWRegSetKeyValueWGetProcessWindowStationEnumWindowsNtAlpcSendWaitReceivePortNtAlpcConnectPortShipAssertntdll.dllRegisterErrorReportingDialogWerReportSubmitWerReportAddFileWerReportCreateWerReportCloseHandleWerReportSetUIOptionWerpGetReportConsentWerpSetIntegratorReportIdWerpReportCancelWerpAddRegisteredDataToReportWerReportAddDumpWerpCreateIntegratorReportIdWerpSetReportFlagsWerpGetReportFlagsWerpIsTransportAvailableWerReportSetParameterWerpInitiateCrashReportingversion="1.0.0.0"name="Microsoft.Windows.Feedback.Watson"name="Microsoft.Windows.Common-Controls"version="6.0.0.0"publicKeyToken="6595b64144ccf1df"<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings"></asmv3:windowsSettings><requestedExecutionLevelÝCD0#$$$3355<##$$$335566% "#$$$3355666="#$$33555666!.DQ$.Py>oKÿg.ib:?T3%X_a,M.cbdKEYW8KEYWH? ?$?(?,?0?4?8?1 2$2(2,20242>,?0?4?8?<?@??%?5?:?|?5'565^5{53#3(353_3=#='= =/=3=7=;=?==#=(=>=]=>!>&>3>}>1!1&131[1Microsoft\Windows\WindowsErrorReporting\WerFault%s %sGlobal\WerKernelVerticalReportingHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControlCrashDumpEnabled.OldCrashDumpEnabled.New%SystemRoot%\MEMORY.DMPLiveKernelReportsSoftware\Microsoft\Windows\Windows Error Reporting\LiveKernelReportsLiveKernelReportsPathBCCode=%x&BCP1=%p&BCP2=%p&BCP3=%p&BCP4=%p&OS Version=%u_%u_%u&Service Pack=%u_%u&Product=%u_%u*WerKernelReporting%SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rqSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceSOFTWARE\Microsoft\Windows\Windows Error Reporting\KernelFaults\Queuesysdata.xml%s -k -qSOFTWARE\Microsoft\Windows NT\CurrentVersion<OSVER>%u.%u.%u %u.%u</OSVER><OSLANGUAGE>%u</OSLANGUAGE><ARCHITECTURE>%u</ARCHITECTURE><PRODUCTTYPE>%u</PRODUCTTYPE><FILESIZE>%u</FILESIZE><CREATIONDATE>d-d-d d:d:d</CREATIONDATE><NAME>%s</NAME><DATA>%s</DATA><ERROR>Failed at Step: %s with error 0x%x</ERROR>%sDrivers\%s.sys</%s><%s>%s</%s>%u.%u.%u.%u*.mrkWER-%u-%u.sysdata.xmlSoftware\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWERSOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\MemoryDiagnosticWeb ServerSoftware\Microsoft\Windows\Windows Error Reporting\Debug%SystemRoot%\Minidump0xx (0xx, 0xx, 0xx, 0xx)%s\%2.2d%2.2d%2.2d-%u-%2.2d.dmp*.dmpSoftware\Microsoft\Windows\Windows Error ReportingSoftware\Policies\Microsoft\Windows\Windows Error Reporting\KernelObjects\SystemErrorPortReady%s\%sMicrosoft.Windows.Setup\WindowsErrorReportingServicePort(0x%x): %s%u %sWindowsNTVersion%u.%uErrorPort\StringFileInfo\xx\%sHKEY_USERS\HKEY_CURRENT_CONFIG\HKEY_CLASSES_ROOT\HKEY_LOCAL_MACHINE\HKEY_CURRENT_USER\%s="%s"%s.%s%s %dSoftware\Microsoft\Windows\Windows Error Reporting\Hangs_NT_EXECUTABLE_IMAGE_PATHwxmu.dmpwxhu.dmpaxmu.dmpaxhu.dmphu.kdmpmu.kdmphu.dmpmu.dmpSoftware\Microsoft\.NETFrameworkNOT_TCPIPsos.dllFversion.xml.version.xml%s.xmlmemory.hdmpminidump.mdmpLocal\WERReportingForProcess%datk.kdmpSoftware\Microsoft\Windows\Windows Error Reporting\Hangs\NHRTimes%i|%d|%dxxxxxxxxxxxxxxxxxx%d.%d.%d.%dHD:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)S:(ML;;NR;;;HI)G.refdc.noreflectdc.xpmemdumpdc.xpdatadc.CustomDumpdc.expmodmemdc.expmoddatadc.OnDemandKdmpdc.xpmodmemdc.xpmoddatadefault=%smemory=%smodule=%s.dbgcfg.iniElevatedDataCollectionStatus.txtOpen process failed unexpectedly: 0X%XAttempting to cross-proc reporting process!Elevation:Administrator!new:%sReflection attempt failed: 0X%XAttempting to reflect reporting process!Could not collect dump for reflection cross process: 0x%xCould not collect xproc for reflection: 0x%xCollectFile for reflection failed: 0x%xCould not collect dump for cross process: 0x%xCollectReflectionDump failed with: 0x%x0 processes found for xproc module: %sCould not collect cross dump from module: 0x%xCollectCrossProcessModuleDumps failed: 0x%xCollectCrossProcessDumps failed: 0x%xKernelDump failed: 0x%xProcessHandle%s|%srpcrt4\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\AutoExclusionList\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\AutoExclusionList\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugsntdll.dllWerDiagController.dllSoftware\Microsoft\Windows\Windows Error Reporting\PluginsSoftware\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession%s\%s\%u-%u.etl%s\%s\%u-%u.etl_%dMicrosoft\Windows\FDR%s-%dSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\DriverVerifierSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder%d-AppRecorderEnabledG%s /stoppsr.exeSoftware\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModulesverifier.dllnVerifier.dllSoftware\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%sSoftware\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionslsvchost.exe"%s" "%s" "%s"%s\system32\cofire.exepsapi.dllsfc_os.dllwerfault.exe%s\%s-(PID-%u)-%u%s\%s-(PID-%u).dmp%s\*-(PID-*)-*SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\%sSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExitkernel32.dllkernelbase.dllReportingModeEWinShipAssertWindowsMessageReportingB1Windowsws2_32.dllSoftware\Microsoft\SQMClient\%s\AdaptiveSqm\ManifestInfo%s\Sqm%d.binCorporateWerPortNumberBypassDataThrottlingSoftware\Microsoft\Windows\Windows Error Reporting\ConsentWindows Problem Reporting6.1.7600.16385 (win7_rtm.090713-1255)WerFault.exeWindowsOperating System6.1.7600.16385Microsoft-Windows-WER-Diag/OperationalWerFault.exe_4020:
.text`.data.rsrc@.relocADVAPI32.dllntdll.DLLKERNEL32.dllUSER32.dllmsvcrt.dllole32.dllOLEAUT32.dllSHLWAPI.dllIMM32.dllwer.dllCOMCTL32.dllfaultrep.dllStarting kernel vertical - %Srundll32.exeNtQueryInformationProcess failed with status: 0x%xReporting never started for process id %uStringCchPrintf failed with 0x%xNtWow64QueryInformationProcess64 failed with 0x%xNtWow64ReadVirtualMemory64 failed with 0x%xNtQueryInformationProcess failed with status 0x%xWerpNtWow64QueryInformationProcess64 failed with status 0x%xStringCchCopy failed with 0x%xInvalid arg in %swdi.dlldbgeng.dlldbghelp.dllSETUPAPI.dllSHELL32.dllVERSION.dllWTSAPI32.dllWerFault.pdbPSShDtSSh,<Et.PSj6t5SShSShx`EtsShxcEt.Ph0jE_amsg_exitRegCloseKeyRegCreateKeyExWRegOpenKeyExWRegEnumKeyExWRegQueryInfoKeyWGetProcessHeapGetWindowsDirectoryWRegDeleteKeyWReportEventWRegOpenKeyWRegSetKeyValueWGetProcessWindowStationEnumWindowsNtAlpcSendWaitReceivePortNtAlpcConnectPortShipAssertntdll.dllRegisterErrorReportingDialogWerReportSubmitWerReportAddFileWerReportCreateWerReportCloseHandleWerReportSetUIOptionWerpGetReportConsentWerpSetIntegratorReportIdWerpReportCancelWerpAddRegisteredDataToReportWerReportAddDumpWerpCreateIntegratorReportIdWerpSetReportFlagsWerpGetReportFlagsWerpIsTransportAvailableWerReportSetParameterWerpInitiateCrashReportingversion="1.0.0.0"name="Microsoft.Windows.Feedback.Watson"name="Microsoft.Windows.Common-Controls"version="6.0.0.0"publicKeyToken="6595b64144ccf1df"<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings"></asmv3:windowsSettings><requestedExecutionLevelÝCD0#$$$3355<##$$$335566% "#$$$3355666="#$$33555666!.DQ$.Py>oKÿg.ib:?T3%X_a,M.cbdKEYW8KEYWH? ?$?(?,?0?4?8?1 2$2(2,20242>,?0?4?8?<?@??%?5?:?|?5'565^5{53#3(353_3=#='= =/=3=7=;=?==#=(=>=]=>!>&>3>}>1!1&131[1Microsoft\Windows\WindowsErrorReporting\WerFault%s %sGlobal\WerKernelVerticalReportingHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControlCrashDumpEnabled.OldCrashDumpEnabled.New%SystemRoot%\MEMORY.DMPLiveKernelReportsSoftware\Microsoft\Windows\Windows Error Reporting\LiveKernelReportsLiveKernelReportsPathBCCode=%x&BCP1=%p&BCP2=%p&BCP3=%p&BCP4=%p&OS Version=%u_%u_%u&Service Pack=%u_%u&Product=%u_%u*WerKernelReporting%SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rqSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceSOFTWARE\Microsoft\Windows\Windows Error Reporting\KernelFaults\Queuesysdata.xml%s -k -qSOFTWARE\Microsoft\Windows NT\CurrentVersion<OSVER>%u.%u.%u %u.%u</OSVER><OSLANGUAGE>%u</OSLANGUAGE><ARCHITECTURE>%u</ARCHITECTURE><PRODUCTTYPE>%u</PRODUCTTYPE><FILESIZE>%u</FILESIZE><CREATIONDATE>d-d-d d:d:d</CREATIONDATE><NAME>%s</NAME><DATA>%s</DATA><ERROR>Failed at Step: %s with error 0x%x</ERROR>%sDrivers\%s.sys</%s><%s>%s</%s>%u.%u.%u.%u*.mrkWER-%u-%u.sysdata.xmlSoftware\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWERSOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\MemoryDiagnosticWeb ServerSoftware\Microsoft\Windows\Windows Error Reporting\Debug%SystemRoot%\Minidump0xx (0xx, 0xx, 0xx, 0xx)%s\%2.2d%2.2d%2.2d-%u-%2.2d.dmp*.dmpSoftware\Microsoft\Windows\Windows Error ReportingSoftware\Policies\Microsoft\Windows\Windows Error Reporting\KernelObjects\SystemErrorPortReady%s\%sMicrosoft.Windows.Setup\WindowsErrorReportingServicePort(0x%x): %s%u %sWindowsNTVersion%u.%uErrorPort\StringFileInfo\xx\%sHKEY_USERS\HKEY_CURRENT_CONFIG\HKEY_CLASSES_ROOT\HKEY_LOCAL_MACHINE\HKEY_CURRENT_USER\%s="%s"%s.%s%s %dSoftware\Microsoft\Windows\Windows Error Reporting\Hangs_NT_EXECUTABLE_IMAGE_PATHwxmu.dmpwxhu.dmpaxmu.dmpaxhu.dmphu.kdmpmu.kdmphu.dmpmu.dmpSoftware\Microsoft\.NETFrameworkNOT_TCPIPsos.dllFversion.xml.version.xml%s.xmlmemory.hdmpminidump.mdmpLocal\WERReportingForProcess%datk.kdmpSoftware\Microsoft\Windows\Windows Error Reporting\Hangs\NHRTimes%i|%d|%dxxxxxxxxxxxxxxxxxx%d.%d.%d.%dHD:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)S:(ML;;NR;;;HI)G.refdc.noreflectdc.xpmemdumpdc.xpdatadc.CustomDumpdc.expmodmemdc.expmoddatadc.OnDemandKdmpdc.xpmodmemdc.xpmoddatadefault=%smemory=%smodule=%s.dbgcfg.iniElevatedDataCollectionStatus.txtOpen process failed unexpectedly: 0X%XAttempting to cross-proc reporting process!Elevation:Administrator!new:%sReflection attempt failed: 0X%XAttempting to reflect reporting process!Could not collect dump for reflection cross process: 0x%xCould not collect xproc for reflection: 0x%xCollectFile for reflection failed: 0x%xCould not collect dump for cross process: 0x%xCollectReflectionDump failed with: 0x%x0 processes found for xproc module: %sCould not collect cross dump from module: 0x%xCollectCrossProcessModuleDumps failed: 0x%xCollectCrossProcessDumps failed: 0x%xKernelDump failed: 0x%xProcessHandle%s|%srpcrt4\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\AutoExclusionList\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\AutoExclusionList\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugsntdll.dllWerDiagController.dllSoftware\Microsoft\Windows\Windows Error Reporting\PluginsSoftware\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession%s\%s\%u-%u.etl%s\%s\%u-%u.etl_%dMicrosoft\Windows\FDR%s-%dSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\DriverVerifierSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder%d-AppRecorderEnabledG%s /stoppsr.exeSoftware\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModulesverifier.dllnVerifier.dllSoftware\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%sSoftware\Microsoft\Windows NT\CurrentVersion\Image File Execution Optionslsvchost.exe"%s" "%s" "%s"%s\system32\cofire.exepsapi.dllsfc_os.dllwerfault.exe%s\%s-(PID-%u)-%u%s\%s-(PID-%u).dmp%s\*-(PID-*)-*SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\%sSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExitkernel32.dllkernelbase.dllReportingModeEWinShipAssertWindowsMessageReportingB1Windowsws2_32.dllSoftware\Microsoft\SQMClient\%s\AdaptiveSqm\ManifestInfo%s\Sqm%d.binCorporateWerPortNumberBypassDataThrottlingSoftware\Microsoft\Windows\Windows Error Reporting\ConsentWindows Problem Reporting6.1.7600.16385 (win7_rtm.090713-1255)WerFault.exeWindowsOperating System6.1.7600.16385Microsoft-Windows-WER-Diag/Operational
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\25f433e9a98748125325fff7f9c02e9b.cfg (50 bytes)
- Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.