Worm.Win32.AutoItGen_557cdbaefd
GenericEmailWorm.YR, WormAutoItGen.YR (Lavasoft MAS)
Behaviour: Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 557cdbaefd0db67bb620699ced75c238
SHA1: fea4fe3d76b1be476293aa60f9ffdcb38bbdbffe
SHA256: 83bcf8fe6eaa30e66378801f88b6775a568702d65ff3d11cd67d8108e3a14d5b
SSDeep: 98304:F9vF1R2VyDsTwwEOvUUEBhjL8GMYi74R2RFCtEAoHqGz:pVDgwwcXzgZC2AoHqGz
Size: 4313352 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, UPolyXv05_v6
Company: PC Utilities Software Limited
Created at: 2013-02-04 20:24:57
Analyzed on: Windows7Ada SP1 64-bit
Summary:
Worm. A program that is primarily replicating on networks or removable drives.
Payload
| Behaviour | Description |
|---|---|
| EmailWorm | Worm can send e-mails. |
Process activity
The Worm creates the following process(es):
unins000.exe:2044
%original file name%.exe:2492
OptProStart.exe:816
_iu14D2N.tmp:324
557cdbaefd0db67bb620699ced75c238.tmp:2312
The Worm injects its code into the following process(es):
OptimizerPro.exe:2564
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process OptimizerPro.exe:2564 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\Documents\Optimizer Pro\CookiesException.txt (90 bytes)
The process unins000.exe:2044 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_iu14D2N.tmp (7596 bytes)
The process %original file name%.exe:2492 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-D7C27.tmp\557cdbaefd0db67bb620699ced75c238.tmp (50 bytes)
The process _iu14D2N.tmp:324 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-F5FV6.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-F5FV6.tmp\_isetup\_setup64.tmp (6 bytes)
The process 557cdbaefd0db67bb620699ced75c238.tmp:2312 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Program Files% (x86)\Optimizer Pro 3.38\is-NEQP4.tmp (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\OptProHelper.dll (8020 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-KDJOK.tmp (32054 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-LT48B.tmp (712 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Check updates.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-U76OH.tmp (3073 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-C3JNF.tmp (1281 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\OptimizerPro.exe (291 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-006S0.tmp (25426 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-OMCM9.tmp (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\_isetup\_setup64.tmp (6 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-VMKQI.tmp (20 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-R5MDU.tmp (48 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-51OHT.tmp (3361 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-VLSN7.tmp (601 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\unins000.msg (646 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-PLMDG.tmp (7971 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-BR1TT.tmp (56 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Uninstall Optimizer Pro.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-965I1.tmp (673 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-MTLCD.tmp (65 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-2JH58.tmp (2321 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Help.lnk (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro on the Web.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-54C84.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\itdownload.dll (1489 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\unins000.dat (22397 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Optimizer Pro.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-C0UUH.tmp (898 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-NFLVM.tmp (22 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-UQLKK.tmp (601 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-0QERA.tmp (2321 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-NALI7.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro.lnk (1 bytes)
Registry activity
The process OptimizerPro.exe:2564 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKCU\Software\Optimizer Pro]
"SpeedGuard" = "0"
"ShowRebootMessage" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Optimizer Pro]
"Stat1a" = "90"
"s_Enable" = "0"
"UndoDir" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Optimizer Pro\Undo"
"LastScanChecked" = "1111011"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Optimizer Pro]
"AppStart" = "1"
"UpgradeID" = "BZDV_PCSM_ML_PCUP_OPTIMIZERPRO_YELLOW"
"ItemsCleaned" = "0"
"Reminder" = "1"
"RunDate" = "68 F3 60 2A CA 87 E4 40"
"s_Time" = "79 F1 6B 29 CA 87 E4 40"
"LOGDIR" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Optimizer Pro\Log"
"QuerryDate" = "68 F3 60 2A CA 87 E4 40"
"s_SmartMode" = "0"
"LastVersionChecking" = "79 F1 6B 29 CA 87 E4 40"
"LastScanFound" = "219"
"ProblemsFixed" = "0"
"UseExceptionList" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Optimizer Pro]
"DisplayName" = "Optimizer Pro"
"s_SmartScan" = "1"
"ResidualFilesCleaned" = "0"
"ItemsToScan" = "1111111111"
"Version" = "3.2"
"ItemsToFix" = "90"
"InstallStat" = "1"
"ItemsToClean" = "129"
"s_SmartExec" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Worm deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process unins000.exe:2044 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\PUPautoinsaller_v1.exe, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\31ec1c24\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\python.dll, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\VMwareDnD\6c88b866\, , \??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_iu14D2N.tmp,"
The process OptProStart.exe:816 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKCU\Software\Optimizer Pro]
"ScanAtStartup" = "0"
"UninstallURL" = "https://safecart.com/pcutilitiespro/.op-special/purchase?sid=111000501-UA-002"
"Querry" = "http://bi.secure-download.net/t/op?sid=111000501-UA-002&dt=%dt%&gid=%GID%&tz=%tz%&ln=%ln%&lc=%lc%&bis=%bis%&bief=%bief%&biefx=%biefx%&bif=%bif%&os=%os%&f=270730756"
"homepageurl" = "http://www.pcutilitiespro.com/"
"BuyNowURL" = "http://gen.securedshopgate.com/?t=01&tid=111000501-UA-002_B1191E57-169A-0822-2D09-59A9561F88E3&a=dejebel"
"InstallDate" = "8F 0E 0E 29 CA 87 E4 40"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Optimizer Pro]
"AdsBuyNowURL" = "http://www.safeshopgate.com/r?s=121000501&g=B1191E57-169A-0822-2D09-59A9561F88E3"
"DelayedStart" = "0"
"UseAds" = "1"
"ShowEUA" = "1"
"AdsDownloadURL" = "http://dl.repairlabshost.com/121000501/DriverPro.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Optimizer Pro]
"AdsHost" = "dl.repairlabshost.com"
"OS" = "106"
"MachineGuid" = "B1191E57-169A-0822-2D09-59A9561F88E3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"
[HKCU\Software\Optimizer Pro]
"AppStart" = "0"
"WelcomeURL" = ""
"SupportURL" = "http://support.pcutilitiespro.com/"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Worm deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
The process 557cdbaefd0db67bb620699ced75c238.tmp:2312 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\RestartManager\Session0000]
"RegFilesHash" = "E9 84 69 97 49 34 C3 7B E9 1F B2 2E 9B C5 49 21"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"RegFiles0000" = "%Program Files% (x86)\Optimizer Pro 3.38\OptimizerPro.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProStart.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProReminder.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProSmartScan.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProGuard.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProSchedule.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProLauncher.exe, %Program Files% (x86)\Optimizer Pro 3.38\OptProUninstaller.exe, %Program Files% (x86)\Optimizer Pro 3.38\sqlite3.dll, %Program Files% (x86)\Optimizer Pro 3.38\OptimizerPro.chm, %Program Files% (x86)\Optimizer Pro 3.38\OptProHelper.dll, %Program Files% (x86)\Optimizer Pro 3.38\itdownload.dll"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"URLInfoAbout" = "http://www.pcutilitiespro.com"
[HKCU\Software\Optimizer Pro]
"cufValue" = "CUF=0"
"culValue" = ""
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"Inno Setup: User" = "%CurrentUserName%"
"DisplayIcon" = "%Program Files% (x86)\Optimizer Pro 3.38\OptProLauncher.exe"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"SessionHash" = "8A 3A 14 D2 6C 99 5B 5D B6 96 37 A2 C2 2A 92 6C"
[HKCU\Software\Optimizer Pro]
"Language" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"Inno Setup: Deselected Tasks" = ""
"Inno Setup: Selected Tasks" = "runoptpro,runoptprodaily,desktopicon"
"URLUpdateInfo" = "http://www.pcutilitiespro.com"
"DisplayVersion" = "3.2.0.3"
"HelpLink" = "http://www.pcutilitiespro.com"
"Inno Setup: Language" = "en"
"Inno Setup: Setup Version" = "5.5.3 (u)"
"DisplayName" = "Optimizer Pro v3.2"
"NoRepair" = "1"
"Inno Setup: App Path" = "%Program Files% (x86)\Optimizer Pro 3.38"
"QuietUninstallString" = "%Program Files% (x86)\Optimizer Pro 3.38\unins000.exe /SILENT"
[HKCU\Software\Optimizer Pro]
"setupname" = "c:\%original file name%.exe"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"InstallDate" = "20150211"
"EstimatedSize" = "10901"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"Sequence" = "1"
[HKCU\Software\Optimizer Pro]
"Ir" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"MinorVersion" = "2"
"Inno Setup: Icon Group" = "Optimizer Pro v3.2"
[HKCU\Software\Optimizer Pro]
"SessionID" = "BA0B5C4A-F59C-42DE-8C19-81CA43A780D4"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"MajorVersion" = "3"
"UninstallString" = "%Program Files% (x86)\Optimizer Pro 3.38\unins000.exe"
"NoModify" = "1"
[HKCU\Software\Microsoft\RestartManager\Session0000]
"Owner" = "08 09 00 00 BA E0 79 BC BC 45 D0 01"
[HKCU\Software\Optimizer Pro]
"CBM" = "1"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1]
"Publisher" = "PC Utilities Software Limited"
"InstallLocation" = "%Program Files% (x86)\Optimizer Pro 3.38\"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Optimizer Pro" = "%Program Files% (x86)\Optimizer Pro 3.38\OptProLauncher.exe"
The Worm deletes the following registry key(s):
[HKCU\Software\Microsoft\RestartManager\Session0000]
The Worm deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\RestartManager\Session0000]
"RegFilesHash"
"Sequence"
"RegFiles0000"
"SessionHash"
"Owner"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
Dropped PE files
| MD5 | File path |
|---|---|
| 3fef156c0093c95e79479599584b974c | c:\Program Files (x86)\Optimizer Pro 3.38\OptProGuard.exe |
| fc3982674164a92c11a46c9c02248131 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProHelper.dll |
| 211226c4b252aae745a50dcd81c84e02 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProLauncher.exe |
| cf8d9f2945afa1fe86a47a8a9b02f335 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProReminder.exe |
| 4bd522bffb43b404dc8c70714353622d | c:\Program Files (x86)\Optimizer Pro 3.38\OptProSchedule.exe |
| 7f816e41f3fb8a9a0bc9c2585bef0df0 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProSmartScan.exe |
| fdc1e5e55aad343482c97e6c6d1fd995 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProStart.exe |
| cb78d0aaecab5b17e55b1f0b8cbdf355 | c:\Program Files (x86)\Optimizer Pro 3.38\OptProUninstaller.exe |
| b5f2257651f92f1495e6d6f50ff41200 | c:\Program Files (x86)\Optimizer Pro 3.38\OptimizerPro.exe |
| d82a429efd885ca0f324dd92afb6b7b8 | c:\Program Files (x86)\Optimizer Pro 3.38\itdownload.dll |
| 0f66e8e2340569fb17e774dac2010e31 | c:\Program Files (x86)\Optimizer Pro 3.38\sqlite3.dll |
| e1ea01f7d64e3996731ce0c2a1e849f7 | c:\Program Files (x86)\Optimizer Pro 3.38\unins000.exe |
| e1ea01f7d64e3996731ce0c2a1e849f7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_iu14D2N.tmp |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: PC Utilities Software Limited
Product Name: Optimizer Pro 3.2
Product Version: 3.2.0.3
Legal Copyright: PC Utilities Software Limited
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 3.2.0.3
File Description:
Comments: This installation was built with Inno Setup.
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 61740 | 61952 | 4.43024 | 3a126e478661f20816f9d9285615f98e |
| .itext | 69632 | 2884 | 3072 | 3.97317 | ba48b9b17b3dd8b92da3bd93f20ddb34 |
| .data | 73728 | 3208 | 3584 | 1.55702 | d7fd5f4b562d7961758f3d6a8c834fd0 |
| .bss | 77824 | 22196 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .idata | 102400 | 3536 | 3584 | 3.44625 | 93d91a2b90e60bd758fc0c4908856ae1 |
| .tls | 106496 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rdata | 110592 | 24 | 512 | 0.14174 | 3dffc444ccc131c9dcee18db49ee6403 |
| .rsrc | 114688 | 41292 | 41472 | 4.41528 | 4baccc27040840ecc477e030c9d61216 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 1
930de8607b8fe8992c3cb07a90ac5b74
URLs
| URL | IP |
|---|---|
| hxxp://bi.secure-download.net/t/op?sid=111000501-UA-002&dt=1423640247&gid=B1191E57-169A-0822-2D09-59A9561F88E3&tz=2&ln=1&lc=0&bis=1&bief=0&biefx=0&bif=0&os=106&f=270730756 | |
| hxxp://service.smartpcupdate.com/rpc/sendspminstall?partner=BZDV_PCSM_ML_PCUP_OPTIMIZERPRO_YELLOW&build=3.2 | |
| hxxp://pcup-optimizerpro.com/inst?hid=f9fa0c8af68693bc10e76c7b051b0f2683651245&sid=BA0B5C4A-F59C-42DE-8C19-81CA43A780D4&tr=111000501-UA-002&adm=1&os=6.1&x64=1&sil=0&e=600 | |
| hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b1ccd395ee99a9dc | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/microsoftrootcert.crl | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/WinPCA.crl | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftTimeStampPCA.crl | |
| hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
| hxxp://a1621.g.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8e8d43eb436062e2 | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
| hxxp://e6845.ce.akamaiedge.net/pca3.crl | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | |
| hxxp://e8218.ce.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
| hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s= | |
| hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs= | |
| hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEETiV2tweIHKNF6KMhnt3r4= | |
| hxxp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= | |
| hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8e8d43eb436062e2 | |
| hxxp://crl.verisign.com/pca3.crl | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= | |
| hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEETiV2tweIHKNF6KMhnt3r4= | |
| hxxp://crl.microsoft.com/pki/crl/products/WinPCA.crl | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= | |
| hxxp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= | |
| hxxp://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b1ccd395ee99a9dc |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
SURICATA UDPv4 invalid checksum
SURICATA IPv4 invalid checksum
Traffic
GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sat, 24 May 2014 05:04:51 GMT
If-None-Match: "96bfbfb1d77cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Wed, 07 Jan 2015 06:02:43 GMT
Accept-Ranges: bytes
ETag: "88c4768d3f2ad01:0"
Server: Microsoft-IIS/8.5
VTag: 438331116300000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 813
Cache-Control: max-age=900
Date: Wed, 11 Feb 2015 05:40:29 GMT
Connection: keep-alive0..)0......0...*.H........0_1.0.....&...,d....com1.0.....&...,d....mic
rosoft1-0 ..U...$Microsoft Root Certificate Authority..150106214825Z..
150407100825Z0.0...a......../..100208014912Z._0]0...U.#..0......`@V'..
%..*..S.Y..0... .....7.......0...U......(0... .....7......150406215825
Z0...*.H..............vQ..r..L.Q.N..=#.......V;..r../\.m..<.."...F/
U....(:.....xm.....P.e.F..BE8......=...G....6t:...?...L..B.v..p.M.....
...z..Q.%J.6..I.......8...U. .g..=T=K....L..$w...^....y~..-a.'...*s#N.
o..Qs.$h..:duV'~....8.6..w..b3.... .~)...|.I.y".>R.nJq.ws...3.....f
}.E)\......EB.d\.2.....h...lMjT.7..lj.'lj.b....".L.Os6{[email protected].|7z
.. ......>..Q...([email protected]\]#..Y.*.......T. .C.....A'..
5FW.ETDvX..tE.....g5.....&..&.....x.^H;...../7..'9.t.I&<[.HX.j....Q
w......}...qy3..q`<.....LB.9w|....;..Qw..a ..=.C.:.....HTTP/1.1 200
OK..Content-Type: application/pkix-crl..Last-Modified: Wed, 07 Jan 20
15 06:02:43 GMT..Accept-Ranges: bytes..ETag: "88c4768d3f2ad01:0"..Serv
er: Microsoft-IIS/8.5..VTag: 438331116300000000..P3P: CP="ALL IND DSP
COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT
NAV ONL PHY PRE PUR UNI"..X-Powered-By: ASP.NET..Content-Length: 813..
Cache-Control: max-age=900..Date: Wed, 11 Feb 2015 05:40:29 GMT..Conne
ction: keep-alive..0..)0......0...*.H........0_1.0.....&...,d....com1.
0.....&...,d....microsoft1-0 ..U...$Microsoft Root Certificate Authori
ty..150106214825Z..150407100825Z0.0...a......../..100208014912Z._0]0..
.U.#..0......`@V'..%..*..S.Y..0... .....7.......0...U......(0... .<<< skipped >>>
GET /pki/crl/products/WinPCA.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Wed, 07 May 2014 05:04:02 GMT
If-None-Match: "a413fc3b169cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Sun, 21 Dec 2014 06:03:02 GMT
Accept-Ranges: bytes
ETag: "d2e35dc7e31cd01:0"
Server: Microsoft-IIS/8.5
VTag: 791141515700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 561
Cache-Control: max-age=900
Date: Wed, 11 Feb 2015 05:40:34 GMT
Connection: keep-alive0..-0......0...*.H........0..1.0...U....US1.0...U....Washington1.0...U
....Redmond1.0...U....Microsoft Corporation1 0)..U..."Microsoft Window
s Verification PCA..141220223154Z..150321105154Z._0]0...U.#..0.......p
............<.J0... .....7.......0...U......30... .....7......15032
0224154Z0...*.H.............h.~oH#i.J.vh_.....A'B..g...........F....9c
.{[email protected].^ 4.r..Wv.Q.0.w..j....c9..w....I..%.~.l..F.......xo....
_...o...7BR.;<..\R/ .....b.(....~..]|.v.u.i.X.B....I......./*...P..
A..fi.}& .x.v{TFP[.G......A......L.o...)R.......V.u..V.../.Q..(L.]....
.uki~..HTTP/1.1 200 OK..Content-Type: application/pkix-crl..Last-Modif
ied: Sun, 21 Dec 2014 06:03:02 GMT..Accept-Ranges: bytes..ETag: "d2e35
dc7e31cd01:0"..Server: Microsoft-IIS/8.5..VTag: 791141515700000000..P3
P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OU
R SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"..X-Powered-By: ASP.NET..Co
ntent-Length: 561..Cache-Control: max-age=900..Date: Wed, 11 Feb 2015
05:40:34 GMT..Connection: keep-alive..0..-0......0...*.H........0..1.0
...U....US1.0...U....Washington1.0...U....Redmond1.0...U....Microsoft
Corporation1 0)..U..."Microsoft Windows Verification PCA..141220223154
Z..150321105154Z._0]0...U.#..0.......p............<.J0... .....7...
....0...U......30... .....7......150320224154Z0...*.H.............h.~o
H#i.J.vh_.....A'B..g...........F....9c.{[email protected].^ 4.r..Wv.Q.0.w..
j....c9..w....I..%.~.l..F.......xo...._...o...7BR.;<..\R/ .....b.(.
...~..]|.v.u.i.X.B....I......./*...P..A..fi.}& .x.v{TFP[.G......A.<<< skipped >>>
GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Mon, 05 May 2014 05:04:34 GMT
If-None-Match: "87fbb3811f68cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Fri, 19 Dec 2014 06:02:00 GMT
Accept-Ranges: bytes
ETag: "9a9a44d511bd01:0"
Server: Microsoft-IIS/8.5
VTag: 438589357000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 550
Cache-Control: max-age=900
Date: Wed, 11 Feb 2015 05:40:40 GMT
Connection: keep-alive0.."0......0...*.H........0w1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1!0...U....Microsoft Time-St
amp PCA..141218221600Z..150319103600Z._0]0...U.#..0...#[email protected].. .
.5..0... .....7.......0...U......10... .....7......150318222600Z0...*.
H............./..0Q~.r.}.E....&\....F.Z.C..#..F.s........<&\..9G..-
....j..N... .C.Fk....;l.....2.K5D.........-.>...(...g.0.S.[?...T4q&
gt;[email protected].('..e...Y..Bo..q..........I....'....i>
..y:.eH@h`..\...UA.m#.~.. ;.3..d..;..<..........p..s..J..N `Az.....
[email protected]..
GET /rpc/sendspminstall?partner=BZDV_PCSM_ML_PCUP_OPTIMIZERPRO_YELLOW&build=3.2 HTTP/1.1
Host: service.smartpcupdate.com
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Wed, 11 Feb 2015 05:37:29 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.3.1412..{"ok":1,"error":0}..0..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ/xkCfyHfJr7GQ6M658NRZ4SHo/AQUCPVR6Pv+PT1kNnxoz1t4qN+5xTcCEGC2x6sSmevembHfY1acIZk= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1697
content-transfer-encoding: binary
Cache-Control: max-age=570158, public, no-transform, must-revalidate
Last-Modified: Tue, 10 Feb 2015 20:04:39 GMT
Expires: Tue, 17 Feb 2015 20:04:39 GMT
Date: Wed, 11 Feb 2015 05:42:01 GMT
Connection: keep-alive0..........0..... .....0......0...0...A0?1=0;..U...4VeriSign Class 3 C
ode Signing 2004 CA OCSP Responder..20150210200439Z0s0q0I0... ........
[email protected].!......Q...==d6|h.[x....7..`..........cV.!.....201502
10200439Z....20150217200439Z0...*.H...............U.#..&1x1.......n...
tJ...-..`.-d...X.......\._......[]n\].;....n..}b..Y...b1.q....".2.<
.../..:....\..... ..?...Y. .EF.e....Y!T#SLa.......&....I.t..v...Cy'uGK
...g......-.........G>}q......1....p...pxP,.l.e^f5..i)xoE....]....t
..?.....~..Su......D.,...\........0...0...0..{.........[..I|.....Zm..0
...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....Veri
Sign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/
rpa (c)041.0,..U...%VeriSign Class 3 Code Signing 2004 CA0...140428000
000Z..150729235959Z0?1=0;..U...4VeriSign Class 3 Code Signing 2004 CA
OCSP Responder0.."0...*.H.............0.........Y....h..@..>.....%.
-.....O...' y.........x..Gw.xF.....?..Z..u,.X.&..........3C..H.l.....f
..;]s!.\"v...|....][email protected]. ..W....n..*
..-f?EY.......UN...r...........-_.%..,P;b.....)(.P.4...,.%....<..6.
....[r^X.EV..S...5#'Y.. .TD...........0...0...U.......0.0...U.%..0...
.......0...U...........0... .....0......0f..U. ._0]0[..`.H...E....0L0#
.. .........hXXps://d.symcb.com/cps0%.. .......0...hXXps://d.symcb.com
/rpa0!..U....0...0.1.0...U....TGV-B-1080...U......"...?....`>q..i1o
...0...U.#..0.....Q...==d6|h.[x....70...*.H.............B8@.$..wo.....
.E.....P52"b*@'C\.y.(...n....h.f..7f.....v...pb<...]..|........<<< skipped >>>
GET /t/op?sid=111000501-UA-002&dt=1423640247&gid=B1191E57-169A-0822-2D09-59A9561F88E3&tz=2&ln=1&lc=0&bis=1&bief=0&biefx=0&bif=0&os=106&f=270730756 HTTP/1.1
Content-Type: text/html
Host: bi.secure-download.net
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Wed, 11 Feb 2015 05:37:28 GMT
Content-Type: application/octet-stream
Content-Length: 0
Connection: keep-alive
content-type: text/html
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab?8e8d43eb436062e2 HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Wed, 12 Mar 2014 20:20:10 GMT
If-None-Match: "0b96c77303ecf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/octet-stream
Last-Modified: Fri, 23 Jan 2015 02:29:11 GMT
Accept-Ranges: bytes
ETag: "803565fb436d01:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 57591
Date: Wed, 11 Feb 2015 05:41:16 GMT
Connection: keep-aliveMSCF............,...................I.................6Fm. .authroot.s
tl......8..CK...<T...g.v!M.d..f.%d..}K..5......dM*K..J.,%K"...!..=.
k..........{=/....{g.~...............'....6..N....w......(.$.>.7...
........'.....`.bx....^..$.'.^.K.C......<[email protected]
.....usXq.d.i.jF$.4.........KI.Q........A2m:..E.P|...(.^p..=G|.....m..
.... .6...H.e.....X'...%$r.Y.(..)........|...;...V^r.VM.._*X.I. ..4..
...*.....Y..`.0w.u...c.i.[..-...x..<.8.<.p..,..y.[v.Yn`......!.s
...4e......B...$.,..........w.Pd.)....,..#.%..h...8...`.A...8.i(.!.$/.
=.....i.\X.H......"...a...k...y6....F.._?\*.&..3.AJo.!..`....9....=.p.
u..u....f.f....w...?..S..I.;.....5._...F.f..G?$......."..kq.y'.6tJ.e%.
.G.n.....z<.pX"....1..g."........V:.H.-...!}LM..t..-.y.j&...n{..-.]
H. .....A.O.Xg..B...#[email protected]..*.....T...}o._./S..h@$
[email protected]..#.:?."....1..v.....&G...?O1x6"5.@..$.U...n.J...w
.Y.{..........E.N.&...&.rC..W.....M.........,.e.....&eI(/eSO.B..K...R.
[email protected].....(..Y./;-..M5.0.H2.y....:...........a.U....%.S.).^.
...1.B..a..=...q...X .B....F.../..../.Z...'..t....C....,.^...N=..t%N|I
C.#.)6...q.E.J.i.E.>....".L........>...Vy.7.jxx......G........._
q.1^..H&.4Z......^.E.K 9.Xg...qO.6%>..T....;n..s.'u.-...=.........p
..p.Rn.........=.......F........d. d.AR.0U..........9b...=N..#....c.Ic
z......u.0............Y.q..b.wYE.......R...s..W....r].....hT....k.g..[
...s.....X..`=zb.>..../..=........J.N.h...(}.5.7. .;..=F..F...'.?..
2...3...=...B..`....{...f.`Kb..@..`Z.0!^8.t..<l.j..lI.P.q.>k<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSOJaE2H4hHYQzP74hlLuO41NG+EAQUHsWxLH2H2gJofCW8DAeEP7bP3vECEETiV2tweIHKNF6KMhnt3r4= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 11 Feb 2015 05:42:37 GMT
Server: Apache/2.2.22 (Debian)
Last-Modified: Tue, 10 Feb 2015 09:22:17 GMT
Expires: Sat, 14 Feb 2015 09:22:17 GMT
ETag: 68D02881982AD5FFBF43190B721
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRtl6lMY2+iPob4twryIF+FfgUdvwQUK8NGq7oOyWUqRtF5R8Ri4uHa/LgCEBBwnU/1VAjXMGAB2OqRdbs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.usertrust.com
HTTP/1.1 200 OK
Date: Wed, 11 Feb 2015 05:42:31 GMT
Server: Apache/2.2.22 (Debian)
Last-Modified: Mon, 09 Feb 2015 18:46:20 GMT
Expires: Fri, 13 Feb 2015 18:46:20 GMT
ETag: 01062FBB3D0546CB913A2AA747FBA98E2C378255
Cache-Control: max-age=219228,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: h6edcaocsp1
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0...... .F....e*F.yG.b.......2015020
9184620Z0s0q0I0... ........m..Lco.>..... _.~..... .F....e*F.yG.b...
.....p.O.T..0`....u.....20150209184620Z....20150213184620Z0...*.H.....
........%...........FZ...%........./b..=.P."_.1.....p..J.S.}Q...<t.
.MF.......Z..M....!....D.}...z....Y..H.3.t?.a.Q`H.....`\..f....q.3.W6.
..|.....g..b.Nu..a....w.".....".m.y..... P.f....1y..>)`..)..O..l..&
gt;..N...z...Q.KX......e;[vb..3.H.`..f....rt.P5.O.4%...Z......\..
GET /inst?hid=f9fa0c8af68693bc10e76c7b051b0f2683651245&sid=BA0B5C4A-F59C-42DE-8C19-81CA43A780D4&tr=111000501-UA-002&adm=1&os=6.1&x64=1&sil=0&e=600 HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: pcup-optimizerpro.com
HTTP/1.1 200 OK
Date: Wed, 11 Feb 2015 05:39:53 GMT
Content-Type: text/plain
Content-Length: 0
Connection: keep-alive
Set-Cookie: __cfduid=d336e9b6d61594d5a2e5dc891b9eb15a81423633193; expires=Thu, 11-Feb-16 05:39:53 GMT; path=/; domain=.pcup-optimizerpro.com; HttpOnly
Server: cloudflare-nginx
CF-RAY: 1b6e356237080afc-WAWHTTP/1.1 200 OK..Date: Wed, 11 Feb 2015 05:39:53 GMT..Content-Type: te
xt/plain..Content-Length: 0..Connection: keep-alive..Set-Cookie: __cfd
uid=d336e9b6d61594d5a2e5dc891b9eb15a81423633193; expires=Thu, 11-Feb-1
6 05:39:53 GMT; path=/; domain=.pcup-optimizerpro.com; HttpOnly..Serve
r: cloudflare-nginx..CF-RAY: 1b6e356237080afc-WAW..
GET /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b1ccd395ee99a9dc HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 05 Dec 2013 22:47:50 GMT
If-None-Match: "0af536cf2ce1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ctldl.windowsupdate.com
HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Length: 6408
Content-Type: application/octet-stream
Last-Modified: Thu, 03 Jul 2014 23:34:12 GMT
Accept-Ranges: bytes
ETag: "0b2464b1797cf1:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
X-Powered-By: ARR/2.5
X-Powered-By: ASP.NET
Date: Wed, 11 Feb 2015 05:40:23 GMT
Connection: keep-aliveMSCF............,...................O.......'#.........D.z .disallowed
cert.stl....2..'#CK...8T...g........g.k..".....mlI."d..m...P$"....e.J.
.......z.....\..........9g.9....~.........Q.Q......Q..DL.8.C.PS.K0.!P.
0........#.DY.8.....V.....$.C....a.0...........`......;.S.....0#...m..
. ..`0...?.!vR?.....d....`......_@..}....$...i..OR'..$....K..'Z....o.g
..*.Vc.....[nY e./.EJ...B.Y.......Ag......!....9......u..!..1Yy.......
r...Ss^@...M.Dtl\....i.k....3...B.Z.:.p.N....*......x,...ah/..].[....G
B..T..$A....SY..t.E5R..R...9!....*.*68V....1... ...Q{..."[email protected];
xd{.C.u?..e.U.=f.nx.........y.G..0.......\L .'.^....$......N=..m...Ujr
Zs...J.I.C....;......q_..e......?.T..2..bw....E.L.{...S...~.<......
...-.Q..|.l. .1..6r....[}!J..,...naPk.U.... ..{@LH..W....>.Sq...8.5
.,.z..0.jL.S..........]...yW_...Y.1..h.7...9{.....I......g.Y.,1...i8n.
6..........4.]...........=........^..n.K7...c.g).Z. .0..$7.ys.p...B.5.
].f...|(3!.|..P...j..^..j....#([email protected]..*.O..i..u....9..S.Y.n..HXW..
.F ..i...:.......!.] r......D..*ld.b.>>:Pp.....5:1 o=..5.'..4...
....hO....{.V.rx..V...%.}..u...6Wv-..".iV.b..B0.Q..,...E.Dy...x..5....
?Z.$L..1.....4...=.....g!....%..:..c..j..v~....._R.6.......;.#.Y*p..J.
4.#'..Vo...g^K...J....._.^..u...)....&/.....q....o......4.....S...,q..
...p.8IIe.....d|.3{)...M.0.X...4.."..P.......Hk.... ]!.!... ..#.x..<
;..X.........'.E(<b[.......#.. ....XiLl|[email protected]
[email protected][email protected]..;.......mm....>~............j%..>
;.X.,V...J...C ....*..Z.8- RKGW...0./Z.__..)7g_'{.......pr......;.<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEEIa8pQJhBkfUgpLxiQmp0s= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.usertrust.com
HTTP/1.1 200 OK
Date: Wed, 11 Feb 2015 05:42:26 GMT
Server: Apache/2.2.22 (Debian)
Last-Modified: Tue, 10 Feb 2015 17:46:20 GMT
Expires: Sat, 14 Feb 2015 17:46:20 GMT
ETag: 53F5EBDA8988DE8E4B0FFF48216C580C0AB941B5
Cache-Control: max-age=302033,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: h6edcaocsp1
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2015021
0174620Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.B.......R.K.$&.K....20150210174620Z....20150214174620Z0...*.H........
.....h.....d...[...:...}Z.........U..a...."..[........ks8....p.....~~n
....., ..X...us.......&d.R..}f..u..V.{.}.>....L...C..y...G..Joxv.i.
....27.D.M....JZm..B.`...K....G.,.d..S@h,.m........,S.p..pd^.m.b...&F3
e|?....v..>."....X%U.-...!.k.6..c\).N."....o.(......R...
GET /pca3.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.verisign.com
HTTP/1.1 200 OK
Server: Apache
ETag: "66304c4a5660ab8615727e6bb27b3cdb:1418950819"
Last-Modified: Fri, 19 Dec 2014 01:00:19 GMT
Date: Wed, 11 Feb 2015 05:41:55 GMT
Content-Length: 933
Connection: keep-alive
Content-Type: application/pkix-crl0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc.1705..U
....Class 3 Public Primary Certification Authority..141210000000Z..150
331235959Z0..x0!...v....a_>..2......020924164823Z0!.....A.....{2..Y
.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!...`y..q.....
..fh...020923171400Z0!...?A....a.nF`.P....020923171548Z0!............R
.e.53..010207212458Z0!..!......Y...ISi....010706171411Z0!..$-..I{r....
u<._...080403172226Z0!..&.."?..y..51}..1..010706172118Z0!..4....2..
..{W......080605175030Z0!..B....c............070411175910Z0!..H.Py...N
....* [email protected]!..Y......w
`G........070411175657Z0!..Z`[email protected].*q..080403172017Z0!..l....I..
.Y..] .c..010706171749Z0"......T=deQ...1u.]...010207212247Z0".....p..1
..7<.....e..010207211822Z0...*.H............5..v...V.._)....A... ..
..>.5]....6.(.0uFW.*:T...6$.....R...Y.N.k........%Jn..I.j*.6.3~...r
../[email protected]?....0.A.HTTP/1.1 200 OK..Server: Apache.
.ETag: "66304c4a5660ab8615727e6bb27b3cdb:1418950819"..Last-Modified: F
ri, 19 Dec 2014 01:00:19 GMT..Date: Wed, 11 Feb 2015 05:41:55 GMT..Con
tent-Length: 933..Connection: keep-alive..Content-Type: application/pk
ix-crl..0...0...0...*.H........0_1.0...U....US1.0...U....VeriSign, Inc
.1705..U....Class 3 Public Primary Certification Authority..1412100000
00Z..150331235959Z0..x0!...v....a_>..2......020924164823Z0!.....A..
...{2..Y.#..140129175709Z0!...,.|.|...<...j ...080605174907Z0!...`y
..q.......fh...020923171400Z0!...?A....a.nF`.P....020923171548Z0!.<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECEGVSJuGyLhjhWQ8phawi51w= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1453
content-transfer-encoding: binary
Cache-Control: max-age=446400, public, no-transform, must-revalidate
Last-Modified: Mon, 9 Feb 2015 09:39:15 GMT
Expires: Mon, 16 Feb 2015 09:39:15 GMT
Date: Wed, 11 Feb 2015 05:41:44 GMT
Connection: keep-alive0..........0..... .....0......0...0......T3t.%..O.E..~..F.=....2015020
9093915Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._)..a.
.eR&.....Y.)..".\....20150209093915Z....20150216093915Z0...*.H........
.....~0...hO6...:&.O........D......Bnr.s.PL.....a.......|..]'[>...`
......I...P<I.$.T.....s..zF....... R...39...<.. J........~..{.g.
...W#..............|.r.l..<4.b.....er.kw.3.....P[.........Q.....Z?.
Sa.........6.F......8.{E.[......mQ/[email protected]."O.\....3.S.....0..
.0...0..3......./...b.v..-....l}0...*.H........0_1.0...U....US1.0...U.
...VeriSign, Inc.1705..U....Class 3 Public Primary Certification Autho
rity0...141202000000Z..151216235959Z0..1.0...U....US1.0...U....Symante
c Corporation1.0...U....Symantec Trust Network1?0=..U...6Symantec Clas
s 3 PCA - G1 OCSP Responder Certificate 30.."0...*.H.............0....
......'......Y..x.3B1.7..Q..`..d.. ....s..t.$a.....j2R.{ ,*..c{.3.....
H..3-; ).....0._...*..9M..V...... ...{m...-.......)..tR..{D....~...M..
.T..pS.p..^|o....S..v.).)[email protected]#qh...u1T.].G0.]
E...=._...... ........TE...Sa.s4........r...3.............0..0...U....
0.0l..U. .e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symauth.com/cps
0(.. .......0...hXXp://VVV.symauth.com/rpa0...U.%..0... .......0...U..
......0... .....0......0!..U....0...0.1.0...U....TGV-B-2730...*.H.....
........$..H......oU....Y!.z{*.V.M..u.._z..3>.. 0....3..m.....e....
...a..D...........e..F6:.y.....di.......<y.Z.......x}..q.2....UZ1 :
,....<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAxNF3PJUX7iAOhAP2oGxcI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=486260, public, no-transform, must-revalidate
Last-Modified: Mon, 9 Feb 2015 20:44:24 GMT
Expires: Mon, 16 Feb 2015 20:44:24 GMT
Date: Wed, 11 Feb 2015 05:41:49 GMT
Connection: keep-alive0..........0..... .....0......0...0........6?s....V....OlL".O..2015020
9204424Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
..M.s.Q~...@?j.......20150209204424Z....20150216204424Z0...*.H........
......2..T.U...=..C.V....Bo9..e..2.....S.'.#../Y].k.....n..1.8J\..PM.x
Y.P6H.....Q9...]...Z..d...Bl...!..7W.P*..-.a.-...q.f'k.d.Z...o.. D.q.8
w.!.:..8...C0.j.%V.#&.d..n..Q.,..kE.s...*....p..7....~..MI.LFE....e../
.....\..,Z.clG...v.R....Q....o.w..`...@^...%...K..,...#0...0...0......
....<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U....VeriS
ign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at h
ttps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Sign
ing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US1.0...U..
..VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of u
se at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Class 3
Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.........{
(..t....2.Vf.....&;6).i*[email protected]._p.E.6.|.mk....(.......
...p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..JA..~QG.d.}..
.r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h<.l....(n.
.i.....E.....2....^./Y......Y.m...'...hz..y..E..........0...0...U....0
.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisign.c
om/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp. by
reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U........
0... .....0......0"..U....0...0.1.0...U....TGV-B-24710...*.H......<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEEES5jLHsYoCmjofrIA6uJ8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=592945, public, no-transform, must-revalidate
Last-Modified: Wed, 11 Feb 2015 02:24:43 GMT
Expires: Wed, 18 Feb 2015 02:24:43 GMT
Date: Wed, 11 Feb 2015 05:42:18 GMT
Connection: keep-alive0..........0..... .....0......0...0........6?s....V....OlL".O..2015021
1022443Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
.A..2.....:...:......20150211022443Z....20150218022443Z0...*.H........
.....<..|~!....'s.bW....e4x...VTE.L.....m.v.4-...2:,7.2oY../....~.L
......Ty.P<...*kV........0.0...X......<....XWn0=2;~%./..s...bw..
............"[email protected]....%.....M.3.<.6...)..g%
.Q..B).[[email protected]"..A.U...p. X.OXh.R.4.... ,N..........#0..
.0...0..........<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0.
..U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms
of use at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class
3 Code Signing 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U...
.US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U..
.2Terms of use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3Veri
Sign Class 3 Code Signing 2009-2 OCSP Responder0.."0...*.H............
.0.........{(..t....2.Vf.....&;6).i*[email protected]._p.E.6.|.mk
....(..........p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..J
A..~QG.d.}...r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h&
lt;.l....(n..i.....E.....2....^./Y......Y.m...'...hz..y..E..........0.
..0...U....0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://ww
w.verisign.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CP
S incorp. by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0
...U........0... .....0......0"..U....0...0.1.0...U....TGV-B-24710<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEGwkCSV07gf3g5QOsqmf+MY= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1790
content-transfer-encoding: binary
Cache-Control: max-age=486353, public, no-transform, must-revalidate
Last-Modified: Mon, 9 Feb 2015 20:44:25 GMT
Expires: Mon, 16 Feb 2015 20:44:25 GMT
Date: Wed, 11 Feb 2015 05:42:08 GMT
Connection: keep-alive0..........0..... .....0......0...0........6?s....V....OlL".O..2015020
9204425Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
.l$.%t...............20150209204425Z....20150216204425Z0...*.H........
......'.^.M......_.(.~....b^:.[&...z.^.W.<'g.[..N..Y.k...i....U.Kc-
.:B....]#...l.^..S0K.OV.. ..D/&.E?./...~.z....~.E.YA....c.4...~.t.$..X
[email protected]......... .^.....7.t...*T.=1.3..I...n..m.i9.6l.....
!..r..;..8..V...._......t..YE.^9.7...*&_.a......dM.......#0...0...0...
.......<o&S.-S..}...e.30...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use a
t hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code S
igning 2009-2 CA0...141205000000Z..150305235959Z0..1.0...U....US1.0...
U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms o
f use at hXXps://VVV.verisign.com/rpa (c)091<0:..U...3VeriSign Clas
s 3 Code Signing 2009-2 OCSP Responder0.."0...*.H.............0.......
..{(..t....2.Vf.....&;6).i*[email protected]._p.E.6.|.mk....(....
......p...........X.DF....^0N....b9.:..J. ZK.".^..\..p.'.$..JA..~QG.d.
}...r...gv... f...z.#..}..J...r9h.........LI-..^.......PUD.h<.l....
(n..i.....E.....2....^./Y......Y.m...'...hz..y..E..........0...0...U..
..0.0....U. ...0..0....`.H...E....0..0(.. .........hXXps://VVV.verisig
n.com/CPS0b.. .......0V0...VeriSign, Inc.0.....=VeriSign's CPS incorp.
by reference liab. ltd. (c)97 VeriSign0...U.%..0... .......0...U.....
...0... .....0......0"..U....0...0.1.0...U....TGV-B-24710...*.H...<<< skipped >>>
GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 01 Jul 2014 05:04:34 GMT
If-None-Match: "924558f3e994cf1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com
HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Wed, 28 Jan 2015 06:05:55 GMT
Accept-Ranges: bytes
ETag: "75565c7ac03ad01:0"
Server: Microsoft-IIS/8.0
VTag: 791863242700000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Wed, 11 Feb 2015 05:41:10 GMT
Connection: keep-alive0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Si
gning PCA..150127173215Z..150428055215Z.a0_0...U.#..0..........X..7.3.
..L...0... .....7.........0...U......Y0... .....7......150427174215Z0.
..*.H......................YIw.. ..(..y..O.G].B.."?.@...[1.}.X...]...e
.J....pP.I....!6...%.D.k...>c.|R.?.i..yt.z..B.........b....n..m5...
0....2..I!)v....z....y.#pXz.DO.....mF...e.'e...@.%...6./.bPZ...=....bp
[email protected]..@.. ...M....z....Q...{u. .W..HTT
P/1.1 200 OK..Content-Type: application/pkix-crl..Last-Modified: Wed,
28 Jan 2015 06:05:55 GMT..Accept-Ranges: bytes..ETag: "75565c7ac03ad01
:0"..Server: Microsoft-IIS/8.0..VTag: 791863242700000000..P3P: CP="ALL
IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT
COM INT NAV ONL PHY PRE PUR UNI"..X-Powered-By: ASP.NET..Content-Leng
th: 554..Cache-Control: max-age=900..Date: Wed, 11 Feb 2015 05:41:10 G
MT..Connection: keep-alive..0..&0......0...*.H........0y1.0...U....US1
.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation
1#0!..U....Microsoft Code Signing PCA..150127173215Z..150428055215Z.a0
_0...U.#..0..........X..7.3...L...0... .....7.........0...U......Y0...
.....7......150427174215Z0...*.H......................YIw.. ..(..y..O
.G].B.."?.@...[1.}.X...]...e.J....pP.I....!6...%.D.k...>c.|R.?.i..y
t.z..B.........b....n..m5...0....2..I!)v....z....y.#pXz.DO.....mF...e.
'e...@.%...6./[email protected]..<<< skipped >>>
The Worm connects to the servers at the folowing location(s):
.idata
.edata
P.tls
.rdata
P.reloc
P.rsrc
kernel32.dll
Windows
HKEY
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
;!199{199;0!8&2{199"<;=!!%{199Windows 95
Windows 95 OSR-2
Windows 98
Windows 98 SE
Windows ME
Windows 9x New
Windows NT 3
Windows NT 4
Windows 2000
Windows XP
Windows 2003
Windows Vista
Windows 2008
Windows 7
Windows 2008 R2
Windows 8
Windows Server 8
Windows NT New
user.exe
TMsgHandlers
madToolsMsgHandlerWindow
user32.dll
>0';0974&0{199cmovÌ
setÌ
pop %seg
push %seg
Uh.GA
msvcrt.dll
Uh.wA
VVV.madshi.net
dbghelp.dll
comctl32.dll
4.0.10
ntdll.dll
advapi32.dll
The import table is invalid.
shell32.dll
WindowsLogo
ReportLeaks
UploadViaHttp
HttpServer
HttpSsl
HttpPort
HttpAccount
HttpPassword
BugTrPassword
MailAsSmtpServer
MailAsSmtpClient
SmtpServer
SmtpSsl
SmtpTls
SmtpPort
SmtpAccount
SmtpPassword
bugreport.mbr
screenshot.png
ExceptMsg
FrozenMsg
BitFaultMsg
send bug report
save bug report
print bug report
show bug report
%appname%, %exceptMsg%
bug report
please find the bug report attached
Sending bug report...
PrepAttMsg
MxLookMsg
ConnMsg
SendMailMsg
FieldMsg
SendAttMsg
SendFinalMsg
SendFailMsg
Sorry, sending the bug report didn't work.
TDABugReportCallback
TDABugReportCallbackOO
ShellExecuteExW
madExceptIde_.bpl
wininet.dll
VVV.google.com
SMTP:
mapi32.dll
IpHlpApi.dll
A.ROOT-SERVERS.NET
K.ROOT-SERVERS.NET
VVV.madshi.net_multipart_boundary
TSmtpU
LOGIN
AUTH LOGIN
security.dll
secur32.dll
TWinHttp
winhttp.dll
WinHttpOpen
WinHttpConnect
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryAuthSchemes
WinHttpSetCredentials
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCloseHandle
/api.xml
<url>
password
?cmd=
/xmlrpc.cgi
Bugzilla.version
Product.get_enterable_products
Product.get
Bug.fields
Bugzilla_login
Bugzilla_password
Bug.create
Bug.add_attachment
/api/soap/mantisconnect.php
<?xml version="1.0" encoding="UTF-8"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="hXXp://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><ns1:
</username><password xsi:type="xsd:string">
</password>
*.txt
TSendBugReportExRec
wtsapi32.dll
idapi32.dll
kernelbase.dll
madExcept32.dll
c:\sources\madshi\madExcept32.dll
ReportLeaksNow
GetLeakReport
ShowLeakReport
madExcept32.dll has the wrong version.
coreide70.bpl
ReportFault
FaultRep.dll
internal error. please notify [email protected]
@System@@StartExe$qqrp23System@PackageInfoTablep17System@TLibModule
HardWareKey
setupapi.dll
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s[%d]
%s_%d
.Owner
EInvalidGraphicOperation
Uh.xH
USER32.DLL
uxtheme.dll
PasswordChar
OnKeyDown4RJ
OnKeyPress
OnKeyUp
ssHorizontal
Proportional
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")JumpID("","%s")TKeyEvent
TKeyPressEvent
HelpKeyword`}G
crSQLWait
%s (%s)
imm32.dll
OnExecute
HelpKeyword|}G
AutoHotkeys
AutoHotkeys(
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
tagMSG
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
WS2_32.DLL
127.0.0.1
TIdSocketListWindows
TIdStackWindowsU
IdStackWindows
%s, %.2d %s %.4d %s %s
%s, %d %s %d %s %s
Password
IdHTTPHeaderInfo
ProxyPasswordl
ProxyPort
Mozilla/3.0 (compatible; Indy Library)
ftpTransfer
ftpReady
ftpAborted
ClientPortMinl
ClientPortMax
PortH
EIdCanNotBindPortInRange
EIdInvalidPortRangeSVW
libeay32.dll
ssleay32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_CTX_get_current_cert
des_set_key
saUsernamePassword
Passwordl
Port
0.0.0.1
TIdTCPConnection
TIdTCPConnectionl
IdTCPConnection
EIdTCPConnectionError
sslvrfFailIfNoPeerCert
TPasswordEvent
Certificate
RootCertFile VF
CertFile VF
KeyFiled
OnGetPassword
EIdOSSLLoadingRootCertError0
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
TIdTCPClient
IdTCPClient
BoundPort
PortU
CommentURL
TIdHTTPMethod
IdHTTP
TIdHTTPOption
TIdHTTPOptions
TIdHTTPProtocolVersion
TIdHTTPOnHeadersAvailable
TIdHTTPOnRedirectEvent
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPProtocol
TIdCustomHTTP
TIdHTTP
HTTPOptions
EIdHTTPProtocolException
HTTPS
https
This request method is supported in HTTP 1.1
HTTP/1.0 200 OK
HTTP/
1.2.3
Portable Network Graphics
%s, ClassID: %s
ole32.dll
TNT Internal Error: TWideComponentHelper.Create should never be encountered.
D:\SmartPC\Components\Delphi Unicode Controls\Source\TntClasses.pas
!"#$%&*;<=>@[]^_`{|}D:\SmartPC\Components\Delphi Unicode Controls\Source\TntControls.pas
Internal Error: SubClassUnicodeControl.Control is not Unicode.
.UnicodeClass
TntUnicodeVcl.DestroyWindow
MAPI32.DLL
vsReport
OnKeyUp`UJ
TComboBoxExEnumerator
Uh.XQ
D:\SmartPC\Components\Delphi Unicode Controls\Source\TntActnList.pas
D:\SmartPC\Components\Delphi Unicode Controls\Source\TntStdCtrls.pas
D:\SmartPC\Components\Delphi Unicode Controls\Source\TntForms.pas
D:\SmartPC\Components\Delphi Unicode Controls\Source\TntMenus.pas
Internal Error: SyncHotKeyPosition Failed ("%s" <> "%s").driverpro.exe
Driver Pro\DriverPro.exe
hXXp://VVV.pcutilitiespro.com
UninstallURL
AdsDownloadURL
HomePageURL
SupportURL
BuyNowURL
AdsBuyNowURL
%Program Files% (x86)\Mozilla Firefox\firefox.exe
%Program Files%\Mozilla Firefox\firefox.exe
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
PathToExe
%Program Files% (x86)\Google\Chrome\Application\chrome.exe
%Program Files%\Google\Chrome\Application\chrome.exe
C:\Users\
\AppData\Local\Google\Chrome\Application\chrome.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
%Program Files% (x86)\Internet Explorer\iexplore.exe
%Program Files%\Internet Explorer\iexplore.exe
Software\Opera Software
\opera.exe
\launcher.exe
%Program Files% (x86)\Opera\Opera.exe
%Program Files%\Opera\Opera.exe
%Program Files% (x86)\Opera\launcher.exe
%Program Files%\Opera\launcher.exe
BrowserExe
%Program Files% (x86)\Safari\Safari.exe
%Program Files%\Safari\Safari.exe
http\shell\open\command
Launcher.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
SrClient.dll
1111111111
s_SmartExec
English.ini
French.ini
German.ini
Spanish.ini
Italian.ini
Portuguese.ini
Danish.ini
Dutch.ini
Swedish.ini
Polish.ini
Russian.ini
Brazilian.ini
Finnish.ini
Norwegian.ini
Turkish.ini
Czech.ini
Japanese.ini
Chinese.ini
Arabic.ini
\$RECYCLE.BIN\
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Mozilla\Firefox\
profiles.ini
\cookies.sqlite
\formhistory.sqlite
Google\Chrome\User Data\Default\Cache\
Content.IE5\
regedit.exe
%SYSTEMROOT%\
%Program Files%\
%Program Files% (x86)\
%COMMONPROGRAMFILES%\
%Program Files%\Common Files\
%COMMONPROGRAMFILES(X86)%\
%Program Files% (x86)\Common Files\
%COMMONPROGRAMW6432%\
%USERPROFILE%\
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
\tmp.reg" "
\tmp.reg
WNNC_NET_FTP_NFS
olepro32.dll
\\.\vwin32
shlwapi.dll
Mpr.dll
Uh|%S
D:\SmartPC\Components\EasyListview\Common Library\Source\MPShellUtilities.pas
To show a Context Menu using TNamespace you must pass a valid Owner TWinControl
THKeyArray
TCommonShellExecuteThreadU
D:\SmartPC\Components\EasyListview\Common Library\Source\MPThreadManager.pas
TCommonKeyState
cksShift
TCommonKeyStates
D:\SmartPC\Components\EasyListview\Common Library\Source\MPCommonUtilities.pas
gdi32.dll
Userenv.dll
ShellExecuteW
GetWindowsDirectoryW
RegOpenKeyW
RegOpenKeyExW
SHFileOperationW
D:\SmartPC\Components\EasyListview\Source\EasyListviewAccessible.pas
TEasyAccessibleManager.Create not a TCustomEasyListview type
TEasyGroupAccessibleManager.Create not a TEasyGroup type
TEasyItemAccessibleManager.Create not a TEasyItem type
TEasyColumnAccessibleManager.Create not a TEasyColumn type
TEasyHeaderAccessibleManager.Create not a TEasyHeader type
elsReport
elsReportThumb
TAutoGroupGetKeyEvent
TColumnGetImageIndexEvent
TColumnSetImageIndexEvent
KeyState
KeyStates
TGroupGetImageIndexEvent
TGroupSetImageIndexEvent
HintWindowShown
TItemGetGroupKeyEvent
GroupKey
TItemGetImageIndexEvent
TItemSetGroupKeyEvent
TItemSetImageIndexEvent
MouseMsg
TEasyKeyActionEvent
EscapeKeyPressed
TEasyViewReportItem`>U
TEasyViewReportItem
TEasyViewReportThumbItem
TEasyGridReportGroup
TEasyGridReportThumbGroup
TEasyCellSizeReport
TEasyCellSizeReportTeU
TEasyCellSizeReportThumb
TEasyCellSizeReportThumbtfU
ReportThumb\aU
Report
AlwaysShow
OnAutoGroupGetKey
OnItemGetGroupKey
OnItemSetGroupKey
OnKeyAction
D:\SmartPC\Components\EasyListview\Source\EasyListview.pas
Can not find TEasyGroups.AdjacentItem of an Invisible Item
Uh.uX
EasyListview.Header
TChangesShortForm
An updated version of %s is now available
FormKeyDown
\chrome.exe
\Internet Explorer\iexplore.exe
hXXp://softupdates.smartpcupdate.com/data/update-versions-%s.txt?upgrade_id=%s
\SOFTWARE\Microsoft\Windows\CurrentVersion\Settings\Optimizer Pro
&user_major_version=%s&upgrade_id=%s&user_version=%s
hXXp://softupdates.smartpcupdate.com/scripts/get_link_%s.php?license_key=%s&purchase_date=%s
You are already using the latest version of %s
OnActionExecutep\K
windows-1251
sqlite3.dll
sqlite3_bind_parameter_count
sqlite3_bind_parameter_name
sqlite3_busy_handler
sqlite3_busy_timeout
sqlite3_changes
sqlite3_close
sqlite3_collation_needed
sqlite3_collation_needed16
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_bytes16
sqlite3_column_count
sqlite3_column_double
sqlite3_column_int
sqlite3_column_int64
sqlite3_column_text
sqlite3_column_text16
sqlite3_column_type
sqlite3_column_decltype
sqlite3_column_decltype16
sqlite3_column_name
sqlite3_column_name16
sqlite3_complete
sqlite3_complete16
sqlite3_create_collation
sqlite3_create_collation16
sqlite3_data_count
sqlite3_errcode
sqlite3_errmsg
sqlite3_errmsg16
sqlite3_exec
sqlite3_finalize
sqlite3_free
sqlite3_get_table
sqlite3_free_table
sqlite3_interrupt
sqlite3_last_insert_rowid
sqlite3_open
sqlite3_open16
sqlite3_prepare
sqlite3_prepare16
sqlite3_reset
sqlite3_step
sqlite3_total_changes
sqlite3_libversion
Yahoo.Messenger\CLSID
Yahoo.Messenger.1\CLSID
Software\Microsoft\Windows Live\Messenger
Software\Microsoft\MSNMessenger\PerPassportSettings
imApp.im.loggingLogPath
TMonochromeLookup
The Windows registry stores settings and options for Microsoft Windows. Over time, the registry becomes cluttered with invalid and obsolete data.
%s can remove these unnecessary and invalid registry entries. Check the items you wish to delete and click Save && Close.
\UserExceptionR.txt
Free up disk space and protect your privacy by removing web pages, images, videos and audio files saved by your browser as you surf the Internet.
Free up valuable disk space and protect your privacy by removing cookies and the list of web pages you visited.
When you remove an application there are often residual files or junk files leftover on your system. %s safely finds and removes these unnecessary files.
\UserExceptionF.txt
Registry keys
RegistryKeys
\ProgramExceptionR.txt
\ProgramExceptionF.txt
IdHTTP1
HTTP1Work
Thank you for purchasing %s!
We are now replacing your current version of %s with %s which includes these additional features:
ProVersionUrl
hXXp://
service.smartpcupdate.com
hXXp://service.smartpcupdate.com/rpc/sendspmpurchase
hXXp://service.smartpcupdate.com/rpc/sendpurchase
&key=
hXXp://service.smartpcupdate.com/rpc/sendspminstall
hXXp://service.smartpcupdate.com/rpc/sendspmuninstall
hXXp://service.smartpcupdate.com/rpc/sendinstall
hXXp://service.smartpcupdate.com/rpc/senduninstall
callbanner.png
BannerURL
Do you have a License Key?
If you purchased %s a license key will have been emailed to you. Please enter the license key below and click Activate Now.
License key
Do you need a License Key?
We recommend that you upgrade to the full version of %s
To purchase %s and obtain a license key click
Licensing key has reached its usage limit!
UserKey
Thank you for registering %s!
Support
Register %s
To optimize settings, fix problems and speed up your PC you need to register %s.
Would you like to register %s now?
To immediately fix these problems and speed up your PC you need to register %s.
To remove these privacy risks from your computer you need to register %s.
To immediately fix these problems and to remove invalid shortcuts you need to register %s
To immediately fix these problems and to remove programs from your startup menu you need to register %s.
%s is the leading and award-winning system optimization tool that cleans, repairs and optimizes your system.
To fix problems and speed up your PC, you need to register %s
This is normal and we have marked these items and will attempt to remove them later. It is best to close as many applications (browser, instant messanger, email, etc.) before running %s.
Specify registry key
SpecifyKey
Example: Software\%s
KeyExample
Key not found in the registry!
KeyNotFound
Offers direct access to key features
Guard.exe
Reminder.exe
s_Exec
Schedule.exe
SmartScan.exe
Example: twitter.com
\CookiesException.txt
PSAPI.dll
The startup menu contains programs that are automatically started by Windows every time you start your PC. As more and more programs insert themselves in your startup menu your PCs valuable resources are drained causing it to operate more slowly.
\StartupList.txt
*.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
\*.lnk
hXXp://VVV.google.com/search?hl=en&q=
hkey
d1.smartpcupdate.com
hXXp://d1.smartpcupdate.com/startup/set_deleted.php?names=
FormOptReport
Optimization Report
CleanEmptyKeys
ScanCustomRegKeys
ScanWindowsLogs
actDebugExecute
Welcome to %s
%s's benefits may include faster performance, increased startup speed and fewer error messages when regularly used.
Why register %s?
Remove invalid and unnecessary items to optimize your Windows registry.
Search histories, cookies, recently viewed web pages, videos, photos, music and more.
%s has found the following potential privacy risks on your computer. To keep your information private and free up valuable disk space we recommend deleting the selected items.
Optimize your settings to improve your computer's speed, security and efficiency. Run an optimization report to check the current condition of your PC.
Optimization report
Windows tracking of user actions
Send error reports to Microsoft
Ask password after quitting standby mode
Automatic login to system w/o password entry
Use autofill for URLs
Autofill of login names and passwords in forms
Request for password save
Get the maximum benefit from %s by customizing the settings to meet your needs.
Undo changes made by %s
Information about your version of %s
If there are certain registry keys, files or cookies that you do not want to have included in the %s scan you can use this feature to create an exclusion list.
Log && Undo makes it easy to undo changes made by %s
List of items that could not to be cleaned because they were locked or in use by another application. %s will attempt to remove these items each time you clean your PC.
IEXPLORE.EXE
FIREFOX.EXE
CHROME.EXE
SKYPE.EXE
\PendingExceptionR.txt
\PendingExceptionF.txt
\Scan.gif
SOFTWARE\Microsoft\Windows\Help
SOFTWARE\Microsoft\Windows\HTML Help
SOFTWARE\Microsoft\Windows\CurrentVersion\Fonts
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\
SOFTWARE\Microsoft\Internet Explorer\TypedURLs\
SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Regedit\
SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List\
SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List\
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\
\places.sqlite
visited Web pages and cookies available for removal
.reg"
Cleaning visited webpages...
macromedia.com\support\flashplayer\sys\
Visited Web pages removed
System32\reg.exe
File Windows\System32\reg.exe not found!
\HKCR.reg
\HKCU.reg
\HKLM.reg
\HKU.reg
EXPORT HKCR "
\HKCR.reg"
EXPORT HKCU "
\HKCU.reg"
EXPORT HKLM "
\HKLM.reg"
EXPORT HKU "
\HKU.reg"
\*.reg
IMPORT "
dfrg.msc
DFRGUI.EXE
dfrgui.exe
DATA.BAK
CUSTOM.BAK
OPA11.BAK
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer
DoReport
SOFTWARE\Microsoft\PCHealth\ErrorReporting
PromptPasswordOnResume
SOFTWARE\Policies\Microsoft\Windows\System\Power
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
FormSuggest Passwords
Register your copy of %s
\*.log
OptimizerPro.reg
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
=HKEY_LOCAL_MACHINE#
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#
=HKEY_CLASSES_ROOT#
[-HKEY_CLASSES_ROOT\Applications\
Empty key
EmptyKey
[-HKEY_CLASSES_ROOT\
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\
=HKEY_CURRENT_USER#
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\
HKEY_CLASSES_ROOT\
[-HKEY_CLASSES_ROOT\CLSID\
[HKEY_CLASSES_ROOT\CLSID\
HKEY_LOCAL_MACHINE\
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\
HKEY_CLASSES_ROOT\Interface\
[-HKEY_CLASSES_ROOT\Interface\
HKEY_CLASSES_ROOT\Typelib\
[-HKEY_CLASSES_ROOT\Typelib\
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs
Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\
: HKEY_CURRENT_USER\
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
: HKEY_LOCAL_MACHINE\
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache
SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders#
[HKEY_LOCAL_MACHINE\
AppEvents\Schemes\Apps\.Default
AppEvents\Schemes\Apps\.Default\
\.Current
\.Default
[-HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\
[HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\
\.Current]
\.Default]
HKEY_CURRENT_USER\
[HKEY_CURRENT_USER\
=HKEY_CURRENT_USER#SOFTWARE\
HKEY_CURRENT_USER\SOFTWARE\
[-HKEY_CURRENT_USER\SOFTWARE\
=HKEY_LOCAL_MACHINE#SOFTWARE\
HKEY_LOCAL_MACHINE\SOFTWARE\
[-HKEY_LOCAL_MACHINE\SOFTWARE\
=HKEY_USERS\S-1-5-21-1060284298-1454471165-725345543-1004\SOFTWARE\
HKEY_USERS\...\SOFTWARE\
[-HKEY_USERS\S-1-5-21-1060284298-1454471165-725345543-1004\SOFTWARE\
=HKEY_USERS#
HKEY_USERS\
[HKEY_USERS\
LOGIN
.EXE.DLL.SYS.CAB.MSI.DAT.INF.TLB.BIN.OCX.INI.XML.LOG
*.lo?
INDEX.DAT
/eula.php
/privacy.php
c:\debug.pc
Start.exe
6666666666666666
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
?456789:;<=
!"#$%&'()* ,-./0123
:\Program Files (x86)\Internet Explorer\iexplore.exe
e.exe
GetKeyboardType
RegOpenKeyExA
RegCloseKey
RegQueryInfoKeyA
RegFlushKey
RegEnumKeyA
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExW
RegCreateKeyExA
GetWindowsDirectoryA
GetCPInfo
CreatePipe
version.dll
SetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExW
SetWindowsHookExA
MsgWaitForMultipleObjects
MapVirtualKeyW
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextW
GetKeyNameTextA
GetAsyncKeyState
EnumWindows
EnumThreadWindows
ActivateKeyboardLayout
ShellExecuteExA
ShellExecuteA
SHFileOperationA
comdlg32.dll
wsock32.dll
shfolder.dll
oleacc.dll
winmm.dll
Shell32.dll
MainProgram.exe
:5;{;3<]<; <=<_<|<
5Q5C5N5b5g5
2 2$2(2,20242
=#='= =/=
3o3
> >$>(>,>0>
5 5$5(5,5054585<5
2 2*242>2]2
5"6&62686
6"7&7*7.72787
7$8(80848
; <><`<{<2 2$2(2,2024282
1,2Q2
3 3$3(3,3034383<3@3
7-7C7O7W7a7j7t7}7
3044484
;(<,<0<4<8<
3X3c3%4S4@5
?&?1?@?{?:3;7;;;@;
0115191@1
23373;3@3
<!<)<-<1<5<<<
1 2$2(202
6!7%7)7-747
;.<2<6<:<@<
<.=2=6=@=
1*2.22262<2
4L4K4g4o4
5a6S7
;';1; =-=<=
3-4}4
55j5p5
0 0$0(0,020
4)42494>4
2#2?2]2}2
00Z0m0
4)40454{43$3)383[3
;#;/;6;;;
<#<(<4<;<@<
=#=/=6=;=
6$6-64696
2!2(2-2<2_2
1&1 1:1]1
< ===*>7>}>
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
33333333330
3333338
3333333330
3333833330
3333330
333333330
3333333333
338333?330
33383?3330
3833830
paint.net 4.0;
~.gG@
u-..nkk#
.wJzP
%s}L8
N%uNU%1
kP?%u
m.Se;z
2.Rb;
.vyI$''
:.nuv
YG.txD
.FCRR
* UUU%%%uuumm
hee%u
,*.*.
,-#33 ;;7
%&%SO
'%S?:B.B
pm%C\rlR
U.wqtt
.MgH3
1574674
,:$=73331
:.hf.V
7Dx.Dp
:!m.YW@0
%s`8&
C.zsSS
UuuUuU%UUEU
.dlv,>
.qj_qj]
m-9}h
}uWaeGAncrT
%'Åb
- ###==
/-)-...-- - --/ -
KWindows
UrlMon
UrlHistory
wlibsqlite3
TntWindows
0IdHTTPHeaderInfo
IdTCPServer
IdTCPStream
ÿff
?.EDHaaR@
7'447""'"" $$
[3&&& @^
).6>*!!$)6!6!-.
< .mll
$<","2<2*"*:2:&*&
6'%**<<<55
cg.Br
ChangesShortForm
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
Picture.Data
;A new version of %s (version %s) is available for download.
OnKeyDown
All windows
IconOptions.Arrangement
s%s's benefits may include faster performance, increased startup speed and fewer error messages when regularly used.
GRemove invalid and unnecessary items to optimize your Windows registry.
Windows tracking of user actions
(Ask password after quitting standby mode
,Automatic login to system w/o password entry
Optimize your settings to improve your computer's speed, security and efficiency. Run an optimization report to check the current condition of your PC.
3visited Web pages and cookies available for removal
%Scan selected areas for privacy risks
USearch histories, cookies, recently viewed web pages, videos, photos, music and more.
Windows .....
5Attention! %s found 0 privacy risks on your computer
When you remove an application there are often residual files or junk files leftover on your system. %s safely finds and removes these unnecessary files.
4Log && Undo makes it easy to undo changes made by %s
Lines.Strings
If there are certain registry keys or files that you do not want to have included in the %s scan you can use this feature to create an exclusion list.
.Autofill of login names and passwords in forms
OGet the maximum benefit from %s by customizing the settings to meet your needs.
$Information about your version of %s
Log files|*.log|All files|*.*
*.tmp
*.bak
*.old
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
Request.ContentLength
Request.ContentRangeEnd
Request.ContentRangeStart
Request.ContentType
Request.Accept
Request.BasicAuthentication
Request.UserAgent
&Mozilla/3.0 (compatible; Indy Library)
The Windows registry stores settings and options for Microsoft Windows. Overtime, the registry becomes cluttered with invalid and obsolete data.
m%s can help you clean and optimize your registry. Check the items you wish to delete and click Save && Close.
EditManager.Font.Charset
EditManager.Font.Color
EditManager.Font.Height
EditManager.Font.Name
EditManager.Font.Style
GroupFont.Charset
GroupFont.Color
GroupFont.Height
GroupFont.Name
GroupFont.Style
Header.Columns.Items
Header.Font.Charset
Header.Font.Color
Header.Font.Height
Header.Font.Name
Header.Font.Style
Header.Height
)PaintInfoGroup.MarginBottom.CaptionIndent
Selection.FullItemPaint
oFree up valuable disk space and protect your privacy by removing cookies and the list of web pages you visited
version %s
Support:
OTo immediately fix these problems and speed up your PC you need to register %s.
"Would you like to register %s now?
PTo optimize settings, fix problems and speed up your PC you need to register %s.
l%s is the leading and award winning system optimization tool that cleans, repairs and optimizes your system.
=To fix problems and speed up your PC, you need to register %s
{If you purchased %s a license key will have been emailed to you. Please enter the license key below and click Activate Now..To purchase %s and obtain a license key click
YCheck the email you received after you purchased the product for the correct license key.
&Your license key will look like this:
Thank you for purchasing PC %s!
eWe are now replacing your current version of %s with %s Pro which includes these additional features:
Items.Strings
All files|*.*
R* Monitor your PC's performance right from your desktop without having to start %s
&* Offers direct access to key features
pchelpsoft.com
<assemblyIdentity version="1.0.0.0"
name="OptimizerPro.exe"
<requestedExecutionLevel
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
.jdbg
madExcept.HandleContactForm
madExcept.HandleScreenshotForm
.madExcept
%exceptMsg%
%bugReport%
Úte%
Útetime%
%computerName%
Þsktop%
%userappdata%
%commonappdata%
screenShot.bmp
Tcpip\Parameters
VxD\MSTCP
.jpeg
hXXps://
%userappdata%\
BugReport
screenShot.png
operating system
<tr><td><button onClick="history.back();" style="height:19.5pt;">
<button onClick="document.getElementById('bugReport').style.visibility='visible';this.style.visibility='hidden';" style="height:19.5pt;"> <textarea id="bugReport" readonly cols="80" rows="20" style="width:100%;height:100%;
Software\Microsoft\Windows
GetThreadReport
GetCpuRegisters
\madExcept\Dlls\madExcept32.dll
psapi.dll
suser32.dll
Unspecified error (%d) from %s.
miranda32.exe
PIDLs to operate on are not siblings of the Namespace doing the operation.
Unable to find RegSvr32.exe executable.
RegSvr32.exe
*.dat
\msnmsgr.exe
\msgslang.dll
\msgslang.
Software\Microsoft\MSNMessenger\PerPassportSettings\
*.xml
*.html
\settings.xml
\config.xml
\main.db
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting]
"DoReport"=dword:00000001
"DoReport"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System\Power]
"PromptPasswordOnResume"=dword:00000001
"PromptPasswordOnResume"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall]
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions]
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete]
"FormSuggest Passwords"="YES"
"FormSuggest Passwords"="NO"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
66006666
FORMOPTREPORT
TCHANGESSHORTFORM
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design mode
Unsupported PixelFormat
Invalid stream operation
Unsupported GIF version7Invalid number of colors specified in Screen Descriptor6Invalid number of colors specified in Image Descriptor
Invalid extension introducerúiled to allocate memory for GIF DIB
Invalid Image trailerAInternal error: Extension Instance does not match Extension Label,Unsupported Application Extension block size
Unknown GIF block type'Object type not supported for operation
"%s"8
úiled to set maximum selection range$Failed to set calendar min/max rangeúiled to set calendar selected range
"%s".
"%s".%
oSome operation could not be performed because the system is out of resources. Close some windows and try again.OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
RichEdit line insertion error=This control requires version 4.70 or greater of COMCTL32.DLL
Date exceeds maximum of %s
Date is less than minimum of %s4You must be in ShowCheckbox mode to set to this date#Failed to set calendar date or time
jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.nThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.7The png image could not be loaded from the resource ID.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
SSL status: "%s"
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Command not supported.
Address type not supported.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Chunk StartedDThis authentication method is already registered with class name %s.
%s is not a valid service.
Socket Error # %d
%s is not a valid IP address.
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
No data to read.$Can not bind in port range (%d - %d)
Invalid Port Range (%d - %d)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
No help keyword specified.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Value must be between %d and %d
Unable to insert a line Clipboard does not support Icons
Text exceeds memo capacity/Menu '%s' is already being used by another form
$Unknown picture file extension (.%s)
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
?#''%s'' is not a valid date and time
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
3.2.0.0
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
unins000.exe:2044
%original file name%.exe:2492
OptProStart.exe:816
_iu14D2N.tmp:324
557cdbaefd0db67bb620699ced75c238.tmp:2312 - Delete the original Worm file.
- Delete or disinfect the following files created/modified by the Worm:
C:\Users\"%CurrentUserName%"\Documents\Optimizer Pro\CookiesException.txt (90 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_iu14D2N.tmp (7596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-D7C27.tmp\557cdbaefd0db67bb620699ced75c238.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-F5FV6.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-F5FV6.tmp\_isetup\_setup64.tmp (6 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-NEQP4.tmp (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\OptProHelper.dll (8020 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-KDJOK.tmp (32054 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-LT48B.tmp (712 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Check updates.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-U76OH.tmp (3073 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-C3JNF.tmp (1281 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\OptimizerPro.exe (291 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-006S0.tmp (25426 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-OMCM9.tmp (54 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\_isetup\_setup64.tmp (6 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-VMKQI.tmp (20 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-R5MDU.tmp (48 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-51OHT.tmp (3361 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-VLSN7.tmp (601 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\unins000.msg (646 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-PLMDG.tmp (7971 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-BR1TT.tmp (56 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Uninstall Optimizer Pro.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-965I1.tmp (673 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-MTLCD.tmp (65 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-2JH58.tmp (2321 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Help.lnk (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro on the Web.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-54C84.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\itdownload.dll (1489 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\unins000.dat (22397 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Optimizer Pro.lnk (1 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-C0UUH.tmp (898 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-NFLVM.tmp (22 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-UQLKK.tmp (601 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-0QERA.tmp (2321 bytes)
%Program Files% (x86)\Optimizer Pro 3.38\is-NALI7.tmp (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\is-8QA1C.tmp\_isetup\_shfoldr.dll (47 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2\Optimizer Pro.lnk (1 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Optimizer Pro" = "%Program Files% (x86)\Optimizer Pro 3.38\OptProLauncher.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.