Advertisement
Guest User

syschk.ocx

a guest
Oct 8th, 2010
950
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 19.22 KB | None | 0 0
  1. http://www.virustotal.com/file-scan/report.html?id=744fc36fcc5695cf028e97d3fa926cd3b0ae62c14c760b9d949f4a4ede9f9d0e-1286539021
  2.  
  3. File: syschk.ocx
  4. MD5: 16ba21c1eac48eb20c04ac91ef9c2bd1
  5. Size: 159744
  6.  
  7. Ascii Strings:
  8. ---------------------------------------------------------------------------
  9. !This program cannot be run in DOS mode.
  10. Rich
  11. .text
  12. `.rdata
  13. @.data
  14. .rsrc
  15. @.reloc
  16. L$ R
  17. t$(t
  18. L$(V
  19. PVQRh
  20. L$$P
  21. L$8h
  22. vU;l$,wO
  23. t$0j
  24. l$$;
  25. s|SU
  26. Jt;Ju>j
  27. L$(P3
  28. PVj!R
  29. T$(QR
  30. _^][
  31. _^]3
  32. D$ RP
  33. _^][
  34. t;Ht
  35. IQhd
  36. SUVW
  37. T$ j
  38. _^][
  39. IQhd
  40. _^]3
  41. D$ @
  42. _^][
  43. SUVW
  44. T$$Q
  45. _^]3
  46. D$P3
  47. |$QU
  48. |$Th
  49. L$XQ
  50. T$TQRP
  51. _^]3
  52. |$,P
  53. D$4P
  54. T$4RP
  55. D$<(
  56. D$0j
  57. PUQR
  58. _^]3
  59. _^]3
  60. L$$W
  61. t2VW
  62. IQhh
  63. IQhh
  64. _^[Y
  65. t-E;
  66. L$ Q
  67. D$ +
  68. _^][Y
  69. _^][Y
  70. _^][Y
  71. D$$f
  72. L$(f
  73. }#EA
  74. <(>u
  75. T$(j
  76. _^]2
  77. L$ j
  78. D$<_^]
  79. l$<C
  80. T$<_^]
  81. Ht#Hu
  82. PQUf
  83. SUV3
  84. _^][
  85. SQhH
  86. SRh8
  87. SPh0
  88. D$ RP
  89. A<;u
  90. SUVW
  91. |$ ;
  92. _^][
  93. DSVWh0
  94. L$dPj0Q
  95. Rj1P
  96. Qj2R
  97. Pj3Q
  98. Rj4P
  99. T$ Qj5R
  100. L$$Pj6Q
  101. D$(Rj7P
  102. T$,Qj8R
  103. L$0Pj9Q
  104. D$4RjAP
  105. T$8QjBR
  106. L$<PjCQ
  107. D$@RjDP
  108. T$DQjER
  109. L$HPjFQ
  110. _^[d
  111. >MZt
  112. ^JGQ
  113. QRWV
  114. ^_ZY
  115. QRWV
  116. ^_ZY
  117. wkernel32.dll
  118. \syschk.ocx
  119. shell32.dll
  120. ;|$(u
  121. ShnY
  122. u,Sh
  123. SUVW
  124. |$ ;
  125. _^][
  126. QSUVW
  127. >"u<
  128. <0"t
  129. <0"t
  130. L$$S
  131. <(\t
  132. <(\t
  133. ^][_
  134. SUVW
  135. |$0h
  136. L$$Pj
  137. T$(h
  138. L$(j
  139. T$,QR
  140. _^]3
  141. `SVW3
  142. PVVj
  143. T$<j
  144. D$ j
  145. L$ R
  146. VUSQ
  147. _^[d
  148. SUVW
  149. L$$j
  150. D$4j
  151. D$ hh
  152. _^][
  153. _^][
  154. QSVW`
  155. SVWh`
  156. D$,j
  157. L$4PQSR
  158. L$0j
  159. D$0j
  160. D$@h
  161. L$LQ
  162. IQh\
  163. D$@h
  164. L$Hh
  165. T$,h
  166. D$4P
  167. D$$j
  168. L$0PQSR
  169. L$,j
  170. D$,j
  171. UVW3
  172. L$,h
  173. D$,P
  174. L$,QR
  175. D$,RPSSQ
  176. D$#j
  177. T$ R
  178. \$ E;
  179. D$(h
  180. L$(PQSSR
  181. |$(P
  182. L$0P
  183. T$8QRUP
  184. T$(QPPP
  185. D$(RP
  186. D$ R
  187. L$4j
  188. _^[]
  189. Vu{j
  190. t[VWS
  191. ds4V
  192. UQRP
  193. QVh`
  194. VUUUW
  195. G<4r
  196. ][_^
  197. SUVW
  198. VUUU
  199. _^][
  200. _^][
  201. VUUU
  202. VUUU
  203. N<"t
  204. L$(Qj
  205. l$$j
  206. D$$+
  207. T$(R
  208. _^]d
  209. L$ Q
  210. T$0j
  211. L$<+
  212. D$,j
  213. L$8j
  214. D$$RPj
  215. L$xh`
  216. T$xQUR
  217. L$$PQj
  218. t4hx
  219. D$xh`
  220. L$xh`
  221. L$xh
  222. T$xh
  223. L$(R
  224. L$0PQQQQQ
  225. L$LQ
  226. D$\D
  227. _^][d
  228. SVWP
  229. D$Hj
  230. L$Tj
  231. D$#
  232. IQh\
  233. T$'j
  234. D$&f
  235. SVW3
  236. _^[d
  237. uiSV3
  238. ?j\W
  239. X_^]
  240. x,.u
  241. ;(rU
  242. VPVj0
  243. s$_r
  244. QSVW
  245. QQSVWd
  246. 4SVW
  247. PhYY
  248. X_^[]
  249. SVWUj
  250. ]_^[
  251. t.;t$$t(
  252. tzVS
  253. GIt%
  254. t/Ku
  255. t-9]
  256. _^[]
  257. SUVW
  258. _^][
  259. SVWu
  260. _^[]
  261. VC20XC00U
  262. SVWU
  263. tEVU
  264. t3x<
  265. ]_^[
  266. QSVW
  267. QSVW
  268. t7)E
  269. D$ P
  270. t$ V
  271. NWVS
  272. u7WPS
  273. u&WVS
  274. _^[]
  275. Ww!j
  276. _^[]
  277. _9=,.
  278. YY_[]
  279. tD+E
  280. uRFGHt
  281. Yt)W3
  282. SVWj
  283. j@Y3
  284. Wj@Y3
  285. t7SW
  286.  
  287. @AA;
  288. 8csm
  289. u,9x
  290. X_^]
  291. ub9~
  292. YY_^[
  293. QQVW
  294. sO;>|C;~
  295. u Vj
  296. 8csm
  297. u SW
  298. _^[]
  299. ?csm
  300. 8csm
  301. YYPW
  302. QQSVW
  303. t:jtj
  304. Yt)V
  305. u?jtj
  306. Yt&V
  307. FP=
  308. QQSVW
  309. 9p`t
  310. QQSVW
  311. _WPS
  312. HHtpHHtl
  313. RPWV
  314. u>Wj
  315. t&:a
  316. Yu!j
  317. t%WV
  318. SVW3
  319. ~&WP
  320. SVWj
  321. tYPV
  322. YYF;5
  323. t%WV
  324. QQSV
  325. btHHt.
  326. SVWj
  327. u!PV
  328. YYF;5
  329. X_[^
  330. t%WV
  331. wBVSP
  332. _^[]
  333. HSVWh
  334. t9UW
  335. ?=t"U
  336. QQS3
  337. PSSW
  338. 8"uD
  339. 8"uF@
  340. 8"u,
  341. @@f9
  342. @@f9
  343. SS@SSPVSS
  344. t#SSUP
  345. t$$VSS
  346. _^][YY
  347. j?I_
  348. ulSj
  349. uY;]
  350. pD#U
  351. j #M
  352. j?^;
  353. X_^[
  354. ^_[3
  355. PPPPPPPP
  356. uFWWj
  357. "WWSh4
  358. 9} u
  359. E WW
  360. tMWWS
  361. t@9}
  362. VSh
  363. ^[_3
  364. PPPPPPPP
  365. PPPPPPPP
  366. PVh4
  367. u";E
  368. u+Vj
  369. 8csm
  370. QQSVWj
  371. PSj?
  372. PSj?
  373. >:uNFV
  374. >:u#FV
  375. Y_^[
  376. SVW3
  377. Qf9=
  378. WQPWS
  379. ,f9=\0
  380. WWWj
  381. WWSj
  382. WWWj
  383. _^[]
  384. QQSUVWj
  385. _^][YY
  386. VWsr
  387. 1t*;
  388. VWuBh\
  389. tPh@
  390. <8=u
  391. SVWu
  392. ^}%95
  393. HSVHWtgHHtF
  394. NTuI
  395. H}Fj
  396. QSUV
  397. WWWWj
  398. t/WWUPj
  399. _^][Y
  400. SVWt
  401. _^[]
  402. FGQPS
  403. 0SVW
  404. _u@W
  405. PWPSS
  406. PWPSS
  407. 9] u
  408. tySS
  409. t-VW
  410. QQSVW3
  411. tUj=
  412. t@9u
  413. uT9}
  414. 8<=t
  415. ^][_
  416. tJSWV
  417. u/9F
  418. j@jP
  419. hWj@_;
  420. PPhj
  421. Pl_^
  422. tWS3
  423. QSUVWj
  424. n0SSSSU
  425. _SSSSU
  426. Ph_^][Y
  427. 9Q\u
  428. 9y`u
  429. ;qdt
  430. V9l$
  431. VVUVS
  432. _^][
  433. SUVW
  434. UUWP
  435. _^][Y
  436. !hOe
  437. tuHHt
  438. tD9_Pt?
  439. 9X tn
  440. w]hOe
  441. ~0PPW
  442. E SVj
  443. (wqt\HHtS
  444. tFHt>
  445. t>Ht Ht
  446. u<9E
  447. _^[]
  448. t59~
  449. u09=h-
  450. 9=h-
  451. QQSVW
  452. QQSV
  453. 4SVW
  454. VhOe
  455. tBSh
  456. X_^[
  457. @SVW
  458. btZ-
  459. VWhOe
  460. VhOe
  461. 9p$u
  462. ,SVW
  463. t39w
  464. 9w u
  465. ^$tL
  466. t7j,
  467. tMVW
  468. >(r-
  469. u@hOe
  470. 9HPu
  471. u,;C
  472. _^[d
  473. <VWj
  474. VwltB
  475. r0=8
  476. 97_u
  477. SVW3
  478. ^[+E
  479. F _^
  480. tBSh
  481. tBSh
  482. tBSh
  483. F ^d
  484. SVW3
  485. SShv
  486. _^][
  487. _^[d
  488. ;Nxu
  489. _j X;
  490. QQUV
  491. _^]YY
  492. QSVW
  493. t#;^
  494. QQSVW
  495. 9^xu2
  496. Vu4j
  497. u5SVW
  498. uTVW
  499. PWVWWW
  500. WVWWW
  501. QQV3
  502. j@j<
  503. SUVW
  504. ^,_^][
  505. CWinApp
  506. PreviewPages
  507. Settings
  508. CFileFind
  509. file://
  510. CWinThread
  511. CCmdTarget
  512. .INI
  513. .HLP
  514. CNotSupportedException
  515. CMemoryException
  516. CException
  517. combobox
  518. software
  519. CObject
  520. CTempGdiObject
  521. CTempDC
  522. CGdiObject
  523. CUserException
  524. CResourceException
  525. CTempWnd
  526. CWnd
  527. AfxOldWndProc423
  528. AfxWnd42s
  529. AfxControlBar42s
  530. AfxMDIFrame42s
  531. AfxFrameOrView42s
  532. AfxOleControl42s
  533. GetMonitorInfoA
  534. EnumDisplayMonitors
  535. MonitorFromPoint
  536. MonitorFromRect
  537. MonitorFromWindow
  538. GetSystemMetrics
  539. USER32
  540. DISPLAY
  541. commctrl_DragListMsg
  542. InitCommonControlsEx
  543. COMCTL32.DLL
  544. CMapPtrToPtr
  545. CTempMenu
  546. CMenu
  547. H:mm:ss
  548. dddd, MMMM dd, yyyy
  549. M/d/yy
  550. December
  551. November
  552. October
  553. September
  554. August
  555. July
  556. June
  557. April
  558. March
  559. February
  560. January
  561. Saturday
  562. Friday
  563. Thursday
  564. Wednesday
  565. Tuesday
  566. Monday
  567. Sunday
  568. (8PX
  569. 700WP
  570. `h````
  571. ppxxxx
  572. (null)
  573. runtime error
  574. TLOSS error
  575. SING error
  576. DOMAIN error
  577. R6028
  578. - unable to initialize heap
  579. R6027
  580. - not enough space for lowio initialization
  581. R6026
  582. - not enough space for stdio initialization
  583. R6025
  584. - pure virtual function call
  585. R6024
  586. - not enough spac
  587. e for _onexit/atexit table
  588. R6019
  589. - unable to open console device
  590. R6018
  591. - unexpected heap error
  592. R6017
  593. - unexpected multithread lock error
  594. R6016
  595. - not enough space for thread data
  596. abnormal program termination
  597. R6009
  598. - not enough space for environment
  599. R6008
  600. - not enough space for arguments
  601. R6002
  602. - floating point not loaded
  603. Microsoft Visual C++ Runtime Library
  604. Runtime Error!
  605. Program:
  606. <program name unknown>
  607. SunMonTueWedThuFriSat
  608. JanFebMarAprMayJunJulAugSepOctNovDec
  609. GetLastActivePopup
  610. GetActiveWindow
  611. MessageBoxA
  612. user32.dll
  613. CloseHandle
  614. ReadFile
  615. GetFileSize
  616. CreateFileA
  617. LocalAlloc
  618. LocalFree
  619. GetLastError
  620. UnmapViewOfFile
  621. MapViewOfFile
  622. CreateFileMappingA
  623. SetFileAttributesA
  624. FreeLibrary
  625. GetProcAddress
  626. LoadLibraryA
  627. OpenProcess
  628. HeapFree
  629. HeapAlloc
  630. GetProcessHeap
  631. MultiByteToWideChar
  632. GetFullPathNameA
  633. DeleteFileA
  634. Sleep
  635. GlobalUnlock
  636. GlobalLock
  637. TerminateProcess
  638. GetCurrentProcess
  639. CreateProcessA
  640. GetSystemDirectoryA
  641. InterlockedIncrement
  642. InterlockedDecrement
  643. lstrlenA
  644. WideCharToMultiByte
  645. GetCurrentThreadId
  646. GetCurrentThread
  647. lstrcmpiA
  648. lstrcmpA
  649. GlobalDeleteAtom
  650. GlobalAlloc
  651. FindClose
  652. SetLastError
  653. FindFirstFileA
  654. lstrcpyA
  655. FindNextFileA
  656. GetModuleFileNameA
  657. InitializeCriticalSection
  658. TlsAlloc
  659. DeleteCriticalSection
  660. GlobalFree
  661. GlobalHandle
  662. TlsFree
  663. LeaveCriticalSection
  664. GlobalReAlloc
  665. EnterCriticalSection
  666. TlsSetValue
  667. LocalReAlloc
  668. TlsGetValue
  669. SetErrorMode
  670. lstrcatA
  671. lstrcpynA
  672. GetVersion
  673. GlobalFlags
  674. WritePrivateProfileStringA
  675. GetCurrentDirectoryA
  676. GetModuleHandleA
  677. FileTimeToSystemTime
  678. FileTimeToLocalFileTime
  679. GlobalFindAtomA
  680. GlobalAddAtomA
  681. GlobalGetAtomNameA
  682. GetProcessVersion
  683. WriteFile
  684. FilePointer
  685. FlushFileBuffers
  686. SetEndOfFile
  687. GetCPInfo
  688. GetOEMCP
  689. RtlUnwind
  690. GetTimeZoneInformation
  691. GetSystemTime
  692. GetLocalTime
  693. GetCommandLineA
  694. ExitProcess
  695. RaiseException
  696. HeapSize
  697. HeapReAlloc
  698. GetACP
  699. SetHandleCount
  700. GetStdHandle
  701. GetFileType
  702. GetStartupInfoA
  703. FreeEnvironmentStringsA
  704. FreeEnvironmentStringsW
  705. GetEnvironmentStrings
  706. GetEnvironmentStringsW
  707. HeapDestroy
  708. HeapCreate
  709. VirtualFree
  710. VirtualAlloc
  711. IsBadWritePtr
  712. LCMapStringA
  713. LCMapStringW
  714. GetStringTypeA
  715. GetStringTypeW
  716. GetDriveTypeA
  717. SetUnhandledExceptionFilter
  718. IsBadReadPtr
  719. IsBadCodePtr
  720. SetStdHandle
  721. CompareStringA
  722. CompareStringW
  723. SetEnvironmentVariableA
  724. KERNEL32.dll
  725. CallNextHookEx
  726. CloseClipboard
  727. GetClipboardData
  728. OpenClipboard
  729. IsClipboardFormatAvailable
  730. SetWindowsHookExA
  731. PostQuitMessage
  732. PostMessageA
  733. SendMessageA
  734. SetCursor
  735. EnableWindow
  736. MessageBoxA
  737. GetWindowLongA
  738. IsWindowEnabled
  739. GetLastActivePopup
  740. GetParent
  741. GetCursorPos
  742. PeekMessageA
  743. IsWindowVisible
  744. ValidateRect
  745. GetKeyState
  746. GetActiveWindow
  747. DispatchMessageA
  748. TranslateMessage
  749. GetMessageA
  750. GetNextDlgTabItem
  751. GetFocus
  752. EnableMenuItem
  753. CheckMenuItem
  754. SetMenuItemBitmaps
  755. ModifyMenuA
  756. GetMenuState
  757. LoadBitmapA
  758. GetMenuCheckMarkDimensions
  759. UnhookWindowsHookEx
  760. UnregisterClassA
  761. LoadStringA
  762. GetClassNameA
  763. PtInRect
  764. GetWindowRect
  765. GetDlgCtrlID
  766. GetWindow
  767. ClientToScreen
  768. SetWindowTextA
  769. GetWindowTextA
  770. wsprintfA
  771. GetMenuItemCount
  772. GetDC
  773. ReleaseDC
  774. TabbedTextOutA
  775. DrawTextA
  776. GrayStringA
  777. GetDlgItem
  778. SetWindowLongA
  779. SetWindowPos
  780. ShowWindow
  781. SetFocus
  782. GetSystemMetrics
  783. GetWindowPlacement
  784. IsIconic
  785. SystemParametersInfoA
  786. RegisterWindowMessageA
  787. SetForegroundWindow
  788. GetForegroundWindow
  789. GetMessagePos
  790. GetMessageTime
  791. RemovePropA
  792. CallWindowProcA
  793. GetPropA
  794. SetPropA
  795. GetClassLongA
  796. CreateWindowExA
  797. DestroyWindow
  798. DefWindowProcA
  799. GetMenuItemID
  800. GetSubMenu
  801. GetMenu
  802. RegisterClassA
  803. GetClassInfoA
  804. WinHelpA
  805. GetCapture
  806. GetTopWindow
  807. CopyRect
  808. GetClientRect
  809. AdjustWindowRectEx
  810. GetSysColor
  811. MapWindowPoints
  812. LoadIconA
  813. LoadCursorA
  814. GetSysColorBrush
  815. DestroyMenu
  816. USER32.dll
  817. CreateBitmap
  818. DeleteObject
  819. DeleteDC
  820. SaveDC
  821. RestoreDC
  822. SelectObject
  823. GetStockObject
  824. SetBkColor
  825. SetTextColor
  826. SetMapMode
  827. SetViewportOrgEx
  828. OffsetViewportOrgEx
  829. SetViewportExtEx
  830. ScaleViewportExtEx
  831. SetWindowExtEx
  832. ScaleWindowExtEx
  833. GetClipBox
  834. GetDeviceCaps
  835. PtVisible
  836. RectVisible
  837. TextOutA
  838. ExtTextOutA
  839. Escape
  840. GetObjectA
  841. GDI32.dll
  842. comdlg32.dll
  843. ClosePrinter
  844. DocumentPropertiesA
  845. OpenPrinterA
  846. WINSPOOL.DRV
  847. RegCloseKey
  848. RegQueryValueExA
  849. RegOpenKeyExA
  850. SetFileSecurityA
  851. SetSecurityDescriptorDacl
  852. AddAccessAllowedAce
  853. GetAce
  854. AddAce
  855. InitializeAcl
  856. GetLengthSid
  857. GetAclInformation
  858. GetSecurityDescriptorDacl
  859. InitializeSecurityDescriptor
  860. GetFileSecurityA
  861. LookupAccountNameA
  862. GetUserNameA
  863. RegSetValueExA
  864. RegCreateKeyExA
  865. RegEnumValueA
  866. RegEnumKeyA
  867. ADVAPI32.dll
  868. SHELL32.dll
  869. COMCTL32.dll
  870. CoCreateInstance
  871. CoInitialize
  872. ole32.dll
  873. WSOCK32.dll
  874. InternetAttemptConnect
  875. InternetConnectA
  876. InternetOpenA
  877. InternetCloseHandle
  878. HttpQueryInfoA
  879. InternetSetOptionA
  880. InternetQueryOptionA
  881. HttpSendRequestA
  882. HttpAddRequestHeadersA
  883. HttpOpenRequestA
  884. HttpEndRequestA
  885. InternetWriteFile
  886. HttpSendRequestExA
  887. InternetReadFile
  888. ReadUrlCacheEntryStream
  889. RetrieveUrlCacheEntryStreamA
  890. InternetSetCookieA
  891. FindCloseUrlCache
  892. DeleteUrlCacheEntry
  893. FindNextUrlCacheEntryA
  894. FindFirstUrlCacheEntryA
  895. InternetGetCookieA
  896. WININET.dll
  897. syschk.dll
  898. CheckDrive
  899. SystemCheck
  900. --%s
  901. Content-Disposition: form-data; name="%s"
  902. --%s
  903. Content-Disposition: form-data; name="%s"; filename="%s"
  904. Content-Type: %s
  905. http
  906. .PAVCException@@
  907. Accept: */*
  908. HTTP/1.0
  909. Content-Type: application/x-www-form-urlencoded
  910. POST
  911. Content-Length: %d
  912. Content-Type: multipart/form-data; boundary=---------------------------7dab371b0124
  913. ---------------------------7dab371b0124
  914. application/octet-stream
  915. Content Type
  916. https
  917. value=
  918. name=
  919. <INPUT
  920. T1266545942618/1266545942618/1266545962717
  921. GMAIL_LOGIN
  922. 2000
  923. GMAIL_RTT
  924. __utmc
  925. 173272373
  926. __utmb
  927. name = value; expires = Sat,01-Jan-2000 00:00:00 GMT
  928. asts
  929. https%3A%2F%2Fmail%2Egoogle%2Ecom%2Fmail%2F%3F
  930. continue
  931. GALX
  932. Passwd
  933. Email
  934. PersistentCookie
  935. ctok
  936. cans
  937. charset_
  938. utf-8
  939. draft
  940. undefined
  941. ishtml
  942. body
  943. subject
  944. GMAIL_AT
  945. d:\reg0
  946. futurekimkim
  947. heike931
  948. fuechei.chang
  949. fuechei.chang.drivehq.com/up/
  950. .exe
  951. SHGetFolderPathA
  952. C:\Program Files
  953. SHELL32.DLL
  954. %programfiles%
  955. EnumProcesses
  956. GetModuleBaseNameA
  957. EnumProcessModules
  958. PSAPI.DLL
  959. unknown
  960. iexplore.exe
  961. Internet Explorer.lnk
  962. iexplore
  963. internet
  964. {871C5380-42A0-1069-A2EA-08002B30309D}
  965. favorites
  966. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel\
  967. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu\
  968. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\
  969. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPage\
  970. \Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\
  971. \Microsoft\Internet Explorer\Quick Launch\
  972. \Internet Explorer.lnk
  973. Anything can go here
  974. \iexplore.exe
  975. done
  976. %s\%s
  977. error
  978. %s done
  979. chrome.exe
  980. opera.exe
  981. netscp
  982. firefox
  983. %s%s
  984. %s%s\shellopen\command\
  985. productname
  986. SOFTWARE\Microsoft\Windows NT\CurrentVersion
  987. csdversion
  988. SOFTWARE\Microsoft\Internet Explorer
  989. version
  990. SOFTWARE\classes\local settings\SOFTWARE\Microsoft\Windows\shell\MUICache
  991. SOFTWARE\Microsoft\Windows\ShellNoRoam\MUICache
  992. \adobe\
  993. SOFTWARE\Clients\StartMenuInternet\
  994. SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
  995. http\Shell\open\command
  996. Software\Microsoft\Internet Explorer\TypedURLs
  997. " Func1
  998. %s\rename.ocx
  999. http://%s/rename
  1000. %s\syschk.ocx1
  1001. http://%s%s
  1002. &cmid=1&rt=h&zx=
  1003. &view=up&act=sm&jsid=
  1004. &rid=mail%3Asd.40.2.0&at=
  1005. https://mail.google.com/mail/?ui=2&ik=
  1006. Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
  1007. @gmail.com
  1008. GLOBALS=
  1009. http://www.google.com/
  1010. https://mail.google.com/mail/?logout&hl=ko
  1011. https://www.google.com/accounts/ServiceLoginAuth?service=mail
  1012. https://mail.google.com/mail/
  1013. rundll32.exe "
  1014. "%s" "%s"
  1015. JavaScript/JS
  1016. /FontFile2
  1017. .pdf
  1018. http\Shell\open\command\
  1019. syschk.ocx
  1020. acrobat\Shell\open\command\
  1021. Infect NO!
  1022. Infect OK!
  1023. form.ocx
  1024. .?AVCNoTrackObject@@
  1025. .?AV_AFX_WIN_STATE@@
  1026. .?AVCObject@@
  1027. .?AVCCmdTarget@@
  1028. .?AVCWinThread@@
  1029. .?AVCWinApp@@
  1030. .?AVCFileFind@@
  1031. .?AV_AFX_CTL3D_STATE@@
  1032. .?AV_AFX_CTL3D_THREAD@@
  1033. .?AVCCmdUI@@
  1034. .?AUCThreadData@@
  1035. .?AVCHandleMap@@
  1036. .?AV_AFX_THREAD_STATE@@
  1037. .?AVAFX_MODULE_STATE@@
  1038. .?AVAFX_MODULE_THREAD_STATE@@
  1039. .?AV_AFX_BASE_MODULE_STATE@@
  1040. .PAX
  1041. .PAVCObject@@
  1042. .PAVCSimpleException@@
  1043. .PAVCMemoryException@@
  1044. .?AVCException@@
  1045. .?AVCSimpleException@@
  1046. .?AVCMemoryException@@
  1047. .?AVCNotSupportedException@@
  1048. .?AVCDC@@
  1049. .?AVCGdiObject@@
  1050. .?AVCTempDC@@
  1051. .?AVCTempGdiObject@@
  1052. .?AVCResourceException@@
  1053. .?AVCUserException@@
  1054. .?AVCWnd@@
  1055. .?AVCTestCmdUI@@
  1056. .?AVCTempWnd@@
  1057. .?AVCMapPtrToPtr@@
  1058. .?AVCMenu@@
  1059. .?AVCTempMenu@@
  1060. .?AVtype_info@@
  1061. wwwwww
  1062. wwwwww
  1063. wwwwww
  1064. wwwwww
  1065. wwwwww
  1066. wwwwww
  1067. wwwwww
  1068. wwwwww
  1069. wwww
  1070. wwww
  1071. 1(1Z1q1
  1072. 3t3}3
  1073. 3<4z4
  1074. 4"5U5c5
  1075. 8O9|9
  1076. :5:C:I:
  1077. ;n;s;y;
  1078. =u=z=
  1079. 6$64696F6e6
  1080. 7K7z7
  1081. 8$9*959?9I9Y9c98;A;R;W;^;h;o;
  1082. <!<W<]<c<
  1083. =#><>
  1084. ?#?(?5?:?G?L?Y?^?k?p?
  1085. 0I0q0
  1086. 233L3
  1087. 8(8J8f8
  1088. ;*;0;A;G;X;^;o;u;};
  1089. ;)</<F>S>`>
  1090. 0&0.070>0P0
  1091. 2U3l3
  1092. 4-4Q4b4
  1093. 4E5c5
  1094. 6<6R6f6
  1095. 6#7B7j7
  1096. ;#<F<
  1097. >-?{?
  1098. 4(5H5M5
  1099. 506?6g6
  1100. 8<9E9T9
  1101. :;:O:
  1102. <A<k<
  1103. =,=]=u=
  1104. >'>Z>
  1105. >3?M?
  1106. 0(1C1[1s1
  1107. 2&202j2x2
  1108. 3'353J3U3]3j3t3
  1109. 6!6.6;6_6d6
  1110. 8:8p8v8}8
  1111. 949W9\9
  1112. <(=-=g=l=
  1113. >F>R>n>
  1114. F0K0
  1115. 2 2,2>2V2
  1116. 3/4t4
  1117. 5:5N5
  1118. 5,6i6
  1119. 6G8W8r8
  1120. 9&:d:i:p:u:z:
  1121. 0'1C1
  1122. 1@2R2
  1123. 3?3W3g3~3
  1124. 4'464`4
  1125. 5,5<5X5|5
  1126. 6)656B6H6T6Y6c6j6t6{6
  1127. 707i7
  1128. 898@8\8q8}8
  1129. 9$:S:
  1130. <6>y>
  1131. >!?[?o?
  1132. 0"0K0_0
  1133. 0_5i5
  1134. 6(6\7g7n7
  1135. 8"8)888@8K8Q8W8a8y8~8
  1136. :;:A:
  1137. :%;K;e;l;p;t;x;|;
  1138. ;J<U<p<w<|<
  1139. = =j=p=t=x=|=
  1140. 0;0U0\0`0d0h0l0p0t0x0
  1141. 0:1E1`1g1l1p1t1
  1142. 2Z2`2d2h2l2
  1143. 233^3
  1144. 3 4,434C4I4P4Z4s4{4
  1145. 425g5
  1146. 868u8{8
  1147. 8/9A9P9q9w9
  1148. :5:A:K:V:`:j:p:
  1149. :Z;`;~;
  1150. <!<-<?<M<\<m<
  1151. 5&7+7
  1152. :":(:5:E:K:S:q:w:
  1153. :$;<;B;N;S;
  1154. ;Q<Y<
  1155. <c=r=
  1156. 0p184<4@4D4H4L4P4T4$5*525:5B5N5S5_5g5o5w5
  1157. 6 6&6
  1158. 8(8D8S8e8n8
  1159. <2<E<
  1160. 2-252F2K2X2]2
  1161. 3"3<3^3j3u3
  1162. 6>7D7P7
  1163. 8 8R8\8}8
  1164. 9%929S9x9
  1165. :':1:E:S:`:e:k:
  1166. ;Z;=<V<
  1167. =X=k=
  1168. >8>D>N>V>^>d>l>{>
  1169. ?"?d?x?
  1170. 0!0(01080@0F0Q0Y0
  1171. 303;3A3F3L3Y3v3|3
  1172. 7'787>7Q7
  1173. 7p<u<
  1174. =+=K=
  1175. =T>y>
  1176. m0r0
  1177. 1&3:3
  1178. 3$4*464
  1179. 5<5B5P5V5`5h5n5|5
  1180. 6#6:6U6q6
  1181. 777A7L7V7d7
  1182. 8!8*8;8E8M8U8]8g8p8x8
  1183. 8.9=9k9v9
  1184. :':2:A:R:_:r:x:~:
  1185. :I;n;
  1186. <(<:<B<H<P<
  1187. ='>4>9>F>R>
  1188. ?<?D?
  1189. 0;0]0
  1190. 171B1N1^1
  1191. 5&545=5J5[5
  1192. 8!9?9v9
  1193. <,<7<B<L<T<_<m<
  1194. =M>e>
  1195. >)?3?D?Q?
  1196. 040p0
  1197. 1"171J1
  1198. 4/5>53797T7
  1199. 8%818L8W8c8y8
  1200. 9)9@9L9_9n9w9
  1201. :/<u<
  1202. >"?i?
  1203. M0|0
  1204. 1&2c2h2
  1205. 2^3n3
  1206. 3,4F4f4m4
  1207. 7U7[7f7
  1208. 7>8I8
  1209. 9):`:
  1210. <"=e=
  1211. >,>O>v>
  1212. ?#?)?@?K?X?a?g?~?
  1213. 0'0c0
  1214. 1L1^1|1
  1215. 2 3*404C4N4
  1216. 666q6}6
  1217. 6+7L7_7z7
  1218. 8$8,848N8S8s8.9i9
  1219. <Y<r<
  1220. >$>=>
  1221. >=?B?q?
  1222. 6"6&6*6.62666:6>6B6F6J6X6
  1223. 7(7-7
  1224. 8,9W9
  1225. :H<p<u<
  1226. =Q>r>
  1227. ?Y?f?|?
  1228. $0/050S0
  1229. 111Y1a1j1u1~1
  1230. 282Y2y2
  1231. 4(5.5I5R5q5
  1232. 516D6\6w6
  1233. 737G7W7n7
  1234. 828Q8v8
  1235. 9F9t9
  1236. 9::i:
  1237. >N?\?x?
  1238. #0d0y0
  1239. 141Z1{1
  1240. 3 3&373e3
  1241. 4a4r4~4
  1242. 455J5P5
  1243. 6%7G7r7
  1244. 7M8V8_8q8w8
  1245. 9K9c9
  1246. 9):f:
  1247. ;+;@;O;
  1248. <><R<
  1249. =*=B=c=v=
  1250. ?5?H?
  1251. 0$090N0
  1252. 2&2{2
  1253. 3!303=3L3R3Y3a3s3z3
  1254. 4#4E4\4v4
  1255. 5)555?5V5a5m5
  1256. 616A6P6j6~6
  1257. 6"7(747T7x7
  1258. 8$8/898E8N8W8`8k8s8y8
  1259. 9-9J9\9k9p9
  1260. :,:2:E:^:n:}:
  1261. :%;-;?;Q;
  1262. <O<a<
  1263. <0=I=w=
  1264. >,>W>l>
  1265. ?0?d?
  1266. 0!050J0]0i0
  1267. 1+1=1S1e1y1
  1268. 2&2;2N2a2u2
  1269. 5 5$5(5,5054585<5@5D5H5L5P5`5p5t5
  1270. 6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
  1271. 7 707D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
  1272. 8,80848\8`8
  1273. 9 909P9`9
  1274. : :8:D:H:X:d:h:
  1275. ; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
  1276. < <$<(<,<0<8<D<H<`<l<p<
  1277. =,=D=\=t=
  1278. >4>L>d>|>
  1279. ,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
  1280. 0(1,101418
  1281. 1<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
  1282. 2 2,202H2T2X2h2l2p2t2x2|2
  1283. 4$4(484@4D4P4X4\4
  1284. 7l8p8x8|8
  1285. 9,90989P9h9
  1286. : :(:,:0:D:T:X:`:x:|:
  1287. ;,;<;@;H;`;d;|;
  1288. <$<(<0<H<L<d<t<x<
  1289. = =8=P=h=l=p=t=
  1290. >4>D>H>P>h>l>
  1291. ?$?4?8?@?X?\?`?d?|?
  1292. 0$04080@0X0\0t0
  1293. 1,10181P1T1l1|1
  1294. 2(2D2P2X2
  1295. 3$3,343<3D3L3T3\3d3l3t3|3
  1296. 4 4<4H4d4p4
  1297. 5 5<5D5P5l5t5
  1298. 6 6<6D6P6l6t6|6
  1299. 7(7D7P7l7x7
  1300. 7(848<8H8d8l8x8
  1301. 9(9D9L9X9t9|9
  1302. : :$:(:,:<:H:P:
  1303. ; ;<;H;d;p;
  1304. <4<@<H<x<
  1305. =4=@=\=d=l=x=
  1306. >4>@>\>h>
  1307. 0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0t0x0|0
  1308. (5,505H5h5
  1309. 606`6x6
  1310. 6 7H7X7p7
  1311. 888P8p8
  1312. 9(9@9`9x9
  1313. ; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;
  1314. =$=4=D=
  1315. 34484
  1316. C:\Documents and Settings\Mila\Desktop\Conference Information_2010 IFANS Conference on Global Affairs (1001).pdf
  1317.  
  1318. Unicode Strings:
  1319. ---------------------------------------------------------------------------
  1320. jjjj
  1321. jjjj
  1322. jjjj
  1323. jjjj
  1324. jjjj
  1325. jjjj
  1326. jjjjjj
  1327. (null)
  1328. ((((( H
  1329. VS_VERSION_INFO
  1330. StringFileInfo
  1331. 040904B0
  1332. CompanyName
  1333. FileDescription
  1334. syschk DLL
  1335. FileVersion
  1336. 1, 0, 0, 1
  1337. InternalName
  1338. syschk
  1339. LegalCopyright
  1340. Copyright (C) 2010
  1341. LegalTrademarks
  1342. OriginalFilename
  1343. syschk.DLL
  1344. ProductName
  1345. syschk Dynamic Link Library
  1346. ProductVersion
  1347. 1, 0, 0, 1
  1348. VarFileInfo
  1349. Translation
  1350. MS Shell Dlg
  1351. &New
  1352. Cancel
  1353. &Help
  1354. Open
  1355. Save As
  1356. All Files (*.*)
  1357. Untitled
  1358. an unnamed file
  1359. &Hide
  1360. No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
  1361. Out of memory.
  1362. An unknown error has occurred.
  1363. Invalid filename.
  1364. Failed to open document.
  1365. Failed to save document.
  1366. Save changes to %1? Failed to create empty document.
  1367. The file is too large to open.
  1368. Could not start print job.
  1369. Failed to launch help.
  1370. Internal application error.
  1371. Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
  1372. #Unable to read write-only property.#Unable to write read-only property.
  1373. Unexpected file format.V%1
  1374. Cannot find this file.
  1375. Please verify that the correct path and file name are given.
  1376. Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
  1377. Please enter an integer.
  1378. Please enter a number.*Please enter an integer between %1 and %2.(Please enter a number between %1 and %2.(Please enter no more than %1 characters.
  1379. Please select a button.*Please enter an integer between 0 and 255. Please enter a positive integer. Please enter a date and/or time.
  1380. Please enter a currency.
  1381. No error occurred.-An unknown error occurred while accessing %1.
  1382. %1 was not found.
  1383. %1 contains an invalid path.=%1 could not be opened because there are too many open files.
  1384. Access to %1 was denied..An invalid file handle w
  1385. as associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
  1386. Seek failed on %15A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
  1387. Disk full while accessing %1..An attempt was made to access %1 past its end.
  1388. No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
  1389. %1 has a bad format."%1 contained an unexpected object. %1 contains an incorrect schema.
  1390. #Unable to load mail system support.
  1391. Mail system DLL is invalid.!Send Mail failed to send message.
  1392. pixels
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement