Analysis Date2014-06-01 17:27:19
MD595a15a2d2de6b6e4b0d02d1609ed92e2
SHA117021e01d699ae7fac5c69d8751dc71b653e4218

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.rdata md5: b3f3299e6a7b66b958dd02dc38678538 sha1: 9cb6f70a0d3b426981e0ac2d7bb83e7343942d16 size: 8192
Section.data md5: d108b2d626a3580f695eca4c582dfb4d sha1: b786b384bf01ad7125646660b0a7e64baa320b18 size: 30208
Section.rsrc md5: f44d8a43d7302aa63f6918542ac79cbd sha1: bc146f4b320ba600f0fb302a7c763e4cf2498d74 size: 1536
Timestamp2010-07-19 12:33:53
VersionLegalCopyright: Copyright (C) Microsoft Corp. 1981-2000
InternalName: servicess
FileVersion: 5.50.4134.100
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft(R) Windows(R) 2000 Operating System
SpecialBuild:
ProductVersion: 5.50.4134.100
FileDescription: Microsoft (R) Windows Explorer
OriginalFilename: servicess.exe
PackerMicrosoft Visual C++ v6.0
PEhash36d6d2f5c9c3eb0b41dfc7e80866f82277f6807f
IMPhash5afda5bec5ddd3ba31023406f0fca220
AVAlwil (avast)Agent-CNC [Trj]
AVArcabit (arcavir)Heur.RoundKick
AVAuthentiumW32/Busky.B.gen!Eldorado
AVAvira (antivir)TR/Downloader.A.3089
AVCA (E-Trust Ino)Win32/Cosmu.OP
AVCAT (quickheal)Trojan.Malagent.az3
AVClamAVTrojan.Mybot-12000
AVDr. WebTrojan.Click1.57939
AVEset (nod32)Win32/Agent.NJC worm
AVFortinetW32/Agent.NJC!tr
AVFrisk (f-prot)W32/Busky.B.gen!Eldorado (generic, not disinfectable)
AVF-SecureTrojan.Generic.7014451
AVGrisoft (avg)Generic_r.SO
AVIkarusTrojan.Win32.Sisron
AVKasperskyTrojan.Win32.Cosmu.awlb
AVMalwareBytesBackdoor.Agent
AVMcafeeDownloader-FCK
AVMicrosoft Security EssentialsTrojan:Win32/Phishbank.A
AVMicroWorld (escan)Trojan.Generic.7014451
AVNormandoslegacy/Genetik.E
AVRisingTrojan.Win32.Cosmu.b
AVSophosTroj/Dloadr-DSZ
AVSymantecTrojan.Gen
AVTrend MicroTROJ_PACKE.SMUA5
AVVirusBlokAda (vba32)Worm.Mirror.01

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\Debugger ➝
C:\WINDOWS\system32\LKIMLBHIFBLEELJHKBGGGJF\services.exe\\x00
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\anqe6068 ➝
C:\WINDOWS\system32\LKIMLBHIFBLEELJHKBGGGJF.exe\\x00
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\mirror.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\servicess.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\scservice.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\netdhcp.exe
Creates FileC:\WINDOWS\system32\LKIMLBHIFBLEELJHKBGGGJF\anqe6068.exe
Creates Processc:\windows\system32\lkimlbhifbleeljhkbgggjf\anqe6068.exe

Process
↳ c:\windows\system32\lkimlbhifbleeljhkbgggjf\anqe6068.exe

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\Debugger ➝
C:\WINDOWS\system32\LKIMLBHIFBLEELJHKBGGGJF\services.exe\\x00
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\anqe6068 ➝
C:\WINDOWS\system32\LKIMLBHIFBLEELJHKBGGGJF.exe\\x00
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\mirror.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\servicess.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\scservice.exe
Creates FileC:\WINDOWS\system32\YXVZYOUVSOYRRYWUXOTTTWS\netdhcp.exe
Creates Mutex8606eqna

Network Details:


Raw Pcap

Strings
y
D\........
041904b0
5.50.4134.100
Comments
CompanyName
Copyright (C) Microsoft Corp. 1981-2000
FileDescription
FileVersion
InternalName
LegalCopyright
LegalTrademarks
Microsoft Corporation
Microsoft (R) Windows Explorer
Microsoft(R) Windows(R) 2000 Operating System
OriginalFilename
PrivateBuild
ProductName
ProductVersion
servicess
servicess.exe
SpecialBuild
StringFileInfo
Translation
VarFileInfo
VS_VERSION_INFO
<<<<====>>>>????
====>>>>????@@@@
    !!!!""""
    !!!!""""####	
------
''''(((())))****
(((())))****++++
))))****++++,,,,
}}}}~~~~
$$$$%%%%&&&&''''
\\\\]]]]^^^^____
####$$$$%%%%&&&&
----....////0000
0000111122223333
1234567890
127.0.0.1:80:2:5:1
1I<S,@?
2791CE51-A58F-470b-BB86-A9FCAC1189DC
4444555566667777
5277d6cf9f917a1da0ef9e55f3ae9f8f.m
5555666677778888
9999::::;;;;<<<<
````aaaabbbbcccc
aavmGlob.mtx
aavmSema.apc
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Accept: */*
ACKWIN32
_acmdln
ADAWARE
_adjust_fdiv
AdjustTokenPrivileges
ADVAPI32.dll
ADVXDWIN
AGENTSVR
AGENTW
ALERTSVC
ALEVIR
ALOGSERV
AlternateShell
AMON9X
anti...
anti repla
antispy
anti spy
ANTI-TROJAN
antivir
AntiVirInternetUpdateInstance
ANTIVIRUS
APIMONITOR
APLICA32
APVXDWIN
ASHSERV
ASHSIMPL
asm.script_blocking.conf_data_protect
assignment
aswCreFE
ATGUARD
ATRO55EN
ATWATCH
AUPDATE
AUTODOWN
AUTO-PROTECT.NAV80TRY
AUTOTRACE
AUTOUPDATE
AVCCVxdOnActionEvent
AVCENTER
AVCONSOL
AVControlCenterRefresh
AVControlCenterShutDown
AVGCC32
AVGCTRL
AVGSERV
AVGSERV9
AVGUARD
AVKPOP
AVKSERV
AVKSERVICE
AVKWCTl9
AVLTMAIN
_AVP32
_AVPCC
AVPDOS32
AVPTC32
AVPUPD
AVSCHD_9xStoppEvent
AVSCHED32
AVSchedulerReread
AVSYNMGR
AVWIN95
AVWINNT
AVWUPD
AVWUPD32
AVWUPSRV
AVXMONITOR9X
AVXMONITORNT
AVXQUAR
BACKWEB
BARGAINS
bbbbccccddddeeee
BD_PROFESSIONAL
BEAGLE
B.E late
??BHQ]l~
BIDSERVER
BIPCPEVALSETUP
BLACKD
BLACKICE
bnm.cyberdrill.my
BOOTCONF
BOOTWARN
BRASIL
BUNDLE
bursa.cyberdrill.my
CancelLUEvent
ccAlertPluginMutex
ccccddddeeeeffff
ccEmlPxyEvent
ccEmlPxyMutex
CCEVTMGR
ccEvtMgr_Running
ccEvtMgr_Single_Instance_Lock
ccEvtMgr_Terminate_Lock
ccIMSingleInstance
CCPXYSVC
CCSETMGR
ccSetMgr_Running
ccSetMgr_Single_Instance_Lock
ccSetMgr_Terminate_Lock
celcom.cyberdrill.my
ceo@cyberdrill.my
CFGWIZ
CFIADMIN
CFIAUDIT
CFINET
CFINET32
CharUpperA
cimb.cyberdrill.my
cinderawasih-4
Claw95
CLAW95CF
CLEANER
CLEANER3
CLEANPC
CloseHandle
CMDHDLR_{92211674-DBC0-476a-B72C-7A2244B83E56}
CMESYS
CMGRDIAN
CMON016
cnc.cyberdrill.my
Connection: Keep-Alive
CONNECTIONMONITOR
_controlfp
CopyFileA
CPF9X206
CPFNT206
CreateDirectoryA
CreateEventA
CreateFileA
CreateMutexA
CreateProcessA
CreateSemaphoreA
CreateThread
CreateToolhelp32Snapshot
CWNB181
CWNTDWMO
C:\xampp\htdocs\myphish\index.html
D$(|=@
D$0H=@
D$44=@
D$4|g@
D$4h7@
D$8H7@
D$8pg@
@.data
DATEMANAGER
dbghelp.dll
D$,d=@
D$\d<@
D$D47@
D$d<6@
D$d8<@
D$<dg@
D$DhpC@
D$DPg@
debugger
Debugger
decompi
DEFALERT
default
defender
{D] |E^!}F_"~G`
DEFSCANGUI
DEFWATCH
DEPUTY
D$@\g@
D$h$<@
D$ h0C@
D$h(6@
D$H$7@
DHCPNetServer
D$HDg@
disassemb
D$L8g@
DLLCACHE
DLLREG
document05
download_exec
D$`P<@
DPFSETUP
D$P(g@
D$,PSS
DRVDDLL
Dr. Watson
DRWATSON
DRWEB32
DRWEBUPW
D$(SPP
DSSAGENT
D$\t6@
DVP95_0
D$$VUP
D$`X6@
D$Xx<@
d]YXZ_gr
ECENGINE
EFPEADM
email_spam
EnumWindows
ESCANH95
ESCANHNT
ESCANV95
ESPWATCH
ETHEREAL
ETRUSTCIPE
Event_Changed_Config
Event_Changed_Config_RET
Event_Changed_RT
Event_Changed_RT_RET
Event_EndUpdate
Event_EndUpdate_RET
Event_PCC_Exit
Event_PCC_Exit_RET
Event_RestartPCC
Event_RestartPCC_RET
Event_Run_WebTrap
Event_Run_WebTrap_RET
Event_StartUpdate
Event_StartUpdate_RET
EXANTIVIRUS-CNET
_except_handler3
EXE.AVXW
ExitProcess
ExitThread
EXPERT
Explorer.exe %s
Explorer.exe %s\%s\servicess.exe
F-AGNT95
F-AGOBOT
Failed to establish connection with server
Failed to resolve hostname.
FAMEH32
fclose
file manager
FINDVIRU
FireFoxPro
FIREWALL
FLOWPROTECTOR
FNRB32
F-PROT
F-PROT95
FP-WIN
FP-WIN_TRIAL
FreeLibrary
FSAV32
FSAV530STBYB
FSAV530WTBYB
FSAV95
f-secure
FSGK32
FSMA32
FSMB32
F-STOPW
fwrite
GBMENU
GBPOLL
GENERICS
/gerudi/update.txt
GetComputerNameA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetDriveTypeA
GET / HTTP/1.1
GetLastError
__getmainargs
GetModuleFileNameA
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemDirectoryA
GetSystemTime
GetTempPathA
GetTickCount
GetUserNameA
GetVersionExA
GetWindowsDirectoryA
GetWindowTextA
GetWindowTextLengthA
GetWindowThreadProcessId
gggghhhhiiiijjjj
GGGGHHHHIIIIJJJJ
GlobalAlloc
GlobalFree
G'o$p5
GUARDDOG
HACKTRACERSETUP
HBINST
H-e-l-l-B-o-t-3-!!
H-e-l-l-B-o-t-3-T-e-a-M!!!
HHHHIIIIJJJJKKKK
hijackth
HIJACKTHIS
Host: %s
HOTACTIO
HotBaby...xxx
HOTPATCH
hselayang.cyberdrill.my
HTPATCH
 HTTP/1.0
http://cnc.cyberdrill.my/phish
http://infected.cyberdrill.my/mailer/email.php?target=%s
IAMAPP
IAMSERV
IAMSTATS
IBMASN
IBMAVSP
ICLOAD95
ICLOADNT
ICSUPP95
ICSUPPNT
IEDRIVER
iexplore.exe
Iflmt;
I_FUCK_DEAD_PPL
IFW2000
iiiijjjjkkkkllll
IIIIJJJJKKKKLLLL
ImagePath
images/arrow.png
images/banner.gif
images/footer.png
images/keys_icon.gif
images/login_box.gif
images/login_button.gif
images/notes.gif
images/secure.png
indahwater.cyberdrill.my
INETLNFO
INFWIN
_initterm
INTDEL
InternetGetConnectedState
internet secur
INTREN
IOMON98
IPARMOR
ISPIOMON_MUTEX
ISRV95
ISTSVC
|iYLB;728=EP^o
jalak-93
JAMMER
jaring.cyberdrill.my
JDBGMRG
JJJJKKKKLLLLMMMM
jpn.cyberdrill.my
 &/;J\q
kangen
kaspersky
KAVLITE40ENG
KAVPERS40ENG
kdn.cyberdrill.my
KEENVALUE
KERIO-PF-213-EN-WIN
KERIO-WRL-421-EN-WIN
KERIO-WRP-421-EN-WIN
KERNEL32
KERNEL32.dll
KERNEL32.DLL
KILLPROCESSSETUP161
kkkkllllmmmmnnnn
komodo-6
kpj.cyberdrill.my
:K+v#=]
L$4QPP
L$4QRP
l8L m9M!n:N"o
LAUNCHER
LDNETMON
LDPROMENU
LDSCAN
L$$h C@
LiveUpdateShutdownEvent
LLLLMMMMNNNNOOOO
LNETINFO
LOADER
LoadLibraryA
LOCALNET
LOCKDOWN
LOCKDOWN2000
LOOKOUT
LookupPrivilegeValueA
LORDPE
L$$QRP
LSETUP
lstrcpyA
lstrlenA
L$TQRP
LUCOMSERVER
LUINIT
luke file
M3k>N4l?O5m@P6nA
MakeSureDirectoryPathExists
mampu.cyberdrill.my
MAPISVC32
marine.cyberdrill.my
mas.cyberdrill.my
#.<Max
mbb.cyberdrill.my
mcafee
MCAGENT
_###_MCAGENT_Client_###_
mcmc.cyberdrill.my
MCMNHDLR
McNetExitEvent
McNetLingerEvent
MCSHIELD
MCTOOL
MCUPDATE
MCVSRTE
MCVSSHLD
MessageBoxA
MESSENGERINUSE
MFIN32
MFW2EN
MFWENG3.02D30
MGAVRTCL
MGAVRTE
MGHTML
mindef.cyberdrill.my
MINILOG
mirror
mmmmnnnnoooopppp
MMMMNNNNOOOOPPPP
moa.cyberdrill.my
moh.cyberdrill.my
MONITOR
MOOLIVE
MOSTAT
mosti.cyberdrill.my
mot.cyberdrill.my
MPFAGENT
MPFSERVICE
MPFTRAY
MRFLUX
MSBLAST
MSCACHE
MSCCN32
MSCMAN
MSCONFIG
MSIEXEC16
MSINFO32
MSLAUGH
MSMSGRI32
MSMSGS-Default
MSSMMC32
MSVCRT.dll
MU0311AD
muamalat.cyberdrill.my
}m`VOKJLQYdr
MWATCH
MyB0t [Part of CyberDrill]
mynic.cyberdrill.my
N32SCANW
NAVAP.NAVAPSVC
NAVAPSVC
NAVAPW32
NAVENGNAVEX15.NAVLU32
NAVLU32
NAV_OPTIONS_CHANGED_EVENT
NAVSTUB
NAVW32
NAVWNT
NC2000
NCINST4
NEOMONITOR
NEOWATCHLOG
NETARMOR
NETD32
netdhcp
NETINFO
NETMON
NETSCANPRO
NETSPYHUNTER-1.2
NETSTAT
NETUTILS
newCmd=%s
new_page_1
NISSERV
n[K>4-)(*/7BPau
nnnnooooppppqqqq
NNNNOOOOPPPPQQQQ
norman
NORMIST
norton
Norton AntiVirus Agent Is Running
NORTON_INTERNET_SECU_3.0_407
NOTSTART
NPF40_TW_98_NT_ME_2K
NPFMESSENGER
NPROTECT
NPSCHECK
NPSSVC
NSCHED32
NSSYS32
NSTASK32
NSUPDATE
NTRTSCAN
NTXconfig
NUPGRADE
NVARCH16
NVSVC32
NWINST4
NWSERVICE
NWTOOL16
OLE-COM
OLLYDBG
ONSRVR
ooooppppqqqqrrrr
OpenProcess
OpenProcessToken
OPTIMIZE
OSTRONET
OUTPOST
OUTPOSTINSTALL
OUTPOSTPROINSTALL
PADMIN
PANIXK
PAVPROXY
PAVSCHED
pbapp.cyberdrill.my
PCC2002S902
PCC2K_76_1436
PCCCLT_MUTEX
PCCDETECT
PCCDETECT_RET
PCCIOMON
PCCNTMON
PCCWIN97
PCCWIN98
PCDSETUP
PCFWALLICON
PCIP10117_0
__p__commode
PCSCAN
PDSETUP
PERISCOPE
PERSFW
PERSWF
petronas.cyberdrill.my
__p__fmode
PFWADMIN
PGMONITR
pictures
PINGSCAN
PLATIN
POP3TRAP
Pop3trap_Splash
Pop3trap_Splash_RET
Pop3trap_Warn
Pop3trap_Warn_RET
POPROXY
POPSCAN
PORTDETECTIVE
PORTMONITOR
POWERSCAN
PPINUPDT
PPVSTOP
PQhD:@
PRCKILLER
Presentation1
PreventSecondAVGuard9x
PreventSecondAVSched32Instance
PreventSecondAVWinInstance
PRIZESURFER
PROCDUMP
Process32First
Process32Next
process explorer
process hacker
process killer
PROCESSMONITOR
PROCEXP
PROCEXPLORERV1.0
ProductId
PROGRAMAUDITOR
PROPORT
protection scan
PROTECTX
PSSSWS
ptp.cyberdrill.my
PVIEW95
PWWh0r@
pZG7* 
QCONSOLE
Qkkbal
qqqqrrrrsssstttt
QSERVER
Quarantine Console Mutex
RAPAPP
RAV7WIN
RAV8WIN32ENG
RCSYNC
.rdata
REALMONREGED
RegCloseKey
RegCreateKeyA
REGEDIT
REGEDT32
RegisterServiceProcess
registry
registry monitor
regmon
REGMON
RegOpenKeyExA
RegQueryValueExA
regrun
REGRUN
RegSetValueExA
ReleaseMutex
ReleaseSemaphore
RESCUE
RESCUE32
resource hack
rhb.cyberdrill.my
RRGUARD
rrrrssssttttuuuu	
RSHELL
RTVSCAN
RTVSCN95
RULAUNCH
RUN32DLL
RUNDLL
RUNDLL16
RunTimeDebugger
RUXDLL32
s4GKt5HLu6IMv7JN
SAFEWEB
SAHAGENT
sajholding.cyberdrill.my
SAVENOW
SBSERV
SCAM32
SCAN32
SCAN95
scan for vir
SCANPM
sc.cyberdrill.my
SCRSCAN
SCRSVR
scservice
SCVHOST
%s%d%d
SeDebugPrivilege
SERV95
SERVICE
servicess
SERVLCE
SERVLCES
SESSIONWIDE_DEF_ALERT_MUTEX_{3FD9B483-1106-4388-95A3-D8FE49D36458}
__set_app_type
SetFileAttributesA
SetThreadPriority
SETUP_FLOWPROTECTOR_US
SETUPVAMEEVAL
__setusermatherr
%s.exe
%s.EXE
sex_toy_for_men
SGSSFW32
SHELL32.dll
ShellExecuteA
SHELLSPYINSTALL
ShellWindows
%s?host=%s&state=on
SHOWBEHIND
SMSS32
Software\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\RunServices
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
span.cyberdrill.my
SPHINX
%s\ping.exe %s -l 65500 -n %i
_splitpath
SPOLER
SPOOLCV
SPOOLSV32
sprintf
SS3EDIT
%s\%s.exe
SSG_4104
SSGRATE
%s%simages\
%s\%s\mirror.exe
%s\%s\netdhcp.exe
%s%s.%s
%s\%s\services.exe
%s\%s\servicess.exe
%s\%s\%s.exe
SSV\eq
start_ddos
start_ddos_all
startuplist
STCLOADER
st.cyberdrill.my
strchr
_strlwr
_strrev
strstr
_strupr
SUPFTRL
SUPPORT
SUPPORTER5
SVCHOSTC
SVCHOSTS
SVSHOST
SVWjAY3
SWEEP95
SWEEPNET.SWEEPSRV.SYS.SWNETSUP
syabas.cyberdrill.my
symantec
Symantec.LuComServer.Running
SYMLCSVC
SYMPROXYSVC
SYM_REFRESH_AP_STATUS_EVENT
SYM_REFRESH_AUTOUPDATE_STATUS_EVENT
SYM_REFRESH_FULLSYSTEMSCAN_EVENT
SYM_REFRESH_NAVPROXY_STATUS_EVENT
SYM_REFRESH_SCRIPTBLOCKING_EVENT
SYM_REFRESH_SUBSCRIPTION_STATUS_EVENT
SYM_REFRESH_VIRUS_DEF_STATUS_EVENT
SYMTRAY
SYMWSC
SymWSC_PData_Change
SymWSC_Single_Instance_Lock
SymWSC_Terminate_Lock
SYSEDIT
SysMechanic5Mutex
SYSTEM
SYSTEM32
system configuration
SYSTEM\CurrentControlSet\Control\SafeBoot
SYSTEM\CurrentControlSet\Services\ERSvc\Enum
SYSTEM\CurrentControlSet\Services\srservice
system.ini
SYSUPD
Szczepionka_GDATA
T$4RPP
TALKBACK
taskkill
TASKKILL
task manager
TASKMG
TASKMGR
TASKMO
TAUMON
TBSCAN
TDS2-98
TDS2-NT
TEEKIDS
TerminateProcess
T$|h C@
TheFixToolSemaphore
thelover
!This program cannot be run in DOS mode.
TITANIN
TITANINXP
tm.cyberdrill.my
tnb.cyberdrill.my
tolower
T$(PRV
TRACERT
trend micro
TRICKLER
TRJSCAN
TRJSETUP
trojan ana
TROJANTRAP3
TSADBOT
TTTTUUUUVVVVWWWW
&umO'vnP(woQ)xpR
UNDOBOOT
untitled
UPDATE
UPGRAD
URLDownloadToFileA
urlmon.dll
USBUpdates
USER32.dll
User-Agent: Wget/1.11.4
Userinit
userinit.exe, %s\%s\mirror.exe
UTPOST
uuuuvvvvwwwwxxxx
VBCMSERV
VBCONS
VBWIN9X
VBWINNTW
VCSETUP
VETTRAY
VFSETUP
VIR-HELP
VIRUSMDPERSONALFIREWALL
visual basi
visual c
vmware
VNLAN300
VNPC3000
VPFW30S
vpsNew.sig
vpsUpdat.sig
VPTRAY
VSCAN40
VSCENU6.02D30
VSCHED
vsdrvevent
VSECOMR
VSHWIN32
VSISETUP
VSMAIN
vsmon_Live
vsmon_StatusUpdate
vsmon_unique
VSSTAT
vsutil_dbg
VSWIN9XE
VSWINNTSE
VSWINPERSE
vvvvwwwwxxxxyyyy
VWSPh(C@
W32DSM89
WATCHDOG
WEBDAV
WEBSCANX
WEBTRAP
WFINDV32
WGFE95
WHOSWATCHINGME
WIMMUN32
WIN32US
WINACTIVE
WIN-BUGSFIX
WINDOW
windows
WINDOWS
WindowsUpdateTracingMutex
WinExec
WININETD
WININET.dll
win.ini
WININIT
WININITX
WINLOGIN
WINMAIN
WINNET
WINPPR32
WINRECON
WINSERVN
WINSFCM
Winsock error - Socket creation Failed!
Winsock error - Winsock initialization failed
WINSSK32
WINSTART
WINSTART001
WINTSK32
WINUPDATE
WKUFIND
Woops! You are phohibited to use such skill. Be pray and patient.
workfiles
WRADMIN
WRCTRL
WritePrivateProfileStringA
WSBGATE
WSOCK32.dll
w~T:?$
WUPDATER
WYVERNWORKSFIREWALL
_XcptFilter
xmayabank.html
XPF202EN
XXXXYYYYZZZZ[[[[
*{Xy+|Yz,}Z{-~[|
young_and_dangerous
Y-Yv(^
yyyyzzzz{{{{||||
YYYYZZZZ[[[[\\\\
ZA_PANELSLOADEDEVENT
ZAPSETUP3001
ZATUTOR
ZLCommDB
ZLCommDB_mux
ZONALM2601
ZONEALARM
Zone Alarm Mutex