Certain Windows… stay classy…

Update 2016-07-08

Added Thinstall applications

Old post

An ability to determine the compiler used to compile a binary is quite important. It determines the way we approach the reversing session and automatically tells us what tools to use. There are many static analysis tools available that help with the determination of the compiler/linker/protector used to build a specific binary.

Sometimes it may not be enough though.

In this post I will list a number of windows-related artifacts created by various programming frameworks that may help us to determine what is the payload compiled with. While there are many of such frameworks many of them rely on a very fixed number of more-or-less hidden windows, or window classes that stay persistent across many versions of the framework, or are created at some point in time.

This is by no means an exhaustive list – if you have anything to add, or find a mistake, I will appreciate the feedback.

Note: such list may be used for many purposes:

  • compiler/protector determination
  • data reduction (from strings, or f.ex. strings recognition in IDA, if it itself failed to do so well)
  • classification (whitelisting/blacklisting) of the sandboxes samples
  • installer discovery in sandbox analysis (may trigger a different handling routine f.ex. if Auto It is detected, or any installer, low-level logging may be disabled until the actual autoir / installer script starts execution, etc.)

Here’s the list I gathered:

Visual Basic

  • ThunderRT6Main
  • VBMsoStdCompMgr
  • VBFocusRT6 (this is from Visual Basic 6.0)
  • VBBubbleRT6 (this is from Visual Basic 6.0)
  • VBFocusRT5 (this is from Visual Basic 5.0)
  • VBBubbleRT5 (this is from Visual Basic 5.0)

Visual Basic .NET

  • VBNetStudio

MFC (Microsoft Foundation Classes/Application Framework Extensions)

  • Afx:<hexadecimal number>:<hexadecimal number> f.ex. ‘Afx:400000:0’ or ‘Afx:10000000:0’
  • Afx:StatusBar:<hexadecimal number> f.ex. ‘Afx:StatusBar:400000’
  • Afx:TabWnd:<hexadecimal number> f.ex. ‘Afx:TabWnd:400000’
  • Afx:ToolBar:<hexadecimal number> f.ex. ‘Afx:ToolBar:400000’

QT

  • Qt5QWindowIcon

Installer: Install Shield

  • GLBSInstall
  • InstallShield_Win

Installer: Inno Setup

  • class name: STATIC, window name: InnoSetupLdrWindow

Enigma Protector (not confirmed)

  • TEnigmaProtectorLoaderButton
  • TEnigmaProtectorLoaderEdit
  • TEnigmaProtectorLoaderFormMessage
  • TEnigmaProtectorLoaderFormRegistration
  • TEnigmaProtectorLoaderGroupBox

RunDll32 execution

  • RunDLL

OLE/DDE Windows

  • OleMainDdeClass

AutoIt

  • AutoIt v3
  • AutoIt v3 GUI
  • Au3Info
  • AutoIt
  • AutoIt – Splash

Standard Windows controls

  • ComboBoxEx32
  • commctrl_DragListMsg
  • msctls_hotkey32
  • msctls_progress32
  • msctls_statusbar32
  • msctls_trackbar32
  • msctls_updown32
  • NativeFontCtl
  • ReBarWindow32
  • RichEdit
  • RichEdit20a
  • SysAnimate32
  • SysDateTimePick32
  • SysHeader32
  • SysIPAddress32
  • SysListView32
  • SysMonthCal32
  • SysPager
  • SysTabControl32
  • SysTreeView32
  • ToolbarWindow32
  • tooltips_class32

Thinstall applications

  • ThStatusBarCtrlClass

Others

  • mdiclient (typical class name for MDI /Multiple Document Interface/)

And last, but not least, a ‘gallery’ of classes from a number of dynamically analyzed samples written in

Borland/Delphi/etc.

  • TAbout
  • TAboutBox
  • TAboutBox1
  • TAboutDlg
  • TAboutForm
  • TAboutFrm
  • TActionMainMenuBar
  • TActionToolBar
  • TActivationForm
  • TAdminForm
  • TAdvGlassButton
  • TAdvGlowButton
  • TAdvListView
  • TAdvMemo
  • TAdvOfficePage
  • TAdvOfficePager
  • TAdvOfficeStatusBar
  • TAdvPageControl
  • TAdvProgress
  • TAdvSmoothButton
  • TAdvSmoothPanel
  • TAdvSpinEdit
  • TAdvTabSheet
  • TAdvToolBar
  • TAfterScan
  • TAnimate
  • TAnPane
  • TAppBuilder
  • TApplication
  • TBitBtn
  • TBrowserDlg
  • TBrowserForm
  • TButton
  • TButton2
  • TButtonGroup
  • TCalc
  • TCalculator
  • TCancelScan
  • TCategoryPanelGroup
  • TCentral
  • TChart
  • TChat
  • TChatWindow
  • TCheckBox
  • TCheckListBox
  • TClient
  • TClientForm
  • TCloseForm
  • TCodePanel
  • TColorBox
  • TColorButton
  • TColorGrid
  • TColorWindow
  • TComboBox
  • TComboBoxEx
  • TComComboBox
  • TConerBtn
  • TConfigForm
  • TConfigServer
  • TControlForm
  • TControllerForm
  • TCoolBar
  • TCpanel
  • TCustomDateTimePicker
  • TDateTimePicker
  • TDebugForm
  • TDesco
  • TDirectoryListBox
  • TDragArrow
  • TDrawGrid
  • TDriveComboBox
  • TDsGroupBox
  • TEdit
  • TEdit97
  • TEditForm
  • TEditListBox
  • TEditN
  • TEdits
  • TEnvWindow
  • TError
  • TExeToolForm
  • TEzHelpWindow
  • TFashionPanel
  • TFileListBox
  • TFinalFantasy
  • TFinalPws
  • TFlatButton
  • TFlatCheckBox
  • TFlatComboBox
  • TFlatEdit
  • TFlatGroupBox
  • TFlatPanel
  • TFlatRadioButton
  • TFlatSpinEditInteger
  • TFlatTitlebar
  • TFmMain
  • TFmPrincipal
  • TForm
  • TForm0
  • TForm1
  • TForm1.UnicodeClass
  • TForm10
  • TForm100
  • TForm101
  • TForm102
  • TForm103
  • TForm104
  • TForm105
  • TForm106
  • TForm107
  • TForm108
  • TForm109
  • TForm11
  • TForm110
  • TForm111
  • TForm112
  • TForm113
  • TForm114
  • TForm115
  • TForm116
  • TForm117
  • TForm118
  • TForm119
  • TForm12
  • TForm120
  • TForm121
  • TForm122
  • TForm123
  • TForm124
  • TForm125
  • TForm126
  • TForm127
  • TForm128
  • TForm129
  • TForm13
  • TForm130
  • TForm131
  • TForm132
  • TForm133
  • TForm134
  • TForm135
  • TForm136
  • TForm137
  • TForm138
  • TForm139
  • TForm14
  • TForm140
  • TForm141
  • TForm142
  • TForm143
  • TForm144
  • TForm145
  • TForm146
  • TForm147
  • TForm148
  • TForm149
  • TForm15
  • TForm150
  • TForm151
  • TForm152
  • TForm153
  • TForm154
  • TForm155
  • TForm156
  • TForm157
  • TForm158
  • TForm159
  • TForm16
  • TForm160
  • TForm161
  • TForm162
  • TForm163
  • TForm164
  • TForm165
  • TForm166
  • TForm167
  • TForm168
  • TForm169
  • TForm17
  • TForm170
  • TForm171
  • TForm172
  • TForm173
  • TForm174
  • TForm175
  • TForm176
  • TForm177
  • TForm178
  • TForm179
  • TForm18
  • TForm180
  • TForm181
  • TForm182
  • TForm183
  • TForm184
  • TForm185
  • TForm186
  • TForm187
  • TForm188
  • TForm189
  • TForm19
  • TForm190
  • TForm191
  • TForm192
  • TForm193
  • TForm194
  • TForm195
  • TForm196
  • TForm197
  • TForm198
  • TForm199
  • TForm1a
  • TForm1b
  • TForm1c
  • TForm1w
  • TForm2
  • TForm20
  • TForm200
  • TForm201
  • TForm202
  • TForm203
  • TForm204
  • TForm205
  • TForm206
  • TForm207
  • TForm208
  • TForm209
  • TForm21
  • TForm210
  • TForm211
  • TForm212
  • TForm213
  • TForm214
  • TForm215
  • TForm216
  • TForm217
  • TForm218
  • TForm219
  • TForm22
  • TForm220
  • TForm221
  • TForm222
  • TForm223
  • TForm224
  • TForm225
  • TForm226
  • TForm227
  • TForm228
  • TForm229
  • TForm23
  • TForm230
  • TForm231
  • TForm232
  • TForm233
  • TForm234
  • TForm235
  • TForm236
  • TForm237
  • TForm238
  • TForm239
  • TForm24
  • TForm240
  • TForm241
  • TForm242
  • TForm243
  • TForm244
  • TForm25
  • TForm26
  • TForm27
  • TForm28
  • TForm29
  • TForm2a
  • TForm2b
  • TForm3
  • TForm30
  • TForm31
  • TForm32
  • TForm33
  • TForm34
  • TForm35
  • TForm36
  • TForm37
  • TForm38
  • TForm39
  • TForm3a
  • TForm3b
  • TForm4
  • TForm40
  • TForm41
  • TForm42
  • TForm43
  • TForm44
  • TForm45
  • TForm46
  • TForm47
  • TForm48
  • TForm49
  • TForm4c
  • TForm4d
  • TForm5
  • TForm50
  • TForm51
  • TForm52
  • TForm53
  • TForm54
  • TForm55
  • TForm56
  • TForm57
  • TForm58
  • TForm59
  • TForm5a
  • TForm6
  • TForm60
  • TForm61
  • TForm62
  • TForm63
  • TForm64
  • TForm65
  • TForm66
  • TForm67
  • TForm68
  • TForm69
  • TForm6a
  • TForm6b
  • TForm7
  • TForm70
  • TForm71
  • TForm72
  • TForm73
  • TForm74
  • TForm75
  • TForm76
  • TForm77
  • TForm78
  • TForm79
  • TForm7w
  • TForm8
  • TForm80
  • TForm81
  • TForm82
  • TForm83
  • TForm84
  • TForm85
  • TForm86
  • TForm87
  • TForm88
  • TForm89
  • TForm9
  • TForm90
  • TForm91
  • TForm92
  • TForm93
  • TForm94
  • TForm95
  • TForm96
  • TForm97
  • TForm98
  • TForm99
  • TForm_About
  • TForm_Main
  • TForm_Options
  • TForm_Principal
  • TForm_splash
  • TForm_Undelete
  • TForm_Update
  • TFormAbout
  • TFormaTudo
  • TFormAutorun
  • TFormbb
  • TFormCreateServer
  • TFormDisclaimer
  • TFormExit
  • TFormHTML
  • TForminfo
  • TFormInstaller
  • TFormLogin
  • TFormMain
  • TFormOptions
  • TFormp
  • TFormPasswords
  • TFormPrinc
  • TFormPrincipal
  • TFormProgress
  • TFormregister
  • TFormRunning
  • TFormSetup
  • TFormShell
  • TFormSlectDir
  • TFormSplash
  • TFormUpdate
  • TFormWait
  • TFormWeb
  • TFormwebbrowser
  • TFormXInstaller
  • TFrame1
  • TFrame4
  • TFrame6
  • TFrm_check
  • TFrm_codigo
  • TFrm_Main
  • TFrmAbout
  • TFrmAd
  • TFrmAgree
  • TFrmBrad
  • TFrmCert
  • TFrmChat
  • TFrmControl
  • TFrmDownAgree
  • TFrmDownload
  • TFrmECleanDel
  • TFrmExport
  • TFrmGF
  • TFrmIDSoc
  • TFrmInit
  • TFrmLogin
  • TFrmMain
  • TFrmNewAccount
  • TFrmPass
  • TFrmPassw
  • TFrmPrincipal
  • TFrmReflet
  • TFrmSeting
  • TFrmSetup
  • TFrmSplash
  • TFrmSynNglp
  • TFrmTOKEN1
  • TFrmUpdate
  • TFrmVrfcdr
  • TFunc
  • TGeoPosition
  • TGradBtn
  • TGradPan
  • TGroupBox
  • TGroupButton
  • THeader
  • THelpForm
  • THiddenForm
  • THintWindow
  • THotButton
  • THotGroupBox
  • THotKey
  • THtmlUIForm
  • TImageForm
  • TInfobusca
  • TInfoForm
  • TInplaceEdit
  • TInstallerForm
  • TInstallForm
  • TKeyForm
  • TKeygenForm
  • TLabel
  • TLabeledEdit
  • TLayerWindow
  • TLinkLabel
  • TLinkText
  • TListBox
  • TListenForm
  • TListView
  • TLogForm
  • TLogin
  • TLogin_Form
  • TLoginForm
  • TLogo
  • TLogoForm
  • TLogonDlg
  • TLogonForm
  • TMain
  • TMain_Form
  • TMainF
  • TMainF0rmVer2
  • TMainFM
  • TMainForm
  • TMainFormVer2
  • TMainFrm
  • TMainMPRForm
  • TMainWin
  • TMainWindow
  • TManForm
  • TMaskEdit
  • TMaster
  • TMediaPlayer
  • TMemo
  • TMemoForm
  • TMenuButton
  • TMessageForm
  • TModifiedEdit
  • TMonitor
  • TMonitorForm
  • TMonthCalendar
  • TMormay1
  • TMsgForm
  • TMsgForm2
  • TMyIEButton2
  • TNetComMainFm
  • TNetWindow
  • TNewButton
  • TNewCheckListBox
  • TNewComboBox
  • TNewDiskForm
  • TNewMemo
  • TNewNotebook
  • TNewNotebookPage
  • TNewRadioButton
  • TNewStaticText
  • TNewWindow
  • TNextGrid
  • TNomeDiferente
  • TNotebook
  • TNotifierWindow
  • TNotifyForm
  • TNxButton
  • TNxPopupList
  • TNxTabSheet
  • TOleContainer
  • TOptionsForm
  • TOutline
  • TOvcfrmSplashDlg
  • TPage
  • TPageControl
  • TPageScroller
  • TPainel_Seguranca
  • TPainel_Seguranca2
  • TPanel
  • TPanels
  • TParentForm
  • TPasswordDlg
  • TPasswordForm
  • TPenWindow2
  • TPlanilha
  • TPlayForm
  • TPlaylistForm.UnicodeClass
  • TPngBitBtn
  • TPoolTemplate
  • TPortRedirForm
  • TPreviewWindow
  • TPrincipal
  • TPrnStatusForm
  • TProcessForm
  • TProgressBar
  • TProgressForm
  • TPromoForm
  • TPserver
  • TPwdForm
  • TRadioButton
  • TRadioGroup
  • TRbButton
  • TReg_Form
  • TRegForm
  • TRegHex
  • TRegisterForm
  • TRegistrationWindow
  • TRichEdit
  • TRichEditViewer
  • TRollShadow
  • TRum_
  • TRunningText
  • TRzBitBtn
  • TRzBmpButton
  • TRzButton
  • TRzButtonEdit
  • TRzButtonPair
  • TRzCheckBox
  • TRzComboBox
  • TRzEdit
  • TRzGroup
  • TRzGroupBox
  • TRzGroupButton
  • TRzMaskEdit
  • TRzPageControl
  • TRzPanel
  • TRzRadioButton
  • TRzRadioGroup
  • TRzSizePanel
  • TRzSpinButtons
  • TRzSpinEdit
  • TRzSplitter
  • TRzTabSheet
  • TRzToolbar
  • TSbookF
  • TScrollBar
  • TScrollBox
  • TScroller
  • TSecCenter
  • TSechDir
  • TSelectLanguageForm
  • TSelectWindow
  • TServerForm
  • TSetForm
  • TSettingsForm
  • TSetupForm
  • TSetupMainForm
  • TShellTreeView
  • TShowPm
  • TSiInMay
  • TSkin
  • TSpinButton
  • TSpinEdit
  • TSpinEdit2
  • TSplash
  • TSplashForm
  • TSplashScreen
  • TStaticText
  • TStatusBar
  • TStatusForm
  • TStoringComboBox
  • TStringGrid
  • TStubForm
  • TSupervisor
  • TSynBaseCompletionProposalForm
  • TSynMemo
  • TSystemUpdateService
  • TTabControl
  • TTabPage
  • TTabSet
  • TTabSheet
  • TTabSheetes
  • TTeButton
  • TTeCustomTabSheet
  • TTePanel
  • TTeSEdit
  • TTestForm
  • TTeTabSheet
  • TTetro1
  • TTipForm
  • TToolBar
  • TToolbar97
  • TTrackBar
  • TTransEdit
  • TTransMemo
  • TTreeView
  • TTurcaButton
  • TUnidadU
  • TUnzipPanel
  • TUpdateForm
  • TUpdateFrm
  • TUpDown
  • TUpIpDate
  • TVeeImageButton
  • TVideoWindow
  • TViewForm
  • TVrDemoButton
  • TWaitForm
  • TWarningForm
  • TWelcome
  • TWinApiWnd
  • TWinControl
  • TWindowDisabler-Window
  • TWinForm
  • TWinMain
  • TWizardForm
  • TWizButton
  • TWizDropDownPanel
  • TWnForm

Real coders code in Au3

In my old post about malware writers I mentioned that lots of them code in VB, Today I will explore the topic that has not been explored before – Autoit malware authors. Luckily (or not), Autoit preserves paths to original Autoit script inside some of the compiled Autoit .exes. As a result.. we can decompile these scripts and get an insight into the hard drives of the bad doers…

So.. without further ado… this is how it looks like – see below.

Note: some of these paths may be legitimate, this is from a large sampleset that may contain ‘clean’ legitimate files, also, note the presence of many languages: French, Spanish, German, English, Traditional Chinese, Vietnamese, Turkish:

C:\Documents and Settings\Abdullah\My Documents\AU3\fservice.au3
C:\Documents and Settings\Administrador\Escritorio\Run.au3
C:\Documents and Settings\Administrateur\Bureau\Nouveau AutoIt v3 Script.au3
C:\Documents and Settings\Administrator\Desktop\Auto Scripts\Win.au3
C:\Documents and Settings\Administrator\Desktop\AutoSplash\autosplash.au3
C:\Documents and Settings\Administrator\Desktop\CUOICUNG.au3
C:\Documents and Settings\Administrator\Desktop\Minh-programing\maya\ambr.au3
C:\Documents and Settings\Administrator\Desktop\New Folder\telnet_batch.au3
C:\Documents and Settings\Administrator\Desktop\Portable Apps Creation Master 1.6\Portable Apps Creation Master 1.6.au3
C:\Documents and Settings\Administrator\Desktop\RARDAN YAPMA.au3
C:\Documents and Settings\Administrator\Desktop\SRO Server\EnCodeIt 2.0\SRO AutoLoginAutoParty v1.97_EnCoded1.au3
C:\Documents and Settings\Administrator\Desktop\Total Uninstall 4.6.2\%ProgramFilesDir%\Total Uninstall 4\RARDAN YAPMA.au3
C:\Documents and Settings\Administrator\Desktop\mokka\mythwarbot.au3
C:\Documents and Settings\Administrator\Desktop\thunghiem.au3
C:\Documents and Settings\Administrator\Desktop\vd.au3
C:\Documents and Settings\Administrator\Desktop\wtf.au3
C:\Documents and Settings\Administrator\Desktop\wupdate.au3
C:\Documents and Settings\Administrator\Local Settings\Temp\aus.au3
C:\Documents and Settings\Administrator\My Documents\Autoit V3\Include\Constants.au3
C:\Documents and Settings\Administrator\My Documents\Autoit V3\Include\Process.au3
C:\Documents and Settings\Administrator\My Documents\test.au3
C:\Documents and Settings\Administrator\桌面\DAEMON Tools Pro\Daemon Tools.au3
C:\Documents and Settings\Administrator\桌面\DAEMON Tools2\setup.au3
C:\Documents and Settings\Administrator\桌面\Wopti\install.au3
C:\Documents and Settings\Administrator\桌面\無背景+運行遊戲+無計時器(右上角)@ㄚ超X10\背景+運行遊戲+無計時器(右上角)@ㄚ超X10.au3
C:\Documents and Settings\Administrator\衯?蝃岓\蓏慺 昑糨\AutoIt v3 Script 昑糨.au3
C:\Documents and Settings\Administrator\袤醱\55.au3
C:\Documents and Settings\Administrator\袤醱\5avip_Obfuscated.au3
C:\Documents and Settings\Administrator\袤醱\StartRun6.4埭鎢\StartRun6.4埭鎢\ok赻雄堍俴馱撿6.4.au3
C:\Documents and Settings\Administrator\袤醱\new.au3
C:\Documents and Settings\Administrator\袤醱\pubwin2007 翑忒_Obfuscated.au3
C:\Documents and Settings\Administrator\袤醱\qq.au3
C:\Documents and Settings\Administrator\袤醱\setup.au3
C:\Documents and Settings\Administrator\袤醱\CGO2043赻雄境婥嗣攫\disk2.au3
C:\Documents and Settings\Administrator\袤醱\刉壺掛最唗.au3
C:\Documents and Settings\Administrator\袤醱\厙壽遙\LineSwh.au3
C:\Documents and Settings\Administrator\袤醱\陔膘 AutoIt3褐掛.au3
C:\Documents and Settings\All Users\Documenti\valid wg\File per autoit\Setup.au3
C:\Documents and Settings\All\Desktop\Autoit\TUL.au3
C:\Documents and Settings\Barbara\Desktop\X-SumatraPDF_source_rev3\X-SumatraPDF.au3
C:\Documents and Settings\Barbara\Desktop\X-SumatraPDF_source_rev3\x-launcher.au3
C:\Documents and Settings\Barbara\Desktop\X-SumatraPDF_source_rev3\x-udf.au3
C:\Documents and Settings\Beliar\Desktop\tare rau.au3
C:\Documents and Settings\BrOnZ\Desktop\PlayerPlus\PlayerPlus\Real Player.v11.0.0167.Plus.Beta\Pach_Real.au3
C:\Documents and Settings\Cedega\My Documents\downloads\run-tvc.au3
C:\Documents and Settings\Chef\Desktop\Stuff\v2.08\hhc hotkeys v2.au3
C:\Documents and Settings\Dizzy\Desktop\bots\Copy of Dizzy’s DL Bot 2.0 .au3
C:\Documents and Settings\Eniko\Desktop\decompilat.au3
C:\Documents and Settings\Fast3r\Plocha\AU3\SroTools\options2.au3
C:\Documents and Settings\FeFe BoSs\Desktop\fefe.au3
C:\Documents and Settings\Frognik\FuckKO v0.5\FuckKO.au3
C:\Documents and Settings\Fta&Ebru\Desktop\Yenlogmeini Klas顤 (2)\2.au3
C:\Documents and Settings\GPC\Desktop\11\auto.au3
C:\Documents and Settings\Gabe\Desktop\my-autoit\aurastack.au3
C:\Documents and Settings\GodsPerfectBeing\My Documents\AU3 in progress\ServerSwitch.au3
C:\Documents and Settings\GodsPerfectBeing\My Documents\AU3 in progress\spambot.au3
C:\Documents and Settings\H\Desktop\hans’s\Auto-it projects\Loader\InjectDLL.au3
C:\Documents and Settings\H\Desktop\hans’s\Auto-it projects\Loader\Loader.au3
C:\Documents and Settings\Hai Long\Desktop\Robots.au3
C:\Documents and Settings\HaxLi\Desktop\wm\JoyToKey.au3
C:\Documents and Settings\ILHAN\Desktop\kurprog.au3
C:\Documents and Settings\JOHN & NEO\Desktop\Explorer.au3
C:\Documents and Settings\JOHN & NEO\Desktop\da.au3
C:\Documents and Settings\Jeff Tan\Desktop\Pinnacle.au3
C:\Documents and Settings\Jonas\Skrivbord\Kopia av loader\Loader\Loader\Loader.au3
C:\Documents and Settings\Joshua Taylor\Desktop\KeyLog\KeyLog\KeyLog.au3
C:\Documents and Settings\Joshua Taylor\Desktop\KeyLog\KeyLog\hotmail.au3
C:\Documents and Settings\Joshua Taylor\Desktop\KeyLog\KeyLog\readfile.au3
C:\Documents and Settings\KLOUDJ\Desktop\programs\TechPol.au3
C:\Documents and Settings\Kissy\Desktop\My-AutoIt\Gondus’s Crumble Undead Bot.au3
C:\Documents and Settings\Kyle\Desktop\glider key.au3
C:\Documents and Settings\Le Dinh Thanh\Desktop\zin.au3
C:\Documents and Settings\Le Quang Trung\Desktop\enet.au3
C:\Documents and Settings\MARD\Desktop\Pinnacle.au3
C:\Documents and Settings\Matthew1\Desktop\Scolex RavMonE Eliminator\Scolex RavMonE Eliminator.au3
C:\Documents and Settings\Mohamed\Desktop\2\New AutoIt v3 Script.au3
C:\Documents and Settings\Niels Maerten\Mijn documenten\Miniscripts\sytemlock.au3
C:\Documents and Settings\OWNER\Desktop\cmdhide.au3
C:\Documents and Settings\Philip\Desktop\TB.au3
C:\Documents and Settings\Piotr\Pulpit\Pipen’s BOTS\COMBO BOT[release]\Pinnacle.au3
C:\Documents and Settings\Propriétaire\Bureau\Rayuran Project!\gui_Obfuscated.au3
C:\Documents and Settings\Radek\Pulpit\combo\combo.au3
C:\Documents and Settings\Radevic\Desktop\test\Update.au3
C:\Documents and Settings\Radevic\Desktop\test\update.au3
C:\Documents and Settings\RiCK\My Documents\My AutoIt v3 Scripts\DJ Auto Bot Remote Control\DJ Auto Bot Remote Control 2.au3
C:\Documents and Settings\Ruud\Bureaublad\0.4\OEMLOGO.au3
C:\Documents and Settings\Ruud\Bureaublad\0.4\oem_uninst.au3
C:\Documents and Settings\Ryan\Desktop\AutoItMultiTool\MultiTool.au3
C:\Documents and Settings\Sange\Desktop\aaaaaaaaa.au3
C:\Documents and Settings\Sange\Desktop\g.au3
C:\Documents and Settings\SomeGUy\Desktop\Downloads\GaiaAutoFisher [Red Bait].au3
C:\Documents and Settings\Student_net\My Documents\tkv.au3
C:\Documents and Settings\TSXP\Desktop\sound forge 10.au3
C:\Documents and Settings\TnC\Desktop\Lis\lisans.au3
C:\Documents and Settings\Tony\Desktop\runie.au3
C:\Documents and Settings\USER\迂?轻氵嗜\Computers\AutoIt v3 Script 滔硐.au3
C:\Documents and Settings\User\Desktop\yahoo.au3
C:\Documents and Settings\WelCome\Desktop\IEXPLORE.au3
C:\Documents and Settings\Whw\Local Settings\Temp\aus.au3
C:\Documents and Settings\XMS\Desktop\Scripts\Universal Portable Script.au3
C:\Documents and Settings\XPPRESP3.USER\Desktop\AutoBuffEnglishVer.au3
C:\Documents and Settings\XTZJ\袤醱\xpset1\ChangeScreenRes.au3
C:\Documents and Settings\XTZJ\袤醱\xpset1\xpset.au3
C:\Documents and Settings\abde\Desktop\Logger file\Startup.au3
C:\Documents and Settings\akoutsouradis\My Documents\Scripts\AutoIt\Message.au3
C:\Documents and Settings\cface\袤醱\陎諾荌埏赻雄腎翻\3.au3
C:\Documents and Settings\cuong@\Desktop\svchost3333.au3
C:\Documents and Settings\cuong@\Desktop\svchost68.au3
C:\Documents and Settings\cuong@\My Documents\svchost64.au3
C:\Documents and Settings\cuongadsl\Desktop\vuive\ads2.au3
C:\Documents and Settings\danger\Desktop\x4x.au3
C:\Documents and Settings\dbaez\Escritorio\scripts\TCS_settings_server.au3
C:\Documents and Settings\deh0448\My Documents\asdf.au3
C:\Documents and Settings\eric\Bureau\Caderix\scripts\Transparency2.5.au3
C:\Documents and Settings\h\Desktop\IEXPLORE.au3
C:\Documents and Settings\h\Desktop\fuckall.au3
C:\Documents and Settings\huycuong\My Documents\111.au3
C:\Documents and Settings\jackal\夥鰻 賊\kmp.au3
C:\Documents and Settings\lwc\袤醱\QQ躇鎢hash硉蛌MD5.au3
C:\Documents and Settings\manage\袤醱\Gpedit\CheckPWD.au3
C:\Documents and Settings\manage\袤醱\Gpedit\System Optimize Tools.au3
C:\Documents and Settings\nabreu\Ambiente de trabalho\Share\Bots\Bot K2 DL\Pinnacle.au3
C:\Documents and Settings\nhatquanglan\Desktop\cuoicung.au3
C:\Documents and Settings\nhatquanglan\Desktop\vietlai.au3
C:\Documents and Settings\nn\Desktop\test.au3
C:\Documents and Settings\pash-TET.PASHA\Desktop\123.au3
C:\Documents and Settings\pash-TET.PASHA\Desktop\1233213.au3
C:\Documents and Settings\pc\Desktop\PersonalScreenRes-Install.au3
C:\Documents and Settings\phuong anh\Desktop\CUOICUNG.au3
C:\Documents and Settings\phuong anh\Desktop\nhatquanglan.au3
C:\Documents and Settings\phuong anh\Desktop\nhatquanglan_Obfuscated.au3
C:\Documents and Settings\rallen\Desktop\Extend.au3
C:\Documents and Settings\robotics\Desktop\New Folder\Aggro\ABv0.2\AggroBotv0.23.au3
C:\Documents and Settings\rsarner\Desktop\ROnce.AU3
C:\Documents and Settings\s0uLtaker\My Documents\Archlord Stuff\bot\auto IT\MSN.au3
C:\Documents and Settings\tence\Bureau\KAV\autoit\kasperskys-cd-modif3.au3
C:\Documents and Settings\than sau\Desktop\Tu buff silkroad v1.01.au3
C:\Documents and Settings\thuy\Desktop\kill.au3
C:\Documents and Settings\thuy\Desktop\popup web an.au3
C:\Documents and Settings\trung\My Documents\YIMBot\dkc.au3
C:\Documents and Settings\truong nhat\Desktop\CUOICUNG.au3
C:\Documents and Settings\truong nhat\Desktop\nhatquanglan.au3
C:\Documents and Settings\truong nhat\Desktop\nhatquanglan_Obfuscated.au3
C:\Documents and Settings\viet\Desktop\love.au3
C:\Documents and Settings\weibaichi\袤醱\123.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\Include\array.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\core.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\File.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\IRC.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\config.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\iNet.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\im.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\lang.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\os.au3
C:\Documents and Settings\x0wner\Desktop\florida\PuffBotv1.03-priv(1)\include\uptime.au3
C:\Documents and Settings\xp xp\衯?蝃岓\彶 衯?蝃岓\蓏慺 昑糨\AutoIt v3 Script 昑糨.au3
C:\Documents and Settings\xp xp\衯?蝃岓\蓏慺 昑糨\AutoIt v3 Script 昑糨.au3
C:\Documents and Settings\選顫葬\夥鰻 賊\portable URLSnooper\portable URLSnooper\test.au3
C:\Documents and Settings\轉儰餤冓搿玁?嚦鎀\Mad Dog.au3
C:\Documents and Settings\拸窩\袤醱\Search.au3
C:\Documents and Settings\拸窩\袤醱\UX-theme-patcher\Path.au3
C:\Documents and Settings\拸窩\袤醱\UX-theme-patcher\Restore.au3
C:\Documents and Settings\拸窩\袤醱\qqq.au3
C:\Documents\Scripts\Flickr AutoDownloadr\FAD frontend.au3
C:\Dokumente und Einstellungen\8\Desktop\Dupe AccHack\Starter.au3
C:\Dokumente und Einstellungen\8\Desktop\Dupe AccHack\csrss.au3
C:\Dokumente und Einstellungen\Administrator\Desktop\Botnew\Packs\2\1Original\Kopie von Bot.au3
C:\Dokumente und Einstellungen\Administrator\Desktop\Botnew\Packs\5\Allok.AVI.to.DVD.SVCD.VCD.Converter.v2.1.4.WinAll.Regged-EiTheL\1Original\Kopie von Bot.au3
C:\Dokumente und Einstellungen\Administrator\Desktop\Botnew\Packs\AAF\Adobe Creative Suite 2 Keygen (Photoshop Cs2, Illustrator Cs2, Golive Cs2, More)\1\Kopie von Bot.au3
C:\Dokumente und Einstellungen\Administrator\Desktop\Botnew\Packs\AAF\Adobe Photoshop CS2 9.0 Final Keygen & Acitvater\1\Kopie von Bot.au3
C:\Dokumente und Einstellungen\Administrator\Desktop\P_NAB_source\looter.au3
C:\Dokumente und Einstellungen\Besitzer\Desktop\tools\lossbot\blubtmo_lossbot1.20.au3
C:\Dokumente und Einstellungen\Daniel\Desktop\Fertige Bots\High End\Schoko愀 Bot\Data\IG5.au3
C:\Dokumente und Einstellungen\Daniel\Desktop\Fertige Bots\High End\Schoko愀 Bot\Data\IG6.au3
C:\Dokumente und Einstellungen\IroX\Desktop\PiroX B0t\pirox.au3
C:\Dokumente und Einstellungen\Keller.Florian\Desktop\copy.au3
C:\Dokumente und Einstellungen\Lumsk\Desktop\Botnew\Family Keylogger\Family Keylogger v2.80 with Crack\Limewire.au3
C:\Dokumente und Einstellungen\Sirus\Desktop\1 click Flasher\test.au3
C:\Dokumente und Einstellungen\fearlumsk\Desktop\Bot\Bot\CLIENT.au3
C:\Dokumente und Einstellungen\fearlumsk\Desktop\Bot\Bot\IRCJoinNew.au3
C:\Dokumente und Einstellungen\fearlumsk\Desktop\Bot\Bot\IRCJoinNew2.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\Include\array.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\core.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\File.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\IRC.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\config.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\iNet.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\im.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\lang.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\os.au3
C:\Dokumente und Einstellungen\root\Desktop\spread\include\uptime.au3
C:\Users\Admin\Desktop\sss.au3
C:\Users\Administrator\Desktop\qwee.au3
C:\Users\Administrator\Documents\Projekte\Zeiss\CZ – Enterprise Discovery\WinEDMSG\Version 1.1.0\SOURCE\WinEDMsg.au3
C:\Users\BossTheTuga\AppData\Local\Temp\loaderstub.au3
C:\Users\Brunno\Desktop\antileecher.au3
C:\Users\Dhilip\Desktop\WGAN_Rmvr2.au3
C:\Users\Forever2008\Desktop\PORTABLE PhotoshopCS4 By ForeverXP\Iniciar.au3
C:\Users\John\Documents\Portable Software\AviScreenPortable\Other\AviScreen Portable Source\AutoItTemplate.au3
C:\Users\John\Documents\Portable Software\AviScreenPortable\Other\AviScreen Portable Source\AviScreenPortable.au3
C:\Users\John\Documents\Portable Software\AviScreenPortable\Other\AviScreen Portable Source\BatchExec.au3
C:\Users\John\Documents\Portable Software\AviScreenPortable\Other\AviScreen Portable Source\Registry.au3
C:\Users\MediaDogg\Desktop\GUI-055xDev\CopyGui.au3
C:\Users\MediaDogg\Desktop\GUI-055xDev\FilterGUI.au3
C:\Users\MediaDogg\Desktop\GUI-055xDev\GUI-057x.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\7Zip.au3″ , EXECUTE ( $A0D0F612E41 ) & “\7Zip.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\FTP.au3” , EXECUTE ( $A180F81360F ) & “\FTP.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\Security.au3” , EXECUTE ( $A0EFE21213D ) & “\Security.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\SecurityConstants.au3” , EXECUTE ( $A280F21305C ) & “\SecurityConstants.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\SendMessage.au3” , EXECUTE ( $A58FEE14E3B ) & “\SendMessage.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\StructureConstants.au3” , EXECUTE ( $A4B0F013758 ) & “\StructureConstants.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\WinAPI.au3” , EXECUTE ( $A480FC13826 ) & “\WinAPI.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\WindowsConstants.au3” , EXECUTE ( $A350FE11B29 ) & “\WindowsConstants.au3
C:\Users\NURZA\Desktop\Albator MDP Stealer\file.au3” , EXECUTE ( $A580F41111C ) & “\file.au3
C:\Users\Owner\Desktop\Deploy.au3
C:\Users\Paul\Desktop\OneKey\closeKms.au3
C:\Users\S & M\Desktop\RDK\RDK.au3
C:\Users\searchengine\Desktop\Display.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\Include\array.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\core.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\File.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\IRC.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\config.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\iNet.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\im.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\lang.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\os.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\uptime.au3
C:\Users\slipo\Documents\Mis archivos recibidos\[HitX]\[HitX]\include\usb.au3
C:\Users\volkan\Desktop\4.au3
C:\Users\zouhir\Desktop\haching\Nouveau AutoIt v3 Script.au3