1-Spy

This software was tested by Avira AntiVir Premium and found infection.

Report created on 03/13/2009 07:48:25


AVPack-Version: 7.6.1.2
VDF version: 7.1.2.167 - FUP(0), created 03/13/2009

C:\TMP\DEMO.E - OK
Date: 13.03.2009 Time: 13:48:26 Size: 930438
C:\TMP\DEMO.EXE\presetup.r - OK
C:\TMP\DEMO.EXE\presetup.b - OK
C:\TMP\DEMO.EXE\presetup\License.t - OK
C:\TMP\DEMO.EXE\presetup\Readme.t - OK
C:\TMP\DEMO.EXE\plugins\0\StdUI.d - OK
C:\TMP\DEMO.EXE\plugins\0\lng\ENU.l - OK
C:\TMP\DEMO.EXE\db.p - OK
C:\TMP\DEMO.EXE\main.p - OK
C:\TMP\DEMO.EXE\lng\ENU.l - OK
C:\TMP\DEMO.EXE\Uninstall.e - OK
C:\TMP\DEMO.EXE\data\1-Spy\0\srvspon.e - OK
ALERT: [TR/Spy.Spyrecon.A.5] C:\TMP\DEMO.EXE --> data\1-Spy\1\KbdHook.dll <<< Is the Trojan horse TR/Spy.Spyrecon.A.5
C:\TMP\DEMO.EXE\data\1-Spy\2\Riched20.d - OK
ALERT: [TR/Spy.Spyrecon.A.3] C:\TMP\DEMO.EXE --> data\1-Spy\3\WinCbt.dll <<< Is the Trojan horse TR/Spy.Spyrecon.A.3
C:\TMP\DEMO.EXE\data\1-Spy\4\av2.a - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\ConfirmEmail.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\cpanel.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\general.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\help.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\intro.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\license.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\sfx.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\tools. - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\about.b - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\down.g - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\email.b - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\general.b - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\left.g - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\logging.b - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\reports.b - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\right.g - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\images\top.g - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\applications.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\applog.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\back.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\conversation.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\GeneralReport.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\home.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\imlog.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\imlog_app.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\imlog_conv.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\keyboard.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\keylog.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\screenshot.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\scrlog.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\web.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\weblog.h - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\_aim.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\_icq.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\_miranda.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\_msn.j - OK
C:\TMP\DEMO.EXE\data\1-Spy\4\view\_yahoo.j - OK


----- scan results -----
directories: 0
files: 53
alerts: 2
suspicious: 0
repaired: 0
deleted: 0
renamed: 0
scan time: 00:00:01
--------------------------
Thank you for using AntiVir



This software was tested by Dr.Web antivirus and found infection.

Report dated: 2009-03-13, 07:48:09
Engine version: 5.0.0.12182
Engine API version: 2.02
c:\tmp\Demo.exe packed by UPX
>c:\tmp\Demo.exe - archive BINARYRES
>>c:\tmp\Demo.exe\data001 - Ok
>>c:\tmp\Demo.exe\data002 - archive CAB
>>>c:\tmp\Demo.exe\data002\presetup.rgn - Ok
>>>c:\tmp\Demo.exe\data002\presetup.bmp - Ok
>>>c:\tmp\Demo.exe\data002\presetup\License.txt - Ok
>>>c:\tmp\Demo.exe\data002\presetup\Readme.txt - Ok
>>>c:\tmp\Demo.exe\data002\plugins\0\StdUI.dll - Ok
>>>c:\tmp\Demo.exe\data002\plugins\0\lng\ENU.lng - Ok
>>>c:\tmp\Demo.exe\data002\db.pdb - Ok
>>>c:\tmp\Demo.exe\data002\main.pdb - Ok
>>>c:\tmp\Demo.exe\data002\lng\ENU.lng - Ok
>>>c:\tmp\Demo.exe\data002\Uninstall.exe - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\0\srvspon.exe - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\1\KbdHook.dll - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\2\Riched20.dll - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\3\WinCbt.dll infected with Trojan.SpyRecon
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\av2.avi - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\ConfirmEmail.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.0 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.1 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.2 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.3 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.4 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.5 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm\Script.6 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\cpanel.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm\Script.0 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm\Script.1 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm\Script.2 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm\Script.3 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\general.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.0 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.1 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.2 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.3 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.4 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.5 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.6 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.7 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.8 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.9 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.10 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.11 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.12 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm\Script.13 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\help.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\intro.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\intro.htm\Script.0 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\intro.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\license.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\license.htm\Script.0 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\license.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\sfx.htm - archive HTML
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\sfx.htm\Script.0 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\sfx.htm\Script.1 - Ok
>>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\sfx.htm\Script.2 - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\sfx.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\tools.js - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\about.bmp - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\down.gif - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\email.bmp - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\general.bmp - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\left.gif - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\logging.bmp - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\reports.bmp - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\right.gif - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\images\top.gif - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\applications.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\applog.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\back.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\conversation.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\GeneralReport.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\home.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\imlog.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\imlog_app.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\imlog_conv.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\keyboard.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\keylog.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\screenshot.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\scrlog.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\web.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\weblog.htm - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\_aim.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\_icq.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\_miranda.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\_msn.jpg - Ok
>>>c:\tmp\Demo.exe\data002\data\1-Spy\4\view\_yahoo.jpg - Ok
>>c:\tmp\Demo.exe\data002 - archive contains infected objects
>c:\tmp\Demo.exe - archive contains infected objects
Scan report for "c:\tmp\Demo.exe":
Scanned: 85/84 Cured: 0
Infected found: 1/1 Deleted: 0
Modifications: 0/0 Renamed: 0
Suspicious: 0/0 Moved: 0
Adware: 0/0 Ignored: 0
Dialers: 0/0
Jokes: 0/0 Scan time: 0:00:01
Riskware: 0/0 Scan speed: 4054 Kb/s
Hacktools: 0/0 Scan ended: 7:48:13



This software was tested by Kaspersky Anti-Virus and found infection.

can_Objects$252436 starting 1%
Try delete: No
Try delete container: No
Exclude by mask: No
Include by mask: No
Objects to scan:
"c:\tmp\Demo.exe" Enable=Yes Recursive=No
------------------
c:\tmp\Demo.exe packed UPX
Scan_Objects$252436 running 50%
c:\tmp\Demo.exe//UPX archive GhostInstaller
c:\tmp\Demo.exe//UPX - OK
c:\tmp\Demo.exe archive CAB
c:\tmp\Demo.exe/presetup.rgn - OK
c:\tmp\Demo.exe/presetup.bmp - OK
c:\tmp\Demo.exe/presetup\License.txt - OK
c:\tmp\Demo.exe/presetup\Readme.txt - OK
c:\tmp\Demo.exe/plugins\0\StdUI.dll - OK
c:\tmp\Demo.exe/plugins\0\lng\ENU.lng - OK
c:\tmp\Demo.exe/db.pdb - OK
c:\tmp\Demo.exe/main.pdb - OK
c:\tmp\Demo.exe/lng\ENU.lng - OK
c:\tmp\Demo.exe/Uninstall.exe - OK
c:\tmp\Demo.exe/data\1-Spy\0\srvspon.exe - OK
c:\tmp\Demo.exe/data\1-Spy\1\KbdHook.dll detected Trojan-Spy.Win32.Spyrecon.a
c:\tmp\Demo.exe/data\1-Spy\1\KbdHook.dll skipped
c:\tmp\Demo.exe/data\1-Spy\2\Riched20.dll - OK
c:\tmp\Demo.exe/data\1-Spy\3\WinCbt.dll detected Trojan-Spy.Win32.Spyrecon.a
c:\tmp\Demo.exe/data\1-Spy\4\av2.avi - OK
c:\tmp\Demo.exe/data\1-Spy\4\ConfirmEmail.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\cpanel.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\general.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\help.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\intro.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\license.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\sfx.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\tools.js - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\about.bmp - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\down.gif - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\email.bmp - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\general.bmp - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\left.gif - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\logging.bmp - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\reports.bmp - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\right.gif - OK
c:\tmp\Demo.exe/data\1-Spy\4\images\top.gif - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\applications.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\applog.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\back.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\conversation.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\GeneralReport.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\home.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\imlog.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\imlog_app.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\imlog_conv.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\keyboard.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\keylog.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\screenshot.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\scrlog.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\web.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\weblog.htm - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\_aim.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\_icq.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\_miranda.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\_msn.jpg - OK
c:\tmp\Demo.exe/data\1-Spy\4\view\_yahoo.jpg - OK
Scan_Objects$252436 completed
--- Statistics ---
Time Start: 2009-03-13 07:48:14
Time Finish: 2009-03-13 07:48:24
Completion: 100%
Processed objects: 54
Total detected: 2
Detected exact: 2
Suspicions: 0
Treats detected: 2
Untreated: 2
Disinfected: 0
Quarantined: 0
Deleted: 0
Skipped: 0
Archived: 2
Packed: 1
Password protected: 0
Corrupted: 0
Errors: 0
Last object:
------------------

This software was tested by NOD32 antivirus and found infection.

Scanning Log
Date: 13.3.2009 Time: 07:48:08
Anti-Stealth technology is enabled.
Scanned disks, folders and files: c:\tmp\Demo.exe
c:\tmp\Demo.exe >CAB >presetup.rgn - OK
c:\tmp\Demo.exe >CAB >presetup.bmp - OK
c:\tmp\Demo.exe >CAB >presetup\License.txt - OK
c:\tmp\Demo.exe >CAB >presetup\Readme.txt - OK
c:\tmp\Demo.exe >CAB >plugins\0\StdUI.dll - OK
c:\tmp\Demo.exe >CAB >plugins\0\lng\ENU.lng - OK
c:\tmp\Demo.exe >CAB >db.pdb - OK
c:\tmp\Demo.exe >CAB >main.pdb - OK
c:\tmp\Demo.exe >CAB >lng\ENU.lng - OK
c:\tmp\Demo.exe >CAB >Uninstall.exe - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\0\srvspon.exe - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\1\KbdHook.dll - probably a variant of Win32/Spy.Agent trojan
c:\tmp\Demo.exe >CAB >data\1-Spy\2\Riched20.dll - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\3\WinCbt.dll - Win32/Spy.Spyrecon.A trojan
c:\tmp\Demo.exe >CAB >data\1-Spy\4\av2.avi - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\ConfirmEmail.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\cpanel.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\general.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\help.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\intro.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\license.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\sfx.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\tools.js - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\about.bmp - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\down.gif - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\email.bmp - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\general.bmp - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\left.gif - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\logging.bmp - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\reports.bmp - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\right.gif - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\images\top.gif - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\applications.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\applog.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\back.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\conversation.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\GeneralReport.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\home.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\imlog.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\imlog_app.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\imlog_conv.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\keyboard.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\keylog.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\screenshot.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\scrlog.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\web.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\weblog.htm - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\_aim.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\_icq.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\_miranda.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\_msn.jpg - OK
c:\tmp\Demo.exe >CAB >data\1-Spy\4\view\_yahoo.jpg - OK
c:\tmp\Demo.exe >UPX v12_m5 - OK
Number of scanned files: 53
Number of threats found: 2
Time of completion: 07:48:08 Total scanning time: 0 sec (00:00:00)

Put a free download button on your own website

1-SPY DOWNLOAD

Support 1-Spy, just copy+paste this html: