Gen.Variant.Adware.ConvertAd.78_536a67b3d6
Gen:Variant.Adware.ConvertAd.78 (BitDefender), not-a-virus:HEUR:AdWare.Win32.ConvertAd.gen (Kaspersky), ConvertAd (VIPRE), Adware.ConvertAd.94 (DrWeb), Gen:Variant.Adware.ConvertAd.78 (B) (Emsisoft), Artemis!536A67B3D6DB (McAfee), Trojan.Gen.2 (Symantec), Gen:Variant.Adware.ConvertAd (FSecure), Generic6.CMAO (AVG), NSIS:ConvertAd-C [Adw] (Avast), Gen:Variant.Adware.ConvertAd.78 (AdAware), Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 536a67b3d6db52e954f1887e80493230
SHA1: b7b776fbde77e3145bbbdd6d6be3e37f6f8c4f3f
SHA256: 08b8b48ef3816cbb1c14607699d49cf140bf97a43a46ad41186a1e0fce5d4a45
SSDeep: 24576:gKyfm2A4lvL4SwhJy8v4Mj10D7gAkA4ddkxMu:gKKA42SCJTDj D7JkV2
Size: 829723 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Mail.Ru
Created at: 2009-12-06 00:50:52
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
nss279D.tmp:2340
%original file name%.exe:1968
nsn82D.tmp:544
nsy470F.tmp:1668
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process nss279D.tmp:2340 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\WmiInspector.dll (2840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS1JHSL\stats[1].htm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30EV4AVE\Note-UP_Setup[1].exe (3920 bytes)
%Program Files%\96224D56-1493474771-85B6-3678-738E10744E8C\vnsn6B4.tmp (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\heu39T.nss (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\Uninstall.exe (1610 bytes)
%Program Files%\96224D56-1493474771-85B6-3678-738E10744E8C\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\NUIns.exe (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\IpConfig.dll (3440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnEF27.tmp (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn82D.tmp (5224 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\WmiInspector.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy46E.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi827D.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy5AA.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy885C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn78F.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss83A7.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy880D.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn89F7.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy44C1.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsiEEB8.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnEF27.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn4CC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\inetc.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\System.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi889B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx459A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd8AF2.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi8368.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\IpConfig.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnED9B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnEE49.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsyEE79.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi8939.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss8978.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn89A8.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdEEE8.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd88CB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi40F.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd87DD.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn7DE.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi45DA.tmp (0 bytes)
%Program Files%\96224D56-1493474771-85B6-3678-738E10744E8C\nsn6B4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi47BE.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst53B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd4210.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss3504.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd57A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsdEE0A.tmp (0 bytes)
The process %original file name%.exe:1968 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss279D.tmp (29490 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn25A9.tmp (0 bytes)
The process nsn82D.tmp:544 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy470F.tmp (143993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\318DR7NG\sqOgQjP0[1] (135838 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\INetC.dll (53 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\INetC.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\System.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsi46B0.tmp (0 bytes)
The process nsy470F.tmp:1668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Note-Up.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Note-Up.lnk (1 bytes)
%Program Files%\Note-up\Note-up.exe (137267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\FindProcDLL.dll (63 bytes)
%Program Files%\Note-up\uninstall.exe (1686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\ProcessKiller.dll (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\InvokeShellVerb.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\System.dll (23 bytes)
%Program Files%\Note-up\Note-up.ico (2104 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy6BEC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\FindProcDLL.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\ProcessKiller.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\InvokeShellVerb.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\System.dll (0 bytes)
Registry activity
The process nss279D.tmp:2340 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\System\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies]
"(Default)" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"source" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad]
"WpadLastNetwork" = "{24C5EDBC-2851-452A-B521-5DA992F6C1B5}"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASAPI32]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"ConsoleTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecision" = "3"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecisionTime" = "70 B9 95 A5 F1 C0 D2 01"
[HKLM\System\CurrentControlSet\Services\NlaSvc]
"pname" = "NU"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"FileTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecision" = "3"
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"DisplayName" = "Note-UP"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASAPI32]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"UninstallString" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\Uninstall.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 36 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASAPI32]
"FileDirectory" = "%windir%\tracing"
"MaxFileSize" = "1048576"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadNetworkName" = "Network 2"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASAPI32]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"Publisher" = "QUAHOG LIMITED"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecisionReason" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"stats" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings" = "46 00 00 00 09 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASAPI32]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\nss279D_RASMANCS]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecisionTime" = "70 B9 95 A5 F1 C0 D2 01"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NUIns]
"DisplayIcon" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\Uninstall.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
The process nsn82D.tmp:544 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASMANCS]
"FileTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASAPI32]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASAPI32]
"EnableConsoleTracing" = "0"
"MaxFileSize" = "1048576"
"FileTracingMask" = "4294901760"
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASMANCS]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 37 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\nsn82D_RASMANCS]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
The process nsy470F.tmp:1668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"Favorites" = "00 7C 01 00 00 14 00 1F 80 C8 27 34 1F 10 5C 10"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"@zipfldr.dll,-10148" = "Compressed (zipped) folder"
[HKCR\*\shell\Add event reminder\command]
"(Default)" = "%Program Files%\Note-up\Note-up.exe /addnew"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"@sendmail.dll,-21" = "Desktop (create shortcut)"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesVersion" = "2"
[HKCR\DesktopBackground\shell\Add event reminder]
"Icon" = "%Program Files%\Note-up\Note-up.ico"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"LanguageList" = "en-US, en"
[HKCR\*\shell\Add event reminder]
"Icon" = "%Program Files%\Note-up\Note-up.ico"
[HKCR\DesktopBackground\shell\Add event reminder\command]
"(Default)" = "%Program Files%\Note-up\Note-up.exe /addnew"
[HKCR\Directory\Background\shell\Add event reminder]
"Icon" = "%Program Files%\Note-up\Note-up.ico"
[HKCR\Directory\Background\shell\Add event reminder\command]
"(Default)" = "%Program Files%\Note-up\Note-up.exe /addnew"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E\@C:\Windows\system32]
"FXSRESM.dll,-120" = "Fax recipient"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Note-up]
"DisplayName" = "Note-up"
[HKLM\System\CurrentControlSet\Services\NlaSvc]
"DCGUID" = "{4EDE2466-03AA-49AD-AEE5-E51212EE54D3}"
[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"@sendmail.dll,-4" = "Mail recipient"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesChanges" = "9"
[HKCR\Directory\shell\Add event reminder\command]
"(Default)" = "%Program Files%\Note-up\Note-up.exe /addnew"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\ProcessKiller.dll,"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband]
"FavoritesResolve" = "CC 02 00 00 4C 00 00 00 01 14 02 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Note-up]
"DisplayIcon" = "%Program Files%\Note-up\Note-up.ico"
"Publisher" = "Note-up"
"UninstallString" = "%Program Files%\Note-up\uninstall.exe"
[HKCR\Directory\shell\Add event reminder]
"Icon" = "%Program Files%\Note-up\Note-up.ico"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Note-up" = "%Program Files%\Note-up\note-up.exe /watch"
Dropped PE files
| MD5 | File path |
|---|---|
| 93d73f2ecc2f85d273cda2ee51a617ec | c:\Program Files\96224D56-1493474771-85B6-3678-738E10744E8C\Uninstall.exe |
| 662b7f1d298641b54633d7f009dbfc2d | c:\Program Files\96224D56-1493474771-85B6-3678-738E10744E8C\vnsn6B4.tmp |
| bf3a1f2c03d10e52096f24c664376869 | c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30EV4AVE\Note-UP_Setup[1].exe |
| bf3a1f2c03d10e52096f24c664376869 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn82D.tmp |
| 662b7f1d298641b54633d7f009dbfc2d | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss279D.tmp |
| 662b7f1d298641b54633d7f009dbfc2d | c:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\NUIns.exe |
| 93d73f2ecc2f85d273cda2ee51a617ec | c:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\Uninstall.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 23628 | 24064 | 4.46394 | 856b32eb77dfd6fb67f21d6543272da5 |
| .rdata | 28672 | 4764 | 5120 | 3.4982 | dc77f8a1e6985a4361c55642680ddb4f |
| .data | 36864 | 154712 | 1024 | 3.3278 | 7922d4ce117d7d5b3ac2cffe4b0b5e4f |
| .ndata | 192512 | 581632 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 774144 | 1736 | 2048 | 2.02623 | 83273b1c3bdb7ebe27cef608a0858478 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 40
eb1032a08483c4d095a250e75492a13f
71374a91eaa75ffa779c5ed8f4174757
8ebc71a54fc8d5ee5e4904bf4ef9f080
dc87006e7db9fb740cfe7c0d8ac9e28e
e7c1e72a790ad0c10f68f099d8b9e4dd
2683a9efc372be7dfe3a3f67da983024
1492238fda0596d4efac02f7f6c2efac
a532ab238a3690b18ee3f7d4c7cfec8f
2c5be92aae016e597a9a11a3a5a0ee36
eddb2e41b01b350666797b9c75d43746
86c320d9d447e942a71402b0f7238178
034b3a9b6eac0d67d71db03780b3f713
9a10bdc03ac8b496ed79b9e4c1044583
2fbd6c5f307e8f8d1f44d7af4163c21b
f628c78ec9aeecccac5647875d2a33a1
1630fd98e2970e1c2bcdd5678bbc27f6
a530cfe903ef02bd90d34817288e9148
1df0ddfbf78ac093abb4855bde043910
d85dacdd5efb06b225e71c83751b3881
1cc7e1d1914395779c132741013607ab
4a02a39bcc7080ee889452957981ee9f
27a2cfcf30b3dc6857a38a54e39a102a
921e7219d9419478ba98d0e9d92c2a0e
54a62692739b8ace376f7479fe4c2b4f
d915e90dc737adcd9059afa56bd7755c
URLs
| URL | IP |
|---|---|
| hxxp://livestatscounter.com/countstats/count.php | |
| hxxp://livestatscounter.com/vuupc/stats.php | |
| hxxp://d16hr9n7t75k58.cloudfront.net/Note-UP_Setup.exe | |
| hxxp://livestatscounter.com/SysInfo/dl-noteup.php?sid=1493474787792 | |
| dns.msftncsi.com | |
| teredo.ipv6.microsoft.com | |
| ibf-cmi-1938953175.us-east-1.elb.amazonaws.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
ET POLICY PE EXE or DLL Windows file download HTTP
ET POLICY Executable served from Amazon S3
Traffic
GET /SysInfo/dl-noteup.php?sid=1493474787792 HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: livestatscounter.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.8.1
Date: Sat, 29 Apr 2017 14:06:30 GMT
Content-Type: application/octet-stream
Content-Length: 2481833
Connection: keep-alive
X-Powered-By: PHP/5.5.32
Content-Transfer-Encoding: binary
Content-Disposition: attachment; filename=sqOgQjP0MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^...........0.......p....@.........
.................................................................t....
......xU..............................................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@..@.data...X\......
.....v..............@....ndata...................................rsrc.
..xU.......V...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
.h.B..H.P.u..u..u...Hr@..B...SV.5p.B..E.WP.u...Lr@..e...E..E.P.u...Pr@
..}..e....Dp@........FR..VV..U... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@..E...E.P.E.P.u...Tr@..u
....E..9}...w....~X.te.v4..Lp@....E.tU.}.j.W.E......E.......Pp@..vXW..
Tp@..u..5Xp@.W...E..E.h ...Pj.h`.B.W..Xr@..u.W...u....E.P.u...\r@._^3.
[.....L$....B...Si.....VW.T.....tO.q.3.;5..B.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5..B.r._^[...U..QQ.U.SV..i....<<< skipped >>>
GET /countstats/count.php HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: livestatscounter.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Server: nginx/1.8.1
Date: Sat, 29 Apr 2017 14:05:27 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.5.320..HTTP/1.1 404 Not Found..Server: nginx/1.8.1..Date: Sat, 29 Apr 2017
14:05:27 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Co
nnection: keep-alive..X-Powered-By: PHP/5.5.32..0......
GET /vuupc/stats.php HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: livestatscounter.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.8.1
Date: Sat, 29 Apr 2017 14:06:10 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.5.32e..13941474770LP4..0..HTTP/1.1 200 OK..Server: nginx/1.8.1..Date: Sat,
29 Apr 2017 14:06:10 GMT..Content-Type: text/html..Transfer-Encoding:
chunked..Connection: keep-alive..X-Powered-By: PHP/5.5.32..e..1394147
4770LP4..0..
GET /Note-UP_Setup.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: d16hr9n7t75k58.cloudfront.net
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Content-Type: application/x-msdownload
Content-Length: 68745
Connection: keep-alive
Date: Sat, 29 Apr 2017 10:49:13 GMT
Last-Modified: Wed, 18 May 2016 15:44:58 GMT
ETag: "bf3a1f2c03d10e52096f24c664376869"
Accept-Ranges: bytes
Server: AmazonS3
Age: 11824
X-Cache: Hit from cloudfront
Via: 1.1 e4a44efc4b3241dc23019df63a1f645c.cloudfront.net (CloudFront)
X-Amz-Cf-Id: 47d18cI31izWlsfbQm5Nu_Ppp769b3ysywNqOBc-bQ3KaYpJ516jYg==MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8
...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8.......
.PE..L.....GO.................t...z...B...8............@..............
.........................@.................................@..........
......................`...............................................
........................................text....r.......t.............
..... ..`.rdata..n .......,...x..............@..@.data.... ...........
...............@....ndata...................................rsrc......
.........................@..@.reloc..............................@..B.
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U....\.}..t .}.F.E.u..H
......G..H.P.u..u..u.....@..K...SV.5..G.W.E.P.u.....@..e...E..E.P.u...
..@..}..e....D.@........FR..VV..U... M..........M........E...FQ.....NU
..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.
P.u.....@..u....E..9}...n....~X.te.v4..L.@..E...tU.}.j.W.E......E.....
..P.@..vXW..T.@..u..5X.@.W..h ....E..E.Pj.h.jG.W....@..u.W...u....E.P.
u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..
S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
MSSHooks.dll
IMM32.dll
SHLWAPI.dll
SrchCollatorCatalogInfo
SrchDSSLogin
SrchDSSPortManager
SrchPHHttp
SrchIndexerQuery
SrchIndexerProperties
SrchIndexerPlugin
SrchIndexerClient
SrchIndexerSchema
Msidle.dll
Failed to get REGKEY_FLTRDMN_MS_TO_IDLE, using default
pfps->psProperty.ulKind is LPWSTR but psProperty.lpwstr is NULL or empty
d:\win7sp1_gdr\enduser\mssearch2\common\utils\crchash.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrdmn\fltrdaemon.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\common\include\secutil.hxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracerhelpers.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
</MSG></TRC>
<MSG>
<ERR> 0xx=
<LOC> %s(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%s"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%s"
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
SHELL32.dll
PROPSYS.dll
ntdll.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
MsgWaitForMultipleObjects
SearchProtocolHost.pdb
2 2(20282|2
4%5S5
Software\Microsoft\Windows Search
https
kernel32.dll
msTracer.dll
msfte.dll
lX-X-X-XX-XXXXXX
SOFTWARE\Microsoft\Windows Search
tquery.dll
%s\%s
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
advapi32.dll
WAPI-MS-Win-Core-LocalRegistry-L1-1-0.dll
winhttp.dll
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<LOC> %S(%d) </LOC>
tagname="%S"
logname="%S"
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
Microsoft Windows Search Protocol Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchProtocolHost.exe
Windows
7.00.7601.17610
SearchFilterHost.exe_3444:
.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
IMM32.dll
MSSHooks.dll
mscoree.dll
SHLWAPI.dll
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrhost\bufstm.cxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
SearchFilterHost.pdb
version="5.1.0.0"
name="Microsoft.Windows.Search.MSSFH"
<requestedExecutionLevel
3 3(30383|3
kernel32.dll
Software\Microsoft\Windows Search
SOFTWARE\Microsoft\Windows Search
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
tquery.dll
advapi32.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<ERR> 0xx=
<LOC> %S(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%S"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%S"
</MSG></TRC>
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
winhttp.dll
Microsoft Windows Search Filter Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchFilterHost.exe
Windows
7.00.7601.17610
Note-up.exe_1656:
.text
`.rdata
@.data
.rsrc
@.reloc
uDPj0
u u
f;P.sB
@.PQj9
f;A.sK
.6.78.9:;
B.CDEFFG
] ;^ }6
u%SSh
9>t.hD
tFHt:Ht.Ht"Hu`
SSSSh
j%XtL9E
tWSShW
tl9_ tgSSh
t'SShl
FTCP
u.Ph$
tAHt.HHt
SSh@B
<SShG
FtPW
u$SShe
s%j.Zf
xSSSh
FTPjKS
FtPj;S
C.PjRV
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
foreign_key_list
foreign_key_check
defer_foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat4
sqlite_stat3
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
FOREIGN KEY
GetProcessHeap
RowKey
3.8.10.2
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYWITHOUTERELEASEATTACHAVINGROUPDATEBEGINNERECURSIVEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTRIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
922337203685477580
SQLITE_
%s(%d)
sqlite_master
sqlite_temp_master
?API call with %s database connection pointer
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict at line %d
%s%c%s
cannot limit WAL size: %s
2nd reference to page %d
invalid page number %d
unable to use function %s in the requested context
zeroblob(%d)
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
%r %s BY term out of range - should be between 1 and %d
Expression tree is too large (maximum depth %d)
too many SQL variables
variable number must be between ?1 and ?%d
too many columns in %s
hex literal too big: %s
%.*s"%w"%s
%s%.*s"%w"
%s OR name=%Q
type='trigger' AND (%s)
table %s may not be altered
sqlite_
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
%s cannot use variables
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
%s: %s
%s: %s.%s
object name reserved for internal use: %s
duplicate column name: %s
too many columns on %s
default value of column [%s] is not constant
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
DELETE FROM %Q.%s WHERE %s=%Q
sqlite_stat%d
unknown column "%s" in foreign key definition
number of columns in foreign key does not match the number of columns in the referenced table
foreign key on %s should reference only one column of table %T
a JOIN clause is required before %s
%s.rowid
%s.%s
duplicate WITH table name: %s
no such collation sequence: %s
cannot modify %s because it is a view
table %s may not be modified
foreign key mismatch - "%w" referencing "%w"
FOREIGN KEY constraint failed
error during initialization: %s
no entry point [%s] in shared library [%s]
sqlite3_
unable to open shared library [%s]
sqlite3_extension_init
automatic extension loading failed: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
cannot join using column %s - column not present in both tables
cannot have both ON and USING clauses in the same join
a NATURAL join may not have an ON or USING clause
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
column%d
%s:%d
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
recursive reference in a subquery: %s
multiple recursive references: %s
table %s has %d values for %d columns
circular reference: %s
multiple references to recursive table: %s
SCAN TABLE %s%s%s
sqlite3_get_table() called with two or more incompatible queries
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor did not declare schema: %s
vtable constructor failed: %s
vtable constructor called recursively: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
ANY(%s)
VIRTUAL TABLE INDEX %d:%s
USING INTEGER PRIMARY KEY
INDEX %s
COVERING INDEX %s
PRIMARY KEY
AS %s
TABLE %s
SUBQUERY %d
%s.xBestIndex() malfunction
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
d-d-d d:d:d
d:d:d
d-d-d
M@failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
recovered %d frames from WAL file %s
bind on a busy prepared statement: [%s]
%s: %s.%s.%s
misuse of aliased aggregate %s
not authorized to use function: %s
too many terms in %s BY clause
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
Cannot add a PRIMARY KEY column
CREATE TABLE %Q.%s(%s)
%s - %s
malformed database schema (%s)
%s-shm
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Failed to read ptrmap key=%d
failed to get page %d
%d of %d pages missing from overflow list starting at %d
freelist leaf count too big on page %d
%s %T cannot reference objects in database %s
view %s is circularly defined
LIMIT clause should come after %s not before
ORDER BY clause should come after %s not before
no such table: %s
%s.%s.%s
too many references to "%s": max 65535
sqlite_sq_%p
automatic index on %s(%s)
no such vfs: %s
%s mode not allowed: %s
no such %s mode: %s
recovered %d pages from %s
unknown database: %s
Fragmentation of %d bytes reported as %d on page %d
Multiple uses for byte %u of page %d
Corruption detected in cell %d on page %d
On page %d at right child:
On tree page %d cell %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
Page %d:
Outstanding page count goes from %d to %d during this analysis
Pointer map page %d is referenced
Page %d is never used
unable to identify the object to be reindexed
cannot create INSTEAD OF trigger on table: %S
cannot create %s trigger on view: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')at most %d tables in a join
unknown database %s
there is already another table or index with this name: %s
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
sqlite_sequence
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
view %s may not be altered
sqlite_altertab_%s
there is already an index named %s
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);CREATE%s INDEX %.*s
table %s has no column named %s
sqlite_autoindex_%s_%d
index %s already exists
there is already a table named %s
virtual tables may not be indexed
views may not be indexed
table %s may not be indexed
cannot create a TEMP index on non-TEMP table "%s"
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
no such index: %S
no such trigger: %S
MJ delete: %s
-mjX9X
MJ collide: %s
%s-mjXXXXXX9XXz
EXECUTE %s%s SUBQUERY %d
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
table "%s" has more than one primary key
CREATE TABLE %Q.sqlite_sequence(name,seq)
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE %s %.*s
PRIMARY KEY missing on table %s
unable to open database: %s
database %s is already in use
too many attached databases - max %d
database %s is locked
cannot detach database %s
no such database: %s
unsupported encoding: %s
NULL value in %s.%s
*** in database %s ***
misuse of aggregate: %s()
no such column: %s
%d values for %d columns
table %S has %d columns but %d values were supplied
table %S has no column named %s
-- TRIGGER %s
use DROP VIEW to delete view %s
use DROP TABLE to delete table %s
table %s may not be dropped
sqlite_stat
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
database schema is locked: %s
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
PRAGMA vacuum_db.synchronous=OFF
cannot VACUUM - SQL statements in progress
abort at %d in [%s]: %s
%s constraint failed
%s constraint failed: %s
statement aborts at %d: [%s] %s
database table is locked: %s
cannot change %s wal mode from within a transaction
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot commit transaction - SQL statements in progress
cannot release savepoint - SQL statements in progress
no such savepoint: %s
cannot open savepoint - SQL statements in progress
cannot open value of type %s
cannot open %s column for writing
no such column: "%s"
cannot open view: %s
cannot open table without rowid: %s
cannot open virtual table: %s
indexed
foreign key
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unsupported file format
no such table column: %s.%s
CCmdTarget
CNotSupportedException
CMFCVisualManagerWindows
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
CMDIFrameWndEx
TaskDialogIndirect
CMDITabProxyWnd
CMDIChildWndEx
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
CMFCToolBarsKeyboardPropertyPage
GetProcessWindowStation
operator
portuguese-brazilian
CWebBrowser2
()$^.* ?[]|\-{},:=!Winhttp.dll
WinHttpCrackUrl
Wininet.dll
HttpSendRequestW
HttpOpenRequestW
INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT,
INSERT INTO %s (email) VALUES ('%s')SELECT date_time, reminder_date_time, name, location, notes, send_email, id from %s where user_id = %u
SELECT email from %s where id = %u
UPDATE %s SET email = '%s' WHERE id = %u
INSERT INTO %s (date_time, reminder_date_time, name, location, notes, send_email, user_id) VALUES ('%s', '%s', '%s', '%s', '%s', %i, %u)DELETE FROM %s WHERE id = %u
SELECT date_time, reminder_date_time, name, location, notes, send_email, user_id from %s where id = %u
GetWindowsDirectoryW
GetCPInfo
KERNEL32.dll
GetKeyState
UnhookWindowsHookEx
SetWindowsHookExW
CreateDialogIndirectParamW
GetAsyncKeyState
MapVirtualKeyW
GetKeyboardLayout
GetKeyboardState
GetKeyNameTextW
MapVirtualKeyExW
USER32.dll
GetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GDI32.dll
MSIMG32.dll
COMDLG32.dll
WINSPOOL.DRV
RegOpenKeyW
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
RegDeleteKeyW
RegEnumKeyW
RegEnumKeyExW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
COMCTL32.dll
SHLWAPI.dll
ole32.dll
OLEAUT32.dll
oledlg.dll
GdiplusShutdown
gdiplus.dll
OLEACC.dll
IMM32.dll
WINMM.dll
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.PAVCUserException@@
.PAVCOleException@@
.PAVCObject@@
.PAVCMemoryException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.?AVCMFCVisualManagerWindows@@
.PAVCResourceException@@
.PAVCOleDispatchException@@
.PAVCArchiveException@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WV12@PB_W@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W@@
.?AVCMFCToolBarCmdUI@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W@@
.PAVCFileException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAVCObList@@PAV3@@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCRibbonKeyTip@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WHH@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
.?AVCCmdTarget@@
.?AVCWebBrowser2@@
.PAVCException@@
.?AV?$_Ref_count_del@Usqlite3@@P6AHPAU1@@Z@tr1@std@@
.P6AHPAUsqlite3@@@Z
1JTCP
p.qN3
.IDAT
.IDATH
AYO.xXO
~:v.zgu}7
s',%f
3%Cn,
&I.Ibr
HOJ.oa
u.vjB
}j.jX
cdl6.ptQf
d\'.tA
s?.jP
p.qNs2cC
.QzY(
O\.gA
.YRar
B%f#X
..nax
.mQ$(Xt
.MaeI
.HtCE
~%Uu ,
kJ%UN
".igLO
%FPf!
*"%Dv
#c$D%f
,D.Zl
.yK]EW
\.Wnp`p(
=9=%{.mnWw/X${.mn:23[.Iq&
v`.Ko
q.Ko#
PFTI%f
6wv.TD
V.mE&Qs;
Q`.vc
R%FO8
.aCBC
<KEYTIP>
</KEYTIP>
<ID_PREFIX>WINDOWS7_</ID_PREFIX>
<NAME>Windows7</NAME>
777888999888666
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
2,3034383
88
8"808=8{8; ;&;-;3;<;
9%9X9s9z9
:3;\;};6<
8!8-83898?8
<!<6<[<}<
6'7-767=7
99j9
<.<]<4=}>
3!3,323:3\3~3
88v8D9W;i;r;
0&1.161>1~1
8!8%8)8-81858
; ;$;(;,;0;4;8;<;
? ?$?(?,?0?4?8?<?
= =$=(=,=0=4=8=<=
9 9(909<9`9
=$=,=8=\=|=
<$<,<8<\<|<
= =@=\=`=
3 383\3|3
5 5$5(5,5054585
accKeyboardShortcut
wuser32.dll
hhctrl.ocx
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
KERNEL32.DLL
%s%s.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
UxTheme.dll
Advapi32.dll
comctl32.dll
comdlg32.dll
shell32.dll
mfcm100u.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
SHELL32.DLL
lXXxXXXXXXXX
dwmapi.dll
eShell32.dll
%s:%x:%x:%x:%x
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
%sDockingManager-%d
&%d %s
MSG_CHECKEMPTYMINIFRAME
%sPane-%d%x
%sPane-%d
USER32.DLL
!Hex={X,X,X}kernel32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
úlse
MFCLink_UrlPrefix
MFCLink_Url
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
COMCTL32.DLL
KeyboardManager
%sBasePane-%d%x
%sBasePane-%d
ShowCmd
!%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
%c%d%c%s
)RICHED20.DLL
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
windows
*f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
ENABLE_KEYS
KEYS_MENU
KEYS
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
\Note-UP.db
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin1.inl
%s (%s:%d)
%d.%m.%Y %H:%M
Content-Type: application/x-www-form-urlencoded; charset=utf-8;
hXXp://note-up.com/controllers/json_parser.php
Today, %m/%d/%Y at %I:%M %p
%A, %m/%d/%Y at %I:%M %p
v=1&tid=UA-66670216-1&cid=%s&t=event&ec=%s&ea=%s
hXXp://VVV.google-analytics.com/collect?
NSIS_Inetc (Mozilla)
Content-Type: application/x-www-form-urlencoded
%Program Files%\Note-up\Note-up.exe
AQUA_IDB_OFFICE2007_MENU_BTN%AQUA_IDB_OFFICE2007_MENU_BTN_DISABLED%AQUA_IDB_OFFICE2007_MENU_BTN_SCROLL_T"AQUA_IDB_OFFICE2007_MENU_ITEM_BACK&AQUA_IDB_OFFICE2007_MENU_ITEM_MARKER_C&AQUA_IDB_OFFICE2007_MENU_ITEM_MARKER_R$AQUA_IDB_OFFICE2007_POPUPMENU_BORDER'AQUA_IDB_OFFICE2007_POPUPMENU_RESIZEBAR/AQUA_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HV0AQUA_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HVT.AQUA_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_V(AQUA_IDB_OFFICE2007_RIBBON_BORDER_FLOATY$AQUA_IDB_OFFICE2007_RIBBON_BTN_CHECK&AQUA_IDB_OFFICE2007_RIBBON_BTN_DEFAULT,AQUA_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_IMAGE*AQUA_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT/AQUA_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT_ICON,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_C,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_M,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_C,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_M,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_C,AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_M&AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUP_F&AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUP_L&AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUP_M&AQUA_IDB_OFFICE2007_RIBBON_BTN_GROUP_S*AQUA_IDB_OFFICE2007_RIBBON_BTN_LAUNCH_ICON#AQUA_IDB_OFFICE2007_RIBBON_BTN_MAIN'AQUA_IDB_OFFICE2007_RIBBON_BTN_MENU_H_C'AQUA_IDB_OFFICE2007_RIBBON_BTN_MENU_H_M'AQUA_IDB_OFFICE2007_RIBBON_BTN_MENU_V_C'AQUA_IDB_OFFICE2007_RIBBON_BTN_MENU_V_M'AQUA_IDB_OFFICE2007_RIBBON_BTN_NORMAL_B'AQUA_IDB_OFFICE2007_RIBBON_BTN_NORMAL_S%AQUA_IDB_OFFICE2007_RIBBON_BTN_PAGE_L%AQUA_IDB_OFFICE2007_RIBBON_BTN_PAGE_R(AQUA_IDB_OFFICE2007_RIBBON_BTN_PALETTE_B(AQUA_IDB_OFFICE2007_RIBBON_BTN_PALETTE_M(AQUA_IDB_OFFICE2007_RIBBON_BTN_PALETTE_T)AQUA_IDB_OFFICE2007_RIBBON_BTN_PANEL_MAIN*AQUA_IDB_OFFICE2007_RIBBON_BTN_STATUS_PANE%AQUA_IDB_OFFICE2007_RIBBON_CAPTION_QA AQUA_IDB_OFFICE2007_RIBBON_CAPTION_QA_GLASS(AQUA_IDB_OFFICE2007_RIBBON_CATEGORY_BACK'AQUA_IDB_OFFICE2007_RIBBON_CATEGORY_TAB0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_B_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_TAB0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_G_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_TAB0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_I_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_TAB0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_O_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_TAB/AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_B/AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_T0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_R_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_TAB,AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_SEPARATOR0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_V_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_TAB0AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_Y_BTN_DEFAULT2AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_BACK5AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_CAPTION1AQUA_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_TAB&AQUA_IDB_OFFICE2007_RIBBON_KEYTIP_BACK'AQUA_IDB_OFFICE2007_RIBBON_PANEL_BACK_B'AQUA_IDB_OFFICE2007_RIBBON_PANEL_BACK_T*AQUA_IDB_OFFICE2007_RIBBON_PANEL_SEPARATOR(AQUA_IDB_OFFICE2007_RIBBON_PROGRESS_BACK,AQUA_IDB_OFFICE2007_RIBBON_PROGRESS_INFINITY*AQUA_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL.AQUA_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL_EXT AQUA_IDB_OFFICE2007_RIBBON_SLIDER_BTN_MINUS*AQUA_IDB_OFFICE2007_RIBBON_SLIDER_BTN_PLUS'AQUA_IDB_OFFICE2007_RIBBON_SLIDER_THUMB"AQUA_IDB_OFFICE2007_STATUSBAR_BACK&AQUA_IDB_OFFICE2007_STATUSBAR_BACK_EXT(AQUA_IDB_OFFICE2007_STATUSBAR_PANEBORDER%AQUA_IDB_OFFICE2007_STATUSBAR_SIZEBOX AQUA_IDB_OFFICE2007_SYS_BTN_BACK"AQUA_IDB_OFFICE2007_SYS_BTN_BACK_S!AQUA_IDB_OFFICE2007_SYS_BTN_CLOSE#AQUA_IDB_OFFICE2007_SYS_BTN_CLOSE_S$AQUA_IDB_OFFICE2007_SYS_BTN_MAXIMIZE&AQUA_IDB_OFFICE2007_SYS_BTN_MAXIMIZE_S$AQUA_IDB_OFFICE2007_SYS_BTN_MINIMIZE&AQUA_IDB_OFFICE2007_SYS_BTN_MINIMIZE_S#AQUA_IDB_OFFICE2007_SYS_BTN_RESTORE%AQUA_IDB_OFFICE2007_SYS_BTN_RESTORE_S
BLACK_IDB_OFFICE2007_MENU_BTN&BLACK_IDB_OFFICE2007_MENU_BTN_DISABLED&BLACK_IDB_OFFICE2007_MENU_BTN_SCROLL_T,BLACK_IDB_OFFICE2007_MENU_BTN_VERT_SEPARATOR#BLACK_IDB_OFFICE2007_MENU_ITEM_BACK'BLACK_IDB_OFFICE2007_MENU_ITEM_MARKER_C'BLACK_IDB_OFFICE2007_MENU_ITEM_MARKER_R%BLACK_IDB_OFFICE2007_OUTLOOK_BAR_BACK%BLACK_IDB_OFFICE2007_OUTLOOK_BTN_PAGE%BLACK_IDB_OFFICE2007_POPUPMENU_BORDER(BLACK_IDB_OFFICE2007_POPUPMENU_RESIZEBAR0BLACK_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HV1BLACK_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HVT/BLACK_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_V)BLACK_IDB_OFFICE2007_RIBBON_BORDER_FLOATY&BLACK_IDB_OFFICE2007_RIBBON_BORDER_QAT%BLACK_IDB_OFFICE2007_RIBBON_BTN_CHECK'BLACK_IDB_OFFICE2007_RIBBON_BTN_DEFAULT,BLACK_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_ICON-BLACK_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_IMAGE BLACK_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT0BLACK_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT_ICON-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_C-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_M-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_C-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_M-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_C-BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_M'BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUP_F'BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUP_L'BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUP_M'BLACK_IDB_OFFICE2007_RIBBON_BTN_GROUP_S&BLACK_IDB_OFFICE2007_RIBBON_BTN_LAUNCH BLACK_IDB_OFFICE2007_RIBBON_BTN_LAUNCH_ICON$BLACK_IDB_OFFICE2007_RIBBON_BTN_MAIN(BLACK_IDB_OFFICE2007_RIBBON_BTN_MENU_H_C(BLACK_IDB_OFFICE2007_RIBBON_BTN_MENU_H_M(BLACK_IDB_OFFICE2007_RIBBON_BTN_MENU_V_C(BLACK_IDB_OFFICE2007_RIBBON_BTN_MENU_V_M(BLACK_IDB_OFFICE2007_RIBBON_BTN_NORMAL_B(BLACK_IDB_OFFICE2007_RIBBON_BTN_NORMAL_S&BLACK_IDB_OFFICE2007_RIBBON_BTN_PAGE_L&BLACK_IDB_OFFICE2007_RIBBON_BTN_PAGE_R)BLACK_IDB_OFFICE2007_RIBBON_BTN_PALETTE_B)BLACK_IDB_OFFICE2007_RIBBON_BTN_PALETTE_M)BLACK_IDB_OFFICE2007_RIBBON_BTN_PALETTE_T*BLACK_IDB_OFFICE2007_RIBBON_BTN_PANEL_MAIN BLACK_IDB_OFFICE2007_RIBBON_BTN_STATUS_PANE&BLACK_IDB_OFFICE2007_RIBBON_CAPTION_QA,BLACK_IDB_OFFICE2007_RIBBON_CAPTION_QA_GLASS)BLACK_IDB_OFFICE2007_RIBBON_CATEGORY_BACK(BLACK_IDB_OFFICE2007_RIBBON_CATEGORY_TAB,BLACK_IDB_OFFICE2007_RIBBON_CATEGORY_TAB_SEP1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_B_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_TAB1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_G_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_TAB1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_I_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_TAB1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_O_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_TAB0BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_B0BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_T1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_R_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_TAB-BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_SEPARATOR1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_V_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_TAB1BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_Y_BTN_DEFAULT3BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_BACK6BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_CAPTION2BLACK_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_TAB'BLACK_IDB_OFFICE2007_RIBBON_KEYTIP_BACK(BLACK_IDB_OFFICE2007_RIBBON_PANEL_BACK_B(BLACK_IDB_OFFICE2007_RIBBON_PANEL_BACK_T&BLACK_IDB_OFFICE2007_RIBBON_PANEL_MAIN-BLACK_IDB_OFFICE2007_RIBBON_PANEL_MAIN_BORDER%BLACK_IDB_OFFICE2007_RIBBON_PANEL_QAT BLACK_IDB_OFFICE2007_RIBBON_PANEL_SEPARATOR)BLACK_IDB_OFFICE2007_RIBBON_PROGRESS_BACK-BLACK_IDB_OFFICE2007_RIBBON_PROGRESS_INFINITY BLACK_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL/BLACK_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL_EXT,BLACK_IDB_OFFICE2007_RIBBON_SLIDER_BTN_MINUS BLACK_IDB_OFFICE2007_RIBBON_SLIDER_BTN_PLUS(BLACK_IDB_OFFICE2007_RIBBON_SLIDER_THUMB#BLACK_IDB_OFFICE2007_STATUSBAR_BACK'BLACK_IDB_OFFICE2007_STATUSBAR_BACK_EXT)BLACK_IDB_OFFICE2007_STATUSBAR_PANEBORDER&BLACK_IDB_OFFICE2007_STATUSBAR_SIZEBOX!BLACK_IDB_OFFICE2007_SYS_BTN_BACK#BLACK_IDB_OFFICE2007_SYS_BTN_BACK_S"BLACK_IDB_OFFICE2007_SYS_BTN_CLOSE$BLACK_IDB_OFFICE2007_SYS_BTN_CLOSE_S%BLACK_IDB_OFFICE2007_SYS_BTN_MAXIMIZE'BLACK_IDB_OFFICE2007_SYS_BTN_MAXIMIZE_S%BLACK_IDB_OFFICE2007_SYS_BTN_MINIMIZE'BLACK_IDB_OFFICE2007_SYS_BTN_MINIMIZE_S$BLACK_IDB_OFFICE2007_SYS_BTN_RESTORE&BLACK_IDB_OFFICE2007_SYS_BTN_RESTORE_S
BLUE_IDB_OFFICE2007_MENU_BTN%BLUE_IDB_OFFICE2007_MENU_BTN_DISABLED%BLUE_IDB_OFFICE2007_MENU_BTN_SCROLL_T BLUE_IDB_OFFICE2007_MENU_BTN_VERT_SEPARATOR"BLUE_IDB_OFFICE2007_MENU_ITEM_BACK&BLUE_IDB_OFFICE2007_MENU_ITEM_MARKER_C&BLUE_IDB_OFFICE2007_MENU_ITEM_MARKER_R$BLUE_IDB_OFFICE2007_OUTLOOK_BAR_BACK$BLUE_IDB_OFFICE2007_OUTLOOK_BTN_PAGE$BLUE_IDB_OFFICE2007_POPUPMENU_BORDER'BLUE_IDB_OFFICE2007_POPUPMENU_RESIZEBAR/BLUE_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HV0BLUE_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HVT.BLUE_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_V(BLUE_IDB_OFFICE2007_RIBBON_BORDER_FLOATY%BLUE_IDB_OFFICE2007_RIBBON_BORDER_QAT$BLUE_IDB_OFFICE2007_RIBBON_BTN_CHECK&BLUE_IDB_OFFICE2007_RIBBON_BTN_DEFAULT BLUE_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_ICON,BLUE_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_IMAGE*BLUE_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT/BLUE_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT_ICON,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_C,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_M,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_C,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_M,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_C,BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_M&BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUP_F&BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUP_L&BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUP_M&BLUE_IDB_OFFICE2007_RIBBON_BTN_GROUP_S%BLUE_IDB_OFFICE2007_RIBBON_BTN_LAUNCH*BLUE_IDB_OFFICE2007_RIBBON_BTN_LAUNCH_ICON#BLUE_IDB_OFFICE2007_RIBBON_BTN_MAIN'BLUE_IDB_OFFICE2007_RIBBON_BTN_MENU_H_C'BLUE_IDB_OFFICE2007_RIBBON_BTN_MENU_H_M'BLUE_IDB_OFFICE2007_RIBBON_BTN_MENU_V_C'BLUE_IDB_OFFICE2007_RIBBON_BTN_MENU_V_M'BLUE_IDB_OFFICE2007_RIBBON_BTN_NORMAL_B'BLUE_IDB_OFFICE2007_RIBBON_BTN_NORMAL_S%BLUE_IDB_OFFICE2007_RIBBON_BTN_PAGE_L%BLUE_IDB_OFFICE2007_RIBBON_BTN_PAGE_R(BLUE_IDB_OFFICE2007_RIBBON_BTN_PALETTE_B(BLUE_IDB_OFFICE2007_RIBBON_BTN_PALETTE_M(BLUE_IDB_OFFICE2007_RIBBON_BTN_PALETTE_T)BLUE_IDB_OFFICE2007_RIBBON_BTN_PANEL_MAIN*BLUE_IDB_OFFICE2007_RIBBON_BTN_STATUS_PANE%BLUE_IDB_OFFICE2007_RIBBON_CAPTION_QA BLUE_IDB_OFFICE2007_RIBBON_CAPTION_QA_GLASS(BLUE_IDB_OFFICE2007_RIBBON_CATEGORY_BACK'BLUE_IDB_OFFICE2007_RIBBON_CATEGORY_TAB BLUE_IDB_OFFICE2007_RIBBON_CATEGORY_TAB_SEP0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_B_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_TAB0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_G_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_TAB0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_I_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_TAB0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_O_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_TAB/BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_B/BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_T0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_R_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_TAB,BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_SEPARATOR0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_V_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_TAB0BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_Y_BTN_DEFAULT2BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_BACK5BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_CAPTION1BLUE_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_TAB&BLUE_IDB_OFFICE2007_RIBBON_KEYTIP_BACK'BLUE_IDB_OFFICE2007_RIBBON_PANEL_BACK_B'BLUE_IDB_OFFICE2007_RIBBON_PANEL_BACK_T%BLUE_IDB_OFFICE2007_RIBBON_PANEL_MAIN,BLUE_IDB_OFFICE2007_RIBBON_PANEL_MAIN_BORDER$BLUE_IDB_OFFICE2007_RIBBON_PANEL_QAT*BLUE_IDB_OFFICE2007_RIBBON_PANEL_SEPARATOR(BLUE_IDB_OFFICE2007_RIBBON_PROGRESS_BACK,BLUE_IDB_OFFICE2007_RIBBON_PROGRESS_INFINITY*BLUE_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL.BLUE_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL_EXT BLUE_IDB_OFFICE2007_RIBBON_SLIDER_BTN_MINUS*BLUE_IDB_OFFICE2007_RIBBON_SLIDER_BTN_PLUS'BLUE_IDB_OFFICE2007_RIBBON_SLIDER_THUMB"BLUE_IDB_OFFICE2007_STATUSBAR_BACK&BLUE_IDB_OFFICE2007_STATUSBAR_BACK_EXT(BLUE_IDB_OFFICE2007_STATUSBAR_PANEBORDER%BLUE_IDB_OFFICE2007_STATUSBAR_SIZEBOX BLUE_IDB_OFFICE2007_SYS_BTN_BACK"BLUE_IDB_OFFICE2007_SYS_BTN_BACK_S!BLUE_IDB_OFFICE2007_SYS_BTN_CLOSE#BLUE_IDB_OFFICE2007_SYS_BTN_CLOSE_S$BLUE_IDB_OFFICE2007_SYS_BTN_MAXIMIZE&BLUE_IDB_OFFICE2007_SYS_BTN_MAXIMIZE_S$BLUE_IDB_OFFICE2007_SYS_BTN_MINIMIZE&BLUE_IDB_OFFICE2007_SYS_BTN_MINIMIZE_S#BLUE_IDB_OFFICE2007_SYS_BTN_RESTORE%BLUE_IDB_OFFICE2007_SYS_BTN_RESTORE_S
SILVER_IDB_OFFICE2007_MENU_BTN'SILVER_IDB_OFFICE2007_MENU_BTN_DISABLED'SILVER_IDB_OFFICE2007_MENU_BTN_SCROLL_T-SILVER_IDB_OFFICE2007_MENU_BTN_VERT_SEPARATOR$SILVER_IDB_OFFICE2007_MENU_ITEM_BACK(SILVER_IDB_OFFICE2007_MENU_ITEM_MARKER_C(SILVER_IDB_OFFICE2007_MENU_ITEM_MARKER_R&SILVER_IDB_OFFICE2007_OUTLOOK_BAR_BACK&SILVER_IDB_OFFICE2007_OUTLOOK_BTN_PAGE&SILVER_IDB_OFFICE2007_POPUPMENU_BORDER)SILVER_IDB_OFFICE2007_POPUPMENU_RESIZEBAR1SILVER_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HV2SILVER_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_HVT0SILVER_IDB_OFFICE2007_POPUPMENU_RESIZEBAR_ICON_V*SILVER_IDB_OFFICE2007_RIBBON_BORDER_FLOATY'SILVER_IDB_OFFICE2007_RIBBON_BORDER_QAT&SILVER_IDB_OFFICE2007_RIBBON_BTN_CHECK(SILVER_IDB_OFFICE2007_RIBBON_BTN_DEFAULT-SILVER_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_ICON.SILVER_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_IMAGE,SILVER_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT1SILVER_IDB_OFFICE2007_RIBBON_BTN_DEFAULT_QAT_ICON.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_C.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_F_M.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_C.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_L_M.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_C.SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUPMENU_M_M(SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUP_F(SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUP_L(SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUP_M(SILVER_IDB_OFFICE2007_RIBBON_BTN_GROUP_S'SILVER_IDB_OFFICE2007_RIBBON_BTN_LAUNCH,SILVER_IDB_OFFICE2007_RIBBON_BTN_LAUNCH_ICON%SILVER_IDB_OFFICE2007_RIBBON_BTN_MAIN)SILVER_IDB_OFFICE2007_RIBBON_BTN_MENU_H_C)SILVER_IDB_OFFICE2007_RIBBON_BTN_MENU_H_M)SILVER_IDB_OFFICE2007_RIBBON_BTN_MENU_V_C)SILVER_IDB_OFFICE2007_RIBBON_BTN_MENU_V_M)SILVER_IDB_OFFICE2007_RIBBON_BTN_NORMAL_B)SILVER_IDB_OFFICE2007_RIBBON_BTN_NORMAL_S'SILVER_IDB_OFFICE2007_RIBBON_BTN_PAGE_L'SILVER_IDB_OFFICE2007_RIBBON_BTN_PAGE_R*SILVER_IDB_OFFICE2007_RIBBON_BTN_PALETTE_B*SILVER_IDB_OFFICE2007_RIBBON_BTN_PALETTE_M*SILVER_IDB_OFFICE2007_RIBBON_BTN_PALETTE_T SILVER_IDB_OFFICE2007_RIBBON_BTN_PANEL_MAIN,SILVER_IDB_OFFICE2007_RIBBON_BTN_STATUS_PANE'SILVER_IDB_OFFICE2007_RIBBON_CAPTION_QA-SILVER_IDB_OFFICE2007_RIBBON_CAPTION_QA_GLASS*SILVER_IDB_OFFICE2007_RIBBON_CATEGORY_BACK)SILVER_IDB_OFFICE2007_RIBBON_CATEGORY_TAB-SILVER_IDB_OFFICE2007_RIBBON_CATEGORY_TAB_SEP2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_B_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_B_CATEGORY_TAB2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_G_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_G_CATEGORY_TAB2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_I_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_I_CATEGORY_TAB2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_O_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_O_CATEGORY_TAB1SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_B1SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_PANEL_BACK_T2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_R_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_R_CATEGORY_TAB.SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_SEPARATOR2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_V_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_V_CATEGORY_TAB2SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_Y_BTN_DEFAULT4SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_BACK7SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_CAPTION3SILVER_IDB_OFFICE2007_RIBBON_CONTEXT_Y_CATEGORY_TAB(SILVER_IDB_OFFICE2007_RIBBON_KEYTIP_BACK)SILVER_IDB_OFFICE2007_RIBBON_PANEL_BACK_B)SILVER_IDB_OFFICE2007_RIBBON_PANEL_BACK_T'SILVER_IDB_OFFICE2007_RIBBON_PANEL_MAIN.SILVER_IDB_OFFICE2007_RIBBON_PANEL_MAIN_BORDER&SILVER_IDB_OFFICE2007_RIBBON_PANEL_QAT,SILVER_IDB_OFFICE2007_RIBBON_PANEL_SEPARATOR*SILVER_IDB_OFFICE2007_RIBBON_PROGRESS_BACK.SILVER_IDB_OFFICE2007_RIBBON_PROGRESS_INFINITY,SILVER_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL0SILVER_IDB_OFFICE2007_RIBBON_PROGRESS_NORMAL_EXT-SILVER_IDB_OFFICE2007_RIBBON_SLIDER_BTN_MINUS,SILVER_IDB_OFFICE2007_RIBBON_SLIDER_BTN_PLUS)SILVER_IDB_OFFICE2007_RIBBON_SLIDER_THUMB$SILVER_IDB_OFFICE2007_STATUSBAR_BACK(SILVER_IDB_OFFICE2007_STATUSBAR_BACK_EXT*SILVER_IDB_OFFICE2007_STATUSBAR_PANEBORDER'SILVER_IDB_OFFICE2007_STATUSBAR_SIZEBOX"SILVER_IDB_OFFICE2007_SYS_BTN_BACK$SILVER_IDB_OFFICE2007_SYS_BTN_BACK_S#SILVER_IDB_OFFICE2007_SYS_BTN_CLOSE%SILVER_IDB_OFFICE2007_SYS_BTN_CLOSE_S&SILVER_IDB_OFFICE2007_SYS_BTN_MAXIMIZE(SILVER_IDB_OFFICE2007_SYS_BTN_MAXIMIZE_S&SILVER_IDB_OFFICE2007_SYS_BTN_MINIMIZE(SILVER_IDB_OFFICE2007_SYS_BTN_MINIMIZE_S%SILVER_IDB_OFFICE2007_SYS_BTN_RESTORE'SILVER_IDB_OFFICE2007_SYS_BTN_RESTORE_S
WINDOWS7_IDB_COMBOBOX_BTN
WINDOWS7_IDB_MENU_BTN
WINDOWS7_IDB_MENU_BTN_DISABLED
WINDOWS7_IDB_MENU_ITEM_BACK
WINDOWS7_IDB_MENU_ITEM_MARKER_C
WINDOWS7_IDB_MENU_ITEM_MARKER_R
WINDOWS7_IDB_RIBBON_BORDER_QAT
WINDOWS7_IDB_RIBBON_BTN_DEFAULT$WINDOWS7_IDB_RIBBON_BTN_DEFAULT_ICON%WINDOWS7_IDB_RIBBON_BTN_DEFAULT_IMAGE#WINDOWS7_IDB_RIBBON_BTN_DEFAULT_QAT%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_F_C%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_F_M%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_L_C%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_L_M%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_M_C%WINDOWS7_IDB_RIBBON_BTN_GROUPMENU_M_M
WINDOWS7_IDB_RIBBON_BTN_GROUP_F
WINDOWS7_IDB_RIBBON_BTN_GROUP_L
WINDOWS7_IDB_RIBBON_BTN_GROUP_M
WINDOWS7_IDB_RIBBON_BTN_GROUP_S
WINDOWS7_IDB_RIBBON_BTN_LAUNCH#WINDOWS7_IDB_RIBBON_BTN_LAUNCH_ICON
WINDOWS7_IDB_RIBBON_BTN_MAIN WINDOWS7_IDB_RIBBON_BTN_MENU_H_C WINDOWS7_IDB_RIBBON_BTN_MENU_H_M WINDOWS7_IDB_RIBBON_BTN_MENU_V_C WINDOWS7_IDB_RIBBON_BTN_MENU_V_M WINDOWS7_IDB_RIBBON_BTN_NORMAL_B WINDOWS7_IDB_RIBBON_BTN_NORMAL_S
WINDOWS7_IDB_RIBBON_BTN_PAGE_L
WINDOWS7_IDB_RIBBON_BTN_PAGE_R!WINDOWS7_IDB_RIBBON_BTN_PALETTE_B!WINDOWS7_IDB_RIBBON_BTN_PALETTE_M!WINDOWS7_IDB_RIBBON_BTN_PALETTE_T#WINDOWS7_IDB_RIBBON_BTN_STATUS_PANE
WINDOWS7_IDB_RIBBON_CAPTION_QA!WINDOWS7_IDB_RIBBON_CATEGORY_BACK WINDOWS7_IDB_RIBBON_CATEGORY_TAB$WINDOWS7_IDB_RIBBON_CATEGORY_TAB_SEP"WINDOWS7_IDB_RIBBON_PANEL_BACK_SEP
WINDOWS7_IDB_RIBBON_PANEL_MAIN$WINDOWS7_IDB_RIBBON_SLIDER_BTN_MINUS#WINDOWS7_IDB_RIBBON_SLIDER_BTN_PLUS
WINDOWS7_IDX_STYLE
{8856F961-340A-11D0-A96B-00C04FD705A2}Keyboard
C&urrent Keys:
Press &New Shortcut Key:
Show shortcut &keys in ScreenTips
Windows
Help Keyboard
Keyboard shortcuts:
Customize Keyboard
Press &new shortcut key:
Can't create a new image!,Can't paste bitmap image from the clipboard!2You can paste bitmap with the size (%d x %d) only!
Move Item DownrExecutable (*.exe)|*.exe|Command (*.com)|*.com|Information (*.pdf)|*.pdf|Batch (*.bat)|*.bat|All Files (*.*)|*.*||
You may define up to %d tools.
Expand (%s)
Keys
Default Menu=Default application menu. Appears when no documents are open.[-------------------------------------------------------------------------------------------.Do you really want to delete the toolbar '%s'?
All CommandsLAll your changes will be lost! Do you really want to reset the toolbar '%s'?RAll your changes will be lost! Do you really want to reset all toolbars and menus?IAll your changes will be lost! Do you really want to reset the menu '%s'?
DefaultTAll your changes will be lost! Do you really want to reset the keyboard assignments?
4You can't create more than %d user-defined toolbars!
Undo %d Actions
Row %d of %d
Row %d-%d of %d
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]
1.0.0.1
Note-UP.exe
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
nss279D.tmp:2340
%original file name%.exe:1968
nsn82D.tmp:544
nsy470F.tmp:1668 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\WmiInspector.dll (2840 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS1JHSL\stats[1].htm (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\30EV4AVE\Note-UP_Setup[1].exe (3920 bytes)
%Program Files%\96224D56-1493474771-85B6-3678-738E10744E8C\vnsn6B4.tmp (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\heu39T.nss (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\Uninstall.exe (1610 bytes)
%Program Files%\96224D56-1493474771-85B6-3678-738E10744E8C\Uninstall.exe (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\NUIns\NUIns.exe (5873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\IpConfig.dll (3440 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnEF27.tmp (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsx423F.tmp\inetc.dll (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn82D.tmp (5224 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss279D.tmp (29490 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsy470F.tmp (143993 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\318DR7NG\sqOgQjP0[1] (135838 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\System.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsn471F.tmp\INetC.dll (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Note-Up.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\Desktop\Note-Up.lnk (1 bytes)
%Program Files%\Note-up\Note-up.exe (137267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\FindProcDLL.dll (63 bytes)
%Program Files%\Note-up\uninstall.exe (1686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\ProcessKiller.dll (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\InvokeShellVerb.dll (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nst6C6A.tmp\System.dll (23 bytes)
%Program Files%\Note-up\Note-up.ico (2104 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Note-up" = "%Program Files%\Note-up\note-up.exe /watch" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.