Sample_1930761b17

mzpefinder_pcap_file.YR (Lavasoft MAS) Behaviour: Malware The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information....
Blog rating:1 out of5 with1 ratings

Sample_1930761b17

by malwarelabrobot on August 31st, 2017 in Malware Descriptions.

mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Malware


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 1930761b17113647ef7b7cde179af416
SHA1: 3da27b63a26a4238cc06b0292cd9bfa0a1721710
SHA256: 120c86849f1a8b8c885ed1aaa3bffb89423b8f51bfb97b200b08f3ab0a9ea8c3
SSDeep: 24576:7RbvMp /QlYqSj2yb KKEabCLp43bKv9jNPjs/8Q:7BMpYYAKyKDEaYpwbQjNgf
Size: 1151808 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, Armadillov171
Company: Exent Technologies Ltd.
Created at: 2008-08-20 16:51:24
Analyzed on: Windows7 SP1 32-bit


Summary:

Malware. Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

Payload

No specific payload has been found.

Process activity

The Malware creates the following process(es):

cmhelper.exe:4080
cmhelper.exe:1804
cmhelper.exe:1092
cmhelper.exe:3712
cmhelper.exe:1428
cmhelper.exe:2980
cmhelper.exe:3724
cmhelper.exe:1296
regsvr32.exe:3912
FreeRideGames.exe:1748
%original file name%.exe:3432
RegEdit.exe:3984
RegEdit.exe:4004
RegEdit.exe:3704
Setup.exe:1264
iKernel.exe:4016
IKernel.exe:4032
IKernel.exe:2144

The Malware injects its code into the following process(es):

WerFault.exe:2124
GPlayer.exe:472
Free Ride Games.exe:3400

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process cmhelper.exe:4080 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (73 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (0 bytes)

The process cmhelper.exe:1804 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\X6FP80R3.txt (105 bytes)

The process cmhelper.exe:1092 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\ESALVM6O.txt (211 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\X6FP80R3.txt (0 bytes)

The process cmhelper.exe:3712 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B51JZUNK\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AH411JJS\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7N4CKHF0\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\F6637V5A\desktop.ini (67 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (0 bytes)

The process cmhelper.exe:1428 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\7UWG0E7P.txt (314 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\KMGTASBT.txt (0 bytes)

The process cmhelper.exe:2980 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\FQ0ZQC1W.txt (314 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\7UWG0E7P.txt (0 bytes)

The process cmhelper.exe:3724 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\KMGTASBT.txt (314 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\ESALVM6O.txt (0 bytes)

The process cmhelper.exe:1296 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\CD490DZY.txt (314 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\FQ0ZQC1W.txt (0 bytes)

The process GPlayer.exe:472 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF (2 bytes)
%Program Files%\FantastiGames\Info\1.clg (40275 bytes)
%Program Files%\FantastiGames\Info\co_adm.dat (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FI1HKYYU.txt (1528 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (12078 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\T0HCNPR5.txt (1537 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\OO1RHZ5B.txt (1510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_mDsdT6zr4vUOndJ (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_nkohzXNu8dUYkRt (66 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZDO3F4LP.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF (2674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ITL3JZ46.txt (1537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite (9432 bytes)
%Program Files%\FantastiGames\cmhelper.exe (188 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal (13542 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\74VZKJBU.txt (1508 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\K4UC8OE2.txt (1504 bytes)
%Program Files%\FantastiGames\Info\sXp.dat (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (1447 bytes)
%Program Files%\FantastiGames\Info\co_adm.dat-journal (14082 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Cookies (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\DJDN2C5M.txt (1513 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE (2448 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies (987 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ITL3JZ46.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\DJDN2C5M.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FI1HKYYU.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (0 bytes)
%Program Files%\FantastiGames\Info\co_adm.dat-journal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZDO3F4LP.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\OO1RHZ5B.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\74VZKJBU.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZN9D1766.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\K4UC8OE2.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-shm (0 bytes)

The process FreeRideGames.exe:1748 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\plf4C5B.tmp (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.inx (7913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.cab (8949 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ExentCtl.ocx (9690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\Setup.exe (2318 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\FRGN.ico (3827 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data2.cab (153950 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\exs.dll (13249 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.ini (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.iss (169 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ikernel.ex_ (6473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.hdr (1013 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\layout.bin (417 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\pftw1.pkg (22720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ext4C5C.tmp (5 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\plf4C5B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.inx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.cab (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ExentCtl.ocx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\Setup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\FRGN.ico (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data2.cab (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.iss (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\exs.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.ini (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ikernel.ex_ (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.hdr (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\layout.bin (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\pftw1.pkg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.log (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ext4C5C.tmp (0 bytes)

The process %original file name%.exe:3432 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\00051E97 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\resourceDll.dll (261 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_uninsep.bat (174 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\cmhelper.exe (192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\ExentCtlInstaller.dll (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe (962 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\00051E97 (0 bytes)

The process Setup.exe:1264 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe (618 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IEC4E4E.tmp (2105 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\temp.000 (11328 bytes)

The Malware deletes the following file(s):

%Program Files%\Common Files\InstallShield (0 bytes)
%Program Files%\Common Files\InstallShield\IScript (0 bytes)
%Program Files%\Common Files\InstallShield\Engine\6 (0 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IEC4E4E.tmp (0 bytes)
%Program Files%\Common Files\InstallShield\Engine (0 bytes)

The process Free Ride Games.exe:3400 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion3[1].gif (13064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\R7OD6DBI.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\measurements[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\gamesInQueue[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\757c6a22-140e-494a-be1f-e0407a0c5382 (54286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\offlineheader[1] (398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\emptyFooter[1] (817 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\connection[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\bubbleRight[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\e77284cb-1bb0-4557-8892-2ed1c966596c (54286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PVGOHUDS.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\conf_defines[1] (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\resourceDll.dll (262 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WWR4H4TF.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\SDM_HEADER2[1].css (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XCN81JJL.txt (1157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\servicePromotion1[1].jpg (7004 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7TUMTORV.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\bubbleLeft[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\SDM_PROGRESS[1].css (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XN1WNAN1.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\util[1] (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Exent\GI20170830062205GMT.Log (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\pageURLInfo[1] (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\SDMHTMLInterfaces[1] (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\initialized[1] (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\SDMLog.log (2323573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies (1275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9CI3FM16.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JV92PAKR.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\controller[1] (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2V8FONPT.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\207B9FD92391B9B2A60A89B4C965D5DF (588 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (12078 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FWM1JVI5.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\functions[1] (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6KLB2WYO.txt (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\boxshot_sm[1].jpg (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\defines[1].js (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\progress[1] (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\207B9FD92391B9B2A60A89B4C965D5DF (936 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D41693DAFE5DEF0C36959FF1FCEF5C96 (603 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\offlineheader[1] (199 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\defines[1] (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\14KLX8KR.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal (20958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\beacon[1].js (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarB56A.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\close_disabled[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion2[1].jpg (7596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PINM4I6X.txt (537 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Cookies (27 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabB569.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\FreeRideGames.exe (5534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\b4fd6daa-460f-4d2e-96d4-dc0ed984be7e (54286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\aa48a783-4197-4656-bbdf-e08050496297 (54286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F24TTX69.txt (1449 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\initialized[1] (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\4cb7ea78-f9d1-4dd1-99d3-ea9ee82326e8 (54286 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\connecting_anim[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\header[1].htm (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\EULAFooter[1] (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NPZKBZPA.txt (298 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite (9432 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\conf_defines[1] (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\header[1].jpg (1160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\SDM_DB_143.xml (378 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (737 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6TT3Z53I.txt (955 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\index[1] (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\util[1] (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\I6E3BWDW.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\connecting_anim[1] (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LME52A66.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\extrnalHandler[1] (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D41693DAFE5DEF0C36959FF1FCEF5C96 (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion4[1].jpg (4926 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\defines[1] (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\close_up[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\configuration[1] (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\initialized[1] (401 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\SDM_PROGRESS[1].htm (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\pageURLInfo[1] (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\util[1] (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5GE58KL3.txt (109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FVT01N0M.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\ga[1].js (27865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\07W0X7RA.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\13[1].gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\conf_defines[1] (510 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\minimize_up[1] (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6QTQ4XM0.txt (695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CGOV3MC7.txt (114 bytes)
%Program Files%\FantastiGames\GameInst.dll (49 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\progressFooter[1] (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\SDM_DownloadAcc_1.acc (940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\defines[1] (9 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9CI3FM16.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JV92PAKR.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\R7OD6DBI.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\offlineheader[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F24TTX69.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FWM1JVI5.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\initialized[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6KLB2WYO.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XCN81JJL.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\connecting_anim[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\pageURLInfo[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\util[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5GE58KL3.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FVT01N0M.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PVGOHUDS.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\07W0X7RA.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LME52A66.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WWR4H4TF.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\defines[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2V8FONPT.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\conf_defines[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\offlineheader[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\conf_defines[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\defines[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PINM4I6X.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarB56A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XN1WNAN1.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-shm (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CGOV3MC7.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7TUMTORV.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6TT3Z53I.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\util[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\initialized[1] (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\14KLX8KR.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6QTQ4XM0.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabB569.tmp (0 bytes)

The process IKernel.exe:4032 makes changes in the file system.
The Malware creates and/or writes to the following file(s):

%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62d7.rra (1 bytes)
%Program Files%\FantastiGames\Repo585c.rra (22774 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bf4.rra (25 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgBo60e4.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_u66ec.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_a6641.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\Subs63c1.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos62f6.rra (483 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\canc67b7.rra (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5H7LDD3J.txt (1534 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\load6315.rra (17 bytes)
%Program Files%\FantastiGames\X4Ex57df.rra (16732 bytes)
%Program Files%\FantastiGames\d3dx59f1.rra (32512 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\og_i643e.rra (625 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\play62e7.rra (1 bytes)
%Program Files%\FantastiGames\AX32584c.rra (3404 bytes)
%Program Files%\FantastiGames\X8XS5936.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\canc5ffa.rra (2 bytes)
%Program Files%\FantastiGames\X7XS5965.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dial5f6d.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\mask\upda6798.rra (96 bytes)
%Program Files%\FantastiGames\Skins\000005\mask\play6788.rra (144 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\invi6306.rra (262 bytes)
%Program Files%\FantastiGames\exs.ini (9682 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\dl_i63d1.rra (32 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_5ffa.rra (1 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\iuse515a.rra (6134 bytes)
%Program Files%\FantastiGames\Skins\000005\sound\Popu68b1.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\yaho6641.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\post644d.rra (966 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\tabs63c1.rra (4 bytes)
%Program Files%\FantastiGames\Data\vers58b9.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e6690.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann6299.rra (2 bytes)
C:\ProgramData\FantastiGames\Setu7167.rra (1568 bytes)
%Program Files%\FantastiGames\X8Ex5917.rra (16732 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pids5d6b.rra (58 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e669e.rra (1 bytes)
%Program Files%\FantastiGames\exs58c9.rra (3162 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\data57c0.rra (10160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\isrt.dll (331 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\dott6354.rra (35 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_6019.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\nobu67f5.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\myGa5fcb.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c23.rra (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\defa5408.rra (1 bytes)
%Program Files%\FantastiGames\X6Ex5927.rra (9120 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63f0.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\AC_R63d1.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\eror5f7d.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\mg5d5b.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\skip6853.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\swit647c.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\logi642e.rra (1 bytes)
%Program Files%\FantastiGames\ProviderComponents.ini (577 bytes)
%Program Files%\FantastiGames\Skins\000005\GameInfoDefault\Spla5b29.rra (29 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62a8.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\game6373.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5df7.rra (5 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d99.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Help673a.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_o66dd.rra (6 bytes)
%Program Files%\FantastiGames\GPlr586b.rra (18290 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Tray66fc.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\spla647c.rra (6 bytes)
C:\Windows\Downloaded Program Files\ExentCtl.ocx (512 bytes)
C:\ProgramData\FantastiGames\Exen7148.rra (10160 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6835.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b77.rra (15 bytes)
%Program Files%\FantastiGames\cmhe589a.rra (6134 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\subm60b5.rra (2 bytes)
%Program Files%\FantastiGames\wh_P58b9.rra (4456 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\setu57cf.rra (7384 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\yesb6891.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\Skin64bb.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_i66cd.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\GameInfoDefault\md5b29.rra (383 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c33.rra (15 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\post644e.rra (966 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\Most5fac.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_s66dd.rra (12 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e667f.rra (4 bytes)
%Program Files%\FantastiGames\npGa5a01.rra (51622 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\sign646d.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_d5b58.rra (10 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\mg_i643e.rra (20 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5d2c.rra (22 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d8a.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\jque641f.rra (3404 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\ad5d4b.rra (697 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\gmt\cls_5d2c.rra (10 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6834.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5de7.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6816.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\OffL5b49.rra (374 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5dc8.rra (8 bytes)
%Program Files%\FantastiGames\GUpd58aa.rra (5738 bytes)
%Program Files%\FantastiGames\NPGa5a20.rra (10 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\preR646d.rra (14 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Conn5b39.rra (296 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\_IsRes.dll (258 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\yesb6892.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6843.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\load6383.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\icon5f8d.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\MyGa5fbb.rra (4298 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setup.ini (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\buy_5fdb.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63e0.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\mask\logi6788.rra (144 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL670b.rra (34 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3XAKTYJE.txt (1534 bytes)
C:\Windows\Exen5975.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\sear63a2.rra (23 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgTo6103.rra (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZN9D1766.txt (1534 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\GPla673a.rra (17 bytes)
%Program Files%\FantastiGames\DoDl58c9.rra (6134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.log (139 bytes)
%Program Files%\FantastiGames\AppL588b.rra (33818 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\MyGa6759.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\debu5b68.rra (1 bytes)
C:\ProgramData\FantastiGames\setu7177.rra (259 bytes)
%Program Files%\FantastiGames\GPlayer.exe (485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice534d.rra (38 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bb6.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\MinC6392.rra (6 bytes)
C:\ProgramData\FantastiGames\FRGN7158.rra (2712 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_g66ae.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e07.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d7a.rra (14 bytes)
C:\ProgramData\FantastiGames\exs7148.rra (12280 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e16.rra (35 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\hide6067.rra (2 bytes)
%Program Files%\Common Files\InstallShield\IScript\iscript.dll (225 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\drop6344.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_260a5.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5ba6.rra (20 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\eula5f7d.rra (5 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\skin5e83.rra (11 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5d1d.rra (13 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\stil6335.rra (20 bytes)
%Program Files%\FantastiGames\Skins\000005\Skin5b1a.rra (30 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62c7.rra (2 bytes)
%Program Files%\FantastiGames\X358aa.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\spla5e93.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_p5b68.rra (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\setu532e.rra (7384 bytes)
%Program Files%\FantastiGames\Skins\000005\NIBmps\NetI67a7.rra (2520 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_6009.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\yesn648c.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6086.rra (2 bytes)
%Program Files%\FantastiGames\Clie586b.rra (395 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_l66cd.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Onli674a.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\hide6057.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\trac647c.rra (10 bytes)
%Program Files%\FantastiGames\Skins\000005\Langs\0409\Stri6779.rra (11940 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\layo5f9c.rra (5 bytes)
%Program Files%\FantastiGames\EXEt586b.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b87.rra (22 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\auto6621.rra (36 bytes)
%Program Files%\FantastiGames\Skins\000005\Sett5b0a.rra (1 bytes)
C:\ProgramData\FantastiGames\layo7167.rra (417 bytes)
%Program Files%\FantastiGames\ExentComponents.ini (29803 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.hdr (57 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL66fc.rra (34 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\logi5e74.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\mg_i5e74.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL672b.rra (17 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll (176 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6048.rra (1 bytes)
%Program Files%\FantastiGames\Game586b.rra (4456 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\dial5e55.rra (3 bytes)
%Program Files%\FantastiGames\X4HS57ef.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\logi62d7.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_a5b49.rra (3404 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\nobu6805.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\Thum6151.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\logi62e7.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\topL6289.rra (1 bytes)
C:\ProgramData\FantastiGames\data70fa.rra (164783 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_d6641.rra (22 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5db9.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_m66dd.rra (18 bytes)
%Program Files%\FantastiGames\Skins\000005\dat\GPlr5b1a.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bd5.rra (14 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\upda6872.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\load6132.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b97.rra (23 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\key_642e.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63ff.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\og_i5e83.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\anim6612.rra (13 bytes)
%Program Files%\FantastiGames\X7Ex5946.rra (20620 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\skip6854.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\atta60d4.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\GATr5f8d.rra (2326 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgRi60f3.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\adGa5e35.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL671c.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\nobu67f6.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\main6392.rra (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PNF45JVQ.txt (1534 bytes)
%Program Files%\FantastiGames\AppLoader2KEx.dll (49 bytes)
%Program Files%\FantastiGames\X6XS5936.rra (1568 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\spac5fdb.rra (49 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6815.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos62e7.rra (376 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL671b.rra (34 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\flas63ff.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\clos67e7.rra (2 bytes)
%Program Files%\FantastiGames\repo585c.rra (292 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\clos67e6.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\MyDo674a.rra (17 bytes)
C:\Windows\Downloaded Program Files\Exen5975.rra (18290 bytes)
%Program Files%\FantastiGames\FRGN59e2.rra (4314 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\flas640f.rra (19 bytes)
C:\Users\Public\Desktop\More FREE games.lnk (1 bytes)
%Program Files%\FantastiGames\Skins\000005\Langs\0409\EXEt6769.rra (843 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\logi5b77.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\adGa5e26.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\flas6122.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_16096.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e668f.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\logo5fac.rra (26 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\play643e.rra (729 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\pb5fcb.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\clos6038.rra (2 bytes)
%Program Files%\FantastiGames\Fant59e2.rra (2712 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Chan66ec.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\back67b7.rra (12 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\upda6882.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\NIBmps\NetI6798.rra (1260 bytes)
%Program Files%\FantastiGames\exs.dll (675 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\yesb68a1.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\canc67b8.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\gplayer\gpla5d3c.rra (4365 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL670c.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6038.rra (2 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\obje514a.rra (798 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\dl_i5e55.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_g66bd.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\FRGL672c.rra (17 bytes)
%Program Files%\FantastiGames\myGa59e2.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\chan6344.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_m5b58.rra (23 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\IAF674a.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5da9.rra (10 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_c5b58.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\topR6299.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\play6325.rra (9 bytes)
%Program Files%\FantastiGames\glut5918.rra (2712 bytes)
%Program Files%\FantastiGames\Skins\000005\GameInfoDefault\Game5b1a.rra (12 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e6650.rra (5 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\ctor511b.rra (3404 bytes)
%Program Files%\FantastiGames\glut5946.rra (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice537c.rra (31 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\erro5e64.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgLe60e4.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\mask\erro6779.rra (144 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\isrt53f9.rra (11940 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MBLJWWXW.txt (1534 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\_IsR5418.rra (8474 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\retr6141.rra (3 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\data57b0.rra (1568 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\canc5fea.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\spec64ca.rra (807 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice536d.rra (2343 bytes)
C:\ProgramData\FantastiGames\setu7167.rra (7385 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\drop6363.rra (181 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5be5.rra (22 bytes)
%Program Files%\FantastiGames\X5Ex5955.rra (11328 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\drop63e0.rra (5 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\logo6383.rra (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\234MYWU9.txt (1534 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\dl5d5b.rra (7 bytes)
%Program Files%\FantastiGames\Game58e8.rra (64414 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\yesn5f6d.rra (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\50ae.rra (100 bytes)
C:\ProgramData\FantastiGames\iker7158.rra (6720 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\clos6029.rra (3 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\laun6315.rra (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice536c.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\fram641f.rra (14 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c04.rra (9 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Serv6759.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\data6631.rra (31 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c13.rra (4 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\defa5d4b.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5ca0.rra (5 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\skip6863.rra (6 bytes)
%Program Files%\FantastiGames\glut5917.rra (4314 bytes)
C:\Users\Public\Desktop\Play Free Games.lnk (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\butt5f6d.rra (7 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\Subs63b1.rra (16 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\load6373.rra (2334 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\exs.dll (675 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\valu539b.rra (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6R2FOOCT.txt (1534 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\gplayer\gpla5d4b.rra (16 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\Skin64ab.rra (3 bytes)
%Program Files%\FantastiGames\EXEt59d2.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\auto5e35.rra (1 bytes)
%Program Files%\FantastiGames\Clie58b9.rra (262 bytes)
%Program Files%\FantastiGames\glut68c0.rra (2712 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e26.rra (20 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\layo57b0.rra (417 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6824.rra (2 bytes)
%Program Files%\FantastiGames\X5XS5965.rra (1568 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\comm5e45.rra (92 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5dd8.rra (6 bytes)
%Program Files%\FantastiGames\GPla57ef.rra (154846 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Exit66fc.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6057.rra (2 bytes)
%Program Files%\FantastiGames\lice587b.rra (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\S1ZLQF5G.txt (1534 bytes)
%Program Files%\Common Files\InstallShield\IScript\iscr51e6.rra (7348 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\clie63d1.rra (581 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\canc67c7.rra (6 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\subm60c5.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bott6113.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\GPlr673a.rra (17 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setu57cf.rra (1 bytes)
%Program Files%\FantastiGames\npEx5984.rra (8474 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62b8.rra (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WP2BZ5ZM.txt (1534 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\logo6141.rra (8 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_06086.rra (2 bytes)
%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\core510c.rra (28 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6067.rra (2 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6077.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\load6122.rra (2334 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\fram5e64.rra (5 bytes)
%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setu57c0.rra (1568 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\clos67f5.rra (1 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\PreR64ab.rra (1 bytes)
%Program Files%\FantastiGames\exs58d9.rra (22520 bytes)
%Program Files%\FantastiGames\Skins\000005\Popups\1\Chec67d6.rra (1264 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos6306.rra (247 bytes)
%Program Files%\FantastiGames\Skins\000005\html\OffL5b39.rra (22 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bc5.rra (23 bytes)
%Program Files%\FantastiGames\Skins\000005\icon\Sett6769.rra (17 bytes)
%Program Files%\FantastiGames\Skins\000005\GameInfoDefault\spla5b29.rra (27 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\myGa5fbb.rra (22 bytes)
%Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\PreR649b.rra (2 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\FantastiGames.lnk (1 bytes)

The Malware deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MBLJWWXW.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license PT.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3XAKTYJE.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\234MYWU9.txt (0 bytes)
%Program Files%\FantastiGames\EXEtenderDefaults.reg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\S1ZLQF5G.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\value.shl (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\I6E3BWDW.txt (0 bytes)
%Program Files%\FantastiGames\EXEtenderDefaultsProvider.reg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license.Old.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license FRG.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6R2FOOCT.txt (0 bytes)
%Program Files%\FantastiGames\NPGameTreatPlugin.reg (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\_IsRes.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\isrt.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5H7LDD3J.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license admuse.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WP2BZ5ZM.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license default.txt (0 bytes)
%Program Files%\FantastiGames\glutil.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\default.pal (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\setup.inx (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license BellCanada.txt (0 bytes)
%Program Files%\FantastiGames\X3.vxd (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PNF45JVQ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\license.txt_old (0 bytes)

Registry activity

The process WerFault.exe:2124 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug]
"ExceptionRecord" = "05 00 00 C0 00 00 00 00 00 00 00 00 43 EB 4E 00"

[HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"

[HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles]
"FirstLevelConsentDialog" = "Type: REG_QWORD, Length: 8"

The process GPlayer.exe:472 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\Application on Demand - GPlayer]
"Description" = "%Program Files%\FantastiGames\GPlayer.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\CMC]
"LastShutdownOK" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
"VerCache" = "BD 40 B2 94 38 25 D2 01 7F 0E CA 94 38 25 D2 01"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"FileTracingMask" = "4294901760"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\Application on Demand - GPlayer]
"EventMessageFile" = "%Program Files%\FantastiGames\GPlayer.exe"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinStyle]
"IsVisible" = "0"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E\@%SystemRoot%\system32]
"fveui.dll,-843" = "BitLocker Drive Encryption"
"fveui.dll,-844" = "BitLocker Data Recovery Agent"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\Partner]
"Value" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG]
"MaxFilesCount" = "16"

[HKLM\SOFTWARE\Exent\AOD\Client]
"EnableStopBeforeNavigate" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"PlayTime" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"ProviderId" = "143"

[HKCU\Software\Classes\Applications\GPlayer.exe]
"TaskbarGroupIcon" = "%Program Files%\FantastiGames\Skins\000005\icon\GPlayer.ico"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\TK\TKEnabled]
"IsVisible" = "0"
"IsReadOnly" = "0"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E\@%SystemRoot%\system32]
"dnsapi.dll,-103" = "Domain Name System (DNS) Server Trust"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASMANCS]
"ConsoleTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\Partner]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"TicketID" = "1204111893"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6A060448-60F9-11D5-A6CD-0002B31F7455}]
"VerCache" = "01 D6 50 48 58 21 D3 01 00 BE EA FC 7B C6 CA 01"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\VersionXmlURL]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\Application on Demand - GPlayer]
"TypesSupported" = "7"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\TK\TKEnabled]
"Value" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"TargetURL" = ""
"ErrorID" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinCode]
"Value" = "000005"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E\@%SystemRoot%\system32]
"qagentrt.dll,-10" = "System Health Authentication"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG]
"LastFileIndex" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"RTyp" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"MaxFileSize" = "1048576"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E\@%SystemRoot%\system32]
"p2pcollab.dll,-8042" = "Peer to Peer Trust"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\TK\TKFT]
"IsVisible" = "0"
"IsReadOnly" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"filepath" = "%Program Files%\FantastiGames\Info\1.clg"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD]
"Blob" = "0F 00 00 00 01 00 00 00 20 00 00 00 52 29 BA 15"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\VersionXmlURL]
"Value" = ""

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASMANCS]
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinStyle]
"Value" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASAPI32]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG\1]
"STyp" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\GPlayer_RASMANCS]
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinStyle]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\TK\TKFT]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG]
"RecoverSendFilesCount" = "3"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\Partner]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\VersionXmlURL]
"IsVisible" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Malware deletes the following registry key(s):

[HKCU\Software\AppDataLow\Software\Exent\AOD\Broadcasting\472360487]

The Malware deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"D69B561148F01C77C54578C10926DF5B856976AD"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process regsvr32.exe:3912 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\WOW]
"DefaultSeparateVDM" = "yes"

The process %original file name%.exe:3432 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Malware deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process RegEdit.exe:3984 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Exent\AOD\Client\CMC]
"MediaChangerHotKey" = "193"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnable]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableShortcut]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client]
"ClientReportUrl" = ""

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyPort]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ShowNetworkIndicator]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\OpenShortcutInIE]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoErrorReport]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\PRV]
"eSPT" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingUIEnable]
"IsVisible" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GPlayer.exe" = "9999"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyPort]
"Value" = "0"

[HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GPlayer.exe" = "9999"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyAddress]
"Value" = ""

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SettingLastPage]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoDiskManagment]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoErrorReport]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableDesktopShortcut]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SkinCode]
"Value" = "000001"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoErrorReport]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SettingLastPage]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableDesktopShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\PropmtBeforeCreatingShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\PRV]
"eLPL" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\OpenShortcutInIE]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoDiskManagment]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client]
"Version" = "117724167"

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags]
"{df5f2391-cd77-412c-afc6-99fd6d5f07c8}" = "4"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG]
"LastSuccessfulErrURL" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EBFFAE0-F0A4-4ee6-8524-2751906624C4}]
"AppPath" = ""

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyRadio]
"Value" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EBFFAE0-F0A4-4ee6-8524-2751906624C4}]
"AppName" = "GPlayer.exe"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnableOnStartup]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\PropmtBeforeCreatingShortcut]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyRadio]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyAddress]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ShowNetworkIndicator]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"Mmd" = "8B0424DEFF152C625CB814DF89D8F3C82CE328F87F8F83DCF86A05F35C8852D1890B8F16F4E5285E1DB0B8D2"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnable]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS]
"GPlayer.exe" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnable]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyRadio]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingUIEnable]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EBFFAE0-F0A4-4ee6-8524-2751906624C4}]
"Policy" = "3"

[HKLM\SOFTWARE\Exent\AOD\Client]
"UseClientReportUrl" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\AutoDiskManagment]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CMC]
"CheckDiskSpaceInterval" = "86400000"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnableOnStartup]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SkinCode]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyPort]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\OpenShortcutInIE]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ShowNetworkIndicator]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\PropmtBeforeCreatingShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingEnableOnStartup]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"EnableDumpReport" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\ProxyAddress]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\EnableDesktopShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SchedulingUIEnable]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"RamMaxWindowSize" = "12"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SkinCode]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\0\Settings\SettingLastPage]
"Value" = "0"

The process RegEdit.exe:4004 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}]
"(Default)" = "Game Treat Widget"

[HKCR\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}]
"(Default)" = "FireBreathWin"

[HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GTR.exe" = "9999"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{C9C1FD39-F2D3-50C9-AA6E-662D0EB26128}\TypeLib]
"(Default)" = "{103DFC4E-147A-5606-9B4E-1C216DF227A1}"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\ProgID]
"(Default)" = "GameTreatWidget.GameTreatWidget.1"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\VersionIndependentProgID]
"(Default)" = "GameTreatWidget.GameTreatWidget"

[HKCR\MIME\Database\Content Type\application/x-gametreatwidget]
"Extension" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GTR.exe" = "9999"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\Version]
"(Default)" = "1"

[HKCR\Interface\{FEFD8F9E-7F71-5307-A9E8-D2E60A4AAECA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\MIME\Database\Content Type\application/x-gametreatwidget]
"(Default)" = "Game Treat Widget"

[HKCR\Interface\{7E8621A2-3513-5BAD-85D8-D624558847C7}]
"(Default)" = "IFBComEventSource"

[HKCR\GameTreatWidget.GameTreatWidget\CLSID]
"(Default)" = "{44d07caa-4fc4-5a84-9951-a485ad808d0e}"

[HKCR\GameTreatWidget.GameTreatWidget\CurVer]
"(Default)" = "GameTreatWidget.GameTreatWidget.1"

[HKCR\Interface\{C9C1FD39-F2D3-50C9-AA6E-662D0EB26128}]
"(Default)" = "IFBComJavascriptObject"

[HKCR\GameTreatWidget.GameTreatWidget.1]
"(Default)" = "Game Treat Widget"

[HKCR\MIME\Database\Content Type\application/x-gametreatwidget]
"CLSID" = "{44d07caa-4fc4-5a84-9951-a485ad808d0e}"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\Interface\{FEFD8F9E-7F71-5307-A9E8-D2E60A4AAECA}]
"(Default)" = "IFBControl"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\TypeLib]
"(Default)" = "{103DFC4E-147A-5606-9B4E-1C216DF227A1}"

[HKCR\TypeLib\{103DFC4E-147A-5606-9B4E-1C216DF227A1}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\MiscStatus]
"(Default)" = "0"

[HKCR\Interface\{7E8621A2-3513-5BAD-85D8-D624558847C7}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\GameTreatWidget.GameTreatWidget.1\CLSID]
"(Default)" = "{44d07caa-4fc4-5a84-9951-a485ad808d0e}"

[HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GtrHost.exe" = "9999"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GtrHost.exe" = "9999"

[HKCR\Interface\{7E8621A2-3513-5BAD-85D8-D624558847C7}\TypeLib]
"Version" = "1.0"

[HKCR\AppID\npGameTreatWidget.dll]
"AppID" = "{B415CD14-B45D-4BCA-B552-B06175C38606}"

[HKCR\Interface\{FEFD8F9E-7F71-5307-A9E8-D2E60A4AAECA}\TypeLib]
"(Default)" = "{103DFC4E-147A-5606-9B4E-1C216DF227A1}"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\InprocServer32]
"AppID" = "{B415CD14-B45D-4BCA-B552-B06175C38606}"

[HKCR\GameTreatWidget.GameTreatWidget]
"(Default)" = "Game Treat Widget"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\iexplore\AllowedDomains\*]
"Count" = "0"

[HKCR\Interface\{C9C1FD39-F2D3-50C9-AA6E-662D0EB26128}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{C9C1FD39-F2D3-50C9-AA6E-662D0EB26128}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7E8621A2-3513-5BAD-85D8-D624558847C7}\TypeLib]
"(Default)" = "{103DFC4E-147A-5606-9B4E-1C216DF227A1}"

[HKCR\Interface\{FEFD8F9E-7F71-5307-A9E8-D2E60A4AAECA}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{103DFC4E-147A-5606-9B4E-1C216DF227A1}\1.0]
"(Default)" = "GameTreatWidget 1.0 Type Library"

The process RegEdit.exe:3704 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssCheckUpdatesIntervalInSec]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSDelExp]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushEnableForOldUser]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableARP]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableDesktopShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\GameInfoURL]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAIGsListUrl]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SchedulingEnable]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\PropmtBeforeCreatingShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\PRV]
"eSSTy" = "1"

[HKLM\SOFTWARE\Conduit\AppPaths\GPlayer.exe]
"AppPath" = "%Program Files%\Free Ride Games\GPlayer.exe"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoDiskManagment]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\IGAOptions]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssCheckUpdatesIntervalInSec]
"Value" = "10800"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\OpenShortcutInIE]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFadingScheme]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\PRV]
"eLPL" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinCode]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAlreadyRunSuccessfully]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\CLG]
"LastSuccessfulErrURL" = "/opTools/errorReport.jsp"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RunPlayerOnStartUp]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssUserType]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSDelExp]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyRadio]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssEnable]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFirstTimeDelayInSec]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"Description" = "Exent® AOD Gecko Plugin"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\PropmtBeforeCreatingShortcut]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\GameInfoURL]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFadingScheme]
"Value" = "168,43200"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAlreadyRunSuccessfully]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeRadio]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"Path" = "%Program Files%\Free Ride Games\npExentCtl.dll"

[HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GTR.exe" = "9999"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableShortcut]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Enabled]
"Value" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"GTR.exe" = "9999"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyAddress]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Domain]
"IsVisible" = "0"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"ProductName" = "Games-On-Demand"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SchedulingEnable]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableDesktopShortcut]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RunPlayerOnStartUp]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Names]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssDefaultShowMsgDurationInSec]
"Value" = "60"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableARP]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinCode]
"Value" = "000005"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSNamesEx]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyPort]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssFeedUrl]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeReminderIntervalInMinutes]
"Value" = "4320"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckIntervalInMinutes]
"Value" = "360"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyPort]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"vendor" = "Exent Technologies Ltd."

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushShowMsgDurationInSec]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RunPlayerOnStartUp]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SchedulingEnable]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssFeedUrl]
"Value" = "http://www.freeridegames.com/do/messageRss"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssPersistentMessageFadingScheme]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\IGAOptions]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableDesktopShortcut]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\PRV]
"eSPT" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAIGsListUrl]
"Value" = "http://www.freeridegames.com/do/contentPush"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoErrorReport]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckIntervalInMinutes]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAlreadyRunSuccessfully]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckURL]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssDefaultShowMsgDurationInSec]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushShowMsgDurationInSec]
"Value" = "1200"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\OpenShortcutInIE]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushCheckTimerIntervalInSec]
"Value" = "900"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssDefaultShowMsgDurationInSec]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFirstTimeDelayInSec]
"Value" = "900"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"Version" = "7.0.0.0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushCheckTimerIntervalInSec]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckURL]
"Value" = "http://www.freeridegames.com/do/PlayerUpdateInfo"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Enabled]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\SkinCode]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoErrorReport]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"UseClientReportUrl" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssUserType]
"Value" = "new"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushCheckTimerIntervalInSec]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AccessWebPageConnectionTimeout]
"Value" = "20000"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Enabled]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyAddress]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoErrorReport]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Domain]
"Value" = "www.freeridegames.com"
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyRadio]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"ClientReportUrl" = "/opTools/clientReport.jsp"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssEnable]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeReminderIntervalInMinutes]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\GameInfoURL]
"Value" = "http://www.freeridegames.com/do/gameInfo?contentId=%GAME_ID%"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFadingScheme]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AccessWebPageConnectionTimeout]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\PropmtBeforeCreatingShortcut]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssPersistentMessageFadingScheme]
"Value" = "168,86400"

[HKLM\SOFTWARE\Exent\AOD\Client]
"ProviderId" = "143"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssEnable]
"Value" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\IGAOptions]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckURL]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Names]
"Value" = "143_CS,143_CAMPAIGN_SERIAL_ID,143_REACTIVATION_ID,143_TURNKEY"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSNamesEx]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AccessWebPageConnectionTimeout]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoDiskManagment]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssFeedUrl]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyRadio]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\EnableARP]
"Value" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"DisplayName" = "Fantastigames"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeRadio]
"IsVisible" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushAIGsListUrl]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushShowMsgDurationInSec]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyPort]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ProxyAddress]
"Value" = ""

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeCheckIntervalInMinutes]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeRadio]
"Value" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSNamesEx]
"Value" = "ON(143_CAMPAIGN_SERIAL_ID)ON(143_TURNKEY)ON(143_FIRST_BROWSER)NN(143_CAMPAIGN_PERFORMED_CONVERSIONS)NN(143_DAYS_PLAYED)NN(143_REACTIVATION_ID)NN(143_GAG)NN(143_PCKGS)NN(143_TOKEN)NN(143_EX_ID)"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoClientUpgradeReminderIntervalInMinutes]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssPersistentMessageFadingScheme]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssCheckUpdatesIntervalInSec]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\ContentPushFirstTimeDelayInSec]
"IsVisible" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\Names]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\AutoDiskManagment]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client]
"EnableDumpReport" = "0"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\OpenShortcutInIE]
"IsReadOnly" = "1"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\RssUserType]
"IsReadOnly" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"Publisher" = "Exent Technologies Ltd"

[HKLM\SOFTWARE\Exent\AOD\Client\Providers\143\Settings\CS\CSDelExp]
"IsReadOnly" = "1"

The process iKernel.exe:4016 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCR\Setup.LogServices.1\CLSID]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.LogServices]
"(Default)" = "SetupLogServices Class"

[HKCR\Setup.Kernel]
"(Default)" = "InstallShield setup kernel"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\LocalServer32]
"(Default)" = "C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.Kernel.1\CLSID]
"(Default)" = "{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{8c3c1b17-e59d-11d2-b40b-00a024b9dddd}\TreatAs]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\ProgID]
"(Default)" = "Setup.LogServices.1"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\VersionIndependentProgID]
"(Default)" = "Setup.Kernel"

[HKCR\Setup.Kernel\CLSID]
"(Default)" = "{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\LocalServer32]
"(Default)" = "C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.Kernel.1]
"(Default)" = "InstallShield setup kernel"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "InstallShield setup kernel"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\VersionIndependentProgID]
"(Default)" = "Setup.LogServices"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\ProgID]
"(Default)" = "Setup.Kernel.1"

[HKCR\CLSID\{8c3c1b17-e59d-11d2-b40b-00a024b9dddd}]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.LogServices\CLSID]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.LogServices.1]
"(Default)" = "SetupLogServices Class"

The process Free Ride Games.exe:3400 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"Ad" = "VMware SVGA 3D (Microsoft Corporation - WDDM)"

[HKLM\SOFTWARE\Exent\AOD\CLSID]
"NumberOfCLSIDs" = "1"
"CLSID1" = "0763D0076D174E3CD7001E0100004C5C8D6CBD5CBD76C57CDF1DDEAB604C78A1725C8D548DA90972F89EE50CEE844FB26C5C8B2256"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"advnid" = "5549"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\DirectInput\MostRecentApplication]
"ID" = "FREE RIDE GAMES.EXE534ABEC000075140"
"Version" = "0A 05 00 00"

[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1397407424"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASMANCS]
"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\DirectInput\MostRecentApplication]
"Name" = "FREE RIDE GAMES.EXE"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"gcm" = "832"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"gcr" = "6"

[HKCU\Software\AppDataLow\Software\Exent\AOD\SDM]
"ResumePage" = "index.html#PageId=SDM_PROGRESS"

[HKCU\Software\Microsoft\DirectInput\MostRecentApplication]
"MostRecentStart" = "C7 02 6B 56 58 21 D3 01"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"Tsl" = "1302014992"
"tsh" = "30613848"

[HKCU\Software\Classes\Local Settings\MuiCache\2E\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASMANCS]
"ConsoleTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Direct3D\MostRecentApplication]
"Name" = "Free Ride Games.exe"

[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "Free Ride Games.exe"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\C]
"tsh" = "30613848"
"CS" = "3400"
"Tsl" = "1302014992"

[HKLM\SOFTWARE\AppDataLow\Software\Exent\AOD\Client\DC\GC]
"advr" = "7.14.01.1134 built by: WinDDK"

[HKCU\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\DirectInput\VID_0E0F&PID_0003\Calibration\0]
"Guid" = "90 F8 5F B9 64 8D E7 11 80 01 44 45 53 54 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASMANCS]
"FileDirectory" = "%windir%\tracing"
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\Free Ride Games_RASAPI32]
"MaxFileSize" = "1048576"

To automatically run itself each time Windows is booted, the Malware adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"DependencyCheck" = "Performed"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Exent_SDM" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe l 'Startup' u 'http://www.freeridegames.com/do/SDMC?action=config&type=FANTASTIGAMES_EULA&contentId=%d' p '143' c '595450'"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Malware deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorNum"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorDesc"

The Malware disables automatic startup of the application by deleting the following autorun value:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Exent_SDM"

The process IKernel.exe:4032 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCR\Interface\{15F051E6-59A9-11D3-A25D-06D730000000}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{787D0980-F63F-462C-86BC-FC23847C70F4}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}\InprocServer32]
"(Default)" = "%Program Files%\Common Files\InstallShield\IScript\iscript.dll"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ProgID]
"(Default)" = "ExentCtl.ExentInf.1"

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}]
"Installer" = "MSICD"

[HKCR\Interface\{EDE94BF2-4FB9-11D5-ABAB-00B0D02332EB}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Exent\AOD\Client]
"FinishWindowMessage" = ""

[HKCR\Interface\{4DFB7010-41EB-11D3-BBBA-00105A1F0D68}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\MiscStatus\1]
"(Default)" = "132497"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"EnableFileTracing" = "0"

[HKCU\Software\Exent\AOD\Client\CLG]
"MaxFilesCount" = "16"

[HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303}]
"(Default)" = "ISetupPropertyBag"

[HKCR\Interface\{FEBEC920-1849-11D3-A8FE-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{220A6516-9695-47EF-9413-7BEDC27C34CF}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{BDF8B49D-16D0-49A5-B133-ABE7DCC23DAF}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\MozillaPlugins\www.exent.com/GameTreatWidget]
"Path" = "%Program Files%\FantastiGames\NPGameTreatPlugin.dll"

[HKCU\Software\Exent\AOD\Client\Installer]
"GroupFolderPath" = "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FantastiGames"

[HKCR\Setup.ScriptEngine.1]
"(Default)" = "InstallShield Script Engine"

[HKCR\Setup.ScriptEngine.1\CLSID]
"(Default)" = "{E7D06080-238B-11D3-80D7-00104B1F6CEA}"

[HKCR\Interface\{61892D50-28EF-11D3-A8FF-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\TypeLib\{6A06043B-60F9-11D5-A6CD-0002B31F7455}\1.0\0\win32]
"(Default)" = "C:\Windows\Downloaded Program Files\ExentCtl.ocx"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\TypeLib]
"(Default)" = "{6A06043B-60F9-11D5-A6CD-0002B31F7455}"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\ToolboxBitmap32]
"(Default)" = "C:\Windows\Downloaded Program Files\ExentCtl.ocx, 101"

[HKCR\Interface\{6A060447-60F9-11D5-A6CD-0002B31F7455}]
"(Default)" = "IExentInf"

[HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"DisplayIcon" = "%Program Files%\FantastiGames\Fantastigames_icon.ico"
"LogFile" = "%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\setup.ilg"

[HKCR\Interface\{067DBAA0-38DF-11D3-BBB7-00105A1F0D68}]
"(Default)" = "ISetupScriptEngine"

[HKCR\Interface\{15F051E6-59A9-11D3-A25D-06D730000000}\TypeLib]
"(Default)" = "{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\D]
"Keep Free Space" = "50"

[HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{80FDE82A-2CAA-11D3-88C3-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\C]
"Size" = "15462"

[HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC}]
"(Default)" = "ISetupMultiMedia"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\VersionIndependentProgID]
"(Default)" = "ExentCtl.ExentInf"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"EnableConsoleTracing" = "0"

[HKCR\TypeLib\{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Common Files\InstallShield\IScript\"

[HKCR\ExentCtl.ExentInf]
"(Default)" = "ExentInf Class"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Setup.ScriptDriverWrapper\CLSID]
"(Default)" = "{AA7E2086-CB55-11D2-8094-00104B1F9838}"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{9E561C6B-425D-4E3D-95CA-A2D289D7C3FB}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{FEBEC920-1849-11D3-A8FE-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{AFED5DD0-0694-11D4-A934-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{112EB4F0-5A48-11D3-A90A-00105A088FAC}]
"(Default)" = "ISetupWindowBillBoards"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}\InprocServer32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\ctor.dll"

[HKCR\Interface\{6A060447-60F9-11D5-A6CD-0002B31F7455}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"

[HKCR\Interface\{112EB4F0-5A48-11D3-A90A-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\IScript]
"iscript.dll" = "1"

[HKCR\Interface\{0C8D0880-1AC4-11D3-A8FF-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.User\CLSID]
"(Default)" = "{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}"

[HKCR\Setup.ScriptEngine\CLSID]
"(Default)" = "{E7D06080-238B-11D3-80D7-00104B1F6CEA}"

[HKCR\MIME\Database\Content Type\Application/x-rgmx]
"Extension" = ".rgmx"

[HKCR\EXEtender\DefaultIcon]
"(Default)" = "%Program Files%\FantastiGames\GPlayer.exe,0"

[HKCR\Interface\{112EB4F0-5A48-11D3-A90A-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\"

[HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\Interface\{0C8D0880-1AC4-11D3-A8FF-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BDF8B49D-16D0-49A5-B133-ABE7DCC23DAF}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\TypeLib\{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}\1.0]
"(Default)" = "Setup UI 1.0 Type Library"

[HKCR\Interface\{3D8B6331-D8B1-11D2-80C5-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}]
"(Default)" = "ExentInf Class"

[HKCR\Interface\{9B697780-DBBC-11D2-80C7-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{F4817E4B-04B6-11D3-8862-00C04F72F303}"

[HKCR\TypeLib\{27D2CF3C-D5B0-11D2-8094-00104B1F9838}\1.0\0\win32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\ctor.dll"

[HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\C]
"Games Dir" = "Remote Programs"

[HKLM\SOFTWARE\Exent\AOD\Client]
"BinPath" = "%Program Files%\FantastiGames"

[HKCR\Interface\{83755DD1-086B-11D3-8868-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{FEBEC920-1849-11D3-A8FE-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"MaxFileSize" = "1048576"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\InprocServer32]
"(Default)" = "C:\Windows\Downloaded Program Files\ExentCtl.ocx"

[HKCR\Interface\{9E561C6B-425D-4E3D-95CA-A2D289D7C3FB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{3D8B6331-D8B1-11D2-80C5-00104B1F6CEA}]
"(Default)" = "ISetupUserInterface"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"Progress" = "0"

[HKLM\SOFTWARE\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"Path" = "%Program Files%\FantastiGames\npExentCtl.dll"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}\ProgID]
"(Default)" = "Setup.ScriptDriverWrapper.1"

[HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}\InprocServer32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\iuser.dll"

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}]
"SystemComponent" = "0"

[HKCR\Interface\{9E561C6B-425D-4E3D-95CA-A2D289D7C3FB}]
"(Default)" = "ISetupMainWindow4"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\D]
"Size" = "925"

[HKCR\Setup.ScriptDriverWrapper.1\CLSID]
"(Default)" = "{AA7E2086-CB55-11D2-8094-00104B1F9838}"

[HKCR\Interface\{61892D50-28EF-11D3-A8FF-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{F4817E4B-04B6-11D3-8862-00C04F72F303}\NumMethods]
"(Default)" = "6"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\Version]
"(Default)" = "1.0"

[HKCR\Interface\{80FDE82A-2CAA-11D3-88C3-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{B964AF40-4AB7-11D3-A908-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{103DFC4E-147A-5606-9B4E-1C216DF227A1}\1.0\HELPDIR]
"(Default)" = "%Program Files%\FantastiGames"

[HKCR\Interface\{6A060447-60F9-11D5-A6CD-0002B31F7455}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\EXEtender]
"EditFlags" = "00 00 01 00"

[HKCR\Interface\{AA7E2064-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.ScriptObjectWrapper.1\CLSID]
"(Default)" = "{AA7E2087-CB55-11D2-8094-00104B1F9838}"

[HKCR\Interface\{B964AF40-4AB7-11D3-A908-00105A088FAC}]
"(Default)" = "ISetupSDMessage"

[HKCR\Interface\{0C8D0880-1AC4-11D3-A8FF-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\engine\6\Intel 32]
"objectps.dll" = "1"

[HKCR\Interface\{9E561C6B-425D-4E3D-95CA-A2D289D7C3FB}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%WinDir%\Downloaded Program Files]
"ExentCtl.ocx" = "1"

[HKCR\ExentCtl.ExentInf\CurVer]
"(Default)" = "ExentCtl.ExentInf.1"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{AFED5DD0-0694-11D4-A934-00105A088FAC}]
"(Default)" = "ISetupRebootable"

[HKCR\Interface\{3D8B6331-D8B1-11D2-80C5-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ExentCtl.ocx]
".Owner" = "{6A060448-60F9-11D5-A6CD-0002B31F7455}"

[HKCR\Interface\{3EDC2C10-66FE-11D3-A90F-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{15F051E6-59A9-11D3-A25D-06D730000000}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{0C8D0880-1AC4-11D3-A8FF-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2064-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\D]
"Games Dir" = "Remote Programs"

[HKCR\Interface\{AFED5DD0-0694-11D4-A934-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\engine\6\Intel 32]
"ctor.dll" = "1"

[HKCR\Interface\{B964AF40-4AB7-11D3-A908-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\TypeLib\{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}\1.0]
"(Default)" = "InstallShield Script 1.0 Type Library"

[HKCR\Interface\{6494206F-23EA-11D3-88B0-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{6A060447-60F9-11D5-A6CD-0002B31F7455}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{0C8D0880-1AC4-11D3-A8FF-00105A088FAC}]
"(Default)" = "ISetupWindowImage"

[HKCR\Interface\{BDF8B49D-16D0-49A5-B133-ABE7DCC23DAF}]
"(Default)" = "ISetupProgress2"

[HKCR\Interface\{4DFB7010-41EB-11D3-BBBA-00105A1F0D68}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\AppDataLow\Software\Exent\AOD\ExentCtl]
"runInstallFlag" = "1"

[HKCR\ExentCtl.ExentInf.1]
"(Default)" = "ExentInf Class"

[HKCR\Interface\{BDF8B49D-16D0-49A5-B133-ABE7DCC23DAF}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{4DFB7010-41EB-11D3-BBBA-00105A1F0D68}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\engine\6\Intel 32]
"iKernel.exe" = "1"

[HKCR\Interface\{94F4A332-A2AE-11D3-8378-00C04F59FBE9}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\InstalledVersion]
"LastModified" = "Thu, 18 Mar 2010 09:18:36 GMT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"DisplayName" = "FantastiGames Player"

[HKCR\Interface\{B964AF40-4AB7-11D3-A908-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Setup.ScriptDriverWrapper.1]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\Interface\{EDE94BF2-4FB9-11D5-ABAB-00B0D02332EB}\TypeLib]
"(Default)" = "{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}"

[HKCR\Interface\{112EB4F0-5A48-11D3-A90A-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{3D8B6332-D8B1-11D2-80C5-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{83755DD1-086B-11D3-8868-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{787D0980-F63F-462C-86BC-FC23847C70F4}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{15F051E6-59A9-11D3-A25D-06D730000000}]
"(Default)" = "ISetupScriptError"

[HKCR\Interface\{15F051E6-59A9-11D3-A25D-06D730000000}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{83755DD1-086B-11D3-8868-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{FEBEC920-1849-11D3-A8FE-00105A088FAC}]
"(Default)" = "ISetupWindowText"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"UninstallStringOriginal" = "%Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setup.exe"

[HKCR\Setup.ScriptEngine]
"(Default)" = "InstallShield Script Engine"

[HKCR\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32]
"ThreadingModel" = "Both"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{00345390-4F77-11D3-A908-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}\InprocServer32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\ctor.dll"

[HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}\ProgID]
"(Default)" = "Setup.ScriptEngine.1"

[HKCR\Interface\{83755DD1-086B-11D3-8868-00C04F72F303}]
"(Default)" = "ISetupObjectLifetime"

[HKCR\Interface\{83755DD1-086B-11D3-8868-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9B697780-DBBC-11D2-80C7-00104B1F6CEA}\NumMethods]
"(Default)" = "5"

[HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}]
"(Default)" = "InstallShield setup user interafce"

[HKCR\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}]
"(Default)" = "PSFactoryBuffer"

[HKCR\Setup.ScriptDriverWrapper]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\TypeLib\{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}\1.0\0\win32]
"(Default)" = "%Program Files%\Common Files\InstallShield\IScript\iscript.dll"

[HKCR\Interface\{067DBAA0-38DF-11D3-BBB7-00105A1F0D68}\TypeLib]
"Version" = "1.0"
"(Default)" = "{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\MiscStatus]
"(Default)" = "0"

[HKCR\Interface\{EDE94BF2-4FB9-11D5-ABAB-00B0D02332EB}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{6A06043B-60F9-11D5-A6CD-0002B31F7455}\1.0\HELPDIR]
"(Default)" = "C:\Windows\Downloaded Program Files\"

[HKCR\Interface\{EDE94BF2-4FB9-11D5-ABAB-00B0D02332EB}]
"(Default)" = "ISetupScriptEngine2"

[HKCR\Setup.ScriptObjectWrapper]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\Interface\{61892D50-28EF-11D3-A8FF-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Exent\AOD\Client\Disks\C]
"Keep Free Space" = "50"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{94F4A332-A2AE-11D3-8378-00C04F59FBE9}]
"(Default)" = "ISetupMainWindow2"

[HKCR\Interface\{3EDC2C10-66FE-11D3-A90F-00105A088FAC}]
"(Default)" = "ISetupGUIObject"

[HKCR\Interface\{220A6516-9695-47EF-9413-7BEDC27C34CF}\TypeLib]
"(Default)" = "{6A06043B-60F9-11D5-A6CD-0002B31F7455}"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"EnableFileTracing" = "0"

[HKCR\Interface\{F4817E4B-04B6-11D3-8862-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{F4817E4B-04B6-11D3-8862-00C04F72F303}"

[HKCR\Interface\{AFED5DD0-0694-11D4-A934-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FantastiGames]
"Path" = "%Program Files%\FantastiGames"

[HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{787D0980-F63F-462C-86BC-FC23847C70F4}]
"(Default)" = "ISetupMainWindow3"

[HKCR\Setup.User.1]
"(Default)" = "InstallShield setup user interafce"

[HKCR\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\Interface\{BDF8B49D-16D0-49A5-B133-ABE7DCC23DAF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}\VersionIndependentProgID]
"(Default)" = "Setup.ScriptEngine"

[HKCR\ExentCtl.ExentInf\CLSID]
"(Default)" = "{6A060448-60F9-11D5-A6CD-0002B31F7455}"

[HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}\VersionIndependentProgID]
"(Default)" = "Setup.User"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\engine\6\Intel 32]
"corecomp.ini" = "1"

[HKCR\Interface\{787D0980-F63F-462C-86BC-FC23847C70F4}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\Exent\AOD\Client]
"muid" = "303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB"

[HKCR\Interface\{AA7E2064-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\EXEtender]
"(Default)" = "EXEtender"

[HKCR\Interface\{61892D50-28EF-11D3-A8FF-00105A088FAC}]
"(Default)" = "ISetupProgress"

[HKCR\Interface\{4DFB7010-41EB-11D3-BBBA-00105A1F0D68}]
"(Default)" = "ISetupScriptController"

[HKCR\Interface\{AA7E2064-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKCR\Interface\{6A060447-60F9-11D5-A6CD-0002B31F7455}\TypeLib]
"(Default)" = "{6A06043B-60F9-11D5-A6CD-0002B31F7455}"

[HKCR\Interface\{FEBEC920-1849-11D3-A8FE-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"MaxFileSize" = "1048576"

[HKCR\Interface\{94F4A332-A2AE-11D3-8378-00C04F59FBE9}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{9B697780-DBBC-11D2-80C7-00104B1F6CEA}]
"(Default)" = "ISetupObjectClass"

[HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{3EDC2C10-66FE-11D3-A90F-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{112EB4F0-5A48-11D3-A90A-00105A088FAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{3D8B6332-D8B1-11D2-80C5-00104B1F6CEA}]
"(Default)" = "ISetupMainWindow"

[HKCR\TypeLib\{27D2CF3C-D5B0-11D2-8094-00104B1F9838}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\"

[HKCR\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}\VersionIndependentProgID]
"(Default)" = "Setup.ScriptDriverWrapper"

[HKCR\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}\ProgID]
"(Default)" = "Setup.User.1"

[HKCR\Interface\{AA7E2064-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupWizardUI"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"FileTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCR\Interface\{9E561C6B-425D-4E3D-95CA-A2D289D7C3FB}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{220A6516-9695-47EF-9413-7BEDC27C34CF}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Exent\AOD\Client]
"FinishWindow" = "0"

[HKCR\Interface\{94F4A332-A2AE-11D3-8378-00C04F59FBE9}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FantastiGames]
"(Default)" = "%Program Files%\FantastiGames\FantastiGames"

[HKCR\Interface\{3D8B6331-D8B1-11D2-80C5-00104B1F6CEA}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ExentCtl.ocx]
"{6A060448-60F9-11D5-A6CD-0002B31F7455}" = ""

[HKCR\TypeLib\{6A06043B-60F9-11D5-A6CD-0002B31F7455}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{4DFB7010-41EB-11D3-BBBA-00105A1F0D68}\TypeLib]
"(Default)" = "{DED1EA29-3F89-11D3-BBB9-00105A1F0D68}"

[HKCR\Setup.ScriptObjectWrapper\CLSID]
"(Default)" = "{AA7E2087-CB55-11D2-8094-00104B1F9838}"

[HKCR\Interface\{3D8B6332-D8B1-11D2-80C5-00104B1F6CEA}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\objectps.dll"

[HKCR\.rgmx]
"Content Type" = "application/x-rgmx"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}]
"UninstallString" = "RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setup.exe -l0x9"

[HKCR\Interface\{EDE94BF2-4FB9-11D5-ABAB-00B0D02332EB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AFED5DD0-0694-11D4-A934-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{80FDE82A-2CAA-11D3-88C3-00C04F72F303}]
"(Default)" = "ISetupObjectReboot"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCR\Interface\{61892D50-28EF-11D3-A8FF-00105A088FAC}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%Program Files%\Common Files\InstallShield\engine\6\Intel 32]
"iuser.dll" = "1"

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\Contains\Files\%WinDir%\Downloaded Program Files]
"ExentCtl.ocx" = ""

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\DownloadInformation]
"CodeBase" = ""

[HKCR\TypeLib\{6A06043B-60F9-11D5-A6CD-0002B31F7455}\1.0]
"(Default)" = "ExentCtl 1.0 Type Library"

[HKCR\EXEtender\Shell\Open\Command]
"(Default)" = "%Program Files%\FantastiGames\GPlayer.exe %1"

[HKCR\TypeLib\{103DFC4E-147A-5606-9B4E-1C216DF227A1}\1.0\0\win32]
"(Default)" = "%Program Files%\FantastiGames\npGameTreatWidget.dll"

[HKCR\Interface\{3D8B6332-D8B1-11D2-80C5-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EBFFAE0-F0A4-4ee6-8524-2751906624C4}]
"AppPath" = "%Program Files%\FantastiGames"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"EnableConsoleTracing" = "0"

[HKCR\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\ExentCtl.ExentInf.1\CLSID]
"(Default)" = "{6A060448-60F9-11D5-A6CD-0002B31F7455}"

[HKCR\Interface\{3D8B6331-D8B1-11D2-80C5-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{067DBAA0-38DF-11D3-BBB7-00105A1F0D68}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{3D8B6332-D8B1-11D2-80C5-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}\VersionIndependentProgID]
"(Default)" = "Setup.ScriptObjectWrapper"

[HKCR\Interface\{220A6516-9695-47EF-9413-7BEDC27C34CF}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Setup.User]
"(Default)" = "InstallShield setup user interafce"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\CLSID\{44d07caa-4fc4-5a84-9951-a485ad808d0e}\InprocServer32]
"(Default)" = "%Program Files%\FantastiGames\npGameTreatWidget.dll"

[HKCR\Interface\{067DBAA0-38DF-11D3-BBB7-00105A1F0D68}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{94F4A332-A2AE-11D3-8378-00C04F59FBE9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{80FDE82A-2CAA-11D3-88C3-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorDesc" = "Completed"

[HKCR\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{F4817E4B-04B6-11D3-8862-00C04F72F303}]
"(Default)" = "ISetupServiceProvider"

[HKCR\Setup.ScriptObjectWrapper.1]
"(Default)" = "InstallShield setup object wrapper"

[HKCR\TypeLib\{27D2CF3C-D5B0-11D2-8094-00104B1F9838}\1.0]
"(Default)" = "InstallShield Runtime 1.0 Type Library"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{3EDC2C10-66FE-11D3-A90F-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{220A6516-9695-47EF-9413-7BEDC27C34CF}]
"(Default)" = "_IExentInfEvents"

[HKCR\Setup.User.1\CLSID]
"(Default)" = "{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}"

[HKCR\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}\ProgID]
"(Default)" = "Setup.ScriptObjectWrapper.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6A060448-60F9-11D5-A6CD-0002B31F7455}]
"(Default)" = ""

[HKCR\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}]
"(Default)" = "InstallShield Script Engine"

[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455}\InstalledVersion]
"(Default)" = "07,03,00,00"

[HKCR\Interface\{3EDC2C10-66FE-11D3-A90F-00105A088FAC}\TypeLib]
"(Default)" = "{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}"

[HKCR\Interface\{B964AF40-4AB7-11D3-A908-00105A088FAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{787D0980-F63F-462C-86BC-FC23847C70F4}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\Interface\{80FDE82A-2CAA-11D3-88C3-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKLM\SOFTWARE\Microsoft\Tracing\IKernel_RASMANCS]
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorNum" = "0"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\TypeLib]
"(Default)" = "{27D2CF3C-D5B0-11D2-8094-00104B1F9838}"

[HKCR\TypeLib\{27D2CF3C-D5B0-11D2-8094-00104B1F9838}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\TypeLib\{682C25C5-D7D9-11D2-80C5-00104B1F6CEA}\1.0\0\win32]
"(Default)" = "%Program Files%\Common Files\InstallShield\engine\6\Intel 32\iuser.dll"

[HKCR\.rgmx]
"(Default)" = "EXEtender"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the Malware adds the following link to its file to the system registry autorun key:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

[HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

[HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

The Malware deletes the following value(s) in system registry:

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"Progress"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorNum"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKLM\SOFTWARE\Exent\AOD\Client]
"FinishWindowMessage"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ExtResponse"

[HKCU\Software\Exent\AOD\Client]
"DefaultFeedbackUrl"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKCU\Software\AppDataLow\Software\Exent\AOD\IS]
"ErrorDesc"

[HKLM\SOFTWARE\Exent\AOD\Client]
"FinishWindow"

The process IKernel.exe:2144 makes changes in the system registry.
The Malware creates and/or sets the following values in system registry:

[HKCR\Interface\{1B1B8830-C559-11D3-B289-00C04F59FBE9}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{1F9922A2-F026-11D2-8822-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{54DADAB3-28A6-11D3-88BA-00C04F72F303}]
"(Default)" = "ISetupFileService"

[HKCR\Interface\{8C3C1B14-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7BB118F1-6D5B-470E-82D0-AFB042724560}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8415DE38-1C1D-11D3-889D-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{54DADAB2-28A6-11D3-88BA-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2084-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{761C8359-55AF-4E7B-9C83-C1A927E0F617}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{44D61997-B7D4-11D2-80BA-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Setup.LogServices]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{91814EC3-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Setup.Kernel]
"(Default)" = "InstallShield setup kernel"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{54DADAB3-28A6-11D3-88BA-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\LocalServer32]
"(Default)" = "C:\PROGRA~1\COMMON~1\INSTAL~1\Engine\6\INTEL3~1\IKernel.exe"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{9CFCFE67-0BB8-43E0-8425-378D0A02ACE4}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupTransferEvents"

[HKCR\Interface\{1B1B8830-C559-11D3-B289-00C04F59FBE9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\"

[HKCR\Interface\{C4AAC3B1-C547-11D3-B289-00C04F59FBE9}]
"(Default)" = "ISetupRegistry2"

[HKCR\Interface\{1B1B8830-C559-11D3-B289-00C04F59FBE9}]
"(Default)" = "ISetupShellLink2"

[HKCR\Interface\{DAB9BF17-267D-11D3-88B6-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{54DADAB2-28A6-11D3-88BA-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{E1B9357F-24B9-11D3-88B2-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8415DDF9-1C1D-11D3-889D-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{348440B0-C79A-11D3-B28B-00C04F59FBE9}]
"(Default)" = "ISetupShell2"

[HKCR\Interface\{3EE77D8B-40C1-4A2A-9B77-421907F02058}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{3EE77D8B-40C1-4A2A-9B77-421907F02058}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8415DDF9-1C1D-11D3-889D-00C04F72F303}]
"(Default)" = "ISetupShell"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupOpTypes"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupOpType"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BE6115A1-7DE5-48DC-AD2A-25060E00FCE2}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Setup.Kernel\CLSID]
"(Default)" = "{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}]
"(Default)" = "ISetupTransferErrorInfo"

[HKCR\Interface\{9CFCFE67-0BB8-43E0-8425-378D0A02ACE4}]
"(Default)" = "ISetupCABFile2"

[HKCR\Interface\{65D37452-0EBB-11D3-887B-00C04F72F303}]
"(Default)" = "ISetupRegistry"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{91814EC5-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1B1B8830-C559-11D3-B289-00C04F59FBE9}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7D795704-435D-11D3-88FF-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9CFCFE67-0BB8-43E0-8425-378D0A02ACE4}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{348440B0-C79A-11D3-B28B-00C04F59FBE9}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{1B1B8830-C559-11D3-B289-00C04F59FBE9}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{251753FA-FB3B-11D2-8842-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{6B15A454-9067-4878-B10E-B9DFFE03049D}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{7D795704-435D-11D3-88FF-00C04F72F303}]
"(Default)" = "ISetupFileErrors"

[HKCR\Interface\{E1B9357F-24B9-11D3-88B2-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DAB9BF17-267D-11D3-88B6-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{91814EC5-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "ISetupComponents"

[HKCR\Interface\{39040274-3D36-11D3-88EE-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7BB118F1-6D5B-470E-82D0-AFB042724560}]
"(Default)" = "ISetupReboot2"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{1F9922A2-F026-11D2-8822-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{6B15A454-9067-4878-B10E-B9DFFE03049D}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2067-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{0BA4BA22-2EF0-11D3-88C8-00C04F72F303}]
"(Default)" = "ISetupSharedFiles"

[HKCR\Interface\{3EE77D8B-40C1-4A2A-9B77-421907F02058}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8415DE38-1C1D-11D3-889D-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EC3-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DAB9BF17-267D-11D3-88B6-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{65D37452-0EBB-11D3-887B-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{761C8359-55AF-4E7B-9C83-C1A927E0F617}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{39040274-3D36-11D3-88EE-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2067-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}]
"(Default)" = "ISetupBasicFeature"

[HKCR\Interface\{1F9922A2-F026-11D2-8822-00C04F72F303}]
"(Default)" = "ISetupObjectContext"

[HKCR\CLSID\{8c3c1b17-e59d-11d2-b40b-00a024b9dddd}\TreatAs]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{91814EC3-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{7D795704-435D-11D3-88FF-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2084-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EC3-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{65D37452-0EBB-11D3-887B-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BE6115A1-7DE5-48DC-AD2A-25060E00FCE2}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{D4FF39B9-1A05-11D3-8896-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{348440B0-C79A-11D3-B28B-00C04F59FBE9}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2067-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{E1B9357F-24B9-11D3-88B2-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{BE6115A1-7DE5-48DC-AD2A-25060E00FCE2}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{8c3c1b17-e59d-11d2-b40b-00a024b9dddd}]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{91814EC1-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.Kernel.1]
"(Default)" = "InstallShield setup kernel"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1F9922A2-F026-11D2-8822-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\VersionIndependentProgID]
"(Default)" = "Setup.LogServices"

[HKCR\Interface\{BE6115A1-7DE5-48DC-AD2A-25060E00FCE2}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2084-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}\1.0]
"(Default)" = "Setup Kernel 1.0 Type Library"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{761C8359-55AF-4E7B-9C83-C1A927E0F617}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8415DDF9-1C1D-11D3-889D-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{6B15A454-9067-4878-B10E-B9DFFE03049D}]
"(Default)" = "ISetupLogDB2"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7BB118F1-6D5B-470E-82D0-AFB042724560}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{7BB118F1-6D5B-470E-82D0-AFB042724560}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{54DADAB2-28A6-11D3-88BA-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{348440B0-C79A-11D3-B28B-00C04F59FBE9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupFeatureLogs"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8C3C1B14-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8415DDF9-1C1D-11D3-889D-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EBF-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "ISetupMedia"

[HKCR\Interface\{8C3C1B14-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{91814EBF-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{54DADAB2-28A6-11D3-88BA-00C04F72F303}]
"(Default)" = "ISetupCopyFiles"

[HKCR\Interface\{91814EC1-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "ISetupCABFile"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{8C3C1B14-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{251753FA-FB3B-11D2-8842-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{9CFCFE67-0BB8-43E0-8425-378D0A02ACE4}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DAB9BF17-267D-11D3-88B6-00C04F72F303}]
"(Default)" = "ISetupTextSubstitution"

[HKCR\TypeLib\{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupOpSequence"

[HKCR\Interface\{C4AAC3B1-C547-11D3-B289-00C04F59FBE9}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{91814EC5-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{E1B9357F-24B9-11D3-88B2-00C04F72F303}]
"(Default)" = "ISetupInfo"

[HKCR\Interface\{54DADAB3-28A6-11D3-88BA-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BE6115A1-7DE5-48DC-AD2A-25060E00FCE2}]
"(Default)" = "ISetupTransferEvents2"

[HKCR\TypeLib\{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}\1.0\0\win32]
"(Default)" = "%Program Files%\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe"

[HKCR\Interface\{65D37452-0EBB-11D3-887B-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1F9922A2-F026-11D2-8822-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{39040274-3D36-11D3-88EE-00C04F72F303}]
"(Default)" = "ISetupReboot"

[HKCR\Interface\{44D61997-B7D4-11D2-80BA-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EBF-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{44D61997-B7D4-11D2-80BA-00104B1F6CEA}]
"(Default)" = "ISetupCABFiles"

[HKCR\Interface\{91814EC1-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{D4FF39BB-1A05-11D3-8896-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{39040274-3D36-11D3-88EE-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EBF-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\CLSID\{22D84EC7-E201-4432-B3ED-A9DCA3604594}\ProgID]
"(Default)" = "Setup.LogServices.1"

[HKCR\Interface\{C4AAC3B1-C547-11D3-B289-00C04F59FBE9}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{0BA4BA22-2EF0-11D3-88C8-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupFeature"

[HKCR\Interface\{D4FF39BB-1A05-11D3-8896-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "InstallShield setup kernel"

[HKCR\Interface\{6B15A454-9067-4878-B10E-B9DFFE03049D}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{348440B0-C79A-11D3-B28B-00C04F59FBE9}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EC1-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{761C8359-55AF-4E7B-9C83-C1A927E0F617}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\ProgID]
"(Default)" = "Setup.Kernel.1"

[HKCR\Interface\{8415DE38-1C1D-11D3-889D-00C04F72F303}]
"(Default)" = "ISetupShellLink"

[HKCR\Interface\{AA7E2084-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupObjectHolder"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{D4FF39B9-1A05-11D3-8896-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{D4FF39BB-1A05-11D3-8896-00C04F72F303}]
"(Default)" = "ISetupTypes"

[HKCR\Interface\{AF57A6F1-4101-11D3-88F6-00C04F72F303}]
"(Default)" = "ISetupFileErrorInfo"

[HKCR\Interface\{8C3C1B10-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupLogDB"

[HKCR\Interface\{54DADAB3-28A6-11D3-88BA-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AF57A6F0-4101-11D3-88F6-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{D4FF39B9-1A05-11D3-8896-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupObjects"

[HKCR\Interface\{AA7E2084-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{0BA4BA22-2EF0-11D3-88C8-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2061-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.LogServices.1\CLSID]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{3EE77D8B-40C1-4A2A-9B77-421907F02058}]
"(Default)" = "ISetupComponent2"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupFeatureLog"

[HKCR\Interface\{3EE77D8B-40C1-4A2A-9B77-421907F02058}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EC5-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7D795704-435D-11D3-88FF-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{D4FF39BB-1A05-11D3-8896-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{DAB9BF17-267D-11D3-88B6-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.Kernel.1\CLSID]
"(Default)" = "{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupDriver"

[HKCR\Interface\{8C3C1B16-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{D4FF39BB-1A05-11D3-8896-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8415DE38-1C1D-11D3-889D-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{91814EBF-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2067-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}]
"(Default)" = "ISetupFilesCost"

[HKCR\Interface\{39040274-3D36-11D3-88EE-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{91814EC5-B5F0-11D2-80B9-00104B1F6CEA}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{8415DDF9-1C1D-11D3-889D-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{C4AAC3B1-C547-11D3-B289-00C04F59FBE9}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2069-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupFeatures"

[HKCR\Interface\{0BA4BA22-2EF0-11D3-88C8-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{C4AAC3B1-C547-11D3-B289-00C04F59FBE9}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{E1B9357F-24B9-11D3-88B2-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B14-E59D-11D2-B40B-00A024B9DDDD}]
"(Default)" = "ISetupLogService"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{44D61997-B7D4-11D2-80BA-00104B1F6CEA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2067-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupStringTable"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\VersionIndependentProgID]
"(Default)" = "Setup.Kernel"

[HKCR\Interface\{251753FA-FB3B-11D2-8842-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{251753FA-FB3B-11D2-8842-00C04F72F303}]
"(Default)" = "ISetupFileRegistrar"

[HKCR\Interface\{761C8359-55AF-4E7B-9C83-C1A927E0F617}]
"(Default)" = "ISetupMedia2"

[HKCR\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}\LocalServer32]
"(Default)" = "C:\PROGRA~1\COMMON~1\INSTAL~1\Engine\6\INTEL3~1\IKernel.exe"

[HKCR\Interface\{91814EC1-B5F0-11D2-80B9-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{D4FF39B9-1A05-11D3-8896-00C04F72F303}]
"(Default)" = "ISetupType"

[HKCR\Interface\{251753FA-FB3B-11D2-8842-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{AA7E2062-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupTransfer"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B15-E59D-11D2-B40B-00A024B9DDDD}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Setup.LogServices.1]
"(Default)" = "SetupLogServices Class"

[HKCR\Interface\{44D61997-B7D4-11D2-80BA-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{7BB118F1-6D5B-470E-82D0-AFB042724560}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{91814EC3-B5F0-11D2-80B9-00104B1F6CEA}]
"(Default)" = "ISetupComponent"

[HKCR\Interface\{6B15A454-9067-4878-B10E-B9DFFE03049D}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{7D795704-435D-11D3-88FF-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{0BA4BA22-2EF0-11D3-88C8-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{54DADAB3-28A6-11D3-88BA-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{65D37452-0EBB-11D3-887B-00C04F72F303}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{AA7E2065-CB55-11D2-8094-00104B1F9838}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{8C3C1B12-E59D-11D2-B40B-00A024B9DDDD}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{D4FF39B9-1A05-11D3-8896-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{8415DE38-1C1D-11D3-889D-00C04F72F303}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{AA7E2060-CB55-11D2-8094-00104B1F9838}]
"(Default)" = "ISetupObject"

[HKCR\Interface\{54DADAB2-28A6-11D3-88BA-00C04F72F303}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Setup.LogServices\CLSID]
"(Default)" = "{22D84EC7-E201-4432-B3ED-A9DCA3604594}"

[HKCR\Interface\{DED5FEEC-225A-11D3-88AA-00C04F72F303}\TypeLib]
"(Default)" = "{91814EB1-B5F0-11D2-80B9-00104B1F6CEA}"

[HKCR\Interface\{9CFCFE67-0BB8-43E0-8425-378D0A02ACE4}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{2583251F-0A04-11D3-886B-00C04F72F303}]
"(Default)" = "ISetupBasicFeatureStateEvents"

Dropped PE files

MD5 File path
b3fd01873bd5fd163ab465779271c58f c:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
003a6c011aac993bcde8c860988ce49b c:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
377765fd4de3912c0f814ee9f182feda c:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
8f02b204853939f8aefe6b07b283be9a c:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
b2f7e6dc7e4aae3147fbfc74a2ddb365 c:\Program Files\Common Files\InstallShield\IScript\iscript.dll
72ef2d24d0efd50633e348426acb452f c:\Program Files\FantastiGames\AX32.dll
ac80238406a02347e681b814b993c724 c:\Program Files\FantastiGames\AppLoader2KEx.dll
4974c51ebfe23ea462f4d081e98e95f1 c:\Program Files\FantastiGames\DoDlg.exe
d1988886931fa85179d058e5a325a166 c:\Program Files\FantastiGames\GPlayer.exe
2883cd6742228fcf44009dbf7c2c79d5 c:\Program Files\FantastiGames\GPlrLanc.exe
9235f77aae0362677d15bfc80bb1940a c:\Program Files\FantastiGames\GUpdater.dll
3aebaa29a87560f522509fc650aecaa9 c:\Program Files\FantastiGames\GUpdater.exe
f9508c58e623cf25c5c0ac4512fdd6ff c:\Program Files\FantastiGames\GameInst.dll
9d7a04f91b006e4e03df921e5c3da7d3 c:\Program Files\FantastiGames\GameLauncher.exe
1c4d4642eb024a2feac7a6e6bb5cd07b c:\Program Files\FantastiGames\Report.exe
6ab44d3bfcbb2a3b25aa5c40c8beb451 c:\Program Files\FantastiGames\Uninstall.exe
549d2f6d72267e727ed29baef05aa68b c:\Program Files\FantastiGames\X4Ex_Pr143.sys
51b3cc1f1a2762f31ac35560a1de9004 c:\Program Files\FantastiGames\X4HSEx_Pr143.sys
d6e78146601f20ba947bc9576c3c0fb4 c:\Program Files\FantastiGames\X5Ex_Pr143.sys
8ab65f649dd26b8adb9995b31b5d8595 c:\Program Files\FantastiGames\X5XSEx_Pr143.sys
137008d640c0db7c6c88d444334570e9 c:\Program Files\FantastiGames\X6Ex_Pr143.sys
636248dae1ff854d29fe7beed971a73a c:\Program Files\FantastiGames\X6XSEx_Pr143.sys
d6e78146601f20ba947bc9576c3c0fb4 c:\Program Files\FantastiGames\X7Ex_Pr143.sys
8ab65f649dd26b8adb9995b31b5d8595 c:\Program Files\FantastiGames\X7XSEx_Pr143.sys
137008d640c0db7c6c88d444334570e9 c:\Program Files\FantastiGames\X8Ex_Pr143.sys
636248dae1ff854d29fe7beed971a73a c:\Program Files\FantastiGames\X8XSEx_Pr143.sys
99a82d11ce14d028cbccd521c7bfd034 c:\Program Files\FantastiGames\cmhelper.exe
39c858645cbf37b83bc907e188f8bc85 c:\Program Files\FantastiGames\d3dx9_32.dll
830ca30357530780437c5d4a7de19777 c:\Program Files\FantastiGames\exs.dll
55c38709c3c879b2d0fa24f751d2c824 c:\Program Files\FantastiGames\glutil.dll
3242c94d9c7e35690d48ca717c3ad4d6 c:\Program Files\FantastiGames\npExentCtl.dll
91ce51cbf504a58780c51a0c0193799a c:\Program Files\FantastiGames\npGameTreatWidget.dll
9bc0902f50e58167b4b778ef6f1b1103 c:\Program Files\FantastiGames\wh_Pr143.dll
dd480d149d75badbe0e130e8c3663cfb c:\Program Files\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setup.exe
5fc1bb4249d11957616ab7d1591c93cc c:\ProgramData\FantastiGames\ExentCtl.ocx
dd480d149d75badbe0e130e8c3663cfb c:\ProgramData\FantastiGames\Setup.exe
95ebe8539106eb728f0b3d7b466e6942 c:\ProgramData\FantastiGames\exs.dll
5fc1bb4249d11957616ab7d1591c93cc c:\Users\All Users\FantastiGames\ExentCtl.ocx
dd480d149d75badbe0e130e8c3663cfb c:\Users\All Users\FantastiGames\Setup.exe
95ebe8539106eb728f0b3d7b466e6942 c:\Users\All Users\FantastiGames\exs.dll
6c7a85044feccb6db965d859ead5fee3 c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\4cb7ea78-f9d1-4dd1-99d3-ea9ee82326e8
764dda95f9699fa1a0dd55c0996c3a5d c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\ExentCtlInstaller.dll
e376f21c82146a223e588009eebce770 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe
68049aa04fadd2dc3dacd81ee64bd95a c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\FreeRideGames.exe
6d6f40b115a06e567d7afd9bcb9c8768 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\cmhelper.exe
9f2a4639efc1271cae6c49f3340424fd c:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\resourceDll.dll
5fc1bb4249d11957616ab7d1591c93cc c:\Windows\Downloaded Program Files\ExentCtl.ocx
366f15af00817534a1e6485bf0cc0d08 c:\Windows\ExentInfo.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

Using the driver " \??\%Program Files%\FantastiGames\X6XSEx_Pr143.Sys" the Malware attaches its filter-device object to the Volume Device Object (VDO) of the file system driver.

Propagation

VersionInfo

Company Name: Exent Technologies Ltd.
Product Name: ExentCtl Module
Product Version: 07.02.00.01
Legal Copyright: Copyright (c) 1996-2007 Exent Technologies Ltd. All rights reserved.
Legal Trademarks:
Original Filename: ExentCtl.ocx
Internal Name: ExentCtl
File Version: 07.02.00.01
File Description: ExentCtl Module
Comments: Release.
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 67586 69632 4.53151 13d4df63a29071e604d09a6768d2e641
.rdata 73728 9413 12288 2.89315 1aae2e1490b0b801344569bed4d29505
.data 86016 19400 16384 0.903431 b02c7e2c998cd8ec273626efa37333f3
.rsrc 106496 1041120 1044480 5.25531 3a0df708ca14c1e3b197ccfcba99e3fc

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://e8296.g.akamaiedge.net/do/SDMC?action=config&type=FANTASTIGAMES_EULA&contentId=595450
hxxp://e8296.g.akamaiedge.net/do/SDM?action=config&contentId=595450&type=FANTASTIGAMES_EULA
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=SDM_DownloadStart&sdmVersion=01.51.00.52&fileName=hxxp://dts1.freeridegames.com/FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://a1507.b.akamai.net/free/frg/products/595450/boxshot_sm.jpg
hxxp://e8296.g.akamaiedge.net/check.jsp
hxxp://e8296.g.akamaiedge.net/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
hxxp://a1697.b.akamai.net/FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe
hxxp://a1697.b.akamai.net/freeride_marketing/SDM/SDM_standard/header.html
hxxp://e54.g.akamaiedge.net/meter/www.freeridegames.com/13.gif
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/css/SDM_HEADER2.css
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/css/SDM_PROGRESS.css
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/js/defines.js
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/img/header.jpg
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/img/servicePromotion1.jpg
hxxp://www-google-analytics.l.google.com/ga.js
hxxp://a1294.w20.akamai.net/beacon.js
hxxp://www-google-analytics.l.google.com/r/__utm.gif?utmwv=5.6.7&utms=1&utmn=773848826&utmhn=www.freeridegames.com&utmcs=utf-8&utmsr=1276x846&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=23.0 r0&utmdt=Progress&utmhid=1452637306&utmr=-&utmp=/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The%20Secret%20of%20Margrave%20Manor&GameId=595450&utmht=1504074108955&utmac=UA-4994835-2&utmcc=__utma=1.1589456042.1504074109.1504074109.1504074109.1;+__utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1910116889&utmredir=1&utmu=qlAAAAAAAAAAAAAAAAAAAAAE~
hxxp://a1294.w20.akamai.net/b?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9=
hxxp://a1294.w20.akamai.net/b2?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9=
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/img/servicePromotion2.jpg
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/img/servicePromotion3.gif
hxxp://a1507.b.akamai.net/freeride_marketing/SDM/SDM_standard/img/servicePromotion4.jpg
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=SDM_DownloadFinished&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=SDM_InstallStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?track=playerinstallationstart&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=clientInstallationFinished&ver=117724163&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/opTools/clientTracking.jsp?trackEvent=playerinstallationfinished&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://e8296.g.akamaiedge.net/do/skin?action=cookie
hxxp://e8218.dscb1.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18+P0=
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicrosoftRootAuthority.crl
hxxp://e8218.dscb1.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFE/uXQ4cLc0QEGNMJMGmf8=
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicWinHarComPCA_2010-11-01.crl
hxxp://b.scorecardresearch.com/b2?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9= 62.140.236.146
hxxp://img.exent.com/free/frg/products/595450/boxshot_sm.jpg 2.21.89.33
hxxp://dts1.freeridegames.com/FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe 2.21.89.19
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/css/SDM_HEADER2.css 2.21.89.24
hxxp://crl.microsoft.com/pki/crl/products/MicWinHarComPCA_2010-11-01.crl 62.140.236.147
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/js/defines.js 2.21.89.24
hxxp://b.scorecardresearch.com/beacon.js 62.140.236.146
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/img/servicePromotion1.jpg 2.21.89.24
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=clientInstallationFinished&ver=117724163&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://www.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?track=playerinstallationstart&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://www.freeridegames.com/do/SDM?action=config&contentId=595450&type=FANTASTIGAMES_EULA
hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18+P0= 23.46.123.27
hxxp://crl.microsoft.com/pki/crl/products/MicrosoftRootAuthority.crl 62.140.236.147
hxxp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html 2.21.89.19
hxxp://images.scanalert.com/meter/www.freeridegames.com/13.gif
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/img/servicePromotion2.jpg 2.21.89.24
hxxp://www.google-analytics.com/r/__utm.gif?utmwv=5.6.7&utms=1&utmn=773848826&utmhn=www.freeridegames.com&utmcs=utf-8&utmsr=1276x846&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=23.0 r0&utmdt=Progress&utmhid=1452637306&utmr=-&utmp=/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The%20Secret%20of%20Margrave%20Manor&GameId=595450&utmht=1504074108955&utmac=UA-4994835-2&utmcc=__utma=1.1589456042.1504074109.1504074109.1504074109.1;+__utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1910116889&utmredir=1&utmu=qlAAAAAAAAAAAAAAAAAAAAAE~ 172.217.16.110
hxxp://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFE/uXQ4cLc0QEGNMJMGmf8= 23.46.123.27
hxxp://b.scorecardresearch.com/b?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9= 62.140.236.146
hxxp://www.google-analytics.com/ga.js 172.217.16.110
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_DownloadFinished&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/img/servicePromotion4.jpg 2.21.89.24
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/img/header.jpg 2.21.89.24
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_InstallStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=playerinstallationfinished&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://www.freeridegames.com/do/SDMC?action=config&type=FANTASTIGAMES_EULA&contentId=595450
hxxp://www.freeridegames.com/do/skin?action=cookie
hxxp://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_DownloadStart&sdmVersion=01.51.00.52&fileName=hxxp://dts1.freeridegames.com/FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/css/SDM_PROGRESS.css 2.21.89.24
hxxp://cdn.exent.com/freeride_marketing/SDM/SDM_standard/img/servicePromotion3.gif 2.21.89.24
hxxp://www.freeridegames.com/check.jsp


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET MALWARE Possible Windows executable sent when remote host claims to send html content
ET POLICY PE EXE or DLL Windows file download HTTP
ET POLICY FreeRide Games Some AVs report as TrojWare.Win32.Trojan.Agent.Gen

Traffic

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18+P0= HTTP/1.1
Cache-Control: max-age = 363986
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sun, 17 Nov 2013 16:06:48 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1454
content-transfer-encoding: binary
Cache-Control: max-age=498106, public, no-transform, must-revalidate
Last-Modified: Tue, 29 Aug 2017 00:40:32 GMT
Expires: Tue, 5 Sep 2017 00:40:32 GMT
Date: Wed, 30 Aug 2017 06:22:12 GMT
Connection: keep-alive
0..........0..... .....0......0...0........FC..&..<.0...Y......2017
0829004032Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._).
.a..%...0a.. ...M|......20170829004032Z....20170905004032Z0...*.H.....
........X...a.^.Or..W..S.a..;J..AB.>]...N.,4p9.....jQo....J..#.I...
x.p....Vp.F.....9.P.L....~.a.....$d..9 G.@k. e..=C..#>q.j.. ....'f.
...l....Y......3..q....*....*......y.8G8.K.......cT....Sy..!../.S.`...
......B...&..1.\<.....Pg..s.<Z.0q.M...t.i.D7ZQ....*-...../......
0...0...0..4.......My_e.\....'....j0...*.H........0_1.0...U....US1.0..
.U....VeriSign, Inc.1705..U....Class 3 Public Primary Certification Au
thority0...161122000000Z..171214235959Z0..1.0...U....US1.0...U....Syma
ntec Corporation1.0...U....Symantec Trust Network1?0=..U...6Symantec C
lass 3 PCA - G1 OCSP Responder Certificate 50.."0...*.H.............0.
............4..IP.....B..h.....]..).]w.!"..a..{...="....._...~.s1.E...
....;...6&/...\2..A....\..T aH:.8lH^.....l.v.$...K=sZf.*.|.%.Pb.......
B..*f.T\w.:.s.... ....9..4..cV...3.qc.c..j<.f.....>1X.I...P%?...
......5R-....Ca14..X.U....u.....:.z.\.k..b.E.v..,.J................0..
0...U....0.0l..U. .e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symaut
h.com/cps0(.. .......0...hXXp://VVV.symauth.com/rpa0...U.%..0... .....
..0...U........0... .....0......0"..U....0...0.1.0...U....TGV-OFF-470.
..*.H.............G..\..R.P..e]...N.....m.....4f......b4"8v..b.R....`.
Auz..........2=...@..........5..cWh....J......r...g.h......Kw'...j.@..
.x...
....

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X++hEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18+P0= HTTP/1.1

Cache-Control: max-age = 363986
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sun, 17 Nov 2013 16:06:48 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1454
content-transfer-encoding: binary
Cache-Control: max-age=498106, public, no-transform, must-revalidate
Last-Modified: Tue, 29 Aug 2017 00:40:32 GMT
Expires: Tue, 5 Sep 2017 00:40:32 GMT
Date: Wed, 30 Aug 2017 06:22:12 GMT
Connection: keep-alive
0..........0..... .....0......0...0........FC..&..<.0...Y......2017
0829004032Z0s0q0I0... ........H.dI.....3..^B...d6Q....ZL%."..1.m..._).
.a..%...0a.. ...M|......20170829004032Z....20170905004032Z0...*.H.....
........X...a.^.Or..W..S.a..;J..AB.>]...N.,4p9.....jQo....J..#.I...
x.p....Vp.F.....9.P.L....~.a.....$d..9 G.@k. e..=C..#>q.j.. ....'f.
...l....Y......3..q....*....*......y.8G8.K.......cT....Sy..!../.S.`...
......B...&..1.\<.....Pg..s.<Z.0q.M...t.i.D7ZQ....*-...../......
0...0...0..4.......My_e.\....'....j0...*.H........0_1.0...U....US1.0..
.U....VeriSign, Inc.1705..U....Class 3 Public Primary Certification Au
thority0...161122000000Z..171214235959Z0..1.0...U....US1.0...U....Syma
ntec Corporation1.0...U....Symantec Trust Network1?0=..U...6Symantec C
lass 3 PCA - G1 OCSP Responder Certificate 50.."0...*.H.............0.
............4..IP.....B..h.....]..).]w.!"..a..{...="....._...~.s1.E...
....;...6&/...\2..A....\..T aH:.8lH^.....l.v.$...K=sZf.*.|.%.Pb.......
B..*f.T\w.:.s.... ....9..4..cV...3.qc.c..j<.f.....>1X.I...P%?...
......5R-....Ca14..X.U....u.....:.z.\.k..b.E.v..,.J................0..
0...U....0.0l..U. .e0c0a..`.H...E....0R0&.. .........hXXp://VVV.symaut
h.com/cps0(.. .......0...hXXp://VVV.symauth.com/rpa0...U.%..0... .....
..0...U........0... .....0......0"..U....0...0.1.0...U....TGV-OFF-470.
..*.H.............G..\..R.P..e]...N.....m.....4f......b4"8v..b.R....`.
Auz..........2=...@..........5..cWh....J......r...g.h......Kw'...j.@..
.x.....

<<< skipped >>>

GET /free/frg/products/595450/boxshot_sm.jpg HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: img.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Thu, 27 Jun 2013 06:36:07 GMT
Content-Type: image/jpeg
Content-Length: 3913
Accept-Ranges: bytes
X-Varnish: 591345155 591257867
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:46 GMT
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
......Exif..II*.................Ducky.......d.....mhXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:F8E4D0DB03DCE211B
B4FB0C483C69A6F" xmpMM:DocumentID="xmp.did:37B0D717DEF311E2945197C9A34
9E208" xmpMM:InstanceID="xmp.iid:37B0D716DEF311E2945197C9A349E208" xmp
:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:DerivedFrom s
tRef:instanceID="xmp.iid:78F7FD0CDCA811E2B081EE85099AA43D" stRef:docum
entID="xmp.did:78F7FD0DDCA811E2B081EE85099AA43D"/> </rdf:Descrip
tion> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
....Adobe.d...........................................................
......................................................................
................<.3................................................
...........................................$...4.!.D%5.T&..d7.AQ.#3E6.
....c..Ue...FV'............................!1Qaq$4A..T%.....Dd..5.....
..U6............?..v.A.\>.0...}...........v..yZa...>,?l..fDn..l.
.vX.l.I.J0..8......RIyrI.......B..F..p....X..1. ..f...........m2v.....
.'....._.pvYq.#..[.^.*Z.I..0..............l....(.....x...s.....^..

<<< skipped >>>

GET /do/skin?action=cookie HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
Host: VVV.freeridegames.com
Connection: Keep-Alive
Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_TURNKEY=Default-861504074104616445


HTTP/1.1 200 OK
Server: Apache
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Wed, 30 Aug 2017 06:22:05 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:22:05 GMT
Content-Length: 202
Connection: keep-alive
Set-Cookie: JSESSIONID=A691FACD147FA155B5901E37182C2D1A; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:22:05 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:22:05 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:22:05 GMT; Path=/
...............Q(K-*....U2.3PRH.K.O..K.U*-I..P...q....L-.1.l..sS..M...
<..C......].l...6a.9.@J1...1.1.%5-.4.D.7..U.\. 6..F..F.f"...!8.3$R.
.o...._<.a..>........3=$4...5....f...&..&..&f.f&&.XM.../....=...
.HTTP/1.1 200 OK..Server: Apache..P3P: CP="IDC CURa ADMa DEVa TAIa OUR
BUS IND UNI COM NAV"..Content-Type: text/html..Vary: Accept-Encoding.
.Content-Encoding: gzip..Expires: Wed, 30 Aug 2017 06:22:05 GMT..Cache
-Control: max-age=0, no-cache, no-store..Pragma: no-cache..Date: Wed,
30 Aug 2017 06:22:05 GMT..Content-Length: 202..Connection: keep-alive.
.Set-Cookie: JSESSIONID=A691FACD147FA155B5901E37182C2D1A; Path=/; Http
Only..Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 G
MT; Path=/..Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:0
0:10 GMT; Path=/..Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default;
Expires=Tue, 28-Nov-2017 06:22:05 GMT; Path=/..Set-Cookie: 143_FIRST_B
ROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28
-Nov-2017 06:22:05 GMT; Path=/..Set-Cookie: 143_CT=1; Expires=Wed, 06-
Sep-2017 06:22:05 GMT; Path=/.................Q(K-*....U2.3PRH.K.O..K.
U*-I..P...q....L-.1.l..sS..M...<..C......].l...6a.9.@J1...1.1.%5-.4
.D.7..U.\. 6..F..F.f"...!8.3$R..o...._<.a..>........3=$4...5....
f...&..&..&f.f&&.XM.../....=......

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/header.html HTTP/1.1
Accept: image/jpeg, application/x-ms-application, image/gif, application/xaml xml, image/pjpeg, application/x-ms-xbap, */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: dts1.freeridegames.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache/2.4.4 (Win64)
Last-Modified: Thu, 21 Feb 2013 10:04:09 GMT
Accept-Ranges: bytes
Content-Type: text/html
Content-Encoding: gzip
Content-Length: 1002
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
Vary: Accept-Encoding
...........Umo.6......W.Km,.....m5pl7)....n.."....F....#...=./s......I
Q....{....../......j.7..g...Z....s>YN./^...,.(LjSU....5{........Q.n
......og.....4f!3.....-.[..2...Kc..5&![[[.9.q....6.*..F.i....wh.b... .
.5V......7....t...O...qE*.......!..}.#.....1.....PxC. c.....&..Z...GZj
.W.r..j._..1tfE.vO.....)......u.V..q|...n..o.3Pf.@Yi.m.^...m..........
.......c.."....P.a...t..........WR$HH}.CV..P."2*.,.t.Z.~.....V...[...g
....,........h6....d..........l.....0.4..\8..M.$..3.)).P..`..v...^.kth
C.........)9-C.y....4RP#...4G....;.`.&.Df.S#......|.D.....p.XB.*0..$Z.
.,.'.5.5&....8. I.d ...LYo.F...)...)......=...S.U!U.......G.x9VeM...V.
4"01D5...Z..iJN.....CP...). d..9.&... ....A...N.'?.....|..y.i...H.....
.....T....t.Ic7(..:.'.85e&.~....H.....^h.%..;..._...O.gs......_@v.....
.......n...[..7......M.....b.{.d....n.....S.m...)`vlF...1..R..Ic.Y.l..
.....I.....6..U....S..p...........&.gph,.1...V.X........5...r.... ....
...,(I...V1.iaHt.....q.m...l.....0,.QM|{....x"~y&;t..n.......A.D~.;...
.....~.....7....w..)0l...HTTP/1.1 200 OK..Server: Apache/2.4.4 (Win64)
..Last-Modified: Thu, 21 Feb 2013 10:04:09 GMT..Accept-Ranges: bytes..
Content-Type: text/html..Content-Encoding: gzip..Content-Length: 1002.
.Date: Wed, 30 Aug 2017 06:21:46 GMT..Connection: keep-alive..Vary: Ac
cept-Encoding.............Umo.6......W.Km,.....m5pl7)....n.."....F....
#...=./s......IQ....{....../......j.7..g...Z....s>YN./^...,.(LjSU..
..5{........Q.n......og.....4f!3.....-.[..2...Kc..5&![[[.9.q....6.*..F
.i....wh.b... ..5V......7....t...O...qE*.......!..}.#.....1.....Px

<<< skipped >>>

GET /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1

Range: bytes=0-2276157
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 206 Partial Content
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Range: bytes 0-2276157/11380792
Content-Length: 2276158
Connection: keep-alive
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......d... ... ...
.......5...O...(.......4...O...i......./... .......&...*.......!...Ri
ch ...........PE..L...>.J=.................0...0...............@...
.@.................................x..................................
.....hI..........(....................................................
........................@...............................text...6$.....
..0.................. ..`.rdata.......@... ...@..............@..@.data
...dn...`...@...`..............@....rsrc...(..........................
.@..@.................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..................................................................

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/css/SDM_PROGRESS.css HTTP/1.1
Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:23 GMT
Content-Type: text/css
Accept-Ranges: bytes
X-Varnish: 1334131026 1334122753
Content-Encoding: gzip
Content-Length: 346
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:46 GMT
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
Vary: Accept-Encoding
.............n.0.E. ..HYS..I:..j.].?`.......W../...Q[../...... ~..w.u.
^wJ..s,Y/L6h...I....u2.q<..s9m..F.Q..z,........AM...FqG...JVC.(.HUm
^oFe.&..$ ;Q.:2.$..S.7..R.bpo.&..P.4.'Y.....U*i.....W.d....j...F.?...
B..a..i....1 .q.Ad...o.V....!&X^^7.}.-.....v...=5...r....&."|.#3]....N
t....$.Q......e.....vC.m;.]v..U4......8Y._............c....../C......H
TTP/1.1 200 OK..Last-Modified: Tue, 12 Apr 2011 11:54:23 GMT..Content-
Type: text/css..Accept-Ranges: bytes..X-Varnish: 1334131026 1334122753
..Content-Encoding: gzip..Content-Length: 346..Cache-Control: private,
max-age=259200..Expires: Sat, 02 Sep 2017 06:21:46 GMT..Date: Wed, 30
Aug 2017 06:21:46 GMT..Connection: keep-alive..Vary: Accept-Encoding.
..............n.0.E. ..HYS..I:..j.].?`.......W../...Q[../...... ~..w.u
.^wJ..s,Y/L6h...I....u2.q<..s9m..F.Q..z,........AM...FqG...JVC.(.HU
m ^oFe.&..$ ;Q.:2.$..S.7..R.bpo.&..P.4.'Y.....U*i.....W.d....j...F.?..
.B..a..i....1 .q.Ad...o.V....!&X^^7.}.-.....v...=5...r....&."|.#3]....
Nt....$.Q......e.....vC.m;.]v..U4......8Y._............c....../C......
....



GET /freeride_marketing/SDM/SDM_standard/img/header.jpg HTTP/1.1

Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:24 GMT
Content-Type: image/jpeg
Content-Length: 24975
Accept-Ranges: bytes
X-Varnish: 1334131025 1334113847
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:47 GMT
Date: Wed, 30 Aug 2017 06:21:47 GMT
Connection: keep-alive
......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:E075493B8A6
3DD11AC50F33A9CF1BD4A" xmpMM:DocumentID="xmp.did:635F5D80FD3F11DF973A8
2E7643F8FE6" xmpMM:InstanceID="xmp.iid:635F5D7FFD3F11DF973A82E7643F8FE
6" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:94A0E3898D9311DF986DD6F6636C425C" stRef
:documentID="xmp.did:94A0E38A8D9311DF986DD6F6636C425C"/> </rdf:D
escription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r
"?>....Adobe.d.....................................................
......................................................................
......................d.|.............................................
.................................................!A.1..."...Qaq2.T....
.B..#.U...Rbr.3Ss$DEV...4d..%.F.Cc..t.fvW....5u&6'7...................
....!1Q..Aa...q."....2R....B.D..b...#3.r..C.S...c.$4E5............?..T
...R.q..j3N).0.....mk.Vv0B .....`...v.-_(T.U{0......L.3.P.5?...j..

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/img/servicePromotion3.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:24 GMT
Content-Type: image/gif
Content-Length: 111619
Accept-Ranges: bytes
X-Varnish: 1334974526
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:48 GMT
Date: Wed, 30 Aug 2017 06:21:48 GMT
Connection: keep-alive
GIF89a|.........i............u..f...^.v..i....Q..3..Ku..W....o........
Tgo/g......S.n.e.-...h.....F......R{......&......j.W.....0...R........
.W........c(......H........F....F....................9UgQ..3.....3u...
.%......-^.......s....V..5........H..x...]......3.....4.mNk........"..
x.."...x...,...p...B.......*V./JY.d.....J.....6....$...Y.n.....L...vT.
........G...........0......3..I.....w... ..........Y....r)W...T..3...Y
.I.........{..............!'t...T.>dy...t...............2.j"$`r....
}.....)R........X.G...U..G.7..\...k..I..........E.........Z..........:
}.K..}............4=...R..wR=..........ok.......zv....................
......................................................................
.............................................z.............. .c1J.....
..............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="...
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:m
eta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00
"> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-s
yntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpRights="http:
//ns.adobe.com/xap/1.0/rights/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1
.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" x
mlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpRights:Marked="False" xmpMM
:OriginalDocumentID="uuid:E075493B8A63DD11AC50F33A9CF1BD4A" xmpMM:Docu
mentID="xmp.did:31CC4B0E8DA811DF81C4E30C6ABAF533" xmpMM:InstanceID="xm
p.iid:31CC4B0D8DA811DF81C4E30C6ABAF533" xmp:CreatorTool="Adobe Pho

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFE/uXQ4cLc0QEGNMJMGmf8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: s2.symcb.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1763
content-transfer-encoding: binary
Cache-Control: max-age=501241, public, no-transform, must-revalidate
Last-Modified: Tue, 29 Aug 2017 01:35:56 GMT
Expires: Tue, 5 Sep 2017 01:35:56 GMT
Date: Wed, 30 Aug 2017 06:22:17 GMT
Connection: keep-alive
0..........0..... .....0......0...0.......WI.....L.c=...r..7Z..2017082
9013556Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...3
13..Q?.t8p.4@A.0........20170829013556Z....20170905013556Z0...*.H.....
...........`..O.z`........H....|...?.a..5...}..u^..X"......J....*.zM..
..^..2d...0s..b_....c.*....g....G...T..<...m.w._..I......1.jJB.c...
ya2..DF.za0...A.F..iC.......eL=.!.....)...A.T.....`y........i...A..R@.
CvZ/.....G..,..!.m.q........\ !..m.z(}....eI@.%...n.O........0...0...0
..........^..)......<...T.0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 Ve
riSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 P
ublic Primary Certification Authority - G50...161122000000Z..171214235
959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Symantec
Trust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responder Cert
ificate 50.."0...*.H.............0.............................m..|...
.....1rUZN.b.......t. d......O...NY.lR..k .Q.z.g.4(,...Rp.7...0C.j.)Z.
....... ~..3...x.b.-..... S^0<6...!.(..2}...T.fX}...6...(...1...#..
H..|`.yy.<B.z.q$......u.-..K.!......y..8..--....?.,.[.[...5.e.4....
.D..t.;....).J....\fV..G.........0...0...U.......0.0l..U. .e0c0a..`.H.
..E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...http:
//VVV.symauth.com/rpa0...U.%..0... .......0...U...........0... .....0.
.....0"..U....0...0.1.0...U....TGV-OFF-500...U.......WI.....L.c=...r..
7Z0...U.#..0.....e......0..C9...3130...*.H.............<wN..g..

<<< skipped >>>

GET /meter/VVV.freeridegames.com/13.gif HTTP/1.1
Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: images.scanalert.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: public
Content-Encoding: gzip
Content-Type: image/gif; charset=UTF-8
Expires: Wed, 30 Aug 2017 06:32:03 GMT
Server: Apache
X-Content-Type-Options: nosniff
X-Xss-Protection: 1; mode=block
Content-Length: 57
Vary: Accept-Encoding
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
..........s.t..Ldd`dh``8s......O.F ..."@2.LL.......G. ...HTTP/1.1 200 
OK..Cache-Control: public..Content-Encoding: gzip..Content-Type: image
/gif; charset=UTF-8..Expires: Wed, 30 Aug 2017 06:32:03 GMT..Server: A
pache..X-Content-Type-Options: nosniff..X-Xss-Protection: 1; mode=bloc
k..Content-Length: 57..Vary: Accept-Encoding..Date: Wed, 30 Aug 2017 0
6:21:46 GMT..Connection: keep-alive............s.t..Ldd`dh``8s......O.
F ..."@2.LL.......G. .....


GET /beacon.js HTTP/1.1
Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: application/x-javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Wed, 13 Sep 2017 06:21:47 GMT
Date: Wed, 30 Aug 2017 06:21:47 GMT
Content-Length: 901
Connection: keep-alive
Cache-Control: private, no-transform, max-age=1209600
..........mT.k.6..W.e.....t.........F..}.&(..k.%#.. u..];N[x.`,...9.9*
;..m.. .].0...t3C...9.N.....].L@M....W ....@.B}.,.;...}p...%A..!T.%]/.
.`.9....`.....<b..z.E....!Q&.....po........e.R]Fzk...x%J..#-. ....!
...6Tle..o.......1;7a.....S.w..d4f.,jc.mB.T.......,..z..!..1..~.1.J:..
...csI.J.....~...8:.1.`....{uI ..<?./.j...b..Z.......u.}{.k,.m.;U*.
.....]9...R%..L.&5PXb...Hj....J...ES.>s............@..F...D-.......
......G....*[.....~.q..5......k..>.....X.....".....;.\..0.....^..R.
P1...^t..q$k.|.....c7...d.Z..V.:.^j....Gb...`...W........#.....Y?.....
.yX.....6C..Yb..].....l=.f........A..9L...ab.f.....[.eT.....q... .k..4
...t5P.....0*..e.....T..I%.........eR..}.1..eB&...;.......[G.3.......s
.......bL.~0....cXX..m..l...uv)'.q..D...B.....{.].WO...zp....C.U..a...
....{.J2j ..p. .....f....5....w...?V...':?1..../..J..?.........%.N.0av
.sH..K...|{&.i...=.>..qmr........b.;..;(......5...R@ocv...[..)...1.
.p....
....



GET /b?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9= HTTP/1.1

Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive


HTTP/1.1 302 Moved Temporarily
Content-Length: 0
Location: hXXp://b.scorecardresearch.com/b2?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9=
Date: Wed, 30 Aug 2017 06:21:47 GMT
Connection: keep-alive
Set-Cookie: UID=16262a1402361421dcf4aba1504074107; expires=Tue, 20-Aug-2019 06:21:47 GMT; path=/; domain=.scorecardresearch.com
Set-Cookie: UIDR=1504074107; expires=Tue, 20-Aug-2019 06:21:47 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
....



GET /b2?c1=2&c2=6035233&ns__t=1504074108965&ns_c=windows-1252&ns_if=1&cv=3.1&c8=&c7=http://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html&c9= HTTP/1.1

Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: b.scorecardresearch.com
Connection: Keep-Alive
Cookie: UID=16262a1402361421dcf4aba1504074107; UIDR=1504074107


HTTP/1.1 204 No Content
Content-Length: 0
Date: Wed, 30 Aug 2017 06:21:47 GMT
Connection: keep-alive
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
HTTP/1.1 204 No Content..Content-Length: 0..Date: Wed, 30 Aug 2017 06:
21:47 GMT..Connection: keep-alive..Pragma: no-cache..Expires: Mon, 01
Jan 1990 00:00:00 GMT..Cache-Control: private, no-cache, no-cache=Set-
Cookie, no-store, proxy-revalidate..


GET /pki/crl/products/MicrosoftRootAuthority.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Length: 603
Content-Type: application/pkix-crl
Content-MD5: yvu/ hdFy/Awa9KmYIdukA==
Last-Modified: Sat, 05 Aug 2017 02:03:27 GMT
ETag: 0x8D4DBA629BADAFC
Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
x-ms-request-id: f699f070-0001-00ea-7696-0db871000000
x-ms-version: 2009-09-19
x-ms-lease-status: unlocked
x-ms-blob-type: BlockBlob
Date: Wed, 30 Aug 2017 06:22:14 GMT
Connection: keep-alive
0..W0..?...0...*.H........0p1 0)..U..."Copyright (c) 1997 Microsoft Co
rp.1.0...U....Microsoft Corporation1!0...U....Microsoft Root Authority
..170804173849Z..171103055849Z0:0...:..../...V..091210010336Z0........
$... ..020225080156Z._0]0...U.#..0...J\u".F....9.N...`...0... .....7..
.....0...U......30... .....7......171102174849Z0...*.H..............x.
....j,LG..S. ........P.l..OA-.".Qn.....{.I.3.....n }I..~~........{....
...m.0.1/....?........k3N$WS..VN...q1F...%y...HO}.....#5..j.W. ......^
x.1....)m. ..P.y.C..~Q?.2.-....)E...`..;$.....*..u!..&R.]t....Oa.4X2..
......"0......Y/......fs..M.%.4^t.q.E....p_HTTP/1.1 200 OK..Content-Le
ngth: 603..Content-Type: application/pkix-crl..Content-MD5: yvu/ hdFy/
Awa9KmYIdukA==..Last-Modified: Sat, 05 Aug 2017 02:03:27 GMT..ETag: 0x
8D4DBA629BADAFC..Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0.
.x-ms-request-id: f699f070-0001-00ea-7696-0db871000000..x-ms-version:
2009-09-19..x-ms-lease-status: unlocked..x-ms-blob-type: BlockBlob..Da
te: Wed, 30 Aug 2017 06:22:14 GMT..Connection: keep-alive..0..W0..?...
0...*.H........0p1 0)..U..."Copyright (c) 1997 Microsoft Corp.1.0...U.
...Microsoft Corporation1!0...U....Microsoft Root Authority..170804173
849Z..171103055849Z0:0...:..../...V..091210010336Z0........$... ..0202
25080156Z._0]0...U.#..0...J\u".F....9.N...`...0... .....7.......0...U.
.....30... .....7......171102174849Z0...*.H..............x.....j,LG..S
. ........P.l..OA-.".Qn.....{.I.3.....n }I..~~........{.......m.0.1/..
..?........k3N$WS..VN...q1F...%y...HO}.....#5..j.W. ......^x.1....

<<< skipped >>>

GET /pki/crl/products/MicWinHarComPCA_2010-11-01.crl HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Length: 588
Content-Type: application/pkix-crl
Content-MD5:  AUo0X5nnJfYwuJ2 MqX9A==
Last-Modified: Wed, 23 Aug 2017 20:45:11 GMT
ETag: 0x8D4EA67D94A8641
Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0
x-ms-request-id: 68a8a222-0001-0047-465e-1c981b000000
x-ms-version: 2009-09-19
x-ms-lease-status: unlocked
x-ms-blob-type: BlockBlob
Date: Wed, 30 Aug 2017 06:22:19 GMT
Connection: keep-alive
0..H0..0...0...*.H........0..1.0...U....US1.0...U....Washington1.0...U
....Redmond1.0...U....Microsoft Corporation1 0)..U..."Copyright (c) 20
02 Microsoft Corp.1503..U...,Microsoft Windows Hardware Compatibility
PCA..140523172754Z..440522173902Z.C0A0...U.#..0...[...M..L.UL..>..A
.B}0... .....7.........0...U......L0...*.H.............!0..0......R \0
....C....Y.D....a..|9...6..4.....Wg...Z....{\...... S[...i.....6.....(
....hTccx..3...;!....L....FT*._n..Ai...Z..z.;.......2B...<..m...0S.
...t.!aju.b}...%..m.J..:=...R..R9.......B./.._.E......... .......(L...
..dgC. ...t.........8..9......g..qHTTP/1.1 200 OK..Content-Length: 588
..Content-Type: application/pkix-crl..Content-MD5: AUo0X5nnJfYwuJ2 Mq
X9A==..Last-Modified: Wed, 23 Aug 2017 20:45:11 GMT..ETag: 0x8D4EA67D9
4A8641..Server: Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0..x-ms-req
uest-id: 68a8a222-0001-0047-465e-1c981b000000..x-ms-version: 2009-09-1
9..x-ms-lease-status: unlocked..x-ms-blob-type: BlockBlob..Date: Wed,
30 Aug 2017 06:22:19 GMT..Connection: keep-alive..0..H0..0...0...*.H..
......0..1.0...U....US1.0...U....Washington1.0...U....Redmond1.0...U..
..Microsoft Corporation1 0)..U..."Copyright (c) 2002 Microsoft Corp.15
03..U...,Microsoft Windows Hardware Compatibility PCA..140523172754Z..
440522173902Z.C0A0...U.#..0...[...M..L.UL..>..A.B}0... .....7......
...0...U......L0...*.H.............!0..0......R \0....C....Y.D....a..|
9...6..4.....Wg...Z....{\...... S[...i.....6.....(....hTccx..3...;!...
.L....FT*._n..Ai...Z..z.;.......2B...<..m...0S....t.!aju.b}...%

<<< skipped >>>

HEAD /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Length: 11380792
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
....



GET /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1

Range: bytes=2276158-4552315
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 206 Partial Content
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Range: bytes 2276158-4552315/11380792
Content-Length: 2276158
Connection: keep-alive
HTTP/1.1 206 Partial Content..Server: Apache/2.4.4 (Win64)..Last-Modif
ied: Mon, 08 Feb 2016 13:12:40 GMT..Accept-Ranges: bytes..Content-Type
: application/x-msdownload..Expires: Wed, 30 Aug 2017 06:21:46 GMT..Ca
che-Control: max-age=0, no-cache, no-store..Pragma: no-cache..Date: We
d, 30 Aug 2017 06:21:46 GMT..Content-Range: bytes 2276158-4552315/1138
0792..Content-Length: 2276158..Connection: keep-alive....A..g..k..E3.{
I..2.......Y..t./O)....}...:I.....SO..>..2...I..d~........2...zG.q2
...z.........;..XH..T....y(.a.G....Y.W.....(2...d.}....@.....,.t'0..{&
lt;.....b"q.^J)...nD@...N.93.....RJ^.........*......J[..*M.*..T..L..T.
.J..j......2...*.....t.7I.\........I....L.&...@......|..sF."..0.....qy
=<..S.^.5$-@F....q..............a....?.o.|.`d.....{vH*.n...U.M..XM.
.....u...M.`..O..a...f5.... ..........\A.K.qa._.h.J6....#.k. USZ|...K.
P.&>.~..C....j.j..H.... .BO..w.p..c...........?......A......g..RIv.
.OE.t ..`.8...9.-.{. :Y*MW0......0W]..T.....h.)...h.z..L.u."E......'..
....v..EGI..9e..".:.s>......E.iZ..-.#E.e.......T..W.*.....:....#...
..ih...."lR&[.if.-..$d.._.d.....e..0.....{jP.<.T.}t.V..ii8HjMP..H.t
..2..N..<.).~...$..(..Bb.g.T.~9.mlv..kB..>s../....'.....l3.x.m&l
t;........%....m..~....6.].^l.o...,.q...V..h.......p.2{...\...hG. x.J.
1.ls..^lsE.g.S..&.Bv.4ls.!.mf.0Dk...D.MV..6\....!.......A...4L.~......
...._.e....v."w..... ac.O...F.P.K.=......../.>}......yT<..l.....
..2.1ty6..u..{.J.0,.TbH.......T.C53.....31.......B|F?....p.}<.-.W..
...9.....V[.g.........p..vn.:5..n"..g'.iVK..0{].....2.....|[s....3

<<< skipped >>>

GET /ga.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Strict-Transport-Security: max-age=10886400; includeSubDomains; preload
Timing-Allow-Origin: *
Date: Wed, 30 Aug 2017 04:29:57 GMT
Expires: Wed, 30 Aug 2017 06:29:57 GMT
Last-Modified: Thu, 17 Aug 2017 01:11:09 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 16022
Cache-Control: public, max-age=7200
Age: 6710
...........}kW....w~........pk..f......ZZ(O.,.!$$!q.....gft...>{...
.%.G..>..fF~2........;>..i...&.9.....v*.|x.|$....L.....y. 5.....
!..R*i..........>..mAf.o..@.0L.....1....w.v<_-.|aa.......F.p,...
.yA.....Q.{'...kyA....^.S...'o.2......5K..2o'~.....F#....*.7...c.#.l.P
. >.L.j.4....h...L~-....JW.Z..bm.I.9....s..;...=..Ue...b....r......
...........).......dO.c....v.f...^:....=.}.N'.-4.5m|h..tb.6v..W..r$.@.
8................v......e...T.t.h.c:..(....~.e0.].....{Y.p.....K.@L..J
Z.q.s.8...T...9..1r...u.KS..(xa!..{0!..5.4.^...7..."..........J8... ..
...O....t...q...|...a......a.V.q.5.e.([2..F[.........E...W.|....5a...0
..0...Ma.ML.....d....3.....=/.z`....i....ku#.4.b.Ra.^.:.-.j.*..L......
.A.;...Q.{2i.....}l..H.....T...Y._.Q!q ..V.y...9.@.R..8..!x!...p.e4...
'$c......x....'..AF&*i.../..@...!..zx..bq.{<..9...~..]...cW.Q....@A
...........U..}. .ihA..n..KK0:....b....@.D..U.....b.I>...-=...|..E.
._.W.pS..5....4.Ma..|.B......w...b>X. ...a....gV.1...ra!ZX.).,...[.
.*[.....)s8.. .....X8.c..D6'ai.6..Q.u10..N...p...>V.............!V.
......p#.....#.j...b......C....^........#..>E.`.........y.....%..M.
D.e...Y.HB.....a.G(.b.P.=.......'...&.T._.B..C......T....8..Ra.5.o.*..
.!.o..t ....`"@...='..<.Z.n..}`...m...TY...-...&".!.p....j...H....z
........|....H.....*...4"...K.0D8..2...`.O..R......../`2.6.F.W..,...2.
....I..Y....o...8..yA].....G.....8..8[..U.*x..).]...=.\...0<.pu....
7%.e?".P..f../.C??.h..8|Y.....W.j...^.O(.O.....3W\Q....~.N.G.Z.3.OO..W
.....7i(....c...!.Az....*...*..pdo.c4.k.%..}.......". ..f...{_.z..

<<< skipped >>>

GET /r/__utm.gif?utmwv=5.6.7&utms=1&utmn=773848826&utmhn=VVV.freeridegames.com&utmcs=utf-8&utmsr=1276x846&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=23.0 r0&utmdt=Progress&utmhid=1452637306&utmr=-&utmp=/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The%20Secret%20of%20Margrave%20Manor&GameId=595450&utmht=1504074108955&utmac=UA-4994835-2&utmcc=__utma=1.1589456042.1504074109.1504074109.1504074109.1;+__utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmjid=1910116889&utmredir=1&utmu=qlAAAAAAAAAAAAAAAAAAAAAE~ HTTP/1.1

Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Date: Wed, 30 Aug 2017 06:21:47 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Server: Golfe2
Content-Length: 35
GIF89a.............,...........D..;HTTP/1.1 200 OK..Access-Control-All
ow-Origin: *..Date: Wed, 30 Aug 2017 06:21:47 GMT..Pragma: no-cache..E
xpires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-sto
re, must-revalidate..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-C
ontent-Type-Options: nosniff..Content-Type: image/gif..Server: Golfe2.
.Content-Length: 35..GIF89a.............,...........D..;..


POST /opTools/clientTracking.jsp?track=playerinstallationstart&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1
User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:55 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:55 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=2F015AF9F2BB609DB1674C37615C8F1C; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:55 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:55 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:55 GMT; Path=/
HTTP/1.1 200 OK..Server: Apache..Content-Length: 0..P3P: CP="IDC CURa 
ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Type: text/html..Expi
res: Wed, 30 Aug 2017 06:21:55 GMT..Cache-Control: max-age=0, no-cache
, no-store..Pragma: no-cache..Date: Wed, 30 Aug 2017 06:21:55 GMT..Con
nection: keep-alive..Set-Cookie: JSESSIONID=2F015AF9F2BB609DB1674C3761
5C8F1C; Path=/; HttpOnly..Set-Cookie: 143_userName=""; Expires=Thu, 01
-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_password=""; Expires=T
hu, 01-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_CAMPAIGN_SERIAL_
ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:55 GMT; Path=/..Set
-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776
000; Expires=Tue, 28-Nov-2017 06:21:55 GMT; Path=/..Set-Cookie: 143_CT
=1; Expires=Wed, 06-Sep-2017 06:21:55 GMT; Path=/..
....

<<< skipped >>>

POST /opTools/clientTracking.jsp?trackEvent=clientInstallationFinished&ver=117724163&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; JSESSIONID=2F015AF9F2BB609DB1674C37615C8F1C


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:22:02 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:22:02 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=8C12B66DA292E099B44FC8554A62D064; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:22:02 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:22:02 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:22:02 GMT; Path=/
....



POST /opTools/clientTracking.jsp?trackEvent=playerinstallationfinished&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; JSESSIONID=8C12B66DA292E099B44FC8554A62D064


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:22:03 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:22:03 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=FE2FF1466DE46A60366D4905AD8E2B33; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:22:03 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:22:03 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:22:03 GMT; Path=/
HTTP/1.1 200 OK..Server: Apache..Content-Length: 0..P3P: CP="IDC CURa 
ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Type: text/html..Expi
res: Wed, 30 Aug 2017 06:22:03 GMT..Cache-Control: max-age=0, no-cache
, no-store..Pragma: no-cache..Date: Wed, 30 Aug 2017 06:22:03 GMT..Con
nection: keep-alive..Set-Cookie: JSESSIONID=FE2FF1466DE46A60366D4905AD
8E2B33; Path=/; HttpOnly..Set-Cookie: 143_userName=""; Expires=Thu, 01
-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_password=""; Expires=T
hu, 01-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_CAMPAIGN_SERIAL_
ID=Default-Default; Expires=Tue, 28-Nov-2017 06:22:03 GMT; Path=/..Set
-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776
000; Expires=Tue, 28-Nov-2017 06:22:03 GMT; Path=/..Set-Cookie: 143_CT
=1; Expires=Wed, 06-Sep-2017 06:22:03 GMT; Path=/..

<<< skipped >>>

GET /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1
Range: bytes=6828474-9104631
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 206 Partial Content
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Range: bytes 6828474-9104631/11380792
Content-Length: 2276158
Connection: keep-alive
HTTP/1.1 206 Partial Content..Server: Apache/2.4.4 (Win64)..Last-Modif
ied: Mon, 08 Feb 2016 13:12:40 GMT..Accept-Ranges: bytes..Content-Type
: application/x-msdownload..Expires: Wed, 30 Aug 2017 06:21:46 GMT..Ca
che-Control: max-age=0, no-cache, no-store..Pragma: no-cache..Date: We
d, 30 Aug 2017 06:21:46 GMT..Content-Range: bytes 6828474-9104631/1138
0792..Content-Length: 2276158..Connection: keep-alive....4(......*..C.
..O..#..s.&t..{.f.;M..#[.d.B...Md....a\4k."[. ..z^..|a.\...n.....{...g
.[.Z.....5eu.v_....'.6=\T.#gF....[.xc2...-.=....F.o.M.....d2.!..i..SP{
*O..@.....l ..j........${..3G.28.4..z....i....h2...#d..|.^.Z..=.V..d..
.Y.}"F....qX^.t..}Obu....kf.....*ud.9. A...S.~m..j.kc.....O..of...gw.F
..s;{..X.Af.M.I............(.7!........1...d..~~.}&.)g.8x.............
.}3..6D.`.A.....0..........m.K!...../..d.k.Y{....u.a.....d...jp...|...
..|rr7........z.../.U..CzV.O.*.2.S@.U...}......^Q.q...D..d..}.."..}\_^
_....Dfv.L....F.;p.h..V..H...\....>.Uy9m.e).n..M...6A#4)..6T....U..
.....W....,....,.....q^=...n[......-..-...t~F.x>....O.ev...p.l....$
..LR.".$w.d,......U..A.....5.....>....a.!.G.o.e.6..'.-...g....C.L.2
........75.;..vI..T.......&.B.4...`. y.w.s.:...E....x.:).....f'...k...
g.....9....h....4...'X~.*.Tcn...s_f....Zw...5c...t.......$.R.#G)Y...Yj
<0....S......HG...'......~..|.Uf..<......UN,ZQso.$. Rw...y....^Y
.[...;Zv.0.q.....Zb........j....@..$.........2..[.E...6ve.......U.Y...
17.......:.....c.....?..N.7. ^.L.ZY.W.O..([:cUn..?........b.......d..T
..Q.O..J..hD...6..rTg..v..Z....W...?...D.C..M.......[.fI0...,..j..

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/js/defines.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:25 GMT
Content-Type: application/javascript
Content-Length: 1371
Accept-Ranges: bytes
X-Varnish: 590501816 590493999
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:46 GMT
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
Exent = function()..{..};..Exent.SDM = function()..{..};..Exent.SDM.Ma
rkting = function()..{..};..Exent.SDM.Markting.Defines = function()..{
..};....Exent.SDM.Markting.Defines.BASE_URL = ..{...cdn : "hXXp://cdn.
exent.com/freeride_marketing/SDM/SDM_standard/img/",...freeride : "htt
p://VVV.freeridegames.com/product/img/SDM/"..}..if (navigator.userAgen
t.indexOf("Windows NT 6.0") != -1) ..{.. Exent.SDM.Markting.Defines.S
ERVICE_PROMOTION = .. {.. .servicePromotion1 : "url('" Exent.SDM.M
arkting.Defines.BASE_URL.cdn "servicePromotion1.jpg')",.. .serviceP
romotion2 : "url('" Exent.SDM.Markting.Defines.BASE_URL.cdn "servi
cePromotion2.jpg')",.. servicePromotion3 : "url('" Exent.SDM.Mark
ting.Defines.BASE_URL.cdn "servicePromotion3vista.jpg')",.. .servic
ePromotion4 : "url('" Exent.SDM.Markting.Defines.BASE_URL.cdn "ser
vicePromotion4.jpg')".. };..}..else..{ .. .. Exent.SDM.Markting.Def
ines.SERVICE_PROMOTION = .. {.. .servicePromotion1 : "url('" Exent
.SDM.Markting.Defines.BASE_URL.cdn "servicePromotion1.jpg')",.. .se
rvicePromotion2 : "url('" Exent.SDM.Markting.Defines.BASE_URL.cdn
"servicePromotion2.jpg')",.. servicePromotion3 : "url('" Exent.SD
M.Markting.Defines.BASE_URL.cdn "servicePromotion3.gif')",.. .servi
cePromotion4 : "url('" Exent.SDM.Markting.Defines.BASE_URL.cdn "se
rvicePromotion4.jpg')".. };..}
....

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/img/servicePromotion2.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:24 GMT
Content-Type: image/jpeg
Content-Length: 93029
Accept-Ranges: bytes
X-Varnish: 591345172
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:48 GMT
Date: Wed, 30 Aug 2017 06:21:48 GMT
Connection: keep-alive
......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:E075493B8A6
3DD11AC50F33A9CF1BD4A" xmpMM:DocumentID="xmp.did:38A776B68D9511DFAE5BE
6A790AFC6F4" xmpMM:InstanceID="xmp.iid:38A776B58D9511DFAE5BE6A790AFC6F
4" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:C5457F038C8DDF11BC73DE4FB01F0763" stRef
:documentID="uuid:E075493B8A63DD11AC50F33A9CF1BD4A"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;....Adobe.d........................................................
......................................................................
.....................|................................................
...............................................!..1..AQa".q2R..U.....#
.t&V...B3S$T..uF....br.c.4.^.v....Cs...78.de6fD.....'...............
........!1.AQ.aq.."2.....R...B..D..br#3......S.4T..Ccs...$5.t.%..d....
........?..g......{.......YU...:5*.....F.#B.....hB4!....F.#BD.4.I.

<<< skipped >>>

GET /do/SDMC?action=config&type=FANTASTIGAMES_EULA&contentId=595450 HTTP/1.1
User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 302 Moved Temporarily
Server: Apache
Location: hXXp://VVV.freeridegames.com/do/SDM?action=config&contentId=595450&type=FANTASTIGAMES_EULA
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:44 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:44 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=07A36246270ADFFE840A4F28A4EDDEB3; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_TURNKEY=Default-861504074104616445; Expires=Thu, 30-Aug-2018 06:21:44 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:44 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:44 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:44 GMT; Path=/
....



GET /do/SDM?action=config&contentId=595450&type=FANTASTIGAMES_EULA HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=07A36246270ADFFE840A4F28A4EDDEB3; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1


HTTP/1.1 200 OK
Server: Apache
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:44 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:44 GMT
Content-Length: 2087
Connection: keep-alive
Set-Cookie: JSESSIONID=2D830E1FB063EF9D641B023FDD378B84; Path=/; HttpOnly
<?xml version="1.0" encoding="utf-8"?><ContentConfiguration i
d="595450"><IS><Url>hXXp://dts1.freeridegames.com/FRG_s
ite/downloads/partners/fantastigames_eula/EXEtender.exe</Url><
;Url>hXXp://dts2.freeridegames.com/FRG_site/downloads/partners/fant
astigames_eula/EXEtender.exe</Url><Url>hXXp://VVV.freeride
games.com/downloads/exetender/partners/fantastigames_eula/EXEtender.ex
e</Url><AddOns><Param><ID>""</ID><Nam
e>noaddons</Name><Priority>0</Priority><Checke
d>false</Checked><Dependencies/></Param></AddO
ns><CommandLine/></IS><SDMVersion>1.0.0.22</SD
MVersion><PromotionUrl>hXXp://VVV.freeridegames.com/product/S
DM/SDM_standard</PromotionUrl><ReportUrl>hXXp://VVV.freeri
degames.com/opTools/clientTracking.jsp</ReportUrl><Conversion
Url/><PartnerName>Default</PartnerName><ProviderId&g
t;143</ProviderId><ProviderName>FreeRideGames</Provider
Name><ClientVersion>7.2.0.0</ClientVersion><EULAUrl&
gt;hXXp://VVV.freeridegames.com/do/general?Partner=Default&jspName
=licenseAgreement</EULAUrl><ImgServerUrl>hXXp://img.exent.
com/free/frg</ImgServerUrl><HeaderUrl>hXXp://dts1.freeride
games.com/freeride_marketing/SDM/SDM_standard/header.html</HeaderUr
l><MyGamesUrl/><StartPageId>SDM_EULA</StartPageId>
;<Type>FANTASTIGAMES_EULA</Type><Game><Id>

<<< skipped >>>

POST /opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=2D830E1FB063EF9D641B023FDD378B84; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:45 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:45 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=1872F72B882DC34B582C5015A5C52B81; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:45 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:45 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:45 GMT; Path=/
HTTP/1.1 200 OK..Server: Apache..Content-Length: 0..P3P: CP="IDC CURa 
ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Type: text/html..Expi
res: Wed, 30 Aug 2017 06:21:45 GMT..Cache-Control: max-age=0, no-cache
, no-store..Pragma: no-cache..Date: Wed, 30 Aug 2017 06:21:45 GMT..Con
nection: keep-alive..Set-Cookie: JSESSIONID=1872F72B882DC34B582C5015A5
C52B81; Path=/; HttpOnly..Set-Cookie: 143_userName=""; Expires=Thu, 01
-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_password=""; Expires=T
hu, 01-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_CAMPAIGN_SERIAL_
ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:45 GMT; Path=/..Set
-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776
000; Expires=Tue, 28-Nov-2017 06:21:45 GMT; Path=/..Set-Cookie: 143_CT
=1; Expires=Wed, 06-Sep-2017 06:21:45 GMT; Path=/..
....

<<< skipped >>>

POST /opTools/clientTracking.jsp?trackEvent=SDM_DownloadStart&sdmVersion=01.51.00.52&fileName=hXXp://dts1.freeridegames.com/FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=1872F72B882DC34B582C5015A5C52B81; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=7B9272D53B07589A75A658126D36F85B; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:46 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:46 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:46 GMT; Path=/
....



HEAD /check.jsp HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=7B9272D53B07589A75A658126D36F85B; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1


HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Content-Length: 32
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html;charset=ISO-8859-1
Cache-Control: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
....



GET /product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450 HTTP/1.1

Accept: image/jpeg, application/x-ms-application, image/gif, application/xaml xml, image/pjpeg, application/x-ms-xbap, */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.freeridegames.com
Connection: Keep-Alive
Cookie: JSESSIONID=7B9272D53B07589A75A658126D36F85B; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 22 Jan 2014 14:15:05 GMT
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Content-Encoding: gzip
Cache-Control: max-age=86400
Expires: Thu, 31 Aug 2017 06:21:46 GMT
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Length: 2322
Connection: keep-alive
...........Z{o.8......X...Q[..Ij.Y...x..A.^q(...h..,.D:....~3.$..]{7i7
A.I$.3..p.dw_..?...y.._......'.Cb.=.S......LG..T.eL#.....=.sf..|.;P.P?
........y,.1.r.3....\&.!.nI...%.4dr......X.R...|)-2.Y.m..wqtzu...o.:..
....r9.M.1.)....w.4[D.~...^.z<b....]........J.........H...z......jH
.[.x.G...R.(.q.-G..7.....B....sH........."..\. ..#.......v{1.....9.?..
.|Q..1..l2....@.Z...........|....I.....BN#E.c1.,....o<...1%}:b....z
..v..%#...b..(b.'.J`...c....?.#....%.....GFy.]....P(..".....a........0
..ng..h..."`...sa..E.h.......*..{<... 1N.-0`<..A....AO9.i...tB..
.........2..9<R....<8......9YT.&...I..XC.pm.DE.00_.C0}I@..N..J.D
.>KY...%....q.k.L......$.fs.c.<........%.v.....w...<f."J.o.&d
.~.D........I..(.S0/ .~....EQ.~........~(|...E_.h.._..U..yw.1.B..H....
...u8.C..*.\..P4.=......',....V ......b.a..[.X.,...`.lU...d.3f.F..P...
..#.S=..{{....V....(.*.,@..S.."KRl....6.L....AJ A.[....B...c...A. (...
}{..C..5....B.....0.h.....$.J.....v...).....L...%;.`......G.&EW.....;
....t.!.m..`.h..Q../:...=........?s!..q.A.4..3...=1.,..1l..7.<...N.
Iw'l.HD.N.....me....f...F^......y.."o<#..DR...._Cx.]..je=:.US.. ...
Y....A...F.4v......E..........43'......-9..k.....J...L."..m.6.J...._.V
.m......,.["..b...R.}]d.....JU...?..q...N...d.........@ <.8.R.2....
.}d..............V.Z[L.XB..."........)...b.. `..k.....k.....S.........
0../...C..FO..U..e...O....6....P.byx ..*..e...... .m/#.$.y.....Y....%.
P.E.LW....\..K....;.J.d..-xUB..4nO.,.4.._&..1gR.K... (|..A. B..t.b4.4.
...H. ..|.^..{..1.{mY3..48....`'KV...f^.....Md..........l7...C...R

<<< skipped >>>

GET /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1
Range: bytes=9104632-11380791
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 206 Partial Content
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Range: bytes 9104632-11380791/11380792
Content-Length: 2276160
Connection: keep-alive
HTTP/1.1 206 Partial Content..Server: Apache/2.4.4 (Win64)..Last-Modif
ied: Mon, 08 Feb 2016 13:12:40 GMT..Accept-Ranges: bytes..Content-Type
: application/x-msdownload..Expires: Wed, 30 Aug 2017 06:21:46 GMT..Ca
che-Control: max-age=0, no-cache, no-store..Pragma: no-cache..Date: We
d, 30 Aug 2017 06:21:46 GMT..Content-Range: bytes 9104632-11380791/113
80792..Content-Length: 2276160..Connection: keep-alive.......I.eU..XZR
m......K.......cs...}.W.J......l9.e......_Xy. ....|..o.2.{R..p..a.*...
P).-a...4.....!...`.....a_\ ...K......m....}.n2:..msq..=.,a.....vV..Q.
F.&.>({d..o({...7.xoW.....ro...._.o.umS.2;.1Z.....d..r..(...j..(.
..c...NE......8...y...F..^~.../7.J....k~...A.u>..............^... .
.....u....x......"..-P..ha...'.X\.;=U..j.....K..-}..!...S..(/&..<..
.q.z..(.....O......|......v....M..v,./_x.~...?...E....y.....q.........
...*y..v.......X_... ..Ed.0.Ga...:q6.:q6t.S...'KL4...]..3.E.....[..K..
....E.!-...J....<......].\>.K$.Y..k...b.s..C80.E...7......0....d
<...` ..o..b...|bu..G.....Q....0.;JhL.....V.?.1. . ..6..)Lb;[..G...
....t5Dy..ig......8d.. ....JMf.....G3...>^..a.J..w`Fw.z.Z..f0.F..wC
...........S..:...k..C....NO.........92.....[.ptn&G.b.n-...\s...-.]...
.............j...HZu,iV..b.M .M.....s.X.....v.y....h..... C....r0D...J
%@.6o.......Pl.......\...........=W....K.6.N....x.Cn.5.....p.-A..Z...G
.,.b.s.j..6s..6s.|.........h......C3...}...g#...F..".d.).....HX.6.o$0p
b. 3%V........\..'..L..........o.........?.|........p..\.t..... ......
....._J.O..............7.w..../.....kF.w..?A.?~wO. .../.........?.

<<< skipped >>>

HEAD /check.jsp HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=7B9272D53B07589A75A658126D36F85B; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmc=1; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Content-Length: 32
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html;charset=ISO-8859-1
Cache-Control: no-cache
Date: Wed, 30 Aug 2017 06:21:51 GMT
Connection: keep-alive
HTTP/1.1 200 OK..Server: Apache..Pragma: no-cache..Content-Length: 32.
.P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Ty
pe: text/html;charset=ISO-8859-1..Cache-Control: no-cache..Date: Wed,
30 Aug 2017 06:21:51 GMT..Connection: keep-alive..
....



POST /opTools/clientTracking.jsp?trackEvent=SDM_DownloadFinished&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=7B9272D53B07589A75A658126D36F85B; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmc=1; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:52 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=AEC2E28426944CE1CEF3425433D25F7B; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:52 GMT; Path=/
....



POST /opTools/clientTracking.jsp?trackEvent=SDM_InstallStart&sdmVersion=01.51.00.52&muid=303000302A4820524153F7ED10F5FDFF00000800F5842E75C2685063D8C2EEE100067EDB HTTP/1.1

User-Agent: AHTTPConnection
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=AEC2E28426944CE1CEF3425433D25F7B; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmc=1; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Content-Length: 0
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html
Expires: Wed, 30 Aug 2017 06:21:52 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:52 GMT
Connection: keep-alive
Set-Cookie: JSESSIONID=44CD94624BDB66D89A5254D4FACAB64A; Path=/; HttpOnly
Set-Cookie: 143_userName=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_password=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: 143_CAMPAIGN_SERIAL_ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/
Set-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776000; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/
Set-Cookie: 143_CT=1; Expires=Wed, 06-Sep-2017 06:21:52 GMT; Path=/
HTTP/1.1 200 OK..Server: Apache..Content-Length: 0..P3P: CP="IDC CURa 
ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Type: text/html..Expi
res: Wed, 30 Aug 2017 06:21:52 GMT..Cache-Control: max-age=0, no-cache
, no-store..Pragma: no-cache..Date: Wed, 30 Aug 2017 06:21:52 GMT..Con
nection: keep-alive..Set-Cookie: JSESSIONID=44CD94624BDB66D89A5254D4FA
CAB64A; Path=/; HttpOnly..Set-Cookie: 143_userName=""; Expires=Thu, 01
-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_password=""; Expires=T
hu, 01-Jan-1970 00:00:10 GMT; Path=/..Set-Cookie: 143_CAMPAIGN_SERIAL_
ID=Default-Default; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/..Set
-Cookie: 143_FIRST_BROWSER="Default-MSIE 7.0"; Version=1; Max-Age=7776
000; Expires=Tue, 28-Nov-2017 06:21:52 GMT; Path=/..Set-Cookie: 143_CT
=1; Expires=Wed, 06-Sep-2017 06:21:52 GMT; Path=/..

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD+Oyl+0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFE/uXQ4cLc0QEGNMJMGmf8= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: s2.symcb.com


HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1763
content-transfer-encoding: binary
Cache-Control: max-age=501244, public, no-transform, must-revalidate
Last-Modified: Tue, 29 Aug 2017 01:35:56 GMT
Expires: Tue, 5 Sep 2017 01:35:56 GMT
Date: Wed, 30 Aug 2017 06:22:17 GMT
Connection: keep-alive
0..........0..... .....0......0...0.......WI.....L.c=...r..7Z..2017082
9013556Z0s0q0I0... ...................B.>.I.$&.....e......0..C9...3
13..Q?.t8p.4@A.0........20170829013556Z....20170905013556Z0...*.H.....
...........`..O.z`........H....|...?.a..5...}..u^..X"......J....*.zM..
..^..2d...0s..b_....c.*....g....G...T..<...m.w._..I......1.jJB.c...
ya2..DF.za0...A.F..iC.......eL=.!.....)...A.T.....`y........i...A..R@.
CvZ/.....G..,..!.m.q........\ !..m.z(}....eI@.%...n.O........0...0...0
..........^..)......<...T.0...*.H........0..1.0...U....US1.0...U...
.VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 Ve
riSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 P
ublic Primary Certification Authority - G50...161122000000Z..171214235
959Z0..1.0...U....US1.0...U....Symantec Corporation1.0...U....Symantec
Trust Network1?0=..U...6Symantec Class 3 PCA - G5 OCSP Responder Cert
ificate 50.."0...*.H.............0.............................m..|...
.....1rUZN.b.......t. d......O...NY.lR..k .Q.z.g.4(,...Rp.7...0C.j.)Z.
....... ~..3...x.b.-..... S^0<6...!.(..2}...T.fX}...6...(...1...#..
H..|`.yy.<B.z.q$......u.-..K.!......y..8..--....?.,.[.[...5.e.4....
.D..t.;....).J....\fV..G.........0...0...U.......0.0l..U. .e0c0a..`.H.
..E....0R0&.. .........hXXp://VVV.symauth.com/cps0(.. .......0...http:
//VVV.symauth.com/rpa0...U.%..0... .......0...U...........0... .....0.
.....0"..U....0...0.1.0...U....TGV-OFF-500...U.......WI.....L.c=...r..
7Z0...U.#..0.....e......0..C9...3130...*.H.............<wN..g..

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/css/SDM_HEADER2.css HTTP/1.1
Accept: */*
Referer: hXXp://dts1.freeridegames.com/freeride_marketing/SDM/SDM_standard/header.html
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:23 GMT
Content-Type: text/css
Accept-Ranges: bytes
X-Varnish: 590501812 590491741
Content-Encoding: gzip
Content-Length: 301
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:46 GMT
Date: Wed, 30 Aug 2017 06:21:46 GMT
Connection: keep-alive
Vary: Accept-Encoding
............=O.0..gG......IShQ.....,..*'.8..m]........hG..^.z......g.y
...{.\p...,-...Dm...=?.%c,.~.L.m..R.>".T.....j.....(...n.......Dg..
.L%W..<z...2... .l!...Yk..S..h.;. ..Q..=8*..)[.@.`5j.......{.UO.)..
4.]v.X|.}...n.%..-B.I' ..'.4.u..@.H.>Xy....:>.W.f..*;.bv........
1..1=..i../o^........8U...$.:....
....



GET /freeride_marketing/SDM/SDM_standard/img/servicePromotion1.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:24 GMT
Content-Type: image/jpeg
Content-Length: 51132
Accept-Ranges: bytes
X-Varnish: 591345163 591194386
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:47 GMT
Date: Wed, 30 Aug 2017 06:21:47 GMT
Connection: keep-alive
......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:E075493B8A6
3DD11AC50F33A9CF1BD4A" xmpMM:DocumentID="xmp.did:EFBA4B468D9311DF8C86B
CB125227836" xmpMM:InstanceID="xmp.iid:EFBA4B458D9311DF8C86BCB12522783
6" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:C5457F038C8DDF11BC73DE4FB01F0763" stRef
:documentID="uuid:E075493B8A63DD11AC50F33A9CF1BD4A"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;....Adobe.d........................................................
......................................................................
.....................|................................................
..............................................!.a.1"...AQR.U.q2.#.t.&F
..B....3S$4TEb.s..Vv8...r..C.d.%.....u65.7........................!1Q.
.Aaq..."2....R....D.Br#..b..34..c$5...Cs.dE.............?..Y.....O~.U.
..].*....Em5..P..P..P..P..P..P..T.B.E....T.h..P...U .@.R.J. ..H-*.

<<< skipped >>>

GET /freeride_marketing/SDM/SDM_standard/img/servicePromotion4.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.freeridegames.com/product/SDM/SDM_standard/SDM_PROGRESS.html?GameName=The Secret of Margrave Manor&GameId=595450
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: cdn.exent.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Last-Modified: Tue, 12 Apr 2011 11:54:24 GMT
Content-Type: image/jpeg
Content-Length: 60189
Accept-Ranges: bytes
X-Varnish: 591345173
Cache-Control: private, max-age=259200
Expires: Sat, 02 Sep 2017 06:21:48 GMT
Date: Wed, 30 Aug 2017 06:21:48 GMT
Connection: keep-alive
......Exif..II*.................Ducky.......P......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
0 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpRights="hXXp://ns.adobe.com/xap/1.0/rights/" xmlns
:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.
com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0
/" xmpRights:Marked="False" xmpMM:OriginalDocumentID="uuid:E075493B8A6
3DD11AC50F33A9CF1BD4A" xmpMM:DocumentID="xmp.did:330AA8978FE711DF985FC
47C3930285E" xmpMM:InstanceID="xmp.iid:330AA8968FE711DF985FC47C3930285
E" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:A53833D2E68FDF11A45D900EBDFE88B8" stRef
:documentID="uuid:E075493B8A63DD11AC50F33A9CF1BD4A"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;....Adobe.d........................................................
......................................................................
.....................|................................................
..............................................!..1a"AQR.q...2#....&...
.b..tU.B3$T....rSEF..Cc.4Dd.%uv7.s..5..f....eV'.8.....................
....!1.AQ..aq.."2....R...Bb.Dr..#34...$...CSc...5............?....|...
.=..WN..u.Uo1.[EeX.DE..DQ.DE..DQ..Ga".......4..h.....c...F...N..&g

<<< skipped >>>

GET /FRG_site/downloads/partners/fantastigames_eula/EXEtender_Default.exe HTTP/1.1
Range: bytes=4552316-6828473
User-Agent: AHTTPConnection
Host: dts1.freeridegames.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 206 Partial Content
Server: Apache/2.4.4 (Win64)
Last-Modified: Mon, 08 Feb 2016 13:12:40 GMT
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Expires: Wed, 30 Aug 2017 06:21:46 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 30 Aug 2017 06:21:46 GMT
Content-Range: bytes 4552316-6828473/11380792
Content-Length: 2276158
Connection: keep-alive
HTTP/1.1 206 Partial Content..Server: Apache/2.4.4 (Win64)..Last-Modif
ied: Mon, 08 Feb 2016 13:12:40 GMT..Accept-Ranges: bytes..Content-Type
: application/x-msdownload..Expires: Wed, 30 Aug 2017 06:21:46 GMT..Ca
che-Control: max-age=0, no-cache, no-store..Pragma: no-cache..Date: We
d, 30 Aug 2017 06:21:46 GMT..Content-Range: bytes 4552316-6828473/1138
0792..Content-Length: 2276158..Connection: keep-alive.. ..{\.....@j...
V'.....,....i....k.*..T"....uM..cU.. Y...Z.....).q......xW4N.QQ....vr.
^...e..~...(.R.e.^...L...$W$4....x.. ....k$..k7y..=..M...X.d5..%gG.8..
4.r...v..Za..u.c.l.. i.8..`.._U E.V .."DQk....@.v..._YK.....1wdz.3^.J.
K-.,6.2.g.:}....x..1&l!&...."............1?.G..p...qy..e...;..2=dG.Is.
....)..X.&..........E..Q......q..43.P....o...{D.[_\.MN.J..............
.^..*...........G.\...!..B...U........i.U..m...t..nW..M...d!7.<....
q....!..|Nl...y..;.c... .....z..].5.N..o.=...p..>8..o.p.......(a...
.V.}x./.C........wa.g..]`..B.o.....A.Z......@W.B.....=...p?._.e.p&..y?
.#...fC.g.#.W.7.0.9_../....../......p.y...ws.q ...g..._s_.y.....z.....
.-..........h ..g8.\/r.^..y.m..............5...N.....W,....7c..GN.:...
(.I/t...Z.MHZ.Y...!...a....?.2...O...........jo#...O......{z.V.i.=/.&l
t;...a....:..P~u[.......1....;....Q.~.....%2.g...e....N....B...c......
.........l..X....# d..C.z..{.}...9.E..8.....;.{....}......./9...j..9Qo
.)t..w..u......7.!,.W.?HIx.|_........r1f.P.......A#. ......#.}........
..5...'....h...VP.....s.'.5...|...z.....x....q.......S..7.9.....m,@../
...o...._.. ;........_..8.D{...D.......'.....}.K^..............;..

<<< skipped >>>

HEAD /check.jsp HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=44CD94624BDB66D89A5254D4FACAB64A; __utmc=1; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Content-Length: 32
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html;charset=ISO-8859-1
Cache-Control: no-cache
Date: Wed, 30 Aug 2017 06:21:57 GMT
Connection: keep-alive
HTTP/1.1 200 OK..Server: Apache..Pragma: no-cache..Content-Length: 32.
.P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Ty
pe: text/html;charset=ISO-8859-1..Cache-Control: no-cache..Date: Wed,
30 Aug 2017 06:21:57 GMT..Connection: keep-alive..
....



HEAD /check.jsp HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.freeridegames.com
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: JSESSIONID=44CD94624BDB66D89A5254D4FACAB64A; __utmc=1; 143_TURNKEY=Default-861504074104616445; 143_CAMPAIGN_SERIAL_ID=Default-Default; 143_FIRST_BROWSER="Default-MSIE 7.0"; 143_CT=1; __utma=1.1589456042.1504074109.1504074109.1504074109.1; __utmb=1.1.10.1504074109; __utmz=1.1504074109.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1


HTTP/1.1 200 OK
Server: Apache
Pragma: no-cache
Content-Length: 32
P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"
Content-Type: text/html;charset=ISO-8859-1
Cache-Control: no-cache
Date: Wed, 30 Aug 2017 06:22:03 GMT
Connection: keep-alive
HTTP/1.1 200 OK..Server: Apache..Pragma: no-cache..Content-Length: 32.
.P3P: CP="IDC CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV"..Content-Ty
pe: text/html;charset=ISO-8859-1..Cache-Control: no-cache..Date: Wed,
30 Aug 2017 06:22:03 GMT..Connection: keep-alive..


The Malware connects to the servers at the folowing location(s):

Free Ride Games.exe_3400:

`.rsrc
E8SSSSSh
vhSSSSSSh
SSQSSh
D$,WVPSSh
.tTPV
FTPjK
FtPj;
F.PjRWj
u.WWj
u.VVj
P$8^%uX
SSSSh
<.up3
<8%u=
.FGy/
Fd t.SPW
N.VAPQW
G.f;E.uJ3
N.AQPWjhS
N.AQS
N.AQUS
V.BRUS
f9~.vX
?%uMf
_uninsdm.bat
CCmdTarget
COMCTL32.DLL
CNotSupportedException
__MSVCRT_HEAP_SELECT
portuguese-brazilian
//DownloadAcceleratorDB/URL
<DownloadAcceleratorDB><ID>%s</ID><LastModified>%s</LastModified><URL>%s</URL><Size>%d</Size><PartialFiles>
<Path>%s</Path>
3.8.1
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYHerF
MD5 part of OpenSSL 0.9.8a 11 Oct 2005
DownloadManager.exe
?messageMap@CHtmlSkinDlg@@1UAFX_MSGMAP@@B
?messageMap@CSmallDownloadManagerApp@@1UAFX_MSGMAP@@B
?messageMap@CSmallDownloadManagerDlg@@1UAFX_MSGMAP@@B
******SDM FetchConfigurationXML failed to load XML! URL=
******SDM FetchConfigurationXML failed! URL=
AHTTPConnection
HTTP/1.0
ReportUrl
IS/Url
PromotionUrl
/ContentConfiguration/%s
rd "%s" /q /s
if exist "%s" goto Repeat
del "%s"
strUrl:
Software\AppDataLow\Software\Exent\AOD\SDM
strUrlParams:
strFullUrl:
http:\\VVV.microsoft.com
http:\\VVV.google.com
strResumeURL:
******EXTERNAL: SDM_OpenWebDialog
tUExent_SDM
%S "%S u '%S' p '%d' c '%d'"
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SetUrl Failed!
%s%c%c%c
%s%c%c
<ResumeDownloadListRequest> <ProviderDescriptor Id="%d" /> </ResumeDownloadListRequest>
<AddGameToDownloadListRequest><ContentDescriptor Id="%d" ProviderId="%d" FullDownload="0" ToPriority="-1" DirectionsUrl="%s"><DirectionsString></DirectionsString><AdditionalInfo>%s</AdditionalInfo></ContentDescriptor></AddGameToDownloadListRequest>
SOFTWARE\Exent\AOD\Client
x.x.x.x
<GetGamesIdsListRequest ProviderId="%d" ActiveGamesOnly="0" InDownloadListOnly="1" ReadyToUseOnly="0" NotInDownloadList="0" CurrentOSOnly="0" CacheUpdating="0" SortBy="DownloadPriority" />
SOFTWARE\Exent\AOD\Client\Providers\%s\Settings\SkinCode
SkinCfg.xml
Context=%d, AcceleratorErrorType=%d, HTTPERROR::AHTTPstatusCode=%d, AcceleratorErrorCode=%d, HTTPERROR::AWinInetError=%d, HTTPERROR::StrLastError=%s,
SystemBits=%d, SDMUserIsAdmin=%s, ISChecksum=%s, FileSize=%d, LastError=%d,
user32.dll
XXXXXX
XXXXXXXXX
inetmib1.dll
WS2_32.dll
AWebBrowserIE2
CWebBrowserIE
Err: timerThread: Wait return with invalid code: %u
.?AVCCmdUI@@
.?AVCCmdTarget@@
.PAVCException@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCOleException@@
.PAVCObject@@
.PAVCOleDispatchException@@
.PAVCSimpleException@@
.PAVCResourceException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCFileException@@
.PAVCArchiveException@@
zcÁ
IDispatch error #%d
D:\Work\aod7.3branch_special_10_19\share\ErrorLogger\AErrorsLoggerMgrBlocking.cpp
D:\Work\aod7.3branch_special_10_19\share\ErrorLogger\ErrorLoggerMgr.cpp
[%d]%-20s: %-120s ::%s(=)
!!! %s- %s
AodDebug.ini
%s%s:X
Exception on DoLogEx(FileName: %u, LineNumber: %d)
Exception on DoLogEx(FileName: %s, LineNumber: %d)
netmsg.dll
%s - %s
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\AThread.cpp
Err: Error creating thread, Windows error: %s.
Err: Operation is not allowed within thread context.
Err: Error terminating thread, Windows error: %s.
Err: Error while waiting on object, Windows error: %s.
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\ASyncObject.cpp
Err: Failed to create object, Windows error: %s.
Err: Failed to open object, Windows error: %s.
Err: Failed to set/reset event, Windows error: %s.
Err: Failed to release object, Windows error: %s.
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\ARegistryKey.cpp
Err: Error openning registry key NULL Key.
Err: Error openning/creating registry key %s, Windows error: %s.
Err: Error openning/creating registry key NULL Key.
Err: Error reading from registry key NULL Parameter.
Err: Invalid registry key type at registry key %s.
Err: Error reading from registry key NULL Key.
Err: Error reading from registry key %s, Windows error: %s.
Err: Registry entry %s too long.
Err: Error writing to registry key NULL Parameter.
Err: Error writing to registry key %s, Windows error: %s.
Err: Error writing to registry key NULL Key.
Err: Error deleting registry key %s, Windows error: %s.
Err: Error deleting registry key NULL Parameter.
Err: Error deleting registry key NULL Key.
D:\Work\aod7.3branch_special_10_19\share\AAodUtilities\AWorkQueue.cpp
wininet.dll
%s: %s
Invalid schema (%u).
Invalid url.
Server return HTTP code:%u. err:%s
%s: %u
Failed to read http response. err
Page: %s not found: %s
Fail to query status code err: %s
AHTTPConnection::_Work() - Error. Did not Receive exactly the requested Range.
Failed to end http request. err
%s: %d
Failed to send http request. err
%s: %s
Failed to add http header. err
undefined operation!
Fail to crack URL. err:schema <%u> is not supported.
Fail to crack URL err:%u.
%s %S to %S err: %u
Range: bytes=%u-%u
Fail to read file. err:%u.
Fail to open file %S. err:%u.
Range: bytes=%d-%d
HTTP/1.1
D:\Work\aod7.3branch_special_10_19\share\AAodUtilities\AInternetConnectionTrigger.cpp
Software\\AppDataLow\\Software\\Exent\\AOD\\IS
Mozilla Firefox 2
Exent EXEtender
CREATE TABLE cookies (creation_utc INTEGER NOT NULL UNIQUE PRIMARY KEY, host_key TEXT NOT NULL,name TEXT NOT NULL,value TEXT NOT NULL, path TEXT NOT NULL,expires_utc INTEGER NOT NULL, secure INTEGER NOT NULL,httponly INTEGER NOT NULL, last_access_utc INTEGER DEFAULT 0)
Google Chrome
host_key
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly FROM cookies
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly, encrypted_value FROM cookies
\Google\Chrome\User Data\Default\
UPDATE cookies SET name = ?1, value = ?2, host_key = ?3, path = ?4, expires_utc = ?5, secure = ?6, httponly = ?7, encrypted_value = ?9 WHERE creation_utc = ?8
INSERT INTO cookies (creation_utc, host_key, name, value, path, expires_utc, secure, httponly, last_access_utc) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9, creationTime = ?10 WHERE id = ?1
INSERT INTO moz_cookies (name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain, creationTime) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly, creationTime FROM moz_cookies
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly FROM moz_cookies
Mozilla Firefox 3/4
\cookies.sqlite
profiles.ini
\Mozilla\Firefox\
#HttpOnly_
# HTTP Cookie File
# hXXp://VVV.netscape.com/newsref/std/cookie_spec.html
\cookies.txt
shell32.dll
cmhelper.exe
ietemp1.dat
SELECT name FROM sqlite_master WHERE type = 'table' AND name = '
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
foreign_key_list
foreign_key_check
defer_foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat4
sqlite_stat3
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
GetProcessHeap
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s%s%s
unknown database %s
recovered %d pages from %s
cannot limit WAL size: %s
recovered %d frames from WAL file %s
MJ delete: %s
-mjX9X
MJ collide: %s
%s-mjXXXXXX9XXz
foreign key constraint failed
922337203685477580
%s(%d)
keyinfo(%d
bind on a busy prepared statement: [%s]
statement aborts at %d: [%s] %s
constraint failed at %d in [%s]
abort at %d in [%s]: %s
database table is locked: %s
cannot change %s wal mode from within a transaction
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
sqlite_master
sqlite_temp_master
cannot commit transaction - SQL statements in progress
cannot release savepoint - SQL statements in progress
no such savepoint: %s
cannot open savepoint - SQL statements in progress
Outstanding page count goes from %d to %d during this analysis
Pointer map page %d is referenced
Page %d is never used
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Failed to read ptrmap key=%d
failed to get page %d
%d of %d pages missing from overflow list starting at %d
freelist leaf count too big on page %d
2nd reference to page %d
invalid page number %d
Fragmentation of %d bytes reported as %d on page %d
Multiple uses for byte %d of page %d
Corruption detected in cell %d on page %d
On page %d at right child:
On tree page %d cell %d:
btreeInitPage() returns error code %d
unable to get the page. error code=%d
Page %d:
zeroblob(%d)
cannot open %s column for writing
no such column: "%s"
cannot open view: %s
cannot open virtual table: %s
indexed
foreign key
cannot open value of type %s
%.*s"%w"%s
%s%.*s"%w"
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
unable to open database: %s
database %s is already in use
too many attached databases - max %d
database %s is locked
cannot detach database %s
no such database: %s
%s: %s.%s
API call with %s database connection pointer
error during initialization: %s
no entry point [%s] in shared library [%s]
sqlite3_
unable to open shared library [%s]
%s.%s
sqlite3_extension_init
malformed database schema (%s)
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unsupported file format
database schema is locked: %s
sqlite3_get_table() called with two or more incompatible queries
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
PRAGMA vacuum_db.synchronous=OFF
cannot VACUUM - SQL statements in progress
no such module: %s
vtable constructor did not declare schema: %s
vtable constructor failed: %s
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
Expression tree is too large (maximum depth %d)
too many SQL variables
variable number must be between ?1 and ?%d
too many columns in %s
there is already another table or index with this name: %s
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
sqlite_sequence
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
view %s may not be altered
%s OR name=%Q
type='trigger' AND (%s)
table %s may not be altered
sqlite_
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
Cannot add a PRIMARY KEY column
sqlite_altertab_%s
DELETE FROM %Q.%s WHERE %s=%Q
CREATE TABLE %Q.%s(%s)
misuse of aggregate: %s()
EXECUTE %s%s SUBQUERY %d
invalid name: "%s"
not authorized to use function: %s
%s: %s.%s.%s
misuse of aliased aggregate %s
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
duplicate column name: %s
too many columns on %s
default value of column [%s] is not constant
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
table "%s" has more than one primary key
CREATE TABLE %Q.sqlite_sequence(name,seq)
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE %s %.*s
%s %T cannot reference objects in database %s
%s cannot use variables
view %s is circularly defined
use DROP VIEW to delete view %s
use DROP TABLE to delete table %s
table %s may not be dropped
sqlite_stat
sqlite_stat%d
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
unknown column "%s" in foreign key definition
number of columns in foreign key does not match the number of columns in the referenced table
foreign key on %s should reference only one column of table %T
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
CREATE%s INDEX %.*s
table %s has no column named %s
sqlite_autoindex_%s_%d
index %s already exists
there is already a table named %s
virtual tables may not be indexed
views may not be indexed
table %s may not be indexed
cannot create a TEMP index on non-TEMP table "%s"
indexed columns are not unique
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
no such index: %S
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
cannot modify %s because it is a view
table %s may not be modified
foreign key mismatch - "%w" referencing "%w"
table %S has no column named %s
%d values for %d columns
table %S has %d columns but %d values were supplied
PRIMARY KEY must be unique
constraint %s failed
%s.%s may not be NULL
unsupported encoding: %s
*** in database %s ***
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
%s:%d
no such index: %s
no such table: %s
%s.%s.%s
too many references to "%s": max 65535
sqlite_sq_%p
cannot join using column %s - column not present in both tables
cannot have both ON and USING clauses in the same join
a NATURAL join may not have an ON or USING clause
USE TEMP B-TREE FOR %s
SELECTs to the left and right of %s do not have the same number of result columns
LIMIT clause should come after %s not before
ORDER BY clause should come after %s not before
COMPOUND SUBQUERIES %d AND %d %s(%s)
SCAN TABLE %s%s%s
cannot create INSTEAD OF trigger on table: %S
cannot create %s trigger on view: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
at most %d tables in a join
automatic index on %s(%s)
%s VIRTUAL TABLE INDEX %d:%s
%s (rowid<?)
%s (rowid>?)
%s (rowid>? AND rowid<?)
%s (rowid=?)
%s USING INTEGER PRIMARY KEY
%s USING %sINDEX %s%s
%s USING AUTOMATIC %sINDEX%.0s%s
%s AS %s
%s TABLE %s
%s SUBQUERY %d
%s.xBestIndex() malfunction
table %s: xBestIndex returned an invalid plan
unable to use function %s in the requested context
unknown database: %s
no such vfs: %s
%s mode not allowed: %s
no such %s mode: %s
automatic extension loading failed: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
UrlMon.dll
CLSID%d
SOFTWARE\Exent\AOD\CLSID
Global\{EB900DF8-0D3D-46c3-9B60-1E7A0D34870A}
Kernel32.dll
%X%X%X
HardwareInformation.AdapterString
\\.\PhysicalDrive%d
winio.sys
\\.\Scsi%d:
Service Pack: %d
Windows XP
Windows 2000
Windows NT
Windows ??
Windows Millenium Edition
Windows 98 Second Edition
Windows 98 SP1
Windows 98
Windows 95 OSR2
Windows 95 SP1
Windows 95
Windows CE
Windows
Microsoft Windows Me
Microsoft Windows 98
Microsoft Windows 95
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT
KERNEL32.DLL
GetCPInfo
GetWindowsDirectoryA
RegOpenKeyA
RegNotifyChangeKeyValue
RegEnumKeyA
RegCreateKeyExW
RegOpenKeyExA
RegCreateKeyExA
RegCloseKey
RegOpenKeyExW
RegDeleteKeyA
GetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
ShellExecuteExW
ShellExecuteExA
ShellExecuteA
GetKeyboardLayout
GetAsyncKeyState
GetKeyState
UnhookWindowsHookEx
CreateDialogIndirectParamW
SetWindowsHookExW
FindFirstUrlCacheEntryA
InternetCrackUrlW
FindNextUrlCacheEntryA
FindCloseUrlCache
DeleteUrlCacheEntry
CreateUrlCacheEntryA
CommitUrlCacheEntryA
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestExA
HttpEndRequestA
HttpQueryInfoA
InternetCrackUrlA
.text
`.rdata
@.data
.rsrc
version="4.34.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
CRYPT32.dll
GDI32.dll
ole32.dll
OLEAUT32.dll
oledlg.dll
OLEPRO32.DLL
RPCRT4.dll
SensApi.dll
SHELL32.dll
USER32.dll
VERSION.dll
WININET.dll
WINMM.dll
WINSPOOL.DRV
WSOCK32.dll
commctrl_DragListMsg
%*.*f
N.INI
NMSWHEEL_ROLLMSG
888816666554443
6666554443
!6666554443
SDM_DB_%d.xml
resourceDll.dll
SKINCONFIG.XML
WEBDLG_GetStringsXml
SDMSTRINGS.XML
res://%s/%d
SDM_OpenWebDialog
SDMstrings.xml
SkinConfig.xml
SDM.ICO
IHTTPConnectionThreadPool::Init()
IHTTPConnectionThreadPoolFactory::Create()
index.html
CSmallDownloadManagerDlg::OnFail Context = %d, ErrorType = %d, HttpStatusCode = %d, HttpError = %S, winInetError = %d, AcceleraterError = %d
SDM_IS_EXECUTION_FAILED
OpenWebDialog:
http\shell\open\command
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Software\Classes\ChromeHTML
Software\Classes\ChromeHTML\shell
Software\Classes\ChromeHTML\shell\open
Software\Classes\ChromeHTML\shell\open\command
SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
AddContentToDownloadList: ParseCmdLine
!SDMLog.log
SDMLog.tmp
CSmallDownloadManagerDlg::OnISError ErrorId = %d, strErrDsc = %S
ExentCtl.ExentInf.1
xs.s.s.s
SyncCookies: Failed to sync %s using CSNamesEx, CS error = %d
SyncCookies: Failed to sync %s using CSNames, CS error = %d
d.exe
.http.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
1996-2009 Exent Technologies Ltd. All rights reserved.
FreeRideGames.EXE
1, 0, 0, 19

Free Ride Games.exe_3400_rwx_00401000_0013B000:

E8SSSSSh
vhSSSSSSh
SSQSSh
D$,WVPSSh
.tTPV
FTPjK
FtPj;
F.PjRWj
u.WWj
u.VVj
P$8^%uX
SSSSh
<.up3
<8%u=
.FGy/
Fd t.SPW
N.VAPQW
G.f;E.uJ3
N.AQPWjhS
N.AQS
N.AQUS
V.BRUS
f9~.vX
?%uMf
_uninsdm.bat
CCmdTarget
COMCTL32.DLL
CNotSupportedException
__MSVCRT_HEAP_SELECT
portuguese-brazilian
//DownloadAcceleratorDB/URL
<DownloadAcceleratorDB><ID>%s</ID><LastModified>%s</LastModified><URL>%s</URL><Size>%d</Size><PartialFiles>
<Path>%s</Path>
3.8.1
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYHerF
MD5 part of OpenSSL 0.9.8a 11 Oct 2005
DownloadManager.exe
?messageMap@CHtmlSkinDlg@@1UAFX_MSGMAP@@B
?messageMap@CSmallDownloadManagerApp@@1UAFX_MSGMAP@@B
?messageMap@CSmallDownloadManagerDlg@@1UAFX_MSGMAP@@B
******SDM FetchConfigurationXML failed to load XML! URL=
******SDM FetchConfigurationXML failed! URL=
AHTTPConnection
HTTP/1.0
ReportUrl
IS/Url
PromotionUrl
/ContentConfiguration/%s
rd "%s" /q /s
if exist "%s" goto Repeat
del "%s"
strUrl:
Software\AppDataLow\Software\Exent\AOD\SDM
strUrlParams:
strFullUrl:
http:\\VVV.microsoft.com
http:\\VVV.google.com
strResumeURL:
******EXTERNAL: SDM_OpenWebDialog
tUExent_SDM
%S "%S u '%S' p '%d' c '%d'"
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SetUrl Failed!
%s%c%c%c
%s%c%c
<ResumeDownloadListRequest> <ProviderDescriptor Id="%d" /> </ResumeDownloadListRequest>
<AddGameToDownloadListRequest><ContentDescriptor Id="%d" ProviderId="%d" FullDownload="0" ToPriority="-1" DirectionsUrl="%s"><DirectionsString></DirectionsString><AdditionalInfo>%s</AdditionalInfo></ContentDescriptor></AddGameToDownloadListRequest>
SOFTWARE\Exent\AOD\Client
x.x.x.x
<GetGamesIdsListRequest ProviderId="%d" ActiveGamesOnly="0" InDownloadListOnly="1" ReadyToUseOnly="0" NotInDownloadList="0" CurrentOSOnly="0" CacheUpdating="0" SortBy="DownloadPriority" />
SOFTWARE\Exent\AOD\Client\Providers\%s\Settings\SkinCode
SkinCfg.xml
Context=%d, AcceleratorErrorType=%d, HTTPERROR::AHTTPstatusCode=%d, AcceleratorErrorCode=%d, HTTPERROR::AWinInetError=%d, HTTPERROR::StrLastError=%s,
SystemBits=%d, SDMUserIsAdmin=%s, ISChecksum=%s, FileSize=%d, LastError=%d,
user32.dll
XXXXXX
XXXXXXXXX
inetmib1.dll
WS2_32.dll
AWebBrowserIE2
CWebBrowserIE
Err: timerThread: Wait return with invalid code: %u
.?AVCCmdUI@@
.?AVCCmdTarget@@
.PAVCException@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCOleException@@
.PAVCObject@@
.PAVCOleDispatchException@@
.PAVCSimpleException@@
.PAVCResourceException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCFileException@@
.PAVCArchiveException@@
zcÁ
IDispatch error #%d
D:\Work\aod7.3branch_special_10_19\share\ErrorLogger\AErrorsLoggerMgrBlocking.cpp
D:\Work\aod7.3branch_special_10_19\share\ErrorLogger\ErrorLoggerMgr.cpp
[%d]%-20s: %-120s ::%s(=)
!!! %s- %s
AodDebug.ini
%s%s:X
Exception on DoLogEx(FileName: %u, LineNumber: %d)
Exception on DoLogEx(FileName: %s, LineNumber: %d)
netmsg.dll
%s - %s
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\AThread.cpp
Err: Error creating thread, Windows error: %s.
Err: Operation is not allowed within thread context.
Err: Error terminating thread, Windows error: %s.
Err: Error while waiting on object, Windows error: %s.
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\ASyncObject.cpp
Err: Failed to create object, Windows error: %s.
Err: Failed to open object, Windows error: %s.
Err: Failed to set/reset event, Windows error: %s.
Err: Failed to release object, Windows error: %s.
D:\Work\aod7.3branch_special_10_19\share\AWin32Util\ARegistryKey.cpp
Err: Error openning registry key NULL Key.
Err: Error openning/creating registry key %s, Windows error: %s.
Err: Error openning/creating registry key NULL Key.
Err: Error reading from registry key NULL Parameter.
Err: Invalid registry key type at registry key %s.
Err: Error reading from registry key NULL Key.
Err: Error reading from registry key %s, Windows error: %s.
Err: Registry entry %s too long.
Err: Error writing to registry key NULL Parameter.
Err: Error writing to registry key %s, Windows error: %s.
Err: Error writing to registry key NULL Key.
Err: Error deleting registry key %s, Windows error: %s.
Err: Error deleting registry key NULL Parameter.
Err: Error deleting registry key NULL Key.
D:\Work\aod7.3branch_special_10_19\share\AAodUtilities\AWorkQueue.cpp
wininet.dll
%s: %s
Invalid schema (%u).
Invalid url.
Server return HTTP code:%u. err:%s
%s: %u
Failed to read http response. err
Page: %s not found: %s
Fail to query status code err: %s
AHTTPConnection::_Work() - Error. Did not Receive exactly the requested Range.
Failed to end http request. err
%s: %d
Failed to send http request. err
%s: %s
Failed to add http header. err
undefined operation!
Fail to crack URL. err:schema <%u> is not supported.
Fail to crack URL err:%u.
%s %S to %S err: %u
Range: bytes=%u-%u
Fail to read file. err:%u.
Fail to open file %S. err:%u.
Range: bytes=%d-%d
HTTP/1.1
D:\Work\aod7.3branch_special_10_19\share\AAodUtilities\AInternetConnectionTrigger.cpp
Software\\AppDataLow\\Software\\Exent\\AOD\\IS
Mozilla Firefox 2
Exent EXEtender
CREATE TABLE cookies (creation_utc INTEGER NOT NULL UNIQUE PRIMARY KEY, host_key TEXT NOT NULL,name TEXT NOT NULL,value TEXT NOT NULL, path TEXT NOT NULL,expires_utc INTEGER NOT NULL, secure INTEGER NOT NULL,httponly INTEGER NOT NULL, last_access_utc INTEGER DEFAULT 0)
Google Chrome
host_key
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly FROM cookies
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly, encrypted_value FROM cookies
\Google\Chrome\User Data\Default\
UPDATE cookies SET name = ?1, value = ?2, host_key = ?3, path = ?4, expires_utc = ?5, secure = ?6, httponly = ?7, encrypted_value = ?9 WHERE creation_utc = ?8
INSERT INTO cookies (creation_utc, host_key, name, value, path, expires_utc, secure, httponly, last_access_utc) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9, creationTime = ?10 WHERE id = ?1
INSERT INTO moz_cookies (name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain, creationTime) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly, creationTime FROM moz_cookies
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly FROM moz_cookies
Mozilla Firefox 3/4
\cookies.sqlite
profiles.ini
\Mozilla\Firefox\
#HttpOnly_
# HTTP Cookie File
# hXXp://VVV.netscape.com/newsref/std/cookie_spec.html
\cookies.txt
shell32.dll
cmhelper.exe
ietemp1.dat
SELECT name FROM sqlite_master WHERE type = 'table' AND name = '
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
foreign_key_list
foreign_key_check
defer_foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat4
sqlite_stat3
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
GetProcessHeap
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s%s%s
unknown database %s
recovered %d pages from %s
cannot limit WAL size: %s
recovered %d frames from WAL file %s
MJ delete: %s
-mjX9X
MJ collide: %s
%s-mjXXXXXX9XXz
foreign key constraint failed
922337203685477580
%s(%d)
keyinfo(%d
bind on a busy prepared statement: [%s]
statement aborts at %d: [%s] %s
constraint failed at %d in [%s]
abort at %d in [%s]: %s
database table is locked: %s
cannot change %s wal mode from within a transaction
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
sqlite_master
sqlite_temp_master
cannot commit transaction - SQL statements in progress
cannot release savepoint - SQL statements in progress
no such savepoint: %s
cannot open savepoint - SQL statements in progress
Outstanding page count goes from %d to %d during this analysis
Pointer map page %d is referenced
Page %d is never used
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Failed to read ptrmap key=%d
failed to get page %d
%d of %d pages missing from overflow list starting at %d
freelist leaf count too big on page %d
2nd reference to page %d
invalid page number %d
Fragmentation of %d bytes reported as %d on page %d
Multiple uses for byte %d of page %d
Corruption detected in cell %d on page %d
On page %d at right child:
On tree page %d cell %d:
btreeInitPage() returns error code %d
unable to get the page. error code=%d
Page %d:
zeroblob(%d)
cannot open %s column for writing
no such column: "%s"
cannot open view: %s
cannot open virtual table: %s
indexed
foreign key
cannot open value of type %s
%.*s"%w"%s
%s%.*s"%w"
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
unable to open database: %s
database %s is already in use
too many attached databases - max %d
database %s is locked
cannot detach database %s
no such database: %s
%s: %s.%s
API call with %s database connection pointer
error during initialization: %s
no entry point [%s] in shared library [%s]
sqlite3_
unable to open shared library [%s]
%s.%s
sqlite3_extension_init
malformed database schema (%s)
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unsupported file format
database schema is locked: %s
sqlite3_get_table() called with two or more incompatible queries
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
PRAGMA vacuum_db.synchronous=OFF
cannot VACUUM - SQL statements in progress
no such module: %s
vtable constructor did not declare schema: %s
vtable constructor failed: %s
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
Expression tree is too large (maximum depth %d)
too many SQL variables
variable number must be between ?1 and ?%d
too many columns in %s
there is already another table or index with this name: %s
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
sqlite_sequence
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
view %s may not be altered
%s OR name=%Q
type='trigger' AND (%s)
table %s may not be altered
sqlite_
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
Cannot add a PRIMARY KEY column
sqlite_altertab_%s
DELETE FROM %Q.%s WHERE %s=%Q
CREATE TABLE %Q.%s(%s)
misuse of aggregate: %s()
EXECUTE %s%s SUBQUERY %d
invalid name: "%s"
not authorized to use function: %s
%s: %s.%s.%s
misuse of aliased aggregate %s
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
duplicate column name: %s
too many columns on %s
default value of column [%s] is not constant
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
table "%s" has more than one primary key
CREATE TABLE %Q.sqlite_sequence(name,seq)
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE %s %.*s
%s %T cannot reference objects in database %s
%s cannot use variables
view %s is circularly defined
use DROP VIEW to delete view %s
use DROP TABLE to delete table %s
table %s may not be dropped
sqlite_stat
sqlite_stat%d
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
unknown column "%s" in foreign key definition
number of columns in foreign key does not match the number of columns in the referenced table
foreign key on %s should reference only one column of table %T
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
CREATE%s INDEX %.*s
table %s has no column named %s
sqlite_autoindex_%s_%d
index %s already exists
there is already a table named %s
virtual tables may not be indexed
views may not be indexed
table %s may not be indexed
cannot create a TEMP index on non-TEMP table "%s"
indexed columns are not unique
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
no such index: %S
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
cannot modify %s because it is a view
table %s may not be modified
foreign key mismatch - "%w" referencing "%w"
table %S has no column named %s
%d values for %d columns
table %S has %d columns but %d values were supplied
PRIMARY KEY must be unique
constraint %s failed
%s.%s may not be NULL
unsupported encoding: %s
*** in database %s ***
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
%s:%d
no such index: %s
no such table: %s
%s.%s.%s
too many references to "%s": max 65535
sqlite_sq_%p
cannot join using column %s - column not present in both tables
cannot have both ON and USING clauses in the same join
a NATURAL join may not have an ON or USING clause
USE TEMP B-TREE FOR %s
SELECTs to the left and right of %s do not have the same number of result columns
LIMIT clause should come after %s not before
ORDER BY clause should come after %s not before
COMPOUND SUBQUERIES %d AND %d %s(%s)
SCAN TABLE %s%s%s
cannot create INSTEAD OF trigger on table: %S
cannot create %s trigger on view: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
at most %d tables in a join
automatic index on %s(%s)
%s VIRTUAL TABLE INDEX %d:%s
%s (rowid<?)
%s (rowid>?)
%s (rowid>? AND rowid<?)
%s (rowid=?)
%s USING INTEGER PRIMARY KEY
%s USING %sINDEX %s%s
%s USING AUTOMATIC %sINDEX%.0s%s
%s AS %s
%s TABLE %s
%s SUBQUERY %d
%s.xBestIndex() malfunction
table %s: xBestIndex returned an invalid plan
unable to use function %s in the requested context
unknown database: %s
no such vfs: %s
%s mode not allowed: %s
no such %s mode: %s
automatic extension loading failed: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
UrlMon.dll
CLSID%d
SOFTWARE\Exent\AOD\CLSID
Global\{EB900DF8-0D3D-46c3-9B60-1E7A0D34870A}
Kernel32.dll
%X%X%X
HardwareInformation.AdapterString
\\.\PhysicalDrive%d
winio.sys
\\.\Scsi%d:
Service Pack: %d
Windows XP
Windows 2000
Windows NT
Windows ??
Windows Millenium Edition
Windows 98 Second Edition
Windows 98 SP1
Windows 98
Windows 95 OSR2
Windows 95 SP1
Windows 95
Windows CE
Windows
Microsoft Windows Me
Microsoft Windows 98
Microsoft Windows 95
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT
KERNEL32.DLL
GetCPInfo
GetWindowsDirectoryA
RegOpenKeyA
RegNotifyChangeKeyValue
RegEnumKeyA
RegCreateKeyExW
RegOpenKeyExA
RegCreateKeyExA
RegCloseKey
RegOpenKeyExW
RegDeleteKeyA
GetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
ShellExecuteExW
ShellExecuteExA
ShellExecuteA
GetKeyboardLayout
GetAsyncKeyState
GetKeyState
UnhookWindowsHookEx
CreateDialogIndirectParamW
SetWindowsHookExW
FindFirstUrlCacheEntryA
InternetCrackUrlW
FindNextUrlCacheEntryA
FindCloseUrlCache
DeleteUrlCacheEntry
CreateUrlCacheEntryA
CommitUrlCacheEntryA
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestExA
HttpEndRequestA
HttpQueryInfoA
InternetCrackUrlA
.text
`.rdata
@.data
.rsrc
commctrl_DragListMsg
%*.*f
N.INI
NMSWHEEL_ROLLMSG
ole32.dll
888816666554443
6666554443
!6666554443
SDM_DB_%d.xml
resourceDll.dll
SKINCONFIG.XML
WEBDLG_GetStringsXml
SDMSTRINGS.XML
res://%s/%d
SDM_OpenWebDialog
SDMstrings.xml
SkinConfig.xml
SDM.ICO
IHTTPConnectionThreadPool::Init()
IHTTPConnectionThreadPoolFactory::Create()
index.html
CSmallDownloadManagerDlg::OnFail Context = %d, ErrorType = %d, HttpStatusCode = %d, HttpError = %S, winInetError = %d, AcceleraterError = %d
SDM_IS_EXECUTION_FAILED
OpenWebDialog:
http\shell\open\command
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Software\Classes\ChromeHTML
Software\Classes\ChromeHTML\shell
Software\Classes\ChromeHTML\shell\open
Software\Classes\ChromeHTML\shell\open\command
SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
AddContentToDownloadList: ParseCmdLine
!SDMLog.log
SDMLog.tmp
CSmallDownloadManagerDlg::OnISError ErrorId = %d, strErrDsc = %S
ExentCtl.ExentInf.1
xs.s.s.s
SyncCookies: Failed to sync %s using CSNamesEx, CS error = %d
SyncCookies: Failed to sync %s using CSNames, CS error = %d
USER32.dll
d.exe
.http.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.

Free Ride Games.exe_3400_rwx_10001000_0007B000:

__MSVCRT_HEAP_SELECT
user32.dll
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/dialogs.css"/>
<script type="text/javascript" src="res://resourceDll.dll/js/defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/conf_defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/connection.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/pageURLInfo.js"></script>
var PageUrlInfo = new Exent.SDM.PageUrlInfo();
PageUrlInfo.LoadFromPageUrl();
var strErrId = PageUrlInfo.GetMsg();
var isChatEnabled = PageUrlInfo.GetParam1();
var type = PageUrlInfo.GetType();
document.getElementById("title").innerHTML = AdjustPageTitle ( strTitle );
document.getElementById("title").title = strTitle;
document.getElementById("innerText").innerHTML = GetStringValueById( strErrId );
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.OK;
setTimeout( CheckInternetConnection , Exent.SDM.Defines.Config.CheckConnectionInterval );
CheckConnection( Exent.SDM.Defines.Config.CheckConnectionURL , Exent.SDM.Defines.ConnectionId.Internet, "" );
document.getElementById('connectionStatus').src = 'res://resourceDll.dll/img/disconnected.gif';
document.getElementById('retryDisabled').style.display = "none";
document.getElementById('retryEnabled').style.display = "block";
CheckConnection( Exent.SDM.Defines.Config.CheckConnectionURL , Exent.SDM.Defines.ConnectionId.Other, "" );
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Cancel;
document.getElementById('connectionStatus').src = 'res://resourceDll.dll/img/connecting_anim.gif';
document.getElementById('retryDisabled').style.display = "block";
document.getElementById('retryEnabled').style.display = "none";
window.setTimeout(RetryConnection, 2000 );
<img id="connectionStatus" class="error" src="res://resourceDll.dll/img/disconnected.gif" alt="" />
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnCancel()" /></div>
<img src="res://resourceDll.dll/img/retry_up.gif" id="retryButton" class="retryButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnRetry()" />
<img src="res://resourceDll.dll/img/retry_disabled.gif" id="retryButton" class="retryButton" />
<img src="res://resourceDll.dll/img/cancel_up.gif" id="cancelButton" class="cancelButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnCancel()" />
<a id="surveyURL" target="_blank"><span id="surveyText" class="innerText"></span></a>
<script type="text/javascript" src="res://resourceDll.dll/js/defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/pageurlinfo.js"></script>
var PageUrlInfo = new Exent.SDM.PageUrlInfo();
var isChatEnabled = PageUrlInfo.GetParam1();
var type = PageUrlInfo.GetType();
document.getElementById('title').innerHTML = AdjustPageTitle ( strTitle );
document.getElementById('title').title = strTitle;
document.getElementById('innerText').innerHTML = GetStringValueById( strErrId );
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Retry;
<img id = "connectionStatus" class="error" src="res://resourceDll.dll/img/disconnected.gif" alt="" />
<div class="XButton"><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnRetry()" /></div>
<img src="res://resourceDll.dll/img/retry_up.gif" id="retryButton" class="retryButton retryButtonEnabled" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnRetry();" />
<img src="res://resourceDll.dll/img/cancel_up.gif" id="cancelButton" class="cancelButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnCancel();" />
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/sdm.css" />
<script type="text/javascript" src="res://resourceDll.dll/js/defines.js"></script>
// those functions call by the index.html
top.CloseSDM();
case Exent.SDM.Defines.Status.Disconnected:
case Exent.SDM.Defines.Status.Init:
case Exent.SDM.Defines.Status.ServiceDown:
case Exent.SDM.Defines.Status.OK:
<script type="text/javascript" src="res://resourceDll.dll/js/defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/conf_defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/pageURLInfo.js"></script>
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.OK;
var PageUrlInfo = new Exent.SDM.PageUrlInfo();
PageUrlInfo.LoadFromPageUrl();
var strErrId = PageUrlInfo.GetMsg()
if ( errDesc == PageUrlInfo.GetMsg() ) {
var isChatEnabled = PageUrlInfo.GetParam1();
var type = PageUrlInfo.GetType();
document.getElementById('title').innerText = AdjustPageTitle ( strTitle );
document.getElementById('title').title = strTitle ;
document.getElementById('innerText').innerHTML = errDesc.replace( Exent.SDM.Defines.SDMStringsTokens.ErrorId, strErrCode);
document.getElementById('surveyHolder').style.display = "none";
document.getElementById('retryButtonHolder').style.display = "none";
if ( strErrId == Exent.SDM.Defines.ErrorID.SDM_IS_PROCESS_ABNORMAL_TERMINATION_ERROR) {
document.getElementById('surveyText').innerHTML = GetStringValueById( "SDM_SURVEY_LINK_TEXT" );
document.getElementById('surveyURL').href = Exent.SDM.Defines.HTMLS.SurveyURL;
document.getElementById('OKButtonHolder').style.display = "none";
document.getElementById('retryButtonHolder').style.display = "block";
document.getElementById('surveyHolder').style.display = "block";
document.getElementById('OKButtonHolder').style.display = "block";
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Cancel;
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Retry;
<img class="error" src="res://resourceDll.dll/img/error_header.gif" alt="" />
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnRetry()" /></div>
<img src="res://resourceDll.dll/img/ok_up.gif" class="OKButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnOK()" />
<script type="text/javascript" src="res://resourceDll.dll/js/conf_defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.Event,
Exent.SDM.Defines.Measurements.EULADeclined );
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.SDMVersion,
Exent.SDM.Defines.Version );
top.GetMeasurementsObject().Send();
top.GetControllerObject().Navigate( Exent.SDM.Defines.PageId.EndingPage );
var addOnsArray = top.GetConfigurationObject().GetAddons();
for ( var i = 0; i < addOnsArray.length; i  ) {
if ( addOnsArray[i].strAddOnID == Exent.SDM.Defines.Addons.Toolbar ) {
addOnsArray[i].isSelected = document.getElementById( "FRGToolBar" ).checked;
if ( addOnsArray[i].strAddOnID == Exent.SDM.Defines.Addons.Toolbar_Homepage ) {
addOnsArray[i].isSelected = document.getElementById( "FRGToolBarHomepage" ).checked;
bToolbarWithHomepage = document.getElementById( "FRGToolBarHomepage" ).checked;
addOnsArray[iToolbarIndex].isSelected = false;
if ( Exent.SDM.Defines.Config.SupportsWin64
|| ( top.GetExternalHandlerObject().GetOSType() == "32" ) ) {
top.GetControllerObject().Navigate( Exent.SDM.Defines.PageId.ProgressPage );
top.GetMeasurementsObject().SendError(
GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_OS_NOT_SUPPORTED ) );
top.SetResumeParams( Exent.SDM.Defines.Button.Value.Cancel );
top.GetControllerObject().SetLastErrorCode(
document.getElementById( Exent.SDM.Defines.Addons.Toolbar ).style.display = "block";
document.getElementById( Exent.SDM.Defines.Addons.Toolbar   "Spacer" ).style.display = "none";
document.getElementById( Exent.SDM.Defines.Addons.Toolbar_Homepage ).style.display = "block";
document.getElementById( Exent.SDM.Defines.Addons.Toolbar_Homepage   "Spacer" ).style.display = "none";
addOnsArray[i].isSelected = document.getElementById( "FRGToolBarHomePage" ).checked;
document.getElementById( "idEulaLink" ).href = top.GetConfigurationObject().GetEULAUrl();
if ( document.getElementById( Exent.SDM.Defines.Addons.Toolbar_Homepage ).style.display == "block" ) {
if ( false == document.getElementById( "FRGToolBar" ).checked ) {
document.getElementById( "FRGToolBarHomePage" ).checked = false;
Free Ride Games Toolbar (installs on IE and Firefox).
I have read, agreed and accepted the toolbar <a href="hXXp://conduit.ourtoolbar.com/eula/"
target="_blank">EULA</a> and <a href="hXXp://VVV.conduit.com/privacy/ConduitPrivacy.aspx"
my homepage to the Free Ride Games customized Web Search page</input>
href="hXXp://VVV.freeridegames.com/do/general?partner=Default&jspName=privacy" target="_blank">Privacy
onmouseup="this.style.top='0px';this.style.left='0px';"
onmouseout="this.style.top='0px';this.style.left='0px';"
onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnOK();"></div>
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/dialogs.css">
<script type="text/javascript" src="res://resourceDll.dll/js/pageURLInfo.js"></script>
if ( document.getElementById( 'resumeAfterStartup' ).checked == true ) {
window.location.href = Exent.SDM.Defines.UrlParameter.Close
  Exent.SDM.Defines.Button.Value.CancelWithResume;
  Exent.SDM.Defines.Button.Value.Cancel;
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.CloseMessageBox;
PageUrlInfo.LoadFromPageUrl();
var strErrId = PageUrlInfo.GetMsg();
var strTitle = GetPageTitle( strErrId ).replace( Exent.SDM.Defines.SDMStringsTokens.GameName,
PageUrlInfo.GetGameName() );
document.getElementById( 'title' ).innerHTML = AdjustPageTitle( strTitle );
document.getElementById( 'title' ).title = strTitle;
document.getElementById( 'innerText' ).innerHTML = GetStringValueById( strErrId )
.replace( Exent.SDM.Defines.SDMStringsTokens.GameName, PageUrlInfo.GetGameName() );
document.getElementById( "resumeOnStartupText" ).innerHTML = GetStringValueById( "RESUME_ON_STARTUP_TEXT" );
<img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton"
onmouseup="this.style.filter='alpha(opacity=100)';"
onmouseout="this.style.filter='alpha(opacity=100)';"
onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnXButton()" />
<img src="res://resourceDll.dll/img/continue_up.gif" alt="Continue" class="continueButton"
id="continueButton" onmouseup="this.style.top='0px';this.style.left='0px';"
onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnContinueDownload()">
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/dialogs.css"/>
<script type="text/javascript" src="res://resourceDll.dll/js/defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/conf_defines.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/pageURLInfo.js"></script>
var PageUrlInfo = new Exent.SDM.PageUrlInfo();
PageUrlInfo.LoadFromPageUrl();
var gameName = PageUrlInfo.GetGameName();
text = text.replace(Exent.SDM.Defines.SDMStringsTokens.GameName , gameName );
document.getElementById('innerText').innerHTML = text;
document.getElementById('gameImage').src = PageUrlInfo.GetParam1();
document.getElementById('headerText').innerHTML = gameName;
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.OK;
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnClose()" /></div>
<img src="res://resourceDll.dll/img/ok_up.gif" id="OKButton" class="OKButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onClick="OnClose();" />
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnClose();" /></div>
<script type="text/javascript" src="res://resourceDll.dll/js/functions.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/connection.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/controller.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/configuration.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/extrnalHandler.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/progress.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/measurements.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/SDMHTMLInterfaces.js"></script>
<script type="text/javascript" src="res://resourceDll.dll/js/gamesInQueue.js"></script>
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/sdm.css" >
document.ondragstart = OnDragWindow;
document.onselectstart = OnDragWindow;
window.fireEvent("onselectstart",event);
var sss= document.getElementById("MinimizeButton");
var minLeft = sss.style.screenX-2;
var minRight = sss.style.screenX  sss.style.width;
if ( minLeft >= event.clientX && minRight <= event.clientX )
GetControllerObject().OnConnectionStatusChanged( Exent.SDM.Defines.Status.Disconnected );
setTimeout( CheckConnectionInetrnet, Exent.SDM.Defines.Config.CheckConnectionInterval);
GetControllerObject().OnConnectionStatusChanged( Exent.SDM.Defines.Status.ServiceDown );
setTimeout( CheckConnectionService, Exent.SDM.Defines.Config.CheckConnectionInterval );
CheckConnection( Exent.SDM.Defines.Config.CheckServiceConnectionURL , Exent.SDM.Defines.ConnectionId.Service, "" );
CheckConnection( Exent.SDM.Defines.Config.CheckConnectionURL , Exent.SDM.Defines.ConnectionId.Internet, "" );
GetControllerObject().OnConnectionStatusChanged( Exent.SDM.Defines.Status.OK );
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.Event, Exent.SDM.Defines.Measurements.TotalProcessStart );
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.SDMVersion, Exent.SDM.Defines.Version );
top.GetMeasurementsObject().Send( );
GetControllerObject().LoadFirstPage();
var state = GetExternalHandlerObject().GetInitializationStatus();
case Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_OK:
case Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_ERROR:
HandleInitializedFailed( Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_ERROR );
<div class="bubbleRight"><img src="res://resourceDll.dll/img/bubbleRight.gif" alt="" ></div>
<div class="bubbleLeft"><img src="res://resourceDll.dll/img/bubbleLeft.gif" alt="" ></div>
<div id="enabledXButton" class="enabledXButton" ><img alt="Close" src="res://resourceDll.dll/img/close_up.gif" class="XButton" id="XButtonControl" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnClose();" > </div>
<div id="disabledXButton" class="disabledXButton"><img alt="Close" src="res://resourceDll.dll/img/close_disabled.gif" class="XButton" id="XButtonControl" > </div>
<div id="MinimizeButton" class="MinimizeButton"><img alt="Minimize" src="res://resourceDll.dll/img/minimize_up.gif" class="MinimizeButton" id="MinimizeButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" OnClick="OnMinimize();"> </div>
<div><img alt="" src="res://resourceDll.dll/img/connecting_anim.gif" /></div>
<script type="text/javascript" src="res://resourceDll.dll/js/util.js"></script>
document.getElementById("resumeOnStartupText").innerHTML = GetStringValueById("RESUME_ON_STARTUP_TEXT");
if ( document.getElementById('resumeAfterStartup').checked == true )
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.CancelWithResume;
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Cancel;
document.getElementById("innerText").innerHTML = GetStringValueById( strErrId ).replace(Exent.SDM.Defines.SDMStringsTokens.GameName,PageUrlInfo.GetGameName());
var strTitle = GetPageTitle( strErrId ).replace(Exent.SDM.Defines.SDMStringsTokens.GameName,PageUrlInfo.GetGameName());
document.getElementById("title").innerHTML = AdjustPageTitle ( strTitle ) ;
<img id = "connectionStatus" class="error" src="res://resourceDll.dll/img/error_header.gif" alt="" />
<img src="res://resourceDll.dll/img/retry_up.gif" class="retryButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnRetry();" />
<img src="res://resourceDll.dll/img/cancel_up.gif" class="cancelButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnCancel();" />
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/sdm.css" />
PageUrlInfo.LoadFromPageUrl();
var msg;
switch (PageUrlInfo.GetPageId() )
case Exent.SDM.Defines.PageId.ConnectionLost:
msg = GetStringValueById( "SDM_OFFLINE_BODY_CONNECTION_LOST_TEXT" );
case Exent.SDM.Defines.PageId.ServiceDown:
msg = GetStringValueById( "SDM_OFFLINE_BODY_SERVICE_DOWN_TEXT" );
document.getElementById('offlineBody').innerHTML = msg;
<div style="width:640px;height:278px;text-align:center;padding-top:90px;background-image:url('res://resourceDll.dll/img/wizard_back_offline.gif');">
document.ondragstart = OnDragWindow;
document.onselectstart = OnDragWindow;
var g_StateValue = Exent.SDM.Defines.DownloadState.Value.SDM_STATE_DOWNLOADING;
var g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_DOWNLOADING;
top.SetPageTitle( strTitle );
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_INSTALLING:
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_IDLE:
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_CONNECTING:
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_DOWNLOADING:
top.GetExternalHandlerObject().CancelInstallation();
if ( g_StateValue != Exent.SDM.Defines.DownloadState.Value.SDM_STATE_DOWNLOAD_FINISHED ) {
Exent.SDM.Defines.Measurements.DownloadCanceled );
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_DOWNLOAD_FINISHED:
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_INSALLATION_FINISHED:
case Exent.SDM.Defines.DownloadState.Value.SDM_STATE_COMPLETED:
top.OnMinimize();
var myGamesUrl = top.GetConfigurationObject().GetMyGamesUrl();
if (myGamesUrl != "") {
var gameId = top.GetConfigurationObject().GetGameId();
myGamesUrl = myGamesUrl.replace('%GAME_ID%', gameId);
window.open(myGamesUrl);
top.GetExternalHandlerObject().CloseSDM();
document.getElementById( "progressBarCover" ).style.backgroundImage = "url(res://resourceDll.dll/img/ProgressBarTop.gif)";
document.getElementById( "progressBarCover" ).style.backgroundImage = "url(res://resourceDll.dll/img/ProgressBarTopAnimated.gif)";
var strPrecentageComplete = top.GetProgressObject().GetPrecentageComplete();
top.GetProgressObject().SetPrecentageComplete( strPrecentageComplete );
document.getElementById( "progressPrecentCompleted" ).innerHTML = top.GetProgressObject()
.GetPrecentageComplete()
.GetProgressObject()
.GetRemainsTimeWithUnit()
if ( !top.GetProgressObject().Initialized() )
document.getElementById( "progressBarCover" ).style.width = top.GetProgressObject()
.GetRaiseProgressBar();
top.GetProgressObject().Update();
Exent.SDM.Defines.Measurements.DownloadFinished );
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_DOWNLOAD_FINISHED;
top.DisableCloseControl();
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_INSTALLING;
Exent.SDM.Defines.Measurements.InstallStart );
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_DOWNLOADING;
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_CONNECTING;
top.ShowCloseControl();
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_INSALLATION_FINISHED;
top.PerformConversion( Exent.SDM.Defines.Measurements.PlayerInstallationCompleted );
if (Exent.SDM.Defines.RunOnStartUp) {
top.SetResumeParams( Exent.SDM.Defines.Button.Value.CancelWithResume );
else if (!Exent.SDM.Defines.DisableLaunch) {
top.GetExternalHandlerObject().LaunchPlayer( Exent.SDM.Defines.LaunchMinimized );
Exent.SDM.Defines.Measurements.InstallStop );
if (Exent.SDM.Defines.CloseBeforeComplete) {
g_StateDesc = Exent.SDM.Defines.DownloadState.Description.SDM_STATE_COMPLETED;
document.getElementById( "progressState" ).innerHTML = g_StateDesc
  top.GetConfigurationObject().GetGameName()
document.getElementById( "progressInfo" ).innerHTML = "Total: "
  top.GetProgressObject().GetTotalFileSize();
top.GetProgressObject().SetTotalFileSize( top.GetExternalHandlerObject().GetDownloadInfo() );
UpdateDownloadState( top.GetExternalHandlerObject().GetDownloadState() );
if ( top.GetControllerObject().GetConnectionStatus() == Exent.SDM.Defines.Status.Disconnected ) {
OnConnectionStatusChanged( Exent.SDM.Defines.Status.Disconnected );
if ( top.GetConfigurationObject().IsValid() ) {
// means that we didn't get it in the url param
if ( top.GetControllerObject().GetPageIdFromUrl() != Exent.SDM.Defines.PageId.ProgressPage ) {
Exent.SDM.Defines.Measurements.DownloadStart );
top.GetMeasurementsObject()
.AddParam(
Exent.SDM.Defines.UrlParameter.FileName,
top.GetConfigurationObject()
.BuildISUrlByAddons( top.g_AddOnsIndexArray ) );
else if ( top.GetControllerObject().GetPageIdFromUrl() == Exent.SDM.Defines.PageId.ProgressPage ) {
Exent.SDM.Defines.Measurements.DownloadContinued );
top.GetExternalHandlerObject()
.BeginDownload(
if ( ( g_StateValue == Exent.SDM.Defines.DownloadState.Value.SDM_STATE_INSTALLING )
|| ( g_StateValue == Exent.SDM.Defines.DownloadState.Value.SDM_STATE_COMPLETED ) ) {
GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_IS_PROCESS_ABNORMAL_TERMINATION_ERROR ) );
var ReturnedValue = Exent.SDM.Defines.Button.Value.Cancel;
top.SetResumeParams( ReturnedValue );
g_MsgBoxActive = false;
var strHttpErrors = getHttpErrors( strParams );
top.ShowDownloadingError( strErrId, strHttpErrors );
GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_IS_INSTALLATION_CANCELED_ERROR ) );
<div id="gamesInQueue" class="gamesInQueueText" onmouseover="top.ShowGamesInQueue( )"
onmouseout="top.HideGamesInQueue()">Games In Queue</div>
if ( document.getElementById('resumeAfterStartup').checked == true )
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.CancelWithResume;
window.location.href = Exent.SDM.Defines.UrlParameter.Close   Exent.SDM.Defines.Button.Value.Cancel;
var strErrId = PageUrlInfo.GetMsg();
var strTitle = GetPageTitle( strErrId ).replace(Exent.SDM.Defines.SDMStringsTokens.GameName,PageUrlInfo.GetGameName());
document.getElementById('title').innerHTML = AdjustPageTitle( strTitle );
document.getElementById('title').title = strTitle;
document.getElementById('innerText').innerHTML = GetStringValueById( strErrId ).replace( Exent.SDM.Defines.SDMStringsTokens.GameName, PageUrlInfo.GetGameName() );
document.getElementById("resumeOnStartupText").innerHTML = GetStringValueById("RESUME_ON_STARTUP_TEXT");
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onmouseup="this.style.filter='alpha(opacity=100)';" onmouseout="this.style.filter='alpha(opacity=100)';" onmousedown="this.style.filter='alpha(opacity=60)';" onclick="OnContinueDownload();" /></div>
<img src="res://resourceDll.dll/img/continuedownload_up.gif" class="continueDownloadButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnContinueDownload();" />
<img src="res://resourceDll.dll/img/quit_up.gif" class="quitButton" onmouseup="this.style.top='0px';this.style.left='0px';" onmouseout="this.style.top='0px';this.style.left='0px';" onmousedown="this.style.top='2px';this.style.left='2px';" onclick="OnQuit();" />
<link rel="stylesheet" type="text/css" href="res://resourceDll.dll/css/uac.css"/>
<script type="text/javascript" src="res://resourceDll.dll/js/conf_defines.js"></script>
<div class="XButton" ><img src="res://resourceDll.dll/img/close_up.gif" id="XButton" class="XButton" onMouseUp="this.style.filter='alpha(opacity=100)';" onMouseOut="this.style.filter='alpha(opacity=100)';" onMouseDown="this.style.filter='alpha(opacity=60)';" onClick="OnCancel();" /></div>
<img src="res://resourceDll.dll/img/retry_up.gif" id="retryButton" onMouseUp="this.style.top='0px';this.style.left='0px';" onMouseOut="this.style.top='0px';this.style.left='0px';" onMouseDown="this.style.top='2px';this.style.left='2px';" onClick="OnRetry()"/>
<a id="surveyURL" target="_blank"><span id="surveyText" class="innerText"></span></a>
01.00.00.52
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:848150218F6011DF955CE51E1F9BF56A" xmpMM:DocumentID="xmp.did:848150228F6011DF955CE51E1F9BF56A"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:8481501F8F6011DF955CE51E1F9BF56A" stRef:documentID="xmp.did:848150208F6011DF955CE51E1F9BF56A"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:8A9DF3FE8F6011DFA3E6D00DFB0FF15B" xmpMM:DocumentID="xmp.did:8A9DF3FF8F6011DFA3E6D00DFB0FF15B"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:8A9DF3FC8F6011DFA3E6D00DFB0FF15B" stRef:documentID="xmp.did:8A9DF3FD8F6011DFA3E6D00DFB0FF15B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:71A456C58F6011DF833CA8B6CB947AD8" xmpMM:DocumentID="xmp.did:71A456C68F6011DF833CA8B6CB947AD8"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:71A456C38F6011DF833CA8B6CB947AD8" stRef:documentID="xmp.did:71A456C48F6011DF833CA8B6CB947AD8"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:1A0EA1678F5F11DFBB19CFCE9C3AC6F6" xmpMM:DocumentID="xmp.did:1A0EA1688F5F11DFBB19CFCE9C3AC6F6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:1A0EA1658F5F11DFBB19CFCE9C3AC6F6" stRef:documentID="xmp.did:1A0EA1668F5F11DFBB19CFCE9C3AC6F6"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:FBAA76D08F5E11DFAC73EB7205BEE961" xmpMM:DocumentID="xmp.did:FBAA76D18F5E11DFAC73EB7205BEE961"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:FBAA76CE8F5E11DFAC73EB7205BEE961" stRef:documentID="xmp.did:FBAA76CF8F5E11DFAC73EB7205BEE961"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpMM:InstanceID="xmp.iid:507001618F5F11DFB066B7EA92ADFD84" xmpMM:DocumentID="xmp.did:507001628F5F11DFB066B7EA92ADFD84"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:5070015F8F5F11DFB066B7EA92ADFD84" stRef:documentID="xmp.did:507001608F5F11DFB066B7EA92ADFD84"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:8A0ACE1FE473E011B781D89D266F59E9" xmpMM:DocumentID="xmp.did:37C001F774BA11E091E1BB38D2F89F3B" xmpMM:InstanceID="xmp.iid:37C001F674BA11E091E1BB38D2F89F3B" xmp:CreatorTool="Adobe Photoshop CS5 Windows"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:98E728D4B974E011B781D89D266F59E9" stRef:documentID="xmp.did:8A0ACE1FE473E011B781D89D266F59E9"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
.miJO:
GIMP 2.6.5
2009:03:10 12:06:03
(7),01444
'9=82<.342
zE.cs
!hXXp://ns.adobe.com/xap/1.0/
<rdf:RDF xmlns:rdf='hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#'>
<rdf:Description xmlns:dc='hXXp://purl.org/dc/elements/1.1/'>
<rdf:Description xmlns:xmp='hXXp://ns.adobe.com/xap/1.0/'>
<xmp:CreatorTool>Adobe Photoshop CS2 Windows</xmp:CreatorTool>
<rdf:Description xmlns:xmpMM='hXXp://ns.adobe.com/xap/1.0/mm/'>
xmlns:stRef='hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#'>
<rdf:Description xmlns:tiff='hXXp://ns.adobe.com/tiff/1.0/'>
<rdf:Description xmlns:exif='hXXp://ns.adobe.com/exif/1.0/'>
<rdf:Description xmlns:photoshop='hXXp://ns.adobe.com/photoshop/1.0/'>
IEC hXXp://VVV.iec.ch
.IEC 61966-2.1 Default RGB colour space - sRGB
CRT curv
g_Configuration = new Exent.SDM.Configuration();
class Exent.SDM.Configuration
Description: this class store and parse the configurationXML passed by the SDM
Exent.SDM.Configuration = function( )
var m_strPromotionURL = "";
var m_strConversionURL = "";
var m_strReportURL = "";
var m_strISUrl = "";
var m_strISUrlsList = [];
var m_urlIndex = 0;
var m_strISFullUrl = "";
var m_strEULAUrl = "";
var m_strHeaderUrl = "";
var m_strImgUrl = "";
var m_strErrorReportUrl = "";
var m_strErrorReportFilter = "";
var m_strMyGamesUrl = "";
this.Init
this.IsValid
this.GetPromotionURL
= GetPromotionURL;
this.GetGameName
this.GetGameId
this.GetConversionURL
= GetConversionURL;
this.GetReportURL
= GetReportURL;
this.BuildISUrlByAddons
= BuildISUrlByAddons;
this.GetAddons
this.GetPartnerName
this.AddSelectedAddonsToURL
= AddSelectedAddonsToURL;
this.GetHeaderUrl
= GetHeaderUrl;
this.GetType
this.GetGameImgName
this.GetImgServerUrl
= GetImgServerUrl;
this.GetEULAUrl
= GetEULAUrl;
this.GetErrorReportUrl
= GetErrorReportUrl;
this.GetErrorReportFilter
= GetErrorReportFilter;
this.GetMyGamesUrl
= GetMyGamesUrl;
this.SwitchISUrl
= SwitchISUrl;
this.ResetISUrl
= ResetISUrl;
m_strPromotionURL = "";
m_strConversionURL = "";
m_strReportURL = "";
m_strISUrl = "";
m_strISUrlsList = [];
m_urlIndex = 0;
m_strISFullUrl = "";
m_strMyGamesUrl = "";
m_strConfigurationXML = top.GetExternalHandlerObject().GetConfigurationXML();
xmlDoc.async = false;
xmlDoc.loadXML( strConfigurationXML );
var node = xmlDoc.selectSingleNode( "ContentConfiguration/Game/Id" );
m_strGameId = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/Game/Name" );
m_strGameName = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/Game/SmallImgName" );
m_strGameImg = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/ImgServerUrl" );
m_strImgUrl = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/PromotionUrl" );
m_strPromotionURL = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/ConversionUrl" );
m_strConversionURL = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/ReportUrl" );
m_strReportURL = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/PartnerName" );
m_strPartnerName = node.text;
node = xmlDoc.selectNodes( "ContentConfiguration/IS/Url" );
m_strISUrlsList = node;
if (m_strISUrlsList.length > 0) {
m_strISUrl = m_strISUrlsList[0].text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/EULAUrl" );
m_strEULAUrl = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/HeaderUrl" );
m_strHeaderUrl = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/MyGamesUrl" );
m_strMyGamesUrl = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/Type" );
m_strType = node.text;
node = xmlDoc.selectSingleNode( "ContentConfiguration/ErrorReport/Url" );
m_strErrorReportUrl = node.text;
m_strErrorReportUrl = "";
node = xmlDoc.selectSingleNode( "ContentConfiguration/ErrorReport/ErrorReportFilter" );
m_strErrorReportFilter = node.text;
m_strErrorReportFilter = "";
node = xmlDoc.selectSingleNode( "ContentConfiguration/IS/AddOns" );
var paramNodes = xmlDoc.selectNodes( "ContentConfiguration/IS/AddOns/Param" );
for ( i=0 ; i < paramNodes.length; i  )
var childNodes = paramNodes[i].childNodes;
for ( j=0 ; j < childNodes.length; j   )
if ( childNodes[j].nodeName == "ID" )
paramID = childNodes[j].text;
if ( childNodes[j].nodeName == "Priority" )
paramPriority = childNodes[j].text;
OverrideAddonsFromUrl();
// check if we pass in the url the addons param and get the list of addons
function OverrideAddonsFromUrl()
var AddonsList = GetControllerObject().GetAddonsFromUrl();
var AddonsArray = AddonsList.split(",");
for ( var i = 0 ; i < AddonsArray.length ; i  )
for ( var j = 0 ; j < m_arrayAddOns.length ; j   )
if ( m_arrayAddOns[j].strAddOnID == AddonsArray[i] )
m_arrayAddOns[j].isSelected = true;
function SwitchISUrl() {
m_urlIndex  ;
if (m_urlIndex < m_strISUrlsList.length) {
m_strISUrl = m_strISUrlsList[m_urlIndex].text;
return m_strISUrl;
function ResetISUrl () {
function GetPromotionURL()
return m_strPromotionURL;
function GetConversionURL()
return m_strConversionURL ;
function GetReportURL()
return m_strReportURL;
function GetEULAUrl()
return m_strEULAUrl;
function GetImgServerUrl()
return m_strImgUrl;
function GetHeaderUrl()
return m_strHeaderUrl;
function GetErrorReportUrl()
if ( m_strErrorReportUrl ) {
return m_strErrorReportUrl;
function GetErrorReportFilter()
if ( m_strErrorReportFilter ) {
return m_strErrorReportFilter;
function GetMyGamesUrl() {
return m_strMyGamesUrl;
Configuration::BuildISUrlByAddons()
Description: Build the is url according to the addos selected by the user
function BuildISUrlByAddons( )
if ( m_strISFullUrl != "" )
return m_strISFullUrl;
//m_strISFullUrl = m_strISUrl.replace(".exe" , "_"   m_strPartnerName );
var iLastIndex = m_strISUrl.lastIndexOf( ".exe" );
m_strISFullUrl = m_strISUrl.substr( 0, iLastIndex );
m_strISFullUrl  = "_"   m_strPartnerName;
for ( var i=0 ; i < m_arrayAddOns.length ; i   )
if ( m_arrayAddOns[i].isSelected == true )
m_strISFullUrl = m_strISFullUrl   "_"   m_arrayAddOns[i].strAddOnID;
// add .exe in the end
m_strISFullUrl = m_strISFullUrl   ".exe";
Configuration::GetSelectedAddonsURLParam()
input param - page url info object to set the addons property if needed
Description: set the AddOns property of the pageUrl info if addons selected
function AddSelectedAddonsToURL( pageURLInfo )
selectedAddons = m_arrayAddOns[i].strAddOnID;
pageURLInfo.SetAddons( selectedAddons );
Exent.SDM.Defines.Config =
// URL for checking internet connection
CheckConnectionURL
: "hXXp://cdn.exent.com/FRG_site/check.html",
// URL for checking service connection
CheckServiceConnectionURL
: "hXXp://VVV.freeridegames.com/check.jsp",
// do we allow users of Windows 64 bit to install the player?
SupportsWin64 : true
function CheckConnection( strUrl, connectionId, exParam )
var xmlhttp = new ActiveXObject("Microsoft.XMLHTTP");
xmlhttp.open( "HEAD", strUrl, true );
xmlhttp.onreadystatechange = function( )
if (xmlhttp.readyState == 4)
if (xmlhttp.status==200)
case Exent.SDM.Defines.ConnectionId.Internet:
case Exent.SDM.Defines.ConnectionId.Service:
case Exent.SDM.Defines.ConnectionId.Other:
xmlhttp.send( null );
g_Controller = new Exent.SDM.Controller();
class Exent.SDM.Controller
Exent.SDM.Controller = function()
var m_PageUrlInfo;
var m_PageIdFromUrl;
this.Load = Load;
this.LoadFirstPage
this.GoToErrorPage
this.Navigate
this.SetBody
this.SetPageTitle
this.OnConnectionStatusChanged
this.GetConnectionStatus
this.GetPageId
this.SDMInitializedSuccess
this.GetPageIdFromUrl
= GetPageIdFromUrl;
this.SetLastErrorCode
this.GetLastErrorCode
this.GetAddonsFromUrl
= GetAddonsFromUrl;
if(!m_PageUrlInfo)
InitPageUrlInfo();
Controller::InitPageUrlInfo
function InitPageUrlInfo()
m_PageUrlInfo = new Exent.SDM.PageUrlInfo();
m_PageUrlInfo.LoadFromPageUrl();
m_PageId = m_PageUrlInfo.GetPageId();
// save the original page id that was pass in the url
m_PageIdFromUrl = m_PageId;
m_PageId = Exent.SDM.Defines.PageId.InitPage;
GetPageLogic().OnConnectionStatusChanged( m_ConnectionStatus );
alert("exception OnConnectionStatusChanged="   e.description );
case Exent.SDM.Defines.PageId.InitPage:
Navigate( Exent.SDM.Defines.PageId.FirstPage );
case Exent.SDM.Defines.PageId.EULAPage:
case Exent.SDM.Defines.PageId.ProgressPage:
case Exent.SDM.Defines.PageId.EndingPage:
document.getElementById('Header').src = Exent.SDM.Defines.HTMLS.OfflineHeader;
document.getElementById('Header').src = GetConfigurationObject().GetHeaderUrl();
var promoURL;
document.getElementById('PageBody').height = 278; // restore original size
document.getElementById('PageBody').height = 238; // need more pixels for addons
promoURL = GetPromotionURL( );
document.getElementById('PageBody').src = promoURL;
document.getElementById('PageBody').height = 308; // don't change height without also changing it in SDM_PROGRESS.html
document.getElementById('PageBody').src = Exent.SDM.Defines.HTMLS.Initialized;
document.getElementById('PageFooter').height = 90;// restore original size
document.getElementById('PageFooter').height = 160;
html = Exent.SDM.Defines.HTMLS.EULAFooter;
html = Exent.SDM.Defines.HTMLS.ProgressFooter;
document.getElementById('PageFooter').height = 130;
html = Exent.SDM.Defines.HTMLS.EndingFooter;
html = Exent.SDM.Defines.HTMLS.EmptyFooter;
document.getElementById('PageFooter').src = html;
document.getElementById('title').innerHTML = strTitle;
GetExternalHandlerObject().SetTitle( strTitle );
function GetPromotionURL( )
Description: return a specific promotion URL according to page ID, this function check connection for the URL
return value - the promotion URL
return GetConnectionLostURL( );
return GetServiceDownPromotionURL( );
var promoUrl = GetConfigurationObject().GetPromotionURL();
promoUrl = promoUrl   "/"   m_PageId   ".html";
var url = new Exent.SDM.PageUrlInfo();
url.SetBaseUrl( promoUrl );
url.SetGameName( GetConfigurationObject().GetGameName() );
url.SetGameId( GetConfigurationObject().GetGameId() );
url.SetErrorCode ( m_LastErrorCode );
return url.ToURLString();
return Exent.SDM.Defines.HTMLS.Initialized;
function GetServiceDownPromotionURL( )
Description: return local promotion URL when service is down
pageID - the pageID for which we want to retrieve the promotion URL
return value - the promotion URL
return Exent.SDM.Defines.ServiceDownPromo.EULA;
case Exent.SDM.Defines.PageId.ProgressPage:
return Exent.SDM.Defines.ServiceDownPromo.PROGRESS;
return Exent.SDM.Defines.ServiceDownPromo.ENDING;
function GetConnectionLostURL( )
Description: return local promotion URL when no connection
return Exent.SDM.Defines.NoConnectionPromo.EULA;
return Exent.SDM.Defines.NoConnectionPromo.PROGRESS;
return Exent.SDM.Defines.NoConnectionPromo.ENDING;
function GetAddonsFromUrl()
if(!m_PageUrlInfo)
InitPageUrlInfo();
return m_PageUrlInfo.GetAddons();
// this function return the pageID that was pass by the registry entry if at all
function GetPageIdFromUrl()
return m_PageIdFromUrl;
m_ConnectionStatus = Exent.SDM.Defines.Status.Init;
Controller.Load();
1996-2008 Exent Technologies Ltd. All Rights Reserved.
Exent.SDM = function()
Exent.SDM.Defines = function()
Exent.SDM.Defines.Button = function()
Exent.SDM.Defines.Version = "01.51.00.52";
Exent.SDM.Defines.CloseBeforeComplete = false;
Exent.SDM.Defines.RunOnStartUp = false;
Exent.SDM.Defines.LaunchMinimized = false;
Exent.SDM.Defines.DisableLaunch = false;
Exent.SDM.Defines.SDMStringsTokens =
: "%State%",
Exent.SDM.Defines.Measurements =
// Url parameters.
Exent.SDM.Defines.UrlParameter =
"Msg",
"aod://127.0.0.1/aod.html?OnClose=Close&Info=",
Exent.SDM.Defines.PageId =
Exent.SDM.Defines.ConnectionId =
Exent.SDM.Defines.HTMLS =
: "index.html" ,
: "connectionlost_msg.html",
: "error_msg.html",
: "gameaddedtoqueue_msg.html",
: "gamealreadyinqueue_msg.html",
: "ocxlocked_msg.html",
: "initializedfailed.html",
: "downloadfailed.html",
: "UACCanceled.html",
: "res://resourceDll.dll/html/EULAFooter.html",
: "eulaquit_msg.html",
: "res://resourceDll.dll/html/progressFooter.html",
: "progressquit_msg.html",
: "res://resourceDll.dll/html/endingFooter.html",
: "res://resourceDll.dll/html/pageBodyOffline.html",
: "res://resourceDll.dll/html/offlineheader.html",
: "res://resourceDll.dll/html/initialized.html",
: "res://resourceDll.dll/html/emptyFooter.html",
SurveyURL : "hXXp://cdn.exent.com/FRG_site/data/SDM/Error-Survey.html"
Exent.SDM.Defines.ServiceDownPromo =
: Exent.SDM.Defines.HTMLS.OfflineBody   Exent.SDM.Defines.UrlParameter.FirstParamSeparator   Exent.SDM.Defines.UrlParameter.PageId   Exent.SDM.Defines.UrlParameter.SplitSeparator   Exent.SDM.Defines.PageId.ServiceDown,
: Exent.SDM.Defines.HTMLS.OfflineBody   Exent.SDM.Defines.UrlParameter.FirstParamSeparator   Exent.SDM.Defines.UrlParameter.PageId   Exent.SDM.Defines.UrlParameter.SplitSeparator   Exent.SDM.Defines.PageId.ServiceDown
Exent.SDM.Defines.NoConnectionPromo =
: Exent.SDM.Defines.HTMLS.OfflineBody   Exent.SDM.Defines.UrlParameter.FirstParamSeparator   Exent.SDM.Defines.UrlParameter.PageId   Exent.SDM.Defines.UrlParameter.SplitSeparator   Exent.SDM.Defines.PageId.ConnectionLost,
: Exent.SDM.Defines.HTMLS.OfflineBody   Exent.SDM.Defines.UrlParameter.FirstParamSeparator   Exent.SDM.Defines.UrlParameter.PageId   Exent.SDM.Defines.UrlParameter.SplitSeparator   Exent.SDM.Defines.PageId.ConnectionLost
Exent.SDM.Defines.Status =
Exent.SDM.Defines.DownloadState = function()
Exent.SDM.Defines.DownloadState.Value =
Exent.SDM.Defines.DownloadState.Description =
Exent.SDM.Defines.ErrorID =
SDM_OS_NOT_SUPPORTED
"SDM_OS_NOT_SUPPORTED",
SDM_IS_EXECUTION_FAILED
"SDM_IS_EXECUTION_FAILED",
Exent.SDM.Defines.Button.Value =
Exent.SDM.Defines.Addons =
Exent.SDM.Defines.Types =
// XML doc that reads SDMStrings.XML
var g_MsgBoxActive = false;
g_ExternalHandler = new Exent.SDM.ExternalHandler();
class Exent.SDM.ExternalHandler
Exent.SDM.ExternalHandler = function()
this.Init = Init;
this.BeginDownload
this.SendRequest
this.CloseSDM
this.MinimizeSDM
this.LaunchPlayer
this.OpenWebDialog
= OpenWebDialog;
this.CancelInstallation
this.ResumeInstallation
this.RetryDownload
this.ISProcessAction
this.ReInitSDM
this.SendErrorAndLogFile
this.GetGamesQueue
this.GetConfigurationXML
this.GetDownloadInfo
this.GetDownloadState
this.GetProgress
this.GetInitializationStatus
this.GetStringsXml
this.GetOSType
this.GetMuid
this.GetShellPathByBrowserType
this.GetAllProcessList
this.SetResumeParams
this.SetTitle
function BeginDownload( url )
return external.SDM_BeginDownload( url );
function SendRequest(strMethod, strFullUrl, bAsync)
return external.SDM_SendRequest(strMethod, strFullUrl, bAsync);
return external.SDM_CloseSDM();
return external.SDM_MinimizeSDM();
return external.SDM_LaunchPlayer( bMinimize );
function SendErrorAndLogFile( strFullUrl )
return external.SDM_SendErrorAndLogFile( strFullUrl );
function OpenWebDialog(strUrl, bAddFileFullPath, strTitle, strTarget, bHiddenWnd, bTopMostWnd, bModalDialog,dwWidth, dwHeight, dwWndStylesToAdd, dwWndStylesToRemove, dwNavigationOptions)
return external.SDM_OpenWebDialog( strUrl, bAddFileFullPath, strTitle, strTarget, bHiddenWnd, bTopMostWnd, bModalDialog, dwWidth, dwHeight, dwWndStylesToAdd, dwWndStylesToRemove, dwNavigationOptions );
external.SDM_CancelInstallation();
return external.SDM_ResumeInstallation();
return external.SDM_RetryDownload();
return external.SDM_ReInitSDM();
return external.SDM_ISProcessAction( strActionId) ;
return external.SDM_GetGamesQueue();
return external.SDM_GetConfigurationXML();
return external.SDM_GetDownloadInfo();
return external.SDM_GetDownloadState();
return external.SDM_GetInitializationStatus() ;
return external.SDM_GetProgress();
return external.SDM_GetPrecentageComplete();
return external.SDM_GetStringsXml();
function SetResumeParams(bResume, strResumeURL)
return external.SDM_SetResumeParams(bResume, strResumeURL);
return external.SDM_SetTitle( strTitle );
return external.SDM_GetOSBitType( );
return external.SDM_GetMuidFixed( );
return external.SDM_GetMuidRand( );
return external.SDM_GetShellPathByBrowserType(browserType);
return external.SDM_GetAllProcessList();
return PageFooter.window;
function ConvertWebDialogReturnValue( buttonValue )
buttonValue - the return value from the openWebDialog
function ConvertWebDialogReturnValue ( buttonValue )
case Exent.SDM.Defines.Button.Value.Cancel:
case Exent.SDM.Defines.Button.Value.CancelWithResume:
return Exent.SDM.Defines.Button.Value.Cancel;
Description: called by the controls.html when user click the close button
GetPageLogic().OnClose();
Description: called by the controls.html when user click the minimize button
GetExternalHandlerObject().MinimizeSDM();
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.Event, Exent.SDM.Defines.Measurements.TotalProcessFinished );
top.GetMeasurementsObject().AddParam( Exent.SDM.Defines.UrlParameter.SDMVersion, Exent.SDM.Defines.Version );
top.GetMeasurementsObject().Send( );
GetExternalHandlerObject().CloseSDM();
document.getElementById('enabledXButton').style.display = "none";
document.getElementById('disabledXButton').style.display = "block";
document.getElementById('enabledXButton').style.display = "block";
document.getElementById('disabledXButton').style.display = "none";
var pageURLInfo = new Exent.SDM.PageUrlInfo();
pageURLInfo.SetBaseUrl( Exent.SDM.Defines.HTMLS.ResumePagePrefix );
pageURLInfo.SetPageId(GetControllerObject().GetPageId());
GetConfigurationObject().AddSelectedAddonsToURL( pageURLInfo );
GetExternalHandlerObject().SetResumeParams( false , pageURLInfo.ToResURLString() );
GetExternalHandlerObject().SetResumeParams( true , pageURLInfo.ToResURLString() );
if ( g_MsgBoxActive == true )
g_MsgBoxActive = true;
var showChatButton = isChatEnalbed( Exent.SDM.Defines.ErrorID.SDM_CONNECTION_LOST_MESSAGE );
url.SetBaseUrl( Exent.SDM.Defines.HTMLS.ConnectionLost );
url.SetMsg( Exent.SDM.Defines.ErrorID.SDM_CONNECTION_LOST_MESSAGE );
url.SetParam1( showChatButton );
url.SetType( GetConfigurationObject().GetType() );
var ReturnedValue = GetExternalHandlerObject().OpenWebDialog( url.ToResURLString( ) , true, "", "SDMMsg", false, false, true, 416, height, 0x00000000, 0x00c80181, 1 );
return ConvertWebDialogReturnValue( ReturnedValue );
GetControllerObject().SetPageTitle( strTitle );
GetMeasurementsObject().SendError( GetStringCodeById(strErrId) , strParams );
GetPageLogic().HandleError( strErrId );
url.SetBaseUrl( Exent.SDM.Defines.HTMLS.Error );
url.SetMsg( strErrId );
var ReturnedValue = GetExternalHandlerObject().OpenWebDialog( url.ToResURLString( ), true, "", "SDMMsg", false, false, true, 416, height, 0x00000000, 0x00c80181, 1 );
GetPageLogic().HandleFatalError( strErrId , strParams );
HandleError ( Exent.SDM.Defines.ErrorID.SDM_INVALID_PROVIDER_ERROR );
if (top.GetControllerObject().GetLastErrorCode() != Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_FILE_LOCKED_ERROR)
GetMeasurementsObject().SendError( GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_FILE_LOCKED_ERROR ) );
top.GetControllerObject().SetLastErrorCode( GetStringCodeById(Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_FILE_LOCKED_ERROR) );
GetExternalHandlerObject().ISProcessAction( "1" );
if ( !GetConfigurationObject().IsValid() )
return HandleInitializedFailed( Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_ERROR );
GetControllerObject().SDMInitializedSuccess( );
GetMeasurementsObject().SendError( GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_ERROR ) );
var errorCode = GetStringCodeById( Exent.SDM.Defines.ErrorID.SDM_IS_COMPLETED_WITHOUT_NOTIFICATION_ERROR );
top.GetMeasurementsObject().SendError( errorCode );
var nextUrl = top.GetConfigurationObject().SwitchISUrl();
if (nextUrl) {
var url = top.GetConfigurationObject().BuildISUrlByAddons();
top.GetExternalHandlerObject().BeginDownload(url);
GetPageLogic().HandleDownloadingError( strErrId, strParams );
GetPageLogic().HandleAbnormalTerminationError( strErrId, strParams );
GetMeasurementsObject().SendError( errorCode, strParams );
var muid = top.GetExternalHandlerObject().GetMuid( true);
var conversionURL = GetConfigurationObject().GetConversionURL()   "?"
  Exent.SDM.Defines.UrlParameter.ConversionName
  Exent.SDM.Defines.UrlParameter.SplitSeparator   strConversionName
  Exent.SDM.Defines.UrlParameter.ParamSeparator
  Exent.SDM.Defines.UrlParameter.Format   Exent.SDM.Defines.UrlParameter.SplitSeparator   Exent.SDM.Defines.UrlParameter.FullHtml
  Exent.SDM.Defines.UrlParameter.MUID   Exent.SDM.Defines.UrlParameter.SplitSeparator   muid;
GetExternalHandlerObject().OpenWebDialog( conversionURL , false, "", strConversionName, true, false, false, 0, 0, 0x00000000, 0x00000000, 1);
GetPageLogic().HandleUACCanceled( );
function CheckIfUACSupportedOS()
return ( -1 != navigator.userAgent.indexOf("Windows NT 6.") ); // are we
// (6.0)?
// windows 7
// (6.1)?
GetMeasurementsObject().SendError( GetStringCodeById(strErrId) );
GetPageLogic().HandleFatalError( strErrId );
var res = errorCodeString.match(errorFilter);
if ( !GetConfigurationObject().IsValid() )
if ( g_GamesInQueueArray.length > 0 )
var strGamesInQueue = GetExternalHandlerObject().GetGamesQueue();
xmlDoc.async = false;
xmlDoc.loadXML( strGamesInQueue );
var gameItems = xmlDoc.selectNodes("SDM_Configurations/ContentConfiguration");
for( var i=0; i < gameItems.length ; i   )
var obj = new Exent.SDM.Configuration();
obj.Init(gameItems[i].xml);
AddOneGameToQueue( obj.GetGameId(), obj.GetGameName() );
innerHTML = innerHTML   "<div class='bubbleGameImageHolder'><img src='"   top.GetGameImgURL( gameID )   "' style='width:100%;height:100%;'></div>";
document.getElementById('bubbleMiddle').innerHTML = document.getElementById('bubbleMiddle').innerHTML   innerHTML;
if ( g_GamesInQueueArray.length == 0 )
var obj = document.getElementById('mainBubbleHolder');
obj.style.display = "block";
document.getElementById('mainBubbleHolder').style.display = "none";
Description: handle the "game was added to queue" event - triggered by the SDM HTML_UpdateGUI with errorID = Exent.SDM.Defines.Errors.GameAddedToQueue
var configObj = new Exent.SDM.Configuration();
configObj.Init( strConfigurationXML );
g_GamesInQueueArray[g_GamesInQueueArray.length] = configObj;
AddOneGameToQueue( configObj.GetGameId(), configObj.GetGameName() );
var ReturnedValue = Exent.SDM.Defines.Button.Value.OK;
/*! jQuery v1.7.2 jquery.com | jquery.org/license */
(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cu(a){if(!cj[a]){var b=c.body,d=f("<" a ">").appendTo(b),e=d.css("display");d.remove();if(e==="none"||e===""){ck||(ck=c.createElement("iframe"),ck.frameBorder=ck.width=ck.height=0),b.appendChild(ck);if(!cl||!ck.createElement)cl=(ck.contentWindow||ck.contentDocument).document,cl.write((f.support.boxModel?"<!doctype html>":"") "<html><body>"),cl.close();d=cl.createElement(a),cl.body.appendChild(d),e=f.css(d,"display"),b.removeChild(ck)}cj[a]=e}return cj[a]}function ct(a,b){var c={};f.each(cp.concat.apply([],cp.slice(0,b)),function(){c[this]=a});return c}function cs(){cq=b}function cr(){setTimeout(cs,0);return cq=f.now()}function ci(){try{return new a.ActiveXObject("Microsoft.XMLHTTP")}catch(b){}}function ch(){try{return new a.XMLHttpRequest}catch(b){}}function cb(a,c){a.dataFilter&&(c=a.dataFilter(c,a.dataType));var d=a.dataTypes,e={},g,h,i=d.length,j,k=d[0],l,m,n,o,p;for(g=1;g<i;g  ){if(g===1)for(h in a.converters)typeof h=="string"&&(e[h.toLowerCase()]=a.converters[h]);l=k,k=d[g];if(k==="*")k=l;else if(l!=="*"&&l!==k){m=l " " k,n=e[m]||e["* " k];if(!n){p=b;for(o in e){j=o.split(" ");if(j[0]===l||j[0]==="*"){p=e[j[1] " " k];if(p){o=e[o],o===!0?n=p:p===!0&&(n=o);break}}}}!n&&!p&&f.error("No conversion from " m.replace(" "," to ")),n!==!0&&(c=n?n(c):p(o(c)))}}return c}function ca(a,c,d){var e=a.contents,f=a.dataTypes,g=a.responseFields,h,i,j,k;for(i in g)i in d&&(c[g[i]]=d[i]);while(f[0]==="*")f.shift(),h===b&&(h=a.mimeType||c.getResponseHeader("content-type"));if(h)for(i in e)if(e[i]&&e[i].test(h)){f.unshift(i);break}if(f[0]in d)j=f[0];else{for(i in d){if(!f[0]||a.converters[i " " f[0]]){j=i;break}k||(k=i)}j=j||k}if(j){j!==f[0]&&f.unshift(j);return d[j]}}function b_(a,b,c,d){if(f.isArray(b))f.each(b,function(b,e){c||bD.test(a)?d(a,e):b_(a "[" (typeof e=="object"?b:"") "]",e,c,d)});else if(!c&&f.type(b)==="object")for(var e in b)b_(a "[" e "]",b[e],c,d);else d(a,b)}function b$(a,c){var d,e,g=f.ajaxSettings.flatOptions||{};for(d in c)c[d]!==b&&((g[d]?a:e||(e={}))[d]=c[d]);e&&f.extend(!0,a,e)}function bZ(a,c,d,e,f,g){f=f||c.dataTypes[0],g=g||{},g[f]=!0;var h=a[f],i=0,j=h?h.length:0,k=a===bS,l;for(;i<j&&(k||!l);i  )l=h[i](c,d,e),typeof l=="string"&&(!k||g[l]?l=b:(c.dataTypes.unshift(l),l=bZ(a,c,d,e,l,g)));(k||!l)&&!g["*"]&&(l=bZ(a,c,d,e,"*",g));return l}function bY(a){return function(b,c){typeof b!="string"&&(c=b,b="*");if(f.isFunction(c)){var d=b.toLowerCase().split(bO),e=0,g=d.length,h,i,j;for(;e<g;e  )h=d[e],j=/^\ /.test(h),j&&(h=h.substr(1)||"*"),i=a[h]=a[h]||[],i[j?"unshift":"push"](c)}}}function bB(a,b,c){var d=b==="width"?a.offsetWidth:a.offsetHeight,e=b==="width"?1:0,g=4;if(d>0){if(c!=="border")for(;e<g;e =2)c||(d-=parseFloat(f.css(a,"padding" bx[e]))||0),c==="margin"?d =parseFloat(f.css(a,c bx[e]))||0:d-=parseFloat(f.css(a,"border" bx[e] "Width"))||0;return d "px"}d=by(a,b);if(d<0||d==null)d=a.style[b];if(bt.test(d))return d;d=parseFloat(d)||0;if(c)for(;e<g;e =2)d =parseFloat(f.css(a,"padding" bx[e]))||0,c!=="padding"&&(d =parseFloat(f.css(a,"border" bx[e] "Width"))||0),c==="margin"&&(d =parseFloat(f.css(a,c bx[e]))||0);return d "px"}function bo(a){var b=c.createElement("div");bh.appendChild(b),b.innerHTML=a.outerHTML;return b.firstChild}function bn(a){var b=(a.nodeName||"").toLowerCase();b==="input"?bm(a):b!=="script"&&typeof a.getElementsByTagName!="undefined"&&f.grep(a.getElementsByTagName("input"),bm)}function bm(a){if(a.type==="checkbox"||a.type==="radio")a.defaultChecked=a.checked}function bl(a){return typeof a.getElementsByTagName!="undefined"?a.getElementsByTagName("*"):typeof a.querySelectorAll!="undefined"?a.querySelectorAll("*"):[]}function bk(a,b){var c;b.nodeType===1&&(b.clearAttributes&&b.clearAttributes(),b.mergeAttributes&&b.mergeAttributes(a),c=b.nodeName.toLowerCase(),c==="object"?b.outerHTML=a.outerHTML:c!=="input"||a.type!=="checkbox"&&a.type!=="radio"?c==="option"?b.selected=a.defaultSelected:c==="input"||c==="textarea"?b.defaultValue=a.defaultValue:c==="script"&&b.text!==a.text&&(b.text=a.text):(a.checked&&(b.defaultChecked=b.checked=a.checked),b.value!==a.value&&(b.value=a.value)),b.removeAttribute(f.expando),b.removeAttribute("_submit_attached"),b.removeAttribute("_change_attached"))}function bj(a,b){if(b.nodeType===1&&!!f.hasData(a)){var c,d,e,g=f._data(a),h=f._data(b,g),i=g.events;if(i){delete h.handle,h.events={};for(c in i)for(d=0,e=i[c].length;d<e;d  )f.event.add(b,c,i[c][d])}h.data&&(h.data=f.extend({},h.data))}}function bi(a,b){return f.nodeName(a,"table")?a.getElementsByTagName("tbody")[0]||a.appendChild(a.ownerDocument.createElement("tbody")):a}function U(a){var b=V.split("|"),c=a.createDocumentFragment();if(c.createElement)while(b.length)c.createElement(b.pop());return c}function T(a,b,c){b=b||0;if(f.isFunction(b))return f.grep(a,function(a,d){var e=!!b.call(a,d,a);return e===c});if(b.nodeType)return f.grep(a,function(a,d){return a===b===c});if(typeof b=="string"){var d=f.grep(a,function(a){return a.nodeType===1});if(O.test(b))return f.filter(b,d,!c);b=f.filter(b,d)}return f.grep(a,function(a,d){return f.inArray(a,b)>=0===c})}function S(a){return!a||!a.parentNode||a.parentNode.nodeType===11}function K(){return!0}function J(){return!1}function n(a,b,c){var d=b "defer",e=b "queue",g=b "mark",h=f._data(a,d);h&&(c==="queue"||!f._data(a,e))&&(c==="mark"||!f._data(a,g))&&setTimeout(function(){!f._data(a,e)&&!f._data(a,g)&&(f.removeData(a,d,!0),h.fire())},0)}function m(a){for(var b in a){if(b==="data"&&f.isEmptyObject(a[b]))continue;if(b!=="toJSON")return!1}return!0}function l(a,c,d){if(d===b&&a.nodeType===1){var e="data-" c.replace(k,"-$1").toLowerCase();d=a.getAttribute(e);if(typeof d=="string"){try{d=d==="true"?!0:d==="false"?!1:d==="null"?null:f.isNumeric(d)? d:j.test(d)?f.parseJSON(d):d}catch(g){}f.data(a,c,d)}else d=b}return d}function h(a){var b=g[a]={},c,d;a=a.split(/\s /);for(c=0,d=a.length;c<d;c  )b[a[c]]=!0;return b}var c=a.document,d=a.navigator,e=a.location,f=function(){function J(){if(!e.isReady){try{c.documentElement.doScroll("left")}catch(a){setTimeout(J,1);return}e.ready()}}var e=function(a,b){return new e.fn.init(a,b,h)},f=a.jQuery,g=a.$,h,i=/^(?:[^#<]*(<[\w\W] >)[^>]*$|#([\w\-]*)$)/,j=/\S/,k=/^\s /,l=/\s $/,m=/^<(\w )\s*\/?>(?:<\/\1>)?$/,n=/^[\],:{}\s]*$/,o=/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g,p=/"[^"\\\n\r]*"|true|false|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,q=/(?:^|:|,)(?:\s*\[) /g,r=/(webkit)[ \/]([\w.] )/,s=/(opera)(?:.*version)?[ \/]([\w.] )/,t=/(msie) ([\w.] )/,u=/(mozilla)(?:.*? rv:([\w.] ))?/,v=/-([a-z]|[0-9])/ig,w=/^-ms-/,x=function(a,b){return(b "").toUpperCase()},y=d.userAgent,z,A,B,C=Object.prototype.toString,D=Object.prototype.hasOwnProperty,E=Array.prototype.push,F=Array.prototype.slice,G=String.prototype.trim,H=Array.prototype.indexOf,I={};e.fn=e.prototype={constructor:e,init:function(a,d,f){var g,h,j,k;if(!a)return this;if(a.nodeType){this.context=this[0]=a,this.length=1;return this}if(a==="body"&&!d&&c.body){this.context=c,this[0]=c.body,this.selector=a,this.length=1;return this}if(typeof a=="string"){a.charAt(0)!=="<"||a.charAt(a.length-1)!==">"||a.length<3?g=i.exec(a):g=[null,a,null];if(g&&(g[1]||!d)){if(g[1]){d=d instanceof e?d[0]:d,k=d?d.ownerDocument||d:c,j=m.exec(a),j?e.isPlainObject(d)?(a=[c.createElement(j[1])],e.fn.attr.call(a,d,!0)):a=[k.createElement(j[1])]:(j=e.buildFragment([g[1]],[k]),a=(j.cacheable?e.clone(j.fragment):j.fragment).childNodes);return e.merge(this,a)}h=c.getElementById(g[2]);if(h&&h.parentNode){if(h.id!==g[2])return f.find(a);this.length=1,this[0]=h}this.context=c,this.selector=a;return this}return!d||d.jquery?(d||f).find(a):this.constructor(d).find(a)}if(e.isFunction(a))return f.ready(a);a.selector!==b&&(this.selector=a.selector,this.context=a.context);return e.makeArray(a,this)},selector:"",jquery:"1.7.2",length:0,size:function(){return this.length},toArray:function(){return F.call(this,0)},get:function(a){return a==null?this.toArray():a<0?this[this.length a]:this[a]},pushStack:function(a,b,c){var d=this.constructor();e.isArray(a)?E.apply(d,a):e.merge(d,a),d.prevObject=this,d.context=this.context,b==="find"?d.selector=this.selector (this.selector?" ":"") c:b&&(d.selector=this.selector "." b "(" c ")");return d},each:function(a,b){return e.each(this,a,b)},ready:function(a){e.bindReady(),A.add(a);return this},eq:function(a){a= a;return a===-1?this.slice(a):this.slice(a,a 1)},first:function(){return this.eq(0)},last:function(){return this.eq(-1)},slice:function(){return this.pushStack(F.apply(this,arguments),"slice",F.call(arguments).join(","))},map:function(a){return this.pushStack(e.map(this,function(b,c){return a.call(b,c,b)}))},end:function(){return this.prevObject||this.constructor(null)},push:E,sort:[].sort,splice:[].splice},e.fn.init.prototype=e.fn,e.extend=e.fn.extend=function(){var a,c,d,f,g,h,i=arguments[0]||{},j=1,k=arguments.length,l=!1;typeof i=="boolean"&&(l=i,i=arguments[1]||{},j=2),typeof i!="object"&&!e.isFunction(i)&&(i={}),k===j&&(i=this,--j);for(;j<k;j  )if((a=arguments[j])!=null)for(c in a){d=i[c],f=a[c];if(i===f)continue;l&&f&&(e.isPlainObject(f)||(g=e.isArray(f)))?(g?(g=!1,h=d&&e.isArray(d)?d:[]):h=d&&e.isPlainObject(d)?d:{},i[c]=e.extend(l,h,f)):f!==b&&(i[c]=f)}return i},e.extend({noConflict:function(b){a.$===e&&(a.$=g),b&&a.jQuery===e&&(a.jQuery=f);return e},isReady:!1,readyWait:1,holdReady:function(a){a?e.readyWait  :e.ready(!0)},ready:function(a){if(a===!0&&!--e.readyWait||a!==!0&&!e.isReady){if(!c.body)return setTimeout(e.ready,1);e.isReady=!0;if(a!==!0&&--e.readyWait>0)return;A.fireWith(c,[e]),e.fn.trigger&&e(c).trigger("ready").off("ready")}},bindReady:function(){if(!A){A=e.Callbacks("once memory");if(c.readyState==="complete")return setTimeout(e.ready,1);if(c.addEventListener)c.addEventListener("DOMContentLoaded",B,!1),a.addEventListener("load",e.ready,!1);else if(c.attachEvent){c.attachEvent("onreadystatechange",B),a.attachEvent("onload",e.ready);var b=!1;try{b=a.frameElement==null}catch(d){}c.documentElement.doScroll&&b&&J()}}},isFunction:function(a){return e.type(a)==="function"},isArray:Array.isArray||function(a){return e.type(a)==="array"},isWindow:function(a){return a!=null&&a==a.window},isNumeric:function(a){return!isNaN(parseFloat(a))&&isFinite(a)},type:function(a){return a==null?String(a):I[C.call(a)]||"object"},isPlainObject:function(a){if(!a||e.type(a)!=="object"||a.nodeType||e.isWindow(a))return!1;try{if(a.constructor&&!D.call(a,"constructor")&&!D.call(a.constructor.prototype,"isPrototypeOf"))return!1}catch(c){return!1}var d;for(d in a);return d===b||D.call(a,d)},isEmptyObject:function(a){for(var b in a)return!1;return!0},error:function(a){throw new Error(a)},parseJSON:function(b){if(typeof b!="string"||!b)return null;b=e.trim(b);if(a.JSON&&a.JSON.parse)return a.JSON.parse(b);if(n.test(b.replace(o,"@").replace(p,"]").replace(q,"")))return(new Function("return " b))();e.error("Invalid JSON: " b)},parseXML:function(c){if(typeof c!="string"||!c)return null;var d,f;try{a.DOMParser?(f=new DOMParser,d=f.parseFromString(c,"text/xml")):(d=new ActiveXObject("Microsoft.XMLDOM"),d.async="false",d.loadXML(c))}catch(g){d=b}(!d||!d.documentElement||d.getElementsByTagName("parsererror").length)&&e.error("Invalid XML: " c);return d},noop:function(){},globalEval:function(b){b&&j.test(b)&&(a.execScript||function(b){a.eval.call(a,b)})(b)},camelCase:function(a){return a.replace(w,"ms-").replace(v,x)},nodeName:function(a,b){return a.nodeName&&a.nodeName.toUpperCase()===b.toUpperCase()},each:function(a,c,d){var f,g=0,h=a.length,i=h===b||e.isFunction(a);if(d){if(i){for(f in a)if(c.apply(a[f],d)===!1)break}else for(;g<h;)if(c.apply(a[g  ],d)===!1)break}else if(i){for(f in a)if(c.call(a[f],f,a[f])===!1)break}else for(;g<h;)if(c.call(a[g],g,a[g  ])===!1)break;return a},trim:G?function(a){return a==null?"":G.call(a)}:function(a){return a==null?"":(a "").replace(k,"").replace(l,"")},makeArray:function(a,b){var c=b||[];if(a!=null){var d=e.type(a);a.length==null||d==="string"||d==="function"||d==="regexp"||e.isWindow(a)?E.call(c,a):e.merge(c,a)}return c},inArray:function(a,b,c){var d;if(b){if(H)return H.call(b,a,c);d=b.length,c=c?c<0?Math.max(0,d c):c:0;for(;c<d;c  )if(c in b&&b[c]===a)return c}return-1},merge:function(a,c){var d=a.length,e=0;if(typeof c.length=="number")for(var f=c.length;e<f;e  )a[d  ]=c[e];else while(c[e]!==b)a[d  ]=c[e  ];a.length=d;return a},grep:function(a,b,c){var d=[],e;c=!!c;for(var f=0,g=a.length;f<g;f  )e=!!b(a[f],f),c!==e&&d.push(a[f]);return d},map:function(a,c,d){var f,g,h=[],i=0,j=a.length,k=a instanceof e||j!==b&&typeof j=="number"&&(j>0&&a[0]&&a[j-1]||j===0||e.isArray(a));if(k)for(;i<j;i  )f=c(a[i],i,d),f!=null&&(h[h.length]=f);else for(g in a)f=c(a[g],g,d),f!=null&&(h[h.length]=f);return h.concat.apply([],h)},guid:1,proxy:function(a,c){if(typeof c=="string"){var d=a[c];c=a,a=d}if(!e.isFunction(a))return b;var f=F.call(arguments,2),g=function(){return a.apply(c,f.concat(F.call(arguments)))};g.guid=a.guid=a.guid||g.guid||e.guid  ;return g},access:function(a,c,d,f,g,h,i){var j,k=d==null,l=0,m=a.length;if(d&&typeof d=="object"){for(l in d)e.access(a,c,l,d[l],1,h,f);g=1}else if(f!==b){j=i===b&&e.isFunction(f),k&&(j?(j=c,c=function(a,b,c){return j.call(e(a),c)}):(c.call(a,f),c=null));if(c)for(;l<m;l  )c(a[l],d,j?f.call(a[l],l,c(a[l],d)):f,i);g=1}return g?a:k?c.call(a):m?c(a[0],d):h},now:function(){return(new Date).getTime()},uaMatch:function(a){a=a.toLowerCase();var b=r.exec(a)||s.exec(a)||t.exec(a)||a.indexOf("compatible")<0&&u.exec(a)||[];return{browser:b[1]||"",version:b[2]||"0"}},sub:function(){function a(b,c){return new a.fn.init(b,c)}e.extend(!0,a,this),a.superclass=this,a.fn=a.prototype=this(),a.fn.constructor=a,a.sub=this.sub,a.fn.init=function(d,f){f&&f instanceof e&&!(f instanceof a)&&(f=a(f));return e.fn.init.call(this,d,f,b)},a.fn.init.prototype=a.fn;var b=a(c);return a},browser:{}}),e.each("Boolean Number String Function Array Date RegExp Object".split(" "),function(a,b){I["[object " b "]"]=b.toLowerCase()}),z=e.uaMatch(y),z.browser&&(e.browser[z.browser]=!0,e.browser.version=z.version),e.browser.webkit&&(e.browser.safari=!0),j.test("
")&&(k=/^[\s\xA0] /,l=/[\s\xA0] $/),h=e(c),c.addEventListener?B=function(){c.removeEventListener("DOMContentLoaded",B,!1),e.ready()}:c.attachEvent&&(B=function(){c.readyState==="complete"&&(c.detachEvent("onreadystatechange",B),e.ready())});return e}(),g={};f.Callbacks=function(a){a=a?g[a]||h(a):{};var c=[],d=[],e,i,j,k,l,m,n=function(b){var d,e,g,h,i;for(d=0,e=b.length;d<e;d  )g=b[d],h=f.type(g),h==="array"?n(g):h==="function"&&(!a.unique||!p.has(g))&&c.push(g)},o=function(b,f){f=f||[],e=!a.memory||[b,f],i=!0,j=!0,m=k||0,k=0,l=c.length;for(;c&&m<l;m  )if(c[m].apply(b,f)===!1&&a.stopOnFalse){e=!0;break}j=!1,c&&(a.once?e===!0?p.disable():c=[]:d&&d.length&&(e=d.shift(),p.fireWith(e[0],e[1])))},p={add:function(){if(c){var a=c.length;n(arguments),j?l=c.length:e&&e!==!0&&(k=a,o(e[0],e[1]))}return this},remove:function(){if(c){var b=arguments,d=0,e=b.length;for(;d<e;d  )for(var f=0;f<c.length;f  )if(b[d]===c[f]){j&&f<=l&&(l--,f<=m&&m--),c.splice(f--,1);if(a.unique)break}}return this},has:function(a){if(c){var b=0,d=c.length;for(;b<d;b  )if(a===c[b])return!0}return!1},empty:function(){c=[];return this},disable:function(){c=d=e=b;return this},disabled:function(){return!c},lock:function(){d=b,(!e||e===!0)&&p.disable();return this},locked:function(){return!d},fireWith:function(b,c){d&&(j?a.once||d.push([b,c]):(!a.once||!e)&&o(b,c));return this},fire:function(){p.fireWith(this,arguments);return this},fired:function(){return!!i}};return p};var i=[].slice;f.extend({Deferred:function(a){var b=f.Callbacks("once memory"),c=f.Callbacks("once memory"),d=f.Callbacks("memory"),e="pending",g={resolve:b,reject:c,notify:d},h={done:b.add,fail:c.add,progress:d.add,state:function(){return e},isResolved:b.fired,isRejected:c.fired,then:function(a,b,c){i.done(a).fail(b).progress(c);return this},always:function(){i.done.apply(i,arguments).fail.apply(i,arguments);return this},pipe:function(a,b,c){return f.Deferred(function(d){f.each({done:[a,"resolve"],fail:[b,"reject"],progress:[c,"notify"]},function(a,b){var c=b[0],e=b[1],g;f.isFunction(c)?i[a](function(){g=c.apply(this,arguments),g&&f.isFunction(g.promise)?g.promise().then(d.resolve,d.reject,d.notify):d[e "With"](this===i?d:this,[g])}):i[a](d[e])})}).promise()},promise:function(a){if(a==null)a=h;else for(var b in h)a[b]=h[b];return a}},i=h.promise({}),j;for(j in g)i[j]=g[j].fire,i[j "With"]=g[j].fireWith;i.done(function(){e="resolved"},c.disable,d.lock).fail(function(){e="rejected"},b.disable,d.lock),a&&a.call(i,i);return i},when:function(a){function m(a){return function(b){e[a]=arguments.length>1?i.call(arguments,0):b,j.notifyWith(k,e)}}function l(a){return function(c){b[a]=arguments.length>1?i.call(arguments,0):c,--g||j.resolveWith(j,b)}}var b=i.call(arguments,0),c=0,d=b.length,e=Array(d),g=d,h=d,j=d<=1&&a&&f.isFunction(a.promise)?a:f.Deferred(),k=j.promise();if(d>1){for(;c<d;c  )b[c]&&b[c].promise&&f.isFunction(b[c].promise)?b[c].promise().then(l(c),j.reject,m(c)):--g;g||j.resolveWith(j,b)}else j!==a&&j.resolveWith(j,d?[a]:[]);return k}}),f.support=function(){var b,d,e,g,h,i,j,k,l,m,n,o,p=c.createElement("div"),q=c.documentElement;p.setAttribute("className","t"),p.innerHTML=" <link/><table></table><a href='/a' style='top:1px;float:left;opacity:.55;'>a</a><input type='checkbox'/>",d=p.getElementsByTagName("*"),e=p.getElementsByTagName("a")[0];if(!d||!d.length||!e)return{};g=c.createElement("select"),h=g.appendChild(c.createElement("option")),i=p.getElementsByTagName("input")[0],b={leadingWhitespace:p.firstChild.nodeType===3,tbody:!p.getElementsByTagName("tbody").length,htmlSerialize:!!p.getElementsByTagName("link").length,style:/top/.test(e.getAttribute("style")),hrefNormalized:e.getAttribute("href")==="/a",opacity:/^0.55/.test(e.style.opacity),cssFloat:!!e.style.cssFloat,checkOn:i.value==="on",optSelected:h.selected,getSetAttribute:p.className!=="t",enctype:!!c.createElement("form").enctype,html5Clone:c.createElement("nav").cloneNode(!0).outerHTML!=="<:nav></:nav>",submitBubbles:!0,changeBubbles:!0,focusinBubbles:!1,deleteExpando:!0,noCloneEvent:!0,inlineBlockNeedsLayout:!1,shrinkWrapBlocks:!1,reliableMarginRight:!0,pixelMargin:!0},f.boxModel=b.boxModel=c.compatMode==="CSS1Compat",i.checked=!0,b.noCloneChecked=i.cloneNode(!0).checked,g.disabled=!0,b.optDisabled=!h.disabled;try{delete p.test}catch(r){b.deleteExpando=!1}!p.addEventListener&&p.attachEvent&&p.fireEvent&&(p.attachEvent("onclick",function(){b.noCloneEvent=!1}),p.cloneNode(!0).fireEvent("onclick")),i=c.createElement("input"),i.value="t",i.setAttribute("type","radio"),b.radioValue=i.value==="t",i.setAttribute("checked","checked"),i.setAttribute("name","t"),p.appendChild(i),j=c.createDocumentFragment(),j.appendChild(p.lastChild),b.checkClone=j.cloneNode(!0).cloneNode(!0).lastChild.checked,b.appendChecked=i.checked,j.removeChild(i),j.appendChild(p);if(p.attachEvent)for(n in{submit:1,change:1,focusin:1})m="on" n,o=m in p,o||(p.setAttribute(m,"return;"),o=typeof p[m]=="function"),b[n "Bubbles"]=o;j.removeChild(p),j=g=h=p=i=null,f(function(){var d,e,g,h,i,j,l,m,n,q,r,s,t,u=c.getElementsByTagName("body")[0];!u||(m=1,t="padding:0;margin:0;border:",r="position:absolute;top:0;left:0;width:1px;height:1px;",s=t "0;visibility:hidden;",n="style='" r t "5px solid #000;",q="<div " n "display:block;'><div style='" t "0;display:block;overflow:hidden;'></div></div>" "<table " n "' cellpadding='0' cellspacing='0'>" "<tr><td></td></tr></table>",d=c.createElement("div"),d.style.cssText=s "width:0;height:0;position:static;top:0;margin-top:" m "px",u.insertBefore(d,u.firstChild),p=c.createElement("div"),d.appendChild(p),p.innerHTML="<table><tr><td style='" t "0;display:none'></td><td>t</td></tr></table>",k=p.getElementsByTagName("td"),o=k[0].offsetHeight===0,k[0].style.display="",k[1].style.display="none",b.reliableHiddenOffsets=o&&k[0].offsetHeight===0,a.getComputedStyle&&(p.innerHTML="",l=c.createElement("div"),l.style.width="0",l.style.marginRight="0",p.style.width="2px",p.appendChild(l),b.reliableMarginRight=(parseInt((a.getComputedStyle(l,null)||{marginRight:0}).marginRight,10)||0)===0),typeof p.style.zoom!="undefined"&&(p.innerHTML="",p.style.width=p.style.padding="1px",p.style.border=0,p.style.overflow="hidden",p.style.display="inline",p.style.zoom=1,b.inlineBlockNeedsLayout=p.offsetWidth===3,p.style.display="block",p.style.overflow="visible",p.innerHTML="<div style='width:5px;'></div>",b.shrinkWrapBlocks=p.offsetWidth!==3),p.style.cssText=r s,p.innerHTML=q,e=p.firstChild,g=e.firstChild,i=e.nextSibling.firstChild.firstChild,j={doesNotAddBorder:g.offsetTop!==5,doesAddBorderForTableAndCells:i.offsetTop===5},g.style.position="fixed",g.style.top="20px",j.fixedPosition=g.offsetTop===20||g.offsetTop===15,g.style.position=g.style.top="",e.style.overflow="hidden",e.style.position="relative",j.subtractsBorderForOverflowNotVisible=g.offsetTop===-5,j.doesNotIncludeMarginInBodyOffset=u.offsetTop!==m,a.getComputedStyle&&(p.style.marginTop="1%",b.pixelMargin=(a.getComputedStyle(p,null)||{marginTop:0}).marginTop!=="1%"),typeof d.style.zoom!="undefined"&&(d.style.zoom=1),u.removeChild(d),l=p=d=null,f.extend(b,j))});return b}();var j=/^(?:\{.*\}|\[.*\])$/,k=/([A-Z])/g;f.extend({cache:{},uuid:0,expando:"jQuery" (f.fn.jquery Math.random()).replace(/\D/g,""),noData:{embed:!0,object:"clsid:D27CDB6E-AE6D-11cf-96B8-444553540000",applet:!0},hasData:function(a){a=a.nodeType?f.cache[a[f.expando]]:a[f.expando];return!!a&&!m(a)},data:function(a,c,d,e){if(!!f.acceptData(a)){var g,h,i,j=f.expando,k=typeof c=="string",l=a.nodeType,m=l?f.cache:a,n=l?a[j]:a[j]&&j,o=c==="events";if((!n||!m[n]||!o&&!e&&!m[n].data)&&k&&d===b)return;n||(l?a[j]=n=  f.uuid:n=j),m[n]||(m[n]={},l||(m[n].toJSON=f.noop));if(typeof c=="object"||typeof c=="function")e?m[n]=f.extend(m[n],c):m[n].data=f.extend(m[n].data,c);g=h=m[n],e||(h.data||(h.data={}),h=h.data),d!==b&&(h[f.camelCase(c)]=d);if(o&&!h[c])return g.events;k?(i=h[c],i==null&&(i=h[f.camelCase(c)])):i=h;return i}},removeData:function(a,b,c){if(!!f.acceptData(a)){var d,e,g,h=f.expando,i=a.nodeType,j=i?f.cache:a,k=i?a[h]:h;if(!j[k])return;if(b){d=c?j[k]:j[k].data;if(d){f.isArray(b)||(b in d?b=[b]:(b=f.camelCase(b),b in d?b=[b]:b=b.split(" ")));for(e=0,g=b.length;e<g;e  )delete d[b[e]];if(!(c?m:f.isEmptyObject)(d))return}}if(!c){delete j[k].data;if(!m(j[k]))return}f.support.deleteExpando||!j.setInterval?delete j[k]:j[k]=null,i&&(f.support.deleteExpando?delete a[h]:a.removeAttribute?a.removeAttribute(h):a[h]=null)}},_data:function(a,b,c){return f.data(a,b,c,!0)},acceptData:function(a){if(a.nodeName){var b=f.noData[a.nodeName.toLowerCase()];if(b)return b!==!0&&a.getAttribute("classid")===b}return!0}}),f.fn.extend({data:function(a,c){var d,e,g,h,i,j=this[0],k=0,m=null;if(a===b){if(this.length){m=f.data(j);if(j.nodeType===1&&!f._data(j,"parsedAttrs")){g=j.attributes;for(i=g.length;k<i;k  )h=g[k].name,h.indexOf("data-")===0&&(h=f.camelCase(h.substring(5)),l(j,h,m[h]));f._data(j,"parsedAttrs",!0)}}return m}if(typeof a=="object")return this.each(function(){f.data(this,a)});d=a.split(".",2),d[1]=d[1]?"." d[1]:"",e=d[1] "!";return f.access(this,function(c){if(c===b){m=this.triggerHandler("getData" e,[d[0]]),m===b&&j&&(m=f.data(j,a),m=l(j,a,m));return m===b&&d[1]?this.data(d[0]):m}d[1]=c,this.each(function(){var b=f(this);b.triggerHandler("setData" e,d),f.data(this,a,c),b.triggerHandler("changeData" e,d)})},null,c,arguments.length>1,null,!1)},removeData:function(a){return this.each(function(){f.removeData(this,a)})}}),f.extend({_mark:function(a,b){a&&(b=(b||"fx") "mark",f._data(a,b,(f._data(a,b)||0) 1))},_unmark:function(a,b,c){a!==!0&&(c=b,b=a,a=!1);if(b){c=c||"fx";var d=c "mark",e=a?0:(f._data(b,d)||1)-1;e?f._data(b,d,e):(f.removeData(b,d,!0),n(b,c,"mark"))}},queue:function(a,b,c){var d;if(a){b=(b||"fx") "queue",d=f._data(a,b),c&&(!d||f.isArray(c)?d=f._data(a,b,f.makeArray(c)):d.push(c));return d||[]}},dequeue:function(a,b){b=b||"fx";var c=f.queue(a,b),d=c.shift(),e={};d==="inprogress"&&(d=c.shift()),d&&(b==="fx"&&c.unshift("inprogress"),f._data(a,b ".run",e),d.call(a,function(){f.dequeue(a,b)},e)),c.length||(f.removeData(a,b "queue " b ".run",!0),n(a,b,"queue"))}}),f.fn.extend({queue:function(a,c){var d=2;typeof a!="string"&&(c=a,a="fx",d--);if(arguments.length<d)return f.queue(this[0],a);return c===b?this:this.each(function(){var b=f.queue(this,a,c);a==="fx"&&b[0]!=="inprogress"&&f.dequeue(this,a)})},dequeue:function(a){return this.each(function(){f.dequeue(this,a)})},delay:function(a,b){a=f.fx?f.fx.speeds[a]||a:a,b=b||"fx";return this.queue(b,function(b,c){var d=setTimeout(b,a);c.stop=function(){clearTimeout(d)}})},clearQueue:function(a){return this.queue(a||"fx",[])},promise:function(a,c){function m(){--h||d.resolveWith(e,[e])}typeof a!="string"&&(c=a,a=b),a=a||"fx";var d=f.Deferred(),e=this,g=e.length,h=1,i=a "defer",j=a "queue",k=a "mark",l;while(g--)if(l=f.data(e[g],i,b,!0)||(f.data(e[g],j,b,!0)||f.data(e[g],k,b,!0))&&f.data(e[g],i,f.Callbacks("once memory"),!0))h  ,l.add(m);m();return d.promise(c)}});var o=/[\n\t\r]/g,p=/\s /,q=/\r/g,r=/^(?:button|input)$/i,s=/^(?:button|input|object|select|textarea)$/i,t=/^a(?:rea)?$/i,u=/^(?:autofocus|autoplay|async|checked|controls|defer|disabled|hidden|loop|multiple|open|readonly|required|scoped|selected)$/i,v=f.support.getSetAttribute,w,x,y;f.fn.extend({attr:function(a,b){return f.access(this,f.attr,a,b,arguments.length>1)},removeAttr:function(a){return this.each(function(){f.removeAttr(this,a)})},prop:function(a,b){return f.access(this,f.prop,a,b,arguments.length>1)},removeProp:function(a){a=f.propFix[a]||a;return this.each(function(){try{this[a]=b,delete this[a]}catch(c){}})},addClass:function(a){var b,c,d,e,g,h,i;if(f.isFunction(a))return this.each(function(b){f(this).addClass(a.call(this,b,this.className))});if(a&&typeof a=="string"){b=a.split(p);for(c=0,d=this.length;c<d;c  ){e=this[c];if(e.nodeType===1)if(!e.className&&b.length===1)e.className=a;else{g=" " e.className " ";for(h=0,i=b.length;h<i;h  )~g.indexOf(" " b[h] " ")||(g =b[h] " ");e.className=f.trim(g)}}}return this},removeClass:function(a){var c,d,e,g,h,i,j;if(f.isFunction(a))return this.each(function(b){f(this).removeClass(a.call(this,b,this.className))});if(a&&typeof a=="string"||a===b){c=(a||"").split(p);for(d=0,e=this.length;d<e;d  ){g=this[d];if(g.nodeType===1&&g.className)if(a){h=(" " g.className " ").replace(o," ");for(i=0,j=c.length;i<j;i  )h=h.replace(" " c[i] " "," ");g.className=f.trim(h)}else g.className=""}}return this},toggleClass:function(a,b){var c=typeof a,d=typeof b=="boolean";if(f.isFunction(a))return this.each(function(c){f(this).toggleClass(a.call(this,c,this.className,b),b)});return this.each(function(){if(c==="string"){var e,g=0,h=f(this),i=b,j=a.split(p);while(e=j[g  ])i=d?i:!h.hasClass(e),h[i?"addClass":"removeClass"](e)}else if(c==="undefined"||c==="boolean")this.className&&f._data(this,"__className__",this.className),this.className=this.className||a===!1?"":f._data(this,"__className__")||""})},hasClass:function(a){var b=" " a " ",c=0,d=this.length;for(;c<d;c  )if(this[c].nodeType===1&&(" " this[c].className " ").replace(o," ").indexOf(b)>-1)return!0;return!1},val:function(a){var c,d,e,g=this[0];{if(!!arguments.length){e=f.isFunction(a);return this.each(function(d){var g=f(this),h;if(this.nodeType===1){e?h=a.call(this,d,g.val()):h=a,h==null?h="":typeof h=="number"?h ="":f.isArray(h)&&(h=f.map(h,function(a){return a==null?"":a ""})),c=f.valHooks[this.type]||f.valHooks[this.nodeName.toLowerCase()];if(!c||!("set"in c)||c.set(this,h,"value")===b)this.value=h}})}if(g){c=f.valHooks[g.type]||f.valHooks[g.nodeName.toLowerCase()];if(c&&"get"in c&&(d=c.get(g,"value"))!==b)return d;d=g.value;return typeof d=="string"?d.replace(q,""):d==null?"":d}}}}),f.extend({valHooks:{option:{get:function(a){var b=a.attributes.value;return!b||b.specified?a.value:a.text}},select:{get:function(a){var b,c,d,e,g=a.selectedIndex,h=[],i=a.options,j=a.type==="select-one";if(g<0)return null;c=j?g:0,d=j?g 1:i.length;for(;c<d;c  ){e=i[c];if(e.selected&&(f.support.optDisabled?!e.disabled:e.getAttribute("disabled")===null)&&(!e.parentNode.disabled||!f.nodeName(e.parentNode,"optgroup"))){b=f(e).val();if(j)return b;h.push(b)}}if(j&&!h.length&&i.length)return f(i[g]).val();return h},set:function(a,b){var c=f.makeArray(b);f(a).find("option").each(function(){this.selected=f.inArray(f(this).val(),c)>=0}),c.length||(a.selectedIndex=-1);return c}}},attrFn:{val:!0,css:!0,html:!0,text:!0,data:!0,width:!0,height:!0,offset:!0},attr:function(a,c,d,e){var g,h,i,j=a.nodeType;if(!!a&&j!==3&&j!==8&&j!==2){if(e&&c in f.attrFn)return f(a)[c](d);if(typeof a.getAttribute=="undefined")return f.prop(a,c,d);i=j!==1||!f.isXMLDoc(a),i&&(c=c.toLowerCase(),h=f.attrHooks[c]||(u.test(c)?x:w));if(d!==b){if(d===null){f.removeAttr(a,c);return}if(h&&"set"in h&&i&&(g=h.set(a,d,c))!==b)return g;a.setAttribute(c,"" d);return d}if(h&&"get"in h&&i&&(g=h.get(a,c))!==null)return g;g=a.getAttribute(c);return g===null?b:g}},removeAttr:function(a,b){var c,d,e,g,h,i=0;if(b&&a.nodeType===1){d=b.toLowerCase().split(p),g=d.length;for(;i<g;i  )e=d[i],e&&(c=f.propFix[e]||e,h=u.test(e),h||f.attr(a,e,""),a.removeAttribute(v?e:c),h&&c in a&&(a[c]=!1))}},attrHooks:{type:{set:function(a,b){if(r.test(a.nodeName)&&a.parentNode)f.error("type property can't be changed");else if(!f.support.radioValue&&b==="radio"&&f.nodeName(a,"input")){var c=a.value;a.setAttribute("type",b),c&&(a.value=c);return b}}},value:{get:function(a,b){if(w&&f.nodeName(a,"button"))return w.get(a,b);return b in a?a.value:null},set:function(a,b,c){if(w&&f.nodeName(a,"button"))return w.set(a,b,c);a.value=b}}},propFix:{tabindex:"tabIndex",readonly:"readOnly","for":"htmlFor","class":"className",maxlength:"maxLength",cellspacing:"cellSpacing",cellpadding:"cellPadding",rowspan:"rowSpan",colspan:"colSpan",usemap:"useMap",frameborder:"frameBorder",contenteditable:"contentEditable"},prop:function(a,c,d){var e,g,h,i=a.nodeType;if(!!a&&i!==3&&i!==8&&i!==2){h=i!==1||!f.isXMLDoc(a),h&&(c=f.propFix[c]||c,g=f.propHooks[c]);return d!==b?g&&"set"in g&&(e=g.set(a,d,c))!==b?e:a[c]=d:g&&"get"in g&&(e=g.get(a,c))!==null?e:a[c]}},propHooks:{tabIndex:{get:function(a){var c=a.getAttributeNode("tabindex");return c&&c.specified?parseInt(c.value,10):s.test(a.nodeName)||t.test(a.nodeName)&&a.href?0:b}}}}),f.attrHooks.tabindex=f.propHooks.tabIndex,x={get:function(a,c){var d,e=f.prop(a,c);return e===!0||typeof e!="boolean"&&(d=a.getAttributeNode(c))&&d.nodeValue!==!1?c.toLowerCase():b},set:function(a,b,c){var d;b===!1?f.removeAttr(a,c):(d=f.propFix[c]||c,d in a&&(a[d]=!0),a.setAttribute(c,c.toLowerCase()));return c}},v||(y={name:!0,id:!0,coords:!0},w=f.valHooks.button={get:function(a,c){var d;d=a.getAttributeNode(c);return d&&(y[c]?d.nodeValue!=="":d.specified)?d.nodeValue:b},set:function(a,b,d){var e=a.getAttributeNode(d);e||(e=c.createAttribute(d),a.setAttributeNode(e));return e.nodeValue=b ""}},f.attrHooks.tabindex.set=w.set,f.each(["width","height"],function(a,b){f.attrHooks[b]=f.extend(f.attrHooks[b],{set:function(a,c){if(c===""){a.setAttribute(b,"auto");return c}}})}),f.attrHooks.contenteditable={get:w.get,set:function(a,b,c){b===""&&(b="false"),w.set(a,b,c)}}),f.support.hrefNormalized||f.each(["href","src","width","height"],function(a,c){f.attrHooks[c]=f.extend(f.attrHooks[c],{get:function(a){var d=a.getAttribute(c,2);return d===null?b:d}})}),f.support.style||(f.attrHooks.style={get:function(a){return a.style.cssText.toLowerCase()||b},set:function(a,b){return a.style.cssText="" b}}),f.support.optSelected||(f.propHooks.selected=f.extend(f.propHooks.selected,{get:function(a){var b=a.parentNode;b&&(b.selectedIndex,b.parentNode&&b.parentNode.selectedIndex);return null}})),f.support.enctype||(f.propFix.enctype="encoding"),f.support.checkOn||f.each(["radio","checkbox"],function(){f.valHooks[this]={get:function(a){return a.getAttribute("value")===null?"on":a.value}}}),f.each(["radio","checkbox"],function(){f.valHooks[this]=f.extend(f.valHooks[this],{set:function(a,b){if(f.isArray(b))return a.checked=f.inArray(f(a).val(),b)>=0}})});var z=/^(?:textarea|input|select)$/i,A=/^([^\.]*)?(?:\.(. ))?$/,B=/(?:^|\s)hover(\.\S )?\b/,C=/^key/,D=/^(?:mouse|contextmenu)|click/,E=/^(?:focusinfocus|focusoutblur)$/,F=/^(\w*)(?:#([\w\-] ))?(?:\.([\w\-] ))?$/,G=function(
a){var b=F.exec(a);b&&(b[1]=(b[1]||"").toLowerCase(),b[3]=b[3]&&new RegExp("(?:^|\\s)" b[3] "(?:\\s|$)"));return b},H=function(a,b){var c=a.attributes||{};return(!b[1]||a.nodeName.toLowerCase()===b[1])&&(!b[2]||(c.id||{}).value===b[2])&&(!b[3]||b[3].test((c["class"]||{}).value))},I=function(a){return f.event.special.hover?a:a.replace(B,"mouseenter$1 mouseleave$1")};f.event={add:function(a,c,d,e,g){var h,i,j,k,l,m,n,o,p,q,r,s;if(!(a.nodeType===3||a.nodeType===8||!c||!d||!(h=f._data(a)))){d.handler&&(p=d,d=p.handler,g=p.selector),d.guid||(d.guid=f.guid  ),j=h.events,j||(h.events=j={}),i=h.handle,i||(h.handle=i=function(a){return typeof f!="undefined"&&(!a||f.event.triggered!==a.type)?f.event.dispatch.apply(i.elem,arguments):b},i.elem=a),c=f.trim(I(c)).split(" ");for(k=0;k<c.length;k  ){l=A.exec(c[k])||[],m=l[1],n=(l[2]||"").split(".").sort(),s=f.event.special[m]||{},m=(g?s.delegateType:s.bindType)||m,s=f.event.special[m]||{},o=f.extend({type:m,origType:l[1],data:e,handler:d,guid:d.guid,selector:g,quick:g&&G(g),namespace:n.join(".")},p),r=j[m];if(!r){r=j[m]=[],r.delegateCount=0;if(!s.setup||s.setup.call(a,e,n,i)===!1)a.addEventListener?a.addEventListener(m,i,!1):a.attachEvent&&a.attachEvent("on" m,i)}s.add&&(s.add.call(a,o),o.handler.guid||(o.handler.guid=d.guid)),g?r.splice(r.delegateCount  ,0,o):r.push(o),f.event.global[m]=!0}a=null}},global:{},remove:function(a,b,c,d,e){var g=f.hasData(a)&&f._data(a),h,i,j,k,l,m,n,o,p,q,r,s;if(!!g&&!!(o=g.events)){b=f.trim(I(b||"")).split(" ");for(h=0;h<b.length;h  ){i=A.exec(b[h])||[],j=k=i[1],l=i[2];if(!j){for(j in o)f.event.remove(a,j b[h],c,d,!0);continue}p=f.event.special[j]||{},j=(d?p.delegateType:p.bindType)||j,r=o[j]||[],m=r.length,l=l?new RegExp("(^|\\.)" l.split(".").sort().join("\\.(?:.*\\.)?") "(\\.|$)"):null;for(n=0;n<r.length;n  )s=r[n],(e||k===s.origType)&&(!c||c.guid===s.guid)&&(!l||l.test(s.namespace))&&(!d||d===s.selector||d==="**"&&s.selector)&&(r.splice(n--,1),s.selector&&r.delegateCount--,p.remove&&p.remove.call(a,s));r.length===0&&m!==r.length&&((!p.teardown||p.teardown.call(a,l)===!1)&&f.removeEvent(a,j,g.handle),delete o[j])}f.isEmptyObject(o)&&(q=g.handle,q&&(q.elem=null),f.removeData(a,["events","handle"],!0))}},customEvent:{getData:!0,setData:!0,changeData:!0},trigger:function(c,d,e,g){if(!e||e.nodeType!==3&&e.nodeType!==8){var h=c.type||c,i=[],j,k,l,m,n,o,p,q,r,s;if(E.test(h f.event.triggered))return;h.indexOf("!")>=0&&(h=h.slice(0,-1),k=!0),h.indexOf(".")>=0&&(i=h.split("."),h=i.shift(),i.sort());if((!e||f.event.customEvent[h])&&!f.event.global[h])return;c=typeof c=="object"?c[f.expando]?c:new f.Event(h,c):new f.Event(h),c.type=h,c.isTrigger=!0,c.exclusive=k,c.namespace=i.join("."),c.namespace_re=c.namespace?new RegExp("(^|\\.)" i.join("\\.(?:.*\\.)?") "(\\.|$)"):null,o=h.indexOf(":")<0?"on" h:"";if(!e){j=f.cache;for(l in j)j[l].events&&j[l].events[h]&&f.event.trigger(c,d,j[l].handle.elem,!0);return}c.result=b,c.target||(c.target=e),d=d!=null?f.makeArray(d):[],d.unshift(c),p=f.event.special[h]||{};if(p.trigger&&p.trigger.apply(e,d)===!1)return;r=[[e,p.bindType||h]];if(!g&&!p.noBubble&&!f.isWindow(e)){s=p.delegateType||h,m=E.test(s h)?e:e.parentNode,n=null;for(;m;m=m.parentNode)r.push([m,s]),n=m;n&&n===e.ownerDocument&&r.push([n.defaultView||n.parentWindow||a,s])}for(l=0;l<r.length&&!c.isPropagationStopped();l  )m=r[l][0],c.type=r[l][1],q=(f._data(m,"events")||{})[c.type]&&f._data(m,"handle"),q&&q.apply(m,d),q=o&&m[o],q&&f.acceptData(m)&&q.apply(m,d)===!1&&c.preventDefault();c.type=h,!g&&!c.isDefaultPrevented()&&(!p._default||p._default.apply(e.ownerDocument,d)===!1)&&(h!=="click"||!f.nodeName(e,"a"))&&f.acceptData(e)&&o&&e[h]&&(h!=="focus"&&h!=="blur"||c.target.offsetWidth!==0)&&!f.isWindow(e)&&(n=e[o],n&&(e[o]=null),f.event.triggered=h,e[h](),f.event.triggered=b,n&&(e[o]=n));return c.result}},dispatch:function(c){c=f.event.fix(c||a.event);var d=(f._data(this,"events")||{})[c.type]||[],e=d.delegateCount,g=[].slice.call(arguments,0),h=!c.exclusive&&!c.namespace,i=f.event.special[c.type]||{},j=[],k,l,m,n,o,p,q,r,s,t,u;g[0]=c,c.delegateTarget=this;if(!i.preDispatch||i.preDispatch.call(this,c)!==!1){if(e&&(!c.button||c.type!=="click")){n=f(this),n.context=this.ownerDocument||this;for(m=c.target;m!=this;m=m.parentNode||this)if(m.disabled!==!0){p={},r=[],n[0]=m;for(k=0;k<e;k  )s=d[k],t=s.selector,p[t]===b&&(p[t]=s.quick?H(m,s.quick):n.is(t)),p[t]&&r.push(s);r.length&&j.push({elem:m,matches:r})}}d.length>e&&j.push({elem:this,matches:d.slice(e)});for(k=0;k<j.length&&!c.isPropagationStopped();k  ){q=j[k],c.currentTarget=q.elem;for(l=0;l<q.matches.length&&!c.isImmediatePropagationStopped();l  ){s=q.matches[l];if(h||!c.namespace&&!s.namespace||c.namespace_re&&c.namespace_re.test(s.namespace))c.data=s.data,c.handleObj=s,o=((f.event.special[s.origType]||{}).handle||s.handler).apply(q.elem,g),o!==b&&(c.result=o,o===!1&&(c.preventDefault(),c.stopPropagation()))}}i.postDispatch&&i.postDispatch.call(this,c);return c.result}},props:"attrChange attrName relatedNode srcElement altKey bubbles cancelable ctrlKey currentTarget eventPhase metaKey relatedTarget shiftKey target timeStamp view which".split(" "),fixHooks:{},keyHooks:{props:"char charCode key keyCode".split(" "),filter:function(a,b){a.which==null&&(a.which=b.charCode!=null?b.charCode:b.keyCode);return a}},mouseHooks:{props:"button buttons clientX clientY fromElement offsetX offsetY pageX pageY screenX screenY toElement".split(" "),filter:function(a,d){var e,f,g,h=d.button,i=d.fromElement;a.pageX==null&&d.clientX!=null&&(e=a.target.ownerDocument||c,f=e.documentElement,g=e.body,a.pageX=d.clientX (f&&f.scrollLeft||g&&g.scrollLeft||0)-(f&&f.clientLeft||g&&g.clientLeft||0),a.pageY=d.clientY (f&&f.scrollTop||g&&g.scrollTop||0)-(f&&f.clientTop||g&&g.clientTop||0)),!a.relatedTarget&&i&&(a.relatedTarget=i===a.target?d.toElement:i),!a.which&&h!==b&&(a.which=h&1?1:h&2?3:h&4?2:0);return a}},fix:function(a){if(a[f.expando])return a;var d,e,g=a,h=f.event.fixHooks[a.type]||{},i=h.props?this.props.concat(h.props):this.props;a=f.Event(g);for(d=i.length;d;)e=i[--d],a[e]=g[e];a.target||(a.target=g.srcElement||c),a.target.nodeType===3&&(a.target=a.target.parentNode),a.metaKey===b&&(a.metaKey=a.ctrlKey);return h.filter?h.filter(a,g):a},special:{ready:{setup:f.bindReady},load:{noBubble:!0},focus:{delegateType:"focusin"},blur:{delegateType:"focusout"},beforeunload:{setup:function(a,b,c){f.isWindow(this)&&(this.onbeforeunload=c)},teardown:function(a,b){this.onbeforeunload===b&&(this.onbeforeunload=null)}}},simulate:function(a,b,c,d){var e=f.extend(new f.Event,c,{type:a,isSimulated:!0,originalEvent:{}});d?f.event.trigger(e,null,b):f.event.dispatch.call(b,e),e.isDefaultPrevented()&&c.preventDefault()}},f.event.handle=f.event.dispatch,f.removeEvent=c.removeEventListener?function(a,b,c){a.removeEventListener&&a.removeEventListener(b,c,!1)}:function(a,b,c){a.detachEvent&&a.detachEvent("on" b,c)},f.Event=function(a,b){if(!(this instanceof f.Event))return new f.Event(a,b);a&&a.type?(this.originalEvent=a,this.type=a.type,this.isDefaultPrevented=a.defaultPrevented||a.returnValue===!1||a.getPreventDefault&&a.getPreventDefault()?K:J):this.type=a,b&&f.extend(this,b),this.timeStamp=a&&a.timeStamp||f.now(),this[f.expando]=!0},f.Event.prototype={preventDefault:function(){this.isDefaultPrevented=K;var a=this.originalEvent;!a||(a.preventDefault?a.preventDefault():a.returnValue=!1)},stopPropagation:function(){this.isPropagationStopped=K;var a=this.originalEvent;!a||(a.stopPropagation&&a.stopPropagation(),a.cancelBubble=!0)},stopImmediatePropagation:function(){this.isImmediatePropagationStopped=K,this.stopPropagation()},isDefaultPrevented:J,isPropagationStopped:J,isImmediatePropagationStopped:J},f.each({mouseenter:"mouseover",mouseleave:"mouseout"},function(a,b){f.event.special[a]={delegateType:b,bindType:b,handle:function(a){var c=this,d=a.relatedTarget,e=a.handleObj,g=e.selector,h;if(!d||d!==c&&!f.contains(c,d))a.type=e.origType,h=e.handler.apply(this,arguments),a.type=b;return h}}}),f.support.submitBubbles||(f.event.special.submit={setup:function(){if(f.nodeName(this,"form"))return!1;f.event.add(this,"click._submit keypress._submit",function(a){var c=a.target,d=f.nodeName(c,"input")||f.nodeName(c,"button")?c.form:b;d&&!d._submit_attached&&(f.event.add(d,"submit._submit",function(a){a._submit_bubble=!0}),d._submit_attached=!0)})},postDispatch:function(a){a._submit_bubble&&(delete a._submit_bubble,this.parentNode&&!a.isTrigger&&f.event.simulate("submit",this.parentNode,a,!0))},teardown:function(){if(f.nodeName(this,"form"))return!1;f.event.remove(this,"._submit")}}),f.support.changeBubbles||(f.event.special.change={setup:function(){if(z.test(this.nodeName)){if(this.type==="checkbox"||this.type==="radio")f.event.add(this,"propertychange._change",function(a){a.originalEvent.propertyName==="checked"&&(this._just_changed=!0)}),f.event.add(this,"click._change",function(a){this._just_changed&&!a.isTrigger&&(this._just_changed=!1,f.event.simulate("change",this,a,!0))});return!1}f.event.add(this,"beforeactivate._change",function(a){var b=a.target;z.test(b.nodeName)&&!b._change_attached&&(f.event.add(b,"change._change",function(a){this.parentNode&&!a.isSimulated&&!a.isTrigger&&f.event.simulate("change",this.parentNode,a,!0)}),b._change_attached=!0)})},handle:function(a){var b=a.target;if(this!==b||a.isSimulated||a.isTrigger||b.type!=="radio"&&b.type!=="checkbox")return a.handleObj.handler.apply(this,arguments)},teardown:function(){f.event.remove(this,"._change");return z.test(this.nodeName)}}),f.support.focusinBubbles||f.each({focus:"focusin",blur:"focusout"},function(a,b){var d=0,e=function(a){f.event.simulate(b,a.target,f.event.fix(a),!0)};f.event.special[b]={setup:function(){d  ===0&&c.addEventListener(a,e,!0)},teardown:function(){--d===0&&c.removeEventListener(a,e,!0)}}}),f.fn.extend({on:function(a,c,d,e,g){var h,i;if(typeof a=="object"){typeof c!="string"&&(d=d||c,c=b);for(i in a)this.on(i,c,d,a[i],g);return this}d==null&&e==null?(e=c,d=c=b):e==null&&(typeof c=="string"?(e=d,d=b):(e=d,d=c,c=b));if(e===!1)e=J;else if(!e)return this;g===1&&(h=e,e=function(a){f().off(a);return h.apply(this,arguments)},e.guid=h.guid||(h.guid=f.guid  ));return this.each(function(){f.event.add(this,a,e,d,c)})},one:function(a,b,c,d){return this.on(a,b,c,d,1)},off:function(a,c,d){if(a&&a.preventDefault&&a.handleObj){var e=a.handleObj;f(a.delegateTarget).off(e.namespace?e.origType "." e.namespace:e.origType,e.selector,e.handler);return this}if(typeof a=="object"){for(var g in a)this.off(g,c,a[g]);return this}if(c===!1||typeof c=="function")d=c,c=b;d===!1&&(d=J);return this.each(function(){f.event.remove(this,a,d,c)})},bind:function(a,b,c){return this.on(a,null,b,c)},unbind:function(a,b){return this.off(a,null,b)},live:function(a,b,c){f(this.context).on(a,this.selector,b,c);return this},die:function(a,b){f(this.context).off(a,this.selector||"**",b);return this},delegate:function(a,b,c,d){return this.on(b,a,c,d)},undelegate:function(a,b,c){return arguments.length==1?this.off(a,"**"):this.off(b,a,c)},trigger:function(a,b){return this.each(function(){f.event.trigger(a,b,this)})},triggerHandler:function(a,b){if(this[0])return f.event.trigger(a,b,this[0],!0)},toggle:function(a){var b=arguments,c=a.guid||f.guid  ,d=0,e=function(c){var e=(f._data(this,"lastToggle" a.guid)||0)%d;f._data(this,"lastToggle" a.guid,e 1),c.preventDefault();return b[e].apply(this,arguments)||!1};e.guid=c;while(d<b.length)b[d  ].guid=c;return this.click(e)},hover:function(a,b){return this.mouseenter(a).mouseleave(b||a)}}),f.each("blur focus focusin focusout load resize scroll unload click dblclick mousedown mouseup mousemove mouseover mouseout mouseenter mouseleave change select submit keydown keypress keyup error contextmenu".split(" "),function(a,b){f.fn[b]=function(a,c){c==null&&(c=a,a=null);return arguments.length>0?this.on(b,null,a,c):this.trigger(b)},f.attrFn&&(f.attrFn[b]=!0),C.test(b)&&(f.event.fixHooks[b]=f.event.keyHooks),D.test(b)&&(f.event.fixHooks[b]=f.event.mouseHooks)}),function(){function x(a,b,c,e,f,g){for(var h=0,i=e.length;h<i;h  ){var j=e[h];if(j){var k=!1;j=j[a];while(j){if(j[d]===c){k=e[j.sizset];break}if(j.nodeType===1){g||(j[d]=c,j.sizset=h);if(typeof b!="string"){if(j===b){k=!0;break}}else if(m.filter(b,[j]).length>0){k=j;break}}j=j[a]}e[h]=k}}}function w(a,b,c,e,f,g){for(var h=0,i=e.length;h<i;h  ){var j=e[h];if(j){var k=!1;j=j[a];while(j){if(j[d]===c){k=e[j.sizset];break}j.nodeType===1&&!g&&(j[d]=c,j.sizset=h);if(j.nodeName.toLowerCase()===b){k=j;break}j=j[a]}e[h]=k}}}var a=/((?:\((?:\([^()] \)|[^()] ) \)|\[(?:\[[^\[\]]*\]|['"][^'"]*['"]|[^\[\]'"] ) \]|\\.|[^ > ~,(\[\\] ) |[> ~])(\s*,\s*)?((?:.|\r|\n)*)/g,d="sizcache" (Math.random() "").replace(".",""),e=0,g=Object.prototype.toString,h=!1,i=!0,j=/\\/g,k=/\r\n/g,l=/\W/;[0,0].sort(function(){i=!1;return 0});var m=function(b,d,e,f){e=e||[],d=d||c;var h=d;if(d.nodeType!==1&&d.nodeType!==9)return[];if(!b||typeof b!="string")return e;var i,j,k,l,n,q,r,t,u=!0,v=m.isXML(d),w=[],x=b;do{a.exec(""),i=a.exec(x);if(i){x=i[3],w.push(i[1]);if(i[2]){l=i[3];break}}}while(i);if(w.length>1&&p.exec(b))if(w.length===2&&o.relative[w[0]])j=y(w[0] w[1],d,f);else{j=o.relative[w[0]]?[d]:m(w.shift(),d);while(w.length)b=w.shift(),o.relative[b]&&(b =w.shift()),j=y(b,j,f)}else{!f&&w.length>1&&d.nodeType===9&&!v&&o.match.ID.test(w[0])&&!o.match.ID.test(w[w.length-1])&&(n=m.find(w.shift(),d,v),d=n.expr?m.filter(n.expr,n.set)[0]:n.set[0]);if(d){n=f?{expr:w.pop(),set:s(f)}:m.find(w.pop(),w.length===1&&(w[0]==="~"||w[0]===" ")&&d.parentNode?d.parentNode:d,v),j=n.expr?m.filter(n.expr,n.set):n.set,w.length>0?k=s(j):u=!1;while(w.length)q=w.pop(),r=q,o.relative[q]?r=w.pop():q="",r==null&&(r=d),o.relative[q](k,r,v)}else k=w=[]}k||(k=j),k||m.error(q||b);if(g.call(k)==="[object Array]")if(!u)e.push.apply(e,k);else if(d&&d.nodeType===1)for(t=0;k[t]!=null;t  )k[t]&&(k[t]===!0||k[t].nodeType===1&&m.contains(d,k[t]))&&e.push(j[t]);else for(t=0;k[t]!=null;t  )k[t]&&k[t].nodeType===1&&e.push(j[t]);else s(k,e);l&&(m(l,h,e,f),m.uniqueSort(e));return e};m.uniqueSort=function(a){if(u){h=i,a.sort(u);if(h)for(var b=1;b<a.length;b  )a[b]===a[b-1]&&a.splice(b--,1)}return a},m.matches=function(a,b){return m(a,null,null,b)},m.matchesSelector=function(a,b){return m(b,null,null,[a]).length>0},m.find=function(a,b,c){var d,e,f,g,h,i;if(!a)return[];for(e=0,f=o.order.length;e<f;e  ){h=o.order[e];if(g=o.leftMatch[h].exec(a)){i=g[1],g.splice(1,1);if(i.substr(i.length-1)!=="\\"){g[1]=(g[1]||"").replace(j,""),d=o.find[h](g,b,c);if(d!=null){a=a.replace(o.match[h],"");break}}}}d||(d=typeof b.getElementsByTagName!="undefined"?b.getElementsByTagName("*"):[]);return{set:d,expr:a}},m.filter=function(a,c,d,e){var f,g,h,i,j,k,l,n,p,q=a,r=[],s=c,t=c&&c[0]&&m.isXML(c[0]);while(a&&c.length){for(h in o.filter)if((f=o.leftMatch[h].exec(a))!=null&&f[2]){k=o.filter[h],l=f[1],g=!1,f.splice(1,1);if(l.substr(l.length-1)==="\\")continue;s===r&&(r=[]);if(o.preFilter[h]){f=o.preFilter[h](f,s,d,r,e,t);if(!f)g=i=!0;else if(f===!0)continue}if(f)for(n=0;(j=s[n])!=null;n  )j&&(i=k(j,f,n,s),p=e^i,d&&i!=null?p?g=!0:s[n]=!1:p&&(r.push(j),g=!0));if(i!==b){d||(s=r),a=a.replace(o.match[h],"");if(!g)return[];break}}if(a===q)if(g==null)m.error(a);else break;q=a}return s},m.error=function(a){throw new Error("Syntax error, unrecognized expression: " a)};var n=m.getText=function(a){var b,c,d=a.nodeType,e="";if(d){if(d===1||d===9||d===11){if(typeof a.textContent=="string")return a.textContent;if(typeof a.innerText=="string")return a.innerText.replace(k,"");for(a=a.firstChild;a;a=a.nextSibling)e =n(a)}else if(d===3||d===4)return a.nodeValue}else for(b=0;c=a[b];b  )c.nodeType!==8&&(e =n(c));return e},o=m.selectors={order:["ID","NAME","TAG"],match:{ID:/#((?:[\w\u00c0-\uFFFF\-]|\\.) )/,CLASS:/\.((?:[\w\u00c0-\uFFFF\-]|\\.) )/,NAME:/\[name=['"]*((?:[\w\u00c0-\uFFFF\-]|\\.) )['"]*\]/,ATTR:/\[\s*((?:[\w\u00c0-\uFFFF\-]|\\.) )\s*(?:(\S?=)\s*(?:(['"])(.*?)\3|(#?(?:[\w\u00c0-\uFFFF\-]|\\.)*)|)|)\s*\]/,TAG:/^((?:[\w\u00c0-\uFFFF\*\-]|\\.) )/,CHILD:/:(only|nth|last|first)-child(?:\(\s*(even|odd|(?:[ \-]?\d |(?:[ \-]?\d*)?n\s*(?:[ \-]\s*\d )?))\s*\))?/,POS:/:(nth|eq|gt|lt|first|last|even|odd)(?:\((\d*)\))?(?=[^\-]|$)/,PSEUDO:/:((?:[\w\u00c0-\uFFFF\-]|\\.) )(?:\((['"]?)((?:\([^\)] \)|[^\(\)]*) )\2\))?/},leftMatch:{},attrMap:{"class":"className","for":"htmlFor"},attrHandle:{href:function(a){return a.getAttribute("href")},type:function(a){return a.getAttribute("type")}},relative:{" ":function(a,b){var c=typeof b=="string",d=c&&!l.test(b),e=c&&!d;d&&(b=b.toLowerCase());for(var f=0,g=a.length,h;f<g;f  )if(h=a[f]){while((h=h.previousSibling)&&h.nodeType!==1);a[f]=e||h&&h.nodeName.toLowerCase()===b?h||!1:h===b}e&&m.filter(b,a,!0)},">":function(a,b){var c,d=typeof b=="string",e=0,f=a.length;if(d&&!l.test(b)){b=b.toLowerCase();for(;e<f;e  ){c=a[e];if(c){var g=c.parentNode;a[e]=g.nodeName.toLowerCase()===b?g:!1}}}else{for(;e<f;e  )c=a[e],c&&(a[e]=d?c.parentNode:c.parentNode===b);d&&m.filter(b,a,!0)}},"":function(a,b,c){var d,f=e  ,g=x;typeof b=="string"&&!l.test(b)&&(b=b.toLowerCase(),d=b,g=w),g("parentNode",b,f,a,d,c)},"~":function(a,b,c){var d,f=e  ,g=x;typeof b=="string"&&!l.test(b)&&(b=b.toLowerCase(),d=b,g=w),g("previousSibling",b,f,a,d,c)}},find:{ID:function(a,b,c){if(typeof b.getElementById!="undefined"&&!c){var d=b.getElementById(a[1]);return d&&d.parentNode?[d]:[]}},NAME:function(a,b){if(typeof b.getElementsByName!="undefined"){var c=[],d=b.getElementsByName(a[1]);for(var e=0,f=d.length;e<f;e  )d[e].getAttribute("name")===a[1]&&c.push(d[e]);return c.length===0?null:c}},TAG:function(a,b){if(typeof b.getElementsByTagName!="undefined")return b.getElementsByTagName(a[1])}},preFilter:{CLASS:function(a,b,c,d,e,f){a=" " a[1].replace(j,"") " ";if(f)return a;for(var g=0,h;(h=b[g])!=null;g  )h&&(e^(h.className&&(" " h.className " ").replace(/[\t\n\r]/g," ").indexOf(a)>=0)?c||d.push(h):c&&(b[g]=!1));return!1},ID:function(a){return a[1].replace(j,"")},TAG:function(a,b){return a[1].replace(j,"").toLowerCase()},CHILD:function(a){if(a[1]==="nth"){a[2]||m.error(a[0]),a[2]=a[2].replace(/^\ |\s*/g,"");var b=/(-?)(\d*)(?:n([ \-]?\d*))?/.exec(a[2]==="even"&&"2n"||a[2]==="odd"&&"2n 1"||!/\D/.test(a[2])&&"0n " a[2]||a[2]);a[2]=b[1] (b[2]||1)-0,a[3]=b[3]-0}else a[2]&&m.error(a[0]);a[0]=e  ;return a},ATTR:function(a,b,c,d,e,f){var g=a[1]=a[1].replace(j,"");!f&&o.attrMap[g]&&(a[1]=o.attrMap[g]),a[4]=(a[4]||a[5]||"").replace(j,""),a[2]==="~="&&(a[4]=" " a[4] " ");return a},PSEUDO:function(b,c,d,e,f){if(b[1]==="not")if((a.exec(b[3])||"").length>1||/^\w/.test(b[3]))b[3]=m(b[3],null,null,c);else{var g=m.filter(b[3],c,d,!0^f);d||e.push.apply(e,g);return!1}else if(o.match.POS.test(b[0])||o.match.CHILD.test(b[0]))return!0;return b},POS:function(a){a.unshift(!0);return a}},filters:{enabled:function(a){return a.disabled===!1&&a.type!=="hidden"},disabled:function(a){return a.disabled===!0},checked:function(a){return a.checked===!0},selected:function(a){a.parentNode&&a.parentNode.selectedIndex;return a.selected===!0},parent:function(a){return!!a.firstChild},empty:function(a){return!a.firstChild},has:function(a,b,c){return!!m(c[3],a).length},header:function(a){return/h\d/i.test(a.nodeName)},text:function(a){var b=a.getAttribute("type"),c=a.type;return a.nodeName.toLowerCase()==="input"&&"text"===c&&(b===c||b===null)},radio:function(a){return a.nodeName.toLowerCase()==="input"&&"radio"===a.type},checkbox:function(a){return a.nodeName.toLowerCase()==="input"&&"checkbox"===a.type},file:function(a){return a.nodeName.toLowerCase()==="input"&&"file"===a.type},password:function(a){return a.nodeName.toLowerCase()==="input"&&"password"===a.type},submit:function(a){var b=a.nodeName.toLowerCase();return(b==="input"||b==="button")&&"submit"===a.type},image:function(a){return a.nodeName.toLowerCase()==="input"&&"image"===a.type},reset:function(a){var b=a.nodeName.toLowerCase();return(b==="input"||b==="button")&&"reset"===a.type},button:function(a){var b=a.nodeName.toLowerCase();return b==="input"&&"button"===a.type||b==="button"},input:function(a){return/input|select|textarea|button/i.test(a.nodeName)},focus:function(a){return a===a.ownerDocument.activeElement}},setFilters:{first:function(a,b){return b===0},last:function(a,b,c,d){return b===d.length-1},even:function(a,b){return b%2===0},odd:function(a,b){return b%2===1},lt:function(a,b,c){return b<c[3]-0},gt:function(a,b,c){return b>c[3]-0},nth:function(a,b,c){return c[3]-0===b},eq:function(a,b,c){return c[3]-0===b}},filter:{PSEUDO:function(a,b,c,d){var e=b[1],f=o.filters[e];if(f)return f(a,c,b,d);if(e==="contains")return(a.textContent||a.innerText||n([a])||"").indexOf(b[3])>=0;if(e==="not"){var g=b[3];for(var h=0,i=g.length;h<i;h  )if(g[h]===a)return!1;return!0}m.error(e)},CHILD:function(a,b){var c,e,f,g,h,i,j,k=b[1],l=a;switch(k){case"only":case"first":while(l=l.previousSibling)if(l.nodeType===1)return!1;if(k==="first")return!0;l=a;case"last":while(l=l.nextSibling)if(l.nodeType===1)return!1;return!0;case"nth":c=b[2],e=b[3];if(c===1&&e===0)return!0;f=b[0],g=a.parentNode;if(g&&(g[d]!==f||!a.nodeIndex)){i=0;for(l=g.firstChild;l;l=l.nextSibling)l.nodeType===1&&(l.nodeIndex=  i);g[d]=f}j=a.nodeIndex-e;return c===0?j===0:j%c===0&&j/c>=0}},ID:function(a,b){return a.nodeType===1&&a.getAttribute("id")===b},TAG:function(a,b){return b==="*"&&a.nodeType===1||!!a.nodeName&&a.nodeName.toLowerCase()===b},CLASS:function(a,b){return(" " (a.className||a.getAttribute("class")) " ").indexOf(b)>-1},ATTR:function(a,b){var c=b[1],d=m.attr?m.attr(a,c):o.attrHandle[c]?o.attrHandle[c](a):a[c]!=null?a[c]:a.getAttribute(c),e=d "",f=b[2],g=b[4];return d==null?f==="!=":!f&&m.attr?d!=null:f==="="?e===g:f==="*="?e.indexOf(g)>=0:f==="~="?(" " e " ").indexOf(g)>=0:g?f==="!="?e!==g:f==="^="?e.indexOf(g)===0:f==="$="?e.substr(e.length-g.length)===g:f==="|="?e===g||e.substr(0,g.length 1)===g "-":!1:e&&d!==!1},POS:function(a,b,c,d){var e=b[2],f=o.setFilters[e];if(f)return f(a,c,b,d)}}},p=o.match.POS,q=function(a,b){return"\\" (b-0 1)};for(var r in o.match)o.match[r]=new RegExp(o.match[r].source /(?![^\[]*\])(?![^\(]*\))/.source),o.leftMatch[r]=new RegExp(/(^(?:.|\r|\n)*?)/.source o.match[r].source.replace(/\\(\d )/g,q));o.match.globalPOS=p;var s=function(a,b){a=Array.prototype.slice.call(a,0);if(b){b.push.apply(b,a);return b}return a};try{Array.prototype.slice.call(c.documentElement.childNodes,0)[0].nodeType}catch(t){s=function(a,b){var c=0,d=b||[];if(g.call(a)==="[object Array]")Array.prototype.push.apply(d,a);else if(typeof a.length=="number")for(var e=a.length;c<e;c  )d.push(a[c]);else for(;a[c];c  )d.push(a[c]);return d}}var u,v;c.documentElement.compareDocumentPosition?u=function(a,b){if(a===b){h=!0;return 0}if(!a.compareDocumentPosition||!b.compareDocumentPosition)return a.compareDocumentPosition?-1:1;return a.compareDocumentPosition(b)&4?-1:1}:(u=function(a,b){if(a===b){h=!0;return 0}if(a.sourceIndex&&b.sourceIndex)return a.sourceIndex-b.sourceIndex;var c,d,e=[],f=[],g=a.parentNode,i=b.parentNode,j=g;if(g===i)return v(a,b);if(!g)return-1;if(!i)return 1;while(j)e.unshift(j),j=j.parentNode;j=i;while(j)f.unshift(j),j=j.parentNode;c=e.length,d=f.length;for(var k=0;k<c&&k<d;k  )if(e[k]!==f[k])return v(e[k],f[k]);return k===c?v(a,f[k],-1):v(e[k],b,1)},v=function(a,b,c){if(a===b)return c;var d=a.nextSibling;while(d){if(d===b)return-1;d=d.nextSibling}return 1}),function(){var a=c.createElement("div"),d="script" (new Date).getTime(),e=c.documentElement;a.innerHTML="<a name='" d "'/>",e.insertBefore(a,e.firstChild),c.getElementById(d)&&(o.find.ID=function(a,c,d){if(typeof c.getElementById!="undefined"&&!d){var e=c.getElementById(a[1]);return e?e.id===a[1]||typeof e.getAttributeNode!="undefined"&&e.getAttributeNode("id").nodeValue===a[1]?[e]:b:[]}},o.filter.ID=function(a,b){var c=typeof a.getAttributeNode!="undefined"&&a.getAttributeNode("id");return a.nodeType===1&&c&&c.nodeValue===b}),e.removeChild(a),e=a=null}(),function(){var a=c.createElement("div");a.appendChild(c.createComment("")),a.getElementsByTagName("*").length>0&&(o.find.TAG=function(a,b){var c=b.getElementsByTagName(a[1]);if(a[1]==="*"){var d=[];for(var e=0;c[e];e  )c[e].nodeType===1&&d.push(c[e]);c=d}return c}),a.innerHTML="<a href='#'></a>",a.firstChild&&typeof a.firstChild.getAttribute!="undefined"&&a.firstChild.getAttribute("href")!=="#"&&(o.attrHandle.href=function(a){return a.getAttribute("href",2)}),a=null}(),c.querySelectorAll&&function(){var a=m,b=c.createElement("div"),d="__sizzle__";b.innerHTML="<p class='TEST'></p>";if(!b.querySelectorAll||b.querySelectorAll(".TEST").length!==0){m=function(b,e,f,g){e=e||c;if(!g&&!m.isXML(e)){var h=/^(\w $)|^\.([\w\-] $)|^#([\w\-] $)/.exec(b);if(h&&(e.nodeType===1||e.nodeType===9)){if(h[1])return s(e.getElementsByTagName(b),f);if(h[2]&&o.find.CLASS&&e.getElementsByClassName)return s(e.getElementsByClassName(h[2]),f)}if(e.nodeType===9){if(b==="body"&&e.body)return s([e.body],f);if(h&&h[3]){var i=e.getElementById(h[3]);if(!i||!i.parentNode)return s([],f);if(i.id===h[3])return s([i],f)}try{return s(e.querySelectorAll(b),f)}catch(j){}}else if(e.nodeType===1&&e.nodeName.toLowerCase()!=="object"){var k=e,l=e.getAttribute("id"),n=l||d,p=e.parentNode,q=/^\s*[ ~]/.test(b);l?n=n.replace(/'/g,"\\$&"):e.setAttribute("id",n),q&&p&&(e=e.parentNode);try{if(!q||p)return s(e.querySelectorAll("[id='" n "'] " b),f)}catch(r){}finally{l||k.removeAttribute("id")}}}return a(b,e,f,g)};for(var e in a)m[e]=a[e];b=null}}(),function(){var a=c.documentElement,b=a.matchesSelector||a.mozMatchesSelector||a.webkitMatchesSelector||a.msMatchesSelector;if(b){var d=!b.call(c.createElement("div"),"div"),e=!1;try{b.call(c.documentElement,"[test!='']:sizzle")}catch(f){e=!0}m.matchesSelector=function(a,c){c=c.replace(/\=\s*([^'"\]]*)\s*\]/g,"='$1']");if(!m.isXML(a))try{if(e||!o.match.PSEUDO.test(c)&&!/!=/.test(c)){var f=b.call(a,c);if(f||!d||a.document&&a.document.nodeType!==11)return f}}catch(g){}return m(c,null,null,[a]).length>0}}}(),function(){var a=c.createElement("div");a.innerHTML="<div class='test e'></div><div class='test'></div>";if(!!a.getElementsByClassName&&a.getElementsByClassName("e").length!==0){a.lastChild.className="e";if(a.getElementsByClassName("e").length===1)return;o.order.splice(1,0,"CLASS"),o.find.CLASS=function(a,b,c){if(typeof b.getElementsByClassName!="undefined"&&!c)return b.getElementsByClassName(a[1])},a=null}}(),c.documentElement.contains?m.contains=function(a,b){return a!==b&&(a.contains?a.contains(b):!0)}:c.documentElement.compareDocumentPosition?m.contains=function(a,b){return!!(a.compareDocumentPosition(b)&16)}:m.contains=function(){return!1},m.isXML=function(a){var b=(a?a.ownerDocument||a:0).documentElement;return b?b.nodeName!=="HTML":!1};var y=function(a,b,c){var d,e=[],f="",g=b.nodeType?[b]:b;while(d=o.match.PSEUDO.exec(a))f =d[0],a=a.replace(o.match.PSEUDO,"");a=o.relative[a]?a "*":a;for(var h=0,i=g.length;h<i;h  )m(a,g[h],e,c);return m.filter(f,e)};m.attr=f.attr,m.selectors.attrMap={},f.find=m,f.expr=m.selectors,f.expr[":"]=f.expr.filters,f.unique=m.uniqueSort,f.text=m.getText,f.isXMLDoc=m.isXML,f.contains=m.contains}();var L=/Until$/,M=/^(?:parents|prevUntil|prevAll)/,N=/,/,O=/^.[^:#\[\.,]*$/,P=Array.prototype.slice,Q=f.expr.match.globalPOS,R={children:!0,contents:!0,next:!0,prev:!0};f.fn.extend({find:function(a){var b=this,c,d;if(typeof a!="string")return f(a).filter(function(){for(c=0,d=b.length;c<d;c  )if(f.contains(b[c],this))return!0});var e=this.pushStack("","find",a),g,h,i;for(c=0,d=this.length;c<d;c  ){g=e.length,f.find(a,this[c],e);if(c>0)for(h=g;h<e.length;h  )for(i=0;i<g;i  )if(e[i]===e[h]){e.splice(h--,1);break}}return e},has:function(a){var b=f(a);return this.filter(function(){for(var a=0,c=b.length;a<c;a  )if(f.contains(this,b[a]))return!0})},not:function(a){return this.pushStack(T(this,a,!1),"not",a)},filter:function(a){return this.pushStack(T(this,a,!0),"filter",a)},is:function(a){return!!a&&(typeof a=="string"?Q.test(a)?f(a,this.context).index(this[0])>=0:f.filter(a,this).length>0:this.filter(a).length>0)},closest:function(a,b){var c=[],d,e,g=this[0];if(f.isArray(a)){var h=1;while(g&&g.ownerDocument&&g!==b){for(d=0;d<a.length;d  )f(g).is(a[d])&&c.push({selector:a[d],elem:g,level:h});g=g.parentNode,h  }return c}var i=Q.test(a)||typeof a!="string"?f(a,b||this.context):0;for(d=0,e=this.length;d<e;d  ){g=this[d];while(g){if(i?i.index(g)>-1:f.find.matchesSelector(g,a)){c.push(g);break}g=g.parentNode;if(!g||!g.ownerDocument||g===b||g.nodeType===11)break}}c=c.length>1?f.unique(c):c;return this.pushStack(c,"closest",a)},index:function(a){if(!a)return this[0]&&this[0].parentNode?this.prevAll().length:-1;if(typeof a=="string")return f.inArray(this[0],f(a));return f.inArray(a.jquery?a[0]:a,this)},add:function(a,b){var c=typeof a=="string"?f(a,b):f.makeArray(a&&a.nodeType?[a]:a),d=f.merge(this.get(),c);return this.pushStack(S(c[0])||S(d[0])?d:f.unique(d))},andSelf:function(){return this.add(this.prevObject)}}),f.each({parent:function(a){var b=a.parentNode;return b&&b.nodeType!==11?b:null},parents:function(a){return f.dir(a,"parentNode")},parentsUntil:function(a,b,c){return f.dir(a,"parentNode",c)},next:function(a){return f.nth(a,2,"nextSibling")},prev:function(a){return f.nth(a,2,"previousSibling")},nextAll:function(a){return f.dir(a,"nextSibling")},prevAll:function(a){return f.dir(a,"previousSibling")},nextUntil:function(a,b,c){return f.dir(a,"nextSibling",c)},prevUntil:function(a,b,c){return f.dir(a,"previousSibling",c)},siblings:function(a){return f.sibling((a.parentNode||{}).firstChild,a)},children:function(a){return f.sibling(a.firstChild)},contents:function(a){return f.nodeName(a,"iframe")?a.contentDocument||a.contentWindow.document:f.makeArray(a.childNodes)}},function(a,b){f.fn[a]=function(c,d){var e=f.map(this,b,c);L.test(a)||(d=c),d&&typeof d=="string"&&(e=f.filter(d,e)),e=this.length>1&&!R[a]?f.unique(e):e,(this.length>1||N.test(d))&&M.test(a)&&(e=e.reverse());return this.pushStack(e,a,P.call(arguments).join(","))}}),f.extend({filter:function(a,b,c){c&&(a=":not(" a ")");return b.length===1?f.find.matchesSelector(b[0],a)?[b[0]]:[]:f.find.matches(a,b)},dir:function(a,c,d){var e=[],g=a[c];while(g&&g.nodeType!==9&&(d===b||g.nodeType!==1||!f(g).is(d)))g.nodeType===1&&e.push(g),g=g[c];return e},nth:function(a,b,c,d){b=b||1;var e=0;for(;a;a=a[c])if(a.nodeType===1&&  e===b)break;return a},sibling:function(a,b){var c=[];for(;a;a=a.nextSibling)a.nodeType===1&&a!==b&&c.push(a);return c}});var V="abbr|article|aside|audio|bdi|canvas|data|datalist|details|figcaption|figure|footer|header|hgroup|mark|meter|nav|output|progress|section|summary|time|video",W=/ jQuery\d ="(?:\d |null)"/g,X=/^\s /,Y=/<(?!area|br|col|embed|hr|img|input|link|meta|param)(([\w:] )[^>]*)\/>/ig,Z=/<([\w:] )/,$=/<tbody/i,_=/<|&#?\w ;/,ba=/<(?:script|style)/i,bb=/<(?:script|object|embed|option|style)/i,bc=new RegExp("<(?:" V ")[\\s/>]","i"),bd=/checked\s*(?:[^=]|=\s*.checked.)/i,be=/\/(java|ecma)script/i,bf=/^\s*<!(?:\[CDATA\[|\-\-)/,bg={option:[1,"<select multiple='multiple'>","</select>"],legend:[1,"<fieldset>","</fieldset>"],thead:[1,"<table>","</table>"],tr:[2,"<table><tbody>","</tbody></table>"],td:[3,"<table><tbody><tr>","</tr></tbody></table>"],col:[2,"<table><tbody></tbody><colgroup>","</colgroup></table>"],area:[1,"<map>","</map>"],_default:[0,"",""]},bh=U(c);bg.optgroup=bg.option,bg.tbody=bg.tfoot=bg.colgroup=bg.caption=bg.thead,bg.th=bg.td,f.support.htmlSerialize||(bg._default=[1,"div<div>","</div>"]),f.fn.extend({text:function(a){return f.access(this,function(a){return a===b?f.text(this):this.empty().append((this[0]&&this[0].ownerDocument||c).createTextNode(a))},null,a,arguments.length)},wrapAll:function(a){if(f.isFunction(a))return this.each(function(b){f(this).wrapAll(a.call(this,b))});if(this[0]){var b=f(a,this[0].ownerDocument).eq(0).clone(!0);this[0].parentNode&&b.insertBefore(this[0]),b.map(function(){var a=this;while(a.firstChild&&a.firstChild.nodeType===1)a=a.firstChild;return a}).append(this)}return this},wrapInner:function(a){if(f.isFunction(a))return this.each(function(b){f(this).wrapInner(a.call(this,b))});return this.each(function(){var b=f(this),c=b.contents();c.length?c.wrapAll(a):b.append(a)})},wrap:function(a){var b=f.isFunction(a);return this.each(function(c){f(this).wrapAll(b?a.call(this,c):a)})},unwrap:function(){return this.parent().each(function(){f.nodeName(this,"body")||f(this).replaceWith(this.childNodes)}).end()},append:function(){return this.domManip(arguments,!0,function(a){this.nodeType===1&&this.appendChild(a)})},prepend:function(){return this.domManip(arguments,!0,function(a){this.nodeType===1&&this.insertBefore(a,this.firstChild)})},before:function(){if(this[0]&&this[0].parentNode)return this.domManip(arguments,!1,function(a){this.parentNode.insertBefore(a,this)});if(arguments.length){var a=f
.clean(arguments);a.push.apply(a,this.toArray());return this.pushStack(a,"before",arguments)}},after:function(){if(this[0]&&this[0].parentNode)return this.domManip(arguments,!1,function(a){this.parentNode.insertBefore(a,this.nextSibling)});if(arguments.length){var a=this.pushStack(this,"after",arguments);a.push.apply(a,f.clean(arguments));return a}},remove:function(a,b){for(var c=0,d;(d=this[c])!=null;c  )if(!a||f.filter(a,[d]).length)!b&&d.nodeType===1&&(f.cleanData(d.getElementsByTagName("*")),f.cleanData([d])),d.parentNode&&d.parentNode.removeChild(d);return this},empty:function(){for(var a=0,b;(b=this[a])!=null;a  ){b.nodeType===1&&f.cleanData(b.getElementsByTagName("*"));while(b.firstChild)b.removeChild(b.firstChild)}return this},clone:function(a,b){a=a==null?!1:a,b=b==null?a:b;return this.map(function(){return f.clone(this,a,b)})},html:function(a){return f.access(this,function(a){var c=this[0]||{},d=0,e=this.length;if(a===b)return c.nodeType===1?c.innerHTML.replace(W,""):null;if(typeof a=="string"&&!ba.test(a)&&(f.support.leadingWhitespace||!X.test(a))&&!bg[(Z.exec(a)||["",""])[1].toLowerCase()]){a=a.replace(Y,"<$1></$2>");try{for(;d<e;d  )c=this[d]||{},c.nodeType===1&&(f.cleanData(c.getElementsByTagName("*")),c.innerHTML=a);c=0}catch(g){}}c&&this.empty().append(a)},null,a,arguments.length)},replaceWith:function(a){if(this[0]&&this[0].parentNode){if(f.isFunction(a))return this.each(function(b){var c=f(this),d=c.html();c.replaceWith(a.call(this,b,d))});typeof a!="string"&&(a=f(a).detach());return this.each(function(){var b=this.nextSibling,c=this.parentNode;f(this).remove(),b?f(b).before(a):f(c).append(a)})}return this.length?this.pushStack(f(f.isFunction(a)?a():a),"replaceWith",a):this},detach:function(a){return this.remove(a,!0)},domManip:function(a,c,d){var e,g,h,i,j=a[0],k=[];if(!f.support.checkClone&&arguments.length===3&&typeof j=="string"&&bd.test(j))return this.each(function(){f(this).domManip(a,c,d,!0)});if(f.isFunction(j))return this.each(function(e){var g=f(this);a[0]=j.call(this,e,c?g.html():b),g.domManip(a,c,d)});if(this[0]){i=j&&j.parentNode,f.support.parentNode&&i&&i.nodeType===11&&i.childNodes.length===this.length?e={fragment:i}:e=f.buildFragment(a,this,k),h=e.fragment,h.childNodes.length===1?g=h=h.firstChild:g=h.firstChild;if(g){c=c&&f.nodeName(g,"tr");for(var l=0,m=this.length,n=m-1;l<m;l  )d.call(c?bi(this[l],g):this[l],e.cacheable||m>1&&l<n?f.clone(h,!0,!0):h)}k.length&&f.each(k,function(a,b){b.src?f.ajax({type:"GET",global:!1,url:b.src,async:!1,dataType:"script"}):f.globalEval((b.text||b.textContent||b.innerHTML||"").replace(bf,"/*$0*/")),b.parentNode&&b.parentNode.removeChild(b)})}return this}}),f.buildFragment=function(a,b,d){var e,g,h,i,j=a[0];b&&b[0]&&(i=b[0].ownerDocument||b[0]),i.createDocumentFragment||(i=c),a.length===1&&typeof j=="string"&&j.length<512&&i===c&&j.charAt(0)==="<"&&!bb.test(j)&&(f.support.checkClone||!bd.test(j))&&(f.support.html5Clone||!bc.test(j))&&(g=!0,h=f.fragments[j],h&&h!==1&&(e=h)),e||(e=i.createDocumentFragment(),f.clean(a,i,e,d)),g&&(f.fragments[j]=h?e:1);return{fragment:e,cacheable:g}},f.fragments={},f.each({appendTo:"append",prependTo:"prepend",insertBefore:"before",insertAfter:"after",replaceAll:"replaceWith"},function(a,b){f.fn[a]=function(c){var d=[],e=f(c),g=this.length===1&&this[0].parentNode;if(g&&g.nodeType===11&&g.childNodes.length===1&&e.length===1){e[b](this[0]);return this}for(var h=0,i=e.length;h<i;h  ){var j=(h>0?this.clone(!0):this).get();f(e[h])[b](j),d=d.concat(j)}return this.pushStack(d,a,e.selector)}}),f.extend({clone:function(a,b,c){var d,e,g,h=f.support.html5Clone||f.isXMLDoc(a)||!bc.test("<" a.nodeName ">")?a.cloneNode(!0):bo(a);if((!f.support.noCloneEvent||!f.support.noCloneChecked)&&(a.nodeType===1||a.nodeType===11)&&!f.isXMLDoc(a)){bk(a,h),d=bl(a),e=bl(h);for(g=0;d[g];  g)e[g]&&bk(d[g],e[g])}if(b){bj(a,h);if(c){d=bl(a),e=bl(h);for(g=0;d[g];  g)bj(d[g],e[g])}}d=e=null;return h},clean:function(a,b,d,e){var g,h,i,j=[];b=b||c,typeof b.createElement=="undefined"&&(b=b.ownerDocument||b[0]&&b[0].ownerDocument||c);for(var k=0,l;(l=a[k])!=null;k  ){typeof l=="number"&&(l ="");if(!l)continue;if(typeof l=="string")if(!_.test(l))l=b.createTextNode(l);else{l=l.replace(Y,"<$1></$2>");var m=(Z.exec(l)||["",""])[1].toLowerCase(),n=bg[m]||bg._default,o=n[0],p=b.createElement("div"),q=bh.childNodes,r;b===c?bh.appendChild(p):U(b).appendChild(p),p.innerHTML=n[1] l n[2];while(o--)p=p.lastChild;if(!f.support.tbody){var s=$.test(l),t=m==="table"&&!s?p.firstChild&&p.firstChild.childNodes:n[1]==="<table>"&&!s?p.childNodes:[];for(i=t.length-1;i>=0;--i)f.nodeName(t[i],"tbody")&&!t[i].childNodes.length&&t[i].parentNode.removeChild(t[i])}!f.support.leadingWhitespace&&X.test(l)&&p.insertBefore(b.createTextNode(X.exec(l)[0]),p.firstChild),l=p.childNodes,p&&(p.parentNode.removeChild(p),q.length>0&&(r=q[q.length-1],r&&r.parentNode&&r.parentNode.removeChild(r)))}var u;if(!f.support.appendChecked)if(l[0]&&typeof (u=l.length)=="number")for(i=0;i<u;i  )bn(l[i]);else bn(l);l.nodeType?j.push(l):j=f.merge(j,l)}if(d){g=function(a){return!a.type||be.test(a.type)};for(k=0;j[k];k  ){h=j[k];if(e&&f.nodeName(h,"script")&&(!h.type||be.test(h.type)))e.push(h.parentNode?h.parentNode.removeChild(h):h);else{if(h.nodeType===1){var v=f.grep(h.getElementsByTagName("script"),g);j.splice.apply(j,[k 1,0].concat(v))}d.appendChild(h)}}}return j},cleanData:function(a){var b,c,d=f.cache,e=f.event.special,g=f.support.deleteExpando;for(var h=0,i;(i=a[h])!=null;h  ){if(i.nodeName&&f.noData[i.nodeName.toLowerCase()])continue;c=i[f.expando];if(c){b=d[c];if(b&&b.events){for(var j in b.events)e[j]?f.event.remove(i,j):f.removeEvent(i,j,b.handle);b.handle&&(b.handle.elem=null)}g?delete i[f.expando]:i.removeAttribute&&i.removeAttribute(f.expando),delete d[c]}}}});var bp=/alpha\([^)]*\)/i,bq=/opacity=([^)]*)/,br=/([A-Z]|^ms)/g,bs=/^[\- ]?(?:\d*\.)?\d $/i,bt=/^-?(?:\d*\.)?\d (?!px)[^\d\s] $/i,bu=/^([\- ])=([\- .\de] )/,bv=/^margin/,bw={position:"absolute",visibility:"hidden",display:"block"},bx=["Top","Right","Bottom","Left"],by,bz,bA;f.fn.css=function(a,c){return f.access(this,function(a,c,d){return d!==b?f.style(a,c,d):f.css(a,c)},a,c,arguments.length>1)},f.extend({cssHooks:{opacity:{get:function(a,b){if(b){var c=by(a,"opacity");return c===""?"1":c}return a.style.opacity}}},cssNumber:{fillOpacity:!0,fontWeight:!0,lineHeight:!0,opacity:!0,orphans:!0,widows:!0,zIndex:!0,zoom:!0},cssProps:{"float":f.support.cssFloat?"cssFloat":"styleFloat"},style:function(a,c,d,e){if(!!a&&a.nodeType!==3&&a.nodeType!==8&&!!a.style){var g,h,i=f.camelCase(c),j=a.style,k=f.cssHooks[i];c=f.cssProps[i]||i;if(d===b){if(k&&"get"in k&&(g=k.get(a,!1,e))!==b)return g;return j[c]}h=typeof d,h==="string"&&(g=bu.exec(d))&&(d= (g[1] 1)* g[2] parseFloat(f.css(a,c)),h="number");if(d==null||h==="number"&&isNaN(d))return;h==="number"&&!f.cssNumber[i]&&(d ="px");if(!k||!("set"in k)||(d=k.set(a,d))!==b)try{j[c]=d}catch(l){}}},css:function(a,c,d){var e,g;c=f.camelCase(c),g=f.cssHooks[c],c=f.cssProps[c]||c,c==="cssFloat"&&(c="float");if(g&&"get"in g&&(e=g.get(a,!0,d))!==b)return e;if(by)return by(a,c)},swap:function(a,b,c){var d={},e,f;for(f in b)d[f]=a.style[f],a.style[f]=b[f];e=c.call(a);for(f in b)a.style[f]=d[f];return e}}),f.curCSS=f.css,c.defaultView&&c.defaultView.getComputedStyle&&(bz=function(a,b){var c,d,e,g,h=a.style;b=b.replace(br,"-$1").toLowerCase(),(d=a.ownerDocument.defaultView)&&(e=d.getComputedStyle(a,null))&&(c=e.getPropertyValue(b),c===""&&!f.contains(a.ownerDocument.documentElement,a)&&(c=f.style(a,b))),!f.support.pixelMargin&&e&&bv.test(b)&&bt.test(c)&&(g=h.width,h.width=c,c=e.width,h.width=g);return c}),c.documentElement.currentStyle&&(bA=function(a,b){var c,d,e,f=a.currentStyle&&a.currentStyle[b],g=a.style;f==null&&g&&(e=g[b])&&(f=e),bt.test(f)&&(c=g.left,d=a.runtimeStyle&&a.runtimeStyle.left,d&&(a.runtimeStyle.left=a.currentStyle.left),g.left=b==="fontSize"?"1em":f,f=g.pixelLeft "px",g.left=c,d&&(a.runtimeStyle.left=d));return f===""?"auto":f}),by=bz||bA,f.each(["height","width"],function(a,b){f.cssHooks[b]={get:function(a,c,d){if(c)return a.offsetWidth!==0?bB(a,b,d):f.swap(a,bw,function(){return bB(a,b,d)})},set:function(a,b){return bs.test(b)?b "px":b}}}),f.support.opacity||(f.cssHooks.opacity={get:function(a,b){return bq.test((b&&a.currentStyle?a.currentStyle.filter:a.style.filter)||"")?parseFloat(RegExp.$1)/100 "":b?"1":""},set:function(a,b){var c=a.style,d=a.currentStyle,e=f.isNumeric(b)?"alpha(opacity=" b*100 ")":"",g=d&&d.filter||c.filter||"";c.zoom=1;if(b>=1&&f.trim(g.replace(bp,""))===""){c.removeAttribute("filter");if(d&&!d.filter)return}c.filter=bp.test(g)?g.replace(bp,e):g " " e}}),f(function(){f.support.reliableMarginRight||(f.cssHooks.marginRight={get:function(a,b){return f.swap(a,{display:"inline-block"},function(){return b?by(a,"margin-right"):a.style.marginRight})}})}),f.expr&&f.expr.filters&&(f.expr.filters.hidden=function(a){var b=a.offsetWidth,c=a.offsetHeight;return b===0&&c===0||!f.support.reliableHiddenOffsets&&(a.style&&a.style.display||f.css(a,"display"))==="none"},f.expr.filters.visible=function(a){return!f.expr.filters.hidden(a)}),f.each({margin:"",padding:"",border:"Width"},function(a,b){f.cssHooks[a b]={expand:function(c){var d,e=typeof c=="string"?c.split(" "):[c],f={};for(d=0;d<4;d  )f[a bx[d] b]=e[d]||e[d-2]||e[0];return f}}});var bC=/ /g,bD=/\[\]$/,bE=/\r?\n/g,bF=/#.*$/,bG=/^(.*?):[ \t]*([^\r\n]*)\r?$/mg,bH=/^(?:color|date|datetime|datetime-local|email|hidden|month|number|password|range|search|tel|text|time|url|week)$/i,bI=/^(?:about|app|app\-storage|. \-extension|file|res|widget):$/,bJ=/^(?:GET|HEAD)$/,bK=/^\/\//,bL=/\?/,bM=/<script\b[^<]*(?:(?!<\/script>)<[^<]*)*<\/script>/gi,bN=/^(?:select|textarea)/i,bO=/\s /,bP=/([?&])_=[^&]*/,bQ=/^([\w\ \.\-] :)(?:\/\/([^\/?#:]*)(?::(\d ))?)?/,bR=f.fn.load,bS={},bT={},bU,bV,bW=["*/"] ["*"];try{bU=e.href}catch(bX){bU=c.createElement("a"),bU.href="",bU=bU.href}bV=bQ.exec(bU.toLowerCase())||[],f.fn.extend({load:function(a,c,d){if(typeof a!="string"&&bR)return bR.apply(this,arguments);if(!this.length)return this;var e=a.indexOf(" ");if(e>=0){var g=a.slice(e,a.length);a=a.slice(0,e)}var h="GET";c&&(f.isFunction(c)?(d=c,c=b):typeof c=="object"&&(c=f.param(c,f.ajaxSettings.traditional),h="POST"));var i=this;f.ajax({url:a,type:h,dataType:"html",data:c,complete:function(a,b,c){c=a.responseText,a.isResolved()&&(a.done(function(a){c=a}),i.html(g?f("<div>").append(c.replace(bM,"")).find(g):c)),d&&i.each(d,[c,b,a])}});return this},serialize:function(){return f.param(this.serializeArray())},serializeArray:function(){return this.map(function(){return this.elements?f.makeArray(this.elements):this}).filter(function(){return this.name&&!this.disabled&&(this.checked||bN.test(this.nodeName)||bH.test(this.type))}).map(function(a,b){var c=f(this).val();return c==null?null:f.isArray(c)?f.map(c,function(a,c){return{name:b.name,value:a.replace(bE,"\r\n")}}):{name:b.name,value:c.replace(bE,"\r\n")}}).get()}}),f.each("ajaxStart ajaxStop ajaxComplete ajaxError ajaxSuccess ajaxSend".split(" "),function(a,b){f.fn[b]=function(a){return this.on(b,a)}}),f.each(["get","post"],function(a,c){f[c]=function(a,d,e,g){f.isFunction(d)&&(g=g||e,e=d,d=b);return f.ajax({type:c,url:a,data:d,success:e,dataType:g})}}),f.extend({getScript:function(a,c){return f.get(a,b,c,"script")},getJSON:function(a,b,c){return f.get(a,b,c,"json")},ajaxSetup:function(a,b){b?b$(a,f.ajaxSettings):(b=a,a=f.ajaxSettings),b$(a,b);return a},ajaxSettings:{url:bU,isLocal:bI.test(bV[1]),global:!0,type:"GET",contentType:"application/x-www-form-urlencoded; charset=UTF-8",processData:!0,async:!0,accepts:{xml:"application/xml, text/xml",html:"text/html",text:"text/plain",json:"application/json, text/javascript","*":bW},contents:{xml:/xml/,html:/html/,json:/json/},responseFields:{xml:"responseXML",text:"responseText"},converters:{"* text":a.String,"text html":!0,"text json":f.parseJSON,"text xml":f.parseXML},flatOptions:{context:!0,url:!0}},ajaxPrefilter:bY(bS),ajaxTransport:bY(bT),ajax:function(a,c){function w(a,c,l,m){if(s!==2){s=2,q&&clearTimeout(q),p=b,n=m||"",v.readyState=a>0?4:0;var o,r,u,w=c,x=l?ca(d,v,l):b,y,z;if(a>=200&&a<300||a===304){if(d.ifModified){if(y=v.getResponseHeader("Last-Modified"))f.lastModified[k]=y;if(z=v.getResponseHeader("Etag"))f.etag[k]=z}if(a===304)w="notmodified",o=!0;else try{r=cb(d,x),w="success",o=!0}catch(A){w="parsererror",u=A}}else{u=w;if(!w||a)w="error",a<0&&(a=0)}v.status=a,v.statusText="" (c||w),o?h.resolveWith(e,[r,w,v]):h.rejectWith(e,[v,w,u]),v.statusCode(j),j=b,t&&g.trigger("ajax" (o?"Success":"Error"),[v,d,o?r:u]),i.fireWith(e,[v,w]),t&&(g.trigger("ajaxComplete",[v,d]),--f.active||f.event.trigger("ajaxStop"))}}typeof a=="object"&&(c=a,a=b),c=c||{};var d=f.ajaxSetup({},c),e=d.context||d,g=e!==d&&(e.nodeType||e instanceof f)?f(e):f.event,h=f.Deferred(),i=f.Callbacks("once memory"),j=d.statusCode||{},k,l={},m={},n,o,p,q,r,s=0,t,u,v={readyState:0,setRequestHeader:function(a,b){if(!s){var c=a.toLowerCase();a=m[c]=m[c]||a,l[a]=b}return this},getAllResponseHeaders:function(){return s===2?n:null},getResponseHeader:function(a){var c;if(s===2){if(!o){o={};while(c=bG.exec(n))o[c[1].toLowerCase()]=c[2]}c=o[a.toLowerCase()]}return c===b?null:c},overrideMimeType:function(a){s||(d.mimeType=a);return this},abort:function(a){a=a||"abort",p&&p.abort(a),w(0,a);return this}};h.promise(v),v.success=v.done,v.error=v.fail,v.complete=i.add,v.statusCode=function(a){if(a){var b;if(s<2)for(b in a)j[b]=[j[b],a[b]];else b=a[v.status],v.then(b,b)}return this},d.url=((a||d.url) "").replace(bF,"").replace(bK,bV[1] "//"),d.dataTypes=f.trim(d.dataType||"*").toLowerCase().split(bO),d.crossDomain==null&&(r=bQ.exec(d.url.toLowerCase()),d.crossDomain=!(!r||r[1]==bV[1]&&r[2]==bV[2]&&(r[3]||(r[1]==="http:"?80:443))==(bV[3]||(bV[1]==="http:"?80:443)))),d.data&&d.processData&&typeof d.data!="string"&&(d.data=f.param(d.data,d.traditional)),bZ(bS,d,c,v);if(s===2)return!1;t=d.global,d.type=d.type.toUpperCase(),d.hasContent=!bJ.test(d.type),t&&f.active  ===0&&f.event.trigger("ajaxStart");if(!d.hasContent){d.data&&(d.url =(bL.test(d.url)?"&":"?") d.data,delete d.data),k=d.url;if(d.cache===!1){var x=f.now(),y=d.url.replace(bP,"$1_=" x);d.url=y (y===d.url?(bL.test(d.url)?"&":"?") "_=" x:"")}}(d.data&&d.hasContent&&d.contentType!==!1||c.contentType)&&v.setRequestHeader("Content-Type",d.contentType),d.ifModified&&(k=k||d.url,f.lastModified[k]&&v.setRequestHeader("If-Modified-Since",f.lastModified[k]),f.etag[k]&&v.setRequestHeader("If-None-Match",f.etag[k])),v.setRequestHeader("Accept",d.dataTypes[0]&&d.accepts[d.dataTypes[0]]?d.accepts[d.dataTypes[0]] (d.dataTypes[0]!=="*"?", " bW "; q=0.01":""):d.accepts["*"]);for(u in d.headers)v.setRequestHeader(u,d.headers[u]);if(d.beforeSend&&(d.beforeSend.call(e,v,d)===!1||s===2)){v.abort();return!1}for(u in{success:1,error:1,complete:1})v[u](d[u]);p=bZ(bT,d,c,v);if(!p)w(-1,"No Transport");else{v.readyState=1,t&&g.trigger("ajaxSend",[v,d]),d.async&&d.timeout>0&&(q=setTimeout(function(){v.abort("timeout")},d.timeout));try{s=1,p.send(l,w)}catch(z){if(s<2)w(-1,z);else throw z}}return v},param:function(a,c){var d=[],e=function(a,b){b=f.isFunction(b)?b():b,d[d.length]=encodeURIComponent(a) "=" encodeURIComponent(b)};c===b&&(c=f.ajaxSettings.traditional);if(f.isArray(a)||a.jquery&&!f.isPlainObject(a))f.each(a,function(){e(this.name,this.value)});else for(var g in a)b_(g,a[g],c,e);return d.join("&").replace(bC," ")}}),f.extend({active:0,lastModified:{},etag:{}});var cc=f.now(),cd=/(\=)\?(&|$)|\?\?/i;f.ajaxSetup({jsonp:"callback",jsonpCallback:function(){return f.expando "_" cc  }}),f.ajaxPrefilter("json jsonp",function(b,c,d){var e=typeof b.data=="string"&&/^application\/x\-www\-form\-urlencoded/.test(b.contentType);if(b.dataTypes[0]==="jsonp"||b.jsonp!==!1&&(cd.test(b.url)||e&&cd.test(b.data))){var g,h=b.jsonpCallback=f.isFunction(b.jsonpCallback)?b.jsonpCallback():b.jsonpCallback,i=a[h],j=b.url,k=b.data,l="$1" h "$2";b.jsonp!==!1&&(j=j.replace(cd,l),b.url===j&&(e&&(k=k.replace(cd,l)),b.data===k&&(j =(/\?/.test(j)?"&":"?") b.jsonp "=" h))),b.url=j,b.data=k,a[h]=function(a){g=[a]},d.always(function(){a[h]=i,g&&f.isFunction(i)&&a[h](g[0])}),b.converters["script json"]=function(){g||f.error(h " was not called");return g[0]},b.dataTypes[0]="json";return"script"}}),f.ajaxSetup({accepts:{script:"text/javascript, application/javascript, application/ecmascript, application/x-ecmascript"},contents:{script:/javascript|ecmascript/},converters:{"text script":function(a){f.globalEval(a);return a}}}),f.ajaxPrefilter("script",function(a){a.cache===b&&(a.cache=!1),a.crossDomain&&(a.type="GET",a.global=!1)}),f.ajaxTransport("script",function(a){if(a.crossDomain){var d,e=c.head||c.getElementsByTagName("head")[0]||c.documentElement;return{send:function(f,g){d=c.createElement("script"),d.async="async",a.scriptCharset&&(d.charset=a.scriptCharset),d.src=a.url,d.onload=d.onreadystatechange=function(a,c){if(c||!d.readyState||/loaded|complete/.test(d.readyState))d.onload=d.onreadystatechange=null,e&&d.parentNode&&e.removeChild(d),d=b,c||g(200,"success")},e.insertBefore(d,e.firstChild)},abort:function(){d&&d.onload(0,1)}}}});var ce=a.ActiveXObject?function(){for(var a in cg)cg[a](0,1)}:!1,cf=0,cg;f.ajaxSettings.xhr=a.ActiveXObject?function(){return!this.isLocal&&ch()||ci()}:ch,function(a){f.extend(f.support,{ajax:!!a,cors:!!a&&"withCredentials"in a})}(f.ajaxSettings.xhr()),f.support.ajax&&f.ajaxTransport(function(c){if(!c.crossDomain||f.support.cors){var d;return{send:function(e,g){var h=c.xhr(),i,j;c.username?h.open(c.type,c.url,c.async,c.username,c.password):h.open(c.type,c.url,c.async);if(c.xhrFields)for(j in c.xhrFields)h[j]=c.xhrFields[j];c.mimeType&&h.overrideMimeType&&h.overrideMimeType(c.mimeType),!c.crossDomain&&!e["X-Requested-With"]&&(e["X-Requested-With"]="XMLHttpRequest");try{for(j in e)h.setRequestHeader(j,e[j])}catch(k){}h.send(c.hasContent&&c.data||null),d=function(a,e){var j,k,l,m,n;try{if(d&&(e||h.readyState===4)){d=b,i&&(h.onreadystatechange=f.noop,ce&&delete cg[i]);if(e)h.readyState!==4&&h.abort();else{j=h.status,l=h.getAllResponseHeaders(),m={},n=h.responseXML,n&&n.documentElement&&(m.xml=n);try{m.text=h.responseText}catch(a){}try{k=h.statusText}catch(o){k=""}!j&&c.isLocal&&!c.crossDomain?j=m.text?200:404:j===1223&&(j=204)}}}catch(p){e||g(-1,p)}m&&g(j,k,m,l)},!c.async||h.readyState===4?d():(i=  cf,ce&&(cg||(cg={},f(a).unload(ce)),cg[i]=d),h.onreadystatechange=d)},abort:function(){d&&d(0,1)}}}});var cj={},ck,cl,cm=/^(?:toggle|show|hide)$/,cn=/^([ \-]=)?([\d .\-] )([a-z%]*)$/i,co,cp=[["height","marginTop","marginBottom","paddingTop","paddingBottom"],["width","marginLeft","marginRight","paddingLeft","paddingRight"],["opacity"]],cq;f.fn.extend({show:function(a,b,c){var d,e;if(a||a===0)return this.animate(ct("show",3),a,b,c);for(var g=0,h=this.length;g<h;g  )d=this[g],d.style&&(e=d.style.display,!f._data(d,"olddisplay")&&e==="none"&&(e=d.style.display=""),(e===""&&f.css(d,"display")==="none"||!f.contains(d.ownerDocument.documentElement,d))&&f._data(d,"olddisplay",cu(d.nodeName)));for(g=0;g<h;g  ){d=this[g];if(d.style){e=d.style.display;if(e===""||e==="none")d.style.display=f._data(d,"olddisplay")||""}}return this},hide:function(a,b,c){if(a||a===0)return this.animate(ct("hide",3),a,b,c);var d,e,g=0,h=this.length;for(;g<h;g  )d=this[g],d.style&&(e=f.css(d,"display"),e!=="none"&&!f._data(d,"olddisplay")&&f._data(d,"olddisplay",e));for(g=0;g<h;g  )this[g].style&&(this[g].style.display="none");return this},_toggle:f.fn.toggle,toggle:function(a,b,c){var d=typeof a=="boolean";f.isFunction(a)&&f.isFunction(b)?this._toggle.apply(this,arguments):a==null||d?this.each(function(){var b=d?a:f(this).is(":hidden");f(this)[b?"show":"hide"]()}):this.animate(ct("toggle",3),a,b,c);return this},fadeTo:function(a,b,c,d){return this.filter(":hidden").css("opacity",0).show().end().animate({opacity:b},a,c,d)},animate:function(a,b,c,d){function g(){e.queue===!1&&f._mark(this);var b=f.extend({},e),c=this.nodeType===1,d=c&&f(this).is(":hidden"),g,h,i,j,k,l,m,n,o,p,q;b.animatedProperties={};for(i in a){g=f.camelCase(i),i!==g&&(a[g]=a[i],delete a[i]);if((k=f.cssHooks[g])&&"expand"in k){l=k.expand(a[g]),delete a[g];for(i in l)i in a||(a[i]=l[i])}}for(g in a){h=a[g],f.isArray(h)?(b.animatedProperties[g]=h[1],h=a[g]=h[0]):b.animatedProperties[g]=b.specialEasing&&b.specialEasing[g]||b.easing||"swing";if(h==="hide"&&d||h==="show"&&!d)return b.complete.call(this);c&&(g==="height"||g==="width")&&(b.overflow=[this.style.overflow,this.style.overflowX,this.style.overflowY],f.css(this,"display")==="inline"&&f.css(this,"float")==="none"&&(!f.support.inlineBlockNeedsLayout||cu(this.nodeName)==="inline"?this.style.display="inline-block":this.style.zoom=1))}b.overflow!=null&&(this.style.overflow="hidden");for(i in a)j=new f.fx(this,b,i),h=a[i],cm.test(h)?(q=f._data(this,"toggle" i)||(h==="toggle"?d?"show":"hide":0),q?(f._data(this,"toggle" i,q==="show"?"hide":"show"),j[q]()):j[h]()):(m=cn.exec(h),n=j.cur(),m?(o=parseFloat(m[2]),p=m[3]||(f.cssNumber[i]?"":"px"),p!=="px"&&(f.style(this,i,(o||1) p),n=(o||1)/j.cur()*n,f.style(this,i,n p)),m[1]&&(o=(m[1]==="-="?-1:1)*o n),j.custom(n,o,p)):j.custom(n,h,""));return!0}var e=f.speed(b,c,d);if(f.isEmptyObject(a))return this.each(e.complete,[!1]);a=f.extend({},a);return e.queue===!1?this.each(g):this.queue(e.queue,g)},stop:function(a,c,d){typeof a!="string"&&(d=c,c=a,a=b),c&&a!==!1&&this.queue(a||"fx",[]);return this.each(function(){function h(a,b,c){var e=b[c];f.removeData(a,c,!0),e.stop(d)}var b,c=!1,e=f.timers,g=f._data(this);d||f._unmark(!0,this);if(a==null)for(b in g)g[b]&&g[b].stop&&b.indexOf(".run")===b.length-4&&h(this,g,b);else g[b=a ".run"]&&g[b].stop&&h(this,g,b);for(b=e.length;b--;)e[b].elem===this&&(a==null||e[b].queue===a)&&(d?e[b](!0):e[b].saveState(),c=!0,e.splice(b,1));(!d||!c)&&f.dequeue(this,a)})}}),f.each({slideDown:ct("show",1),slideUp:ct("hide",1),slideToggle:ct("toggle",1),fadeIn:{opacity:"show"},fadeOut:{opacity:"hide"},fadeToggle:{opacity:"toggle"}},function(a,b){f.fn[a]=function(a,c,d){return this.animate(b,a,c,d)}}),f.extend({speed:function(a,b,c){var d=a&&typeof a=="object"?f.extend({},a):{complete:c||!c&&b||f.isFunction(a)&&a,duration:a,easing:c&&b||b&&!f.isFunction(b)&&b};d.duration=f.fx.off?0:typeof d.duration=="number"?d.duration:d.duration in f.fx.speeds?f.fx.speeds[d.duration]:f.fx.speeds._default;if(d.queue==null||d.queue===!0)d.queue="fx";d.old=d.complete,d.complete=function(a){f.isFunction(d.old)&&d.old.call(this),d.queue?f.dequeue(this,d.queue):a!==!1&&f._unmark(this)};return d},easing:{linear:function(a){return a},swing:function(a){return-Math.cos(a*Math.PI)/2 .5}},timers:[],fx:function(a,b,c){this.options=b,this.elem=a,this.prop=c,b.orig=b.orig||{}}}),f.fx.prototype={update:function(){this.options.step&&this.options.step.call(this.elem,this.now,this),(f.fx.step[this.prop]||f.fx.step._default)(this)},cur:function(){if(this.elem[this.prop]!=null&&(!this.elem.style||this.elem.style[this.prop]==null))return this.elem[this.prop];var a,b=f.css(this.elem,this.prop);return isNaN(a=parseFloat(b))?!b||b==="auto"?0:b:a},custom:function(a,c,d){function h(a){return e.step(a)}var e=this,g=f.fx;this.startTime=cq||cr(),this.end=c,this.now=this.start=a,this.pos=this.state=0,this.unit=d||this.unit||(f.cssNumber[this.prop]?"":"px"),h.queue=this.options.queue,h.elem=this.elem,h.saveState=function(){f._data(e.elem,"fxshow" e.prop)===b&&(e.options.hide?f._data(e.elem,"fxshow" e.prop,e.start):e.options.show&&f._data(e.elem,"fxshow" e.prop,e.end))},h()&&f.timers.push(h)&&!co&&(co=setInterval(g.tick,g.interval))},show:function(){var a=f._data(this.elem,"fxshow" this.prop);this.options.orig[this.prop]=a||f.style(this.elem,this.prop),this.options.show=!0,a!==b?this.custom(this.cur(),a):this.custom(this.prop==="width"||this.prop==="height"?1:0,this.cur()),f(this.elem).show()},hide:function(){this.options.orig[this.prop]=f._data(this.elem,"fxshow" this.prop)||f.style(this.elem,this.prop),this.options.hide=!0,this.custom(this.cur(),0)},step:function(a){var b,c,d,e=cq||cr(),g=!0,h=this.elem,i=this.options;if(a||e>=i.duration this.startTime){this.now=this.end,this.pos=this.state=1,this.update(),i.animatedProperties[this.prop]=!0;for(b in i.animatedProperties)i.animatedProperties[b]!==!0&&(g=!1);if(g){i.overflow!=null&&!f.support.shrinkWrapBlocks&&f.each(["","X","Y"],function(a,b){h.style["overflow" b]=i.overflow[a]}),i.hide&&f(h).hide();if(i.hide||i.show)for(b in i.animatedProperties)f.style(h,b,i.orig[b]),f.removeData(h,"fxshow" b,!0),f.removeData(h,"toggle" b,!0);d=i.complete,d&&(i.complete=!1,d.call(h))}return!1}i.duration==Infinity?this.now=e:(c=e-this.startTime,this.state=c/i.duration,this.pos=f.easing[i.animatedProperties[this.prop]](this.state,c,0,1,i.duration),this.now=this.start (this.end-this.start)*this.pos),this.update();return!0}},f.extend(f.fx,{tick:function(){var a,b=f.timers,c=0;for(;c<b.length;c  )a=b[c],!a()&&b[c]===a&&b.splice(c--,1);b.length||f.fx.stop()},interval:13,stop:function(){clearInterval(co),co=null},speeds:{slow:600,fast:200,_default:400},step:{opacity:function(a){f.style(a.elem,"opacity",a.now)},_default:function(a){a.elem.style&&a.elem.style[a.prop]!=null?a.elem.style[a.prop]=a.now a.unit:a.elem[a.prop]=a.now}}}),f.each(cp.concat.apply([],cp),function(a,b){b.indexOf("margin")&&(f.fx.step[b]=function(a){f.style(a.elem,b,Math.max(0,a.now) a.unit)})}),f.expr&&f.expr.filters&&(f.expr.filters.animated=function(a){return f.grep(f.timers,function(b){return a===b.elem}).length});var cv,cw=/^t(?:able|d|h)$/i,cx=/^(?:body|html)$/i;"getBoundingClientRect"in c.documentElement?cv=function(a,b,c,d){try{d=a.getBoundingClientRect()}catch(e){}if(!d||!f.contains(c,a))return d?{top:d.top,left:d.left}:{top:0,left:0};var g=b.body,h=cy(b),i=c.clientTop||g.clientTop||0,j=c.clientLeft||g.clientLeft||0,k=h.pageYOffset||f.support.boxModel&&c.scrollTop||g.scrollTop,l=h.pageXOffset||f.support.boxModel&&c.scrollLeft||g.scrollLeft,m=d.top k-i,n=d.left l-j;return{top:m,left:n}}:cv=function(a,b,c){var d,e=a.offsetParent,g=a,h=b.body,i=b.defaultView,j=i?i.getComputedStyle(a,null):a.currentStyle,k=a.offsetTop,l=a.offsetLeft;while((a=a.parentNode)&&a!==h&&a!==c){if(f.support.fixedPosition&&j.position==="fixed")break;d=i?i.getComputedStyle(a,null):a.currentStyle,k-=a.scrollTop,l-=a.scrollLeft,a===e&&(k =a.offsetTop,l =a.offsetLeft,f.support.doesNotAddBorder&&(!f.support.doesAddBorderForTableAndCells||!cw.test(a.nodeName))&&(k =parseFloat(d.borderTopWidth)||0,l =parseFloat(d.borderLeftWidth)||0),g=e,e=a.offsetParent),f.support.subtractsBorderForOverflowNotVisible&&d.overflow!=="visible"&&(k =parseFloat(d.borderTopWidth)||0,l =parseFloat(d.borderLeftWidth)||0),j=d}if(j.position==="relative"||j.position==="static")k =h.offsetTop,l =h.offsetLeft;f.support.fixedPosition&&j.position==="fixed"&&(k =Math.max(c.scrollTop,h.scrollTop),l =Math.max(c.scrollLeft,h.scrollLeft));return{top:k,left:l}},f.fn.offset=function(a){if(arguments.length)return a===b?this:this.each(function(b){f.offset.setOffset(this,a,b)});var c=this[0],d=c&&c.ownerDocument;if(!d)return null;if(c===d.body)return f.offset.bodyOffset(c);return cv(c,d,d.documentElement)},f.offset={bodyOffset:function(a){var b=a.offsetTop,c=a.offsetLeft;f.support.doesNotIncludeMarginInBodyOffset&&(b =parseFloat(f.css(a,"marginTop"))||0,c =parseFloat(f.css(a,"marginLeft"))||0);return{top:b,left:c}},setOffset:function(a,b,c){var d=f.css(a,"position");d==="static"&&(a.style.position="relative");var e=f(a),g=e.offset(),h=f.css(a,"top"),i=f.css(a,"left"),j=(d==="absolute"||d==="fixed")&&f.inArray("auto",[h,i])>-1,k={},l={},m,n;j?(l=e.position(),m=l.top,n=l.left):(m=parseFloat(h)||0,n=parseFloat(i)||0),f.isFunction(b)&&(b=b.call(a,c,g)),b.top!=null&&(k.top=b.top-g.top m),b.left!=null&&(k.left=b.left-g.left n),"using"in b?b.using.call(a,k):e.css(k)}},f.fn.extend({position:function(){if(!this[0])return null;var a=this[0],b=this.offsetParent(),c=this.offset(),d=cx.test(b[0].nodeName)?{top:0,left:0}:b.offset();c.top-=parseFloat(f.css(a,"marginTop"))||0,c.left-=parseFloat(f.css(a,"marginLeft"))||0,d.top =parseFloat(f.css(b[0],"borderTopWidth"))||0,d.left =parseFloat(f.css(b[0],"borderLeftWidth"))||0;return{top:c.top-d.top,left:c.left-d.left}},offsetParent:function(){return this.map(function(){var a=this.offsetParent||c.body;while(a&&!cx.test(a.nodeName)&&f.css(a,"position")==="static")a=a.offsetParent;return a})}}),f.each({scrollLeft:"pageXOffset",scrollTop:"pageYOffset"},function(a,c){var d=/Y/.test(c);f.fn[a]=function(e){return f.access(this,function(a,e,g){var h=cy(a);if(g===b)return h?c in h?h[c]:f.support.boxModel&&h.document.documentElement[e]||h.document.body[e]:a[e];h?h.scrollTo(d?f(h).scrollLeft():g,d?g:f(h).scrollTop()):a[e]=g},a,e,arguments.length,null)}}),f.each({Height:"height",Width:"width"},function(a,c){var d="client" a,e="scroll" a,g="offset" a;f.fn["inner" a]=function(){var a=this[0];return a?a.style?parseFloat(f.css(a,c,"padding")):this[c]():null},f.fn["outer" a]=function(a){var b=this[0];return b?b.style?parseFloat(f.css(b,c,a?"margin":"border")):this[c]():null},f.fn[c]=function(a){return f.access(this,function(a,c,h){var i,j,k,l;if(f.isWindow(a)){i=a.document,j=i.documentElement[d];return f.support.boxModel&&j||i.body&&i.body[d]||j}if(a.nodeType===9){i=a.documentElement;if(i[d]>=i[e])return i[d];return Math.max(a.body[e],i[e],a.body[g],i[g])}if(h===b){k=f.css(a,c),l=parseFloat(k);return f.isNumeric(l)?l:k}f(a).css(c,h)},c,a,arguments.length,null)}}),a.jQuery=a.$=f,typeof define=="function"&&define.amd&&define.amd.jQuery&&define("jquery",[],function(){return f})})(window);/*------------------------------------------------------------------------
g_Measurements = new Exent.SDM.Measurements();
class Exent.SDM.Measurements
Exent.SDM.Measurements = function()
this.Send
this.AddParam
this.SendError
this.SendErrorReport
= SendErrorReport;
function Init(strURL)
AddParam( Exent.SDM.Defines.UrlParameter.Event, Exent.SDM.Defines.Measurements.Error );
AddParam( Exent.SDM.Defines.UrlParameter.ErrorCode, ErrorCode );
AddParam( Exent.SDM.Defines.UrlParameter.SDMVersion, Exent.SDM.Defines.Version);
AddParam( Exent.SDM.Defines.UrlParameter.OSType, top.GetExternalHandlerObject().GetOSType());
AddParam( Exent.SDM.Defines.UrlParameter.OS, getOS() );
if ( GetControllerObject().GetPageId() == Exent.SDM.Defines.PageId.ProgressPage )
AddParam( Exent.SDM.Defines.UrlParameter.PROGRESS, GetProgressObject().GetPrecentageComplete());
//in some cases we will have strParams - parse it's params and add them to url (and the file name)
for(i = 0; i < paramsArray.length; i  ){
AddParam( Exent.SDM.Defines.UrlParameter.FileName, top.GetConfigurationObject().BuildISUrlByAddons( top.g_AddOnsIndexArray ) );
SendErrorReport(ErrorCode);
m_StrParameters = m_StrParameters   Exent.SDM.Defines.UrlParameter.ParamSeparator;
m_StrParameters = m_StrParameters   ParamName   Exent.SDM.Defines.UrlParameter.SplitSeparator   ParamValue;
var url = GetConfigurationObject().GetReportURL();
if ( url == "" )
AddParam( Exent.SDM.Defines.UrlParameter.MUID, top.GetExternalHandlerObject().GetMuid( true) );
url = url   Exent.SDM.Defines.UrlParameter.FirstParamSeparator;
url = url   m_StrParameters;
return GetExternalHandlerObject().SendRequest("POST", url, false);
function SendErrorReport( ErrorCode )
var errorFilterString = GetConfigurationObject().GetErrorReportFilter();
var url = new String( GetConfigurationObject().GetErrorReportUrl() );
url = url.replace("%ErrorCode%", ErrorCode);
return GetExternalHandlerObject().SendErrorAndLogFile(url);
//returns an array of key and value
strParams = strParams.replace(/^\s\s*/, '').replace(/\s\s*$/, ''); // Trim whitespaces
strParams = strParams.replace(/^\,\,*/, '').replace(/\,\,*$/, ''); // Trim ","
var paramsArray = strParams.split(", ");//seperate params into array of substrings
for(i = 0; i < paramsArray.length; i  )
paramsArray[i] = paramsArray[i].split("=");//convert substrings into key and value
class Exent.SDM.PageUrlInfo
Exent.SDM.PageUrlInfo = function()
var m_BaseUrl = "";
var m_Msg = "";
this.LoadFromPageUrl
= LoadFromPageUrl;
this.ToURLString
= ToURLString;
this.ToResURLString
= ToResURLString;
this.SetBaseUrl
= SetBaseUrl;
this.SetPageId
this.SetGameName
this.SetGameId
this.SetMsg
= SetMsg;
this.SetParam1
this.SetParam2
this.SetErrorCode
this.SetAddons
this.SetType
this.GetBaseUrl
= GetBaseUrl;
this.GetMsg
= GetMsg;
this.GetParam1
this.GetParam2
this.GetErrorCode
this.GetAddons
this.GetType
PageUrlInfo::LoadFromPageUrl
Description: Load object parameters from url.
function LoadFromPageUrl()
var strURLParams;
var location = window.location.href
iTemp = location.indexOf(Exent.SDM.Defines.UrlParameter.FirstResParamSeparator);
strURLParams = location.substring(iTemp   1);
strURLParams = unescape(strURLParams);
arrParams = strURLParams.split(Exent.SDM.Defines.UrlParameter.ParamSeparator);
while(iTemp < arrParams.length)
arrParamData = arrParams[iTemp].split(Exent.SDM.Defines.UrlParameter.SplitSeparator);
case Exent.SDM.Defines.UrlParameter.PageId:
case Exent.SDM.Defines.UrlParameter.GameName:
case Exent.SDM.Defines.UrlParameter.GameId:
case Exent.SDM.Defines.UrlParameter.Msg:
m_Msg = GetParamValue( arrParamData );
case Exent.SDM.Defines.UrlParameter.Param1:
case Exent.SDM.Defines.UrlParameter.Param2:
case Exent.SDM.Defines.UrlParameter.ErrorCode:
case Exent.SDM.Defines.UrlParameter.Addons:
case Exent.SDM.Defines.UrlParameter.Type:
PageUrlInfo::GetParamValue
strParamValue = strParamValue   Exent.SDM.Defines.UrlParameter.SplitSeparator   arrParamData[i] ;
function GetBaseUrl()
return m_BaseUrl;
function GetMsg ( )
return m_Msg;
function SetBaseUrl( BaseUrl )
m_BaseUrl = BaseUrl;
function SetMsg ( Msg )
m_Msg = Msg;
PageUrlInfo::ToString
strParameters = Exent.SDM.Defines.UrlParameter.PageId   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_PageId;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.ParamSeparator;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.GameName   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_GameName;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.GameId   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_GameId;
if ( m_Msg != "" )
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.Msg   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_Msg;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.Param1   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_Param1;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.Param2   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_Param2;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.ErrorCode   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_ErrorCode;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.Addons   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_Addons;
strParameters = strParameters   Exent.SDM.Defines.UrlParameter.Addons   Exent.SDM.Defines.UrlParameter.SplitSeparator   m_Type;
function ToURLString()
var url = GetBaseUrl()   Exent.SDM.Defines.UrlParameter.FirstParamSeparator   ToString() ;
return url;
function ToResURLString()
var url = GetBaseUrl()   Exent.SDM.Defines.UrlParameter.FirstResParamSeparator   ToString() ;
g_Progress = new Exent.SDM.Progress();
class Exent.SDM.Progress
Exent.SDM.Progress = function()
this.Initialized = Initialized;
this.Pause = Pause;
this.Resume = Resume;
this.Update = Update;
this.GetTotalFileSize
this.GetPrecentageComplete
this.GetRemainsTime
this.GetRemainsTimeWithUnit
this.GetRaiseProgressBar
this.SetTotalFileSize
this.SetPrecentageComplete
this.SetRemainsTime
m_strTotalFileSize = top.GetExternalHandlerObject().GetDownloadInfo();
var timeToDownloadInMin = Math.floor( timeToDownloadInSec / 60 );
var timeToDownloadInHours = Math.floor( timeToDownloadInMin / 60 );
m_strTotalFileSize = Math.floor( strTotalFileSize / ( 1024 * 1024 ) ) ;
if ( strID == Exent.SDM.Defines.ErrorID.SDM_GAME_ADDED_TO_QUEUE_ERROR )
//TODO: Need to remove this code - client need to fix the crash when calling twice to openWebUiDialog.
case Exent.SDM.Defines.ErrorID.SDM_INVALID_PROVIDER_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_INTERNAL_ERROR :
case Exent.SDM.Defines.ErrorID.SDM_START_INSTALLATION_PROCESS_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_GENERAL_TRANSFER_ERROR
case Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_PRIVILEGES_ERROR
case Exent.SDM.Defines.ErrorID.SDM_IS_EXECUTION_FAILED:
case Exent.SDM.Defines.ErrorID.SDM_DOWNLOADING_ERROR :
case Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_NOT_ENOUGH_DISK_SPACE_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_CONTENT_ALREADY_QUEUED_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_IS_MONITOR_FILE_LOCKED_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_INITIALIZATION_OK:
// vista user canceled the UAC msg
case Exent.SDM.Defines.ErrorID.SDM_IS_INSTALLATION_CANCELED_ERROR:
if ( true == CheckIfUACSupportedOS() )
case Exent.SDM.Defines.ErrorID.SDM_IS_PROCESS_ABNORMAL_TERMINATION_ERROR:
case Exent.SDM.Defines.ErrorID.SDM_IS_COMPLETED_WITHOUT_NOTIFICATION_ERROR:
GetProgressObject().SetPrecentageComplete(strPrecentageCompleted);
GetProgressObject().SetRemainsTime(strTimeRemains);
GetPageLogic().UpdateProgressBar();
GetPageLogic().UpdateDownloadState(strState);
GetProgressObject().SetTotalFileSize(strInfo);
GetPageLogic().UpdateDownloadInfo();
xmlDoc = new ActiveXObject( "Msxml2.DOMDocument" );
Returns XML dom document with Strings.xml loaded
Try to get String.xml from web dialog external, if the function doesn't exist, get the string from GetStringsXml exteranl function.
g_StringsXMLDoc.async = false;
strStringsXml = external.WEBDLG_GetStringsXml();
strStringsXml = top.GetExternalHandlerObject().GetStringsXml();
g_StringsXMLDoc.loadXML( strStringsXml );
Description: returns the string value from strings.xml.
Get the value of string.xml using SDM-client external.
var StringsNode = objStringsXmlDoc.selectSingleNode( strQuery );
return StringsNode.nodeTypedValue;
Description: returns the string value from the res://resourceDll.dll/xml/SDMstrings.xml
var code = StringsNode.getAttribute( "code" );
Description: returns the string title from the res://resourceDll.dll/xml/SDMstrings.xml
if ( strTitle.length > 44 )
var newTitle = strTitle.substr( 0, 40 );
function GetGameImgURL( gameID )
Description: returns the full path of the image URL
return top.GetConfigurationObject().GetImgServerUrl()   "/products/"   gameID   "/"   top.GetConfigurationObject().GetGameImgName();
this.strAddOnID = strAddOnID;
this.isSelected = isSelected;
Mozilla/5.0 (Windows NT x.y; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
var nFind = navigator.userAgent.indexOf("Windows NT");
strOS = navigator.userAgent.substring(nFind   "Windows NT".length   1 , nFind   "Windows NT".length   4);
* Get only the Http Errors from the params string
* @returns string of HTTP errors and values
function getHttpErrors( strParams )
var strHttpErrors = "";
if ( paramsArray[i].indexOf("HTTPERROR::") >= 0 ) {
strHttpErrors  = paramsArray[i]  ", ";
return strHttpErrors;
var n = paramsArray.length;
<Value>Please close any internet browser windows (Explorer / Firefox / Chrome ) and click "Retry" to complete the installation. If you are still unable to complete the installation click the support button above to get assistance.</Value>
<Value><![CDATA[You were unable to connect to our servers. Please enable 'FreeRideGames.exe' in your firewall settings and check your internet connection, then click 'Retry'.]]></Value>
<Value>Insufficient privileges. To complete the installation, please download a fresh copy from the web site and then click the 'Continue' button when the 'User Account Control' window appears.</Value>
<Value>Resume download on next Windows startup</Value>
<Value>%State% (%PrecentageComplete%%) - %GameName%</Value>
<Value><![CDATA[You were unable to connect to our servers. Please enable 'FreeRideGames.exe' in your firewall settings and check your internet connection, then try again.]]> </Value>
<String Id="SDM_OS_NOT_SUPPORTED" code="4514">
<Value>OS version not supported</Value>
<String Id="SDM_IS_EXECUTION_FAILED" code="4516">
<Value><![CDATA[<!-- BoldChat Live Chat Button HTML v3.00 (Type=Web,ChatButton=FRG - SDM_Error,ChatWindow=FRG - SDM Error,Website=Free Ride Games,Department=FRG SDM) -->
<a href="hXXp://livechat.boldchat.com/aid/6100496956889327616/bc.chat?cwdid=497870019059070241&wdid=345418454248256988&rdid=3366175253394916188&vr=%VR%&vn=&vi=&ve=&vp=%VP_ERROR_CODE%&iq=&curl=" target="_blank" onclick="window.open((window.pageViewer && pageViewer.link || function(link){return link;})(this.href   (this.href.indexOf('?')>=0 ? '&' : '?')   'url='   escape(document.location.href)), 'Chat8664284951332268961', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=800,height=700');return false;">
<div><img alt="Live chat by BoldChat" src="hXXp://cbi.boldchat.com/aid/6100496956889327616/bc.cbi?cbdid=1288709240427314055&wdid=345418454248256988&rdid=3366175253394916188" border="0"/></div>
<Value><![CDATA[<!-- BoldChat Live Chat Button HTML v3.00 (Type=Web,ChatButton=FRG  - SDM_Error,ChatWindow=FRGPlus - SDM Error,Website=FRPlus,Department=FRG ) -->
<a href="hXXp://livechat.boldchat.com/aid/6100496956889327616/bc.chat?cwdid=1049236209672016035&wdid=921063878674411304&rdid=1189479500651305343&vr=%VR%&vn=&vi=&ve=&vp=%VP_ERROR_CODE%&iq=&curl=" target="_blank" onclick="window.open((window.pageViewer && pageViewer.link || function(link){return link;})(this.href   (this.href.indexOf('?')>=0 ? '&' : '?')   'url='   escape(document.location.href)), 'Chat5075368304374042356', 'toolbar=0,scrollbars=1,location=0,statusbar=0,menubar=0,resizable=1,width=800,height=700');return false;">
<div><img alt="Live chat by BoldChat" src="hXXp://cbi.boldchat.com/aid/6100496956889327616/bc.cbi?cbdid=4074922793695869156&wdid=921063878674411304&rdid=1189479500651305343" border="0" /></div>
GetCPInfo
.text
`.rdata
@.data
.rsrc
@.reloc
CONNECTIONLOST_MSG.HTML
DOWNLOADFAILED.HTML
EMPTYFOOTER.HTML
ENDINGFOOTER.HTML
ERROR_MSG.HTML
EULAFOOTER.HTML
EULAQUIT_MSG.HTML
GAMEADDEDTOQUEUE_MSG.HTML
GAMEALREADYINQUEUE_MSG.HTML
INDEX.HTML
INITIALIZED.HTML
INITIALIZEDFAILED.HTML
OCXLOCKED_MSG.HTML
OFFLINEHEADER.HTML
PAGEBODYOFFLINE.HTML
PROGRESSFOOTER.HTML
PROGRESSQUIT_MSG.HTML
UACCANCELED.HTML
VERSION.HTML
ASK_HEADER.GIF
BUBBLELEFT.GIF
BUBBLEMIDDLE.GIF
BUBBLERIGHT.GIF
CANCEL_UP.GIF
CLOSE_DISABLED.GIF
CLOSE_UP.GIF
CONNECTING_ANIM.GIF
CONNECTIONLOST.GIF
CONTINUEDOWNLOAD_UP.GIF
CONTINUE_UP.GIF
DISCONNECTED.GIF
ERROR_HEADER.GIF
EULAFOOTERSTRIPE.GIF
FOOTERSTRIPE.GIF
HEADER_PIXEL.GIF
HEADER_PIXEL_BLUE.GIF
HEADER_PIXEL_SMALL.GIF
I_AGREE_UP.GIF
MINIMIZE_UP.GIF
OK_UP.GIF
PROGRESSBARBOTTOM.GIF
PROGRESSBARFINISH.GIF
PROGRESSBARSTART.GIF
PROGRESSBARTOP.GIF
PROGRESSBARTOPANIMATED.GIF
QUIT_UP.GIF
RETRY_DISABLED.GIF
RETRY_UP.GIF
UACDIALOGBACKGROUND.JPG
WIZARDFOOTERSTRIPE.GIF
WIZARD_BACK_OFFLINE.GIF
CONFIGURATION.JS
CONF_DEFINES.JS
CONNECTION.JS
CONTROLLER.JS
DEFINES.JS
EXTRNALHANDLER.JS
FUNCTIONS.JS
GAMESINQUEUE.JS
JQUERY-1.7.2.MIN.JS
MEASUREMENTS.JS
PAGEURLINFO.JS
PROGRESS.JS
SDMHTMLINTERFACES.JS
UTIL.JS
SDMSTRINGS.XML
SKINCONFIG.XML
SDM.ICO

GPlayer.exe_472:

.text
`.rdata
@.data
.rsrc
u.Whh
bt<Ht.Ht Ht
u8SSh
SSSSh
SSSSSSh
vhSSSSSSh
u.Wh9!
PSSh,
j%SPQ
PSSSSSSh
E@SSSSShl?
t8Ht.Ht
HHt.Ht
.tTPV
?%u#f
FTPjK
FtPj;
F.PjRWj
u.WWj
u.VVj
>.ufFV
3|$@3|$\
3|$83|$@
3|$03|$$
3|$43|$(
3|$83|$$
3|$`3|$83|$$
3|$,3|$\
3|$@3|$,
3|$(3|$,
.VSWRQ
<.up3
<8%u=
.FGy/
Fd t.SPW
N.VAPQW
G.f;E.uJ3
N.AQPWjhS
N.AQS
N.AQUS
V.BRUS
f9~.vX
P$8^%uX
D8^Ht)SSh
u$SShe
?%uMf
mu2.iu`
ContentPushShowMsgDurationInSec
ContentStatusShowMsgDurationInSec
ParentalControlSupportUrl
RssFeedUrl
RssFeedUrlExtension
RssDefaultShowMsgDurationInSec
ProxyPort
AutoErrorReport
ParentalControlESRBRatingUrl
ParentalControlGODRatingUrl
AutoClientUpgradeCheckURL
ScheduleCmdlnStartUpDelayMSec
TKBaseUrl
DisableOnlineLicenseWebPages
RamMaxWindowSize
AccessWebPageConnectionTimeout
VersionXmlURL
OfflineFeedbackUrl
ScheduleCmdlnStartUpMgrConnectTries
ClientErrorLogUrl
BannerUrl
ClientMoreInfoUrl
ClientUpgradeUrl
client_web_ui_url
client_install_url
client_game_assets_url
client_osl_usage_report_url
game_frames_url
EndURL
Feedback_URL
Client_Report_URL
provider_service_url
client_schedule_url
shortcuts_base_url
client_get_rgmx_url
CmdlineSNumber
GameInfoURL
PlayerPostUpgradeCmdline
ContentPushAIGsListUrl
Content_CMD_Line
CmdOptions
CmdLine
CmdStartDir
CMDLINETYPE
CMDList
muid_integrity_key
ApsPort
CmdlineProviderDescription
CmdlineDescription
CmdlineProviderTitle
CmdlineTitle
PreloadMaxBandwidthBeforeCmdlnKBps
Prediction_Tx_URL
CD_Key_Info
CmdParams
global_user_cmdline_parameters_filter
Prediction_Rx_URL
InternetCheckUrls
user_settings_proxy_port
ClientCDMHttpOnConnectRetries
ClientCDMHttpConnectionTimeoutMS
ClientCDMHttpRequestsTimeoutMS
ClientCSMHttpOnConnectRetries
ClientCSMHttpConnectionTimeoutMS
ClientCSMHttpRequestsTimeoutMS
[%d.%d.%d.%d.%d]
Windows Installer
SOFTWARE\CLASSES\CLSID\{C46C1BC1-3C52-11D0-9200-848C1D000000}\InprocServer32
SOFTWARE\Microsoft\Windows NT\CurrentVersion\drivers.desc
SOFTWARE\Microsoft\Windows NT\CurrentVersion\OpenGLDrivers
SOFTWARE\Classes\MDACVer.Version\CurVer
QuickTimeCheckObject.QuickTimeCheck\CLSID
dplayx.dll
dxmedia.exe
QuickTime.cpl
Qtwmci32.dll
QuickTime.qts
Dirapi.dll
Iml32.dll
MSI.DLL
COMCTL32.DLL
CCmdTarget
CNotSupportedException
KERNEL32.DLL
__MSVCRT_HEAP_SELECT
portuguese-brazilian
RSA part of OpenSSL 0.9.8a 11 Oct 2005
passed a null parameter
DSO support routines
x509 certificate routines
error:lX:%s:%s:%s
USER32.DLL
NETAPI32.DLL
ADVAPI32.DLL
ssl_sess_cert
ssl_cert
evp_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
%d.%lu
.\crypto\evp\evp_key.c
nkey <= EVP_MAX_KEY_LENGTH
EVP part of OpenSSL 0.9.8a 11 Oct 2005
CERTIFICATE
cert_info
CERTIFICATE REQUEST
NEW CERTIFICATE REQUEST
RSA PRIVATE KEY
PUBLIC KEY
DSA PRIVATE KEY
EC PRIVATE KEY
Big Number part of OpenSSL 0.9.8a 11 Oct 2005
lhash part of OpenSSL 0.9.8a 11 Oct 2005
RAND part of OpenSSL 0.9.8a 11 Oct 2005
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
Stack part of OpenSSL 0.9.8a 11 Oct 2005
ASN.1 part of OpenSSL 0.9.8a 11 Oct 2005
RC4 part of OpenSSL 0.9.8a 11 Oct 2005
MD5 part of OpenSSL 0.9.8a 11 Oct 2005
PEM part of OpenSSL 0.9.8a 11 Oct 2005
phrase is too short, needs to be at least %d chars
Enter PEM pass phrase:
TRUSTED CERTIFICATE
X509 CERTIFICATE
PRIVATE KEY
ANY PRIVATE KEY
ENCRYPTED PRIVATE KEY
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
AUTHORITY_KEYID
keyid
X509_CERT_PAIR
X509_CERT_AUX
EC part of OpenSSL 0.9.8a 11 Oct 2005
.\crypto\ec\ec_key.c
ECDSA part of OpenSSL 0.9.8a 11 Oct 2005
DSA part of OpenSSL 0.9.8a 11 Oct 2005
Diffie-Hellman part of OpenSSL 0.9.8a 11 Oct 2005
value.single
value.set
pubkey
enc_key
key_enc_algor
cert
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
d.data
d.other
priv_key
pub_key
EC_PRIVATEKEY
publicKey
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
.\crypto\evp\evp_pkey.c
NETSCAPE_CERT_SEQUENCE
certs
.\crypto\pem\pem_pkey.c
SHA1 part of OpenSSL 0.9.8a 11 Oct 2005
SHA-256 part of OpenSSL 0.9.8a 11 Oct 2005
DlSHA-512 part of OpenSSL 0.9.8a 11 Oct 2005
Verifying - %s
%lu:%s:%s:%d:%s
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sCPS: %s
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
.\crypto\dh\dh_key.c
RIPE-MD160 part of OpenSSL 0.9.8a 11 Oct 2005
SHA part of OpenSSL 0.9.8a 11 Oct 2005
MD4 part of OpenSSL 0.9.8a 11 Oct 2005
MD2 part of OpenSSL 0.9.8a 11 Oct 2005
PROXY_CERT_INFO_EXTENSION
%d.%d.%d.%d
CONF part of OpenSSL 0.9.8a 11 Oct 2005
%d.%d.%d.%d/%d.%d.%d.%d
%*s%s:
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
name.relativename
name.fullname
<UNSUPPORTED>
.\crypto\x509v3\v3_akey.c
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
'() ,-./:=?
CONF_def part of OpenSSL 0.9.8a 11 Oct 2005
[[%s]]
[%s] %s=%s
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
%s - d:d:d %d%s
\X
- %-15s
%s.dll
3.8.1
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYHerF
Broken pipe
Inappropriate I/O control operation
Operation not permitted
WINMM.dll
USER32.dll
GDI32.dll
KERNEL32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
ADVAPI32.dll
ShellExecuteW
ShellExecuteA
ShellExecuteExA
SHELL32.dll
COMCTL32.dll
ole32.dll
OLEPRO32.DLL
OLEAUT32.dll
InternetCrackUrlW
InternetCrackUrlA
WININET.dll
WTSAPI32.dll
SHLWAPI.dll
ImageGetCertificateData
ImageGetCertificateHeader
ImageEnumerateCertificates
imagehlp.dll
WSOCK32.dll
VERSION.dll
MPR.dll
oledlg.dll
SensApi.dll
GetKeyState
MsgWaitForMultipleObjects
GetKeyNameTextW
MapVirtualKeyW
GetKeyboardLayout
GetAsyncKeyState
CreateDialogIndirectParamW
UnhookWindowsHookEx
SetWindowsHookExW
GetProcessWindowStation
SetWindowsHookExA
SetViewportOrgEx
GetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
GetWindowsDirectoryA
GetProcessHeap
GetWindowsDirectoryW
GetCPInfo
RegEnumKeyExA
RegCreateKeyExW
RegDeleteKeyA
RegEnumKeyA
ReportEventA
RegOpenKeyA
WINSPOOL.DRV
comdlg32.dll
CRYPT32.dll
ShellExecuteExW
HttpQueryInfoA
HttpEndRequestA
HttpSendRequestExA
HttpAddRequestHeadersA
HttpOpenRequestA
CommitUrlCacheEntryA
CreateUrlCacheEntryA
DeleteUrlCacheEntry
FindCloseUrlCache
FindNextUrlCacheEntryA
FindFirstUrlCacheEntryA
GPlayer.exe
%d, %d
IDS_CONTENT_PUSH_COMPLETE_INFO_MSG_FORMAT
IDS_CONTENT_PUSH_COMPLETE_TITLE_MSG_FORMAT
p_%u_general
IDS_CONTENT_INFO_MSG_FORMAT
IDS_CONTENT_TITLE_MSG_FORMAT
GetItem( %d )
%C,,%d,
Exentender_ContentIdGetRgmxForPlay_0d
AHTTPConnection
%d %d %s %S
%d %d %d %d %S
%S %d
GetExeDirPath
cid=%d, pid=%d
dest=%S
src=%S
%d, %S, %s, %S, %d, %d, %S, %S, %S
%S, %d
%S, %S, %d
%s %S
%d %d
%d,%d,%c,%d
IDS_SETTINGS_PARENTAL_CONTROL_ACTIVE_SUPPORT
IDS_SETTINGS_PARENTAL_CONTROL_ACTIVE_PASSWORD_RETRIEVED_INTRO
IDS_SETTINGS_PARENTAL_CONTROL_ACTIVE_FORGOT_PASSWORD
Wrong Password
Fill in password
&#%u;
_SetParam(),ContentId = %d, strSec = %s, strKey = %s
%d %d %s %s
Warning !!!! - Content doesn't exist %d
_GetParam(),ContentId = %d, strSec = %s, strKey = %s
%s_%d
CalculateProgress: m_dwLastTime = <%d>, m_LastTimeBytesRead = <%f> m_LastBytesPerSec = <%f>
trackEvent=playermessagedisplayed&rsschannelid=newuser&messageid=%s&time=%s
%d,%d,%d,%d
ASchedulingMgr::ActivateNextTask m_dwNextActivatedPriority = %d
ASchedulingMgr::Stop m_SchedulingStatus = %d
ASchedulingMgr::Execute m_SchedulingStatus = %d, ContentId = %d
Prevent double execute
%d %d %d %d
ASchedulingMgr::ClearTaskFailCount cid=%d, pid=%d
ASchedulingMgr::IncrementTaskFailCount cid=%d,pid=%d NewFailureCount = %d
ASchedulingMgr::NotifyScheduledTaskFailure m_CurrentExecutedContnetId = %d
cid=%d,pid=%d %s %s %s
cid=%d, pid=%d %s %s %s
IDS_EXETENDER_COPY_RIGHT
IDS_OPERATING_SYSTEM
IDS_LAST_EXECUTION
IDS_LICENSE_EXECUTIONS
%d,%d
%d,%d).
IDS_PORT
,%d,,
,%d,%d,
IDS_SETTINGS_GENERAL_AUTO_SEND_ERR_REPORT
Sounds (*.wav)|*.wav||
IDS_SETTINGS_PARENTAL_CONTROL_ACTIVE_PASSWORD_INTRO
IDS_SETTINGS_PARENTAL_CONTROL_ERROR_WRONG_PASSWORD
IDS_SETTINGS_PARENTAL_CONTROL_ERROR_NO_PASSWORD
IDS_SETTINGS_PARENTAL_CONTROL_PASSWORD_HINT_INTRO
IDS_SETTINGS_PARENTAL_CONTROL_CONFIRM_PASSWORD_INTRO
IDS_SETTINGS_PARENTAL_CONTROL_SET_PASSWORD_INTRO
IDS_SETTINGS_PARENTAL_CONTROL_ERROR_PASSWORD_CONFIRMATION_MISMATCH
IDS_SETTINGS_PARENTAL_CONTROL_ERROR_INVALID_PASSWORD
IDS_SETTINGS_PARENTAL_CONTROL_ERROR_EMPTY_PASSWORD
ASettingsSheet
%d,%d,,
ShContentFolderCmd_
ShStartMenuCmd_
ShDesktopCmd_
%s %S %d %d
%S %S %S %S %S %S %d
%d %s
%d %S
%S %S %S %S
%d %S %S %d
%S %S %S
%d %d %S %s %d
Shell32.dll
%S %d %S %s
%d %d %s %d
%S %S %d
%d %S %S
%S %d %S %S
IDS_START_MENU_SHORTCUT_STATUS_INITIAL_DOWNLOAD_COMPLETE_TRY_CMD1
IDS_START_MENU_SHORTCUT_STATUS_FULL_DOWNLOAD_COMPLETE_TRY_CMD1
IDS_START_MENU_SHORTCUT_STATUS_INITIAL_DOWNLOAD_COMPLETE_OFFLINE_ENABLED_TRY_CMD1
IDS_START_MENU_SHORTCUT_STATUS_FULL_DOWNLOAD_COMPLETE_OFFLINE_ENABLED_TRY_CMD1
IDS_START_MENU_SHORTCUT_STATUS_DOWNLOAD_TRY_CMD1
IDS_START_MENU_SHORTCUT_STATUS_INITIAL_DOWNLOAD_COMPLETE_PM_CMD1
IDS_START_MENU_SHORTCUT_STATUS_FULL_DOWNLOAD_COMPLETE_PM_CMD1
IDS_START_MENU_SHORTCUT_STATUS_DOWNLOAD_OFFLINE_ENABLED_CMD1
IDS_START_MENU_SHORTCUT_STATUS_INITIAL_DOWNLOAD_COMPLETE_OFFLINE_ENABLED_CMD1
IDS_START_MENU_SHORTCUT_STATUS_FULL_DOWNLOAD_COMPLETE_OFFLINE_ENABLED_CMD1
IDS_START_MENU_SHORTCUT_STATUS_DOWNLOAD_PM_CMD1
%d %s %S
%S %s
Content.md
ClientShortcutUrl
CurrnetCmdLine
MaxCmdLine
%d %s %s %d %d
%s %s %d %d
IDS_SILENT_UPGRADE_EXETENDER_UPDATE_DESC
IDS_SILENT_UPGRADE_EXETENDER_UPDATE_CAPTION
.PAVCException@@
FindItem() failed: GetItem( %d ) failed.
GetItem( %d )
CreateWindow() %d
RegisterClass() %d
UnregisterClass() %d
DestroyWindow() %d
Shell_NotifyIcon() %d
%A, %B %d, %Y
dwPercentComplete = %d
%s,Unable to create directory,%d
%s,Not a directory,
ShellExecute for strFileName = %s failed in AHttpShellExecute
ShellExecute for strFileName = %S failed in AHttpShellExecute
Skn%s_%S
EI%s_%S.exe
ReadFile,%S,%d
Opened %S on second try.
CreateFile,%S,%d
DeleteFile() %s,%d.
CopyFile() %S,%S,%d
"%S%S" %S
"%S%S" %S %d
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%d,%d,%d
%d %d %d
%S %S
%S&AppId=%d&RunIndex=%d&LangId=%x&AppName=%S&MUID=%s&PlayTimeLeft=%d&PlayCountLeft=%d&Type=%s&DisplayMode=%s
%S?AppId=%d&RunIndex=%d&LangId=%x&AppName=%S&MUID=%s&PlayTimeLeft=%d&PlayCountLeft=%d&Type=%s&DisplayMode=%s
FormatWebUIErrUrlParams szPostBuffer = %s
AppId=%d&AppName=%s&Type=%d&DisplayMode=%s&LangId=%x&License=%d&OfflineEnabled=%d&CDwnd=%I64u&IDwnd=%I64u&FDwnd=%I64u
WebUI
%s %d %d
IDS_WEB_UI_DEFAULT_PAGE_TITLE
IDS_WEB_UI_DELAYED_START_PAGE_TITLE
IDS_WEB_UI_AUTHENTICATION_PAGE
IDS_WEB_UI_END_SESSION_PAGE_TITLE
IDS_WEB_UI_TRIAL_LICENSE_EXPIRED_PAGE_TITLE
IDS_WEB_UI_PURCHASE_USE_END_PAGE_TITLE
IDS_WEB_UI_PURCHASE_USE_START_PAGE_TITLE
IDS_WEB_UI_TRIAL_END_PAGE_TITLE
IDS_WEB_UI_TRIAL_START_PAGE_TITLE
IDS_WEB_UI_INVALID_LICENSE_PAGE_TITLE
IDS_WEB_UI_LICENSE_EXPIRED_PAGE_TITLE
Exentender_ContentIdInUse_0d
Exentender_GUIActiveContent_0d
ValidateAndFixFileName() strFileName after validation = %S
HTTP/1.0
CGPlayerApp::CGPlayerApp() - m_SingletoneCreationMutex.Create failed
%s started
ExentCtl.ocx
GameInst.dll
%s version %s
IDS_EXETENDER_INFO
exs.dll
&MUID=%s
%s,%s
IsLaptop=%d
NotifyStatus status = %d, reason = %d, ContenId = %d, m_ContentId = %d
%d %d %d %d %d %d %s %d
%s, %d
%u %d
%d, %d, %d
%s,%d
%S %d,%d
%s,%s,%s,%s
ClientReportUrl
SOFTWARE\Exent\AOD\Client
%d,%d,%d,
%d, %d, %S
RunContent ContentId %d = SUCCESS
TerminateContent ContentId %d = SUCCESS
%d,%d,%d,%C,%d
IDS_LOCAL_EXECUTION_MISSING_DATA_QUESTION
RemoveContent ContentId %d = SUCCESS
%d,WaitForSingleObject return %d
IDS_BUTTON_EXENT_TOOL_TIP
SOFTWARE\Classes\Applications\GPlayer.exe
TRAY_ICON_BALLON_START_DOWNLOADING_MSG_FORMAT
TRAY_ICON_BALLON_PLAYER_MINIMIZED_MSG
TRAY_ICON_BALLON_PLAYER_FIRST_RUN_MSG
WaitForSingleObject() return %d
WaitForMultipleObjects() return %d
version.tmp
version.xml
version.xml.dat
version.ini
UsageReportMgr
%d, %d, %S, %d
%s %d %S %d
%d %S %d
owebui, type=%d
OnNotifyLicenseStatusMsg()
%S, %d, %S
IDS_ONLINE_EXECUTION_RECOMMENDATION_CLICK_NO
IDS_ONLINE_EXECUTION_RECOMMENDATION_CLICK_YES
IDS_ONLINE_EXECUTION_RECOMMENDATION_QUESTION
<none>, %S
%S, %S
SwitchSkin fail with skin code %s
SetLanguage fail with Language Id %d
cid=%d, m_cid=%d; pid=%d, m_pid=%d
cid=%d. pid=%d
.?AVMessageException@ExentExceptions@Exent@@
%S,%d
%s %d %s
%s %d %s %s
%s %d
%s%c%c%c
%s%c%c
<%S>, %d
NTDLL.DLL
XXXXXXXXX
Global\{EB900DF8-0D3D-46c3-9B60-1E7A0D34870A}
inetmib1.dll
WS2_32.dll
XXXXXX
SOFTWARE\Exent\AOD\Client\MUID
user32.dll
SOFTWARE\Exent\AOD\Client\Providers\%d\Settings\SkinCode
%s&AppId=%d&RunIndex=%d&PrvId=%d&AcID=%S&OpenShInIE=%d&PrvDir=%S
%s?AppId=%d&RunIndex=%d&PrvId=%d&AcID=%S&OpenShInIE=%d&PrvDir=%S
kernel32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket
AWebUIDlg
%d, %d, %d, %d
NavigateBrowser catch(...) Url = %S
TimerWndCLASS%d%s
TimerWndTITLE%d%s
IDispatch error #%d
SOFTWARE\Exent\AOD\Client\Reminders
%x.%x.%x.%x
SOFTWARE\Exent\AOD\Client\CLG
Global\.ALogMux
CLG Opened OK. Boot=d/d/d d:d:d Path=<%ws>
.?AVExentException@ExentExceptions@Exent@@
.?AVRuntimeException@ExentExceptions@Exent@@
.?AVSystemException@ExentExceptions@Exent@@
.?AVWaitOnLockException@ExentExceptions@Exent@@
.?AVNullPointerException@ExentExceptions@Exent@@
Err: timerThread: Wait return with invalid code: %u
AWebBrowserIE2
CWebBrowserIE
AWebBrowserIE2::SetHeadContext has changed from <%x> to <%x>
AWebBrowserIE2::NavigateEx called with the following parameters %S %S %S %x
%s %u
Scheme=%u, URL=%S
URL=%S, Schema=%S
AWebBrowserIE2::Stop called CWebBrowserIE::Stop()
AWebBrowserIE2::Stop cancel context <%x>
AWebBrowserIE2::OnAsyncHeadOK context <%x> is already canceled
AWebBrowserIE2::OnAsyncHeadFail context <%x> is already canceled
AWebBrowserIE2::destroyContext delete context <%x>
Skin=%s_Prov=%d
Strings.ini
Strings.xml
Langs/Lang[@Id="%S"]/%S[@Id="%S"]/%S
Langs/Lang[@Id="%S"]
Sft=%X, Ctrl=%X, Alt=%X, bck=%X, Tab=%X, wParam=%X
TranslateAccelerator (lpMsg->message=%d)
%s NotInUse %d
StoreStr %s %s hRoot=0xX rootPath=%s
OpenCreate %s %s hRoot=0xX rootPath=%s
StoreDWORD %s %s hRoot=0xX rootPath=%s
SOFTWARE\Exent\AOD\Client\Providers\%d\Settings
Settings.xml
SOFTWARE\Exent\AOD\Client\Providers\%d\Settings\Skins\%s
Settings[@Type="%s" and @Id="%s"]
Group[@Name="%s"]
Setting[@Id="%s"]
noName, %u
%u %u
%s\a%u.rgms
temp.rgmx
SOFTWARE\Exent\AOD\Client\SL
%s %s
cid=%u, pid=%u
cid=%u, pid=%u (ln=%d)
sXp.dat
s9x.dat
%d = %u
.?AVTextException@ExentExceptions@Exent@@
.?AVUnSupportedTextFormatException@ExentExceptions@Exent@@
.?AVMemoryAllocationException@ExentExceptions@Exent@@
C:\Work\AOD7.3Branch\Client\Exceptions\SystemException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\WaitOnLockException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\NullPointerException.cpp
.?AVLoaderInitDbgDetectedException@Driver@Client@Exent@@
.?AVLoaderInitDriverLockedException@Driver@Client@Exent@@
.?AVLoaderInitUnSupportedOsException@Driver@Client@Exent@@
.?AVLoaderInitIncompatibleVersionsException@Driver@Client@Exent@@
.?AVLoaderInitDriverNotFoundException@Driver@Client@Exent@@
.?AVLoaderAlreadyInitiatedException@Driver@Client@Exent@@
MediaChangerHotKey
SOFTWARE\Exent\AOD\Client\CMC
C:\Work\AOD7.3Branch\Client\Exceptions\RuntimeException.cpp
.?AVContractException@ExentExceptions@Exent@@
.?AVPreConditionException@ExentExceptions@Exent@@
.?AVIllegalArgumentValueException@ExentExceptions@Exent@@
.?AVNoSuchElementException@ExentExceptions@Exent@@
.?AVUtilException@ExentExceptions@Exent@@
.?AVNoSuchSectionException@ExentExceptions@Exent@@
.?AVNoSuchGroupException@Information@Exent@@
.?AVInternalContractException@ExentExceptions@Exent@@
.?AVTypeFormatException@ExentExceptions@Exent@@
.?AVNumberFormatException@ExentExceptions@Exent@@
.?AVStringEncodingException@ExentExceptions@Exent@@
C:\Work\AOD7.3Branch\Client\Exceptions\UnSupportedTextFormatException.cpp
.?AVTextFormatException@ExentExceptions@Exent@@
%d,%u
%d %s %d
AUsageReportMgr
<Session ID="%s" ContentId="%d" GGID="%s" SNumber="%d" StartPlayTime="%s" DurationInSec="%d"/>
<Session ID="%S" ContentId="%S" GGID="%S" SNumber="%S" StartPlayTime="%S" DurationInSec="%S"/>
<?xml version="1.0" encoding="UTF-8"?><UpdateOSLUsageRequest><Header version="1.0"><Signature>%S</Signature></Header>%s</UpdateOSLUsageRequest>
<Data ProviderId="%S" MUID="%S" ClientClockSendTime="%S" >%S</Data>
targetURL
07.04.08.00
%d,%c
%c,%d,%d,%d
LicMgr, %u
C:\Work\AOD7.3Branch\Client\Exceptions\IllegalArgumentValueException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\NoSuchElementException.cpp
C:\Work\AOD7.3Branch\Client\Information\NoSuchGroupException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\InternalContractException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\NumberFormatException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\StringEncodingException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\TextFormatException.cpp
.?AVDirectionsException@Directions@Client@Exent@@
.?AVDirectionsInformationException@Directions@Client@Exent@@
%s %s %d
User_Setting_%d
Service_Setting_%d
Info_Url
Target_Url
Upgrade_Info_%d
%s,%s,%s
LastSuccessfulErrURL
%s,%s,%d
\%d.clg
%s,%s,%u,%u,%u
%d,%d,%s
%d,%s
TargetURL
%s\%d
%s,%s - cont
%s,%s - cont.
%d,%d,<%s>
Report.exe
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInitIncompatibleVersionsException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInitUnSupportedOsException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInitDriverLockedException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInitDriverNotFoundException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderAlreadyInitiatedException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInitDbgDetectedException.cpp
0xx
.?AVLoaderInvalidRequestException@Driver@Client@Exent@@
.?AVObjectInitiationException@ExentExceptions@Exent@@
%s,%d,%d,%s,%s
%s\%c
SOFTWARE\Exent\AOD\Client\Disks
%c,%d,%s,%s
Err = 0x%X, RemName=%s
%d,%S,%S,%u,%s
%d,%S,%S
%u,%s
%d,%s,%d
%d %u,%s
%d,%u,%s
%d, %u, %s
%d,%u,%u
%d %d %d %d %d %d %d
\//:*<>|
%u,%u
%u %d %d
%d,%d,%d,%d,%d,%d,%d
GPlrLanc.dat
GPlrLanc.exe
*.lnk
*.rgmxold
2k.rif
2k.Rif
HttpPool
%d, %s, %d
%s, %s, %d
%d, %s, %d, %d
info:%u,%I64u,0x%I64x,%u
%u,%I64u,%u,0x%I64x,%u
%I64u,%u,0x%I64x
.?AVPMLicenseException@ExentExceptions@Exent@@
%u,%u,0x%I64x,%u
0x%I64x,%u,%u,%u,%u,%u,%u
%u,0x%I64x
%s,%u
%s %s %u
C:\Work\AOD7.3Branch\Client\Exceptions\PreConditionException.cpp
SOFTWARE\Exent\AOD\Client\ICC
_d
.?AVDirectionsFormatIsNotSupportedException@Directions@Client@Exent@@
Cmdline_%d
[%d]%s
CD_KEY_INFO_%d
%s,%S
xxxx
<%s %s="%d"><%s>%s</%s><%s>%s</%s><%s>%s</%s><%s>%d</%s><%s>%s</%s></%s>
%s,%u,%u
C:\Work\AOD7.3Branch\Client\DirectionsManager\DirectionsInformationException.cpp
SOFTWARE\Exent\AOD\Client\PRV
EnableDumpReport
AppLoader2kEx.dll
C:\Work\AOD7.3Branch\Client\DriverAdapter\LoaderInvalidRequestException.cpp
.?AVElementAlreadyExistsException@ExentExceptions@Exent@@
%u,0x%I64x,%u,%d
ListCount=%u, ListSize=%u, RemainingTime=%u, RemainingPlayCount=%u, nRemainingLevels=%u
%u,0x%I64x,%u
%u,%u,%I64u
.?AVContentException@ContentsRunnerEngine@Client@Exent@@
.?AVContentIsAlreadyInitiatedException@ContentsRunnerEngine@Client@Exent@@
.?AVContentsRunnerException@ContentsRunnerEngine@Client@Exent@@
.?AVAnOtherContentIsAlreadyInitiatedException@ContentsRunnerEngine@Client@Exent@@
.?AVIllegalContentStateOperationException@ContentsRunnerEngine@Client@Exent@@
.?AVContentNotFoundException@ContentsRunnerEngine@Client@Exent@@
.?AVNotEnoughDiskSpaceException@ExentExceptions@Exent@@
.?AVInvalidLicenseException@ContentsRunnerEngine@Client@Exent@@
.?AVInCompatibleContentDependenciesException@ContentsRunnerEngine@Client@Exent@@
<?xml version="1.0" encoding="UTF-8"?><CreateOSLRequest><Header version="1.0"><Signature>%S</Signature></Header>%s</CreateOSLRequest>
<Data><GGID>%S</GGID><MUID>%S</MUID><ClientBlock>%s</ClientBlock></Data>
<![CDATA[<ClientBlock><ClockID>%S</ClockID><CurrentClockIDTime>%S</CurrentClockIDTime></ClientBlock>]]>
<?xml version="1.0" encoding="UTF-8"?><RemoveOSLRequest><Header version="1.0"><Signature>%S</Signature></Header>%s</RemoveOSLRequest>
<Data><GGID>%S</GGID><MUID>%S</MUID><CR>%S</CR></Data>
OfflineSupported
CmdLineSNumber
CmdLineDesc
CmdLineTitle
CmdLineInfo_%u
%u,%u,%s,%u
DefCmdLine
%u,%u,%s,%s
%u,%u,%s
p_%u_lic
CmdLineParams
p_%u_cmd_%u
%u,%lu
C:\Work\AOD7.3Branch\Client\DirectionsManager\DirectionsFormatIsNotSupportedException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\ElementAlreadyExistsException.cpp
.?AVAPSAddressCanNotBeTranslatedException@Driver@Client@Exent@@
.?AVIOException@ExentExceptions@Exent@@
.?AVNetworkException@ExentExceptions@Exent@@
%d,%d,%d,%d,%s
%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d.%d
C:\Work\AOD7.3Branch\Client\DriverAdapter\PMlicenseException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\ContentIsAlreadyInitiatedException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\AnOtherContentIsAlreadyInitiatedException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\IllegalContentStateOperationException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\ContentNotFoundException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\InvalidLicenseException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\NotEnoughDiskSpaceException.cpp
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\InCompatibleContentDependenciesException.cpp
HTTPConnection
StartConnect (cid=%d, cn=%d)
Disconnect (cid=%d)
C:\Work\AOD7.3Branch\Client\DriverAdapter\APSAddressCanNotBeTranslatedException.cpp
C:\Work\AOD7.3Branch\Client\Exceptions\NetworkException.cpp
http=hXXp://%s:%d
ReqId=%d
HTTP/1.1
Range: bytes=%d-%d
%d, %d, %d, %s
%s/	u/	u/%s
Content.rgx
pid=%d
, Msg:
.?AVUnKnownContentStatusIDException@Driver@Client@Exent@@
.?AVIllegalContentNotificationException@Driver@Client@Exent@@
%d,%d,%d,%d,%d,%d,%d,%d,%d,%d
%s %d %d %s
%d,%s,%s,%s
.?AVDirectionsApsInfoNotFoundException@ContentsRunnerEngine@Client@Exent@@
.?AVParseException@ExentExceptions@Exent@@
%u(0xX),%u(0xx)
NotFullyDownloaded %d %d %d %d %d %d
%d,%u(0xX),%d
NotUsed,%s:%d
User,Port,%d
Manual,%s:%d
Machine,Port,%d
AutoDetect,%s:%d
Provider,Port,%d
%s:%d
Failed to save bypass information to registry.
ProxyBypassList
%d,%d,%d,%s:%d,%s:%d,%d
%d %S %d %d %s
%d, ,%d
%s, %d, %d
%d,%s,%s
CID-0d/CN-d/%s
predict.dat
%d,%S,%S,%d
\SC-0d-d.ico
Cmd[@id="%d"]
ExentMCEEvent_0d_d
C:\Work\AOD7.3Branch\Client\DriverAdapter\UnKnownContentStatusIDException.cpp
C:\Work\AOD7.3Branch\Client\DriverAdapter\IllegalContentNotificationException.cpp
ggid=%s
%d, %u, %s, %u
%s,%d,%d
C:\Work\AOD7.3Branch\Client\ContentsRunnerEngine\DirectionsApsInfoNotFoundException.cpp
-----BEGIN PUBLIC KEY-----
fVEhSlxxjE5s15XohAaeiTJKYxcveCzZw2CiIpeHOD26hZXMt2s9xkEYkQLtcN5x
-----END PUBLIC KEY-----
Init, IsAlreadyInitialized=%s, cURLSIsEmpty=%s, cstrTicket=%s, cstrClientVersion=%s, TicketId=%lu
HTTPConnPool
http:\\VVV.yahoo.com
http:\\VVV.microsoft.com
http:\\VVV.google.com
Certificate Request
%d, errId=%d, subErrId=%d
last ATTEMPT to send KA at: %s ;last SUCCESS to send KA at: %s ;last KA response time: %s
Unable to generate symmetric key
Received invalid certificate
C:\Work\AOD7.3Branch\Client\Exceptions\ParseException.cpp
GSCertReq
GSCertRes
CertData
./CacheKey
%s, %s
.?AVSoftwareCheckerOperationException@DependencyChecker@Client@Exent@@
D3D10.DLL
WINDOWS
INST.EXE
GLU32.DLL
CLSID\%s\InprocServer32
.?AVHardwareCheckerOperationException@DependencyChecker@Client@Exent@@
[%s:%u:%s]
[%s:%x:%s]
%s\%s
Joystick%dOEMName
%s\%s\%s
Software\AppDataLow\Software\Exent\AOD\Client\DC\GC
Software\AppDataLow\Software\Exent\AOD\Client\DC\C
Software\AppDataLow\Software\Exent\AOD\Client\DC
D3D8.DLL
DINPUT.DLL
DDRAW.DLL
C:\Work\AOD7.3Branch\Client\DependencyChecker\SoftwareCheckerOperationException.cpp
AffinityMask = %d; Initial APIC = %d; Physical ID = %d, Core ID = %d, SMT ID = %d
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Local video memory = %d MB
Toal video memory = %d MB
megs = %d / (1024*1024) = %d MB
On-screen memory = %d MB
lpdd7->GetAvailableVidMem(DDSCAPS_LOCALVIDMEM) returned dwTotal=%d Bytes
last_megs (Sub-Total Video memory) = %d / (1024*1024) = %d MB
lpdd7->GetAvailableVidMem(DDSCAPS_NONLOCALVIDMEM) returned dwTotal=%d Bytes
winmm.dll
exent_%u
SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
%u, %S, %S
Error=0x%X, File=%S
%s %s %s
%s %s %s %d %d %S
web:length = %d, str = %S
DirectionXMLRequest ansi: %s
DirectionXMLRequest unicode: %S
%S %S %d %d %S
<WebUIInfo>
%d, %S
CWebBrowserMZ
%S->%S
Style_%d-View_%d
Software\AppDataLow\Software\Exent\AOD\Broadcasting\
Exent EXEtender
Mozilla Firefox 3/4
Google Chrome
%s %d %x
SOFTWARE\Exent\AOD\Client\IGA
STRINGS_%d_%d_%s
%hs %d, %d
Unknown Asset dl Ok %d, %d
check: bad widget err=%d %ws
check: IGL files=%d dirs=%d Mb=%d %ws
check: err=%d %ws
%s\%x\
s2i %s
%s\%x
%s\tmp
not zip err=%d %ws %ws
not 7z err=%d %s %ws
%s&AppId=%d&PrvId=%d
%s?AppId=%d&PrvId=%d
d/d/d-d:d:d
CertGetNameStringA
CertFreeCertificateContext
crypt32.dll
wintrust.dll
//Password
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCResourceException@@
.PAVCArchiveException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCOleException@@
.PAVCOleDispatchException@@
.PAVCFileException@@
zcÁ
Err: Error while waiting on object, Windows error: %s.
C:\Work\AOD7.3Branch\Share\AWin32Util\ASyncObject.cpp
Err: Failed to create object, Windows error: %s.
Err: Failed to open object, Windows error: %s.
Err: Failed to set/reset event, Windows error: %s.
Err: Failed to release object, Windows error: %s.
[%d]%-20s: %-120s ::%s(=)
!!! %s- %s
AodDebug.ini
%s%s:X
Exception on DoLog(File: %u, LineNumber: %d)
Exception on DoLog(FileName: %s, LineNumber: %d)
Exception on DoLogEx(FileName: %u, LineNumber: %d)
Exception on DoLogEx(FileName: %s, LineNumber: %d)
netmsg.dll
C:\Work\AOD7.3Branch\Share\AWin32Util\ARegistryKey.cpp
Err: Error openning registry key NULL Key.
Err: Error openning/creating registry key %s, Windows error: %s.
Err: Error openning/creating registry key NULL Key.
Err: Error reading from registry key NULL Parameter.
Err: Invalid registry key type at registry key %s.
Err: Error reading from registry key NULL Key.
Err: Error reading from registry key %s, Windows error: %s.
Err: Registry entry %s too long.
Err: Error writing to registry key NULL Parameter.
Err: Error writing to registry key %s, Windows error: %s.
Err: Error writing to registry key NULL Key.
Err: Error deleting registry key %s, Windows error: %s.
Err: Error deleting registry key NULL Parameter.
Err: Error deleting registry key NULL Key.
Err: Error enumerating registry key %s, Windows error %s.
C:\Work\AOD7.3Branch\Share\AWin32Util\AThread.cpp
Err: Error creating thread, Windows error: %s.
Err: Operation is not allowed within thread context.
Err: Error terminating thread, Windows error: %s.
FLT_INVALID_OPERATION
FLT_DENORMAL_OPERAND
Fail to get stack, Exceprion code = %X
Flags:X
DS:X ES:X FS:X GS:X
SS:ESP:X:X EBP:X
CS:EIP:X:X
EAX:X EBX:X ECX:X EDX:X ESI:X EDI:X
Fault address: X X:X %s
Exception code: X %s
Process: %s [PID=%u] (On thread ID: 0x%X)
Process: %s [PID=%u]
Local time: %s. d/d/d - d:d:d.d
X X X:X %s
C:\Work\AOD7.3Branch\Share\ErrorLogger\ErrorLoggerMgr.cpp
C:\Work\AOD7.3Branch\Share\ErrorLogger\AErrorsLoggerMgrBlocking.cpp
%s - %s
?456789:;<=
!"#$%&'()* ,-./0123
\StringFileInfo\xx\%s
C:\Work\AOD7.3Branch\Share\AAodUtilities\ABufferPool.cpp
C:\Work\AOD7.3Branch\Share\AAodUtilities\AWorkQueue.cpp
C:\Work\AOD7.3Branch\Share\AAodUtilities\AInternetConnectionTrigger.cpp
wininet.dll
%s: %s
Invalid schema (%u).
Invalid url.
Server return HTTP code:%u. err:%s
%s: %u
Failed to read http response. err
Page: %s not found: %s
Fail to query status code err: %s
AHTTPConnection::_Work() - Error. Did not Receive exactly the requested Range.
Failed to end http request. err
%s: %d
Failed to send http request. err
%s: %s
Failed to add http header. err
undefined operation!
Fail to crack URL. err:schema <%u> is not supported.
Fail to crack URL err:%u.
%s %S to %S err: %u
Range: bytes=%u-%u
Fail to read file. err:%u.
Fail to open file %S. err:%u.
C:\Work\AOD7.3Branch\Share\AAodUtilities\ASharedListEx.cpp
SharedListEventName_%s
d/d/%d d:d
assets.xml
CLSID%d
SOFTWARE\Exent\AOD\CLSID
Kernel32.dll
%X%X%X
HardwareInformation.AdapterString
\\.\PhysicalDrive%d
winio.sys
\\.\Scsi%d:
The data file expired ftime=%s, stime=%d:%d:%d
CREATE TABLE cookies (creation_utc INTEGER NOT NULL UNIQUE PRIMARY KEY, host_key TEXT NOT NULL,name TEXT NOT NULL,value TEXT NOT NULL, path TEXT NOT NULL,expires_utc INTEGER NOT NULL, secure INTEGER NOT NULL,httponly INTEGER NOT NULL, last_access_utc INTEGER DEFAULT 0)
host_key
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly FROM cookies
SELECT creation_utc, name, value, host_key, path, expires_utc, secure, httponly, encrypted_value FROM cookies
\Google\Chrome\User Data\Default\
UPDATE cookies SET name = ?1, value = ?2, host_key = ?3, path = ?4, expires_utc = ?5, secure = ?6, httponly = ?7 WHERE creation_utc = ?8
UPDATE cookies SET name = ?1, value = ?2, host_key = ?3, path = ?4, expires_utc = ?5, secure = ?6, httponly = ?7, encrypted_value = ?9 WHERE creation_utc = ?8
INSERT INTO cookies (creation_utc, host_key, name, value, path, expires_utc, secure, httponly, last_access_utc) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9, creationTime = ?10 WHERE id = ?1
INSERT INTO moz_cookies (name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain, creationTime) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly, creationTime FROM moz_cookies
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8, baseDomain = ?9 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed, baseDomain) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9, ?10)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7, lastAccessed = ?8 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly, lastAccessed) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8, ?9)
UPDATE moz_cookies SET value = ?2, host = ?3, path = ?4, expiry = ?5, isSecure = ?6, isHttpOnly = ?7 WHERE id = ?1
INSERT INTO moz_cookies (id, name, value, host, path, expiry, isSecure, isHttpOnly) VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7, ?8)
SELECT id, name, value, host, path, expiry, isSecure, isHttpOnly FROM moz_cookies
\cookies.sqlite
profiles.ini
\Mozilla\Firefox\
Mozilla Firefox 2
#HttpOnly_
# HTTP Cookie File
# hXXp://VVV.netscape.com/newsref/std/cookie_spec.html
\cookies.txt
*.txt
#!*.*
Microsoft.MicrosoftEdge_*.*
shell32.dll
cmhelper.exe
ietemp1.dat
SELECT name FROM sqlite_master WHERE type = 'table' AND name = '
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
foreign_key_list
foreign_key_check
defer_foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat4
sqlite_stat3
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s%s%s
unknown database %s
recovered %d pages from %s
cannot limit WAL size: %s
recovered %d frames from WAL file %s
MJ delete: %s
-mjX9X
MJ collide: %s
%s-mjXXXXXX9XXz
foreign key constraint failed
922337203685477580
%s(%d)
keyinfo(%d
bind on a busy prepared statement: [%s]
statement aborts at %d: [%s] %s
constraint failed at %d in [%s]
abort at %d in [%s]: %s
database table is locked: %s
cannot change %s wal mode from within a transaction
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
sqlite_master
sqlite_temp_master
cannot commit transaction - SQL statements in progress
cannot release savepoint - SQL statements in progress
no such savepoint: %s
cannot open savepoint - SQL statements in progress
Outstanding page count goes from %d to %d during this analysis
Pointer map page %d is referenced
Page %d is never used
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Failed to read ptrmap key=%d
failed to get page %d
%d of %d pages missing from overflow list starting at %d
freelist leaf count too big on page %d
2nd reference to page %d
invalid page number %d
Fragmentation of %d bytes reported as %d on page %d
Multiple uses for byte %d of page %d
Corruption detected in cell %d on page %d
On page %d at right child:
On tree page %d cell %d:
btreeInitPage() returns error code %d
unable to get the page. error code=%d
Page %d:
zeroblob(%d)
cannot open %s column for writing
no such column: "%s"
cannot open view: %s
cannot open virtual table: %s
indexed
foreign key
cannot open value of type %s
%.*s"%w"%s
%s%.*s"%w"
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
unable to open database: %s
database %s is already in use
too many attached databases - max %d
database %s is locked
cannot detach database %s
no such database: %s
%s: %s.%s
API call with %s database connection pointer
error during initialization: %s
no entry point [%s] in shared library [%s]
sqlite3_
unable to open shared library [%s]
%s.%s
sqlite3_extension_init
malformed database schema (%s)
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unsupported file format
database schema is locked: %s
sqlite3_get_table() called with two or more incompatible queries
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
PRAGMA vacuum_db.synchronous=OFF
cannot VACUUM - SQL statements in progress
no such module: %s
vtable constructor did not declare schema: %s
vtable constructor failed: %s
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
Expression tree is too large (maximum depth %d)
too many SQL variables
variable number must be between ?1 and ?%d
too many columns in %s
there is already another table or index with this name: %s
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
sqlite_sequence
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
view %s may not be altered
%s OR name=%Q
type='trigger' AND (%s)
table %s may not be altered
sqlite_
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
Cannot add a PRIMARY KEY column
sqlite_altertab_%s
DELETE FROM %Q.%s WHERE %s=%Q
CREATE TABLE %Q.%s(%s)
misuse of aggregate: %s()
EXECUTE %s%s SUBQUERY %d
invalid name: "%s"
not authorized to use function: %s
%s: %s.%s.%s
misuse of aliased aggregate %s
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
duplicate column name: %s
too many columns on %s
default value of column [%s] is not constant
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
table "%s" has more than one primary key
CREATE TABLE %Q.sqlite_sequence(name,seq)
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE %s %.*s
%s %T cannot reference objects in database %s
%s cannot use variables
view %s is circularly defined
use DROP VIEW to delete view %s
use DROP TABLE to delete table %s
table %s may not be dropped
sqlite_stat
sqlite_stat%d
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
unknown column "%s" in foreign key definition
number of columns in foreign key does not match the number of columns in the referenced table
foreign key on %s should reference only one column of table %T
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
CREATE%s INDEX %.*s
table %s has no column named %s
sqlite_autoindex_%s_%d
index %s already exists
there is already a table named %s
virtual tables may not be indexed
views may not be indexed
table %s may not be indexed
cannot create a TEMP index on non-TEMP table "%s"
indexed columns are not unique
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
no such index: %S
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
cannot modify %s because it is a view
table %s may not be modified
foreign key mismatch - "%w" referencing "%w"
table %S has no column named %s
%d values for %d columns
table %S has %d columns but %d values were supplied
PRIMARY KEY must be unique
constraint %s failed
%s.%s may not be NULL
unsupported encoding: %s
*** in database %s ***
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
no such index: %s
no such table: %s
%s.%s.%s
too many references to "%s": max 65535
sqlite_sq_%p
cannot join using column %s - column not present in both tables
cannot have both ON and USING clauses in the same join
a NATURAL join may not have an ON or USING clause
USE TEMP B-TREE FOR %s
SELECTs to the left and right of %s do not have the same number of result columns
LIMIT clause should come after %s not before
ORDER BY clause should come after %s not before
COMPOUND SUBQUERIES %d AND %d %s(%s)
SCAN TABLE %s%s%s
cannot create INSTEAD OF trigger on table: %S
cannot create %s trigger on view: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
at most %d tables in a join
automatic index on %s(%s)
%s VIRTUAL TABLE INDEX %d:%s
%s (rowid<?)
%s (rowid>?)
%s (rowid>? AND rowid<?)
%s (rowid=?)
%s USING INTEGER PRIMARY KEY
%s USING %sINDEX %s%s
%s USING AUTOMATIC %sINDEX%.0s%s
%s AS %s
%s TABLE %s
%s SUBQUERY %d
%s.xBestIndex() malfunction
table %s: xBestIndex returned an invalid plan
unable to use function %s in the requested context
unknown database: %s
no such vfs: %s
%s mode not allowed: %s
no such %s mode: %s
automatic extension loading failed: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
UrlMon.dll
UMUploadRequestHTTP
0x%X (S)
\\.\%s
X4EXT.Sys
code %d bits %d->%d
gen_codes: max_code %d
bl code -
opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u
last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)
1.1.3
CD%sWndTITLE
CD%sWndCLASS
%s_%s
MAILSLOT%s
fail to create mailSlot. err: %d
fail to create 'AllAccess' object. err:<%d>
fail to open mailSlot. err: %d
\\.\mailslot\
fail to write to mailSlot, err:<%u>
fail to read from mailSlot, err:<%u>
fail to get mailSlot info. err: %d
windows
Service Pack: %d
Windows XP
Windows 2000
Windows NT
Windows ??
Windows Millenium Edition
Windows 98 Second Edition
Windows 98 SP1
Windows 98
Windows 95 OSR2
Windows 95 SP1
Windows 95
Windows CE
Windows
Microsoft Windows Me
Microsoft Windows 98
Microsoft Windows 95
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows NT
version="4.34.0.0"
<description>EXEtender Player</description>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
yw}nlwWRuA8v1%u 
3333331
3333333
^UeA9[6.V2(X1)X1(]6.fA9}\S
commctrl_DragListMsg
tAfx:%x:%x:%x:%x:%x
Afx:%x:%x
t%*.*f
S.INI
tMSWHEEL_ROLLMSG
888816666554443
6666554443
!6666554443
e.exe
>%s%s
& ErrCode=%d
?ErrCode=%d
SGPlayer.exe
Please install the latest version of the EXEtender Player now.
%d second(s) left
NM_CP_%u.xml
%s\a%u.rgmt
%s %s %d %s
GameLauncher.exe
PLAY_INFO_IDS_LAUNCHER_INSTALL_URL
ExetenderOptionsHelp.htm
%s (%s %d/%d)
Show again in %d hour(s)
D%s%s%s
!@#$%^&*()_ 
!@#$%^&*()_ 
%c:\%s
SUrl
rLink[@Id="%d"]
S<cmdlinetitle>
%d, %S, %d, %d, %S, %S, %s %d %d %d %d %d
(%.1f %s/%s)
%.2f%s/%.2f%s
,%.2f %s
%.2f%s
%s\x\%s
http\shell\open\command
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Software\Classes\ChromeHTML
Software\Classes\ChromeHTML\shell
Software\Classes\ChromeHTML\shell\open
Software\Classes\ChromeHTML\shell\open\command
SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
%d %s
d %s
dDirection[%d].rgmxold
%c:\%s\%s\
.rgmt
%s\%s\%s-%s
PU.rgmxold
PM.rgmxold
SBMP-0d-d.pic
SC-0d-d.ico
-UserCmdline
ExetenderPlayerHelp.htm
CM.dll
UI_OpenWebDialog
UI_LoginPopupWindow
http:\\VVV.exent.com\logo_click.html
%s/%s
-WebLaunch
%d.ico
AuthKey
%s?%s
string number %u is empty
string %u Title: %s,
string %u Question: %s
%s=%d&%s=%d&%s=%s&%s=%d&%s=%d
%s=%d&%s=%d&%s=%d&%s=%d
%s=%d&%s=%d
&%s=%s
\IGL.ini
ComponentMgrConfig.xml
Widget.dll
GFComponent.dll
w%SystemRoot%\ehome\ehshell.exe
ExentControl.ExentInf1
ExentCtl.ExentInf
dat\GPlrLanc.dat
regsvr32.exe
Can't read config file <%s>
(error:%s)
Can't open config file <%s>
fail to load XML string. <%s>
x%d.%d.%d.%d
%X.%X.%X.%X
%ws\%u.clg
%s\x
%s\*x
HTTPpool
uxtheme.dll
168,3600
168,43200
5,3600,-1,86400
./Url
e%S\%s\
clientErrorLogUrl
clientMoreInfoURL
clientUpgradeURL
bannerUrl
progressUrl
cmdParams
cmdStartDir
cmdLine
proxyPort
apsPort
x	u/	u/x/%s
x/
x.dat
%S.lic
e2.0.0.0
nHidE.dll
HidEmu.xml
//InternetCheckUrls/Url
OSLMgrURL
grant/forAll[@varName="%S"]/xmlExpresion[. = "ContentId/%d"]
00.00.00.00
Win32_VideoController.DeviceId="VideoController1"
\\.\root\cimv2
'%c' (%hu, 0x%hX)
%d (0x%X)
URLInfoAbout
lcid=%u;name=%s;dir=%s;prvid=%u;cmdid=%u;prvdir=%s
<?xml version="1.0" encoding="UTF-8"?><GetDirectionRequest><AppId>%s</AppId><RunIndex>%s</RunIndex><Muid>%s</Muid><AcID>%s</AcID><AuthKey>%s</AuthKey><DirectionsType>%s</DirectionsType><UserType>%s</UserType><UserChannel>%s</UserChannel><AdditionalInfo>%s</AdditionalInfo></GetDirectionRequest>
Directions/AuthUiUrl
Directions/SilentAuthUrl
Authentication/Key
WEB_UI
File://%sConnecting.html
File://%shtml\Connecting.html
File://%sOffLineErrUI.html?%s
File://%shtml\OffLineErrUI.html?%s
File://%sOffLineWebUI.html
File://%shtml\OffLineWebUI.html
File://%sPromotion.html
File://%shtml\Promotion.html
OfflineSplash.jpg
%spics\OfflineSplash.jpg
BUTTON_EXENT
WEB_UI_BUY
WEB_UI_AUTHENTICATION
WEB_UI_END_SESSION
SkinCfg.ini
SkinCfg.xml
res://%s/%d
hGPlrLanc.dat
ExetenderPlayerSkin/%s/%s[@Id="%d"]/Path
DefaultUrl
DefaultUrls
ExetenderPlayerSkin/%s/%s[@Id="%d"]
PopupWindows
WebUIs
ExetenderPlayerSkin/Views/Style[@Id="%d"]/View[@Id="%d"]
View[@Id="%d"]/Menus
./Resources/Resource[@Id="%s"]
./Configurations/Configuration[@Id="%d"]/Setting
ContentExecutionErrId
ActivationKey
IsHttpOnly
CmdlineId
ReportOSLUsageRequest
GetExecutionStateRequest
DirectionsUrl
BaseUrl
CreateUrl
RemoveUrl
widget.dll
USERMSG/
INFO_URL
TARGET_URL
r.xml
<DBItemWebURL><![CDATA[
]]></DBItemWebURL>
//DBItemWebURL
exent_msg:name
exent_msg:expiration_time
exent_msg:show_duration_time_in_sec
exent_msg:is_message_persistent
web_type_url
AIGsXML_%u.xml
//cp:dsurl
</Password>
<Password>
.http.tmp
md.dat
%s\%S_%S
%s\%S_%s
GF.env
\%sEnvironment\%s.env
SOFTWARE\Exent\Games Enhancement
GameInfoUrl
RulesUrl
UrlPrototype
<Header Version="%d" />
<GEMEnvironment><Header Version="%d" /><Data /></GEMEnvironment>
-----BEGIN RSA PRIVATE KEY-----
-----END RSA PRIVATE KEY-----
<CacheMgr><CacheInfo><StorageID>%S</StorageID><Signature/></CacheInfo><Records/></CacheMgr>
./URL
xmlns:xsi="hXXp://VVV.w3.org/2001/XMLSchema-instance"
%Program Files%\FantastiGames\GPlayer.exe
1996-2016 Exent Technologies Ltd. All rights reserved.
$$Not enough disk space - The EXEtender cannot continue running the application...
$$ Free disk reqired for play %s (%s)
$$Free disk space for %s full download (%s)
$$Currently selected %s...
$$You need to free at least %s disk space in order to run %s...
$$Preserve all settings and saved information (will leave %s)...
$$|| / >
$$Automatic error report sending...
$$Are you sure you want to remove %s?...
$$3.5.3...
$$%Program Files%\Exetender...
1996-2004 Exent Technologies...
$$Click 'Finish' to return to Exetender Player...
$$Port:
$$EXEtender recommends of the following steps:...
$$Increase the reserved space for application caching on drive %c:...
$$Free disk space required to play %s
$$Set Password:
$$Confirm Password:
$$Password Hint:
$$Parental Controls settings lets you control your subscription game content on Verizon Games On Demand. Once you set your settings a password will be required to play any game you don't allow.
$$Please Enter Your Parental Control Password to access this feature:
$$Forgot Password?
$$Please send an e-mail to our Customer Support
$$Your Password:
Please enter your Parental Controls Password:
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
#Unable to load mail system support.

svchost.exe_1592:

.text
`.data
.rsrc
@.reloc
msvcrt.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
KERNEL32.dll
NTDLL.DLL
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
RPCRT4.dll
ole32.dll
ntdll.dll
_amsg_exit
RegCloseKey
RegOpenKeyExW
GetProcessHeap
svchost.pdb
version="5.1.0.0"
name="Microsoft.Windows.Services.SvcHost"
<description>Host Process for Windows Services</description>
<requestedExecutionLevel
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
\PIPE\
Host Process for Windows Services
6.1.7600.16385 (win7_rtm.090713-1255)
svchost.exe
Windows
Operating System
6.1.7600.16385

WerFault.exe_2124:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
USER32.dll
msvcrt.dll
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
IMM32.dll
wer.dll
COMCTL32.dll
faultrep.dll
Starting kernel vertical - %S
rundll32.exe
NtQueryInformationProcess failed with status: 0x%x
Reporting never started for process id %u
StringCchPrintf failed with 0x%x
NtWow64QueryInformationProcess64 failed with 0x%x
NtWow64ReadVirtualMemory64 failed with 0x%x
NtQueryInformationProcess failed with status 0x%x
WerpNtWow64QueryInformationProcess64 failed with status 0x%x
StringCchCopy failed with 0x%x
Invalid arg in %s
wdi.dll
dbgeng.dll
dbghelp.dll
SETUPAPI.dll
SHELL32.dll
VERSION.dll
WTSAPI32.dll
WerFault.pdb
PSShD
tSSh,<
t.PSj6
t5SSh
SShx`
tsShxc
t.Ph0j
_amsg_exit
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
GetProcessHeap
GetWindowsDirectoryW
RegDeleteKeyW
ReportEventW
RegOpenKeyW
RegSetKeyValueW
GetProcessWindowStation
EnumWindows
NtAlpcSendWaitReceivePort
NtAlpcConnectPort
ShipAssert
ntdll.dll
RegisterErrorReportingDialog
WerReportSubmit
WerReportAddFile
WerReportCreate
WerReportCloseHandle
WerReportSetUIOption
WerpGetReportConsent
WerpSetIntegratorReportId
WerpReportCancel
WerpAddRegisteredDataToReport
WerReportAddDump
WerpCreateIntegratorReportId
WerpSetReportFlags
WerpGetReportFlags
WerpIsTransportAvailable
WerReportSetParameter
WerpInitiateCrashReporting
version="1.0.0.0"
name="Microsoft.Windows.Feedback.Watson"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
</asmv3:windowsSettings>
<requestedExecutionLevel
ÝCD0
#$$$3355<
##$$$335566
% "#$$$3355666=
"#$$33555666
!.DQ$
.Py>o
Kÿg
.ib:?
T3%X_
a,M.cbd
KEYW8
KEYWH
? ?$?(?,?0?4?8?
1 2$2(2,20242
>,?0?4?8?<?@?
?%?5?:?|?
5'565^5{5
3#3(353_3
=#='= =/=3=7=;=?=
=#=(=>=]=
>!>&>3>}>
1!1&131[1
Microsoft\Windows\WindowsErrorReporting\WerFault
%s %s
Global\WerKernelVerticalReporting
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl
CrashDumpEnabled.Old
CrashDumpEnabled.New
%SystemRoot%\MEMORY.DMP
LiveKernelReports
Software\Microsoft\Windows\Windows Error Reporting\LiveKernelReports
LiveKernelReportsPath
BCCode=%x&BCP1=%p&BCP2=%p&BCP3=%p&BCP4=%p&OS Version=%u_%u_%u&Service Pack=%u_%u&Product=%u_%u
*WerKernelReporting
%SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\Windows Error Reporting\KernelFaults\Queue
sysdata.xml
%s -k -q
SOFTWARE\Microsoft\Windows NT\CurrentVersion
<OSVER>%u.%u.%u %u.%u</OSVER>
<OSLANGUAGE>%u</OSLANGUAGE>
<ARCHITECTURE>%u</ARCHITECTURE>
<PRODUCTTYPE>%u</PRODUCTTYPE>
<FILESIZE>%u</FILESIZE>
<CREATIONDATE>d-d-d d:d:d</CREATIONDATE>
<NAME>%s</NAME>
<DATA>%s</DATA>
<ERROR>Failed at Step: %s with error 0x%x</ERROR>
%sDrivers\%s.sys
</%s>
<%s>%s</%s>
%u.%u.%u.%u
*.mrk
WER-%u-%u.sysdata.xml
Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\MemoryDiagnostic
Web Server
Software\Microsoft\Windows\Windows Error Reporting\Debug
%SystemRoot%\Minidump
0xx (0xx, 0xx, 0xx, 0xx)
%s\%2.2d%2.2d%2.2d-%u-%2.2d.dmp
*.dmp
Software\Microsoft\Windows\Windows Error Reporting
Software\Policies\Microsoft\Windows\Windows Error Reporting
\KernelObjects\SystemErrorPortReady
%s\%s
Microsoft.Windows.Setup
\WindowsErrorReportingServicePort
(0x%x): %s
%u %s
WindowsNTVersion
%u.%u
ErrorPort
\StringFileInfo\xx\%s
HKEY_USERS\
HKEY_CURRENT_CONFIG\
HKEY_CLASSES_ROOT\
HKEY_LOCAL_MACHINE\
HKEY_CURRENT_USER\
%s="%s"
%s.%s
%s %d
Software\Microsoft\Windows\Windows Error Reporting\Hangs
_NT_EXECUTABLE_IMAGE_PATH
wxmu.dmp
wxhu.dmp
axmu.dmp
axhu.dmp
hu.kdmp
mu.kdmp
hu.dmp
mu.dmp
Software\Microsoft\.NETFramework
NOT_TCPIP
sos.dll
version.xml
.version.xml
%s.xml
memory.hdmp
minidump.mdmp
Local\WERReportingForProcess%d
atk.kdmp
Software\Microsoft\Windows\Windows Error Reporting\Hangs\NHRTimes
%i|%d|%d
xxxxxxxxxxxxxxxx
xx
%d.%d.%d.%d
D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)
D:P(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;%s)S:(ML;;NR;;;HI)
dc.noreflect
dc.xpmemdump
dc.xpdata
dc.CustomDump
dc.expmodmem
dc.expmoddata
dc.OnDemandKdmp
dc.xpmodmem
dc.xpmoddata
default=%s
memory=%s
module=%s
.dbgcfg.ini
ElevatedDataCollectionStatus.txt
Open process failed unexpectedly: 0X%X
Attempting to cross-proc reporting process!
Elevation:Administrator!new:%s
Reflection attempt failed: 0X%X
Attempting to reflect reporting process!
Could not collect dump for reflection cross process: 0x%x
Could not collect xproc for reflection: 0x%x
CollectFile for reflection failed: 0x%x
Could not collect dump for cross process: 0x%x
CollectReflectionDump failed with: 0x%x
0 processes found for xproc module: %s
Could not collect cross dump from module: 0x%x
CollectCrossProcessModuleDumps failed: 0x%x
CollectCrossProcessDumps failed: 0x%x
KernelDump failed: 0x%x
ProcessHandle
%s|%s
rpcrt4
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected\AutoExclusionList
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\AutoExclusionList
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebugProtected
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
sntdll.dll
WerDiagController.dll
Software\Microsoft\Windows\Windows Error Reporting\Plugins
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession
%s\%s\%u-%u.etl
%s\%s\%u-%u.etl_%d
Microsoft\Windows\FDR
%s-%d
Software\Microsoft\Windows\Windows Error Reporting\Plugins\DriverVerifier
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder
%d-AppRecorderEnabled
%s /stop
psr.exe
Software\Microsoft\Windows\Windows Error Reporting\RuntimeExceptionHelperModules
verifier.dll
nVerifier.dll
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\%s
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
lsvchost.exe
"%s" "%s" "%s"
%s\system32\cofire.exe
psapi.dll
sfc_os.dll
werfault.exe
%s\%s-(PID-%u)-%u
%s\%s-(PID-%u).dmp
%s\*-(PID-*)-*
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit
kernel32.dll
kernelbase.dll
ReportingMode
WinShipAssert
WindowsMessageReportingB1
Windows
ws2_32.dll
Software\Microsoft\SQMClient\%s\AdaptiveSqm\ManifestInfo
%s\Sqm%d.bin
CorporateWerPortNumber
BypassDataThrottling
Software\Microsoft\Windows\Windows Error Reporting\Consent
Windows Problem Reporting
6.1.7600.16385 (win7_rtm.090713-1255)
WerFault.exe
Windows
Operating System
6.1.7600.16385
Microsoft-Windows-WER-Diag/Operational


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Scan a system with an anti-rootkit tool.
  2. Terminate malicious process(es) (How to End a Process With the Task Manager):

    cmhelper.exe:4080
    cmhelper.exe:1804
    cmhelper.exe:1092
    cmhelper.exe:3712
    cmhelper.exe:1428
    cmhelper.exe:2980
    cmhelper.exe:3724
    cmhelper.exe:1296
    regsvr32.exe:3912
    FreeRideGames.exe:1748
    %original file name%.exe:3432
    RegEdit.exe:3984
    RegEdit.exe:4004
    RegEdit.exe:3704
    Setup.exe:1264
    iKernel.exe:4016
    IKernel.exe:4032
    IKernel.exe:2144

  3. Delete the original Malware file.
  4. Delete or disinfect the following files created/modified by the Malware:

    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Temp\ietemp1.dat (73 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\X6FP80R3.txt (105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\ESALVM6O.txt (211 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B51JZUNK\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AH411JJS\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7N4CKHF0\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\F6637V5A\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\7UWG0E7P.txt (314 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\FQ0ZQC1W.txt (314 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\KMGTASBT.txt (314 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Low\CD490DZY.txt (314 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF (2 bytes)
    %Program Files%\FantastiGames\Info\1.clg (40275 bytes)
    %Program Files%\FantastiGames\Info\co_adm.dat (311 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FI1HKYYU.txt (1528 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite-wal (12078 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\T0HCNPR5.txt (1537 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\OO1RHZ5B.txt (1510 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_mDsdT6zr4vUOndJ (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\etilqs_nkohzXNu8dUYkRt (66 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZDO3F4LP.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF (2674 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ITL3JZ46.txt (1537 bytes)
    %Program Files%\FantastiGames\cmhelper.exe (188 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal (13542 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\74VZKJBU.txt (1508 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\K4UC8OE2.txt (1504 bytes)
    %Program Files%\FantastiGames\Info\sXp.dat (34 bytes)
    %Program Files%\FantastiGames\Info\co_adm.dat-journal (14082 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Default\Cookies (27 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\DJDN2C5M.txt (1513 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE (2448 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\plf4C5B.tmp (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.inx (7913 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.cab (8949 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ExentCtl.ocx (9690 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\Setup.exe (2318 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\FRGN.ico (3827 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data2.cab (153950 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\exs.dll (13249 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.ini (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.iss (169 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\ikernel.ex_ (6473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\data1.hdr (1013 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\layout.bin (417 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\pftw1.pkg (22720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ext4C5C.tmp (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\00051E97 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\resourceDll.dll (261 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_uninsep.bat (174 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\cmhelper.exe (192 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\ExentCtlInstaller.dll (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe (962 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe (618 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IEC4E4E.tmp (2105 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\temp.000 (11328 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion3[1].gif (13064 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\R7OD6DBI.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\measurements[1] (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\gamesInQueue[1] (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\757c6a22-140e-494a-be1f-e0407a0c5382 (54286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\offlineheader[1] (398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\emptyFooter[1] (817 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\connection[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\bubbleRight[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\e77284cb-1bb0-4557-8892-2ed1c966596c (54286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PVGOHUDS.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\conf_defines[1] (510 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WWR4H4TF.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\SDM_HEADER2[1].css (471 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XCN81JJL.txt (1157 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\servicePromotion1[1].jpg (7004 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7TUMTORV.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\bubbleLeft[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\SDM_PROGRESS[1].css (732 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XN1WNAN1.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\util[1] (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Exent\GI20170830062205GMT.Log (28 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\pageURLInfo[1] (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\SDMHTMLInterfaces[1] (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\initialized[1] (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\SDMLog.log (2323573 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9CI3FM16.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JV92PAKR.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\controller[1] (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\2V8FONPT.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\207B9FD92391B9B2A60A89B4C965D5DF (588 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FWM1JVI5.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\functions[1] (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6KLB2WYO.txt (325 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\boxshot_sm[1].jpg (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\defines[1].js (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\progress[1] (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\207B9FD92391B9B2A60A89B4C965D5DF (936 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D41693DAFE5DEF0C36959FF1FCEF5C96 (603 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\offlineheader[1] (199 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\defines[1] (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\14KLX8KR.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\beacon[1].js (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\TarB56A.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\close_disabled[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion2[1].jpg (7596 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PINM4I6X.txt (537 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CabB569.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\FreeRideGames.exe (5534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\b4fd6daa-460f-4d2e-96d4-dc0ed984be7e (54286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\aa48a783-4197-4656-bbdf-e08050496297 (54286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F24TTX69.txt (1449 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\initialized[1] (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\4cb7ea78-f9d1-4dd1-99d3-ea9ee82326e8 (54286 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\connecting_anim[1] (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\header[1].htm (331 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\EULAFooter[1] (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NPZKBZPA.txt (298 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\conf_defines[1] (510 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\header[1].jpg (1160 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\SDM_DB_143.xml (378 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6TT3Z53I.txt (955 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\index[1] (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\util[1] (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\I6E3BWDW.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\connecting_anim[1] (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LME52A66.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\extrnalHandler[1] (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D41693DAFE5DEF0C36959FF1FCEF5C96 (904 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\servicePromotion4[1].jpg (4926 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\close_up[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\configuration[1] (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\initialized[1] (401 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\SDM_PROGRESS[1].htm (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\pageURLInfo[1] (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\util[1] (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5GE58KL3.txt (109 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FVT01N0M.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\ga[1].js (27865 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\07W0X7RA.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\13[1].gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\conf_defines[1] (510 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\minimize_up[1] (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6QTQ4XM0.txt (695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CGOV3MC7.txt (114 bytes)
    %Program Files%\FantastiGames\GameInst.dll (49 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\progressFooter[1] (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Exent\DACC\SDM_DownloadAcc_1.acc (940 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\defines[1] (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62d7.rra (1 bytes)
    %Program Files%\FantastiGames\Repo585c.rra (22774 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bf4.rra (25 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgBo60e4.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_u66ec.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_a6641.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\Subs63c1.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos62f6.rra (483 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\canc67b7.rra (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\5H7LDD3J.txt (1534 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\load6315.rra (17 bytes)
    %Program Files%\FantastiGames\X4Ex57df.rra (16732 bytes)
    %Program Files%\FantastiGames\d3dx59f1.rra (32512 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\og_i643e.rra (625 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\play62e7.rra (1 bytes)
    %Program Files%\FantastiGames\AX32584c.rra (3404 bytes)
    %Program Files%\FantastiGames\X8XS5936.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\canc5ffa.rra (2 bytes)
    %Program Files%\FantastiGames\X7XS5965.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dial5f6d.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\mask\upda6798.rra (96 bytes)
    %Program Files%\FantastiGames\Skins\000005\mask\play6788.rra (144 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\invi6306.rra (262 bytes)
    %Program Files%\FantastiGames\exs.ini (9682 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\dl_i63d1.rra (32 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_5ffa.rra (1 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\iuse515a.rra (6134 bytes)
    %Program Files%\FantastiGames\Skins\000005\sound\Popu68b1.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\yaho6641.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\post644d.rra (966 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\tabs63c1.rra (4 bytes)
    %Program Files%\FantastiGames\Data\vers58b9.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e6690.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann6299.rra (2 bytes)
    C:\ProgramData\FantastiGames\Setu7167.rra (1568 bytes)
    %Program Files%\FantastiGames\X8Ex5917.rra (16732 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pids5d6b.rra (58 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e669e.rra (1 bytes)
    %Program Files%\FantastiGames\exs58c9.rra (3162 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\data57c0.rra (10160 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\isrt.dll (331 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\dott6354.rra (35 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_6019.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\nobu67f5.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\myGa5fcb.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c23.rra (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\defa5408.rra (1 bytes)
    %Program Files%\FantastiGames\X6Ex5927.rra (9120 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63f0.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\AC_R63d1.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\eror5f7d.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\mg5d5b.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\skip6853.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\swit647c.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\logi642e.rra (1 bytes)
    %Program Files%\FantastiGames\ProviderComponents.ini (577 bytes)
    %Program Files%\FantastiGames\Skins\000005\GameInfoDefault\Spla5b29.rra (29 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62a8.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\game6373.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5df7.rra (5 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d99.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Help673a.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_o66dd.rra (6 bytes)
    %Program Files%\FantastiGames\GPlr586b.rra (18290 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Tray66fc.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\spla647c.rra (6 bytes)
    C:\Windows\Downloaded Program Files\ExentCtl.ocx (512 bytes)
    C:\ProgramData\FantastiGames\Exen7148.rra (10160 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6835.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b77.rra (15 bytes)
    %Program Files%\FantastiGames\cmhe589a.rra (6134 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\subm60b5.rra (2 bytes)
    %Program Files%\FantastiGames\wh_P58b9.rra (4456 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\setu57cf.rra (7384 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\yesb6891.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\Skin64bb.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_i66cd.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\GameInfoDefault\md5b29.rra (383 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c33.rra (15 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\post644e.rra (966 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\Most5fac.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_s66dd.rra (12 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e667f.rra (4 bytes)
    %Program Files%\FantastiGames\npGa5a01.rra (51622 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\sign646d.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_d5b58.rra (10 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\mg_i643e.rra (20 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5d2c.rra (22 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d8a.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\jque641f.rra (3404 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\ad5d4b.rra (697 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\gmt\cls_5d2c.rra (10 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6834.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5de7.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6816.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\OffL5b49.rra (374 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5dc8.rra (8 bytes)
    %Program Files%\FantastiGames\GUpd58aa.rra (5738 bytes)
    %Program Files%\FantastiGames\NPGa5a20.rra (10 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\preR646d.rra (14 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Conn5b39.rra (296 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\_IsRes.dll (258 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\yesb6892.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6843.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\load6383.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\icon5f8d.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\MyGa5fbb.rra (4298 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setup.ini (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\buy_5fdb.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63e0.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\mask\logi6788.rra (144 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL670b.rra (34 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3XAKTYJE.txt (1534 bytes)
    C:\Windows\Exen5975.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\sear63a2.rra (23 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgTo6103.rra (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZN9D1766.txt (1534 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\GPla673a.rra (17 bytes)
    %Program Files%\FantastiGames\DoDl58c9.rra (6134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\pft4C5D.tmp\setup.log (139 bytes)
    %Program Files%\FantastiGames\AppL588b.rra (33818 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\MyGa6759.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\debu5b68.rra (1 bytes)
    C:\ProgramData\FantastiGames\setu7177.rra (259 bytes)
    %Program Files%\FantastiGames\GPlayer.exe (485 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice534d.rra (38 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bb6.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\MinC6392.rra (6 bytes)
    C:\ProgramData\FantastiGames\FRGN7158.rra (2712 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_g66ae.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e07.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5d7a.rra (14 bytes)
    C:\ProgramData\FantastiGames\exs7148.rra (12280 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e16.rra (35 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\hide6067.rra (2 bytes)
    %Program Files%\Common Files\InstallShield\IScript\iscript.dll (225 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\drop6344.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_260a5.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5ba6.rra (20 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\eula5f7d.rra (5 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\skin5e83.rra (11 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5d1d.rra (13 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\stil6335.rra (20 bytes)
    %Program Files%\FantastiGames\Skins\000005\Skin5b1a.rra (30 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62c7.rra (2 bytes)
    %Program Files%\FantastiGames\X358aa.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\spla5e93.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_p5b68.rra (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\setu532e.rra (7384 bytes)
    %Program Files%\FantastiGames\Skins\000005\NIBmps\NetI67a7.rra (2520 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\chk_6009.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\yesn648c.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6086.rra (2 bytes)
    %Program Files%\FantastiGames\Clie586b.rra (395 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_l66cd.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Onli674a.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\hide6057.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\trac647c.rra (10 bytes)
    %Program Files%\FantastiGames\Skins\000005\Langs\0409\Stri6779.rra (11940 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\layo5f9c.rra (5 bytes)
    %Program Files%\FantastiGames\EXEt586b.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b87.rra (22 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\auto6621.rra (36 bytes)
    %Program Files%\FantastiGames\Skins\000005\Sett5b0a.rra (1 bytes)
    C:\ProgramData\FantastiGames\layo7167.rra (417 bytes)
    %Program Files%\FantastiGames\ExentComponents.ini (29803 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL66fc.rra (34 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\logi5e74.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\mg_i5e74.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL672b.rra (17 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll (176 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6048.rra (1 bytes)
    %Program Files%\FantastiGames\Game586b.rra (4456 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\dial5e55.rra (3 bytes)
    %Program Files%\FantastiGames\X4HS57ef.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\logi62d7.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_a5b49.rra (3404 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\nobu6805.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\Thum6151.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\logi62e7.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\topL6289.rra (1 bytes)
    C:\ProgramData\FantastiGames\data70fa.rra (164783 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_d6641.rra (22 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5db9.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_m66dd.rra (18 bytes)
    %Program Files%\FantastiGames\Skins\000005\dat\GPlr5b1a.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bd5.rra (14 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\upda6872.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\load6132.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5b97.rra (23 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\key_642e.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\erro63ff.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\og_i5e83.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\anim6612.rra (13 bytes)
    %Program Files%\FantastiGames\X7Ex5946.rra (20620 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\skip6854.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\atta60d4.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\GATr5f8d.rra (2326 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgRi60f3.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\adGa5e35.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL671c.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\nobu67f6.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\main6392.rra (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PNF45JVQ.txt (1534 bytes)
    %Program Files%\FantastiGames\AppLoader2KEx.dll (49 bytes)
    %Program Files%\FantastiGames\X6XS5936.rra (1568 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\spac5fdb.rra (49 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6815.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos62e7.rra (376 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL671b.rra (34 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\flas63ff.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\clos67e7.rra (2 bytes)
    %Program Files%\FantastiGames\repo585c.rra (292 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\clos67e6.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\MyDo674a.rra (17 bytes)
    C:\Windows\Downloaded Program Files\Exen5975.rra (18290 bytes)
    %Program Files%\FantastiGames\FRGN59e2.rra (4314 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\flas640f.rra (19 bytes)
    C:\Users\Public\Desktop\More FREE games.lnk (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\Langs\0409\EXEt6769.rra (843 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\logi5b77.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\adGa5e26.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\flas6122.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_16096.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e668f.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\logo5fac.rra (26 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\play643e.rra (729 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\pb5fcb.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\clos6038.rra (2 bytes)
    %Program Files%\FantastiGames\Fant59e2.rra (2712 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Chan66ec.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\back67b7.rra (12 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\upda6882.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\NIBmps\NetI6798.rra (1260 bytes)
    %Program Files%\FantastiGames\exs.dll (675 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\yesb68a1.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\canc67b8.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\gplayer\gpla5d3c.rra (4365 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL670c.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6038.rra (2 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\obje514a.rra (798 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\dl_i5e55.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_g66bd.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\FRGL672c.rra (17 bytes)
    %Program Files%\FantastiGames\myGa59e2.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\chan6344.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_m5b58.rra (23 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\IAF674a.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5da9.rra (10 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\ap_c5b58.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\topR6299.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\play6325.rra (9 bytes)
    %Program Files%\FantastiGames\glut5918.rra (2712 bytes)
    %Program Files%\FantastiGames\Skins\000005\GameInfoDefault\Game5b1a.rra (12 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\pl\pl_e6650.rra (5 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\ctor511b.rra (3404 bytes)
    %Program Files%\FantastiGames\glut5946.rra (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice537c.rra (31 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\erro5e64.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bgLe60e4.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\mask\erro6779.rra (144 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\isrt53f9.rra (11940 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MBLJWWXW.txt (1534 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\_IsR5418.rra (8474 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\retr6141.rra (3 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\data57b0.rra (1568 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\canc5fea.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\spec64ca.rra (807 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice536d.rra (2343 bytes)
    C:\ProgramData\FantastiGames\setu7167.rra (7385 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\drop6363.rra (181 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5be5.rra (22 bytes)
    %Program Files%\FantastiGames\X5Ex5955.rra (11328 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\drop63e0.rra (5 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\logo6383.rra (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\234MYWU9.txt (1534 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\dl5d5b.rra (7 bytes)
    %Program Files%\FantastiGames\Game58e8.rra (64414 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\yesn5f6d.rra (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\50ae.rra (100 bytes)
    C:\ProgramData\FantastiGames\iker7158.rra (6720 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\clos6029.rra (3 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\laun6315.rra (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\lice536c.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\fram641f.rra (14 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c04.rra (9 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Serv6759.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\YUI\data6631.rra (31 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5c13.rra (4 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\defa5d4b.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5ca0.rra (5 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\skip6863.rra (6 bytes)
    %Program Files%\FantastiGames\glut5917.rra (4314 bytes)
    C:\Users\Public\Desktop\Play Free Games.lnk (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\butt5f6d.rra (7 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\Subs63b1.rra (16 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\skinUI\load6373.rra (2334 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{2b7bdadb-ec8c-4c54-b5dd-ce45a016d3a7}\valu539b.rra (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6R2FOOCT.txt (1534 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\gplayer\gpla5d4b.rra (16 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\Skin64ab.rra (3 bytes)
    %Program Files%\FantastiGames\EXEt59d2.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\auto5e35.rra (1 bytes)
    %Program Files%\FantastiGames\Clie58b9.rra (262 bytes)
    %Program Files%\FantastiGames\glut68c0.rra (2712 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5e26.rra (20 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\layo57b0.rra (417 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\pinb6824.rra (2 bytes)
    %Program Files%\FantastiGames\X5XS5965.rra (1568 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\comm5e45.rra (92 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\prvd5dd8.rra (6 bytes)
    %Program Files%\FantastiGames\GPla57ef.rra (154846 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Exit66fc.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\help6057.rra (2 bytes)
    %Program Files%\FantastiGames\lice587b.rra (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\S1ZLQF5G.txt (1534 bytes)
    %Program Files%\Common Files\InstallShield\IScript\iscr51e6.rra (7348 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\clie63d1.rra (581 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\canc67c7.rra (6 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\subm60c5.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\bott6113.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\GPlr673a.rra (17 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setu57cf.rra (1 bytes)
    %Program Files%\FantastiGames\npEx5984.rra (8474 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\masks\bann62b8.rra (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\WP2BZ5ZM.txt (1534 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\logo6141.rra (8 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\ok_06086.rra (2 bytes)
    %Program Files%\Common Files\InstallShield\Engine\6\Intel 32\core510c.rra (28 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6067.rra (2 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\btn\more6077.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\dialogBox\load6122.rra (2334 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\css\fram5e64.rra (5 bytes)
    %Program Files%\InstallShield Installation Information\{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}\Setu57c0.rra (1568 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\clos67f5.rra (1 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\PreR64ab.rra (1 bytes)
    %Program Files%\FantastiGames\exs58d9.rra (22520 bytes)
    %Program Files%\FantastiGames\Skins\000005\Popups\1\Chec67d6.rra (1264 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\preRoll\clos6306.rra (247 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\OffL5b39.rra (22 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Exent\classes\cls_5bc5.rra (23 bytes)
    %Program Files%\FantastiGames\Skins\000005\icon\Sett6769.rra (17 bytes)
    %Program Files%\FantastiGames\Skins\000005\GameInfoDefault\spla5b29.rra (27 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\img\myGa5fbb.rra (22 bytes)
    %Program Files%\FantastiGames\Skins\000005\html\Skin\Provider\js\skin_events\PreR649b.rra (2 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\FantastiGames.lnk (1 bytes)

  5. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "DependencyCheck" = "Performed"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exent_SDM" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\SDM143\Free Ride Games.exe l 'Startup' u 'http://www.freeridegames.com/do/SDMC?action=config&type=FANTASTIGAMES_EULA&contentId=%d' p '143' c '595450'"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

    [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

    [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Exetender" = "%Program Files%\FantastiGames\GPlayer.exe /runonstartup"

  6. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  7. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Average: 1 (1 vote)

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now