Trojan.Generic.19959250_45a1ce46be

by malwarelabrobot on December 17th, 2016 in Malware Descriptions.

Trojan.Win32.Autoit.abclk (Kaspersky), Trojan.Generic.19959250 (B) (Emsisoft), Trojan.Generic.19959250 (AdAware), Worm.Win32.AutoIt.FD, WormAutoItGen.YR (Lavasoft MAS)
Behaviour: Trojan, Worm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 45a1ce46bef1495be6ae3512cf6cbefb
SHA1: 94ed75986be92a399879c041100059ab95655061
SHA256: 4255625d7efad5863be27159c0e10c6a86ba80ada9f550dc5174197fdbfaf5c1
SSDeep: 49152:MKTe044CXQz/6EZYJl3UMfufXHNbRDmpSh92ehxfMj3Y5sZD7KnuVBL:WpzQWEuJhZuf3xfxBMjSsZD75
Size: 2256896 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Software Assistant
Created at: 2014-10-31 05:28:47
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

MIICRU~1.EXE:3856
ecVV.exe:3604
%original file name%.exe:3888

The Trojan injects its code into the following process(es):

RegSvcs.exe:3952
wuapp.exe:3632

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process MIICRU~1.EXE:3856 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ecVV.exe (10129 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\HSbBN (10564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\ecVV.exe (1874 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut9453.tmp (5505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut951E.tmp (9365 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\HSbBN (1 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut9453.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut951E.tmp (0 bytes)

The process ecVV.exe:3604 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UHiQVTPeKYCJ.lnk (838 bytes)

The process %original file name%.exe:3888 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\MIICRU~1.EXE (38125 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ecVV.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\HSbBN (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\MIICRU~1.EXE (0 bytes)

The process RegSvcs.exe:3952 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\STLcyHegih\SS2Svc64.exe (44 bytes)

Registry activity

The process %original file name%.exe:3888 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"

The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0"

The process RegSvcs.exe:3952 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"dCncPGxdPI" = "C:\Users\"%CurrentUserName%"\AppData\Local\STLCYH~1\SS2Svc64.exe"

Dropped PE files

MD5 File path
0071b7c5aaec775409469ea439c0d192 c:\Users\"%CurrentUserName%"\AppData\Local\STLcyHegih\SS2Svc64.exe
b06e67f9767e5023892d9698703ad098 c:\Users\"%CurrentUserName%"\WcCLwdV5hL4bqF1C\ecVV.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16384
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16384 (winblue_rtm.130821-1623)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: Japanese (Japan)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 26980 27136 4.40175 22c7cbc7745692002dbdf65a4bc48e63
.data 32768 6796 1024 2.20139 317f8a934ee443eee01c2a315bde9ca1
.idata 40960 4220 4608 3.49841 a5d9b0c8d0d0e35bcbb5219dda1a3075
.rsrc 49152 2220295 2220544 5.4419 10c201bfae8374d9f9e6b821b44e5b9b
.reloc 2273280 2240 2560 4.41763 7772c8e6ff71410862c324630aac5515

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
xmr.crypto-pool.fr 212.129.44.155


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY BitCoinMiner Cpuminer Login

Traffic

The Trojan connects to the servers at the folowing location(s):

ecVV.exe_3604:

.text
`.rdata
@.data
.rsrc
@.reloc
j.Yf;
r%f;M
j.Xf;
j.Zf;
PSSSSSSh
Gt.Ht$
.Jw`8Hw~fHw
kernel32.dll
?#%X.y
GetProcessWindowStation
operator
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
WSOCK32.dll
VERSION.dll
WINMM.dll
COMCTL32.dll
MPR.dll
InternetCrackUrlW
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
WININET.dll
PSAPI.DLL
IPHLPAPI.DLL
USERENV.dll
UxTheme.dll
GetProcessHeap
CreatePipe
GetWindowsDirectoryW
KERNEL32.dll
OpenWindowStationW
SetProcessWindowStation
CloseWindowStation
MapVirtualKeyW
EnumChildWindows
EnumWindows
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
keybd_event
EnumThreadWindows
ExitWindowsEx
UnregisterHotKey
RegisterHotKey
GetKeyboardLayoutNameW
USER32.dll
SetViewportOrgEx
GDI32.dll
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
RegEnumKeyExW
RegDeleteKeyW
ADVAPI32.dll
ShellExecuteW
SHFileOperationW
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
GetCPInfo
TC<jTk.jTI)jT5(jT
(jTI.jT
zcÁ
UQ.WP
mI.Us
\.gGL
.FFF<
,.bh9
].Whjj*
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
? ?$?(?,?0?4?8?
2 2$2(2,2024282
<#<'< </<
4F4s4
4D4C4R4e4u4
2!2%2)2-2125292=2
01s1
2=22393@3[3
?&?-?4?:?
8Ÿ94:
8!9*919<9
> >$>(>,>
? ?$?(?,?0?
/AutoIt3ExecuteScript
/AutoIt3ExecuteLine
CMDLINE
CMDLINERAW
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLSENDMSG
GUIGETMSG
GUIREGISTERMSG
HOTKEYSET
HTTPSETPROXY
HTTPSETUSERAGENT
ISKEYWORD
MAPKEYS
MSGBOX
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTEWAIT
TCPACCEPT
TCPCLOSESOCKET
TCPCONNECT
TCPLISTEN
TCPNAMETOIP
TCPRECV
TCPSEND
TCPSHUTDOWN
TCPSTARTUP
TRAYGETMSG
UDPBIND
UDPCLOSESOCKET
UDPOPEN
UDPRECV
UDPSEND
UDPSHUTDOWN
UDPSTARTUP
SendKeyDownDelay
SendKeyDelay
TCPTimeout
mscoree.dll
combase.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
USER32.DLL
789:;<=>?
APPSKEY
WINDOWSDIR
AUTOITEXE
HOTKEYPRESSED
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
KEYS
Line %d:
\\?\UNC\
04090000
%u.%u.%u.%u
0.0.0.0
Mddddd
"%s" (%d) : ==> %s:
\??\%s
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
255.255.255.255
Keyword
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 14, 2
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_USERS
%d/d/d
C:\Users\"%CurrentUserName%"\AppData\Roaming\ecVV.exe
hXXp://VVV.autoitscript.com/autoit3/
AutoIt3.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.

RegSvcs.exe_3952:

.text
`.rdata
@.data
.rsrc
@.reloc
GetProcessWindowStation
operator
shell32.dll
ntdll.dll
xmr.crypto-pool.fr:3333
SS2Svc64.exe
-a cryptonight -o stratum tcp://%s -u %s -p %s -t %u
GetWindowsDirectoryW
KERNEL32.dll
USER32.dll
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
ADVAPI32.dll
ole32.dll
GetProcessHeap
GetCPInfo
zcÁ
VgCSP%X
!R7%x8
0].Mk
.Qx=ZK_
Mlt%U
7-u}h
yO.JB|Ea
;_t|%u
n%.DS
]:~.rAN
\.LHTP
.,.pe|
a*.BzO[
z.SVP
.aD\AY
%uf^A`
\.adgj/
%xX{<
T|HtCp
- %cGsambi$ou
t/ux
ourl=URL0
passb:P
S.eadjN
CPU=%d;KHS
c%c==
HTTP/
WebSOj
tX4Fr.rh.46Aw-wl-6
#"! '&%$ *)(/.-,32107654
Û`6
rj<s.yN>
#[.xU
a-C7}
.Wtxz(
lle.muig
.ana2
xz%Dm
7[\]^_`_
tCPb
.pPFgR
K.mi;o
.nnr1
7.46.0386l
.zxx.
TCP_N\LAY
~.Unm3
o.ZFWw
gg_'2r%S___
_i5%s-job_
(;%x'i
1W.pO R
MV.Zh
}X# .idX
yKey!K
#y.Bv
KERNEL32.DLL
Normaliz.dll
WLDAP32.dll
WS2_32.dll
0V.FP
ing.subs
X(.Lt
eURL
\.EEEEU
libcurl/
SB.dB
]B.dB
2.ssc#]
q.anges: b
.ukum
DsT%ul
O@.Oe
d%X^6
41234567
%S08l
.di0"
j_.Zm
.lC4H
K.yv 0
%S,]Q
p.sb:P
PASSWOR
t.zdjN
m tcp?{7X
.rh.46Aw-wl-6
.eK9K\9.
"$&(*,.0
`255[^:]
.Unm3
**/*"1.1
|%ds|X|
127[^,],3
2_32.Dr
o.GO5pe,g]
WEBS
.WAYw
.gifmr
.DzA[a
.DV''''p
NCRT!pN
msvcrt.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
01n1|1
8!9-9q9}9
3 3$3(3,30343~3
mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
notepad.exe
explorer.exe
System32\wuapp.exe
System32\svchost.exe
taskmgr.exe
:Zone.Identifier
1.0.0.1
sysmagr.exe

RegSvcs.exe_3952_rwx_00070000_000BA000:

.text
`.rdata
@.data
.rsrc
@.reloc
GetProcessWindowStation
operator
shell32.dll
ntdll.dll
xmr.crypto-pool.fr:3333
SS2Svc64.exe
-a cryptonight -o stratum tcp://%s -u %s -p %s -t %u
GetWindowsDirectoryW
KERNEL32.dll
USER32.dll
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
ADVAPI32.dll
ole32.dll
GetProcessHeap
GetCPInfo
zcÁ
VgCSP%X
!R7%x8
0].Mk
.Qx=ZK_
Mlt%U
7-u}h
yO.JB|Ea
;_t|%u
n%.DS
]:~.rAN
\.LHTP
.,.pe|
a*.BzO[
z.SVP
.aD\AY
%uf^A`
\.adgj/
%xX{<
T|HtCp
- %cGsambi$ou
t/ux
ourl=URL0
passb:P
S.eadjN
CPU=%d;KHS
c%c==
HTTP/
WebSOj
tX4Fr.rh.46Aw-wl-6
#"! '&%$ *)(/.-,32107654
Û`6
rj<s.yN>
#[.xU
a-C7}
.Wtxz(
lle.muig
.ana2
xz%Dm
7[\]^_`_
tCPb
.pPFgR
K.mi;o
.nnr1
7.46.0386l
.zxx.
TCP_N\LAY
~.Unm3
o.ZFWw
gg_'2r%S___
_i5%s-job_
(;%x'i
1W.pO R
MV.Zh
}X# .idX
yKey!K
#y.Bv
KERNEL32.DLL
Normaliz.dll
WLDAP32.dll
WS2_32.dll
0V.FP
ing.subs
X(.Lt
eURL
\.EEEEU
libcurl/
SB.dB
]B.dB
2.ssc#]
q.anges: b
.ukum
DsT%ul
O@.Oe
d%X^6
41234567
%S08l
.di0"
j_.Zm
.lC4H
K.yv 0
%S,]Q
p.sb:P
PASSWOR
t.zdjN
m tcp?{7X
.rh.46Aw-wl-6
.eK9K\9.
"$&(*,.0
`255[^:]
.Unm3
**/*"1.1
|%ds|X|
127[^,],3
2_32.Dr
o.GO5pe,g]
WEBS
.WAYw
.gifmr
.DzA[a
.DV''''p
NCRT!pN
msvcrt.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
01n1|1
8!9-9q9}9
3 3$3(3,30343~3
mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
notepad.exe
explorer.exe
System32\wuapp.exe
System32\svchost.exe
taskmgr.exe
:Zone.Identifier
1.0.0.1
sysmagr.exe

SearchProtocolHost.exe_3964:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
MSSHooks.dll
IMM32.dll
SHLWAPI.dll
SrchCollatorCatalogInfo
SrchDSSLogin
SrchDSSPortManager
SrchPHHttp
SrchIndexerQuery
SrchIndexerProperties
SrchIndexerPlugin
SrchIndexerClient
SrchIndexerSchema
Msidle.dll
Failed to get REGKEY_FLTRDMN_MS_TO_IDLE, using default
pfps->psProperty.ulKind is LPWSTR but psProperty.lpwstr is NULL or empty
d:\win7sp1_gdr\enduser\mssearch2\common\utils\crchash.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrdmn\fltrdaemon.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\common\include\secutil.hxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracerhelpers.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
</MSG></TRC>
<MSG>
<ERR> 0xx=
<LOC> %s(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%s"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%s"
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
SHELL32.dll
PROPSYS.dll
ntdll.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
MsgWaitForMultipleObjects
SearchProtocolHost.pdb
2 2(20282|2
4%5S5
Software\Microsoft\Windows Search
https
kernel32.dll
msTracer.dll
msfte.dll
lX-X-X-XX-XXXXXX
SOFTWARE\Microsoft\Windows Search
tquery.dll
%s\%s
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
advapi32.dll
WAPI-MS-Win-Core-LocalRegistry-L1-1-0.dll
winhttp.dll
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<LOC> %S(%d) </LOC>
tagname="%S"
logname="%S"
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
Microsoft Windows Search Protocol Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchProtocolHost.exe
Windows
7.00.7601.17610

wuapp.exe_3632:

bb b!"bb#$bbbb%&'bbb(b)*b bbb,-.bb/0123bbbb4b5bbbbbbb6bbbbbb789:;<bbbbbbbb=bbb>?@ABCDEbbbbFbbbbGHbbbbbIbJKLbbbbbMNbbbOObbPbbbbbbbbbQbbRbSTUVWbXbbbbbbYZ[b\bb]^_bb`ba
>%ugj
u.hPHL
t.Gj:W
3|$\3|$4
option requires an argument -- %c
option requires an argument -- %s
unknown option -- %c
unknown option -- %s
\ux
\ux\ux
`%s near '%s'
%s near end of file
unable to decode byte 0x%x
control character 0x%x
invalid Unicode '\uX\uX'
invalid Unicode '\uX'
duplicate object key
unable to open %s: %s
0123456789;
-o, --url=URL URL of mining server
-O, --userpass=U:P username:password pair for mining server
-p, --pass=PASSWORD password for mining server
--cert=FILE certificate for mining server using SSL
-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy
--no-longpoll disable long polling support
--no-getwork disable getwork support
--no-gbt disable getblocktemplate support
--no-stratum disable X-Stratum support
--no-extranonce disable Stratum extranonce support
--no-redirect ignore requests to change the URL of the mining server
-b, --api-bind IP/Port for the miner API (default: 127.0.0.1:4048)
A127.0.0.1
seturl
CPU=%d;KHS=%.2f|
NAME=%s;VER=%s;API=%s;ALGO=%s;CPUS=%d;KHS=%.2f;ACC=%d;REJ=%d;ACCMN=%.3f;DIFF=%.6f;TEMP=%.1f;FAN=%d;FREQ=%d;UPTIME=%.0f;TS=%u|
%c%c==
%c%c%c=
%c%c%c%c
clientkey: %s
%s258EAFA5-E914-47DA-95CA-C5AB0DC85B11
HTTP/1.1 101 Switching Protocol
Upgrade: WebSocket
Sec-WebSocket-Accept: %s
Sec-WebSocket-Protocol: text
0.0.0.0
API not running (no valid IPs specified)%s
API initialisation failed (%s)%s
API initialisation 2 failed (%s)%s
API bind to port %d failed - trying again in 20sec
API bind to port %d failed (%s)%s
API initialisation 3 failed (%s)%s
API failed (%s)%s
API: connection from %s - %s
Sec-WebSocket-Key
API: exec command %s(%s)
tX4Fr.rh.46Aw-wl-6
.eK9K\9.
t44Fr.rh.66Aw-wl-
..eK9K\9
.rh.44Fr-wl-66Aw
O9K\9..eKW
trh.44Fr.wl-66Aw-
K\9..eK9
h.44Fr.rl-66Aw-w
O\9..eK9K=W
tXXFr.rh.44Aw-wl-66
.44Fr.rh-66Aw-wl
9..eK9K\W
r.rh.44Fw-wl-66A
rj<s.yN>
#[.xU
a-C7}
8.lCd
..r.zb)zKK
K.EGG
..rKzb)zKK
%sXAA
.hWBB
Visual C   CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
operator
ftps
https
smtp
smtps
tftp
7.46.0
libcurl/7.46.0
Unrecognized parameter value passed via CURLOPT_SSLVERSION
Curl_poll(%d ds, %d ms)
Pipe broke: handle %p, url = %s
In state %d with no easy_conn, bail out!
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
Operation timed out after %ld milliseconds with %I64d bytes received
Internal error clearing splay node = %d
Internal error removing splay node = %d
ignoring failed cookie_init for %s
23[^;
=] =I99[^;
httponly
skipped cookie with bad tailmatch domain: %s
#HttpOnly_
%s cookie %s="%s" for domain %s, path %s, expire %I64d
%s%s%s
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# Fatal libcurl error
WARNING: failed to save cookies in %s
security.dll
secur32.dll
Could not resolve %s: %s
init_resolve_thread() failed for %s; %s
getaddrinfo() failed for %s:%d; %s
%s:%d
Hostname %s was found in DNS cache
%5[^:]:%d
Couldn't parse CURLOPT_RESOLVE removal entry '%s'!
%5[^:]:%d:%5s
Couldn't parse CURLOPT_RESOLVE entry '%s'!
Address in '%s' found illegal!
Added %s:%d:%s to DNS cache
rcmd
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Found bundle for host %s: %p
Server doesn't support multi-use yet, wait
Server doesn't support multi-use (yet)
Pipe is full, skip (%zu)
Multiplexed connection found!
Connected to %s (%s) port %ld (#%ld)
Failed to convert %s to ACE;
Protocol "%s" not supported or disabled in libcurl
Illegal characters found in URL
[^:]:%[^
:]://%[^
<url> malformed
SMTP.
Rebuilt URL to: %s
Please URL encode %% as %%, see RFC 6874.
http_proxy
No valid port number in proxy string (%s)
[%*45[0123456789abcdefABCDEF:.]%c
IPv6 numerical address used in URL without brackets
;type=%c
%s://%s%s%s:%hu%s%s%s
Port number out of range
Couldn't find host %s in the _netrc file; using defaults
PTF@example.com
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
%s://%s
Found connection %ld, with requests in the pipe (%zu)
Re-using existing connection! (#%ld) with %s %s
No more connections allowed to host: %d
User-Agent: %s
Connection #%ld to host %s left intact
Send failure: %s
Recv failure: %s
Write callback asked for PAUSE when not supported!
[%s %s %s]
Failed to set SO_KEEPALIVE on fd %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Couldn't bind to interface '%s'
Local Interface %s is ip %s using address family %i
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
Local port: %hu
Bind to local port %hu failed, trying next
bind failed with errno %d: %s
getpeername() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
connect to %s port %ld failed: %s
Failed to connect to %s port %ld: %s
Could not set TCP_NODELAY: %s
TCP_NODELAY set
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
Immediate connect fail for %s: %s
schannel: SSL/TLS connection with %s port %hu (step 1/3)
schannel: disabled server certificate revocation checks
schannel: checking server certificate revocation
schannel: verifyhost setting prevents Schannel from comparing the supplied target name with the subject names in server certificates. Also disables SNI.
schannel: SNI or certificate check failed: %s
schannel: AcquireCredentialsHandle failed: %s
schannel: using IP address, SNI is not supported by OS.
schannel: initial InitializeSecurityContext failed: %s
schannel: SSL/TLS connection with %s port %hu (step 2/3)
schannel: a client certificate has been requested
schannel: next InitializeSecurityContext failed: %s
schannel: SSL/TLS connection with %s port %hu (step 3/3)
schannel: incremented credential handle refcount = %d
select/poll on SSL/TLS socket, errno: %d
select/poll on SSL socket, errno: %d
schannel: Curl_read_plain returned CURLE_AGAIN
schannel: Curl_read_plain returned CURLE_RECV_ERROR
schannel: Curl_read_plain returned error %d
schannel: failed to read data from server: %s
schannel: shutting down SSL/TLS connection with %s port %hu
schannel: ApplyControlToken failure: %s
schannel: failed to send close msg: %s (bytes written: %zd)
schannel: decremented credential handle refcount = %d
--:--:--
%3I64d %s %3I64d %s %3I64d %s %s %s %s %s %s %s
operation aborted by callback
Read callback asked for PAUSE when not supported!
seek callback returned error %d
the ioctl callback returned %d
ioctl callback returned error %d
Rewinding stream by : %zd bytes on url %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
HTTP server doesn't seem to support byte ranges. Cannot resume.
Simulate a HTTP 304 response!
%s in chunked-encoding
Rewinding stream by : %zu bytes on url %s (size = %I64d, maxdownload = %I64d, bytecount = %I64d, nread = %zd)
Excess found in a non pipelined read: excess = %zu, size = %I64d, maxdownload = %I64d, bytecount = %I64d
No URL set!
%%x
[^?&/:]://%c
Issue another request to this URL: '%s'
Disables POST, goes with %s
HTTPS
%s:%s
%sAuthorization: Basic %s
The requested URL returned error: %d
%s auth using %s with user '%s'
%s, d %s M d:d:d GMT
If-Modified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Referer: %s
Accept-Encoding: %s
Chunky upload is not supported by HTTP 1.0
Host: %s%s%s
Host: %s%s%s:%hu
PTF://
Range: bytes=%s
Content-Range: bytes %s%I64d/%I64d
Content-Range: bytes %s/%I64d
PTF://%s:%s@%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s=%s
Internal HTTP POST error!
Content-Type: application/x-www-form-urlencoded
Failed sending HTTP POST request
Failed sending HTTP request
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %s
Connection closure while negotiating auth (HTTP 1.0?)
HTTP error before end of send, stop sending
HTTP/%d.%d %d
Lying server, not serving HTTP/2
HTTP =
RTSP/%d.%d =
HTTP 1.0, assume close after body
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 connection set to keep alive!
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Conn: %ld (%p) Receive pipe weight: (%I64d/%zu), penalized: %s
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
d:d:d
d:d
0123456789
Unsupported protocol
URL using bad/illegal format or missing URL
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
FTP: weird server reply
FTP: The server failed to connect to data port
FTP: Accepting server connect has timed out
FTP: The server did not accept the PRET command.
FTP: unknown PASS reply
FTP: unknown PASV reply
FTP: unknown 227 response format
FTP: can't figure out the host in the PASV response
Error in the HTTP2 framing layer
FTP: couldn't set file type
FTP: couldn't retrieve (RETR failed) the specified file
HTTP response code said error
FTP: command PORT failed
FTP: command REST failed
Operation was aborted by an application callback
A libcurl function was given a bad argument
An unknown option was passed in to libcurl
SSL peer certificate or SSH remote key was not OK
Problem with the local SSL certificate
Peer certificate cannot be authenticated with given CA certificates
Problem with the SSL CA cert (path? access rights?)
Unrecognized or bad HTTP Content or Transfer-Encoding
Invalid LDAP URL
Issuer check against peer certificate failed
Login denied
TFTP: File Not Found
TFTP: Access Violation
TFTP: Illegal operation
TFTP: Unknown transfer ID
TFTP: No such user
Caller must register CURLOPT_CONV_ callback options
Error in the SSH layer
Unable to parse FTP file list
SSL public key does not match pinned public key
SSL server certificate status verification FAILED
Protocol option is unsupported
Protocol is unsupported
Socket is unsupported
Operation not supported
Address family not supported
Protocol family not supported
Winsock version not supported
Unknown error %d (%#x)
SEC_E_CERT_EXPIRED
SEC_E_CERT_UNKNOWN
SEC_E_CERT_WRONG_USAGE
SEC_E_KDC_CERT_EXPIRED
SEC_E_KDC_CERT_REVOKED
SEC_E_NO_KERB_KEY
SEC_E_NO_S4U_PROT_SUPPORT
SEC_E_QOP_NOT_SUPPORTED
SEC_E_SMARTCARD_CERT_EXPIRED
SEC_E_SMARTCARD_CERT_REVOKED
SEC_E_STRONG_CRYPTO_NOT_SUPPORTED
SEC_E_UNSUPPORTED_FUNCTION
SEC_E_UNSUPPORTED_PREAUTH
SEC_E_ILLEGAL_MESSAGE (0xXX) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.
%s (0xXX)
%s - %s
%d.%d.%d.%d
LOGIN %s %s
AUTHENTICATE %s %s
AUTHENTICATE %s
No known authentication mechanisms supported!
LIST "%s" *
SELECT %s
FETCH %s BODY[%s]<%s>
FETCH %s BODY[%s]
APPEND %s (\Seen) {%I64d}
SEARCH %s
LOGINDISABLED
STARTTLS not supported.
STARTTLS denied. %c
Access denied. %c
%cd
%s %s
USER %s
APOP %s %s
AUTH %s %s
AUTH %s
STLS not supported.
Authentication failed: %d
PASS %s
CLIENT libcurl 7.46.0
MATCH %s %s %s
DEFINE %s %s
WSAStartup failed (%d)
insufficient winsock version to support telnet
%s IAC %s
%s IAC %d
%s %s %s
%s %s %d
%s %d %d
Sending data failed (%d)
%s IAC SB
%s (unsupported)
%d (unknown)
USER,%s
7[^= ]%*[ =]%5s
Syntax error in telnet option: %s
Unknown telnet option %s
%c%c%c%c%s%c%c
7[^,],7s
%c%s%c%s
WS2_32.DLL
failed to load WS2_32.DLL (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEnumNetworkEvents function (%d)
WSACreateEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACloseEvent failed (%d)
FreeLibrary(wsock2) failed (%d)
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
got option=(%s) value=(%s)
blksize is larger than max supported
%s (%d)
blksize is smaller than min supported
%s (%ld)
%s (%d) %s (%d)
invalid tsize -:%s:- value in OACK packet
%s%c%s%c
tftp_send_first: internal error
Received last DATA packet block %d again.
Received unexpected DATA packet block %d, expecting block %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
Received ACK for block %d, expecting %d
tftp_tx: giving up waiting for block %d ack
tftp_tx: internal error, event: %i
TFTP finished
bind() failed; %s
TFTP response timeout
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
LDAP local: %s
LDAP local: trying to establish %s connection
LDAP local: Cannot connect to %s:%ld
LDAP local: ldap_simple_bind_s %s
LDAP remote: %s
There are more than %d entries
SMTP
SMTPS
EHLO %s
HELO %s
MAIL FROM:%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s SIZE=%s
RCPT TO:%s
RCPT TO:<%s>
Got unexpected smtp-server response: %d
Remote access denied: %d
Command failed: %d
MAIL failed: %d
RCPT failed: %d
DATA failed: %d
PORT
FTPS
Preparing for accepting server on data port
FTP response timeout
FTP response aborted due to select/poll error: %d
CWD %s
getsockname() failed: %s
failed to resolve the address provided to PORT: %s
socket failure: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) failed: %s
bind() failed, we ran out of ports!
%s |%d|%s|%hu|
Failure sending EPRT command: %s
,%d,%d
Failure sending PORT command: %s
Connect data stream passively
PRET %s
PRET STOR %s
PRET RETR %s
REST %d
SIZE %s
MDTM %s
APPE %s
STOR %s
RETR %s
%c%c%c%u%c
Illegal port number in EPSV reply
%d,%d,%d,%d,%d,%d
Skip %d.%d.%d.%d for data connection, re-use %s instead
Bad PASV/EPSV response: d
Can't resolve proxy host %s:%hu
Can't resolve new host %s:%hu
Failed to do PORT
dddddd
ddd d:d:d GMT
Last-Modified: %s, d %s M d:d:d GMT
unsupported MDTM reply format
Got a d response code instead of the assumed 200
ftp server doesn't support SIZE
Failed FTP upload: 
RETR response: d
PBSZ %d
ACCT %s
Access denied: d
ACCT rejected by server: d
Got a d ftp-server response when 220 was expected
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
PROT %c
Entry path is '%s'
QUOT command failed with d
MKD %s
Failed to MKD dir: d
PRET command not accepted: d
Remembering we are in dir "%s"
Failure sending ABOR command: %s
server did not report OK, got %d
QUOT string not accepted: %s
TYPE %c
Connecting to %s (%s) port %d
ftp_perform ends with SECONDARY: %d
Wildcard - START of "%s"
Wildcard - "%s" skipped by user
Failure sending QUIT command: %s
Uploading to a URL without a file name!
Couldn't open file %s
Can't open %s for writing
Can't get the size of %s
Refusing to issue an RTSP request [%s] without a session ID.
Transport:
Transport: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Range: %s
%s %s RTSP/1.0
Session: %s
%s%s%s%s%s%s%s%s
Unable to read the CSeq header: [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
curl
login
password
%sAuthorization: Digest %s
%sAuthorization: NTLM %s
SOCKS4 communication to %s:%d
SOCKS4 connect to %s (locally resolved)
Failed to resolve "%s" for SOCKS4 connect.
SOCKS4%s request granted.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
User was rejected by the SOCKS5 server (%d %d).
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
Failed to resolve "%s" for SOCKS5 connect.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Establish HTTP proxy tunnel to %s:%hu
%s:%hu
%s%s%s:%hu
Host: %s
CONNECT %s HTTP/%s
%s%s%s%s
HTTP/1.%d %d
TUNNEL_STATE switched to: %d
Received HTTP code %d from proxy after CONNECT
.jpeg
.html
; filename="%s"
%s; boundary=%s
Content-Type: multipart/mixed; boundary=%s
Content-Type: %s
couldn't open file "%s"
--%s--
------------------------xx
%sAuthorization: Negotiate %s
LOGIN
%s xxxxxxxxxxxxxxxx
user=%s
auth=Bearer %s
host=%s
port=%ld
Unsupported SASL authentication mechanism
0123456789-
KGS!@#$%%s/%s
NTLM handshake failure (type-3 message): Status=%x
SSPI error: %s failed: %s
User was rejected by the SOCKS5 server (%u %u).
Invalid SSPI authentication response type (%u %u).
SOCKS5 server authencticated user %s with GSS-API.
SOCKS5 server supports GSS-API %s data protection.
Invalid SSPI encryption response type (%u %u).
SOCKS5 access with%s protection granted.
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
{"method": "submit", "params": {"id": "%s", "job_id": "%s", "nonce": "%s", "result": "%s"},"id":4}
thread %d create failed
%d miner threads started, using '%s' algorithm.
{"method": "getwork", "params": ["%s"], "id":4}
{"method": "getblocktemplate", "params": [{"capabilities": ["coinbasetxn", "coinbasevalue", "longpoll", "workid"], "longpollid": "%s"}], "id":0}
{"method": "getjob", "params": {"id": "%s"}, "id":1}
json_rpc_call failed, retry after %d seconds
...terminating workio thread
...retry after %d seconds
{"method": "login", "params": {"login": "%s", "pass": "%s", "agent": "%s"}, "id": 1}
DEBUG: authenticated in %d ms
CURL initialization failed
DEBUG: job_id='%s' extranonce2=%s ntime=x
network hashrate too high, waiting %s...
Binding thread %d to cpu %d (mask %x)
Binding thread %d to cpu mask %x
work retrieval failed, exiting mining thread %d
Benchmark: %s
Mining timeout of %ds reached, exiting...
CPU #%d: %.2f H/s
CPU #%d: %s kH/s
Total: %s H/s
Total: %s kH/s
CURL init failed
Long-polling on %s
cert
%s detected new block%s
userpass
JSON decode failed(%d): %s
Starting Stratum on %s
Connection changed to %s
%s block %d, diff %.3f
%s %s block %d
net diff: %f -> shift %u, bits x
%s asks job %d for block %d
jansson/%s
pthreads/%d.%d.%d.%d
POK received: xx
getmininginfo not supported
%s block %d, %s
Unknown algo parameter '%s'
incorrect Nfactor %d
Current block is %d
%s:%d: %s
Switching to getwork, gbt version %d
Unrecognized block version: %u
hXXp://
hXXps://
stratum tcp://
unknown protocol -- '%s'
invalid URL -- '%s'
hXXp://%s
invalid username:password pair -- '%s'
invalid address -- '%s'
JSON option %s invalid
%s: unsupported non-option argument -- '%s'
accepted: %lu/%lu (%.2f%%), %s kH/s %s
reject reason: %s
127.0.0.1
block %u was already solved
Using config %s
CPU Supports AES-NI: %s
%s: no URL supplied
https:
{"method": "submit", "params": {"id": "%s", "job_id": "%s", "nonce": "%s", "result": "%s"}, "id":4}
{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}
{"method": "submitblock", "params": ["%s%s", %s], "id":4}
{"method": "submitblock", "params": ["%s%s"], "id":4}
Binding process to cpu mask %x
DEBUG: %s
Hash: %s
Target: %s
http%s
Stratum connection failed: %s
mining.notify
Stratum set nonce %s with extranonce2 size=%d
{"id": 1, "method": "mining.subscribe", "params": []}
{"id": 1, "method": "mining.subscribe", "params": ["cpuminer-multi/1.2-dev", "%s"]}
{"id": 1, "method": "mining.subscribe", "params": ["cpuminer-multi/1.2-dev"]}
JSON-RPC call failed: %s
Stratum session id: %s
{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}
{"id": 3, "method": "mining.extranonce.subscribe", "params": []}
extranonce subscribe not supported
Auth id: %s
JSON returned status "%s"
rpc2_login_decode
%s: fail
json_rpc2.0 error: %s
[%d-d-d d:d:d]%s %s%s
%s\cpuminer\cpuminer-conf.json
%s%scpuminer-conf.json
%.2f %cH/s
%.2f H/s%c
stratum tcp://%s:%d
Ignoring request to reconnect to %s
Server requested reconnection to %s
MESSAGE FROM SERVER: %s
mining.set_difficulty
mining.set_extranonce
client.reconnect
client.get_version
client.show_message
HTTP request failed: %s
xxxx
%ss%s: %s
Remote config read failed: %s
hex2bin failed on '%s'
JSON key '%s' not found
JSON key '%s' is not a string
zcÁ
694983729836531
C:\Windows\System32\wuapp.exe
GetCPInfo
GetProcessHeap
PeekNamedPipe
CryptDestroyKey
CryptImportKey
,%.%"8#"
8448408
.text
`.rdata
@.data
.reloc
#y.Bv
KERNEL32.DLL
ADVAPI32.dll
Normaliz.dll
USER32.dll
WLDAP32.dll
WS2_32.dll
.mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
2.exe
ERROR %d converting to Punycode
combase.dll

wuapp.exe_3632_rwx_00400000_000E8000:

bb b!"bb#$bbbb%&'bbb(b)*b bbb,-.bb/0123bbbb4b5bbbbbbb6bbbbbb789:;<bbbbbbbb=bbb>?@ABCDEbbbbFbbbbGHbbbbbIbJKLbbbbbMNbbbOObbPbbbbbbbbbQbbRbSTUVWbXbbbbbbYZ[b\bb]^_bb`ba
>%ugj
u.hPHL
t.Gj:W
3|$\3|$4
option requires an argument -- %c
option requires an argument -- %s
unknown option -- %c
unknown option -- %s
\ux
\ux\ux
`%s near '%s'
%s near end of file
unable to decode byte 0x%x
control character 0x%x
invalid Unicode '\uX\uX'
invalid Unicode '\uX'
duplicate object key
unable to open %s: %s
0123456789;
-o, --url=URL URL of mining server
-O, --userpass=U:P username:password pair for mining server
-p, --pass=PASSWORD password for mining server
--cert=FILE certificate for mining server using SSL
-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy
--no-longpoll disable long polling support
--no-getwork disable getwork support
--no-gbt disable getblocktemplate support
--no-stratum disable X-Stratum support
--no-extranonce disable Stratum extranonce support
--no-redirect ignore requests to change the URL of the mining server
-b, --api-bind IP/Port for the miner API (default: 127.0.0.1:4048)
A127.0.0.1
seturl
CPU=%d;KHS=%.2f|
NAME=%s;VER=%s;API=%s;ALGO=%s;CPUS=%d;KHS=%.2f;ACC=%d;REJ=%d;ACCMN=%.3f;DIFF=%.6f;TEMP=%.1f;FAN=%d;FREQ=%d;UPTIME=%.0f;TS=%u|
%c%c==
%c%c%c=
%c%c%c%c
clientkey: %s
%s258EAFA5-E914-47DA-95CA-C5AB0DC85B11
HTTP/1.1 101 Switching Protocol
Upgrade: WebSocket
Sec-WebSocket-Accept: %s
Sec-WebSocket-Protocol: text
0.0.0.0
API not running (no valid IPs specified)%s
API initialisation failed (%s)%s
API initialisation 2 failed (%s)%s
API bind to port %d failed - trying again in 20sec
API bind to port %d failed (%s)%s
API initialisation 3 failed (%s)%s
API failed (%s)%s
API: connection from %s - %s
Sec-WebSocket-Key
API: exec command %s(%s)
tX4Fr.rh.46Aw-wl-6
.eK9K\9.
t44Fr.rh.66Aw-wl-
..eK9K\9
.rh.44Fr-wl-66Aw
O9K\9..eKW
trh.44Fr.wl-66Aw-
K\9..eK9
h.44Fr.rl-66Aw-w
O\9..eK9K=W
tXXFr.rh.44Aw-wl-66
.44Fr.rh-66Aw-wl
9..eK9K\W
r.rh.44Fw-wl-66A
rj<s.yN>
#[.xU
a-C7}
8.lCd
..r.zb)zKK
K.EGG
..rKzb)zKK
%sXAA
.hWBB
Visual C   CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
operator
ftps
https
smtp
smtps
tftp
7.46.0
libcurl/7.46.0
Unrecognized parameter value passed via CURLOPT_SSLVERSION
Curl_poll(%d ds, %d ms)
Pipe broke: handle %p, url = %s
In state %d with no easy_conn, bail out!
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
Operation timed out after %ld milliseconds with %I64d bytes received
Internal error clearing splay node = %d
Internal error removing splay node = %d
ignoring failed cookie_init for %s
23[^;
=] =I99[^;
httponly
skipped cookie with bad tailmatch domain: %s
#HttpOnly_
%s cookie %s="%s" for domain %s, path %s, expire %I64d
%s%s%s
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# Fatal libcurl error
WARNING: failed to save cookies in %s
security.dll
secur32.dll
Could not resolve %s: %s
init_resolve_thread() failed for %s; %s
getaddrinfo() failed for %s:%d; %s
%s:%d
Hostname %s was found in DNS cache
%5[^:]:%d
Couldn't parse CURLOPT_RESOLVE removal entry '%s'!
%5[^:]:%d:%5s
Couldn't parse CURLOPT_RESOLVE entry '%s'!
Address in '%s' found illegal!
Added %s:%d:%s to DNS cache
rcmd
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Found bundle for host %s: %p
Server doesn't support multi-use yet, wait
Server doesn't support multi-use (yet)
Pipe is full, skip (%zu)
Multiplexed connection found!
Connected to %s (%s) port %ld (#%ld)
Failed to convert %s to ACE;
Protocol "%s" not supported or disabled in libcurl
Illegal characters found in URL
[^:]:%[^
:]://%[^
<url> malformed
SMTP.
Rebuilt URL to: %s
Please URL encode %% as %%, see RFC 6874.
http_proxy
No valid port number in proxy string (%s)
[%*45[0123456789abcdefABCDEF:.]%c
IPv6 numerical address used in URL without brackets
;type=%c
%s://%s%s%s:%hu%s%s%s
Port number out of range
Couldn't find host %s in the _netrc file; using defaults
PTF@example.com
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
%s://%s
Found connection %ld, with requests in the pipe (%zu)
Re-using existing connection! (#%ld) with %s %s
No more connections allowed to host: %d
User-Agent: %s
Connection #%ld to host %s left intact
Send failure: %s
Recv failure: %s
Write callback asked for PAUSE when not supported!
[%s %s %s]
Failed to set SO_KEEPALIVE on fd %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Couldn't bind to interface '%s'
Local Interface %s is ip %s using address family %i
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
Local port: %hu
Bind to local port %hu failed, trying next
bind failed with errno %d: %s
getpeername() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
connect to %s port %ld failed: %s
Failed to connect to %s port %ld: %s
Could not set TCP_NODELAY: %s
TCP_NODELAY set
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
Immediate connect fail for %s: %s
schannel: SSL/TLS connection with %s port %hu (step 1/3)
schannel: disabled server certificate revocation checks
schannel: checking server certificate revocation
schannel: verifyhost setting prevents Schannel from comparing the supplied target name with the subject names in server certificates. Also disables SNI.
schannel: SNI or certificate check failed: %s
schannel: AcquireCredentialsHandle failed: %s
schannel: using IP address, SNI is not supported by OS.
schannel: initial InitializeSecurityContext failed: %s
schannel: SSL/TLS connection with %s port %hu (step 2/3)
schannel: a client certificate has been requested
schannel: next InitializeSecurityContext failed: %s
schannel: SSL/TLS connection with %s port %hu (step 3/3)
schannel: incremented credential handle refcount = %d
select/poll on SSL/TLS socket, errno: %d
select/poll on SSL socket, errno: %d
schannel: Curl_read_plain returned CURLE_AGAIN
schannel: Curl_read_plain returned CURLE_RECV_ERROR
schannel: Curl_read_plain returned error %d
schannel: failed to read data from server: %s
schannel: shutting down SSL/TLS connection with %s port %hu
schannel: ApplyControlToken failure: %s
schannel: failed to send close msg: %s (bytes written: %zd)
schannel: decremented credential handle refcount = %d
--:--:--
%3I64d %s %3I64d %s %3I64d %s %s %s %s %s %s %s
operation aborted by callback
Read callback asked for PAUSE when not supported!
seek callback returned error %d
the ioctl callback returned %d
ioctl callback returned error %d
Rewinding stream by : %zd bytes on url %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
HTTP server doesn't seem to support byte ranges. Cannot resume.
Simulate a HTTP 304 response!
%s in chunked-encoding
Rewinding stream by : %zu bytes on url %s (size = %I64d, maxdownload = %I64d, bytecount = %I64d, nread = %zd)
Excess found in a non pipelined read: excess = %zu, size = %I64d, maxdownload = %I64d, bytecount = %I64d
No URL set!
%%x
[^?&/:]://%c
Issue another request to this URL: '%s'
Disables POST, goes with %s
HTTPS
%s:%s
%sAuthorization: Basic %s
The requested URL returned error: %d
%s auth using %s with user '%s'
%s, d %s M d:d:d GMT
If-Modified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Referer: %s
Accept-Encoding: %s
Chunky upload is not supported by HTTP 1.0
Host: %s%s%s
Host: %s%s%s:%hu
PTF://
Range: bytes=%s
Content-Range: bytes %s%I64d/%I64d
Content-Range: bytes %s/%I64d
PTF://%s:%s@%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s=%s
Internal HTTP POST error!
Content-Type: application/x-www-form-urlencoded
Failed sending HTTP POST request
Failed sending HTTP request
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %s
Connection closure while negotiating auth (HTTP 1.0?)
HTTP error before end of send, stop sending
HTTP/%d.%d %d
Lying server, not serving HTTP/2
HTTP =
RTSP/%d.%d =
HTTP 1.0, assume close after body
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 connection set to keep alive!
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Conn: %ld (%p) Receive pipe weight: (%I64d/%zu), penalized: %s
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
d:d:d
d:d
0123456789
Unsupported protocol
URL using bad/illegal format or missing URL
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
FTP: weird server reply
FTP: The server failed to connect to data port
FTP: Accepting server connect has timed out
FTP: The server did not accept the PRET command.
FTP: unknown PASS reply
FTP: unknown PASV reply
FTP: unknown 227 response format
FTP: can't figure out the host in the PASV response
Error in the HTTP2 framing layer
FTP: couldn't set file type
FTP: couldn't retrieve (RETR failed) the specified file
HTTP response code said error
FTP: command PORT failed
FTP: command REST failed
Operation was aborted by an application callback
A libcurl function was given a bad argument
An unknown option was passed in to libcurl
SSL peer certificate or SSH remote key was not OK
Problem with the local SSL certificate
Peer certificate cannot be authenticated with given CA certificates
Problem with the SSL CA cert (path? access rights?)
Unrecognized or bad HTTP Content or Transfer-Encoding
Invalid LDAP URL
Issuer check against peer certificate failed
Login denied
TFTP: File Not Found
TFTP: Access Violation
TFTP: Illegal operation
TFTP: Unknown transfer ID
TFTP: No such user
Caller must register CURLOPT_CONV_ callback options
Error in the SSH layer
Unable to parse FTP file list
SSL public key does not match pinned public key
SSL server certificate status verification FAILED
Protocol option is unsupported
Protocol is unsupported
Socket is unsupported
Operation not supported
Address family not supported
Protocol family not supported
Winsock version not supported
Unknown error %d (%#x)
SEC_E_CERT_EXPIRED
SEC_E_CERT_UNKNOWN
SEC_E_CERT_WRONG_USAGE
SEC_E_KDC_CERT_EXPIRED
SEC_E_KDC_CERT_REVOKED
SEC_E_NO_KERB_KEY
SEC_E_NO_S4U_PROT_SUPPORT
SEC_E_QOP_NOT_SUPPORTED
SEC_E_SMARTCARD_CERT_EXPIRED
SEC_E_SMARTCARD_CERT_REVOKED
SEC_E_STRONG_CRYPTO_NOT_SUPPORTED
SEC_E_UNSUPPORTED_FUNCTION
SEC_E_UNSUPPORTED_PREAUTH
SEC_E_ILLEGAL_MESSAGE (0xXX) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.
%s (0xXX)
%s - %s
%d.%d.%d.%d
LOGIN %s %s
AUTHENTICATE %s %s
AUTHENTICATE %s
No known authentication mechanisms supported!
LIST "%s" *
SELECT %s
FETCH %s BODY[%s]<%s>
FETCH %s BODY[%s]
APPEND %s (\Seen) {%I64d}
SEARCH %s
LOGINDISABLED
STARTTLS not supported.
STARTTLS denied. %c
Access denied. %c
%cd
%s %s
USER %s
APOP %s %s
AUTH %s %s
AUTH %s
STLS not supported.
Authentication failed: %d
PASS %s
CLIENT libcurl 7.46.0
MATCH %s %s %s
DEFINE %s %s
WSAStartup failed (%d)
insufficient winsock version to support telnet
%s IAC %s
%s IAC %d
%s %s %s
%s %s %d
%s %d %d
Sending data failed (%d)
%s IAC SB
%s (unsupported)
%d (unknown)
USER,%s
7[^= ]%*[ =]%5s
Syntax error in telnet option: %s
Unknown telnet option %s
%c%c%c%c%s%c%c
7[^,],7s
%c%s%c%s
WS2_32.DLL
failed to load WS2_32.DLL (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEnumNetworkEvents function (%d)
WSACreateEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACloseEvent failed (%d)
FreeLibrary(wsock2) failed (%d)
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
got option=(%s) value=(%s)
blksize is larger than max supported
%s (%d)
blksize is smaller than min supported
%s (%ld)
%s (%d) %s (%d)
invalid tsize -:%s:- value in OACK packet
%s%c%s%c
tftp_send_first: internal error
Received last DATA packet block %d again.
Received unexpected DATA packet block %d, expecting block %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
Received ACK for block %d, expecting %d
tftp_tx: giving up waiting for block %d ack
tftp_tx: internal error, event: %i
TFTP finished
bind() failed; %s
TFTP response timeout
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
LDAP local: %s
LDAP local: trying to establish %s connection
LDAP local: Cannot connect to %s:%ld
LDAP local: ldap_simple_bind_s %s
LDAP remote: %s
There are more than %d entries
SMTP
SMTPS
EHLO %s
HELO %s
MAIL FROM:%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s SIZE=%s
RCPT TO:%s
RCPT TO:<%s>
Got unexpected smtp-server response: %d
Remote access denied: %d
Command failed: %d
MAIL failed: %d
RCPT failed: %d
DATA failed: %d
PORT
FTPS
Preparing for accepting server on data port
FTP response timeout
FTP response aborted due to select/poll error: %d
CWD %s
getsockname() failed: %s
failed to resolve the address provided to PORT: %s
socket failure: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) failed: %s
bind() failed, we ran out of ports!
%s |%d|%s|%hu|
Failure sending EPRT command: %s
,%d,%d
Failure sending PORT command: %s
Connect data stream passively
PRET %s
PRET STOR %s
PRET RETR %s
REST %d
SIZE %s
MDTM %s
APPE %s
STOR %s
RETR %s
%c%c%c%u%c
Illegal port number in EPSV reply
%d,%d,%d,%d,%d,%d
Skip %d.%d.%d.%d for data connection, re-use %s instead
Bad PASV/EPSV response: d
Can't resolve proxy host %s:%hu
Can't resolve new host %s:%hu
Failed to do PORT
dddddd
ddd d:d:d GMT
Last-Modified: %s, d %s M d:d:d GMT
unsupported MDTM reply format
Got a d response code instead of the assumed 200
ftp server doesn't support SIZE
Failed FTP upload: 
RETR response: d
PBSZ %d
ACCT %s
Access denied: d
ACCT rejected by server: d
Got a d ftp-server response when 220 was expected
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
PROT %c
Entry path is '%s'
QUOT command failed with d
MKD %s
Failed to MKD dir: d
PRET command not accepted: d
Remembering we are in dir "%s"
Failure sending ABOR command: %s
server did not report OK, got %d
QUOT string not accepted: %s
TYPE %c
Connecting to %s (%s) port %d
ftp_perform ends with SECONDARY: %d
Wildcard - START of "%s"
Wildcard - "%s" skipped by user
Failure sending QUIT command: %s
Uploading to a URL without a file name!
Couldn't open file %s
Can't open %s for writing
Can't get the size of %s
Refusing to issue an RTSP request [%s] without a session ID.
Transport:
Transport: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Range: %s
%s %s RTSP/1.0
Session: %s
%s%s%s%s%s%s%s%s
Unable to read the CSeq header: [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
curl
login
password
%sAuthorization: Digest %s
%sAuthorization: NTLM %s
SOCKS4 communication to %s:%d
SOCKS4 connect to %s (locally resolved)
Failed to resolve "%s" for SOCKS4 connect.
SOCKS4%s request granted.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
User was rejected by the SOCKS5 server (%d %d).
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
Failed to resolve "%s" for SOCKS5 connect.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Establish HTTP proxy tunnel to %s:%hu
%s:%hu
%s%s%s:%hu
Host: %s
CONNECT %s HTTP/%s
%s%s%s%s
HTTP/1.%d %d
TUNNEL_STATE switched to: %d
Received HTTP code %d from proxy after CONNECT
.jpeg
.html
; filename="%s"
%s; boundary=%s
Content-Type: multipart/mixed; boundary=%s
Content-Type: %s
couldn't open file "%s"
--%s--
------------------------xx
%sAuthorization: Negotiate %s
LOGIN
%s xxxxxxxxxxxxxxxx
user=%s
auth=Bearer %s
host=%s
port=%ld
Unsupported SASL authentication mechanism
0123456789-
KGS!@#$%%s/%s
NTLM handshake failure (type-3 message): Status=%x
SSPI error: %s failed: %s
User was rejected by the SOCKS5 server (%u %u).
Invalid SSPI authentication response type (%u %u).
SOCKS5 server authencticated user %s with GSS-API.
SOCKS5 server supports GSS-API %s data protection.
Invalid SSPI encryption response type (%u %u).
SOCKS5 access with%s protection granted.
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
{"method": "submit", "params": {"id": "%s", "job_id": "%s", "nonce": "%s", "result": "%s"},"id":4}
thread %d create failed
%d miner threads started, using '%s' algorithm.
{"method": "getwork", "params": ["%s"], "id":4}
{"method": "getblocktemplate", "params": [{"capabilities": ["coinbasetxn", "coinbasevalue", "longpoll", "workid"], "longpollid": "%s"}], "id":0}
{"method": "getjob", "params": {"id": "%s"}, "id":1}
json_rpc_call failed, retry after %d seconds
...terminating workio thread
...retry after %d seconds
{"method": "login", "params": {"login": "%s", "pass": "%s", "agent": "%s"}, "id": 1}
DEBUG: authenticated in %d ms
CURL initialization failed
DEBUG: job_id='%s' extranonce2=%s ntime=x
network hashrate too high, waiting %s...
Binding thread %d to cpu %d (mask %x)
Binding thread %d to cpu mask %x
work retrieval failed, exiting mining thread %d
Benchmark: %s
Mining timeout of %ds reached, exiting...
CPU #%d: %.2f H/s
CPU #%d: %s kH/s
Total: %s H/s
Total: %s kH/s
CURL init failed
Long-polling on %s
cert
%s detected new block%s
userpass
JSON decode failed(%d): %s
Starting Stratum on %s
Connection changed to %s
%s block %d, diff %.3f
%s %s block %d
net diff: %f -> shift %u, bits x
%s asks job %d for block %d
jansson/%s
pthreads/%d.%d.%d.%d
POK received: xx
getmininginfo not supported
%s block %d, %s
Unknown algo parameter '%s'
incorrect Nfactor %d
Current block is %d
%s:%d: %s
Switching to getwork, gbt version %d
Unrecognized block version: %u
hXXp://
hXXps://
stratum tcp://
unknown protocol -- '%s'
invalid URL -- '%s'
hXXp://%s
invalid username:password pair -- '%s'
invalid address -- '%s'
JSON option %s invalid
%s: unsupported non-option argument -- '%s'
accepted: %lu/%lu (%.2f%%), %s kH/s %s
reject reason: %s
127.0.0.1
block %u was already solved
Using config %s
CPU Supports AES-NI: %s
%s: no URL supplied
https:
{"method": "submit", "params": {"id": "%s", "job_id": "%s", "nonce": "%s", "result": "%s"}, "id":4}
{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}
{"method": "submitblock", "params": ["%s%s", %s], "id":4}
{"method": "submitblock", "params": ["%s%s"], "id":4}
Binding process to cpu mask %x
DEBUG: %s
Hash: %s
Target: %s
http%s
Stratum connection failed: %s
mining.notify
Stratum set nonce %s with extranonce2 size=%d
{"id": 1, "method": "mining.subscribe", "params": []}
{"id": 1, "method": "mining.subscribe", "params": ["cpuminer-multi/1.2-dev", "%s"]}
{"id": 1, "method": "mining.subscribe", "params": ["cpuminer-multi/1.2-dev"]}
JSON-RPC call failed: %s
Stratum session id: %s
{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}
{"id": 3, "method": "mining.extranonce.subscribe", "params": []}
extranonce subscribe not supported
Auth id: %s
JSON returned status "%s"
rpc2_login_decode
%s: fail
json_rpc2.0 error: %s
[%d-d-d d:d:d]%s %s%s
%s\cpuminer\cpuminer-conf.json
%s%scpuminer-conf.json
%.2f %cH/s
%.2f H/s%c
stratum tcp://%s:%d
Ignoring request to reconnect to %s
Server requested reconnection to %s
MESSAGE FROM SERVER: %s
mining.set_difficulty
mining.set_extranonce
client.reconnect
client.get_version
client.show_message
HTTP request failed: %s
xxxx
%ss%s: %s
Remote config read failed: %s
hex2bin failed on '%s'
JSON key '%s' not found
JSON key '%s' is not a string
zcÁ
694983729836531
C:\Windows\System32\wuapp.exe
GetCPInfo
GetProcessHeap
PeekNamedPipe
CryptDestroyKey
CryptImportKey
,%.%"8#"
8448408
.text
`.rdata
@.data
.reloc
#y.Bv
KERNEL32.DLL
ADVAPI32.dll
Normaliz.dll
USER32.dll
WLDAP32.dll
WS2_32.dll
.mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
2.exe
ERROR %d converting to Punycode
combase.dll

conhost.exe_3980:

.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641

SearchFilterHost.exe_3776:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
IMM32.dll
MSSHooks.dll
mscoree.dll
SHLWAPI.dll
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrhost\bufstm.cxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
SearchFilterHost.pdb
version="5.1.0.0"
name="Microsoft.Windows.Search.MSSFH"
<requestedExecutionLevel
3 3(30383|3
kernel32.dll
Software\Microsoft\Windows Search
SOFTWARE\Microsoft\Windows Search
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
tquery.dll
advapi32.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<ERR> 0xx=
<LOC> %S(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%S"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%S"
</MSG></TRC>
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
winhttp.dll
Microsoft Windows Search Filter Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchFilterHost.exe
Windows
7.00.7601.17610


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    MIICRU~1.EXE:3856
    ecVV.exe:3604
    %original file name%.exe:3888

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ecVV.exe (10129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\HSbBN (10564 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\ecVV.exe (1874 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut9453.tmp (5505 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut951E.tmp (9365 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\HSbBN (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UHiQVTPeKYCJ.lnk (838 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\MIICRU~1.EXE (38125 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\STLcyHegih\SS2Svc64.exe (44 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "dCncPGxdPI" = "C:\Users\"%CurrentUserName%"\AppData\Local\STLCYH~1\SS2Svc64.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now