Worm.Win32.AutoItGen_6a90ec5f35

HEUR:Trojan.MSIL.Generic (Kaspersky), Worm.Win32.AutoIt.FD, WormAutoItGen.YR (Lavasoft MAS) Behaviour: Trojan, Worm The description has been automatically generated by Lavasoft Malware Analysis Syste...
Blog rating:2 out of5 with1 ratings

Worm.Win32.AutoItGen_6a90ec5f35

by malwarelabrobot on November 12th, 2017 in Malware Descriptions.

HEUR:Trojan.MSIL.Generic (Kaspersky), Worm.Win32.AutoIt.FD, WormAutoItGen.YR (Lavasoft MAS)
Behaviour: Trojan, Worm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 6a90ec5f357f5622abb10d1e8e98ee71
SHA1: 96802798627b958cd1eb8968ad69f2e12d0cd85d
SHA256: 8e5db9673f39d9750142ecaf403c3bc11f7844f249dcb7ffa0cfa2e3c3d183dd
SSDeep: 24576:0eanGeP7crbvRfsRDIx0LqK8R/luZOGd6AM/7In:hanGA7abls1I2rMluZOG0xI
Size: 923304 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2017-10-23 19:12:02
Analyzed on: Windows7 SP1 32-bit


Summary:

Worm. A program that is primarily replicating on networks or removable drives.

Payload

No specific payload has been found.

Process activity

The Worm creates the following process(es):

%original file name%.exe:4008
netsh.exe:2096
rundll32.exe:3828
systeminfo.exe:3032

The Worm injects its code into the following process(es):

%original file name%.exe:2448

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:4008 makes changes in the file system.
The Worm creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\svhost.exe (11518 bytes)

The process %original file name%.exe:2448 makes changes in the file system.
The Worm creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5DD9.tmp (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\log\Passwords.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\log\AutoUpdate.exe (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tqyakoq (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5F9F.tmp (3465 bytes)

The Worm deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5DD9.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tqyakoq (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5F9F.tmp (0 bytes)

The process rundll32.exe:3828 makes changes in the file system.
The Worm creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A49RRPIQ\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AVOOSAB0\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UN62KCDO\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QS0ZUQ50\desktop.ini (67 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini (67 bytes)

Registry activity

The process %original file name%.exe:2448 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASMANCS]
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"TaskbarNoNotification" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASMANCS]
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASAPI32]
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASMANCS]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"ConsentPromptBehaviorAdmin" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\6a90ec5f357f5622abb10d1e8e98ee71_RASMANCS]
"FileDirectory" = "%windir%\tracing"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoUpdate" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\log\AutoUpdate.exe"

The Worm deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process netsh.exe:2096 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E\@%SystemRoot%\system32]
"eapqec.dll,-102" = "1.0"
"eapqec.dll,-103" = "Microsoft Corporation"
"eapqec.dll,-100" = "EAP Quarantine Enforcement Client"
"eapqec.dll,-101" = "Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies."
"dhcpqec.dll,-102" = "Microsoft Corporation"
"dhcpqec.dll,-103" = "1.0"
"dhcpqec.dll,-100" = "DHCP Quarantine Enforcement Client"
"dhcpqec.dll,-101" = "Provides DHCP based enforcement for NAP"
"tsgqec.dll,-102" = "1.0"
"tsgqec.dll,-103" = "Microsoft Corporation"
"tsgqec.dll,-100" = "RD Gateway Quarantine Enforcement Client"
"tsgqec.dll,-101" = "Provides RD Gateway enforcement for NAP"
"napipsec.dll,-1" = "IPsec Relying Party"
"napipsec.dll,-3" = "Microsoft Corporation"
"napipsec.dll,-2" = "Provides IPsec based enforcement for Network Access Protection"
"napipsec.dll,-4" = "1.0"

[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"

The process systeminfo.exe:3032 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:

[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E\@%SystemRoot%\system32]
"mlang.dll,-4386" = "English (United States)"

[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"

Dropped PE files

MD5 File path
32827e69b293b99013bbbe37d029245d c:\Users\"%CurrentUserName%"\AppData\Local\Temp\svhost.exe
a970c7acb1ba960122445d88ea010c67 c:\Users\"%CurrentUserName%"\AppData\Roaming\log\AutoUpdate.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 8192 911257 911360 5.51328 ffb30495cda46b67016d1abc86e4b68e
.rsrc 925696 3394 3584 3.77403 213c4f2929eadfd63f8792bcf9d00009
.reloc 933888 12 512 0.056519 531bcd81ad14eef9ab44f43a2408956a

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 1
69a1113ca1bc1dfba417f6014829ff36

URLs

URL IP
dns.msftncsi.com
time.windows.com
virtualsmsonline.site
icanhazip.com


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

The Worm connects to the servers at the folowing location(s):

%original file name%.exe_2448:

`.rsrc
SSh8*K
.hP6K
PSSSSSSh
Gt.Ht$
t.jGZf;
PSSShl
PVSShl
j.Zf;
;K|s%f
.ku`8iu~fiu
?#%X.y
GetProcessWindowStation
operator
kernel32.dll
oleaut32.dll
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
zcÁ
GetProcessHeap
CreatePipe
GetWindowsDirectoryW
GetCPInfo
RegDeleteKeyW
RegEnumKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
SetViewportOrgEx
ShellExecuteExW
SHFileOperationW
ShellExecuteW
RegisterHotKey
GetKeyboardLayoutNameW
ExitWindowsEx
EnumThreadWindows
UnregisterHotKey
keybd_event
GetAsyncKeyState
SetKeyboardState
GetKeyboardState
GetKeyState
VkKeyScanW
EnumWindows
EnumChildWindows
MapVirtualKeyW
CloseWindowStation
SetProcessWindowStation
OpenWindowStationW
InternetCrackUrlW
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
##@,&,//,))
.jQG2
3(-,'')-*/%' 
9(***3).**-)'
H%d=j@
0!;....(
.text
`.rdata
@.data
.rsrc
@.reloc
.textO
n..GGHHH
n...GGHHH
n ....HGHHHH
n  ....G.HHH
~~~~{~{{{{
n!! ....HGHHHH
n!!  .....HHHHHH
!!!  ....GGHHH
!!"".....HHHHnv
"""...-.nv
=%Sc\RJ
jmN.UB
p6.Ih
F.zL=cK\x!_c
kÈn4O
6Ü0#v
U J.Zk
rw.dM
.OVu&`
i.vbG
F.TYG
MÓC
4d.JF 
KEY6_
CP%FI)
5.hBp
%a$|%F
km.KH*L
&.lJ-X
.NTiK
/x%d,
.Mn@9v
1.jT^
(.nvYV
%D'lU
e6#pd.MC,
5KEyT|jv
t-.eN
q4&.ga
0.Yl%x
guRL
}I%Dz
q.RnV
?T .Yv
Y-,.Ab
QkSqlnwBc?P
[@M'
<1k%u
#Cf%X
^N[%u
#OÖ
e.nI%Tg
lk;
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"/>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IPHLPAPI.DLL
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
UxTheme.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
mscoree.dll
combase.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
USER32.DLL
>>>AUTOIT NO CMDEXECUTE<<<
CMDLINERAW
CMDLINE
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
APPSKEY
789:;<=>?
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLSENDMSG
GUIGETMSG
GUIREGISTERMSG
HOTKEYSET
HTTPSETPROXY
HTTPSETUSERAGENT
ISKEYWORD
MSGBOX
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTEWAIT
TCPACCEPT
TCPCLOSESOCKET
TCPCONNECT
TCPLISTEN
TCPNAMETOIP
TCPRECV
TCPSEND
TCPSHUTDOWN
TCPSTARTUP
TRAYGETMSG
UDPBIND
UDPCLOSESOCKET
UDPOPEN
UDPRECV
UDPSEND
UDPSHUTDOWN
UDPSTARTUP
SendKeyDelay
SendKeyDownDelay
TCPTimeout
WINDOWSDIR
AUTOITEXE
HOTKEYPRESSED
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
04090000
%u.%u.%u.%u
0.0.0.0
Mddddd
"%s" (%d) : ==> %s:
\??\%s
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
255.255.255.255
Keyword
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 12, 0
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_USERS
%d/d/d
c:\%original file name%.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
1.2.0.1

%original file name%.exe_2448_rwx_00400000_001C3000:

`.rsrc
SSh8*K
.hP6K
PSSSSSSh
Gt.Ht$
t.jGZf;
PSSShl
PVSShl
j.Zf;
;K|s%f
.ku`8iu~fiu
?#%X.y
GetProcessWindowStation
operator
kernel32.dll
oleaut32.dll
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
zcÁ
GetProcessHeap
CreatePipe
GetWindowsDirectoryW
GetCPInfo
RegDeleteKeyW
RegEnumKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
SetViewportOrgEx
ShellExecuteExW
SHFileOperationW
ShellExecuteW
RegisterHotKey
GetKeyboardLayoutNameW
ExitWindowsEx
EnumThreadWindows
UnregisterHotKey
keybd_event
GetAsyncKeyState
SetKeyboardState
GetKeyboardState
GetKeyState
VkKeyScanW
EnumWindows
EnumChildWindows
MapVirtualKeyW
CloseWindowStation
SetProcessWindowStation
OpenWindowStationW
InternetCrackUrlW
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
##@,&,//,))
.jQG2
3(-,'')-*/%' 
9(***3).**-)'
H%d=j@
0!;....(
.text
`.rdata
@.data
.rsrc
@.reloc
.textO
n..GGHHH
n...GGHHH
n ....HGHHHH
n  ....G.HHH
~~~~{~{{{{
n!! ....HGHHHH
n!!  .....HHHHHH
!!!  ....GGHHH
!!"".....HHHHnv
"""...-.nv
=%Sc\RJ
jmN.UB
p6.Ih
F.zL=cK\x!_c
kÈn4O
6Ü0#v
U J.Zk
rw.dM
.OVu&`
i.vbG
F.TYG
MÓC
4d.JF 
KEY6_
CP%FI)
5.hBp
%a$|%F
km.KH*L
&.lJ-X
.NTiK
/x%d,
.Mn@9v
1.jT^
(.nvYV
%D'lU
e6#pd.MC,
5KEyT|jv
t-.eN
q4&.ga
0.Yl%x
guRL
}I%Dz
q.RnV
?T .Yv
Y-,.Ab
QkSqlnwBc?P
[@M'
<1k%u
#Cf%X
^N[%u
#OÖ
e.nI%Tg
lk;
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"/>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IPHLPAPI.DLL
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
UxTheme.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
mscoree.dll
combase.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
USER32.DLL
>>>AUTOIT NO CMDEXECUTE<<<
CMDLINERAW
CMDLINE
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
APPSKEY
789:;<=>?
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLSENDMSG
GUIGETMSG
GUIREGISTERMSG
HOTKEYSET
HTTPSETPROXY
HTTPSETUSERAGENT
ISKEYWORD
MSGBOX
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTEWAIT
TCPACCEPT
TCPCLOSESOCKET
TCPCONNECT
TCPLISTEN
TCPNAMETOIP
TCPRECV
TCPSEND
TCPSHUTDOWN
TCPSTARTUP
TRAYGETMSG
UDPBIND
UDPCLOSESOCKET
UDPOPEN
UDPRECV
UDPSEND
UDPSHUTDOWN
UDPSTARTUP
SendKeyDelay
SendKeyDownDelay
TCPTimeout
WINDOWSDIR
AUTOITEXE
HOTKEYPRESSED
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
04090000
%u.%u.%u.%u
0.0.0.0
Mddddd
"%s" (%d) : ==> %s:
\??\%s
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
255.255.255.255
Keyword
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 12, 0
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_USERS
%d/d/d
c:\%original file name%.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
1.2.0.1

conhost.exe_3344:

.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641

TrustedInstaller.exe_3228:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
msvcrt.dll
ole32.dll
j.Yf;
Failed to execute shutdown processing.
FFailed a critical portion of startup processing.
Failed to initialize delayed portion.
TrustedInstaller terminated unexpectedly with pending operations the last time around; will skip core startup processing.
Failed to execute service.
Starting the Trusted Installer in standalone mode based on command-line switch: %S
Failed to expand path to servicing stack directory: %S
Failed to open servicing stack version registry key.
TI found cbscore.dll at: %S
Failed to initialize the DLL: %S
Failed to locate 'SfpInitialize' method in DLL: %S
Failed to load sfp DLL from path: %S
Failed to supply callback for revoking shutdown processing; assuming it is not supported.
Failed to initialize the Core DLL: %S
Warning: Failed to locate 'CbsCoreFinalizeShutdownProcessing' method in Core DLL: %S
Warning: Failed to locate 'CbsCorePrepareShutdownProcessing' method in Core DLL: %S
Warning: Failed to locate 'CbsCoreIsExecutionEngineIdle' method in Core DLL: %S
CbsCoreIsExecutionEngineIdle
Warning: Failed to locate 'CbsCoreUnregisterWinlogonNotification' method in Core DLL: %S
Warning: Failed to locate 'CbsCoreSetState' method in Core DLL: %S
Warning: Failed to locate 'CbsCoreServiceIdleProcessing' method in Core DLL: %S
Failed to locate 'CbsCoreFinalize' method in Core DLL: %S
Failed to locate 'CbsCoreShutdownProcessing' method in Core DLL: %S
Failed to locate 'CbsCoreEnsureNoStartupProcessing' method in Core DLL: %S
Failed to locate 'CbsCoreStartupProcessing' method in Core DLL: %S
Failed to locate 'CbsCoreInitializeDelayedPortion' method in Core DLL: %S
CbsCoreInitializeDelayedPortion
Failed to locate 'CbsCoreInitialize' method in Core DLL: %S
Failed to load Core DLL from path: %S
Failed to initialize sxsstore.dll
Failed to load SxsStore.dll
Failed to append dll name: %S to path: %S.
Failed to backslash-terminate system directory: %S.
May have successfully finished startup processing but another reboot and executing startup processing again is required to be sure.
Ignoring failure to set reboot callback; assuming reboot indication is not supported.
Failed to allocate string to format: %S
failed to allocate string to format: %S
Failed to get length of passed in string
Failed to get full path for string: %S
Failed to expand environment variables in string: %S
Failed to allocate string to enum registry value: %S
Registry value for %S is not a dword type.
%s [HRESULT = 0xx - %s]
Failed to open the registry root: n/a, key: %S.
Failed to query registry value: %S
Failed during startup processing, continuing with Trusted Installer execution
Warning: Failed to execute service idle processing. Error code: 0X%x
SSSh \
Startup: Failed to wait on startup thread. Wait result: 0x%x
Failed to wait on startup thread. Wait result: 0x%x
Failed to wait on idle processing thread. Wait result: 0x%x
Warning: Failed while executing service idle processing.
Failed while executing shutdown processing.
Failed to open RebootPending key.
Reboot mark refs incremented to: %u
RebootPending key exists unexpectedly.
Failed to create RebootPending key.
Reboot mark refs: %u
Failed to delete RebootPending key.
Failed to open TrustedInstaller service to change config, hopefully the auto-start registry key is already set.
Failed to change the Trusted Installer to an auto start service, hopefully the auto-start registry key is already set.
Failed to locate setup log directory while executing during setup. Probably not really running under setup.
d:\w7rtm\base\cbs\util\cbsutil.cpp
Failed to allocate delete search string for backup logs directory path: %S
Failed to wait on makecab.exe process.
Failed to delete backup log after archiving: %S.
Failed to transfer cab timestamp: %S.
Failed to open handle for cab timestamp transfer: %S.
Archived backup log: %S.
Failed to allocate full path to makecab.exe.
Failed to ensure makecab.exe path ended with a backslash: %S.
Failed to allocate makecab.exe path from windows directory: %S.
Failed to get windows directory for makecab.exe path.
Failed to get proc address for ConstructPartialMsgVA.
ConstructPartialMsgVA
Could not allocate a backup name for the log file: %S, we'll just continue with our current log file.
Failed to initialize logging with dll: %S, log directory: %S
Failed to move log: %S to backup log: %S, continuing anyway.
Failed to add log name log directory: %S
Failed to store log path argument: %S
Failed to ensure that logging directory exists: %S
Failed to add 'servicing' name on to log directory: %S
Failed to ensure log directory ended with a backslash: %S
Failed to allocate log directory from windows directory: %S
Failed to get windows directory for log file.
Failed to initialize logging with DLL: %S, log file: %S
Failed to allocate log file name: %S
Failed to get proc address for WdsGenericSetupLogInit.
WdsGenericSetupLogInit
Failed to get proc address for WdsSetupLogInit.
WdsSetupLogInit
Failed to load WDSCORE DLL: %S
Could not load WDSCORE DLL from path: %S. Continuing without text file logging.
Failed to ensure Wds path ended with a backslash: %S
Failed to allocate Wds path from windows directory: %S
Failed to get windows directory for WDSCORE DLL path.
Failed to get attributes for file: %S
Failed to create path: %S
Failed to copy parent of path: %S
Cannot find parent for path: %S.
Failed to allocate string to read registry value: %S
Failed to query value to get type and size of registry root: n/a, value: %S
Failed initial query of value to get type, size, and value of registry value: %S
Failed to look up privilege name: %S
CERT_E_INVALID_NAME
CERT_E_INVALID_POLICY
CERT_E_UNTRUSTEDCA
CERT_E_WRONG_USAGE
CERT_E_CN_NO_MATCH
CERT_E_REVOCATION_FAILURE
CERT_E_UNTRUSTEDTESTROOT
CERT_E_REVOKED
CERT_E_CHAINING
CERT_E_UNTRUSTEDROOT
CERT_E_PATHLENCONST
CERT_E_CRITICAL
CERT_E_PURPOSE
CERT_E_ISSUERCHAINING
CERT_E_MALFORMED
CERT_E_ROLE
CERT_E_EXPIRED
CERT_E_VALIDITYPERIODNESTING
CRYPT_E_MISSING_PUBKEY_PARA
CRYPT_E_BAD_MSG
CRYPT_E_NO_DECRYPT_CERT
CRYPT_E_NO_KEY_PROPERTY
CRYPT_E_UNEXPECTED_MSG_TYPE
CRYPT_E_STREAM_MSG_NOT_READY
CRYPT_E_INVALID_MSG_TYPE
CRYPT_E_MSG_ERROR
CBS_E_SQM_REPORT_IGNORED_AI_FAILURES_ON_TRANSACTION_RESOLVE
CBS_E_INVALID_DRIVER_OPERATION_KEY
SPAPI_E_REMOTE_REQUEST_UNSUPPORTED
SPAPI_E_NON_WINDOWS_DRIVER
SPAPI_E_NON_WINDOWS_NT_DRIVER
SPAPI_E_KEY_DOES_NOT_EXIST
!"#$%&'()* ,-./0
ERROR_MCA_UNSUPPORTED_COLOR_TEMPERATURE
ERROR_MCA_UNSUPPORTED_MCCS_VERSION
ERROR_EVT_INVALID_OPERATION_OVER_ENABLED_DIRECT_CHANNEL
ERROR_EVT_FILTER_UNSUPPORTEDOP
ERROR_SXS_INCORRECT_PUBLIC_KEY_TOKEN
ERROR_SXS_PROTECTION_PUBLIC_KEY_TOO_SHORT
ERROR_SXS_KEY_NOT_FOUND
ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH
ERROR_IPSEC_IKE_INVALID_CERT_KEYLEN
ERROR_IPSEC_IKE_UNSUPPORTED_ID
ERROR_IPSEC_IKE_ADD_UPDATE_KEY_FAILED
ERROR_IPSEC_IKE_NO_PEER_CERT
ERROR_IPSEC_IKE_PROCESS_ERR_CERT_REQ
ERROR_IPSEC_IKE_PROCESS_ERR_CERT
ERROR_IPSEC_IKE_NO_PUBLIC_KEY
ERROR_IPSEC_IKE_SIMULTANEOUS_REKEY
ERROR_IPSEC_IKE_NO_PRIVATE_KEY
ERROR_IPSEC_IKE_INVALID_CERT_TYPE
ERROR_IPSEC_IKE_INVALID_KEY_USAGE
ERROR_IPSEC_IKE_NO_CERT
ERROR_IPSEC_TRANSPORT_FILTER_PENDING_DELETION
ERROR_IPSEC_TRANSPORT_FILTER_NOT_FOUND
ERROR_IPSEC_TRANSPORT_FILTER_EXISTS
ERROR_NOT_SUPPORTED_ON_STANDARD_SERVER
ERROR_DS_NOT_SUPPORTED_SORT_ORDER
ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY
ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD
ERROR_DS_KEY_NOT_UNIQUE
ERROR_DS_ILLEGAL_XDOM_MOVE_OPERATION
ERROR_DS_PDC_OPERATION_IN_PROGRESS
ERROR_DS_DRA_NOT_SUPPORTED
ERROR_DS_UNKNOWN_OPERATION
ERROR_DS_ILLEGAL_MOD_OPERATION
ERROR_DS_NOT_SUPPORTED
ERROR_DS_AUTH_METHOD_NOT_SUPPORTED
ERROR_DS_OPERATIONS_ERROR
ERROR_OPERATION_NOT_SUPPORTED_IN_TRANSACTION
ERROR_CANNOT_EXECUTE_FILE_IN_TRANSACTION
ERROR_TRANSACTED_MAPPING_UNSUPPORTED_REMOTE
ERROR_TRANSACTIONS_UNSUPPORTED_REMOTE
ERROR_IMPLICIT_TRANSACTION_NOT_SUPPORTED
ERROR_TRANSACTION_NOT_JOINED
ERROR_LOG_MULTIPLEXED
ERROR_CS_ENCRYPTION_UNSUPPORTED_SERVER
ERROR_EFS_VERSION_NOT_SUPPORT
ERROR_VOLUME_NOT_SUPPORT_EFS
ERROR_NOT_EXPORT_FORMAT
ERROR_NO_USER_KEYS
ERROR_CLUSTER_RESTYPE_NOT_SUPPORTED
ERROR_CLUSTER_JOIN_ABORTED
ERROR_INVALID_OPERATION_ON_QUORUM
ERROR_CLUSTER_JOIN_NOT_IN_PROGRESS
ERROR_CLUSTER_JOIN_IN_PROGRESS
ERROR_IEPORT_FULL
ERROR_NO_SUPPORTING_DRIVES
ERROR_CONTROLLING_IEPORT
ERROR_TRANSPORT_FULL
ERROR_UNABLE_TO_INVENTORY_TRANSPORT
ERROR_INVALID_OPERATION
RPC_S_INTERFACE_NOT_EXPORTED
RPC_S_NOT_ALL_OBJS_EXPORTED
RPC_X_PIPE_EMPTY
RPC_X_PIPE_DISCIPLINE_ERROR
RPC_X_PIPE_CLOSED
RPC_X_WRONG_PIPE_VERSION
RPC_X_WRONG_PIPE_ORDER
RPC_X_INVALID_PIPE_OBJECT
RPC_S_UNSUPPORTED_AUTHN_LEVEL
RPC_S_CANNOT_SUPPORT
RPC_S_NOT_ALL_OBJS_UNEXPORTED
RPC_S_NOTHING_TO_EXPORT
RPC_S_UNSUPPORTED_NAME_SYNTAX
RPC_S_UNSUPPORTED_TYPE
RPC_S_UNSUPPORTED_TRANS_SYN
RPC_S_PROTSEQ_NOT_SUPPORTED
ERROR_CONNECTED_OTHER_PASSWORD_DEFAULT
ERROR_CONNECTED_OTHER_PASSWORD
ERROR_CLIPPING_NOT_SUPPORTED
ERROR_TRANSFORM_NOT_SUPPORTED
ERROR_METAFILE_NOT_SUPPORTED
ERROR_PASSWORD_MUST_CHANGE
ERROR_UNKNOWN_PORT
ERROR_PATCH_REMOVAL_UNSUPPORTED
ERROR_PATCH_PACKAGE_UNSUPPORTED
ERROR_INSTALL_PLATFORM_UNSUPPORTED
ERROR_UNSUPPORTED_TYPE
ERROR_INSTALL_LANGUAGE_UNSUPPORTED
ERROR_SYMLINK_NOT_SUPPORTED
ERROR_REQUIRES_INTERACTIVE_WINDOWSTATION
ERROR_INVALID_KEYBOARD_HANDLE
ERROR_INVALID_MSGBOX_STYLE
ERROR_HOTKEY_NOT_REGISTERED
ERROR_CLASS_HAS_WINDOWS
ERROR_HOTKEY_ALREADY_REGISTERED
ERROR_NO_USER_SESSION_KEY
ERROR_PASSWORD_EXPIRED
ERROR_PASSWORD_RESTRICTION
ERROR_ILL_FORMED_PASSWORD
ERROR_WRONG_PASSWORD
ERROR_NULL_LM_PASSWORD
ERROR_LOCAL_USER_SESSION_KEY
ERROR_ACCESS_DISABLED_WEBBLADE_TAMPER
ERROR_ACCESS_DISABLED_WEBBLADE
ERROR_INVALID_IMPORT_OF_NON_DLL
ERROR_NOT_SUPPORTED_ON_SBS
ERROR_LOGIN_WKSTA_RESTRICTION
ERROR_LOGIN_TIME_RESTRICTION
ERROR_PORT_UNREACHABLE
ERROR_INVALID_PASSWORDNAME
ERROR_DISK_OPERATION_FAILED
ERROR_SERVICE_NOT_IN_EXE
ERROR_KEY_HAS_CHILDREN
ERROR_KEY_DELETED
ERROR_BADKEY
ERROR_OPERATION_ABORTED
ERROR_PRIMARY_TRANSPORT_CONNECT_FAILED
ERROR_CARDBUS_NOT_SUPPORTED
ERROR_IMAGE_MACHINE_TYPE_MISMATCH_EXE
ERROR_PORT_NOT_SET
ERROR_UNSUPPORTED_COMPRESSION
ERROR_PORT_MESSAGE_TOO_LONG
ERROR_INVALID_PORT_ATTRIBUTES
ERROR_PIPE_LISTENING
ERROR_PIPE_CONNECTED
ERROR_EAS_NOT_SUPPORTED
ERROR_PIPE_NOT_CONNECTED
ERROR_PIPE_BUSY
ERROR_BAD_PIPE
ERROR_PIPE_LOCAL
ERROR_EXE_CANNOT_MODIFY_STRONG_SIGNED_BINARY
ERROR_EXE_CANNOT_MODIFY_SIGNED_BINARY
ERROR_EXE_MACHINE_TYPE_MISMATCH
ERROR_BAD_EXE_FORMAT
ERROR_EXE_MARKED_INVALID
ERROR_INVALID_EXE_SIGNATURE
ERROR_ATOMIC_LOCKS_NOT_SUPPORTED
ERROR_IS_JOIN_PATH
ERROR_SUBST_TO_JOIN
ERROR_JOIN_TO_SUBST
ERROR_JOIN_TO_JOIN
ERROR_NOT_JOINED
ERROR_IS_JOINED
ERROR_IS_JOIN_TARGET
ERROR_BROKEN_PIPE
ERROR_INVALID_PASSWORD
ERROR_TOO_MANY_CMDS
ERROR_NOT_SUPPORTED
SL_E_VL_KEY_MANAGEMENT_SERVICE_VM_NOT_SUPPORTED
SL_E_OPERATION_NOT_ALLOWED
SL_E_SLP_OEM_CERT_MISSING
SL_E_PKEY_INVALID_UPGRADE
SL_E_BLOCKED_PRODUCT_KEY
SL_E_INVALID_PRODUCT_KEY
SL_E_VL_KEY_MANAGEMENT_SERVICE_ID_MISMATCH
SL_E_VL_KEY_MANAGEMENT_SERVICE_NOT_ACTIVATED
SL_E_VL_NOT_WINDOWS_SLP
SL_E_PRODUCT_KEY_INSTALLATION_NOT_ALLOWED
SL_E_CIDIID_VERSION_NOT_SUPPORTED
SL_E_PROXY_KEY_NOT_FOUND
SL_E_WINDOWS_INVALID_LICENSE_STATE
SL_E_LICENSE_SERVER_URL_NOT_FOUND
SL_E_NOT_SUPPORTED
SL_E_PKEY_NOT_INSTALLED
SL_E_INVALID_PKEY
SL_E_MISMATCHED_PKEY_RANGE
SL_E_PKEY_INVALID_KEYCHANGE2
SL_E_PKEY_INVALID_KEYCHANGE3
SL_E_PKEY_INVALID_KEYCHANGE4
SL_E_PKEY_INVALID_KEYCHANGE1
SL_E_PKEY_INTERNAL_ERROR
SL_E_PKEY_INVALID_ALGORITHM
SL_E_PKEY_INVALID_UNIQUEID
SL_E_PKEY_INVALID_CONFIG
SL_E_CHREF_PRODUCT_KEY_BINDING_MISMATCH
SL_E_CHREF_PRODUCT_KEY_POLICY_OVERLAPPED
SL_E_CHREF_INVALID_PRODUCT_KEY_UNIQUEID
SL_E_CHREF_PRODUCT_KEY_POLICY_MISSING
SL_E_CHREF_INVALID_PRODUCT_KEY_ALGORITHM
SL_E_CHPA_FAILED_TO_INSERT_PRODUCT_KEY_RECORD
SL_E_CHPA_FAILED_TO_UPDATE_PRODUCT_KEY_RECORD
SL_E_CHREF_INVALID_PRODUCT_KEY
SL_E_CHREF_EXCLUDED_PRODUCT_KEY
SL_E_CHREF_PRODUCT_KEY_REVOKED
SL_E_CHPA_PRODUCT_KEY_BEING_USED
SL_E_CHPA_FAILED_TO_DELETE_PRODUCTKEY_BINDING
SL_E_CHPA_FAILED_TO_PROCESS_PRODUCT_KEY_BINDINGS_XML
SL_E_CHPA_FAILED_TO_INSERT_PRODUCT_KEY_PROPERTY
SL_E_CHPA_FAILED_TO_UPDATE_PRODUCT_KEY_PROPERTY
SL_E_CHPA_FAILED_TO_DELETE_PRODUCT_KEY_PROPERTY
SL_E_CHPA_UNKNOWN_PRODUCT_KEY_TYPE
SL_E_CHPA_FAILED_TO_INSERT_PRODUCTKEY_BINDING
SL_E_CHPA_FAILED_TO_UPDATE_PRODUCTKEY_BINDING
SL_E_CHPA_TIMEBASED_PRODUCT_KEY_NOT_CONFIGURED
SL_E_CHPA_INVALID_PRODUCT_KEY_CHAR
SL_E_CHPA_INVALID_PRODUCT_KEY_FORMAT
SL_E_CHPA_INVALID_PRODUCT_KEY_LENGTH
SL_E_CHPA_UNSUPPORTED_PRODUCT_KEY
SL_E_CHPA_INVALID_PRODUCT_KEY
SL_E_CHPA_PRODUCT_KEY_BLOCKED
SL_E_CHPA_PRODUCT_KEY_OUT_OF_RANGE
SL_E_SRV_INVALID_PRODUCT_KEY_LICENSE
t.Ht!HHt
JET_wrnKeyChanged
JET_wrnUniqueKey
JET_errInvalidOperation
JET_errLanguageNotSupported
JET_errKeyDuplicate
JET_errKeyNotMade
JET_errKeyIsMade
JET_errColumnIndexed
JET_errIndexTuplesKeyTooSmall
JET_errTooManyOpenIndexes
JET_errIllegalOperation
JET_errNullKeyDisallowed
JET_errLinkNotSupported
JET_errTooManyKeys
JET_errTooManyIndexes
JET_errUnicodeNormalizationNotSupported
JET_errSectorSizeNotSupported
JET_errInvalidLoggedOperation
JET_errKeyTooBig
JET_errKeyTruncated
JET_errKeyBoundary
RegCloseKey
RegOpenKeyExW
RegOpenKeyW
RegCreateKeyExW
RegDeleteKeyW
GetWindowsDirectoryW
_amsg_exit
TrustedInstaller.pdb
9$9*979_9
=!=&= =4=
SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Version
\cbscore.dll
0.0.0.1
\wrpint.dll
Software\Microsoft\Windows\CurrentVersion\Component Based Servicing\RebootPending
%s\%s
.WorkingDirectory
\CbsPersist_*.*
"%s" %s %s
\CbsPersist_*.log
makecab.exe
%s\CbsPersist_dddddd.log
\CBS.log
SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
wdscore.dll
SxsStore.dll
Windows Modules Installer
6.1.7601.17514 (win7sp1_rtm.101119-1850)
TrustedInstaller.exe
Windows
Operating System
6.1.7601.17514


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:4008
    netsh.exe:2096
    rundll32.exe:3828
    systeminfo.exe:3032

  2. Delete the original Worm file.
  3. Delete or disinfect the following files created/modified by the Worm:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\svhost.exe (11518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5DD9.tmp (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\log\Passwords.txt (0 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\log\AutoUpdate.exe (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tqyakoq (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\aut5F9F.tmp (3465 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A49RRPIQ\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AVOOSAB0\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UN62KCDO\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QS0ZUQ50\desktop.ini (67 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini (67 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "AutoUpdate" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\log\AutoUpdate.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Average: 2 (1 vote)

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now