Adware.SearchProtect.O_d146670a37
Adware.SearchProtect.O (AdAware), SearchProtectToolbar_pcap.YR, SearchProtectToolbar.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: d146670a3773b1cb9524fbba94bf7693
SHA1: 5a3d444172405b205cbdde66702ea02dd7b6a0f8
SHA256: c0c36a5386430e216bf272d2c526ab122757902c6e7c364e3cf2025aff4d22a3
SSDeep: 196608:msVG2er3x5z2Vr5W6fzk9posL3AYFTx3yMkw:mgG2w5z2V4RAQC2
Size: 8388608 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2011-07-06 17:31:20
Analyzed on: WindowsXP SP3 32-bit
Summary:
Adware. Delivers advertising content in a manner or context that may be unexpected and unwanted by users. Many adware applications also perform tracking functions. Users may want to remove adware if they object to such tracking, do not wish to see the advertising caused by the program or are frustrated by its effects on system performance.
Payload
No specific payload has been found.
Process activity
The Adware creates the following process(es):
%original file name%.exe:260
CltMngSvc.exe:1928
CltMngSvc.exe:1140
CltMngSvc.exe:1480
CltMngSvc.exe:2876
cltmng.exe:3112
cltmng.exe:884
nsl1E.exe:2288
SPSetup.exe:3172
cltmngui.exe:1628
cltmngui.exe:1452
nsd17.exe:2708
nst12.exe:1556
The Adware injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:260 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\main.js (10 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPTool64.exe (50351 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg11.tmp (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (256 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsxE.tmp (699919 bytes)
%Program Files%\SearchProtect\UI\bin\cltmngui.exe (100605 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.html (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-dia.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\v.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (886 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (933 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CARRIER_ID[1] (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst12.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\SPtool.dll (81732 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (1552 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def-grey.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (4 bytes)
%Program Files%\SearchProtect\Main\bin\SPTool.dll (81732 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (478 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (378 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\x.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (360 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (2 bytes)
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (2262 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\15.tmp (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (983 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (859 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (3 bytes)
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (98785 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (173700 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (274 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\System.dll (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (3312 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (6584 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (3 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (8184 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64.dll (153889 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32.dll (246690 bytes)
%Program Files%\SearchProtect\EULA.txt (784 bytes)
%Program Files%\SearchProtect\Main\bin\uninstall.exe (33747 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\defaults.js (591 bytes)
%Program Files%\SearchProtect\UI\dialogs\style.css (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\inetc.dll (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso10.tmp (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd17.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings.html (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CT3331172[1] (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\SP_DialogBG.png (10 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (2 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nshD.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\SPtool.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso10.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg11.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\System.dll (0 bytes)
The process CltMngSvc.exe:1928 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (171 bytes)
The process CltMngSvc.exe:2876 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Program Files%\SearchProtect\Main\rep\cfi.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\pni.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\edk.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (91 bytes)
%Program Files%\SearchProtect\Main\rep\trn.bin (708 bytes)
The process cltmng.exe:884 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\SPSetup.exe (247423 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\16.tmp (976945 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserSettings.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (1961 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Setup.exe (247423 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\16.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\STG\Init_15.tmp (0 bytes)
The process nsl1E.exe:2288 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%WinDir%\Temp\nsr20.tmp\inetc.dll (30 bytes)
The Adware deletes the following file(s):
%WinDir%\Temp\nsr20.tmp\a.txt (0 bytes)
%WinDir%\Temp\nsr20.tmp\inetc.dll (0 bytes)
%WinDir%\Temp\nsr20.tmp (0 bytes)
%WinDir%\Temp\nsb1F.tmp (0 bytes)
%WinDir%\Temp\nsl1E.tmp (0 bytes)
The process SPSetup.exe:3172 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Program Files%\SearchProtect\UI\dialogs\Images\Icon.ico (3312 bytes)
%WinDir%\Temp\nsr1C.tmp\System.dll (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\main.js (10 bytes)
%WinDir%\Temp\nsr1C.tmp\inetc.dll (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (256 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC32.dll (262279 bytes)
%Program Files%\SearchProtect\UI\bin\cltmngui.exe (106386 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.html (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPtool64.exe (52609 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\DialogAPI.js (3 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-dia.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\v.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (886 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (1 bytes)
%Program Files%\SearchProtect\Main\bin\SPtool.dll (93030 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (933 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (1 bytes)
%WinDir%\Temp\nsr1C.tmp\SPTool.dll (93030 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (1552 bytes)
%WinDir%\Temp\nsp21.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def-grey.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (4 bytes)
%Documents and Settings%\LocalService\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (4 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\RN32.dll (8184 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (378 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\x.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (360 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (784 bytes)
%Program Files%\SearchProtect\Main\bin\sptool.dll_1418205318509 (18934 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (2 bytes)
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (64 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (2 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC64Loader.dll (9320 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (983 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (859 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection (4 bytes)
%WinDir%\Temp\nsr1D.tmp (869 bytes)
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (101987 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC32Loader.dll (8184 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (186350 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (274 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (3312 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (3 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (1 bytes)
%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLSNQ10Z\CARRIER_ID[1] (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall (4 bytes)
%Program Files%\SearchProtect\EULA.txt (784 bytes)
%Program Files%\SearchProtect\Main\bin\uninstall.exe (34365 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs (4 bytes)
%WinDir%\Temp\nsl1E.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\style.css (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (424 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings.html (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC64.dll (161974 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\SP_DialogBG.png (10 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\defaults.js (591 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (2 bytes)
%WinDir%\Temp\nsl1B.tmp (698190 bytes)
The Adware deletes the following file(s):
%WinDir%\Temp\nsr1C.tmp\System.dll (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\main.js (0 bytes)
%WinDir%\Temp\nsr1C.tmp\inetc.dll (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPTool64.exe (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (0 bytes)
%Program Files%\SearchProtect\UI\bin\cltmngui.exe (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (0 bytes)
%WinDir%\Temp\nsl1A.tmp (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-dia.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\v.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.css (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (0 bytes)
%WinDir%\Temp\nsr1C.tmp\SPTool.dll (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def-grey.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (0 bytes)
%Program Files%\SearchProtect\UI\bin (0 bytes)
%Program Files%\SearchProtect\Main\bin\SPTool.dll (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\x.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (0 bytes)
%Program Files%\SearchProtect\UI (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (0 bytes)
%WinDir%\Temp\nsr1D.tmp (0 bytes)
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64.dll (0 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32.dll (0 bytes)
%Program Files%\SearchProtect\EULA.txt (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (0 bytes)
%Program Files%\SearchProtect\UI\dialogs (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\defaults.js (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\style.css (0 bytes)
%Program Files%\SearchProtect\UI\rep (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (0 bytes)
%WinDir%\Temp\nsr1C.tmp (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\SP_DialogBG.png (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (0 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (0 bytes)
The process cltmngui.exe:1628 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI\rep\UIRepository.dat (1067 bytes)
The process cltmngui.exe:1452 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI\rep\UIRepository.dat (5 bytes)
The process nsd17.exe:2708 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsq19.tmp\inetc.dll (30 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsq19.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd17.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq19.tmp\a.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq19.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk18.tmp (0 bytes)
The process nst12.exe:1556 makes changes in the file system.
The Adware creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nss14.tmp\inetc.dll (30 bytes)
The Adware deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nst12.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsc13.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss14.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss14.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss14.tmp\a.txt (0 bytes)
Registry activity
The process %original file name%.exe:260 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nst12.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\SPtool.dll,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs" = "C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"Publisher" = "Client Connect LTD"
[HKLM\SOFTWARE\SearchProtect]
"Environment" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"UninstallString" = "C:\PROGRA~1\SearchProtect\Main\bin\uninstall.exe /S"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayVersion" = "2.17.26.7"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\SearchProtect]
"InstallDir" = "C:\PROGRA~1\SearchProtect"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayIcon" = "C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe"
"DisplayName" = "Search Protect"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EA 9C 75 67 AA 8A C3 17 B4 B7 00 83 F3 48 14 E3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The Adware disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallCleanUp"
The process CltMngSvc.exe:1928 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "89 C0 31 BF 56 AA 84 61 9D CB 50 41 BB 5A D4 F0"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\SPPDCOM]
"TS" = "0"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"
The process CltMngSvc.exe:1140 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3B E9 85 ED D5 CA 9C B4 E7 7E 79 8D 83 64 B0 09"
The process CltMngSvc.exe:1480 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "38 31 CC A1 B9 76 85 5D 9F 62 34 0B E4 B4 04 AF"
The process CltMngSvc.exe:2876 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 06 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6F 11 00 1A 3D FE C6 78 93 AB 67 F4 9E 10 75 8B"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nst12.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\SPtool.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\System.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd17.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\, , \??\%WinDir%\TEMP\nsr20.tmp\, , \??\%WinDir%\TEMP\nsl1E.exe, , \??\%WinDir%\TEMP\nsr20.tmp\, , \??\%WinDir%\TEMP\nsr1C.tmp\SPTool.dll,"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\SOFTWARE\SPPDCOM]
"TS" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Adware deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"
The process cltmng.exe:3112 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A2 80 4D 36 76 6E 7B D5 80 12 8C 09 62 6A E5 F8"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The process cltmng.exe:884 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 20 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2F 07 8C FE AB 95 72 E9 99 3A 03 28 84 9C 2F 27"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process nsl1E.exe:2288 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 05 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
"BaseClass" = "Drive"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
"BaseClass" = "Drive"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "46 A1 1A 40 DC 83 AB 80 4E 4D 93 08 74 A8 99 31"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nst12.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\SPtool.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\System.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd17.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\, , \??\%WinDir%\TEMP\nsr20.tmp\,"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Adware deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"
The process SPSetup.exe:3172 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\LocalService\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"Publisher" = "Client Connect LTD"
[HKLM\SOFTWARE\SearchProtect]
"Environment" = ""
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs" = ""
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"UninstallString" = "C:\PROGRA~1\SearchProtect\Main\bin\uninstall.exe /S"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayVersion" = "2.19.0.260"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"
[HKLM\SOFTWARE\SearchProtect]
"InstallDir" = "C:\PROGRA~1\SearchProtect"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayIcon" = "C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe"
"DisplayName" = "Search Protect"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "02 18 D3 A5 C5 59 5B B9 41 AA A4 B3 EE B6 AC 70"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nst12.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\SPtool.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\System.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd17.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\,"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Adware deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"
The Adware disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallCleanUp"
The process cltmngui.exe:1628 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 21 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5F 08 3A B4 47 A4 52 AC 04 23 6F F6 E2 85 D6 C0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process cltmngui.exe:1452 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D8 33 E9 E1 17 0D 79 15 37 05 40 7D 4F F0 61 27"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The process nsd17.exe:2708 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nst12.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\SPtool.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\System.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nshF.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsq19.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 22 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DE 1A 2A 95 86 2D FE CF 73 21 DE DF 1F 7F E6 20"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process nst12.exe:1556 makes changes in the system registry.
The Adware creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nss14.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E0 6A 9F CD CC AB E3 94 FF BB 57 39 0E 5D 18 28"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Adware modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Adware modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Adware modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Adware deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
| MD5 | File path |
|---|---|
| 42365308ed484a0630563a9171ab00c9 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nshF.tmp\SPtool.dll |
| 5ccde6cbe28a74c393f2b7b6f5cc7458 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nshF.tmp\System.dll |
| 8326b29343614f3db9d8e3da200bde36 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nshF.tmp\inetc.dll |
| a847a883a6d472420adc982157ec943e | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nst12.exe |
| 4f9b3200df88342d781dab23d27b6591 | c:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe |
| a9037d95602980f7d4d7dfab57248058 | c:\Program Files\SearchProtect\Main\bin\SPTool.dll |
| b19f9389d4cd85cbd05c55fa596efaaf | c:\Program Files\SearchProtect\Main\bin\uninstall.exe |
| 42a6752c3cef4732d1be0005b43462f4 | c:\Program Files\SearchProtect\SearchProtect\bin\SPTool64.exe |
| 42b862b84e259ae476c2ad930ae2f954 | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32.dll |
| 96830f449d00f18ba30ad31f950e9ba5 | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll |
| 71341b5165fc81ad0fdaa2cb15b2392f | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC64.dll |
| d4ee1125f943c7209d84678e0b5ded0d | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC64Loader.dll |
| 6bf7a45328017bfdbd1535663a0b6acc | c:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe |
| d2931d2cdf0fbe2efd8dbbc4422f9c5f | c:\Program Files\SearchProtect\UI\bin\cltmngui.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Client Connect LTD
Product Name: Search Protect
Product Version: 2.17.26.7
Legal Copyright: (c) 2014 ClientConnect Ltd.
Legal Trademarks:
Original Filename: SearchProtect
Internal Name: Unknown
File Version: 2.17.26.7
File Description: Search Protect
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 25506 | 25600 | 4.49191 | 3291075913c14a1799655a261fb21cca |
| .rdata | 32768 | 6386 | 6656 | 3.3883 | 170563e94de7ebfd6e622a164ce38c8a |
| .data | 40960 | 419484 | 512 | 0.991115 | 23d69b1e3a55dee07701198b7650a06b |
| .ndata | 462848 | 2215936 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 2678784 | 96712 | 96768 | 2.98395 | 4244cfb5b429ac4e89fafab81dc45416 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 200
bdc0a9791cd5a5021877f2d5c93e8d9a
27dd6c4995ae90478d38129cb9fd05fd
9eb64531fc9dffa377b38560ee43c3ed
e00d7076d1508240cf5a83f047c7d796
7f718c92fd842c77a2493cf2d0755b30
fe9057d8f1b766ed2705a349bb6a4f3e
169aea9362ae27c26f3dfd417c83d967
95709066666c26f01c33da90ccb5cf67
f440acfcafe8216bebba2d528046fca7
b5b704d3dcc8f5069a9f6c566835515c
3070a18a8f6dc6cacce654f50d4f4904
ae909f60bf7f203b3be0d87d1f20dda9
038f73486e57aa08a8983ab28e0a3d41
3abc6635ca4b14c1fccecc862a4fa179
79aa439c4d2ba572cd49f6a902887319
e30bffdea44cb183957b41779e60eeb9
4740c7403694215859c659be34851c19
6282e9ee82925b33878523f1a58ec062
4fe69198606180e648b25fa2872ee5fa
4d2fed93263493851eb7b0de43167bb6
1c6cf8ca512a19eac6aacf91b2245aeb
10edcfe525cef69808f1ef908eddb573
51f47effd70765264d89d8195e6cfa32
51881ba5de1148c5ce8a83220420b3b5
c251604c30aee495ef478417f6af4311
URLs
| URL | IP |
|---|---|
| hxxp://Jazz-1846647836.us-east-1.elb.amazonaws.com/ | |
| hxxp://sp-ip2location.ams.spccint.com/ip/?client=sp | |
| hxxp://a1015.g1.akamai.net/UP/settings/?ctid=CT3331172&UM=&c=UA&DUM=2 | |
| hxxp://e9287.g.akamaiedge.net/AutoUpdate/2.19.0.260/AutoUpdate.zip | |
| hxxp://sp-ip2location.spccint.com/ip/?client=sp | |
| hxxp://sp-storage.spccinta.com/AutoUpdate/2.19.0.260/AutoUpdate.zip | |
| hxxp://sp-alive-msg.databssint.com/ | |
| hxxp://sp-usage.databssint.com/ | |
| hxxp://c.api.seccint.com/UP/settings/?ctid=CT3331172&UM=&c=UA&DUM=2 | |
| servicemap.spccint.com | |
| sp-settings.spccint.com | |
| sp-autoupdate.spccint.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
SURICATA STREAM ESTABLISHED packet out of window
SURICATA STREAM Packet with invalid ack
SURICATA STREAM ESTABLISHED invalid ack
Traffic
GET /ip/?client=sp HTTP/1.1
User-Agent: SearchProtect;2.17.26.7;Microsoft Windows XP;SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E
Accept: */*
Host: sp-ip2location.spccint.com
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 178
Content-Type: application/json; charset=text/plain
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
P3P: CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Date: Wed, 10 Dec 2014 09:52:30 GMT{"Location":{"City":"KHARKIV","Country":"UKRAINE","CountryCode":"UA","
IP":"37.57.16.189","Latitude":49.98081,"Longitude":36.25272,"Region":"
KHARKIVS'KA OBLAST'"},"Language":"uk"}HTTP/1.1 200 OK..Cache-Control:
private..Content-Length: 178..Content-Type: application/json; charset=
text/plain..Server: Microsoft-IIS/7.5..X-AspNet-Version: 4.0.30319..X-
Powered-By: ASP.NET..P3P: CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS
IND UNI COM NAV INT"..Date: Wed, 10 Dec 2014 09:52:30 GMT..{"Location"
:{"City":"KHARKIV","Country":"UKRAINE","CountryCode":"UA","IP":"37.57.
16.189","Latitude":49.98081,"Longitude":36.25272,"Region":"KHARKIVS'KA
OBLAST'"},"Language":"uk"}..
GET /AutoUpdate/2.19.0.260/AutoUpdate.zip HTTP/1.1
User-Agent: SearchProtect;2.17.26.7;Microsoft Windows XP;SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E
Accept: */*
Host: sp-storage.spccinta.com
HTTP/1.1 200 OK
Last-Modified: Wed, 10 Dec 2014 12:37:52 GMT
Accept-Ranges: bytes
ETag: "7d1d224a1fafad9f71f49af80bf681ec"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
P3P: CP="IDC DSP COR CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT"
Content-Length: 15312309
Date: Wed, 10 Dec 2014 09:52:32 GMT
Connection: keep-alivePK..........{E......t..;v.....Setup.exe...xT..?|.G.!L.A...0JP4.....t.9
.j.'.3...".0.C.&...e.0.e8...m.m.-.mmk.... ..0.J.."-Z..=.D... ..~.>g
B.......}..y.]s.....k......._..3p.g.(...q......z.....(......MW.....j..
....5U.._[U_. ....o...k..K.q..o..O...,...`....._sG."...c.{...{.v...x.z
.#w.......{Y...\[email protected]].....%..6.F.Fp\5"..8n>..=.a `.6z..9...
tN}..5..X..7Pv He..C.......a....|K7......c.......<..W....7.x>.V
C..j..L>F3...J....r.6.q........Z..I....c....S....Z.c.... .>....P
c4.m.-:F...{.......?....]...-B!~K%>[../..JY..-.....E.*.Y.MJ.....~7f
...f.G./.?.bY.....sQ.....i.H.B}a..'M(...Qtiy.t..Y....G.^-t...:...tN.:.
.g.;zLQ>....nyv....S6t _r".......n.qY....r.i.K.....3..,B.a...Bk*Ff%
g.0R.l.x...E!...^Q......W6.Tr.P.."..G...:_.......Mx(9..P6,.)9.....Y...
)'..(..?..vGJ.....hF>.w.^.#}u..}...VN* 0...=..j_.wp..Lo.8..<^_..
:.b.u...%. .G(?V.3.%.@.^0,LL..0.#.W..........8R...o..t..FsK....D.K WW.
4....K.42...J...P).Y..d;..:.A.'....i.2.=..............-.&....#D2.....
.d.>.....`P.......g...t.....ok_]....ph....CINH./19.....ZN.O.sD.]bJ.
....6.>..|{.....1..'..H..m.....|sPH.w...p............x.....7...#.=.
y.I..L...I...\.n.;..4.:.w.......S$...H..}...K.A[..x..d0..nR.........#.
.t...i...#da.a>i.@..~*..l.FN*)0F.C...v.J?.Y.r......9..^I(0%.R.1b...
......:a.K~."8..._...? .i....D.".....#........v....2.......<.. .-..
..cEP..\%g..12......S.Fm'>'..,"...Z..Z.....=..g.k.`..y|7.f..r...Xt.
...wH.D..s'.....;.Fu...i.2sg..Hv..QCJ.h.O...K]..a.Zz.zR4P1..=..c..M..)
wJ..!v.Cb.4.C..4.$1...*...E..T.....;.:W..4T.TN`..B..........~H(p .<<< skipped >>>
POST / HTTP/1.1
Content-Type: application/json
Accept: */*
User-Agent: SearchProtect;2.17.26.7;Microsoft Windows XP;SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E
Host: sp-alive-msg.databssint.com
Content-Length: 459
Connection: Keep-Alive
Cache-Control: no-cache
{"SP_ID":"SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E","SP_version":"2.17.26.7","OS_name":"Microsoft Windows XP","OS_version":"5.1","install_date":"20141210","environment":"","machine_ID":"XBCH99S2MORNV BFTUNCQDORF4GOQHAH O2SAU9AQYIBBSAVNOX00IKATVZ0NLXRAOGOZEEWD3TW93FKX3FRHW","Experiment":"","Variant":"","action_type":"alive","type":"","brand":"SP","carrier_ID":"CT3331172","driver_enabled":"false","browser":"InternetExplorer","browser_version":"6.0.2900.5512"}
HTTP/1.1 202 Accepted
Date: Wed, 10 Dec 2014 09:52:31 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-aliveHTTP/1.1 202 Accepted..Date: Wed, 10 Dec 2014 09:52:31 GMT..P3P: CP="N
OI ADM DEV COM NAV OUR STP"..Server: Apache-Coyote/1.1..Content-Length
: 0..Connection: keep-alive..
POST / HTTP/1.0
Content-Type: application/json
Accept: */*
Host: sp-usage.databssint.com
Content-Length: 420
Connection: Keep-Alive
Pragma: no-cache
{"SP_ID":"SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E","Experiment":"","Variant":"","oslocale":"en-US","environment":"","OS_version":"5.1","OS_name":"Microsoft Windows XP","machine_ID":"XBCH99S2MORNV BFTUNCQDORF4GOQHAH O2SAU9AQYIBBSAVNOX00IKATVZ0NLXRAOGOZEEWD3TW93FKX3FRHW","sequence_timestamp":"1418205258775","SP_version":"2.17.26.7","brand":"SP","action_type":"driver_first_enabled","result":"success","failure_reason":""}
HTTP/1.1 202 Accepted
Access-Control-Allow-Methods: GET,POST,HEAD,OPTIONS,PUT
Access-Control-Allow-Origin: *
Date: Wed, 10 Dec 2014 09:52:24 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-aliveHTTP/1.1 202 Accepted..Access-Control-Allow-Methods: GET,POST,HEAD,OPT
IONS,PUT..Access-Control-Allow-Origin: *..Date: Wed, 10 Dec 2014 09:52
:24 GMT..P3P: CP="NOI ADM DEV COM NAV OUR STP"..Server: Apache-Coyote/
1.1..Content-Length: 0..Connection: keep-alive..
GET /UP/settings/?ctid=CT3331172&UM=&c=UA&DUM=2 HTTP/1.1
User-Agent: SearchProtect;2.17.26.7;Microsoft Windows XP;SP05C27ED2-6166-4A8D-B56A-38CB1BE55A4E
Accept: */*
Host: c.api.seccint.com
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 3.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Content-Length: 4226
Cache-Control: private, max-age=3600
Expires: Wed, 10 Dec 2014 10:52:31 GMT
Date: Wed, 10 Dec 2014 09:52:31 GMT
Connection: keep-alive{"GeneralId":null,"Ctid":"CT3331172","ProviderId":2,"ProviderName":"Bi
ng","UserIP":"37.57.16.189","UserLanguage":"ru","ToolbarLanguage":"en"
,"EntityLanguage":"en","CountryShortCode":"UA","IsUserRTL":false,"IsTo
olbarRTL":false,"IsEntityRTL":false,"ShowClientDialog":true,"HomePageU
rl":"hXXp://VVV.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&I
SID=ISID_ID&SearchSource=55&CUI=SB_CUI&UM=6&UP=UP_ID","IsCustomizedHom
epage":false,"HomePageButtonUrl":"hXXp://VVV.trovi.com/?gd=&ctid=CT333
1172&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=55&CUI=SB_CUI&UM
=6&UP=UP_ID&SAT=HPB","UM":"","SearchDomain":"VVV.trovi.com","ToolbarSe
archBox":{"History":{"IsEnabled":true,"Position":1,"MaxAmount":5,"Labe
l":{"Text":"History"}},"Verticals":[{"Name":"SearchImages","SearchUrl"
:"hXXp://VVV.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID
=ISID_ID&SearchSource=67&SearchType=SearchImages&CUI=SB_CUI&UM=6&UP=UP
_ID&q=UCM_SEARCH_TERM","EmptySearchUrl":"hXXp://VVV.trovi.com/?gd=&cti
d=CT3331172&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&Search
Type=SearchImages&CUI=SB_CUI&UM=6&UP=UP_ID"}],"EmptySearchUrl":"http:/
/VVV.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=ISID_ID
&SearchSource=67&CUI=SB_CUI&UM=6&UP=UP_ID","SearchUrl":"hXXp://VVV.tro
vi.com/Results.aspx?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=ISI
D_ID&SearchSource=67&CUI=SB_CUI&UM=6&UP=UP_ID&q=UCM_SEARCH_TERM","Sugg
est":{"SearchResultsUrl":"hXXp://VVV.trovi.com/Results.aspx?gd=&ctid=C
T3331172&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&Sugge<<< skipped >>>
The Adware connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.reloc
SHA256 block transform for x86, CRYPTOGAMS by <[email protected]>
SHA1 block transform for x86, CRYPTOGAMS by <[email protected]>
.EKSWU
DlSHA512 block transform for x86, CRYPTOGAMS by <[email protected]>
\$$;\$0|
Montgomery Multiplication for x86, CRYPTOGAMS by <[email protected]>
6-9'6-9'
$6.:$6.:
*?#1*?#1
>8$4,8$4,
AES for x86, CRYPTOGAMS by <[email protected]>
FtPS
GF(2^m) Multiplication for x86, CRYPTOGAMS by <[email protected]>
Camellia for x86 by <[email protected]>
AES for Intel AES-NI, CRYPTOGAMS by <[email protected]>
RC4 for x86, CRYPTOGAMS by <[email protected]>
GHASH for x86, CRYPTOGAMS by <[email protected]>
[email protected]
t.JuG
PSSSSSSh
t.VVW
<1%u5
FTPj
tCPQ
,4,56,789
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
0123456789-
%b %d %H : %M : %S %Y
%m / %d / %y
%I : %M : %S %p
%d / %m / %y
boost thread: trying joining itself
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flagVisual C CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
operator
GetProcessWindowStation
kernel32.dll
The repeat operator "*" cannot start a regular expression.
The repeat operator "?" cannot start a regular expression.
The repeat operator " " cannot start a regular expression.
Found a closing repetition operator } with no corresponding {.Can't terminate a sub-expression with an alternation operator |.
The \c and \C escape sequences are not supported by POSIX basic regular expressions: try the Perl syntax instead.
A regular expression can start with the alternation operator |.
Invalid alternation operators within (?...) block.
More than one alternation operator | was encountered inside a conditional expression.
Alternation operators are not allowed inside a DEFINE block.
A repetition operator cannot be applied to a zero-width assertion.
left-curly-bracket
right-curly-bracket
0123456789
Unmatched quantified repeat operator { or \{.Invalid preceding regular expression prior to repetition operator.
len>=0 && len<=(int)sizeof(ctx->key)
j <= (int)sizeof(ctx->key)
SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013
SHA1 part of OpenSSL 1.0.1e 11 Feb 2013
ssl_sess_cert
ssl_cert
evp_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013
passed a null parameter
DSO support routines
x509 certificate routines
Stack part of OpenSSL 1.0.1e 11 Feb 2013
Any Extended Key Usage
anyExtendedKeyUsage
supportedAlgorithms
crossCertificatePair
certificateRevocationList
cACertificate
userCertificate
userPassword
supportedApplicationContext
Microsoft Local Key set
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
certificateIssuer
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
hexkey
rsa_keygen_pubexp
rsa_keygen_bits
lhash part of OpenSSL 1.0.1e 11 Feb 2013
ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013
Big Number part of OpenSSL 1.0.1e 11 Feb 2013
%d.%d.%d.%d
EC part of OpenSSL 1.0.1e 11 Feb 2013
ECDSA part of OpenSSL 1.0.1e 11 Feb 2013
.\crypto\ec\ec_key.c
priv_key
pub_key
DSA part of OpenSSL 1.0.1e 11 Feb 2013
Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013
.\crypto\dh\dh_key.c
RSA part of OpenSSL 1.0.1e 11 Feb 2013
value.single
value.set
RAND part of OpenSSL 1.0.1e 11 Feb 2013
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
keylen <= sizeof key
EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)
EVP part of OpenSSL 1.0.1e 11 Feb 2013
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
ECDH part of OpenSSL 1.0.1e 11 Feb 2013
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
d.receiptList
d.allOrFirstTier
d.compressedData
d.authenticatedData
d.encryptedData
d.digestedData
d.envelopedData
d.signedData
d.data
d.ori
d.pwri
d.kekri
d.kari
d.ktri
CMS_PasswordRecipientInfo
keyDerivationAlgorithm
keyIdentifier
CMS_KeyAgreeRecipientInfo
recipientEncryptedKeys
CMS_OriginatorIdentifierOrKey
d.originatorKey
CMS_OriginatorPublicKey
publicKey
CMS_RecipientEncryptedKey
CMS_KeyAgreeRecipientIdentifier
d.rKeyId
CMS_RecipientKeyIdentifier
CMS_OtherKeyAttribute
keyAttr
keyAttrId
CMS_KeyTransRecipientInfo
encryptedKey
keyEncryptionAlgorithm
certificates
d.crl
d.subjectKeyIdentifier
d.issuerAndSerialNumber
CMS_CertificateChoices
d.other
d.v2AttrCert
d.v1AttrCert
d.extendedCertificate
d.certificate
CMS_OtherCertificateFormat
otherCert
otherCertFormat
AES part of OpenSSL 1.0.1e 11 Feb 2013
%s: (%d bit)
Public-Key
Private-Key
recommended-private-length: %d bits
public-key:
private-key:
PKCS#3 DH Public-Key
PKCS#3 DH Private-Key
Public-Key: (%d bit)
Private-Key: (%d bit)
USER32.DLL
NETAPI32.DLL
KERNEL32.DLL
ADVAPI32.DLL
keylength
keyfunc
.\crypto\pkcs12\p12_key.c
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
CONF part of OpenSSL 1.0.1e 11 Feb 2013
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
name.relativename
name.fullname
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
%*s%s:
%*sOnly Attribute Certificates
%*sOnly CA Certificates
%*sOnly User Certificates
%d.%d.%d.%d/%d.%d.%d.%d
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
keyid
.\crypto\x509v3\v3_akey.c
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
%*sCPS: %s
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
pubkey
cert_info
X.509 part of OpenSSL 1.0.1e 11 Feb 2013
PROXY_CERT_INFO_EXTENSION
EC_PRIVATEKEY
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
x%s
Basis Type: %s
Field Type: %s
ASN1 OID: %s
%s %s%lu (%s0x%lx)
%s - d:d:d%.*s %d%s
\X
'() ,-./:=?
CONF_def part of OpenSSL 1.0.1e 11 Feb 2013
[[%s]]
[%s] %s=%s
MD5 part of OpenSSL 1.0.1e 11 Feb 2013
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
certs
AUTHORITY_KEYID
enc_key
key_enc_algor
cert
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
X509_CERT_PAIR
X509_CERT_AUX
PEM part of OpenSSL 1.0.1e 11 Feb 2013
ddddddZ
ddddddZ
value.bag
value.safes
value.shkeybag
value.keybag
value.sdsicert
value.x509cert
value.other
%s.dll
?456789:;<=
!"#$%&'()* ,-./0123
Verifying - %s
NETSCAPE_CERT_SEQUENCE
RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013
SHA part of OpenSSL 1.0.1e 11 Feb 2013
MD4 part of OpenSSL 1.0.1e 11 Feb 2013
CAST part of OpenSSL 1.0.1e 11 Feb 2013
Blowfish part of OpenSSL 1.0.1e 11 Feb 2013
:RC2 part of OpenSSL 1.0.1e 11 Feb 2013
.pp@0
aEÐ
(#EÚ
ÚE<<0
IDEA part of OpenSSL 1.0.1e 11 Feb 2013
libdes part of OpenSSL 1.0.1e 11 Feb 2013
DES part of OpenSSL 1.0.1e 11 Feb 2013
%T%D%Q%W%J%S%L%B%J%
%F%J%H%
p%K%N%K%J%R%K%d%V%V%@%Q%v%Q%D%Q%@%
d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp
{{{$1201}}}{{{$1205}}}{{{$1206}}}{{{$712}}}{{{$1207}}}{{{$1215}}}{{{$1217}}}{{{$1219}}}{{{$1218}}}{{{$1221}}}{{{$1220}}}{{{$1223}}}{{{$1222}}}{{{$1225}}}{{{$1224}}}{{{$1227}}}{{{$1226}}}{{{$1229}}}{{{$1228}}}{{{$1231}}}{{{$1230}}}{{{$1233}}}{{{$1232}}}{{{$1261}}}{{{$1262}}}{{{$1263}}}{{{$1265}}}{{{$1264}}}{{{$1267}}}{{{$1266}}}{{{$1269}}}{{{$1268}}}{{{$1270}}}{{{$1272}}}{{{$1271}}}{{{$1277}}}{{{$1273}}}{{{$1275}}}{{{$1276}}}{{{$1274}}}@%]%U%I%J%W%@%W%
{{{$1282}}}{{{$1284}}}{{{$1283}}}{{{$1285}}}\9\.\/\5\3\2\
{{{$1290}}}{{{$1291}}}{{{$1293}}}{{{$1292}}}{{{$1294}}}{{{$1295}}}{{{$1296}}}{{{$145}}}{{{$146}}}{{{$149}}}{{{$147}}}{{{$148}}}{{{$154}}}{{{$150}}}{{{$153}}}{{{$156}}}{{{$155}}}{{{$128}}}{{{$131}}}{{{$126}}}{{{$127}}}{{{$134}}}{{{$135}}}{{{$132}}}{{{$133}}}{{{$138}}}{{{$136}}}{{{$137}}}{{{$141}}}F#F4F0F/F%F#FfF#F>F/F5F2F5FfF$F3F2FfF
F#F4F0F/F%F#FfF4F#F2F3F4F(F#F"FfF#F4F4F)F4FfF
[>[)[-[2[8[>[{[[3[:[5[<[>[{[[>[)[-[2[8[>[{[:[.[/[4[6[:[/[2[8[{[?[>[7[:["[>[?[{[=[:[2[7[>[?[{{{$548}}}{{{$546}}}Y1YD3P48A0BSSHLXUP0IBHHU4I0VCX7B9HHZJ6J0CXHG68QGQFPCKQQ6ZRB11JO34K3VBHMVDBBTDLOQ1JE70J9KC9EVTA0V6IH6D1DV16F4FL2F5O0YPEBV3LSDZCWKD44BDHWEEPQQ14O9L37OB4XY
{{{$543}}}{{{$536}}}0c3c.cCcNcCc!c
]2]2])].])]/]<]-]8]/]}]
]8]:]4].])]8]/]
]/]2]*].]8]/]
]4];]8])]4]0]8]
@2@!@.@$@
@/@,@$@%@2@
{{{$570}}}{{{$571}}}{{{$574}}}{{{$573}}}{{{$572}}}{{{$575}}}{{{$576}}}{{{$583}}}{{{$582}}}{{{$581}}}{{{$585}}}{{{$584}}}{{{$586}}}{{{$590}}}{{{$589}}}{{{$588}}}{{{$587}}}{{{$591}}}{{{$593}}}{{{$592}}}{{{$595}}}{{{$594}}}{{{$596}}}{{{$597}}}{{{$600}}}{{{$599}}}{{{$598}}}{{{$601}}}{{{$602}}}{{{$603}}}{{{$606}}}{{{$605}}}{{{$604}}}F4F)F'F"F%F'F5F2F
{{{$607}}}{{{$608}}}{{{$610}}}{{{$609}}}{{{$699}}}{{{$698}}}{{{$697}}}{{{$696}}}{{{$701}}}{{{$700}}}D D>D-D(D(D%D
{{{$448}}}{{{$447}}}{{{$449}}}|[|!|'|<|
{{{$452}}}{{{$455}}}{{{$458}}}{{{$471}}}{{{$472}}}CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);
insert into ItemTable (key, value) VALUES ('%s', '%s');_0_<_>_3_
_ _>_ _:_
,D D)D!D4D%D#D!D
D*D!D3D0D%D&D4D%D#D!D
_0_1_9_6_-_2_
_'_ _:_1_,_6_0_1_
{{{$350}}}{{{$351}}}{{{$352}}}{{{$372}}}{{{$401}}}{{{$403}}}{{{$402}}}{{{$404}}}^1^1^9^2^;^
^6^,^1^3^;^
^-^;^,^~^
g%W%D%K%A%v%@%Q%Q%L%K%B%V%
^ ^,^,^;^0^*^
^;^,^-^7^1^0^
{{{$716}}}{{{$717}}}{{{$718}}}{{{$715}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h
\StringFileInfo\xx\%s
(more frames truncated from call stack report)
%d/%d/%d d:d:d
File Size: %-10d File Time: %s
Company: %s
Product: %s
Module %d
Image Base: 0xx Image Size: 0xx
Checksum: 0xx Time Stamp: 0xx
Windows Vista
FileDesc: %s
FileVer: %d.%d.%d.%d
ProdVer: %d.%d.%d.%d
Windows 9
Windows 7
Windows Server 2012
Windows 8
Windows Server 9
Windows 2000
Web Edition
Windows Server 2008
Windows XP
Windows Server 2008 R2
This sample does not support this version of Windows.
Error occurred at %s.
(build %d)
%d processor(s), type %d.
%d%% memory in use.
%d MBytes physical memory free.
Operating system: %s
Operating system: Could not Determine
Windows Storage Server 2003
Windows Home Server
%d MBytes paging file.
Windows XP Professional x64 Edition
%d MBytes user address space free.
Windows Server 2003
%d MBytes user address space.
%d MBytes paging file free.
a Float Denormal Operand
Web Server Edition
Windows Server 2003 R2
a Float Invalid Operation
0xx:
%d MBytes physical memory.
%s\CRASH_REPORT_%s.txt
%s caused %s (0xx)
in module %s at x:x.
EDI: 0xx ESI: 0xx EAX: 0xx
EBX: 0xx ECX: 0xx EDX: 0xx
EIP: 0xx EBP: 0xx SegCs: 0xx
EFlags: 0xx ESP: 0xx SegSs: 0xx
===== [end of %s] =====
%s location x caused an access violation.
%s\CRASH_DUMP_%s.dmp
Exception code is 0xX
Crash dump file: %s
Crash report file :%s
Error creating dump file, err=%d
P%d_T%d_Dld_ld_ld_Tld_ld_ld
code: %x, addr: %x, module: %s
code: %x
00:00:00.
@2@#@(@)@4@%@#@4@5@2@%@
NtQueryKey
{{{$704}}}{{{$705}}}{{{$706}}}{{{$707}}}{{{$702}}}{{{$703}}}{{{$709}}}{{{$708}}}{{{$710}}}{{{$790}}}{{{$791}}}{{{$792}}}{{{$793}}}%s 0x%I64x %s [file:%s(%u)]
hXXp://
wininet.dll
hXXps://
PTF://
[%u, 0xx] %s
https
HTTP/1.0
Content-Type: application/x-www-form-urlencoded
request HttpSendRequestA failed...
Content-Length: %u
response failed...last error %d
1.1.3
gen_codes: max_code %d
code %d bits %d->%d
bl code -
last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)
opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u
{{{$822}}}{{{$823}}}{{{$825}}}{{{$824}}}@'@%@.@4@
@/@)@.@`@7@!@)@4@)@.@'@`@&@/@2@`@
@/@.@%@`@
@%@3@0@/@.@3@%@}@
{{{$826}}}{{{$827}}}{{{$828}}}{{{$830}}}{{{$829}}}{{{$831}}}{{{$832}}}{{{$835}}}{{{$833}}}{{{$834}}}{{{$839}}}{{{$836}}}{{{$837}}}{{{$838}}}{{{$840}}}{{{$847}}}{{{$848}}}{{{$849}}}{{{$851}}}_0_-_4_:_-_
_>_6_3_:_;_
_(_>_6_ _
_>_8_:_1_ _
_:_)_:_1_ _,_
{{{$852}}}%{{{$761}}}{{{$762}}}{{{$763}}}{{{$764}}}{{{$756}}}{{{$757}}}{{{$760}}}{{{$765}}}SQLite format 3
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYthstndrd
CREATE TABLE sqlite_master(
sql text
3.7.16
CREATE TEMP TABLE sqlite_temp_master(
{{{$105}}}{{{$104}}}{{{$106}}}{{{$103}}}{{{$112}}}{{{$111}}}{{{$114}}}{{{$113}}}{{{$108}}}{{{$107}}}{{{$110}}}{{{$109}}}{{{$115}}}{{{$116}}}{{{$117}}}{{{$120}}}{{{$121}}}{{{$118}}}{{{$119}}}{{{$124}}}{{{$125}}}{{{$122}}}{{{$123}}}{{{$102}}}{{{$783}}}{{{$782}}}{{{$785}}}{{{$784}}}{{{$781}}}{{{$787}}}{{{$786}}}{{{$788}}}boost::too_few_args: format-string referred to more arguments than were passed
boost::too_many_args: format-string referred to less arguments than were passed
{{{$144}}}Content-Disposition: form-data; name="%s"
Content-Disposition: form-data; name="%s"; filename="%s"
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
API call with %s database connection pointer
922337203685477580
RowKey
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
GetProcessHeap
delayed %dms for lock/sharing conflict
%s-shm
%s\etilqs_
%s\%s
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
invalid page number %d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
2nd reference to page %d
Failed to read ptrmap key=%d
Page %d:
unable to get the page. error code=%d
failed to get page %d
freelist leaf count too big on page %d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Corruption detected in cell %d on page %d
Page %d is never used
Pointer map page %d is referenced
unknown database %s
Outstanding page count goes from %d to %d during this analysis
keyinfo(%d
%s(%d)
MJ delete: %s
MJ collide: %s
%s-mjXXXXXX9XXz
-mjX9X
foreign key constraint failed
bind on a busy prepared statement: [%s]
unable to use function %s in the requested context
zeroblob(%d)
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
abort at %d in [%s]: %s
cannot commit transaction - SQL statements in progress
no such savepoint: %s
cannot release savepoint - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
database table is locked: %s
statement aborts at %d: [%s] %s
cannot change %s wal mode from within a transaction
cannot open value of type %s
cannot open view: %s
no such column: "%s"
cannot open virtual table: %s
cannot open %s column for writing
foreign key
indexed
misuse of aliased aggregate %s
%s: %s
not authorized to use function: %s
%s: %s.%s.%s
%s: %s.%s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
variable number must be between ?1 and ?%d
too many SQL variables
Expression tree is too large (maximum depth %d)
too many columns in %s
EXECUTE %s%s SUBQUERY %d
%.*s"%w"%s
misuse of aggregate: %s()
sqlite_rename_trigger
sqlite_rename_parent
%s%.*s"%w"
sqlite_rename_table
type='trigger' AND (%s)
%s OR name=%Q
there is already another table or index with this name: %s
view %s may not be altered
sqlite_
table %s may not be altered
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_stat1
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
database %s is already in use
invalid name: "%s"
too many attached databases - max %d
unable to open database: %s
no such database: %s
database %s is locked
sqlite_detach
cannot detach database %s
access to %s.%s.%s is prohibited
sqlite_attach
%s %T cannot reference objects in database %s
access to %s.%s is prohibited
object name reserved for internal use: %s
too many columns on %s
duplicate column name: %s
there is already an index named %s
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
default value of column [%s] is not constant
table "%s" has more than one primary key
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
view %s is circularly defined
CREATE TABLE %Q.sqlite_sequence(name,seq)
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
sqlite_stat
table %s may not be dropped
unknown column "%s" in foreign key definition
indexed columns are not unique
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
table %s may not be indexed
views may not be indexed
index %s already exists
sqlite_autoindex_%s_%d
virtual tables may not be indexed
there is already a table named %s
table %s has no column named %s
no such index: %S
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
sqlite_version
sqlite_source_id
sqlite_compileoption_get
sqlite_log
sqlite_compileoption_used
foreign key mismatch - "%w" referencing "%w"
%d values for %d columns
table %S has no column named %s
table %S has %d columns but %d values were supplied
constraint %s failed
PRIMARY KEY must be unique
%s.%s may not be NULL
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
sqlite3_extension_init
error during initialization: %s
automatic extension loading failed: %s
foreign_keys
foreign_key_list
foreign_key_check
*** in database %s ***
unsupported encoding: %s
malformed database schema (%s)
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
%s - %s
database schema is locked: %s
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
unknown or unsupported join type: %T %T%s%T
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
%s.%s
%s:%d
COMPOUND SUBQUERIES %d AND %d %s(%s)
SELECTs to the left and right of %s do not have the same number of result columns
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
too many references to "%s": max 65535
%s.%s.%s
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
no such trigger: %S
-- TRIGGER %s
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')no such column: %s
PRAGMA vacuum_db.synchronous=OFF
cannot VACUUM - SQL statements in progress
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
vtable constructor failed: %s
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
no such module: %s
vtable constructor did not declare schema: %s
table %s: xBestIndex returned an invalid plan
%s TABLE %s
%s AS %s
%s SUBQUERY %d
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid>?)
%s (rowid<?)
%s (rowid=?)
%s (rowid>? AND rowid<?)
at most %d tables in a join
cannot use index: %s
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
unknown operation
large file support is disabled
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
cannot open file at line %d of [%.10s]
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
{{{$803}}}{{{$804}}}{{{$805}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\SearchProtector\Dev\2.19.0\Output\Release_32\CltMngSvc.pdb
WTSAPI32.dll
USERENV.dll
KERNEL32.dll
USER32.dll
ReportEventW
ADVAPI32.dll
SHELL32.dll
ole32.dll
OLEAUT32.dll
I_RpcBindingInqTransportType
RPCRT4.dll
PSAPI.DLL
VERSION.dll
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestW
HttpSendRequestA
HttpSendRequestExW
HttpEndRequestW
HttpQueryInfoA
WININET.dll
CryptMsgClose
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CRYPT32.dll
dbghelp.dll
GetCPInfo
RegCloseKey
RegOpenKeyExW
RegDeleteKeyW
RegEnumKeyExW
RegCreateKeyExW
RegNotifyChangeKeyValue
RegSaveKeyExW
RegRestoreKeyW
ReportEventA
zcÁ
C:\PROGRA~1\SearchProtect\
;74/, (%#
~{xrpfa\ZSM@;3-%Ufunction k(a) { return a < 10 ? "0" a : a } function o(a) { p.lastIndex = 0; return p.test(a) ? '"' a.replace(p, function (a) { var c = r[a]; return typeof c === "string" ? c : "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) }) '"' : '"' a '"' } function l(a, j) {var c, d, h, m, g = e, f, b = j[a]; b && typeof b === "object" && typeof b.toJSON === "function" && (b = b.toJSON(a)); typeof i === "function" && (b = i.call(j, a, b)); switch (typeof b) {e = n; f = []; if (Object.prototype.toString.apply(b) === "[object Array]") { m = b.length; for (c = 0; c < m; c = 1) f[c] = l(c, b) || "null"; h = f.length === 0 ? "[]" : e ? "[\n" e f.join(",\n" e) "\n" g "]" : "[" f.join(",") "]"; e = g; return h } if (i && typeof i === "object") { m = i.length; for (c = 0; c < m; c = 1) typeof i[c] === "string" && (d = i[c], (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h)) } else for (d in b) Object.prototype.hasOwnProperty.call(b, d) && (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h); h = f.length === 0 ? "{}" : e ? "{\n" e f.join(",\n" e) "\n" g "}" : "{" f.join(",") } if (typeof Date.prototype.toJSON !== "function") Date.prototype.toJSON = function () { return isFinite(this.valueOf()) ? this.getUTCFullYear() "-" k(this.getUTCMonth() 1) "-" k(this.getUTCDate()) "T" k(this.getUTCHours()) ":" k(this.getUTCMinutes()) ":" k(this.getUTCSeconds()) "Z" : null }, String.prototype.toJSON = Number.prototype.toJSON = Boolean.prototype.toJSON = function () { return this.valueOf() }; var q = /[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,p = /[\\\"\x00-\x1f\x7f-\x9f\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g, e, n, r = { "\u0008": "\\b", "\t": "\\t", "\n": "\\n", "\u000c": "\\f", "\r": "\\r", '"': '\\"', "\\": "\\\\" }, i; if (typeof JSON.stringify !== "function") JSON.stringify = function (a, j, c) {var d; n = e = ""; if (typeof c === "number") for (d = 0; d < c; d = 1) n = " "; else typeof c === "string" && (n = c); if ((i = j) && typeof j !== "function" && (typeof j !== "object" || typeof j.length !== "number")) throw Error("JSON.stringify"); return l("",}; if (typeof JSON.parse !== "function") JSON.parse = function (a, e) {function c(a, d) { var g, f, b = a[d]; if (b && typeof b === "object") for (g in b) Object.prototype.hasOwnProperty.call(b, g) && (f = c(b, g), f !== void 0 ? b[g] = f : delete b[g]); return e.call(a, d, b) } var d, a = String(a); q.lastIndex = 0; q.test(a) && (a = a.replace(q, function (a) { return "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) })); if (/^[\],:{}\s]*$/.test(a.replace(/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g, "@").replace(/"[^"\\\n\r]*"|true|false|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,"]").replace(/(?:^|:|,)(?:\s*\[) /g, ""))) return d = eval("(" a ")"), typeof e === "function" ? c({ "": d }, "") : d; throw new SyntaxError("JSON.parse");ws.api = ws.api || {};ws.api.FunctionsEnum = {SET_KEY: 1,
GET_KEY: 2,
REMOVE_KEY: 3,
ws.api.StatusEnum = {SP_RESULT_KEY_DOES_NOT_EXIST: -2,
ws.api.RESULT_TIMOUET = 3000;
ws.api.storage = ws.api.storage || {};ws.api.storage.setKey =
function (pluginId, key, value, callback, options) {if (typeof (pluginId) !== 'string' || pluginId === "" || typeof (key) !== 'string' || key === "" || typeof (callback) !== 'function') {callback(ws.api.StatusEnum.SP_RESULT_INVALID_PARAMS);
// Construct an object which will be passed to the VC holding all the parameters
data.funcId = ws.api.FunctionsEnum.SET_KEY;
data.pluginId = pluginId;
data.key = key;
data.value = value;
data.options = options; // Currently not used - this is for future use, if we will want to add more parameters we will
var resultObj = JSON.parse(result);
callback(resultObj.status);
callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE);
}, ws.api.RESULT_TIMOUET);
ws.internal.SendStringToVC(JSON.stringify(data), myCallback);
ws.api.storage.getKey =
function (pluginId, key, callback, options) {data.funcId = ws.api.FunctionsEnum.GET_KEY;
var value = resultObj.value;
if (resultObj.status != ws.api.StatusEnum.SP_RESULT_SUCCESS) {callback(resultObj.status, value);
callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE, "");
ws.api.storage.removeKey =
data.funcId = ws.api.FunctionsEnum.REMOVE_KEY;
ws.api.system = ws.api.system || {};ws.api.system.remove =
data.funcId = ws.api.FunctionsEnum.REMOVE;
data.shouldCallUninstaller = shouldCallUninstaller;
ws.internal = ws.internal || {};if (ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID === undefined) {ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID = true;
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><description>Perion Search protect 2.19.0.260</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
5 5$5(5,5
0$1(1,1014181!2
9Ÿ9a9q9
444`4$5 5[5
6$6-666d6k6t6}6
9 9$9(9,9094989<9@9[9
8„8C8d8v8
343C3R3a3p3
8„8C8R8a8p8
:):0:;:[:
3%3,373\3
>(?,?0?4?
11
5)5/585>5[5
=$=-=4=~=
< <$<(<,<
7%7U7
0 0$0(0,0
= =$=(=,=0=4=~=
> >?>_>~>
;,;0;4;8;<;@;
9 9$9(9,9094989<9
3 3$3(3,3034383<3@3
8 8$8(8,80848
8 8$8(8,8084888<8
=4=8=<=@=
; ;$;(;,;0;4;
9(:,:\:`:
= =$=,=4=8=<=
= =$=(=,=0=4=8=<=
3 3$3(3,3034383
1,181@1`1|1
7 7@7\7`7
mmscoree.dll
Xkernel32.dll
combase.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
{{{$711}}}Failed to execute installer :
Setup.exe
}%s (Error: %d)
*.dmp
{{{$1210}}}{{{$1213}}}{{{$1281}}}{{{$1280}}}WindowsSessionManagerThread
2.19.0.260
UserRepository.dat
UIRepository.dat
SystemRepository.dat
{{{$694}}}{{{$411}}}{{{$410}}}_0.localstorage
chrome-extension_
{{{$275}}}{{{$276}}};{{{$278}}}{{{$279}}}36.0.0.0
32.0.0.0
{{{$329}}}{{{$328}}}{{{$332}}}{{{$331}}}{{{$334}}}{{{$335}}}Failed to set Url
{{{$341}}}{{{$342}}}{{{$343}}}{{{$344}}}{{{$345}}}{{{$347}}}{{{$348}}}{{{$354}}}{{{$355}}}{{{$359}}}{{{$360}}}{{{$363}}}V36.0.0.0
{{{$367}}}{{{$368}}}{{{$370}}}{{{$371}}}{{{$382}}}{{{$383}}}{{{$388}}}{{{$389}}}{{{$392}}}{{{$393}}}{{{$396}}}{{{$397}}}{{{$400}}}{{{$399}}}{{{$424}}}{{{$425}}}{{{$422}}}{{{$414}}}{{{$413}}}{{{$412}}}HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_NLSTEXT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_CURRENT_USER_LOCAL_SETTINGS
{{{$807}}}user32.dll
ieframe.dll
Windows Vista
Windows Server 2008
Windows 8
Windows Server 2012
Windows 8.1
Windows 7
Windows Server 2008 R2
Not supported
Windows Home Server 2011
Windows Essential Server Solution Additional
Windows Essential Server Solution Management SVC
Windows Small Business Server
Windows Essential Server Solution Additional SVC
Windows Essential Server Solution Management
Windows MultiPoint Server
Windows Storage Server 2008 R2 Essentials
Windows Essential Business Server Management Server
Windows Essential Business Server Messaging Server
Windows Essential Business Server Security Server
Windows Small Business Server 2011 Essentials
Windows Server 2008 for Windows Essential Server Solutions
Windows Server 2008 without Hyper-V for Windows Essential Server Solutions
Web Server (full installation)
Web Server (core installation)
%x %x[%s] %I64x %x %x
{{{$798}}}{{{$797}}}TargetInstance.Name
ySELECT * FROM Win32_OperatingSystem
ntdll.dll
%s%s%s
Correct password required
{{{$820}}}{{{$766}}}888816666554443
6666554443
!6666554443
HIDispatch error #%d
01234567
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe
cltmng.exe_3112:
.text
`.rdata
@.data
.rsrc
@.reloc
SHA256 block transform for x86, CRYPTOGAMS by <[email protected]>
SHA1 block transform for x86, CRYPTOGAMS by <[email protected]>
.EKSWU
DlSHA512 block transform for x86, CRYPTOGAMS by <[email protected]>
\$$;\$0|
Montgomery Multiplication for x86, CRYPTOGAMS by <[email protected]>
6-9'6-9'
$6.:$6.:
*?#1*?#1
>8$4,8$4,
AES for x86, CRYPTOGAMS by <[email protected]>
FtPS
GF(2^m) Multiplication for x86, CRYPTOGAMS by <[email protected]>
Camellia for x86 by <[email protected]>
AES for Intel AES-NI, CRYPTOGAMS by <[email protected]>
RC4 for x86, CRYPTOGAMS by <[email protected]>
GHASH for x86, CRYPTOGAMS by <[email protected]>
[email protected]
t;j.Yf
j.Xf9
!\$0!\$4
<1%u5
FTPj
tCPQ
,4,56,789
PSSSSSSh
FTPj
F\ FTP
j.Yf;
_tcPVj@
.PjRW
r%f;M
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
0123456789-
%b %d %H : %M : %S %Y
%m / %d / %y
%I : %M : %S %p
%d / %m / %y
kernel32.dll
boost::filesystem::directory_iterator::operator
The repeat operator "*" cannot start a regular expression.
The repeat operator "?" cannot start a regular expression.
The repeat operator " " cannot start a regular expression.
Found a closing repetition operator } with no corresponding {.Can't terminate a sub-expression with an alternation operator |.
The \c and \C escape sequences are not supported by POSIX basic regular expressions: try the Perl syntax instead.
A regular expression can start with the alternation operator |.
Invalid alternation operators within (?...) block.
More than one alternation operator | was encountered inside a conditional expression.
Alternation operators are not allowed inside a DEFINE block.
A repetition operator cannot be applied to a zero-width assertion.
left-curly-bracket
right-curly-bracket
0123456789
Unmatched quantified repeat operator { or \{.Invalid preceding regular expression prior to repetition operator.
boost thread: trying joining itself
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flagVisual C CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
operator
GetProcessWindowStation
len>=0 && len<=(int)sizeof(ctx->key)
j <= (int)sizeof(ctx->key)
SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013
SHA1 part of OpenSSL 1.0.1e 11 Feb 2013
ssl_sess_cert
ssl_cert
evp_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013
passed a null parameter
DSO support routines
x509 certificate routines
Stack part of OpenSSL 1.0.1e 11 Feb 2013
Any Extended Key Usage
anyExtendedKeyUsage
supportedAlgorithms
crossCertificatePair
certificateRevocationList
cACertificate
userCertificate
userPassword
supportedApplicationContext
Microsoft Local Key set
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
certificateIssuer
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
hexkey
rsa_keygen_pubexp
rsa_keygen_bits
lhash part of OpenSSL 1.0.1e 11 Feb 2013
ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013
Big Number part of OpenSSL 1.0.1e 11 Feb 2013
%d.%d.%d.%d
EC part of OpenSSL 1.0.1e 11 Feb 2013
ECDSA part of OpenSSL 1.0.1e 11 Feb 2013
.\crypto\ec\ec_key.c
priv_key
pub_key
DSA part of OpenSSL 1.0.1e 11 Feb 2013
Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013
.\crypto\dh\dh_key.c
RSA part of OpenSSL 1.0.1e 11 Feb 2013
value.single
value.set
RAND part of OpenSSL 1.0.1e 11 Feb 2013
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
keylen <= sizeof key
EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)
EVP part of OpenSSL 1.0.1e 11 Feb 2013
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
ECDH part of OpenSSL 1.0.1e 11 Feb 2013
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
d.receiptList
d.allOrFirstTier
d.compressedData
d.authenticatedData
d.encryptedData
d.digestedData
d.envelopedData
d.signedData
d.data
d.ori
d.pwri
d.kekri
d.kari
d.ktri
CMS_PasswordRecipientInfo
keyDerivationAlgorithm
keyIdentifier
CMS_KeyAgreeRecipientInfo
recipientEncryptedKeys
CMS_OriginatorIdentifierOrKey
d.originatorKey
CMS_OriginatorPublicKey
publicKey
CMS_RecipientEncryptedKey
CMS_KeyAgreeRecipientIdentifier
d.rKeyId
CMS_RecipientKeyIdentifier
CMS_OtherKeyAttribute
keyAttr
keyAttrId
CMS_KeyTransRecipientInfo
encryptedKey
keyEncryptionAlgorithm
certificates
d.crl
d.subjectKeyIdentifier
d.issuerAndSerialNumber
CMS_CertificateChoices
d.other
d.v2AttrCert
d.v1AttrCert
d.extendedCertificate
d.certificate
CMS_OtherCertificateFormat
otherCert
otherCertFormat
AES part of OpenSSL 1.0.1e 11 Feb 2013
%s: (%d bit)
Public-Key
Private-Key
recommended-private-length: %d bits
public-key:
private-key:
PKCS#3 DH Public-Key
PKCS#3 DH Private-Key
Public-Key: (%d bit)
Private-Key: (%d bit)
USER32.DLL
NETAPI32.DLL
KERNEL32.DLL
ADVAPI32.DLL
keylength
keyfunc
.\crypto\pkcs12\p12_key.c
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
CONF part of OpenSSL 1.0.1e 11 Feb 2013
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
name.relativename
name.fullname
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
%*s%s:
%*sOnly Attribute Certificates
%*sOnly CA Certificates
%*sOnly User Certificates
%d.%d.%d.%d/%d.%d.%d.%d
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
keyid
.\crypto\x509v3\v3_akey.c
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
%*sCPS: %s
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
pubkey
cert_info
X.509 part of OpenSSL 1.0.1e 11 Feb 2013
PROXY_CERT_INFO_EXTENSION
EC_PRIVATEKEY
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
x%s
Basis Type: %s
Field Type: %s
ASN1 OID: %s
%s %s%lu (%s0x%lx)
%s - d:d:d%.*s %d%s
\X
'() ,-./:=?
CONF_def part of OpenSSL 1.0.1e 11 Feb 2013
[[%s]]
[%s] %s=%s
MD5 part of OpenSSL 1.0.1e 11 Feb 2013
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
certs
AUTHORITY_KEYID
enc_key
key_enc_algor
cert
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
X509_CERT_PAIR
X509_CERT_AUX
PEM part of OpenSSL 1.0.1e 11 Feb 2013
ddddddZ
ddddddZ
value.bag
value.safes
value.shkeybag
value.keybag
value.sdsicert
value.x509cert
value.other
%s.dll
?456789:;<=
!"#$%&'()* ,-./0123
Verifying - %s
NETSCAPE_CERT_SEQUENCE
RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013
SHA part of OpenSSL 1.0.1e 11 Feb 2013
MD4 part of OpenSSL 1.0.1e 11 Feb 2013
CAST part of OpenSSL 1.0.1e 11 Feb 2013
Blowfish part of OpenSSL 1.0.1e 11 Feb 2013
:RC2 part of OpenSSL 1.0.1e 11 Feb 2013
.pp@0
aEÐ
(#EÚ
ÚE<<0
IDEA part of OpenSSL 1.0.1e 11 Feb 2013
libdes part of OpenSSL 1.0.1e 11 Feb 2013
DES part of OpenSSL 1.0.1e 11 Feb 2013
%T%D%Q%W%J%S%L%B%J%
%F%J%H%
p%K%N%K%J%R%K%d%V%V%@%Q%v%Q%D%Q%@%
d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp
{{{$712}}}{{{$865}}}{{{$866}}}{{{$867}}}{{{$868}}}0c3c.cCcNcCc.c
{{{$871}}}{{{$872}}}{{{$536}}}{{{$543}}}{{{$546}}}{{{$548}}}{{{$452}}}{{{$455}}}{{{$458}}}{{{$471}}}{{{$472}}}D D>D-D(D(D%D
{{{$447}}}{{{$448}}}{{{$449}}}|[|!|'|<|
CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);
insert into ItemTable (key, value) VALUES ('%s', '%s');_0_<_>_3_
_ _>_ _:_
,D D)D!D4D%D#D!D
D*D!D3D0D%D&D4D%D#D!D
_0_1_9_6_-_2_
_'_ _:_1_,_6_0_1_
{{{$350}}}{{{$351}}}{{{$352}}}{{{$372}}}{{{$401}}}{{{$402}}}{{{$403}}}{{{$404}}}^1^1^9^2^;^
^6^,^1^3^;^
^-^;^,^~^
g%W%D%K%A%v%@%Q%Q%L%K%B%V%
' ).;<52
\StringFileInfo\xx\%s
(more frames truncated from call stack report)
Module %d
%d/%d/%d d:d:d
Image Base: 0xx Image Size: 0xx
File Size: %-10d File Time: %s
Checksum: 0xx Time Stamp: 0xx
Company: %s
FileDesc: %s
Product: %s
ProdVer: %d.%d.%d.%d
FileVer: %d.%d.%d.%d
Windows Vista
Windows 7
Windows Server 2008
Windows 8
Windows Server 2008 R2
Windows 9
Web Edition
Windows Server 2012
Windows XP
Windows Server 9
Windows 2000
(build %d)
This sample does not support this version of Windows.
Error occurred at %s.
Operating system: %s
%d processor(s), type %d.
Operating system: Could not Determine
%d%% memory in use.
%d MBytes paging file.
%d MBytes physical memory free.
%d MBytes user address space free.
%d MBytes user address space.
Web Server Edition
Windows Storage Server 2003
Windows Server 2003 R2
Windows XP Professional x64 Edition
Windows Home Server
Windows Server 2003
a Float Denormal Operand
%d MBytes paging file free.
a Float Invalid Operation
%d MBytes physical memory.
0xx:
EDI: 0xx ESI: 0xx EAX: 0xx
EIP: 0xx EBP: 0xx SegCs: 0xx
EBX: 0xx ECX: 0xx EDX: 0xx
%s\CRASH_REPORT_%s.txt
EFlags: 0xx ESP: 0xx SegSs: 0xx
%s caused %s (0xx)
in module %s at x:x.
%s location x caused an access violation.
%s\CRASH_DUMP_%s.dmp
===== [end of %s] =====
Error creating dump file, err=%d
Exception code is 0xX
Crash dump file: %s
Crash report file :%s
P%d_T%d_Dld_ld_ld_Tld_ld_ld
code: %x
code: %x, addr: %x, module: %s
^ ^,^,^;^0^*^
^;^,^-^7^1^0^
{{{$715}}}{{{$717}}}{{{$716}}}{{{$718}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h
NtQueryKey
{{{$703}}}{{{$704}}}{{{$702}}}{{{$707}}}{{{$708}}}{{{$705}}}{{{$706}}}{{{$709}}}{{{$710}}}{{{$790}}}{{{$793}}}{{{$791}}}{{{$792}}}%s 0x%I64x %s [file:%s(%u)]
hXXp://
hXXps://
PTF://
wininet.dll
[%u, 0xx] %s
https
HTTP/1.0
Content-Type: application/x-www-form-urlencoded
request HttpSendRequestA failed...
Content-Length: %u
response failed...last error %d
{{{$756}}}{{{$761}}}{{{$762}}}{{{$757}}}{{{$760}}}{{{$765}}}{{{$763}}}{{{$764}}}{{{$875}}}{{{$876}}}{{{$874}}}{{{$877}}}v%u%h%
%v%u%h%
{{{$1070}}}{{{$1069}}}]/]2] ]4]9]8]/]
{{{$994}}}{{{$993}}}u&u%u
PHIWTLUW6SYUN1TXAX3ZQMPMN9QM7ZD3QFJ25XMZL24NQUDO50B6VN8R3VJOKAP6YXXKVITITUV7VSSHFA385Q4MVX83SLA35RTVT0RKXS7D0HL81ILSSH17VNAHQVNDGBS3RQ8CJKBE
K8YD7KOT1MEVRRN8ACURL5VW9ZLBMF
]/]/]2]/]
]2]1]4]>]$]
]<]3]<]:]8]/]}]`]`]}]3](]1]1]-])]/]
\=\.\2\5\2\;\
{{{$880}}}{{{$881}}}{{{$1103}}}{{{$1102}}}\9\.\/\5\3\2\
D×D0D
9]<])]<]0]3]
{{{$861}}}{{{$863}}}{{{$862}}}{{{$864}}}8{7{/{6{5{<{${({6{${8{7{({//6.0!?.:%<,
1'7&=$ ;&
9!0!6*3&
*3 :)) :
<<$=,=*6/:
<<,=)6/?
<<,=*6/3
<6/<<<&55<&
22 3"3$8!4
22"3'8!1
22"3$8!=
28!222(;;2(
,,5-3"<-9&?/
,,<-:&?#
,,<.(%<-::
,&?,,_,6
33*2;#2&9 0
33#2&9 <
33#17:#2%%
39 33@3)
00)18 1%:#3
00 1&:#?
2*4%;*>!8(
22 3:"3'8!1
22"3'8!=
lTU@CMDi@OEMDaww@MTDakraaa
/%<///%<///5
$.7$$=%;*4%1.7'
$$4%2[@,
//6.'?.:%<,
>>'?.?(4-1
ovz`SDIPDQ@vFWLUQee|dzkudpovfJKQ@]Qees
33*2#2%9 <
33#2&9 0
lTU@CMDi@OEMDaq`wkrnCKDBUaaa
??&>7/>*5,<
?5,??/>/>)5,0
77.6(9'6"=$4
==$<5-<(7.>
=7.==-<-<(7.2
75(9*,5=6,
33#2%9 <
..7/1 >/;$=-
..>/8$=!
.$=...$=...4
39 33*2,=#2&9 0
99 8&7)8,3*:
99)8/3*6
??&> 1/>*5,<
;;":$5 :.1(8
!!8 >/1 4 2"
v%J%C%Q%R%D%W%@%y%d%U%U%a%D%Q%D%i%J%R%y%v%J%C%Q%R%D%W%@%y%v%H%D%W%Q%g%D%W%y%f%w%
[5[4[,[5[
[:[)[)[2[>[)[
[([:[<[>[
:_'_ _:_1_,_6_0_1_
L%K%V%Q%D%I%I%z%Q%\%U%@%
p%V%@%W%f%M%D%K%B%@%
spx.params
spx.assets
\>\.\3\ \/\9\.\
SQLite format 3
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY_\
CREATE TABLE sqlite_master(
sql text
3.7.16
CREATE TEMP TABLE sqlite_temp_master(
{{{$103}}}{{{$104}}}{{{$108}}}{{{$109}}}{{{$110}}}{{{$111}}}{{{$105}}}{{{$106}}}{{{$107}}}{{{$112}}}{{{$113}}}{{{$114}}}{{{$115}}}{{{$102}}}{{{$117}}}{{{$118}}}{{{$119}}}{{{$116}}}{{{$122}}}{{{$120}}}{{{$121}}}{{{$123}}}{{{$124}}}{{{$125}}}{{{$625}}}{{{$624}}}{{{$611}}}{{{$612}}}{{{$613}}}{{{$616}}}{{{$617}}}{{{$618}}}{{{$619}}}{{{$614}}}{{{$615}}}{{{$620}}}{{{$621}}}{{{$623}}}{{{$262}}}{{{$261}}}{{{$648}}}{{{$647}}}{{{$652}}}{{{$651}}}{{{$653}}}{{{$649}}}{{{$650}}}{{{$656}}}{{{$655}}}{{{$658}}}{{{$657}}}{{{$654}}}{{{$660}}}{{{$662}}}{{{$661}}}{{{$659}}}{{{$664}}}{{{$665}}}{{{$663}}}{{{$667}}}{{{$666}}}{{{$670}}}{{{$668}}}{{{$669}}}{{{$673}}}{{{$674}}}{{{$671}}}{{{$677}}}{{{$676}}}{{{$680}}}{{{$678}}}{{{$679}}}{{{$682}}}{{{$683}}}{{{$681}}}{{{$685}}}{{{$684}}}{{{$688}}}{{{$686}}}{{{$687}}}{{{$690}}}{{{$691}}}{{{$689}}}{{{$693}}}{{{$692}}}0c3c.cCcNcCc!c
]2]2])].])]/]<]-]8]/]}]
]8]:]4].])]8]/]
]/]2]*].]8]/]
]4];]8])]4]0]8]
{{{$592}}}{{{$596}}}{{{$594}}}{{{$593}}}{{{$595}}}{{{$597}}}{{{$600}}}{{{$599}}}{{{$598}}}{{{$601}}}{{{$602}}}{{{$604}}}{{{$603}}}{{{$606}}}{{{$605}}}F4F)F'F"F%F'F5F2F
{{{$607}}}{{{$608}}}{{{$609}}}{{{$610}}}{{{$696}}}{{{$698}}}{{{$697}}}{{{$700}}}{{{$699}}}{{{$701}}}{{{$823}}}{{{$822}}}{{{$824}}}{{{$825}}}{{{$826}}}@'@%@.@4@
@/@)@.@`@7@!@)@4@)@.@'@`@&@/@2@`@
@/@.@%@`@
@%@3@0@/@.@3@%@}@
{{{$829}}}{{{$828}}}{{{$827}}}{{{$830}}}{{{$832}}}{{{$831}}}{{{$834}}}{{{$833}}}{{{$835}}}{{{$837}}}{{{$836}}}{{{$839}}}{{{$840}}}{{{$838}}}{{{$848}}}{{{$847}}}{{{$849}}}_0_-_4_:_-_
_>_6_3_:_;_
_(_>_6_ _
_>_8_:_1_ _
_:_)_:_1_ _,_
{{{$852}}}{{{$851}}}00:00:00.
@2@#@(@)@4@%@#@4@5@2@%@
{{{$724}}}{{{$729}}}{{{$726}}}{{{$725}}}{{{$728}}}{{{$727}}}1.1.3
gen_codes: max_code %d
code %d bits %d->%d
bl code -
last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)
opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u
{{{$145}}}{{{$146}}}{{{$149}}}{{{$148}}}{{{$150}}}{{{$147}}}{{{$154}}}{{{$153}}}{{{$156}}}{{{$155}}}{{{$127}}}{{{$126}}}{{{$131}}}{{{$128}}}{{{$137}}}{{{$136}}}{{{$138}}}{{{$133}}}{{{$132}}}{{{$135}}}{{{$134}}}{{{$141}}}boost::too_many_args: format-string referred to less arguments than were passed
boost::too_few_args: format-string referred to more arguments than were passed
Union operator has to be applied to node sets
Content-Disposition: form-data; name="%s"; filename="%s"
Content-Disposition: form-data; name="%s"
invalid map<K, T> key
SQLITE_OK
%s[%d]: %s
SQLITE_PERM
SQLITE_ABORT
SQLITE_ERROR
SQLITE_INTERNAL
SQLITE_NOMEM
SQLITE_READONLY
SQLITE_BUSY
SQLITE_LOCKED
SQLITE_CORRUPT
SQLITE_NOTFOUND
SQLITE_INTERRUPT
SQLITE_IOERR
SQLITE_PROTOCOL
SQLITE_EMPTY
SQLITE_FULL
SQLITE_CANTOPEN
SQLITE_CONSTRAINT
SQLITE_MISMATCH
SQLITE_SCHEMA
SQLITE_TOOBIG
SQLITE_AUTH
SQLITE_FORMAT
SQLITE_MISUSE
SQLITE_NOLFS
SQLITE_DONE
CPPSQLITE_ERROR
SQLITE_RANGE
SQLITE_ROW
SQLITE_
d:d:d
d-d-d
d-d-d d:d:d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
RowKey
GetProcessHeap
delayed %dms for lock/sharing conflict
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
%s-shm
%s\etilqs_
%s\%s
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
2nd reference to page %d
Failed to read ptrmap key=%d
invalid page number %d
failed to get page %d
freelist leaf count too big on page %d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
btreeInitPage() returns error code %d
On tree page %d cell %d:
Page %d:
unable to get the page. error code=%d
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Outstanding page count goes from %d to %d during this analysis
Page %d is never used
Pointer map page %d is referenced
unknown database %s
keyinfo(%d
%s(%d)
%s-mjXXXXXX9XXz
-mjX9X
foreign key constraint failed
MJ delete: %s
MJ collide: %s
unable to use function %s in the requested context
zeroblob(%d)
bind on a busy prepared statement: [%s]
abort at %d in [%s]: %s
no such savepoint: %s
cannot release savepoint - SQL statements in progress
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
sqlite_temp_master
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open virtual table: %s
cannot open value of type %s
foreign key
indexed
cannot open view: %s
no such column: "%s"
misuse of aliased aggregate %s
cannot open %s column for writing
%s: %s.%s.%s
%s: %s.%s
%s: %s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
too many columns in %s
variable number must be between ?1 and ?%d
too many SQL variables
misuse of aggregate: %s()
EXECUTE %s%s SUBQUERY %d
%s%.*s"%w"
sqlite_rename_table
%.*s"%w"%s
%s OR name=%Q
sqlite_rename_trigger
sqlite_rename_parent
sqlite_
table %s may not be altered
type='trigger' AND (%s)
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
there is already another table or index with this name: %s
view %s may not be altered
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
sqlite_altertab_%s
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
database %s is already in use
cannot detach database %s
unable to open database: %s
no such database: %s
sqlite_attach
%s %T cannot reference objects in database %s
database %s is locked
sqlite_detach
access to %s.%s is prohibited
access to %s.%s.%s is prohibited
there is already an index named %s
object name reserved for internal use: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
too many columns on %s
duplicate column name: %s
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE TABLE %Q.sqlite_sequence(name,seq)
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
view %s is circularly defined
sqlite_stat
table %s may not be dropped
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
unknown column "%s" in foreign key definition
indexed columns are not unique
virtual tables may not be indexed
there is already a table named %s
table %s may not be indexed
views may not be indexed
table %s has no column named %s
index %s already exists
sqlite_autoindex_%s_%d
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
no such index: %S
a JOIN clause is required before %s
table %s may not be modified
cannot modify %s because it is a view
unable to identify the object to be reindexed
no such collation sequence: %s
sqlite_log
sqlite_compileoption_used
sqlite_version
sqlite_source_id
sqlite_compileoption_get
table %S has %d columns but %d values were supplied
foreign key mismatch - "%w" referencing "%w"
%s.%s may not be NULL
%d values for %d columns
table %S has no column named %s
constraint %s failed
PRIMARY KEY must be unique
sqlite3_extension_init
error during initialization: %s
automatic extension loading failed: %s
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
foreign_keys
foreign_key_list
foreign_key_check
*** in database %s ***
unsupported encoding: %s
%s - %s
malformed database schema (%s)
database schema is locked: %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unknown or unsupported join type: %T %T%s%T
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
COMPOUND SUBQUERIES %d AND %d %s(%s)
USE TEMP B-TREE FOR %s
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
%s.%s
%s:%d
no such index: %s
sqlite_subquery_%p_
SELECTs to the left and right of %s do not have the same number of result columns
no such table: %s
too many references to "%s": max 65535
%s.%s.%s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
no such column: %s
no such trigger: %S
-- TRIGGER %s
cannot VACUUM - SQL statements in progress
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
PRAGMA vacuum_db.synchronous=OFF
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
vtable constructor did not declare schema: %s
vtable constructor failed: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s SUBQUERY %d
%s TABLE %s
%s AS %s
%s (rowid=?)
%s (rowid>? AND rowid<?)
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
%s (rowid>?)
%s (rowid<?)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
unknown operation
large file support is disabled
unknown database: %s
%s mode not allowed: %s
no such vfs: %s
no such %s mode: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
#@,@)@%@.@4@6@%@2@3@)@/@.@
S2S:S?S6S7SsS'S<SsS4S<SsS<S&S'SsS5S<S!SsS2SsS S6S!S%S:S0S6SsSiS
{{{$804}}}{{{$805}}}{{{$803}}}{{{$144}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\SearchProtector\Dev\2.19.0\Output\Release_32\cltmng.pdb
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
VERSION.dll
PSAPI.DLL
InternetCrackUrlW
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestW
HttpSendRequestA
HttpSendRequestExW
HttpEndRequestW
HttpQueryInfoA
WININET.dll
dbghelp.dll
CryptMsgClose
CertGetNameStringW
CertFreeCertificateContext
CertFindCertificateInStore
CertCloseStore
CryptMsgGetParam
CRYPT32.dll
UrlUnescapeW
SHLWAPI.dll
CreateIoCompletionPort
GetCPInfo
RegCloseKey
RegOpenKeyExW
RegDeleteKeyW
RegEnumKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegNotifyChangeKeyValue
ReportEventA
ADVAPI32.dll
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
I_RpcBindingInqTransportType
RPCRT4.dll
zcÁ
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect
;74/, (%#
~{xrpfa\ZSM@;3-%Ufunction k(a) { return a < 10 ? "0" a : a } function o(a) { p.lastIndex = 0; return p.test(a) ? '"' a.replace(p, function (a) { var c = r[a]; return typeof c === "string" ? c : "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) }) '"' : '"' a '"' } function l(a, j) {var c, d, h, m, g = e, f, b = j[a]; b && typeof b === "object" && typeof b.toJSON === "function" && (b = b.toJSON(a)); typeof i === "function" && (b = i.call(j, a, b)); switch (typeof b) {e = n; f = []; if (Object.prototype.toString.apply(b) === "[object Array]") { m = b.length; for (c = 0; c < m; c = 1) f[c] = l(c, b) || "null"; h = f.length === 0 ? "[]" : e ? "[\n" e f.join(",\n" e) "\n" g "]" : "[" f.join(",") "]"; e = g; return h } if (i && typeof i === "object") { m = i.length; for (c = 0; c < m; c = 1) typeof i[c] === "string" && (d = i[c], (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h)) } else for (d in b) Object.prototype.hasOwnProperty.call(b, d) && (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h); h = f.length === 0 ? "{}" : e ? "{\n" e f.join(",\n" e) "\n" g "}" : "{" f.join(",") } if (typeof Date.prototype.toJSON !== "function") Date.prototype.toJSON = function () { return isFinite(this.valueOf()) ? this.getUTCFullYear() "-" k(this.getUTCMonth() 1) "-" k(this.getUTCDate()) "T" k(this.getUTCHours()) ":" k(this.getUTCMinutes()) ":" k(this.getUTCSeconds()) "Z" : null }, String.prototype.toJSON = Number.prototype.toJSON = Boolean.prototype.toJSON = function () { return this.valueOf() }; var q = /[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,p = /[\\\"\x00-\x1f\x7f-\x9f\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g, e, n, r = { "\u0008": "\\b", "\t": "\\t", "\n": "\\n", "\u000c": "\\f", "\r": "\\r", '"': '\\"', "\\": "\\\\" }, i; if (typeof JSON.stringify !== "function") JSON.stringify = function (a, j, c) {var d; n = e = ""; if (typeof c === "number") for (d = 0; d < c; d = 1) n = " "; else typeof c === "string" && (n = c); if ((i = j) && typeof j !== "function" && (typeof j !== "object" || typeof j.length !== "number")) throw Error("JSON.stringify"); return l("",}; if (typeof JSON.parse !== "function") JSON.parse = function (a, e) {function c(a, d) { var g, f, b = a[d]; if (b && typeof b === "object") for (g in b) Object.prototype.hasOwnProperty.call(b, g) && (f = c(b, g), f !== void 0 ? b[g] = f : delete b[g]); return e.call(a, d, b) } var d, a = String(a); q.lastIndex = 0; q.test(a) && (a = a.replace(q, function (a) { return "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) })); if (/^[\],:{}\s]*$/.test(a.replace(/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g, "@").replace(/"[^"\\\n\r]*"|true|false|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,"]").replace(/(?:^|:|,)(?:\s*\[) /g, ""))) return d = eval("(" a ")"), typeof e === "function" ? c({ "": d }, "") : d; throw new SyntaxError("JSON.parse");ws.api = ws.api || {};ws.api.FunctionsEnum = {SET_KEY: 1,
GET_KEY: 2,
REMOVE_KEY: 3,
ws.api.StatusEnum = {SP_RESULT_KEY_DOES_NOT_EXIST: -2,
ws.api.RESULT_TIMOUET = 3000;
ws.api.storage = ws.api.storage || {};ws.api.storage.setKey =
function (pluginId, key, value, callback, options) {if (typeof (pluginId) !== 'string' || pluginId === "" || typeof (key) !== 'string' || key === "" || typeof (callback) !== 'function') {callback(ws.api.StatusEnum.SP_RESULT_INVALID_PARAMS);
// Construct an object which will be passed to the VC holding all the parameters
data.funcId = ws.api.FunctionsEnum.SET_KEY;
data.pluginId = pluginId;
data.key = key;
data.value = value;
data.options = options; // Currently not used - this is for future use, if we will want to add more parameters we will
var resultObj = JSON.parse(result);
callback(resultObj.status);
callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE);
}, ws.api.RESULT_TIMOUET);
ws.internal.SendStringToVC(JSON.stringify(data), myCallback);
ws.api.storage.getKey =
function (pluginId, key, callback, options) {data.funcId = ws.api.FunctionsEnum.GET_KEY;
var value = resultObj.value;
if (resultObj.status != ws.api.StatusEnum.SP_RESULT_SUCCESS) {callback(resultObj.status, value);
callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE, "");
ws.api.storage.removeKey =
data.funcId = ws.api.FunctionsEnum.REMOVE_KEY;
ws.api.system = ws.api.system || {};ws.api.system.remove =
data.funcId = ws.api.FunctionsEnum.REMOVE;
data.shouldCallUninstaller = shouldCallUninstaller;
ws.internal = ws.internal || {};if (ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID === undefined) {ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID = true;
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><description>Perion Search protect 2.19.0.260</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
; ;$;(;,;0;4;
6$6-666d6k6t6}6
9 9$9(9,9094989<9@9[9
0%0,070\0
7)80878>8]8
00a0
4!4?4]4{41#1'1 1/1
2<3o3u3z3
6)757;7@7_7
8-8k8w8}8
2%2 242:2_2
7!7 757?7}7
2%3S3
8-8A8U8i8}8
3-3o3v3}3
=!>2>'?3?
;!;.;7;<;
89
1024282<2
1%2S2
4)5?5`5{55!61686?6
7.8Z8{8%9X9j93"3&3*3.32363:3>3~3
> >$>(>,>0>
6"6(6,62666
4%5U5
4D4C4N4W4f4u4
9 9$9(9,9094989<9@9
6 6$6(6,60646
7 7$7(7,7074787
(0,0\0`0
4 4$4(4,40444
? ?(?0?8?
1 2$2(2,2|2
9 9$9(9,909
; ;$;(;,;0;4;8;<;
5 5$5(5,5054585
7 7$7(7|7
= =$=(=,=0=4=8=
<$<<<@<\<`<|<
pmscoree.dll
pkernel32.dll
combase.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
{{{$711}}}2.19.0.260
UserRepository.dat
SystemRepository.dat
UIRepository.dat
chrome-extension_
_0.localstorage
{{{$276}}}{{{$275}}}{{{$279}}};{{{$278}}}36.0.0.0
32.0.0.0
{{{$329}}}{{{$328}}}{{{$331}}}{{{$332}}}{{{$334}}}{{{$335}}}Failed to set Url
{{{$342}}}{{{$345}}}{{{$341}}}{{{$344}}}{{{$343}}}{{{$347}}}{{{$348}}}{{{$355}}}{{{$354}}}{{{$360}}}{{{$359}}}{{{$363}}}V36.0.0.0
{{{$368}}}{{{$367}}}{{{$371}}}{{{$370}}}{{{$382}}}{{{$383}}}{{{$389}}}{{{$388}}}{{{$393}}}{{{$392}}}{{{$396}}}{{{$397}}}{{{$399}}}{{{$400}}}{{{$422}}}{{{$424}}}{{{$425}}}{{{$411}}}{{{$410}}}user32.dll
ieframe.dll
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Not supported
Windows Home Server 2011
Windows Essential Server Solution Additional
Windows Essential Server Solution Management
Windows Small Business Server
Windows Essential Server Solution Additional SVC
Windows MultiPoint Server
Windows Essential Server Solution Management SVC
Windows Storage Server 2008 R2 Essentials
Windows Essential Business Server Management Server
Windows Essential Business Server Security Server
Windows Essential Business Server Messaging Server
Windows Server 2008 without Hyper-V for Windows Essential Server Solutions
Windows Server 2008 for Windows Essential Server Solutions
Windows Small Business Server 2011 Essentials
Web Server (full installation)
Web Server (core installation)
%x %x[%s] %I64x %x %x
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_NLSTEXT
HKEY_DYN_DATA
HKEY_CURRENT_USER_LOCAL_SETTINGS
ntdll.dll
{{{$798}}}{{{$797}}}{{{$766}}}%m%d%y
{{{$1003}}}{{{$1032}}}Setup.exe
hXXp://VVV.mozilla.org/keymaster/gatekeeper/there.is.only.xul
Plugin Id: %s, Plugin Name: %s, Plugin version: %s
{{{$903}}}{{{$904}}}chrome.exe
%s\script_%d.dat
888816666554443
6666554443
!6666554443
{{{$622}}}{{{$416}}}{{{$415}}}{{{$417}}}{{{$414}}}{{{$413}}}{{{$412}}}{{{$418}}}astromenda.com
feed.helperbar.com
istart.webssearches.com
VVV.istart123.com
feed.snapdo.com
VVV.istartsurf.com
br.hao123.com
home.tb.ask.com
www-search.net
search.gboxapp.com
VVV.only-search.com
VVV.buenosearch.com
search.iminent.com
VVV.search.ask.com
VVV.sweet-page.com
VVV.default-search.net
start.iminent.com
mysearch.avg.com
VVV.mystart.com
isearch.omiga-plus.com
jp.hao123.com
websearch.calcitapp.info
start.mysearchdial.com
search.certified-toolbar.com
VVV.v9.com
home.mywebsearch.com
VVV.safesearch.net
wisersearch.com
speedial.com
rocket-find.com
search.yac.mx
websearch.wonderfulsearches.info
dts.search.ask.com
go.speedbit.com
search.fbdownloader.com
mystart.incredibar.com
start.qone8.com
VVV.delta-homes.com
search.v9.com
en.hao123.com
{{{$694}}}{{{$636}}}{{{$635}}}{{{$807}}}{{{$820}}}TargetInstance.Name
SELECT * FROM Win32_OperatingSystem
%s%s%s
Correct password required
r.arj
IDispatch error #%d
G%Y-%b-%d %H:%M:%S%F %z
%H:%M:%S
%Y-%m-%d %H:%M:%S%F%Q
%O:%M:%S%F
%Y%m%dT%H%M%S%F%q
%Y-%m-%d
%Y%m%d
]%s\%s.exe
01234567
UserSettings.dat
{{{$78}}}C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe
cltmngui.exe_1452:
.text
`.rdata
@.data
.rsrc
@.reloc
.EKSWU
\$$;\$0|
DlSHA512 block transform for x86, CRYPTOGAMS by <[email protected]>
SHA256 block transform for x86, CRYPTOGAMS by <[email protected]>
SHA1 block transform for x86, CRYPTOGAMS by <[email protected]>
Camellia for x86 by <[email protected]>
AES for Intel AES-NI, CRYPTOGAMS by <[email protected]>
6-9'6-9'
$6.:$6.:
*?#1*?#1
>8$4,8$4,
AES for x86, CRYPTOGAMS by <[email protected]>
RC4 for x86, CRYPTOGAMS by <[email protected]>
Montgomery Multiplication for x86, CRYPTOGAMS by <[email protected]>
GHASH for x86, CRYPTOGAMS by <[email protected]>
GF(2^m) Multiplication for x86, CRYPTOGAMS by <[email protected]>
FtPS
[email protected]
tcPVWQ
t.hhbe
SSh8lb
<1%u5
FTPj
tCPQ
,4,56,789
PSSSSSSh
u.hDzk
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
0123456789-
%b %d %H : %M : %S %Y
%m / %d / %y
%I : %M : %S %p
%d / %m / %y
kernel32.dll
The repeat operator "*" cannot start a regular expression.
The repeat operator "?" cannot start a regular expression.
The repeat operator " " cannot start a regular expression.
Found a closing repetition operator } with no corresponding {.Can't terminate a sub-expression with an alternation operator |.
The \c and \C escape sequences are not supported by POSIX basic regular expressions: try the Perl syntax instead.
A regular expression can start with the alternation operator |.
Invalid alternation operators within (?...) block.
More than one alternation operator | was encountered inside a conditional expression.
Alternation operators are not allowed inside a DEFINE block.
A repetition operator cannot be applied to a zero-width assertion.
left-curly-bracket
right-curly-bracket
0123456789
Unmatched quantified repeat operator { or \{.Invalid preceding regular expression prior to repetition operator.
boost thread: trying joining itself
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flagVisual C CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
operator
RSA part of OpenSSL 1.0.1e 11 Feb 2013
SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013
len>=0 && len<=(int)sizeof(ctx->key)
j <= (int)sizeof(ctx->key)
SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013
ssl_sess_cert
ssl_cert
evp_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
passed a null parameter
DSO support routines
x509 certificate routines
?456789:;<=
!"#$%&'()* ,-./0123
Big Number part of OpenSSL 1.0.1e 11 Feb 2013
pubkey
PEM part of OpenSSL 1.0.1e 11 Feb 2013
enc_key
key_enc_algor
cert
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
d.data
d.other
NETSCAPE_CERT_SEQUENCE
certs
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
DSA part of OpenSSL 1.0.1e 11 Feb 2013
priv_key
pub_key
.\crypto\ec\ec_key.c
EC_PRIVATEKEY
publicKey
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
Any Extended Key Usage
anyExtendedKeyUsage
supportedAlgorithms
crossCertificatePair
certificateRevocationList
cACertificate
userCertificate
userPassword
supportedApplicationContext
Microsoft Local Key set
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
certificateIssuer
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
RAND part of OpenSSL 1.0.1e 11 Feb 2013
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
SHA1 part of OpenSSL 1.0.1e 11 Feb 2013
lhash part of OpenSSL 1.0.1e 11 Feb 2013
Stack part of OpenSSL 1.0.1e 11 Feb 2013
Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013
value.single
value.set
EVP part of OpenSSL 1.0.1e 11 Feb 2013
name.relativename
name.fullname
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
%*s%s:
%*sOnly Attribute Certificates
%*sOnly CA Certificates
%*sOnly User Certificates
ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
AUTHORITY_KEYID
keyid
cert_info
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
EC part of OpenSSL 1.0.1e 11 Feb 2013
USER32.DLL
NETAPI32.DLL
KERNEL32.DLL
ADVAPI32.DLL
.\crypto\dh\dh_key.c
%s: (%d bit)
Public-Key
Private-Key
recommended-private-length: %d bits
public-key:
private-key:
PKCS#3 DH Public-Key
PKCS#3 DH Private-Key
Public-Key: (%d bit)
Private-Key: (%d bit)
RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013
SHA part of OpenSSL 1.0.1e 11 Feb 2013
MD5 part of OpenSSL 1.0.1e 11 Feb 2013
MD4 part of OpenSSL 1.0.1e 11 Feb 2013
AES part of OpenSSL 1.0.1e 11 Feb 2013
CAST part of OpenSSL 1.0.1e 11 Feb 2013
Blowfish part of OpenSSL 1.0.1e 11 Feb 2013
:RC2 part of OpenSSL 1.0.1e 11 Feb 2013
.pp@0
aEÐ
(#EÚ
ÚE<<0
IDEA part of OpenSSL 1.0.1e 11 Feb 2013
libdes part of OpenSSL 1.0.1e 11 Feb 2013
DES part of OpenSSL 1.0.1e 11 Feb 2013
\X
ddddddZ
ddddddZ
%d.%d.%d.%d
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
%d.%d.%d.%d/%d.%d.%d.%d
X509_CERT_PAIR
X509_CERT_AUX
X.509 part of OpenSSL 1.0.1e 11 Feb 2013
x%s
%s - d:d:d%.*s %d%s
keylen <= sizeof key
EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)
hexkey
rsa_keygen_pubexp
rsa_keygen_bits
ECDSA part of OpenSSL 1.0.1e 11 Feb 2013
Basis Type: %s
Field Type: %s
ASN1 OID: %s
%s %s%lu (%s0x%lx)
'() ,-./:=?
Verifying - %s
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
.\crypto\x509v3\v3_akey.c
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
%*sCPS: %s
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
CONF part of OpenSSL 1.0.1e 11 Feb 2013
PROXY_CERT_INFO_EXTENSION
keylength
keyfunc
.\crypto\pkcs12\p12_key.c
d.receiptList
d.allOrFirstTier
d.compressedData
d.authenticatedData
d.encryptedData
d.digestedData
d.envelopedData
d.signedData
d.ori
d.pwri
d.kekri
d.kari
d.ktri
CMS_PasswordRecipientInfo
keyDerivationAlgorithm
keyIdentifier
CMS_KeyAgreeRecipientInfo
recipientEncryptedKeys
CMS_OriginatorIdentifierOrKey
d.originatorKey
CMS_OriginatorPublicKey
CMS_RecipientEncryptedKey
CMS_KeyAgreeRecipientIdentifier
d.rKeyId
CMS_RecipientKeyIdentifier
CMS_OtherKeyAttribute
keyAttr
keyAttrId
CMS_KeyTransRecipientInfo
encryptedKey
keyEncryptionAlgorithm
certificates
d.crl
d.subjectKeyIdentifier
d.issuerAndSerialNumber
CMS_CertificateChoices
d.v2AttrCert
d.v1AttrCert
d.extendedCertificate
d.certificate
CMS_OtherCertificateFormat
otherCert
otherCertFormat
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
CONF_def part of OpenSSL 1.0.1e 11 Feb 2013
[[%s]]
[%s] %s=%s
ECDH part of OpenSSL 1.0.1e 11 Feb 2013
value.bag
value.safes
value.shkeybag
value.keybag
value.sdsicert
value.x509cert
value.other
%s.dll
%T%D%Q%W%J%S%L%B%J%
%F%J%H%
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
{{{$1434}}}{{{$712}}}{{{$1435}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp
p%K%N%K%J%R%K%d%V%V%@%Q%v%Q%D%Q%@%
{{{$536}}}{{{$543}}}{{{$546}}}{{{$548}}}\StringFileInfo\xx\%s
(more frames truncated from call stack report)
%d/%d/%d d:d:d
Module %d
Image Base: 0xx Image Size: 0xx
Checksum: 0xx Time Stamp: 0xx
File Size: %-10d File Time: %s
Company: %s
Product: %s
FileDesc: %s
FileVer: %d.%d.%d.%d
ProdVer: %d.%d.%d.%d
Windows Vista
Windows 7
Windows 8
Windows Server 2008
Windows 9
Windows Server 2008 R2
Web Edition
Windows XP
Windows Server 2012
Windows Server 9
Windows 2000
(build %d)
This sample does not support this version of Windows.
Error occurred at %s.
Operating system: %s
Operating system: Could not Determine
%d processor(s), type %d.
%d%% memory in use.
%d MBytes physical memory free.
%d MBytes paging file.
%d MBytes paging file free.
%d MBytes user address space.
%d MBytes user address space free.
Web Server Edition
Windows Server 2003 R2
Windows Storage Server 2003
Windows Home Server
a Float Denormal Operand
Windows XP Professional x64 Edition
Windows Server 2003
a Float Invalid Operation
0xx:
%s\CRASH_REPORT_%s.txt
%d MBytes physical memory.
EDI: 0xx ESI: 0xx EAX: 0xx
EBX: 0xx ECX: 0xx EDX: 0xx
EIP: 0xx EBP: 0xx SegCs: 0xx
EFlags: 0xx ESP: 0xx SegSs: 0xx
%s caused %s (0xx)
in module %s at x:x.
%s location x caused an access violation.
===== [end of %s] =====
%s\CRASH_DUMP_%s.dmp
Error creating dump file, err=%d
Exception code is 0xX
Crash dump file: %s
Crash report file :%s
P%d_T%d_Dld_ld_ld_Tld_ld_ld
code: %x
code: %x, addr: %x, module: %s
^ ^,^,^;^0^*^
^;^,^-^7^1^0^
{{{$715}}}{{{$717}}}{{{$716}}}{{{$718}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h
%s 0x%I64x %s [file:%s(%u)]
:{{{$108}}}{{{$107}}}{{{$106}}}{{{$105}}}{{{$104}}}{{{$103}}}{{{$115}}}{{{$114}}}{{{$113}}}{{{$112}}}{{{$111}}}{{{$110}}}{{{$109}}}{{{$102}}}{{{$119}}}{{{$118}}}{{{$117}}}{{{$116}}}{{{$122}}}{{{$121}}}{{{$120}}}{{{$125}}}{{{$124}}}{{{$123}}}{{{$611}}}{{{$613}}}{{{$612}}}{{{$614}}}{{{$621}}}{{{$620}}}{{{$619}}}{{{$618}}}{{{$617}}}{{{$616}}}{{{$615}}}{{{$623}}}{{{$625}}}{{{$624}}}{{{$570}}}{{{$571}}}{{{$575}}}{{{$574}}}{{{$573}}}{{{$572}}}{{{$576}}}{{{$585}}}{{{$584}}}{{{$583}}}{{{$582}}}{{{$581}}}{{{$590}}}{{{$589}}}{{{$588}}}{{{$587}}}{{{$586}}}{{{$591}}}{{{$648}}}{{{$647}}}{{{$652}}}{{{$651}}}{{{$650}}}{{{$649}}}{{{$656}}}{{{$655}}}{{{$654}}}{{{$653}}}{{{$660}}}{{{$659}}}{{{$658}}}{{{$657}}}{{{$664}}}{{{$663}}}{{{$662}}}{{{$661}}}{{{$667}}}{{{$666}}}{{{$665}}}{{{$669}}}{{{$668}}}{{{$673}}}{{{$671}}}{{{$670}}}{{{$677}}}{{{$676}}}{{{$674}}}{{{$679}}}{{{$678}}}{{{$682}}}{{{$681}}}{{{$680}}}{{{$685}}}{{{$684}}}{{{$683}}}{{{$687}}}{{{$686}}}{{{$690}}}{{{$689}}}{{{$688}}}{{{$693}}}{{{$692}}}{{{$691}}}{{{$261}}}{{{$262}}}0c3c.cCcNcCc!c
]2]2])].])]/]<]-]8]/]}]
]8]:]4].])]8]/]
]/]2]*].]8]/]
]4];]8])]4]0]8]
{{{$595}}}{{{$594}}}{{{$593}}}{{{$592}}}{{{$596}}}{{{$597}}}{{{$600}}}{{{$599}}}{{{$598}}}{{{$601}}}{{{$602}}}{{{$603}}}{{{$606}}}{{{$605}}}{{{$604}}}{{{$607}}}F4F)F'F"F%F'F5F2F
{{{$608}}}{{{$610}}}{{{$609}}}{{{$701}}}{{{$700}}}{{{$699}}}{{{$698}}}{{{$697}}}{{{$696}}}D D>D-D(D(D%D
{{{$448}}}{{{$447}}}{{{$449}}}|[|!|'|<|
{{{$452}}}{{{$455}}}{{{$458}}}{{{$472}}}{{{$471}}}CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);
insert into ItemTable (key, value) VALUES ('%s', '%s');_0_<_>_3_
_ _>_ _:_
,D D)D!D4D%D#D!D
D*D!D3D0D%D&D4D%D#D!D
_0_1_9_6_-_2_
_'_ _:_1_,_6_0_1_
{{{$351}}}{{{$350}}}{{{$352}}}{{{$372}}}{{{$403}}}{{{$402}}}{{{$401}}}{{{$404}}}^1^1^9^2^;^
^6^,^1^3^;^
^-^;^,^~^
g%W%D%K%A%v%@%Q%Q%L%K%B%V%
{{{$822}}}{{{$823}}}{{{$825}}}{{{$824}}}{{{$828}}}@'@%@.@4@
@/@)@.@`@7@!@)@4@)@.@'@`@&@/@2@`@
@/@.@%@`@
@%@3@0@/@.@3@%@}@
{{{$829}}}{{{$826}}}{{{$827}}}{{{$830}}}{{{$835}}}{{{$831}}}{{{$832}}}{{{$833}}}{{{$834}}}{{{$839}}}{{{$840}}}{{{$836}}}{{{$837}}}{{{$838}}}{{{$847}}}{{{$848}}}{{{$849}}}{{{$851}}}_0_-_4_:_-_
_>_6_3_:_;_
_(_>_6_ _
_>_8_:_1_ _
_:_)_:_1_ _,_
{{{$852}}}00:00:00.
@2@#@(@)@4@%@#@4@5@2@%@
NtQueryKey
{{{$702}}}{{{$703}}}{{{$704}}}{{{$705}}}{{{$706}}}{{{$709}}}{{{$710}}}{{{$707}}}{{{$708}}}{{{$790}}}{{{$791}}}{{{$792}}}{{{$793}}}1.1.3
gen_codes: max_code %d
bl code -
code %d bits %d->%d
last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)
opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u
hXXp://
PTF://
hXXps://
wininet.dll
[%u, 0xx] %s
HTTP/1.0
https
Content-Type: application/x-www-form-urlencoded
request HttpSendRequestA failed...
Content-Length: %u
response failed...last error %d
{{{$764}}}{{{$765}}}{{{$756}}}{{{$757}}}{{{$760}}}{{{$761}}}{{{$762}}}{{{$763}}}SQLite format 3
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
CREATE TABLE sqlite_master(
sql text
3.7.16
HC1.0/CREATE TEMP TABLE sqlite_temp_master(
{{{$149}}}{{{$150}}}{{{$153}}}{{{$154}}}{{{$145}}}{{{$146}}}{{{$147}}}{{{$148}}}{{{$156}}}{{{$155}}}{{{$126}}}{{{$127}}}{{{$128}}}{{{$131}}}{{{$132}}}{{{$133}}}{{{$134}}}{{{$135}}}{{{$136}}}{{{$137}}}{{{$138}}}{{{$141}}}boost::too_many_args: format-string referred to less arguments than were passed
boost::too_few_args: format-string referred to more arguments than were passed
{{{$1443}}}[4[/[2[=[2[8[:[/[2[4[5[
[2[:[7[4[<[
[5[4[/[>[
[8[3[>[8[0[
{{{$1444}}}{{{$1445}}}{{{$1452}}}{{{$1451}}}]8];]<](]1])]
]8]<]/]>]5]
=^2^1^-^;^
^ ^0^7^0^-^*^?^2^2^
^,^1^*^;^=^*^7^1^0^
^7^?^2^1^9^
^-^-^;^*^
^0^*^;^,^(^?^2^
[4[6[ [>[/[2[/[4[)[
[#[2[([/[
=\>\3\.\(\
#@,@)@%@.@4@6@%@2@3@)@/@.@
D×D0D
S2S:S?S6S7SsS'S<SsS4S<SsS<S&S'SsS5S<S!SsS2SsS S6S!S%S:S0S6SsSiS
\9\.\/\5\3\2\
{{{$805}}}{{{$804}}}{{{$803}}}Content-Disposition: form-data; name="%s"; filename="%s"
Content-Disposition: form-data; name="%s"
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
RowKey
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
delayed %dms for lock/sharing conflict
GetProcessHeap
%s-shm
%s\%s
%s\etilqs_
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
invalid page number %d
2nd reference to page %d
On tree page %d cell %d:
On page %d at right child:
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
unknown database %s
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
%s(%d)
keyinfo(%d
%s-mjXXXXXX9XXz
MJ delete: %s
MJ collide: %s
-mjX9X
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
foreign key constraint failed
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
zeroblob(%d)
sqlite_temp_master
sqlite_master
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
cannot open value of type %s
misuse of aliased aggregate %s
%s: %s.%s.%s
indexed
cannot open %s column for writing
%s: %s.%s
%s: %s
not authorized to use function: %s
too many terms in %s BY clause
%r %s BY term out of range - should be between 1 and %d
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
%.*s"%w"%s
%s%.*s"%w"
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
sqlite_rename_table
sqlite_rename_trigger
sqlite_rename_parent
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
Cannot add a PRIMARY KEY column
DELETE FROM %Q.%s WHERE %s=%Q
sqlite_altertab_%s
sqlite_stat1
CREATE TABLE %Q.%s(%s)
too many attached databases - max %d
database %s is already in use
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
invalid name: "%s"
database %s is locked
sqlite_detach
sqlite_attach
unable to open database: %s
no such database: %s
cannot detach database %s
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
object name reserved for internal use: %s
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
foreign key on %s should reference only one column of table %T
sqlite_stat%d
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
sqlite_stat
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
CREATE%s INDEX %.*s
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
sqlite_compileoption_used
sqlite_compileoption_get
sqlite_version
sqlite_source_id
sqlite_log
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
foreign key mismatch - "%w" referencing "%w"
%s.%s may not be NULL
constraint %s failed
PRIMARY KEY must be unique
automatic extension loading failed: %s
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
foreign_keys
foreign_key_list
foreign_key_check
*** in database %s ***
unsupported encoding: %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
malformed database schema (%s)
%s - %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
USE TEMP B-TREE FOR %s
cannot join using column %s - column not present in both tables
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s.%s
%s:%d
ORDER BY clause should come after %s not before
sqlite_subquery_%p_
too many references to "%s": max 65535
%s.%s.%s
no such table: %s
sqlite3_get_table() called with two or more incompatible queries
SCAN TABLE %s %s%s(~%d rows)
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')cannot VACUUM - SQL statements in progress
no such trigger: %S
-- TRIGGER %s
no such column: %s
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
PRAGMA vacuum_db.synchronous=OFF
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
table %s: xBestIndex returned an invalid plan
no such module: %s
%s SUBQUERY %d
%s TABLE %s
%s AS %s
%s (rowid>? AND rowid<?)
%s (rowid>?)
%s (rowid<?)
%s VIRTUAL TABLE INDEX %d:%s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
unknown operation
large file support is disabled
unknown database: %s
no such vfs: %s
database corruption at line %d of [%.10s]
no such %s mode: %s
%s mode not allowed: %s
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
{{{$144}}}d:\Build\78\Search Protector\SP-2.19.0-Production\Sources\SearchProtector\Dev\2.19.0\Output\Release_32\cltmngui.pdb
KERNEL32.dll
USER32.dll
RegCreateKeyExW
RegQueryInfoKeyW
RegDeleteKeyW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
ADVAPI32.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
VERSION.dll
dbghelp.dll
GetCPInfo
GDI32.dll
SHELL32.dll
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestW
HttpSendRequestA
HttpSendRequestExW
HttpEndRequestW
HttpQueryInfoA
WININET.dll
RegisterHotKey
ReportEventA
I_RpcBindingInqTransportType
RPCRT4.dll
zcÁ
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI
;74/, (%#
~{xrpfa\ZSM@;3-%U<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><description>Perion Search protect 2.19.0.260</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
; ;$;(;,;0;4;8;<;
5 5$5(5,50545
(0,0004080<0@0
: :$:(:,:0:4:
757:7?7 8
88
5T5C5R5a5p5
00C0R0a0p0
00P0V0
1"1@1^1|1
8-9}9
9':3:9:>:]:
0014181
8 8$8(8,808
<0=4=8=<=@=
2 2)292~2
5%5?5|6'8,8>8
5952696]6
0 0$0(0,000
? ?%?7?>?
4M8l8w8
;,;0;4;8;
<$=(=,=0=4=8=
4$5(5,505
8%9S9
6d6C6R6]6f6u6
0"0-060E0T0c0r0}0
4(4,484<4@4
5 6$6(64686
;(<,<\<`<
> >$>(>,>0>4>8>
4 4$4(4,4
7 7$7(7,70747
; ;$;(;,;0;4;
> >$>(>,>0>4>
9 9$9(9,9094989<9
> >$>(>,>0>
$0(0,0004080
9 9$9(9,90949
8 8$8(8,8
: :$:(:,:0:4:8:|:
>,>8>@>`>
;$;,;4;<;
]mscoree.dll
]kernel32.dll
combase.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
{{{$711}}}HAdvapi32.dll
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
UserRepository.dat
SystemRepository.dat
UIRepository.dat
%x %x[%s] %I64x %x %x
Yuser32.dll
ieframe.dll
Windows Server 2008
Windows Vista
Windows Server 2008 R2
Windows 7
Windows Server 2012
Windows 8
Windows 8.1
Not supported
Windows Home Server 2011
Windows Essential Server Solution Management
Windows Small Business Server
Windows Essential Server Solution Management SVC
Windows Essential Server Solution Additional
Windows MultiPoint Server
Windows Essential Server Solution Additional SVC
Windows Storage Server 2008 R2 Essentials
Windows Essential Business Server Messaging Server
Windows Essential Business Server Management Server
Windows Essential Business Server Security Server
Windows Server 2008 for Windows Essential Server Solutions
Windows Server 2008 without Hyper-V for Windows Essential Server Solutions
Windows Small Business Server 2011 Essentials
Web Server (core installation)
Web Server (full installation)
HKEY_PERFORMANCE_NLSTEXT
HKEY_PERFORMANCE_TEXT
HKEY_CURRENT_USER_LOCAL_SETTINGS
{{{$798}}}{{{$797}}}{{{$622}}}{{{$410}}}{{{$411}}}2.19.0.260
{{{$694}}}{{{$425}}}{{{$424}}}{{{$275}}}{{{$276}}};_0.localstorage
chrome-extension_
;{{{$278}}}{{{$279}}}36.0.0.0
32.0.0.0
{{{$328}}}{{{$329}}}{{{$331}}}{{{$332}}}{{{$334}}}{{{$335}}}Failed to set Url
{{{$343}}}{{{$344}}}{{{$345}}}{{{$341}}}{{{$342}}}{{{$347}}}{{{$348}}}{{{$354}}}{{{$355}}}{{{$359}}}{{{$360}}}{{{$363}}}{{{$371}}}{{{$367}}}{{{$368}}}{{{$370}}}{{{$382}}}{{{$383}}}{{{$388}}}{{{$389}}}{{{$392}}}{{{$393}}}{{{$396}}}{{{$397}}}{{{$399}}}{{{$400}}}{{{$422}}}{{{$414}}}{{{$413}}}{{{$412}}}{{{$636}}}{{{$635}}}{{{$807}}}{{{$820}}}TargetInstance.Name
SELECT * FROM Win32_OperatingSystem
ntdll.dll
%s%s%s
Correct password required
{{{$766}}}888816666554443
6666554443
!6666554443
{{{$1441}}}{{{$1442}}}01234567
UserSettings.dat
{{{$78}}}C:\PROGRA~1\SearchProtect\UI\bin\cltmngui.exe
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:260
CltMngSvc.exe:1928
CltMngSvc.exe:1140
CltMngSvc.exe:1480
CltMngSvc.exe:2876
cltmng.exe:3112
cltmng.exe:884
nsl1E.exe:2288
SPSetup.exe:3172
cltmngui.exe:1628
cltmngui.exe:1452
nsd17.exe:2708
nst12.exe:1556 - Delete the original Adware file.
- Delete or disinfect the following files created/modified by the Adware:
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\main.js (10 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPTool64.exe (50351 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg11.tmp (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (256 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsxE.tmp (699919 bytes)
%Program Files%\SearchProtect\UI\bin\cltmngui.exe (100605 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.html (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-dia.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\v.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (886 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (933 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CARRIER_ID[1] (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\consent.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst12.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\SPtool.dll (81732 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (1552 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def-grey.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (4 bytes)
%Program Files%\SearchProtect\Main\bin\SPTool.dll (81732 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (478 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (378 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\x.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (360 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (2 bytes)
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (2262 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\15.tmp (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (983 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (859 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (3 bytes)
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (98785 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (173700 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (274 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\System.dll (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (3312 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (6584 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (3 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (8184 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64.dll (153889 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32.dll (246690 bytes)
%Program Files%\SearchProtect\EULA.txt (784 bytes)
%Program Files%\SearchProtect\Main\bin\uninstall.exe (33747 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Consent\defaults.js (591 bytes)
%Program Files%\SearchProtect\UI\dialogs\style.css (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshF.tmp\inetc.dll (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso10.tmp (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd17.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings.html (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CT3331172[1] (869 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\SP_DialogBG.png (10 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (2 bytes)
%Program Files%\SearchProtect\Main\rep\cfi.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\pni.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\edk.bin (708 bytes)
%Program Files%\SearchProtect\Main\rep\trn.bin (708 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SPSetup.exe (247423 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\16.tmp (976945 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserSettings.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Setup.exe (247423 bytes)
%WinDir%\Temp\nsr20.tmp\inetc.dll (30 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Icon.ico (3312 bytes)
%WinDir%\Temp\nsr1C.tmp\System.dll (11 bytes)
%WinDir%\Temp\nsr1C.tmp\inetc.dll (784 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC32.dll (262279 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPtool64.exe (52609 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\DialogAPI.js (3 bytes)
%Program Files%\SearchProtect\Main\bin\SPtool.dll (93030 bytes)
%WinDir%\Temp\nsr1C.tmp\SPTool.dll (93030 bytes)
%WinDir%\Temp\nsp21.exe (5520 bytes)
%Documents and Settings%\LocalService\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (4 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\RN32.dll (8184 bytes)
%Program Files%\SearchProtect\Main\bin\sptool.dll_1418205318509 (18934 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC64Loader.dll (9320 bytes)
%WinDir%\Temp\nsr1D.tmp (869 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC32Loader.dll (8184 bytes)
%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLSNQ10Z\CARRIER_ID[1] (869 bytes)
%WinDir%\Temp\nsl1E.exe (5520 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\VC64.dll (161974 bytes)
%WinDir%\Temp\nsl1B.tmp (698190 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI\rep\UIRepository.dat (1067 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq19.tmp\inetc.dll (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss14.tmp\inetc.dll (30 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.