Gen.Variant.Kazy.148243_699afde8dd
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Kazy.148243 (B) (Emsisoft), Gen:Variant.Kazy.148243 (AdAware), Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericInjector.YR (Lavasoft MAS)
Behaviour: Banker, Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 699afde8dda577567e7578b126f9def1
SHA1: 5b9475234e90e43fbe682304f8f34d0eb4595abf
SHA256: 973e9150d0436d614db4a11d63feeaae6d988039df7d6f4f63508f6ad09484f0
SSDeep: 49152:0dcqG/VD0vs94PgAWcL6lbw0x8UrSNtAhbOkxIXr3J:
Size: 3555328 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: Mail.Ru
Created at: 2010-11-17 10:58:00
Analyzed on: Windows7 SP1 32-bit
Summary:
Banker. Steals data relating to online banking systems, e-payment systems and credit card systems.
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
chrome.exe:1792
torrent.exe:4000
torrent.exe:2988
%original file name%.exe:2452
windefender.exe:3092
The Trojan injects its code into the following process(es):
chrome.exe:3584
mini-KMS_Activator_v1.053.exe:2668
windefender.exe:2476
Explorer.EXE:1440
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process chrome.exe:3584 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\admlog.dat (15 bytes)
C:\Windows\System32\windefender\windefender.exe (573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm7 (12568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm8 (80 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm2.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm7 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm8 (0 bytes)
The process torrent.exe:4000 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe (3361 bytes)
C:\Windows\System32\drivers\etc\hosts (155 bytes)
The process torrent.exe:2988 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\System32\windefender\windefender.exe (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm2.txt (230 bytes)
The process %original file name%.exe:2452 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\mini-KMS_Activator_v1.053.exe (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\torrent.exe (1146 bytes)
The process mini-KMS_Activator_v1.053.exe:2668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\instsrv.exe (288 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ChkOf.cmd (590 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KeyMngOf.cmd (173 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KeyMngW.cmd (267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\cscript.exe (241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\hidcon.exe (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\RearmOf.cmd (958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KMService.exe (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\RearmW.cmd (770 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\PortQry.exe (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\hs_message.vbs (796 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ospp.vbs (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\srvany.exe (200 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ChkWin.cmd (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\choice.exe (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\autorun.exe (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ActOf.cmd (108 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\autorun.apm (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\slerror.xml (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ospprearm.exe (190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\VL.vbs (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Help.txt (341 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Start.cmd (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Rest.cmd (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KMSIns.cmd (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\service.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ActWin.cmd (302 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\osppc.dll (359 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp (0 bytes)
The process windefender.exe:3092 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\System32\drivers\etc\hosts (155 bytes)
Registry activity
The process chrome.exe:3584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\nemesis torrent]
"NewIdentification" = "nemesis torrent"
[HKCU\Software\Google\Chrome\BLBeacon]
"failed_count" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\nemesis torrent]
"NewGroup" = "Type: REG_EXPAND_SZ, Length: 0"
[HKCU\Software\Google\Chrome\BLBeacon]
"State" = "2"
[HKCU\Software\nemesis torrent]
"FirstExecution" = "03/11/2017 -- 11:08"
[HKCU\Software\Classes\Local Settings\MuiCache\63\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process torrent.exe:4000 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"csrss.exe" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe"
The process torrent.exe:2988 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{15HXLAC0-3P34-FJ14-P563-67MY5E56KJI0}]
"StubPath" = "C:\Windows\system32\windefender\windefender.exe Restart"
The process %original file name%.exe:2452 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process mini-KMS_Activator_v1.053.exe:2668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process windefender.exe:3092 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"csrss.exe" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe"
Dropped PE files
MD5 | File path |
---|---|
bca43e19e7013331d99ff788ea6b42a0 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KMService.exe |
c6ac67f4076ca431acc575912c194245 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\PortQry.exe |
9f5db165601843001dd313c6c2840db9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\autorun.exe |
a704d22d57b62553e27ad261276b0625 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\choice.exe |
34098403f9d8f71ce2ec749122168e89 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\cscript.exe |
b2dadab18c318443301d0087cd7200ba | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\hidcon.exe |
9f7acaad365af0d1a3cd9261e3208b9b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\instsrv.exe |
1d9c3d7a1f8838e6280fa3f7d1fe4ed8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\osppc.dll |
7ffae006610a85317fbb092a2d65d1a9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ospprearm.exe |
4635935fc972c582632bf45c26bfcb0e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\srvany.exe |
1dc3305f9f30c17c4f4c2a0fba87f05b | c:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe |
893d91fda6148e85f47148ba55931441 | c:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\mini-KMS_Activator_v1.053.exe |
1dc3305f9f30c17c4f4c2a0fba87f05b | c:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\torrent.exe |
1dc3305f9f30c17c4f4c2a0fba87f05b | c:\Windows\System32\windefender\windefender.exe |
HOSTS file anomalies
The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 155 bytes in size. The following strings are added to the hosts file listed below:
127.0.0.1 | virustotal.com |
127.0.0.1 | scanner.novirusthanks.org |
127.0.0.1 | scanner2.novirusthanks.org |
127.0.0.1 | virusscan.jotti.org |
127.0.0.1 | virscan.org |
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name:
Product Version: 0.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename: setup.exe
Internal Name: setup.exe
File Version: 0.0.0.0
File Description:
Comments:
Language: Spanish (Spain, International Sort)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 8192 | 3513924 | 3514368 | 4.16811 | 26e3a9d652f663a0d2d9701960458329 |
.sdata | 3522560 | 130 | 4096 | 0.227912 | bb68096dff6ad4705ea5d8f20e128cb6 |
.rsrc | 3530752 | 27836 | 28672 | 2.94227 | 4f3a79e8beccd7293875f5d4f45bc314 |
.reloc | 3563520 | 12 | 4096 | 0.011373 | 90bc23212e065d4a081e404e0a8f24d0 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
seireiteiro.sytes.net | ![]() |
teredo.ipv6.microsoft.com | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
The Trojan connects to the servers at the folowing location(s):
`.rsrc
u&SSh2
SHELL32.DLL
WindowClass_%d
Kernel32.DLL
Please enter the password.
This program is not supported on this operating system.
Password
Passwort
Falsches Passwort.
Wrong password.
Bitte geben Sie das Passwort ein.
diu2.iu
cscript HS_MESSAGE.vbs "Did you run the program as Administrator? " "Activation Tool" Q YESNO
if %errorlevel$==6 start /wait autorun.exe
<err0xC004B007>The activation server reported that the computer could not connect to the activation server.</err0xC004B007>
<err0xC004C001>The activation server determined the specified product key is invalid.</err0xC004C001>
<err0xC004C002>The activation server determined there is a problem with the specified product key.</err0xC004C002>
<err0xC004C003>The activation server determined the specified product key has been blocked.</err0xC004C003>
<err0xC004C004>The activation server determined the specified product key is invalid. </err0xC004C004>
<err0xC004C007>The activation server determined the specified product key is invalid.</err0xC004C007>
<err0xC004C008>The activation server determined that the specified product key could not be used.</err0xC004C008>
<err0xC004C00E>The activation server determined the specified product key is invalid.</err0xC004C00E>
<err0xC004C00F>The activation server determined the specified product key is invalid.</err0xC004C00F>
<err0xC004C010>The activation server determined the specified product key is invalid.</err0xC004C010>
<err0xC004C020>The activation server reported that the Multiple Activation Key has exceeded its limit.</err0xC004C020>
<err0xC004C021>The activation server reported that the Multiple Activation Key extension limit has been exceeded.</err0xC004C021>
<err0xC004C022>The activation server reported that the re-issuance limit was not found. </err0xC004C022>
<err0xC004C023>The activation server reported that the override request was not found. </err0xC004C023>
<err0xC004C016>The activation server reported that the specified product key cannot be used for online activation.</err0xC004C016>
<err0xC004C017>The activation server determined the specified product key has been blocked for this geographic location.</err0xC004C017>
<err0xC004C030>The activation server reported that time based activation attempted before start date.</err0xC004C030>
<err0xC004C031>The activation server reported that time based activation attempted after end date.</err0xC004C031>
<err0xC004C032>The activation server reported that new time based activation not available.</err0xC004C032>
<err0xC004C033>The activation server reported that time based product key not configured for activation.</err0xC004C033>
<err0xC004C04F>The activation server reported that no business rules available to activate specified product key.</err0xC004C04F>
<err0xC004C700>The activation server reported that business rule cound not find required input.</err0xC004C700>
<err0xC004C750>The activation server reported that NULL value specified for business property name and Id.</err0xC004C750>
<err0xC004C751>The activation server reported that property name specifies unknown property.</err0xC004C751>
<err0xC004C752>The activation server reported that property Id specifies unknown property.</err0xC004C752>
<err0xC004C755>The activation server reported that it failed to update product key binding.</err0xC004C755>
<err0xC004C756>The activation server reported that it failed to insert product key binding.</err0xC004C756>
<err0xC004C757>The activation server reported that it failed to delete product key binding.</err0xC004C757>
<err0xC004C758>The activation server reported that it failed to process input XML for product key bindings.</err0xC004C758>
<err0xC004C75A>The activation server reported that it failed to insert product key property.</err0xC004C75A>
<err0xC004C75B>The activation server reported that it failed to update product key property.</err0xC004C75B>
<err0xC004C75C>The activation server reported that it failed to delete product key property.</err0xC004C75C>
<err0xC004C764>The activation server reported that the product key type is unknown.</err0xC004C764>
<err0xC004C770>The activation server reported that the product key type is being used by another user.</err0xC004C770>
<err0xC004C780>The activation server reported that it failed to insert product key record.</err0xC004C780>
<err0xC004C781>The activation server reported that it failed to update product key record.</err0xC004C781>
<err0xC004C801>The activation server determined the specified product key is invalid.</err0xC004C801>
<err0xC004C802>The activation server determined the specified product key is invalid.</err0xC004C802>
<err0xC004C803>The activation server determined the specified product key has been revoked.</err0xC004C803>
<err0xC004C804>The activation server determined the specified product key is invalid.</err0xC004C804>
<err0xC004C805>The activation server determined the specified product key is invalid.</err0xC004C805>
<err0xC004C810>The activation server determined the specified product key is invalid.</err0xC004C810>
<err0xC004C812>The activation server determined that the specified product key has exceeded its activation count.</err0xC004C812>
<err0xC004C814>The activation server determined the specified product key is invalid.</err0xC004C814>
<err0xC004C816>The activation server reported that the specified product key cannot be used for online activation.</err0xC004C816>
<err0xC004E002>The Software Licensing Service reported that the license store contains inconsistent data.</err0xC004E002>
<err0xC004E003>The Software Licensing Service reported that license evaluation failed.</err0xC004E003>
<err0xC004E004>The Software Licensing Service reported that the license has not been evaluated.</err0xC004E004>
<err0xC004E005>The Software Licensing Service reported that the license is not activated.</err0xC004E005>
<err0xC004E006>The Software Licensing Service reported that the license contains invalid data.</err0xC004E006>
<err0xC004E007>The Software Licensing Service reported that the license store does not contain the requested license.</err0xC004E007>
<err0xC004E008>The Software Licensing Service reported that the license property is invalid.</err0xC004E008>
<err0xC004E009>The Software Licensing Service reported that the license store is not initialized.</err0xC004E009>
<err0xC004E00A>The Software Licensing Service reported that the license store is already initialized.</err0xC004E00A>
<err0xC004E00B>The Software Licensing Service reported that the license property is invalid.</err0xC004E00B>
<err0xC004E00C>The Software Licensing Service reported that the license could not be opened or created.</err0xC004E00C>
<err0xC004E00D>The Software Licensing Service reported that the license could not be written.</err0xC004E00D>
<err0xC004E00E>The Software Licensing Service reported that the license store could not read the license file.</err0xC004E00E>
<err0xC004E00F>The Software Licensing Service reported that the license property is corrupted.</err0xC004E00F>
<err0xC004E010>The Software Licensing Service reported that the license property is missing.</err0xC004E010>
<err0xC004E011>The Software Licensing Service reported that the license store contains an invalid license file.</err0xC004E011>
<err0xC004E012>The Software Licensing Service reported that the license store failed to start synchronization properly.</err0xC004E012>
<err0xC004E013>The Software Licensing Service reported that the license store failed to synchronize properly.</err0xC004E013>
<err0xC004E014>The Software Licensing Service reported that the license property is invalid.</err0xC004E014>
<err0xC004E015>The Software Licensing Service reported that license consumption failed.</err0xC004E015>
<err0xC004E016>The Software Licensing Service reported that the product key is invalid.</err0xC004E016>
<err0xC004E017>The Software Licensing Service reported that the product key is invalid.</err0xC004E017>
<err0xC004E018>The Software Licensing Service reported that the product key is invalid.</err0xC004E018>
<err0xC004E019>The Software Licensing Service determined that validation of the specified product key failed.</err0xC004E019>
<err0xC004E01A>The Software Licensing Service reported that invalid add-on information was found. </err0xC004E01A>
<err0xC004E01B>The Software Licensing Service reported that not all hardware information could be collected. </err0xC004E01B>
<err0xC004E01C>This evaluation product key is no longer valid.</err0xC004E01C>
<err0xC004E01D>The new product key cannot be used on this installation of Windows. Type a different product key. (CD-AB)</err0xC004E01D>
<err0xC004E01E>The new product key cannot be used on this installation of Windows. Type a different product key. (AB-AB)</err0xC004E01E>
<err0xC004E01F>The new product key cannot be used on this installation of Windows. Type a different product key. (AB-CD)</err0xC004E01F>
<err0xC004E020>The Software Licensing Service reported that there is a mismatched between a policy value and information stored in the OtherInfo section.</err0xC004E020>
<err0xC004E021>The Software Licensing Service reported that the Genuine information contained in the license is not consistent.</err0xC004E021>
<err0xC004E022>The Software Licensing Service reported that the secure store id value in license does not match with the current value.</err0xC004E022>
<err0x8004E101>The Software Licensing Service reported that the Token Store file version is invalid. </err0x8004E101>
<err0x8004E102>The Software Licensing Service reported that the Token Store contains an invalid descriptor table. </err0x8004E102>
<err0x8004E103>The Software Licensing Service reported that the Token Store contains a token with an invalid header/footer. </err0x8004E103>
<err0x8004E104>The Software Licensing Service reported that a Token Store token has an invalid name. </err0x8004E104>
<err0x8004E105>The Software Licensing Service reported that a Token Store token has an invalid extension. </err0x8004E105>
<err0x8004E106>The Software Licensing Service reported that the Token Store contains a duplicate token. </err0x8004E106>
<err0x8004E107>The Software Licensing Service reported that a token in the Token Store has a size mismatch. </err0x8004E107>
<err0x8004E108>The Software Licensing Service reported that a token in the Token Store contains an invalid hash. </err0x8004E108>
<err0x8004E109>The Software Licensing Service reported that the Token Store was unable to read a token. </err0x8004E109>
<err0x8004E10A>The Software Licensing Service reported that the Token Store was unable to write a token. </err0x8004E10A>
<err0x8004E10B>The Software Licensing Service reported that the Token Store attempted an invalid file operation. </err0x8004E10B>
<err0x8004E10C>The Software Licensing Service reported that there is no active transaction. </err0x8004E10C>
<err0x8004E10D>The Software Licensing Service reported that the Token Store file header is invalid. </err0x8004E10D>
<err0x8004E10E>The Software Licensing Service reported that a Token Store token descriptor is invalid. </err0x8004E10E>
<err0xC004F001>The Software Licensing Service reported an internal error.</err0xC004F001>
<err0xC004F002>The Software Licensing Service reported that rights consumption failed.</err0xC004F002>
<err0xC004F003>The Software Licensing Service reported that the required license could not be found.</err0xC004F003>
<err0xC004F004>The Software Licensing Service reported that the product key does not match the range defined in the license.</err0xC004F004>
<err0xC004F005>The Software Licensing Service reported that the product key does not match the product key for the license.</err0xC004F005>
<err0xC004F006>The Software Licensing Service reported that the signature file for the license is not available.</err0xC004F006>
<err0xC004F007>The Software Licensing Service reported that the license could not be found.</err0xC004F007>
<err0xC004F008>The Software Licensing Service reported that the license could not be found.</err0xC004F008>
<err0xC004F009>The Software Licensing Service reported that the grace period expired.</err0xC004F009>
<err0xC004F00A>The Software Licensing Service reported that the application ID does not match the application ID for the license.</err0xC004F00A>
<err0xC004F00B>The Software Licensing Service reported that the product identification data is not available.</err0xC004F00B>
<err0x4004F00C>The Software Licensing Service reported that the application is running within the valid grace period.</err0x4004F00C>
<err0x4004F00D>The Software Licensing Service reported that the application is running within the valid out of tolerance grace period.</err0x4004F00D>
<err0xC004F00F>The Software Licensing Service reported that the hardware ID binding is beyond the level of tolerance.</err0xC004F00F>
<err0xC004F010>The Software Licensing Service reported that the product key is invalid.</err0xC004F010>
<err0xC004F011>The Software Licensing Service reported that the license file is not installed.</err0xC004F011>
<err0xC004F012>The Software Licensing Service reported that the call has failed because the value for the input key was not found.</err0xC004F012>
<err0xC004F014>The Software Licensing Service reported that the product key is not available.</err0xC004F014>
<err0xC004F015>The Software Licensing Service reported that the license is not installed.</err0xC004F015>
<err0xC004F016>The Software Licensing Service determined that the request is not supported.</err0xC004F016>
<err0xC004F017>The Software Licensing Service reported that the license is not installed.</err0xC004F017>
<err0xC004F018>The Software Licensing Service reported that the license does not contain valid location data for the activation server.</err0xC004F018>
<err0xC004F01B>The Software Licensing Service reported that the event ID is already registered.</err0xC004F01B>
<err0xC004F01C>The Software Licensing Service reported that the license is not installed.</err0xC004F01C>
<err0xC004F01D>The Software Licensing Service reported that the verification of the license failed.</err0xC004F01D>
<err0xC004F021>The Software Licensing Service reported that the validity period of the license has expired.</err0xC004F021>
<err0xC004F022>The Software Licensing Service reported that the license authorization failed.</err0xC004F022>
<err0xC004F023>The Software Licensing Service reported that the license is invalid.</err0xC004F023>
<err0xC004F024>The Software Licensing Service reported that the license is invalid.</err0xC004F024>
<err0xC004F025>The Software Licensing Service reported that the action requires administrator privilege.</err0xC004F025>
<err0xC004F026>The Software Licensing Service reported that the required data is not found.</err0xC004F026>
<err0xC004F027>The Software Licensing Service reported that the license is tampered.</err0xC004F027>
<err0xC004F028>The Software Licensing Service reported that the policy cache is invalid.</err0xC004F028>
<err0xC004F02A>The Software Licensing Service reported that the license is invalid.</err0xC004F02A>
<err0xC004F02C>The Software Licensing Service reported that the format for the offline activation data is incorrect.</err0xC004F02C>
<err0xC004F02E>The Software Licensing Service determined that the version of the offline Confirmation ID (CID) is not supported.</err0xC004F02E>
<err0xC004F02F>The Software Licensing Service reported that the length of the offline Confirmation ID (CID) is incorrect.</err0xC004F02F>
<err0xC004F033>The Software Licensing Service reported that the product key is not allowed to be installed. Please see the eventlog for details.</err0xC004F033>
<err0xC004F034>The Software Licensing Service reported that the license could not be found or was invalid.</err0xC004F034>
<err0xC004F035>The Software Licensing Service reported that the computer could not be activated with a Volume license product key. Volume-licensed systems require upgrading from a qualifying operating system. Please contact your system administrator or use a different type of key.</err0xC004F035>
<err0xC004F038>The Software Licensing Service reported that the computer could not be activated. The count reported by your Key Management Service (KMS) is insufficient. Please contact your system administrator.</err0xC004F038>
<err0xC004F039>The Software Licensing Service reported that the computer could not be activated. The Key Management Service (KMS) is not enabled.</err0xC004F039>
<err0x4004F040>The Software Licensing Service reported that the computer was activated but the owner should verify the Product Use Rights.</err0x4004F040>
<err0xC004F041>The Software Licensing Service determined that the Key Management Service (KMS) is not activated. KMS needs to be activated. Please contact system administrator.</err0xC004F041>
<err0xC004F042>The Software Licensing Service determined that the specified Key Management Service (KMS) cannot be used.</err0xC004F042>
<err0xC004F047>The Software Licensing Service reported that the proxy policy has not been updated.</err0xC004F047>
<err0xC004F04F>The Software Licensing Service reported that license management information was not found in the licenses.</err0xC004F04F>
<err0xC004F050>The Software Licensing Service reported that the product key is invalid.</err0xC004F050>
<err0xC004F051>The Software Licensing Service reported that the product key is blocked.</err0xC004F051>
<err0xC004F052>The Software Licensing Service reported that the licenses contain duplicated properties. </err0xC004F052>
<err0xC004F054>The Software Licensing Service reported that license management information has duplicated data. </err0xC004F054>
<err0xC004F055>The Software Licensing Service reported that the base SKU is not available.</err0xC004F055>
<err0xC004F056>The Software Licensing Service reported that the computer could not be activated using the Key Management Service (KMS).</err0xC004F056>
<err0xC004F057>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F057>
<err0xC004F058>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F058>
<err0xC004F059>The Software Licensing Service reported that a license in the computer BIOS is invalid.</err0xC004F059>
<err0xC004F061>The Software Licensing Service determined that this specified product key can only be used for upgrading, not for clean installations.</err0xC004F061>
<err0xC004F062>The Software Licensing Service reported that a required license could not be found.</err0xC004F062>
<err0xC004F063>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F063>
<err0xC004F064>The Software Licensing Service reported that the non-genuine grace period expired.</err0xC004F064>
<err0x4004F065>The Software Licensing Service reported that the application is running within the valid non-genuine grace period.</err0x4004F065>
<err0xC004F066>The Software Licensing Service reported that the genuine information property can not be set before dependent property been set.</err0xC004F066>
<err0xC004F067>The Software Licensing Service reported that the non-genuine grace period expired (type 2).</err0xC004F067>
<err0x4004F068>The Software Licensing Service reported that the application is running within the valid non-genuine grace period (type 2).</err0x4004F068>
<err0xC004F069>The Software Licensing Service reported that the product SKU is not found.</err0xC004F069>
<err0xC004F06A>The Software Licensing Service reported that the requested operation is not allowed.</err0xC004F06A>
<err0xC004F06B>The Software Licensing Service determined that it is running in a virtual machine. The Key Management Service (KMS) is not supported in this mode.</err0xC004F06B>
<err0xC004F06C>The Software Licensing Service reported that the computer could not be activated. The Key Management Service (KMS) determined that the request timestamp is invalid.</err0xC004F06C>
<err0xC004F071>The Software Licensing Service reported that the plug-in manifest file is incorrect.</err0xC004F071>
<err0xC004F072>The Software Licensing Service reported that the license policies for fast query could not be found.</err0xC004F072>
<err0xC004F073>The Software Licensing Service reported that the license policies for fast query have not been loaded.</err0xC004F073>
<err0xC004F074>The Software Licensing Service reported that the computer could not be activated. No Key Management Service (KMS) could be contacted. Please see the Application Event Log for additional information.</err0xC004F074>
<err0xC004F075>The Software Licensing Service reported that the operation cannot be completed because the service is stopping.</err0xC004F075>
<err0xC004F076>The Software Licensing Service reported that the requested plug-in cannot be found.</err0xC004F076>
<err0xC004F078>The Software Licensing Service reported that the key is mismatched.</err0xC004F078>
<err0xC004F079>The Software Licensing Service reported that the authentication data is not set.</err0xC004F079>
<err0xC004F07A>The Software Licensing Service reported that the verification could not be done.</err0xC004F07A>
<err0xC004F07B>The requested operation is unavailable while the Software Licensing Service is running.</err0xC004F07B>
<err0xC004F200>The Software Licensing Service reported that current state is not genuine.</err0xC004F200>
<err0xC004F301>The Software Licensing Service reported that the computer could not be activated. The token-based activation challenge has expired.</err0xC004F301>
<err0xC004F302>The Software Licensing Service reported that Silent Activation failed. The Software Licensing Service reported that there are no certificates found in the system that could activate the product without user interaction.</err0xC004F302>
<err0xC004F303>The Software Licensing Service reported that the certificate chain could not be built or failed validation.</err0xC004F303>
<err0xC004F304>The Software Licensing Service reported that required license could not be found.</err0xC004F304>
<err0xC004F305>The Software Licensing Service reported that there are no certificates found in the system that could activate the product.</err0xC004F305>
<err0xC004F306>The Software Licensing Service reported that this software edition does not support token-based activation.</err0xC004F306>
<err0xC004F307>The Software Licensing Service reported that the computer could not be activated. Activation data is invalid.</err0xC004F307>
<err0xC004F308>The Software Licensing Service reported that the computer could not be activated. Activation data is tampered.</err0xC004F308>
<err0xC004F309>The Software Licensing Service reported that the computer could not be activated. Activation challenge and response do not match.</err0xC004F309>
<err0xC004F30A>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the conditions in the license.</err0xC004F30A>
<err0xC004F30B>The Software Licensing Service reported that the inserted smartcard could not be used to activate the product.</err0xC004F30B>
<err0xC004F30C>The Software Licensing Service reported that the token-based activation license content is invalid.</err0xC004F30C>
<err0xC004F30D>The Software Licensing Service reported that the computer could not be activated. The thumbprint is invalid.</err0xC004F30D>
<err0xC004F30E>The Software Licensing Service reported that the computer could not be activated. The thumbprint does not match any certificate.</err0xC004F30E>
<err0xC004F30F>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the criteria specified in the issuance license.</err0xC004F30F>
<err0xC004F310>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the trust point identifier (TPID) specified in the issuance license.</err0xC004F310>
<err0xC004F311>The Software Licensing Service reported that the computer could not be activated. A soft token cannot be used for activation.</err0xC004F311>
<err0xC004F312>The Software Licensing Service reported that the computer could not be activated. The certificate cannot be used because its private key is exportable.</err0xC004F312>
<err0xC004F313>The Software Licensing Service reported that the CNG encryption library could not be loaded. The current certificate may not be available on this version of Windows.</err0xC004F313>
<err0xC004FC03>A networking problem has occurred while activating your copy of Windows.</err0xC004FC03>
<err0x4004FC04>The Software Licensing Service reported that the application is running within the timebased validity period.</err0x4004FC04>
<err0x4004FC05>The Software Licensing Service reported that the application has a perpetual grace period.</err0x4004FC05>
<err0x4004FC06>The Software Licensing Service reported that the application is running within the valid extended grace period.</err0x4004FC06>
<err0xC004FC07>The Software Licensing Service reported that the validity period expired.</err0xC004FC07>
<err0xC004FE00>The Software Licensing Service reported that activation is required to recover from tampering of SL Service trusted store.</err0xC004FE00>
<err0xC004D101>The security processor reported an initialization error.</err0xC004D101>
<err0x8004D102>The security processor reported that the machine time is inconsistent with the trusted time.</err0x8004D102>
<err0xC004D103>The security processor reported that an error has occurred.</err0xC004D103>
<err0xC004D104>The security processor reported that invalid data was used.</err0xC004D104>
<err0xC004D105>The security processor reported that the value already exists.</err0xC004D105>
<err0xC004D107>The security processor reported that an insufficient buffer was used.</err0xC004D107>
<err0xC004D108>The security processor reported that invalid data was used.</err0xC004D108>
<err0xC004D109>The security processor reported that an invalid call was made.</err0xC004D109>
<err0xC004D10A>The security processor reported a version mismatch error.</err0xC004D10A>
<err0x8004D10B>The security processor cannot operate while a debugger is attached.</err0x8004D10B>
<err0xC004D301>The security processor reported that the trusted data store was tampered.</err0xC004D301>
<err0xC004D302>The security processor reported that the trusted data store was rearmed.</err0xC004D302>
<err0xC004D303>The security processor reported that the trusted store has been recreated.</err0xC004D303>
<err0xC004D304>The security processor reported that entry key was not found in the trusted data store.</err0xC004D304>
<err0xC004D305>The security processor reported that the entry key already exists in the trusted data store.</err0xC004D305>
<err0xC004D306>The security processor reported that the entry key is too big to fit in the trusted data store.</err0xC004D306>
<err0xC004D307>The security processor reported that the maximum allowed number of re-arms has been exceeded. You must re-install the OS before trying to re-arm again.</err0xC004D307>
<err0xC004D308>The security processor has reported that entry data size is too big to fit in the trusted data store.</err0xC004D308>
<err0xC004D309>The security processor has reported that the machine has gone out of hardware tolerance.</err0xC004D309>
<err0xC004D30A>The security processor has reported that the secure timer already exists.</err0xC004D30A>
<err0xC004D30B>The security processor has reported that the secure timer was not found.</err0xC004D30B>
<err0xC004D30C>The security processor has reported that the secure timer has expired.</err0xC004D30C>
<err0xC004D30D>The security processor has reported that the secure timer name is too long.</err0xC004D30D>
<err0xC004D30E>The security processor reported that the trusted data store is full.</err0xC004D30E>
<err0xC004D401>The security processor reported a system file mismatch error.</err0xC004D401>
<err0xC004D402>The security processor reported a system file mismatch error.</err0xC004D402>
<err0xC004D501>The security processor reported an error with the kernel data.</err0xC004D501>
.idata
.rdata
P.reloc
P.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MM Operation after uninstall.
Note: To obtain a log file containing detail on memory leaks, enable the "FullDebugMode" and "LogMemoryLeakDetailToFile" conditional defines. To disable this memory leak check, undefine "EnableMemoryLeakReporting".
If you want to use FastMM4, please make sure that FastMM4.pas is the very first unit in the "uses"
section of your project's .dpr file.
FastMM4.pas MUST be the first unit in your project's .dpr file, otherwise memory may be allocated
go into its configuration page and ensure that the FastMM4.pas unit is initialized before any other unit.
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s_%d
.Owner
EInvalidGraphicOperation
Uh}%C
Uh
USER32.DLL
Uh.DC
windows
comctl32.dll
uxtheme.dll
%s%s%s%s%s%s%s%s%s%s
Proportional
OnProgresshyD
MAPI32.DLL
PasswordChar
OnKeyDown<vD
OnKeyPress
OnKeyUp
ssHorizontal
UhCMD
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
TKeyEvent
TKeyPressEvent
HelpKeywordt
crSQLWait
%s (%s)
UhÞ
imm32.dll
AutoHotkeys
AutoHotkeys,
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
aatGotoWeb
iatWebBrowser
TAPMWindowStyle
awsShaped
absWindows
afsShowAll
TSPWindowStyle
swsShaped
TAPMWebBrowserControlBarStyle
Reverse transformation is not implemented in %s.
Forward transformation is not implemented in %s.
ÍROM%
%SysDir%
Þsktop%
ole32.dll
01234567
1.2.3
Portable Network Graphics
FormKeyDown
user32.dll
rlAutoKeyboard
Import\
Export\
%s - %s
RICHED20.DLL
RICHED32.DLL
olepro32.dll
hXXp://VVV.adobe.com/go/EN_US-H-GET-READER
CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\InprocServer32
IWebBrowser
IWebBrowserApp
IWebBrowser2
TWebBrowserStatusTextChange
TWebBrowserProgressChange
TWebBrowserCommandStateChange
TWebBrowserTitleChange
TWebBrowserPropertyChange
TWebBrowserBeforeNavigate2
TWebBrowserNewWindow2
TWebBrowserNavigateComplete2
TWebBrowserDocumentComplete
TWebBrowserOnVisible
TWebBrowserOnToolBar
TWebBrowserOnMenuBar
TWebBrowserOnStatusBar
TWebBrowserOnFullScreen
TWebBrowserOnTheaterMode
TWebBrowser
pcmdtReserved
TWebBrowserEx
WebBrowserEx
CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32
hXXp://VVV.macromedia.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash
"TWindowsMediaPlayerOpenStateChange
"TWindowsMediaPlayerPlayStateChange
&TWindowsMediaPlayerAudioLanguageChange
TWindowsMediaPlayerScriptCommand
TWindowsMediaPlayerDisconnect
TWindowsMediaPlayerBuffering
TWindowsMediaPlayerWarning
TWindowsMediaPlayerEndOfStream
!TWindowsMediaPlayerPositionChange
TWindowsMediaPlayerMarkerHit
%TWindowsMediaPlayerDurationUnitChange
#TWindowsMediaPlayerCdromMediaChange
!TWindowsMediaPlayerPlaylistChange
(TWindowsMediaPlayerCurrentPlaylistChange
/TWindowsMediaPlayerCurrentPlaylistItemAvailable
TWindowsMediaPlayerMediaChange
,TWindowsMediaPlayerCurrentMediaItemAvailable
$TWindowsMediaPlayerCurrentItemChange
6TWindowsMediaPlayerMediaCollectionAttributeStringAdded
8TWindowsMediaPlayerMediaCollectionAttributeStringRemoved
8TWindowsMediaPlayerMediaCollectionAttributeStringChanged
2TWindowsMediaPlayerPlaylistCollectionPlaylistAdded
4TWindowsMediaPlayerPlaylistCollectionPlaylistRemoved
9TWindowsMediaPlayerPlaylistCollectionPlaylistSetAsDeleted
TWindowsMediaPlayerModeChange
TWindowsMediaPlayerMediaError
%TWindowsMediaPlayerOpenPlaylistSwitch
TWindowsMediaPlayerDomainChange
TWindowsMediaPlayerClick
TWindowsMediaPlayerDoubleClick
TWindowsMediaPlayerKeyDown
nKeyCode
TWindowsMediaPlayerKeyPress
nKeyAscii
TWindowsMediaPlayerKeyUp
TWindowsMediaPlayerMouseDown
TWindowsMediaPlayerMouseMove
TWindowsMediaPlayerMouseUp
TWindowsMediaPlayer
URLXgL
OnKeyDown
OnKeyPressHuL
TWindowsMediaPlayer6DVDNotify
TWindowsMediaPlayer6EndOfStream
#TWindowsMediaPlayer6OpenStateChange
#TWindowsMediaPlayer6PlayStateChange
!TWindowsMediaPlayer6ScriptCommand
TWindowsMediaPlayer6Buffering
TWindowsMediaPlayer6MarkerHit
TWindowsMediaPlayer6Warning
TWindowsMediaPlayer6Disconnect
"TWindowsMediaPlayer6PositionChange
$TWindowsMediaPlayer6ReadyStateChange
TWindowsMediaPlayer6
TWindowsMediaPlayer6h
OnKeyUp<vD
SendKeyboardEvents
InvokeURLs
BaseURL
hXXp://VVV.microsoft.com/windows/windowsmedia/default.aspx
CLSID\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\InprocServer32
CLSID\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\InprocServer32
FormKeyPress
TfrmMsg
ÍROM%\
hXXp://
MSGFRAME
deflate 1.1.2 Copyright 1995-1998 Jean-loup Gailly
audiere.dll
_AdrGetSupportedAudioDevices@0
_AdrGetSupportedFileFormats@0
*.wsz
*.wav;*.ogg;*.mp3;*.mp2;*.mp1;*.mod;*.xm;*.s3m;*.it;*.flac;*.spx;*.aiff;*.m3u;*.pls
*.wav;*.ogg;*.mp3;*.mp2;*.mp1;*.mod;*.xm;*.s3m;*.it;*.flac;*.spx;*.aiff
*.m3u;*.pls
%s|%s|%s|%s|%s|%s
.JPEG
ActionInvalidExecutable
AlwaysShowPageZero
WindowStyle
SysMsgBox
AdminMsg
TAPMWebBrowser
TAPMWebBrowserD
APMWebBrowser
hXXp://VVV.microsoft.com/windows/ie/default.mspx
CLSID\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}\InProcServer32
AutoURLDetect
hXXps://
PTF://
\WININIT.INI
gdiplus.dll
GdiplusShutdown
GdipSetPenLineJoin
GdipGetPenLineJoin
GdipSetCustomLineCapStrokeJoin
GdipGetCustomLineCapStrokeJoin
GdipSetImageAttributesColorKeys
GdipSetStringFormatHotkeyPrefix
GdipGetStringFormatHotkeyPrefix
XPThemesSupportT
1.0.4
#%s%s%s
id="%s"
bgcolor="%s"
text="%s"
link="%s"
vlink="%s"
alink="%s"
face="%s"
size="%s"
color="%s"
align="%s"
href="%s"
type="%s"
name="%s"
method="%s"
<img src="%s"
width="%d"
height="%d"
size="%d"
value="%s"
var1="%s"
var2="%s"
var3="%s"
FontData\*.*
Can not load audiere.dll, music player control may not work.
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
1.1.2
inflate 1.0.4 Copyright 1995-1996 Mark Adler
GetKeyboardType
advapi32.dll
RegOpenKeyExA
RegCloseKey
RegFlushKey
RegCreateKeyExA
GetWindowsDirectoryA
GetCPInfo
version.dll
gdi32.dll
SetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
EnumWindows
EnumThreadWindows
ActivateKeyboardLayout
winspool.drv
shell32.dll
ShellExecuteExA
ShellExecuteA
comdlg32.dll
winmm.dll
oledlg.dll
.text
`.data
KERNEL32.dll
CRTDLL.DLL
.rsrc
%s,3]
n.UlI
)(Y.dYT
.dY.4H
8Y.dYD
\.Vz[#_
!#<848!#
!#,($(!#
.T.Nw
u%$W.ad
\.Gm
j.AU>
)Ø/,
/k7H%D
%D?5h
?@.Ba
.dlR1#Ql
Th%s'WF
.ld:D
- 9 6 2004
!"$%&')* ,-./0123456%
7889:;;<<==>?@
210/.-, *)'&%$"!
s.sf.net
f%.eS
")D %s
ET=v%d,
4M.FZz
@i@%d
3h%ug
KERNEL32.DLL
WINMM.dll
bgmusic.dll
d:\#]
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
KWindows
UrlMon
.JvProgressUtils
JvExExtCtrls
.JvPcx
rAPMWebBrowser
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
frmMsg
Picture.Data
CtrlIA.ControlType
name="Linasoft.AutoPlayMenuBuilder.Loader"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
NTDLL.DLL
USER32.dll
WS2_32.dll
SHLWAPI.dll
VERSION.dll
msvcrt.dll
choice.pdb
j@YSSh
MPR.dll
ntdll.dll
GetProcessHeap
GetConsoleOutputCP
@.reloc
OLEAUT32.dll
ADVAPI32.dll
cscript.exe
CreateURLMonikerEx
urlmon.dll
@@8X%uIj
%s%s.DLL
wintrust.dll
Invalid parameter passed to C runtime function.
0x%8X
SOFTWARE\Classes\%s\%s
PSShL
RegCreateKeyExW
RegOpenKeyExW
ReportEventW
RegEnumKeyExA
RegCreateKeyA
cscript.pdb
stdole2.tlbWWW
.ObjectWW
KeyW
WindowsFolderWWW4
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Object
5064686<6^6
`.rdata
Name: %s; Password: %s
%s: Error %d from %s on line %d
d:\nt\sdktools\reskit\content\instsrv\source\instsrv.c
mscoree.dll
Please contact the application's support team for more information.
GetProcessWindowStation
instsrv.pdb
@.data
SSSh0GB
__MSVCRT_HEAP_SELECT
RPCRT4.dll
F#Z%U
.WUX^f:
Windows 7 activation code is delivered successfully!
ZWT Keygen for Windows 7 Pro
Error is: %s
%s failed with error %d: %s
ncacn_ip_tcp
Error: 0x%x
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x%x' to display the error text.
osppc.dll
MSVCR90.dll
_crt_debugger_hook
_amsg_exit
t:\licensing\x86\ship\0\ospprearm.pdb
ship\0\ospprearm.exe\bbtopt\ospprearmO.pdb
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.1" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
3hXXp://crl.microsoft.com/pki/crl/products/CSPCA.crl0H
,hXXp://VVV.microsoft.com/pki/certs/CSPCA.crt0
3hXXp://crl.microsoft.com/pki/crl/products/tspca.crl0H
,hXXp://VVV.microsoft.com/pki/certs/tspca.crt0
hXXp://office.microsoft.com 0
.Rich
t.VhT
.8\4%u(h4
GetAsyncKeyState
WLDAP32.dll
NETAPI32.dll
GetTcpTable
GetUdpTable
iphlpapi.dll
PSAPI.DLL
Invalid port specified with -o option: %s
Invalid port order entered with -o option: %s
Valid ports: 1-65535
Winsock initialization error: %d
Initial source port set to %d
Processing local system's ports...
Invalid port range specified.
Port range specified is invalid
Check the start port
Port range specified is invalid.
Check the start port.
Invalid port range specified.
Check end port
Valid port range 1-65535
portqry -r 25:100
Error creating or opening file %s
PortQry is stopping without generating a report file.
Invalid source port specified.
-wport
Invalid destination port specified.
Invalid port order entered. -o option requires parameters
Invalid host name entered: %s
Invalid IP address entered: %s
Invalid port specified
/wport
-wport
System Date: %s
PortQry Version 2.0 Log File
Creating log file called %s
Overwriting %s
A file called %s already exists
Slow link delay for UDP enabled
PortQry version 2.0 GOLD
PortQry version 2.0 Gold
portqry -wport 53 -l dnslog.txt
portqry -wpid 1272 -wt 5 -l logfile.txt -y -v
portqry -local -l logfile.txt -v
portqry -local
Port to process mapping may not be available on all systems
reports when PID's connection status changes
reports when port's connection status changes
-wport [port_number] watches specified port
-local enumerates local port usage, port to process mapping,
service port usage, and lists loaded modules
Local Mode used to get detailed data on local system's ports
portqry -local | -wpid pid | -wport port [-wt seconds] [-l logfile] [-v]
portqry -i -n server1 -e 135 -p both
- run portqry.exe
portqry -i [-options]
portqry -n host2 -cn !my community name! -e 161 -p udp
portqry -n host1.dev.reskit.com -r 21:445
portqry -n 10.0.0.1 -o 25,445,1024 -p both -sp 53
portqry -n myserver.com -e 25
portqry -n 10.0.0.1 -e 53 -p UDP -i
Defaults: TCP, port 80, no log file, slow link delay off
Notes: PortQry runs on Windows 2000 and later systems
-q 'quiet' operation runs with no output
returns 0 if port is listening
returns 1 if port is not listening
returns 2 if port is listening or filtered
ignored unless querying an SNMP port
-nr by-passes default IP address-to-name resolution
-sl 'slow link delay' waits longer for UDP replies from remote systems
-sp [source port] initial source port to use for query
-o [end point order] range of ports to query in an order (x,y,z)
-r [end point range] range of ports to query (start:end)
-e [endpoint] single port to query (valid range: 1-65535)
-p [protocol] TCP or UDP or BOTH (default is TCP)
portqry -n name_to_query [-p protocol] [-e || -r || -o endpoint(s)] [-q]
[-l logfile] [-sp source_port] [-sl] [-cn SNMP community name]
Local Mode: portqry -local | -wpid pid| -wport port [-options]
Interactive mode: portqry -i [-n name_to_query] [-options]
Command line mode: portqry -n name_to_query [-options]
PortQry version 2.0
Displays the state of TCP and UDP ports
WSAVERNOTSUPPORTED (10092): WinSock version requested not supported.
WSAEAFNOSUPPORT (10047): Address family not supported by protocol.
WSAEINPROGRESS (10036): Operation is in progress.
WSAEINTR (10004): A blocking Windows Socket 1.1 call was canceled.
Data returned from port:
error: %d
Error: %d
Port did not return extended data - request timed out
smtp
TCP port %i (%s service): LISTENING
Error opening socket: %d
TCP port %i (%s service): FILTERED
TCP port %i (%s service): NOT LISTENING
Cannot use specified source port
Winsock error %d
Port %d is already in use
Specify a port that is not in use and run the command again
Port is already in use
Error Opening socket: error %d
Error Opening socket: Error %d
IP address resolved to %s
Name resolved to %s
ms-sql-m
No response from udp port %i (%s service)
UDP port %i (%s service): LISTENING
Error accessing port %i
tftp
ms-sql-m
UDP port %i (%s service): LISTENING or FILTERED
UDP port %i (%s service): NOT LISTENING
PortQry encountered an error while attempting to send data to the target system
PortQry Test Message
source port is the same as the destination port
127.0.0.1
run PortQry to query ISAKMP
Cannot use source port %d, this port is already in use
Remote ISAKMP/IPSec services may only communicate with source port 500
on the system you are running PortQry from and run the command again
UDP port 500
Using source port UDP 500
UDP port %i is LISTENING
Using ephemeral source port
Sending LDAP query to TCP port %i...
LDAP query to port %i failed
Sending LDAP query to UDP port %i...
currentdate: %s/%s/%s %s:%s:%s (unadjusted GMT)
currentdate: %s/%s/%s %s:%s:%s (unadjusted GMT)
Log file %s successfully created in current directory
Error closing file %s. Program stopped abnormally. Output may not be complete.
PortQry developed by Tim Rains
Failed to parse Endpoint Mapper's response (%x)
RPC query failed (%x).
TCP port %i is FILTERED
UDP port %i is FILTERED
UUID: %s %s
Error attempting to query the End Point Mapper (%x)
Error encountered attempting to bind to the RPC server (%x)
Error attempting to bind to the RPC server (%x)
ncadg_ip_udp
UDP port: LISTENING
UDP port: FILTERED
NETBIOS name for %s not found (timeout)
Attempting NETBIOS adapter status query to UDP port 137...
Sending ISA query to UDP port %i...
No response from TCP port %i
Error waiting for response: %d
No extended data was returned from the port
PortQry encountered an error while attempting to query the target system
Sending ISA query to TCP port %i...
Sending SNMP query to UDP port %i...
By default PortQry uses the community name: public
Sending DNS query to UDP port %i...
Sending SQL Server query to UDP port %i...
No response from UDP port %i
UDP port %i (%s service): FILTERED
Sending TFTP query to UDP port %i...
Sending L2TP query to UDP port %i...
==== End of SQL Server query response ====
PortQry requires exclusive use of source port UDP 500 for this operation
This port is already in use so PortQry cannot use it
Remote ISAKMP services may only communicate with source port UDP 500
For best results run PortQry in the context of
prevent PortQry from accessing more information
Port and Module Information by Process
AllocateAndGetUdpExTableFromStack
AllocateAndGetTcpExTableFromStack
TCP table not found
UDP table not found
Failed to get TCP endpoints.
Failed to get UDP endpoints.
TCP ports in an UNKNOWN state:
%d = %.2f%%
TCP ports in a DELETE TCB state:
TCP ports in a TIME WAIT state:
TCP ports in a LAST ACK state:
TCP ports in a CLOSING state:
TCP ports in a CLOSE WAIT state:
TCP ports in a FIN WAIT-2 state:
TCP ports in a FIN WAIT-1 state:
TCP ports in a ESTABLISHED state:
TCP ports in a SYN RECEIVED state:
TCP ports in a SYN SENT state:
TCP ports in a LISTENING state:
TCP ports in a CLOSED state:
Port Statistics
TCP mappings: %d
UDP mappings: %d
UDP %i
UDP %i
%d:%s UDP %i
%d:%s
%d:%s UDP %i
%s:%d
%s:%d
TCP %i
TCP %i
%d:%s TCP %i
%d:%s TCP %i
Port
Remote IP:Port
Port
Remote IP:Port
%d mappings found
TCP/UDP Port to Process Mappings
No active ports found on local system
Port
%d active ports found
TCP/UDP Port Usage
Port to process mappings unavailable
%s (0xX)
Process ID: %u
Display Name: %s
Service Name: %s
exiting PortQry Interactive Mode...
TFTP - queries UDP port 69
SQL - queries TCP port 1433 & UDP port 1434
SNMP - queries UDP port 161
SMTP - queries TCP port 25
RPC - queries TCP & UDP port 135
POP3 - queries TCP port 110
MAIL - queries TCP ports 25,110,143
L2TP - queries UDP port 1701
LDAP - queries TCP & UDP port 389
ISA - queries TCP & UDP port 1745
IPSEC - queries UDP port 500
IMAP - queries TCP port 143
FTP - queries TCP port 21
DNS - queries TCP & UDP port 53
sl - toggles slow link delay for UDP queries
- doubles timeout period waiting for UDP responses
protocol=p - set protocol used for query, TCP, UDP, or BOTH
sport=n - set source port number, 0=ephemeral
- set sport= or set sp=
port=n - set port number to query
- set port= or set e=
phelp or ?p - display list of frequently used ports
SNMP community name: %s
Default Node: %s
TFTP
SMTP
*** PortQry version 2.0 ***
*** Can't find address for node %s
%s resolved to %s
WHO DEVELOPED PORTQRY?
slow link delay for UDP disabled
slow link delay for UDP enabled
valid protocol values include: TCP, UDP, and BOTH
example: set protocol=tcp
source port value must be a valid number between 0 and 65535
example: set sport=1200
port value must be a valid number between 1 and 65535
example: set port=53
Type 'phelp' for a sample list of valid ports
Invalid option specified: %s
slow link delay for UDP enabled
source port=
end port=
0.0.0.0
exiting PortQry...
PortQry Interactive Mode
Winsock error: %d
3389 TCP RDP
1701 UDP L2TP
1723 TCP PPTP
1434 TCP/UDP Microsoft-SQL-Monitor
1433 TCP/UDP Microsoft-SQL-Server
500 UDP Internet Key Exchange (IPSec)
464 TCP/UDP Kerberos (v5)
445 TCP/UDP Microsoft CIFS
443 TCP HTTPS
389 TCP/UDP LDAP
162 UDP SNMP TRAP
161 UDP SNMP
143 TCP IMAP4
139 TCP NETBIOS Session Service
138 UDP NETBIOS Datagram Service
137 TCP/UDP NETBIOS Name Service
135 TCP/UDP RPC/DCOM
110 TCP POP3
88 TCP/UDP Kerberos
80 TCP HTTP
69 UDP TFTP
67 UDP DHCP Server
53 TCP/UDP DNS
25 TCP SMTP
23 TCP Telnet
21 TCP FTP-control
20 TCP FTP-data
Port TCP/UDP Service
Frequently Used Ports
UDP port resolved to the '%s' service
TCP port resolved to the '%s' service
escape key pressed: stopped watching port %d
press escape key to stop watching port
UDP mappings: 0
TCP mappings: 0
Specified port currently does not have any port mappings
Watching port: %d
**press escape to stop watching port
Checking for changes every %d seconds
**press escape to stop watching port and close log file
PortQry Version 2.0
Port to process mapping is not supported on this system
escape key pressed: stopped watching PID %d
press escape key to stop watching PID
Specified PID currently does not have any port mappings
Watching PID: %d
zcÁ
OS2SSService-%d
OS2.EXE /S /P
OS2.EXE /S /P C:\OS2\PMSHELL.EXE /C C:\OS2\PMSHELL.EXE
srvany.pdb
2.1.4.0, Mon 03/02/2009 12:32:57.69
SLGetInstalledProductKeyIds
SLGetPKeyId
SLGetPKeyInformation
SLSetCurrentProductKey
osppc.pdb
F64.Mo&
<$=*=8=\>
; ;<;@;\;`;
;(;,;0;4;
8hXXp://crl.microsoft.com/pki/crl/products/CodeSigPCA.crl0M
1hXXp://VVV.microsoft.com/pki/certs/CodeSigPCA.crt0
ChXXp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
<hXXp://VVV.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
$Microsoft Root Certificate Authority0
$Microsoft Root Certificate Authority
?hXXp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8hXXp://VVV.microsoft.com/pki/certs/MicrosoftRootCert.crt0
.tq[m
8hXXp://VVV.microsoft.com/pki/certs/MicrosoftRootCert.crt0v
hXXp://VVV.microsoft.com0
Signature="$Windows NT$"
AddReg=Add.Reg
[Add.Reg]
HKLM,"SYSTEM\CurrentControlSet\services\KMService","ImagePath",0x20000,"%\srvany.exe"
HKLM,"SYSTEM\CurrentControlSet\services\KMService\Parameters","Application",0x0,"%\KMService.exe"
echo Microsoft (R) Windows Software Licensing.
PortQry -n 127.0.0.1 -e 1688 | findstr /i /r NOT.LISTENING >nul && goto:starts
echo Press 1 to install KMS emulator as Windows Service.
IF ERRORLEVEL 2 echo Emulator running... & start /b KMService.exe >nul && echo
1>nul 2>nul copy /y srvany.exe %WINDIR%\System32 & 1>nul 2>nul copy /y KMService.exe %WINDIR% && echo
1>nul 2>nul instsrv.exe KMService %WINDIR%\System32\srvany.exe && echo
1>nul 2>nul rundll32 advpack,LaunchINFSection service.inf,DefaultInstall,0 && echo
echo Remove KMS host name (sets port to default).
1>nul 2>nul cscript ospp.vbs /remhst
1>nul 2>nul REG DELETE "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\59a52881-a989-479d-af46-f275c6370663" /f
echo Key Management Service machine name set to Localhost successfully.
1>nul 2>nul cscript ospp.vbs /sethst:127.0.0.1
echo Please wait. Executing activation requests...
cscript ospp.vbs /act | find /i "0xC004F074" >nul
if /i %i% == 8 ospprearm.exe >nul & ping -n 2 localhost >nul & goto:second
cscript ospp.vbs /act >check
echo 3. Also try to reinstall KMS-Client key of Office 2010.
status: OK & echo. & cscript ospp.vbs /dstatus & echo Activation successful. %i% attempt(s) used. & goto:end
IF ERRORLEVEL 1 tasklist /fi "imagename eq KMService.exe" 2>nul | find /i /n "KMService.exe" >nul && taskkill /t /f /im KMService.exe 1>nul 2>nul
echo Press any key to exit...
2>nul REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentVersion | findstr /i 6.* 1>nul
cscript VL.vbs | find /i "NOVOLUME" >nul
PortQry -n 127.0.0.1 -e 1688 | findstr /i /r NOT.LISTENING > nul && goto:starts
choice /C YN /N /M "Is Windows KMS Client key installed? [y/n]: "
echo Key Management Service machine name set to Localhost...
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -skms 127.0.0.1 >check
1>nul 2>nul findstr /l "127.0.0.1" check
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ato | find /i "0xC004F074" >nul
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ato >check
status: OK & echo. & echo. & echo --------------------------------------------------------- & echo. & cscript "%SYSTEMROOT%\System32\slmgr.vbs" -dlv & echo --------------------------------------------------------- & echo. & echo Activation successful. %i% attempt(s) used. & del check & goto:end
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Professional" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:AA
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Professional N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:BB
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:CC
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise E" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:DD
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:EE
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 HPC Edition" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:FF
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Datacenter" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:GG
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:HH
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Itanium" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:II
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Standard" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:JJ
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Web Server 2008 R2" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:KK
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Business" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:LL
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Business N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:M
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:NN
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Enterprise N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:OO
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Datacenter" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:PP
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Itanium" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:QQ
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:RR
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Standard" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:SS
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Web Server (R) 2008" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:TT
echo Select your Windows edition from the list: & echo. & goto:keys
:keys
echo ## Windows KMS Client keys manager (6.0; 6.1) ##
:keys1
echo a) Windows 7 Professional l) Windows Vista Business
echo b) Windows 7 Professional N m) Windows Vista Business N
echo c) Windows 7 Enterprise n) Windows Vista Enterprise
echo d) Windows 7 Enterprise E o) Windows Vista Enterprise N
echo e) Windows 7 Enterprise N p) Windows Server 2008 Datacenter
echo f) Windows Server 2008 R2 HPC Edition q) Windows Server 2008 Itanium
echo g) Windows Server 2008 R2 Datacenter r) Windows Server 2008 Enterprise
echo h) Windows Server 2008 R2 Enterprise s) Windows Server 2008 Standard
echo i) Windows Server 2008 R2 Itanium t) Windows Server 2008 Web
echo j) Windows Server 2008 R2 Standard
echo k) Windows Server 2008 R2 Web
choice /C abcdefghijklmnopqrst /N /M "Select installed Windows edition [a-t]: "
set a=Windows 7 Professional
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4 | find /i "FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4" >nul
set a=Windows 7 Professional N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk MRPKT-YTG23-K7D7T-X2JMM-QY7MG | find /i "MRPKT-YTG23-K7D7T-X2JMM-QY7MG" >nul
set a=Windows 7 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 33PXH-7Y6KF-2VJC9-XBBR8-HVTHH | find /i "33PXH-7Y6KF-2VJC9-XBBR8-HVTHH" >nul
set a=Windows 7 Enterprise E
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YDRBP-3D83W-TY26F-D46B2-XCKRJ | find /i "YDRBP-3D83W-TY26F-D46B2-XCKRJ" >nul
set a=Windows 7 Enterprise N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk C29WB-22CC8-VJ326-GHFJW-H9DH4 | find /i "C29WB-22CC8-VJ326-GHFJW-H9DH4" >nul
set a=Windows Server 2008 R2 HPC Edition
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk FKJQ8-TMCVP-FRMR7-4WR42-3JCD7 | find /i "FKJQ8-TMCVP-FRMR7-4WR42-3JCD7" >nul
set a=Windows Server 2008 R2 Datacenter
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 74YFP-3QFB3-KQT8W-PMXWJ-7M648 | find /i "74YFP-3QFB3-KQT8W-PMXWJ-7M648" >nul
set a=Windows Server 2008 R2 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 489J6-VHDMP-X63PK-3K798-CPX3Y | find /i "489J6-VHDMP-X63PK-3K798-CPX3Y" >nul
set a=Windows Server 2008 R2 Itanium
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk GT63C-RJFQ3-4GMB6-BRFB9-CB83V | find /i "GT63C-RJFQ3-4GMB6-BRFB9-CB83V" >nul
set a=Windows Server 2008 R2 Standard
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YC6KT-GKW9T-YTKYR-T4X34-R7VHC | find /i "YC6KT-GKW9T-YTKYR-T4X34-R7VHC" >nul
set a=Windows Web Server 2008 R2
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 6TPJF-RBVHG-WBW2R-86QPH-6RTM4 | find /i "6TPJF-RBVHG-WBW2R-86QPH-6RTM4" >nul
set a=Windows Vista Business
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YFKBB-PQJJV-G996G-VWGXY-2V3X8 | find /i "YFKBB-PQJJV-G996G-VWGXY-2V3X8" >nul
set a=Windows Vista Business N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk HMBQG-8H2RH-C77VX-27R82-VMQBT | find /i "HMBQG-8H2RH-C77VX-27R82-VMQBT" >nul
set a=Windows Vista Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk VKK3X-68KWM-X2YGT-QR4M6-4BWMV | find /i "VKK3X-68KWM-X2YGT-QR4M6-4BWMV" >nul
set a=Windows Vista Enterprise N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk VTC42-BM838-43QHV-84HX6-XJXKV | find /i "VTC42-BM838-43QHV-84HX6-XJXKV" >nul
set a=Windows Server 2008 Datacenter
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 7M67G-PC374-GR742-YH8V4-TCBY3 | find /i "7M67G-PC374-GR742-YH8V4-TCBY3" >nul
set a=Windows Server 2008 Itanium
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 4DWFP-JF3DJ-B7DTH-78FJB-PDRHK | find /i "4DWFP-JF3DJ-B7DTH-78FJB-PDRHK" >nul
set a=Windows Server 2008 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YQGMW-MPWTJ-34KDK-48M3W-X4Q6V | find /i "YQGMW-MPWTJ-34KDK-48M3W-X4Q6V" >nul
set a=Windows Server 2008 Standard
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk TM24T-X9RMF-VWXK6-X8JC9-BFGM2 | find /i "TM24T-X9RMF-VWXK6-X8JC9-BFGM2" >nul
set a=Windows Web Server 2008
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk WYR28-R7TFJ-3X2YQ-YCY4H-M249D | find /i "WYR28-R7TFJ-3X2YQ-YCY4H-M249D" >nul
echo The function can work on Windows 6.0 or newer only.
echo Error! After %i% plenty of attempts Windows activation failed.
if /i %b% == 3 echo Error! Key %i% installation failed. & goto:end
echo Error! Key %i% installation failed. Try more.
goto:keys1
echo Key %i% successfully installed.
echo Error! Operation is not completed.
echo Windows edition detected is not a VL edition.
echo. & cscript ospp.vbs /dstatus
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -dlv
echo ## Key Manager Office 2010 VL ##
1>nul 2>nul cscript ospp.vbs /unpkey:H3GVB
echo Product key uninstall successful.
cscript ospp.vbs /inpkey:VYBBJ-TRJPB-QFQRF-QFT4D-H3GVB | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:8R6BM
cscript ospp.vbs /inpkey:V7QKV-4XVVR-XYV4D-F7DFM-8R6BM | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:VVRCK
cscript ospp.vbs /inpkey:D6QFG-VBYP2-XQHM7-J97RH-VVRCK | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:VHKC6
cscript ospp.vbs /inpkey:YGX6F-PGV49-PGW3J-9BTGG-VHKC6 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:F9PGB
cscript ospp.vbs /inpkey:4HP3K-88W3F-W2K3D-6677X-F9PGB | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:WX8BJ
cscript ospp.vbs /inpkey:D9DWC-HPYVV-JGF4P-BTWQB-WX8BJ | find /i "0xC004F050" >nul
set i=7MCW8-VRQVK-G677T-PDJCM-Q8TCP
1>nul 2>nul cscript ospp.vbs /unpkey:Q8TCP
cscript ospp.vbs /inpkey:7MCW8-VRQVK-G677T-PDJCM-Q8TCP | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:KHFGJ
cscript ospp.vbs /inpkey:767HD-QGMWX-8QTDB-9G3R2-KHFGJ | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:38W9R
cscript ospp.vbs /inpkey:YBJTT-JG6MD-V9Q7P-DBKXJ-38W9R | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:B8K32
cscript ospp.vbs /inpkey:7TC2V-WXF6P-TD7RT-BQRXR-B8K32 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:CRY7T
cscript ospp.vbs /inpkey:HVHB3-C6FV7-KQX9W-YQG79-CRY7T | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:CW9BM
cscript ospp.vbs /inpkey:H62QG-HXVKF-PP4HP-66KMR-CW9BM | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:P4VTT
cscript ospp.vbs /inpkey:RC8FX-88JRY-3PF7C-X8P67-P4VTT | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:X3DWQ
cscript ospp.vbs /inpkey:7YDC2-CWM8M-RRTJC-8MDVC-X3DWQ | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:T7DDX
cscript ospp.vbs /inpkey:V7Y44-9T38C-R2VJK-666HK-T7DDX | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:4T3J4
cscript ospp.vbs /inpkey:QYYW6-QP4CB-MBV6G-HYMCJ-4T3J4 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:BT37T
cscript ospp.vbs /inpkey:K96W8-67RPQ-62T9Y-J8FQJ-BT37T | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:D3XHX
cscript ospp.vbs /inpkey:Q4Y4M-RHWJM-PY37F-MTKWH-D3XHX | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:83YTP
cscript ospp.vbs /inpkey:BFK7F-9MYHM-V68C7-DRQ66-83YTP | find /i "0xC004F050" >nul
echo Selected key %i% successfully installed.
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:A
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:B
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:C
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:D
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:E
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:F
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:G
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:H
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:I
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:J
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:K
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:L
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:N
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:O
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:P
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:Q
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:R
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:S
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:T
tasklist /fi "imagename eq KMService.exe" 2>nul | find /i /n "KMService.exe" >nul && taskkill /t /f /im KMService.exe 1>nul 2>nul && echo
1>nul 2>nul del %WINDIR%\System32\srvany.exe & ping -n 3 localhost >nul & 1>nul 2>nul del %WINDIR%\KMService.exe && echo
ospprearm.exe | find /i "Microsoft Office rearm successful." >nul
1>nul 2>nul cscript ospp.vbs /osppsvcrestart
choice /C YN /N /M "You have selected Windows trial reset. Continue? [y/n]: "
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -rearm
IF NOT ERRORLEVEL 1 cscript HS_MESSAGE.vbs "KMService it is successfully restarted." "Activation Tool" I OK & exit
IF ERRORLEVEL 1 cscript HS_MESSAGE.vbs "KMService it not installing or not running." "Activation Tool" E OK & exit
relese date 29.04.2010
The activator is based on ZWT KMS-Keygen.
KMS-Keygen is installed as Windows Service, not too much memory used, around 2 mb of RAM.
Code generated by KMS-Keygen is not always valid, that
This is KMS-Keygen problem, but not the the activator fault.
Activator works on 32 and 64 edition of Office 2010 and Windows 6.0 or newer.
Trial reset for all Office 2010 products and Windows 6.0 or newer
Entering of KMS-Client keys for all Windows VL editions
Activation of Windows 6.0 VL products
Activation status check of Windows 6.0 products
In Volume versions of Office 2010 KMS client key is installed by default
s recommended to reinstall Office 2010 VL keys
For Windows activation you have to install the respective KMS client key first.
Windows key depends on edition of product installed! (Enterprise, Professional, Home etc).
1.051 - Optimized error recognition during Office 2010 and Windows activation,
and while entering windows keys.
1.052 - Office 2010 products trial reset is based on final RTM release 14.0.4763.1000.
Fixed: On some systems menu inaccessible (flashing cmd window).
For activation You have choice: run KMS server as windows service or run it once.
Added: Installed OS is automatically determined and the respective key is installed without asking user.
Added detection of activation possibility using volume license channel (for Windows 6.1).
Added GVLK keys for all office 2010 products (Thanks swmyp & Dark_Diver).
Optimized installation and removing of KMService on Windows Server 2003.
Used unpacked ZWT KMS-keygen (Thanks Dark_Diver).
* Activator work depends on generated by ZWT KMS-Keygen activation codes.
ZWT KMS-keygen.
KMS-keygen
Windows,
, KMS-keygen
Windows
Windows;
Windows.
14.0.4763.1000.
Windows 6.1)
Windows Server 2003.
ZWT KMS-keygen,
ZWT KMS-keygen'
Windows NT 6.0
Windows 7 Professional; Windows 7 Professional N; Windows 7 Enterprise; Windows 7 Enterprise E; Windows 7 Enterprise N;
Windows Server 2008 R2 HPC Edition; Windows Server 2008 R2 Datacenter; Windows Server 2008 R2 Enterprise; Windows Server 2008 R2 Itanium;
Windows Server 2008 R2 Standard; Windows Server 2008 R2 Web; Windows Vista Business; Windows Vista Business N; Windows Vista Enterprise;
Windows Vista Enterprise N; Windows Server 2008 Datacenter; Windows Server 2008 Itanium; Windows Server 2008 Enterprise;
Windows Server 2008 Standard; Windows Server 2008 Web.
, Windows 7 Ultimate?
KMS-keygen
Windows VL".
Windows
Windows - 10.
(KMS-keygen)
Windows?
127.0.0.1.
ZWT KMS-keygen
Windows VL".
Windows KMS Client
) Windows?
Windows".
Windows.On Error Resume Next
Set Args=WScript.Arguments
Set WshShell=WScript.CreateObject("WScript.Shell")
If Args.Count<4 Or Args.Count>5 Then WScript.Quit(255)
If Args.Count=5 Then nSecondsToWait=Args(4) Else nSecondsToWait=0
WScript.Quit( WshShell.Popup(strText, nSecondsToWait, strTitle, nType) )
CONST HKEY_LOCAL_MACHINE =&H80000002
CONST KEY_SET_VALUE =&H0002
CONST KEY_QUERY_VALUE =&H0001
CONST OfficeAppId = "59a52881-a989-479d-af46-f275c6370663"
CONST STR_SYS32PATH = ":\Windows\System32\"
CONST MSG_NOREGRIGHTS = "Insufficient rights to perform operation."
CONST MSG_ISCMD_ELEVATED = "Ensure cmd.exe is elevated (right click > run as administrator)."
CONST MSG_CREDENTIALFAILURE = "Connection failed with passed credentials."
CONST MSG_FILENOTFOUND = "File not found: "
CONST MSG_CREDENTIALERR = "Passing credentials not supported for this option."
CONST MSG_SEPERATE = "---------------------------------------------------------"
CONST MSG_PROCESSING = " "
CONST MSG_EXIT = " "
CONST MSG_UNSUPPORTED = "Unsupported command passed."
CONST MSG_SUCCESS = "Successfully applied setting."
CONST MSG_ACTATTEMPT = "Installed product key detected - attempting to activate the following product:"
CONST MSG_TOKACTATTEMPT = "Installed product key detected - attempting to token activate the following product:"
CONST MSG_NOKEYSINSTALLED = "<No installed product keys detected>"
CONST MSG_UNINSTALLKEYSUCCESS = "<Product key uninstall successful>"
CONST MSG_ACTSUCCESS = "<Product activation successful>"
CONST MSG_OFFLINEACTSUCCESS = "<Offline product activation successful>"
CONST MSG_KEYINSTALLSUCCESS = "<Product key installation successful>"
CONST MSG_PARTIALKEY = "Last 5 characters of installed product key: "
CONST MSG_UNINSTALLKEY = "Uninstalling product key for: "
CONST MSG_UNRECOGFILE = "Unrecognized file. Office 2010 licenses have an .xrm-ms file extension."
CONST MSG_INSTALLLICENSE = "Installing Office 2010 license: "
CONST MSG_INSTALLLICSUCCESS = "Office 2010 license installed successfully."
CONST MSG_SEARCHEVENTSKMS = "Searching for KMS activation events on machine: "
CONST MSG_SEARCHEVENTSRET = "Searching for Internet activation failure events on machine: "
CONST MSG_NOEVENTSSKMS = "No KMS activation events found on machine: "
CONST MSG_NOEVENTSRET = "No failure events found on machine: "
CONST MSG_OSPPSVC_NOINSTALL = "Error: The Software Protection Platform service is not installed."
CONST MSG_OSPPSVC_NORUN = "Error: The Software Protection Platform service is not running."
CONST MSG_ERRPARTIALKEY = "The last 5 characters of an installed product key are required to run this option. Run the /dstatus option to display the partial product key."
CONST MSG_KEYNOTFOUND = "<Product key not found>"
CONST MSG_CMID = "Client Machine ID (CMID): "
CONST MSG_NOLICENSEFOUND = "<No licenses found>"
CONST MSG_REMILID = "Removed Token-based Activation License with License ID (ILID): "
CONST MSG_NOTFOUNDILID = "License not found with License ID (ILID): "
CONST MSG_SKUID = "SKU ID: "
CONST MSG_LICENSENAME = "LICENSE NAME: "
CONST MSG_DESCRIPTION = "LICENSE DESCRIPTION: "
CONST MSG_LICSTATUS = "LICENSE STATUS: "
CONST MSG_LICENSED = " ---LICENSED--- "
CONST MSG_UNLICENSED = " ---UNLICENSED--- "
CONST MSG_OOBGRACE = " ---OOB_GRACE--- "
CONST MSG_OOTGRACE = " ---OOT_GRACE--- "
CONST MSG_NONGENGRACE = " ---NON_GENUINE_GRACE--- "
CONST MSG_NOTIFICATION = " ---NOTIFICATIONS--- "
CONST MSG_EXTENDEDGRACE = " ---EXTENDED GRACE--- "
CONST MSG_LICUNKNOWN = " ---UNKNOWN--- "
CONST MSG_REMAINGRACE = "REMAINING GRACE: "
CONST MSG_ERRCODE = "ERROR CODE: "
CONST MSG_ERRDESC = "ERROR DESCRIPTION: "
CONST MSG_ERRUNKNOWN = "An unknown error occurred."
CONST MSG_ERRCODEVALUE = "An error code must start with '0x'. Example: 0xC004F009"
Set WshShell = WSCript.CreateObject("WSCript.Shell")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objNetwork = WSCript.CreateObject("WSCript.Network")
currentDir = Left(WScript.ScriptFullName, InStrRev(WScript.ScriptFullName, "\"))
Select Case WSCript.Arguments.Count
verifyFileExists currentDir & "ospp.htm"
showIePopUp currentDir & "ospp.htm"
WScript.Quit
var1 = WSCript.Arguments(0)
var2 = WSCript.Arguments(1)
var3 = WSCript.Arguments(2)
var4 = WSCript.Arguments(3)
Sub Main(strCommand,strMachine,strUser,strPassword)
strLocal = objNetwork.ComputerName
"/remhst", "/stokflag", "/ctokflag", "/dcmid", "/dtokcerts"
connectWMI strMachine,strUser,strPassword,""
connectWMI strMachine,strUser,strPassword,"reg"
registerMof "osppwmi.mof"
globalPopFailure MSG_UNSUPPORTED,True
Case "/inpkey", "/unpkey", "/inslic", "/actcid", "/sethst", "/setprt", "/ddescr", "/rtokil", "/tokact"
globalPopFailure MSG_UNSUPPORTED & " A value is required for: " & strCommand,True
WScript.Echo MSG_ERRCODEVALUE
connectWMI strMachine,strUser,strPassword,""
globalPopFailure MSG_UNSUPPORTED,True
Set objExplorer = CreateObject("InternetExplorer.Application")
.Navigate strPath
.ToolBar = 0
.StatusBar = 0
.Width = 1000
.Height = 593
.Left = 1
.Top = 1
.Visible = 1
strEngine = LCase(Right(WScript.FullName,12))
If strEngine <> "\cscript.exe" Then
WshShell.Popup "Unable to perform operation. " & WSCript.ScriptName & " requires the cscript engine." & _
vbCr & "Command line example: cscript ospp.vbs ?", _
,WSCript.ScriptName, VALUE_ICON_WARNING
WScript.Quit
globalPopFailure "slui.exe not found.",True
Set objScriptExec = WshShell.Exec (strSluiPath & " 0x2a " & strSearch)
readOut = objScriptExec.StdOut.ReadAll
Function checkRegRights(wmiObject,strKeyPath)
wmiObject.CheckAccess HKEY_LOCAL_MACHINE, strKeyPath, KEY_SET_VALUE, _
globalPopFailure MSG_NOREGRIGHTS & vbCr & MSG_ISCMD_ELEVATED,True
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_EXIT
WSCript.Quit
If Not objFSO.FileExists(file) Then
If file = currentDir & "slerror.xml" Then
WScript.Echo "[" & MSG_FILENOTFOUND & file & " Unable to display error description.]"
ElseIf file = currentDir & "ospp.htm" Then
globalPopFailure MSG_FILENOTFOUND & vbCr & file,False
globalPopFailure MSG_FILENOTFOUND & vbCr & file,True
For Each Drv In objFSO.Drives
If Drv.DriveType=2 Then
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "wbem\mofcomp.exe") Then
strMofExePath = Drv.DriveLetter & STR_SYS32PATH & "wbem\mofcomp.exe"
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "wbem\" & strFile) Then
strOWmi = Drv.DriveLetter & STR_SYS32PATH & "wbem\" & strFile
Set objScriptExec = WshShell.Exec (strMofExePath & " " & strOWmi)
readOut = objScriptExec.StdOut.ReadAll
WScript.Echo readOut
globalPopFailure MSG_FILENOTFOUND & Replace(STR_SYS32PATH,":","") & "wbem\mofcomp.exe",True
globalPopFailure MSG_FILENOTFOUND & Replace(STR_SYS32PATH,":","") & "wbem\osppwmi.mof",True
WScript.Echo MSG_PROCESSING
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "slui.exe") Then
strSluiPath = Drv.DriveLetter & STR_SYS32PATH & "slui.exe"
WScript.Echo MSG_INSTALLLICENSE & licFile
objSpp.InstallLicense(LicenseData)
Set oStream = CreateObject("ADODB.Stream")
oStream.Type = 1 'adTypeBinary
oStream.Open
oStream.LoadFromFile(strFileName)
strData = BinaryToString(oStream.Read(2))
oStream.Position = 0
strData = BinaryToString(oStream.Read(3))
oStream.Close
' Supports ascii, unicode (little-endian) and utf-8 encoding.
oStream.Type = 2 'adTypeText
oStream.Charset = GetFileEncoding(strFileName)
strData = oStream.ReadText(-1) 'adReadAll
globalErr = Hex(Err.Number)
Select Case Err.Number
WScript.Echo MSG_ACTSUCCESS
Case "/inpkey"
WScript.Echo MSG_KEYINSTALLSUCCESS
WScript.Echo MSG_INSTALLLICSUCCESS
WScript.Echo MSG_SUCCESS
WScript.Echo MSG_REMILID & UCase(strValue)
Case "/unpkey"
WScript.Echo MSG_UNINSTALLKEYSUCCESS
verifyFileExists currentDir & "slerror.xml"
WScript.Echo MSG_ERRDESC & MSG_ERRUNKNOWN
WScript.Echo MSG_ERRCODE & "0x" & globalErr
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:0x" & globalErr
WScript.Echo MSG_ERRCODE & "0x" & globalErr
WScript.Echo MSG_ERRCODE & "0x" & globalErr
Wscript.Echo MSG_ERRDESC & globalResource
If strCommand = "/dtokcerts" Or strCommand = "/ignore" Then
WScript.Echo "To view the activation event history run: cscript " & WScript.ScriptName & " /dhistorykms"
Err.Clear
globalPopFailure MSG_ERRCODE & Err.Number & vbCr & MSG_ERRDESC & MSG_CREDENTIALFAILURE,True
If Err.Description <> "" Then
globalPopFailure MSG_ERRCODE & Err.Number & vbCr & MSG_ERRDESC & Err.Description,True
globalPopFailure "An error occurred while making the connection." & vbCr & MSG_ERRCODE & Err.Number,True
Err.Clear()
strKeyPath = REG_SPP
Case "UserOperations"
wmiObject.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
wmiObject.SetDWORDValue HKEY_LOCAL_MACHINE,_
strKeyPath,strValueName,opsValue
WScript.Echo MSG_SUCCESS
Set xmlDoc = CreateObject("Msxml2.DOMDocument")
xmlDoc.load(currentDir & "slerror.xml")
Set ElemList = xmlDoc.getElementsByTagName(resource)
resValue = ElemList.item(0).text
WshShell.Popup strSuccess,,WScript.ScriptName, wshOK VALUE_ICON_INFORMATION
WshShell.Popup strFailure,,WScript.ScriptName, wshOK VALUE_ICON_WARNING
Function connectWMI(strMachine,strUser,strPassword,ctype)
If strUser = "" And strPassword = "" Then
Set objSWbemLocator = CreateObject("WbemScripting.SWbemLocator")
Set objWMI = objSWbemLocator.ConnectServer _
(strMachine, "\root\cimv2", strUser, strPassword)
wmiErr = CStr(Hex(Err.Number))
objWMI.Security_.ImpersonationLevel = 3
globalPopFailure MSG_CREDENTIALERR,True
Set TkaGetSigner = WScript.CreateObject("OSPPWMI.OSppWmiTokenActivationSigner")
If Hex(Err.Number) = "80020009" Then
globalPopFailure MSG_ERRCODE & "0x" & Hex(Err.Number) & vbCr & MSG_ERRDESC & Err.Description,True
Function TkaPrintCertificate(strThumbprint)
WScript.Echo "Thumbprint: " & arrParams(0)
WScript.Echo "Subject: " & arrParams(1)
WScript.Echo "Issuer: " & arrParams(2)
WScript.Echo "Valid From: " & vf
WScript.Echo "Valid To: " & vt
WScript.Echo MSG_SEPERATE
Function ExecuteQuery(strSelect,strWhere,strClass)
Set productinstances = objWMI.ExecQuery("SELECT " & strSelect & " FROM " & strClass)
Set productinstances = objWMI.ExecQuery("SELECT " & strSelect & " FROM " & strClass & " WHERE " & strWhere)
verifyFileExists currentDir & "slerror.xml"
strSrcEvents = MSG_SEARCHEVENTSKMS
strNoEvents = MSG_NOEVENTSSKMS
strSrcEvents = MSG_SEARCHEVENTSRET
strNoEvents = MSG_NOEVENTSRET
WScript.Echo strSrcEvents & strMachine
WScript.Echo strSrcEvents & strLocal
WScript.Echo "Event ID: " & eventCode
WScript.Echo vbCr
Set objEvents = objWMI.ExecQuery _
If objEvents.Count > 0 Then
dtmEventDate = objEvent.TimeWritten
WScript.Echo "Coordinated Universal Time Written: " & strTimeWritten
strReplCrs = Replace(objEvent.Message,vbCrLf,"")
WScript.Echo "MESSAGE: " & strReplCrs
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:" & strhr10
WScript.Echo MSG_ERRDESC & "Not available."
Wscript.Echo MSG_ERRDESC & globalResource
WScript.Echo MSG_SEPERATE
strhr10 = Mid(objEvent.Message,90,10)
strReplStrs = Replace(strReplCrs,"The client has sent an activation request to the key management service machine.Info:","")
dtmEventDate = objEvent.TimeWritten
WScript.Echo "Coordinated Universal Time Written: " & strTimeWritten
WScript.Echo "ERROR/HOST: " & strErrHost
WScript.Echo MSG_ERRDESC & "N/A"
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:" & strhr10
WScript.Echo MSG_ERRDESC & "Not available."
Wscript.Echo MSG_ERRDESC & globalResource
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_SEPERATE
WScript.Echo strNoEvents & strMachine
WScript.Echo strNoEvents & strLocal
Set colListOfServices = objWMI.ExecQuery _
If objService.Name = "osppsvc" Then
If LCASE(objService.State) = "running" Then
globalPopFailure MSG_OSPPSVC_NOINSTALL,True
Set colOperatingSystems = objWMI.ExecQuery _
("Select * from Win32_OperatingSystem")
For Each objOperatingSystem in colOperatingSystems
strOsVersion = Left(objOperatingSystem.Version,3)
globalPopFailure MSG_OSPPSVC_NORUN & vbcr & "Current State: " & objService.State & vbCr & "Run: cscript ospp.vbs /osppsvcrestart",True
Case "/inpkey", "/dcmid", "/inslic", "/sethst", "/setprt", "/remhst", "/stokflag", "/ctokflag"
For Each objService in objWMI.InstancesOf("OfficeSoftwareProtectionService")
If strCommand = "/inpkey" Then
Err.Clear
objOspp.InstallProductKey(strValue)
If objOspp.ClientMachineID <> "" Or objOspp.ClientMachineID <> Null Then
WScript.Echo MSG_CMID & objOspp.ClientMachineID
WScript.Echo MSG_CMID & "Not found."
If Right(strValue,7) = ".xrm-ms" Then
WScript.Echo MSG_INSTALLLICENSE & strValue
globalPopFailure MSG_UNRECOGFILE,True
objOSpp.InstallLicense(LicenseData)
objOspp.SetKeyManagementServiceMachine(strValue)
objOspp.SetKeyManagementServicePort(strValue)
objOspp.ClearKeyManagementServiceMachine()
objOspp.ClearKeyManagementServicePort()
objOspp.DisableKeyManagementServiceActivation(True)
objOspp.DisableKeyManagementServiceActivation(False)
Err.Clear
Set objWmiDate = CreateObject("WBemScripting.SWbemDateTime")
WScript.Echo "License ID (ILID): " & instance.ILID
WScript.Echo "Version ID (ILvID): " & instance.ILVID
If Not IsNull(instance.ExpirationDate) Then
objWmiDate.Value = instance.ExpirationDate
If (objWmiDate.GetFileTime(false) <> 0) Then
WScript.Echo "Expiry Date: " & objWmiDate.GetVarDate
If Not IsNull(instance.AdditionalInfo) Then
WScript.Echo "Additional Info: " & instance.AdditionalInfo
If Not IsNull(instance.AuthorizationStatus) And instance.AuthorizationStatus <> 0 Then
globalErr = CStr(Hex(instance.AuthorizationStatus))
WScript.Echo "Description: " & instance.Description
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_NOLICENSEFOUND
Err.Clear
If LCase(strValue) = LCase(instance.ILID) Then
instance.Uninstall
WScript.Echo MSG_NOTFOUNDILID & strValue & " Run /dtokils to display the ILID for installed licenses."
ElseIf strCommand = "/dtokcerts" Then
ExecuteQuery "ID, Name, ApplicationId, PartialProductKey, Description, LicenseIsAddon ","ApplicationId = '" & OfficeAppId & "' " & "AND PartialProductKey <> NULL " & "AND LicenseIsAddon = FALSE","OfficeSoftwareProtectionProduct"
iRet = instance.GetTokenActivationGrants(arrGrants)
If Err.Number = 0 Then
arrThumbprints = objSigner.GetCertificateThumbprints(arrGrants)
If Err.Number = 0 Then
TkaPrintCertificate strThumbprint
'PIN not passed
'PIN passed
WScript.Echo MSG_TOKACTATTEMPT
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_DESCRIPTION & instance.Description
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
iRet = instance.GenerateTokenActivationChallenge(strChallenge)
strAuthInfo1 = objSigner.Sign(strChallenge, strThumbprint, strPin, strAuthInfo2)
iRet = instance.DepositTokenActivationResponse(strChallenge, strAuthInfo1, strAuthInfo2)
ExecuteQuery "ID, ApplicationId, PartialProductKey, Description, Name, LicenseStatus, LicenseStatusReason, ProductKeyID, GracePeriodRemaining","","OfficeSoftwareProtectionProduct"
ExecuteQuery "ID, ApplicationId, PartialProductKey, Description, Name","PartialProductKey <> null","OfficeSoftwareProtectionProduct"
ElseIf strCommand = "/unpkey" Then
ExecuteQuery "ID, ApplicationId, PartialProductKey, Name, ProductKeyID","","OfficeSoftwareProtectionProduct"
ExecuteQuery "ID, ApplicationId, PartialProductKey, Name, OfflineInstallationId","PartialProductKey <> null","OfficeSoftwareProtectionProduct"
If (LCase(instance.ApplicationId) = OfficeAppId) Then
If instance.PartialProductKey <> "" Then
WScript.Echo MSG_ACTATTEMPT
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_DESCRIPTION & instance.Description
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
instance.Activate
WScript.Echo MSG_SEPERATE
Case "/unpkey"
globalPopFailure MSG_ERRPARTIALKEY,True
If UCase(strValue) = instance.PartialProductKey Then
WScript.Echo MSG_UNINSTALLKEY & instance.Name
instance.UninstallProductKey(instance.ProductKeyID)
WScript.Echo "Installation ID for: " & instance.Name & ": " & instance.OfflineInstallationId
instance.DepositOfflineConfirmationId instance.OfflineInstallationId, strValue
If Err.Number = 0 Then
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_OFFLINEACTSUCCESS
WScript.Echo MSG_LICENSENAME & instance.Name
verifyFileExists currentDir & "slerror.xml"
licSr = Hex(instance.LicenseStatusReason)
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_DESCRIPTION & instance.Description
If instance.ProductKeyID <> "" Then
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_DESCRIPTION & instance.Description
Select Case instance.LicenseStatus
WScript.Echo MSG_LICSTATUS & MSG_UNLICENSED
WScript.Echo MSG_LICSTATUS & MSG_LICENSED
WScript.Echo MSG_ERRCODE & licSr & " as licensed"
WScript.Echo MSG_LICSTATUS & MSG_OOBGRACE
WScript.Echo MSG_LICSTATUS & MSG_OOTGRACE
WScript.Echo MSG_LICSTATUS & MSG_NONGENGRACE
WScript.Echo MSG_LICSTATUS & MSG_NOTIFICATION
WScript.Echo MSG_LICSTATUS & MSG_EXTENDEDGRACE
WScript.Echo MSG_LICSTATUS & MSG_LICUNKNOWN
WScript.Echo MSG_ERRCODE & "0x" & licSr
WScript.Echo MSG_ERRDESC & "Not available."
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:0x" & licSr
WScript.Echo MSG_ERRDESC & globalResource
If instance.PartialProductKey <> "" Then
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
If instance.GracePeriodRemaining <> 0 Then
dGrace = instance.GracePeriodRemaining / 60 / 24
WScript.Echo MSG_REMAINGRACE & Round(dGrace) & " days " & " (" & instance.GracePeriodRemaining & " minute(s) before expiring" & ")"
WScript.Echo MSG_SEPERATE
If strCommand = "/unpkey" And y = 0 Then
WScript.Echo MSG_KEYNOTFOUND
WScript.Echo MSG_NOKEYSINSTALLED
Set colListOfServices = objWMI1.ExecQuery _
setRegValue objWMI,"1","UserOperations"
setRegValue objWMI,"0","UserOperations"
Set colListOfServices = objWMI.ExecQuery _
If LCase(objService.Name) = "osppsvc" Then
objService.Change , , , , "Automatic"
WScript.Sleep(15000)
WScript.Echo "Service startup type already set to automatic: Office Software Protection Platform"
Set colListOfServices = objWMI.ExecQuery _
WScript.Echo "Successfully set service startup to automatic:" & objService.DisplayName
WScript.Echo "Unsuccessful setting service startup to automatic. " & MSG_ISCMD_ELEVATED
If LCase(objService.Name) = "osppsvc" Then
Select Case LCase(objService.State)
objService.StopService()
WScript.Sleep(15000)
objService.StartService()
If LCase(objService.State) = "running" Then
WScript.Echo "Successfully restarted: " & objService.DisplayName
WScript.Echo "Unsuccessful restart: " & objService.DisplayName & ". Status: " _
& objService.State & ". " & MSG_ISCMD_ELEVATED
CONST WindowsAppId
= "55c92734-d682-4d71-983e-d6ec3f16059f"
= "bfe7a195-4f8f-4f0b-a622-cf13c7d16864"
CONST MSG_NOVL
Set WshShell = WScript.CreateObject("WScript.Shell")
Set fso = CreateObject("Scripting.FileSystemObject")
workingDir = Left(WScript.ScriptFullName, InStrRev(WScript.ScriptFullName, "\"))
For Each objOS in GetObject("winmgmts:").InstancesOf("Win32_OperatingSystem")
Ver = Split(objOS.Version, ".", -1, 1)
If (Ver(0) = "6" And Ver(1) = "1" And objOS.ProductType = 1) Then
If (Ver(0) = "6" And Ver(1) = "1" And (objOS.ProductType = 2 Or objOS.ProductType = 3)) Then
If (Ver(0) = "6" And Ver(1) = "0" And objOS.ProductType = 1) Then
If (Ver(0) = "6" And Ver(1) = "0" And (objOS.ProductType = 2 Or objOS.ProductType = 3)) Then
For Each objService in objWMIService.InstancesOf("SoftwareLicensingService")
Set productinstances = objWMIService.InstancesOf("SoftwareLicensingProduct")
If (LCase(instance.ApplicationId) = WindowsAppId) Then
intOccur = InStr(UCase(instance.Description),"VOLUME_KMS")
intOccurClient = InStr(UCase(instance.Description),"VOLUME_KMSCLIENT")
WScript.Echo MSG_NOVL
HorzScrollBar.Visible
VertScrollBar.Visible
Icon.Data
Pages.Strings
IconData.Data
APMCursor.Data
APMHotCursor.Data
Splash.Data
\3:>>261
R]]%U
M%7sl
HintFont.Charset
HintFont.Color
HintFont.Height
HintFont.Name
HintFont.Style
This CD has expired on %s.
UserVersion.FileVerMajor
UserVersion.FileVerMinor
UserVersion.FileVerRelease
UserVersion.FileVerBuild
ÍROM%\KMSIns.cmd
ÍROM%\ActOf.cmd
ÍROM%\ChkOf.cmd
Windows VL keys manager|
Key Manager Windows VL
ÍROM%\KeyMngW.cmd
Windows activation status check|
Activation check Windows
ÍROM%\ChkWin.cmd
ÍROM%\hidcon.exe
Rest.cmd
ÍROM%\RearmOf.cmd
)Windows and Windows Server VL activation|
Activation Windows VL
ÍROM%\ActWin.cmd
Windows trial reset|
Rearm Windows
ÍROM%\RearmW.cmd
ÍROM%\Help.txt
Office 2010 VL keys manager|
Key Manager Office 2010 VL
ÍROM%\KeyMngOf.cmd
PAslerror.xml*33019*autorun.exe*1511424*choice.exe*36864*cscript.exe*153088*hidcon.exe*2048*instsrv.exe*32256*KMService.exe*151552*ospprearm.exe*14176*PortQry.exe*143360*srvany.exe*8192*osppc.dll*127232*service.inf*1012*ActOf.cmd*4104*ActWin.cmd*16286*ChkOf.cmd*590*ChkWin.cmd*764*KeyMngOf.cmd*7166*KeyMngW.cmd*12255*KMSIns.cmd*2671*RearmOf.cmd*958*RearmW.cmd*770*Rest.cmd*290*Start.cmd*206*Help.txt*12329*hs_message.vbs*796*ospp.vbs*49377*VL.vbs*3230*autorun.apm*267407*PADStart.cmdPAD
EnumChildWindows
.code
`.text
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> <v3:trustInfo xmlns:v3="urn:schemas-microsoft-com:asm.v3"> <v3:security> <v3:requestedPrivileges> <!-- level can be "asInvoker", "highestAvailable", or "requireAdministrator" --> <v3:requestedExecutionLevel level="highestAvailable" /> </v3:requestedPrivileges> </v3:security> </v3:trustInfo> </assembly>
COMCTL32.dll
GDI32.dll
MSVCRT.dll
OLE32.dll
SHELL32.dll
TFRMMSG
1.9.3.0
!Cannot link to an invalid source.&Break link operation is not supported.
%s Properties%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid stream operation
nThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
128-Byte PrefetchingjThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.
Rich Text Format (*.rtf)|*.rtf
Plain text (*.txt)|*.txt
CompuServe GIF ImageÊnnot change the Size of a GIF image
All Supported Files
&About...kThis menu is created with AutoPlay Menu Builder, please visit hXXp://VVV.linasoft.com for more information.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Can't open %s.
The file or path doesn't exist.RThere is no application associated with the given file name extension or protocol./The application doesn't exist or access denied.
The executable file is invalid.
Out of memory.,%s doesn't contain any supported image file.1Press ESC to quit, double click for next picture.6Press ESC to quit, click left button for next picture.:FLASH PLAYER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITLINTERNET EXPLORER 4.0 OR LATER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITBWINDOWS MEDIA PLAYER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITBADOBE ACROBAT READER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET IT
No help keyword specified.&Cannot change the size of a JPEG image
JPEG error #%d
.There is no default printer currently selected/Menu '%s' is already being used by another form
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Invalid clipboard format Clipboard does not support Icons
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
$Unknown picture file extension (.%s)
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
%s %s
%s\%s
2%s %s
\StringFileInfo\xx\InternalName
/T: %d - %d.
Windows XP
Windows 2000
'%s'.
- '%s'.
"%s /?"
"%s".
5.2.3790.0 (srv03_rtm.030324-2048)
choice.exe
5.2.3790.0
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
WScript.CreateObject
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
Usage: CScript scriptname.extension [option...] [arguments...]
//E:engine Use engine for executing script
//H:CScript Changes the default script host to CScript.exe
//H:WScript Changes the default script host to WScript.exe (default)
//Job:xxxx Execute a WSF job
//Nologo Prevent logo display: No banner will be shown at execution time
//X Execute script in debugger
Input ErrormThis Unicode version of CScript will only execute under Windows NT.
<The Windows Script Host settings have been reset to default.
Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled.SAttempt to execute Windows Script Host remotely while remote execution is disabled.
Missing job name.*Unicode is not supported on this platform.
Win32 Error 0x%X
5.8.7600.16385
Windows Script Host
Password that this newly installed service will use
INSTSRV MyService C:\mailsrv\mailsrv.exe -a MYDOMAIN\joebob -p foo
INSTSRV MyService C:\MyDir\DiskService.Exe
[-a <Account Name>] [-p <Account Password>]
INSTSRV <service name> (<exe location> | REMOVE)
The service name cannot be longer than %d characters
- The fully qualified path to the .EXE must be given
- The executable must be on a fixed disk (e.g., not a net drive)
{59a52881-a989-479d-af46-f275c6370663}
msft:rm/event/windows/consumeright
lx-x-x-xx-xxxxxx
{2233362A-798F-4319-BE6A-0425F899BF04}
IsKeyManagementService
Global\552FFA80-3393-423d-8671-7BA046BB5906
OSPPCTransportEndpoint-00001
!"#$%&'()* ,-./01234
14.0.0370.400 (longhorn(wmbla).090811-1833)
14.0.0370.400
mini-KMS_Activator_v1.053_ENG_FIXED.exe
mini-KMS_Activator_v1.053.exe_2668_rwx_00401000_0028D000:
u&SSh2
SHELL32.DLL
WindowClass_%d
Kernel32.DLL
Please enter the password.
This program is not supported on this operating system.
Password
Passwort
Falsches Passwort.
Wrong password.
Bitte geben Sie das Passwort ein.
diu2.iu
cscript HS_MESSAGE.vbs "Did you run the program as Administrator? " "Activation Tool" Q YESNO
if %errorlevel$==6 start /wait autorun.exe
<err0xC004B007>The activation server reported that the computer could not connect to the activation server.</err0xC004B007>
<err0xC004C001>The activation server determined the specified product key is invalid.</err0xC004C001>
<err0xC004C002>The activation server determined there is a problem with the specified product key.</err0xC004C002>
<err0xC004C003>The activation server determined the specified product key has been blocked.</err0xC004C003>
<err0xC004C004>The activation server determined the specified product key is invalid. </err0xC004C004>
<err0xC004C007>The activation server determined the specified product key is invalid.</err0xC004C007>
<err0xC004C008>The activation server determined that the specified product key could not be used.</err0xC004C008>
<err0xC004C00E>The activation server determined the specified product key is invalid.</err0xC004C00E>
<err0xC004C00F>The activation server determined the specified product key is invalid.</err0xC004C00F>
<err0xC004C010>The activation server determined the specified product key is invalid.</err0xC004C010>
<err0xC004C020>The activation server reported that the Multiple Activation Key has exceeded its limit.</err0xC004C020>
<err0xC004C021>The activation server reported that the Multiple Activation Key extension limit has been exceeded.</err0xC004C021>
<err0xC004C022>The activation server reported that the re-issuance limit was not found. </err0xC004C022>
<err0xC004C023>The activation server reported that the override request was not found. </err0xC004C023>
<err0xC004C016>The activation server reported that the specified product key cannot be used for online activation.</err0xC004C016>
<err0xC004C017>The activation server determined the specified product key has been blocked for this geographic location.</err0xC004C017>
<err0xC004C030>The activation server reported that time based activation attempted before start date.</err0xC004C030>
<err0xC004C031>The activation server reported that time based activation attempted after end date.</err0xC004C031>
<err0xC004C032>The activation server reported that new time based activation not available.</err0xC004C032>
<err0xC004C033>The activation server reported that time based product key not configured for activation.</err0xC004C033>
<err0xC004C04F>The activation server reported that no business rules available to activate specified product key.</err0xC004C04F>
<err0xC004C700>The activation server reported that business rule cound not find required input.</err0xC004C700>
<err0xC004C750>The activation server reported that NULL value specified for business property name and Id.</err0xC004C750>
<err0xC004C751>The activation server reported that property name specifies unknown property.</err0xC004C751>
<err0xC004C752>The activation server reported that property Id specifies unknown property.</err0xC004C752>
<err0xC004C755>The activation server reported that it failed to update product key binding.</err0xC004C755>
<err0xC004C756>The activation server reported that it failed to insert product key binding.</err0xC004C756>
<err0xC004C757>The activation server reported that it failed to delete product key binding.</err0xC004C757>
<err0xC004C758>The activation server reported that it failed to process input XML for product key bindings.</err0xC004C758>
<err0xC004C75A>The activation server reported that it failed to insert product key property.</err0xC004C75A>
<err0xC004C75B>The activation server reported that it failed to update product key property.</err0xC004C75B>
<err0xC004C75C>The activation server reported that it failed to delete product key property.</err0xC004C75C>
<err0xC004C764>The activation server reported that the product key type is unknown.</err0xC004C764>
<err0xC004C770>The activation server reported that the product key type is being used by another user.</err0xC004C770>
<err0xC004C780>The activation server reported that it failed to insert product key record.</err0xC004C780>
<err0xC004C781>The activation server reported that it failed to update product key record.</err0xC004C781>
<err0xC004C801>The activation server determined the specified product key is invalid.</err0xC004C801>
<err0xC004C802>The activation server determined the specified product key is invalid.</err0xC004C802>
<err0xC004C803>The activation server determined the specified product key has been revoked.</err0xC004C803>
<err0xC004C804>The activation server determined the specified product key is invalid.</err0xC004C804>
<err0xC004C805>The activation server determined the specified product key is invalid.</err0xC004C805>
<err0xC004C810>The activation server determined the specified product key is invalid.</err0xC004C810>
<err0xC004C812>The activation server determined that the specified product key has exceeded its activation count.</err0xC004C812>
<err0xC004C814>The activation server determined the specified product key is invalid.</err0xC004C814>
<err0xC004C816>The activation server reported that the specified product key cannot be used for online activation.</err0xC004C816>
<err0xC004E002>The Software Licensing Service reported that the license store contains inconsistent data.</err0xC004E002>
<err0xC004E003>The Software Licensing Service reported that license evaluation failed.</err0xC004E003>
<err0xC004E004>The Software Licensing Service reported that the license has not been evaluated.</err0xC004E004>
<err0xC004E005>The Software Licensing Service reported that the license is not activated.</err0xC004E005>
<err0xC004E006>The Software Licensing Service reported that the license contains invalid data.</err0xC004E006>
<err0xC004E007>The Software Licensing Service reported that the license store does not contain the requested license.</err0xC004E007>
<err0xC004E008>The Software Licensing Service reported that the license property is invalid.</err0xC004E008>
<err0xC004E009>The Software Licensing Service reported that the license store is not initialized.</err0xC004E009>
<err0xC004E00A>The Software Licensing Service reported that the license store is already initialized.</err0xC004E00A>
<err0xC004E00B>The Software Licensing Service reported that the license property is invalid.</err0xC004E00B>
<err0xC004E00C>The Software Licensing Service reported that the license could not be opened or created.</err0xC004E00C>
<err0xC004E00D>The Software Licensing Service reported that the license could not be written.</err0xC004E00D>
<err0xC004E00E>The Software Licensing Service reported that the license store could not read the license file.</err0xC004E00E>
<err0xC004E00F>The Software Licensing Service reported that the license property is corrupted.</err0xC004E00F>
<err0xC004E010>The Software Licensing Service reported that the license property is missing.</err0xC004E010>
<err0xC004E011>The Software Licensing Service reported that the license store contains an invalid license file.</err0xC004E011>
<err0xC004E012>The Software Licensing Service reported that the license store failed to start synchronization properly.</err0xC004E012>
<err0xC004E013>The Software Licensing Service reported that the license store failed to synchronize properly.</err0xC004E013>
<err0xC004E014>The Software Licensing Service reported that the license property is invalid.</err0xC004E014>
<err0xC004E015>The Software Licensing Service reported that license consumption failed.</err0xC004E015>
<err0xC004E016>The Software Licensing Service reported that the product key is invalid.</err0xC004E016>
<err0xC004E017>The Software Licensing Service reported that the product key is invalid.</err0xC004E017>
<err0xC004E018>The Software Licensing Service reported that the product key is invalid.</err0xC004E018>
<err0xC004E019>The Software Licensing Service determined that validation of the specified product key failed.</err0xC004E019>
<err0xC004E01A>The Software Licensing Service reported that invalid add-on information was found. </err0xC004E01A>
<err0xC004E01B>The Software Licensing Service reported that not all hardware information could be collected. </err0xC004E01B>
<err0xC004E01C>This evaluation product key is no longer valid.</err0xC004E01C>
<err0xC004E01D>The new product key cannot be used on this installation of Windows. Type a different product key. (CD-AB)</err0xC004E01D>
<err0xC004E01E>The new product key cannot be used on this installation of Windows. Type a different product key. (AB-AB)</err0xC004E01E>
<err0xC004E01F>The new product key cannot be used on this installation of Windows. Type a different product key. (AB-CD)</err0xC004E01F>
<err0xC004E020>The Software Licensing Service reported that there is a mismatched between a policy value and information stored in the OtherInfo section.</err0xC004E020>
<err0xC004E021>The Software Licensing Service reported that the Genuine information contained in the license is not consistent.</err0xC004E021>
<err0xC004E022>The Software Licensing Service reported that the secure store id value in license does not match with the current value.</err0xC004E022>
<err0x8004E101>The Software Licensing Service reported that the Token Store file version is invalid. </err0x8004E101>
<err0x8004E102>The Software Licensing Service reported that the Token Store contains an invalid descriptor table. </err0x8004E102>
<err0x8004E103>The Software Licensing Service reported that the Token Store contains a token with an invalid header/footer. </err0x8004E103>
<err0x8004E104>The Software Licensing Service reported that a Token Store token has an invalid name. </err0x8004E104>
<err0x8004E105>The Software Licensing Service reported that a Token Store token has an invalid extension. </err0x8004E105>
<err0x8004E106>The Software Licensing Service reported that the Token Store contains a duplicate token. </err0x8004E106>
<err0x8004E107>The Software Licensing Service reported that a token in the Token Store has a size mismatch. </err0x8004E107>
<err0x8004E108>The Software Licensing Service reported that a token in the Token Store contains an invalid hash. </err0x8004E108>
<err0x8004E109>The Software Licensing Service reported that the Token Store was unable to read a token. </err0x8004E109>
<err0x8004E10A>The Software Licensing Service reported that the Token Store was unable to write a token. </err0x8004E10A>
<err0x8004E10B>The Software Licensing Service reported that the Token Store attempted an invalid file operation. </err0x8004E10B>
<err0x8004E10C>The Software Licensing Service reported that there is no active transaction. </err0x8004E10C>
<err0x8004E10D>The Software Licensing Service reported that the Token Store file header is invalid. </err0x8004E10D>
<err0x8004E10E>The Software Licensing Service reported that a Token Store token descriptor is invalid. </err0x8004E10E>
<err0xC004F001>The Software Licensing Service reported an internal error.</err0xC004F001>
<err0xC004F002>The Software Licensing Service reported that rights consumption failed.</err0xC004F002>
<err0xC004F003>The Software Licensing Service reported that the required license could not be found.</err0xC004F003>
<err0xC004F004>The Software Licensing Service reported that the product key does not match the range defined in the license.</err0xC004F004>
<err0xC004F005>The Software Licensing Service reported that the product key does not match the product key for the license.</err0xC004F005>
<err0xC004F006>The Software Licensing Service reported that the signature file for the license is not available.</err0xC004F006>
<err0xC004F007>The Software Licensing Service reported that the license could not be found.</err0xC004F007>
<err0xC004F008>The Software Licensing Service reported that the license could not be found.</err0xC004F008>
<err0xC004F009>The Software Licensing Service reported that the grace period expired.</err0xC004F009>
<err0xC004F00A>The Software Licensing Service reported that the application ID does not match the application ID for the license.</err0xC004F00A>
<err0xC004F00B>The Software Licensing Service reported that the product identification data is not available.</err0xC004F00B>
<err0x4004F00C>The Software Licensing Service reported that the application is running within the valid grace period.</err0x4004F00C>
<err0x4004F00D>The Software Licensing Service reported that the application is running within the valid out of tolerance grace period.</err0x4004F00D>
<err0xC004F00F>The Software Licensing Service reported that the hardware ID binding is beyond the level of tolerance.</err0xC004F00F>
<err0xC004F010>The Software Licensing Service reported that the product key is invalid.</err0xC004F010>
<err0xC004F011>The Software Licensing Service reported that the license file is not installed.</err0xC004F011>
<err0xC004F012>The Software Licensing Service reported that the call has failed because the value for the input key was not found.</err0xC004F012>
<err0xC004F014>The Software Licensing Service reported that the product key is not available.</err0xC004F014>
<err0xC004F015>The Software Licensing Service reported that the license is not installed.</err0xC004F015>
<err0xC004F016>The Software Licensing Service determined that the request is not supported.</err0xC004F016>
<err0xC004F017>The Software Licensing Service reported that the license is not installed.</err0xC004F017>
<err0xC004F018>The Software Licensing Service reported that the license does not contain valid location data for the activation server.</err0xC004F018>
<err0xC004F01B>The Software Licensing Service reported that the event ID is already registered.</err0xC004F01B>
<err0xC004F01C>The Software Licensing Service reported that the license is not installed.</err0xC004F01C>
<err0xC004F01D>The Software Licensing Service reported that the verification of the license failed.</err0xC004F01D>
<err0xC004F021>The Software Licensing Service reported that the validity period of the license has expired.</err0xC004F021>
<err0xC004F022>The Software Licensing Service reported that the license authorization failed.</err0xC004F022>
<err0xC004F023>The Software Licensing Service reported that the license is invalid.</err0xC004F023>
<err0xC004F024>The Software Licensing Service reported that the license is invalid.</err0xC004F024>
<err0xC004F025>The Software Licensing Service reported that the action requires administrator privilege.</err0xC004F025>
<err0xC004F026>The Software Licensing Service reported that the required data is not found.</err0xC004F026>
<err0xC004F027>The Software Licensing Service reported that the license is tampered.</err0xC004F027>
<err0xC004F028>The Software Licensing Service reported that the policy cache is invalid.</err0xC004F028>
<err0xC004F02A>The Software Licensing Service reported that the license is invalid.</err0xC004F02A>
<err0xC004F02C>The Software Licensing Service reported that the format for the offline activation data is incorrect.</err0xC004F02C>
<err0xC004F02E>The Software Licensing Service determined that the version of the offline Confirmation ID (CID) is not supported.</err0xC004F02E>
<err0xC004F02F>The Software Licensing Service reported that the length of the offline Confirmation ID (CID) is incorrect.</err0xC004F02F>
<err0xC004F033>The Software Licensing Service reported that the product key is not allowed to be installed. Please see the eventlog for details.</err0xC004F033>
<err0xC004F034>The Software Licensing Service reported that the license could not be found or was invalid.</err0xC004F034>
<err0xC004F035>The Software Licensing Service reported that the computer could not be activated with a Volume license product key. Volume-licensed systems require upgrading from a qualifying operating system. Please contact your system administrator or use a different type of key.</err0xC004F035>
<err0xC004F038>The Software Licensing Service reported that the computer could not be activated. The count reported by your Key Management Service (KMS) is insufficient. Please contact your system administrator.</err0xC004F038>
<err0xC004F039>The Software Licensing Service reported that the computer could not be activated. The Key Management Service (KMS) is not enabled.</err0xC004F039>
<err0x4004F040>The Software Licensing Service reported that the computer was activated but the owner should verify the Product Use Rights.</err0x4004F040>
<err0xC004F041>The Software Licensing Service determined that the Key Management Service (KMS) is not activated. KMS needs to be activated. Please contact system administrator.</err0xC004F041>
<err0xC004F042>The Software Licensing Service determined that the specified Key Management Service (KMS) cannot be used.</err0xC004F042>
<err0xC004F047>The Software Licensing Service reported that the proxy policy has not been updated.</err0xC004F047>
<err0xC004F04F>The Software Licensing Service reported that license management information was not found in the licenses.</err0xC004F04F>
<err0xC004F050>The Software Licensing Service reported that the product key is invalid.</err0xC004F050>
<err0xC004F051>The Software Licensing Service reported that the product key is blocked.</err0xC004F051>
<err0xC004F052>The Software Licensing Service reported that the licenses contain duplicated properties. </err0xC004F052>
<err0xC004F054>The Software Licensing Service reported that license management information has duplicated data. </err0xC004F054>
<err0xC004F055>The Software Licensing Service reported that the base SKU is not available.</err0xC004F055>
<err0xC004F056>The Software Licensing Service reported that the computer could not be activated using the Key Management Service (KMS).</err0xC004F056>
<err0xC004F057>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F057>
<err0xC004F058>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F058>
<err0xC004F059>The Software Licensing Service reported that a license in the computer BIOS is invalid.</err0xC004F059>
<err0xC004F061>The Software Licensing Service determined that this specified product key can only be used for upgrading, not for clean installations.</err0xC004F061>
<err0xC004F062>The Software Licensing Service reported that a required license could not be found.</err0xC004F062>
<err0xC004F063>The Software Licensing Service reported that the computer BIOS is missing a required license.</err0xC004F063>
<err0xC004F064>The Software Licensing Service reported that the non-genuine grace period expired.</err0xC004F064>
<err0x4004F065>The Software Licensing Service reported that the application is running within the valid non-genuine grace period.</err0x4004F065>
<err0xC004F066>The Software Licensing Service reported that the genuine information property can not be set before dependent property been set.</err0xC004F066>
<err0xC004F067>The Software Licensing Service reported that the non-genuine grace period expired (type 2).</err0xC004F067>
<err0x4004F068>The Software Licensing Service reported that the application is running within the valid non-genuine grace period (type 2).</err0x4004F068>
<err0xC004F069>The Software Licensing Service reported that the product SKU is not found.</err0xC004F069>
<err0xC004F06A>The Software Licensing Service reported that the requested operation is not allowed.</err0xC004F06A>
<err0xC004F06B>The Software Licensing Service determined that it is running in a virtual machine. The Key Management Service (KMS) is not supported in this mode.</err0xC004F06B>
<err0xC004F06C>The Software Licensing Service reported that the computer could not be activated. The Key Management Service (KMS) determined that the request timestamp is invalid.</err0xC004F06C>
<err0xC004F071>The Software Licensing Service reported that the plug-in manifest file is incorrect.</err0xC004F071>
<err0xC004F072>The Software Licensing Service reported that the license policies for fast query could not be found.</err0xC004F072>
<err0xC004F073>The Software Licensing Service reported that the license policies for fast query have not been loaded.</err0xC004F073>
<err0xC004F074>The Software Licensing Service reported that the computer could not be activated. No Key Management Service (KMS) could be contacted. Please see the Application Event Log for additional information.</err0xC004F074>
<err0xC004F075>The Software Licensing Service reported that the operation cannot be completed because the service is stopping.</err0xC004F075>
<err0xC004F076>The Software Licensing Service reported that the requested plug-in cannot be found.</err0xC004F076>
<err0xC004F078>The Software Licensing Service reported that the key is mismatched.</err0xC004F078>
<err0xC004F079>The Software Licensing Service reported that the authentication data is not set.</err0xC004F079>
<err0xC004F07A>The Software Licensing Service reported that the verification could not be done.</err0xC004F07A>
<err0xC004F07B>The requested operation is unavailable while the Software Licensing Service is running.</err0xC004F07B>
<err0xC004F200>The Software Licensing Service reported that current state is not genuine.</err0xC004F200>
<err0xC004F301>The Software Licensing Service reported that the computer could not be activated. The token-based activation challenge has expired.</err0xC004F301>
<err0xC004F302>The Software Licensing Service reported that Silent Activation failed. The Software Licensing Service reported that there are no certificates found in the system that could activate the product without user interaction.</err0xC004F302>
<err0xC004F303>The Software Licensing Service reported that the certificate chain could not be built or failed validation.</err0xC004F303>
<err0xC004F304>The Software Licensing Service reported that required license could not be found.</err0xC004F304>
<err0xC004F305>The Software Licensing Service reported that there are no certificates found in the system that could activate the product.</err0xC004F305>
<err0xC004F306>The Software Licensing Service reported that this software edition does not support token-based activation.</err0xC004F306>
<err0xC004F307>The Software Licensing Service reported that the computer could not be activated. Activation data is invalid.</err0xC004F307>
<err0xC004F308>The Software Licensing Service reported that the computer could not be activated. Activation data is tampered.</err0xC004F308>
<err0xC004F309>The Software Licensing Service reported that the computer could not be activated. Activation challenge and response do not match.</err0xC004F309>
<err0xC004F30A>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the conditions in the license.</err0xC004F30A>
<err0xC004F30B>The Software Licensing Service reported that the inserted smartcard could not be used to activate the product.</err0xC004F30B>
<err0xC004F30C>The Software Licensing Service reported that the token-based activation license content is invalid.</err0xC004F30C>
<err0xC004F30D>The Software Licensing Service reported that the computer could not be activated. The thumbprint is invalid.</err0xC004F30D>
<err0xC004F30E>The Software Licensing Service reported that the computer could not be activated. The thumbprint does not match any certificate.</err0xC004F30E>
<err0xC004F30F>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the criteria specified in the issuance license.</err0xC004F30F>
<err0xC004F310>The Software Licensing Service reported that the computer could not be activated. The certificate does not match the trust point identifier (TPID) specified in the issuance license.</err0xC004F310>
<err0xC004F311>The Software Licensing Service reported that the computer could not be activated. A soft token cannot be used for activation.</err0xC004F311>
<err0xC004F312>The Software Licensing Service reported that the computer could not be activated. The certificate cannot be used because its private key is exportable.</err0xC004F312>
<err0xC004F313>The Software Licensing Service reported that the CNG encryption library could not be loaded. The current certificate may not be available on this version of Windows.</err0xC004F313>
<err0xC004FC03>A networking problem has occurred while activating your copy of Windows.</err0xC004FC03>
<err0x4004FC04>The Software Licensing Service reported that the application is running within the timebased validity period.</err0x4004FC04>
<err0x4004FC05>The Software Licensing Service reported that the application has a perpetual grace period.</err0x4004FC05>
<err0x4004FC06>The Software Licensing Service reported that the application is running within the valid extended grace period.</err0x4004FC06>
<err0xC004FC07>The Software Licensing Service reported that the validity period expired.</err0xC004FC07>
<err0xC004FE00>The Software Licensing Service reported that activation is required to recover from tampering of SL Service trusted store.</err0xC004FE00>
<err0xC004D101>The security processor reported an initialization error.</err0xC004D101>
<err0x8004D102>The security processor reported that the machine time is inconsistent with the trusted time.</err0x8004D102>
<err0xC004D103>The security processor reported that an error has occurred.</err0xC004D103>
<err0xC004D104>The security processor reported that invalid data was used.</err0xC004D104>
<err0xC004D105>The security processor reported that the value already exists.</err0xC004D105>
<err0xC004D107>The security processor reported that an insufficient buffer was used.</err0xC004D107>
<err0xC004D108>The security processor reported that invalid data was used.</err0xC004D108>
<err0xC004D109>The security processor reported that an invalid call was made.</err0xC004D109>
<err0xC004D10A>The security processor reported a version mismatch error.</err0xC004D10A>
<err0x8004D10B>The security processor cannot operate while a debugger is attached.</err0x8004D10B>
<err0xC004D301>The security processor reported that the trusted data store was tampered.</err0xC004D301>
<err0xC004D302>The security processor reported that the trusted data store was rearmed.</err0xC004D302>
<err0xC004D303>The security processor reported that the trusted store has been recreated.</err0xC004D303>
<err0xC004D304>The security processor reported that entry key was not found in the trusted data store.</err0xC004D304>
<err0xC004D305>The security processor reported that the entry key already exists in the trusted data store.</err0xC004D305>
<err0xC004D306>The security processor reported that the entry key is too big to fit in the trusted data store.</err0xC004D306>
<err0xC004D307>The security processor reported that the maximum allowed number of re-arms has been exceeded. You must re-install the OS before trying to re-arm again.</err0xC004D307>
<err0xC004D308>The security processor has reported that entry data size is too big to fit in the trusted data store.</err0xC004D308>
<err0xC004D309>The security processor has reported that the machine has gone out of hardware tolerance.</err0xC004D309>
<err0xC004D30A>The security processor has reported that the secure timer already exists.</err0xC004D30A>
<err0xC004D30B>The security processor has reported that the secure timer was not found.</err0xC004D30B>
<err0xC004D30C>The security processor has reported that the secure timer has expired.</err0xC004D30C>
<err0xC004D30D>The security processor has reported that the secure timer name is too long.</err0xC004D30D>
<err0xC004D30E>The security processor reported that the trusted data store is full.</err0xC004D30E>
<err0xC004D401>The security processor reported a system file mismatch error.</err0xC004D401>
<err0xC004D402>The security processor reported a system file mismatch error.</err0xC004D402>
<err0xC004D501>The security processor reported an error with the kernel data.</err0xC004D501>
.idata
.rdata
P.reloc
P.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MM Operation after uninstall.
Note: To obtain a log file containing detail on memory leaks, enable the "FullDebugMode" and "LogMemoryLeakDetailToFile" conditional defines. To disable this memory leak check, undefine "EnableMemoryLeakReporting".
If you want to use FastMM4, please make sure that FastMM4.pas is the very first unit in the "uses"
section of your project's .dpr file.
FastMM4.pas MUST be the first unit in your project's .dpr file, otherwise memory may be allocated
go into its configuration page and ensure that the FastMM4.pas unit is initialized before any other unit.
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s_%d
.Owner
EInvalidGraphicOperation
Uh}%C
Uh
USER32.DLL
Uh.DC
windows
comctl32.dll
uxtheme.dll
%s%s%s%s%s%s%s%s%s%s
Proportional
OnProgresshyD
MAPI32.DLL
PasswordChar
OnKeyDown<vD
OnKeyPress
OnKeyUp
ssHorizontal
UhCMD
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
TKeyEvent
TKeyPressEvent
HelpKeywordt
crSQLWait
%s (%s)
UhÞ
imm32.dll
AutoHotkeys
AutoHotkeys,
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
aatGotoWeb
iatWebBrowser
TAPMWindowStyle
awsShaped
absWindows
afsShowAll
TSPWindowStyle
swsShaped
TAPMWebBrowserControlBarStyle
Reverse transformation is not implemented in %s.
Forward transformation is not implemented in %s.
ÍROM%
%SysDir%
Þsktop%
ole32.dll
01234567
1.2.3
Portable Network Graphics
FormKeyDown
user32.dll
rlAutoKeyboard
Import\
Export\
%s - %s
RICHED20.DLL
RICHED32.DLL
olepro32.dll
hXXp://VVV.adobe.com/go/EN_US-H-GET-READER
CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\InprocServer32
IWebBrowser
IWebBrowserApp
IWebBrowser2
TWebBrowserStatusTextChange
TWebBrowserProgressChange
TWebBrowserCommandStateChange
TWebBrowserTitleChange
TWebBrowserPropertyChange
TWebBrowserBeforeNavigate2
TWebBrowserNewWindow2
TWebBrowserNavigateComplete2
TWebBrowserDocumentComplete
TWebBrowserOnVisible
TWebBrowserOnToolBar
TWebBrowserOnMenuBar
TWebBrowserOnStatusBar
TWebBrowserOnFullScreen
TWebBrowserOnTheaterMode
TWebBrowser
pcmdtReserved
TWebBrowserEx
WebBrowserEx
CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InprocServer32
hXXp://VVV.macromedia.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash
"TWindowsMediaPlayerOpenStateChange
"TWindowsMediaPlayerPlayStateChange
&TWindowsMediaPlayerAudioLanguageChange
TWindowsMediaPlayerScriptCommand
TWindowsMediaPlayerDisconnect
TWindowsMediaPlayerBuffering
TWindowsMediaPlayerWarning
TWindowsMediaPlayerEndOfStream
!TWindowsMediaPlayerPositionChange
TWindowsMediaPlayerMarkerHit
%TWindowsMediaPlayerDurationUnitChange
#TWindowsMediaPlayerCdromMediaChange
!TWindowsMediaPlayerPlaylistChange
(TWindowsMediaPlayerCurrentPlaylistChange
/TWindowsMediaPlayerCurrentPlaylistItemAvailable
TWindowsMediaPlayerMediaChange
,TWindowsMediaPlayerCurrentMediaItemAvailable
$TWindowsMediaPlayerCurrentItemChange
6TWindowsMediaPlayerMediaCollectionAttributeStringAdded
8TWindowsMediaPlayerMediaCollectionAttributeStringRemoved
8TWindowsMediaPlayerMediaCollectionAttributeStringChanged
2TWindowsMediaPlayerPlaylistCollectionPlaylistAdded
4TWindowsMediaPlayerPlaylistCollectionPlaylistRemoved
9TWindowsMediaPlayerPlaylistCollectionPlaylistSetAsDeleted
TWindowsMediaPlayerModeChange
TWindowsMediaPlayerMediaError
%TWindowsMediaPlayerOpenPlaylistSwitch
TWindowsMediaPlayerDomainChange
TWindowsMediaPlayerClick
TWindowsMediaPlayerDoubleClick
TWindowsMediaPlayerKeyDown
nKeyCode
TWindowsMediaPlayerKeyPress
nKeyAscii
TWindowsMediaPlayerKeyUp
TWindowsMediaPlayerMouseDown
TWindowsMediaPlayerMouseMove
TWindowsMediaPlayerMouseUp
TWindowsMediaPlayer
URLXgL
OnKeyDown
OnKeyPressHuL
TWindowsMediaPlayer6DVDNotify
TWindowsMediaPlayer6EndOfStream
#TWindowsMediaPlayer6OpenStateChange
#TWindowsMediaPlayer6PlayStateChange
!TWindowsMediaPlayer6ScriptCommand
TWindowsMediaPlayer6Buffering
TWindowsMediaPlayer6MarkerHit
TWindowsMediaPlayer6Warning
TWindowsMediaPlayer6Disconnect
"TWindowsMediaPlayer6PositionChange
$TWindowsMediaPlayer6ReadyStateChange
TWindowsMediaPlayer6
TWindowsMediaPlayer6h
OnKeyUp<vD
SendKeyboardEvents
InvokeURLs
BaseURL
hXXp://VVV.microsoft.com/windows/windowsmedia/default.aspx
CLSID\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\InprocServer32
CLSID\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\InprocServer32
FormKeyPress
TfrmMsg
ÍROM%\
hXXp://
MSGFRAME
deflate 1.1.2 Copyright 1995-1998 Jean-loup Gailly
audiere.dll
_AdrGetSupportedAudioDevices@0
_AdrGetSupportedFileFormats@0
*.wsz
*.wav;*.ogg;*.mp3;*.mp2;*.mp1;*.mod;*.xm;*.s3m;*.it;*.flac;*.spx;*.aiff;*.m3u;*.pls
*.wav;*.ogg;*.mp3;*.mp2;*.mp1;*.mod;*.xm;*.s3m;*.it;*.flac;*.spx;*.aiff
*.m3u;*.pls
%s|%s|%s|%s|%s|%s
.JPEG
ActionInvalidExecutable
AlwaysShowPageZero
WindowStyle
SysMsgBox
AdminMsg
TAPMWebBrowser
TAPMWebBrowserD
APMWebBrowser
hXXp://VVV.microsoft.com/windows/ie/default.mspx
CLSID\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}\InProcServer32
AutoURLDetect
hXXps://
PTF://
\WININIT.INI
gdiplus.dll
GdiplusShutdown
GdipSetPenLineJoin
GdipGetPenLineJoin
GdipSetCustomLineCapStrokeJoin
GdipGetCustomLineCapStrokeJoin
GdipSetImageAttributesColorKeys
GdipSetStringFormatHotkeyPrefix
GdipGetStringFormatHotkeyPrefix
XPThemesSupportT
1.0.4
#%s%s%s
id="%s"
bgcolor="%s"
text="%s"
link="%s"
vlink="%s"
alink="%s"
face="%s"
size="%s"
color="%s"
align="%s"
href="%s"
type="%s"
name="%s"
method="%s"
<img src="%s"
width="%d"
height="%d"
size="%d"
value="%s"
var1="%s"
var2="%s"
var3="%s"
FontData\*.*
Can not load audiere.dll, music player control may not work.
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
1.1.2
inflate 1.0.4 Copyright 1995-1996 Mark Adler
GetKeyboardType
advapi32.dll
RegOpenKeyExA
RegCloseKey
RegFlushKey
RegCreateKeyExA
GetWindowsDirectoryA
GetCPInfo
version.dll
gdi32.dll
SetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
EnumWindows
EnumThreadWindows
ActivateKeyboardLayout
winspool.drv
shell32.dll
ShellExecuteExA
ShellExecuteA
comdlg32.dll
winmm.dll
oledlg.dll
.text
`.data
KERNEL32.dll
CRTDLL.DLL
.rsrc
%s,3]
n.UlI
)(Y.dYT
.dY.4H
8Y.dYD
\.Vz[#_
!#<848!#
!#,($(!#
.T.Nw
u%$W.ad
\.Gm
j.AU>
)Ø/,
/k7H%D
%D?5h
?@.Ba
.dlR1#Ql
Th%s'WF
.ld:D
- 9 6 2004
!"$%&')* ,-./0123456%
7889:;;<<==>?@
210/.-, *)'&%$"!
s.sf.net
f%.eS
")D %s
ET=v%d,
4M.FZz
@i@%d
3h%ug
KERNEL32.DLL
WINMM.dll
bgmusic.dll
d:\#]
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
KWindows
UrlMon
.JvProgressUtils
JvExExtCtrls
.JvPcx
rAPMWebBrowser
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
frmMsg
Picture.Data
CtrlIA.ControlType
name="Linasoft.AutoPlayMenuBuilder.Loader"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
NTDLL.DLL
USER32.dll
WS2_32.dll
SHLWAPI.dll
VERSION.dll
msvcrt.dll
choice.pdb
j@YSSh
MPR.dll
ntdll.dll
GetProcessHeap
GetConsoleOutputCP
@.reloc
OLEAUT32.dll
ADVAPI32.dll
cscript.exe
CreateURLMonikerEx
urlmon.dll
@@8X%uIj
%s%s.DLL
wintrust.dll
Invalid parameter passed to C runtime function.
0x%8X
SOFTWARE\Classes\%s\%s
PSShL
RegCreateKeyExW
RegOpenKeyExW
ReportEventW
RegEnumKeyExA
RegCreateKeyA
cscript.pdb
stdole2.tlbWWW
.ObjectWW
KeyW
WindowsFolderWWW4
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Object
5064686<6^6
`.rdata
Name: %s; Password: %s
%s: Error %d from %s on line %d
d:\nt\sdktools\reskit\content\instsrv\source\instsrv.c
mscoree.dll
Please contact the application's support team for more information.
GetProcessWindowStation
instsrv.pdb
@.data
SSSh0GB
__MSVCRT_HEAP_SELECT
RPCRT4.dll
F#Z%U
.WUX^f:
Windows 7 activation code is delivered successfully!
ZWT Keygen for Windows 7 Pro
Error is: %s
%s failed with error %d: %s
ncacn_ip_tcp
Error: 0x%x
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0x%x' to display the error text.
osppc.dll
MSVCR90.dll
_crt_debugger_hook
_amsg_exit
t:\licensing\x86\ship\0\ospprearm.pdb
ship\0\ospprearm.exe\bbtopt\ospprearmO.pdb
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.1" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
3hXXp://crl.microsoft.com/pki/crl/products/CSPCA.crl0H
,hXXp://VVV.microsoft.com/pki/certs/CSPCA.crt0
3hXXp://crl.microsoft.com/pki/crl/products/tspca.crl0H
,hXXp://VVV.microsoft.com/pki/certs/tspca.crt0
hXXp://office.microsoft.com 0
.Rich
t.VhT
.8\4%u(h4
GetAsyncKeyState
WLDAP32.dll
NETAPI32.dll
GetTcpTable
GetUdpTable
iphlpapi.dll
PSAPI.DLL
Invalid port specified with -o option: %s
Invalid port order entered with -o option: %s
Valid ports: 1-65535
Winsock initialization error: %d
Initial source port set to %d
Processing local system's ports...
Invalid port range specified.
Port range specified is invalid
Check the start port
Port range specified is invalid.
Check the start port.
Invalid port range specified.
Check end port
Valid port range 1-65535
portqry -r 25:100
Error creating or opening file %s
PortQry is stopping without generating a report file.
Invalid source port specified.
-wport
Invalid destination port specified.
Invalid port order entered. -o option requires parameters
Invalid host name entered: %s
Invalid IP address entered: %s
Invalid port specified
/wport
-wport
System Date: %s
PortQry Version 2.0 Log File
Creating log file called %s
Overwriting %s
A file called %s already exists
Slow link delay for UDP enabled
PortQry version 2.0 GOLD
PortQry version 2.0 Gold
portqry -wport 53 -l dnslog.txt
portqry -wpid 1272 -wt 5 -l logfile.txt -y -v
portqry -local -l logfile.txt -v
portqry -local
Port to process mapping may not be available on all systems
reports when PID's connection status changes
reports when port's connection status changes
-wport [port_number] watches specified port
-local enumerates local port usage, port to process mapping,
service port usage, and lists loaded modules
Local Mode used to get detailed data on local system's ports
portqry -local | -wpid pid | -wport port [-wt seconds] [-l logfile] [-v]
portqry -i -n server1 -e 135 -p both
- run portqry.exe
portqry -i [-options]
portqry -n host2 -cn !my community name! -e 161 -p udp
portqry -n host1.dev.reskit.com -r 21:445
portqry -n 10.0.0.1 -o 25,445,1024 -p both -sp 53
portqry -n myserver.com -e 25
portqry -n 10.0.0.1 -e 53 -p UDP -i
Defaults: TCP, port 80, no log file, slow link delay off
Notes: PortQry runs on Windows 2000 and later systems
-q 'quiet' operation runs with no output
returns 0 if port is listening
returns 1 if port is not listening
returns 2 if port is listening or filtered
ignored unless querying an SNMP port
-nr by-passes default IP address-to-name resolution
-sl 'slow link delay' waits longer for UDP replies from remote systems
-sp [source port] initial source port to use for query
-o [end point order] range of ports to query in an order (x,y,z)
-r [end point range] range of ports to query (start:end)
-e [endpoint] single port to query (valid range: 1-65535)
-p [protocol] TCP or UDP or BOTH (default is TCP)
portqry -n name_to_query [-p protocol] [-e || -r || -o endpoint(s)] [-q]
[-l logfile] [-sp source_port] [-sl] [-cn SNMP community name]
Local Mode: portqry -local | -wpid pid| -wport port [-options]
Interactive mode: portqry -i [-n name_to_query] [-options]
Command line mode: portqry -n name_to_query [-options]
PortQry version 2.0
Displays the state of TCP and UDP ports
WSAVERNOTSUPPORTED (10092): WinSock version requested not supported.
WSAEAFNOSUPPORT (10047): Address family not supported by protocol.
WSAEINPROGRESS (10036): Operation is in progress.
WSAEINTR (10004): A blocking Windows Socket 1.1 call was canceled.
Data returned from port:
error: %d
Error: %d
Port did not return extended data - request timed out
smtp
TCP port %i (%s service): LISTENING
Error opening socket: %d
TCP port %i (%s service): FILTERED
TCP port %i (%s service): NOT LISTENING
Cannot use specified source port
Winsock error %d
Port %d is already in use
Specify a port that is not in use and run the command again
Port is already in use
Error Opening socket: error %d
Error Opening socket: Error %d
IP address resolved to %s
Name resolved to %s
ms-sql-m
No response from udp port %i (%s service)
UDP port %i (%s service): LISTENING
Error accessing port %i
tftp
ms-sql-m
UDP port %i (%s service): LISTENING or FILTERED
UDP port %i (%s service): NOT LISTENING
PortQry encountered an error while attempting to send data to the target system
PortQry Test Message
source port is the same as the destination port
127.0.0.1
run PortQry to query ISAKMP
Cannot use source port %d, this port is already in use
Remote ISAKMP/IPSec services may only communicate with source port 500
on the system you are running PortQry from and run the command again
UDP port 500
Using source port UDP 500
UDP port %i is LISTENING
Using ephemeral source port
Sending LDAP query to TCP port %i...
LDAP query to port %i failed
Sending LDAP query to UDP port %i...
currentdate: %s/%s/%s %s:%s:%s (unadjusted GMT)
currentdate: %s/%s/%s %s:%s:%s (unadjusted GMT)
Log file %s successfully created in current directory
Error closing file %s. Program stopped abnormally. Output may not be complete.
PortQry developed by Tim Rains
Failed to parse Endpoint Mapper's response (%x)
RPC query failed (%x).
TCP port %i is FILTERED
UDP port %i is FILTERED
UUID: %s %s
Error attempting to query the End Point Mapper (%x)
Error encountered attempting to bind to the RPC server (%x)
Error attempting to bind to the RPC server (%x)
ncadg_ip_udp
UDP port: LISTENING
UDP port: FILTERED
NETBIOS name for %s not found (timeout)
Attempting NETBIOS adapter status query to UDP port 137...
Sending ISA query to UDP port %i...
No response from TCP port %i
Error waiting for response: %d
No extended data was returned from the port
PortQry encountered an error while attempting to query the target system
Sending ISA query to TCP port %i...
Sending SNMP query to UDP port %i...
By default PortQry uses the community name: public
Sending DNS query to UDP port %i...
Sending SQL Server query to UDP port %i...
No response from UDP port %i
UDP port %i (%s service): FILTERED
Sending TFTP query to UDP port %i...
Sending L2TP query to UDP port %i...
==== End of SQL Server query response ====
PortQry requires exclusive use of source port UDP 500 for this operation
This port is already in use so PortQry cannot use it
Remote ISAKMP services may only communicate with source port UDP 500
For best results run PortQry in the context of
prevent PortQry from accessing more information
Port and Module Information by Process
AllocateAndGetUdpExTableFromStack
AllocateAndGetTcpExTableFromStack
TCP table not found
UDP table not found
Failed to get TCP endpoints.
Failed to get UDP endpoints.
TCP ports in an UNKNOWN state:
%d = %.2f%%
TCP ports in a DELETE TCB state:
TCP ports in a TIME WAIT state:
TCP ports in a LAST ACK state:
TCP ports in a CLOSING state:
TCP ports in a CLOSE WAIT state:
TCP ports in a FIN WAIT-2 state:
TCP ports in a FIN WAIT-1 state:
TCP ports in a ESTABLISHED state:
TCP ports in a SYN RECEIVED state:
TCP ports in a SYN SENT state:
TCP ports in a LISTENING state:
TCP ports in a CLOSED state:
Port Statistics
TCP mappings: %d
UDP mappings: %d
UDP %i
UDP %i
%d:%s UDP %i
%d:%s
%d:%s UDP %i
%s:%d
%s:%d
TCP %i
TCP %i
%d:%s TCP %i
%d:%s TCP %i
Port
Remote IP:Port
Port
Remote IP:Port
%d mappings found
TCP/UDP Port to Process Mappings
No active ports found on local system
Port
%d active ports found
TCP/UDP Port Usage
Port to process mappings unavailable
%s (0xX)
Process ID: %u
Display Name: %s
Service Name: %s
exiting PortQry Interactive Mode...
TFTP - queries UDP port 69
SQL - queries TCP port 1433 & UDP port 1434
SNMP - queries UDP port 161
SMTP - queries TCP port 25
RPC - queries TCP & UDP port 135
POP3 - queries TCP port 110
MAIL - queries TCP ports 25,110,143
L2TP - queries UDP port 1701
LDAP - queries TCP & UDP port 389
ISA - queries TCP & UDP port 1745
IPSEC - queries UDP port 500
IMAP - queries TCP port 143
FTP - queries TCP port 21
DNS - queries TCP & UDP port 53
sl - toggles slow link delay for UDP queries
- doubles timeout period waiting for UDP responses
protocol=p - set protocol used for query, TCP, UDP, or BOTH
sport=n - set source port number, 0=ephemeral
- set sport= or set sp=
port=n - set port number to query
- set port= or set e=
phelp or ?p - display list of frequently used ports
SNMP community name: %s
Default Node: %s
TFTP
SMTP
*** PortQry version 2.0 ***
*** Can't find address for node %s
%s resolved to %s
WHO DEVELOPED PORTQRY?
slow link delay for UDP disabled
slow link delay for UDP enabled
valid protocol values include: TCP, UDP, and BOTH
example: set protocol=tcp
source port value must be a valid number between 0 and 65535
example: set sport=1200
port value must be a valid number between 1 and 65535
example: set port=53
Type 'phelp' for a sample list of valid ports
Invalid option specified: %s
slow link delay for UDP enabled
source port=
end port=
0.0.0.0
exiting PortQry...
PortQry Interactive Mode
Winsock error: %d
3389 TCP RDP
1701 UDP L2TP
1723 TCP PPTP
1434 TCP/UDP Microsoft-SQL-Monitor
1433 TCP/UDP Microsoft-SQL-Server
500 UDP Internet Key Exchange (IPSec)
464 TCP/UDP Kerberos (v5)
445 TCP/UDP Microsoft CIFS
443 TCP HTTPS
389 TCP/UDP LDAP
162 UDP SNMP TRAP
161 UDP SNMP
143 TCP IMAP4
139 TCP NETBIOS Session Service
138 UDP NETBIOS Datagram Service
137 TCP/UDP NETBIOS Name Service
135 TCP/UDP RPC/DCOM
110 TCP POP3
88 TCP/UDP Kerberos
80 TCP HTTP
69 UDP TFTP
67 UDP DHCP Server
53 TCP/UDP DNS
25 TCP SMTP
23 TCP Telnet
21 TCP FTP-control
20 TCP FTP-data
Port TCP/UDP Service
Frequently Used Ports
UDP port resolved to the '%s' service
TCP port resolved to the '%s' service
escape key pressed: stopped watching port %d
press escape key to stop watching port
UDP mappings: 0
TCP mappings: 0
Specified port currently does not have any port mappings
Watching port: %d
**press escape to stop watching port
Checking for changes every %d seconds
**press escape to stop watching port and close log file
PortQry Version 2.0
Port to process mapping is not supported on this system
escape key pressed: stopped watching PID %d
press escape key to stop watching PID
Specified PID currently does not have any port mappings
Watching PID: %d
zcÁ
OS2SSService-%d
OS2.EXE /S /P
OS2.EXE /S /P C:\OS2\PMSHELL.EXE /C C:\OS2\PMSHELL.EXE
srvany.pdb
2.1.4.0, Mon 03/02/2009 12:32:57.69
SLGetInstalledProductKeyIds
SLGetPKeyId
SLGetPKeyInformation
SLSetCurrentProductKey
osppc.pdb
F64.Mo&
<$=*=8=\>
; ;<;@;\;`;
;(;,;0;4;
8hXXp://crl.microsoft.com/pki/crl/products/CodeSigPCA.crl0M
1hXXp://VVV.microsoft.com/pki/certs/CodeSigPCA.crt0
ChXXp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
<hXXp://VVV.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
$Microsoft Root Certificate Authority0
$Microsoft Root Certificate Authority
?hXXp://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8hXXp://VVV.microsoft.com/pki/certs/MicrosoftRootCert.crt0
.tq[m
8hXXp://VVV.microsoft.com/pki/certs/MicrosoftRootCert.crt0v
hXXp://VVV.microsoft.com0
Signature="$Windows NT$"
AddReg=Add.Reg
[Add.Reg]
HKLM,"SYSTEM\CurrentControlSet\services\KMService","ImagePath",0x20000,"%\srvany.exe"
HKLM,"SYSTEM\CurrentControlSet\services\KMService\Parameters","Application",0x0,"%\KMService.exe"
echo Microsoft (R) Windows Software Licensing.
PortQry -n 127.0.0.1 -e 1688 | findstr /i /r NOT.LISTENING >nul && goto:starts
echo Press 1 to install KMS emulator as Windows Service.
IF ERRORLEVEL 2 echo Emulator running... & start /b KMService.exe >nul && echo
1>nul 2>nul copy /y srvany.exe %WINDIR%\System32 & 1>nul 2>nul copy /y KMService.exe %WINDIR% && echo
1>nul 2>nul instsrv.exe KMService %WINDIR%\System32\srvany.exe && echo
1>nul 2>nul rundll32 advpack,LaunchINFSection service.inf,DefaultInstall,0 && echo
echo Remove KMS host name (sets port to default).
1>nul 2>nul cscript ospp.vbs /remhst
1>nul 2>nul REG DELETE "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\59a52881-a989-479d-af46-f275c6370663" /f
echo Key Management Service machine name set to Localhost successfully.
1>nul 2>nul cscript ospp.vbs /sethst:127.0.0.1
echo Please wait. Executing activation requests...
cscript ospp.vbs /act | find /i "0xC004F074" >nul
if /i %i% == 8 ospprearm.exe >nul & ping -n 2 localhost >nul & goto:second
cscript ospp.vbs /act >check
echo 3. Also try to reinstall KMS-Client key of Office 2010.
status: OK & echo. & cscript ospp.vbs /dstatus & echo Activation successful. %i% attempt(s) used. & goto:end
IF ERRORLEVEL 1 tasklist /fi "imagename eq KMService.exe" 2>nul | find /i /n "KMService.exe" >nul && taskkill /t /f /im KMService.exe 1>nul 2>nul
echo Press any key to exit...
2>nul REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v CurrentVersion | findstr /i 6.* 1>nul
cscript VL.vbs | find /i "NOVOLUME" >nul
PortQry -n 127.0.0.1 -e 1688 | findstr /i /r NOT.LISTENING > nul && goto:starts
choice /C YN /N /M "Is Windows KMS Client key installed? [y/n]: "
echo Key Management Service machine name set to Localhost...
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -skms 127.0.0.1 >check
1>nul 2>nul findstr /l "127.0.0.1" check
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ato | find /i "0xC004F074" >nul
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ato >check
status: OK & echo. & echo. & echo --------------------------------------------------------- & echo. & cscript "%SYSTEMROOT%\System32\slmgr.vbs" -dlv & echo --------------------------------------------------------- & echo. & echo Activation successful. %i% attempt(s) used. & del check & goto:end
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Professional" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:AA
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Professional N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:BB
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:CC
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise E" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:DD
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows 7 Enterprise N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:EE
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 HPC Edition" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:FF
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Datacenter" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:GG
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:HH
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Itanium" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:II
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server 2008 R2 Standard" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:JJ
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Web Server 2008 R2" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:KK
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Business" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:LL
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Business N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:M
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:NN
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Vista (TM) Enterprise N" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:OO
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Datacenter" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:PP
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Itanium" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:QQ
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Enterprise" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:RR
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Server (R) 2008 Standard" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:SS
REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | find /i "Windows Web Server (R) 2008" >nul
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:TT
echo Select your Windows edition from the list: & echo. & goto:keys
:keys
echo ## Windows KMS Client keys manager (6.0; 6.1) ##
:keys1
echo a) Windows 7 Professional l) Windows Vista Business
echo b) Windows 7 Professional N m) Windows Vista Business N
echo c) Windows 7 Enterprise n) Windows Vista Enterprise
echo d) Windows 7 Enterprise E o) Windows Vista Enterprise N
echo e) Windows 7 Enterprise N p) Windows Server 2008 Datacenter
echo f) Windows Server 2008 R2 HPC Edition q) Windows Server 2008 Itanium
echo g) Windows Server 2008 R2 Datacenter r) Windows Server 2008 Enterprise
echo h) Windows Server 2008 R2 Enterprise s) Windows Server 2008 Standard
echo i) Windows Server 2008 R2 Itanium t) Windows Server 2008 Web
echo j) Windows Server 2008 R2 Standard
echo k) Windows Server 2008 R2 Web
choice /C abcdefghijklmnopqrst /N /M "Select installed Windows edition [a-t]: "
set a=Windows 7 Professional
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4 | find /i "FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4" >nul
set a=Windows 7 Professional N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk MRPKT-YTG23-K7D7T-X2JMM-QY7MG | find /i "MRPKT-YTG23-K7D7T-X2JMM-QY7MG" >nul
set a=Windows 7 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 33PXH-7Y6KF-2VJC9-XBBR8-HVTHH | find /i "33PXH-7Y6KF-2VJC9-XBBR8-HVTHH" >nul
set a=Windows 7 Enterprise E
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YDRBP-3D83W-TY26F-D46B2-XCKRJ | find /i "YDRBP-3D83W-TY26F-D46B2-XCKRJ" >nul
set a=Windows 7 Enterprise N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk C29WB-22CC8-VJ326-GHFJW-H9DH4 | find /i "C29WB-22CC8-VJ326-GHFJW-H9DH4" >nul
set a=Windows Server 2008 R2 HPC Edition
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk FKJQ8-TMCVP-FRMR7-4WR42-3JCD7 | find /i "FKJQ8-TMCVP-FRMR7-4WR42-3JCD7" >nul
set a=Windows Server 2008 R2 Datacenter
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 74YFP-3QFB3-KQT8W-PMXWJ-7M648 | find /i "74YFP-3QFB3-KQT8W-PMXWJ-7M648" >nul
set a=Windows Server 2008 R2 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 489J6-VHDMP-X63PK-3K798-CPX3Y | find /i "489J6-VHDMP-X63PK-3K798-CPX3Y" >nul
set a=Windows Server 2008 R2 Itanium
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk GT63C-RJFQ3-4GMB6-BRFB9-CB83V | find /i "GT63C-RJFQ3-4GMB6-BRFB9-CB83V" >nul
set a=Windows Server 2008 R2 Standard
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YC6KT-GKW9T-YTKYR-T4X34-R7VHC | find /i "YC6KT-GKW9T-YTKYR-T4X34-R7VHC" >nul
set a=Windows Web Server 2008 R2
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 6TPJF-RBVHG-WBW2R-86QPH-6RTM4 | find /i "6TPJF-RBVHG-WBW2R-86QPH-6RTM4" >nul
set a=Windows Vista Business
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YFKBB-PQJJV-G996G-VWGXY-2V3X8 | find /i "YFKBB-PQJJV-G996G-VWGXY-2V3X8" >nul
set a=Windows Vista Business N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk HMBQG-8H2RH-C77VX-27R82-VMQBT | find /i "HMBQG-8H2RH-C77VX-27R82-VMQBT" >nul
set a=Windows Vista Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk VKK3X-68KWM-X2YGT-QR4M6-4BWMV | find /i "VKK3X-68KWM-X2YGT-QR4M6-4BWMV" >nul
set a=Windows Vista Enterprise N
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk VTC42-BM838-43QHV-84HX6-XJXKV | find /i "VTC42-BM838-43QHV-84HX6-XJXKV" >nul
set a=Windows Server 2008 Datacenter
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 7M67G-PC374-GR742-YH8V4-TCBY3 | find /i "7M67G-PC374-GR742-YH8V4-TCBY3" >nul
set a=Windows Server 2008 Itanium
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk 4DWFP-JF3DJ-B7DTH-78FJB-PDRHK | find /i "4DWFP-JF3DJ-B7DTH-78FJB-PDRHK" >nul
set a=Windows Server 2008 Enterprise
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk YQGMW-MPWTJ-34KDK-48M3W-X4Q6V | find /i "YQGMW-MPWTJ-34KDK-48M3W-X4Q6V" >nul
set a=Windows Server 2008 Standard
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk TM24T-X9RMF-VWXK6-X8JC9-BFGM2 | find /i "TM24T-X9RMF-VWXK6-X8JC9-BFGM2" >nul
set a=Windows Web Server 2008
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -ipk WYR28-R7TFJ-3X2YQ-YCY4H-M249D | find /i "WYR28-R7TFJ-3X2YQ-YCY4H-M249D" >nul
echo The function can work on Windows 6.0 or newer only.
echo Error! After %i% plenty of attempts Windows activation failed.
if /i %b% == 3 echo Error! Key %i% installation failed. & goto:end
echo Error! Key %i% installation failed. Try more.
goto:keys1
echo Key %i% successfully installed.
echo Error! Operation is not completed.
echo Windows edition detected is not a VL edition.
echo. & cscript ospp.vbs /dstatus
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -dlv
echo ## Key Manager Office 2010 VL ##
1>nul 2>nul cscript ospp.vbs /unpkey:H3GVB
echo Product key uninstall successful.
cscript ospp.vbs /inpkey:VYBBJ-TRJPB-QFQRF-QFT4D-H3GVB | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:8R6BM
cscript ospp.vbs /inpkey:V7QKV-4XVVR-XYV4D-F7DFM-8R6BM | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:VVRCK
cscript ospp.vbs /inpkey:D6QFG-VBYP2-XQHM7-J97RH-VVRCK | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:VHKC6
cscript ospp.vbs /inpkey:YGX6F-PGV49-PGW3J-9BTGG-VHKC6 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:F9PGB
cscript ospp.vbs /inpkey:4HP3K-88W3F-W2K3D-6677X-F9PGB | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:WX8BJ
cscript ospp.vbs /inpkey:D9DWC-HPYVV-JGF4P-BTWQB-WX8BJ | find /i "0xC004F050" >nul
set i=7MCW8-VRQVK-G677T-PDJCM-Q8TCP
1>nul 2>nul cscript ospp.vbs /unpkey:Q8TCP
cscript ospp.vbs /inpkey:7MCW8-VRQVK-G677T-PDJCM-Q8TCP | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:KHFGJ
cscript ospp.vbs /inpkey:767HD-QGMWX-8QTDB-9G3R2-KHFGJ | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:38W9R
cscript ospp.vbs /inpkey:YBJTT-JG6MD-V9Q7P-DBKXJ-38W9R | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:B8K32
cscript ospp.vbs /inpkey:7TC2V-WXF6P-TD7RT-BQRXR-B8K32 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:CRY7T
cscript ospp.vbs /inpkey:HVHB3-C6FV7-KQX9W-YQG79-CRY7T | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:CW9BM
cscript ospp.vbs /inpkey:H62QG-HXVKF-PP4HP-66KMR-CW9BM | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:P4VTT
cscript ospp.vbs /inpkey:RC8FX-88JRY-3PF7C-X8P67-P4VTT | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:X3DWQ
cscript ospp.vbs /inpkey:7YDC2-CWM8M-RRTJC-8MDVC-X3DWQ | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:T7DDX
cscript ospp.vbs /inpkey:V7Y44-9T38C-R2VJK-666HK-T7DDX | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:4T3J4
cscript ospp.vbs /inpkey:QYYW6-QP4CB-MBV6G-HYMCJ-4T3J4 | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:BT37T
cscript ospp.vbs /inpkey:K96W8-67RPQ-62T9Y-J8FQJ-BT37T | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:D3XHX
cscript ospp.vbs /inpkey:Q4Y4M-RHWJM-PY37F-MTKWH-D3XHX | find /i "0xC004F050" >nul
1>nul 2>nul cscript ospp.vbs /unpkey:83YTP
cscript ospp.vbs /inpkey:BFK7F-9MYHM-V68C7-DRQ66-83YTP | find /i "0xC004F050" >nul
echo Selected key %i% successfully installed.
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:A
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:B
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:C
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:D
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:E
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:F
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:G
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:H
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:I
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:J
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:K
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:L
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:N
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:O
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:P
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:Q
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:R
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:S
IF NOT ERRORLEVEL 1 echo Installed OS successfully determined. & echo. & echo Installing key... & goto:T
tasklist /fi "imagename eq KMService.exe" 2>nul | find /i /n "KMService.exe" >nul && taskkill /t /f /im KMService.exe 1>nul 2>nul && echo
1>nul 2>nul del %WINDIR%\System32\srvany.exe & ping -n 3 localhost >nul & 1>nul 2>nul del %WINDIR%\KMService.exe && echo
ospprearm.exe | find /i "Microsoft Office rearm successful." >nul
1>nul 2>nul cscript ospp.vbs /osppsvcrestart
choice /C YN /N /M "You have selected Windows trial reset. Continue? [y/n]: "
cscript "%SYSTEMROOT%\System32\slmgr.vbs" -rearm
IF NOT ERRORLEVEL 1 cscript HS_MESSAGE.vbs "KMService it is successfully restarted." "Activation Tool" I OK & exit
IF ERRORLEVEL 1 cscript HS_MESSAGE.vbs "KMService it not installing or not running." "Activation Tool" E OK & exit
relese date 29.04.2010
The activator is based on ZWT KMS-Keygen.
KMS-Keygen is installed as Windows Service, not too much memory used, around 2 mb of RAM.
Code generated by KMS-Keygen is not always valid, that
This is KMS-Keygen problem, but not the the activator fault.
Activator works on 32 and 64 edition of Office 2010 and Windows 6.0 or newer.
Trial reset for all Office 2010 products and Windows 6.0 or newer
Entering of KMS-Client keys for all Windows VL editions
Activation of Windows 6.0 VL products
Activation status check of Windows 6.0 products
In Volume versions of Office 2010 KMS client key is installed by default
s recommended to reinstall Office 2010 VL keys
For Windows activation you have to install the respective KMS client key first.
Windows key depends on edition of product installed! (Enterprise, Professional, Home etc).
1.051 - Optimized error recognition during Office 2010 and Windows activation,
and while entering windows keys.
1.052 - Office 2010 products trial reset is based on final RTM release 14.0.4763.1000.
Fixed: On some systems menu inaccessible (flashing cmd window).
For activation You have choice: run KMS server as windows service or run it once.
Added: Installed OS is automatically determined and the respective key is installed without asking user.
Added detection of activation possibility using volume license channel (for Windows 6.1).
Added GVLK keys for all office 2010 products (Thanks swmyp & Dark_Diver).
Optimized installation and removing of KMService on Windows Server 2003.
Used unpacked ZWT KMS-keygen (Thanks Dark_Diver).
* Activator work depends on generated by ZWT KMS-Keygen activation codes.
ZWT KMS-keygen.
KMS-keygen
Windows,
, KMS-keygen
Windows
Windows;
Windows.
14.0.4763.1000.
Windows 6.1)
Windows Server 2003.
ZWT KMS-keygen,
ZWT KMS-keygen'
Windows NT 6.0
Windows 7 Professional; Windows 7 Professional N; Windows 7 Enterprise; Windows 7 Enterprise E; Windows 7 Enterprise N;
Windows Server 2008 R2 HPC Edition; Windows Server 2008 R2 Datacenter; Windows Server 2008 R2 Enterprise; Windows Server 2008 R2 Itanium;
Windows Server 2008 R2 Standard; Windows Server 2008 R2 Web; Windows Vista Business; Windows Vista Business N; Windows Vista Enterprise;
Windows Vista Enterprise N; Windows Server 2008 Datacenter; Windows Server 2008 Itanium; Windows Server 2008 Enterprise;
Windows Server 2008 Standard; Windows Server 2008 Web.
, Windows 7 Ultimate?
KMS-keygen
Windows VL".
Windows
Windows - 10.
(KMS-keygen)
Windows?
127.0.0.1.
ZWT KMS-keygen
Windows VL".
Windows KMS Client
) Windows?
Windows".
Windows.On Error Resume Next
Set Args=WScript.Arguments
Set WshShell=WScript.CreateObject("WScript.Shell")
If Args.Count<4 Or Args.Count>5 Then WScript.Quit(255)
If Args.Count=5 Then nSecondsToWait=Args(4) Else nSecondsToWait=0
WScript.Quit( WshShell.Popup(strText, nSecondsToWait, strTitle, nType) )
CONST HKEY_LOCAL_MACHINE =&H80000002
CONST KEY_SET_VALUE =&H0002
CONST KEY_QUERY_VALUE =&H0001
CONST OfficeAppId = "59a52881-a989-479d-af46-f275c6370663"
CONST STR_SYS32PATH = ":\Windows\System32\"
CONST MSG_NOREGRIGHTS = "Insufficient rights to perform operation."
CONST MSG_ISCMD_ELEVATED = "Ensure cmd.exe is elevated (right click > run as administrator)."
CONST MSG_CREDENTIALFAILURE = "Connection failed with passed credentials."
CONST MSG_FILENOTFOUND = "File not found: "
CONST MSG_CREDENTIALERR = "Passing credentials not supported for this option."
CONST MSG_SEPERATE = "---------------------------------------------------------"
CONST MSG_PROCESSING = " "
CONST MSG_EXIT = " "
CONST MSG_UNSUPPORTED = "Unsupported command passed."
CONST MSG_SUCCESS = "Successfully applied setting."
CONST MSG_ACTATTEMPT = "Installed product key detected - attempting to activate the following product:"
CONST MSG_TOKACTATTEMPT = "Installed product key detected - attempting to token activate the following product:"
CONST MSG_NOKEYSINSTALLED = "<No installed product keys detected>"
CONST MSG_UNINSTALLKEYSUCCESS = "<Product key uninstall successful>"
CONST MSG_ACTSUCCESS = "<Product activation successful>"
CONST MSG_OFFLINEACTSUCCESS = "<Offline product activation successful>"
CONST MSG_KEYINSTALLSUCCESS = "<Product key installation successful>"
CONST MSG_PARTIALKEY = "Last 5 characters of installed product key: "
CONST MSG_UNINSTALLKEY = "Uninstalling product key for: "
CONST MSG_UNRECOGFILE = "Unrecognized file. Office 2010 licenses have an .xrm-ms file extension."
CONST MSG_INSTALLLICENSE = "Installing Office 2010 license: "
CONST MSG_INSTALLLICSUCCESS = "Office 2010 license installed successfully."
CONST MSG_SEARCHEVENTSKMS = "Searching for KMS activation events on machine: "
CONST MSG_SEARCHEVENTSRET = "Searching for Internet activation failure events on machine: "
CONST MSG_NOEVENTSSKMS = "No KMS activation events found on machine: "
CONST MSG_NOEVENTSRET = "No failure events found on machine: "
CONST MSG_OSPPSVC_NOINSTALL = "Error: The Software Protection Platform service is not installed."
CONST MSG_OSPPSVC_NORUN = "Error: The Software Protection Platform service is not running."
CONST MSG_ERRPARTIALKEY = "The last 5 characters of an installed product key are required to run this option. Run the /dstatus option to display the partial product key."
CONST MSG_KEYNOTFOUND = "<Product key not found>"
CONST MSG_CMID = "Client Machine ID (CMID): "
CONST MSG_NOLICENSEFOUND = "<No licenses found>"
CONST MSG_REMILID = "Removed Token-based Activation License with License ID (ILID): "
CONST MSG_NOTFOUNDILID = "License not found with License ID (ILID): "
CONST MSG_SKUID = "SKU ID: "
CONST MSG_LICENSENAME = "LICENSE NAME: "
CONST MSG_DESCRIPTION = "LICENSE DESCRIPTION: "
CONST MSG_LICSTATUS = "LICENSE STATUS: "
CONST MSG_LICENSED = " ---LICENSED--- "
CONST MSG_UNLICENSED = " ---UNLICENSED--- "
CONST MSG_OOBGRACE = " ---OOB_GRACE--- "
CONST MSG_OOTGRACE = " ---OOT_GRACE--- "
CONST MSG_NONGENGRACE = " ---NON_GENUINE_GRACE--- "
CONST MSG_NOTIFICATION = " ---NOTIFICATIONS--- "
CONST MSG_EXTENDEDGRACE = " ---EXTENDED GRACE--- "
CONST MSG_LICUNKNOWN = " ---UNKNOWN--- "
CONST MSG_REMAINGRACE = "REMAINING GRACE: "
CONST MSG_ERRCODE = "ERROR CODE: "
CONST MSG_ERRDESC = "ERROR DESCRIPTION: "
CONST MSG_ERRUNKNOWN = "An unknown error occurred."
CONST MSG_ERRCODEVALUE = "An error code must start with '0x'. Example: 0xC004F009"
Set WshShell = WSCript.CreateObject("WSCript.Shell")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objNetwork = WSCript.CreateObject("WSCript.Network")
currentDir = Left(WScript.ScriptFullName, InStrRev(WScript.ScriptFullName, "\"))
Select Case WSCript.Arguments.Count
verifyFileExists currentDir & "ospp.htm"
showIePopUp currentDir & "ospp.htm"
WScript.Quit
var1 = WSCript.Arguments(0)
var2 = WSCript.Arguments(1)
var3 = WSCript.Arguments(2)
var4 = WSCript.Arguments(3)
Sub Main(strCommand,strMachine,strUser,strPassword)
strLocal = objNetwork.ComputerName
"/remhst", "/stokflag", "/ctokflag", "/dcmid", "/dtokcerts"
connectWMI strMachine,strUser,strPassword,""
connectWMI strMachine,strUser,strPassword,"reg"
registerMof "osppwmi.mof"
globalPopFailure MSG_UNSUPPORTED,True
Case "/inpkey", "/unpkey", "/inslic", "/actcid", "/sethst", "/setprt", "/ddescr", "/rtokil", "/tokact"
globalPopFailure MSG_UNSUPPORTED & " A value is required for: " & strCommand,True
WScript.Echo MSG_ERRCODEVALUE
connectWMI strMachine,strUser,strPassword,""
globalPopFailure MSG_UNSUPPORTED,True
Set objExplorer = CreateObject("InternetExplorer.Application")
.Navigate strPath
.ToolBar = 0
.StatusBar = 0
.Width = 1000
.Height = 593
.Left = 1
.Top = 1
.Visible = 1
strEngine = LCase(Right(WScript.FullName,12))
If strEngine <> "\cscript.exe" Then
WshShell.Popup "Unable to perform operation. " & WSCript.ScriptName & " requires the cscript engine." & _
vbCr & "Command line example: cscript ospp.vbs ?", _
,WSCript.ScriptName, VALUE_ICON_WARNING
WScript.Quit
globalPopFailure "slui.exe not found.",True
Set objScriptExec = WshShell.Exec (strSluiPath & " 0x2a " & strSearch)
readOut = objScriptExec.StdOut.ReadAll
Function checkRegRights(wmiObject,strKeyPath)
wmiObject.CheckAccess HKEY_LOCAL_MACHINE, strKeyPath, KEY_SET_VALUE, _
globalPopFailure MSG_NOREGRIGHTS & vbCr & MSG_ISCMD_ELEVATED,True
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_EXIT
WSCript.Quit
If Not objFSO.FileExists(file) Then
If file = currentDir & "slerror.xml" Then
WScript.Echo "[" & MSG_FILENOTFOUND & file & " Unable to display error description.]"
ElseIf file = currentDir & "ospp.htm" Then
globalPopFailure MSG_FILENOTFOUND & vbCr & file,False
globalPopFailure MSG_FILENOTFOUND & vbCr & file,True
For Each Drv In objFSO.Drives
If Drv.DriveType=2 Then
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "wbem\mofcomp.exe") Then
strMofExePath = Drv.DriveLetter & STR_SYS32PATH & "wbem\mofcomp.exe"
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "wbem\" & strFile) Then
strOWmi = Drv.DriveLetter & STR_SYS32PATH & "wbem\" & strFile
Set objScriptExec = WshShell.Exec (strMofExePath & " " & strOWmi)
readOut = objScriptExec.StdOut.ReadAll
WScript.Echo readOut
globalPopFailure MSG_FILENOTFOUND & Replace(STR_SYS32PATH,":","") & "wbem\mofcomp.exe",True
globalPopFailure MSG_FILENOTFOUND & Replace(STR_SYS32PATH,":","") & "wbem\osppwmi.mof",True
WScript.Echo MSG_PROCESSING
If objFSO.FileExists(Drv.DriveLetter & STR_SYS32PATH & "slui.exe") Then
strSluiPath = Drv.DriveLetter & STR_SYS32PATH & "slui.exe"
WScript.Echo MSG_INSTALLLICENSE & licFile
objSpp.InstallLicense(LicenseData)
Set oStream = CreateObject("ADODB.Stream")
oStream.Type = 1 'adTypeBinary
oStream.Open
oStream.LoadFromFile(strFileName)
strData = BinaryToString(oStream.Read(2))
oStream.Position = 0
strData = BinaryToString(oStream.Read(3))
oStream.Close
' Supports ascii, unicode (little-endian) and utf-8 encoding.
oStream.Type = 2 'adTypeText
oStream.Charset = GetFileEncoding(strFileName)
strData = oStream.ReadText(-1) 'adReadAll
globalErr = Hex(Err.Number)
Select Case Err.Number
WScript.Echo MSG_ACTSUCCESS
Case "/inpkey"
WScript.Echo MSG_KEYINSTALLSUCCESS
WScript.Echo MSG_INSTALLLICSUCCESS
WScript.Echo MSG_SUCCESS
WScript.Echo MSG_REMILID & UCase(strValue)
Case "/unpkey"
WScript.Echo MSG_UNINSTALLKEYSUCCESS
verifyFileExists currentDir & "slerror.xml"
WScript.Echo MSG_ERRDESC & MSG_ERRUNKNOWN
WScript.Echo MSG_ERRCODE & "0x" & globalErr
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:0x" & globalErr
WScript.Echo MSG_ERRCODE & "0x" & globalErr
WScript.Echo MSG_ERRCODE & "0x" & globalErr
Wscript.Echo MSG_ERRDESC & globalResource
If strCommand = "/dtokcerts" Or strCommand = "/ignore" Then
WScript.Echo "To view the activation event history run: cscript " & WScript.ScriptName & " /dhistorykms"
Err.Clear
globalPopFailure MSG_ERRCODE & Err.Number & vbCr & MSG_ERRDESC & MSG_CREDENTIALFAILURE,True
If Err.Description <> "" Then
globalPopFailure MSG_ERRCODE & Err.Number & vbCr & MSG_ERRDESC & Err.Description,True
globalPopFailure "An error occurred while making the connection." & vbCr & MSG_ERRCODE & Err.Number,True
Err.Clear()
strKeyPath = REG_SPP
Case "UserOperations"
wmiObject.CreateKey HKEY_LOCAL_MACHINE,strKeyPath
wmiObject.SetDWORDValue HKEY_LOCAL_MACHINE,_
strKeyPath,strValueName,opsValue
WScript.Echo MSG_SUCCESS
Set xmlDoc = CreateObject("Msxml2.DOMDocument")
xmlDoc.load(currentDir & "slerror.xml")
Set ElemList = xmlDoc.getElementsByTagName(resource)
resValue = ElemList.item(0).text
WshShell.Popup strSuccess,,WScript.ScriptName, wshOK VALUE_ICON_INFORMATION
WshShell.Popup strFailure,,WScript.ScriptName, wshOK VALUE_ICON_WARNING
Function connectWMI(strMachine,strUser,strPassword,ctype)
If strUser = "" And strPassword = "" Then
Set objSWbemLocator = CreateObject("WbemScripting.SWbemLocator")
Set objWMI = objSWbemLocator.ConnectServer _
(strMachine, "\root\cimv2", strUser, strPassword)
wmiErr = CStr(Hex(Err.Number))
objWMI.Security_.ImpersonationLevel = 3
globalPopFailure MSG_CREDENTIALERR,True
Set TkaGetSigner = WScript.CreateObject("OSPPWMI.OSppWmiTokenActivationSigner")
If Hex(Err.Number) = "80020009" Then
globalPopFailure MSG_ERRCODE & "0x" & Hex(Err.Number) & vbCr & MSG_ERRDESC & Err.Description,True
Function TkaPrintCertificate(strThumbprint)
WScript.Echo "Thumbprint: " & arrParams(0)
WScript.Echo "Subject: " & arrParams(1)
WScript.Echo "Issuer: " & arrParams(2)
WScript.Echo "Valid From: " & vf
WScript.Echo "Valid To: " & vt
WScript.Echo MSG_SEPERATE
Function ExecuteQuery(strSelect,strWhere,strClass)
Set productinstances = objWMI.ExecQuery("SELECT " & strSelect & " FROM " & strClass)
Set productinstances = objWMI.ExecQuery("SELECT " & strSelect & " FROM " & strClass & " WHERE " & strWhere)
verifyFileExists currentDir & "slerror.xml"
strSrcEvents = MSG_SEARCHEVENTSKMS
strNoEvents = MSG_NOEVENTSSKMS
strSrcEvents = MSG_SEARCHEVENTSRET
strNoEvents = MSG_NOEVENTSRET
WScript.Echo strSrcEvents & strMachine
WScript.Echo strSrcEvents & strLocal
WScript.Echo "Event ID: " & eventCode
WScript.Echo vbCr
Set objEvents = objWMI.ExecQuery _
If objEvents.Count > 0 Then
dtmEventDate = objEvent.TimeWritten
WScript.Echo "Coordinated Universal Time Written: " & strTimeWritten
strReplCrs = Replace(objEvent.Message,vbCrLf,"")
WScript.Echo "MESSAGE: " & strReplCrs
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:" & strhr10
WScript.Echo MSG_ERRDESC & "Not available."
Wscript.Echo MSG_ERRDESC & globalResource
WScript.Echo MSG_SEPERATE
strhr10 = Mid(objEvent.Message,90,10)
strReplStrs = Replace(strReplCrs,"The client has sent an activation request to the key management service machine.Info:","")
dtmEventDate = objEvent.TimeWritten
WScript.Echo "Coordinated Universal Time Written: " & strTimeWritten
WScript.Echo "ERROR/HOST: " & strErrHost
WScript.Echo MSG_ERRDESC & "N/A"
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:" & strhr10
WScript.Echo MSG_ERRDESC & "Not available."
Wscript.Echo MSG_ERRDESC & globalResource
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_SEPERATE
WScript.Echo strNoEvents & strMachine
WScript.Echo strNoEvents & strLocal
Set colListOfServices = objWMI.ExecQuery _
If objService.Name = "osppsvc" Then
If LCASE(objService.State) = "running" Then
globalPopFailure MSG_OSPPSVC_NOINSTALL,True
Set colOperatingSystems = objWMI.ExecQuery _
("Select * from Win32_OperatingSystem")
For Each objOperatingSystem in colOperatingSystems
strOsVersion = Left(objOperatingSystem.Version,3)
globalPopFailure MSG_OSPPSVC_NORUN & vbcr & "Current State: " & objService.State & vbCr & "Run: cscript ospp.vbs /osppsvcrestart",True
Case "/inpkey", "/dcmid", "/inslic", "/sethst", "/setprt", "/remhst", "/stokflag", "/ctokflag"
For Each objService in objWMI.InstancesOf("OfficeSoftwareProtectionService")
If strCommand = "/inpkey" Then
Err.Clear
objOspp.InstallProductKey(strValue)
If objOspp.ClientMachineID <> "" Or objOspp.ClientMachineID <> Null Then
WScript.Echo MSG_CMID & objOspp.ClientMachineID
WScript.Echo MSG_CMID & "Not found."
If Right(strValue,7) = ".xrm-ms" Then
WScript.Echo MSG_INSTALLLICENSE & strValue
globalPopFailure MSG_UNRECOGFILE,True
objOSpp.InstallLicense(LicenseData)
objOspp.SetKeyManagementServiceMachine(strValue)
objOspp.SetKeyManagementServicePort(strValue)
objOspp.ClearKeyManagementServiceMachine()
objOspp.ClearKeyManagementServicePort()
objOspp.DisableKeyManagementServiceActivation(True)
objOspp.DisableKeyManagementServiceActivation(False)
Err.Clear
Set objWmiDate = CreateObject("WBemScripting.SWbemDateTime")
WScript.Echo "License ID (ILID): " & instance.ILID
WScript.Echo "Version ID (ILvID): " & instance.ILVID
If Not IsNull(instance.ExpirationDate) Then
objWmiDate.Value = instance.ExpirationDate
If (objWmiDate.GetFileTime(false) <> 0) Then
WScript.Echo "Expiry Date: " & objWmiDate.GetVarDate
If Not IsNull(instance.AdditionalInfo) Then
WScript.Echo "Additional Info: " & instance.AdditionalInfo
If Not IsNull(instance.AuthorizationStatus) And instance.AuthorizationStatus <> 0 Then
globalErr = CStr(Hex(instance.AuthorizationStatus))
WScript.Echo "Description: " & instance.Description
WScript.Echo MSG_SEPERATE
WScript.Echo MSG_NOLICENSEFOUND
Err.Clear
If LCase(strValue) = LCase(instance.ILID) Then
instance.Uninstall
WScript.Echo MSG_NOTFOUNDILID & strValue & " Run /dtokils to display the ILID for installed licenses."
ElseIf strCommand = "/dtokcerts" Then
ExecuteQuery "ID, Name, ApplicationId, PartialProductKey, Description, LicenseIsAddon ","ApplicationId = '" & OfficeAppId & "' " & "AND PartialProductKey <> NULL " & "AND LicenseIsAddon = FALSE","OfficeSoftwareProtectionProduct"
iRet = instance.GetTokenActivationGrants(arrGrants)
If Err.Number = 0 Then
arrThumbprints = objSigner.GetCertificateThumbprints(arrGrants)
If Err.Number = 0 Then
TkaPrintCertificate strThumbprint
'PIN not passed
'PIN passed
WScript.Echo MSG_TOKACTATTEMPT
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_DESCRIPTION & instance.Description
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
iRet = instance.GenerateTokenActivationChallenge(strChallenge)
strAuthInfo1 = objSigner.Sign(strChallenge, strThumbprint, strPin, strAuthInfo2)
iRet = instance.DepositTokenActivationResponse(strChallenge, strAuthInfo1, strAuthInfo2)
ExecuteQuery "ID, ApplicationId, PartialProductKey, Description, Name, LicenseStatus, LicenseStatusReason, ProductKeyID, GracePeriodRemaining","","OfficeSoftwareProtectionProduct"
ExecuteQuery "ID, ApplicationId, PartialProductKey, Description, Name","PartialProductKey <> null","OfficeSoftwareProtectionProduct"
ElseIf strCommand = "/unpkey" Then
ExecuteQuery "ID, ApplicationId, PartialProductKey, Name, ProductKeyID","","OfficeSoftwareProtectionProduct"
ExecuteQuery "ID, ApplicationId, PartialProductKey, Name, OfflineInstallationId","PartialProductKey <> null","OfficeSoftwareProtectionProduct"
If (LCase(instance.ApplicationId) = OfficeAppId) Then
If instance.PartialProductKey <> "" Then
WScript.Echo MSG_ACTATTEMPT
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_DESCRIPTION & instance.Description
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
instance.Activate
WScript.Echo MSG_SEPERATE
Case "/unpkey"
globalPopFailure MSG_ERRPARTIALKEY,True
If UCase(strValue) = instance.PartialProductKey Then
WScript.Echo MSG_UNINSTALLKEY & instance.Name
instance.UninstallProductKey(instance.ProductKeyID)
WScript.Echo "Installation ID for: " & instance.Name & ": " & instance.OfflineInstallationId
instance.DepositOfflineConfirmationId instance.OfflineInstallationId, strValue
If Err.Number = 0 Then
WScript.Echo MSG_LICENSENAME & instance.Name
WScript.Echo MSG_OFFLINEACTSUCCESS
WScript.Echo MSG_LICENSENAME & instance.Name
verifyFileExists currentDir & "slerror.xml"
licSr = Hex(instance.LicenseStatusReason)
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_DESCRIPTION & instance.Description
If instance.ProductKeyID <> "" Then
WScript.Echo MSG_SKUID & instance.ID
WScript.Echo MSG_DESCRIPTION & instance.Description
Select Case instance.LicenseStatus
WScript.Echo MSG_LICSTATUS & MSG_UNLICENSED
WScript.Echo MSG_LICSTATUS & MSG_LICENSED
WScript.Echo MSG_ERRCODE & licSr & " as licensed"
WScript.Echo MSG_LICSTATUS & MSG_OOBGRACE
WScript.Echo MSG_LICSTATUS & MSG_OOTGRACE
WScript.Echo MSG_LICSTATUS & MSG_NONGENGRACE
WScript.Echo MSG_LICSTATUS & MSG_NOTIFICATION
WScript.Echo MSG_LICSTATUS & MSG_EXTENDEDGRACE
WScript.Echo MSG_LICSTATUS & MSG_LICUNKNOWN
WScript.Echo MSG_ERRCODE & "0x" & licSr
WScript.Echo MSG_ERRDESC & "Not available."
WScript.Echo MSG_ERRDESC & "Run the following: cscript ospp.vbs /ddescr:0x" & licSr
WScript.Echo MSG_ERRDESC & globalResource
If instance.PartialProductKey <> "" Then
WScript.Echo MSG_PARTIALKEY & instance.PartialProductKey
If instance.GracePeriodRemaining <> 0 Then
dGrace = instance.GracePeriodRemaining / 60 / 24
WScript.Echo MSG_REMAINGRACE & Round(dGrace) & " days " & " (" & instance.GracePeriodRemaining & " minute(s) before expiring" & ")"
WScript.Echo MSG_SEPERATE
If strCommand = "/unpkey" And y = 0 Then
WScript.Echo MSG_KEYNOTFOUND
WScript.Echo MSG_NOKEYSINSTALLED
Set colListOfServices = objWMI1.ExecQuery _
setRegValue objWMI,"1","UserOperations"
setRegValue objWMI,"0","UserOperations"
Set colListOfServices = objWMI.ExecQuery _
If LCase(objService.Name) = "osppsvc" Then
objService.Change , , , , "Automatic"
WScript.Sleep(15000)
WScript.Echo "Service startup type already set to automatic: Office Software Protection Platform"
Set colListOfServices = objWMI.ExecQuery _
WScript.Echo "Successfully set service startup to automatic:" & objService.DisplayName
WScript.Echo "Unsuccessful setting service startup to automatic. " & MSG_ISCMD_ELEVATED
If LCase(objService.Name) = "osppsvc" Then
Select Case LCase(objService.State)
objService.StopService()
WScript.Sleep(15000)
objService.StartService()
If LCase(objService.State) = "running" Then
WScript.Echo "Successfully restarted: " & objService.DisplayName
WScript.Echo "Unsuccessful restart: " & objService.DisplayName & ". Status: " _
& objService.State & ". " & MSG_ISCMD_ELEVATED
CONST WindowsAppId
= "55c92734-d682-4d71-983e-d6ec3f16059f"
= "bfe7a195-4f8f-4f0b-a622-cf13c7d16864"
CONST MSG_NOVL
Set WshShell = WScript.CreateObject("WScript.Shell")
Set fso = CreateObject("Scripting.FileSystemObject")
workingDir = Left(WScript.ScriptFullName, InStrRev(WScript.ScriptFullName, "\"))
For Each objOS in GetObject("winmgmts:").InstancesOf("Win32_OperatingSystem")
Ver = Split(objOS.Version, ".", -1, 1)
If (Ver(0) = "6" And Ver(1) = "1" And objOS.ProductType = 1) Then
If (Ver(0) = "6" And Ver(1) = "1" And (objOS.ProductType = 2 Or objOS.ProductType = 3)) Then
If (Ver(0) = "6" And Ver(1) = "0" And objOS.ProductType = 1) Then
If (Ver(0) = "6" And Ver(1) = "0" And (objOS.ProductType = 2 Or objOS.ProductType = 3)) Then
For Each objService in objWMIService.InstancesOf("SoftwareLicensingService")
Set productinstances = objWMIService.InstancesOf("SoftwareLicensingProduct")
If (LCase(instance.ApplicationId) = WindowsAppId) Then
intOccur = InStr(UCase(instance.Description),"VOLUME_KMS")
intOccurClient = InStr(UCase(instance.Description),"VOLUME_KMSCLIENT")
WScript.Echo MSG_NOVL
HorzScrollBar.Visible
VertScrollBar.Visible
Icon.Data
Pages.Strings
IconData.Data
APMCursor.Data
APMHotCursor.Data
Splash.Data
\3:>>261
R]]%U
M%7sl
HintFont.Charset
HintFont.Color
HintFont.Height
HintFont.Name
HintFont.Style
This CD has expired on %s.
UserVersion.FileVerMajor
UserVersion.FileVerMinor
UserVersion.FileVerRelease
UserVersion.FileVerBuild
ÍROM%\KMSIns.cmd
ÍROM%\ActOf.cmd
ÍROM%\ChkOf.cmd
Windows VL keys manager|
Key Manager Windows VL
ÍROM%\KeyMngW.cmd
Windows activation status check|
Activation check Windows
ÍROM%\ChkWin.cmd
ÍROM%\hidcon.exe
Rest.cmd
ÍROM%\RearmOf.cmd
)Windows and Windows Server VL activation|
Activation Windows VL
ÍROM%\ActWin.cmd
Windows trial reset|
Rearm Windows
ÍROM%\RearmW.cmd
ÍROM%\Help.txt
Office 2010 VL keys manager|
Key Manager Office 2010 VL
ÍROM%\KeyMngOf.cmd
PAslerror.xml*33019*autorun.exe*1511424*choice.exe*36864*cscript.exe*153088*hidcon.exe*2048*instsrv.exe*32256*KMService.exe*151552*ospprearm.exe*14176*PortQry.exe*143360*srvany.exe*8192*osppc.dll*127232*service.inf*1012*ActOf.cmd*4104*ActWin.cmd*16286*ChkOf.cmd*590*ChkWin.cmd*764*KeyMngOf.cmd*7166*KeyMngW.cmd*12255*KMSIns.cmd*2671*RearmOf.cmd*958*RearmW.cmd*770*Rest.cmd*290*Start.cmd*206*Help.txt*12329*hs_message.vbs*796*ospp.vbs*49377*VL.vbs*3230*autorun.apm*267407*PADStart.cmdPAD
EnumChildWindows
.code
`.text
TFRMMSG
1.9.3.0
!Cannot link to an invalid source.&Break link operation is not supported.
%s Properties%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid stream operation
nThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
128-Byte PrefetchingjThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.
Rich Text Format (*.rtf)|*.rtf
Plain text (*.txt)|*.txt
CompuServe GIF ImageÊnnot change the Size of a GIF image
All Supported Files
&About...kThis menu is created with AutoPlay Menu Builder, please visit hXXp://VVV.linasoft.com for more information.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Can't open %s.
The file or path doesn't exist.RThere is no application associated with the given file name extension or protocol./The application doesn't exist or access denied.
The executable file is invalid.
Out of memory.,%s doesn't contain any supported image file.1Press ESC to quit, double click for next picture.6Press ESC to quit, click left button for next picture.:FLASH PLAYER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITLINTERNET EXPLORER 4.0 OR LATER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITBWINDOWS MEDIA PLAYER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET ITBADOBE ACROBAT READER IS NOT INSTALLED\nPLEASE CLICK HERE TO GET IT
No help keyword specified.&Cannot change the size of a JPEG image
JPEG error #%d
.There is no default printer currently selected/Menu '%s' is already being used by another form
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Invalid clipboard format Clipboard does not support Icons
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
$Unknown picture file extension (.%s)
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
%s %s
%s\%s
2%s %s
\StringFileInfo\xx\InternalName
/T: %d - %d.
Windows XP
Windows 2000
'%s'.
- '%s'.
"%s /?"
"%s".
5.2.3790.0 (srv03_rtm.030324-2048)
choice.exe
5.2.3790.0
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
WScript.CreateObject
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
Usage: CScript scriptname.extension [option...] [arguments...]
//E:engine Use engine for executing script
//H:CScript Changes the default script host to CScript.exe
//H:WScript Changes the default script host to WScript.exe (default)
//Job:xxxx Execute a WSF job
//Nologo Prevent logo display: No banner will be shown at execution time
//X Execute script in debugger
Input ErrormThis Unicode version of CScript will only execute under Windows NT.
<The Windows Script Host settings have been reset to default.
Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled.SAttempt to execute Windows Script Host remotely while remote execution is disabled.
Missing job name.*Unicode is not supported on this platform.
Win32 Error 0x%X
5.8.7600.16385
Windows Script Host
Password that this newly installed service will use
INSTSRV MyService C:\mailsrv\mailsrv.exe -a MYDOMAIN\joebob -p foo
INSTSRV MyService C:\MyDir\DiskService.Exe
[-a <Account Name>] [-p <Account Password>]
INSTSRV <service name> (<exe location> | REMOVE)
The service name cannot be longer than %d characters
- The fully qualified path to the .EXE must be given
- The executable must be on a fixed disk (e.g., not a net drive)
{59a52881-a989-479d-af46-f275c6370663}
msft:rm/event/windows/consumeright
lx-x-x-xx-xxxxxx
{2233362A-798F-4319-BE6A-0425F899BF04}
IsKeyManagementService
Global\552FFA80-3393-423d-8671-7BA046BB5906
OSPPCTransportEndpoint-00001
!"#$%&'()* ,-./01234
14.0.0370.400 (longhorn(wmbla).090811-1833)
14.0.0370.400
conhost.exe_4048:
.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641
cscript.exe_3828:
.text
`.data
.rsrc
@.reloc
KERNEL32.dll
NTDLL.DLL
msvcrt.dll
OLEAUT32.dll
ole32.dll
VERSION.dll
ADVAPI32.dll
USER32.dll
diu2.iu)`iuE$ku^
cscript.exe
kernel32.dll
advapi32.dll
CreateURLMonikerEx
urlmon.dll
@@8X%uIj
%s%s.DLL
wintrust.dll
Invalid parameter passed to C runtime function.
0x%8X
SOFTWARE\Classes\%s\%s
PSShL
GetCPInfo
GetProcessHeap
RegCreateKeyExW
RegCreateKeyExA
RegOpenKeyExW
ReportEventW
RegEnumKeyExA
RegCreateKeyA
RegOpenKeyExA
RegCloseKey
EnumThreadWindows
MsgWaitForMultipleObjects
cscript.pdb
stdole2.tlbWWW
.ObjectWW
KeyW
WindowsFolderWWW4
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Object
5064686<6^6
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
WScript.CreateObject
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
Usage: CScript scriptname.extension [option...] [arguments...]
//E:engine Use engine for executing script
//H:CScript Changes the default script host to CScript.exe
//H:WScript Changes the default script host to WScript.exe (default)
//Job:xxxx Execute a WSF job
//Nologo Prevent logo display: No banner will be shown at execution time
//X Execute script in debugger
Input ErrormThis Unicode version of CScript will only execute under Windows NT.
<The Windows Script Host settings have been reset to default.
Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled.SAttempt to execute Windows Script Host remotely while remote execution is disabled.
Missing job name.*Unicode is not supported on this platform.
Win32 Error 0x%X
5.8.7600.16385
Windows Script Host
chrome.exe_3584:
.text
`.rdata
@.data
.gfids
@.tls
.rsrc
@.reloc
D$,j.Xf
j.Yf;
_tcPVj@
.PjRW
ole32.dll
POWRPROF.dll
address family not supported
broken pipe
function not supported
inappropriate io control operation
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
InitOnceExecuteOnce
operator
operator ""
?#%X.y
%S#[k
?OLEAUT32.dll
user32.dll
c:\b\build\slave\win-pgo\build\src\chrome\app\chrome_exe_main_win.cc
c:\b\build\slave\win-pgo\build\src\chrome\app\main_dll_loader_win.cc
Failed to load Chrome DLL from
ChromeMain
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Could not find exported function
%s: option `%s' is ambiguous (could be `--%s' or `--%s')
%s: invalid option -- `-%c'
%s: argument required for option `
--%s'
0.8.0
%ls (%s) %s
hXXps://crashpad.chromium.org/
hXXps://crashpad.chromium.org/bug/new
Report %ls bugs to
%s home page: <%s>
%ls: %s
(0x%X)
Error (0x%X) while retrieving error. (0x%X)
PlatformFile.UnknownErrors.Windows
c:\b\build\slave\win-pgo\build\src\base\threading\thread_local_win.cc
0123456789
(flags = 0x%x)
Histogram: %s recorded %d samples
.syzygy
.thunks
Windows NT
Histogram.InconsistentCountHigh
Histogram.InconsistentCountLow
c:\b\build\slave\win-pgo\build\src\base\metrics\persistent_memory_allocator.cc
(%d = %3.1f%%)
UMA.CreatePersistentHistogram.Result
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
Line: %i, column: %i, %s
widevinecdmadapter.dll
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_update_settings.cc
Failed to write to application's ClientState key
Removed incremental installer failure key; switching to channel:
Removed multi-install failure key; switching to channel:
CHROME_PROBED_PROGRAM_FILES_PATH
chrome-sxs
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_chrome_distribution.cc
iexplore.exe
googlechrome
googlechromeframe
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\channel_info.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\language_selector.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_commands.cc
Cannot initialize AppCommands from an invalid key.
Skipping over key "
Failed to open key "
Cannot initialize an AppCommand from an invalid key.
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_command.cc
CHROME_MAIN_TICKS
user_experience_metrics.reporting_enabled
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\settings.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\numeric\in_range_cast.h
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\crash_report_database_win.cc
x-x-x-xx-xxxxxx
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\misc\uuid.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io.cc
--annotation=KEY=VALUE set a process annotation in each crash report
--database=PATH store the crash report database at PATH
create a new pipe and send its name via HANDLE
--pipe-name=PIPE communicate with the client over PIPE
--url=URL send crash reports to this Breakpad server URL,
pipe-name
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\handler_main.cc
duplicate key
--annotation requires KEY=VALUE
--handshake-handle and --pipe-name are incompatible
--handshake-handle or --pipe-name is required
SetProcessShutdownParameters
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\crash_report_upload_thread.cc
reserved key
FinishedWritingCrashReport failed
PrepareNewCrashReport failed
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\win\crash_report_exception_handler.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_file_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writer_util.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writable.cc
%s.%s,%s,%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_context_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\process_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\crashpad_info_client_options.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_simple_string_dictionary_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\module_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\exception_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\module_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\system_snapshot_win.cc
%s %d.%d.%d.%s%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_reader_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_string_list_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\capture_memory.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\cpu_context_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_annotations_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_subrange_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_resource_reader.cc
kernel32.dll
c:\b\build\slave\win-pgo\build\src\sandbox\win\src\sandbox_policy_base.cc
NtOpenKey
NtCreateKey
GetCertificateSize
GetCertificate
GetCertificateSizeByHandle
GetCertificateByHandle
SetOPMSigningKeyAndSequenceNumbers
CreateNamedPipeW
NtOpenKeyEx
PruneCrashReportDatabase: Failed to get pending reports
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\prune_crash_reports.cc
PruneCrashReportDatabase: Failed to get completed reports
Database Pruning: Failed to remove report
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\exception_handler_server.cc
::GetNamedPipeClientProcessId
\\.\pipe\crashpad_%d_
ImpersonateNamedPipeClient
ConnectNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_transport_win.cc
WinHttpCrackUrl
WinHttpConnect
WinHttpOpenRequest
WinHttpCloseHandle
Crashpad/0.8.0
WinHttpOpen
WinHttpSetTimeouts
WinHttpReceiveResponse
WinHttpQueryHeaders
HTTP status %d
WinHttpReadData
WinHttpAddRequestHeaders
WinHttpSendRequest
%%x
--%s%sContent-Disposition: form-data; name="%s"
; filename="%s"%s
Content-Type: %s%s
multipart/form-data; boundary=%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_process_suspend.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_seeker.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\process_info.cc
Reading x64 process from x86 process not supported
0x%llx 0x%llx (%s)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\module_version.cc
<failed to retrieve error message (0x%x)>
(0xx)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_local_alloc.cc
SetNamedPipeHandleState
WaitNamedPipe
TransactNamedPipe: expected
TransactNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\registration_protocol_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_body.cc
InvokeMainViaCRT
ExitMainViaCRT
Microsoft.CRTProvider
C:\b\build\slave\win-pgo\build\src\out\Release\initialexe\chrome.exe.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLB
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zETW0
.rdata$zETW1
.rdata$zETW2
.rdata$zETW9
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data
.data$r
.didat$5
.gfids$x
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
chrome.exe
SignalChromeElf
chrome_elf.dll
RegOpenKeyExW
RegEnumKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegCloseKey
ADVAPI32.dll
CreateIoCompletionPort
GetWindowsDirectoryW
GetProcessHandleCount
KERNEL32.dll
ShellExecuteExW
SHELL32.dll
CloseWindowStation
CreateWindowStationW
GetProcessWindowStation
SetProcessWindowStation
USER32.dll
VERSION.dll
WINMM.dll
WTSAPI32.dll
RPCRT4.dll
GetCPInfo
GetProcessHeap
PeekNamedPipe
DisconnectNamedPipe
WaitNamedPipeW
WINHTTP.dll
.?AU_Crt_new_delete@std@@
a.IDATx
%F?????????3
ÿFFFFFFFFFFFFFFF?B%
:1----16
Rhgf^rrrr( ?NOCdhgfrrrr...DlEBScjhg^rr,001k>985Tnhherr-12
:BBBBBBBBBB>>-.jdddcccca
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="54.0.2840.59" version="54.0.2840.59" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
3 3*363@3
6 6%6-646
-0F3K4U4g4m4r4}4
1$3 303{3
081?1_1?3
4!4%4)4{4
9—9d9
; <0<6<;<
<&=.=6=>=~=
? ?$?(?,?
5 5$5(5,5
5 5$5(5,5054585
9,9094989
< <$<(<,<0<4<
4 4<4@4\4`4|4
5 5<5@5\5`5|5
KERNEL32.DLL
mscoree.dll
ext-ms-win-ntuser-windowstation-l1-1-0
portuguese-brazilian
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
nchrome_watcher.dll
PreReadChromeChildInBrowser
${windows}
Ndebug.log
\StringFileInfo\xx\%ls
ntdll.dll
shell32.dll
resources.pak
script.log
chrome
pepflashplayer.dll
Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\Chromium
{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Chrome
chrome_child.dll
chrome.dll
Google Chrome Canary
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}
ChromeCanary
Chrome Canary HTML Document
ChromeSSHTM
{1BEAC3E3-B852-44F4-B468-8906C062422E}
{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}
Google Chrome binaries
hXXps://support.google.com/chrome/contact/chromeuninstall3?hl=$1
Google Chrome
%d.%d.%d
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
ChromeHTML
Chrome HTML Document
{8A69D345-D564-463c-AFF1-A69D9E530F96}
{5C65F4B0-3651-4514-B207-D10CB699B14B}
Google Chrome Frame
Chrome in a Frame.
Google\Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{8BA986DA-5100-405E-AA35-86F34A02ACBF}
WebAccessible
-chromeframe
-chrome
lSOFTWARE\Policies\Google\Chrome
reports
settings.dat
ALPC Port
\Sessions\%d\AppContainerNamedObjects\%ls
sHKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_NLSTEXT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
pipe\
egdi32.dll
tntdll.dll
xntdll.dll
Chrome_MessageWindow
Failed to create directory %ls, last error is %d
Chrome SxS\Application
winhttp.dll
54.0.2840.59
chrome_exe
chrome.exe_3584_rwx_00060000_00001000:
KERNEL32.DLL
chrome.exe_1792:
.text
`.rdata
@.data
.gfids
@.tls
.rsrc
@.reloc
D$,j.Xf
j.Yf;
_tcPVj@
.PjRW
ole32.dll
POWRPROF.dll
address family not supported
broken pipe
function not supported
inappropriate io control operation
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
InitOnceExecuteOnce
operator
operator ""
?#%X.y
%S#[k
?OLEAUT32.dll
user32.dll
c:\b\build\slave\win-pgo\build\src\chrome\app\chrome_exe_main_win.cc
c:\b\build\slave\win-pgo\build\src\chrome\app\main_dll_loader_win.cc
Failed to load Chrome DLL from
ChromeMain
RelaunchChromeBrowserWithNewCommandLineIfNeeded
Could not find exported function
%s: option `%s' is ambiguous (could be `--%s' or `--%s')
%s: invalid option -- `-%c'
%s: argument required for option `
--%s'
0.8.0
%ls (%s) %s
hXXps://crashpad.chromium.org/
hXXps://crashpad.chromium.org/bug/new
Report %ls bugs to
%s home page: <%s>
%ls: %s
(0x%X)
Error (0x%X) while retrieving error. (0x%X)
PlatformFile.UnknownErrors.Windows
c:\b\build\slave\win-pgo\build\src\base\threading\thread_local_win.cc
0123456789
(flags = 0x%x)
Histogram: %s recorded %d samples
.syzygy
.thunks
Windows NT
Histogram.InconsistentCountHigh
Histogram.InconsistentCountLow
c:\b\build\slave\win-pgo\build\src\base\metrics\persistent_memory_allocator.cc
(%d = %3.1f%%)
UMA.CreatePersistentHistogram.Result
Dictionary keys must be quoted.
Unsupported encoding. JSON must be UTF-8.
Line: %i, column: %i, %s
widevinecdmadapter.dll
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_update_settings.cc
Failed to write to application's ClientState key
Removed incremental installer failure key; switching to channel:
Removed multi-install failure key; switching to channel:
CHROME_PROBED_PROGRAM_FILES_PATH
chrome-sxs
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\google_chrome_distribution.cc
iexplore.exe
googlechrome
googlechromeframe
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\channel_info.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\language_selector.cc
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_commands.cc
Cannot initialize AppCommands from an invalid key.
Skipping over key "
Failed to open key "
Cannot initialize an AppCommand from an invalid key.
c:\b\build\slave\win-pgo\build\src\chrome\installer\util\app_command.cc
CHROME_MAIN_TICKS
user_experience_metrics.reporting_enabled
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\settings.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\numeric\in_range_cast.h
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\crash_report_database_win.cc
x-x-x-xx-xxxxxx
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\misc\uuid.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_io.cc
--annotation=KEY=VALUE set a process annotation in each crash report
--database=PATH store the crash report database at PATH
create a new pipe and send its name via HANDLE
--pipe-name=PIPE communicate with the client over PIPE
--url=URL send crash reports to this Breakpad server URL,
pipe-name
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\handler_main.cc
duplicate key
--annotation requires KEY=VALUE
--handshake-handle and --pipe-name are incompatible
--handshake-handle or --pipe-name is required
SetProcessShutdownParameters
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\crash_report_upload_thread.cc
reserved key
FinishedWritingCrashReport failed
PrepareNewCrashReport failed
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\handler\win\crash_report_exception_handler.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_file_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writer_util.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_writable.cc
%s.%s,%s,%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\minidump\minidump_context_writer.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\process_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\crashpad_info_client_options.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_simple_string_dictionary_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\module_snapshot_minidump.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\exception_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\module_snapshot_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\system_snapshot_win.cc
%s %d.%d.%d.%s%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_reader_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\minidump\minidump_string_list_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\capture_memory.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\cpu_context_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_annotations_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\process_subrange_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\snapshot\win\pe_image_resource_reader.cc
kernel32.dll
c:\b\build\slave\win-pgo\build\src\sandbox\win\src\sandbox_policy_base.cc
NtOpenKey
NtCreateKey
GetCertificateSize
GetCertificate
GetCertificateSizeByHandle
GetCertificateByHandle
SetOPMSigningKeyAndSequenceNumbers
CreateNamedPipeW
NtOpenKeyEx
PruneCrashReportDatabase: Failed to get pending reports
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\client\prune_crash_reports.cc
PruneCrashReportDatabase: Failed to get completed reports
Database Pruning: Failed to remove report
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\exception_handler_server.cc
::GetNamedPipeClientProcessId
\\.\pipe\crashpad_%d_
ImpersonateNamedPipeClient
ConnectNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_reader.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_transport_win.cc
WinHttpCrackUrl
WinHttpConnect
WinHttpOpenRequest
WinHttpCloseHandle
Crashpad/0.8.0
WinHttpOpen
WinHttpSetTimeouts
WinHttpReceiveResponse
WinHttpQueryHeaders
HTTP status %d
WinHttpReadData
WinHttpAddRequestHeaders
WinHttpSendRequest
%%x
--%s%sContent-Disposition: form-data; name="%s"
; filename="%s"%s
Content-Type: %s%s
multipart/form-data; boundary=%s
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_process_suspend.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\file\file_seeker.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\process_info.cc
Reading x64 process from x86 process not supported
0x%llx 0x%llx (%s)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\module_version.cc
<failed to retrieve error message (0x%x)>
(0xx)
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\scoped_local_alloc.cc
SetNamedPipeHandleState
WaitNamedPipe
TransactNamedPipe: expected
TransactNamedPipe
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\win\registration_protocol_win.cc
c:\b\build\slave\win-pgo\build\src\third_party\crashpad\crashpad\util\net\http_body.cc
InvokeMainViaCRT
ExitMainViaCRT
Microsoft.CRTProvider
C:\b\build\slave\win-pgo\build\src\out\Release\initialexe\chrome.exe.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLB
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zETW0
.rdata$zETW1
.rdata$zETW2
.rdata$zETW9
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data
.data$r
.didat$5
.gfids$x
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
chrome.exe
SignalChromeElf
chrome_elf.dll
RegOpenKeyExW
RegEnumKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegCloseKey
ADVAPI32.dll
CreateIoCompletionPort
GetWindowsDirectoryW
GetProcessHandleCount
KERNEL32.dll
ShellExecuteExW
SHELL32.dll
CloseWindowStation
CreateWindowStationW
GetProcessWindowStation
SetProcessWindowStation
USER32.dll
VERSION.dll
WINMM.dll
WTSAPI32.dll
RPCRT4.dll
GetCPInfo
GetProcessHeap
PeekNamedPipe
DisconnectNamedPipe
WaitNamedPipeW
WINHTTP.dll
.?AU_Crt_new_delete@std@@
a.IDATx
%F?????????3
ÿFFFFFFFFFFFFFFF?B%
:1----16
Rhgf^rrrr( ?NOCdhgfrrrr...DlEBScjhg^rr,001k>985Tnhherr-12
:BBBBBBBBBB>>-.jdddcccca
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="54.0.2840.59" version="54.0.2840.59" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
3 3*363@3
6 6%6-646
-0F3K4U4g4m4r4}4
1$3 303{3
081?1_1?3
4!4%4)4{4
9—9d9
; <0<6<;<
<&=.=6=>=~=
? ?$?(?,?
5 5$5(5,5
5 5$5(5,5054585
9,9094989
< <$<(<,<0<4<
4 4<4@4\4`4|4
5 5<5@5\5`5|5
KERNEL32.DLL
mscoree.dll
ext-ms-win-ntuser-windowstation-l1-1-0
portuguese-brazilian
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
nchrome_watcher.dll
PreReadChromeChildInBrowser
${windows}
Ndebug.log
\StringFileInfo\xx\%ls
ntdll.dll
shell32.dll
resources.pak
script.log
chrome
pepflashplayer.dll
Browse the web
Software\Microsoft\Windows\CurrentVersion\Uninstall\Chromium
{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Chrome
chrome_child.dll
chrome.dll
Google Chrome Canary
{4ea16ac7-fd5a-47c3-875b-dbf4a2008c20}
ChromeCanary
Chrome Canary HTML Document
ChromeSSHTM
{1BEAC3E3-B852-44F4-B468-8906C062422E}
{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}
Google Chrome binaries
hXXps://support.google.com/chrome/contact/chromeuninstall3?hl=$1
Google Chrome
%d.%d.%d
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
ChromeHTML
Chrome HTML Document
{8A69D345-D564-463c-AFF1-A69D9E530F96}
{5C65F4B0-3651-4514-B207-D10CB699B14B}
Google Chrome Frame
Chrome in a Frame.
Google\Chrome Frame
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame
{8BA986DA-5100-405E-AA35-86F34A02ACBF}
WebAccessible
-chromeframe
-chrome
lSOFTWARE\Policies\Google\Chrome
reports
settings.dat
ALPC Port
\Sessions\%d\AppContainerNamedObjects\%ls
sHKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_TEXT
HKEY_PERFORMANCE_NLSTEXT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
pipe\
egdi32.dll
tntdll.dll
xntdll.dll
Chrome_MessageWindow
Failed to create directory %ls, last error is %d
Chrome SxS\Application
winhttp.dll
%Program Files%\Google\Chrome\Application\chrome.exe
54.0.2840.59
chrome_exe
chrome.exe_3584_rwx_000A0000_00001000:
KERNEL32.DLL
chrome.exe_3584_rwx_00270000_00001000:
KERNEL32.DLL
chrome.exe_3584_rwx_003B0000_00001000:
KERNEL32.DLL
windefender.exe_2476:
.idata
.rdata
P.reloc
P.rsrc
####@####
kernel32.dll
VBoxService.exe
SbieDll.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
76487-644-3177037-23510
76487-337-8429955-22614
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SICE
\\.\NTICE
ShellExecuteA
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
\Internet Explorer\iexplore.exe
PSAPI.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Microsoft\Network\Connections\pbk\rasphone.pbk
rasapi32.dll
rnaph.dll
RAS Passwords |
uURLHistory
Password:
abe2869f-9b47-4cd9-a358-c22904dba7f7
Password
UnitPasswords
advapi32.dll
WindowsLive:name=*
xxxyyyzzz.dat
\Mozilla Firefox\
mozcrt19.dll
sqlite3.dll
nspr4.dll
plc4.dll
plds4.dll
nssutil3.dll
softokn3.dll
nss3.dll
PK11_GetInternalKeySlot
userenv.dll
\Mozilla\Firefox\
profiles.ini
\signons3.txt
\signons2.txt
\signons1.txt
\signons.txt
(unnamed password)
explorer.exe
?456789:;<=
!"#$%&'()* ,-./0123
hu2.iu
user32.dll
GetKeyboardType
RegOpenKeyExA
RegCloseKey
oleaut32.dll
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
SetWindowsHookExA
GetKeyboardState
ole32.dll
pstorec.dll
crypt32.dll
7%8 838\8
2&2.262^2
67
2 2$2(2,2024282
KWindows
KuURLHistory
IEpasswords
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@####
!,.GN
V.dR
<n%dplB-*
.Fdc}
Jb!.Qj
5kE.Sc
#W.Kg
3.ICL'o
.KVXlGQ
.kIgQ
Es%S8
.FN;`q
$(, 048<
G x.uW
msGS
,($ 0000
$%xWy9
.vhtd<?
P.bba
T.%XX
Î>$
ÌCC"Tb@0
chrome.exe_3584_rwx_003F0000_00001000:
KERNEL32.DLL
chrome.exe_3584_rwx_00430000_00001000:
KERNEL32.DLL
chrome.exe_3584_rwx_00460000_00001000:
advapi32.dll
chrome.exe_3584_rwx_00490000_00001000:
RegOpenKeyA
chrome.exe_3584_rwx_004A0000_00001000:
advapi32.dll
chrome.exe_3584_rwx_004D0000_00001000:
AVICAP32.DLL
chrome.exe_3584_rwx_00510000_00001000:
AVICAP32.DLL
chrome.exe_3584_rwx_00740000_00001000:
gdi32.dll
chrome.exe_3584_rwx_00780000_00001000:
gdi32.dll
chrome.exe_3584_rwx_007B0000_00001000:
gdiplus.dll
chrome.exe_3584_rwx_00910000_00001000:
gdiplus.dll
chrome.exe_3584_rwx_00940000_00001000:
mpr.dll
chrome.exe_3584_rwx_01940000_00001000:
mpr.dll
chrome.exe_3584_rwx_01A70000_00001000:
msacm32.dll
chrome.exe_3584_rwx_01AB0000_00001000:
msacm32.dll
chrome.exe_3584_rwx_01BE0000_00001000:
ntdll.dll
chrome.exe_3584_rwx_01C20000_00001000:
ntdll.dll
chrome.exe_3584_rwx_01C50000_00001000:
ole32.dll
chrome.exe_3584_rwx_01C90000_00001000:
ole32.dll
chrome.exe_3584_rwx_01CC0000_00001000:
oleaut32.dll
chrome.exe_3584_rwx_01F00000_00001000:
oleaut32.dll
chrome.exe_3584_rwx_01F30000_00001000:
powrprof.dll
chrome.exe_3584_rwx_02070000_00001000:
powrprof.dll
chrome.exe_3584_rwx_021B0000_00001000:
shell32.dll
chrome.exe_3584_rwx_021E0000_00001000:
ShellExecuteA
chrome.exe_3584_rwx_021F0000_00001000:
shell32.dll
chrome.exe_3584_rwx_02320000_00001000:
user32.dll
chrome.exe_3584_rwx_02360000_00001000:
user32.dll
chrome.exe_3584_rwx_02390000_00001000:
wininet.dll
chrome.exe_3584_rwx_023C0000_00001000:
FtpOpenFileA
chrome.exe_3584_rwx_023D0000_00001000:
wininet.dll
chrome.exe_3584_rwx_02400000_00001000:
winmm.dll
chrome.exe_3584_rwx_02540000_00001000:
winmm.dll
chrome.exe_3584_rwx_02670000_00001000:
wsock32.dll
chrome.exe_3584_rwx_026B0000_00001000:
wsock32.dll
chrome.exe_3584_rwx_10480000_00065000:
`.rsrc
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
shell32.dll
URLDownloadToFileA
urlmon.dll
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
\Internet Explorer\iexplore.exe
####@####
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Turkey
Windows 3.1
Windows 95 (Release 2)
Windows 95
Windows 98 SE
Windows 98
Windows ME
Windows 7
Windows Vista
%s %s
Windows XP Professional x64
Windows XP Home
Windows XP Professional
Windows 2000 Professional
Windows NT %d.%d
Windows 2008
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Unknown Platform ID (%d)
%d.%d
%s (Build: %d
- Service Pack: %s
KERNEL32.DLL
teste.vbs
teste.txt
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
objFile.WriteLine(Info)
objFile.Close
cscript.exe
AVICAP32.dll
tFtpAccess
v1.07.5
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
127.0.0.1
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
GetExtendedTcpTable
GetExtendedUdpTable
Mozilla3_5Password
GetChromePass
StartHttpProxy
1.2.3
keyboardkey
webcaminactive
webcamgetbuffer
webcam
enviarexecnormal
enviarexechidden
openweb
openwebpage
openwebhidden
downexec
sendftp
keylogger
keyloggergetlog
keyloggereraselog
keyloggerativar
keyloggerdesativar
renamekey
windowsfechar
windowsmax
windowsmin
windowsmostrar
windowsocultar
windowsmintodas
windowscaption
listarportas
listarportasdns
finalizarprocessoportas
webcamsettings
chatmsg
getpassword
updateservidorweb
keyloggersearch
urlredirect
urlredirecttrue
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
\config\SteamAppData.vdf
AutoLoginUser
/ClientRegistry.Blob
\ClientRegistry.blob
\steam.dll
%SYS%
ÞSKTOP%
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
FirstExecution
chatmsg|
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
registro|renamekey|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keyloggersearchok|
webcam|webcaminactive|
webcam|webcamactive|
SOFTWARE\Mozilla\Mozilla Firefox
getfirefox
getielogin
getiepass
getieweb
getchrome
getpassword|getpasswordlist|
getpassword|getpassworderror|
duac.bat
%windir%\System32\cmd.exe /k %windir%\System32\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
cmd.exe duac.bat
C:\Windows\System32\drivers\etc\hosts
Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\
Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\
Software\Microsoft\Windows\CurrentVersion\RunServices\
Software\Microsoft\Windows\CurrentVersion\RunOnce\
Software\Microsoft\Windows\CurrentVersion\Run\
temp.vbs
ntdll.dll
log.dat
SQLite3.dll
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
)ju2.iu
KWindows
RegExport
UrlMon
UnitExecutarComandos
uftp
.UnitBytesSize
UnitListarPortasAtivas
UnitWebcam
UnitKeylogger
WinExec
SetNamedPipeHandleState
GetProcessHeap
CreatePipe
RegQueryInfoKeyA
RegOpenKeyExA
RegOpenKeyA
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
RegCloseKey
GdiplusShutdown
keybd_event
MsgWaitForMultipleObjects
MapVirtualKeyA
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyState
GetAsyncKeyState
ExitWindowsEx
EnumWindows
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpOpenFileA
%( % & % % % ]
.idata
.reloc
P.rsrc
hbS%S
advapi32.dll
AVICAP32.DLL
gdi32.dll
gdiplus.dll
mpr.dll
msacm32.dll
ole32.dll
oleaut32.dll
powrprof.dll
user32.dll
wininet.dll
winmm.dll
wsock32.dll
windefender.exe_2476_rwx_00400000_0004F000:
.idata
.rdata
P.reloc
P.rsrc
####@####
kernel32.dll
VBoxService.exe
SbieDll.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
76487-644-3177037-23510
76487-337-8429955-22614
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SICE
\\.\NTICE
ShellExecuteA
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
\Internet Explorer\iexplore.exe
PSAPI.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Microsoft\Network\Connections\pbk\rasphone.pbk
rasapi32.dll
rnaph.dll
RAS Passwords |
uURLHistory
Password:
abe2869f-9b47-4cd9-a358-c22904dba7f7
Password
UnitPasswords
advapi32.dll
WindowsLive:name=*
xxxyyyzzz.dat
\Mozilla Firefox\
mozcrt19.dll
sqlite3.dll
nspr4.dll
plc4.dll
plds4.dll
nssutil3.dll
softokn3.dll
nss3.dll
PK11_GetInternalKeySlot
userenv.dll
\Mozilla\Firefox\
profiles.ini
\signons3.txt
\signons2.txt
\signons1.txt
\signons.txt
(unnamed password)
explorer.exe
?456789:;<=
!"#$%&'()* ,-./0123
hu2.iu
user32.dll
GetKeyboardType
RegOpenKeyExA
RegCloseKey
oleaut32.dll
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
SetWindowsHookExA
GetKeyboardState
ole32.dll
pstorec.dll
crypt32.dll
7%8 838\8
2&2.262^2
67
2 2$2(2,2024282
KWindows
KuURLHistory
IEpasswords
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@####
!,.GN
V.dR
<n%dplB-*
.Fdc}
Jb!.Qj
5kE.Sc
#W.Kg
3.ICL'o
.KVXlGQ
.kIgQ
Es%S8
.FN;`q
$(, 048<
G x.uW
msGS
,($ 0000
$%xWy9
.vhtd<?
P.bba
T.%XX
Î>$
ÌCC"Tb@0
Explorer.EXE_1440_rwx_01C20000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_03AA0000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_03C80000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_03D70000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_03F20000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_04060000_00001000:
KERNEL32.DLL
Explorer.EXE_1440_rwx_04090000_00001000:
advapi32.dll
Explorer.EXE_1440_rwx_04110000_00001000:
RegOpenKeyA
Explorer.EXE_1440_rwx_04160000_00001000:
advapi32.dll
Explorer.EXE_1440_rwx_04190000_00001000:
AVICAP32.DLL
Explorer.EXE_1440_rwx_04210000_00001000:
AVICAP32.DLL
Explorer.EXE_1440_rwx_04660000_00001000:
gdi32.dll
Explorer.EXE_1440_rwx_046E0000_00001000:
gdi32.dll
Explorer.EXE_1440_rwx_04710000_00001000:
gdiplus.dll
Explorer.EXE_1440_rwx_047A0000_00001000:
gdiplus.dll
Explorer.EXE_1440_rwx_048A0000_00001000:
mpr.dll
Explorer.EXE_1440_rwx_04920000_00001000:
mpr.dll
Explorer.EXE_1440_rwx_04990000_00001000:
msacm32.dll
Explorer.EXE_1440_rwx_049D0000_00001000:
msacm32.dll
Explorer.EXE_1440_rwx_04A00000_00001000:
ntdll.dll
Explorer.EXE_1440_rwx_04AC0000_00001000:
ntdll.dll
Explorer.EXE_1440_rwx_04C30000_00001000:
ole32.dll
Explorer.EXE_1440_rwx_04C70000_00001000:
ole32.dll
Explorer.EXE_1440_rwx_04D70000_00001000:
oleaut32.dll
Explorer.EXE_1440_rwx_04DF0000_00001000:
oleaut32.dll
Explorer.EXE_1440_rwx_04E20000_00001000:
powrprof.dll
Explorer.EXE_1440_rwx_04FE0000_00001000:
powrprof.dll
Explorer.EXE_1440_rwx_05050000_00001000:
shell32.dll
Explorer.EXE_1440_rwx_05080000_00001000:
ShellExecuteA
Explorer.EXE_1440_rwx_050D0000_00001000:
shell32.dll
Explorer.EXE_1440_rwx_05100000_00001000:
user32.dll
Explorer.EXE_1440_rwx_05180000_00001000:
user32.dll
Explorer.EXE_1440_rwx_051B0000_00001000:
wininet.dll
Explorer.EXE_1440_rwx_05220000_00001000:
FtpOpenFileA
Explorer.EXE_1440_rwx_05230000_00001000:
wininet.dll
Explorer.EXE_1440_rwx_05260000_00001000:
winmm.dll
Explorer.EXE_1440_rwx_06640000_00001000:
winmm.dll
Explorer.EXE_1440_rwx_06670000_00001000:
wsock32.dll
Explorer.EXE_1440_rwx_066B0000_00001000:
wsock32.dll
Explorer.EXE_1440_rwx_10410000_00065000:
`.rsrc
kernel32.dll
Portions Copyright (c) 1999,2003 Avenger by NhT
SHFileOperationA
shell32.dll
URLDownloadToFileA
urlmon.dll
ShellExecuteA
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
http\shell\open\command
\Internet Explorer\iexplore.exe
####@####
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Portugal
Turkey
Windows 3.1
Windows 95 (Release 2)
Windows 95
Windows 98 SE
Windows 98
Windows ME
Windows 7
Windows Vista
%s %s
Windows XP Professional x64
Windows XP Home
Windows XP Professional
Windows 2000 Professional
Windows NT %d.%d
Windows 2008
%s %s Server
Windows 2003 Server Datacenter
Windows 2003 Server Enterprise
Windows 2003 Server Web Edition
Windows 2003 Server
Windows Home Server
Windows 2003 Server (Release 2)
Windows 2000 Server Datacenter
Windows 2000 Server Enterprise
Windows 2000 Server Web Edition
Windows 2000 Server
Windows NT 4.0 Server Datacenter
Windows NT 4.0 Server Enterprise
Windows NT 4.0 Server Web Edition
Windows NT 4.0 Server
Unknown Platform ID (%d)
%d.%d
%s (Build: %d
- Service Pack: %s
KERNEL32.DLL
teste.vbs
teste.txt
Set objSecurityCenter = GetObject("winmgmts:\\.\root\SecurityCenter")
Set colFirewall = objSecurityCenter.ExecQuery("Select * From FirewallProduct",,48)
Set colAntiVirus = objSecurityCenter.ExecQuery("Select * From AntiVirusProduct",,48)
Set objFileSystem = CreateObject("Scripting.fileSystemObject")
Set objFile = objFileSystem.CreateTextFile("
Info = Info & "F" & CountFw & ") " & objFirewall.displayName & " v" & objFirewall.versionNumber & Enter
Info = Info & "A" & CountAV & ") " & objAntiVirus.displayName & " v" & objAntiVirus.versionNumber & Enter
objFile.WriteLine(Info)
objFile.Close
cscript.exe
AVICAP32.dll
tFtpAccess
v1.07.5
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
SetupApi.dll
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
PDCAP_D0_SUPPORTED
PDCAP_D1_SUPPORTED
PDCAP_D2_SUPPORTED
PDCAP_D3_SUPPORTED
PDCAP_WAKE_FROM_D0_SUPPORTED
PDCAP_WAKE_FROM_D1_SUPPORTED
PDCAP_WAKE_FROM_D2_SUPPORTED
PDCAP_WAKE_FROM_D3_SUPPORTED
PDCAP_WARM_EJECT_SUPPORTED
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
127.0.0.1
iphlpapi.dll
AllocateAndGetTcpExTableFromStack
AllocateAndGetUdpExTableFromStack
SetTcpEntry
GetExtendedTcpTable
GetExtendedUdpTable
Mozilla3_5Password
GetChromePass
StartHttpProxy
1.2.3
keyboardkey
webcaminactive
webcamgetbuffer
webcam
enviarexecnormal
enviarexechidden
openweb
openwebpage
openwebhidden
downexec
sendftp
keylogger
keyloggergetlog
keyloggereraselog
keyloggerativar
keyloggerdesativar
renamekey
windowsfechar
windowsmax
windowsmin
windowsmostrar
windowsocultar
windowsmintodas
windowscaption
listarportas
listarportasdns
finalizarprocessoportas
webcamsettings
chatmsg
getpassword
updateservidorweb
keyloggersearch
urlredirect
urlredirecttrue
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
PSAPI.dll
\config\SteamAppData.vdf
AutoLoginUser
/ClientRegistry.Blob
\ClientRegistry.blob
\steam.dll
%SYS%
ÞSKTOP%
Uhm%D
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
FirstExecution
chatmsg|
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
listarjanelas|windowsfechar|
listarjanelas|windowsmax|
listarjanelas|windowsmin|
listarjanelas|windowsmostrar|
listarjanelas|windowsocultar|
listarjanelas|windowsmintodas|
listarjanelas|windowscaption|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
listarportas|listadeportaspronta|
listarportas|finalizarconexao|
listarportas|finalizarprocessoportas|Y|
listarportas|finalizarprocessoportas|N|
registro|renamekey|
keylogger|keylogger|keyloggerativar|
keylogger|keylogger|keyloggerdesativar|
keylogger|keyloggergetlog|
keylogger|keylogger|keyloggervazio|
keyloggersearchok|
webcam|webcaminactive|
webcam|webcamactive|
SOFTWARE\Mozilla\Mozilla Firefox
getfirefox
getielogin
getiepass
getieweb
getchrome
getpassword|getpasswordlist|
getpassword|getpassworderror|
duac.bat
%windir%\System32\cmd.exe /k %windir%\System32\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
cmd.exe duac.bat
C:\Windows\System32\drivers\etc\hosts
Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\
Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\
Software\Microsoft\Windows\CurrentVersion\RunServices\
Software\Microsoft\Windows\CurrentVersion\RunOnce\
Software\Microsoft\Windows\CurrentVersion\Run\
temp.vbs
ntdll.dll
log.dat
SQLite3.dll
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
)ju2.iu
KWindows
RegExport
UrlMon
UnitExecutarComandos
uftp
.UnitBytesSize
UnitListarPortasAtivas
UnitWebcam
UnitKeylogger
WinExec
SetNamedPipeHandleState
GetProcessHeap
CreatePipe
RegQueryInfoKeyA
RegOpenKeyExA
RegOpenKeyA
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
RegCloseKey
GdiplusShutdown
keybd_event
MsgWaitForMultipleObjects
MapVirtualKeyA
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyState
GetAsyncKeyState
ExitWindowsEx
EnumWindows
FtpGetFileSize
FtpSetCurrentDirectoryA
FtpOpenFileA
%( % & % % % ]
.idata
.reloc
P.rsrc
hbS%S
advapi32.dll
AVICAP32.DLL
gdi32.dll
gdiplus.dll
mpr.dll
msacm32.dll
ole32.dll
oleaut32.dll
powrprof.dll
user32.dll
wininet.dll
winmm.dll
wsock32.dll
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
chrome.exe:1792
torrent.exe:4000
torrent.exe:2988
%original file name%.exe:2452
windefender.exe:3092 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Roaming\admlog.dat (15 bytes)
C:\Windows\System32\windefender\windefender.exe (573 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm7 (12568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm8 (80 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe (3361 bytes)
C:\Windows\System32\drivers\etc\hosts (155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\adm2.txt (230 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\mini-KMS_Activator_v1.053.exe (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Templates\torrent.exe (1146 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\instsrv.exe (288 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ChkOf.cmd (590 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KeyMngOf.cmd (173 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KeyMngW.cmd (267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\cscript.exe (241 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\hidcon.exe (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\RearmOf.cmd (958 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KMService.exe (703 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\RearmW.cmd (770 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\PortQry.exe (503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\hs_message.vbs (796 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ospp.vbs (426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\srvany.exe (200 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ChkWin.cmd (764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\choice.exe (900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\autorun.exe (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ActOf.cmd (108 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\autorun.apm (674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\slerror.xml (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ospprearm.exe (190 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\VL.vbs (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Help.txt (341 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Start.cmd (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\Rest.cmd (290 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\KMSIns.cmd (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\service.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\ActWin.cmd (302 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\6B60.tmp\osppc.dll (359 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"csrss.exe" = "C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\System\Services\csrss.exe" - Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
127.0.0.1 localhost - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.