Gen.Variant.MSILKrypt.11_615d5697ae

by malwarelabrobot on November 2nd, 2016 in Malware Descriptions.

Trojan.Win32.Inject.enip (Kaspersky), Gen:Variant.MSILKrypt.11 (B) (Emsisoft), Gen:Variant.MSILKrypt.11 (AdAware), Trojan.Win32.Bumat.FD, GenericAutorunWorm.YR, BankerGeneric.YR (Lavasoft MAS)
Behaviour: Banker, Trojan, Worm, WormAutorun


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 615d5697aec32f9ce6fde23e2cb9b5fb
SHA1: 9113766e0c40a2d63b08d4932c1e88e2b79f8047
SHA256: 5af717703f6f9425006e7e4ced094540b96336c79e5e22630bfaec4377e484ef
SSDeep: 98304:FClMK/okgKLKH3T5BS7VFTGQOg4mc7uX1eT6 7EYOG7MYk:UlM/vNXTXSn4fmcyXTZak
Size: 5722112 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2016-10-15 16:18:12
Analyzed on: Windows7 SP1 32-bit


Summary:

Banker. Steals data relating to online banking systems, e-payment systems and credit card systems.

Payload

Behaviour Description
WormAutorun A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.


Process activity

The Trojan creates the following process(es):

%original file name%.exe:1968
2.exe:3504

The Trojan injects its code into the following process(es):

1.exe:2224
2.exe:1300

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:1968 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe (732 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2.exe (129 bytes)

The process 1.exe:2224 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mm_9742.tmp\log.txt (315 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab96C3.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D (325 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\828298824EA5549947C17DDABF6871F5_6B5C8B321CA02275A82E95FA81D6DE62 (1068 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8A574ED5927B3CEC9626151D220C7448 (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\828298824EA5549947C17DDABF6871F5_6B5C8B321CA02275A82E95FA81D6DE62 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D (876 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_6D5D2989278EB7E813FFA194F5CA6156 (660 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar96C4.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_6D5D2989278EB7E813FFA194F5CA6156 (463 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8A574ED5927B3CEC9626151D220C7448 (248 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar96C4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab96C3.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mm_9742.tmp (0 bytes)

The process 2.exe:1300 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\stcheck.txt (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\icheck.txt (3 bytes)
C:\Windows\System32\drivers\etc\hosts (120 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\OF9L3DR3.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\HGQPYGV7.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\983WD333.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\F15L1QF6.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\P2Z07O4S.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\UNO1WWMQ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\GF0JZXVN.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\00CZ9B9Z.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\59FYE1S2.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\4CWVLDFS.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\QVWF9XLH.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\SHMEGTHE.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\379IMDJA.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\KJGZP41Y.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9UFT3VMU.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\A5VV6NGJ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\O761920L.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\SK6RC4AQ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7ZFPBM01.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PMGXNABP.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\AJQLWW1A.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\K4EMAOY7.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CZKDRHGB.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\5a2ce8gs.default\cookies.sqlite (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FBUBDDF0.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8WNTYFZE.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\O7L86NTO.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\FDGZES7U.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\SN1VAMHK.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NNXQMEB1.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ETGRPT21.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\VPSNR0J4.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\8Q2KNK5G.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\YJCP8HIK.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\1I56O6EZ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\PFR2GFQJ.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\GB74HSLE.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\KUZ61ORW.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\Z40SB5AS.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LXL295FY.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\XJJJSX58.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\KCULDY7L.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\03Z3OHNC.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\AW5IGQT7.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\KK0IK9EV.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\0VR58838.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\IAU75TW2.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\OLCWAOT0.txt (0 bytes)

Registry activity

The process %original file name%.exe:1968 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process 1.exe:2224 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASMANCS]
"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASMANCS]
"FileTracingMask" = "4294901760"
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASMANCS]
"EnableFileTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad]
"WpadLastNetwork" = "{24C5EDBC-2851-452A-B521-5DA992F6C1B5}"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASMANCS]
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASAPI32]
"EnableFileTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecision" = "3"
"WpadDecisionTime" = "20 8F 0E ED 2E 34 D2 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"DefaultConnectionSettings" = "46 00 00 00 09 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecision" = "3"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASAPI32]
"MaxFileSize" = "1048576"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecisionReason" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASAPI32]
"EnableConsoleTracing" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 36 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadNetworkName" = "Network 2"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASMANCS]
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASAPI32]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{24C5EDBC-2851-452A-B521-5DA992F6C1B5}]
"WpadDecisionReason" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\1_RASAPI32]
"FileTracingMask" = "4294901760"

"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-e1-da-d8]
"WpadDecisionTime" = "20 8F 0E ED 2E 34 D2 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process 2.exe:1300 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden" = "0"

[HKCU\Software\Classes\Local Settings\MuiCache\2F\52C64B7E]
"LanguageList" = "en-US, en"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSASCui.exe"

Dropped PE files

MD5 File path
eb6a3740315ac6b4f2accc74921902a5 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe
8a554becca51457c68c5efcfd2cba410 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmpG263.tmp

HOSTS file anomalies

The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 120 bytes in size. The following strings are added to the hosts file listed below:

127.0.0.1 74.53.201.162
127.0.0.1 66.66.132.220.30
127.0.0.1 66.35.241.92
127.0.0.1 94.23.199.60


Rootkit activity

No anomalies have been detected.

Propagation

A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.

VersionInfo

Company Name:
Product Name:
Product Version: 0.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename: Beautiful Sun Mod ENB Samp 4.0.exe
Internal Name: Beautiful Sun Mod ENB Samp 4.0.exe
File Version: 0.0.0.0
File Description:
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 8192 5708420 5709824 5.12154 8ee80fc7c533d1feeb05f55d45409648
.rsrc 5718016 1672 4096 1.30277 0298314fcfd2913db2ccd3698c25dc98
.reloc 5726208 12 4096 0.011373 cb1540f6e173713df9a21d5188472695

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://e6845.dscb1.akamaiedge.net/crls/secureca.crl
hxxp://e8218.dscb1.akamaiedge.net/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6kg==
hxxp://clients.l.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGnnWmtKeBq7
hxxp://www3.l.google.com/GIAG2.crl
hxxp://crl.geotrust.com/crls/secureca.crl 23.43.133.163
hxxp://g.symcd.com/MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6kg== 23.55.155.27
hxxp://pki.google.com/GIAG2.crl 74.125.232.224
hxxp://clients1.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGnnWmtKeBq7 216.58.214.238
ssl.google-analytics.com 74.125.232.254
smtp.gmail.com 173.194.220.108


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGnnWmtKeBq7 HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: clients1.google.com


HTTP/1.1 200 OK
Content-Type: application/ocsp-response
Date: Mon, 31 Oct 2016 23:04:14 GMT
Expires: Fri, 04 Nov 2016 23:04:14 GMT
Server: ocsp_responder
Content-Length: 463
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Cache-Control: public, max-age=345600
Age: 42893
0..........0..... .....0......0...0......J......h.v....b..Z./..2016103
1130257Z0k0i0A0... ..........j.....p.I.#z...(~d..J......h.v....b..Z./.
.i.ZkJx......20161031130257Z....20161107130257Z0...*.H................
...!6.jB...m.X.Y/..Cd..d...D@.......!..........A....h/RIj..c.....Kv.L.
D...j;...7)?........9..............K.......t....X..%...m..;3.j..A.-.V{
3Pc.STg...J..%...v.L.~>..n..tD...............v........Uk$u.k....E..
W..u.,.z..e..Ag..R.....V7.?.;....<.!.x@l..~sg<HTTP/1.1 200 OK..C
ontent-Type: application/ocsp-response..Date: Mon, 31 Oct 2016 23:04:1
4 GMT..Expires: Fri, 04 Nov 2016 23:04:14 GMT..Server: ocsp_responder.
.Content-Length: 463..X-XSS-Protection: 1; mode=block..X-Frame-Options
: SAMEORIGIN..Cache-Control: public, max-age=345600..Age: 42893..0....
......0..... .....0......0...0......J......h.v....b..Z./..201610311302
57Z0k0i0A0... ..........j.....p.I.#z...(~d..J......h.v....b..Z./..i.Zk
Jx......20161031130257Z....20161107130257Z0...*.H...................!6
.jB...m.X.Y/..Cd..d...D@.......!..........A....h/RIj..c.....Kv.L.D...j
;...7)?........9..............K.......t....X..%...m..;3.j..A.-.V{3Pc.S
Tg...J..%...v.L.~>..n..tD...............v........Uk$u.k....E..W..u.
,.z..e..Ag..R.....V7.?.;....<.!.x@l..~sg<..


GET /GIAG2.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: pki.google.com


HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Type: application/pkix-crl
Date: Tue, 01 Nov 2016 10:16:39 GMT
Expires: Tue, 01 Nov 2016 11:16:39 GMT
Last-Modified: Tue, 01 Nov 2016 02:15:00 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Age: 2550
Cache-Control: public, max-age=3600
Accept-Ranges: none
Transfer-Encoding: chunked
339c..0.3.0.2....0...*.H........0I1.0...U....US1.0...U....Google Inc1%
0#..U....Google Internet Authority G2..161101010003Z..161111010003Z0.1
.0'..u.e.kl....160915211903Z0.0...U.......0'....._|.....160915211951Z0
.0...U.......0'../....=.:..160915211941Z0.0...U.......0'..NH...M....16
0915211829Z0.0...U.......0'..;Jy..)l...160915211944Z0.0...U.......0'..
...Y[.I...160915211321Z0.0...U.......0'..]tR..k.6..160915211814Z0.0...
U.......0'...G.. G....160915212012Z0.0...U.......0'..@~}m:.....1609152
11902Z0.0...U.......0'..i..Hj#....160915211900Z0.0...U.......0'..1_..?
.M...160915211841Z0.0...U.......0'...I..5.....160915212030Z0.0...U....
...0'.......8.-..160915211750Z0.0...U.......0'..tR."g.....160915211936
Z0.0...U.......0'.....x......160915211950Z0.0...U.......0'..[......U..
160915211655Z0.0...U.......0'....Y.sO.#..160915211505Z0.0...U.......0'
..i.?.D3.S..160915211611Z0.0...U.......0'..n..N......160915212018Z0.0.
..U.......0'..M,...w....160915211533Z0.0...U.......0'........h...16091
5211358Z0.0...U.......0'........{...160915211518Z0.0...U.......0'...q.
...}...160915211439Z0.0...U.......0'..@:...L....160120100747Z0.0...U..
.....0'....|.......160915211959Z0.0...U.......0'.......(.t..1609152114
04Z0.0...U.......0'..!C........160915211535Z0.0...U.......0'..@..:.G.G
..160915211352Z0.0...U.......0'..X...6.E...160915211953Z0.0...U.......
0'..Es}.Vr....160915211801Z0.0...U.......0'......k..y..160915211632Z0.
0...U.......0'..}2."...J..160915211541Z0.0...U.......0'...C4...<...
160915211738Z0.0...U.......0'....;.<J....160915211606Z0.0...U..

<<< skipped >>>

GET /MEQwQjBAMD4wPDAJBgUrDgMCGgUABBSxtDkXkBa3l3lQEfFgudSiPNvt7gQUAPkqw0GRtsnCuD5V8sCXEROgByACAwI6kg== HTTP/1.1
Cache-Control: max-age = 564348
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Wed, 12 Oct 2016 22:33:53 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: g.symcd.com


HTTP/1.1 200 OK
Server: nginx/1.4.7
Content-Type: application/ocsp-response
Content-Length: 1362
content-transfer-encoding: binary
Cache-Control: max-age=534127, public, no-transform, must-revalidate
Last-Modified: Mon, 31 Oct 2016 15:20:44 GMT
Expires: Mon, 7 Nov 2016 15:20:44 GMT
Date: Tue, 01 Nov 2016 10:59:02 GMT
Connection: keep-alive
0..N......G0..C.. .....0.....40..00.......j.#.p.e$.\ps.*.. .j..2016103
1152044Z0f0d0<0... ..........9.....yP..`...<.......*.A.....>U
....... ...:.....20161031152044Z....20161107152044Z0...*.H............
.Sh....x"..(.....t..Znk.Z..N...&.k.a...K..k...IP........8....A....xh..
...G.5UIh........ ..O P$.U.dn..<F.....\.D_z.:........[.....~.s.N'..
.J...3x...>....B.8[L.....k`%oG.c.[P..=<.8<[email protected].?..=f/..Lj
..G...`%|H.A~...R08YW.)....7\-......7m}[email protected]..[....?#..I....0...0..
|0..d........:.0...*.H........0B1.0...U....US1.0...U....GeoTrust Inc.1
.0...U....GeoTrust Global CA0...151203170230Z..161214170230Z02100...U.
..'GeoTrust Global CA TGV OCSP Responder 40.."0...*.H.............0...
......[.c.#zj......RME.....,......(..U......!-.l..R..E.~..%."./8mv..D.
..*...Rx........mw.~2..Q5T\.H...Wk*..a.z.$._..T......;T.S.r(._*.G....^
.P.!.3..t.......s......P....C._.g.b.oK...EV..>...>.|.o.~quo.....
........v4..Tt....Q.]A.Y......... w.E..=.%.n7.......{" *C........0..0.
..U.#..0....z.h.....d..}.}e...N0... .....0......0...U.%..0... .......0
...U...........0...U.......0.0 ..U....0...0.1.0...U....TGV-C-670...*.H
...............aEc<..'R......]C.ri.Zm.....|..B.$..76..h....l...Xbxu
a...C.X.S....~K..A..._.T@$.....9(.... ......\.*.....5.b.x...[QM.._9P.=
..l...gf..L.?..3 ......Z....._...20R;...x.......C..0....l.G.A..5TS>
d.U......w.(\....v..9.z7.....J..;..'[email protected]....

<<< skipped >>>

GET /crls/secureca.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 09:30:22 GMT
If-None-Match: "b6a46da3cf1aa70c10b101b12c9733f4:1476351022"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.geotrust.com


HTTP/1.1 200 OK
Server: Apache
ETag: "74bba333eda428b937af47928766d9f5:1477996245"
Last-Modified: Tue, 01 Nov 2016 10:30:45 GMT
Date: Tue, 01 Nov 2016 10:58:56 GMT
Content-Length: 325
Connection: keep-alive
Content-Type: application/pkix-crl
0..A0..0...*.H........0N1.0...U....US1.0...U....Equifax1-0 ..U...$Equi
fax Secure Certificate Authority..161101102300Z..161111102300Z0,0....%
...020514181157Z0.....3..020515130611Z0...*.H.............(..?...B....
....o..D.....w.,.......(:.....-.8.H2.w......7!.Q.......W9....gc9.....{
.....k.....>[../...*~....X*N..p....F...Cr...`HTTP/1.1 200 OK..Serve
r: Apache..ETag: "74bba333eda428b937af47928766d9f5:1477996245"..Last-M
odified: Tue, 01 Nov 2016 10:30:45 GMT..Date: Tue, 01 Nov 2016 10:58:5
6 GMT..Content-Length: 325..Connection: keep-alive..Content-Type: appl
ication/pkix-crl..0..A0..0...*.H........0N1.0...U....US1.0...U....Equi
fax1-0 ..U...$Equifax Secure Certificate Authority..161101102300Z..161
111102300Z0,0....%...020514181157Z0.....3..020515130611Z0...*.H.......
......(..?...B........o..D.....w.,.......(:.....-.8.H2.w......7!.Q....
...W9....gc9.....{.....k.....>[../...*~....X*N..p....F...Cr...`..


The Trojan connects to the servers at the folowing location(s):

1.exe_2224:

`.rsrc
I.sign(H
TArray<System.Byte>
TArray<System.Char>
Generics.Collections
doOwnsKeys
crTextColor
TWMKey
KeyData
grfLocksSupported
ISupportErrorInfo
HelpKeyword
UnderstandsKeyword
ssShift
htKeyword
EInvalidOperation
TList.TDirection
AOperator
TThread.TSynchronizeRecord
TOperation
Operation
TComponent$%C
FOnExecute
OnExecute
TArray<System.string>
TArray<System.TObject>
TList.Sort$594$0$Intf
TList.Sort$594$ActRec
$TComponent.FindComponent$1217$0$Intf
$TComponent.FindComponent$1217$ActRec
TRegKeyInfo
NumSubKeys
MaxSubKeyLen
FCurrentKey
FRootKey
FCloseRootKey
CloseKey
CreateKey
DeleteKey
GetKeyInfo
GetKeyNames
HasSubKeys
KeyExists
LoadKey
MoveKey
OpenKey
OpenKeyReadOnly
ReplaceKey
RestoreKey
SaveKey
UnLoadKey
CurrentKey
LastErrorMsg
RootKey
RootKeyName8
TLocalTimeZone.TYearlyChanges
TLocalTimeZone.TYearlyChanges0
:TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
LTArray<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
QTEnumerator<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>(
QTEnumerator<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
QTEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>-
QTEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>D
FTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TItem
KTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TItemArray
IEqualityComparer<System.Word>
Generics.Defaults
#TCollectionNotifyEvent<System.Word>
?TCollectionNotifyEvent<DateUtils.TLocalTimeZone.TYearlyChanges>
TArray<System.Word>
TEnumerator<System.Word>(
TEnumerator<System.Word>
TEnumerable<System.Word>-
TEnumerable<System.Word>$
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyEnumerator;
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyEnumeratorT
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyCollection;
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyCollectionP
/TArray<DateUtils.TLocalTimeZone.TYearlyChanges>
4TEnumerator<DateUtils.TLocalTimeZone.TYearlyChanges>(
4TEnumerator<DateUtils.TLocalTimeZone.TYearlyChanges>
4TEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>-
4TEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>$
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueEnumerator;
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueEnumerator
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueCollection;
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueCollection
PTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TPairEnumerator;
PTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TPairEnumerator
FOnKeyNotify
FKeyCollection
@TDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>9
ContainsKey
@TDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
Keys
OnKeyNotify
FTObjectDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>M
FTObjectDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
e:{Generics.Collections}TList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.:1
OIComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
\TCollectionNotifyEvent<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
Item:TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
QIEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
WTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.TEnumerator5
WTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.TEnumerator
KTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>&
KTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
,:{Generics.Collections}TList<System.Word>.:1
IComparer<System.Word>
IEnumerable<System.Word>
TList<System.Word>.TEnumerator5
TList<System.Word>.TEnumeratorP^E
TList<System.Word>&
TList<System.Word>
H:{Generics.Collections}TList<DateUtils.TLocalTimeZone.TYearlyChanges>.:1
2IComparer<DateUtils.TLocalTimeZone.TYearlyChanges>
4IEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>
:TList<DateUtils.TLocalTimeZone.TYearlyChanges>.TEnumerator5
:TList<DateUtils.TLocalTimeZone.TYearlyChanges>.TEnumeratordjE
.TList<DateUtils.TLocalTimeZone.TYearlyChanges>&
.TList<DateUtils.TLocalTimeZone.TYearlyChanges>,lE
QTComparison<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
OTComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>2
OTComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
e:{Generics.Collections}TList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.:3
TComparison<System.Word>
TComparer<System.Word>2
TComparer<System.Word>
,:{Generics.Collections}TList<System.Word>.:3
4TComparison<DateUtils.TLocalTimeZone.TYearlyChanges>
2TComparer<DateUtils.TLocalTimeZone.TYearlyChanges>2
2TComparer<DateUtils.TLocalTimeZone.TYearlyChanges>
H:{Generics.Collections}TList<DateUtils.TLocalTimeZone.TYearlyChanges>.:3
XTDelegatedComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>8
XTDelegatedComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
TDelegatedComparer<System.Word>8
TDelegatedComparer<System.Word>
;TDelegatedComparer<DateUtils.TLocalTimeZone.TYearlyChanges>8
;TDelegatedComparer<DateUtils.TLocalTimeZone.TYearlyChanges>D
ServerKey
FSupportsLicensing
SupportsLicensing
Operator
EVariantBadIndexError
ENotSupportedException
ENotSupportedExceptionL
ENoMonitorSupportException
ENoMonitorSupportExceptionh
TArray<SysUtils.TLangRec>
csshiftjis
windows-936
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
windows-874
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
TArray<SysUtils.TUnitHashEntry>
etNoMonitorSupportException
biClrImportant
tagMSG
Windows
HKEY
thHeaderItemLeftPressed
tsArrowBtnLeftPressed
ttbThumbLeftPressed
lrMonoChrome
IsShortCut
FHelpKeyword
HelpKeywordd
FPasswordChar
PasswordChar
OnKeyDown
OnKeyPress
OnKeyUpd{N
ssHorizontal
TCustomButton.TButtonStyle
poPortrait
APort
Port
FAutoHotkeys
RethinkHotkeys
AutoHotkeysx
AutoHotkeys
EInvalidGraphicOperation
EInvalidGraphicOperation,AK
SupportsPartialTransparency
SupportsClipboardFormat
Monochrome
ssHotTrack
TWindowState
poProportional
fsShowing
FWindowState
FKeyPreview
WantChildKey
KeyPreview
WindowState
KeyPreview8dN
WindowState0
FBiDiKeyboard
FNonBiDiKeyboard
FEnumAllWindowsOnActivateHint
FOnActionExecute
Keyword
EnumAllWindowsOnActivateHint
BiDiKeyboard
NonBiDiKeyboard@
OnActionExecute
FProportional
Proportional@
sltURL
TCustomLinkLabel.TLinkAlignment
FURL
igoParentPassthrough
FAlwaysShowDragImages
AlwaysShowDragImages@
toFlickFallbackKeys
'TCustomGestureEngine.TGestureEngineFlag
(TCustomGestureEngine.TGestureEngineFlags
Supported
TKeyEvent
TKeyPressEvent
HelpKeywordD
FOnKeyDown
FOnKeyPress
FOnKeyUp
IsHintMsg
FNativeWheelSupport
FWheelSupportMessage
fKeyword
ImportPalette
ImportColorTable
ImportDIBColors
ImportColorMap
ExportPalette
rmWindows20
rmWindows256
rmWindowsGray
rmMonochrome
rmQuantizeWindows
TMonochromeLookup7
TMonochromeLookup
WebCaption\
WebText
TKeyValues *
TKeyValues
TKeyValuesData
std::vector<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> >
std::_Vector_val<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> >
TKeyValuesData *
TKeyValuesBlock *
std::vector<TKeyValuesData,std::allocator<TKeyValuesData> >
std::vector<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> > *
std::vector<TKeyValuesData,std::allocator<TKeyValuesData> > *
std::_Vector_val<TKeyValuesData,std::allocator<TKeyValuesData> >
TKeyValuesBlock
LeftPartButton
LeftPartButtonMouse
WriteKeyList
FPort
FPassword
URLDecode
URLEncode
Password
rsa_keygen
dsa_keygen
pub_key
priv_key
PEVP_PKEY
EVP_PKEY_union
EVP_PKEY
pkey
pkey_type
required_pkey_type
key_len
key_length
AUTHORITY_KEYID
keyid
PAUTHORITY_KEYID|kZ
X509_PUBKEY
public_key
PX509_PUBKEYtmZ
X509_CERT_AUX
PX509_CERT_AUX
cert_info
ex_nscert
get_cert_methods
cert_crl
ppem_password_cb
key_arg_length
key_arg
master_key_length
master_key
sess_cert
Ptlsext_ticket_key_cb!
cert_store
default_passwd_callback
default_passwd_callback_userdata
client_cert_cb
extra_certs
max_cert_list
cert
msg_callback
msg_callback_arg
client_cert_engine
tlsext_tick_key_name
tlsext_tick_hmac_key
tlsext_tick_aes_key
tlsext_ticket_key_cb
init_msg
read_key
write_key
key_material_length
key_material
tmp_cert_type
tmp_cert_length
tmp_cert_verify_md
tmp_cert_req
tmp_key_block_length
tmp_key_block
tmp_cert_request
msg_len
w_msg_hdr
r_msg_hdr
AMsg
sslvrfFailIfNoPeerCert
TCallbackExEvent
TPasswordEvent
TPasswordEventEx
VPassword
Certificate
fsRootCertFile
fsCertFile
fsKeyFile
RootCertFile
CertFile
KeyFile
LoadRootCert
LoadCert
KeyFileP
fPeerCert
PeerCert
fOnGetPassword
fOnGetPasswordEx
OnGetPassword\
OnGetPasswordEx
MakeFTPSvrPort
MakeFTPSvrPasv
EIdOSSLLoadingRootCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingCertErrorp4[
EIdOSSLLoadingKeyError
EIdOSSLLoadingKeyError(5[
fPassThrough
PassThrough@
FLastCmdResult
TIdTCPConnectionB
RaiseExceptionForLastCmdResult
SendCmd
SendCmdf
TIdTCPConnection
IdTCPConnection
LastCmdResult@
FBoundPort
FBoundPortMax
FBoundPortMin
TIdTCPClientCustom'
TIdTCPClientCustom
IdTCPClient
BoundPort
BoundPortMax
BoundPortMin
TIdTCPClient
%EIdSocksUDPNotSupportedBySOCKSVersion
saUsernamePassword
FUDPSocksAssociation
OpenUDP
RecvFromUDP
SendToUDP9
CloseUDP
Portp
FClientPortMin
FClientPortMax
FPeerPort
ClientPortMin
ClientPortMax
Port@
PeerPort
TIdIPAddressH
IPAsString
FDefaultPort
DefaultPortp
VMsgEnd
EIdPortRequired
EIdTCPConnectionError
EIdTCPConnectionErrorPg]
EIdObjectTypeNotSupported
"EIdTransparentProxyUDPNotSupported
SendToUDPm
IdStackWindows
TIdSocketListWindows4
TIdSocketListWindows
TIdStackWindowsg
VPort
WSGetServByPort
APortNumber
ReceiveMsg
WSTranslateSocketErrorMsg
SupportsIPv6
CheckIPVersionSupport
TIdStackWindows
EIdIPVersionUnsupported0
EIdIPVersionUnsupported
ReceiveMsg,
EIdCanNotBindPortInRange
EIdCanNotBindPortInRanged
EIdInvalidPortRangeD
EIdInvalidPortRange
ftpTransfer
ftpReady
ftpAborted
WMHTTP *
WMHTTP
WMHTTP0
TSQLTimeStamp
TSQLTimeStampOffset
TSQLTimeStampVariantType0
TSQLTimeStampVariantType
SqlTimSt
TSQLTimeStampOffsetVariantType0
TSQLTimeStampOffsetVariantType
TSQLTimeStampData6
ASQLTimeStamp
TSQLTimeStampData k_
TSQLTimeStampOffsetData6
ASQLTimeStampOffset
TSQLTimeStampOffsetDatadp_
%u8F3
C.Pj W
TApi.HttpGetText$17277$0$Intf
TApi.HttpGetText$17277$ActRec
log/send_report
ntdll.dll
\Capabilities\UrlAssociations
TC32Url
TC32Urls
Urls
LicenseUrl
ConfidentialUrl
$TDownstalHelper.LoadImg$17299$0$Intf
$TDownstalHelper.LoadImg$17299$ActRec
$TDownstalHelper.LoadImg$17299$ActRecp\a
7TDownstalHelper.DownloadAndInstallPartners$17304$0$Intf
_http
7TDownstalHelper.DownloadAndInstallPartners$17304$ActRec
7TDownstalHelper.DownloadAndInstallPartners$17304$ActRecP
cWM_VKEYTOITEM
cWM_SETHOTKEY
cWM_GETHOTKEY
cEM_SETPASSWORDCHAR
cEM_GETPASSWORDCHAR
cWM_KEYDOWN
cWM_KEYUP
cWM_SYSKEYDOWN
cWM_SYSKEYUP
cWM_KEYLAST
cWM_CTLCOLORMSGBOX
cCB_MSGMAX
cWM_IME_KEYDOWN
cWM_IME_KEYUP
cWM_HOTKEY
cWM_DDE_EXECUTE
PMsgDecoded
TMsgDecoded
TMsg
Cmsg
PTCKeyDown
TTCKEYDOWN
wVKey
TOnThreadExecute
TPenJoin
Join
G6_KeyPreview
TOnKey
TTabKey
TTabKeys
eoPassword
ScrollCmd
fOnKeyUp
fOnKeyDown
FOnREOverURL
FOnREURLClick
fPass2DefProc
fWndProcKeybd
fExMsgProc
fTBttCmd
fWindowState
fKeyPreviewCount
fREUrl
pszUrl
pszKeywords
pszMsgText
pszMsgTitle
fExecute
pszUrlJump1
pszUrlJump2
pszCurUrl
CmdLine
TWindowsVersion
TWindowsVersions
TGPPenLineJoin
LineJoinMiter
LineJoinBevel
LineJoinRound
LineJoinMiterClipped
PHTTPHeader
THTTPHeader4
HTTPVersion
PHTTPDownloadd
THTTPHdrRecvEvent
PHTTPDownload
THTTPProgressEvent
THTTPErrorEvent
THTTPDownloadEvent
KOLHTTPDownload
THTTPStatusEvent
THTTPDownload
HttpGetText$17238$0$Intf
HttpGetText$17238$ActRec
http:
PKeySendProcess
user32.dll
clCrt@
hXXp://corp.sputnik.ru/legal
hXXp://corp.sputnik.ru/browser/legal
hXXps://VVV.360totalsecurity.com/ru/privacy/
hXXps://VVV.360totalsecurity.com/ru/license/360-total-security/
SOFTWARE\GameModding.net
\toolbar.exe
SQLite
SOFTWARE\GameModding.net\
\VVV.GameModding.net mods\
FormKeyDown
GameModding.net
log\debug.log
\VVV.GameModding.net\
AUTOR_WEB
hXXp://VVV.gamemodding.net/
models\gta3.img
pc\models\cdimages\vehicles.img
VVV.GameModding.net\
VVV.GameModding.net\Uninstall
VVV.GameModding.net\Uninstall(
hXXp://log.gamemodding.net
lblWebCaption
lblWebText$
idHTTP
idHTTPFinish
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
GMMInstallMods.log
res_mods\0.8.4\text
res_mods\0.8.5\text
res_mods\0.8.6\text
res_mods\0.8.7\text
res_mods\0.8.8\text
res_mods\0.8.9\text
res_mods\0.9.0\text
res_mods\0.9.1\text
res_mods\0.9.2\text
res_mods\0.9.3\text
res_mods\0.9.4\text
res_mods\0.9.5\text
res_mods\0.8.10\text
data.config
readme.txt
VVV.GameModding.net.url
hXXp://VVV.GameModding.net/
GAME_EXE_NAME
Data.cfg
data.cfg
cleo\skin.img
config.ini
skin.png
skin.json
.xpfl
label.gm
%dir%
gmm.dff
vgs_palm%d
tree%d
gtatreeshi%d
radar%d
ce_ground%d
ce_lod_%d
ce_bankalley%d
melrose%d
sw_block%d
vgnretail%d
gta3.img
gmm.lbl
SEARCH_KEY1
SEARCH_KEY
cstrike\gameinfo.txt
\Fallout4\plugins.txt
Data.Path =
Data.DataSize =
\SOFTWARE\GameModding.net
\SOFTWARE\GameModding.net\
config.data
config.cfg
Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0; .NET CLR 1.0.2914)
xxtype.cpp
derv->tpClass.tpcFlags & CF_HAS_BASES
Inappropriate I/O control operation
Broken pipe
Operation not permitted
%H:%M:%S
%m/%d/%y
%A, %B %d, %Y
d/d/d d:d:d.d
kernel32.dll
xx.cpp
varType->tpClass.tpcFlags & CF_HAS_DTOR
varType->tpClass.tpcDtorAddr
(vbFlag && (errPtr->ERRcInitDtc >= varType->tpClass.tpcDtorCount)) || (!vbFlag && (errPtr->ERRcInitDtc >= varType->tpClass.tpcNVdtCount)) || flags
memType->tpClass.tpcFlags & CF_HAS_DTOR
varType->tpArr.tpaElemType->tpClass.tpcFlags & CF_HAS_DTOR
dttPtr->dttType->tpPtr.tppBaseType->tpClass.tpcFlags & CF_HAS_DTOR
IS_CLASS(dttPtr->dttType->tpMask) && (dttPtr->dttType->tpClass.tpcFlags & CF_HAS_DTOR)
elemType->tpClass.tpcFlags & CF_HAS_DTOR
_noParam.VType == VT_ERROR
variant.cpp
_empty.VType == varEmpty
VType == rhs.VType
C:\Builds\TP\include\windows\rtl\utilcls.h
Parms.VType == (VT_ARRAY|VT_VARIANT)
ParmTypes.VType == (VT_ARRAY|VT_I4)
?456789:;<=
!"#$%&'()* ,-./0123
{"generator":"MediaMagnet", "values":{ "targetname":"\u0424\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438 \u043a\u043e\u0442\u0438\u043a\u043e\u0432", "place_domain":"domain.ru", "MediaMagnetLicUrl":"hXXps://coin32.com/MediaMagnet.html", "MediaMagnetConfUrl":"", }, "targeturl":"hXXp://fastloadmedia.ru/libs/test/kotiki.zip", "api_url":["hXXp://medialogger.ru/api/v3.1.0/"], "resource_url":"hXXp://downloadcloud.ru", "api_key":"^3e86f9e990fb82f58e181887c75e4d466107fa1a647681e6c17dd3260973dae2", "place_id":"1", "site_id":"1", "referrer":"hXXp://referer.url/", "timestamp" : 1433370034, "embedded_data" : { }, "download_plugins":{ "narod": "hXXp://fastloadmedia.ru/libs/modules/narod.bin", "torrent": "hXXp://fastloadmedia.ru/libs/modules/torrent.bin", "yadisk":"hXXp://fastloadmedia.ru/libs/modules/yadisk.bin" }, "adv_ti":{ "regSoftwareAmigo": "HKCU\\Software\\Amigo", "regAmigoInstaller": "HKCU\\Software\\Mail.Ru\\AmigoInstaller", "regSoftwareMailUninstall": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MailRuUpdater", "regSoftwareYandex": "HKCU\\Software\\Yandex", "regSoftwareYandexBrowser": "HKCU\\Software\\Yandex\\YandexBrowser", "regSoftwareRambler": "HKCU\\Software\\Rambler", "regSoftwareRamblerUpdate": "HKCU\\Software\\Rambler\\Update", "dirAmigoPathExists": "{localappdata}Amigo\\", "dirMailPathExists": "{localappdata}Mail.Ru\\", "dirMailSputnikPathExists": "{localappdata}Mail.Ru\\Sputnik\\", "dirYandexPathExists": "{localappdata}Yandex\\", "dirYandexBrowserPathExists": "{localappdata}Yandex\\YandexBrowser\\", "dirYandexUpdaterPathExists": "{localappdata}Yandex\\Updater\\", "dirRamblerPathExists": "{localappdata}Rambler\\", "dirRamblerUpdaterPathExists": "{localappdata}Rambler\\RamblerUpdater\\", "dirZaxarPathExists": "{programfiles(x86)}Zaxar\\", "fileAmigoFileExists": "{localappdata}Amigo\\Application\\amigo.exe", "fileMailRuUpdater": "{localappdata}Mail.Ru\\MailRuUpdater.exe", "fileSputnikMailRuIco": "{localappdata}Mail.Ru\\Sputnik\\MailRu.ico", "fileYandexClidsBarie": "{appdata}Yandex\\clids-barie.xml", "fileYandexBrowser": "{localappdata}Yandex\\YandexBrowser\\Application\\browser.exe", "fileZaxarFileExists": "{programfiles(x86)}Zaxar\\ZaxarGameBrowser.exe" }, "logging": true}
AKv.AKv
KERNEL32.DLL
USER32.DLL
WINDOWSCODECS.DLL
DWMAPI.DLL
UXTHEME.DLL
SHELL32.DLL
gta.exe
@$xp$10Kol@TOnKey
@$xp$11Kol@TTabKey
@$xp$12Kol@TPenJoin
@$xp$12Kol@TTabKeys
@$xp$14Kol@PTCKeyDown
@$xp$14Kol@TTCKEYDOWN
@$xp$15Kol@PMsgDecoded
@$xp$15Kol@TMsgDecoded
@$xp$16Kol@TWindowState
@$xp$19C32lib_main@TC32Url
@$xp$19Kol@TWindowsVersion
@$xp$20C32lib_main@TC32Urls
@$xp$20Kol@TOnThreadExecute
@$xp$20Kol@TWindowsVersions
@$xp$21Utils@PKeySendProcess
@$xp$24Kolgdipv2@TGPPenLineJoin
@$xp$25Kolhttpdownload@TSpecials
@$xp$27Kolhttpdownload@PHTTPHeader
@$xp$27Kolhttpdownload@THTTPHeader
@$xp$29Kolhttpdownload@PHTTPDownload
@$xp$29Kolhttpdownload@THTTPDownload
@$xp$30Kolhttpdownload@TEventHandlers
@$xp$31Kolhttpdownload@PDownloadWorker
@$xp$31Kolhttpdownload@TDownloadWorker
@$xp$31Kolhttpdownload@THTTPErrorEvent
@$xp$32Kolhttpdownload@PREQUEST_CONTEXT
@$xp$32Kolhttpdownload@THTTPStatusEvent
@$xp$32Kolhttpdownload@TREQUEST_CONTEXT
@$xp$33Kolhttpdownload@THTTPHdrRecvEvent
@$xp$34Kolhttpdownload@THTTPDownloadEvent
@$xp$34Kolhttpdownload@THTTPProgressEvent
@$xp$8Kol@TMsg
@@Wmhttp@Finalize
@@Wmhttp@Initialize
@Admutil@IsWindowsAdministrator$qqrv
@Apicontroller@TApi@GetKey$qqrv
@Apicontroller@TApi@HttpGetText$qqrx20System@UnicodeStringp12Kol@TStrList20System@UnicodeStringt3
@Apicontroller@TApi@send_report$qqr20System@UnicodeString
@Browserdetect@OpenURL$qqr20System@UnicodeString
@Comobj@GetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatchSystem@WideString
@Comobj@GetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatch%i
@Comobj@SetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatchSystem@WideStringrx17System@OleVariant
@Comobj@SetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatch%irx17System@OleVariant
@Comobj@TComObject@$bctr$qqrp17TComObjectFactoryx45System@ÞlphiInterface$t17System@IInterface%
@Downstalhelper@TDownstalHelper@OnDownloadError$qqrp29Kolhttpdownload@THTTPDownloadus
@Downstalhelper@TDownstalHelper@OnDownloadTargetProgress$qqrp29Kolhttpdownload@THTTPDownloadiiii
@Downstalhelper@TDownstalHelper@OnHeaderReceived$qqrp29Kolhttpdownload@THTTPDownloadp12Kol@TStrList
@Downstalhelper@TDownstalHelper@OnHttpProgress$qqrp29Kolhttpdownload@THTTPDownloadiiii
@Downstalhelper@TDownstalHelper@OnStatusEvent$qqrp29Kolhttpdownload@THTTPDownloadpvuiuit2ui
@Kol@AutoMinimizeApplet$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@CharIn$qqrbrx29System@%Set$tc$iuc$0$iuc$255%
@Kol@DummyOnDrawItemProc$qqrpvp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%
@Kol@DummyOnLVCustomDrawProc$qqrpvp12Kol@TControlp5HDC__uiiirx11Types@TRect44System@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%rit9
@Kol@ExePath$qqrv
@Kol@ExecuteConsoleAppIORedirect$qqrx20System@UnicodeStringt1t1uit1r20System@UnicodeStringui
@Kol@ExecuteIORedirect$qqrx20System@UnicodeStringt1t1uipuit5t5t5
@Kol@ExecuteWait$qqrx20System@UnicodeStringt1t1uiuipui
@Kol@FormSetIndexedEvent$qqrp12Kol@TControl
@Kol@FormSetKeyPreviewTrue$qqrp12Kol@TControl
@Kol@FormSetWindowState$qqrp12Kol@TControl
@Kol@GetWindowsDir$qqrv
@Kol@IsWinVer$qqr47System@%Set$t19Kol@TWindowsVersion$iuc$0$iuc$9%
@Kol@MsgBox$qqrx20System@UnicodeStringui
@Kol@MsgOK$qqrx20System@UnicodeString
@Kol@NewBitBtn$qqrp12Kol@TControlx20System@UnicodeString45System@%Set$t17Kol@TBitBtnOption$iuc$0$iuc$4Kol@TGlyphLayoutp9HBITMAP__i
@Kol@NewCombobox$qqrp12Kol@TControl45System@%Set$t16Kol@TComboOption$iuc$0$iuc$10%
@Kol@NewDateTimePicker$qqrp12Kol@TControl53System@%Set$t25Kol@TDateTimePickerOption$iuc$0$iuc$5%
@Kol@NewEditbox$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewGraphEditbox$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewListView$qqrp12Kol@TControl18Kol@TListViewStyle48System@%Set$t19Kol@TListViewOption$iuc$0$iuc$25%p14Kol@TImageListt4t4
@Kol@NewListbox$qqrp12Kol@TControl44System@%Set$t15Kol@TListOption$iuc$0$iuc$12%
@Kol@NewOpenDirDialog$qqrx20System@UnicodeString46System@%Set$t18Kol@TOpenDirOption$iuc$0$iuc$8%
@Kol@NewOpenSaveDialog$qqrx20System@UnicodeStringt148System@%Set$t19Kol@TOpenSaveOption$iuc$0$iuc$14%
@Kol@NewProgressbarEx$qqrp12Kol@TControl50System@%Set$t22Kol@TProgressbarOption$iuc$0$iuc$1%
@Kol@NewRichEdit$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewRichEdit1$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewScrollBox$qqrp12Kol@TControl14Kol@TEdgeStyle44System@%Set$t16Kol@TScrollerBar$iuc$0$iuc$1%
@Kol@NewTabControl$qqrp12Kol@TControlpxpbxi50System@%Set$t21Kol@TTabControlOption$iuc$0$iuc$14%p14Kol@TImageListi
@Kol@NewTabEmpty$qqrp12Kol@TControl50System@%Set$t21Kol@TTabControlOption$iuc$0$iuc$14%p14Kol@TImageList
@Kol@NewToolbar$qqrp12Kol@TControl17Kol@TControlAlign46System@%Set$t18Kol@TToolbarOption$iuc$0$iuc$7%p9HBITMAP__pxpbxipxixi
@Kol@NewTreeView$qqrp12Kol@TControl48System@%Set$t19Kol@TTreeViewOption$iuc$0$iuc$13%p14Kol@TImageListt3
@Kol@RegKeyClose$qqrp6HKEY__
@Kol@RegKeyDelete$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyDeleteValue$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyExists$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetBinary$qqrp6HKEY__x20System@UnicodeStringpvi
@Kol@RegKeyGetDateTime$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetDw$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetStr$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetStrEx$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetSubKeys$qqrxp6HKEY__p13Kol@TWStrList
@Kol@RegKeyGetValueNames$qqrxp6HKEY__p13Kol@TWStrList
@Kol@RegKeyGetValueTyp$qqrxp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenCreate$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenRead$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenWrite$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeySetBinary$qqrp6HKEY__x20System@UnicodeStringpxvi
@Kol@RegKeySetDateTime$qqrp6HKEY__x20System@UnicodeString16System@TDateTime
@Kol@RegKeySetDw$qqrp6HKEY__x20System@UnicodeStringui
@Kol@RegKeySetStr$qqrp6HKEY__x20System@UnicodeStringt2
@Kol@RegKeySetStrEx$qqrp6HKEY__x20System@UnicodeStringt2o
@Kol@RegKeyValExists$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyValueSize$qqrp6HKEY__x20System@UnicodeString
@Kol@ShowMsg$qqrx20System@UnicodeStringui
@Kol@StrIn$qqrx27System@%AnsiStringT$us$i0$%px27System@%AnsiStringT$us$i0$%xi
@Kol@StrIs$qqrx27System@%AnsiStringT$us$i0$%px27System@%AnsiStringT$us$i0$%xiri
@Kol@SupportAnsiMnemonics$qqri
@Kol@SystemTime2Str$qqrrx11_SYSTEMTIMExuix47System@%Set$t19Kol@TTimeFormatFlag$iuc$0$iuc$3%pxb
@Kol@TColorDialog@Execute$qqrv
@Kol@TControl@AttachProc$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@AttachProcEx$qqrpqqrp12Kol@TControlr8Kol@TMsgri$oo
@Kol@TControl@CallDefWndProc$qqrr8Kol@TMsg
@Kol@TControl@CreateChildWindows$qqrv
@Kol@TControl@DefaultBtnProc$qqrr8Kol@TMsgri
@Kol@TControl@DetachProc$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@FormCreateParameters$qqrp65System@%StaticArray$pqqrp12Kol@TControl$p12Kol@TControli$i65536$%pc
@Kol@TControl@FormExecuteCommands$qqrp12Kol@TControlp31System@%StaticArray$si$i65536$%
@Kol@TControl@GetKeyPreview$qqrv
@Kol@TControl@GetWindowState$qqrv
@Kol@TControl@Get_OnKeyDown$qqrv
@Kol@TControl@Get_OnKeyUp$qqrv
@Kol@TControl@GraphButtonKeyboardProcess$qqrr8Kol@TMsgri
@Kol@TControl@GraphicButtonMouse$qqrr8Kol@TMsg
@Kol@TControl@GraphicCheckBoxMouse$qqrr8Kol@TMsg
@Kol@TControl@GraphicEditMouse$qqrr8Kol@TMsg
@Kol@TControl@IsProcAttached$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@LVAdd$qqrx20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVInsert$qqrix20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVSetItem$qqriix20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVSetItemState$qqrix51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%
@Kol@TControl@Postmsg$qqsuiii
@Kol@TControl@REGetAutoURLDetect$qqrv
@Kol@TControl@REGetOnURL$qqrxi
@Kol@TControl@REGetTextSize$qqr46System@%Set$t18Kol@TRichTextSizes$iuc$0$iuc$3%
@Kol@TControl@RESetAutoURLDetect$qqrxo
@Kol@TControl@RESetOnURL$qqrxixynpqqrp8Kol@TObj$v
@Kol@TControl@SetKeyPreview$qqrxo
@Kol@TControl@SetLVOptions$qqrx48System@%Set$t19Kol@TListViewOption$iuc$0$iuc$25%
@Kol@TControl@SetOnDrawItem$qqrxynpqqrp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%$o
@Kol@TControl@SetOnKeyDown$qqrxynpqqrp12Kol@TControlriui$v
@Kol@TControl@SetOnKeyUp$qqrxynpqqrp12Kol@TControlriui$v
@Kol@TControl@SetOnLVCustomDraw$qqrxynpqqrp12Kol@TControlp5HDC__uiiirx11Types@TRect44System@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%rit8$ui
@Kol@TControl@SetOnRE_OverURL$qqrxynpqqrp8Kol@TObj$v
@Kol@TControl@SetOnRE_URLClick$qqrxynpqqrp8Kol@TObj$v
@Kol@TControl@SetWindowState$qqr16Kol@TWindowState
@Kol@TControl@Set_OnMessage$qqrxynpqqrr8Kol@TMsgri$o
@Kol@TControl@SupportMnemonics$qqrv
@Kol@TControl@WndProc$qqrr8Kol@TMsg
@Kol@TGraphicTool@GetPenJoin$qqrv
@Kol@TGraphicTool@SetFontStyle$qqrx43System@%Set$t15Kol@TFontStyles$iuc$0$iuc$3%
@Kol@TGraphicTool@SetPenJoin$qqrx12Kol@TPenJoin
@Kol@TIcon@LoadFromExecutable$qqrx20System@UnicodeStringi
@Kol@TIniFile@ClearKey$qqrx20System@UnicodeString
@Kol@TMenu@AddItem$qqrpbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@Insert$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@InsertItem$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@InsertItemEx$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%o
@Kol@TMenu@SetOnDrawItem$qqrxynpqqrp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%$o
@Kol@TOpenDirDialog@Execute$qqrv
@Kol@TOpenSaveDialog@Execute$qqrv
@Kol@TStrList@Join$qqrx27System@%AnsiStringT$us$i0$%
@Kol@TStrListEx@AddObject$qqrx27System@%AnsiStringT$us$i0$%ui
@Kol@TStrListEx@InsertObject$qqrix27System@%AnsiStringT$us$i0$%ui
@Kol@TThread@Execute$qqrv
@Kol@TerminateExecution$qqrrp12Kol@TControl
@Kol@ToolbarsIDcmd
@Kol@WindowsLogoff$qqro
@Kol@WindowsShutdown$qqrx20System@UnicodeStringoo
@Kol@WndProcAppAsm$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcCtrl$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcDoEraseBkgnd$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcDummy$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcKeybd$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcMenu$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcMouse$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcUnicodeChars$qqrp12Kol@TControlr8Kol@TMsgri
@Kolgdipv2@GdiplusShutdown
@Kolgdipv2@NewGPFont$qqrix20System@UnicodeString43System@%Set$t15Kol@TFontStyles$iuc$0$iuc$3%
@Kolgdipv2@NewGPImageS$qqrx34System@ÞlphiInterface$t7IStream%o
@Kolgdipv2@NewGPStringFormat$qqr62System@%Set$t33Kolgdipv2@TGPStringFormatBitFlags$iuc$0$iuc$14%
@Kolgdipv2@SaveGPImageS$qqrpx18Kolgdipv2@TGPImagex34System@ÞlphiInterface$t7IStream%x29Kolgdipv2@TGdiPlusImageFormat
@Kolgdipv2@TGPImageAttributes@SetColorKey$qqrpxuixi31Kolgdipv2@TGPColorRemapCategory
@Kolgdipv2@TGPPen@GetLineJoin$qqrv
@Kolgdipv2@TGPPen@SetLineJoin$qqr24Kolgdipv2@TGPPenLineJoin
@Kolgdipv2@TGPStringFormat@SetFormatFlags$qqr62System@%Set$t33Kolgdipv2@TGPStringFormatBitFlags$iuc$0$iuc$14%
@Kolgdipv2@TKOLStreamAdapter@Clone$qqsr34System@ÞlphiInterface$t7IStream%
@Kolgdipv2@TKOLStreamAdapter@CopyTo$qqs34System@ÞlphiInterface$t7IStream%jrjt3
@Kolhttpdownload@DecodeURL$qqrx27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@EncodeURI$qqrx20System@UnicodeString
@Kolhttpdownload@EncodeURL$qqrx20System@UnicodeString
@Kolhttpdownload@EvHandler
@Kolhttpdownload@FileSpecialChar
@Kolhttpdownload@Finalization$qqrv
@Kolhttpdownload@GetMimeTypeExtension$qqr20System@UnicodeString
@Kolhttpdownload@GetMimeTypeFromData$qqr20System@UnicodeStringp11Kol@TStream
@Kolhttpdownload@GetURLFileName$qqrp29Kolhttpdownload@THTTPDownload20System@UnicodeStringt2
@Kolhttpdownload@GetWinInetError$qqrui
@Kolhttpdownload@HttpGetText$qqrpx29Kolhttpdownload@THTTPDownloadx20System@UnicodeStringp12Kol@TStrList20System@UnicodeString27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@HttpGetText$qqrx20System@UnicodeStringp12Kol@TStrList20System@UnicodeString27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@Internet_Options
@Kolhttpdownload@NewDownloadWorker$qqrp29Kolhttpdownload@THTTPDownload
@Kolhttpdownload@NewHTTPDownload$qqrv
@Kolhttpdownload@ParseURL$qqrx20System@UnicodeStringr20System@UnicodeStringt2t2t2t2t2
@Kolhttpdownload@TDownloadWorker@
@Kolhttpdownload@TDownloadWorker@$bdtr$qqrv
@Kolhttpdownload@TDownloadWorker@On_DownloadExecute$qqrp11Kol@TThread
@Kolhttpdownload@TDownloadWorker@On_UpdateProgress$qqrv
@Kolhttpdownload@TDownloadWorker@On_WatchExecute$qqrp11Kol@TThread
@Kolhttpdownload@TDownloadWorker@StartDownload$qqrv
@Kolhttpdownload@TDownloadWorker@StopDownload$qqrv
@Kolhttpdownload@TEventHandlers@
@Kolhttpdownload@TEventHandlers@onDownload$qqrp29Kolhttpdownload@THTTPDownloadp11Kol@TStream
@Kolhttpdownload@TEventHandlers@onError$qqrp29Kolhttpdownload@THTTPDownloadus
@Kolhttpdownload@THTTPDownload@
@Kolhttpdownload@THTTPDownload@$bdtr$qqrv
@Kolhttpdownload@THTTPDownload@CancelDownload$qqrv
@Kolhttpdownload@THTTPDownload@CheckConnection$qqr20System@UnicodeString
@Kolhttpdownload@THTTPDownload@FormField$qqr20System@UnicodeStringt1
@Kolhttpdownload@THTTPDownload@FormFieldsClear$qqrv
@Kolhttpdownload@THTTPDownload@GetResource$qqr20System@UnicodeString
@Kolhttpdownload@THTTPDownload@ParseHeaders$qqrrp27Kolhttpdownload@THTTPHeader
@Kolhttpdownload@THTTPDownload@SetAuthInfo$qqr20System@UnicodeStringt1
@Kolhttpdownload@THTTPDownload@SetCustomHeaders$qqrp12Kol@TStrList
@Kolhttpdownload@THTTPDownload@SetDataStream$qqrp11Kol@TStream
@Kolhttpdownload@THTTPDownload@SetProxySettings$qqr20System@UnicodeStringi
@Kolhttpdownload@THTTPDownload@fOnErrorCall$qqrp29Kolhttpdownload@THTTPDownloadp11Kol@TThreadus
@Kolhttpdownload@URISpecialChar
@Kolhttpdownload@URLSpecialChar
@Kolhttpdownload@WaitUntilTrue$qqroi
@Kolhttpdownload@initialization$qqrv
@Spstdctrls@TSPCustomLabel@CMDialogChar$qqrr15Messages@TWMKey
@Spstdctrls@TSPCustomLabel@Notification$qqrp18Classes@TComponent18Classes@TOperation
@TSPImageScroll@GetProportionall$qp17Graphics@TPicturei
@TSPImageScroll@MouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TSPImageScroll@MouseMove$qqrp14System@TObject46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TSPImageScroll@MouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TWMActionGTASettings@GetKeyCount$q20System@UnicodeStringt1
@TWMCustomHeaderData@rlblWebC$qqrv
@TWMCustomHeaderData@rlblWebT$qqrv
@TWMCustomHeaderData@wlblWebC$qqrp15Stdctrls@TLabel
@TWMCustomHeaderData@wlblWebT$qqrp15Stdctrls@TLabel
@TWMDialogReplaseModel@Execute$qqrv
@TWMDownloader@SetURL$qqr20System@UnicodeString
@TWMSkinManager@SetRect$q31System@%AnsiStringT$us$i65001$System@Variant
@Tspadvancedinifiles@TSPCustomIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPMemIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPMemIniFile@WriteKeyList$qqrx20System@UnicodeStringp16Classes@TStrings
@Utils@ExecWin$qqr20System@UnicodeStringt1t1oi
@Utils@KeySendProcess
@Utils@MsgBox2$qqrx20System@UnicodeStringuii20System@UnicodeString
@Utils@TClassObj@senderkeynder$qqrv
@Utils@isShiftDown$qqrv
@WTSPCheckBox@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPImageButton@myMouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPImageButton@myMouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPLabelButton@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPLabelButton@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPPageGraphicControl@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPPageGraphicControl@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@MouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@MouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@rLeftPartButton$qqrv
@WTSPStechButton@rLeftPartButtonMouse$qqrv
@WTSPStechButton@wLeftPartButton$qqrp17Graphics@TPicture
@WTSPStechButton@wLeftPartButtonMouse$qqrp17Graphics@TPicture
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
Picture.Data
"iTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:9610CCF6377911E5AC72A378DCF3C356" xmpMM:DocumentID="xmp.did:9610CCF7377911E5AC72A378DCF3C356"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:9610CCF4377911E5AC72A378DCF3C356" stRef:documentID="xmp.did:9610CCF5377911E5AC72A378DCF3C356"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>Utw
.ffP F
kEY{V
(.qA/
%U`5H
`.sg:ON
`.ÿ/
Proportional
Font.Pitch
Font.Quality
LeftPartButton.Data
CenterPartButton.Data
RightPartButton.Data
LeftPartButtonMouse.Data
RightPartButtonMouse.Data
CenterPartButtonMouse.Data
sputnik.ru
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:E6B0FA2B377211E5A78FE9305C68A7CE" xmpMM:DocumentID="xmp.did:E6B0FA2C377211E5A78FE9305C68A7CE"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:E6B0FA29377211E5A78FE9305C68A7CE" stRef:documentID="xmp.did:E6B0FA2A377211E5A78FE9305C68A7CE"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>[>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:29ED0095377A11E5BC2792A256311590" xmpMM:DocumentID="xmp.did:29ED0096377A11E5BC2792A256311590"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:29ED0093377A11E5BC2792A256311590" stRef:documentID="xmp.did:29ED0094377A11E5BC2792A256311590"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
fiTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:F808BFF21198E511B58D893E85EBF264" xmpMM:DocumentID="xmp.did:02FC136F981211E5A24BC905F2B92D35" xmpMM:InstanceID="xmp.iid:02FC136E981211E5A24BC905F2B92D35" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:F908BFF21198E511B58D893E85EBF264" stRef:documentID="xmp.did:F808BFF21198E511B58D893E85EBF264"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
keq.eXd
%F`:V1
S3~%fP
U.LmwV1
 hXXp://ns.adobe.com/xap/1.0/
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:1379A282F81711E59F3C9295ECA48D7A" xmpMM:DocumentID="xmp.did:1379A283F81711E59F3C9295ECA48D7A"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:1379A280F81711E59F3C9295ECA48D7A" stRef:documentID="xmp.did:1379A281F81711E59F3C9295ECA48D7A"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
.ikJOt2
3Y.YR
.Ex-S[
worldofmods.com
BackgroundImage.Data
lblWebCaption
lblWebText
VVV.gamemodding.net
CaptionList.Strings
Diese Modifikation ist nicht von Moderatoren der Website GameModding.net durchgepruft. Sicherheit und Leistungsfahigkeit der Modifikationen kann nicht garantiert werden!
Margins.Left
Margins.Top
Margins.Right
Margins.Bottom
Font.Orientation
LangList.Strings
?5=This modification was downloaded from GameModding.net website
11=hXXp://vk.com/gamemoddingnet
&12=hXXps://twitter.com/GameModdingNet
'13=hXXp://VVV.facebook.com/gamemodding
114=hXXp://VVV.youtube.com/user/GameModdingPreview
GameModding.net
214=hXXp://VVV.youtube.com/user/GameModdingPreview
G5=Cette modification a ete telewchar_tge depuis le site GameModding.net
J5=Diese Modifikation wurde von der Website GameModding.net heruntergeladen
fd:\SteamLibrary\steamapps\common\Grand Theft Auto V\_CommonRedist\176633-2014-mclaren-p1-v2.6-gtav.exe
LanguageList.Strings
GameModding.net
GameModding.net
GameModding.net.
VVV.GameModding.net
LangImage.Data
3=Web Site to Autor:
WebCaption
"8=Add GameModding.net to Favorites
19=Place a GameModding.net shortcut on the desktop
17=This modification is not checked by GameModding.net moderators. Usability and safety of the modification cannot be guaranteed!
"All Programs" in VVV.GameModding.net folder
C37=Visit us again! We will be glad to see you again on our website!
*8=GameModding.net zu Favoriten hinzufuegen
59=GameModding.net Verknuepfung auf dem desktop setzen
17= Diese Modifikation ist nicht von Moderatoren der Website GameModding.net durchgepruft. Sicherheit und Leistungsfahigkeit der Modifikationen kann nicht garantiert werden!
"Alle Programme"- im Ordner VVV.GameModding.net
n37=Kommen Sie und sehen uns wieder! Wir hoffen Sie kommen uns bald einmal auf unserer Website wieder besuchen.
/8=Ajouter worldofmods.com dans le marque-pages
49=Envoyer le raccourci sur le bureau worldofmods.com
rateur du site GameModding.net. La s
\5=hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-cleo-scripts/8940-skin-selector-v21.html
frmRPM.WTSPPageGraphicControl1
W1=With the IMGTool 1.3 program import files from the folder %dir% into the archive -
o4=You can download IMGTool 1.3 hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
6=Import into IMG
(7=Importing files into the game archive:
,12=Unable to complete import in IMG archive!
15=Importing file Into IMG:
17=To import to
B18=Files from the folder %dir% to be imported into the archive -
%dir%
: hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
%dir%
d1=Mit dem Programm IMGTool 1.3 importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
}4=Die Download-Link fuer IMGTool 1.3 ist hier: hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
6=Import in IMG
.7=Importieren von Dateien in das Spiel-Archiv:
B12=Der Import in das IMG Archiv kann nicht vervollstandigt werden!
15=Importieren Datei in IMG:
316=Beim Import der Datei ist ein Fehler aufgetreten
17=Import in
.18=Dateien aus dem Ordner %dir% in das Archiv
k1=With the IMGTool 2.0 or Crazy IMG Editor program import files from the folder %dir% into the archive -
t4=You can download IMGTool 2.0 here: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
5=Crazy IMG Editor here: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
]17=hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-cleo-scripts/8940-skin-selector-v21.html
19=Importing file Into IMG:
21=To import to
B22=Files from the folder %dir% to be imported into the archive -
: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
z1=Mit dem Programm IMGTool 2.0 oder Crazy IMG Editor importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
~4=Die Download-Link fuer IMGTool 2.0 ist hier: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
~5=Crazy IMG Editor hier: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
19=Importieren Datei in IMG:
620=Beim Import der Datei ist ein Fehler aufgetreten:
21=Import in
.22=Dateien aus dem Ordner %dir% in das Archiv
^1=With the SparkIV or OpenIV program import files from the folder %dir% into the archive -
!3=to be imported into the archive
^4=You can download SparkIV hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
S5=Crazy OpenIV: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
(12=Unable to complete import in archive!
16=Importing file Into IMG:
17=Importing file Into RPF:
19=To import to
B20=Files from the folder %dir% to be imported into the archive -
: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
n1=Mit dem Programm SparkIV oder OpenIV importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
o4=Die Download-Link fuer SparkIV ist hier: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
R5=OpenIV hier: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
12=Der Import in das Archiv kann nicht vervollst
16=Importieren Datei in IMG:
17=Importieren Datei in RPF:
618=Beim Import der Datei ist ein Fehler aufgetreten:
19=Import in
.20=Dateien aus dem Ordner %dir% in das Archiv
#1=Replacement options for transport
)1=Replacement-Optionen fuer den Transport
DefaultPort
SSLOptions.Mode
SSLOptions.VerifyMode
SSLOptions.VerifyDepth
LabelFontDisable.Charset
LabelFontDisable.Color
LabelFontDisable.Height
LabelFontDisable.Name
LabelFontDisable.Style
PictureLabel.Data
FontLabels.Charset
FontLabels.Color
FontLabels.Height
FontLabels.Name
FontLabels.Style
Langs.Strings
SkinImage.Data
Paint.NET v3.22
%5UUUM
$A{.fR
CreatePipe
GetCPInfo
GetCPInfoExW
GetProcessHeap
GetWindowsDirectoryW
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegEnumKeyExW
RegFlushKey
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegReplaceKeyW
RegRestoreKeyW
RegSaveKeyW
RegUnLoadKeyW
SetViewportOrgEx
GdipSetPenLineJoin
GdipSetImageAttributesColorKeys
GdipGetPenLineJoin
SHFileOperationW
ShellExecuteA
ShellExecuteExW
ShellExecuteW
ActivateKeyboardLayout
EnumChildWindows
EnumThreadWindows
EnumWindows
ExitWindowsEx
GetAsyncKeyState
GetKeyNameTextW
GetKeyState
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayoutNameW
GetKeyboardState
LoadKeyboardLayoutW
MapVirtualKeyW
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
SetWindowsHookExW
UnhookWindowsHookEx
VkKeyScanExW
keybd_event
HttpAddRequestHeadersW
HttpOpenRequestW
HttpQueryInfoA
HttpQueryInfoW
HttpSendRequestW
InternetOpenUrlW
.text
`.data
.rdata
P.idata
@.didata
.edata
@.rsrc
@.reloc
UrlA
.4P.iG
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="UACAwareApplication" type="win32"/>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" language="*" processorArchitecture="*"/>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings"/>
ADVAPI32.DLL
COMCTL32.DLL
COMDLG32.DLL
GDI32.DLL
GDIPLUS.DLL
MSIMG32.DLL
OLE32.DLL
OLEAUT32.DLL
SHFOLDER.DLL
SHLWAPI.DLL
URLMON.DLL
VERSION.DLL
WININET.DLL
WINMM.DLL
WINSPOOL.DRV
\\?\UNC\
uxtheme.dll
comctl32.dll
TaskDialogIndirect
%s[%d]
%s_%d
.Owner
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
%s%s%.2d:%.2d
%s%s%.2d
%d.%d
%s, ProgID: "%s"
ole32.dll
oleaut32.dll
%s-%s
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
olepro32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
%s (*.%s)|*.%1:s
%s (%s)|%1:s|
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
%s%s%s%s%s%s%s%s%s%s
crSQLWait
%s (%s)
imm32.dll
Portable Network Graphics
data.ini
*<>#%"{}|\^[]`
*<>#%"{}|\^[]` 
HTTPS
libeay32.dll
ssleay32.dll
libssl32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_add_cert
X509_STORE_CTX_get_current_cert
i2d_DSAPrivateKey
d2i_DSAPrivateKey
d2i_PrivateKey
d2i_PrivateKey_bio
DES_set_key
_ossl_old_des_set_key
RSA_generate_key
RSA_check_key
RSA_generate_key_ex
i2d_PrivateKey_bio
i2d_RSAPrivateKey
d2i_RSAPrivateKey
i2d_RSAPublicKey
d2i_RSAPublicKey
i2d_PrivateKey
i2d_NETSCAPE_CERT_SEQUENCE
X509_get_default_cert_file
X509_get_default_cert_file_env
X509_set_pubkey
X509_REQ_set_pubkey
PEM_read_bio_RSAPrivateKey
PEM_read_bio_RSAPublicKey
PEM_read_bio_DSAPrivateKey
PEM_read_bio_PrivateKey
PEM_read_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_RSAPublicKey
PEM_write_bio_DSAPrivateKey
PEM_write_bio_PrivateKey
PEM_write_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_PKCS8PrivateKey
EVP_PKEY_type
EVP_PKEY_new
EVP_PKEY_free
EVP_PKEY_assign
Open SSL Support DLL Delphi and C  Builder interface
hXXp://VVV.indyproject.org/
1993 - 2009
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
csShiftJIS
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
0.0.0.1
0.0.0.0
255.255.255.255
Wship6.dll
Fwpuclnt.dll
WS2_32.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
MSWSOCK.DLL
WSARecvMsg
WSASendMsg
Kernel32.dll
127.0.0.1
10.5.7
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
http\shell\open\command
psapi.dll
base_url
windows
log.txt
api_url
api_key
resource_url
Load image HTTP error #
|adv_ti|api_url|resource_url|values|embedded_data|
merge_keys
API key:
vendor_logo_url
appended_keys
append_keys
http_error
default_keys
_fail_exec
api.get_stat(
Result of api.get_stat:
targeturl
target_content.dat
Target content url:
hXXps://ssl.google-analytics.com/collect
hXXp://VVV.google-analytics.com/collect
ds=web
dl=hXXp://vpn-ping.ru/
Exception %s in module %s at %p.
Operation aborted
I/O error %d
Invalid pointer operation
Invalid floating point operation
Access violation at address %p. %s of address %p
External exception %x
Interface not supported
%s (%s, line %d)
Access violation at address %p in module '%s'. %s of address %p
D:\Dev\coin32\desktop-downstaller\desktop-libraries\kol_libs\err.pas
Win32 Error. Code: %d.
.manifest
2000/1/1
dd.MM.yyyy
DumpWindowed.txt
HHCTRL.OCX
GdiPlus.dll
GdiplusShutdown
.html
default.html
wininet.dll
Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)
https
http=
Content-Type: application/x-www-form-urlencoded
Balanced tree root node level is %d
Shell32.dll
{43826D1E-E718-42EE-BC55-A1E261C37BFE}
D:\Dev\coin32\desktop-downstaller\downstaler\libs\Utils.pas
Certificats table file offset: $
Certificats table size:
Certificats table real size:
%s Pb
%s Tb
%s Gb
%s Mb
%s Kb
%d.%d.%d
mail.ru
@Mail.Ru
search_url
startup_urls
urls_to_restore_on_startup
opera
Opera Software\
icudt.dll
Opera\Opera\
operaprefs.ini
search.ini
Home URL
firefox
Mozilla\Firefox\
profiles.ini
prefs.js
browser.search.selectedEngine
browser.startup.homepage
Software\Microsoft\Windows\CurrentVersion\Uninstall\
Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
WbemScripting.SWbemLocator
Select %s from %s
hXXp://VVV.gamemodding.net/?from=inst_link
hXXp://VVV.gamemodding.net/ru/toolbar.html
hXXp://VVV.gamemodding.net/en/toolbar.html
hXXp://VVV.gamemodding.net/feedback/
hXXp://VVV.gamemodding.net/forum/index.php
hXXp://VVV.gamemodding.net/?from=inst_logo
hXXp://VVV.facebook.com/gamemodding
hXXp://vk.com/gamemoddingnet
hXXp://VVV.youtube.com/user/GameModdingPreview
hXXps://twitter.com/GameModdingNet
hXXps://plus.google.com/communities/107466553082411818715
hXXp://ok.ru/group/52311790387354
8\\\?\
r\\?\
L==\\?\
\0 1 2 0 1 2
HTTP/1.1
%)('=<@/ 7>83&:*2?6,91;.50-4
KUTF8: A start byte not followed by enough continuation bytes in position %s
%s is not a valid BCD value$Could not parse SQL TimeStamp string
Invalid SQL date/time values
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Set Size Exceeded.AUTF8: Type cannot be determined out of header byte at position %sDUTF8: An unexpected continuation byte in %s-byte UTF8 in position %s
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
Socket Error # %d
Operation would block.
Operation now in progress.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.$Cannot change a connected IOHandler.%No IOHandler of type %s is installed.
Reply Code is not valid: %s
Reply Code already exists: %s4Failed attempting to retrieve time zone information.-Error on call to Winsock2 library function %s
Command not supported.
Address type not supported."%d: Circular links are not allowed"Not enough data in buffer. (%d/%d)
File "%s" not found
Object type not supported.
Host field is empty)UDP is not support in this SOCKS version.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
SSL status: "%s"
%s Alert
%s Read Alert
%s Write Alert
Optimizing'Algorithm %s not permitted in FIPS mode$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Unsupported PixelFormat
Invalid stream operation
Invalid extension introducerúiled to allocate memory for GIF DIB
Invalid Image trailerAInternal error: Extension Instance does not match Extension Label,Unsupported Application Extension block size
Unknown GIF block type'Object type not supported for operation
dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.]The program tried to add a existent critical chunk to the current image which is not allowed.IIt's not allowed to add a new chunk because the current image is invalid.7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA)OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.oThe "Portable Network Graphics" could not be created because invalid image type parameters have being provided.
"Failed to set tab "%s" at index %d Failed to set object at index %d<MultiLine must be True when TabPosition is tpLeft or tpRightE%d is an invalid PageIndex value. PageIndex must be between 0 and %d&Cannot change the size of a JPEG image
JPEG error #%d
JPEG Image FilejThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it againnThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d."PageControl must first be assigned"%s requires Windows Vista or later %s requires themes to be enabled
Button%d
RadioButton%d
Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d Failed to get object at index %d
Value must be between %d and %d
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard: %s
Text exceeds memo capacity Operation not supported on selected printer.There is no default printer currently selected
%s property out of range
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active0Can only modify an image if it contains a bitmap*A control cannot have itself as its parent
$Unknown picture file extension (.%s)
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Scan line index out of range!Cannot change the size of an iconÊnnot change the size of a WIC Image Invalid operation on TOleGraphic
Invalid destination array"Character index out of bounds (%d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
/Custom variant type (%s%.4x) already used by %s*Custom variant type (%s%.4x) is not usable2Too many custom variant types have been registered5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Object lock not owned(Monitor support function not initialized
(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s,Custom variant type (%s%.4x) is out of range
Integer overflow Invalid floating point operation
Invalid class typecast0Access violation at address %p. %s of address %p
No help found for %s
Duplicates not allowed('%s' is not a valid floating point value '%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
WThe given "%s" local time is invalid (situated within the missing period prior to DST).$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and <= %drHigh surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properlyrLow surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly2Length of Strings and Objects arrays must be equal
Invalid Timeout value: %s
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid time
No help found for context %d
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread2Cannot call Start on a running or suspended thread;Cannot call CheckTerminated on an externally created thread9Cannot call SetReturnValue on an externally create thread'Parameter %s cannot be a negative value*Input buffer exceeded for %s = %d, %s = %d
The specified path is too long The specified path was not found The path format is not supported The specified file was not found
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream)%s has not been registered as a COM class
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Invalid data type for '%s'
OLE error %.8x#Object factory for class %s missing%Type information missing for class %s'Incorrect type information for class %s(Dispatch interface missing from class %s.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
VVV.GameModding.net
3.1.0.0
1.0.0.0

1.exe_2224_rwx_00401000_003A2000:

TArray<System.Byte>
TArray<System.Char>
Generics.Collections
doOwnsKeys
crTextColor
TWMKey
KeyData
grfLocksSupported
ISupportErrorInfo
HelpKeyword
UnderstandsKeyword
ssShift
htKeyword
EInvalidOperation
TList.TDirection
AOperator
TThread.TSynchronizeRecord
TOperation
Operation
TComponent$%C
FOnExecute
OnExecute
TArray<System.string>
TArray<System.TObject>
TList.Sort$594$0$Intf
TList.Sort$594$ActRec
$TComponent.FindComponent$1217$0$Intf
$TComponent.FindComponent$1217$ActRec
TRegKeyInfo
NumSubKeys
MaxSubKeyLen
FCurrentKey
FRootKey
FCloseRootKey
CloseKey
CreateKey
DeleteKey
GetKeyInfo
GetKeyNames
HasSubKeys
KeyExists
LoadKey
MoveKey
OpenKey
OpenKeyReadOnly
ReplaceKey
RestoreKey
SaveKey
UnLoadKey
CurrentKey
LastErrorMsg
RootKey
RootKeyName8
TLocalTimeZone.TYearlyChanges
TLocalTimeZone.TYearlyChanges0
:TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
LTArray<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
QTEnumerator<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>(
QTEnumerator<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
QTEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>-
QTEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>D
FTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TItem
KTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TItemArray
IEqualityComparer<System.Word>
Generics.Defaults
#TCollectionNotifyEvent<System.Word>
?TCollectionNotifyEvent<DateUtils.TLocalTimeZone.TYearlyChanges>
TArray<System.Word>
TEnumerator<System.Word>(
TEnumerator<System.Word>
TEnumerable<System.Word>-
TEnumerable<System.Word>$
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyEnumerator;
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyEnumeratorT
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyCollection;
OTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TKeyCollectionP
/TArray<DateUtils.TLocalTimeZone.TYearlyChanges>
4TEnumerator<DateUtils.TLocalTimeZone.TYearlyChanges>(
4TEnumerator<DateUtils.TLocalTimeZone.TYearlyChanges>
4TEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>-
4TEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>$
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueEnumerator;
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueEnumerator
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueCollection;
QTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TValueCollection
PTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TPairEnumerator;
PTDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>.TPairEnumerator
FOnKeyNotify
FKeyCollection
@TDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>9
ContainsKey
@TDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
Keys
OnKeyNotify
FTObjectDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>M
FTObjectDictionary<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
e:{Generics.Collections}TList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.:1
OIComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
\TCollectionNotifyEvent<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
Item:TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>
QIEnumerable<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
WTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.TEnumerator5
WTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.TEnumerator
KTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>&
KTList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
,:{Generics.Collections}TList<System.Word>.:1
IComparer<System.Word>
IEnumerable<System.Word>
TList<System.Word>.TEnumerator5
TList<System.Word>.TEnumeratorP^E
TList<System.Word>&
TList<System.Word>
H:{Generics.Collections}TList<DateUtils.TLocalTimeZone.TYearlyChanges>.:1
2IComparer<DateUtils.TLocalTimeZone.TYearlyChanges>
4IEnumerable<DateUtils.TLocalTimeZone.TYearlyChanges>
:TList<DateUtils.TLocalTimeZone.TYearlyChanges>.TEnumerator5
:TList<DateUtils.TLocalTimeZone.TYearlyChanges>.TEnumeratordjE
.TList<DateUtils.TLocalTimeZone.TYearlyChanges>&
.TList<DateUtils.TLocalTimeZone.TYearlyChanges>,lE
QTComparison<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
OTComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>2
OTComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
e:{Generics.Collections}TList<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>.:3
TComparison<System.Word>
TComparer<System.Word>2
TComparer<System.Word>
,:{Generics.Collections}TList<System.Word>.:3
4TComparison<DateUtils.TLocalTimeZone.TYearlyChanges>
2TComparer<DateUtils.TLocalTimeZone.TYearlyChanges>2
2TComparer<DateUtils.TLocalTimeZone.TYearlyChanges>
H:{Generics.Collections}TList<DateUtils.TLocalTimeZone.TYearlyChanges>.:3
XTDelegatedComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>8
XTDelegatedComparer<DateUtils.TPair<System.Word,DateUtils.TLocalTimeZone.TYearlyChanges>>
TDelegatedComparer<System.Word>8
TDelegatedComparer<System.Word>
;TDelegatedComparer<DateUtils.TLocalTimeZone.TYearlyChanges>8
;TDelegatedComparer<DateUtils.TLocalTimeZone.TYearlyChanges>D
ServerKey
FSupportsLicensing
SupportsLicensing
Operator
EVariantBadIndexError
ENotSupportedException
ENotSupportedExceptionL
ENoMonitorSupportException
ENoMonitorSupportExceptionh
TArray<SysUtils.TLangRec>
csshiftjis
windows-936
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
windows-874
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
TArray<SysUtils.TUnitHashEntry>
etNoMonitorSupportException
biClrImportant
tagMSG
Windows
HKEY
thHeaderItemLeftPressed
tsArrowBtnLeftPressed
ttbThumbLeftPressed
lrMonoChrome
IsShortCut
FHelpKeyword
HelpKeywordd
FPasswordChar
PasswordChar
OnKeyDown
OnKeyPress
OnKeyUpd{N
ssHorizontal
TCustomButton.TButtonStyle
poPortrait
APort
Port
FAutoHotkeys
RethinkHotkeys
AutoHotkeysx
AutoHotkeys
EInvalidGraphicOperation
EInvalidGraphicOperation,AK
SupportsPartialTransparency
SupportsClipboardFormat
Monochrome
ssHotTrack
TWindowState
poProportional
fsShowing
FWindowState
FKeyPreview
WantChildKey
KeyPreview
WindowState
KeyPreview8dN
WindowState0
FBiDiKeyboard
FNonBiDiKeyboard
FEnumAllWindowsOnActivateHint
FOnActionExecute
Keyword
EnumAllWindowsOnActivateHint
BiDiKeyboard
NonBiDiKeyboard@
OnActionExecute
FProportional
Proportional@
sltURL
TCustomLinkLabel.TLinkAlignment
FURL
igoParentPassthrough
FAlwaysShowDragImages
AlwaysShowDragImages@
toFlickFallbackKeys
'TCustomGestureEngine.TGestureEngineFlag
(TCustomGestureEngine.TGestureEngineFlags
Supported
TKeyEvent
TKeyPressEvent
HelpKeywordD
FOnKeyDown
FOnKeyPress
FOnKeyUp
IsHintMsg
FNativeWheelSupport
FWheelSupportMessage
fKeyword
ImportPalette
ImportColorTable
ImportDIBColors
ImportColorMap
ExportPalette
rmWindows20
rmWindows256
rmWindowsGray
rmMonochrome
rmQuantizeWindows
TMonochromeLookup7
TMonochromeLookup
WebCaption\
WebText
TKeyValues *
TKeyValues
TKeyValuesData
std::vector<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> >
std::_Vector_val<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> >
TKeyValuesData *
TKeyValuesBlock *
std::vector<TKeyValuesData,std::allocator<TKeyValuesData> >
std::vector<TKeyValuesBlock *,std::allocator<TKeyValuesBlock *> > *
std::vector<TKeyValuesData,std::allocator<TKeyValuesData> > *
std::_Vector_val<TKeyValuesData,std::allocator<TKeyValuesData> >
TKeyValuesBlock
LeftPartButton
LeftPartButtonMouse
WriteKeyList
FPort
FPassword
URLDecode
URLEncode
Password
rsa_keygen
dsa_keygen
pub_key
priv_key
PEVP_PKEY
EVP_PKEY_union
EVP_PKEY
pkey
pkey_type
required_pkey_type
key_len
key_length
AUTHORITY_KEYID
keyid
PAUTHORITY_KEYID|kZ
X509_PUBKEY
public_key
PX509_PUBKEYtmZ
X509_CERT_AUX
PX509_CERT_AUX
cert_info
ex_nscert
get_cert_methods
cert_crl
ppem_password_cb
key_arg_length
key_arg
master_key_length
master_key
sess_cert
Ptlsext_ticket_key_cb!
cert_store
default_passwd_callback
default_passwd_callback_userdata
client_cert_cb
extra_certs
max_cert_list
cert
msg_callback
msg_callback_arg
client_cert_engine
tlsext_tick_key_name
tlsext_tick_hmac_key
tlsext_tick_aes_key
tlsext_ticket_key_cb
init_msg
read_key
write_key
key_material_length
key_material
tmp_cert_type
tmp_cert_length
tmp_cert_verify_md
tmp_cert_req
tmp_key_block_length
tmp_key_block
tmp_cert_request
msg_len
w_msg_hdr
r_msg_hdr
AMsg
sslvrfFailIfNoPeerCert
TCallbackExEvent
TPasswordEvent
TPasswordEventEx
VPassword
Certificate
fsRootCertFile
fsCertFile
fsKeyFile
RootCertFile
CertFile
KeyFile
LoadRootCert
LoadCert
KeyFileP
fPeerCert
PeerCert
fOnGetPassword
fOnGetPasswordEx
OnGetPassword\
OnGetPasswordEx
MakeFTPSvrPort
MakeFTPSvrPasv
EIdOSSLLoadingRootCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingCertErrorp4[
EIdOSSLLoadingKeyError
EIdOSSLLoadingKeyError(5[
fPassThrough
PassThrough@
FLastCmdResult
TIdTCPConnectionB
RaiseExceptionForLastCmdResult
SendCmd
SendCmdf
TIdTCPConnection
IdTCPConnection
LastCmdResult@
FBoundPort
FBoundPortMax
FBoundPortMin
TIdTCPClientCustom'
TIdTCPClientCustom
IdTCPClient
BoundPort
BoundPortMax
BoundPortMin
TIdTCPClient
%EIdSocksUDPNotSupportedBySOCKSVersion
saUsernamePassword
FUDPSocksAssociation
OpenUDP
RecvFromUDP
SendToUDP9
CloseUDP
Portp
FClientPortMin
FClientPortMax
FPeerPort
ClientPortMin
ClientPortMax
Port@
PeerPort
TIdIPAddressH
IPAsString
FDefaultPort
DefaultPortp
VMsgEnd
EIdPortRequired
EIdTCPConnectionError
EIdTCPConnectionErrorPg]
EIdObjectTypeNotSupported
"EIdTransparentProxyUDPNotSupported
SendToUDPm
IdStackWindows
TIdSocketListWindows4
TIdSocketListWindows
TIdStackWindowsg
VPort
WSGetServByPort
APortNumber
ReceiveMsg
WSTranslateSocketErrorMsg
SupportsIPv6
CheckIPVersionSupport
TIdStackWindows
EIdIPVersionUnsupported0
EIdIPVersionUnsupported
ReceiveMsg,
EIdCanNotBindPortInRange
EIdCanNotBindPortInRanged
EIdInvalidPortRangeD
EIdInvalidPortRange
ftpTransfer
ftpReady
ftpAborted
WMHTTP *
WMHTTP
WMHTTP0
TSQLTimeStamp
TSQLTimeStampOffset
TSQLTimeStampVariantType0
TSQLTimeStampVariantType
SqlTimSt
TSQLTimeStampOffsetVariantType0
TSQLTimeStampOffsetVariantType
TSQLTimeStampData6
ASQLTimeStamp
TSQLTimeStampData k_
TSQLTimeStampOffsetData6
ASQLTimeStampOffset
TSQLTimeStampOffsetDatadp_
%u8F3
C.Pj W
TApi.HttpGetText$17277$0$Intf
TApi.HttpGetText$17277$ActRec
log/send_report
ntdll.dll
\Capabilities\UrlAssociations
TC32Url
TC32Urls
Urls
LicenseUrl
ConfidentialUrl
$TDownstalHelper.LoadImg$17299$0$Intf
$TDownstalHelper.LoadImg$17299$ActRec
$TDownstalHelper.LoadImg$17299$ActRecp\a
7TDownstalHelper.DownloadAndInstallPartners$17304$0$Intf
_http
7TDownstalHelper.DownloadAndInstallPartners$17304$ActRec
7TDownstalHelper.DownloadAndInstallPartners$17304$ActRecP
cWM_VKEYTOITEM
cWM_SETHOTKEY
cWM_GETHOTKEY
cEM_SETPASSWORDCHAR
cEM_GETPASSWORDCHAR
cWM_KEYDOWN
cWM_KEYUP
cWM_SYSKEYDOWN
cWM_SYSKEYUP
cWM_KEYLAST
cWM_CTLCOLORMSGBOX
cCB_MSGMAX
cWM_IME_KEYDOWN
cWM_IME_KEYUP
cWM_HOTKEY
cWM_DDE_EXECUTE
PMsgDecoded
TMsgDecoded
TMsg
Cmsg
PTCKeyDown
TTCKEYDOWN
wVKey
TOnThreadExecute
TPenJoin
Join
G6_KeyPreview
TOnKey
TTabKey
TTabKeys
eoPassword
ScrollCmd
fOnKeyUp
fOnKeyDown
FOnREOverURL
FOnREURLClick
fPass2DefProc
fWndProcKeybd
fExMsgProc
fTBttCmd
fWindowState
fKeyPreviewCount
fREUrl
pszUrl
pszKeywords
pszMsgText
pszMsgTitle
fExecute
pszUrlJump1
pszUrlJump2
pszCurUrl
CmdLine
TWindowsVersion
TWindowsVersions
TGPPenLineJoin
LineJoinMiter
LineJoinBevel
LineJoinRound
LineJoinMiterClipped
PHTTPHeader
THTTPHeader4
HTTPVersion
PHTTPDownloadd
THTTPHdrRecvEvent
PHTTPDownload
THTTPProgressEvent
THTTPErrorEvent
THTTPDownloadEvent
KOLHTTPDownload
THTTPStatusEvent
THTTPDownload
HttpGetText$17238$0$Intf
HttpGetText$17238$ActRec
http:
PKeySendProcess
user32.dll
clCrt@
hXXp://corp.sputnik.ru/legal
hXXp://corp.sputnik.ru/browser/legal
hXXps://VVV.360totalsecurity.com/ru/privacy/
hXXps://VVV.360totalsecurity.com/ru/license/360-total-security/
SOFTWARE\GameModding.net
\toolbar.exe
SQLite
SOFTWARE\GameModding.net\
\VVV.GameModding.net mods\
FormKeyDown
GameModding.net
log\debug.log
\VVV.GameModding.net\
AUTOR_WEB
hXXp://VVV.gamemodding.net/
models\gta3.img
pc\models\cdimages\vehicles.img
VVV.GameModding.net\
VVV.GameModding.net\Uninstall
VVV.GameModding.net\Uninstall(
hXXp://log.gamemodding.net
lblWebCaption
lblWebText$
idHTTP
idHTTPFinish
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
GMMInstallMods.log
res_mods\0.8.4\text
res_mods\0.8.5\text
res_mods\0.8.6\text
res_mods\0.8.7\text
res_mods\0.8.8\text
res_mods\0.8.9\text
res_mods\0.9.0\text
res_mods\0.9.1\text
res_mods\0.9.2\text
res_mods\0.9.3\text
res_mods\0.9.4\text
res_mods\0.9.5\text
res_mods\0.8.10\text
data.config
readme.txt
VVV.GameModding.net.url
hXXp://VVV.GameModding.net/
GAME_EXE_NAME
Data.cfg
data.cfg
cleo\skin.img
config.ini
skin.png
skin.json
.xpfl
label.gm
%dir%
gmm.dff
vgs_palm%d
tree%d
gtatreeshi%d
radar%d
ce_ground%d
ce_lod_%d
ce_bankalley%d
melrose%d
sw_block%d
vgnretail%d
gta3.img
gmm.lbl
SEARCH_KEY1
SEARCH_KEY
cstrike\gameinfo.txt
\Fallout4\plugins.txt
Data.Path =
Data.DataSize =
\SOFTWARE\GameModding.net
\SOFTWARE\GameModding.net\
config.data
config.cfg
Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0; .NET CLR 1.0.2914)
xxtype.cpp
derv->tpClass.tpcFlags & CF_HAS_BASES
Inappropriate I/O control operation
Broken pipe
Operation not permitted
%H:%M:%S
%m/%d/%y
%A, %B %d, %Y
d/d/d d:d:d.d
kernel32.dll
xx.cpp
varType->tpClass.tpcFlags & CF_HAS_DTOR
varType->tpClass.tpcDtorAddr
(vbFlag && (errPtr->ERRcInitDtc >= varType->tpClass.tpcDtorCount)) || (!vbFlag && (errPtr->ERRcInitDtc >= varType->tpClass.tpcNVdtCount)) || flags
memType->tpClass.tpcFlags & CF_HAS_DTOR
varType->tpArr.tpaElemType->tpClass.tpcFlags & CF_HAS_DTOR
dttPtr->dttType->tpPtr.tppBaseType->tpClass.tpcFlags & CF_HAS_DTOR
IS_CLASS(dttPtr->dttType->tpMask) && (dttPtr->dttType->tpClass.tpcFlags & CF_HAS_DTOR)
elemType->tpClass.tpcFlags & CF_HAS_DTOR
_noParam.VType == VT_ERROR
variant.cpp
_empty.VType == varEmpty
VType == rhs.VType
C:\Builds\TP\include\windows\rtl\utilcls.h
Parms.VType == (VT_ARRAY|VT_VARIANT)
ParmTypes.VType == (VT_ARRAY|VT_I4)
?456789:;<=
!"#$%&'()* ,-./0123
{"generator":"MediaMagnet", "values":{ "targetname":"\u0424\u043e\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438 \u043a\u043e\u0442\u0438\u043a\u043e\u0432", "place_domain":"domain.ru", "MediaMagnetLicUrl":"hXXps://coin32.com/MediaMagnet.html", "MediaMagnetConfUrl":"", }, "targeturl":"hXXp://fastloadmedia.ru/libs/test/kotiki.zip", "api_url":["hXXp://medialogger.ru/api/v3.1.0/"], "resource_url":"hXXp://downloadcloud.ru", "api_key":"^3e86f9e990fb82f58e181887c75e4d466107fa1a647681e6c17dd3260973dae2", "place_id":"1", "site_id":"1", "referrer":"hXXp://referer.url/", "timestamp" : 1433370034, "embedded_data" : { }, "download_plugins":{ "narod": "hXXp://fastloadmedia.ru/libs/modules/narod.bin", "torrent": "hXXp://fastloadmedia.ru/libs/modules/torrent.bin", "yadisk":"hXXp://fastloadmedia.ru/libs/modules/yadisk.bin" }, "adv_ti":{ "regSoftwareAmigo": "HKCU\\Software\\Amigo", "regAmigoInstaller": "HKCU\\Software\\Mail.Ru\\AmigoInstaller", "regSoftwareMailUninstall": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\MailRuUpdater", "regSoftwareYandex": "HKCU\\Software\\Yandex", "regSoftwareYandexBrowser": "HKCU\\Software\\Yandex\\YandexBrowser", "regSoftwareRambler": "HKCU\\Software\\Rambler", "regSoftwareRamblerUpdate": "HKCU\\Software\\Rambler\\Update", "dirAmigoPathExists": "{localappdata}Amigo\\", "dirMailPathExists": "{localappdata}Mail.Ru\\", "dirMailSputnikPathExists": "{localappdata}Mail.Ru\\Sputnik\\", "dirYandexPathExists": "{localappdata}Yandex\\", "dirYandexBrowserPathExists": "{localappdata}Yandex\\YandexBrowser\\", "dirYandexUpdaterPathExists": "{localappdata}Yandex\\Updater\\", "dirRamblerPathExists": "{localappdata}Rambler\\", "dirRamblerUpdaterPathExists": "{localappdata}Rambler\\RamblerUpdater\\", "dirZaxarPathExists": "{programfiles(x86)}Zaxar\\", "fileAmigoFileExists": "{localappdata}Amigo\\Application\\amigo.exe", "fileMailRuUpdater": "{localappdata}Mail.Ru\\MailRuUpdater.exe", "fileSputnikMailRuIco": "{localappdata}Mail.Ru\\Sputnik\\MailRu.ico", "fileYandexClidsBarie": "{appdata}Yandex\\clids-barie.xml", "fileYandexBrowser": "{localappdata}Yandex\\YandexBrowser\\Application\\browser.exe", "fileZaxarFileExists": "{programfiles(x86)}Zaxar\\ZaxarGameBrowser.exe" }, "logging": true}
AKv.AKv
KERNEL32.DLL
USER32.DLL
WINDOWSCODECS.DLL
DWMAPI.DLL
UXTHEME.DLL
SHELL32.DLL
gta.exe
@$xp$10Kol@TOnKey
@$xp$11Kol@TTabKey
@$xp$12Kol@TPenJoin
@$xp$12Kol@TTabKeys
@$xp$14Kol@PTCKeyDown
@$xp$14Kol@TTCKEYDOWN
@$xp$15Kol@PMsgDecoded
@$xp$15Kol@TMsgDecoded
@$xp$16Kol@TWindowState
@$xp$19C32lib_main@TC32Url
@$xp$19Kol@TWindowsVersion
@$xp$20C32lib_main@TC32Urls
@$xp$20Kol@TOnThreadExecute
@$xp$20Kol@TWindowsVersions
@$xp$21Utils@PKeySendProcess
@$xp$24Kolgdipv2@TGPPenLineJoin
@$xp$25Kolhttpdownload@TSpecials
@$xp$27Kolhttpdownload@PHTTPHeader
@$xp$27Kolhttpdownload@THTTPHeader
@$xp$29Kolhttpdownload@PHTTPDownload
@$xp$29Kolhttpdownload@THTTPDownload
@$xp$30Kolhttpdownload@TEventHandlers
@$xp$31Kolhttpdownload@PDownloadWorker
@$xp$31Kolhttpdownload@TDownloadWorker
@$xp$31Kolhttpdownload@THTTPErrorEvent
@$xp$32Kolhttpdownload@PREQUEST_CONTEXT
@$xp$32Kolhttpdownload@THTTPStatusEvent
@$xp$32Kolhttpdownload@TREQUEST_CONTEXT
@$xp$33Kolhttpdownload@THTTPHdrRecvEvent
@$xp$34Kolhttpdownload@THTTPDownloadEvent
@$xp$34Kolhttpdownload@THTTPProgressEvent
@$xp$8Kol@TMsg
@@Wmhttp@Finalize
@@Wmhttp@Initialize
@Admutil@IsWindowsAdministrator$qqrv
@Apicontroller@TApi@GetKey$qqrv
@Apicontroller@TApi@HttpGetText$qqrx20System@UnicodeStringp12Kol@TStrList20System@UnicodeStringt3
@Apicontroller@TApi@send_report$qqr20System@UnicodeString
@Browserdetect@OpenURL$qqr20System@UnicodeString
@Comobj@GetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatchSystem@WideString
@Comobj@GetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatch%i
@Comobj@SetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatchSystem@WideStringrx17System@OleVariant
@Comobj@SetDispatchPropValue$qqr36System@ÞlphiInterface$t9IDispatch%irx17System@OleVariant
@Comobj@TComObject@$bctr$qqrp17TComObjectFactoryx45System@ÞlphiInterface$t17System@IInterface%
@Downstalhelper@TDownstalHelper@OnDownloadError$qqrp29Kolhttpdownload@THTTPDownloadus
@Downstalhelper@TDownstalHelper@OnDownloadTargetProgress$qqrp29Kolhttpdownload@THTTPDownloadiiii
@Downstalhelper@TDownstalHelper@OnHeaderReceived$qqrp29Kolhttpdownload@THTTPDownloadp12Kol@TStrList
@Downstalhelper@TDownstalHelper@OnHttpProgress$qqrp29Kolhttpdownload@THTTPDownloadiiii
@Downstalhelper@TDownstalHelper@OnStatusEvent$qqrp29Kolhttpdownload@THTTPDownloadpvuiuit2ui
@Kol@AutoMinimizeApplet$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@CharIn$qqrbrx29System@%Set$tc$iuc$0$iuc$255%
@Kol@DummyOnDrawItemProc$qqrpvp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%
@Kol@DummyOnLVCustomDrawProc$qqrpvp12Kol@TControlp5HDC__uiiirx11Types@TRect44System@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%rit9
@Kol@ExePath$qqrv
@Kol@ExecuteConsoleAppIORedirect$qqrx20System@UnicodeStringt1t1uit1r20System@UnicodeStringui
@Kol@ExecuteIORedirect$qqrx20System@UnicodeStringt1t1uipuit5t5t5
@Kol@ExecuteWait$qqrx20System@UnicodeStringt1t1uiuipui
@Kol@FormSetIndexedEvent$qqrp12Kol@TControl
@Kol@FormSetKeyPreviewTrue$qqrp12Kol@TControl
@Kol@FormSetWindowState$qqrp12Kol@TControl
@Kol@GetWindowsDir$qqrv
@Kol@IsWinVer$qqr47System@%Set$t19Kol@TWindowsVersion$iuc$0$iuc$9%
@Kol@MsgBox$qqrx20System@UnicodeStringui
@Kol@MsgOK$qqrx20System@UnicodeString
@Kol@NewBitBtn$qqrp12Kol@TControlx20System@UnicodeString45System@%Set$t17Kol@TBitBtnOption$iuc$0$iuc$4Kol@TGlyphLayoutp9HBITMAP__i
@Kol@NewCombobox$qqrp12Kol@TControl45System@%Set$t16Kol@TComboOption$iuc$0$iuc$10%
@Kol@NewDateTimePicker$qqrp12Kol@TControl53System@%Set$t25Kol@TDateTimePickerOption$iuc$0$iuc$5%
@Kol@NewEditbox$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewGraphEditbox$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewListView$qqrp12Kol@TControl18Kol@TListViewStyle48System@%Set$t19Kol@TListViewOption$iuc$0$iuc$25%p14Kol@TImageListt4t4
@Kol@NewListbox$qqrp12Kol@TControl44System@%Set$t15Kol@TListOption$iuc$0$iuc$12%
@Kol@NewOpenDirDialog$qqrx20System@UnicodeString46System@%Set$t18Kol@TOpenDirOption$iuc$0$iuc$8%
@Kol@NewOpenSaveDialog$qqrx20System@UnicodeStringt148System@%Set$t19Kol@TOpenSaveOption$iuc$0$iuc$14%
@Kol@NewProgressbarEx$qqrp12Kol@TControl50System@%Set$t22Kol@TProgressbarOption$iuc$0$iuc$1%
@Kol@NewRichEdit$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewRichEdit1$qqrp12Kol@TControl44System@%Set$t15Kol@TEditOption$iuc$0$iuc$11%
@Kol@NewScrollBox$qqrp12Kol@TControl14Kol@TEdgeStyle44System@%Set$t16Kol@TScrollerBar$iuc$0$iuc$1%
@Kol@NewTabControl$qqrp12Kol@TControlpxpbxi50System@%Set$t21Kol@TTabControlOption$iuc$0$iuc$14%p14Kol@TImageListi
@Kol@NewTabEmpty$qqrp12Kol@TControl50System@%Set$t21Kol@TTabControlOption$iuc$0$iuc$14%p14Kol@TImageList
@Kol@NewToolbar$qqrp12Kol@TControl17Kol@TControlAlign46System@%Set$t18Kol@TToolbarOption$iuc$0$iuc$7%p9HBITMAP__pxpbxipxixi
@Kol@NewTreeView$qqrp12Kol@TControl48System@%Set$t19Kol@TTreeViewOption$iuc$0$iuc$13%p14Kol@TImageListt3
@Kol@RegKeyClose$qqrp6HKEY__
@Kol@RegKeyDelete$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyDeleteValue$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyExists$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetBinary$qqrp6HKEY__x20System@UnicodeStringpvi
@Kol@RegKeyGetDateTime$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetDw$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetStr$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetStrEx$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyGetSubKeys$qqrxp6HKEY__p13Kol@TWStrList
@Kol@RegKeyGetValueNames$qqrxp6HKEY__p13Kol@TWStrList
@Kol@RegKeyGetValueTyp$qqrxp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenCreate$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenRead$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyOpenWrite$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeySetBinary$qqrp6HKEY__x20System@UnicodeStringpxvi
@Kol@RegKeySetDateTime$qqrp6HKEY__x20System@UnicodeString16System@TDateTime
@Kol@RegKeySetDw$qqrp6HKEY__x20System@UnicodeStringui
@Kol@RegKeySetStr$qqrp6HKEY__x20System@UnicodeStringt2
@Kol@RegKeySetStrEx$qqrp6HKEY__x20System@UnicodeStringt2o
@Kol@RegKeyValExists$qqrp6HKEY__x20System@UnicodeString
@Kol@RegKeyValueSize$qqrp6HKEY__x20System@UnicodeString
@Kol@ShowMsg$qqrx20System@UnicodeStringui
@Kol@StrIn$qqrx27System@%AnsiStringT$us$i0$%px27System@%AnsiStringT$us$i0$%xi
@Kol@StrIs$qqrx27System@%AnsiStringT$us$i0$%px27System@%AnsiStringT$us$i0$%xiri
@Kol@SupportAnsiMnemonics$qqri
@Kol@SystemTime2Str$qqrrx11_SYSTEMTIMExuix47System@%Set$t19Kol@TTimeFormatFlag$iuc$0$iuc$3%pxb
@Kol@TColorDialog@Execute$qqrv
@Kol@TControl@AttachProc$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@AttachProcEx$qqrpqqrp12Kol@TControlr8Kol@TMsgri$oo
@Kol@TControl@CallDefWndProc$qqrr8Kol@TMsg
@Kol@TControl@CreateChildWindows$qqrv
@Kol@TControl@DefaultBtnProc$qqrr8Kol@TMsgri
@Kol@TControl@DetachProc$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@FormCreateParameters$qqrp65System@%StaticArray$pqqrp12Kol@TControl$p12Kol@TControli$i65536$%pc
@Kol@TControl@FormExecuteCommands$qqrp12Kol@TControlp31System@%StaticArray$si$i65536$%
@Kol@TControl@GetKeyPreview$qqrv
@Kol@TControl@GetWindowState$qqrv
@Kol@TControl@Get_OnKeyDown$qqrv
@Kol@TControl@Get_OnKeyUp$qqrv
@Kol@TControl@GraphButtonKeyboardProcess$qqrr8Kol@TMsgri
@Kol@TControl@GraphicButtonMouse$qqrr8Kol@TMsg
@Kol@TControl@GraphicCheckBoxMouse$qqrr8Kol@TMsg
@Kol@TControl@GraphicEditMouse$qqrr8Kol@TMsg
@Kol@TControl@IsProcAttached$qqrpqqrp12Kol@TControlr8Kol@TMsgri$o
@Kol@TControl@LVAdd$qqrx20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVInsert$qqrix20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVSetItem$qqriix20System@UnicodeStringi51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%iiui
@Kol@TControl@LVSetItemState$qqrix51System@%Set$t23Kol@TListViewItemStates$iuc$0$iuc$3%
@Kol@TControl@Postmsg$qqsuiii
@Kol@TControl@REGetAutoURLDetect$qqrv
@Kol@TControl@REGetOnURL$qqrxi
@Kol@TControl@REGetTextSize$qqr46System@%Set$t18Kol@TRichTextSizes$iuc$0$iuc$3%
@Kol@TControl@RESetAutoURLDetect$qqrxo
@Kol@TControl@RESetOnURL$qqrxixynpqqrp8Kol@TObj$v
@Kol@TControl@SetKeyPreview$qqrxo
@Kol@TControl@SetLVOptions$qqrx48System@%Set$t19Kol@TListViewOption$iuc$0$iuc$25%
@Kol@TControl@SetOnDrawItem$qqrxynpqqrp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%$o
@Kol@TControl@SetOnKeyDown$qqrxynpqqrp12Kol@TControlriui$v
@Kol@TControl@SetOnKeyUp$qqrxynpqqrp12Kol@TControlriui$v
@Kol@TControl@SetOnLVCustomDraw$qqrxynpqqrp12Kol@TControlp5HDC__uiiirx11Types@TRect44System@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%rit8$ui
@Kol@TControl@SetOnRE_OverURL$qqrxynpqqrp8Kol@TObj$v
@Kol@TControl@SetOnRE_URLClick$qqrxynpqqrp8Kol@TObj$v
@Kol@TControl@SetWindowState$qqr16Kol@TWindowState
@Kol@TControl@Set_OnMessage$qqrxynpqqrr8Kol@TMsgri$o
@Kol@TControl@SupportMnemonics$qqrv
@Kol@TControl@WndProc$qqrr8Kol@TMsg
@Kol@TGraphicTool@GetPenJoin$qqrv
@Kol@TGraphicTool@SetFontStyle$qqrx43System@%Set$t15Kol@TFontStyles$iuc$0$iuc$3%
@Kol@TGraphicTool@SetPenJoin$qqrx12Kol@TPenJoin
@Kol@TIcon@LoadFromExecutable$qqrx20System@UnicodeStringi
@Kol@TIniFile@ClearKey$qqrx20System@UnicodeString
@Kol@TMenu@AddItem$qqrpbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@Insert$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@InsertItem$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%
@Kol@TMenu@InsertItemEx$qqripbynpqqrp9Kol@TMenui$v43System@%Set$t15Kol@TMenuOption$iuc$0$iuc$9%o
@Kol@TMenu@SetOnDrawItem$qqrxynpqqrp8Kol@TObjp5HDC__rx11Types@TRecti44System@%Set$t16Kol@TDrawActions$iuc$0$iuc$2DSystem@%Set$t15Kol@TDrawStates$iuc$0$iuc$14%$o
@Kol@TOpenDirDialog@Execute$qqrv
@Kol@TOpenSaveDialog@Execute$qqrv
@Kol@TStrList@Join$qqrx27System@%AnsiStringT$us$i0$%
@Kol@TStrListEx@AddObject$qqrx27System@%AnsiStringT$us$i0$%ui
@Kol@TStrListEx@InsertObject$qqrix27System@%AnsiStringT$us$i0$%ui
@Kol@TThread@Execute$qqrv
@Kol@TerminateExecution$qqrrp12Kol@TControl
@Kol@ToolbarsIDcmd
@Kol@WindowsLogoff$qqro
@Kol@WindowsShutdown$qqrx20System@UnicodeStringoo
@Kol@WndProcAppAsm$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcCtrl$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcDoEraseBkgnd$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcDummy$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcKeybd$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcMenu$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcMouse$qqrp12Kol@TControlr8Kol@TMsgri
@Kol@WndProcUnicodeChars$qqrp12Kol@TControlr8Kol@TMsgri
@Kolgdipv2@GdiplusShutdown
@Kolgdipv2@NewGPFont$qqrix20System@UnicodeString43System@%Set$t15Kol@TFontStyles$iuc$0$iuc$3%
@Kolgdipv2@NewGPImageS$qqrx34System@ÞlphiInterface$t7IStream%o
@Kolgdipv2@NewGPStringFormat$qqr62System@%Set$t33Kolgdipv2@TGPStringFormatBitFlags$iuc$0$iuc$14%
@Kolgdipv2@SaveGPImageS$qqrpx18Kolgdipv2@TGPImagex34System@ÞlphiInterface$t7IStream%x29Kolgdipv2@TGdiPlusImageFormat
@Kolgdipv2@TGPImageAttributes@SetColorKey$qqrpxuixi31Kolgdipv2@TGPColorRemapCategory
@Kolgdipv2@TGPPen@GetLineJoin$qqrv
@Kolgdipv2@TGPPen@SetLineJoin$qqr24Kolgdipv2@TGPPenLineJoin
@Kolgdipv2@TGPStringFormat@SetFormatFlags$qqr62System@%Set$t33Kolgdipv2@TGPStringFormatBitFlags$iuc$0$iuc$14%
@Kolgdipv2@TKOLStreamAdapter@Clone$qqsr34System@ÞlphiInterface$t7IStream%
@Kolgdipv2@TKOLStreamAdapter@CopyTo$qqs34System@ÞlphiInterface$t7IStream%jrjt3
@Kolhttpdownload@DecodeURL$qqrx27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@EncodeURI$qqrx20System@UnicodeString
@Kolhttpdownload@EncodeURL$qqrx20System@UnicodeString
@Kolhttpdownload@EvHandler
@Kolhttpdownload@FileSpecialChar
@Kolhttpdownload@Finalization$qqrv
@Kolhttpdownload@GetMimeTypeExtension$qqr20System@UnicodeString
@Kolhttpdownload@GetMimeTypeFromData$qqr20System@UnicodeStringp11Kol@TStream
@Kolhttpdownload@GetURLFileName$qqrp29Kolhttpdownload@THTTPDownload20System@UnicodeStringt2
@Kolhttpdownload@GetWinInetError$qqrui
@Kolhttpdownload@HttpGetText$qqrpx29Kolhttpdownload@THTTPDownloadx20System@UnicodeStringp12Kol@TStrList20System@UnicodeString27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@HttpGetText$qqrx20System@UnicodeStringp12Kol@TStrList20System@UnicodeString27System@%AnsiStringT$us$i0$%
@Kolhttpdownload@Internet_Options
@Kolhttpdownload@NewDownloadWorker$qqrp29Kolhttpdownload@THTTPDownload
@Kolhttpdownload@NewHTTPDownload$qqrv
@Kolhttpdownload@ParseURL$qqrx20System@UnicodeStringr20System@UnicodeStringt2t2t2t2t2
@Kolhttpdownload@TDownloadWorker@
@Kolhttpdownload@TDownloadWorker@$bdtr$qqrv
@Kolhttpdownload@TDownloadWorker@On_DownloadExecute$qqrp11Kol@TThread
@Kolhttpdownload@TDownloadWorker@On_UpdateProgress$qqrv
@Kolhttpdownload@TDownloadWorker@On_WatchExecute$qqrp11Kol@TThread
@Kolhttpdownload@TDownloadWorker@StartDownload$qqrv
@Kolhttpdownload@TDownloadWorker@StopDownload$qqrv
@Kolhttpdownload@TEventHandlers@
@Kolhttpdownload@TEventHandlers@onDownload$qqrp29Kolhttpdownload@THTTPDownloadp11Kol@TStream
@Kolhttpdownload@TEventHandlers@onError$qqrp29Kolhttpdownload@THTTPDownloadus
@Kolhttpdownload@THTTPDownload@
@Kolhttpdownload@THTTPDownload@$bdtr$qqrv
@Kolhttpdownload@THTTPDownload@CancelDownload$qqrv
@Kolhttpdownload@THTTPDownload@CheckConnection$qqr20System@UnicodeString
@Kolhttpdownload@THTTPDownload@FormField$qqr20System@UnicodeStringt1
@Kolhttpdownload@THTTPDownload@FormFieldsClear$qqrv
@Kolhttpdownload@THTTPDownload@GetResource$qqr20System@UnicodeString
@Kolhttpdownload@THTTPDownload@ParseHeaders$qqrrp27Kolhttpdownload@THTTPHeader
@Kolhttpdownload@THTTPDownload@SetAuthInfo$qqr20System@UnicodeStringt1
@Kolhttpdownload@THTTPDownload@SetCustomHeaders$qqrp12Kol@TStrList
@Kolhttpdownload@THTTPDownload@SetDataStream$qqrp11Kol@TStream
@Kolhttpdownload@THTTPDownload@SetProxySettings$qqr20System@UnicodeStringi
@Kolhttpdownload@THTTPDownload@fOnErrorCall$qqrp29Kolhttpdownload@THTTPDownloadp11Kol@TThreadus
@Kolhttpdownload@URISpecialChar
@Kolhttpdownload@URLSpecialChar
@Kolhttpdownload@WaitUntilTrue$qqroi
@Kolhttpdownload@initialization$qqrv
@Spstdctrls@TSPCustomLabel@CMDialogChar$qqrr15Messages@TWMKey
@Spstdctrls@TSPCustomLabel@Notification$qqrp18Classes@TComponent18Classes@TOperation
@TSPImageScroll@GetProportionall$qp17Graphics@TPicturei
@TSPImageScroll@MouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TSPImageScroll@MouseMove$qqrp14System@TObject46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TSPImageScroll@MouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@TWMActionGTASettings@GetKeyCount$q20System@UnicodeStringt1
@TWMCustomHeaderData@rlblWebC$qqrv
@TWMCustomHeaderData@rlblWebT$qqrv
@TWMCustomHeaderData@wlblWebC$qqrp15Stdctrls@TLabel
@TWMCustomHeaderData@wlblWebT$qqrp15Stdctrls@TLabel
@TWMDialogReplaseModel@Execute$qqrv
@TWMDownloader@SetURL$qqr20System@UnicodeString
@TWMSkinManager@SetRect$q31System@%AnsiStringT$us$i65001$System@Variant
@Tspadvancedinifiles@TSPCustomIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPMemIniFile@DeleteKey$qqrx20System@UnicodeStringt1
@Tspadvancedinifiles@TSPMemIniFile@WriteKeyList$qqrx20System@UnicodeStringp16Classes@TStrings
@Utils@ExecWin$qqr20System@UnicodeStringt1t1oi
@Utils@KeySendProcess
@Utils@MsgBox2$qqrx20System@UnicodeStringuii20System@UnicodeString
@Utils@TClassObj@senderkeynder$qqrv
@Utils@isShiftDown$qqrv
@WTSPCheckBox@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPCheckSlider@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPImageButton@myMouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPImageButton@myMouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPLabelButton@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPLabelButton@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPPageGraphicControl@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPPageGraphicControl@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseDown$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseMove$qqr46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPSlider@MouseUp$qqr21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@MouseDown$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@MouseUp$qqrp14System@TObject21Controls@TMouseButton46System@%Set$t18Classes@Classes__1$iuc$0$iuc$8%ii
@WTSPStechButton@rLeftPartButton$qqrv
@WTSPStechButton@rLeftPartButtonMouse$qqrv
@WTSPStechButton@wLeftPartButton$qqrp17Graphics@TPicture
@WTSPStechButton@wLeftPartButtonMouse$qqrp17Graphics@TPicture
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
Picture.Data
"iTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:9610CCF6377911E5AC72A378DCF3C356" xmpMM:DocumentID="xmp.did:9610CCF7377911E5AC72A378DCF3C356"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:9610CCF4377911E5AC72A378DCF3C356" stRef:documentID="xmp.did:9610CCF5377911E5AC72A378DCF3C356"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>Utw
.ffP F
kEY{V
(.qA/
%U`5H
`.sg:ON
`.ÿ/
Proportional
Font.Pitch
Font.Quality
LeftPartButton.Data
CenterPartButton.Data
RightPartButton.Data
LeftPartButtonMouse.Data
RightPartButtonMouse.Data
CenterPartButtonMouse.Data
sputnik.ru
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:E6B0FA2B377211E5A78FE9305C68A7CE" xmpMM:DocumentID="xmp.did:E6B0FA2C377211E5A78FE9305C68A7CE"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:E6B0FA29377211E5A78FE9305C68A7CE" stRef:documentID="xmp.did:E6B0FA2A377211E5A78FE9305C68A7CE"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>[>
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:29ED0095377A11E5BC2792A256311590" xmpMM:DocumentID="xmp.did:29ED0096377A11E5BC2792A256311590"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:29ED0093377A11E5BC2792A256311590" stRef:documentID="xmp.did:29ED0094377A11E5BC2792A256311590"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
fiTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:F808BFF21198E511B58D893E85EBF264" xmpMM:DocumentID="xmp.did:02FC136F981211E5A24BC905F2B92D35" xmpMM:InstanceID="xmp.iid:02FC136E981211E5A24BC905F2B92D35" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:F908BFF21198E511B58D893E85EBF264" stRef:documentID="xmp.did:F808BFF21198E511B58D893E85EBF264"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
keq.eXd
%F`:V1
S3~%fP
U.LmwV1
 hXXp://ns.adobe.com/xap/1.0/
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:1379A282F81711E59F3C9295ECA48D7A" xmpMM:DocumentID="xmp.did:1379A283F81711E59F3C9295ECA48D7A"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:1379A280F81711E59F3C9295ECA48D7A" stRef:documentID="xmp.did:1379A281F81711E59F3C9295ECA48D7A"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
.ikJOt2
3Y.YR
.Ex-S[
worldofmods.com
BackgroundImage.Data
lblWebCaption
lblWebText
VVV.gamemodding.net
CaptionList.Strings
Diese Modifikation ist nicht von Moderatoren der Website GameModding.net durchgepruft. Sicherheit und Leistungsfahigkeit der Modifikationen kann nicht garantiert werden!
Margins.Left
Margins.Top
Margins.Right
Margins.Bottom
Font.Orientation
LangList.Strings
?5=This modification was downloaded from GameModding.net website
11=hXXp://vk.com/gamemoddingnet
&12=hXXps://twitter.com/GameModdingNet
'13=hXXp://VVV.facebook.com/gamemodding
114=hXXp://VVV.youtube.com/user/GameModdingPreview
GameModding.net
214=hXXp://VVV.youtube.com/user/GameModdingPreview
G5=Cette modification a ete telewchar_tge depuis le site GameModding.net
J5=Diese Modifikation wurde von der Website GameModding.net heruntergeladen
fd:\SteamLibrary\steamapps\common\Grand Theft Auto V\_CommonRedist\176633-2014-mclaren-p1-v2.6-gtav.exe
LanguageList.Strings
GameModding.net
GameModding.net
GameModding.net.
VVV.GameModding.net
LangImage.Data
3=Web Site to Autor:
WebCaption
"8=Add GameModding.net to Favorites
19=Place a GameModding.net shortcut on the desktop
17=This modification is not checked by GameModding.net moderators. Usability and safety of the modification cannot be guaranteed!
"All Programs" in VVV.GameModding.net folder
C37=Visit us again! We will be glad to see you again on our website!
*8=GameModding.net zu Favoriten hinzufuegen
59=GameModding.net Verknuepfung auf dem desktop setzen
17= Diese Modifikation ist nicht von Moderatoren der Website GameModding.net durchgepruft. Sicherheit und Leistungsfahigkeit der Modifikationen kann nicht garantiert werden!
"Alle Programme"- im Ordner VVV.GameModding.net
n37=Kommen Sie und sehen uns wieder! Wir hoffen Sie kommen uns bald einmal auf unserer Website wieder besuchen.
/8=Ajouter worldofmods.com dans le marque-pages
49=Envoyer le raccourci sur le bureau worldofmods.com
rateur du site GameModding.net. La s
\5=hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-cleo-scripts/8940-skin-selector-v21.html
frmRPM.WTSPPageGraphicControl1
W1=With the IMGTool 1.3 program import files from the folder %dir% into the archive -
o4=You can download IMGTool 1.3 hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
6=Import into IMG
(7=Importing files into the game archive:
,12=Unable to complete import in IMG archive!
15=Importing file Into IMG:
17=To import to
B18=Files from the folder %dir% to be imported into the archive -
%dir%
: hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
%dir%
d1=Mit dem Programm IMGTool 1.3 importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
}4=Die Download-Link fuer IMGTool 1.3 ist hier: hXXp://VVV.gamemodding.net/gta-vice-city/gta-vc-programms/830-img-tool-13.html
6=Import in IMG
.7=Importieren von Dateien in das Spiel-Archiv:
B12=Der Import in das IMG Archiv kann nicht vervollstandigt werden!
15=Importieren Datei in IMG:
316=Beim Import der Datei ist ein Fehler aufgetreten
17=Import in
.18=Dateien aus dem Ordner %dir% in das Archiv
k1=With the IMGTool 2.0 or Crazy IMG Editor program import files from the folder %dir% into the archive -
t4=You can download IMGTool 2.0 here: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
5=Crazy IMG Editor here: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
]17=hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-cleo-scripts/8940-skin-selector-v21.html
19=Importing file Into IMG:
21=To import to
B22=Files from the folder %dir% to be imported into the archive -
: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
z1=Mit dem Programm IMGTool 2.0 oder Crazy IMG Editor importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
~4=Die Download-Link fuer IMGTool 2.0 ist hier: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/829-imgtool-20.html
~5=Crazy IMG Editor hier: hXXp://VVV.gamemodding.net/gta-san-andreas/gta-sa-programms/828-gta-san-andreas-crazy-img-editor.html
19=Importieren Datei in IMG:
620=Beim Import der Datei ist ein Fehler aufgetreten:
21=Import in
.22=Dateien aus dem Ordner %dir% in das Archiv
^1=With the SparkIV or OpenIV program import files from the folder %dir% into the archive -
!3=to be imported into the archive
^4=You can download SparkIV hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
S5=Crazy OpenIV: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
(12=Unable to complete import in archive!
16=Importing file Into IMG:
17=Importing file Into RPF:
19=To import to
B20=Files from the folder %dir% to be imported into the archive -
: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
n1=Mit dem Programm SparkIV oder OpenIV importieren Sie Dateien aus dem Ordner %dir% Datei(en) in das Archiv
o4=Die Download-Link fuer SparkIV ist hier: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/832-sparkiv.html
R5=OpenIV hier: hXXp://VVV.gamemodding.net/gta-iv/gta-iv-programms/831-openiv.html
12=Der Import in das Archiv kann nicht vervollst
16=Importieren Datei in IMG:
17=Importieren Datei in RPF:
618=Beim Import der Datei ist ein Fehler aufgetreten:
19=Import in
.20=Dateien aus dem Ordner %dir% in das Archiv
#1=Replacement options for transport
)1=Replacement-Optionen fuer den Transport
DefaultPort
SSLOptions.Mode
SSLOptions.VerifyMode
SSLOptions.VerifyDepth
LabelFontDisable.Charset
LabelFontDisable.Color
LabelFontDisable.Height
LabelFontDisable.Name
LabelFontDisable.Style
PictureLabel.Data
FontLabels.Charset
FontLabels.Color
FontLabels.Height
FontLabels.Name
FontLabels.Style
Langs.Strings
SkinImage.Data
Paint.NET v3.22
%5UUUM
$A{.fR
CreatePipe
GetCPInfo
GetCPInfoExW
GetProcessHeap
GetWindowsDirectoryW
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegEnumKeyExW
RegFlushKey
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegReplaceKeyW
RegRestoreKeyW
RegSaveKeyW
RegUnLoadKeyW
SetViewportOrgEx
GdipSetPenLineJoin
GdipSetImageAttributesColorKeys
GdipGetPenLineJoin
SHFileOperationW
ShellExecuteA
ShellExecuteExW
ShellExecuteW
ActivateKeyboardLayout
EnumChildWindows
EnumThreadWindows
EnumWindows
ExitWindowsEx
GetAsyncKeyState
GetKeyNameTextW
GetKeyState
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayoutNameW
GetKeyboardState
LoadKeyboardLayoutW
MapVirtualKeyW
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
SetWindowsHookExW
UnhookWindowsHookEx
VkKeyScanExW
keybd_event
HttpAddRequestHeadersW
HttpOpenRequestW
HttpQueryInfoA
HttpQueryInfoW
HttpSendRequestW
InternetOpenUrlW
.text
`.data
.rdata
P.idata
@.didata
.edata
@.rsrc
@.reloc
\\?\UNC\
uxtheme.dll
comctl32.dll
TaskDialogIndirect
%s[%d]
%s_%d
.Owner
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
%s%s%.2d:%.2d
%s%s%.2d
%d.%d
%s, ProgID: "%s"
ole32.dll
oleaut32.dll
%s-%s
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
olepro32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
%s (*.%s)|*.%1:s
%s (%s)|%1:s|
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
%s%s%s%s%s%s%s%s%s%s
crSQLWait
%s (%s)
imm32.dll
Portable Network Graphics
data.ini
*<>#%"{}|\^[]`
*<>#%"{}|\^[]` 
HTTPS
libeay32.dll
ssleay32.dll
libssl32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_add_cert
X509_STORE_CTX_get_current_cert
i2d_DSAPrivateKey
d2i_DSAPrivateKey
d2i_PrivateKey
d2i_PrivateKey_bio
DES_set_key
_ossl_old_des_set_key
RSA_generate_key
RSA_check_key
RSA_generate_key_ex
i2d_PrivateKey_bio
i2d_RSAPrivateKey
d2i_RSAPrivateKey
i2d_RSAPublicKey
d2i_RSAPublicKey
i2d_PrivateKey
i2d_NETSCAPE_CERT_SEQUENCE
X509_get_default_cert_file
X509_get_default_cert_file_env
X509_set_pubkey
X509_REQ_set_pubkey
PEM_read_bio_RSAPrivateKey
PEM_read_bio_RSAPublicKey
PEM_read_bio_DSAPrivateKey
PEM_read_bio_PrivateKey
PEM_read_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_RSAPublicKey
PEM_write_bio_DSAPrivateKey
PEM_write_bio_PrivateKey
PEM_write_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_PKCS8PrivateKey
EVP_PKEY_type
EVP_PKEY_new
EVP_PKEY_free
EVP_PKEY_assign
Open SSL Support DLL Delphi and C  Builder interface
hXXp://VVV.indyproject.org/
1993 - 2009
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
csShiftJIS
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
0.0.0.1
0.0.0.0
255.255.255.255
Wship6.dll
Fwpuclnt.dll
WS2_32.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
MSWSOCK.DLL
WSARecvMsg
WSASendMsg
Kernel32.dll
127.0.0.1
10.5.7
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
http\shell\open\command
psapi.dll
base_url
windows
log.txt
api_url
api_key
resource_url
Load image HTTP error #
|adv_ti|api_url|resource_url|values|embedded_data|
merge_keys
API key:
vendor_logo_url
appended_keys
append_keys
http_error
default_keys
_fail_exec
api.get_stat(
Result of api.get_stat:
targeturl
target_content.dat
Target content url:
hXXps://ssl.google-analytics.com/collect
hXXp://VVV.google-analytics.com/collect
ds=web
dl=hXXp://vpn-ping.ru/
Exception %s in module %s at %p.
Operation aborted
I/O error %d
Invalid pointer operation
Invalid floating point operation
Access violation at address %p. %s of address %p
External exception %x
Interface not supported
%s (%s, line %d)
Access violation at address %p in module '%s'. %s of address %p
D:\Dev\coin32\desktop-downstaller\desktop-libraries\kol_libs\err.pas
Win32 Error. Code: %d.
.manifest
2000/1/1
dd.MM.yyyy
DumpWindowed.txt
HHCTRL.OCX
GdiPlus.dll
GdiplusShutdown
.html
default.html
wininet.dll
Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)
https
http=
Content-Type: application/x-www-form-urlencoded
Balanced tree root node level is %d
Shell32.dll
{43826D1E-E718-42EE-BC55-A1E261C37BFE}
D:\Dev\coin32\desktop-downstaller\downstaler\libs\Utils.pas
Certificats table file offset: $
Certificats table size:
Certificats table real size:
%s Pb
%s Tb
%s Gb
%s Mb
%s Kb
%d.%d.%d
mail.ru
@Mail.Ru
search_url
startup_urls
urls_to_restore_on_startup
opera
Opera Software\
icudt.dll
Opera\Opera\
operaprefs.ini
search.ini
Home URL
firefox
Mozilla\Firefox\
profiles.ini
prefs.js
browser.search.selectedEngine
browser.startup.homepage
Software\Microsoft\Windows\CurrentVersion\Uninstall\
Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
WbemScripting.SWbemLocator
Select %s from %s
hXXp://VVV.gamemodding.net/?from=inst_link
hXXp://VVV.gamemodding.net/ru/toolbar.html
hXXp://VVV.gamemodding.net/en/toolbar.html
hXXp://VVV.gamemodding.net/feedback/
hXXp://VVV.gamemodding.net/forum/index.php
hXXp://VVV.gamemodding.net/?from=inst_logo
hXXp://VVV.facebook.com/gamemodding
hXXp://vk.com/gamemoddingnet
hXXp://VVV.youtube.com/user/GameModdingPreview
hXXps://twitter.com/GameModdingNet
hXXps://plus.google.com/communities/107466553082411818715
hXXp://ok.ru/group/52311790387354
8\\\?\
r\\?\
L==\\?\
\0 1 2 0 1 2
HTTP/1.1
%)('=<@/ 7>83&:*2?6,91;.50-4
KUTF8: A start byte not followed by enough continuation bytes in position %s
%s is not a valid BCD value$Could not parse SQL TimeStamp string
Invalid SQL date/time values
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Set Size Exceeded.AUTF8: Type cannot be determined out of header byte at position %sDUTF8: An unexpected continuation byte in %s-byte UTF8 in position %s
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
Socket Error # %d
Operation would block.
Operation now in progress.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.$Cannot change a connected IOHandler.%No IOHandler of type %s is installed.
Reply Code is not valid: %s
Reply Code already exists: %s4Failed attempting to retrieve time zone information.-Error on call to Winsock2 library function %s
Command not supported.
Address type not supported."%d: Circular links are not allowed"Not enough data in buffer. (%d/%d)
File "%s" not found
Object type not supported.
Host field is empty)UDP is not support in this SOCKS version.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
SSL status: "%s"
%s Alert
%s Read Alert
%s Write Alert
Optimizing'Algorithm %s not permitted in FIPS mode$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Unsupported PixelFormat
Invalid stream operation
Invalid extension introducerúiled to allocate memory for GIF DIB
Invalid Image trailerAInternal error: Extension Instance does not match Extension Label,Unsupported Application Extension block size
Unknown GIF block type'Object type not supported for operation
dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.]The program tried to add a existent critical chunk to the current image which is not allowed.IIt's not allowed to add a new chunk because the current image is invalid.7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA)OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.oThe "Portable Network Graphics" could not be created because invalid image type parameters have being provided.
"Failed to set tab "%s" at index %d Failed to set object at index %d<MultiLine must be True when TabPosition is tpLeft or tpRightE%d is an invalid PageIndex value. PageIndex must be between 0 and %d&Cannot change the size of a JPEG image
JPEG error #%d
JPEG Image FilejThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it againnThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d."PageControl must first be assigned"%s requires Windows Vista or later %s requires themes to be enabled
Button%d
RadioButton%d
Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d Failed to get object at index %d
Value must be between %d and %d
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard: %s
Text exceeds memo capacity Operation not supported on selected printer.There is no default printer currently selected
%s property out of range
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active0Can only modify an image if it contains a bitmap*A control cannot have itself as its parent
$Unknown picture file extension (.%s)
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Scan line index out of range!Cannot change the size of an iconÊnnot change the size of a WIC Image Invalid operation on TOleGraphic
Invalid destination array"Character index out of bounds (%d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
/Custom variant type (%s%.4x) already used by %s*Custom variant type (%s%.4x) is not usable2Too many custom variant types have been registered5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Object lock not owned(Monitor support function not initialized
(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s,Custom variant type (%s%.4x) is out of range
Integer overflow Invalid floating point operation
Invalid class typecast0Access violation at address %p. %s of address %p
No help found for %s
Duplicates not allowed('%s' is not a valid floating point value '%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
WThe given "%s" local time is invalid (situated within the missing period prior to DST).$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and <= %drHigh surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properlyrLow surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly2Length of Strings and Objects arrays must be equal
Invalid Timeout value: %s
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid time
No help found for context %d
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread2Cannot call Start on a running or suspended thread;Cannot call CheckTerminated on an externally created thread9Cannot call SetReturnValue on an externally create thread'Parameter %s cannot be a negative value*Input buffer exceeded for %s = %d, %s = %d
The specified path is too long The specified path was not found The path format is not supported The specified file was not found
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream)%s has not been registered as a COM class
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Invalid data type for '%s'
OLE error %.8x#Object factory for class %s missing%Type information missing for class %s'Incorrect type information for class %s(Dispatch interface missing from class %s.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found

2.exe_1300:

.text
`.sdata
.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
v2.0.50727
Microsoft.VisualBasic
Syslogger_Stub.My
MyWebServices
SQLiteDataTypes
Keyboard
KeyStructure
CMSNMessengerPasswords
MSNPass
CMSNMessengerPassword
Syslogger_Stub.My.Resources
SQLiteHandler
sqlite_master_entry
Microsoft.VisualBasic.ApplicationServices
WindowsFormsApplicationBase
.ctor
Microsoft.VisualBasic.Devices
.cctor
get_WebServices
m_MyWebServicesObjectProvider
WebServices
System.Windows.Forms
System.Collections
loadCerts
System.Text
GetProcessHeap
sqlite3_open
sqlite3_close
sqlite3_exec
sqlite3_errmsg
sqlite3_prepare_v2
sqlite3_step
sqlite3_column_count
sqlite3_column_name
sqlite3_column_type
sqlite3_column_int
sqlite3_column_double
sqlite3_column_text
sqlite3_column_blob
sqlite3_column_table_name
sqlite3_finalize
SQL_OK
SQL_ROW
SQL_DONE
System.Data
System.ComponentModel
smtp
port
ftpuser
ftppass
ftpurl
ftpst
DeleteMozillaCookies
DeleteMozillaSignons
user32.dll
AntiKeyscrambler
SetWindowsHookEx
KeyDelegate
SetWindowsHookExA
UnhookWindowsHookEx
Keys
System.Collections.Generic
HKEY_CURRENT_USER
KEY_QUERY_VALUE
KEY_ENUMERATE_SUB_KEYS
KEY_NOTIFY
KEY_SET_VALUE
KEY_CREATE_SUB_KEY
KEY_READ
KEY_WRITE
kernel32.dll
advapi32.dll
crypt32.dll
RegOpenKeyEx
hKey
lpSubKey
RegOpenKeyExA
RegEnumKeyEx
RegEnumKeyExA
RegCloseKey
shell32.dll
msidcrl.dll
PassportFreeMemory
m_MSNPass
getMSN75Passwords
DOMAIN_PASSWORD
DOMAIN_CERTIFICATE
DOMAIN_VISIBLE_PASSWORD
lpstrKeyword
strLogin
strPass
m_szLogin
m_szPassword
szLogin
szPassword
get_Password
get_Login
Password
Login
System.Resources
System.Globalization
System.Configuration
opera_salt
key_size
sUrlTemp
sPassTemp
sUrl
sPass
lasturl
LoginData
SQLDataTypeSize
sql_statement
System.CodeDom.Compiler
System.Diagnostics
Microsoft.VisualBasic.CompilerServices
System.ComponentModel.Design
HelpKeywordAttribute
System.Reflection
ContainsKey
InvalidOperationException
System.Runtime.CompilerServices
System.Runtime.InteropServices
System.IO
DllImportAttribute
Crypt32.dll
System.Threading
System.Text.RegularExpressions
mozsqlite3
System.Drawing
get_ExecutablePath
MsgBoxResult
MsgBoxStyle
MsgBox
System.Net.Mail
SmtpClient
System.Net
set_Port
Operators
FtpWebRequest
WebRequest
Microsoft.Win32
Microsoft.VisualBasic.MyServices
System.Collections.ObjectModel
Microsoft.VisualBasic.FileIO
System.Security.Cryptography
set_Key
RegistryKey
OpenSubKey
GetExecutingAssembly
IsKeyLocked
get_ModifierKeys
Syslogger Stub.exe
Syslogger_Stub.Resources.resources
Syslogger_Stub.Form1.resources
8.0.0.0
My.Application
My.Forms
My.Computer
My.WebServices
My.User
System.Windows.Forms.Form
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
4.3.2.1
$92cfe5a8-c556-4a58-8735-4e19116a1afa
_CorExeMain
mscoree.dll
C:\Users\Public\Documents\Visual Studio 2010\Projects\SysLogger Stub\SysLogger Stub\obj\x86\Release\Syslogger Stub.pdb
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
\Google\Chrome\User Data\Default\Login Data
logins
origin_url
password_value
|----------------------------------------|Google Chrome|--------------------------------------------|
Password:
\Mozilla Firefox\
Password:
Mozilla Firefox
---Firefox---
mozcrt19.dll
nspr4.dll
plc4.dll
plds4.dll
ssutil3.dll
sqlite3.dll
mozsqlite3.dll
nssutil3.dll
softokn3.dll
nss3.dll
PK11_GetInternalKeySlot
SELECT name FROM sqlite_master WHERE type IN (
System.Int32
System.Single
System.String
icheck.txt
st.txt
stcheck.txt
|-----------------------------------|Windows Live Messenger|-----------------------------------|
Login:
127.0.0.1 74.53.201.162
127.0.0.1 66.66.132.220.30
127.0.0.1 66.35.241.92
127.0.0.1 94.23.199.60
\Steam\config\SteamAppData.vdf
HKEY_LOCAL_MACHINE\SOFTWARE\Valve\Steam
ClientRegistry.blob
%Documents and Settings%\All Users\Start Menu\Programs\Startup\MSASCui.exe
Windows Defender
MSASCui.exe
errorchecker.txt
\Mozilla\Firefox\Profiles
svchost.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HDDFile.com
autorun.inf
shellexecute=
Software\Microsoft\Windows\CurrentVersion\Run
keyscrambler
npfmsg
lo.txt
\MSN Messenger\msidcrl.dll
ps:password
<wsse:Password>
</wsse:Password>
PasswordMSN Messenger Service
Password.NET Messenger Service
User.NET Messenger Service
Passport.Net\*
82BD0E67-9FEA-4748-8672-D5EFE5B779B0
Syslogger_Stub.Resources
\Opera\Opera\wand.dat
\Opera\Opera\profile\wand.dat
hXXp://
hXXps://
PTF://
---Opera---
SQLite format 3
Not a valid SQLite 3 Database File
Auto-vacuum capable database is not supported
No supported Schema layer file-format
1.2.3.4

2.exe_1300_rwx_00312000_00009000:

.tgpptg

2.exe_1300_rwx_69722000_00002000:

.ri3J
-yiq.yiw
-yiq.yi


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:1968
    2.exe:3504

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1.exe (732 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\2.exe (129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\mm_9742.tmp\log.txt (315 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab96C3.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D (325 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\828298824EA5549947C17DDABF6871F5_6B5C8B321CA02275A82E95FA81D6DE62 (1068 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8A574ED5927B3CEC9626151D220C7448 (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\828298824EA5549947C17DDABF6871F5_6B5C8B321CA02275A82E95FA81D6DE62 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D (876 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_6D5D2989278EB7E813FFA194F5CA6156 (660 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar96C4.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_6D5D2989278EB7E813FFA194F5CA6156 (463 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8A574ED5927B3CEC9626151D220C7448 (248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\stcheck.txt (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\icheck.txt (3 bytes)
    C:\Windows\System32\drivers\etc\hosts (120 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender" = "C:\Users\"%CurrentUserName%"\AppData\Local\Temp\MSASCui.exe"

  5. Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
    127.0.0.1 localhost
  6. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  7. Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
  8. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now