SpyTool.Win32.Ardamax_97c94f7678
HEUR:Trojan-Downloader.Win32.Generic (Kaspersky), SpyTool.Win32.Ardamax.FD, Trojan.Win32.Swrort.3.FD (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan, SpyTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 97c94f7678fa89eb87858f8e5a7c13ab
SHA1: 14558f60160dbed797a212c4db37ad8a5c6859ef
SHA256: e0edf44c18eb85831920443c696c4e75c9d5c4c92d056552e8c3e6f0413c7ca0
SSDeep: 6144:6/QiQPsDJZVpdtyhvOJGYgBpl7 hCnaTxUKsE9ceJRvcj68xhxXqo7V5/q/hAUfB:CQiGs1ZVpXyVOJilKhC2Iqjzva6WXd5
Size: 385387 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
SpyTool. A program used to apply passive protection methods to spyware, such as obfuscation, encryption or polymorphism. The original malicious program is usually encrypted/compressed and stored inside the wrapper.
Payload
No specific payload has been found.
Process activity
The SpyTool creates the following process(es):
taskkill.exe:320
taskkill.exe:1336
taskkill.exe:2044
97c94f7678fa89eb87858f8e5a7c13ab.tmp:1680
tasklist.exe:1928
tasklist.exe:364
upmbot_ca_014010265.exe:1092
%original file name%.exe:668
mbot_ca_014010265.exe:1736
encrypt.exe:216
encrypt.exe:1260
encrypt.exe:196
encrypt.exe:264
setup.tmp:1896
setup.exe:1948
The SpyTool injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process 97c94f7678fa89eb87858f8e5a7c13ab.tmp:1680 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O9YZOXQZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KH2NKL2Z\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\S5Q3CH2Z\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\idp.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\ODABS1EF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\setup.exe (657385 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\_isetup\_shfoldr.dll (23 bytes)
The SpyTool deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\_isetup (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\setup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\_isetup\_shfoldr.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\idp.dll (0 bytes)
The process upmbot_ca_014010265.exe:1092 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Cookies\index.dat (788 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.cyl (428 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (231 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@youandmeandmeandyouhihi[1].txt (182 bytes)
The process %original file name%.exe:668 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-8Q7DH.tmp\97c94f7678fa89eb87858f8e5a7c13ab.tmp (3780 bytes)
The SpyTool deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-8Q7DH.tmp\97c94f7678fa89eb87858f8e5a7c13ab.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8Q7DH.tmp (0 bytes)
The process mbot_ca_014010265.exe:1736 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\mbot_ca_014010265\1.10\cnf.cyl (269 bytes)
The process encrypt.exe:216 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.exe (16609 bytes)
The process encrypt.exe:1260 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.exe (20237 bytes)
The process encrypt.exe:196 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.exe (16649 bytes)
The process encrypt.exe:264 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.exe (3300 bytes)
The process setup.tmp:1896 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\encrypt.exe (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.7z (8657 bytes)
%Program Files%\mbot_ca_014010265\is-OP7DE.tmp (28787 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-HE4TJ.tmp (4185 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\MYBESTOFFERSTODAY\MyBestOffersToday.lnk (837 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-HT75P.tmp (7971 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-LGPBB.tmp (7433 bytes)
%Program Files%\mbot_ca_014010265\unins000.dat (35465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\CheckProc.cmd (288 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.7z (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-61C0M.tmp (8657 bytes)
%Program Files%\mbot_ca_014010265\mbot_ca_014010265.exe (29430 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\idp.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe (23062 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-6DL8S.tmp (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.7z (7971 bytes)
%Program Files%\mbot_ca_014010265\mybestofferstoday_widget.exe (23404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.7z (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\ex.bat (1564 bytes)
%Program Files%\mbot_ca_014010265\predm.exe (4185 bytes)
The SpyTool deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\encrypt.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.7z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\CheckProc.cmd (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\MYBESTOFFERSTODAY_WIDGET.7Z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.7z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\_isetup\_shfoldr.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\av.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.7z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\_isetup (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\UPMBOT_CA_014010265.7Z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.7z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\MBOT_CA_014010265.7Z (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\ex.bat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\idp.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp (0 bytes)
The process setup.exe:1948 makes changes in the file system.
The SpyTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-5BNLS.tmp\setup.tmp (6319 bytes)
The SpyTool deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-5BNLS.tmp\setup.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-5BNLS.tmp (0 bytes)
Registry activity
The process taskkill.exe:320 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "78 43 41 0D 5F 0A A9 63 31 40 17 91 F8 D5 2B FF"
The process taskkill.exe:1336 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2A 2E 08 D3 C4 75 BB 80 AC 80 FE 84 D1 2B A2 E5"
The process taskkill.exe:2044 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9E 50 3F 17 6A E9 42 E2 F1 ED BE BF FB 5F DA 64"
The process 97c94f7678fa89eb87858f8e5a7c13ab.tmp:1680 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6C 35 00 E8 F2 D2 BC 60 D3 4B 65 FD 7D A9 CF 61"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The SpyTool modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The SpyTool modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The SpyTool modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The SpyTool deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process tasklist.exe:1928 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E4 9A B0 64 40 76 1C EF EE 26 7B 4E 5B C9 F1 A0"
The process tasklist.exe:364 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "35 79 78 1E 12 96 79 C4 05 FA 38 05 28 42 80 1B"
The process upmbot_ca_014010265.exe:1092 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Tutorials\updatetutorialeshp]
"Version" = "mbot_ca_014010265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Tutorials]
"HostGUID" = "93DCBECB-77B0-45FA-8C3B-666267523CCF"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9F 0C 6E 09 57 E6 62 0A 4F 59 B7 EC 44 A0 A4 DE"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Tutorials\updatetutorialeshp]
"MainDir" = "%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The SpyTool modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The SpyTool modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The SpyTool modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the SpyTool adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"upmbot_ca_014010265.exe" = "%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe -runhelper"
The SpyTool deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:668 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E5 27 91 7B A2 73 84 5A 7A 77 E9 3D C8 C3 3E 5A"
The process mbot_ca_014010265.exe:1736 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "39 10 C3 9C CF C5 D4 3D 79 BC 3D A7 30 4E 5C AF"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The process encrypt.exe:216 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5C 5E 6A F4 1E D7 95 19 E7 62 F7 A5 CF E5 CE 05"
The process encrypt.exe:1260 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3A 0E 08 D5 1E 2D A4 3A FA 0F 66 A2 D2 40 C8 65"
The process encrypt.exe:196 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BE D0 CE 93 50 EA 39 BC 26 B3 FF 21 0A 0D 80 FA"
The process encrypt.exe:264 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CD 9B E5 29 0A F9 E4 BA C4 C7 82 46 75 E2 F0 59"
The process setup.tmp:1896 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKCU\Software\Tutorials\updv]
"Version" = "16.03.12"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"NoModify" = "1"
"Inno Setup: Language" = "ca"
"Inno Setup: User" = "%CurrentUserName%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"InstallDate" = "20160312"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"DisplayName" = "MyBestOffersToday 026.014010265"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"Inno Setup: Setup Version" = "5.5.4 (a)"
"Inno Setup: Icon Group" = "MYBESTOFFERSTODAY"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\MYBESTOFFERSTODAY\mbot_ca_014010265]
"PathInstall" = "%Program Files%\mbot_ca_014010265"
[HKCU\Software\TutoTag]
"OnceInstalled" = "ca"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"UninstallString" = "%Program Files%\mbot_ca_014010265\unins000.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Tutorials\updatetutorialshp]
"MainDir" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKCU\Software\Microsoft\Tinstalls]
"20160312" = "1"
[HKCU\Software\Microsoft]
"Tinstalls" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"NoRepair" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "35 7B 06 24 23 BA 65 46 D7 9E DF 9C DA 1E 04 20"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"Inno Setup: App Path" = "%Program Files%\mbot_ca_014010265"
"InstallLocation" = "%Program Files%\mbot_ca_014010265\"
[HKCU\Software\TutoTag]
"AgenceInstalledYet" = "true"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mbot_ca_014010265_is1]
"Publisher" = "MYBESTOFFERSTODAY"
"QuietUninstallString" = "%Program Files%\mbot_ca_014010265\unins000.exe /SILENT"
[HKCU\Software\TutoTag]
"OnceInstalled2" = "ca"
To automatically run itself each time Windows is booted, the SpyTool adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mbot_ca_014010265" = "%Program Files%\mbot_ca_014010265\mbot_ca_014010265.exe"
The process setup.exe:1948 makes changes in the system registry.
The SpyTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "11 2A 46 F5 D3 11 B4 55 2C 0B 8B B3 A5 D1 F5 7E"
Dropped PE files
| MD5 | File path |
|---|---|
| 2fdd98650bb540f9fac1fe0a62a0b990 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe |
| 7305c34a9b7b27fe1fe64c4f2d50381e | c:\Program Files\mbot_ca_014010265\mbot_ca_014010265 - uninstall.exe |
| 11cd6c758e7a66bd126f2bf8658eb59b | c:\Program Files\mbot_ca_014010265\mbot_ca_014010265.exe |
| 989a9919e922f52086201ddfeabd3c2b | c:\Program Files\mbot_ca_014010265\mybestofferstoday_widget.exe |
| 3044176a198d1c94e6b18cb7ef10b302 | c:\Program Files\mbot_ca_014010265\predm.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name: MyBestOffersToday
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version:
File Description: MyBestOffersToday Setup
Comments: This installation was built with Inno Setup.
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| CODE | 4096 | 40240 | 40448 | 4.59679 | c3bd95c4b1a8e5199981e0d9b45fd18c |
| DATA | 45056 | 592 | 1024 | 1.90742 | 1ee71d84f1c77af85f1f5c278f880572 |
| BSS | 49152 | 3724 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .idata | 53248 | 2384 | 2560 | 3.07115 | bb5485bf968b970e5ea81292af2acdba |
| .tls | 57344 | 8 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rdata | 61440 | 24 | 512 | 0.14174 | 9ba824905bf9c7922b6fc87a38b74366 |
| .reloc | 65536 | 2244 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 69632 | 11264 | 11264 | 3.14703 | 86384a97e0453cb56499ecc334d6f61b |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 163
2b7b7a52efe8396b0216f4a05260ef2d
9d284e9fed9955f910eef1ae7287159d
2f9e864b52474c400bd02edce6a5810a
5932f9c130120565222b600225023e41
7059a51294e236d4fc52cd0e424241bf
4bfd0d9d96cea895041cdf4b1e654631
66b59b5cb4eb3b9f42fb05d650abf687
956c81b158d392a57c94cc58b1d9b96b
c84ece819a6175620d08eacc6851084d
2331123d3fc0308c0bc5c576566ded63
aae70780f303d40607f55afe6c40671d
e5996e0b5bdeae2492661b82c41ed663
c5ea6329994c08a6947bc53a8d7f468c
9e3305071b41c395fa799af6533f7a9c
610ed4fbad849e51346d035c8f0af609
db7804c6c3b9bddaee87754eeb036518
be41f2a70019f8d54dbf1f3ad7c6f76d
53e82bc5fee2ad1a1f2751287d719811
f70c244a1965e12409fcced19c0f23da
a10d93a8f5ecb7a4affff17751521a6d
d8478b37b2f855b5435090b481cbdf0c
1a2c205f9b6a6905620d3c462c7babc8
253c1c04e27a5fe49c4dabaefe94773a
c41947ad52f30f0423cbd088be9956a1
242b1a149e8945fe47933f0c677afff0
URLs
| URL | IP |
|---|---|
| hxxp://dl.tuto4pc.com/download/trasgo/amonetize/ca/setup_mbot_ca.exe | |
| hxxp://prof.eorezo.com/cgi-bin/get_protect.cgi?checking=true&version=gmsd_us_233&forceGEO=US | |
| hxxp://ads.regiedepub.com/cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_INI | |
| hxxp://prof.eorezo.com/cgi-bin/get_protect.cgi | |
| hxxp://ads.under-myscreen.be/cgi-bin/advert/getkws.cgi?did=90068&version=0&key=azJJ.s8MVPsHc | |
| hxxp://ads.regiedepub.com/cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_F11 | |
| hxxp://ads.regiedepub.com/cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_FIN | |
| hxxp://dl.tcoupichou.eu/download/trasgo/amonetize/ca/setup_mbot_ca.exe | |
| hxxp://prof.youandmeandmeandyouhihi.com/cgi-bin/get_protect.cgi | |
| upd.adskyforever.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
ET POLICY Signed TLS Certificate with md5WithRSAEncryption
ET MALWARE Adware-Win32/EoRezo Reporting
Traffic
GET /cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_FIN HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: ads.regiedepub.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:25 GMT
Server: Apache/2.2.16 (Debian) mod_ssl/2.2.16 OpenSSL/0.9.8o mod_wsgi/3.3 Python/2.6.6 mod_perl/2.0.4 Perl/v5.10.1
Content-Location: settags.cgi
Vary: negotiate
TCN: choice
Cache-Control: no-store, no-cache, must-revalidate
X-C4PC-ServerName: ads.regiedepub.com
P3P: policyref="hXXp://ads.regiedepub.com/w3c/p3p.xml",CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Expires: Sat, 12 Mar 16 21:12:00 GMT
Set-Cookie: _c4aid=220D4706AE854B09B81F07469B850CB9; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com; path=/;
Set-Cookie: _c4aid2=220D4706AE854B09B81F07469B850CB9,1457817145.99322; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com
GET /cgi-bin/advert/getkws.cgi?did=90068&version=0&key=azJJ.s8MVPsHc HTTP/1.1
User-Agent: mbot_ca_014010265-1.10
Host: ads.under-myscreen.be
Accept: */*
Accept-Encoding: gzip, deflate
Referer:
Cookie:
Accept-Language: en,en-US
X-Guuid: 75ed9567-aa58-4c8e-a8ea-3cad7c47ab03
X-OS-Ver: 5.1.2.2600
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:23 GMT
Server: Apache/2.2.22 (Debian) mod_ssl/2.2.22 OpenSSL/1.0.1e mod_wsgi/3.3 Python/2.7.3 mod_perl/2.0.7 Perl/v5.14.2
X-C4PC-ServerName: ads.under-myscreen.be
Set-Cookie: _c4aid=75ED9567AA584C8EA8EA3CAD7C47AB03; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=under-myscreen.be; path=/;
Set-Cookie: _c4aid2=75ED9567AA584C8EA8EA3CAD7C47AB03,1457817143.84413; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=under-myscreen.be; path=/;
Connection: close
Transfer-Encoding: chunked
Content-Type: text/javascript34d..{"dids":{"90077":{"unmatch":["regiedepub.com|directrev.com|under-
myscreen.be|eorezo.com|regiedepub.com"],"match":[{"u":0,"m":"pinterest
|apple|ask|microsoft|bmo|wordpress|cibc|paypal|baidu|cbc"},{"u":0,"m":
"xvideos|imbd|instagram|netflix|craigslist|kickass|td|thepiratebay"},{
"u":0,"m":"yahoo|live|wikipedia|bing|msn|amazon|tumblr|royalbank|reddi
t|ebay"},{"u":0,"m":"youtube|yahoo|live|wikipedia|bing|msn|amazon|tumb
lr|royalbank|reddit"},{"u":0,"m":"xhamster|http|fa|go|yah|hot|twit|blo
g|msn|apple|facebook|google|twitter"},{"u":0,"m":"xhamster"},{"u":0,"m
":"pinterest|apple|ask|microsoft|bmo|wordpress|cibc|paypal|baidu|cbc"}
,{"u":0,"m":"ebay|xvideos|imbd|instagram|netflix|craigslist|kickass|td
|thepiratebay"},{"u":0,"m":"http|fa|go|yah|hot|twit|blog|msn|apple|fac
ebook|google|twitter|youtube"}]}},"freeze":3600,"refresh":3600,"versio
n":118285}..0..
GET /cgi-bin/get_protect.cgi?checking=true&version=gmsd_us_233&forceGEO=US HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: prof.eorezo.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:18 GMT
Server: Apache/2.2.22
x-eorezo-crc32: -1
x-eorezo-crypted: 1
x-eorezo-length: 632
Set-Cookie: conftime=1457817138; expires=Thu, 06 Jul 16 14:58:00 GMT; domain=eorezo.com; path=/;
Set-Cookie: EoRezo=194.242.96.218.1457817138770161; path=/; expires=Mon, 11-Apr-16 21:12:18 GMT
Connection: close
Transfer-Encoding: chunked
Content-Type: text/plain358..Xg8nssf/4H10OdRv/PBlQCyF9RkAzpy/PPG8paJnu rCw3mAaqFpX2 ZKEgbMMA2h
tCshaMIPoMPkSppoNIfvqD ZyWxTIl1LyUx8yWjlHHNhn1WF5uF0H6qLM uZMwkTiGldZX
5iSj uCsroOrbj/qdFgfbU9hmNOF2lZWiRA4D1nmKWD56o30N03aMe cM TaH0Zt8tkkpV
IrV86sjShA2ibI4frmimtvqttCmZq2iOlFsKeYNJxrj/jP12cx2lA7NiBrk4PKXXug7tpK
b65atNqDRlvUKKAF9c9zPzn4F2eh8GAfVbPOtZhSf/o/50RLSfemcISdhtiO8gTINReeSo
YdUAqhmbrscZPjwnJCjKfgrUbQCV1J0DBwv2J mQsGJZQH4xDticU8Aw3zUoh3vFhu1Wg3
CUqlkPjaoTHyfoXpQMPgXLOCXbzPycQALj/NcItWUUrMNRe kdxupcE1jN4IzWnf18j9K2
2lWOLNAxMrPXujOAPP62LFEXRprTnccE4UideNhUT6DZiskWqf r0XSAkp94qxjVd0han4
yoYTsCe73I6nVdoolp8ZVRkkPBXhF4j0HnxGK7gNIlCPG9CPWv3omojAUMA/b1D0QyJmrJ
XkW4wDQZDG70ubUzvxaL8e7tIXGaOPoNaaawcsncgjizZ4iLzFWuT7SqAme snGMZyD25H
DIX85w1NDBG/7j7KXONYkUsLgo0muKS18VS3O815AXMRvhUqrsNbIl14wyH2HdK2Y6rOde
diRY/mUWwpxc4SIFGJvBzItOLGyenMOutfgI/PzuVUWr5spHZWUtnBhgucXvuMx85rof39
lP/XE5KUbGoqL6Aeb3w==..0..
GET /cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_INI HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: ads.regiedepub.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:18 GMT
Server: Apache/2.2.16 (Debian) mod_ssl/2.2.16 OpenSSL/0.9.8o mod_wsgi/3.3 Python/2.6.6 mod_perl/2.0.4 Perl/v5.10.1
Content-Location: settags.cgi
Vary: negotiate
TCN: choice
Cache-Control: no-store, no-cache, must-revalidate
X-C4PC-ServerName: ads.regiedepub.com
P3P: policyref="hXXp://ads.regiedepub.com/w3c/p3p.xml",CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Expires: Sat, 12 Mar 16 21:12:00 GMT
Set-Cookie: _c4aid=D3B79603FC7E4A9C8FB98F925370E2BE; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com; path=/;
Set-Cookie: _c4aid2=D3B79603FC7E4A9C8FB98F925370E2BE,1457817138.92826; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com; path=/;
Connection: close
Transfer-Encoding: chunked
Content-Type: text/javascript41.......if (window.rdp_callback).....rdp_callback(1203, 255559);.....
.0..
POST /cgi-bin/get_protect.cgi HTTP/1.1
x-spidermessenger-crypted: 2
x-spidermessenger-crc32: 2055166265
x-spidermessenger-length: 275
Content-Type: text/*
User-Agent: mbot_ca_014010265-mbot_ca_014010265
Host: prof.youandmeandmeandyouhihi.com
Content-Length: 382
Cache-Control: no-cache
ujXl2iaEv3+xg2nmk5XqjNFxudZ4eC/dyLKVClDHrgytgp9na1YznA1k2sbSq1rpblkEa9ZKaQ1Wwn4SmwElJXtSv7LRCE910ON1TEZkOpikVPs0NmG6pauUOoeVJSuD7bwT6xVPl/Q9wAnpz8090A7JYzEPa4dTn2lAvm4etvM/lgFyGw7qg5HsoRIQ5jkHm1Hj6TME+Z22i4XCGD7auQF8GDqKXkss9k7NBp99DMsAIWRpNtN4zLe9JkOz4rsIjlMqZxuWf+eZ1OGoqjLBfAMnuAoebFSON424/gL2okjLce3ejQZwj3JPlFBhztqC6fQ7XEPW+mE5ErzKDmOdJWdL4mIadPxmZkcP1P9WOKo=
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:23 GMT
Server: Apache/2.2.22
x-SPIDERMESSENGER-crypted: 2
x-SPIDERMESSENGER-length: 1983
x-SPIDERMESSENGER-crc32: -1
Set-Cookie: conftime=1457817143; expires=Thu, 06 Jul 16 14:59:00 GMT; domain=youandmeandmeandyouhihi.com; path=/;
Set-Cookie: EoRezo=194.242.96.218.1457817143574585; path=/; expires=Mon, 11-Apr-16 21:12:23 GMT
Vary: Accept-Encoding
Connection: close
Transfer-Encoding: chunked
Content-Type: text/plaina60..0NogVEVNeZU/g6fcxXpPm8L/TbLACp6qNZeGXV8m6ec/K8dk0/yY5pa2OZ8Vz3njZ
Hd9v29yzT3I48VojCBBmA2s0/SxoZIOAAhT SK4vV7sDhBM0aTmg2 IVnRKydYHunoaf9p
bRw2 G5ivu0QKWc3/l WPP1gNlgnspvbmqk4aS7ehZBwwMTOxZSE84DysrG8f3S hIgVSA
INyXu9s UPJeM98UAjt6p7fBFT6zMtkh 3j1ETePa4NR6v5nTfw5XqoE1sK6iaLoC4VpTh
hXFImxqo8kWLg41HIXBDHRdF950YBd00yrMS//vftM2BgU2lwIGKjVkNlmY0QWivyhi c6
FkNLk8qwrEs/rFNjOmDaAErIlj KNtqGnUkY e6D3O/1/I 8DpBydFoBJ91LdZab/WrBBb
IHR0mgEkJTQoBXjm/T 2a3azIWpikcxx30rHKp0xFBPgCNjxJhe5w0Mo4JSA6v8dx n8bB
c8fcjovYnaZwRkR7UwhT7Vghxy9eoX6xpvq6DDXUXVc8AdbR7pqgyB0IzeZHlMtG rwrTy
lkciy9hcS4rZSwcRo9g6KSHmtXVZb2lVLgiFX3oaPopPdfYG6vA0GJsxeq6zf7EIcicRfC
4KZzM4J7Ro6YbwlJP6RUDNbYNqz6so6qAo0CMoZ6LbE1zBLIYOXmrFd9EwbmDZiOAZCl2G
K/de/irxXmNOW5WoMLOeZ3Rxv3/uhb jSBoVDkznDGJCknuGV/kmP rrjbuI5qTWlAs34a
UItH2qjEEeW1Jioq2puQuFKpKOrQTcG4TQZ9VPZlf8IuP qkA5lolo8h0g3BJrdVyPNGvr
AHVEgE2lLNmk3L6cFd1kiGIF8A4VHdQ9FlhlrSUcb6rq9n1/NQsHwsUwialxOcXHmybteA
i1KTH4d9lbKNXkBEUb6pBlo4S7/OccM0c4q5GjewekIcMqEUm0BoMPcBoJhM9EwnNgmTX
IiF1psW05lxUOV50wzEAPZI63kEUwSrWEWXBaXClEF3/43Gi5QN3ek77Yng9Eu0TbbDwAI
UDuBKXeF5NL5Xq5VPXPkAPREGqZnF9paybsZJK7DCapPWXLwNzYa5IGlsUC6MLp9ljxedA
EFRvOgUMQXj0QfMe8eWGVGCCHFrwSsqDnx9FF/rqGAA6wYRUWllQ1lVJNtxiAVCY8/2o0N
0llGnJ5VZOlKfUYdLL1Hg/OQnRYmqMtmdh28VLW/zYklZfD6aTL186Hz7h3LK2vj75hTKb
iRdqpH6SFwzFNgku qd1pjmbmCU77SmPeYVNOfqjNczNaxagN0QnalCBBl/ghWP92SU2/z
c4JjtDA6EHZR7/yoOOF/15s4Vr9woTzL/Wrjd F5uxawMNxDeZ7cJ2Nf0n8V12KzWu5TLc
bRf UeSqwGY0UOROgcFo04bH/u271KjafRZeMcqbeL54nmcnslLnwN2dkc9Lbqzizf7OSp
47lEM2phEkB1OREQxx6ZID364W8TaSNDd7cm6Qz2FlEIjo VGPybLrRefWQf CUsVF<<< skipped >>>
GET /cgi-bin/advert/settags?x_mode=args&x_format=javascript&x_dp_id=1203&x_pub_id=255559&tag=CA_AMONETIZE_INSTALL_F11 HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: ads.regiedepub.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:25 GMT
Server: Apache/2.2.16 (Debian) mod_ssl/2.2.16 OpenSSL/0.9.8o mod_wsgi/3.3 Python/2.6.6 mod_perl/2.0.4 Perl/v5.10.1
Content-Location: settags.cgi
Vary: negotiate
TCN: choice
Cache-Control: no-store, no-cache, must-revalidate
X-C4PC-ServerName: ads.regiedepub.com
P3P: policyref="hXXp://ads.regiedepub.com/w3c/p3p.xml",CP="NON DSP COR CURa PSA PSD OUR BUS NAV STA"
Expires: Sat, 12 Mar 16 21:12:00 GMT
Set-Cookie: _c4aid=0C846B3A5BF443AFB068F8F0503164D7; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com; path=/;
Set-Cookie: _c4aid2=0C846B3A5BF443AFB068F8F0503164D7,1457817145.87228; expires=Thu, 08 Sep 16 21:12:00 GMT; domain=regiedepub.com; path=/;
Connection: close
Transfer-Encoding: chunked
Content-Type: text/javascript41.......if (window.rdp_callback).....rdp_callback(1203, 255559);.....
.0..
HEAD /download/trasgo/amonetize/ca/setup_mbot_ca.exe HTTP/1.1
Accept: */*
User-Agent: InnoDownloadPlugin/1.4
Host: dl.tcoupichou.eu
Content-Length: 0
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:12 GMT
Server: Apache/2.2.16
Last-Modified: Sat, 12 Mar 2016 11:37:00 GMT
ETag: "2140379-5079c7-52dd8773e0344"
Accept-Ranges: bytes
Content-Length: 5274055
Keep-Alive: timeout=15, max=200
Connection: Keep-Alive
Content-Type: application/x-msdos-program
GET /download/trasgo/amonetize/ca/setup_mbot_ca.exe HTTP/1.1
Accept: */*
User-Agent: InnoDownloadPlugin/1.4
Host: dl.tcoupichou.eu
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sat, 12 Mar 2016 21:12:12 GMT
Server: Apache/2.2.16
Last-Modified: Sat, 12 Mar 2016 11:37:00 GMT
ETag: "2140379-5079c7-52dd8773e0344"
Accept-Ranges: bytes
Content-Length: 5274055
Keep-Alive: timeout=15, max=200
Connection: Keep-Alive
Content-Type: application/x-msdos-programMZP.....................@.............................................
..!..L.!..This program must be run under Win32..$7....................
......................................................................
..............................................PE..L....^B*............
..............................@.......................................
[email protected]...............................
......................................................................
..............CODE....0........................... ..`DATA....P.......
....................@...BSS......................................idata
[email protected]................................
[email protected]....................
[email protected][email protected].............@..
[email protected]..............................................
......................................................................
..............................................string................&l
t;[email protected].@..........)@..(@..(@..)@.....$)@..Free..0)@..InitInstance.
.L)@..CleanupInstance..h(@..ClassType..l(@..ClassName...(@..ClassNameI
s...(@..ClassParent...)@..ClassInfo...(@..InstanceSize...)@..InheritsF
rom...)@..Dispatch...)@..MethodAddress..<*@..MethodName..x*@..Field
Address...)@..DefaultHandler...(@..NewInstance...(@..FreeInstance.TObj
ect.@...@..% .@....%..@....%..@....%..@....%..@....%..@....%..@....%(.
@....%..@....%..@....%..@....%..@....%..@....%..@....%..@....%..@.<<< skipped >>>
The SpyTool connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.reloc
RSSSSSSh
QSSh(,j
tFHt:Ht.Ht"Hu`
SSSSh
SSSShxno
u$SShe
tWSShW
tl9_ tgSSh
t'SShl
j%XtL9E
FtPW
SSh@B
u.SSh
tsSSh
FTCP
t.WWWSP
tAHt.HHt
FTPS
t.VhxPj
<SShG
u)SShF
s%j.Zf
xSSSh
FTPjKS
FtPj;S
C.PjRV
LookupPrivilegeValue error: %u
?456789:;<=
!"#$%&'()* ,-./0123
ntdll.dll
RegSetKeySecurity error! (rc=%lu)
Key not found.
Error opening key.
%%X
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is not compiled with PCRE_UTF8 support
PCRE does not support \L, \l, \N, \U, or \u
support for \P, \p, and \X has not been compiled
(*VERB) with an argument is not supported
!"#$%&'((()* ,-./01
CNotSupportedException
CCmdTarget
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
CFtpFileFind
CHttpConnection
CFtpConnection
CHttpFile
RegDeleteKeyExW
TaskDialogIndirect
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
CHotKeyCtrl
CMFCToolBarsKeyboardPropertyPage
GetProcessWindowStation
operator
portuguese-brazilian
qR.Rd
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
Error %d: Could not begin update of %s
Error %d: Updating resource
!"#$%&'()* ,-./:;<=>?@[\]^_`{|}~E:\wizz\EOP - OFF\EOP - OFF\Release\temp.pdb
IPHLPAPI.DLL
PSAPI.DLL
GetProcessHeap
GetWindowsDirectoryW
GetCPInfo
KERNEL32.dll
GetKeyState
SetWindowsHookExW
CreateDialogIndirectParamW
UnhookWindowsHookEx
MsgWaitForMultipleObjectsEx
GetAsyncKeyState
MapVirtualKeyW
GetKeyboardLayout
GetKeyboardState
GetKeyNameTextW
MapVirtualKeyExW
EnumChildWindows
USER32.dll
GetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GDI32.dll
MSIMG32.dll
COMDLG32.dll
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExW
RegUnLoadKeyW
RegLoadKeyW
RegSetKeySecurity
RegEnumKeyExW
RegDeleteKeyW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumKeyW
ADVAPI32.dll
ShellExecuteW
ShellExecuteExW
SHELL32.dll
COMCTL32.dll
UrlUnescapeW
SHLWAPI.dll
ole32.dll
OLEAUT32.dll
oledlg.dll
OLEACC.dll
HttpQueryInfoW
HttpSendRequestW
HttpOpenRequestW
InternetCrackUrlW
InternetCanonicalizeUrlW
FtpDeleteFileW
FtpRenameFileW
FtpCreateDirectoryW
FtpRemoveDirectoryW
FtpSetCurrentDirectoryW
FtpGetCurrentDirectoryW
FtpPutFileW
FtpGetFileW
HttpAddRequestHeadersW
HttpEndRequestW
HttpSendRequestExW
FtpOpenFileW
FtpCommandW
FtpFindFirstFileW
InternetOpenUrlW
WININET.dll
GdiplusShutdown
gdiplus.dll
IMM32.dll
WINMM.dll
.?AVCCmdTarget@@
.?AV?$CArray@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@ABV12@@@
.PAVCFileException@@
.PAVCInternetException@@
.PAVCMemoryException@@
.PAVCSimpleException@@
.PAVCException@@
.PAVCObject@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCOleException@@
.?AVCCmdUI@@
.PAVCArchiveException@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCResourceException@@
.?AVCFtpFileFind@@
.?AVCFtpConnection@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WV12@PB_W@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0EA@@ATL@@
.?AVCToolCmdUI@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCKeyboardManager@@
.PAVCOleDispatchException@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AV?$CArray@PAVCMFCRibbonKeyTip@@PAV1@@@
.?AVCMFCWindowsManagerDialog@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAUHMENU__@@PAU3@@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAVCObList@@PAV3@@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W@@
.?AVCMFCStatusBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCHotKeyCtrl@@
.?AVCMFCRibbonKeyTip@@
.?AVCOleCmdUI@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WHH@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCRibbonKeyboardCustomizeDialog@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
XGCCA_ggqfQQe0ggrmSSK=ggKfuuw/jjxKlleHqqv/ttGKMMB5nnf^EE3%XXN SSNASSA ddY~vvKCjjsLllvfxxu%uudcxxY,ppx=ggz$mm2o99JQggronnfVXXc.ttNXjjwsbbJLccJ~IIyIppHqIIuCXXx)LLGxttmVLLx3vvJaNNE}ttc2dd1qnn32xxyrCCp]ttAThhNWddCwkkszLLn>XXd7HH1tpp4"uu2sxxs.LLi\uupullNBccB.nnIxwwriLLt/vvJMggUZoocjxxLDll36ddW,XXpHNN8bbbH<NNZWmmrpxxP!SSx9gg1jbbZWVVqNwwJ#33w/vvvFRRCDQQHOee4#XXs7bbHzuuwfllI9WWf,oo1^bbK,HH6?mmNMtt2occNFnnRjggw}ddOEXXx6jjmmjjJ2lluEww1%LLg=XXB4LLC*nndÿ2:bbvUUUROXXv7ggURkkc(ggk:vvHY66d!uufJddCUnnHfpmjjN[llj/llcTLLr#ooe2NNveQQw/NN4soo4|LLo]hhJ=ggPmnnv}11ANppp~VVORjjxhqqbHjjpxXXU>lld466sKCCrobbPpttpFjjmPttwIllxOwwpUddnrXX1TLLEGSS3wxxo*jjvaVVLfWWG/NNH$SSG`ddq`CCHR00O"CCHPHH3Auu1e33q~WW1,qqL0mmp1ll2^uuwnIInVnnrBoo5zwwdMwwVISS3<66p8xxKEXXb,llHxVVm8uuZYxxlwWWGIggmACCBtww4*nnfk55E3XXe:FFP/jjGBqqjmttB EEB`mm1oxxifSSJ;MM5}ggxC665Epp2vggLBjjz3ggh'uuzhVVCfoosett8'ttHDHH1KQQKKdd8TQQG,HH2EoovL00A<CCN.FF5=www)ggjBxxfANNi4ggebll3ZXXH^jjx1WWKyqqEskkv[LLP wwx:ll6lSSs3oo1}jj1bNNN\ooJ!UUPrjjJFFFE2xxH#11A(bb3-VVNIoov-66u|kkfRee2kvve4NN6hvvK4bb6=jjJudd8,CCGSnnYuccG"ll1fXXB{ooVSvvK&ggt#jjcoMM5NllJCtt5{kkp1ddhFttmEddqcCCHYqqMmww4allf1ll4Oaa29ggf8XXp$CCwUll5Attpoww46ooN#eeHkoozHSSRshhJxdd8dnn1MIIf5wwe,008_CCHHRRZwSSHrqqoAxxAbddo&xxw;nnmtmmeGbb4Dggx3ggcBXXpGXXK[ll2IllGHppf|VVBOuuJ$33tzxxf~VVN'ggNRVVH9uumHeeRNXXGujjdJSSe5jjk>ggv"XXE&CCx9llO9WWm~LLhVCCmIdd6!uuG3jjN4bbc!jjurvveXUUE/ll1R00B1llf6bbV.XXwSxxk0wwwSnncPggHO33V^kkeIxxxfnnxAggqQCCJM33Y\ppeclls CCJ&VV4foor3ll5BXXmXnnnQWWx$LL4[kkfhggI@kkmRnnnvmmwY33W CCe>RRl\QQx\qqoDggwVxxeFllN"VVzEWWw|dd3{llNXddz=ll3vnn6jkkc<XXWajj3IqqiznnH~552$lld\XXrISSH,MMHfoo4znnuiuud4ddP SSs9nny1CCdRll67jjwEooRJppc:ggcBvvKmllH0oowWggr7CCG|SSR1QQ1gqq2hvvB8LL5BWWxTLLJPSSp%NNMruuw]ggbJWWf 55Z&ggJ;ddquxxvxRRc=ppH%xxjCXXHhddayXXeInnmOllZANNPhpp3hgge SSHb66m7wwHjnnJ@vvvZttJUjjK8jj11uurdqqPznnH,nn1`ggv#33qwllN4bbZvQQc3LL2>ttB1EEBpwwK!ddRKSSxWNNWnjjzzNNzFll3hjj5\ggv/IIbOuuwillWQXXH`LLV$ttGHMMB&XXwf33d*oo24ddO8ooJC66t4jjNUFF30WWfRdddmuuHe33l`mmHs00mDxxx~xxndmmfYFFZ\jjdaggR%WW2:dd5Cnnvl66V)ppBFLL5Exx1rxxCVggvGXXoSpp2f553AXXeaRR3vWWH)nne$ggp/jjxMttx_MMVvXXNcll8MSS2)IIB{uuN4jjJEttvWNNMLuuGNNN6Pjje~33vdQQc3jjf nnJ*FFZ%SSr0FF6"ppd^VVenhhH\RRUiCCv9RRPJbb2KLLR6wwK@FFV\XX3XXX1QuuvCVV4;mmcXddBDnnehIIlGWWJ0lle:jjG.ttEKQQdYqqe(XXZ0jjw&mmr~nnOTWWe8nnN3ggf llxrppm.xxzgppf!NNiHkkm.ttUMttN%VVu8oodKxx4}uurZnnTWSSvDNNa<jjBhllBDvvwAnnE4xxG7xxyGvvfCEEBrkkBRttRcggJ%XXoIppdZNNG>ttw.33m#QQw,xx8hmm1,RRuWppfKeeVBuuvVnnV!SSv/VVeBSSwJLLNaooHbgg4jbbNNXXWGnneM66kibbJ)XXZ!ood`nnb@QQ24VVpojjev00yBQQdSllwGbbwWnnZ}WWdgFF6=SS4,ggmRxxB{ddLxggxAnnK=SSzVttP[lldDXXVnWWzbxx4&ppNZxxk`SSf^IIN.jjwXSSN\wwA@nnifXX2Gggh-CCe~XX5-kks%LLG/XXN,gg6lvvH9RRx6XXr2wwR:xxZ(VV5dooN(aa4qkkvgnn3Qmmcpdd8AWWd/ddOJppzrnnb3ccNjll5IuuHB66V[xx1mLLMFWWzFlljlWWw900CRjj1~eeE$ppNHXXUfoopQjjYXllpannJ-hhB0ddoajj2KddBYSSswllRNbbx2VVkfXXG#VVq{SSeAIIxmjjG_jj2]ppNYMM1,llJMjjO)ppsTlld=bb2=00A*QQckllo-oo1|HHE7nnB~bbEoWWe?66LRnnfEddz}SSH»Ajjj4ZXXEZppNyddz,llJDNNYWccJp991SggH1HH2&QQpnXX8[hhJ}llT{mmKZHH3hSSN{66hwCCBAllL4QQ1qMMJ%WWr%jju|ccGQbbZ3bbZ{dd51CCmALLt]ppG2xxfCSSx>gge9uue3nnyWvvJjgg3!uux;aaR_WWd9VVu&llmjbbHcggcdHHNtccJUHH3ebbvVMMRivvB)ddWqpp2|ggiBSSf^XXK<llzaXXH{wwv|ww6YooKTXXxqSSz5nn6QWW1/66pmjjv_NNRnXX3MwwJDccHFUUN}XXARllv0XXNXnnfHSSzPggd]kkx_llHCttvd00z,wwvSllJ;xxJLddmICCf'HHP/bbp5llZ/nns}LLCrbb3TqqkshhH1IIkUnn3Yjja0nn1FxxZ=ggHbbbPFvvBOll2<wwZXFF5ZttBAEEBzvvv[MM4?ttxfjje!CCHlaaVkmm3466fIttGkMMBkuu1mXXx;kksgxxWAbbJtnnN(XXwWqqG$jjvluuV6ll1nggZexx4<nn2uoomdll4OXXJ8LLp^hhN'jjhouuKmxxnCllvR994$XXv4ooHAnn1jddRGjjvaggBCjjAwbbV-QQed00GPXX19VVYRllrBllB2ooJcxxGOccG5VVshggcbggaomm2?jjYTww1200j(uuwwllqaQQcxjj37jjzrVVy7XXdzVV2/mmG@oo30SSwqooN;XX4Dddu.QQZzggk;wwetHHA4vvv_XX5mkkp1xxv9WWHTjjbBnnJ:jjqKWWK=oo4)CCBAbbPzpp1xllYXttc"FFPUllr=HHJ|ww1]RRgHggs?nnPSooAtoo1Kmm4xqqc}ppdXddZ!kkxzoo3swwvBSSH0ggz)XXU}SSwJgg1VQQpPNNo<bb1attEnmm4RNNB@jjpRuuVlvvdM66Nwooc ggcKuusdlloXQQxkLLO~ggzuxxCvuuA^ttUnttJojjT1QQJ"nnLqnn3Q00JgWWv`RRNJttG<MMB|XXcVqqI.bbJE001!cc2>jjV'ccZ`aaR/jjzQaaR~uuz]tt23jjmv66GcCCvxEEB%yysEggN2CCfmxxD%QQJiddISnnm7tt8`ttKZxxE4QQv@ggTIXXdS00G6bbxQ99E2uupuooEtuupLaaAvjjGYwwY\nnc6VVN.ttB5EEBvnnG-NNvKppJjLL4JppG-jj1^QQxfXXG;jj3TMMJIttG=MMB[QQrCxx6WmmG7nnphjjs4ddr]QQNuMMRXxxz;ll6AooB:eeP7uup0XXl9kkeQllExwwzZggErXXHTVVBCQQcYllr>nnH566Y`kkc;llIdCCc6VVp3xx4,nnP6wweOUUJ<jjHVaaP_SS2sddKVXXHPLLb:oof>jjY9ttc[LLk5jjGpxxYUllpZxxb_mmHsSSArQQf<EEHvWWvtEE6FccNHnnkqmmp llpCoo2 nnWojjwEXXsIuu1/RRt=mmBVnn4pwwz-HH1BCCeTjjBfSSGvjj1|bb3^MMV0nnc[NNZ<uue/aaJevvKwee1\pp1*335wQQeQnnr#uuHOnn4sjjzcjj5]xxeK00icbbvsRRgVppwpEE1allZDtt6XllJSSSEfoopfddd7XXZOVVYFccJsMM1)ggGrFF6MCCx466n»GSxxK-xxJMddpQll38ooH'pp2]994AppwVll1kWW2:ddK"XXJ7006Yttc~VVbaQQ1hXXL[lle)llPdjjwNllG<ll1^nnH.WW10EEH4XXz4aaHbnnAettU&ttJGVVU8SSrEggDPnnfcRRKTcc2{66VeQQv<wwBikkB<ggNhQQ3wqqAGQQ4$llNObb4yllt4nnvCRRE4nncittB;yyszggPSccJOXX3~QQcINNV1QQA}llm[ppd^qq69ttGFMMB7mmpdXXk)QQ4Lww2QuuJ]99RxQQ1YVVeVooxGxxe!ll1.IIKKppv'ddU2ooeuNNp,ttxvXX1OWWw|NNiJvvrCxxMkppf&jjx_ttvzoo3XmmG0qqB pp2jxx53bbx4gg1YwwwBMMAInnw&LLcJggJ@oo6GXX2cxx1illADnno\oo4%jjj?xxcIxxicSS2,ooE(WWw`NNy_QQr_NNP;SSe ggk<bbH/xxvNggwtjjzQjj4{ddtQbbKtxxMbWWzEgg5QCCcENNRFXXe?ddPnCCH7NNixxxc?ddPVXXekddcvCCcDdd4pjjK~XXtvggp;ddplxxep55RjhhH/IIN[llZUttAuggdoll5LllZzxxZvggeNll5lnnHmNNY.hhNZVVW-hhGvllg,kkeCHHE`bbNpFFPZttm-LLZ!vvx]MM4rvvzKggyybbp%VV5QppczttVlllv)XXA SSB!ddV/mm2T338(uue<llT.ggsXll5\jjGCqqK[SSw?II6XQQJtXXPJQQH{nnu@XXv,FFHxjjZGlll&ttx*SS3wWWGzbbJRggw2dccHHEE2iCCxOggIoWWfsddV8QQN^XXt>ggfESSVhXXwQddu_nnd{qquenn2Rll4Ejje3xx3Yjj4vnniwWW4yxxvfbb4zggkTmmNvllq>nnH<RRLHSSZ^wwN{bbJ}XXy*nn3M66s]ggH<dd32bbGMqqEfppeqjj1{uuHvoo6 mmc?LL6\bb1hNNuKjj1ejj8roo1|nnPhbbGfnnOSjjwLggmfppHjbbVEWW3<oo3'xxNIjjI^XXN"jjNopp39XXcCoo1\eeEammz}jju wwr"ddywggdFddk/SS1gXXL*mme Ukkkf:NNL'ppNDSS1%SSwxLLr\WWvFVVJ'uurVNNt0XXrpqqIappe VVf%XXpHNNx_WWvHwwP3bbZKnnJIvvH666e.ooJcddbxvvH]XXYYvvH}UUHrbbvl00swllw@nn3Hxx4Rqqs,SSwubb2/uuzennVDmmwU11R`ppf5bbV>kkrQXXPMww4Hjjb2ppeF00moppd)55B>yys(ggO0oor\ddvLppvKjj2CpprmSSZ`ggwsxxz_SSvcIIhrXXdjnnT$uuN_VVaSXXNm55BkkkBAgg3)jjp=XXiGWW3bgguolld/bbH;oow,00jdbbx(ooPzbb25FF4>kkmHbbEcww2]NNs8mmH@LLikuufnddN#ggpvggc!vvN#ggv,wwe2VVJpbb1<lln$oozbNNxuCCHMRRUSggH611VdSS4taaHXCCvwVVKDkkc{jjI4vvcsww5_nnG6SSEQWWmfxxxBXXeHXXVhuu1)00suCCe3ww6IWW2!MMEsvvxWVVhJuu12uu5Qnn4Djjg(XX3(SSATnnJjNNz#WW1 nndgww3;ll6!SSJ?LLM}jjB}xxOvbbH6qq3|uuc@jjtwwwfw00krnnrzFF1awwN*jjm"CCGUXXNGllH*nnatuuetqq6#ggH[ooPexxmObbHoccG(xxCFccJgFFJqooKYddVnuuKnee1#xx44qqHwwwwnqqjMuu3wqqr@xxHpRR1KCCf]VVp/vvd}LLcHXXvFIIrxjjfMIIz-mmznHHEnbbJpjjoJggz0xxe2oop0jjw'mm4Faa5fxxddNNTzggwPeePQxxw jjuuxxfJddM mmHvLLw4jj17FFJ nn3QnnH8XXm5nndCooJXIIB}SSexXXtTXXx;NNqoggwcqqJ}WWmznnA6ppH3ggK]bbG VVRlXXK^NN8 hhG(ooAiSS1gxxbcjjH,aa1HXXdrjjPtuuz{gg5 QQc@XXoGWWf2jjucCCJ0662!xxwfggKvjjd;llgbxxwIjjKcSSHjNNl}ll3qNNlNWWfe00ZmxxpwooR6ggcSbb3?QQz_xxR.ll2=LLg[kkv&LLv1wwGsbb23jjf>99RMQQ1ORR3*jj1,NN1%nnxTuuEQQQ3z66x?ww15xxh\pp2N333*XXpqggmBbbK1FFJRXXxZuuAIttwPddnJooKiddwyXXfGRRYdjjNuLLf~SS4/MMJ$vvN"ddk_ttc$xxY7ppedXXCHXXd#ggg,oos@llibxxv`LLoFjj32LLgxooeGnnHYllm9LLP<pp2™R&QQzhwwVlxxvNxxsaXXr`XXdcCCwu33sDoodFNNa9nnHq66BbSSJ LLOCuu2xggJ ttp,xxW7ggKeVVImhhK]VVi mmz[NN5BbbJAEEJ^ppGuqqGkllZ'xxZ1pp4nooH)uuf<LLYdSSK:ooJTmmKKuuR"mmZSnnY%SSN[ddjAppp1VV5|oodr55HPhhNlnnv|CCGNSSE[pp34NNkzkkfVggs[WWw|XXEsnnr1ggWuQQKhXXTmppN'66a>nnpSqqPeXX2;ww5AXXfiIIv{ll1|qqURCCv`VVBWWWev00tOttB~EEB^QQHCllWdnnK|gg1Skkx855R}ggp'XXb&mmH[NNTrSSJ4XXUtvvdHlld3nnwHaa2attGfMMBxpp2wNNNFllJkFFRDQQH.IIl.QQdzqqtkoorAVVbPooe(qq6TvvxPnnG?WWpbjj1]uup$aaPiSSp1VVh7bbJ[NNCaSSeFeeVQccKIjjoXCCc*XXdXnnz#NNEqvvBuLLqzggdP552dnn4wggCxmmdm66e,kkwG554VSS1)tt2|CCpZddZdbbN0uu6vpp4{MM4PllNPddVCppx6XXl1oox<66B9QQNf66n4jjd&ddr(oop.dd6ummxIVVG kkv"nngHxxGNVVj^CCzPqqu{vveN66I~uuxGee2lCCcdeeE6ttxaddq2XXxVMMJrnnv100UekkcWbb1<wwG=llqmCCd}MMR"oormnnMNppeLnnJTSSzvSSAgttvUggP0XXA.llrqggwjVV2NQQw566Z7XX2/MM5iQQHuxxHKQQ2ALLJrxxmceeZhoo2XXX1:nnZJnnrYwwzSjjdRooJJggY{nnB'llP4ll2hRR1jQQp"ee3ChhK.LLR0nnvrggJMnnG5aa6qggHPddhlwwzJXX8QQQpvjjH&CCeN66U,mmd2jjIEoovFVV1MWWw_lli[XX47ggk:oo24xxcexxw~EEZ`ggNTbbA'vvK\ooH[nneZ996QllznaaViQQfKXXJ'XXK*LLeIttp&xxZJCCNQxxk$llve111)llZ5bbJeWWJnooE7kkrsllu5llJ~XXzHllJQllcollHwxxu>gge$00Z4uuAellWvllG"xxHLooH*qqW.QQ4%XXqtggppVVb ll1 llsjnnwNjjZPvvfFddM{llx!dd8~vvG,bbE`wwGeFFZ:XX1KggxHCCfwnnR"nnH/llsbuu1nggvrmm2QVVM4llf ggIollN:LL4Ypp2ySSH}QQ41jjnoppNpLLH8oow"VVIMWWc=NN3Kuu30nnxIoorpSSZ?bb2KllT\jj1 66mvuuz3HHRlllvqggxvggvQVVx;wwmELLEJoorTjjT$vvz,nnqWllA,xxyubbZDllz3SSApee1YQQ4:ddnqXXJclle'ggexddcGttvWooA/nnv$XXJkSSHw00y"jjH:llGcllN@ggJ*WWzijjlLvvz-qqz/jjdqbb1Wvvs(llB%SSNkVVZ0llvQIIWynnKTFFAWvvpKjjehccJoHHP7uuv?UUHEWWxxnndMCCe/NNz6CCH`99Zxbbm8nnO!QQ4!ddi8kkvi33Z?jjfd00lzbbZrllnkxx2mjjE*lleySSJBmmNQqqO#QQNMqqO1nnHBuu6?SSK]oo6jSS2|66vEQQcDLLtkXXZWXXt{hhKpxxG%ll1allUlxxKaqqI0mmZ]nns(ggryggI_xxfONN1jvvv@llCdCCeINNlXQQwsRRceppf`II2:pp1_LL4iXXHq00NjppfE668~wwJ/ggm)nnNsqqkrXXNI66ngQQHaIIaMjje9eeZ uuwoqqi/wwsDxx1'kkfE00ZsbbJ VVojttB}EEByQQJ6ddI0nnm@tt8>ttJ333BkQQ4^llDzbb2pddDuuuz@ee1ruuzXeeEOuuGGbb3%ttBwEEB2SSzuqqi-uus[ddvMvvH;552:uuHXjjJDxxw)MMPwttGgMMBImmfL336gooH/jjzlvvfUIIy4hhHlFF4fuucjVVa6QQ1Fll38kkw<XXfknnNDHH3"CCd,XXRIll1_qqoySSwaRRenxxw4jjkpQQrLdd63ggr`LLk8pp2^xxg6mmH;MM3?XXcaVVkfQQsfllOqCCp:llC4nnxbbbN}ww3|qqMbww4;qqC|pps MM2`ttc.XXo=uumsllugppsexxl;jj4GVV5[nnr&XXAwmmKzXXkbxx3FnnmDhhK-xxTnWWKtXX3Ppp2gNNU,nnw2ooExoo3'nnZQwww<II6!WWv=55ZLnnZUggu}SSAMddv4nnJ;66drjj4:lljagge{SSEIWWGDVV5-XXeh00RlwwxNll3qCCe@555voopLooH`ooz]ttZvggHjooV~ggm4llO@kkxbxxy-vvHellKZkkw?qqnwjj3`MMHdkkcxddbPjj4:llB'SSJ{nnp7ppdgllWhuuAWLL2#ggHkjjWpbb3666xcuuwabb2MnneceeJ)ppGtddy#uu4wddCOQQN=qqugwwBixxT=xx1nnnU/WW3OllqFjjGNjjA7wwp]xxfQllwAFF3]ooxTFFZBvvd1lltiWWG llrVuuJ\nnZ$XXedUU3GbbH,XXA`ww4FNNO(xx4!XX3@QQJfVVV2hhHYLLHnuu3<jjZ1kkd6VVwUSSf~xxK3nn4>XXvfllebggvmlld#66WfSSdlnnx9QQw$llB%vvxRNN3ouudT66YKCCeAaaP-WWe RRx]jjc ll2"wwK*llicWWphjjrLooz1qqWIvvmKMMN7lldyww5#uuK\LLT9ww1uRRL:mm3}bb2bCCf'XXW2mme 11B=yysVggERSSJ700JbWWv}RRDLSS2txxA7XXJ/xxAMttG MMB}SSrPggTEnnBP666UQQ4OxxVIQQJbllIYnnvbddY*nnfS33NXbbvb66H~CCv=0033WWf'NNMmWWms66G,QQ2p11B}yysfggAVnnvPXXDiWWf/IIG]XXx]00GRQQc%qqY&CCm-tt8tttNUjjTfnnK`ll4Bbbc/ggN2ccdrRRwgXXc4llT/SSJ!NNV|QQr{uuBoyys,ggA"nnv!XXDESS4zxxE1nnd]00OAnnc|HHB$kkBkgg3PSSflllVXXXfzxx1 XXcxllT)SSJ^NNV!QQfuxxZmWWriaaBQyysFgg1hwwrILLlyuudyNNi;jjp$jj3AxxN{qqOPbbBktt8*ttH]33y^oo17bb2?bbNDxxiUvvf/LLe^WWGoxx1pSSv&33RmmmKoNNo2mmw]11ZVttwK33ZfQQceLLUewwzyjjnwggrLVVU*kkcqFF1Bjjd<NNBGppc"LL8cooZmxxi0hhG8ggscWW3xbbEYSSf2MMHlppc\NNckuudDjjl7SSwoeeA*nne#00cQnnJZUUNAbb2pnnAruuZ3ddh^nnNR66K;mmfA33j!QQp,qqG8SSHuNNUPmme$ggY:llexqqz@hhH=VVM?CCJiHHN*llw-00eSCCJlee6lkkfN33I9oomjwwNPjjJ3RR1!xxd;LLdWggH5ttRSggfPLLzzoownnnT%ww3i66y5XXcEddHDggr|qqUTkks*xxMWwwr ddj5llKrFFN_CCv;nns.XXvMII1?bbKÝAhmmw,qq3FWWcHNN2}jj4oxxxOnne5ddjslle/IIJUppHO66Thnn1,RRr8jjG*jjj8hhH]99V`WWs-nnL7nnmQnndaggvcSS2/ooZ"llfittm#ww2VQQZpnnzqttxcLLt~uuc]llGYbbB|ooZUww2Q66B&QQHpxxk=bbwT11Hqmme/115@bbJowwEbmm2MjjZkbbmyddWxQQp!nnu[uuJ"NNgLggwfXXrqppH*xxr0kkw,ddBjQQc?VVsOxxK1VVJ7nnB1MM1knnz~jjj0QQHDggM\mmAgwwRRnnxESSEsbb3:xxO.SSxTggrMppBwllW7xxJmLLj@jjK$ooZrxxK%XXsXmmfxLL34CCvNXXk,nnxwXX1_vvcpnnG_jjdVttBHyys(gg1tQQBpllf6uuxGxxItXXZsjjA(ll2PMMBvkkBztt58ww4ojjO;vvJ1NNGPbbc?XXGzkkd7XXtcCCN,VVWeppf xxybWWv!XXZ"uuZdddNEQQK5qql4kkcrXXCBvvvW00OeWWJsXXwKmmN:LL8DCCp&VVj}wwG'ddI(ggczggGzmmz{bb1_SSJ=ddzBSSwWxxu)kkxRqqpjXXf/LL6fQQp/jjqjSSJ/dd4rppv'ooH2bbc-qqitwwx/jjgDnnd?qqJ wwK=VVd;vvN,uuJfbbG9ggV7SSfy335SmmzcVVM;wwe_aa1IWWZ?ddH-oo4,FFPPppNIdd4=WWdfnn6uggctFFNCXXvURROdmmf~llq3mmfvllI[vvN0XX3FwwxCNNtGSSeO00HQQQ4!xxtHuumjddTgCCwBIIJ0ggvflliPxxeAllTRSS2GddtEnnr:bb6=kkc[NNtkQQHP66y{nnesqqCAbbJkHHPGWW1cnne?WWeCqqPgbbwCXXUTxxeCqq13pp4\LL5<pps2ddW"QQwFXXkYmmBAddimXXGWxxm^wwvUggBYooJKRRAxwwGkjjpMjjZ[wwNtooc>qqq/ww2s33ERkkzkVV6*mm24UUPSuu3Ijji CCKcggywbb4~ww2LkkrSeeP6nnc>ttBNyys~gg1ASSJzddGGnnx^00UHQQ2<XXDUSS2rxxA$XXJ<xxA@ttG>MMBLQQf(00K}yyJlVVI&QQvA33L/QQf(NNO3nncPllMDbbc<ooYcbb2J00IMttBeEEBSXXrVggV5bb2<xxD XXc|ggUncc2UnnT?SSJM33V>XXsItt8GttJDVV1/XXrvaa8bccso00SDyyA\xxZpccsH00Gjnn2iHHIfbbJXNNYmccs1001DSSJ0ddG]nnm366G"nn2(HH/BWWxX00U8QQ2LSS0WggcWFFJ;CCd800ZynncDgg2|WWvajjN;XXJrxxA|iimvxxZUggK9VVDfSS2uxxA{XXJ\NNG5nnviNNH iimtxxZwggKyVVDGbb2400I<QQvkxxYOXXzu11NjSSAkttUittKIxxE"nndY003{SSJ'RRD]nnJ000AYQQvkdd1sttGDMMBUWWrKll1HSSzlLLS=yy3'EETAggcrjjS/yy2?jjK/WWmb33B:WWvw66Swyy2SXXN7XXdf00EaSSJw001qnnvOjj1iyyJ-jjKYWWp 005Xcc40jjNzSSKZnnLIbb2xxx2fnncqtt03ggc7uuJbCCd&00ZSnncIgg2MWWvVjjNMWWv-oo0'ggc=uuJlCCdQ00K_XXvpNNHWcc2eXXN2QQGX11NqSSA{ttU*ttKpnnN?SSKtjjL[QQ2|55B'kkB!ggIHbbJp001Bcc2=jjV\ccZSaaR!jjzPaaR/uuz4tt2vjjm;gg0PAD_tDRUIxukMdsjmfWNkshtcQrxjVUoqczAvqusVFaZOQuujOJMriyVhkQdzw_aCsRaelsbiIcgWFjGqhxehHLJsTI<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><ms_windowsSettings:dpiAware xmlns:ms_windowsSettings="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</ms_windowsSettings:dpiAware></windowsSettings></application></assembly>PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
<$=,=6=<=
5_6v6
5!5(5;5^5
8"8&8*8.82868=8
4#4 434;4
7.8=829^9
7(8?8]8}8
<#<,<5<><
5#5'5 5/535
4(565<5\5}5
< <$<(<6<
4%4X4{47"7)7?7_7
2%2U2o2
78
5(6.646:6
;"<&=:=\=
6e6C6k6
9Ÿ9^9z9
3#4-4M4e4}4
7!7'7.797_7
2*3034383<3
5!5%5)5-5
1%1<304|4
7 7$7(7,707
7 7$7(7,7074787<7
5 5$5(5,5054585<5@5
< <$<(<,<0<
1 1$1(1,1
6 6$6(6,606
7 7$7(7,7074787<7@7\7`7|7
5 5$5(5@5
6$6,686`6
2$2,282\2|2
8 8(808<8`8
7 7(707<7`7
2 2(202<2`2
; ;<;@;`;
2 2<2@2`2
? ?$?(?,?0?4?8?<?\?
upd_url_format
trace_url_format
reg_supd_key
Software\Wnkey
%s\%s
X-X-X-X-X-X
Auser32.dll
4294967295
SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
%s-%s
%s: %d
%s: %s
HttpOpenRequest failed: %lu
HttpSendRequest failed: %lu
%8x-%4x-%4x-%2x%2x-%2x%2x%2x%2x%2x%2x
CWindows XP
Windows Server 2003
Windows Vista
Windows 98
Windows Me
Windows 2000, Windows NT 4.0, or Windows 95
Win32s on Windows 3.1.
OS: %s, SP: %s, STATE:%d, HOME:%s
C%d.%d
.----/01/01/01
{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|{|File%d
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
KERNEL32.DLL
%s%s.dll
E%s (%s:%d)
%s (%s:%d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
Advapi32.dll
Ff:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
accKeyboardShortcut
wuser32.dll
hhctrl.ocx
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
Fcomctl32.dll
Fcomdlg32.dll
Fshell32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin1.inl
kernel32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
{X-X-X-XX-XXXXXX}PTF://
hXXp://
AWININET.DLL
HTTP/1.0
mfcm100u.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
OLEAUT32.DLL
%sCLSID\%s
%d.%d
TYPELIB\%s
CLSID\%s
CLSID\%s\%s
SHELL32.DLL
lXXxXXXXXXXX
dwmapi.dll
UxTheme.dll
eShell32.dll
%s:%x:%x:%x:%x
r%s\shell\open\%s
%s\shell\print\%s
%s\shell\printto\%s
%s\DefaultIcon
%s\ShellNew
%s\ShellEx
\{8895b1c6-b41f-4c1c-a562-0d564250836f}ddeexec
Hf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
f{8895b1c6-b41f-4c1c-a562-0d564250836f}{E357FCCD-A995-4576-B01F-234630154E96}Software\Microsoft\Windows\CurrentVersion\PreviewHandlers
%s\ShellEx\%s
COMCTL32.DLL
USER32.DLL
%sMFCToolBar-%d%x
%sMFCToolBar-%d
ShortcutKeys
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
IDB_OFFICE2007_RIBBON_KEYTIP_BACK
KEYTIP
%sKeyboard-%d
KeyboardManager
%sCommandManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
propsys.dll
%2x%2x%2x
xxx
%s(%i)
MFCLink_UrlPrefix
MFCLink_Url
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
&%d %s
%s-%d
%sMDIClientArea-%d
Zf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewform.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
Aexe
%sBasePane-%d%x
%sBasePane-%d
%sMFCRibbonBar-%d%x
%sMFCRibbonBar-%d
%sPane-%d%x
%sPane-%d
windows
ShowCmd
QHex={X,X,X}1&0 %s
Y%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
Yf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olefact.cpp
Ymsctls_hotkey32
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
A%c%d%c%s
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olecli1.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
[%d, %d, %d
%d, %d
\RICHED32.DLL
RICHED20.DLL
\%s %s
\f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
%s-Bar%d
%s-Summary
MRUDockLeftPos
Bar#%d
RGB(%d, %d, %d)
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
^f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\dockcont.cpp
^f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olelink.cpp
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
ADVAPI32.DLL
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]
mbot_ca_014010265.exe_1736:
.text
`.rdata
@.data
.rsrc
@.reloc
.FGy"
u&u
u.VWhD
8sqliu
u.Whd
2 34 567
%STUV
F><.tN<[tJ<\tF<*tB<|t><^t:<$t6
tWSShW
tl9_ tgSSh
u$SShe
t'SShl
SSSSh
j%XtL9E
tAHt.HHt
<SShG
FtPW
SSh@B
FTCP
s%j.Zf
xSSSh
FTPjKS
FtPj;S
C.PjRV
8Y%u-
>.uEV
RR R!"RR#$RRRR%&'RRR(R)*R RRR,-.RR/0123RRRR4R5RRRRRRR6RRRRRR789:;<RRRRRRRR=RRR>?@ABCDERRRRFRRRRGHRRRRRIRRJKRRRRRLMRRRNNRRORRRRRRRRRPRRQ
!"EEE#E$Eî&E'()EEEE*EEEEEEEE EEEEEEEEEEEE,EE-.EEEEEEEEEEE/E0EEEEEEEEEEEEEE12EE345EE6789:EEEEEEEE;<EE=>?EE@EEEEEABCEEEEED^
%u$Vj%
tCPh
t.Gj:W
FTPG
FTPj
.EKSWU
SHA1 block transform for x86, CRYPTOGAMS by <[email protected]>
SHA256 block transform for x86, CRYPTOGAMS by <[email protected]>
DlSHA512 block transform for x86, CRYPTOGAMS by <[email protected]>
|$@3|$<3
Camellia for x86 by <[email protected]>
6-9'6-9'
$6.:$6.:
*?#1*?#1
>8$4,8$4,
AES for x86, CRYPTOGAMS by <[email protected]>
RC4 for x86, CRYPTOGAMS by <[email protected]>
Montgomery Multiplication for x86, CRYPTOGAMS by <[email protected]>
FtPS
CB_ColorKey
CB_Keydown
CB_Keyup
()$^.* ?[]|\-{},:=!CNotSupportedException
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
CCmdTarget
RegDeleteKeyExW
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
CMFCToolBarsKeyboardPropertyPage
operator
GetProcessWindowStation
portuguese-brazilian
F%D,3
dbghelp.dll
%Y-%m-%dT%H:%M:%SZ
Could not resolve %s: %s; %s
getaddrinfo() failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
About to connect() to %s%s port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
Protocol %s not supported or disabled in libcurl
<url> malformed
:]://%[^
[^:]:%[^
http_proxy
%5[^:@]:%5[^@]
:%5[^@]
Port number too large: %lu
%s://%s%s%s:%hu%s%s%s
;type=%c
[%*45[0123456789abcdefABCDEF:.]%c
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
User-Agent: %s
Re-using existing connection! (#%ld) with host %s
%s://%s
Connection #%ld to host %s left intact
operation aborted by callback
ioctl callback returned error %d
the ioctl callback returned %d
seek callback returned error %d
Problem (%d) in the Chunked-Encoded data
HTTP server doesn't seem to support byte ranges. Cannot resume.
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Unrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Rewinding stream by : %zd bytes on url %s (zero-length body)
Operation timed out after %ld milliseconds with %lld bytes received
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
Added %s:%d:%s to DNS cache
Resolve %s found illegal!
%5[^:]:%d:%5s
No URL set!
[^?&/:]://%c
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Disables POST, goes with %s
Issue another request to this URL: '%s'
unspecified error %d
%s cookie %s="%s" for domain %s, path %s, expire %lld
#HttpOnly_
skipped cookie with bad tailmatch domain: %s
skipped cookie with illegal dotcount domain: %s
httponly
23[^;
=]=I99[^;
%s%s%s
# Fatal libcurl error
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/rfc/cookie_spec.html
# This file was generated by libcurl! Edit at your own risk.
WARNING: failed to save cookies in %s
[%s %s %s]
Send failure: %s
Recv failure: %s
bind failed with errno %d: %s
Local port: %hu
getsockname() failed with errno %d: %s
Bind to local port %hu failed, trying next
Couldn't bind to '%s'
Name '%s' family %i resolved to '%s' family %i
Local Interface %s is ip %s using address family %i
ssloc inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
getpeername() failed with errno %d: %s
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Failed to connect to %s: %s
Trying %s...
sa_addr inet_ntop() failed with errno %d: %s
Unable to parse FTP file list
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Access Violation
TFTP: File Not Found
Login denied
Issuer check against peer certificate failed
Invalid LDAP URL
Unrecognized or bad HTTP Content or Transfer-Encoding
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with given CA certificates
Problem with the local SSL certificate
SSL peer certificate or SSH remote key was not OK
An unknown option was passed in to libcurl
A libcurl function was given a bad argument
Operation was aborted by an application callback
FTP: command REST failed
FTP: command PORT failed
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: The server did not accept the PRET command.
FTP: weird server reply
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
URL using bad/illegal format or missing URL
Unsupported protocol
Winsock version not supported
Protocol family not supported
Address family not supported
Operation not supported
Socket is unsupported
Protocol is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
Internal error removing splay node = %d
Internal error clearing splay node = %d
libcurl is now using a weak random seed!
not supported file type '%s' for certificate
file type P12 for certificate not supported
file type ENG for certificate not implemented
not supported file type for private key
Private key does not match the certificate public key
file type P12 for private key not supported
file type ENG for private key not supported
unable to set private key file: '%s' type %s
unable to use client certificate (no key found or wrong pass phrase?)
SSL Engine not supported
select/poll on SSL socket, errno: %d
SSL read: %s, errno %d
d-d-d d:d:d %s
common name: %s (matched)
common name: %s (does not match '%s')
SSL: certificate subject name '%s' does not match target host name '%s'
SSL: unable to obtain common name from peer certificate
SSL: illegal cert name field
subjectAltName does not match %s
subjectAltName: %s matched
CERT verify
Client key exchange
Server key exchange
CERT
Client CERT
Request CERT
Client key
SSLv%c, %s%s (%d):
SSL: SSL_set_fd failed: %s
SSL: SSL_set_session failed: %s
error loading CRL file: %s
CRLfile: %s
CAfile: %s
CApath: %s
successfully set certificate verify locations:
error setting certificate verify locations, continuing anyway:
error setting certificate verify locations:
SSL: couldn't create a context: %s
SSL connection using %s
SSL certificate problem, verify that the CA cert is OK. Details:
Unknown SSL protocol error in connection to %s:%ld
%s: %s
x:
%s(%s)
%s: %s
Signature: %s
Cert
RSA Public Key
RSA Public Key (%d bits)
pub_key
priv_key
Unable to load public key
Public Key Algorithm
Public Key Algorithm: %s
Expire date: %s
Start date: %s
Serial Number: %s
x%c
Signature Algorithm: %s
Issuer: %s
- Subject: %s
--- Certificate chain
SSL certificate verify ok.
SSL certificate verify result: %s (%ld), continuing anyway.
SSL certificate verify result: %s (%ld)
SSL certificate issuer check ok (%s)
SSL: Certificate issuer check failed (%s)
SSL: Unable to read issuer cert (%s)
SSL: Unable to open issuer cert (%s)
issuer: %s
expire date: %s
start date: %s
subject: %s
Server certificate:
SSL: couldn't get peer certificate!
SSL_write() return error %d
SSL_write() error: %s
SSL_write() returned SYSCALL, errno = %d
--:--:--
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
%s%s%s%s%s%s
Session: %s
%s %s RTSP/1.0
Range: %s
Referer: %s
Accept-Encoding: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Transport: %s
Transport:
Refusing to issue an RTSP request [%s] without a session ID.
Got RTSP Session ID Line [%s], but wanted ID [%s]
Unable to read the CSeq header: [%s]
SMTPS
SMTP
EHLO %s
HELO %s
AUTH %s
No known auth mechanisms supported!
AUTH %s %s
LOGIN
Access denied: %d
%s xxxxxxxxxxxxxxxx
Authentication failed: %d
MAIL FROM:<%s>
MAIL FROM:%s
RCPT TO:<%s>
RCPT TO:%s
STARTTLS denied. %c
Got unexpected smtp-server response: %d
USER %s
PASS %s
Access denied. %c
Invalid message. %c
RETR %s
LIST %s
%s LOGIN %s %s
%s SELECT %s
%s FETCH 1 BODY[TEXT]
%s LOGOUT
%s STARTTLS
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
invalid tsize -:%s:- value in OACK packet
%s (%ld)
blksize is smaller than min supported
%s (%d)
blksize is larger than max supported
%s (%d) %s (%d)
got option=(%s) value=(%s)
tftp_rx: internal error
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: giving up waiting for block %d
Received unexpected DATA packet block %d
tftp_tx: internal error, event: %i
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
bind() failed; %s
tftp_send_first: internal error
%s%c%s%c
TFTP finished
TFTP response timeout
Can't get the size of %s
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
There are more than %d entries
LDAP remote: %s
LDAP local: ldap_simple_bind_s %s
LDAP local: Cannot connect to %s:%hu
LDAP local: trying to establish %s connection
LDAP local: %s
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
CLIENT libcurl 7.22.0
MATCH %s %s %s
DEFINE %s %s
insufficient winsock version to support telnet
WSAStartup failed (%d)
%s %d %d
%s %s %d
%s %s %s
%s IAC %d
%s IAC %s
Sending data failed (%d)
%d (unknown)
%s (unsupported)
%s IAC SB
Syntax error in telnet option: %s
Unknown telnet option %s
7[^= ]%*[ =]%5s
USER,%s
%c%c%c%c%s%c%c
%c%s%c%s
7[^,],7s
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
FTPS
PORT
FTP response aborted due to select/poll error: %d
FTP response timeout
%s %s
,%d,%d
%s |%d|%s|%hu|
bind() failed, we ran out of ports!
bind(port=%hu) failed: %s
socket failure: %s
Curl_resolv failed, we can not recover!
getsockname() failed: %s
Connect data stream passively
PRET RETR %s
PRET STOR %s
PRET %s
REST %d
SIZE %s
STOR %s
APPE %s
Failed to do PORT
Got a d response code instead of the assumed 200
ftp server doesn't support SIZE
Failed FTP upload:
RETR response: d
PBSZ %d
Access denied: d
ACCT %s
ACCT rejected by server: d
TYPE %c
Connecting to %s (%s) port %d
Uploading to a URL without a file name!
MDTM %s
Bad PASV/EPSV response: d
Can't resolve new host %s:%hu
Can't resolve proxy host %s:%hu
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
%c%c%c%u%c
ddd d:d:d GMT
dddddd
unsupported MDTM reply format
QUOT string not accepted: %s
Wildcard - "%s" skipped by user
Wildcard - START of "%s"
CWD %s
PRET command not accepted: d
Failed to MKD dir: d
MKD %s
QUOT command failed with d
Entry path is '%s'
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
Got a d ftp-server response when 220 was expected
server did not report OK, got %d
Remembering we are in dir "%s"
HTTPS
%sAuthorization: Basic %s
%s:%s
%s auth using %s with user '%s'
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %d
If-Unmodified-Since: %s
Last-Modified: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Failed sending HTTP request
%s%s=%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
PTF://%s:%s@%s
Content-Range: bytes %s/%lld
Content-Range: bytes %s%lld/%lld
Range: bytes=%s
PTF://
Host: %s%s%s:%hu
Host: %s%s%s
Chunky upload is not supported by HTTP 1.0
%s, TE
HTTP error before end of send, stop sending
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
RTSP/%d.%d =
HTTP =
HTTP/%d.%d =
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
SOCKS4%s request granted.
Failed to resolve "%s" for SOCKS4 connect.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
password
login
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
%sAuthorization: NTLM %s
%s, algorithm="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop="%s", response="%s"
%s:%s:x:%s:%s:%s
%s:%.*s
%s:%s:%s
Error while processing content unencoding: %s
1.2.0.4
d:d
%c%c==
%c%c%c=
Received HTTP code %d from proxy after CONNECT
HTTP/1.%d %d
CONNECT %s:%hu HTTP/%s
%s%s%s%s
Host: %s
%s:%hu
Establish HTTP proxy tunnel to %s:%hu
0123456789-
.jpeg
.html
--%s--
couldn't open file "%s"
Content-Type: %s
; filename="%s"
Content-Disposition: attachment; filename="%s"
Content-Type: multipart/mixed, boundary=%s
%s; boundary=%s
NTLMSSP%c
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%s%s
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
KGS!@#$%.rnd
\X
X.509 part of OpenSSL 1.0.0e 6 Sep 2011
OPENSSL_ALLOW_PROXY_CERTS
passed a null parameter
DSO support routines
x509 certificate routines
error:lX:%s:%s:%s
ASN.1 part of OpenSSL 1.0.0e 6 Sep 2011
d.registeredID
d.iPAddress
d.uniformResourceIdentifier
d.ediPartyName
d.directoryName
d.dNSName
d.rfc822Name
d.otherName
Stack part of OpenSSL 1.0.0e 6 Sep 2011
x%s
%s - d:d:d%.*s %d%s
%*s<Not Supported>
%*s%s
%*s%s:
CERTIFICATE
Big Number part of OpenSSL 1.0.0e 6 Sep 2011
unsupported or invalid name syntax
unsupported or invalid name constraint syntax
unsupported name constraint type
name constraints minimum and maximum not supported
Unsupported extension feature
invalid or inconsistent certificate policy extension
invalid or inconsistent certificate extension
key usage does not include digital signature
key usage does not include CRL signing
unable to get CRL issuer certificate
key usage does not include certificate signing
authority and subject key identifier mismatch
certificate rejected
certificate not trusted
unsupported certificate purpose
proxy certificates not allowed, please set the appropriate flag
invalid non-CA certificate (has CA markings)
invalid CA certificate
certificate revoked
certificate chain too long
unable to verify the first certificate
unable to get local issuer certificate
self signed certificate in certificate chain
self signed certificate
format error in certificate's notAfter field
format error in certificate's notBefore field
certificate has expired
certificate is not yet valid
certificate signature failure
unable to decode issuer public key
unable to decrypt certificate's signature
unable to get certificate CRL
unable to get issuer certificate
cert_info
OpenSSL 1.0.0e 6 Sep 2011
MD5 part of OpenSSL 1.0.0e 6 Sep 2011
libdes part of OpenSSL 1.0.0e 6 Sep 2011
DES part of OpenSSL 1.0.0e 6 Sep 2011
MD4 part of OpenSSL 1.0.0e 6 Sep 2011
RAND part of OpenSSL 1.0.0e 6 Sep 2011
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
RSA part of OpenSSL 1.0.0e 6 Sep 2011
DSA part of OpenSSL 1.0.0e 6 Sep 2011
.\crypto\ec\ec_key.c
Diffie-Hellman part of OpenSSL 1.0.0e 6 Sep 2011
supportedAlgorithms
crossCertificatePair
certificateRevocationList
cACertificate
userCertificate
userPassword
supportedApplicationContext
Microsoft Local Key set
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
certificateIssuer
certicom-arc
Proxy Certificate Information
proxyCertInfo
Microsoft Smartcardlogin
msSmartcardLogin
joint-iso-itu-t
JOINT-ISO-ITU-T
set-rootKeyThumb
setAttr-Cert
setCext-cCertRequired
setCext-certType
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertResData
setct-CertReqTBS
setct-CertReqData
setct-PCertResTBS
setct-PCertReqData
setct-AcqCardCodeMsg
certificate extensions
set-certExt
set-msgExt
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-mod-msg-v3
sdsiCertificate
x509Certificate
localKeyID
certBag
pkcs8ShroudedKeyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
extendedKeyUsage
X509v3 Authority Key Identifier
authorityKeyIdentifier
X509v3 Certificate Policies
certificatePolicies
X509v3 Private Key Usage Period
privateKeyUsagePeriod
X509v3 Key Usage
keyUsage
X509v3 Subject Key Identifier
subjectKeyIdentifier
Netscape Certificate Sequence
nsCertSequence
Netscape CA Policy Url
nsCaPolicyUrl
Netscape Renewal Url
nsRenewalUrl
Netscape CA Revocation Url
nsCaRevocationUrl
Netscape Revocation Url
nsRevocationUrl
Netscape Base Url
nsBaseUrl
Netscape Cert Type
nsCertType
Netscape Certificate Extension
nsCertExt
extendedCertificateAttributes
challengePassword
dhKeyAgreement
value.single
value.set
ssl_sess_cert
ssl_cert
evp_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
X509_PUBKEY
public_key
.\crypto\asn1\x_pubkey.c
<ASN1 %d>
appl [ %d ]
cont [ %d ]
priv [ %d ]
'() ,-./:=?
%d.%d.%d.%d/%d.%d.%d.%d
ddddddZ
ddddddZ
lhash part of OpenSSL 1.0.0e 6 Sep 2011
TRUSTED CERTIFICATE
CERTIFICATE REQUEST
NEW CERTIFICATE REQUEST
RSA PRIVATE KEY
DSA PRIVATE KEY
EC PRIVATE KEY
X509 CERTIFICATE
/usr/local/ssl/certs
/usr/local/ssl/cert.pem
SSL_CERT_DIR
SSL_CERT_FILE
%lu:%s:%s:%d:%s
%sx - <SPACES/NULS>
x -
PEM part of OpenSSL 1.0.0e 6 Sep 2011
phrase is too short, needs to be at least %d chars
Enter PEM pass phrase:
PRIVATE KEY
ENCRYPTED PRIVATE KEY
ANY PRIVATE KEY
name.relativename
name.fullname
certificateHold
Certificate Hold
cessationOfOperation
Cessation Of Operation
keyCompromise
Key Compromise
%*sOnly Attribute Certificates
%*sOnly CA Certificates
%*sOnly User Certificates
PROXY_CERT_INFO_EXTENSION
AUTHORITY_KEYID
keyid
X509_CERT_PAIR
X509_CERT_AUX
USER32.DLL
NETAPI32.DLL
KERNEL32.DLL
ADVAPI32.DLL
EC part of OpenSSL 1.0.0e 6 Sep 2011
.\crypto\dh\dh_key.c
%s: (%d bit)
Public-Key
Private-Key
recommended-private-length: %d bits
public-key:
private-key:
PKCS#3 DH Public-Key
PKCS#3 DH Private-Key
Public-Key: (%d bit)
Private-Key: (%d bit)
SHA1 part of OpenSSL 1.0.0e 6 Sep 2011
SHA-256 part of OpenSSL 1.0.0e 6 Sep 2011
SHA-512 part of OpenSSL 1.0.0e 6 Sep 2011
<unsupported>
IP Address:%d.%d.%d.%d
URI:%s
DNS:%s
email:%s
EdiPartyName:<unsupported>
X400Name:<unsupported>
othername:<unsupported>
pubkey
enc_key
key_enc_algor
cert
d.encrypted
d.digest
d.signed_and_enveloped
d.enveloped
d.sign
d.data
d.other
EC_PRIVATEKEY
publicKey
privateKey
value.implicitlyCA
value.parameters
value.named_curve
p.char_two
p.prime
p.ppBasis
p.tpBasis
p.onBasis
p.other
PKCS8_PRIV_KEY_INFO
pkey
pkeyalg
.\crypto\evp\evp_pkey.c
keylen <= sizeof key
EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)
%*sPolicy Text: %s
%*scrlUrl:
EXTENDED_KEY_USAGE
%*sZone: %s, User:
.\crypto\x509v3\v3_akey.c
d.usernotice
d.cpsuri
CERTIFICATEPOLICIES
%*sExplicit Text: %s
%*sNumber%s:
%*sOrganization: %s
%*sCPS: %s
PKEY_USAGE_PERIOD
keyCertSign
Certificate Sign
keyAgreement
Key Agreement
keyEncipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
NETSCAPE_CERT_SEQUENCE
certs
.\crypto\pem\pem_pkey.c
.\crypto\asn1\x_pkey.c
.\crypto\evp\evp_key.c
nkey <= EVP_MAX_KEY_LENGTH
EVP part of OpenSSL 1.0.0e 6 Sep 2011
?456789:;<=
!"#$%&'()* ,-./0123
ECDSA part of OpenSSL 1.0.0e 6 Sep 2011
Basis Type: %s
Field Type: %s
ASN1 OID: %s
%s %s%lu (%s0x%lx)
hexkey
rsa_keygen_pubexp
rsa_keygen_bits
RIPE-MD160 part of OpenSSL 1.0.0e 6 Sep 2011
SHA part of OpenSSL 1.0.0e 6 Sep 2011
CAST part of OpenSSL 1.0.0e 6 Sep 2011
Blowfish part of OpenSSL 1.0.0e 6 Sep 2011
RC2 part of OpenSSL 1.0.0e 6 Sep 2011
.pp@0
aEÐ
(#EÚ
ÚE<<0
IDEA part of OpenSSL 1.0.0e 6 Sep 2011
len>=0 && len<=(int)sizeof(ctx->key)
j <= (int)sizeof(ctx->key)
keylength
keyfunc
.\crypto\pkcs12\p12_key.c
crlUrl
certStatus
certId
OCSP_CERTSTATUS
value.unknown
value.revoked
value.good
value.byKey
value.byName
reqCert
OCSP_CERTID
issuerKeyHash
CONF part of OpenSSL 1.0.0e 6 Sep 2011
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
d.receiptList
d.allOrFirstTier
d.compressedData
d.authenticatedData
d.encryptedData
d.digestedData
d.envelopedData
d.signedData
d.ori
d.pwri
d.kekri
d.kari
d.ktri
CMS_PasswordRecipientInfo
keyDerivationAlgorithm
keyIdentifier
CMS_KeyAgreeRecipientInfo
recipientEncryptedKeys
CMS_OriginatorIdentifierOrKey
d.originatorKey
CMS_OriginatorPublicKey
CMS_RecipientEncryptedKey
CMS_KeyAgreeRecipientIdentifier
d.rKeyId
CMS_RecipientKeyIdentifier
CMS_OtherKeyAttribute
keyAttr
keyAttrId
CMS_KeyTransRecipientInfo
encryptedKey
keyEncryptionAlgorithm
certificates
d.crl
d.subjectKeyIdentifier
d.issuerAndSerialNumber
CMS_CertificateChoices
d.v2AttrCert
d.v1AttrCert
d.extendedCertificate
d.certificate
CMS_OtherCertificateFormat
otherCert
otherCertFormat
CONF_def part of OpenSSL 1.0.0e 6 Sep 2011
[[%s]]
[%s] %s=%s
Verifying - %s
ECDH part of OpenSSL 1.0.0e 6 Sep 2011
value.bag
value.safes
value.shkeybag
value.keybag
value.sdsicert
value.x509cert
value.other
%s.dll
%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%s
EXPORT56
EXPORT40
EXPORT
.\ssl\ssl_cert.c
wrong number of key bits
unsupported status type
unsupported ssl version
unsupported protocol
unsupported elliptic curve
unsupported digest type
unsupported compression algorithm
unsupported cipher
unknown pkey type
unknown key exchange type
unknown certificate type
unable to find public key parameters
unable to extract public key
unable to decode ecdh certs
unable to decode dh certs
tried to use unsupported cipher
tls peer did not respond with certificate list
tls client cert req with anon cipher
tlsv1 unsupported extension
tlsv1 certificate unobtainable
tlsv1 bad certificate status response
tlsv1 bad certificate hash value
tlsv1 alert export restriction
sslv3 alert unsupported certificate
sslv3 alert no certificate
sslv3 alert certificate unknown
sslv3 alert certificate revoked
sslv3 alert certificate expired
sslv3 alert bad certificate
signature for non signing certificate
reuse cert type not zero
reuse cert length not zero
public key not rsa
public key is not rsa
public key encrypt error
peer error unsupported certificate type
peer error no certificate
peer error certificate
peer did not return a certificate
null ssl method passed
no publickey
no private key assigned
no privatekey
Peer haven't sent GOST certificate, required for selected ciphersuite
no client cert received
no client cert method
no ciphers passed
no certificate specified
no certificate set
no certificate returned
no certificate assigned
no certificates returned
missing tmp rsa pkey
missing tmp rsa key
missing tmp ecdh key
missing tmp dh key
missing rsa signing cert
missing rsa encrypting cert
missing rsa certificate
missing export tmp rsa key
missing export tmp dh key
missing dsa signing cert
missing dh rsa cert
missing dh key
missing dh dsa cert
krb5 server rd_req (keytab perms?)
key arg too long
invalid ticket keys length
http request
https proxy request
error generating tmp rsa key
ecc cert should have sha1 signature
ecc cert should have rsa signature
ecc cert not for signing
ecc cert not for key agreement
cert length mismatch
certificate verify failed
bad ecc cert
bad dh pub key length
TLS1_SETUP_KEY_BLOCK
tls1_cert_verify_mac
SSL_VERIFY_CERT_CHAIN
SSL_use_RSAPrivateKey_file
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey
SSL_use_PrivateKey_file
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey
SSL_use_certificate_file
SSL_use_certificate_ASN1
SSL_use_certificate
SSL_SET_PKEY
SSL_SET_CERT
SSL_SESS_CERT_NEW
SSL_GET_SIGN_PKEY
SSL_GET_SERVER_SEND_CERT
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_CTX_use_certificate_ASN1
SSL_CTX_use_certificate
SSL_CTX_set_client_cert_engine
SSL_CTX_check_private_key
SSL_CHECK_SRVR_ECC_CERT_AND_ALG
SSL_check_private_key
SSL_CERT_NEW
SSL_CERT_INSTANTIATE
SSL_CERT_INST
SSL_CERT_DUP
SSL_add_file_cert_subjects_to_stack
SSL_add_dir_cert_subjects_to_stack
SSL3_SETUP_KEY_BLOCK
SSL3_SEND_SERVER_KEY_EXCHANGE
SSL3_SEND_SERVER_CERTIFICATE
SSL3_SEND_CLIENT_KEY_EXCHANGE
SSL3_SEND_CLIENT_CERTIFICATE
SSL3_SEND_CERTIFICATE_REQUEST
SSL3_OUTPUT_CERT_CHAIN
SSL3_GET_SERVER_CERTIFICATE
SSL3_GET_KEY_EXCHANGE
SSL3_GET_CLIENT_KEY_EXCHANGE
SSL3_GET_CLIENT_CERTIFICATE
SSL3_GET_CERT_VERIFY
SSL3_GET_CERT_STATUS
SSL3_GET_CERTIFICATE_REQUEST
SSL3_GENERATE_KEY_BLOCK
SSL3_CHECK_CERT_AND_ALGORITHM
SSL3_ADD_CERT_TO_BUF
SSL2_SET_CERTIFICATE
SSL2_GENERATE_KEY_MATERIAL
REQUEST_CERTIFICATE
GET_CLIENT_MASTER_KEY
DTLS1_SEND_SERVER_KEY_EXCHANGE
DTLS1_SEND_SERVER_CERTIFICATE
DTLS1_SEND_CLIENT_KEY_EXCHANGE
DTLS1_SEND_CLIENT_CERTIFICATE
DTLS1_SEND_CERTIFICATE_REQUEST
DTLS1_OUTPUT_CERT_CHAIN
DTLS1_ADD_CERT_TO_BUF
CLIENT_MASTER_KEY
CLIENT_CERTIFICATE
TLSv1 part of OpenSSL 1.0.0e 6 Sep 2011
SSLv3 part of OpenSSL 1.0.0e 6 Sep 2011
SSLv2 part of OpenSSL 1.0.0e 6 Sep 2011
s->session->master_key_length >= 0 && s->session->master_key_length < (int)sizeof(s->session->master_key)
c->iv_len <= (int)sizeof(s->session->key_arg)
s->s2->key_material_length <= sizeof s->s2->key_material
key expansion
client write key
server write key
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
.\crypto\engine\eng_pkey.c
Load certs from files in a directory
%s%clx.%s%d
unsupported type
unsupported recpientinfo type
unsupported recipient type
unsupported kek algorithm
unsupported content type
signer certificate not found
private key does not match certificate
no public key
no private key
no msgsigdigest
no key or cert
no key
not supported for this key type
not key transport
msgsigdigest wrong length
msgsigdigest verification failure
msgsigdigest error
invalid key length
invalid encrypted key length
error setting key
error getting public key
certificate verify error
certificate has no keyid
certificate already present
CMS_SIGNERINFO_VERIFY_CERT
CMS_RecipientInfo_set0_pkey
CMS_RecipientInfo_set0_key
CMS_RecipientInfo_ktri_cert_cmp
cms_msgSigDigest_add1
CMS_GET0_CERTIFICATE_CHOICES
CMS_EncryptedData_set1_key
CMS_decrypt_set1_pkey
CMS_decrypt_set1_key
CMS_add1_recipient_cert
CMS_add0_recipient_key
CMS_add0_cert
unsupported requestorname type
no certificates in chain
error parsing url
PARSE_HTTP_LINE1
OCSP_parse_url
OCSP_cert_id_new
unimplemented public key method
invalid cmd number
invalid cmd name
failed loading public key
failed loading private key
cmd not executable
ENGINE_UNLOAD_KEY
ENGINE_load_ssl_client_cert
ENGINE_load_public_key
ENGINE_load_private_key
ENGINE_get_pkey_meth
ENGINE_get_pkey_asn1_meth
ENGINE_ctrl_cmd_string
ENGINE_ctrl_cmd
ENGINE_cmd_is_executable
unsupported version
unsupported md algorithm
invalid signer certificate purpose
ess signing certificate error
ess add signing cert error
TS_VERIFY_CERT
TS_TST_INFO_set_msg_imprint
TS_RESP_CTX_set_signer_cert
TS_RESP_CTX_set_certs
TS_REQ_set_msg_imprint
TS_MSG_IMPRINT_set_algo
TS_CHECK_SIGNING_CERTS
ESS_SIGNING_CERT_NEW_INIT
ESS_CERT_ID_NEW_INIT
ESS_ADD_SIGNING_CERT
functionality not supported
WIN32_JOINER
unsupported pkcs12 mode
key gen error
PKCS8_add_keyusage
PKCS12_PBE_keyivgen
PKCS12_newpass
PKCS12_MAKE_SHKEYBAG
PKCS12_MAKE_KEYBAG
PKCS12_key_gen_uni
PKCS12_key_gen_asc
PKCS12_add_localkeyid
unsupported option
unable to get issuer keyid
policy syntax not currently supported
operation not defined
no proxy cert policy language defined
no issuer certificate
extension setting not supported
V2I_EXTENDED_KEY_USAGE
V2I_AUTHORITY_KEYID
S2I_SKEY_ID
S2I_ASN1_SKEY_ID
R2I_CERTPOL
unsupported cipher type
unable to find certificate
signing not supported for this key type
operation not supported on this type
no recipient matches key
no recipient matches certificate
encryption not supported for this key type
decrypted key is wrong length
PKCS7_add_certificate
unsupported method
no port specified
no port defined
no accept port specified
broken pipe
BIO_get_port
ECDH_compute_key
data too large for key size
unsupported field
passed null parameter
not a supported NIST prime
missing private key
keys not set
invalid private key
PKEY_EC_SIGN
PKEY_EC_PARAMGEN
PKEY_EC_KEYGEN
PKEY_EC_DERIVE
PKEY_EC_CTRL_STR
PKEY_EC_CTRL
o2i_ECPublicKey
i2o_ECPublicKey
i2d_ECPrivateKey
EC_KEY_print_fp
EC_KEY_print
EC_KEY_new
EC_KEY_generate_key
EC_KEY_copy
EC_KEY_check_key
ECKEY_TYPE2PARAM
ECKEY_PUB_ENCODE
ECKEY_PUB_DECODE
ECKEY_PRIV_ENCODE
ECKEY_PRIV_DECODE
ECKEY_PARAM_DECODE
ECKEY_PARAM2TYPE
DO_EC_KEY_PRINT
d2i_ECPrivateKey
zlib not supported
wrong public key type
unsupported public key type
unsupported encryption algorithm
unsupported any defined by type
unknown public key type
unable to decode rsa private key
unable to decode rsa key
streaming not supported
private key header missing
digest and key type not supported
bad password read
X509_PKEY_new
i2d_RSA_PUBKEY
i2d_PublicKey
i2d_PrivateKey
i2d_EC_PUBKEY
i2d_DSA_PUBKEY
d2i_X509_PKEY
d2i_PublicKey
d2i_PrivateKey
d2i_AutoPrivateKey
unsupported algorithm
unknown key type
unable to get certs public key
public key encode error
public key decode error
no cert set for us to verify
method not supported
loading cert dir
key values mismatch
key type mismatch
cert already in hash table
cant check dh key
X509_verify_cert
X509_STORE_add_cert
X509_REQ_check_private_key
X509_PUBKEY_set
X509_PUBKEY_get
X509_load_cert_file
X509_load_cert_crl_file
X509_get_pubkey_parameters
X509_check_private_key
GET_CERT_BY_SUBJECT
ADD_CERT_DIR
PKEY_DSA_KEYGEN
PKEY_DSA_CTRL
unsupported key components
unsupported encryption
read key
public key no rsa
problems getting password
keyblob too short
keyblob header parse error
expecting public key blob
expecting private key blob
error converting private key
PEM_WRITE_PRIVATEKEY
PEM_READ_PRIVATEKEY
PEM_READ_BIO_PRIVATEKEY
PEM_PK8PKEY
PEM_F_PEM_WRITE_PKCS8PRIVATEKEY
DO_PK8PKEY_FP
DO_PK8PKEY
d2i_PKCS8PrivateKey_fp
d2i_PKCS8PrivateKey_bio
unsupported salt type
unsupported private key algorithm
unsupported prf
unsupported key size
unsupported key derivation function
unsupported keylength
unsuported number of rounds
private key encode error
private key decode error
operaton not initialized
operation not supported for this keytype
no operation set
no key set
keygen failure
invalid operation
expecting a ec key
expecting a ecdsa key
expecting a dsa key
expecting a dh key
expecting an rsa key
different key types
ctrl operation not implemented
command not supported
camellia key setup failed
bn pubkey error
bad key length
aes key setup failed
PKEY_SET_TYPE
PKCS5_v2_PBE_keyivgen
PKCS5_PBE_keyivgen
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover
EVP_PKEY_verify_init
EVP_PKEY_verify
EVP_PKEY_sign_init
EVP_PKEY_sign
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen
EVP_PKEY_new
EVP_PKEY_keygen_init
EVP_PKEY_keygen
EVP_PKEY_get1_RSA
EVP_PKEY_get1_EC_KEY
EVP_PKEY_GET1_ECDSA
EVP_PKEY_get1_DSA
EVP_PKEY_get1_DH
EVP_PKEY_encrypt_old
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt
EVP_PKEY_derive_set_peer
EVP_PKEY_derive_init
EVP_PKEY_derive
EVP_PKEY_decrypt_old
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_ctrl
EVP_PKEY_copy_parameters
EVP_PKEY2PKCS8_broken
EVP_PKCS82PKEY_BROKEN
EVP_PKCS82PKEY
EVP_CIPHER_CTX_set_key_length
ECKEY_PKEY2PKCS8
ECDSA_PKEY2PKCS8
DSA_PKEY2PKCS8
DSAPKEY2PKCS8
D2I_PKEY
CAMELLIA_INIT_KEY
AES_INIT_KEY
invalid public key
PKEY_DH_KEYGEN
PKEY_DH_DERIVE
GENERATE_KEY
COMPUTE_KEY
rsa operations not supported
key size too small
invalid keybits
illegal or unsupported padding mode
digest too big for rsa key
data too small for key size
RSA_generate_key
RSA_check_key
RSA_BUILTIN_KEYGEN
PKEY_RSA_VERIFYRECOVER
PKEY_RSA_SIGN
PKEY_RSA_CTRL_STR
PKEY_RSA_CTRL
inflate 1.2.5 Copyright 1995-2010 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
-3.7.8
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
!"#$%&'()* ,-./:;<=>?@[\]^_`{|}~%d.%d.%d.%d
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Software\Classes\.html
debug.txt
unexpected key token
expected key token
,[]{}#&*!|>'"%@`?,[]{}#&*!|>'"%@`tag:yaml.org,2002:
#;/?:@&= $,_.!~*'()[]
#;/?:@&= $_.~*'
illegal map key
?:,]}%@`
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_stat2
sqlite_attach
sqlite_detach
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s\etilqs_
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
keyinfo(%d
%s(%d)
%s-mjX
foreign key constraint failed
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
zeroblob(%d)
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot %s savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%.*s"%w"%s
%s%.*s"%w"
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
database %s is already in use
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
no such collation sequence: %s
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
unable to identify the object to be reindexed
table %s may not be modified
cannot modify %s because it is a view
foreign key mismatch
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
%s.%s may not be NULL
PRIMARY KEY must be unique
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
foreign_key_list
*** in database %s ***
unsupported encoding: %s
malformed database schema (%s)
%s - %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s.%s
%s:%d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')no such trigger: %S
-- TRIGGER %s
no such column: %s
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s SUBQUERY %d
%s TABLE %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid>? AND rowid<?)
%s (rowid>?)
%s (rowid<?)
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
1.2.5
E:\wizz\COMBROADCASTER\COMBROADCASTER\Release\ComBroadcaster.pdb
SHELL32.dll
RPCRT4.dll
GetWindowsDirectoryW
GetCPInfo
PeekNamedPipe
GetProcessHeap
KERNEL32.dll
EnumChildWindows
EnumWindows
UnhookWindowsHookEx
GetKeyState
SetWindowsHookExW
MapVirtualKeyW
GetAsyncKeyState
CreateDialogIndirectParamW
GetKeyboardLayout
GetKeyboardState
GetKeyNameTextW
MapVirtualKeyExW
USER32.dll
GetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GDI32.dll
WINSPOOL.DRV
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegOpenKeyExA
RegCreateKeyExW
RegDeleteKeyW
RegEnumKeyExW
ADVAPI32.dll
ShellExecuteW
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
MSIMG32.dll
COMCTL32.dll
OLEACC.dll
GdiplusShutdown
gdiplus.dll
IMM32.dll
SHFileOperationW
VERSION.dll
WS2_32.dll
WINMM.dll
WLDAP32.dll
ReportEventA
.?AUDWebBrowserEvents2@@
.PAVCException@@
.PAVCMemoryException@@
.PAVCSimpleException@@
.PAVCObject@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCOleException@@
.?AVCCmdTarget@@
.PAVCArchiveException@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCResourceException@@
.PAVCFileException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_W@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WPAVCObList@@PAV3@@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PB_WHH@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
.?AV?$CAtlExeModuleT@VCDummyModule@@@ATL@@
.?AVUrlCatcher@@
Inappropriate I/O control opera
XGCCA_ttHfQQN0NNImXXv=eeZfpp4/LLVKQQBHtt8/ttBKLL25XXJ^VVz%xxd ddAAwwr VVj~xx4CXXLLXXzfXX2%oowcbbH,ll1=XXM$ooroddPQQQconn1Vjj4.VV2Xjj2snn2LppG~ooHIggdqMMACXXd)FFPxjjeVggZ3QQ3addR}ccG2bbZqwwK2HHNrSS1]NN3TCCeWggZwooxzVVw>SSN7LLvtlle"66CsCCK.lld\lldullbBSSJ.995xggfinnt/oocMgg5Zxx1jNNIDoox666r,CCxHgggbWWe<nnCWSSvpjjw!XXK9SS1jttmWllPNuuK#xxx/jjwFqqnDooNOnnx#ll17oo1zllKfNNG9oo3,dd8^mmw,xxJ?SScMxxtoCCeFnnajjjp}jjyEXX46HHAmxxz2FFPEll4%ggi=mmN4uuZ*CCw%ggR:ooHUqqwOww17ggIRmmr(xx8:vvdYnnt!lldJXXcUllf%IIumnn1[663/ppsTnnC#bb32bbNemm2/ddhsllr|oo3]QQZ=SS6mQQZ}uuANuum~eePRnnwhHH3HwwJxjjt>CCf466vKQQ3oHH2pggHF115PooZISSAOWWfU66prvveTHH2GCCvwRRJ*oowaqqOfoo1/ggU$ccH`FFH`SSKRooV"QQJP00kAkkfeLLK~SSc,NNP0uuc1SSA^pp3nHH6VvvfBIIRzww4MXXiISSG<xxR8wwJEddJ,QQvxMME8WWGYnnjwbbBIee1AXXwt33m*wwdkddV3ll1:ggj/wwcBLLPmkke ttA`nnxoLLxfuuK;oo6}QQHCHHHEllsvdd4BuuG3VV3'wwZhjj6fppdellh'ttBDEEBKpppKeeVTnn1,RRKEmmJLRRm<WWz.ggb=SSs)tt8BttKAXXE4nn1bHHJZWWv^llb1QQvyVVdsWWf[FFP CCs:bbRlQQ23ggl}wwHbddA\uu3!xxErbbxFMM62kkv#NN8(uu2-ddiIxxf-NN8|ccGRqqJkxxe4xxGhWWK4nnN=jjmuxxp,llcSuu2uQQ2"llRfSSf{LLmSmmA&nn2#pp4onnENXXKCVVd{xx2133KFnndEMMNcttvY33Amooea00M1llxONNs9uuv8RRC$SSxU66yAmmJoNNy6wwx#nnmkppeH66VsXXKxqqxdSSeMHHH5XXv,RRR_mmfH338wpprrbbPAbbGbnnt&ppG;ddItoo4Gdd8DQQv3eeNBwwJGllz[wwKIXXZHXXN|nnKOnnw$nnwzQQe~ee5'lleRSSE9bbHH33nNooruLL8JWWZ5VVj>ppw"llR&WWv9eeV9uu3~bbPVxxGIooR!xxc3llj4uuK!oo4rXXdXFFN/uu4RXX51QQ2666G.nn1Snn20WWwSqqYPmmcOuuZ^kkfI338fppeANNpQxxsMllj\QQJcjjy uuZ&aaNfXXe3llABhhGXNN4Qjjx$gg5[pp4hddE@ttwRggKvbb3Ygg8 bbA>eeN\ooe\ww4DggxV66PFnnv"jjoEggw|ggE{wwxXaaH=vvfvRRvjmm2<RRraQQrIooJzvvs~nnK$WWv\jjYIppw,NNyfQQHzRRoiXXr4xxa ggB9xxU1jjrRjjB7ppeEllEJXXK:qqZBXXZmgg10nnHWSS37ccH|HHZ1wwHgbbAhvve8IIdBSSzTllxPppK%VVVrQQ1]jjeJkkf SSV&pp2;jjiuXXmxLLE=vve%ggqCbb3hXXhyWWwIXX5OjjxAqqGhuuxhggc nnAbnnr7oo3jLLl@vvHZ00fUbbG8llO1XXrdFFHzww3,ww2`SSc#ggiwwwr4jjJvggN3xx1>wwd1jjGpwwd!xxIKuuxWllvnuuvzUU2FQQ4hjjk\ppJ/jjnObbwiRRvQnn2`jjv$ggsHllG&ggKfnn4*WWd4bb28lldC66K4ww1UFF20SSNRnn1mXXee00o`XXGsnniDQQr~SS5dSSzYqqP\wweaaaZ%ppN:XXrCSSHlEE1)nnfFooPEkksrttUVttHG55ESvvffxxyACCwaRRjvllx)eeZ$ttG/MMBMppx_xx5voo1c33HMjjw)qqd{llv4LLmEkkvWNNYLQQ3NjjWPbbG~ddldWWe3VVq oox*VVKÌv0llk"CCp^gg6nSSw\ee6iwwG9llWJkkrKxxA6bbp@VV2\oo1XbbVQnncCllj;jjcXwwZDXXxhFFNGbbN0HH4:ccK.LLOKll3Yddh(SSe0ddt&ww2~XXaTQQc8wwA3jjJ 33truud.xxYguuv!552Hggr.NNwMhhK%ggi8llwKNNb}mmGZddbWppvD333<ooAhllKDxxeAqqW4WWH7NNpGnnwCIITrmmKRww2cbbJUNIXXmZxxu>XX1.llt#ppG,eeJhuu4,NNhWWWrKFF4BnnvVRR2!bbG/llcBoo2JeeAahhNbllLjjjsNooRGooeM66Ninn4)bb5!oo3`SSV@hhN4XX6oppcvnnBBnn2Sbb6GoovWjjU}QQ1g66M=SSc,eeVRvvw{VVtxggHAFFP=XX3VjjN[llGDVVmnuudbggm&SSJZnnl`nnc^NNC.oowXttA\ttw@RRNfpprGXXU-nnJ~LLr-xx4%ww2/oo1,ttPluuw900P6nnK2ttZ:bbx(LL8dXXe(nnequufgMMZQppdpqqHAuuH/IIgJppprNNW3kkfj66kIXXxBxxO[bbHmIIqFggzFggNlllw9VVERXXm~oo3$QQHH336fXX3QXXuXlleaddO-QQs0dd5aQQxK66MYXXfwggvNoop2jj3fuuf#ggP{bbcAggvmQQ2_ggq]jj1Y33m,QQzMqqB)pp3TLLB=nn1=66N*wwxkLLI-vve|55J7wwZ~ggIobb2?EEJRuuKEnnH}kkw%xxNjvvpZddEZuudytt6,kkpDddoWXXGpnnGSwwK1NN8&WWwnVVu[xxs}wwZ{vvJZllthkkf{xxJwoorAVVt4kkwq66p%ttc%ggn|nnsQnnz3ww3{XXI1xx1A553]xxx2668CQQc>ggH9uuc3xxnWoowjdd4!vvH;jjM_XX1900v&SSejww3cjj2d00mtSSwUxxTeQQ1VqqiihhK)xxrqvvw|ddGBnn4^NNH<ppwajjE{nne|RRLYSSvTxxJqmmc5nn4Qjjv/66ImuuG_XXAnCCrMNNwDxxxFll8}wweRxxm0WWdXHHVHXXKPxxw]uuJ_ggeCSSwdllZ,SSpSaa2;vvpLbb3ISSv'llh/llm5ddZ/ggG}jj2rXXHT33Yswww1qqZUppcYLLj0llrFeeJ=WWZbqqUFjj1OggR<ooJXggPZXXfAllqzQQJ[33x?xxJfuuV!CCclllzkuuv4xxRIWW3kuu6kxxvm115;nnHgttPAuuJt00i(ooGWxxx$jjdlllz6pp3nNNOeuuc<ooAuWWddFFROxxx8bb2^ttB'EEBoppGmnnoCSS3RMMJ$ppm4ddzAllwjnnlGmmsaxxcCWWrwwwB-kkBdggNPjjB9llVRbb3BVV32mmNcbbZOSSc5MMJhmmJbVVvoSSv?nnqTCCm2bb1(SScwqqtammwxIIj7mmzrjjK7ccHznno/ooe@ll60llzqFF4;QQ2DRRw.SSfzNNV;mmGtVVv4QQd_qq2mnnN155E9SSwTSS4BxxH:bbHKuuZ=llR)lldA55ZzooAxxxHXttv"xxxUjj2=FFH|xxc]VV8Hoof?ggCSooHtllkKuuvxxxN}xxeXjjd!nncznnesww2BooJ0bbZ)llC}WWfJnnuVkkrPLLg<nnfajjEnXXZRnny@lldRSS3ljjfMNN4wQQc NNeKuuxdoo3XggwkNNv~wwrullNvQQw^66NnllBoLLG1bbw"665qWWdQwwNgkkf`NN3Juu2<SSE|wwNVaa2.vvBEdd6!xxJ>99V'SS3`XXg/oo2Qnnf~ggf]66c3SSKvtt3cWWNxXXB%ttwEXXy2ppZmddz%ppfinnzSkke7llO`QQHZbb14jjJ@llpISSfSVVo6bbGQjjr2xxduqqitxxGLnnsvXXHYRR1\jje6aa3.lld5ddUvpp1-VViKCCrjFF4JQQs-llL^oo4fnnb;ggJTXX6IQQv=jjR[jjpCddEWvvH733AhQQ34MMZ]vveuLLvXmm4;xxuAvvz:jjW7SSZ0jjb9ppdQjjaxSScZjjYrppJTXXECnndYnnm>xxp5VVJ`oox;VVldQQp6ggJ3wwv,66z6hhNOqqp<xxfVggn_QQdsjjKVSSzPHHZ:WWv>nnC9mm4[qqV5CCrpggRUuu3ZNNe_WWfsNNVrQQd<qqMvhhKtXXnFllwHVVwqmmH 33BCSSH MMEonn1Eee2Imm2/UU1=QQ2Vtt6pmmf-LLbBnn3TLLffWWKvww4|QQf^UU20nnH[jjy<CCf/SSZeXXGwxxm\ggp*ttRwllvQNNJ#CCHOxxzsxxJcHH5]XXrKVVbcQQJs33jVkkvp33yaxxcDggjXXXcSNNTfQQJfHHE7WWfOLLsFWWrsttZ)ppvrll3Mllz4xx8%kkwS33R-nnKMooZQuuN8ddj'WWc]MMPAggxVggWkjje:qqc"xxf7RRhYxxB~ddNann1hVVO[nnf)LLBdwwwNLLe<wwZ^VVn.xxK0VVs4mm34nnIbttweLLT&SScGqql8WW2ENNdPWWccNNdTQQH{llNejj1<xxfiSSx<wwNhXXcwllGGjjJ$XXxOWWmyddk4CCKCxxg4nn2inn4;wwvz556SkkrOVVc~vvpIqqW1WWd}xxq[wwN^xxK9WWwFjjc7oomdooZ)ppGLuu6QWWJ]jjIxuuGYlleVXXfGNNT!ppH.RRcKccH'ggm2kkeuXX1,nn2vLLJOxxz|ddoJoopCVVdkppB&xxh_mmHzRRvXXXf0EE5 ww3jqqN3QQd4NNlYmmrBnnMIkkz&nnHJkkx@xxzGbbpcNNLixx3DuuR\jj2%XXI?bb3Iaa1cll1,66P(llN`662_SSw_552;SSK xxi<jjZ/xxNNXXAtnnnQoor{LLAQuurtXXtbggmEttUQttJEddEFSSe?llTnQQv7ddLxQQB?tt8VttKkxxEvnnsD66Vpnnr~jjOvCCv;nnTlSSJpxx2jnnc/ttY[bb2U00IuttBoEEBLbbczqqEvppJNddIlnnmmtt8.ttJZ33B-QQ4vllD,bb2CddD`uuzpee1Zuuz-eeE!uuG]bb3rttBKEEBybbc%qqEQwwfzddAlXXf)66N SSB!tt8/ttJTxxT(SSJ<xx8.QQAXttU\ttJCddE[SSd?llNXSS4tooBJkkB{gg3@SSf,ooYxbbJGxx1&bbp*aaEwuuzzaaARyyJ%jjTdQQmHttUittJOddEoSSdsnnN8SSK^jjL>QQ2E55BhkkBQttR_yyG{eeEettBREEBEQQ23VVJYppKvxxKwhhJyxxBfwwwznniTmmfvVVz>gge<33IHuuv^SSB{kkB}ggU*SSJMFFA]hhN<XXg2ggxMjjrfxxwq33z{xx3vqqC kkc?VV6\nnZhqqcKjjGeVVzrppw|33phooffeeASbbxLaaPfXXsjMM1EQQN<66I'll1ISSV^WW4"LLRoxxZ9nneCXXw\334aooG}ddO bbc"bbNwXX1F006/XXHgllx*uu1f2kvvN:66J'mmHDVVz%jjNx66p\jjGFXXl'vvHVuuE0xxzplldaQQ1 XXV%WWfHNNo_llwHjj23nnBKnnKIggp6ddU.uuecRRKxWWc]ww1YbbZ}VVlrQQ4laa5wmmJ@uuHHvvfR66a,xxzuNNE/QQzeNN3DQQ2UXXr`bbJ533N>QQsQlllMkkrHtt52uuBFllEoQQ2)NNW>ccB(bbR0SSJ\VVYLkkmKLL8Cpp2mggv`wwrsuuR_llNc551rQQvjwwP$CCe_SSASwwrmVVvkCCxAjjV)jjz=ttEGQQfbMMVoSS4/qqz;oow,lladxx2(66kzbbK5jj1>ggGHqqycpp2]5558SS1@11RkCCdnllo#QQHvnnr!WWf#dd8,mmd2xxOpww4<xxm$SSBbddfuSSHMIIgSkkx6FFNdoo1tIIUXll1wUU5Dxxc{ww64ggssLLd_wwp6xxgQllwfxxNBvvcHnnohmme)tt5uxxf3xxvIjj4!MM5sxxcWqq8JWWZ2ttZQll2DnnK(ww2(II3TmmrjVVo#wwJ ggqgppJ;33k!lls?ddb}SSw}llPvbbx666M|llr@dd8wWW3wggBrjjdzNNqaXXe*ttE"pp1UjjiGkkw*IIutooNtjjj#XXv[wwJeWW3O66Govvd(llsFWWcgqqUquuwYqqxnwwenjjs#uuB4LLKwvvxnbbRMXX2wnnW@ggHpbbEKjjN]nny/xxd}qqeHxxpFuu3xSSrMddc-ppvnRR3nmmdpVVEJttx0VVI2ggf0HH3'oodFVVUfQQddVVnzppfPggRQmm2 LLVuggdJggp ppJvLL64SSJ7jjA mmNQnnT8hhJ566ECwwvXRRM}ttBxEEBTCCp;llWojjHcjjj}xxKzqqC6ttv3ooJ]ttw llBljjH^ggH nnw(VVBiCCNg66ccttG,MMBHggzrXXOtQQv{33h kkw@ggeGWW42aaZcXXK0NNI!nnrfXXsvWWr;HH6bCCsIddwcttxjllL}ppfqMMZNbb3eVVompp1wVVy6xxdSggt?ppG_jjI.nnw=333[XXH&ggs1mmKsNNZ3QQG>NNfMwwfOIIw*hhK,aa3%QQGTVVOQoozzNNP?WWd5MMH\ww4Nxxg*CCcqFF3Bllp1ddKRvveZaa5ICCdPjjiJjj3innAyWWfGEE4djjfuggg~uue/991$WWv"jjC_SS2$gg87mm2dxxuHxxH#LLY,jje@qqvbll3`nnyFllp2aaRxCCNGNN4Yxx1900K<mm2 U&nnfhggklSScNnn8aCCp`ggKcQQ1unn1DSS1FUUE9bbwqnnwbnnx dd3CQQ4xLLl oo2,MMN7vvzegg3mnnZ]XXY uup[SS3BCCKAllg^ooAuLL8kll1'NNP1WWKnFFE)pp1<ttHdpp4:ddbTllHK008"ggNSLL1%ooz[jjLAjjJ1ee5|ccGrlltPXXBlxxZ|nnmNllL[llG4xxZzccJVXX4[SSe|NNnsxxA1nniuQQAhllqmppJ'115>XXvSLLiellJ;jj3AvvKiXXG{XX3|XXqRttx`ddCWSSzvuuHOnnA~llh^hhBCxxudXX4|FF1SnnN8dd4}nn4'dd5&WW1[RRlrjjG4ggxtxxrHXXr3xxxHddiaggef005xQQxwqqmFXX2kVVjDvvx.LLs.vvBzddTkmmGAuu4PhhK(qq5TnnGPnnJ?uuJbnnT]XXw$qqvimmw111Z7xxB[nn8aQQGFxxkQxxdI55HXmmr*XXfXvvH#ee6qmmxueeRzxxJPddVdxx3wttZxCCwm99R,ppKGxxzVooz)ttR|mmfZFF5dCCw0uuPvxxH{xxHPjjzPNNpCuuJ6EE41mmc<qqr9ooKfLLK4ll2&00q(XXr.bbBuDDoI===PADywCyvtbpxtDzDeXNEKaYhQexloyTtuoEQYetyTC_vEOJrkHjMBtnCLZfSZYZiPAD<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
1-1U1}1
< <$<(<,<&?8?
?!?'?,?:?
12u2
2 2-2?2[2
3#4=4]4}4
7|7H7Q7W7]7c7i7t7
7p7F7Q7
4&505-676
= =$=(=,=0=
? ?$?(?,?
6%6S<
<!= =:=_=
4#5(545>5
?!?,?6?~?
8094989<9
6o7U7
9!:':-:3:
: ;&;4;`;
=$=)=.=5=:=~=
8 8&818@8
6 606_6~6
; ;);0;_;
:0:<:]:}:
:!;-;`;};
11S1U2a2o2x2
<~=#>4>{>1'101?112
0p0
4%5-535:5
0 1:1`1|1
4-4S4b4}4
1 2$2(2,2:2
0 0$0(0,0:0
9Ÿ9
3!4 454?4
7$7-767d7k7t7}7
: ;$;(;,;0;4;
5 5$5(5,505
= =$=(=,=0=4=8=<=@=
3%4X4
9 9$9(9,9
> >$>(>,>0>4>8><>@>
7 7$7(7,7074787<7@7\7`7|7
? ?$?(?,?0?4?8?<?@?
? ?$?(?,?0?4?8?<?
7 7$7,70787<7
:(:,:0:4:|:
8 8$8(8,80848|8
> >$>(>,>0>4>8>
:$:,:8:\:|:
1 1<1@1`1
4 4<4@4`4
4 4(404<4\4|4
background-url
CB_DownloadAndExec
CB_NavOpenUrl
CB_OpenUrl
]%s\Google\Chrome\Application\chrome.exe
\Mozilla Firefox\firefox.exe
\places.sqlite
\*.default
Firefox
Ncomctl32.dll
Ncomdlg32.dll
Nshell32.dll
%s (%s:%d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
Advapi32.dll
accKeyboardShortcut
wuser32.dll
hhctrl.ocx
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
kernel32.dll
Nf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin1.inl
dwmapi.dll
UxTheme.dll
eShell32.dll
%s:%x:%x:%x:%x
MFCLink_UrlPrefix
MFCLink_Url
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
&%d %s
VHex={X,X,X}ShowCmd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
WExecute
%sPane-%d%x
%sPane-%d
windows
Z%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
%c%d%c%s
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
\RICHED20.DLL
\f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
Invalid parameter or key doesn't exist.
Floating point (%%e, %%f, %%g, and %%G) is not supported by the WTL::CString class.
%s-tmp
"%s" "%s"
%s has stopped working
Error launching CrashSender.exe
The operation was cancelled by client.
Couldn't launch CrashSender.exe process.
Couldn't set C exception handlers for main execution thread.
Couldn't create crash report directory.
%s\CrashRpt\UnsentCrashReports\%s_%s
Local\CrashRptEvent_%s
Couldn't load dbghelp.dll.
crashrpt_lang.ini
CrashSender.exe is not found in the specified path.
CrashSender%d.exe
%s %s Error Report
The flag CR_INST_STORE_ZIP_ARCHIVES should be used with CR_INST_DONT_SEND_REPORT flag.
Invalid registry key or invalid destination file is specified.
The registry key coudn't be open.
Empty subkey is not allowed.
HKEY_CURRENT_USER\
HKEY_LOCAL_MACHINE\
SOFTWARE\Microsoft\Windows NT\CurrentVersion
%u.%u.%u.%u
https
Mozilla
Chrome
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
777705555443332
5555443332
5555443332
ydebug.txt
\%s\%s\%s
\Internet Explorer\iexplore.exe
install.bat
n.folder
%Program Files%\mbot_ca_014010265\mbot_ca_014010265.exe
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
taskkill.exe:320
taskkill.exe:1336
taskkill.exe:2044
97c94f7678fa89eb87858f8e5a7c13ab.tmp:1680
tasklist.exe:1928
tasklist.exe:364
upmbot_ca_014010265.exe:1092
%original file name%.exe:668
mbot_ca_014010265.exe:1736
encrypt.exe:216
encrypt.exe:1260
encrypt.exe:196
encrypt.exe:264
setup.tmp:1896
setup.exe:1948 - Delete the original SpyTool file.
- Delete or disinfect the following files created/modified by the SpyTool:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O9YZOXQZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KH2NKL2Z\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\S5Q3CH2Z\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\idp.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\ODABS1EF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\setup.exe (657385 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-HE87O.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (788 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.cyl (428 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (231 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@youandmeandmeandyouhihi[1].txt (182 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8Q7DH.tmp\97c94f7678fa89eb87858f8e5a7c13ab.tmp (3780 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\mbot_ca_014010265\1.10\cnf.cyl (269 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.exe (16609 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.exe (20237 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.exe (16649 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.exe (3300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\encrypt.exe (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mbot_ca_014010265.7z (8657 bytes)
%Program Files%\mbot_ca_014010265\is-OP7DE.tmp (28787 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-HE4TJ.tmp (4185 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\MYBESTOFFERSTODAY\MyBestOffersToday.lnk (837 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-HT75P.tmp (7971 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-LGPBB.tmp (7433 bytes)
%Program Files%\mbot_ca_014010265\unins000.dat (35465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\CheckProc.cmd (288 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\upmbot_ca_014010265.7z (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-61C0M.tmp (8657 bytes)
%Program Files%\mbot_ca_014010265\mbot_ca_014010265.exe (29430 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\idp.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe (23062 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\is-6DL8S.tmp (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\mybestofferstoday_widget.7z (7971 bytes)
%Program Files%\mbot_ca_014010265\mybestofferstoday_widget.exe (23404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\predm.7z (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-14JSR.tmp\ex.bat (1564 bytes)
%Program Files%\mbot_ca_014010265\predm.exe (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-5BNLS.tmp\setup.tmp (6319 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"upmbot_ca_014010265.exe" = "%Documents and Settings%\%current user%\Local Settings\Application Data\mbot_ca_014010265\upmbot_ca_014010265.exe -runhelper"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mbot_ca_014010265" = "%Program Files%\mbot_ca_014010265\mbot_ca_014010265.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.