Trojan-Dropper.Win32.Vtimrun_89b3befd12
Trojan.Win32.Llac.jfik (Kaspersky), Trojan-PSW.Win32.MSNPassword.FD, TrojanDropperVtimrun.YR (Lavasoft MAS)
Behaviour: Trojan-Dropper, Trojan-PSW, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 89b3befd1259337cfe789d529aae2a39
SHA1: 9a90395e803ee2d8fba3c678effeb204562e8535
SHA256: 62199e436afd9936a8b3a3a6f0d97693d4915084feb1e9bcab8c76071fec30cd
SSDeep: 393216:YEoRoiAUMANAscTHLWGJaVGY9MvDyZq8qMu9J/dC66E6TW8Kn8:FLiAOclaVG2QuZeBC7EkWB8
Size: 17835008 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: HQ-Quality-v1.6
Created at: 2013-10-14 08:50:27
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Payload
No specific payload has been found.
Process activity
The Trojan-Dropper creates the following process(es):
autorun.exe:460
HARDDI~1.EXE:652
%original file name%.exe:892
The Trojan-Dropper injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process autorun.exe:460 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Verdana_1.TFT (137 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Trajan Pro.TFT (68 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Arial_1.TFT (1648 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Symbol.TFT (69 bytes)
The process HARDDI~1.EXE:652 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\btn_donate_SM.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRWipeTransitions.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\attention.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\50_1644.btn (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\Folder.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{8BAB0DFF-94C7-4A12-849F-99A6FBA900DA}_Large.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{B704C68B-BAC0-493B-BAD0-358999040560}_Large.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_i.swf (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{8BAB0DFF-94C7-4A12-849F-99A6FBA900DA}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\CC13.jpg (2425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\desktop.ini (374 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\3_1644.btn (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRSlideTransition.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\Click1.ogg (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\High1.ogg (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_clouds.swf (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\hoBrl77.png (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\autorun.cdd (6441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\hdsentinel_pro_setup.exe (103529 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRDissolveTransition.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\ChattChitto RG.nfo.txt (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\Clipboard\Clipboard.lmd (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\globe.swf (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{FACB06FE-F1B9-45D4-9237-DABBDDACC4AD}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\autorun.exe (22471 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\Thumbs.db (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\02 - God Rest Ye Merry, Gentlemen.wma (12751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{B704C68B-BAC0-493B-BAD0-358999040560}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\ChattChittoRG.ico (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArtSmall.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_glitter.swf (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\600px-Feed_Icon_Bl-Or.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\7_1644.btn (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\HDSentinel.zip (679 bytes)
The process %original file name%.exe:892 makes changes in the file system.
The Trojan-Dropper creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\test11.exe (6881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\HARDDI~1.EXE (281494 bytes)
Registry activity
The process autorun.exe:460 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D0 54 0B FD D5 D3 09 B8 CE BF 68 FA CE D6 56 C8"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process %original file name%.exe:892 makes changes in the system registry.
The Trojan-Dropper creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1A 6D B1 E1 70 B1 D3 D2 A9 87 0C 86 A4 3C A4 29"
To automatically run itself each time Windows is booted, the Trojan-Dropper adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
Dropped PE files
| MD5 | File path |
|---|---|
| 232cf610841959200aac19117332f913 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\HARDDI~1.EXE |
| 584db1a945b73a9c92ebf20d7fa3d295 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\test11.exe |
| 06e91208e9a9d41188c70fab16445b33 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\hdsentinel_pro_setup.exe |
| d6fce9ed4ff1e94c7281b56ec8834da0 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\Clipboard\Clipboard.lmd |
| 6a9b0ab9341ac4204aafc7fac9872962 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRDissolveTransition.tns |
| c6fc6f1cd59b8b72ec955d98c29b111e | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRSlideTransition.tns |
| a539ec7d0360ec3cec602f2efae23431 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRWipeTransitions.tns |
| 05a81e5a63ae3001cc3cb3d9eb094006 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\ir_ext_temp_0\autorun.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16428
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 26060 | 26112 | 4.42567 | e9bf1a1e456a9a811b1b86e6602e3636 |
| .data | 32768 | 6796 | 1024 | 2.20139 | 317f8a934ee443eee01c2a315bde9ca1 |
| .idata | 40960 | 4216 | 4608 | 3.49941 | d8675ba112ef922c6057a02546757a1a |
| .rsrc | 49152 | 17797120 | 17797120 | 5.54484 | 836db9a002326d9fad85a9517b78b551 |
| .reloc | 17846272 | 5038 | 5120 | 2.58043 | 83de2f9b2c95be6fea06bced7e8a058e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
No activity has been detected.
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Web Traffic was not found.
The Trojan-Dropper connects to the servers at the folowing location(s):
.text
`.data
.idata
@.rsrc
@.reloc
Invalid parameter passed to C runtime function.
advapi32.dll
setupx.dll
setupapi.dll
advpack.dll
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
ADMQCMD
USRQCMD
FINISHMSG
IXPd.TMP
msdownld.tmp
TMP4351$.TMP
wextract.pdb
PSSSSSSh
SSSh<
PSSShp
PSShp
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
Command.com /c %s
rundll32.exe %s,InstallHinfSection %s 128 %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
%s /D:%s
PendingFileRenameOperations
SHELL32.DLL
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
RegCreateKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegCloseKey
ADVAPI32.dll
GetWindowsDirectoryA
KERNEL32.dll
GDI32.dll
ExitWindowsEx
MsgWaitForMultipleObjects
USER32.dll
_amsg_exit
_acmdln
msvcrt.dll
COMCTL32.dll
Cabinet.dll
VERSION.dll
)%u]Q
Bp.Dx
gA`0)%UJ
HARDDI~1.EXE
test11.exe
v.aOk
],^<O7h.oP[
^.Oz^
SMB%DL
FY%xW
.bG7#
%s_Xp
Ch%CJ
\f@%X
07a%%F#
X.IJE
.gO1"H5/
l.AZ'T
.IdP8
`1i.od@
J|Ö
.jNhv
.xaR6
Q.Jgz
.Okt0/!
P.p3Vl%d
1}].Tw0?
e%d|!fNm
%U{Y>nK.gV
:F%S-
I.bL-7
-.FC`
,%DmOh
;-.pz&
m.zKVzi%
)"%s}
.RN>F
tcpE
%X]`s%
%dJ:;
Rf%f~
Z)K8%C
S%fyXH
7u.JY
:2UŸR
4tGd%f
.dP|X
f.QVF
SmJ%F
}.yv"(
Y/:.Lt6
.OK)^
H%8UK
50E.dO
cQ.OE31
rWH.ti
7%u\0
.zlTD
@%U-.P
J.oF0
vu%xxS
%c)vLFV
[k.EP
m.asPwa
A%Dvr`
.VJnK
Û 7c
.SIM}
(8%DX
5nt.QY=
vR%Sw#
]`-pN}
j.FYN
.uzL:
.OG"b
QZ.fu
_z}.vv
.RN}D
.Oq(? H8
.Si$1
.sxB '
%X|v%
:%SZ!#
SD%U`
p%szn
%u=!xj
*.up]
0\f.JD!
:5%x#
N%fNc
"}\%XE
O.zm3
2%x5F
uh,.Aq:`
x%FJ`
$-.Mt
u7.ULf
i,h.qdz[N#x
zf >%c
%dr76
UU8p.Jxb/
XR.yCY
!&.se
.Xzy@:J
Iweb
U{7.swr-0o%s
t<.Vn
.pZil
J~BPU%d
2ÖC%t
.gg}M
.jq~$,
$.kA3
e.vg
>%3s3
=.FOa
gR9%D
.Azz7j
5).nt
1R.XHJ
a%c$#Z
b}.VD
%cu)"
D%Fu}
;h.duBu
.Iy\Bv{-z%sO
!*%.c
K.hXW<T
L.XW4
sRX%dQ
DUlQ%C
}*.eLz
Y%Dy!
sG:%x
.Vh=o
%d.i
9A]).GGx
D%d% )
[L%4S
.lpW>
Cm:(1.iq
.FMUf68p
"%5s3/U
E.cIM
tf.hx
XN%d`
Þ\[b
/.eziHa
a.Dn-
cuKg%d
#%DWT
j{KeYY%c>7i"Y0
?.kaq
>.QCbM
.#.eMN]E
dU%uw&
y#.ML
y!y.WG346
6AM
%F}G'
.HPVv
""-p}
_m7%US
94[Tz.ynX "
ZR.cW
ga.qV
.dUCLh
.KR&@ 0
|.TT2I
.CdKA
-Lk},
{.DXM_y33.vN
.ab|n
.kt*F
%D!_H
.wD5c
tG(B.od
.nB3S
%sw.#L
cl.UA<S.Q[V
1Gq.GK@
Y p.iV>
%c|2p
%SSlN137
d%1Um
B<.Op$
5\.MMBO
;.Cx,
&*.*2@
P%.Od
9c.jV
P.FRS^
M\I..ZB
8%Uk-
/ü
Vq.ta2l
}gD.aea
.MTCV
!K&-%.Eg
G.MMU
b3.wD
Unr.kA
.KBB(Jn
-]%XI
Yr.zX
hk%XA
b`.LWj
.GW1>AI
3U%X@
PqT.ag
"%ucf
jC.NtO Y5
*,eXeL
O%co4k
N.PC]
*.zNx
>.Sx=
Jvl\/
.oM?G
Q^U.ikD
AutoPlay/Buttons/3_1644.btn
C%CLT
WZ%XG
`N.EA
EUw.nW
AutoPlay/Buttons/50_1644.btn
.uBZ.;
)(.pR2
H"6.JW(
AutoPlay/Buttons/7_1644.btn
"g.SO=8sR
~]Z.CS
AutoPlay/Docs/ChattChitto RG.nfo.txt
AutoPlay/Docs/HDSentinel.zip
AutoPlay/Docs/hdsentinel_pro_setup.exe
a .Cu
v%D]8
pÀQ1
.Fy9`
2.Ts8
c2.iu
W.WW&
[.hAf
.%Dg
z-2O}
".xrm
RiG
|Q]
g:\nD
Y.JA3
{hv%c%uCKEz
|&.Eh
#h.jCkQI
u|.XU
"6.aW
zd.Dn
lkq>T%C]y
Z?.qV
6{.ov6VCKp.Pt1b
Z~P.AG
hn8V%C
v.LhM
NXÊ
E.zmG%
8.EGG
3.IIj[
.SAX`H
>.JL~
z0 %s
Î`R
.fG}{.QxMagO
\TI%u]
k.xG!7
F.sE5
%S184
.Ns&$
6w.kV
L%fvih
m.JO~
yCrt
%uy4G5
Ik.irQ
20.JP
1KX.ox
%.pbN"
q%Ct2
.mXHY
%uJGX
rV
vN_.jf
3%.Pqhs
%XK/;C<
o2^%.d
6]e.yH
3} %xBf
Sa.Ir
.%S?>
*sY(%x
sE
.lb5{h.LGw>}
j<.ZT
%sUF<
-ZB}I
.fX"u
$Dt.cI
?.zk.?X
JRH_%f
'Zdd.Fg
g?%c`
.UJR'
Sc.nE
&:.hk
%s!=[
-l}2>Z
q%s2/z
xtJ.fs>e
^5S%c
%c}|{%uM7j
=M.ns`L>L
j.vp'
<9*.Ti
.hN Vz
[_U.rUS
Uo.yWQ
rv.Hv1
R.rrM
V.%UG3
/XxN%f:
[A3=-t}
"0D%c
;.NpZ
*]-SW.lq
K~J%d^
J.lD\
=B -.hv
A.mMz
.IJ["
FJ;2m.DI#
2exeNJR
R.Ybu
R#pe%x
`.fxA
X$.yo5
PH.Cgr
:Et%u
.ZM~m
6.YXh*.
r%d}a
M{f%U|:.mnG}
.UH#`i
U.Fkg:
.mU4y
VE_P29.ZZ
F.nre
2a=.kZ
/>f%f
$-v}|%`,\rM
.clbZ
X<.gwk
tI%fi5x
ma.DoQ.;W
\n.xY
$.gVx-l_L
4p%cH
.Vkky
CEXE
QWv!%u#
Ftpv
7.Hl1
JM.ak
-.tNQ
Y@%dtXp?
br g%F
B.Kgz
Dw.Zi~,1i]v
.oB?1
pp3%U
.Nl,N
%SnF6
-Q}Jz
G_<-Q%C
.USRFG&
y3%S<
P%C|Qq
2C%ua
LN%C/v{v%6sh0
6".QAL
6.wu[
.aQ"a41
%X]53
.PC[,
|/.TX
%sRO%
/o.
i.rGG
.yWMdJ
|.EH)
.A.iZ
z%n%cM
:.mgf1
yk.Frb I|
0.VPs
Z08-;G.vnq
:r.Lk
q.tjG
%SZ}39 ;
kA.AA
Hu%DOD
>b
!-g}<
j.FV|
8.Xa3,
%uNtZ1
u%u26
S)%Dn
:nûBR
tn.Sx
.MM'U
DYk%SS
4X.ES
40.Hrm"
O/.nl$H
.vR;x
.nO(M
.MM>y
qtl%x7
Qw-e}
.iedL
`8.FC
qp/E.lv
%S;~X
L{w.daI.Qyw
7%xDK
.jY,:
.JU.e
C$%x.
KMl%x
z}.ON
1)Z.FiO
oR.Xi
.pp'l
P/M!-%U5N
.fj A
%.oLD
/<h%d
`/.QCL
f?.QH
.ab3}
-3w}v
n&.cE
U^.Av%
-N}S\
%%uPh
.qWs1=
.iG&,6
p.wZf
fÀO
A%d&p
.xS[F
|.zG_
0CMU.Yu
N\'_p.zc>
H.e.aD
,af.Ht
S;I%UT
r.Ni!
!r.PD
\.SJ8
SP.Sm
.zS*D
"o%Dp
pA.GCd
X.XbH
y.GDR
17%d"
KNR'x.be
Y%UHd7
.XD(`EA
RÛ5J
R,;0c%U
?[u6%D}y
.lfrz
'-M}A
K#O%d
C9>.PS
.ud Q/e
.Gr0Z
j{.Kn44j.ZTw
.qkpx
qJ%D-
49%d%
-PoDh}
{X.eSez%U-nn
v<.ty/
].GCK
Z.pHy
M Ï
G.er!
.hs6
fs.on9FfGA
R.JNH
~fAamL%C
.CvuY
h.Bq@
IVÕZ
.fNj;
*GfN;%D
LD9.KaFW
\%sTG,*
.cQ/p7
aeo%7S
.UR7T|
)&\.Ud`
K20%F
UY!%x
%c?)s
B.yb@_
-8}/X
18.hB
><E.IHHW
Z#.go
K.syW
%XH"]4
ik.Wp^)
u `%d
%sOb:
);.qs
.pGn?1J
.pO)Y
'.RO
}.riH
}z÷?<=
D.iV]@
.Gzf.
<%c*N
8#(%d
t.Nn;m
Ó8/lX
@f',%X
xF%F/
X.=}N%F
# %sH
xYb%X
u.gk)
@^%UH
%x[|h
.rt9V
g.qAR
{P9%u.vU-O
2e.rg
H .me$_
%X~NH
WRko%c
o_J.BQ
%SDp;
VbH%S8C
@e.Xh
z<8-o}(A3
V.zTD
.66û85
%UmYz
TR{E%Sa%UrV
!%dJ
yU.vP['
.aKbe
"%sZ3
e..pw
&.bKo
R.DQw[
f%X@rJ*
Y.nk5
>-gJV}W>
%d~7D
OZ%X(<j
y8%U1
d`.Jr
.hV=I
.kB;l<*
sZ6%f>
%X;-(
.tzlg
S.mM\
%dHVcu
.ESWz
.XdLm
.Vt w
.XQeW
.lF%-x:.^{j?G.Ds=
.jb,a
c5z%d
}.Cc"P
T='%s
Ka.Lt
.AL4:
c.sDWynIQZ<
0%cs\BG
1.RqE
Õ]m
E%u#@w
N6.FX
Z.iL8c
RExER!
{.pUBL%u1X`'
/gg.TC
^(.ri
3e{%cRi#.ti
!2A%X?Z,
C\8.UEI
]i<.EmxJ
%U!}OX
X.zsI
7.hn%
f"%7X
E.>$.eV
W%X\rf
'6'7--$@
.PbmxD
.uqH&
B.NDc
.WC(Y
0ABNX%u{~FZ|-K}s_
7y%Sd
mÈE
V:\)^
lC.NT
l.UW
n0%1xL
F5%D:
qNjj.KKi
.Psw>aN
I;%4sdX
~xt.lW
P.dNAL
'È8
|$5Ç
o.CS&
;%s<'
}%x7Q
\.IR9
9%u(&
&P%XP
C.ri|
%}*#|{45^E.HJP&
%sJHOC
.Gv>vvN
\@.VC
.KYzN
%u zl$T
TN.oZ
].eSw
Y%.D<
}"ch(%Sy
B%s^Eb^<
I%9SS
s.yx~
b.qiC
3n.aM
42%s)
Ru.UB
nU-f}"JS
.UA7Y
M{.OFh.zbB
%?.Np
#.nkE
L)R.WyE
Lw.EE
.mVY-
J %8x
yE.YaNg
_.gBB
9.kRID
.AgO2
.JE)-0
T}.Kc
'.ol&!N
\%s{I_.MB4yU
.uf^qe
[%C$=Z
#5.VN
*28:%C:
\.KEM
(/1%S7JQ5
vf.My
:SJ.bb
@%uv:
S.WJ2
C.Hy
w.zB(
UdPf
k/f.Sk
x-T}<ph
J=.pC
@wC%x
b%xOK
\%ub#x
5.bV6
(r@Ó
.YrA3
.sh{QNI.NQ$"
%xN <
e.bnqt}
V#%D$
<^%ct
3'.gp}
.gXl<
5%c/EO
Ss.Fl
zF%snWu
zK_1b\.DE
h(-F}
%.-.BL
2De.dN
.jb]'
~.KBL;e
N6.cx
$z.iY
IxLnab%1X
.BKO]
}wEbb1
Q-M}H
`.Ua0$
#.zW8"
.Za9"
0-%dO
$vn.wv
%x(@4
X%xl(
7`3;#.^~
.uEpR=
CmDy
O.Yie
=k.kW5
_/udp
EcMd
%U;n3K
m'.JY
8e|
1U.MA
.wChJ
lN.TS
.PC6S
=*H/%s
#h%fR
%%U>`
%suO!
'7T.iO
i~.fx4u
|.vvb
_ew-l}8
z.VM%
G.Vrs
k.mAr
0B.Mn
9v.zj
KEy1%ex
=C.eD
f|%sb
N<.JDf}
5Feh%U
%U~3>W
Q,.DH
m[G%UE
%S:,?
AL.mt
%su-Y|
.us.t
U.mh1
.B<%X
$Wgj%D
.aP~,
')=(".E(r%uS
.VVjR
.tUbl
M!q.FB
2:%f(*IJ2
`.MOkkn[
~.GIr
ovPGLa.bZ
:.zCO
UZ3.ZDf
!C.qPn
oy%sz
g/.sH
@P%CH
Q.zod=
io0
~B\%f)
aC.NRIo]
c%X?F_
.qi=T
%ulWM]
v*.QWr
.yz;W_
%S6xT
B).wT
A6.Sv
#I`l.LT`qA
b]O=.HHVy
V.Cjg
.IzX9j
k$*%D
}m-.lT/
PF/U%C
-H9p.sk
-tZ}0
*5U{.dRj.jZ>
%x4\c
&.Wg'1
>.rhZ
L.Ouu
C%F;s&
H#xI.ew
<s6%x
4 _.NY
*.Brm
kEy/:=]
SN%uZ
i2%ug
7.XFW[D
yt`.Bf
-uri}C.O
;.uhR
E]MPn.jBUL
1\~nÚ
Z5.EZ
o).vm
8.cn-t
p.OWI
{G.KJPZB*%se=
\ N.rb
4q
%S=fW
D%3s/
.WOHn
Q O%Sn
.YhS19c
]%U6J1
*,M
.Jq)jK
%SHUbi
.NzS$
.GFf[&
y_<.hG
..Ql5=
/.zSM
%2uO4
%sF?a~[
&s %c
{-.oHehzG6?%S
x.PoM
y#.To
.TyHPi
;.xhDl
.tz#k
z).My
E).Ma
n<.mn
Q.Kc1
/(%DG
4%fOvfN
[& [%x
c.ias
mA8%sY
..EV{$&(vC.Dli
E9.vts
.sL!_
f%x|c{.HP|B
yAYSvr5þ
C &%U
.obH.
$-U}EC
V.MC.f
.lNF
vi.tf
*[13(|?_
}%Xsr
.uw,Y
e.qE.
/&n5.Di
U.SX2
\`U%x
.bW>k
,.cL9
.ySD2
#.SE<
MG.Qh
Úuq
[o.Hs
w}.UT
D-aux}
%2SCV
Lj.FH
WC.bK
%Cw\[
.SDpM
==y%uB0T
.IayE
#%uhj*
iA.PG
.ciEK
`9F3.EI%
%S<1/
W#.Kun
.rf`Ckp
.SpVg9G0 B
vAj.IWW
4`t.iUd
j:\.3W
(Gj%D.0Zu
"e.Tv
H%d/k
.pK0UL)
V.uKnekj
%xSDO
|9.fXyF
%F.$AA
.kBv$
>/.ns
,9.JY
4J.Jn
&.Ee:
[h=`MsG
<(b.As
2.XEPp
*.bRh
.dmR'
.XcJh1y7-
.CJ[,
R9On%xsM
0-e}C
-2$o#%x
).LrM
%UI)L
.lK}\'
1.jLK9
La%XG
`Ø(
Gx%cNK
=?#Ñ
%SdtDJP,
%1x%|p
1kq.Zp
HÎy
%K.hYX
q<-OU%s(
:H%F(
9\Í
/O^.utPh
o.szS
[>U%f
.XzN4
.bYZ0
r.vQW
FqÄ,
SQLf~
7-of}
_!.DB
r%C=Dse
S%c>)&;
4.TgJ
=S.lzNQo
CJd[.Ej
CrtX
t.fQF
U.gqL
FQZ.lSL
1GN.Sd3@
mSGW
.UImU
}J.Wj
=#.eM
%FnRi1
@$<%f
}%Fn6i
<.ml9
v.wt]`
%Ckq`m[
\%8X_
N.OCn[S
%.f5E.
.zVza
-v}I*OLx
[6.Gt
WebX
lUq%X_F
f%seu
YN.lC
-mS.HrZJ
|%N.cKtB
'.OcQ
.UR&.h
/JRm%U
.FgP?
Uh.xK
^TiR&-%cV*
.bH91
d.ui9F
fWEb
.pX\Rpv
E.YaZd
%ScI9
%d`EV
-te}T
.Ll(
\dF%C
.tVpB
U=.qQ
.sZv%
%D/(8%
.HoU<
D.XZfT
.Qu[4{%UE6cMnKz
..QhK
~.e.tL
bx%C}
AO;uDPo^g
bX.za
'[.ag
,=2%S
.Q_ ]%u
Ex%DO
o%X$!<w
.q.Yy
~t0.Lr
).oL'
7%S5@
%sV7o
J.ALaA
y`..qth
HSU9.wv5
~,%Xu
".pfs
}%Sv>]
$.lz2x
.zoOk
.CQ^q
VO.Zp
6zI.Nt_
f$vwA%s
;%:.FC
E<.Gbf
VF.Nw
Pnb 4_%f&
rkoI.IT
.JhOk
ki.Yb
keyc
x;whT%u&
8,.kB
rz.mY
x&Ú
#w.FW
>.Fs|
y]s?%s
%d>}}X
.St4G-
..hHcvo\>B&w
.bH93
e.XB7
8e{.Lgy@ZL1%u|\?$1
bn.GT
h.edJ
q.Cs=
.eDg8?
S.HQR
~4.LZ
!e.Td5l
.LI=x
yA*h.fY
gIT.PaH
%x]Y6
Q -F}#R
%U}&c
U%DIU
jI.CB
%coyl
i=:7`%u
g%X4;
ZT.hE
%s}^E0
J6t}V%f
].LhL
i%X1r
D*K;%u,
8.MKwT
6.bSPf
2.HU Q
ru.CZ
{[.sou.eso
=?.Ht
%FJl^
2.QS@
(.uDv
w-%cU|
}%.RX
R["BV.UL
y&.YJ
>8.Jc
N.SNBs`}XH
.pIaU
%xf8'
>e%u7
KRÄ
.jiXW
.vWW`
.Xl1E
2%C}/_
LP.hh
.vWk,
.YVmU
at}1%c
.dC;OV
0#"&"/!6=
%SYL,
2/.aK
}.FA#
_/};) =49
N.Ytm
'CL%u<
tFtP
%X$QDsV
U[.ar
-.yis
uRLC
uH.nW
%fxfT|Y
Lc\E.Hy
!qw%s,
~_%Sg
x%s\h
K%H%C
.M%cxH
>%UGC|0
%D>?
;<.Ko
oO?VWeB
c.SHJk>
.AYub
Vb%D:f
$ t.Dx/*
O=#%siH
dG%ci
=V.fzBPnDa
.NIH_X
I.cFT
&xA%s
'.wS.N
`UI.VhY
7tx.IC`
Z|za.GMp
.MJIb
.oVd7)
r&.je
f/U}Qþt
Y?YTx.eO
b!@%c
S)%u2H
t@#%C
Xy3a.Uh$
|"}hsK.gk
4.qk"< )
s.cfi
Op/sSH
X.Tc(
.aW.(
4-EX}
L.cK8g%V
b-M}*
m;/.kEI
@Uo%X
W-oX}
7nLQ%u
%c>^H,
rJM-w}K,
GH.iN
.iYuy
|t`.wn
vyh.nW
k)%6u
*.pjE
%Ci=j?
~.vNy
L" C%S
.knA@^
MR%dY'
z"4.li
.Io)O12
p%FKG
.E.GT
{e-FA}f.YV|;p'
xx%f^
jh.nG.
yV:.IK
b.DKo"Z!
1.fa!
v .FI
.Ba>.
t.PO/
qf$%c
iH.QV
.fXv}
c.BE8
.ami`
>8c%u
7O.Sfm
cmDV
C%.gKd
d^%8XZ
c%XNi.w
}8%S?
'.Cda
r.eW)
".ks9
I%UxH
B.oC5S
-Uy}~rs
W5s%x
.uV!0
.AFuw
!wO3%Sp[;
I.QA`8
P.Qa^<
K.HBil
^l.sR
Us.Fq|
>.ejf
22`~ $=}
.MyG5
keyRN
.nXn`J
K.Cg5
SN#%f
$.KUA
Z.JW~
vL.EI
a.IZU
BÓD
/.nb4
gmSGmHib
.cHko(
%%XyC
AQ.fp
nu}.se<c
OB"%c
cY.jM
crpP%f*,
P3%F|
$.pzCm
w.Bh~!
`*'
52w.IS
.Mb,#1
M%f M
~.xT=
hmWeB
AutoPlay/Flash/globe.swf
CUq%f
p.viF
.ga8F
[-l}6
AutoPlay/Flash/indigo_clouds.swf
.ztTR
.iq@(
!*.qh|
!.KIOKS
%XoH~
%X6DQ
%8Xqm
leF%SFY{62.Yr
.XKvHMM
q.cQ4=
.sn&,r
.GxY<
%C"n/ N
F.mUg
3RNz %S
.vhw.
gS.Zj
.aGzeX-{0x3.EzUO
%XeXLu
cuq.gb
{-U}NGNP.pG
8dD>%s%
vs_vY8KY%x7
%x~046
KeYTQ
AutoPlay/Images/hoBrl77.png
j/..PO=
]ru
AutoPlay/Images/Thumbs.db
AutoPlay/Plugins/Clipboard/Clipboard.lmd
.DIg(
z.tYS
`@g.kc
Xn.xM
{:.pPAutoPlay/Plugins/IRDissolveTransition.tns
%CPPJ7
2.qa.
SuÉ
@.xz`=
j9nuiq%x
AutoPlay/Plugins/IRSlideTransition.tns
R3%Cy
\.Zl0j*Y7
tCpxI
Url~th
X=.Lu
AutoPlay/Plugins/IRWipeTransitions.tns
l%c-R
@.lwu
,.Ta'.
.Nn|h
autorun.exe
PL[.vV
%Fp\'C
.vDBv
V%DgX`s
%2u~1
=x%x2
f.fh9
Cb.nD
6]#%fO
mJQ%u
.Vz^F
.JPF-
&j%s (
q%sKZp'
h%F!3
%SJPo
.-c}@
:hDd%C
=pd%uv
!;Q%7S
H |CUv%d
.IO6&
O%D,^P
BY%XGG{5.iaKxP
%-|,3.UK
N6;"sB6%UX
%fnm
}.DYd
.gnZsZ-I
dD.rE
9.SSob
2;.bH.7x
c%fjK
%UAKXKv
.GD4Z
.XX#X
M!.yAe
8_.ir
.Ig`oR
*]%D{T?].SA`
DV.fYBt
.zP&e]
JQ@%F
58N.Nr
%U-,i
9uG%s
%f_?C
p.qRPp
%fSKk#
]x*.ex
Ae6%csq
c%U=H
%FG1B5
%x:4-
\%djgW
.iN@!
r.GT'O
f.`.Kh
H%U,K
.oeCV
|4n%U
`H_S>%U-
x#.pxF
W.hIg
CeRZ%dQe
]NO
.yFflNy
8.NSL
1.MeW
]%u%g.[
%Xu%l
8.qpn
p:\dy
E.YO}4&ya
=.q-.QP
52W%f
.bZ%Ux
Y)V;%s
UfÊi
wg;?%d*
c 5%D
V%F{9YfU.aMZ
.VGwc
{ftpbD(R%X1LNM
!dU%u
%FV=`
.QRgT[
p>%dQ
GOsQlJ
.rCs_TL
hc%D[
.kL,m
up.hm,
v%Cxk
ltF.vjPE
f.sb<
W=h%f
v.cug
(G.hg
'`.JuzB
ql.Mp
}1.mA
dgf^ .bj
.Fhok
5n.Gh=t
.Rd_8
E.lNX
cM%s3I]
%f?H)
)IÝ
e,N%U
'eW"%u*6
r1V(%UI
.yswP|
.lM<x/
nZ5.PF
.Qx/h
JL.ME[v%`
%x6)q
%UE`W{xj
}.FA@^
E8;.jo
*.Gkah
.%D~2
u.xa-
Y[^y.hI
.tw'i
EX{%dA?&%X
ZBV%cSj
w.Sz`E
d/2œi
~`.mj
<assemblyIdentity version="5.1.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/><!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>Kernel32.dll
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.KKan geen informatie krijgen over schijfruimte van: %s.
Systeemmelding: %s.#Kan een benodigde bron niet vinden."Weet u zeker dat u wilt annuleren?
Setup kan geen station vinden met %s kB beschikbare schijfruimte om het programma te installeren. Maak schijfruimte vrij en probeer het opnieuw of annuleer de installatie.QDe map is ongeldig. Controleer of de map bestaat en of deze niet alleen-lezen is.DU moet een map met een volledig pad opgeven of op Annuleren klikken.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process <%s>. Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
-Kan het invoervak voor de map niet bijwerken.KKan de functies die vereist zijn voor het bladerdialoogvenster, niet laden.UKan het bestand Shell32.dll dat vereist is voor het bladerdialoogvenster, niet laden.
-Fout bij het maken van proces <%s>. Reden: %s8De clustergrootte in dit systeem wordt niet ondersteund. Een vereiste bron lijkt beschadigd te zijn.^Voor deze installatie is Windows 95 of Windows NT 4.0 B
Fout bij het laden van %s.uGetProcAddress() is mislukt bij functie %s. Mogelijke reden: er wordt een incorrecte versie van advpack.dll gebruikt.7Voor de installatie is Windows 95 of Windows NT vereist
Kan de map %s niet maken.
U hebt %s kB schijfruimte nodig op station %s om het programma te installeren. Het wordt aanbevolen de benodigde schijfruimte vrij te maken voordat u verdergaat.
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
$Fout bij het ophalen van Windows-map
NT wordt afgesloten: OpenProcessToken-fout.0NT wordt afgesloten: AdjustTokenPrivileges-fout.(NT wordt afgesloten: ExitWindowsEx-fout.
Het uitpakken van het bestand is mislukt. Waarschijnlijk door gebrek aan geheugen (te weinig schijfruimte voor wisselbestand) of beschadigd CAB-bestand.bHet installatieprogramma kan de volumegegevens voor station (%s) niet ophalen.
Systeembericht: %s.
Setup kan geen station vinden met %s kB vrije schijfruimte voor de installatie van het programma. Maak schijfruimte vrij en probeer het opnieuw.\Het installatieprogramma is beschadigd. Neem contact op met de verkoper van deze toepassing.
/C:<Cmd> -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
jEr wordt al een exemplaar van het pakket %s op de computer uitgevoerd. Wilt u een extra exemplaar starten?
Kan het bestand %s niet vinden.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
.De map %s bestaat niet. Wilt u deze map maken?hHet pakket %s is al op het systeem ge
n exemplaar tegelijkertijd gebruiken.FHet pakket %s is niet compatibel met de Windows-versie die u gebruikt.QHet pakket %s is niet compatibel met de versie van het bestand %s op de computer.
11.00.9600.16428 (winblue_gdr.131013-1700)
WEXTRACT.EXE .MUI
11.00.9600.16428
HARDDI~1.EXE_652:
.text
`.rdata
@.data
.rsrc
u.hD3C
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
%*.*f
CCmdTarget
commctrl_DragListMsg
COMCTL32.DLL
CNotSupportedException
MSWHEEL_ROLLMSG
__MSVCRT_HEAP_SELECT
user32.dll
GetCPInfo
KERNEL32.dll
MsgWaitForMultipleObjects
UnhookWindowsHookEx
SetWindowsHookExA
GetKeyState
CreateDialogIndirectParamA
USER32.dll
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GDI32.dll
comdlg32.dll
WINSPOOL.DRV
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
ADVAPI32.dll
SHFileOperationA
SHELL32.dll
COMCTL32.dll
End tag not completed for element %s
End tag does not correspond to %s
Expecting end tag of element %s
End tag of %s element not found
.PAVCException@@
"SFXSOURCE:%s"
%s\ir_ext_temp_%d
"%s" %s
.PAVCObject@@
.PAVCZipException@@
1.1.3
.PAVCFileException@@
%s (%s)
Incorrect password set for the file being decrypted
\\?\unc\
.PAVCArchiveException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCSimpleException@@
.PAVCResourceException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.?AVCNotSupportedException@@
zcÁ
windows
KERNEL32.DLL
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\HARDDI~1.EXE
version="7.5.1000.0"
name="autorun.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
04090000
Created with AutoPlay Media Studio (VVV.indigorose.com)
21.25.32.445
2008-2009-2010-2011 (VVV.ChattChitto.com)
Hard Disk Sentinel Pro v4.00 Key [ChattChitto RG].exe
Hard Disk Sentinel Pro v4.00 Key
4.0.0.0
autorun.exe_460:
.text
`.rdata
@.data
.rsrc
t.Ht&
<.uEF
<.uOCA;
u.hP=g
u.WWWWSW
u SSSSh?
u)SSSSh?
uUSSh
.FG;}
Ht.Ht!
t.It"
INIt.It
u.Jt$Jt
t.Ht Ht
F<%u3
t,SSh
t'SSSSSSSSh
uASSh
It.It#Iuy
%UUUU3
Pj.VQ
Qj.WP
.tTPV
FTPjK
FtPj;
F.PjRWj
u.WWj
u.VVj
u$SShe
On Key
>1.2.8
LIBTIFF, Version 3.7.0
deflate 1.2.3 Copyright 1995-2003 Jean-loup Gailly
1.2.3
inflate 1.2.3 Copyright 1995-2005 Mark Adler
%u BitsPerSample not allowed for JPEG
PhotometricInterpretation %u not allowed for JPEG
$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $
$URL: VVV.lua.org $
#<wnaspi32.dll
GetASPI32SupportInfo
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
CNotSupportedException
{X-X-X-XX-XXXXXX}%*.*f
CHttpConnection
CHttpFile
hXXp://
windows
MSWHEEL_ROLLMSG
ddeexec
%s\ShellNew
%s\DefaultIcon
%s\shell\printto\%s
%s\shell\print\%s
%s\shell\open\%s
ole32.dll
cmd.exe
command.com
__MSVCRT_HEAP_SELECT
Broken pipe
Inappropriate I/O control operation
Operation not permitted
portuguese-brazilian
user32.dll
FWININET.dll
InternetCrackUrlA
InternetCanonicalizeUrlA
InternetOpenUrlA
FtpDeleteFileA
FtpRenameFileA
FtpCreateDirectoryA
FtpRemoveDirectoryA
FtpSetCurrentDirectoryA
FtpGetCurrentDirectoryA
FtpOpenFileA
FtpPutFileA
FtpGetFileA
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestA
HttpEndRequestA
HttpSendRequestExA
HttpQueryInfoA
FtpFindFirstFileA
WINMM.dll
WSOCK32.dll
VERSION.dll
MSACM32.dll
GetWindowsDirectoryA
GetProcessHeap
GetCPInfo
KERNEL32.dll
GetKeyState
MsgWaitForMultipleObjects
EnumWindows
GetAsyncKeyState
ExitWindowsEx
EnumChildWindows
UnhookWindowsHookEx
SetWindowsHookExA
CreateDialogIndirectParamA
USER32.dll
GetViewportExtEx
SetViewportExtEx
SetViewportOrgEx
OffsetViewportOrgEx
ScaleViewportExtEx
GDI32.dll
comdlg32.dll
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
RegOpenKeyA
RegCreateKeyExA
RegDeleteKeyA
RegQueryInfoKeyA
RegEnumKeyExA
RegEnumKeyA
RegCreateKeyA
ADVAPI32.dll
ShellExecuteA
ShellExecuteExA
SHELL32.dll
COMCTL32.dll
oledlg.dll
OLEPRO32.DLL
OLEAUT32.dll
URLDownloadToFileA
urlmon.dll
NETAPI32.dll
CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32.?AVCCmdTarget@@
Error evaluating stack - operand stack is empty.
%s.%d
A value was expected at position %d.
Missing operator before open parenthesis.
There is an operator missing before the open parenthesis at position %d.
The quotation mark at position %d is missing a match.
Operator:
The backslash (\) at position %d must be followed by another backslash (\) or a quote (") to form a valid escape sequence.The closed parenthesis at position %d does not have a matching open parenthesis.
The open parenthesis at position %d does not have a matching closed parenthesis.
The closed parenthesis at position %d needs something else to the left of it.
The open parenthesis at position %d needs something else to the left of it.
The operator at position %d needs a value to the left of it.
Values must be separated by operators.
The value at position %d needs something else to the left of it.
The operator at position %d needs a value to the right of it.
Operators must be separated by values.
There can't be two %s operators in a row.
"%s"%s
%s"%s"
"%s" %s "%s"
Error in operate(): no value on the operand stack
Error in operate(): not enough values on the operand stack
%s: %s
Error loading .btn file.
Error loading URL
Unable to display object: %s is not installed.
Web Object
Windows Media Player
Failed to load button file (#%d): %d
_manifest.xml
The file "%s" does not exist.
Could not load Down > Disabled image: "%s".
Could not load Down > Highlight image: "%s".
Could not load Down > Normal image: "%s".
Could not load Up > Disabled image: "%s".
Could not load Up > Highlight image: "%s".
Could not load Up > Normal image: "%s".
Copying "%s"
.PAVCFileException@@
kernel32.dll
"%s" %s
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
.bak%d
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Content-Type: application/x-www-form-urlencoded
%%x
%s %s %s %s
%s %s
%s v%d.%d
Windows ME
Windows 98
Windows 95
Windows Vista
Windows XP
Windows Server,XP x64
Windows 2000
Windows NT 4
Windows NT 3
%s\shell\open\command
\WININIT.INI
NUL=%s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.lnk
%s\%s.url
%s\%s.pif
*.tns
_fonts.dat
%s_%d
/\:*?"<>|
gdi32.dll
%s\_ir_tmpfnt_%d
MSG_INITIALIZING
Incorrect HTTP status returned by server: %d
.PAVCInternetException@@
Could not create Internet session: %u
Could not create HTTP connection: %u
Could not open request: %u
Send request failed: %u
WinINet.dll
d:d
.PAVCMemoryException@@
Error downloading file: %u
Error writing the destination file: %d-%u
Could not create HTTP connection
Could not HTTP file: %u
Could not open HTTP file: %s
.PAVCException@@
PTF://
hXXps://
jsproxy.dll
DetectAutoProxyUrl
wininet.dll
.tiff
.jpeg
.wbmp
End tag not completed for element %s
End tag does not correspond to %s
Expecting end tag of element %s
End tag of %s element not found
UxTheme.dll
*.gif
*.pcd
*.psd
*.emf
*.apm
*.wmf
*.tif
*.tga
*.png
*.pcx
*.jpg
*.bmp
.PAVCObject@@
.PAVCThreadException@@
.PAVCResourceException@@
Page %d of %d
local this="%s";
%s -> %s -> %s
local this="%s";local e_Key=%d;local e_Modifiers = {};e_Modifiers.ctrl=%s;e_Modifiers.alt=%s;e_Modifiers.shift=%sCAMSGridCtrl
CAMSGridCell
.?AVCAMSGridCell@@
.?AVCAMSGridCtrl@@
local e_Row = %d; local e_Column = %d; local e_OldText = "%s"; local e_NewText = "%s";
local e_Row = %d; local e_Column = %d;
local e_NodeIndex="%s";local this="%s";
local e_Key=%d;local e_Modifiers = {};e_Modifiers.ctrl=%s;e_Modifiers.alt=%s;e_Modifiers.shift=%s;local this="%s";local e_NodeIndex="%s";local e_Expanded=%s;local this="%s";
local e_NodeIndex="%s";local e_Checked=%s;local this="%s";
local e_NodeIndex="%s";local e_NewText="%s";local e_OldText ="%s";local this="%s";
%s%s1
number e_Key, table e_Modifiers
local this="%s";
local this="%s";local e_Index = %d; local e_FilePath = "%s"
%s -> %s ->
CAutoPlayWebObject
.?AVCAutoPlayWebObject@@
hXXp://VVV.indigorose.com
string e_URL
.?AVCWebBrowser2@@
WebWindow
local e_Key=%d;local e_Modifiers = {};e_Modifiers.ctrl=%s;e_Modifiers.alt=%s;e_Modifiers.shift=%s;local this="%s"local e_Selection=%d;local this="%s"
%s;local this="%s"
local e_Min=%d;local e_Max = %d;local e_Link = "%s";local this="%s"
local e_Min=%d;local e_Max = %d;local this="%s"
local e_Key=%d;local e_Modifiers = {};e_Modifiers.ctrl=%s;e_Modifiers.alt=%s;e_Modifiers.shift=%sProxy-Authorization: Basic %s
KERNEL32.DLL
PSAPI.DLL
Kernel32.dll
WS2_32.DLL
CWebBrowser2
MakeKeywordIndex
SearchKeywords
__NOREPORT__
Keywords
TRACE: LastError = %d ("%s")PasswordInput
All Files (*.*)|*.*|
Page.Jump("MSG_MOVING
MSG_COPYING
MSG_FROM_CAP
MSG_TO_CAP
MSG_DELETING
MSG_SEARCHING
OpenURL
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
ErrorMsg
%Y-%m-%dT%H:%M:%S
%A, %B %d, %Y
MSG_NOTICE
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
MSG_INSTALLING
RunMsiexec
\msi.dll
msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
\msiexec.exe
Page.Jump does not work during a Page Preview
Page.Navigate does not work during a Page Preview
GetKeyNames
DoesKeyExist
DeleteKey
CreateKey
AutoDetectURL
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion
MSG_SIZE_GIGABYTES
MSG_SIZE_MEGABYTES
MSG_SIZE_KILOBYTES
MSG_SIZE_BYTES
IsKeyDown
%s-%s-%s
%s/%s/%s
%d:%s:%s AM
%d:%s:%s PM
%s:%s:%s
Windows Server 2008
Windows Server 2003
xxxxxx
Software\Microsoft\Windows NT\CurrentVersion
MSG_ERROR
MSG_REBOOT_FAILED
AlwaysShowSelection
LoadURL
GetURL
GetHTTPErrorInfo
PPassword
Password
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%u %s/%u %s
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_FROM
MSG_SAVING
MSG_DOWNLOADING
WININET.DLL
MSG_QUERYING_INTERNET
MSG_READING
local e_Type = %d; local e_X = %d; local e_Y = %d;local this="%s";
local e_X = %d; local e_Y = %d;local this="%s";
local e_Type = %d; local e_X = %d; local e_Y = %d; local this="%s";
local e_Type = %d; local e_X = %d; local e_Y = %d;local this="%s"
%s -> %s
local this="%s";local e_Channel=%d;local e_State="%s"
local e_WindowWidth = %d; local e_WindowHeight = %d; local e_DialogWidth = %d; local e_DialogHeight = %d; local e_Type = %d;local this="%s";
%s/%s
%s (0x%2x)
Cannot play back the video stream: format 'RPZA' is not supported.
Some of the streams in this movie are in an unsupported format.
Use of this filter is restricted by a software key. The application must unlock the filter.
Frame stepping is not supported.
This operation is not permitted in the current domain.
This user operation is inhibited by DVD content at this time.
No video port hardware is available, or the hardware is not responding.
The video port connection negotiation process has failed.
Pins cannot connect because they don't support the same transport.
Cannot play back the file: the format is not supported.
Cannot play back the video stream: the video format is not supported.
Cannot play back the audio stream: the audio format is not supported.
Cannot play back the audio stream: no audio hardware is available, or the hardware is not supported.
The operation could not be performed because the filter is in the wrong state
The operation could not be performed because the filter is not running.
The operation could not be performed because the filter is not paused.
The operation could not be performed because the filter is not stopped.
No matching color key is available.
Setting a palette would conflict with the color key already set.
Setting a color key would conflict with the palette already set.
Current pin connection is not using the IMemInputPin transport.
Current pin connection is not using the IOverlay transport.
No color key has been set.
The operation cannot be performed because the pins are not connected.
One of the specified pins supports no media types.
At least one of the pins involved in the operation is already connected.
This operation cannot be performed because the filter is active.
font%d.dat
Advapi32.dll
MSG_REDIRECTING
MSG_STATUS_REQUEST_COMPLETE
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_HANDLE_CREATED
MSG_CONNECTION_CLOSED
MSG_CLOSING_CONNECTION
MSG_CONNECTED_TO_SERVER
MSG_CONNECTING_TO_SERVER
MSG_HOST_NAME_RESOLVED
MSG_RESOLVING_HOST_NAME
%s, Line %d: %s
[%d]: %s
*** LOCATION: %s
local e_WindowWidth = %d; local e_WindowHeight = %d; local e_PageWidth = %d; local e_PageHeight = %d; local e_Type = %d;local this="%s";
local e_WindowWidth = %d; local e_WindowHeight = %d; local e_PageWidth = %d; local e_PageHeight = %d; local e_Type = %d;
Project -> %s
local e_ID = %d;%s;local this="%s"
local e_ID = %d;%s
local e_ItemInfo = {}; e_ItemInfo.Text="%s";e_ItemInfo.ID=%d; e_ItemInfo.Checked=%s;e_ItemInfo.Enabled=%s; e_ItemInfo.IconID=%d0.0.0.0
%s >= %s
__IR_TEMP_DETECT_VER = %s();
RICHED32.DLL
RICHED20.DLL
comctl32.dll
Failed to initialize sound system: %s
{19813504-68A4-EFEC-925D-B3CD087B8175}_proj.dat
Recording not supported on this device
An invalid parameter was passed to this function
The version number of this file format is not supported
Error setting cooperative level for hardware.
Soundcard does not support the features needed for this soundsystem (16bit stereo output)
and can not be run with the commercial version's runtime executable.
Detection script: %s
_detect.dat
MissingAXHelpURL
?;%s\AutoPlay\Scripts\?;%s\AutoPlay\Scripts\?.lua;%s\?.lua;%s\?;
Failed to load plugin: %s (#%d)
Debug.ShowWindow(true);
Debug.SetTraceMode(true);
%s\menu1.dah
local this="%s";local e_FSCommand="%s";local e_FSArgs="%s";
local this="%s";local e_URL="%s";
local e_Type = %d; local e_X = %d; local e_Y = %d
Created with AutoPlay Media Studio Trial - hXXp://VVV.indigorose.com
%Program Files%
C:\Temp
_WindowsFolder
IS 3.0.58.3
DIBToHBITMAP error: GetLastError = %d
SetWinMetaFileBits failed GetLastError = %d
read %d. layersLen %d
ISLib PNG Error : %s
1.2.8
Reading PCD sub-image #%d (%d x %d)
ISLib JPG Error : %s
ISLib JPG marker # %d, len: %d
ISLib JPG comment : %s
Found bad IPTC data resource (len exceeds block end). ID=%d
NULL row buffer for row %ld, pass %d
libpng error: %s
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning: %s
libpng warning no. %s: %s
iTXt chunk not supported.
GeoKeyDirectory
%s: Cannot modify tag "%s" while writing
%s: Unknown %stag %u
%s: Bad value %f for "%s"
%s: Invalid %stag "%s" (not supported by codec)
%s: Bad field type %d for "%s"
%s: Pass by value is not implemented.
%s: Failed to allocate space for list of custom values
%s: Bad value %ld for "%s"
%s: Bad value %d for "%s"
%s: Sorry, cannot nest SubIFDs
Nonstandard tile length %d, convert file
Nonstandard tile width %d, convert file
Bad value %ld for "%s" tag ignored
%s: Invalid InkNames value; expecting %d names, found %d
%s: Error fetching directory count
%s: Error fetching directory link
Sorry, can not handle images with %d-bit samples
Sorry, LogL data must have %s=%d
Sorry, can not handle LogLuv images with %s=%d
Sorry, LogLuv data must have %s=%d or %d
Sorry, can not handle image with %s=%d
Sorry, can not handle YCbCr images with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d and Bits/Sample=%d
Sorry, can not handle RGB image with %s=%d
Sorry, can not handle separated image with %s=%d
Missing needed %s tag
%s: Read error at scanline %lu, strip %lu; got %lu bytes, expected %lu
%s: Read error at scanline %lu; got %lu bytes, expected %lu
%s: Seek error at scanline %lu, strip %lu
%s: Data buffer too small to hold strip %lu
%s: Read error on strip %lu; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld, tile %ld; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld; got %lu bytes, expected %lu
%s: Seek error at row %ld, col %ld, tile %ld
%s: Data buffer too small to hold tile %ld
%s: No space for data buffer at scanline %ld
Integer overflow in %s
"%s": Bad mode
Not a TIFF file, bad version number %d (0x%x)
This is a BigTIFF file. This format not supported
Not a TIFF file, bad magic number %d (0x%x)
%s: Out of memory (TIFF structure)
Corrupt JPEG data: found marker 0xx instead of RST%d
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
RST%d
At marker 0xx, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Unsupported marker type 0xx
Failed to create temporary file %s
Unsupported JPEG process: SOF type 0xx
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Huffman table 0xx was not defined
Backing store not supported
Cannot transcode due to multiple use of quantization table %d
Maximum supported image dimension is %u pixels
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
Buffer passed to JPEG library is too small
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Wrong JPEG library version: library is %d, caller expects %d
IDCT output block size %d not supported
Invalid component ID %d in SOS
Bogus message code %d
%s: Write error at scanline %lu
%s: Seek error at scanline %lu
"%s": Information lost writing value (%g) as (unsigned) RATIONAL
Error writing data for field "%s"
%s: Error writing SubIFD directory link
ExifInteroperabilityOffset
InteroperabilityIndex
InteroperabilityVersion
Unknown zTXt compression type %d
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
Internal error, unknown tag 0x%x
Tag %d
Compression scheme %u %s encoding is not implemented
%s %s encoding is not implemented
Compression scheme %u %s decoding is not implemented
%s %s decoding is not implemented
Compression algorithm does not support random access
%s: cannot handle zero strip size
%s: cannot handle zero tile size
%s: cannot handle zero scanline size
%s: Bogus "%s" field, ignoring and calculating from imagelength
%s: TIFF directory is missing required "%s" field, calculating from imagelength
%s: cannot handle zero number of %s
%s: wrong data type %d for "%s"; tag ignored
%s: unknown field with tag %d (0x%x) encountered
%s: invalid TIFF directory; tags are not sorted in ascending order
%s: Can not read TIFF directory
%s: Can not read TIFF directory count
%s: Seek error accessing TIFF directory
%s: Failed to allocate space for IFD list
No space %s
%s: Cannot determine size of unknown tag type %d
%s: TIFF directory is missing required "%s" field
incorrect count for field "%s" (%lu, expecting %lu); tag trimmed
incorrect count for field "%s" (%lu, expecting %lu); tag ignored
Error fetching data for field "%s"
%s: Rational with zero denominator (num = %lu)
Cannot handle different per-sample values for field "%s"
cannot read TIFF_ANY type %d for field "%s"
%ld%c
%s compression support is not configured
?%s: No space for LogLuv state block
Inappropriate photometric interpretation %d for SGILog compression; %s
LogL16Decode: Not enough data at row %d (short %d pixels)
LogLuvDecode24: Not enough data at row %d (short %d pixels)
LogLuvDecode32: Not enough data at row %d (short %d pixels)
%s: No space for SGILog translation buffer
No support for converting user data format to LogL
No support for converting user data format to LogLuv
SGILog compression supported only for %s, or raw data
Unknown data format %d for LogLuv compression
Unknown encoding %d for LogLuv compression
PixarLog compression can't handle bits depth/data format combination (depth: %d)
%d bit input not supported in PixarLog
PixarLogDecode: unsupported bits/sample: %d
%s: zlib error: %s
%s: Not enough data at scanline %d (short %d bytes)
%s: Decoding error at scanline %d, %s
PixarLog compression can't handle %d bit linear encodings
%s: Encoder error: %s
%s: No space for state block
%s: Bad code word at scanline %d (x %lu)
%s: %s at scanline %d (got %lu, expected %lu)
%s: Premature EOF at scanline %d (x %lu)
%s: No space for Group 3/4 reference line
%s: Uncompressed data (not supported) at scanline %d (x %lu)
Fax SubAddress: %s
(%u = 0x%x)
%suncompressed data
%sEOL padding
%s2-d encoding
%s compression not supported
Tiled Wang image not supported in libtiff
Does not support lossless Huffman coding
Decompressor will try reading with sampling %d,%d.
Improper JPEG sampling factors %d,%d
Apparently should be %d,%d.
Improper JPEG strip/tile size, expected %dx%d, got %dx%d
RowsPerStrip must be multiple of %d for JPEG
JPEG tile width must be multiple of %d
JPEG tile height must be multiple of %d
BitsPerSample %d not allowed for JPEG
PhotometricInterpretation %d not allowed for JPEG
ThunderDecode: %s data at scanline %ld (%lu != %lu)
PackBitsDecode: discarding %d bytes to avoid buffer overrun
LZWDecode: Corrupted LZW table at scanline %d
LZWDecode: Not enough data at scanline %d (short %d bytes)
LZWDecode: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecode: Strip %d not terminated with EOI code
LZWDecode: Bogus encoding, loop in the code table; scanline %d
LZWDecodeCompat: Corrupted LZW table at scanline %d
LZWDecodeCompat: Not enough data at scanline %d (short %d bytes)
LZWDecodeCompat: Wrong length of decoded string: data probably corrupted at scanline %d
DumpModeDecode: Not enough data for scanline %d
Horizontal differencing "Predictor" not supported with %d-bit samples
"Predictor" value %d not supported
%u (0x%x)
Lua 5.0.2
bad argument #%d to `%s' (%s)
calling `%s' on bad self (%s)
%s expected, got %s
%s:%d:
stack overflow (%s)
cannot read %s: %s
attempt to %s a %s value
attempt to %s %s `%s' (a %s value)
attempt to compare %s with %s
attempt to compare two %s values
%s:%d: %s
system error %d
file (%s)
`popen' not supported
field `%s' missing in date table
^$* ?.([%-
missing `[' after `%%f' in pattern
no function environment for tail call at level %d
could not load package `%s' from path `%s'
error loading package `%s' (%s)
?;?.lua
`__pow' (`^' operator) is not a function
invalid key for `next'
too many %s (limit=%d)
%s:%d: %s near `%s'
char(%d)
`%s' expected (to close `%s' at line %d)
`%s' expected
bad code in %s
unexpected end of file in %s
bad integer in %s
bad nupvalues in %s: read %d; expected %d
bad constant type (%d) in %s
unknown number format in %s
%s too old: read version %d.%d; expected at least %d.%d
%s too new: read version %d.%d; expected at most %d.%d
bad signature in %s
virtual machine mismatch in %s: size of %s is %d but read %d
C:\Dev\fmodsrc375win\src\fsound_stream.c
http:\\
C:\Dev\fmodsrc375win\src\fsound.c
C:\Dev\fmodsrc375win\src\fsound_tag.c
C:\Dev\fmodsrc375win\src\system_memory.c
C:\Dev\fmodsrc375win\src\fsound_dsp.c
C:\Dev\fmodsrc375win\src\system_thread.c
C:\Dev\fmodsrc375win\src\system_file.c
The DLLs/EXEs of ASPI don't version check
No resources available to execute cmd
ASPI for windows failed init
Unsupported Windows mode
ASPI manager doesn't support Windows
C:\Dev\fmodsrc375win\win\src\fsound_cdda.c
\\.\%c:
ERROR: %c: already open
ERROR: Couldn't access CD/DVD device at %c:
ERROR: %s
ERROR: Failed to initialise ASPI (%s)
wmvcore.dll
C:\Dev\fmodsrc375win\win\src\format_asf.cpp
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\vorbisfile.c
C:\Dev\fmodsrc375win\win\src\format_dshow.c
C:\Dev\fmodsrc375win\src\fsound_sample.c
C:\Dev\fmodsrc375win\src\format_mpeg.c
C:\Dev\fmodsrc375win\src\format_oggvorbis.c
C:\Dev\fmodsrc375win\src\format_wav.c
C:\Dev\fmodsrc375win\src\format_fsb.c
C:\Dev\fmodsrc375win\src\format_oggvorbis_net.c
C:\Dev\fmodsrc375win\src\format_mpeg_net.c
StreamUrl='
HTTP/1.1
HTTP/1.0
C:\Dev\fmodsrc375win\src\fsound_stream_net.c
ice-url
ice-url:
icy-url
icy-url:
Authorization: Basic %s
Host: %s
GET %s HTTP/1.1
C:\Dev\fmodsrc375win\src\sound_software.c
C:\Dev\fmodsrc375win\win\src\output_winmm.c
ddraw.dll
\d3d9.dll
dsound3d.dll
dsound.dll
%s: Left = ASIO CH %d Right = ASIO CH %d
C:\Dev\fmodsrc375win\win\src\output_asio.cpp
C:\Dev\fmodsrc375win\win\src\fsound_systemmixer_win32.c
Software\Microsoft\Windows\CurrentVersion\Multimedia\MIDIMap
C:\Dev\fmodsrc375win\win\src\music_formatmidi.c
C:\Dev\fmodsrc375win\src\fsound_dsp_fft.c
C:\Dev\fmodsrc375win\ogg_vorbis\ogg\src\framing.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\info.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\block.c
C:\Dev\fmodsrc375win\src\format_it.c
C:\Dev\fmodsrc375win\src\system_net.c
C:\Dev\fmodsrc375win\src\music_formatmod.c
C:\Dev\fmodsrc375win\src\music_formatit.c
C:\Dev\fmodsrc375win\src\music_formatxm.c
C:\Dev\fmodsrc375win\src\music_formats3m.c
C:\Dev\fmodsrc375win\src\music_formatfsb.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\psy.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\sharedbook.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\codebook.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\mdct.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\envelope.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\mapping0.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\res0.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\floor1.c
C:\Dev\fmodsrc375win\ogg_vorbis\vorbis\lib\floor0.c
%s %s
%s %s (%s)
u/u/u u:u
%s %lx
%s %d %s
All Files|*.*||
dzprog32 /%c /u /T=%s
Version: 4.00.04 - %s %s
%s [Memory]
%s [Tested]
%s [Extracted]
--- DynaZIP UnZIP Log - %s ---
\DUNZLOG.TXT
%s exists and is Read Only, do you want to overwrite it?
Decryption key not provided, or too long
UNZIPCMDSTRUCT Size is incorrect.
\DYNAZIP.LOG
decryptFlag: %d
returnCount: %d
noDirectoryItemsFlag: %d
recurseFlag: %d
noDirectoryNamesFlag: %d
testFlag: %d
quietFlag: %d
overWriteFlag: %d
updateFlag: %d
freshenFlag: %d
index: %d
Function: %d
--- DynaZIP UnZIP Diagnostic Log - %s ---
returnCount: %d
File to Memory: %s
Testing: %s
Extracting: %s
Item %d of %d
%s is encrypted, and you have not provided the correct code. Go to next item (if any)?
%s exists, do you want to overwrite it?
User skipped this operation
User cancelled this operation
Bad or missing decryption key
Application cancelled operation
Multi-disk archive, not supported
Target Media is NON-Removable and can not be used for a Multi-Volume operation.
Please insert Disk Volume %d of %d.
Please insert Disk Volume %d.
PKBACK# d
dzprog32.exe /%c /z /T=%s
:;,= "[]<>|
-.Z:.zip:.zoo:.arc:.lzh:.arj
PKBACK# .d
%s [Deleted]
%s [Added]
--- DynaZIP ZIP Log - %s ---
\DZIPLOG.TXT
Wiping Drive %c:...
Formatting Cylinder %d
Formatting Drive %c:...
zip error: STORE not supported for pipes or devices
local extra (%d bytes) != central extra (%d bytes):
has %d bytes of extra data:
unknown internal attributes = 0xx:
starts on disk %u:
unknown compression method %u:
undefined bits used in flags = 0xx:
local flags = 0xx, central = 0xx:
needs unzip %d.%d on system type %d:
made by version %d.%d on system type %d:
Could not complete operation
Operation interrupted by application
encryptFlag: %d
dontCompressTheseSuffixesFlag: %d
includeSysHiddenFlag: %d
noDirectoryEntriesFlag: %d
excludeFollowingFlag: %d
includeOnlyFollowingFlag: %d
oldAsLatestFlag: %d
afterDateFlag: %d
addCommentFlag: %d
convertLFtoCRLFFlag: %d
growExistingFlag: %d
deleteOriginalFlag: %d
includeVolumeFlag: %d
fixHarderFlag: %d
fixFlag: %d
pathForTempFlag: %d
compFactor: %d
dosifyFlag: %d
Function: %d
--- DynaZIP ZIP Diagnostic Log - %s ---
was getting encryption password
encryption not supported
\\.\vwin32
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCArchiveException@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.PAVCOleException@@
.PAVCOleDispatchException@@
zcÁ
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\ir_ext_temp_0\autorun.exe
333333334
.nM(aL8
(H7.www
version="7.5.1000.0"
name="autorun.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
hDRMHeader.SubscriptionContentID
DRMHeader.ContentDistributor
DRMHeader.SECURITYVERSION
DRMHeader.CID
DRMHeader.LAINFO
DRMHeader.KID
LicenseStateData.Transfer.NONSDMI
LicenseStateData.Transfer.SDMI
LicenseStateData.Print.redbook
LicenseStateData.Play
ActionAllowed.Backup
ActionAllowed.Transfer.NONSDMI
ActionAllowed.Transfer.SDMI
ActionAllowed.Print.redbook
ActionAllowed.Play
BaseLAURL
Transfer.NONSDMI
Transfer.SDMI
Print.redbook
CopyrightURL
BannerImageURL
WM/AlbumCoverURL
WM/PromotionURL
To see what data this error report contains,
We have created an error report which will help us to improve this product. We will treat this report as confidential and anonymous. No personal data will be transmitted other than what you provide to us.
Jump target not found2The operating system is out of memory or resources!The specified file was not found.!The specified path was not found.AThe .exe file is invalid (non-Win32 .exe or error in .exe image).9The operating system denied access to the specified file.3The file name association is incomplete or invalid._The DDE transaction could not be completed because other DDE transactions were being processed.
The DDE transaction failed.IThe DDE transaction could not be completed because the request timed out.1The specified dynamic-link library was not found.FThere is no application associated with the given file name extension.6There was not enough memory to complete the operation.
Unidentified execution error.=Could not find the startup page specified in Project|Settings
Page does not exist:#The specified object was not found.EThe action could not be performed because the content file is closed.:The Video Object's state was incompatible with the action.2The "SeekTime" value is to large for Video Object.6The "SeekTime" value cannot be less than negative one.
%d arguments required.
Argument %d must be of type %s.
Confirm Abort2Are you sure that you want to abort the operation?
Replace%Select the entire document
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Page %u
Pages %u-%u
Output.prn1Printer Files (*.prn)|*.prn|All Files (*.*)|*.*||
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
04090000
Created with AutoPlay Media Studio (VVV.indigorose.com)
21.25.32.445
2008-2009-2010-2011 (VVV.ChattChitto.com)
autorun.exe
Hard Disk Sentinel Pro v4.00 Key
4.0.0.0
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
autorun.exe:460
HARDDI~1.EXE:652
%original file name%.exe:892 - Delete the original Trojan-Dropper file.
- Delete or disinfect the following files created/modified by the Trojan-Dropper:
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Verdana_1.TFT (137 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Trajan Pro.TFT (68 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Arial_1.TFT (1648 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_tmpfnt_1\Symbol.TFT (69 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\btn_donate_SM.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRWipeTransitions.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\attention.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\50_1644.btn (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\Folder.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{8BAB0DFF-94C7-4A12-849F-99A6FBA900DA}_Large.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{B704C68B-BAC0-493B-BAD0-358999040560}_Large.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_i.swf (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{8BAB0DFF-94C7-4A12-849F-99A6FBA900DA}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\CC13.jpg (2425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\desktop.ini (374 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\3_1644.btn (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRSlideTransition.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\Click1.ogg (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\High1.ogg (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_clouds.swf (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\hoBrl77.png (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\autorun.cdd (6441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\hdsentinel_pro_setup.exe (103529 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\IRDissolveTransition.tns (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\ChattChitto RG.nfo.txt (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Plugins\Clipboard\Clipboard.lmd (1209 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\globe.swf (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{FACB06FE-F1B9-45D4-9237-DABBDDACC4AD}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\autorun.exe (22471 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\Thumbs.db (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\02 - God Rest Ye Merry, Gentlemen.wma (12751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArt_{B704C68B-BAC0-493B-BAD0-358999040560}_Small.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\ChattChittoRG.ico (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Audio\AlbumArtSmall.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Flash\indigo_glitter.swf (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Images\600px-Feed_Icon_Bl-Or.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Buttons\7_1644.btn (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ir_ext_temp_0\AutoPlay\Docs\HDSentinel.zip (679 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\test11.exe (6881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\HARDDI~1.EXE (281494 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.