Trojan.Win32.Swrort.3_8420bcfca9

Trojan-Downloader.Win32.Upatre.fwnb (Kaspersky), Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS) Behaviour: Trojan-Downloader, Trojan The description has been automatically generated...
Blog rating:5 out of5 with1 ratings

Trojan.Win32.Swrort.3_8420bcfca9

by malwarelabrobot on March 21st, 2017 in Malware Descriptions.

Trojan-Downloader.Win32.Upatre.fwnb (Kaspersky), Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan-Downloader, Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 8420bcfca9f50ac4f44a5d8daff062a5
SHA1: 474466ee9120d2c10bf73482f16ba905d0c8d054
SHA256: 44890b89b0b17d88ca669dcbd24e8bfb07519df6ae2c72cdc9503fddd001dbc6
SSDeep: 98304:AzlkbFDVrQMyOr3S3d6cLhUzTo51vXBiq7FGY98E:KeVUKSN6c1UzcGq7FuE
Size: 3646459 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-02-09 23:57:00
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

%original file name%.exe:1084
start.exe:3972
soundbar.exe:3352
cpa.exe:3568
irsetup.exe:2404
irsetup.exe:3436

The Trojan injects its code into the following process(es):

CodecFixDivx.exe:4012
ntvdm.exe:4016
irsetup.exe:1480
irsetup.exe:3456

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:1084 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dll (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (50 bytes)

The process ntvdm.exe:4016 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9B93.tmp (335 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp (269 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9B93.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp (0 bytes)

The process start.exe:3972 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\lua5.1.dll (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.exe (50 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\lua5.1.dll (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe (0 bytes)

The process soundbar.exe:3352 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\lua5.1.dll (329 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe (0 bytes)

The process cpa.exe:3568 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\lua5.1.dll (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe (50 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (0 bytes)

The process irsetup.exe:2404 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Windows\chromebrowser.exe (39122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\lua5.1.dll (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.dat (1209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\dox.enc (26347 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG1.JPG (2 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG1.JPG (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG2.JPG (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.dat (0 bytes)

The process irsetup.exe:1480 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.dat (143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\IRIMG1.JPG (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\lua5.1.dll (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\IRIMG2.JPG (21 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.dat (0 bytes)

The process irsetup.exe:3456 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.dat (1209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\Elow.enc (10720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\CUE.enc (11337 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\start.enc (43519 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\fox.enc (28 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9Z68MLW7.txt (159 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wowrr.exe (4016 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\start.exe (69050 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fox.exe (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CodecFixDivx.exe (17280 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\kube.enc (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\lua5.1.dll (331 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IRW8F63.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3Y8Q956L.txt (0 bytes)

The process irsetup.exe:3436 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar3FDF.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\setupfiles.txt (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\cpa.enc (14968 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\soundbar.exe (3932903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\46VRC840.txt (121 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LRMHZCNI.txt (329 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB (471 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB (1278 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DCE3BDBF5BDD86E2AB5B471CB90709B4_9EDD577FDC96330CA9B09E84FD8389E3 (992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab3FDE.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DCE3BDBF5BDD86E2AB5B471CB90709B4_9EDD577FDC96330CA9B09E84FD8389E3 (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\RLOS3CDY.txt (70 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dll (331 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3Y8Q956L.txt (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3SNVEHUW.txt (244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpa.exe (28837 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 (1290 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar3FDF.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\RLOS3CDY.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IRW1DEB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IRW6D46.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab3FDE.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\46VRC840.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (0 bytes)

Registry activity

The process %original file name%.exe:1084 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe,"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process start.exe:3972 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process soundbar.exe:3352 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process cpa.exe:3568 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process irsetup.exe:2404 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments]
"SaveZoneInformation" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations]
"LowRiskFileTypes" = ".avi;.bat;.com;.cmd;.exe;.htm;.html;.lnk;.mpg;.mpeg;.mov;.mp3;.msi;.m3u;.rar;.reg;.txt;.vbs;.wav;.zip;"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"EnableLUA" = "0"
"ConsentPromptBehaviorAdmin" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"chromebrowser" = "C:\Windows\chromebrowser.exe"

The process irsetup.exe:3456 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3D 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

"UNCAsIntranet" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"

The process irsetup.exe:3436 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASAPI32]
"MaxFileSize" = "1048576"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASMANCS]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASAPI32]
"FileDirectory" = "%windir%\tracing"
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD]
"Blob" = "0F 00 00 00 01 00 00 00 20 00 00 00 52 29 BA 15"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASMANCS]
"FileTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASMANCS]
"FileDirectory" = "%windir%\tracing"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASAPI32]
"EnableFileTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASMANCS]
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Microsoft\Tracing\irsetup_RASAPI32]
"EnableConsoleTracing" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"D69B561148F01C77C54578C10926DF5B856976AD"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

Dropped PE files

MD5 File path
aa6d8d2e9de1b879abc9f3b914113e72 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\CodecFixDivx.exe
c3f5f4a1fb69b5889f0bbb313cf6017f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dll
e68dab1a49554dbf2f9c6a0d57997b26 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\soundbar.exe
9bdcf813d65265255b820bc7a704da3c c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe
c3f5f4a1fb69b5889f0bbb313cf6017f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\lua5.1.dll
9bdcf813d65265255b820bc7a704da3c c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe
c3f5f4a1fb69b5889f0bbb313cf6017f c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\lua5.1.dll
d7e65559e9394e62788aeee611f52bfe c:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpa.exe
d385f55d7e943108e85b1a75c6aad5bb c:\Users\"%CurrentUserName%"\AppData\Local\Temp\fox.exe
cfc25d9ad183c712593ddaf19a9146af c:\Users\"%CurrentUserName%"\AppData\Local\Temp\start.exe
92ef5c26c25757f85161fdac6cb2de77 c:\Windows\chromebrowser.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name: Setup Factory Runtime
Product Version: 9.5.0.0
Legal Copyright: Setup Engine Copyright (c) 2004-2015 Indigo Rose Corporation
Legal Trademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Original Filename: suf_launch.exe
Internal Name: suf_launch
File Version: 9.5.0.0
File Description: Setup Application
Comments: Created with Setup Factory
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 22296 22528 4.47735 c76b9ce587690b8a39ba7840b7dd540c
.rdata 28672 11906 12288 3.44864 e96aa4f970e6f6799910a72904df3100
.data 40960 6504 3072 1.79291 e504fdbba062ee9bbd9ac425a4f5c0f5
.rsrc 49152 29324 29696 4.02217 6141235749f568a85fe4b093f65da085
.reloc 81920 4242 4608 2.5731 a88bdb6f651ecf67b1b3db4a2866ea4e

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 10
f2eac8f098a69f1cb1cbe4b0cb910da3
09c4e1d9d6e09c5171ecae3d93c441bf
15ba4f516276debb9359f1cceb6e277c
9887437f69b2b34521c77355d97d6e90
2ede0d1ddf14f9973c6d95e6205103b1
f30e813f1abfe1467ff928c263d4ad0a
0559d2993708479850dd627646114156
a9598332413972f98b14e1d5350a194a
282b1803c5123a0904fe9185e82cdd8a
4191e5f649762e227fadf4a25e7d731b

URLs

URL IP
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX+JrHYM=
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8=
hxxp://cs9.wac.phicdn.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY+sl+j4yzQuAcL2oQno5fCgQUUWj/kK8CB3U8zNllZGKiErhZcjsCEA9N5D4ZnViCc5eMbrXeuZM=
hxxp://alfafile.net/file/UD4G 195.211.221.157
hxxp://a9.alfafile.net/dl/zf2tV/Elo.exe 78.108.187.88
hxxp://alfafile.net/file/UkjZ 195.211.221.157
hxxp://huh.adowableunco.bid/h_redir.php?offer_id=4&aff_id=2091&source=1918&aff_sub=MeDrop&aff_sub2=&aff_sub3=&aff_sub4=LP_DEF&aff_sub5=1110300186&url=http://huh.adowableunco.bid/offer.php?affId={aff_id}&trackingId=199063968&instId=1918&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&net=4.5.50709&ie=9.0.8112.16421&wv=7sp1&db=InternetExplorer&uac=1&cid=5c12d1104cca24294ae7d8d45ce8d028&v=3 52.222.174.185
hxxp://a1363.dscg.akamai.net/pki/crl/products/MicCodSigPCA_08-31-2010.crl
hxxp://a1158.b.akamai.net/MFUwUzBRME8wTTAJBgUrDgMCGgUABBTkLVLomfJQOu5CFIgPOR73ljBRHAQU+L36r3N3xscb+UtNEafRM6+vchECFEOZrYpYgDwxeWGj/HetMtWiXvU/
hxxp://clients.l.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGZimYWX7CS+
hxxp://crl.comodoca.com.cdn.cloudflare.net/UTN-DATACorpSGC.crl 104.16.93.188
hxxp://vassg142.ocsp.omniroot.com/MFUwUzBRME8wTTAJBgUrDgMCGgUABBTkLVLomfJQOu5CFIgPOR73ljBRHAQU+L36r3N3xscb+UtNEafRM6+vchECFEOZrYpYgDwxeWGj/HetMtWiXvU/ 2.21.89.35
hxxp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl 212.30.134.167
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8= 93.184.220.29
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX+JrHYM= 93.184.220.29
hxxp://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY+sl+j4yzQuAcL2oQno5fCgQUUWj/kK8CB3U8zNllZGKiErhZcjsCEA9N5D4ZnViCc5eMbrXeuZM= 93.184.220.29
hxxp://clients1.google.com/ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGZimYWX7CS+ 172.217.20.174
hxxp://crl.comodoca.com/UTN-DATACorpSGC.crl 104.16.93.188
hxxp://huh.adowableunco.bidhxxp://huh.adowableunco.bid/h_redir.php?offer_id=4&aff_id=2091&source=1918&aff_sub=MeDrop&aff_sub2=&aff_sub3=&aff_sub4=LP_DEF&aff_sub5=1110300186&url=http://huh.adowableunco.bid/offer.php?affId={aff_id}&trackingId=199063968&instId=1918&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&net=4.5.50709&ie=9.0.8112.16421&wv=7sp1&db=InternetExplorer&uac=1&cid=5c12d1104cca24294ae7d8d45ce8d028&v=3 52.222.174.185
www.dropbox.com 162.125.66.1
dl.dropboxusercontent.com 162.125.66.6


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile
ET POLICY Terse Named Filename EXE Download - Possibly Hostile
ET POLICY PE EXE or DLL Windows file download HTTP
ET TROJAN Backdoor User-Agent (InstallCapital)
ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected

Traffic

GET hXXp://huh.adowableunco.bid/h_redir.php?offer_id=4&aff_id=2091&source=1918&aff_sub=MeDrop&aff_sub2=&aff_sub3=&aff_sub4=LP_DEF&aff_sub5=1110300186&url=http://huh.adowableunco.bid/offer.php?affId={aff_id}&trackingId=199063968&instId=1918&ho_trackingid={transaction_id}&cc={country_code}&cc_typ=ho&sb=x86&net=4.5.50709&ie=9.0.8112.16421&wv=7sp1&db=InternetExplorer&uac=1&cid=5c12d1104cca24294ae7d8d45ce8d028&v=3 HTTP/1.1
Host: huh.adowableunco.bid
Connection: close
Accept: */*
User-Agent: InstallCapital


HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 0
Connection: close
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.3.28
Date: Mon, 20 Mar 2017 05:53:26 GMT
X-Cache: Miss from cloudfront
Via: 1.1 cd57e6888980d1e458b233b5ef20ee46.cloudfront.net (CloudFront)
X-Amz-Cf-Id: M3hMjtJJO0k1u1lMlXXQTazFeazAwjYcTglXUhjVYAjPEJFqRoXo1A==


GET /dl/zf2tV/Elo.exe HTTP/1.1
Accept: */*
User-Agent: Setup Factory 8.0
Host: a9.alfafile.net
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx
Date: Mon, 20 Mar 2017 05:53:52 GMT
Content-Type: application/octet-stream
Content-Length: 7974917
Last-Modified: Sun, 19 Mar 2017 22:06:59 GMT
Connection: keep-alive
Content-Disposition: attachment; filename="Elo.exe"
ETag: "58cf0103-79b005"
Strict-Transport-Security: max-age=604800
Accept-Ranges: bytes
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.........2...\...\.
..\..'....\..'....\.......\...]...\..'....\..'....\..'....\.Rich..\...
......PE..L...,-.T.................X...........).......p....@.........
.................P......J6....@.................................<..
.d........n...................0.......................................
...@............p..x............................text....W.......X.....
............. ..`.rdata.......p...0...\..............@..@.data...h....
.......................@....rsrc....n.......p..................@..@.re
loc.......0......................@..B.................................
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U...X......... .@.3..E.
SVW.}.3.h....S....@...dq@.P..hq@........`........V......SP.......Pp@..
..W..;.}.W......P...p@.3.h..........WP..............9=..@.......3.F...
@..4.......P...p@......./ub......<Tt"<Wt.<tt.<wuL......P..
...u>.......6......P.....~(......:u....~....P......P......P........
j.h.q@.j.......PVj....p@....u..5..@.G;=..@...O.................F...1w.
.......u.j.h.q@.......Pj...lq@........u....M._..^3.[.........V..W3.h..
........WP...q@...0.....8.....<.....@.....D....A..............H

<<< skipped >>>

GET /file/UD4G HTTP/1.1
Accept: */*
Content-Type: application/x-www-form-urlencoded
User-Agent: Setup Factory 8.0
Host: alfafile.net
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 302 Moved Temporarily
Server: nginx
Date: Mon, 20 Mar 2017 05:53:51 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: hXXp://a9.alfafile.net/dl/zf2tV/Elo.exe
Set-Cookie: pref=m+NgPUhaqL3hDkY3InAZg6XU2Wwaz9Wpja7Yn8UdklQ=|672d428ab363dab863eec490f0b536c8; expires=Mon, 20-Mar-2017 06:53:51 GMT; Max-Age=3600; path=/payment
Set-Cookie: lang=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Set-Cookie: ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/file/UD4G
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Strict-Transport-Security: max-age=604800
0..HTTP/1.1 302 Moved Temporarily..Server: nginx..Date: Mon, 20 Mar 20
17 05:53:51 GMT..Content-Type: text/html; charset=UTF-8..Transfer-Enco
ding: chunked..Connection: keep-alive..Location: hXXp://a9.alfafile.ne
t/dl/zf2tV/Elo.exe..Set-Cookie: pref=m+NgPUhaqL3hDkY3InAZg6XU2Wwaz9W
pja7Yn8UdklQ=|672d428ab363dab863eec490f0b536c8; expires=Mon, 20-Ma
r-2017 06:53:51 GMT; Max-Age=3600; path=/payment..Set-Cookie: lang=del
eted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/..Set-Co
okie: ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; p
ath=/file/UD4G..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control:
no-cache..Strict-Transport-Security: max-age=604800..0..


GET /file/UkjZ HTTP/1.1
Accept: */*
Content-Type: application/x-www-form-urlencoded
User-Agent: Setup Factory 8.0
Host: alfafile.net
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx
Date: Mon, 20 Mar 2017 05:54:00 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: pref=9Wr/deARqbu69nIpu70RS/HA0xn7Xypc1ytLlKQ5omA=|c3ad8634dc75dc4c56975e7b6efe941e; expires=Mon, 20-Mar-2017 06:54:00 GMT; Max-Age=3600; path=/payment
Set-Cookie: lang=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Strict-Transport-Security: max-age=604800
ece..<!doctype html>.<html lang="en">.<head>.    <
;title>File: Done.exe | Alfafile.net</title>.. <link hr
ef='hXXp://fonts.googleapis.com/css?family=Open Sans:400,600,700&s
ubset=cyrillic,cyrillic-ext,latin' rel='stylesheet' type='text/css'>
;. . <link rel="stylesheet" href="/build/css/libs.out-000594a
915.css" type="text/css"/>. <link rel="stylesheet" href="/bui
ld/css/master.out-808199fc1e.css" type="text/css"/>. .. <m
eta charset="utf-8">. <meta name="Keywords" content=""/>.
<meta name="Description" content=""/>.. <!--<base hr
ef="hXXp://alfafile.net/" />-->.</head>..<body >.<
;div id="all">. . <!-- Header -->. <div id="h
eader">. <div id="header_inner">. <div c
lass="wrapper">. <a href="/" id="logo" title="Alf
afile.net"></a>. . . <ul id="main
_nav">. . <li><a href="/affiliat
e" id="a_menu_top_10">Affiliate program</a></li>.
. <li><a href="/news" id="a_menu_top_2"&
gt;News</a></li>. . <li>&l
t;a href="/faq" id="a_menu_top_4">FAQ</a></li>.
. <li><a href="/about_us" id="a_menu_top_1
">About us</a></li>. . <li
><a href="/support" id="a_menu_top_6">Support</a>&l

<<< skipped >>>

GET /ocsp/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBTy4Gr5hYodjXCbSRkjeqm1Gih+ZAQUSt0GFhu89mi1dvWBtrtiGrpagS8CCGZimYWX7CS+ HTTP/1.1
Cache-Control: max-age = 345600
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: clients1.google.com


HTTP/1.1 200 OK
Content-Type: application/ocsp-response
Date: Sun, 19 Mar 2017 05:40:59 GMT
Expires: Thu, 23 Mar 2017 05:40:59 GMT
Server: ocsp_responder
Content-Length: 463
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Cache-Control: public, max-age=345600
Age: 87204
0..........0..... .....0......0...0......J......h.v....b..Z./..2017031
8190230Z0k0i0A0... ..........j.....p.I.#z...(~d..J......h.v....b..Z./.
.fb....$.....20170318190230Z....20170325190230Z0...*.H................
L.....V..I..aE........cX............M.uKG...D.3.......]y....2.R....|.f
...XB.k.[...=v;..........j.......|%i......y.o..w....../.h...UW.^...(..
..\.......C;4/.....=...s....H..].7.k.&\a...|.......n.).... "3..,...0..
b.9...?.ek.........4......\Px...N...S!..c.WHTTP/1.1 200 OK..Content-Ty
pe: application/ocsp-response..Date: Sun, 19 Mar 2017 05:40:59 GMT..Ex
pires: Thu, 23 Mar 2017 05:40:59 GMT..Server: ocsp_responder..Content-
Length: 463..X-XSS-Protection: 1; mode=block..X-Frame-Options: SAMEORI
GIN..Cache-Control: public, max-age=345600..Age: 87204..0..........0..
... .....0......0...0......J......h.v....b..Z./..20170318190230Z0k0i0A
0... ..........j.....p.I.#z...(~d..J......h.v....b..Z./..fb....$.....2
0170318190230Z....20170325190230Z0...*.H................L.....V..I..aE
........cX............M.uKG...D.3.......]y....2.R....|.f...XB.k.[...=v
;..........j.......|%i......y.o..w....../.h...UW.^...(....\.......C;4/
.....=...s....H..].7.k.&\a...|.......n.).... "3..,...0..b.9...?.ek....
.....4......\Px...N...S!..c.W..


GET /UTN-DATACorpSGC.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 19 Nov 2013 13:17:06 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.comodoca.com


HTTP/1.1 200 OK
Date: Mon, 20 Mar 2017 05:54:28 GMT
Content-Type: application/x-pkcs7-crl
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d122cf42cd865fa7b1b40dc7af2e7f93e1489989268; expires=Tue, 20-Mar-18 05:54:28 GMT; path=/; domain=.comodoca.com; HttpOnly
Last-Modified: Sun, 19 Mar 2017 07:00:40 GMT
ETag: W/"58ce2c98-22d"
X-CCACDN-Mirror-ID: rmdccacrl7
Cache-Control: public, max-age=14400
CF-Cache-Status: HIT
Expires: Mon, 20 Mar 2017 09:54:28 GMT
Server: cloudflare-nginx
CF-RAY: 34266ac3213e63f1-FRA
239..0..50......0...*.H........0..1.0...U....US1.0...U....UT1.0...U...
.Salt Lake City1.0...U....The USERTRUST Network1!0...U....hXXp://VVV.u
sertrust.com1.0...U....UTN - DATACorp SGC..170319070040Z..170323070040
Z0#0!....^{.j.......^....161004055749Z.00.0...U.#..0...S2........].N..
.E..O0...U........0...*.H.............*S>.S.d...6..zBn.(.!z.B......
..>.F.D.Kz...t.!B....TL2....y..]w.y..W..t`...n....O....$.N'....H Q
...Y^....v..._,.gP.H....q.l..f.p_..q..>.~YE..A..c.'....j.y...9.z{Cp
6..K..J......W3.[^.2..`-p.........^~l.L3C%R....!c.D..3<.Dg$..2(t.e.
.**Y{R.?b.&29.n 3..X.M......0..HTTP/1.1 200 OK..Date: Mon, 20 Mar 2017
05:54:28 GMT..Content-Type: application/x-pkcs7-crl..Transfer-Encodin
g: chunked..Connection: keep-alive..Set-Cookie: __cfduid=d122cf42cd865
fa7b1b40dc7af2e7f93e1489989268; expires=Tue, 20-Mar-18 05:54:28 GMT; p
ath=/; domain=.comodoca.com; HttpOnly..Last-Modified: Sun, 19 Mar 2017
07:00:40 GMT..ETag: W/"58ce2c98-22d"..X-CCACDN-Mirror-ID: rmdccacrl7.
.Cache-Control: public, max-age=14400..CF-Cache-Status: HIT..Expires:
Mon, 20 Mar 2017 09:54:28 GMT..Server: cloudflare-nginx..CF-RAY: 34266
ac3213e63f1-FRA..239..0..50......0...*.H......

<<< skipped >>>

GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 29 Oct 2013 05:02:50 GMT
If-None-Match: "b8b5df1d64d4ce1:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.microsoft.com


HTTP/1.1 200 OK
Content-Type: application/pkix-crl
Last-Modified: Sun, 26 Feb 2017 06:01:29 GMT
Accept-Ranges: bytes
ETag: "3cb9d3c5f58fd21:0"
Server: Microsoft-IIS/8.5
VTag: 279861857000000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Content-Length: 554
Cache-Control: max-age=900
Date: Mon, 20 Mar 2017 05:54:12 GMT
Connection: keep-alive
0..&0......0...*.H........0y1.0...U....US1.0...U....Washington1.0...U.
...Redmond1.0...U....Microsoft Corporation1#0!..U....Microsoft Code Si
gning PCA..170225173331Z..170527055331Z.a0_0...U.#..0..........X..7.3.
..L...0... .....7.........0...U......c0... .....7......170526174331Z0.
..*.H.............K..q1;...H..q......7...&m]..2..t.,.5...ln...z[.=Z..G
K,2.T..JS}.3./..z...d.....<..j,.......Ww_!...............y...l3.w..
............'8.........~..D|.qC.o.........a~Td......j.......m....(dFl.
3d.;{..[..(o....3....:bn..1[..O...-?^.....a.m=.Y-O..:...-^i.'X0_.*.HTT
P/1.1 200 OK..Content-Type: application/pkix-crl..Last-Modified: Sun,
26 Feb 2017 06:01:29 GMT..Accept-Ranges: bytes..ETag: "3cb9d3c5f58fd21
:0"..Server: Microsoft-IIS/8.5..VTag: 279861857000000000..P3P: CP="ALL
IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT
COM INT NAV ONL PHY PRE PUR UNI"..X-Powered-By: ASP.NET..Content-Leng
th: 554..Cache-Control: max-age=900..Date: Mon, 20 Mar 2017 05:54:12 G
MT..Connection: keep-alive..0..&0......0...*.H........0y1.0...U....US1
.0...U....Washington1.0...U....Redmond1.0...U....Microsoft Corporation
1#0!..U....Microsoft Code Signing PCA..170225173331Z..170527055331Z.a0
_0...U.#..0..........X..7.3...L...0... .....7.........0...U......c0...
.....7......170526174331Z0...*.H.............K..q1;...H..q......7...&
m]..2..t.,.5...ln...z[.=Z..GK,2.T..JS}.3./..z...d.....<..j,.......W
w_!...............y...l3.w..............'8.........~..D|.qC.o.........
a~Td......j.......m....(dFl.3d.;{..[..(o....3....:bn..1[..O...-?^.

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX+JrHYM= HTTP/1.1
Cache-Control: max-age = 517590
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 06:25:50 GMT
If-None-Match: "57ff28ee-1d7"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: public, max-age=172800
Content-Type: application/ocsp-response
Date: Mon, 20 Mar 2017 05:53:37 GMT
Etag: "58cf1d2e-1d7"
Expires: Sun, 26 Mar 2017 17:53:37 GMT
Last-Modified: Mon, 20 Mar 2017 00:07:10 GMT
Server: ECS (vie/F3C2)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2017
0319220000Z0s0q0I0... ............(..A...B..G@B.X....>.i...G...&...
.cd ....y.D.... .a_.k......20170319220000Z....20170326220000Z0...*.H..
............)..I.rI&..e....O.a..0....R..g8.kkW.&....@.w.@H5..0=...k..w
...-..G.4...... X>..n.5.K..q.l..I. ..Q.W\.......#,....l...whBSS....
.t....Ij.&.I;9....4....sx7.=.n..?E.....q?.....S...E9QI.\Q...-.d{_..w;.
....Su..c....iX%......0Z..z..n:5..J..~~h!.F.J...t...e>.30z.KHTTP/1.
1 200 OK..Accept-Ranges: bytes..Cache-Control: public, max-age=172800.
.Content-Type: application/ocsp-response..Date: Mon, 20 Mar 2017 05:53
:37 GMT..Etag: "58cf1d2e-1d7"..Expires: Sun, 26 Mar 2017 17:53:37 GMT.
.Last-Modified: Mon, 20 Mar 2017 00:07:10 GMT..Server: ECS (vie/F3C2).
.X-Cache: HIT..Content-Length: 471..0..........0..... .....0......0...
0.......>.i...G...&....cd ...20170319220000Z0s0q0I0... ............
(..A...B..G@B.X....>.i...G...&....cd ....y.D.... .a_.k......2017031
9220000Z....20170326220000Z0...*.H..............)..I.rI&..e....O.a..0.
...R..g8.kkW.&....@.w.@H5..0=...k..w...-..G.4...... X>..n.5.K..q.l.
.I. ..Q.W\.......#,....l...whBSS.....t....Ij.&.I;9....4....sx7.=.n..?E
.....q?.....S...E9QI.\Q...-.d{_..w;.....Su..c....iX%......0Z..z..n:5..
J..~~h!.F.J...t...e>.30z.K
....

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8= HTTP/1.1

Cache-Control: max-age = 511667
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 04:57:34 GMT
If-None-Match: "57ff143e-1d7"
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: public, max-age=172800
Content-Type: application/ocsp-response
Date: Mon, 20 Mar 2017 05:53:43 GMT
Etag: "58cf0511-1d7"
Expires: Sun, 26 Mar 2017 17:53:43 GMT
Last-Modified: Sun, 19 Mar 2017 22:24:17 GMT
Server: ECS (vie/F2D5)
X-Cache: HIT
Content-Length: 471
0..........0..... .....0......0...0.......>.i...G...&....cd ...2017
0318220000Z0s0q0I0... ............(..A...B..G@B.X....>.i...G...&...
.cd ........\..m. B.]......20170318220000Z....20170325220000Z0...*.H..
........... .[..... .F..8..x.....U.M..#..da....|... b.y.&E.|KQ..e..C0.
.B@.}a....>...0.....R.X<......7....} .......:j....X. ..K2.....|.
....= .....%H..v...tG.B..S.:......{P[.\G..?...h.q.;..........XA.)... .
...Z.T8...y.M.C..#.i.21.......@..o.....4C"...._...s...._....H..HTTP/1.
1 200 OK..Accept-Ranges: bytes..Cache-Control: public, max-age=172800.
.Content-Type: application/ocsp-response..Date: Mon, 20 Mar 2017 05:53
:43 GMT..Etag: "58cf0511-1d7"..Expires: Sun, 26 Mar 2017 17:53:43 GMT.
.Last-Modified: Sun, 19 Mar 2017 22:24:17 GMT..Server: ECS (vie/F2D5).
.X-Cache: HIT..Content-Length: 471..0..........0..... .....0......0...
0.......>.i...G...&....cd ...20170318220000Z0s0q0I0... ............
(..A...B..G@B.X....>.i...G...&....cd ........\..m. B.]......2017031
8220000Z....20170325220000Z0...*.H............. .[..... .F..8..x.....U
.M..#..da....|... b.y.&E.|KQ..e..C0..B@.}a....>...0.....R.X<....
..7....} .......:j....X. ..K2.....|.....= .....%H..v...tG.B..S.:......
{P[.\G..?...h.q.;..........XA.)... ....Z.T8...y.M.C..#.i.21.......@..o
.....4C"...._...s...._....H..
....

<<< skipped >>>

GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY+sl+j4yzQuAcL2oQno5fCgQUUWj/kK8CB3U8zNllZGKiErhZcjsCEA9N5D4ZnViCc5eMbrXeuZM= HTTP/1.1

Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.digicert.com


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: public, max-age=172800
Content-Type: application/ocsp-response
Date: Mon, 20 Mar 2017 05:53:48 GMT
Etag: "58cf3a18-3e0"
Expires: Sun, 26 Mar 2017 17:53:48 GMT
Last-Modified: Mon, 20 Mar 2017 02:10:32 GMT
Server: ECS (vie/F3A7)
X-Cache: HIT
Content-Length: 992
0..........0..... .....0......0...0.......Qh.....u<..edb...Yr;..201
70320014200Z0..y0..u0I0... .........&....~...B../j..._...Qh.....u<.
.edb...Yr;...M.>..X.s..n........20170320014200Z....20170327005700Z.
...0...0..... .....y..............w.......X......gp.<5.......w.....
....Z.........H0F.!..6...|.....g...,..S:.a...o...[...!..V.R..kM.l...R.
?...........(..]M.v.V.../.......D.>.Fv....\....U.......Z.........G0
E.!....i...5.H..A6.;.......3......Pn. ^...>=..MU...[.p.H..{..?.....
.J-.w..K..u.`..Bi....f..~_.r....{.z......Z.........H0F.!...F.h.b......
.....>"1....Tj._d...!..;3Z.......H.........X.u.!...n...v.......q...
#...{G8W...R....d6.......Z.........G0E. ?..A.W....q*;S.w....5..(..8.A.
...!.......G....;*......Y9^_..L....k_0...*.H...............5..h.=...:.
M...n.sk.g....|..5..0P.j.....Z.J....#..P...N-..Bo:.....wq/j.=s.&...m.l
......0.br.N..I.mS...w...x.dc...c..Im.7...1'V.U........H..=..ke....<
;.?..........y......\."..ll......-....[....x...u(.......... X.M.L].^..
.&A.....Q.....|...8..h...`.#.......!HTTP/1.1 200 OK..Accept-Ranges: by
tes..Cache-Control: public, max-age=172800..Content-Type: application/
ocsp-response..Date: Mon, 20 Mar 2017 05:53:48 GMT..Etag: "58cf3a18-3e
0"..Expires: Sun, 26 Mar 2017 17:53:48 GMT..Last-Modified: Mon, 20 Mar
2017 02:10:32 GMT..Server: ECS (vie/F3A7)..X-Cache: HIT..Content-Leng
th: 992..0..........0..... .....0......0...0.......Qh.....u<..edb..
.Yr;..20170320014200Z0..y0..u0I0... .........&....~...B../j..._...Qh..
...u<..edb...Yr;...M.>..X.s..n........20170320014200Z....201

<<< skipped >>>

GET /MFUwUzBRME8wTTAJBgUrDgMCGgUABBTkLVLomfJQOu5CFIgPOR73ljBRHAQU+L36r3N3xscb+UtNEafRM6+vchECFEOZrYpYgDwxeWGj/HetMtWiXvU/ HTTP/1.1
Cache-Control: max-age = 339923
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 13 Oct 2016 09:41:21 GMT
If-None-Match: "c06e9a4e33eec9dd813b8faff15397229f914d2a"
User-Agent: Microsoft-CryptoAPI/6.1
Host: vassg142.ocsp.omniroot.com


HTTP/1.1 200 OK
Server: nginx
Content-Type: application/ocsp-response
Content-Length: 1746
Last-Modified: Mon, 20 Mar 2017 05:00:09 GMT
ETag: "b1ee29266a92b3238f91ec4517ce6861a6a06858"
Cache-Control: public, no-transform, must-revalidate, max-age=337178
Expires: Fri, 24 Mar 2017 03:33:56 GMT
Date: Mon, 20 Mar 2017 05:54:18 GMT
Connection: keep-alive
0..........0..... .....0......0...0.......d._t.a...(..fx..r....2017032
0050009Z0w0u0M0... .........-R...P:.B...9...0Q.......sw....KM...3..r..
.C...X.<1ya..w.2..^.?....20170320050009Z....20170324050009Z0...*.H.
.............r..a.....,....#6..8.f..?t...n[1.{.E4...i.....v@...m......
;4"......pgO...t..v.[...M..k~.Co?g.......g..#d...f<.UL..0...`. ....
W...H2...s.,v......D).G%.....U........uJ!\...OO6"1.^@..m..z.e..6.(.0A.
.....F...p>&.T.....v.:.D%......46.b.[.s......;....1........QB....0.
..0...0..........&.L..J..T...vP..yV..0...*.H........0..1.0...U....NL1.
0...U....Amsterdam1%0#..U....Verizon Enterprise Solutions1.0...U....Cy
bertrust1.0,..U...%Verizon Akamai SureServer CA G14-SHA20...1703102136
26Z..180309213625Z0..1.0...U....NL1.0...U....Amsterdam1%0#..U....Veriz
on Enterprise Solutions1.0...U....Cybertrust1%0#..U....vassg142 OCSP R
esponder 20170.."0...*.H.............0..........\..K.......:..K&!...!`
D#'2~mL...<..E`.:Y.I..w.....P..)..o..><^-7.h.zL......3.."....
T...-s.g........zUY5q....u...D........(....C.XmF=.r...8h....I.....[...
P. ...;..c...0.'x..F..h...&<Q.vO.b2.pm.y..J.P"...H....A....T.......
_.dc.F-..W....Z...).=.Y..n2...N..E........H0..D0... .....0......0L..U.
.E0C0A.. .....>..0402.. ........&hXXps://secure.omniroot.com/repos
itory0~.. ........r0p06.. .....0..*hXXps://cacert.a.omniroot.com/vassg
142.crt06.. .....0..*hXXps://cacert.a.omniroot.com/vassg142.der0...U..
.........0...U.%..0... .......0...U.#..0.......sw....KM...3..r.0...U..
.....d._t.a...(..fx..r..0...*.H..................6..dez....$...^I.

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

cpa.exe_3568:

.text
`.rdata
@.data
.rsrc
@.reloc
diu2.iu
Advapi32.dll
lua5.1.dll
irsetup.exe
Could not determine a temp directory name. Try running setup.exe /T:<Path>
c:\temp
%s\irsetup.exe
%s%s_%d
"__IRSID:%s"
"__IRCT:%d"
"__IRAFN:%s"
GetProcessWindowStation
operator
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
ADVAPI32.dll
ShellExecuteExA
SHELL32.dll
GetCPInfo
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpa.exe
%xERRj3cqZQ
! !!####0
;;;9551%%0
! !!565665@
version="9.5.0.0"
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
<!-- Windows Vista Support -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 Support -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 Support -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 Support -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 Support -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
7%7S7v7|7
mscoree.dll
KERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
9.5.0.0
suf_launch.exe

irsetup.exe_1480:

`.rsrc
t%SSSS
SSSSh
t%SWV
u)SSh
u)SShd
TSShX
@ SSh
u%SSSV
SSShT
SSSh`
9^$u&SSSSh?
9^$u SSSSh?
9^$u)SSSSh?
|SShF
t2SSh
Ht.Ht S
FLSSh
GLSSh
GXSSh
FpSSh
FtSSh
G`SSh
.WWWW
Nt.Nt
t'SShl
u$SShe
@ SSHPWj
tFHt:Ht.Ht"Hu`
tWSShW
tl9_ tgSSh
tAHt.HHt
j%XtL9E
<SShG
FtPW
SSh@B
FTCP
u.Ph,
.FG;}
FTPQ
FTPh
V SShW
O SSh
O SSh,
diu2.iu
kernel32.dll
%s (%s:%d)
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin1.inl
MSG_ERROR
%s %d. %s
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM
A%s%s%s.%d
%s.%d
%s, Line %d: %s
File condition evaluation for file "%s"
msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
C:\temp\SUF_SFX_TEST\
MSG_INITIALIZING
16670749
_IgnoreInvalidCertificate
SetEntriesInAcl Error %u
SetNamedSecurityInfo Error %u
*.gif
*.tif
*.tga
*.png
*.pcx
*.jpg
*.bmp
[%d]: %s
*** LOCATION: %s
__NOREPORT__
in function <%s:%d>
in function '%s'
Line: %d
%d: [%s]
Script: %s, %s (%s)
__ir_eval_value = %s;
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
MainWindowSettings
%s at offset %d unterminated
Incorrect %s at offset %d
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_CANCEL
MSG_OK
MSG_BROWSE
MSG_PATH
Windows Server 10
Windows 10
Windows Server 2012 R2
Windows 8.1
Windows Server 2012
Windows 8
Windows Server 2008 R2
Windows 7
Windows Server 2008
Windows Vista
Windows Server 2003
Windows XP
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
%TempFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartFolder%
%StartProgramsFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SystemDrive%
_WindowsFolder
%WindowsFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%FontsFolder%
ÞsktopFolderCommon%
;?;?.lua
UninstallSupportFiles
CPRegKey
Run extra uninstall script: %d
Original: %d
Calculated: %d
Unable to open archive file: %d
lua5.1.dll
%SourceDrive%
%SourceFilename%
\irsetup.dat
{D387204B-8FB9-6A21-15FA-0CD14BF40EA9}
Support file added to uninstall list:
Registry key added to uninstall list:
Removed! %d
IDispatch error #%d
Error 0xx: %s
Register font: %s, %s
%sbk%d
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
Remove uninstall support file:
MSG_NO
MSG_YES_TOALL
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib failure reason: %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM failure reason: %s
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s (New count = %d)
%s\%s
%s (%d)
\irsetup.skin
local e_Stage = %d;local e_CurrentItemText=[==[%s]==];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_SYSREQ_ABORT
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
%s: %d
MSG_SYSREQ_SCREENWIDTH
%s: %d %s
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
Operating System
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_WSRV10
MSG_OS_W10
MSG_OS_WSRV2012_R2
MSG_OS_W8_1
MSG_OS_WSRV2012
MSG_OS_W8
MSG_OS_WSRV2008_R2
MSG_OS_W7
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
%s %d %s
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
%s %I64d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s (Return code: %d)
Product: %s, version %s
MSG_SEEKING
%s (%d):
Arc: %s
FN: %s
%s (#%d)
MSG_SKIPPING
MSG_INSTALLING
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Existing uninstall executable is newer. Will not overwrite.
Compared uninstall file versions. New: %s Old: %s Result: %d
Uninstall executable already exists: %s
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
"%s" "/U:%s"
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
Dependency Detection Passed
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
[%s] %s
%m/%d/%Y %H:%M:%S
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_500
ERR_WEB_404
ERR_WEB_403
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyName%
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%TempFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%AppFolder%\uninstall.exe
uninstall.xml
CWebBrowser2
Confirm Operation
KERNEL32.DLL
PSAPI.DLL
Kernel32.dll
WS2_32.DLL
Copying "%s"
"%s" %s
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
Sfc.dll
.bak%d
Windows ME
Windows 98
Windows 95
Windows 2000
Windows NT 4
Windows NT 3
%s\shell\open\command
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.pif
srclient.dll
%s_%d
%s\_ir_tmpfnt_%d
/\:*?"<>|
%%x
d:d
WinINet.dll
Could not create Internet session: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
PTF://
hXXps://
hXXp://
%s; DIRECT
jsproxy.dll
DetectAutoProxyUrl
wininet.dll
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG: %d
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, Line %d
All Files (*.*)|*.*|
PasswordInput
MSG_MOVING
MSG_COPYING
MSG_FROM
MSG_TO
MSG_DELETING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
ErrorMsg
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
\msiexec.exe
RunMsiexec
SQLInstallerError
SQLRemoveDriverManager
odbccp32.dll
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverManager
SQLRemoveDriver
\Kernel32.dll
GetKeyNames
DoesKeyExist
DeleteKey
CreateKey
ShortcutKey
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
xxxxxx
%s-%s-%s
%s/%s/%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s PM
MSG_REBOOT_FAILED
WININET.DLL
PPassword
Password
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_DOWNLOADING
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_READING
GetHTTPErrorInfo
%s > %s
number e_CtrlID, number e_MsgID, table e_Details
Removed: %s
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Check%d
ComboBox%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Application.Exit();
Screen.Next();
Screen.Back();
Radio%d
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_BILLBOARD_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_BILLBOARD_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
hXXp://VVV.indigorose.com/route.php?pid=suf9buy
r@.psd
.tiff
.jpeg
.wbmp
CNotSupportedException
user32.dll
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
CCmdTarget
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
comctl32.dll
comdlg32.dll
shell32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
%s%s.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
RegOpenKeyTransactedA
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
CHttpConnection
CHttpFile
HTTP/1.0
msctls_hotkey32
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
mfcm100.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
Shell32.dll
%s:%x:%x:%x:%x
RegDeleteKeyExA
lXXxXXXXXXXX
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
MFCLink_UrlPrefix
MFCLink_Url
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
&%d %s
Hex={X,X,X}
ShowCmd
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
%sPane-%d%x
%sPane-%d
%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
%c%d%c%s
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
windows
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
CMFCToolBarsKeyboardPropertyPage
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
operator
GetProcessWindowStation
IS 5.0.2.4
Error %d in %s (%s)
Error %d in %s (%s) [%s]
C.o.p.y.r.i.g.h.t...2.0.1.0.
ISLib PNG Error : %s
1.2.22
ISLib JPG Error : %s
DIBToHBITMAP error: GetLastError = %d
read %d. layersLen %d
Reading PCD sub-image #%d (%d x %d)
.cals
Keywords
SetWinMetaFileBits failed GetLastError = %d
GeoKeyDirectory
%s: Invalid InkNames value; expecting %d names, found %d
%s: Bad value %u for "%s" tag
%s: Invalid %stag "%s" (not supported by codec)
%s: Bad field type %d for "%s"
%s: Failed to allocate space for list of custom values
%s: Bad value %d for "%s" tag
%s: Sorry, cannot nest SubIFDs
Nonstandard tile width %d, convert file
Nonstandard tile length %d, convert file
%s: Cannot modify tag "%s" while writing
%s: Unknown %stag %u
%s: Error fetching directory link
%s: Error fetching directory count
Sorry, can not handle images with %d-bit samples
Sorry, LogL data must have %s=%d
Sorry, can not handle LogLuv images with %s=%d
Sorry, LogLuv data must have %s=%d or %d
Sorry, can not handle image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d and Bits/Sample=%d
Sorry, can not handle RGB image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d
Sorry, can not handle separated image with %s=%d
Missing needed %s tag
No space %s
%s: Read error at scanline %lu, strip %lu; got %lu bytes, expected %lu
%s: Read error at scanline %lu; got %lu bytes, expected %lu
%s: Seek error at scanline %lu, strip %lu
%s: Read error at row %ld, col %ld, tile %ld; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld; got %lu bytes, expected %lu
%s: Seek error at row %ld, col %ld, tile %ld
%s: No space for data buffer at scanline %ld
%s: Data buffer too small to hold strip %lu
%s: Read error on strip %lu; got %lu bytes, expected %lu
%s: Invalid strip byte count %lu, strip %lu
%s: Data buffer too small to hold tile %ld
"%s": Bad mode
Not a TIFF file, bad version number %d (0x%x)
This is a BigTIFF file. This format not supported
Not a TIFF or MDI file, bad magic number %d (0x%x)
%s: Out of memory (TIFF structure)
Error writing data for field "%s"
%s: Error writing SubIFD directory link
M"%s": Information lost writing value (%g) as (unsigned) RATIONAL
Integer overflow in %s
LIBTIFF, Version 3.9.1
0123456789ABCDEFlibpng error: %s
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning: %s
libpng warning no. %s: %s
1.2.3
NULL row buffer for row %ld, pass %d
iTXt chunk not supported.
Corrupt JPEG data: found marker 0xx instead of RST%d
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
RST%d
At marker 0xx, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Unsupported marker type 0xx
Failed to create temporary file %s
Unsupported JPEG process: SOF type 0xx
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Huffman table 0xx was not defined
Backing store not supported
Cannot transcode due to multiple use of quantization table %d
Maximum supported image dimension is %u pixels
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
Buffer passed to JPEG library is too small
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Wrong JPEG library version: library is %d, caller expects %d
IDCT output block size %d not supported
Invalid component ID %d in SOS
Bogus message code %d
Found bad IPTC data resource (len exceeds block end). ID=%d
ExifInteroperabilityOffset
InteroperabilityVersion
InteroperabilityIndex
AsShotPreProfileMatrix
AsShotICCProfile
AsShotWhiteXY
AsShotNeutral
InteroperabilityIFDOffset
Internal error, unknown tag 0x%x
Tag %d
Compression algorithm does not support random access
Compression scheme %u %s encoding is not implemented
%s %s encoding is not implemented
Compression scheme %u %s decoding is not implemented
%s %s decoding is not implemented
%s: Cannot determine size of unknown tag type %d
%s: TIFF directory is missing required "%s" field
incorrect count for field "%s" (%u, expecting %u); tag trimmed
incorrect count for field "%s" (%u, expecting %u); tag ignored
%s: Can not read TIFF directory
%s: Can not read TIFF directory count
%s: Seek error accessing TIFF directory
Error fetching data for field "%s"
%s: Rational with zero denominator (num = %u)
unexpected count for field "%s", %u, expected 2; ignored
cannot read TIFF_ANY type %d for field "%s"
Cannot handle different per-sample values for field "%s"
%s: cannot handle zero strip size
%s: cannot handle zero tile size
%s: cannot handle zero scanline size
%s: Wrong "%s" field, ignoring and calculating from imagelength
%s: Bogus "%s" field, ignoring and calculating from imagelength
%s: TIFF directory is missing required "%s" field, calculating from imagelength
%s: cannot handle zero number of %s
%s: wrong data type %d for "%s"; tag ignored
Registering anonymous field with tag %d (0x%x) failed
%s: unknown field with tag %d (0x%x) encountered
%s: invalid TIFF directory; tags are not sorted in ascending order
%s: Failed to read directory at offset %u
Unknown zTXt compression type %d
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
deflate 1.2.3 Copyright 1995-2003 Jean-loup Gailly
%ld%c
%s compression support is not configured
inflate 1.2.3 Copyright 1995-2005 Mark Adler
LogL16Decode: Not enough data at row %d (short %d pixels)
LogLuvDecode24: Not enough data at row %d (short %d pixels)
LogLuvDecode32: Not enough data at row %d (short %d pixels)
?%s: No space for SGILog translation buffer
No support for converting user data format to LogL
No support for converting user data format to LogLuv
Inappropriate photometric interpretation %d for SGILog compression; %s
SGILog compression supported only for %s, or raw data
Unknown data format %d for LogLuv compression
Unknown encoding %d for LogLuv compression
%s: No space for LogLuv state block
?PixarLog compression can't handle bits depth/data format combination (depth: %d)
%d bit input not supported in PixarLog
PixarLogDecode: unsupported bits/sample: %d
%s: stride %d is not a multiple of sample count, %d, data truncated.
%s: zlib error: %s
%s: Not enough data at scanline %d (short %d bytes)
%s: Decoding error at scanline %d, %s
PixarLog compression can't handle %d bit linear encodings
A%s: Encoder error: %s
%s: Bad code word at line %u of %s %u (x %u)
%s: Uncompressed data (not supported) at line %u of %s %u (x %u)
%s: %s at line %u of %s %u (got %u, expected %u)
%s: Premature EOF at line %u of %s %u (x %u)
%s: No space for Group 3/4 reference line
@ Fax DCS: %s
Fax SubAddress: %s
(%u = 0x%x)
%sEOL padding
%s2-d encoding
%suncompressed data
%s: No space for state block
JpegRestartInterval: %u
JpegProc: %u
OJPEG encoding not supported; use new-style JPEG compression instead
Unknown marker type %d in JPEG data
Subsampling values [%d,%d] are not allowed in TIFF
Subsampling inside JPEG data does not match subsampling tag values [%d,%d] (nor any other values allowed in TIFF); assuming subsampling inside JPEG data is correct and desubsampling inside JPEG decompression
Subsampling inside JPEG data [%d,%d] does not match subsampling tag values [%d,%d]; assuming subsampling inside JPEG data is correct
Subsampling tag is not set, yet subsampling inside JPEG data [%d,%d] does not match default values [2,2]; assuming subsampling inside JPEG data is correct
SamplesPerPixel %d not supported for this compression scheme
JPEG strip/tile size exceeds expected dimensions, expected %dx%d, got %dx%d
Decompressor will try reading with sampling %d,%d.
Improper JPEG sampling factors %d,%d
Apparently should be %d,%d.
Improper JPEG strip/tile size, expected %dx%d, got %dx%d
RowsPerStrip must be multiple of %d for JPEG
JPEG tile width must be multiple of %d
JPEG tile height must be multiple of %d
BitsPerSample %d not allowed for JPEG
PhotometricInterpretation %d not allowed for JPEG
ThunderDecode: %s data at scanline %ld (%lu != %lu)
LZWDecode: Bogus encoding, loop in the code table; scanline %d
LZWDecode: Not enough data at scanline %d (short %ld bytes)
LZWDecode: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecode: Corrupted LZW table at scanline %d
LZWDecode: Strip %d not terminated with EOI code
LZWDecodeCompat: Corrupted LZW table at scanline %d
LZWDecodeCompat: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecodeCompat: Not enough data at scanline %d (short %ld bytes)
DumpModeDecode: Not enough data for scanline %d
Horizontal differencing "Predictor" not supported with %d-bit samples
Floating point "Predictor" not supported with %d data format
"Predictor" value %d not supported
Out of memory allocating %d byte temp buffer.
%u (0x%x)
WindowsForms
NTDLL.DLL
COMCTL32.DLL
USER32.DLL
MSCTF.DLL
GDI32.DLL
SHLWAPI.DLL
UXTHEME.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
LEFTPRESSED
ALWAYSSHOWSIZINGBAR
MSGBOXFONT
%[^,], %ld, %s
User32.dll
msimg32.dll
windows-1254
windows-874
SUBLANG_PORTUGUESE_BRAZILIAN
Portuguese (Brazil)
SUBLANG_PORTUGUESE
LANG_PORTUGUESE
Portuguese (Portugal)
windows-1255
windows-1257
windows-1253
windows-1252
windows-1250
windows-1256
windows-1251
1.2.40
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
WININET.dll
?#%X.y
InternetCrackUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCISImageEx@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDVCRect@@AAV3@@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.PAVCThreadException@IR@@
.PAVCObject@@
.PAVCOleException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCArchiveException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDV12@PBD@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.PAVCOleDispatchException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCObList@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDHH@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe
GetProcessHeap
GetCPInfo
GetWindowsDirectoryA
RegCloseKey
RegOpenKeyExA
RegCreateKeyExA
RegEnumKeyA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteKeyA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GetViewportExtEx
GdiplusShutdown
ShellExecuteExA
ShellExecuteA
UrlUnescapeA
URLDownloadToFileA
MapVirtualKeyExA
GetKeyboardState
GetKeyboardLayout
MapVirtualKeyA
GetKeyNameTextA
SetWindowsHookExA
UnhookWindowsHookEx
CreateDialogIndirectParamA
GetKeyState
ExitWindowsEx
EnumWindows
MsgWaitForMultipleObjects
GetAsyncKeyState
|5#" " " 
# # #""%"$
^)1-"*"<.
2;%SK
%.Fh3>$]R
]<%XZ
WEBI
]>2?>2/"
H%FZW
|@@@@8>-
\ ,%X
[9<;.MK31?MM&
!3-%#;3&1
##0#3131%& 
.QICN,1#-#5<## @I3>##Jl;>C3I=I6lIC6&-4-350T-3]
$&%f#F>#
:0@033*00
$,0($,$4
(,,4,4,$
0488<<<( 0
.text
`.rdata
@.data
.rsrc
@.reloc
%xERRj3cqZQ
! !!####0
;;;9551%%0
! !!565665@
version="9.5.0.0"
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
<!-- Windows Vista Support -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 Support -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 Support -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 Support -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 Support -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
gdiplus.dll
imagehlp.dll
IMM32.dll
MSIMG32.dll
NETAPI32.dll
OLEACC.dll
OLEAUT32.dll
oledlg.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
VERSION.dll
WINMM.dll
WINSPOOL.DRV
accKeyboardShortcut
hhctrl.ocx
dwmapi.dll
xUxTheme.dll
yDWrite.dll
D2D1.dll
SHELL32.DLL
RICHED20.DLL
mscoree.dll
ekernel32.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
aero.msstyles
winxp.royale.cjstyles
royale.msstyles
winxp.luna.cjstyles
luna.msstyles
Argument %d must be of type %s.
%d arguments required.
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]
9.5.0.0
2015 Indigo Rose Corporation (VVV.indigorose.com)
suf_rt.exe

irsetup.exe_1480_rwx_00B01000_003DD000:

t%SSSS
SSSSh
t%SWV
u)SSh
u)SShd
TSShX
@ SSh
u%SSSV
SSShT
SSSh`
9^$u&SSSSh?
9^$u SSSSh?
9^$u)SSSSh?
|SShF
t2SSh
Ht.Ht S
FLSSh
GLSSh
GXSSh
FpSSh
FtSSh
G`SSh
.WWWW
Nt.Nt
t'SShl
u$SShe
@ SSHPWj
tFHt:Ht.Ht"Hu`
tWSShW
tl9_ tgSSh
tAHt.HHt
j%XtL9E
<SShG
FtPW
SSh@B
FTCP
u.Ph,
.FG;}
FTPQ
FTPh
V SShW
O SSh
O SSh,
diu2.iu
kernel32.dll
%s (%s:%d)
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin1.inl
MSG_ERROR
%s %d. %s
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM
A%s%s%s.%d
%s.%d
%s, Line %d: %s
File condition evaluation for file "%s"
msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
C:\temp\SUF_SFX_TEST\
MSG_INITIALIZING
16670749
_IgnoreInvalidCertificate
SetEntriesInAcl Error %u
SetNamedSecurityInfo Error %u
*.gif
*.tif
*.tga
*.png
*.pcx
*.jpg
*.bmp
[%d]: %s
*** LOCATION: %s
__NOREPORT__
in function <%s:%d>
in function '%s'
Line: %d
%d: [%s]
Script: %s, %s (%s)
__ir_eval_value = %s;
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
MainWindowSettings
%s at offset %d unterminated
Incorrect %s at offset %d
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_CANCEL
MSG_OK
MSG_BROWSE
MSG_PATH
Windows Server 10
Windows 10
Windows Server 2012 R2
Windows 8.1
Windows Server 2012
Windows 8
Windows Server 2008 R2
Windows 7
Windows Server 2008
Windows Vista
Windows Server 2003
Windows XP
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
%TempFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartFolder%
%StartProgramsFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SystemDrive%
_WindowsFolder
%WindowsFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%FontsFolder%
ÞsktopFolderCommon%
;?;?.lua
UninstallSupportFiles
CPRegKey
Run extra uninstall script: %d
Original: %d
Calculated: %d
Unable to open archive file: %d
lua5.1.dll
%SourceDrive%
%SourceFilename%
\irsetup.dat
{D387204B-8FB9-6A21-15FA-0CD14BF40EA9}
Support file added to uninstall list:
Registry key added to uninstall list:
Removed! %d
IDispatch error #%d
Error 0xx: %s
Register font: %s, %s
%sbk%d
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
Remove uninstall support file:
MSG_NO
MSG_YES_TOALL
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib failure reason: %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM failure reason: %s
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s (New count = %d)
%s\%s
%s (%d)
\irsetup.skin
local e_Stage = %d;local e_CurrentItemText=[==[%s]==];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_SYSREQ_ABORT
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
%s: %d
MSG_SYSREQ_SCREENWIDTH
%s: %d %s
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
Operating System
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_WSRV10
MSG_OS_W10
MSG_OS_WSRV2012_R2
MSG_OS_W8_1
MSG_OS_WSRV2012
MSG_OS_W8
MSG_OS_WSRV2008_R2
MSG_OS_W7
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
%s %d %s
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
%s %I64d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s (Return code: %d)
Product: %s, version %s
MSG_SEEKING
%s (%d):
Arc: %s
FN: %s
%s (#%d)
MSG_SKIPPING
MSG_INSTALLING
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Existing uninstall executable is newer. Will not overwrite.
Compared uninstall file versions. New: %s Old: %s Result: %d
Uninstall executable already exists: %s
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
"%s" "/U:%s"
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
Dependency Detection Passed
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
[%s] %s
%m/%d/%Y %H:%M:%S
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_500
ERR_WEB_404
ERR_WEB_403
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyName%
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%TempFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%AppFolder%\uninstall.exe
uninstall.xml
CWebBrowser2
Confirm Operation
KERNEL32.DLL
PSAPI.DLL
Kernel32.dll
WS2_32.DLL
Copying "%s"
"%s" %s
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
Sfc.dll
.bak%d
Windows ME
Windows 98
Windows 95
Windows 2000
Windows NT 4
Windows NT 3
%s\shell\open\command
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.pif
srclient.dll
%s_%d
%s\_ir_tmpfnt_%d
/\:*?"<>|
%%x
d:d
WinINet.dll
Could not create Internet session: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
PTF://
hXXps://
hXXp://
%s; DIRECT
jsproxy.dll
DetectAutoProxyUrl
wininet.dll
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG: %d
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, Line %d
All Files (*.*)|*.*|
PasswordInput
MSG_MOVING
MSG_COPYING
MSG_FROM
MSG_TO
MSG_DELETING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
ErrorMsg
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
\msiexec.exe
RunMsiexec
SQLInstallerError
SQLRemoveDriverManager
odbccp32.dll
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverManager
SQLRemoveDriver
\Kernel32.dll
GetKeyNames
DoesKeyExist
DeleteKey
CreateKey
ShortcutKey
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
xxxxxx
%s-%s-%s
%s/%s/%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s PM
MSG_REBOOT_FAILED
WININET.DLL
PPassword
Password
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_DOWNLOADING
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_READING
GetHTTPErrorInfo
%s > %s
number e_CtrlID, number e_MsgID, table e_Details
Removed: %s
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Check%d
ComboBox%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Application.Exit();
Screen.Next();
Screen.Back();
Radio%d
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_BILLBOARD_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_BILLBOARD_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
hXXp://VVV.indigorose.com/route.php?pid=suf9buy
r@.psd
.tiff
.jpeg
.wbmp
CNotSupportedException
user32.dll
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
CCmdTarget
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
comctl32.dll
comdlg32.dll
shell32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
%s%s.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
RegOpenKeyTransactedA
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
CHttpConnection
CHttpFile
HTTP/1.0
msctls_hotkey32
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
mfcm100.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
Shell32.dll
%s:%x:%x:%x:%x
RegDeleteKeyExA
lXXxXXXXXXXX
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
MFCLink_UrlPrefix
MFCLink_Url
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
&%d %s
Hex={X,X,X}
ShowCmd
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
%sPane-%d%x
%sPane-%d
%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
%c%d%c%s
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
windows
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
CMFCToolBarsKeyboardPropertyPage
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
operator
GetProcessWindowStation
IS 5.0.2.4
Error %d in %s (%s)
Error %d in %s (%s) [%s]
C.o.p.y.r.i.g.h.t...2.0.1.0.
ISLib PNG Error : %s
1.2.22
ISLib JPG Error : %s
DIBToHBITMAP error: GetLastError = %d
read %d. layersLen %d
Reading PCD sub-image #%d (%d x %d)
.cals
Keywords
SetWinMetaFileBits failed GetLastError = %d
GeoKeyDirectory
%s: Invalid InkNames value; expecting %d names, found %d
%s: Bad value %u for "%s" tag
%s: Invalid %stag "%s" (not supported by codec)
%s: Bad field type %d for "%s"
%s: Failed to allocate space for list of custom values
%s: Bad value %d for "%s" tag
%s: Sorry, cannot nest SubIFDs
Nonstandard tile width %d, convert file
Nonstandard tile length %d, convert file
%s: Cannot modify tag "%s" while writing
%s: Unknown %stag %u
%s: Error fetching directory link
%s: Error fetching directory count
Sorry, can not handle images with %d-bit samples
Sorry, LogL data must have %s=%d
Sorry, can not handle LogLuv images with %s=%d
Sorry, LogLuv data must have %s=%d or %d
Sorry, can not handle image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d and Bits/Sample=%d
Sorry, can not handle RGB image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d
Sorry, can not handle separated image with %s=%d
Missing needed %s tag
No space %s
%s: Read error at scanline %lu, strip %lu; got %lu bytes, expected %lu
%s: Read error at scanline %lu; got %lu bytes, expected %lu
%s: Seek error at scanline %lu, strip %lu
%s: Read error at row %ld, col %ld, tile %ld; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld; got %lu bytes, expected %lu
%s: Seek error at row %ld, col %ld, tile %ld
%s: No space for data buffer at scanline %ld
%s: Data buffer too small to hold strip %lu
%s: Read error on strip %lu; got %lu bytes, expected %lu
%s: Invalid strip byte count %lu, strip %lu
%s: Data buffer too small to hold tile %ld
"%s": Bad mode
Not a TIFF file, bad version number %d (0x%x)
This is a BigTIFF file. This format not supported
Not a TIFF or MDI file, bad magic number %d (0x%x)
%s: Out of memory (TIFF structure)
Error writing data for field "%s"
%s: Error writing SubIFD directory link
M"%s": Information lost writing value (%g) as (unsigned) RATIONAL
Integer overflow in %s
LIBTIFF, Version 3.9.1
0123456789ABCDEFlibpng error: %s
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning: %s
libpng warning no. %s: %s
1.2.3
NULL row buffer for row %ld, pass %d
iTXt chunk not supported.
Corrupt JPEG data: found marker 0xx instead of RST%d
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
RST%d
At marker 0xx, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Unsupported marker type 0xx
Failed to create temporary file %s
Unsupported JPEG process: SOF type 0xx
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Huffman table 0xx was not defined
Backing store not supported
Cannot transcode due to multiple use of quantization table %d
Maximum supported image dimension is %u pixels
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
Buffer passed to JPEG library is too small
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Wrong JPEG library version: library is %d, caller expects %d
IDCT output block size %d not supported
Invalid component ID %d in SOS
Bogus message code %d
Found bad IPTC data resource (len exceeds block end). ID=%d
ExifInteroperabilityOffset
InteroperabilityVersion
InteroperabilityIndex
AsShotPreProfileMatrix
AsShotICCProfile
AsShotWhiteXY
AsShotNeutral
InteroperabilityIFDOffset
Internal error, unknown tag 0x%x
Tag %d
Compression algorithm does not support random access
Compression scheme %u %s encoding is not implemented
%s %s encoding is not implemented
Compression scheme %u %s decoding is not implemented
%s %s decoding is not implemented
%s: Cannot determine size of unknown tag type %d
%s: TIFF directory is missing required "%s" field
incorrect count for field "%s" (%u, expecting %u); tag trimmed
incorrect count for field "%s" (%u, expecting %u); tag ignored
%s: Can not read TIFF directory
%s: Can not read TIFF directory count
%s: Seek error accessing TIFF directory
Error fetching data for field "%s"
%s: Rational with zero denominator (num = %u)
unexpected count for field "%s", %u, expected 2; ignored
cannot read TIFF_ANY type %d for field "%s"
Cannot handle different per-sample values for field "%s"
%s: cannot handle zero strip size
%s: cannot handle zero tile size
%s: cannot handle zero scanline size
%s: Wrong "%s" field, ignoring and calculating from imagelength
%s: Bogus "%s" field, ignoring and calculating from imagelength
%s: TIFF directory is missing required "%s" field, calculating from imagelength
%s: cannot handle zero number of %s
%s: wrong data type %d for "%s"; tag ignored
Registering anonymous field with tag %d (0x%x) failed
%s: unknown field with tag %d (0x%x) encountered
%s: invalid TIFF directory; tags are not sorted in ascending order
%s: Failed to read directory at offset %u
Unknown zTXt compression type %d
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
deflate 1.2.3 Copyright 1995-2003 Jean-loup Gailly
%ld%c
%s compression support is not configured
inflate 1.2.3 Copyright 1995-2005 Mark Adler
LogL16Decode: Not enough data at row %d (short %d pixels)
LogLuvDecode24: Not enough data at row %d (short %d pixels)
LogLuvDecode32: Not enough data at row %d (short %d pixels)
?%s: No space for SGILog translation buffer
No support for converting user data format to LogL
No support for converting user data format to LogLuv
Inappropriate photometric interpretation %d for SGILog compression; %s
SGILog compression supported only for %s, or raw data
Unknown data format %d for LogLuv compression
Unknown encoding %d for LogLuv compression
%s: No space for LogLuv state block
?PixarLog compression can't handle bits depth/data format combination (depth: %d)
%d bit input not supported in PixarLog
PixarLogDecode: unsupported bits/sample: %d
%s: stride %d is not a multiple of sample count, %d, data truncated.
%s: zlib error: %s
%s: Not enough data at scanline %d (short %d bytes)
%s: Decoding error at scanline %d, %s
PixarLog compression can't handle %d bit linear encodings
A%s: Encoder error: %s
%s: Bad code word at line %u of %s %u (x %u)
%s: Uncompressed data (not supported) at line %u of %s %u (x %u)
%s: %s at line %u of %s %u (got %u, expected %u)
%s: Premature EOF at line %u of %s %u (x %u)
%s: No space for Group 3/4 reference line
@ Fax DCS: %s
Fax SubAddress: %s
(%u = 0x%x)
%sEOL padding
%s2-d encoding
%suncompressed data
%s: No space for state block
JpegRestartInterval: %u
JpegProc: %u
OJPEG encoding not supported; use new-style JPEG compression instead
Unknown marker type %d in JPEG data
Subsampling values [%d,%d] are not allowed in TIFF
Subsampling inside JPEG data does not match subsampling tag values [%d,%d] (nor any other values allowed in TIFF); assuming subsampling inside JPEG data is correct and desubsampling inside JPEG decompression
Subsampling inside JPEG data [%d,%d] does not match subsampling tag values [%d,%d]; assuming subsampling inside JPEG data is correct
Subsampling tag is not set, yet subsampling inside JPEG data [%d,%d] does not match default values [2,2]; assuming subsampling inside JPEG data is correct
SamplesPerPixel %d not supported for this compression scheme
JPEG strip/tile size exceeds expected dimensions, expected %dx%d, got %dx%d
Decompressor will try reading with sampling %d,%d.
Improper JPEG sampling factors %d,%d
Apparently should be %d,%d.
Improper JPEG strip/tile size, expected %dx%d, got %dx%d
RowsPerStrip must be multiple of %d for JPEG
JPEG tile width must be multiple of %d
JPEG tile height must be multiple of %d
BitsPerSample %d not allowed for JPEG
PhotometricInterpretation %d not allowed for JPEG
ThunderDecode: %s data at scanline %ld (%lu != %lu)
LZWDecode: Bogus encoding, loop in the code table; scanline %d
LZWDecode: Not enough data at scanline %d (short %ld bytes)
LZWDecode: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecode: Corrupted LZW table at scanline %d
LZWDecode: Strip %d not terminated with EOI code
LZWDecodeCompat: Corrupted LZW table at scanline %d
LZWDecodeCompat: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecodeCompat: Not enough data at scanline %d (short %ld bytes)
DumpModeDecode: Not enough data for scanline %d
Horizontal differencing "Predictor" not supported with %d-bit samples
Floating point "Predictor" not supported with %d data format
"Predictor" value %d not supported
Out of memory allocating %d byte temp buffer.
%u (0x%x)
WindowsForms
NTDLL.DLL
COMCTL32.DLL
USER32.DLL
MSCTF.DLL
GDI32.DLL
SHLWAPI.DLL
UXTHEME.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
LEFTPRESSED
ALWAYSSHOWSIZINGBAR
MSGBOXFONT
%[^,], %ld, %s
User32.dll
msimg32.dll
windows-1254
windows-874
SUBLANG_PORTUGUESE_BRAZILIAN
Portuguese (Brazil)
SUBLANG_PORTUGUESE
LANG_PORTUGUESE
Portuguese (Portugal)
windows-1255
windows-1257
windows-1253
windows-1252
windows-1250
windows-1256
windows-1251
1.2.40
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
WININET.dll
?#%X.y
InternetCrackUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCISImageEx@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDVCRect@@AAV3@@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.PAVCThreadException@IR@@
.PAVCObject@@
.PAVCOleException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCArchiveException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDV12@PBD@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.PAVCOleDispatchException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCObList@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDHH@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe
GetProcessHeap
GetCPInfo
GetWindowsDirectoryA
RegCloseKey
RegOpenKeyExA
RegCreateKeyExA
RegEnumKeyA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteKeyA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GetViewportExtEx
GdiplusShutdown
ShellExecuteExA
ShellExecuteA
UrlUnescapeA
URLDownloadToFileA
MapVirtualKeyExA
GetKeyboardState
GetKeyboardLayout
MapVirtualKeyA
GetKeyNameTextA
SetWindowsHookExA
UnhookWindowsHookEx
CreateDialogIndirectParamA
GetKeyState
ExitWindowsEx
EnumWindows
MsgWaitForMultipleObjects
GetAsyncKeyState
|5#" " " 
# # #""%"$
^)1-"*"<.
2;%SK
%.Fh3>$]R
]<%XZ
WEBI
]>2?>2/"
H%FZW
|@@@@8>-
\ ,%X
[9<;.MK31?MM&
!3-%#;3&1
##0#3131%& 
.QICN,1#-#5<## @I3>##Jl;>C3I=I6lIC6&-4-350T-3]
$&%f#F>#
:0@033*00
$,0($,$4
(,,4,4,$
0488<<<( 0
.text
`.rdata
@.data
.rsrc
@.reloc
accKeyboardShortcut
hhctrl.ocx
dwmapi.dll
xUxTheme.dll
yDWrite.dll
D2D1.dll
SHELL32.DLL
RICHED20.DLL
mscoree.dll
ekernel32.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
aero.msstyles
winxp.royale.cjstyles
royale.msstyles
winxp.luna.cjstyles
luna.msstyles
Argument %d must be of type %s.
%d arguments required.
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]

soundbar.exe_3352:

.text
`.rdata
@.data
.rsrc
@.reloc
diu2.iu
Advapi32.dll
lua5.1.dll
irsetup.exe
Could not determine a temp directory name. Try running setup.exe /T:<Path>
c:\temp
%s\irsetup.exe
%s%s_%d
"__IRSID:%s"
"__IRCT:%d"
"__IRAFN:%s"
GetProcessWindowStation
operator
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
ADVAPI32.dll
ShellExecuteExA
SHELL32.dll
GetCPInfo
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\soundbar.exe
%xERRj3cqZQ
! !!####0
;;;9551%%0
! !!565665@
version="9.5.0.0"
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
<!-- Windows Vista Support -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 Support -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 Support -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 Support -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 Support -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
7%7S7v7|7
mscoree.dll
KERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
9.5.0.0
suf_launch.exe

irsetup.exe_3456:

`.rsrc
t%SSSS
9=@%C
SSSSh
t%SWV
u)SSh
u)SShd
TSShX
@ SSh
u%SSSV
SSShT
SSSh`
9^$u&SSSSh?
9^$u SSSSh?
9^$u)SSSSh?
|SShF
t2SSh
Ht.Ht S
FLSSh
NLhD%C
GLSSh
GXSSh
FpSSh
FtSSh
G`SSh
.WWWW
Nt.Nt
t'SShl
u$SShe
@ SSHPWj
tFHt:Ht.Ht"Hu`
tWSShW
tl9_ tgSSh
tAHt.HHt
j%XtL9E
<SShG
FtPW
SSh@B
FTCP
u.Ph,
.FG;}
FTPQ
FTPh
V SShW
O SSh
O SSh,
diu2.iu
kernel32.dll
%s (%s:%d)
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin1.inl
MSG_ERROR
%s %d. %s
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM
A%s%s%s.%d
%s.%d
%s, Line %d: %s
File condition evaluation for file "%s"
msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
C:\temp\SUF_SFX_TEST\
MSG_INITIALIZING
16670749
_IgnoreInvalidCertificate
SetEntriesInAcl Error %u
SetNamedSecurityInfo Error %u
*.gif
*.tif
*.tga
*.png
*.pcx
*.jpg
*.bmp
[%d]: %s
*** LOCATION: %s
__NOREPORT__
in function <%s:%d>
in function '%s'
Line: %d
%d: [%s]
Script: %s, %s (%s)
__ir_eval_value = %s;
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
MainWindowSettings
%s at offset %d unterminated
Incorrect %s at offset %d
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_CANCEL
MSG_OK
MSG_BROWSE
MSG_PATH
Windows Server 10
Windows 10
Windows Server 2012 R2
Windows 8.1
Windows Server 2012
Windows 8
Windows Server 2008 R2
Windows 7
Windows Server 2008
Windows Vista
Windows Server 2003
Windows XP
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
%TempFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartFolder%
%StartProgramsFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SystemDrive%
_WindowsFolder
%WindowsFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%FontsFolder%
ÞsktopFolderCommon%
;?;?.lua
UninstallSupportFiles
CPRegKey
Run extra uninstall script: %d
Original: %d
Calculated: %d
Unable to open archive file: %d
lua5.1.dll
%SourceDrive%
%SourceFilename%
\irsetup.dat
{D387204B-8FB9-6A21-15FA-0CD14BF40EA9}
Support file added to uninstall list:
Registry key added to uninstall list:
Removed! %d
IDispatch error #%d
Error 0xx: %s
Register font: %s, %s
%sbk%d
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
Remove uninstall support file:
MSG_NO
MSG_YES_TOALL
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib failure reason: %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM failure reason: %s
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s (New count = %d)
%s\%s
%s (%d)
\irsetup.skin
local e_Stage = %d;local e_CurrentItemText=[==[%s]==];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_SYSREQ_ABORT
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
%s: %d
MSG_SYSREQ_SCREENWIDTH
%s: %d %s
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
Operating System
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_WSRV10
MSG_OS_W10
MSG_OS_WSRV2012_R2
MSG_OS_W8_1
MSG_OS_WSRV2012
MSG_OS_W8
MSG_OS_WSRV2008_R2
MSG_OS_W7
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
%s %d %s
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
%s %I64d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s (Return code: %d)
Product: %s, version %s
MSG_SEEKING
%s (%d):
Arc: %s
FN: %s
%s (#%d)
MSG_SKIPPING
MSG_INSTALLING
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Existing uninstall executable is newer. Will not overwrite.
Compared uninstall file versions. New: %s Old: %s Result: %d
Uninstall executable already exists: %s
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
"%s" "/U:%s"
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
Dependency Detection Passed
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
[%s] %s
%m/%d/%Y %H:%M:%S
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_500
ERR_WEB_404
ERR_WEB_403
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyName%
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%TempFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%AppFolder%\uninstall.exe
uninstall.xml
CWebBrowser2
Confirm Operation
KERNEL32.DLL
PSAPI.DLL
Kernel32.dll
WS2_32.DLL
Copying "%s"
"%s" %s
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
Sfc.dll
.bak%d
Windows ME
Windows 98
Windows 95
Windows 2000
Windows NT 4
Windows NT 3
%s\shell\open\command
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.pif
srclient.dll
%s_%d
%s\_ir_tmpfnt_%d
/\:*?"<>|
%%x
d:d
WinINet.dll
Could not create Internet session: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
PTF://
hXXps://
hXXp://
%s; DIRECT
jsproxy.dll
DetectAutoProxyUrl
wininet.dll
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG: %d
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, Line %d
All Files (*.*)|*.*|
PasswordInput
MSG_MOVING
MSG_COPYING
MSG_FROM
MSG_TO
MSG_DELETING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
ErrorMsg
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
\msiexec.exe
RunMsiexec
SQLInstallerError
SQLRemoveDriverManager
odbccp32.dll
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverManager
SQLRemoveDriver
\Kernel32.dll
GetKeyNames
DoesKeyExist
DeleteKey
CreateKey
ShortcutKey
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
xxxxxx
%s-%s-%s
%s/%s/%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s PM
MSG_REBOOT_FAILED
WININET.DLL
PPassword
Password
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_DOWNLOADING
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_READING
GetHTTPErrorInfo
%s > %s
number e_CtrlID, number e_MsgID, table e_Details
Removed: %s
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Check%d
ComboBox%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Application.Exit();
Screen.Next();
Screen.Back();
Radio%d
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_BILLBOARD_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_BILLBOARD_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
hXXp://VVV.indigorose.com/route.php?pid=suf9buy
r@.psd
.tiff
.jpeg
.wbmp
CNotSupportedException
user32.dll
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
CCmdTarget
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
comctl32.dll
comdlg32.dll
shell32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
%s%s.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
RegOpenKeyTransactedA
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
CHttpConnection
CHttpFile
HTTP/1.0
msctls_hotkey32
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
mfcm100.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
Shell32.dll
%s:%x:%x:%x:%x
RegDeleteKeyExA
lXXxXXXXXXXX
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
MFCLink_UrlPrefix
MFCLink_Url
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
&%d %s
Hex={X,X,X}
ShowCmd
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
%sPane-%d%x
%sPane-%d
%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
%c%d%c%s
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
windows
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
CMFCToolBarsKeyboardPropertyPage
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
operator
GetProcessWindowStation
IS 5.0.2.4
Error %d in %s (%s)
Error %d in %s (%s) [%s]
C.o.p.y.r.i.g.h.t...2.0.1.0.
ISLib PNG Error : %s
1.2.22
ISLib JPG Error : %s
DIBToHBITMAP error: GetLastError = %d
read %d. layersLen %d
Reading PCD sub-image #%d (%d x %d)
.cals
Keywords
SetWinMetaFileBits failed GetLastError = %d
GeoKeyDirectory
%s: Invalid InkNames value; expecting %d names, found %d
%s: Bad value %u for "%s" tag
%s: Invalid %stag "%s" (not supported by codec)
%s: Bad field type %d for "%s"
%s: Failed to allocate space for list of custom values
%s: Bad value %d for "%s" tag
%s: Sorry, cannot nest SubIFDs
Nonstandard tile width %d, convert file
Nonstandard tile length %d, convert file
%s: Cannot modify tag "%s" while writing
%s: Unknown %stag %u
%s: Error fetching directory link
%s: Error fetching directory count
Sorry, can not handle images with %d-bit samples
Sorry, LogL data must have %s=%d
Sorry, can not handle LogLuv images with %s=%d
Sorry, LogLuv data must have %s=%d or %d
Sorry, can not handle image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d and Bits/Sample=%d
Sorry, can not handle RGB image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d
Sorry, can not handle separated image with %s=%d
Missing needed %s tag
No space %s
%s: Read error at scanline %lu, strip %lu; got %lu bytes, expected %lu
%s: Read error at scanline %lu; got %lu bytes, expected %lu
%s: Seek error at scanline %lu, strip %lu
%s: Read error at row %ld, col %ld, tile %ld; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld; got %lu bytes, expected %lu
%s: Seek error at row %ld, col %ld, tile %ld
%s: No space for data buffer at scanline %ld
%s: Data buffer too small to hold strip %lu
%s: Read error on strip %lu; got %lu bytes, expected %lu
%s: Invalid strip byte count %lu, strip %lu
%s: Data buffer too small to hold tile %ld
"%s": Bad mode
Not a TIFF file, bad version number %d (0x%x)
This is a BigTIFF file. This format not supported
Not a TIFF or MDI file, bad magic number %d (0x%x)
%s: Out of memory (TIFF structure)
Error writing data for field "%s"
%s: Error writing SubIFD directory link
M"%s": Information lost writing value (%g) as (unsigned) RATIONAL
Integer overflow in %s
LIBTIFF, Version 3.9.1
0123456789ABCDEFlibpng error: %s
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning: %s
libpng warning no. %s: %s
1.2.3
NULL row buffer for row %ld, pass %d
iTXt chunk not supported.
Corrupt JPEG data: found marker 0xx instead of RST%d
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
RST%d
At marker 0xx, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Unsupported marker type 0xx
Failed to create temporary file %s
Unsupported JPEG process: SOF type 0xx
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Huffman table 0xx was not defined
Backing store not supported
Cannot transcode due to multiple use of quantization table %d
Maximum supported image dimension is %u pixels
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
Buffer passed to JPEG library is too small
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Wrong JPEG library version: library is %d, caller expects %d
IDCT output block size %d not supported
Invalid component ID %d in SOS
Bogus message code %d
Found bad IPTC data resource (len exceeds block end). ID=%d
ExifInteroperabilityOffset
InteroperabilityVersion
InteroperabilityIndex
AsShotPreProfileMatrix
AsShotICCProfile
AsShotWhiteXY
AsShotNeutral
InteroperabilityIFDOffset
Internal error, unknown tag 0x%x
Tag %d
Compression algorithm does not support random access
Compression scheme %u %s encoding is not implemented
%s %s encoding is not implemented
Compression scheme %u %s decoding is not implemented
%s %s decoding is not implemented
%s: Cannot determine size of unknown tag type %d
%s: TIFF directory is missing required "%s" field
incorrect count for field "%s" (%u, expecting %u); tag trimmed
incorrect count for field "%s" (%u, expecting %u); tag ignored
%s: Can not read TIFF directory
%s: Can not read TIFF directory count
%s: Seek error accessing TIFF directory
Error fetching data for field "%s"
%s: Rational with zero denominator (num = %u)
unexpected count for field "%s", %u, expected 2; ignored
cannot read TIFF_ANY type %d for field "%s"
Cannot handle different per-sample values for field "%s"
%s: cannot handle zero strip size
%s: cannot handle zero tile size
%s: cannot handle zero scanline size
%s: Wrong "%s" field, ignoring and calculating from imagelength
%s: Bogus "%s" field, ignoring and calculating from imagelength
%s: TIFF directory is missing required "%s" field, calculating from imagelength
%s: cannot handle zero number of %s
%s: wrong data type %d for "%s"; tag ignored
Registering anonymous field with tag %d (0x%x) failed
%s: unknown field with tag %d (0x%x) encountered
%s: invalid TIFF directory; tags are not sorted in ascending order
%s: Failed to read directory at offset %u
Unknown zTXt compression type %d
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
deflate 1.2.3 Copyright 1995-2003 Jean-loup Gailly
%ld%c
%s compression support is not configured
inflate 1.2.3 Copyright 1995-2005 Mark Adler
LogL16Decode: Not enough data at row %d (short %d pixels)
LogLuvDecode24: Not enough data at row %d (short %d pixels)
LogLuvDecode32: Not enough data at row %d (short %d pixels)
?%s: No space for SGILog translation buffer
No support for converting user data format to LogL
No support for converting user data format to LogLuv
Inappropriate photometric interpretation %d for SGILog compression; %s
SGILog compression supported only for %s, or raw data
Unknown data format %d for LogLuv compression
Unknown encoding %d for LogLuv compression
%s: No space for LogLuv state block
?PixarLog compression can't handle bits depth/data format combination (depth: %d)
%d bit input not supported in PixarLog
PixarLogDecode: unsupported bits/sample: %d
%s: stride %d is not a multiple of sample count, %d, data truncated.
%s: zlib error: %s
%s: Not enough data at scanline %d (short %d bytes)
%s: Decoding error at scanline %d, %s
PixarLog compression can't handle %d bit linear encodings
A%s: Encoder error: %s
%s: Bad code word at line %u of %s %u (x %u)
%s: Uncompressed data (not supported) at line %u of %s %u (x %u)
%s: %s at line %u of %s %u (got %u, expected %u)
%s: Premature EOF at line %u of %s %u (x %u)
%s: No space for Group 3/4 reference line
@ Fax DCS: %s
Fax SubAddress: %s
(%u = 0x%x)
%sEOL padding
%s2-d encoding
%suncompressed data
%s: No space for state block
JpegRestartInterval: %u
JpegProc: %u
OJPEG encoding not supported; use new-style JPEG compression instead
Unknown marker type %d in JPEG data
Subsampling values [%d,%d] are not allowed in TIFF
Subsampling inside JPEG data does not match subsampling tag values [%d,%d] (nor any other values allowed in TIFF); assuming subsampling inside JPEG data is correct and desubsampling inside JPEG decompression
Subsampling inside JPEG data [%d,%d] does not match subsampling tag values [%d,%d]; assuming subsampling inside JPEG data is correct
Subsampling tag is not set, yet subsampling inside JPEG data [%d,%d] does not match default values [2,2]; assuming subsampling inside JPEG data is correct
SamplesPerPixel %d not supported for this compression scheme
JPEG strip/tile size exceeds expected dimensions, expected %dx%d, got %dx%d
Decompressor will try reading with sampling %d,%d.
Improper JPEG sampling factors %d,%d
Apparently should be %d,%d.
Improper JPEG strip/tile size, expected %dx%d, got %dx%d
RowsPerStrip must be multiple of %d for JPEG
JPEG tile width must be multiple of %d
JPEG tile height must be multiple of %d
BitsPerSample %d not allowed for JPEG
PhotometricInterpretation %d not allowed for JPEG
ThunderDecode: %s data at scanline %ld (%lu != %lu)
LZWDecode: Bogus encoding, loop in the code table; scanline %d
LZWDecode: Not enough data at scanline %d (short %ld bytes)
LZWDecode: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecode: Corrupted LZW table at scanline %d
LZWDecode: Strip %d not terminated with EOI code
LZWDecodeCompat: Corrupted LZW table at scanline %d
LZWDecodeCompat: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecodeCompat: Not enough data at scanline %d (short %ld bytes)
DumpModeDecode: Not enough data for scanline %d
Horizontal differencing "Predictor" not supported with %d-bit samples
Floating point "Predictor" not supported with %d data format
"Predictor" value %d not supported
Out of memory allocating %d byte temp buffer.
%u (0x%x)
WindowsForms
NTDLL.DLL
COMCTL32.DLL
USER32.DLL
MSCTF.DLL
GDI32.DLL
SHLWAPI.DLL
UXTHEME.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
LEFTPRESSED
ALWAYSSHOWSIZINGBAR
MSGBOXFONT
%[^,], %ld, %s
User32.dll
msimg32.dll
windows-1254
windows-874
SUBLANG_PORTUGUESE_BRAZILIAN
Portuguese (Brazil)
SUBLANG_PORTUGUESE
LANG_PORTUGUESE
Portuguese (Portugal)
windows-1255
windows-1257
windows-1253
windows-1252
windows-1250
windows-1256
windows-1251
1.2.40
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
WININET.dll
?#%X.y
InternetCrackUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCISImageEx@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDVCRect@@AAV3@@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.PAVCThreadException@IR@@
.PAVCObject@@
.PAVCOleException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCArchiveException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDV12@PBD@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.PAVCOleDispatchException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCObList@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDHH@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe
GetProcessHeap
GetCPInfo
GetWindowsDirectoryA
RegCloseKey
RegOpenKeyExA
RegCreateKeyExA
RegEnumKeyA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteKeyA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GetViewportExtEx
GdiplusShutdown
ShellExecuteExA
ShellExecuteA
UrlUnescapeA
URLDownloadToFileA
MapVirtualKeyExA
GetKeyboardState
GetKeyboardLayout
MapVirtualKeyA
GetKeyNameTextA
SetWindowsHookExA
UnhookWindowsHookEx
CreateDialogIndirectParamA
GetKeyState
ExitWindowsEx
EnumWindows
MsgWaitForMultipleObjects
GetAsyncKeyState
|5#" " " 
# # #""%"$
^)1-"*"<.
2;%SK
%.Fh3>$]R
]<%XZ
WEBI
]>2?>2/"
H%FZW
|@@@@8>-
\ ,%X
[9<;.MK31?MM&
!3-%#;3&1
##0#3131%& 
.QICN,1#-#5<## @I3>##Jl;>C3I=I6lIC6&-4-350T-3]
$&%f#F>#
:0@033*00
$,0($,$4
(,,4,4,$
0488<<<( 0
.text
`.rdata
@.data
.rsrc
@.reloc
%xERRj3cqZQ
! !!####0
;;;9551%%0
! !!565665@
version="9.5.0.0"
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
<!-- Windows Vista Support -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 Support -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 Support -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 Support -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 Support -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
gdiplus.dll
imagehlp.dll
IMM32.dll
MSIMG32.dll
NETAPI32.dll
OLEACC.dll
OLEAUT32.dll
oledlg.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
VERSION.dll
WINMM.dll
WINSPOOL.DRV
accKeyboardShortcut
hhctrl.ocx
$WININET.DLL
dwmapi.dll
xUxTheme.dll
yDWrite.dll
D2D1.dll
SHELL32.DLL
(RICHED20.DLL
mscoree.dll
ekernel32.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
aero.msstyles
winxp.royale.cjstyles
royale.msstyles
winxp.luna.cjstyles
luna.msstyles
Argument %d must be of type %s.
%d arguments required.
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]
9.5.0.0
2015 Indigo Rose Corporation (VVV.indigorose.com)
suf_rt.exe

irsetup.exe_3456_rwx_000E1000_003DD000:

t%SSSS
9=@%C
SSSSh
t%SWV
u)SSh
u)SShd
TSShX
@ SSh
u%SSSV
SSShT
SSSh`
9^$u&SSSSh?
9^$u SSSSh?
9^$u)SSSSh?
|SShF
t2SSh
Ht.Ht S
FLSSh
NLhD%C
GLSSh
GXSSh
FpSSh
FtSSh
G`SSh
.WWWW
Nt.Nt
t'SShl
u$SShe
@ SSHPWj
tFHt:Ht.Ht"Hu`
tWSShW
tl9_ tgSSh
tAHt.HHt
j%XtL9E
<SShG
FtPW
SSh@B
FTCP
u.Ph,
.FG;}
FTPQ
FTPh
V SShW
O SSh
O SSh,
diu2.iu
kernel32.dll
%s (%s:%d)
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin1.inl
MSG_ERROR
%s %d. %s
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM
A%s%s%s.%d
%s.%d
%s, Line %d: %s
File condition evaluation for file "%s"
msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
C:\temp\SUF_SFX_TEST\
MSG_INITIALIZING
16670749
_IgnoreInvalidCertificate
SetEntriesInAcl Error %u
SetNamedSecurityInfo Error %u
*.gif
*.tif
*.tga
*.png
*.pcx
*.jpg
*.bmp
[%d]: %s
*** LOCATION: %s
__NOREPORT__
in function <%s:%d>
in function '%s'
Line: %d
%d: [%s]
Script: %s, %s (%s)
__ir_eval_value = %s;
c:\Program Files\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
MainWindowSettings
%s at offset %d unterminated
Incorrect %s at offset %d
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_CANCEL
MSG_OK
MSG_BROWSE
MSG_PATH
Windows Server 10
Windows 10
Windows Server 2012 R2
Windows 8.1
Windows Server 2012
Windows 8
Windows Server 2008 R2
Windows 7
Windows Server 2008
Windows Vista
Windows Server 2003
Windows XP
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
%TempFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartFolder%
%StartProgramsFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SystemDrive%
_WindowsFolder
%WindowsFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%FontsFolder%
ÞsktopFolderCommon%
;?;?.lua
UninstallSupportFiles
CPRegKey
Run extra uninstall script: %d
Original: %d
Calculated: %d
Unable to open archive file: %d
lua5.1.dll
%SourceDrive%
%SourceFilename%
\irsetup.dat
{D387204B-8FB9-6A21-15FA-0CD14BF40EA9}
Support file added to uninstall list:
Registry key added to uninstall list:
Removed! %d
IDispatch error #%d
Error 0xx: %s
Register font: %s, %s
%sbk%d
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
Remove uninstall support file:
MSG_NO
MSG_YES_TOALL
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib failure reason: %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM failure reason: %s
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s (New count = %d)
%s\%s
%s (%d)
\irsetup.skin
local e_Stage = %d;local e_CurrentItemText=[==[%s]==];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_SYSREQ_ABORT
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
%s: %d
MSG_SYSREQ_SCREENWIDTH
%s: %d %s
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
Operating System
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_WSRV10
MSG_OS_W10
MSG_OS_WSRV2012_R2
MSG_OS_W8_1
MSG_OS_WSRV2012
MSG_OS_W8
MSG_OS_WSRV2008_R2
MSG_OS_W7
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
%s %d %s
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
%s %I64d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s (Return code: %d)
Product: %s, version %s
MSG_SEEKING
%s (%d):
Arc: %s
FN: %s
%s (#%d)
MSG_SKIPPING
MSG_INSTALLING
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Existing uninstall executable is newer. Will not overwrite.
Compared uninstall file versions. New: %s Old: %s Result: %d
Uninstall executable already exists: %s
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
"%s" "/U:%s"
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
Dependency Detection Passed
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
[%s] %s
%m/%d/%Y %H:%M:%S
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_500
ERR_WEB_404
ERR_WEB_403
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyName%
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%TempFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%AppFolder%\uninstall.exe
uninstall.xml
CWebBrowser2
Confirm Operation
KERNEL32.DLL
PSAPI.DLL
Kernel32.dll
WS2_32.DLL
Copying "%s"
"%s" %s
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
Sfc.dll
.bak%d
Windows ME
Windows 98
Windows 95
Windows 2000
Windows NT 4
Windows NT 3
%s\shell\open\command
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.pif
srclient.dll
%s_%d
%s\_ir_tmpfnt_%d
/\:*?"<>|
%%x
d:d
WinINet.dll
Could not create Internet session: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
PTF://
hXXps://
hXXp://
%s; DIRECT
jsproxy.dll
DetectAutoProxyUrl
wininet.dll
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG: %d
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, Line %d
All Files (*.*)|*.*|
PasswordInput
MSG_MOVING
MSG_COPYING
MSG_FROM
MSG_TO
MSG_DELETING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
ErrorMsg
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
\msiexec.exe
RunMsiexec
SQLInstallerError
SQLRemoveDriverManager
odbccp32.dll
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverManager
SQLRemoveDriver
\Kernel32.dll
GetKeyNames
DoesKeyExist
DeleteKey
CreateKey
ShortcutKey
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
xxxxxx
%s-%s-%s
%s/%s/%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s PM
MSG_REBOOT_FAILED
WININET.DLL
PPassword
Password
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_DOWNLOADING
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_READING
GetHTTPErrorInfo
%s > %s
number e_CtrlID, number e_MsgID, table e_Details
Removed: %s
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Check%d
ComboBox%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Application.Exit();
Screen.Next();
Screen.Back();
Radio%d
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_BILLBOARD_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_BILLBOARD_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
hXXp://VVV.indigorose.com/route.php?pid=suf9buy
r@.psd
.tiff
.jpeg
.wbmp
CNotSupportedException
user32.dll
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
commctrl_DragListMsg
CCmdTarget
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
comctl32.dll
comdlg32.dll
shell32.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winfrm.cpp
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
%s%s.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
lX-X-x-XX-XXXXXX
RegOpenKeyTransactedA
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
CHttpConnection
CHttpFile
HTTP/1.0
msctls_hotkey32
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\winctrl2.cpp
mfcm100.dll
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
Shell32.dll
%s:%x:%x:%x:%x
RegDeleteKeyExA
lXXxXXXXXXXX
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
MFCLink_UrlPrefix
MFCLink_Url
CMDITabProxyWnd
CMDIChildWndEx
CMDIFrameWndEx
%sMFCToolBar-%d%x
%sMFCToolBar-%d
%sMFCToolBarParameters
TOOLBAR_RESETKEYBAORD
KeyboardManager
MSG_CHECKEMPTYMINIFRAME
%sDockingManager-%d
&%d %s
Hex={X,X,X}
ShowCmd
CMDIChildWnd
CMDIFrameWnd
CMDIClientAreaWnd
%sMDIClientArea-%d
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\viewcore.cpp
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oleipfrm.cpp
%sBasePane-%d%x
%sBasePane-%d
%sPane-%d%x
%sPane-%d
%sMFCOutlookBar-%d%x
%sMFCOutlookBar-%d
%c%d%c%s
RGB(%d, %d, %d)
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\olestrm.cpp
%sDockablePaneAdapter-%d%x
%sDockablePaneAdapter-%d
ENABLE_KEYS
KEYS_MENU
KEYS
windows
f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\oledrop2.cpp
CMFCToolBarsKeyboardPropertyPage
%sMFCTasksPane-%d%x
%sMFCTasksPane-%d
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
operator
GetProcessWindowStation
IS 5.0.2.4
Error %d in %s (%s)
Error %d in %s (%s) [%s]
C.o.p.y.r.i.g.h.t...2.0.1.0.
ISLib PNG Error : %s
1.2.22
ISLib JPG Error : %s
DIBToHBITMAP error: GetLastError = %d
read %d. layersLen %d
Reading PCD sub-image #%d (%d x %d)
.cals
Keywords
SetWinMetaFileBits failed GetLastError = %d
GeoKeyDirectory
%s: Invalid InkNames value; expecting %d names, found %d
%s: Bad value %u for "%s" tag
%s: Invalid %stag "%s" (not supported by codec)
%s: Bad field type %d for "%s"
%s: Failed to allocate space for list of custom values
%s: Bad value %d for "%s" tag
%s: Sorry, cannot nest SubIFDs
Nonstandard tile width %d, convert file
Nonstandard tile length %d, convert file
%s: Cannot modify tag "%s" while writing
%s: Unknown %stag %u
%s: Error fetching directory link
%s: Error fetching directory count
Sorry, can not handle images with %d-bit samples
Sorry, LogL data must have %s=%d
Sorry, can not handle LogLuv images with %s=%d
Sorry, LogLuv data must have %s=%d or %d
Sorry, can not handle image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d and Bits/Sample=%d
Sorry, can not handle RGB image with %s=%d
Sorry, can not handle contiguous data with %s=%d, and %s=%d
Sorry, can not handle separated image with %s=%d
Missing needed %s tag
No space %s
%s: Read error at scanline %lu, strip %lu; got %lu bytes, expected %lu
%s: Read error at scanline %lu; got %lu bytes, expected %lu
%s: Seek error at scanline %lu, strip %lu
%s: Read error at row %ld, col %ld, tile %ld; got %lu bytes, expected %lu
%s: Read error at row %ld, col %ld; got %lu bytes, expected %lu
%s: Seek error at row %ld, col %ld, tile %ld
%s: No space for data buffer at scanline %ld
%s: Data buffer too small to hold strip %lu
%s: Read error on strip %lu; got %lu bytes, expected %lu
%s: Invalid strip byte count %lu, strip %lu
%s: Data buffer too small to hold tile %ld
"%s": Bad mode
Not a TIFF file, bad version number %d (0x%x)
This is a BigTIFF file. This format not supported
Not a TIFF or MDI file, bad magic number %d (0x%x)
%s: Out of memory (TIFF structure)
Error writing data for field "%s"
%s: Error writing SubIFD directory link
M"%s": Information lost writing value (%g) as (unsigned) RATIONAL
Integer overflow in %s
LIBTIFF, Version 3.9.1
0123456789ABCDEFlibpng error: %s
libpng error: %s, offset=%d
libpng error no. %s: %s
libpng warning: %s
libpng warning no. %s: %s
1.2.3
NULL row buffer for row %ld, pass %d
iTXt chunk not supported.
Corrupt JPEG data: found marker 0xx instead of RST%d
Warning: unknown JFIF revision number %d.d
Corrupt JPEG data: %u extraneous bytes before marker 0xx
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Component %d: %dhx%dv q=%d
Start Of Frame 0xx: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
RST%d
At marker 0xx, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0xx
Miscellaneous marker 0xx, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0xx, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.d, density %dx%d %d
= = = = = = = =
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0xx
Define Arithmetic Table 0xx: 0xx
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0xx 0xx, transform %d
Unsupported marker type 0xx
Failed to create temporary file %s
Unsupported JPEG process: SOF type 0xx
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0xx 0xx
Quantization table 0xx was not defined
Huffman table 0xx was not defined
Backing store not supported
Cannot transcode due to multiple use of quantization table %d
Maximum supported image dimension is %u pixels
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
Buffer passed to JPEG library is too small
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Wrong JPEG library version: library is %d, caller expects %d
IDCT output block size %d not supported
Invalid component ID %d in SOS
Bogus message code %d
Found bad IPTC data resource (len exceeds block end). ID=%d
ExifInteroperabilityOffset
InteroperabilityVersion
InteroperabilityIndex
AsShotPreProfileMatrix
AsShotICCProfile
AsShotWhiteXY
AsShotNeutral
InteroperabilityIFDOffset
Internal error, unknown tag 0x%x
Tag %d
Compression algorithm does not support random access
Compression scheme %u %s encoding is not implemented
%s %s encoding is not implemented
Compression scheme %u %s decoding is not implemented
%s %s decoding is not implemented
%s: Cannot determine size of unknown tag type %d
%s: TIFF directory is missing required "%s" field
incorrect count for field "%s" (%u, expecting %u); tag trimmed
incorrect count for field "%s" (%u, expecting %u); tag ignored
%s: Can not read TIFF directory
%s: Can not read TIFF directory count
%s: Seek error accessing TIFF directory
Error fetching data for field "%s"
%s: Rational with zero denominator (num = %u)
unexpected count for field "%s", %u, expected 2; ignored
cannot read TIFF_ANY type %d for field "%s"
Cannot handle different per-sample values for field "%s"
%s: cannot handle zero strip size
%s: cannot handle zero tile size
%s: cannot handle zero scanline size
%s: Wrong "%s" field, ignoring and calculating from imagelength
%s: Bogus "%s" field, ignoring and calculating from imagelength
%s: TIFF directory is missing required "%s" field, calculating from imagelength
%s: cannot handle zero number of %s
%s: wrong data type %d for "%s"; tag ignored
Registering anonymous field with tag %d (0x%x) failed
%s: unknown field with tag %d (0x%x) encountered
%s: invalid TIFF directory; tags are not sorted in ascending order
%s: Failed to read directory at offset %u
Unknown zTXt compression type %d
Incomplete compressed datastream in %s chunk
Data error in compressed datastream in %s chunk
Buffer error in compressed datastream in %s chunk
gamma = (%d/100000)
gx=%f, gy=%f, bx=%f, by=%f
wx=%f, wy=%f, rx=%f, ry=%f
incorrect gamma=(%d/100000)
deflate 1.2.3 Copyright 1995-2003 Jean-loup Gailly
%ld%c
%s compression support is not configured
inflate 1.2.3 Copyright 1995-2005 Mark Adler
LogL16Decode: Not enough data at row %d (short %d pixels)
LogLuvDecode24: Not enough data at row %d (short %d pixels)
LogLuvDecode32: Not enough data at row %d (short %d pixels)
?%s: No space for SGILog translation buffer
No support for converting user data format to LogL
No support for converting user data format to LogLuv
Inappropriate photometric interpretation %d for SGILog compression; %s
SGILog compression supported only for %s, or raw data
Unknown data format %d for LogLuv compression
Unknown encoding %d for LogLuv compression
%s: No space for LogLuv state block
?PixarLog compression can't handle bits depth/data format combination (depth: %d)
%d bit input not supported in PixarLog
PixarLogDecode: unsupported bits/sample: %d
%s: stride %d is not a multiple of sample count, %d, data truncated.
%s: zlib error: %s
%s: Not enough data at scanline %d (short %d bytes)
%s: Decoding error at scanline %d, %s
PixarLog compression can't handle %d bit linear encodings
A%s: Encoder error: %s
%s: Bad code word at line %u of %s %u (x %u)
%s: Uncompressed data (not supported) at line %u of %s %u (x %u)
%s: %s at line %u of %s %u (got %u, expected %u)
%s: Premature EOF at line %u of %s %u (x %u)
%s: No space for Group 3/4 reference line
@ Fax DCS: %s
Fax SubAddress: %s
(%u = 0x%x)
%sEOL padding
%s2-d encoding
%suncompressed data
%s: No space for state block
JpegRestartInterval: %u
JpegProc: %u
OJPEG encoding not supported; use new-style JPEG compression instead
Unknown marker type %d in JPEG data
Subsampling values [%d,%d] are not allowed in TIFF
Subsampling inside JPEG data does not match subsampling tag values [%d,%d] (nor any other values allowed in TIFF); assuming subsampling inside JPEG data is correct and desubsampling inside JPEG decompression
Subsampling inside JPEG data [%d,%d] does not match subsampling tag values [%d,%d]; assuming subsampling inside JPEG data is correct
Subsampling tag is not set, yet subsampling inside JPEG data [%d,%d] does not match default values [2,2]; assuming subsampling inside JPEG data is correct
SamplesPerPixel %d not supported for this compression scheme
JPEG strip/tile size exceeds expected dimensions, expected %dx%d, got %dx%d
Decompressor will try reading with sampling %d,%d.
Improper JPEG sampling factors %d,%d
Apparently should be %d,%d.
Improper JPEG strip/tile size, expected %dx%d, got %dx%d
RowsPerStrip must be multiple of %d for JPEG
JPEG tile width must be multiple of %d
JPEG tile height must be multiple of %d
BitsPerSample %d not allowed for JPEG
PhotometricInterpretation %d not allowed for JPEG
ThunderDecode: %s data at scanline %ld (%lu != %lu)
LZWDecode: Bogus encoding, loop in the code table; scanline %d
LZWDecode: Not enough data at scanline %d (short %ld bytes)
LZWDecode: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecode: Corrupted LZW table at scanline %d
LZWDecode: Strip %d not terminated with EOI code
LZWDecodeCompat: Corrupted LZW table at scanline %d
LZWDecodeCompat: Wrong length of decoded string: data probably corrupted at scanline %d
LZWDecodeCompat: Not enough data at scanline %d (short %ld bytes)
DumpModeDecode: Not enough data for scanline %d
Horizontal differencing "Predictor" not supported with %d-bit samples
Floating point "Predictor" not supported with %d data format
"Predictor" value %d not supported
Out of memory allocating %d byte temp buffer.
%u (0x%x)
WindowsForms
NTDLL.DLL
COMCTL32.DLL
USER32.DLL
MSCTF.DLL
GDI32.DLL
SHLWAPI.DLL
UXTHEME.DLL
API-MS-WIN-CORE-LIBRARYLOADER-L1-1-0.DLL
LEFTPRESSED
ALWAYSSHOWSIZINGBAR
MSGBOXFONT
%[^,], %ld, %s
User32.dll
msimg32.dll
windows-1254
windows-874
SUBLANG_PORTUGUESE_BRAZILIAN
Portuguese (Brazil)
SUBLANG_PORTUGUESE
LANG_PORTUGUESE
Portuguese (Portugal)
windows-1255
windows-1257
windows-1253
windows-1252
windows-1250
windows-1256
windows-1251
1.2.40
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
WININET.dll
?#%X.y
InternetCrackUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCISImageEx@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDVCRect@@AAV3@@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.PAVCThreadException@IR@@
.PAVCObject@@
.PAVCOleException@@
.PAVCSimpleException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.PAVCArchiveException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDV12@PBD@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCDocument@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD_N_N@@
.?AV?$CMap@PAVCDocument@@PAV1@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.PAVCOleDispatchException@@
.?AVCMDITabProxyWnd@@
.?AVCMDIChildWndEx@@
.?AVCMDIChildWnd@@
.?AVCMDIFrameWndEx@@
.?AVCMDIFrameWnd@@
.?AVCMFCToolBarCmdUI@@
.?AVCMFCAcceleratorKey@@
.?AVCMFCColorBarCmdUI@@
.?AV?$CMap@KKV?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBD@@
.?AV?$CList@PAVCMDIChildWndEx@@PAV1@@@
.?AVCMDIClientAreaWnd@@
.?AVCMFCRibbonCmdUI@@
.?AVCMFCCmdUsageCount@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDPAVCObList@@PAV3@@@
.?AV?$CMap@V?$CStringT@DV?$StrTraitMFC@DV?$ChTraitsCRT@D@ATL@@@@@ATL@@PBDHH@@
.?AVCMFCRibbonKeyTip@@
.?AVCMFCToolBarsKeyboardPropertyPage@@
.?AVCMFCTasksPaneToolBarCmdUI@@
.?AVCMFCAcceleratorKeyAssignCtrl@@
zcÁ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe
GetProcessHeap
GetCPInfo
GetWindowsDirectoryA
RegCloseKey
RegOpenKeyExA
RegCreateKeyExA
RegEnumKeyA
RegEnumKeyExA
RegQueryInfoKeyA
RegDeleteKeyA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportOrgEx
GetViewportExtEx
GdiplusShutdown
ShellExecuteExA
ShellExecuteA
UrlUnescapeA
URLDownloadToFileA
MapVirtualKeyExA
GetKeyboardState
GetKeyboardLayout
MapVirtualKeyA
GetKeyNameTextA
SetWindowsHookExA
UnhookWindowsHookEx
CreateDialogIndirectParamA
GetKeyState
ExitWindowsEx
EnumWindows
MsgWaitForMultipleObjects
GetAsyncKeyState
|5#" " " 
# # #""%"$
^)1-"*"<.
2;%SK
%.Fh3>$]R
]<%XZ
WEBI
]>2?>2/"
H%FZW
|@@@@8>-
\ ,%X
[9<;.MK31?MM&
!3-%#;3&1
##0#3131%& 
.QICN,1#-#5<## @I3>##Jl;>C3I=I6lIC6&-4-350T-3]
$&%f#F>#
:0@033*00
$,0($,$4
(,,4,4,$
0488<<<( 0
.text
`.rdata
@.data
.rsrc
@.reloc
accKeyboardShortcut
hhctrl.ocx
$WININET.DLL
dwmapi.dll
xUxTheme.dll
yDWrite.dll
D2D1.dll
SHELL32.DLL
(RICHED20.DLL
mscoree.dll
ekernel32.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
aero.msstyles
winxp.royale.cjstyles
royale.msstyles
winxp.luna.cjstyles
luna.msstyles
Argument %d must be of type %s.
%d arguments required.
All Files (*.*)
No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
#Unable to load mail system support.
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted.fRecover the auto-saved documents
%s [Recovered]

ntvdm.exe_4016:

.text
`.data
.rsrc
@.reloc
KERNEL32.dll
NTDLL.DLL
ADVAPI32.dll
GDI32.dll
USER32.dll
sfc.dll
sfc_os.DLL
SHELL32.dll
SoftPC
mscoree.dll
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
Invalid parameter passed to C runtime function.
GetProcessWindowStation
USER32.DLL
d:\w7rtm\base\mvdm\softpc.new\base\video\video.c
BIOS keyboard buffer overflow
hardware keyboard buffer overflow
%s Mouse %d.01 already installed
%s Mouse %d.01 installed
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_timer.c
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_eoi.c
C:\IBMBIO.SYS
C:\IO.SYS
C:\IBMDOS.SYS
C:\MSDOS.SYS
\ntio404.sys
\ntio411.sys
\ntio412.sys
\ntio804.sys
\ntio.sys
%s %lxh
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_com.c
d:\w7rtm\base\mvdm\softpc.new\host\src\config.c
Software\Microsoft\Windows NT\CurrentVersion\WOW\Console
\\.\$VDMLPT2
\\.\$VDMLPT3
\\.\$VDMLPT1
FONT.NT
\ega.cpi
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_fulsc.c
Drive %c:
Incompatible DOS diskette, C H R N = %d %d %d %d
\\.\A:
\\.\?:
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_event.c
cmd.exe
WINDOWS VMM 4.0
WINDOWS NT 3.1
WINDOWS 386 3.0
WINDOWS 286 3.0
\_default.pif
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_det.c
VrRemoveOpenNamedPipeInfo
VrConvertLocalNtPipeName
VrAddOpenNamedPipeInfo
VrIsNamedPipeHandle
VrIsNamedPipeName
VrWriteNamedPipe
VrReadNamedPipe
midiOutShortMsg
midiOutLongMsg
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_hosts.c
NtDeviceIoControlFile failed %x
d:\w7rtm\base\mvdm\softpc.new\host\src\nt_sec.c
SoftPc: NtDeCommitVirtualMemory failed !!!! Status = %lx
NTVDMD.DLL
Check Keyboard Status
\ntdos404.sys
\ntdos411.sys
\ntdos412.sys
\ntdos804.sys
\ntdos.sys
demDosDispCall %s
config.nt
PIPE
%c:%sNUL
Software\Microsoft\Windows\CurrentVersion\Setup
Unimplemented SVC %d
Software\Microsoft\Windows NT\CurrentVersion\WOW
tmp dir is <%s>
env var is <%s>
InitFileRedirect:%s ;
RedirectShortFileName: to:<%s>
RedirectShortFileName: from <%s>
RedirectShortEnvVar: to <%s>
RedirectShortEnvVar: <%s>
RedirectLongFileName: to <%s>
RedirectLongFileName: <%s>
%SystemRoot%
%SystemDrive%\Temp
%SystemRoot%\Temp
%s=%s%s /p %s\system32
%s=%3.3u,%3.3u,%s\system32\%s.sys%s
Error Code 0x%x
Software\Microsoft\Windows NT\CurrentVersion\WOW\CmdLine
krnl386.exe
%s - %s
COMMAND.COM
KEYB
\KEYBOARD.SYS
\KEYJ31.SYS
\KEY02.SYS
\KEY01.SYS
\KEYAX.SYS
%s,%d,%s
\KB16.COM
DosKeybIDs
System\CurrentControlSet\Control\Keyboard Layout\
DosKeybCodes
00000409
Software\Microsoft\Windows NT\CurrentVersion\WOW\Compatibility
ntvdm.exe
d:\w7rtm\base\mvdm\dpmi32\buffer.c
Broken pipe
Inappropriate I/O control operation
Operation not permitted
ega.rom
vga.rom
v7vga.rom
bios4.rom
bios1.rom
profile.spc
.spcprofile
d:\w7rtm\base\mvdm\softpc.new\host\src\x86_emm.c
CS:x IP:x OP:x x x x x
ntvdm.pdb
YtYHt.Hut
t.VVVV
t.IIt
SSSSh
~,WSSh
QSSSSh
PSSSSh
SSSSSh
j.Yf;
9t.Ht
s'f;O%s!
V<%ue
tK<%uAj
Ht.HuL
t4HtPHt.Ht
Ht.Ht
|.WSV
GetCPInfo
GetConsoleOutputCP
NtEnumerateValueKey
NtOpenKey
ntdll.dll
RegCloseKey
RegQueryInfoKeyA
RegOpenKeyExA
GetSystemWindowsDirectoryA
GetWindowsDirectoryA
SetConsoleOutputCP
SetConsoleKeyShortcuts
VDMConsoleOperation
GetConsoleKeyboardLayoutNameA
EnumWindows
GetKeyState
VkKeyScanW
MapVirtualKeyA
GetKeyboardType
GetProcessHeap
SoftPcEoi
cmdCheckTemp
cmdCheckTempInit
demIsShortPathName
'?--?1-?6-?:-??-??-:?-6?-1?--?1-?6-?:-??-:?-6?-1?--?--?1-?6-?:-??-:?-6?-1?
$$$(((---222888???
!"#$%&'( 
SoftPC-AT Version 3
89:;<=>?
autoexec.nt
00030<0?0
30333<3?3
<0<3<<<?<
?0?3?<???
!"#$%&'()
Software\Microsoft\Windows NT\CurrentVersion\Terminal Server
\System32\command.com
zcÁ
C:\Windows\system32\ntvdm.exe
\\.\B:
COMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
C:\Windows
6$6(6,606
< <*<`<~<
4L4K4Q4o4
7-8}8
;<<@<\<`<
2 2$2(2,2024282
KERNEL32.DLL
KERNELBASE.DLL
kernel32.dll
kernelbase.dll
Microsoft.Windows.NTVDM
tWOW32.DLL
VDMREDIR.DLL
WINMM.DLL
NTVDM.EXE
6.1.7600.16385 (win7_rtm.090713-1255)
Windows
Operating System
6.1.7600.16385
5The NTVDM CPU has encountered an illegal instruction."Internal error in NTVDM procedure.#NTVDM does not support a ROM BASIC.BFailure to allocate the requested number of Expanded Memory pages.*A continuous RESET state has been entered.
LAn installation file required by NTVDM is missing, execution must terminate.
Insufficient memory resources.=The NTVDM CPU has encountered an unsupported 386 instruction.TThe EMM command line in your config.nt contains invalid parameters or syntax errors.5The NTVDM CPU has encountered an unhandled exception.t
MS-DOS program files must end with the extension .EXE, .COM, or .BAT.
vAn application has attempted to %s, which cannot be supported. This may cause the application to function incorrectly./directly access an incompatible diskette format
16 bit Windows Subsystem
VThe system file is not suitable for running MS-DOS and Microsoft Windows applications."Memory error during intialization.
A temporary file needed for initialization could not be created or could not be written to. Make sure that the directory path exists, and disk space is available.-This system does not support fullscreen mode.?Insufficient memory to load installable Virtual Device Drivers.8Virtual Device Driver format in the registry is invalid.?An installable Virtual Device Driver failed Dll initialization.
Unable to lock for exclusive access. Another application may be using the drive. When the other application has finished using the drive you may retry the operation.
Drive %c: ZThe Application attempted to enable DOS graphics mode. DOS graphics mode is not supported.
Function failed$NTVDM has encountered a System Error*Driver does not support selected Baud Rate<The system cannot open %s port requested by the application.

ntvdm.exe_4016_rwx_00000000_00010000:

C:\USERS\ADM\APPDATA\LOCAL\TEMP\WOWRR.EXE
WOWRR EXE
."/\[]:|<> =;,
c:\wina20.386
%WinDir%\SYSTEM32\COUNTRY.SYS
89:;<=>?
1234567890-=
!@#$%^&*()_ 
789-456 1230.
!"#$%&,-./012
t.exe
%WinDir%\SYSTEM32\COMMAND.COM
%File allocation table bad, drive %1
Invalid COMMAND.COM
!Press any key to continue . . .
Cannot execute %1
Error in EXE file
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp
arameter vaCOMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
OS=Windows_NT
PATH=C:\Perl\site\bin;C:\Perl\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WINDOW~1\v1.0\;c:\PROGRA~1\WIRESH~1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PSMODULEPATH=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
SYSTEMROOT=C:\Windows
WINDOWS_TRACING_FLAGS=3
WINDOWS_TRACING_LOGFILE=C:\BVTBin\Tests\installpackage\csilogfile.log
COMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
<title>File: Done.exe | Alfafile.net</title>
<link href='hXXp://fonts.googleapis.com/css?family=Open Sans:400,600,700&subset=cyrillic,cyrillic-ext,latin' rel='stylesheet' type='text/css'>
<link rel="stylesheet" href="/build/css/libs.out-000594a915.css" type="text/css"/>
<link rel="stylesheet" href="/build/css/master.out-808199fc1e.css" type="text/css"/>
<meta name="Keywords" content=""/>
<!--<base href="hXXp://alfafile.net/" />-->
<a href="/" id="logo" title="Alfafile.net"></a>
<li><a href="/support" id="a_menu_top_6">Support</a></li>
<li><a href="/language/pt" class="noicon">Portugu
<a href="#" class="button button__login"><span id="sp_login">Login</span></a>
<div class="login_popup">
<form action="/user/login/?url=/file/UkjZ" method="post">
<input type="email" required="required" name="email" placeholder="youremail@domain.com" class="b-form-input">
<label>Password</label>
<input type="password" required="required" name="password" placeholder="password" class="b-form-input">
<span><a href="/user/forgot_password">Forgot your password?</a></span>
<input type="submit" value="Login" class="button_submit">
<a href="hXXps://alfafile.net/file/UkjZ"><img src="/img/ssl.png" alt="SSL On"></a>
<strong id="st_file_name" title="Done.exe"><span class="ico_file"></span>Done.exe</strong>
<td><img src="/img/sep4.gif" alt="NO"></td>
<td><img src="/img/sep5.png" alt="YES"></td>
<td class="col1">Support for resuming downloads</td>
<td class="col1">Support for download accelerators</td>
2014-2015 Alfafile.net. All Rights Reseved.</div>
<!--script src="/js/jquery-1.10.2.min.js"></script>
<script src="/js/libs/formstyler/jquery.formstyler.js"></script>
<script src="/js/scripts.js"></script>
<script src="/js/fingerprint.js"></script-->
<script src="/build/js/libs.out-578a3fc543.js"></script>
<script src="/js/download.js"></script>
<script src="/build/js/scripts-856d836110.js"></script>
$(document).ready(function() {
$('input:checkbox:not(.nostyler)').styler();
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','//VVV.google-analytics.com/analytics.js','ga');
%Intermediate file error during pipe
Switches may be preset in the DIRCMD environment variable. Override
>Quits the COMMAND.COM program (command interpreter).
]Displays or sets a search path for executable files.
$B | (pipe)
%Displays the MS-DOS version.
LRecords comments (remarks) in a batch file or CONFIG.SYS.
key to continue...."
PATH=PROMPT=COMSPEC=DIRCMD=
.COM.EXE.BAT?VBAPWRHSvDANEDSG
%WinDir%\SYSTEM32
[]|<> =;"

ntvdm.exe_4016_rwx_00010000_00090000:

COMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp
89:;<=>?
D%WinDir%\SYSTEM32\HIMEM.SYS
Q001,437,%WinDir%\SYSTEM32\COUNTRY.SYS
S%WinDir%\SYSTEM32\COMMAND.COM
/P %WinDir%\SYSTEM32
/P %WinDir%\SYSTEM32
%WinDir%\SYSTEM32\COUNTRY.SYS
[]|<> =;"
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9B93.tmp
%WinDir%\SYSTEM32\COMMAND.COM
NTCMDPROMPTT
Unrecognized command in CONFIG.SYS
Insufficient memory for COUNTRY.SYS file
Incorrect order in CONFIG.SYS line $Error in CONFIG.SYS line $WARNING! Logical drives past Z: exist and will be ignored
1234567890-=
!@#$%^&*()_ 
789-456 1230.
!"#$%&,-./012
00030<0?0
30333<3?3
<0<3<<<?<
?0?3?<???
Windows NT MS-DOS subsystem Mouse Driver
/)()(00)(
/@%}-{.Nb#b
t.exe
!Press any key to continue . . .
%Intermediate file error during pipe
Switches may be preset in the DIRCMD environment variable. Override
>Quits the COMMAND.COM program (command interpreter).
]Displays or sets a search path for executable files.
$B | (pipe)
%Displays the MS-DOS version.
LRecords comments (remarks) in a batch file or CONFIG.SYS.
key to continue...."
PATH=PROMPT=COMSPEC=DIRCMD=
.COM.EXE.BAT?VBAPWRHSvDANEDSG
%WinDir%\SYSTEM32\DOSX
NT.EXE
C:\USERS\ADM\APPDATA\LOCAL\TEMP\WOWRR.EXE
nt.exe
DOSX.EXE

conhost.exe_4060:

.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641

ntvdm.exe_4016_rwx_000A0000_0002B000:

66666666
6666666
6666666666666666
6666666676666666
6666667076666666
66666666666
66666707666
66666666666666666666
66666666666707666666
6666666666666
89:;<=>?
'/7?-16:?
V M ware, Inc. VBE support 2.0
$o.o.oJo.o8o

ntvdm.exe_4016_rwx_000CB000_00011000:

COMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
OS=Windows_NT
PATH=C:\Perl\site\bin;C:\Perl\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WINDOW~1\v1.0\;c:\PROGRA~1\WIRESH~1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PSMODULEPATH=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
SYSTEMROOT=C:\Windows
WINDOWS_TRACING_FLAGS=3
WINDOWS_TRACING_LOGFILE=C:\BVTBin\Tests\installpackage\csilogfile.log
C:\Windows\system32\DOSX.EXE
C:\Windows\system32\mscdexnt.exe
C:\Windows\system32\redir
nt.exe
C:\LANMAN.DOS
C:\Windows\system32\dosx
C:\Windows\SYSTEM.INI
STEM.INI
SYSTEM.INI

ntvdm.exe_4016_rwx_000DC000_0000C000:

06/02/2011
000000000000
Keyboard
[MS_VM_CERT/SHA1/27d66596a61c48dd3dc7216fd715126e33f59ae7]

ntvdm.exe_4016_rwx_000E8000_00008000:

00030<0?0
30333<3?3
<0<3<<<?<
?0?3?<???
Windows NT MS-DOS subsystem Mouse Driver

ntvdm.exe_4016_rwx_000F0000_00010000:

:[MS_VM_CERT/SHA1/27d66596a61c48dd3dc7216fd715126e33f59ae7]
<%X8X
Operating System not found
Operating System not found, retrying boot now...
Operating System not found, retrying boot in
Windows XP Mode active
06/02/11
08:28:06
00/00/00
00:00:00
/8.BCPNV
1234567890-=

ntvdm.exe_4016_rwx_00100000_00010000:

C:\USERS\ADM\APPDATA\LOCAL\TEMP\WOWRR.EXE
WOWRR EXE
."/\[]:|<> =;,
c:\wina20.386
%WinDir%\SYSTEM32\COUNTRY.SYS
89:;<=>?
1234567890-=
!@#$%^&*()_ 
789-456 1230.
!"#$%&,-./012
t.exe
%WinDir%\SYSTEM32\COMMAND.COM
%File allocation table bad, drive %1
Invalid COMMAND.COM
!Press any key to continue . . .
Cannot execute %1
Error in EXE file
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp
arameter vaCOMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
OS=Windows_NT
PATH=C:\Perl\site\bin;C:\Perl\bin;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WINDOW~1\v1.0\;c:\PROGRA~1\WIRESH~1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PSMODULEPATH=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
SYSTEMROOT=C:\Windows
WINDOWS_TRACING_FLAGS=3
WINDOWS_TRACING_LOGFILE=C:\BVTBin\Tests\installpackage\csilogfile.log
COMSPEC=%WinDir%\SYSTEM32\COMMAND.COM
<title>File: Done.exe | Alfafile.net</title>
<link href='hXXp://fonts.googleapis.com/css?family=Open Sans:400,600,700&subset=cyrillic,cyrillic-ext,latin' rel='stylesheet' type='text/css'>
<link rel="stylesheet" href="/build/css/libs.out-000594a915.css" type="text/css"/>
<link rel="stylesheet" href="/build/css/master.out-808199fc1e.css" type="text/css"/>
<meta name="Keywords" content=""/>
<!--<base href="hXXp://alfafile.net/" />-->
<a href="/" id="logo" title="Alfafile.net"></a>
<li><a href="/support" id="a_menu_top_6">Support</a></li>
<li><a href="/language/pt" class="noicon">Portugu
<a href="#" class="button button__login"><span id="sp_login">Login</span></a>
<div class="login_popup">
<form action="/user/login/?url=/file/UkjZ" method="post">
<input type="email" required="required" name="email" placeholder="youremail@domain.com" class="b-form-input">
<label>Password</label>
<input type="password" required="required" name="password" placeholder="password" class="b-form-input">
<span><a href="/user/forgot_password">Forgot your password?</a></span>
<input type="submit" value="Login" class="button_submit">
<a href="hXXps://alfafile.net/file/UkjZ"><img src="/img/ssl.png" alt="SSL On"></a>
<strong id="st_file_name" title="Done.exe"><span class="ico_file"></span>Done.exe</strong>
<td><img src="/img/sep4.gif" alt="NO"></td>
<td><img src="/img/sep5.png" alt="YES"></td>
<td class="col1">Support for resuming downloads</td>
<td class="col1">Support for download accelerators</td>
2014-2015 Alfafile.net. All Rights Reseved.</div>
<!--script src="/js/jquery-1.10.2.min.js"></script>
<script src="/js/libs/formstyler/jquery.formstyler.js"></script>
<script src="/js/scripts.js"></script>
<script src="/js/fingerprint.js"></script-->
<script src="/build/js/libs.out-578a3fc543.js"></script>
<script src="/js/download.js"></script>
<script src="/build/js/scripts-856d836110.js"></script>
$(document).ready(function() {
$('input:checkbox:not(.nostyler)').styler();
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','//VVV.google-analytics.com/analytics.js','ga');
%Intermediate file error during pipe
Switches may be preset in the DIRCMD environment variable. Override
>Quits the COMMAND.COM program (command interpreter).
]Displays or sets a search path for executable files.
$B | (pipe)
%Displays the MS-DOS version.
LRecords comments (remarks) in a batch file or CONFIG.SYS.
key to continue...."
PATH=PROMPT=COMSPEC=DIRCMD=
.COM.EXE.BAT?VBAPWRHSvDANEDSG
%WinDir%\SYSTEM32
[]|<> =;"

fox.exe_4044:

.text
`.data
.rsrc
MSVBVM60.DLL
learn25 (arnel.c.decastro) Date Calculator Program
%Program Files% (x86)\Microsoft Visual Studio\VB98\VB6.OLB
user32.dll
shell32.dll
ShellExecuteA
EnumChildWindows
VBA6.DLL
hXXp://bit.ly/2kIq8xQ
hXXp://bit.ly/2kyNWJf
fox.exe

CodecFixDivx.exe_4012:

.text
`.rdata
@.data
.gfids
@.rsrc
@.reloc
B.idat
operator
operator ""
%S#[k
.text$mn
.text$x
.idata$5
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data
.data$r
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
KERNEL32.dll
USER32.dll
GetCPInfo
GetProcessHeap
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CodecFixDivx.exe
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='*' publicKeyToken='6595b64144ccf1df' language='*' />
4 4$4(4,4
;$;,;0;4;8;<;
= =$=(=,=0=4=
9 :$:(:,:
.rsrc
%D J|
D$8j.Xf
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
GetProcessWindowStation
openUrl
appCmd
appImageUrl
appSetupUrl
appTYUrl
HTTP/1.1
GET hXXp://
POST hXXp://
hXXps://
hXXp://
Fx
id[]=%d
application/x-www-form-urlencoded
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
IE.HTTP
FirefoxURL
Firefox
ChromeHTML
Chrome
HTTP\shell\open\command
RegOpenKeyTransactedW
CreateDialogIndirectParamW
CryptImportKey
CryptSetKeyParam
CryptDestroyKey
RegOpenKeyExW
RegCloseKey
RegEnumKeyW
RegOpenKeyExA
GetWindowsAccountDomainSid
ADVAPI32.dll
COMCTL32.dll
ole32.dll
WS2_32.dll
SHFileOperationW
ShellExecuteW
ShellExecuteExW
SHELL32.dll
SHLWAPI.dll
OLEAUT32.dll
GDI32.dll
WinHttpOpen
WinHttpConnect
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCloseHandle
WINHTTP.dll
VERSION.dll
zcÁ
.?AVHttpRequestContent@@
:::#222.111 )))
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
: :$:(:,:0:4:
6(606\6`6
mscoree.dll
ext-ms-win-ntuser-windowstation-l1-1-0
combase.dll
kernel32.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
USER32.DLL
%systemroot%\system32\msiexec.exe
"%s" /i "%s" /quiet %s
"%s" ,%s %s
B%s\%s
/Cookie: %s
.runas
%d.%d.%d.%d
diexplore.exe
firefox.exe
chrome.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
@Advapi32.dll
{8856F961-340A-11D0-A96B-00C04FD705A2}

CodecFixDivx.exe_4012_rwx_00510000_0005F000:

.text
`.rdata
@.data
.rsrc
@.reloc
%D J|
D$8j.Xf
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
operator
GetProcessWindowStation
openUrl
appCmd
appImageUrl
appSetupUrl
appTYUrl
HTTP/1.1
GET hXXp://
POST hXXp://
hXXps://
hXXp://
Fx
id[]=%d
application/x-www-form-urlencoded
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
IE.HTTP
FirefoxURL
Firefox
ChromeHTML
Chrome
HTTP\shell\open\command
RegOpenKeyTransactedW
GetProcessHeap
KERNEL32.dll
CreateDialogIndirectParamW
USER32.dll
CryptImportKey
CryptSetKeyParam
CryptDestroyKey
RegOpenKeyExW
RegCloseKey
RegEnumKeyW
RegOpenKeyExA
GetWindowsAccountDomainSid
ADVAPI32.dll
COMCTL32.dll
ole32.dll
WS2_32.dll
SHFileOperationW
ShellExecuteW
ShellExecuteExW
SHELL32.dll
SHLWAPI.dll
OLEAUT32.dll
GDI32.dll
WinHttpOpen
WinHttpConnect
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCloseHandle
WINHTTP.dll
VERSION.dll
GetCPInfo
zcÁ
.?AVHttpRequestContent@@
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CodecFixDivx.exe
:::#222.111 )))
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
: :$:(:,:0:4:
6(606\6`6
combase.dll
kernel32.dll
mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
USER32.DLL
%systemroot%\system32\msiexec.exe
"%s" /i "%s" /quiet %s
"%s" ,%s %s
S%s\%s
/Cookie: %s
.runas
%d.%d.%d.%d
diexplore.exe
firefox.exe
chrome.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
QAdvapi32.dll
{8856F961-340A-11D0-A96B-00C04FD705A2}

CodecFixDivx.exe_4012_rwx_00FC6000_000E3000:

.text
`.rdata
@.data
.rsrc
@.reloc
%D J|
D$8j.Xf
j.Yf;
_tcPVj@
.PjRW
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
operator
GetProcessWindowStation
openUrl
appCmd
appImageUrl
appSetupUrl
appTYUrl
HTTP/1.1
GET hXXp://
POST hXXp://
hXXps://
hXXp://
Fx
id[]=%d
application/x-www-form-urlencoded
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
IE.HTTP
FirefoxURL
Firefox
ChromeHTML
Chrome
HTTP\shell\open\command
RegOpenKeyTransactedW
GetProcessHeap
KERNEL32.dll
CreateDialogIndirectParamW
USER32.dll
CryptImportKey
CryptSetKeyParam
CryptDestroyKey
RegOpenKeyExW
RegCloseKey
RegEnumKeyW
RegOpenKeyExA
GetWindowsAccountDomainSid
ADVAPI32.dll
COMCTL32.dll
ole32.dll
WS2_32.dll
SHFileOperationW
ShellExecuteW
ShellExecuteExW
SHELL32.dll
SHLWAPI.dll
OLEAUT32.dll
GDI32.dll
WinHttpOpen
WinHttpConnect
WinHttpOpenRequest
WinHttpSetTimeouts
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCloseHandle
WINHTTP.dll
VERSION.dll
GetCPInfo
zcÁ
.?AVHttpRequestContent@@
:::#222.111 )))
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
: :$:(:,:0:4:
6(606\6`6
combase.dll
kernel32.dll
mscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
portuguese-brazilian
USER32.DLL
%systemroot%\system32\msiexec.exe
"%s" /i "%s" /quiet %s
"%s" ,%s %s
B%s\%s
/Cookie: %s
.runas
%d.%d.%d.%d
diexplore.exe
firefox.exe
chrome.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
@Advapi32.dll
{8856F961-340A-11D0-A96B-00C04FD705A2}


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:1084
    start.exe:3972
    soundbar.exe:3352
    cpa.exe:3568
    irsetup.exe:2404
    irsetup.exe:3436

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dll (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (50 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9B93.tmp (335 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\scs9BA3.tmp (269 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\lua5.1.dll (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.exe (50 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.exe (50 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\lua5.1.dll (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\lua5.1.dll (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe (50 bytes)
    C:\Windows\chromebrowser.exe (39122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG2.JPG (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\irsetup.dat (1209 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\dox.enc (26347 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_3\IRIMG1.JPG (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\irsetup.dat (143 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\IRIMG1.JPG (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_1\IRIMG2.JPG (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\IRIMG2.JPG (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\irsetup.dat (1209 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\Elow.enc (10720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\CUE.enc (11337 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\start.enc (43519 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\fox.enc (28 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\9Z68MLW7.txt (159 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wowrr.exe (4016 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\start.exe (69050 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\fox.exe (56 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\CodecFixDivx.exe (17280 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\IRIMG1.JPG (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_2\kube.enc (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar3FDF.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\setupfiles.txt (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\cpa.enc (14968 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 (471 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\soundbar.exe (3932903 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\46VRC840.txt (121 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LRMHZCNI.txt (329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB (471 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB (1278 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DCE3BDBF5BDD86E2AB5B471CB90709B4_9EDD577FDC96330CA9B09E84FD8389E3 (992 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab3FDE.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DCE3BDBF5BDD86E2AB5B471CB90709B4_9EDD577FDC96330CA9B09E84FD8389E3 (1640 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\RLOS3CDY.txt (70 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3Y8Q956L.txt (157 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\3SNVEHUW.txt (244 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\cpa.exe (28837 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619 (1290 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "chromebrowser" = "C:\Windows\chromebrowser.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Average: 5 (1 vote)

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now