Trojan.Win32.SwrortProxy_55da6106db

by malwarelabrobot on April 24th, 2016 in Malware Descriptions.

Trojan.Win32.Iconomon.FD, GenericEmailWorm.YR, TrojanSwrortProxy.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, EmailWorm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 55da6106db73acabd8921518822ba29a
SHA1: 62434c2c8dc3dc35c4e859566b9483c603d8ee8d
SHA256: 00b21a755700cc6906a886c81c83bf58f84afcab6931249041833e9a9f2eaf88
SSDeep: 98304:N3M 4gAay3q1uoW1Qm0oL9Mu8EoByN53ZZzU:hM Q38up6oJMuwByN5JZY
Size: 4147296 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-11-02 16:05:30
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

Behaviour Description
EmailWorm Worm can send e-mails.


Process activity

The Trojan creates the following process(es):

%original file name%.exe:2012
DriverPro.exe:1484
drvprosetup.exe:232
drvprosetup.tmp:1832
DPStartScan.exe:1996

The Trojan injects its code into the following process(es):

DriverPro.exe:312
DPTray.exe:1904

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:2012 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\drvprosetup.exe (454607 bytes)
%Documents and Settings%\%current user%\NTUSER.DAT.LOG (5208 bytes)
%Documents and Settings%\%current user%\NTUSER.DAT (3612 bytes)

The process DriverPro.exe:312 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\etilqs_jLDCvLgEjiD7ShN (1484853 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\etilqs_MpZWKYVP4aw52Mg (1484745 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers32.db-journal (8674 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Scan.ini (227 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Snapshot.ini (1 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\PCInfo.ini (151 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\current_5_32_cxw.7z (15021 bytes)
%WinDir%\setupapi.log (3760 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\DevicesPlus.ini (3 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers.db (154783 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers32.db (12460873 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Devices.ini (224 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\etilqs_cu612yBGA7qsgvd (2177340 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\program.log (2355 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Application Data\Driver Pro\current_5_32_cxw.7z (0 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers32.db-journal (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\DriverPro.madExcept (0 bytes)

The process DriverPro.exe:1484 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Driver Pro\HomePage.url (121 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\program.log (506 bytes)

The Trojan deletes the following file(s):

%Program Files%\Driver Pro\HomePage.url (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\DriverPro.madExcept (0 bytes)

The process drvprosetup.exe:232 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\is-IHCAK.tmp\drvprosetup.tmp (7386 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\is-IHCAK.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-IHCAK.tmp\drvprosetup.tmp (0 bytes)

The process drvprosetup.tmp:1832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Driver Pro\is-EKFN1.tmp (4 bytes)
%Program Files%\Driver Pro\is-6PIV0.tmp (13 bytes)
%Program Files%\Driver Pro\is-VHBVB.tmp (6841 bytes)
%Documents and Settings%\%current user%\Desktop\Driver Pro.lnk (701 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Uninstall Driver Pro.lnk (734 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Help.lnk (713 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\_isetup\_shfoldr.dll (23 bytes)
%Program Files%\Driver Pro\is-5TF5P.tmp (9605 bytes)
%Program Files%\Driver Pro\unins000.msg (646 bytes)
%Program Files%\Driver Pro\is-K8K84.tmp (4185 bytes)
%Program Files%\Driver Pro\unins000.dat (10580 bytes)
%Program Files%\Driver Pro\is-COEU5.tmp (1425 bytes)
%Program Files%\Driver Pro\is-7KEB1.tmp (14022 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro.lnk (713 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro on the Web.lnk (708 bytes)
%Program Files%\Driver Pro\is-14QTC.tmp (547 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\DrvProHelper.dll (7971 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-E206L.tmp (61 bytes)
%Program Files%\Driver Pro\is-GO5M7.tmp (26 bytes)
%Program Files%\Driver Pro\is-KLAVF.tmp (7971 bytes)
%Program Files%\Driver Pro\is-C3PED.tmp (31745 bytes)
%Program Files%\Driver Pro\is-JPJNV.tmp (35505 bytes)
%Program Files%\Driver Pro\is-3MTUP.tmp (54 bytes)
%Program Files%\Driver Pro\is-8B5PP.tmp (56 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\_isetup\_shfoldr.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\_isetup (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\DrvProHelper.dll (0 bytes)

Registry activity

The process %original file name%.exe:2012 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "01 BD 8C 3F 2B 41 7F EB 98 80 30 D8 4F AC 0C A0"

[HKCU\Software\Driver Pro]
"setupname" = "c:\%original file name%.exe"

The process DriverPro.exe:312 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Driver Pro]
"s_Enable" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Driver Pro]
"UpdateWindowShown" = "0"
"InstallStat" = "0"
"BackupPath" = "%Documents and Settings%\%current user%\My Documents\Driver Pro\Backup\"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"

[HKCU\Software\Driver Pro]
"s_SmartScan" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Driver Pro]
"InstallationDate" = "04-23-2016"
"ShowAlertMessages" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCU\Software\Driver Pro]
"s_SmartMode" = "0"
"ShowUpdateWindow" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Driver Pro]
"QuerryDate" = "37 7D ED 82 68 BE E4 40"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Driver Pro]
"TrayNotification" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Driver Pro]
"s_Time" = "58 9A 46 7E 68 BE E4 40"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Driver Pro]
"LastScan" = "87 B7 E1 82 68 BE E4 40"
"TotalDrivers" = "65"
"DownloadPath" = "%Documents and Settings%\%current user%\My Documents\Driver Pro\Drivers\"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Templates" = "%Documents and Settings%\%current user%\Templates"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Driver Pro]
"ShowRebootMessage" = "1"
"LastUpdate" = "58 9A 46 7E 68 BE E4 40"
"ForceUpdate" = "0"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Driver Pro]
"ProxyAddress" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Driver Pro]
"OutdatedDrivers" = "0"
"nDownloads" = "3"
"LastDatabaseCheck" = "58 9A 46 7E 68 BE E4 40"
"s_SmartDate" = "58 9A 46 7E 48 BE E4 40"
"DatabaseDate" = "58 9A 46 7E 68 BE E4 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Driver Pro]
"ShowSRPMessage" = "1"
"ScanExecuted" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Driver Pro]
"s_SmartExec" = "0"
"StartWithWindows" = "0"
"s_Mode" = "0"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "37 29 E3 26 35 15 8B 64 01 9D 3C 6D 19 4E C0 18"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Driver Pro]
"AppStart" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKCU\Software\Driver Pro]
"ProxyPassword" = ""
"ProxyPort" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"

[HKCU\Software\Driver Pro]
"UseProxy" = "0"
"ProxyLogin" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process DriverPro.exe:1484 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "31 58 8A BB 4C 09 E5 BC 36 69 EF 63 8E 74 97 CB"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Templates" = "%Documents and Settings%\%current user%\Templates"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
"Personal" = "%Documents and Settings%\%current user%\My Documents"

The process drvprosetup.exe:232 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EC 34 3D A4 C5 1A 66 C9 8C 4B 86 7D B2 AD 96 16"

The process drvprosetup.tmp:1832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"DisplayVersion" = "3.2.0.2"
"NoRepair" = "1"
"Inno Setup: Language" = "en"

[HKCU\Software\Driver Pro]
"ia" = "%Program Files%\Driver Pro\SafeCheckout.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"MajorVersion" = "3"
"Inno Setup: Deselected Tasks" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"URLUpdateInfo" = "http://www.pcutilitiespro.com"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCU\Software\Driver Pro]
"Ir" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Inno Setup: Icon Group" = "Driver Pro"
"Inno Setup: Setup Version" = "5.5.3 (u)"
"Inno Setup: User" = "%CurrentUserName%"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"UninstallString" = "%Program Files%\Driver Pro\unins000.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"DisplayName" = "Driver Pro v3.2.0.2"
"Inno Setup: App Path" = "%Program Files%\Driver Pro"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

[HKCU\Software\Driver Pro]
"SessionID" = "1FBE27EB-6A41-4CC2-89241E1B828D9E10"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"InstallLocation" = "%Program Files%\Driver Pro\"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKCU\Software\Driver Pro]
"CBM" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"URLInfoAbout" = "http://www.pcutilitiespro.com"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKCU\Software\Driver Pro]
"Language" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"HelpLink" = "http://www.pcutilitiespro.com"
"InstallDate" = "20160423"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Publisher" = "PC Utilities Software Limited"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B4 AD 20 58 65 7B 25 05 44 1D 68 A0 56 2A E8 A3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Inno Setup: Selected Tasks" = "desktopicon"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"QuietUninstallString" = "%Program Files%\Driver Pro\unins000.exe /SILENT"
"NoModify" = "1"
"MinorVersion" = "2"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Driver Pro" = "%Program Files%\Driver Pro\DPLauncher.exe"

The process DPTray.exe:1904 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "92 4A 15 79 12 20 50 3D D0 C2 73 8C 60 17 F3 FD"

[HKCU\Software\Driver Pro]
"s_Enable" = "0"
"s_Exec" = "0"
"s_SmartMode" = "0"
"s_SmartScan" = "1"
"s_SmartDate" = "C0 DC ED 7D 48 BE E4 40"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Driver Pro]
"TrayNotification" = "1"
"StartWithWindows" = "0"
"s_Mode" = "0"

The process DPStartScan.exe:1996 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Driver Pro]
"SupportURL" = "http://support.pcutilitiespro.com/"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Driver Pro]
"MachineGuid" = "7CF7C041-4C97-0825-20E8-DA4A22D072AA"
"UninstallURL" = "https://safecart.com/pcutilitiespro/.dp-xsell-special/purchase?sid=121000884-KR-003"
"DelayedStart" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Driver Pro]
"UseAds" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Driver Pro]
"QuerryDate" = "1A 2A 14 7E 68 BE E4 40"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKCU\Software\Driver Pro]
"OS" = "102"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Driver Pro]
"BuyNowURL" = "http://pcup25.pcutilitiespro.revenuewire.net/driverpro/xsell?121000884-KR-003_7CF7C041-4C97-0825-20E8-DA4A22D072AA"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Driver Pro]
"Querry" = "http://bi.secure-download.net/t/dp?sid=121000884-KR-003&dt=%dt%&gid=%GID%&tz=%tz%&ln=%ln%&lc=%lc%&bis=%bis%&bief=%bief%&biefx=%biefx%&bif=%bif%&os=%os%&f=3539780431"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKCU\Software\Driver Pro]
"sc" = "http://pcup25.pcutilitiespro.revenuewire.net/driverpro/xsell?121000884-KR-003_7CF7C041-4C97-0825-20E8-DA4A22D072AA"

"homepageurl" = "http://www.pcutilitiespro.com/"
"AppStart" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "77 EE 83 20 43 16 97 83 79 07 67 A7 A0 DA 81 2A"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Driver Pro]
"DriverPro.exe" = "Driver Pro"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Driver Pro]
"InstallDate" = "BE 7F 06 7E 68 BE E4 40"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

Dropped PE files

MD5 File path
41aee5653b2a810a04d5e24aac3d1f83 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\drvprosetup.exe
04ad4b80880b32c94be8d0886482c774 c:\Program Files\Driver Pro\7z.dll
7e3f6349ad1ed16082386102976e5a0a c:\Program Files\Driver Pro\DPStartScan.exe
9d1f25b9934376a04565c131a03675ae c:\Program Files\Driver Pro\DPTray.exe
01465648fff147a82247d7da8d4d2809 c:\Program Files\Driver Pro\DriverPro.exe
e0964c6bccc62987a6627a1c97eac16c c:\Program Files\Driver Pro\DrvProHelper.dll
e768faf7a1cba9637cbfd818b2048cd5 c:\Program Files\Driver Pro\SafeCheckout.exe
d8aec01ff14e3e7ad43a4b71e30482e4 c:\Program Files\Driver Pro\sqlite3.dll
7dfbdb3c046020639f67f075cde12541 c:\Program Files\Driver Pro\unins000.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name: PC Utilities Software Limited
Product Name: Driver Pro v3.2
Product Version: 3.2.0.2
Legal Copyright: PC Utilities Software Limited
Legal Trademarks:
Original Filename: Driver Pro
Internal Name: Driver Pro
File Version: 3.2.0.2
File Description: Keep your PC drivers up to date
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 83149 83456 4.55483 153c25a894558c86b486e20495de16f9
.rdata 90112 20754 20992 3.39472 5f38eb7c519337a5f17c3010bfc0e341
.data 114688 13444 5632 2.15756 2cef89c59f35f4fcafe95749186c0933
.rsrc 131072 4013316 4013568 5.46669 dcbbf9056648215577ba9569f353882f
.reloc 4145152 17424 17920 1.73339 f70fe10f52920658854ebfc48b5a6ee5

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://idriverpro.com/inst?hid=8151a8f9650e97debee6a573878cc0181172fc7f&sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&tr=121000884-KR-003&a=NA&adm=1&os=5.1&x64=0&sil=1&st=201511022&e=200 104.28.20.75
hxxp://idriverpro.com/inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&e=210 104.28.20.75
hxxp://idriverpro.com/inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&du=6187&e=400 104.28.20.75
hxxp://bi.secure-download.net/t/dp?sid=121000884-KR-003&dt=1461392529&gid=7CF7C041-4C97-0825-20E8-DA4A22D072AA&tz=2&ln=1&lc=0&bis=0&bief=0&biefx=0&bif=0&os=102&f=3539780431 107.6.170.117
hxxp://service.smartpcupdate.com/rpc/sendinstall?partner=PCUtilitiesPro&build=3.2 176.9.2.105
hxxp://service.smartpcupdate.com/rpc/getdatabasecxw?arch=32&os=5 176.9.2.105
hxxp://d2.smartpcupdate.com/dbs/current_5_32_cxw.7z 173.192.91.180
hxxp://d2.smartpcupdate.com/rpc/sendsnapshot 173.192.91.180
hxxp://bi.secure-download.net/t/dp?sid=121000884-KR-003&dt=1461392580&gid=7CF7C041-4C97-0825-20E8-DA4A22D072AA&tz=2&ln=1&lc=0&bis=1&bief=0&biefx=0&bif=0&os=102&f=3539780431 107.6.170.117
hxxp://Idriverpro.com/inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&du=6187&e=400
hxxp://Idriverpro.com/inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&e=210
hxxp://Idriverpro.com/inst?hid=8151a8f9650e97debee6a573878cc0181172fc7f&sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&tr=121000884-KR-003&a=NA&adm=1&os=5.1&x64=0&sil=1&st=201511022&e=200


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /t/dp?sid=121000884-KR-003&dt=1461392580&gid=7CF7C041-4C97-0825-20E8-DA4A22D072AA&tz=2&ln=1&lc=0&bis=1&bief=0&biefx=0&bif=0&os=102&f=3539780431 HTTP/1.1
Content-Type: text/html; charset=ISO-8859-1
Host: bi.secure-download.net
Accept: text/html, */*
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Sat, 23 Apr 2016 03:20:44 GMT
Content-Type: application/octet-stream
Content-Length: 0
Connection: keep-alive
content-type: text/html


GET /rpc/sendinstall?partner=PCUtilitiesPro&build=3.2 HTTP/1.1
Host: service.smartpcupdate.com
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Sat, 23 Apr 2016 03:19:56 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.5.26
12..{"ok":1,"error":0}..0..


GET /inst?hid=8151a8f9650e97debee6a573878cc0181172fc7f&sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&tr=121000884-KR-003&a=NA&adm=1&os=5.1&x64=0&sil=1&st=201511022&e=200 HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: Idriverpro.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Sat, 23 Apr 2016 03:19:48 GMT
Content-Type: text/plain
Content-Length: 0
Connection: keep-alive
Set-Cookie: __cfduid=d739adedaafba1a93b6d643be56e535091461381588; expires=Sun, 23-Apr-17 03:19:48 GMT; path=/; domain=.idriverpro.com; HttpOnly
Server: cloudflare-nginx
CF-RAY: 297e2d115bbd2afd-WAW
HTTP/1.1 200 OK..Date: Sat, 23 Apr 2016 03:19:48 GMT..Content-Type: te
xt/plain..Content-Length: 0..Connection: keep-alive..Set-Cookie: __cfd
uid=d739adedaafba1a93b6d643be56e535091461381588; expires=Sun, 23-Apr-1
7 03:19:48 GMT; path=/; domain=.idriverpro.com; HttpOnly..Server: clou
dflare-nginx..CF-RAY: 297e2d115bbd2afd-WAW..
....



GET /inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&e=210 HTTP/1.1

Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: Idriverpro.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Sat, 23 Apr 2016 03:19:49 GMT
Content-Type: text/plain
Content-Length: 0
Connection: keep-alive
Set-Cookie: __cfduid=ddb4aca89d5d0107fd6458ee00104ea8e1461381589; expires=Sun, 23-Apr-17 03:19:49 GMT; path=/; domain=.idriverpro.com; HttpOnly
Server: cloudflare-nginx
CF-RAY: 297e2d139bd22afd-WAW
HTTP/1.1 200 OK..Date: Sat, 23 Apr 2016 03:19:49 GMT..Content-Type: te
xt/plain..Content-Length: 0..Connection: keep-alive..Set-Cookie: __cfd
uid=ddb4aca89d5d0107fd6458ee00104ea8e1461381589; expires=Sun, 23-Apr-1
7 03:19:49 GMT; path=/; domain=.idriverpro.com; HttpOnly..Server: clou
dflare-nginx..CF-RAY: 297e2d139bd22afd-WAW..
....



GET /inst?sid=1FBE27EB-6A41-4CC2-89241E1B828D9E10&st=0&du=6187&e=400 HTTP/1.1

Content-Type: application/x-www-form-urlencoded
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: Idriverpro.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Sat, 23 Apr 2016 03:19:53 GMT
Content-Type: text/plain
Content-Length: 0
Connection: keep-alive
Set-Cookie: __cfduid=dcbc24854dfcbceaed0560fcc16ea1edf1461381592; expires=Sun, 23-Apr-17 03:19:52 GMT; path=/; domain=.idriverpro.com; HttpOnly
Server: cloudflare-nginx
CF-RAY: 297e2d2bbc872afd-WAW
HTTP/1.1 200 OK..Date: Sat, 23 Apr 2016 03:19:53 GMT..Content-Type: te
xt/plain..Content-Length: 0..Connection: keep-alive..Set-Cookie: __cfd
uid=dcbc24854dfcbceaed0560fcc16ea1edf1461381592; expires=Sun, 23-Apr-1
7 03:19:52 GMT; path=/; domain=.idriverpro.com; HttpOnly..Server: clou
dflare-nginx..CF-RAY: 297e2d2bbc872afd-WAW..


GET /t/dp?sid=121000884-KR-003&dt=1461392529&gid=7CF7C041-4C97-0825-20E8-DA4A22D072AA&tz=2&ln=1&lc=0&bis=0&bief=0&biefx=0&bif=0&os=102&f=3539780431 HTTP/1.1
Host: bi.secure-download.net
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.6.0
Date: Sat, 23 Apr 2016 03:19:53 GMT
Content-Type: application/octet-stream
Content-Length: 0
Connection: keep-alive
content-type: text/html


GET /rpc/getdatabasecxw?arch=32&os=5 HTTP/1.1
Content-Type: text/html; charset=ISO-8859-1
Host: service.smartpcupdate.com
Accept: text/html, */*
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Sat, 23 Apr 2016 03:19:57 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.5.26
81..{"ok":1,"error":0,"url":"http:\/\/d2.smartpcupdate.com\/dbs\/curre
nt_5_32_cxw.7z","file_hash":"ff612b999f2c17b46fcb948e01ad5c2d"}..0..


POST /rpc/sendsnapshot HTTP/1.0
Connection: keep-alive
Content-Type: multipart/form-data; boundary=--------042316062300393
Content-Length: 1846
Host: d2.smartpcupdate.com
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)

----------042316062300393
Content-Disposition: form-data; name="snapshot_file"; filename="Snapshot.ini"
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: binary

[Settings]
Version=1
Program=Driver Pro
Base=2016-01-18
Generated=04-23-2016

[1]
request_type=unknown
version_user=12.4.0.6
vendor_user=MICROSOFT
date_user=2009-11-17
os_id=5_32
title=PS/2 Compatible Mouse
group=Other
hardid=ACPI\PNP0F13,*PNP0F13
created=program

[2]
request_type=unknown
version_user=12.4.0.6
vendor_user=VMWARE
date_user=2009-11-17
os_id=5_32
title=VMware Pointing Device
group=Mouse
hardid=ACPI\PNP0F13,*PNP0F13
created=program

[3]
request_type=unknown
version_user=1.2.0.2
vendor_user=VMWARE
date_user=1999-11-14
os_id=5_32
title=VMware SCSI Controller
group=Other
hardid=PCI\VEN_104B&DEV_1040&SUBSYS_1040104B&REV_01,PCI\VEN_104B&DEV_1040&SUBSYS_1040104B,PCI\VEN_104B&DEV_1040&CC_010000,PCI\VEN_104B&DEV_1040&CC_0100
created=program

[4]
request_type=unknown
version_user=11.8.11.0
vendor_user=VMWARE
date_user=2011-07-01
os_id=5_32
title=VMware SVGA II
group=Display
hardid=PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00,PCI\VEN_15AD&DEV_0405&SUBSY
HTTP/1.1 200 OK
Server: nginx/1.5.5
Date: Sat, 23 Apr 2016 03:20:44 GMT
Content-Type: text/html
Connection: close
X-Powered-By: PHP/5.5.20
{"ok":1,"error":0,"date":"2016-04-23 04:20:44","inserted":7}..


HEAD /dbs/current_5_32_cxw.7z HTTP/1.1
Content-Type: text/html; charset=ISO-8859-1
Host: d2.smartpcupdate.com
Accept: text/html, */*
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.5.5
Date: Sat, 23 Apr 2016 03:19:57 GMT
Content-Type: application/x-7z-compressed
Content-Length: 2164030
Last-Modified: Tue, 19 Jan 2016 08:33:03 GMT
Connection: keep-alive
ETag: "569df4bf-21053e"
Accept-Ranges: bytes
....



GET /dbs/current_5_32_cxw.7z HTTP/1.1

Content-Type: text/html; charset=ISO-8859-1
Host: d2.smartpcupdate.com
Accept: text/html, */*
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)


HTTP/1.1 200 OK
Server: nginx/1.5.5
Date: Sat, 23 Apr 2016 03:19:57 GMT
Content-Type: application/x-7z-compressed
Content-Length: 2164030
Last-Modified: Tue, 19 Jan 2016 08:33:03 GMT
Connection: keep-alive
ETag: "569df4bf-21053e"
Accept-Ranges: bytes
7z..'....t....!.....Z.........a..).E.`...&d..&.1...!..m....9......<
..Q.6..;.E..:.._g...hS5..$..../*[email protected]{...J...U.xv."Z.Q0
..t..} .7...C......Y.....}t.{/... 2d..$.].....c.....q<.%..0U{..z...
...S...0...A'.k7Zy.Z.kl.=.]w..E_v.u.X..g.w..M.{..E...L.t.8..r/..tsF2P.
...9..O.J.i...........J........%.....e.... T>...Z.~...E........g3..
....M.Y.f._E....g.sR...?...{}Kj....w..U..{..YH_......FG.N..C.&.?K.A x6
...W.....p..T.3.kB.-X>...E_8Q&ES3.{.d......o.,...rm..V;.....?...g.
.w....<u.[UZ......E.%v.8l(.>J....VV..w.mV.W.".RvGS.P.Ah"Q.z..kx.
[email protected]^...p....b.....D..&...........]..........
.p"X..Y....^)*........Z7p5nk.t.T.7..)\L.#...kJ...H./.^=.....]......6..
V..X..^...K)c.....3..;.i..P...S.t-;..d.....Oyy\..tjr......n.7.~..c...6
[email protected].........?........0.f.,!....D.......
..-.0......F......_.a....n..1...1.pd!|.w...{V\t..........7 ..D.W.%....
.....1..Z..Sd........Gp.8..-]e...,.~..L`....h&..bwE....&t~W..B".?!8^.j
.....OX...E.....9.a..$..B...GF......9=.#0MO,Maq.z1~..........d...*A...
Qj.Uv.k.,..x......./%....9..o;.9q....6C...>fG.=....u..ABQ...X....h~
...9....-....QZi..Y.HU|...X..$'.a..Z/.k8....Y.H.. B..... .C...8..2....
.l.h.....o\.....w...:.b...*..y..23..VX..6.>......j..a..8..6.....<
;nDD.<( '..v....K&.C..YkJD.........N.J......'...=.4.3.........toE/!
..Axl~.....B..Eg*..u..z..j.}.!.....P..%,|..~Y..j....H.3`........\.(.:z
d1.....t.....i..dY..........Z*8KHx.en....5..*....(..<..dm .z"%..,..
...."..A..M.....V.'..T....!..K.....9......a.i]>.7...$jtp^H...uG

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

DPTray.exe_1904:

.text
`.itext
`.data
.idata
.didata
.rdata
@.reloc
B.rsrc
biClrImportant
tagMSG
Windows
HKEY
etNoMonitorSupportException
TArray<System.Byte>
ENotSupportedException
ENotSupportedException$qA
ENoMonitorSupportException
ENoMonitorSupportException@
TArray<SysUtils.TLangRec>
TArray<System.Char>
csshiftjis
windows-936
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
windows-874
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
TArray<SysUtils.TUnitHashEntry>
TWMKey
KeyData
grfLocksSupported
Operator
EVariantBadIndexError
EVariantBadIndexError0
ssShift
htKeyword
EInvalidOperation
TList.TDirection
AOperator
TThread.TSynchronizeRecord
TOperation
Operation
FOnExecute
OnExecute
TArray<System.string>
TArray<System.TObject>
TList.Sort$594$0$Intf@
TList.Sort$594$ActRec
TList.Sort$594$ActRec(
Uh.KD
$TComponent.FindComponent$1217$0$Intf@
$TComponent.FindComponent$1217$ActRec
DeleteKey
TRegKeyInfo
NumSubKeys
MaxSubKeyLen
FCurrentKey
FRootKey
FCloseRootKey
CloseKey
CreateKey
GetKeyInfo
GetKeyNames
HasSubKeys
KeyExists
LoadKey
MoveKey
OpenKey
OpenKeyReadOnly
ReplaceKey
RestoreKey
SaveKey
UnLoadKey
CurrentKey\
LastErrorMsg
RootKey\
RootKeyName
EInvalidGraphicOperation
EInvalidGraphicOperationH^E
SupportsPartialTransparency
SupportsClipboardFormat
Monochrome,
IsShortCut
FHelpKeyword
HelpKeyword|'C
igoParentPassthrough
FAlwaysShowDragImages
AlwaysShowDragImages
toFlickFallbackKeys
'TCustomGestureEngine.TGestureEngineFlag
(TCustomGestureEngine.TGestureEngineFlags
Supported
TKeyEvent
TKeyPressEvent
HelpKeyword\'C
FOnKeyDown
FOnKeyPress
FOnKeyUp
IsHintMsg
FNativeWheelSupport
FWheelSupportMessage
Uh.uG
thHeaderItemLeftPressed
tsArrowBtnLeftPressed
ttbThumbLeftPressed
lrMonoChrome
FAutoHotkeys
RethinkHotkeys
AutoHotkeys`II
AutoHotkeys
HelpKeyword
UnderstandsKeyword
poPortrait
APort
Port
OnKeyDown
OnKeyPress|
OnKeyUpX
FProportional
Proportional
ssHotTrack
TWindowState
poProportional
fsShowing
FWindowState
FKeyPreview
WantChildKey
KeyPreview
WindowState
KeyPreview,
FBiDiKeyboard
FNonBiDiKeyboard
FEnumAllWindowsOnActivateHint
FOnActionExecute
Keyword
EnumAllWindowsOnActivateHint\
BiDiKeyboard\
NonBiDiKeyboard
OnActionExecute<
fKeyword
AMsg
CheckIPVersionSupport
VPort
WSGetServByPort
APortNumber
AddServByPortToList
TIdSocketListWindows4
TIdSocketListWindows
IdStackWindows
TIdStackWindowsg
ReceiveMsg
WSTranslateSocketErrorMsg
SupportsIPv6
TIdStackWindows
EIdIPVersionUnsupported@
EIdIPVersionUnsupported
FSourcePort
FDestPort
SourcePort
DestPort
Generics.Defaults
Generics.Collections
UrlMon
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
oleaut32.dll
advapi32.dll
RegOpenKeyExW
RegCloseKey
user32.dll
kernel32.dll
UnhookWindowsHookEx
SetWindowsHookExW
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MapVirtualKeyW
LoadKeyboardLayoutW
GetKeyboardState
GetKeyboardLayoutNameW
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextW
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
msimg32.dll
gdi32.dll
SetViewportOrgEx
version.dll
GetCPInfoExW
GetCPInfo
RegUnLoadKeyW
RegSaveKeyW
RegRestoreKeyW
RegReplaceKeyW
RegQueryInfoKeyW
RegLoadKeyW
RegFlushKey
RegEnumKeyExW
RegDeleteKeyW
RegCreateKeyExW
SHFolder.dll
ole32.dll
comctl32.dll
winspool.drv
shell32.dll
ShellExecuteW
windowscodecs.dll
uxtheme.dll
DWMAPI.DLL
1$1$0,0004080
;%;<;^;{;
;*;.;2;6;:;
7-7L7}7
7 7$7(7,7074787
9"9&9*9.9>9
9”9C9p9
,0004080<0@0
7%7 74787
363U3c3q3
11D1^1y1
?!?%?)?-?1?
7"7&7*7.72767:7>7
8 9Ÿ9
2&2U2f2
6 6$656_6
? ?(?0?8?
8 8$8(8,8084888<8@8`8~8
< <%<5<:<@<
7 7$7(7,7074787<7
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
@000///1111*$&
Paint.NET v3.5.100
paint.net 4.0;
KWindows
CGenerics.Defaults
%sTray
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
(%s found NN outdated drivers on your PC.
-%s detected a new device attached to your PC.
<assemblyIdentity version="1.0.0.0"
name="SmartDriverUpdater.exe"
<requestedExecutionLevel
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
PSAPI.dll
NTDLL.DLL
%s-%s
%s[%d]
%s_%d
.Owner
\\?\UNC\
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
%s (*.%s)|*.%1:s
%s (%s)|%1:s|
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
crSQLWait
%s (%s)
imm32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
hXXp://VVV.pcutilitiespro.com
HomePageURL
AfterInstallURL
AfterInstallURLHidden
SupportURL
UninstallURL
BuyNowURL
AdsDownloadURL
AdsBuyNowURL
AdsDownloadURL2
AdsBuyNowURL2
hXXps://safecart.com/pcutilitiespro/.driverpro
hXXp://support.pcutilitiespro.com
hXXp://dejebel.pcutilitiespro.revenuewire.net/optimizerpro/xsell
hXXp://filecdn.avanquest.com/rw/xsell/pcutilitiespro/dejebel/OptimizerPro.exe
*.status
%s detected a new device attached to your PC.
English.ini
French.ini
German.ini
Spanish.ini
Italian.ini
Portuguese.ini
Danish.ini
Dutch.ini
Swedish.ini
Polish.ini
Russian.ini
Brazilian.ini
Finnish.ini
Norwegian.ini
Japanese.ini
Chinese.ini
Czech.ini
Arabic.ini
StartWithWindows
s_Exec
D:\Projects\Components XE\Indy\Lib\System\IdGlobal.pas
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
csShiftJIS
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
WS2_32.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
MSWSOCK.DLL
WSARecvMsg
WSASendMsg
Wship6.dll
Fwpuclnt.dll
IdnDL.dll
Normaliz.dll
iphlpapi.dll
0.0.0.0
127.0.0.1
D:\Projects\Components XE\Indy\Lib\System\IdStack.pas
HTTP-EQUIV
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
*<>#%"{}|\^[]`
Backup\*.*
Drivers\*.*
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Portable Network Graphics
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
optimizerpro.exe
Optimizer Pro\OptimizerPro.exe
Kernel32.dll
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA)OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.oThe "Portable Network Graphics" could not be created because invalid image type parameters have being provided.-Error on call to Winsock2 library function %s&Error on loading Winsock2 library (%s)
Socket Error # %d
Operation would block.yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it againnThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.]The program tried to add a existent critical chunk to the current image which is not allowed.IIt's not allowed to add a new chunk because the current image is invalid.
All Clipboard does not support Icons Operation not supported on selected printer.There is no default printer currently selected/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)
Enhanced Metafiles Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex
Invalid image!Cannot change the size of an iconÊnnot change the size of a WIC Image$Unknown picture file extension (.%s)
Unsupported clipboard format
Invalid Timeout value: %s
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid time
No help found for context %d
No help found for %s
Thread creation error: %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread2Cannot call Start on a running or suspended thread;Cannot call CheckTerminated on an externally created thread9Cannot call SetReturnValue on an externally create thread'Parameter %s cannot be a negative value*Input buffer exceeded for %s = %d, %s = %d
The specified path is too long The specified path was not found The path format is not supported The specified file was not found$No help viewer that supports filters2Length of Strings and Objects arrays must be equal
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream)%s has not been registered as a COM class
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid destination array"Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
External exception %x
Interface not supported
Object lock not owned(Monitor support function not initialized
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s,Custom variant type (%s%.4x) is out of range/Custom variant type (%s%.4x) already used by %s*Custom variant type (%s%.4x) is not usable2Too many custom variant types have been registered5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Write$Error creating variant or safe array('%s' is not a valid floating point value '%d.%d' is not a valid timestamp
I/O error %d
Integer overflow Invalid floating point operation
3.1.0.5
DPTray.exe

DriverPro.exe_312:

.text
`.itext
`.data
.idata
.didata
.edata
@.tls
.rdata
@.reloc
B.rsrc
biClrImportant
tagMSG
Windows
HKEY
TWMKey
KeyData
etNoMonitorSupportException
TArray<System.Byte>
ENotSupportedException
ENotSupportedException(
ENoMonitorSupportException
ENoMonitorSupportExceptionD
TArray<SysUtils.TLangRec>
TArray<System.Char>
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
TArray<SysUtils.TUnitHashEntry>
grfLocksSupported
tdPortNameOffset
Operator
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
TList.TDirection
AOperator
TThread.TSynchronizeRecord
TOperation
Operation
FOnExecute
OnExecute
TArray<System.string>
TArray<System.TObject>
TList.Sort$594$0$Intfh
TList.Sort$594$ActRec
TList.Sort$594$ActRecp
$TComponent.FindComponent$1217$0$Intfh
$TComponent.FindComponent$1217$ActRec
$TComponent.FindComponent$1217$ActRec<
Generics.Collections
TRegKeyInfo
NumSubKeys
MaxSubKeyLen
FCurrentKey
FRootKey
FCloseRootKey
CloseKey
CreateKey
DeleteKey
GetKeyInfo
GetKeyNames
HasSubKeys
KeyExists
LoadKey
MoveKey
OpenKey
OpenKeyReadOnly
ReplaceKey
RestoreKey
SaveKey
UnLoadKey
CurrentKey\
LastErrorMsg
RootKey\
RootKeyName
EInvalidGraphicOperation
SupportsPartialTransparency
SupportsClipboardFormat
MonochromeT
IsShortCut
FHelpKeyword
HelpKeyword
igoParentPassthrough
FAlwaysShowDragImages
AlwaysShowDragImages
toFlickFallbackKeys
'TCustomGestureEngine.TGestureEngineFlag
(TCustomGestureEngine.TGestureEngineFlags
Supported
TKeyEvent
TKeyPressEvent
HelpKeywordt$C
FOnKeyDown
FOnKeyPress
FOnKeyUp
IsHintMsg
FNativeWheelSupport
FWheelSupportMessage
Uh.eG
thHeaderItemLeftPressed
tsArrowBtnLeftPressed
ttbThumbLeftPressed
lrMonoChrome
FAutoHotkeys
RethinkHotkeys
AutoHotkeys
AutoHotkeys("I
UnderstandsKeyword
FPasswordChar
PasswordChar
OnKeyDown
OnKeyPress|
OnKeyUpX
ssHorizontal
OnKeyUp
TCustomButton.TButtonStyle
FProportional
Proportional
FOldKeyDown
cdsShowKeyboardCues
vsReport
FURL
ssHotTrack
TWindowState
poProportional
fsShowing
FWindowState
FKeyPreview
WantChildKey
KeyPreview$<I
WindowStateD
KeyPreview
WindowState
FBiDiKeyboard
FNonBiDiKeyboard
FEnumAllWindowsOnActivateHint
FOnActionExecute
Keyword
EnumAllWindowsOnActivateHint\
BiDiKeyboard\
NonBiDiKeyboard
OnActionExecuteD
Uh%CN
fKeyword
IFontAccessh
IPictureAccessh
TCommonShellExecuteThread0
TCommonShellExecuteThread
shell32.dll
shlwapi.dll
Mpr.dll
THKeyArray
TCommonKeyState
cksShift
TCommonKeyStates
Userenv.dll
NETAPI32.DLL
SVRAPI.DLL
elsReport
elsReportThumb
TAutoGroupGetKeyEvent
TColumnGetImageIndexEvent
TColumnSetImageIndexEvent
KeyState
KeyStates
TGroupGetImageIndexEvent
TGroupSetImageIndexEvent
HintWindowShown
TItemGetGroupKeyEvent
GroupKey
TItemGetImageIndexEvent
TItemSetGroupKeyEvent
TItemSetImageIndexEvent
MouseMsg
TEasyKeyActionEvent
EscapeKeyPressed
TEasyViewReportItem
TEasyViewReportThumbItem
TEasyViewReportThumbItemX
TEasyGridReportGroup
TEasyGridReportGroupd
TEasyGridReportThumbGroup
TEasyGridReportThumbGroupP
TEasyCellSizeReport8
TEasyCellSizeReport
TEasyCellSizeReportThumb
TEasyCellSizeReportThumb0
ReportThumb
Report
AlwaysShow
OnAutoGroupGetKey
OnItemGetGroupKey
OnItemSetGroupKey
OnKeyAction
UhE%U
EIdCanNotBindPortInRange
EIdCanNotBindPortInRange<
EIdInvalidPortRange
TIdSocketListWindows
IdStackWindows
TIdStackWindows`SX
TIdStackWindowslRX
EIdIPVersionUnsupportedx
EIdIPVersionUnsupportedP
TIdStackLocalAddressh
LicenseKey
ESQLiteException
SQLiteTable3
TSQLiteDatabaseT
TSQLiteDatabase@
TSQLiteTable
ftpTransfer
ftpReady
ftpAborted
EIdPortRequired
EIdTCPConnectionError
EIdTCPConnectionError(
EIdObjectTypeNotSupported
Port
ClientPortMin
ClientPortMax\
"EIdTransparentProxyUDPNotSupported
"EIdTransparentProxyUDPNotSupportedd
TIdTCPClientCustom
TIdTCPClientCustomd
IdTCPClient
TIdTCPClient
BoundPort
%EIdSocksUDPNotSupportedBySOCKSVersion
%EIdSocksUDPNotSupportedBySOCKSVersion`
saUsernamePassword
Password
DefaultPort
TIdTCPConnection
IdTCPConnection
IdHTTPHeaderInfo
ProxyPassword
ProxyPort\
Password\
TIdMetaHTTPEquiv
EIdUnsupportedOperation
sslvrfFailIfNoPeerCert
AMsg
TCallbackExEvent
TPasswordEvent
TPasswordEventEx
VPassword
Certificate
RootCertFile\
CertFile\
KeyFile\
OnGetPassword
OnGetPasswordEx\
EIdOSSLLoadingRootCertErrorl
EIdOSSLLoadingRootCertError@
EIdOSSLLoadingCertError(
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
TIdHTTPOption
hoNoParseMetaHTTPEquiv
IdHTTP
TIdHTTPOptions
TIdHTTPProtocolVersion
TIdHTTPOnRedirectEvent
TIdHTTPOnHeadersAvailable
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPProtocol
TIdCustomHTTP
TIdHTTP4
TIdHTTPl
HTTPOptionst
EIdHTTPProtocolException
TMonochromeLookup
SetupDiOpenClassRegKey
SetupDiOpenClassRegKeyExA
SetupDiOpenClassRegKeyExW
SetupDiCreateDeviceInterfaceRegKeyA
SetupDiCreateDeviceInterfaceRegKeyW
SetupDiOpenDeviceInterfaceRegKey
SetupDiDeleteDeviceInterfaceRegKey
SetupDiCreateDevRegKeyA
SetupDiCreateDevRegKeyW
SetupDiOpenDevRegKey
SetupDiDeleteDevRegKey
CM_Delete_Class_Key
CM_Delete_Class_Key_Ex
CM_Delete_DevNode_Key
CM_Delete_DevNode_Key_Ex
CM_Get_Class_Key_NameA
CM_Get_Class_Key_NameW
CM_Get_Class_Key_Name_ExA
CM_Get_Class_Key_Name_ExW
CM_Open_Class_KeyA
CM_Open_Class_KeyW
CM_Open_Class_Key_ExA
CM_Open_Class_Key_ExW
CM_Open_DevNode_Key
CM_Open_DevNode_Key_Ex
IProgressh
ICryptoGetTextPasswordh
ICryptoGetTextPassword2h
Common.LoggerWindow
Common.Logger
Common.LoggerH
Driver.CoreSnapshot
Driver.CoreResult
Common.RestorePoint\
Driver.CoreInstall
UhD%c
'TPair<System.Cardinal,System.TDateTime>
BTArray<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>
GTEnumerator<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>(
GTEnumerator<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>TCc
GTEnumerable<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>-
GTEnumerable<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>
3TDictionary<System.Cardinal,System.TDateTime>.TItem
8TDictionary<System.Cardinal,System.TDateTime>.TItemArray
"IEqualityComparer<System.Cardinal>h
Generics.Defaults
'TCollectionNotifyEvent<System.Cardinal>
(TCollectionNotifyEvent<System.TDateTime>
TArray<System.Cardinal>
TEnumerator<System.Cardinal>(
TEnumerator<System.Cardinal><Ic
TEnumerable<System.Cardinal>-
TEnumerable<System.Cardinal>`Jc
<TDictionary<System.Cardinal,System.TDateTime>.TKeyEnumerator;
<TDictionary<System.Cardinal,System.TDateTime>.TKeyEnumerator
<TDictionary<System.Cardinal,System.TDateTime>.TKeyCollection;
<TDictionary<System.Cardinal,System.TDateTime>.TKeyCollectionpMc
TArray<System.TDateTime>
TEnumerator<System.TDateTime>(
TEnumerator<System.TDateTime>
TEnumerable<System.TDateTime>-
TEnumerable<System.TDateTime>
>TDictionary<System.Cardinal,System.TDateTime>.TValueEnumerator;
>TDictionary<System.Cardinal,System.TDateTime>.TValueEnumerator
>TDictionary<System.Cardinal,System.TDateTime>.TValueCollection;
>TDictionary<System.Cardinal,System.TDateTime>.TValueCollection
=TDictionary<System.Cardinal,System.TDateTime>.TPairEnumerator;
=TDictionary<System.Cardinal,System.TDateTime>.TPairEnumerator
FOnKeyNotify
FKeyCollection
-TDictionary<System.Cardinal,System.TDateTime>9
ContainsKey
-TDictionary<System.Cardinal,System.TDateTime>
Keys
OnKeyNotify
[:{Generics.Collections}TList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>.:1
Driver.CoreInstall8Bc
EIComparer<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>h
RTCollectionNotifyEvent<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>
Item'TPair<System.Cardinal,System.TDateTime>
GIEnumerable<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>
MTList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>.TEnumerator5
MTList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>.TEnumerator`*d
ATList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>&
ATList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>P,d
0:{Generics.Collections}TList<System.Cardinal>.:1
IComparer<System.Cardinal>h
IEnumerable<System.Cardinal>
"TList<System.Cardinal>.TEnumerator5
"TList<System.Cardinal>.TEnumerator
TList<System.Cardinal>&
TList<System.Cardinal>
1:{Generics.Collections}TList<System.TDateTime>.:1
IComparer<System.TDateTime>h
IEnumerable<System.TDateTime>
#TList<System.TDateTime>.TEnumerator5
#TList<System.TDateTime>.TEnumerator
TList<System.TDateTime>&
TList<System.TDateTime>
GTComparison<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>h
ETComparer<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>2
ETComparer<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>
[:{Generics.Collections}TList<Driver.CoreInstall.TPair<System.Cardinal,System.TDateTime>>.:3
TComparison<System.Cardinal>h
TComparer<System.Cardinal>2
TComparer<System.Cardinal>
0:{Generics.Collections}TList<System.Cardinal>.:3
TComparison<System.TDateTime>h
TComparer<System.TDateTime>2
TComparer<System.TDateTime>
1:{Generics.Collections}TList<System.TDateTime>.:3
Driver.Core
EInvalidGridOperation
EInvalidGridOperation$
goAlwaysShowEditor
doKeyColFixed
TKeyOption
keyEdit
keyAdd
keyDelete
keyUnique
TKeyOptions
KeyName
KeyValue
FKeyOptions
FDupKeySave
KeyOptions
KeyIsValid
FKeyDesc
KeyDesc
;!199{199
;0!8&2{199
"<;=!!%{199
Windows 95
Windows 95 OSR-2
Windows 98
Windows 98 SE
Windows ME
Windows 9x New
Windows NT 3
Windows NT 4
Windows 2000
Windows XP
Windows 2003
Windows Vista
Windows 2008
Windows 7
Windows 2008 R2
Windows 8
Windows 2012
Windows 8.1
Windows 2012 R2
Windows 10
Windows NT New
TMsgHandler
TMsgHandlerOO
user.exe
TMsgHandlers
madToolsMsgHandlerWindow
>0';0974&0{199
Export
MapFileNameVVV.madshi.net
dbghelp.dll
4.0.12
bSendBugReport
bSaveBugReport
bPrintBugReport
bShowBugReport
esSysUtilsShowException
esHttpExtension
esIntraweb
esTThreadExecute
epCompleteReport
TBugReportCallback
bugReport
TBugReportCallbackOO
eaSendBugReport
eaSaveBugReport
eaPrintBugReport
eaSendBugReport2
eaSaveBugReport2
eaPrintBugReport2
eaSendBugReport3
eaSaveBugReport3
eaPrintBugReport3
eaShowBugReport
TBugReportPluginA
TBugReportPluginW
TBugReportPluginExA
TBugReportPluginExW
advapi32.dll
The import table is invalid.
WindowsLogo
ReportLeaks
UploadViaHttp
HttpServer
HttpSsl
HttpPort
HttpAccount
HttpPassword
BugTrPassword
MailAsSmtpServer
MailAsSmtpClient
SmtpServer
SmtpSsl
SmtpTls
SmtpPort
SmtpAccount
SmtpPassword
bugreport.mbr
screenshot.png
ExceptMsg
FrozenMsg
BitFaultMsg
send bug report
save bug report
print bug report
show bug report
%appname%, %exceptMsg%
bug report
please find the bug report attached
Sending bug report...
PrepAttMsg
MxLookMsg
ConnMsg
SendMailMsg
FieldMsg
SendAttMsg
SendFinalMsg
SendFailMsg
Sorry, sending the bug report didn't work.
GetWindowsLogo
SetWindowsLogo
GetFilter1NoBugReport
GetFilter2NoBugReport
GetGeneralNoBugReport
SetFilter1NoBugReport
SetFilter2NoBugReport
SetGeneralNoBugReport
GetAutoShowBugReport
SetAutoShowBugReport
GetHttpServer
SetHttpServer
GetHttpSsl
SetHttpSsl
GetHttpPort
SetHttpPort
GetHttpAccount
SetHttpAccount
GetHttpPassword
SetHttpPassword
GetBugTrackerPassword
SetBugTrackerPassword
GetMailAsSmtpServer
SetMailAsSmtpServer
GetMailAsSmtpClient
SetMailAsSmtpClient
GetSmtpServer
SetSmtpServer
GetSmtpSsl
SetSmtpSsl
GetSmtpTls
SetSmtpTls
GetSmtpPort
SetSmtpPort
GetSmtpAccount
SetSmtpAccount
GetSmtpPassword
SetSmtpPassword
GetAttachBugReport
SetAttachBugReport
GetAttachBugReportFile
SetAttachBugReportFile
GetDeleteBugReportFile
SetDeleteBugReportFile
GetBugReportSendAs
SetBugReportSendAs
GetBugReportZip
SetBugReportZip
GetBugReportFile
SetBugReportFile
GetAppendBugReports
SetAppendBugReports
GetBugReportFileSize
SetBugReportFileSize
GetExceptMsg
SetExceptMsg
GetFrozenMsg
SetFrozenMsg
GetBitFaultMsg
SetBitFaultMsg
GetPrepareAttachMsg
SetPrepareAttachMsg
GetMxLookupMsg
SetMxLookupMsg
GetConnectMsg
SetConnectMsg
GetSendMailMsg
SetSendMailMsg
GetFieldsMsg
SetFieldsMsg
GetSendAttachMsg
SetSendAttachMsg
GetSendFinalizeMsg
SetSendFinalizeMsg
GetSendFailureMsg
SetSendFailureMsg
TDABugReportCallback
TDABugReportCallbackOO
FBugReportHeader
FBugReportSections
FBugReport
FBugReportCallbacks
FBugReportCallbacksOO
FCreateBugReport
FCorrectBugReportNo
GetBugReportHeader
GetBugReportSections
GetBugReport_
SetBugReport
GetBugReport
RegisterBugReportCallback
bugReportCallback
UnregisterBugReportCallback
GetCreateBugReport
SetCreateBugReport
ShowBugReport
SendBugReport
SaveBugReport
PrintBugReport
CompleteBugReport
CriticalBugReportCallbackExists
VVV.google.com
SMTP:
A.ROOT-SERVERS.NET
K.ROOT-SERVERS.NET
VVV.madshi.net_multipart_boundary
sbtPassResponse
cSupportedAlgs
palgSupportedAlgs
FTlsSupported
TSmtp
port
password
LOGIN
AUTH LOGIN
TWinHttpProxyInfo
lpszProxyBypass
FUrl
FPort
FBugTrackerPassword
FHttpAuthUser
FHttpAuthPassword
FProxyPassword
TWinHttp<
httpAuthUser
httpAuthPassword
bugTrackerPassword
proxyBypass
proxyPassword
TWinHttp
/api.xml
<url>
?cmd=
/xmlrpc.cgi
Bugzilla.version
Product.get_enterable_products
Product.get
Bug.fields
Bugzilla_login
Bugzilla_password
Bug.create
Bug.add_attachment
/api/soap/mantisconnect.php
<?xml version="1.0" encoding="UTF-8"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="hXXp://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><ns1:
</username><password xsi:type="xsd:string">
</password>
*.txt
TSendBugReportExRec
FDefaultMsgBox
defaultMsgBox
BugReportChanged
Uh.dk
ServerSupportFunctionNext
kernel32.dll
user32.dll
coreide150.bpl
FaultRep.dll
internal error. please notify [email protected]
IWebBrowser
IWebBrowserApp
IWebBrowser2T'l
TWebBrowserStatusTextChange
TWebBrowserProgressChange
TWebBrowserCommandStateChange
TWebBrowserTitleChange
TWebBrowserPropertyChange
TWebBrowserBeforeNavigate2
TWebBrowserNewWindow2
TWebBrowserNavigateComplete2
TWebBrowserDocumentComplete
TWebBrowserOnVisible
TWebBrowserOnToolBar
TWebBrowserOnMenuBar
TWebBrowserOnStatusBar
TWebBrowserOnFullScreen
TWebBrowserOnTheaterMode
TWebBrowserWindowSetResizable
TWebBrowserWindowSetLeft
TWebBrowserWindowSetTop
TWebBrowserWindowSetWidth
TWebBrowserWindowSetHeight
TWebBrowserWindowClosing
TWebBrowserClientToHostWindow
TWebBrowserSetSecureLockIcon
TWebBrowserFileDownload
TWebBrowserNavigateError
%TWebBrowserPrintTemplateInstantiation
TWebBrowserPrintTemplateTeardown
TWebBrowserUpdatePageStatus
%TWebBrowserPrivacyImpactedStateChange
TWebBrowserNewWindow3
bstrUrlContext
bstrUrl
"TWebBrowserSetPhishingFilterStatus
TWebBrowserWindowStateChanged
dwWindowStateFlags
TWebBrowserNewProcess
TWebBrowserThirdPartyUrlBlocked
!TWebBrowserRedirectXDomainBlocked
StartURL
RedirectURL
TWebBrowserBeforeScriptExecute
TWebBrowserWebWorkerStarted
TWebBrowserWebWorkerFinsihed
TWebBrowser
OnWindowSetResizable
OnWindowSetLeftp1l
OnWindowSetTop
OnWindowSetWidthT2l
OnWindowSetHeight
OnWindowStateChanged
OnThirdPartyUrlBlocked\<l
OnBeforeScriptExecute
OnWebWorkerStarted
OnWebWorkerFinsihed
FormKeyDown
IdHTTP1
HTTPWorkBegin
HTTPWork
HTTPWorkEnd
TIdTCPStream
IdTCPStream
utNoTLSSupport
EIdTLSClientTLSNegCmdFailed
EIdSASLNotSupported
TIdSMTPEnhancedCode
TIdSMTPEnhancedCode`
IdReplySMTP
TIdReplySMTP
EIdSMTPReplyError
EIdSMTPReply
EIdSMTPReply|
EIdSMTPReplyInvalidReplyString
EIdSMTPReplyInvalidReplyString
EIdSMTPReplyInvalidClass
TIdSMTPFailedRecipient
TIdSMTPBase
TIdSMTPBasel
IdSMTPBase
PipeLine
TIdSMTPAuthenticationType
IdSMTP
TIdSMTP
ValidateAuthLoginCapability
IdSMTP1
Driver.CoreDriverList
*TArray<Driver.CoreDriverList.TDeviceEntry>
/TEnumerator<Driver.CoreDriverList.TDeviceEntry>(
/TEnumerator<Driver.CoreDriverList.TDeviceEntry>
/TEnumerable<Driver.CoreDriverList.TDeviceEntry>-
/TEnumerable<Driver.CoreDriverList.TDeviceEntry>
C:{Generics.Collections}TList<Driver.CoreDriverList.TDeviceEntry>.:1
Driver.CoreDriverList(
-IComparer<Driver.CoreDriverList.TDeviceEntry>h
:TCollectionNotifyEvent<Driver.CoreDriverList.TDeviceEntry>
/IEnumerable<Driver.CoreDriverList.TDeviceEntry>
5TList<Driver.CoreDriverList.TDeviceEntry>.TEnumerator5
5TList<Driver.CoreDriverList.TDeviceEntry>.TEnumeratorT&o
)TList<Driver.CoreDriverList.TDeviceEntry>&
)TList<Driver.CoreDriverList.TDeviceEntry>
/TObjectList<Driver.CoreDriverList.TDeviceEntry><
/TObjectList<Driver.CoreDriverList.TDeviceEntry>
1TArray<Driver.CoreDriverList.TDriverPackageEntry>
6TEnumerator<Driver.CoreDriverList.TDriverPackageEntry>(
6TEnumerator<Driver.CoreDriverList.TDriverPackageEntry>
6TEnumerable<Driver.CoreDriverList.TDriverPackageEntry>-
6TEnumerable<Driver.CoreDriverList.TDriverPackageEntry>t5o
J:{Generics.Collections}TList<Driver.CoreDriverList.TDriverPackageEntry>.:1
Driver.CoreDriverList o
4IComparer<Driver.CoreDriverList.TDriverPackageEntry>h
ATCollectionNotifyEvent<Driver.CoreDriverList.TDriverPackageEntry>
6IEnumerable<Driver.CoreDriverList.TDriverPackageEntry>
<TList<Driver.CoreDriverList.TDriverPackageEntry>.TEnumerator5
<TList<Driver.CoreDriverList.TDriverPackageEntry>.TEnumerator
0TList<Driver.CoreDriverList.TDriverPackageEntry>&
0TList<Driver.CoreDriverList.TDriverPackageEntry>
6TObjectList<Driver.CoreDriverList.TDriverPackageEntry><
6TObjectList<Driver.CoreDriverList.TDriverPackageEntry>XDo
6TComparison<Driver.CoreDriverList.TDriverPackageEntry>h
4TComparer<Driver.CoreDriverList.TDriverPackageEntry>2
4TComparer<Driver.CoreDriverList.TDriverPackageEntry>
8TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>
dTPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
TArray<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
TEnumerator<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>(
TEnumerator<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
TEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>-
TEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
oTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TItem
tTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TItemArray
!IEqualityComparer<System.Integer>h
&TCollectionNotifyEvent<System.Integer>
fTCollectionNotifyEvent<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
Item8TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>
TArray<System.Integer>
TEnumerator<System.Integer>(
TEnumerator<System.Integer>
TEnumerable<System.Integer>-
TEnumerable<System.Integer>
xTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TKeyEnumerator;
xTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TKeyEnumerator8
xTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TKeyCollection;
xTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TKeyCollection
VTArray<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
[TEnumerator<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>(
[TEnumerator<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
[TEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>-
[TEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
zTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TValueEnumerator;
zTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TValueEnumerator
zTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TValueCollection;
zTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TValueCollection,
yTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TPairEnumerator;
yTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TPairEnumerator
iTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>9
iTDictionary<System.Integer,Generics.Collections.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
OnKeyNotify,
/TComparison<Driver.CoreDriverList.TDeviceEntry>h
-TComparer<Driver.CoreDriverList.TDeviceEntry>2
-TComparer<Driver.CoreDriverList.TDeviceEntry>H
C:{Generics.Collections}TList<Driver.CoreDriverList.TDeviceEntry>.:3
J:{Generics.Collections}TList<Driver.CoreDriverList.TDriverPackageEntry>.:3
=TDelegatedComparer<Driver.CoreDriverList.TDriverPackageEntry>8
=TDelegatedComparer<Driver.CoreDriverList.TDriverPackageEntry>
:{Generics.Collections}TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>.:1
Driver.CoreDriverList|yo
IComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>h
TCollectionNotifyEvent<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
ItemdTPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
IEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>.TEnumerator5
TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>.TEnumeratorh
TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>&
TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
/:{Generics.Collections}TList<System.Integer>.:1
IComparer<System.Integer>h
IEnumerable<System.Integer>
!TList<System.Integer>.TEnumerator5
!TList<System.Integer>.TEnumerator
TList<System.Integer>&
TList<System.Integer>
o:{Generics.Collections}TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.:1
YIComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>h
[IEnumerable<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
aTList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TEnumerator5
aTList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.TEnumerator
UTList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>&
UTList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
TComparison<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>h
TComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>2
TComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>
:{Generics.Collections}TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>>.:3
TComparison<System.Integer>h
TComparer<System.Integer>2
TComparer<System.Integer>
/:{Generics.Collections}TList<System.Integer>.:3
[TComparison<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>h
YTComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>2
YTComparer<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>
o:{Generics.Collections}TList<Driver.CoreDriverList.TPair<System.Integer,Driver.CoreDriverList.TDeviceEntry>>.:3
Common.Internet
TfrmCheckURL
URLChecker
IdHTTP0x
IdHTTP11|
btnCheckURL
HTTP0Work
HTTP0Work2
HTTP1Start
HTTP2Start
HTTP3Start
HTTP4Start
HTTP5Start
HTTP1Work
HTTP2Work
HTTP3Work
HTTP4Work
HTTP5Work
InstallExeDriver
actDebugExecute
btnCheckURLClick
UrlMon
Common.Params
Driver.Utils
Common.Utils
Driver.CoreDevices
Driver.CoreDevicesHelpers
SQLite3
IdTCPServer
IdCustomTCPServer
Common.RestorePoint
JwaWS2tcpip
JwaIpExport
IdCmdTCPServer
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!"%$%&%(%*% %-%/%1%3%5%7%9%;$=%?%A%D%F%H%J%K%L%M%N%O%R%U%X%[%^%_%`%a%b%d%f%h%i%j%k%l%m%o%s% !,!
P%S%V%Y%\%
6666666666666666
?456789:;<=
!"#$%&'()* ,-./0123
0123456
!"#$%&'()* ,-./0123456789:;<=>?
&'()* ,-./0123456789:;<=>?
oleaut32.dll
RegOpenKeyExW
RegCloseKey
UnhookWindowsHookEx
SetWindowsHookExW
SetKeyboardState
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MapVirtualKeyW
LoadKeyboardLayoutW
GetKeyboardState
GetKeyboardLayoutNameW
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextW
GetAsyncKeyState
ExitWindowsEx
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
msimg32.dll
gdi32.dll
SetViewportOrgEx
SetViewportExtEx
version.dll
WinExec
GetWindowsDirectoryA
GetWindowsDirectoryW
GetCPInfoExW
GetCPInfo
CreatePipe
RegQueryInfoKeyW
RegOpenKeyExA
RegFlushKey
RegEnumKeyExW
RegDeleteKeyW
RegCreateKeyExA
RegCreateKeyExW
SHFolder.dll
ole32.dll
comctl32.dll
SHFileOperationA
SHFileOperationW
ShellExecuteExA
ShellExecuteExW
ShellExecuteA
ShellExecuteW
wininet.dll
HttpSendRequestW
HttpQueryInfoW
HttpOpenRequestW
comdlg32.dll
oleacc.dll
sqlite3.dll
sqlite3_finalize
sqlite3_column_type
sqlite3_column_text
sqlite3_column_int
sqlite3_column_double
sqlite3_column_bytes
sqlite3_column_blob
sqlite3_step
sqlite3_column_decltype
sqlite3_column_name
sqlite3_column_count
sqlite3_prepare
sqlite3_free
sqlite3_errcode
sqlite3_errmsg
sqlite3_close
sqlite3_open
winmm.dll
ntdll.dll
wsock32.dll
windowscodecs.dll
uxtheme.dll
DWMAPI.DLL
MainProgram.exe
1$1$0,0004080
7#7'7 7/73777
5S5F5c5q5
3<3U3`3h3v3
0#0*01090\0
11n1x1
4M4]4{4
6l6K6O6c6k6o6
> >$>(>,>??
5 55595_5
:":):0:7:@:\:
4L4O4i4
6-6S6Z6a6h6o6v6}6
969>9\9|9
6$6 626:6\6~6
8#8'8 8/838
!0%0)0-01050G0U0a0p0}0
89:&</<0=
11D1]1l1
>!>&> >0>5>;>
3%4U4z4
"0&0*0.02060:0
263C3
9"9*9/999
00C0T0c0p0
9œ9a9
979<9_9|9
:&: :0:?:}:
333F3`3w3
7.73787@7
0 0$0(0.0
3L4R4h4
2#3(3-3U3}3
9!9)91999
< <$<,<4<
1>1 2)2]2
3#3-353:3?3
2!2-24292
1!2 252\2{3
7$70777<7
;&;2;9;>;_;
0 1:1?1\1
6 6$6(6,606
7094989<9\9|9
6 7$74787<7@7
333333333333333333
33333833
3333339
3333333333333338
:*"*"$3338
3333333
33333333
33333333333
3333333333338
33338?383
333333333333
:*3:"$3338
333333333333333
@000///1111*$&
paint.net 4.0;
!.WE/4
.IDAThC
.pIDI
Paint.NET v3.5.100
.DFFr
Paint.NET v3.5.11G
xyT%U
5F.VR
=UN.EN.
Wj.zY
}0(*.pw
pm%C\rlR
t%DMM
Pegg.UjF|jFbZzbj
%cPn:
7:5221>8=
gOÝe
%XzVSoMx
 h.FG
t.ESZH'p
K.kf]Q
.Xpeg
r%SKI
H.uuu
.nl#]cS-
4IP%u
5;1% >)#6!-*6%<*14
{&#:%9.;
Q.tHJJ\
nmr.M2.Mb6
7-'7-&5.$5,&
|^}<^}\^
eeA%u
4/%7.&5,%
w.WMl
WG,.gr
@70".0*>2)#&9;6)'1
30,*<,>6>52-)"'>4#
2)!%1&%)1.!!
$KU%uM5
2214652
x~~avv.tU
.vqI18
k...ii)
KWindows
CGenerics.Defaults
#IdSMTP
 IdSMTPBase
 IdTCPServer
fJwaIpExport
eCommon.LoggerWindow
}Common.Params
oDriver.Utils
CCommon.Utils
bDriver.CoreSnapshot
]Driver.CoreDevices
0IdHTTPHeaderInfo
?1)19%)%%
d;%%%C
cg.Br
Font.Charset
Font.Color
Font.Height
Font.Name
Font.Style
All windows
Check URL
%Select the drivers you wish to backup
EditManager.Font.Charset
EditManager.Font.Color
EditManager.Font.Height
EditManager.Font.Name
EditManager.Font.Style
GroupFont.Charset
GroupFont.Color
GroupFont.Height
GroupFont.Name
GroupFont.Style
Header.Columns.Items
Header.Font.Charset
Header.Font.Color
Header.Font.Height
Header.Font.Name
Header.Font.Style
Header.Height
ImageList1)PaintInfoGroup.MarginBottom.CaptionIndent
Selection.FullRowSelect
%Driver backup successfully completed!
%Select name, location and backup type
Items.Strings
Groups.Items
$Product information and support link
Support
Support:
Register %s
Version: %s
Header.ShowInAllViews
Header.Visible
PaintInfoGroup.Expandable
)PaintInfoGroup.MarginBottom.CaptionIndent
%Save downloded drivers to this folder
Login
Welcome to %s
Webcam drivers
Windows system drivers
Keyboard drivers
Picture.Data
%s found
TIdHTTP
IdHTTP11
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
Request.CharSet
Request.ContentLength
Request.ContentRangeEnd
Request.ContentRangeStart
"Request.ContentRangeInstanceLength
Request.ContentType
Request.Accept
Request.BasicAuthentication
Request.UserAgent
&Mozilla/3.0 (compatible; Indy Library)
Request.Ranges.Units
Request.Ranges
HTTPOptions
IdHTTP0
.NN outdated drivers have been found on your PC
"Would you like to register %s now?
FTo immediately download and fix these drivers you need to register %s.
Do you have a License Key?
License key
]If you already have a License Key, please enter it in the form below and click "Activate Now"
Do you need a License Key?
.To purchase %s and obtain a license key click
YCheck the email you received after you purchased the product for the correct license key.
&Your license key will look like this:
'The license key you entered is for %s.
>%s is a separate product and requires a different license key.
to purchase %s.
BWe NOT reccomend your use this driver for current Windows version.
Current Windows version:
Backuped driver Windows version:
"Report a problem with a new driver
Thank you for trying %s!
xYour feedback is very valuable and will help us create better products. Please let us know why you did not register %s:
,%s did not find the driver I was looking for
frmCheckURL
.Would you like to renew your subscription now?
UTo immediately download and fix these drivers you need to renew your %s subscription.
,Your %s subscription will expire in NN days.
<assemblyIdentity version="1.0.0.0"
name="program.exe"
<requestedExecutionLevel
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
PSAPI.dll
NTDLL.DLL
%s-%s
%s[%d]
%s_%d
.Owner
\\?\UNC\
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
TaskDialogIndirect
crSQLWait
%s (%s)
imm32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
Items.ItemData
%s%s%s%s%s%s%s%s%s%s
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
%s, ClassID: %s
%s, ProgID: "%s"
WNNC_NET_FTP_NFS
PIDLs to operate on are not siblings of the Namespace doing the operation.
olepro32.dll
\\.\vwin32
Unable to find RegSvr32.exe executable.
RegSvr32.exe
RegOpenKeyW
%s, %.2d %s %.4d %s %s
%s, %.2d%s%s%s%.4d %s %s
%s, %d %s %d %s %s
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.irv:1983
csISO16Portuguese
csISO84Portuguese2
windows-936
csShiftJIS
windows-874
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csMicrosoftPublishing
Windows-31J
csWindows31J
PTCP154
csPTCP154
windows-1250
windows-1251
windows-1252
windows-1253
windows-1254
windows-1255
windows-1256
windows-1257
windows-1258
WS2_32.DLL
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
MSWSOCK.DLL
WSARecvMsg
WSASendMsg
Wship6.dll
Fwpuclnt.dll
IdnDL.dll
Normaliz.dll
iphlpapi.dll
0.0.0.0
127.0.0.1
0123456789
!"#$%&'()* ,-./;<=>?@[\]^_`{|}~
.nml=animation/narrative
.aac=audio/mp4
.aif=audio/x-aiff
.aifc=audio/x-aiff
.aiff=audio/x-aiff
.au=audio/basic
.gsm=audio/x-gsm
.kar=audio/midi
.m3u=audio/mpegurl
.mid=audio/midi
.midi=audio/midi
.mpega=audio/x-mpg
.mp2=audio/x-mpg
.mp3=audio/x-mpg
.mpga=audio/x-mpg
.m3u=audio/x-mpegurl
.pls=audio/x-scpls
.qcp=audio/vnd.qcelp
.ra=audio/x-realaudio
.ram=audio/x-pn-realaudio
.rm=audio/x-pn-realaudio
.sd2=audio/x-sd2
.sid=audio/prs.sid
.snd=audio/basic
.wav=audio/x-wav
.wax=audio/x-ms-wax
.wma=audio/x-ms-wma
.mjf=audio/x-vnd.AudioExplosion.MjuiceMediaFile
.art=image/x-jg
.bmp=image/bmp
.cdr=image/x-coreldraw
.cdt=image/x-coreldrawtemplate
.cpt=image/x-corelphotopaint
.djv=image/vnd.djvu
.djvu=image/vnd.djvu
.gif=image/gif
.ief=image/ief
.ico=image/x-icon
.jng=image/x-jng
.jpg=image/jpeg
.jpeg=image/jpeg
.jpe=image/jpeg
.pat=image/x-coreldrawpattern
.pcx=image/pcx
.pbm=image/x-portable-bitmap
.pgm=image/x-portable-graymap
.pict=image/x-pict
.png=image/x-png
.pnm=image/x-portable-anymap
.pntg=image/x-macpaint
.ppm=image/x-portable-pixmap
.psd=image/x-psd
.qtif=image/x-quicktime
.ras=image/x-cmu-raster
.rf=image/vnd.rn-realflash
.rgb=image/x-rgb
.rp=image/vnd.rn-realpix
.sgi=image/x-sgi
.svg=image/svg xml
.svgz=image/svg xml
.targa=image/x-targa
.tif=image/x-tiff
.wbmp=image/vnd.wap.wbmp
.webp=image/webp
.xbm=image/xbm
.xbm=image/x-xbitmap
.xpm=image/x-xpixmap
.xwd=image/x-xwindowdump
.xml=text/xml
.uls=text/iuls
.txt=text/plain
.rtx=text/richtext
.wsc=text/scriptlet
.rt=text/vnd.rn-realtext
.htt=text/webviewhtml
.htc=text/x-component
.vcf=text/x-vcard
.asf=video/x-ms-asf
.asx=video/x-ms-asf
.avi=video/x-msvideo
.dl=video/dl
.dv=video/dv
.flc=video/flc
.fli=video/fli
.gl=video/gl
.lsf=video/x-la-asf
.lsx=video/x-la-asf
.mng=video/x-mng
.mp2=video/mpeg
.mp3=video/mpeg
.mp4=video/mpeg
.mpeg=video/x-mpeg2a
.mpa=video/mpeg
.mpe=video/mpeg
.mpg=video/mpeg
.ogv=video/ogg
.moov=video/quicktime
.mov=video/quicktime
.mxu=video/vnd.mpegurl
.qt=video/quicktime
.qtc=video/x-qtc
.rv=video/vnd.rn-realvideo
.ivf=video/x-ivf
.webm=video/webm
.wm=video/x-ms-wm
.wmp=video/x-ms-wmp
.wmv=video/x-ms-wmv
.wmx=video/x-ms-wmx
.wvx=video/x-ms-wvx
.rms=video/vnd.rn-realvideo-secure
.asx=video/x-ms-asf-plugin
.movie=video/x-sgi-movie
.aab=application/x-authorware-bin
.aam=application/x-authorware-map
.aas=application/x-authorware-seg
.abw=application/x-abiword
.ace=application/x-ace-compressed
.ai=application/postscript
.alz=application/x-alz-compressed
.ani=application/x-navi-animation
.arj=application/x-arj
.asf=application/vnd.ms-asf
.bat=application/x-msdos-program
.bcpio=application/x-bcpio
.boz=application/x-bzip2
.bz=application/x-bzip
.bz2=application/x-bzip2
.cab=application/vnd.ms-cab-compressed
.cat=application/vnd.ms-pki.seccat
.ccn=application/x-cnc
.cco=application/x-cocoa
.cdf=application/x-cdf
.cer=application/x-x509-ca-cert
.chm=application/vnd.ms-htmlhelp
.chrt=application/vnd.kde.kchart
.cil=application/vnd.ms-artgalry
.class=application/java-vm
.com=application/x-msdos-program
.clp=application/x-msclip
.cpio=application/x-cpio
.cpt=application/mac-compactpro
.cqk=application/x-calquick
.crd=application/x-mscardfile
.crl=application/pkix-crl
.csh=application/x-csh
.dar=application/x-dar
.dbf=application/x-dbase
.dcr=application/x-director
.deb=application/x-debian-package
.dir=application/x-director
.dist=vnd.apple.installer xml
.distz=vnd.apple.installer xml
.dll=application/x-msdos-program
.dmg=application/x-apple-diskimage
.doc=application/msword
.dot=application/msword
.dvi=application/x-dvi
.dxr=application/x-director
.ebk=application/x-expandedbook
.eps=application/postscript
.evy=application/envoy
.exe=application/x-msdos-program
.fdf=application/vnd.fdf
.fif=application/fractals
.flm=application/vnd.kde.kivio
.fml=application/x-file-mirror-list
.gzip=application/x-gzip
.gnumeric=application/x-gnumeric
.gtar=application/x-gtar
.gz=application/x-gzip
.hdf=application/x-hdf
.hlp=application/winhlp
.hpf=application/x-icq-hpf
.hqx=application/mac-binhex40
.hta=application/hta
.ims=application/vnd.ms-ims
.ins=application/x-internet-signup
.iii=application/x-iphone
.iso=application/x-iso9660-image
.jar=application/java-archive
.karbon=application/vnd.kde.karbon
.kfo=application/vnd.kde.kformula
.kon=application/vnd.kde.kontour
.kpr=application/vnd.kde.kpresenter
.kpt=application/vnd.kde.kpresenter
.kwd=application/vnd.kde.kword
.kwt=application/vnd.kde.kword
.latex=application/x-latex
.lha=application/x-lzh
.lcc=application/fastman
.lrm=application/vnd.ms-lrm
.lz=application/x-lzip
.lzh=application/x-lzh
.lzma=application/x-lzma
.lzo=application/x-lzop
.lzx=application/x-lzx
.mpp=application/vnd.ms-project
.mvb=application/x-msmediaview
.man=application/x-troff-man
.mdb=application/x-msaccess
.me=application/x-troff-me
.ms=application/x-troff-ms
.msi=application/x-msi
.mpkg=vnd.apple.installer xml
.mny=application/x-msmoney
.nix=application/x-mix-transfer
.oda=application/oda
.odb=application/vnd.oasis.opendocument.database
.odc=application/vnd.oasis.opendocument.chart
.odf=application/vnd.oasis.opendocument.formula
.odg=application/vnd.oasis.opendocument.graphics
.odi=application/vnd.oasis.opendocument.image
.odm=application/vnd.oasis.opendocument.text-master
.odp=application/vnd.oasis.opendocument.presentation
.ods=application/vnd.oasis.opendocument.spreadsheet
.ogg=application/ogg
.odt=application/vnd.oasis.opendocument.text
.otg=application/vnd.oasis.opendocument.graphics-template
.oth=application/vnd.oasis.opendocument.text-web
.otp=application/vnd.oasis.opendocument.presentation-template
.ots=application/vnd.oasis.opendocument.spreadsheet-template
.ott=application/vnd.oasis.opendocument.text-template
.p7b=application/x-pkcs7-certificates
.p7r=application/x-pkcs7-certreqresp
.package=application/vnd.autopackage
.pfr=application/font-tdpfr
.pkg=vnd.apple.installer xml
.pdf=application/pdf
.pko=application/vnd.ms-pki.pko
.pl=application/x-perl
.pnq=application/x-icq-pnq
.pot=application/mspowerpoint
.pps=application/mspowerpoint
.ppt=application/mspowerpoint
.ppz=application/mspowerpoint
.ps=application/postscript
.pub=application/x-mspublisher
.qpw=application/x-quattropro
.qtl=application/x-quicktimeplayer
.rar=application/rar
.rdf=application/rdf xml
.rjs=application/vnd.rn-realsystem-rjs
.rm=application/vnd.rn-realmedia
.rmf=application/vnd.rmf
.rmp=application/vnd.rn-rn_music_package
.rmx=application/vnd.rn-realsystem-rmx
.rnx=application/vnd.rn-realplayer
.rpm=application/x-redhat-package-manager
.rsml=application/vnd.rn-rsml
.rtsp=application/x-rtsp
.rss=application/rss xml
.scm=application/x-icq-scm
.ser=application/java-serialized-object
.scd=application/x-msschedule
.sda=application/vnd.stardivision.draw
.sdc=application/vnd.stardivision.calc
.sdd=application/vnd.stardivision.impress
.sdp=application/x-sdp
.setpay=application/set-payment-initiation
.setreg=application/set-registration-initiation
.sh=application/x-sh
.shar=application/x-shar
.shw=application/presentations
.sit=application/x-stuffit
.sitx=application/x-stuffitx
.skd=application/x-koan
.skm=application/x-koan
.skp=application/x-koan
.skt=application/x-koan
.smf=application/vnd.stardivision.math
.smi=application/smil
.smil=application/smil
.spl=application/futuresplash
.ssm=application/streamingmedia
.sst=application/vnd.ms-pki.certstore
.stc=application/vnd.sun.xml.calc.template
.std=application/vnd.sun.xml.draw.template
.sti=application/vnd.sun.xml.impress.template
.stl=application/vnd.ms-pki.stl
.stw=application/vnd.sun.xml.writer.template
.svi=application/softvision
.sv4cpio=application/x-sv4cpio
.sv4crc=application/x-sv4crc
.swf=application/x-shockwave-flash
.swf1=application/x-shockwave-flash
.sxc=application/vnd.sun.xml.calc
.sxi=application/vnd.sun.xml.impress
.sxm=application/vnd.sun.xml.math
.sxw=application/vnd.sun.xml.writer
.sxg=application/vnd.sun.xml.writer.global
.tar=application/x-tar
.tcl=application/x-tcl
.tex=application/x-tex
.texi=application/x-texinfo
.texinfo=application/x-texinfo
.tbz=application/x-bzip-compressed-tar
.tbz2=application/x-bzip-compressed-tar
.tgz=application/x-compressed-tar
.tlz=application/x-lzma-compressed-tar
.tr=application/x-troff
.trm=application/x-msterminal
.troff=application/x-troff
.tsp=application/dsptype
.torrent=application/x-bittorrent
.ttz=application/t-time
.txz=application/x-xz-compressed-tar
.udeb=application/x-debian-package
.uin=application/x-icq
.urls=application/x-url-list
.ustar=application/x-ustar
.vcd=application/x-cdlink
.vor=application/vnd.stardivision.writer
.vsl=application/x-cnet-vsl
.wcm=application/vnd.ms-works
.wb1=application/x-quattropro
.wb2=application/x-quattropro
.wb3=application/x-quattropro
.wdb=application/vnd.ms-works
.wks=application/vnd.ms-works
.wmd=application/x-ms-wmd
.wms=application/x-ms-wms
.wmz=application/x-ms-wmz
.wp5=application/wordperfect5.1
.wpd=application/wordperfect
.wpl=application/vnd.ms-wpl
.wps=application/vnd.ms-works
.wri=application/x-mswrite
.xfdf=application/vnd.adobe.xfdf
.xls=application/x-msexcel
.xlb=application/x-msexcel
.xpi=application/x-xpinstall
.xps=application/vnd.ms-xpsdocument
.xsd=application/vnd.sun.xml.draw
.xul=application/vnd.mozilla.xul xml
.zoo=application/x-zoo
.zip=application/x-zip-compressed
.wml=text/vnd.wap.wml
.wmlc=application/vnd.wap.wmlc
.wmls=text/vnd.wap.wmlscript
.wmlsc=application/vnd.wap.wmlscriptc
.asm=text/x-asm
.pas=text/x-pascal
.cs=text/x-csharp
.cpp=text/x-c  src
.cxx=text/x-c  src
.cc=text/x-c  src
.hpp=text/x-c  hdr
.hxx=text/x-c  hdr
.hh=text/x-c  hdr
.java=text/x-java
.css=text/css
.js=text/javascript
.htm=text/html
.html=text/html
.xhtml=application/xhtml xml
.xht=application/xhtml xml
.ls=text/javascript
.mocha=text/javascript
.shtml=server-parsed-html
.sgm=text/sgml
.sgml=text/sgml
.mht=message/rfc822
HTTP-EQUIV
()<>@,;:\"./
()<>@,;:\"/[]?=
()<>@,;:\"/[]?={}
*<>#%"{}|\^[]`
*<>#%"{}|\^[]` 
HTTPS
Failed to open database "%s" : %s
Failed to open database "%s" : unknown error
"%s" : %s
Error executing SQL
Could not prepare SQL statement
Error executing SQL statement
select [sql] from sqlite_master where [type] = 'table' and lower(name) = '
SQLite is Busy
<%s> invalid zipfile
Shell.Application
<%s> invalid source
<%s> invalid target folder
%s (%d/%d)
A Port is required
0.0.0.1
Mozilla/3.0 (compatible; Indy Library)
X-HTTP-Method-Override
%d-%d
https
HttpOnly
HTTPONLY=
HTTPONLY
WINDOWS
()[]<>:;.,@\"
%s <%s>
Content-Disposition: form-data; name="%s"
; filename="%s"
Content-Type: %s
; charset="%s"
Content-Transfer-Encoding: %s
libeay32.dll
ssleay32.dll
libssl32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
X509_STORE_add_cert
X509_STORE_CTX_get_current_cert
i2d_DSAPrivateKey
d2i_DSAPrivateKey
d2i_PrivateKey
d2i_PrivateKey_bio
DES_set_key
_ossl_old_des_set_key
RSA_generate_key_ex
RSA_generate_key
RSA_check_key
i2d_PrivateKey_bio
i2d_RSAPrivateKey
d2i_RSAPrivateKey
i2d_RSAPublicKey
d2i_RSAPublicKey
i2d_PrivateKey
i2d_NETSCAPE_CERT_SEQUENCE
X509_get_default_cert_file
X509_get_default_cert_file_env
X509_set_pubkey
X509_REQ_set_pubkey
X509_PUBKEY_get
PEM_read_bio_RSAPrivateKey
PEM_read_bio_RSAPublicKey
PEM_read_bio_DSAPrivateKey
PEM_read_bio_PrivateKey
PEM_read_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_RSAPrivateKey
PEM_write_bio_RSAPublicKey
PEM_write_bio_DSAPrivateKey
PEM_write_bio_PrivateKey
PEM_write_bio_NETSCAPE_CERT_SEQUENCE
PEM_write_bio_PKCS8PrivateKey
EVP_CIPHER_CTX_set_key_length
EVP_CIPHER_CTX_rand_key
EVP_PKEY_type
EVP_PKEY_new
EVP_PKEY_free
EVP_PKEY_assign
EVP_CIPHER_key_length
EVP_CIPHER_CTX_key_length
EVP_PKEY_decrypt_old
EVP_PKEY_encrypt_old
EVP_PKEY_id
EVP_PKEY_base_id
EVP_PKEY_bits
EVP_PKEY_size
EVP_PKEY_set_type
EVP_PKEY_set_type_str
EVP_PKEY_get0
EVP_PKEY_set1_RSA
EVP_PKEY_get1_RSA
EVP_PKEY_set1_DSA
EVP_PKEY_get1_DSA
EVP_PKEY_set1_DH
EVP_PKEY_get1_DH
EVP_PKEY_set1_EC_KEY
EVP_PKEY_get1_EC_KEY
d2i_PublicKey
i2d_PublicKey
d2i_AutoPrivateKey
EVP_PKEY_copy_parameters
EVP_PKEY_missing_parameters
EVP_PKEY_save_parameters
EVP_PKEY_cmp_parameters
EVP_PKEY_cmp
EVP_PKEY_print_public
EVP_PKEY_print_private
EVP_PKEY_print_params
EVP_PKEY_get_default_digest_nid
PKCS5_PBE_keyivgen
PKCS5_v2_PBE_keyivgen
EVP_PKEY_asn1_get_count
EVP_PKEY_asn1_get0
EVP_PKEY_asn1_find
EVP_PKEY_asn1_find_str
EVP_PKEY_asn1_add0
EVP_PKEY_asn1_add_alias
EVP_PKEY_asn1_get0_info
EVP_PKEY_get0_asn1
EVP_PKEY_asn1_new
EVP_PKEY_asn1_copy
EVP_PKEY_asn1_free
EVP_PKEY_asn1_set_public
EVP_PKEY_asn1_set_private
EVP_PKEY_asn1_set_param
EVP_PKEY_asn1_set_free
EVP_PKEY_asn1_set_ctrl
EVP_PKEY_meth_find
EVP_PKEY_meth_new
EVP_PKEY_meth_get0_info
EVP_PKEY_meth_copy
EVP_PKEY_meth_free
EVP_PKEY_meth_add0
EVP_PKEY_CTX_new
EVP_PKEY_CTX_new_id
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_free
EVP_PKEY_CTX_ctrl
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_get_operation
EVP_PKEY_CTX_set0_keygen_info
EVP_PKEY_new_mac_key
EVP_PKEY_CTX_set_data
EVP_PKEY_CTX_get_data
EVP_PKEY_CTX_get0_pkey
EVP_PKEY_CTX_get0_peerkey
EVP_PKEY_CTX_set_app_data
EVP_PKEY_CTX_get_app_data
EVP_PKEY_sign_init
EVP_PKEY_sign
EVP_PKEY_verify_init
EVP_PKEY_verify
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt
EVP_PKEY_derive_init
EVP_PKEY_derive_set_peer
EVP_PKEY_derive
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen
EVP_PKEY_keygen_init
EVP_PKEY_keygen
EVP_PKEY_CTX_set_cb
EVP_PKEY_CTX_get_cb
EVP_PKEY_CTX_get_keygen_info
EVP_PKEY_meth_set_init
EVP_PKEY_meth_set_copy
EVP_PKEY_meth_set_cleanup
EVP_PKEY_meth_set_paramgen
EVP_PKEY_meth_set_keygen
EVP_PKEY_meth_set_sign
EVP_PKEY_meth_set_verify
EVP_PKEY_meth_set_verify_recover
EVP_PKEY_meth_set_signctx
EVP_PKEY_meth_set_verifyctx
EVP_PKEY_meth_set_encrypt
EVP_PKEY_meth_set_decrypt
EVP_PKEY_meth_set_derive
EVP_PKEY_meth_set_ctrl
secur32.dll
security.dll
HTTP/1.0 200 OK
HTTP/
SetupApi.dll
cfgmgr32.dll
7z.dll
Error loading library %s
%s is not a 7z library
%s is not a Format library
XWindow.GetWindowPlacementEvg
XSettings.GetDebugPrivilege
XProcess.IsWow64Process
XFile.LogicalDriveStringsInit
XFile.ExpandRawPath
Psapi.dll
XProcess.GetProcessStartTime
XFile.DeleteFolder
SHFileOperation fail:
XFile.AssignFileW
XFile.WriteLnW
_prev.log
DriverUpdater.dpr
c:\debug.log.pc
ERROR (%s): %s
MESS: %s
PARAMS: %s
LAST_ERR (%d -> %s): %s
LAST_ERR (%d, %s): %s
%s%s%s%s
%s: %s
%s: %s PARAMS: %s
program.log
program_error.log
Multiple errors: %s Count: %d
Multiple logs: %s Count: %d
%s %s
XLog.Execute
c:\debug.pc
CERTANCE
%d.%d.%d.%d
Setupapi.dll
CM_PROB_DRIVER_SERVICE_KEY_INVALID
CM_DEVCAP_LOCKSUPPORTED
CM_DEVCAP_EJECTSUPPORTED
FILE_CHARACTERISTIC_WEBDAV_DEVICE
DNF_INDEXED_DRIVER
SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSettings\
DriverKey=
OpenKey fail
Snapshot.ini
hXXp://d2.smartpcupdate.com/rpc/sendsnapshot
*.status
Ini.UpdateFile fail
Ini.UpdateFile fail 2
Scan.ini
DevicesPlus.ini
.status
5.2.3790.
5.1.2600.
6.0.6000.
6.0.6001.
6.0.6002.
6.1.6002.
6.1.7100.
6.1.7600.
6.1.7601.
6.2.8400.
6.2.9200.
6.3.9600.
6.3.9431.
10.0.10240.
EnumKey=
SetupDiEnumDriverInfoW fail, EnumKey=
SELECT * FROM hardids JOIN drivers ON hardids.id = drivers.hardid_full_index JOIN files ON files.id = drivers.file_id JOIN vendors ON vendors.id = drivers.vendor_id JOIN versions ON versions.id = drivers.version_id LEFT JOIN installers ON installers.id = drivers.installer_id JOIN devices_descriptions ON devices_descriptions.id = drivers.device_id WHERE hardids.hardid = "%s"
SELECT * FROM hardids JOIN drivers ON hardids.id = drivers.hardid_index JOIN files ON files.id = drivers.file_id JOIN vendors ON vendors.id = drivers.vendor_id JOIN versions ON versions.id = drivers.version_id LEFT JOIN installers ON installers.id = drivers.installer_id JOIN devices_descriptions ON devices_descriptions.id = drivers.device_id WHERE hardids.hardid = "%s"
AND os=%s
Drivers64.db
Drivers32.db
Devices.ini
Cannot delete and rename DevicesPlus.ini file
Cannot delete and rename Scan.ini file
EnumKey
ClassKey
SOFTWARE\Microsoft\Windows\CurrentVersion
DevWebSite
OpenKeyReadOnly 3 fail
OpenKeyReadOnly 3 fail
OpenKeyReadOnly 2 fail
OpenKeyReadOnly 2 fail
{8ECC055D-047F-11D1-A537-0000F8753ED1}
TSWbemLocator.Create fail
EOleException %s %x
wmiLocator.ConnectServer fail
wmiLocator.ConnectServer 2 fail
%s%s%s%s%s%s
%s%s%s
%s%s%s%s%s%s%s%s
TSchedulerStartupRegularItem.ItemRead
SrClient.dll
hXXp://service.smartpcupdate.com/rpc/senddriverstats
TUploadThread.Execute
Ini.UpdateFile fail 1
Ini.UpdateFile fail 1.2
Ini.UpdateFile fail 2.2
Ini.UpdateFile fail 3
Ini.UpdateFile fail 3.2
*.dul
DriverKey empty
GetCurrentSnapshot.OnFail
EnumKey empty
GetCurrentSnapshot.FindDevice fail:
Temp.ini
GetCurrentSnapshot.GetDriverParameters fail:
Device.Scan empty
SaveInstallLogs.AddSetupAPIlogs
Windows=
Devices.Count = 0
setupapi.log
Inf\setupapi.app.log
Inf\setupapi.dev.log
C:\Intel\Logs\IntelChipset.log
explorer.exe
firefox.exe
chrome.exe
iexplore.exe
opera.exe
raptr.exe
msiexec.exe
drvinst.exe
rundll32.exe
setup.exe
IsThereVisibleWindows.EnumWindowsProc
IsThereVisibleWindows
No visible windows for 30 seconds
No visible windows
There are visible windows:
ShellExecuteAndWait: begin: Path=
ShellExecuteAndWait: GetProcessId fail:
ShellExecuteAndWait: lpExecInfo.hProcess = 0:
ShellExecuteAndWait: ShellExecuteEx fail:
readme.txt
installmanagerapp.exe
InstallExeOrMsiDriver: begin: FName=
InstallExeOrMsiDriver: File not found:
InstallExeOrMsiDriver: Install disabled:
autorun.exe
InstallExeOrMsiDriver: CreateProcessAndWait failed
InstallExeOrMsiDriver: ShellExecuteAndWait failed
stub64.exe
newdev.dll
advpack.dll
IncompatibleWindowsLogoError
NonSupportedMethod
advpack.dll,LaunchINFSectionEx "
InstallInfDriver: Direct install advpack.dll,LaunchINFSectionEx success, for
InstallInfDriver: Direct install advpack.dll,LaunchINFSectionEx success but nothing changed, for
InfDefaultInstall.exe
CoreInstall.UnzipCallback
setupapi.log fail
InstallDriverLL.PrepareSystemLogs
IntelChipset.log fail
isInstalling exe/msi from zip: Cancelled
isInstalling exe/msi: Cancelled
empty EnumKey field
.restart
Restart of Windows detected
*.pre
stub64.exe was not found
Driver.CoreInit
CreateBaseIndexes
PCInfo.ini
program_prev.log
program_error_prev.log
TGenerateThread.Execute
TInstallThread.Execute
hXXp://VVV.pcutilitiespro.com
HomePageURL
AfterInstallURL
AfterInstallURLHidden
SupportURL
UninstallURL
BuyNowURL
AdsDownloadURL
AdsBuyNowURL
AdsDownloadURL2
AdsBuyNowURL2
hXXps://safecart.com/pcutilitiespro/.driverpro
hXXp://support.pcutilitiespro.com
hXXp://dejebel.pcutilitiespro.revenuewire.net/optimizerpro/xsell
hXXp://filecdn.avanquest.com/rw/xsell/pcutilitiespro/dejebel/OptimizerPro.exe
%s=%s
msvcrt.dll
.jdbg
madExcept.HandleContactForm
madExcept.HandleScreenshotForm
.madExcept
%exceptMsg%
%bugReport%
Úte%
Útetime%
%computerName%
Þsktop%
%userappdata%
%commonappdata%
cc32110mt.dll
cc32110.dll
screenShot.bmp
madExceptIde_.bpl
mapi32.dll
Tcpip\Parameters
VxD\MSTCP
IpHlpApi.dll
.jpeg
winhttp.dll
WinHttpOpen
WinHttpConnect
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryAuthSchemes
WinHttpSetCredentials
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCloseHandle
hXXps://
hXXp://
%userappdata%\
BugReport
screenShot.png
operating system
<tr><td><button onClick="history.back();" style="height:19.5pt;"> 
<button onClick="document.getElementById('bugReport').style.visibility='visible';this.style.visibility='hidden';" style="height:19.5pt;"> 
<textarea id="bugReport" readonly cols="80" rows="20" style="width:100%;height:100%;
wtsapi32.dll
Software\Microsoft\Windows
idapi32.dll
GetThreadReport
GetCpuRegisters
kernelbase.dll
madExcept32.dll
c:\sources\madshi\madExcept32.dll
\madExcept\Dlls\madExcept32.dll
ReportLeaksNow
GetLeakReport
ShowLeakReport
madExcept32.dll has the wrong version.
ReportFault
@System@@StartExe$qqrp23System@PackageInfoTablep17System@TLibModule
%Program Files% (x86)\Mozilla Firefox\firefox.exe
%Program Files%\Mozilla Firefox\firefox.exe
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
PathToExe
%Program Files% (x86)\Google\Chrome\Application\chrome.exe
%Program Files%\Google\Chrome\Application\chrome.exe
C:\Users\
\AppData\Local\Google\Chrome\Application\chrome.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
%Program Files% (x86)\Internet Explorer\iexplore.exe
%Program Files%\Internet Explorer\iexplore.exe
Software\Opera Software
\opera.exe
\launcher.exe
%Program Files% (x86)\Opera\Opera.exe
%Program Files%\Opera\Opera.exe
%Program Files% (x86)\Opera\launcher.exe
%Program Files%\Opera\launcher.exe
BrowserExe
%Program Files% (x86)\Safari\Safari.exe
%Program Files%\Safari\Safari.exe
http\shell\open\command
SOFTWARE\Microsoft\Windows\CurrentVersion\Settings\Driver Pro
hXXp://service.smartpcupdate.com/rpc/sendinstall?partner=
URLParams
hXXps://gen.securedshopgate.com/?b=11
Tray.exe
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
SOFTWARE\Microsoft\Windows\CurrentVersion\OEMInformation
\oeminfo.ini
Check the email you received after you purchased the product for the correct license key.
Your license key will look like this:
hXXp://service.smartpcupdate.com/rpc/sendspmpurchase
hXXp://service.smartpcupdate.com/rpc/sendpurchase
&key=
hXXp://service.smartpcupdate.com/rpc/sendspminstall
hXXp://service.smartpcupdate.com/rpc/sendspmuninstall
hXXp://service.smartpcupdate.com/rpc/sendinstall
hXXp://service.smartpcupdate.com/rpc/senduninstall
%s is a separate product and requires a different license key.
Enter License Key
Please enter your %s license key below. You would have received the license key in your purchase confirmation email. Please note, your license key is formatted as %d sets of %d characters (i.e., %s).
If you already have a License Key, please enter it in the form below and click "Activate Now".
We recommend that you upgrade to the full version of %s
To purchase %s and obtain a license key click
The license key you entered is for %s.
This key was already used! Please enter another key!
UsedKey
Licensing key has reached its usage limit!
Thank you for registering %s!
Register %s now to download and install new drivers.
Would you like to register %s?
Current Windows version
Backuped driver Windows version
We NOT reccomend your use this driver for current Windows version.
5 (Windows XP)
6 (Windows Vista)
7 (Windows 7)
8 (Windows 8)
CreateBaseIndexesOld
ProxyPort
ProxyLogin
hXXp://service.smartpcupdate.com/rpc/getdatabasecxw?arch=%d&os=%d
hXXp://service.smartpcupdate.com/rpc/getdatabasezxw?arch=%d&os=%d
hXXp://service.smartpcupdate.com/rpc/getdatabasex%d_wd
TForm4a.Button2Click
IdHTTP1.Get 1 fail
IdHTTP1.Head fail
IdHTTP1.Get 2 fail
Drivers32prev.db
Drivers64prev.db
Drivers.db
CreateBaseIndexes success
SetupFiles.txt
IdRead() method of TIdTCPStream class does not support seeking
Block passed to TIdDecoderBinHex4.Decode is missing a starting colon :
Block passed to TIdDecoderBinHex4.Decode is missing a terminating colon :
Data passed to TIdEncoderBinHex4.Encode is missing a filename
\/:*?"<>|
Importance
PIPELINING
LOGIN
smtp
Report a problem with a new driver!
mail.smartpctools.com
[email protected]
13-10-2015 14-03
[email protected]
[email protected]
report.zip
Your feedback is very valuable and will help us create better products. Please let us know why you did not register %s:
%s did not find the driver I was looking for
hXXp://service.smartpcupdate.com/rpc/feedback?reason=
TDeviceEntry.GetIcon
TDriversList.Scan
TDriversList.ScanPreFiles
Keyboard
Ports
MultiPortSerial
XInternet.LoadInternetData
HttpOpenRequest timeout:
HttpOpenRequest fail
HttpSendRequest fail:
HttpSendRequest timeout:
HttpQueryInfo HTTP_QUERY_STATUS_CODE fail:
HttpQueryInfo HTTP_QUERY_CONTENT_LENGTH fail:
Mozilla/5.0
XInternet.CloseInternet
XInternet.ConnectToInternet
URL is empty
URL is not trimmed
Cannot open the URL
To immediately download and fix these drivers you need to renew your %s subscription.
Your %s subscription will expire in NN days.
hXXp://service.smartpcupdate.com/rpc/candownloadfiles?partner=
English.ini
French.ini
German.ini
Spanish.ini
Italian.ini
Portuguese.ini
Danish.ini
Dutch.ini
Swedish.ini
Polish.ini
Russian.ini
Brazilian.ini
Finnish.ini
Norwegian.ini
Japanese.ini
Chinese.ini
Czech.ini
Arabic.ini
Product information and support link
InstallLog.ini
UpdateWindowShown
StartWithWindows
s_SmartExec
Software\Microsoft\Windows\CurrentVersion\Settings\
UserKey
TForm1a.WMQueryEndSession
Vendors.txt
ScanExecuted
Scan.gif
TForm1a.Callback: incorrect Status
drivers.db
Exclusions.txt
1.0.0.0
%d new drivers in %d driver packages found for your computer
hXXp://update1.smartpcupdate.com/rpc/getlastupdate
hXXp://service.smartpcupdate.com/rpc/getstatus?exedate=
hXXp://update1.smartpcupdate.com/rpc/sendinstall?partner=
hXXp://update1.smartpcupdate.com/rpc/sendreport?filename=
hXXp://update1.smartpcupdate.com/rpc/sendstats?partner=
This version is no longer supported!
UpdateList.txt
SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
hXXp://VVV.google.com/search?hl=en&q=
.SYS.DLL.INF.CAT.NFO.EXE.REG.AX.DRV.CPL
RUNDLL32.EXE
LAYOUT.INF
regedit.exe
Backups.ini
\Enum.reg" "HKEY_LOCAL_MACHINE\
\Classes.reg" "HKEY_LOCAL_MACHINE\
\*.inf
\Log.txt
/s zipfldr.dll
regsvr32.exe
\.zip\CompressedFolder\ShellNew
\Classes.reg
\Classes.reg"
\Enum.reg
\Enum.reg"
*.exe
AUTORUN.EXE
32.EXE
64.EXE
*.inf
01-01-2012
TForm1a.InstallCallback
RunExe
TForm1a.HTTP1Start
hXXp://service.smartpcupdate.com/downloads/
Form1a.HTTP1Start
TForm1a.HTTP2Start
Form1a.HTTP2Start
TForm1a.HTTP3Start
Form1a.HTTP3Start
TForm1a.HTTP4Start
Form1a.HTTP4Start
TForm1a.HTTP5Start
Form1a.HTTP5Start
TForm1a.HTTP1Work
TForm1a.HTTP2Work
TForm1a.HTTP3Work
TForm1a.HTTP4Work
TForm1a.HTTP5Work
s_Exec
Backup\*.*
Drivers\*.*
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HomePage.url
Portable Network Graphics
::{26EE0668-A00A-44D7-9371-BEB064C98683}
EasyListview.Header
Kernel32.dll
Open SSL Support DLL Delphi and C  Builder interface
hXXp://VVV.indyproject.org/
1993 - 2014
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s
optimizerpro.exe
Optimizer Pro\OptimizerPro.exe
CreateBaseIndexes fail
66006666
TFRMCHECKURL
,Unsupported Application Extension block size
Unknown GIF block type'Object type not supported for operation
Unsupported PixelFormat
Invalid stream operation
!Do AcquireCredentialsHandle first"CompleteAuthToken is not supported
Unsupported GIF version
Invalid extension introducerúiled to allocate memory for GIF DIB
The domain controller certificate used for smartcard logon has been revoked. Please contact your system administrator with the contents of your system event log.IA signature operation must be performed before the user can authenticate.AOne or more of the parameters passed to the function was invalid.DClient policy does not allow credential delegation to target server.bClient policy does not allow credential delegation to target server with NLTM only authentication.1The recipient rejected the renegotiation request.-The required security context does not exist.`The PKU2U protocol encountered an error while attempting to utilize the associated certificates.:The identity of the server computer could not be verified.
Unknown error#SSPI %s returns error #%d(0x%x): %s0SSPI interface has failed to initialise properly
The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation.7Client's supplied SSPI channel bindings were incorrect.9The received certificate was mapped to multiple accounts.
SEC_E_NO_KERB_KEY5The certificate is not valid for the requested usage.
The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.
An untrusted certificate authority was detected While processing the smartcard certificate used for authentication. Please contact your system administrator.
The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.lThe smartcard certificate used for authentication was not trusted. Please contact your system administrator.hThe smartcard certificate used for authentication has expired. Please contact your system administrator.
The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user.
An attempt was made by this server to make a Kerberos constrained delegation request for a target outside of the server's realm. This is not supported, and indicates a misconfiguration on this server's allowed to delegate to list. Please contact your administrator.
The revocation status of the domain controller certificate used for smartcard authentication could not be determined. There is additional information in the system event log. Please contact your system administrator.
An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Please contact your system administrator.
The domain controller certificate used for smartcard logon has expired. Please contact your system administrator with the contents of your system event log.
mThe client is trying to negotiate a context and the server requires user-to-user but didn't send a TGT reply.aUnable to accomplish the requested task because the local machine does not have any IP addresses.bThe supplied credential handle does not match the credential associated with the security context.]The crypto system or checksum function is invalid because a required function is unavailable.9The number of maximum ticket referrals has been exceeded.KThe local machine must be a Kerberos KDC (domain controller) and it is not.qThe other end of the security negotiation is requires strong crypto but it is not supported on the local machine.5The KDC reply contained more than one principal name.OExpected to find PA data for a hint of what etype to use, but it was not found.
The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Please contact your administrator.-Smartcard logon is required and was not used.!A system shutdown is in progress.'An invalid request was sent to the KDC.DThe KDC was unable to generate a referral for the service requested.:The encryption type requested is not supported by the KDC.QAn unsupported preauthentication mechanism was presented to the Kerberos package.
The credentials supplied were not complete, and could not be verified. Additional information can be returned from the context.4The context data must be renegotiated with the peer.'The target principal name is incorrect.:There is no LSA mode context associated with this context.8The clocks on the client and server machines are skewed.;The certificate chain was issued by an untrusted authority.7The message received was unexpected or badly formatted.;An unknown error occurred while processing the certificate.%The received certificate has expired.*The specified data could not be encrypted.*The specified data could not be decrypted.YThe client and server cannot communicate, because they do not possess a common algorithm.
The security context could not be established due to a failure in the requested quality of service (e.g. mutual authentication or delegation).dA security context was deleted before the context was completed. This is considered a logon failure.^The security package is not able to marshall the logon buffer, so the logon attempt has failedNThe per-message Quality of Protection is not supported by the security package?The security context does not allow impersonation of the client
The logon attempt failed;The credentials supplied to the package were not recognized4No credentials are available in the security packageCThe message or signature supplied for verification has been altered8The message supplied for verification is out of sequence3No authority could be contacted for authentication.UThe function completed successfully, but must be called again to complete the contextEThe function completed successfully, but CompleteToken must be calledtThe function completed successfully, but both CompleteToken and this function must be called to complete the contextsThe logon was completed, but no network authority was available. The logon was made using locally known information-The requested security package does not exist2The context has expired and can no longer be used.DThe supplied message is incomplete. The signature was not verified.
The handle specified is invalid'The function requested is not supported.The specified target is unknown or unreachable0The Local Security Authority cannot be contacted-The requested security package does not exist6The caller is not the owner of the desired credentialsBThe security package failed to initialize, and cannot be installed-The token supplied to the function is invalid
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Failed to load %s.
SSL status: "%s"
%s Alert
%s Read Alert
%s Write Alert
Host field is empty*SSL IOHandler is required for this setting8This value can not be set while the client is connected.$SSL is not available on this server.%Start SSL negotiation command failed.
Unsupported operation./Could not encode header data using charset "%s"
Unknown Protocol(Request method requires HTTP version 1.1KUnsupported hash algorithm. This implementation supports only MD5 encoding.<TIdMessagePart can not be created. Use descendant classes.
Attachment %s is blocked.$Error accepting connection with SSL.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Reply Code is not valid: %s
Reply Code already exists: %s
IOHandler value is not valid'Algorithm %s not permitted in FIPS mode The specified SASL handlers are not ready!!5Doesn't support AUTH or the specified SASL handlers!!'Need SASL mechanisms to login with it!!
File "%s" not found
Object type not supported.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.
QRequest rejected because the client program and identd report different user-ids.
Command not supported.
Address type not supported."%s: Circular links are not allowed"Not enough data in buffer. (%d/%d)
1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
End of stream: Class %s at %d)UDP is not support in this SOCKS version.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Socket operation on non-socket.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Resolving hostname %s.
Connecting to %s.
Socket Error # %d
Operation would block.
Operation now in progress.
Operation already in progress.
OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Invalid destination array"Character index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid codepage (%d)4Failed attempting to retrieve time zone information.-Error on call to Winsock2 library function %s&Error on loading Winsock2 library (%s)BThe "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it againnThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.]The program tried to add a existent critical chunk to the current image which is not allowed.IIt's not allowed to add a new chunk because the current image is invalid.7The png image could not be loaded from the resource ID.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
Button%d
RadioButton%d
Invalid owner=This control requires version 4.70 or greater of COMCTL32.DLL
Date exceeds maximum of %s
Date is less than minimum of %s4You must be in ShowCheckbox mode to set to this date#Failed to set calendar date or timeúiled to set maximum selection range$Failed to set calendar min/max rangeúiled to set calendar selected rangejThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.
Value*A key with the name of "%s" already exists
Key "%s" not found%goColMoving is not a supported option%Key may not contain equals sign ("=")
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"%s requires Windows Vista or later %s requires themes to be enabled
Value must be between %d and %d
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard: %s
Text exceeds memo capacity/Menu '%s' is already being used by another form
Grid too large for operation Too many rows or columns deleted
Invalid input value7Invalid input value. Use escape key to abandon changes
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
%s property out of range
Scan line index out of range!Cannot change the size of an iconÊnnot change the size of a WIC Image Invalid operation on TOleGraphic
Unsupported clipboard format
#''%s'' is not a valid integer value
''%s'' is not a valid time
No help found for context %d
No help found for %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread2Cannot call Start on a running or suspended thread
The specified path is too long The specified path was not found The path format is not supported The specified file was not found
?$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and <= %drHigh surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properlyrLow surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly
''%s'' is not a valid date#''%s'' is not a valid date and time
List index out of bounds (%d) Out of memory while expanding memory stream)%s has not been registered as a COM class
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
Start index out of bounds (%d)
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
External exception %x
Interface not supported
Object lock not owned(Monitor support function not initialized
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported('%s' is not a valid floating point value!'%s' is not a valid date and time '%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
I/O error %d
Integer overflow Invalid floating point operation
3.1.0.5


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:2012
    DriverPro.exe:1484
    drvprosetup.exe:232
    drvprosetup.tmp:1832
    DPStartScan.exe:1996

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Documents and Settings%\%current user%\Local Settings\Temp\drvprosetup.exe (454607 bytes)
    %Documents and Settings%\%current user%\NTUSER.DAT.LOG (5208 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\etilqs_jLDCvLgEjiD7ShN (1484853 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\etilqs_MpZWKYVP4aw52Mg (1484745 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers32.db-journal (8674 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\Scan.ini (227 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\Snapshot.ini (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\PCInfo.ini (151 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\current_5_32_cxw.7z (15021 bytes)
    %WinDir%\setupapi.log (3760 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\DevicesPlus.ini (3 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\Drivers.db (154783 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\Devices.ini (224 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\etilqs_cu612yBGA7qsgvd (2177340 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\program.log (2355 bytes)
    %Program Files%\Driver Pro\HomePage.url (121 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\is-IHCAK.tmp\drvprosetup.tmp (7386 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\is-EKFN1.tmp (4 bytes)
    %Program Files%\Driver Pro\is-6PIV0.tmp (13 bytes)
    %Program Files%\Driver Pro\is-VHBVB.tmp (6841 bytes)
    %Documents and Settings%\%current user%\Desktop\Driver Pro.lnk (701 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Uninstall Driver Pro.lnk (734 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Help.lnk (713 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\_isetup\_shfoldr.dll (23 bytes)
    %Program Files%\Driver Pro\is-5TF5P.tmp (9605 bytes)
    %Program Files%\Driver Pro\unins000.msg (646 bytes)
    %Program Files%\Driver Pro\is-K8K84.tmp (4185 bytes)
    %Program Files%\Driver Pro\unins000.dat (10580 bytes)
    %Program Files%\Driver Pro\is-COEU5.tmp (1425 bytes)
    %Program Files%\Driver Pro\is-7KEB1.tmp (14022 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro.lnk (713 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro on the Web.lnk (708 bytes)
    %Program Files%\Driver Pro\is-14QTC.tmp (547 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\is-8B1IU.tmp\DrvProHelper.dll (7971 bytes)
    %Documents and Settings%\%current user%\Application Data\Driver Pro\is-E206L.tmp (61 bytes)
    %Program Files%\Driver Pro\is-GO5M7.tmp (26 bytes)
    %Program Files%\Driver Pro\is-KLAVF.tmp (7971 bytes)
    %Program Files%\Driver Pro\is-C3PED.tmp (31745 bytes)
    %Program Files%\Driver Pro\is-JPJNV.tmp (35505 bytes)
    %Program Files%\Driver Pro\is-3MTUP.tmp (54 bytes)
    %Program Files%\Driver Pro\is-8B5PP.tmp (56 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Driver Pro" = "%Program Files%\Driver Pro\DPLauncher.exe"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now