not-a-virus:AdWare.Win32.OpenCandy.aq (Kaspersky), Trojan.NSIS.StartPage.FD, Trojan.Win32.BHO.FD, Trojan.Win32.Ransom.FD, Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)Behaviour: Ransom, Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 431ce28a13c102f094e0ddd1e6c8a023
SHA1: c0ac53c76f25a1c4adb02360b998e2de163f8aa9
SHA256: fb7933db75604bfe00dc9e2dd533e122f350e39fa29c23a1e26905b69f7519fe
SSDeep: 393216:8VylAQ4kOJxPVtDn3Xej2NjLMs2MqdWTkXr0kIHGbZ:8glApjPv6aNKWgXdIw
Size: 12732963 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2011-05-28 19:04:29
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
DAEMONLite4.41.exe:3616
sidebar.exe:1808
%original file name%.exe:1796
rundll32.exe:3972
DrvInst.exe:2628
DrvInst.exe:3532
DrvInst.exe:4052
SetupHelper.exe:2904
regsvr32.exe:1428
The Trojan injects its code into the following process(es):
DT_free_Rus_YandexBar1022.exe:2792
DTLite4413-0173.exe:1672
irsetup.exe:2296
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process DAEMONLite4.41.exe:3616 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)
The process %original file name%.exe:1796 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\เครà¸â€Âิต.txt (133 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_337648 (0 bytes)
The process DrvInst.exe:2628 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\inf\setupapi.dev.log (478 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Windows\Temp\Tar4716.tmp (2712 bytes)
C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
C:\Windows\Temp\Tar4659.tmp (2712 bytes)
C:\Windows\Temp\Tar4598.tmp (2712 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab45E7.tmp (48 bytes)
C:\Windows\Temp\Tar4628.tmp (2712 bytes)
C:\Windows\Temp\Cab4658.tmp (48 bytes)
C:\Windows\Temp\Cab4627.tmp (48 bytes)
C:\Windows\Temp\Cab4715.tmp (48 bytes)
C:\Windows\inf\oem10.PNF (7501 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
C:\Windows\Temp\Cab4597.tmp (48 bytes)
The Trojan deletes the following file(s):
C:\Windows\Temp\Tar4716.tmp (0 bytes)
C:\Windows\Temp\Tar45E8.tmp (0 bytes)
C:\Windows\Temp\Tar4659.tmp (0 bytes)
C:\Windows\Temp\Tar4598.tmp (0 bytes)
C:\Windows\Temp\Cab45E7.tmp (0 bytes)
C:\Windows\Temp\Tar4628.tmp (0 bytes)
C:\Windows\Temp\Cab4658.tmp (0 bytes)
C:\Windows\Temp\Cab4627.tmp (0 bytes)
C:\Windows\Temp\Cab4715.tmp (0 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (0 bytes)
C:\Windows\Temp\Cab4597.tmp (0 bytes)
The process DrvInst.exe:3532 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
C:\Windows\System32\DriverStore\infpub.dat (252 bytes)
C:\Windows\Temp\Tar415A.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
C:\Windows\Temp\Tar4127.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (4 bytes)
C:\Windows\Temp\Tar417B.tmp (2712 bytes)
C:\Windows\inf\oem10.inf (1 bytes)
C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
C:\Windows\Temp\Tar4139.tmp (2712 bytes)
C:\Windows\Temp\Cab417A.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab4138.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
C:\Windows\Temp\Cab4126.tmp (48 bytes)
C:\Windows\Temp\Cab40C7.tmp (48 bytes)
C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
C:\Windows\Temp\Cab4159.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)
The Trojan deletes the following file(s):
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (0 bytes)
C:\Windows\Temp\Tar415A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (0 bytes)
C:\Windows\Temp\Tar4127.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (0 bytes)
C:\Windows\Temp\Tar417B.tmp (0 bytes)
C:\Windows\Temp\Tar4139.tmp (0 bytes)
C:\Windows\Temp\Cab417A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.sys (0 bytes)
C:\Windows\Temp\Cab4138.tmp (0 bytes)
C:\Windows\Temp\Cab4126.tmp (0 bytes)
C:\Windows\Temp\Cab40C7.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.inf (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.cat (0 bytes)
C:\Windows\Temp\Tar40C8.tmp (0 bytes)
C:\Windows\Temp\Cab4159.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (0 bytes)
The process DrvInst.exe:4052 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\inf\setupapi.dev.log (2324 bytes)
The process DTLite4413-0173.exe:1672 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
%Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
%Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
%Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (844 bytes)
%Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
%Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
%Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
%Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
%Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
%Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
%Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
%Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
%Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.sys (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.inf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.cat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (0 bytes)
The process irsetup.exe:2296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (0 bytes)
Registry activity
The process DAEMONLite4.41.exe:3616 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process sidebar.exe:1808 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings]
"ShowGadgets" = "1"
The process %original file name%.exe:1796 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process rundll32.exe:3972 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process DrvInst.exe:2628 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Security" = "01 00 04 90 00 00 00 00 00 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"dtsoftbus01.sys" = "5"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"ClassGUID" = "{4d36e97d-e325-11ce-bfc1-08002be10318}"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI Miniport" = "42 00 00 00 00 01 00 00 01 01 00 00 19 00 00 00"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Service" = "dtsoftbus01"
"DeviceCharacteristics" = "256"
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Exclusive"
"DeviceType"
"LowerFilters"
"UpperFilters"
The process DrvInst.exe:3532 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD]
"Blob" = "0F 00 00 00 01 00 00 00 20 00 00 00 52 29 BA 15"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"D69B561148F01C77C54578C10926DF5B856976AD"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
The process DrvInst.exe:4052 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultRequestFlags" = "8"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDAAccurate" = "1"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"TypesSupported" = "7"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDASupported" = "1"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI CDROM Class" = "03 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"cdrom.sys" = "1"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"SettingsFromDevice" = "1"
[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"EventMessageFile" = "%SystemRoot%\System32\IoLogMsg.dll"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"ClassGUID" = "{4d36e965-e325-11ce-bfc1-08002be10318}"
"Service" = "cdrom"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultDvdRegion" = "1"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"ReadSizesSupported" = "4294967295"
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"DeviceType"
"DeviceCharacteristics"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PnPSysprep\ServiceStartTypeBackup]
"cdrom"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"LowerFilters"
"UpperFilters"
"Exclusive"
"Security"
The process SetupHelper.exe:2904 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process DTLite4413-0173.exe:1672 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit30]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit62]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit124]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit117]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit114]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit28]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit13]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit40]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit58]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit60]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit17]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit50]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit18]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit82]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.app.log" = "4096"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit113]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"Class" = "dtsoftbus01"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit90]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit120]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdx]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayName" = "DAEMON Tools Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit39]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit111]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"B67DE95D-274B-0C7D-C784-82C002ECA45C" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit26]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite\DefaultIcon]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe,0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit53]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}\Properties]
"Security" = "01 00 0C 90 00 00 00 00 00 00 00 00 00 00 00 00"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit77]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoDisplayClass" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit103]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit81]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit91]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit93]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Minor" = "41"
"Version Release" = "3"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit67]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit97]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit108]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit34]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit101]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mdx]
"(Default)" = "DAEMON.Tools.Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit23]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit116]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit1]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit66]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit2]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit63]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit10]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit96]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit36]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit92]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayIcon" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit5]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit12]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"Path" = "%Program Files%\DAEMON Tools Lite\"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit118]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit4]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit70]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit41]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit7]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit107]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit76]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit71]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit121]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdf]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit119]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit35]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit38]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit25]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit126]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit14]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit110]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit98]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoUseClass" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit83]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit49]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Major" = "4"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit99]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\Config]
"AdapterStateDT" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit42]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit46]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit15]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit44]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit48]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit54]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit68]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit86]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit21]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit80]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite]
"(Default)" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit102]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit84]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit73]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit89]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit106]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit51]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit45]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit75]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit55]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit16]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit20]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit57]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mds]
"(Default)" = "DAEMON.Tools.Lite"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit69]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit19]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit65]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit85]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit22]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mds]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit95]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayVersion" = "4.41.3.0173"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit123]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit6]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit0]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit9]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit105]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit115]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit94]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit78]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit56]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit61]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"Publisher" = "DT Soft Ltd"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit32]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit72]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.dev.log" = "4096"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit104]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite\shell\open\command]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -shellmount %1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit100]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit88]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Path" = "%Program Files%\DAEMON Tools Lite\"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit11]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"AdapterStatus" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit29]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "45"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"client" = "41 3B 13 40 37 80 B7 AF AB 63 56 48 3F BA 8E B6"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit59]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit37]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"URLInfoAbout" = "http://www.daemon-tools.cc/"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit33]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit122]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit31]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"UninstallString" = "%Program Files%\DAEMON Tools Lite\uninst.exe"
[HKCU\Software\DT Soft\DAEMON Tools Pro\Config]
"AutoStart" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit64]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit47]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit79]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit74]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit43]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit109]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit27]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit24]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mdf]
"(Default)" = "DAEMON.Tools.Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit125]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit3]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit8]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit112]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit52]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit87]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun"
The following driver will be automatically launched by the NT Native code (IoInitSystem method):
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"Start" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\%Program Files%\DAEMON Tools Lite]
"DTLite.exe"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
The process regsvr32.exe:1428 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCR\DTGadget.RSS.1]
"(Default)" = "RSS Class"
[HKCR\DTGadget.GadgetControl.1]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.GadgetControl\CurVer]
"(Default)" = "DTGadget.GadgetControl.1"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\HELPDIR]
"(Default)" = "%Program Files%\DAEMON Tools Lite"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
"(Default)" = "DTGadget.GadgetControl"
[HKCR\DTGadget.RSS\CurVer]
"(Default)" = "DTGadget.RSS.1"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\DTGadget.RSS.1\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"Version" = "1.0"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}]
"(Default)" = "IGadgetControl"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}]
"(Default)" = "IRSS"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0]
"(Default)" = "DTGadget 1.0 Type Library"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\0\win32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]
"(Default)" = "DTGadget.GadgetControl.1"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.GadgetControl.1\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\DTGadget.RSS\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"Version" = "1.0"
[HKCR\AppID\{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}]
"(Default)" = "DTGadget"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
"(Default)" = "DTGadget.RSS"
[HKCR\DTGadget.GadgetControl\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"
[HKCR\AppID\DTGadget.DLL]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"(Default)" = "RSS Class"
[HKCR\DTGadget.GadgetControl]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.RSS]
"(Default)" = "RSS Class"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
"(Default)" = "DTGadget.RSS.1"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"ThreadingModel" = "Apartment"
The Trojan deletes the following registry key(s):
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\Programmable]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\Programmable]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]
Dropped PE files
MD5 | File path |
---|---|
fd5b3fbfe4346f45d3764d149afc761a | c:\Program Files\DAEMON Tools Lite\DTCommonRes.dll |
00d0a111a66f1e531f849727a528036b | c:\Program Files\DAEMON Tools Lite\DTGadget32.dll |
62f4fda5c8db21799ca4c30c10046ca7 | c:\Program Files\DAEMON Tools Lite\DTGadget64.dll |
252ff12c709418a7792b593605188cb6 | c:\Program Files\DAEMON Tools Lite\DTHelper.exe |
cea0461aae4b8b6216f164501b1b5a10 | c:\Program Files\DAEMON Tools Lite\DTLite.exe |
f9803b1b1fa3e9d34f309d2dd8db30b5 | c:\Program Files\DAEMON Tools Lite\DTShellHlp.exe |
1bc6ff991384848c588e4ec94512a2fc | c:\Program Files\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe |
f605346de44da5e5037392616d3b919d | c:\Program Files\DAEMON Tools Lite\Engine.dll |
e52159020ed1fe44684f8aa003f2dd40 | c:\Program Files\DAEMON Tools Lite\InstallGadget.exe |
cf0ba43ae03d5dc57e96fa583d26f506 | c:\Program Files\DAEMON Tools Lite\Lang\AFK.dll |
92749b95321bf93e7e285537229feaad | c:\Program Files\DAEMON Tools Lite\Lang\ARA.dll |
c1286d50ea59268af55eb7bc72e9fd30 | c:\Program Files\DAEMON Tools Lite\Lang\BGR.dll |
9d692d85639d0d9fcc8fd8428cb8ff2c | c:\Program Files\DAEMON Tools Lite\Lang\BIH.dll |
98b5f8d3c7f45937fa6b920e51e83782 | c:\Program Files\DAEMON Tools Lite\Lang\CHS.dll |
44def48444c237ca2455b12f020a41d6 | c:\Program Files\DAEMON Tools Lite\Lang\CHT.dll |
1838b84c7cc7529319dd704759d4273e | c:\Program Files\DAEMON Tools Lite\Lang\CSY.dll |
49dfb5b9bc3b193a847f96f72ba7deab | c:\Program Files\DAEMON Tools Lite\Lang\DAN.dll |
7305e2e252ec3ca9809fd3172dd63a68 | c:\Program Files\DAEMON Tools Lite\Lang\DEU.dll |
27d9823928ab2be476b6f07ead03c33c | c:\Program Files\DAEMON Tools Lite\Lang\ELL.dll |
ae1efc111af8c51865f7982cf6563178 | c:\Program Files\DAEMON Tools Lite\Lang\ENU.dll |
e1a42e5f8460ccbd8cd0a389a8798cc7 | c:\Program Files\DAEMON Tools Lite\Lang\ESN.dll |
7731e2156769c740f8a2c31b5e4df534 | c:\Program Files\DAEMON Tools Lite\Lang\FIN.dll |
614fcda9095d370e39209d6d42958fb3 | c:\Program Files\DAEMON Tools Lite\Lang\FRA.dll |
4211100519c955e423215e9a3a08c1d7 | c:\Program Files\DAEMON Tools Lite\Lang\HEB.dll |
9731e2fe05e3da9a66067908f6d3be07 | c:\Program Files\DAEMON Tools Lite\Lang\HRV.dll |
b5ec9c8bb10b4d032c1362463758a25e | c:\Program Files\DAEMON Tools Lite\Lang\HUN.dll |
61c46b0a6fa7e2d189dc104632800be6 | c:\Program Files\DAEMON Tools Lite\Lang\HYE.dll |
70f07f8cc1a4b5fc982df281c543f2a8 | c:\Program Files\DAEMON Tools Lite\Lang\IND.dll |
95b38c347abd82b8b87408434bd16077 | c:\Program Files\DAEMON Tools Lite\Lang\ITA.dll |
d0b2fed29ef162a3a8d736fd40961b3b | c:\Program Files\DAEMON Tools Lite\Lang\JPN.dll |
b3eaa9d656acff1824c20c8248c35e76 | c:\Program Files\DAEMON Tools Lite\Lang\KAT.dll |
5765c1d93c810fa191b2603952d0534f | c:\Program Files\DAEMON Tools Lite\Lang\KOR.dll |
85fa1b1123c4b48671e0da25dacf246b | c:\Program Files\DAEMON Tools Lite\Lang\LTH.dll |
e4d780ef46b04d4e79baf5148f3d8dd9 | c:\Program Files\DAEMON Tools Lite\Lang\LVI.dll |
d02efd07e77c06b994430065b69d2c2f | c:\Program Files\DAEMON Tools Lite\Lang\NLB.dll |
89906933894f18cde773b2325e6bb042 | c:\Program Files\DAEMON Tools Lite\Lang\NOR.dll |
2b58f578d140b24e70ef8382223263b6 | c:\Program Files\DAEMON Tools Lite\Lang\PLK.dll |
f10f25b99d119f70d033aaf1f6e1b172 | c:\Program Files\DAEMON Tools Lite\Lang\PTB.dll |
4e1d52f4c97d3c47325c0e7eea53427a | c:\Program Files\DAEMON Tools Lite\Lang\ROM.dll |
9477befb435d7e49a495785b9e12af0f | c:\Program Files\DAEMON Tools Lite\Lang\RUS.dll |
bbcb4687f9d735db1999e4e3541c2561 | c:\Program Files\DAEMON Tools Lite\Lang\SKY.dll |
0c6d4a502a4a7da18b170d80711ba345 | c:\Program Files\DAEMON Tools Lite\Lang\SLV.dll |
60f3def51db1fb1cb6f0cdd26c517f6f | c:\Program Files\DAEMON Tools Lite\Lang\SRL.dll |
c24c9fc4ac8f4bd44f8e89746cf97cc4 | c:\Program Files\DAEMON Tools Lite\Lang\SVE.dll |
43baa07c3f4326d6783fc05c0f620e8f | c:\Program Files\DAEMON Tools Lite\Lang\TRK.dll |
e29dd8fc5f137994c80629a7ad002d5c | c:\Program Files\DAEMON Tools Lite\Lang\UKR.dll |
d2adc3ee87c7983b34c1d284aad2d163 | c:\Program Files\DAEMON Tools Lite\SPTDinst-x64.exe |
fd62e3b8d7e193ab19e71f26c1fc81b6 | c:\Program Files\DAEMON Tools Lite\SPTDinst-x86.exe |
c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Program Files\DAEMON Tools Lite\dtsoftbus01.sys |
d6cd851869a9a3fbeb2254d3766a9aba | c:\Program Files\DAEMON Tools Lite\imgengine.dll |
92e541cb724a8a0ee3f04469b8099c04 | c:\Program Files\DAEMON Tools Lite\uninst.exe |
a20431e552a37ab90e6cc98ce5ed82d1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe |
d74a7db367d407dec2fcbbd22043a91b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll |
ee6d5584f593fab1c5d3d8e548b7203b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe |
e808a6b7751f6f980f97008d1aeb8036 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe |
cdec84efa7e61e09f8f344f1a151ba59 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe |
4f88bef9204d347c0d1c99d7be7baae8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe |
cf0ba43ae03d5dc57e96fa583d26f506 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll |
92749b95321bf93e7e285537229feaad | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll |
c1286d50ea59268af55eb7bc72e9fd30 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll |
9d692d85639d0d9fcc8fd8428cb8ff2c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll |
98b5f8d3c7f45937fa6b920e51e83782 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll |
44def48444c237ca2455b12f020a41d6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll |
1838b84c7cc7529319dd704759d4273e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll |
49dfb5b9bc3b193a847f96f72ba7deab | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll |
7305e2e252ec3ca9809fd3172dd63a68 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll |
27d9823928ab2be476b6f07ead03c33c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll |
ae1efc111af8c51865f7982cf6563178 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll |
e1a42e5f8460ccbd8cd0a389a8798cc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll |
7731e2156769c740f8a2c31b5e4df534 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll |
614fcda9095d370e39209d6d42958fb3 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll |
4211100519c955e423215e9a3a08c1d7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll |
9731e2fe05e3da9a66067908f6d3be07 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll |
b5ec9c8bb10b4d032c1362463758a25e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll |
61c46b0a6fa7e2d189dc104632800be6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll |
70f07f8cc1a4b5fc982df281c543f2a8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll |
95b38c347abd82b8b87408434bd16077 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll |
d0b2fed29ef162a3a8d736fd40961b3b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll |
b3eaa9d656acff1824c20c8248c35e76 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll |
5765c1d93c810fa191b2603952d0534f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll |
85fa1b1123c4b48671e0da25dacf246b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll |
e4d780ef46b04d4e79baf5148f3d8dd9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll |
d02efd07e77c06b994430065b69d2c2f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll |
89906933894f18cde773b2325e6bb042 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll |
2b58f578d140b24e70ef8382223263b6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll |
f10f25b99d119f70d033aaf1f6e1b172 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll |
4e1d52f4c97d3c47325c0e7eea53427a | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll |
9477befb435d7e49a495785b9e12af0f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll |
bbcb4687f9d735db1999e4e3541c2561 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll |
0c6d4a502a4a7da18b170d80711ba345 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll |
60f3def51db1fb1cb6f0cdd26c517f6f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll |
c24c9fc4ac8f4bd44f8e89746cf97cc4 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll |
43baa07c3f4326d6783fc05c0f620e8f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll |
e29dd8fc5f137994c80629a7ad002d5c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll |
7fbc1cd7de7bc2dc40e9960bd3d3ecc8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe |
959ea64598b9a3e494c00e8fa793be7e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll |
9adb3f7c3d4b623f74c4a17ee665d65f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll |
c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.sys |
c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Windows\System32\drivers\dtsoftbus01.sys |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
DAEMONLite4.41.exe:3616
sidebar.exe:1808
%original file name%.exe:1796
rundll32.exe:3972
DrvInst.exe:2628
DrvInst.exe:3532
DrvInst.exe:4052
SetupHelper.exe:2904
regsvr32.exe:1428 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\เครà¸â€Âิต.txt (133 bytes)
C:\Windows\inf\setupapi.dev.log (478 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Windows\Temp\Tar4716.tmp (2712 bytes)
C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
C:\Windows\Temp\Tar4659.tmp (2712 bytes)
C:\Windows\Temp\Tar4598.tmp (2712 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab45E7.tmp (48 bytes)
C:\Windows\Temp\Tar4628.tmp (2712 bytes)
C:\Windows\Temp\Cab4658.tmp (48 bytes)
C:\Windows\Temp\Cab4627.tmp (48 bytes)
C:\Windows\Temp\Cab4715.tmp (48 bytes)
C:\Windows\inf\oem10.PNF (7501 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
C:\Windows\Temp\Cab4597.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
C:\Windows\Temp\Tar415A.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
C:\Windows\Temp\Tar4127.tmp (2712 bytes)
C:\Windows\Temp\Tar417B.tmp (2712 bytes)
C:\Windows\inf\oem10.inf (1 bytes)
C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
C:\Windows\Temp\Tar4139.tmp (2712 bytes)
C:\Windows\Temp\Cab417A.tmp (48 bytes)
C:\Windows\Temp\Cab4138.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
C:\Windows\Temp\Cab4126.tmp (48 bytes)
C:\Windows\Temp\Cab40C7.tmp (48 bytes)
C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
C:\Windows\Temp\Cab4159.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
%Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
%Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
%Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
%Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
%Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
%Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
%Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
%Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
%Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
%Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
%Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
%Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 72088 | 72192 | 4.546 | 984dfeff737935f78877d3d08b82ef95 |
.rdata | 77824 | 7189 | 7680 | 3.37138 | 0fb0a72395723950e1915d6bf373f506 |
.data | 86016 | 65324 | 512 | 2.43883 | 11ffdfc240c81dfe9d957f6bf1761f00 |
.CRT | 151552 | 16 | 512 | 0.147711 | a5ba361df79e0a565f00bd42dc501625 |
.rsrc | 155648 | 16504 | 16896 | 2.78807 | 4a42d4a1c79a481d4a049c0bb7911c60 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://dt.web-search-home.com/getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A== | 198.16.77.12 |
hxxp://dt.web-search-home.com/download/yandexdtLite | 198.16.77.12 |
hxxp://mirror23.mountspace.com/getfile.php?p=hxxp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe | 188.120.245.109 |
hxxp://web-search-home.com/download/yandexdtLite | 198.16.77.12 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A== HTTP/1.1
Connection: Keep-Alive
Host: dt.web-search-home.com
HTTP/1.1 200 OK
Server: nginx/1.0.15
Date: Sun, 19 Mar 2017 20:50:07 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.3.29
Set-Cookie: PHPSESSID=tmtd9mej8682qtd5kn84kdgja7; path=/; domain=web-search-home.com
Content-Length: 3904
Jhz9HA/OCm0GW6fp9ZcSPDN34A485s78WSH2Jd SS2e96LkhrSzsfWe/aniircng kpRLoZsqhAQv8vCVpKIf08MvKSvlWND8pTpxJea euCVcbwqRQCtsUE vavGJoC630cVWj/iIQHNtvbMPDN9ChUZ66FNi6Cn0I5sEQsCRCGAwt5Tjkb1rnTGMV hGpIrOtC1q924swB3 7RaNPOkIYAco8kr9kFVuFmXRs0sD9UmV13VFwenUxK0H1bbFve5xHdkhoGDFDUDC5adsSfz43jS/TmKtIQm7GEjMZFE7EKZ qAlIjCRV3BBhX /VpWDS4TO9aXEtdHbJq7bsR RldNXvJjl9y du67xyCIwYdaw WJbMzBRGQA fW/WOmpdzUDaY44j5mm1T89qA8UbM18s998P9YW4zZAqmfOAU16hWoG3v/ixsNPAMnKnEzFTdcWLDTD32iNGzbbhPMrB AslbUUtWrqoUvhd/neRJWKWFU4L2roLbhRI0qNGMtKe7YXF9p3EVFCy hSXE5HAV88AV4z0vw4rVop2baNVxyrwrrd8RN9tHVBsVvRvGR5RVb7MeOAX bmXo7d2kPm6n4mLUZWnGLdpojnYK4J70mRW7DL9KStSF2iHuZnUrGTvgSCVlKgT31eba02Ho6iK7AbIYzImgScRxdnNoJzvnnVgH9C8K99Y03AQLBiByudppCDFVxmk IDSxiIF5x5EwKkj2zjZ5h94RsqGB63KFNOmMmowv8s/EZSHGP7lJuLyscLN7rl6qttro6lHpGe6HtT8W3UCKn60EMERHisGRpCFV u3YcdVYSctQrHSwIlZ0Hy1rPNq8iGRrQjpIG/bNBiEd dYIFH7WYyDVsts6 iFDJklN18/Fuw7xXDGm8IPlumykb4ufaT6a/4OstjcX3c9dychuaghoNWiGEXI1QRgzdT6r2T5fvfV4pd0kg9JXIMOTbi62fIikQj9ZnCEo67fG3H0NXE0ZKklKmdjSUaIlGZkKkANicWsbCrKYA3zuKPDJv0lD7WQrP7m8s7Hbv5TawxpRVPSOj2ay1rjIkrSSkXVJECoqEVjloZzYctZJ0D60AoCN4GyxkC8cIwxK4ho/wG8T2mPi31H3iYw0WzSTmkadHNcZggYo6qZOhWOEPPMJJW3uCH5oJs0Loccx OiRChZ2EvQ22jKrM40EPkNEZyNt6ILjRYIZDgJIp4tfq5AMpCwRd24d5TmdVTvlbE43TMuPkP4suVvVKjxGQcLxsQfDSyU7EPSxVS39HgQqsMkAMhXbdoVSGS4Kbrob97ByKsz//02CMpGIA54QOlNEs0nfdhtRBPJwD2tVCW6AYlhUis/1ctmqWJ5pG1rncAPBn8CRTMEpQmBit9T/IjYmPOYB/GgvKFuePlfx1kYTVqP Bb3SIevwVIsMdefhBHn29Ub4KEo9esQiNQ47bpFxpnINyaseLMDvYUx4lR22L1oed4s0a9cJcpokLK/ e5QBRb7frT6ljCDUw lFLrqNjX07iOMJ/0cxdS/tWi
<<< skipped >>>
GET /getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe HTTP/1.1
Connection: Keep-Alive
Host: mirror23.mountspace.com
HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Sun, 19 Mar 2017 20:50:22 GMT
Content-Type: application/octet-stream
Connection: close
X-Powered-By: PHP/5.3.19
Cache-Control:
Pragma:
Content-Disposition: attachment; filename="DT_free_Rus_YandexBar1022.exe"
Content-Transfer-Encoding: binary
Accept-Ranges: bytes
Content-Length: 878208
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^".u.C.&.C.&.C.&..S&.C.&..g&kC.&..f&3C.&.;^&.C.&.C.&.C.&..b&.C.&..W&.C.&..P&.C.&Rich.C.&........................PE..L....v.P.............................O............@..................................Z....@.....................................x....p...............R.......p..$...`...............................p...@............................................text............................... ..`.rdata...V.......X..................@..@.data....1...0......................@....rsrc........p.......,..............@..@.reloc...$...p...&...,..............@..B................................................................................................................................................................................................................................................................................................................................................U..W....9w@t5.G....w].$...@...tR.F..I..tI.F.P.A.P....@..5..t5.F..,..t,.F..#......w6......s...Nt%......u...t.....uJ.M............_].........2...r...8...v.......u....H...v..A......RP....@...VS... ..WP....@._]....I...@.%.@.9.@.l.@.l.@.........................U....$.U..M.SV.u..^..F.W.}..U.3.R.U..U..U..U..U.R.U.RQ.]..]..^...W.E..M.P.....E.$....E......}....M....N...tK..9w.t....r'../v...7u..]..<......t...1...v...8...v..F..u..U..F.Rj.P....@.........u..N...F...t .~..u..N.......F..B.Q...F......._^..[..]...........
<<< skipped >>>
GET /download/yandexdtLite HTTP/1.1
Connection: Keep-Alive
Host: web-search-home.com
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.0.15
Date: Sun, 19 Mar 2017 20:50:22 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/5.3.29
Set-Cookie: PHPSESSID=qq11dd7q3ss3td1dp3d1v6kch6; path=/; domain=web-search-home.com
Location: hXXp://mirror23.mountspace.com/getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe
0..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_1796:
.text
.text
`.rdata
`.rdata
@.data
@.data
@.rsrc
@.rsrc
VSSSSh
VSSSSh
^SShq
^SShq
%.*s(%d)%s
%.*s(%d)%s
COMCTL32.dll
COMCTL32.dll
SHLWAPI.dll
SHLWAPI.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
COMDLG32.dll
COMDLG32.dll
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
ADVAPI32.dll
ADVAPI32.dll
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
WINRAR.SFX
WINRAR.SFX
d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
version="1.0.0.0"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
r%.*s(%d)%s
r%.*s(%d)%s
rtmp%d
rtmp%d
Shell.Explorer
Shell.Explorer
%s %s
%s %s
%s %s %s
%s %s %s
GETPASSWORD1
GETPASSWORD1
%s%s%d
%s%s%d
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%s.%d.tmp
%s.%d.tmp
winrarsfxmappingfile.tmp
winrarsfxmappingfile.tmp
-el -s2 "-d%s" "-p%s" "-sp%s"
-el -s2 "-d%s" "-p%s" "-sp%s"
__tmp_rar_sfx_access_check_%u
__tmp_rar_sfx_access_check_%u
sfxcmd
sfxcmd
riched20.dll
riched20.dll
riched32.dll
riched32.dll
Extracting %s
Extracting %s
c:\%original file name%.exe
c:\%original file name%.exe
Enter password
Enter password
&Enter password for the encrypted file:
&Enter password for the encrypted file:
Skipping %s
Skipping %s
The file "%s" header is corrupt%The archive comment header is corrupt
The file "%s" header is corrupt%The archive comment header is corrupt
Unknown method in %s
Unknown method in %s
Cannot open %s
Cannot open %s
Cannot create %s
Cannot create %s
Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password.
Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password.
CRC failed in %s
CRC failed in %s
Packed data CRC failed in %s
Packed data CRC failed in %s
Wrong password for %s5Write error in the file %s. Probably the disk is full
Wrong password for %s5Write error in the file %s. Probably the disk is full
Read error in the file %s
Read error in the file %s
Extracting from %s
Extracting from %s
ErroraErrors encountered while performing the operation
ErroraErrors encountered while performing the operation
Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt.
Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt.
Extracting files to %s folder$Extracting files to temporary folder
Extracting files to %s folder$Extracting files to temporary folder
=Total path and file name length must not exceed %d characters
=Total path and file name length must not exceed %d characters
conhost.exe_3496:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
GDI32.dll
GDI32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
ntdll.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
KERNEL32.dll
IMM32.dll
IMM32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
Cannot allocate 0n%d bytes
|%SWj
|%SWj
O.fBf;
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
FTPh
\>.Sj
\>.Sj
GetKeyboardLayout
GetKeyboardLayout
MapVirtualKeyW
MapVirtualKeyW
VkKeyScanW
VkKeyScanW
GetKeyboardState
GetKeyboardState
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExW
SetWindowsHookExW
GetKeyState
GetKeyState
ActivateKeyboardLayout
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
GetKeyboardLayoutNameW
_amsg_exit
_amsg_exit
_acmdln
_acmdln
ShipAssert
ShipAssert
NtReplyWaitReceivePort
NtReplyWaitReceivePort
NtCreatePort
NtCreatePort
NtEnumerateValueKey
NtEnumerateValueKey
NtQueryValueKey
NtQueryValueKey
NtOpenKey
NtOpenKey
NtAcceptConnectPort
NtAcceptConnectPort
NtReplyPort
NtReplyPort
SetProcessShutdownParameters
SetProcessShutdownParameters
GetCPInfo
GetCPInfo
conhost.pdb
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%$%a%b%V%U%c%Q%W%]%\%[%
%
%
version="5.1.0.0"
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
name="Microsoft.Windows.ConsoleHost"
name="Microsoft.Windows.ConsoleHost.SystemDefault"
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
:>@>
:>@>
2%2X2
2%2X2
%SystemRoot%
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
WindowSize
ColorTableu
ColorTableu
ExtendedEditkeyCustom
ExtendedEditkeyCustom
ExtendedEditKey
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
\ !:=/.;|&
\ !:=/.;|&
%d/%d
%d/%d
cmd.exe
cmd.exe
desktop.ini
desktop.ini
\console.dll
\console.dll
%d/%d
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
CONHOST.EXE
Windows
Windows
Operating System
Operating System
6.1.7601.17641
6.1.7601.17641
DAEMONLite4.41.exe_3616:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
diu2.iu
diu2.iu
Advapi32.dll
Advapi32.dll
irsetup.exe
irsetup.exe
Could not determine a temp directory name. Try running setup.exe /T:
Could not determine a temp directory name. Try running setup.exe /T:
c:\temp
c:\temp
%s\irsetup.exe
%s\irsetup.exe
%s%s_%d
%s%s_%d
"__IRSID:%s"
"__IRSID:%s"
"__IRCT:%d"
"__IRCT:%d"
"__IRAFN:%s"
"__IRAFN:%s"
__IRAOFF:%u
__IRAOFF:%u
KERNEL32.DLL
KERNEL32.DLL
mscoree.dll
mscoree.dll
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
kernel32.dll
kernel32.dll
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
operator
operator
KERNEL32.dll
KERNEL32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
USER32.dll
USER32.dll
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteExA
ShellExecuteExA
SHELL32.dll
SHELL32.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe
%xERRj3cqZQ
%xERRj3cqZQ
! !!####0
! !!####0
;;;9551%%0
;;;9551%%0
! !!565665@
! !!565665@
version="8.1.1000.0"
version="8.1.1000.0"
name="setup.exe"/>
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
04090000
04090000
VVV.u-soft.org
VVV.u-soft.org
0.0.0.0
0.0.0.0
suf80_launch.exe
suf80_launch.exe
irsetup.exe_2296:
`.rsrc
`.rsrc
FtPh
FtPh
FtPhu
FtPhu
SSSSh
SSSSh
SSh`UQ
SSh`UQ
SSh4UQ
SSh4UQ
SShlTQ
SShlTQ
SShDTQ
SShDTQ
u1SSh
u1SSh
Su%Sh
Su%Sh
SShx`Q
SShx`Q
txSSh
txSSh
SSh _Q
SSh _Q
@ SSh
@ SSh
.hPsQ
.hPsQ
SSShDxQ
SSShDxQ
9^$u&SSSSh?
9^$u&SSSSh?
u SSSSh?
u SSSSh?
9^$u)SSSSh?
9^$u)SSSSh?
u.VWS
u.VWS
WSSh|DQ
WSSh|DQ
udPQ
udPQ
t.Ht Ht(Ht
t.Ht Ht(Ht
y2SSh
y2SSh
FHSSh
FHSSh
GHSSh
GHSSh
GTSSh
GTSSh
G\SSh
G\SSh
FlSSh
FlSSh
Nt.Nt
Nt.Nt
SShlSR
SShlSR
tjSShHSR
tjSShHSR
t;SSh$SR
t;SSh$SR
F
F
t'SShl
t'SShl
u$SShe
u$SShe
aSSSh
aSSSh
.VVVVVSRSSj
.VVVVVSRSSj
FTPjK
FTPjK
FtPj;
FtPj;
C.PjRV
C.PjRV
diu2.iuz
diu2.iuz
MSG_ERROR
MSG_ERROR
%s %d. %s
%s %d. %s
MSG_ASK_FOR_DISK
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM_ABORT
MSG_CONFIRM
MSG_CONFIRM
A%s.%d
A%s.%d
%s, Line %d: %s
%s, Line %d: %s
File condition evaluation for file "%s"
File condition evaluation for file "%s"
C:\temp\SUF_SFX_TEST\
C:\temp\SUF_SFX_TEST\
msi.dll
msi.dll
\msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
Software\Microsoft\Windows\CurrentVersion\Installer
MSG_INITIALIZING
MSG_INITIALIZING
16670749
16670749
[%d]: %s
[%d]: %s
*** LOCATION: %s
*** LOCATION: %s
__NOREPORT__
__NOREPORT__
Script: %s, %s (%s)
Script: %s, %s (%s)
__ir_eval_value = %s;
__ir_eval_value = %s;
%s (%s:%d)
%s (%s:%d)
F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl
F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
WindowStyle
MainWindowSettings
MainWindowSettings
%s at offset %d unterminated
%s at offset %d unterminated
Incorrect %s at offset %d
Incorrect %s at offset %d
Element '%s' at offset %d not ended
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d bytes
%s%d wide chars to %d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
MSG_SEARCH_FILE
(*.*)|*.*||
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_INSERTDISK
MSG_CANCEL
MSG_CANCEL
MSG_OK
MSG_OK
MSG_BROWSE
MSG_BROWSE
MSG_PATH
MSG_PATH
Windows Server 2008
Windows Server 2008
Windows Vista
Windows Vista
Windows Server 2003
Windows Server 2003
Windows XP
Windows XP
Windows 2000
Windows 2000
Windows NT4
Windows NT4
Windows NT3
Windows NT3
Windows ME
Windows ME
Windows 98
Windows 98
Windows 95
Windows 95
CPasswordData
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
number e_ErrorCode, string e_ErrorMsgID
%WindowsFolder%\%ProductName% Setup Log.txt
%WindowsFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartupFolder%
%StartFolder%
%StartFolder%
%StartProgramsFolder%
%StartProgramsFolder%
ÞsktopFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SourceFolder%
%SystemDrive%
%SystemDrive%
_WindowsFolder
_WindowsFolder
%WindowsFolder%
%WindowsFolder%
%SystemFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonProgramW6432%
%CommonDocumentsFolder%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%StartFolderCommon%
%FontsFolder%
%FontsFolder%
ÞsktopFolderCommon%
ÞsktopFolderCommon%
UninstallSupportFiles
UninstallSupportFiles
CPRegKey
CPRegKey
Run extra uninstall script: %d
Run extra uninstall script: %d
%SourceDrive%
%SourceDrive%
%SourceFilename%
%SourceFilename%
\irsetup.dat
\irsetup.dat
Support file added to uninstall list:
Support file added to uninstall list:
Registry key added to uninstall list:
Registry key added to uninstall list:
Remove uninstall support file:
Remove uninstall support file:
Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\
Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\
Register font: %s, %s
Register font: %s, %s
%sbk%d
%sbk%d
MSG_NO
MSG_NO
MSG_YES_TOALL
MSG_YES_TOALL
MSG_YES
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
: %s (#%d)
Global include script: %s
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib: %s
RegisterTypeLib: %s - %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM file: %s
Register COM file: %s - System Error # %u
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
Register COM file on reboot: %s
regsvr32.exe /s %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s
Increment usage count: %s (New count = %d)
Increment usage count: %s (New count = %d)
%s\%s
%s\%s
%s (%d)
%s (%d)
local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;
local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_NOTICE
MSG_SYSREQ_ABORT
MSG_SYSREQ_ABORT
%s: %s
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
MSG_SYSREQ_SCREENHEIGHT
MSG_SYSREQ_SCREENWIDTH
MSG_SYSREQ_SCREENWIDTH
%s: %d
%s: %d
%s: %d %s
%s: %d %s
MSG_SYSREQ_RAM
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
MSG_SIZE_MEGABYTES
Operating System
Operating System
MSG_SYSREQ_OS
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_NONE
MSG_OS_WSRV2008
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_WXP
MSG_OS_W2000
MSG_OS_W2000
MSG_OS_WNT4
MSG_OS_WNT4
MSG_OS_WNT3
MSG_OS_WNT3
MSG_OS_WME
MSG_OS_WME
MSG_OS_W98
MSG_OS_W98
MSG_OS_W95
MSG_OS_W95
MSG_OS_UNKNOWN
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
MSG_SYSREQ_NOTMET
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
MSG_EXP_USESLEFT2
%s %d %s
%s %d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
MSG_EXP_CONTACT_START
MSG_SEEKING
MSG_SEEKING
Dependency Detection Passed
Dependency Detection Passed
Arc: %s
Arc: %s
FN: %s
FN: %s
%s (#%d)
%s (#%d)
MSG_SKIPPING
MSG_SKIPPING
MSG_INSTALLING
MSG_INSTALLING
Run project event: %s
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
%s (%s: %u)
\WININIT.INI
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s\%s.lnk
%s (Return code: %d)
%s (Return code: %d)
Product: %s, version %s
Product: %s, version %s
%s (%d):
%s (%d):
MSG_PROG_UNINSTALL_CREATECONTROLFILE
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Overwrite uninstall executable:
MSG_PROG_UNINSTALL_CREATEEXE
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
@MSG_PROG_UNINSTALL_CREATEDATFILE
?MSG_PROG_UNINSTALL_CREATEFOLDER
?MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
"%s",%d
Uninstall CP entry: URLUpdateInfo =
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
URLInfoAbout
"%s" "/U:%s"
"%s" "/U:%s"
HKEY_LOCAL_MACHINE\
HKEY_LOCAL_MACHINE\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
%s %s
MSG_REQUIRED_DRIVE
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
MSG_AVAILABLE_DRIVE
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
%A, %B %d, %Y
[%s] %s
[%s] %s
%m/%d/%Y %H:%M:%S
%m/%d/%Y %H:%M:%S
MsgFile
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_503
ERR_WEB_500
ERR_WEB_500
ERR_WEB_404
ERR_WEB_404
ERR_WEB_403
ERR_WEB_403
ERR_WEB_400
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyURL%
%CompanyName%
%CompanyName%
UxTheme.dll
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%WindowsFolder%\%ProductName% Uninstall Log.txt
%WindowsFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%CompanyName% Support Department
%WindowsFolder%\%ProductName%\uninstall.exe
%WindowsFolder%\%ProductName%\uninstall.exe
uninstall.xml
uninstall.xml
CWebBrowser2
CWebBrowser2
Confirm Operation
Confirm Operation
kernel32.dll
kernel32.dll
KERNEL32.DLL
KERNEL32.DLL
PSAPI.DLL
PSAPI.DLL
Kernel32.dll
Kernel32.dll
WS2_32.DLL
WS2_32.DLL
Copying "%s"
Copying "%s"
"%s" %s
"%s" %s
%d.%d.%d.%d
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
\StringFileInfo\xx\PrivateBuild
.bak%d
.bak%d
Windows NT 4
Windows NT 4
Windows NT 3
Windows NT 3
%s\shell\open\command
%s\shell\open\command
NUL=%s
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
***!!!***@@
Advapi32.dll
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.url
%s\%s.pif
%s\%s.pif
srclient.dll
srclient.dll
%s_%d
%s_%d
%s\_ir_tmpfnt_%d
%s\_ir_tmpfnt_%d
/\:*?"|
/\:*?"|
jsproxy.dll
jsproxy.dll
DetectAutoProxyUrl
DetectAutoProxyUrl
wininet.dll
wininet.dll
%%x
%%x
d:d
d:d
WinINet.dll
WinINet.dll
Could not create Internet session: %u
Could not create Internet session: %u
Error downloading file: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection: %u
Could not create HTTP connection
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Incorrect HTTP status returned by server: %d
Send request failed: %u
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
Could not open HTTP file: %s
PTF://
PTF://
hXXps://
hXXps://
hXXp://
hXXp://
Could not open request: %u
Could not open request: %u
Could not HTTP file: %u
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG_CLOSING_CONNECTION
TRACE: LastError = %d ("%s")
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, %s
Script: %s, Line %d
Script: %s, Line %d
All Files (*.*)|*.*|
All Files (*.*)|*.*|
PasswordInput
PasswordInput
MSG_MOVING
MSG_MOVING
MSG_COPYING
MSG_COPYING
MSG_FROM
MSG_FROM
MSG_TO
MSG_TO
MSG_DELETING
MSG_DELETING
MSG_SEARCHING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
\StringFileInfo\xx\CompanyName
ErrorMsg
ErrorMsg
%Y-%m-%dT%H:%M:%S
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
OpenURL
\msiexec.exe
\msiexec.exe
RunMsiexec
RunMsiexec
SQLInstallerError
SQLInstallerError
SQLRemoveDriverManager
SQLRemoveDriverManager
odbccp32.dll
odbccp32.dll
SQLConfigDataSource
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverEx
SQLInstallDriverManager
SQLInstallDriverManager
SQLRemoveDriver
SQLRemoveDriver
\Kernel32.dll
\Kernel32.dll
GetKeyNames
GetKeyNames
DoesKeyExist
DoesKeyExist
DeleteKey
DeleteKey
CreateKey
CreateKey
ShortcutKey
ShortcutKey
keycode
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
>MSG_SIZE_GIGABYTES
xxxxxx
xxxxxx
%s-%s-%s
%s-%s-%s
%s/%s/%s
%s/%s/%s
%s:%s:%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s AM
%d:%s:%s PM
%d:%s:%s PM
MSG_REBOOT_FAILED
MSG_REBOOT_FAILED
WININET.DLL
WININET.DLL
PPassword
PPassword
Password
Password
%s %s %s %s (%0.2f %s)
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_SAVING
MSG_DOWNLOADING
MSG_DOWNLOADING
%s %s %s %s
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_QUERYING_INTERNET
MSG_READING
MSG_READING
GetHTTPErrorInfo
GetHTTPErrorInfo
%s > %s
%s > %s
local e_CtrlID=%d; local e_MsgID=%d;
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Button%d
Check%d
Check%d
ComboBox%d
ComboBox%d
Edit%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Error: The specified file: '%s' could not be read.
number e_CtrlID, number e_MsgID, table e_Details
number e_CtrlID, number e_MsgID, table e_Details
Application.Exit();
Application.Exit();
Screen.Next();
Screen.Next();
Screen.Back();
Screen.Back();
Radio%d
Radio%d
Total space required: %SpaceRequired%
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
CTRL_CHECK_BOX_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $
$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $
$URL: VVV.lua.org $
$URL: VVV.lua.org $
!"#$%&'()* ,-./012
!"#$%&'()* ,-./012
#*1892 $
#*1892 $
%,3:;4-&
%,3:;4-&
'.5?
'.5?
ÂmgM
ÂmgM
CNotSupportedException
CNotSupportedException
GDI32.DLL
GDI32.DLL
hhctrl.ocx
hhctrl.ocx
Afx:%p:%x:%p:%p:%p
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
Afx:%p:%x
commctrl_DragListMsg
commctrl_DragListMsg
CCmdTarget
CCmdTarget
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
comctl32.dll
comctl32.dll
comdlg32.dll
comdlg32.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
ntdll.dll
ntdll.dll
%s.dll
%s.dll
mfcm80.dll
mfcm80.dll
CHttpConnection
CHttpConnection
CHttpFile
CHttpFile
HTTP/1.0
HTTP/1.0
user32.dll
user32.dll
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
ole32.dll
mscoree.dll
mscoree.dll
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
cmd.exe
cmd.exe
command.com
command.com
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
portuguese-brazilian
portuguese-brazilian
?#%X.y
?#%X.y
operator
operator
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
OLEACC.dll
OLEACC.dll
WININET.dll
WININET.dll
InternetCrackUrlA
InternetCrackUrlA
InternetCanonicalizeUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpQueryInfoA
HttpSendRequestA
HttpSendRequestA
HttpOpenRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.?AVCCmdTarget@@
.PAVCFileException@@
.PAVCFileException@@
.PAVCException@@
.PAVCException@@
.?AVCMainWindowSettings@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCInternetException@@
.PAVCMemoryException@@
.PAVCMemoryException@@
.PAVCResourceException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.?AVCScreenCtrlMsgDetail@@
Lua 5.0.2
Lua 5.0.2
attempt to %s a %s value
attempt to %s a %s value
attempt to %s %s `%s' (a %s value)
attempt to %s %s `%s' (a %s value)
attempt to compare %s with %s
attempt to compare %s with %s
attempt to compare two %s values
attempt to compare two %s values
%s:%d: %s
%s:%d: %s
system error %d
system error %d
file (%s)
file (%s)
`popen' not supported
`popen' not supported
field `%s' missing in date table
field `%s' missing in date table
^$* ?.([%-
^$* ?.([%-
missing `[' after `%%f' in pattern
missing `[' after `%%f' in pattern
no function environment for tail call at level %d
no function environment for tail call at level %d
could not load package `%s' from path `%s'
could not load package `%s' from path `%s'
error loading package `%s' (%s)
error loading package `%s' (%s)
?;?.lua
?;?.lua
bad argument #%d to `%s' (%s)
bad argument #%d to `%s' (%s)
calling `%s' on bad self (%s)
calling `%s' on bad self (%s)
%s expected, got %s
%s expected, got %s
%s:%d:
%s:%d:
stack overflow (%s)
stack overflow (%s)
cannot read %s: %s
cannot read %s: %s
`__pow' (`^' operator) is not a function
`__pow' (`^' operator) is not a function
invalid key for `next'
invalid key for `next'
too many %s (limit=%d)
too many %s (limit=%d)
%s:%d: %s near `%s'
%s:%d: %s near `%s'
char(%d)
char(%d)
`%s' expected (to close `%s' at line %d)
`%s' expected (to close `%s' at line %d)
`%s' expected
`%s' expected
bad code in %s
bad code in %s
unexpected end of file in %s
unexpected end of file in %s
bad integer in %s
bad integer in %s
bad nupvalues in %s: read %d; expected %d
bad nupvalues in %s: read %d; expected %d
bad constant type (%d) in %s
bad constant type (%d) in %s
unknown number format in %s
unknown number format in %s
%s too old: read version %d.%d; expected at least %d.%d
%s too old: read version %d.%d; expected at least %d.%d
%s too new: read version %d.%d; expected at most %d.%d
%s too new: read version %d.%d; expected at most %d.%d
bad signature in %s
bad signature in %s
virtual machine mismatch in %s: size of %s is %d but read %d
virtual machine mismatch in %s: size of %s is %d but read %d
.PAVCSimpleException@@
.PAVCSimpleException@@
.PAVCObject@@
.PAVCObject@@
.PAVCNotSupportedException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCOleException@@
.PAVCOleException@@
.PAVCUserException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCCmdUI@@
.PAVCArchiveException@@
.PAVCArchiveException@@
.?AVCHttpConnection@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.PAVCOleDispatchException@@
.PAVCOleDispatchException@@
zcÃ
zcÃ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
GetConsoleOutputCP
GetConsoleOutputCP
GetCPInfo
GetCPInfo
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryA
GetWindowsDirectoryA
RegEnumKeyA
RegEnumKeyA
RegOpenKeyA
RegOpenKeyA
RegCloseKey
RegCloseKey
RegEnumKeyExA
RegEnumKeyExA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
ScaleViewportExtEx
ScaleViewportExtEx
SetViewportExtEx
SetViewportExtEx
OffsetViewportOrgEx
OffsetViewportOrgEx
SetViewportOrgEx
SetViewportOrgEx
GetViewportExtEx
GetViewportExtEx
ShellExecuteA
ShellExecuteA
ShellExecuteExA
ShellExecuteExA
UrlUnescapeA
UrlUnescapeA
URLDownloadToFileA
URLDownloadToFileA
SetWindowsHookExA
SetWindowsHookExA
UnhookWindowsHookEx
UnhookWindowsHookEx
CreateDialogIndirectParamA
CreateDialogIndirectParamA
GetKeyState
GetKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
GetAsyncKeyState
GetAsyncKeyState
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
%xERRj3cqZQ
%xERRj3cqZQ
! !!####0
! !!####0
;;;9551%%0
;;;9551%%0
! !!565665@
! !!565665@
version="8.1.1000.0"
version="8.1.1000.0"
name="setup.exe"/>
name="setup.exe"/>
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
GDI32.dll
GDI32.dll
NETAPI32.dll
NETAPI32.dll
OLEAUT32.dll
OLEAUT32.dll
oledlg.dll
oledlg.dll
SHELL32.dll
SHELL32.dll
SHLWAPI.dll
SHLWAPI.dll
urlmon.dll
urlmon.dll
USER32.dll
USER32.dll
VERSION.dll
VERSION.dll
WINMM.dll
WINMM.dll
WINSPOOL.DRV
WINSPOOL.DRV
accKeyboardShortcut
accKeyboardShortcut
Argument %d must be of type %s.
Argument %d must be of type %s.
%d arguments required.
%d arguments required.
All Files (*.*)
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
8.1.1000.0
8.1.1000.0
2008 Indigo Rose Corporation (VVV.indigorose.com)
2008 Indigo Rose Corporation (VVV.indigorose.com)
suf80_rt.exe
suf80_rt.exe
irsetup.exe_2296_rwx_00401000_00172000:
FtPhu
FtPhu
SSSSh
SSSSh
FtPh
FtPh
SSh`UQ
SSh`UQ
SSh4UQ
SSh4UQ
SShlTQ
SShlTQ
SShDTQ
SShDTQ
u1SSh
u1SSh
Su%Sh
Su%Sh
SShx`Q
SShx`Q
txSSh
txSSh
SSh _Q
SSh _Q
@ SSh
@ SSh
.hPsQ
.hPsQ
SSShDxQ
SSShDxQ
9^$u&SSSSh?
9^$u&SSSSh?
u SSSSh?
u SSSSh?
9^$u)SSSSh?
9^$u)SSSSh?
u.VWS
u.VWS
WSSh|DQ
WSSh|DQ
udPQ
udPQ
t.Ht Ht(Ht
t.Ht Ht(Ht
y2SSh
y2SSh
FHSSh
FHSSh
GHSSh
GHSSh
GTSSh
GTSSh
G\SSh
G\SSh
FlSSh
FlSSh
Nt.Nt
Nt.Nt
SShlSR
SShlSR
tjSShHSR
tjSShHSR
t;SSh$SR
t;SSh$SR
F
F
t'SShl
t'SShl
u$SShe
u$SShe
aSSSh
aSSSh
.VVVVVSRSSj
.VVVVVSRSSj
FTPjK
FTPjK
FtPj;
FtPj;
C.PjRV
C.PjRV
diu2.iuz
diu2.iuz
MSG_ERROR
MSG_ERROR
%s %d. %s
%s %d. %s
MSG_ASK_FOR_DISK
MSG_ASK_FOR_DISK
MSG_NEW_LOCATION
MSG_NEW_LOCATION
MSG_CONFIRM_ABORT
MSG_CONFIRM_ABORT
MSG_CONFIRM
MSG_CONFIRM
A%s.%d
A%s.%d
%s, Line %d: %s
%s, Line %d: %s
File condition evaluation for file "%s"
File condition evaluation for file "%s"
C:\temp\SUF_SFX_TEST\
C:\temp\SUF_SFX_TEST\
msi.dll
msi.dll
\msi.dll
\msi.dll
Software\Microsoft\Windows\CurrentVersion\Installer
Software\Microsoft\Windows\CurrentVersion\Installer
MSG_INITIALIZING
MSG_INITIALIZING
16670749
16670749
[%d]: %s
[%d]: %s
*** LOCATION: %s
*** LOCATION: %s
__NOREPORT__
__NOREPORT__
Script: %s, %s (%s)
Script: %s, %s (%s)
__ir_eval_value = %s;
__ir_eval_value = %s;
%s (%s:%d)
%s (%s:%d)
F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl
F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl
%Copyright%. All rights reserved. %CompanyURL%
%Copyright%. All rights reserved. %CompanyURL%
WindowStyle
WindowStyle
MainWindowSettings
MainWindowSettings
%s at offset %d unterminated
%s at offset %d unterminated
Incorrect %s at offset %d
Incorrect %s at offset %d
Element '%s' at offset %d not ended
Element '%s' at offset %d not ended
End tag '%s' at offset %d does not match start tag '%s' at offset %d
End tag '%s' at offset %d does not match start tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
No start tag for end tag '%s' at offset %d
%s%d bytes
%s%d bytes
%s%d wide chars to %d bytes
%s%d wide chars to %d bytes
%d bytes to %s%d wide chars
%d bytes to %s%d wide chars
MSG_SEARCH_FILE
MSG_SEARCH_FILE
(*.*)|*.*||
(*.*)|*.*||
MSG_SEARCH_ALL
MSG_SEARCH_ALL
MSG_SEARCH_MASK
MSG_SEARCH_MASK
MSG_INSERTDISK
MSG_INSERTDISK
MSG_CANCEL
MSG_CANCEL
MSG_OK
MSG_OK
MSG_BROWSE
MSG_BROWSE
MSG_PATH
MSG_PATH
Windows Server 2008
Windows Server 2008
Windows Vista
Windows Vista
Windows Server 2003
Windows Server 2003
Windows XP
Windows XP
Windows 2000
Windows 2000
Windows NT4
Windows NT4
Windows NT3
Windows NT3
Windows ME
Windows ME
Windows 98
Windows 98
Windows 95
Windows 95
CPasswordData
CPasswordData
-- Defined in _SUF70_Global_Functions.lua
-- Defined in _SUF70_Global_Functions.lua
number e_ErrorCode, string e_ErrorMsgID
number e_ErrorCode, string e_ErrorMsgID
%WindowsFolder%\%ProductName% Setup Log.txt
%WindowsFolder%\%ProductName% Setup Log.txt
%StartupFolder%
%StartupFolder%
%StartFolder%
%StartFolder%
%StartProgramsFolder%
%StartProgramsFolder%
ÞsktopFolder%
ÞsktopFolder%
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%CommonFilesFolder%\Microsoft Shared\DAO
%CommonFilesFolder%\Microsoft Shared\DAO
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO350.dll
Software\Microsoft\Shared Tools\DAO360.dll
Software\Microsoft\Shared Tools\DAO360.dll
ÚOPath%
ÚOPath%
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%SourceFolder%
%SourceFolder%
%SystemDrive%
%SystemDrive%
_WindowsFolder
_WindowsFolder
%WindowsFolder%
%WindowsFolder%
%SystemFolder%
%SystemFolder%
%CommonFilesFolder%
%CommonFilesFolder%
%CommonFilesFolder64%
%CommonFilesFolder64%
%CommonProgramW6432%
%CommonProgramW6432%
%CommonDocumentsFolder%
%CommonDocumentsFolder%
%StartupFolderCommon%
%StartupFolderCommon%
%StartProgramsFolderCommon%
%StartProgramsFolderCommon%
%StartFolderCommon%
%StartFolderCommon%
%FontsFolder%
%FontsFolder%
ÞsktopFolderCommon%
ÞsktopFolderCommon%
UninstallSupportFiles
UninstallSupportFiles
CPRegKey
CPRegKey
Run extra uninstall script: %d
Run extra uninstall script: %d
%SourceDrive%
%SourceDrive%
%SourceFilename%
%SourceFilename%
\irsetup.dat
\irsetup.dat
Support file added to uninstall list:
Support file added to uninstall list:
Registry key added to uninstall list:
Registry key added to uninstall list:
Remove uninstall support file:
Remove uninstall support file:
Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\
Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\
Register font: %s, %s
Register font: %s, %s
%sbk%d
%sbk%d
MSG_NO
MSG_NO
MSG_YES_TOALL
MSG_YES_TOALL
MSG_YES
MSG_YES
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_OK_REMOVE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_NO_APP_USE
MSG_UNINSTALL_REMOVE_SHARED
MSG_UNINSTALL_REMOVE_SHARED
Decrement shared file count: %s (New count = %d)
Decrement shared file count: %s (New count = %d)
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
: %s (#%d)
: %s (#%d)
Global include script: %s
Global include script: %s
RegisterTypeLib: %s
RegisterTypeLib: %s
RegisterTypeLib: %s - %s
RegisterTypeLib: %s - %s
Register COM file: %s
Register COM file: %s
Register COM file: %s - System Error # %u
Register COM file: %s - System Error # %u
Register COM file on reboot: %s
Register COM file on reboot: %s
regsvr32.exe /s %s
regsvr32.exe /s %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Increment usage count: %s
Increment usage count: %s
Increment usage count: %s (New count = %d)
Increment usage count: %s (New count = %d)
%s\%s
%s\%s
%s (%d)
%s (%d)
local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;
local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;
MSG_SYSREQ_WARN
MSG_SYSREQ_WARN
MSG_NOTICE
MSG_NOTICE
MSG_SYSREQ_ABORT
MSG_SYSREQ_ABORT
%s: %s
%s: %s
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_USERPERMISSION
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_SYSTEMADMIN
MSG_SYSREQ_COLORDEPTH
MSG_SYSREQ_COLORDEPTH
MSG_BITSPERPIXEL
MSG_BITSPERPIXEL
MSG_SYSREQ_SCREENHEIGHT
MSG_SYSREQ_SCREENHEIGHT
MSG_SYSREQ_SCREENWIDTH
MSG_SYSREQ_SCREENWIDTH
%s: %d
%s: %d
%s: %d %s
%s: %d %s
MSG_SYSREQ_RAM
MSG_SYSREQ_RAM
MSG_SIZE_MEGABYTES
MSG_SIZE_MEGABYTES
Operating System
Operating System
MSG_SYSREQ_OS
MSG_SYSREQ_OS
MSG_OS_PART_ORNEWER
MSG_OS_PART_ORNEWER
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_NOSERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SERVPACK
MSG_OS_PART_SE
MSG_OS_PART_SE
MSG_OS_PART_C
MSG_OS_PART_C
MSG_OS_PART_B
MSG_OS_PART_B
MSG_OS_PART_A
MSG_OS_PART_A
MSG_OS_ALL
MSG_OS_ALL
MSG_OS_NONE
MSG_OS_NONE
MSG_OS_WSRV2008
MSG_OS_WSRV2008
MSG_OS_WVISTA
MSG_OS_WVISTA
MSG_OS_WSRV2003
MSG_OS_WSRV2003
MSG_OS_WXP
MSG_OS_WXP
MSG_OS_W2000
MSG_OS_W2000
MSG_OS_WNT4
MSG_OS_WNT4
MSG_OS_WNT3
MSG_OS_WNT3
MSG_OS_WME
MSG_OS_WME
MSG_OS_W98
MSG_OS_W98
MSG_OS_W95
MSG_OS_W95
MSG_OS_UNKNOWN
MSG_OS_UNKNOWN
MSG_SYSREQ_NOTMET
MSG_SYSREQ_NOTMET
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT
MSG_EXP_USESLEFT2
MSG_EXP_USESLEFT2
%s %d %s
%s %d %s
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT
MSG_EXP_DAYSLEFT2
MSG_EXP_DAYSLEFT2
Software\Microsoft\Windows\CurrentVersion\I652R9823\
Software\Microsoft\Windows\CurrentVersion\I652R9823\
MSG_EXP_CONTACT_START
MSG_EXP_CONTACT_START
MSG_SEEKING
MSG_SEEKING
Dependency Detection Passed
Dependency Detection Passed
Arc: %s
Arc: %s
FN: %s
FN: %s
%s (#%d)
%s (#%d)
MSG_SKIPPING
MSG_SKIPPING
MSG_INSTALLING
MSG_INSTALLING
Run project event: %s
Run project event: %s
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
local e_ErrorCode=%d; local e_ErrorMsgID = "%s"
Start project event: %s
Start project event: %s
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_NOREMOVE
MSG_UNINSTALLFILE_INUSE
MSG_UNINSTALLFILE_INUSE
%s (%s: %u)
%s (%s: %u)
\WININIT.INI
\WININIT.INI
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_INUSE
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_RETRY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_ANY
MSG_FILE_EXISTS_NEWER
MSG_FILE_EXISTS_NEWER
MSG_FILE_OVERWRITE_CONFIRM
MSG_FILE_OVERWRITE_CONFIRM
%s\%s.lnk
%s\%s.lnk
%s (Return code: %d)
%s (Return code: %d)
Product: %s, version %s
Product: %s, version %s
%s (%d):
%s (%d):
MSG_PROG_UNINSTALL_CREATECONTROLFILE
MSG_PROG_UNINSTALL_CREATECONTROLFILE
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_READ
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
ERR_CREATEUNINSTALL_OPEN_EXE_WRITE
Overwrite uninstall executable:
Overwrite uninstall executable:
MSG_PROG_UNINSTALL_CREATEEXE
MSG_PROG_UNINSTALL_CREATEEXE
@MSG_PROG_UNINSTALL_CREATEDATFILE
@MSG_PROG_UNINSTALL_CREATEDATFILE
?MSG_PROG_UNINSTALL_CREATEFOLDER
?MSG_PROG_UNINSTALL_CREATEFOLDER
"/U:%s"
"/U:%s"
MSG_PROG_UNINSTALL_CREATESC
MSG_PROG_UNINSTALL_CREATESC
Create uninstall CP entry key
Create uninstall CP entry key
ERR_CREATEUNINSTALL_CREATEREGKEY
ERR_CREATEUNINSTALL_CREATEREGKEY
"%s",%d
"%s",%d
Uninstall CP entry: URLUpdateInfo =
Uninstall CP entry: URLUpdateInfo =
URLUpdateInfo
URLUpdateInfo
Uninstall CP entry: URLInfoAbout =
Uninstall CP entry: URLInfoAbout =
URLInfoAbout
URLInfoAbout
"%s" "/U:%s"
"%s" "/U:%s"
HKEY_LOCAL_MACHINE\
HKEY_LOCAL_MACHINE\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_CREATECPENTRY
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYSUPPORTFILES
MSG_PROG_UNINSTALL_COPYPLUGINS
MSG_PROG_UNINSTALL_COPYPLUGINS
%s %s
%s %s
MSG_REQUIRED_DRIVE
MSG_REQUIRED_DRIVE
MSG_AVAILABLE_DRIVE
MSG_AVAILABLE_DRIVE
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_DRIVESPACE
MSG_PROG_CHECKING_FILES
MSG_PROG_CHECKING_FILES
%A, %B %d, %Y
%A, %B %d, %Y
[%s] %s
[%s] %s
%m/%d/%Y %H:%M:%S
%m/%d/%Y %H:%M:%S
MsgFile
MsgFile
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_REMOVAL_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_PATCH_PACKAGE_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_UNSUPPORTED_TYPE
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_ODBC_INVALID_KEYWORD_VALUE
ERR_WEB_503
ERR_WEB_503
ERR_WEB_500
ERR_WEB_500
ERR_WEB_404
ERR_WEB_404
ERR_WEB_403
ERR_WEB_403
ERR_WEB_400
ERR_WEB_400
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_PASSWORD
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_SET_PROXY_USERNAME
ERR_WEB_WRITE_MEMORY
ERR_WEB_WRITE_MEMORY
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_FTP_FILE_OPEN
ERR_WEB_USER_ABORT
ERR_WEB_USER_ABORT
ERR_WEB_FILE_WRITE
ERR_WEB_FILE_WRITE
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_DOWNLOAD_FILE_ERROR
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_INVALID_HTTP_RESPONSE
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_DESTINATION_FILE_OPEN
ERR_WEB_SEND_REQUEST
ERR_WEB_SEND_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_OPEN_REQUEST
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_HTTP_CONNECTION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_WEB_CREATE_INTERNET_SESSION
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_GET_SUB_KEY_NAME
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_NON_EXISTANT_SUB_KEY
ERR_REG_DELETE_KEY
ERR_REG_DELETE_KEY
ERR_REG_CREATE_KEY
ERR_REG_CREATE_KEY
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_FILE_EXECUTION_FAILED_ELEVATION
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_KEY_RUN_ON_REBOOT_FAILED
ERR_USER_ABORTED_OPERATION
ERR_USER_ABORTED_OPERATION
ERR_NON_EXISTANT_VIEWER_EXE
ERR_NON_EXISTANT_VIEWER_EXE
ERR_FILE_EXECUTION_FAILED
ERR_FILE_EXECUTION_FAILED
ERR_SPECIFIED_EXE_FILE_INVALID
ERR_SPECIFIED_EXE_FILE_INVALID
MSG_SUCCESS
MSG_SUCCESS
Language set: Primary = %d, Secondary = %d
Language set: Primary = %d, Secondary = %d
%CompanyURL%
%CompanyURL%
%CompanyName%
%CompanyName%
UxTheme.dll
UxTheme.dll
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%Copyright% %CompanyName%. All rights reserved. %CompanyURL%
%WindowsFolder%\%ProductName% Uninstall Log.txt
%WindowsFolder%\%ProductName% Uninstall Log.txt
%CompanyName% Support Department
%CompanyName% Support Department
%WindowsFolder%\%ProductName%\uninstall.exe
%WindowsFolder%\%ProductName%\uninstall.exe
uninstall.xml
uninstall.xml
CWebBrowser2
CWebBrowser2
Confirm Operation
Confirm Operation
kernel32.dll
kernel32.dll
KERNEL32.DLL
KERNEL32.DLL
PSAPI.DLL
PSAPI.DLL
Kernel32.dll
Kernel32.dll
WS2_32.DLL
WS2_32.DLL
Copying "%s"
Copying "%s"
"%s" %s
"%s" %s
%d.%d.%d.%d
%d.%d.%d.%d
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\ProductVersion
\StringFileInfo\xx\PrivateBuild
\StringFileInfo\xx\PrivateBuild
.bak%d
.bak%d
Windows NT 4
Windows NT 4
Windows NT 3
Windows NT 3
%s\shell\open\command
%s\shell\open\command
NUL=%s
NUL=%s
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
***!!!***@@
***!!!***@@
Advapi32.dll
Advapi32.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\%s.url
%s\%s.url
%s\%s.pif
%s\%s.pif
srclient.dll
srclient.dll
%s_%d
%s_%d
%s\_ir_tmpfnt_%d
%s\_ir_tmpfnt_%d
/\:*?"|
/\:*?"|
jsproxy.dll
jsproxy.dll
DetectAutoProxyUrl
DetectAutoProxyUrl
wininet.dll
wininet.dll
%%x
%%x
d:d
d:d
WinINet.dll
WinINet.dll
Could not create Internet session: %u
Could not create Internet session: %u
Error downloading file: %u
Error downloading file: %u
Error writing the destination file: %d-%u
Error writing the destination file: %d-%u
Could not create HTTP connection: %u
Could not create HTTP connection: %u
Could not create HTTP connection
Could not create HTTP connection
Incorrect HTTP status returned by server: %d
Incorrect HTTP status returned by server: %d
Send request failed: %u
Send request failed: %u
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Could not open HTTP file: %s
Could not open HTTP file: %s
PTF://
PTF://
hXXps://
hXXps://
hXXp://
hXXp://
Could not open request: %u
Could not open request: %u
Could not HTTP file: %u
Could not HTTP file: %u
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CREATED
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_HANDLE_CLOSING
MSG_STATUS_REQUEST_COMPLETE
MSG_STATUS_REQUEST_COMPLETE
MSG_REDIRECTING
MSG_REDIRECTING
MSG_CONNECTION_CLOSED
MSG_CONNECTION_CLOSED
MSG_RESOLVING_HOST_NAME
MSG_RESOLVING_HOST_NAME
MSG_HOST_NAME_RESOLVED
MSG_HOST_NAME_RESOLVED
MSG_CONNECTING_TO_SERVER
MSG_CONNECTING_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CONNECTED_TO_SERVER
MSG_CLOSING_CONNECTION
MSG_CLOSING_CONNECTION
TRACE: LastError = %d ("%s")
TRACE: LastError = %d ("%s")
Script: %s, %s
Script: %s, %s
Script: %s, Line %d
Script: %s, Line %d
All Files (*.*)|*.*|
All Files (*.*)|*.*|
PasswordInput
PasswordInput
MSG_MOVING
MSG_MOVING
MSG_COPYING
MSG_COPYING
MSG_FROM
MSG_FROM
MSG_TO
MSG_TO
MSG_DELETING
MSG_DELETING
MSG_SEARCHING
MSG_SEARCHING
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\SpecialBuild
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\OriginalFilename
\StringFileInfo\xx\Comments
\StringFileInfo\xx\Comments
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalTrademarks
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\LegalCopyright
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\ProductName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\InternalName
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\FileDescription
\StringFileInfo\xx\CompanyName
\StringFileInfo\xx\CompanyName
ErrorMsg
ErrorMsg
%Y-%m-%dT%H:%M:%S
%Y-%m-%dT%H:%M:%S
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_DO_YOU_WANT_OVERWRITE
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG
MSG_INSTALL_FILE_OLDER_MSG
MSG_INSTALL_FILE_OLDER_MSG
OpenURL
OpenURL
\msiexec.exe
\msiexec.exe
RunMsiexec
RunMsiexec
SQLInstallerError
SQLInstallerError
SQLRemoveDriverManager
SQLRemoveDriverManager
odbccp32.dll
odbccp32.dll
SQLConfigDataSource
SQLConfigDataSource
SQLInstallDriverEx
SQLInstallDriverEx
SQLInstallDriverManager
SQLInstallDriverManager
SQLRemoveDriver
SQLRemoveDriver
\Kernel32.dll
\Kernel32.dll
GetKeyNames
GetKeyNames
DoesKeyExist
DoesKeyExist
DeleteKey
DeleteKey
CreateKey
CreateKey
ShortcutKey
ShortcutKey
keycode
keycode
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
MSG_SIZE_BYTES
MSG_SIZE_BYTES
P?MSG_SIZE_KILOBYTES
P?MSG_SIZE_KILOBYTES
>MSG_SIZE_GIGABYTES
>MSG_SIZE_GIGABYTES
xxxxxx
xxxxxx
%s-%s-%s
%s-%s-%s
%s/%s/%s
%s/%s/%s
%s:%s:%s
%s:%s:%s
%d:%s:%s AM
%d:%s:%s AM
%d:%s:%s PM
%d:%s:%s PM
MSG_REBOOT_FAILED
MSG_REBOOT_FAILED
WININET.DLL
WININET.DLL
PPassword
PPassword
Password
Password
%s %s %s %s (%0.2f %s)
%s %s %s %s (%0.2f %s)
%0.1f %s/%0.1f %s
%0.1f %s/%0.1f %s
%I64u %s/%I64u %s
%I64u %s/%I64u %s
MSG_KB_PER_SEC
MSG_KB_PER_SEC
MSG_ESTIMATED_TIME_LEFT
MSG_ESTIMATED_TIME_LEFT
MSG_SAVING
MSG_SAVING
MSG_DOWNLOADING
MSG_DOWNLOADING
%s %s %s %s
%s %s %s %s
MSG_QUERYING_INTERNET
MSG_QUERYING_INTERNET
MSG_READING
MSG_READING
GetHTTPErrorInfo
GetHTTPErrorInfo
%s > %s
%s > %s
local e_CtrlID=%d; local e_MsgID=%d;
local e_CtrlID=%d; local e_MsgID=%d;
Button%d
Button%d
Check%d
Check%d
ComboBox%d
ComboBox%d
Edit%d
Edit%d
Space available on selected drive: %SpaceAvailable%
Space available on selected drive: %SpaceAvailable%
Space required: %SpaceRequired%
Space required: %SpaceRequired%
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be found.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' could not be opened.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' is too large to read.
Error: The specified file: '%s' could not be read.
Error: The specified file: '%s' could not be read.
number e_CtrlID, number e_MsgID, table e_Details
number e_CtrlID, number e_MsgID, table e_Details
Application.Exit();
Application.Exit();
Screen.Next();
Screen.Next();
Screen.Back();
Screen.Back();
Radio%d
Radio%d
Total space required: %SpaceRequired%
Total space required: %SpaceRequired%
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_CHECK_BOX_d
IDS_CTRL_BUTTON_d
IDS_CTRL_BUTTON_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_STATICTEXT_LABEL_d
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_COMBOBOX_d_DEFAULT
IDS_CTRL_EDIT_d
IDS_CTRL_EDIT_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_RADIO_BUTTON_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_LISTBOX_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_SCROLLTEXT_BODY_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_PROGRESS_BAR_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_GROUP_BOX_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_SELECT_PACKAGE_TREE_d
CTRL_CHECK_BOX_d
CTRL_CHECK_BOX_d
CTRL_BUTTON_d
CTRL_BUTTON_d
CTRL_STATICTEXT_LABEL_d
CTRL_STATICTEXT_LABEL_d
CTRL_COMBOBOX_d
CTRL_COMBOBOX_d
CTRL_EDIT_d
CTRL_EDIT_d
CTRL_RADIO_BUTTON_d
CTRL_RADIO_BUTTON_d
CTRL_LIST_BOX_d
CTRL_LIST_BOX_d
CTRL_SCROLLTEXT_BODY_d
CTRL_SCROLLTEXT_BODY_d
CTRL_PROGRESS_BAR_d
CTRL_PROGRESS_BAR_d
CTRL_GROUP_BOX_d
CTRL_GROUP_BOX_d
CTRL_SELECT_PACKAGE_TREE_d
CTRL_SELECT_PACKAGE_TREE_d
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_COMBOBOX_d_ITEMS
IDS_CTRL_SCROLLTEXT_FILE_d
IDS_CTRL_SCROLLTEXT_FILE_d
WebWindow
WebWindow
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_NAME_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d
$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $
$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $
$URL: VVV.lua.org $
$URL: VVV.lua.org $
!"#$%&'()* ,-./012
!"#$%&'()* ,-./012
#*1892 $
#*1892 $
%,3:;4-&
%,3:;4-&
'.5?
'.5?
ÂmgM
ÂmgM
CNotSupportedException
CNotSupportedException
GDI32.DLL
GDI32.DLL
hhctrl.ocx
hhctrl.ocx
Afx:%p:%x:%p:%p:%p
Afx:%p:%x:%p:%p:%p
Afx:%p:%x
Afx:%p:%x
commctrl_DragListMsg
commctrl_DragListMsg
CCmdTarget
CCmdTarget
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
comctl32.dll
comctl32.dll
comdlg32.dll
comdlg32.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
ntdll.dll
ntdll.dll
%s.dll
%s.dll
mfcm80.dll
mfcm80.dll
CHttpConnection
CHttpConnection
CHttpFile
CHttpFile
HTTP/1.0
HTTP/1.0
user32.dll
user32.dll
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
ole32.dll
ole32.dll
mscoree.dll
mscoree.dll
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
cmd.exe
cmd.exe
command.com
command.com
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
portuguese-brazilian
portuguese-brazilian
?#%X.y
?#%X.y
operator
operator
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
OLEACC.dll
OLEACC.dll
WININET.dll
WININET.dll
InternetCrackUrlA
InternetCrackUrlA
InternetCanonicalizeUrlA
InternetCanonicalizeUrlA
HttpQueryInfoA
HttpQueryInfoA
HttpSendRequestA
HttpSendRequestA
HttpOpenRequestA
HttpOpenRequestA
.?AVCCmdTarget@@
.?AVCCmdTarget@@
.PAVCFileException@@
.PAVCFileException@@
.PAVCException@@
.PAVCException@@
.?AVCMainWindowSettings@@
.?AVCMainWindowSettings@@
.?AVCMD5@@
.?AVCMD5@@
.?AVCPasswordData@@
.?AVCPasswordData@@
.?AVCRTSessionVarMgr@@
.?AVCRTSessionVarMgr@@
.?AVCScreenCrtrMeasure@@
.?AVCScreenCrtrMeasure@@
.?AVCWebBrowser2@@
.?AVCWebBrowser2@@
.PAVCInternetException@@
.PAVCInternetException@@
.PAVCMemoryException@@
.PAVCMemoryException@@
.PAVCResourceException@@
.PAVCResourceException@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsg@@
.?AVCScreenCtrlMsgDetail@@
.?AVCScreenCtrlMsgDetail@@
Lua 5.0.2
Lua 5.0.2
attempt to %s a %s value
attempt to %s a %s value
attempt to %s %s `%s' (a %s value)
attempt to %s %s `%s' (a %s value)
attempt to compare %s with %s
attempt to compare %s with %s
attempt to compare two %s values
attempt to compare two %s values
%s:%d: %s
%s:%d: %s
system error %d
system error %d
file (%s)
file (%s)
`popen' not supported
`popen' not supported
field `%s' missing in date table
field `%s' missing in date table
^$* ?.([%-
^$* ?.([%-
missing `[' after `%%f' in pattern
missing `[' after `%%f' in pattern
no function environment for tail call at level %d
no function environment for tail call at level %d
could not load package `%s' from path `%s'
could not load package `%s' from path `%s'
error loading package `%s' (%s)
error loading package `%s' (%s)
?;?.lua
?;?.lua
bad argument #%d to `%s' (%s)
bad argument #%d to `%s' (%s)
calling `%s' on bad self (%s)
calling `%s' on bad self (%s)
%s expected, got %s
%s expected, got %s
%s:%d:
%s:%d:
stack overflow (%s)
stack overflow (%s)
cannot read %s: %s
cannot read %s: %s
`__pow' (`^' operator) is not a function
`__pow' (`^' operator) is not a function
invalid key for `next'
invalid key for `next'
too many %s (limit=%d)
too many %s (limit=%d)
%s:%d: %s near `%s'
%s:%d: %s near `%s'
char(%d)
char(%d)
`%s' expected (to close `%s' at line %d)
`%s' expected (to close `%s' at line %d)
`%s' expected
`%s' expected
bad code in %s
bad code in %s
unexpected end of file in %s
unexpected end of file in %s
bad integer in %s
bad integer in %s
bad nupvalues in %s: read %d; expected %d
bad nupvalues in %s: read %d; expected %d
bad constant type (%d) in %s
bad constant type (%d) in %s
unknown number format in %s
unknown number format in %s
%s too old: read version %d.%d; expected at least %d.%d
%s too old: read version %d.%d; expected at least %d.%d
%s too new: read version %d.%d; expected at most %d.%d
%s too new: read version %d.%d; expected at most %d.%d
bad signature in %s
bad signature in %s
virtual machine mismatch in %s: size of %s is %d but read %d
virtual machine mismatch in %s: size of %s is %d but read %d
.PAVCSimpleException@@
.PAVCSimpleException@@
.PAVCObject@@
.PAVCObject@@
.PAVCNotSupportedException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.?AVCNotSupportedException@@
.PAVCOleException@@
.PAVCOleException@@
.PAVCUserException@@
.PAVCUserException@@
.?AVCTestCmdUI@@
.?AVCTestCmdUI@@
.?AVCCmdUI@@
.?AVCCmdUI@@
.PAVCArchiveException@@
.PAVCArchiveException@@
.?AVCHttpConnection@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AVCHttpFile@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
.PAVCOleDispatchException@@
.PAVCOleDispatchException@@
zcÃ
zcÃ
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
GetConsoleOutputCP
GetConsoleOutputCP
GetCPInfo
GetCPInfo
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryA
GetWindowsDirectoryA
RegEnumKeyA
RegEnumKeyA
RegOpenKeyA
RegOpenKeyA
RegCloseKey
RegCloseKey
RegEnumKeyExA
RegEnumKeyExA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
ScaleViewportExtEx
ScaleViewportExtEx
SetViewportExtEx
SetViewportExtEx
OffsetViewportOrgEx
OffsetViewportOrgEx
SetViewportOrgEx
SetViewportOrgEx
GetViewportExtEx
GetViewportExtEx
ShellExecuteA
ShellExecuteA
ShellExecuteExA
ShellExecuteExA
UrlUnescapeA
UrlUnescapeA
URLDownloadToFileA
URLDownloadToFileA
SetWindowsHookExA
SetWindowsHookExA
UnhookWindowsHookEx
UnhookWindowsHookEx
CreateDialogIndirectParamA
CreateDialogIndirectParamA
GetKeyState
GetKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
GetAsyncKeyState
GetAsyncKeyState
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
accKeyboardShortcut
accKeyboardShortcut
Argument %d must be of type %s.
Argument %d must be of type %s.
%d arguments required.
%d arguments required.
All Files (*.*)
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
#Unable to load mail system support.
#Unable to load mail system support.
Access to %1 was denied..An invalid file handle was associated with %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
DTLite4413-0173.exe_1672:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
RegDeleteKeyExW
RegDeleteKeyExW
Kernel32.DLL
Kernel32.DLL
PSAPI.DLL
PSAPI.DLL
%s=%s
%s=%s
GetWindowsDirectoryW
GetWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationW
SHFileOperationW
ShellExecuteW
ShellExecuteW
SHELL32.dll
SHELL32.dll
RegDeleteKeyW
RegDeleteKeyW
RegCloseKey
RegCloseKey
RegEnumKeyW
RegEnumKeyW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
%U/nE
%U/nE
q4*.rIY
q4*.rIY
.cr1h
.cr1h
;$;(;,;0;4;8;
;$;(;,;0;4;8;
4 4@4\4`4
4 4@4\4`4
2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.
2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.
3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
hXXps://VVV.verisign.com/rpa0
hXXps://VVV.verisign.com/rpa0
hXXp://ocsp.verisign.com0?
hXXp://ocsp.verisign.com0?
3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
.Class 3 Public Primary Certification Authority0
.Class 3 Public Primary Certification Authority0
hXXps://VVV.verisign.com/cps0*
hXXps://VVV.verisign.com/cps0*
#hXXp://logo.verisign.com/vslogo.gif0
#hXXp://logo.verisign.com/vslogo.gif0
hXXp://ocsp.verisign.com01
hXXp://ocsp.verisign.com01
hXXp://crl.verisign.com/pca3.crl0)
hXXp://crl.verisign.com/pca3.crl0)
hXXp://ocsp.verisign.com0
hXXp://ocsp.verisign.com0
"hXXp://crl.verisign.com/tss-ca.crl0
"hXXp://crl.verisign.com/tss-ca.crl0
Thawte Certification1
Thawte Certification1
0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0
0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0
Nullsoft Install System v2.46-Unicode
Nullsoft Install System v2.46-Unicode
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
%u.%u%s%s
%u.%u%s%s
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
*?|/":
*?|/":
pData\Local\Temp\nsr342B.tmp\setuphlp.dll
pData\Local\Temp\nsr342B.tmp\setuphlp.dll
0173.exe /S
0173.exe /S
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll
ON Tools Lite\DTGadget.lnk
ON Tools Lite\DTGadget.lnk
te.lnk
te.lnk
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp
6.exe
6.exe
Monkey's Audio!
Monkey's Audio!
Windows Media Audio
Windows Media Audio
`~!@#$^&*() =[]{}\:;'",|/
`~!@#$^&*() =[]{}\:;'",|/
nsr342B.tmp
nsr342B.tmp
\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S
\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S
342B.tmp\Lang\
342B.tmp\Lang\
\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp
\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S
%Program Files%\DAEMON Tools Lite
%Program Files%\DAEMON Tools Lite
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0
DTLite4413-0173.exe
DTLite4413-0173.exe
ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp
ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe
Windows Gadget
Windows Gadget
Integrate with Windows Explorer
Integrate with Windows Explorer
SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features.
SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features.
Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop.
Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop.
4.41.3.0173.0
4.41.3.0173.0
DAEMONSetup4.41.3.0173.exe
DAEMONSetup4.41.3.0173.exe
dinotify.exe_3912:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
KERNEL32.dll
KERNEL32.dll
msvcrt.dll
msvcrt.dll
pnpui.dll
pnpui.dll
dinotify.pdb
dinotify.pdb
_amsg_exit
_amsg_exit
version="1.0.0.0"
version="1.0.0.0"
name="DINotify.exe"
name="DINotify.exe"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
pnpui.dll,SimplifiedDINotification
pnpui.dll,SimplifiedDINotification
Windows Device Installation
Windows Device Installation
6.1.7600.16385 (win7_rtm.090713-1255)
6.1.7600.16385 (win7_rtm.090713-1255)
dinotify.exe
dinotify.exe
Windows
Windows
Operating System
Operating System
6.1.7600.16385
6.1.7600.16385
sidebar.exe_1808:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
ntdll.DLL
ntdll.DLL
KERNEL32.dll
KERNEL32.dll
GDI32.dll
GDI32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
ATL.DLL
ATL.DLL
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
COMCTL32.dll
COMCTL32.dll
gdiplus.dll
gdiplus.dll
SHLWAPI.dll
SHLWAPI.dll
SHELL32.dll
SHELL32.dll
urlmon.dll
urlmon.dll
CRYPT32.dll
CRYPT32.dll
sfc_os.dll
sfc_os.dll
dwmapi.dll
dwmapi.dll
CRYPTUI.dll
CRYPTUI.dll
UxTheme.dll
UxTheme.dll
SSShZ
SSShZ
SSSSSSh
SSSSSSh
FTPQ
FTPQ
#SSSh
#SSSh
1.1.4
1.1.4
1.3.6.1.4.1.311.2.1.12
1.3.6.1.4.1.311.2.1.12
DwmApplyWindowScaleFactor
DwmApplyWindowScaleFactor
FTPh
FTPh
SSShw
SSShw
PSSh|
PSSh|
tWHt;Ht.Ht
tWHt;Ht.Ht
sidebar.exe
sidebar.exe
WININET.dll
WININET.dll
WTSAPI32.dll
WTSAPI32.dll
WINMM.dll
WINMM.dll
IPHLPAPI.DLL
IPHLPAPI.DLL
WINTRUST.dll
WINTRUST.dll
PROPSYS.dll
PROPSYS.dll
Wlanapi.dll
Wlanapi.dll
wlanutil.dll
wlanutil.dll
OLEACC.dll
OLEACC.dll
COMDLG32.dll
COMDLG32.dll
InternetCreateUrlW
InternetCreateUrlW
InternetCrackUrlW
InternetCrackUrlW
GetUrlCacheEntryInfoW
GetUrlCacheEntryInfoW
PSGetPropertyKeyFromName
PSGetPropertyKeyFromName
ntdll.dll
ntdll.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegNotifyChangeKeyValue
RegNotifyChangeKeyValue
RegDeleteKeyW
RegDeleteKeyW
ReportEventW
ReportEventW
GetProcessHeap
GetProcessHeap
RegEnumKeyExW
RegEnumKeyExW
GetSystemWindowsDirectoryW
GetSystemWindowsDirectoryW
RegCreateKeyExW
RegCreateKeyExW
SetViewportOrgEx
SetViewportOrgEx
GetKeyState
GetKeyState
GetKeyboardState
GetKeyboardState
UnregisterHotKey
UnregisterHotKey
RegisterHotKey
RegisterHotKey
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
GetAsyncKeyState
GetAsyncKeyState
_amsg_exit
_amsg_exit
_acmdln
_acmdln
GdipSetPenLineJoin
GdipSetPenLineJoin
GdipSetImageAttributesColorKeys
GdipSetImageAttributesColorKeys
GdiplusShutdown
GdiplusShutdown
PathIsURLW
PathIsURLW
UrlIsW
UrlIsW
UrlEscapeW
UrlEscapeW
PathCreateFromUrlW
PathCreateFromUrlW
UrlUnescapeW
UrlUnescapeW
ShellExecuteW
ShellExecuteW
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
URLOpenBlockingStreamW
URLOpenBlockingStreamW
CreateURLMoniker
CreateURLMoniker
CertCloseStore
CertCloseStore
CertFreeCertificateContext
CertFreeCertificateContext
CertGetNameStringW
CertGetNameStringW
CertFindCertificateInStore
CertFindCertificateInStore
CryptMsgGetParam
CryptMsgGetParam
CryptMsgClose
CryptMsgClose
CryptUIDlgViewCertificateW
CryptUIDlgViewCertificateW
sidebar.pdb
sidebar.pdb
name="Microsoft.Windows.Sidebar"
name="Microsoft.Windows.Sidebar"
version="1.0.0.0"
version="1.0.0.0"
Windows Sidebar
Windows Sidebar
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
stdole2.tlbWWWp)
stdole2.tlbWWWp)
vOperationWW
vOperationWW
.ssid
.ssid
.backgroundWW
.backgroundWW
.lpbstrStdDisplayNameWD
.lpbstrStdDisplayNameWD
KEYWh
KEYWh
"" ,,/,**)((
"" ,,/,**)((
!
!
yuussHIBA@
yuussHIBA@
wfb=3/-A}
wfb=3/-A}
444600,,)''%%$$
444600,,)''%%$$
"
"
=55/** ('%%$$
=55/** ('%%$$
@
@
!!//---*)(
!!//---*)(
62.*(&$#
62.*(&$#
,63.*)&$$##
,63.*)&$$##
/963.*)&#
/963.*)&#
L[Q9930.*'$$&.LhmlEF
L[Q9930.*'$$&.LhmlEF
7000--,,**''''
7000--,,**''''
U$.eH~
U$.eH~
}#$##$$$ !
}#$##$$$ !
} / 0/01&&()#
} / 0/01&&()#
];
];
@.lF!=^
@.lF!=^
*8
*8
6666666666
6666666666
.oeA(
.oeA(
l.GCc
l.GCc
"Cw%X
"Cw%X
%d%t3
%d%t3
%fLpX
%fLpX
%US7i
%US7i
;w.VS]}
;w.VS]}
.IDATx
.IDATx
&p.VM
&p.VM
j.ah@
j.ah@
g?.Vf
g?.Vf
Q.hH5
Q.hH5
)%uuu
)%uuu
d^pÇ
d^pÇ
{D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost'
{D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost'
'sidebar.EXE'
'sidebar.EXE'
val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523}
val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523}
NoRemove 'Windows Sidebar'
NoRemove 'Windows Sidebar'
*021:1@1
*021:1@1
3 3$3(3,3034383
3 3$3(3,3034383
? ?$?(?,?
? ?$?(?,?
8 8$8(8,808
8 8$8(8,808
4 4'4.4;4
4 4'4.4;4
="=)=0=7=
="=)=0=7=
6#6*61676
6#6*61676
=4=8=\=`=
=4=8=\=`=
4 4
4 4
5 5
5 5
Section%d
Section%d
Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings
Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings
Software\Microsoft\Windows Sidebar\IEOverride
Software\Microsoft\Windows Sidebar\IEOverride
00.00.00.02
00.00.00.02
Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility
Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar
Microsoft\Windows Sidebar\Gadgets
Microsoft\Windows Sidebar\Gadgets
Settings.ini
Settings.ini
Microsoft\Windows Sidebar
Microsoft\Windows Sidebar
AnimationsTimerT%d
AnimationsTimerT%d
Gadget.xml
Gadget.xml
*.Gadget
*.Gadget
hXXp://go.microsoft.com/fwlink/?LinkId=124093
hXXp://go.microsoft.com/fwlink/?LinkId=124093
imageres.dll
imageres.dll
{557CF406-1A04-11D3-9A73-0000F81EF32E}
{557CF406-1A04-11D3-9A73-0000F81EF32E}
Windows Sidebar\Shared Gadgets
Windows Sidebar\Shared Gadgets
Msg_GadgetInstalled
Msg_GadgetInstalled
%d.%d.%d.%d
%d.%d.%d.%d
Wversion.dll
Wversion.dll
%s %s
%s %s
.0123456789
.0123456789
ddwmapi.dll
ddwmapi.dll
Msxml.DOMDocument
Msxml.DOMDocument
Windows Sidebar\Gadgets
Windows Sidebar\Gadgets
%s\%s
%s\%s
keywords
keywords
website
website
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Section %d
Section %d
\\?\UNC\
\\?\UNC\
BurlyWood
BurlyWood
Windows
Windows
Keywords
Keywords
Windows Sidebar
Windows Sidebar
mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947
mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947
hXXp://
hXXp://
.html
.html
.Gadget
.Gadget
Cert
Cert
mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b
mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b
url("gbackground:///%s")
url("gbackground:///%s")
SupportLink
SupportLink
SidebarExecute
SidebarExecute
{00000000-0000-0000-0000-000000000000}
{00000000-0000-0000-0000-000000000000}
\\?\Volume
\\?\Volume
style.backgroundImage
style.backgroundImage
style.width
style.width
style.height
style.height
Software\Microsoft\Windows\CurrentVersion\Sidebar
Software\Microsoft\Windows\CurrentVersion\Sidebar
style.backgroundColor
style.backgroundColor
%windir%\system32\schtasks.exe
%windir%\system32\schtasks.exe
/run /tn Microsoft\Windows\SideShow\GadgetManager
/run /tn Microsoft\Windows\SideShow\GadgetManager
HARDWARE\DESCRIPTION\System\CentralProcessor\%d
HARDWARE\DESCRIPTION\System\CentralProcessor\%d
Shell.Application
Shell.Application
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones
@tzres.dll,
@tzres.dll,
\tzres.dll
\tzres.dll
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s.mui
.\%s\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s\%s.mui
&C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
&C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
Windows Desktop Gadgets
Windows Desktop Gadgets
6.1.7601.17514 (win7sp1_rtm.101119-1850)
6.1.7601.17514 (win7sp1_rtm.101119-1850)
sidebar.EXE
sidebar.EXE
Windows
Windows
Operating System
Operating System
1.0.7601.17514
1.0.7601.17514
Microsoft-Windows-Sidebar/Diagnostic
Microsoft-Windows-Sidebar/Diagnostic
DT_free_Rus_YandexBar1022.exe_2792:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
operator
operator
GetProcessWindowStation
GetProcessWindowStation
%d %d %d %d
%d %d %d %d
inflate 1.1.3 Copyright 1995-1998 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
-DTLite.exe
-DTLite.exe
YandexSetup.exe
YandexSetup.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar
--distr /passive /msicl "
--distr /passive /msicl "
E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb
E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb
KERNEL32.dll
KERNEL32.dll
EnumChildWindows
EnumChildWindows
EnumThreadWindows
EnumThreadWindows
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
RegCreateKeyExA
RegCreateKeyExA
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteExW
ShellExecuteExW
ShellExecuteExA
ShellExecuteExA
SHELL32.dll
SHELL32.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD
t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD
BYL
BYL
k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>,
k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>,
PD.XK5RD.xm[
PD.XK5RD.xm[
RE.VI3PC,
RE.VI3PC,
NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F
NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F
G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G
G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G
OC.TI6RG3MA-NB.MA-K?*
OC.TI6RG3MA-NB.MA-K?*
?5$?5$>4#>4#=4#=3"=4#=3"
?5$?5$>4#>4#=4#=3"=4#=3"
8/!:2$4,
8/!:2$4,
@6$>4"8,
@6$>4"8,
8/!8/!8/!8.!7. 7. 7. 7. 6-
8/!8/!8/!8.!7. 7. 7. 7. 6-
80 90"2(
80 90"2(
6- 6- 6-
6- 6- 6-
JJJ...SSS
JJJ...SSS
/,)/,)?:7
/,)/,)?:7
tGHt.Ht&
tGHt.Ht&
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
USER32.DLL
USER32.DLL
Seed: %d
Seed: %d
D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb
D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb
RegOpenKeyExW
RegOpenKeyExW
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
URLOpenBlockingStreamW
URLOpenBlockingStreamW
urlmon.dll
urlmon.dll
WINTRUST.dll
WINTRUST.dll
VERSION.dll
VERSION.dll
GetConsoleOutputCP
GetConsoleOutputCP
zcÃ
zcÃ
3.44484
3.44484
"hXXp://crl.verisign.com/tss-ca.crl0
"hXXp://crl.verisign.com/tss-ca.crl0
hXXp://ocsp.verisign.com0
hXXp://ocsp.verisign.com0
Thawte Certification1
Thawte Certification1
0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0
0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0
2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.
2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.
3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D
hXXps://VVV.verisign.com/rpa0
hXXps://VVV.verisign.com/rpa0
hXXp://ocsp.verisign.com0?
hXXp://ocsp.verisign.com0?
3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0
.Class 3 Public Primary Certification Authority0
.Class 3 Public Primary Certification Authority0
hXXps://VVV.verisign.com/cps0*
hXXps://VVV.verisign.com/cps0*
#hXXp://logo.verisign.com/vslogo.gif0
#hXXp://logo.verisign.com/vslogo.gif0
hXXp://ocsp.verisign.com01
hXXp://ocsp.verisign.com01
hXXp://crl.verisign.com/pca3.crl0)
hXXp://crl.verisign.com/pca3.crl0)
hXXp://VVV.yandex.ru0
hXXp://VVV.yandex.ru0
4O4
4O4
3:3?3!4.444`4
3:3?3!4.444`4
2(3,3034383
2(3,3034383
mscoree.dll
mscoree.dll
KERNEL32.DLL
KERNEL32.DLL
WUSER32.DLL
WUSER32.DLL
dhXXp://legal.yandex.ru/elements_agreement/
dhXXp://legal.yandex.ru/elements_agreement/
_Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF}
_Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF}
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe
DAEMON Tools Lite ve Yandex.Bar
DAEMON Tools Lite ve Yandex.Bar
Yandex.Bar
Yandex.Bar
Instalovat Yandex.Bar Seznam Edition
Instalovat Yandex.Bar Seznam Edition
Nastavit Seznam.cz jako domovskou str
Nastavit Seznam.cz jako domovskou str
m Yandex.Baru Seznam Edition souhlas
m Yandex.Baru Seznam Edition souhlas
Yandex.Bar v barv
Yandex.Bar v barv
tu Yandex.Bar v barv
tu Yandex.Bar v barv
by Seznam.cz
by Seznam.cz
The file "%s" is signed and the signature was verified.
The file "%s" is signed and the signature was verified.
The file "%s" is not signed.
The file "%s" is not signed.
An unknown error occurred trying to verify the signature of the "%s" file.
An unknown error occurred trying to verify the signature of the "%s" file.
Error is: 0x%x.
Error is: 0x%x.
For using type: downloader.exe --partner [--distr ] [--try] [--sync]
For using type: downloader.exe --partner [--distr ] [--try] [--sync]
Oops after %d bytes.
Oops after %d bytes.
File downloading complete: %s, size: %d
File downloading complete: %s, size: %d
Speed: %dKBs
Speed: %dKBs
File doesn't exist: %s
File doesn't exist: %s
Can't create file '%s'
Can't create file '%s'
Error: 0x%x
Error: 0x%x
Exit code: 0x%x
Exit code: 0x%x
Can't get exit code. Error: 0x%x
Can't get exit code. Error: 0x%x
Downloading installer: %s
Downloading installer: %s
try %d
try %d
HRESULT: 0xX
HRESULT: 0xX
Distr: %s
Distr: %s
Try to run: %s %s
Try to run: %s %s
%d.%d.%d
%d.%d.%d
Val: %d
Val: %d
templ: %s
templ: %s
%s: %s
%s: %s
New partner name: %s
New partner name: %s
url: %s
url: %s
name: %s
name: %s
fb: %s
fb: %s
lt: %s
lt: %s
\downloader.log
\downloader.log
cmd: %s
cmd: %s
ver: %s
ver: %s
os: %s
os: %s
elevated: %s
elevated: %s
\seed.txt
\seed.txt
Params: '%s'
Params: '%s'
hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss
hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss
hXXp://download.yandex.ru/yandex-pack/downloader/info.rss
hXXp://download.yandex.ru/yandex-pack/downloader/info.rss
hXXp://downloader.yandex.net/yandex-pack/
hXXp://downloader.yandex.net/yandex-pack/
YandexPackSetup.exe
YandexPackSetup.exe
YandexSearch.exe
YandexSearch.exe
DebugURL
DebugURL
downloader.yandex.net
downloader.yandex.net
download.yandex.ru
download.yandex.ru
suffix: %s
suffix: %s
%d.%d.%d.%d
%d.%d.%d.%d
0.1.0.16
0.1.0.16
download.exe
download.exe
DT Yandex Setup.exe
DT Yandex Setup.exe
WMIADAP.EXE_3440:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
ntdll.DLL
ntdll.DLL
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
wbemcomn.dll
wbemcomn.dll
OLEAUT32.dll
OLEAUT32.dll
ole32.dll
ole32.dll
loadperf.dll
loadperf.dll
`.bik
`.bik
PSSSSSSh
PSSSSSSh
WMIADAP.exe
WMIADAP.exe
?CloseSubKey@CRegistry@@AAEXXZ
?CloseSubKey@CRegistry@@AAEXXZ
?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z
?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z
?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z
?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z
?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z
?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z
?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z
?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z
?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z
?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z
?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z
?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z
?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z
?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z
?GetCurrentSubKeyCount@CRegistry@@QAEKXZ
?GetCurrentSubKeyCount@CRegistry@@QAEKXZ
?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z
?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z
?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z
?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z
?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z
?GetLongestSubKeySize@CRegistry@@QAEKXZ
?GetLongestSubKeySize@CRegistry@@QAEKXZ
?GethKey@CRegistry@@QAEPAUHKEY__@@XZ
?GethKey@CRegistry@@QAEPAUHKEY__@@XZ
?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z
?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z
?NextSubKey@CRegistry@@QAEKXZ
?NextSubKey@CRegistry@@QAEKXZ
?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z
?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z
?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z
?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z
?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z
?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z
?OpenSubKey@CRegistry@@AAEKXZ
?OpenSubKey@CRegistry@@AAEKXZ
?RewindSubKeys@CRegistry@@QAEXXZ
?RewindSubKeys@CRegistry@@QAEXXZ
?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z
?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z
?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z
?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z
?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z
?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z
?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z
?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z
?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z
?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z
?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z
?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z
?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z
?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z
?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z
?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z
?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z
?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z
?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z
?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z
?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z
?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z
QSSh0
QSSh0
Invalid parameter passed to C runtime function.
Invalid parameter passed to C runtime function.
ntdll.dll
ntdll.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
RegEnumKeyW
RegEnumKeyW
RegDeleteKeyW
RegDeleteKeyW
RegQueryInfoKeyW
RegQueryInfoKeyW
_amsg_exit
_amsg_exit
_acmdln
_acmdln
?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z
?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z
WMIADAP.pdb
WMIADAP.pdb
5m6z6
5m6z6
%s_x
%s_x
%s_x_
%s_x_
Global\WMI_SysEvent_Semaphore_%d
Global\WMI_SysEvent_Semaphore_%d
WinMSGWMIADAP
WinMSGWMIADAP
\\.\root\cimv2
\\.\root\cimv2
WMIADAP Msg window
WMIADAP Msg window
\\.\root\wmi
\\.\root\wmi
PSAPI.DLL
PSAPI.DLL
x=%s
x=%s
Describes all the counters supported via WMI Hi-Performance providers
Describes all the counters supported via WMI Hi-Performance providers
_new.ini
_new.ini
xx %s%s.ini
xx %s%s.ini
xx %s
xx %s
\\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\""
\\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\""
WmiApRes.dll
WmiApRes.dll
%s\%s
%s\%s
6.1.7600.16385 (win7_rtm.090713-1255)
6.1.7600.16385 (win7_rtm.090713-1255)
wmicookr.dll
wmicookr.dll
Windows
Windows
Operating System
Operating System
6.1.7600.16385
6.1.7600.16385